P20 · p20.remote-authenticated-product-mcp
source implemented not deployedStreamable HTTP, OAuth metadata, origin checks, bearer introspection, session expiry and revocation exist in source; durable AWS broker plus real Chat/Work/Codex proof remain required.
P21 · p21.session-signing-broker-foundation
source foundation not deployedPer-agent sessions, operation receipts and shared QA-wallet budget accounting exist in source; DynamoDB/IAM/KMS readback, wallet enrollment and deployed revocation proof remain required.
P22 · p22.isolated-browser-worker
source implemented not deployedBrowser-worker policy, Caster-origin allowlist, consent checks and screenshot bounds exist in source; isolated AWS browser deployment and UI-to-API-to-data receipts remain required. Browser page content is treated as untrusted data.
P23 · p23.active-source-merger-feedback
source implemented not deployedExact-candidate merge policies, trusted-check requirements, lease heartbeat checks and release-feedback guards exist in source; an authorized integration-target write remains required.
P24 · p24.release-dispatcher-feedback
source implemented not deployedThe dispatcher requires a merged candidate, trusted checks, measured capacity and immutable image digest before invoking the fenced release script once; release lease, canary, public verification and rollback proof remain required.
P25 · p25.product-tool-docs-catalog
source foundation not deployedVersioned source catalog, service docs and this in-app route provide customer-facing connection, workflow, revocation and troubleshooting guidance; deployed route verification remains required.