mirror of
https://github.com/rcourtman/Pulse.git
synced 2026-09-10 02:25:56 +00:00
Govern commercial offer and lifecycle
This commit is contained in:
@@ -4,8 +4,8 @@
|
||||
> Primary v6 execution authority is `docs/release-control/v6/internal/SOURCE_OF_TRUTH.md` (+ `docs/release-control/v6/internal/status.json`).
|
||||
> This file remains the detailed pricing evidence/spec and must stay aligned with the release-control source.
|
||||
|
||||
> **Status:** APPROVED — Final structure for v6 launch.
|
||||
> **Date:** 2026-02-25
|
||||
> **Status:** APPROVED — Current commercial contract.
|
||||
> **Date:** 2026-07-14
|
||||
> **Replaces:** All previous pricing documents and v5 pricing structure.
|
||||
|
||||
This document is the single source of truth for Pulse v6 pricing, tiering, feature
|
||||
@@ -186,6 +186,19 @@ marketing pitch focuses on three things:
|
||||
Relay connectivity and the team extras (RBAC, audit logging, reporting, and agent profiles)
|
||||
are bundled, but they are supporting entitlements rather than evidence of a product ladder.
|
||||
|
||||
### Self-hosted license and support scope
|
||||
|
||||
- One Relay or Pro subscription covers one owner-operated Pulse environment.
|
||||
- Monitored systems and child resources are not metered.
|
||||
- The subscription permits three concurrent activations inside that environment
|
||||
for primary, migration, and recovery use. Independently operated client
|
||||
environments require MSP.
|
||||
- Verified administrative ownership transfer is supported; resale, sharing,
|
||||
and unverified third-party assignment are prohibited.
|
||||
- Relay and Pro include verified commercial support for billing, activation,
|
||||
transfer, configuration, and diagnostics, typically within two business
|
||||
days. This is not a contractual SLA or priority-support commitment.
|
||||
|
||||
### Pro+ — Legacy continuity tier only
|
||||
|
||||
Existing Pro+ entitlements remain supported for continuity, but Pro+ is no longer part of
|
||||
@@ -195,10 +208,14 @@ still preserve self-hosted monitoring and child-resource volume as not metered w
|
||||
|
||||
---
|
||||
|
||||
## Cloud Tiers (Hosted — separate page)
|
||||
## Cloud Tiers (Hosted — unavailable)
|
||||
|
||||
All Cloud tiers include everything in Pro + managed hosting + daily automated backups.
|
||||
Cloud launches alongside v6 (not behind a waitlist).
|
||||
Cloud is not currently offered. The prices and tier shapes below are dormant
|
||||
commercial proposals retained for implementation planning; they are not a
|
||||
signup promise, supported capacity contract, trial promise, or current support
|
||||
commitment. Cloud must not reopen until its economic unit/caps, card policy,
|
||||
support, retention, export, cancellation, reactivation, and runtime enforcement
|
||||
pass the governed Cloud reopening gate.
|
||||
|
||||
### Cloud Starter — $29/month or $249/year
|
||||
|
||||
@@ -242,7 +259,9 @@ Cloud launches alongside v6 (not behind a waitlist).
|
||||
|
||||
Pulse MSP is not the shared-process organization model. The default MSP route is provider-hosted: the MSP runs a Stripe-free control plane that creates one isolated Pulse runtime/container per client workspace. A signed MSP license sets the plan version and client workspace cap. Pulse-hosted MSP is an optional request-assisted path where Pulse operates that provider stack.
|
||||
|
||||
MSP is built and staged for assisted rollout, but it is not a public self-serve checkout path yet. Pricing, availability, and launch wording need owner review before publication.
|
||||
MSP is an assisted preview, not a public self-serve checkout path. Public copy
|
||||
may show the recorded monthly and annual prices, but fulfillment remains
|
||||
request-assisted and must not imply immediate Pulse-hosted provisioning.
|
||||
|
||||
### MSP Starter — $149/month or $1,490/year
|
||||
|
||||
@@ -349,9 +368,28 @@ There is no proactive self-hosted upsell cadence in v6 GA. If older compatibilit
|
||||
mention prompt reduction, treat them as legacy controls; the v6 default is already quiet unless
|
||||
the user enters an explicit commercial path or has an entitlement state that needs attention.
|
||||
|
||||
### 9. Cloud launches with v6
|
||||
Not behind a waitlist. Real pricing, real signup. Captures convenience buyers who don't
|
||||
want to self-host.
|
||||
### 9. Cloud remains unavailable until reopening proof
|
||||
The public Cloud surface must state that signup is closed. Dormant Cloud prices,
|
||||
caps, trial language, and implementation paths remain non-public planning
|
||||
inputs until the governed reopening gate passes.
|
||||
|
||||
### 10. Self-service lifecycle contract
|
||||
|
||||
| Change | Effective time | Billing treatment |
|
||||
|---|---|---|
|
||||
| Community to Relay or Pro | After successful checkout | New subscription |
|
||||
| Relay to Pro | Immediate after explicit quote and successful payment | Prorated |
|
||||
| Monthly to annual, same tier | Immediate after explicit quote and successful payment | Prorated |
|
||||
| Pro to Relay | Current paid period end | No proration |
|
||||
| Annual to monthly, same tier | Current paid period end | No proration |
|
||||
| Voluntary cancellation | Current paid period end | No proration |
|
||||
|
||||
Combined transitions use the most restrictive timing rule. Voluntary
|
||||
cancellation has a seven-day recovery-only window after paid entitlement ends;
|
||||
payment failure has a separate seven-day functional grace period. Downgrades
|
||||
preserve configuration, report definitions, and audit records. Out-of-tier
|
||||
history and generated artifacts soft-hide for 30 days and become
|
||||
purge-eligible after 60 days.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -236,19 +236,16 @@ user language should update the control plane.
|
||||
## Current State
|
||||
|
||||
1. v6 is the current active release profile.
|
||||
2. `v6-ga-promotion` is the current active engineering target.
|
||||
The next public v6 release target is GA from the current
|
||||
`pulse/v6-release` branch after accumulated post-RC7 fixes and final
|
||||
current-branch validation. The published RC7 candidate must not be promoted
|
||||
unchanged, and another RC is not planned by default unless a release-owner
|
||||
decision changes that.
|
||||
3. `v6-product-lane-expansion` remains planned behind the GA launch target.
|
||||
Its candidate-lane surface remains available in the linked
|
||||
`candidate_lanes` and `coverage_gaps`, but it should not displace release
|
||||
execution while GA is the current objective.
|
||||
4. The older RC line reached the historical `release_ready` floor, but the
|
||||
current GA target now requires fresh current-branch validation because the
|
||||
release will include accumulated fixes and changes after RC7.
|
||||
2. `v6-product-lane-expansion` is the current active engineering target.
|
||||
Pulse v6 GA and the initial 6.0.x patch line have shipped; active
|
||||
development and stable release preparation now run on `main`.
|
||||
3. `v6-ga-promotion` is complete. Its release records remain historical
|
||||
evidence and must not keep pre-GA branch, checkout, or readiness posture
|
||||
active in current lane state.
|
||||
4. Candidate lanes and coverage gaps now route post-GA product expansion.
|
||||
Release-blocking correctness work may still override that default queue
|
||||
when a shipped customer contract can drift across billing, entitlements,
|
||||
runtime behavior, or public copy.
|
||||
5. `v6-rc-stabilization` is completed after the shipped RCs established the
|
||||
current monitored-first floor and the active objective moved to stable
|
||||
promotion.
|
||||
@@ -256,8 +253,8 @@ user language should update the control plane.
|
||||
7. The existing v6 control surfaces are still live, but they now sit underneath
|
||||
an evergreen Pulse control plane rather than pretending to be the whole
|
||||
long-term system.
|
||||
8. Until the explicit post-GA branch cutover happens, both prerelease and
|
||||
stable v6 promotions resolve to `pulse/v6-release` via `control_plane.json`.
|
||||
8. Both prerelease and stable v6 promotions resolve to `main` via
|
||||
`control_plane.json`.
|
||||
9. Legacy maintenance releases that still feed governed automation outside the
|
||||
active v6 line must also resolve through `control_plane.json`.
|
||||
Right now the remaining `5.1.x` stable maintenance line resolves to `main`
|
||||
|
||||
@@ -157,6 +157,70 @@ Companion drill:
|
||||
legacy recurring price, or cancellation/reactivation leaves pricing and
|
||||
entitlement state inconsistent across Stripe, Pulse runtime, and customer UI.
|
||||
|
||||
## Gate: `self-hosted-commercial-transition-coherence`
|
||||
|
||||
- Why this is risky:
|
||||
Relay/Pro and cadence changes cross Stripe proration and schedules, durable
|
||||
webhook processing, grandfathering, local entitlement projection, license
|
||||
versioning, Relay grant enforcement, downgrade preservation, and customer-
|
||||
visible account state. The current implementation can update Stripe price
|
||||
identifiers without atomically changing tier or features, which can charge
|
||||
for one plan while granting another.
|
||||
- Primary runtime surfaces:
|
||||
`pulse-pro/license-server/v6_checkout.go`
|
||||
`pulse-pro/license-server/v6_stripe.go`
|
||||
`pulse-pro/license-server/v6_reconcile.go`
|
||||
`pulse-pro/license-server/v6_state.go`
|
||||
`pulse-pro/license-server/v6_store.go`
|
||||
`pulse-pro/license-server/v6_grants.go`
|
||||
`pkg/licensing/...`
|
||||
Pulse Account Billing and Stripe customer/subscription state
|
||||
- Automated proof:
|
||||
Local unit and integration proof now covers the Community/Relay/Pro and
|
||||
monthly/annual timing matrix, quote/apply parameter binding, idempotent
|
||||
immediate retry convergence, schedule creation/reuse/cancellation ownership,
|
||||
atomic commercial snapshot projection, payment-failure versus cancellation
|
||||
grace, downgrade history timing, report entitlement denial, and safe artifact
|
||||
purge. The remaining duplicate/reversed/missing external-event matrix and
|
||||
restrictive Relay grant version-floor scenario require the governed Stripe
|
||||
test-mode rehearsal; until that evidence is registered, the gate remains
|
||||
blocked.
|
||||
- Manual scenario:
|
||||
1. In Stripe test mode, create fresh Community-to-Relay and Community-to-Pro
|
||||
acquisitions for monthly and annual plans.
|
||||
2. Exercise immediate quoted/prorated Relay-to-Pro and monthly-to-annual
|
||||
changes, including success, decline, timeout-after-success, duplicate
|
||||
request, and replay.
|
||||
3. Exercise renewal-bound Pro-to-Relay and annual-to-monthly changes,
|
||||
including cancellation/resume before the effective timestamp.
|
||||
4. Exercise voluntary paid-through expiry, recovery-only access, involuntary
|
||||
payment-failure grace and recovery, grace expiry, refund/dispute, and
|
||||
current-price re-entry after continuity ends.
|
||||
5. Reverse, duplicate, suppress, and later replay Stripe events; reconcile
|
||||
from the current Stripe snapshot and confirm the same final state.
|
||||
6. Confirm every material entitlement reduction increments
|
||||
`license_version`, rejects the old grant in Relay/runtime, and preserves
|
||||
configuration, report definitions, audit records, and the governed
|
||||
downgrade history window.
|
||||
7. Exercise the buyer/account journey at desktop and phone width and confirm
|
||||
the quoted amount, effective date, plan, cadence, cancellation state, and
|
||||
recovery behavior match runtime truth.
|
||||
- Pass when:
|
||||
Each scenario leaves exactly one billing contract and one entitlement
|
||||
projection for the commercial subject; Stripe price, local plan, cadence,
|
||||
runtime capabilities, license version, and customer-visible state agree;
|
||||
replay/order variation does not change the result; and no downgrade or
|
||||
cancellation deletes protected customer configuration or records.
|
||||
- Latest exercised record:
|
||||
Local implementation and browser evidence is recorded in
|
||||
`docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md`.
|
||||
No qualifying real-external-e2e record exists yet.
|
||||
- Block release if:
|
||||
Any supported transition can charge and grant different plans, mutate
|
||||
entitlement without a version bump, restore ended grandfathering, rely on
|
||||
mutable Customer Portal plan-switch configuration, or produce different
|
||||
state under duplicate, missing, or reordered Stripe delivery.
|
||||
|
||||
## Gate: `known-rc-issue-closure-for-ga`
|
||||
|
||||
- Why this is risky:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# Pulse v6 Source Of Truth
|
||||
|
||||
Last updated: 2026-07-02
|
||||
Last updated: 2026-07-14
|
||||
Status: ACTIVE
|
||||
|
||||
This file is the stable human governance layer for the active v6 release
|
||||
@@ -471,6 +471,13 @@ Assertion design rules:
|
||||
document bound to the audited SHA selected at runtime. The checker must
|
||||
never execute real-lab, device, relay, or other mutation-gated commands
|
||||
itself.
|
||||
24. Do not ship or expose self-service plan or cadence transitions unless the
|
||||
authoritative Stripe subscription snapshot, local billing contract,
|
||||
entitlement projection, continuity epoch, license version, and grant
|
||||
revocation/outbox state converge through one idempotent transition
|
||||
authority. A customer must never pay for one plan while Pulse grants
|
||||
another, and duplicate, missing, or reordered webhook delivery must not
|
||||
change the final commercial state.
|
||||
|
||||
## Locked Decisions
|
||||
|
||||
@@ -545,6 +552,40 @@ Assertion design rules:
|
||||
trust, or installer/update/rollback path changed, and the exact-SHA release
|
||||
dry run passed. Those risk conditions require RC lineage unless an active
|
||||
customer-harm emergency is recorded through the hotfix exception.
|
||||
16. The canonical self-hosted offer is job-based rather than a
|
||||
good/better/best ladder: Community is the free local monitoring foundation,
|
||||
Relay is remote access plus Pulse Mobile pairing, push, and 14-day history,
|
||||
and Pro is Patrol-powered investigation and governed operations with
|
||||
90-day history and Relay bundled. One Relay or Pro subscription covers one
|
||||
owner-operated environment with unmetered monitored-system and child-
|
||||
resource volume plus three concurrent primary/migration/recovery
|
||||
activations. It does not cover independently operated client environments.
|
||||
17. Verified administrative ownership transfers are permitted, while resale,
|
||||
sharing, and unverified third-party assignment are prohibited. Relay and
|
||||
Pro include standard verified commercial support for billing, activation,
|
||||
transfer, configuration, and diagnostics, normally targeted within two
|
||||
business days without a contractual SLA or priority-support promise.
|
||||
18. Self-hosted subscription transitions follow the approved lifecycle matrix
|
||||
in
|
||||
`docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md`:
|
||||
Relay-to-Pro and monthly-to-annual changes are immediate only after an
|
||||
explicit prorated quote and successful payment; capability downgrades and
|
||||
annual-to-monthly changes occur at renewal without proration; voluntary
|
||||
cancellation ends paid capability at the paid-through timestamp; a
|
||||
separate seven-day recovery-only window grants no paid capability; and
|
||||
involuntary payment failure receives seven days of functional grace.
|
||||
Configuration, report definitions, and audit records survive downgrade;
|
||||
out-of-tier history and generated artifacts soft-hide for 30 days and
|
||||
become purge-eligible after 60 days. Completed cancellation or a completed
|
||||
tier/cadence change ends grandfathered recurring-price continuity.
|
||||
19. Cloud is unavailable until a governed reopening gate proves its economic
|
||||
unit/caps, card policy, support, retention, export, cancellation,
|
||||
reactivation, and runtime enforcement. Historical Cloud prices and caps
|
||||
are dormant proposals, not a current offer. MSP remains an assisted
|
||||
preview, provider-hosted by default, with 5/15/40 isolated client-
|
||||
workspace limits; public copy may state the recorded monthly and annual
|
||||
prices but must not promise immediate self-service checkout or Pulse-hosted
|
||||
fulfillment.
|
||||
|
||||
## TrueNAS Support Floor
|
||||
|
||||
|
||||
+169
@@ -0,0 +1,169 @@
|
||||
# Commercial Offer And Lifecycle Contract
|
||||
|
||||
Date: 2026-07-14
|
||||
Owner: project owner
|
||||
Status: approved for implementation
|
||||
|
||||
## Decision
|
||||
|
||||
Pulse commercial packaging and lifecycle behavior must converge on one
|
||||
versioned offer contract. The public site, Pulse Account, in-product plan
|
||||
surfaces, checkout projection, Stripe catalog audit, license-server billing
|
||||
state, runtime entitlements, and support policy must not maintain independent
|
||||
commercial definitions.
|
||||
|
||||
## Self-Hosted Offer
|
||||
|
||||
1. Community is the free local monitoring foundation with 7-day history.
|
||||
2. Relay is the secure remote-access, Pulse Mobile pairing, push-delivery, and
|
||||
14-day-history service.
|
||||
3. Pro is the Patrol-powered investigation and governed-operations product
|
||||
with 90-day history and team/admin controls. Pro includes Relay; a buyer
|
||||
never needs simultaneous Relay and Pro subscriptions for one environment.
|
||||
4. Community, Relay, and Pro solve distinct jobs. They must not be presented
|
||||
as a recommended good/better/best ladder.
|
||||
5. Ordinary self-hosted trial acquisition remains retired.
|
||||
|
||||
## License Scope And Support
|
||||
|
||||
1. One Relay or Pro subscription covers one owner-operated Pulse environment.
|
||||
2. Monitored-system and child-resource volume is not metered for self-hosted
|
||||
Community, Relay, or Pro.
|
||||
3. A paid subscription permits three concurrent activations inside that one
|
||||
environment for primary, migration, and recovery use. It does not license
|
||||
independently operated client environments; that is the MSP product job.
|
||||
4. Verified administrative ownership transfer is permitted. Resale, sharing,
|
||||
and unverified third-party assignment are prohibited.
|
||||
5. Relay and Pro include standard verified commercial support for billing,
|
||||
activation, transfer, configuration, and diagnostics. The public target is
|
||||
typically within two business days, without a contractual SLA or a
|
||||
priority-support promise.
|
||||
|
||||
## Subscription Transition Matrix
|
||||
|
||||
| From | To | Effective time | Billing treatment | Entitlement treatment |
|
||||
|---|---|---|---|---|
|
||||
| Community | Relay or Pro | After successful checkout | New subscription | Grant the purchased plan atomically |
|
||||
| Relay | Pro, same cadence | Immediate after explicit quote and successful prorated payment | Prorated upgrade | Pro plus bundled Relay |
|
||||
| Monthly | Annual, same tier | Immediate after explicit quote and successful prorated payment | Prorated cadence change | Tier unchanged |
|
||||
| Pro | Relay | Current paid period end | No proration | Remove Pro-only capabilities; retain Relay |
|
||||
| Annual | Monthly, same tier | Current paid period end | No proration | Tier unchanged |
|
||||
| Any paid plan | Community by cancellation | Current paid period end | No proration | Paid capabilities end at the paid-through timestamp |
|
||||
|
||||
Combined transitions follow the most restrictive rule. Any transition that
|
||||
reduces capabilities or moves annual to monthly takes effect at renewal.
|
||||
Customer-visible confirmation must state the effective date and quoted charge
|
||||
or credit before mutation.
|
||||
|
||||
## Cancellation, Grace, And Continuity
|
||||
|
||||
1. Voluntary cancellation is scheduled for period end. Paid capabilities end
|
||||
at the paid-through timestamp.
|
||||
2. A seven-day post-term recovery window may support subscription reactivation,
|
||||
license retrieval, and account recovery, but it is not a paid-entitlement
|
||||
extension and must not grant Relay or Pro capabilities.
|
||||
3. Involuntary payment failure receives a separate seven-day functional grace
|
||||
period. Existing paid capabilities remain available during that grace, then
|
||||
fail closed if payment has not recovered.
|
||||
4. Reversing scheduled cancellation before the paid-through timestamp
|
||||
preserves subscription continuity.
|
||||
5. Grandfathered recurring price continuity survives only while the original
|
||||
recurring subscription remains continuous. Completed cancellation or a
|
||||
completed tier/cadence change exits the grandfathered contract; later
|
||||
re-entry uses current pricing.
|
||||
6. A full refund or dispute revokes the affected paid entitlement and requires
|
||||
explicit reactivation or repurchase.
|
||||
|
||||
## Downgrade Preservation
|
||||
|
||||
1. Configuration, report definitions, and audit records are not deleted solely
|
||||
because a customer downgrades.
|
||||
2. Pro-only configuration remains stored but inert while the entitlement is
|
||||
absent.
|
||||
3. History and generated artifacts outside the lower tier's active window are
|
||||
soft-hidden for 30 days and become purge-eligible after 60 days.
|
||||
4. Re-upgrade during the soft-hide window restores access without
|
||||
reconfiguration.
|
||||
5. Every capability, tier, cadence, restrictive state, or entitlement change
|
||||
increments `license_version` and invalidates obsolete grants atomically.
|
||||
|
||||
## Cloud And MSP Availability
|
||||
|
||||
1. Cloud is unavailable. Its historical prices, caps, trial, and support labels
|
||||
are dormant proposals, not a current customer offer. Cloud cannot reopen
|
||||
until card policy, economic unit/caps, support, retention, export,
|
||||
cancellation, reactivation, and runtime enforcement pass a governed
|
||||
readiness gate.
|
||||
2. MSP is an assisted preview and provider-hosted by default. Starter, Growth,
|
||||
and Scale retain 5, 15, and 40 isolated client-workspace limits at the
|
||||
recorded monthly and annual prices. Enterprise remains custom.
|
||||
3. Public MSP copy may publish the recorded monthly and annual prices, but it
|
||||
must not promise immediate self-service checkout or Pulse-hosted fulfillment.
|
||||
4. Pulse-hosted MSP remains an optional assisted arrangement, not the default
|
||||
public delivery model.
|
||||
|
||||
## Implementation Boundary
|
||||
|
||||
Stripe remains billing truth, but one Pulse-owned transition authority must
|
||||
apply the authoritative Stripe snapshot atomically to billing contract,
|
||||
entitlement projection, continuity epoch, transition history, license version,
|
||||
and grant-revocation outbox state. Checkout, webhook, reconciliation, refunds,
|
||||
support/admin actions, and future Pulse Account transitions must converge on
|
||||
that authority. Stripe Customer Portal subscription updates remain disabled;
|
||||
Pulse-owned plan transitions must not depend on mutable portal configuration.
|
||||
|
||||
## Proof Required Before Closure
|
||||
|
||||
1. Contract drift proof across public pricing, Pulse Account, in-product plan
|
||||
presentation, Stripe product/price descriptions, support policy, and runtime
|
||||
entitlements.
|
||||
2. Complete Community/Relay/Pro and monthly/annual transition matrix proof.
|
||||
3. Stripe test-mode payment, proration, schedule, cancellation, payment-failure,
|
||||
refund, and re-entry proof.
|
||||
4. Duplicate, reversed, missing, and replayed webhook convergence proof.
|
||||
5. Restrictive-transition grant version-floor proof in Pulse and Relay.
|
||||
6. Downgrade soft-hide, restoration, purge-eligibility, and configuration
|
||||
preservation proof.
|
||||
7. Desktop and phone-width buyer/account browser proof.
|
||||
8. A read-only production Stripe catalog and portal expected-state audit before
|
||||
any separately approved external configuration change.
|
||||
|
||||
## Implemented Local Evidence
|
||||
|
||||
The 2026-07-14 implementation slice now provides the local, non-transactional
|
||||
foundation required by this contract:
|
||||
|
||||
1. `pulse-pro/license-server/v6_commercial_projection.go` owns atomic catalog,
|
||||
billing-contract, entitlement, continuity-epoch, license-version, transition
|
||||
history, and revocation-outbox projection. Unknown or multi-price snapshots
|
||||
fail closed, and checkout, subscription, invoice, cancellation, payment-
|
||||
failure, and refund paths converge on that projection.
|
||||
2. `pulse-pro/license-server/v6_commercial_transitions.go` owns authenticated,
|
||||
durable transition quotes. Immediate expansion uses the exact quoted Stripe
|
||||
proration timestamp with `pending_if_incomplete`; restrictive changes use a
|
||||
renewal-bound subscription schedule without proration. Retry paths reuse
|
||||
Stripe idempotency keys and already-created schedules.
|
||||
3. `pulse-pro/landing-page/manage.html` exposes invoices/payment methods,
|
||||
quoted Relay/Pro and cadence changes, period-end cancellation, reactivation,
|
||||
and scheduled-change cancellation behind an emailed verification code.
|
||||
4. `pkg/licensing/subscription_transitions.go`, `pkg/metrics/store.go`, and
|
||||
`internal/api/report_schedules.go` persist downgrade timing, keep protected
|
||||
configuration and report definitions, restrict out-of-tier access
|
||||
immediately, delay physical history cleanup until day 60, block background
|
||||
report execution without the current entitlement, and purge generated
|
||||
report artifacts without following symlinks after eligibility.
|
||||
5. Local proof is green for the complete license-server Go suite, 359 Python
|
||||
pricing/copy tests, the Pulse licensing/metrics/API suites, and desktop plus
|
||||
390-pixel buyer/account browser exercise. These are local implementation and
|
||||
rehearsal facts, not a substitute for the required Stripe test-mode and
|
||||
production read-only evidence.
|
||||
|
||||
## Remaining Readiness Boundary
|
||||
|
||||
The `self-hosted-commercial-transition-coherence` gate remains blocked. No
|
||||
Stripe test-mode mutation, live catalog/configuration change, purchase,
|
||||
deployment, or production customer-data access was authorized or performed in
|
||||
this slice. Before self-service is released, the project still needs the
|
||||
governed external transition matrix, event-order/reconciliation exercise,
|
||||
Relay version-floor proof, and read-only production catalog/portal audit named
|
||||
above.
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"version": "6.0",
|
||||
"updated_at": "2026-07-02",
|
||||
"updated_at": "2026-07-14",
|
||||
"scope": {
|
||||
"active_repos": [
|
||||
"pulse",
|
||||
@@ -4676,6 +4676,55 @@
|
||||
"evidence_tier": "test-proof"
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "RA41",
|
||||
"summary": "Self-hosted commercial state remains coherent across the canonical offer, Stripe billing, Pulse Account, license-server persistence, runtime and Relay entitlements, support policy, and customer-visible lifecycle: Community, Relay, and Pro keep distinct jobs with Pro bundling Relay; every tier or cadence transition applies the approved timing and proration matrix through one idempotent transition authority; restrictive changes invalidate old grants; downgrade preserves governed customer data; and replay, cancellation, refund, grace, or re-entry cannot make billing and entitlement drift.",
|
||||
"kind": "trust-gate",
|
||||
"blocking_level": "release-ready",
|
||||
"proof_type": "manual",
|
||||
"lane_ids": [
|
||||
"L2",
|
||||
"L3",
|
||||
"L12",
|
||||
"L17"
|
||||
],
|
||||
"subsystem_ids": [
|
||||
"cloud-paid"
|
||||
],
|
||||
"release_gate_ids": [
|
||||
"self-hosted-commercial-transition-coherence"
|
||||
],
|
||||
"evidence": [
|
||||
{
|
||||
"repo": "pulse",
|
||||
"path": "docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md",
|
||||
"kind": "file"
|
||||
},
|
||||
{
|
||||
"repo": "pulse",
|
||||
"path": "docs/release-control/v6/internal/subsystems/cloud-paid.md",
|
||||
"kind": "file"
|
||||
},
|
||||
{
|
||||
"repo": "pulse",
|
||||
"path": "internal/api/report_schedules_test.go",
|
||||
"kind": "file",
|
||||
"evidence_tier": "test-proof"
|
||||
},
|
||||
{
|
||||
"repo": "pulse",
|
||||
"path": "pkg/licensing/subscription_test.go",
|
||||
"kind": "file",
|
||||
"evidence_tier": "test-proof"
|
||||
},
|
||||
{
|
||||
"repo": "pulse-pro",
|
||||
"path": "license-server/v6_commercial_transitions_test.go",
|
||||
"kind": "file",
|
||||
"evidence_tier": "test-proof"
|
||||
}
|
||||
]
|
||||
}
|
||||
],
|
||||
"evidence_reference_policy": {
|
||||
@@ -4778,15 +4827,15 @@
|
||||
"status": "partial",
|
||||
"completion": {
|
||||
"state": "bounded-residual",
|
||||
"summary": "Commercial readiness is coherent for explicit preview, checkout handoff, paid-user activation/recovery, hosted-mode paths, and the first Pulse Intelligence value-evidence reporting surface, while default self-hosted app surfaces stay free-first and non-promotional; because v6 is not publicly GA, production public checkout stays on v5 until explicit GA cutover approval, and the production public flip plus release-day rollout execution plus the broader governed Patrol control experience remain separate follow-ups.",
|
||||
"summary": "The approved Community / Relay / Pro contract is now projected into local public/account copy, support and legal policy, atomic license-server entitlement state, quoted Relay/Pro and cadence transition sagas, and runtime downgrade preservation. Local Go, copy-model, and desktop/phone browser proof is green. Self-service remains unreleased until the governed Stripe test-mode event/reconciliation matrix, Relay version-floor proof, and production read-only catalog/portal audit satisfy the commercial transition gate.",
|
||||
"tracking": [
|
||||
{
|
||||
"kind": "lane-followup",
|
||||
"id": "commercial-ga-promotion-package"
|
||||
"id": "pulse-intelligence-pro-activation-loop"
|
||||
},
|
||||
{
|
||||
"kind": "lane-followup",
|
||||
"id": "pulse-intelligence-pro-activation-loop"
|
||||
"kind": "release-gate",
|
||||
"id": "self-hosted-commercial-transition-coherence"
|
||||
}
|
||||
]
|
||||
},
|
||||
@@ -4847,11 +4896,16 @@
|
||||
"name": "Cloud paid readiness",
|
||||
"target_score": 8,
|
||||
"current_score": 8,
|
||||
"status": "target-met",
|
||||
"status": "partial",
|
||||
"completion": {
|
||||
"state": "complete",
|
||||
"summary": "Cloud-paid runtime and billing surfaces are at the current tracked RC floor, including real cancellation/reactivation continuity across checkout, entitlement boundaries, and the shared commercial billing shell/model now used by both self-hosted Pulse Pro and hosted organization billing.",
|
||||
"tracking": []
|
||||
"state": "bounded-residual",
|
||||
"summary": "The local commercial projection now changes Stripe catalog identity, tier, cadence, features, continuity epoch, license version, transition history, and revocation outbox atomically, with a quote-bound transition authority for self-hosted plan and cadence changes. Cloud remains unavailable and MSP remains an assisted preview. External Stripe event/reconciliation and Relay version-floor proof remain governed release residuals.",
|
||||
"tracking": [
|
||||
{
|
||||
"kind": "release-gate",
|
||||
"id": "self-hosted-commercial-transition-coherence"
|
||||
}
|
||||
]
|
||||
},
|
||||
"blockers": [],
|
||||
"subsystems": [
|
||||
@@ -5907,11 +5961,16 @@
|
||||
"name": "Customer account portal",
|
||||
"target_score": 6,
|
||||
"current_score": 6,
|
||||
"status": "target-met",
|
||||
"status": "partial",
|
||||
"completion": {
|
||||
"state": "complete",
|
||||
"summary": "Pulse Account is now a first-class governed customer-account surface at the current RC floor: hosted accounts land directly in Workspaces, the signed-in shell stays task-first across Workspaces, Access, Billing, and Support, and MSP plus self-serve commercial actions converge on one coherent authenticated account boundary.",
|
||||
"tracking": []
|
||||
"state": "bounded-residual",
|
||||
"summary": "The self-hosted manage entry point is now Pulse-named and job-first, with verified invoice/payment access, quoted Relay/Pro and cadence changes, cancellation, reactivation, and scheduled-change cancellation. Retrieve, refund, and data-request utilities remain separate specialist jobs. The lane stays residual until real Stripe transition/reconciliation and Relay entitlement proofs satisfy the governed transition gate.",
|
||||
"tracking": [
|
||||
{
|
||||
"kind": "release-gate",
|
||||
"id": "self-hosted-commercial-transition-coherence"
|
||||
}
|
||||
]
|
||||
},
|
||||
"blockers": [],
|
||||
"subsystems": [],
|
||||
@@ -7874,6 +7933,46 @@
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "self-hosted-commercial-transition-coherence",
|
||||
"summary": "Confirm the approved self-hosted offer and lifecycle remain coherent across public pricing, Stripe billing, Pulse Account, license-server state, runtime and Relay entitlements, support policy, and customer-visible transitions: quoted/prorated immediate upgrades, renewal-bound reductions, paid-through cancellation, distinct recovery and payment-failure grace, downgrade preservation, grant version invalidation, and current-price re-entry all converge under replay and reconciliation.",
|
||||
"owner": "project-owner",
|
||||
"blocking_level": "release-ready",
|
||||
"minimum_evidence_tier": "real-external-e2e",
|
||||
"status": "blocked",
|
||||
"verification_doc": "docs/release-control/v6/internal/HIGH_RISK_RELEASE_VERIFICATION_MATRIX.md",
|
||||
"lane_ids": [
|
||||
"L2",
|
||||
"L3",
|
||||
"L12",
|
||||
"L17"
|
||||
],
|
||||
"evidence": [
|
||||
{
|
||||
"repo": "pulse",
|
||||
"path": "docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md",
|
||||
"kind": "file"
|
||||
},
|
||||
{
|
||||
"repo": "pulse",
|
||||
"path": "internal/api/report_schedules_test.go",
|
||||
"kind": "file",
|
||||
"evidence_tier": "test-proof"
|
||||
},
|
||||
{
|
||||
"repo": "pulse",
|
||||
"path": "pkg/licensing/subscription_test.go",
|
||||
"kind": "file",
|
||||
"evidence_tier": "test-proof"
|
||||
},
|
||||
{
|
||||
"repo": "pulse-pro",
|
||||
"path": "license-server/v6_commercial_transitions_test.go",
|
||||
"kind": "file",
|
||||
"evidence_tier": "test-proof"
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "settings-surface-layout-consistency",
|
||||
"summary": "Confirm comparable settings surfaces present the canonical page shell, with consistent header framing and no ad hoc top-level layout chrome.",
|
||||
@@ -8078,17 +8177,6 @@
|
||||
],
|
||||
"cross_repo": false
|
||||
},
|
||||
{
|
||||
"id": "commercial-ga-promotion-package",
|
||||
"summary": "Track the explicitly approved GA production public flip and release-day execution work for the self-hosted commercial package; until that work is active, production public checkout must remain on v5 with v6 approval disabled, and default self-hosted app surfaces must stay free-first and non-promotional.",
|
||||
"owner": "project-owner",
|
||||
"status": "planned",
|
||||
"recorded_at": "2026-04-20",
|
||||
"lane_ids": [
|
||||
"L2"
|
||||
],
|
||||
"subsystem_ids": []
|
||||
},
|
||||
{
|
||||
"id": "journey-post-ga-expansion",
|
||||
"summary": "Track broader same-lane end-to-end journey expansion beyond the current GA floor now that prerelease-to-GA promotion proof is recorded.",
|
||||
@@ -8631,7 +8719,21 @@
|
||||
]
|
||||
}
|
||||
],
|
||||
"work_claims": [],
|
||||
"work_claims": [
|
||||
{
|
||||
"id": "codex-lane-l23",
|
||||
"agent_id": "codex",
|
||||
"summary": "Implement an independent-ground-truth Pulse Patrol qualification benchmark with disposable live-lab, replay, Watch, investigation, remediation, safety, statistical gates, and reporting support.",
|
||||
"target_id": "v6-product-lane-expansion",
|
||||
"claimed_at": "2026-07-14T09:15:01Z",
|
||||
"heartbeat_at": "2026-07-14T09:15:01Z",
|
||||
"expires_at": "2026-07-14T11:15:01Z",
|
||||
"work_item": {
|
||||
"kind": "lane",
|
||||
"id": "L23"
|
||||
}
|
||||
}
|
||||
],
|
||||
"open_decisions": [],
|
||||
"source_of_truth_file": "docs/release-control/v6/internal/SOURCE_OF_TRUTH.md",
|
||||
"resolved_decisions": [
|
||||
@@ -9442,6 +9544,65 @@
|
||||
"lane_ids": [
|
||||
"L5"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "cloud-msp-availability-contract",
|
||||
"summary": "Cloud is unavailable; historical Cloud prices, caps, trial, and support labels are dormant proposals rather than a current offer, and reopening requires governed proof of card policy, economic unit/caps, support, retention, export, cancellation, reactivation, and runtime enforcement. MSP remains an assisted preview, provider-hosted by default, with 5/15/40 isolated client-workspace limits and recorded monthly/annual prices; this supersedes the earlier Starter self-serve buying motion until a later explicit decision reopens it.",
|
||||
"kind": "pricing",
|
||||
"decided_at": "2026-07-14",
|
||||
"subsystem_ids": [
|
||||
"cloud-paid"
|
||||
],
|
||||
"lane_ids": [
|
||||
"L2",
|
||||
"L3",
|
||||
"L4",
|
||||
"L17"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "self-hosted-commercial-scope-support-contract",
|
||||
"summary": "One Relay or Pro subscription covers one owner-operated Pulse environment with unmetered monitored systems and child resources plus three concurrent primary/migration/recovery activations. Verified administrative transfer is permitted, resale/sharing/unverified assignment is prohibited, and Relay/Pro include standard verified commercial support typically within two business days without an SLA or priority-support promise.",
|
||||
"kind": "contract",
|
||||
"decided_at": "2026-07-14",
|
||||
"subsystem_ids": [
|
||||
"cloud-paid"
|
||||
],
|
||||
"lane_ids": [
|
||||
"L2",
|
||||
"L3",
|
||||
"L17"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "self-hosted-commercial-transition-contract",
|
||||
"summary": "Relay-to-Pro and monthly-to-annual changes are immediate only after an explicit prorated quote and successful payment; capability downgrades and annual-to-monthly changes occur at renewal without proration; voluntary cancellation ends paid capability at the paid-through timestamp with a seven-day recovery-only window, while payment failure receives seven days of functional grace. Downgrade preserves configuration, report definitions, and audit records; out-of-tier history/artifacts soft-hide for 30 days and become purge-eligible after 60 days; completed cancellation or tier/cadence change ends grandfathered recurring-price continuity.",
|
||||
"kind": "contract",
|
||||
"decided_at": "2026-07-14",
|
||||
"subsystem_ids": [
|
||||
"cloud-paid"
|
||||
],
|
||||
"lane_ids": [
|
||||
"L2",
|
||||
"L3",
|
||||
"L12",
|
||||
"L17"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "unified-commercial-offer-projection-contract",
|
||||
"summary": "Community, Relay, and Pro remain distinct customer jobs with Pro explicitly bundling Relay; one versioned commercial offer contract must project into public pricing, Pulse Account, in-product plans, checkout, read-only Stripe catalog audit, support policy, billing persistence, and runtime entitlements. Stripe stays billing truth, while one Pulse-owned idempotent transition authority atomically owns the local commercial projection and every material entitlement change increments license_version.",
|
||||
"kind": "architecture",
|
||||
"decided_at": "2026-07-14",
|
||||
"subsystem_ids": [
|
||||
"cloud-paid"
|
||||
],
|
||||
"lane_ids": [
|
||||
"L2",
|
||||
"L3",
|
||||
"L12",
|
||||
"L17"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user