Govern commercial offer and lifecycle

This commit is contained in:
rcourtman
2026-07-14 11:54:22 +01:00
parent 5d4f51c027
commit 99c2ef22a6
6 changed files with 520 additions and 50 deletions
+47 -9
View File
@@ -4,8 +4,8 @@
> Primary v6 execution authority is `docs/release-control/v6/internal/SOURCE_OF_TRUTH.md` (+ `docs/release-control/v6/internal/status.json`).
> This file remains the detailed pricing evidence/spec and must stay aligned with the release-control source.
> **Status:** APPROVED — Final structure for v6 launch.
> **Date:** 2026-02-25
> **Status:** APPROVED — Current commercial contract.
> **Date:** 2026-07-14
> **Replaces:** All previous pricing documents and v5 pricing structure.
This document is the single source of truth for Pulse v6 pricing, tiering, feature
@@ -186,6 +186,19 @@ marketing pitch focuses on three things:
Relay connectivity and the team extras (RBAC, audit logging, reporting, and agent profiles)
are bundled, but they are supporting entitlements rather than evidence of a product ladder.
### Self-hosted license and support scope
- One Relay or Pro subscription covers one owner-operated Pulse environment.
- Monitored systems and child resources are not metered.
- The subscription permits three concurrent activations inside that environment
for primary, migration, and recovery use. Independently operated client
environments require MSP.
- Verified administrative ownership transfer is supported; resale, sharing,
and unverified third-party assignment are prohibited.
- Relay and Pro include verified commercial support for billing, activation,
transfer, configuration, and diagnostics, typically within two business
days. This is not a contractual SLA or priority-support commitment.
### Pro+ — Legacy continuity tier only
Existing Pro+ entitlements remain supported for continuity, but Pro+ is no longer part of
@@ -195,10 +208,14 @@ still preserve self-hosted monitoring and child-resource volume as not metered w
---
## Cloud Tiers (Hosted — separate page)
## Cloud Tiers (Hosted — unavailable)
All Cloud tiers include everything in Pro + managed hosting + daily automated backups.
Cloud launches alongside v6 (not behind a waitlist).
Cloud is not currently offered. The prices and tier shapes below are dormant
commercial proposals retained for implementation planning; they are not a
signup promise, supported capacity contract, trial promise, or current support
commitment. Cloud must not reopen until its economic unit/caps, card policy,
support, retention, export, cancellation, reactivation, and runtime enforcement
pass the governed Cloud reopening gate.
### Cloud Starter — $29/month or $249/year
@@ -242,7 +259,9 @@ Cloud launches alongside v6 (not behind a waitlist).
Pulse MSP is not the shared-process organization model. The default MSP route is provider-hosted: the MSP runs a Stripe-free control plane that creates one isolated Pulse runtime/container per client workspace. A signed MSP license sets the plan version and client workspace cap. Pulse-hosted MSP is an optional request-assisted path where Pulse operates that provider stack.
MSP is built and staged for assisted rollout, but it is not a public self-serve checkout path yet. Pricing, availability, and launch wording need owner review before publication.
MSP is an assisted preview, not a public self-serve checkout path. Public copy
may show the recorded monthly and annual prices, but fulfillment remains
request-assisted and must not imply immediate Pulse-hosted provisioning.
### MSP Starter — $149/month or $1,490/year
@@ -349,9 +368,28 @@ There is no proactive self-hosted upsell cadence in v6 GA. If older compatibilit
mention prompt reduction, treat them as legacy controls; the v6 default is already quiet unless
the user enters an explicit commercial path or has an entitlement state that needs attention.
### 9. Cloud launches with v6
Not behind a waitlist. Real pricing, real signup. Captures convenience buyers who don't
want to self-host.
### 9. Cloud remains unavailable until reopening proof
The public Cloud surface must state that signup is closed. Dormant Cloud prices,
caps, trial language, and implementation paths remain non-public planning
inputs until the governed reopening gate passes.
### 10. Self-service lifecycle contract
| Change | Effective time | Billing treatment |
|---|---|---|
| Community to Relay or Pro | After successful checkout | New subscription |
| Relay to Pro | Immediate after explicit quote and successful payment | Prorated |
| Monthly to annual, same tier | Immediate after explicit quote and successful payment | Prorated |
| Pro to Relay | Current paid period end | No proration |
| Annual to monthly, same tier | Current paid period end | No proration |
| Voluntary cancellation | Current paid period end | No proration |
Combined transitions use the most restrictive timing rule. Voluntary
cancellation has a seven-day recovery-only window after paid entitlement ends;
payment failure has a separate seven-day functional grace period. Downgrades
preserve configuration, report definitions, and audit records. Out-of-tier
history and generated artifacts soft-hide for 30 days and become
purge-eligible after 60 days.
---
+12 -15
View File
@@ -236,19 +236,16 @@ user language should update the control plane.
## Current State
1. v6 is the current active release profile.
2. `v6-ga-promotion` is the current active engineering target.
The next public v6 release target is GA from the current
`pulse/v6-release` branch after accumulated post-RC7 fixes and final
current-branch validation. The published RC7 candidate must not be promoted
unchanged, and another RC is not planned by default unless a release-owner
decision changes that.
3. `v6-product-lane-expansion` remains planned behind the GA launch target.
Its candidate-lane surface remains available in the linked
`candidate_lanes` and `coverage_gaps`, but it should not displace release
execution while GA is the current objective.
4. The older RC line reached the historical `release_ready` floor, but the
current GA target now requires fresh current-branch validation because the
release will include accumulated fixes and changes after RC7.
2. `v6-product-lane-expansion` is the current active engineering target.
Pulse v6 GA and the initial 6.0.x patch line have shipped; active
development and stable release preparation now run on `main`.
3. `v6-ga-promotion` is complete. Its release records remain historical
evidence and must not keep pre-GA branch, checkout, or readiness posture
active in current lane state.
4. Candidate lanes and coverage gaps now route post-GA product expansion.
Release-blocking correctness work may still override that default queue
when a shipped customer contract can drift across billing, entitlements,
runtime behavior, or public copy.
5. `v6-rc-stabilization` is completed after the shipped RCs established the
current monitored-first floor and the active objective moved to stable
promotion.
@@ -256,8 +253,8 @@ user language should update the control plane.
7. The existing v6 control surfaces are still live, but they now sit underneath
an evergreen Pulse control plane rather than pretending to be the whole
long-term system.
8. Until the explicit post-GA branch cutover happens, both prerelease and
stable v6 promotions resolve to `pulse/v6-release` via `control_plane.json`.
8. Both prerelease and stable v6 promotions resolve to `main` via
`control_plane.json`.
9. Legacy maintenance releases that still feed governed automation outside the
active v6 line must also resolve through `control_plane.json`.
Right now the remaining `5.1.x` stable maintenance line resolves to `main`
@@ -157,6 +157,70 @@ Companion drill:
legacy recurring price, or cancellation/reactivation leaves pricing and
entitlement state inconsistent across Stripe, Pulse runtime, and customer UI.
## Gate: `self-hosted-commercial-transition-coherence`
- Why this is risky:
Relay/Pro and cadence changes cross Stripe proration and schedules, durable
webhook processing, grandfathering, local entitlement projection, license
versioning, Relay grant enforcement, downgrade preservation, and customer-
visible account state. The current implementation can update Stripe price
identifiers without atomically changing tier or features, which can charge
for one plan while granting another.
- Primary runtime surfaces:
`pulse-pro/license-server/v6_checkout.go`
`pulse-pro/license-server/v6_stripe.go`
`pulse-pro/license-server/v6_reconcile.go`
`pulse-pro/license-server/v6_state.go`
`pulse-pro/license-server/v6_store.go`
`pulse-pro/license-server/v6_grants.go`
`pkg/licensing/...`
Pulse Account Billing and Stripe customer/subscription state
- Automated proof:
Local unit and integration proof now covers the Community/Relay/Pro and
monthly/annual timing matrix, quote/apply parameter binding, idempotent
immediate retry convergence, schedule creation/reuse/cancellation ownership,
atomic commercial snapshot projection, payment-failure versus cancellation
grace, downgrade history timing, report entitlement denial, and safe artifact
purge. The remaining duplicate/reversed/missing external-event matrix and
restrictive Relay grant version-floor scenario require the governed Stripe
test-mode rehearsal; until that evidence is registered, the gate remains
blocked.
- Manual scenario:
1. In Stripe test mode, create fresh Community-to-Relay and Community-to-Pro
acquisitions for monthly and annual plans.
2. Exercise immediate quoted/prorated Relay-to-Pro and monthly-to-annual
changes, including success, decline, timeout-after-success, duplicate
request, and replay.
3. Exercise renewal-bound Pro-to-Relay and annual-to-monthly changes,
including cancellation/resume before the effective timestamp.
4. Exercise voluntary paid-through expiry, recovery-only access, involuntary
payment-failure grace and recovery, grace expiry, refund/dispute, and
current-price re-entry after continuity ends.
5. Reverse, duplicate, suppress, and later replay Stripe events; reconcile
from the current Stripe snapshot and confirm the same final state.
6. Confirm every material entitlement reduction increments
`license_version`, rejects the old grant in Relay/runtime, and preserves
configuration, report definitions, audit records, and the governed
downgrade history window.
7. Exercise the buyer/account journey at desktop and phone width and confirm
the quoted amount, effective date, plan, cadence, cancellation state, and
recovery behavior match runtime truth.
- Pass when:
Each scenario leaves exactly one billing contract and one entitlement
projection for the commercial subject; Stripe price, local plan, cadence,
runtime capabilities, license version, and customer-visible state agree;
replay/order variation does not change the result; and no downgrade or
cancellation deletes protected customer configuration or records.
- Latest exercised record:
Local implementation and browser evidence is recorded in
`docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md`.
No qualifying real-external-e2e record exists yet.
- Block release if:
Any supported transition can charge and grant different plans, mutate
entitlement without a version bump, restore ended grandfathering, rely on
mutable Customer Portal plan-switch configuration, or produce different
state under duplicate, missing, or reordered Stripe delivery.
## Gate: `known-rc-issue-closure-for-ga`
- Why this is risky:
@@ -1,6 +1,6 @@
# Pulse v6 Source Of Truth
Last updated: 2026-07-02
Last updated: 2026-07-14
Status: ACTIVE
This file is the stable human governance layer for the active v6 release
@@ -471,6 +471,13 @@ Assertion design rules:
document bound to the audited SHA selected at runtime. The checker must
never execute real-lab, device, relay, or other mutation-gated commands
itself.
24. Do not ship or expose self-service plan or cadence transitions unless the
authoritative Stripe subscription snapshot, local billing contract,
entitlement projection, continuity epoch, license version, and grant
revocation/outbox state converge through one idempotent transition
authority. A customer must never pay for one plan while Pulse grants
another, and duplicate, missing, or reordered webhook delivery must not
change the final commercial state.
## Locked Decisions
@@ -545,6 +552,40 @@ Assertion design rules:
trust, or installer/update/rollback path changed, and the exact-SHA release
dry run passed. Those risk conditions require RC lineage unless an active
customer-harm emergency is recorded through the hotfix exception.
16. The canonical self-hosted offer is job-based rather than a
good/better/best ladder: Community is the free local monitoring foundation,
Relay is remote access plus Pulse Mobile pairing, push, and 14-day history,
and Pro is Patrol-powered investigation and governed operations with
90-day history and Relay bundled. One Relay or Pro subscription covers one
owner-operated environment with unmetered monitored-system and child-
resource volume plus three concurrent primary/migration/recovery
activations. It does not cover independently operated client environments.
17. Verified administrative ownership transfers are permitted, while resale,
sharing, and unverified third-party assignment are prohibited. Relay and
Pro include standard verified commercial support for billing, activation,
transfer, configuration, and diagnostics, normally targeted within two
business days without a contractual SLA or priority-support promise.
18. Self-hosted subscription transitions follow the approved lifecycle matrix
in
`docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md`:
Relay-to-Pro and monthly-to-annual changes are immediate only after an
explicit prorated quote and successful payment; capability downgrades and
annual-to-monthly changes occur at renewal without proration; voluntary
cancellation ends paid capability at the paid-through timestamp; a
separate seven-day recovery-only window grants no paid capability; and
involuntary payment failure receives seven days of functional grace.
Configuration, report definitions, and audit records survive downgrade;
out-of-tier history and generated artifacts soft-hide for 30 days and
become purge-eligible after 60 days. Completed cancellation or a completed
tier/cadence change ends grandfathered recurring-price continuity.
19. Cloud is unavailable until a governed reopening gate proves its economic
unit/caps, card policy, support, retention, export, cancellation,
reactivation, and runtime enforcement. Historical Cloud prices and caps
are dormant proposals, not a current offer. MSP remains an assisted
preview, provider-hosted by default, with 5/15/40 isolated client-
workspace limits; public copy may state the recorded monthly and annual
prices but must not promise immediate self-service checkout or Pulse-hosted
fulfillment.
## TrueNAS Support Floor
@@ -0,0 +1,169 @@
# Commercial Offer And Lifecycle Contract
Date: 2026-07-14
Owner: project owner
Status: approved for implementation
## Decision
Pulse commercial packaging and lifecycle behavior must converge on one
versioned offer contract. The public site, Pulse Account, in-product plan
surfaces, checkout projection, Stripe catalog audit, license-server billing
state, runtime entitlements, and support policy must not maintain independent
commercial definitions.
## Self-Hosted Offer
1. Community is the free local monitoring foundation with 7-day history.
2. Relay is the secure remote-access, Pulse Mobile pairing, push-delivery, and
14-day-history service.
3. Pro is the Patrol-powered investigation and governed-operations product
with 90-day history and team/admin controls. Pro includes Relay; a buyer
never needs simultaneous Relay and Pro subscriptions for one environment.
4. Community, Relay, and Pro solve distinct jobs. They must not be presented
as a recommended good/better/best ladder.
5. Ordinary self-hosted trial acquisition remains retired.
## License Scope And Support
1. One Relay or Pro subscription covers one owner-operated Pulse environment.
2. Monitored-system and child-resource volume is not metered for self-hosted
Community, Relay, or Pro.
3. A paid subscription permits three concurrent activations inside that one
environment for primary, migration, and recovery use. It does not license
independently operated client environments; that is the MSP product job.
4. Verified administrative ownership transfer is permitted. Resale, sharing,
and unverified third-party assignment are prohibited.
5. Relay and Pro include standard verified commercial support for billing,
activation, transfer, configuration, and diagnostics. The public target is
typically within two business days, without a contractual SLA or a
priority-support promise.
## Subscription Transition Matrix
| From | To | Effective time | Billing treatment | Entitlement treatment |
|---|---|---|---|---|
| Community | Relay or Pro | After successful checkout | New subscription | Grant the purchased plan atomically |
| Relay | Pro, same cadence | Immediate after explicit quote and successful prorated payment | Prorated upgrade | Pro plus bundled Relay |
| Monthly | Annual, same tier | Immediate after explicit quote and successful prorated payment | Prorated cadence change | Tier unchanged |
| Pro | Relay | Current paid period end | No proration | Remove Pro-only capabilities; retain Relay |
| Annual | Monthly, same tier | Current paid period end | No proration | Tier unchanged |
| Any paid plan | Community by cancellation | Current paid period end | No proration | Paid capabilities end at the paid-through timestamp |
Combined transitions follow the most restrictive rule. Any transition that
reduces capabilities or moves annual to monthly takes effect at renewal.
Customer-visible confirmation must state the effective date and quoted charge
or credit before mutation.
## Cancellation, Grace, And Continuity
1. Voluntary cancellation is scheduled for period end. Paid capabilities end
at the paid-through timestamp.
2. A seven-day post-term recovery window may support subscription reactivation,
license retrieval, and account recovery, but it is not a paid-entitlement
extension and must not grant Relay or Pro capabilities.
3. Involuntary payment failure receives a separate seven-day functional grace
period. Existing paid capabilities remain available during that grace, then
fail closed if payment has not recovered.
4. Reversing scheduled cancellation before the paid-through timestamp
preserves subscription continuity.
5. Grandfathered recurring price continuity survives only while the original
recurring subscription remains continuous. Completed cancellation or a
completed tier/cadence change exits the grandfathered contract; later
re-entry uses current pricing.
6. A full refund or dispute revokes the affected paid entitlement and requires
explicit reactivation or repurchase.
## Downgrade Preservation
1. Configuration, report definitions, and audit records are not deleted solely
because a customer downgrades.
2. Pro-only configuration remains stored but inert while the entitlement is
absent.
3. History and generated artifacts outside the lower tier's active window are
soft-hidden for 30 days and become purge-eligible after 60 days.
4. Re-upgrade during the soft-hide window restores access without
reconfiguration.
5. Every capability, tier, cadence, restrictive state, or entitlement change
increments `license_version` and invalidates obsolete grants atomically.
## Cloud And MSP Availability
1. Cloud is unavailable. Its historical prices, caps, trial, and support labels
are dormant proposals, not a current customer offer. Cloud cannot reopen
until card policy, economic unit/caps, support, retention, export,
cancellation, reactivation, and runtime enforcement pass a governed
readiness gate.
2. MSP is an assisted preview and provider-hosted by default. Starter, Growth,
and Scale retain 5, 15, and 40 isolated client-workspace limits at the
recorded monthly and annual prices. Enterprise remains custom.
3. Public MSP copy may publish the recorded monthly and annual prices, but it
must not promise immediate self-service checkout or Pulse-hosted fulfillment.
4. Pulse-hosted MSP remains an optional assisted arrangement, not the default
public delivery model.
## Implementation Boundary
Stripe remains billing truth, but one Pulse-owned transition authority must
apply the authoritative Stripe snapshot atomically to billing contract,
entitlement projection, continuity epoch, transition history, license version,
and grant-revocation outbox state. Checkout, webhook, reconciliation, refunds,
support/admin actions, and future Pulse Account transitions must converge on
that authority. Stripe Customer Portal subscription updates remain disabled;
Pulse-owned plan transitions must not depend on mutable portal configuration.
## Proof Required Before Closure
1. Contract drift proof across public pricing, Pulse Account, in-product plan
presentation, Stripe product/price descriptions, support policy, and runtime
entitlements.
2. Complete Community/Relay/Pro and monthly/annual transition matrix proof.
3. Stripe test-mode payment, proration, schedule, cancellation, payment-failure,
refund, and re-entry proof.
4. Duplicate, reversed, missing, and replayed webhook convergence proof.
5. Restrictive-transition grant version-floor proof in Pulse and Relay.
6. Downgrade soft-hide, restoration, purge-eligibility, and configuration
preservation proof.
7. Desktop and phone-width buyer/account browser proof.
8. A read-only production Stripe catalog and portal expected-state audit before
any separately approved external configuration change.
## Implemented Local Evidence
The 2026-07-14 implementation slice now provides the local, non-transactional
foundation required by this contract:
1. `pulse-pro/license-server/v6_commercial_projection.go` owns atomic catalog,
billing-contract, entitlement, continuity-epoch, license-version, transition
history, and revocation-outbox projection. Unknown or multi-price snapshots
fail closed, and checkout, subscription, invoice, cancellation, payment-
failure, and refund paths converge on that projection.
2. `pulse-pro/license-server/v6_commercial_transitions.go` owns authenticated,
durable transition quotes. Immediate expansion uses the exact quoted Stripe
proration timestamp with `pending_if_incomplete`; restrictive changes use a
renewal-bound subscription schedule without proration. Retry paths reuse
Stripe idempotency keys and already-created schedules.
3. `pulse-pro/landing-page/manage.html` exposes invoices/payment methods,
quoted Relay/Pro and cadence changes, period-end cancellation, reactivation,
and scheduled-change cancellation behind an emailed verification code.
4. `pkg/licensing/subscription_transitions.go`, `pkg/metrics/store.go`, and
`internal/api/report_schedules.go` persist downgrade timing, keep protected
configuration and report definitions, restrict out-of-tier access
immediately, delay physical history cleanup until day 60, block background
report execution without the current entitlement, and purge generated
report artifacts without following symlinks after eligibility.
5. Local proof is green for the complete license-server Go suite, 359 Python
pricing/copy tests, the Pulse licensing/metrics/API suites, and desktop plus
390-pixel buyer/account browser exercise. These are local implementation and
rehearsal facts, not a substitute for the required Stripe test-mode and
production read-only evidence.
## Remaining Readiness Boundary
The `self-hosted-commercial-transition-coherence` gate remains blocked. No
Stripe test-mode mutation, live catalog/configuration change, purchase,
deployment, or production customer-data access was authorized or performed in
this slice. Before self-service is released, the project still needs the
governed external transition matrix, event-order/reconciliation exercise,
Relay version-floor proof, and read-only production catalog/portal audit named
above.
+186 -25
View File
@@ -1,6 +1,6 @@
{
"version": "6.0",
"updated_at": "2026-07-02",
"updated_at": "2026-07-14",
"scope": {
"active_repos": [
"pulse",
@@ -4676,6 +4676,55 @@
"evidence_tier": "test-proof"
}
]
},
{
"id": "RA41",
"summary": "Self-hosted commercial state remains coherent across the canonical offer, Stripe billing, Pulse Account, license-server persistence, runtime and Relay entitlements, support policy, and customer-visible lifecycle: Community, Relay, and Pro keep distinct jobs with Pro bundling Relay; every tier or cadence transition applies the approved timing and proration matrix through one idempotent transition authority; restrictive changes invalidate old grants; downgrade preserves governed customer data; and replay, cancellation, refund, grace, or re-entry cannot make billing and entitlement drift.",
"kind": "trust-gate",
"blocking_level": "release-ready",
"proof_type": "manual",
"lane_ids": [
"L2",
"L3",
"L12",
"L17"
],
"subsystem_ids": [
"cloud-paid"
],
"release_gate_ids": [
"self-hosted-commercial-transition-coherence"
],
"evidence": [
{
"repo": "pulse",
"path": "docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md",
"kind": "file"
},
{
"repo": "pulse",
"path": "docs/release-control/v6/internal/subsystems/cloud-paid.md",
"kind": "file"
},
{
"repo": "pulse",
"path": "internal/api/report_schedules_test.go",
"kind": "file",
"evidence_tier": "test-proof"
},
{
"repo": "pulse",
"path": "pkg/licensing/subscription_test.go",
"kind": "file",
"evidence_tier": "test-proof"
},
{
"repo": "pulse-pro",
"path": "license-server/v6_commercial_transitions_test.go",
"kind": "file",
"evidence_tier": "test-proof"
}
]
}
],
"evidence_reference_policy": {
@@ -4778,15 +4827,15 @@
"status": "partial",
"completion": {
"state": "bounded-residual",
"summary": "Commercial readiness is coherent for explicit preview, checkout handoff, paid-user activation/recovery, hosted-mode paths, and the first Pulse Intelligence value-evidence reporting surface, while default self-hosted app surfaces stay free-first and non-promotional; because v6 is not publicly GA, production public checkout stays on v5 until explicit GA cutover approval, and the production public flip plus release-day rollout execution plus the broader governed Patrol control experience remain separate follow-ups.",
"summary": "The approved Community / Relay / Pro contract is now projected into local public/account copy, support and legal policy, atomic license-server entitlement state, quoted Relay/Pro and cadence transition sagas, and runtime downgrade preservation. Local Go, copy-model, and desktop/phone browser proof is green. Self-service remains unreleased until the governed Stripe test-mode event/reconciliation matrix, Relay version-floor proof, and production read-only catalog/portal audit satisfy the commercial transition gate.",
"tracking": [
{
"kind": "lane-followup",
"id": "commercial-ga-promotion-package"
"id": "pulse-intelligence-pro-activation-loop"
},
{
"kind": "lane-followup",
"id": "pulse-intelligence-pro-activation-loop"
"kind": "release-gate",
"id": "self-hosted-commercial-transition-coherence"
}
]
},
@@ -4847,11 +4896,16 @@
"name": "Cloud paid readiness",
"target_score": 8,
"current_score": 8,
"status": "target-met",
"status": "partial",
"completion": {
"state": "complete",
"summary": "Cloud-paid runtime and billing surfaces are at the current tracked RC floor, including real cancellation/reactivation continuity across checkout, entitlement boundaries, and the shared commercial billing shell/model now used by both self-hosted Pulse Pro and hosted organization billing.",
"tracking": []
"state": "bounded-residual",
"summary": "The local commercial projection now changes Stripe catalog identity, tier, cadence, features, continuity epoch, license version, transition history, and revocation outbox atomically, with a quote-bound transition authority for self-hosted plan and cadence changes. Cloud remains unavailable and MSP remains an assisted preview. External Stripe event/reconciliation and Relay version-floor proof remain governed release residuals.",
"tracking": [
{
"kind": "release-gate",
"id": "self-hosted-commercial-transition-coherence"
}
]
},
"blockers": [],
"subsystems": [
@@ -5907,11 +5961,16 @@
"name": "Customer account portal",
"target_score": 6,
"current_score": 6,
"status": "target-met",
"status": "partial",
"completion": {
"state": "complete",
"summary": "Pulse Account is now a first-class governed customer-account surface at the current RC floor: hosted accounts land directly in Workspaces, the signed-in shell stays task-first across Workspaces, Access, Billing, and Support, and MSP plus self-serve commercial actions converge on one coherent authenticated account boundary.",
"tracking": []
"state": "bounded-residual",
"summary": "The self-hosted manage entry point is now Pulse-named and job-first, with verified invoice/payment access, quoted Relay/Pro and cadence changes, cancellation, reactivation, and scheduled-change cancellation. Retrieve, refund, and data-request utilities remain separate specialist jobs. The lane stays residual until real Stripe transition/reconciliation and Relay entitlement proofs satisfy the governed transition gate.",
"tracking": [
{
"kind": "release-gate",
"id": "self-hosted-commercial-transition-coherence"
}
]
},
"blockers": [],
"subsystems": [],
@@ -7874,6 +7933,46 @@
}
]
},
{
"id": "self-hosted-commercial-transition-coherence",
"summary": "Confirm the approved self-hosted offer and lifecycle remain coherent across public pricing, Stripe billing, Pulse Account, license-server state, runtime and Relay entitlements, support policy, and customer-visible transitions: quoted/prorated immediate upgrades, renewal-bound reductions, paid-through cancellation, distinct recovery and payment-failure grace, downgrade preservation, grant version invalidation, and current-price re-entry all converge under replay and reconciliation.",
"owner": "project-owner",
"blocking_level": "release-ready",
"minimum_evidence_tier": "real-external-e2e",
"status": "blocked",
"verification_doc": "docs/release-control/v6/internal/HIGH_RISK_RELEASE_VERIFICATION_MATRIX.md",
"lane_ids": [
"L2",
"L3",
"L12",
"L17"
],
"evidence": [
{
"repo": "pulse",
"path": "docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md",
"kind": "file"
},
{
"repo": "pulse",
"path": "internal/api/report_schedules_test.go",
"kind": "file",
"evidence_tier": "test-proof"
},
{
"repo": "pulse",
"path": "pkg/licensing/subscription_test.go",
"kind": "file",
"evidence_tier": "test-proof"
},
{
"repo": "pulse-pro",
"path": "license-server/v6_commercial_transitions_test.go",
"kind": "file",
"evidence_tier": "test-proof"
}
]
},
{
"id": "settings-surface-layout-consistency",
"summary": "Confirm comparable settings surfaces present the canonical page shell, with consistent header framing and no ad hoc top-level layout chrome.",
@@ -8078,17 +8177,6 @@
],
"cross_repo": false
},
{
"id": "commercial-ga-promotion-package",
"summary": "Track the explicitly approved GA production public flip and release-day execution work for the self-hosted commercial package; until that work is active, production public checkout must remain on v5 with v6 approval disabled, and default self-hosted app surfaces must stay free-first and non-promotional.",
"owner": "project-owner",
"status": "planned",
"recorded_at": "2026-04-20",
"lane_ids": [
"L2"
],
"subsystem_ids": []
},
{
"id": "journey-post-ga-expansion",
"summary": "Track broader same-lane end-to-end journey expansion beyond the current GA floor now that prerelease-to-GA promotion proof is recorded.",
@@ -8631,7 +8719,21 @@
]
}
],
"work_claims": [],
"work_claims": [
{
"id": "codex-lane-l23",
"agent_id": "codex",
"summary": "Implement an independent-ground-truth Pulse Patrol qualification benchmark with disposable live-lab, replay, Watch, investigation, remediation, safety, statistical gates, and reporting support.",
"target_id": "v6-product-lane-expansion",
"claimed_at": "2026-07-14T09:15:01Z",
"heartbeat_at": "2026-07-14T09:15:01Z",
"expires_at": "2026-07-14T11:15:01Z",
"work_item": {
"kind": "lane",
"id": "L23"
}
}
],
"open_decisions": [],
"source_of_truth_file": "docs/release-control/v6/internal/SOURCE_OF_TRUTH.md",
"resolved_decisions": [
@@ -9442,6 +9544,65 @@
"lane_ids": [
"L5"
]
},
{
"id": "cloud-msp-availability-contract",
"summary": "Cloud is unavailable; historical Cloud prices, caps, trial, and support labels are dormant proposals rather than a current offer, and reopening requires governed proof of card policy, economic unit/caps, support, retention, export, cancellation, reactivation, and runtime enforcement. MSP remains an assisted preview, provider-hosted by default, with 5/15/40 isolated client-workspace limits and recorded monthly/annual prices; this supersedes the earlier Starter self-serve buying motion until a later explicit decision reopens it.",
"kind": "pricing",
"decided_at": "2026-07-14",
"subsystem_ids": [
"cloud-paid"
],
"lane_ids": [
"L2",
"L3",
"L4",
"L17"
]
},
{
"id": "self-hosted-commercial-scope-support-contract",
"summary": "One Relay or Pro subscription covers one owner-operated Pulse environment with unmetered monitored systems and child resources plus three concurrent primary/migration/recovery activations. Verified administrative transfer is permitted, resale/sharing/unverified assignment is prohibited, and Relay/Pro include standard verified commercial support typically within two business days without an SLA or priority-support promise.",
"kind": "contract",
"decided_at": "2026-07-14",
"subsystem_ids": [
"cloud-paid"
],
"lane_ids": [
"L2",
"L3",
"L17"
]
},
{
"id": "self-hosted-commercial-transition-contract",
"summary": "Relay-to-Pro and monthly-to-annual changes are immediate only after an explicit prorated quote and successful payment; capability downgrades and annual-to-monthly changes occur at renewal without proration; voluntary cancellation ends paid capability at the paid-through timestamp with a seven-day recovery-only window, while payment failure receives seven days of functional grace. Downgrade preserves configuration, report definitions, and audit records; out-of-tier history/artifacts soft-hide for 30 days and become purge-eligible after 60 days; completed cancellation or tier/cadence change ends grandfathered recurring-price continuity.",
"kind": "contract",
"decided_at": "2026-07-14",
"subsystem_ids": [
"cloud-paid"
],
"lane_ids": [
"L2",
"L3",
"L12",
"L17"
]
},
{
"id": "unified-commercial-offer-projection-contract",
"summary": "Community, Relay, and Pro remain distinct customer jobs with Pro explicitly bundling Relay; one versioned commercial offer contract must project into public pricing, Pulse Account, in-product plans, checkout, read-only Stripe catalog audit, support policy, billing persistence, and runtime entitlements. Stripe stays billing truth, while one Pulse-owned idempotent transition authority atomically owns the local commercial projection and every material entitlement change increments license_version.",
"kind": "architecture",
"decided_at": "2026-07-14",
"subsystem_ids": [
"cloud-paid"
],
"lane_ids": [
"L2",
"L3",
"L12",
"L17"
]
}
]
}