From 99c2ef22a67c1bf1e033cc0af1714783b67f84c7 Mon Sep 17 00:00:00 2001 From: rcourtman Date: Tue, 14 Jul 2026 11:54:22 +0100 Subject: [PATCH] Govern commercial offer and lifecycle --- docs/architecture/v6-pricing-and-tiering.md | 56 ++++- .../release-control/internal/CONTROL_PLANE.md | 27 +-- .../HIGH_RISK_RELEASE_VERIFICATION_MATRIX.md | 64 ++++++ .../v6/internal/SOURCE_OF_TRUTH.md | 43 +++- ...ial-offer-lifecycle-contract-2026-07-14.md | 169 ++++++++++++++ docs/release-control/v6/internal/status.json | 211 +++++++++++++++--- 6 files changed, 520 insertions(+), 50 deletions(-) create mode 100644 docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md diff --git a/docs/architecture/v6-pricing-and-tiering.md b/docs/architecture/v6-pricing-and-tiering.md index d9e421b42..7f016c93e 100644 --- a/docs/architecture/v6-pricing-and-tiering.md +++ b/docs/architecture/v6-pricing-and-tiering.md @@ -4,8 +4,8 @@ > Primary v6 execution authority is `docs/release-control/v6/internal/SOURCE_OF_TRUTH.md` (+ `docs/release-control/v6/internal/status.json`). > This file remains the detailed pricing evidence/spec and must stay aligned with the release-control source. -> **Status:** APPROVED — Final structure for v6 launch. -> **Date:** 2026-02-25 +> **Status:** APPROVED — Current commercial contract. +> **Date:** 2026-07-14 > **Replaces:** All previous pricing documents and v5 pricing structure. This document is the single source of truth for Pulse v6 pricing, tiering, feature @@ -186,6 +186,19 @@ marketing pitch focuses on three things: Relay connectivity and the team extras (RBAC, audit logging, reporting, and agent profiles) are bundled, but they are supporting entitlements rather than evidence of a product ladder. +### Self-hosted license and support scope + +- One Relay or Pro subscription covers one owner-operated Pulse environment. +- Monitored systems and child resources are not metered. +- The subscription permits three concurrent activations inside that environment + for primary, migration, and recovery use. Independently operated client + environments require MSP. +- Verified administrative ownership transfer is supported; resale, sharing, + and unverified third-party assignment are prohibited. +- Relay and Pro include verified commercial support for billing, activation, + transfer, configuration, and diagnostics, typically within two business + days. This is not a contractual SLA or priority-support commitment. + ### Pro+ — Legacy continuity tier only Existing Pro+ entitlements remain supported for continuity, but Pro+ is no longer part of @@ -195,10 +208,14 @@ still preserve self-hosted monitoring and child-resource volume as not metered w --- -## Cloud Tiers (Hosted — separate page) +## Cloud Tiers (Hosted — unavailable) -All Cloud tiers include everything in Pro + managed hosting + daily automated backups. -Cloud launches alongside v6 (not behind a waitlist). +Cloud is not currently offered. The prices and tier shapes below are dormant +commercial proposals retained for implementation planning; they are not a +signup promise, supported capacity contract, trial promise, or current support +commitment. Cloud must not reopen until its economic unit/caps, card policy, +support, retention, export, cancellation, reactivation, and runtime enforcement +pass the governed Cloud reopening gate. ### Cloud Starter — $29/month or $249/year @@ -242,7 +259,9 @@ Cloud launches alongside v6 (not behind a waitlist). Pulse MSP is not the shared-process organization model. The default MSP route is provider-hosted: the MSP runs a Stripe-free control plane that creates one isolated Pulse runtime/container per client workspace. A signed MSP license sets the plan version and client workspace cap. Pulse-hosted MSP is an optional request-assisted path where Pulse operates that provider stack. -MSP is built and staged for assisted rollout, but it is not a public self-serve checkout path yet. Pricing, availability, and launch wording need owner review before publication. +MSP is an assisted preview, not a public self-serve checkout path. Public copy +may show the recorded monthly and annual prices, but fulfillment remains +request-assisted and must not imply immediate Pulse-hosted provisioning. ### MSP Starter — $149/month or $1,490/year @@ -349,9 +368,28 @@ There is no proactive self-hosted upsell cadence in v6 GA. If older compatibilit mention prompt reduction, treat them as legacy controls; the v6 default is already quiet unless the user enters an explicit commercial path or has an entitlement state that needs attention. -### 9. Cloud launches with v6 -Not behind a waitlist. Real pricing, real signup. Captures convenience buyers who don't -want to self-host. +### 9. Cloud remains unavailable until reopening proof +The public Cloud surface must state that signup is closed. Dormant Cloud prices, +caps, trial language, and implementation paths remain non-public planning +inputs until the governed reopening gate passes. + +### 10. Self-service lifecycle contract + +| Change | Effective time | Billing treatment | +|---|---|---| +| Community to Relay or Pro | After successful checkout | New subscription | +| Relay to Pro | Immediate after explicit quote and successful payment | Prorated | +| Monthly to annual, same tier | Immediate after explicit quote and successful payment | Prorated | +| Pro to Relay | Current paid period end | No proration | +| Annual to monthly, same tier | Current paid period end | No proration | +| Voluntary cancellation | Current paid period end | No proration | + +Combined transitions use the most restrictive timing rule. Voluntary +cancellation has a seven-day recovery-only window after paid entitlement ends; +payment failure has a separate seven-day functional grace period. Downgrades +preserve configuration, report definitions, and audit records. Out-of-tier +history and generated artifacts soft-hide for 30 days and become +purge-eligible after 60 days. --- diff --git a/docs/release-control/internal/CONTROL_PLANE.md b/docs/release-control/internal/CONTROL_PLANE.md index d9c90623c..ef66f8b6d 100644 --- a/docs/release-control/internal/CONTROL_PLANE.md +++ b/docs/release-control/internal/CONTROL_PLANE.md @@ -236,19 +236,16 @@ user language should update the control plane. ## Current State 1. v6 is the current active release profile. -2. `v6-ga-promotion` is the current active engineering target. - The next public v6 release target is GA from the current - `pulse/v6-release` branch after accumulated post-RC7 fixes and final - current-branch validation. The published RC7 candidate must not be promoted - unchanged, and another RC is not planned by default unless a release-owner - decision changes that. -3. `v6-product-lane-expansion` remains planned behind the GA launch target. - Its candidate-lane surface remains available in the linked - `candidate_lanes` and `coverage_gaps`, but it should not displace release - execution while GA is the current objective. -4. The older RC line reached the historical `release_ready` floor, but the - current GA target now requires fresh current-branch validation because the - release will include accumulated fixes and changes after RC7. +2. `v6-product-lane-expansion` is the current active engineering target. + Pulse v6 GA and the initial 6.0.x patch line have shipped; active + development and stable release preparation now run on `main`. +3. `v6-ga-promotion` is complete. Its release records remain historical + evidence and must not keep pre-GA branch, checkout, or readiness posture + active in current lane state. +4. Candidate lanes and coverage gaps now route post-GA product expansion. + Release-blocking correctness work may still override that default queue + when a shipped customer contract can drift across billing, entitlements, + runtime behavior, or public copy. 5. `v6-rc-stabilization` is completed after the shipped RCs established the current monitored-first floor and the active objective moved to stable promotion. @@ -256,8 +253,8 @@ user language should update the control plane. 7. The existing v6 control surfaces are still live, but they now sit underneath an evergreen Pulse control plane rather than pretending to be the whole long-term system. -8. Until the explicit post-GA branch cutover happens, both prerelease and - stable v6 promotions resolve to `pulse/v6-release` via `control_plane.json`. +8. Both prerelease and stable v6 promotions resolve to `main` via + `control_plane.json`. 9. Legacy maintenance releases that still feed governed automation outside the active v6 line must also resolve through `control_plane.json`. Right now the remaining `5.1.x` stable maintenance line resolves to `main` diff --git a/docs/release-control/v6/internal/HIGH_RISK_RELEASE_VERIFICATION_MATRIX.md b/docs/release-control/v6/internal/HIGH_RISK_RELEASE_VERIFICATION_MATRIX.md index cf029d50c..1a3c8b942 100644 --- a/docs/release-control/v6/internal/HIGH_RISK_RELEASE_VERIFICATION_MATRIX.md +++ b/docs/release-control/v6/internal/HIGH_RISK_RELEASE_VERIFICATION_MATRIX.md @@ -157,6 +157,70 @@ Companion drill: legacy recurring price, or cancellation/reactivation leaves pricing and entitlement state inconsistent across Stripe, Pulse runtime, and customer UI. +## Gate: `self-hosted-commercial-transition-coherence` + +- Why this is risky: + Relay/Pro and cadence changes cross Stripe proration and schedules, durable + webhook processing, grandfathering, local entitlement projection, license + versioning, Relay grant enforcement, downgrade preservation, and customer- + visible account state. The current implementation can update Stripe price + identifiers without atomically changing tier or features, which can charge + for one plan while granting another. +- Primary runtime surfaces: + `pulse-pro/license-server/v6_checkout.go` + `pulse-pro/license-server/v6_stripe.go` + `pulse-pro/license-server/v6_reconcile.go` + `pulse-pro/license-server/v6_state.go` + `pulse-pro/license-server/v6_store.go` + `pulse-pro/license-server/v6_grants.go` + `pkg/licensing/...` + Pulse Account Billing and Stripe customer/subscription state +- Automated proof: + Local unit and integration proof now covers the Community/Relay/Pro and + monthly/annual timing matrix, quote/apply parameter binding, idempotent + immediate retry convergence, schedule creation/reuse/cancellation ownership, + atomic commercial snapshot projection, payment-failure versus cancellation + grace, downgrade history timing, report entitlement denial, and safe artifact + purge. The remaining duplicate/reversed/missing external-event matrix and + restrictive Relay grant version-floor scenario require the governed Stripe + test-mode rehearsal; until that evidence is registered, the gate remains + blocked. +- Manual scenario: + 1. In Stripe test mode, create fresh Community-to-Relay and Community-to-Pro + acquisitions for monthly and annual plans. + 2. Exercise immediate quoted/prorated Relay-to-Pro and monthly-to-annual + changes, including success, decline, timeout-after-success, duplicate + request, and replay. + 3. Exercise renewal-bound Pro-to-Relay and annual-to-monthly changes, + including cancellation/resume before the effective timestamp. + 4. Exercise voluntary paid-through expiry, recovery-only access, involuntary + payment-failure grace and recovery, grace expiry, refund/dispute, and + current-price re-entry after continuity ends. + 5. Reverse, duplicate, suppress, and later replay Stripe events; reconcile + from the current Stripe snapshot and confirm the same final state. + 6. Confirm every material entitlement reduction increments + `license_version`, rejects the old grant in Relay/runtime, and preserves + configuration, report definitions, audit records, and the governed + downgrade history window. + 7. Exercise the buyer/account journey at desktop and phone width and confirm + the quoted amount, effective date, plan, cadence, cancellation state, and + recovery behavior match runtime truth. +- Pass when: + Each scenario leaves exactly one billing contract and one entitlement + projection for the commercial subject; Stripe price, local plan, cadence, + runtime capabilities, license version, and customer-visible state agree; + replay/order variation does not change the result; and no downgrade or + cancellation deletes protected customer configuration or records. +- Latest exercised record: + Local implementation and browser evidence is recorded in + `docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md`. + No qualifying real-external-e2e record exists yet. +- Block release if: + Any supported transition can charge and grant different plans, mutate + entitlement without a version bump, restore ended grandfathering, rely on + mutable Customer Portal plan-switch configuration, or produce different + state under duplicate, missing, or reordered Stripe delivery. + ## Gate: `known-rc-issue-closure-for-ga` - Why this is risky: diff --git a/docs/release-control/v6/internal/SOURCE_OF_TRUTH.md b/docs/release-control/v6/internal/SOURCE_OF_TRUTH.md index 0bf4f6236..a06c958db 100644 --- a/docs/release-control/v6/internal/SOURCE_OF_TRUTH.md +++ b/docs/release-control/v6/internal/SOURCE_OF_TRUTH.md @@ -1,6 +1,6 @@ # Pulse v6 Source Of Truth -Last updated: 2026-07-02 +Last updated: 2026-07-14 Status: ACTIVE This file is the stable human governance layer for the active v6 release @@ -471,6 +471,13 @@ Assertion design rules: document bound to the audited SHA selected at runtime. The checker must never execute real-lab, device, relay, or other mutation-gated commands itself. +24. Do not ship or expose self-service plan or cadence transitions unless the + authoritative Stripe subscription snapshot, local billing contract, + entitlement projection, continuity epoch, license version, and grant + revocation/outbox state converge through one idempotent transition + authority. A customer must never pay for one plan while Pulse grants + another, and duplicate, missing, or reordered webhook delivery must not + change the final commercial state. ## Locked Decisions @@ -545,6 +552,40 @@ Assertion design rules: trust, or installer/update/rollback path changed, and the exact-SHA release dry run passed. Those risk conditions require RC lineage unless an active customer-harm emergency is recorded through the hotfix exception. +16. The canonical self-hosted offer is job-based rather than a + good/better/best ladder: Community is the free local monitoring foundation, + Relay is remote access plus Pulse Mobile pairing, push, and 14-day history, + and Pro is Patrol-powered investigation and governed operations with + 90-day history and Relay bundled. One Relay or Pro subscription covers one + owner-operated environment with unmetered monitored-system and child- + resource volume plus three concurrent primary/migration/recovery + activations. It does not cover independently operated client environments. +17. Verified administrative ownership transfers are permitted, while resale, + sharing, and unverified third-party assignment are prohibited. Relay and + Pro include standard verified commercial support for billing, activation, + transfer, configuration, and diagnostics, normally targeted within two + business days without a contractual SLA or priority-support promise. +18. Self-hosted subscription transitions follow the approved lifecycle matrix + in + `docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md`: + Relay-to-Pro and monthly-to-annual changes are immediate only after an + explicit prorated quote and successful payment; capability downgrades and + annual-to-monthly changes occur at renewal without proration; voluntary + cancellation ends paid capability at the paid-through timestamp; a + separate seven-day recovery-only window grants no paid capability; and + involuntary payment failure receives seven days of functional grace. + Configuration, report definitions, and audit records survive downgrade; + out-of-tier history and generated artifacts soft-hide for 30 days and + become purge-eligible after 60 days. Completed cancellation or a completed + tier/cadence change ends grandfathered recurring-price continuity. +19. Cloud is unavailable until a governed reopening gate proves its economic + unit/caps, card policy, support, retention, export, cancellation, + reactivation, and runtime enforcement. Historical Cloud prices and caps + are dormant proposals, not a current offer. MSP remains an assisted + preview, provider-hosted by default, with 5/15/40 isolated client- + workspace limits; public copy may state the recorded monthly and annual + prices but must not promise immediate self-service checkout or Pulse-hosted + fulfillment. ## TrueNAS Support Floor diff --git a/docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md b/docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md new file mode 100644 index 000000000..b74d6d601 --- /dev/null +++ b/docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md @@ -0,0 +1,169 @@ +# Commercial Offer And Lifecycle Contract + +Date: 2026-07-14 +Owner: project owner +Status: approved for implementation + +## Decision + +Pulse commercial packaging and lifecycle behavior must converge on one +versioned offer contract. The public site, Pulse Account, in-product plan +surfaces, checkout projection, Stripe catalog audit, license-server billing +state, runtime entitlements, and support policy must not maintain independent +commercial definitions. + +## Self-Hosted Offer + +1. Community is the free local monitoring foundation with 7-day history. +2. Relay is the secure remote-access, Pulse Mobile pairing, push-delivery, and + 14-day-history service. +3. Pro is the Patrol-powered investigation and governed-operations product + with 90-day history and team/admin controls. Pro includes Relay; a buyer + never needs simultaneous Relay and Pro subscriptions for one environment. +4. Community, Relay, and Pro solve distinct jobs. They must not be presented + as a recommended good/better/best ladder. +5. Ordinary self-hosted trial acquisition remains retired. + +## License Scope And Support + +1. One Relay or Pro subscription covers one owner-operated Pulse environment. +2. Monitored-system and child-resource volume is not metered for self-hosted + Community, Relay, or Pro. +3. A paid subscription permits three concurrent activations inside that one + environment for primary, migration, and recovery use. It does not license + independently operated client environments; that is the MSP product job. +4. Verified administrative ownership transfer is permitted. Resale, sharing, + and unverified third-party assignment are prohibited. +5. Relay and Pro include standard verified commercial support for billing, + activation, transfer, configuration, and diagnostics. The public target is + typically within two business days, without a contractual SLA or a + priority-support promise. + +## Subscription Transition Matrix + +| From | To | Effective time | Billing treatment | Entitlement treatment | +|---|---|---|---|---| +| Community | Relay or Pro | After successful checkout | New subscription | Grant the purchased plan atomically | +| Relay | Pro, same cadence | Immediate after explicit quote and successful prorated payment | Prorated upgrade | Pro plus bundled Relay | +| Monthly | Annual, same tier | Immediate after explicit quote and successful prorated payment | Prorated cadence change | Tier unchanged | +| Pro | Relay | Current paid period end | No proration | Remove Pro-only capabilities; retain Relay | +| Annual | Monthly, same tier | Current paid period end | No proration | Tier unchanged | +| Any paid plan | Community by cancellation | Current paid period end | No proration | Paid capabilities end at the paid-through timestamp | + +Combined transitions follow the most restrictive rule. Any transition that +reduces capabilities or moves annual to monthly takes effect at renewal. +Customer-visible confirmation must state the effective date and quoted charge +or credit before mutation. + +## Cancellation, Grace, And Continuity + +1. Voluntary cancellation is scheduled for period end. Paid capabilities end + at the paid-through timestamp. +2. A seven-day post-term recovery window may support subscription reactivation, + license retrieval, and account recovery, but it is not a paid-entitlement + extension and must not grant Relay or Pro capabilities. +3. Involuntary payment failure receives a separate seven-day functional grace + period. Existing paid capabilities remain available during that grace, then + fail closed if payment has not recovered. +4. Reversing scheduled cancellation before the paid-through timestamp + preserves subscription continuity. +5. Grandfathered recurring price continuity survives only while the original + recurring subscription remains continuous. Completed cancellation or a + completed tier/cadence change exits the grandfathered contract; later + re-entry uses current pricing. +6. A full refund or dispute revokes the affected paid entitlement and requires + explicit reactivation or repurchase. + +## Downgrade Preservation + +1. Configuration, report definitions, and audit records are not deleted solely + because a customer downgrades. +2. Pro-only configuration remains stored but inert while the entitlement is + absent. +3. History and generated artifacts outside the lower tier's active window are + soft-hidden for 30 days and become purge-eligible after 60 days. +4. Re-upgrade during the soft-hide window restores access without + reconfiguration. +5. Every capability, tier, cadence, restrictive state, or entitlement change + increments `license_version` and invalidates obsolete grants atomically. + +## Cloud And MSP Availability + +1. Cloud is unavailable. Its historical prices, caps, trial, and support labels + are dormant proposals, not a current customer offer. Cloud cannot reopen + until card policy, economic unit/caps, support, retention, export, + cancellation, reactivation, and runtime enforcement pass a governed + readiness gate. +2. MSP is an assisted preview and provider-hosted by default. Starter, Growth, + and Scale retain 5, 15, and 40 isolated client-workspace limits at the + recorded monthly and annual prices. Enterprise remains custom. +3. Public MSP copy may publish the recorded monthly and annual prices, but it + must not promise immediate self-service checkout or Pulse-hosted fulfillment. +4. Pulse-hosted MSP remains an optional assisted arrangement, not the default + public delivery model. + +## Implementation Boundary + +Stripe remains billing truth, but one Pulse-owned transition authority must +apply the authoritative Stripe snapshot atomically to billing contract, +entitlement projection, continuity epoch, transition history, license version, +and grant-revocation outbox state. Checkout, webhook, reconciliation, refunds, +support/admin actions, and future Pulse Account transitions must converge on +that authority. Stripe Customer Portal subscription updates remain disabled; +Pulse-owned plan transitions must not depend on mutable portal configuration. + +## Proof Required Before Closure + +1. Contract drift proof across public pricing, Pulse Account, in-product plan + presentation, Stripe product/price descriptions, support policy, and runtime + entitlements. +2. Complete Community/Relay/Pro and monthly/annual transition matrix proof. +3. Stripe test-mode payment, proration, schedule, cancellation, payment-failure, + refund, and re-entry proof. +4. Duplicate, reversed, missing, and replayed webhook convergence proof. +5. Restrictive-transition grant version-floor proof in Pulse and Relay. +6. Downgrade soft-hide, restoration, purge-eligibility, and configuration + preservation proof. +7. Desktop and phone-width buyer/account browser proof. +8. A read-only production Stripe catalog and portal expected-state audit before + any separately approved external configuration change. + +## Implemented Local Evidence + +The 2026-07-14 implementation slice now provides the local, non-transactional +foundation required by this contract: + +1. `pulse-pro/license-server/v6_commercial_projection.go` owns atomic catalog, + billing-contract, entitlement, continuity-epoch, license-version, transition + history, and revocation-outbox projection. Unknown or multi-price snapshots + fail closed, and checkout, subscription, invoice, cancellation, payment- + failure, and refund paths converge on that projection. +2. `pulse-pro/license-server/v6_commercial_transitions.go` owns authenticated, + durable transition quotes. Immediate expansion uses the exact quoted Stripe + proration timestamp with `pending_if_incomplete`; restrictive changes use a + renewal-bound subscription schedule without proration. Retry paths reuse + Stripe idempotency keys and already-created schedules. +3. `pulse-pro/landing-page/manage.html` exposes invoices/payment methods, + quoted Relay/Pro and cadence changes, period-end cancellation, reactivation, + and scheduled-change cancellation behind an emailed verification code. +4. `pkg/licensing/subscription_transitions.go`, `pkg/metrics/store.go`, and + `internal/api/report_schedules.go` persist downgrade timing, keep protected + configuration and report definitions, restrict out-of-tier access + immediately, delay physical history cleanup until day 60, block background + report execution without the current entitlement, and purge generated + report artifacts without following symlinks after eligibility. +5. Local proof is green for the complete license-server Go suite, 359 Python + pricing/copy tests, the Pulse licensing/metrics/API suites, and desktop plus + 390-pixel buyer/account browser exercise. These are local implementation and + rehearsal facts, not a substitute for the required Stripe test-mode and + production read-only evidence. + +## Remaining Readiness Boundary + +The `self-hosted-commercial-transition-coherence` gate remains blocked. No +Stripe test-mode mutation, live catalog/configuration change, purchase, +deployment, or production customer-data access was authorized or performed in +this slice. Before self-service is released, the project still needs the +governed external transition matrix, event-order/reconciliation exercise, +Relay version-floor proof, and read-only production catalog/portal audit named +above. diff --git a/docs/release-control/v6/internal/status.json b/docs/release-control/v6/internal/status.json index e6e5d74d6..f3b8a70ca 100644 --- a/docs/release-control/v6/internal/status.json +++ b/docs/release-control/v6/internal/status.json @@ -1,6 +1,6 @@ { "version": "6.0", - "updated_at": "2026-07-02", + "updated_at": "2026-07-14", "scope": { "active_repos": [ "pulse", @@ -4676,6 +4676,55 @@ "evidence_tier": "test-proof" } ] + }, + { + "id": "RA41", + "summary": "Self-hosted commercial state remains coherent across the canonical offer, Stripe billing, Pulse Account, license-server persistence, runtime and Relay entitlements, support policy, and customer-visible lifecycle: Community, Relay, and Pro keep distinct jobs with Pro bundling Relay; every tier or cadence transition applies the approved timing and proration matrix through one idempotent transition authority; restrictive changes invalidate old grants; downgrade preserves governed customer data; and replay, cancellation, refund, grace, or re-entry cannot make billing and entitlement drift.", + "kind": "trust-gate", + "blocking_level": "release-ready", + "proof_type": "manual", + "lane_ids": [ + "L2", + "L3", + "L12", + "L17" + ], + "subsystem_ids": [ + "cloud-paid" + ], + "release_gate_ids": [ + "self-hosted-commercial-transition-coherence" + ], + "evidence": [ + { + "repo": "pulse", + "path": "docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md", + "kind": "file" + }, + { + "repo": "pulse", + "path": "docs/release-control/v6/internal/subsystems/cloud-paid.md", + "kind": "file" + }, + { + "repo": "pulse", + "path": "internal/api/report_schedules_test.go", + "kind": "file", + "evidence_tier": "test-proof" + }, + { + "repo": "pulse", + "path": "pkg/licensing/subscription_test.go", + "kind": "file", + "evidence_tier": "test-proof" + }, + { + "repo": "pulse-pro", + "path": "license-server/v6_commercial_transitions_test.go", + "kind": "file", + "evidence_tier": "test-proof" + } + ] } ], "evidence_reference_policy": { @@ -4778,15 +4827,15 @@ "status": "partial", "completion": { "state": "bounded-residual", - "summary": "Commercial readiness is coherent for explicit preview, checkout handoff, paid-user activation/recovery, hosted-mode paths, and the first Pulse Intelligence value-evidence reporting surface, while default self-hosted app surfaces stay free-first and non-promotional; because v6 is not publicly GA, production public checkout stays on v5 until explicit GA cutover approval, and the production public flip plus release-day rollout execution plus the broader governed Patrol control experience remain separate follow-ups.", + "summary": "The approved Community / Relay / Pro contract is now projected into local public/account copy, support and legal policy, atomic license-server entitlement state, quoted Relay/Pro and cadence transition sagas, and runtime downgrade preservation. Local Go, copy-model, and desktop/phone browser proof is green. Self-service remains unreleased until the governed Stripe test-mode event/reconciliation matrix, Relay version-floor proof, and production read-only catalog/portal audit satisfy the commercial transition gate.", "tracking": [ { "kind": "lane-followup", - "id": "commercial-ga-promotion-package" + "id": "pulse-intelligence-pro-activation-loop" }, { - "kind": "lane-followup", - "id": "pulse-intelligence-pro-activation-loop" + "kind": "release-gate", + "id": "self-hosted-commercial-transition-coherence" } ] }, @@ -4847,11 +4896,16 @@ "name": "Cloud paid readiness", "target_score": 8, "current_score": 8, - "status": "target-met", + "status": "partial", "completion": { - "state": "complete", - "summary": "Cloud-paid runtime and billing surfaces are at the current tracked RC floor, including real cancellation/reactivation continuity across checkout, entitlement boundaries, and the shared commercial billing shell/model now used by both self-hosted Pulse Pro and hosted organization billing.", - "tracking": [] + "state": "bounded-residual", + "summary": "The local commercial projection now changes Stripe catalog identity, tier, cadence, features, continuity epoch, license version, transition history, and revocation outbox atomically, with a quote-bound transition authority for self-hosted plan and cadence changes. Cloud remains unavailable and MSP remains an assisted preview. External Stripe event/reconciliation and Relay version-floor proof remain governed release residuals.", + "tracking": [ + { + "kind": "release-gate", + "id": "self-hosted-commercial-transition-coherence" + } + ] }, "blockers": [], "subsystems": [ @@ -5907,11 +5961,16 @@ "name": "Customer account portal", "target_score": 6, "current_score": 6, - "status": "target-met", + "status": "partial", "completion": { - "state": "complete", - "summary": "Pulse Account is now a first-class governed customer-account surface at the current RC floor: hosted accounts land directly in Workspaces, the signed-in shell stays task-first across Workspaces, Access, Billing, and Support, and MSP plus self-serve commercial actions converge on one coherent authenticated account boundary.", - "tracking": [] + "state": "bounded-residual", + "summary": "The self-hosted manage entry point is now Pulse-named and job-first, with verified invoice/payment access, quoted Relay/Pro and cadence changes, cancellation, reactivation, and scheduled-change cancellation. Retrieve, refund, and data-request utilities remain separate specialist jobs. The lane stays residual until real Stripe transition/reconciliation and Relay entitlement proofs satisfy the governed transition gate.", + "tracking": [ + { + "kind": "release-gate", + "id": "self-hosted-commercial-transition-coherence" + } + ] }, "blockers": [], "subsystems": [], @@ -7874,6 +7933,46 @@ } ] }, + { + "id": "self-hosted-commercial-transition-coherence", + "summary": "Confirm the approved self-hosted offer and lifecycle remain coherent across public pricing, Stripe billing, Pulse Account, license-server state, runtime and Relay entitlements, support policy, and customer-visible transitions: quoted/prorated immediate upgrades, renewal-bound reductions, paid-through cancellation, distinct recovery and payment-failure grace, downgrade preservation, grant version invalidation, and current-price re-entry all converge under replay and reconciliation.", + "owner": "project-owner", + "blocking_level": "release-ready", + "minimum_evidence_tier": "real-external-e2e", + "status": "blocked", + "verification_doc": "docs/release-control/v6/internal/HIGH_RISK_RELEASE_VERIFICATION_MATRIX.md", + "lane_ids": [ + "L2", + "L3", + "L12", + "L17" + ], + "evidence": [ + { + "repo": "pulse", + "path": "docs/release-control/v6/internal/records/commercial-offer-lifecycle-contract-2026-07-14.md", + "kind": "file" + }, + { + "repo": "pulse", + "path": "internal/api/report_schedules_test.go", + "kind": "file", + "evidence_tier": "test-proof" + }, + { + "repo": "pulse", + "path": "pkg/licensing/subscription_test.go", + "kind": "file", + "evidence_tier": "test-proof" + }, + { + "repo": "pulse-pro", + "path": "license-server/v6_commercial_transitions_test.go", + "kind": "file", + "evidence_tier": "test-proof" + } + ] + }, { "id": "settings-surface-layout-consistency", "summary": "Confirm comparable settings surfaces present the canonical page shell, with consistent header framing and no ad hoc top-level layout chrome.", @@ -8078,17 +8177,6 @@ ], "cross_repo": false }, - { - "id": "commercial-ga-promotion-package", - "summary": "Track the explicitly approved GA production public flip and release-day execution work for the self-hosted commercial package; until that work is active, production public checkout must remain on v5 with v6 approval disabled, and default self-hosted app surfaces must stay free-first and non-promotional.", - "owner": "project-owner", - "status": "planned", - "recorded_at": "2026-04-20", - "lane_ids": [ - "L2" - ], - "subsystem_ids": [] - }, { "id": "journey-post-ga-expansion", "summary": "Track broader same-lane end-to-end journey expansion beyond the current GA floor now that prerelease-to-GA promotion proof is recorded.", @@ -8631,7 +8719,21 @@ ] } ], - "work_claims": [], + "work_claims": [ + { + "id": "codex-lane-l23", + "agent_id": "codex", + "summary": "Implement an independent-ground-truth Pulse Patrol qualification benchmark with disposable live-lab, replay, Watch, investigation, remediation, safety, statistical gates, and reporting support.", + "target_id": "v6-product-lane-expansion", + "claimed_at": "2026-07-14T09:15:01Z", + "heartbeat_at": "2026-07-14T09:15:01Z", + "expires_at": "2026-07-14T11:15:01Z", + "work_item": { + "kind": "lane", + "id": "L23" + } + } + ], "open_decisions": [], "source_of_truth_file": "docs/release-control/v6/internal/SOURCE_OF_TRUTH.md", "resolved_decisions": [ @@ -9442,6 +9544,65 @@ "lane_ids": [ "L5" ] + }, + { + "id": "cloud-msp-availability-contract", + "summary": "Cloud is unavailable; historical Cloud prices, caps, trial, and support labels are dormant proposals rather than a current offer, and reopening requires governed proof of card policy, economic unit/caps, support, retention, export, cancellation, reactivation, and runtime enforcement. MSP remains an assisted preview, provider-hosted by default, with 5/15/40 isolated client-workspace limits and recorded monthly/annual prices; this supersedes the earlier Starter self-serve buying motion until a later explicit decision reopens it.", + "kind": "pricing", + "decided_at": "2026-07-14", + "subsystem_ids": [ + "cloud-paid" + ], + "lane_ids": [ + "L2", + "L3", + "L4", + "L17" + ] + }, + { + "id": "self-hosted-commercial-scope-support-contract", + "summary": "One Relay or Pro subscription covers one owner-operated Pulse environment with unmetered monitored systems and child resources plus three concurrent primary/migration/recovery activations. Verified administrative transfer is permitted, resale/sharing/unverified assignment is prohibited, and Relay/Pro include standard verified commercial support typically within two business days without an SLA or priority-support promise.", + "kind": "contract", + "decided_at": "2026-07-14", + "subsystem_ids": [ + "cloud-paid" + ], + "lane_ids": [ + "L2", + "L3", + "L17" + ] + }, + { + "id": "self-hosted-commercial-transition-contract", + "summary": "Relay-to-Pro and monthly-to-annual changes are immediate only after an explicit prorated quote and successful payment; capability downgrades and annual-to-monthly changes occur at renewal without proration; voluntary cancellation ends paid capability at the paid-through timestamp with a seven-day recovery-only window, while payment failure receives seven days of functional grace. Downgrade preserves configuration, report definitions, and audit records; out-of-tier history/artifacts soft-hide for 30 days and become purge-eligible after 60 days; completed cancellation or tier/cadence change ends grandfathered recurring-price continuity.", + "kind": "contract", + "decided_at": "2026-07-14", + "subsystem_ids": [ + "cloud-paid" + ], + "lane_ids": [ + "L2", + "L3", + "L12", + "L17" + ] + }, + { + "id": "unified-commercial-offer-projection-contract", + "summary": "Community, Relay, and Pro remain distinct customer jobs with Pro explicitly bundling Relay; one versioned commercial offer contract must project into public pricing, Pulse Account, in-product plans, checkout, read-only Stripe catalog audit, support policy, billing persistence, and runtime entitlements. Stripe stays billing truth, while one Pulse-owned idempotent transition authority atomically owns the local commercial projection and every material entitlement change increments license_version.", + "kind": "architecture", + "decided_at": "2026-07-14", + "subsystem_ids": [ + "cloud-paid" + ], + "lane_ids": [ + "L2", + "L3", + "L12", + "L17" + ] } ] }