Kairos War Room · MN data rooms

MN Data Access OS · 12 rooms · living latest

Every room.
One protocol.

A token opens a door. It does not onboard a data room. Every source now moves through the same visible gates—from registration to one commissioned use, then into continuous readiness.

Automatic contract · every new room

The onboarding protocol.

Five gates complete onboarding. The sixth never finishes: it keeps a commissioned source fresh and usable. Data read and Write protection are separate facts, so a working read can never be mislabeled as blocked merely because write prevention is still unproved.

Key logistics Needed → Requested → Received → Stored → Rotated → Revoked

Acceptance rule Received never means Data read passed. Data read passed never means Write protection passed. Each gate reports only its own contract.

01

Register

Do we know what this room is, why it matters, its intended doorway and the owner role?

Pass when Purpose, expected source, intended doorway, key-holder role and privacy tier are recorded.

02

Data read

Does the declared path return useful source data?

Pass when The identity is known and a harmless fixture returns real source data for the declared slice. Coverage gaps belong to Inventory, not this gate.

03

Write protection

Is the same identity prevented from changing the source?

Pass when Vendor permissions, an immutable artifact or an accepted compensating control proves that the read path cannot mutate or administer the source.

04

Inventory

Do we know the reachable objects, fields, history and gaps?

Pass when Reachable objects, fields, time bounds, pagination, denominators and unknown perimeter are measured.

05

Commission

Has one named use passed a decision contract?

Pass when One question-specific use names its grain, window, denominator, ceiling, failure condition and acceptance owner, then passes.

06 continuous

Maintain

Will this room keep working without Lee chasing the same access again?

Pass when Continuous ownership, refresh cadence, credential rotation and revocation, change detection and re-acceptance are proven and working.
Passed

The contract is met only for this gate and its named scope.

Active

Kairos is executing this gate now.

Waiting owner

The next required action is with a named external owner or owner role.

Blocked

The gate contract is unmet and no accepted continuation can run.

Not started

This gate is unopened, not failed.

Reopened

A material change or failure invalidated earlier acceptance; this gate must pass again.

Unproven

No write capability has been exercised, but source-side prevention or an accepted compensating control has not been proved. Reads may continue; this safety gate has not passed.

Overprivileged

The current identity is proved able to change the source. Non-mutating mapping may continue, but this safety gate cannot pass until the identity is narrowed or isolated.

Show

Showing all 12 rooms

Onboarding board · 12 rooms

Connection. Gates. Exact next move.

Fully onboarded: 0 of 12. Maintain passing: 0. There is no numeric rating: completion requires a live interactive connection plus all five setup gates, so a frozen archive cannot look equivalent to a live source.

Data roomConnectionCurrent gate

Data room

Slack public-channel export

Knowledge and decisions · Key Not Needed

Connection

Static snapshotFrozen at 18 Aug 2026; no Slack API, MCP-compatible connector or automated refresh is accepted.
RegisterPassed
Data readPassed
Write protectionPassed
InventoryPassed
CommissionPassed
MaintainBlocked

Current gate · Maintain

Give Šaras one authorised read-only Slack connection that can retrieve a message posted after 18 Aug 2026. A ZIP export or another frozen copy does not pass.

Data room

BigQuery mysterium-bq

Warehouse · Key Received

Connection

Live interactiveThe authenticated web path can return useful BigQuery data; the local CLI path is currently blocked.
RegisterPassed
Data readPassed
Write protectionUnproven
InventoryPassed
CommissionPassed
MaintainBlocked

Current gate · Write protection

Prove source-side mutation denial and durable credential custody without widening the current grant.

Data room

CJ advertiser commissions

Affiliate finance · Key Received

Connection

Live interactiveThe configured advertiser CID can be queried again through the API.
RegisterPassed
Data readPassed
Write protectionPassed
InventoryReopened
CommissionPassed
MaintainBlocked

Current gate · Inventory

Prove the complete advertiser-CID denominator, account lifetimes, credential entitlements, retention and a same-filter UI/export reconciliation.

Data room

ClickUp MN workspace

Work management · Key Stored

Connection

Live interactiveCurrent task-space metadata can be requested again on demand across all 13 known Spaces.
RegisterPassed
Data readPassed
Write protectionOverprivileged
InventoryPassed
CommissionPassed
MaintainActive

Current gate · Write protection

Replace or isolate the personal token so the accepted identity cannot mutate or administer ClickUp.

Data room

Omnisend campaigns

Email marketing · Key Received

Connection

Partial interactiveCampaign metadata is live; Brand identity and aggregate Analytics are denied.
RegisterPassed
Data readPassed
Write protectionOverprivileged
InventoryPassed
CommissionPassed
MaintainActive

Current gate · Write protection

Prove source-side write denial; the actual Owner/Admin must also enable Brand identity and Analytics before any performance analysis.

Data room

Ahrefs API v3

SEO · Key Received

Connection

Static snapshotThe accepted 27 Aug capture is retained; all three bounded GET checks on 7 Sep returned HTTP 401.
RegisterPassed
Data readPassed
Write protectionOverprivileged
InventoryPassed
CommissionNot started
MaintainBlocked

Current gate · Maintain

Restore an authorized fresh GET path and re-accept it without executing a mutation test.

Data room

Grafana and VictoriaMetrics

Operational telemetry · Key Received

Connection

Live interactiveGrafana and VictoriaMetrics reads return current telemetry on demand.
RegisterPassed
Data readPassed
Write protectionOverprivileged
InventoryPassed
CommissionNot started
MaintainNot started

Current gate · Write protection

Remove annotation create, write and delete permissions, or isolate the reads behind an accepted read-only path.

Data room

impact.com advertiser reporting

Affiliate finance · Key Stored

Connection

Live interactiveReports-only calls return current performance and action data on demand when SUBAID=23845 is supplied.
RegisterPassed
Data readPassed
Write protectionUnproven
InventoryPassed
CommissionNot started
MaintainNot started

Current gate · Write protection

Prove that the active source identity is vendor-enforced Reports-only or place it behind an MN-controlled GET-only broker; the adapter allowlist alone is a compensating control.

Data room

GoProxies reseller reporting

Proxy product · Key Received

Connection

No useful readThe documented reseller login path has not accepted the supplied identity.
RegisterPassed
Data readBlocked
Write protectionNot started
InventoryNot started
CommissionNot started
MaintainNot started

Current gate · Data read

Issue an identified reporting-only reseller identity and prove one bounded statistics fixture.

Data room

Pipedrive sales CRM

Sales operations · Key Received

Connection

No useful readThe corrected identity path rejected the supplied candidate and returned no source data.
RegisterPassed
Data readBlocked
Write protectionNot started
InventoryNot started
CommissionNot started
MaintainNot started

Current gate · Data read

Install the MN-controlled read-only OAuth grant, bind the intended company and pass one complete closed preceding 90-day aggregate funnel fixture.

Data room

Mysterium business API

Network and product · Key Received

Connection

UnverifiedThe represented service and connection contract remain unidentified.
RegisterBlocked
Data readNot started
Write protectionNot started
InventoryNot started
CommissionNot started
MaintainNot started

Current gate · Register

Identify the exact service, entity, issuer, authentication contract and intended read perimeter.

Data room

RichAds advertiser reporting

Paid media · Key Received

Connection

UnverifiedNo official advertiser-reporting connection contract has been verified.
RegisterBlocked
Data readNot started
Write protectionNot started
InventoryNot started
CommissionNot started
MaintainNot started

Current gate · Register

Obtain the official reporting contract, verified account owner and dedicated reporting identity.

Separate board · 3 missions

Analysis starts with a decision.

Commissioning proves one bounded use inside a room. An analysis mission is different: it names the decision, the source contract and the kill condition. Cross-analysis begins only when every required room is ready for that mission.

CROSS ROOM

Complete with finding

Affiliate attribution integrity

Decision Can the current warehouse attribution path reliably preserve independently proven affiliate orders?

  1. Select
  2. Contract
  3. Run
  4. Decide
  5. Close / refresh

ATTRIBUTION CONFLICT · WAREHOUSE COVERAGE GAP

Of 146 independently CJ-proven orders, 145 reached both warehouse spines and none was classified affiliate; one warehouse record was missing.

Next Closed for this contract. Do not treat it as profitability, partner-performance or net-revenue evidence.

FOLLOW UP

Closed · no lead

Attribution lineage · Contract 2A

Decision Does the commissioned Slack perimeter name a source-addressable repair lead for the attribution conflict?

  1. Select
  2. Contract
  3. Run
  4. Decide
  5. Close / refresh

LINEAGE LEAD NOT FOUND

The bounded run examined 322 Slack records and three relevant human records, but found no source-addressable lineage lead.

Next Kill condition fired. Do not repeat Contract 2A or open Contract 2B without a new source-addressable lead.

CROSS ROOM

Waiting for Impact commissioning

All-network affiliate performance

Decision Which affiliate activity is real across networks, and what can be compared on a stable basis?

  1. Select
  2. Contract
  3. Run
  4. Decide
  5. Close / refresh

NO COMPARABLE CROSS-NETWORK CONTRACT

Impact now has verified performance and action data, but its source semantics, stable warehouse join and bounded use are not commissioned; no cross-network comparison claim can run yet.

Next Commission one bounded Impact use with reconciled source semantics and stable IDs, then write the cross-room comparison contract.

Evidence drill-down

Three states that never collapse into one.

Key state is logistics. It says whether a credential is needed, requested or received. It never certifies the doorway.

Overall source state reports work maturity, not permissions. Data read and Write protection remain separate evidence. Analysis missions then run on their own contracts.

“Unknown by name” is a live control defect. Gitanas routes access-unlock work across MN. The administrator of each source remains the actual key holder.

Source status · meaning before colour

What the room may support now.

Status describes whether Kairos can use the connection responsibly. It does not grade the value of the source or the team behind it.

Use Commissioned

1

Kairos has a working read path, has measured the reachable scope, and has passed the checks required for one named use. The approval stops at that use.

Example Slack is ready for historical public-channel lineage work through 18 Aug 2026. It is not ready for current-state, private-channel, attachment-content, or live-workspace claims.

Mapping Partial

7

A useful read path works and returns real source data, but coverage, meaning, ownership, durability, or safe operating limits are incomplete. Mapping may continue; no broader analytical conclusion is commissioned.

Example Grafana returns live telemetry, but the current identity can also mutate annotations. The source is readable; its safety boundary and metric meaning are still incomplete.

Useful Read Blocked

4

No accepted useful read path exists for the intended source. Authentication may fail, the required data may not be exposed, or no valid reporting contract has been demonstrated. Connection diagnostics do not count as source access.

Example GoProxies remains blocked because no accepted useful reporting path or source payload has been demonstrated.

Working terms and concrete examples 16 definitions
Data room
One source system or bounded source connection that Kairos may need to inspect. Example: BigQuery, Slack and Grafana are separate data rooms.
Doorway
The actual route used to reach the source, such as an API, export, browser session or database query. Example: The Slack doorway is a frozen export, not a live Slack login.
Key type
The class of identity or secret that opens the doorway. The map names the class, never the secret value. Example: A person-bound OAuth session and an organisation-controlled service identity are different key types.
Grant
What the current identity is actually allowed to read or do, including the hard edge where permission stops. Example: A grant may allow report listing while still denying report data.
Key holder
The person or role able to issue, widen, replace or revoke access. A delivery contact is not automatically the administrator. Example: Gitanas can route an unlock request while the source administrator remains the actual key holder.
Durability gap
The reason access may fail when a person leaves, a token expires, a snapshot ages, or ownership is unclear. Example: A borrowed personal login with no backup or rotation rehearsal has a durability gap.
Denominator
The complete set against which a coverage claim is measured. Without it, a count can look complete while omitting unknown data. Example: 145 matched orders means little until the tested denominator of 146 CJ-proven orders is named.
Perimeter
The measured boundary of what the active identity can reach. Data outside that boundary is unknown, not absent. Example: BigQuery's 503-object perimeter excludes policy-hidden objects and other locations.
Source fitness
Evidence that a specific object or slice is reliable enough for one stated question, with known grain, coverage and failure conditions. Example: Passing a purchase-table fitness check does not certify every warehouse table or join.
Principal
The user, service account or role whose identity determines the effective permissions. Example: A borrowed Google user and an MN-controlled service account are different principals.
IAM
Identity and Access Management: the rules that decide who can reach which cloud resources and with what permissions. Example: An IAM owner can create a durable read-only BigQuery identity.
PAT
Personal Access Token: an API credential tied to one named user rather than a durable organisation role. Example: The current CJ connection uses a person-bound PAT.
FTS
Full-text search index: a derived index that makes message text searchable without changing the source snapshot. Example: Slack has 1,085,280 stored rows and the same number of FTS rows.
Mutation denial
Proof that the active identity cannot create, edit or delete source data or configuration. Example: A read-only claim is incomplete until attempted write classes are denied or otherwise proved impossible.
Correction-aware collapse
A rule for combining reversals and corrected events without double-counting an order or erasing its final state. Example: CJ's February correction pairs stay excluded until this rule is approved.
Acceptance owner
The person or team responsible for checking that the requested access or analysis meets its stated contract. Example: MN changes the source grant; Kairos independently accepts the resulting connection.

Evidence table A · access topology

Who holds which keys.

Read left to right on desktop. On a phone, every row becomes a complete room card. The first column stays anchored while the desktop table moves.

MN data rooms, the data inside, current access, credential class, users, grant limits, key holders and durability gaps.
Data roomData insideCurrent doorwayKey typeWho can use itCurrent grant and limitsKey holder / access escalationDurability gap
BigQuery mysterium-bqWarehouseEvidence 2026-08-2724 reachable datasets; 503 reachable objects; 7,760 columns. Curated payment, revenue, user, product, marketing, analytics and claude.* objects inside the current principal's visible perimeter.A usable authenticated BigQuery web read path has returned a private Intercom corpus. The configured local bq CLI principal still requires interactive reauthentication.Person-bound Google sessions: the web path is currently usable, while the local CLI OAuth session cannot refresh non-interactively. No reusable service account or application-default credential is available.Kairos has used the authenticated web path for one bounded private corpus export. The local bq CLI has no current caller until interactive reauthentication completes.A useful BigQuery web read is proved for the bounded Intercom corpus. Source-side mutation denial and a reusable automation perimeter are unproved. The parked Impact mission submitted no BigQuery job and produced no join or billing receipt.Project/IAM owner: unknown by name. Curated claude.* data and lineage: Simonas. Kairos conduit: Šaras. Gitanas routes the unnamed admin request.The web session is person-bound and the local CLI OAuth session is expired for non-interactive use. A durable Kairos principal, IAM perimeter, backup and offboarding path remain open.
CJ advertiser commissionsAffiliate financeEvidence 2026-08-26Configured-CID perimeter: 319/319 closed monthly advertiser item_sale queries completed, with 169 visible commission events in 11 active months. The complete current and historical MN advertiser-CID universe, account lifetimes, credential entitlements and retention horizon remain unproven.CJ GraphQL Commission Detail API through the MN advertiser account; advertiserCommissions root.Personal Access Token bound to a named MN account user. Expiry and replacement rehearsal are unrecorded.Kairos Lee-side connector. The account user's name is absent from the current receipt.Read-only advertiserCommissions access covers one configured advertiser CID under closed item_sale and posting-month filters in windows of 31 days or less. Publisher-side access returned 401. No evidence yet proves that this credential can see every current and historical MN advertiser CID.MN CJ advertiser administrator: unknown by name. Vendor support can evidence historical account scope. Šaras routes the administrator request and returns only credential-free proof.Person-bound PAT. Replacement, revocation and rotation have not been rehearsed.
impact.com advertiser reportingAffiliate financeEvidence 2026-08-27A catalog of 112 rows with 88 distinct report handles and 49 API-accessible reports. The aggregate-only adapter executed all 49 across July 2026; 37 returned records and 28 returned a non-zero additive measure.impact.com advertiser Reports API through the MN advertiser account, using the required SUBAID=23845 selector for the verified reporting slice.Matching account SID plus Reports authentication value. The credential values are omitted; the current pair authenticates and returns useful report data when the verified selector is supplied. Vendor-side mutation prevention is not yet evidenced.Kairos aggregate-only live reporting probes under the MN advertiser principal.The accepted adapter path returns live aggregate performance and action-listing data through GET-only Reports endpoints. No wider data grant is required; administration and mutation remain outside the accepted perimeter and source-side prevention is unproven.No wider data grant is required. The MN impact.com report owner must evidence the active role's Reports-only boundary or approve an MN-controlled GET-only broker, document selector and metric semantics, and own credential backup, rotation and revocation.The selector-aware aggregate-only adapter is on authenticated Kairos main at commit feac6db; 6/6 unit tests pass. Credential expiry, named primary and backup ownership, a receiver-tested replacement and vendor-side read-only enforcement remain unconfirmed.
Omnisend campaignsEmail marketingEvidence 2026-08-27Sixteen reachable campaign records with aggregate channel, status, type, language, field-set and date-horizon metadata. Bound Brand identity and aggregate Analytics are required but denied.Official Omnisend API 2026-03-15 Campaigns, current Brand and aggregate Analytics surfaces.MN brand-bound API key supplied by Šarūnas. It is not proved vendor-enforced read-only. The credential value is omitted; the actual human Brand Owner or Admin login remains unidentified.Kairos aggregate-only adapter under an MN API principal. sarunas@mysterium.network is the authorized delivery identity, not a recognized Omnisend account login.Campaign read is effective and returned 16/16 distinct campaigns in one complete page. Current Brand identity and the documented aggregate Analytics fixture each returned HTTP 403. Source-side absence of write capability is unverified; no mutation endpoint was exercised.Actual MN Omnisend Brand Owner or Admin: not identified. That owner must preserve Campaigns read and add Brand identity plus Analytics read without widening into customer or write scopes.The repaired shared aggregate-only adapter is on authenticated Kairos main at commit 1e72797; 6/6 adapter tests and 5/5 independent acceptance tests pass. Schema 2 records unknown vendor expiry with a fixed rotation deadline. Human owner, backup, successful rotation and revocation remain unnamed or unproved.
Ahrefs API v3SEOEvidence 2026-09-07Historical 27 Aug snapshot covering all three then-visible workspace projects and 13 API families with 148 operations; 2,161 own-domain organic keyword rankings, 261 ranking pages, 2,096 live referring domains, monthly history, 30-day change sets and API-unit controls.Ahrefs API v3 through the MN workspace.Bearer API key created by a named MN workspace user. Recorded expiry: 25 Aug 2027. The inherited bearer scheme also covers 18 potential Management and Social mutations.No accepted current API caller. The saved bearer key was rejected on all three measured GET paths, and the available browser profile did not show an authenticated workspace.The retained 27 Aug snapshot supports the measured own-domain mapping and exact change denominators. Fresh reads are blocked: all three bounded GET checks on 7 Sep returned HTTP 401. Effective denial of all 18 documented Management and Social mutations remains unproved. No mutation was executed.Actual MN Ahrefs Workspace Owner or Admin, currently unidentified.The retained 27 Aug snapshot, shared GET-only adapter, runbook and seven passing adapter tests remain durable. Fresh access, server-enforced read-only scope, backup ownership and tested rotation are open.
RichAds advertiser reportingPaid mediaEvidence 2026-08-26Intended perimeter: campaigns, creatives, spend, impressions, clicks, conversions and cost reporting with stable IDs, currency and time zone. Actual exposed objects remain unknown.No verified doorway. An API key exists; base URL, authentication scheme, account binding and response contract remain unidentified.Unidentified RichAds API key. Scope, read or write power, account, expiry and revocation are unknown.No authorised connector has used the value. Named custodian is unrecorded.No measured grant. Endpoint guessing is prohibited.MN RichAds account owner and verified RichAds account manager: both unknown by name. They must supply the official advertiser-reporting packet and dedicated reporting credential. Gitanas routes the request.Uncommissioned. Recovery, rotation and revocation paths are absent.
Mysterium business APINetwork and productEvidence 2026-08-26Intended room: MN business telemetry and reporting. The represented service, entity, objects, fields and history remain unknown.No identified API. Candidate endpoint and authentication shapes returned 401 or 404. TequilAPI and node-management surfaces sit outside this unidentified claim.Unidentified supplied value. Principal, issuer and credential type are unknown.No current caller.No measured scope and no accepted business data.Original MN credential issuer or service owner: unknown. They must identify the exact service, base URL, auth type, entity and read perimeter, or issue a documented replacement. Gitanas routes until the issuer is named.No custody, rotation, revocation, expiry or recovery chain. This remains an unidentified credential record.
GoProxies reseller reportingProxy productEvidence 2026-08-26Intended perimeter: traffic, request and country statistics; account and read-only subuser metadata; plan and customer usage; linkage for contribution analysis.Documented reseller sequence is username and password login to a bearer session, followed by statistics reads. Supplied values failed the tested contract.Unidentified supplied values that do not match the documented login contract.No current caller. Credential issuer and represented account are unknown.No authenticated scope and no returned business data. Public reseller credentials may also permit mutations; a safe connection requires vendor-enforced read-only or an approved compensating connector.GoProxies account administrator or credential issuer: unknown by name. They must issue a reporting-only reseller identity and state whether mutations can be vendor-denied. Gitanas routes the request.No working credential, custody chain, expiry, rotation or revocation path.
Grafana and VictoriaMetricsOperational telemetryEvidence 2026-08-27152 dashboards, 16 folders and 20 datasources; 2,280 panels, 3,133 stored panel queries, 286 variables, 125 alert rules, and nine Prometheus-compatible metric catalogs. Logs, traces and annotation records were not retrieved.Grafana HTTP APIs and /api/ds/query through an MN Grafana organisation Viewer service account.Service-account token. Named token custodian and rotation owner are unrecorded.Kairos Lee-side connector. Principal is owned by the MN Grafana organisation.Dashboard, folder, datasource, query and alert-rule reads work. Effective permissions also allow annotation create, write and delete, so the connection remains outside the required read-only boundary.Grafana organisation administrator and telemetry owner: both unknown by name. The first repairs role and token; the second supplies metric definitions, units, retention and lineage. Gitanas routes both requests.Service identity is structurally durable. Current grant is overprivileged. Expiry and replacement rehearsal are unrecorded.
ClickUp MN workspaceWork managementEvidence 2026-08-2713 Spaces, 30 Folders, 225 Lists and 7,007 distinct reachable tasks; aggregate status types, assignment/subtask counts, custom-field types and task date horizons. Task content, comments, attachment bodies and person-level fields are not persisted.ClickUp API through the authorised Šarūnas personal-token principal and the Kairos fixed-host GET-only adapter.Authorised personal API token supplied by Šarūnas. Person-bound; vendor-documented as non-expiring, with a fixed rotation deadline; credential value omitted from every evidence artifact.Šarūnas is the represented principal. Kairos uses only the tested aggregate GET path for Lee-side MN research.Live reads reach all 13 known Spaces and the complete declared task-space perimeter. The personal token inherits the principal's ClickUp permissions, so source-side mutation denial is not proved even though the adapter refuses every non-GET request.Šarūnas owns the current personal credential. The MN ClickUp Workspace Owner or Admin owns role narrowing and any vendor-enforced replacement; a backup owner is not recorded.The GET-only adapter is repeatable and schema 2 records the vendor non-expiry contract plus a fixed rotation deadline. Backup owner, successful rotation and revocation rehearsal, and denominator-drift monitoring remain open.
Slack public-channel exportKnowledge and decisionsEvidence 2026-08-26Immutable snapshot: 237 public-channel records, 292 user profiles and 1,085,280 indexed messages from 19 Oct 2017 to 18 Aug 2026, plus file and edit metadata present in the export. DMs, MPDMs and private channels are absent.Accepted archive plus derived local index. Snapshot connection; no live Slack API or workspace session.No secret key. The credential-equivalent asset is the accepted export artifact.Kairos internal analysis team. Šaras and Metis acted as the delivery conduit; that does not prove Slack admin authority.Full accepted public-channel snapshot. Live completeness, post-18 Aug 2026 activity, private surfaces, linked documents and attachment contents sit outside the connection.MN Slack Workspace Primary Owner or export administrator: unknown by name. Šaras and Metis are the known delivery route. Gitanas is the overall unlock router.Artifact is durable; refresh is not. No repeatable refresh identity, cadence, revocation owner or live denominator.
Pipedrive sales CRMSales operationsEvidence 2026-08-27Intended perimeter: aggregate pipelines, stages, leads, deals, persons, organisations, activities, products, users and custom-field families, plus stable Universe or customer identity fields.Corrected vendor-documented users/me identity probe. The supplied personal-token candidate was rejected; the target is an MN-controlled read-only OAuth installation.Protected local token candidate with unverified provenance, owner and company binding; rejected by Pipedrive. No credential value enters the map.No accepted caller. No authenticated Pipedrive company session exists for Kairos.No accepted grant and zero visible source objects. Effective read perimeter, company denominator and source-side mutation denial are unmeasured.MN Pipedrive Account Admin: unknown by name. That admin and the sales-operations data owner must bind the intended company, read scopes and source controls.No working credential, named backup, accepted expiry contract, rotation rehearsal, revocation rehearsal or denominator-drift monitor.

Evidence table B · execution record

What happened inside.

A working access path does not make every object fit for every question. The evidence column names the examined denominator; the untouched column shows the remaining perimeter.

Work completed in each MN data room, evidence coverage, untouched scope, state, next action and owners.
Data roomWhat was doneEvidence and coverageWhat remains untouchedCurrent stateExact next stepAction and acceptance owners
BigQuery mysterium-bqWarehouseEvidence 2026-08-27Preserved the accepted warehouse inventory and CJ attribution controls, and acquired one bounded private Intercom corpus through the web path. The exact Impact-to-BigQuery mission is parked; its source leg completed, but no warehouse join ran.Historical warehouse control: 146 independently proven CJ orders, 145 warehouse matches and zero affiliate-labelled matches. A later usable BigQuery web read acquired a private Intercom corpus. Current Impact source control: July 193 actions and November 2024 3,679 actions. The parked Impact mission remains without a join. No BigQuery query job was submitted; processed and billed bytes are absent.Every Impact candidate join; current join-target schemas and rows; duplicate grain, unmatched counts, attribution labels, money reconciliation, Impact UI/export parity and business conclusions.Mapping PartialA useful web read works; the CLI path, write boundary and credential durability remain incomplete.Do not resume the Impact join automatically. Rank it in the opportunity-evidence programme first. Separately prove source-side write protection and establish a durable MN-controlled read principal.BigQuery IAM owner: unnamed. Curated lineage: Simonas. Account conduit: Šarūnas. Kairos accepts only bounded reads with current receipts; identity consent remains with the represented principal.
CJ advertiser commissionsAffiliate financeEvidence 2026-08-26Inventoried the configured-CID schema and visible history; established commissionId as event grain; isolated February correction pairs; and completed the bounded ten-month CJ-to-warehouse attribution-integrity control. Contract 2A searched the commissioned Slack perimeter for a repair lead and returned LINEAGE LEAD NOT FOUND.Configured-CID result: 308/319 monthly queries returned zero rows, classified ZERO_RETURNED_SCOPE_UNPROVEN rather than empty; 11 months from Sep 2025 to Jul 2026 returned 169 visible events (15.4 per active month; largest month 24). Correction-safe control: 146 orders; 145 clean and revenue matches; zero affiliate, 118 direct, 13 other, 14 without a marketing row and 1 warehouse-missing. Contract 2A scanned 322 Slack records and found 3 relevant human records, but no source-addressable lineage lead.Publisher-side commissions, non-closed and non-item_sale activity, item detail, shopper and device fields, amount currency and sign semantics, the authoritative current and historical advertiser-CID census, account active dates and migrations, credential entitlements, retention policy, UI/export reconciliation, impact.com and every other network. February's repeated-order correction groups remain outside the one-order control.Mapping PartialConfigured-CID read path works; full-history account scope and zero-window meaning are unproven.Do not repeat Contract 2A or rerun the same one-CID sweep as a substitute. Through Šaras, obtain one credential-free CJ evidence packet: every current and historical MN advertiser CID; each CID's active dates and migration links; the supplied credential's CID entitlements; Commission Detail retention; a same-filter CJ UI/export reconciliation with original/correction counts; one known-positive fixture per historical CID; and the source-owner answer on pre-Sep-2025 activity.MN: CJ advertiser admin and vendor support. Kairos acceptance: Talos and Tris.
impact.com advertiser reportingAffiliate financeEvidence 2026-08-27Corrected the earlier empty-result diagnosis by proving that SUBAID=23845 is causally required. All five applicable performance cuts reconcile July 2026 actions, revenue and cost; four expose clicks and reconcile to 68,993. The shared totals are 193 approved actions, EUR 1,056.22 revenue and EUR 232.05 cost; the action listing returned all 193 rows. All 49 API-accessible reports then completed, including the hourly report through 31 daily chunks and 744 rows.SUBAID=23845 control: the July daily report returned 31 date rows with zero populated metric cells without the selector and 31/31 rows with a nonzero additive metric with it. Four performance cuts exposing clicks reconcile to 68,993; all five applicable cuts reconcile to 193 actions, EUR 1,056.22 revenue and EUR 232.05 cost. Inventory: 49/49 complete payloads, 37 with records, 28 with a non-zero additive measure.Source-owned SUBAID, Funnel-click and lock-date semantics; UI or source-export reconciliation; stable Impact-to-warehouse joins; credential ownership, expiry, replacement and vendor-side read-only evidence; and every cross-network business conclusion.Mapping PartialUseful read and the measured 49-report inventory are complete; source semantics, least-privilege proof, warehouse reconciliation and one bounded commissioned use remain incomplete.Close the source-side read-only and credential durability gaps; obtain source-owned metric semantics and a same-filter UI or export reconciliation; map a stable action or order join to the warehouse; then commission one bounded use. Do not request a wider Impact permission grant.Kairos/Talos: adapter, inventory, reconciliation and commissioning. MN impact.com report owner: selector and metric semantics plus credential backup, rotation and revocation; no grant change.
Omnisend campaignsEmail marketingEvidence 2026-08-27Bound the supplied independent three-surface evidence and the repaired shared adapter's fresh reconfirmation. Campaign pagination closed at 16 distinct campaigns across one complete page with zero duplicate IDs and zero missing required fields; Brand identity and aggregate Analytics each returned HTTP 403. No credential value, raw brand or campaign ID, campaign name or content, audience, sending setting, recipient/contact data or raw row was persisted.Campaigns: 16/16 across one complete page; 13 sent and 3 draft; 14 regular and 2 booster; all email and en_US; zero duplicate IDs; zero missing required fields; one consistent suppressed brand identifier. Brand identity: HTTP 403. Documented /api/analytics/reports campaign-performance fixture: HTTP 403.Bound Brand identity and every aggregate delivery or engagement metric because their endpoints were forbidden; source-side write denial; campaign names, subjects, content, audiences, sending settings, contacts, recipients and raw rows by persistence policy; owner, backup, rotation, revocation and all performance or business conclusions.Mapping PartialCampaign inventory is commissioned. Strict gate: OVERPRIVILEGED / SOURCE_BLOCKED / SOURCE_NOT_READY because source-side write scope, Brand identity and Analytics remain unresolved.The actual MN Brand Owner or Admin proves a source-side read-only scope while preserving Campaigns read and enabling Brand identity plus Analytics read. Keep Contacts, Orders, Products, Carts, raw Events, billing, user management, writes and administration excluded; then rerun the same fixture.MN: actual Omnisend Brand Owner or Admin, currently unidentified; Šarūnas is the credential delivery route. Kairos acceptance: Talos through the aggregate-only adapter.
Ahrefs API v3SEOEvidence 2026-09-07Preserved the 13-family, 148-operation and 3-project perimeter, then mapped the own-domain denominators: 2,161 keyword rankings, 261 pages and 2,096 live referring domains. Validated top-100 detail samples for all three datasets plus exact 30-day gained and lost keyword and page sets. Migrated the access receipt to schema 2 without weakening the strict gate. No mutation was executed and no business finding was commissioned.Top-100 coverage: keywords 4.63%, pages 38.31%, referring domains 4.77%; 300/300 aggregate sample rows valid with zero duplicate identities. Exact 30-day change sets: 250 gained and 250 lost keyword-country-URL rows; 35 gained and 35 lost page URLs. Measured denominators: 2,161 ranking keywords, 261 ranking pages and 2,096 live referring domains. Run cost: 22,635 units (24,961→47,596 of 400,000). On 7 Sep 2026, all three GET checks returned HTTP 401; the retained capture remained readable and hash-matched.2,061 current keyword rankings, 161 pages and 1,996 referring domains at row detail; backlinks, anchors, paid search, ideas, competitors and other API families; cross-source joins; effective mutation denial; named owner and backup; tested rotation; and every business conclusion.Mapping PartialRetained snapshot remains readable and mapped; fresh API access is blocked by three measured HTTP 401 responses. The cause is unknown; the recorded 2027 expiry does not establish current credential validity.Restore one authorized fresh GET path, then prove mutation denial through a vendor read-only credential or an MN-controlled allowlisted GET-only broker. Name the owner, backup and rotation path; rerun schema-2 acceptance before commissioning one question-specific use.MN: actual Ahrefs Workspace Owner or Admin. Kairos acceptance: Talos after current-schema connection and security-gate evidence; no mutation test.
RichAds advertiser reportingPaid mediaEvidence 2026-08-26Recorded credential metadata. No endpoint was guessed and no probe was run because the official advertiser API contract is absent.No accepted source payload, denominator or business fixture.Authentication, account binding, role, campaigns, history, fields, spend, click and conversion metrics, pagination, read-only enforcement, UI reconciliation and analysis.Useful Read BlockedOfficial advertiser-reporting contract is missing.Obtain the official advertiser-reporting packet and a dedicated reporting credential from the verified account manager. Run one known active seven-day report and prove campaign totals plus mutation denial.MN: RichAds account owner and verified account manager. Kairos acceptance: Talos and Tris.
Mysterium business APINetwork and productEvidence 2026-08-26Tested candidate authentication shapes against candidate surfaces; all returned 401 or 404. The result is a credential-identification failure. No business data was returned.Access diagnostics only; no real-object denominator.Exact service, entity, principal, auth contract, schema, history, business fixture, inventory, fitness and analysis.Useful Read BlockedAuthentication fails; the service is unidentified.The original issuer identifies the service and contract or issues a documented read-only replacement. Then run a harmless identity and denominator probe plus one closed seven-day business fixture.MN: original internal API issuer or service owner, to be named. Kairos acceptance: Talos and Tris.
GoProxies reseller reportingProxy productEvidence 2026-08-26Tested supplied values on three candidate authentication surfaces. The documented login-to-bearer-to-statistics contract was identified. No business payload was accepted.Access diagnostics only: 404 user-not-found and 401 under raw and Bearer forms.Traffic, requests, countries, subusers, customers, plans, history, billing and revenue linkage, contribution economics and conversion joins.Useful Read BlockedAuthentication fails; no business payload accepted.Issue an identified reporting-only reseller identity. Run a closed seven-day traffic and request control, reconcile to the dashboard, enumerate accounts and subusers, and prove mutation denial or the approved compensating connector.MN: GoProxies account admin or credential issuer. Kairos acceptance: Talos and Tris.
Grafana and VictoriaMetricsOperational telemetryEvidence 2026-08-27Fetched 152/152 dashboards with 0 errors; inventoried 2,280 panels, 3,133 stored queries and 286 variables. Summarised 125 alert rules (1 paused). Attempted all 9 metric catalogs: 6 complete, 2 partial because 18 malformed UTF-8 names were omitted, and 1 returned HTTP 502. Ran a live first-series fixture and a bounded history probe. No business conclusion was commissioned.168 search objects: 152 dashboards and 16 folders; 20 datasources; 2,280 panels; 3,133 stored queries; 7 mystproxy_connections series × 61 points = 427/427 non-null. Observed history lower bound: 30 days; the 90-day probe hit the source 30-billion-sample ceiling.Metric owners, business definitions, units, configured retention, refresh contracts and revenue lineage; the two partial metric catalogs and one HTTP-502 catalog; log lines, trace spans, annotation records and alert instances; and every business or revenue conclusion.Mapping PartialRead path works and is mapped; safety boundary and metric meaning remain incomplete.Remove annotation create, write and delete from the effective role or isolate a read-only proxy or organisation. Resolve the two malformed catalogs and one HTTP-502 catalog, then commission the first series with a named owner, unit, definition, retention and question.MN: Grafana organisation admin and telemetry owner. Kairos acceptance: Talos and Tris.
ClickUp MN workspaceWork managementEvidence 2026-08-27Enumerated 13/13 Spaces, 30 Folders and 225 Lists; closed every active and archived List-task page and deduplicated 7,007 reachable tasks. Commissioned one seven-day aggregate activity fixture: 201 updated tasks across 7 Spaces. No mutation was executed and no task content or credential value was persisted.13 active and 0 archived Spaces; 30 Folders; 225 Lists, of which 193 returned tasks and 32 returned none; 7,007 tasks, 5,150 closed/done, 1,754 subtasks and 91 custom-field IDs. Created horizon 2023-12-12→2026-08-27. 547 GET requests; 0 rate-limit retries.Task comments and comment history, audit log, Docs content, attachment bodies, Goals, time-entry detail, webhook events, source-side write denial, credential backup/rotation/revocation rehearsal, denominator drift monitoring and every cross-source or person-level claim.Mapping PartialThirteen-Space read and one aggregate use pass; source-side write denial remains open.Replace the personal token with vendor-enforced read-only access or isolate it behind an MN-controlled read-only broker. Name a backup owner, rehearse replacement and revocation, and install metadata-only denominator drift detection.MN: Šarūnas plus the ClickUp Workspace Owner or Admin for role, replacement and revocation. Kairos acceptance: Talos through the Lee-side GET-only adapter.
Slack public-channel exportKnowledge and decisionsEvidence 2026-08-26Commissioned the frozen public-channel snapshot for bounded historical prior-art and coordination-lineage reconstruction. Checked the accepted archive, every structural record, every index and FTS row, classifier boundaries, a bounded retrieval fixture and an independent logical rebuild. Earlier work completed the corpus and marketing maps, payment estate, metric lineage, team and role map, and operational recurrence topology. Contract 2A examined 322 records and 3 relevant human hits, returning LINEAGE LEAD NOT FOUND; no BigQuery extension was opened.237 channels; 292 users; 1,085,280 index rows and 1,085,280 FTS rows from 19 Oct 2017 to 18 Aug 2026; 171,017 human-classified and 914,263 bot or app-classified rows; zero duplicate channel and timestamp pairs; SQLite integrity ok. A clean rebuild matched every stored message, user and channel field plus the 114-hit bounded fixture. Contract 2A denominator: 322 records, 318 human-classified and 3 distinct relevant human hits; zero source-addressable lineage leads.Semantic remainder across many channels; 18,533 attachment pointers and their contents; linked documents and dashboards; DMs, MPDMs and private channels; live workspace denominator; post-18 Aug activity; present-state claims; source-system performance; and person-level conclusions outside the commissioned identity boundary.Use CommissionedFrozen public-channel history use commissioned.Do not repeat Contract 2A. No source-addressable lineage lead was found, so any later warehouse work needs a separately scoped contract. Name the Slack export owner and define refresh cadence, live denominator and accepted-delta process.MN: Slack Primary Owner or export admin. Kairos acceptance: Talos and Tris against the accepted archive.
Pipedrive sales CRMSales operationsEvidence 2026-08-27Registered Pipedrive as the twelfth room; corrected an invalid first URL; probed the documented identity endpoint; inspected custody and relay metadata without exposing the value. No source row was read.Corrected users/me identity probe returned HTTP 401 unauthorized, zero user or company identity and zero source objects. The candidate shape is syntactically clean, but provenance and possible truncation remain unverified.Every pipeline, stage, lead, deal, contact, organisation, activity, product, user and custom field; company and archived-object denominators; pagination; 90-day control; schema fitness; identity joins; write denial; ownership; rotation; revocation; and every business conclusion.Useful Read BlockedCorrected identity probe returned HTTP 401; no business payload was accepted.Create or designate an MN-controlled Pipedrive OAuth app with only the listed read scopes; return the metadata-only owner and grant packet through the established route; then reconcile an aggregate 90-day funnel fixture to company UI or export controls.MN: Pipedrive Account Admin and sales-operations data owner, coordinated through Šarūnas. Kairos acceptance: Talos against the read-only adapter and source-owner controls.

Method and boundary

How this stays useful.

Current through
2026-09-07
Canonical machine source
data.json · map schema kairos-mn-data-rooms/v6 · onboarding schema kairos-data-room-onboarding/v3 · source hash 5d7017f16ce6
Automatic protocol rule
A room cannot build without all six stage states and one connection mode. Completion requires LIVE_INTERACTIVE plus the first five gates; maintain is continuous.
Update rule
Every new login, token, export, role change, inventory, analysis, correction or blocked-state change updates the room, its onboarding stages and any dependent mission.
Commission rule
USE_COMMISSIONED permits only the named bounded use. It is not a claim that every security or maintenance gate has passed.
Mission rule
Analysis requires its own Select → Contract → Run → Decide → Close / refresh stages. A readable source does not authorize an uncontracted analysis.
Privacy
Credential metadata and aggregate evidence only. No credential values, customer rows, private paths or local storage mechanics.
Audience
Kairos War Room team tier under the existing Cloudflare Access contract.

Use Commissioned: Kairos has a working read path, has measured the reachable scope, and has passed the checks required for one named use. The approval stops at that use.

Mapping Partial: A useful read path works and returns real source data, but coverage, meaning, ownership, durability, or safe operating limits are incomplete. Mapping may continue; no broader analytical conclusion is commissioned.

Useful Read Blocked: No accepted useful read path exists for the intended source. Authentication may fail, the required data may not be exposed, or no valid reporting contract has been demonstrated. Connection diagnostics do not count as source access.

Data room: One source system or bounded source connection that Kairos may need to inspect.

Doorway: The actual route used to reach the source, such as an API, export, browser session or database query.

Key type: The class of identity or secret that opens the doorway. The map names the class, never the secret value.

Grant: What the current identity is actually allowed to read or do, including the hard edge where permission stops.

Key holder: The person or role able to issue, widen, replace or revoke access. A delivery contact is not automatically the administrator.

Durability gap: The reason access may fail when a person leaves, a token expires, a snapshot ages, or ownership is unclear.

Denominator: The complete set against which a coverage claim is measured. Without it, a count can look complete while omitting unknown data.

Perimeter: The measured boundary of what the active identity can reach. Data outside that boundary is unknown, not absent.

Source fitness: Evidence that a specific object or slice is reliable enough for one stated question, with known grain, coverage and failure conditions.

Principal: The user, service account or role whose identity determines the effective permissions.

IAM: Identity and Access Management: the rules that decide who can reach which cloud resources and with what permissions.

PAT: Personal Access Token: an API credential tied to one named user rather than a durable organisation role.

FTS: Full-text search index: a derived index that makes message text searchable without changing the source snapshot.

Mutation denial: Proof that the active identity cannot create, edit or delete source data or configuration.

Correction-aware collapse: A rule for combining reversals and corrected events without double-counting an order or erasing its final state.

Acceptance owner: The person or team responsible for checking that the requested access or analysis meets its stated contract.

Data room: The named source or system moving through the shared onboarding protocol.

Connection: Shows whether the accepted path is live and repeatable, partial, a frozen snapshot, unavailable or still unverified. It is not a quality rating.

Register: Records what the room is, why it matters, its doorway, owner role and privacy tier.

Data read: Proves that the declared path returns useful source data. It says nothing about write permissions.

Write protection: Shows separately whether the same identity is prevented from mutating or administering the source.

Inventory: Measures reachable objects, fields, history, pagination, denominators and gaps.

Commission: Accepts one named use under a bounded decision contract.

Maintain: Continuously keeps ownership, refresh cadence, credential rotation and revocation, change detection and re-acceptance working.

Current gate: The gate controlling the next accepted action for this room.

Passed: The contract is met only for this gate and its named scope.

Active: Kairos is executing this gate now.

Waiting owner: The next required action is with a named external owner or owner role.

Blocked: The gate contract is unmet and no accepted continuation can run.

Not started: This gate is unopened, not failed.

Reopened: A material change or failure invalidated earlier acceptance; this gate must pass again.

Unproven: No write capability has been exercised, but source-side prevention or an accepted compensating control has not been proved. Reads may continue; this safety gate has not passed.

Overprivileged: The current identity is proved able to change the source. Non-mutating mapping may continue, but this safety gate cannot pass until the identity is narrowed or isolated.

Live interactive: The connection can request current source data again on demand. This does not by itself prove complete coverage or write protection.

Partial interactive: A live source path works, but it does not reach the accepted intended perimeter.

Static snapshot: The accepted data is frozen at a stated cut-off. Later source changes are absent until a new snapshot or live connector is accepted.

No useful read: The attempted path does not currently return accepted useful source data.

Unverified: No accepted source connection contract has been demonstrated yet.