Extend Workspace Context
Immutable Context, scoped evidence, approved edits, and background enrichment.
Company creation requires a name, website, timezone, and currency and produces an active workspace and ordinary chat. The browser offers an optional integration step before opening that chat; ordinary work is available from the sidebar throughout. Integrations, public research, department discovery, and Context review do not gate work. PostgreSQL commits all five profiles, three departments, initial schedules, research tasks, chat, and the initial Context pointer together. See Background company research.
Immutable structured Context
Each publication contains a complete manifest of twelve structured files: organization and three
department facts.toml, preferences.toml, and workflows.toml. The manifest records content hashes,
field origins, supporting claims, and processing receipts. Files and manifests use immutable keys;
the system/fact-evidence-ledger PostgreSQL row selects the current revision. Missing or corrupt
publications fail explicitly. There is no mutable structured-file fallback.
All writers read a revision, validate the change, upload immutable bytes outside transactions, and compare-and-swap the pointer in a short transaction. Research processing receipts commit with that pointer. Competing publishers rebase on the winner. Approved edits merge the actual changed fields and preserve concurrent unrelated enrichment; a changed field with conflicting edits requires a new review. Every reader pins one publication, including runtime hydration, Context APIs, and audits. Append-only memory notes retain their existing handling.
Defaults have versioned operating_default provenance. Submitted company details have setup_input
provenance. Owner edits have human_edit provenance, including intentional clearing. Research may
fill only explicitly enrichment-eligible unknown facts. Zero, false, and empty collections are known
values. Research never changes authority, settings, budgets, priorities, resource selections, or
workflows. Conflicts retain reviewable claims; conflicting research-owned values become disputed.
Evidence and source formats
Preserve original bytes and typed source manifests. Validate identity, tenant, scope, hash, size,
UTF-8, retained publisher URLs, and any derived artifacts. Treat documents as untrusted data. A
source-bound URL uses https://publisher.example/article#source=<UUID>; source:<UUID> is also
supported. These integrity checks establish provenance. They do not establish semantic credibility.
Human decisions establish declarations rather than independent validation.
Add formats through bounded, deterministic extraction without executing embedded content. Reject unsafe paths, symlinks, oversized files, and malformed input. Update the upload UI and reference alongside acceptance changes. Source browsing returns readable sources plus source-specific issues, so one damaged unrelated source does not hide the rest. Explicitly cited missing or corrupt evidence blocks its dependent operation.
Approved changes and audits
contextctl verify is a local, read-only validator. Authenticated publication belongs to the backend.
Agents stage complete changed documents, validate them, obtain approval over the diff through Human
Inbox, and invoke oblivectl context revision promote. Chat can add reviewed memory notes through
oblivectl context promote. Operational questions arise only when a task needs the answer.
Integration purpose, usage, policy, and working resources remain revisioned PostgreSQL state. Credentials, permissions, and readiness are backend-owned. Integration reconciliation reads only its affected registry records and relevant Context; full audits may inspect the full authorized inventory. Both are ordinary bounded tasks. Health assessments describe known gaps without blocking unrelated company work.
Company identity, timezone, and currency changes use the company-details API; structured Context revision promotion rejects changes to these operational fields. A website host change through that API advances the identity generation, removes only unchanged research-owned facts from the old identity, and schedules both research passes. Name and same-host URL changes preserve research. Owner edits and operating settings survive domain changes.
The first full Context audit creates the health assessment directly from validated current files, sources and the safe integration snapshot; it does not require a legacy onboarding review. Publication atomically fences an absent prior revision, so two first audits cannot overwrite each other. Existing reports still require their original bytes and hash. Before publication, the Health view shows the actual review status or next scheduled review and links directly to the task. Missing assessment history never implies that business Context is missing.
Full audits are Operator work. Their backend-generated context/health-sources.json inventory
includes every canonical uploaded and retained source, including uncited sources. Available ingested
content is hydrated under onboarding/sources/ or onboarding/evidence/. Stored, failed, missing or
corrupt content remains visible in the inventory as an assessment limitation; it does not prevent
the audit from reporting gaps. Ordinary work still hydrates only cited evidence and preserves its
strict integrity and department-scope checks. Publication validates the complete current source set,
so a concurrent source change cannot silently produce an incomplete assessment.
Changed file or source inventories retry through the existing request-attempt and aggregate-run
budgets. Historical attempts and consumed credits are retained.