Version. 0.1 · Date. 2026-08-08 · Author. Claude.ai (drafting) / Marvin Percival (approving).
Target. /Users/dunin7/loomworks, branch main.
Baseline. Surface c5919b4, engine ae58d34. CC confirms both at Step 0.
Companion to. completion-records/loomworks-cr-2026-188-b47-halted-with-findings-v0_1.md — CR-2026-188 halted at Step 1 because it described adding controls to a list that does not exist. This CR replaces it. Supersedes CR-2026-188 in intent; that CR stays filed as halted.
Charter. Autonomous regime. Status. Ready for CC execution.
The engine pathway is complete and has never had a screen. This CR builds one.
What is settled and not reopened:
ROOMS and thereby assert that credentials are a room.What the precedent does not settle, and this CR must: SeedViewer only reads. This panel acts — it issues and revokes write access. Issue and revoke need their own care and must not inherit SeedViewer's weight.
Sourced from CR-2026-188's Step 1 report and cited as such rather than restated as fact. CC verifies each against the code:
POST /engagements/{eid}/contribution-credentials (201), GET the same path, POST …/{cid}/revoke. All Operator-only via _require_operator.IssuedContributionCredentialResponse extends the list shape with claim_token and claim_url; the list model has neither. One-time reveal is enforced at the response-model boundary, not by UI convention.recipient_label (optional) and expires_at (required).Not established and Step 1 must report: what fields the list response actually carries (label, issued-at, expiry, revoked state, claimed state?), and whether a revoked or expired credential is distinguishable from an active one in that response. The list cannot show a state the wire does not carry — if it can't distinguish, report it rather than inventing a display.
Opened from a header control on the engagement surface. Renders below the header in the main column, per precedent.
The header control's wording carries weight. It sits beside "view seed," a passive action. Whatever it says should make clear that what lies behind it grants access — not "Credentials" alone if that reads as a settings shelf. CC proposes wording and states its reasoning; strings live in strings.ts per the brand-strings discipline.
What exists, per §2's findings. Plain terms throughout. Only-show-what-is-available: no disabled rows, no greyed controls. A revoked credential either shows as revoked or does not appear — CC decides from what the wire carries and states which.
Form: recipient label (optional), expiry (required, dated field, sensible default the Operator can change).
The form states what it is about to grant — unmoderated write access to this engagement's Memory — in plain terms, before submission, not after. The person should not have to infer the stakes from the word "credential."
Shown once. Copy-to-clipboard. No path back — not by reload, navigation, browser history, or the list.
Never logged. Never in a URL or query string. Never persisted client-side — not in local storage, session storage, or a cache the issuance response could be re-read from.
The screen says plainly that this is the only showing.
On the list. Confirmation before it fires — revoking is not recoverable and should not be one click from a row.
Issuance and revocation are Operator acts. Nothing here transitions automatically.
B-69 applies. Credentials are engagement-scoped; if issuance, the claim link, or revocation reads or derives from seed state, record the contact point with its Kind label. Likely Kind C — record it as one if so.
| Step | What | Mode |
|---|---|---|
| 0 | Pre-flight. | Auto |
| 1 | Verify §2 and report the list response's actual fields. Halt if an engine change is needed. | Auto, conditional halt |
| 2 | Panel shell + header control + tests. | Auto |
| 3 | List + tests. | Auto |
| 4 | Issuance form + tests. | Auto |
| 5 | Reveal + tests, including §3.4's no-path-back assertions. | Auto |
| 6 | Revoke + confirmation + tests. | Auto |
| 7 | Surface sweep — lint, tsc, build, vitest. | Auto |
| A | Checkpoint. | Checkpoint |
| 8 | Tag cr-2026-193-b47-credential-surface. Push. | Auto |
Execute CR-2026-193 v0.1 at ~/Downloads/cr-2026-193-loomworks-b47-
credential-surface-v0_1.md. Confirm the CR number against the ledger
first.
This replaces CR-2026-188, which halted because it described adding
controls to a credentials list that does not exist. Placement is now
settled from your own survey: a header-opened panel following the
SeedViewer / VoiceListeningPanel precedent. Don't reopen it.
The thing the precedent does NOT settle: SeedViewer only reads. This
panel acts — it issues and revokes write access. Don't let the issue
and revoke affordances inherit SeedViewer's weight.
Step 1 verifies the three routes and the response models against the
code rather than trusting my §2, which is sourced from your own earlier
report. What's genuinely unknown: what fields the list response carries,
and whether a revoked or expired credential is distinguishable from an
active one. The list cannot show a state the wire doesn't carry — if it
can't distinguish, report it, don't invent a display.
HALT if the surface can't do its job without an engine change.
Gate item 3 is the one that won't surface in ordinary testing: verify
explicitly that the token reaches no log, no URL, no query string, and
no client-side store — including that the issuance response isn't
cached anywhere it could be re-read. Check it rather than assume it.
§3.1: propose the header control's wording and state your reasoning. It
sits beside "view seed," which is passive; this one grants access.
Note migration 0103 is now applied to playground_dev, so these routes
are live there.
DUNIN7 — Done In Seven LLC — Miami, Florida CR-2026-193 — B-47 credential surface — v0.1 — 2026-08-08