{ "schema": "runx.incident_commander.evidence.v1", "summary": "Published and dogfooded incident-commander as a reusable RunX governance workflow, then drove it through the shipped agency runner over a declared SEV-2 incident. The committed raw runtime records show the event-stream read and fold, immutable registry member execution, member receipt feedback, and CAS append at the folded version.", "skill": { "owner": "mossony", "name": "incident-commander", "version": "sha-f94caa7b3588", "registry_ref": "mossony/incident-commander@sha-f94caa7b3588", "digest": "e1a9dcb860ecea3d1d7c759366eb5c0abb95f7e6ce92c0056dd110aae0ff5365", "profile_digest": "c3c2c5f140a65033f41834ebe71324e3ba57b8c97797e06413367d2cebd57bc7", "publisher_owner": "mossony", "public_url": "https://runx.ai/x/mossony/incident-commander@sha-f94caa7b3588", "pr_url": "https://github.com/runxhq/runx/pull/347", "source_url": "https://github.com/runxhq/runx/pull/347/files", "x_yaml": "https://raw.githubusercontent.com/runxhq/runx/refs/pull/347/head/skills/incident-commander/X.yaml", "skill_md": "https://raw.githubusercontent.com/runxhq/runx/refs/pull/347/head/skills/incident-commander/SKILL.md" }, "toolchain": { "runx_version_command": "runx --version", "runx_version_output": "runx-cli 0.7.1", "publish_method": "runx login --provider github --for publish --from-gh; runx registry publish ./skills/incident-commander/SKILL.md --registry https://api.runx.ai", "install_command": "runx add mossony/incident-commander@sha-f94caa7b3588 --registry https://api.runx.ai --json", "registry_read_command": "runx registry read mossony/incident-commander@sha-f94caa7b3588 --registry https://api.runx.ai --json", "local_harness_command": "runx harness ./skills/incident-commander -R ../runx-evidence/local-harness --json" }, "harness": { "local_status": "passed", "hosted_status": "green", "hosted_cases_passed": 2, "hosted_cases_total": 2, "hosted_receipt_ref": "runx:receipt:sha256:f88f55b5b502bcaa50ed9177c1a7bf463de7142b37a4dbef53cd3d1f16928a12", "cases": [ { "name": "status-update-awaits-then-roster-approval-advances", "status": "sealed", "observed": "The first phase remained awaiting_approval with a non-executable send-as plan bound to stakeholders:checkout-api and sha256:4e44f31f628799267f0957c554b8c47d90d2eabf41e5a84248941d28c45955ae. The follow-up used approval principal incident:comms:morgan and advanced the turn." }, { "name": "assign-without-named-roster-owner-needs-agent", "status": "needs_agent", "observed": "The ops-desk sub-step blocked without caller.answers; no named run was returned." } ] }, "dogfood": { "package": "mossony/incident-commander@sha-f94caa7b3588", "input": { "case_id": "incident-112-mossony-20260718", "incident_objective": "send", "incident_severity": "SEV-2", "incident_scope": "checkout-api", "approval_principal": "incident:comms:morgan", "named_comms_run": { "skill": "send-as", "runner": "plan", "channel": "email", "audience": { "list_ref": "stakeholders:checkout-api", "classification": "incident-stakeholders" }, "content_digest": "sha256:4e44f31f628799267f0957c554b8c47d90d2eabf41e5a84248941d28c45955ae" } }, "command": "runx skill mossony/incident-commander@sha-f94caa7b3588 advance --registry https://api.runx.ai -R evidence/frantic-112-incident-commander/receipts --json", "receipt_ref": "runx:receipt:sha256:bf3149287c60d6562e3d55d36e3c4bff296c7a3b9dafcc1bb3ba70c01e274353", "raw_receipt": "https://raw.githubusercontent.com/runxhq/runx/refs/pull/347/head/evidence/frantic-112-incident-commander/receipts/sha256-bf3149287c60d6562e3d55d36e3c4bff296c7a3b9dafcc1bb3ba70c01e274353.json", "raw_graph_state": "https://raw.githubusercontent.com/runxhq/runx/refs/pull/347/head/evidence/frantic-112-incident-commander/receipts/runs/run_advance_057142a05ffd.graph-state.json", "verify_command": "RUNX_RECEIPT_VERIFY_KID=mossony-frantic-112-20260718 RUNX_RECEIPT_VERIFY_ED25519_PUBLIC_KEY_BASE64=UlNOg2tuiyOkDf6A2Dd/H0V30n5Z0cdqp4+fwiElocU= runx verify --receipt evidence/frantic-112-incident-commander/receipts/sha256-bf3149287c60d6562e3d55d36e3c4bff296c7a3b9dafcc1bb3ba70c01e274353.json --json", "verify_verdict": { "valid": true, "status": "valid", "signature_mode": "production", "kid": "mossony-frantic-112-20260718", "findings": [] }, "tree_verify_verdict": { "valid": true, "receipt_count": 5, "parent_missing": null, "findings": [] }, "harness_cases": [ { "name": "status-update-awaits-then-roster-approval-advances", "status": "sealed" }, { "name": "assign-without-named-roster-owner-needs-agent", "status": "needs_agent" } ] }, "agency_spine": { "case_id": "incident-112-mossony-20260718", "data_source_ref": "tenant://agency/frantic-112", "provider": "sqlite-event-store", "open_receipt_ref": "runx:receipt:sha256:81f7210034ae42fd05bc61c4db806b3455454d30cdce1db6049fa56f2fd98b8b", "dispatch_receipt_ref": "runx:receipt:sha256:6f893a84f25511c01b8d9c612341666d52501a9f810f31c366bfd50f2938f6f4", "member_receipt_ref": "runx:receipt:sha256:bf3149287c60d6562e3d55d36e3c4bff296c7a3b9dafcc1bb3ba70c01e274353", "bind_receipt_ref": "runx:receipt:sha256:fc683f33c30cca0e194808ade4e201897cbfa04fff2a5ea8b7fa476de3990db2", "bind_tree_verify_verdict": { "valid": true, "signature_mode": "production", "receipt_count": 6, "parent_missing": null, "findings": [] }, "read_events": { "versions": [1, 2], "after_version": 2, "result_digest": "sha256:b9b5bf8c239b9f37f6fc53f1bd0ae6b8162ccef841d42695b3b678b1fe541ed1" }, "fold": { "expected_version": 2, "turn_no": 1, "member_outcome": "advanced" }, "append_event": { "status": "committed", "before_version": 2, "after_version": 3, "idempotency_key": "incident-112-mossony-20260718:turn:2:agency-bind-member-receipt", "event_ref": "agency_cases:incident-112-mossony-20260718:3", "event_digest": "sha256:45d1be3548ccd87833b60cff43a76511fa8cf6aad58b668383a4cbf4aa4f7b16" }, "embedded_member_receipt_ref": "runx:receipt:sha256:bf3149287c60d6562e3d55d36e3c4bff296c7a3b9dafcc1bb3ba70c01e274353", "raw_bind_graph_state": "https://raw.githubusercontent.com/runxhq/runx/refs/pull/347/head/evidence/frantic-112-incident-commander/receipts/runs/run_advance_838254eeead6.graph-state.json", "raw_bind_root_receipt": "https://raw.githubusercontent.com/runxhq/runx/refs/pull/347/head/evidence/frantic-112-incident-commander/receipts/sha256-fc683f33c30cca0e194808ade4e201897cbfa04fff2a5ea8b7fa476de3990db2.json", "raw_receipt_index": "https://raw.githubusercontent.com/runxhq/runx/refs/pull/347/head/evidence/frantic-112-incident-commander/receipts/index.json", "verification_key": "https://raw.githubusercontent.com/runxhq/runx/refs/pull/347/head/evidence/frantic-112-incident-commander/verification-key.json" }, "observations": [ "runx --version returned exactly runx-cli 0.7.1. The publish, clean install, registry read, dogfood, and verify commands used that binary, satisfying the runx-cli 0.6.14 minimum.", "The authenticated publisher owner is mossony; the exact immutable package is mossony/incident-commander@sha-f94caa7b3588 with digest e1a9dcb860ecea3d1d7c759366eb5c0abb95f7e6ce92c0056dd110aae0ff5365 and profile digest c3c2c5f140a65033f41834ebe71324e3ba57b8c97797e06413367d2cebd57bc7.", "The canonical public URL is https://runx.ai/x/mossony/incident-commander@sha-f94caa7b3588; the public PR is https://github.com/runxhq/runx/pull/347; source_url is its public files view; raw x_yaml and skill_md are bound to the PR head under skills/incident-commander.", "The local harness passed status-update-awaits-then-roster-approval-advances and assign-without-named-roster-owner-needs-agent. The hosted registry harness is green at 2/2 and links sealed harness receipt sha256:f88f55b5b502bcaa50ed9177c1a7bf463de7142b37a4dbef53cd3d1f16928a12.", "The happy turn first stayed awaiting_approval, then matched approval principal incident:comms:morgan and named send-as plan for audience stakeholders:checkout-api with content_digest sha256:4e44f31f628799267f0957c554b8c47d90d2eabf41e5a84248941d28c45955ae. It did not claim that a provider send occurred.", "The stop case omitted caller.answers for an assignment with no named roster owner. It returned needs_agent with no named run; this is the refused or escalated reason required by the contract.", "The real dogfood incident was declared SEV-2 for checkout-api. Running the published registry package produced post-publish receipt sha256:bf3149287c60d6562e3d55d36e3c4bff296c7a3b9dafcc1bb3ba70c01e274353, which verifies valid in production signature mode.", "The shipped agency runner opened the case, read_events over versions 1 and 2, folded expected_version 2, and committed append_event from before_version 2 to after_version 3 using idempotency key incident-112-mossony-20260718:turn:2:agency-bind-member-receipt.", "The agency bind run graph input and persisted turn event both embed member_result.receipt_ref runx:receipt:sha256:bf3149287c60d6562e3d55d36e3c4bff296c7a3b9dafcc1bb3ba70c01e274353. The outer agency receipt tree rooted at sha256:fc683f33c30cca0e194808ade4e201897cbfa04fff2a5ea8b7fa476de3990db2 verifies valid across six production-signed receipts.", "A new user can install with runx add mossony/incident-commander@sha-f94caa7b3588 --registry https://api.runx.ai, run the immutable package with runx skill mossony/incident-commander@sha-f94caa7b3588 --registry https://api.runx.ai, and verify the raw receipt using the public Ed25519 key in verification-key.json without private context.", "Machine-readable verification is in verification.json; the human report is report.md. Both point to the same immutable registry version, PR, raw receipt set, and public verification key." ], "credential_hygiene": { "tokens_in_artifacts": false, "email_addresses_in_artifacts": false, "signing_seed_persisted": false, "public_verification_key_only": true }, "value_assessment": { "real_operator_value": true, "summary": "The package gives an incident operator a fixed-roster, approval-bound decision turn while leaving durable contention to the shipped agency CAS lease and provider delivery to separately governed communication skills." } }