Appearance
Service Audit Findings
This file records sub-agent findings that have been triaged into service task packs. It is not a replacement for the task packs; it preserves evidence and priority context for later agents.
2026-07-09 Spawn Packet And IAM/Profile Continuation Audit
Source: explorers Hegel (019f4662-1472-75a3-b893-5dfb854eabcc), Zeno (019f4662-2a36-7b30-adcd-d4cb0934b7a2), and Linnaeus (019f4662-4006-7f30-b8e8-cc265288dc42), 2026-07-09.
Key findings:
- Canonical service rows and per-service task packs cover every service in the pasted HocTapAZ plan, with aliases for school/question/document/import/AI implementation directories and explicit retirement/runtime-adapter rules for
user-serviceandformula-docx-service. - No deployable
auth-serviceboundary was found./api/auth*and/v1/auth*remain compatibility namespaces backed byiam-service. - Dispatch docs and VitePress were already broadly usable, but a ready-to-spawn prompt packet catalog reduces operator mistakes when copying service owner, task pack, writable scope, and first verification into worker prompts.
- A machine-readable service-agent manifest now anchors
SVC-001throughSVC-023so guard scripts can check the human roster, wave board, workflow matrix, task packs, spawn packets, and runtime manifest against the same row set. - IAM/Profile default proof is still pending. Current evidence covers non-default candidate diff/live/browser/rollback paths, but production-like populated target validation with a required migrator run report, same-target UUID validation, promoted-route browser/runtime proof, and rollback proof are still blockers.
Triaged into:
docs/agents/service-agent-spawn-packets.mddocs/agents/service-agent-manifest.jsondocs/agents/service-agent-manifest.mddocs/agents/service-agent-spawn-runbook.mddocs/microservices/index.mddocs/.vitepress/config.tsscripts/test/agent-dispatch-readiness-coverage.shscripts/test/service-task-pack-coverage.sh
2026-07-09 Wave Readiness Refresh
Source: explorers Bohr (019f45df-aeee-7793-9c27-1e2a2aeb8b51), Jason (019f45df-cc3a-7562-a8b3-27654a49d420), Pauli (019f45df-e429-7801-8ce3-c41d8198440e), and Euclid (019f45e0-0479-71d0-b08c-9fdd53f12c69), 2026-07-09.
Verdict:
- Wave 1 through Wave 4 service foundations are present and the documented first verification commands pass for the canonical implementation directories.
- The full service rollout is not complete. The remaining blockers are cutover-grade proof gaps: default-route promotion, live/browser smoke, rollback evidence, runtime/broker subscriber proof, populated-target validation, and route-specific workflow parity.
auth-serviceremains intentionally absent as a service row. Auth, login/session, and access-control work stays routed toiam-service.user-serviceremains deprecated compatibility only. It is quarantine-ready, not removal-ready, until IAM/Profile route and backfill parity plus rollback evidence are complete.
Key findings by wave:
- Wave 1 passed service-local and route-guard checks for
api-gateway,bff-service,iam-service,profile-service,organization-service, andclassroom-service. Remaining blockers are IAM/Profile default cutover, organization membership live proof with real IDs/token, and uneven public-route browser/rollback evidence. - Wave 2 passed service-local checks for course, question, exam, attempt, file, import, formula runtime adapter, and search. Remaining blockers are question write editor save/reload live/browser proof, mostly static public-route readiness for learning/import/search routes, PDF/OCR/MathType runtime proof, formula corpus parity, and search freshness/event proof.
- Wave 3 passed service-local checks for AI and monetization services plus the current static/self-test monetization guards. Remaining blockers are broker subscribers for wallet/usage, replay/dead-letter tooling, live broker smoke, payment/billing/wallet/usage public route parity, and AI provider/runtime completion beyond hermetic self-tests.
- Wave 4 passed service-local checks for notification, audit, analytics, and admin plus current route guards. Remaining blockers are default route promotion for admin/notifications/alerts/analytics, audit producer/backfill runtime proof, and user-service retirement removal criteria.
Commands reported by the wave agents include:
make test-service-readinessmake test-runtime-foundationGOTOOLCHAIN=go1.25.11 go test ./services/<service>/...make test-auth-routes test-profile-routes test-profile-kyc-routes test-profile-admin-kyc-routesmake test-organization-routes test-classroom-route-guard test-bff-routesmake test-student-course-routes test-student-course-progress-routesmake test-question-read-routes test-question-types-routes test-question-classification-apply-routesmake test-question-write-routesQUESTION_WRITE_SELF_TEST=1 make test-question-write-liveQUESTION_WRITE_BROWSER_SELF_TEST=1 make test-question-write-browsermake test-exam-authoring-routes test-attempt-routesmake test-import-create-routes test-import-status-routes test-import-approval-routes test-import-review-roundtrip-routesmake test-monetization-event-chain test-monetization-routes test-monetization-broker-transportmake test-notification-routes test-parent-alert-routes test-audit-admin-compat-routesmake test-analytics-routes test-feature-maintenance-routes test-admin-audit-routes
Triaged into:
docs/agents/service-agent-wave-board.mddocs/agents/service-workflow-test-matrix.mddocs/agents/service-agent-spawn-runbook.mddocs/agents/service-tasks/iam-profile-default-cutover-proof.mddocs/agents/service-tasks/question-write-parity.mddocs/qa/question-write-route-rehearsals.mddocs/agents/service-tasks/monetization-broker-transport.mddocs/agents/service-tasks/user-service-retirement.mddocs/qa/service-agent-readiness-smoke.md
2026-07-09 Service-Agent Orchestration Audit
Source: explorers Ampere (019f45af-d75a-71d3-aca8-b829a25d35fc), Hume (019f45af-ef72-7443-b968-d7ccc9e969db), and Chandrasekhar (019f45b0-0938-76a0-bbc1-985f48b80b75), 2026-07-09.
Key findings:
- The wave-board prompt could let service agents skip the dispatch roster and workflow test matrix. The prompt and coverage guard now require both files.
classroom-serviceandsearch-serviceneeded delegated route-proof scopes. Their task packs now allow only assigned non-default gateway route examples, focused route tests, QA docs, and Make targets; default route promotion stays orchestrator-owned.api-gatewayownership ofdeploy/gateway/*.jsonwas too broad. The task pack now limits gateway edits to assigned non-default route rehearsal examples unless the orchestrator owns the default-route cutover.formula-docx-serviceremains an external read-only runtime adapter. Coverage now rejects deployable service/API/K8s/VitePress API surfaces unless a later ADR changes that boundary.- AI quota/payment ownership and monetization broker transport proof were documented but under-guarded. The workflow matrix, wave board, and coverage now keep quota checks in
usage-service, credit movement inwallet-service, and broker transport proof in monetization handoffs. - Admin dashboard source maps and source snapshots must name owner-service APIs and must not synthesize owner totals from admin-service storage. The task pack, workflow matrix, wave board, and coverage guard this boundary.
Remaining watch items:
- Course/exam, question, file, and future search route rehearsals still need concrete live/browser proof before any public route promotion.
- Admin route-proof QA docs and monetization broker runtime evidence should stay explicit in each future wave handoff rather than being inferred from static task-pack wording.
Triaged into:
docs/agents/service-agent-dispatch-roster.mddocs/agents/service-agent-wave-board.mddocs/agents/service-workflow-test-matrix.mddocs/agents/service-tasks/api-gateway.mddocs/agents/service-tasks/classroom-service.mddocs/agents/service-tasks/search-service.mdscripts/test/service-task-pack-coverage.sh
2026-07-09 Wave 2 Route-Proof Follow-up
Source: orchestrator follow-up from the 2026-07-09 service-agent orchestration audit.
Key findings:
question-servicealready had live/browser route targets for question types and question reads, but the central workflow docs only required static route guards. The workflow matrix, wave board, task pack, and coverage guard now require those concrete proof targets before public read/type promotion.course-serviceandexam-serviceroute rehearsals are currently static route-table proof only. New QA docs record the required live/browser proof gate so agents cannot treatmake test-student-course-*ormake test-exam-authoring-routesas public promotion evidence.course-servicenow has a named student browser smoke target. Its self-test checks the non-default route table and response contract; live mode requires a running frontend/gateway/course-service plus seeded student token and organization state so/student/coursesemits/api/student/coursestraffic through the gateway.file-servicestorage/media parity proves HTTP byte equivalence, not browser UI rendering. The storage QA page now calls out the separate browser proof gate before any public storage route promotion.
Triaged into:
docs/qa/student-course-route-rehearsals.mdscripts/test/student-course-browser-smoke.shscripts/test/student-course-browser-smoke.mjsdocs/qa/exam-authoring-route-rehearsals.mddocs/qa/storage-media-parity-smoke.mddocs/agents/service-tasks/question-service.mddocs/agents/service-tasks/course-service.mddocs/agents/service-tasks/exam-service.mddocs/agents/service-tasks/file-service.mddocs/agents/service-agent-wave-board.mddocs/agents/service-workflow-test-matrix.mdscripts/test/service-task-pack-coverage.sh
Import / File / AI Audit
Source: explorer Euclid, 2026-07-06.
Key findings:
document-servicecurrently covers storage/media routes only. Full teaching document lifecycle remains a gap.- Object content reads need stronger service-local authorization or signed-read semantics instead of relying only on gateway/header discipline.
- Legacy storage upload checks quota before upload; native file-service needs integration points with future
usage-service/wallet-service. docx-import-servicehas a high-risk approval bug candidate: review saves edited parse JSON, but approval may use the original parser result instead of reviewed output.- Native import is DOCX-heavy; PDF/OCR/MathType conversion routes need explicit task slices or legacy adapters before cutover.
ai-classifier-serviceis foundation-level only: prompts need real question content/taxonomy/current values, public job routes need queue/runtime parity, and provider settings exist in schema before runtime integration is complete.- The approval bug candidate has a baseline fix in this worktree:
approvalQuestionPayloadnow prefersReviewResultandTestApproveJobIntoQuestionBankUsesReviewedParseResultcovers reviewedquestionTypeManualOverridemetadata flowing to question-service.
Triaged into:
docs/agents/service-tasks/file-service.mddocs/agents/service-tasks/import-service.mddocs/agents/service-tasks/formula-docx-service.mddocs/agents/service-tasks/ai-service.md
Identity / Organization / Profile / Classroom Audit
Source: explorer Leibniz, 2026-07-06.
Key findings:
- Frontend auth code is gateway-first; no direct
/v1/*frontend calls were found in the inspected auth client. - Default gateway keeps
/api/auth,/api/organizations, and/api/classroomslegacy-proxied; native route tables are rehearsal-only. - High-risk boundary issue: IAM and school-service both have organization membership storage/APIs, which can split access-control truth from tenant validation.
- IAM invite create/accept/revoke is now implemented with security-event capture and Postgres-backed integration coverage.
- Profile-service matches the education profile boundary. A non-default profile gateway rehearsal now covers current-user profile PATCH routes while default
/api/authrouting stays legacy. - Classroom-service is still a class/member foundation; lessons/materials/ tuition/announcements/exams remain legacy.
Triaged into:
docs/agents/service-tasks/iam-service.mddocs/agents/service-tasks/organization-service.mddocs/agents/service-tasks/iam-org-membership-canonical.mddocs/agents/service-tasks/iam-invites.mddocs/agents/service-tasks/profile-gateway-adapter.mddocs/agents/service-tasks/classroom-public-adapter-preflight.md
Monetization / Operations Audit
Source: explorer Ohm, 2026-07-06.
Key findings:
admin-service,notification-service, andanalytics-servicehave Phase 9 foundations, but default gateway routes still keep admin/notification/alerts/ analytics plus wallet/hooks legacy-proxied.payment-service,wallet-service,billing-service, andusage-servicenow have native foundation scaffolds.search-servicenow has a rebuildable index foundation for question/exam/course/document copies.audit-servicenow has an internal append-only compliance/security ledger foundation.bff-servicenow has a no-primary-DB screen aggregation foundation for admin/teacher dashboard and operations shells plus frontend route metadata.- Monetization is the largest missing service group. Wallet/AZ Credit and SePay/webhook behavior must remain legacy until payment/wallet/billing/usage foundations exist and replay/parity tests pass. The first payment slice covers payment-order and webhook idempotency only; the first wallet slice covers immutable ledger idempotency only; the first billing slice covers plan, subscription, invoice, and entitlement idempotency only; the first usage slice covers entitlement snapshots, quota counters, limit overrides, and check/consume/reset idempotency only. Subscription credit grants and wallet debits still stay outside usage-service.
usage-serviceis the canonical service name;entitlement-serviceshould be treated as a planning alias unless a separate rename decision is made.audit-serviceis a native event sink only; public admin audit still lives inadmin-serviceuntil compatibility/backfill and gateway route evidence exist.bff-serviceis screen aggregation only; it must not hide domain writes or replace owner services.search-serviceis rebuildable index storage only; question/exam/course/ document owner services remain source of truth and public routes stay gateway-controlled until parity evidence exists.
Triaged into:
docs/agents/service-tasks/billing-service.mddocs/agents/service-tasks/wallet-service.mddocs/agents/service-tasks/usage-service.mddocs/agents/service-tasks/payment-service.mddocs/agents/service-tasks/entitlement-service.mddocs/agents/service-tasks/bff-service.mddocs/agents/service-tasks/monetization-scaffold-wave.md
Learning / Question / Exam / Attempt Audit
Source: explorer Kant, 2026-07-06.
Key findings:
- Core service boundaries broadly match the target spec: course owns course/ lesson/material/progress references, question-service owns canonical question rows/types/taxonomy read models, exam owns authoring/publish snapshots, and attempt owns copied attempt snapshots/answers/events.
- Main gap is public workflow readiness. Many public route groups remain legacy or non-default rehearsal only.
- Highest-risk cutover is attempt start: native attempt start needs hydrated exam runtime snapshot and assignment/link/password/open-window decision before
/api/exams/:examId/startcan safely route native. - Question read parity exists, including compatibility projections, but rich create/update/delete/version/folder/group write parity remains pending.
- Exam-service now has native assignment, result-release, and runtime access-decision foundations; it still needs full folders, sections, share-link CRUD, export, blueprint/generation, public teacher scope parity, and route-promotion proof.
- Course-service now has usecase hardening for manager/student/public workflows and material visibility tied to attached lesson visibility; deferred question/quiz/mastery/recommendation/report/purchase/file-streaming slices remain.
- Attempt-service has native student attempt list coverage; it still needs result-release propagation for already-started attempts plus more parent/teacher access/result visibility route-promotion proof.
Triaged into:
docs/agents/service-tasks/question-service.mddocs/agents/service-tasks/question-write-parity.mddocs/agents/service-tasks/exam-service.mddocs/agents/service-tasks/exam-runtime-access.mddocs/agents/service-tasks/course-service.mddocs/agents/service-tasks/course-workflow-hardening.mddocs/agents/service-tasks/attempt-service.mddocs/agents/service-tasks/attempt-public-surfaces.mddocs/agents/service-tasks/learning-public-gateway-cutover.md