WORKSPACE-GLOBAL
Resources
Canonical resource inventory. Campaign membership is configured separately.
Authorization and runtime eligibility are separate. Server state is canonical.
| Identity | Name | Authorization | Global runtime | Proxy | Metadata |
|---|---|---|---|---|---|
| Set a workspace ID and refresh. | |||||
New campaign context
New campaign: Prepare campaign first (DRAFT → STARTING), then explicitly Run (STARTING → RUNNING). Prepare does not start collection or sending.
To stop: Stop blocks new campaign work (RUNNING or PAUSED → STOPPING); then explicitly Finish stop (STOPPING → STOPPED). Already in-flight external operations may finish.
Campaign send budget
Workspace, account and actor safety limits remain mandatory.
Assign accounts and sources
Membership changes are explicit and audited.
This declares the selected channel Source ID and discussion source only. Telegram must confirm the pair; reading and sending still need separate access and policy checks.
Controls are fail-closed server decisions; stale snapshots return conflict and reload.
| Job | Action | State | Account | Blocker / next | Controls |
|---|---|---|---|---|---|
| Select a campaign. | |||||
—
| Review | Stage | State | Run | Created | |
|---|---|---|---|---|---|
| Select a campaign and load reviews. | |||||
Provision versioned LLM pipeline
LIMITED_AUTO / AUTO do not require approval of every comment. A genuine human session, signed rollout/readiness and runtime safety gates are still required. Selecting AUTO is not proof of production readiness and does not start the campaign.
Configured policy has not been read. No production-readiness claim.
No pipeline changes yet.
SHADOW only, PUBLIC request scope, LLM enabled. The server still enforces actual context privacy and provider egress authorization. No automatic retry; a lost response can mean the run already exists. Inspect recent decisions before any further action.
No SHADOW run requested.
| Run | Decision | State | AUTO authorization / reason | Action job | Created |
|---|---|---|---|---|---|
| Read decisions explicitly; no background polling. | |||||
—
Reads one explicitly selected identity. Does not send, join, grant source access or approve a campaign. The account must be enabled and not owned by a live worker.
For linked discussion: first resolve the registered channel, then use its source UUID and returned negative peer ID. This reads channel metadata only; configure the returned group pair separately under Campaign sources. NOT_JOINED does not mean comments are inaccessible.
No identity lookup performed.
—
—
—
—
—
Choose the label and expected action yourself from reviewed evidence. Model output is not a human label. Nothing is saved until you explicitly click Save.
—
—