Experiential Labs review integration handoff
CO PR: ContextualWisdomLab/contextual-orchestrator#1145
User credential: EXPERIENTAL_LABS_API_KEY (exact registered spelling).
Read-only local central snapshot: ContextualWisdomLab/.github at
58e63c2. Current remote contents could not be
verified: REST returned HTTP403 rate limit on 2026-09-12T14:18:40Z,
request B7CA:74260:577857:7DD2DD:6AA55F40. Do not present this snapshot as current.
Observed integration boundaries:
- .github/workflows/noema-review.yml transports five provider secrets into
contextual_orchestrator_review_sidecar.sh, but not the new optional key.
- sidecar.sh checks the same five-name bootstrap list before launch.
- contextual_orchestrator_review_policy.py rejects unknown provider names
before source-identity and free/ZDR admission; its duplicated registry must
consume the canonical CO contract or receive a coordinated minimal update.
- The explicit ZDR policy table must not invent an Experiential attestation.
Official catalog retention is not enforcement; organization require-ZDR
policy and applicable no-training/retention evidence remain unverified.
- Pricing schema of authenticated /v1/models is incompletely documented.
CO retains unknown cost rather than considering BYOK, credits or allowance
free. No paid inference was authorized or performed.
Owner next action: revalidate latest central head and active writer scope after
API reset, link to the existing integration issue or create one if none exists,
then coordinate secret transport and canonical readiness contract adoption.
The consumer stays gateway-token + orchestrator/free. Do not rerun the failed
consumer and claim repair before the adopted provider can pass actual free/ZDR
admission. Local contract tests are not live organization policy proof.
Run34696894945 evidence only identifies Bytez HTTP500 followed by PolicyError;
that ordering does not establish Bytez as the sole cause of policy failure.
Reproduction and acceptance
Executed the actual parse_discovery_report function from the read-only local
snapshot with an Experiential row carrying unknown prices and is_free=False.
It raises PolicyError: provider 'experiential_labs' is not registered in the ZDR policy table before candidate admission. No inference or secret access was
involved. This is a confirmed local integration rejection, not proof of the
current hosted source behavior.
Acceptance: accepted provider identity survives report normalization; absent
privacy/price evidence still excludes serving; configured optional Secret reaches
KV; paid routes remain excluded; real organization ZDR policy and catalog prices
are verified before the motivating private-review rerun is called repaired.
Owner: central review/bootstrap maintainers, coordinated with CO PR1145.
Next investigation checkpoint: 2026-09-13, to revalidate the live central source
and identify the delegated integration slice. This next-day checkpoint follows
an active private-review failure and is not a promise of deployment completion.
Experiential Labs review integration handoff
CO PR: ContextualWisdomLab/contextual-orchestrator#1145
User credential: EXPERIENTAL_LABS_API_KEY (exact registered spelling).
Read-only local central snapshot: ContextualWisdomLab/.github at
58e63c2. Current remote contents could not be
verified: REST returned HTTP403 rate limit on 2026-09-12T14:18:40Z,
request B7CA:74260:577857:7DD2DD:6AA55F40. Do not present this snapshot as current.
Observed integration boundaries:
contextual_orchestrator_review_sidecar.sh, but not the new optional key.
before source-identity and free/ZDR admission; its duplicated registry must
consume the canonical CO contract or receive a coordinated minimal update.
Official catalog retention is not enforcement; organization require-ZDR
policy and applicable no-training/retention evidence remain unverified.
CO retains unknown cost rather than considering BYOK, credits or allowance
free. No paid inference was authorized or performed.
Owner next action: revalidate latest central head and active writer scope after
API reset, link to the existing integration issue or create one if none exists,
then coordinate secret transport and canonical readiness contract adoption.
The consumer stays gateway-token + orchestrator/free. Do not rerun the failed
consumer and claim repair before the adopted provider can pass actual free/ZDR
admission. Local contract tests are not live organization policy proof.
Run34696894945 evidence only identifies Bytez HTTP500 followed by PolicyError;
that ordering does not establish Bytez as the sole cause of policy failure.
Reproduction and acceptance
Executed the actual
parse_discovery_reportfunction from the read-only localsnapshot with an Experiential row carrying unknown prices and
is_free=False.It raises
PolicyError: provider 'experiential_labs' is not registered in the ZDR policy tablebefore candidate admission. No inference or secret access wasinvolved. This is a confirmed local integration rejection, not proof of the
current hosted source behavior.
Acceptance: accepted provider identity survives report normalization; absent
privacy/price evidence still excludes serving; configured optional Secret reaches
KV; paid routes remain excluded; real organization ZDR policy and catalog prices
are verified before the motivating private-review rerun is called repaired.
Owner: central review/bootstrap maintainers, coordinated with CO PR1145.
Next investigation checkpoint: 2026-09-13, to revalidate the live central source
and identify the delegated integration slice. This next-day checkpoint follows
an active private-review failure and is not a promise of deployment completion.