ELMERANG

Clear boundaries.

Source-inspected communication inventory. Example route shapes only: no secrets, live payloads or personal records. Current local/device authentication is not an internet deployment approval.

Device and dashboard API

RouteDataPermission
GET /api/inboxRecording names, queue states, processing statusread recordings
GET /api/transcript/{sha256}Transcript text, segments, duration and model metadataread transcripts
PUT /api/audio/{sha256}Audio bytes; base64 recording name; SHA-256upload recording
GET /api/contextWorkouts, calendar/activity locations, people context and document linksread private context
PUT /api/captures/{uuid}Versioned workout sessions, notes, activity completion and orderstore capture
GET /api/assistantConfigured routes, command messages, replies and delivery statusread commands
PUT /api/assistant/{uuid}Text, timestamp; explicit targets or workflow ID + revisionqueue explicit command
GET /api/decisionsReview cards, obligations and availability stateread decisions
PUT /api/decisions/{uuid}Action, reviewed revision and action-specific approval fieldsdecide exact action
PUT /api/decisions/busyAvailability action payloadchange availability
GET /api/updateRelease version, hash, size and availabilityread release
GET /api/update/{sha256}Signed Android APKdownload release
PUT /api/diagnostics/{uuid}Version, timestamp, health counters, event codes; optional user-entered problem notesubmit diagnostics
GET /api/dashboardService status, recent runs, email subjects, decisions and usagelocal dashboard read
GET /api/trace?id={trace}&after={sequence}Redacted ordered audit payloads; 200-entry pageslocal trace read

Communication boundaries

Android → Sheath

TLS with certificate pin + hostname validation

Routes listed above; large audio/APK traffic requires Wi-Fi

Remaining boundary: Shared embedded credential; device enrollment/revocation/scoped tokens still required before additional installs

Local browser → Sheath dashboard / inbox

Loopback HTTP 8769 / 8766 with Host allowlist + token for APIs

Dashboard/trace; legacy inbox also exposes GET context/inbox/transcript

Remaining boundary: Not internet-ready; remote gateway and session authorization pending

Sheath email workers → Outlook Graph / Gmail API

Provider HTTPS + PC-owned OAuth credentials

Selected message/thread content, draft creation and separately approved sends

Remaining boundary: Scope review and credential provisioning needed on each new host

Sheath inference adapter → Authenticated Codex CLI / configured provider

Local subprocess; provider communication via CLI

Scoped thread/evidence, voice instructions, schema and draft candidate

Remaining boundary: Only current CLI adapter implemented; local inference and cloud egress policy adapter needed

Android navigation / resource tap → Selected map app / HTTPS resource

Explicit user action through Android intents

Destination/address or resource link

Remaining boundary: Physical mapping and third-party permissions remain separate from synthetic tests

Remote browser → Vercel portal → proposed Access gateway → PC

Planned HTTPS with owner session and outbound tunnel

Public marketing; private dashboard only behind gateway

Remaining boundary: Not deployed/validated; no shared PC credential in public JavaScript

Future PC2 / agents → Sheath queues and inference hosts

Planned authenticated encrypted worker connections

Scoped job context, results and receipts

Remaining boundary: Temporal/PostgreSQL and per-worker identity not implemented

Back to validation