Qoil finds what may have gone quiet. Your words decide what is real.
For one configured pilot inbox, Qoil accepts an organization-owner-selected address only after finding it in authenticated source mail, privately surfaces candidates authored from that address, shows a verbatim quote when evidence is available, and lets the owner confirm or dismiss each candidate without a later model update undoing that decision for the same source revision.
A private correction surface, not another place to work.
The scan shows quiet candidates, the available source evidence, when each was due, and two answers. Open candidates collapse to one reassurance count; when nothing is quiet, the page stops.
- Once fully configured, signed source wake-ups and six-hour catch-up runs are consumed by a bounded authenticated scheduler pass; retry, failure, or remaining runnable work turns its pulse red
- With operator provisioning and NANGO_OWNER_CONNECTION_CONTROL=controlled_development, an active owner starts the allowlisted provider authorization from Qoil; a signed matching activation is still required
- The organization-owner-selected address must appear in authenticated source mail and is encrypted per tenant connection
- New openings, cancellations, and revisions from anybody except the confirmed mailbox owner are rejected before persistence; third-party completion evidence remains allowed
- Available source quotes are verbatim, never AI summaries
- Confirm or dismiss each quiet candidate in one tap
- A prompt update or delayed older retry cannot resurrect a dismissed candidate for the same source revision
- Private model processing stays closed unless four separate deployment reviews, the exact tenant, the exact extractor identity, and a fixed unexpired policy all match
“I’ll send the revised proposal by Friday.”
quiet for 4 daysdue Friday
Every fact has a receipt.
“Working pilot build” means the behavior is on the private product path. “Passed in rehearsal” means the mechanism runs end to end against a fixed answer key, but is not being presented as a live customer result.
- 01Working pilot build
The account owner can start the source authorization inside Qoil.
When one reviewed Gmail or Outlook integration is configured in Qoil's explicitly enabled controlled-development mode, an active organization owner can create a short-lived Nango Connect link from settings. Qoil serializes the tenant decision, refuses to replace an ambiguous or separately managed inbox, accepts only an exact https://connect.nango.dev link, and keeps the source pending until a signed activation webhook matches the server-owned binding.
After an operator provisions the reviewed provider integration and explicitly enables the controlled path, the owner starts or resumes authorization without asking an operator to mint and share a link. This is not evidence of a live provider run or production self-service.Inspect the receipt
src/lib/integrations/nango/owner-control.tsActive-owner authority and source state are locked and rechecked in two short tenant transactions around the provider request.src/lib/integrations/nango/owner-control.test.tsThe provider call runs with no tenant transaction open; tests also pin concurrent first-install convergence to one source and binding.src/lib/integrations/nango/http-client.test.tsThe HTTP boundary returns only the allowlisted hosted link and expiry and discards Nango's session token.src/lib/integrations/nango/http-client.test.tsThe HTTP boundary rejects a redirect whose exact origin is not Nango Connect.src/lib/integrations/nango/webhook.test.tsActivation input must pass the current signature check over the exact received bytes.src/lib/integrations/nango/gateway.test.tsA verified activation becomes active only through the durable pending binding and server-issued pseudonymous tags.
- 02Working pilot build
“Your promises” starts with an address the source actually contains.
For one active or degraded email connection, an active organization owner can select an address only when that exact normalized address appears as From in one of the 500 most recent eligible authenticated source records. Qoil encrypts the selected address under organization-and-connection associated data and lets the owner correct it for that connection.
The scan uses a source-observed address selected by the organization owner. It does not claim provider identity, mailbox ownership, or mailbox control, and it does not decide from a global setting, cross-customer lookup, or AI guess.Inspect the receipt
src/lib/kernel/source-events/mailbox-owner.tsOrganization-owner authority, exact tenant connection, authenticated From occurrence, encryption, and correction meet at one deterministic write boundary.src/lib/kernel/source-events/mailbox-owner.test.tsTests exercise tenant collisions, correction scope, no plaintext persistence, key rotation, and deletion.
- 03Working pilot build
A connected source has a bounded, unattended catch-up path.
With the controlled Nango adapter and source-encryption key fully configured, each invocation of Qoil's authenticated scheduler selects at most five due organizations through a fixed content-free database capability, executes at most five source jobs globally, and fetches at most one page of 100 normalized records per claimed job. Signed sync webhooks create durable wake-ups, and a scheduled full reconciliation becomes due every six hours so a missed webhook is not the only recovery path.
The working build does not require an operator to notice a webhook, press Import, or watch a queue for source changes to move. A waiting retry, terminal failure, or unresolved backlog left after the bounded pass makes the scheduler pulse unhealthy. This is repository proof, not evidence that a live Nango Records sync or deployed scheduler has run.Inspect the receipt
src/app/api/webhooks/nango/route.tsAuthenticated Nango ingress durably queues the provider-neutral wake-up instead of doing provider fetch work in the webhook request.src/lib/kernel/source-events/scheduled.test.tsThe executable batch proof schedules, claims, fetches, persists, and completes while the provider fetch holds no tenant transaction open.src/lib/kernel/source-events/jobs.test.tsThe durable queue proof advances from Qoil's checkpoint after a deliberately omitted wake-up and completes a scheduled full pass.src/lib/db/migrations/frozen/2026082103.tsThe pre-tenant selector returns only organization identities for runnable, failed, or stale source work.src/app/api/cron/process/route.tsThe authenticated cron catalog runs the source processor and marks retry, terminal failure, or remaining backlog unhealthy.
- 04Working pilot build
It cannot turn somebody else’s new promise into yours.
For one configured email connection, Qoil requires an owner-confirmed, source-observed address before interpretation. Deterministic code rejects openings, cancellations, and revisions from any other primary sender before persistence; a third party may still provide completion evidence. The private scan independently checks authorship again for legacy or backfilled rows.
A model cannot assign a customer’s or colleague’s promise to you, even if it misreads the message. You review a short list of source-linked candidates scoped to what you wrote.Inspect the receipt
src/lib/kernel/interpretation/source-context.tsInterpretation requires the encrypted owner-confirmed identity for the exact source connection.src/lib/kernel/interpretation/runner.tsDeterministic code drops non-owner openings and keeps only supported completion claims.src/lib/kernel/interpretation/store.tsPersistence rechecks the durable owner-identity version under the connection lock.src/lib/kernel/interpretation/first-scan.tsThe private scan independently rejects a row whose authenticated author is not the confirmed owner.
- 05Working pilot build
When it quotes you, the words are verbatim.
When a quiet card’s authenticated evidence span still resolves, Qoil slices the displayed quote verbatim from the source. If the source or span cannot be authenticated, the card shows no quote instead of inventing one.
A visible quote is source evidence, not an AI rewrite; a missing quote stays visibly missing.Inspect the receipt
src/lib/kernel/interpretation/first-scan.tsThe displayed excerpt is sliced from the authenticated canonical source view.src/lib/kernel/interpretation/first-scan.test.tsTests pin the verbatim-quote and no-invention behavior.
- 06Working pilot build
One tap records what belongs.
The owner can confirm a quiet candidate or dismiss it as not relevant. The decision is bound to the candidate version and source fingerprint; a dismissed candidate stays out of later scans.
Correction is two buttons on the promise itself, not a setup ritual or a second queue to maintain.Inspect the receipt
src/app/(dashboard)/skanning/quiet-promises.tsxEach tap names the exact proposal version and source fingerprint the owner saw.src/lib/rehearsal/first-scan-pipeline.test.tsThe end-to-end owner-tap beat re-derives the scan and verifies dismissal persists.
- 07Working pilot build
A model update cannot bring back what you dismissed.
For one exact source revision and purpose, only one completed interpretation set can reach Qoil's product reads. Before review, the most recently scheduled completed set stands, and an abstention clears older unreviewed candidates. Once an owner or coordinator confirms, dismisses, or corrects any candidate in that set, deterministic code pins the reviewed run, skips later scheduling before source decryption, rejects replacement before model use and persistence, and refuses stale cards and evidence.
You do not have to teach Qoil the same correction after a prompt or model deployment, and a late retry cannot silently put an older answer back.Inspect the receipt
src/lib/kernel/interpretation/standing-run.tsOne centralized projection lets a reviewed run win permanently and otherwise orders completed runs by schedule rather than finish time.src/lib/kernel/interpretation/adjudication.test.tsThe integration test records an ordinary owner decision and proves a changed prompt cannot invoke the extractor or persist another run.src/lib/kernel/interpretation/shadow-ledger.test.tsThe ledger and resolution catalog expose only the newer set, then expose none after a newer abstention.src/lib/kernel/interpretation/jobs.test.tsA delayed older job may finish for audit but cannot regain product standing from a newer scheduled run.src/lib/kernel/interpretation/evidence-preview.test.tsA stale browser card cannot disclose source evidence once another run stands.
- 08Working pilot build
One missing privacy approval closes the model path.
Qoil's concrete restricted-content gate approves only when vendor review, retention, residency, and deletion are each explicitly accepted; the exact organization and exact extractor key, model-bearing version, prompt version, and output schema are allowlisted; and the fixed policy expiry is still in the future. Missing controls, truthy aliases, wildcards, tenant drift, extractor drift, and expiry all deny.
Private source processing cannot be enabled by one vague AI switch or silently spread to another customer or model version. This is an executable deployment gate, not evidence that a production source processor is connected or running.Inspect the receipt
src/lib/kernel/interpretation/deployment-data-use-gate.tsThe production-shaped gate evaluates content-free tenant, grant, extractor, policy, control, and time metadata only.src/lib/kernel/interpretation/deployment-data-use-gate.test.tsThe executable matrix removes each required approval in turn and pins the corresponding denial.src/lib/kernel/interpretation/deployment-data-use-gate.test.tsTests reject permissive shortcuts and non-fixed policy scope.src/lib/kernel/interpretation/jobs.tsThe existing queue contract rechecks the injected deployment decision around restricted work rather than trusting enqueue-time state.
- 09Passed in rehearsal
The guardian interrupts the owner once, never the other person.
The guardian’s current rehearsal sends only to the owner and permits at most one notification claim per newly quiet promise. Replaying the same state produces no second notification.
The intended follow-through is a sparse private interruption, not automated chasing or a notification feed.Inspect the receipt
src/lib/kernel/interpretation/quiet-guardian.tsA derived database key arbitrates concurrent notification claims before email is sent.src/lib/rehearsal/first-scan-pipeline.test.tsThe full guardian beat is run twice and the replay must stay silent.
- 10Working pilot build
The inbox permission has a clock and an off switch.
The coded retention policy gives encrypted observed source content a 30-day window. When the authenticated cron route is invoked, its first processor commits a bounded, tenant-scoped sweep and the check-in fails while expired data remains. A confirmed provider deletion receipt erases local source events, content, cursors, and reconciliation jobs while retaining a minimal connection tombstone.
The code has an enforcement path and a tested local erasure path. Production enforcement is earned only after the declared scheduler is observed running for the deployed commit.Inspect the receipt
src/lib/retention/sweep.test.tsThe 30-day observed-content policy is exercised by a ciphertext-redaction test.src/lib/db/migrations/frozen/2026082101.tsFixed database capabilities expose only due tenant identities and bounded global expiry counts.src/app/api/cron/process/route.tsThe cron processor catalog runs retention first and treats a remaining backlog as failure.src/app/api/cron/process/route.tsThe cron route rejects callers without the configured bearer secret.render.yamlThe repository declares an intended five-minute Render schedule; the file cannot prove a live job exists or ran.src/lib/db/rls-wall.pg-test.tsThe opt-in PostgreSQL 16 lane exercises capability access while direct global and unscoped tenant reads stay closed.src/lib/kernel/source-events/connections.test.tsProvider-confirmed deletion erases only the scoped connection and is safe to replay.
One private interruption. Once.
The guardian passes a deterministic replay rehearsal: it sends a newly quiet candidate only to the owner and the same candidate cannot claim a second notification. It is not yet a generally available unattended service.
The boundary is part of the product.
- No live customer outcome or time-saved claim has been proven yet.
- Provider integration and OAuth-app provisioning remain operator work, and no live vendor run or production self-service has been proven. In exact controlled-development mode, an active owner can create the hosted authorization link inside Qoil; activation still requires the signed webhook and matching server-owned binding.
- Qoil does not yet independently verify that an outcome happened.
- Qoil does not message the other party or chase anyone in the current horizontal pilot.
- The five-minute Render schedule is declared in code; this commit does not prove that the production job exists or ran for the deployed SHA.
- The restricted-content data-use gate is implemented but no live source processor composes it yet.
Let Qoil surface one promise you may have forgotten.
In the controlled build, an owner can start authorization for one operator-provisioned provider integration, select one source-observed address inside Qoil, and privately check candidates against available source evidence.
Enter the pilot