Product feedback
A scenario runner can support sensitive multi-step journeys only when its sessions are bound to an owner/subject and replay shows which scenario, persona artifact, policy reference, and user-confirmed checkpoint governed each transition. A consumer should not have to build an ad hoc authorization and provenance format around DRIFT.
Scope
- Add optional, transport-neutral session provenance fields for owner/subject/relationship reference, interaction reference, scenario content hash, persona artifact reference, policy reference/receipt reference, and consent/confirmation checkpoint reference.
- Require authorization for session reads, events, context-pack retrieval, and replay. Same-tenant access alone must not grant access to another user's session.
- Support declared checkpoints that require explicit external confirmation before a transition or mutation intent is emitted.
- Define policy-gated safety terminals such as paused-for-safety and escalated that cannot be coerced into a normal completed journey.
- Ensure slots accept only permitted minimal values and fixtures never require raw reflection content.
- Provide replay fixtures for cross-user injection, missing or altered provenance, terminal-session mutation attempts, confirmation refusal, idempotent retry, scenario-version mismatch, BLOCK, and ESCALATE.
Acceptance criteria
Product feedback
A scenario runner can support sensitive multi-step journeys only when its sessions are bound to an owner/subject and replay shows which scenario, persona artifact, policy reference, and user-confirmed checkpoint governed each transition. A consumer should not have to build an ad hoc authorization and provenance format around DRIFT.
Scope
Acceptance criteria