Skip to content

Route Sentry and Datadog findings through one audited draft-PR repair lane #3338

Description

@aviyashchin

Job

Firstmate can accept a Sentry Seer or Datadog Bits finding for a registered project, deduplicate it into one incident, assign exactly one repair writer, and deliver at most a draft PR with an auditable evidence chain; it can never auto-merge or auto-deploy.

Why this belongs in Firstmate

Sentry and Datadog can investigate and propose repairs, but they do not own cross-agent concurrency, project worktree isolation, proof policy, or captain merge authority. If both vendors independently edit the same incident, observability becomes a second uncontrolled fleet. Firstmate is the orchestration and claim-provenance boundary.

Observable outcome

Given two provider findings that refer to the same repository/SHA/error fingerprint, Firstmate creates one durable task, records both sources, launches no more than one writer, runs the project's existing validation path, and reports a draft PR plus provider/test evidence to the captain.

Exit criterion

bash tests/test-provider-repair-intake.sh

returns 0 and proves:

  1. Sentry and Datadog payloads are treated as untrusted findings, not facts;
  2. repository, environment, release SHA, issue/monitor ID, and fingerprint are normalized deterministically;
  3. matching findings deduplicate to one task and one worktree writer;
  4. a finding without repository/SHA/evidence is parked for clarification, not dispatched;
  5. the generated brief requires reproduction/falsification before repair;
  6. provider evidence, agent changes, test output, commit, and draft PR are recorded as distinct provenance hops;
  7. the delivery path refuses merge/deploy regardless of provider recommendation;
  8. concurrency/session caps from feat(bin): cap active crew concurrency per home #3323 still apply;
  9. dry-run fixtures require no live provider token or project write.

Prerequisites

  • Firstmate feat(bin): cap active crew concurrency per home #3323 or equivalent bounded active-crew policy.
  • Rehoboam/Holodeck expose immutable releases and provider-readable evidence before live intake is enabled.
  • Captain-confirmed policy: draft PR only; no automatic merge or deployment.

Files in scope

  • The smallest existing inbox/procevent/task-intake and brief-generation scripts
  • A provider-neutral normalized finding schema in the existing private-state conventions
  • Deterministic fixture-based tests and one short configuration/runbook section

Reuse first

  • Existing procevent, durable inbox, task metadata, project registry, one-writer worktree guard, no-mistakes pipeline, PR polling, and captain merge boundary.
  • Prefer a small adapter that maps provider payloads into existing intake over a new daemon or agent framework.

Security and authority

  • Provider credentials remain in the operator secret store and are never copied into briefs, state logs, PRs, or project repos.
  • Default intake is poll/read or verified webhook-to-private-inbox; payloads cannot execute commands.
  • Vendor suggestions are evidence tagged reported, never verified until reproduced.
  • Provider write scope may create analysis/remediation proposals, but Firstmate alone decides whether to dispatch a draft-PR task.

Out of scope

  • Automatic merge/deploy, direct writes into project primary checkouts, autonomous production rollback, a new incident-management product, or vendor-specific policy forks.

Activity

  1. aviyashchin commented on Aug 30, 2026

    @aviyashchin
    Author

    Initial project bindings

    Live provider intake stays disabled until each project has provider-readable immutable release identity. Fixture/dry-run implementation can proceed independently.

  2. aviyashchin commented on Aug 30, 2026

    @aviyashchin
    Author

    Canonical implementation references (reviewed 2026-08-30)

    Provider output is untrusted reported evidence. Normalize repository, environment, release SHA, provider object ID, and fingerprint before deduplication; dispatch only one writer; retain separate receipts for reproduction, change, test, commit, and draft PR. Provider self-healing must never bypass Firstmate's captain-only merge/deploy boundary.

  3. kunchenguid commented on Aug 30, 2026

    @kunchenguid
    Owner

    Speaking as Kun's firstmate: Triaged against main 1260adce77a49ffd5979d8158743d4b0ac40d15d.

    Verdict: VISION-aligned feature when kept captain-gated and opt-in; unfixed on main (no Sentry/Datadog/repair-intake surface in tree); no covering open PR. Prerequisite #3323 remains open — fixture/dry-run may proceed; live intake stays off until that bound and project release identity exist. Labeling ready-for-pr.

    Contract-class: opt-in — off unless the captain enables intake; draft-PR only; never auto-merge/deploy.

    VISION (per major section):

    • One captain one interface: aligns — one audited repair lane to the captain, not vendor chatter.
    • Authority explicit: aligns — draft PR only; captain merge; no consent assumed; live intake disabled by default.
    • Scripts vs agents: aligns — normalize/dedupe/determinism in scripts; repair judgment in a writer agent.
    • Restart non-event: aligns — durable incident/task records.
    • Delegation with spine: aligns — explicit contract, one writer, existing validation path.
    • Fleet outlives vendor: aligns — provider-neutral schema; vendors are evidence sources.
    • Scope: aligns if tightly scoped — adapter into existing inbox/procevent/intake; does not align if it grows into an incident-management product or workshop. Issue's out-of-scope list is load-bearing.

    Ship as the smallest opt-in adapter + fixtures (tests/test-provider-repair-intake.sh); refuse merge/deploy regardless of provider recommendation; keep credentials out of briefs/state/PRs. Do not open a competing implementation PR beyond this issue's scope.

  4. added
    ready-for-prTriage: real bug or VISION-aligned feature, open for a PR
    on Aug 30, 2026
  5. devin-ai-integration commented on Sep 24, 2026

    @devin-ai-integration
    No description provided.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestready-for-prTriage: real bug or VISION-aligned feature, open for a PR

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions