Follow-up to #501, found in a post-merge review.
- archive / unarchive fail closed. A governance update never sends a write unless it first got a complete record. A failed or empty read makes the command refuse and exit non-zero. Prefer a server-side partial update (Flair's PATCH merges), which also closes the read-then-write race.
- search signs as the operator.
tps memory search signs with TPS_AGENT_ID (and refuses when it is unset), sends the target agent as the search's agentId parameter, and leaves read scoping to Flair. The changelog line about which identity signs matches the code.
- approve / reject. Route these to Flair's promotion path, or remove them until one exists. Flair's write path refuses direct changes to the promotion status.
Acceptance: a read that returns 503 or 404 sends no write and exits non-zero; the happy path sends only the governance fields; search signs as the operator and carries the target as a parameter; with TPS_AGENT_ID unset, search refuses; approve/reject either succeed against a real Flair or are absent from the CLI.
Follow-up to #501, found in a post-merge review.
tps memory searchsigns withTPS_AGENT_ID(and refuses when it is unset), sends the target agent as the search'sagentIdparameter, and leaves read scoping to Flair. The changelog line about which identity signs matches the code.Acceptance: a read that returns 503 or 404 sends no write and exits non-zero; the happy path sends only the governance fields; search signs as the operator and carries the target as a parameter; with
TPS_AGENT_IDunset, search refuses; approve/reject either succeed against a real Flair or are absent from the CLI.