Limited requester
Own Billing Agent answers and constrained request status
production / miranda-platform-admin / platform_admin_lightsail_control_plane
Verified 2026-06-02T20:04:33.751Z
Runtime
8 services
Scheduler uses postgres_schedule_registry with bullmq_redis; 7/7 automations are active-ready and raw server cron is blocked.
Ingress
CloudFront + WAF
Stable Lightsail origin is protected by the origin verification header and direct-origin denial.
Data Plane
local_postgresql
PostgreSQL, Redis, artifacts, and parser are local to the single Lightsail host for this pilot profile.
Recovery
No backup
This pilot records cold rebuild evidence and no-restore risk acceptance instead of snapshots or managed backups.
Capacity
3 / 10 / 1
Lightsail pilot limits are 3 sync runs, 10 async runs, and 1 browser or sandbox run before upgrade review.
Observability
Postgres detail
Runtime egress trace detail returned metadata-only trace detail for trace:bioness:runtime:tool-egress-denial; customer data, raw payloads, external calls, and paid provider calls are blocked.
Identity
Shared app
Miranda uses the shared platform Entra app and Teams bot; Bioness tenant consent and group mapping remain onboarding gates.
Audit
Hash chain
Audit-critical mutation paths fail closed when local audit storage is unavailable; Object Lock exports require an upgrade.
Support
Preview gates
5 support action previews returned preview-only controls; commits, raw-payload access, customer notification delivery, compliance export, external calls, and paid provider calls remain blocked.
Model Spend
Stub only
OpenAI, Anthropic, and OpenRouter paid inference remains blocked without bounded approval evidence.
Governance
Fail closed
Scheduler create/edit/action controls return draft-only or preview-only records with confirmation, approval, readiness, and rollback gates before activation.
Deployment
Live bundle
Current 4220696afe32; rollback f6caf43d8858.
Rollout
Single pilot
Feature flags, environment pins, soak gates, and rollback manifests are Miranda-native records; second-customer rollout is blocked until soak evidence exists.
Own Billing Agent answers and constrained request status
Billing workflow approvals, evals, and component status
Users, roles, connector health, policy, budget, and audit summaries
Deployments, fleet health, support sessions, queues, and rollout state
Audit search, approvals, policy decisions, retention, and evidence
| Item | Status | Owner | Evidence |
|---|---|---|---|
| billing-agent-bootstrap-allow | allowed | limited_requester | evals/billing-agent/bootstrap-cases.json |
| billing-agent-bootstrap-deny | denied | limited_requester | tooling/scripts/smoke-contracts.mjs |
| openwebui-chat-smoke | allowed | platform_operator | BIONESS-RUNTIME-DEPLOYMENT |
| browser-sandbox-policy-check | policy_ready_not_executed | platform_operator | runtime-policy:bootstrap-browser-sandbox-ready |
Live provider routes remain disabled until model readiness, processor approval, budget binding, eval gate, and rollback target evidence pass.