# Session notes — 25 Aug 2026

## Done

### Design review human gate
- Orchestrator entry `route` node: clarification resume re-analyzes; `DESIGN_REVIEW` resume approves or fails.
- After Solution Architect: `design_review_gate` posts Jira comment and pauses in `DESIGN_REVIEW`.
- Approve → `IMPLEMENTING` + `design_approved=true` (no developer yet).
- Reject (`reject` / `rejected` comment prefix) → `FAILED`.

### Allowlist enforcement
- `enforce_allowlist()` in `packages/artifacts/design.py`: normalize type aliases, strip out-of-allowlist + destructive actions, escalate risks.
- Empty plan after filtering → orchestrator `FAILED`.

### Webhook resume
- `should_resume_design_review` + `design_review_decision` in `jira_webhook.py`.
- API stores `design_decision` / `design_resume_comment` then enqueues resume.
- Trigger rules updated for design-review comments.

### Tests
- `pytest -q` → **16 passed** (design review approve/reject, allowlist strip, API resume).

### Docs
- [Phase 3 handoff](../phase-2/PHASE3_HANDOFF.md)

## Live ops checklist

- [ ] Set `LLM_PROVIDER=openai` + `OPENAI_API_KEY`; restart **both** API and worker; confirm `llm_provider=openai` in logs.
- [ ] Mock vs live analyst/architect on SALES-101 / SALES-102; note outputs below.
- [ ] Refresh ngrok URL → update Jira webhook.
- [ ] Smoke-test: incomplete issue → clarify → resume → architect → `DESIGN_REVIEW` → approve → `IMPLEMENTING`.

### Live LLM comparison (25 Aug)

| Story | Provider | Result |
|-------|----------|--------|
| SALES-101 | mock | clear, confidence ~0.82, CustomField plan (unit + prior session) |
| SALES-101 | openai | **blocked** — `OPENAI_API_KEY` empty in `.env` |
| SALES-102 | mock | unclear, confidence ~0.35, clarification questions |
| SALES-102 | openai | **blocked** — `OPENAI_API_KEY` empty in `.env` |

Keep `LLM_PROVIDER=mock` for CI. After pasting a key: restart API + worker, re-run comparison, then ngrok + Jira webhook smoke-test.

**Ngrok:** terminal idle (not running). Start `ngrok http 8001` (or current API port) and update the Jira webhook URL before live smoke-test.

## Blockers / next
- OpenAI key required for live LLM comparison (keep `LLM_PROVIDER=mock` for CI).
- Phase 3: Salesforce Developer + Git/PR per [PHASE3_HANDOFF.md](../phase-2/PHASE3_HANDOFF.md).
- ngrok free URL rotates — update Jira webhook after each restart.
