Outcome
Decide whether to offer a versioned local interface (an MCP server and/or localhost API) through which MIS, web-to-print systems, and AI agents can inspect, plan, and preview.
Parent and boundary
Parent: #110. This is an expansion candidate. Produce a value case, owning module, contract sketch, and threat notes, then record go, no-go, or defer. No implementation lands from this issue. A new public PDF, schema, worker, or workflow contract needs an architect checkpoint with concrete fixtures and migration behavior.
Grounding
- Integrations and agents can drive Loop today only through the PdfTool CLI.
- Roadmap §5 rules out a web shell.
Decision inputs
- An authority model equal to L08: no approval, no publication, and no filesystem access beyond granted inputs.
- Local-only transport and authentication, with a receipt per call.
- Typed outputs so document content cannot escalate through prompt injection.
- Failure case: approval and publication never become callable through this interface.
Required proof
Decision record with the value case (user, frequency, current alternative, evidence), owning module, contract sketch, fixtures or corpus plan, independent oracle where a claim is made, and risks.
Handoff
State go, no-go, or defer. On go, file bounded implementation sub-issues under the owning module parent and link them here.
Sources
Approved master roadmap §5 · Gap review of the issue suite against the approved roadmap, 2026-09-27.
Outcome
Decide whether to offer a versioned local interface (an MCP server and/or localhost API) through which MIS, web-to-print systems, and AI agents can inspect, plan, and preview.
Parent and boundary
Parent: #110. This is an expansion candidate. Produce a value case, owning module, contract sketch, and threat notes, then record go, no-go, or defer. No implementation lands from this issue. A new public PDF, schema, worker, or workflow contract needs an architect checkpoint with concrete fixtures and migration behavior.
Grounding
Decision inputs
Required proof
Decision record with the value case (user, frequency, current alternative, evidence), owning module, contract sketch, fixtures or corpus plan, independent oracle where a claim is made, and risks.
Handoff
State go, no-go, or defer. On go, file bounded implementation sub-issues under the owning module parent and link them here.
Sources
Approved master roadmap §5 · Gap review of the issue suite against the approved roadmap, 2026-09-27.