RUMBO IA CRM — OpenAI portal handoff V20

Date: 2026-09-13 Budget invariant: MONEY_SPEND=0 Candidate SHA: 9152f5a50de42be55508f0effed5ed09aee44c60 Technical gate: PASS Submission/publication authority: NOT_GRANTED

Purpose

Execute only the remaining OpenAI portal checks. This handoff does not authorize production promotion, Submit for Review, or publication.

Before entering the portal

  1. Confirm organization is Rumbo.
  2. Inspect both currently observed Platform projects: Default project and RUMBO-AI-DEV.
  3. Select a submission project only after the portal/API proves its data residency is GLOBAL. Do not infer residency from project name or age.
  4. Confirm the acting account has Apps Management Write (api.apps.write) or owner-equivalent access.
  5. Confirm verified individual/business publisher identity matches RUMBO IA listing identity.

MCP/listing values prepared

  • Submission type: remote MCP-only / With MCP.
  • URL type: Universal.
  • Authentication: None for bounded v1.
  • Candidate endpoint for scanning only: https://rumbo-crm-openai-staging.val.run/api/openai-plugin/mcp.
  • Production MCP URL: deliberately unset until separate production-host authority.
  • Four tools only; schemas, output schemas, annotations, and 12/12 annotation justifications validated.
  • Listing/support/privacy/terms/logo materials are technically ready in PORTAL_PACKET.json.
  • Reviewer tests: 5 positive + 3 negative, validated server-side.

Portal sequence — stop before submission

  1. Open Plugin/App submission management under organization Rumbo.
  2. Prove project residency is global and record the selected project.
  3. Prove Apps Management Write and publisher identity.
  4. Upload the canonical logo from the packet.
  5. Once production-host authority exists, enter the authorized production MCP URL — never the staging URL merely to clear a form.
  6. Generate the domain-verification challenge token. Configure the exact token as OPENAI_APPS_CHALLENGE_TOKEN on the authorized production host and verify /.well-known/openai-apps-challenge returns it verbatim.
  7. Run Scan Tools; require exactly four tools with expected names, schemas and annotations. Save the scan snapshot/diagnostics.
  8. Enter the three starter prompts, listing metadata, five positive tests, three negative tests, release notes, and public support/privacy/terms/website URLs.
  9. Choose availability/countries only with separate distribution authority.
  10. Complete policy attestations only after all displayed facts are rechecked.
  11. STOP. Do not select Submit for Review without separate explicit submission authority. Do not publish after review without separate publication authority.

Evidence-to-blocker mapping

  • Verified global project -> clears global_data_residency_unverified.
  • Apps Management Write -> clears apps_management_write_unverified.
  • Verified publisher identity -> clears publisher_identity_unverified.
  • Uploaded canonical logo -> clears logo_portal_upload_not_executed.
  • Authorized production URL -> clears production_mcp_url_not_authorized.
  • Successful domain challenge -> clears domain_verification_not_completed.
  • Successful current tool scan -> clears scan_tools_not_executed.
  • Explicit countries/regions -> clears distribution_scope_unset.
  • Completed accurate attestations -> clears policy_attestations_not_completed.
  • Live GitHub reconciliation of candidate HEAD -> clears github_candidate_head_unreconciled.

Fail-closed rule

TECHNICAL_PASS != GLOBAL_PROJECT_RESIDENCY != APPS_MANAGEMENT_WRITE != VERIFIED_PUBLISHER != PRODUCTION_HOST_AUTHORITY != DOMAIN_VERIFIED != SCAN_TOOLS_PASS != DISTRIBUTION_AUTHORITY != SUBMISSION_AUTHORITY != PUBLICATION