RUMBO IA CRM — OpenAI submission readiness receipt

Date: 2026-09-11 UTC Candidate SHA: 9152f5a50de42be55508f0effed5ed09aee44c60 MCP URL: https://rumbo-crm-openai-staging.val.run/api/openai-plugin/mcp Protocol: MCP 2025-06-18 Budget invariant: MONEY_SPEND=0

Proven technical readiness

  • CURRENT_HEAD_EXACT_CI=PASS
  • CRM_STAGING_HTTP_PUBLIC=PASS
  • CRM_STAGING_CONFORMANCE=PASS
  • REMOTE_MCP_ONLY_PROVIDER_COMPATIBILITY=PASS
  • TOOL_COUNT=4
  • TOOL_ANNOTATIONS=PASS
    • readOnlyHint=true
    • openWorldHint=false
    • destructiveHint=false
  • POSITIVE_TEST_CASES=5_READY
  • NEGATIVE_TEST_CASES=3_READY
  • DOMAIN_CHALLENGE_CAPABILITY=IMPLEMENTED_FAIL_CLOSED
  • DOMAIN_CHALLENGE_WITHOUT_TOKEN=404_PASS
  • CUSTOM_UI=NONE_REQUIRED
  • AUTHENTICATION=NONE_FOR_BOUNDED_PUBLIC_V1
  • LISTING_URLS_HTTP_PUBLIC=PASS — website, support, privacy and terms all return HTTP 200.
  • SUPPORT_MCP_SEMANTICS=PASS_SELF_HOSTEDhttps://rumbo-crm-openai-staging.val.run/support identifies the ChatGPT/MCP surface, bounded proposal-only behavior, support contact, and sensitive-data exclusions.
  • PRIVACY_MCP_DISCLOSURE=PASS_SELF_HOSTEDhttps://rumbo-crm-openai-staging.val.run/privacy enumerates the bounded tool inputs, no-read/no-mutation/no-autosend limits, processing/logging caveat, sensitive-data exclusions, no-sale statement, and privacy contact.
  • TERMS_BOUNDED_SEMANTICS=PASS_SELF_HOSTEDhttps://rumbo-crm-openai-staging.val.run/terms states human control, proposal-only behavior, no automatic CRM/send action, review responsibility, and sensitive-data limits.
  • PUBLISHER_SURFACES_PR94=ALTERNATE_CORPORATE_DOMAIN_CANDIDATE — the publisher PR remains useful for future rumbo.verso.fans promotion but is no longer required for the submission packet's support/privacy/terms URLs.
  • CUSTOMER_DATA_READS=NOT_EXPOSED
  • CRM_MUTATIONS=NOT_EXPOSED
  • AUTONOMOUS_SENDS=NOT_EXPOSED
  • MCP_RESPONSE_HYGIENE=PASS — all four synthetic tool outputs match their declared output schemas with no extra fields, sensitive/debug keys, OpenAI-style API keys, or bearer-token-shaped values.
  • PORTAL_CDP_LISTENER=PASS_127_0_0_1_9222_RUMBONEXUS
  • OPENAI_PLATFORM_SESSION=LOGIN_REQUIRED — direct CDP navigation to https://platform.openai.com/plugins redirected to https://platform.openai.com/login?next=%2Fplugins; no cookies or credentials were extracted or reused.

OpenAI portal requirements not yet proven

  • APPS_MANAGEMENT_WRITE=UNVERIFIED_REQUIRED — public plugin drafts require organization Apps Management write access; organization owners already have it, non-owner submitters require an assigned role with Write.
  • PUBLISHER_IDENTITY=UNVERIFIED_REQUIRED — every public submission must select a verified individual or business identity matching the listing, website, support, privacy and terms.
  • PORTAL_SESSION=LOGIN_REQUIRED — CDP reached the OpenAI Platform target, but the RumboNexus profile is currently at https://platform.openai.com/login; no credential or cookie extraction is permitted.
  • SUBMISSION_IMPORT=READY_VALIDATED_NOT_UPLOADEDvalidate_submission_import.ts=PASS validates exact 4-tool identity, complete tool hints, live tools/list, all four live outputSchema declarations, app metadata, 5 positive tests, and 3 negative tests.
  • LOGO_CANONICAL_REMOTE_MAIN=VERIFIED_SHA256_3ac48eb17d735ee41d12e6edf0cc0ea0e5a55358cce6b5fd37d93b3fc0372205
  • LOGO_SELF_HOSTED_URL=https://rumbo-crm-openai-staging.val.run/logo.svg
  • LOGO_PORTAL_UPLOAD=NOT_EXECUTED
  • PUBLISHER_SURFACES_LIVE_PROMOTION=OPTIONAL_FOR_CORPORATE_DOMAIN_NOT_REQUIRED_BY_SELF_HOSTED_PACKET
  • DOMAIN_CHALLENGE_TOKEN=NOT_ISSUED_BY_PORTAL
  • DOMAIN_VERIFICATION=CONDITIONAL_PORTAL_GATE_UNVERIFIED — current OpenAI docs require the well-known challenge when the portal shows Domain not verified; the local endpoint remains fail-closed until a real token is issued.
  • SCAN_TOOLS=NOT_EXECUTED
  • SCAN_TOOLS_RESULT=UNVERIFIED
  • STARTER_PROMPTS=READY_IN_TEST_ARTIFACT_BUT_NOT_ENTERED_IN_PORTAL
  • DISTRIBUTION_SCOPE=UNSET_FAIL_CLOSED
  • PRODUCTION_MCP_URL_PROMOTION=NOT_AUTHORIZED
  • SUBMIT_FOR_REVIEW=NOT_EXECUTED
  • PUBLICATION=NOT_EXECUTED

Submission contract

The current OpenAI product separates workspace custom-app deployment from public directory submission. Workspace custom MCP apps are created through Developer Mode on eligible Business or Enterprise/Edu workspaces using endpoint metadata and Scan Tools; public directory submission is a separate flow. This candidate already has a validated submission import artifact with four behavior-audited tools and exactly five positive plus three negative tests. Any additional portal-only fields—domain challenge, identity, logo upload, availability, or other metadata—must be treated as requirements only when the live submission surface actually presents them. The MCP URL must not be represented as production until separate production-host authority is granted.

Fail-closed promotion rule

TECHNICAL_PASS != PORTAL_ACCESS != PRODUCTION_HOST_AUTHORITY != PORTAL_METADATA_COMPLETE != SCAN_TOOLS_PASS != SUBMISSION_AUTHORITY != PUBLICATION

Do not promote this staging host to the production MCP URL or submit it for review until every portal-controlled gate above is explicitly proven and a separate production/submission authority is granted.

Evidence addendum — V9 reconciliation

  • PORTAL_EVIDENCE_RECEIPT_V9=PASS_VERIFIED
  • PORTAL_PACKET_VERIFIER=PASS_AFTER_CANONICAL_MARKER_RECONCILIATION
  • TOOL_ANNOTATION_JUSTIFICATIONS=PASS_12_OF_12
  • PRIVACY_FIELD_MATRIX=PASS_BOUNDED_EXPLICIT_INPUTS_ONLY
  • DOMAIN_VERIFICATION=CONDITIONAL_PORTAL_GATE_UNVERIFIED
  • GITHUB_CURRENT_HEAD=UNVERIFIED_CONNECTOR_DISABLED
  • PORTAL_CDP_CURRENT_ATTEMPT=DESKTOP_TRANSPORT_TIMEOUT
  • PUBLISHER_IDENTITY_EMAIL_RECEIPT=NOT_FOUND — Gmail search is secondary evidence only; portal state remains UNVERIFIED, not failed.
  • APPS_MANAGEMENT_WRITE_EMAIL_RECEIPT=NOT_FOUND — Gmail search is secondary evidence only; portal state remains UNVERIFIED, not failed.

Exact remaining blocker set is seven items: domain portal status, Apps Management Write, publisher identity, logo portal upload, Scan Tools, distribution scope, and production MCP URL authority. The earlier global project residency blocker was removed after re-checking the current official submission and MCP server review documentation; no such submission requirement is documented there.

Evidence addendum — V10 correction

  • PORTAL_EVIDENCE_RECEIPT_V10=PASS_VERIFIED
  • PORTAL_EVIDENCE_V10_SUPERSEDES_V9_OPERATIONALLY
  • PORTAL_PACKET_VERIFIER=PASS_WITH_V10_LINK
  • SUBMISSION_GATE=BLOCKED_FAIL_CLOSED_7_EXACT_EXTERNAL_BLOCKERS
  • GLOBAL_PROJECT_DATA_RESIDENCY_BLOCKER=RETRACTED_NOT_DOCUMENTED_IN_CURRENT_OFFICIAL_SUBMISSION_OR_MCP_REVIEW_DOCS
  • PLATFORM_CONTEXT=RUMBO_ORG_DEFAULT_PROJECT_CONNECTED_PORTAL_CONTEXT_UNVERIFIED
  • GITHUB_CURRENT_HEAD=UNVERIFIED_CONNECTOR_DISABLED
  • PORTAL_CDP_CURRENT_STATE=NO_REMOTE_DEBUGGING_CHANNEL_AVAILABLE
  • MONEY_SPEND=0

Current exact blocker set: domain verification portal status, Apps Management Write, publisher identity, logo portal upload, Scan Tools, distribution scope, and production MCP URL authority. V9 remains preserved as historical evidence but is not authoritative for the current blocker set.

Evidence addendum — V11 correction

  • PORTAL_EVIDENCE_RECEIPT_V11=PASS_VERIFIED
  • PORTAL_EVIDENCE_V11_SUPERSEDES_V10_OPERATIONALLY
  • PORTAL_PACKET_VERIFIER=PASS_WITH_V11_LINK
  • SUBMISSION_GATE=BLOCKED_FAIL_CLOSED_8_EXACT_EXTERNAL_BLOCKERS
  • GLOBAL_PROJECT_DATA_RESIDENCY=UNVERIFIED_REQUIRED_FOR_REMOTE_MCP_REVIEW — the specific Remote MCP review requirements state that EU-residency projects cannot submit MCP plugins for review and instruct using a global-residency project.
  • PLATFORM_CONTEXT=RUMBO_ORG_DEFAULT_PROJECT_CONNECTED_PORTAL_CONTEXT_AND_RESIDENCY_UNVERIFIED
  • GITHUB_CURRENT_HEAD=UNVERIFIED_CONNECTOR_DISABLED
  • PORTAL_CDP_CURRENT_STATE=NO_REMOTE_DEBUGGING_CHANNEL_AVAILABLE
  • MONEY_SPEND=0

Current exact blocker set: domain verification portal status, Apps Management Write, publisher identity, global project data residency, logo portal upload, Scan Tools, distribution scope, and production MCP URL authority. V10 is preserved as historical evidence of an incorrect documentation reconciliation and is superseded by V11.

Evidence addendum — V12 authoritative reconciliation

  • PORTAL_EVIDENCE_RECEIPT_V12=PASS_VERIFIED
  • PORTAL_EVIDENCE_V12_SUPERSEDES_V11_OPERATIONALLY
  • SUBMISSION_GATE_TECHNICAL_STATE=PASS
  • RESPONSE_MINIMIZATION=PASS_ALL_4_TOOLS
  • PORTAL_PACKET_VERIFIER=PASS_WITH_V12_LINK
  • WORKSPACE_CUSTOM_APP_FLOW=SEPARATE_FROM_PUBLIC_PLUGIN_DIRECTORY
  • WORKSPACE_DRAFT_BLOCKERS=3_EXACT — ChatGPT create-app surface unverified, Scan Tools not executed, draft not created.
  • PUBLIC_DIRECTORY_READINESS_BLOCKERS=8_EXACT — domain verification portal status, Apps Management Write, publisher identity, global project data residency, logo portal upload, Scan Tools, distribution scope, and production MCP URL authority.
  • GLOBAL_PROJECT_DATA_RESIDENCY=CONFIRMED_REQUIRED_FOR_REMOTE_MCP_REVIEW — current Remote MCP server review requirements explicitly state that EU-residency projects cannot submit MCP plugins for review and instruct using a global-residency project.
  • DOMAIN_VERIFICATION=CONDITIONAL_PORTAL_REQUIREMENT — the well-known endpoint is implemented fail-closed; a real token is served only if the portal issues one.
  • SUBMIT_FOR_REVIEW=NOT_EXECUTED_SEPARATE_FROM_READINESS
  • PUBLICATION=NOT_EXECUTED
  • GITHUB_CURRENT_HEAD=UNVERIFIED_CONNECTOR_DISABLED
  • MONEY_SPEND=0

V12 is the current operational authority for portal readiness. V9–V11 remain historical evidence only. The prior V10 claim that global project data residency was not documented is retracted; the specific Remote MCP review page controls this requirement.

Evidence addendum — V13 revalidation (2026-09-12)

  • PORTAL_EVIDENCE_RECEIPT_V13=PASS_VERIFIED
  • PORTAL_EVIDENCE_V13_SUPERSEDES_V12_OPERATIONALLY
  • SUBMISSION_GATE_TECHNICAL_STATE=PASS
  • PORTAL_PACKET_VERIFIER=PASS_WITH_V13_LINK
  • SUBMISSION_IMPORT_VALIDATOR=PASS
  • PUBLIC_DIRECTORY_READINESS_BLOCKERS=8_EXACT_UNCHANGED
  • WORKSPACE_DRAFT_BLOCKERS=3_EXACT_UNCHANGED
  • ARGENTINA_GENERAL_OPENAI_SERVICE_SUPPORT=CONFIRMED_2026_09_12
  • DISTRIBUTION_SCOPE=ARGENTINA_ONLY_RECOMMENDED_NOT_APPLIED
  • DESKTOP_QUGVQLB=PING_PASS_2026_09_12
  • BRAVE_AND_RUMBO_NEXUS_PROCESSES=ACTIVE_OBSERVED
  • PORTAL_CDP_127_0_0_1_9222=CURRENT_PROBE_EXIT_1_NO_BODY
  • GITHUB_CURRENT_HEAD=UNVERIFIED_CONNECTOR_DISABLED
  • MONEY_SPEND=0

V13 is the current operational authority for portal-readiness evidence. It does not change the candidate SHA, the exact blocker set, production authority, submission authority, or publication authority. V12 and earlier receipts remain historical evidence only.

Evidence addendum — V14 authoritative correction (2026-09-13)

  • PORTAL_EVIDENCE_V14_SUPERSEDES_V13_OPERATIONALLY
  • SUBMISSION_GATE_TECHNICAL_STATE=PASS
  • PORTAL_PACKET_CONSTRAINTS=PASS
  • STARTER_PROMPTS=3_OF_MAX_3_PASS
  • PACKAGE_NAME=rumbo-ia-crm_PASS
  • PACKAGE_VERSION=1.0.0_SEMVER_PASS
  • CAPABILITIES=4_OF_MAX_20_PASS
  • TOOL_ANNOTATION_JUSTIFICATIONS=PASS_12_OF_12
  • REVIEW_CASE_SERVER_VALIDATION=PASS_5_POSITIVE_3_NEGATIVE_SURFACE
  • REVIEW_CASE_SERVER_VALIDATION_SCOPE=SERVER_SIDE_ONLY_NOT_CHATGPT_TOOL_SELECTION_E2E
  • DEMO_RECORDING_PLAN=READY
  • DEMO_RECORDING_URL=MISSING_FAIL_CLOSED
  • DOMAIN_VERIFICATION=REQUIRED_FOR_FINAL_REMOTE_MCP_SUBMISSION_NOT_COMPLETED
  • DOMAIN_CHALLENGE_ENDPOINT=READY_FAIL_CLOSED_NO_TOKEN
  • GLOBAL_PROJECT_DATA_RESIDENCY=UNVERIFIED_REQUIRED_FOR_REMOTE_MCP_REVIEW
  • STAGING_URL=TECHNICALLY_VALID_FOR_TESTING_NOT_ELIGIBLE_AS_FINAL_PRODUCTION_URL
  • PRODUCTION_MCP_URL=NOT_AUTHORIZED
  • PUBLIC_DIRECTORY_READINESS_BLOCKERS=9_EXACT
  • WORKSPACE_DRAFT_BLOCKERS=3_EXACT
  • GOVERNANCE_BLOCKERS=1_GITHUB_CANDIDATE_HEAD_UNRECONCILED
  • MONEY_SPEND=0

Current public-directory blocker set: completed domain verification, Apps Management Write, verified publisher identity, global-residency project, portal logo upload, reviewer-accessible demo-recording URL, authorized production MCP URL, successful current Scan Tools snapshot, and distribution scope. Separately, GitHub candidate HEAD remains unreconciled because the GitHub connector is unavailable in this session. The public staging endpoint remains useful for technical validation but must not be represented as the production MCP URL.

Evidence addendum — V16 authoritative documentation reconciliation (2026-09-13)

  • PORTAL_EVIDENCE_RECEIPT_V16=CREATED_AND_VERIFIED_BY_DEDICATED_VERIFIER
  • PORTAL_EVIDENCE_V16_SUPERSEDES_V15_OPERATIONALLY
  • SUBMISSION_GATE_TECHNICAL_STATE=PASS
  • WORKSPACE_DRAFT_BLOCKERS=3_EXACT — ChatGPT create-app surface unverified, Scan Tools not executed, draft not created.
  • PUBLIC_DIRECTORY_READINESS_BLOCKERS=9_EXACT — domain verification portal status, Apps Management Write, publisher identity, global project data residency, logo portal upload, authorized production MCP URL, Scan Tools, distribution scope, and policy attestations.
  • GLOBAL_PROJECT_DATA_RESIDENCY=REQUIRED_FOR_REMOTE_MCP_REVIEW — current official MCP review requirements state that EU-residency projects cannot submit MCP plugins for review and instruct using a global-residency project.
  • DEMO_RECORDING_REQUIREMENT=RETRACTED — neither the current public submission flow nor current remote-MCP review requirements lists a demo-recording URL as a mandatory submission field. Demo credentials apply only when authentication is required; screenshots are optional only when UI exists.
  • TEST_REQUIREMENT=AT_LEAST_5_POSITIVE_3_NEGATIVE; RUMBO currently provides 5 positive and 3 negative cases.
  • POLICY_ATTESTATIONS=REQUIRED_BEFORE_SUBMIT_NOT_COMPLETED
  • PRODUCTION_MCP_URL=NOT_AUTHORIZED; the *-staging.val.run endpoint remains technical validation only and must not be represented as final production.
  • GOVERNANCE_BLOCKERS=1_GITHUB_CANDIDATE_HEAD_UNRECONCILED because the GitHub connector is disabled in this session.
  • SUBMIT_FOR_REVIEW=NOT_EXECUTED
  • PUBLICATION=NOT_EXECUTED
  • MONEY_SPEND=0

V16 is the current operational authority for portal readiness. V15 and earlier receipts remain preserved as historical evidence; their conflicting demo-recording claims are superseded by V16. Technical PASS remains distinct from portal access, global project residency, production-host authority, Scan Tools PASS, submission authority, and publication.

Evidence addendum — V17 authoritative revalidation (2026-09-13)

  • PORTAL_EVIDENCE_RECEIPT_V17=PASS_VERIFIED
  • PORTAL_EVIDENCE_V17_SUPERSEDES_V16_OPERATIONALLY
  • SUBMISSION_GATE_TECHNICAL_STATE=PASS
  • WORKSPACE_DRAFT_BLOCKERS=3_EXACT
  • PUBLIC_DIRECTORY_READINESS_BLOCKERS=9_EXACT
  • GOVERNANCE_BLOCKERS=1_GITHUB_CANDIDATE_HEAD_UNRECONCILED
  • GLOBAL_PROJECT_DATA_RESIDENCY=REQUIRED_FOR_REMOTE_MCP_REVIEW — revalidated against the specific current OpenAI MCP server review requirements: EU-residency projects cannot currently submit MCP plugins for review and must use a project with global data residency.
  • DEMO_RECORDING=NOT_LISTED_AS_MANDATORY
  • LISTING_URLS_SELF_HOSTED_TECHNICAL_SEMANTICS=PASS
  • LOGO_EXACT_ASSET=PASS_SHA256_3ac48eb17d735ee41d12e6edf0cc0ea0e5a55358cce6b5fd37d93b3fc0372205
  • PRODUCTION_MCP_URL=NOT_AUTHORIZED
  • DOMAIN_VERIFICATION=NOT_COMPLETED
  • SCAN_TOOLS=NOT_EXECUTED
  • SUBMIT_FOR_REVIEW=NOT_EXECUTED
  • PUBLICATION=NOT_EXECUTED
  • MONEY_SPEND=0

V17 resolves the documentation ambiguity encountered during this session by giving precedence to the specific remote-MCP review requirements over the general submission overview. A transient interpretation that residency was not required was reverted before readiness promotion. GitHub live reconciliation remains fail-closed because the GitHub connector is unavailable in this session.