Part of #12150 (Epic: ADR-0126 implementation, v17 line — 17.x minor, maintainer-ruled).
Blocked-by: #12155
Dispatch: coordinated under the #12150 program — ⛔ not from the general queue; the program dispatches on unlock (maintainer anti-preemption instruction, 2026-08-25, PM session session_01KWRU3s15AJz7PGW7a7wdCh). Contract: ADR-0126 §7.2 (merged 28b47a93).
Deliverable
The automation engine consumes the ledger:
Acceptance
Refs: ADR-0126 §7.2 · #10243 · #11665 §2.3/§6.3 · ADR-0112
Part of #12150 (Epic: ADR-0126 implementation, v17 line — 17.x minor, maintainer-ruled).
Blocked-by: #12155
Dispatch: coordinated under the #12150 program — ⛔ not from the general queue; the program dispatches on unlock (maintainer anti-preemption instruction, 2026-08-25, PM session
session_01KWRU3s15AJz7PGW7a7wdCh). Contract: ADR-0126 §7.2 (merged28b47a93).Deliverable
The automation engine consumes the ledger:
execute()-seam refusal beside the existingFLOW_DISABLEDguard (Design: post-install customization of packaged flows — clone-to-customize + org-level takeover (supersedes the org-tunable-parameters framing) #11665 §2.3 — the one seam every entry path crosses), reusing theFLOW_DISABLEDcode — ⛔ no new ADR-0112 ledger entry; the distinction rides the message.toggleFlowsemantics. (Pre-charted future per-org rows cannot unbind — entry-time refusal only; not built in this line.)flowEnabledmap — the durable ledger row replaces it as the sanctioned off-switch; remove the mechanism, don't shade it.Acceptance
execute()on every entry path (record-change, schedule, time-relative, api, subflow) with theFLOW_DISABLEDcode and a message that distinguishes ledger-disable.flowEnabledmap gone; the Decide whether POST /api/v1/automation/:name/toggle belongs in the manage_metadata write set — it mutates flow enablement with no authoring capability #10243 leak shape (tenant flipping env-wide, in-process) is no longer reachable.Refs: ADR-0126 §7.2 · #10243 · #11665 §2.3/§6.3 · ADR-0112