# Gift Graph Product Log
> **Mantra:** Share the hint, keep the secret.
![[gift-graph-replit-03-plan.png|300]]![[gift-graph-replit-08-security-center.png|300]]![[gift-graph-replit-25-demo-privacy.png|300]]
*September 30 build on Replit · the six-step plan before any code · the security review, clean · the live demo from Claude Code, pull, fish, revoke*
**The vision:** My partner tells his Claude about the fonts he wants licenses for. Months later I ask my own Claude for gift ideas. Gift Graph is the shared layer between those two agents. Each person decides what their agent may drop and at what level of detail, and the other agent can pull only what was shared, in the form it was shared. The couple is the smallest instance of a pattern enterprises already ache for, and the consumer version is the cheapest place to learn whether the tiers are understandable.
It is a consent-gated MCP server with two agents, four disclosure tiers, and one veto on each end. v0.1 was built with Replit Agent from a written brief, deployed on Autoscale, and driven from Claude Code as both users. The concept and the architecture diagram live in [[Concept - Gift Graph - Consent-Gated Context Between Agents]]; the platform it was built on gets its own read in [[Replit Case Study]].
## Quick Links
| Planning | Build | Status |
| --- | --- | --- |
| [[Gift Graph Technical Specification (v0.1)]] | [[Gift Graph Build Log]] | [[Gift Graph Validation Log]] |
| [[Gift Graph Product Plan]] | [[Gift Graph Technical Decisions]] | [[Gift Graph Bug Tracker]] |
| [[Concept - Gift Graph - Consent-Gated Context Between Agents\|Concept page]] | [[Gift Graph Feature Backlog]] | [[Replit Case Study]] |
## Current State
*Updated 2026-10-01 · v0.1 live at gift-graph.replit.app, privacy model verified from Claude Code, repo private on GitHub*
| Area | Where it stands |
| --- | --- |
| **Core loop** | Request a connection, approve it with a default tier, drop a preference, pull by prompt. Seven tools over Streamable HTTP, seeded users, bearer tokens in Replit Secrets. |
| **Privacy model** | The tier filter lives in the query. A pull for the category text returned only that text; a pull for the verbatim word returned nothing; a pull after revoke returned nothing. 12 integration tests at build. |
| **Identity** | Static tokens, the right prototype choice and the wrong production choice. The ladder runs to Clerk sign-in, then MCP OAuth, then the customer's identity provider ([[Gift Graph Product Plan]]). |
| **Deployment** | Autoscale, 2 vCPU and 4 GiB, North America, chosen after Agent confirmed the transport is stateless (TDR-007). Security scan clean, Auto-Protect on. |
| **Repo** | Private `gift-graph` on GitHub, 13 commits, the multi-artifact layout already in main. The local clone and the junction into this folder are still to do. |
| **Open calls** | Drop scope (one connection or the owner), reconnect semantics, and whether the 12 tests pass in the new layout before a republish (BUG-009). |
| **Next** | Semantic matching built only from disclosed text, then Probe 1 with my partner for one gift cycle. |
---
### 2026-10-01: Live, and Driven From the Outside
v0.1 is live. I pushed the working server to a private repo, connected Claude Code to the published endpoint as both users, and ran the story end to end against the thing I built the night before: request, approve at category, drop "wants a license for Söhne" with the category text "type and lettering," pull. The category text came back. A pull for "Söhne" came back empty, which is the fishing test, and it is the best privacy proof of the night. Revoke, pull again, empty. [[Gift Graph Validation Log]] has every command and result; [[Gift Graph Build Log]] has the entry.
The server taught me two things the spec had not. It refused vibe text on a category drop, which keeps unused private text out of storage entirely. And `drop` takes a `requesterId`, which makes a drop belong to one connection rather than to the owner. Agent's reading is stricter than mine, and it is also a quiet deviation from the spec, which is exactly the kind of thing a forward deployed engineer notices and confirms with the customer before it ships ([[Gift Graph Technical Decisions#TDR-006]]).
Turns out a natural prompt misses. "Gift ideas about fonts" returned nothing, because v0.1 matches literal words against disclosed text and no word overlapped. That is the privacy model working, and it is also the next feature: semantic matching whose embeddings are built only from text the requester may see, or meaning-based search reopens the leak literal matching closes.
**The Product Thought:**
Where a privacy guarantee lives, and where it can still leak. Claude Code's summary at the pull step mentioned the hidden verbatim text. The server never sent it; Claude knew it because the same session had dropped it a minute earlier as the other identity. Two identities in one terminal make a testing shortcut, and the shortcut showed its edge. In real use each person's agent holds only its own token and its own history, and the server's identity rule is what keeps them apart. The guarantee is the server's. The agent's context is the second surface, and nothing in the server can police it. That split is the thing to say out loud whenever someone asks what Gift Graph protects.
**Mantra Check-in:**
> *Share the hint, keep the secret.*
The hint came through at category tier. The secret stayed in the database, and the one place it surfaced was a memory the server never touched.
---
### 2026-09-30: Build Night on Replit
I imported a zip holding a README, a `replit.md` brief, and five docs, with no code. Agent read it, found nothing to run, and asked what I wanted before touching anything, which is the plan-before-build rule from the brief holding on the first turn. I installed my voice rules as a project skill in `.agents/skills`, submitted "Build and run the initial version," and got a six-step plan that passed every check I had written down: anti-inference engine and tombstones deferred, drop and pull as MCP tools over Streamable HTTP, the built-in database, two seeded users. One of its choices was better than what I asked for. Agent chose owner-written category and vibe text over model summaries, which closes a leak the spec did not name ([[Gift Graph Technical Decisions#TDR-004]]).
I selected Revise and opened my text with "Approved with three additions." Agent read the text, and five minutes later v0.1 was running with 12 passing tests. The additions all landed. The gate had still bent, and that became the night's sharpest product note ([[Gift Graph Bug Tracker#BUG-002]]). The security review found nothing, Auto-Protect switched on the firewall, encryption, and dependency patching, and the panel said no code goes to the scanners behind it, which is the second question a security reviewer asks. Publish then failed for want of a run command, Plan mode turned the fix into a reviewable task card, Agent checked whether the transport held session state before picking Autoscale, and the progress bar walked through build, scan, and promote. Live a little after midnight.
**The Product Thought:**
A written brief is the forward deployed version of a voice prompt. For a solo builder, describing the app out loud is the faster and more Replit-native start, and Agent would propose its own structure. For an enterprise customer, scope, exclusions, and an approval gate before code are things the customer has to agree on in writing, and someone has to write them down before Agent starts. The README and `replit.md` played that role here, and cutting the v0.1 scope up front, deciding what to leave out, was the first real decision of the build. The second was watching the gate hold, then bend, then hold again under Plan mode. An enterprise security team will ask about exactly that sequence, and now I have seen it.
**Mantra Check-in:**
> *Share the hint, keep the secret.*
The brief shared the shape and kept the scope. Agent built what it was given.
---
### 2026-09-01: The Concept
The spec, the four tiers, the anti-inference batcher, the PSI tombstones, and the architecture diagram, written up as a concept page and published to the garden. Decided against patenting; publishing the spec is the cheaper protection and the better use of the idea. Nothing built yet. The full page: [[Concept - Gift Graph - Consent-Gated Context Between Agents]].