Skip to content
Documentation menu

Systems

junelife-ops Model Context Protocol server

A Model Context Protocol server for a 388,000-page platform, where the expensive failure was never a bug — it was an agent acting confidently on a stale number.

A Model Context Protocol server for a 388,000-page platform where the expensive failure was never a bug. It was an agent acting confidently on a stale number, or re-opening a question the owner had already ruled on.

It runs in Python on Cloud Run under Google Cloud Platform, reads the estate over BigQuery and SQL, and exposes its tools to Claude through tool calling. The fix was architectural, not procedural. The rules stopped being documentation an agent could skim and became a surface it has to transact against.

The numbers

1 Estate writers exactly one tool writes to the estate, and only to the declared receipts sink

| 388,329 | Pages governed | junelifeinsurance.com, live sitemap index, 2026-08-08 | | 0 | Stored credentials | keyless auth via workload identity federation; zero plaintext service-account keys, marker-verified |

No tool files a ruling, edits the ledger, or fires a build. Mail and task tools reach systems outside the estate and each require their own per-action word.

The architecture

junelife-ops architecture Three agent seats call a governance Model Context Protocol (MCP) server on Cloud Run. The server reads the filed record and BigQuery, and writes only to a receipts sink. Charlie's pen is the human gate. The server refuses when the estate moved since the ruling. ARCHITECTURE JUNELIFE-OPS AGENT SEATS Build seat implements Audit seat verifies Infra seat deploys HUMAN GATE Charlie's pen build word · promote go no tool files a ruling, edits the ledger, or fires a build MODEL CONTEXT PROTOCOL SERVER JUNELIFE-OPS Python · Cloud Run · Google Cloud Platform (GCP) keyless · 0 credentials Governance precedence, not prose Protocol tools runs the filed protocol Byte verify bytes → summary only read tools · 1 estate writer measured 2026-08-08 THE ESTATE FILED RECORD Rulings › state › ledger order of authority, enforced 388,329 pages governed live sitemap, 2026-08-08 BIGQUERY · SQL Search analytics read-only RECEIPTS SINK the only place a tool may write tool calls read read write refuses when the estate moved since the ruling

Design decisions

Authority is enforced, not documented

Rulings outrank doctrine; doctrine outranks narrative. The precedence chain is executed by the tools that answer questions, so an agent cannot quote a handover over a ruling by accident.

Tools execute filed protocols

Protocol tools run the checked-in markdown protocol rather than reimplementing it. The file stays the single source; the tool is only the executor. Drift between doc and behaviour becomes structurally impossible.

Refusal is a feature

The pre-fire receipt binds a normalised snapshot of the estate. If anything moved between the snapshot and the go-ahead, verification refuses — the approval no longer describes reality, so it no longer counts.

One writer, by architecture

No tool can file a ruling, edit the ledger, or fire a build. Exactly one writes, to one declared sink. The owner’s authority is not a policy an agent is asked to respect — it is a capability the agent does not have.

Bytes, never summaries

Verbatim quotes are checked against stored raw bytes, not headers or prior summaries. Identity flows bytes → summary and never the reverse, which is how a paraphrase stops being able to impersonate a source.

Every figure is a pointer

Returned numbers are explicitly typed as pointers, never facts, and must be re-measured from disk before any irreversible action. Two states — unparsed and absent — are reported and never inferred from prose.

What it was built after

The keyless architecture in the numbers above is not a preference. It is the cure from Entry 001 of the incident log: a compromised

service-account key, $11,089.77 billed against $0.71 expected, charges accumulated across roughly 48 hours before the account was suspended.

Every user-managed key was disabled and five plaintext key files shredded — including two that survived in cloud-synced folders and were found only because a previously killed sweep was re-run. The project was reinstated 2026-06-17 and the full amount was reversed by two banks independently as fraud. The case was covered by The Register on 2026-07-03.

The lesson that outlived the incident: a disabled key does not help if a copy is sitting in an archive nobody remembers restoring. The cure had to be the absence of the key, not the revocation of it.

That is why this server holds zero credentials rather than holding them carefully.

The peer

callcharlie-ops is the second server, built to the same doctrine for a different organ: this one governs a publishing estate, that one governs a corpus. The constraints diverge where the failure modes do.

↑↓ navigate↵ openesc close