Skip to content

DL-340

The forge Linear provider gains an outbound SELF-DELEGATE write path: forge.CreateIssue carries optional DelegateSelf bool + Assignee string (Linear-only; GitHub ignores DelegateSelf), and Linear.CreateIssue sets input["delegateId"] to its OWN app-user id (resolved via a viewer { id app } sibling of the existing actorAttribution probe, and set ONLY when the probe confirms the actor is app-capable — a non-app principal’s viewer.id is never delegated to) and input["assigneeId"] when set — degrade-on-probe-failure (create without delegate + warn, never fail). The outbound shape ALWAYS sets BOTH slots (Matt, 2026-09-05): a human assigneeId alongside the app delegateId, never delegate-only, since Linear’s UI offers no delegate-without-assignee; the Assignee field stays typed optional (empty = unset) but the policy forbids the empty case on a self-delegated create, and the assignee UUID is caller-supplied, never defaulted in the provider. A live probe (2026-09-05, RIG-3302) confirmed an actor=app client-credentials token scoped read,write,app:assignable MAY self-delegate on issueCreate (success: true), and the assignee slot is INDEPENDENT (delegate-only leaves assignee null; a human assignee + app delegate coexist in one create) — so the self-delegate path is ratified over the agentSessionCreateOnIssue fallback, and the oracle mint scope moves to read,write,app:assignable (tools/forge-linear-token/index.ts). Outbound half only (app token, no user credential — DL-324 stays live); the inbound delegation round-trip is Record B

Status: Active (Matt, 2026-09-05)

Record: ../../server/compass-forge-self-delegate/design.md