---
status: reconciled-partial
coverage_depth: deep-for-authoring-and-durable-receipt
last_walked: 2026-07-20
last_reconciled: 2026-07-20
specs:
  - apps/oshun/web/e2e/lilith-studio-new-scene.spec.ts
  - apps/oshun/web/e2e/lilith-studio-shell-smoke.spec.ts
  - apps/oshun/web/e2e/lilith-scene-editor-smoke.spec.ts
  - apps/oshun/web/e2e/lilith-scene-editor-deep.spec.ts
  - apps/oshun/web/e2e/lilith-scene-publish.spec.ts
source: WALKTHROUGH/journeys/lilith-studio-tara-scene-publish.md
---

# Journey result: Lilith Studio Tara scene publish

- **Walked**: 2026-05-29 at `bf12b0f7d8c291499e1df1ec75d4bd21acf3f6b1`, with the
  access-denied link repaired later in
  `c9ff6edc40232c1f42ae0bee896e663577cdda41`. The retained walker was an
  ephemeral `/tmp` script.
- **Reconciled and re-run**: 2026-07-20 at source and published tip
  `343b87fe359270d1ad756050f2f67a1ffebd52a4`. Store, route, export, erasure,
  real-PostgreSQL restart, two-process exact-bundle, and five focused Chromium
  publish cases passed. The surrounding historical shell/editor observations
  retain their cited evidence dates.
- **Verdict**: **partial** — current evidence is deep through the local Tara
  scene editor and its durable exact-manifest owner receipt. The named
  end-to-end journey still stops before editorial approval, audit/immutable
  provenance lineage, supersede/withdraw, and customer read-back on `/tara` or
  `/lilith`.
- **Current authority**:
  [`WALKTHROUGH/journeys/lilith-studio-tara-scene-publish.md`](../journeys/lilith-studio-tara-scene-publish.md)
  The journey coverage row rates the authoring layer `deep`; the stricter
  Results ledger remains partial for the unfinished publication legs.

## Result at a glance

| Evidence layer       | Historical 2026-05-29 observation                                                                                        | Current-source proof                                                                                                                                                                                         | Authority limit                                                                                                                      |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ |
| Route and role gate  | `/lilith`, `/lilith-studio`, `/lilith-studio/tara`, and `/lilith-studio/scene/new` rendered; non-editorial access denied | All 12 current Lilith/Lilith Studio inventory routes survive; shell specs prove editorial entry and signed-in viewer denial                                                                                  | Anonymous redirect and signed-in denial are proven; the fallback's “Request operator access” still only opens `/profile`             |
| Thin scene creation  | `/scene/new` POSTed to `/v1/lilith-studio/scenes`                                                                        | Live-BFF create, pending lockout, keyboard kind selection, normalized session index, validation, offline error, entry links, and mobile standalone                                                           | Creates an authoring row; it is distinct from the full Tara editor and its durable release receipt                                   |
| Tara scene editor    | Not exercised because the dated walker could not obtain editor scope                                                     | Every asset/control, keyboard + drag placement, graph, lighting/audio/binding, 4,096-attendee model, accessibility gates, manifest, fixture provenance, draft reset, service-worker replay, and mobile width | Fixture-backed authored metadata and deterministic simulation—not live media, 4,096 clients, or immutable provenance                 |
| Release receipt      | The old result described reachability, not approval or consumer publication                                              | Scope-gated exact-manifest POST waits for durable commit; stable replay, owner-only minimized list, manifest digest, PostgreSQL restart recovery, DSAR, erasure fence, retention, and browser success passed | Durable receipt only; no tenant placement, audit event, approval identity, immutable asset resolution, withdraw, or customer release |
| Customer publication | Implied by the historical result title, not walked                                                                       | No `/tara` or `/lilith` consumer imports the publish store                                                                                                                                                   | Absent: the receipt is not an approved scene edition and is not customer-visible                                                     |

## Evidence map

The solid path is the current deep boundary. Dashed edges are the still-missing
meaning of “publish to Tara.”

```mermaid
flowchart LR
    A[Editorial session] --> B[Lilith Studio shell]
    B --> C[Tara scene editor]
    C --> D[Readiness gates]
    D --> E[Exact-manifest publish POST]
    E --> F[Durable owner receipt]
    C --> G[Fixture manifest and provenance]
    G --> F
    F -. not linked .-> H[Editorial review identity]
    H -. not approved .-> I[Durable release edition]
    I -. not consumed .-> J[Tara and Lilith surfaces]
```

## Proven observations

### The historical route repair remains valid

- The walked commit and repair commit both resolve to immutable repository
  objects. The current route inventory includes `/lilith`, the ten
  `/lilith-studio*` entries, and `/lilith-studio/tara`; none of the four dated
  surfaces has regressed to a missing route.
- `/lilith-studio/tara` remains a read-only server view over Tara today,
  sittings, and ritual responses. It describes what the BFF currently serves; it
  is not a preview of a newly authored scene edition.
- `/lilith-studio/scene/new` remains a member-scoped live-BFF form for a title,
  `sit|ritual|reading` kind, optional path, and session index. Its accepted row
  opens the separate `/lilith-studio/scenes` workspace.
- The dead `/profile/operator-access` CTA was repaired to `/profile`. That
  removes the 404 but does not create an operator-access request or governance
  workflow; its visible label still promises more than the link performs.
- The old “all render/route” and correct access-denied observation therefore
  survives as a dated smoke result. Its missing `/tmp` walker prevents selector,
  environment, and raw-report inspection.

### The current editor proof is deep and appropriately bounded

- `lilith-scene-editor-deep.spec.ts` walks every scene-editor control, all asset
  handles and placement buttons, browser drag/drop, graph selection, lighting,
  audio, binding, capacity, sharding, accessibility, readiness, manifest, and
  provenance selections, then proves edit-after-publish returns the browser to
  draft.
- The authoring state includes four assets and zones, three selectable lighting
  presets, three rights-cleared audio beds, three triggers/actions, four
  capacity tiers, three sharding profiles, and two options per accessibility
  dimension. Control coverage is broad enough to earn `deep` at this layer.
- The 4,096-attendee result is a pure browser model. The tested stadium +
  interest-management configuration reports 16 shards; it is not traffic,
  networking, or runtime-load evidence.
- The accessibility gate exposes row-level text and remediation, blocks publish
  while any requirement fails, and retains keyboard placement as an equivalent
  to drag. The exact route is also replayed from the real service worker while
  offline and checked at a 390px standalone viewport.
- Provenance rows are fixture declarations rendered by
  `LilithProvenanceInspector`. No cited test resolves them to signed immutable
  asset records.

### “Published” currently means a durable owner receipt

- The editor sends `sceneId`, title, capacity tier, shard count, and its exact
  manifest JSON to `/v1/admin/studio/scenes/publish`. The route derives the
  owner from validated auth and returns only after the complete snapshot
  commits.
- `StudioScenePublishStore` is a strict schema-v1 owner authority over the
  Postgres-backed snapshot sink. Exact retries have one stable identity; restart
  recovers the same receipt and manifest digest. GET lists only the exact
  owner's unexpired receipts and never returns raw manifest JSON.
- The exact-owner DSAR contains the original manifest bytes. Signed
  generated-artifact erasure removes the subject, preserves adjacent owners, and
  persists a fence that rejects stale recreation. The canonical 365-day window
  has startup and weekly legal-hold-aware purge execution.
- The route still never calls the admin editorial release-stream service, writes
  an audit event, resolves declared provenance to immutable assets, identifies
  an approval decision, or provides withdraw/supersede endpoints.
- The browser publish spec does reach the real route/store, but it intercepts
  the island request and reissues it with a server-generated `studio:editorial`
  development bearer because the in-browser API token is null in E2E. Natural
  browser-token propagation is not proven by that case.
- `/tara` and `/lilith` still do not consume the receipt. Re-editing clears the
  local surfaced identity while the prior durable row remains until retention or
  signed account erasure.

## Boundaries and gaps

- **Deep authoring is not end-to-end publication.** The coverage grade is earned
  through the editor and durable receipt, not through approval or customer
  availability.
- **A release-stream string is not a release stream.** It is derived from scene
  id + a stable content/owner digest and has no approval event log or workflow
  consumer.
- **A durable receipt is not a distributed release authority.** The bounded
  whole-snapshot queue is per process and has no distributed compare-and-swap;
  concurrent BFF writers can still lose an update.
- **Exact bytes are not semantic publication validation.** Placements,
  interactions, accessibility evidence, provenance, and scene graph cross the
  boundary, but the JSON object is not checked against a complete immutable
  release schema or asset resolver.
- **Fixture provenance is not ledger provenance.** The inspector renders
  authored declarations without signed-asset read-back.
- **A modelled audience is not a load test.** The 4,096/16-shard result
  exercises deterministic readiness logic only.
- **The browser auth seam is assisted.** Server-side bearer injection proves
  route behavior, not the editor's natural access-token path.
- **The access CTA is a live link, not a request.** `/profile` cannot grant or
  submit editorial access.
- **The approval bridge is navigational only.** A header link reaches the V1
  workflow surface, but no shared scene identity enters its evaluator or the
  operator queue.
- **Customer and audit read-back are absent.** `/tara`, `/lilith`, cold PWA,
  entitlement/tenant policy, crisis framing, audit reconstruction, and
  supersede/withdraw remain open.
- **The focused execution is not full-journey proof.** The durable publish spec
  was rerun in Chromium against the exact production BFF bundle; the historical
  12-route shell sweep and other editor specs were not all rerun in this slice.

## Re-run evidence

Run the live BFF and production-like web app at one immutable commit, then run
the focused specs sequentially with one worker:

```bash
pnpm --dir apps/oshun/web exec playwright test -c playwright.config.ts e2e/lilith-studio-new-scene.spec.ts --project=chromium --workers=1
pnpm --dir apps/oshun/web exec playwright test -c playwright.config.ts e2e/lilith-studio-shell-smoke.spec.ts --project=chromium --workers=1
pnpm --dir apps/oshun/web exec playwright test -c playwright.config.ts e2e/lilith-scene-editor-smoke.spec.ts --project=chromium --workers=1
pnpm --dir apps/oshun/web exec playwright test -c playwright.config.ts e2e/lilith-scene-editor-deep.spec.ts --project=chromium --workers=1
pnpm --dir apps/oshun/web exec playwright test -c playwright.config.ts e2e/lilith-scene-publish.spec.ts --project=chromium --workers=1
```

Retain the exact commit, BFF backing tier, browser/storage state, JSON/report
artifacts, and the publish-store restart result. A future complete gate must
carry one immutable scene identity through manifest persistence, review,
approval, durable edition, customer cold-load, and audit reconstruction.

The 2026-07-20 focused rerun used the exact rebased production BFF bundle
(34,982,194 bytes; SHA-256
`68c46219f13f2f7dafb25632f82924ef0cb2146d44085569469c22aebcfaeba4`).
Store/route/export/erasure tests passed 53/53, the real-PostgreSQL restart and
fence integration passed 1/1, and `lilith-scene-publish.spec.ts` passed 5/5 in
Chromium with one worker. Two clean BFF processes recovered receipt
`scene-publish-e25f2c4e84d1077b3ac2396ebb5cb89d9e4830257e86a5d410f17f75fd49d0ac`
and the same manifest digest. The isolated database, Redis namespace, and ports
were removed after proof.

## Source trail

- [Current journey contract](../journeys/lilith-studio-tara-scene-publish.md)
- [Current coverage registry](../journeys/coverage.md)
- [Lilith Studio access gate](../../apps/oshun/web/src/app/lilith-studio/layout.tsx)
- [Access-denied fallback](../../apps/oshun/web/src/app/lilith-studio/LilithStudioAccessDenied.tsx)
- [Thin scene-create form](../../apps/oshun/web/src/app/lilith-studio/scene/new/StudioNewSceneForm.tsx)
- [Tara read-only mirror](../../apps/oshun/web/src/app/lilith-studio/tara/page.tsx)
- [Tara scene editor](../../apps/oshun/web/src/app/lilith-studio/scenes/TaraSceneEditor.tsx)
- [Scene publish route](../../apps/oshun/bff/src/routes/admin-studio-scene-publish.ts)
- [Scene publish store](../../apps/oshun/bff/src/studio/studio-scene-publish-store.ts)
- [External scene contract](./external-dependencies/studio-scene-contract.md)

## Cross-references

- [Lilith Studio shell evidence](../customer/10-lilith/lilith-studio.md)
- [Scene editor evidence](../customer/10-lilith/lilith-studio-scenes.md)
- [Tara consumer evidence](../customer/03-tara/tara.md)
- [Lilith public surface evidence](../customer/10-lilith/lilith.md)
- [Editorial review journey](../journeys/editorial-review-approval.md)
- [Scene keep-and-share journey](../journeys/scene-keep-and-share.md)
- [Current completeness audit](./v1-completeness-audit-2026-06-22.md)

## Open questions

- Should the current action be renamed “Record release receipt” until a reviewed
  edition exists?
- Which complete publication schema and asset resolver will validate the now-
  retained manifest's immutable references, tenant/surface target, and policy
  versions?
- How will one scene identity enter automated checks, human review, audit
  events, publication, supersede/withdraw, and erasure workflows?
- Which distributed compare-and-swap or row-level authority replaces the
  per-process whole-snapshot queue across multiple BFF instances?
- When will `/tara` consume only approved editions and prove the result in a
  clean entitled customer context, including cold/offline behavior?
- What first-class workflow should the access-denied CTA open to request,
  approve, expire, and audit `studio:editorial` access?
