Blocked-by: ruling G on #17396 (5642381255, addendum 5642795312) — package-authored scheduled work stays OFF for multi-tenant kernels. Re-entry, falsifiable: the maintainer turns package-authored scheduled work ON for a multi-tenant kernel, or a cloud customer asks for a packaged schedule under isolated.
Filed by the director seat (objectstack#12708, session_01AsCNgFBs8HCjwhyHQsFbx3) on the maintainer's ruling A on #20619 (batch #244, 2026-09-29; the ruling record is on #20619): ruling G is kept and #20619 becomes the docs line; this card records the end state so the shape is not re-derived when the premise changes. ⛔ Not a claim; ⛔ not to be dispatched while blocked.
The shape (option B of the #20619 packet, 5888104788)
- Spec (
packages/spec/src/automation/schedule-organization.zod.ts, a domain:spec child): config.organization: '*' accepted on a schedule / time_relative flow only when the flow is package-authored; a hand-authored flow keeps declaring one organization. The 2026-09-08 rule's substance is kept: every run acts as exactly one declared organization, never a guessed one.
- Services (
packages/services/service-automation bind gate, packages/triggers/trigger-schedule): under isolated with the deployment switch ON, a '*' flow is armed once per installing organization and each run executes as that organization; per-organization run accounting; a cost ceiling (runs per organization per cadence) is part of the deliverable, because ruling G's premise is cost.
- "Each organization with this package installed": on the cloud,
sys_package_installation (cloud-provided) is the source; on the OSS runtime a package loads for the whole kernel, so '*' means every organization — the card states both.
- Mainstream reference: Salesforce managed packages — each subscriber org schedules its own copy of the package's jobs, each run inside one org.
Confidence gaps (from triage, unchanged)
- Not measured: whether any
isolated deployment runs with the switch ON.
- Not measured: whether the cloud records a package installation per organization.
Related: #20619 (the docs line, ruling A), #17396 (ruling G), #18378 (ruling A′ for group), cloud#2216 (HotCRM's flows on record).
Blocked-by: ruling G on #17396 (
5642381255, addendum5642795312) — package-authored scheduled work stays OFF for multi-tenant kernels. Re-entry, falsifiable: the maintainer turns package-authored scheduled work ON for a multi-tenant kernel, or a cloud customer asks for a packaged schedule underisolated.Filed by the director seat (objectstack#12708,
session_01AsCNgFBs8HCjwhyHQsFbx3) on the maintainer's ruling A on #20619 (batch #244, 2026-09-29; the ruling record is on #20619): ruling G is kept and #20619 becomes the docs line; this card records the end state so the shape is not re-derived when the premise changes. ⛔ Not a claim; ⛔ not to be dispatched while blocked.The shape (option B of the #20619 packet,
5888104788)packages/spec/src/automation/schedule-organization.zod.ts, adomain:specchild):config.organization: '*'accepted on aschedule/time_relativeflow only when the flow is package-authored; a hand-authored flow keeps declaring one organization. The 2026-09-08 rule's substance is kept: every run acts as exactly one declared organization, never a guessed one.packages/services/service-automationbind gate,packages/triggers/trigger-schedule): underisolatedwith the deployment switch ON, a'*'flow is armed once per installing organization and each run executes as that organization; per-organization run accounting; a cost ceiling (runs per organization per cadence) is part of the deliverable, because ruling G's premise is cost.sys_package_installation(cloud-provided) is the source; on the OSS runtime a package loads for the whole kernel, so'*'means every organization — the card states both.Confidence gaps (from triage, unchanged)
isolateddeployment runs with the switch ON.Related: #20619 (the docs line, ruling A), #17396 (ruling G), #18378 (ruling A′ for
group), cloud#2216 (HotCRM's flows on record).