Block a user
a member whose backend 400s dies in one second, and fleetd returns the lost turn as a successful empty reply
CB-634: deliver IDE guidance as an on-disk overlay, not the system-prompt charter
broker: uriEnv config + non-fatal unreachable broker on boot (closes #151, #152)
CB-633: constrain a member's environment with a real allow-list (memberCredentials.policy)
CB-632 unit 3: rename the example config file and prefer fleetd.yaml at startup
CB-624: add scripts/rename-checkout.sh (rename checkout claude-bridge -> fleetd)
CI: drop host port mapping on rabbitmq service in contract job
CB-622 Unit A: register fleet_* MCP tools, keep bridge_* working
CB-622: rename bridge_* tool names to fleet_* in Markdown docs
CB-622 (unit C): rename bridge_* tools to fleet_* in scripts, e2e tests, config; mount name bridged -> fleetd
CB-617 Unit B: role agent definitions
CB-617 Unit A: role charter via file, not argv
CB-596: config-driven deny-by-default member credential policy
CB-586: prune refs/wip/* whose tree is reachable from main and older than 24h
CB-606: refuse an unknown auth.mode/placement at config load
CB-604: reject an unrecognized profile kind at config load
CB-582: make a pending bridge_ask question visible on the lead's poll cadence
CB-584: carry agentSessionId on a failed ticket's ReleaseDetail
CB-600: make it safe to install the launchd agent
CB-602: catch a config key that never reaches the example