Parent
Part of #709. Depends on the provider identity split issue created immediately before this one.
Problem
The first real campaign and a direct Devin work order proved idempotent comment posting but not operational result transport. Cursor campaign triggers currently target a review surface, and Devin did not acknowledge on this repository. A paid/manual provider must not appear ready merely because a token and executable-shaped registry entry exist.
Acceptance criteria
- Model hosted release qualification as a closed, explicit dispatch profile with separate auth, installation/capability, trigger, trusted responder, and adoption-result return checks.
- Cursor Cloud Agent uses its actual builder trigger contract, not BugBot/reviewer comments.
- Devin remains opt-in and paid; if the App or response-return capability cannot be verified, doctor and campaign dry-run report unavailable before dispatch with an exact setup/remediation path.
- Never automatically retry paid work. One explicit retry remains the only mutation after timeout.
- Add bounded offline fixtures for verified, unavailable, timeout, spoofed responder, and successful result return.
- Perform at most one live smoke per hosted provider after dry-run and record nonresponse as infrastructure evidence, not a passing qualification.
- Update release-qualification and provider docs. Preserve metadata-only privacy and never persist issue bodies, provider output, auth output, local paths, or secrets.
Parent
Part of #709. Depends on the provider identity split issue created immediately before this one.
Problem
The first real campaign and a direct Devin work order proved idempotent comment posting but not operational result transport. Cursor campaign triggers currently target a review surface, and Devin did not acknowledge on this repository. A paid/manual provider must not appear ready merely because a token and executable-shaped registry entry exist.
Acceptance criteria