Transparency
What Services stores
Its own PostgreSQL database has these tables and nothing else: manifests, releases, release_log, trust, trust_history, playground_runs, plus the event outbox. That is release metadata keyed to Network app ids, trust tiers (metadata), validated manifests, and a log of playground runs (who ran what, the outcome and the problem code).
What Services does not store
- Projects, members, apps, credentials, grants and quotas: OpenVibe.Network owns them; Services shows what Network answers for the signed-in person.
- Client secrets: Network returns a new secret once, Services shows it in that response and keeps no copy. Network itself stores only a hash.
- Access tokens: your Network session sits in httpOnly cookies in your browser; tokens a playground uses exist only for that request.
- Webhook secrets typed into the tester: used for one computation, then dropped.
What Services does not do
- It does not enforce quotas: each service that owns a capability does (quotas are shown as recorded limits).
- It does not issue tokens or decide grants: Network does.
- Trust tiers never grant anything: authority comes only from grants.
Events it publishes
services.app.published, services.app.deprecated, services.app.revoked, services.moderation.action when a release is published, deprecated or revoked (through OpenVibe.Events once its relay is configured).
Status
Stage alpha.
Not yet
- The playgrounds have never been used on production (0 playground runs); the one production end-to-end run used curl, and it is not a committed, repeatable check
- Usage counts come from the services' hourly *.usage.recorded rollups (Network adds them up per day; the current hour is not counted) and cost lives in Billing, not on the usage page; no trace or error dashboards beyond the sampled failures
- Billing sandbox, Chat bot and Realtime playgrounds; CLI and scaffolding; templates
- Consent screen for third-party production apps (a Network gap)
- Governance material (code of conduct, contribution guide, contributor ladder, moderation policy) is written as drafts pending owner review: not in effect, not indexed
- plan T13 step 4 done in OpenVibe.Contracts v0.110.0 (services.resource.read is registered, active and first-party), step 5 done in Network, step 7 (read model + ingestion), steps 9-15 (console, control operations, recipes, usage, deploy)