Fact 203
Effective April 1, 2026, Iris owns Lantern’s customer promise, adoption criteria, and UI interpretation.
Source evidence (1)
003397Mar 26, 2026 / 12:08 UTC-04:00
The Lantern strategy meeting is complete. After reviewing the frozen operating evidence and the divergent Harbor Health and Mosaic Commerce requests, Hema and Theo decided that Lantern will become a Sphere product-platform line effective April 1, 2026 rather than remain only a narrow add-on. Through March 31, the existing authorization and operating terms remain unchanged. Effective April 1, Iris owns the customer promise, adoption criteria, and UI interpretation. I retain freshness, tenant-isolation, authorization-denial, latency, and error monitoring plus the shared data contract, source-registration safety gates, and failure-mode review. Product Engineering owns implementation. Lantern explains provenance-backed service and system state, Cardinality Guardrails owns pipeline limits and cost signals, and the owner map remains the source of published responsibility. Lantern will not produce release-readiness judgments or employee-performance interpretations. Any new source type must enter through shared registration with tenant-scoped authorization before source access, required provenance and source timestamps, explicit unknown for stale or missing input, excluded-field checks, and a successful safety rerun before customer use. From April 1 through September 30, Harbor Health and Mosaic Commerce—and no other accounts—are authorized for continued read-only access through the shared authorization wrapper, limited to provenance-backed deploy movement, published service ownership, timestamped incident-load summaries, and explicit unknown states. No additional account, cost data, CSV export, raw incident text, internal room metadata, employee identifier or comparison, inferred or unpublished ownership, internal-only fallback data, or write capability is authorized. An authorization-wrapper bypass, adapter call after denial, cross-tenant material, stale or missing source rendered as anything other than explicit unknown, deploy event without required provenance, unpublished ownership, incident-load summary without its source timestamp, exposure of any excluded field, or loss of read-only enforcement immediately suspends both accounts pending correction and a successful rerun of the affected safety check. Latency and other errors do not independently suspend access unless they cause one of those violations. Convert “Lantern platform boundary proposal — March 26 strategy review” into the final decision record, including the frozen evidence reviewed, and append the transition decision to “Lantern October 8 final-review decision record,” clearly preserving the current terms through March 31 and dating the new direction, role split, and access terms to April 1.
Message 003397 in history