2026-10-03 · Creator Publishing Hub Personal Social Desk, Audience Profile Scanner, Engagement Watcher, Owned-device Agent Data API, Image Intake
Social Desk preserves confirmed profile evidence, reads retry scan results, exposes per-person follow history and supports verified owned-device writes and image processing.
What changed
- Existing retry review files join the profile-result pull so their saved observations can appear in coverage and follower records. No recorded engagement is never treated as proof of inactivity.
- An explicit private owner-confirmed death workflow records an exact profile, month-only date and evidence, with Facebook memorialization recorded separately. Confirmed identities are protected from ordinary activity alerts, new cleanup or purge work, birthday suggestions and pinned-post tag suggestions.
- Ordinary activity prefers the newest explicitly owner-authored nonpinned visible post. Pinned-only and unproven-author observations leave ordinary activity unknown.
- Complete coherent follower rosters can create per-person possible-unfollow evidence when earlier exact follower proof exists. Partial captures retain omitted people. Follow notifications update person records and the follower ledger without manufacturing engagement scores.
- Follow history and an Unfollow review view expose sourced events and resolutions. Stable capture receipts, exact identity checks and newer-proof preservation protect retries and concurrent edits.
- A separate owned-device API provides bounded reads and serialized revision-checked writes for notes, review drafts, relationship tracking, observations and photos. Follower workflow writes have an additional disabled-by-default gate.
- New image intake runs a pinned local pixel-cleanup backend before accepting a WebP derivative. Private originals remain intact; failed processing or fidelity checks hold the result. Dimensions, transparency, lettering and measured image fidelity are checked.
- Packaged scanner support provides disjoint bucket leases, a shared profile-attempt ceiling, durable per-profile checkpoints, login-wall cooldown and forced-logout stopping. Known login-wall retries default to deferred until the coordinator final phase.
- The birthday sender adds a same-day check immediately before the native click and a midnight recheck after audit. Protected exact profile aliases cannot bypass the server preflight.
- Existing views, detailed follower statistics and drilldowns remain available, with new deceased and unfollow-review filters in the readable full-window layout.
Verification
- The complete local application regression suite and feature contract passed before packaging, including actual route persistence, identity conflicts, partial-roster withholding and ledger-first interrupted-save recovery.
- Scanner support passed twenty Node tests and seven Python tests on both the development machine and Linux with synthetic transport. The tests cover concurrency, permanent guards, quota reservation, cooldown, forced logout, all ten profile routes, pin and authorship rules, and owner evidence protection.
- The configured image backend completed a real transparent-image fixture with original dimensions and alpha preserved. A separate fidelity fixture was held as expected. Backend execution is distinct from proprietary watermark-detector verification.
- The maintained Linux installation passed all 782 application tests plus the scanner fixture suites. All nine PWA views rendered; deceased protection, follow history and detailed follower statistics were independently reviewed in the live interface.
- An owned device completed a real revision-checked relationship note write and received the original durable receipt on replay. A real private photo upload produced an accepted WebP with byte-verified original preservation, matching dimensions and exact alpha; its cloud transfer remains pending.
Rollout
The maintained PWA and image intake are installed and independently reviewed. Owned-device reads and writes are verified with the 2026.10.3.06 connection patch. Scanner support remains packaged pending the existing coordinator plan, a verified idle transition, shared current-day attempt accounting and a fresh-observation canary. Browser extension activation and native notification production remain pending.
Updating
- Refresh or reopen Social Desk after the maintained installation is verified to load the new app shell. No audience database migration is required.
- Agent access requires an already owned, untagged private-network device and local server configuration. Follower workflow writes remain disabled during the fresh-rescan pass.
- The scanner coordinator must preserve its queues and the existing signed-in browser while assigning disjoint buckets and completing the documented idle checks. The packaged source does not start workers.
- The reviewed Engagement Watcher must be loaded into the browser before its birthday click guard can run. Installation does not send a greeting.
Scope and limitations
- Fresh rescan coverage remains partial. An active timer, aggregate import date or failed attempt does not prove a successful fresh profile observation. Name-only records cannot be visited until an exact profile link is resolved.
- No actual follower removal or new purge queue is authorized by this update. Owner evidence does not create a Facebook memorial label.
- Per-person notification ingestion is implemented, but its native notification capture producer remains pending. A possible unfollow remains review evidence rather than a platform-confirmed unfollow.
- Pixel regeneration is best effort; proprietary invisible watermark detection and exact logo identity are not certified. Existing saved media are not silently reprocessed.
- Live browser authentication, checkpoints, inaccessible profiles and missing public facts can still limit capture. The update does not reconstruct unavailable historic performance data.