The guest-to-operator bridge is the contract that lets public guest conversation become operator-visible clarity without pretending every guest is verified or every request is actionable.
The Guest Agent and Engine portions of this bridge were verified from source on 2026-08-12. The latest accepted Guest Agent same-deploy and model-provider proof remains the 2026-07-18 receipt for commit fbf77b662511cf004ee1f46787e05773a8a78d71. This documentation pass made no new live signal submission, provider call, live-data read, or authenticated Admin interaction; it does not freshly prove end-to-end delivery, rendering, or human action.
Product Role
Guest-facing Lucia is a front-of-house teammate.
Operator-facing Lucia is a calm operating partner.
The bridge between them must be structured, authenticated, privacy-safe, and honest about verification.
guest conversationstructured signaloperator review/link/action
Source-implemented bridge — verified 2026-08-12
The source-reviewed bridge and its downstream display contract are:
Evidence scope:
The 2026-07-18 Guest Agent runtime receipt proves that exact Guest deployment and its model-bearing path. It does not independently prove the Engine signal path, Admin visibility, booking linkage, or operator follow-through.
Routing Safety
Unlinked or merely claimed guest signals do not open a fake action workspace.
Operator-linked or verified signals may eventually route to a bounded action workspace when safe.
The deterministic routing contract is:
DAW remains an action/save surface. It must not become a fake destination for unverified guest claims.
Operator Review Doctrine
The operator can receive guest-facing context before the guest is verified.
But the operator surface must preserve the meaning of:
Operator language should distinguish:
Focus Ops Drift Protection
Operator-assistance behavior must prevent unlinked or merely claimed guest signals from drifting into similar existing bookings.
This matters most when two guests share:
Service overlap is never identity evidence.
Airport pickup overlap must never attach an unlinked guest to Synthetic Guest A, Synthetic Guest B, or any existing record. Those labels are explicitly synthetic.
Future Admin Surface
Engine source supports a protected downstream handoff, but the 2026-08-12 documentation review did not establish dated authenticated proof of current Admin rendering. The Admin behaviors below therefore remain downstream product expectations.
Roadmap Admin work includes:
See Also