Files
sure/app/models/assistant.rb
Claude ec38a89d0c Expose the Statement Vault to external agents over MCP
A user wants to manage patrimonial history — a document-backed record of a
family's wealth where every figure traces back to the statement it came from —
by pointing an external agent harness at Sure. That model belongs in the
harness, not in Sure: it needs numbered build deltas, golden tests and closed
periods that a mutable Postgres row cannot provide.

What Sure was missing was the seam. The Statement Vault already does most of
the work — original bytes retained, SHA-256 dedup, period detection, account
matching with a confidence score, reconciliation against ledger balances, and a
month-by-month coverage map — but it is reachable only from the web UI. An
agent could not archive a document, cite one, or check for gaps.

Adds five preview MCP tools over what already exists, plus a citation grammar
for values the agent writes:

- upload_account_statement, list_account_statements, get_account_statement,
  get_statement_coverage
- record_valuation, whose source citation is parsed rather than trusted:
  ["estimated: "] citation [" (grade: A|B|C)"]. An uncited or free-styled
  value is rejected at the write boundary instead of landing in the ledger
  looking authoritative.

link and reject are deliberately not exposed. Attaching a statement to an
account is the human's decision, and the vault UI is where it is made; the
agent reports the suggested match and stops there.

Assistant.function_classes now takes a user so preview tools stay out of the
default surface. They are hidden from tools/list and not callable by name
without the preference enabled, and the vault tools re-check the manager role
and per-account permissions, since MCP calls never pass through a controller.

Docs: the blueprint this implements, and a guide covering which side owns which
layer, the vocabulary map between the two, the monthly runbook, and the gaps
(non-user holders, non-statement documents, one value per date).

No migrations, no API endpoints, no UI.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JFDp9HhXDeswadu4cxFojn
2026-08-01 00:00:12 -07:00

70 lines
2.0 KiB
Ruby

module Assistant
Error = Class.new(StandardError)
REGISTRY = {
"builtin" => Assistant::Builtin,
"external" => Assistant::External
}.freeze
# Statement Vault + provenance tools, for users who opted into preview features
# in Settings -> Preferences. They back the patrimonial agent-harness workflow
# documented in docs/llm-guides/patrimonial-agent-harness.md.
PREVIEW_FUNCTION_CLASSES = [
Function::UploadAccountStatement,
Function::ListAccountStatements,
Function::GetAccountStatement,
Function::GetStatementCoverage,
Function::RecordValuation
].freeze
class << self
def for_chat(chat)
implementation_for(chat).for_chat(chat)
end
def config_for(chat)
raise Error, "chat is required" if chat.blank?
Assistant::Builtin.config_for(chat)
end
def available_types
REGISTRY.keys
end
# The single registry behind both the builtin chat and the /mcp endpoint's
# tools/list — a function class added here is immediately callable by an
# external agent, so pass the user to keep preview tools out of the default
# surface.
def function_classes(user = nil)
classes = [
Function::GetTransactions,
Function::GetAccounts,
Function::GetHoldings,
Function::GetBalanceSheet,
Function::GetIncomeStatement,
Function::GetBudget,
Function::ImportBankStatement,
Function::SearchFamilyFiles,
Function::CreateGoal,
Function::GetTags,
Function::CreateTag,
Function::UpdateTag,
Function::GetCategories,
Function::CreateCategory,
Function::UpdateCategory
]
classes += PREVIEW_FUNCTION_CLASSES if user&.preview_features_enabled?
classes
end
private
def implementation_for(chat)
raise Error, "chat is required" if chat.blank?
type = ENV["ASSISTANT_TYPE"].presence || chat.user&.family&.assistant_type.presence || "builtin"
REGISTRY.fetch(type) { REGISTRY["builtin"] }
end
end
end