channels/dm-app-review · the four unauthored items
Grouped by what they are, not by their letter. A and C have a surface, so they are
drawn as the screen. B and D are procedures, so they are drawn as the runbook you
would actually follow. The plan behind all four is
plans/rethink/dm-app-review-kickoff.md.
Today it answers 500. The request was refused by a foreign key, but the operator is told the server broke. Two honest answers exist and they look different. Pick one.
This flow is off and has run 47 times.
A session and a run event are meaningless without the flow that names them. The operator gets a path out, and the list never fills with rows nobody can remove.
Needs a migration. Two foreign keys get dropped and re-added, so it must be asked for before it is authored: one session authors migrations at a time.
This flow is off and has run 47 times.
Cheaper, and the audit trail survives. But archive does not exist yet, so this option is really two features, and until the second lands the operator still cannot clear the row.
FlowVersion cascades. FlowSession and FlowRunEvent do not.
A 500 says we broke. A 409 says you asked for something we will not do. Only one of those is true.
Recommendation: cascade. Say the word and it goes red-then-green behind a test that seeds a session and a run event.
The opener is a bare string. For a year the code said that was Meta's rule. It is not a rule, it is our code — the claim was withdrawn on 2026-08-01 and the docstring never caught up. Whether the right-hand version is even possible is unproven in both directions.
One string, sent as a private reply addressed by comment_id. Works. Boring. Real.
Settling it means sending one to a member of the public, which is exactly what App Review gates. Build after approval, not before.
comment-dm-opener.ts and comment-pipeline.ts). A withdrawn inference
sitting in a docstring is how it gets re-inherited as fact by the next session.
Instagram is proven. Facebook has been carried as the word “untested” since 2026-08-04 with no procedure attached. Not blocked by App Review: a tester-role account can DM the Page today, which is precisely what Standard Access permits.
facebook:dms to live. It reads off on prod. This is your flip, not a session's, and it goes back to off afterwards.dm trigger on facebook, set live. Use a nonsense keyword. A real word means a real customer can trip it.messaging row in webhook_events with signature_valid and processed true; a row in flow_sessions; the entry node ok in flow_run_events and the message on the phone.Rolling 30-day window from 2026-07-30. Submit after it and every permission must be re-exercised first. Two of the four are cheap. Two are not, and that asymmetry is the whole argument for not letting it lapse.
| Permission | How | Cost |
|---|---|---|
instagram_basic | Any Posts screen refresh hits GET /{ig-user}/media | One click |
instagram_manage_comments | Comment on our own post from a tester account, let the pipeline reply, hide it, unhide it | Five minutes |
instagram_manage_messages | A role-holding account DMs the business account, staff replies | Phone in hand, two people |
pages_messaging | The same round trip on Messenger to the Page | Phone in hand, two people |