# Credential page release deployed, 2026-09-10

Release `20260910-012403-4086e43` was activated by the governed module after the owner ran the
launcher. Application commit `4086e43e451f9aeb67926d0c350bbb249598253d`; the deployment tooling is
the same commit (candidate fingerprint `58978f83…`, unchanged from the previous release, 237 files).
It carries the three commits after `829c4bb`: the shared legacy-docs ownership guard in the IIS
adapter, the previous deployment record, and the credential page fixes (self-refresh while a test
is in flight, "Last verified call" written from the proving test, the licence switch out of the AI menu).

Preparation: `local\deploy\Prepare-Deploy.ps1` (gate clone, publish, candidate build, fingerprint
equal to the clean export). WhatIf ran at 01:25:59 UTC, outcome Planned, 161 plan entries,
production state untouched. Execute ran from 01:56:54 to 01:57:37 UTC: `Ok: true`,
`Outcome: Executed`, nothing thrown, 12/12 checks, transaction
`7828ed0d-6055-43b8-8ca8-acbac3ef3a5d`, IIS backup `SibylaE2-20260910-015653`. Evidence:
`local\artifacts\credential-page-release-260910\` (WhatIf and Execute result, journal, transcript,
privilege proof, the launcher and the preparation log).

Independent verification at 01:59 UTC, outside the runner:

- all three `CURRENT.txt` pointers name the release and `PREVIOUS.txt` names `20260909-175028-829c4bb`;
- the worker service is Running from the release tree, process started 01:57:14 UTC;
- web `/`, API `/health`, API `/health/ready` and docs `/naming-glossary.md` answer 200;
- the three IIS sites and pools are Started on the release paths;
- the deployed `Sibyla.Web.dll` carries a label introduced in `4086e43` and none from the later
  alerting commit, so the binary is the commit the gate names;
- the worker's first report after restart (01:57:15 UTC) reads signed in, `oauth_token`, source
  `token`, one active credential: extraction still runs on the stored credential.

Rollback target on every host: `20260909-175028-829c4bb`. C6 is unchanged: NP Group's 52 sync runs
remain protected and nothing here is a cutover. The alerting feature committed after this release
(`7f77835`) is not deployed; it needs its own release and an `Alerts` section in the web host's
secrets file before it sends anything.
