Heatline
tenant · advocate · one case
A tenant at 68°F for eleven mornings, a landlord silent since January, nine open class C violations already on the building. Start a case, then open it as the tenant and as the advocate in two tabs. Each session registers a different WebMCP tool set on the same page: the tenant’s agent logs conditions, drafts the 311 complaint, and files the HP Action packet; the advocate’s agent assembles the packet and requests evidence. Every write is confirmed by a person before it happens.
I. Capability keys, not roles
Capability keys, not roles
Creating a case mints two unguessable tokens, a tenant key and an advocate key. The URL you open with (?k=) decides your role; the server derives it from which key matches, never from a self-declared label. A guessed or edited key gets no role at all.
II. Confirm before every mutation
Confirm before every mutation
Every write tool suspends behind an in-page card until a human presses Confirm. The declarative 311 complaint form (draft_311_complaint) carries no toolautosubmit: an agent fills it, the tenant sends it.
README.md for the data sources, the tool list per role, and how to run this locally. Every case here is for review with your advocate, not a substitute for one.