Adds the missing pieces the wizard needed and the sidebar controls
around it:
- LoopsWizard is now a 6-step flow (identity → repo → task/topology
→ triggers → repeat → assign agents) plus the existing secrets
card. ResearchWizard picks up the same repo step and a hard gate
when the workspace has zero agents.
- New LoopStaffingStep with three tabs — Individual / Team /
Organization — that mix freely per loop; selections persist via
new loop_agents / loop_teams / loop_orgs join tables (0035
migration), each cascading on loop_id so hard-delete stays a
single-row DELETE.
- Backend CreateLoopRequest / UpdateLoopRequest accept the three
lists and apply_staffing does a transactional replace-all;
list_loops / get_loop hydrate the lists via a flattened
LoopWithStaffing response.
- LoopsList sidebar gains per-row enable/disable, edit (reopens the
wizard prefilled with the current loop, PATCHes on submit), and
delete with an inline confirm.
- NoAgentsGate blocks launching a loop or research topic from a
workspace with no roster; the sidebar `+` buttons also disable
with a tooltip pointing at the TEAM tier.
Not yet wired: the run driver still fills role slots from the
workspace-wide pool; teaching enqueue_iteration to prefer
loop_agents/loop_teams/loop_orgs is a follow-up.
Third commit of the Research + Loops arc. Lights up loops as durable
recurring topology executions:
GET /api/loops list workspace's loops
POST /api/loops create — returns webhook_token +
signing_key ONCE when webhook trigger
is enabled; never exposed again
GET /api/loops/:id detail
PATCH /api/loops/:id update definition
DELETE /api/loops/:id delete
POST /api/loops/:id/run trigger one iteration NOW
POST /api/loops/:id/enable set enabled=true
POST /api/loops/:id/disable set enabled=false
POST /webhooks/loops/:token public; HMAC-SHA256-verified
Scheduler (cm_runtime::spawn_loop_scheduler) wakes every 10s, queries the
partial index on (next_fire_at) for due loops, enqueues one topology_runs
row per fire with loop_id + iteration + parent_run_id chained back to the
previous iteration. Uses croner via the existing scheduling::next_occurrence
helper. Missed windows fire ONCE and skip the backlog — next_fire_at is
always computed strictly AFTER now(), so a late scheduler doesn't drain a
buildup.
Webhook signatures follow the same pattern as the Stripe billing webhook
(HMAC-SHA256 with constant-time hex compare). Token + signing key are
24-byte OS-RNG values; the URL uses base64-url for the token, and the
signing key is base64-std. Both surface exactly once at create time.
All three fire paths (scheduler, immediate-run, webhook) funnel through
`cm_db::repo::loops::enqueue_iteration` so the invariants stay in one
place. `iters` repeat policy is enforced by the scheduler tick; `until`
and `on_completion` land with the orchestrator hook in commit 4.
Adds cm-llm as a direct cm-api dep, getrandom for the webhook material
generator, and wires the scheduler spawn into the server binary alongside
the resume sweeper and outbox drainer.