Operational freshness and key-copy improvements
- • The agency dashboard now provides a Copy ID action beside every stored key identifier. Full API secrets remain copyable only during their one-time create/rotate reveal; existing full secrets are never recoverable from storage.
- • /api/v1/data-freshness and the equivalent MCP resource now report durable ingestion status, validation, row count, run outcome and age for monitored dataset families instead of placeholder null timestamps. Unknown remains explicit until a governed importer records a successful run.
- • Scheduled freshness monitoring, read-only Stripe-to-agency reconciliation, partitioned usage rollups, bounded raw-ledger retention and direct AI COGS/token monitoring are live operational controls. No public response exposes internal supplier-cost headers.