Path: FDE blank to live
Audience: field engineers landing a tenant-level enhancement. Time: a multi-session engagement. Prerequisite: a provisioned (possibly empty) customer tenant; platform-ops access for the provisioning steps.
By the end of this path one scoped enhancement is live: a capability backed by a skill, a tool/MCP install, and a connector binding, verified in governed sessions and handed over with artifacts.
Work the stages in order. Each stage links the Build page that shows how; this path adds no new reference of its own. The full technical depth stays on the FDE path and the Connector SDK.
Stage 1: scope the enhancement
Section titled “Stage 1: scope the enhancement”- Read the FDE overview.
- Write the one-page scope doc first: Discovery — workload, systems, risk, exclusions,
org_idcontext.
Check: work owners signed off on “yes, this is the work,” with an observable pilot outcome defined.
Stage 2: build the environment narrow
Section titled “Stage 2: build the environment narrow”- Turn the scope doc into context, tools, and policy: Environment.
- Run the probe sequence as test sessions (happy path, boundary, draft quality, gate check, denial path, wrong-org check) before users arrive.
Check: each probe passes before the next; failures loop back to the build.
Stage 3: add the capability
Section titled “Stage 3: add the capability”- Capabilities that make the environment useful: Skills, tools and MCP — tools first, skills second, wiring verified last.
- Ground the wiring in the platform model: SDK concepts, SDK auth, SDK lifecycle.
Check: capabilities register extended (capability, layer, status, verification date, notes).
Stage 4: bind the connector-backed tool
Section titled “Stage 4: bind the connector-backed tool”- A connector tool is only real for the tenant when its binding exists: Extend a connector.
- Run the one fully worked binding pass: E2E: HubSpot inbound import.
- Building new coverage rather than binding existing: Build a connector and Examples.
Check: end-to-end chain verified in-environment (skill to tools via MCP install where applicable, under environment policy, gates firing). Honest gap: beyond HubSpot, bindings follow the same contract but have no step-by-step here yet.
Stage 5: prove it in governed sessions
Section titled “Stage 5: prove it in governed sessions”- Gate on risk: Approvals design — the approval matrix, approver roles, the reviewable decision experience.
- Pilot with real users on real goals (not staged demos); read denial patterns as design feedback and loop back.
Check: each gated class fires its gate with complete content; allow path runs with a complete record; deny path degrades gracefully.
Stage 6: hand over
Section titled “Stage 6: hand over”- Train each role on their slice with live pairing: Handoff. Users rehearse via the User sessions path.
- Deliver the pack: scope doc, environment spec, capabilities register, approval matrix, open items list, rhythm one-pager. Week-2 check-in scheduled.
Check: pre-handoff gate holds (pilot ran on real goals, artifacts current, probes re-run after the last change, open items ticketed with owners, none verbal).
Full reference for this path
Section titled “Full reference for this path”- Worked path: blank to live: the exact end-to-end checklist, practice vs product labeled per step.
- Connector SDK overview: concepts, auth, lifecycle, build/extend, examples.
What next
Section titled “What next”- Tenant admins own the result via the Day-0 admin path.
- Platform-side provisioning behind this path is the Platform ops path.

