# promote_docx_candidate

[MAINTENANCE] W1-K — explicitly promote a status='candidate' docx derivative to be THE accepted derivative for its source_path, demoting whatever derivative previously held that role (if any) to status='superseded' in the same call — a real state transition with an audit trail (promoted_at/promoted_by_session_id on the newly-accepted row; superseded_at/superseded_by_derivative_id on the demoted one), mirroring promote_experiment_run's promotion-pattern precedent. Idempotent on an already-accepted derivative (mirrors promote_research_run's idempotency guard): a repeat call on the same derivative_id returns the existing accepted state unchanged (idempotent_retry=true), never a duplicate transition or an error. Rejects with {error} when the derivative's status is 'superseded' — a superseded derivative can never be re-promoted; register a fresh candidate instead. Returns {derivative_id, derivative, superseded_derivative_id, idempotent_retry}. Persistent-state disclosure: on hosted Meridian, supplied text and project/session metadata -- including task log entries, pinned decisions, sprint items, notes, handoff/goal state, and HITL queue items -- are sent to and stored in Meridian's service, in an isolated per-tenant Postgres database (Neon); self-hosted deployments keep the same categories in the configured local SQLite/Postgres database. This data is visible in the dashboard and API, and may resurface in later project context or handoffs. Notes and pinned decisions can be deleted individually; task log entries and sprint items can be deleted via the dashboard/API (not exposed as an agent-facing tool); HITL queue items and handoff state have no per-record delete. Full removal of any of this data is available via project or account deletion, using the documented controls. Do not include secrets.

Agent View of the PolicyLayer registry record for `promote_docx_candidate`. HTML page: https://policylayer.com/tools/io-github-ajc3xc-meridian/promote-docx-candidate

## Facts

- Tool: `promote_docx_candidate`
- Server: Meridian (`@meridianmcp/mcp`) — https://policylayer.com/tools/io-github-ajc3xc-meridian.md
- Install: `npx -y @meridianmcp/mcp`
- Homepage: https://github.com/meridianmcp/Meridian
- Risk category: Write (Medium risk)
- Registry record: grade D, identity unverified
- Server auth posture: gated
- Server CORS policy: *
- Server rate-limited: no
- Parameters: 4 (1 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `project_id` | string | no |  |
| `session_id` | string | no |  |
| `project_name` | string | no | Project name — an alternative to project_id; resolved to the id internally. project_id wins if both are given. |
| `derivative_id` | string | yes |  |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "promote_docx_candidate",
    "arguments": {
      "derivative_id": "<derivative_id>"
    }
  }
}
```

## Why promote_docx_candidate is rated Medium

An AI agent can call promote_docx_candidate faster than any human can review: one bad instruction and it creates or modifies resources in Meridian by the hundred, each call as confident as the last.

## Use case

AI agents use promote_docx_candidate to create or update resources in Meridian, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Meridian environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Meridian:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "promote_docx_candidate": {
      "limits": [
        {
          "counter": "promote_docx_candidate_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Meridian (234)

- `accept_handoff` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/accept-handoff.md
- `acquire_docx_document_lease` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/acquire-docx-document-lease.md
- `answer_hitl` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/answer-hitl.md
- `batch_mutate` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/batch-mutate.md
- `capture_research_finding` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/capture-research-finding.md
- `checkpoint` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/checkpoint.md
- `claim_docx_region` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/claim-docx-region.md
- `claim_file` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/claim-file.md
- `claim_sprint_item` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/claim-sprint-item.md
- `clear_capability_profile` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/clear-capability-profile.md
- `clone_profile_layer` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/clone-profile-layer.md
- `delete_custom_hook` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/delete-custom-hook.md
- `delete_note` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/delete-note.md
- `delete_sprint_item_pointer` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/delete-sprint-item-pointer.md
- `delete_watchlist_query` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/delete-watchlist-query.md
- `dismiss_hitl` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/dismiss-hitl.md
- `fan_out_sprint_items` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/fan-out-sprint-items.md
- `idle_until_all_done` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/idle-until-all-done.md
- `index_equation` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/index-equation.md
- `index_figure` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/index-figure.md
- `index_table` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/index-table.md
- `ingest_document` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/ingest-document.md
- `ingest_document_structure` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/ingest-document-structure.md
- `link_figure_caption` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/link-figure-caption.md
- `link_flag_to_section` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/link-flag-to-section.md
- `link_proposal_lineage` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/link-proposal-lineage.md
- `link_table_caption` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/link-table-caption.md
- `log_task` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/log-task.md
- `purge_ai_log` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/purge-ai-log.md
- `receive_messages` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/receive-messages.md
- …and 204 more: https://policylayer.com/tools/io-github-ajc3xc-meridian.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=io-github-ajc3xc-meridian · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/io-github-ajc3xc-meridian
