# release_sprint_item_claim

[MAINTENANCE] W1-I — voluntarily release a LIVE in_progress claim on a sprint item back to pending. Distinct from reconcile_stale_claims: that tool is for a claim whose owning session is dead/abandoned (multi-signal liveness classification); this is for a session that is still alive and has simply decided not to work the item after all (wrong scope, superseded, claimed by mistake) and wants to hand it back to the board cleanly instead of going silent and letting it eventually get swept as stale. Only the session recorded as the item's current actor may release its own claim — a mismatch is refused (NOT_CLAIM_OWNER) unless force=true is explicitly passed. Also clears the item's claimed_at/actor columns (not just status) and releases any file/symbol resource locks the claim held. Returns a structured {blocked: true, error: ...} dict (NOT_IN_PROGRESS / NOT_CLAIM_OWNER / RACE_LOST) rather than raising when it can't proceed; on success returns {item_id, prior_actor, prior_claimed_at, released_resources, item}, plus kept_for_sibling_items when a lock was deliberately kept because another in_progress item held by the same session still declares that file/symbol. Persistent-state disclosure: on hosted Meridian, supplied text and project/session metadata -- including task log entries, pinned decisions, sprint items, notes, handoff/goal state, and HITL queue items -- are sent to and stored in Meridian's service, in an isolated per-tenant Postgres database (Neon); self-hosted deployments keep the same categories in the configured local SQLite/Postgres database. This data is visible in the dashboard and API, and may resurface in later project context or handoffs. Notes and pinned decisions can be deleted individually; task log entries and sprint items can be deleted via the dashboard/API (not exposed as an agent-facing tool); HITL queue items and handoff state have no per-record delete. Full removal of any of this data is available via project or account deletion, using the documented controls. Do not include secrets.

Agent View of the PolicyLayer registry record for `release_sprint_item_claim`. HTML page: https://policylayer.com/tools/io-github-ajc3xc-meridian/release-sprint-item-claim

## Facts

- Tool: `release_sprint_item_claim`
- Server: Meridian (`@meridianmcp/mcp`) — https://policylayer.com/tools/io-github-ajc3xc-meridian.md
- Install: `npx -y @meridianmcp/mcp`
- Homepage: https://github.com/meridianmcp/Meridian
- Risk category: Destructive (Critical risk)
- Registry record: grade D, identity unverified
- Server auth posture: gated
- Server CORS policy: *
- Server rate-limited: no
- Parameters: 6 (2 required)
- Recommended policy verdict: Hidden

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `force` | boolean | no | Release a DIFFERENT live session's claim anyway. Default false — an ownership mismatch is refused by default. |
| `reason` | string | no | Optional human-readable reason, recorded in the audit trail only (never written to the item's own notes). |
| `item_id` | string | yes | The in_progress sprint item to release. |
| `project_id` | string | no |  |
| `session_id` | string | yes | The calling session's own identity. Must match the item's current actor unless force=true. |
| `project_name` | string | no | Project name — an alternative to project_id; resolved to the id internally. project_id wins if both are given. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "release_sprint_item_claim",
    "arguments": {
      "item_id": "<item_id>",
      "session_id": "<session_id>"
    }
  }
}
```

## Why release_sprint_item_claim is rated Critical

An AI agent that decides to call release_sprint_item_claim doesn't hesitate, doesn't double-check, and doesn't stop at one. Whatever it removes from Meridian is gone. There is no undo for destructive operations.

## Use case

AI agents call release_sprint_item_claim to permanently remove resources in Meridian, typically in cleanup and lifecycle workflows. It does its job in a single call, and there is no undo.

## Recommended policy (PolicyLayer)

Verdict: **Hidden**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Meridian:

```json
{
  "version": "1",
  "default": "deny",
  "hide": [
    "release_sprint_item_claim"
  ]
}
```

## Other tools on Meridian (234)

- `accept_handoff` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/accept-handoff.md
- `acquire_docx_document_lease` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/acquire-docx-document-lease.md
- `answer_hitl` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/answer-hitl.md
- `batch_mutate` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/batch-mutate.md
- `capture_research_finding` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/capture-research-finding.md
- `checkpoint` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/checkpoint.md
- `claim_docx_region` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/claim-docx-region.md
- `claim_file` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/claim-file.md
- `claim_sprint_item` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/claim-sprint-item.md
- `clear_capability_profile` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/clear-capability-profile.md
- `clone_profile_layer` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/clone-profile-layer.md
- `delete_custom_hook` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/delete-custom-hook.md
- `delete_note` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/delete-note.md
- `delete_sprint_item_pointer` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/delete-sprint-item-pointer.md
- `delete_watchlist_query` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/delete-watchlist-query.md
- `dismiss_hitl` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/dismiss-hitl.md
- `fan_out_sprint_items` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/fan-out-sprint-items.md
- `idle_until_all_done` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/idle-until-all-done.md
- `index_equation` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/index-equation.md
- `index_figure` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/index-figure.md
- `index_table` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/index-table.md
- `ingest_document` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/ingest-document.md
- `ingest_document_structure` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/ingest-document-structure.md
- `link_figure_caption` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/link-figure-caption.md
- `link_flag_to_section` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/link-flag-to-section.md
- `link_proposal_lineage` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/link-proposal-lineage.md
- `link_table_caption` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/link-table-caption.md
- `log_task` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/log-task.md
- `purge_ai_log` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/purge-ai-log.md
- `receive_messages` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/receive-messages.md
- …and 204 more: https://policylayer.com/tools/io-github-ajc3xc-meridian.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=io-github-ajc3xc-meridian · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/io-github-ajc3xc-meridian
