The register

Everything the platform does, and what each thing refuses.

This is the whole platform, entry by entry: what each capability does, what it leaves behind as a record, where its authority ends, and whether it is built. Entries we have not built are listed here too, marked, in the same table as the ones we have. That is the point of publishing a register rather than a feature list.

Where this is verified

Every entry marked Built is implemented and verified against a live database, against synthetic records, with positive and negative evidence retained — in a dedicated development environment for the core slices, and in a disposable local environment for the bounded extensions whose entries say so; each entry's own evidence line names the environment it was measured in. The isolated Git-linked FDE host serves the public front door at fde.lockedinlabs.ai, the exact code-bearing public web release is production-verified, and the hosted production schema is applied — schema posture, not signed-in acceptance. There is no public sign-up or self-serve access, and no accepted customer production identity, data, or Storage. Figures on this page are counts from our own verification runs, dated, and nothing else on this page takes a number.

What nothing here does

No capability on this platform executes a client effect: no pilot runs, no connector connects, and no workflow or agent definition acquires authority to act by existing — compilation resolves bindings read-only and grants no execution authority. No credential is stored anywhere in the system; there is no column for one. Where a capability's specification includes AI assistance, that assistance is proposal-only by design; the platform's one bounded, admission-gated model path can produce a proposed draft for human review and nothing else, and no text published on this page or register is model-generated.

The labels

Three labels. Every entry carries exactly one.

The register uses no others. Each label is copied from a named row in an internal capability truth register, whose status date is 2026-08-31; every entry below prints the row it was copied from.

The three status labels, what each means, and the truth-register labels each is drawn from.
LabelMeansDrawn from
BuiltImplemented and verified against a live database with retained positive and negative evidence — the refusal probes matter more than the happy path.Truth-register rows labelled VERIFIED or IMPLEMENTED
In buildSome of it exists and works; the target acceptance is incomplete. The entry says which half is which.Truth-register rows labelled PARTIAL
IntendedAccepted architecture, specified in writing, not implemented. No implementation claim of any kind.Truth-register rows labelled PLANNED or NOT STARTED

Plane one

Company Chartroom

Holds the client's operating reality as a governed asset. Refuses to answer beyond its evidence.

c-01

Engagement and organisation records

BuiltLifecycle: Discover

What it does
Establishes the client organisation and the engagement boundary, with named participants carrying exact roles. Every engagement-owned record is bound to exactly one workspace inside one engagement inside one organisation, and that binding is immutable; provider-owned reusable records — the publishable playbooks — are the deliberate exception, required to carry no engagement or workspace binding at all.
What it leaves behind
Organisation, engagement, and workspace records with named memberships and their validity windows.
Where authority ends
Provisioning is restricted to provider administrators; a caller without that authority receives a not-found rather than a refusal message, because a refusal message is itself information. An unreadable authority holds the surface closed rather than degrading to a permissive default.
Verified by
Five focused source contracts, with provisioning wired to the audited gateway actions. A live browser run of the provisioning forms is not yet claimed.
Truth register
Discover workspace + trusted gateway2026-08-22
Used in
S-09

c-02

Discover baseline

BuiltLifecycle: Discover

What it does
Captures interviews, digest-pinned sources, and attributed observations, then carries a baseline through draft → in review → validated against an evidence digest by an authenticated client actor who currently holds the stored sponsor organization role.
What it leaves behind
An immutable validated baseline version bound to an onboarding mandate that stores sponsor responsibility as the client organization and role. The baseline's separate validation trail attributes the act to its authenticated principal and retains the evidence digest and recorded limitations. The downstream records that carry a baseline pin — opportunity, proposal, report, outcome contract, roadmap, role impact, and charter — each pin the baseline they were built on, and that pin is checked again at every later gate; workflow and agent definitions carry opportunity and outcome linkage without a baseline pin.
Where authority ends
The delivery side cannot validate. Validation is restricted to client-organisation members holding an accountable role, enforced in the authorisation layer rather than the interface. A superseded baseline invalidates the gates that depended on it: a proposal cannot be submitted, a roadmap cannot be projected, and a report cannot be issued against a pin that has moved.
Verified by
An end-to-end run against a live database in the dedicated development environment: 19 positive gateway steps plus 13 refusal and boundary probes — unauthenticated, cross-origin, unrelated tenant, unassigned administrator, wrong-role validation, invalid lifecycle jump, epoch-pinned revocation. 18 authorisation unit contracts. Evidence dated 2026-08-21 and 2026-08-22.
Truth register
Discover workspace + trusted gateway2026-08-22
Used in
S-01, S-03

c-03

Governed retrieval and system inventory

BuiltThe durable cited read remains verified in the dedicated synthetic development environment. The evidence-bound inventory is verified only in the disposable local FDE environment. The richer knowledge fabric around both remains in build.Lifecycle: Discover, consumed by all stages

What it does
Reads the engagement's own records back with their citations attached — attributed observations with exact source and interview citations and content digests — and holds an evidence-bound inventory of systems plus interface and dependency relationships. Inventory facts can be recorded only from exact current corroborated observations and available source digests, with role-valued responsibility and an optional reference to one metadata-only connector version.
What it leaves behind
A retrieved answer whose every claim carries the source it came from; a workspace-wide list of explicit gaps; and immutable version chains for systems, interfaces, and dependencies, each retaining its exact observation and source citations, accountable organization role, and provider-review act.
Where authority ends
Search is parameterised and literal, and it never widens the verified workspace binding. A register that did not answer is reported as unavailable rather than as empty. There is no model in this path: it does not summarise, infer, rank by relevance, discover a system, or generate. Inventory recording and review are provider-side acts; provider review is not client confirmation. A connector reference is descriptive metadata only and grants no credential, connection, network authority, tool execution, or external effect. Client confirmation is NOT STARTED.
Verified by
The prior dedicated-project governed-read evidence is retained. The disposable local candidate passed the complete local data gate and focused pure-domain, gateway, interface, authorization, replica-mode, and concurrency contracts for the inventory slice. No hosted or client-browser verification is claimed for that extension.
Truth register
Organization knowledge fabric and governed retrieval2026-08-24
Used in
S-01

See Knowledge fabric

c-04

Assessment Studio

BuiltThe Assessment core remains verified in the dedicated synthetic development environment. Playbooks, evidence requests, and cited workcells are verified only in the disposable local FDE environment.Lifecycle: Discover

What it does
Holds the structured assessment instrument from governed method to cited review: provider administrators compose immutable assessment playbooks; separated provider actors review and publish them; an exact current published version launches a plan by copying its dimensions, evidence requirements, organization-role requirements, and gates. The plan moves draft → approved → in field → coverage complete → closed, with evidence-linked scores, client-role evidence requests, and deterministic cited review workcells around it.
What it leaves behind
A database-sealed playbook version and exact plan pin; the immutable plan and score chains; evidence requests attributed to their requester and terminal actor with exact fulfilment provenance; and work orders retaining their cited snapshot, explicit missing-evidence reasons, human proposal decisions, and any non-authorizing handoff to an already registered human action.
Where authority ends
Arbitrary new plan creation is closed: launch requires the exact current published provider playbook. A dimensionless plan, scoring a draft plan, and a score with no evidence link are refused. Coverage-complete still requires accepted scores for every required dimension unless a named human records the variation; fulfilling an evidence request does not satisfy that gate by itself. A reviewer-level grant cannot accept a score. A workcell calls no model, prompt, tool, connector, or external system, and accepting its proposal performs no underlying action.
Verified by
The prior dedicated-project Assessment-core evidence is retained. The disposable local candidate passed the complete local data gate and focused workcell, playbook, evidence-request, gateway, interface, authorization, replica-mode, and concurrency contracts. No hosted-browser or dedicated-project verification is claimed for those extensions.
Truth register
Assessment Studio (spec 01 core)2026-08-24
Used in
S-02, S-20

Plane two

Engineering Studio

Holds integrations, workflows, agent definitions, and plans as versioned, reviewable records. Refuses to grant power.

c-05

Opportunity portfolio

BuiltLifecycle: Discover → Design

What it does
Derives draft recommendations from the assessment by a pure deterministic rule over the plan's dimension weights and accepted scores, with conservative treatment of re-scored dimensions and deterministic tie-breaks, then holds accepted opportunities as records traceable to the baseline.
What it leaves behind
Accepted opportunities with recorded value and effort on the 0–100 scale the data contract holds, each anchored to a validated baseline.
Where authority ends
Effort, savings, and ROI are never derived — unknown is printed as unknown with the assumption stated. Unscored dimensions are held back from the draft rather than defaulted. Acceptance is exclusively a named human act through an audited mutation, and the surface holds acceptance closed when no validated baseline exists.
Verified by
Inside a 40-check live run, 0 failures, end to end from provisioning through named-human acceptance and outsider not-found; eight unit and source contracts.
Truth register
Proposal drafting (spec 04 slice)2026-08-22
Used in
S-04

c-06

Proposal versions

BuiltLifecycle: Design

What it does
Holds proposals as immutable versions with contiguous ranked items, moving draft → internally reviewed → submitted → client accepted or declined, where a revision opens a clean draft in the same chain.
What it leaves behind
The version register with a separate attributed-act trail: the authenticated principals who reviewed, submitted, and decided, together with the act timestamps, client decision organization, and recorded note. Those principal identifiers say who performed each act; they are not person-valued responsibility.
Where authority ends
Submission is gated on the baseline pin still being validated: after a baseline is superseded, a stale submission is refused. The client decision is restricted to members of the client's own organisation — the delivery side cannot accept its own proposal, and that is enforced in the authorisation layer.
Verified by
A 37-check live run, 0 failures, covering composition through named client acceptance plus refusals — empty selection, unknown pins, lifecycle jumps, wrong-side actors, stale-baseline submission, cross-origin, unrelated tenant. Eight unit contracts, eight source contracts.
Truth register
Proposal versions (spec 04 slice)2026-08-22
Used in
S-04

c-07

Report Studio

BuiltLifecycle: Design

What it does
Assembles governed report versions as a deterministic projection of the pinned records — executive, baseline, findings, portfolio, and decision sections — moving draft → internally reviewed → issued → submitted, with stale as a first-class named state.
What it leaves behind
An immutable report version with cited narrative sections, three required disclosure statements as non-null fields, pins to the baseline, plan, and proposal it was composed from, and a chrome-free print rendering of that exact version carrying its lifecycle state, accountability record, disclosures, and pins on the page.
Where authority ends
A quantitative claim in a narrative section with no citation is refused by a lint at assembly, not caught in review. Issue is gated on every pin still being current. Projection sections carry no citations because they cite nothing — they restate recorded values and counts, and state absences as absences. The printed artifact drops application chrome and loads no external assets; the screen-only print control is a client-side leaf, hidden from print.
Verified by
A 45-check live run, 0 failures, covering assembly through submission and both renderings, plus refusals including uncited quantitative claims, unknown citations, issue on a superseded pin, and reason-less stale marking. Eight unit contracts, seven source contracts.
Truth register
Report Studio (spec 05 slice)2026-08-22
Used in
S-05

c-08

Outcome definitions — the measurement contract

BuiltLifecycle: Design → Improve

What it does
Holds the measurement contract every selected opportunity must carry before delivery. Each element is a required non-null field rather than a prompt: metric name and source, population, measurement window, baseline measurement or an explicit statement that it was not measured, target statement and deadline, accountable organization role, decision-authority organization role, leading and lagging indicators, guardrails, cost measures, human-intervention measures, attribution assumptions, cadence, and accepted limitations.
What it leaves behind
Published, immutable outcome definitions bound to a covered opportunity and a validated baseline. Supersession preserves the published version, because anything already measured against it relies on it.
Where authority ends
Publication is reserved to a current member of the recorded decision-authority or accountable organization role — a bystander cannot publish the contract. Publication is refused against a superseded baseline pin. The platform will not fabricate a baseline measurement: not measured is the honest recorded answer and the schema accepts it as one.
Verified by
A 35-check live run, 0 failures, covering definition through publication and supersession plus refusals including missing indicators, bystander publication, and superseded-pin publication. Six unit contracts.
Truth register
Outcome Definitions (spec 06 slice)2026-08-22
Used in
S-06, S-18

c-09

Roadmap versions

BuiltLifecycle: Design

What it does
Holds the sequenced plan as immutable versions: declared modernisation streams, contiguous item sequences, a fully shown accountable role and stage gate for every item, and backward-only dependencies — moving draft → internally approved → projected → client approved → active → superseded.
What it leaves behind
The sequenced register with four named-act groups: internal approval, projection, client approval naming the approver's organisation, and activation.
Where authority ends
No roadmap item can exist without a published outcome contract covering exactly its opportunity — enforced by a database trigger, not a review step. There are no dates: horizons are categorical (30/60/90 or long horizon) because no date column exists to invent one in. Forward and cyclic dependencies are impossible by construction. A material change reopens a clean draft with every prior act cleared. Client approval is restricted to the client's own organisation.
Verified by
A 49-check live run, 0 failures, covering composition through activation plus refusals including draft-contract items, contract/opportunity mismatch, undeclared streams, forward dependencies, and stale-baseline projection. Eight unit contracts.
Truth register
Roadmap versions (spec 06 slice)2026-08-22
Used in
S-07

c-10

Workforce planner

BuiltLifecycle: Design → Improve

What it does
Holds role impact assessments and enablement tracks: what the change eliminates, simplifies, automates, makes AI-assisted, or newly creates, by role and team — and the enablement each affected team receives, moving planned → scheduled → running → completed or suspended.
What it leaves behind
Accepted role impact assessments and enablement tracks whose completion carries a retained evidence digest and an evidence statement, and whose suspension carries a recorded reason.
Where authority ends
Forward ownership is stored as the owning organization and role. A legacy person-valued track-owner field remains only on historical held rows; it is never copied into a successor or treated as current responsibility. Role impacts describe roles and teams only, so individual-level judgment is structurally out of scope rather than merely discouraged. Acceptance requires two distinct authenticated actors, enforced as a database check, one of them in the client organisation; their principal identifiers attribute the review and acceptance acts, not responsibility. A zero-change assessment is refused. Scheduling is gated on an accepted role impact; completion without evidence is refused; suspension without a reason is refused.
Verified by
A 40-check live run, 0 failures, covering the full path plus refusals including no-change assessments, scheduling before acceptance, and completion without evidence. Seven unit contracts.
Truth register
Workforce planner (spec 07 slice)2026-08-22
Used in
S-08, S-17

c-11

Pilot charters

BuiltLifecycle: Execute

What it does
Holds non-executable pilot charters: hypothesis, affected population, duration statement, success criteria, stop criteria, rollback plan, and environment statement — all required — moving draft → internally approved → client accepted → mobilised.
What it leaves behind
The immutable charter register, with rework reopening a clean draft.
Where authority ends
Execution is not claimed, and the surface prints that sentence on every charter. No part of this capability runs, deploys, dispatches, or collects run evidence. A charter cannot exist without a published outcome contract covering exactly its opportunity — a database trigger — nor without the affected team's enablement track. Mobilisation is refused while that track is merely planned or scheduled: it must actually be running or complete. Client acceptance is restricted to the client's own organisation.
Verified by
A 45-check live run, 0 failures, including mobilisation refused at both planned and scheduled enablement, stop-criteria-less charters, and mobilisation on a superseded contract. Six unit contracts.
Truth register
Pilot charters (spec 10 slice)2026-08-22
Used in
S-15

c-12

Workflow definitions

BuiltLifecycle: Design → Deliver

What it does
Holds workflow definitions as immutable versions of typed steps — trigger, automated, agent, tool, human gate, verification, outcome — each carrying a required boundary statement and a validated declaration of what it may touch, connected by edges bound to declared steps. A pure compiler decides whether the graph is admissible, and the definition moves draft → compile clean → in review → approved → published → deprecated or revoked.
What it leaves behind
A published definition with a canonical content digest, every step's boundary in writing, every human gate named to its owning role, the compiler's pinned verdict, and separation-of-duties approval.
Where authority ends
A compiled or published definition acquires no power to act. Compilation resolves agent bindings read-only against the current register — refusing an unread, missing, ambiguous, revoked, or unpublished binding — and that standing resolution grants no execution authority; nothing dispatches a step, no model, tool, or effect is invoked, and no runner exists on this path. The compiler refuses — with exact diagnostics, not warnings — a missing trigger, outcome, or verification step, unreachable steps, cycles, an ungated write-effect tool, an unverified outcome path after a write, a missing boundary, or a step above its rung on the opportunity ladder. A tool step must declare exactly one read or write effect. The approver cannot be the author. Revocation requires a recorded reason and is terminal.
Verified by
A 49-check live run, 0 failures, covering composition through publication plus refusals including compiler rejection of an unverified graph, an agent step above its rung, author self-approval, and publication on a superseded pin. Nine unit contracts, eight source contracts.
Truth register
Workflow definitions (spec 08 slice)2026-08-22
Used in
S-12

c-13

Agent definitions

BuiltLifecycle: Design → Execute

What it does
Holds bounded agent definitions as immutable versions: role, objectives, eligible model routes, tool allowlist, context purposes, boundary statement and may-touch declaration, an explicit delegation statement, and a ladder rung restricted to AI-assist, bounded agent, or justified autonomy with a required recorded justification. Every definition carries an evaluation plan of typed checks, and a pure deterministic evaluator decides them.
What it leaves behind
A published definition with its evaluation plan, evaluation results and their digest, the ladder justification, and separation-of-duties approval.
Where authority ends
A published agent definition acquires no power to act. No session, dispatch, executor, or model provider exists on this path. Model routes and tools are reference strings only. The evaluator makes no model call and no network call — every check is decided from the definition itself — and the evaluated act is refused if any check fails, including a definition that violates the plan it wrote for itself. An agent is never the default rung: a non-agentic rung is refused here, because that work belongs in a workflow. The approver cannot be the author.
Verified by
A 39-check live run, 0 failures, covering composition through publication plus refusals including a definition failing its own evaluation plan, a justification-less definition, and author self-approval. Five unit contracts, eight source contracts.
Truth register
Agent definitions (spec 09 slice)2026-08-22
Used in
S-13

c-14

Connector registry

BuiltAt the metadata rung, and pinned there by a database check.Lifecycle: Design → Deliver

What it does
Holds descriptive, immutable connector entries: dotted key, display and system names, kind (MCP, REST, CLI, server-to-server, event, file pipeline), capability statement, and a reference-only locator.
What it leaves behind
The register of what the engagement's estate contains, with reasoned deprecation and supersession.
Where authority ends
Registration is never execution authority. Every row is pinned by a database check to the metadata-discovery rung; the parser fails closed on any higher rung; the gateway pins it at the payload literal. The four rungs above — governed read, proposed action, controlled write, operational automation — are each their own future increment carrying their own authority model and human gates. Raising a connector requires a migration, never a flag flip. No credential column exists anywhere, every text field rejects secret-bearing content, and no network call exists on this path.
Verified by
A 21-check live run, 0 failures, including refusal of every higher maturity rung, a credential-bearing locator rejected by the data contract, and reason-less deprecation. Three unit contracts.
Truth register
Connector registry (D-023 slice)2026-08-22
Used in
S-14

See Integration Lab

Plane three

Control plane

Holds the verifiers and the authority model. Refuses to let an agent be its own judge, and refuses to let monitoring pass as control.

Read this plane carefully. The authority model underneath the platform is built and verified. The runtime control plane — bounded execution, held privileged actions, independent production verification — is not. Both facts are on this page in the same table.

c-15

Tenancy, entitlement, and object authorisation

BuiltLifecycle: all stages

What it does
Evaluates, server-side and on every read and mutation, whether this caller may touch this record: organisation and workspace binding, commercial entitlement, exact per-user module assignment, object-level authorisation, and revocation pinned to principal and membership epochs. All reads travel through a trusted server gateway that holds no session data path.
What it leaves behind
Nothing visible — which is the point. What it produces is a refusal, and refusals are uniform: an outsider receives a not-found, never a message describing what exists.
Where authority ends
It fails closed. An unreadable authority holds the surface closed rather than degrading to permissive. A refusal costs exactly its own lane and never widens a caller's reach. Entitlement is never object access: paying for a module does not grant a record. The entitlement gate is evaluated here; the commercial ledger behind it is in build, and the hosting entry says so.
Verified by
Negative probes are carried in every slice run on this page — unauthenticated, cross-origin, unrelated tenant, unassigned administrator, wrong-role act, epoch-pinned revocation deny, outsider not-found — plus 18 authorisation unit contracts and 26 regression contracts covering a directory partition defect found and fixed on 2026-08-22. Also bound to the truth-register row "Workspace directory resolution".
Truth register
Discover workspace + trusted gateway2026-08-22
Used in
S-09 and every other entry on this page.

See Hosting, identity, and deployment topologies

c-16

Immutability, audit, and secret rejection

BuiltLifecycle: all stages

What it does
Holds every governed artifact as an immutable version chain with an append-only audit trail, and keeps that discipline distinct from the small set of intentionally mutable operational control state — runtime holds and rate-limit counters — which is updated in place by design and is never a governed record. Row-level security is enabled and forced on every table in the schema, verified by catalogue query rather than by assertion. Protected content-bearing text fields reject secret-bearing content at the data layer; a plain display-name field is not a secret sink and carries no such check.
What it leaves behind
The record that a reviewer can walk backwards: what was written, when, by whom, and what it superseded.
Where authority ends
Validated and published versions are never mutated — they are superseded, and the superseded version survives because anything that relied on it still relies on it. There is no administrative edit path, no soft delete that rewrites history, and no credential column anywhere in the schema.
Verified by
The executable current-candidate data gate covers 76 official pgTAP files with 2804 assertions across 244 FDE tables. The retained 2026-08-29 disposable-local run passed 60 official pgTAP files with 2083 assertions across 203 FDE tables — covering the estate member register and D-067 Stage B's two append-only synthetic execution receipt tables through the foundation contract's dynamic RLS census; the contact-center agent-definition register (migration 202608300130), the distributed-export citation register (migration 202608300135), and the database-export citation register (migration 202608300145), with their 33-, 44-, and 44-assertion contracts, are included in the current local reset gate; the recovery-coordinator activation (migration 202608300140) with its 26-assertion contract landed after that retained run. The #91 disposable-local gate then reset cleanly through migration 202608300145, returned zero schema-lint findings, and passed all 64 pgTAP files / 2230 assertions, including the database-export contract at 44/44. The review repair advanced only that contract to 45 assertions and its final focused run passed 45/45 after the same clean migration apply. The gate also covers all 15 concurrency harnesses (registered, including Storage), and 66 additional fixture-backed behavioral assertions outside that official pgTAP file-and-assertion census. D-067 Stage B registers a third noninteractive executor class, closes the pre-existing class-to-role fail-open at the table with an always-enabled null-safe guard, and remains default held with no executor, activation, or effect authority. It also covers the clean-reset and schema-lint checks under the pinned toolchain. The foundation contract checks every table for enabled-and-forced RLS, and the private data plane exposes only the intended schemas with signups and anonymous auth disabled. The recovery-coordinator activation migration pins the one immutable binding receipt and least-privilege grants (four v1 RPCs to authenticated; five coordinator entry points to a dedicated NOLOGIN role only), and the reviewed owner-factor-removal adapter is compiled in; recovery still remains OFF everywhere until the owner sets the exact acceptance environment values and provisions the coordinator login and credential, none of which exist in source. The governed synthetic implementation handoff remains inactive and PARTIAL. D-065 adds a default-held, FDE-owned noninteractive service-principal foundation with no consumer activation, v2 mutation adapter, hosted credential, or Storage broker. D-066 adds only the default-held D-048 lock-order repair; it creates no activation, credential, provider call, or effect authority. The frozen combined candidate verification run also passes the application, source, asset, dependency, formatting, lint, typecheck, test, disposable-data, and optimized production-build gates under the pinned toolchains. Separately, the 2026-08-30 hosted delta apply records the hosted production project at migration history 98/98 with 212 FDE tables, RLS enabled and forced on 212/212, and zero anon/authenticated grants — hosted schema posture only, with MFA recovery still OFF and no signed-in walk against the hosted deployment. The gate evidence above is disposable-local candidate evidence, not authenticated, activated, accepted, or SHIPPED evidence, and the hosted receipt promotes no activation or UAT claim.
Truth register
FDE data foundation2026-08-28
Used in
Every entry on this page.

c-17

Act attribution and separation of duties

BuiltLifecycle: all stages

What it does
Makes responsibility structural without assigning it to a person. Where a governed record carries responsibility or decision authority, the contract is a stored organization-and-role pair. Lifecycle transitions separately attribute each review, approval, submission, or decision act to the authenticated principal and timestamp. Where two distinct actors are required, approver ≠ author is a table check. Where a decision belongs to the client, the actor must hold the applicable role in the client's own organisation.
What it leaves behind
An attributable act trail — principal, timestamp, organization where relevant, and note — beside the separate organization-role responsibility contract. The principal identifies who performed the act; it never becomes the accountable owner.
Where authority ends
The delivery side cannot act for the client. Baseline validation, proposal acceptance, roadmap approval, role-impact acceptance, and pilot acceptance are reserved to current members holding the required client-organization role; no provider role — including provider administrator — satisfies that client-side responsibility. An author cannot approve their own workflow or agent definition.
Verified by
Wrong-side refusal probes in every slice run — sponsor cannot submit, lead cannot decide for the client, author cannot self-approve, bystander cannot publish another's contract, reviewer grant cannot compose. Bound to the truth-register rows for proposals, roadmaps, workforce, pilots, workflows, and agents, with retained local and browser evidence.
Truth register
Proposal versions (spec 04 slice)2026-08-22
Used in
S-03, S-04, S-07, S-08, S-15

c-18

Portfolio and engagement command

BuiltLifecycle: all stages

What it does
Reads the practice at two altitudes. Portfolio command is every engagement the signed-in person can open, with each engagement's real state on it. Engagement command aggregates every landed lane of one engagement on one surface — every figure derived by the same expression the lane's own surface uses, so the two cannot disagree.
What it leaves behind
Nothing new — a read, composed by a pure function over the same gateway bundles.
Where authority ends
An unknown is never a zero. A register that answered and was empty prints as an absence; a register that did not answer is named as unknown on that row, and every total carries the count of engagements that could not contribute to it. No composite, index, weighting, or health score exists anywhere — there is no way to invent one, because there is no code path that computes one. Reads are bounded: at most twelve engagements are read in full and the remainder are listed as explicitly not read. Each engagement is re-resolved from scratch through the same access check as its own dashboard; a refusal costs that engagement its figures and nothing else.
Verified by
A 34-check live run, 0 failures, from a cold server: figures agreeing with both the canonical registers and each engagement's own dashboard, 18 organisations outside the persona's memberships absent and unreachable by direct locator, and a no-workspace engagement stated rather than zeroed. 13 focused contracts. Also bound to the truth-register row "Engagement command dashboard".
Truth register
Portfolio command (`/workspace`)2026-08-22
Used in
S-16

c-19

Print-ready executive summary

BuiltLifecycle: all stages

What it does
Renders a one-page engagement summary under the report print discipline — the printed artifact drops application chrome and external assets, and the screen-only print control is a client-side leaf hidden from print: engagement facts, the baseline with its validating act and evidence digest, top opportunities as an ordering of recorded scores, proposal decisions, published contracts, roadmap composition, workforce posture, and charters.
What it leaves behind
A document that prints, carrying a citation register naming every record id it was composed from and a generation timestamp.
Where authority ends
The ordering of opportunities is a presentation ordering of recorded scores — it computes no new score. The page states in words that it is a live composition and not a governed report version, so it can never be mistaken for one in a boardroom. Unreadable registers are named on the page as unknown.
Verified by
Four composer unit contracts and three source contracts, with a rendered live run asserting the citations, metric names, and generation line.
Truth register
Executive summary surface2026-08-22
Used in
S-05

Not finished

In build

Listed with the same weight as the built entries. Each says which half exists.

c-20

Knowledge fabric — indexes, Context Packs, retrieval audit

In buildPartial current source candidate; hosted schema applied, signed-in acceptance unverified.

What it does
The durable governed read is built. The current local source candidate also persists purpose-bound Context Packs and Retrieval Records for reviewed human use and exact published-agent consumers, with bounded excerpts, exact source pins, expiry, and invalidation. Authorised index projections and revocation workers remain unimplemented.
What it leaves behind
A durable, scope-bound pack and its retrieval record survive the request that assembled them. No model, tool, connector, or effect is invoked, and no broader authorised index projection is created.
Where authority ends
Packs preserve the reader, purpose, handling ceiling, exact evidence versions, and currentness boundary; they do not confer execution authority. The hosted schema is applied; signed-in authenticated acceptance, authorised index projections, and the broader retention and projection workers remain unverified.
Truth register
Organization knowledge fabric and governed retrieval2026-08-24

See Governed retrieval

c-21

Integration Lab

In build

What it does
The metadata connector registry is built. The Integration Lab — versioned MCP, CLI, REST, server-to-server, event, and pipeline definitions with schema and mapping validation, dry-run traces, and immutable preview publication — is a local preview.
What it leaves behind
Nothing durable in the Lab lane. The registry lane's immutable entries are the only durable record either lane holds.
Where authority ends
In both lanes there is no network call, no shell, no credential, and no production effect of any kind.
Truth register
Integration Lab and connector-contract design2026-08-22

See Connector registry

c-22

Runtime, Harness, Interlock, Verification

In buildPartial shipped source with the schema hosted-applied; D049 inactive and D-067 default held, with executor registration, activation, and authenticated acceptance unverified.

What it does
This is the row to read if you are evaluating the control plane. The shipped source persists durable workflow Runtime control records and immutable Agentic Harness SessionSpecs, and that schema is included in the hosted production apply recorded on the data-foundation entry. D048 adds one exact restart-safe Proposal Drafter worker contract with one model call, zero tools, zero external effects, and terminal reconciliation; it has no hosted activation or retained live-provider call. D049 preserves a database-local synthetic ActionIntent, Interlock, receipt, and Verification candidate, but every activation door is explicitly closed. D-067 registers a bounded synthetic workflow executor class and append-only synthetic receipt shapes that remain inert and default-closed, with no executor registered.
What it leaves behind
Durable definitions, Runtime holds, human-task control state, held Harness specifications, and the bounded D048 worker evidence model survive the request that recorded them. The inactive D049 candidate leaves no actionable browser command or effect authority.
Where authority ends
There is no general runner, tool executor, active production-effect path, or independent production verifier. D048 is confined to its exact one-model, zero-tool, zero-effect worker class. D049 remains inactive and unregistered; its preserved schema and source cannot wake into execution or authorize a production effect. Hosting the schema grants nothing: executor registration, activation, provider and effect authority, authenticated acceptance, and independent production Verification remain unverified and default-closed, D-067 included.
Truth register
Durable workflow Runtime and human task state2026-08-26
  • RuntimeDurable control records and exact human-task holds are persisted. The general lease plane remains closed; D048 is one separately bounded worker exception, and D-067's synthetic executor class stays default held with no executor registered.
  • Agentic HarnessImmutable, principal-bound SessionSpecs pin the exact agent, workflow attempt, Context Pack, sandbox, output policy, and budgets. D048 records a separate exact child run for one model call, zero tools, and zero effects; no general executor exists.
  • InterlockD049 preserves exact ActionIntent and named-client decision source/schema, but the browser actions, processor, recovery, and host wake are inactive. Production effects are closed.
  • Independent VerificationD049 preserves a distinct service-verifier candidate and closed verdict vocabulary while activation remains blocked. There is no independent production verifier.

c-23

Hosting, identity, and deployment topologies

In buildMixed — each item below carries its own label.

What it does
Where LockedIn Labs FDE can be run, and by whom. The isolated Git-linked FDE host serves the public front door at fde.lockedinlabs.ai, and the exact code-bearing public web release is production-verified — a claim bound to the exact main revision recorded, with its date, in the truth-register row this entry cites, under the Git-linked discipline that redeploys every main merge. The hosted production schema is applied — schema posture only. There is no public sign-up or self-serve access, and no accepted customer production identity, data, or Storage.
What it leaves behind
Nothing a client holds. This entry distinguishes the public host and domain boundary from customer deployment capability; it does not claim an available customer topology.
Where authority ends
The host and domain boundary exists and the hosted production schema is applied; signed-in identity acceptance, customer data, Storage acceptance, and customer topology readiness do not exist. Managed service, dedicated instance, private or VPC, hybrid, client-premises, and licensee operation remain planned individually and are not purchasable; none is implied by another.
Verified by
Bound to the exact main revision recorded, with its receipt and its 2026-08-30 date, in the truth-register row this entry cites, under the Git-linked deploy discipline that redeploys every main merge. The 2026-08-30 hosted delta apply records the hosted production data plane at migration history 98/98, with 212 FDE tables, RLS enabled and forced on 212/212, and zero anon/authenticated browser-role grants. That is hosted schema posture and the hosted-applied gate alone, not signed-in identity, customer-data, or Storage acceptance — those are structurally blocked rather than pending, MFA recovery remains OFF, and no signed-in walk has occurred or can be attempted, because the hosted project holds no tenant, organization, or membership and no sanctioned path establishes tenancy on a hosted project.
Truth register
Independent hosted FDE environment2026-08-30
  • Public host and domain — Built boundaryThe isolated Git-linked FDE host serves the public front door at fde.lockedinlabs.ai, and the retained exact code-bearing public web release is production-verified at the exact main revision recorded in the cited truth-register row. The hosted production schema is applied — schema posture only. This does not accept production identity, customer data, Storage, or a customer deployment topology.
  • Hosted identity — In buildCookie replay, MFA, and session coverage exist as contracts; hosted identity acceptance is not pending but structurally blocked — the hosted data plane holds no organization membership, and no sanctioned path establishes one there, so a signed-in walk cannot be attempted.
  • Deployment topologies — IntendedManaged service, dedicated instance, private or VPC, hybrid, client-premises, and licensee operation are each planned individually and not purchasable; none is implied by another or by the public host.
  • Commercial entitlement ledger — In buildContracts and the gate exist; there is no hosted commercial ledger.
  • Client projections — In buildDirectional projection contracts and schema exist; there is no materialisation and there are no derived-channel workers, so nothing is projected into a client's own tenant today.

c-24

Solution Assembly

In buildPartial source candidate with the schema hosted-applied; design record only.Lifecycle: Design

What it does
Creates immutable, client-engagement solution-design versions that bind one accepted opportunity, published Outcome Definition, source-sealed blueprint, model-capability preference, typed client decisions, and an exact six-part component manifest. A distinct current client reviewer may accept the design; later dependency drift is reported as standing rather than rewriting the historical act.
What it leaves behind
A versioned design record, exact component pins, explicit design gaps, and activation holds. Design-ready and design-accepted are design states only.
Where authority ends
The record provides no endpoint, credential, connector grant, model or tool call, runner, effect, deployment, Interlock, or Verification authority. Its schema is applied to the hosted production project, but the capability is not acceptance-verified, deployed, or SHIPPED, and it cannot execute anything.
Verified by
Migration 070 adds three private Solution Assembly tables behind the then-current 69-action registry; the current candidate practitioner registry contains 133 actions. Focused local evidence passed 47/47 pgTAP assertions, 11/11 static contracts, one two-order concurrency harness (1/1), and authenticated synthetic Aurora acceptance on 11/11 routes at desktop and mobile. This is local source-candidate evidence plus hosted schema application only — not signed-in acceptance, deployment, SHIPPED, or execution evidence.
Truth register
Solution Assembly design records2026-08-25

c-25

Contact-center operations and voice-agent lane

In buildLocal package source plus a register migration now applied to the hosted production project as schema posture only (agent-definition compiler, assessment-playbook data, golden-call eval-suite/result records, a trusted-gateway module, a deployment-pack exporter, two read-only demo cards); no accepted hosted record, no platform golden-call run, and only a read-only navigation lane exists.

What it does
Specifies a third capability lane beside enterprise assessment and workflow building: a contact-center operations assessment, a governed voice-agent definition record — verification policy, tool contracts, a playbook and system-instruction template, and a RAG corpus manifest — and a receipt-bound deployment pack, reusing the existing evidence, digest-pin, and separation-of-duties machinery rather than inventing new controls.
What it leaves behind
Four synthetic tool-chest catalog entries (a contact-center assessment method, a voice-agent workflow blueprint, a golden-call evaluation pack, and a reference-architecture client deliverable, each carrying REFERENCE_BLUEPRINT_REVIEW_REQUIRED maturity and NONE execution authority), plus local package source: a typed agent-definition compiler/lifecycle module, a typed assessment-playbook definition, and two typed golden-call eval record kinds, all pure. A durable register migration and a trusted-gateway module (compose/revise/transition/read) for the agent-definition record now exist, and the register migration is applied to the hosted production project — schema posture only, with no accepted hosted record: nothing has been composed, persisted, or accepted through it. A deployment-pack exporter and a session-gated download route also exist, but both currently produce output only from one hardcoded synthetic fixture — no per-engagement wiring exists. A read-only eval scorecard renders a second hardcoded synthetic fixture — a synthetic representation of a claimed off-platform donor run, not platform execution — on the same workbench page, which is registered as a read-only Contact Center lane in the console navigation.
Where authority ends
No assessment plan can be launched, and no agent-definition record has been persisted or accepted through the gateway — the register migration is applied to the hosted production project as schema posture only, and no gateway call has written to it. The deployment-pack exporter can only ever produce a pack from its one hardcoded synthetic fixture; it has no live per-engagement input. No golden-call harness has run on this platform; the scorecard's fixture is a hardcoded synthetic representation of a claimed off-platform donor run, not a platform record of one. Navigation reaches only the read-only workbench lane, and catalog selection carries SYNTHETIC_DEMO_DATA classification and grants no execution authority by existing.
Verified by
packages/fde-core: 28 tests for the agent-definition compiler/lifecycle module (contact-center.ts), 5 for the assessment-playbook data (contact-center-operations-assessment-playbook.ts), and 40 for the two golden-call eval record kinds (contact-center-evals.ts), all passing locally; strict tsc clean; package build clean. apps/web: 15 static-source tests for the trusted-gateway module, 33 for the deployment-pack exporter and its route, and 14 for the read-only eval scorecard card, all passing locally against local source only — no live database was exercised. The migration 202608300130_contact_center_agent_definitions.sql and its 33-assertion pgTAP contract were recorded as local source in that run; Docker was unavailable in this environment, so no local or hosted Postgres reset/apply was attempted then — that validation is deferred to CI, and a later retained hosted apply receipt records the migration applied to the hosted production project as schema posture only. This is local source-candidate evidence only — no accepted-record, gateway, signed-in, or execution evidence.
Truth register
Contact-center operations and voice-agent lane2026-08-29

c-26

Distributed/VMware estate assessment lane

In buildEngine, screens, and a durable citation-only intake register on main; the register migration is hosted-applied as schema only, no client corpus is registered anywhere, and the screens render the labelled synthetic fixture corpus only, with no hosted or signed-in acceptance.

What it does
Holds the mainframe assessment lane's distributed sibling: evidence-bound parsing of field-standard estate exports (RVTools-style VM inventories, cron and Control-M-style scheduler workloads), an evidence-gated estate rollup with a first-class gap census, and a five-option workload disposition under the same citation, confidence, and refusal discipline. Two screens now sit over the engine: a navigation-registered estate overview that keeps the three disposition verdict kinds apart — recommended, candidates only, insufficient evidence — never combined into one figure, with every capacity sum labelled with the population it is over; and an inventory that mounts the shared evidence-table island rather than a table of its own, with unread export lines unioned in as gap rows so the row count states what the export contained rather than what parsed. An exact-scope citation register now stands behind the lane's intake: a client's already-accepted governed field-evidence exports can be registered by citation, and the screens' seam reads that register through the trusted gateway.
What it leaves behind
Four pure modules in packages/fde-modernization: inventory parsing whose extracted facts are unconstructible without a citation and whose unparseable rows are retained as typed residue; scheduler parsing that captures declared dependencies only; a rollup that separates evidenced from inferred, discloses absent configured capacity as its own gap kind, and never folds absence into a total; and a disposition whose retirement option requires cited evidence and consults an inbound-declaration index so a workload other jobs depend on is never proposed for retirement. What is durable is the citation-only register row a registration writes through the trusted gateway — the exact evidence locator, recorded byte count, and content digest, never the export bytes, which stay in governed field evidence. The screens themselves leave nothing: rows are built server-side, and the shared island sorts, filters, and hides but computes nothing.
Where authority ends
Registering an export is a citation-only declaration over evidence a person already supplied through governed field intake: it grants no second intake path, no storage write, and no model, tool, Runtime, Interlock, or effect authority, and the register stores no export bytes. The register migration is applied to the hosted production project as schema only — the register table exists there with no rows — and no client has registered an export anywhere, so the seam's live branch still resolves the labelled fixture with its stated reason, keeping a register that answered empty apart from one that could not answer, and an engagement that has never been checked for client exports is never presented as one that was checked and found empty. No connector reads a live estate — every input is a file export a person supplies and registers — and it proposes dispositions while carrying no execution authority of any kind.
Verified by
packages/fde-modernization: 325/325 tests on main (286 baseline + 39 new), strict tsc and package build clean, consumers' web build clean. The three blocking review findings — inverted dependency direction, absence-scored secondaries, unconverted GB→MiB parse — were each reproduced by executable probe and are pinned as named tests. The screens wave passed 2073/2073 web tests in its own run (baseline 2046 with the new file removed, so the gain of 27 is verified rather than inferred), with the seam's three provenance arms, the gap-row union, and the verdict separation pinned by focused lane contracts. The register wave landed migration 202608300135 with its 44-assertion pgTAP contract, which passed 44/44 in its own disposable-database run and is included in the current local reset gate; the practitioner registry moved 129 to 131 with the two citation-only register and withdraw actions, and the intake seam, provenance arms, and gateway contracts are pinned by focused web tests. The register migration was applied to the hosted production project in the 2026-08-30 delta apply, which carried hosted migration history to 98 migrations — hosted schema posture only, with no hosted register row and no signed-in walk. This is package, web, and disposable-local data evidence only — no accepted hosted, signed-in, or execution evidence.
Truth register
Distributed/VMware estate assessment lane2026-08-30

c-27

Session Room — live working-session capture

In buildShipped web source with focused suite evidence in the local environment; no hosted or signed-in browser acceptance of this lane is claimed.Lifecycle: Discover

What it does
Turns a live client working session into governed records as the room talks. The capture island gates on a real open interview — no open session, no form, and an ambiguous set of open sessions demands an explicit human pick rather than an auto-select. Five capture kinds — observation, open question, decision, evidence request, and text-encoded sketch — each compose onto an already-registered gateway act, never a new verb, and an observation is structurally unsubmittable without at least one pinned registered source. A scoped reader answers the two reads no existing reader could, and the timeline and separation-of-duties handoff rail mount over it.
What it leaves behind
Interview, source, observation, decision-request, and field-evidence rows written through the trusted gateway, which re-derives identity and re-checks entitlement, module assignment, and the exact object grant before any row is written. The in-room ledger is a browser-local echo that claims no durability: a reload loses the echo while the gateway rows survive. Every timeline row renders as a proposal awaiting a named human act, never as a promoted fact.
Where authority ends
Capture composes payloads for existing registered acts only; a denial comes back as the server's own code, never softened or retried, and nothing in this room can approve, accept, or promote what it captured. The reader pins tenant, organization, and workspace scope explicitly on every table it touches, and an unanswered or over-cap register returns as unread, never as empty — the timeline refuses to render at all when a register it needs did not answer, naming which one, because drawing an observation without its evidence pins would assert a state the gateway refuses to write. Participant attribution is folded into free text as a delimited note, never claimed as a structured fact, because no participant column exists.
Verified by
The capture wave passed 2135/2135 web tests in its own run (a verified gain of 89 across three lanes over its measured baseline); the reader-and-mount wave passed 2194/2194 (baseline 2178 with the new file removed, so the gain is verified rather than inferred). The reader is registered in the reader-conformance manifest, whose counters moved 82 to 84 reader roots, 42 to 44 workspace-class readers, and 106 to 110 pinned scope statements in that wave; the manifest has since grown and the suite now pins 86 reader roots, 44 of them workspace-class, so the wave figures are read as that wave's movement and not as the current census. Local suite evidence only — no hosted, signed-in, or live-database session evidence is claimed for this lane.
Truth register
Session Room live working-session lane2026-08-30

See Discover baseline

c-28

Command palette and navigation

In buildShipped web source with focused model and source-scan suite evidence in the local environment; no hosted or signed-in acceptance run of the palette is claimed.

What it does
Opens a keyboard command palette over the real console model: a pure, dependency-free model derived from the same console sections the navigation itself renders, scored by a four-tier deterministic fuzzy match, with recency held in guarded browser session storage and a full accessible combobox keyboard loop. It is mounted on the token-native WorkspaceFrame surfaces where no palette existed — deliberately not beside the engagement shell's existing command bar, so two dialogs never race one keystroke.
What it leaves behind
Nothing durable. A selection navigates; the only browser-side residue is a small recency list in session storage, which the model treats as advisory and absent-safe.
Where authority ends
Navigation only, by the standing D-011 decision: the palette goes places and never acts — no entry executes, mutates, or submits anything, and no code path leads from a palette entry to a gateway act. Without an organization in scope it offers the one entry that is true rather than fabricating engagement links. Scoring is deterministic — no model call and no network call exists on this path. The engagement shell's existing command bar is not replaced, and the palette does not search records or registers.
Verified by
The palette wave passed 2089/2089 web tests in its own run (a verified gain of 43 over its measured baseline), with the deterministic scorer, the recency guard, the keyboard loop, and the navigation-only rule pinned by focused model and source-scan contracts. Local suite evidence only.
Truth register
Command palette and console navigation2026-08-30

c-29

Governed AI rails — explanation doors, drafting bridge, workspace assistant

In buildShipped web source with focused route, grounding, and discipline suite evidence in the local environment; no hosted activation, no retained live-provider transcript for these doors, and no signed-in acceptance is claimed.

What it does
Adds two grounded explanation doors in the modernization lane — one over a program's deterministic disposition contest and one over a business-case line's recorded cost assumptions and citations — each drawing the same shared durable daily admission ledger as the existing rule-explanation door, never a second cap. A drafting bridge on the proposals surface points at the exact Models-lane flow with prerequisite steps that name the exact act still owed and who owes it. A workspace assistant panel is mounted in the console chrome over a workspace-scoped door that re-verifies the caller's membership server-side and grounds only on the caller's own discovery register.
What it leaves behind
Nothing durable beyond the shared admission ledger's own counters. Model output renders dashed-bordered and named as the model's reading — a proposal, never a recorded fact — and every non-answer carries its stated reason rather than fallback prose.
Where authority ends
Locators only reach these doors: no client text becomes a trusted fact, and an engagement locator is re-verified against the caller's own membership rather than trusted as asserted. The bridge grants zero new authority — it cannot mint a connection, a governed-read origin, or a provider credential; it names the act still owed and links to where a person performs it. The assistant can only explain what the registers say — it cannot accept, reject, or dispose of anything. Every held decision stays held, pinned by exclusion scans: the D-048 worker, the D-060 broker, D-049 execution, and D-067 agent steps acquire nothing here, and no second admission cap exists.
Verified by
The rails wave passed 2141/2141 web tests in its own run (a verified gain of 95 over its measured baseline), including the shared-ledger proof that both new doors draw the existing 50 per-principal and 2000 global daily admission caps, the held-decision exclusion scans, and the assistant's discipline contracts. Local suite evidence only — no hosted activation or retained live-provider call is claimed.
Truth register
Governed AI explanation and drafting rails2026-08-30

See Runtime, Harness, Interlock, Verification

c-30

Guided tour

In buildShipped web source with content, engine, and source-scan suite evidence in the local environment; no hosted or signed-in acceptance run of the tour is claimed.

What it does
Walks thirteen steps across the shipped screens — the platform's argument, screen by screen — as a floating card over the live product, never a modal wall: anchored beside the step's element when its selector resolves, docked otherwise, keyboard-driven end to end.
What it leaves behind
Nothing durable. The only residue is the viewer's own resume position, held in that viewer's browser. Every step's route is pinned to an existing screen and every anchor to a literal string in that screen's own source, by test.
Where authority ends
The tour claims nothing the screens do not: step copy carries no digits and no overclaim vocabulary — both enforced by test, not convention — and a step over a fixture-backed screen states that standing in the same banner language the screen itself carries. The tour navigates and narrates; it performs no act, and it teaches nothing that is not on this branch.
Verified by
The tour wave's own PR run recorded 2363/2363 web tests on its branch, with the 13 steps' routes, anchors, and copy each pinned by focused content and engine contracts; the merged branch's full suite counts 2412/2412, the union of the night's sibling waves. Local suite evidence only.
Truth register
Guided tour walk-through2026-08-30

c-31

Database estate assessment lane

In buildPure package engine, two screens, and a durable citation register in current source; the register migration is hosted-applied as schema only, with no hosted register row, and the screens remain on the labelled fixture until a client corpus is registered.

What it does
Holds the third assessment sibling over database inventory CSV, stored-procedure DDL dumps, and schedule exports. Its parsing keeps a stated row count of zero distinct from an absent row count, and its string- and comment-aware DDL reader records calls only from explicit call keywords while retaining unread residue. Two screens sit over the engine, and one exact-scope citation register can now bind accepted field-evidence versions to the three content-first export kinds without copying export bytes.
What it leaves behind
Four pure modernization modules plus two server-rendered screens and a durable citation-only register. The register stores safe name, declared parser kind, bounded line counts, and the sealed digest; the seam re-reads exact Storage bytes, rechecks byte count and SHA-256, fatally decodes UTF-8, and refuses the whole corpus if any member fails. Until an engagement registers readable exports, the screens continue to render the labelled Thornbury Mutual fixture with the exact fixture reason.
Where authority ends
No connector reads a live database and no second upload or Storage-write path exists: every registered input is an already-accepted field-evidence file export. The source migration is not applied to a hosted target and no client export has been registered or rendered. Retire and retain remain candidate-only proposals, and registration grants no model, tool, Runtime, Interlock, connector, or execution authority.
Verified by
Engine history remains 344/344 then 353/353 package tests, with the screens wave at 2447/2447 web tests. The register wave's disposable-local gate reset cleanly through migration 202608300145 with zero schema-lint findings and passed its 44-assertion pgTAP contract; focused source contracts cover two standard gateway actions, an exact-scope locked reader, content-first three-kind admission, and whole-corpus provenance. This remains source/disposable-local evidence only: no hosted migration, registered client corpus, signed-in acceptance, live-database connector, or execution evidence.
Truth register
Database estate assessment lane2026-08-30

See Distributed estate sibling

c-32

Data estate assessment lane

In buildWeb lane seam, fixture corpus, and four screens on main over engines already merged in the domain package, rendering the labelled fictional fixture corpus only; no intake register, no persistence, and no hosted or signed-in acceptance.

What it does
Holds the fourth assessment sibling, and the standing phrase travels with it everywhere because its name sits one letter from its neighbour's: data content, not database shape. The database lane reads schema exports and answers what a database is declared to be; this one reads what is IN the data, from exports produced on the client's own side by the client's own tooling — a source census and a document-corpus census, column-level profile exports, a PII/PHI scan whose intake type structurally cannot carry a sample value, declared source-to-target mappings, authority declarations with cited conflict samples, and a canonical field-mapping spec. Four screens sit over the domain engines: a lane landing whose verdict families are counted apart with no sum across them anywhere on it; a source inventory where a census row that answered everything, a row that left an answer unstated, and a line that produced no record are three standings carried by three border styles rather than by colour; quality scorecards where an unmeasured dimension renders as unmeasured beside what would measure it, and a dataset that can only offer clearing the bar never wears the words a dataset that asserts it uses; and a classification register where a scanned column with a detector hit and no taxonomy disposition renders as suppressing the readiness verdict rather than lowering it. Every screen resolves through one seam, so no two of them can disagree about whose exports they describe, and each renders the same three-arm provenance banner.
What it leaves behind
Nothing durable. Rows are built on the server from a labelled fictional fixture corpus — Wrenfield Cooperative Grocers, a grocery co-operative that does not exist — and the shared evidence-table island sorts, filters, and hides columns while computing nothing. Freshness is measured against the engagement's anchored handover date rather than a clock, so the same exports score the same on any day, and every freshness reading is inferred with its basis stated rather than read from a source system. Export lines no parser could read are retained as counted, cited rows so a row count states what was handed over rather than what parsed, and the seam records which parser read which file, so a profile line nobody could read never appears as a source that failed to appear. Every citation minted from a scan or a conflict export is redacted to its file and line, because those are the two intakes most likely to carry a value the platform must never receive.
Where authority ends
No data intake register, migration, or gateway action exists for this lane — the distributed lane's export register is that lane's own and serves nothing here — so the seam's live branch resolves the honest no-register reason, and an engagement that has never been checked for client exports is never presented as one that was checked and found empty. No connector reads a live source: every input is a file export a person supplies, and the screens render the labelled fixture corpus only. The platform connects to nothing, runs no profiler, executes no scan, builds no index, computes no embedding, parses no document, and retrieves nothing; it reads supplied exports and records decisions about them. Where a surface here needs a column's existence or type it comes from this engagement's own uploaded artifacts and never from the database lane's corpus. Sensitivity treatments and source-of-truth adjudications are recorded decisions, never applied: a tag travels a declared lineage edge and an undeclared one propagates nothing. It proposes readings and carries no execution authority of any kind.
Verified by
The lane wave passed 2616/2616 web tests in its own run (baseline 2588 with the new suite removed, so the gain of 28 is verified rather than inferred), with the seam's three provenance arms composed and asserted rather than grepped for, each planted fixture defect pinned to the engine behaviour it exercises, and the withhold pinned as carrying no numeric field at all. Ten targeted mutations of the lane's own modules were run: the suite as first written killed eight, and the two survivors — a residue filter removed, and an absent corpus census rendering as a count — each produced a new rule, after which all ten died. The domain package was untouched in this wave and passed 673/673. This is web source evidence only: no register, no database, no hosted, no signed-in, and no execution evidence is claimed.
Truth register
Data estate assessment lane2026-08-30

See Database estate sibling · See Distributed estate sibling

c-33

AI-substrate decision studio

In buildFour screens on main over the DE-4 through DE-7 engines already merged in the domain package, rendering the labelled fictional Wrenfield fixture corpus only; no intake register, no persistence, no contact-center seam, and no hosted or signed-in acceptance.

What it does
Turns 'what should we build to make this data answerable' from an opinion into a citable record. Seven axes — retrieval architecture, chunking per document class, embedding and index, refresh and re-indexing per source, knowledge graph, parsing tier per document class, and structured access — are each decided against ONE anchored use case from declared evidence, and each emits a verdict carrying the options it scored, the cited criterion that moved every one of them, and the published threshold that fired. Three verdict shapes stay structurally separate on screen and five row states carry them, because a candidate that CANNOT be promoted until a named artefact exists and one that merely has not been are different facts, and because two options inside the published eight-point margin band are neither. A margin-band row reads 'undistinguishable — evidence does not separate the options', names both options at one weight with their scores, and asserts no leader: no tie is broken anywhere. Alongside it the readiness scorecard rates six weighted pillars against published anchors with the weights always on screen, refuses any rating with no evidence link into DE-1 through DE-6, withholds the composite entirely until every pillar rates, and flags the weakest rated pillar as the ceiling while saying so when a pillar is still unrated and the true ceiling can only be lower.
What it leaves behind
Nothing durable. The record and the scorecard are computed per request from declared fixture evidence and rendered on the shared evidence-table island, which sorts, filters, and hides columns while computing nothing. Every citation the studio mints is looked up in its own declaration table and throws rather than pointing at a line the fixture does not contain, so a hand-written citation cannot drift to a line number nobody checked. Absences are designed states rather than zeros: an unrated pillar carries no rating field, an unavailable composite carries no score field, a suppressed build verdict carries no numeric field of any kind, and a coverage figure over an undeclared denominator carries no value — each naming instead the act that would make it exist.
Where authority ends
No index is built, no embedding computed, no document parsed or retrieved; substrate decisions are records about a client's future build, not executions. Deciding is not executing. No retrieval is performed, no chunker or embedder or vector store exists anywhere in this tree, no golden-set evaluation is run, and no re-index is triggered — where the record says a refresh design is eval-gated, that is a condition written into a record and not a pipeline this platform operates. It runs no scan, no profile, and no eval of its own: every figure it rates is one an upstream stage already emitted from a client's own export. A classification withheld by DE-3 crosses into DE-6 as suppression and never as a discount — the build verdict becomes unavailable rather than lower, because the exposure was not measured and found small, it was not measured at all. Remediation items are not emitted into c-09 Roadmap versions and not emitted into the c-05 Opportunity portfolio; the roadmap is not written, read, or versioned here, and no opportunity is created, scored, or updated. No register, no migration, and no gateway action exists for this stage, and the contact-center manifest is unchanged by it. It proposes readings and carries no execution authority of any kind.
Verified by
Every figure here was re-derived in the merged tree rather than copied from the pull request body. The merge touches 16 files at 5,901 insertions / 2 deletions — 15 added and 1 modified, none deleted — every path under `apps/web`, with four of the added files route files, one per surface, and with no migration, no pgTAP file, no `fde` table, and no gateway action anywhere in it. Suites re-run on that tree: `apps/web` 2687/2687 in 78 suites, green with zero failures, against a 2663 baseline measured on the same tree by holding the merge's one new test file aside and re-running rather than by subtraction — a gain of 24. Typecheck exits 0 and prettier is clean on every touched file. This is gate 1, SOURCE SHIPPED: merged with the suites green and nothing beyond that — not hosted-applied, not activated, not verified. Web source evidence only: no register, no database, no hosted, no signed-in, and no execution evidence is claimed, and the authoring session's mutation scores were not re-derived here, so they are published nowhere as figures.
Truth register
AI-substrate decision studio2026-08-30

See Data estate assessment lane · See Contact-center operations and voice-agent lane · See Knowledge fabric

c-34

The Chartroom

In buildPure composer modules, three migrations since hosted-applied as schema only, and their contract in current source; no gateway action, no lane, no web surface, no hosted row, and no signed-in acceptance.

What it does
Projects what the lanes have already registered into one canonical graph, and is never a second source of truth. Seven pure lane composers — discovery, system inventory, mainframe, database, distributed, contact centre, and governance — read exact current registered facts through versioned derivation rules whose field maps and identity keys are declared, allowlisted records rather than code constants, so an answer cites the rule that turned evidence into a claim and a rule change is a diffable, attributable event. Entity resolution is deliberately boring and permanently so: declared keys only, with no fuzzy match, no embedding similarity, and no model-proposed merge — not a first-version simplification but a property of the design. A reference that cannot be resolved becomes an unresolved-reference edge to a gap node and is counted in the gap census rather than dropped, and the sealed digest of a build covers those gaps as well as the nodes and edges, so a graph cannot be made to look complete by leaving out what it could not answer. Merging two keys is a register change, never a Chartroom act.
What it leaves behind
Ten pure modules in the domain core, and three migrations holding the derivation-rule register, the node and edge store with its mandatory provenance stamp, and the append-only build receipts and snapshots. Every projection row is bound at persistence to the exact current source record, materialization, derivation rule, handling profile, and scope by foreign key rather than by convention, so an invented source identifier fails even where a fabricated materialization and rule row exist. Retraction, supersession, materialization withdrawal, or rule retirement invalidates the whole scoped graph and the current snapshot; a stale projection is invalidated, never repaired in place, and a new snapshot rechecks live counts and standing before it is written. A row carrying no evidence reference cannot be written at all.
Where authority ends
The Chartroom creates no authority, connects to nothing, and executes nothing. There is no insert path into it a human can reach: the lane registers are the write surface, and where the projection disagrees with the registers the projection is wrong and is invalidated rather than reconciled by editing it — there is no repair path, deliberately. A projection never becomes evidence, and no substrate acquires authority from a layer below it, so reading a projection of a register is not standing in that register and a claim cannot be laundered into fact by passing through the graph. No gateway action, no lane, no web surface, no browser write, no human edit, and no model or similarity path exists for any of it. The migrations are applied to the hosted production project as schema only, and they grant no table or routine privilege to the PostgREST roles; a graph composed from records that already exist grants nothing that was not already granted where those records live.
Verified by
Every figure here was re-derived in the merged tree rather than copied from the pull request body. The merge touches 21 files at 4,033 insertions / 6 deletions: ten `chartroom` modules in the domain core, three migrations — `202609010142`, `202609010143`, `202609010144` — creating five `fde` tables, one pgTAP contract declaring 61 assertions, and that contract's registration in the local data gate. The pure composer suite re-runs here at 13/13 and the package holding it at 255/255, green with zero failures. The tree census the honesty suite derives from the filesystem moved with this merge, from 94 migrations, 206 `fde` tables, 64 official pgTAP files, and 2231 declared assertions to 97, 211, 65, and 2292 respectively; later merges have moved it further and the current census is published on the data-foundation row rather than here. This was SOURCE SHIPPED at that merge: the source suites green and nothing beyond that. The hosted delta apply has since taken the three migrations to the HOSTED APPLIED gate for their schema alone — not activated, not verified, no signed-in walk, and the tables it created are empty. The 61-assertion contract was NOT RUN in this tree, because it needs a disposable local database this environment does not have; no hosted row, no signed-in acceptance, no gateway action, and no execution evidence is claimed.
Truth register
The Chartroom2026-08-30

See Immutability, audit, and secret rejection · See Knowledge fabric

c-35

The Discover Counsel

In buildPure domain modules, server-side enforcement, provenance chrome, and the addressed receipt merged to main; no published Counsel Card, no persisted proposal artifact or accepted record, and no hosted or signed-in acceptance.

What it does
Turns the workspace assistant into a governed counsel whose every answer is a cited Proposal Artifact rather than a paraphrase. Three things carry it. Per-assertion provenance is PROJECTED, never authored: no input anywhere sets a provenance tier, so the mark is derived from whether an evidence span resolved and from what the model draft's own review status already recorded — the source is declared positively and is never inferred from omission, so human authorship requires a named, parsed principal and a register-derived assertion names its row, unknown is the absence of a span, and a model that writes the word "unknown" into its own output changes nothing. Acceptance is parsed on the same principle: an accepted record names a principal and an instant that both parse, so an empty acceptor or a nonsense timestamp is refused rather than recorded. The proposal/accepted distinction is a TYPE, not a dashed border: the two are distinct types with no shared supertype any renderer accepts, so drawing a proposal in accepted chrome is a compile error rather than a style someone can override. And the citation contract, the refusal ladder, and the grounding scope are enforced server-side before anything reaches a browser — a citation resolving outside the card's own register namespaces is refused rather than quietly dropped, because a sentence left standing with its support removed reads as better evidenced than it is.
What it leaves behind
Two pure modules in packages/fde-core and one server module in the app. The floating assistant sidebar retires: a general-purpose chat pane bolted to the edge of every screen is a second, unaudited path to information that competes with the evidence tables. The engine does not die — model.ts stays and becomes the Counsel's. Provenance chrome renders its first tier always and its second tier only on demand, mounted rather than CSS-hidden so an unopened panel is absent from the accessibility tree, because maximalist provenance erodes trust rather than building it. The decision receipt gains a permanent, pasteable address alongside its existing download, re-derived per request from the same records by the same issuer, and stores nothing new.
Where authority ends
It proposes and it never acts. It grounds only on projected provenance and mints no evidence of its own: every mark is derived from a span that resolved or from a review status a person already recorded, and the Counsel writes neither. It acquires no authority from the projection it reads — no substrate acquires authority from a layer below it, so reading a projection of a register is not standing in that register. It holds no execution capability of any kind: every artifact is proposal-only, and accepting a proposal is refused outright for any assertion whose evidence never resolved. No Counsel Card is published, because publishing requires separation of duties — the approver may not be the author — and the package that wrote the definition cannot approve it, so with no published card the enforced answer is a REFUSAL rather than a fallback to ungoverned prose; an assistant that degrades to ungoverned text whenever its governance is absent has governance-when-convenient. Nothing is persisted: no proposal artifact and no accepted record is written, and no migration, gateway action, or register table exists for any of it. No new model path, no new admission class, no change to caps, and no widening of the assistant's grounding, which remains the caller's own Discover register. The receipt address grants no authority the download did not already have.
Verified by
Every figure here was re-derived in the merged tree rather than copied from the pull request body. The merge touches 22 files at 2,151 insertions and 56 deletions, and carries no migration, no pgTAP file, no fde table, and no gateway action; it adds exactly one route file, the addressed receipt page. Suites run on that tree: packages/fde-core 551/551 against a 533 baseline measured on the same tree by holding the package's two new test files aside and re-running rather than by subtraction, a gain of 18; apps/web 2,638/2,638 in 78 suites against a 2,627 baseline measured the same way for the three new web test files, a gain of 11. Both suites are green with zero failures. This is gate 1, SOURCE SHIPPED: merged with the suites green and nothing beyond that — not hosted-applied, not activated, not verified. Package and web source evidence only, with no database, hosted, signed-in, or execution evidence; the authoring session's mutation scores were not re-derived here and are therefore not recorded as figures.
Truth register
The Discover Counsel2026-08-30

See Governed AI explanation and drafting rails

c-36

Signed install manifest

In buildSource on main with the release tooling and its own fixtures; no published manifest, no hosted apply, no signed-in acceptance.

What it does
Composes a deterministic, source-derived release census of one source tree, as deployment topology spec 12 describes it: the exact source revision, the release branch, the application and data-plane boundary the census was built for, and the required environment-variable names — names only, never a value. Cryptography stays outside the domain module. The caller injects the repository's one governed-receipt canonicalizer and a hashing primitive, and the release adapter seals the closed receipt body with the existing deployment receipt key, so the single governed-receipt canonicalizer is never forked into a second one that would verify in one path and fail in another.
What it leaves behind
A closed, canonically ordered manifest body and its sealed receipt, held inside the release tooling and its own fixtures. Nothing is written to the product database, and no manifest is published anywhere.
Where authority ends
A manifest is provenance for one source tree and nothing else. It is not a topology qualification, not an install record, and not evidence that any environment holds the tree it describes — the qualification claim is recorded as not asserted, only the field topology is represented at the current version, and a later topology requires its own accepted qualification work. No signing key exists in source. No value of any named environment variable is accepted into a manifest or emitted from one, and there is no hosted apply and no signed-in acceptance.
Verified by
Every figure here was re-derived in the merged tree rather than copied from the pull request body. The merge touches 15 files at 1,823 insertions and 0 deletions. The pure contract holds 757 lines, the release adapter holds 527 lines, and the release verifier holds 261 lines. Evidence 2026-08-30: 5 pure contract tests in `packages/fde-core` and 4 adapter tests in `tools`, both green with zero failures, inside a package suite of 643 tests at 0 failures. This is gate 1, SOURCE SHIPPED — merged with the suites green and nothing beyond that; not hosted-applied, not activated, not verified.
Truth register
Signed install manifest2026-08-30

See Hosting, identity, and deployment topologies

c-37

Deployment posture lane

In buildPure contract and a fixture-backed lane on main; no register, no migration, no gateway action, no signed-in acceptance.

What it does
Holds the pure Deployment Posture contract: caller-supplied, citation-pinned observations are evaluated into criteria verdicts, and the immutable record a future register may persist is defined here rather than left to the surface that would show it. A lane sits over the engine — an overview and a criteria surface — and each renders the provenance of what it is describing rather than presenting the corpus as a client's.
What it leaves behind
Nothing durable. There is no register, no migration, and no gateway action, so a posture evaluation survives only the request that composed it, and the lane shows a labelled fixture corpus rather than a client posture.
Where authority ends
The module holds no register, environment, network, credential, model, tool, provisioning, or external-effect authority, and it reads no environment to find out what is true — every observation is supplied by its caller and pinned to a citation. A verdict is a reading of what was declared, never a qualification of a deployment, and no client posture has been recorded anywhere.
Verified by
Every figure here was re-derived in the merged tree rather than copied from the pull request body. The merge touches 21 files at 4,104 insertions and 9 deletions, and the pure contract holds 1,464 lines. The lane adds 2 routes over a labelled fixture corpus. Evidence 2026-08-30: 17 pure contract tests in `packages/fde-core` and 11 lane-view tests in `apps/web`, both green with zero failures. This is gate 1, SOURCE SHIPPED — merged with the suites green and nothing beyond that.
Truth register
Deployment posture lane2026-08-30

See Hosting, identity, and deployment topologies

c-38

The Convener

In buildPure domain modules and one read-only web bundle on main; no persistence, no gateway action, no counsel consulted, no signed-in acceptance.

What it does
Routes one question to the counsels whose substrate can answer it, checkpoints each consultation as it lands, and reconciles what came back — deliberately not a knower. The ignorance fence is in the types rather than in a review convention: a citation handle carries a record id, a version, and a digest and has no text field at all, so a Convener that wanted to quote evidence has nothing to quote from, and it therefore cannot manufacture an uncited claim or become the plane that both reads the evidence and composes the answer. The Mission Brief is published in full to every consulted counsel — the client-facing question, who else was consulted, and every refusal already recorded — so no counsel is handed a narrowed slice of the objective and orchestrator-suppression is structurally unavailable. A narrow reconciliation margin defers to a human and raises a decision request; no tie is broken anywhere, because a tiebreak would manufacture a decision the evidence does not support. A refusal is terminal and survives verbatim, and dissent is retained rather than averaged away.
What it leaves behind
An append-only mission ledger in memory: every consultation is checkpointed as it lands, and resuming is a pure function of what is already recorded, so a restart neither loses a consultation already paid for nor silently repeats one. Overwriting an existing ledger entry is refused. Nothing is persisted — there is no mission table, no migration, and no gateway action — so the ledger survives only the process that held it.
Where authority ends
The Convener reads register-row identifiers, versions, digests, verdict shapes, evidence bases, decision margins, citation sets, and refusals, and it may not read evidence bodies, excerpt text, or documents. It holds no model, tool, connector, or provider authority, and no counsel has been consulted: the routing table names substrates, and an unroutable class is refused rather than assigned to whichever counsel is nearest. No mission has been persisted, and there is no hosted or signed-in acceptance.
Verified by
Every figure here was re-derived in the merged tree rather than copied from the pull request body. The merge touches 17 files at 2,416 insertions and 1 deletion, adding 4 modules under `packages/fde-core/src/convener`. Evidence 2026-08-30: 48 pure contract tests in `packages/fde-core` and 5 bundle tests in `apps/web`, both green with zero failures. The authoring session recorded a mutation score of 14 killed of 14; that is retained as its own claim and was not re-derived here. This is gate 1, SOURCE SHIPPED — merged with the suites green and nothing beyond that.
Truth register
The Convener2026-08-30

See The Discover Counsel

c-39

Act intents and approval budget

In buildPure core modules and their contract in current source, with a migration ordered ahead of #138's. No gateway action, no lane, no web surface, no hosted row, and no signed-in acceptance.

What it does
Holds the typed boundary between a proposal and an act. A register-write proposal binds exact proposed content and current cited evidence into inline batch review; an internal artifact remains a structural draft until a reviewer opens it; an outbound-to-human draft withholds recommended text until a named reviewer opens cited evidence and may become durable only through a named-human release bound to the exact viewed draft and final-render digest. The currently constructible register forms are claim, link, and supersession; gap stays withheld behind the separately owned public gap contract. A versioned engagement-week approval budget derives standing from recorded proposal and decision history, including unchanged rejected recurrence, and stops proposal generation when policy or required metrics are unavailable or when the configured decision-time floor or release-rate ceiling fires.
What it leaves behind
Immutable scope-bound intent, citation, draft-version, review-event, batch-ratification, release, receipt-verification, policy-head, and decision rows. The server-only release repository derives authority from locked private rows, reuses the existing governed-receipt signer and verifier, and atomically records the verified receipt, its verification fact, and the approval decision; failed verification or stale evidence leaves none of them durable.
Where authority ends
An act intent is a record that something was intended, never that it happened. Nothing in this package executes, transmits, or effects anything: there is no sender, no connector, no provider call, no egress, and no executor of any kind — a Class 2 receipt becoming durable grants none of them. A durable receipt is evidence that an intent was recorded and verified, and a reader must not take it as evidence that the intended act occurred. This package ships no lane route and therefore no console record, deliberately — there is no surface to reach and none is claimed. No hosted row, no activation, no signed-in acceptance.
Verified by
The additive act-intent migration creates 10 FDE tables and its registered pgTAP contract declares 142 assertions. The resulting current tree contains 99 migrations, 222 FDE tables, 67 official pgTAP files with 2498 declared assertions, 15 registered concurrency harnesses, and 66 additional fixture-backed behavioral assertions. Direct pinned-runtime evidence passed the pure act contracts, focused web act suite, capability-honesty, capability-coverage, counterexample, and protected-wiring checks. A clean disposable reset and zero-finding schema lint then passed the focused claim-plus-act contracts at 206 of 206. The retained repair mutation score is 3 killed of 3, with zero survivors: a real network-module import made the no-egress check fail, restoring the unparenthesized JSON relation-array expression made the transitive-evidence contract fail, and restoring the over-strong workspace row lock prevented the Class 2 release from reaching its claim-lineage lock before all three canonical repairs passed. This remains PARTIAL source and disposable-local evidence. Any exact-final full-pipeline and optimized-build evidence is retained with the PR handoff rather than treated as hosted, activated, routed, signed-in, or effect evidence.
Truth register
Act intents and approval budget2026-08-31

See Immutability, audit, and secret rejection · See Act attribution and separation of duties

c-40

AI estate lane

In buildDomain engines and a fixture-backed lane on main; no intake register, no persistence, no hosted or signed-in acceptance.

What it does
Holds the register of what AI is actually in use inside a client organisation, on the standing rule that the inventory is never the sanctioned list. Three asset classes stay three: folding AI switched on inside already-approved software into the unsanctioned class is how the largest and least visible surface stops being counted, and filing it as sanctioned asserts a decision nobody made. Register completeness is a type rather than a check — a complete register is minted only by the completeness assessment on its complete arm, so a disposition written without the gate does not compile — and an incomplete register strips every disposition rather than some, because a row keeping its classification beside an incompleteness notice invites the reader to trust it anyway. A block with no alternative is derived down to a candidate from the absent alternative itself, never from a caller's flag. A source that answered nothing and a source nobody supplied are different facts, and the census says what each absence does not mean. A written policy with no enforcement point is recorded as a gap, never as a control.
What it leaves behind
A rolled-up estate with its completeness verdict, its per-asset dispositions, and a census that names what it could not answer. Nothing is durable: there is no intake register, no migration, and no gateway action, and the lane shows a labelled fixture corpus rather than a client's estate.
Where authority ends
Nothing here scans, discovers, or reads a client system: every asset in the register was declared by a person, and the lane says so on the page rather than in a footnote. There is no model, tool, or connector call on this path and no authority over any client system. No client estate has been registered, no disposition has been acted on, and there is no hosted or signed-in acceptance.
Verified by
Every figure here was re-derived in the merged tree rather than copied from the pull request body. The merge touches 15 files at 2,745 insertions and 0 deletions, adding 3 modules to `packages/fde-modernization` at 911 lines and 1 route under the workspace lane. Evidence 2026-08-30: 15 engine tests in `packages/fde-modernization` and 11 lane tests in `apps/web`, both green with zero failures, inside a package suite of 688 tests at 0 failures. The authoring session recorded mutation scores of 24 killed of 24 on the engines and 10 killed of 10 on the lane; those are retained as its own claims and were not re-derived here. This is gate 1, SOURCE SHIPPED — merged with the suites green and nothing beyond that.
Truth register
AI estate lane2026-08-30

See Data estate assessment lane · See AI-substrate decision studio

c-41

Gap register

In buildDomain, private register, coverage generators, closed origin vocabulary and an optional mount contract on main; rendered in no production composition. Source shipped and nothing beyond it.

What it does
Defines structured absence as a governed first-class gap rather than an empty state or a zero score. The pure contract binds each gap to its exact tenant, owner organisation, engagement, workspace, handling profile, closer kind, optional closer role holding, closing test, blocked claims and gates, opening instrument, and actor. The closed opening-origin vocabulary admits only `distributed.export.parser`, `estate.instrumentation.coverage`, `claim.recommended.ratification`, and `claim.recommended.corroboration`; the matching coverage generators refuse anything outside those origins. Its projection keeps unread, answered-empty, and unknown-and-blocking structurally distinct, and an optional Mission Cockpit mount accepts only that projection. A server-only adapter exact-binds a trusted current-plan target and server-derived Discover scope before reusing the existing `requestEvidence` gateway.
What it leaves behind
Migration source defines one private, immutable, audited `fde.gaps` register, while the pure and web modules define the gap contract, coverage generators, card projection, optional mount, and evidence-request adapter. Each gap names what remains unknown, the evidence that would close it, the responsible closer kind and available role holding, and the exact claims or gates held by the absence. Age is derived from the stored opening instant and an explicit as-of clock rather than persisted as stale truth. The closer role holding remains nullable until the real organisational picture supplies its foreign key; no placeholder authority is invented.
Where authority ends
Current production composition renders zero gap cards. There is no governed read of `fde.gaps` through the engagement overview, no trusted generator-to-register insert adapter, no production caller of the evidence adapter, and no live evidence transition, read, or action path. A gap row neither authorizes evidence creation nor unblocks its named claims or gates. The Mission Cockpit mount contract is optional and no production caller supplies it. That is an integration boundary, not a defect, and it is stated here so nobody reads the merged module as a live card. No hosted apply, no hosted row, no signed-in acceptance.
Verified by
Evidence 2026-08-31: the pure core gap suite passed 9/9 tests and the executed web composition suite passed 10/10 tests on this source tree. Migration `202609020162` creates 1 `fde` table; its pgTAP contract declares 46 assertions, and retained clean-apply evidence passed 46/46 assertions with zero schema-lint findings. The authored mutation campaign killed 45/45 mutants with zero survivors. The exact source census is 100 migrations, 68 official pgTAP files / 2544 declared assertions, 223 `fde` tables, 15 registered concurrency harnesses, and 133 actions. The canonical full gate has not yet run at this exact head. This is SOURCE SHIPPED only: no hosted apply, hosted row, production composition, live read or action, or signed-in acceptance is claimed.
Truth register
Gap register2026-08-31

See Assessment Studio · See Immutability, audit, and secret rejection · See Evidence claim register

c-42

Evidence claim register

In buildPure contracts and a migration on main, hosted-applied as schema only; no hosted row, no gateway action, no web surface, no signed-in acceptance.

What it does
Holds a claim as an authoritative evidence-register row, and keeps that layer distinct from the two it is most often confused with: a claim is not an accepted cross-lane decision, which is what a Standing Reference points to, and it is not a derived graph materialization, which is what the Chartroom projects. The pure contract mirrors the closed database contract at process boundaries — basis class, confidence level, likelihood band, ancestry, and ratification — while the database remains the authority for tenancy, source standing, ancestry, ratification, and the immutable version chain. Method priors are published as their own contract so a prior is a citable record rather than a constant nobody can argue with.
What it leaves behind
An immutable, row-level-security-enforced claim register with its version chain and ratification trail, and a pgTAP contract standing behind it. The hosted table it created is empty.
Where authority ends
The pure contract holds no register, network, clock, persistence, model, tool, or effect authority — it parses and refuses, and the database decides. A claim asserts evidence standing, never a decision: ratifying one is a human act recorded elsewhere, and no ratification act has been performed anywhere. The migration is hosted-applied as schema only; that is schema posture and not acceptance, there is no hosted register row, and no gateway action or web surface for claims exists.
Verified by
Every figure here was re-derived in the merged tree rather than copied from the pull request bodies. The claim contract holds 977 lines and the method priors hold 1,211 lines; migration `202609020160` creates 1 `fde` table, and its pgTAP contract declares 64 assertions, both inside the current local-data gate census published on the data-foundation entry. Evidence 2026-08-30: 35 pure contract tests in `packages/fde-core`, green with zero failures, inside a package suite of 643 tests at 0 failures. The pgTAP contract needs a disposable local database this environment does not have and was NOT RUN here. This is gate 1, SOURCE SHIPPED, with the migration at the hosted-applied gate for its schema alone.
Truth register
Evidence claim register2026-08-30

See The Chartroom · See Standing References

c-43

Standing References

In buildOne pure contract on main with one in-tree consumer; no register, no surface, no signed-in acceptance.

What it does
Points, and only points, at a terminal human act held at one exact version and digest — the cross-lane reference contract that lets one lane cite a decision another lane already made without copying it, restating it, or re-deciding it. Every input is a caller-supplied snapshot: the module holds no register of its own, so it can say whether a cited act still stands and nothing more.
What it leaves behind
Nothing durable. There is no register, no migration, no gateway action, and no web surface, so a resolved reference survives only the request that resolved it.
Where authority ends
The module holds no register, network, clock, persistence, model, tool, or effect authority. A partial composition is a refusal rather than a permissive default: the source state must be its exact permissive value, so a half-constructed envelope, or a round-trip that dropped the field, is refused rather than silently endorsed. One guard is carried forward without a test holding it, and that is stated here rather than left for a reader to discover. No standing reference has been persisted anywhere, and there is no hosted or signed-in acceptance.
Verified by
Every figure here was re-derived in the merged tree rather than copied from the pull request body. The merge touches 4 files at 1,324 insertions and 0 deletions, and the contract holds 682 lines. The earlier receipt recorded that the contract had no consumers anywhere in the tree; that is superseded, because the deployment-posture contract now cites it and remains its only in-tree consumer. Evidence 2026-08-30: 19 pure contract tests in `packages/fde-core`, green with zero failures, inside a package suite of 643 tests at 0 failures. This is gate 1, SOURCE SHIPPED — merged with the suites green and nothing beyond that.
Truth register
Standing References2026-08-30

See Deployment posture lane · See Evidence claim register

c-44

Mainframe modernization assessment lane

In buildEngines, screens, and a durable citation-only intake register on main, published here for the first time; register migration not hosted-applied, screens fixture-backed, no acceptance of any kind.

What it does
Holds the first of the estate assessment siblings — the lane the distributed, database, and data lanes are each described against, and which this register has until now only ever mentioned as somebody else's sibling. Fixed- and free-format COBOL line modelling, copybook and picture and packed-decimal reading, statement segmentation, business-rule extraction, and job-control reading feed an estate scan and its rollup; per-program disposition is argued from what the source states rather than asserted, and a proposed target architecture, a migration wave plan, a business case, and a six-dimension readiness rubric sit on top of it. Every extracted fact is unconstructible without a citation, which is the honesty substrate the whole lane is built on. Client member text enters exclusively through the existing field-evidence pipeline; a citation-only intake register pins one accepted artifact version per member, and registering an export re-reads the exact stored bytes, re-verifies the digest, and checks the declared kind content-first, refusing a contradiction with redacted diagnostics that never carry member text.
What it leaves behind
A row-level-security-enforced, audited, no-delete citation register naming the exact accepted artifact version per member — name, declared kind, bounded line counts, and sealed digest — where registered to withdrawn is the only legal transition and carries its actor and reason. The derived estate models are a bounded cache over that register, not a second store. Until an engagement registers readable exports the lane shows a labelled fixture corpus, and a register that could not answer is disclosed as silence rather than shown as empty.
Where authority ends
Read this entry more sceptically than the ones around it, and the reason is on the record: a lane this size shipped without a register entry, so nothing on this page had been checked against it until now, and its scope is stated narrowly here rather than generously. The lane reads what a client already supplied and holds no authority over any client system — no model, tool, or connector reads client source, there is no scheduler or runtime knowledge, and no malware or data-loss screening is claimed beyond the evidence lane's recorded not-performed value. A disposition is an argument with its citations attached and never an instruction to act; a readiness rating is a reading of declared evidence and never a verdict on a system; a wave plan is a proposal that sequences nothing and schedules nothing. The intake register's migration is applied to the hosted project as schema only — the table exists and holds nothing — no client corpus has been registered, and no acceptance of any kind is claimed or implied: no browser walk, no dedicated-project run, no hosted row, and no signed-in acceptance.
Verified by
Every figure here was re-derived in the merged tree rather than copied from any pull request body, because this lane has never had an entry whose figures anyone could have been checking. `packages/fde-modernization` holds 22 lane modules over the shared honesty substrate, and 10 routes sit under the workspace modernization lane. Migration `202608290113` adds the citation register, and 2 registry actions ride the standard gateway stack. Evidence 2026-08-30: `packages/fde-modernization` runs 688 tests at 0 failures, green. This is package and web source evidence and nothing else. NOT RUN here and therefore not claimed: the hosted apply of the intake migration, any disposable-local database run, any browser or dedicated-project walk, and any signed-in acceptance. The entry states what the source holds; it does not state that anyone has accepted it.
Truth register
Mainframe modernization assessment lane2026-08-30

See Distributed/VMware estate assessment lane · See Database estate assessment lane · See Governed AI explanation and drafting rails

c-45

Model economics

In buildA pure register and one lane surface on main; no persistence, no provider call, no cost measured against a client workload, no signed-in acceptance.

What it does
Answers the question the rest of the model lane cannot: what a unit of delivered capability costs, per workload shape. The lane governs whether a model may be connected, delivered, invoked, and reconciled, and holds not one figure about what any of that costs. Two layers stay separate and are never added together — first-party measured, composed only from provider receipts this workspace itself recorded, and third-party reference, which is somebody else's measurement and travels with their source, their method, and the statement that would falsify it. The shipped rate card is third-party: published list prices attributed to their source, whose cache figures are declared as derived from the published input rate by the documented multipliers rather than published per band, because a derived figure that reads like a published one is a figure nobody can check. Every figure traces to one dated observation and is aged against a declared freshness threshold.
What it leaves behind
Nothing durable. There is no register table, no migration, and no gateway action, so a costing survives only the request that composed it. What the surface leaves the reader is the provenance of each figure: which layer it came from, the date it was observed, and, where a band has no first-party observation at all, the sentence saying so.
Where authority ends
It prices nothing and buys nothing: no provider is called on this path, no receipt is collected, and no cost has been measured against a client workload. The third-party rate card is a dated, sourced observation and never our measurement, and it is never summed into a first-party figure. The reasoning band is reported as unmeasured rather than as zero, because no register in this lane counts reasoning tokens separately and zero is a measurement while absence is not. An observation past the declared threshold withholds its number and names its own date rather than rendering as current, and an observation dated in the future ages out rather than being trusted, so a wrong clock cannot launder a figure past the only guard the surface has. The shipped rate card was observed on 2026-06-24 and ages out from 2026-09-23 unless it is re-observed; nothing here refreshes it. There is no persistence, no activation, and no hosted or signed-in acceptance.
Verified by
Every figure here was re-derived at the rebased head rather than copied from the pull request body. The merge touches 7 files at 2,432 insertions and 0 deletions; the pure contract holds 616 lines, the lane's presentation module holds 450 lines, and its screen holds 357 lines. The rate card holds 4 rows of published list prices attributed to their source. Of the 5 cost bands, 4 are measured and 1 is not. The declared freshness threshold is 90 days. Evidence 2026-08-30: 18 lane tests in `apps/web`, green with zero failures, inside a package suite of 643 tests at 0 failures. There is no dedicated package test file for the contract; it is exercised through the web suite, and that gap is recorded rather than papered over. This is gate 1, SOURCE SHIPPED — merged with the suites green and nothing beyond that.
Truth register
Model economics surface2026-08-30

See Governed AI rails · See Runtime, Harness, Interlock, Verification

c-46

Composition board

In buildA pure contract, a shared canvas substrate, and one lane surface on main; fixture-backed, with no persistence, no register row, no migration, and no signed-in acceptance.

What it does
A board for composing governed workflow acts, where each step declares what it may propose, what it may execute, and what it is forbidden. A route that would grant an act to a step permitted only to propose is refused while the connection is still being drawn, and the refusal carries the workflow compiler's own diagnostic code against the same step the compiler would name. The subset of the compiler's diagnostics answered during a drag is exactly those a single route is enough to decide; every other diagnostic is listed with a written reason for deferring it and is stated as the definition stands rather than guessed at mid-gesture. Agreement between the two readers is proven by running both over every candidate route of every fixture board, in both directions, rather than by having them share a helper.
What it leaves behind
Nothing durable. No workflow definition is written to any register, there is no migration and no gateway action, and the board a reader composes survives only the page it was composed on. What it leaves the reader is the reason: a refusal names its code, its policy, and the step it blames, and a route that names a step nobody placed is reported by name rather than silently dropped.
Where authority ends
It records nothing and runs nothing. No step on the board can be executed from it — a compiled order is data about the graph and confers no authority to run it — no engagement corpus is read, and no register row stands behind the lane. The board reads one literal fixture corpus held in the lane's own source. A step placed from the palette cites the hand that placed it and declares no binding reference, because a citation the surface invented on the author's behalf would be the first untruth on a board whose subject is provenance. There is no persistence, no activation, and no hosted or signed-in acceptance.
Truth register
Composition board (governed acts, refused mid-drag)2026-08-30

See Workflow definitions and compilation · See System map

c-47

System map

In buildA pure derivation, a shared canvas substrate, and one lane surface on main; one synthetic corpus, with no persistence, no register row, no migration, and no signed-in acceptance.

What it does
Derives a system's shape from supplied evidence — components, dependencies, data flows, ownership — where every node and every edge names the source it was read from. A component nobody supplied is drawn as a hole carrying the artifact that would fill it and the accountable role; an unresolved relationship terminates in that hole rather than being omitted. What is unknown is a thing on the plane, not a gap in the drawing. The confidence a node carries is a corroboration rung on a published four-step ladder, printed as the rung's own word: the underlying figure selects how many marks are filled and never reaches the screen, because a two-decimal fraction is the notation of a probability whatever the sentence beside it says.
What it leaves behind
Nothing durable. There is no evidence register behind the lane, no migration, and no gateway action. What the surface leaves the reader is a ledger of the sources that were expected and which of them arrived, and a list of the questions this map cannot answer, each with the artifact that would close it and the role accountable for supplying it.
Where authority ends
It does not discover. It reaches no system, no network, and no repository; it reads only evidence that was handed to it. It reports no completeness figure — no percentage, no coverage score, no estimated total — because it does not know how large the estate is, and the census is held to counts of things actually on the map. It is not a drawing surface: a connection drawn by hand is refused, and a dependency is recorded by supplying the source that states it. It runs on one synthetic corpus held in the lane's own source, so no reading on this lane is a reading of a real estate. There is no persistence, no activation, and no hosted or signed-in acceptance.
Truth register
System map (derived from supplied evidence, holes drawn)2026-08-30

See Systems and integration topology · See Composition board

c-48

Reflexion instrument

In buildInstrument and route on main against a labelled synthetic corpus, fixture-backed with no register and no migration. Source shipped and nothing beyond it.

What it does
Compares a low-confidence client-asserted or explicitly inferred high-level architecture model with an extracted source model through an explicit, attributed human map. The engine parses canonical `ClaimRecord` evidence and requires exact endpoints plus a closed relation semantic before it reports convergence, divergence, or absence — never a score. Every finding retains the relation, interaction, endpoint, map, and claim evidence that produced it; coverage carries its denominator, deliberately deferred regions remain visible, an investigated exception suppresses only the exact evidence snapshot it records, and an effort-changing divergence carries its revised estimate rather than laundering it into a confidence figure.
What it leaves behind
An immutable in-memory comparison and one read-only authenticated workspace lane over a clearly labelled synthetic fixture. There is no Reflexion register, migration, persistence adapter, gateway action, model or provider call, client extraction, client evidence, client architecture, hosted row, or durable exceptions ledger. The fixture exception snapshot is explicit human-reviewed test evidence, not a client audit record.
Where authority ends
A reflexion instrument reads what was recorded and reports what it finds; it decides nothing and changes nothing. Its output is an observation about the record, not a claim within it, and nothing it produces authorizes an act, satisfies a gate, or discharges an obligation elsewhere in the platform. It reads the labelled synthetic corpus only. No client corpus is registered anywhere, no hosted row exists, and no signed-in acceptance has occurred. Its findings have never been reviewed by anyone, because nothing has yet been given to it that a person was asked to judge.
Verified by
Evidence 2026-08-31, every figure re-derived at the exact final local candidate: the candidate touches 21 files at 5,012 insertions and 3 deletions, and the pure Reflexion module holds 1,529 lines. Direct Node 24.19.0 runs passed 24 of 24 core Reflexion tests and 33 of 33 route/surface-bijection plus lane tests, 57 of 57 total, with zero failures. The earlier authoring receipt recorded 29 of 29 physical mutations killed with zero survivors; that score predates the final rebase and is retained as historical evidence rather than claimed as an exact-head rerun. This is gate-one source evidence and nothing beyond it.
Truth register
Reflexion instrument2026-08-31

See Evidence claim register · See System map

c-49

Artifact intake and disposition

In buildEngine and lane on main against a labelled synthetic corpus, fixture-backed with no register and no migration. This is source shipped and nothing beyond it.

What it does
Reads a heterogeneous pile of client material — SQL/DDL including the mainframe dialect, delimited inventories, and structured text — says what each artifact IS from its content rather than its filename, and proposes one of six dispositions for it with the reasoning that produced the proposal and the observation that would overturn it. Classification is from the bytes: the extension is recorded as evidence and reported when it disagrees, never resolved silently in its own favour. Extraction is derivation — every fact is READ from a named line or marked INFERRED with its basis and a confidence band, and the two never render at the same weight. Provenance is per-fact rather than per-file, so every extracted fact cites the artifact and the line within it. The artifact is keyed by its content, so re-ingesting the same bytes converges and a revision arriving under an unchanged filename is recognised as a revision rather than silently overwriting what it supersedes.
What it leaves behind
Nothing durable. There is no register table, no migration, and no gateway action, so a reading survives only the request that composed it. What the surface leaves a reader is each artifact’s proposed disposition, the figures behind it, and the falsifier that would overturn it — plus, where a module has no register to receive material, the statement that it is retained unrouted for that reason rather than filed somewhere that cannot hold it.
Where authority ends
An artifact intake proposes; it never files. Every disposition this engine produces is a recommendation awaiting a named human’s acceptance, and nothing it emits moves a record, updates a register, or admits an artifact into the estate on its own authority. A disposition is an argument about where something belongs, not an act of putting it there. What it extracts is derived from the artifact and nothing else. A fact it could not read is absent and visible as absent; a fact it inferred is marked inferred and carries its basis. It does not complete a partial picture, and a shape it did not find in the file does not appear because the file resembled one that had it. It reads the artifact classes it declares and refuses the rest by name rather than by guessing. `cannot classify` is a real answer it is permitted to give and is never a fallback into the nearest bucket. No client corpus is registered anywhere. The corpus this lane renders is the labelled synthetic one; no hosted row, no signed-in acceptance, no activation, and no migration. Its dispositions have never been accepted by anyone, because nothing has yet been given to it that a human was asked to decide about. A decision composed here is not retained. The contract determines what a valid acceptance or rejection consists of; nothing yet records one, and no decision made against this version survives the request that made it.
Verified by
Evidence at the exact rebased head: the package gate passed with the complete artifact-intake domain suite, including executed intake boundaries, decision acts, extraction, and enterprise-corpus cases. A compiling mutation campaign killed every planted decision-contract weakening after the measured first pass exposed and closed a surviving boundary. The engine remains behind one alphabetically placed sub-barrel line and the existing registered lane. No migration, register, hosted apply, signed-in walk, retained decision, or accepted disposition is claimed.
Truth register
Artifact intake and disposition2026-08-31

See Database estate assessment lane · See Mainframe modernization assessment lane

c-50

Interface actionability assessment

In buildEngine modules on main behind their barrel lines, unit-tested with inline constructed values. No lane, no route, no fixture corpus, no register, no migration. Source shipped and nothing beyond it.

What it does
Reads a system interface and answers, separately and with a citation each, the four questions that decide whether an agent may touch it: can it be read, can it be written, is the write idempotent, and is there a compensating reversal. Answers are marked DECLARED where a specification states them and OBSERVED where traffic or a probe established them, and the two never count as the same evidence. Specification coverage and specification accuracy are held apart — a specification describing an endpoint the system no longer serves has full coverage and no accuracy — so accuracy stays unknown where no traffic export was supplied rather than being inferred from coverage. It proposes one of five dispositions with the signals that produced it and the observation that would overturn it, and publishes the D-023 rung the evidence would support as a reading rather than a grant.
What it leaves behind
Nothing durable. There is no register table, no migration, and no gateway action, so a reading survives only the request that composed it. What it leaves a reader is each interface’s disposition, the observed-answer count behind it, the named questions nobody answered, and the falsifier that would overturn it.
Where authority ends
Actionability assesses per interface and recommends; it decides nothing. Every recommendation it produces is an argument about what should happen next, addressed to a person who may reject it, and nothing it emits schedules work, assigns anyone, or discharges an obligation recorded elsewhere. A compensating reversal is something this lane READS from the client’s exports, never something it proposes. Its absence is a finding about the system, and the refusal it triggers is absolute: no write path without one is wrapped at any autonomy tier. What the assessment could not determine is stated as undetermined rather than scored, and an interface it was given no evidence for is absent from the assessment rather than rated zero. No client corpus is registered, no hosted row exists, and no recommendation has been accepted by anyone.
Verified by
Every figure re-derived at the rebased head by executing the built module or the named gate, not copied from a pull request body. 2 engine modules at 563 lines behind 2 barrel lines; 5 dispositions; 4 supported rungs; 9 interface protocols; 3 answers; 2 evidence kinds; minimum evidence basis 40, minimum decision margin 8; 0 routes, 0 migrations, 0 registers, 0 lane screens. Under `npm --prefix packages/fde-modernization test`: 705 tests, 705 pass, 0 fail, of which 17 are this domain’s. Mutation 14/14 after a measured 12/14 first pass, with no compile-error credit. NOT RUN and therefore not claimed: `npm run test:data:local`, which cannot run on the authoring machine.
Truth register
Interface actionability assessment2026-08-31

See Mainframe modernization assessment lane · See Artifact intake and disposition

c-51

Regulatory obligation register

In buildEngine modules on main behind their barrel lines, unit-tested with inline constructed values. No lane, no route, no fixture corpus, no register, no migration. Source shipped and nothing beyond it.

What it does
Cites regulatory requirements against operator-registered authoritative instruments and classifies the systems they bear on. Every obligation row carries an anchor into a registered instrument, addressed in that instrument’s own declared grammar; a row whose anchor resolves into a derived working copy — a spreadsheet extract, a JSON export, a prior-session summary — halts rather than degrading into a weaker row, because the transformation that produced the copy is exactly where a requirement’s text and ordering silently change. Per system it records the regulatory classification and the provider-versus-deployer role, territorial scope, whether a governance body exists, and — separately — whether that body holds the authority to stop a deployment. It also holds one control-library crosswalk, mapping each control once and reporting it into many frameworks.
What it leaves behind
Nothing durable. There is no register table, no migration, and no gateway action. What it leaves a reader is each cited obligation with its instrument anchor, each system’s classification with the register-completeness verdict it was computed under, the governance findings held apart, and — where an instrument was never supplied — a named request for the exact document and edition that would close the gap.
Where authority ends
This platform never authors a regulatory requirement. It only cites one. Every obligation held here traces to a source outside this system, and an obligation whose citation cannot be resolved is not an obligation — it is a gap, and it renders as one. Nothing here interprets a regulation, asserts that one applies, or certifies compliance with any of it. Accountability is an organization and a role, never a person: there is no field for a name, and a role the client’s own organization export does not declare is refused outright rather than recorded. This lane does not assess whether an obligation has been met, and produces no compliance verdict and no legal advice. An obligation whose citation cannot be resolved is returned as insufficient evidence naming the instrument that would close it, never as a weaker obligation. No client corpus is registered, no hosted row exists, and no signed-in acceptance has occurred.
Verified by
Every figure re-derived at the rebased head by executing the built module or the named gate, not copied from a pull request body. 3 engine modules at 772 lines behind 3 barrel lines; 4 anchor grammars; 3 halt-authority findings; 4 risk classifications; 3 governance evidence kinds; 0 routes, 0 migrations, 0 registers, 0 lane screens. Under `npm --prefix packages/fde-modernization test`: 711 tests, 711 pass, 0 fail, of which 23 are this domain’s. Mutation 19/19 after a measured 17/19 first pass, with no compile-error credit. NOT RUN and therefore not claimed: `npm run test:data:local`, which cannot run on the authoring machine.
Truth register
Regulatory obligation register2026-08-31

See AI estate lane · See Interface actionability assessment

c-52

Process opportunity register

In buildEngine modules on main behind their barrel lines, unit-tested with inline constructed values. No lane, no route, no fixture corpus, no register, no migration. Source shipped and nothing beyond it.

What it does
Reads client-exported event logs and mines the process as it actually ran — variants, case counts, and median cycle times, each carrying the window they were mined from. It classifies conformance deviation as value-destroying or legitimate and counts the two apart, because a single deviation figure reports an operation serving three customer segments differently as an operation out of control. Per activity it states suitability three ways and never two: rules-based, judgment on unstructured text, or blocked on upstream data — and the third routes to the data estate rather than to an automation. It ranks candidates on value against a feasibility it CONSUMES from the Actionability Register, and reads the existing automation estate from orchestrator run logs, where a bot driving a screen is the strongest available evidence of a missing interface.
What it leaves behind
Nothing durable. There is no register table, no migration, and no gateway action. What it leaves a reader is the locked baseline with the window and case count behind it, each candidate’s value and consumed feasibility with the Actionability verdict they rest on, the two deviation counts held apart, and — where no lockable baseline exists — the named export that would produce one, or the statement that it is unrecoverable.
Where authority ends
An opportunity is a possibility nobody has claimed, held separately from anything that has been decided. Naming one authorizes nothing, commits no one, and creates no obligation — a reader must not take its presence here as evidence that anyone intends to pursue it. Process findings are derived from the supplied event evidence and no further. The baseline is locked before any opportunity is ranked: the lock is minted only from a timestamped, pre-intervention event log, and no opportunity can be produced without one. This lane does not itself compare later measurements against that baseline — the locked pack is handed onward, and that handoff is not built. Where the evidence could not establish a path, the gap is visible rather than interpolated. It never asserts feasibility; that verdict belongs to the Actionability Register, and an interface refused there for having a write path with no compensating reversal is not ranked low here, it is not ranked at all. No client event log is registered, no hosted row exists, no signed-in acceptance has occurred, and no opportunity has been reviewed by anyone.
Verified by
Every figure re-derived at the rebased head by executing the built module or the named gate, not copied from a pull request body. 3 engine modules at 738 lines behind 3 barrel lines; 4 baseline sources; 3 activity suitabilities; 4 intervention types; 5 disposition-to-feasibility transcriptions; minimum decision margin 8; 0 routes, 0 migrations, 0 registers, 0 lane screens. Under `npm --prefix packages/fde-modernization test`: 709 tests, 709 pass, 0 fail, of which 21 are this domain’s. Mutation 18/18 after a measured 16/18 first pass, with no compile-error credit. NOT RUN and therefore not claimed: `npm run test:data:local`, which cannot run on the authoring machine.
Truth register
Process opportunity register2026-08-31

See Interface actionability assessment · See Outcome contracts

Status

Status, and what is not claimed.

The legend again, in full, for the reader who scrolled here first. Truth register status date: 2026-08-31.

The three status labels, what each means, and the truth-register labels each is drawn from.
LabelMeansDrawn from
BuiltImplemented and verified against a live database with retained positive and negative evidence — the refusal probes matter more than the happy path.Truth-register rows labelled VERIFIED or IMPLEMENTED
In buildSome of it exists and works; the target acceptance is incomplete. The entry says which half is which.Truth-register rows labelled PARTIAL
IntendedAccepted architecture, specified in writing, not implemented. No implementation claim of any kind.Truth-register rows labelled PLANNED or NOT STARTED

Intended — specified, not implemented.

These are accepted architecture with written specifications and no implementation claim:

  • Process modelling, transformation maturity assessment, target-state scenario comparison, and architecture decision records
  • Portfolio, work, and delivery continuity
  • General-purpose workflow timers, retries, workers, leases, effects, and compensation beyond the exact D048 exception
  • Workflow simulation and deployment plans
  • Enterprise server registries and model route decisions
  • Engineering change proposals and the natural-language engineering workbench — local preview only, with no provider dispatch
  • Pilot work packages, deployments, run evidence, and outcome reviews
  • Adoption measures bound to outcome definitions; capability transfer packages; skill transition paths; succession-risk surfacing
  • Operations, incidents, queues, observability, and the learning loop
  • Contextual collaboration
  • The governed terminal, the field CLI, and any action-executing command palette — the shipped palette is navigation-only and is listed above at its own status
  • Healthcare accelerators and PHI-aware handling profiles — an optional accelerator carrying no compliance claim of any kind

Not claimed anywhere, at any status.

Any hosted or production execution
No pilot runs and no production effect. D048 is one disposable-local, deploy-equivalent worker contract for an exact Proposal Drafter call with zero tools and zero effects; it has no hosted activation or retained live-provider call. D049 is preserved but inactive. No connector connects, no tool executes, and no client or production system is changed.
Any AI-generated content
The bounded D073/D048 path may produce one unreviewed proposed draft only after exact context release, but this candidate retains no live-provider receipt or generated artifact. Broader AI extraction, opportunity generation, graph drafting, and curriculum drafting remain absent. Nothing published on this public surface is model-generated.
Any fabricated figure
The platform never derives volumes, costs, savings, benchmarks, or ROI. Unknown stays unknown and displays as unknown.
Any compliance certification
We hold none, we claim none, and adjacency to a regulated estate is not a posture.
Any customer outcome
We publish no client names, no case studies, and no measured results.

How to read a change to this page.

Every entry is bound to a row in an internal capability truth register that governs what may be published. When a capability is promoted there, this page changes in the same commit; a status promotion requires the exact source revision and environment, the implemented scope with its explicit exclusions, the authorisation and data-policy behaviour, positive and negative acceptance evidence, and the marketing copy corrected to match. An agent self-report, a generated screen, a successful HTTP response, a local mock, or a passing exit code is insufficient on its own.

If you are evaluating this platform to license it, the two paragraphs above are the ones worth arguing with. Bring them to the briefing.

Request a briefing