Execution lifecycle — always within explicit authority
VERIFY → AUTHORIZE → EXECUTE → TEST → PRESERVE EVIDENCE → REVIEW → CLOSE → STOP
One active bounded write cut. No automatic chaining. READY ≠ AUTHORIZED. Author checks ≠ independent acceptance. The exact canonical manual and Cut Contract follow.
EXECUTION GOVERNANCE + BUILD MANUAL v0.2 — APPROVED PLANNING BASELINE
EXECUTION GOVERNANCE + BUILD MANUAL v0.2 — APPROVED PLANNING BASELINE
Phase 0 · 3 October 2026 · Owner adoption: PASS WITH CONDITIONS · NOT ACTIVATED
Adoption authority: Owner Planning Disposition §§1/4/5. This governing planning manual is approved subject to its open dependencies and Owner gates. The original v1.2-RC candidate is preserved in its verified backup. No Governor/Execution Chat is appointed or activated, and no future cut is authorized. Historical candidate-authoring references below identify provenance, not current adoption status.
Sources: current Owner §11; Constitution IV–IX/XII–XVIII; Roadmap/Hierarchy v0.2 and five preceding candidate specifications. This is a documentary operating contract, not an authorization service, appointed Governor, production permission or activated execution system.
Governing procedure
Governing procedure
VERIFY → AUTHORIZE → EXECUTE → TEST → PRESERVE EVIDENCE → REVIEW → CLOSE → STOP.
- VERIFY: read current Owner/source indexes/full relevant governing clauses, current state/ledger, roadmap/Child/profile and exact artifact versions; inspect actual state/hashes and whether an incomplete prior write may already have applied. Reject stale chat, starter code or derivative state as authority.
- AUTHORIZE: record actual issuer/delegation, unit/cut/version, class, scope, data/environment, conditions, cost and current validity. Verify evidence dependencies/appointments/no STOP. Missing conditions block work; READY alone grants nothing.
- EXECUTE: perform only the bounded cut. Normally one active state-changing cut; parallel writes require explicit collision/dependency/shared-state disposition. No implied subdelegation.
- TEST: instantiate proportional success and failure procedures from the Child contract and affected specs; preserve methodology, actual results, samples/limits. Never invent executed tests or relax mandatory criteria after failure.
- PRESERVE EVIDENCE: requirement→procedure→observation mapping, attributable source/version/ID/environment/time, safe logs/diffs/requests/screens/hashes and reproducibility where practical. Exclude secrets/private payload dumps.
- REVIEW: route to designated actual appointed function. Independent review must be sufficiently separate and capable of rejection; author self-check is not independent assurance. Owner-reserved approval cannot be substituted by a technical PASS.
- CLOSE: only explicit applicable acceptance, required mandatory evidence, disclosed bounded gaps, appropriately authorized cleanup and coherent durable records qualify. Until then REVIEW_PENDING, not CLOSED.
- STOP: completed cut authority is consumed unless explicit separate permission remains; do not start another cut because it is listed or technically possible.
Roles, permission classes and records
Roles, permission classes and records
Owner: material business/architecture/scope/legal/rights/spend/security/irreversible/first-launch/major-phase authority. Governor: interpret/review/prepare/progression decisions only within explicit appointment/delegation. Executor: bounded implementation/analysis/testing/evidence, not independent acceptance by default. No role holder is appointed here; missing role routes to Owner.
Permission classes are separate: documentary authoring; read-only research/review; isolated validation; implementation; spend/procurement/resource creation; production operation/publication; destructive cleanup/migration. Permission for one never supplies another. Routine reversible work under a valid existing contract need not interrupt Owner repeatedly.
Proposed durable authorization record (manual/documentary, no runtime mechanism selected): reference/issuer/date; role/delegation; identified cut/version; class/scope/exclusions; data/environment/resources; conditions/cost ceiling; validity/expiration; revocation/supersession/current status. Ledger stores record/evidence pointers, not credentials.
Authorization may expire, be consumed, revoked or invalidated by material state/scope/architecture/risk/cost/environment/authority changes. Review validity immediately before use; no cached historical permission. No retrospective authorization. Material rework/resumption after STOP requires appropriate renewed authority, not automatic restart.
Mandatory Execution Cut contract
Mandatory Execution Cut contract
Every future cut must instantiate every field; inherited Child definitions are not a blank check. Exact technology/file/command/resource details remain PENDING DEFINITION until their prerequisite decisions are evidenced.
| Field | Required content |
|---|---|
| CUT ID | Unique bounded cut/version and durable authorization/evidence reference |
| PHASE / PARENT / CHILD | Exact approved ownership references and current lifecycle state |
| VERIFIED STARTING STATE | Actual source/spec versions, files/resources/state/evidence and interrupted-operation checks |
| OBJECTIVE | Coherent observable outcome, not an indefinite backlog |
| AUTHORIZED SCOPE | Exact work and action classes permitted by actual authority |
| PROHIBITED SCOPE | Ratified exclusions, data/resource/cost/production restrictions and Child-specific non-scope |
| DEPENDENCIES | Closed/accepted applicable unit evidence and exact G-symbol approval records |
| PRECONDITIONS | Permissions/roles/data/environment/tool capabilities and actual constraints satisfied |
| AFFECTED AREAS | Named files/components/resources and collision boundaries, not “all backend” |
| ACCEPTANCE CRITERIA | Child-specific observable requirements, mandatory/conditional distinction |
| TEST PLAN | Concrete proportional commands/procedures, expected results/profile/sample and limitations |
| FAILURE TESTS | Child/profile cases including rejection, outage, ambiguity, replay, restart or rights withdrawal as affected |
| EVIDENCE REQUIRED | Safe requirement-result map, observed logs/requests/builds/screens/data verification and hashes |
| STOP CONDITIONS | Missing authority/evidence, source conflict, material risk/cost change, unsafe operation, bounded troubleshooting exhaustion |
| ROLLBACK / RECOVERY | Rights-valid release/code plan, persistent/external-state effects and required separate destructive/replay authority |
| AUTHORIZER | Actual Owner or specifically delegated decision function with verifiable scope |
| PERMISSION CLASS | Separate classes explicitly covered; no implied spend/production/destruction |
| ENVIRONMENT | Exact project/resource boundary, credentials/data class, test destination and geographic restrictions |
| COST BOUNDARY | Approved actual ceiling/conditions and expected recurring/attempt costs; no assumed free allowance |
| DEFINITION OF DONE | Full scope and mandatory tests/evidence, reviewed gaps/cleanup, coherent state; author handoff normally REVIEW_PENDING |
| REVIEWER | Actually appointed designated function; independent where required; Owner-reserved ratifier explicit |
| NEXT PERMITTED STATE | Explicit pending review/blocked/deferred/closure disposition; STOP, no automatic next operation |
Current Phase 0 autonomous window
Current Phase 0 autonomous window
The latest explicit Owner grants Replit a conditional Phase 0 autonomous window. Use 21_PHASE_0_AUTONOMOUS_WINDOW.md for the current H1 resumption preflight contract. Continue only one valid, dependency-eligible, evidenced cut at a time; routine covered continuations require no repeated Owner approval. Mandatory Cut fields, acceptance, failure tests, cost boundary, review/closure and Owner gates remain unchanged. Direct Replit authorization does not activate any standing AI role. Current H1 preflight is BLOCKED on actual North America/Autoscale configuration and cost proof; do not publish documentation/starter as H1. Phase 1/product/Architecture freeze remain separate Owner gates.
HISTORICAL — prior Master Edition documentary cut
HISTORICAL — prior Master Edition documentary cut
Current reporting cut: PHASE 0 / PH0.PLAN / BOOK.RATIFY.ONBOARD.2026-10-03. Master Edition v1.0 is RATIFIED — CANONICAL CONSOLIDATED PROJECT SOURCE OF TRUTH; onboarding PREPARED ONLY. The final Owner ratification remains valid; latest Owner consistency correction permits documentary repair/reissue only. Preserve the exact 395-page archive, substantive contracts and all prior evidence. Governor, Execution and Review remain NOT ACTIVATED. No technical execution, formal Parent/Child closure, publication or new authority. Next permitted activity: Owner transfer → reconstruction → three role calibrations → Owner review of actual results → explicit appointment/activation. STOP.
HISTORICAL — SUPERSEDED EDITION-PREPARATION STATUS: S09 held earlier S08 issuance for edition review; BOOK.MASTER.EDITION.2026-10-03 was REVIEW_PENDING. That was the pre-ratification cut only, not current state. Final ratification superseded that hold. Neither an author's check nor roadmap presence supplies execution authority.
Historical Official Book documentary cut
Historical Official Book documentary cut
| Contract field | Current value |
|---|---|
| CUT ID / location | BOOK.AUTHOR.2026-10-03 / PH0 / PH0.PLAN; associated historical PH0.PLAN.C01, no new Child |
| Verified starting state | Owner reports Governor-assisted review; adopts eight v1.2-RC planning outputs PASS WITH CONDITIONS; immutable C/T/A and three backups verified; H1 BLOCKED |
| Objective / scope | Record adoption; author complete canonical consolidated official Book v1.0-RC, HTML/Markdown/local preview/print/PDF/mirrors/revision/freshness/manifest/backup/report |
| Prohibited | Product, H1/H2–H11 execution, dependencies/providers/resources/spend/production/publication, freeze, final proposed brand/content/rights approval, standing AI appointment/activation, Phase 1 |
| Dependencies / preconditions | Current S07 §§1–16; no unresolved governing conflict; preserve exact original sources and prior evidence/backups; only existing local tooling for PDF |
| Affected areas | Documentary sources/Book/scripts/editions, existing preview landing, evidence/master-book/deliverables/replit boundary records; no public product |
| Acceptance / test / failure | Full requested hierarchy/sections/source notes/complete sources and contracts; 6/12/46; open facts explicit; search/nav/mobile/print/PDF; BOOK_STALE on material mismatch; nonzero failure, no false authorization |
| Evidence / risks | Pre-cut documentary hashes, source map/current source and output hashes, actual audit/visual/PDF checks, manifests; author checks not independent acceptance |
| STOP / recovery | Material contradiction or unsafe export scope → STOP affected work. Preserve sources/history/prior backups; regenerate editions only under current authority. Return → STOP |
| Authorizer / class | Explicit Owner Planning Disposition §§6–16 / bounded documentary authoring only |
| Environment / cost | Current repository/existing local preview and already available local Chromium; no new material dependency/external paid service or resource |
| DoD / reviewer / next state | Deliver verified Book editions/state/history/integrity/new backup/report; REVIEW_PENDING; permission consumed on delivery; STOP for Owner + Governor review, no closure/activation inferred |
Historical master planning documentary cut
Historical master planning documentary cut
| Contract field | Current value |
|---|---|
| CUT ID / ownership | PLAN.COMPLETE.2026-10-03 / PH0 / PH0.PLAN / PH0.PLAN.C01; new reporting references |
| Verified starting state | Owner accepts v1.1-RC documentary baseline; three governing texts restored/hash verified; preserved backups/H1; architecture candidate/not frozen; H1 BLOCKED |
| Objective/scope | Author five v0.1 candidate specs in order, then Roadmap/Units/Manual v0.2; queue, Brain/static Control Room/handoff/evidence/report/new backup |
| Prohibited | H1 resumption/H2–H11; public product/dependencies/providers/resources/spend/publication/infrastructure; freeze/self-ratification/Phase 1/implementation |
| Dependencies/preconditions | Full current Owner instruction; governing source clauses; accepted baseline integrity; no source conflict; existing local documentary environment |
| Affected areas | docs/project-brain, documentary scripts, project-brain/identical existing preview mirror, master-planning evidence/deliverables and collaborator boundary notes |
| Acceptance | All specified topics and complete inherited Child/cut contracts, four status axes, acyclic traceable dependencies, truthful decisions/content/vendor/risk/authority; reconstructible candidate package |
| Test/failure plan | Source/baseline/archive hashes; field/ID/reference/count/state/dependency audits; no unsupported selected vendors/ACTIVE units; portable static links/JS/mirrors/local desktop/mobile; preserve inputs on conflict |
| Evidence | Current Owner/source hashes, pre-change baseline, candidate clause map, actual author audits/local screenshots, change/package manifests and ZIP checksum |
| Failure/STOP | Material conflict or unsafe scope → affected STOP; actual unresolved choice stays open; missing review → REVIEW_PENDING; return → STOP |
| Recovery | Preserve exact sources/accepted v1.1-RC and earlier backup/evidence; regenerate only derivatives; no destructive resources |
| Authorizer/class | Current explicit Owner Master Planning Completion instruction / single documentary planning program only |
| Environment/cost | Current repository/local static preview; no new paid commitment/provider resource/product installation; no claim ordinary platform use is free |
| DoD | Complete candidate package, documented unresolved decisions/limits, actual author verification and new integrity backup returned |
| Reviewer/next state | Owner + separately appointed independent Governor; REVIEW_PENDING, no appointment/closure/activation; authority consumed on delivery |
States, review outcomes and closure
States, review outcomes and closure
Constitutional states: DRAFT → REVIEW → READY → AUTHORIZED → ACTIVE → REVIEW_PENDING → CLOSED, with BLOCKED/DEFERRED/CANCELLED dispositions. Actual state and permission record must agree. Readiness filters—READY IN PRINCIPLE, DEPENDENCY UNSATISFIED, OWNER DECISION REQUIRED, VALIDATION REQUIRED—are classifications, not additional unit states.
Review outcomes: PASS / PASS WITH GAPS / FAIL / BLOCKED / DEFERRED. Each non-critical gap needs risk/owner/disposition/follow-up; no failed mandatory criterion can hide behind PASS WITH GAPS. H1 PASS WITH ADJUSTMENT separately retains Technical Direction mandatory checks, user-impact/cost assessment, actual approved adjustment and confirming evidence.
Closure requires completed required work/tests, reviewed evidence, explicit designated acceptance, applicable Owner approval, bounded gaps and authorized temporary-resource cleanup. An accepted working recovery baseline is not independent closure of every prior cut or ratification of candidate artifacts. Conditional N/A/deferral is justified and recorded, not an invented PASS.
Next-eligible preparation — documentary algorithm, not running automation
Next-eligible preparation — documentary algorithm, not running automation
For each candidate Child:
- Resolve exact source/spec/Child/profile versions and proposed Phase/Parent ownership.
- Check each dependency: required accepted closure/evidence; conditional explicit N/A/deferral with no hidden mandatory waiver; external G-symbol actual record.
- Check all applicable authority: appointment/delegation, permission class, scope, data/environment/cost, validity, Owner-reserved conditions.
- Check no STOP, unresolved material conflict, unsafe parallel state change or unmet actual precondition.
- If all required conditions are true, the appointed Governor may prepare a narrow cut and evidence/test checklist within delegated preparation authority. Label proposal/prepared; record readiness.
- A prepared proposal does not self-grant Owner permission. Execution may start only under valid explicit cut authority covering actual work; record AUTHORIZED before ACTIVE.
- After work, REVIEW_PENDING and STOP; closure is separately reviewed. Verify fresh eligibility/authority for any later unit.
The present Control Room can filter documentary classifications only. It does not calculate authoritative readiness from live resources, appoint roles, authorize cuts, trigger agents or execute this algorithm. READY IN PRINCIPLE is not an execution button.
STOP, blockers, troubleshooting and discovered work
STOP, blockers, troubleshooting and discovered work
Valid Owner/authorized Governor STOP overrides affected permission immediately. Cease new state changes, reach only the minimum safe atomic boundary, preserve minimal evidence, report done/in-progress/not-started and record directed valid state. No broader completion or new operation under the safe-boundary exception.
Typically stop after at most three materially distinct evidence-producing troubleshooting approaches unless a valid cut specifies another justified bound. Unchanged retries are not new hypotheses; investigate whether writes already applied. At bound: preserve attempts/evidence, current hypothesis and safe disposition, await authorization.
Necessary discovered work within current scope may be documented; material expansion needs explicit approved change first. Unnecessary work remains future candidate, not implemented. Missing provider/account/rights/cost/reviewer/evidence is a legitimate blocker, never justification for silent fallback.
Change control and Owner interruptions
Change control and Owner interruptions
Routine reversible choices within valid contracts use appropriate delegated authority. Escalate only material scope/architecture/business/legal/rights/cost/geography/privilege/irreversible/risk/major-phase matters or information genuinely requiring Owner. Queue grouped blocking decisions in OWNER_DECISION_QUEUE; do not ask again about settled directions.
Record proposal, evidence, alternatives, impact, affected artifacts, risks/cost and required approval before material change. Reconcile affected documents before implementation; do not relax criteria after failure. Planned framework/provider details cannot replace pending gate evidence.
Production/destructive/migration gates require explicit actual Owner authority and consequences/recovery evidence; code rollback cannot promise to undo persistent or third-party effects. No such permission exists here.
Evidence, continuity and dual-chat handoff
Evidence, continuity and dual-chat handoff
After interruption: 06 state → 05 ledger → current original Owner instruction → 14 sources/hashes → exact Child/profile/roadmap/spec/cut. Check consumed/revoked/expired authority and partial writes before resumption. Preserve immutable history, accepted backups and evidence; no secrets in packages/chats.
Future Governor Chat may interpret/review/prepare/control progression only after explicit independent function appointment/delegation. Future Execution Control Room Chat receives one actual authorized cut at a time, executes/tests/preserves/reports and stops. Same authoring context cannot claim independent review without a specifically separate legitimate review function. Neither chat is created/appointed/activated by this manual.
Current next action: return candidate package; Owner + independent Governor review; STOP.