Exact Git-tracked sourcedocs/LIFECYCLE_AND_HIL.md View exact source

Lifecycle, Delta flow, and human gates

Evidence Lane separates entry classification, bounded work, continuing-work refresh, full-PV proposals, authority-owned human decisions, pointer movement, State Travel, and Goal completion.

Current counts are derived release facts, not permanent ceilings.

Turn and Delta flow

Prompt or steer
    -> Entry Slip
    -> Source Intake / project recipe / Mode
    -> typed action and owning authority
    -> ENV selection
    -> UOP operators, formulas and gates
    -> condition-true tools and transport
    -> validate result and authority effects
    -> adaptive Delta-exit append for continuing work

Entry Slip is emitted for every prompt or steer. Adaptive Delta-exit append is not an Exit Slip. Exit Slip is emitted only when State Travel completes or the Goal is explicitly completed through option 2.

Project and Learning HIL

Build and full-PV Refresh can seal an immutable unaccepted proposal. Project HIL and Learning HIL are separate pending decisions. Plan acceptance, natural language, tests, Git, CI, packaging, installation, restart, deployment, or a website preview cannot satisfy either gate.

Exact Fuse may move the accepted Project pointer only after the current Project decision contract passes. Learning acceptance moves only its separate Learning pointer. Ordinary Delta refresh never creates or promotes Project Overlay.

Canon Input HIL

Canon input is receiver-owned and uses the exact current contract for ACCEPT, REJECT, or MORE_RESEARCH. It admits or rejects bounded task input only; it cannot decide Project HIL, Learning HIL, Goal completion, or pointer movement.

Rollback

Logical rollback moves an accepted pointer among immutable accepted PVs under its exact gate. Hard ZIP restore is a separate explicit recovery operation.

State Travel

State Travel resumes exact unfinished work in a fresh task after task, workspace/worktree, dirty-byte, source, runtime, Plan/Goal, accepted-pointer, and continuity bindings pass. It does not restart the app, reconstruct the Plan from chat, replay HIL, or infer identity from a title, CWD, PID, or successful test.

Goal completion

Goal completion is human-owned and independent of every HIL. Only the explicit Goal completion path can close it. Completion authorizes no Project acceptance, pointer movement, Git action, installation, merge, or deployment.

Source-bound workflow map

This page is projected from the same current executable snapshot as the rest of the documentation set. The map is deliberately two-directional: each horizontal district shows peer stages while vertical edges show ownership and state progression.

flowchart TB
    subgraph InputDistrict["Input and classification"]
      direction LR
      A["Prompt, steer, or carried task"] --> B["Entry Slip and Delta entry"] --> C["Active Plan row"]
    end
    subgraph ExecutionDistrict["Selection and execution"]
      direction TB
      D["Bounded execution and refresh"] --> E["Candidate or continuing work"] --> F["Authority-owned validation"]
    end
    subgraph EvidenceDistrict["Evidence and outcome"]
      direction LR
      G["Delta, HIL, or Exit receipt"] --> H["Fuse, rollback, State Travel, or Goal"]
      G -. mismatch .-> I["Never infer approval from execution"]
    end
    C --> D
    F --> G

Contract and readback

Phase Current contract Required readback
Input Prompt, steer, or carried task Exact identity, provenance, and scope
Classification Entry Slip and Delta entry Owning schema, action, lane, skill, or authority
Owner Active Plan row One canonical implementation owner
Route Bounded execution and refresh Condition-true ordered route with no hidden alias
Execution Candidate or continuing work Real execution or a visible fail-closed result
Validation Authority-owned validation Hash, schema, authority-effect, and negative-case checks
Receipt Delta, HIL, or Exit receipt Content-addressed result and provenance receipt
Downstream Fuse, rollback, State Travel, or Goal Only the explicitly eligible next state
Failure Never infer approval from execution No inferred HIL, candidate acceptance, or pointer movement

Canonical source owners

Exact backend readback

Source contract Bytes SHA-256
schemas/lifecycle/runtime-workflow-registry.v1.json 14195 7088B8A9D890E515A7A4EC56C97C1914F196F4DB774D4850356F9575A4159C19
skills/evidence-lane-code-lifecycle/SKILL.md 41631 A4AA856D1FE094F7DF17FF65492F77CB0F5095F0CB40E8C9E186068B1DE102FA
schemas/fuse/dual-hil-fuse.v1.json 717 D5219CD384AC2CD94046F2303A261934DACA3CFFDB4599653933278737896DFF

Cross-surface invariants


This page is a Git-tracked documentation projection. Executable source, SQLite authorities, installed-runtime receipts, and explicit human gates remain the governing evidence.