Factory docs, home
Page navigation

What it does for you: It checks a built-in fixture while exactly one owner holds the Attempt, and stores a report before settling anything. If a controller dies partway through, the next verify or recover settles that Attempt from its report, or proves the old work cannot resume. Only verify then starts a replacement, within the Run's Budget.

Module studies, plate 1: six Plumb studies for the records-and-runs modules, each labelled with its module's name.

Plate 1, position 6, Plumb double-checks: a round loupe over a folded blank report. The plate is shown whole; its other five positions are the records-and-runs modules it works with.

How it links: Takes ownership from Execution, fences and workspaces from Attempt fence / workspace, fixture runs from the Local fixture worker and Verdicts from Evidence / Assurance · Gives settled Attempts back to Execution and writes its records to the Command journal.

Honest limits:

  • It covers only the fixed built-in fixtures, tested on one macOS host with Node 26.8.1. It is not a sandbox for arbitrary code, its state directory is trusted rather than defended, and power loss is untested.
  • A closed fence proves that the old work cannot resume, not that its process exited. Without proof, the Run stays unresolved. Nothing recovers in the background: it happens only when someone runs verify, recover or cancel.

Status: Accepted for trusted fixtures (local review, 28 September 2026). This is local test-fixture infrastructure, not a pilot or a release, and all 27 epics remain open.

Agent reference →

Source: docs/guide/guarded-verification.md