Factory docs, home
Page navigation

No study yet: this module has no plate position.

What it does for you: It keeps one durable record per Product that decides what delivery work may start. It binds the Product once to a store the Factory owns, and holds grants (which operations, which paths, how many runs, how long), their revocations, a stop switch and the one current owner. A Slice is frozen with its own allowance. Every production, check and branch move must then be admitted: under a live grant that, like the Slice, allows it, with no stop, by the current owner, before the Slice's deadline and within its allowance. At most one production and one check or branch move are in flight per Product at a time, and a branch move whose result is unknown blocks every later move until it is confirmed. A move is admitted only after its Verified proof is worked out again, inside the decision, from the stored Evidence, and only if the Candidate changes nothing outside the Slice's frozen paths. The delivery records beside it keep the frozen Slice, the store binding, the proof and each move's intent and receipt, each written once. They work out the Slice's measured outcome when asked, without storing a conclusion.

How it links: It takes Verdicts and their re-derivation from Repository Assurance, owner fences from the Attempt fence and store identities from Repository, and it records everything in the Command journal. It gives nothing to the rest of the Factory yet: the delivery flow that will call it is not built.

Honest limits:

  • Nothing calls it yet. It admits and records; it runs no Git, program or model itself, and no Slice has been delivered through it.
  • The journal and Git are never one transaction: a revocation that lands after a move was admitted cannot stop that move, and the record shows the admitted effect. An unknown move is never settled by guessing. There is no rebind and no operator override.
  • Ownership passes only on proof that the previous owner was fenced off or let go, never by time, so a live but stuck owner blocks its successor. The gate cannot see the fence itself: it relies on the caller's fence check. Proof is re-derivation over trusted local files, not cryptography: anyone who can write the journal or the Evidence store can forge.
  • Gate state is never compacted: at 768 KiB new work is refused, while settling what was already admitted still fits.

Status: Accepted as step 1, increment 2, reviewed together with increment 1 (Repository Assurance): independent code review (Astra high) passed on 29 September 2026 in round 6, after rounds 1–5 each found something to fix (build review). Not composed into a delivery. This is local development only, not a release, a Verdict or a customer benefit, and all 27 epics remain open.

Agent reference →

Source: docs/guide/product-gate.md