27 outcome-based epics. Proposal; none is implemented by this document.
Prove one small customer-value experiment in E01-E05 using an existing product and its verified release and recovery facilities. Build only what this path needs. Later epics expand the demonstrated scope; they never postpone safety required by an earlier release. Dependencies govern order; numbers identify outcomes. Account proofs can run before second-product exposure. Build no service merely to complete an epic. All applicable quality, security, privacy and authority gates apply throughout; emphasis labels grant no exemptions. Commission targets progressively before dependent execution. Each epic ends with independently checked evidence; an unachieved outcome stays open, is replanned or is explicitly retired.
Pilot exposure gate. Pilot exposure requires pinned acceptance and runtime privilege checks; proportionate threat modelling, dependency/secret checks and a privacy-canary test; integration/build provenance; validated instrumentation; required alpha; customer-path probes; and a restoration drill independent of planner/provider. Assurance establishes applicability and recency of existing proof. If new account/data handling or migration lacks necessary proof, narrow the pilot or prove it before exposure.
Common success contract
Reliability. Declare the affected transition/fault matrix, forbidden effects and recovery limits. Rerun affected matrices on foundation changes and at the commissioned cadence. Use controlled tests or authorised bounded drills. Pass every named case with zero forbidden writes, false successes or lost accepted decisions. Unknown external results stay explicit. Test counts describe the tested boundary; they never prove external exactly-once or production availability.
Coverage. Trace required behaviours, critical journeys, abuse cases and named faults to independent executable evidence. All release-critical checks pass; missing evidence is inconclusive. Reproduce defects before and after repair, and add fresh independent scenarios. Line coverage is supporting information.
Modularity. One decision owner per fact; zero forbidden dependency edges. Test each changed boundary independently and demonstrate a representative internal change without consumer implementation edits. Keep abstractions only when real consumers justify them.
Performance. Before dependent execution, the owning domain fixes numerical targets, baseline, workload/population, environment, observation window, sample/stopping rule and Budget. Measure latency, throughput and resources separately. Meet the declared rule and customer guardrails; never lower an active failing target to obtain a pass.
Composability. Exercise the real affected composition, preserving IDs, authority, provenance, failure semantics and recovery. Use doubles for faults and real adapters for integration proof. Provider and product substitution must later pass the same applicable contracts.
Value. Link each epic to an evidenced customer or operator need. Independently verify results under its predeclared rule. Separate Run completion, customer availability and supported/rejected/inconclusive benefit. A rejected experiment may finish as learning; an epic promising benefit is achieved only when that benefit is demonstrated.
Branding. Shared contract factory-brand-v1. Where an epic adds or changes user-visible copy, surfaces or brand assets, follow the Factory brand. Completion evidence for affected surfaces includes a brand consistency check; accessibility checks (contrast, alt text, reduced motion, no colour-only meaning); a truth-state check that security, destructive, failure, blocker, privacy and spend states stay plain and that no copy claims more than its evidence; and any required assets with provenance. An internal-only epic records that there is no visible change and needs no new artwork. Branding never closes an epic, relaxes another gate or implies benefit.
Design and language · Review decisions. The structured outcome map is the source of this guideline.
E01 · Make one valuable pilot executable
A small evidenced customer problem has a safe, measurable path to resolution.
Depends on: No prior epic.
- Planning selects one existing product/problem using current customer evidence and records why it outranks at least one plausible alternative.
- Within existing delegation, Planning and Operations commission the pilot measurement, authority, spend, access, data, alert destination and recovery contracts. All required fields have values and accountable owners before dependent execution; only genuinely unavailable decisions need the human owner.
- Assurance pins acceptance, existing critical journeys and falsification checks; unsupported assumptions and unavailable permissions cannot become approved facts.
Proof: Pilot Slice, source evidence, calibrated contracts and independent readiness verdict.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E02 · Repair the pilot with trustworthy verification
The observed pilot problem has a reviewable repair and an independently verified published result.
Depends on: E01.
- The original customer scenario fails before and passes after repair; affected existing journeys pass. Independently exercise the real UI where applicable and retain redacted observations tied to the exact Candidate.
- Within the commissioned Budget, deny worker access to release credentials, authoritative acceptance, collectors and Verdicts. Applicable security/privacy checks pass; future hardening grants no exemption.
- Publish a real product check whose conclusion matches the pinned revision and independent Evidence. Inject timeout, duplicate publication, restart and corrupt Evidence: zero false passes or blind recreation; unresolved effects stay unknown.
- Prove command deduplication, atomic result/outbox persistence and crash recovery on this path. Projection replay issues zero external writes; fixtures and actual adapter observations remain separately identified.
Proof: Before/after customer reproduction, immutable Candidate, independent Verdict, publication Receipts and repeatable fault results.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E03 · Prove the pilot can be exposed and recovered safely
Operations can integrate the exact improvement and restore safe product behaviour before customer exposure.
Depends on: E02.
- Verify the prospective merge-queue revision; inject a concurrent branch change and reject its stale Verdict. Confirm actual integrated revision and artefact identity.
- Using verified existing release facilities, drill disablement or restoration while the planner/provider is unavailable; customer-path checks recover within the commissioned limit. No first exposure precedes the applicable proof.
- Prove relevant state compatibility, current recovery authority and data handling. Select a reversible low-risk pilot; any required unproven destructive migration blocks its release.
Proof: Integration race test, artefact provenance and observed independent recovery drill.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E04 · Make the pilot improvement available to customers
The small improvement is actually available through the intended customer channel.
Depends on: E03.
- Expose within product Authority and Policy, including alpha first if potentially unsafe; meet the commissioned health/customer-flow observation rule before promotion.
- Obtain a channel Receipt and independently use the released behaviour through the customer access path; upload or merge alone cannot close delivery.
- Release accurate user guidance with the behaviour and independently validate instrumentation, privacy and security gates before measured exposure.
Proof: Channel/build Receipts, customer-path probe, observation report and matching user guidance.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E05 · Know whether the pilot helped
The first real customer experiment yields an honest result and changes the next decision.
Depends on: E04.
- Complete the declared observation/sample rule and independently reconcile captured events to observed tasks; assess guardrails and affected segments.
- Record supported, rejected or inconclusive benefit under the predeclared rule, with causal or observational qualification; count only supported benefit as a value win.
- Planning records keep, revise, retire or further-test action using the result; delivery Runs remain terminal during follow-up observation.
Proof: Assessment, validated measurements and the evidence-linked next decision.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E06 · Let workers recover and cooperate without collisions
Concurrent delivery continues safely through worker loss and competing edits.
Depends on: E02.
- Crash each exercised multi-step boundary, duplicate outbox delivery and lose the workflow cursor: reconcile from durable facts without reviving terminal Runs or repeating confirmed Actions.
- Run competing workers on shared and independent scopes; stale epochs cause zero accepted results/effects, while unrelated valid workers proceed.
- Replacement atomically adopts unfinished work/Actions with stable intent and identity; hung owners are stopped or quarantined before exclusive reuse.
Proof: Seeded concurrency/fault runs, public-state reconciliation and resource ownership traces.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E07 · Keep authorised work moving through blockers
Recoverable outages no longer require avoidable operator intervention.
Depends on: E06.
- Inject provider outage, expired recoverable access, transient infrastructure failure and external waiting; permitted repair/replan routes complete without human unblocking.
- Exhaust Budget or remove authority: preserve an honest wait/Escalation with remedies tried, missing decision, owner and wake condition or deadline. Make zero unauthorised calls or automatic limit increases; overdue self-solvable work still follows permitted recovery.
- Cancel during an uncertain Action, restart the scheduler and resume another eligible Slice: reconciliation continues, new cancelled dispatch stays stopped, and useful work meets its queue budget.
Proof: Blocker matrix with interventions, costs, wake conditions and outstanding-Action reconciliation.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E08 · Keep assurance trustworthy when challenged
Fabricated success and changes to the verifier cannot authorise unsafe delivery.
Depends on: E02.
- Every required Capability in scope has a decision owner and independently executable checks. Deny Delivery mutations of authoritative scenarios, fixtures, collectors and Verdicts; fabricated or missing evidence never passes.
- Fresh independent scenarios expose seeded defects missed by the fixed suite; a second provider agreeing with the builder cannot override executable failure.
- Change one assurance mechanism through a separately pinned evaluator; preserve old/new evidence and reject an intentionally weakened variant.
- Track Capability disposition separately from health; absent checks mean Unknown. Fresh-scenario cadence and verification diversity follow commissioned risk rules. Normal product code and its regression test may change together; authoritative acceptance changes require separate independent assessment.
Proof: Adversarial assurance results and independently approved verifier-change experiment.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E09 · Recover a failed factory update without the factory
The factory can improve itself while an independent path preserves safe operation.
Depends on: E03, E06, E08, E10.
- Before enabling unattended self-update, prove backup restoration, current deletion obligations and factory-down recovery against a pinned baseline; enablement without these proofs is denied. Then ship one useful factory fix through ordinary Slice, Candidate, Verdict and release contracts.
- Interrupt a factory update and remove declared planner/provider/orchestration dependencies; independent recovery restores verified service within the commissioned limit. Also fail the recovery path: it enters a bounded safe wait and reaches its commissioned escalation destination.
- Before restored state can dispatch, reconcile Action records, current authority and deletion obligations. Reject stale snapshot authority; quarantine unresolved effects. Flap protection bounds recovery, and recovery/controller updates cannot share one rollout.
Proof: Factory-consumer delivery evidence and observed factory-down restoration drills.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E10 · Honour deletion throughout recovery and evidence
Data subjects are protected even when records, artefacts or backups are restored.
Depends on: E03, E08.
- For synthetic subjects, execute access/export/deletion within product Authority and Policy across live data, derived data, linkable references, evidence and backup handling.
- Restore an older backup: independently prove deletion obligations are reapplied before customer exposure and no deleted subject becomes accessible.
- Scan durable history and captured UI artefacts: zero seeded secrets/raw identifiers escape the allowed retention boundary; preserve non-identifying decision provenance.
Proof: Data inventory, subject-lifecycle checks, retention evidence and restore/deletion reconciliation.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E11 · Close security exposure through verified remediation
An observed security risk is removed from actual customer availability.
Depends on: E04, E08.
- Continuously check dependencies, secrets, code and relevant runtime attack paths at the commissioned cadence; detect a seeded exposure and begin the prioritised repair within its severity deadline.
- Prove the exploit or unsafe behaviour fails after repair while required customer journeys still pass; dependency/scanning success alone is insufficient.
- Verify the fixed build at the customer access path, rotate/restrict affected access if required by the scenario, and observe the declared post-release window.
Proof: Threat/abuse reproduction, independent repair Verdict and deployed remediation evidence.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E12 · Change product data without stranding customers
A state-bearing improvement survives mixed versions and interrupted migration.
Depends on: E03, E10.
- Exercise old/new readers and writers, migration interruption, retry and forward repair against a representative dataset; meet declared integrity and latency limits.
- Prove the selected rollback, disablement or forward-recovery path from each destructive boundary before crossing it; preserve deletion and Action obligations.
- Independently reconcile migrated records and critical journeys before/after exposure; zero unexplained losses or duplicates occur within the declared matrix.
Proof: Migration rehearsal, reconciled dataset checks and customer-path recovery evidence.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E13 · Restore customer service before diagnosing incidents
Product and factory incidents recover autonomously within authorised bounds.
Depends on: E04, E07, E09.
- Inject product failure during factory unavailability; independent Operations recovery restores customer journeys inside the product recovery objective.
- Exercise misleading health, failed rollback and regression during Retiring: bounded recovery restores safe required/replacement service without cancelling retirement or reviving harmful behaviour. Missing evidence remains Unknown.
- After restoration, create and verify the causal repair plus regression check; customer status/guidance follows confirmed facts and communications Policy.
Proof: Incident timelines, independent availability probes and completed corrective Slice.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E14 · Spend delivery capacity on the strongest evidenced need
Customer feedback and business priorities produce a better next delivered choice.
Depends on: E05, E07.
- Compare attributed support, usage, incident and business Signals; record affected segments, competing choices, dependency order and opportunity cost. Compare prior predictions with observed results to calibrate the next choice.
- Deliver the highest eligible bounded Slice selected under the declared priority rule and assess its Outcome; no backlog growth metric substitutes for customer benefit.
- Introduce contradictory fresh evidence and an urgent incident; rerank within delegation, preserve active acceptance, and keep WIP/capacity inside commissioned limits.
Proof: Priority decision, rejected alternatives and a complete subsequent delivery/Assessment packet.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E15 · Make a difficult customer journey easier and accessible
An evidenced UI obstacle is removed without sacrificing existing users needs.
Depends on: E05, E08.
- Reproduce customer friction or accessibility failure; commission the applicable accessibility standard and task-success, error/time and segment guardrails before redesign.
- Independently exercise complete journeys with relevant keyboard, assistive-technology and viewport/device cases; all required accessibility/behaviour checks pass.
- Expose safely and meet the declared task-success, error/time and segment-guardrail rules. A rejected design may finish as learning, but this improvement epic remains unachieved until its benefit is demonstrated.
Proof: Comparative live-task evidence, accessibility checks and post-exposure UX assessment.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E16 · Improve a real performance bottleneck
Customers complete an important task faster within resource and correctness limits.
Depends on: E05.
- Identify an observed bottleneck and commission realistic workload, environment and task-level latency/resource thresholds before optimisation.
- Meet the declared customer-performance target under representative load, with unchanged required behaviour and no guardrail breach.
- Independently compare before/after runs and customer observation. A gate test rejects a cost-only optimisation that breaches the customer-performance rule.
Proof: Reproducible benchmark, end-to-end traces and customer observation against the contract.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E17 · Substitute model providers without changing promises
Claude and OpenAI can perform the same authorised work with measured differences.
Depends on: E06, E08.
- Run both real adapters on the same representative tasks and independent acceptance contract; each meets declared quality, latency and cost limits for its assigned role.
- Inject a hung response, interruption and provider replacement mid-Run; bounded Attempts preserve IDs, completed work, Action ownership and Evidence, with zero repeated confirmed effects.
- Replace an adapter implementation without changing domain consumers; invalid output, unavailable models and unsupported capabilities fail explicitly.
Proof: Comparative real-provider task results, substitution drill and unchanged consumer contracts.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E18 · Deliver value in a second product without coupling the first
The working lifecycle is reused across two independently operated products.
Depends on: E05, E06, E08.
- Complete a second-product Slice through availability and Assessment using existing contracts. Required account/access proofs precede exposure: use proven product facilities or the applicable E19/E20 proofs, which may run earlier.
- Inject product-specific failure and cross-product credential/data requests; the first product remains within its service guardrails and all forbidden cross-boundary access is denied.
- Change one shared implementation and one product-specific behaviour with unchanged consumer contracts. Upgrade or roll back one Product Pack while the other product and its pinned active Slices remain within guardrails.
Proof: Second product delivery packet, isolation tests and demonstrated confined changes.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E19 · Keep customer accounts correct across products
Customers can acquire, change and leave each product without accidental identity or permission sharing.
Depends on: E05, E10.
- Exercise signup, authentication, account recovery, entitlement/access change, revocation, export and deletion for synthetic customers in each product. All specified journeys pass; cross-product/role negative cases permit zero unauthorised access.
- Reuse an account-lifecycle contract while preserving product-specific consent, identity stores and entitlements. Any intentional shared identity requires explicit authority and isolation/consent proof.
- An interrupted account operation or revoked entitlement preserves Action identity and current authority; reconcile its actual result and meet the commissioned account-journey reliability and latency rules.
Proof: Independent account journey, isolation, revocation and interruption results for both products.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E20 · Keep operating access available within authority
Vendor accounts and credentials support autonomous work without unsafe credential handling.
Depends on: E05, E07, E10.
- Exercise authorised vendor-account provisioning, scoped access, renewal and revocation using protected credential storage; planted secrets never enter worker output or Evidence.
- Inject expired recoverable access and provider failure; permitted recovery restores operation within its commissioned limit without human intervention. Unavailable authentication remains an honest Escalation after permitted remedies.
- Revocation blocks queued dispatch across affected products; unrelated authorised work continues. Product customer identities and vendor operating identities remain separately owned.
Proof: Access-lifecycle drill, redacted provider Receipts, secret-canary and revocation evidence.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E21 · Learn which truthful communication brings suitable customers
A permitted launch or acquisition experiment links accurate claims to measured customer behaviour.
Depends on: E04, E05.
- Publish one authorised website/docs/blog/launch experiment whose availability and benefit claims trace to confirmed evidence; simulated stale claims are rejected.
- Validate acquisition-to-activation and attribution under the declared population/window rule. Paid advertising requires delegated spend authority and the commissioned profitability/viability rule; privacy and budget limits hold.
- Record supported/rejected/inconclusive acquisition results and the next Planning decision; no advertisement runs without explicit budget authority.
Proof: Published communication Receipts, claim traceability and acquisition/activation assessment.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E22 · Keep useful delivery economically sustainable
Measured economics guide investment without degrading customer experience.
Depends on: E05, E14, E21.
- Reconcile factory/provider/infrastructure, acquisition and support costs to completed deliveries and observed customer outcomes; reconcile revenue where applicable without inventing lifetime value.
- Apply a predeclared viability/resource rule to continue, limit or redirect one activity; measure before/after spend and customer guardrails.
- Budget exhaustion causes safe replanning or an explicit unavailable-decision escalation; cost optimisation cannot pass by breaching experience/performance thresholds.
Proof: Reconciled unit-economics assessment and an observed bounded investment decision.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E23 · Adapt operating policy without acquiring new authority
The factory can improve decisions while active work and owner limits remain protected.
Depends on: E06, E08.
- Adopt one independently assessed operating-policy or measurement change within delegation, retaining versioned rationale and effective scope.
- Active Slices retain pinned acceptance; attempted retroactive weakening and undelegated authority expansion are denied, even with unanimous agent agreement.
- Revoke an existing permission during queued work; dispatch uses current revocation, while unrelated permitted work proceeds and historical outcomes remain reproducible.
Proof: Policy transition matrix, prospective application evidence and denied-expansion tests.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E24 · Turn nightly research into bounded useful learning
Research regularly produces evaluated decisions and safely adopted improvements when justified.
Depends on: E09, E23.
- Commission timezone, cadence, capacity and occurrence identity; restart across a boundary and coalesce missed windows into one current pass without duplicate effects.
- Compare a relevant proposal with a pinned baseline under a falsifiable contract; demonstrate one real accepted improvement and rejection of a seeded attractive regression.
- Promote through normal factory delivery gates; a no-change night is valid, source material grants no authority, and research cannot consume reserved incident/product capacity.
Proof: Scheduled occurrence traces, comparative experiments and a verified adopted factory improvement.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E25 · Simplify weekly without losing abilities
Recurring simplification removes proven complexity while preserving required behaviour.
Depends on: E09, E08.
- Commission weekly capacity/schedule, inventory consumers and dormant recovery paths, then remove one demonstrated duplication, stale flag or obsolete instruction through a bounded Slice.
- Independently meet the declared reduction in change effort, duplication or interface complexity while preserving required capability and recovery checks; removed file or line counts alone cannot pass.
- Inject lost capability and a faulty check separately: restore safe behaviour first; amend a wrong check only through independent review. Restarted schedules produce no duplicate logical cleanup.
Proof: Before/after capability and complexity evidence, restoration drill and weekly occurrence record.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E26 · Retire obsolete behaviour without abandoning customers
A low-value or harmful capability ends deliberately with verified migration and data handling.
Depends on: E05, E10, E12.
- Before retirement, Planning records evidence beyond low usage, consumers, authority, migration/replacement, notice, recovery window and closure criteria. Account-data retirement additionally requires the applicable E19 identity, export and deletion proof.
- Regress behaviour during Retiring: recovery restores safe required/replacement service without resetting disposition or reviving harmful/Retired behaviour.
- Meet migration/customer-protection and deletion criteria, independently approve the revised baseline, and remove the implementation after its recovery window; retain non-sensitive decision provenance.
Proof: Retirement decision, migration/cohort verification and tested health/disposition transitions.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
E27 · Sustain autonomous delivery across the portfolio
Two products, incidents and improvement schedules coexist without hidden starvation or runaway cost.
Depends on: E13, E15, E16, E17, E18, E19, E20, E22, E24, E25, E26.
- Commission and run a representative portfolio workload/window mixing delivery, waiting Actions, provider loss, account changes, incidents, retirement, nightly research and weekly defrag.
- Meet declared service, recovery, queue-age, fairness, throughput and Budget rules. Reconcile required Actions to the declared terminal or honest durable-wait state; terminal Runs stay terminal and forbidden cross-product effects remain zero.
- Independently reconcile operator intervention reasons and real delivery/Assessment evidence; claim only measured reliability for the observed workload/window and commission the next capacity change from those results.
Proof: Portfolio soak/fault report, reconciled evidence ledger and measured capacity decision.
Branding: factory-brand-v1 for any copy, surfaces or assets this epic changes.
