Factory docs, home
Page navigation

Reference document, shown as written except that local paths appear as placeholders. Where it describes the Factory as intended, read it as design, not current state: only local infrastructure is accepted, no release, customer value or scheduled automation is established, and all 27 customer-value epics remain open. Current state: Factory model.

Proposed design, Astra-reviewed; of its modules only the schedule and the collector are built (increments 1 and 2, each independently reviewed). Reproduced from <local evidence archive> (Astra round 3 PASS); only its two archive paths are made absolute, and its one anchor into src/intelligence.ts follows the line it cites (695 in the spec, 709 since increment 1 and main's step 1 increment 3 each added one declaration above it). Increment 0 (§9) declares the planned modules in the Intelligence registry and builds none of them; its three Astra tasks are declared blocked until increment 7, since no effort is yet established on codex exec (why). Increment 1 builds the Lifecycle schedule on fixtures with a fake clock and passed independent review (Astra round 4 PASS); nothing runs on a schedule. Increment 2 builds the collector, Discovery sources, tested only against a loopback corpus; it passed independent review (Astra round 5 PASS); its own proposed bounds are listed in that reference. The owner decisions in §11 stay open: where increment 0, 1 or 2 uses a default, it is a proposal, not a signed commission.

Status: proposal for owner decision, 29 September 2026, Claude (Opus 5.5), at main e62abe6. Base: token-economy, with grafts from evidence-first and owner-minimal (<local evidence archive>). Nothing is built or scheduled; all 27 epics stay open. Assumptions [An] are listed in §12. Revised after Astra r1 and r2; Astra r3 PASS (<local evidence archive>).

1. Principles

  1. Code decides what code can: fetching, dedup, provenance, scoring, rules, statistics, schedules, budgets. Model output is data until a named check accepts it.
  2. Models only make admission harder: they triage, draft or challenge; never admit, select, publish or expose.
  3. Deltas only: a model sees content with a new hash; results are cached by (content hash, policy digest); a no-change day makes no call.
  4. Research is not a customer interview (docs/design.md:9): web-only Evidence admits a validation Slice, never a feature Slice.
  5. Unknown is never zero; a Budget is never extended.
  6. One short owner queue: ≤ 5 items a week, four classes (§6); silence is never consent.
  7. Subscriptions only: Claude sign-in via claude, ChatGPT sign-in via codex, on this Mac.

2. Modules

Domains: Pl Planning, Gr Growth, Op Operations. Gates read complete / valuable.

ModulePurposeGateIntelligence (tier: reason)Trigger
lifecycle-schedule (Op)Occurrence identity, capacity ledger, deferralone terminal record per due occurrence across restarts / output used downstreamnone: rules over clock and counters; a model makes runs unrepeatableLaunchAgent
discovery-sources (Pl)Fetch commissioned Sources into Captures, Citations, coverageevery Source has a status / Captures cited by admits; 8 weeks at zero proposes removalnone: hashing, dedup and quote checks are exact byte operationseach occurrence
signal-intake (Pl)Triage new Captures into Signals and Clusters; weekly search; weekly auditeach new Capture triaged or untriaged / audit agreement ≥ 80%optional: efficient triage and search (bulk classification); frontier Astra audit (independent measure of the efficient tier)daily, weekly
opportunity-synthesis (Pl)Clusters over threshold → ≤ 5 Opportunitieswatermark advances, proposals validate / admitted, then Supported (E14)optional: frontier Opus 5.5 high; composing falsifiable needs changes a decisionweekly, only if a Cluster crosses
planning (Pl; new file planning/opportunity-gate.ts)Admit, park or reject; challenge the marginal band; rankone disposition per Opportunity naming its rule, challenge or answer / calibration (§6)optional: frontier Astra challenge, other provider, may only lowerweekly after synthesis
owner-decisions (Pl)Weekly Escalation bundle, typed answers, single-use Action grantscommand-ID replay, stale answers refused / answered versus parkednone: recommendations render from verified recordsMonday 07:00
growth (Gr)Draft release notes, changelog, site, launch, deprecation copy with a claim tracea pack and stale-claim sweep per release / kept versus discardedoptional: efficient Sonnet 5 low; prose is where a model helps, code renders every claim from typed facts and Astra reviews the proseVerified plus integrated
outcome-validation (Pl)Measurement contracts, A/B designs, read-outs, Assessmentsan Assessment per released Slice once its window closes (a scheduled read-out is pending, not complete) / Supported onlynone: statistics over frozen contracts; a model would be a correlated second judgewindow close
capability-retirement (Pl)Inventory dormant or harmful Capabilities; draft the E26 caseall inventoried / no customer regression, Capability preserved (E25)optional: frontier Opus 5.5 high, ≤ 2 cases per Product a month; weighs consumers and migrationweekly defrag

No new module for docs (same Slice, docs/design.md:101), verification (Assurance) or cleanup (planning/propose-improvement, fed the retirement inventory).

3. The loop

Portfolio: Product, Objectives, Capabilities, owner-confirmed brief
  -> lifecycle-schedule: daily basic | weekly full occurrence
    -> discovery-sources: Captures, Citations, coverage              [no model]
      -> signal-intake: Signals, Clusters                            [efficient; Astra audit]
        -> opportunity-synthesis (only if a Cluster crosses)         [frontier]
          -> opportunity gate: rules -> challenge (only lowers) -> owner (4 classes)
            -> backlog -> Planning selects into a Slice (freezeSlice + contract + docs scope)
              -> product gate -> Candidate (code + docs) -> Assurance Verdict -> integrate-local
                -> growth: draft pack + claim trace -> owner gate (Action grant) -> owner-sourced Receipt
                -> outcome-validation: frozen contract -> window -> Assessment
                  -> outcome Signal + calibration -> next synthesis and gate thresholds
capability-retirement (weekly) -> same gate -> Planning or owner -> staged removal Slices

A Capture in a delivered Opportunity's Cluster is recurrence after change, not a duplicate.

4. Interface sketch (type names only)

  • lifecycle-schedule: Rhythm, OccurrenceId, Occurrence, OccurrenceStatus (completed | partial | deferred | unavailable), DeferralReason (usage-limit | budget-exhausted | sign-in-needed | volume-unmounted | logged-out), ScheduleCommission, CapacityLedger, LedgerEntry, UsageLimitObservation.
  • discovery-sources: ResearchBrief, Source, SourceStatus, Capture, CaptureNovelty (new | changed | repeat | unchanged), Citation (Evidence kind sf-citation/1), CoverageRecord.
  • signal-intake: Signal, SignalKind (problem | request | competitor-move | praise | noise | outcome), SourceClass (customer-voice | competitor | press | first-party), ProblemKey, Cluster, QuoteSpan, TriageRequest, TriageResult, SearchProposal, AuditSample, AuditResult.
  • opportunity-synthesis: ClusterScore, Watermark, PriorDigest, SynthesisDelta, Opportunity, OpportunityAmendment.
  • planning/opportunity-gate: GatePolicy, GateRuleId, Disposition (admitted | admitted-validation-only | parked | rejected | owner-routed), OpportunityDecision, ChallengeFinding, CalibrationRecord.
  • owner-decisions: EscalationBundle, OwnerItem, OwnerItemClass, OwnerAnswer, ActionGrant, OwnerSourcedReceipt.
  • growth: ReleaseFact, DraftPack, DraftBlock, ClaimTrace, StaleClaim.
  • outcome-validation: MeasurementContract, ExperimentDesign, PowerCalculation, SampleRatioCheck, Readout, and a new outcome-evidence evaluator binding release and exposure identity, the frozen contract and independently checked observations. deriveAssessment (src/delivery-records.ts:340) judges only local acceptance (declared values or check results) and is not customer benefit.
  • capability-retirement: CapabilityInventory, RetirementCandidate, RetirementCase, RetirementStage.
  • Reviewed edits: src/intelligence.ts: Transport gains "codex-cli"; Allowance gains "discovery-window"; ClaudeResearchProfile; Sonnet 5 qualified in MODEL_TIERS. src/claude-producer.ts: the transport and commission accept only CLAUDE_MODEL (:358, :1865), so extending them to Sonnet 5 is a reviewed edit with wrong-model refusal tests.
  • Tasks: signal-intake/triage, /search, /audit; opportunity-synthesis/propose; planning/challenge-opportunity; growth/draft-pack, /review-pack; capability-retirement/draft-case.
  • Reused unchanged: SliceNeed, freezeSlice (src/product-gate.ts:531), Observation, Verdict, Attention's owner-blocker rule (src/attention.ts:179-181).

Records live in <local discovery journal> [A9]; <local Portfolio journal> only gains coverage and usage Observations through a collector.

5. Discovery schedule

Local time [A8]; the owner's sessions share the usage window [A6], so runs stagger 20 minutes per Product within 02:00–05:00.

RhythmWhenWorkModel, subscriptionBounds per Product
Daily basicnightlyConditional GET of fast Sources (issues, forums, reviews, changelogs); triage of new and changed Captures onlysignal-intake/triage: claude-sonnet-5 low, Claude sign-in, tool-free [A3]≤ 40 requests, ≤ 8 MiB fetched, 0–3 calls of ≤ 20 Captures, ≤ 90 KB in, 10-minute deadline
Weekly fullThu–Sat, two Products a night, replacing the basicEvery Source incl. competitor pricing, docs, store listings; drift re-fetch of cited pagestriage as above; signal-intake/search: Sonnet 5 low, research profile, once commissioned [A5]≤ 150 requests, 0–8 triage calls, 1 search call of ≤ 8 searches, 45-minute deadline
Weekly auditSunday 02:00, portfolio-wideRe-label 10 sampled Capturessignal-intake/audit: gpt-6-astra xhigh, ChatGPT sign-in via codex exec [A4]1 call
Synthesis and gateSunday 02:30Synthesis where Clusters crossed; gate; challenge in the marginal bandopportunity-synthesis/propose: claude-opus-5-5 high, Claude sign-in; planning/challenge-opportunity: Astra xhigh0–1 synthesis call, ≤ 120 KB in (~70% cacheable prefix); ≤ 3 challenge calls
BundleMonday 07:00Escalation bundle to Attentionnone≤ 5 items portfolio-wide

Occurrence IDs discovery/<product>/basic/<date> and …/full/<iso-week> are stable; each transition (admit, defer, reconcile, resume, settle) has its own deterministic command ID under the occurrence, and a retried transition replays its receipt (src/journal.ts:234-241). deferred is not terminal; each occurrence settles once. Missed windows coalesce. Discovery debits a new discovery-window allowance, a Factory admission limit only: the subscription's headroom is shared with the owner's sessions and unknown, so no provider capacity is reserved. An unknown call stays debited at its bound. Beyond the weekly ceiling (decision 6) occurrences are deferred budget-exhausted.

Failure rules, every task:

  • F1 A usage limit is unavailable usage-limit with a checked resetsAt [A2]; the occurrence is deferred, its Signals unknown.
  • F2 No retry inside the window; resume the same occurrence at the first slot after resetsAt by its resume transition, reconciling remote: unknown first and never re-dispatching an unknown effect.
  • F3 Never switch model, provider or tier; never probe a limit.
  • F4 isUsingOverage: true fails closed. It is seen only after contact, so it cannot prove no charge: any provider contact, qualification probes included, needs S1's current record that paid overage is off, otherwise unavailable.
  • F5 401 or 403 is an owner blocker, "sign-in needed".
  • F6 Malformed output takes the fallback.

The five external Products have no brief, so no discovery runs for them until one is confirmed.

6. Decision gate

A versioned Policy; thresholds are proposals [A7]. Rules run first, in order, at no token cost.

RulePasses whenOtherwise
G1 shapeparses; SliceNeed valid under RECORD_LIMITS; Objective exists and is current; Capability resolvesreject
G2 provenanceevery cited Signal is the Product's, and each Citation re-verifies from recorded bytes or, once its bytes have expired, is dropped as unverifiable (unknown, not failed)reject
G3 noveltynot open work; Cluster-set Jaccard < 0.6 with open or rejected Opportunities; a repeat of a rejection brings ≥ 3 new Signalsreject
G4 Evidence≥ 3 verified Signals from ≥ 2 domains (a domain counts once per Cluster per window), ≥ 2 customer-voice (so competitor-only parks), ≥ 1 under 30 dayspark
G5 measurablea measurement source exists, or the Slice is instrumentationpark
G6 capacitybacklog below the commissioned cappark
G7 Authorityno new Objective, first delivery grant, spend, customer contact, pricing or positioning, new data class or customer-visible retirementroute to owner
G8 Evidence classa first-party usage or support Signal, or a prior Supported Assessmentadmit as validation-only (the Opportunity's cheapestValidation)

Then admit when the deterministic score (distinct domains × recency × severity × Objective weight × weeks recurring, less cost class) clears the threshold; the marginal band (± 15%) or a guidance conflict goes to the challenge.

Who decides:

  • Rules reject and park. Parked items re-enter on new Signals; after 8 quiet weeks they are rejected, reason kept.
  • The challenge (Astra xhigh; a drafter in phase plan, since a verifier presumes a Candidate) returns fixed reason codes citing Citations, and the gate re-runs the checkable ones. It may only lower admit to park; if unavailable, the item parks.
  • Planning admits within existing Objectives: admission is reversible, inspectable (docs/human-interface.md:11) and never selects. Planning ranks within the WIP cap, recording rejected alternatives and opportunity cost (E14).
  • The owner answers four classes only: an outward Action (publish, post, contact, live traffic, release, spend); expanding Authority (first delivery grant, new Objective); customer-visible retirement; one-time commissions. Each item shows objective, trade-offs, recommendation, effect and Evidence one click away. Overflow parks as owner-queue-full; an unanswered item returns once, then parks as owner-unanswered.

Calibration: delivered admits later Supported; rejected Clusters that kept growing; challenge parks confirmed versus overturned. Thresholds change only by reviewed Policy revision, calibrated against Assessments, never admission counts.

7. Post-development gates

StageGateIntelligenceOwner
Verificationindependent Assurance Verdict; before first exposure, the integrated artefact's identity and a recovery drill (E03); an availability claim also needs a channel Receipt, customer-path probe and health observation (E04)unchangedthe release itself (Action grant)
Docssame Slice; a doc-drift scenario fails acceptance when changed flags, exports, UI strings or Capability IDs lack docs; stale-claim sweep per releasenonenone
Growth draftsevery claim renders from a typed fact (subject, value, scope, population, window, causal or observational) in code, and Astra reviews the model's prose against those facts; every block cites a current fact: availability a release fact and probe, benefit a Supported Assessment, competitor claims Citations < 30 days plus owner approval; no uncited figures, superlatives, guarantees or pricing; British spelling; owner-data screen; a withdrawn fact invalidates the packSonnet 5 low drafts as data; Factory code writes the pack and digest under <local evidence archive>one "publish?" item bound to digest and channel; with no Action gateway, the owner acts and records the URL as an owner-sourced Receipt
Validationcontract frozen before exposure: primary metric (task success, adoption or tagged support load), 28-day baseline, target, population, window (28 days, ≥ 14, until the declared sample, cap 90), guardrails (errors, p95 latency, churn), decision rule. Supported only when target met, guardrails held, sample sufficient, coverage exact, and instrumentation, adverse segments and the decision rule's application checked by Assurance; else Rejected or Inconclusive naming the next decision. Cluster recurrence is observational onlynonea new data class
A/Bonly under declared uncertainty; deterministic design (unit, allocation, minimum detectable effect, α 0.05, power 0.8, sample, horizon, stop rule); no efficacy read before the horizon, while guardrails are monitored throughout under the frozen stop rule; sample-ratio mismatch (χ² p < 0.001) gives Inconclusive; flag ships in an ordinary Slicenonestart, ramp and ship each need an Action grant; the start grant pre-authorises one stop-to-control on a guardrail breach
Cleanupweekly defrag Slice (E25); line counts alone cannot passexistingnone
Deprecationevidence beyond low usage; E26 fields (consumers, migration, notice, data handling, recovery window, closure; account data also needs E19 proof); staged Slices: Retiring, migration, removal after the window; Assurance verifies each baseline; a regression while Retiring restores safe behaviour without resetting dispositionOpus 5.5 high drafts the casecustomer-visible retirement and notice

8. Transport and confinement per role

RoleProfileAudit findings it depends on
Triage, synthesis, drafts, retirement caseT0, the existing producer argv (src/claude-producer.ts:154-167): --tools "" --restricted --safe-mode, empty MCP and settings, empty cwd, data inlined on stdin; its four-key environment grows by the chosen remedies (a new rules revision)The audit's own mappings (completeness README, remedy table): C1 E1 (CLAUDE_CODE_HARBOR_KITE=0) + X3; C2, C3, C5 E1; C4 O3; T2–T4, AT12c A1, with detection only (the request may already be sent); AT1a, AT11a E7, verified by file-read or request-content observation, with B or X1 + O8 (untrusted stdin can carry @path); M13 O2, drafts screened for owner data; M15 B or X1 + O8; H5 O1 + X2; P1, P2 E3, then O5 after Tr2, Tr8, Tr9; P6 Tr2 + O5; P3 E4; P5 E5 + Tr1; P9 Tr3; every other open or unknown row by its listed remedy
Weekly searchT1, a second reviewed claude-cli profile: --tools WebSearch only, no fetch tool (Factory fetches allow-listed URLs; others become "proposed Sources"); tool blocks checked by name; ≤ 8 searches; public-only brief; query screenIts own complete audit and qualification of this exact profile: closures that rest on an empty pool (T3, T4, T5, T9) do not carry over from T0, and WebSearch's sub-requests need auditing; a by-name check detects but neither prevents another tool nor enforces the search bound before dispatch. C1–C5 closed, not accepted (a standing exfiltration channel; C4 by a separately demonstrated registry switch); M13 only by Alternative B, since a query screen sees a query after it has left. Unavailable until these are independently proved; live last
Audit, challenge, pack reviewT2, new codex-cli Transport: codex exec -m gpt-6-astra -s read-only --ephemeral --ignore-user-config --ignore-rules --json --output-schema <file> -C <empty dir> [A11], absolute path, stdin; never the alias or --searchunaudited: a pinned 0.153.4 audit of the app-server daemon, queue, hooks, plugins, MCP and CODEX_HOME reads; PROVIDER_TRANSPORT edit (decision 3)
CollectorHTTPS GET to allow-listed domains; fixed User-Agent; no cookies, credentials or scripts; robots.txt and terms honoured; ≤ 2 MiB per fetch, ≤ 4 KiB text per Capture, larger refused; cache ≤ 35 days under <local cache>; only hash and quote durable; after expiry a Citation is unverifiable: it counts towards no rule and supports no claimnone: no model, no owner data
RunnerLaunchAgent as the owner, StartCalendarInterval, one Factory command per occurrencesign-in from launchd not established [A1]. Rejected: cron, desktop scheduled tasks, CronCreate, cloud routines, GitHub Actions (no receipt, owner-level tools, or sign-in off this Mac)

Never: Platform keys, --bare, --fallback-model, setup-token, codex login --with-api-key or --with-access-token, exported sign-ins, --max-budget-usd as a control.

Before any live scheduled run:

  • L1 Claude T0 qualified: the chosen remedies as a new rules revision (argv, environment and policy digests) independently reviewed; an owner-signed completeness audit saying complete: true for that profile, since qualification refuses otherwise; the owed traces and named acceptances; a fresh qualification and commission receipt.
  • L2 The selector's implicit-retries refusal (src/intelligence.ts:709, one request per invocation) lifted only by a commission establishing one request per invocation, or by a reviewed selector change after O5.
  • L3 Each efficient task (triage, search, draft pack) measured separately against Opus 5.5 low on its own owner-labelled corpus by cost per completed task (docs/agents/intelligence.md:81); each goes live only on its own result.
  • L4 F1–F6 fixture-proved; a live limit event recorded in a manual run.
  • L5 One owner-launched manual occurrence proves sign-in from the LaunchAgent.
  • L6 Applicable docs/self-improvement.md proofs: a restart gives one occurrence; a seeded attractive proposal is rejected.
  • L7 A confirmed brief and allow-list.
  • L8 A two-week shadow that admits nothing.

The owner signs: S1 schedule commission (timezone, times, ceilings) and the owner's dated record of each account's subscription sign-in and disabled paid overage, stale after 30 days or any sign-in change [A13]; S2 Claude T0 commission and route acceptances; S3 Codex commission after its audit; S4 research profile (last); S5 each brief and allow-list; S6 loading the LaunchAgent plist; S7 any first delivery grant.

9. Increment plan

Each increment: independent Astra review, both module pages, a receipt, rebuilt site.

#IncrementAcceptance
0Planned declarations (extension protocols); discovery-window; codex-cli declared unqualified; new terms Capture, Cluster, Opportunity, Citation, Action grantregistry tests pass; docs reviewed
1lifecycle-schedule, fake clockday, week, DST boundaries; restart gives one occurrence; coalescing; injected limit defers and resumes the same occurrence under distinct transition IDs, with exactly one settlement and no re-dispatch of an unknown effect; overage fails closed; ceiling refuses
2discovery-sources, loopback corpusidentical Captures on replay; oversized refused; forged quote, cross-domain duplicate, drift, injected instructions, owner-email bait handled
3signal-intake, synthesis, predetermined transportspans verify; a re-run dispatches nothing; week 2 sees only the delta; no-change day, zero calls
3bMinimal versioned Objective and Capability records (owner, Authority reference, resolution rule); the first Product's scope commissioned (S5), not derived from its focus textG1 resolves only current records; focus text alone refuses
4Gate, owner-decisions, typed dashboard decide commandattractive unsupported proposal rejected; competitor-only parked; web-only admitted validation-only; marginal parks without the challenge; challenge only lowers; bundle capped; silence does nothing
5growth, outcome-validation, retirement detectionstale claim rejected; all three Assessments; sample-ratio mismatch Inconclusive; A/B read-out and guardrail stop on fixtures; low-usage-only retirement refused; undocumented flag fails; on fixtures, a cleanup restoration drill (E25) and a retirement migration, recovery-window and deletion drill (E26)
6Claude transport extended to Sonnet 5; qualification (S2)wrong-model and wrong-profile refusals; L1, L2; L3 for triage (search and draft packs qualify on their own comparisons in increments 10 and 11): basis measured, or the pin changes by reviewed edit
7codex-cli audit, transport, qualification (S3)commission receipt; audit and challenge pass on fixtures
8Live fetch and triage, one Product, two-week shadowL4–L8; E24 occurrence traces
9Live synthesis, gate and bundleone admit selected into a Slice within a grant
10Research profile: its own audit and qualification (S4)independently shown: permitted search, refusal of every other tool, the search bound enforced before excess dispatch, allow-list conformance, every searched URL re-fetched by the collector; L3 for search. Otherwise T1 stays unavailable
11Live post-developmentL3 for draft packs; one owner-granted, owner-executed release with E03 and E04 Evidence; a completed window; an independently checked Assessment and its recorded next decision [A10]

10. First one-Product end-to-end proof

Product: software-factory (decision 11), the only Product with focus-objective text and guidance; its Objective, Capabilities and scope still need records (increment 3b) and a commission (S5). It has no customers, so its customer-outcome Assessments can only be Inconclusive; a local deriveAssessment result is not customer benefit. Delivery needs handover step 1 [A12].

Run: offline on the recorded corpus, then live for 14 days (12 basic, 2 full, 2 synthesis occurrences) with an injected restart and scripted usage limit.

Passes when:

  1. Each occurrence settles once with coverage and a token ledger; restart and limit resume the same occurrences.
  2. Unchanged re-fetches make no model call; every Citation re-verifies from recorded bytes.
  3. At least one Opportunity maps to an Objective; every disposition names its rule, challenge or answer.
  4. One admit is frozen into a Slice, delivered through the product gate and Verified locally.
  5. A release-notes draft passes the claim trace, a seeded stale claim is rejected, and the draft waits at the owner gate.
  6. The contract is frozen and the read-out scheduled.
  7. Astra reviews the trace.

This proves mechanism, not value; it advances E01, E14 and E24 and closes none.

11. Open owner decisions

  1. Small fast model. Default: claude-sonnet-5 low, measured against Opus 5.5 low; Haiku 4.5 only if qualification settles --effort.
  2. Synthesis model. Default: claude-opus-5-5 high, one pin with deferral; Fable 5.1 needs a transport change and ran out of usage on 28 September.
  3. OpenAI transport. Default: add codex-cli and re-point openai to it; keep openai-producer.ts accepted but unpinned. Alternative: two transports per provider.
  4. Small OpenAI model. Default: none; Astra xhigh audits and challenges, keeping drafter and checker on different providers.
  5. Timezone and times. Default: Europe/London, as §5.
  6. Capacity. Default: discovery-window; weekly ceiling at shadow p95 × 1.25, never extended; a Factory admission limit, not a provider reservation.
  7. Retries. Default: O5 for tool-free roles once Tr2, Tr8 and Tr9 show a finite bound (visible retries fail; wall-clock deadline), with the reviewed selector change L2 names.
  8. Owner email (M13). Default: accept O2 for tool-free roles; search needs Alternative B.
  9. Admission autonomy. Default: Planning admits within existing Objectives; for each Product's first 8 weeks the bundle carries a read-only admit digest the owner may overrule. Alternative: the owner approves every admit while calibrating.
  10. Bundle cap. Default: five a week, one reminder, then owner-unanswered.
  11. First Product. Default: software-factory, then one external Product with a confirmed brief.
  12. External briefs. Default: the owner writes or confirms a one-paragraph public brief and allow-list; the Factory drafts one only under a granted read.
  13. Sources. Default: public pages only; no login, paywall or sites forbidding automated access; 15-word quotes; 35-day cache.
  14. A/B guardrail stop. Default: every start grant pre-authorises one stop-to-control.

12. Assumptions

  • A1 A LaunchAgent reaches the Claude Keychain sign-in and CODEX_HOME.
  • A2 The live limit event matches the fake rate_limit_info {status, rateLimitType, resetsAt, isUsingOverage} (test/helpers/claude-events.ts:101).
  • A3 claude-sonnet-5 --effort low works through claude-cli on the subscription.
  • A4 codex exec -m gpt-6-astra --output-schema runs headless on ChatGPT sign-in (only --help read).
  • A5 WebSearch works under --restricted --tools WebSearch.
  • A6 Scheduled runs share the owner's usage window; token counts are estimates, billing unknown.
  • A7 Every threshold (3 Signals, 2 domains, 30 days, Jaccard 0.6, SimHash 3, 90 days, 8 weeks, ± 15%, 80%, the 30-day overage record) is a proposal.
  • A8 The owner's timezone is Europe/London.
  • A9 A separate discovery.sqlite journal is acceptable.
  • A10 Products will export measurements; until then validation is Inconclusive.
  • A11 --skip-git-repo-check may be needed for an empty -C directory; the audit decides.
  • A12 Handover step 1 (delivery composition) lands before increment 9.
  • A13 Each subscription lets paid overage be turned off and shows that setting to the owner; not established. If not, every model role stays unavailable.

13. Out of scope

Publishing, posting or contacting customers; surveys and interviews; advertising and spend; live traffic or release without an Action grant; Product-side instrumentation; logged-in, paywalled or paid sources; embeddings; Platform keys or exported sign-ins; models in CI or the cloud; automatic Objectives or customer-visible retirement; the Factory's nightly tools research; customer-value claims from local proof; closing any epic.

Source: docs/lifecycle.md