IntDEx logo

ai_delivery_engine_initialisation_v1.md

Markdown (.md)
  1. <!-- AI-native Delivery Experience - IntDEx. Provided under CC BY 4.0. https://IntDEx.org -->
  2. <!--
  3. Note about comments:
  4. For AI models: Ignore them.
  5. For Humans: Deleting the comments will reduce the unactionable contentthe AI model will read.
  6. TEMPLATE FILE - USER SETTINGS
  7. The engine BUILD SPECIFICATION. ai_delivery_engine_initialisation.ps1 (if exists) is an implementation of it;
  8. this file is the contract that a deterministic script/buidl mechanism must satisfy. Lose the script and a competent model rebuilds
  9. it from this file alone. That is why this is a seed and the script is not.
  10. READ ONLY when initialising or repairing. NEVER during routine per-message work: the split exists
  11. to keep this cost off every message. The essential-files gate prints a SCOPE line telling you which
  12. situation you are in.
  13. TO REUSE ON A NEW PROJECT edit only: (1) Product Name, (2) the Created timestamp, ONCE, and
  14. (3) the Bootstrap Registry, if your organisation needs an extra register - and then you MUST add
  15. the code that emits it to the script in the same work item.
  16. DO NOT EDIT the Gate Behaviour Specifications, Output Contract, Self-Test or No-Stub Rule. They are
  17. observable-behaviour contracts that make independently authored gates interchangeable. Loosening a
  18. pass condition here loosens it everywhere, permanently, and the loosened gate still reports PASS.
  19. -->
  20. # AI Delivery Engine Initialisation (v{v})
  21. <!-- SETTING 1: product name. Keep identical across all artefacts. -->
  22. ## Product Name
  23. XYZ
  24. <!-- SETTING 2: reset "Created" ONCE when copying to a new project. -->
  25. ## Artefact Metadata
  26. - Created: 2026-09-03 13:40:00 +02:00
  27. - Created By: human
  28. - Stage: engine
  29. - Work Item: manifest_split
  30. - Timestamp Source: engine-clock
  31. ## Governing Principles
  32. Four principles generate most of the rules below. They are stated once here and referenced by name
  33. rather than restated.
  34. - **P1 Seeds vs derived.** The essential files are listed in ONE place: the marker block in
  35. `.pdm/ai_delivery_engine/ai_delivery_engine_manifest_v{v}.md` between `INTDEX_ESSENTIAL_FILES_START`
  36. and `INTDEX_ESSENTIAL_FILES_END`. They are human-owned and MUST NEVER be generated or overwritten.
  37. Everything else under `.pdm/` is derived and MUST be reproducible from the seeds alone. Bootstrap
  38. never overwrites an existing file, so re-running is always safe and idempotent.
  39. - **P2 False assurance is worse than absence.** A control that reports success while enforcing
  40. nothing satisfies the per-message procedure and makes every downstream control decorative, while
  41. continuing to display success. Wherever this file offers a choice between failing loudly and
  42. passing quietly, fail loudly. A known gap is recoverable; a false pass is not.
  43. - **P3 Presence is not function.** Creating a filename is not creating an artefact. Counts, file
  44. presence and reference-integrity scans are all satisfied by an empty shell. Only content
  45. comparison and the self-test distinguish a working engine from a plausible-looking one.
  46. - **P4 The engine holds no authority over itself.** It MUST NOT author its own ethical constraints,
  47. autonomy scope or capability boundary. A limit the engine wrote about itself is a self-granted
  48. permission and will be obeyed exactly as far as it is convenient.
  49. ## Status and Loading Rule
  50. This is an **essential file** (P1), enforced by the essential-files block of
  51. `per_message_deterministic_script.ps1`.
  52. Load it ONLY when initialising or repairing: the bootstrap script is absent, a gate script is
  53. missing, or a Bootstrap Registry artefact is found missing. Loading it during routine work while
  54. the gate reports the engine COMPLETE is a context-scope error and MUST be reported as one.
  55. It is authoritative for initialisation and defines the process so that any model, provider family
  56. or agent host produces the same end state. No specific command phrasing triggers it.
  57. **Why one file sits outside `.pdm/`.** `.github/copilot-instructions.md` is the only file the agent
  58. host injects automatically, so it is the sole entry point through which anything else is reached and
  59. cannot be relocated or merged. Its size is a recurring per-message cost; initialisation content is
  60. needed rarely, so it lives here and loads on demand. This does not weaken reproducibility, because
  61. this file is a seed, not a derived artefact. Were it derived, a workspace missing the bootstrap
  62. script would also be missing the instructions for recreating it, and self-heal would be impossible.
  63. ## Initialisation Procedure
  64. ### Tier 1 (preferred, deterministic)
  65. Relax the PowerShell execution policy for the current process only, then run
  66. `.pdm/ai_delivery_engine/ai_delivery_engine_initialisation.ps1` with `-WorkspaceRoot` and
  67. `-OperatingModel`. That is the whole procedure. It creates the gate scripts AND runs them, and
  68. records the Continuous Behaviour Validation baseline. Two models running it produce byte-identical
  69. artefacts.
  70. `-WorkspaceRoot` is the authoritative scope setting. If omitted the script may auto-discover the
  71. root by walking up to the first folder containing `.pdm`, but generated artefacts MUST treat the
  72. resolved value as current scope and never hardcode historical paths.
  73. Gate script names, their order and their exit-code meanings are internal to the engine and MUST NOT
  74. appear in any initialisation instruction. Requiring a human to remember five script names moves
  75. engine knowledge into human memory, where it decays, and a gate nobody remembers to run is not a
  76. control. After initialisation, state explicitly that the workspace is governed but unvalidated.
  77. If a gate script or any derived artefact is missing during routine operation, re-run the bootstrap;
  78. it regenerates whatever is absent without touching what exists (P1). Never hand-author a derived
  79. engine file. Any model from any provider family MUST be able to do this: depend on no feature
  80. specific to one assistant product or IDE.
  81. ### Tier 2 (fallback, bootstrap script missing)
  82. Author the script from this specification, then run Tier 1. MUST NOT hand-create derived artefacts
  83. one by one while leaving the script absent; that reintroduces per-model variation and leaves the
  84. workspace unable to self-heal.
  85. Tier 2 is a REBUILD of the generator, not a sketch. Its output MUST be shippable as the canonical
  86. bootstrap for every future workspace. A file that merely has the right name, or prints progress
  87. without writing engine logic, is a Tier 2 FAILURE and MUST be reported as one.
  88. Build in this order; each step depends on the one before:
  89. 1. **`engine_paths.ps1` first.** Every gate dot-sources it. Implement `Get-IntdexRoot`,
  90. `Resolve-IntdexPath` (including `{v}` highest-version resolution) and `Get-IntdexEssentialFiles`
  91. (parsing the manifest marker block). A gate written before this exists will hardcode paths.
  92. 2. **Each gate body in full**, to `Gate Behaviour Specifications` and the `Mandatory Gate Output
  93. Contract`. Write the real parsing, scanning and counting logic; a gate MUST derive its exit code
  94. from what it observed on disk in this run.
  95. 3. **Embed every body** in the generator as a single-quoted here-string, per `Engine Script Bodies`.
  96. 4. **Every registry artefact**, to the substance floor in `No-Stub Rule`.
  97. 5. **Run the generator**, then run the `Gate Falsifiability Self-Test`. A generator that has not
  98. been executed has not been written: a here-string is opaque to the parser, so its contents are
  99. unverified until they run.
  100. If a gate's logic cannot be implemented, write it to exit `3` with an explicit `NOT-IMPLEMENTED`
  101. message naming the gate, report the gap in the summary and in `engine_capability_boundary_v{v}.md`
  102. with `Enforced by: Nothing`. MUST NOT write a gate that exits `0` (P2).
  103. ### Bootstrap script requirements
  104. `ai_delivery_engine_initialisation.ps1` MUST:
  105. - accept `-WorkspaceRoot`, optional `-WhatIfReport` (report-only), optional `-OperatingModel` and
  106. optional `-SkipGates` (diagnostic);
  107. - verify the essential files FIRST and exit `1` with the hard-stop message if any is missing;
  108. - be SELF-CONTAINED: carry the body of every executable engine script it creates, depending on
  109. nothing outside the seeds (see `Engine Script Bodies`);
  110. - never overwrite an existing file (P1);
  111. - create every folder and file in the Bootstrap Registry;
  112. - regenerate the markdown cost reports from the CSV ledgers, and the metrics report from the engine
  113. artefacts;
  114. - stamp any markdown artefact under `.pdm/` lacking an `## Artefact Metadata` block;
  115. - verify governance reference integrity and report dangling references;
  116. - RUN every gate it created, in per-message order, print each gate's own output verbatim, and
  117. summarise every exit code;
  118. - COMPARE CONTENT, not only presence (P3). Re-materialise every embedded script body and compare it
  119. byte-for-byte by hash against the live `.ps1`; compare the `## ` section structure of every
  120. embedded markdown seed against the live artefact. Report any mismatch as `DRIFT` naming the file.
  121. This is the only mechanical detection of a double-edit violation that exists; without it a
  122. bootstrap reports `Created: 32 / Failed: 0` while reproducing a degraded engine. Structural, not
  123. byte, comparison is used for markdown because a live register legitimately diverges once
  124. customised: a MISSING SECTION is drift, differing prose is not;
  125. - record the initial CBV baseline AFTER the gates have run, so it reflects the state they ran
  126. against;
  127. - SELF-TEST every gate per `Gate Falsifiability Self-Test`, and fail initialisation if any gate
  128. cannot be made to return non-zero. Running a gate proves it executes; only the self-test proves it
  129. decides;
  130. - VERIFY the `No-Stub Rule` substance floor for every artefact written, reporting shortfalls by name;
  131. - print that EC-01 to EC-08 are active and unauthored, and name authoring them as the first required
  132. human action;
  133. - exit `0` on success; `1` if a blocking gate did not pass, any gate failed the self-test, or any
  134. artefact fell below its substance floor; `3` on write failure. Self-test and substance-floor
  135. failures are exit `1`, never a warning (P2);
  136. - depend only on Windows PowerShell 5.1 built-ins: no network, no LLM call.
  137. A non-zero exit from `cost_telemetry.ps1` is NOT blocking; `2` is its normal unverified result and
  138. MUST be reported as such rather than as an error.
  139. ## No-Stub Rule (normative)
  140. The Bootstrap Registry lists files that must EXIST AND FUNCTION (P3). A registry of filenames is
  141. trivially satisfiable by writing thirty headings, and the result passes every presence check, file
  142. count and reference scan while containing no engine.
  143. These are FAILURES, not partial successes, and MUST be reported as such with a non-zero exit:
  144. - A `.ps1` that prints a message and exits without the observable behaviour specified for it.
  145. `Write-Host 'gate: ready'; exit 0` is not a gate.
  146. - A `.ps1` whose exit code is a literal constant rather than derived from what it observed this run.
  147. Every gate MUST have at least one reachable input state producing a non-zero exit.
  148. - A markdown register consisting only of a title, `## Product Name` and `## Artefact Metadata`
  149. where the registry requires seeded rows, a template or defined sections.
  150. - Any `TODO`, `TBD`, `placeholder`, `stub`, `to be implemented`, `coming soon`, or empty section
  151. body in any derived artefact.
  152. - A generator that writes artefacts but does not carry every engine script body, and so cannot
  153. rebuild from the seeds alone.
  154. **Substance floor.** Floors, not targets, stated numerically only so failure is mechanically
  155. detectable rather than a matter of judgement. Meeting a floor does not make a file correct; falling
  156. below one makes it certainly incomplete.
  157. | Artefact class | Minimum | Must contain |
  158. |---|---|---|
  159. | `engine_paths.ps1` | 30 non-comment lines | All three exported functions, `{v}` highest-version resolution, manifest marker parsing |
  160. | `per_message_deterministic_script.ps1` | 200 non-comment lines | Five distinct, separately callable blocks; `pre`, `post`, `all`, `baseline` phases; per-block output and exit aggregation |
  161. | `code_security_gate.ps1` | 40 non-comment lines | At least 4 GS-03 and 4 GS-04 patterns, a real file walk, a skip list, the GS-01/GS-02 unenforced disclosure |
  162. | `cost_manager.ps1`, `metrics_report.ps1`, `lifecycle_manager.ps1`, `cost_telemetry.ps1` | 40 non-comment lines each | Their `-Mode`/`-Phase` parameters, real file I/O, the specified exit-code range |
  163. | `ai_delivery_engine_initialisation.ps1` | All engine script bodies, plus every registry seed | Self-containment: seeds plus this file build a complete engine |
  164. | Seeded register (`risk_log`, `ethics_constraints`, `incident_autonomy`, `engine_capability_boundary`) | Every row the registry names | R-001 to R-009, EC-01 to EC-08, CB-01 to CB-07, both incident criteria, as applicable |
  165. | Template register (`hitl_checkpoints`) | Full `entry_template` | Every field in the manifest's HITL minimum-field list |
  166. | Ledger CSV | Header row | Exactly the normative column order, unreordered |
  167. | Generated report (`metrics_report`, cost logs, `artefact_traceability`, `functionality_coverage_matrix`) | Written by its generator, not by hand | Values computed from artefacts on disk, `NOT-COMPUTABLE` where input is absent |
  168. A model that cannot meet a floor MUST say so explicitly, naming the artefact and shortfall. It MUST
  169. NOT pad to reach a line count, and MUST NOT silently emit less.
  170. ## Engine Script Bodies
  171. Every executable engine script is carried inside the bootstrap as a single-quoted here-string. That
  172. file plus the seeds is a complete engine.
  173. An external source folder was tried and reverted: it removed the double-edit rule but made the
  174. generator depend on twelve files instead of one, and its copy was byte-identical, so it bought no
  175. transformation, only distribution fragility.
  176. **DOUBLE-EDIT RULE (normative).** Each engine script exists twice: the live `.ps1` and the embedded
  177. copy. A change to one MUST be applied to the other in the same work item. A fix applied only to the
  178. live copy works today and disappears at the next bootstrap.
  179. This has already failed in practice: six of eleven embedded bodies were once found drifted, and the
  180. embedded lifecycle manager still referenced a methodology filename that no longer existed. Every
  181. clean-room rebuild in that period reported success while reproducing a degraded engine, because
  182. verification counted files and compared references but never compared CONTENT. Two consequences:
  183. - Verification MUST compare content, not counts (P3). Hash comparison of each generated `.ps1`
  184. against the live one is what detects a double-edit violation, and MUST run whenever a script
  185. changes.
  186. - A here-string is opaque to the parser, so a syntax error inside one is undetectable until the
  187. generated script runs. An edit to an embedded body MUST be validated by executing the generated
  188. script, never by inspection alone.
  189. ## Bootstrap Registry
  190. **Folders:** `.pdm/ai_delivery_engine`, `.pdm/epics`, `.pdm/features`, `.pdm/intents`,
  191. `.pdm/prompts`, `.pdm/contexts`, `.pdm/constraints`, `.pdm/tests/prompts`,
  192. `.pdm/tests/prompts/results`. No other folder may be created.
  193. No subfolder of the results tree is created at initialisation: filing subfolders are a readability
  194. measure only, created by a human if wanted, never assumed. Every scanner reading result artefacts,
  195. in particular the independent-verification block and `metrics_report.ps1`, MUST nevertheless recurse
  196. into that tree. A subfolder that escaped the gate would let a workspace clear an inadmissible `PASS`
  197. by moving the file, converting a governance control into a filing convention.
  198. `.pdm/contexts` and `.pdm/constraints` are created EMPTY and are human-owned; the engine MUST NOT
  199. generate an artefact into either (P4). An engine-authored description of product and stack
  200. duplicates sections 1-3 of `.github/copilot-instructions.md` and drifts from it with nothing to flag
  201. the contradiction. `.pdm/constraints` holds PROJECT constraints per IntDEx section 6.5 `Context and
  202. Constraint Dependent`: sovereignty, regulatory, data-residency, cost, performance, accessibility and
  203. domain rules. It exists from initialisation so the place to put them precedes the first intent, and
  204. is loaded in Tier 1 alongside `.pdm/contexts` so constraints are never read later than the context
  205. they bound. An empty folder is not a defect and MUST NOT be reported as one.
  206. No scratch or temporary folder may be created anywhere under `.pdm/`. Transient output belongs in
  207. the operating system temporary directory; under `.pdm/` the stamping pass and reference scan would
  208. both treat it as a governed artefact.
  209. The reference-integrity scan checks backticked file paths, backticked `.pdm/` folder paths AND
  210. plain-text engine filenames, because a reference naming a missing path misleads regardless of its
  211. punctuation. Prefer describing an absent path to naming it; where naming is unavoidable, mark it per
  212. the manifest section `Reference Integrity Convention`.
  213. **Files**, with the content each must contain (all under `ai_delivery_engine/` unless shown):
  214. | File | Required content |
  215. |---|---|
  216. | `ai_delivery_engine_initialisation.ps1` | This specification, implemented. Carries every engine script body. |
  217. | `engine_paths.ps1` | Shared versioned-path resolver, dot-sourced by the gates. Written first; the gates depend on it. |
  218. | `per_message_deterministic_script.ps1` | Block 1 core-file hard stop, Block 2 unvalidated Major checkpoint gate, Block 3 mechanically decidable ethics gate, Block 4 configuration-drift demand (warn-only), Block 5 evidence admissibility. Phases `pre`, `post`, `all`, `baseline`. |
  219. | `code_security_gate.ps1` | GS-03 secret shapes and GS-04 insecure defaults, by pattern matching only. |
  220. | `cost_telemetry.ps1` | Deterministic verified/unverified probe. |
  221. | `cost_manager.ps1` | Ledger append, schema migration, report rebuild. |
  222. | `metrics_v{v}.md` | Metric definitions, each with data source and verification tier. |
  223. | `metrics_report.ps1` | Deterministic metric computation over engine artefacts. |
  224. | `metrics_report_v{v}.md` | Generated; never hand-edited. |
  225. | `lifecycle_events_v{v}.csv` | Header row only. Append-only stage-transition ledger. |
  226. | `lifecycle_manager.ps1` | Metadata stamping, stage-event append, manual release flag. |
  227. | `prompt_cost_events_v{v}.csv`, `interaction_cost_events_v{v}.csv` | Header row only. |
  228. | `prompt_cost_log_v{v}.md`, `interaction_cost_log_v{v}.md` | Generated from their ledgers. |
  229. | `hitl_checkpoints_v{v}.md` | YAML block, `entries: []`, full `entry_template`. |
  230. | `artefact_traceability_v{v}.md` | GENERATED by `metrics_report.ps1` every run from the `Work Item` field of every artefact under `.pdm/`. Never hand-edited, never seeded empty: an empty register nobody populates is documentation, not a control. |
  231. | `functionality_coverage_matrix_v{v}.md` | GENERATED every run from the same work-item grouping, joined to result artefacts and their declared `verification_source`. Never hand-edited. |
  232. | `cbv_baseline_v{v}.md` | CBV baseline. Written by `-Phase baseline`, not by the bootstrap directly, so it records the state the gates actually ran against. |
  233. | `risk_log_v{v}.md` | Seven-column table seeded R-001 to R-009. |
  234. | `ethics_constraints_v{v}.md` | EC-01 to EC-08, EC-07 operating rules, limits-of-mechanical-enforcement statement, tiering rule, empty determination ledger. |
  235. | `release_checklist_v{v}.md` | Checklist plus a not-releasable release status. |
  236. | `intent_prompt_rebuild_log_v{v}.md` | Empty rebuild-evidence table. |
  237. | `messages_from_the_engine.md` | Table plus the initialisation message. |
  238. | `user_chat_messages_log.md` | Empty latest-first table. |
  239. | `user_stories_engine_created.md` | Latest-first heading. |
  240. | `evidential_independence_v{v}.md` | Admissible and inadmissible evidence rules. |
  241. | `untrusted_content_v{v}.md` | UC-01 to UC-08, unenforced rules recorded as open gaps, never as satisfied. |
  242. | `generated_code_security_v{v}.md` | GS-01 to GS-07 and RR-01 to RR-05, unenforced rules as open gaps. |
  243. | `incident_autonomy_v{v}.md` | Criteria A severity (WHEN), Criteria B change-type matrix (WHAT), plan pre-approval rule, autonomy-scope drift rule, empty adoption ledger. Seeded closed, per `Seeded-Closed Artefacts`. |
  244. | `engine_capability_boundary_v{v}.md` | CB-01 to CB-07: read, write, execute, egress, installation and credential scope, each as `Observed today` / `Proposed boundary` / `Enforced by` / `Open question`. Seeded closed. Where no script enforces a row, `Enforced by` MUST read `Nothing` rather than being left implied. |
  245. **CSV column order is normative and MUST NOT be reordered:**
  246. - prompt: `timestamp,event_type,model,estimated_input_tokens,estimated_output_tokens,estimated_tool_calls,estimated_total_usd,actual_total_usd,estimation_method,verification_status,notes`
  247. - interaction: `timestamp,interaction_id,event_phase,model,estimated_input_tokens,estimated_output_tokens,estimated_tool_calls,estimated_total_usd,actual_total_usd,estimation_method,verification_status,notes`
  248. - lifecycle: `timestamp,work_item,stage,event,actor,verification_source,notes`
  249. Markdown header format and the `## Artefact Metadata` block are specified in the per-message
  250. manifest and are not restated here.
  251. ### Licence attribution (normative)
  252. Every derived artefact MUST carry the IntDEx CC BY 4.0 attribution as its FIRST content, not only
  253. markdown ones. An engine that attributes its prose but not its code distributes the part most likely
  254. to be copied with no licence attached. Syntax MUST be correct for the language: an attribution that
  255. breaks the parser is worse than a missing one.
  256. | File type | Required first line | Placement |
  257. |---|---|---|
  258. | Markdown | `<!-- AI-native Delivery Experience - IntDEx. Provided under CC BY 4.0. https://IntDEx.org -->` | Line 1 |
  259. | PowerShell | `# AI-native Delivery Experience - IntDEx. Provided under CC BY 4.0. https://IntDEx.org` | After `#requires`, before comment-based help |
  260. | CSV | None | A comment line would corrupt the header row and every parser reading it |
  261. HTML comment syntax MUST NOT appear in a `.ps1`: it is a syntax error and would make the script
  262. unloadable. `#requires` MUST remain line 1, since PowerShell honours it only there. This rule
  263. applies to embedded bodies too, and is therefore subject to the DOUBLE-EDIT RULE.
  264. ## Gate Behaviour Specifications
  265. Observable behaviour, not implementation, so independently authored scripts are interchangeable.
  266. `per_message_deterministic_script.ps1` is abbreviated `PMDS` below.
  267. | Gate | Input | Pass condition | Exit codes |
  268. |---|---|---|---|
  269. | PMDS Block 1 essential files, `pre` | Essential-file list from manifest markers | Every listed file present | `0` pass, `1` block with hard-stop message and missing list. MUST also print an advisory `SCOPE` line stating whether the engine is COMPLETE or INCOMPLETE, determined solely from derived marker artefacts and never from essential files, which are always present whenever this gate can pass. When COMPLETE it names the initialisation-scope artefacts as out of scope for routine work; when INCOMPLETE it lists absent markers and routes repair to the bootstrap. The advisory MUST NEVER block |
  270. | PMDS Block 2 HITL major, `pre` | `hitl_checkpoints_v{v}.md` | Unvalidated `Major` entries `<= 3` | `0` pass, `1` block; always prints the unvalidated count |
  271. | PMDS Block 3 ethics, `pre` | `ethics_constraints_v{v}.md`, `.pdm/` and product source, test results | Artefact present and no mechanically decidable violation of EC-01, EC-03, EC-05 or EC-08. An `AWAITING-HUMAN-AUTHORING` definition WARNS while the workspace holds no delivery artefact and BLOCKS as soon as one exists. MUST always print EC-02, EC-04, EC-06, EC-07 as not adjudicated and MUST NEVER report them passed | `0` no mechanical violation, `1` block or artefact missing, `3` scan failure |
  272. | PMDS Block 4 CBV drift, `post` and `baseline` | The essential files, resolved via `engine_paths.ps1`, against `cbv_baseline_v{v}.md` | Watched-surface hashes match the baseline and the operating model is unchanged | `0` always in check; drift WARNS and never blocks; `3` scan failure. MUST warn, not fail, when no baseline exists, and MUST warn when re-baselining on `model-self-report-unverified` evidence |
  273. | PMDS Block 5 independent verification, `post` | `.pdm/tests/prompts/results/*.md` | Every file asserting `PASS` declares a `verification_source` of `executed`, `human`, `cross-model` or `prior-artefact` | `0` pass, `1` block listing each violation |
  274. | `code_security_gate.ps1` | Product source and `.pdm/` artefacts | No match among implemented GS-03 / GS-04 patterns | `0` no finding, `1` finding requiring human triage. MUST print that GS-01 (SAST) and GS-02 (dependency/CVE) remain unenforced, and that absence of findings does not mean secure |
  275. | `cost_telemetry.ps1` | Usage file, provider API credentials, or metrics config | An authoritative source is found | `0` verified, `2` unverified (normal, not an error), `1` probe failure |
  276. | `metrics_report.ps1` | Registry artefacts, HITL register, risk log, test results, cost ledgers, core files | All metrics computed and the report written | `0` success, `1` a required input is missing, `3` write failure |
  277. | `lifecycle_manager.ps1` | `-Mode stamp` markdown under `.pdm/`; `-Mode append`/`-Mode release` the lifecycle ledger | Stamping adds metadata only where absent and never alters an existing `Created`; appends are additive and preserve column order | `0` success, `1` invalid stage/event/arguments or a release without an actor, `3` write failure |
  278. | Bootstrap embedded-body drift check | Every embedded script body and markdown seed, against the live artefact | Every `.ps1` body matches after line-ending normalisation, and every required `## ` section of a seed is present in the live register | Advisory. Reports `DRIFT` per file and carries the count into the summary. MUST NOT block, because a drifted engine still needs to be buildable to be repaired, but the count MUST appear where it cannot be missed |
  279. `lifecycle_manager.ps1` MUST be idempotent in `-Mode stamp`, never rewrite an existing `Created`,
  280. and refuse a `release` event without an actor, since an unattributed release claim is
  281. indistinguishable from a self-declared one.
  282. `metrics_report.ps1` MUST compute every metric from artefacts on disk only, MUST NOT infer, estimate
  283. or narrate, and MUST mark any metric whose input is absent as `NOT-COMPUTABLE` rather than omitting
  284. it. Metrics are indicators, never evidence: a metric value MUST NOT justify a `PASS`.
  285. `cost_telemetry.ps1` MUST log credential environment variable **names** only, never values.
  286. `cost_manager.ps1` MUST clear `actual_total_usd` whenever `verification_status` is not `verified`.
  287. ### Mandatory Gate Output Contract
  288. A pass condition producing no distinguishing output cannot be audited from outside the script, and a
  289. gate printing only its own name is indistinguishable from one that does nothing. Each gate MUST emit
  290. at least one line carrying its identifying token AND the count it observed. The count is the
  291. cheapest available proof that the gate inspected something: a stub can print a label, but not a
  292. number it never computed.
  293. | Gate / block | Token | Must also print |
  294. |---|---|---|
  295. | Block 1 essential files | `ESSENTIAL-FILES-GATE` | Number of essential files resolved, and the `SCOPE` advisory |
  296. | Block 2 HITL major | `HITL-MAJOR-GATE` | Unvalidated `Major` count and the threshold |
  297. | Block 3 ethics | `ETHICS-GATE` | Per-constraint state for EC-01/03/05/08, and EC-02/04/06/07 explicitly as `UNVERIFIED` |
  298. | Block 4 CBV drift | `CBV-GATE` | Baseline id and number of watched surfaces compared |
  299. | Block 5 independent verification | `INDEPENDENT-VERIFICATION-GATE` | Result files scanned and violations found |
  300. | `code_security_gate.ps1` | `CODE-SECURITY-GATE` | Files scanned, findings count, GS-01/GS-02 unenforced disclosure |
  301. The engine MUST NOT report a gate as run unless that gate's token appeared in THIS run's output.
  302. Paraphrasing a gate's output, or summarising it as "gates passed", is prohibited.
  303. ### Gate Falsifiability Self-Test
  304. Every pass condition above is satisfied by a script whose only statement is `exit 0`. Presence
  305. checks, file counts and reference scans do not distinguish such a script from a working gate. This
  306. self-test is the only mechanical check that does, and it MUST be implemented.
  307. After the gates run and before the summary, the bootstrap MUST, for each gate, construct a condition
  308. the gate is specified to reject, invoke the gate, and confirm a non-zero exit, then restore the
  309. workspace exactly. All fixtures MUST be built under the OS temporary directory or reverted in a
  310. `finally` block, never left under `.pdm/`.
  311. | Gate | Injected condition | Required result |
  312. |---|---|---|
  313. | Block 1 essential files | `-WorkspaceRoot` pointed at an empty temporary folder | Exit `1` and the hard-stop message |
  314. | Block 2 HITL major | Temporary HITL register holding 4 unvalidated `Major` entries | Exit `1` and the block message |
  315. | Block 3 ethics | Temporary delivery artefact under `.pdm/intents` while definitions are unauthored | Exit `1` |
  316. | Block 4 CBV drift | Baseline recording a different operating model | Exit `0` with a drift WARNING present |
  317. | Block 5 independent verification | Temporary result file asserting `PASS` with no `verification_source` | Exit `1` naming the file |
  318. | `code_security_gate.ps1` | Temporary file containing `AKIA` plus 16 upper-case alphanumerics | Exit `1` with a `GS-03` finding |
  319. A gate returning `0` for its injected condition is NOT implemented, regardless of line count or how
  320. plausible its source reads. The bootstrap MUST print `SELF-TEST: <gate> FAILED - gate cannot reject
  321. its own reject condition`, name every such gate in the summary, and exit `1`. This MUST NOT be
  322. softened (P2): an engine whose gates cannot fail is not partially working, it is a reporting surface
  323. that returns PASS unconditionally.
  324. ## Seeded-Closed Artefacts
  325. `ethics_constraints_v{v}.md`, `incident_autonomy_v{v}.md` and `engine_capability_boundary_v{v}.md`
  326. MUST be created in the SAME run as every other registry artefact, never later and never on request.
  327. An engine that can act before its constraints exist has an unconstrained window at exactly the point
  328. it is least observed. Existing copies MUST NOT be overwritten (P1). If one is found missing during
  329. routine operation, treat it as a repair trigger and restore it before continuing delivery work.
  330. All three are seeded CLOSED, granting no authority, because the engine holds none over itself (P4):
  331. - **Ethics.** EC-01 to EC-08 seeded `AWAITING-HUMAN-AUTHORING`. An unauthored definition cannot be
  332. adjudicated, so it MUST NOT be reported as passed.
  333. - **Incident autonomy.** `metrics` and `plans` both EMPTY lists; status `DRAFT-ENGINE-AUTHORED`,
  334. under which every severity level is treated as its most restrictive neighbour and no plan may
  335. execute. Detection declared `deterministic-script-only`: a model MUST NOT adjudicate whether its
  336. own behaviour has drifted. Severity ordering seeded so autonomy DECREASES as severity increases —
  337. an engine acting most freely during the most severe incidents has the safety property backwards.
  338. - **Capability boundary.** EMPTY Adoption Ledger. The engine MUST NOT seed an adopted boundary.
  339. The Criteria B change-type matrix is not tunable by severity. A change in a mandatory human
  340. checkpoint type — security, authentication, authorisation, privacy, schema, data contract,
  341. user-visible behaviour, release, or engine constraints — is NEVER made autonomous by a severity
  342. value.
  343. **Three authoring states**, which the seed MUST define so a workspace later obtaining draft wording
  344. has somewhere truthful to record it:
  345. | State | Meaning | Gate effect |
  346. |---|---|---|
  347. | `AWAITING-HUMAN-AUTHORING` | No wording exists; cannot be adjudicated at all | WARNS pre-delivery, BLOCKS once any delivery artefact exists |
  348. | `DRAFT-ENGINE-AUTHORED` | Drafted by the engine at explicit operator request, recorded as a Major HITL checkpoint. Not canonical, no ethical authority | WARNS; reported `UNVERIFIED` |
  349. | `HUMAN-AUTHORED` | Authored or explicitly adopted by a named human, recorded in the Authorship Ledger | May be adjudicated per its Detection column |
  350. The engine MUST NEVER write `HUMAN-AUTHORED` or add a row to the Authorship Ledger. A mechanical
  351. check against `DRAFT-ENGINE-AUTHORED` wording verifies conformance to text the engine wrote about
  352. itself, and is `script-detected` against draft wording, never `human-reviewed`.
  353. **Pre-delivery ethics posture.** The gate MUST NOT block unconditionally either: a workspace holding
  354. no delivery artefact has nothing to adjudicate, and blocking there deadlocks initialisation, since
  355. the engine cannot act yet authoring the constraints is itself an action. A gate that blocks where
  356. nothing can be harmed protects nothing and trains operators to bypass it. Therefore:
  357. - No artefact under `.pdm/intents`, `.pdm/prompts`, `.pdm/epics`, `.pdm/features` or
  358. `.pdm/tests/prompts/results`: unauthored definitions WARN and the gate reports `PRE-DELIVERY
  359. PASS`, which is explicitly neither ethical clearance nor a pass for any delivery work.
  360. - Any such artefact present: unauthored definitions BLOCK.
  361. Delivery-work detection MUST be a deterministic file count; a model MUST NOT decide whether delivery
  362. work has begun. Authoring EC-01 to EC-08 is the FIRST required human action after initialisation.
  363. The initialisation output MUST state that EC-01 to EC-08 are active from the first message, that
  364. EC-07 prohibits unlawful or foreseeably seriously harmful use, cannot be waived by any operator
  365. instruction, prompt or artefact, and is assessed on assembled intent rather than the wording of a
  366. single message, and that constraints whose `detection` is `human` are `UNVERIFIED` until a named
  367. human reviews them, so initialisation confers no ethical clearance whatsoever.
  368. ## Post-initialisation Obligations
  369. Initialisation produces an empty, governed workspace, not a validated one. The engine MUST report
  370. that no delivery work has been validated, that cost control runs `model-self-report` / `unverified`
  371. until a provider usage source is configured, that the release checklist is unticked, and that no
  372. ethics constraint has been human-reviewed. Bootstrap success evidences engine completeness only,
  373. never product correctness and never ethical acceptability.
  374. It MUST report the `Gate Falsifiability Self-Test` result gate by gate, and MUST NOT describe the
  375. engine as initialised, ready, complete or operational if any gate failed it or the self-test was not
  376. run. "The files were created" reports file creation, not engine completeness, and the difference
  377. between the two is the entire control surface (P3).
  378. It MUST also report that EC-01 to EC-08 are unauthored, that the ethics gate is in its pre-delivery
  379. warning posture, and that creating any delivery artefact before a named human authors those
  380. definitions will block the gate. This is the obligation most likely to be deferred, because an
  381. initialised workspace looks ready.

Back to home

Comments

Sign in to add and view your comments and replies.