Factory Studio / Graph Ops

Follow the proof path.

A bounded control plane for Product, Mission, Proof, Gate, Trace, semantic lineage, and verified counterfactual repair. Follow the failure, compare every candidate, and understand the winning proof without executing it.

Read-only inspection. Graph Ops cannot execute, approve, publish, deploy, sign, message, access credentials, or grant connectors until a named person creates a narrowly scoped, expiring local authorization. WebMCP is a progressive enhancement; checking browser support.

Live Factory telemetry

Connecting to the local workspace.

Loading

Current stage, elapsed time, completed stages, and measured telemetry will appear here. Unknown token, cost, and productivity values stay unknown.

Mission Control · shared authority map

One truth for people and connected agents.

Humans decide intent and final approval. Agents receive the same sealed, local evidence but cannot alter the contract, threshold, scope, repair decision, Git state, or release. Unknowns stay visible instead of being inferred away.

Loading
Human controlReview state loading
Agent controlSupervised protocol loading
IntentOracle evidence loading
RepairRepair evidence loading
DecisionNext action loading

This panel is read-only. It never turns a green card into approval or a connected agent into an authorized actor.

Memory Spine · proof-aware briefing

Turn the diff into the next safe proof.

See what changed, why it affects evidence, the smallest next step, and who local Git history observed on the selected work. It is explanatory and read-only: it does not run a proof, recall memory bodies, or authorize a person.

Loading local facts
1 · What changedLoading local change facts.
2 · Evidence stateLoading proof state.
3 · Do this nextLoading next action.
4 · Team contributionLoading local Git attribution.

Observed project contributors

Loading bounded local Git history.

Brief refreshes no more than once every five seconds. Live assembly telemetry refreshes separately.

Proof Review · team inbox

Review the riskiest item first.

Current, stale, and invalid proof reviews stay separate. This queue never infers productivity and never approves work.

Loading
Current0
Stale0
Invalid0
Learned regressions0
No current review itemCreate a proof review from a confirmed intent contract.
Revenue · evidence before action

See exactly where purchase reality diverges.

Build the monetization lane, replay the observed lifecycle, challenge every failure path, and invalidate only conclusions touched by policy drift.

No bundle
Build contractNo hash-bound bundle
Purchase replayNo build-bound replay
Failure matrixNo negative-path evidence
Policy watchNo source comparison
TestFlight inboxNo authorized local export
Human decisionUnknowns and mismatches block green; provider writes remain locked.
No generated bundle yet. App Store writes, pricing, offers, experiments, and publication remain locked.
SaaS Reality · provider neutral

Did login, payment, and permission agree?

Trace an observed OAuth/OIDC identity through tenant authorization, checkout, verified webhook, entitlement, feature access, and revocation. Clerk, Auth0, Okta, Entra, Cognito, Supabase, Firebase, and other compliant providers use the same evidence contract.

No receipt
IdentityIssuer, audience, active token, and PKCE contract
AuthorizationSubject, tenant, and role binding
EntitlementPromise, SKU, webhook, and access order
RevocationCancel, refund, and expiry must remove access
No hash-valid receipt. Unknown evidence stays blocked; no provider is contacted or mutated.
AppForge + SaaS · mission control

Improve your app before Apple finds the gap.

Start with one plain-English mission and one exact build. AppForge binds user design input, strict UI and accessibility evidence, SaaS reality, policy applicability, and current-build media without placing secrets in Code Factory. A supervised agent may prepare the packet; only a named human can authorize the final Apple handoff.

Init + 4 evidence lanes
1 · MissionWho the app serves and what they need to accomplish.
2 · TensionWhich design, policy, or runtime gap could delay review.
3 · GuidanceThe smallest exact evidence needed to resolve it.
4 · AgencyYou choose human-controlled or supervised preparation.
5 · TransformationUnknowns become verified facts or visible blockers.
6 · Ready handoffA sealed receipt and named approval unlock one exact next step.
Use a keychain item or environment-variable name. Raw keys and passwords are refused.
Your review pathConnect references
Classify every policy
Import current-build evidence
Resolve every blocker
Review what changed
Authorize one exact handoff

Locked: App Review, Store media, SaaS lifecycle, and strict quality-audit receipts must match the same candidate before AppForge issues the final Markdown/PDF dossier. A separate named, expiring human authorization is still required for any Apple handoff. This page never receives raw credentials or silently submits an app.

Oracle Firewall · Shadow Oracle Loop

Prove the gate is still honest.

Freeze the exact original request before coding. Only human-confirmed or trusted-source rules can release work. A separate challenge lane targets the implementation and boundary cases; it cannot edit the contract, production code, or a test.

No sealed contract
SourceNo immutable handoff
Approved obligationNo approved rule
Forbidden behaviorNo negative invariant
Gate + testNo independent challenge plan
Evidence → decisionHuman review remains required
0 current contractsAny threshold relaxation, removed negative case, new exception, or rewritten test emits E_ORACLE_WEAKENING, pauses autonomous work, and opens a demotion incident.

Locked: this screen reads local proof. It cannot approve a successor contract, raise autonomy, modify a test, run a challenge, or contact a provider. Use a separate named human approval to seal a successor.

Atomic mechanics · independent proof bridge

Keep the workflow, verify the handoff.

Import a compact workflow export to inspect its typed stage DAG, capability-scoped handoffs, source-precondition hashes, and checkpoint continuity against the sealed intent contract. This display never starts Atomic, resumes a checkpoint, or turns a declared workflow into authority.

No imported run
Sealed intentNo Oracle Contract binding
Typed DAGNo declared stages
Scoped handoffsNo capability evidence
Checkpoint continuityNo imported checkpoint
Human decisionImported evidence never grants execution or release authority.

Locked: Graph Ops only reads hash-valid local receipt facts. A declared worktree, container, VM, or remote host is not proof of a sandbox. Inspect the exact Oracle Contract and receipt before authorizing separate work.

Agent Proof Bridge · provider-neutral handoff

Bring the agent’s evidence, not its authority.

Inspect a compact Eve, Junie, Grok Build, or generic export against the exact sealed intent. Code Factory binds the declared workflow, original source preconditions, and real local before/after artifacts. It never starts, resumes, approves, or deploys an agent run.

No imported proof
Sealed intentNo Oracle Contract binding
Declared workflowNo provider-neutral DAG
Source preconditionsNo source-byte binding
Before/after proofNo local artifact pair
Human decisionEvidence remains read-only; authority stays outside the bridge.

Locked: a provider export is not provider identity, sandbox, checkpoint, deployment, or agent-quality proof. It must remain tied to a current Oracle Contract and actual local evidence artifacts; a separate human still controls every real action.

Operations Control · preconditions before work

Make the work envelope reviewable before an agent starts.

Bind the base revision, branch isolation, failed reproduction, change budget, evidence tier, architecture zones, and local repository heads. A receipt says what was checked; it does not create a worktree, run a repair, or approve a merge.

No envelope
IsolateNo verified base or branch
ReproduceNo failure budget receipt
ConstrainNo change envelope
ProveNo declared evidence tier
CoordinateNo local repository head binding

Locked: operations controls observe local preconditions only. They do not execute a task, allocate a sandbox, invoke a model, create an approval, or change Git state.

Session Trace · explicit continuity

Trace the handoff without trusting a story.

Each recorded stage names the declared harness and session, binds input and output hashes to a sealed Oracle Contract, and points to the prior receipt. Session traces are local, hash-linked evidence—not identity, execution, or release authority.

No trace
Sealed intentNo Oracle Contract binding
SessionNo declared harness session
StageNo hash-bound lifecycle stage
EvidenceNo local evidence hash
Human reviewNo review-required state

Locked: this is an inspection-only trace. It cannot resume a session, contact a provider, alter intent, grant an agent permission, or mark work approved.

Repair Loop · consequence-aware

Fix the exact fault, then challenge the fix.

Turn a real failure into a bounded packet: affected obligation, explicit potential consequences, observed reproduction, candidate hash, positive and negative independent re-checks, and a named human reviewer. The loop cannot self-approve or keep guessing after evidence breaks.

No packet
IssueNo exact failure
ConsequencesNo reviewed consequence
ReproduceNo bound failure evidence
ChallengeNo positive and negative re-check
Human decisionNo named review

Locked: a packet is a review artifact, not a repair command. Any scope, oracle, evidence, or independent-check gap remains blocked.

Journey Proof · repair supervision

Choose who may attempt the repair—not who may approve it.

Human-controlled mode only verifies a prepared repair. Supervised-auto mode permits one bounded local agent command, then independently audits its identity, command, workspace delta, scope, positive proof, and negative mutation. Neither mode grants final approval.

Loading receipts
0 verified receiptsNo Journey Proof receipts are loaded. The controls create an inert template only; they never start an agent or approve a repair.

Final approval is always withheld. Run the copied manifest through factory journey heal-verify in a separately reviewed terminal.

Forge receipt · intent trace

Did the shipped work honor the sealed intent?

This is a local, read-only projection of the newest Forge ship receipt. It shows the intent hash and obligation result without treating a receipt as execution or approval authority.

Loading traceability
Fail-closed boundary. No local Forge ship receipt has been projected; intent traceability is unverified.

Nodes

Edges

Evidenced

Lineage runs

Forensic findings

Repair candidates

Graph status

Loading

Proof path visual

One compact visual map of the supplied requirement-to-decision flow. It explains the current state; it never executes a graph action.

Local facts
Intent0 requirements
Verifier0 receipts
PolicyNo dossier
Human decisionReview required

Evidence health

Deterministic ratios from this bounded graph result, not estimated productivity or a quality score.

Loading
evidenced
Requirements
Policy drift
Blocked gates

Graph lanes

Loading the authenticated local graph result.

Graph data is read from /api/graph-ops. A separate token-bound local request can record one named authorization or consume one Reality Check authorization. Labels are rendered as text nodes.