Proof path visual
One compact visual map of the supplied requirement-to-decision flow. It explains the current state; it never executes a graph action.
Factory Studio / Graph Ops
A bounded control plane for Product, Mission, Proof, Gate, Trace, semantic lineage, and verified counterfactual repair. Follow the failure, compare every candidate, and understand the winning proof without executing it.
Connecting to the local workspace.
Current stage, elapsed time, completed stages, and measured telemetry will appear here. Unknown token, cost, and productivity values stay unknown.
Humans decide intent and final approval. Agents receive the same sealed, local evidence but cannot alter the contract, threshold, scope, repair decision, Git state, or release. Unknowns stay visible instead of being inferred away.
This panel is read-only. It never turns a green card into approval or a connected agent into an authorized actor.
See what changed, why it affects evidence, the smallest next step, and who local Git history observed on the selected work. It is explanatory and read-only: it does not run a proof, recall memory bodies, or authorize a person.
Loading bounded local Git history.
Brief refreshes no more than once every five seconds. Live assembly telemetry refreshes separately.
Current, stale, and invalid proof reviews stay separate. This queue never infers productivity and never approves work.
Build the monetization lane, replay the observed lifecycle, challenge every failure path, and invalidate only conclusions touched by policy drift.
Trace an observed OAuth/OIDC identity through tenant authorization, checkout, verified webhook, entitlement, feature access, and revocation. Clerk, Auth0, Okta, Entra, Cognito, Supabase, Firebase, and other compliant providers use the same evidence contract.
Start with one plain-English mission and one exact build. AppForge binds user design input, strict UI and accessibility evidence, SaaS reality, policy applicability, and current-build media without placing secrets in Code Factory. A supervised agent may prepare the packet; only a named human can authorize the final Apple handoff.
Locked: App Review, Store media, SaaS lifecycle, and strict quality-audit receipts must match the same candidate before AppForge issues the final Markdown/PDF dossier. A separate named, expiring human authorization is still required for any Apple handoff. This page never receives raw credentials or silently submits an app.
Freeze the exact original request before coding. Only human-confirmed or trusted-source rules can release work. A separate challenge lane targets the implementation and boundary cases; it cannot edit the contract, production code, or a test.
E_ORACLE_WEAKENING, pauses autonomous work, and opens a demotion incident.Locked: this screen reads local proof. It cannot approve a successor contract, raise autonomy, modify a test, run a challenge, or contact a provider. Use a separate named human approval to seal a successor.
Import a compact workflow export to inspect its typed stage DAG, capability-scoped handoffs, source-precondition hashes, and checkpoint continuity against the sealed intent contract. This display never starts Atomic, resumes a checkpoint, or turns a declared workflow into authority.
Locked: Graph Ops only reads hash-valid local receipt facts. A declared worktree, container, VM, or remote host is not proof of a sandbox. Inspect the exact Oracle Contract and receipt before authorizing separate work.
Inspect a compact Eve, Junie, Grok Build, or generic export against the exact sealed intent. Code Factory binds the declared workflow, original source preconditions, and real local before/after artifacts. It never starts, resumes, approves, or deploys an agent run.
Locked: a provider export is not provider identity, sandbox, checkpoint, deployment, or agent-quality proof. It must remain tied to a current Oracle Contract and actual local evidence artifacts; a separate human still controls every real action.
Bind the base revision, branch isolation, failed reproduction, change budget, evidence tier, architecture zones, and local repository heads. A receipt says what was checked; it does not create a worktree, run a repair, or approve a merge.
Locked: operations controls observe local preconditions only. They do not execute a task, allocate a sandbox, invoke a model, create an approval, or change Git state.
Each recorded stage names the declared harness and session, binds input and output hashes to a sealed Oracle Contract, and points to the prior receipt. Session traces are local, hash-linked evidence—not identity, execution, or release authority.
Locked: this is an inspection-only trace. It cannot resume a session, contact a provider, alter intent, grant an agent permission, or mark work approved.
Turn a real failure into a bounded packet: affected obligation, explicit potential consequences, observed reproduction, candidate hash, positive and negative independent re-checks, and a named human reviewer. The loop cannot self-approve or keep guessing after evidence breaks.
Locked: a packet is a review artifact, not a repair command. Any scope, oracle, evidence, or independent-check gap remains blocked.
Human-controlled mode only verifies a prepared repair. Supervised-auto mode permits one bounded local agent command, then independently audits its identity, command, workspace delta, scope, positive proof, and negative mutation. Neither mode grants final approval.
Final approval is always withheld. Run the copied manifest through factory journey heal-verify in a separately reviewed terminal.
Inspect imported TestSprite-shaped or other provider evidence beside local proof. This view separates observed facts from hypotheses and keeps every execution, repair, merge, and release control locked.
Inspect the first failed step and hypothesis before admitting a bounded local proof. No automatic repair is available.
review_external_runtime_failureThis is a local, read-only projection of the newest Forge ship receipt. It shows the intent hash and obligation result without treating a receipt as execution or approval authority.
Nodes
—Edges
—Evidenced
—Lineage runs
—Forensic findings
—Repair candidates
—Graph status
LoadingOne compact visual map of the supplied requirement-to-decision flow. It explains the current state; it never executes a graph action.
Deterministic ratios from this bounded graph result, not estimated productivity or a quality score.
See the structural critical path, safe parallel waves, shared-proof candidates, and blocker chains before selecting a separate, approved harness.
Blocks propagate visibly; every runnable item still requires independent verification.
These are proposal-only groups. They do not start work or authorize proof reuse.
No sealed admission packet has been projected from this workspace.
Locked: export and re-verify a time-bounded packet with a separate harness. Graph Ops cannot execute a wave, approve, repair, merge, publish, deploy, sign, message, access credentials, or grant a connector.
Every candidate is hash-bound, scope-checked, independently proven, mutation-tested, and ranked by one deterministic ordering.
No evaluation loaded.
Inspect, export, and validate the decision here. Applying code, merging, publishing, and deploying require separate authority.
Locked: ProofSearch has no workspace-mutation, approval, merge, publication, or deployment authority.
Rank supplied, non-executing experiments by exactly how many viable repair pairs they separate. Predictions are hypotheses, never proof or execution authority.
No sealed Evidence Frontier loaded.
Copy, export, and validate the plan. A separate approved runner is required before any experiment may run.
Locked: Graph Ops ranks evidence only; it cannot execute a command, mutate a workspace, or grant approval.
Only independently promoted, exact-scope, purpose-bound, non-expired references can influence a future decision. This panel redacts memory references and summaries by design.
No local continuity records loaded.
Graph Ops can inspect local metadata. It cannot store memory content, promote a lesson, sign evidence, or grant an agent access to a record.
Locked: promotion requires a separate identity, exact purpose, evidence references, and an explicit local CLI action.
Judgment Capsules preserve a scoped engineering decision with an owner, review date, and hash-bound proof obligations. Proposals are not active until an independent human promotes them.
No tracked Judgment Capsules were projected.
Use this board to inspect local decision metadata. A Change Safety Case routes a scoped diff to the named owner only when its proof obligations are bound and verified. Add a human-declared Change Profile to make novelty and attention explicit—this UI never guesses from source code.
Locked: this UI cannot infer intent, promote or waive a decision, execute a repair, approve code, merge, publish, deploy, sign, message, or access credentials.
Each declared agent earns a local, expiring tier from governed run evidence. A severe hollow-test, hollow-validator, or scope-escape result demotes it automatically. Identity remains declared unless an external harness proves it.
No governed agent evidence has been projected.
Inspect and verify local evidence here. This screen cannot issue a license, raise autonomy, start a candidate, or grant execution authority.
Locked: licenses are derived from independently verified governed events. Use the explicit local CLI after recording evidence; Graph Ops does not promote an agent.
Compare sealed state lineage, isolate the first semantic divergence, and preview the smallest recovery branch.
No deterministic concurrency or state anomalies detected.
Prepare and validate the recovery locally. Workspace mutation stays locked until a separate signed approval is supplied.
Locked: no named, expiring, signed approval is bound. Graph Ops cannot grant one.
Loading the authenticated local graph result.
Graph data is read from /api/graph-ops. A separate token-bound local request can record one named authorization or consume one Reality Check authorization. Labels are rendered as text nodes.