Product architecture | source-grounded notes

Architecture Notes

Reader-facing product architecture for the AI Capability Playbook workstream. These notes shape sequencing and source-grounded assistant boundaries, but they do not approve runtime behavior or production use.

AI Capability Playbook Playbook Home Playbook Map Shared Foundations AI Capability Discipline Assistant Architecture Notes

Navigation Posture

Architecture Notes are user-facing source and backlog documentation for the AI Capability Playbook workstream. The primary navigation points to this HTML index rather than raw Markdown. Source notes remain linked for maintainers and grounding, but this page is the reader route.

These notes do not create runtime behavior, backend services, GUI work, provider execution, connector ingestion, repo migration, generated artifact redesign, policy approval, or production approval.

Backlog Governance

Triage

Backlog Triage And Delivery Sequence

Planning-only repo governance artifact that classifies the open issue backlog, recommends the next sequence, and identifies candidate closure, deferred, and owner-decision issues. It is not approved package authority, policy, product doctrine, runtime behavior, source approval, implementation authorization, or issue closure evidence.

Label hygiene

Backlog Label Hygiene

Planning-only repo governance artifact that records existing-label-only additive issue-label hygiene, skipped ambiguous decisions, taxonomy gaps, and PR-label hygiene boundaries. Labels do not imply implementation approval, package authority, issue closure, or replacement of owner decisions.

Workflow

Backlog Triage Dependency Supersession Workflow

Tool-agnostic repo operating-model workflow that defines the Backlog Triage Agent role, issue completeness, label taxonomy discipline, duplicate, dependency, supersession, and stale checks, classification, close semantics, and approval gates without mutating issues or runtime state.

Label enforcement

Backlog Label Enforcement And Codex Ticket Compliance

Hardens repo mechanics after the #350 missing-label-at-creation defect by requiring exact Required Labels sections, child issue labels at creation or immediate repair before implementation and PR creation, PR closeout label-state reporting, deterministic fixtures, no-new-label discipline, and validation without live GitHub calls.

Backlog audit

Full Closed Backlog Reality Audit

Audits the complete closed issue backlog against linked PR evidence, labels, follow-up tracking, OKF, Google SDLC, multi-agent orchestration, and Source Registry Admin Layer reality without reopening, closing, or mutating issues. The governance rule also blocks assumption-based execution when owner intent or close semantics are unclear and requires post-closeout next-action output instead of acknowledgement-only responses.

Backlog delta

Closed Backlog Audit Coverage Delta

Preserves the #304 audit baseline, matrix high-water mark, post-audit closed issue delta, full re-audit decision, future delta rule, and recurrence-prevention control so later backlog-governance work can avoid repeating full historical review by default.

Decision ledger

Audit Recommendation Follow-Up Ledger

Groups #304 audit recommendations, #306 delta controls, and #308 ticket-first controls into priority bands, owner-review states, suggested child issue titles, and hard boundaries so the owner can choose the next executable lane without starting implementation work.

Owner review

Owner-Review Disposition Packet

Converts the 22 ambiguous closed-backlog owner-review items from #304 for #312 into owner-clarification prompts, candidate disposition states, counts, next owner-decision options, recurrence-prevention control, and hard boundaries without reopening, relabeling, creating child issues, mutating source registries, changing runtime behavior, or changing package authority.

Owner decision

Owner-Review Disposition Decision Record

Records the owner-approved baseline for the 22 ambiguous closed-backlog items from #312 after PR #384: keep closed 12, covered by open parent or meta issue 9, defer #254 metadata cleanup into a later broader label-hygiene pass, reopen 0, child issue creation 0, relabeling 0, and explanatory comments 0, with no metadata execution, runtime change, source-registry mutation, or package-authority change.

Recalibration

Assistant Enrichment Lane Backlog Triage Recalibration

Reviews the open assistant, corpus, provider-boundary, session-source, and governed-corpus-runtime backlog against all-state grounded-assistant issues, closed-issue audit evidence, and later proof receipts. It recommends #196 next, #187 second, and #176 residual-scope review third without mutating runtime behavior, source registries, issue metadata, Cloudflare, provider configuration, #269, #271, or codex-automerge.

Residual scope

Source-Grounded Assistant Corpus UX Residual-Scope Review

Reviews #176 after #196, #187, and #389, records what is already satisfied, identifies the smallest safe next slice as corpus coverage inventory plus generator-only minimal additions for already-approved human-readable package sources if gaps are proven, keeps provider-backed smoke optional or deferred when credentials and protected environment access are unavailable, and preserves runtime, provider, Cloudflare, upload, source registry, source-set, package authority, issue mutation, worker-loop, #269/#271, and codex-automerge boundaries.

Corpus inventory

Source-Grounded Assistant Corpus Coverage Inventory

Implements the #176 owner-narrowed corpus coverage slice by measuring assistant-corpus source-family coverage, citation identity, source paths, line spans, reader targets, default-answer versus evidence-admin roles, and package metadata posture. It records no additional generator-only package source additions were needed and preserves runtime, provider, Cloudflare, upload, source-registry, approved-source-set, package-authority, #269/#271, and codex-automerge boundaries.

Disposition review

Source-Grounded Assistant Stale Issue Disposition Review

Reviews older open source-grounded assistant and proof issues after #176 closed and PR #395 landed, recording owner disposition recommendations for #153, #156, #159, #78, #165, #167, #169, #172, and #182. It identifies contract/design and proof/smoke bundle candidates, keeps #182 separate for owner clarification, records no automatically authorized next implementation lane, and preserves issue-mutation, runtime, provider, Cloudflare, upload, source, package-authority, loop, #269/#271, and codex-automerge boundaries.

Access posture

Ghostmesh Access Posture Decision

Evaluates split/public, full-site protected, and hybrid access postures for ghostmesh.ai. It recommends a hybrid posture that keeps public approved package and corpus surfaces inspectable, keeps proof/API and future private lanes protected, and routes implementation to #182 for route inventory, public/private navigation, Access-protected route set, redirects, fallback-domain behavior, validation, and smoke receipts without changing Cloudflare configuration or runtime behavior.

Route protection

Proof API Route Protection Readiness

Implements the repo-local #182 readiness packet for the #188 hybrid Ghostmesh posture, including route inventory, public and protected surfaces, navigation split, protected proof/API route set, redirects, fallback domains, Cloudflare Access status, rate-limit posture, smoke expectations, validation coverage, and residual risks without changing Cloudflare configuration or runtime behavior.

Source lanes

Protected Package Current Context Source Lane Scaffold

Records the #400 protected Package plus current context source-lane scaffold for the source-grounded assistant proof surface, including package-only default behavior, explicit protected mode, package versus current/public citation classes, lane-separated synthesis, current/public enrichment-only posture, server-side provider boundary, refusal preservation, validation coverage, and no Cloudflare, provider/model, source-registry, durable retrieval, upload/session-source, package-authority, or issue-boundary changes.

Request model

Run-Scoped Enrichment Source Selection

Defines the #413 request-side model for explicit package-only versus package plus enrichment requests, selected profile visibility, registry-backed selected and excluded source IDs, session-source separation, deterministic refusals, and validation boundaries without adding UX, source fetching, provider/model changes, durable memory, registry mutation, source-set mutation, package-authority mutation, #78 mutation, #271 reopening, or codex-automerge.

Backend routing

Backend Managed Enrichment Routing

Defines the #431 backend-managed enrichment routing contract by assistant mode, selected profile, eligible source packs, source eligibility rules, server allowlist aliases, telemetry, and fail-closed behavior while preserving package authority, registry immutability, browser and provider boundaries, #78, #271, #428, #432, and codex-automerge boundaries.

Answer evidence

Mode Profile Enrichment Answer Evidence

Proves #432 with deterministic fixtures showing backend-managed mode/profile enrichment changes cited final answer evidence when eligible enrichment evidence exists, while package-only behavior still works, unsupported and insufficient evidence refuses or qualifies, selected/routed metadata alone is not evidence, package and current/public citation classes remain separate, and package authority, registry, provider/model, Cloudflare, #78, #271, #428, #433, and codex-automerge boundaries remain intact.

Governance model

Enrichment Source UX And Governance

Documents the #418 enrichment-source UX and governance model across package authority, approved enrichment registry, run-scoped source selection, session-only pasted source text, source-pack defaults, vendor/provider authority limits, licensed and draft gates, forbidden behavior, validator coverage, and operator handoff boundaries without changing runtime behavior, UI behavior, source registry content, package authority, source sets, #78, #271, #419, or codex-automerge.

Candidate review

Enrichment Source Expansion Review

Defines the #419 non-implementation candidate-review and backlog-control model for future enrichment-source expansion, including generic candidate classes, required review fields, lifecycle statuses, source-pack alignment, vendor/provider boundaries, licensed and draft-source gates, forbidden behavior, validation expectations, and future child-issue rules without adding candidate entries, registry mutation, source fetching, runtime behavior, package authority, source-set changes, #78, #271, or codex-automerge.

Verification harness

SourceMesh Verification Harness

Defines the #54 operator verification harness for normalized transcripts, practitioner videos, podcasts, articles, repos, and vendor-promoted material, including claim classification, verification status, sponsor and commercial incentive split, safe and unsafe reuse, pattern routing, stop conditions, and non-inference rules without adding arbitrary web search, browser-side fetching, provider calls, source registry mutation, package authority mutation, Cloudflare changes, production approval, vendor approval, model approval, tool approval, or codex-automerge.

Architecture

Governed Corpus Runtime And Context-As-Code

Codifies the governed corpus runtime pattern and context-as-code storage model across canonical source, generated artifacts, assistant packages, runtime telemetry boundaries, optional future data stores, scaling thresholds, and Copilot Studio/front-door posture without implementing runtime behavior, uploads, Package + current context mode, telemetry routing, databases, retrieval indexes, Cloudflare changes, source registry mutation, package-authority changes, #269, #271, or codex-automerge.

Session source design

Session-Scoped File Upload Sources

Defines uploaded files and pasted text as user-provided session sources for source-grounded assistant review use cases, with separate uploaded/session citations, privacy and retention boundaries, token/cost accounting, validation and refusal behavior, and no durable ingestion, runtime upload behavior, database, vector store, source-set mutation, or package-authority change.

Clarification

Source Registry Admin Parent Meta Closure Clarification

Records live #269 closed state and #271 open state, identifies repo-local Source Registry Admin parent/meta ambiguity, and presents owner decision options A through E without reopening #269, starting #271, creating continuation issues, relabeling, or changing runtime or source-registry behavior.

Requirements

Source Registry Admin Product Requirements

Defines Source Registry Admin as governed source lifecycle administration for enrichment lanes, including add/register source approval, lifecycle states, source record fields, admin actions, citation behavior, extraction-profile dependency, and guardrails while keeping #269 closed and #271 open and separate.

Command contract

Source Registry Admin Command Contract

Defines the first Source Registry Admin command-surface design slice for administrative actions, inputs, outputs, refusals, receipts, lifecycle transitions, environment behavior, authority-lane behavior, and validation boundaries without implementing commands or mutating source registries.

Validation

Source Registry Admin Schema Lifecycle Validation

Defines repo-local Source Registry Admin source-record schema and lifecycle-state validation for required fields, allowed and forbidden transitions, environment eligibility, authority-lane constraints, refusal behavior, fixtures, and audit-history expectations without implementing live commands or mutating source registries.

Dry-run parser

Source Registry Admin Dry-Run Command Parser

Defines a repo-local dry-run command parser for Source Registry Admin command recognition, bounded deep validation, refusal output, receipt-preview output, and fixture-backed checks without implementing live commands or mutating source registries or source sets.

Receipt schema

Source Registry Admin Dry-Run Receipt Schema

Defines formal schema enforcement for dry-run receipt-preview output, including mutating command posture, non-mutating reduced posture, refusal receipt posture, fixtures, invariants, and validator coverage without implementing live commands or mutating source registries or source sets.

Snapshot model

Source Registry Admin Dry-Run Registry Snapshot Model

Defines dry-run registry snapshot and last-known-good posture for rollback, emergency-disable, promotion, and receipt-preview evidence without implementing live snapshot creation or mutating source registries or source sets.

Workflow

Source Registry Admin Dry-Run Add Validate Workflow

Defines dry-run add_source plus validate_source workflow depth for accepted and refused workflow output, command sequence posture, receipt previews, snapshot/LKG posture, fixtures, and boundary confirmations without implementing live admin commands or mutating source registries or source sets.

Workflow

Source Registry Admin Dry-Run Preview Enable Disable Workflow

Defines dry-run Preview enable and Preview disable workflow depth for accepted and refused workflow output, intended Preview source-set deltas, receipt previews, snapshot/LKG posture, fixtures, and boundary confirmations without implementing live admin commands or mutating source registries or source sets.

Workflow

Source Registry Admin Dry-Run Production Promote Emergency Disable Workflow

Defines dry-run Production promote and emergency-disable workflow depth for accepted and refused workflow output, intended Production and emergency disable deltas, receipt previews, snapshot/LKG posture, fixtures, and boundary confirmations without implementing live admin commands or mutating source registries or source sets.

Architecture

OKF Bundle And Derived Retrieval Index

Defines the Git-first OKF-compatible bundle decision, context-pack projection relationship, Cloudflare near-term runtime projection, Supabase longer-term relational knowledge projection, optional MCP layer, authority-lane enforcement, citation and chunk model, rebuild, rollback, and sequencing impact for registry and extraction-profile work.

Orchestration

Queue-Backed Multi-Agent Work Engine Evaluation

Evaluates queue-backed multi-agent work, prompt mode versus work mode, GitHub Issues and PRs as the near-term state substrate, candidate states, transition evidence, lock and lease semantics, structured work-item payloads, queue substrate options, OKF and MCP future interactions, and human approval gates without implementing workers, loops, external trackers, custom databases, runtime changes, or MCP behavior.

Orchestration

GitHub Issues Agent Work Engine MVP

Defines the repo-local GitHub Issues queue-backed agent work engine MVP with work states, transition rules, payload schema, parallelism classification, claim locks, lease recovery, planner lanes, deterministic fixtures, validation, and closeout proof while avoiding autonomous loops, external queue providers, MCP behavior, source mutation, Cloudflare changes, runtime retrieval changes, and package-authority changes.

Orchestration

GitHub Issues Queue Planner

Defines the read-only queue planner and parallelism report that consumes deterministic repo-local work-item fixtures and emits JSON or Markdown lanes for serial work, safe parallel work, blocked work, owner decisions, high-risk gates, lock conflicts, stale locks, invalid items, validation requirements, and closeout requirements without live GitHub mutation, autonomous execution, external queue providers, source mutation, runtime changes, or package-authority changes.

Orchestration

GitHub Issues Work Payload Template

Defines the repo-local GitHub issue-body work payload template for planner-readable metadata, including objective, dependencies, required labels, execution surface, risk class, parallelism class, allowed files, forbidden zones, validation, closeout, approval gates, lock and lease expectations, retry, rollback, non-mutation boundaries, close semantics, and post-closeout next action classification without live export, live parsing, GitHub mutation, autonomous execution, external queue providers, source mutation, runtime changes, or package-authority changes.

Orchestration

GitHub Issues Read-Only Export Fixture

Defines the repo-local read-only GitHub issue export fixture that converts issue-body work payload records into deterministic planner-readable data, preserves source issue metadata, flags malformed or incomplete payloads, and keeps live GitHub inspection explicit and read-only without GitHub mutation, planner-triggered execution, autonomous loops, external queue providers, source mutation, runtime changes, or package-authority changes.

Orchestration

GitHub Issues Exported Planner Report

Defines the deterministic exported-issue planner integration report that consumes the committed exported fixture, maps normalized exported records into read-only planner lanes, preserves rejected payloads before planning, and carries source metadata, validation, closeout, and non-mutation confirmations forward without live GitHub calls, GitHub mutation, planner-triggered execution, autonomous loops, external queue providers, source mutation, runtime changes, or package-authority changes.

Orchestration

Human-Mediated Orchestration Lane Operating Packet

Defines the human-mediated operating packet for interpreting planner lanes, handling serial, safe-parallel, blocked, owner-decision, high-risk gated, and rejected-before-planning work, preventing duplicate work and branch/file collisions, using claim and lease evidence manually, documenting owner decisions, preserving closeout receipts, and keeping planner output from triggering implementation or autonomous worker behavior.

Orchestration

Human-Mediated Orchestration Dry-Run Receipt

Defines the deterministic dry-run receipt proof for the human-mediated lane operating packet, covering safe-parallel, serial, blocked, owner-decision, high-risk gated, rejected-before-planning, duplicate/collision, and stale or missing claim evidence outcomes without starting work, creating child issues or branches from planner output, mutating GitHub, adding autonomous execution, changing source sets, Cloudflare, runtime retrieval, or package authority.

Orchestration

Orchestration Architecture Index

Maps the seven landed orchestration layers from the GitHub Issues queue-backed model through the human-mediated dry-run receipt, explains the issue payload to child-ticket-or-stop flow, and records proven, not-proven, future-gated, evidence, receipt, and forbidden-scope boundaries without adding autonomous execution, live GitHub mutation, worker loops, source mutation, Cloudflare mutation, runtime mutation, or package-authority changes.

Orchestration

Controlled Worker Design Packet

Defines the design-only boundary for any possible future controlled worker, including identity, least-privilege permissions, allowed read-only planning posture, prohibited behavior, claim and lease stop conditions, owner gates, validation, rollback, closeout receipts, and relationship to the landed orchestration stack without implementing a worker, worker loop, polling, scheduled or webhook-triggered execution, external queues, GitHub mutation, source mutation, Cloudflare mutation, runtime mutation, or package-authority changes.

Orchestration

Parallel Codex Lane Dry-Run Packet

Defines the design-only dry-run packet for manually launching multiple Codex chats from safe-parallel planner output, including child-ticket separation, branch separation, duplicate and collision prevention, claim and lease evidence, stop handling, validation per lane, merge sequencing, cross-lane conflict detection, closeout receipts, and the Tony plus Codex control plane without implementing autonomous execution, worker loops, polling, scheduled or webhook-triggered execution, external queues, GitHub mutation, source mutation, Cloudflare mutation, runtime mutation, or package-authority changes.

Orchestration

Codex Lane Handoff Packet Template

Defines the no-manual-step handoff template Tony gives Codex after a human-mediated serial or safe-parallel lane decision, requiring Codex-owned local sync and repo hygiene, remote baseline, work issue, branch, commit message, hard boundaries, validation and local-server bind fallback handling, draft PR only behavior, no-automerge behavior, closeout receipts, stop gates, and next-turn collateral without implementing autonomous execution, worker loops, polling, scheduled or webhook-triggered execution, external queues, GitHub mutation, source mutation, Cloudflare mutation, runtime mutation, or package-authority changes.

Orchestration

Codex Handoff Dry-Run Receipt

Defines the manual deterministic receipt proving the Codex lane handoff packet template can produce serial-lane and safe-parallel-lane handoff collateral with remote baseline, repo path, work issue, branch, commit message, Codex-owned sync, stop conditions, validation expectations, draft PR only behavior, no-automerge behavior, and closeout receipts without asking Tony to run local commands or implementing autonomous execution, worker loops, polling, scheduled or webhook-triggered execution, external queues, GitHub mutation, source mutation, Cloudflare mutation, runtime mutation, or package-authority changes.

Orchestration

Codex Orchestration Operator Quickstart

Defines the manual operator quickstart for Tony plus Codex, mapping draft PR closeout, merged PR closeout, stale local main, failed sync, dirty worktree, residue, issue-state stops, owner-decision, blocked, high-risk gated, rejected-before-planning, serial handoff, and safe-parallel handoff states to next actions, Codex-owned repo mechanics, Tony decision evidence, handoff collateral, and closeout receipt fields without implementing autonomous execution, worker loops, polling, scheduled or webhook-triggered execution, external queues, GitHub mutation, source mutation, Cloudflare mutation, runtime mutation, or package-authority changes.

Orchestration

Codex Orchestration Operator Quickstart Dry-Run Receipt

Defines the manual deterministic receipt proving the Codex orchestration operator quickstart maps draft PR closeout, merged PR closeout, stale local main, failed sync, dirty worktree, residue, issue-state stops, owner-decision, blocked, high-risk gated, rejected-before-planning, serial handoff, and safe-parallel handoff states to safe human-mediated next actions while keeping Tony out of local command execution, preserving Codex-owned sync, draft PR only behavior, no-automerge behavior, complete closeout receipts, and non-autonomous boundaries without implementing worker loops, webhook or scheduled execution, external queues, GitHub mutation, source mutation, Cloudflare mutation, runtime mutation, or package-authority changes.

Prompt pattern

Mainline Dense Infographic Prompt Pattern

Defines the preferred future pattern for repo-aligned dense technical explainer infographic prompts, preserving a white or near-white background, black and deep-red title treatment, red gray black hierarchy, technical architecture layout, governance callouts, reusable prompt skeleton, hardening/risk section, lifecycle/process section, recommended implementation path, bottom verdict banner, and optional good-instincts vs hardening-needs panel while rejecting teal/navy/purple primary palettes, colorful gradients, SaaS marketing look, cyberpunk/neon/cartoon/glossy 3D styling, runtime mutation, source mutation, Cloudflare mutation, provider/runtime/browser/package-authority mutation, autonomous worker behavior, webhook/scheduled/polling/external queue behavior, #269/#271 reopening, or codex-automerge.

Operating model

Tool-Agnostic Invariant-Driven Agent Operating Model

Defines Planner, Executor, Auditor, Documentation Maintainer, Lessons-Learned Mechanic, Backlog Triage Agent relationship, Exploration, Execution, Audit modes, execution-surface classification, repo-local executor routing, anti-manual-toil, ticket-first response, post-closeout next-action output, no-assumption owner clarification, and the rule that Tony must not be the execution engine.

Propagation

Artifact Consistency Audit And Propagation Workflow

Tool-agnostic repo operating-model workflow that defines the Artifact Consistency Auditor role, controlled artifact classes, audit triggers, contradiction, gap, stale guidance, missing propagation, implementation-reality checks, severity, routing, approval gates, and repeatable propagation checklist.

Source-Grounded Assistant Sequence

Contract

Source-Grounded Assistant Prototype

Defines the approved package-only assistant contract, citation schema, refusal behavior, and non-runtime boundaries.

Modes

Source-Grounded Semantic Explainer

Frames Find, Explain, and Assess behavior over approved package sources and keeps model memory out of source authority.

Session sources

Session-Scoped File Upload And Paste Sources

Defines future upload and paste-source behavior as session-only user evidence that must be cited separately from approved package sources and cannot override grounding rules, become approved corpus, or create durable ingestion.

Registry governance

Current Source Registry Governance

Defines owner-approved current/public source registry governance, deterministic enrichment-source registry v01, production enablement checks, Access-authenticated Production runtime smoke gating, smoke tests, rollback, candidate-only registry evidence, expanded source review, expanded source catalog, the first substantive current-source extraction-profile slice, the #271 closure-readiness audit, the first non-NIST staged enablement plan, Source Registry Admin Layer specification, read-only admin inspection, receipt generation, Preview dry-run planning, command-contract design, schema/lifecycle validation, and dry-run receipt-preview schema enforcement through scripts/source_registry_admin_inspection.py and focused validators, SSDF-only PR-preparation authorization, source-specific draft authorizations, curated enrichment direction, the review-only NIST plan, and owner authorization records.

Routing telemetry

Runtime Model Routing And Tokenomics Telemetry

Defines model routing, safe tokenomics metadata, inference-use policy, and durable telemetry prerequisites without enabling retrieval, uploads, or storage.

Assessment

Proposal Assessment Path

Names proposal review dimensions, finding classes, and the distinction between guidance and approval.

External proof

Static Site Chat Proxy Requirements

Records the server-side proxy requirement, source-grounding posture, security boundaries, and deferred persistence scope.

Deployment And Operating Notes

Internal path

Microsoft-Native Internal Pilot

Separates the reader site, grounding corpus, and interpretation layer for an internal pilot path.

API path

External API Reference Implementation

Defines the reference adapter boundary without approving any provider, model, workflow, or production use.

Routing

Workload Model Routing Discipline

Preserves swappable model and provider posture while keeping deterministic checks and token evidence visible.

Product boundary

Playbook Product Architecture

Records the governed package boundary and the relationship between the reader surface, corpus, assistant, and proof environment.

Reader Boundary

The polished route is this HTML page. Markdown files remain source notes and context-pack material. #216 adds a gated runtime proof for Package + current context mode. #219 adds controlled current/public retrieval only behind explicit server-side configuration. #221 defines owner-approved current-source registry governance before any production retrieval can be enabled. #223 records candidate-only current/public source review evidence without enabling production retrieval. #225 prepares a review-only NIST AI RMF single-source enablement plan without changing production retrieval. #227 records owner authorization for the later single-source NIST production current-context test while keeping retrieval disabled. #235 captures curated enrichment, divergence, human-approved update candidates, source-watch loops, and future admin-source-management direction without changing runtime behavior or source enablement. #244 defines the expanded current/public source catalog and approval matrix while keeping every new source candidate-only and retrieval disabled. #269 defines the future Source Registry Admin Layer as architecture/specification only, with command contracts, guardrails, receipts, rollback, emergency disable, smoke orchestration, and child implementation slices but no admin CLI implementation or source-set mutation. #327 documents the first substantive NIST AI RMF current-source extraction-profile slice as architecture and validation evidence while keeping #271 open. #347 adds a deterministic NIST evidence-lane smoke demo for the existing Preview source-grounded proof UI without mutating registries, source sets, Cloudflare configuration, provider/model configuration, runtime retrieval semantics, or package authority. #285 keeps Git canonical, models OKF-compatible bundles as a portable semantic layer, treats database/vector indexes as derived projections, keeps Cloudflare as the near-term GhostMesh runtime path, and routes Supabase/Postgres toward longer-term Open Brain / SourceMesh / ArtifactPlane relational knowledge. The first non-NIST current/public source enablement plan authorizes SSDF-only PR preparation for NIST SSDF SP 800-218 final v1.1 while keeping OWASP GenAI 2025 Top 10 and exact-path CISA / NSA / NCSC secure AI guidance candidate-only and draft-only until later owner authorization. #189 defines runtime routing and safe tokenomics telemetry metadata without adding #187 uploads, #188 whole-site Access, billing integration, or durable telemetry/database storage. #274 defines repo-owned agent operating rules so local Git, validation, sync, cleanup, generated artifact, draft-to-ready, and closeout proof work routes to a repo-local executor instead of making Tony the execution engine.