# AWP Governance Amendment — 2026-08-21

**Date:** 2026-08-21
**Status:** **BINDING — owner-authorized amendment; supersedes the clauses it names**
**Authority:** Owner decision, recorded here as the single authoritative amendment record
**Scope:** governance only — no product/architecture direction changes, no ADR supersession
**Binding digest:** [`I0-I1-AUTHORITY.md`](I0-I1-AUTHORITY.md)
**Pain invariants:** [`AWP-PAIN-INVARIANTS.md`](AWP-PAIN-INVARIANTS.md)

## Why This Exists

An external review found that the corpus's own gates had deadlocked and were then silently bypassed:

```text
AWP-I0-I1-REUSE-PREFLIGHT.md
  forbids equivalent custom I0/I1 code until an exact Overdeck
  source/path/commit harvest is recorded

the authoring session had no access to that source
  -> the gate could never turn green from inside the corpus

implementation landed anyway (PRs #8-#16)
  -> nobody amended the gate
  -> "the specification is source of truth" became false in practice
```

A gate that cannot be satisfied and is then ignored is worse than no gate: it teaches every subsequent agent that the written rule is decorative. This amendment closes that gap by changing the rules to match reality under explicit owner authority, rather than leaving stale rules in place and continuing to work around them.

Three further defects are corrected in the same act: an unholdable binding-context volume, a corpus-generated visual rule the owner never asked for, and an I0 proof burden larger than the I0 build burden.

## A1 — Implementation Start Is Ratified Retroactively

The implementation work already landed on `main` (I0/I1 substrate under `packages/`, `apps/`, `tests/`, `infra/`) is **ratified**. It is not rework, not out-of-process, and does not require retroactive gate closure.

```text
implementation start          RATIFIED as of the first landed I0 commit
gate state at that moment     amended, not violated
required remediation          none
```

The general rule this establishes:

> When a gate blocks on evidence the current environment cannot produce, the correct move is to amend the gate with owner authority and record the amendment. Proceeding without amending is a governance defect and must be reported, not repeated.

## A2 — Overdeck Harvest Becomes a Parallel Non-Blocking Track

The following clause in [`AWP-I0-I1-REUSE-PREFLIGHT.md`](AWP-I0-I1-REUSE-PREFLIGHT.md) § *Overdeck Physical Harvest — Hard Blocker* is **superseded**:

> "Before equivalent custom I0/I1 code, authorized source access must inspect at least: […]"

and, insofar as it is applied to the Overdeck harvest, the § *Exit Condition* clause:

> "A blocked live proof is not an architecture blocker, but it is a **start-work blocker for the code that depends on that proof**."

Replacement rule:

```text
Overdeck capability harvest
  = parallel evidence track (lane E)
  = NON-BLOCKING for I0/I1 implementation

when authorized source access exists
  -> harvest, record path + commit + capability + disposition
  -> raise a replacement/adoption Decision where a harvested mechanic
     is genuinely better than what AWP already built

absence of the harvest
  -> never blocks writing, landing or dogfooding AWP code
```

Reuse-before-build survives for every source AWP can actually reach: Platform packages, native Node/PostgreSQL/Kubernetes primitives, and selected FOSS/providers. The [`AWP-I0-I1-REUSE-PREFLIGHT.md`](AWP-I0-I1-REUSE-PREFLIGHT.md) § *No-Build Hold List* remains fully binding — AWP still does not write its own HTTP framework, workflow engine, auth framework or wire protocols.

## A3 — Step-0 Checkbox Reclassification

Every unticked checkbox in [`STEP-0-PREPARATION-DEPENDENCIES.md`](STEP-0-PREPARATION-DEPENDENCIES.md) is reclassified into exactly one of two buckets. Classification is **by gate section**, so it is exhaustive by construction and does not depend on a checkbox count.

```text
GOLIVE-BLOCKING   must be green before the GOLIVE journey passes
POST-DOGFOOD      deferred; scheduled after the first real dogfood run
```

| Step-0 gate section | Bucket | Amended requirement |
|---|---|---|
| Step-0 Exit Gate — Overdeck physical harvest | POST-DOGFOOD | Per A2: parallel track, never blocking. |
| Step-0 Exit Gate — Platform package consumer integration/pins | GOLIVE-BLOCKING | Exact installed/imported/tested Platform packages with pinned versions. |
| Step-0 Exit Gate — DBOS failure/recovery runtime proof | GOLIVE-BLOCKING (descoped) | Per A4: one integration test, not the 9-scenario matrix. |
| Step-0 Exit Gate — K3s Workspace/WIP runtime proof | GOLIVE-BLOCKING | Pod execution containment is NON-negotiable. See A4. |
| Step-0 Exit Gate — gVisor representative compatibility proof | POST-DOGFOOD | Per A4. |
| Step-0 Exit Gate — Dev Container representative environment proof | POST-DOGFOOD | Per A4. |
| Step-0 Exit Gate — Fabro/ACP live mapping proofs | GOLIVE-BLOCKING (descoped) | One integration test per provider. See A4. |
| Step-0 Exit Gate — ARC ephemeral runner proof | POST-DOGFOOD | Moves with the whole ARC gate. |
| Step-0 Exit Gate — trusted I1 publication/merge E2E | GOLIVE-BLOCKING | Trusted publication boundary is the point of I1. |
| Step-0 Exit Gate — executable security mitigation evidence for privileged I1 | SPLIT | Pod execution containment: GOLIVE-BLOCKING. Everything else in the I1 security gate: POST-DOGFOOD. |
| Day-One CI / ARC Gate (entire checklist) | POST-DOGFOOD | The "day one" framing is withdrawn; see A4. Repository CI may run on hosted runners until then. |
| Durable Workflow Gate (9-step proof block) | GOLIVE-BLOCKING (descoped) | Reduced to one integration test. See A4. |
| Workspace / WIP Gate (7-step proof block) | GOLIVE-BLOCKING (descoped) | Reduced to one integration test plus the non-negotiable containment assertion. See A4. |
| Runtime Isolation Gate (gVisor) | POST-DOGFOOD | See A4. |
| Trusted Git Publication Gate | GOLIVE-BLOCKING | Unchanged in substance. |
| Account / Subrouter Gate | GOLIVE-BLOCKING (descoped) | One integration test per provider. |
| Data / Observability Gate | GOLIVE-BLOCKING | Already scoped as I0 implementation work. |
| Platform Gate / Three-Plane Foundation Gate / UI Gate | unchanged | Already green or already executable in-repo. |

The `[ ]` glyphs inside `STEP-0-PREPARATION-DEPENDENCIES.md` are no longer an implementation gate. They are a work ledger for the GOLIVE journey. Do not treat an unticked box there as a stop-work signal.

## A4 — I0 Proof Descope

I0's stated proof burden exceeded its build burden: nine DBOS failure scenarios, eleven ARC conditions, gVisor compatibility across two toolchains, and a full SecretStore seam, all before a single dogfood run. That ordering produces evidence about systems nobody has used yet.

New I0 proof requirement:

```text
per external provider (DBOS, Kubernetes/Workspace, Forge/GitHub,
Factory/Fabro, Agent/ACP, Account routing)
  -> ONE integration test that exercises the real provider seam
  -> deepened into failure/recovery matrices AFTER the first dogfood,
     driven by what actually broke
```

**Non-negotiable and unchanged:** K3s pod execution containment. An AgentRun executes in an isolated Kubernetes pod with its own ServiceAccount, NetworkPolicy and resource limits, holds no reusable Git publication/merge credential, and has no host filesystem or socket access. This is the single security property that must be proven before any agent runs real work, and it is not descoped, deferred or negotiable.

Moved to post-dogfood:

```text
ARC / GitHub Actions on K3s        the 11-condition day-one gate
gVisor RuntimeClass compatibility  representative toolchain proofs
SecretStore seam                   full abstraction + rotation semantics
```

Interim positions while those are deferred: repository CI runs on hosted GitHub runners; the container runtime default applies without a gVisor RuntimeClass; credentials are held as `CredentialReference` values resolved against Kubernetes Secrets directly, with no plaintext secret in any product column, event, log or UI payload. The `CredentialReference` *contract* stays — only the pluggable `SecretStore` implementation behind it is deferred, so activating it later is an adapter change and not a data-model change.

## A5 — Full-Target Visual Freeze Rule Is Revoked

The rule that the first high-fidelity design of a page must freeze the **final full-product composition** — including the placement of capabilities scheduled as far out as I8 — was generated inside this corpus. The owner did not request it and has revoked it.

Revoked clauses, quoted from their live locations:

| Document | Revoked text |
|---|---|
| [`AWP-DESIGN-PROGRESS.md`](AWP-DESIGN-PROGRESS.md) § Product Premise | "no incremental implementation that forgets the final product" / "no visual drift from temporary layouts" *(as a gate on first high-fi; retained as non-binding aspiration)* |
| [`AWP-DESIGN-PROGRESS.md`](AWP-DESIGN-PROGRESS.md) § Ratified Development Model | "OWNER-APPROVED FULL-TARGET HIGH-FI" as a required stage before incremental implementation |
| [`AWP-DESIGN-PROGRESS.md`](AWP-DESIGN-PROGRESS.md) § Visual Language Locked for I1 | "Material I1 page relocation or state-semantic changes require owner-approved amendment." |
| [`AWP-U1-PROJECT-HIGH-FIDELITY-BRIEF.md`](AWP-U1-PROJECT-HIGH-FIDELITY-BRIEF.md) § navigation | "The final U1 shell intentionally presents the complete product destination map." |
| [`AWP-INCREMENTAL-DELIVERY-PLAN.md`](AWP-INCREMENTAL-DELIVERY-PLAN.md) § Core Rule / § Per-Increment Design Complete Gate | "full-target page composition" and "full-target composition prototype exists" as entry conditions |
| [`AWP-INCREMENTAL-DELIVERY-PLAN.md`](AWP-INCREMENTAL-DELIVERY-PLAN.md) § Anti-Drift Rules | "move approved U1–U6 composition casually" *(narrowed — see below)* |

Replacement rule:

```text
first high-fi of a page
  = frozen composition for THAT increment only

a later increment
  = may relocate, restructure or replace the composition
    when the new capability makes a different layout better

still binding
  = visual language (dark shell, operational density, restrained accent,
    names before IDs, one dominant primary action, no KPI-card texture)
  = the approved U1-U6 set as the I1 acceptance journey
  = do not casually move I1 composition WITHIN I1
```

Designing I8-era placements is no longer a precondition for shipping the first screen. The U1–U6 mockups under `docs/mockups/i1/` remain the binding target for I1 implementation; they simply stop being a claim about I2–I9.

## A6 — Binding Authority Set Is Reduced

Roughly 210,000 tokens across ~40 documents were marked binding. No implementing agent can hold that alongside working context, so in practice agents held none of it and improvised. A binding set that cannot be read is not binding.

New authority rule:

```text
BINDING (read in full, always)
  docs/specs/adr/*.md                  9 ADRs
  docs/plans/I0-I1-AUTHORITY.md        distilled implementation digest
  GOLIVE.md                            repo-root go-live journey
  docs/plans/AWP-PAIN-INVARIANTS.md    owner pain -> design invariants
  this amendment

REFERENCE (consult on demand, for the surface you are touching)
  everything else under docs/specs/ and docs/plans/

PRECEDENCE
  ADRs + I0-I1-AUTHORITY.md  win over any reference spec
  this amendment             wins over any clause it names
  a reference spec           wins only where nothing above speaks
```

`GOLIVE.md` lands at the repository root in a parallel branch; it is named here as a member of the binding set so the rule is complete when it arrives.

Reference specs are not deprecated and are not stale by default. They remain the detailed authority for the surface they govern — an agent implementing the review flow should read `docs/specs/domains/reviews.md`. What changed is that no agent is expected to have read all of them before starting.

## A7 — Internal Merge Protection

GitHub branch protection and rulesets are unavailable to this repository (private repository on a free personal plan; the protection APIs return 404 even with owner credentials). Merge protection is therefore **internal and mandatory**, enforced by convention plus a mechanical alarm, until AWP's own trusted-merge path replaces it.

```text
code change
  -> pull request
  -> CI job green on the PR head commit
  -> merge
  never merge on a red or pending check

direct push to main
  allowed only for docs-only changes (CI still runs its docs-only path)
  or an emergency fix whose purpose is to turn a red main green

red main = STOP-THE-LINE
  no lane lands new work until main is green
  fix forward or revert — whichever is faster
  the CI workflow auto-opens a STOP-THE-LINE issue on a red main push;
  closing it without main being green is a governance defect

endgame
  the I1 trusted publication/merge path (GOLIVE AC scope) becomes the
  mechanical gate for AWP's own repository — AWP dogfoods its own
  merge protection; GitHub-native protection is re-evaluated only if
  the hosting plan changes
```

This rule binds every lane and orchestrator working on this repository, including external (ChatGPT-web) implementation lanes.

## Documents Amended by This Record

Each of these carries a pointer banner back to this amendment. Their bodies were deliberately left intact so there is exactly one place where the amended rule is stated.

```text
docs/plans/STEP-0-PREPARATION-DEPENDENCIES.md      A2, A3, A4
docs/plans/AWP-I0-I1-REUSE-PREFLIGHT.md            A2, A4
docs/plans/AWP-DESIGN-PROGRESS.md                  A5
docs/plans/AWP-U1-PROJECT-HIGH-FIDELITY-BRIEF.md   A5
docs/plans/AWP-INCREMENTAL-DELIVERY-PLAN.md        A3, A4, A5
docs/specs/INDEX.md                                A6
README.md                                          A6
```

## What This Amendment Does Not Change

```text
the three-plane topology and all 9 ADRs
the domain model, lifecycle chain and identity rules
the atomic state + event + audit + outbox transaction pattern
the module dependency law and architecture fitness checks
trusted publication: agents never hold reusable merge credentials
K3s pod execution containment
the No-Build Hold List
GOLIVE is not a primitive; it is a Goal
```

## Supersession Rule

This amendment is itself amendable, by the same mechanism: an owner-authorized record that names the clause it supersedes and updates the pointer banners in the affected documents. Silent divergence between landed code and a written gate is a defect to be reported in the next review, not a precedent.
