This page distinguishes the implemented closed-language rewrite from the remaining review, packaging and rollout work. It does not authorize publication or a production cutover.
The organizing groups are Platform, Integrations, UI, Domain and Applications. Platform owns the SDK and executor together. Templates are inspectable descriptions; a Process is one execution. Simple and composed templates share the same compositional interface.
The application API, worker, editor, generic frontend and bespoke applications consume compiled registrations and canonical Process views. Native provider handlers, callback-based expression registries, arbitrary script execution, old Domain algorithm implementations and obsolete SDK provider-step unions have been removed. Application graph source is owned by the small app-authoring library; Integrations owns provider configuration shapes, Domain owns field macros, and Platform owns only generic fields, closed syntax and generic effects.
All 13 shipped templates compile to serialized executable definitions. The thirteen attested historical script bodies and the known app display IIFEs have explicit closed replacements. Domain regression evidence includes 384 source-hashed frozen synthetic outcomes plus independent EVM/Solana codec checks. Frozen evidence is test data, not a second executable implementation.
Named visits, interaction permissions, sparse field audit, raw state changes, lifecycle commands, files, records, and detached children use one canonical application service. Child creation has occurrence receipts and pinned definitions. Offline conversion preserves recorded history and human/wait continuations without replay; uncertain automatic work is held for reconciliation.
See language model, coverage, boundaries and deployment bindings.
Four changes were approved separately from compatibility preservation:
Host-dependent datetime parsing is a recorded generic effect. It is not an ambient timezone read inside a pure expression. Known definitive failure policies are expressed by closed recovery/backoff composition, separately from uncertain transport outcomes.
The complete npm run verify gate passed locally on the frontend endpoint at 1cb0803,
using synthetic fixtures across all 27 verification stages:
Default and Allocation Risk legacy deployments also passed their own production builds, CSS checks and 24 compiled HTTP checks each. The Spell deployment was restored and its four browser journeys passed again. The final documentation-only checkpoint records this evidence; it does not alter the tested implementation.
Independent reviews also checked the retired native paths, template-author capability compatibility, immutable cache safety and mechanical folder/cwd changes. This is local evidence, not hosted CI, live-provider or production-data certification. See verification.
The physical five-group layout is present: platform/, integrations/, ui/, domain/ and
applications/. Main is a separate application workspace; the root owns orchestration only.
The follow-up architecture review approved independent Spell and Allocation Risk frontends and
a bounded generic frontend. That ownership slice is implemented and locally verified;
see frontend ownership.
Previously unfulfilled product features remain distinct: Spell capability probes cover review/Q&A, private notes and cycle-move requirements without claiming those features are fully mounted. Platform follow-ups include stronger durability, reconciliation, bounded retries, retention and parallel execution.
The authorized September 23 rehearsal export exposed older script variants, display IIFEs, obsolete metadata and a retired Notion record step not covered by the original synthetic snapshot matrix. Offline adaptations now preserve these as closed definitions rather than executing historical source. The rehearsal converter accepts all 122 exported processes and 13 latest templates without holds or rejects. These counts describe that snapshot only, not a final quiesced production backup.
The CLI reports all template/process failures together, blocks import for unresolved records, and supports explicit create-only Mongo import with redacted driver errors. See closed-runtime cutover. All 122 aggregates and 13 latest registrations passed canonical-hash readback in an authenticated loopback Mongo rehearsal; a repeat created no records. All 54 running processes retain their awaiting-input visits and historical context/results/timestamps remain preserved. No external effects ran in that rehearsal.
Real configuration/key provisioning, attachment backup, final exact-head verification, hosted CI, and coordinated activation remain separate acceptance gates. No production migration or deployment has been performed.
The dependency/framework slice passed the complete 27-stage local gate on Node 22.23.2, including 881 library tests and 619 main tests with coverage, packed consumers, production HTTP/browser checks and independently installed Main, Spell, Allocation Risk, generic frontend and backend projects. The final RPC-preflight parser correction was reviewed separately and passed both affected suites (17 tests). After that correction, Main typechecks and all 620 tests with coverage passed again; default, Allocation Risk and Spell profiles each passed a production build, CSS parity and 24 compiled HTTP checks. The final Spell build also passed all four browser journeys. Boundary and documentation checks passed. These are synthetic/local proofs, not live tenant or provider acceptance.
The non-mutating preflight was also run inside each of the four existing production services. It reports the two new protected-store keys as missing and no other configuration-shape failure for the selected roles/capabilities. Sealed Railway credentials are present at runtime even when omitted from control-plane listings. No keys or production configuration were changed.
The required application-access model separates deployment ownership from participant affiliation. Main, independent backend and worker share it; the opt-in/legacy branch has been removed. The CLI requires an explicit ownership map and uses owner-aware stores. Provider accounts remain in place. App grants are scoped email-to-role declarations; operator grants are separate.
The candidate also adds browser-bound OAuth state, stream-bounded uploads and activity/field-aware file deletion. Legacy attachments require reviewed ownership metadata before deletion can be enabled. These changes are local candidates, not production fixes. Production additionally needs the required access policy and reviewed migration, beyond the earlier protected-key preflight findings.
See review disposition for Lako's items and remaining activation gates. Current verification evidence is recorded per candidate; earlier green gates do not certify subsequent uncommitted edits.