Expressiveness and migration coverage

This map records implemented repository coverage and the evidence still required for a live cutover. Repository fixtures are not a census of externally edited or production definitions.

Repository perimeter

All 13 shipped templates compile and round-trip through validated registrations. The historical source census identified five script bodies plus substantial display IIFEs; these now have closed app-owned replacements. The original census counts describe the earlier source, not current node counts.

Consumer coverage

ConsumerClosed implementation and evidence
Spell / allocation riskHuman suspension, permissions, nested fields, defaults/visibility/completion, mutable state, loose-mode edits, lifecycle, documents and records; canonical API/UI tests
Agent reviews / onboardingCompiled human/routing/notification definitions; full rendered markdown golden fixtures
NFAT setup/enable/subscribeABI encoding, checksummed/ICAP addresses, nested tuple/array codecs and independent ethers vectors
Curve / IB payoutsDune pagination/refresh, completed-week calculations with explicit clock, exact Safe batches, Solana payloads, waits, tracker/notification definitions
MerklExplicit scheduling, campaign JSON, HTTP encode request and response validation, deterministic golden fixtures
Solana freeze verificationRPC/account/base64/byte/log checks in closed composition, synthetic response vectors. The original script defined its helpers; an earlier missing-helper claim was incorrect.
Detached child creationPinned target definition, copied context, generic service creation receipts; not a parallel join

applications/main/src/templates/declarative/registered-programs.test.ts admits complete real registrations with synthetic capability references, not placeholder provider bodies. applications/main/src/migration/repo-processes.test.ts restores existing human visits across the repository registrations without external dispatch.

Libraries and generic substrate

Dune, Gemini, Slack, Telegram, Notion, Sheets and Safe are serialized library definitions. Provider methods, pagination, payload conversion and failure policies are not Platform opcodes. Safe includes service-address/count/order checks, already-executed shortcut, EVM signing/serialization, RPC submission hash assertion, receipt and replacement handling. It does not claim signature-owner verification absent from the original behavior.

Domain definitions cover Prime matching, dates, amount arithmetic, ABI/RLP/Safe, Solana messages/PDA search and byte construction. Generic bounded integer, byte, hash and curve primitives provide the substrate. The native implementations have been removed; 384 source-hashed frozen outcomes and independent encoders preserve their regression evidence. Valid Solana floating rounding remains explicit; invalid uint64 amounts are rejected under the approved safety exception.

Authoring text is parsed into closed syntax. Named app render macros replace the large historical IIFEs. Historical-source attestation is an offline/author-time converter, not a runtime evaluator. Unknown source is rejected. Static field macros expand before registration; runtime sees generic interaction and presentation contracts.

Compatibility decisions

  • Execution is pinned; current presentation may overlay process reads while original process mode stays fixed. Presentation and execution identities are separate.
  • Edits update shared activity-key memory without replay; visits/audits retain occurrence identity.
  • Recorded waits keep their deadline. Host-dependent parsing is an explicit effect, not pure ambient IO.
  • Credential placements include approved headers, query/path, form/JSON body and protected handles. Runtime values/history do not contain secrets, OAuth tokens, signatures or signed raw transactions.
  • Known failure/soft warning policies remain distinct from uncertain external outcomes.
  • Semantic input/conversion errors differ from resource/invalid-AST defects.
  • Closed syntax does not confer unlimited fuel/history or arbitrary JavaScript coercion support.

Remaining acceptance

Final packed/application/browser proofs must run on the finished tree after organization/configuration changes. Physical five-group organization and the joint architecture review remain part of the agreed endpoint; the generic/bespoke UI ownership slice is now part of the landing target. Live Auth0/provider/storage behavior, real record sizes and unsupported external authoring are not established by synthetic tests.

Use deployment bindings and migration for activation and conversion, current status for gates, and Platform follow-ups for stronger recovery, retention and future parallelism. No live provider calls or production writes are needed for local implementation verification.