This map records implemented repository coverage and the evidence still required for a live cutover. Repository fixtures are not a census of externally edited or production definitions.
All 13 shipped templates compile and round-trip through validated registrations. The historical source census identified five script bodies plus substantial display IIFEs; these now have closed app-owned replacements. The original census counts describe the earlier source, not current node counts.
| Consumer | Closed implementation and evidence |
|---|---|
| Spell / allocation risk | Human suspension, permissions, nested fields, defaults/visibility/completion, mutable state, loose-mode edits, lifecycle, documents and records; canonical API/UI tests |
| Agent reviews / onboarding | Compiled human/routing/notification definitions; full rendered markdown golden fixtures |
| NFAT setup/enable/subscribe | ABI encoding, checksummed/ICAP addresses, nested tuple/array codecs and independent ethers vectors |
| Curve / IB payouts | Dune pagination/refresh, completed-week calculations with explicit clock, exact Safe batches, Solana payloads, waits, tracker/notification definitions |
| Merkl | Explicit scheduling, campaign JSON, HTTP encode request and response validation, deterministic golden fixtures |
| Solana freeze verification | RPC/account/base64/byte/log checks in closed composition, synthetic response vectors. The original script defined its helpers; an earlier missing-helper claim was incorrect. |
| Detached child creation | Pinned target definition, copied context, generic service creation receipts; not a parallel join |
applications/main/src/templates/declarative/registered-programs.test.ts admits complete real registrations with
synthetic capability references, not placeholder provider bodies. applications/main/src/migration/repo-processes.test.ts
restores existing human visits across the repository registrations without external dispatch.
Dune, Gemini, Slack, Telegram, Notion, Sheets and Safe are serialized library definitions. Provider methods, pagination, payload conversion and failure policies are not Platform opcodes. Safe includes service-address/count/order checks, already-executed shortcut, EVM signing/serialization, RPC submission hash assertion, receipt and replacement handling. It does not claim signature-owner verification absent from the original behavior.
Domain definitions cover Prime matching, dates, amount arithmetic, ABI/RLP/Safe, Solana messages/PDA search and byte construction. Generic bounded integer, byte, hash and curve primitives provide the substrate. The native implementations have been removed; 384 source-hashed frozen outcomes and independent encoders preserve their regression evidence. Valid Solana floating rounding remains explicit; invalid uint64 amounts are rejected under the approved safety exception.
Authoring text is parsed into closed syntax. Named app render macros replace the large historical IIFEs. Historical-source attestation is an offline/author-time converter, not a runtime evaluator. Unknown source is rejected. Static field macros expand before registration; runtime sees generic interaction and presentation contracts.
Final packed/application/browser proofs must run on the finished tree after organization/configuration changes. Physical five-group organization and the joint architecture review remain part of the agreed endpoint; the generic/bespoke UI ownership slice is now part of the landing target. Live Auth0/provider/storage behavior, real record sizes and unsupported external authoring are not established by synthetic tests.
Use deployment bindings and migration for activation and conversion, current status for gates, and Platform follow-ups for stronger recovery, retention and future parallelism. No live provider calls or production writes are needed for local implementation verification.