Current stageR12-R20 local foundations
Live development scope

What is in motion now

updated from the public state
  • R4.1-R10Protocol + conformanceGuarded / conforming
  • R12Worker boundaries + permission receiptsImplemented locally
  • R13A2A / ACP transport + adaptersImplemented locally
  • R14Model Atlas + usage ledgerImplemented locally
  • R15Control rooms + private projectionsImplemented locally
  • R16Library intake + progressive onboardingImplemented locally
  • R18Trusted devices + recoveryFoundation / gated
  • R19Authenticator + mobile approvalsFoundation / gated
  • R20Multi-authority queues + routingFoundation / gated
  • M5Hosted tenancy + external operationsNot enabled

Green means the local contract or conformance work is implemented. Yellow marks a foundation whose production boundary is still gated. Red means the capability is intentionally not enabled.

Release route

Ship the safe path first.

Where we are, what ships next, and what this public site refuses—then the R0–R20 + M5 gates with proof you can open.

Stance

Are. Next. Refuse.

Where we are R12–R20 local foundation implemented

Framework boundaries, A2A/ACP transport, Model Atlas telemetry, private projections, guided onboarding, Jira, trusted devices, mobile approvals, and multi-authority queues now have tested local contract boundaries.

Release plan →

What's next Production bindings are next

The next gates bind real custody, external peers and tenants, native devices, authenticated sinks, independent review, and production backup/recovery. Local execution remains the safe default; the local R12–R20 contract foundations are already implemented and tested.

Harness track →

What we refuse Public-safe limits stay firm

No secret-holding Pages. No model self-approval dressed as independent review. No unpublished ITSM science, credentials, or confidential transcripts on this site.

Publication boundary ↗

Stages

R12–R20 local contract foundations are implemented. Production provider bindings, external interoperability, native device operations, and hosted features remain gated.

Canonical plan ↗
R0 Completed

Foundation

Protocol kernel, evidence gates, local MCP, and public-boundary checks.

complete

M1 proof ↗

R1–R3 Completed

Public-safe foundation

GitHub contract, Knowledge Hub projections, and read-only discovery CLI.

shipped

M2 contract ↗

R4 Completed

Overseer MVP

Normalize transcripts, compare model intakes, dispatch bounded round-table questions, and queue human decisions.

shipped

Exit gate ↗

R10 Completed

Adapter Conformance Kit

Freeze post-H4 envelopes, run golden fixtures, and report provider limitations explicitly.

complete

Conformance kit →

R4.1–R9 Completed

Guarded interoperability

Notion, Slack, archive lifecycle, MCP apply/rollback, and provider-neutral adapter contracts.

implemented
H1-H4 - guarded core implemented

One harness, four local model families, human authority preserved.

The harness is a provider-neutral execution layer over local CLIs and adapters. It records receipts, redacts outputs, checkpoints durable runs, and bridges guarded MCP/A2A envelopes; it queues the result for a human and never turns model consensus into approval.

H1Completed

Local fan-out

Run Grok CLI, Claude Code, Gemini/Antigravity, and ChatGPT/Codex through isolated adapters with receipts and budgets.

implemented (core)
H2Completed

Comparison and review

Normalize responses, support the desktop round-table chat, detect agreement and conflict, bind evidence, and produce an advisory Overseer packet.

implemented (core)
H3Completed

Durable runs

Add checkpoints, resume, cancellation, idempotent retries, failure isolation, and cost-aware escalation.

implemented (core)
H4Completed

Adapter and protocol bridge

Formalize provider receipts, capability discovery, optional LiteLLM routing, and guarded MCP/A2A bridge envelopes.

implemented (core)
Post-H4 route

Extend the harness without giving it authority.

Full post-H4 plan →Product roadmap →
R11

Controlled live routing, budgets, receipts, retries, and local fallback.

planned · approval-gated
R12

Restricted framework boundaries, worker traces, permissions, and conformance fixtures.

implemented · SDK/network isolation pending
R13

A2A/ACP transport with Ed25519 trust, runtime custody, deadlines, replay, and cancellation.

implemented · remote production peer pending
R14

Model Atlas observations, communication profiles, scan catalogs, and digest-only telemetry.

implemented · independent measurement pending
R15

Approval-gated private projections, durable replay, reconciliation, rollback, and encrypted state.

implemented · production custody/backup pending
R16

Guided onboarding, scoped workspaces, digestible-item catalogs, and consent-gated source extraction.

implemented · broader provider semantics pending
R17

Jira request plans, runtime custody, durable replay, conflicts, and rollback/rebuild.

implemented · live tenant pending
R18

Trusted-device lifecycle, enrollment/step-up proofs, delegation, and recovery drills.

implemented · native custody/attestation pending
R19

Offline-safe mobile votes and RP-bound authenticator assertion boundaries.

implemented · native mobile UX pending
R20

Durable any/all/quorum queues, scheduler, delivery, retention, and mobile drill.

implemented · authenticated sinks/review pending
R21

Deferred institutional evidence workflows for government, insurance, education, and regulated sectors.

deferred · custom build
M5

Hosted tenancy, billing, deletion, migration, support, and abuse controls.

future · separate product gate
R4.1 · implemented

Deterministic policy evaluation (advisory-only).

Humans author the rules; Overseer may execute clean matches at scale. Questionable or failed matches notify and enter the human queue. Silence is never acceptance. See ADR-003.

Auto-pass
Auto-pass · policy match
Questionable
Questionable · human look
Escalated
Escalated · required human
Human queue
Human queue · waiting
Standing policy

Human-authored rules with risk ceiling, scope, and hashed snapshot at apply time.

Comparison packet

Multi-model intakes with provenance—input to evaluate, never silent authority.

Notify + queue

Grey-zone and hard fails interrupt a human. Delivery channels are projections only.

Build map

Every convenience layer has an evidence gate.

Canonical plan ↗
R0

Foundation

Canonical records, policy gates, local MCP, public-boundary checks.

Complete
R1–R3

Safe collaboration

GitHub contract, Knowledge Hub projections, and read-only discovery CLI.

Complete
R4

Overseer MVP

Transcript normalization, comparison packets, assignment, provenance, redaction, and human approval queue.

Shipped
R5–R6

Control rooms

Opt-in Notion projection, then Slack channels, threads, notifications, and signed commands.

Implemented (guarded)
R7–R8

Archive and installer

Low-RAM local bookshelf, bounded archive watcher, relevance filtering, retention/export, recoverable delete/restore/purge, MCP discovery, dry-run configuration plans, backup and rollback.

Implemented (core)
R9

Provider adapters

Provider-neutral receipts, readiness-aware model capability registry, comparison routing, and local-model fallback boundary.

Implemented (guarded)
H1-H4

Multi-model harness

Local fan-out, comparison, durable runs, bounded budgets, receipts, and optional protocol bridges across the supported model families.

Implemented (guarded)