factory first-proof --root .Factory Studio / Graph Ops
Follow the proof path.
A bounded control plane for Product, Mission, Proof, Gate, Trace, semantic lineage, and verified counterfactual repair. Follow the failure, compare every candidate, and understand the winning proof without executing it.
What do you need to prove today?
Choose the outcome that matches your work. Code Factory keeps the deeper machinery available without making you learn it before your first useful result.
factory oracle status --root .factory graph ops --root . --jsonShow specialized modules only when needed
Advanced proof, SaaS, mobile, multi-repository, and enterprise controls appear below. AppForge applies only when mobile delivery is explicitly in scope. Every consequential action remains separately reviewed.
This guide runs nothing. It does not approve intent, start an agent, change a repository, access credentials, or release work.
Live Factory telemetry
Connecting to the local workspace.
Current stage, elapsed time, completed stages, and measured telemetry will appear here. Unknown token, cost, and productivity values stay unknown.
Open specialized modules and their blockersFor teams already using sealed intent, agent evidence, SaaS, mobile delivery, or enterprise controls.
One truth for people and connected agents.
Humans decide intent and final approval. Agents receive the same sealed, local evidence but cannot alter the contract, threshold, scope, repair decision, Git state, or release. Unknowns stay visible instead of being inferred away.
This panel is read-only. It never turns a green card into approval or a connected agent into an authorized actor.
Make the factory legible to humans and agents.
Mission Control exposes observable swim-lanes, model routing, typed handoffs, lazy cookbook context, reusable workflows, capability registries, durable task cards, and sandbox boundaries as read-only facts.
This panel reports deterministic metadata only. It cannot invoke a model, run a task, mutate source, approve work, merge, publish, or access credentials.
Six ways a green build can still fail users.
Challenge workflow invariants, tenant boundaries, retries and recovery, consumer contracts, database migrations, and performance or memory retention. Every lane shows what failed, why it matters, the evidence digest, and the smallest repair.
No self-hash-verified receipt yet. Run an externally signed six-lane plan; this screen cannot invent thresholds or execute tests.
Turn the diff into the next safe proof.
See what changed, why it affects evidence, the smallest next step, and who local Git history observed on the selected work. It is explanatory and read-only: it does not run a proof, recall memory bodies, or authorize a person.
Observed project contributors
Loading bounded local Git history.
Brief refreshes no more than once every five seconds. Live assembly telemetry refreshes separately.
Review the riskiest item first.
Current, stale, and invalid proof reviews stay separate. This queue never infers productivity and never approves work.
See exactly where purchase reality diverges.
Build the monetization lane, replay the observed lifecycle, challenge every failure path, and invalidate only conclusions touched by policy drift.
Did login, payment, and permission agree?
Trace an observed OAuth/OIDC identity through tenant authorization, checkout, verified webhook, entitlement, feature access, and revocation. Clerk, Auth0, Okta, Entra, Cognito, Supabase, Firebase, and other compliant providers use the same evidence contract.
Improve your app before Apple finds the gap.
Start with one plain-English mission and one exact build. AppForge binds user design input, adaptive native-surface signals, an iPhone/iPad proof plan, truthful storefront story coverage, strict UI and accessibility evidence, SaaS reality, policy applicability, current-build media, supervised physical-device evidence, and a credential-free release rehearsal without placing secrets in Code Factory. A supervised agent may prepare evidence; only a named human can authorize the final Apple handoff.
Classify every policy
Import current-build evidence
Resolve every blocker
Review what changed
Authorize one exact handoff
Locked: App Review, Store media, SaaS lifecycle, strict quality-audit, adaptive native-surface preflight, and any required Device Reality receipt must match the same candidate before AppForge issues the final Markdown/PDF dossier. Native Surface binds confirmed user design input to local Swift sources, adaptive navigation signals, accessibility fallbacks, restrained custom glass, and the device-bound screenshot storyboard. It is static evidence—not a device or approval claim. Release Rehearsal seals a Fastlane lane, App Store Connect CLI app ID, Cider YAML-manifest hash, Swiftlane build/test/archive/export source sequence, or a Zealot-style artifact/channel/audience manifest. It keeps local readiness, archive, upload, processing, beta delivery, review submission, and Apple decision separate—and never invokes a provider. Device Reality seals the approved journey, forbidden outcome, design-input hash, and allowed capture transport before evidence collection. A separate named, expiring human authorization is still required for any Apple handoff.
Prove the gate is still honest.
Freeze the exact original request before coding. Only human-confirmed or trusted-source rules can release work. A separate challenge lane targets the implementation and boundary cases; it cannot edit the contract, production code, or a test.
Proof chain: source → obligation → forbidden behavior → gate → test → evidence → decision.
E_ORACLE_WEAKENING, pauses autonomous work, and opens a demotion incident.Locked: this screen reads local proof. It cannot approve a successor contract, raise autonomy, modify a test, run a challenge, or contact a provider. Use a separate named human approval to seal a successor.
An admitted receipt is not an executed action.
Before a separate runner can rely on a task, FactoryLine can bind its declared workload, tenant policy, exact paths, action category, revocation state, and—when required—its live semantic lease. The receipt is replay-safe and visible; it never becomes a hidden permission grant.
Locked: this view reads local signed facts only. It cannot authenticate a cloud workload, grant a credential, invoke a tool, enforce a network boundary, execute a release, or bypass human review.
Keep the workflow, verify the handoff.
Import a compact workflow export to inspect its typed stage DAG, capability-scoped handoffs, source-precondition hashes, and checkpoint continuity against the sealed intent contract. This display never starts Atomic, resumes a checkpoint, or turns a declared workflow into authority.
Locked: Graph Ops only reads hash-valid local receipt facts. A declared worktree, container, VM, or remote host is not proof of a sandbox. Inspect the exact Oracle Contract and receipt before authorizing separate work.
Bring the agent’s evidence, not its authority.
Inspect a compact Eve, Junie, Grok Build, or generic export against the exact sealed intent. Code Factory binds the declared workflow, original source preconditions, and real local before/after artifacts. It never starts, resumes, approves, or deploys an agent run.
Locked: a provider export is not provider identity, sandbox, checkpoint, deployment, or agent-quality proof. It must remain tied to a current Oracle Contract and actual local evidence artifacts; a separate human still controls every real action.
Make the work envelope reviewable before an agent starts.
Bind the base revision, branch isolation, failed reproduction, change budget, evidence tier, architecture zones, and local repository heads. A receipt says what was checked; it does not create a worktree, run a repair, or approve a merge.
Locked: operations controls observe local preconditions only. They do not execute a task, allocate a sandbox, invoke a model, create an approval, or change Git state.
Trace the handoff without trusting a story.
Each recorded stage names the declared harness and session, binds input and output hashes to a sealed Oracle Contract, and points to the prior receipt. Session traces are local, hash-linked evidence—not identity, execution, or release authority.
Locked: this is an inspection-only trace. It cannot resume a session, contact a provider, alter intent, grant an agent permission, or mark work approved.
Fix the exact fault, then challenge the fix.
Turn a real failure into a bounded packet: affected obligation, explicit potential consequences, observed reproduction, candidate hash, positive and negative independent re-checks, and a named human reviewer. The loop cannot self-approve or keep guessing after evidence breaks.
Locked: a packet is a review artifact, not a repair command. Any scope, oracle, evidence, or independent-check gap remains blocked.
Choose who may attempt the repair—not who may approve it.
Human-controlled mode only verifies a prepared repair. Supervised-auto mode permits one bounded local agent command, then independently audits its identity, command, workspace delta, scope, positive proof, and negative mutation. Neither mode grants final approval.
Final approval is always withheld. Run the copied manifest through factory journey heal-verify in a separately reviewed terminal.
What did the runtime runner actually observe?
Inspect imported TestSprite-shaped or other provider evidence beside local proof. This view separates observed facts from hypotheses and keeps every execution, repair, merge, and release control locked.
Review before repair
Inspect the first failed step and hypothesis before admitting a bounded local proof. No automatic repair is available.
review_external_runtime_failureDid the shipped work honor the sealed intent?
This is a local, read-only projection of the newest Forge ship receipt. It shows the intent hash and obligation result without treating a receipt as execution or approval authority.
Nodes
—Edges
—Evidenced
—Lineage runs
—Forensic findings
—Repair candidates
—Graph status
LoadingProof path visual
One compact visual map of the supplied requirement-to-decision flow. It explains the current state; it never executes a graph action.
Evidence health
Deterministic ratios from this bounded graph result, not estimated productivity or a quality score.
Portfolio Flight Plan
See the structural critical path, safe parallel waves, shared-proof candidates, and blocker chains before selecting a separate, approved harness.
Sequenced workset
Blocks propagate visibly; every runnable item still requires independent verification.
Safe parallel waves
These are proposal-only groups. They do not start work or authorize proof reuse.
Shared proof candidates
Sealed admission posture
No sealed admission packet has been projected from this workspace.
Locked: export and re-verify a time-bounded packet with a separate harness. Graph Ops cannot execute a wave, approve, repair, merge, publish, deploy, sign, message, access credentials, or grant a connector.
Which repair is smallest and actually proven?
Every candidate is hash-bound, scope-checked, independently proven, mutation-tested, and ranked by one deterministic ordering.
Winner rationale
No evaluation loaded.
Execution controls
Inspect, export, and validate the decision here. Applying code, merging, publishing, and deploying require separate authority.
Locked: ProofSearch has no workspace-mutation, approval, merge, publication, or deployment authority.
What should you prove next?
Rank supplied, non-executing experiments by exactly how many viable repair pairs they separate. Predictions are hypotheses, never proof or execution authority.
Evidence decision
No sealed Evidence Frontier loaded.
Execution controls
Copy, export, and validate the plan. A separate approved runner is required before any experiment may run.
Locked: Graph Ops ranks evidence only; it cannot execute a command, mutate a workspace, or grant approval.
What prior work is safe to reuse?
Only independently promoted, exact-scope, purpose-bound, non-expired references can influence a future decision. This panel redacts memory references and summaries by design.
Eligibility boundary
No local continuity records loaded.
Human promotion required
Graph Ops can inspect local metadata. It cannot store memory content, promote a lesson, sign evidence, or grant an agent access to a record.
Locked: promotion requires a separate identity, exact purpose, evidence references, and an explicit local CLI action.
Stop rediscovering the same design decision.
Judgment Capsules preserve a scoped engineering decision with an owner, review date, and hash-bound proof obligations. Proposals are not active until an independent human promotes them.
Safety-case boundary
No tracked Judgment Capsules were projected.
Decision controls
Use this board to inspect local decision metadata. A Change Safety Case routes a scoped diff to the named owner only when its proof obligations are bound and verified. Add a human-declared Change Profile to make novelty and attention explicit—this UI never guesses from source code.
Locked: this UI cannot infer intent, promote or waive a decision, execute a repair, approve code, merge, publish, deploy, sign, message, or access credentials.
Agent supervision board
Each declared agent earns a local, expiring tier from governed run evidence. A severe hollow-test, hollow-validator, or scope-escape result demotes it automatically. Identity remains declared unless an external harness proves it.
Permission boundary
No governed agent evidence has been projected.
Supervision controls
Inspect and verify local evidence here. This screen cannot issue a license, raise autonomy, start a candidate, or grant execution authority.
Locked: licenses are derived from independently verified governed events. Use the explicit local CLI after recording evidence; Graph Ops does not promote an agent.
Why did this graph run change?
Compare sealed state lineage, isolate the first semantic divergence, and preview the smallest recovery branch.
No deterministic concurrency or state anomalies detected.
Changed state
Causal path
Rerun only
Evidence to refresh
Guarded Action Dock
Prepare and validate the recovery locally. Workspace mutation stays locked until a separate signed approval is supplied.
Locked: no named, expiring, signed approval is bound. Graph Ops cannot grant one.
Graph lanes
Loading the authenticated local graph result.
Graph data is read from /api/graph-ops. A separate token-bound local request can record one named authorization or consume one Reality Check authorization. Labels are rendered as text nodes.