{
  "claimsContract": 2,
  "$comment": "The only sentences any public asset may assert about what this framework does. AGENTS.md: 'every claim in the docs, the ADR, the PR body and the JTBD matrix traces to a merged test — a capability and its limitation are stated in the same breath.' This file extends that rule to marketing. Templates reference claims by id ({{claim:C-01}}); `npm run site:check` fails the build if a claim is missing evidence, missing a limitation, references a file that does not exist, or is defined and never used. Contract 2 (ADR-027): measuredAgainst additionally requires testFiles and testsTree, and no claim, limitation or repoFact may type an exact test count — the one number lives in measuredAgainst and reaches a page as {{measured.tests}}.",
  "measuredAgainst": {
    "date": "2026-09-29",
    "sha": "eacce47",
    "command": "npm run verify",
    "tests": 2413,
    "failures": 0,
    "testFiles": 204,
    "testsTree": "1113cd908e60afb159f8259ce092529de90e08c8",
    "files": {
      "tests/action-contract.test.js": {
        "tests": 12
      },
      "tests/action-runtime-semantics.test.js": {
        "tests": 6
      },
      "tests/actor-fails-closed.test.js": {
        "tests": 8
      },
      "tests/admin-actions.test.js": {
        "tests": 8
      },
      "tests/admin-contracts.test.js": {
        "tests": 8
      },
      "tests/admin-core.test.js": {
        "tests": 9
      },
      "tests/admin-customer-data.test.js": {
        "tests": 9
      },
      "tests/admin-delivery-change.test.js": {
        "tests": 23
      },
      "tests/admin-delivery.test.js": {
        "tests": 5
      },
      "tests/admin-lifecycle.test.js": {
        "tests": 16
      },
      "tests/admin-marketing.test.js": {
        "tests": 7
      },
      "tests/admin-modules.test.js": {
        "tests": 15
      },
      "tests/admin-pipeline.test.js": {
        "tests": 8
      },
      "tests/admin-quotes.test.js": {
        "tests": 7
      },
      "tests/admin-service.test.js": {
        "tests": 27
      },
      "tests/admin-signature.test.js": {
        "tests": 5
      },
      "tests/admin-spine.test.js": {
        "tests": 13
      },
      "tests/admin-work.test.js": {
        "tests": 17
      },
      "tests/agent-tool-selection-contract.test.js": {
        "tests": 28
      },
      "tests/agent-tool-selection-prompts.test.js": {
        "tests": 31
      },
      "tests/agent-tool-selection-scoring.test.js": {
        "tests": 67
      },
      "tests/analytics-pipeline-metrics.test.js": {
        "tests": 6
      },
      "tests/api.test.js": {
        "tests": 1
      },
      "tests/app-inspect.test.js": {
        "tests": 27
      },
      "tests/async-record-modules-packages.test.js": {
        "tests": 2
      },
      "tests/async-record-modules-postgresql.test.js": {
        "tests": 2
      },
      "tests/async-record-modules.test.js": {
        "tests": 4
      },
      "tests/benchmark-harness.test.js": {
        "tests": 13
      },
      "tests/benchmark-scorer.test.js": {
        "tests": 15
      },
      "tests/characterization/commercial-characterization.test.js": {
        "tests": 24
      },
      "tests/characterization/intelligence-characterization.test.js": {
        "tests": 29
      },
      "tests/characterization/signature-characterization.test.js": {
        "tests": 23
      },
      "tests/characterization/source-scan.test.js": {
        "tests": 9
      },
      "tests/codex-mcp-cwd.test.js": {
        "tests": 1
      },
      "tests/collection-filter.test.js": {
        "tests": 2
      },
      "tests/commercial-capabilities.test.js": {
        "tests": 2
      },
      "tests/commercial-contract.test.js": {
        "tests": 10
      },
      "tests/commercial-e2e.test.js": {
        "tests": 3
      },
      "tests/commercial-package-absence.test.js": {
        "tests": 2
      },
      "tests/commercial-quotes-deprecation.test.js": {
        "tests": 2
      },
      "tests/contracts-activation-e2e.test.js": {
        "tests": 7
      },
      "tests/contracts-contract.test.js": {
        "tests": 9
      },
      "tests/contracts-registry-review.test.js": {
        "tests": 5
      },
      "tests/contracts-review.test.js": {
        "tests": 6
      },
      "tests/core-adapters.test.js": {
        "tests": 4
      },
      "tests/create-accordo-package.test.js": {
        "tests": 8
      },
      "tests/custom-package-e2e.test.js": {
        "tests": 1
      },
      "tests/customer-data-complete-reads.test.js": {
        "tests": 4
      },
      "tests/customer-data-faults.test.js": {
        "tests": 6
      },
      "tests/customer-data-foundation.test.js": {
        "tests": 15
      },
      "tests/customer-data-identity-conflicts.test.js": {
        "tests": 4
      },
      "tests/customer-data-label-snapshot.test.js": {
        "tests": 1
      },
      "tests/customer-data-operations-v2.test.js": {
        "tests": 15
      },
      "tests/data-governance-classification.test.js": {
        "tests": 7
      },
      "tests/delivery-change-acceptance-e2e.test.js": {
        "tests": 9
      },
      "tests/delivery-change-acceptance-evidence.test.js": {
        "tests": 12
      },
      "tests/delivery-change-acceptance-integration.test.js": {
        "tests": 7
      },
      "tests/delivery-economics-e2e.test.js": {
        "tests": 14
      },
      "tests/delivery-execution-e2e.test.js": {
        "tests": 12
      },
      "tests/delivery-handover-e2e.test.js": {
        "tests": 8
      },
      "tests/distribution-intent.test.js": {
        "tests": 7
      },
      "tests/docs-mcp-http.test.js": {
        "tests": 10
      },
      "tests/docs-mcp.test.js": {
        "tests": 24
      },
      "tests/event-bus-outbox.test.js": {
        "tests": 8
      },
      "tests/falsify.test.js": {
        "tests": 7
      },
      "tests/generated-api-e2e.test.js": {
        "tests": 1
      },
      "tests/generated-api.test.js": {
        "tests": 4
      },
      "tests/gtm-current-claims.test.js": {
        "tests": 4
      },
      "tests/gtm-release-integration.test.js": {
        "tests": 3
      },
      "tests/http-envelope.test.js": {
        "tests": 2
      },
      "tests/http-keep-alive-reap.test.js": {
        "tests": 3
      },
      "tests/implementation-evidence.test.js": {
        "tests": 32
      },
      "tests/intelligence-capability-consumer.test.js": {
        "tests": 3
      },
      "tests/intelligence-contract.test.js": {
        "tests": 11
      },
      "tests/intelligence-package-absence.test.js": {
        "tests": 2
      },
      "tests/intelligence-pre-extraction-upgrade.test.js": {
        "tests": 3
      },
      "tests/intelligence-signal-value.test.js": {
        "tests": 11
      },
      "tests/jobs-json.test.js": {
        "tests": 15
      },
      "tests/jtbd-portfolio-gate.test.js": {
        "tests": 45
      },
      "tests/jtbd-publication-surface.test.js": {
        "tests": 8
      },
      "tests/jtbd-query-tool.test.js": {
        "tests": 7
      },
      "tests/lead-conversion-e2e.test.js": {
        "tests": 15
      },
      "tests/lead-intelligence-e2e.test.js": {
        "tests": 3
      },
      "tests/lead-qualification-e2e.test.js": {
        "tests": 2
      },
      "tests/lifecycle-amendment-execution-e2e.test.js": {
        "tests": 17
      },
      "tests/lifecycle-amendment-execution.test.js": {
        "tests": 16
      },
      "tests/lifecycle-amendment-upgrade.test.js": {
        "tests": 2
      },
      "tests/lifecycle-renewal-operations-e2e.test.js": {
        "tests": 13
      },
      "tests/lifecycle-renewal-operations.test.js": {
        "tests": 19
      },
      "tests/marketing-e2e.test.js": {
        "tests": 3
      },
      "tests/marketing-funnel.test.js": {
        "tests": 7
      },
      "tests/marketing-no-external-effect.test.js": {
        "tests": 4
      },
      "tests/marketing-package.test.js": {
        "tests": 6
      },
      "tests/marketing-proposal.test.js": {
        "tests": 15
      },
      "tests/mcp.test.js": {
        "tests": 3
      },
      "tests/measure-refresh.test.js": {
        "tests": 18
      },
      "tests/measurement-report.test.js": {
        "tests": 7
      },
      "tests/module-evolution-factory.test.js": {
        "tests": 17
      },
      "tests/module-evolution.test.js": {
        "tests": 11
      },
      "tests/module-factory-e2e.test.js": {
        "tests": 1
      },
      "tests/module-factory.test.js": {
        "tests": 14
      },
      "tests/module-manifest-cli.test.js": {
        "tests": 4
      },
      "tests/module-manifest.test.js": {
        "tests": 11
      },
      "tests/module-migrations.test.js": {
        "tests": 6
      },
      "tests/opportunity-pipeline-e2e.test.js": {
        "tests": 12
      },
      "tests/package-contract.test.js": {
        "tests": 11
      },
      "tests/package-operations-seam.test.js": {
        "tests": 5
      },
      "tests/package-scaffold.test.js": {
        "tests": 35
      },
      "tests/package-test-command.test.js": {
        "tests": 34
      },
      "tests/pinned-certificate-verification.test.js": {
        "tests": 6
      },
      "tests/pipeline-contract.test.js": {
        "tests": 5
      },
      "tests/production-spine.test.js": {
        "tests": 22
      },
      "tests/project-bootstrap.test.js": {
        "tests": 29
      },
      "tests/project-doctor.test.js": {
        "tests": 33
      },
      "tests/project-verify.test.js": {
        "tests": 44
      },
      "tests/public-evidence.test.js": {
        "tests": 22
      },
      "tests/read-only-composition-postgresql.test.js": {
        "tests": 15
      },
      "tests/read-only-storage-mode.test.js": {
        "tests": 6
      },
      "tests/reference-fields-e2e.test.js": {
        "tests": 2
      },
      "tests/reference-resolver.test.js": {
        "tests": 6
      },
      "tests/repository-truth-contract.test.js": {
        "tests": 76
      },
      "tests/repository-truth.test.js": {
        "tests": 13
      },
      "tests/scaffold.test.js": {
        "tests": 1
      },
      "tests/scenario-document.test.js": {
        "tests": 21
      },
      "tests/scenario-run.test.js": {
        "tests": 43
      },
      "tests/service-operations-e2e.test.js": {
        "tests": 6
      },
      "tests/service-operations-evidence.test.js": {
        "tests": 11
      },
      "tests/service-operations-integration.test.js": {
        "tests": 5
      },
      "tests/service-operations-upgrade.test.js": {
        "tests": 1
      },
      "tests/signature-contract.test.js": {
        "tests": 13
      },
      "tests/signature-order-e2e.test.js": {
        "tests": 5
      },
      "tests/signature-orders-capability.test.js": {
        "tests": 1
      },
      "tests/signature-package-absence.test.js": {
        "tests": 2
      },
      "tests/signature-signer-input.test.js": {
        "tests": 1
      },
      "tests/signed-terms-consumption-guard.test.js": {
        "tests": 3
      },
      "tests/signed-terms-e2e.test.js": {
        "tests": 4
      },
      "tests/signed-terms-integrity.test.js": {
        "tests": 16
      },
      "tests/signed-terms-upgrade.test.js": {
        "tests": 1
      },
      "tests/site-analytics.test.js": {
        "tests": 4
      },
      "tests/site-art-direction.test.js": {
        "tests": 12
      },
      "tests/site-pages.test.js": {
        "tests": 18
      },
      "tests/site-seo.test.js": {
        "tests": 19
      },
      "tests/skill-parity.test.js": {
        "tests": 3
      },
      "tests/solution-plan.test.js": {
        "tests": 18
      },
      "tests/solution-verify.test.js": {
        "tests": 60
      },
      "tests/spine-configuration-refusal.test.js": {
        "tests": 15
      },
      "tests/spine-integration-production-operations-postgresql.test.js": {
        "tests": 4
      },
      "tests/spine-integration-production-operations.test.js": {
        "tests": 16
      },
      "tests/spine-plane-collision.test.js": {
        "tests": 5
      },
      "tests/spine-route-authorization.test.js": {
        "tests": 7
      },
      "tests/spine-tenancy-truth.test.js": {
        "tests": 6
      },
      "tests/spine-v2-m0-characterization.test.js": {
        "tests": 8
      },
      "tests/spine-v2-m1-storage-contract.test.js": {
        "tests": 10
      },
      "tests/spine-v2-m2-final-portable-exit.test.js": {
        "tests": 7
      },
      "tests/spine-v2-m2-final-posture.test.js": {
        "tests": 21
      },
      "tests/spine-v2-m2-final-raw-boundary.test.js": {
        "tests": 8
      },
      "tests/spine-v2-m2-requirement-map.test.js": {
        "tests": 11
      },
      "tests/spine-v2-m2b-definition-version-store.test.js": {
        "tests": 40
      },
      "tests/spine-v2-m2c-execution-run-store.test.js": {
        "tests": 43
      },
      "tests/spine-v2-m2d-transaction-context.test.js": {
        "tests": 16
      },
      "tests/spine-v2-m2e1-contract-versions.test.js": {
        "tests": 23
      },
      "tests/spine-v2-m2e2-async-lifecycle.test.js": {
        "tests": 12
      },
      "tests/spine-v2-m2e2-portable-facade.test.js": {
        "tests": 12
      },
      "tests/spine-v2-m2e2-portable-http.test.js": {
        "tests": 15
      },
      "tests/spine-v2-m2e3-public-async-factory.test.js": {
        "tests": 12
      },
      "tests/spine-v2-m2f-cross-plane-audit.test.js": {
        "tests": 31
      },
      "tests/spine-v2-m2f-deployment-storage.test.js": {
        "tests": 29
      },
      "tests/spine-v2-m2f-entry-wiring.test.js": {
        "tests": 16
      },
      "tests/spine-v2-m2f-verifier-preconnect.test.js": {
        "tests": 12
      },
      "tests/spine-v2-m3a-dialect-intent.test.js": {
        "tests": 4
      },
      "tests/spine-v2-m3a-module-state-adoption.test.js": {
        "tests": 7
      },
      "tests/spine-v2-m3a-physical-names.test.js": {
        "tests": 5
      },
      "tests/spine-v2-m3a-schema-migrations-ledger.test.js": {
        "tests": 13
      },
      "tests/spine-v2-m3b-postgresql-adapter.test.js": {
        "tests": 16
      },
      "tests/spine-v2-m3c-postgresql-application.test.js": {
        "tests": 11
      },
      "tests/spine-v2-m3p-dual-bundled-graphs.test.js": {
        "tests": 8
      },
      "tests/spine-v2-m4a-idempotency-recovery.test.js": {
        "tests": 12
      },
      "tests/spine-v2-m4b-leases-tenant-authority.test.js": {
        "tests": 12
      },
      "tests/spine-v2-m4c-http-sdk-admin-cli.test.js": {
        "tests": 12
      },
      "tests/spine-v3a-durable-jobs-postgresql.test.js": {
        "tests": 2
      },
      "tests/spine-v3a-durable-jobs-sqlite.test.js": {
        "tests": 27
      },
      "tests/spine-v3b-transactional-outbox-postgresql.test.js": {
        "tests": 10
      },
      "tests/spine-v3b-transactional-outbox-sqlite.test.js": {
        "tests": 9
      },
      "tests/spine-v3c-timer-consumers-postgresql.test.js": {
        "tests": 3
      },
      "tests/spine-v3c-timer-consumers-sqlite.test.js": {
        "tests": 12
      },
      "tests/spine-v4a-secrets-provider.test.js": {
        "tests": 13
      },
      "tests/spine-v4b-backup-restore-postgresql.test.js": {
        "tests": 4
      },
      "tests/spine-v4b-backup-restore-render-boundary.test.js": {
        "tests": 2
      },
      "tests/spine-v4b-backup-restore.test.js": {
        "tests": 20
      },
      "tests/spine-v4c-observability-export-postgresql.test.js": {
        "tests": 3
      },
      "tests/spine-v4c-observability-export.test.js": {
        "tests": 27
      },
      "tests/surface-budget.test.js": {
        "tests": 6
      },
      "tests/tour-claim.test.js": {
        "tests": 5
      },
      "tests/vercel-unshallow.test.js": {
        "tests": 8
      },
      "tests/work-legacy-task-migration.test.js": {
        "tests": 5
      },
      "tests/work-operations-e2e.test.js": {
        "tests": 13
      },
      "tests/work-operations-evidence.test.js": {
        "tests": 6
      },
      "tests/work-package-absence.test.js": {
        "tests": 4
      },
      "tests/work-provenance-and-actor.test.js": {
        "tests": 4
      },
      "tests/work-source-key-stability.test.js": {
        "tests": 3
      },
      "tests/workflow.test.js": {
        "tests": 4
      },
      "tests/writer-guard-covers-reads.test.js": {
        "tests": 4
      },
      "tests/writer-lease-renewal-postgresql.test.js": {
        "tests": 3
      },
      "tests/writer-lease-renewer.test.js": {
        "tests": 9
      }
    },
    "note": "Written by `node scripts/measure-suite.js --apply` from a real run on a clean tree. Never edit these numbers by hand: scripts/site-check.js verifies sha, testsTree, testFiles and the per-file map against the commit, so a record moved forward without a re-run fails the build."
  },
  "claims": [
    {
      "id": "C-01",
      "text": "Write a module manifest; the agent turns it into a migration, a service, a REST resource, an SDK method and Admin screens — with no page code.",
      "evidence": {
        "jtbd": "JTBD-01",
        "tests": [
          "tests/module-factory-e2e.test.js",
          "tests/generated-api-e2e.test.js",
          "tests/admin-modules.test.js",
          "tests/admin-core.test.js"
        ],
        "docs": [
          "docs/MODULE_FACTORY.md",
          "docs/ADMIN.md"
        ]
      },
      "limitation": "Generated CRUD only. The factory does not generate workflows or approvals for a custom object — that is still handwritten (JTBD-06, partially supported).",
      "surfaces": [
        "site",
        "readme",
        "launch"
      ]
    },
    {
      "id": "C-02",
      "text": "Generated objects reference each other: a foreign key, runtime target validation, schema metadata and an Admin selector, all from one field declaration.",
      "evidence": {
        "jtbd": "JTBD-01b",
        "tests": [
          "tests/reference-fields-e2e.test.js",
          "tests/reference-resolver.test.js",
          "tests/module-factory.test.js"
        ],
        "docs": [
          "docs/MODULE_FACTORY.md"
        ]
      },
      "limitation": "Generated-to-generated many-to-one only. Many-to-many, inverse collections, cascade delete and generated-to-core references do not exist.",
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "C-03",
      "text": "Commercial policy is deterministic code, not a model's judgement: a renewal at or above the threshold stops and waits for a named human.",
      "evidence": {
        "jtbd": "JTBD-02",
        "tests": [
          "tests/workflow.test.js",
          "tests/api.test.js"
        ],
        "docs": [
          "ARCHITECTURE.md",
          "DECISIONS.md"
        ]
      },
      "limitation": "Proven for the built-in renewal object and its single value threshold. A general policy engine over arbitrary custom objects does not exist.",
      "surfaces": [
        "site",
        "readme",
        "launch"
      ]
    },
    {
      "id": "C-04",
      "text": "The agent cannot approve on the human's behalf. A test asserts the refusal, so the boundary is a property of the system rather than a promise in a README.",
      "evidence": {
        "jtbd": "JTBD-02",
        "tests": [
          "tests/workflow.test.js"
        ],
        "docs": [
          "ARCHITECTURE.md"
        ],
        "testName": "approval workflow rejects an agent pretending to make the human decision"
      },
      "limitation": "In local-development mode the actor is asserted, not authenticated: no authentication ships, so an actor header there is not an identity. This holds a boundary against an honest agent, not against an attacker with network access.",
      "surfaces": [
        "site",
        "readme",
        "launch"
      ]
    },
    {
      "id": "C-05",
      "text": "Opportunities move through code-first pipeline stages under a server-authoritative action — the client asks, the server decides.",
      "evidence": {
        "jtbd": "JTBD-03",
        "tests": [
          "tests/opportunity-pipeline-e2e.test.js",
          "tests/pipeline-contract.test.js",
          "tests/admin-pipeline.test.js"
        ],
        "docs": [
          "docs/ACTIONS.md"
        ]
      },
      "limitation": "Pipelines are proven on the built-in Opportunity module. Configurable pipelines for generated custom objects are not claimed.",
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "C-06",
      "text": "A lead is captured, scored, routed, qualified and converted into Company, Contact and Opportunity through explicit actions, each one atomic and audited.",
      "evidence": {
        "jtbd": "JTBD-04, JTBD-05, JTBD-05b, JTBD-LI-01, JTBD-LI-02, JTBD-LI-04",
        "tests": [
          "tests/lead-qualification-e2e.test.js",
          "tests/lead-conversion-e2e.test.js",
          "tests/lead-intelligence-e2e.test.js"
        ],
        "docs": [
          "docs/LEAD_INTELLIGENCE.md"
        ]
      },
      "limitation": "Enrichment runs against a fixture provider — no real external data source is wired. The Lead model is the starter's, not a built-in core module.",
      "surfaces": [
        "site",
        "readme",
        "launch"
      ]
    },
    {
      "id": "C-07",
      "text": "Scoring is explainable and versioned: every score carries the fingerprint of the model version that produced it, so a number from last quarter can still be accounted for.",
      "evidence": {
        "jtbd": "JTBD-LI-02, JTBD-LI-07",
        "tests": [
          "tests/lead-intelligence-e2e.test.js",
          "tests/intelligence-contract.test.js"
        ],
        "docs": [
          "docs/LEAD_INTELLIGENCE.md"
        ]
      },
      "limitation": "Deterministic weighted rules, not a machine-learning model. Nothing trains, fits or backtests.",
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "C-08",
      "text": "Quotes price on the server from a catalog — one-time and recurring, flat, per-unit, volume and graduated tiers — and freeze into an immutable version when a discount goes for approval.",
      "evidence": {
        "jtbd": "JTBD-CO-01, JTBD-CO-03",
        "tests": [
          "tests/commercial-e2e.test.js",
          "tests/commercial-contract.test.js",
          "tests/admin-quotes.test.js"
        ],
        "docs": [
          "docs/COMMERCIAL_OPERATIONS.md"
        ]
      },
      "limitation": "Catalog sync runs against a fixture provider; no real external catalog (Stripe, Zuora, ERP) is connected. Money is integer cents with no FX — currencies are never summed.",
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "C-09",
      "text": "A signature envelope produces verified events and a hashed signed artifact, and exactly one immutable Order is built from the approved quote version.",
      "evidence": {
        "jtbd": "JTBD-CO-07",
        "tests": [
          "tests/signature-order-e2e.test.js",
          "tests/signature-contract.test.js",
          "tests/admin-signature.test.js"
        ],
        "docs": [
          "docs/SIGNATURE_ORDER.md"
        ]
      },
      "limitation": "A fixture signature provider with a test-only webhook key. No DocuSign, Adobe Sign or Dropbox Sign adapter exists, and the artifact hash is provider-reported rather than independently recomputed.",
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "C-10",
      "text": "A signed Order activates into a Commercial Contract, an immutable contract version, a Subscription and explicitly pending delivery and service obligations — every component classified, never guessed.",
      "evidence": {
        "jtbd": "JTBD-CS-01, JTBD-CS-02",
        "tests": [
          "tests/contracts-activation-e2e.test.js",
          "tests/contracts-contract.test.js",
          "tests/admin-contracts.test.js",
          "tests/lifecycle-amendment-execution-e2e.test.js",
          "tests/lifecycle-amendment-execution.test.js",
          "tests/signed-terms-e2e.test.js"
        ],
        "docs": [
          "docs/CONTRACT_ACTIVATION.md",
          "docs/RENEWAL_AMENDMENT.md"
        ],
        "facts": [
          "domain.lifecycle.package_native=package_native"
        ]
      },
      "limitation": "Terms frozen into the signed quote document retain signed-order provenance; legacy orders without signed terms can use explicitly labelled post-signature operational metadata. Operational dates are never promoted to signed terms. Governed renewal and amendment execution creates a successor agreement from its own signed Order, with immutable lineage and a derived line delta. Historical contracts and subscriptions are not edited. There is no automatic renewal, cancellation execution, billing or customer notification.",
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "C-11",
      "text": "Pending obligations hand over into a Delivery Project with work packages, milestones and an optional partner — atomically, idempotently, and across a package boundary the kernel never learns about.",
      "evidence": {
        "jtbd": "JTBD-DS-01",
        "tests": [
          "tests/delivery-handover-e2e.test.js",
          "tests/delivery-execution-e2e.test.js",
          "tests/admin-delivery.test.js"
        ],
        "docs": [
          "docs/DELIVERY_HANDOVER.md"
        ]
      },
      "limitation": "It hands work over and runs it through human-driven transitions. Nothing schedules, staffs, computes percent complete or bills. Deliverables and recorded customer acceptance exist as of M14b2, and acceptance there is evidence a user actor recorded — never an authenticated customer, a legal signature or authorization to bill.",
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "C-12",
      "text": "Delivery records what it consumed: append-only time and expense evidence, costed server-side by a versioned fingerprinted policy, with a reproducible contribution estimate grouped by currency.",
      "evidence": {
        "jtbd": "JTBD-DS-06, JTBD-DS-07",
        "tests": [
          "tests/delivery-economics-e2e.test.js"
        ],
        "docs": [
          "docs/DELIVERY_ECONOMICS.md"
        ]
      },
      "limitation": "Deliberately not a margin: no revenue recognition, no cost of goods sold, no ARR/MRR/TCV, no annualization, no FX. A project carrying a recurring obligation returns no estimate at all and says why.",
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "C-24",
      "text": "A pending service obligation activates into operational coverage and an immutable entitlement; support cases then move through a declared transition table with elapsed-time SLA evidence and human-recorded escalation.",
      "evidence": {
        "jtbd": "JTBD-SV-01, JTBD-SV-03, JTBD-SV-07",
        "tests": [
          "tests/service-operations-e2e.test.js",
          "tests/service-operations-evidence.test.js",
          "tests/service-operations-integration.test.js"
        ],
        "docs": [
          "docs/SERVICE_OPERATIONS.md",
          "examples/scenarios/service-sla-escalation.scenario.json"
        ]
      },
      "limitation": "No authenticated customer portal, notification delivery, business-hours calendar or automatic escalation ships. SLA evidence records elapsed-time observations; it is not a contractual breach determination, and a recorded escalation routes to nobody.",
      "surfaces": [
        "site"
      ]
    },
    {
      "id": "C-13",
      "text": "A customer-authored domain package attaches and detaches with the kernel's fingerprint unchanged, and reaches another package only through a capability it declares.",
      "evidence": {
        "jtbd": "JTBD-PK-01, JTBD-PK-02",
        "tests": [
          "tests/package-contract.test.js",
          "tests/custom-package-e2e.test.js",
          "tests/contracts-registry-review.test.js"
        ],
        "docs": [
          "docs/PACKAGE_AUTHORING.md"
        ],
        "facts": [
          "domain.commercial.package_native=package_native",
          "domain.contracts.package_native=package_native",
          "domain.customer_data.package_native=package_native",
          "domain.delivery.package_native=package_native",
          "domain.intelligence.package_native=package_native",
          "domain.lifecycle.package_native=package_native",
          "domain.service.package_native=package_native",
          "domain.signature.package_native=package_native",
          "domain.work.package_native=package_native"
        ]
      },
      "limitation": "The scaffold that starts one writes an empty package and nothing else: no business logic, no composition, no global identity-uniqueness check. There is no registry, no marketplace, no publication and no sandboxing — package code runs with the host process's authority. Detaching leaves its data behind; there is no uninstall.",
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "C-14",
      "text": "One command tells an agent what an application actually is — packages, capabilities, resources, actions, policies, providers — read from checked-in source, in a single deterministic JSON report.",
      "evidence": {
        "jtbd": "JTBD-AX-01, JTBD-AX-02",
        "tests": [
          "tests/app-inspect.test.js"
        ],
        "docs": [
          "docs/APPLICATION_INSPECTION.md",
          "docs/AGENT_HARNESS_COMPATIBILITY.md"
        ],
        "facts": [
          "rail.app_inspect.implemented=implemented",
          "rail.project_doctor.implemented=implemented",
          "rail.solution_check.implemented=implemented"
        ]
      },
      "limitation": "Source-only and read-only. It never opens the database, contacts a provider, reads a secret, or reports runtime, CI or authorization state — and it lists those blind spots as machine-readable limitations in its own output.",
      "surfaces": [
        "site",
        "readme",
        "launch"
      ]
    },
    {
      "id": "C-22",
      "text": "One command composes the whole thing and then inspects it: 76 modules, 9 packages, 71 resources, 64 actions, 7 policies and 1 providers, applied from manifests and driven end to end — then it prints the eleven things the inspector says it cannot see.",
      "evidence": {
        "tests": [
          "tests/app-inspect.test.js",
          "tests/contracts-activation-e2e.test.js",
          "tests/delivery-economics-e2e.test.js"
        ],
        "docs": [
          "docs/APPLICATION_INSPECTION.md"
        ],
        "repoFacts": [
          "npm run tour runs examples/starters/b2b-lead-qualification/install.mjs, which CI runs on every push, into a directory it keeps",
          "the counts are the app inspect report of that composed project",
          "scripts/tour.js exits non-zero if the composed application is ever empty"
        ],
        "facts": [
          "domain.commercial.package_native=package_native",
          "domain.contracts.package_native=package_native",
          "domain.customer_data.package_native=package_native",
          "domain.delivery.package_native=package_native",
          "domain.intelligence.package_native=package_native",
          "domain.lifecycle.package_native=package_native",
          "domain.service.package_native=package_native",
          "domain.signature.package_native=package_native",
          "domain.work.package_native=package_native"
        ]
      },
      "limitation": "It composes the starter's application, not yours, and it runs entirely locally against SQLite with no authentication. The counts describe what that starter applies; a different composition gives different numbers. Wall-clock time varies by machine and is deliberately not claimed.",
      "surfaces": [
        "site",
        "readme",
        "launch"
      ]
    },
    {
      "id": "C-21",
      "text": "The same refusal holds where the money is: an agent actor asking to approve a discounted quote is refused with a 403, and only a human user actor can decide.",
      "evidence": {
        "jtbd": "JTBD-CO-03",
        "tests": [
          "tests/commercial-e2e.test.js"
        ],
        "docs": [
          "docs/COMMERCIAL_OPERATIONS.md"
        ],
        "testName": "commercial e2e: approval boundary, revise/version-2, concurrency, fault injection, provider failures, drift",
        "assertion": "tests/commercial-e2e.test.js — quote.approve with actor { type: 'agent' } rejects with status 403 and code HUMAN_APPROVAL_REQUIRED"
      },
      "limitation": "The assertion lives inside a composite end-to-end test rather than a test named for it, so the citation is a file and a line rather than a test name. Extracting it into a named test is tracked in docs/strategy/GO_TO_MARKET.md; until then, cite the line.",
      "surfaces": [
        "site",
        "readme",
        "launch"
      ]
    },
    {
      "id": "C-15",
      "text": "A Solution Plan is a checked-in file with a contract and a canonical fingerprint, validated against a real inspection — so a plan written against a composition that has since moved reports itself stale.",
      "evidence": {
        "jtbd": "JTBD-AX-03",
        "tests": [
          "tests/solution-plan.test.js"
        ],
        "docs": [
          "docs/SOLUTION_PLAN.md"
        ],
        "facts": [
          "rail.solution_check.implemented=implemented",
          "rail.solution_verify.implemented=implemented"
        ]
      },
      "limitation": "A document contract, not a planner and not a runtime. Nothing executes a plan, and the validator refuses a plan that carries a command.",
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "C-16",
      "text": "Every mutation goes through a module service or a named workflow, and leaves an audit event and a step-level trace behind it.",
      "evidence": {
        "jtbd": "JTBD-02",
        "tests": [
          "tests/workflow.test.js",
          "tests/action-runtime-semantics.test.js",
          "tests/event-bus-outbox.test.js"
        ],
        "docs": [
          "ARCHITECTURE.md",
          "docs/ACTIONS.md"
        ]
      },
      "limitation": "Audit records what the process did under an asserted actor. It is not a tamper-evident or externally attestable log, and it is not a compliance control.",
      "surfaces": [
        "site",
        "readme",
        "launch"
      ]
    },
    {
      "id": "C-17",
      "text": "SQLite is Node's built-in node:sqlite. PostgreSQL requires one pinned runtime driver, pg@8.23.0. There is no ORM, no query builder, no build step and no framework underneath your framework.",
      "evidence": {
        "repoFacts": [
          "package.json.dependencies is exactly { pg: \"8.23.0\" }",
          "SQLite via node:sqlite",
          "the HTTP server and test runner are Node built-ins",
          "PostgreSQL uses the pinned pg@8.23.0 driver; there is no ORM"
        ],
        "tests": [
          "tests/spine-v2-m3b-postgresql-adapter.test.js",
          "tests/api.test.js"
        ],
        "docs": [
          "ARCHITECTURE.md",
          "AGENTS.md"
        ]
      },
      "limitation": "Applications that select PostgreSQL carry pg@8.23.0. The SQLite path still needs no third-party driver. This is not a production-readiness claim and not shared-database tenancy; composition is dedicated-database, not row tenancy.",
      "surfaces": [
        "site",
        "readme",
        "launch"
      ]
    },
    {
      "id": "C-18",
      "text": "The MCP server exposes project context and narrow write tools to a coding agent; anything that generates code or destroys state is dry-run unless you pass an explicit apply flag.",
      "evidence": {
        "jtbd": "JTBD-AX-02",
        "tests": [
          "tests/mcp.test.js",
          "tests/scaffold.test.js"
        ],
        "docs": [
          "docs/MCP.md"
        ]
      },
      "limitation": "Stdio only, local only. There is no hosted or authenticated MCP endpoint, and the server inherits the local process's authority.",
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "C-19",
      "text": "Generated modules evolve without rewriting history: explicit revisions, a checked-in state file and append-only named migrations.",
      "evidence": {
        "tests": [
          "tests/module-evolution.test.js",
          "tests/module-evolution-factory.test.js",
          "tests/module-migrations.test.js"
        ],
        "docs": [
          "docs/MODULE_EVOLUTION.md"
        ]
      },
      "limitation": "The view is source-only: what the checked-in revisions and migrations say is knowable; what a particular database has actually applied is not.",
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "C-20",
      "text": "The verification gate runs on every push — source checks and then the whole test suite — covering happy paths and the policy boundaries that matter: hostile input, transaction rollback, idempotency, concurrency and immutability among them.",
      "evidence": {
        "repoFacts": [
          "measuredAgainst in this file records the run: npm run verify, green, at the commit named there, with a fingerprint of the tests/ tree it was taken over",
          ".github/workflows/ci.yml runs verify and smoke on push and pull_request, and runs the public-claims gate over full history so the measurement can be traced"
        ],
        "docs": [
          "docs/QUALITY_GATES.md"
        ],
        "facts": [
          "rail.project_verify.implemented=implemented",
          "rail.scenario_run.implemented=implemented"
        ]
      },
      "limitation": "A test count measures effort, not correctness — read the adversarial-review categories in docs/QUALITY_GATES.md to see what is actually attacked. Real-browser tests are run manually and are not in CI.",
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "C-23",
      "text": "Five rules can be removed on purpose in one command, and the suite catches every one in about two seconds — naming the test that caught it. Anything that survives is reported as a gap, not omitted.",
      "evidence": {
        "tests": [
          "tests/falsify.test.js",
          "tests/module-factory.test.js",
          "tests/workflow.test.js"
        ],
        "docs": [
          "docs/FALSIFY.md"
        ],
        "repoFacts": [
          "npm run falsify at 6489982: 5 caught, 0 survived, 0 stale, 2.2s",
          "npm run falsify --only delivery-cost-rounding: caught by 'cost arithmetic is exact at every boundary' in 108.3s",
          "the run refuses to start over uncommitted target files and verifies every restore byte-for-byte"
        ]
      },
      "limitation": "It falsifies six named rules, not the claims in this ledger, and it proves only that a test holds each one — a rule that is wrong but faithfully defended passes every mutation. It is not mutation testing: nothing is generated or sampled, and no score is derived.",
      "surfaces": [
        "site",
        "readme",
        "launch"
      ]
    }
  ],
  "limitations": [
    {
      "id": "L-01",
      "headline": "No authentication ships: the framework authenticates nobody.",
      "text": "Production Spine v1 (ADR-038) gives the framework verified identity, organizations and memberships, server-authoritative authorization and one tenant per application instance — so tenancy and authorization now exist and are enforced. What does not exist is authentication: no login, password, session or OIDC implementation ships, and a deployment must supply the adapter that verifies the request. Production mode refuses to start without one. In local-development mode an actor header is accepted as an assertion and is not an identity, which is the default developer posture. This is not shared-database multi-tenancy and it is not a readiness claim.",
      "evidence": {
        "jtbd": "JTBD-15",
        "docs": [
          "docs/PROJECT_STATUS.md",
          "README.md",
          "DECISIONS.md"
        ],
        "tests": [
          "tests/production-spine.test.js",
          "tests/actor-fails-closed.test.js"
        ],
        "repoFacts": [
          "crm app inspect reports a productionPosture that refuses to be read as a readiness claim"
        ],
        "facts": [
          "spine.authentication.framework_verifier=absent",
          "spine.authorization.enforced=enforced",
          "spine.tenant.isolation.mode=one_tenant_per_instance",
          "spine.tenant.crm_data_plane_enforced=enforced_by_binding",
          "spine.multi_tenant_single_instance=refused_at_startup",
          "spine.identity.contract=1"
        ]
      },
      "surfaces": [
        "site",
        "readme",
        "launch"
      ]
    },
    {
      "id": "L-02",
      "headline": "Not shared-database tenancy.",
      "text": "createAccordoAppAsync can boot one tenant onto dedicated PostgreSQL databases. Shared-database row-level tenancy is not implemented, and this is not a production-readiness claim.",
      "evidence": {
        "docs": [
          "docs/PROJECT_STATUS.md",
          "docs/strategy/PLATFORM_CAPABILITIES.md"
        ],
        "facts": [
          "spine.postgresql.implemented=implemented"
        ]
      },
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "L-03",
      "headline": "The build benchmark has not been run.",
      "text": "The protocol is designed and published; no Successful Agent Build Rate exists yet. Any number you see quoted for this project is not ours.",
      "evidence": {
        "docs": [
          "docs/strategy/CRM_BUILD_BENCHMARK.md",
          "docs/PROJECT_STATUS.md"
        ],
        "facts": [
          "benchmark.build_rate.measured=not_measured",
          "benchmark.tool_selection.comparative=false"
        ]
      },
      "surfaces": [
        "site",
        "readme",
        "launch"
      ]
    },
    {
      "id": "L-04",
      "headline": "Timers exist; a service that runs them for you does not.",
      "text": "Durable jobs, a transactional outbox and scheduled asks exist for self-hosted applications that explicitly start a worker. Nothing autostarts; a timer opens an ask, never makes a decision, and no managed worker service or recurrence is included.",
      "evidence": {
        "jtbd": "JTBD-07, JTBD-10",
        "docs": [
          "docs/strategy/JOBS_AND_OUTBOX.md"
        ],
        "facts": [
          "spine.timer_consumers.implemented=implemented",
          "spine.managed_jobs_service.implemented=absent",
          "spine.durable_job_store.implemented=implemented",
          "spine.transactional_outbox.implemented=implemented"
        ]
      },
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "L-05",
      "headline": "No email, calendar or marketing integrations.",
      "text": "An in-memory notification provider contract exists. MK1 marketing records supplied funnel observations and human-reviewed proposals only; it has no sending, publishing or spending path.",
      "evidence": {
        "jtbd": "JTBD-14",
        "docs": [
          "docs/strategy/INTEGRATION_RUNTIME.md"
        ],
        "facts": [
          "marketing_runtime.implemented=implemented"
        ],
        "tests": [
          "tests/marketing-no-external-effect.test.js",
          "tests/marketing-e2e.test.js"
        ]
      },
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "L-06",
      "headline": "Bounded customer imports and logical identity; incomplete data operations.",
      "text": "Customer Data Foundation supports bounded JSON imports with preview/apply, per-row receipts and idempotency, deterministic duplicate candidates, and human-governed canonical identity as logical links. It does not provide CSV ingestion, physical merge, complete export/erasure, bulk editing, saved views or global search.",
      "evidence": {
        "docs": [
          "docs/benchmarks/CRM_JTBD_MATRIX.md"
        ],
        "tests": [
          "tests/customer-data-foundation.test.js"
        ],
        "facts": [
          "domain.customer_data.package_native=package_native",
          "cdf.full_cdp.implemented=absent"
        ]
      },
      "surfaces": [
        "site",
        "readme"
      ]
    },
    {
      "id": "L-08",
      "headline": "Ownership means vendored source: there is no framework dependency to bump.",
      "text": "The published create-accordo@0.1.0 scaffolds vendored source; it is the August 19 snapshot, not the current repository feature set. Use a current source checkout for the capabilities described here; upgrades require merging source (L-08). The framework is copied into the project, not installed as a framework library dependency. The accordo npm name is an empty reservation; the @accordo scope is claimed and deliberately empty.",
      "evidence": {
        "tests": [
          "tests/project-bootstrap.test.js"
        ],
        "docs": [
          "docs/PROJECT_STATUS.md",
          "docs/plans/project-bootstrap-installability.md"
        ],
        "repoFacts": [
          "the project bootstrap writes a project from an empty directory, dry-run unless --apply",
          "tests/create-accordo-package.test.js packs the publication twice, byte-identically, installs it offline and runs the generated project's own checks",
          "site/brand.json records the registry status and the source status as two separate fields, and scripts/distribution-check.js fails if either disagrees with the tree",
          "publication is staged from CI through OIDC trusted publishing and goes live only after a human approves the staged version with 2FA"
        ]
      },
      "surfaces": [
        "site",
        "readme",
        "launch"
      ]
    },
    {
      "id": "L-09",
      "headline": "Personal-data readiness requires deployment work beyond the foundation.",
      "text": "Customer Data Foundation supplies bounded import and identity governance, not complete personal-data operations. Authentication must be supplied by the deployment, and complete subject export and erasure remain absent; the framework alone does not establish compliance or suitability for real customer data. Lead scoring remains deterministic, versioned and explainable.",
      "evidence": {
        "jtbd": "JTBD-15",
        "tests": [
          "tests/lead-intelligence-e2e.test.js",
          "tests/customer-data-foundation.test.js"
        ],
        "docs": [
          "docs/strategy/DATA_GOVERNANCE.md",
          "docs/benchmarks/CRM_JTBD_MATRIX.md"
        ],
        "repoFacts": [
          "Customer Data Foundation records bounded imports and human-governed logical canonical identity without deleting or rewriting source records",
          "Complete subject export and erasure are not supplied by Customer Data Foundation",
          "scoring is a deterministic weighted model with a persisted version fingerprint (C-07)"
        ],
        "facts": [
          "spine.authentication.framework_verifier=absent",
          "cdf.full_cdp.implemented=absent",
          "customer_timeline.complete=absent"
        ]
      },
      "surfaces": [
        "site",
        "readme",
        "launch"
      ]
    },
    {
      "id": "L-07",
      "headline": "The framework is source you run; the Cloud hosts only what a Blueprint expresses.",
      "text": "The framework is not a hosted service: its output is an application in your repository that you run. The managed Cloud is a separate offer: a free workspace on shared capacity configured through a Project Blueprint (record types, fields and approval gates), and a paid Dedicated Cell for custom application code.",
      "evidence": {
        "docs": [
          "PRODUCT.md",
          "docs/strategy/CATEGORY.md"
        ]
      },
      "surfaces": [
        "site",
        "readme",
        "launch"
      ]
    },
    {
      "id": "L-10",
      "headline": "Nothing bills.",
      "text": "No invoice, payment, tax, usage rating, proration or revenue recognition exists, and MRR, ARR and TCV are not derived from contract data.",
      "evidence": {
        "jtbd": "JTBD-DS-10, JTBD-CS-05",
        "docs": [
          "docs/strategy/EXECUTION_ROADMAP.md",
          "docs/benchmarks/CRM_JTBD_MATRIX.md"
        ],
        "repoFacts": [
          "EXECUTION_ROADMAP.md lists invoicing, billing, payment, usage rating, proration, tax and FX as explicitly deferred",
          "packages/contracts/modules/subscription.module.json describes itself as a commercial activation record, not a billing engine, with no invoice schedule, usage rating, proration, payment, renewal or cancellation state",
          "JTBD-DS-10 (activate billing on accepted milestones) and JTBD-CS-05 (calculate MRR, ARR and TCV from real contract data) both read 'not supported'"
        ],
        "facts": [
          "billing.implemented=absent"
        ]
      },
      "surfaces": [
        "site"
      ]
    },
    {
      "id": "L-11",
      "headline": "Marketing proposals are local evidence; campaign execution is absent.",
      "text": "The optional MK1 package records supplied funnel counts, derives a drop insight and prepares a complete-or-refused proposal for human approval. It performs no audience execution, consent enforcement, sending, publishing, spending, scheduling or attribution. JTBD row promotion remains a separate review.",
      "evidence": {
        "jtbd": "JTBD-MK-01",
        "docs": [
          "docs/strategy/MARKETING_GROWTH_OPERATIONS.md",
          "docs/benchmarks/CRM_JTBD_MATRIX.md"
        ],
        "repoFacts": [
          "packages/marketing is optional and the default generated domain registry is empty",
          "MK1 approval creates local immutable evidence and declares no provider or external operation"
        ],
        "facts": [
          "marketing_runtime.implemented=implemented"
        ],
        "tests": [
          "tests/marketing-e2e.test.js",
          "tests/marketing-no-external-effect.test.js"
        ]
      },
      "surfaces": [
        "site"
      ]
    }
  ],
  "sourceVisibility": {
    "repository": "https://github.com/khaoss85/agent-crm",
    "note": "Evidence paths resolve in the public repository."
  }
}
