PRODUCT SYSTEM

The product can move toward release without pretending it is already released.

This local cockpit turns the WCN public-release gate into a machine-readable package: source freeze, build proof, route proof, public-claim review, deployment authorization, smoke evidence, rollback, and release export.

Release bindings
10
Local ready
10
Production bound
0
External required
10
Release ready
false
Evidence sections
8
Evidence ready
8
Open production gates
5
Evidence export ready
true
Execution phases
8
Plan ready
true
Blocking evidence
24
Executable
false
Cutover workflows
8
Local ready
8
Production bound
0
Cutover ready
false
Open production gates
5
Production bindings
10
Binding ready
true
External ready
false
Production bound
0
Open production gates
5
Submission steps
8
Submission ready
true
Authority evidence
5
Human Gate submission
false
Executable
false
Handoff items
1
Closure handoff
true
Missing candidates
5
Unsatisfied criteria
8
Partial closable
0
Executable
false
Adoption ready
0
Adoption waiting
0
Adoption blocked
0
API access controls
6
API local ready
true
API production ready
false
API external required
6
False boundary
deploy=false
secrets=false
domain=false
smoke=false
rollback=false
claims=false
customerSecret=false
paidSpend=false
unreviewedTool=false
closureEvidenceStored=false
partialGateCanClose=false
productionCompletionReady=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
Evolution adoption snapshot
target=release_evidence
ready=0
waiting=0
blocked=0
changes=none

Public release closure handoff package

This package fuses the release gate, release evidence, execution plan, cutover command center, production binding evidence, Human Gate submission, API access gate, and public-release closure matrix row into one takeover surface. It is locally ready but still blocked by missing external production evidence.

Closure Handoff API
wcn-product-release-closure-handoff-public-release · public-release

Production release gate

Closure matrix row: wcn-module-completion-closure-matrix-4-wcn_product_system-public-release · wcn-module-completion-execution-packet-4-wcn-product-system-public-release · wcn-module-completion-work-order-4-wcn_product_system-public-release
draft_not_submitted
Required candidates
5
Missing candidates
5
Closure criteria
8
Unsatisfied criteria
8
Partial closable
false
Executable
false
Closure blockers
5 required evidence candidates are missing for public-release.
8 closure criteria remain unsatisfied for public-release.
closureEvidenceStored=false and acceptedForHumanGateClosureReview=false.
closureReviewStatus=awaiting_dry_run_accepted_closure_evidence_bundle; closureEvidenceAcceptedLocal=false.
closureHumanGateDecisionStatus=draft_not_submitted; decisionSubmitted=false.
Production execution records, post-execution verification, rollback readiness, and ready-claim approval are still external Human Gate dependencies.
External public release production evidence has not been submitted to Human Gate.
The local handoff package cannot close public-release without approved release decision, deploy target, production build/deploy, smoke, rollback, API/secret custody, evidence export, and ready-claim approval.
Next action
Submit redacted candidate metadata for all 5 evidence requests in public-release.
Dry-run a complete closure evidence bundle with POST /api/agent-os/production-readiness/closure-evidence.
Submit a closure review draft with POST /api/agent-os/production-readiness/closure-review/public-release/human-gate-draft only after the closure evidence dry-run is accepted.
Record independent Human Gate review decisions without self-approval.
Attach real production execution records and post-execution verification outside local-only mode before any production-ready claim.
Submit all ten product release production binding evidence groups through the Human Gate package.
Keep productionDeployExecuted=false and productionReadyClaimAllowed=false until an approved production authority packet exists.
Validation
npm run check:mvp-local
npm run check:agent-os-product
npm run build
npm run check:agent-os-implementation
npm run check:agent-os-completion-roadmap
curl -s http://localhost:3000/api/agent-os/modules/completion-roadmap
curl -s http://localhost:3000/api/agent-os/modules/completion-work-orders
curl -s http://localhost:3000/api/agent-os/product-system/release-gate
curl -s http://localhost:3000/api/agent-os/product-system/release-execution-plan
curl -s http://localhost:3000/api/agent-os/product-system/release-cutover-command-center
curl -s http://localhost:3000/api/agent-os/product-system/production-binding-evidence
curl -s http://localhost:3000/api/agent-os/product-system/release-human-gate-submission
curl -s http://localhost:3000/api/agent-os/modules/completion-work-orders/execution-packets
curl -s http://localhost:3000/zh/agent-os/product-system
npm run check:agent-os-production-readiness
curl -s http://localhost:3000/api/agent-os/modules/completion-work-orders/closure-matrix
curl -s http://localhost:3000/api/agent-os/production-readiness/closure-criteria
curl -s http://localhost:3000/api/agent-os/production-readiness/closure-evidence
curl -s http://localhost:3000/api/agent-os/production-readiness/closure-review
curl -s http://localhost:3000/api/agent-os/production-readiness/closure-review/human-gate-queue
curl -s http://localhost:3000/api/agent-os/production-readiness/closure-review/public-release/human-gate-draft
curl -s http://localhost:3000/zh/agent-os/production-readiness
curl -s http://localhost:3000/api/agent-os/product-system/release-closure-handoff
curl -s http://localhost:3000/api/agent-os/product-system/release-evidence
curl -s http://localhost:3000/api/agent-os/product-system/api-access-gate
Authority evidence
public-release-evidence-01
public-release-evidence-05
public-release-evidence-02
public-release-evidence-03
public-release-evidence-04
Release gate bindings
wcn-product-release-approved-decision
wcn-product-release-source-truth-freeze
wcn-product-release-build-artifact
wcn-product-release-public-route-registry
wcn-product-release-public-claim-review
wcn-product-release-env-secret-boundary
wcn-product-release-deployment-target
wcn-product-release-post-deploy-smoke
wcn-product-release-rollback-plan
wcn-product-release-evidence-export
Evidence sections
wcn-release-evidence-human-gate-packet
wcn-release-evidence-source-truth-manifest
wcn-release-evidence-build-typecheck
wcn-release-evidence-route-claim-matrix
wcn-release-evidence-module-gate-snapshot
wcn-release-evidence-post-deploy-smoke-plan
wcn-release-evidence-rollback-plan
wcn-release-evidence-agent-handoff-context
Release phases
wcn-product-release-phase-01-release_approval
wcn-product-release-phase-02-source_truth_freeze
wcn-product-release-phase-03-build_verification
wcn-product-release-phase-04-route_claim_verification
wcn-product-release-phase-05-deployment_authorization
wcn-product-release-phase-06-post_deploy_smoke_preflight
wcn-product-release-phase-07-rollback_preflight
wcn-product-release-phase-08-release_evidence_export
API controls
wcn-product-api-account-identity
wcn-product-api-key-custody
wcn-product-api-v1-scope-map
wcn-product-api-user-provider-boundary
wcn-product-api-agent-tool-consent
wcn-product-api-audit-rate-revoke
Runbook
wcn-product-cutover-release-candidate-intake
wcn-product-cutover-source-truth-and-claim-freeze
wcn-product-cutover-build-route-claim-acceptance
wcn-product-cutover-api-access-and-external-agent-preflight
wcn-product-cutover-deployment-target-authorization
wcn-product-cutover-smoke-observability-monitoring
wcn-product-cutover-rollback-pause-rehearsal
wcn-product-cutover-release-evidence-handoff
Required production binding
wcn-product-release-prod-binding-approved-decision
wcn-product-release-prod-binding-deployment-target
wcn-product-release-prod-binding-env-secrets
wcn-product-release-prod-binding-build-deploy
wcn-product-release-prod-binding-smoke
wcn-product-release-prod-binding-rollback
wcn-product-release-prod-binding-api-key
wcn-product-release-prod-binding-customer-provider-secret
wcn-product-release-prod-binding-evidence-export
wcn-product-release-prod-binding-ready-claim
Human Gate inputs
wcn-product-release-submission-release-decision
wcn-product-release-submission-source-claim-freeze
wcn-product-release-submission-build-route-acceptance
wcn-product-release-submission-deployment-target
wcn-product-release-submission-post-deploy-smoke
wcn-product-release-submission-rollback-pause
wcn-product-release-submission-api-secret-custody
wcn-product-release-submission-evidence-ready-claim
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
productionOauthBound=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
unreviewedAgentToolUseAllowed=false
closureEvidenceStored=false
partialGateCanClose=false
productionCompletionReady=false
productionReadyClaimAllowed=false
productionAuthBound=false
productionChainWriteExecuted=false
realFundsTouched=false
productionSideEffectExecuted=false
source=lib/agent-os/product-release-closure-handoff.ts · localOnly=true · readOnly=true · productionBound=false · closureEvidenceStored=false · partialGateCanClose=false · productionCompletionReady=false · productionReadyClaimAllowed=false · productionSideEffectExecuted=false

Release Human Gate submission package

This package orders the public-release Human Gate submission: decision, source and claim freeze, build and route acceptance, deployment target, smoke evidence, rollback and emergency pause, API access and customer secret custody, evidence export, and production-ready claim approval.

Release Submission API
01 · release_decision_submission · 08-human-gate-governance

Release decision submission

Package the release scope, owner roster, rollback owner, public surfaces, and affected claims into the Human Gate go/no-go decision.

humanGateRequired=true
Upstream refs
lib/agent-os/product-release-gate.ts
lib/agent-os/product-release-evidence.ts
app/api/agent-os/production-authority-intake
Authority evidence
public-release-evidence-01
Human Gate inputs
Release candidate id, scope, and public surfaces
Release owner, deploy owner, rollback owner, and reviewer identity
Explicit go/no-go decision with evidence refs
Missing production evidence
Approved production release decision id
Authenticated reviewer identity proof
Production decision ledger attachment
Validation
npm run check:agent-os-product
npm run check:agent-os-governance
GET /api/agent-os/product-system/release-human-gate-submission
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
02 · source_truth_claim_submission · product-truth

Source truth and public claim submission

Bind the release to frozen source files, public route inventory, and claim review before any page or production-ready statement can be published.

humanGateRequired=true
Upstream refs
lib/agent-os/product-release-evidence.ts
lib/public-routes.ts
scripts/generate-whitepaper-v3-hash-manifest.mjs
Authority evidence
public-release-evidence-01
public-release-evidence-05
Human Gate inputs
Frozen source path list and release-candidate hash manifest
Public claim review for legal, investment, token, and production-readiness claims
Decision on archived versions and public navigation exposure
Missing production evidence
Signed source freeze manifest
Approved public claim exception list
Production-visible source version id
Validation
npm run check:whitepaper-v3
npm run check:public-route-registry
npm run check:public-claims
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
03 · build_route_acceptance_submission · 02-wcn-product-system

Build and route acceptance submission

Attach build, typecheck, route, and Agent OS implementation results to the release decision before deploy authorization is considered.

humanGateRequired=true
Upstream refs
package.json
app/[locale]/agent-os/product-system/page.tsx
scripts/check-agent-os-implementation.ts
Authority evidence
public-release-evidence-02
public-release-evidence-05
Human Gate inputs
Build command, source identifier, build timestamp, and artifact digest
Route registry result and public surface acceptance
Acknowledgement of known non-blocking warnings
Missing production evidence
Production build artifact id
Deployment provider build URL
Release decision attachment for build output
Validation
npm run build
npx tsc --noEmit --pretty false
npm run check:agent-os-implementation
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
04 · deployment_target_submission · 02-wcn-product-system

Deployment target submission

Bind production project, domain, branch, environment, deploy strategy, and operator separation before deploy execution can exist.

humanGateRequired=true
Upstream refs
lib/agent-os/product-release-execution-plan.ts
lib/agent-os/product-release-cutover-command-center.ts
lib/agent-os/product-release-production-binding-evidence.ts
Authority evidence
public-release-evidence-02
Human Gate inputs
Production project, domain, branch, and environment
Deploy strategy, deploy trigger owner, and approval owner
Rollback owner separated from deploy trigger owner
Missing production evidence
Approved production project id
Approved production domain
Deployment provider authorization record
Validation
npm run check:agent-os-product
npm run check:agent-os-production-readiness
GET /api/agent-os/product-system/production-binding-evidence
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
05 · post_deploy_smoke_submission · 05-platform-reliability-kernel

Post-deploy smoke submission

Require post-deploy HTTP, API, Agent OS, and public-claim smoke evidence before a release can be treated as externally verified.

humanGateRequired=true
Upstream refs
lib/agent-os/product-release-cutover-command-center.ts
lib/agent-os/production-observability-operator-console.ts
lib/agent-os/production-observability-external-binding-evidence.ts
Authority evidence
public-release-evidence-03
public-release-evidence-05
Human Gate inputs
Production base URL and smoke timestamp
HTTP status, content marker, API status, and Agent OS page evidence
Observer identity and incident threshold decision
Missing production evidence
Post-deploy HTTP smoke record
Production observability delivery proof
Human Gate attachment for smoke output
Validation
npm run check:agent-os-reliability
npm run check:agent-os-product
GET /api/agent-os/reliability-kernel/production-observability-external-binding-evidence
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
06 · rollback_pause_submission · 08-human-gate-governance

Rollback and emergency pause submission

Attach rollback command, threshold, owner, emergency pause authority, and execution record requirements before production release acceptance.

humanGateRequired=true
Upstream refs
lib/agent-os/product-release-cutover-command-center.ts
lib/agent-os/production-governance-ops-command-center.ts
app/api/agent-os/decision-ledger/emergency-pause/route.ts
Authority evidence
public-release-evidence-04
public-release-evidence-05
Human Gate inputs
Rollback owner and rollback command
Rollback threshold and emergency pause authority
Execution or rehearsal record attached to the release decision
Missing production evidence
Production rollback command record
Emergency pause authority roster
Rollback execution or rehearsal proof
Validation
npm run check:agent-os-governance
npm run check:agent-os-product
GET /api/agent-os/decision-ledger/production-governance-ops
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
07 · api_access_secret_custody_submission · 02-wcn-product-system

API access and customer secret custody submission

Separate WCN API key issuance from customer-owned provider secret custody, tool consent, budget, audit, rate limit, and revocation evidence.

humanGateRequired=true
Upstream refs
lib/agent-os/product-api-access-gate.ts
lib/agent-os/runtime-agent-api-authorization.ts
app/api/agent-os/product-system/api-access-gate/route.ts
Authority evidence
public-release-evidence-02
public-release-evidence-05
Human Gate inputs
Production API key issuance policy and scope
Customer-owned provider secret custody design
Tool consent, budget, audit, rate limit, and revocation proof
Missing production evidence
Production API key issuance record
Encrypted customer-owned provider secret storage proof
Revocation and audit evidence from production controls
Validation
npm run check:agent-os-product
npm run check:agent-os-runtime
GET /api/agent-os/product-system/api-access-gate
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
08 · evidence_export_ready_claim_submission · product-truth

Production evidence export and ready-claim submission

Require the final production evidence export and explicit production-ready claim approval before WCN can publicly claim the release is production-ready.

humanGateRequired=true
Upstream refs
lib/agent-os/product-release-production-binding-evidence.ts
lib/agent-os/production-readiness-external-evidence.ts
app/api/agent-os/production-readiness/external-evidence/route.ts
Authority evidence
public-release-evidence-05
Human Gate inputs
Production evidence export with build, route, claim, smoke, and rollback proof
Production-ready claim review and approval decision
Public publication owner and proof archive location
Missing production evidence
Production release evidence export id
Approved production-ready public claim decision
Public proof/archive publication record
Validation
npm run check:agent-os-product
npm run check:agent-os-production-readiness
GET /api/agent-os/production-readiness/external-evidence
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
source=lib/agent-os/product-release-human-gate-submission.ts · localOnly=true · productionBound=false · humanGateProductionSubmissionReady=false · productionReleaseExecutable=false · productionReadyClaimAllowed=false

Production release external binding matrix

This matrix makes the external production blockers explicit: release decision, deployment target, production environment and secrets, build/deploy proof, smoke, rollback, API key issuance, customer provider secret custody, evidence export, and production-ready claim approval.

Production Binding Evidence API
01 · approved_release_decision_binding · 08-human-gate-governance

Approved release decision binding

Bind the production release to an explicit Human Gate go/no-go decision before deploy, publish, API access, or production-ready claims.

productionBound=false
Local signals
lib/agent-os/product-release-gate.ts
lib/agent-os/product-release-evidence.ts
app/api/agent-os/decision-ledger/production-governance/route.ts
Human Gate inputs
Release scope and affected public surfaces
Release owner, deploy owner, and rollback owner
Explicit go/no-go decision id with evidence refs
Missing production evidence
Approved production release decision id
Authenticated reviewer identity proof
Production decision ledger persistence
Validation
npm run check:agent-os-product
npm run check:agent-os-governance
GET /api/agent-os/product-system/production-binding-evidence
Release gate bindings
approved_release_decision
Evidence sections
human_gate_release_packet
Release phases
release_approval
Observability workflows
release_candidate_intake
API controls
none
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
02 · deployment_target_binding · 02-wcn-product-system

Deployment target binding

Bind project, domain, branch, environment, deploy strategy, and operator authority before any production deploy is executable.

productionBound=false
Local signals
lib/agent-os/product-release-execution-plan.ts
lib/agent-os/product-release-cutover-command-center.ts
app/[locale]/agent-os/production-readiness/page.tsx
Human Gate inputs
Production project and domain
Branch, environment, and deploy strategy
Deploy trigger, approver, and rollback owner separation
Missing production evidence
Production project id
Approved production domain
Deploy authorization record
Validation
npm run check:agent-os-production-readiness
npm run check:agent-os-product
GET /api/agent-os/product-system/release-cutover-command-center
Release gate bindings
deployment_target
Evidence sections
agent_os_module_gate_snapshot
Release phases
deployment_authorization
Observability workflows
deployment_target_cutover_authorization
API controls
none
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
03 · production_environment_secret_binding · auth-rbac-security

Production environment and secret boundary binding

Prove production secrets are injected only through the approved deployment environment and never leak into local artifacts, public pages, or agent memory.

productionBound=false
Local signals
lib/agent-os/product-release-gate.ts
lib/agent-os/product-api-access-gate.ts
app/api/agent-os/production-readiness/route.ts
Human Gate inputs
Production secret owner
Rotation and revocation policy
No-secret-in-artifact evidence
Missing production evidence
Approved production secret store
Secret rotation owner
Production environment variable audit
Validation
npm run check:agent-os-product
npm run check:agent-os-gateway
GET /api/agent-os/product-system/api-access-gate
Release gate bindings
environment_secret_boundary
deployment_target
Evidence sections
agent_os_module_gate_snapshot
Release phases
deployment_authorization
Observability workflows
deployment_target_cutover_authorization
API controls
wcn_api_key_custody
user_owned_provider_api_boundary
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
04 · production_build_deploy_binding · 02-wcn-product-system

Production build and deploy binding

Connect the frozen release candidate, clean build, build artifact, deployment provider record, and deploy operator without executing deploy locally.

productionBound=false
Local signals
package.json
next.config.ts
lib/agent-os/product-release-execution-plan.ts
Human Gate inputs
Frozen source identifier
Build command, timestamp, and artifact digest
Deployment provider build URL
Missing production evidence
Production build artifact id
Production deployment id
Deploy operator identity proof
Validation
npx tsc --noEmit --pretty false
npm run build
GET /api/agent-os/product-system/production-binding-evidence
Release gate bindings
build_artifact
deployment_target
Evidence sections
build_typecheck_artifact
Release phases
build_verification
deployment_authorization
Observability workflows
build_route_claim_acceptance
API controls
none
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
05 · post_deploy_smoke_binding · 05-platform-reliability-kernel

Post-deploy smoke binding

Bind production smoke routes, expected invariants, operator identity, alert routing, and incident timeline before a release can be called healthy.

productionBound=false
Local signals
lib/agent-os/production-observability-cutover-evidence.ts
app/api/agent-os/reliability-kernel/production-observability-cutover-evidence/route.ts
app/[locale]/agent-os/reliability/page.tsx
Human Gate inputs
Approved production smoke route list
Expected response invariants
Alert destination and on-call owner
Missing production evidence
Production smoke execution record
External alert delivery proof
Production incident timeline
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/production-observability-cutover-evidence
GET /api/agent-os/product-system/production-binding-evidence
Release gate bindings
post_deploy_smoke
Evidence sections
post_deploy_smoke_plan
Release phases
post_deploy_smoke_preflight
Observability workflows
smoke_observability_monitoring
API controls
none
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
06 · rollback_execution_binding · 05-platform-reliability-kernel

Rollback execution binding

Bind rollback target, command, threshold, operator, emergency pause path, and public-claim correction plan before cutover.

productionBound=false
Local signals
lib/agent-os/reliability-side-effect-readiness.ts
lib/agent-os/production-governance-ops-command-center.ts
app/api/agent-os/decision-ledger/emergency-pause/route.ts
Human Gate inputs
Rollback command and target
Rollback threshold and owner
Emergency pause roster and public-claim correction owner
Missing production evidence
Production rollback execution proof
Production emergency pause roster
Public-claim correction evidence
Validation
npm run check:agent-os-reliability
npm run check:agent-os-governance
GET /api/agent-os/decision-ledger/production-governance-ops
Release gate bindings
rollback_plan
Evidence sections
rollback_evidence_plan
Release phases
rollback_preflight
Observability workflows
rollback_pause_rehearsal
API controls
audit_rate_limit_revocation
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
07 · production_api_key_issuance_binding · developer-platform

Production API key issuance binding

Bind account identity, API key custody, /api/v1 scopes, rate limits, audit export, and revocation before external agents can call production WCN APIs.

productionBound=false
Local signals
lib/agent-os/product-api-access-gate.ts
app/api/agent-os/product-system/api-access-gate/route.ts
app/api/v1
Human Gate inputs
Allowed production API scopes
API key custody and rotation policy
Rate limit, audit, and revocation owner
Missing production evidence
Production WCN API key issuance evidence
Production /api/v1 scope map
Production audit and revocation proof
Validation
npm run check:agent-os-product
npm run check:agent-os-gateway
GET /api/agent-os/product-system/api-access-gate
Release gate bindings
environment_secret_boundary
Evidence sections
public_route_claim_matrix
Release phases
deployment_authorization
Observability workflows
api_access_and_external_agent_preflight
API controls
account_registration_identity
wcn_api_key_custody
scoped_v1_protocol_api
audit_rate_limit_revocation
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
08 · customer_provider_secret_custody_binding · 04-agent-interoperability-gateway

Customer provider secret custody binding

Bind encrypted customer-owned provider secrets, explicit consent, spend limits, retention, deletion, and no raw-secret access for runtime agents.

productionBound=false
Local signals
lib/agent-os/product-api-access-gate.ts
lib/agent-os/production-interoperability-controls.ts
lib/agent-os/runtime-agent-api-authorization.ts
Human Gate inputs
Customer consent and provider/model allowlist
Encrypted secret custody policy
Budget, retention, deletion, and audit owner
Missing production evidence
Encrypted customer-owned provider secret storage
Production consent and budget record
Runtime no-raw-secret enforcement proof
Validation
npm run check:agent-os-product
npm run check:agent-os-gateway
npm run check:agent-os-runtime
Release gate bindings
environment_secret_boundary
Evidence sections
public_route_claim_matrix
Release phases
deployment_authorization
Observability workflows
api_access_and_external_agent_preflight
API controls
user_owned_provider_api_boundary
agent_tool_consent_budget
audit_rate_limit_revocation
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
09 · production_evidence_export_binding · 01-meta-agent-os

Production release evidence export binding

Export a durable release package for future Codex, Claude Code, WCN agents, Human Gate reviewers, production operators, and external auditors.

productionBound=false
Local signals
lib/agent-os/product-release-evidence.ts
lib/agent-os/system-handoff.ts
app/api/agent-os/system-handoff/route.ts
Human Gate inputs
Final go/no-go disposition
Accepted residual risk list
Production operator and follow-up owner list
Missing production evidence
Production release evidence export id
Production evidence hash or immutable storage pointer
Reviewer-readable final handoff packet
Validation
npm run check:agent-os-implementation
npm run check:composition-contracts
GET /api/agent-os/system-handoff
Release gate bindings
release_evidence_export
Evidence sections
agent_handoff_context_pack
Release phases
release_evidence_export
Observability workflows
release_evidence_handoff
API controls
none
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
10 · production_ready_claim_approval_binding · 08-human-gate-governance

Production-ready claim approval binding

Block public production-ready claims until release approval, deploy proof, smoke proof, rollback readiness, evidence export, and residual risk acceptance all exist.

productionBound=false
Local signals
lib/agent-os/production-readiness.ts
lib/agent-os/product-release-production-binding-evidence.ts
app/api/agent-os/production-readiness/route.ts
Human Gate inputs
Production-ready claim approval
Residual risk acceptance
Public claim correction owner
Missing production evidence
Production-ready claim approval id
Accepted residual risk record
Public production-ready statement approval
Validation
npm run check:agent-os-production-readiness
npm run check:agent-os-product
GET /api/agent-os/product-system/production-binding-evidence
Release gate bindings
approved_release_decision
post_deploy_smoke
release_evidence_export
Evidence sections
human_gate_release_packet
agent_handoff_context_pack
Release phases
release_approval
post_deploy_smoke_preflight
release_evidence_export
Observability workflows
release_evidence_handoff
API controls
none
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
source=lib/agent-os/product-release-production-binding-evidence.ts · localOnly=true · productionBound=false · productionExternalBindingsReady=false · productionReadyClaimAllowed=false

Local release cutover command center

This command center connects release candidate intake, source and claim freeze, build acceptance, API access preflight, deployment authorization, smoke monitoring, rollback rehearsal, and evidence handoff into a local go/no-go surface.

Release Cutover API
01 · wcn-product-cutover-release-candidate-intake · release_candidate_intake

Release candidate intake

Package the release candidate scope, public surfaces, owner roster, and Human Gate release decision requirements before cutover.

productionBound=false
Operator inputs
Release candidate id and scope
Public surfaces, API surfaces, and affected claims
Release owner, rollback owner, and Human Gate decision target
Local signals
lib/agent-os/product-release-gate.ts
lib/agent-os/product-release-evidence.ts
app/api/agent-os/product-system/release-gate/route.ts
Runbook
Open the release gate and release evidence reports for the candidate.
Confirm each public surface has a source-truth anchor and owner.
Keep the candidate local until a Human Gate release decision exists.
Human Gate inputs
Release scope and affected public surfaces
Release owner and rollback owner
Explicit go/no-go decision id
Missing production evidence
Approved release Human Gate decision
Production release owner roster
Release candidate artifact id
Release phases
release_approval
API controls
Observability workflows
Governance workflows
production_authority_intake
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
02 · wcn-product-cutover-source-truth-and-claim-freeze · source_truth_and_claim_freeze

Source truth and claim freeze

Freeze source paths, public routes, whitepaper v3 surfaces, and public claims before any production-ready statement.

productionBound=false
Operator inputs
Frozen source path list
Public route and canonical URL list
Public claim review and exception list
Local signals
content/wcn-public/Documents/0-Foundational
app/brand/whitepaper/v3/page.tsx
lib/public-routes.ts
Runbook
Freeze source truth and route scope for the release candidate.
Attach claim review evidence for legal, investment, token, production readiness, and AI autonomy claims.
Downgrade unsupported claims before Human Gate review.
Human Gate inputs
Frozen source-truth manifest
Approved public claim exception list
Decision on archive visibility for old versions
Missing production evidence
Signed source freeze manifest
Production route crawl result
Approved public claim review export
Release phases
source_truth_freeze
route_claim_verification
API controls
Observability workflows
Governance workflows
decision_audit_export_handoff
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
03 · wcn-product-cutover-build-route-claim-acceptance · build_route_claim_acceptance

Build, route, and claim acceptance

Bind clean build, typecheck, route registry, and public claim checks into the cutover go/no-go packet.

productionBound=false
Operator inputs
Build command and artifact output
Typecheck result and known warning disposition
Route and claim verification result
Local signals
package.json
next.config.ts
scripts/check-public-route-registry.ts
Runbook
Run the local build and typecheck from the frozen candidate.
Verify public route registry and proxy access.
Attach claim review result before calling the candidate release-ready.
Human Gate inputs
Build output and artifact digest
Route registry acceptance
Public claim acceptance or downgrade decision
Missing production evidence
Production build artifact URL
Production canonical URL crawl
Release decision attachment for build and route proof
Release phases
build_verification
route_claim_verification
API controls
Observability workflows
Governance workflows
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
04 · wcn-product-cutover-api-access-and-external-agent-preflight · api_access_and_external_agent_preflight

API access and external agent preflight

Keep registration, WCN API keys, scoped /api/v1 access, user-owned provider APIs, budget, audit, rate limit, and revocation in the release packet.

productionBound=false
Operator inputs
Included API surfaces and scopes
User-owned provider API policy
Budget, consent, audit, rate-limit, and revocation rules
Local signals
lib/agent-os/product-api-access-gate.ts
app/api/agent-os/product-system/api-access-gate/route.ts
app/api/v1
Runbook
Verify every external-facing API surface maps to explicit scopes and audit rules.
Confirm user-owned provider secrets remain outside runtime-agent raw context.
Block cutover when budget, consent, rate limit, or revocation policy is missing.
Human Gate inputs
Allowed production API scopes
User provider secret custody policy
Budget, audit, rate-limit, and revocation owner
Missing production evidence
Production API key issuance evidence
Encrypted customer-owned provider secret storage
Production audit/rate-limit/revocation proof
Release phases
deployment_authorization
API controls
account_registration_identity
wcn_api_key_custody
scoped_v1_protocol_api
user_owned_provider_api_boundary
agent_tool_consent_budget
audit_rate_limit_revocation
Observability workflows
Governance workflows
authenticated_reviewer_session
mfa_role_matrix_preflight
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
05 · wcn-product-cutover-deployment-target-authorization · deployment_target_cutover_authorization

Deployment target cutover authorization

Prepare the production project, domain, branch, environment, secret boundary, and deploy operator decision without executing deploy.

productionBound=false
Operator inputs
Production project, domain, branch, and environment
Deploy trigger owner and approver owner
Secret boundary and no-secret-in-artifact evidence
Local signals
lib/agent-os/product-release-execution-plan.ts
lib/agent-os/production-readiness.ts
app/[locale]/agent-os/production-readiness/page.tsx
Runbook
Confirm the target project and domain are approved by Human Gate.
Bind deploy trigger and deploy approval to distinct accountable humans.
Keep productionDeployExecuted=false and productionSecretsLoaded=false in local reports.
Human Gate inputs
Deployment target authorization
Secret owner and rotation policy
Deploy trigger, approver, and rollback owner
Missing production evidence
Production deploy target
Production environment binding
Production secret boundary evidence
Release phases
deployment_authorization
API controls
Observability workflows
release_observability_handoff
Governance workflows
release_deploy_chain_funds_guardrail
decision_audit_export_handoff
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
06 · wcn-product-cutover-smoke-observability-monitoring · smoke_observability_monitoring

Smoke and observability monitoring

Prepare production HTTP smoke, alert routing, incident timeline, rollback threshold, and evidence export for the cutover window.

productionBound=false
Operator inputs
Smoke route list and response invariants
Alert destination and on-call owner
Incident escalation and rollback threshold
Local signals
lib/agent-os/production-observability-operator-console.ts
app/api/agent-os/reliability-kernel/production-operator-console/route.ts
app/api/agent-os/reliability-kernel/operations-evidence/route.ts
Runbook
Prepare production smoke routes and expected response invariants.
Map critical alerts to on-call owner and Human Gate escalation.
Block release-ready claims until smoke and observability evidence are attached.
Human Gate inputs
Approved smoke route list
On-call and escalation owner
Rollback or pause threshold
Missing production evidence
Production smoke execution record
External alert delivery channel
Production incident timeline evidence
Release phases
post_deploy_smoke_preflight
API controls
Observability workflows
production_smoke_monitoring
alert_triage
incident_escalation
release_observability_handoff
Governance workflows
readiness_review_queue_triage
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
07 · wcn-product-cutover-rollback-pause-rehearsal · rollback_pause_rehearsal

Rollback and emergency pause rehearsal

Prepare rollback commands, emergency pause authority, public-claim correction, and operator identities before cutover.

productionBound=false
Operator inputs
Rollback command and target
Emergency pause operator and expiry
Public-claim correction plan
Local signals
lib/agent-os/reliability-side-effect-readiness.ts
lib/agent-os/production-governance-ops-command-center.ts
app/api/agent-os/decision-ledger/emergency-pause/route.ts
Runbook
Confirm rollback owner and emergency pause owner are named.
Record conditions that trigger rollback, pause, or public-claim correction.
Keep productionRollbackExecuted=false until real cutover approval exists.
Human Gate inputs
Rollback owner and rollback command
Emergency pause roster and authority
Public-claim correction owner
Missing production evidence
Production rollback execution proof
Production emergency pause roster
Public-claim correction evidence
Release phases
rollback_preflight
API controls
audit_rate_limit_revocation
Observability workflows
rollback_readiness
audit_export
Governance workflows
emergency_pause_rehearsal
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
08 · wcn-product-cutover-release-evidence-handoff · release_evidence_handoff

Release evidence handoff

Export the cutover packet for future Codex, Claude Code, WCN agents, Human Gate reviewers, and production operators.

productionBound=false
Operator inputs
Release evidence export
Cutover go/no-go disposition
Residual risk and follow-up owner list
Local signals
lib/agent-os/product-release-evidence.ts
lib/agent-os/system-handoff.ts
app/api/agent-os/system-handoff/route.ts
Runbook
Export the release evidence package and command center report.
Attach remaining production gaps and false boundaries to the handoff.
Keep production-ready claims blocked until Human Gate approves the final cutover evidence.
Human Gate inputs
Final go/no-go disposition
Accepted residual risk list
Production operator and follow-up owner list
Missing production evidence
Production release evidence export
Final production cutover decision
Production-ready claim approval
Release phases
release_evidence_export
API controls
Observability workflows
audit_export
Governance workflows
decision_audit_export_handoff
False boundary
productionDeployExecuted=false
productionSecretsLoaded=false
productionDomainTouched=false
productionSmokeExecuted=false
productionRollbackExecuted=false
publicClaimsPublished=false
productionApiKeyIssued=false
customerSecretStored=false
customerSecretLoaded=false
runtimeAgentCanReadRawSecret=false
externalProviderCallExecuted=false
paidModelSpendExecuted=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
source=lib/agent-os/product-release-cutover-command-center.ts · localOnly=true · productionBound=false · productionReleaseCutoverReady=false · productionReadyClaimAllowed=false

Local release execution plan

This execution plan turns the release gate and evidence export into ordered phases: approval, source freeze, build, route and claim checks, deployment authorization, smoke preflight, rollback preflight, and release evidence export.

Release Execution Plan API
01 · release_approval · 08-human-gate-governance

Human Gate release approval

executable=false
Release gate bindings
wcn-product-release-approved-decision
Evidence sections
wcn-release-evidence-human-gate-packet
Local signals
app/api/agent-os/decision-ledger/route.ts
app/api/agent-os/decision-ledger/[decisionId]/review/route.ts
lib/agent-os/production-governance.ts
lib/agent-os/product-release-gate.ts
app/api/agent-os/decision-ledger/production-governance/route.ts
app/api/agent-os/product-system/release-gate/route.ts
Validation
npm run check:agent-os-governance
GET /api/agent-os/decision-ledger/production-governance
npm run check:agent-os-product
npm run check:agent-os-production-readiness
Human Gate inputs
Create a release decision with explicit scope, release owner, rollback owner, and affected public surfaces.
Require authenticated reviewer identity and segregation-of-duties evidence before approval.
Attach all release evidence ids before the decision can authorize deployment.
Release scope, public surfaces, release owner, rollback owner, and affected claims.
Authenticated reviewer identity with segregation-of-duties evidence.
Explicit approval or rejection decision linked to the evidence export.
Missing production evidence
Approved production release decision id.
Reviewer identity proof from production auth.
Decision ledger storage in production.
Next action
Collect an approved release decision with release scope, owner, rollback owner, and evidence refs before any production deploy.
02 · source_truth_freeze · product-truth

Source-truth freeze

executable=false
Release gate bindings
wcn-product-release-source-truth-freeze
Evidence sections
wcn-release-evidence-source-truth-manifest
Local signals
docs/agent-os/modules/02-wcn-product-system.deep.md
content/wcn-public
app/brand/whitepaper/v3/page.tsx
content/wcn-public/Documents/0-Foundational
scripts/generate-whitepaper-v3-hash-manifest.mjs
Validation
npm run check:public-claims
npm run check:public-route-registry
npm run check:whitepaper-v3
Human Gate inputs
Freeze source documents, route list, release notes, and public claim registry for the release candidate.
Record the exact source paths and hash manifest used to build the public surface.
Reject manual edits to generated public artifacts after freeze.
Frozen source path list and release-candidate hash manifest.
Public claim review notes for legal, investment, token, and production-readiness claims.
Decision on whether old versions remain archived or are excluded from public navigation.
Missing production evidence
Final signed source freeze manifest.
Approved public claim exception list.
Production-visible source version id.
Next action
Freeze the source paths, hash manifest, release notes, public routes, and claim registry for the release candidate.
03 · build_verification · 02-wcn-product-system

Build and typecheck verification

executable=false
Release gate bindings
wcn-product-release-build-artifact
Evidence sections
wcn-release-evidence-build-typecheck
Local signals
npm run build
.next
next.config.ts
package.json
Validation
npm run build
npx tsc --noEmit --pretty false
npm run lint
Human Gate inputs
Run a clean production build from the frozen source candidate.
Record build command, commit or worktree identifier, timestamp, and artifact digest.
Attach build output and warnings to the release decision.
Build command, source identifier, build timestamp, and artifact digest.
Acknowledgement of known non-blocking lint warnings.
Decision that the build artifact is approved for a named deployment target.
Missing production evidence
Production build artifact id.
Deployment provider build URL.
Release decision attachment for build output.
Next action
Run a clean production build and typecheck from frozen source, then attach artifact output to the release packet.
04 · route_claim_verification · product-truth

Public route and claim verification

executable=false
Release gate bindings
wcn-product-release-public-route-registry, wcn-product-release-public-claim-review
Evidence sections
wcn-release-evidence-route-claim-matrix
Local signals
lib/public-routes.ts
proxy.ts
app/[locale]/agent-os/product-system/page.tsx
npm run check:public-claims
app/brand/whitepaper/v3/page.tsx
docs/agent-os/modules/02-wcn-product-system.deep.md
Validation
npm run check:public-route-registry
npm run check:agent-os-implementation
npm run check:public-claims
npm run check:agent-os-production-readiness
Human Gate inputs
Verify every public release route is registered, crawlable, and not accidentally auth-gated.
Record localized canonical routes and API smoke paths for release verification.
Block release if proxy or route registry drift is detected.
Review public claims for legal, investment, token, AI autonomy, and production-readiness overclaims.
Attach source evidence or downgrade each unsupported public claim to draft language.
Require Human Gate approval for high-impact public statements before publish.
Missing production evidence
Production route crawl result.
Production canonical URL evidence.
Approved claim review export.
Next action
Verify public routes, proxy access, canonical paths, and claim evidence before any public publication claim.
05 · deployment_authorization · 02-wcn-product-system

Deployment target authorization

executable=false
Release gate bindings
wcn-product-release-env-secret-boundary, wcn-product-release-deployment-target
Evidence sections
wcn-release-evidence-module-gate-snapshot
Local signals
proxy.ts
lib/core/api-response.ts
app/api/agent-os/production-readiness/route.ts
app/api/agent-os/product-system/release-gate/route.ts
app/[locale]/agent-os/production-readiness/page.tsx
lib/agent-os/production-readiness.ts
Validation
npm run lint
GET /api/agent-os/production-readiness
npm run check:agent-os-product
npm run check:agent-os-production-readiness
npm run check:agent-os-modules
npm run check:agent-os-evolution
npm run check:agent-os-implementation
npm run check:composition-contracts
Human Gate inputs
Confirm the release candidate does not load production secrets in local-only mode.
Bind production environment variables through approved deployment settings only.
Record secret owner, rotation policy, and no-secret-in-artifact evidence.
Select the production project, domain, branch, environment, and deploy strategy under Human Gate approval.
Record who can trigger deploy, who can approve deploy, and who can roll it back.
Do not allow local MVP evidence to substitute for deployment authorization.
Missing production evidence
Approved disposition for remaining partial production gates.
Production owner roster.
Release-scoped module gate export.
Next action
Bind the target project, domain, branch, environment, secret boundary, and release-blocking module gate disposition under Human Gate.
06 · post_deploy_smoke_preflight · 05-platform-reliability-kernel

Post-deploy smoke preflight

executable=false
Release gate bindings
wcn-product-release-post-deploy-smoke
Evidence sections
wcn-release-evidence-post-deploy-smoke-plan
Local signals
lib/agent-os/production-observability.ts
app/api/agent-os/reliability-kernel/production-observability/route.ts
app/[locale]/agent-os/reliability/page.tsx
app/[locale]/agent-os/production-readiness/page.tsx
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/production-observability
GET /api/agent-os/production-readiness
Human Gate inputs
Run production HTTP smoke checks after deployment against the approved domain.
Capture status code, route, timestamp, operator identity, and response invariant.
Attach smoke evidence to both release decision and production observability timeline.
Production domain, required routes, expected statuses, and response invariants.
Smoke operator identity and escalation owner.
Decision on thresholds that trigger rollback or pause.
Missing production evidence
Post-deploy HTTP smoke output from production domain.
Production observability timeline entry.
Operator identity attached to smoke record.
Next action
Prepare production smoke routes, expected invariants, operator identity, escalation owner, and rollback thresholds before deploy.
07 · rollback_preflight · 05-platform-reliability-kernel

Rollback preflight

executable=false
Release gate bindings
wcn-product-release-rollback-plan
Evidence sections
wcn-release-evidence-rollback-plan
Local signals
lib/agent-os/reliability-kernel.ts
app/api/agent-os/reliability-kernel/observability/route.ts
app/[locale]/agent-os/reliability/page.tsx
lib/agent-os/production-observability.ts
app/api/agent-os/reliability-kernel/production-observability/route.ts
Validation
npm run check:agent-os-reliability
npm run check:agent-os-governance
npm run check:agent-os-production-readiness
Human Gate inputs
Record rollback command, owner, threshold, and time window before release.
Connect rollback execution to an authenticated operator and incident timeline.
Require Human Gate for high-impact rollback decisions affecting public claims or user data.
Rollback command, rollback owner, trigger threshold, and execution window.
Decision on whether rollback can be operator-triggered or requires Human Gate.
Public claim correction plan if rollback affects already published material.
Missing production evidence
Production rollback target and command.
Rollback owner identity.
Rollback execution or dry-run evidence from production tooling.
Next action
Record rollback target, command, owner, trigger threshold, and public-claim correction plan before release.
08 · release_evidence_export · 01-meta-agent-os

Release evidence export

executable=false
Release gate bindings
wcn-product-release-evidence-export
Evidence sections
wcn-release-evidence-agent-handoff-context
Local signals
app/api/agent-os/modules/route.ts
app/api/agent-os/production-readiness/route.ts
app/api/agent-os/product-system/release-gate/route.ts
app/api/agent-os/evolution-ledger/adoption-queue/route.ts
app/api/agent-os/product-system/release-evidence/route.ts
app/api/agent-os/product-system/api-access-gate/route.ts
Validation
npm run check:agent-os-implementation
GET /api/agent-os/product-system/release-gate
npm run check:agent-os-product
npm run check:agent-os-evolution
Human Gate inputs
Export the release package with module gates, build proof, route proof, claim review, smoke evidence, and rollback plan.
Store export hash and decision id in the evolution ledger or release ledger.
Make the package readable by future Codex, Claude Code, or external WCN maintenance agents.
Which agent system is allowed to continue release preparation.
Scope limits for Codex, Claude Code, or external maintenance agents.
Evidence package URL or file path that future agents must treat as handoff truth.
Missing production evidence
Human-approved handoff owner.
Production evidence package location.
Release continuation task order.
Next action
Export the full release evidence package and handoff context for future Codex, Claude Code, and WCN maintenance agents.
Command plan
npm run check:agent-os-product
npm run check:agent-os-production-readiness
npm run check:agent-os-governance
npm run check:agent-os-reliability
npm run check:agent-os-implementation
npm run check:composition-contracts
npx tsc --noEmit --pretty false
npm run build
GET /api/agent-os/product-system/release-execution-plan
GET /zh/agent-os/product-system
False boundary
deploy=false
secrets=false
domain=false
smoke=false
rollback=false
claims=false
sideEffect=false
productionReleaseExecutable=false
productionReadyClaimAllowed=false
source=lib/agent-os/product-release-execution-plan.ts · localOnly=true · productionBound=false

User API access gate

This package connects registration, WCN API keys, scoped /api/v1 routes, user-owned provider API boundaries, agent tool consent, budget, audit, rate limit, and revocation into one local product gate.

account_registration_identity · 02-wcn-product-system

Account registration and identity surface

productionBound=false
Product surface: Signup / Login / Dashboard API Keys
Local signals
app/[locale]/signup/ui.tsx
app/[locale]/login/ui.tsx
app/[locale]/dashboard/api-keys/page.tsx
Required production binding
Bind user accounts to production auth sessions before any user-owned API or WCN API credential can be used.
Record organization, role, node ownership, and terms acceptance before issuing broad scopes.
Require Human Gate for role elevation, wildcard scopes, production connector access, or account-level custody changes.
Validation
npm run check:agent-os-product
npm run check:agent-os-governance
wcn_api_key_custody · auth-rbac-security

WCN API key custody

productionBound=false
Product surface: Dashboard API Key -> WCN /api/v1
Local signals
prisma/schema.prisma model ApiKey
lib/modules/apikeys/service.ts
app/api/apikeys/route.ts
app/[locale]/dashboard/api-keys/ui.tsx
Required production binding
Hash, scope, rotate, revoke, expire, and rate-limit WCN API keys under authenticated ownership.
Show raw WCN API keys exactly once and prevent raw keys from logs, public pages, Agent OS exports, and runtime-agent memory.
Record key owner, node binding, scope, rate plan, lastUsedAt, revocation authority, and audit export.
Validation
npm run check:agent-os-gateway
npm run check:agent-os-product
scoped_v1_protocol_api · developer-platform

Scoped WCN protocol API surface

productionBound=false
Product surface: Bearer wcn_* -> /api/v1/*
Local signals
lib/modules/apikeys/middleware.ts
app/api/v1/projects/route.ts
app/api/v1/nodes/route.ts
app/api/v1/deals/route.ts
app/api/v1/ingest/route.ts
Required production binding
Map each public protocol endpoint to explicit scopes, idempotency behavior, audit ownership, and rollback policy.
Keep broad writes behind quarantine or review when they affect proof, settlement, governance, public claims, or chain anchors.
Export a route and scope matrix so external agents can call WCN without inheriting internal authority.
Validation
npm run check:agent-os-gateway
npm run check:agent-os-implementation
user_owned_provider_api_boundary · 04-agent-interoperability-gateway

User-owned provider API boundary

productionBound=false
Product surface: User-Owned Model/API Key -> WCN Agent Tool
Local signals
lib/agent-os/production-interoperability-controls.ts
MVP usesOwnApi enters Human Gate
source.customerSecretLoaded=false
Required production binding
Store user-owned provider keys only in encrypted customer-controlled secret storage after explicit consent.
Bind provider/model scope, spending limits, retention, deletion policy, and audit export before a runtime agent can use the key.
Prevent WCN agents from reading raw provider secrets or using them outside an approved work order.
Validation
npm run check:agent-os-gateway
npm run check:agent-os-production-readiness
agent_tool_consent_budget · 03-runtime-business-agent-network

Agent tool consent and budget boundary

productionBound=false
Product surface: Runtime Agent -> User API / WCN Tool
Local signals
app/api/mvp/agent-run-bridge/local/route.ts
lib/mvp/wcn-mvp-agent-run-bridge.ts
lib/agent-os/production-runtime-controls.ts
Required production binding
Require a user-approved work order before runtime agents call user-owned APIs or paid model providers.
Attach budget, scope, model/provider allowlist, output review policy, and cancellation controls to each run.
Record tool calls as attributable AgentRun evidence without exposing raw secrets to the agent context.
Validation
npm run check:agent-os-runtime
npm run check:agent-os-product
audit_rate_limit_revocation · 05-platform-reliability-kernel

Audit, rate limit, and revocation loop

productionBound=false
Product surface: API Request -> Rate Limit / Audit / Revoke
Local signals
lib/modules/apikeys/middleware.ts
lib/rate-limit.ts
app/api/apikeys/route.ts DELETE
ApiKey.lastUsedAt
Required production binding
Enforce rate limits by organization, key, scope, endpoint, risk level, and abuse history.
Preserve audit events for key creation, last use, denied scope, revoke, quarantine, and Human Gate review.
Allow immediate revocation and emergency pause when a credential is leaked, abused, or outside approved scope.
Validation
npm run check:agent-os-reliability
npm run check:agent-os-governance
source=lib/agent-os/product-api-access-gate.ts · localOnly=true · productionBound=false · customerSecretLoaded=false

Local release evidence export

This package turns the public-release gate into a Human Gate handoff: release decision packet, source-truth manifest, build/typecheck artifact, route and claim matrix, module gate snapshot, smoke plan, rollback plan, and agent handoff context.

human_gate_release_packet · 08-human-gate-governance

Human Gate release packet

productionBound=false
Local signals
lib/agent-os/product-release-gate.ts
lib/agent-os/production-governance.ts
app/api/agent-os/decision-ledger/production-governance/route.ts
app/api/agent-os/product-system/release-gate/route.ts
Validation
npm run check:agent-os-product
npm run check:agent-os-governance
npm run check:agent-os-production-readiness
Human Gate inputs
Release scope, public surfaces, release owner, rollback owner, and affected claims.
Authenticated reviewer identity with segregation-of-duties evidence.
Explicit approval or rejection decision linked to the evidence export.
Missing production evidence
Approved production release decision id.
Reviewer identity proof from production auth.
Decision ledger storage in production.
source_truth_manifest · product-truth

Source-truth manifest

productionBound=false
Local signals
content/wcn-public/Documents/0-Foundational
docs/agent-os/modules/02-wcn-product-system.deep.md
app/brand/whitepaper/v3/page.tsx
scripts/generate-whitepaper-v3-hash-manifest.mjs
Validation
npm run check:whitepaper-v3
npm run check:public-claims
Human Gate inputs
Frozen source path list and release-candidate hash manifest.
Public claim review notes for legal, investment, token, and production-readiness claims.
Decision on whether old versions remain archived or are excluded from public navigation.
Missing production evidence
Final signed source freeze manifest.
Approved public claim exception list.
Production-visible source version id.
build_typecheck_artifact · 02-wcn-product-system

Build and typecheck artifact

productionBound=false
Local signals
package.json
next.config.ts
.next
Validation
npm run build
npx tsc --noEmit --pretty false
npm run lint
Human Gate inputs
Build command, source identifier, build timestamp, and artifact digest.
Acknowledgement of known non-blocking lint warnings.
Decision that the build artifact is approved for a named deployment target.
Missing production evidence
Production build artifact id.
Deployment provider build URL.
Release decision attachment for build output.
public_route_claim_matrix · product-truth

Public route and claim matrix

productionBound=false
Local signals
lib/public-routes.ts
proxy.ts
app/[locale]/agent-os/product-system/page.tsx
lib/agent-os/product-api-access-gate.ts
app/api/agent-os/product-system/api-access-gate/route.ts
Validation
npm run check:public-route-registry
npm run check:public-claims
npm run check:agent-os-implementation
Human Gate inputs
Canonical public routes included in the release.
Claims that require source evidence or downgrade before publication.
Decision on whether Agent OS pages are public, internal, or staged.
Missing production evidence
Production route crawl result.
Production canonical URL evidence.
Approved claim review export.
agent_os_module_gate_snapshot · 01-meta-agent-os

Agent OS module gate snapshot

productionBound=false
Local signals
lib/agent-os/module-registry.ts
lib/agent-os/evolution-adoption-queue.ts
lib/agent-os/production-readiness.ts
docs/agent-os/modules
Validation
npm run check:agent-os-modules
npm run check:agent-os-evolution
npm run check:agent-os-implementation
npm run check:composition-contracts
Human Gate inputs
Decision on whether remaining partial gates block release or remain staged.
Owner assignment for production deploy, observability, chain signer, and governance identity.
Evidence that no module claims production readiness without production authority.
Missing production evidence
Approved disposition for remaining partial production gates.
Production owner roster.
Release-scoped module gate export.
post_deploy_smoke_plan · 05-platform-reliability-kernel

Post-deploy smoke plan

productionBound=false
Local signals
lib/agent-os/production-observability.ts
app/api/agent-os/reliability-kernel/production-observability/route.ts
app/[locale]/agent-os/production-readiness/page.tsx
Validation
npm run check:agent-os-reliability
GET /api/agent-os/production-readiness
Human Gate inputs
Production domain, required routes, expected statuses, and response invariants.
Smoke operator identity and escalation owner.
Decision on thresholds that trigger rollback or pause.
Missing production evidence
Post-deploy HTTP smoke output from production domain.
Production observability timeline entry.
Operator identity attached to smoke record.
rollback_evidence_plan · 05-platform-reliability-kernel

Rollback evidence plan

productionBound=false
Local signals
lib/agent-os/reliability-kernel.ts
lib/agent-os/production-observability.ts
app/api/agent-os/reliability-kernel/production-observability/route.ts
Validation
npm run check:agent-os-reliability
npm run check:agent-os-production-readiness
Human Gate inputs
Rollback command, rollback owner, trigger threshold, and execution window.
Decision on whether rollback can be operator-triggered or requires Human Gate.
Public claim correction plan if rollback affects already published material.
Missing production evidence
Production rollback target and command.
Rollback owner identity.
Rollback execution or dry-run evidence from production tooling.
agent_handoff_context_pack · 01-meta-agent-os

Agent handoff context pack

productionBound=false
Local signals
app/api/agent-os/modules/route.ts
app/api/agent-os/evolution-ledger/adoption-queue/route.ts
app/api/agent-os/product-system/release-gate/route.ts
app/api/agent-os/product-system/release-evidence/route.ts
app/api/agent-os/product-system/api-access-gate/route.ts
docs/WCN-organization-agent-os-architecture.md
Validation
npm run check:agent-os-product
npm run check:agent-os-evolution
npm run check:agent-os-implementation
Human Gate inputs
Which agent system is allowed to continue release preparation.
Scope limits for Codex, Claude Code, or external maintenance agents.
Evidence package URL or file path that future agents must treat as handoff truth.
Missing production evidence
Human-approved handoff owner.
Production evidence package location.
Release continuation task order.
source=lib/agent-os/product-release-evidence.ts · localOnly=true · productionBound=false

Product release gate package

wcn-product-release-approved-decision · approved_release_decision

Approved release Human Gate decision

productionBound=false
Local signals
app/api/agent-os/decision-ledger/route.ts
app/api/agent-os/decision-ledger/[decisionId]/review/route.ts
lib/agent-os/production-governance.ts
Required production binding
Create a release decision with explicit scope, release owner, rollback owner, and affected public surfaces.
Require authenticated reviewer identity and segregation-of-duties evidence before approval.
Attach all release evidence ids before the decision can authorize deployment.
Validation
npm run check:agent-os-governance
GET /api/agent-os/decision-ledger/production-governance
wcn-product-release-source-truth-freeze · source_truth_freeze

Source-truth freeze

productionBound=false
Local signals
docs/agent-os/modules/02-wcn-product-system.deep.md
content/wcn-public
app/brand/whitepaper/v3/page.tsx
Required production binding
Freeze source documents, route list, release notes, and public claim registry for the release candidate.
Record the exact source paths and hash manifest used to build the public surface.
Reject manual edits to generated public artifacts after freeze.
Validation
npm run check:public-claims
npm run check:public-route-registry
wcn-product-release-build-artifact · build_artifact

Build artifact proof

productionBound=false
Local signals
npm run build
.next
next.config.ts
Required production binding
Run a clean production build from the frozen source candidate.
Record build command, commit or worktree identifier, timestamp, and artifact digest.
Attach build output and warnings to the release decision.
Validation
npm run build
npx tsc --noEmit --pretty false
wcn-product-release-public-route-registry · public_route_registry

Public route registry proof

productionBound=false
Local signals
lib/public-routes.ts
proxy.ts
app/[locale]/agent-os/product-system/page.tsx
Required production binding
Verify every public release route is registered, crawlable, and not accidentally auth-gated.
Record localized canonical routes and API smoke paths for release verification.
Block release if proxy or route registry drift is detected.
Validation
npm run check:public-route-registry
npm run check:agent-os-implementation
wcn-product-release-public-claim-review · public_claim_review

Public claim review

productionBound=false
Local signals
npm run check:public-claims
app/brand/whitepaper/v3/page.tsx
docs/agent-os/modules/02-wcn-product-system.deep.md
Required production binding
Review public claims for legal, investment, token, AI autonomy, and production-readiness overclaims.
Attach source evidence or downgrade each unsupported public claim to draft language.
Require Human Gate approval for high-impact public statements before publish.
Validation
npm run check:public-claims
npm run check:agent-os-production-readiness
wcn-product-release-env-secret-boundary · environment_secret_boundary

Environment and secret boundary

productionBound=false
Local signals
proxy.ts
lib/core/api-response.ts
app/api/agent-os/production-readiness/route.ts
Required production binding
Confirm the release candidate does not load production secrets in local-only mode.
Bind production environment variables through approved deployment settings only.
Record secret owner, rotation policy, and no-secret-in-artifact evidence.
Validation
npm run lint
GET /api/agent-os/production-readiness
wcn-product-release-deployment-target · deployment_target

Deployment target authorization

productionBound=false
Local signals
app/api/agent-os/product-system/release-gate/route.ts
app/[locale]/agent-os/production-readiness/page.tsx
lib/agent-os/production-readiness.ts
Required production binding
Select the production project, domain, branch, environment, and deploy strategy under Human Gate approval.
Record who can trigger deploy, who can approve deploy, and who can roll it back.
Do not allow local MVP evidence to substitute for deployment authorization.
Validation
npm run check:agent-os-product
npm run check:agent-os-production-readiness
wcn-product-release-post-deploy-smoke · post_deploy_smoke

Post-deploy smoke evidence

productionBound=false
Local signals
lib/agent-os/production-observability.ts
app/api/agent-os/reliability-kernel/production-observability/route.ts
app/[locale]/agent-os/reliability/page.tsx
Required production binding
Run production HTTP smoke checks after deployment against the approved domain.
Capture status code, route, timestamp, operator identity, and response invariant.
Attach smoke evidence to both release decision and production observability timeline.
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/production-observability
wcn-product-release-rollback-plan · rollback_plan

Rollback plan

productionBound=false
Local signals
lib/agent-os/reliability-kernel.ts
app/api/agent-os/reliability-kernel/observability/route.ts
app/[locale]/agent-os/reliability/page.tsx
Required production binding
Record rollback command, owner, threshold, and time window before release.
Connect rollback execution to an authenticated operator and incident timeline.
Require Human Gate for high-impact rollback decisions affecting public claims or user data.
Validation
npm run check:agent-os-reliability
npm run check:agent-os-governance
wcn-product-release-evidence-export · release_evidence_export

Release evidence export

productionBound=false
Local signals
app/api/agent-os/modules/route.ts
app/api/agent-os/production-readiness/route.ts
app/api/agent-os/product-system/release-gate/route.ts
Required production binding
Export the release package with module gates, build proof, route proof, claim review, smoke evidence, and rollback plan.
Store export hash and decision id in the evolution ledger or release ledger.
Make the package readable by future Codex, Claude Code, or external WCN maintenance agents.
Validation
npm run check:agent-os-implementation
GET /api/agent-os/product-system/release-gate
source=lib/agent-os/product-release-gate.ts · localOnly=true · productionBound=false