TS — TFW_20260830-114238_ASSISTED15: Prompt/File Assisted 1.5 Product and Maintenance Bridge¶
Date: 2026-08-30 Author: saubakirov via Codex Coordinator Status: ✅ APPROVED — owner amendment A1 and bounded autonomous mandate, 2026-08-30 Parent HL: HL-TFW_20260830-114238_ASSISTED15 Contract baseline: re-freeze commit with reserved
freezescope after amendment A1 Research: Iteration 1 RES · Iteration 2 RES, with executable-runtime conclusions superseded by A1
1. Objective¶
Deliver the single amended phase as a complete public Assisted 1.5 under editions/: a standalone neutral Russian starter whose TFW mechanics are prompts, Markdown skills, static contracts and ordinary agent file operations. Remove the executable identity/registration and maintenance/update/self-test runtime introduced by the earlier implementation. Preserve the useful templates, truthful Assisted changelog, static release authority, asymmetric forward/update promotion route, downstream state and read-only Innoforce evidence. шаблоны/build_a4.py may remain only as an artifact-template builder.
2. Scope¶
In Scope¶
- Keep the five complete Assisted skills and metadata, but make
tfw-identitya Markdown-only prompt/file procedure and/tfw-updatean agent-led compare, gate, file-update and promotion procedure. - Delete
editions/02-assisted/.agents/skills/tfw-identity/scripts/tfw_identity.pyandeditions/maintenance/assisted_maintenance.py; add no replacement workflow executable. - Remove every product command, claim, metadata dependency and shipped test contract that requires the deleted runtime.
- Retain and regenerate the static release manifest and maintenance policy as human/agent-readable authorities rather than executable-engine inputs.
- Preserve the complete neutral Russian note, work-plan, A4 and presentation templates; keep
build_a4.pystrictly inside artifact generation. - Preserve the exact retired-hook deletion, public Assisted
VERSION/CHANGELOG, edition guidance and installed-state protection rules. - Regenerate task-local RF/EV/evidence for the amended no-code product, including prompt/file scenario evidence and both maintenance directions.
- Make scoped local commits; after terminal RF, stop at a clean boundary for the Coordinator's one-time history compaction before final independent review.
Out of Scope¶
- Any product edit outside
editions/, including.tfw/, root guides,KNOWLEDGE.md,TECH_DEBT.md,editions/01-light/, or unrelated task folders. - Any executable TFW registration, identity, lifecycle, maintenance, update, locking, ACL, synchronization or product self-test subsystem, regardless of language.
- Expanding
шаблоны/build_a4.pybeyond A4 artifact generation or using it to verify/operate TFW mechanics. - Any write, rename, cleanup, generated artifact or metadata change under
H:\Shared drives\IT\Innoforce AI-First Knowledge\innoforce_starter_v1.5or adjacent preserved versions. - Copying Innoforce knowledge, people, facts, products, branding, paths, identifiers, release history or unique operational context into the public package or public evidence.
- Automatic mutation of the current mixed field tree, a symmetric mirror, source authentication/signing, a distributed-transaction claim, English localization, push, tag creation/deletion/rewrite or remote publication.
- Deleting or rewriting the external local tag
v2.0.0-dirty.5; final evidence records it as concurrent external state. - Reopening another frozen claim, accepting a path/LOC overrun, or modifying unrelated TFW-55/TFW-60 work without a new owner ruling.
3. Principles Check¶
| # | Principle (from amended HL §7) | Enforced by | Gate |
|---|---|---|---|
| P1 | Field practice is evidence, not product authority | AC-2, AC-6, AC-8 | Human behavior is retained; field runtime and company context are absent |
| P2 | Templates are product behavior | AC-7 | Complete worked templates render offline and are visually inspected |
| P3 | Neutral core, explicit overlay | AC-4–AC-6 | Static authorities and skill instructions distinguish public, customizable and downstream paths |
| P4 | One static authority per file class | AC-4, AC-5 | Every maintained path has one declared owner and one documented rule |
| P5 | Promotion, not blind synchronization | AC-5, AC-6, AC-10 | Forward work is gated; reverse work is candidate-only and independently reviewed |
| P6 | Standalone by default | AC-1, AC-2 | A copied starter works without Full, Light, Innoforce, registry or hidden service |
| P7 | Human authority and honest automation | AC-2, AC-3, AC-5 | Ambiguity asks/stops; optional orchestration never replaces acceptance gates |
| P8 | Stable trace over moving state | AC-3, AC-9, AC-10 | Same role sessions and durable task traces survive amendment and compaction |
| P9 | Prompt and files over workflow runtime | AC-1, AC-2, AC-4, AC-8 | Product code inventory permits only the artifact builder |
| P10 | Functional completeness over byte identity or executable complexity | AC-1, AC-7–AC-10 | Useful behavior and outputs are evidenced without copying field bytes or shipping a mechanics engine |
4. Affected Files¶
| File | Action | Description |
|---|---|---|
editions/README.md |
MODIFY | Accurate Assisted 1.5 choice and no-code capability boundary |
editions/02-assisted/{AGENTS.md,README.md,PROJECT.md,MIGRATION.md} |
MODIFY | Neutral onboarding, project-unknown state, prompt/file mechanics and migration contract |
editions/02-assisted/{people/README.md,knowledge/INDEX.md} |
MODIFY | Profile/file procedure and empty knowledge navigation with no shipped participant state |
editions/02-assisted/{VERSION,CHANGELOG.md} |
CREATE | Exact public version authority and truthful public-only history |
editions/02-assisted/.codex/{hooks.json,hooks/tfw-hook.ps1,hooks/tfw-hook.sh} |
DELETE | Exact retired stock lifecycle-hook payload |
editions/02-assisted/.agents/skills/{tfw-plan,tfw-handoff,tfw-review,tfw-update,tfw-identity}/{SKILL.md,agents/openai.yaml} |
CREATE | Five complete prompt/Markdown role contracts and metadata |
editions/02-assisted/.agents/skills/tfw-identity/scripts/tfw_identity.py |
DELETE FROM CURRENT TASK RESULT | Remove executable registration/identity runtime; final path is absent and therefore not a baseline product-diff path |
editions/ASSISTED_MAINTENANCE.md |
CREATE | Static authority classes and agent-led compare/update/promotion route |
editions/maintenance/{release-manifest.json,maintenance-policy.json} |
CREATE | Static release inventory and maintenance policy |
editions/maintenance/assisted_maintenance.py |
DELETE FROM CURRENT TASK RESULT | Remove executable maintenance/update/self-test runtime; final path is absent and therefore not a baseline product-diff path |
editions/02-assisted/шаблоны/{заметка.md,план_работы.md,документ_A4.md,презентация.html,build_a4.py,theme.css} |
CREATE | Complete neutral Russian practical templates and artifact builder |
editions/02-assisted/шаблоны/overlay/theme.css |
CREATE | Stock-customizable six-property artifact theme overlay |
editions/02-assisted/шаблоны/assets/tfw-mark.svg |
CREATE | Neutral shape-only artifact mark |
Final product budget from f3eb986: at most 33 paths—23 new, seven modified and three deleted—and at most 2,600 changed product lines. The two removed runtime files are current-task deletions but disappear from the final baseline diff. Any 34th final path, 24th new file or line over 2,600 is a hard stop for a new owner amendment.
5. Acceptance Criteria¶
AC-1: Release boundary, standalone package and no-code product¶
The final edition is a complete uninitialized public Assisted 1.5, and TFW mechanics ship no executable runtime.
- [ ] Product diffs attributed to this task are confined to
editions/; no Assisted task commit changes.tfw/, root guides oreditions/01-light/. - [ ]
VERSIONcontains exactly1.5\n;CHANGELOG.mdtruthfully records public Assisted 1.0 and 1.5 without importing Innoforce history. - [ ] A clean copy starts without profile, binding,
project_id, work, task trace, organization record, registry or hidden Full/Light/Innoforce dependency. - [ ]
tfw_identity.pyandassisted_maintenance.pyare absent. No product.py,.ps1,.sh,.js,.ts,.bator.cmdimplements TFW mechanics;шаблоны/build_a4.pyis the sole permitted Python product file and only builds artifacts. - [ ] Final product diff is no more than 33 paths, 23 new files and 2,600 changed lines, with the expected three hook deletions.
Gate: Exact task-attributed Git census from f3eb986, product executable inventory, private-marker scan and clean-copy inspection.
Evidence: Retain the path/action/LOC census, executable semantic inventory, version bytes and clean-copy file tree in EV.
AC-2: Prompt/file identity and profile safety [depends: AC-1]¶
Identity is a Markdown procedure performed by the agent with ordinary reads, questions and file creation; it is not registration software.
- [ ]
tfw-identity/SKILL.mdenumerates validpeople/*.mdprofiles, uses the explicit one-profile rule only when exactly one valid profile exists, and otherwise asks the human rather than guessing. - [ ] Participant, organization role, project role, task owner and AI role are separate fields; changing a session participant or role never changes an existing task owner silently.
- [ ] New profile creation requires explicit name, surname and roles; derives the documented surname identifier; checks the exact target immediately before creation; never overwrites a collision; rereads the created file.
- [ ] Zero, one and multiple profile scenarios; Cyrillic/Latin surname; missing surname; collision; invalid profile; explicit fixed selection; and autonomous no-human-role behavior are complete in the written contract.
- [ ] No machine binding, local registry, device namespace, ACL probe, lock file, temporary identity store or OS-security promise remains in product text, metadata or paths.
Gate: Independent semantic walkthrough of the Markdown skill and scenario table against isolated synthetic people/ trees; before/after manifests prove only the explicitly approved profile file changes.
Evidence: Record each prompt, available profiles, user-supplied choice, expected file action and observed result; do not execute a shipped helper.
AC-3: Complete lifecycle and reusable role boundary [depends: AC-1]¶
The five skills implement plan → handoff → independent review → human acceptance with a complete manual path and optional capability-gated orchestration.
- [ ] All five
SKILL.mdand metadata pairs are complete, consistent and reference only paths present in the copied starter. - [ ] Stable task paths, Coordinator/Executor/Reviewer role locks, human acceptance, knowledge decision and manual/autonomous choice are explicit.
- [ ] Missing capability, ambiguous handle or unconfirmed interruption stops or switches to manual-complete without spawning an automatic duplicate.
- [ ] Correction reuses the same Executor; re-review reuses the same independent Reviewer and reruns the full amended contract; child reports go only to the Coordinator.
- [ ] No lifecycle hook, startup registration, hidden product test command or automatic enforcement claim remains.
Gate: Contract/link scan plus a written deterministic role scenario matrix for complete, partial, lost-handle, no-interrupt, overlap, manual fallback and full re-review. Evidence: Use this task's actual one-Coordinator/same-Executor/same-Reviewer trace and a manual-complete tabletop; no product runtime is required.
AC-4: Static release and maintenance authority [depends: AC-1]¶
The manifest and policy are static, deterministic, readable authorities; they are not an executable maintenance protocol.
- [ ]
release-manifest.jsonself-excludes, includesmaintenance-policy.json, and lists every remaining public payload file exactly once with relative path, size and SHA-256. - [ ]
maintenance-policy.jsondeclares release version, accepted public baseline, the three exact retired hook hashes, public/customizable/downstream authority classes and target-only preservation. - [ ] JSON parses with no duplicate/colliding/traversal/absolute paths; paths are normalized text and resolve within
editions/during task-local verification. - [ ]
/tfw-updateandASSISTED_MAINTENANCE.mddescribe how the agent reads these records, compares actual files, stops on ambiguity/drift and presents one gated change plan. - [ ] No product command parses, validates, journals or applies the records automatically.
Gate: Two independent task-local regenerations of the static row set produce identical rows and hashes; semantic review confirms the policy has one authority per path class.
Evidence: Retain the two generated row sets/digests and the reviewer-readable authority table; task-local tools may verify but are not shipped in editions/.
AC-5: Agent-led forward update and installed-state preservation [depends: AC-4]¶
Forward update is a reviewed sequence of ordinary file operations, not an engine or transaction claim.
- [ ] The update skill requires source manifest/policy, complete target inventory and exact baseline comparison before proposing any write.
- [ ] The plan classifies every path as public, customizable, downstream-only, retired stock or unresolved; unresolved/drifted state stops before change.
- [ ] One explicit gate identifies the exact files to create/replace/delete; after approval the agent rechecks each precondition, uses ordinary file tools and captures a post-change manifest.
- [ ]
work/, knowledge, people/profiles, project identity, personalization, unrelated.codex, unknown target-only paths and modified templates remain byte-identical unless one explicit migration rule covers them. - [ ] A partial ordinary-file update is reported as partial and returned to review; documentation never calls the sequence atomic or distributed-transaction safe.
Gate: A clean synthetic downstream fixture and a drifted/customized fixture are executed by the same Executor using only the documented skill/file procedure.
Evidence: Before/plan/approval/after tables show every path, preserved bytes, stopped drift and zero unexplained change; no assisted_maintenance.py invocation exists.
AC-6: Reverse promotion privacy and field immutability [depends: AC-4]¶
Reverse work produces a reviewed generic candidate, never a mirror or direct public mutation.
- [ ] The update skill compares downstream/public inventories, classifies generic versus organization-specific differences and prepares a candidate outside the public core.
- [ ] Candidate text contains no private path, hash, person, organization, brand, project, release-history or unique operational context.
- [ ] Independent semantic review is mandatory before any candidate can become a later public product change; this task does not auto-apply it.
- [ ] The real field lineage is read-only comparison evidence and its 29-row tree is identical before and after all task work under both documented digest orders.
Gate: Synthetic generic/private reverse cases plus a non-mutating comparison of the pinned field source. Evidence: Retain candidate/privacy verdicts and field pre/post row equality; never retain private source contents in public product files.
AC-7: Useful neutral offline templates [depends: AC-1]¶
The practical template set remains complete, generic, Russian-authoritative and readable offline.
- [ ] Note, work plan, A4 source and presentation are complete worked generic examples rather than placeholders.
- [ ]
build_a4.pyaccepts only artifact inputs/outputs/theme/title, resolves local resources within the template tree and contains no TFW registration, identity, update, maintenance or test behavior. - [ ] Theme overlay and SVG mark retain their closed passive interface; external/network/active resources reject.
- [ ] Stock/custom A4 and presentation render with network blocked; every produced page/capture is visually inspected for readability, correct file type, no local URL/header and no private marker.
Gate: Static attack fixtures, two artifact-builder runs, blocked-network render, page/signature checks and visual inspection. Evidence: Save current rendered outputs under task evidence and record page-by-page inspection; the builder is assessed solely as an artifact tool.
AC-8: Cross-file agreement, neutrality and removed-runtime closure [depends: AC-2, AC-3, AC-4, AC-7]¶
Every public claim agrees on the amended prompt/file product and contains no stale runtime or downstream residue.
- [ ] Edition/root docs, skills, migration, people guide, templates, changelog, manifest and policy agree on exact paths, version, prompt identity and agent-led update semantics.
- [ ] No command or link names either removed Python runtime; no text requires a local registry, OS lock, ACL proof, executable verifier or automatic maintenance operation.
- [ ] No Innoforce/company/person/product/leadership/value/location/path/brand/logo/project default, private hash or field-only release heading appears in product text, metadata, assets or generated output.
- [ ] Public 1.0 baseline and 1.5 amendment history are truthful; no product text invents a tag, SemVer, English mirror or private provenance.
Gate: Full text/link/code inventory, removed-path reference scan, binary/SVG inspection, synthetic private-token corpus and independent semantic review. Evidence: EV names every removed runtime reference and its corrected public statement; zero hits are resolvable, not asserted from memory.
AC-9: Proportionate no-code evidence package [depends: AC-2–AC-8]¶
Task-local evidence proves the amended product without shipping a product verification engine.
- [ ] Evidence covers the exact product census, no-code inventory, static manifest regeneration, prompt identity scenarios, lifecycle/role scenarios, forward preservation, reverse privacy, template renders, cross-file agreement and source immutability.
- [ ] Every negative scenario proves zero unauthorized product/fixture mutation through before/after manifests or documented no-write observation.
- [ ] Repeated static inventory and render checks produce the same public hashes; nondeterministic environment facts are recorded rather than hidden.
- [ ] RF/EV explicitly supersede earlier runtime evidence and prior REVISE conclusions; no stale
FINAL=PASS, ACL, lock or no-tag-containment claim is reused as current proof. - [ ] Task-local evidence scripts, if retained, live only under this task, are not referenced by the product and test files rather than operate user workflow state.
Gate: Complete EV row audit, task schema validation, task-attributed Git audit and independent attachment resolution. Evidence: Every VERIFIED row cites a current attachment; previous evidence remains historical but is not counted as amended acceptance.
AC-10: Both directions, truthful publication state and final review [depends: AC-5, AC-6, AC-9]¶
The amended result closes both maintenance directions and the task lifecycle without rewriting external state.
- [ ] Agent-led clean public→downstream fixture reaches Assisted 1.5 with protected state unchanged; downstream-generic→public produces only a reviewed candidate.
- [ ] No Assisted task operation performs push, tag creation/deletion/rewrite or remote publication. Evidence truthfully records that concurrent external local tag
v2.0.0-dirty.5contains Assisted ancestors and that no remote-tracking ref contains the terminal result at capture time. - [ ] Same role lineage is preserved through amendment: one Phase Coordinator, same Executor, same independent Reviewer, with a full final rerun against the re-frozen HL and revised TS.
- [ ] After terminal RF/evidence and before final review, the Coordinator performs history compaction exactly once on a recoverable local backup branch (not a tag), preserves all unrelated TFW-55/TFW-60 commits and dirty files, and proves pre/post tree equality.
- [ ] Final compact history contains logical owner-config, task plan/research/final TS, final Assisted product, evidence/RF with preserved review traces, and final approval/closure commits; obsolete task checkpoint/fixup commits are absent.
Gate: Direction evidence, source digest, Git operation-attribution audit, one-time compaction attestation, exact tree comparison and full independent /tfw-review.
Evidence: Retain compact commit mapping, backup branch name, old/new tree IDs, unrelated commit preservation audit, current tag/remote containment facts and final Reviewer verdict.
Evidence Artifacts¶
| File | Description |
|---|---|
evidence/EV__TFW_20260830-114238_ASSISTED15.md |
Amended AC-1–AC-10 evidence table and verdict |
evidence/assisted15-verification.log |
Task-local commands, exit statuses and static/no-code verification summary |
evidence/assisted15-fixture-results.json |
Privacy-safe prompt/file, role, update and static-manifest scenario outcomes |
evidence/boundary-and-source-attestation.md |
Product boundary, runtime removal, publication attribution and field pre/post attestation |
evidence/templates/ |
Rendered A4/presentation outputs and inspected page captures |
evidence/history-compaction-attestation.md |
Coordinator-created one-time compact-history and tree-equality proof |
6. Technical Guidance¶
- Amendment A1 is product authority. Do not repair or simplify either deleted runtime; remove it and every dependency instead.
- “No-code TFW mechanics” applies to shipped
editions/behavior. Ordinary agent tools and task-local diagnostic scripts may verify files, but may not become product commands or operate user registration/update state. tfw-identitymust be understandable and performable as written by an agent with profile reads, one concise human question when needed, exact target checks and ordinary file creation./tfw-updatemust expose compare → classify → plan → explicit gate → recheck → ordinary file changes → verify → candidate/review. Static JSON records are references, not an executable protocol.- Regenerate
release-manifest.jsonafter runtime deletion; it excludes itself and includesmaintenance-policy.json. Keep the policy declarative and free of script entry points. - Preserve template TI1 and visual evidence.
build_a4.pymust not import or call task/workflow/identity/maintenance modules and must not be described as a TFW engine. - Preserve unrelated dirty changes and use exact pathspec staging. Do not alter the external tag or field source.
- Executor stops after a clean terminal RF/evidence commit. The Coordinator alone performs the single history compaction at the next safe boundary, then returns the same Reviewer for the terminal full rerun.
7. Definition of Failure¶
- ❌ Any task-attributed product file outside
editions/changes, including.tfw, a root guide or Light. - ❌ Final product exceeds 33 paths, 23 new files or 2,600 changed lines without a new owner amendment.
- ❌
tfw_identity.py,assisted_maintenance.pyor another executable TFW registration/identity/lifecycle/update/maintenance/self-test mechanism remains or is reintroduced under a different name. - ❌
build_a4.pyperforms anything beyond artifact-template building. - ❌ Prompt identity guesses a participant/role/owner, overwrites a profile, writes a machine registry or claims OS-level confinement.
- ❌ Agent-led update silently handles an unresolved path or changed baseline, overwrites downstream state, claims transactionality or skips the explicit gate.
- ❌ Reverse work mutates public core directly, mirrors the field tree or leaks organization/private context.
- ❌ Any write reaches the Innoforce source or adjacent versions; any company/brand/history residue enters product or public evidence.
- ❌ Templates remain branded/placeholders, require network access, accept active resources or lack readable visual evidence.
- ❌ Product docs/metadata reference removed runtime or contradict prompt/file mechanics, version, authority classes or changelog history.
- ❌ RF/EV counts stale runtime runs as amended evidence or conceals the concurrent external local tag.
- ❌ History is compacted before terminal amended RF, compacted more than once, uses a tag as backup, changes the final tree, drops unrelated TFW-55/TFW-60 commits or disturbs dirty files.
- ❌ Final review is delta-only, uses a new role session, or does not reopen the complete amended contract.
- ❌ An Assisted task operation pushes, creates/deletes/rewrites a tag or publishes remotely.
8. Phase Risks¶
| Risk | Mitigation |
|---|---|
| Removing runtime leaves stale commands or metadata | Full removed-path/reference scan plus independent semantic review |
| Prompt identity becomes vague or silently guesses | Closed written scenario table, one-profile rule and explicit question on ambiguity |
| Static maintenance guidance is too weak to preserve downstream state | Exact authority table, before/after manifests, explicit gate and clean/drifted fixture walkthroughs |
| “No-code” accidentally removes the useful artifact builder | Keep one explicit exception and semantically inspect build_a4.py boundaries |
| Task-local verification is mistaken for shipped product runtime | Keep it under task evidence only; product references no evidence command |
| Existing evidence overstates the superseded runtime | Rewrite RF/EV truthfully and count only current amended attachments |
| Concurrent tag makes publication wording stale | Attribute acts, record current containment, never mutate the external tag |
| One-time history rewrite disturbs shared work | Use a backup branch, isolated rewrite, exact tree/commit audits and atomic ref update only at a clean task boundary |
| Unrelated dirty work enters a commit | Exact pathspec staging plus cached-diff and final status audit |
TS — TFW_20260830-114238_ASSISTED15: Prompt/File Assisted 1.5 Product and Maintenance Bridge | 2026-08-30