Everything Fulltrace might do next, run as a queue. Every idea becomes a row with an ID, a risk class and the rules it must respect, and nothing gets built without one. The standout tracks are below, then the full live register. How a row becomes shipped software is the factory page; what already shipped is the build log.
The register does not rank by excitement, but this page can: what just landed, and the tracks that change what Fulltrace is.
The panel had grown to nine tabs, and the screen that builds Fulltrace sat last, behind eight tabs meant for using it. A switch above the tab bar now picks Operate or Build. Operate is eight tabs. Build is six, with the cockpit as a screen of its own and the decision gates one click away instead of three. The panel reopens where I left it, remembered per project folder.
The written process no longer assumes Claude. A file at the top of the repo tells any assistant where the rules live and what only I decide, and one component turns a choice like "Codex, on my subscription" into the exact command, or refuses when nobody has verified it. The first watched Codex run found the rules and diagnosed the problem well, then stopped: in that mode Codex cannot write files here. Removing its sandbox is my call, and it is written down as one.
A Chat tab shipped in Studio on 25 August: pick a model, send, and every reply says which model answered and what it cost, under a cap that stops the tab. A model already on my machine can answer at $0. The routing brain that would pick a model for me is built and has no button yet; the tier control and the live routed send are the next rows.
Shipped 11 to 23 August. A definition is checked against a fixed shape, accepted by an act that binds its exact content, then runs as an ordinary run. Arrows can carry conditions. A definition with a write in it is refused, and before I accept one I see where its bytes could leave. Binding the accepted reach, and not only the content, is the open row.
Each of the nineteen invariants has a code-owned record with its enforcement checked against the real tree, a screen under Config > Governance, and a ruling: eighteen permanent, one temporary. A rule can retire through a drafted change. A project can bend a rule only through a code-owned exemption that is off by default.
Shipped 12 to 22 August. The outbound rule is invariant G19. Thirteen places bytes can leave are listed in code and locked by tests; nine are loopback. The push tool refuses a remote that is not mine, the assistants' shells refuse the four commands that send, and the extension keeps a checked list of the outside services it may reach.
The night runs under four hand-set caps, keyed to calendar dates so daylight saving cannot fire a tick twice. Since 25 August the Schedule tab arms and disarms jobs, and since 26 August it creates and edits them and the night's limits, with the runtime checking every entry before it is written. Editing a job disarms it until I arm it again.
A maintenance track that became the dark factory: queued slices up to risk class R3 built and shipped by a session with nobody in it, under a time cap per slice, a runner tier that sets what a night costs, a step up to a stronger model only when the evidence says the model was the problem, and an Awaiting ruling lane for any fork. Under it, a nightly battery breaks the code on purpose and checks that the same tests go red.
A spend page for what the runs cost, filterable by model, and two runs side by side. The runner now prices itself as it goes, so a night run can be capped in dollars, and a soft daily ceiling is read back at the moment I press Run. It never blocks a launch; it tells me.
A saved run can be replayed with no model called and compared with the original: 89 of 101 recorded runs reproduce exactly. It tests the machinery around a model, never the model. Scoring models against each other on a fixed task set is designed and still waits until it earns its spend.
Push notifications and a read-only mobile page over the tailnet have worked since July. The phone now names which slice a run or decision is for, says when a closeout step ticks, gets a heads-up before the chain runs out of work, and hears why it stopped. The first off-machine write, approving from the phone, still waits on demonstrated demand.
A five-model Ollama fleet on my own machine, observed and warmed from Config > Models. Its first job was an embeddings index over the project's own docs, searched at $0 a query. Since 30 August the Chat tab can talk to a local model too, showing memory and time instead of a price. Pipeline participation stays refused.
A browser page on this machine that can act, wrapped in the same freeze, simulate, approve, apply spine as everything else. Nine verbs shipped in July behind a write session minted at the node, and the headless callers moved onto a machine write token. Even localhost is treated as a hostile caller.
Several machines, each running its own copy, push what they are doing to one place I can watch. The foundation shipped in July: node identity, the push publisher, and a centre that can only look. It never approves, never applies, and holds no authority channel back to a node: a fleet I can watch but never command.
All 45 live rows, straight off the steering board. Role says why a row exists: boundary rows lock or open a standing rule, keystones are load-bearing, unlocks enable a later step, hygiene fixes what a check found, polish improves a screen. Risk sets how much design happens before code. Shipped rows leave this table at closeout: 340 so far, narrated in the build log, so a prerequisite you cannot find below has already shipped.
| ID | Title | Role | Risk | Prereq | Status |
|---|---|---|---|---|---|
| 5A.7 | Tier 3 _getWebviewContent() decomposition: the Development and Studio tab render functions, the client JS, and the nonce/CSP asset lift | hygiene | R2 | 5A.6 | deferred |
| 5AG.6 | The slice-memory store sits under a path named for one plane | hygiene | R1 | 5AG.1 | deferred |
| 5AG.9 | The armed chain does not record which agent it runs under | boundary | R4 | 5AG.4, 5G.3 | proposed |
| 5AG.13 | Proposal-first execution: codex as a proposal engine, never a mutation engine | boundary | R4 | 5AG.4 | proposed |
| 5K.134 | The code-audit and content-audit model router hardcodes the same retired free OpenRouter model 5AG.15 just retired from the codex profiles | hygiene | R1 | none | proposed |
| 5AG.17 | Memory is a store every plane mutates and the mutating-tool policy cannot see | unlock | R2 | none | proposed |
| 5C.3 | Roadmap-authoring interview: design | unlock | R0 | 5C.2 | proposed |
| 5C.7 | Website machinery to config: the enrolment path's last code edit | unlock | R4 | none | proposed |
| 5D.1 | Slack outbound notifications design | unlock | R0 | 5EG.2 | proposed |
| 5E.1 | Goals interface design | unlock | R0 | none | proposed |
| I2w | Public website flip to Fulltrace (separate Showcase repo) | hygiene | R1 | none | proposed |
| 5ID.2 | Internal doc bodies still say AgentOS, so the repo carries two names for one product | hygiene | R1 | none | proposed |
| 5ID.3 | The 124 AgentOS-prefixed doc filenames, behind a stub-and-redirect strategy | polish | R2 | 5ID.2 | proposed |
| 5J.10 | Studio's pill row holds two nouns, and thirteen of them | hygiene | R2 | 5J.9 | proposed |
| 5J.13 | The model catalogue is an eighth projection and the P1 to P7 contract does not know it | hygiene | R2 | 5J.9 | proposed |
| 5T.2 | Backup implementation and Settings tab controls | unlock | R4 | 5T.1 | deferred |
| 5V.4 | Remote decision surface: design gate | boundary | R0 | 5V.2, 5V.3 shipped + demonstrated demand | proposed |
| 5W.8 | The Chat-tab tier control and the live routed send | unlock | R3 | 5W.4 | proposed |
| 5W.9 | The model picker cannot be filtered by cost, or by anything else | polish | R2 | 5W.8 | proposed |
| 5W.7 | The Chat-tab subscription affordance and the live send | unlock | R3 | 5W.3 | proposed |
| 5W.6 | Chat can be told things but never shown anything, and the id for the fix was reserved at the design | unlock | R3 | 5W.2 | proposed |
| 5W.10 | The Chat tab can choose which model answers and not how hard it thinks, and the two keep being read as one control | unlock | R2 | 5W.2 | proposed |
| 5Z.2 | Wall-clock term in the graph budget | boundary | R0 | 5Z.1 | deferred |
| TR2 | Traicy on the website: showcase replay narration | unlock | R2 | TR1, I2w | proposed |
| TR3 | Traicy in Studio: replay waterfall narration | unlock | R2 | TR1 | proposed |
| 5R.7 | Bind the accepted reach, not only the accepted content | boundary | R4 | 5R.5 | proposed |
| 5GL.1 | Goal Loop Boundary: ratify the operator-declared bounded loop design | boundary | R4 | none | proposed |
| 5K.48 | The battery runs every break against the whole suite, and most breaks can only reach one shard | hygiene | R1 | 5K.32 | proposed |
| 5K.52 | The battery's own noise floor refuses every blessing, so no block can move | hygiene | R1 | none | deferred |
| 5K.32 | Move the first suite blocks by substrate, under the rules | hygiene | R1 | 5K.30, 5K.31 | proposed |
| 5V.8 | Acting on a slice from the phone collides with three positions already taken | boundary | R0 | 5K.24, 5U.2, 5V.4 | proposed |
| 4F.12 | A run record does not say which depth it ran at, so a launch estimate cannot price a focused sweep | hygiene | R1 | 4F.11 | proposed |
| 5K.131 | The fork detector is a phrase list, so a row that carries a decision in its own words reads as settled | hygiene | R2 | none | proposed |
| 5K.133 | Every registered web page prefix matches zero pages on the live site, so the one project that passes the publish gate would create a duplicate | hygiene | R1 | none | proposed |
| 5K.137 | The version's minor digit is a frozen literal, so the phase it names cannot move and nothing says whether it should | hygiene | R1 | 5K.136 | proposed |
| 5K.138 | The build stamp is written and shipped but nothing reads it, so which slices are in the installed build is a question you answer by unzipping a vsix | polish | R2 | 5K.136 | proposed |
| 5U.10 | The runner's controls are a flat stack of six siblings, and the one pane in the middle of it shoves everything below it down the page when it appears | polish | R2 | 5U.9 | proposed |
| 5U.12 | The lane whose rows wait on a decision is the only lane with no control on it, so every ruling has been a free-hand edit | unlock | R2 | 5U.10 | proposed |
| 5K.139 | The chain brief prints lifetime minutes and spend beside a shipped count from one night | hygiene | R1 | none | proposed |
| 5K.140 | Nothing invokes the night report, so the chain's own brief exists only when somebody runs it by hand, and "morning" stopped being true on 22/08 | hygiene | R2 | none | proposed |
| 5K.141 | A click pass is owed after every deploy, is named in thirty places, and the ceremony has never produced an artefact for it | hygiene | R2 | 5K.140 | proposed |
| 5K.142 | The safe-restart wrapper polls the port but reads the tracked pid once, so a restart that worked reported REFUSED | hygiene | R1 | none | proposed |
| 5K.143 | The Restart MCP Server button runs the bare pm2 restart 5K.96 replaced, and the panel's own warning names the wrapper it does not call | hygiene | R2 | none | proposed |
| 5K.144 | The build stamp slice list names rows that changed nothing in the build and omits the work that is actually in it | hygiene | R1 | 5K.136 | proposed |
| 5ID.6 | The rename swept source literals and never swept data, so two registries still name the product AgentOS | hygiene | R2 | none | proposed |