Skip to content

Governed Capability Portfolio Roadmap

Status: canonical roadmap adoption authority and capability delivery standard.

This document governs how AncientOS capability work enters and leaves the active portfolio. The master portfolio view is the operator-facing summary. The Architecture and Capability Posture Taxonomy defines lifecycle and posture vocabulary.

AncientOS completed its numbered-era sequence through Era 8. No numbered era is active and Era 9 is not adopted. A capability appears here as a candidate only for analysis; it becomes authoritative work only after an explicit operator adoption decision is recorded.

Portfolio lifecycle

The canonical lifecycle states are:

  • candidate: identified option, not authorized work;
  • proposed: complete adoption packet awaiting operator decision;
  • adopted: explicitly selected for implementation, not yet started;
  • in_progress: adopted implementation has begun;
  • blocked: adopted work cannot progress for named reasons;
  • complete: acceptance criteria and required validation are satisfied;
  • deferred: intentionally inactive until stated conditions change;
  • rejected: explicitly declined; reconsideration needs a new proposal;
  • historical: retained provenance outside the current portfolio.

Portfolio state is not implementation readiness, runtime health, or execution authority. Those remain independent dimensions in the canonical taxonomy.

Current portfolio

Lifecycle state Items
proposed None
adopted Keeper exact-task completion lifecycle consolidation
in_progress None
blocked None
complete Broad capability-backed read-only cognition (bounded source coverage; see C1)
candidate qBittorrent pause/resume; read-only service diagnostics; the optional and prerequisite-bound inference follow-ons enumerated in the completed inference section
deferred governed experiential confidence/reinforcement; container restart; Compose deploy/recreate; Git update; package/system update; broad delete; general scheduler; autonomous remediation; general shell executor; the routing, monitoring, persistent-default, and model-lifecycle inference items enumerated in the completed inference section

Candidate order is not priority. No candidate is an implied next capability.

Program sequence — 2026-09-07

Reconciled against clean main at d914f2a, the September 7 Media milestone, recent implementation reports, runtime composition, current source and deployed surfaces. This is the current program view inside the existing adoption authority, not a second backlog or a new governance system. Recommendations do not silently adopt work. The exact-task Keeper adoption remains valid.

Recommended next objective: Keeper exact-task completion lifecycle consolidation.

NOW — foundational convergence

  1. Broad compositional read-only cognition (C1, complete): the shared runtime discovers principal-authorized Rubick operation contracts, executes a finite observational batch, and preserves Oracle source provenance and uncertainty in Kernel Records. Plex inventory no longer requires generic inference. Registered sources span media, notifications, governance, work, runtime and project state. Optional model interpretation remains dependent on inference availability; individual peer diagnostics and live device control readiness are not implied. See the implemented architecture for effect policy, authorization, bounds and deployed-surface limitations. Completion does not grant authority to execute recommendations.
  2. Program truth (C2): this reconciliation repairs the stale Media lifecycle, missing Keeper adoption in runtime metadata and obsolete next-step state. Observational roadmap ownership no longer requires a progression word: current state questions resolved to AncientOS also reach Oracle evidence. Maintain canonical-document/runtime agreement; evidence reconciliation is a release obligation, not an autonomous backlog writer. Runtime synthesis now consumes the canonical recommended objective without granting adoption.
  3. Security and validation hygiene (S1, V1): close authenticated chat's missing session-bound CSRF check and repair report-archive test discovery. Preserve existing Lich/identity authority. Finish deterministic test-fixture hygiene where baseline failures demonstrate it is necessary.

NEXT — bounded convergence after NOW

  • C3: Keeper exact-task completion, already adopted: reuse durable exact-action proposal/approval/evidence/receipt primitives and test restart/uncertainty. Existing conversational task completion is not proof of the adopted canonical lifecycle. No new task backend, bulk completion or task mutation is implied.
  • C4: Lich presentation parity: connect existing controls and simple scoped confirmation to normal proposal rendering, hide opaque identifiers by default, preserve exact binding and high-risk recent-authentication requirements.
  • C5: observer/delivery host independence: move only the existing typed pulse hosting contract out of Discord when separately scoped; use shared Io and outcome-return primitives. Do not create a workflow engine or a second outbox.
  • A1: cold-device playback truth: distinguish command dispatch, app/profile barrier and observed playback. Never report “playing” solely from dispatch. This can be a narrow App fix alongside Core convergence, not a reopened Media program or authorization to actuate a room during maintenance.

PRODUCT TRACKS

  • Rotes (P1): design corpus ingested; documentation reconciliation complete. The source authority inventory preserves the Conceptual Specification Draft 1, Ontology and Effect Semantics Draft 1, and the authoritative reconstructed collectibility/curation/provenance addendum, plus supplied architecture context. The addendum records its replacement adoption and is not a verbatim recovery of the unavailable original. The reconciliation and decision ledger separates settled intent, recommendations, unresolved choices and direct implementation evidence. Universal semantics fit Core conceptual architecture; Apps may specialize domain cognition without redefining them. Chen remains Core. The first bounded informational exchange is implemented in 79dc3628b5e1627c7e9aec29bc6f903c9c1b6ca7; the historical map's implementation and retrieval absences no longer describe current state. Project-corpus reads and narrow establishment have deployed evidence, without claiming complete broad planning. Next recommended Rote slice: governed read-only inspection of one received informational Rote with provenance and restrictions. Global discovery and effectful forms remain deferred. This recommendation does not grant implementation authority or displace the separately adopted Keeper slice.
  • Apps (P2): Media Manager, Home Automation, Naga Siren, X Feed, Meeting Intelligence and the read-only Prophet boundary retain independent domain ownership. Prioritize an explicit operator outcome per App; do not make all Apps prerequisites for Core or Rotes. No speculative Android product is implied.

ARCHITECTURE / MIGRATION

  • M1: identity and repository migration: AncientOS is the system; Luna is the configurable interface. Preserve discord-luna, module names, Compose service identities, environment aliases, URLs, bind paths and data locations where they have consumers. First inventory consumer contracts and backups/restore; then separately approve remote rename, checkout relocation, compatibility changes and deployment validation. No blind global rename or storage move.
  • M2: Core/App extraction: retain Chen, runtime, routing, governance, Keeper, Rubick, Oracle, LifeVault and shared observation/return contracts in Core. Extract App-owned policy/adapters only after consumer and state boundaries are proven. Reconcile Naga's two histories and deployed availability before moving it. Existing X Feed/ops histories should be preserved. A container, integration or hero name alone does not justify a repository.
  • M3: legacy reliability seams: database migration exception visibility, old Keeper stores/audit references, provider launch parity and duplicate host mount authority need isolated contracts and validation before deletion.

BOUNDED FOLLOW-UPS — reconciled recovered register

“Open” means current evidence supports the issue, not permission to execute. “Verify” means historical evidence is insufficient to claim current closure. Owner is Core, App, ops or integration; priority follows the sequence above.

ID Item and disposition Type / owner Evidence, dependency and completion boundary
C1 Complete: bounded compositional inquiry ownership Architecture/correctness / Core runtime/compositional_inspection.py, Rubick reviewed operations and Oracle composition; multiple authorized sources precede generic fallback. Optional synthesis can be unavailable without erasing observations.
C2 Reconciled: roadmap lifecycle/next objective Correctness / Core architecture/roadmap_state.py and this document now agree; contradiction still fails closed. Does not automatically reconcile all external project state.
C3 Open: exact-task completion Adopted capability / Core Keeper 2026-08-25 adoption; current keeper/execution.py completion lane is not the durable adopted contract. Depends on stable platform, benefits from C4.
C4 Open: Lich normal presentation UX / Core + transports Web Inbox, Discord LichApprovalActionView, scoped confirmation already exist; runtime/pipeline.py still renders opaque approval commands. Keep policy reauthentication.
C5 Open: observer host independence Architecture / Core wiring bot.py hosts Clockwerk/Io/Chen pulses; shared io_tethers.py exists. Decouple hosting, not domain policy or approval.
C6 Open: asynchronous Web/Terminal conversational return Integration / Core transports notifications/web_push.py shared outcome-return methods; durable rows and Push shared, Web polling is not proactive conversation delivery. Depends on C5 only for liveness, not a new store.
C7 Open: Web conversation scoping Correctness / Core transport Shared Web channel and authenticated principal are distinct concepts; define browser/conversation continuity before widening delivery.
S1 Repaired: authenticated chat CSRF omission Security / Web ingress Chat now checks existing session-bound header before runtime; Lich/settings already checked it. Anonymous read-only requests remain unprivileged.
S2 Open: high-risk Web reauthentication ceremony Security UX / Core identity Existing separate-secret endpoint and recent-auth checks; do not weaken to ordinary yes/no. Need threat-model and browser acceptance, not a second approval system.
S3 Open: preference-write telemetry Observability / Core Name preferences can persist while generic metadata says mutation_occurred=false; distinguish preference persistence from operational mutation without granting authority.
S4 Resolved in Media: canonical Web principal mismatch Correctness / Core/App seam 62fb131, chen_media_watch_loop tests; invalid/revoked/mismatched contexts still refuse. Do not generalize this to every legacy path.
V1 Repaired: pytest report-archive collection Validation infrastructure pytest.ini excludes disposable report copies only; app/services/tests remain discoverable. Reports are evidence, not executable suite inputs.
V2 Repaired: date-sensitive dormancy tests Test infrastructure / Core tests September reports name two fixed-date fixtures. Use controlled evaluation time; do not alter production aging policy.
V3 Repaired: repository byte-budget fixture Test infrastructure / Core tests Old assertion depends on growing live source contents; use fixed temporary source. Preserve production budget and chunk contract.
A1 Open: cold Apple TV/profile barrier and truthful outcome Bug / Media + device integration Operator observed profile screen despite “playing” notification; awake/profile-selected Plex works. Require observed session or explicit unverified/intervention result.
Source inspection also found a concrete weak assumption: Earthshaker accepts a
matching Plex session with missing player state as playing. This is a bounded
follow-up lead, not proof of the cause of the reported cold-device event.
A2 Open: exact-episode playback rating key Bug / Media media_manager/governed_watch.py uses show-level lookup in a path; movie acceptance cannot establish episode parity. Depends on verified episode identity.
A3 Open: clarification claim crash recovery Reliability / Media Durable claim can be stranded after claim before proposal; review idempotent recovery and uncertainty, not blind replay.
A4 Open: retained post-copy staging payload Ops hygiene / Media /media/plex/downloads/complete/... preserved intentionally; exact files, Plex verification, retention and separately governed cleanup required. Never blanket delete.
A5 Open: catalog eligibility vs peer viability Integration / Media providers Bitmagnet/qBittorrent Search/Prowlarr discovery does not prove live peers; trackerless metadata stalls remain possible. Report separate evidence dimensions.
A6 Verify: naturally eligible continuation replay Acceptance / Media One-shot replay guard repaired in d914f2a; prior live window confounded by containment. Next naturally eligible approved objective, no manufactured acquisition.
A7 Verify: fresh post-atomic-claim Pixel return Acceptance / notification integration Real Pixel delivery preceded final race fix; 019d900 adds conditional claim. Await normal authorized outcome; no test notification sent here.
A8 Resolved: wrong-series/latest-episode routing and provider-year gate Bug / Media September 6/7 title/clarification fixes and 68cff41, defd37f, 62fb131; retain regression coverage, not active reimplementation.
A9 Resolved: unsafe SQLite-file flock interaction Correctness / Media persistence September 7 download-status report and 62fb131 move coordination off database inode; previous integrity check passed. No DB reset needed.
A10 Open: spaced episode-range exclusion Bug / Media policy acquisition_discovery._parse_episode_coordinates recognizes compact ranges but can treat S01E01 - E03 or S01E01 to E03 as one episode. Bound hardening before claiming exhaustive exact-episode selection.
A11 Verify: late Plex readiness recovery Integration / Media Earlier promotion reports lack a verify-only continuation after bounded failure; completion-v2 supersedes some lifecycle gaps but not proof for every legacy promotion row. No automatic retry authorization.
C8 Open: unresolvable Discord-origin starvation Reliability / Core transport bot.deliver_origin_notifications skips malformed/missing channels before disposition; oldest bounded page may starve newer records. Resolve or record bounded failure through shared outbox.
V4 Open: test default-store isolation Test infrastructure / Core Historical tests can use default stores; use disposable paths consistently before claiming zero developer-test data effects. Report directories are not governed evidence.
I6 Verify: Prowlarr/Usenet and third-party Search hardening Integration / Media Multi-provider code is delivered; Prowlarr deployment/indexers and typed Usenet execution are not implied. Native Search plugin upstream timeout/redirect/read bounds need separate provider review.
W5 Verify: physical device logout/revocation and exact-review click acceptance Acceptance / Web identity Controlled deployed API denial exists; later physical Push evidence supersedes missing-enrollment reports, but not every device ceremony. Do not revoke the user's working device merely to test.
W1 Removed: retired NeoHabit card and endpoint Hygiene / Web No deployed NeoHabit container; both featured card and static endpoint removed.
W2 Already delivered: qBittorrent WebUI link UX / Web integration launcher/services.js, /api/tui/qbittorrent-webui; configuration-backed redirect is not provider health.
W3 Open: launcher shortcut vs capability readiness Truth / Web Most service links remain configured static shortcuts, explicit status probes exist; do not label all configured endpoints healthy. Remove dead placeholders instead of inventing live feeds.
W4 Already delivered: enrollment/current-device Push and cookie continuity UX / Core notifications Durable sessions, Inbox subscription status, device replacement and fan-out exist; A7 is narrower remaining acceptance.
I1 Open: inference deadline and configuration drift Integration / inference Live Web fallback reproduced a roughly 30-second inference_service_error; runtime-status showed local mode and a reachable service. Inventory on 2026-09-07 reports Qwen2.5 and llama.cpp Qwen ready, configured Mistral missing, Ollama Qwen3.8 degraded, xAI unobserved. No model install/selector change; C1 does not repair inference reliability.
I2 Open: compatibility configuration/reporting consumers Debt / inference Compose fast/mid/heavy fields remain consumed; do not delete role names just because local/frontier mode exists. Current self-inspection implementation already distinguishes configuration and observation.
I3 Already delivered: model registry/selection and runtime self-inspection Capability / Core inference dd6ddcc and completed inference contract; unknown is honest. Optional providers/benchmarks are separate decisions.
I4 Open: Naga/provider readiness across launch paths Packaging / App + Core integration Prior audit found host package versus container gap; executable visibility is not authorization. Verify each actual launcher before claiming availability.
I5 Open: Rubick setting observation gaps Observability / Core integrations September settings audit distinguishes desired/deployed/observed; many non-model keys have no process observer. Add adapters only for operator value; unknown values are not inherently bugs.
O1 Resolved: qBittorrent/Gluetun namespace recurrence repair Ops / external deployment 0f86e74, guarded namespace/paused-state reconciliation and separate supervisor; no generic Docker authority. Current host containers inspected.
O2 Resolved: old torrent cleanup approvals/blockers Historical ops residue September 5 exact cleanup reports supersede earlier waiting-authority reports. Preserve receipts and retained files; do not replay approvals.
O3 Open: duplicate /host_bin mount authority Security/ops decision Compose declares RO and RW for same target; effective access is RW. Settling intended lane authority precedes change.
O4 Open: migration exception suppression Reliability / Core persistence app/db.py and migration runner historical catch paths; need existing-DB/cold-start and observable failure contract. No schema mutation here.
O5 Open: obsolete cleanup script safety Hygiene / developer tooling scripts/cleanup_bak_files.py can delete after archive failure; review consumers, then retire rather than automate unsafe cleanup. Never run it as archaeology.
O6 Open: old Keeper local store/audit references Architecture / Core task_store.py, keeper_audit; retain SQL/CSV evidence until consumers/retention decision established. No shadow backend expansion.
O7 Open: legacy context injection signature mismatch Bug / legacy Discord path Identity report found one-argument call versus two-argument inject_luna_context; neutral fallback masks it. Fix only with real affected transport acceptance.
O8 Open: host Terminal preference-write permissions Ops / LifeVault adapter Host reads container-created preferences; writes need explicit ownership policy. No chmod/chown inferred.
O9 Deferred: trivial compatibility-helper simplification Low-value debt / Core _is_relative_to can eventually use supported Python API; does not block product progression. Delete only with consumers/tests known.
D1 Delivered: development authorization/plan binding and commit integration Core governance d82c02c, 03c99e0, September 1 finalization lineage supersedes earlier blocked reports; deeper continuation parity remains an acceptance question, not new commit authority.
D3 Deferred: broader project-authority envelope Architecture / Core governance September 1 target architecture is broader than delivered bounded development authorization; checkpoint/amendment/revocation and cross-domain effect semantics need separate adoption.
D2 Verify: cross-transport development continuation acceptance Core integration Historical implementation report deferred deeper continuation/change attribution; later commit integration closes only its own scope. Reuse exact authorization records; no automatic commit/push.
L1 Open/conditional: ordinary LifeVault retrieval and universal Zeus linkage Core integration Foundation durable memory/evidence exists; coverage is not universal across legacy domains. Scope one real consumer before adding stores or global hooks.
P1 First bounded informational exchange implemented; received-Rote inspection next recommended Rote domain over Core primitives Current capability, preserved sources; public discovery and effectful forms deferred.
P2 Deferred: App extraction/product expansion Product/architecture See boundary model and September 4 audit; no App must exist for Core identity to survive.
R1 Research: Obscura vs SearXNG Search integration Operator interest in h4ckf0r0day/obscura; SearXNG already deployed. No installation, credentials or new exposure authorized.

RESEARCH / EXPERIMENTS

R1 is ready for a bounded read-only comparative study after Core inquiry convergence. Establish the problem not served by SearXNG, overlap and unique capabilities, privacy/retention and trust implications, maintenance cost and whether a second search surface is justified. Default classification: search integration, not a new Core component or App. Expose both only if evidence supports independent operator value. No upstream functionality is asserted here; the study has not been performed and nothing was installed.

Inference benchmarks, extra providers, experiential reinforcement, networked identity and speculative automation are not maintenance prerequisites. Preserve the existing explicit inference/experience deferral gates below.

DONE / SUPERSEDED and subtractive decisions

Retire “finish Chen watch loop” as a broad active objective; preserve its bounded exceptions. Do not rebuild notification/outcome stores, Lich approvals, Io, canonical-principal identity, qBittorrent linking, model self-inspection or Media provider routing already delivered. Earlier blocked authorization reports are historical when later exact work completed; they do not create fresh backlog. Remove NeoHabit presentation. Exclude disposable report copies from test discovery without deleting reports. Keep unknown capability posture explicit instead of creating adapters merely to fill a dashboard. Retain compatibility paths until consumer evidence supports migration; a name mismatch alone is not a defect.

First-principles review: pipeline ordering and stale hand-maintained adoption metadata reflect historical growth. A second router, registry, scheduler or approval store would increase the ownership problem. Simplify by using the existing intent boundary, bounded provider contracts and single authorities. Do not automate roadmap mutation to compensate for unreconciled release records. Do not optimize model selection to answer questions already owned by evidence. DELETE > SIMPLIFY > OPTIMIZE > AUTOMATE remains the sequencing rule.

Dependency graph and release gates

flowchart TD Truth[Reconciled program truth and reliable validation] --> Inquiry[C1 shared inquiry ownership] Security[S1 authenticated ingress] --> Inquiry Inquiry --> Reach[Evidence-backed Plex and independent Core inquiry acceptance] Reach --> UX[C4 Lich presentation parity] Platform[Existing governed platform] --> Keeper[C3 adopted exact-task completion] UX --> Keeper Platform --> Host[C5 typed observer hosting] Host --> Delivery[C6 Web and Terminal return adapters] Identity[C7 conversation and principal scope] --> Delivery Episode[Verified episode identity] --> Playback[A1 and A2 truthful playback] Imports[P1 preserved Rote corpus] --> Design[Documented reconciliation] Design --> Exchange[Implemented bounded informational exchange] Exchange --> Inspection[Recommended governed received-Rote inspection] Boundaries[M2 proven Core and App consumer boundaries] --> Migration[M1 staged identity and repository migration] Reach --> Research[R1 Obscura comparison]

Arrows are sequencing recommendations unless an adopted contract says otherwise. Rote conceptual requirements are now attributed to the preserved sources and separated from implemented dependencies in the reconciliation. The first exchange has bounded verified-instance mechanisms; broader network and identity mechanisms remain deferred. No graph edge authorizes implementation or mutation. For each implementation slice: focused/full tests, architecture/static/hooks/docs, diff review, Compose rebuild/health and actual affected-surface acceptance. Never substitute mocked providers for live device/notification acceptance.

Completed portfolio

Platform foundation

AncientOS Platform v1 Alpha provides the shared transport-neutral runtime, Runtime Composition, durable Kernel Records, restart-safe explanation, Governed Proposals, durable Lich approvals, bounded execution, Zeus evidence and receipts, rollback or compensation records, and transport parity.

This foundation is complete for the current alpha contract. It is not a claim of production readiness or universal capability coverage.

Oracle Operational Ergonomics

Historical program: Era 7. Portfolio state: complete.

Oracle supplies operator-facing inspection, action queue, governed proposal preflight, simplified proposal intake, explicit apply vocabulary, and proposal audit over existing governed services. Oracle remains advisory and does not own approval, execution, evidence, receipts, memory, or a second proposal lifecycle.

Completion commits:

  • 0dba71e Add Oracle governed proposal preflight
  • e7c6ae6 Fix governed action precondition race
  • 6c31539 Add unified Oracle action queue
  • 8be8ee0 Add Oracle governed proposal audit
  • 9263433 Add simplified Oracle proposal intake
  • 08edff2 Add explicit Oracle governed apply vocabulary

Spectre terminal observation

Portfolio state: complete for terminal observation v1.

Spectre ingests explicit spectre-shell terminal records, applies deterministic redaction, supports explicit process-bounded conversation binding, and supplies read-only evidence for Oracle interpretation. It does not intercept SSH, capture hidden screens, execute commands, approve work, or certify success.

Completion commits:

  • 0384b82 Add Spectre terminal observation capability
  • b6477df Fix Spectre pre-commit hygiene

First governed capability portfolio

Historical program: Era 8. Portfolio state: complete.

Capability Operator outcome Authority and persistence Evidence boundary
governed_configuration_value_edit Inspect and change one registered non-secret scalar Lich-bound proposal; bounded executor; durable Zeus evidence, receipts, and exact rollback Shared-runtime smoke tested in a disposable workspace
governed_atomic_file_rename Rename one registered regular file without overwrite Lich-bound proposal; no-replace executor; metadata-only Zeus evidence and exact reverse receipt Shared-runtime and filesystem integration tested
governed_home_assistant_light_set_state Inspect and set one registered light.* entity on or off Lich-bound proposal; bounded provider; token-free Zeus evidence; reconciled or uncertain receipt; separate compensation Fake provider only; not credentialed or live-provider validated
governed capability discovery List and inspect the portfolio from Rubick Oracle read-only rendering; no second registry or authority Shared-runtime tested

Completion commits:

  • cdc31ef Adopt governed capability portfolio as Era 8
  • 8b06de0 Add governed configuration value edits
  • 319d0e3 Add governed atomic file rename
  • 97cf673 Add governed Home Assistant light state
  • 124e896 Add Oracle capability portfolio discovery
  • 288a861 Add Era 8 portfolio runtime acceptance
  • ee65fb7 Complete Era 8 governed capability portfolio

Governed experiential-learning foundation

Portfolio state: complete for the current advisory foundation.

AncientOS can persist independently certified experiential assertions through the governed LifeVault promotion lifecycle, derive deterministic scoped snapshots, attach an exact snapshot to LegionCommander plans after the deterministic task graph is complete, and retain the snapshot identity and evidence provenance for replay. Supported certification evidence is currently limited to exact governed-action receipts and deterministic pytest receipts with exact file-content subject binding and the shared 90-day evidence freshness policy.

LegionCommander is the only experiential consumer. Experience is advisory and cannot influence intent or semantic routing, Rubick readiness or authority_mode, Lich approval, mutation or pending-action authorization, or executor selection. Durable promotion authorizes only persistence of the advisory assertion; it does not approve the action described by that assertion.

Completion commit:

  • 775d0fe Add governed experiential learning foundation

The following remain intentionally absent from the completed contract:

  • confidence or reinforcement scoring, frequency-based ranking, and adaptive strategy weighting;
  • automatic promotion or automatic contradiction adjudication;
  • advisory consumers other than LegionCommander;
  • learned routing, capability readiness, authority, or approval;
  • automatic cross-domain experiential transfer;
  • aggregate validation-suite receipts and generalized artifact/tree subject binding;
  • arbitrary model-authored durable experiential knowledge; and
  • generalized self-optimization.

These limits are architectural boundaries, not incomplete acceptance criteria for the completed foundation.

Governed Inference Registry and Model Selection

Portfolio state: complete for the current production boundary.

The operator explicitly authorized Slices 1–5B and the completion pass. The implemented boundary comprises canonical provider-independent model identity, configuration composition, deterministic aliases, discovery/reachability/ readiness evidence with freshness, bounded Ollama and authenticated OpenAI-compatible observation, canonical inventory and Oracle projection, read-only model questions, request and session selection, bounded restoration, reset to configured routing, targeted readiness verification, provider-name disambiguation, exact-target local/xAI invocation, and shared natural-language semantics across transports.

Live acceptance on 2026-08-21 established the local llama.cpp Qwen 3.8 target and the configured xAI grok-4.3 target through luna-inference. The same Qwen GGUF remains discovered but not ready through Ollama. OpenAI has a provider and adapter contract but no deployed outbound key/model target; LUNA_OPENAI_API_KEY remains only the inbound AncientOS API guard. Completion evidence is recorded in the initiative implementation, tests, deployed acceptance record, and repository history.

The completed capability changes cognition only. It does not change Rubick, Lich, Zeus, executor, mutation, external-contact, tool, or pending-action authority. Explicit selection has no fallback. Existing fast/mid/heavy, LUNA_MODEL_MODE, and luna-local:preferred values remain compatibility configuration when no explicit selection exists.

Remaining inference work is intentionally inactive:

Item Classification Reconsideration condition
Governed persistent default mutation deferred, prerequisite-bound Define an exact registry-ID-to-role/model-mode mutation contract, Lich approval, restart convergence, Zeus evidence, rollback, and unambiguous intent; do not edit environment files from ordinary conversation
Cost-aware routing and local-first/frontier fallback deferred Adopt explicit cost/egress budgets and fallback semantics; preserve no fallback for explicit selection
Automatic capability-aware routing deferred Demonstrate a bounded role/capability policy and replay evidence without granting models routing authority
LegionCommander-selected inference deferred Adopt an advisory-only planning contract with deterministic policy ownership outside the model
Model quality and latency benchmarking candidate, optional Define representative, privacy-safe datasets, metrics, repeatability, and cost bounds
Proactive/background readiness monitoring deferred, scheduler-bound Adopt a narrow cancelable monitor with bounded paid probes, persistence, and no health-triggered switching
Further inventory latency optimization candidate, optional Current five-minute cache, target verification, and provider-scoped reads prove insufficient under measured operator workload
Provider-role readiness unification candidate, prerequisite-bound Define reconciliation between static role/provider posture and concrete target evidence without inflating readiness
Additional frontier providers candidate, provider-bound Supply a concrete credential/configuration boundary, bounded adapter, egress policy, and live acceptance
Multimodal or vision selection candidate, optional Define canonical modality requirements, transport artifacts, provider capability evidence, and privacy policy
Long-context policy candidate, optional Establish per-role context budgets, truncation/retrieval rules, and provider-specific evidence
Model download, removal, and lifecycle management deferred, mutation-bound Adopt typed storage/identity, capacity, provenance, approval, rollback or non-reversibility, and runtime convergence contracts
Automatic model updates deferred Supply artifact trust, compatibility, rollback, and explicit scheduling governance
Session identity cleanup candidate, compatibility-bound Replace historical default_session_key()/discord: labeling only with migration and transport parity evidence
Deeper selection history candidate, optional Demonstrate operator need beyond the bounded two-prior-state restoration contract
Default Ollama availability repair candidate, operational Choose an intended fast target or grant suitable acceleration/resources; current luna-local:preferred resolves to a CPU-loaded 15.4 GiB Qwen3.6 model plus 3.9 GiB KV cache whose runner terminates
Remote data-egress policy enhancement candidate, policy-bound Decide per-target/provider disclosure, content classes, retention assumptions, and whether explicit selection is sufficient authorization
Usage and cost accounting candidate, policy-bound Define provider usage normalization, privacy-safe persistence, budgets, and operator reporting
Per-model observability and metrics candidate, optional Define bounded labels, latency/error/token metrics, retention, and cardinality limits without prompt/output capture

These classifications close the initiative without adopting optional routing, monitoring, lifecycle, or policy work. A future session must explicitly adopt one bounded item before implementation.

Media Manager read-only episode inventory and acquisition discovery

Portfolio state: complete for the current read-only slices.

Episode inventory resolves an explicit TV series through TVmaze and Plex, compares canonical aired-order episodes within an explicit latest-episode, latest-season, or whole-series scope, and returns bounded missing, duplicate, unmatched, wrong-library, ambiguity, and Plex-ahead observations. Acquisition discovery consumes one uniquely resolved aired episode, checks Plex first, and normalizes, filters, deduplicates, and ranks bounded provider observations into an advisory recommendation under media_preference_v1.

Neither slice creates an executable proposal, invokes Lich, starts acquisition, contacts a candidate locator, controls a downloader, mutates the filesystem, refreshes Plex, schedules monitoring, or gains approval or execution authority. The deployed Bitmagnet candidate adapter remains unavailable until a bounded normalized observation contract exists; the synthetic provider is explicit acceptance-only.

Future provider adapters, quality/version policy changes, duplicate handling workflows, automated missing-episode workflows, scheduled monitoring, approval-gated acquisition, download-client integration, filesystem placement, and Plex refresh are not active capabilities. Each requires separate adoption and its applicable evidence, governance, execution, receipt, rollback or non-reversibility, and deployed acceptance boundary.

Completed Media vertical slice

Portfolio state: complete for the demonstrated governed objective lifecycle. The 2026-08-25 watch-loop plan is historical lineage; subsequent operator work extended its provider and playback scope. Commits 62fb131, 019d900, and d914f2a establish the current boundary: natural objective, canonical principal, entity resolution and bounded clarification, exact Lich approval, separate execution, completion observation, Plex verification and qBittorrent cleanup, durable outcome return, current-device Push, named-room playback and observation. A real Pixel notification and awake Living Room playback were observed during that milestone. Playback replay was repaired to make it a one-shot objective. These are historical acceptance facts, not fresh live acceptance in this audit.

Do not reopen the milestone as an unfinished general acquisition program. Cold-device/profile barriers, exact-episode playback identity, observer hosting, clarification crash recovery, retained copies and fresh post-repair replay/Push acceptance are bounded follow-ups in the recovered register below. Completion is not universal device readiness, peer viability, or universal transport parity.

Candidate analysis

Candidates are retained because repository evidence shows plausible bounded operator outcomes. They are not adopted and have no mandatory order.

qBittorrent pause/resume

  • Outcome: pause or resume one exact observed torrent.
  • Reuse: read-only qBittorrent adapter, Chen provider experience, governed proposal and receipt lifecycle.
  • Missing adoption evidence: exact hash identity, fixed operations, provider configuration, durable lifecycle integration, reconciliation, compensation, and transport acceptance.
  • Authority boundary: any mutation remains separately Lich-gated.

Read-only service diagnostics

  • Outcome: explain one service degradation from bounded evidence without remediation.
  • Reuse: Beastmaster inspection, Oracle synthesis, Runtime Composition.
  • Missing adoption evidence: exact target class, freshness, redaction, provider identity, route, and deterministic unavailable behavior.
  • Boundary: read-only diagnosis must not grow an execution or repair path.

Deferred analysis

Deferred items are intentionally outside the active portfolio:

  • container restart and Compose deploy/recreate because Docker authority, convergence, and reversal are unresolved;
  • Git update because remote trust, signatures, dirty state, divergence, and recovery are unresolved;
  • package/system update because root authority, reboot impact, network trust, and downgrade evidence are unresolved;
  • broad delete because retention and irreversibility are unresolved;
  • general scheduling because unattended durable execution and cancellation semantics are absent;
  • autonomous remediation because explicit human governance remains doctrine;
  • general shell execution because typed bounded capabilities are safer and more inspectable.

Reconsideration requires a new evidence-backed adoption proposal. Deferred items do not become candidates automatically when another capability completes.

Governed experiential confidence and reinforcement

Portfolio state: deferred. This is future architecture work, not an implemented capability, an adopted implementation slice, or a Rubick capability. The completed foundation intentionally has no confidence score, reinforcement score, frequency ranking, or adaptive strategy weight.

Before reconsideration, a dedicated planning and review pass must define:

  • the independent evidence that may justify a state change; model self-assessment cannot reinforce its own advice;
  • the exact reinforcement unit (for example a scoped experience, strategy, planning heuristic, evidence relationship, or capability-specific advisory preference) without assuming one in advance;
  • explicit domain, actor, subsystem, capability, and problem-class scope, with no implicit cross-domain transfer;
  • deduplication by underlying evidence identity and treatment of correlated receipts from the same execution or validation chain as non-independent;
  • failure, contradiction, and explicit supersession semantics that preserve historical evidence rather than producing simplistic score oscillation;
  • whether evidence freshness makes a derived posture stale and whether any decay model is justified; automatic decay is not approved;
  • an immutable replay projection containing the exact ranking inputs and state supplied to historical cognition;
  • deterministic inputs, ordering, bounds, and tie-breaking for any advisory ranking;
  • whether automatic evidence-derived updates and operator-authored judgments are durable mutations, and the governance required for each;
  • an explanation contract that answers why one experience ranked above another using evidence and provenance rather than opaque learned state.

Any design must preserve the authority firewall: confidence or reinforcement cannot grant authority, reduce Lich requirements, change authority_mode, make a capability ready, select an unauthorized executor, alter deterministic semantic routing, approve mutation, or authorize pending-action continuation. Its first consumer, if separately adopted, must remain inside an established post-boundary advisory path. LegionCommander is the only current experiential consumer; no additional consumer is approved by this roadmap.

The prohibited feedback loop is explicit: experience may advise cognition, but cognition selecting a strategy and declaring itself successful cannot increase experiential posture without independent certification.

Recommended reconsideration sequence, with each step requiring its own bounded decision where applicable:

  1. accumulate and validate real certified experiences under the completed foundation;
  2. add missing evidence or exact subject-binding adapters only when stable repository contracts justify them;
  3. perform the confidence/reinforcement architecture planning and governance review described above;
  4. consider one bounded deterministic advisory-ranking implementation; and
  5. review any additional advisory consumer separately.

This sequence is not an adopted queue and does not authorize implementation.

Adoption contract

An adoption proposal must contain:

  1. stable capability ID and one bounded operator outcome;
  2. explicit scope, targets, operations, and non-goals;
  3. implementation, integration, and operator-route evidence;
  4. dependency and provider configuration requirements;
  5. authority classes and the exact Lich boundary for mutation;
  6. Zeus evidence, receipt, and outcome-reconciliation requirements;
  7. persistence and restart behavior;
  8. rollback, compensation, or explicit non-reversibility;
  9. security, privacy, identity, and blast-radius analysis;
  10. fixture, local, credentialed integration, and live-provider validation expectations;
  11. focused, transport, package-isolation, documentation, and full repository validation;
  12. explicit operator decision metadata.

Oracle and Rubick may assemble advisory evidence for this packet. They cannot change its lifecycle state. The operator records adopted, deferred, or rejected.

Adoption is not mutation approval. An adopted capability can remain default-disabled, and every live action can remain Lich-gated.

Delivery standard

Read-only capability

A read-only capability must demonstrate:

  • bounded evidence and stable identity;
  • provider configuration and request-time readiness without unsafe probes;
  • deterministic failure for missing, stale, malformed, or unauthorized evidence;
  • transport-neutral Runtime Kernel routing;
  • Runtime Composition and Kernel Record linkage;
  • operator-friendly and diagnostic rendering;
  • no write-capable method reachable from the read path;
  • focused, integration, transport, and repository-wide validation.

Governed mutation capability

A mutation capability must additionally demonstrate:

  • deterministic durable proposal construction;
  • exact action, target, scope, actor, hash, and expiry binding;
  • durable Lich approval separated from execution;
  • request-time freshness and precondition validation;
  • bounded typed execution with no general command path;
  • durable Zeus before/after evidence and receipts;
  • reconciliation for external outcomes;
  • exact rollback, compensation, or explicit non-reversibility;
  • restart-safe continuation and explanation;
  • default-disabled configuration and explicit allowlists;
  • fixture and local acceptance plus honest external validation posture.

Platform extension gate

Capabilities should consume existing platform primitives. A shared platform extension requires either:

  • at least two independent capability consumers; or
  • a demonstrated correctness, security, compatibility, or truthful observability need.

The proposal must document consumers, failure semantics, persistence or migration impact, compatibility, and validation boundaries. Capability-local parsing, policy, allowlists, providers, evidence normalization, execution, and rollback should remain outside shared runtime layers.

Do not introduce a general executor, scheduler, registry, named subsystem, protocol, persistence hierarchy, or transport-specific business rule merely to anticipate candidate work.

Decision record

Decision State Evidence
Adopt Era 7 Oracle Operational Ergonomics historical decision; program complete Era 7 completion commits and Oracle tests
Adopt first Governed Capability Portfolio as Era 8 historical decision; program complete cdc31ef through ee65fb7
Adopt Era 9 No decision; not adopted No canonical adoption record exists
Defer Chen operator watch loop deferred by operator on 2026-08-25 Preserved dirty implementation; reconsideration conditions in deferred analysis
Adopt Chen operator watch loop Historical adoption on 2026-08-25; completed through subsequent Media milestone Exact implementation contract; completion gaps preserved
Adopt Keeper exact-task completion lifecycle consolidation adopted by operator on 2026-08-25; implementation not started Bounded adoption contract
Complete Media objective vertical slice complete, reconciled 2026-09-07 62fb131, 019d900, d914f2a; bounded live limitations retained
Reconcile AncientOS program Authorized bounded catch-up, 2026-09-07 Operator program-reconciliation instruction; no new product adoption or runtime mutation authority
Adopt another capability No decision Keeper exact-task completion remains adopted; the next Core recommendation is advisory

Future decisions must be added here or in a linked canonical decision record, then reflected in architecture metadata and the master portfolio view. Editing a candidate description alone is not adoption.

Historical relationship

The completed Era 8 contract proved configuration edit, atomic rename, Home Assistant light state, and capability discovery. Earlier detailed rankings, recommended sequences, and implementation prompts were planning inputs for that completed program. They are preserved by Git history and must not be replayed as the current queue.

Root era plans and other proposals are historical unless docs/documentation_status.md explicitly classifies them as canonical.