> For the complete documentation index, see [llms.txt](https://faction-os.gitbook.io/faction-os-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/phases/phase_08/decommission_approval_matrix.md).

# Phase 08 Decommission Approval Matrix

**Phase**: 08 - Release Hardening and Legacy Decommission **Session**: 07 - Legacy Evidence Decommission and Media Release Gate **Status**: Session 07 final-review tracking active - cleanup remains fail-closed **Created**: 2026-05-31 **Last Updated**: 2026-05-31

***

## Purpose

This matrix lists legacy evidence, reports, ignored media intake, copied historical bundles, and progress-ledger sources that may be retained, blocked, archived, reduced, deleted, or marked unavailable. Session 01 created the candidate-only baseline. Session 07 owns the final approval/action record at `.spec_system/archive/phases/phase_08/legacy_decommission_media_release_gate.md`.

## Disposition Vocabulary

| Disposition | Meaning                                                                                                                                |
| ----------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| Candidate   | Listed for later Session 07 review; no deletion is approved.                                                                           |
| Retain      | Keep because stable docs still need the source or no replacement exists.                                                               |
| Archive     | Move or preserve in an approved archive after stable docs retain the value.                                                            |
| Reduce      | Remove duplicate detail only after stable docs preserve unique requirements, risks, and decisions.                                     |
| Delete      | Remove only after Session 07 approval and affected gates pass.                                                                         |
| Blocked     | Do not change the candidate because stable replacement coverage, gate evidence, or cleanup authority is incomplete.                    |
| Unavailable | Candidate is absent from the tracked or local evidence available to the session; retain conservative wording and do not claim cleanup. |

## Approval Rule

No candidate is approved for deletion by default. Deletion, reduction, or archive requires all of the following:

1. Stable docs preserve unique requirements, contracts, risks, provenance conclusions, hashes, decisions, or future-work notes.
2. No raw token, OAuth, probe output, prompt, sensitive local path, copied code, generated draft, or quarantined media content is copied into stable docs.
3. Session 07 records the exact disposition in the action record and reruns affected release, media, quarantine, sensitive-output, docs, whitespace, ASCII, and LF gates.

## Session 07 Final Review Tracking

The current Session 07 disposition is conservative: retain stable evidence, keep ignored `EXAMPLES/` material ignored, and block destructive cleanup where media, sensitive-output, or replacement coverage could drift. The action record contains the detailed rollback notes and command outcomes.

| Candidate group                                                                                         | Session 07 outcome                                                | Stable replacement status                                                                                                                                          | Cleanup authority                                                          | Session 08 handoff                                                                                                                                     |
| ------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Historical route, event, hook, architecture, build-link, and prompt findings under `EXAMPLES/findings/` | Retain ignored evidence                                           | API, hook, package, privacy, media, and legacy docs preserve current conclusions without raw content                                                               | No deletion or reduction approved in tracked output                        | Verify no final release copy depends on ignored files as product authority.                                                                            |
| Copied first-pass artifacts under `EXAMPLES/1st-pass-artifacts/`                                        | Retain ignored evidence                                           | Package READMEs, API docs, isolation docs, and legacy consolidation preserve hook, manifest, template, Docker, package, and token-hygiene lessons                  | No deletion or reduction approved in tracked output                        | Keep copied code out of stable docs and release artifacts.                                                                                             |
| Historical reports `EXAMPLES/REPORT.md` and `EXAMPLES/REPORT.html`                                      | Retain ignored evidence                                           | Stable docs preserve migration pointers, unique findings, media/service/license/security conclusions, and rejected/deferred rationale at summary level             | No deletion or reduction approved in tracked output                        | Confirm final docs do not duplicate raw report content or rely on reports as current authority.                                                        |
| `docs/PROGRESS.md`                                                                                      | Retain tracked evidence                                           | PRD phase history, stable docs, archived sessions, and Git history provide replacement context, but tracked ledger remains useful resume evidence until Session 08 | No reduction or deletion approved                                          | Session 08 may reassess after final release closeout sync.                                                                                             |
| Ignored `EXAMPLES/` media intake and copied build output                                                | Blocked from release promotion; retain ignored reference evidence | `docs/media-assets.md`, Phase 04 media gap matrix, and ADR 0004 preserve quarantine policy and blocker conclusions                                                 | No runtime import, copy, transform, archive, delete, or promotion approved | Keep non-release wording unless all source, rights, attribution, optimization, metadata, fallback, accessibility, privacy, and budget evidence closes. |
| Generated media drafts and provider staging                                                             | Retain tracked manifest; block raw staging promotion              | Draft manifest and media docs preserve redacted draft posture and blocker conclusions                                                                              | No raw provider output is tracked; no runtime promotion approved           | Keep provider-run evidence sanitized and non-runtime.                                                                                                  |
| Historical service-discovery, hosted-service, token, OAuth, probe, prompt, and path evidence            | Block raw evidence; retain posture conclusions only               | Hosted-services, privacy/security, and environment docs preserve no-claim and reserved-variable conclusions                                                        | No raw values or probe output may be copied into tracked docs              | Secret scan and docs review remain required.                                                                                                           |
| Archived spec-system sessions and phase artifacts                                                       | Retain                                                            | Archive records and PRD phase history remain validation evidence                                                                                                   | No deletion approved                                                       | Session 08 consumes archive evidence for final closeout.                                                                                               |

## Candidate Matrix

The original candidate matrix remains below as the detailed source map and blocked-condition reference. The Session 07 outcome table above and the action record are the current decision layer.

| Candidate                                                                                    | Current role                                                                                                                 | Retained value to preserve                                                                                                | Replacement or stable owner before action                                                                     | Allowed Session 07 options                                                             | Blocked deletion conditions                                                                                                                            |
| -------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `EXAMPLES/findings/api-routes.txt`                                                           | Historical route inventory and unsupported-route evidence.                                                                   | Route families, unsupported/stubbed classifications, local server boundary risks.                                         | `docs/api/event-api-hook-contracts.md`, `docs/api/README_api.md`, server README.                              | Retain, reduce, archive, or delete after coverage review.                              | Blocked if unsupported routes, route auth/schema gaps, or future route families are not represented elsewhere.                                         |
| `EXAMPLES/findings/websocket-events.txt`                                                     | Historical WebSocket event names and hydration comparison evidence.                                                          | Current hydration frames, client-message boundaries, typed-only/planned event names.                                      | Protocol README, API docs, Phase 01 archive, current tests.                                                   | Retain, reduce, archive, or delete after coverage review.                              | Blocked if event families or unsupported behavior are not represented in protocol/API docs.                                                            |
| `EXAMPLES/findings/claude-hook-contract.md`                                                  | Historical hook payload and compatibility reference.                                                                         | Hook event mapping, supported `eventName`/`hook` dispatch, selected compatibility lessons.                                | `apps/hooks/README_hooks.md`, `docs/api/event-api-hook-contracts.md`.                                         | Retain, reduce, archive, or delete after coverage review.                              | Blocked if hook mapping, fallback, spool, or privacy requirements are not captured.                                                                    |
| `EXAMPLES/findings/architecture.md`                                                          | Historical architecture and optional service map.                                                                            | Local-first package map, optional services, archive/memory posture, hosted-service gaps.                                  | `docs/ARCHITECTURE.md`, `docs/hosted-services.md`, `docs/privacy-and-security.md`.                            | Retain, reduce, archive, or delete after coverage review.                              | Blocked if hosted identity, erasure, production validation, adapter, or media risks are not captured elsewhere.                                        |
| `EXAMPLES/findings/BUILD_LINKS.md`                                                           | Historical build/source pointers.                                                                                            | Pointer evidence for source groups and stale claims superseded by current docs/tests.                                     | `docs/legacy-consolidation.md`, package READMEs, Git history.                                                 | Retain, archive, or delete after confirming no unique contract remains.                | Blocked if any current package boundary still relies on this file as the only reference.                                                               |
| `EXAMPLES/findings/llm-prompts/`                                                             | Historical prompt inventory.                                                                                                 | Prompt surface boundaries, provider-transfer caution, privacy-sensitive prompt handling.                                  | Server README, privacy docs, Phase 01 LLM fallback archive.                                                   | Retain, reduce, archive, or delete after privacy review.                               | Blocked if raw prompt bodies would need to be copied into stable docs; preserve conclusions only.                                                      |
| `EXAMPLES/1st-pass-artifacts/`                                                               | Copied historical packages, hooks, manifests, templates, Docker recipe, skills, service configs, and media/model references. | Hook install lessons, manifest/template gaps, package evidence, Docker/isolation future-scope notes, token hygiene risks. | Package READMEs, `docs/legacy-consolidation.md`, `docs/isolation-and-sandbox.md`, API docs, security posture. | Retain, reduce, archive, or delete by child group after replacement review.            | Blocked if copied code is the only evidence for a requirement, risk, or future-work note; do not copy bundled historical code into stable docs.        |
| `EXAMPLES/REPORT.md` and `EXAMPLES/REPORT.html`                                              | Historical extraction reports.                                                                                               | Migration pointers, unique findings, media/service/license/security conclusions.                                          | PRD, UX PRD, API docs, media docs, security docs, legacy consolidation.                                       | Retain ignored, archive, or delete after unique findings are captured.                 | Blocked if unique findings are not represented or if removal would lose rationale for rejected/deferred scope.                                         |
| `docs/PROGRESS.md`                                                                           | Historical build ledger.                                                                                                     | Milestone chronology, old phase labels, progress context for previous development.                                        | Stable docs, PRD phase history, Git history, archived session summaries.                                      | Retain, reduce, archive, or delete after stable docs and Git history cover milestones. | Blocked if current resume context, phase status, or milestone evidence is still available only here.                                                   |
| Ignored `EXAMPLES/` media intake                                                             | Quarantined prototype, unknown-provenance, copied, generated, or historical media and build output.                          | Standards, gaps, hashes, provenance concerns, rejected/deferred media decisions.                                          | `docs/media-assets.md`, Phase 04 media gap matrix, Session 07 final media/decommission record.                | Retain, archive, or delete only after media gate review; no runtime promotion.         | Blocked if source, rights, attribution, optimization, metadata, browser support, fallback, accessibility, privacy, or size-budget evidence is missing. |
| Generated media drafts and provider staging                                                  | Ignored local first-draft outputs and provider response evidence.                                                            | Draft provenance, prompt-redaction lessons, rights/cost/retention risk notes.                                             | Draft manifest, media docs, release media gate evidence.                                                      | Retain ignored, reduce, or delete after final media gate review.                       | Blocked if raw provider prompts, response payloads, account ids, output paths, or draft media would need to be tracked.                                |
| Historical service-discovery, hosted-service, token, OAuth, probe, prompt, and path evidence | Sensitive posture evidence in historical intake.                                                                             | Posture conclusions, no-overclaim lessons, blocked categories, reserved variable lessons.                                 | Hosted-services docs, privacy docs, environment docs, security posture.                                       | Retain ignored, summarize, archive, or delete after sensitive-output review.           | Blocked if stable docs would need raw tokens, OAuth values, probe output, prompt bodies, command output, or sensitive local paths.                     |
| Archived spec-system sessions and phase artifacts                                            | Completed session evidence and validation records.                                                                           | Validated implementation history, test outcomes, security/compliance notes, handoff records.                              | `.spec_system/archive/` and current PRD phase history.                                                        | Retain.                                                                                | Deletion blocked unless a separate archival policy replaces validation evidence.                                                                       |

## Blocked Deletion Conditions

Session 07 must block deletion or reduction when any of these conditions apply:

* A candidate is the only source for a unique requirement, API/event/hook contract, route classification, package boundary, media provenance conclusion, security risk, privacy rule, or future-work note.
* Stable docs do not yet preserve the retained value in concise current language.
* Replacement docs would require raw tokens, OAuth values, service-role values, account ids, zone ids, probe responses, prompt bodies, command output, sensitive local paths, copied bundled code, generated provider payloads, or quarantined media excerpts.
* Media candidates lack source, rights, attribution, optimized output, metadata cleanup, browser support, fallback, accessibility, privacy, or budget evidence.
* Deletion would change public demo cache behavior, media availability, release docs, package README claims, API docs, or security posture without rerunning affected gates.
* The final approval matrix has not assigned a disposition and owner to the exact child path being changed.

## Candidate Summary

| Group                                     | Session 01 disposition | Session 07 handoff                                                                                                                     |
| ----------------------------------------- | ---------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| Historical findings                       | Candidate only         | Verify stable API/event/hook/architecture/hosted/security coverage before reduce/archive/delete.                                       |
| Copied first-pass artifacts               | Candidate only         | Review by child group; preserve package, hook, template, Docker, and service-config lessons without copying historical code.           |
| Reports                                   | Candidate only         | Preserve unique migration pointers and findings before local deletion or archive.                                                      |
| Progress ledger                           | Candidate only         | Confirm PRD phase history, stable docs, archived summaries, and Git history cover retained milestones.                                 |
| Ignored media intake and generated drafts | Candidate only         | Revalidate media provenance, quarantine, rights, metadata, accessibility, privacy, service-worker, and budget gates before any action. |
| Sensitive service-discovery evidence      | Candidate only         | Preserve posture conclusions only; never copy raw sensitive values into stable docs.                                                   |
| Archived spec-system sessions             | Retain                 | Keep validation and implementation history unless a separate archival policy replaces it.                                              |

This matrix deliberately contains no "approved delete" row. Any later cleanup must update this file or a Session 07 successor with final disposition, approval evidence, commands or affected paths, gate results, and residual-risk wording.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/phases/phase_08/decommission_approval_matrix.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
