> For the complete documentation index, see [llms.txt](https://faction-os.gitbook.io/faction-os-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/phases/phase_08/phase08_requirement_routing_matrix.md).

# Phase 08 Requirement Routing Matrix

**Phase**: 08 - Release Hardening and Legacy Decommission **Session**: 08 - Release Candidate Validation and Documentation Closeout **Status**: Routing updated for Session 08 closeout; complete **Created**: 2026-05-31 **Last Updated**: 2026-05-31

***

## Purpose

This matrix assigns each Phase 08 release requirement to the smallest owning session or to an explicit later deferral. It keeps release blockers visible before implementation begins and prevents local, mocked, planned, unavailable, or documentation-only evidence from being treated as release completion.

## Routing Vocabulary

| Value    | Meaning                                                                              |
| -------- | ------------------------------------------------------------------------------------ |
| Owns     | The session must implement or validate the requirement before Phase 08 can claim it. |
| Supports | The session provides evidence or documentation that another owner consumes.          |
| Defers   | The requirement is explicitly outside Phase 08 or outside the owning session.        |
| No claim | The release must avoid the claim unless later evidence changes this row.             |

## Session Ownership Map

| Session | Primary ownership                                                                                                                                                                  | Prerequisites consumed                                                                                                          | Evidence produced                                                                                                                                                                            |
| ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| S0802   | Unified erasure contract and storage inventory across local, browser, Worker, archive, replay, export, diagnostic, backup, valid spool, workspace, and future hosted placeholders. | Session 01 baseline, current storage docs, Phase 07 erasure deferrals, package README boundaries.                               | Protocol-owned erasure vocabulary, storage-boundary inventory, authority model, dry-run/verification vocabulary, unsupported-claim tests, non-erasure docs.                                  |
| S0803   | Local erasure runtime and CLI/web controls for release-scoped local and browser state.                                                                                             | Session 02 erasure contracts and inventory; local backup, archive, lifecycle, browser, replay, diagnostics, and settings paths. | Dry-run and confirmed local erasure, explicit confirmation UX, audit output, verification, idempotency/partial-failure/redaction tests, package docs.                                        |
| S0804   | War Room room-state erasure and hosted identity release gate.                                                                                                                      | Sessions 01-03 erasure baselines, Phase 07 hosted identity guardrails, current Worker authority and Durable Object persistence. | Worker erasure or no-claim behavior, hosted identity active-validation or no-claim gate, Worker/protocol/web tests, docs that separate room authority, hosted identity, and trusted erasure. |
| S0805   | Production-hosted validation and deploy smoke.                                                                                                                                     | Session 01 validation targets, deployment docs, safe credential or unavailable environment.                                     | Sanitized deployed public demo/app/Worker smoke evidence, Cloudflare dashboard or no-claim evidence, repeatable scripts/runbooks, sanitized residual-risk wording.                           |
| S0806   | Mobile and accessibility release evidence for `apps/web` and public demo surfaces.                                                                                                 | Session 01 claim gates, Phase 06 local browser evidence, release-critical web surfaces.                                         | Supported viewport/browser/input criteria, automated/manual evidence, focused fixes if found, docs distinguishing evidence from formal certification.                                        |
| S0807   | Legacy evidence decommission approval and media release gate revalidation.                                                                                                         | Session 01 decommission matrix, media gates, release docs, stable docs that preserve retained value.                            | Session 07 action record, fail-closed cleanup or retention outcomes, media/quarantine/sensitive-output/docs gate evidence, final candidate dispositions, and no-overclaim handoff.           |
| S0808   | Release-candidate validation and documentation closeout.                                                                                                                           | Sessions 01-07 evidence and residual risks, release gate commands, validation targets.                                          | Full release gate record, PRD/UX/security/docs sync, release readiness or exact blockers, final residual-risk handoff. S0808 consumes S0807 evidence but remains final closeout owner.       |

## Requirement Matrix

| ID       | Requirement                                                                                                                                                                                  | Owner | Supporting sessions | Required evidence                                                                                                                                                                                          | Current claim state                                                                                                                                       |
| -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----- | ------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
| P08-R001 | Preserve local-first operation for server, web, hooks, CLI, adapters, public demo, and Worker-unavailable states.                                                                            | S0808 | S0802-S0807         | Full release gates, docs review, credential-free local workflow evidence.                                                                                                                                  | Local-first release-candidate evidence passed for current shipped surfaces.                                                                               |
| P08-R002 | Define release claim gates and evidence vocabulary before implementation proceeds.                                                                                                           | S0801 | S0808               | This baseline, routing matrix, risk matrix, stable docs references.                                                                                                                                        | Documentation-only baseline.                                                                                                                              |
| P08-R003 | Inventory all release-scoped erasure boundaries.                                                                                                                                             | S0802 | S0803, S0804, S0808 | Boundary list with owner, status, authority, dry-run, verification, and unsupported wording.                                                                                                               | Inventory evidence produced; S0808 keeps full trusted unified erasure no-claim.                                                                           |
| P08-R004 | Add shared erasure contracts for dry-run, confirmation, partial failure, audit, verification, idempotency, and unsupported claims.                                                           | S0802 | S0803, S0804        | Protocol contracts and focused tests that block one-boundary cleanup from being labeled trusted erasure.                                                                                                   | Contract evidence produced; no full trusted unified-erasure claim from contract evidence alone.                                                           |
| P08-R005 | Implement local trusted erasure for archives, memory, exports, replay buffers, settings, diagnostics, logs, backups, lifecycle files, valid spool state, and browser state in release scope. | S0803 | S0802, S0808        | CLI/web controls, explicit confirmation, local deletion/verification, redacted audit, idempotency and failure tests.                                                                                       | Local/browser boundary evidence produced; no hosted, Worker-adjacent, public replay, push, remote, broad workspace-file, or full unified claim by itself. |
| P08-R006 | Keep local erasure redacted and user-initiated.                                                                                                                                              | S0803 | S0802               | Tests and docs prove no raw prompts, paths, commands, tokens, logs, exports, backups, or replay buffers are exposed in previews, progress, errors, or audit output.                                        | Redaction and user-confirmation evidence produced; S0808 docs review passed.                                                                              |
| P08-R007 | Close or explicitly gate War Room Durable Object erasure.                                                                                                                                    | S0804 | S0802, S0803, S0808 | Worker/protocol/web erasure tests or release no-claim docs for Worker storage, authority hashes, participants, idempotency metadata, and recent events.                                                    | Worker room-state evidence produced for one room record; no hosted identity or full trusted unified-erasure claim.                                        |
| P08-R008 | Prevent room-local Worker authority from being described as hosted account identity.                                                                                                         | S0804 | S0801, S0808        | Hosted identity release gate tests and docs; copy blocks SSO, organization, public collaboration safety, analytics consent, production audit proof, and hosted identity claims without active auth.        | Guardrails only; no hosted identity claim.                                                                                                                |
| P08-R009 | Validate active hosted auth before any hosted identity claim, or record explicit no-claim status.                                                                                            | S0804 | S0808               | End-to-end auth evidence or no-claim release docs; account lifecycle, consent, revocation, authorization, audit, abuse controls, local fallback.                                                           | No hosted auth runtime.                                                                                                                                   |
| P08-R010 | Define and run production-hosted validation for deployed app shell if release copy claims it.                                                                                                | S0805 | S0808               | Sanitized app URL/load/fallback evidence, no credential leakage, unavailable no-claim evidence if no host exists.                                                                                          | No production-hosted app claim.                                                                                                                           |
| P08-R011 | Validate deployed public demo release surface.                                                                                                                                               | S0805 | S0807, S0808        | Pages deploy smoke, browser load, service-worker/cache status, public-demo limitations, media gate alignment, sanitized output.                                                                            | Live public-demo smoke remains blocked/no-claim with `SENSITIVE_OUTPUT`; local public-demo gates passed.                                                  |
| P08-R012 | Validate deployed War Room Worker release surface.                                                                                                                                           | S0805 | S0804, S0808        | `/health` smoke, custom domain/workers.dev status, app-level rate limit posture, dashboard constraints, sanitized no-token output.                                                                         | Live Worker smoke remains blocked/no-claim with `WORKER_DEPLOYMENT` and `WORKER_HEALTH_RATE_LIMIT`.                                                       |
| P08-R013 | Keep production-hosted evidence sanitized.                                                                                                                                                   | S0805 | S0801, S0808        | Scripts/runbooks avoid raw account ids, zone ids, tokens, request bodies, room payloads, prompts, commands, local paths, exports, logs, backups, and replay buffers.                                       | S0808 evidence records sanitized issue codes and no raw hosted output.                                                                                    |
| P08-R014 | Produce mobile and accessibility release evidence for declared cockpit and public demo surfaces.                                                                                             | S0806 | S0808               | Viewport, keyboard, focus, dialog, label, reduced-motion, contrast, text-fit, fallback, and mobile evidence.                                                                                               | Phase 06 local evidence only; no formal certification.                                                                                                    |
| P08-R015 | Distinguish automated/manual evidence from formal certification.                                                                                                                             | S0806 | S0808               | UX PRD, web README, release docs, and validation notes label evidence classes and unsupported certification claims.                                                                                        | No formal WCAG/mobile certification claim.                                                                                                                |
| P08-R016 | Revalidate media release gates and conditional media blockers.                                                                                                                               | S0807 | S0805, S0808        | Media gate commands, quarantine checks, service-worker cache review, rights/attribution/metadata/fallback/accessibility/privacy/budget evidence, and `legacy_decommission_media_release_gate.md` outcomes. | S0808 media gates passed; only approved battlefield runtime records are release-ready.                                                                    |
| P08-R017 | Preserve unique legacy evidence value before deletion, reduction, or archive.                                                                                                                | S0807 | S0801, S0808        | Final approval matrix, stable-doc replacements, explicit retain/archive/reduce/delete/blocked/unavailable decisions, affected gate results, rollback notes.                                                | S0807 fail-closed dispositions remain; no additional destructive cleanup is approved by S0808.                                                            |
| P08-R018 | Keep historical prompts, probes, OAuth values, tokens, sensitive paths, copied code, generated drafts, and quarantined media out of stable docs.                                             | S0807 | S0801, S0808        | Sensitive-output scan, docs review, media quarantine gate, manual review, and sanitized evidence-only action record.                                                                                       | Sanitized evidence rule active; raw historical evidence remains out of stable docs.                                                                       |
| P08-R019 | Run full release-candidate gate stack.                                                                                                                                                       | S0808 | S0802-S0807         | Install, format, lint, workspace typecheck, tests, build, media checks, battlefield checks, secret scan, whitespace, ASCII/LF, focused Phase 08 validation commands.                                       | Local-first gate stack passed; live hosted blockers are recorded in `release_candidate_validation_record.md`.                                             |
| P08-R020 | Synchronize PRD, UX PRD, security posture, considerations, release docs, package READMEs, and final handoff.                                                                                 | S0808 | S0801-S0807         | Updated docs, residual-risk table, release readiness or exact blocker list.                                                                                                                                | Docs sync and handoff are complete for implementation closeout; validate is pending.                                                                      |

## Explicit Later Deferrals

These requirements are not Phase 08 Session 01 deliverables and must remain outside shipped release claims unless a later owning session adds evidence:

| Deferral                                                                                                                                                    | Owner or future scope                                                            | No-claim wording                                                                   |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- |
| Active Supabase auth, SSO, organization membership, account UI, billing, or account-backed audit trails                                                     | S0804 only if explicitly scoped; otherwise later hosted identity phase           | The release makes no hosted identity or account-backed authorization claim.        |
| Active hosted storage, Supabase schema/buckets/RLS/migrations, hosted public replay pages, hosted retention, hosted takedown, or account-backed persistence | Later scoped hosted persistence/public replay phase                              | Hosted persistence and public replay remain planned or disabled guardrails.        |
| Active analytics capture, tracking scripts, dashboards, recorder, heatmaps, session replay, or server ingestion                                             | Later scoped analytics activation phase                                          | Analytics remains disabled by default; Phase 07 proves guardrails only.            |
| Web Push delivery, push subscription storage, VAPID runtime use, Cloudflare Tunnel, remote access gateway, remote executor, or hosted diagnostic agent      | Later scoped operations phase                                                    | Browser notifications are local-only and remote operations are unavailable.        |
| Real file, git, terminal, Docker, Worker, remote, hosted, or webhook command executors                                                                      | Future threat-model phase                                                        | Guarded actions remain proposals/decisions with unavailable execution.             |
| Broad media promotion beyond approved battlefield records                                                                                                   | S0807 or later media promotion phase                                             | Conditional and quarantined media remain non-release.                              |
| Formal third-party WCAG certification or physical-device certification                                                                                      | S0806 only if matching evidence exists; otherwise later certification engagement | Phase 08 may record evidence, but not formal certification without matching proof. |

## Coverage Review

| Coverage area                       | Routed requirements                              | Owner coverage                                                                                                 |
| ----------------------------------- | ------------------------------------------------ | -------------------------------------------------------------------------------------------------------------- |
| Release baseline and final closeout | P08-R001, P08-R002, P08-R019, P08-R020           | S0801 establishes the baseline; S0808 validates final release readiness.                                       |
| Trusted erasure                     | P08-R003, P08-R004, P08-R005, P08-R006, P08-R007 | S0802 defines contracts/inventory, S0803 implements local/browser runtime, S0804 handles Worker/no-claim gate. |
| Hosted identity                     | P08-R008, P08-R009                               | S0804 owns active hosted identity proof or no-claim wording.                                                   |
| Production-hosted validation        | P08-R010, P08-R011, P08-R012, P08-R013           | S0805 owns deployed app/public-demo/Worker validation and sanitization.                                        |
| Mobile/accessibility evidence       | P08-R014, P08-R015                               | S0806 owns release evidence and certification no-overclaim wording.                                            |
| Media and decommission              | P08-R016, P08-R017, P08-R018                     | S0807 owns media gate revalidation, approval matrix, and sensitive-output preservation.                        |

No Phase 08 release requirement is intentionally unrouted. Requirements that would activate hosted auth, hosted persistence, active analytics, push, remote access, tunnels, real executors, broad media promotion, or formal certification remain explicit no-claim or later-deferral rows unless a future accepted scope changes the PRD.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/phases/phase_08/phase08_requirement_routing_matrix.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
