> For the complete documentation index, see [llms.txt](https://faction-os.gitbook.io/faction-os-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/phases/phase_08/prd_phase_08.md).

# PRD Phase 08: Release Hardening and Legacy Decommission

**Status**: Complete **Sessions**: 8 **Estimated Duration**: 8-16 days

**Progress**: 8/8 sessions validated (100%); Sessions 01, 02, 03, 04, 05, 06, 07, and 08 validation and documentation closeouts complete

***

## Overview

Phase 08 turned the completed local-first runtime, collaboration, media, hosted guardrail, and documentation work into release-grade evidence. It recorded or gated the remaining deferrals from Phase 07: trusted unified erasure, production-hosted validation, release-candidate hardening, mobile and accessibility certification evidence, hosted identity claim gates, and legacy evidence decommission.

This phase must preserve FactionOS as local-first by default. Core workflows must continue to work without hosted accounts, hosted storage, analytics, public replay hosting, push delivery, remote access, Cloudflare credentials, provider credentials, or real executors. Any release claim about hosted identity, hosted storage, analytics, public replay, push, remote access, trusted erasure, certification, or production deployment must be backed by source, tests, docs, and validation evidence in this phase.

***

## Progress Tracker

| Session | Name                                                    | Status                 | Est. Tasks | Validated  |
| ------- | ------------------------------------------------------- | ---------------------- | ---------- | ---------- |
| 01      | Release Requirements and Risk Baseline                  | Complete and validated | \~14-20    | 2026-05-31 |
| 02      | Unified Erasure Contract and Inventory                  | Complete and validated | \~16-24    | 2026-05-31 |
| 03      | Local Erasure Runtime and Controls                      | Complete and validated | \~16-24    | 2026-05-31 |
| 04      | War Room and Hosted Identity Release Gate               | Complete and validated | \~16-24    | 2026-05-31 |
| 05      | Production Hosted Validation and Deploy Smoke           | Complete and validated | \~14-22    | 2026-05-31 |
| 06      | Mobile and Accessibility Certification Evidence         | Complete and validated | \~14-22    | 2026-05-31 |
| 07      | Legacy Evidence Decommission and Media Release Gate     | Complete and validated | \~14-22    | 2026-05-31 |
| 08      | Release Candidate Validation and Documentation Closeout | Complete and validated | \~18-25    | 2026-05-31 |

***

## Completed Sessions

* Session 01: Release Requirements and Risk Baseline
* Session 02: Unified Erasure Contract and Inventory
* Session 03: Local Erasure Runtime and Controls
* Session 04: War Room and Hosted Identity Release Gate
* Session 05: Production Hosted Validation and Deploy Smoke
* Session 06: Mobile and Accessibility Certification Evidence
* Session 07: Legacy Evidence Decommission and Media Release Gate

***

## Current And Upcoming Sessions

* Session 01: Release Requirements and Risk Baseline - complete and validated.
* Session 02: Unified Erasure Contract and Inventory - complete and validated.
* Session 03: Local Erasure Runtime and Controls - complete and validated.
* Session 04: War Room and Hosted Identity Release Gate - complete and validated.
* Session 05: Production Hosted Validation and Deploy Smoke - complete and validated.
* Session 06: Mobile and Accessibility Certification Evidence - complete and validated.
* Session 07: Legacy Evidence Decommission and Media Release Gate - complete and validated.
* Session 08: Release Candidate Validation and Documentation Closeout - complete and validated.

## Session 08 Closeout Artifact

Session 08 creates the final release-candidate validation record:

* `.spec_system/archive/phases/phase_08/release_candidate_validation_record.md`

This artifact is the Phase 08 source of truth for release gate command outcomes, prior-session evidence rollup, residual risks, blocker wording, release notes inputs, rollback notes, and the validate workflow handoff. Session 08 release gates and docs sync are recorded for final closeout; Phase 08 is complete, and unproven hosted identity, production-hosted, formal certification, broad media readiness, real executor, analytics/push/remote, and full trusted unified-erasure claims remain no-claim or future scope.

***

## Objectives

1. Convert Phase 08 release, erasure, certification, production validation, and decommission deferrals into a source-backed routing baseline.
2. Ship one trusted unified erasure workflow covering local, browser, Worker, archive, replay, export, diagnostic, backup, and future hosted-state boundaries that are in release scope.
3. Close hosted identity and production-hosted validation release findings without overclaiming optional hosted surfaces.
4. Produce mobile and accessibility certification evidence for supported release surfaces.
5. Decommission or retain legacy evidence only after stable docs and release gates preserve the required value.
6. Run and document final release-candidate gates, security posture, and handoff status.

## Session 01 Baseline Artifacts

Session 01 creates the source-backed baseline for the rest of Phase 08:

* `.spec_system/archive/phases/phase_08/release_requirements_risk_baseline.md`
* `.spec_system/archive/phases/phase_08/phase08_requirement_routing_matrix.md`
* `.spec_system/archive/phases/phase_08/phase08_release_risk_matrix.md`
* `.spec_system/archive/phases/phase_08/decommission_approval_matrix.md`

These artifacts route release requirements to Sessions 02 through 08, define claim-state vocabulary and evidence standards, map open findings to owners, and list decommission candidates without approving deletion. They do not implement erasure, activate hosted identity/storage/analytics/push/remote surfaces, validate production hosting, certify mobile or accessibility behavior, promote media, or delete legacy evidence.

***

## Prerequisites

* Phase 07 completed and archived.
* Phase 07 closeout, `CONSIDERATIONS.md`, `SECURITY-COMPLIANCE.md`, PRD, UX PRD, release, deployment, hosted-service, privacy, and legacy-consolidation docs are reviewed before planning Session 01.
* Optional Cloudflare, hosted, analytics, media-provider, and adapter credentials remain out of tracked files and are used only in explicitly scoped validation environments.
* No legacy evidence, reports, progress ledger entries, or historical media are deleted until Session 07 creates and validates the decommission approval record.

***

## Technical Considerations

### Architecture

Phase 08 should keep release hardening additive, auditable, and reversible. Shared data shapes and release vocabulary should start in `packages/protocol` when more than one package consumes them. Secret-bearing or authorization sensitive release checks should run through server or CLI mediated flows, not browser-exposed raw credentials.

Trusted erasure must be explicit about scope, identity or authority, dry-run summary, irreversible action, idempotency, partial failure, audit output, and verification. Local cleanup, browser reset, Worker leave, diagnostics recovery, and deleting one storage area must not be described as trusted erasure unless the unified workflow proves the complete release scope.

Hosted identity remains a release claim gate. The release may either ship validated active hosted auth or make no hosted identity claim. Room-local Worker authority is still not account identity, organization membership, SSO, public collaboration safety, production audit proof, analytics consent, or trusted erasure.

### Technologies

* TypeScript shared contracts in `packages/protocol`
* Node 20 Express server, CLI, and hook lifecycle state
* React/Vite web cockpit and static public demo
* Cloudflare Worker and Durable Object War Room backend
* Vitest, Playwright, Biome, media gates, secret scan, and release scripts

### Risks

* Trusted erasure is easy to overclaim: require inventory coverage, tests, dry-run output, and negative-claim docs.
* Production-hosted validation may depend on credentials or deployed resources: keep skipped or unavailable evidence explicit and sanitized.
* Legacy decommission can destroy useful evidence: preserve decisions, contracts, risks, hashes, or docs references before deletion.
* Certification wording can overstate automated evidence: distinguish local browser checks, mobile device checks, WCAG evidence, and formal certification.
* Conditional media and hosted-service blockers remain active until the relevant release gates close them.

### Relevant Considerations

* \[P07] **Unified erasure deferred to Phase 08**: one trusted erase/reset workflow must cover archives, memory, settings, lifecycle files, browser state, War Room Durable Object state, replay/export buffers, diagnostics, logs, backups, valid spool state, workspace files, and future hosted surfaces in release scope.
* \[P07] **Hosted services ship as disabled-default guardrails only**: active hosted auth, storage, analytics, push, public replay, and remote access need scoped consent, minimization, redaction, authorization, abuse controls, tests, and docs before any active claim.
* \[P07] **Phase complete is not release complete**: Phase 08 owns release hardening, trusted erasure, production-hosted validation, mobile certification, and legacy decommission.
* \[P04] **Asset provenance gate remains active**: only approved battlefield runtime media are release-ready until promotion evidence closes blockers.
* \[Security] **Open findings**: hosted identity, trusted erasure, and production-hosted validation remain active release risks.

***

## Success Criteria

Phase complete when:

* [ ] All 8 sessions completed and validated.
* [ ] Trusted unified erasure has source, tests, docs, and verification evidence for every release-scoped storage boundary.
* [ ] Hosted identity and optional hosted-service claims are either validated end to end or explicitly absent from release copy.
* [ ] Production-hosted app, public demo, and War Room Worker validation evidence is recorded or explicitly marked unavailable with no release claim.
* [ ] Mobile and accessibility certification evidence is recorded without overclaiming unsupported coverage.
* [ ] Legacy evidence decommission decisions are captured and approved before any deletion or reduction.
* [x] Final release-candidate gates, docs, PRD, UX PRD, security posture, and handoff notes are synchronized.

***

## Dependencies

### Depends On

* Phase 07: Hosted Services and Analytics Guardrails
* Phase 06: Collaboration, Isolation, and Mobile
* Phase 04: Media Catalog and Audio/Visual Pipeline

### Enables

* Release candidate packaging and publication
* Post-release maintenance and future scoped hosted-service activation


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/phases/phase_08/prd_phase_08.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
