> For the complete documentation index, see [llms.txt](https://faction-os.gitbook.io/faction-os-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/phases/phase_08/release_requirements_risk_baseline.md).

# Phase 08 Release Requirements And Risk Baseline

**Phase**: 08 - Release Hardening and Legacy Decommission **Session**: 01 - Release Requirements and Risk Baseline **Status**: Baseline complete for Session 01 **Created**: 2026-05-31

***

## Purpose

This baseline records the release claim gates, evidence standards, local-first release boundary, open release risks, and ownership handoff for Phase 08. It is documentation-only: it does not implement trusted erasure, activate hosted services, certify mobile or accessibility behavior, validate production hosting, promote media, or approve legacy deletion.

## Source Evidence Reviewed

| Source                                                                                                                                                                      | Release relevance                                                                                                                  |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- |
| `.spec_system/PRD/PRD.md`                                                                                                                                                   | Phase 08 product objective, local-first constraints, status map, and historical-source rules.                                      |
| `.spec_system/PRD/PRD_UX.md`                                                                                                                                                | UX no-overclaim rules for hosted services, certification, media, reset, and erasure wording.                                       |
| `.spec_system/archive/phases/phase_08/PRD_phase_08.md`                                                                                                                      | Phase 08 objectives, prerequisites, risks, success criteria, and session sequence.                                                 |
| `.spec_system/archive/phases/phase_08/session_02_unified_erasure_contract_and_inventory.md` through `session_08_release_candidate_validation_and_documentation_closeout.md` | Owning session stubs for erasure, identity, production validation, certification evidence, media/decommission, and final closeout. |
| `.spec_system/archive/sessions/phase07-session07-hosted-guardrails-validation-and-documentation-closeout/validation.md`                                                     | Phase 07 closure evidence and explicit Phase 08 deferrals.                                                                         |
| `.spec_system/CONSIDERATIONS.md`                                                                                                                                            | Active concerns for erasure, hosted guardrails, redaction, media provenance, local-first boundaries, and release completeness.     |
| `.spec_system/SECURITY-COMPLIANCE.md`                                                                                                                                       | Open findings for hosted identity, trusted erasure, and production-hosted validation.                                              |
| `docs/release.md`                                                                                                                                                           | Current release gates, Phase 07 guardrail evidence, and decommission gates.                                                        |
| `docs/deployment.md`                                                                                                                                                        | Current deployment status, Cloudflare surfaces, and production-hosted no-claim wording.                                            |
| `docs/hosted-services.md`                                                                                                                                                   | Hosted-service boundaries for identity, storage, analytics, public replay, push, remote access, and diagnostics.                   |
| `docs/privacy-and-security.md`                                                                                                                                              | Data inventory, external-transfer boundaries, and open release risks.                                                              |
| `docs/ARCHITECTURE.md`                                                                                                                                                      | Local-first architecture boundaries and current gaps.                                                                              |
| `docs/environments.md`                                                                                                                                                      | Local, deployed Worker, hosted, and reserved-variable environment boundaries.                                                      |
| `docs/legacy-consolidation.md`                                                                                                                                              | Historical evidence disposition vocabulary and Phase 08 candidate-only cleanup rules.                                              |
| Package README files                                                                                                                                                        | Boundary ownership for protocol, server, web, warroom, cli, hooks, and adapters.                                                   |

## Local-First Release Boundary

FactionOS remains local-first by default for Phase 08. The release can claim local-first operation only when the server, web cockpit, hooks, CLI, adapters, public demo, and optional Worker-unavailable War Room states keep working without:

* Hosted accounts, Supabase, SSO, organization membership, hosted storage, or account-backed audit trails.
* Umami analytics capture, analytics dashboards, recorder, heatmap, session replay, or account-backed analytics consent storage.
* Public replay hosting, hosted replay upload, takedown runtime, hosted retention, hosted deletion, or hosted diagnostics upload.
* Web Push delivery, push subscription storage, VAPID private key use, Cloudflare Tunnel, remote access, remote executors, hosted diagnostic agents, or real file/git/terminal/Docker executors.
* Cloudflare credentials, provider credentials, deployed app credentials, hosted project credentials, or real executor credentials.

Optional Worker federation remains a separate external-transfer surface. It can be described as an optional room relay only when docs and tests preserve the room-local authority boundary, redacted payload allowlists, and local-only fallback. It must not be described as hosted identity, hosted storage, public replay hosting, analytics, production-hosted validation, remote execution, or trusted erasure.

## Release Claim Gate Inventory

| Claim surface                | Current evidence                                                                                                                                                                                                      | Release claim allowed now                                                                                                                       | Phase 08 gate before stronger claim                                                                                                                                                                                                |
| ---------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Local-first operation        | Phase 07 full suite and stable docs show core workflows run credential-free and hosted surfaces are disabled, planned, or unavailable.                                                                                | Yes, limited to current local server, web, hooks, CLI, adapters, public demo, and optional Worker-unavailable fallback behavior.                | Session 08 must rerun release gates and docs review after Phase 08 changes.                                                                                                                                                        |
| Optional Worker federation   | Phase 05 and Phase 06 validated optional Worker room lifecycle, room-local authority, safe frames, and local browser UX with mocked or same-origin evidence; deployment docs list Worker endpoints and health checks. | Yes, as an optional room relay with redacted federation and local fallback.                                                                     | Session 04 must address Worker erasure and hosted identity no-overclaim gates; Session 05 must record deployed Worker smoke or no-claim unavailable evidence.                                                                      |
| Hosted identity              | Phase 07 Session 03 ships planned/unavailable vocabulary, diagnostics, browser helper copy, and no-overclaim docs only.                                                                                               | No active hosted identity, SSO, organization, account UI, production audit, public collaboration safety, or account-backed authorization claim. | Session 04 must either validate active hosted auth end to end or record an explicit no-hosted-identity claim.                                                                                                                      |
| Hosted storage               | Phase 07 Session 04 ships planned/unavailable hosted persistence and disabled public replay vocabulary only; no Supabase client, schema, bucket, migration, upload endpoint, or account storage exists.               | No active hosted storage or account-backed persistence claim.                                                                                   | Later scoped hosted-persistence work must ship schema artifacts, authorization, consent, retention, export, deletion, tests, docs, and local fallback. Phase 08 should keep no-claim wording unless that work exists.              |
| Analytics                    | Phase 07 Session 05 ships disabled-default analytics readiness and payload scrubbing; no sender, SDK import, tracking script, dashboard, or event capture is active.                                                  | Yes, guardrails only: analytics remains disabled by default and no events are sent.                                                             | Any active analytics claim needs config plus consent, opt-out, payload minimization, sender tests, docs, and local fallback in a scoped session.                                                                                   |
| Public replay                | Current replay sharing is redacted local URL-fragment sharing. Phase 07 public replay posture is disabled.                                                                                                            | No hosted public replay claim.                                                                                                                  | Future public replay needs consent, caps, redaction, expiration, takedown, no-index, abuse controls, authorization, local fallback, and tests before activation.                                                                   |
| Push                         | Phase 07 Session 06 keeps browser notifications local-only and Web Push disabled/unavailable.                                                                                                                         | Yes, local OS notification behavior only; no push delivery claim.                                                                               | Future Web Push needs opt-in, subscription storage, VAPID boundary, unsubscribe, retention, payload tests, and local fallback.                                                                                                     |
| Remote access and tunnels    | Phase 07 Session 06 keeps remote access, Cloudflare Tunnel, and hosted diagnostic agents unavailable; CLI diagnostics are loopback-only.                                                                              | No remote access, tunnel, hosted diagnostic agent, or remote executor claim.                                                                    | Future remote access needs explicit opt-in, local auth or hosted authorization, token expiration and revocation, Origin/CORS, rate limits, audit, abuse controls, redaction, timeout handling, tests, and docs.                    |
| Trusted unified erasure      | Security posture records P06-S07-ERASURE as open. Current cleanup, reset, leave, uninstall, recovery, storage deletion, and diagnostics cleanup are narrow operations only.                                           | No trusted erasure or release-grade deletion claim.                                                                                             | Sessions 02-04 must define inventory, contracts, authority, dry-run, confirmation, runtime behavior, Worker state coverage or no-claim wording, audit, verification, idempotency, partial failure, and redaction.                  |
| Certification                | Phase 06 validates scoped local desktop/mobile browser behavior; UX PRD says formal certification remains out of scope.                                                                                               | No formal WCAG certification, mobile device certification, or broad accessibility certification claim.                                          | Session 06 must define supported surfaces and evidence classes, run release evidence, fix scoped blockers, and label automated/manual/formal evidence honestly.                                                                    |
| Production-hosted validation | Deployment docs list public demo Pages and War Room Worker endpoints, but Phase 07 closeout says local/mocked/same-origin evidence does not prove deployed behavior.                                                  | No deployed app, production-hosted app, production account, or production-hosted validation claim.                                              | Session 05 must define targets, run or record deployed app/public demo/Worker smoke, sanitize output, and record unavailable no-claim evidence where credentials or hosts are absent.                                              |
| Media readiness              | Phase 04 makes battlefield background and hero standees release-ready; portraits, brand, showcase, public-demo speech/music, generated references/drafts, unknown provenance, and historical intake retain blockers.  | Yes, only for the approved battlefield runtime records and their public-demo mirrors.                                                           | Session 07 must revalidate media gates, conditional media, quarantine, sensitive-output checks, service-worker cache, rights, attribution, metadata, fallback, accessibility, privacy, and budgets before any broader media claim. |
| Legacy deletion              | `docs/release.md` and `docs/legacy-consolidation.md` list candidates only and require Phase 08 gates before deletion.                                                                                                 | No deletion, reduction, or decommission completion claim.                                                                                       | Session 07 must preserve unique retained value, approve dispositions, perform cleanup if allowed, and rerun affected release/media/sensitive-output/docs gates.                                                                    |

## Evidence Standards

### Claim State Vocabulary

| State         | Meaning                                                                                                             | Release-copy rule                                                                    |
| ------------- | ------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------ |
| Shipped       | Source, tests, docs, and validation evidence exist for the current release surface.                                 | May be described as current behavior with evidence path references.                  |
| Guardrail     | Source and tests protect a disabled, planned, unavailable, or no-overclaim boundary, but the feature is not active. | May be described as a guardrail only; do not imply active capability.                |
| Planned       | Requirements or contracts exist, but runtime behavior is not active.                                                | Describe as planned or future only.                                                  |
| Disabled      | Runtime code exists but does not execute or transfer data unless explicit config and consent/intent exist.          | Describe the disabled default and activation gate; do not imply capture or transfer. |
| Unavailable   | The surface reports a compact unsupported or unavailable state.                                                     | Describe as unavailable; do not treat as failure of local-first operation.           |
| Evidence-only | Historical, archived, local, mocked, or documentation evidence exists for traceability.                             | Cite as evidence only; do not describe as current shipped behavior.                  |
| No claim      | The release intentionally avoids the claim because evidence is absent or out of scope.                              | Use negative wording in release docs and residual-risk notes.                        |
| Blocked       | A release claim cannot be made because required evidence is missing or failing.                                     | Name the blocker, owner session, and required evidence.                              |

### Minimum Evidence By Claim Type

| Claim type                         | Required evidence before claiming                                                                                                                                                                                                                                                              |
| ---------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Local-first operation              | Credential-free local workflow checks, release gates, docs review, and confirmation that absent hosted credentials do not break core workflows.                                                                                                                                                |
| Hosted identity                    | Provider/account flow source, token validation, consent, expiry, logout, revocation, account export/deletion handoff, role/organization mapping if claimed, authorization checks, audit events, abuse controls, failure paths, local-only fallback, tests, docs, and production-safe evidence. |
| Hosted storage or public replay    | Schema artifacts or bucket policy, server-mediated authorization where sensitive, RLS/authorization tests, consent, retention, export, deletion, expiration, takedown, no-index posture, abuse controls, public-safe errors, local fallback, tests, and docs.                                  |
| Analytics capture                  | Explicit config plus consent, opt-out dominance, payload allowlists, blocked-category tests, sender or SDK tests, dashboard/retention docs if claimed, no raw sensitive fields, and local fallback.                                                                                            |
| Push delivery                      | Permission and app opt-in, subscription consent, VAPID exposure boundaries, unsubscribe, retention, payload minimization, backend delivery tests, failure states, and local notification fallback.                                                                                             |
| Remote access or tunnels           | Explicit operator opt-in, local auth or hosted authorization, token expiration and revocation, Origin/CORS controls, rate limits, audit, abuse controls, redaction, timeouts, no executor overclaim, tests, and docs.                                                                          |
| Trusted erasure                    | Complete release-scoped boundary inventory, authority model, dry-run, irreversible confirmation, idempotency, partial-failure reporting, redacted audit output, verification, failure states, tests, docs, and explicit exclusions.                                                            |
| Production-hosted validation       | Sanitized deployed target checks for app shell, public demo, Worker health/custom domain, dashboard constraints where applicable, unavailable no-claim evidence for absent hosts or credentials, and no raw credential or payload output.                                                      |
| Mobile/accessibility certification | Declared supported surfaces, viewports, browsers, input methods, focus/dialog/label/reduced-motion/contrast/text-fit criteria, automated and manual evidence as applicable, and wording that does not claim formal certification without matching proof.                                       |
| Media release readiness            | Source, rights, attribution, optimized output, dimensions/duration, byte size, metadata cleanup, browser support, fallback behavior, accessibility, privacy, service-worker/cache impact, and budget evidence.                                                                                 |
| Legacy decommission                | Stable-doc replacement of retained value, final approval disposition, sensitive-output review, affected release/media/docs gates, and a rollback or recovery note where useful.                                                                                                                |

### No-Overclaim Rules

* Worker room authority is room-local bearer proof only. It is not hosted account identity, SSO, organization membership, public collaboration safety, analytics consent, production audit proof, or trusted erasure.
* Local reset, browser storage cleanup, diagnostics recovery, CLI uninstall, Worker leave, one-boundary deletion, or manual file removal is not trusted unified erasure.
* Local, mocked, same-origin, or browser-only evidence is not production-hosted validation.
* Automated accessibility checks and local Playwright evidence are not formal WCAG certification or physical-device certification unless matching manual or third-party evidence is recorded.
* Guardrail tests for hosted config, identity, persistence, analytics, operations, notifications, and diagnostics prove guarded posture only. They do not activate hosted auth, hosted storage, analytics capture, public replay hosting, push delivery, remote access, tunnels, production validation, or trusted erasure.
* Historical artifacts, archived reports, ignored media intake, generated drafts, and `docs/PROGRESS.md` are evidence only until Session 07 records an approved disposition and affected gates pass.

### Sanitized Output Requirements

Phase 08 artifacts and validation notes may record bounded labels, counts, booleans, status summaries, docs paths, command names, test file names, hashes, and sanitized URLs that are already public documentation values. They must not record raw:

* Env values, bearer tokens, API keys, service-role values, VAPID private keys, OAuth codes, refresh tokens, ID tokens, webhook secrets, or provider keys.
* Cloudflare account ids, zone ids, API tokens, tunnel tokens, request headers, request bodies, client IPs, room payloads, or authority tokens.
* Prompts, provider prompts, transcripts, command bodies, terminal output, raw file contents, broad local paths, home paths, workspace roots, exports, archives, logs, backups, replay buffers, scan payloads, or diagnostics.
* Raw provider responses, generated draft prompts, generated absolute output paths, copied historical code, copied historical excerpts, or quarantined media content.

## Phase 08 Ownership Summary

| Area                                      | Owner session | Baseline requirement                                                                                            | Release copy before owner closes                                                         |
| ----------------------------------------- | ------------- | --------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- |
| Claim gates and risk baseline             | S0801         | Maintain this source-backed baseline and keep docs from overclaiming before implementation evidence exists.     | Session 01 is planning evidence only.                                                    |
| Unified erasure contract and inventory    | S0802         | Inventory every release-scoped storage boundary and define shared erasure vocabulary before runtime deletion.   | No trusted erasure claim.                                                                |
| Local erasure runtime and controls        | S0803         | Implement user-initiated dry-run, confirmation, audit, and verification for local/browser state in scope.       | Current cleanup/reset/recovery flows remain narrow operations.                           |
| War Room erasure and hosted identity gate | S0804         | Prove Worker room-state erasure or record no-claim status; prove hosted identity or block the claim.            | Worker authority is room-local only; no hosted identity or Worker trusted-erasure claim. |
| Production-hosted validation              | S0805         | Define and run sanitized deployed app/public-demo/Worker smoke, or record unavailable no-claim evidence.        | Local/mocked evidence is not production-hosted validation.                               |
| Mobile/accessibility evidence             | S0806         | Record supported-surface evidence and fix scoped blockers without overstating certification.                    | Phase 06 evidence remains local browser evidence, not formal certification.              |
| Legacy decommission and media gate        | S0807         | Approve final dispositions, preserve retained value, revalidate media gates, and perform only approved cleanup. | Legacy and media entries are candidates only; conditional media remains non-release.     |
| Final release candidate closeout          | S0808         | Run full release gate stack, sync docs/security posture, and declare release readiness or exact blockers.       | Phase 08 is not release-complete until Session 08 validates and closes.                  |

## Residual-Risk Wording

Use these exact baseline statements until the owning session replaces them with validated evidence:

| Topic                              | Residual wording                                                                                                                                                                                                                        |
| ---------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Hosted identity                    | "Hosted identity remains planned or unavailable. Room-local Worker authority is not hosted account identity, SSO, organization membership, public collaboration safety, analytics consent, production audit proof, or trusted erasure." |
| Trusted erasure                    | "Trusted unified erasure is not yet shipped. Local reset, browser cleanup, diagnostics recovery, CLI uninstall, Worker leave, one-boundary deletion, and manual file removal are not release-grade erasure."                            |
| Production-hosted validation       | "Production-hosted validation is not complete. Local, mocked, same-origin, and documentation evidence do not prove deployed app, deployed Worker, Cloudflare dashboard, production account, or release-candidate behavior."             |
| Mobile/accessibility certification | "Current evidence is local browser evidence unless Session 06 records a stronger evidence class. Do not describe automated checks as formal WCAG certification or physical-device certification."                                       |
| Hosted storage and public replay   | "Hosted persistence remains planned or unavailable and public replay hosting remains disabled. Current replay links are redacted local URL fragments only."                                                                             |
| Analytics                          | "Analytics guardrails are implemented, but capture remains disabled by default. No tracking script, SDK sender, dashboard, recorder, heatmap, session replay, or account-backed consent storage is active."                             |
| Push, remote access, and tunnels   | "Browser notifications are local-only. Web Push, push subscription storage, Cloudflare Tunnel, remote access, remote executors, and hosted diagnostic agents remain unavailable."                                                       |
| Media                              | "Release-ready media remains limited to approved battlefield runtime records and mirrors until Session 07 revalidates any broader media claim."                                                                                         |
| Decommission                       | "Legacy evidence is candidate-only. No `EXAMPLES/`, findings, reports, ignored media intake, copied historical bundles, or `docs/PROGRESS.md` deletion is approved until Session 07 records disposition and gates pass."                |
| Sensitive evidence                 | "Release evidence must use sanitized summaries and must not track raw secrets, ids, prompts, commands, paths, room payloads, exports, logs, backups, replay buffers, provider output, or quarantined historical content."               |

## Non-Goals For Session 01

* No trusted erasure contract, runtime, CLI control, web control, Worker erasure, hosted deletion, or audit execution is implemented here.
* No hosted identity, hosted storage, analytics capture, public replay hosting, push delivery, remote access, tunnel, hosted diagnostic agent, or real executor surface is activated here.
* No production-hosted validation, deployed app claim, deployed Worker release claim, formal WCAG certification, mobile device certification, media promotion, or legacy deletion approval is made here.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/phases/phase_08/release_requirements_risk_baseline.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
