> For the complete documentation index, see [llms.txt](https://faction-os.gitbook.io/faction-os-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/sessions/phase08-session08-release-candidate-validation-and-documentation-closeout/spec.md).

# Session Specification

**Session ID**: `phase08-session08-release-candidate-validation-and-documentation-closeout` **Phase**: 08 - Release Hardening and Legacy Decommission **Status**: Complete **Created**: 2026-05-31 **Package**: Cross-cutting **Package Stack**: Node 20 npm workspace gates, Biome, Vitest, Playwright, media and security scripts, stable documentation, Phase 08 PRD artifacts, public demo docs, and package README files across `.spec_system`, `docs`, `apps`, `packages`, `public-demo`, `scripts`, and `tests`

***

## 1. Session Overview

This session is the final Phase 08 release-candidate closeout. Sessions 01 through 07 completed the release baseline, erasure inventory, local/browser erasure runtime, Worker room-state and hosted identity gate, production-hosted smoke command, mobile/accessibility evidence, and legacy/media decommission record. The remaining work is to run the release-candidate gate stack, collect the exact evidence, synchronize stable docs and security posture, and decide whether Phase 08 is release-ready or blocked by concrete residual criteria.

The session is intentionally evidence-driven. It should not add unrelated features, broaden hosted surfaces, delete additional legacy evidence, promote conditional media, or upgrade local browser evidence into formal certification. It consumes the previous Phase 08 artifacts and produces one final release validation record with command results, unavailable/no-claim states, residual risks, blockers, and handoff notes.

The closeout must preserve FactionOS as local-first by default. Core server, web, hooks, CLI, adapters, public demo, and optional Worker fallback workflows must remain described as usable without hosted accounts, hosted storage, analytics, push, Cloudflare credentials, public replay hosting, provider credentials, remote access, or real executors. Any unproven hosted identity, trusted erasure, production-hosted, certification, or media-readiness claim must remain absent or explicitly marked as unavailable/no-claim.

***

## 2. Objectives

1. Run the full release-candidate gate stack and record exact pass, fail, skip, unavailable, or blocker outcomes.
2. Aggregate Sessions 01-07 release evidence into a final Phase 08 validation record with residual risks and no-overclaim decisions.
3. Synchronize the PRD, UX PRD, security posture, considerations, release docs, stable docs, public-demo docs, and package READMEs with validated behavior.
4. Produce a release handoff that states whether Phase 08 can complete, which blockers remain, and which claims must stay unsupported.

***

## 3. Prerequisites

### Required Sessions

* [x] `phase08-session01-release-requirements-and-risk-baseline` - provides release claim gates, routing, risk ownership, and decommission candidate baseline.
* [x] `phase08-session02-unified-erasure-contract-and-inventory` - provides erasure vocabulary, storage inventory, and unsupported-claim boundaries.
* [x] `phase08-session03-local-erasure-runtime-and-controls` - provides local/browser erasure runtime evidence, audit wording, and no full trusted-erasure boundary.
* [x] `phase08-session04-war-room-and-hosted-identity-release-gate` - provides Worker room-state erasure evidence and hosted identity no-claim boundaries.
* [x] `phase08-session05-production-hosted-validation-and-deploy-smoke` - provides sanitized hosted smoke command, no-network evidence, and production-hosted no-claim rules.
* [x] `phase08-session06-mobile-and-accessibility-certification-evidence` - provides local browser/component evidence and certification no-overclaim wording.
* [x] `phase08-session07-legacy-evidence-decommission-and-media-release-gate` - provides final media/decommission dispositions, gate outcomes, and Session 08 handoff.

### Required Tools/Knowledge

* Root release gates from `docs/release.md` and `docs/development.md`.
* Phase 08 artifacts under `.spec_system/PRD/phase_08/`.
* Current security and compliance posture in `.spec_system/SECURITY-COMPLIANCE.md`.
* Institutional memory in `.spec_system/CONSIDERATIONS.md`.
* Package boundaries from root, app, public-demo, and package README files.
* Existing release scripts: `media:*`, `battlefield:check`, `release:hosted-smoke`, `security:secrets`, and workspace quality gates.

### Environment Requirements

* Node 20+ and npm available; Node 22+ may be needed for Wrangler deploy/dev checks if live Worker validation is attempted.
* Dependencies can be installed with `npm ci --no-audit --no-fund` or an exact blocker is recorded.
* Optional production, Cloudflare, hosted, analytics, media-provider, push, and adapter credentials are not required for local release gates.
* If live production-hosted validation cannot run safely, `npm run release:hosted-smoke -- --no-network --json` records unavailable/no-claim states.

***

## 4. Scope

### In Scope (MVP)

* Maintainer can read a final Phase 08 validation record with command results, evidence rollup, blockers, residual risks, and release-readiness status.
* Maintainer can verify the full release gate stack: install, format, lint, workspace typecheck, tests, build, media checks, battlefield checks, hosted smoke, secret scan, whitespace, ASCII, LF, and focused Phase 08 validation commands.
* Stable docs and package READMEs reflect shipped behavior, completed Phase 08 evidence, local-first boundaries, and unsupported claims.
* Security posture and GDPR notes reflect erasure, hosted identity, production-hosted validation, certification, legacy decommission, media readiness, and residual-risk outcomes.
* PRD and UX PRD status maps distinguish complete, blocked, unavailable, planned, deferred, no-claim, and residual-risk states.
* Release notes inputs, rollback notes, version alignment, unsupported claims, and next workflow handoff are explicit.

### Out of Scope (Deferred)

* New feature implementation unrelated to release blockers - *Reason: this is final evidence and documentation closeout.*
* Deleting additional legacy evidence beyond Session 07 approvals - *Reason: Session 07 already recorded fail-closed dispositions and no broad deletion approval.*
* Promoting conditional, generated, unknown-provenance, public-demo, brand, portrait, showcase, or quarantined media to release-ready status - *Reason: media promotion still requires source, rights, attribution, metadata, fallback, accessibility, privacy, and budget evidence.*
* Activating hosted auth, hosted storage, analytics capture, public replay hosting, push delivery, remote access, Cloudflare Tunnel, provider generation, or real executors - *Reason: these require separate scoped threat model, consent, authorization, tests, and docs.*
* Claiming formal WCAG certification, physical-device mobile certification, production-hosted app readiness, hosted identity, or full trusted unified erasure without matching evidence - *Reason: release copy must avoid unsupported claims.*

***

## 5. Technical Approach

### Architecture

Create a final release validation artifact under `.spec_system/PRD/phase_08/` that acts as the evidence index for Phase 08 closeout. The artifact should list each required gate, exact command, outcome, command scope, sanitized summary, blocker status, and source file for supporting evidence. It should also roll up Sessions 01-07 evidence by requirement and risk so docs updates are traceable instead of opinion-based.

Use existing repository commands rather than adding new validation infrastructure unless a blocker proves a command is missing. Gate outcomes should be summarized, not pasted wholesale. Credentials, raw host responses, account ids, zone ids, tokens, prompts, local paths, command bodies, room payloads, exports, logs, backups, replay buffers, and ignored historical content must stay out of tracked evidence.

Apply documentation updates after command results are known. The PRD, UX PRD, security posture, considerations, release docs, deployment/privacy/media/legacy docs, public-demo docs, and package READMEs should agree on the same claims: what shipped, what was validated, what is unavailable/no-claim, and what remains future scope.

### Design Patterns

* Evidence-first closeout: command results and previous session artifacts drive docs wording.
* No-overclaim wording: unproven hosted, erasure, production, certification, analytics, push, remote, executor, and media claims stay absent or unavailable.
* Sanitized evidence: tracked artifacts use labels, counts, statuses, booleans, docs paths, command names, and concise conclusions only.
* Local-first fallback: absent credentials or network access must create no-claim evidence, not local workflow failure.
* Traceable handoff: every residual risk names owner, current status, blocker, and next allowed workflow step.

### Technology Stack

* Node 20 npm workspaces and root scripts from `package.json`.
* Biome format/lint checks.
* TypeScript package typechecks and builds.
* Vitest focused and full suite coverage.
* Playwright app and public-demo desktop/mobile projects.
* Existing media, battlefield, hosted-smoke, secret-scan, whitespace, ASCII, and LF gates.
* Markdown PRD, security, docs, README, implementation notes, and validation artifacts.

***

## 6. Deliverables

### Files to Create

| File                                                                                                                   | Purpose                                                                                                                                                                 | Est. Lines |
| ---------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- |
| `.spec_system/PRD/phase_08/release_candidate_validation_record.md`                                                     | Final Phase 08 release gate command record, evidence rollup, residual-risk table, blockers, release-readiness status, release notes inputs, rollback notes, and handoff | \~220      |
| `.spec_system/specs/phase08-session08-release-candidate-validation-and-documentation-closeout/implementation-notes.md` | Implementation log with command outcomes, docs sync decisions, blockers, and validation handoff                                                                         | \~160      |

### Files to Modify

| File                                                              | Changes                                                                                                                  | Est. Lines |
| ----------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------ | ---------- |
| `.spec_system/PRD/phase_08/PRD_phase_08.md`                       | Update Phase 08 progress, success criteria, and Session 08 closeout status after validation                              | \~60       |
| `.spec_system/PRD/phase_08/phase08_requirement_routing_matrix.md` | Mark S0808 evidence produced and record final requirement claim states                                                   | \~40       |
| `.spec_system/PRD/phase_08/phase08_release_risk_matrix.md`        | Update residual-risk wording and closeout criteria for S0808-owned risks                                                 | \~70       |
| `.spec_system/PRD/PRD.md`                                         | Synchronize Phase 08 status map, product objective status, and release/no-claim wording                                  | \~60       |
| `.spec_system/PRD/PRD_UX.md`                                      | Synchronize Phase 08 UX release gate, certification, mobile, and production-hosted wording                               | \~45       |
| `docs/PRD.md`                                                     | Mirror product PRD status exposed to stable docs                                                                         | \~60       |
| `docs/PRD_UX.md`                                                  | Mirror UX PRD status exposed to stable docs                                                                              | \~45       |
| `.spec_system/SECURITY-COMPLIANCE.md`                             | Update open findings, GDPR posture, dependency security, and Phase 08 closeout notes                                     | \~120      |
| `.spec_system/CONSIDERATIONS.md`                                  | Carry forward active residual risks and mark resolved Phase 08 lessons without overstating release readiness             | \~80       |
| `docs/release.md`                                                 | Update release gates, Phase 08 evidence summaries, version alignment, release notes inputs, blockers, and rollback notes | \~140      |
| `docs/deployment.md`                                              | Align production-hosted and Worker deploy smoke wording with final evidence                                              | \~60       |
| `docs/privacy-and-security.md`                                    | Align erasure, hosted identity, production-hosted, decommission, and sensitive-output posture                            | \~90       |
| `docs/legacy-consolidation.md`                                    | Align Session 07 dispositions with final Session 08 release-candidate status                                             | \~50       |
| `docs/media-assets.md`                                            | Align media release gate status and conditional blocker wording                                                          | \~50       |
| `docs/hosted-services.md`                                         | Preserve hosted-service no-claim wording and disabled/default posture                                                    | \~50       |
| `docs/environments.md`                                            | Align reserved credential, hosted, analytics, push, and remote-access variable guidance                                  | \~35       |
| `README.md`                                                       | Update top-level Phase 08 release hardening summary and residual limitations                                             | \~45       |
| Package README files                                              | Update affected package boundaries where final evidence changes package-facing guidance                                  | \~80       |
| `public-demo/docs_public-demo/validation.md`                      | Align public-demo release validation, production-hosted smoke, mobile/accessibility, and media/cache evidence            | \~50       |

***

## 7. Success Criteria

### Functional Requirements

* [ ] Full release gate stack passes or exact blockers are recorded with command, scope, failing condition, and release impact.
* [ ] Final Phase 08 validation record maps every S0808-owned requirement and risk to passed evidence, no-claim evidence, blocked status, or future scope.
* [ ] PRD, UX PRD, security posture, considerations, release docs, package READMEs, and public-demo docs match shipped behavior and validated evidence.
* [ ] Release copy makes no unsupported hosted identity, hosted storage, analytics capture, public replay hosting, push delivery, remote access, production-hosted, certification, broad media readiness, real executor, or trusted unified erasure claim.
* [ ] Release notes inputs, rollback notes, version alignment, unsupported claims, residual risks, and next workflow command are explicit.

### Testing Requirements

* [ ] `npm ci --no-audit --no-fund` passes or blocker is recorded.
* [ ] `npm run format:check`, `npm run lint`, `npm run typecheck --workspaces --if-present`, `npm test`, and `npm run build --workspaces --if-present` pass or blockers are recorded.
* [ ] Media, battlefield, hosted-smoke, secret-scan, whitespace, ASCII, and LF gates pass or blockers are recorded.
* [ ] Focused Phase 08 validation commands from Sessions 02-07 are rerun where practical or prior evidence is explicitly cited with blocker rationale.
* [ ] Manual no-overclaim docs review is completed and recorded.

### Non-Functional Requirements

* [ ] Local-first operation remains the primary release posture.
* [ ] Evidence artifacts are sanitized and do not include raw secrets, ids, prompts, paths, payloads, logs, backups, exports, replay buffers, or ignored historical content.
* [ ] Docs remain concise and source-backed rather than duplicating long historical reports or raw command output.
* [ ] Missing optional credentials or network access produce explicit unavailable/no-claim evidence.

### Quality Gates

* [ ] All files ASCII-encoded.
* [ ] Unix LF line endings.
* [ ] Code and docs follow project conventions.
* [ ] `git diff --check` passes.
* [ ] State is ready for the next workflow step.

***

## 8. Implementation Notes

### Key Considerations

* Sessions 01-07 are complete according to the analyzer and provide the prerequisite evidence for this final closeout.
* The release gate stack is intentionally broader than the Session 07 media/decommission gates; it includes install, quality, workspace typecheck, full tests, build, media, hosted smoke, security, whitespace, ASCII, and LF checks.
* `npm run release:hosted-smoke -- --no-network --json` is acceptable default evidence for absent safe production credentials or network validation, but docs must preserve no-claim wording.
* Version alignment must check root `package.json`, workspace package versions, and `packages/protocol/src/index.ts` runtime version before release notes are prepared.
* `docs/PROGRESS.md` remains tracked from Session 07 unless Session 08 explicitly records a stable replacement and approved reduction; no broad deletion is assumed.

### Potential Challenges

* Full release gates may be slow or environment-sensitive: mitigate by recording exact command, environment, failure, and release impact rather than hiding failures.
* `npm ci` can be blocked by network or registry issues: mitigate by recording it separately from source correctness and rerunning local gates if dependencies are already present.
* Docs can drift while command evidence is being gathered: mitigate by updating docs after command outcomes and using the final validation record as the source of truth.
* Hosted or production validation may lack credentials: mitigate with sanitized unavailable/no-claim evidence and no production-hosted app claim.
* Closing security findings can be overbroad: mitigate by closing only claims backed by runtime/deployed/destructive/certification/media evidence and keeping residual risks open where appropriate.

### Relevant Considerations

* \[P07] **Unified erasure deferred to Phase 08**: final closeout must decide whether Sessions 02-04 plus S0808 evidence allow any trusted erasure wording or require no full trusted unified-erasure claim.
* \[P07] **Hosted services ship as disabled-default guardrails only**: final release docs must not imply hosted auth, storage, analytics, push, public replay, or remote access activation.
* \[P07] **Redaction is boundary-specific**: release evidence must avoid raw env values, tokens, ids, paths, payloads, prompts, logs, backups, replay buffers, and quarantined content.
* \[P04] **Asset provenance gate remains active**: media readiness remains limited to approved battlefield runtime records unless gate evidence changes.
* \[P07] **Phase complete is not release complete**: this session is the step that decides Phase 08 release-readiness or exact blockers; earlier phase completion is not enough.
* \[P03] **Stable docs are the current contract**: final wording should use README files, `docs/api/`, architecture, privacy, deployment, release, media, hosted-service, and legacy-consolidation docs as current truth.

***

## 9. Testing Strategy

### Unit Tests

* Run the full `npm test` suite for repository-level release confidence.
* Run focused tests for Phase 08 surfaces when failures need isolation, including erasure, hosted identity/config/persistence/analytics/operations, War Room, production-hosted smoke, mobile accessibility, and media gates.

### Integration Tests

* Run workspace typecheck and build commands.
* Run Playwright app and public-demo desktop/mobile projects if environment allows; otherwise record exact blocker or cite prior Session 06 evidence without overclaiming.
* Run media and battlefield gate scripts.
* Run production-hosted smoke in no-network mode by default and live mode only when safe target configuration exists.

### Manual Testing

* Review release docs, PRD, UX PRD, README files, and package docs for unsupported claims.
* Review security and compliance findings for claims that can be closed versus residual risks that must remain open.
* Review release notes inputs, rollback notes, and version alignment.

### Edge Cases

* Optional credentials absent.
* Network unavailable during install or hosted smoke.
* A full gate fails because of pre-existing unrelated changes.
* A docs update would imply hosted identity, trusted erasure, production-hosted readiness, certification, analytics capture, push, remote access, real execution, or broad media readiness.
* Prior evidence exists but is local, mocked, no-network, or browser-only and must not be overstated.

***

## 10. Dependencies

### External Libraries

* None expected. This session should use existing workspace dependencies and scripts.

### Other Sessions

* **Depends on**: `phase08-session01-release-requirements-and-risk-baseline`, `phase08-session02-unified-erasure-contract-and-inventory`, `phase08-session03-local-erasure-runtime-and-controls`, `phase08-session04-war-room-and-hosted-identity-release-gate`, `phase08-session05-production-hosted-validation-and-deploy-smoke`, `phase08-session06-mobile-and-accessibility-certification-evidence`, `phase08-session07-legacy-evidence-decommission-and-media-release-gate`
* **Depended by**: Phase 08 validation, updateprd, and phase transition `audit` if all Phase 08 criteria are complete

***

## Next Steps

Run the implement workflow step to begin AI-led implementation.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://faction-os.gitbook.io/faction-os-docs/.spec_system/archive/sessions/phase08-session08-release-candidate-validation-and-documentation-closeout/spec.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
