Portfolio review path: Start with the capabilities and architecture below, then reproduce the documented verification commands. See SECURITY.md, CONTRIBUTING.md, and RIGHTS.md for the project's operating and reuse boundaries.
Tip
For a recruiter- and engineer-friendly architecture tour, see ENGINEERING_OVERVIEW.md.
Current state: Stage 4 Alpha Vertical Trust Slice complete and Stage 5 authorized; the full LAOS v8 runtime is not implemented.
The repository contains the Stage 1 recovery/governance baseline, the accepted Stage 2 typed kernel, and a Stage 3 accepted local Security Spine. Stage 3 implements transactional local SQLite state, repository seals, safe paths and archives, authenticated capability bindings, default-deny policy, a minimum signed Action Capsule, workspace and command brokers, a digest-pinned network-denied Docker sandbox, broker-owned evidence, a local-only model path, emergency stop, and minimal pre-Alpha operator recovery paths. These are local test-profile controls, not production signing, complete evidence custody, a complete privileged runtime, or a release.
Stage 4 adds one real local weaker-agent Alpha proof: a signed one-use capsule, one bounded source edit, a clean
reconstruction, a protected Docker check, result-bound evidence, an independent runtime reviewer identity, and
Git compare-and-swap promotion. The development pilot is deliberately small and supports architecture pruning and
budget calibration only; it is not a final efficacy claim. See docs/STAGE_4_ALPHA_CONTRACT.md,
STAGE_4_GO_NO_GO_AND_SCOPE_FREEZE_CANDIDATE.md, and Evidence/STAGE_4_ALPHA_RUNTIME/run.json.
Nilhan is the sole human reviewer and go/no-go authority, independent from Codex as implementer. See
docs/GOVERNANCE_REVIEW_AUTHORITY_AMENDMENT_2026-07-13.md. Runtime role separation and technical independence
gates remain mandatory.
The active plan is root LAOS_v8_EXECUTION_AND_RELEASE_PLAN.md Revision 1.1. LAOS_v8_TEN_STAGE_IMPLEMENTATION_PLAN.md is a subordinate execution index. Earlier documents under design_inputs/ are historical Stage 0 inputs.
This repository is the clean, version-controlled rebuild workspace for LAOS v8. It preserves the verified LAOS v7 baseline, imports surviving v8 plans only as design inputs, records every known defect as a regression obligation, and establishes the mission, trust architecture, threat model, ADRs, policies, and requirements ledger.
The master framework is for the highly capable Software Architect AI. Weaker agents must never receive this repository or master planning material directly; later milestones will compile separate, minimal execution packs and one Action Capsule at a time.
Start with:
LAOS_v8_EXECUTION_AND_RELEASE_PLAN.mdRECOVERY_STATE.mddocs/PLAN_AUTHORITY.mdPROGRAM_STAGE_LEDGER.jsonREQUIREMENTS_LEDGER.jsonRELEASE_BLOCKERS.jsonTHREAT_REGISTER.json
The laos CLI exposes diagnostics, status, schema export, read-only migration discovery, denial explanation, state
backup/restore, evidence export/purge reconciliation, and epoch-bound trust recovery. See
docs/STAGE_3_OPERATOR_PATHS.md. Do not describe these paths as a complete execution runtime or production release.
The exact status is machine-readable in IMPLEMENTATION_STATUS.json.
