Decisions
This is a compact index, not a second specification. Follow the first link in each entry for the canonical detail. The initial decisions and evidence links were reviewed on 2026-08-09. Later decisions carry their approval date.
-
D-001 — Named trains coordinate independent package semvers. Vivary Governed Context is a release label, not a suite version. Packages bump only when their own surface changes; only
create-vivaryand@vivary/createuse the same version. This is the selected resolution of #149. -
D-002 —
vivary-coreis a shared seam, not a fifth role or CLI. Tropo observes and retrieves, Strato decides, Ozone verifies and proposes, and Exo projects caller-owned control state. Their manifests provide the executable dependency evidence. -
D-003 — The Python-owned CLI is the baseline agent interface; MCP is optional and narrower. Python packages own behavior and command envelopes; the npm scaffolder is a launcher for the canonical Python CLI. MCP exposes four bounded read-only projections over operator-bound roots and cannot replace setup, migration, mutation, execution, approval, or publication commands. MCP.md owns its limits and authority boundary.
-
D-004 — Memory remains optional and cannot silently become authored truth. Provider recall produces candidates; Core classifies them and returns a deterministic Learning Proposal before a create or supersede transition can receive exact human approval. Recall tests are the behavior evidence.
-
D-005 — Unknown, conflicting, or omitted context stays visible. Core does not convert missing evidence into confidence. Task Capsules, Execution Receipts, Integrity Views, and ContextIntegrityEvents preserve the distinction; the public vocabulary owns those terms.
-
D-006 — Canonical source docs own truth; generated site pages are mirrors. Behavior, migration, and release facts change in their named canonical owner first. Site synchronization happens only in the approved release workflow.
-
D-007 — Product engineering is the default. Jeff approved this policy on 2026-09-12. Implement a coherent user capability, run relevant checks, exercise the real app, fix failures, and commit. Invoke high-assurance mode for a named dangerous failure. Preserve existing evidence, budgets, and specific external-action authority.
For a new hard-to-reverse choice, add a focused ADR beside the affected spec and link it here. Use MIGRATION-STATUS.md for changing maturity status, not an ADR.
