# Fabric Photoshop and Unity autonomy contract

## Outcome

Fabric may autonomously plan and execute only operations present in
`physical_capability_manifest.CAPABILITIES` with `production_ready=true` and
fresh application readiness evidence. Discovery is not execution authority.
Unknown operations and understood-but-unqualified operations route to governed
capability acquisition and cannot be selected by the production planner.

This gives Fabric broad, expandable tool knowledge without pretending that
every Photoshop command, Unity package, custom Editor window, or project data
shape is already safe to automate.

## How an agent chooses a capability

1. The planner turns authoritative ticket/project evidence into semantic
   operations; it never emits raw JSX or C#.
2. The matcher considers only capabilities whose health is `available` or
   `pilot` and whose exact intent overlaps the requested operation.
3. The compiler resolves the semantic operation through the shared manifest to
   one exact provider/category/action and seals the complete plan digest.
4. Effectful work requires approval bound to that operation, candidate, and
   plan digest. Read-only inspection does not gain write authority.
5. The runtime records observations and runs independent validators. Provider
   success alone does not satisfy the goal.
6. An unknown or unqualified operation produces a non-executable Toolsmith
   candidate. Independent qualification and explicit pilot promotion are
   required before it can enter planning.
7. A generated pilot becomes production only through
   `physical_production_readiness`: at least 20 unique attributable real-ticket
   cases, actual provider invocation, zero manual application operations,
   at least 95% mechanical success, 100% postconditions/source preservation,
   zero unauthorized writes or fabricated completion, 100% recovery-or-stop,
   human acceptance, and independent review. Every passing dimension is 10/10;
   one missing dimension makes the entire gate fail closed.

## Current qualified surface

Photoshop's qualified surface includes document/layer inspection, duplicate
working documents, declared layer visibility and selection, Smart Object
replacement, deterministic resize/crop/mask/text/merge/flatten operations,
PNG/JPEG export, and close-without-save. Effectful sequences are generated by a
deterministic JSX compiler and must protect the source by duplicating and
discarding the working document.

The native Fabric Photoshop UXP v2 provider implements 47 exact actions. One
versioned contract drives pairing, transport validation, capability discovery,
and the plugin-handler inventory. It covers inspection, working-copy document
lifecycle, image/canvas transforms, layers/groups, text, Smart Objects, masks,
layer comps, color/history, and typed BMP/GIF/JPEG/PNG/PSD/PSB/WebP plus
artboard/atlas output. The provider has no action for raw JSX, arbitrary
`batchPlay`, or unconstrained Photoshop commands. The physical manifest retains
30 additional operations as candidates until each operation family has the
required evidence; handler presence and a successful health probe do not by
themselves grant production authority.

Unity's qualified MCP surface covers all 61 exact handlers registered by the
installed `com.zynga.unity-mcp-server@0.4.315` package, including menu discovery/execution,
AssetDatabase refresh and search, asset inspection, typed texture import,
material and ScriptableObject fields, component/property edits, prefab-stage
operations, scene save, asset-bundle and Addressables operations, tests/status,
console inspection, and screenshots. The local project adapter additionally
supports two narrow contained mutations: an existing named sprite pivot and an
existing top-level scalar ProtoDB field.

The versioned local `com.forge.fabric-toolsmith` Editor package adds four fixed
typed operations the installed MCP package does not provide: serialized-state
inspection, stable UI Toolkit window inspection, typed control value setting,
and approval-bound Button invocation. It exchanges sealed project-local
requests through `Library/Forge/FabricToolsmith`; it accepts no C#, method
names, arbitrary filesystem paths, or screen coordinates.

Capability Center attaches application version, document/project identity,
worker identity, qualification time, and freshness to both applications.
Stale or unavailable evidence removes the capability from automatic matching.
Generated capabilities also expose explicit maturity—acquisition-only,
implementation candidate, fixture-qualified, bounded pilot, or
production-ready—and a recomputed production score. A stored lifecycle label
or caller-provided `production_ready` boolean is not trusted.

## Explicit acquisition-only surface

The MCP package still does not register runtime allowlist mutation, and its
generic batch executor is a registered control rather than production
capability evidence. Arbitrary custom Editor extensions remain acquisition
work unless they can be expressed through the fixed serialized-state or stable
UI Toolkit contracts. This is deliberate fail-closed behavior. The same applies to arbitrary C#, arbitrary JSX,
unrecognized Photoshop portrait tooling, new ProtoDB fields, arbitrary file
paths, and unfamiliar custom Editor extensions.

## Evidence obtained in this change

- Photoshop 27.8.0: a real PSD was opened, duplicated, resized to 64 x 64,
  exported, and closed without saving. The source SHA-256 was identical before
  and after the run.
- Photoshop 27.8.0 with Fabric UXP v2: the exact 47-action inventory matched
  the owner-only pairing contract. A source PNG was duplicated to an unsaved
  working document, resized from 380 x 359 to 190 x 180, exported through the
  typed PNG handler with a non-empty 8,079-byte receipt, and closed without
  saving. A second unsaved working copy produced independently identified,
  non-empty PSD, PSB, JPEG, WebP, BMP, and GIF outputs; the shared modal helper
  was corrected after this matrix exposed an in-modal WebP rejection. The
  original SHA-256 remained
  `7afd504b41c0c9d4f8703b2967bcb7a4c5a900b97810b998b0f8365076b7d8cf`.
- Unity 2022.3.62f2 with MCP 0.4.315: the live project identity was proven,
  the Toolsmith extension compiled with a clean console, and
  `Assets/Art/Chests/prefabs/ChestCamera.prefab` passed the typed serialized
  reference/component/property inspection.
- A package-owned disposable UI Toolkit window passed stable-selector inspect,
  typed set, approved Button invocation and read-back; the observable callback
  counter incremented.
- A real disposable AssetDatabase texture import passed exact asset identity,
  serialized-reference and console verification. The restricted rollback
  removed the asset and its dedicated qualification folder; the post-rollback
  asset count was zero.

This evidence qualifies the tested bindings; it is not a claim that every PSD,
prefab, custom window, or third-party Unity package is autonomously supported.

## Production benchmark and rollout gate

The benchmark is now an executable, sealed release contract rather than a
documentation convention. `forge.physical-capability-benchmark.v1` binds one
pilot digest to at least 20 unique ticket, run and evidence identities. The
evaluator recomputes every metric from the retained cases and rejects duplicate
cases, compiler-only evidence, manual application work, unsafe writes, source
corruption, unverifiable completion, failed recovery or missing independent
review.

`physical_toolsmith.promote_production` consumes only a 10/10 report and a
separately claimed durable approval that names the exact pilot and benchmark
digests. `capability_builder.transition` and store validation independently
recompute the benchmark, so a caller cannot promote by copying a readiness
label. The resumable Studio `capability_production_promotion` job exposes this
same service path and explicitly returns publishing, commissioning and tool
execution authority as false.

Generated-tool execution repeats live application preflight after approval and
before provider dispatch. Stale readiness stops the call; Unity must be attached
to the contained project; and a production candidate runs only on an
application version represented by its passing release corpus. Generated Unity
plans may dispatch to both the installed MCP bridge and the registered,
contained project adapter—never an unregistered provider.

General Photoshop/Unity production promotion still requires collecting the real reviewed
corpora: at least 20 Photoshop tickets and 20 Unity tickets. No synthetic or
repository-only run is counted as that external evidence. Each case must retain
the selected semantic operations, exact bindings, approval decisions,
application/project identity, changed-path and artifact hashes, independent
postconditions, rerun safety, failure recovery, and human acceptance.

Rollout proceeds from no-write qualification, to disposable-fixture execution,
to an approval-bound pilot, and only then to production eligibility. Candidate,
certified, published, and commissioned are separate states. Neither
certification nor this architecture change publishes or commissions an agent.

## Agentic AI boundary

Agentic mode may decompose goals, choose among qualified capabilities, schedule
a linear flow or DAG, retry bounded read-only work, and propose recovery. It
does not create its own runtime authority, bypass effect/approval gates, or turn
an unregistered operation into a production capability. New capability
knowledge becomes usable only after the same manifest, compiler, verifier, and
promotion contract is satisfied.

## Production-ready architecture versus production evidence

The control architecture is production-ready: authority, durability,
idempotency, exact binding, measured promotion, restart recovery, rollback and
separate publication/commissioning boundaries are implemented and tested.
Individual generated capabilities are not called production-ready until their
real case corpus passes the release gate. This distinction is intentional: the
platform can be ready to evaluate production evidence while a particular tool
is still a pilot.

The top-level `forge_product_readiness` decision now requires separate 10/10,
20-case Photoshop and Unity summaries plus verified production controls. A
green agent fleet or healthy connector cannot compensate for missing physical
autonomy evidence.
