# Fabric six-plane authority map

**Status:** authoritative logical responsibility map for the current repository snapshot
(2026-08-20).

Forge and Fabric are organized into six responsibility planes. These planes describe ownership and
trust boundaries, not deployment hosts or UI layers. A local workstation may run all six in one
process; a hybrid deployment may split them across a control plane and workers without changing the
contracts between them.

```mermaid
flowchart LR
  I["1 · Intelligence<br/>deterministic sufficiency · bounded specialists · model routing"]
  C["2 · Context & Knowledge<br/>Context Envelope · World State · RAG · provenance"]
  K["3 · Capability<br/>typed registry · skills · Skill Graphs · provider bindings"]
  E["4 · Execution<br/>workflow · replan · jobs · provider dispatch · reconciliation"]
  G["5 · Governance<br/>identity · consent · approvals · claims · commissions · secrets"]
  A["6 · Assurance<br/>confidence · validators · contracts · emergency stop · attestations"]
  I --> C --> K --> E --> G --> A
  A -. evidence and stop conditions .-> I
```

The arrows show dependency, not permission. No upstream plane can manufacture authority owned by a
downstream plane, and Assurance can stop any plane without granting it permission to proceed.

## Plane contracts and boundaries

| Plane | Owns | Does not own | Current shared spine |
|---|---|---|---|
| **Intelligence** | Deterministic sufficiency, bounded planning/reasoning, one qualified specialist route, model/provider selection | Tool execution, approval, source authority, or lifecycle promotion | Fabric Intelligence Gateway and Core Orchestrator; advisory results only |
| **Context & Knowledge** | Read-only context composition, World State projection, retrieval evidence, source provenance, decision replay manifest | Canonical production facts or permission inferred from retrieved text | `fabric.context-envelope.v1`, `fabric.shared-context-binding.v1`, `fabric.world-state.v1` |
| **Capability** | Typed capability vocabulary, executable skill contracts, Skill Graph identity/lifecycle, exact provider bindings | Qualification inferred from discovery, a profile, handler presence, or RAG indexing | Capability registry, physical manifest, skill manifest, commissioned graph bindings |
| **Execution** | Workflow scheduling, state-aware replanning, durable jobs, provider dispatch, effect reconciliation | Blind retries, invented rollback, or success after unknown completion | `fabric.world-state-replan.v1`, sealed runtime outcomes, deadline and reconciliation records |
| **Governance** | Caller/workspace scope, consent, approvals, execution claims, commissions, Secret Broker leases | Self-asserted authority, credential disclosure, or approval inferred from confidence | Exact digest bindings, single-use scoped secret references, default-deny route policy |
| **Assurance** | Evidence-derived confidence, deterministic validation, shared contract discipline, emergency stop, environment/attestation checks | Execution or production promotion merely because a check passed | `fabric.evidence-confidence.v1`, contract registry, independent verifier/attestor seams |

## Current repository truth

The current repository snapshot establishes the shared Context Envelope, World
State/replan, evidence-derived
confidence, shared-context binding, fail-closed source-authority admission, replay deadline and
unknown-completion handling, Secret Broker adoption, observer durability, and the read-only Unity
disposable-attestation feed boundary.

The shared contract registry contains **30 contracts** and **3 compatibility deprecations**. Golden
fixtures and future-version, malformed-document, and authority-widening rejection cases protect the
new shared-context, observer-runtime, and Unity-feed contracts. Compatibility facades remain bounded
by the deprecation ledger; they are not competing authorities.

The live autonomy inventory reports **90 discovered skills: 53 executable and 37 requiring reviewed
activation contracts**. Discovery, indexing, a recommended profile, and handler presence do not
grant execution authority.

## Open gates

| Gate | Repository state | Evidence still required |
|---|---|---|
| RAG reconciliation | Canonical-to-derived reconciliation, freshness metadata, fail-closed consumers, and a safe rebuild command are implemented. All seven workspaces completed a verified post-recommission refresh. Default was recommissioned at a clean Event Spine boundary: the prior signed chain is retained read-only under a checksum manifest, zero ambiguous Default facts were migrated, and all non-Default signed rows were preserved exactly. Later canonical edits correctly make the derived indexes stale again until a new source freeze and refresh. | Reconcile after canonical changes settle. Protected Google Sheets still require service authorization, and the remaining Atlassian Cloud source needs access or explicit retirement. Unavailable collectors remain degraded evidence; never reconcile the cache back into authority. |
| Source authority | The gateway injects an exact, expiring server-owned registry; the specialist-preview host producer atomically registers and re-verifies all exact source/revision/digest/workspace/caller/task bindings. Shared admission rejects caller self-assertions with `source_authority_unverified`. | Every future authoritative producer must use the same server-owned registration boundary. Do not invent a receipt in the gateway. |
| Unity disposable attestation | Forge can read one exact externally signed record from a read-only feed and pinned Ed25519 public key; deployment seams carry public trust only. | Operate the independent attestor, mount its versioned feed, and pin the reviewed identity/key. Forge must never receive its signing key. |
| Environment and capability qualification | Repository contracts, deterministic tests, disabled review batches, and auditors exist. | Pin the OS/application/model/runtime fingerprint; run real disposable and accepted-ticket cases; obtain owner approval, independent review, signing/notarization, certification, publication, and commissioning where applicable. |

Repository-complete work proves that the boundary exists and fails closed. It does not prove a live
provider, writable production scope, external signer, human approval, accepted corpus, or production
commission.

## Cache policy and sequencing

World State, Context Envelope, evidence-derived confidence, and state-aware replanning are upstream
of cache optimization. Provider/runtime KV and exact prompt-prefix caching may be used behind their
existing contracts, but they remain performance mechanisms and never authorities.

Fabric does **not** implement a semantic answer cache. Reusing a prior generated answer can silently
cross freshness, provenance, workspace, model, policy, approval, and validation boundaries. Keep it
off unless a future design can bind all of those inputs, revalidate the result, fail closed on any
drift, and demonstrate a material benefit. Even then, it would remain below the state/replan spine.
