Skip to content

ctower-project development authority

This page separates the current read-only visibility boundary, the approved fresh-database development pilot, and disaster-safe full Increment 1 exit.

Current state

I1.7A provides strict cutover-health contracts, compact read-only Project Delivery data, and authenticated online-only migration command spellings that refuse. This visibility boundary is implemented, but it has not established fresh-database ctower-project authority, carried an item forward, issued a CT-I1-008 development verdict, or proved CP3-D. Mission Control remains the writable ctower-project source.

Bulk legacy import is not an upcoming active phase. It is dormant and requires a separate future operator decision.

Approved development path — fresh start plus minimal carry-forward

  1. Establish the ctower Company / Project / checkpoint hierarchy and compact read-only Project Delivery projection on the fresh database.
  2. Inventory, hash, sign, and seal the complete legacy corpus as read-only provenance.
  3. Review one exact allowlist of still-actionable items.
  4. Recreate each approved item through ordinary generated API/CLI commands and attach its stable legacy alias and source digest.
  5. Reconcile that exact set through public reads, then issue the CT-I1-008 development dogfood verdict and commit the writer epoch.

There is no corpus importer, automatic backfill, fuzzy dedupe, or dual-write period. The ordinary command path cannot forge proof, gates, effects, delivery, resolution, closure, or arbitrary status. The development cohort excludes credentials, accounting, production authority/effects, incidents, client data, and irreplaceable artifacts.

Two go/no-go meanings

CT-I1-008 means the development dogfood go/no-go. It may be GO_WITH_LIMITS while CP3-D is red and may complete only the development Project Delivery pilot/I1.7 checkpoint. Health must continue to expose CP3_D_NOT_PROVEN.

Full normative I1 exit is a separate gate and remains NO-GO until CP3-D proves external-failure-domain acknowledgement, key recovery, isolated destructive restore, and measured RPO/RTO. The CT-I2-001 dependency on CT-I1-008 means this full normative I1 exit, not the development verdict. Therefore I2 is not authorized while CP3-D is red.

Before the development epoch, discard the incomplete fresh database if necessary while Mission Control remains authoritative. After the epoch, rollback means a compatible ctower build/restore or explicit read-only/spool mode; legacy mutation never resumes.