Skip to content

STD-EXEC-002: Execution Surface Validity

Status: Canonical & Binding Standard ID: STD-EXEC-002 Owner: BLU Scope: All scheduled, autonomous, and agent-initiated factory runs across the Bluefly estate.


1. Primary Rule

A factory job that requires authoritative Factory state MUST execute on a Factory-capable execution surface.

Do not knowingly schedule authoritative factory work into a sandbox that cannot access the authority it must mutate.

This is not a reporting problem. It is an execution-placement defect.


2. Required Authorities

For any task whose acceptance requires durable factory mutation, routing, MR delivery, or canonical readback, the execution surface MUST provide:

TAILNET_ACCESS=YES
GAS_CITY_ACCESS=YES
BEADS_ACCESS=YES
DOLT_AUTHORITY=YES
GAS_CITY_MAIL=YES
PRIVATE_GITLAB_ACCESS=YES
MACHINE_IDENTITY=YES
SECRET_ACCESS_VIA_APPROVED_PATH=YES
CANONICAL_READBACK=YES

It does NOT require Thomas's personal interactive session. Use a governed machine identity and existing infrastructure. Do not copy personal credentials into containers. Do not introduce plaintext tokens.


3. Preflight Is Mandatory

Do not spend tokens performing expensive investigation when the environment cannot act on the findings.

Before significant investigation, every factory run must assert:

EXECUTION_SURFACE_VALID=
GAS_CITY_ACCESS=
BEADS_ACCESS=
MAIL_ACCESS=
SOURCE_ACCESS=
DELIVERY_ACCESS=
SECRET_PATH=
CAN_MUTATE_REQUIRED_AUTHORITY=

If the mission requires writes and any mandatory authority is unavailable:

DO NOT RUN THE EXPENSIVE AUDIT.
ROUTE EXECUTION TO A VALID SURFACE.

This prevents the double-spend:

Run 1: research → cannot persist → transcript
Run 2: reconstruct → research again → finally execute

4. Thomas Is Not the Dispatcher

Do not return:

  • "Start this task from the card on your Mac."
  • "Run this from a tailnet-connected session."
  • "Tell me to queue it."

Thomas is not the handoff relay.

If the current session cannot execute the work:

  1. Identify the existing owning Bead.
  2. Route the work through Gas City.
  3. Assign to an execution surface with required authority.
  4. Verify routing and readback.
  5. Record the invalid execution environment as an infrastructure defect Bead.
  6. Continue other eligible work.
HUMAN_GATE=NO

unless genuinely non-delegable.


5. A Queued Task Card Is Not Factory State

A task stored only in an assistant UI, transient scheduler, local chat, or model-specific queue is not sufficient durable state.

NOTHING_HAS_TO_BE_RELEARNED=YES

is only valid when another agent can discover the work using Factory-native authority without reading a transcript.

Durable factory authority:

Bead          = durable work
Gas City Mail = durable coordination
Order         = repeatable trigger/action
Formula       = repeatable execution method
Rig           = execution scope
GitLab        = source/delivery chain
BluCity-Docs  = accepted durable knowledge

6. Read-Only Degradation

A job may execute in a read-only environment only if its defined purpose is genuinely read-only:

  • public-source research
  • upstream documentation comparison
  • external market research
  • public vulnerability intelligence

If the task contract includes any of the following, READ_ONLY_SANDBOX=INVALID_EXECUTION_SURFACE:

  • update Beads
  • curate work graph
  • send Gas City Mail
  • repair MR / merge / verify release
  • update canonical docs

Do not silently downgrade the contract to "report findings."


7. Fix the Producer, Not This One Run

Acceptance is not "the findings eventually got written down."

Acceptance is: the next scheduled run does not have this problem.

Required proof:

SCHEDULED_EXECUTION_SURFACE_VALID=YES
TAILNET_ACCESS=YES
GAS_CITY_ACCESS=YES
BEADS_READ_WRITE=YES
GC_MAIL_SEND_READBACK=YES
PRIVATE_GITLAB_AUTH=YES
MACHINE_IDENTITY=VERIFIED
SECRET_PATH=APPROVED
CANONICAL_READBACK=YES
DEGRADED_REPORT_ONLY_LOOP=REMOVED
THOMAS_REQUIRED_TO_START_HANDOFF=NO

Find the scheduler/producer:

SCHEDULER_OWNER=
CURRENT_EXECUTION_SURFACE=
WHY_CLOUD_CONTAINER_SELECTED=
REQUIRED_AUTHORITIES=
AVAILABLE_AUTHORITIES=
GAP=

Preferred target architecture:

ORDER / EXISTING SCHEDULER
  → Gas City-capable execution surface
  → Bead / Formula
  → Rig
  → agent execution
  → canonical mutations
  → readback
  → Mail / receipt

Do not build a new scheduler if Gas City Orders or existing CI already owns this. Do not build a new remote-execution framework.


8. Degraded-Run Findings Must Survive

If a degraded run produced useful findings, do not discard or repeat them.

Transfer them into the owning durable Bead when execution reaches a valid surface.

The receiving worker begins with:

EXISTING_FINDINGS_FROM_DEGRADED_RUN=YES
RESEARCH_ALREADY_COMPLETED= <list known findings>

Then follows the curation order from STD-WORK-001 §9:

premise → ownership → dependencies → routing → delivery state → evidence → disposition → metadata cleanup

9. Canonical Architecture

Cloud sandbox  → public research only
Factory host   → authoritative work

Once a task requires Beads, Mail, private source, claims, worktrees, CI, or release readback, route it onto the governed Factory execution surface before the expensive work begins.