Skip to content

STD-WORK-001: Durable Work Governance, Worktree Isolation & Completion Standard

Status: Canonical & Binding Standard ID: STD-WORK-001 Owner: Durable Work Gov (DURABLE_WORK_GOVERNANCE) Scope: All autonomous agents, human operators, rigs, packs, and worktrees across the Bluefly estate.


1. Prime Directive & Purpose

Sessions are disposable. Work is durable in Beads. Source is durable in GitLab. Worktrees are temporary execution environments that MUST be cleaned and removed upon completion.

This standard establishes the binding governance law for work ownership, fleet concurrency, worktree lifecycles, and definition of done across all operational windows. It prevents concurrency drift, cross-lane boundary violations, dirty worktree abandonment, and premature task closeout.

Durable Work Gov defines the lifecycle law; BluCityPacks implements the mechanical Formulas, Orders, and Agent configurations.


2. Fleet Specialization & Window Ownership

To prevent concurrency conflicts and ownership collisions, the Bluefly fleet operates across strict, mutually exclusive lanes. No agent may cross into another lane's implementation.

Window / Lane Identifier Owns Does NOT Own
Blu DIRECTOR Global director, routing, dependency graph, P0 sequencing, cross-lane acceptance, deduplication Implementation (unless no lane owns it)
Drupal Factory DRUPAL_FACTORY Drupal CMS 2.0 factory, recipes, site template, Composer/BOM, contrib-first assembly, DDEV factory proof ContextControl-specific product work, Bluefly.io content/site changes
Oracle IaC Convergence ORACLE_IAC Oracle capacity, Terraform/IaC, storage expansion, runner/runtime deployment convergence, immutable-runtime enforcement App code, Drupal features
Fleet Posture READ_ONLY_FLEET_OBSERVER Read-only health, gc doctor, disk/load/session/rig posture, alerts, evidence, drift detection Mutations, repairs, claiming implementation beads
Agent ID IDENTITY_PROVENANCE Machine/service identity, Git/SSH identity, provenance, gt whoami, personal-key removal Secrets delivery implementation itself
Durable Work Gov DURABLE_WORK_GOVERNANCE Bead lifecycle, claims, dependencies, closeout, worktree lifecycle, completion law, authority rules Product/app features, pack implementation
BluCityPacks GASCITY_PACK_IMPLEMENTATION Packs, Formulas, Orders, Events, agent-role configuration; implements governed factory behaviors Canonical doctrine text, app implementation
OpenClaw OPENCLAW OpenClaw gateway/runtime/config/security/channel integration only Gas City control plane, generic agent identity
ContextControl CONTEXTCONTROL contextcontrol-ai, Drupal human control surface, kb_cache, context-cli, dashboard/operator UX Generic Drupal factory or unrelated platform infra
Bluefly.io BLUEFLY_IO Bluefly.io Drupal site, content model, Canvas/SDC, site-specific integrations Drupal platform/factory abstractions
MCP MCP_TOOL_PROTOCOL MCP servers/tools/registry/gateway, Tool API boundary, protocol integration Agent orchestration or Drupal workflow ownership

Cross-Lane Boundary Rules

  1. Blu does not implement: Blu coordinates, routes, and verifies.
  2. Fleet Posture never mutates: Fleet Posture reports observations as findings routed to the owning lane.
  3. Authority boundaries generate handoffs, not idle time: When work falls outside an agent's assigned lane, the agent routes it via gc sling and gc mail and continues the next ready work inside its lane.
  4. No cross-lane hijacking: An agent inspecting another repository or subsystem for evidence may NOT make code or configuration changes outside its lane.

3. Concurrency Law & Work Selection

  1. NO_NEW_P0_STARTS: The fleet is converging, not expanding. No new P0 work may be created or claimed unless Blu explicitly routes an existing canonical P0 to that lane.
  2. One Active Bead Per Lane (1 LANE = 1 ACTIVE BEAD): An agent maintains at most one actively executing unit of work in state in_progress at any time, unless the Bead explicitly declares governed parallel child work.
  3. Prefer Convergence Over Discovery: Prioritize finish → verify → merge → close → clean over discover → create → expand → parallelize.
  4. Blocked Work Invariant: TASK_BLOCKED=YES does NOT imply AGENT_BLOCKED=YES. When a task is blocked, record the blocker edge, update the Bead, send mail, and claim the next independent authorized work.

4. Bead Lifecycle State Machine

Every unit of work transitions through a governed lifecycle in canonical Dolt (127.0.0.1:3308/hq):

  PROPOSED ──► READY ──► CLAIMED (in_progress) ──► IMPLEMENTED ──► VERIFIED ──► ACCEPTED ──► CLOSED
                            │                                                     ▲
                            └──► BLOCKED (needs edge + handoff mail) ─────────────┘

Lifecycle Gates

  • PROPOSED / READY: Work item exists in the graph with clear title, scope, acceptance criteria, and owner.
  • CLAIMED: Agent executes gc hook --claim (or bd update <id> --status in_progress). The Bead must exist in canonical Dolt before implementation begins.
  • BLOCKED: Requires:
    TASK_BLOCKED=YES
    BLOCKED_BY=<named authority / issue ID>
    OWNER=<owning lane>
    HANDOFF_BEAD=<bead ID>
    MAIL_RECEIPT=<sent to owning lane>
    NEXT_INDEPENDENT_WORK=<next task ID>
    
  • IMPLEMENTED: Code written, tests passing, committed and pushed to release/v0.1.x.
  • VERIFIED: Verified by independent tests, CI pipeline, or runtime evidence.
  • ACCEPTED: Formal acceptance by the owning authority (e.g. Mayor or Blu).
  • CLOSED: Final receipt attached, worktree confirmed deregistered and removed, Dolt state updated to closed.

5. Worktree Lifecycle & Isolation Law

Canonical Worktree Roots

  • Canonical Engineering Worktree Root: $ESTATE_ROOT/worktrees/<bead-id-or-name>
  • Strictly Forbidden for Engineering Worktrees: $ESTATE_ROOT/BluCity/.gc/worktrees/ (reserved for internal GC runtime only)
  • Estate Root Prohibition: $ESTATE_ROOT/ is the estate root. NEVER clone, branch, or create worktrees directly in the root.

Scope Distinction Law

To prevent cross-host reporting confusion, all worktree receipts MUST distinguish scope:

LOCAL_CANONICAL_ENGINEERING_WORKTREE_ROOT = <count> active
ORACLE_GAS_CITY_DISCOVERED_WORKTREES     = <count> valid
Never report an unadorned worktrees = 0 or worktrees = 48 without naming host and root.

Worktree State Machine

PROVISIONED ──► CLEAN_CHECKOUT ──► ACTIVE_WORK ──► COMMITTED ──► PUSHED ──► MR_MERGED ──► DEREGISTERED ──► REMOVED
  1. Provisioning: Create isolated worktree:
    git worktree add $ESTATE_ROOT/worktrees/<bead-id> release/v0.1.x
    
  2. Isolation: Never develop directly in canonical checkouts, NAS mounts, or Oracle production runtime.
  3. Prohibited Operations:
  4. NO git stash (uncommitted work belongs in the worktree or a branch, never stashed).
  5. NO git rebase on shared branches.
  6. NO git reset --hard on shared branches.
  7. NO force pushes.
  8. Deregistration & Removal: Once MR is merged and verified:
    cd <canonical-repo>
    git worktree remove $ESTATE_ROOT/worktrees/<bead-id>
    git worktree prune
    git branch -d <feature-branch>
    

6. The Hard Completion Law (The 9-Point Gate)

Work is not done because code was written, tests passed, or a branch was pushed. Work is complete ONLY when all 9 gates are satisfied:

SUCCESS =
    1. IMPLEMENTED               (code and configs cleanly authored)
  + 2. PUSHED                    (branch pushed to GitLab)
  + 3. MR_MERGED_TO_TARGET       (merged to release/v0.1.x via governed path)
  + 4. EXTERNAL_VERIFIED         (independent tests or runtime verification pass)
  + 5. DURABLE_RECEIPT_RECORDED  (structured receipt attached to Bead)
  + 6. WORKTREE_CLEAN            (no uncommitted or untracked changes)
  + 7. WORKTREE_DEREGISTERED     (git worktree remove executed)
  + 8. WORKTREE_REMOVED          (worktree directory confirmed deleted from disk)
  + 9. BEAD_CLOSED               (Bead closed in canonical Dolt)
VALID_COMPLETED_WORK + UNCOMMITTED        = FAILURE
VALID_COMPLETED_WORK + UNPUSHED            = FAILURE
VALID_COMPLETED_WORK + NO_MR               = FAILURE
GREEN_MERGEABLE_MR   + NOT_MERGED          = FAILURE
MERGED_MR            + ABANDONED_WORKTREE  = CLEANUP_FAILURE
BEAD_CLOSED          + ACTIVE_WORKTREE     = GOVERNANCE_VIOLATION

7. Inter-Lane Communication & Required End-of-Work Receipt (STD-GATE-001)

When handing off work, reporting status to Blu, or closing a Bead, agents MUST emit the complete structured End-of-Work Receipt as defined in STD-GATE-001:

BEAD=
OWNER=
RIG=

REQUESTED_EFFECT=

SOURCE_CHANGED=
RUNTIME_CHANGED=
DOCS_CHANGED=

BRANCH=
COMMIT=
MR=
CI=

EVIDENCE=
COVERAGE=
KNOWN_LIMITS=

BEAD_UPDATED=
DEPENDENCIES_UPDATED=

CANONICAL_DOC_UPDATED=
DOC_PATH=

SOURCE_DELIVERED=
RUNTIME_VERIFIED=
WITNESS_VERIFIED=

IS_THE_NEXT_RUN_GETTING_CHEAPER_AND_MORE_REUSABLE=
WHY=

NEXT_ACTION=
Without this complete receipt, DONE=NO.


8. Mechanical Specification for BluCityPacks

BluCityPacks implements this standard through Gas City Formulas, Orders, and Agent configurations:

Required Formulas

  1. formula-bead-claim:
  2. Validates agent lane against Bead owner/metadata.
  3. Enforces 1 LANE = 1 ACTIVE BEAD.
  4. Provisions isolated worktree under $ESTATE_ROOT/worktrees/<bead-id>.
  5. Transitions Bead status to in_progress in canonical Dolt.
  6. formula-bead-closeout:
  7. Verifies GitLab MR merged status on release/v0.1.x.
  8. Asserts git status --porcelain is empty in the worktree.
  9. Executes git worktree remove and git worktree prune.
  10. Asserts worktree directory no longer exists on disk.
  11. Attaches final structured receipt to Bead notes.
  12. Transitions Bead status to closed in canonical Dolt.

Required Orders & Event Gates

  • Order: order-worktree-reconciliation: Periodic or post-session order scanning for merged MRs with abandoned worktrees; alerts Fleet Posture.
  • Pre-Close Gate: Fail-closed constraint preventing bd close if the associated worktree is still listed in git worktree list.

9. SINGLE COMPLETION LAW

Effective immediately, no Bluefly Factory change is complete unless its durable work state and durable knowledge state are updated as part of the same operation.

This applies to every Agent, every Rig, every Formula, every infrastructure change, every Drupal change, every policy change, every CI change, and every runtime repair.

The required lifecycle is:

BEAD → CLAIM → EXECUTE → VERIFY → RECORD EVIDENCE → UPDATE DURABLE KNOWLEDGE → SOURCE DELIVER → WITNESS → CLOSE

A change that skips any applicable stage is DONE=NO.

10. DOCUMENT AUTHORITY ORDER & UPDATES

Documentation is required when the work changes: - ARCHITECTURE - OWNERSHIP - OPERATING MODEL - SECURITY MODEL - DEPLOYMENT MODEL - CONFIGURATION MODEL - API CONTRACT - PRODUCT BOUNDARY - FACTORY STANDARD - RECOVERY PROCEDURE - KNOWN LIMITATION

Authority Order

  1. CURRENT SOURCE / LIVE RUNTIME
  2. ENGINEERING STANDARD / ADR
  3. PRODUCT AUTHORITY
  4. PROJECT-SPECIFIC DURABLE DOC
  5. BEAD
  6. GENERATED REPORT / SCRATCH (Scratch is NEVER authority)

When to Update BluCity-Docs

Update BluCity-Docs only for durable cross-project knowledge such as Factory architecture, Gas City operating standards, identity/auth standards, CI standards, security standards. Task status belongs in Beads.

When to Update Project Docs

Project-specific implementation knowledge stays with the owning project (e.g., api_normalization architecture, ContextControl integration design).

ADR Required for Material Architecture Decisions

Create or update an ADR when a decision changes system authority, source ownership, deployment topology, runtime boundary, security boundary, storage authority, public/private Pack boundary, API exposure, identity model.

11. ECONOMIC & PRODUCT IMPACT GATES

Every change must answer Product Impact:

CUSTOMER_OPERATION_SERVED=
PRODUCT_BLOCKER=
REVENUE_EFFECT=
COST_EFFECT=
RELIABILITY_EFFECT=

And Economic Gate:

IS_THE_NEXT_RUN_GETTING_CHEAPER_AND_MORE_REUSABLE=YES|NO|NOT_ESTABLISHED
WHY=

12. LEARNING & REPEAT WORK PROMOTION

When substantially the same action is performed repeatedly (REPEAT_COUNT >= 3), the Agent must ask: IS_THIS_A_CAPABILITY_CANDIDATE=

If yes: record candidate, attach evidence, state limits, prove on second estate. Then consider reusable packaging (policy, check, test, procedure, Formula, configuration, integration, Skill).

13. SESSION END GATE

Before any Agent stops or rotates:

ACTIVE_BEAD_UPDATED=YES
UNCOMMITTED_WORK_ACCOUNTED_FOR=YES
UNPUSHED_WORK_ACCOUNTED_FOR=YES
MR_STATE_RECORDED=YES
BLOCKERS_RECORDED=YES
DOC_CHANGES_RECORDED=YES
NEXT_ACTION_RECORDED=YES

14. UNIVERSAL FACTORY GATE

Before mutation: FACTORY_GATE=PASS (must check work authority, source authority, owner, rig, bead, claim, capability match, authority, service identity, policy, dependencies, execution surface, acceptance, verification, delivery path, evidence path, documentation disposition).

After mutation:

BEAD_UPDATED=
DOCS_UPDATED=
SOURCE_DELIVERED=
RUNTIME_VERIFIED=
WITNESS_VERIFIED=
ECONOMIC_GATE=
If any required value is missing, DONE=NO.


CENTRAL LAW - If the work happened but the Bead was not updated, the Factory does not know it happened. - If the architecture changed but the documentation was not updated, the next Agent will rediscover or contradict it. - If runtime changed without source delivery, the next deployment can erase it. - If the Agent claims success without evidence, the result is not trusted.