STD-WORK-001: Durable Work Governance, Worktree Isolation & Completion Standard¶
Status: Canonical & Binding
Standard ID: STD-WORK-001
Owner: Durable Work Gov (DURABLE_WORK_GOVERNANCE)
Scope: All autonomous agents, human operators, rigs, packs, and worktrees across the Bluefly estate.
1. Prime Directive & Purpose¶
Sessions are disposable. Work is durable in Beads. Source is durable in GitLab. Worktrees are temporary execution environments that MUST be cleaned and removed upon completion.
This standard establishes the binding governance law for work ownership, fleet concurrency, worktree lifecycles, and definition of done across all operational windows. It prevents concurrency drift, cross-lane boundary violations, dirty worktree abandonment, and premature task closeout.
Durable Work Gov defines the lifecycle law; BluCityPacks implements the mechanical Formulas, Orders, and Agent configurations.
2. Fleet Specialization & Window Ownership¶
To prevent concurrency conflicts and ownership collisions, the Bluefly fleet operates across strict, mutually exclusive lanes. No agent may cross into another lane's implementation.
| Window / Lane | Identifier | Owns | Does NOT Own |
|---|---|---|---|
| Blu | DIRECTOR |
Global director, routing, dependency graph, P0 sequencing, cross-lane acceptance, deduplication | Implementation (unless no lane owns it) |
| Drupal Factory | DRUPAL_FACTORY |
Drupal CMS 2.0 factory, recipes, site template, Composer/BOM, contrib-first assembly, DDEV factory proof | ContextControl-specific product work, Bluefly.io content/site changes |
| Oracle IaC Convergence | ORACLE_IAC |
Oracle capacity, Terraform/IaC, storage expansion, runner/runtime deployment convergence, immutable-runtime enforcement | App code, Drupal features |
| Fleet Posture | READ_ONLY_FLEET_OBSERVER |
Read-only health, gc doctor, disk/load/session/rig posture, alerts, evidence, drift detection |
Mutations, repairs, claiming implementation beads |
| Agent ID | IDENTITY_PROVENANCE |
Machine/service identity, Git/SSH identity, provenance, gt whoami, personal-key removal |
Secrets delivery implementation itself |
| Durable Work Gov | DURABLE_WORK_GOVERNANCE |
Bead lifecycle, claims, dependencies, closeout, worktree lifecycle, completion law, authority rules | Product/app features, pack implementation |
| BluCityPacks | GASCITY_PACK_IMPLEMENTATION |
Packs, Formulas, Orders, Events, agent-role configuration; implements governed factory behaviors | Canonical doctrine text, app implementation |
| OpenClaw | OPENCLAW |
OpenClaw gateway/runtime/config/security/channel integration only | Gas City control plane, generic agent identity |
| ContextControl | CONTEXTCONTROL |
contextcontrol-ai, Drupal human control surface, kb_cache, context-cli, dashboard/operator UX |
Generic Drupal factory or unrelated platform infra |
| Bluefly.io | BLUEFLY_IO |
Bluefly.io Drupal site, content model, Canvas/SDC, site-specific integrations | Drupal platform/factory abstractions |
| MCP | MCP_TOOL_PROTOCOL |
MCP servers/tools/registry/gateway, Tool API boundary, protocol integration | Agent orchestration or Drupal workflow ownership |
Cross-Lane Boundary Rules¶
- Blu does not implement: Blu coordinates, routes, and verifies.
- Fleet Posture never mutates: Fleet Posture reports observations as findings routed to the owning lane.
- Authority boundaries generate handoffs, not idle time: When work falls outside an agent's assigned lane, the agent routes it via
gc slingandgc mailand continues the next ready work inside its lane. - No cross-lane hijacking: An agent inspecting another repository or subsystem for evidence may NOT make code or configuration changes outside its lane.
3. Concurrency Law & Work Selection¶
NO_NEW_P0_STARTS: The fleet is converging, not expanding. No new P0 work may be created or claimed unless Blu explicitly routes an existing canonical P0 to that lane.- One Active Bead Per Lane (
1 LANE = 1 ACTIVE BEAD): An agent maintains at most one actively executing unit of work in statein_progressat any time, unless the Bead explicitly declares governed parallel child work. - Prefer Convergence Over Discovery: Prioritize
finish → verify → merge → close → cleanoverdiscover → create → expand → parallelize. - Blocked Work Invariant:
TASK_BLOCKED=YESdoes NOT implyAGENT_BLOCKED=YES. When a task is blocked, record the blocker edge, update the Bead, send mail, and claim the next independent authorized work.
4. Bead Lifecycle State Machine¶
Every unit of work transitions through a governed lifecycle in canonical Dolt (127.0.0.1:3308/hq):
PROPOSED ──► READY ──► CLAIMED (in_progress) ──► IMPLEMENTED ──► VERIFIED ──► ACCEPTED ──► CLOSED
│ ▲
└──► BLOCKED (needs edge + handoff mail) ─────────────┘
Lifecycle Gates¶
PROPOSED/READY: Work item exists in the graph with clear title, scope, acceptance criteria, and owner.CLAIMED: Agent executesgc hook --claim(orbd update <id> --status in_progress). The Bead must exist in canonical Dolt before implementation begins.BLOCKED: Requires:TASK_BLOCKED=YES BLOCKED_BY=<named authority / issue ID> OWNER=<owning lane> HANDOFF_BEAD=<bead ID> MAIL_RECEIPT=<sent to owning lane> NEXT_INDEPENDENT_WORK=<next task ID>IMPLEMENTED: Code written, tests passing, committed and pushed torelease/v0.1.x.VERIFIED: Verified by independent tests, CI pipeline, or runtime evidence.ACCEPTED: Formal acceptance by the owning authority (e.g. Mayor or Blu).CLOSED: Final receipt attached, worktree confirmed deregistered and removed, Dolt state updated toclosed.
5. Worktree Lifecycle & Isolation Law¶
Canonical Worktree Roots¶
- Canonical Engineering Worktree Root:
$ESTATE_ROOT/worktrees/<bead-id-or-name> - Strictly Forbidden for Engineering Worktrees:
$ESTATE_ROOT/BluCity/.gc/worktrees/(reserved for internal GC runtime only) - Estate Root Prohibition:
$ESTATE_ROOT/is the estate root. NEVER clone, branch, or create worktrees directly in the root.
Scope Distinction Law¶
To prevent cross-host reporting confusion, all worktree receipts MUST distinguish scope:
LOCAL_CANONICAL_ENGINEERING_WORKTREE_ROOT = <count> active
ORACLE_GAS_CITY_DISCOVERED_WORKTREES = <count> valid
worktrees = 0 or worktrees = 48 without naming host and root.
Worktree State Machine¶
PROVISIONED ──► CLEAN_CHECKOUT ──► ACTIVE_WORK ──► COMMITTED ──► PUSHED ──► MR_MERGED ──► DEREGISTERED ──► REMOVED
- Provisioning: Create isolated worktree:
git worktree add $ESTATE_ROOT/worktrees/<bead-id> release/v0.1.x - Isolation: Never develop directly in canonical checkouts, NAS mounts, or Oracle production runtime.
- Prohibited Operations:
- NO
git stash(uncommitted work belongs in the worktree or a branch, never stashed). - NO
git rebaseon shared branches. - NO
git reset --hardon shared branches. - NO force pushes.
- Deregistration & Removal: Once MR is merged and verified:
cd <canonical-repo> git worktree remove $ESTATE_ROOT/worktrees/<bead-id> git worktree prune git branch -d <feature-branch>
6. The Hard Completion Law (The 9-Point Gate)¶
Work is not done because code was written, tests passed, or a branch was pushed. Work is complete ONLY when all 9 gates are satisfied:
SUCCESS =
1. IMPLEMENTED (code and configs cleanly authored)
+ 2. PUSHED (branch pushed to GitLab)
+ 3. MR_MERGED_TO_TARGET (merged to release/v0.1.x via governed path)
+ 4. EXTERNAL_VERIFIED (independent tests or runtime verification pass)
+ 5. DURABLE_RECEIPT_RECORDED (structured receipt attached to Bead)
+ 6. WORKTREE_CLEAN (no uncommitted or untracked changes)
+ 7. WORKTREE_DEREGISTERED (git worktree remove executed)
+ 8. WORKTREE_REMOVED (worktree directory confirmed deleted from disk)
+ 9. BEAD_CLOSED (Bead closed in canonical Dolt)
VALID_COMPLETED_WORK + UNCOMMITTED = FAILURE
VALID_COMPLETED_WORK + UNPUSHED = FAILURE
VALID_COMPLETED_WORK + NO_MR = FAILURE
GREEN_MERGEABLE_MR + NOT_MERGED = FAILURE
MERGED_MR + ABANDONED_WORKTREE = CLEANUP_FAILURE
BEAD_CLOSED + ACTIVE_WORKTREE = GOVERNANCE_VIOLATION
7. Inter-Lane Communication & Required End-of-Work Receipt (STD-GATE-001)¶
When handing off work, reporting status to Blu, or closing a Bead, agents MUST emit the complete structured End-of-Work Receipt as defined in STD-GATE-001:
BEAD=
OWNER=
RIG=
REQUESTED_EFFECT=
SOURCE_CHANGED=
RUNTIME_CHANGED=
DOCS_CHANGED=
BRANCH=
COMMIT=
MR=
CI=
EVIDENCE=
COVERAGE=
KNOWN_LIMITS=
BEAD_UPDATED=
DEPENDENCIES_UPDATED=
CANONICAL_DOC_UPDATED=
DOC_PATH=
SOURCE_DELIVERED=
RUNTIME_VERIFIED=
WITNESS_VERIFIED=
IS_THE_NEXT_RUN_GETTING_CHEAPER_AND_MORE_REUSABLE=
WHY=
NEXT_ACTION=
DONE=NO.
8. Mechanical Specification for BluCityPacks¶
BluCityPacks implements this standard through Gas City Formulas, Orders, and Agent configurations:
Required Formulas¶
formula-bead-claim:- Validates agent lane against Bead owner/metadata.
- Enforces
1 LANE = 1 ACTIVE BEAD. - Provisions isolated worktree under
$ESTATE_ROOT/worktrees/<bead-id>. - Transitions Bead status to
in_progressin canonical Dolt. formula-bead-closeout:- Verifies GitLab MR merged status on
release/v0.1.x. - Asserts
git status --porcelainis empty in the worktree. - Executes
git worktree removeandgit worktree prune. - Asserts worktree directory no longer exists on disk.
- Attaches final structured receipt to Bead notes.
- Transitions Bead status to
closedin canonical Dolt.
Required Orders & Event Gates¶
- Order:
order-worktree-reconciliation: Periodic or post-session order scanning for merged MRs with abandoned worktrees; alerts Fleet Posture. - Pre-Close Gate: Fail-closed constraint preventing
bd closeif the associated worktree is still listed ingit worktree list.
9. SINGLE COMPLETION LAW¶
Effective immediately, no Bluefly Factory change is complete unless its durable work state and durable knowledge state are updated as part of the same operation.
This applies to every Agent, every Rig, every Formula, every infrastructure change, every Drupal change, every policy change, every CI change, and every runtime repair.
The required lifecycle is:
BEAD → CLAIM → EXECUTE → VERIFY → RECORD EVIDENCE → UPDATE DURABLE KNOWLEDGE → SOURCE DELIVER → WITNESS → CLOSE
A change that skips any applicable stage is DONE=NO.
10. DOCUMENT AUTHORITY ORDER & UPDATES¶
Documentation is required when the work changes: - ARCHITECTURE - OWNERSHIP - OPERATING MODEL - SECURITY MODEL - DEPLOYMENT MODEL - CONFIGURATION MODEL - API CONTRACT - PRODUCT BOUNDARY - FACTORY STANDARD - RECOVERY PROCEDURE - KNOWN LIMITATION
Authority Order¶
- CURRENT SOURCE / LIVE RUNTIME
- ENGINEERING STANDARD / ADR
- PRODUCT AUTHORITY
- PROJECT-SPECIFIC DURABLE DOC
- BEAD
- GENERATED REPORT / SCRATCH (Scratch is NEVER authority)
When to Update BluCity-Docs¶
Update BluCity-Docs only for durable cross-project knowledge such as Factory architecture, Gas City operating standards, identity/auth standards, CI standards, security standards. Task status belongs in Beads.
When to Update Project Docs¶
Project-specific implementation knowledge stays with the owning project (e.g., api_normalization architecture, ContextControl integration design).
ADR Required for Material Architecture Decisions¶
Create or update an ADR when a decision changes system authority, source ownership, deployment topology, runtime boundary, security boundary, storage authority, public/private Pack boundary, API exposure, identity model.
11. ECONOMIC & PRODUCT IMPACT GATES¶
Every change must answer Product Impact:
CUSTOMER_OPERATION_SERVED=
PRODUCT_BLOCKER=
REVENUE_EFFECT=
COST_EFFECT=
RELIABILITY_EFFECT=
And Economic Gate:
IS_THE_NEXT_RUN_GETTING_CHEAPER_AND_MORE_REUSABLE=YES|NO|NOT_ESTABLISHED
WHY=
12. LEARNING & REPEAT WORK PROMOTION¶
When substantially the same action is performed repeatedly (REPEAT_COUNT >= 3), the Agent must ask:
IS_THIS_A_CAPABILITY_CANDIDATE=
If yes: record candidate, attach evidence, state limits, prove on second estate. Then consider reusable packaging (policy, check, test, procedure, Formula, configuration, integration, Skill).
13. SESSION END GATE¶
Before any Agent stops or rotates:
ACTIVE_BEAD_UPDATED=YES
UNCOMMITTED_WORK_ACCOUNTED_FOR=YES
UNPUSHED_WORK_ACCOUNTED_FOR=YES
MR_STATE_RECORDED=YES
BLOCKERS_RECORDED=YES
DOC_CHANGES_RECORDED=YES
NEXT_ACTION_RECORDED=YES
14. UNIVERSAL FACTORY GATE¶
Before mutation:
FACTORY_GATE=PASS (must check work authority, source authority, owner, rig, bead, claim, capability match, authority, service identity, policy, dependencies, execution surface, acceptance, verification, delivery path, evidence path, documentation disposition).
After mutation:
BEAD_UPDATED=
DOCS_UPDATED=
SOURCE_DELIVERED=
RUNTIME_VERIFIED=
WITNESS_VERIFIED=
ECONOMIC_GATE=
DONE=NO.
CENTRAL LAW - If the work happened but the Bead was not updated, the Factory does not know it happened. - If the architecture changed but the documentation was not updated, the next Agent will rediscover or contradict it. - If runtime changed without source delivery, the next deployment can erase it. - If the Agent claims success without evidence, the result is not trusted.