Skip to content

BLUEFLY FACTORY GOVERNANCE — CORE LAW

Authority: blucity-packs/core + BluCity-Docs. Durable work authority is Beads and Gas City on Oracle (127.0.0.1:3308/hq).

Reuse First

  1. Search Before Authoring — inspect via CodeGraph, grep, rig catalog before creating anything new.
  2. Bluefly capabilities, formulas, and libraries must be reused. Never author duplicate microservices or ad-hoc task systems.
  3. Shared dependencies belong in blueflyio/gitlab_components or core libraries, not re-implemented in consumer repos.

Work Authority

  1. Beads is the exclusive work authority. No private todo lists, memory files, or ephemeral agent tasks.
  2. Canonical Dolt: 127.0.0.1:3308/hq.
  3. WIP=1: claim exactly one bead before beginning work.
  4. BLU owns the board. Cross-lane or cross-rig handoffs route through BLU via gc mail and gc sling.
  5. When waiting on async pipelines: record state, continue other ready authorized work. Never poll.

Agent Identity and Provenance

  1. Autonomous agents execute under their assigned service account — never a human identity.
  2. Never assert flux423 or @bluefly as agent identity.
  3. Every task execution and handoff must record trace IDs and receipt hashes.
  4. Secrets via 1Password references only. Never print, inspect, echo, or commit credentials.

Delegation and Action Governance

  1. Subagents execute exclusively within the scope granted by the parent agent.
  2. No privilege escalation beyond parent grant.
  3. Action tiers:
  4. Safe Inspection: always permitted for authenticated workers
  5. Worktree Mutation: permitted strictly within the bead-assigned worktree
  6. Cross-Rig / External Operations: requires explicit ContractPlane grant evaluation
  7. Irreversible Destructive Actions: prohibited for autonomous agents

Workspace Hygiene

  1. Dead code removal, temp file cleanup, and worktree deletion upon acceptance are mandatory deliverables.
  2. Local deletions: use trash. Never rm.
  3. Never write scratch files to estate root or config directories. Use Scratch/<task>/.
  4. Clean up Scratch/<task>/ once deliverables are shipped and accepted.

Verification and Acceptance

  1. Work is complete ONLY when effects are demonstrated by passing tests, pipelines, or receipts — not when code is generated.
  2. Every completed bead must emit a final verification receipt:
    TASK=  BEAD=  OWNER=  RESULT=  MR=  COMMIT=  PIPELINE=  VERIFICATION=  NEW_BLOCKERS=  NEXT_WORK=
    

Ownership and Audit

  1. When an issue is discovered in generated/installed projections (web/, vendor/), fix the upstream producer — never the copy.
  2. Rigs, packs, and documentation must have exactly one authoritative GitLab repository owner.