BLUEFLY FACTORY GOVERNANCE — CORE LAW¶
Authority:
blucity-packs/core+BluCity-Docs. Durable work authority is Beads and Gas City on Oracle (127.0.0.1:3308/hq).
Reuse First¶
- Search Before Authoring — inspect via CodeGraph, grep, rig catalog before creating anything new.
- Bluefly capabilities, formulas, and libraries must be reused. Never author duplicate microservices or ad-hoc task systems.
- Shared dependencies belong in
blueflyio/gitlab_componentsor core libraries, not re-implemented in consumer repos.
Work Authority¶
- Beads is the exclusive work authority. No private todo lists, memory files, or ephemeral agent tasks.
- Canonical Dolt:
127.0.0.1:3308/hq. - WIP=1: claim exactly one bead before beginning work.
- BLU owns the board. Cross-lane or cross-rig handoffs route through BLU via
gc mailandgc sling. - When waiting on async pipelines: record state, continue other ready authorized work. Never poll.
Agent Identity and Provenance¶
- Autonomous agents execute under their assigned service account — never a human identity.
- Never assert
flux423or@blueflyas agent identity. - Every task execution and handoff must record trace IDs and receipt hashes.
- Secrets via 1Password references only. Never print, inspect, echo, or commit credentials.
Delegation and Action Governance¶
- Subagents execute exclusively within the scope granted by the parent agent.
- No privilege escalation beyond parent grant.
- Action tiers:
- Safe Inspection: always permitted for authenticated workers
- Worktree Mutation: permitted strictly within the bead-assigned worktree
- Cross-Rig / External Operations: requires explicit ContractPlane grant evaluation
- Irreversible Destructive Actions: prohibited for autonomous agents
Workspace Hygiene¶
- Dead code removal, temp file cleanup, and worktree deletion upon acceptance are mandatory deliverables.
- Local deletions: use
trash. Neverrm. - Never write scratch files to estate root or config directories. Use
Scratch/<task>/. - Clean up
Scratch/<task>/once deliverables are shipped and accepted.
Verification and Acceptance¶
- Work is complete ONLY when effects are demonstrated by passing tests, pipelines, or receipts — not when code is generated.
- Every completed bead must emit a final verification receipt:
TASK= BEAD= OWNER= RESULT= MR= COMMIT= PIPELINE= VERIFICATION= NEW_BLOCKERS= NEXT_WORK=
Ownership and Audit¶
- When an issue is discovered in generated/installed projections (
web/,vendor/), fix the upstream producer — never the copy. - Rigs, packs, and documentation must have exactly one authoritative GitLab repository owner.