Skip to content

Builder Agent operator guide

Status: RELEASED, LOCAL-SYNTHETIC CONTRACT SURFACE. The Builder contracts, tests and synthetic reference fixture are present in the current public release. They are not a user-facing arbitrary-system builder, a command to connect a live system, production evidence or publication authority.

Operator flow

  1. Open one issue-style delivery contract with scope, non-scope, dependencies, numbered acceptance criteria, negative probes, evidence, recovery and honest non-claims.
  2. Keep SAFE_GUIDED as the intake default. CUSTOM can widen only through its declared governed routes. The canonical RAMPAGE_FULL_CONTROL_LAB profile (RAMPAGE and FULL_CONTROL_LAB aliases) is a different, dangerous lab/escape choice: after exact Owner risk acceptance it may bypass PanSphaira action and Approval gates, but never the host process's OS/host ceiling. Use only in a disposable or explicitly bounded lab, downgrade claims for bypassed layers, and bind reset/rollback/recovery before use.
  3. Supply a synthetic Machine Manifest, operation-scoped System Advisor Guide and bounded cause/effect context. Discovery selects only requested operations and covered context.
  4. Review the effective-rights explanation. Rights are the intersection of the Host/System ceiling, Owner profile, assignments and current constraints. The Builder Agent itself is untrusted and cannot mint rights or approvals.
  5. Reuse an exact compatible capability. Keep any gap as an inactive, non-executable UNRESOLVED_INTENT; never convert unknown intent directly into an effect.
  6. Review the generic integration plan, fixtures and recovery strategy. A target-specific contract may bind fields and operations, but the shared Builder core remains target-neutral.
  7. Validate readback, receipts and rollback in a synthetic isolated fixture. Installation, activation, mutation and publication are separate routes.
  8. Generate a sanitized contribution bundle only when sharing is deliberately requested. The released v1 contract is opt-in and synthetic, and every generated bundle carries publication authorization ABSENT.

Stop conditions

Stop without activation or publication when an input has an unknown field, schema or digest drift, incompatible capability, missing tenant binding, unresolved recovery, failed readback, rollback mismatch, cross-tenant request, credential-shaped content, private path, raw prompt/runtime receipt, customer data or absent Owner routing.

In governed Profiles, AUTO_EXECUTE is a mediated route selected within the Owner's effective rights and does not override the Host/System ceiling, capability admission, use-time checks, tenant isolation or current constraints. The lab profile's separately declared bypass is not described as mediated and inherits no Builder/Canon security claim for the bypassed gates.

Recovery

Deactivate the isolated profile, revert the bounded implementation, restore only fixture-owned state, reconcile through readback, revoke the specific assignment and retain digest-only evidence. Reset, rollback, revoke and cleanup are separate operations. Restart, revoke or cleanup returns the published lab profile lifecycle to SAFE_GUIDED. A failed recovery produces no success claim.

Evidence and non-claims

Accept a local checkpoint only when focused tests, negative probes, full tests, checksum closure, supply-chain declarations and deterministic public staging pass in proportion to the changed surface. Local synthetic evidence is not production authorization, customer-data fitness, hostile-host containment, security certification or universal agent/system compatibility. Release of the contract bytes does not authorize a live connection, activation or publication.

Local synthetic proof of concept — not a production release or security certification.