Run it · first run
Quickstart
One command, one receipt. What the entry point prints, how to read each field, and three boundaries you can watch refuse.
Open quickstartDocumentation
Nine reference pages cover the operator entry point and the contracts around it: the flags it accepts, the receipt it prints, the kernel those lines are projected from, the service door that refuses to guess, and every named boundary at which a run refuses instead of acting.
Start here
Each of these reads the same operator entry point. They differ in what you are looking for: a first run, the exact command surface, or the receipt you are holding.
The whole set
Understand the words, run the loop, or operate the service. Each of the nine reference pages appears once below, with the one line that says what it is for; the quickstart is the way in.
Understand it
What does the product mean by each of these words?
What each domain module supplies — evidence, candidate, baseline, mandate — and what its gates mean.
The typed identities, the invariant each one holds, the replay law, and what a pack or model module must supply.
Every named way a run can refuse, the scenario token that shows it, and the behaviour to expect. 15 boundaries today.
Run it
What do I type, and what comes back?
One command, one receipt, and three boundaries you can watch refuse on your own machine.
The five modes with their flags and requirements, the scenario tokens, and the failure contract.
Every field a receipt carries, what it binds, and the seven conditions mapped to the lines that show them.
Operate it
How do I run the service, and what keeps it honest?
What serve binds, what the boot self-check proves, the refused wake, and what unpausing the schedule requires.
The five boundaries, what the product never reaches, how refused material is handled, and how to report a concern.
Symptom, cause, action for the refusals you will actually meet, and when a refusal is the correct outcome.
How these docs are organised
Nothing here is filed twice. If a fact has a home, the home is the surface that owns it, and the other pages link to it rather than repeating it.
Why the loop is shaped this way: the six stages, the refusal each stage owns, and what a verified outcome means.
The exact contract: receipt fields, scenario tokens, per-domain gates, and the limits the product will not cross.
What you type and what comes back: the local entry point, its service door, and the console that projects this deployment.
Before you run anything
The entry point reads sealed corpora and checked-in fixtures on your machine. There is no hosted service to sign in to, no customer data, and no external effect.
MapWhere the product talks about itself
The loop walkthrough explains the stages and their refusals, the proof surface explains what verified means, the verification method explains what would falsify it, and pricing covers the commercial shape without a released plan.