ForgeLayer

Private beta findings and action plan

Turn pilot evidence into clear findings, owners, priorities, and next controlled actions.

Review demonstrated strengths, unresolved control and evidence gaps, production blockers, suggested owners, and completion criteria without creating production decisions or side effects.

Deterministic previewLocal state onlyNon-persistentGeneric Platform Guidance: Human approval required

Pilot scenario

Choose the evidence set to review

Changing the scenario resets local owner and status choices. Nothing is saved or sent.
ScenarioSecure a payment webhook
Strengths1
Unresolved gaps7
Production blockers2
Human decisions7

Findings

Strengths, gaps, and blocked production requirements

8 of 8 deterministic findings shown. Status and owner changes remain local.
finding_connected_control_story

The controlled work journey is understandable end to end

medium prioritycompleted in preview
Categorydemonstrated strength
Affected modulesWorkspace, Journey, Pilot, Evaluation
OwnerPilot lead
Observed evidence
  • Stable module ownership
  • Connected stage state
  • Linked deterministic record references
  • Webhook test plan drafted
  • Protected payment path matched
System interpretation

ForgeLayer can demonstrate module ownership, handoffs, and human control without executing work.

Unresolved limitation

The connected journey uses deterministic sample records and local state.

Human decision required

Confirm that the sequence and module responsibilities match the pilot team's expectations.

Recommendation

Use the same scenario in the Pilot, Evaluation, and Findings surfaces during reviewer sessions.

Completion criteria
  • Reviewer can explain the control journey and identify the human approval gate.
Dependencies
  • A selected deterministic pilot scenario
Future production requirement

No additional blocker identified for this preview finding.

finding_review_evidence_is_simulated

Review evidence needs production-grade provenance

high priorityopen
Categoryevidence gap
Affected modulesReview Runs, MergeGuard, AI Work Ledger
OwnerEngineering lead
Observed evidence
  • Safe Review Run summary
  • Policy and verification labels
  • Check and comment previews
  • Webhook test plan drafted
  • Protected payment path matched
System interpretation

The product demonstrates evidence structure, but not durable production evidence.

Unresolved limitation

Verification and evidence may be simulated, derived, or preview-only.

Human decision required

Identify which test, build, policy, and reviewer evidence a real pilot must capture.

Recommendation

Define evidence sources and retention rules before expanding persistent Review Runs.

Completion criteria
  • Required evidence sources, ownership, and acceptance rules are documented.
Dependencies
  • Workspace identity
  • Evidence schema
  • Retention policy
Future production requirement
  • No production persistence
  • No verified evidence ingestion
finding_human_approval_is_local

Human approval is explicit but not durable

high priorityopen
Categoryapproval gap
Affected modulesPilot, Control Flow, AI Work Ledger
OwnerSecurity reviewer
Observed evidence
  • Explicit local approve, request-changes, or block decision
  • Webhook test plan drafted
  • Protected payment path matched
System interpretation

The control gate is visible, while identity, authority, and decision history remain foundation work.

Unresolved limitation

Approval decisions update local preview state only.

Human decision required

Define who may approve each risk class and what evidence they must review.

Recommendation

Design workspace-scoped approval records after identity and RLS boundaries are reviewed.

Completion criteria
  • Approval roles, evidence requirements, and revocation behavior are defined.
Dependencies
  • Production identity
  • Workspace roles
  • RLS
Future production requirement
  • No durable approval record
  • No production approver identity
finding_policy_needs_workspace_ownership

Repository policy needs authenticated workspace ownership

high priorityplanned
Categorypolicy gap
Affected modulesRepoBrain, MergeGuard, Workspace
OwnerPlatform owner
Observed evidence
  • Blocked actions
  • Required control gates
  • Scenario risk signals
  • Webhook test plan drafted
  • Protected payment path matched
System interpretation

RepoBrain shows how repository rules influence review, but policy authority is not established.

Unresolved limitation

Deterministic policy context is not bound to a production workspace identity.

Human decision required

Confirm who owns repository policy and how policy changes are reviewed.

Recommendation

Bind repository installations and policy versions to workspace-scoped identity before writes.

Completion criteria
  • Policy ownership, versioning, and change-approval rules are documented.
Dependencies
  • Workspace identity
  • GitHub installation ownership
  • Policy version records
Future production requirement
  • No production workspace boundary
finding_workspace_identity_required

Workspace identity and RLS are prerequisites for durable records

critical priorityblocked
Categoryoperational prerequisite
Affected modulesWorkspace, AI Work Ledger, Review Runs, Agent Work Records
OwnerPlatform owner
Observed evidence
  • Readiness prerequisites and intentionally blocked capabilities
  • Webhook test plan drafted
  • Protected payment path matched
System interpretation

Persistent records cannot safely expand until the implemented identity, membership, role, and tenant-isolation foundation is activated and integration-tested.

Unresolved limitation

The private-beta workspace is a non-persistent demo boundary.

Human decision required

Review the production architecture plan and approve an identity-first implementation sequence.

Recommendation

Implement workspace identity and tested RLS before adding durable Agent Work Records or approvals.

Completion criteria
  • Identity, membership, role, and RLS designs pass security review.
Dependencies
  • Production architecture review
Future production requirement
  • Production auth not live
  • Workspace RLS not implemented
finding_write_actions_blocked

Repository writes and automatic actions remain blocked by design

critical priorityblocked
Categoryproduction blocker
Affected modulesMergeGuard, GitHub App, AgentOS
OwnerSecurity reviewer
Observed evidence
  • Disabled execution, writes, posting, merge, and persistence flags
  • Webhook test plan drafted
  • Protected payment path matched
System interpretation

The blocked posture is intentional and prevents the preview from becoming an execution path.

Unresolved limitation

No repository write, GitHub posting, automatic merge, or live agent execution is available.

Human decision required

Keep the blocked posture until permissions, idempotency, audit events, and kill switches are reviewed.

Recommendation

Treat write and execution capabilities as separate, explicitly approved production phases.

Completion criteria
  • Every future side effect has an explicit gate, owner, audit event, idempotency key, and kill switch.
Dependencies
  • Workspace identity
  • Approved repository
  • Audit events
  • Kill switches
Future production requirement
  • No controlled execution boundary
  • No production write authorization
finding_analytics_are_preview_only

Analytics need consent, retention, and production event semantics

medium priorityplanned
Categoryoperational prerequisite
Affected modulesAI Work Analytics, AI Work Ledger, Workspace
OwnerProduct owner
Observed evidence
  • Deterministic activity records
  • Linked evidence count
  • Control outcome summaries
  • Webhook test plan drafted
  • Protected payment path matched
System interpretation

The preview demonstrates useful control questions, not measured customer behavior.

Unresolved limitation

Analytics use fixed sample records and are not production telemetry.

Human decision required

Choose which control insights justify collecting production events.

Recommendation

Define event schemas, consent, retention, and privacy boundaries before enabling telemetry.

Completion criteria
  • Approved metrics have documented source events, purpose, retention, and access rules.
Dependencies
  • Workspace identity
  • Event schema
  • Retention policy
Future production requirement
  • Production telemetry disabled
finding_control_flow_can_expand_later

Controlled output intake is a future opportunity

low priorityplanned
Categoryfuture opportunity
Affected modulesAgentOS, Control Flow, Agent Work Records
OwnerProduct owner
Observed evidence
  • Primary and supporting agent recommendations
  • Capability and control-risk context
  • Webhook test plan drafted
  • Protected payment path matched
System interpretation

A future controlled intake layer could accept agent output without granting autonomous authority.

Unresolved limitation

ForgeLayer recommends and plans work but does not contact or execute agents.

Human decision required

Validate demand and safety requirements before designing any external agent connection.

Recommendation

Keep external execution blocked; prototype output intake only after production foundations exist.

Completion criteria
  • A reviewed design separates task routing, output intake, verification, approval, and execution.
Dependencies
  • Production identity
  • Durable Work Records
  • Verification controls
Future production requirement
  • No external agent calls
  • No execution authorization

Deterministic action plan

Move from pilot discussion to controlled follow-up

No deadlines, budgets, commitments, repository changes, or execution actions are created.

Immediate pilot follow-up

action_validate_pilot_findingsReview the findings with the pilot team
high
Suggested owner
Pilot lead
Supporting findings
finding_connected_control_story, finding_review_evidence_is_simulated, finding_human_approval_is_local
Dependency
A completed deterministic Pilot and Evaluation walkthrough
Completion criteria
The team confirms strengths, gaps, owners, and human decisions that still need definition.
Safety impact
Keeps recommendations separate from human decisions.
Next controlled step
Record local owner and status choices, then export the discussion manually if needed.

Private-beta preparation

action_define_beta_evidence_and_policyDefine pilot evidence and repository-policy ownership
high
Suggested owner
Engineering lead
Supporting findings
finding_review_evidence_is_simulated, finding_policy_needs_workspace_ownership
Dependency
Pilot team agreement on required evidence and policy reviewers
Completion criteria
Evidence sources, policy owners, and review expectations are written and reviewed.
Safety impact
Prevents simulated evidence or unowned policy from being treated as an approval basis.
Next controlled step
Compare the agreed requirements with Review Runs, RepoBrain, and MergeGuard previews.

Production foundation

action_build_identity_firstImplement identity and workspace isolation before durable expansion
critical
Suggested owner
Platform owner
Supporting findings
finding_human_approval_is_local, finding_workspace_identity_required, finding_analytics_are_preview_only
Dependency
Approved production architecture and security review
Completion criteria
Users, memberships, roles, workspace scope, and RLS are implemented and tested.
Safety impact
Establishes who can view, approve, and persist each workspace record.
Next controlled step
Use the production architecture plan to sequence identity, RLS, and durable records.

Controlled execution preparation

action_keep_execution_blockedDesign side-effect gates before considering execution
critical
Suggested owner
Security reviewer
Supporting findings
finding_write_actions_blocked, finding_control_flow_can_expand_later
Dependency
Identity, permissions, audit events, idempotency, and kill switches
Completion criteria
Each possible write or execution action has an explicit permission, approval, audit, and rollback design.
Safety impact
Preserves the current no-write, no-posting, no-merge, no-execution boundary.
Next controlled step
Keep all execution flags disabled and review the GitHub Checks and production architecture plans.

Production blockers

Requirements that stay blocked

BlockedWorkspace identity and RLS are prerequisites for durable recordsPlatform owner
  • Production auth not live
  • Workspace RLS not implemented
BlockedRepository writes and automatic actions remain blocked by designSecurity reviewer
  • No controlled execution boundary
  • No production write authorization

Next controlled action

Complete the human pilot decision

Return to the Evaluation or Pilot before treating any finding as resolved.

Open next surface

Deterministic completion summary

Secure a payment webhook

1 strength identified, 7 unresolved gaps, and 2 production blockers. 11 modules require follow-up and 7 human decisions remain.

Preview onlyNon-persistentNo live execution