Factory Studio / Graph Ops

Follow the proof path.

A bounded control plane for Product, Mission, Proof, Gate, Trace, semantic lineage, and verified counterfactual repair. Follow the failure, compare every candidate, and understand the winning proof without executing it.

Read-only inspection. Graph Ops cannot execute, approve, publish, deploy, sign, message, access credentials, or grant connectors until a named person creates a narrowly scoped, expiring local authorization. WebMCP is a progressive enhancement; checking browser support.

Live Factory telemetry

Connecting to the local workspace.

Loading

Current stage, elapsed time, completed stages, and measured telemetry will appear here. Unknown token, cost, and productivity values stay unknown.

Memory Spine · proof-aware briefing

Turn the diff into the next safe proof.

See what changed, why it affects evidence, the smallest next step, and who local Git history observed on the selected work. It is explanatory and read-only: it does not run a proof, recall memory bodies, or authorize a person.

Loading local facts
1 · What changedLoading local change facts.
2 · Evidence stateLoading proof state.
3 · Do this nextLoading next action.
4 · Team contributionLoading local Git attribution.

Observed project contributors

Loading bounded local Git history.

Brief refreshes no more than once every five seconds. Live assembly telemetry refreshes separately.

Proof Review · team inbox

Review the riskiest item first.

Current, stale, and invalid proof reviews stay separate. This queue never infers productivity and never approves work.

Loading
Current0
Stale0
Invalid0
Learned regressions0
No current review itemCreate a proof review from a confirmed intent contract.
Revenue · evidence before action

See exactly where purchase reality diverges.

Build the monetization lane, replay the observed lifecycle, challenge every failure path, and invalidate only conclusions touched by policy drift.

No bundle
Build contractNo hash-bound bundle
Purchase replayNo build-bound replay
Failure matrixNo negative-path evidence
Policy watchNo source comparison
TestFlight inboxNo authorized local export
Human decisionUnknowns and mismatches block green; provider writes remain locked.
No generated bundle yet. App Store writes, pricing, offers, experiments, and publication remain locked.
SaaS Reality · provider neutral

Did login, payment, and permission agree?

Trace an observed OAuth/OIDC identity through tenant authorization, checkout, verified webhook, entitlement, feature access, and revocation. Clerk, Auth0, Okta, Entra, Cognito, Supabase, Firebase, and other compliant providers use the same evidence contract.

No receipt
IdentityIssuer, audience, active token, and PKCE contract
AuthorizationSubject, tenant, and role binding
EntitlementPromise, SKU, webhook, and access order
RevocationCancel, refund, and expiry must remove access
No hash-valid receipt. Unknown evidence stays blocked; no provider is contacted or mutated.
AppForge + SaaS · mission control

Improve your app before Apple finds the gap.

Start with one plain-English mission and one exact build. AppForge binds user design input, strict UI and accessibility evidence, SaaS reality, policy applicability, and current-build media without placing secrets in Code Factory. A supervised agent may prepare the packet; only a named human can authorize the final Apple handoff.

Init + 4 evidence lanes
1 · MissionWho the app serves and what they need to accomplish.
2 · TensionWhich design, policy, or runtime gap could delay review.
3 · GuidanceThe smallest exact evidence needed to resolve it.
4 · AgencyYou choose human-controlled or supervised preparation.
5 · TransformationUnknowns become verified facts or visible blockers.
6 · Ready handoffA sealed receipt and named approval unlock one exact next step.
Use a keychain item or environment-variable name. Raw keys and passwords are refused.
Your review pathConnect references
Classify every policy
Import current-build evidence
Resolve every blocker
Review what changed
Authorize one exact handoff

Locked: App Review, Store media, SaaS lifecycle, and strict quality-audit receipts must match the same candidate before AppForge issues the final Markdown/PDF dossier. A separate named, expiring human authorization is still required for any Apple handoff. This page never receives raw credentials or silently submits an app.

Journey Proof · repair supervision

Choose who may attempt the repair—not who may approve it.

Human-controlled mode only verifies a prepared repair. Supervised-auto mode permits one bounded local agent command, then independently audits its identity, command, workspace delta, scope, positive proof, and negative mutation. Neither mode grants final approval.

Loading receipts
0 verified receiptsNo Journey Proof receipts are loaded. The controls create an inert template only; they never start an agent or approve a repair.

Final approval is always withheld. Run the copied manifest through factory journey heal-verify in a separately reviewed terminal.

Forge receipt · intent trace

Did the shipped work honor the sealed intent?

This is a local, read-only projection of the newest Forge ship receipt. It shows the intent hash and obligation result without treating a receipt as execution or approval authority.

Loading traceability
Fail-closed boundary. No local Forge ship receipt has been projected; intent traceability is unverified.

Nodes

Edges

Evidenced

Lineage runs

Forensic findings

Repair candidates

Graph status

Loading

Proof path visual

One compact visual map of the supplied requirement-to-decision flow. It explains the current state; it never executes a graph action.

Local facts
Intent0 requirements
Verifier0 receipts
PolicyNo dossier
Human decisionReview required

Evidence health

Deterministic ratios from this bounded graph result, not estimated productivity or a quality score.

Loading
evidenced
Requirements
Policy drift
Blocked gates

Graph lanes

Loading the authenticated local graph result.

Graph data is read from /api/graph-ops. A separate token-bound local request can record one named authorization or consume one Reality Check authorization. Labels are rendered as text nodes.