This target repository follows wellmanifest/new-project policy-as-code.
Before any multi-step implementation, an agent must:
.governance/manifest.json, TODO.md, project/TICKETS.md and the
active ticket../project/new-ticket.sh --title "..." --agent "..."
--workstream "...".README.md, owned ai-*.md, intent.json and TODO.md.WAIT_FOR_APPROVAL; do not change implementation files yet.EDIT and stay inside intent.json
allowedPaths.project/ticket-*/user-*.md; only its human owner or a
trusted intake boundary may do so../project/governance-check.sh plus the stack and Docker checks before
reporting completion.integrationTicket coordinates work but does not
transfer path ownership.IN_PROGRESS reserves a workstream and write scope. BACKLOG, PLAN
and BLOCKED retain evidence without blocking another implementation;
transition back to IN_PROGRESS before changing source or tests.User login is in protected trusted-reviewers or a Bot login
is in the separate protected trusted-validator-apps input. Never trust an
arbitrary Bot review.LLM_MODEL_VALIDATOR=openrouter/z-ai/glm-5.2; model findings stay advisory.delete_branch_on_merge=true. A merged ticket branch
must disappear after merge. A PR closed without merge keeps its branch until
the owner explicitly discards that unmerged work. When no PR is open, the
only remote branch is the default branch.Markdown approval is an audit note, not trusted merge authorization. Required merge approval comes from the repository’s protected review, attestation and ruleset boundary.