Release summaries
adaptive-dataview-command-center
Add adaptive DataView management-shell contracts and command-center proof metadata.
maintainer
DataView specs can now declare management-shell header, toolbar, selection, row-card, detail-panel, pagination, action placement/boundary, field-role, personalization, and RoleMorph references.
integrator
Host applications receive additive metadata for command-center DataView layouts while retaining ownership of CRUD side effects, modal state, validation, and destructive confirmations.
adaptive-dataview-management-contract
Add optional DataView management-shell metadata for adaptive command-center layouts.
maintainer
DataView contracts now include additive management-shell metadata for semantic field roles, action placement, toolbar/header/selection/detail-panel, and adaptive binding hints.
integrator
Integrators can describe command-center layouts and action boundaries in metadata while keeping application behavior host-owned.
adoption-aware-release-pipeline
Adoption-aware release pipeline with accumulating release index, per-version detail files, CLI changelog list/view commands, and web changelog version pages.
maintainer
Release build now syncs adoption catalogs, writes pending upgrades, and produces an accumulating release index with per-version detail files. CLI changelog commands (list/view) consume the generated index.
integrator
The `after-release-build` adoption hook is available in CI and local builds. Adoption catalog entries are now enriched from release index data.
customer
Web changelog now supports per-version detail pages with package breakdown, migration instructions, upgrade steps, and deprecation notices.
adoption-engine-and-authoring-targets
Add a family-aware ContractSpec Adoption Engine, expand contract authoring targets across CLI and VS Code tooling, and refresh release-facing schema and policy artifacts for downstream workspaces.
maintainer
Maintainers get a shared adoption catalog and resolver, Connect adoption hooks, MCP exposure for reuse decisions, expanded authoring-target coverage, and updated static policy artifacts.
integrator
Integrators can resolve existing workspace or ContractSpec OSS surfaces before adding new implementations, and can scaffold more contract families from the CLI and VS Code extension.
customer
Customer workspaces gain setup-managed adoption guidance, Connect `adoption sync/resolve` flows, stronger runtime-import and deprecated-monolith guardrails, and updated bundled schemas in the published CLI entrypoint.
agent-application-foundation
Add a contract-first, filesystem-authored agent application foundation with governed runtime ports, durable cross-adapter conformance, isolated EVE integration, agent evals, and a reference application.
integrator
AgentSpec and WorkflowSpec now share one canonical runtime-adapter identity that includes `eve`; exhaustive adapter switches must handle the new key without importing EVE types into generic libraries.
maintainer
Durable stores, sandbox, file retrieval, subagent dispatch, collaboration leases, runtime parity, filesystem compilation, and eval evidence now have explicit package-local verification surfaces.
agent
Filesystem-authored applications can compile into portable AgentSpec and WorkflowSpec output, run bounded orchestrator/verifier flows, and emit replay-linked evaluation evidence.
agentic-communication-command-inbox
Add fail-closed agentic interaction and CommunicationOS command-inbox release evidence across contracts, runtime, module, examples, and agent-facing docs.
maintainer
Maintainers get a validation matrix for the subpath-only AIP safety surface, command-inbox runtime projection, module facade, focused CommunicationOS proof, and Operating Cockpit CompanyOS bridge proof.
integrator
Integrators can adopt message-originated command evidence without granting send, credential, shell, or high-impact CompanyOS execution authority.
agent
Agents must treat command-inbox items as non-executing evidence and keep blocked signals fail-closed until an external approval path acts.
builder-v3-control-plane-rollout
Introduce the Builder v3 control plane as a governed authoring layer over external execution providers.
maintainer
Builder v3 now has a governed contract, runtime, and provider surface that keeps authoring, readiness, and export orchestration aligned across the package stack.
integrator
Integrators can compose managed, local, and hybrid runtime modes with Builder workbench/mobile-review modules and provider adapters for Codex, Claude Code, Gemini, Copilot, STT, and local models.
customer
Builder operators now get a unified workbench and mobile-review experience across provider routing, readiness, export approval, and omnichannel control flows.
byok-monorepo-env-config
Add first-class monorepo-aware environment contracts and managed/BYOK credential setup helpers.
integrator
Monorepos can declare logical environment variables once and materialize framework-specific aliases such as NEXT_PUBLIC_* and EXPO_PUBLIC_* per app target.
maintainer
Integration specs can expose managed/BYOK credential manifests while runtime reports redact secret and sensitive values.
customer
BYOK setup can be validated from shared contracts without placing raw secrets in specs, docs, reports, or generated env examples.
company-intelligence-authenticated-api
Add a contract-derived authenticated Company Intelligence v1 Elysia boundary with durable tenant-scoped replay and request budgets, canonical PostgreSQL operation bindings, and production-only model service ports.
integrator
Mount the v1 Company Intelligence API only with tenant-bound session or service-principal authority and the approved tenant-scoped PostgreSQL repositories. Apply migration 0027 for durable replay and request budgets. Built-in PostgreSQL adapters authorize evidence, replay, reviews, graph, and Brain access. Bind external extraction and grounded-answer services separately; health stays degraded and those two operations fail closed until their dependencies are available.
companyos-connect-canonicalization-v1
Add a strict historical-v1 database read boundary so a human can approve forward-only migration 007 before it normalizes text storage to the unchanged public integer-v1 contract, while preserving approval-event provenance across historical JSON-only and complete denormalized storage shapes.
integrator
Integrators retain the literal canonicalizationVersion 1 contract while exact historical PostgreSQL text "1" is read compatibly for approval and then normalized by a tracked migration; approval event provenance remains canonical in integrity_metadata before and after denormalization.
maintainer
Migration owners get a dry-run-first CLI with advisory locking, predecessor enforcement, transactional rollback, ledger replay, and explicit confirmation. The first-reviewer provisioning apply is intentionally outside the otherwise-circular Connect signature gate, but requires the authenticated migration-owner role, seven exact confirmations, rollback evidence, and idempotent replay. Migration 006a preserves historical ledger IDs while adding reviewer-runtime nonce, issuer, and RLS support; explicit public authorization and reviewer proof metadata replace embedded trust.
companyos-solutions-starting-points
Redesign the CompanyOS /solutions buyer path around starter workflows, reusable governed workflow patterns, and bring-your-own-process conversion while adding structured marketing contract card fields and icon-key transport.
integrator
MarketingSectionContract cards may now carry optional iconKey and structured fields. Existing title/description/href cards remain valid; renderers can opt into labelled card content without parsing description strings.
customer
CompanyOS /solutions now frames named packages as starter doors that prove reusable governed workflow patterns and routes buyers to bring their own workflow when the catalog does not match their first process.
connect-local-approval-kernel
Add the durable local Connect approval kernel, linkage recovery, and tenant isolation.
integrator
Integrators can persist generic channel or Connect approval subjects with immutable digest generations and recover an incomplete Connect runtime link safely.
maintainer
PostgreSQL operators must run the ordered approval migrations with a migration owner while the non-owner runtime uses transaction-local tenant and workspace context.
connect-spec-alignment-april-2026
Implement ContractSpec Connect as a first-class spec, runtime, and CLI workflow.
maintainer
Connect is now a governed repo surface with CLI commands, workspace services, and versioned docs that keep risky edits, review packets, and replay artifacts aligned.
integrator
Integrators can enable `.contractsrc.json > connect`, emit local context/plan/verdict artifacts, and route adapter-facing review or replay flows through the shared workspace services.
agent
Coding-agent surfaces now have a first-class Connect workflow for context packs, plan packets, mutation verdicts, review packets, and replay/eval evidence instead of relying on ad hoc governance prose.
contract-dx-first-slice
Improve app-config, theme, and feature authoring with explicit validation APIs, first-class theme discovery and scaffolding, and key-based app-config generation across contracts, workspace tooling, and the CLI.
maintainer
Maintainers can rely on authored validators for app-config, theme, and feature specs instead of shallow per-surface checks, and can scaffold theme specs directly from the CLI.
integrator
Integrators get a stable `defineTheme` authoring path, new theme and feature validation helpers, and key-based app-config DTOs and templates across shared tooling.
customer
CLI users can now run `contractspec create theme`, and validation catches more app-config, theme, and feature mistakes before publish or CI promotion.
contracts-spec-entities-module
Add entities module to contracts-spec — EdgeSpec, defineContractEdge, defineContractEntity (Layer 1+2), EntityRegistry.
maintainer
New entities/ module adds EdgeSpec, defineContractEdge, defineContractEntity (Layer 1+2), and EntityRegistry. All exports are additive. Schema layer (lib.schema defineEntity) is untouched per A4 invariant. 11 unit tests added covering Layer-1 and Layer-2 round-trips, A4 verification, EntityRegistry CRUD and listEdges flattening, and duplicate guards.
integrator
Import EdgeSpec, defineContractEdge, defineContractEntity, and EntityRegistry from @lssm-tech/lib.contracts-spec. Use defineContractEntity Layer 1 (meta + edges) for slug-only entity declarations, or Layer 2 (meta + entity + edges) to attach a full EntitySpec<TFields> from @lssm-tech/lib.schema. Register all entities and edges in EntityRegistry before any DataViewRenderer resolves graph slugs.
contracts-spec-loop-d-operation-aliases
Loop D D4 — `@lssm-tech/lib.contracts-spec` now supports `meta.aliases?: readonly string[]` on operations. `OperationSpecRegistry.get()` falls back to alias lookup when the canonical key misses. Future namespace migrations can ship as additive instead of BREAKING.
maintainer
Added `aliases?: readonly string[]` to `OperationSpecMeta`. Overrode `OperationSpecRegistry.get()` to fall back to alias lookup on canonical-key miss. Direct matches retain precedence — aliases never shadow registered operations. 6 new tests in `operations/operation-aliases.test.ts` cover the regression baseline, alias resolution, version filtering, and the precedence rule. Full pre-existing test sweep across 1715 tests is zero-regression.
integrator
To soften a future namespace migration, list the legacy keys in `meta.aliases` on the new contract. Registry lookups by the legacy key will resolve to the new operation, letting downstream consumers migrate at their own pace. No changes required for operations that don't migrate.
contracts-spec-root-crypto-surface
Remove avoidable Node crypto imports from ContractSpec runtime surfaces and keep signing helpers isolated.
integrator
Browser and Next.js consumers can use workflow, telemetry, experiments, root, and broad control-plane surfaces without static Node crypto imports.
contractspec-form-operation-marketing-components
Form-like marketing/BillingOS UI renders through ContractSpec FormSpec/OperationSpec bindings as the primary path; bespoke design-system form/pricing control APIs are removed.
maintainer
contracts-spec adds marketing/billing FormSpecs (MarketingLeadCaptureFormSpec, MarketingEstimateInputFormSpec, BillingEstimateIntakeFormSpec) and side-effect-free operations (marketing.lead.capture, marketing.estimate.calculate, billing.estimate.prepare), plus formRef/hostExecutionBoundary on marketing presentation bindings. The validation issue code missing_presentation_operation_ref is renamed to missing_operation_ref_for_executable_binding, and missing_form_ref_for_form_primitive / invalid_host_execution_boundary are now emitted.
integrator
MarketingLeadCapture and MarketingPricingCalculator render form-like UI through the FormSpec renderer. MarketingPricingCalculator no longer accepts estimate/renderTotal/onEstimate and no longer computes pricing; callers pass formSpec plus a host/operation-owned total node. Hosts retain ownership of submission, pricing math, persistence, and provider execution.
customer
Security/safety boundary: no production provider, payment, CRM, PA, e-invoicing, or credentialed runtime path is added. Lead-capture declares PII metadata; estimate/billing queries are read-only and side-effect-free. BillingOS-adjacent estimate/quote vocabulary is fixture/example only.
contractspec-generative-core
Add experimental graph artifact contracts and read-only graph/drift CLI workflows.
maintainer
Maintainers get additive, subpath-scoped graph artifact schemas and registry schema parity for policy/capability/job/translation items.
customer
CLI users can inspect graph artifacts and run read-only drift checks with schema-versioned JSON output.
contractspec-i18n-diagnostics-cli
Expose reusable static translation diagnostics and add contractspec i18n check for CI-friendly catalog validation, including missing catalogs, missing keys, blank values, ICU syntax, placeholder parity, JSON output, and optional .contractsrc.json i18n defaults.
contractspec-i18n-runtime
Add a ContractSpec-native production-grade translation runtime and optional i18next adapter.
maintainer
Translation specs now keep stable bundle identity separate from locale variants while the runtime owns formatter-backed ICU resolution, fallback chains, overrides, diagnostics, async loading, SSR snapshots, and optional downstream i18next projection.
integrator
Integrators should use the production translation runtime for server, React, React Native, and CLI resolution, and use the i18next subpath only as a downstream adapter with caller-owned ICU formatting configuration.
customer
Multilingual surfaces can now rely on BCP 47 locale variants, ICU formatting, deterministic SSR snapshots, and safer migration away from locale-suffixed translation bundle keys.
core-operation-approval-enforcement
Add scoped operation approval enforcement across core, REST, and MCP runtimes.
maintainer
Operations can opt into fail-closed scoped approval enforcement before handlers run.
integrator
REST and MCP adapters can supply client-held approval receipts through common runtime context.
cross-platform-contracts-spec-navsurface
Extend NavSurface with optional mobileRoute field and MobileRouteSchema discriminated union to express mobile navigation shape in the same contract that drives web navigation.
maintainer
NavSurface now accepts an optional mobileRoute field. Existing contracts without mobileRoute are unaffected — the field is optional and defaults to undefined.
integrator
If you extend NavSurface definitions, you may now add mobileRoute to express Expo Router navigation shape. Mobile consumers resolve path from surface.mobileRoute.path.
data-fetching-ecosystem-reset
Collapse data fetching into one spec-first protocol + an in-house engine in the new contracts-runtime-core; remove the data-transmission packages; prove it end-to-end on entity-workspace.
maintainer
One canonical, I/O-free protocol lives in contracts-spec (QueryEnvelope, QueryResultEnvelope, createQueryKey, CacheStatus, InvalidationTag, ConflictPolicy, QueryConsistency, VersionToken, QueryState). The new contracts-runtime-core owns the in-house engine (Transport/reachability/storage ports, request dedup, durable offline queue + replay-on-reconnect, etag conflict detection + per-contract resolver registry, optimistic apply/rollback, auth-expiry pause/resume, GC, and PII-free observability) and the re-homed Collaboration* envelopes. data-transmission-spec and data-transmission-runtime are removed.
integrator
useContractQuery(envelope, opts) and useContractMutation(opts) bind to a DataEngine via ContractDataEngineProvider and return the canonical QueryState / mutation state with zero adapter into design-system components. REST and MCP are interchangeable Transport adapters carrying ContractResult<QueryResultEnvelope>; MCP decodes structuredContent first. provider-database.executeQuery emits a real versionToken on the proof entities; runtime-local feeds reachability into the engine via an input-port adapter. crdt-loro registers as the opt-in CRDT conflict resolver.
customer
Offline-capable reads and writes with explicit conflict resolution and recoverable auth-expiry (never a silent drop), surfaced through one consistent loading / stale / offline / conflict UI model.
data-table-overflow-policy
Add contract-driven overflow behavior and typed DataView hints for shared DataView and DataTable surfaces.
maintainer
DataView contracts, renderers, scaffolds, and docs now expose overflow hints and typed data hints end-to-end, from spec authoring through table rendering and generated starter files.
integrator
OSS consumers can specify `overflow` on DataView fields or table columns, while the CLI and workspace scaffolds emit the new shape and richer format/filter metadata.
customer
Published data-view docs now describe overflow behavior, expansion mode, and generated table defaults more concretely.
data-views-collection-readiness
Add production-ready collection defaults and renderer mode switching for DataView list, grid, and table specs.
maintainer
DataView collection specs now share view-mode, toolbar, pagination, and density defaults under view.collection.
integrator
DataViewRenderer can switch among allowed list, grid, and table projections while preserving existing specs and caller-controlled props.
customer
Generated data-view screens can expose modern list/grid/table switching, search, filters, pagination, and density controls.
data-views-personalization-integration
Add preference-aware DataView collection defaults and personalization adapters.
maintainer
DataView contracts now expose neutral data-depth and collection personalization hints while keeping contracts-spec independent from personalization runtime code.
integrator
Apps can resolve preferred DataView mode, density, and data depth through personalization helpers and pass plain props to web/native DataViewRenderer.
customer
Collection screens can remember or infer list/grid/table mode and compact/detail preferences without duplicating DataView specs.
database-mutation-docs-llms
Align database mutation docs, release-capsule guidance, and LLM-facing surfaces around governed domain-command writes.
maintainer
Release authors now have an explicit database mutation checklist covering contract/provider separation, domain-command authority, managed/BYOK posture, and LLM regeneration evidence.
integrator
Contracts-spec docs identify portable governed mutation descriptors while provider-database docs identify the adapter-owned SQL/Drizzle execution boundary.
customer
Database write guidance now emphasizes approved domain-command envelopes, idempotency, audit/replay evidence, and managed/BYOK production posture before adapters execute writes.
design-system-entity-surfaces
Advance contract-driven entity surface foundations, gates, and consumer docs.
integrator
Consumers get a documented, contract-first path for entity listing, search, filter, detail, and edit workflows using EntityWorkspace for product shells or DataViewRenderer for lower-level renderer composition.
maintainer
Maintainers get entity-workspace inventory, public API gate, native parity matrix, package export alignment, DataView registry regression coverage, and workspace form-output resolution tests.
agent
Agent-facing docs and prompts now explain how to implement entity surfaces without overclaiming the planned EntityWorkspace facade or hard-coupling DataViewSpec to FormSpec.
drizzle-postgresql-monorepo-leverage
Add portable database bindings and governed PostgreSQL provider leverage across ContractSpec core surfaces.
maintainer
Portable database contract metadata now threads through contracts-spec, RBAC, knowledge, data exchange, and provider-database without leaking adapter dependencies into runtime-agnostic libs.
integrator
Applications can describe governed database-backed views, lookups, policies, knowledge provenance, and SQL endpoints using portable metadata, then execute through provider adapters.
enterprise-agent-platform
Add provider-adaptable multiplayer agents, governed self-improvement, continuous workers, self-maintaining APIs, and fail-closed enterprise qualification.
integrator
Compose the exact agent capabilities and enterprise controls required by a project, then choose or replace Vercel, Railway, Supabase, Docker, and custom profiles according to infrastructure, budget, security, and residency constraints.
maintainer
Qualify the exact digest-bound plan in each target environment and run multiplayer, improvement, maintenance, audit, recovery, and rollback workflows with live evidence.
entity-bound-form-projections
Document entity-bound FormSpec projections, permissive intake debt, and the public guidance export.
maintainer
Maintainers have a stable package subpath and DocBlock for entity-first form projection, completion-debt, and intake-boundary guidance.
integrator
Integrators can distinguish permissive capture from strict readiness before wiring quick/full/message-intake forms into runtime or UI surfaces.
entity-workspace-row-card-rendering
Improve EntityWorkspace row/card rendering with configurable leading icons, top-right status fields, and per-field label visibility overrides, then adopt the shared contract in the Agent Fleet example.
maintainer
Maintainers can now express richer row/card layouts through the shared EntityWorkspace row-card contract instead of screen-specific rendering code.
integrator
Integrators can configure leading icons, top-right status fields, and per-field label visibility overrides on EntityWorkspace consumers.
customer
Command-center surfaces can keep the existing visual style while rendering richer, quieter row/cards with shared EntityWorkspace primitives.
forms-autocomplete-combobox
Improve FormSpec autocomplete rendering and resolver-backed search.
maintainer
FormSpec autocomplete docs now describe local and resolver-backed authoring without adding transport fields to the contract.
integrator
React FormSpec autocomplete resolvers receive query, dependency values, field name, and AbortSignal args while stale responses are ignored.
customer
Contract-rendered autocomplete fields now use an accessible editable combobox on web and show loading, empty, error, and selected states more reliably.
forms-email-field
Add first-class FormSpec email fields with native renderer affordances.
maintainer
Maintainers can declare single-address email inputs with `kind: "email"` while keeping validation in the form model.
integrator
Integrators get native email input attributes through the existing form renderer driver slots without adding an EmailInput slot.
customer
Contract-driven email fields now use email keyboards, autofill, and browser email input behavior by default.
forms-layout-input-groups
Add FormSpec layout hints, semantic field rendering, and portable text/textarea input-group addons.
maintainer
Maintainers can express richer FormSpec layout and field chrome without embedding renderer-specific UI.
integrator
Integrators can render contract forms with semantic legends, descriptions, errors, grid rows, colspans, and input addons through driver slots.
customer
Contract-driven forms can now present dense multi-column layouts and input adornments while preserving accessible field semantics.
forms-numeric-temporal-fields
Add numeric and temporal FormSpec field kinds with shared renderer support for number, percent, currency, and duration inputs.
maintainer
FormSpec contracts and examples can now declare numeric and temporal field-specific formatting metadata without bespoke renderer code.
integrator
Custom form drivers can implement `NumberField`, `PercentField`, `CurrencyField`, and `DurationField` slots, while older drivers fall back to standard inputs.
customer
Contract-driven forms can now express budgets, completion ratios, currency amounts, and durations with consistent metadata and shared rendering defaults.
forms-password-rendering
Add password-aware FormSpec rendering with current/new password manager hints and visibility toggles.
maintainer
Maintainers can declare current and new password fields as additive FormSpec text metadata.
integrator
Integrators can render password fields through an optional driver slot while older drivers fall back to masked inputs.
customer
Contract-driven password forms now mask values, expose a visibility toggle, and provide password-manager autocomplete hints.
forms-progressive-layout
Add progressive FormSpec section and step layout metadata with shared React and design-system rendering support.
maintainer
Maintainers can declare progressive form sections or steps as additive FormSpec layout metadata while keeping the field list canonical.
integrator
Integrators can render long contract-driven forms through shared section or step layouts without custom per-form wrappers.
customer
Long forms can now be split into scannable sections or progressive steps, improving completion ergonomics without changing submitted data.
formspec-layout-scoped-filters
Add mobile-safe FormSpec layout helpers and scoped DataView filters.
maintainer
Maintainers can add mobile-safe FormSpec layout metadata and first-class scoped filter contracts without breaking existing numeric layout semantics.
integrator
Integrators can reuse one DataView contract for generic and restricted list/search screens while locked filters stay out of user-editable URL state.
customer
Contract-driven forms can opt into mobile-safe layouts, and scoped listings now show non-removable locked filter chips by default.
graph-m5-ai-native-editing
M5 AI-native graph editing — graph.edit / graph.refactor / graph.compose / graph.suggest_evolution + AiPairPanel
maintainer
Adds four new LLM-backed graph editing tools (graph.edit, graph.refactor, graph.compose, graph.suggest_evolution), a conversation-scoped memory model (InMemoryAgentMemory, TTL 60 min, 50-turn cap), and an AI pair editing panel (AiPairPanel + AiTurnTimeline) for web and native. All 10 template files (5 templates × 2 role variants) extended with optional `aiPair?` prop — no breaking change, falls back to existing P7 behavior when omitted. New exports in @lssm-tech/lib.contracts-spec/agent/commands: graphEdit.command.ts, graphRefactor.command.ts, graphCompose.command.ts, graphSuggestEvolution.command.ts, graphConversation.ts (GraphConversation, AiTurnState) New exports in @lssm-tech/lib.ui-kit-web/ui/graph: GraphTemplateM5Layer, AiPairPanel, AiTurnTimeline, AiDiffPreview, GraphTemplateM5Props, AiPairPanelProps, AiTurnTimelineProps New exports in @lssm-tech/lib.ui-kit/ui/graph: AiPairPanel.native, AiTurnTimeline.native, AiDiffPreview.native
integrator
Add `aiPair?: AiPairPanelProps` to any of the five graph templates to enable the M5 AI pair editing surface. Pass `session`, `onSubmit`, `onUndo`, `onRedo`, `costUsed`, and `costCap` props. Omit entirely to keep existing M3/M4 P7 behavior unchanged. All four M5 LLM tools are available via @lssm-tech/lib.contracts-spec/agent/commands. They require human confirmation before applying mutations — `AiSuggestionConfirm` is rendered automatically when `aiPair` is wired. Provider: claude-sonnet-4-6 (default). Budget ceilings in .omc/state/m5-p0-decisions.md.
customer
Graph views now support an AI pair editing panel: describe what you want to change in natural language, review the AI's suggestion, and apply or discard it with a single click. Full conversation history with per-turn cost display and undo/redo support. Works on web and mobile (iOS/Android). All changes require your explicit confirmation.
graph-m5-stability-stable
Promote M5-shipped graph contracts from beta to stable.
maintainer
Stability promoted from `beta` to `stable` for all graph surfaces that shipped in M3/M4 and have now passed the full M5 quality gate (eval harness ≥95% JSON validity, ≥95% budget adherence, 100% mutation safety, designer review sign-off). Promoted symbols: AGENT_STABILITY = StabilityEnum.Stable (packages/libs/contracts-spec/src/agent/constants.ts) graph template files (5 templates × 2 variants, design-system) ui-kit-web graph primitives and template layers ui-kit native graph primitives No API surface changes — pure metadata promotion.
integrator
No breaking changes. All M3/M4 graph contracts (LayoutSpec, GraphFilterSpec, SavedView, Annotation, StorySlide, GraphExport, GraphAccessibilityProvider, the 4 graphOps tools, SSE GraphSubscription, Yjs MultiplayerTransport, all 5 graph templates × 2 variants) are now at stable stability. No migration required.
customer
Graph features (filters, saved views, annotations, layout, collaboration, AI tools, story mode, export) are now stable. These APIs will not have breaking changes without a major version bump and migration guide.
graph-timeline-primitives-milestone
Graph & timeline primitives milestone — new DataViewKinds, UI primitives, EntityRegistry, and 3 reference examples.
maintainer
Milestone landing: DataViewKind extended with graph/timeline/timeline-graph; DataViewGraphSpec discriminated union with 5 source types; entities module (EdgeSpec, defineContractEdge, defineContractEntity Layer1+2, EntityRegistry); shared ui-kit-core prop interfaces and hooks (useAdaptiveGraphRenderer with SVG/Canvas/WebGL threshold ladder); GraphCanvas/Timeline/ TimelineGraph SVG primitives in ui-kit-web; .native.tsx parity in ui-kit; DataViewGraph/Timeline/TimelineGraph design-system renderers; DataViewRenderer split into 13 focused modules; 3 reference example implementations. Zero breaking changes.
integrator
New graph and timeline DataView kinds are available. Import DataViewGraphSpec and DataViewGraphSource from @lssm-tech/lib.contracts-spec. Use GraphCanvas, Timeline, and TimelineGraph from @lssm-tech/lib.ui-kit-web (or .native.tsx from @lssm-tech/lib.ui-kit). Build entity graphs with defineContractEntity + EntityRegistry from contracts-spec. See example packages for inline-op, two-op, and entity-declarative reference patterns.
harness-browser-verification
Add OSS harness CLI verification with deterministic Playwright, optional agent-browser visual runs, auth profile refs, visual diff evidence, replay bundles, and core scenario success semantics.
maintainer
Harness scenarios now support typed browser actions, auth profile refs, visual-diff assertions, setup/reset hook execution, required evidence enforcement, success rules, and a shared CLI runtime used by both `contractspec harness eval` and `contractspec connect eval`.
integrator
Integrators can run OSS full-app verification locally or in CI with Playwright, agent-browser, or both, while writing replay bundles and browser evidence under `.contractspec/harness`.
customer
Browser, authenticated, and visual app flows can now be verified with replayable evidence before accepting provider or agent-generated work.
i18n-diagnostics-cli
Expose reusable static translation diagnostics and add contractspec i18n check for CI-friendly catalog validation, including missing catalogs, missing keys, blank values, ICU syntax, placeholder parity, JSON output, and optional .contractsrc.json i18n defaults.
i18n-readiness-diagnostic-dx
Add the report-only missing_translation static diagnostic to contracts-spec and an optional locale-override argument to the design-system useI18n hook for the en/fr/es readiness program.
maintainer
Translation diagnostics gain a missing_translation code (non-en value identical to en) emitted at info level (report-only), with checkMissingTranslation and missingTranslationAllowlist options. useI18n accepts an optional localeOverride for per-component locale resolution.
integrator
Surfaces can detect untranslated English stubs per catalog group (with a brand/code/cognate allowlist) without failing CI, and pass a per-component locale into useI18n to drive locale-correct value formatting.
integration-hub-uplift-phase-1-contracts
Ship integrations Wave A reads + Wave B mutations (21 contracts) with full operation-contract metadata bar.
integrator
8 Wave A read contracts and 13 Wave B mutation contracts are available in the integrations operations namespace and registered in `integrationsOperationPartial`. Handlers can now bind through the registry.
maintainer
Four security-class flows (`credentials.rotate`, `credentials.revoke`, `secrets.unlink`, `secrets.reveal_once_audit_only`) ship as `stability: beta` with `compatibility:breaking-allowed-this-plan` tags. All other contracts are additive.
m2-contracts-spec-v2
BREAKING: M2 contracts-spec — V1 workflow dual-shape adapter removed; DataViewGraphSpec, rich-reference, shared-entities, AgentTask V2 added.
maintainer
M2 adds three new modules and removes the V1 workflow dual-shape adapter. New: DataViewGraphSpec (sibling to DataViewSpec) with three DataViewGraphSource variants (inline-op, two-op, entity-declarative). New: shared-entities module — defineContractEntity, defineContractEdge, EntityRegistry, EntitySpec, EdgeSpec. New: rich-reference module — defineReferenceKind, RichReference<TPayload>, entity kind factory. Breaking: V1 WorkflowTask.id field removed (use taskId); V1 workflow runner dual-shape adapter removed (specs must use tasks[] + edges[] DAG shape).
integrator
BREAKING — if your workflow specs still use the V1 flat WorkflowTask shape (without tasks[] + edges[]), you must migrate to the M2 DAG shape before upgrading. BREAKING — any code reading WorkflowTask.id must change to WorkflowTask.taskId. New additive imports available: DataViewGraphSpec from data-views/graph-spec, defineReferenceKind from rich-reference, defineContractEntity from shared-entities.
customer
Graph data-views and workflow task trees now use a richer, more explicit structure. No direct customer-facing changes.
m3-contracts-spec-layout-spec
M3 — LayoutSpec discriminated union replaces GraphLayoutKind string enum; additive graph subscription, export, annotation, story-mode, and AI operation contracts.
maintainer
Replace all usages of GraphLayoutKind string literals with the LayoutSpec discriminated union. Use layoutKindToSpec() shim for incremental migration.
integrator
DataViewGraph spec consumers must update layout field from string to LayoutSpec object. Additive contracts (GraphSubscription, export, annotation, story-mode, AI ops) have no required migration.
managed-companyos-dynamic-intelligence-planning
Replace static Company Intelligence and OPA fixtures with authenticated, tenant-free dynamic surface descriptors and responsive managed templates.
integrator
Company Intelligence and Organization Planning pages now resolve authenticated authority per request and consume tenant-free server projections; no production route falls back to named-company fixtures.
maintainer
The additive surface descriptor accepts only a logical surface id and returns canonical route, route state, freshness, safe-read posture, action availability, and dependency blocks derived on the server.
managed-companyos-personal-team-contexts
Add non-shareable personal CompanyOS contexts and atomic opaque personal/company/team/workspace selection with request-time authority proof.
integrator
Authenticated users can operate in a personal context without a company and can atomically select any server-returned company, team, and workspace through opaque references.
maintainer
Context tokens bind session, user, projection, nonce, version, and expiry; explicit direct/team workspace grants constrain enumeration and selection, and protected requests fail closed when nested authority is stale.
managed-companyos-production-operation-v2
Add explicit v2 design-partner readiness, expert attestation, and founder approval contracts with server-derived authority, scoped durable receipts, pending evidence projection, replay linkage, and fail-closed health while preserving v1 unchanged. The release supports a private production-scoped pilot but does not activate a tenant or authorize broader production surfaces.
maintainer
The key-only CompanyOS registry remains pinned to the unchanged v1 operations. A new companyOsDesignPartnerOperationVersions registry exposes 1.0.0 and 2.0.0 side by side.
integrator
Adopt v2 when the API derives authority from verified server sessions and can commit durable business state, audit, command receipt, and evidence outbox intent atomically.
customer
Activate only one approved tenant/workspace and the invite/login, readiness, expert attestation, founder approval, and audit/evidence/replay journey. Keep GA, mobile, VPS worker, providers/outbound dispatch, real customer data, public SLA, and compliance claims deferred until separately approved.
marketing-contract-component-mapping
Introduce ContractSpec-first semantic marketing presentation primitives, serializable runtime descriptors, a design-system renderer registry, and Managed CompanyOS proof adoption.
integrator
Marketing presentation bindings now use semantic primitive IDs and optional render target hints. Consumers with arbitrary component-name primitives must migrate to the supported primitive IDs and required payload shapes before relying on descriptor normalization or the design-system renderer.
agent
Author marketing contracts semantically first. Keep React component names as render hints only, keep descriptor normalization serializable, and route product proof pages through the shared design-system renderer registry instead of bundle-local component assembly.
nav-surface-contract
Add navigation surface contract with role-aware registry and graph model.
maintainer
New navigation contract layer enables spec-first, role-aware navigation composition across apps and bundles with capability binding validation.
integrator
Bundles can now define navigation surfaces as NavSurfaceItemSpec entries, register them with NavRegistry, and resolve role-aware nav subsets via resolveForRoleMorph. Apps can render NavGraphSpec for power-user nav-map views.
customer
Applications support persona-based navigation with optional policy gates, density hints, and group-level hiding preferences.
nav-surface-mobile-extension
Add optional mobile-extension fields to NavSurfaceItemSpec for Expo Router native navigation.
maintainer
NavSurfaceItemSpec gains three optional additive fields: tabBarIcon? (string), gestureHint? (NativeGestureHint), and parentGroupKey? (NavGroupKey). No existing field is modified or removed. isNavSurfaceItemSpec type guard updated to validate new optional fields when present. NativeGestureHint exported from navigation index.
integrator
Native Expo Router shells can now read tabBarIcon, gestureHint, and parentGroupKey from NavSurfaceItemSpec entries to drive tab-vs-stack navigation hierarchy, per-screen gesture configuration, and platform-specific tab bar icons from the NavRegistry — without per-screen hard-coding in _layout.tsx. Web shells ignore absent optional fields.
customer
No user-visible change. Internal navigation contract gains mobile-native fields enabling contract-driven navigation in the CompanyOS and CommunicationOS mobile apps.
notification-library-shell
Move notifications to library-first contracts/runtime surfaces and add AppShell in-app notification affordances.
maintainer
Notification contracts now live in contracts-spec, reusable notification helpers live in lib.notification, and the old module remains as a compatibility shim.
integrator
Applications can adopt the new library imports without breaking existing module imports, then wire AppShell notification state through props.
ontology-company-work-graph
Align CompanyOS work, surface, adaptation, and safety authoring on canonical ontology graph refs.
maintainer
Contracts-spec owns the canonical ontology graph vocabulary while RoleMorph and personalization consume ontology refs instead of defining competing taxonomies.
integrator
Migrate CompanyOS graph, DataView, RoleMorph, adaptive-event, behavior-signal, and fine-tuning traces to ontology refs with fail-closed safety metadata for high-impact work orders.
customer
Autonomous Work Order traces can explain work, surfaces, personalization, approvals, audit, redaction, and training evidence through one governed graph.
ontology-public-surface
Document the intentional breaking ontology surface, Autonomous Work Order migration, safety invariant, and final release verification gate.
maintainer
Maintainers get one release packet for the ontology graph, Autonomous Work Order state machine, safety defaults, RoleMorph bridge, personalization bridge, and fine-tuning evidence gate.
integrator
Integrators must migrate high-impact graph mutations and adaptive operating surfaces to ontology refs and explicit safety evidence before treating work as committed.
agent
Agents get documented fail-closed defaults for Autonomous Work Order transitions and sanitized evidence-linked fine-tuning traces.
outcome-claims-contractspec
Add evidence-backed OutcomeClaim contracts, validators, and public exports to contracts-spec.
maintainer
ContractSpec now owns the domain-neutral OutcomeClaim kernel with portable refs, evidence, provenance, review state, correction history, factories, and validators. The invariant is no evidence, no claim.
integrator
Import OutcomeClaim helpers from @lssm-tech/lib.contracts-spec/outcome-claims. Runtime emission belongs in lib.ai-agent and business projections belong in CompanyOS; the kernel remains provider-neutral and persistence-free.
phone-number-field-support
Add first-class FormSpec phone input support with country detection, split outputs, and flag rendering.
maintainer
FormSpec phone contracts now expose input, output, country, and display configuration while keeping the schema-owned value model backward compatible.
integrator
Host renderers can set phone defaults through `createFormRenderer({ phone })`, while individual FormSpecs can choose object, E.164, or split linked outputs.
customer
Form-rendered phone fields can show country flags, detect countries from international input, and keep single or split controls synchronized.
pioneer-ai-self-improvement
Add vendor-neutral AI self-improvement contracts and a mock-first Pioneer adapter.
maintainer
Maintainers get a thin AI-improvement evidence/policy envelope, package-owned bridge helpers, Connect evidence, and a targeted Pioneer adapter boundary.
integrator
Integrators can connect AI-improvement routes, evidence, policy decisions, promotion gates, rollback, and Pioneer job receipts without taking a dependency on Pioneer-specific core types.
customer
AI improvement workflows are safer by default because vendor export, auto-apply, and learning are controlled by explicit gates and replay evidence.
pwa-update-management
Add PWA update management contracts and runtime helpers.
integrator
App developers can define PWA release policy once, override it per release, and consume a standard update-check API from the frontend.
maintainer
Maintainers get typed contracts, registry helpers, server evaluation helpers, and React prompt state helpers for PWA update workflows.
real-organizations-auth-recovery
Ship server-authoritative organization and workspace contracts with API/web recovery runtime, and separate authentication readiness from the legacy ND pilot-admission tuple without weakening legacy route admission.
integrator
Adopt organization.list, organization.set-active, and workspace.list as additive operations. Use organization.set-active authorityToken for stale-request rejection while retaining authorityVersion as a compatibility field. Continue treating existing tenantId fields as compatibility assertions only. The API and browser adapters now bind these operations with ambient credentials, explicit no-store transport, and canonical authority revalidation.
maintainer
Authentication readiness validates auth, database, origin, cookie, and secret prerequisites. Keep the pilot tuple configured for the legacy ND route until persisted organization authority replaces that admission guard. The public composition requires credentialed exact-trusted-origin authority refresh with a private no-store policy, plus one lazy app-owned authority runtime reused until host shutdown. Corrective v1 semantics preserve every distinct provider Set-Cookie, bypass caches for post-write canonical revalidation, recover through membership listing before selection, and atomically audit only actual active-organization transitions. The API, Node response adapter, browser transport, and web switching runtime implement these semantics; live production migration, bootstrap, deployment, and cutover remain separately gated.
real-organizations-bootstrap-recovery
Make the three-organization bootstrap resumable with durable phase receipts and truthful cross-connection interruption semantics.
integrator
Bootstrap receipts now expose the stable manifest revision, eight phases, and recovered phases as an additive CompanyOS contract.
maintainer
Operators can rerun the same manifest after interruption and must require all eight durable receipts plus three final bindings and grants before cutover.
real-organizations-canonical-seeding
Seed the canonical LSSM, CompanyOS, and NDconsulting organization families from one contract-owned manifest with deterministic replay and redacted evidence.
integrator
Adopt the additive organization-seed subpath for exact identities, families, digest versions, expected counts, and redacted receipt DTOs. The existing organization-bootstrap:v1 revision and receipt semantics remain unchanged.
maintainer
Run migrate, canonical bootstrap, one manifest-wide seed, and complete verification. Do not supply live tenant/workspace selectors or treat receipt presence alone as replay proof.
integrator
Public profile drafts may represent intentionally inactive event metadata with destination mode unavailable; active unavailable events fail validation. Approved hybrid destinations remain HTTPS/Calendly-only.
relationship-detail-rendering
Declare relationships on a DataView detail config and render related records inside EntityDetailPanel (web + native), reusing the per-field formatting/intelligent-action machinery.
maintainer
contracts-spec adds an additive DataViewSectionRelationship primitive (DataViewSections gains optional kind/relationship; fields relaxed to optional). design-system adds RelationshipSection/RelationSwitcher (web+native, no ARIA tablist roles) and an optional fieldActions prop on the shared DataViewList(.native) (default off; existing consumers byte-identical). WEB LIST ROW ELEMENT: rows with interactive descendants (fieldActions='auto' or a renderActions slot) are no longer a native <button> — to avoid nesting focusable controls they render as a plain clickable region plus a primary <button data-row-select> keyboard affordance, with actions as valid siblings; rows with no interactive descendants stay a native <button> (byte-identical). EntityWorkspace(web+native) and EntityDetailPanel/DataViewDetail forward optional relationData/getRelationData/onOpenRelated/dataViewRegistry props.
integrator
Authors declare relationships (cardinality, displayMode table/list/compact-list, inline fields or child specKey, limit, emptyState). Related records are host-supplied — embedded dataPath, a relationData map / getRelationData resolver, the RelationDataContext provider, or the new optional EntityWorkspace/EntityDetailPanel/DataViewDetail props (relationData, getRelationData, onOpenRelated, dataViewRegistry); the declared OpRef is executed by the host. Drill-in via onOpenRelated(relationKey, record); read-only when omitted. The design-system performs no I/O. NOTE for DataViewList consumers: rows that render per-field actions or a renderActions slot are now a clickable region with a [data-row-select] keyboard affordance instead of a wrapping <button> (no-actions rows are unchanged) — update any tests/selectors that assumed the row is always a <button>.
customer
Detail views can show related records (e.g. a client's addresses) inline, switch between relations or view all stacked, and open a related record — on web and mobile.
reviewready-app-submission-readiness-contracts
Add the ReviewReady app-submission-readiness contract and event surface to contracts-spec.
maintainer
contracts-spec now ships an app-submission-readiness domain with 27 typed operation contracts, 3 domain events, keyed operation/event registries, shared domain constants, and additive subpaths. Contracts are secret-ref-only and rule contracts require official source provenance.
integrator
Downstream runtime, module, and app lanes can resolve ReviewReady operations and events through appSubmissionReadinessOperationRegistry and appSubmissionReadinessEventRegistry instead of reaching into individual contract files.
customer
ReviewReady gains an explicit, auditable contract layer for mobile submission readiness that never stores raw credentials and traces rule guidance to official store sources.
reviewready-store-integrations
Add the ReviewReady provider capability registry and read-first App Store Connect / Google Play integration packages.
maintainer
contracts-spec adds an additive provider-capabilities subpath with a typed capability registry and lookup helper. Two new integration packages expose read-first, write-disabled App Store Connect and Google Play Android Publisher clients with deterministic mocks and secret-ref-only auth.
integrator
Downstream lanes can map provider results to canonical capability states via getProviderCapability, run audits with deterministic mock clients in CI, and only enable live store reads by supplying resolved secret refs. Fields the official APIs do not expose surface as manual-required, unsupported, or degraded capability results, never fake data.
customer
ReviewReady gains honest, source-cited store integrations that never store raw credentials and clearly mark which submission fields must be completed manually in the store console.
rich-code-diff-surfaces
Add governed rich code/diff surfaces with references, redaction, RoleMorph, and personalization support. Historical wave-0 entry; the legacy CodeBlock/DiffBlock/ObjectReferenceHandler surfaces are superseded by the rich-reference foundation (see `rich-reference-breaking-release`).
maintainer
Historical wave-0 introduction of `rich-content`, `CodeBlock`, `DiffBlock`, `surface-runtime/rolemorph`, and `personalization/rich-code-preferences`. Superseded by the rich-reference foundation (this is kept for release-history continuity).
rich-reference-expo-safe-detector
Replace Node crypto, create-hash, create-hmac, and global randomUUID usage outside apps with an internal Expo-safe crypto utility package.
integrator
Expo and browser-capable apps can import patched public surfaces without Metro resolving Node crypto, create-hash/create-hmac, cipher-base, or stream from hash, HMAC, UUID, cache-key, delegated-subject, or RichReference paths.
maintainer
Hashing, HMAC, and UUID generation now route through the zero-dependency @lssm-tech/lib.crypto-utils package; asynchronous Web Crypto signer paths remain explicit.
rich-reference-foundation
Canonical RichReference subpath + ReferenceRuntime (split) + canonical serializer + detector + reference.resolve/detail queries + REST/GraphQL/MCP adapter wirings + S-9 agent surface (markdown envelope, agent-export passthrough, MCP tool descriptors, delegated/agent subject modes).
maintainer
Schema-first `defineReferenceKind` API (required `sensitiveFields`), process-global `ReferenceKindRegistry`, HMAC-signed `DenialToken`, four governance ports, six built-in kinds, canonical serializer, server-side detector with idempotent SHA-256 cache, strict-passthrough `toAgentJson`, symmetric markdown envelope. No runtime side-effects on import.
integrator
Import `@lssm-tech/lib.contracts-spec/rich-reference` for the foundation, `@lssm-tech/integration.runtime/rich-reference/{wire-rest,wire-graphql,wire-mcp}` for composition roots, and `@lssm-tech/lib.authos-runtime/subject/{agent,delegated}` for subject modes.
role-adaptive-companyos-app-shell
Document the additive release posture and verification matrix for the contract-driven role-adaptive CompanyOS app shell.
maintainer
Maintainers get a lane-by-lane acceptance matrix for contract, resolver, personalization, UI, bundle, app, and release-evidence work.
integrator
Integrators can adopt the adaptive shell only after resolver invariants, import boundaries, and Managed CompanyOS proof evidence are attached.
customer
Managed CompanyOS shell adaptation remains evidence-backed, provider-neutral, and guarded by RoleMorph/personalization safety constraints.
roles-permissions-rbac-policy-system
Add a shared roles and permissions policy system across contracts, RBAC evaluation, AppShell adaptation, and personalization suppression.
maintainer
Contract authors can declare shared static policy requirements while RBAC providers evaluate static, dynamic, and hybrid workspace-scoped grants.
integrator
AppShell navigation and personalization adapters can consume runtime policy decisions without becoming enforcement authorities.
customer
Workspace applications can hide or disable unauthorized navigation and avoid promoting denied fields while server-side policy decisions remain authoritative.
special-ops-review-decide-weekly-approve-contracts
Add two additive Managed CompanyOS Special Ops operation contracts — specialOps.reviewCard.decide and specialOps.weeklyReport.approve — on the canonical production contracts surface to retroactively govern the already-shipped decideReviewCard and publishWeeklyReport handlers in api-application-monolith. The example special-ops-cockpit package stays a pure fixture demo.
maintainer
Two new defineCommand contracts live under packages/libs/contracts-spec/src/companyos/commands (reviewCardDecide.command.ts, weeklyReportApprove.command.ts), exported via the commands barrel and registered in companyOsOperationRegistry under keys specialOps.reviewCard.decide and specialOps.weeklyReport.approve. Each carries a same-file DocBlock (kind reference, visibility internal) linked via meta.docId and declares sideEffects.audit for the intended managed_companyos_audit_events emission.
integrator
The change is additive — new operation keys only; no existing contract, registry key, or schema changes. Special Ops handlers in api-application-monolith are now governed by production contracts. The example package (packages/examples/special-ops-cockpit) remains an unchanged, network/DB-free fixture demo.
theme-radius-design-system
Add the public ContractSpec editorial radius scale and semantic aliases across contracts, design-system Tailwind bridges, app CSS parity, and bounded preview/toast migrations.
maintainer
Maintainers can rely on a documented radius taxonomy with parity tests across contracts, app CSS, and the design-system bridge.
integrator
Integrators receive additive `--radius-*` and `--ds-radius-*` aliases without losing existing `default`, `--radius`, or `sm/md/lg/xl/full` support.
theme-tailwind-bridge
Add ThemeSpec light/dark modes and a design-system Tailwind bridge for CSS variables, presets, CSS text, and OKLCH color pass-through.
maintainer
Maintainers can keep ThemeSpec as the source of truth while exposing Tailwind variables and runtime theme modes from the design-system package.
integrator
Integrators can resolve ThemeSpec tokens for light or dark mode, consume a Tailwind preset, or serialize CSS text without adding a required generation step.
customer
Product surfaces can use ThemeSpec-backed light/dark themes with OKLCH colors while keeping existing Tailwind semantic classes such as `bg-primary` and `text-foreground`.
translation-catalog-sharding-ssr-additive
Add factory-stack SSR snapshot/hydration, loader shard scoping, RouteShardManifest, and parity diagnostics extensions for translation catalog sharding + SSR.
maintainer
BREAKING: createTranslationRuntime engine deleted from translation-runtime (subpaths ./runtime, ./registry, ./runtime-helpers removed; preference-override-layer construction dropped). createRuntimeTranslationResolver removed from design-system. Factory stack gains snapshot/hydration/load surface (I18nFactorySnapshot, I18nFactoryHydrationPayload, createI18nFactoryFromHydrationPayload, collectLocaleScopedCatalogs, resolveLocaleWithin). Parity diagnostics gain unsupported_locale_claim, manifest_spec_key_missing, validateManifestCatalogDrift, ManifestRouteEntry. Loader gains specKeys?, computeShardDelta, loadShardDelta. RouteShardManifest + defineRouteShardManifest authored in app layer. resolveTranslationPreferenceContext (context/precedence resolution) is preserved.
integrator
BREAKING: remove all createTranslationRuntime call sites; migrate to createI18nFactory + hydrationPayload() + createI18nFactoryFromHydrationPayload for SSR. Replace createRuntimeTranslationResolver with createTranslationResolver in design-system. Use loadShardDelta for route-level lazy loading. Use validateManifestCatalogDrift to catch manifest↔catalog drift in CI. RouteShardManifest defines route→specKey tier bindings in the app/bundle layer. Preference-override-layer construction has no replacement; drop it.
customer
Translation shards are now scoped per route for faster initial loads and incremental navigation fetches with no hydration mismatch.
typed-result-system
Add a canonical typed result system for ContractSpec success and failure propagation across operations, workflows, jobs, server adapters, MCP, GraphQL, and React clients.
maintainer
Maintainers can declare operation, workflow, and job result catalogs and have runtime registries enforce custom success and failure outcomes.
integrator
Integrators get consistent result mapping for REST, NextResponse, Nest-compatible filters/interceptors, GraphQL extensions, MCP tool errors, and React client parsing.
customer
Product surfaces can rely on consistent success metadata, retry hints, field issues, and Problem Details-style errors across API, job, workflow, and frontend boundaries.
unified-contractspec-database-runtime
Unified ContractSpec database runtime: createDatabaseRuntime() preset (pooling, zero-config observability, RLS tenant scoping, AuthOS principal carriage, governed resolvers) plus a typed N+1-safe relational read path, a spec-first generated Drizzle schema, and an SSR prefetch→hydrate bridge. Fully additive.
maintainer
New server-only runtime-managed/database subpath exports createDatabaseRuntime returning { provider (tenant-scoped), governedQuery, governedMutation, withTenant, close }. provider-database gains governed-relational-read (LEFT JOIN LATERAL + json_agg), governed-sql-guards, typed-read, and a generated Drizzle schema + manifest. contracts-spec adds database.query.relational@1.0.0, defineDatabaseTable + databaseTables, and database.query/database.mutation SignalSpecs; QueryState.pageInfo + CacheEntry.pageInfo are additive. providers-impls deprecates the raw createDatabaseProvider hatch (guard test added). database.query.readonly@2.0.0 and governed-read.ts are behaviorally unchanged.
integrator
Adopt createDatabaseRuntime() from @lssm-tech/integration.runtime-managed/database (server-only) for pooled, observability-bound, tenant-scoped data access with pre-bound governed resolvers. Use withTenant(tenantId) on known-tenant server paths (the top-level provider fails closed without a tenant). For SSR, prefetchGovernedQuery → dehydrateGovernedQuery → HydrationBoundary from @lssm-tech/lib.presentation-runtime-next/data, building the client engine over the same CacheStore via createDataEngine({ localOffline: 'offline-capable' }). useContractQuery now exposes hasNextPage + fetchNextPage() (cursor default; offset unchanged).
customer
Database-backed pages load faster: server-prefetched reads hydrate on the client with no second fetch, lists paginate by cursor, and every query is automatically tenant-isolated and observable.
unified-query-stack-cursor-read
Add the first unified query stack across contracts, runtime client cache boundaries, governed provider reads, and EntityWorkspace local-vs-remote query ownership.
maintainer
Maintainers get a canonical contract-owned query envelope and DataView cursor descriptor that package surfaces can share instead of reimplementing search, filter, sort, pagination, and offline policy shapes.
integrator
Integrators can execute governed cursor reads through provider-database while using runtime client cache helpers without binding public APIs to TanStack implementation types.
customer
EntityWorkspace hosts can opt into remote query ownership so server-filtered results are not double-filtered locally on web or native.
versioning-release-system
Add versioning-backed release capsules, generated patch notes, and guided upgrade flows.
maintainer
Release communication is now generated from versioning-backed release capsules and enforced on release branches.
integrator
Guided upgrade plans and agent prompts now come from generated upgrade manifests instead of ad hoc prose.
customer
Web changelog consumers can prefer generated release manifests while older package changelogs remain supported as fallback.
