Skip to content

Current RIGOR Progress

Status: Active current projection Updated: 2026-08-28

In plain language: the Agent-first software platform and simulated laboratory are implemented and requalified for the current software release. Bounded recovery, duration-unbounded execution status polling, explicit fail-closed Operation verification, scoped object storage, backup/restore, Agent profile quality, deliberate failure cases, browser journeys, and a one-hour simulated soak have passed. Production deployment remains a separate external-evidence gate: the target still needs institution identity, PostgreSQL selection, redundant object storage, and independent monitored backup. Physical-device integration and qualification are outside the current product scope and do not appear in the current release gate or delivery order. The PRISM reviewable-analysis slice is implemented: automatically captured analysis events and structured decisions now produce a scientist-facing Story, interactive Graph, and Timeline without exposing or inventing hidden reasoning.

Progress Scope

The main product design governs accepted behavior. This page is the concise current projection of implementation, qualification, open operational gates, and delivery order. Detailed completed-iteration evidence is frozen in:

The Completed Designs index preserves historical acceptance denominators; they are not current roadmaps.

Current Status

ScopeCurrent state
Agent-first Phase A/P0Software contract gate complete
Agent-first Phase B/CRuntime, frontend-contract, durable-job, and four-unit deployment convergence complete
Agent-first Phase D/P210 of 12 historical gates pass; physical-device qualification is outside the current scope, while production deployment remains the active external-evidence gate
Agent architecture Phase EOrdered PlanRevision, Specialist lineage, executable profiles, Composer model-path migration, and live profile quality gate complete
CoN4Cl benchmark Phase F/P0Software implementation and live-stack benchmark qualified; physical furnace execution is outside the current scope
Maintainability Phase G/P1Baseline implemented and qualified
Agent-native virtual labPhases 0-3 and truthful browser Showcase Mode complete; physical substitution is outside the current scope
PRISM analysis decision reviewImplemented: stable Skill Tool references, grouped immutable gaps, conclusion-first Evidence summary/Story, scientific Graph with advanced runtime layer, grouped Timeline, independent status indicators, accessible mobile review, legacy degradation, and immutable review actions
Knowledge-driven process adaptationImplemented: Composer reads complete Process Skill knowledge and a hash-addressed LabBridge device/material snapshot, may generate a semantic Procedure without a Workflow-pool dependency, validates material substitutions plus process/device range intersections and concrete inputs, freezes lineage into PACE, and automatically recomposes through ASCEND when the resource snapshot is stale
Creator ModeOwner-aware slice implemented: ASCEND accepts public GitHub sources or bounded archives in a dedicated Creator sandbox, validates a source-bound Extension Plan, installs Composer Skills and Workflows separately through Composer, and retains PRISM/Scientist owner validation; immutable unverified process proposals can enter Composer local compilation with hash provenance; inventory, version update, rollback UI, LabBridge integration installation, and private-repository support remain later scope
Experiment-owned history lifecycleImplemented: Experiment is the normal management root; cross-service manifests expose logical/object locations; deletion stops active work, uses a separately scoped object-purge identity to remove owner data in dependency order, and removes the ASCEND root last; unassigned legacy records remain explicit for governed engineering reconciliation
Device Access Point editingImplemented: each fixed device may define separate device-relative work positions for multiple mobile units and declare delivery, operation, and pickup roles; selecting equipment shows its configured positions and occupied/safety envelopes, while private navigation targets remain derived and revision qualification blocks invalid starts, positions, or connectivity
Lab and layout interactionImplemented: ASCEND follows Observe -> Inspect -> Act from one typed LabSituation projection; LabBridge makes the 2D canvas the sole placed-object manager, unifies fixed and movable equipment behind one marked add/select/move/remove interaction, anchors applicable device actions beside the selected marker, continuously qualifies the autosaved LayoutDraft, and creates and activates an immutable revision only through a ready Review & use
Current release requalificationSelected software tree passed static, contract, module, Web, recovery, browser, Agent, storage, backup/restore, failure-injection, and one-hour soak gates

The pre-PRISM Golden Loop and PACE-PRISM-ASCEND P0 software paths are complete against their retained historical acceptance criteria. Production readiness is still an active gate. Physical qualification is outside the current product scope and is not inferred from simulated or software-only success.

Current Foundations

  • ASCEND is the normal researcher surface and owns goals, policy, Coordinations, immutable Iterations, Attention, decisions, and current plan recovery.
  • ASCEND Experiments is the normal data-management surface. Each Experiment can show its cross-service record manifest and logical/object locations. Deletion is a durable owner-confirmed purge: active work stops first, external owners remove metadata and owned data, and ASCEND keeps the Experiment root whenever an owner fails. Session sandbox reclamation is asynchronous and bounded; owner failures are isolated and circuit-broken by failure domain; partial cleanup exposes typed, localized recovery guidance with affected counts. Module-level cleanup remains an engineering-only migration and repair surface for explicitly unassigned legacy records.
  • ASCEND automatically projects each committed round into a fixed Goal → Plan → Rehearsal → Execution → Operations → Evidence → Analysis → Conclusion source chain. Evidence shows completeness, authority, verification, explicit gaps, and an optional bounded Agent explanation; Agent failure cannot alter or hide the deterministic chain. Experiment and Round views expose compact status, while raw Trace remains an advanced engineering view.
  • ASCEND persists internal Coordination stage deadlines and recovery budgets. Disabled routine automation creates typed Attention only when that automation is expected; rehearsal-only work is excluded. Attention delivery rechecks the latest iteration and cannot restore an older Working state over a newer blocked or terminal result; superseded liveness prompts expire automatically. An expired internal stage receives one bounded recovery attempt by default before typed retry/stop Attention. EXECUTING has no elapsed-duration deadline: ASCEND keeps reading the authoritative PACE projection, and a recognized active status may remain Working for hours or days. Status-read failures retry only the read for a five-minute communication grace period by default, then create typed retry/stop Attention without repeating a device action.
  • Composer owns bounded planning, full Process Skill knowledge, material and capability adaptation, optional Workflow-fragment reuse, dynamic semantic Procedure generation, deterministic validation, and immutable RunSpec/package construction.
  • PACE owns immutable execution input, loop orchestration, result extraction, evidence archives, diagnostics, and delivery to PRISM.
  • LabFlow owns Procedure/workflow validation, scheduling, durable waits, locks, cancellation, and run export.
  • LabBridge owns semantic capabilities, device/material resource facts, hash-addressed planning snapshots, Operations, controllers, Human Tasks, artifacts, spatial state, virtual environments, and device fault boundaries.
  • LabBridge map revisions treat explicit device-relative Access Points as user-owned, role-aware robot destinations. A fixed device may have separate delivery/operation/pickup positions for multiple mobile units. Mobile units declare collision geometry and clearance; revision-only validation starts support pre-activation connectivity checks without becoming live positions. Drafts may be saved for review, but activation recalculates typed bounds, collision, Access Point, validation-start, and connectivity checks and fails closed on any hard blocker; runtime path planning starts from the controller-frozen pose and remains internal.
  • Rehearsal is a mandatory automatic gate for every side-effecting experimental LabBridge capability input. ASCEND creates and revalidates exact immutable lineage, PACE rejects a formal experiment without it, LabFlow carries it in a signed workflow context, and LabBridge rejects missing, stale, mismatched, or uncovered inputs. Read-only and cancel/stop/safe-stop safety paths remain available without the gate.
  • LabBridge projects missing terminal verification as unverified; accepted Human Task confirmation and observed controller evidence declare verification explicitly. PACE rejects unverified physical evidence.
  • PRISM owns isolated evidence analysis, Analysis Skills, committed structured results, archives, and callbacks.
  • PRISM preserves objective Agent and Tool activity, requires typed decision checkpoints in the result contract, permits one bounded non-fabricating repair, and deterministically commits a decision graph with stable Skill Tool refs. ASCEND shows a conclusion-first summary/Story, scientific Graph, and grouped Timeline. Repeated missing links are grouped but retained as immutable gaps; historical runs degrade to legacy trace only. Researcher review, questions, and clarification requests append ASCEND-owned records without modifying the PRISM result.
  • The normal deployment surface is Control, Execution, LabBridge, and Analysis Worker; deployments/topology.json is the topology fact source. Supervisor is runtime infrastructure, not a seventh domain or fifth domain unit. The Docs Web service is also required default infrastructure and remains outside domain authority.
  • Shared Agent, job, RunSpec, schema, sandbox, object-store, UI-contract, and lab map packages provide reusable mechanics without absorbing domain authority.

Recently Completed

  • The first Creator Mode slice adds an explicit ASCEND conversation mode, archive upload and public GitHub preparation, a dedicated versioned profile with a request-scoped Tool allowlist, and a separate session sandbox. A source-bound Extension Plan now classifies components by semantic consumer, side effect, evidence authority, owner, and readiness; MCP transport itself does not decide ownership. Composer process Skills and executable Workflows install through separate owner APIs, while Analysis Skills enter PRISM only through its validator. ASCEND additionally owns atomic Scientist Skill + HTTPS MCP packs with exact Tool allowlists, handshake-before-commit, dynamic next-turn admission, and failed-activation rollback. Immutable, explicitly unverified scientific-process proposals can be selected for an iteration; Composer requires the companion Skill, checks the content hash, preserves provenance, and resolves local Capability/SOP gaps rather than treating a proposal as executable. Invalid, conflicting, or unsafe content leaves no partial install.
  • Repository validation now has deterministic quick and deep tiers selected from the actual Git diff. Quick runs mapped static, domain, and focused browser checks; deep adds full suites only for impacted modules. Unmapped production source fails closed, while process recovery, storage, fault-injection, soak, production, and physical qualification remain separate explicit gates.
  • ASCEND now scopes caller-provided PlanRevision intent labels to their immutable revision identity, allowing curated presets to be replayed without mutating or colliding with earlier plan history.
  • LabBridge map revisions now bind geometry, equipment placements, navigation parameters, and multi-mobile, role-aware device-relative Access Points to one immutable version. Editing reconstructs only that version, so active-map coordinates cannot leak into a draft. Only Access Points are user-authored map targets; service faces, ports and localization semantics belong to DeviceModel/controller definitions, and any station-like ID materialized for a frozen navigation contract remains private. No observe, edit, replay, or Docs renderer exposes a station marker.
  • Layout qualification exposes stable checks and object-addressed issues for map schema/bounds, fixed-equipment clearance, revision-only mobile validation starts, Access Point local clearance, and assigned-mobile connectivity. Users may keep an incomplete draft, but Review & use is disabled and the activation API returns the same typed qualification until all hard blockers are resolved. Device-owned targets and paths are private projections, and the server never silently moves an explicitly chosen Access Point. ExecutionSnapshots continue to freeze the resolved scene. Map deletion still distinguishes governed evidence from closed, ownerless pre-lineage rehearsal chains; owned or active records remain protected.
  • Layout editing now separates mutable authoring from immutable runtime history and gives each control one role. Add to layout contains unplaced fixed and visibly marked movable equipment plus occupied footprint, restricted zone, and wall. Selecting placed equipment opens an anchored action bubble for applicable move, remove, mobile assignment, and robot work-point actions; the adjacent Selected equipment panel remains informational. View and edit modes now share a stable left-map/right-context layout: Device sits above Layout history in view mode, while Selected equipment, Add and Map setup use the same right rail in edit mode. Read-only selection updates that rail instead of opening an in-map device inspector or persistent label. Spatial objects use a non-obscuring context bar; walls are visible/selectable in 2D and 3D, removable from their shared context, and use 2D whole-wall or endpoint dragging for precise geometry. The workspace LayoutDraft autosaves with optimistic revision control and stays continuously qualified. Review & use rechecks readiness, atomically publishes and activates one immutable MapRevision, and discards the draft; incomplete drafts remain editable.
  • ASCEND Lab now derives its normal researcher surface from one typed situation projection rather than joining capability and spatial snapshots in the browser. It distinguishes reachability, operational state, report age, map relevance, and simulated/physical authority; only explicitly spatial devices can be reported as missing. Current work and exceptions precede inventory, selection is shared by map and device rail, Take over is a governed contextual dialog that tracks submitted Operations automatically, and demo video is labelled before it opens. Engineering revision IDs, derived Access objects, and layout geometry are absent from the default Observe view. Contextual layout/device maintenance opens the same full Console workspace and service rail as the global Console control.
  • The shared 2D renderer now provides bounded pan, zoom, reset, mouse and touch gestures without owning business state. All editing and drop coordinates are converted through the transformed surface, while controls retain accessible targets and the mobile view no longer sits under fixed navigation.
  • ASCEND conversations now keep one stable, accessible live-reply surface from queueing through final commit. Typed backend phases, safe Tool status, truthful waiting/elapsed time, visible typed model and whole-turn retry recovery, backend-provided stop availability, durable partial Markdown, SSE final runtime metadata, reconnect/poll fallback, responsive layout, and reduced-motion behavior replace the former generic pending placeholder. The durable chat worker now survives queue-database contention with bounded backoff, reconciles terminal or removed turns before execution, and exposes worker liveness plus bounded queue age through ASCEND health; queued UI copy states that the reply has not started instead of implying model work. Partial text remains explicitly uncommitted until the durable terminal turn is written; refresh and reconnect recover the latest persisted revision without exposing hidden model reasoning or raw Tool payloads. While a reply is queued or running, the normal Send control becomes a backend-authorized Stop control; stopping affects only that reply. Closing or refreshing the browser does not own or cancel the worker task.
  • ASCEND Scientist now has one versioned materials-design Skill backed by a configured Streamable HTTP MCP client. The external server is restricted to its eight database selection, inspection, filtering, counting, plotting, candidate-design, and process-design tools. Dataset/design lineage stays immutable and internal; proposed candidates and process routes remain explicitly unverified. These MCP tools are optional at the task boundary, so temporary server unavailability does not break unrelated Scientist turns.
  • Shared Agent context governance now distinguishes active model context from cumulative per-segment task spend. Oversized Tool output remains bounded or referenced, task-budget boundaries stop before new side effects, and a typed checkpoint records observable progress without hidden reasoning. Active Goals continue automatically across bounded segments; ordinary ASCEND conversations show saved task/context usage and a one-click Continue task action.
  • PRISM analysis review now connects committed evidence to concise scientific questions, findings, limitations, decisions, and conclusions. Runtime events, Tool calls/results, artifacts, and validation are captured automatically; deterministic checks reject dangling support references and expose omissions or Tool failures. The ASCEND Evidence page opens Story, interactive Graph, and Timeline views from the Provenance Analysis stage on desktop and mobile, with independent completeness, validation, gap, and researcher-review states.
  • The shared Podman sandbox baseline now uses an immutable root filesystem, drops all Linux capabilities, enables no-new-privileges, and supplies bounded writable cache/tmpfs mounts. ASCEND, Composer, and PRISM add managed owner/session/policy labels and enforce the centrally configured free-space reserve before creating a sandbox. Supervisor reconciles only stale terminal labeled containers, audits material cleanup, exposes maintenance health to Controller, and presents storage pressure in all three UI languages. Shell compatibility telemetry records executable name and missing-command outcome without command arguments or environment values.
  • ASCEND Attention now distinguishes human work from transport recovery. Needs you contains only actionable decisions and live Human Tasks; exhausted delivery moves to a separate Problem surface with an exact persisted-decision retry. Home compact views group related requests without turning independent approvals into one batch decision. Producer 404/terminal LabFlow runs and deleted Coordination lineage expire their mirrored cards automatically. LabFlow tests now inject an explicit dispatch-disabled configuration instead of reading the live generated projection, and Planner qualification no longer fabricates ASCEND lineage, preventing test approvals from entering the live Inbox.
  • ASCEND Home and experiment records now project the durable experiment start time and the first terminal end time; later archive or maintenance updates do not rewrite the displayed lifecycle interval.
  • ASCEND decision automation now treats an Agent runtime error or a missing required proposal as a failed AgentRun rather than successful empty output. It consumes the configured bounded recovery budget immediately, then raises a typed Attention that names timeout, run-limit, configuration, or missing- decision causes while preserving completed execution, analysis, and evidence.
  • Mandatory Rehearsal is implemented as an ASCEND-orchestrated, LabBridge-enforced first-class subsystem rather than a Composer feature or a seventh module. Composer-package, direct atomic, ordered PlanRevision, and promoted RunSpec paths now persist and propagate selected branch, plan, and ExecutionSnapshot lineage; retry/start cannot silently drop it. PACE and signed LabFlow transport fail closed, LabBridge validates the exact capability input against the completed branch and current capability catalog, and migration v18 preserves direct-action lineage. The normal UI remains on Working and gains no manual Rehearse/Promote lifecycle button.
  • Controller now uses an exception-first responsive operations layout: module work opens through ASCEND, service recovery lives in a contextual drawer, whole-stack actions require a secondary confirmed flow, and central YAML is collapsed behind its health summary. Its full surface supports English, Simplified Chinese, and Spanish. ASCEND now exposes the configured Docs URL in primary navigation and a Settings shortcut immediately after Console; all Controller links use the configured public URL and module deep links.
  • Runtime configuration is centralized in ignored config/sdlx.yaml and config/secrets.yaml. Existing module values and keys were migrated without blanking; six modules, Supervisor, Docs, local MinIO/EMQX, backup, and credential rotation consume generated projections instead of business-setting environment variables. RIGOR Control provides redacted view, validation, change impact, revisioned apply, and rollback; startup rejects invalid or drifting configuration before launching services.
  • Bundled MinIO clients now fail configuration validation when LabBridge, PACE, or PRISM drift from their provisioned bucket or scoped identity, and a PACE MinIO delivery requires a matching PRISM reader configuration. This prevents late artifact-upload 403 failures and unreadable S3 deliveries.
  • ASCEND now opens configured Engineering Consoles in one responsive workspace. A fixed desktop rail or mobile bottom rail switches Composer, PACE, LabFlow, LabBridge, and PRISM without discarding visited iframe state. Service status and contextual deep-link state such as the LabBridge map editor are preserved; remains visible, while start/stop/restart stay progressively disclosed in the selected module's service-management panel and continue to use Supervisor capability flags and explicit confirmation. While embedded, this rail is the single module-runtime status surface: module headers suppress duplicate online/upstream indicators, Composer no longer repeats the selected Tab's title and explanation, and developer or physical-maintenance actions are removed from the everyday top bar while remaining available in standalone diagnostics or Settings where appropriate.
  • The Docs home page now presents a read-only 2D/3D laboratory view using the shared map renderer. ASCEND owns the sdlx.lab-showcase/v1 selection and truth labels: it chooses the newest eligible committed execution or rehearsal by recorded time and falls back to current layout. Rehearsal uses recorded events and collision-checked paths; formal execution without historical motion is shown only against current layout context. Docs cannot issue actions or upgrade evidence authority.
  • ASCEND now provides an allowlisted MCP transport gateway. Standard clients use /mcp/<module> with Streamable HTTP; Xiaozhi-compatible clients use /xiaozhi/mcp/<module> with WebSocket. The first registered owner is LabBridge, whose tool, policy, Operation, audit, and evidence authority stays unchanged. Client credentials are consumed at ASCEND rather than forwarded, upstream service credentials remain separate, and both transports fail closed when no trusted identity boundary or access token is configured. LabBridge artifact downloads now use a stable ASCEND route; current API, Human Task, trace, and MCP projections derive that route from immutable artifact ids without rewriting historical evidence rows.
  • Agent-native virtual-lab rehearsal, branching, findings, Plan revision, comparison, promotion, scene projection, shared 2D/3D rendering, deterministic action replay, and the multi-device 3D showcase are implemented through Phase 3. Showcase Mode now adds automatic replay/camera direction, bounded Agent activity and handoff/evidence effects, while typed SimFleet navigation exposes current/target station, registered approach, controller-owned route, and motion progress for continuous mobile-unit display. Showcase Workflow v3 visits the balance, electron microscope, and XPS device approaches, then returns the mobile manipulator to staging. Execution snapshots freeze the selected map and mobile starting state so historical replay does not drift. Rehearsal now resolves semantic equipment targets against its frozen snapshot before creating a branch. The resulting immutable PlanRevision records the user-assigned mobile unit, private device-work station, exact target pose and deterministic path; missing work positions, incompatible assignments and all route blockers return together with map-edit guidance. The planner uses clearance-weighted directional A*, turn costs, collision-checked line-of-sight simplification and smoothing, while preserving safe narrow passages and final work-position orientation. Frozen poses of other mobile units remain collision bodies; live traffic avoidance remains controller-owned. The v2 curated materials rehearsal_only preset no longer embeds legacy station, approach or route ids. It runs ASCEND -> LabBridge directly, disables promotion, marks Composer/PACE/LabFlow/PRISM as skipped, and retains predicted authority. Existing replay without a recorded path remains stationary. These presentation effects remain read-only; rehearsal output remains predicted and cannot become committed evidence.
  • CoN4Cl XPS control-matrix intake, factorial guardrails, evidence-bound Skills, prospective design Iteration, and physical-device compatibility filtering are implemented and live-stack qualified.
  • Governed Stop Experiments and Reset Devices supports one resolved impact decision, cancellation barrier, per-device automatic or Human Task reset, idempotency, verification-aware aggregate results, and a hard no-resume boundary.
  • ASCEND primary journeys, durable background jobs, shared runtime profiles, generated contracts, versioned storage migration mechanics, immutable object storage software paths, and four-unit topology checks are in place.
  • Documentation is classified by lifecycle: current authority stays at stable root paths; completed PRDs and investigations are archived; ADRs and release records are retained; illustration prompts are explicitly non-normative.
  • AI-assisted development guidance now has repository, domain, infrastructure, shared-package, firmware, and documentation scopes with automated drift and size gates. The main PRD, Composer planning implementation, PACE and LabBridge UI entry components, shared lab-map renderer, and the three largest active style sheets were split into focused maintained units.

Qualification Summary

The detailed 2026-08-03 snapshot records the exact module, contract, cross-process, browser, localization, build, migration, recovery, and virtual-lab checks run for this baseline. The maintainability release record contains the pinned quality gates and architecture-boundary evidence.

The frozen software baseline evidence includes:

  • module contract and API suites across all six domains;
  • PACE -> PRISM -> ASCEND real-process delivery and replay;
  • PACE incident decision round trips and live process restart recovery;
  • ASCEND desktop/mobile primary journeys and virtual-lab 2D/3D parity;
  • generated OpenAPI/client drift, public-schema compatibility, migration, topology, architecture import, and Engineering Console diagnostic-budget gates;
  • deterministic checked-in Web build manifests;
  • immutable object-write/checksum behavior behind the shared object-store contract.

The current dated evidence additionally covers scoped MinIO identities and retention, online backup/restore, PostgreSQL native restore mechanics, Agent profile quality, deliberate process/Agent/storage failures, and a one-hour software/SimFleet soak. See the 2026-08-06 software qualification. It does not qualify external identity, online PostgreSQL selection, redundant storage, or off-host backup. It makes no physical instrument/device claim.

Every later integration must repeat the exact static, generated-contract, deterministic Web, module, recovery, and browser gates against its selected clean release tree; it cannot inherit this dated result automatically.

Active Gates

  • Select PostgreSQL as the target deployment's online system of record and run its migration/restore evidence against that deployment.
  • Move immutable storage from the single-volume local fixture to redundant managed S3/MinIO and place verified backups on independent monitored storage.
  • Integrate trusted proxy headers with the institution identity provider and organization account lifecycle; the public deployment must not remain in disabled-auth mode for a production claim.
  • Add a shared ASCEND event fan-out transport only when horizontal API scaling is introduced.
  • Continue reducing the 23 explicitly budgeted legacy source/test hotspots. Their checked-in line budgets may decrease but cannot grow; new maintained files must remain within the default documentation, source, entry-component, and test limits.

Out-of-Scope Physical Work

Real instruments, robots, mobile platforms, firmware delivery, physical-effect verification, controller calibration, and physical-device qualification are not part of the current backlog, release gate, or recommended delivery order. They may resume only through a later accepted PRD revision for a named device, owner, evidence profile, and safety boundary. The current platform retains truthful evidence labels and semantic Capability boundaries but schedules no physical delivery work.

  1. Integrate the trusted-header boundary with the deployment identity provider.
  2. Select and restore the production PostgreSQL system of record.
  3. Provision redundant production object storage and off-host monitored backup.
  4. Continue reducing registered maintainability hotspots without increasing their budgets.
  5. Introduce shared event fan-out only when a second ASCEND API instance creates the requirement.

Human-aware shared-workspace gate (2026-08-17)

  • LabBridge now accepts privacy-bounded, short-lived human-presence, obstruction, and equipment-interaction observations from trusted controllers.
  • Shared robot navigation, docking, and station-mode semantic capabilities are guarded at the final Operation boundary by deterministic proceed, wait, reroute, or communicate decisions. Missing or ambiguous physical context fails closed; cancellation, emergency response, and safe-stop are unaffected.
  • Capability projections, public observation/decision contracts, audit records, controller protocol documentation, focused tests, and change-aware mappings are synchronized. The shipped implementation is software/simulation scoped; physical perception and human-subject qualification remain open.

RIGOR product, architecture, operations, and contributor documentation