00

Prove the harness can participate

Identify whether the agent or harness can read required source, write to the isolated candidate, execute commands, and operate within task content and tool requirements.

A model failure and a harness limitation are not the same product outcome.

01

Survey and declare

Declare target owner or surface, desired outcome, allowed creates/changes/deletes/relocations, protected entrypoints/exports/literals/opaque artifacts, behavior scenarios, architecture goals, project gates, dependency transitions, and dirty-worktree policy.

Operator-reviewed declarations remain authoritative.

02

Capture the before-state

Record a content-addressed or Git-backed immutable candidate from the real current workspace. The original fingerprint becomes part of the final transfer condition.

A clean commit is not required to pretend the developer’s actual work does not exist.

03

Analyze without granting mutation authority

Analyzers may identify complexity, dead code, clone families, package boundaries, symbol ownership, public contracts, cycles, effects, order sensitivity, affected tests, behavior scenarios, and security findings.

Those findings are sensors. They do not automatically gain authority to edit or define the semantic goal.

04

Obtain bounded judgment

For ambiguous valid choices, produce a compact decision request with the exact goal, source-backed options, evidence references, risks, allowed selection shape, coverage boundary, and refusal paths.

The agent selects, rejects, requests more evidence, or refuses.

05

Conform and actuate

Verify option identity, source freshness, input/output contract, declared files and bindings, preview digest, permissions, and evidence tier before applying a registered actuator.

Unsupported actions stop or move to an explicitly different manual lane.

06

Iterate against evidence

Run cheap affected evidence first while retaining a required full gate before transfer. The agent should receive one next command, not reconstruct workflow state from prose.

Evidence remains visible and causal.

07

Finish and classify

Separate candidate regression, incomplete architecture objective, scope/policy violation, baseline debt, environment drift, unavailable evidence, unsupported coverage, agent workflow failure, and harness failure.

Classification prevents a red result from becoming an undifferentiated mystery.

08

Transfer atomically

Require a passing verdict, exact declared mutation set, terminal-clean candidate controls, unchanged original fingerprint, and verified transfer receipt.

The original remains untouched when those conditions are not met.

Manual lane

The system does not pretend every semantic implementation is deterministic.

A one-way manual handoff may be appropriate when KodeProof can prove the decision but does not own the implementation, the harness cannot compose required source through candidate-edit APIs, a framework lies outside actuator coverage, or the user deliberately chooses a manual transaction.

The handoff is explicit. The product does not silently widen its claim.

Take the next step

Make the boundary visible before the agent starts.

The private alpha is designed around one bounded transaction, known project gates, and an engineer who owns the outcome.