# PRAXIS context-to-runtime bridge: proposed acceptance contract

Inspected read-only on 3 October 2026: local PRAXIS source 8ff509b877f1dcd2b3ed6d074d2d5e96e3f9b923. This document does not certify the current deployed source or private authenticated acceptance.

Existing components: `src/lib/agent-runtime/worker.ts`, `cloud-tasks.ts`, `postgres.ts`, `types.ts`; existing owner-scoped agent routes. Stored run states are `queued`, `running`, `waiting_approval`, `succeeded`, `failed`, `cancelled`, `expired`. Dispatch/ledger diagnostics are separate UI states. Owner envelope schema 3 and capsule/v2 compatibility remain intact.

## Narrow proposed flow

Pinned owner capsule -> selected task packet -> existing queue/run request -> bounded runtime -> proposed artifact -> exact-revision human review -> saved output with dependencies.

The adapter, complete project/team journey and automated dependency-impact review are unvalidated. No second backend, model credential, service, endpoint or production capsule standard is introduced by the website. `tacitus-web-context/1` is a local teaching view model only.

## Required future acceptance

1. Resolve owner identity, capsule revision, source versions and applicable method. Do not substitute latest for a pin.
2. Check source access and rights separately from structural validity, byte integrity, local review and factual accuracy. Fail closed on unavailable sources; preserve the missing-evidence receipt.
3. Expose selection reasons, omissions, output schema, operation boundaries, step/time limits and cancellation. Imported content cannot expand authorization.
4. Reject stale-review submissions when any bound input or output changes. Approval belongs to a specified reviewer, purpose and exact revision.
5. Execute through the existing worker/queue. Exercise queued, running, waiting_approval and each terminal state with durable receipts.
6. Demonstrate cancellation, timeout, provider/tool failure, recovery and inaccessible evidence without returning a cached answer as fresh work.
7. Handle duplicate dispatch/completion idempotently; persist one attributable output binding and record retries.
8. Save the proposed artifact, sentence dependencies, source/method versions and review decision durably. Reopen under the owner and an explicitly approved successor.
9. Changed sources mark only true dependent artifacts potentially stale; retain old snapshots and historical approvals.
10. Independently evaluate semantic round trip, output/citation quality, ownership boundaries and repeat-assignment effort. A successful run or source-linked answer alone does not establish these outcomes.

No production cross-owner promotion or sharing is authorized by this contract. Existing PRAXIS promotion paths remain the only canonical writing boundary.
