ChatWell Gen-5 System atlas
L3

Source authority and traceability

L3.1How provenance is shownPermalink

  • At the claim group. Each statement group carries a quiet identifier (in this source, a comment line such as cg: WS-OWN-1).
  • At the chapter foot. Where this comes from lists every claim group with its state, its authority coverage and its sources by name. A claim group that restates others names no source of its own: its row reads via and the groups it restates. Records are not listed there — a DNA record's state is Decided — not currently available and an SD record's is Sources disagree, each fixed by the register it belongs to, and their sources are in the sidecar.
  • On demand. Exact identities — repository, path, document status, immutable commit, content checksum, section and line locator, and authority scope — live in the traceability sidecar gen5-system-guide.sources.yaml, next to this file.

Coverage values: Full — a registered authority owns and states it. Partly defined — established by the accepted implementation where registered documents are silent, or its wider meaning is not defined. Gap — no registered document supports it: the canonical documents say otherwise, or nothing addresses it; where it works today, only the accepted implementation shows it. Sources disagree — applicable authorities conflict.

Coverage is a fact about the sources, not a reader label. A statement that works today carries the Partly defined qualifier whether its coverage is Partly defined or Gap, because Gap is not one of the five labels; the two are told apart only in these tables and in the sidecar. Sources disagree describes a question held as a record rather than a claim group, so no row at a chapter foot carries it; those records are listed in L1.3.

L3.2The sourcesPermalink

SourceWhat it is cited for, here
Workspace & project lifecycle modelWorkspace and project lifecycle, archival, ownership transfer, and governance: roles, derived Project Owner, the role vocabulary, the authority ladder, and that the owner's project membership is not derived ownership
Membership modelMembership periods, access rules, event identity, the data classes of stored content, and the project-access policy for every workspace type
Task lifecycle & assignment modelTask lifecycle, transitions, permissions, assignment, reviewer selection and the assignee/reviewer separation, archive semantics and task history
Task operation contractThe public task operation contract: callable behaviour, authorization and refusal
Gen-5 task implementation specificationHow the task model and contract are realized; its records of deferred and out-of-scope items
Gen-5 lifecycle decisionsDecisions G5-01 to G5-17: ownership transfer, owner-elected archival, the personal-workspace carve-out, deny-by-default access after archival, operator access, export, task disposition on archival
Task authority decision recordThe Task authority layering, and the record of the departure disagreement
Project access policy decisionThe workspace owner's standing project membership in active projects, and that workspace membership alone grants no project membership
Task reviewer authority decisionReviewer selection as its own authority, and that a task's assignee is never its reviewer
Beta workspace creation decisionThe Personal Workspace as unconditional, and the two permissions an additional workspace needs during beta
Workspace templates runbookHow workspace templates are permitted and authorized today, and what each template setting means
Identity invariantsAccount identity and attribution
Default template contractThe default workspace template (with an unresolved amendment), the unconditional Personal Workspace guarantee, and that "free" is positioning rather than a system setting
Source of Truth MapWhich document owns which topic, at the accepted documentation base
Decision IndexThe identity and status of an open question — here, how many workspaces an account may have
Accepted Gen-5 implementationWhat is deployed: the accepted Gen-5 migration chain, which is also the applied hosted LOCAL ledger
Accepted runtime evidence (Gate-25)Runtime acceptance of the task work on hosted LOCAL, scoped to tasks (evidence, not a registered authority)
Accepted runtime evidence (R1–R4)Runtime acceptance on hosted LOCAL of the project-access, reviewer-authority and beta-creation decisions (evidence, not a registered authority)

The sidecar also records the Checkpoint-X closure and the accepted LOCAL integration record. Neither is cited for an individual claim: together they are what ties the accepted implementation to the hosted LOCAL ledger.

Runtime evidence is never an authority of its own. Where a statement here is marked as working today on the strength of it, an accepted document says the same thing first; the evidence says only that the running system agrees.

L3.3Reader terms and source termsPermalink

This guide uses its own words. The mapping back to the sources' vocabulary:

Reader termSource term
membership periodmembership episode (workspace_membership_episode, project_membership_episode)
who owns the workspacethe open workspace_ownership_episode
being able to act / accessworkspace_effective_access, project_effective_access
stored role: member, adminworkspace_member.role, project_member.role ∈ {member, admin}
owner / derived project ownereffective authority owner; Project Owner ≡ Workspace Owner
finished taskterminal status: complete, canceled
task historytask_status_event and task_activity_event, merged on a shared sequence
Open · In Progress · Blocked · Ready for Review · Complete · Canceledopen · in_progress · blocked · ready_for_review · complete · canceled
main projectproject of kind workspace_main
Personal Workspace / user-created workspaceworkspace_origin = system_personal / user_created
the owner's separate ownership signalis_owner, returned per workspace by the account bootstrap
the reason a task closedthe task's closed_reason (for archival: project_archived)
the owner's standing project membershipG5-PA-01 — an open project_membership_episode with project_role = admin
the two permissions a further workspace needsG5-WC-02 — account authorization and template permission, today carried by one workspace_template_grant row
a position on a taska capacity — Creator, Assignee, Reviewer, Project Admin, Project Owner

L3.4Conventions of this sourcePermalink

For maintainers, and for the rendering of Representation B.

  • Markers. A comment line directly above a block: cg (claim group), rec (record), block, emphasis, figure, link, anchor, joined by | . A block runs until the next marker. A record's title is the heading immediately above its rec marker. link names the claim groups or records a block restates, illustrates or points to; a block with link and no cg carries no claim of its own and gets no provenance row. figure on a block: figure marker declares that block to be that figure; figure on a cg or rec marker names the figure that illustrates it, which may be declared in another chapter. A figure is rendered once, where it is declared; every other binding is a reference to it.
  • Blocks. opener, rule, statement, aside, scenario, figure, matrix, prototype, provenance. No other block exists. A matrix cell is ✓, —, a state label with its record, or a short phrase where yes or no is not the whole answer.
  • Emphasis. At most one lead per section.
  • Labels. Only the five in T0.1. A statement that does not work today starts with its state label; the Partly defined qualifier sits next to the claim it qualifies.
  • Figures. Fenced structure-map, state-map or timeline declarations. Nodes are reader concepts only — Account, Person, Personal Workspace, Workspace, Project, Task — or named states. Each declares what it shows; a figure of current behaviour contains only current behaviour. Every figure declares id, caption and shows; a structure map declares nodes and may declare contains and edges; a state map declares states and transitions; a timeline declares entries, read top to bottom in the order written. An optional note is a footnote: it may restate or point to claim groups, never carry a claim of its own. A node written as a bare kind name — Project — stands for the kind, so it may sit under more than one container; a node written Kind (Name) stands for one named thing, and sits under exactly one. Grammar: A > B under contains: — B sits inside A; A -> B : label — a relation, or in a state map a transition; A ..> B : label — a derived relation; A -x B : label — a relation that does not exist; overlay: — ownership or access drawn over the same outline; [person] / [system] — who makes a transition. Every endpoint is a declared node or state.
  • Records. Each DNA record carries the capability, the decision and today's consequence, and either an anchor list or a register-only reason. The notice at each anchor is written there, names the record's capability, and adds nothing the record does not state.
  • Prototype entries end with — from and the claim groups or records they derive from.
  • Provenance. Every claim group appears once in its chapter's Where this comes from, and has an exact record in the sidecar.

Exact source identities

From the traceability sidecar — a component of the guide, not a separate document. Each card leads with the scope the source may be cited within: several of those scopes are the only thing preventing a reasonable over-reading.

document

Beta workspace creation decision

D-BWC7 citations

cited only withinDecision anchor for owner ruling R4, both limbs: G5-WC-01 (the Personal Workspace is provisioned unconditionally, independent of grants, creation eligibility, catalog availability and visibility, beta authorization and instance limits; `free` is positioning only and no billing semantic follows) and G5-WC-02 (an additional Workspace during beta needs account authorization AND template permission). canonical-for: —; the operative rules live with product/default-template-contract.md §1.1, §4.1 and runbooks/workspace-templates.md §2, §3.

repository
ChatWellApp/chatwell-docs
path
decisions/ADR-2026-09-beta-workspace-creation.md
immutable ref
cbab557b1b2f6b23a856b08041877ee0ebcefe8a
content checksum
ae1176d490f2eaee41f735c02bf5005974b3b751
type
process
status
adopted
decision status
adopted
document

Identity invariants

D-ID2 citations

cited only withinCanonical for identity invariants: account lifecycle, attribution and deletion.

repository
ChatWellApp/chatwell-docs
path
architecture/identity-invariants.md
immutable ref
cbab557b1b2f6b23a856b08041877ee0ebcefe8a
content checksum
fde60aa3f7e18f0dc15392e6fa4fa3bd1e4a7623
type
architecture
status
canonical
document

Decision Index

D-IDX1 citation

cited only withinThe register of adopted decisions and open questions. Cited only for the identity and status of an open question — here P-1, whether the dev-only workspace-limits changes amend the Default template contract — never for a semantic.

repository
ChatWellApp/chatwell-docs
path
decisions/index.md
immutable ref
cbab557b1b2f6b23a856b08041877ee0ebcefe8a
content checksum
7ec8505b0dea18b964f977170be17589f8251eae
type
process
status
canonical
document

Gen-5 lifecycle decisions

D-LIFE15 citations

cited only withinRegistered canonical for decisions G5-01..G5-17 (ownership transfer, owner-elected archival, personal-workspace carve-out, deny-by-default post-archival access, export before archival, operator access, task disposition on archival, invitations).

repository
ChatWellApp/chatwell-docs
path
decisions/ADR-2026-08-gen5-lifecycle-domain.md
immutable ref
cbab557b1b2f6b23a856b08041877ee0ebcefe8a
content checksum
4fce60d71fc0fb97af110281e5975414794e0a1c
type
architecture
status
adopted
decision status
adopted
document

Membership model

D-MEM35 citations

cited only withinCanonical for membership episodes and historical identity, the live access predicates (the two historical predicates are superseded for Gen-5 by G5-09), the event identity model, and the data-class classification of stored content (section 5B).

repository
ChatWellApp/chatwell-docs
path
architecture/membership-episodes-model.md
immutable ref
cbab557b1b2f6b23a856b08041877ee0ebcefe8a
content checksum
4eb24609d6116d0a825223d23642ea197c6bf18d
type
architecture
status
canonical
document

Project access policy decision

D-PAP18 citations

cited only withinDecision anchor for owner rulings R1 (G5-PA-01, the Workspace Owner's standing `admin` project membership in ACTIVE projects, conditioned on the owner's current workspace access) and R2 (G5-PA-02, workspace membership alone never grants project membership). canonical-for: —; the operative rules live with membership-episodes-model.md §3 and workspace-lifecycle-model.md §6.

repository
ChatWellApp/chatwell-docs
path
decisions/ADR-2026-09-project-access-policy.md
immutable ref
cbab557b1b2f6b23a856b08041877ee0ebcefe8a
content checksum
95e832a038f9deb8450f7388399f701bfebe48b7
type
process
status
adopted
decision status
adopted
document

Source of Truth Map

D-SOT5 citations

cited only withinRegistry of topic ownership. Ref-specific: its contents differ between refs, so it is cited only at this ref.

repository
ChatWellApp/chatwell-docs
path
source-of-truth-map.md
immutable ref
cbab557b1b2f6b23a856b08041877ee0ebcefe8a
content checksum
d316904b00d400e8b7979a342c57f0d349fe12a9
type
process
status
canonical
document

Gen-5 task implementation specification

D-TASKI28 citations

cited only withinCanonical for the implementation realization of the task model and contract only (never product semantics); cited here for realization facts and for its records of deferred and out-of-scope items (sections AK, I.4).

repository
ChatWellApp/chatwell-docs
path
architecture/gen5-task-domain-implementation-specification.md
immutable ref
cbab557b1b2f6b23a856b08041877ee0ebcefe8a
content checksum
87d23f2d27365fec3290924b6bd38524d51d6f89
type
architecture
status
canonical
document

Task lifecycle & assignment model

D-TASKP41 citations

cited only withinCanonical product semantics for task lifecycle states and transitions, task permissions, assignment, reviewer, archive semantics and the task event model.

repository
ChatWellApp/chatwell-docs
path
product/task-lifecycle-and-assignment-model.md
immutable ref
cbab557b1b2f6b23a856b08041877ee0ebcefe8a
content checksum
a296f6753702b6737f2a75b3c6e80965ef2f969e
type
product-spec
status
canonical
document

Task operation contract

D-TASKR21 citations

cited only withinCanonical for the public task operation contract: callable behaviour, authorization and refusal, externally meaningful validation and errors, the read layer, task realtime and replica identity.

repository
ChatWellApp/chatwell-docs
path
architecture/task-domain-rpc-contracts.md
immutable ref
cbab557b1b2f6b23a856b08041877ee0ebcefe8a
content checksum
080898faf6cf91184f12e5e8c8eba68ed26f51da
type
architecture
status
canonical
document

Task authority decision record

D-TAUTH1 citation

cited only withinDecision anchor for the Task authority layering; records the departure-handling contradiction between the task lifecycle model and the RPC contract/implementation specification without resolving it. canonical-for: —.

repository
ChatWellApp/chatwell-docs
path
decisions/ADR-2026-09-gen5-task-authority-adoption.md
immutable ref
cbab557b1b2f6b23a856b08041877ee0ebcefe8a
content checksum
f72995193e51661f8fc87f89d067092238ba6ae2
type
process
status
adopted
decision status
adopted
document

Default template contract

D-TMPL3 citations

cited only withinCanonical for the default template and the `default_personal` lifecycle rules L1-L9, with the P-1 amendment (instance limits and their counting) unresolved — neither version of that to be treated as settled. Cited to mark the starting structure as not settled, and for §1.1's unconditional Personal Workspace provisioning guarantee and its positioning-not-pricing rule (LOCKED — A4).

repository
ChatWellApp/chatwell-docs
path
product/default-template-contract.md
immutable ref
cbab557b1b2f6b23a856b08041877ee0ebcefe8a
content checksum
bdcb16795ed97d9d561931ef5e8511ee7575f823
type
product-spec
status
canonical
document

Workspace templates runbook

D-TMPLR5 citations

cited only withinRegistered owner of workspace template operations: the visibility policy and the beta creation gate (§2), the operator procedures that confer authorization (§3), and instance limits (§3.7). Cited only for template visibility and the beta authorization mechanism; it owns no workspace, project or task semantic.

repository
ChatWellApp/chatwell-docs
path
runbooks/workspace-templates.md
immutable ref
cbab557b1b2f6b23a856b08041877ee0ebcefe8a
content checksum
ae6e61f6e51d08539b34f453f95c6f58377143a0
type
runbook
status
canonical
document

Task reviewer authority decision

D-TRA15 citations

cited only withinDecision anchor for owner ruling R3, both limbs: G5-TR-01 (reviewer selection requires a capacity other than Assignee, and capacities are additive) and G5-TR-02 (the current Assignee is never the Reviewer of the same task). canonical-for: —; the operative rules live with task-lifecycle-and-assignment-model.md §1.9, §2, §3 and task-domain-rpc-contracts.md. Explicitly does NOT decide reviewer departure (SD-1).

repository
ChatWellApp/chatwell-docs
path
decisions/ADR-2026-09-task-reviewer-authority.md
immutable ref
cbab557b1b2f6b23a856b08041877ee0ebcefe8a
content checksum
bef9c3af931a4c8b3d40ffd9e27c8c79f3179bde
type
process
status
adopted
decision status
adopted
document

Workspace & project lifecycle model

D-WSL39 citations

cited only withinCanonical for workspace and project lifecycle, archival, ownership transfer, deletion policy, project archival, and workspace/project governance: the four roles, derived Project Owner, the stored role vocabulary {member, admin} and the effective-authority ladder.

repository
ChatWellApp/chatwell-docs
path
architecture/workspace-lifecycle-model.md
immutable ref
cbab557b1b2f6b23a856b08041877ee0ebcefe8a
content checksum
df1f8146be326ed30d2f019714da96cc5c67bb34
type
architecture
status
canonical
migration-chain

Accepted Gen-5 implementation

B-MIG108 citations

cited only withinThe registered non-document authority for what is deployed (schema, access rules, operations, realtime). Establishes current behaviour and absence of operations; never product intent. The last definition in chain order governs, and an operation is user-reachable only where EXECUTE is granted to authenticated. Sixteen units at this ref; equal to the hosted LOCAL applied ledger, head 20260911102642 (R-R1R4). The eleven-unit predecessor is recorded by R-CX and R-INT.

repository
ChatWellApp/chatwell-supabase
path
supabase/migrations/
immutable ref
3bf502a701e5c4ee8f32637c00664b73ca952405
tree
874a9338c974e80743444458f9f71b2d4d88b7a8
16 units in the chain
  1. 20260901022656_baseline_gen5_1of4_schema.sql
  2. 20260901201626_baseline_gen5_2of4_functions_and_triggers.sql
  3. 20260902061658_baseline_gen5_3of4_security_rls_realtime.sql
  4. 20260902212802_correct_gen5_scheduled_worker_advisory_locks.sql
  5. 20260902235207_baseline_gen5_4of4_seed_and_schedules.sql
  6. 20260904234359_correct_gen5_mailbox_first_principal_and_invitation_identity.sql
  7. 20260905163747_gen5_task_domain_types_schema_stores_retirement.sql
  8. 20260905175604_gen5_task_domain_predicates_rpcs_and_security.sql
  9. 20260905202219_gen5_task_domain_archival_and_departure_integration.sql
  10. 20260907070001_correct_gen5_task_whitespace_validation.sql
  11. 20260907173509_correct_gen5_workspace_departure_serialization_timestamp.sql
  12. 20260911101829_correct_gen5_invitation_project_chat_fanout_removal.sql
  13. 20260911102001_correct_gen5_task_reviewer_authority_and_collision.sql
  14. 20260911102134_correct_gen5_departure_replacement_reviewer_collision.sql
  15. 20260911102459_correct_gen5_workspace_owner_project_membership_writers.sql
  16. 20260911102642_backfill_gen5_workspace_owner_project_membership.sql
runtime-evidence

Accepted runtime evidence (Checkpoint-X)

R-CXrecorded for identity; not cited for an individual claim

cited only withinCheckpoint-X hosted LOCAL closure, CLOSED / PASS: ledger 11, head migration 20260907173509 — the ELEVEN-UNIT PREDECESSOR of the chain B-MIG now names; superseded as the current tie by R-R1R4. Asserts nothing about DEV, STAGING or PROD. Evidence, not a registered authority. Recorded for identity, with R-INT, as what ties the accepted chain to the hosted LOCAL environment; not cited for an individual claim.

repository
ChatWellApp/chatwell-gate25-evidence
path
CHECKPOINT_X_FINAL_CLOSURE.txt
immutable ref
f89481aa8bc32f125a48fc88224aa0ac30dc1bd5
content checksum
4cc5094f91e7e24a43ceabc85d53249d6ff27e8b
basis
db023e6139b39cf21077a3ca132d26e27150bc68
runtime-evidence

Accepted runtime evidence (Gate-25)

R-G25recorded for identity; not cited for an individual claim

cited only withinGate-25 hosted LOCAL runtime acceptance, formally CLOSED / PASS. Scoped to the Task / Checkpoint-X work only; it proves nothing about non-task domains. Evidence, not a registered authority. Recorded for identity; behaviour-level claims cite the specific block (R-G25-R4).

repository
ChatWellApp/chatwell-gate25-evidence
path
G25_FINAL_CLOSURE.txt
immutable ref
36f677371437227d3b0c42d7bd34ac290326e0c6
content checksum
6018a63008f9d6f53bb8844c0eea2fb7789ba76b
runtime-evidence

Accepted runtime evidence (Gate-25)

R-G25-R41 citation

cited only withinGate-25 block G25-R4: terminal task immutability runtime acceptance on hosted LOCAL. Evidence, not a registered authority; scoped to the task work.

repository
ChatWellApp/chatwell-gate25-evidence
path
R4_EXEC_RESULTS.txt
immutable ref
36f677371437227d3b0c42d7bd34ac290326e0c6
content checksum
4a792caeb09e24593fe65cb2e0fa52d5f0ab97ff
runtime-evidence

Accepted LOCAL integration record

R-INTrecorded for identity; not cited for an individual claim

cited only withinRecords that chatwell-supabase local was fast-forwarded to 38a7075, so the eleven-unit chain equalled the hosted LOCAL applied ledger at that time. Historical identity evidence for the predecessor checkpoint; superseded as the current tie by R-R1R4. Not cited for any claim.

repository
ChatWellApp/chatwell-gate25-evidence
path
CHECKPOINT_X_LOCAL_GIT_INTEGRATION_EXECUTION.json
immutable ref
3e0499197242daefe021dcca3db3a108552cab6e
content checksum
3a66352bdb2ee1223dd8b1dd913a7f9e7a06d742
runtime-evidence

Accepted runtime evidence (R1–R4)

R-R1R420 citations

cited only withinHosted LOCAL runtime acceptance of the R1-R4 conformance work, scoped to the assertions the script makes: R1 (owner admin membership on project creation; owner cannot leave, be removed from, or be demoted in an active project), R2 (invitation acceptance opens a workspace membership and no project episode, project member row or chat membership), R3 (reviewer selection capacity, capacity additivity, the reviewer-required refusal, the non-review-edge refusal, and the assignee/reviewer collision on every mutation path including departure replacement) and R4 (Personal Workspace provisioned with zero grants; zero public templates; no direct workspace insert; no create_workspace/_v2). It proves nothing outside those assertions and nothing about DEV, STAGING or PROD. Evidence, not a registered authority: every claim it supports is stated first by an accepted document.

repository
ChatWellApp/chatwell-supabase
path
supabase/operator-runbooks/verify_gen5_r1r4_conformance.sql
immutable ref
3bf502a701e5c4ee8f32637c00664b73ca952405
content checksum
c3fe736814350a100877fa0ebc0f27bf2ff43160
executed on
hosted LOCAL, applied ledger head 20260911102642, equal to B-MIG at this ref
recorded result
C1 control OK; 24 assertions, 24 PASS, 0 FAIL; U4 pre-existing census eligible 9, conforming 9. Verification runs inside a transaction that is rolled back; nothing is retained.

The committed artifact is the verification script itself — the assertions it makes and the conditions each asserts. The recorded outcome of the hosted-LOCAL execution above is the accepted checkpoint result and is NOT committed as a file in any repository; no result artifact exists to cite.