What is built,
what is held,
and what it waits on.

The delivery corpus decides gates; this page tracks work. Phase 0 has run and has not exited — eleven of fourteen spikes are stage-closed on paper because they close on a running system and none exists. Exactly one limb of one exit criterion is open enough to write code against. That limb is section 01.

Track Implementation, phases 0–9 Updated Programme Basis D-07 §7.1 · week 0 = 19 Aug 2026
01

Implementation — unblocked now

This is the whole of the authorised build. It discharges the third limb of Phase 0 exit criterion 3: a command written against absent code is the same TODO in a new form, so the criterion closes at the first commit that lands a scaffold those commands run against. It permitted nothing else — every real-world gate in section 05 stays shut.

A second wave followed it. Four Phase 0 spikes — SPK-04, SPK-05, SPK-06 and SPK-07 — now run as working prototypes under /spikes, because the spike register's rule is that no spike closes without a running system and the repository previously had no way to satisfy it. None of the four closed, and each says so in its own evidence document. Their results are in section 03 and the defects they found are in docs/plan/implementation-findings.md. Three spikes could not be attempted at all: SPK-01 needs a probe fleet at other cloud providers, SPK-02 needs S3 Object Lock, SPK-03 needs induced failure against real storage. That is the largest single constraint on exit criterion 1, and it is procurement rather than engineering.

Five rows read Blocked and are not idle. A3 to A7 are built, running and verified — 4,013 matrix assertions enumerated across the four suites, and 159 unit tests over the verdict rules themselves, all green. They are blocked at closure rather than at start, because this register's own rule is that a task is done when its verification passes against real code, and a suite that passes because there is nothing to test is a failure. Each waits on its subject: the operator surface and audit store at phase 8, the credit ledger at phase 6, invoice records at phase 7, and a probe fleet that by D-08 §6.1 must sit outside this repository altogether. The status vocabulary has no term for complete as far as this phase can take it, so this paragraph is the term.

The suites must fail against an absent implementation rather than pass vacuously. A green suite over no code is precisely the failure the audit-integrity design exists to prevent, which is why a green :shadow lane is itself a failed Release. test:nfr-gov-001 is the specific case: a Release with no operator surface must assert the absence, and a skip is recorded as a failure.
02

Schedule

D-07 estimate · week 0 = 19 Aug 2026

Every figure here is D-07's own estimate, not a specification figure and not a commitment. §37's week figures are disclaimed at source. D-07 is itself drafted, not delivered — converting effort to calendar needs a team size and a stack, and §38 staffs nothing. The dates below anchor D-07's week offsets to a week 0 of 19 August 2026 and carry both correlated ends: optimistic at T = 5.6 scope points per week, pessimistic at T = 4.5. T is borrowed from §37, not measured.

Optimistic extent (T = 5.6) Slip zone to pessimistic (T = 4.5) Tranche, interleaved — not a successor to phase 5
MilestoneWeekOptimisticPessimisticWhat it releases
The spine is understated and the tranches are not. D-07 puts the spine at 52–66 weeks against §37's 36–45, and at 52–66 against 44–57 once §37's own 8–12 week contention allowance is set beside it — an understatement of 8 to 9 weeks the allowance does not absorb. The omission is concentrated in the engine phases, where the scope ratio reaches 1.34 in phase 2 and 1.40 in phase 3; the allowance was raised for phase 4 and does not reach them.
03

Phase 0 — run, not exited

14 spikes · 8 deliverables

All four exit criteria assessed as at 19 August 2026. No spike has met all of its closing conditions. Eleven close on a running system; three closed on simulated external evidence, which briefs the real engagement rather than substituting for it. A closure record is not a discharge of the obligation it records.

Exit criterionStateWhat is missing
1 — Spikes closed on evidence, D-01…D-08 deliveredNot met11 stage-closed on paper, 3 on simulated evidence. D-02 held, D-03 open, D-04 not adopted, D-07 drafted, D-08 provisional
2 — Standing verification per binding NFRNot metAll four suites now written, running and correctly RED — 4013 assertions enumerated, 159 harness unit tests green. Not met: a suite is standing verification only once it has a subject to verify
3 — D-08 records the stack; CLAUDE.md gains the commandsPartialLimb 3 discharged 19 Aug 2026 — the commands run against a real scaffold and pass or fail. Decision still provisional; orchestration still undecided
Blocking rule — "an open input blocks the item"Replaced 20 Aug 2026Six registers carried a sentence that, read literally, blocked every item in every phase permanently — including the work that produces the evidence the spikes wait for. Replaced by a Release-gate/build-gate split. The money, contract and Release gates are unchanged
4 — §39.1 re-checked, no epic orphanedNot metD-07 records four epics with no acceptance criterion to verify

The fourteen spikes

SpikeSubjectDispositionEvidenceUnmet

The eight deliverables

DeliverableSubjectDisposition
04

The forward track

29 epics · 254 Must/MVP requirements

The numbering is not a sequence. Phases 0–4 are the spine, 5 is ongoing, and 6–9 interleave with 1–4 rather than succeeding 5. Three of the four hold Must/MVP scope the phase 4 pilot cannot clear without. Sequencing authority is delivery-interlocks.md; the registers cite it rather than re-derive it.

PhaseScopeEpicsSID-07§37Δ
Two hard gates, both running from a tranche into the spine. Tranche 6's admission and settlement integration gates phase 3; tranche 8's provisioning and lifecycle path gates the phase 4 pilot — not the start of phase 4. Tranche 7 gates the pilot on the same footing but says so only in §37's arithmetic paragraph, never in its own row. And the three Golden Crews are a phase 3 exit condition, not a pilot gate: a register that moves them has moved a gate the specification deliberately placed earlier.
Phase 1 is the worst slip in the programme. It moves the spine and pins tranche 8's start, so it reaches phase 4 twice — once through the spine, once through the longest tranche — and the two do not cancel.
05

Held gates

None of these moves on internal work. Each closes on a named external party or a named deliverable, and each forbids a specific commercial act until it does.

06

Update protocol

How this file stays true

This page renders from a single TRACK_A array at the top of its own source. Marking a task complete is a one-token status edit plus a done date; the counters, the meter and the filters all re-derive. It is updated at the completion of each task, and redeployed in the same step, so the deployed page and the repository never disagree.

What may not be recorded here. A task is done when its verification runs and passes against real code — not when it is written. The three binding-NFR suites are the case that matters: a suite that passes because there is nothing to test is a failure, and must be recorded as one. Where a task is closed ahead of its evidence, the row says so rather than reading as clean.