statecraft: the governed agentic delivery control plane
001-statecraft-thesis
The product thesis and the consolidation record, rewritten ground-up on 2026-07-19 from the grand-refactor realignment. statecraft is the control plane for governed AI-native software delivery: intent becomes a governed spec, the factory stamps an application from the EnRaHiTu template, the fleet operates the resulting governed cells, and the customer's code lives in the customer's GitHub org the entire time. The architecture is a two-plane model: the platform is ONE EnRaHiTu app (embedded rauthy as THE platform IdP, operator surfaces gated on a custom statecraft_operator role, observability via the in-substrate flag-gated admin dashboard) and every tenant app is ANOTHER, independent EnRaHiTu app (its own IdP, its own state, its own /metrics). Every app honors the substrate observability contract and carries app-model.json, the hash-anchored extracted record of what it contains and what it is permitted to do; enforcement phases in behind the model (Phase A: extraction, kernel adjudication, Decision ledger; Phase B: the Rust effect tier). This spec records the consolidation history, the service map, and the milestone ladder that orders the build.
- Depends on
- Establishes
- README.md
- Sections
- 001: statecraft thesis
- 1. Purpose
- 2. What consolidates here
- 3. Architecture: the two-plane model
- 3.1 Two planes
- 3.2 The platform app
- 3.3 Identity: one rauthy, role-separated
- 3.4 Observability: a substrate contract, not a platform stack
- 3.5 The governed cell and app-model.json
- 3.6 Service map
- 4. Tenancy
- 5. Licensing
- 6. Milestone ladder
- 7. Out of scope
- Source
- specs/001-statecraft-thesis/spec.md @ f136bf323cecas of 2026-07-21 ยท shard e28ef8f55b8d