--- kind: spec status: ratified ratified: 2026-09-01 (Jason Woltje; PRD rev1 ratification PR) succeeds: origin/next:docs/PRD.md (2026-08-26 North Star, commit 9aa4983c, sha256 60cc2f98697471850caa3440d79139d70f67eda585a2ee465fdcd517bc36afdf) --- # PRD: Mosaic Stack — rev1 The project source of truth, successor to the 2026-08-26 North Star PRD (rev0). Ratified 2026-09-01; this bundle is frozen — the next revision is drafted in a lane and lands as a new bundle ([[GOV.1-prd-lifecycle]]). This file assembles the section documents in this bundle; the sections own the detail. Order authority and naming: [[PRD.0-index]]. Lifecycle (shim, frozen revision bundles, archival): [[GOV.1-prd-lifecycle]]. The PRD is **mission-independent**: missions pin an accepted PRD version and reference it (register OD-16/OD-19); they never usurp it. rev0 ([rev0 PRD](../2026-08-26_PRD_rev0/PRD.md)) is archived verbatim beside this bundle; `docs/PRD.md` is the permanent shim pointing here. ## Metadata - **Owner / decision authority:** Jason Woltje - **Status:** ratified 2026-09-01 (Jason Woltje). Drafted as a class-2 draft-native in lane `fleet/lanes/control-plane-surfaces` (estate brain); grill record in [[GOV.5-open-questions]] - **Base text:** rev0, pinned at `origin/next` commit `9aa4983c` - **Pulled sources (inputs, never ratified; not shipped in this bundle):** [rev0 PRD](../2026-08-26_PRD_rev0/PRD.md) and the operator DECISION-REGISTER (estate brain `docs/guides/proposed/DECISION-REGISTER.md`, snapshot 2026-08-28, sha256 `2cc81be1…aabec`; operator-only corpus, not shipped) ## Revision log | Rev | Date | State | Notes | |-----|------|-------|-------| | rev0 | 2026-08-26 | superseded 2026-09-01; archived verbatim as `docs/PRDs/2026-08-26_PRD_rev0/PRD.md` | North Star PRD (Part I product north star from D1–D14 + D15; Part II workstream contracts) | | rev1 | 2026-08-31 | **ratified 2026-09-01** (Jason; grill rounds 1–8 closed the GOV.5 frontier) | rev0 + control-plane surfaces (seats, roles, harnesses, providers, authentication, sessions, WebUI/CLI), consolidated decision map, authorization gap register, docs-estate consolidation | ## Mandate (2026-08-31 drafting directive) 1. Combine the official PRD (rev0) with the `control-plane-surfaces` and `agent-runtime-ng` lane findings. 2. Ingest and reconcile the pertinent document corpus — stack `docs/` on `origin/next`, `~/.mosaic/docs`, `~/.mosaic/docs/guides/proposed` ([[GOV.2-docs-inventory]] is the audit trail). 3. Specify all functions of the site and the north star in one place, with full `mosaic` CLI ↔ WebUI parity. 4. Remove the no-central-location ambiguity; clear up drift and naming issues; clarify ambiguous structural language. 5. Walk open questions via ms-grill-me before ratification ([[GOV.5-open-questions]]). --- ## Part I — Product north star **[[VIS.1-north-star]]** — what Mosaic Stack is, who it is for, deployment modes, hierarchy and tenancy, identity, onboarding, data custody, the webUI-over-tooling architecture gate, the v1 slice, the fleet-north-star subordination, non-goals, and tiered containerized deployment. rev0 Part I preserved as base text with marked rev1 annotations. ## Part II — Platform model (control plane) | Section | Owns | |---|---| | [[DATA.1-record-authority]] | record-class authority (J1), the configuration data model, seat-file consolidation, reconciliation obligation | | [[AUTHZ.1-capability-authority]] | intersection authority model, `mosaic-core` enforcement, firewalls, privilege escapation, accepted risk, gap register G1–G7 | | [[ROLE.1-role-governance]] | role definitions/revisions, manifest invariants, role surface, seat/role separation rule | | [[SEAT.1-seat-profile]] | instance contract, seat surface, the separated role-binding control (G5), OD-02/OD-03 semantics | | [[HARN.1-harness-config]] | harness install/enable, model allowlists, adapter boundary (register OD-38) | | [[PROV.1-providers]] | hosted and local providers, named instances, activation | | [[AUTHN.1-auth-accounts]] | agent-side provider accounts, OAuth/API, custody rules, broker boundary | | [[SESS.1-session-continuity]] | Stack session id, incarnation layering, mid-stream switching via register OD-57–OD-61, the two-operations rule | ## Part III — Surfaces | Section | Owns | |---|---| | [[UI.1-webui-surfaces]] | governing rules and the complete page/function inventory, including the authorization-audit page | | [[CLI.1-parity]] | CLI primacy, the one-engine rule (OD-53), the parity-matrix obligation, command families | ## Part IV — Governance | Section | Owns | |---|---| | [[GOV.1-prd-lifecycle]] | SOT rule, shim, frozen revision bundles, archival | | [[GOV.2-docs-inventory]] | corpus inventory, supersession verdicts, naming-defects register | | [[GOV.3-decision-map]] | every binding decision registry, collision rule, reconciliation notes | | [[GOV.5-open-questions]] | the grill list; ratification gate | ## Part V — Active workstream contracts (preserved unchanged) **[[GOV.4-workstream-contracts]]** — rev0 Part II carried verbatim: #1194 drift detection, Compaction Refresh Trust Lifecycle, Pi Persistent Goal Loop, FCM, cross-harness comms, KBN-101, TESS, channel plugins, MOS-PORT, workspace placement guard, Release Integrity, T78 CLI migration. Open issues bind to them; they graduate out individually as workstreams close. --- ## Ratification Per [[GOV.1-prd-lifecycle]]: this bundle freezes into `mosaicstack/stack docs/PRDs/` (branch off `origin/next`), rev0 archives as a one-file bundle, `docs/PRD.md` becomes the generated pointer (register OD-18). Gate: [[GOV.5-open-questions]] empty or explicitly deferred; then reviewed PR per stack delivery gates.