Capture the Security Fest talk in TAC loop-engineering guidance. Treat agents with file, tool, code, or deploy access as insider-threat candidates and require least privilege, no raw secrets, sandboxing, supply-chain checks, human approval for business-impacting actions, receipts, and promotion attestation. |
||
|---|---|---|
| .. | ||
| meta-prompts | ||
| schema | ||
| templates | ||
| README.md | ||
README.md
Plans
Living Plan F3 artifacts for Product Factory builds.
Plans are durable engineering artifacts consumed by humans, teams, and agents.
Required files per product:
plans/<product_id>/plan.md
plans/<product_id>/plan.html
Rules:
- include frontmatter with
product_id,purpose, andreferences - include required sections: purpose, problem, solution, files, phases, validation, references, notes
- updates append
## Amendment <UTC timestamp>blocks - deploy remains guarded through
git-proxy:8099/deploy