# Axelyn Forge — implementation checklist

Public companion to Blueprint 001. You may copy and adapt this checklist for an internal evidence-grounded document workflow. Attribution to Axelyn Forge is appreciated.

This checklist describes an architecture pattern. Change its controls, review rules and acceptance thresholds to match the consequences of your own workflow.

## 1. Define authority before prompts

- [ ] Name the exact document or decision the system produces.
- [ ] Name the person who approves the result.
- [ ] List the sources that may support factual claims.
- [ ] List every field the model may edit.
- [ ] List every field the model must never edit.
- [ ] Decide what must happen when evidence is missing.
- [ ] Treat external instructions and uploaded documents as untrusted input.

**Gate:** A reviewer can state which source controls facts, structure, presentation and generated language.

## 2. Create the canonical data model

- [ ] Represent the document as schema-validated structured data.
- [ ] Give each meaningful entity a stable semantic ID.
- [ ] Reject duplicate IDs recursively.
- [ ] Protect identity, dates, organisations and other factual anchors.
- [ ] Version the schema separately from the document content.
- [ ] Validate canonical data before any generation begins.

**Gate:** Reordering an array does not break evidence references or presentation bindings.

## 3. Index verified evidence

- [ ] Keep human-editable source files as the source of truth.
- [ ] Split sources at deterministic semantic boundaries.
- [ ] Store source path, hierarchy, order and content hash for every chunk.
- [ ] Replace the index snapshot transactionally.
- [ ] Make deleted or changed sources disappear from the next snapshot.
- [ ] Separate each user or organisation’s private evidence store.

**Gate:** Every indexed chunk can be traced back to a current source file.

## 4. Normalise the external request

- [ ] Accept exactly one request source per run.
- [ ] Validate encoding, size, URL scheme, host and port.
- [ ] Block local hosts, private IP addresses and embedded credentials.
- [ ] Restrict retrieval to the requested source where possible.
- [ ] Fail when the exact requested material cannot be retrieved.
- [ ] Retain the normalised input and source references for audit.

**Gate:** The system never silently substitutes a similar external source.

## 5. Select context by known IDs

- [ ] Give the selector a catalog of available evidence chunks.
- [ ] Require a typed response with ranked chunk IDs.
- [ ] Set a maximum number of selected chunks.
- [ ] Reject empty, duplicate, unknown or excessive selections.
- [ ] Resolve accepted IDs from local storage.
- [ ] Pass only the resolved evidence into the generation request.

**Gate:** The generation stage cannot introduce an evidence source that the local system did not resolve.

## 6. Separate support from similarity

- [ ] Extract required, preferred and responsibility-level concepts.
- [ ] Define controlled aliases and morphological variants locally.
- [ ] Classify every concept as exact, alias, contextual or unsupported.
- [ ] Give generation only the supported concepts to surface.
- [ ] Preserve unsupported concepts as visible gaps.
- [ ] Describe coverage as evidence coverage, not outcome probability.

**Gate:** A missing requirement cannot become a candidate claim through keyword pressure.

## 7. Generate semantic operations

- [ ] Expose a small catalog of editable targets and current values.
- [ ] Require strict structured output.
- [ ] Require one typed operation per target.
- [ ] Reject protected, unknown or duplicate targets.
- [ ] Reject incorrect value types and empty required fields.
- [ ] Remove no-op rewrites before applying changes.
- [ ] Apply accepted operations to a deep copy.
- [ ] Validate the complete resulting document.

**Gate:** The model proposes changes but cannot write directly to the final document.

## 8. Bind content to presentation

- [ ] Keep templates separate from generated content.
- [ ] Map semantic fields to explicit template tags.
- [ ] Fail on missing required bindings.
- [ ] Replace only text owned by the tagged control.
- [ ] Preserve layout, styles, tables and numbering around the control.
- [ ] Refuse to overwrite the source template.
- [ ] Test the output in every supported layout engine.

**Gate:** A content rewrite cannot silently reconstruct or damage the presentation template.

## 9. Publish as a transaction

- [ ] Build every required artifact in a staging directory.
- [ ] Validate structured data, documents and converted files.
- [ ] Verify converted file signatures and non-empty content.
- [ ] Publish final outputs only when the complete package succeeds.
- [ ] Use atomic replacement for final paths.
- [ ] Retain operations, selection, alignment and source audits.
- [ ] Clean temporary files without deleting the last valid package.

**Gate:** A failed run leaves no partial package presented as complete.

## 10. Record operation without storing private prompts

- [ ] Create a request record before each model call.
- [ ] Group stages under one workflow ID.
- [ ] Record model, status, duration, tokens and tool actions.
- [ ] Keep failed and interrupted requests visible.
- [ ] Version any public pricing estimate used for cost reporting.
- [ ] Exclude prompts, private source text, generated documents and secrets from usage tables.

**Gate:** Operators can diagnose cost and failure without turning telemetry into another private-content store.

## 11. Test the boundaries

- [ ] Unknown stable ID is rejected.
- [ ] Duplicate operation target is rejected.
- [ ] Protected factual field is rejected.
- [ ] Unsupported requirement remains a gap.
- [ ] Prompt injection inside external material does not expand model authority.
- [ ] Missing template binding stops rendering.
- [ ] Invalid structured output fails visibly.
- [ ] Failed conversion publishes nothing.
- [ ] Separate profiles cannot share private storage paths.
- [ ] Deployment rollback restores the last healthy release.

**Release gate:** A reviewer can follow one final sentence back through the output binding, semantic operation and verified source evidence that allowed it.
