SIGNAL · CLEAR
LAT 37.1°NLON 93.0°WVOL XVII · 2026
DISPATCH 042 — STRUCTURE OVER STACK·FIELD NOTE — AUDITABLE BY DESIGN·DOCTRINE — DEFENSIBLE UNDER SCRUTINY·NEW SPRINT WINDOW OPEN · Q3·DISPATCH 042 — STRUCTURE OVER STACK·FIELD NOTE — AUDITABLE BY DESIGN·DOCTRINE — DEFENSIBLE UNDER SCRUTINY·NEW SPRINT WINDOW OPEN · Q3·
N · 03
90 · S
System Brief · 03

Waypoint

CategoryExecution
StatusActive
MethodologyUntrusted-renderer architecture, honest run verbs
Index03 / 13

Origin

A governed build runtime with no cockpit is a process only its author can see. Atlas Orchestrator governs the run, but a headless run is invisible while it happens, its approval gates are files on disk, and its history lives in a state file. Waypoint was built so that a single operator can launch, watch, pause, approve, and stop a governed run from buttons — and so that the desktop application doing this is itself defensible. The founding position is that the IPC boundary is the product's reason to be trusted: a control surface for AI execution that could be talked into spawning a shell command would undo the governance it exists to display. Waypoint does not author graphs, does not write code, and does not duplicate the orchestrator's governance logic. It is a second MCP client to the same engine the executor uses.

Design

The lifecycle is the spine. A project attaches a master specification and successive dependency graphs; every graph in every state (draft, validated, frozen, superseded, archived) is listed, selectable, and rendered. Freezing a successor supersedes the prior contract in one transaction, never leaving zero or two live contracts, and is refused while a non-terminal run still references it. The frozen contract's authored identity, computed by the engine's own primitive, is stamped and displayed. Launching runs the frozen contract with real Claude Code and the real Atlas engine; the run directory is continuous across a project's runs, and the engine rules each encounter (restore, succession, or refusal) with its ruling relayed verbatim on the run view. The run verbs are honest: Stop is terminal; Pause lands at the next checkpoint; Resume is a manual act; Relaunch continues a crashed run from persisted state with a lineage-linked new row. Four discriminated pause kinds each carry their own banner. Approval gates are prepared and written by the app as records the engine consumes at the gate; operator guidance is delivered at the next checkpoint as context, never as authorization.

Structure

Three layers, one rule. The renderer is React and untrusted; the preload is a sandboxed, inert one-line-per-method message-passer with zero Node and no logic; the main process is privileged, and its repository layer is the only code in the application that holds a database handle or executes SQL. Security invariants are each verified with an adversarial test. Every process is created through one wrapper with shell: false and array arguments, so OS metacharacters in an instruction are inert data. No exposed channel takes a command string and executes it; every spawning channel starts a fixed executable chosen by main — claude, the resolved Atlas build, or git — and the renderer only ever picks a verb and sends ids. The preload runs with sandbox, context isolation, and node integration disabled; window.require does not exist in the renderer. File reads map an identifier to a path inside main and refuse absolute paths and traversal. A build row carries an instruction or a graph id, never both, enforced by the database. The evidence layer sits on top: a regression check that re-verifies done nodes and reopens any that regressed, a fail-closed evidence handoff bundle, a Field Record exporter producing dual output from one truth, and a time-anchor rider so the record renders its anchoring status in three ways rather than one. The built-in demo uses real gates and a scripted executor, so the demonstration is the product.

Defense

The record must not lie. The lifecycle waves recorded in the decision log are named for that rule: waived nodes render as waived, never as done; terminal_with_waivers is the engine's own term end to end; historical run views resolve to their archives instead of showing a successor's state; the run view narrates succession in the engine's words. The instruction-mode build console underneath — type an instruction, press run — has no governance and says so; the two paths are not blended, and an instruction build never acquires governance by proximity. The decision log also records what the proofs did and did not bind. The 116-second live proof established that the governed loop works from a Node harness; whether the shipped app could launch that loop was a separate claim, and the zero-token rehearsal that first ran it found two bugs invisible to every prior test. That finding is kept as a standing lesson: a proof binds only the exact path it ran. The evidence surfaces are honest in the same way — Waypoint provides run-directory continuity, the engine rules the encounter, and the harness-side forged-record alarm is detection layered on the engine's chain, not a substitute for it.

Status

Active. Development underway by June 29, 2026 (run-derived fixtures June 29–30); decision log established July 3; Master Specification v1.0 committed in-repo and bylined Atlas North Institute · Brandon King. Released as Waypoint 1.1.0 bundled with Atlas Orchestrator 1.5.0 on July 10, with a Windows installer. Four lifecycle waves landed July 8; evidence handoff, Field Record exporter, built-in demo, and time-anchor riders landed July 9; skills library July 10. Companion and derivative of Atlas Orchestrator; together they are the reference implementation of GAD, and Waypoint's build corpus supplies the GAD field-record evidence. Repository has no license file.