Submission, validation, review, approval, publishing, and monitoring each had different evidence and authority requirements.

Turn a watched review queue into a testable workflow.
This worked example maps the Marketplace template lifecycle from submission through monitoring, then tests it with representative local fixtures. It runs in shadow mode only. Nothing is written, published, or approved in production.
- Status Prototype
- Mode Shadow only
- Cases 5 replayed
- Writes None
Every claim here traces back to an artifact.
The worked example now answers one question: what changed for the operator, how the workflow was compiled, which artifacts remain owned, and what evidence makes the prototype claim inspectable.
Spend less time rebuilding context.
The prototype turns a known operating path into explicit contracts and replayable decisions. These are prototype measurements, not customer ROI claims.
A missing approval, unsupported claim, or unknown action could not safely inherit authority from the surrounding process.
The compiler validates the boundary, generates linked operating artifacts, replays representative cases, and fails closed.
Describe. Map. Compile. Simulate. Pilot.
Each stage narrows uncertainty without silently expanding authority. Operate begins only after a separate live-runtime, approval, rollback, and retention decision.
Name objects, events, states, owners, evidence requirements, and runtime targets.
Map-shaped contracts show which work can pass, wait for approval, or stop.
Produce schemas, tool and agent contracts, approval surfaces, evals, receipts, and a read-only console.
Exercise passing, approval-required, blocked, insufficient-evidence, and unknown-action outcomes.
The current prototype stops before deployment, external writes, approvals, publishing, or credential changes.
The map produces artifacts for all three tiers.
The package points to the existing systems that own live state and execution. It does not replace submission, validation, review, Control, or the shared system foundation.
Shows the records the workflow reads, the states it can enter, and the evidence saved after each change.
Shows which tools the agent may call, how a case is replayed, and what the operator sees while work runs.
Shows who may act, when approval is required, what happens when evidence is missing, and which unknown actions must stop.
The same input produced the same governed bundle twice.
The verifier compiles from clean directories, compares every generated file byte for byte, checks content hashes, and requires explicit outcome coverage.
Content-hashed generated artifacts
Representative workflow cases
Pass, approval-required, and blocked outcome classes
Clean compilations compared byte for byte
Pass: 1 · Approval required: 1 · Blocked: 3 · Governance complete: true
Representative fixture evidence. No client outcome or production execution is claimed.- 15 content-hashed artifacts
- 5 representative cases
- 3 outcome classes
- 2 clean compilations
Bring the handoff your team still watches by hand.
Map can define the systems, the owners, and the failure points first. Build follows only when the controlled lane is clear enough to test.
- Owner
- Workflow owner
- Authority
- Separate pilot approval
- Proof
- Map + compiled candidate + replay plan
- State
- review