4.0.0 — Hosted collaboration & the open-core structural finish

Milestone: 4.0.0 (open) · Status: declared (not yet active) · Declared: 2026-09-04 · Supersedes the retired 3.3.x declaration for the hosted/experience work · Advances: epics #1800 (SaaS sync & event-envelope hardening), #1091 (Team Kitty launch gate), #3322 (CLI auth & token-lifecycle reliability), #2173 (infra-to-logic ports), #2519 (charter authoring & lifecycle), #3549 (event-log integrity).

Why now

A release-queue reconciliation on 2026-08-23 retired the 3.3.x milestone (its open work re-triaged into 4.0.0 or Product backlog), repurposed the former 3.2.x milestone (#4) into Product backlog, and split the near-term work into discrete 3.2.6 (stabilization, code-complete), 3.2.7 (post-reconciliation follow-ups — doctrine-term renames, profile-load consolidation, perf CI, dedups), and 4.0.0 (this cycle) milestones. 4.0.0 is the largest open milestone (80 open issues) and had no declaration-of-intent, breaking the project's own release-goals convention (one durable declaration per milestone). This document is that declaration. The taxonomy re-anchor that surfaced the gap is recorded in the milestone roadmap's 2026-09-04 addendum.

Theme

With 3.2.x's core-domain single-sources-of-truth substantially in place and 3.2.6 shipped clean, 4.0.0 turns to hosted collaboration and next-generation product capabilities — the hosted Team Kitty surface (sync, consent/identity, auth, launch) and the charter/runtime depth that builds on the stabilized core. It is also the intended landing zone for the open-core structural strangler that 3.2.x exists to finish — committed to this cycle by operator decision (2026-09-04). Same discipline as the prior cycles: no new shadow paths — route or extract onto an existing authority, never build a parallel one.

Goals

G1 — Hosted collaboration (Team Kitty)

Make the hosted surface a coherent, trustworthy product rather than a set of bolt-ons. The durable invariants and sub-areas were held by the SaaS & Hosted Sync domain plan (retired 2026-09-06, Convergence #3881 — the surface re-homed to the authoritative upstream repos); this cycle ships their release-scoped work:

  • Sync & event-envelope integrity — sync never reports success while authored state is stranded; every synced event carries a contract-valid envelope. Epic #1800; load-bearing P0 #3278 (sync false success while MissionCreated stranded).
  • Consent & identity boundary — only explicitly consenting projects transmit, under one unambiguous project→identity resolution. Load-bearing P0 #3178 (wrong-authority egress); P1s #3197 / #3196 / #3198.
  • Auth & token lifecycle — a logged-in CLI stays authenticated, human auth is browser-mediated, machine/CI auth has a supported path, refresh failures are named. Epic #3322 (owns #3279 / #3277 / #3233).
  • Hosted rollout & launch gate — fail-closed-by-default rollout, named readiness failures, launch defaults. Epic #1091.
  • Event-log integrity — one canonical event store, honestly reported, delivered without silent loss. Epic #3549.

G2 — Next-generation product capabilities

Deepen the governance and runtime surfaces the stabilized core now supports:

  • Charter authoring & lifecycle robustness — the author/observe/reproduce paths, charter domain events, deterministic intake. Epic #2519 (moved 3.2.x → 4.0.0 in the reconciliation; see the Doctrine & Charter Domain Plan §3.1).
  • Infrastructure-to-logic separation — inject ports for FS, Clock, GitOps, SaaSQueue, Renderer; keep the core pure and stub-testable. Epic #2173 (moved 3.2.x → 4.0.0).

G3 — Finish the open-core structural strangler

The G1/G2 strangler spine the 3.2.x cycle exists to finish — see Structural strangler spine — committed to 4.0.0 — is the structural foundation for 4.0.0's hosted and next-gen work. Committed to 4.0.0 by operator decision (2026-09-04): the spine epics now carry milestone 4.0.0 on the live tracker.

Committed scope (verified milestone 4.0.0, 2026-09-04)

These epics and P0s carry milestone 4.0.0 on the live tracker:

Item Role Goal
#1800 Epic: SaaS sync & event-envelope hardening G1
#1091 Epic: Team Kitty launch gate G1
#3322 Epic: CLI auth & token-lifecycle reliability G1
#3549 Epic: event-log integrity G1
#3278 P0: sync reports success while MissionCreated stranded G1
#3178 P0: wrong-authority egress (FR-007 not discharged by FR-002) G1
#2519 Epic: charter authoring & lifecycle robustness G2
#2173 Epic: infrastructure-to-logic separation (ports) G2

Verify live state via gh issue view <n> --repo Priivacy-ai/spec-kitty before acting; the milestone description carries the one-line pointer back here.

Structural strangler spine — committed to 4.0.0 (2026-09-04)

The open-core structural strangler spine — the G1/G2 structural work the 3.2.x cycle exists to finish — is committed to 4.0.0 by operator decision (2026-09-04). It had sat in Product backlog (validated, but on no committed release — exit criterion 8's anti-drift guard fired in a blind spot, and the work rode into Product backlog silently instead of onto a release). The epics below now carry milestone 4.0.0 on the live tracker:

Epic Role Milestone
#1619 mission-execution-context root (P0) 4.0.0
#1797 degod / unshim delivery 4.0.0
#1868 seam-binding enabler (WS4 / WS6) 4.0.0
#1746 Mission Clarity Layer (P1) 4.0.0
#2160 coord-artifact authority (P0) 4.0.0
#1676 deterministic structured authoring (P0) 4.0.0
#2466 / #2467 / #2468 pack ecosystem + extensibility kinds 4.0.0
#2539 pack trust / verified distribution 4.0.0
#645 / #3179 stable public API surface for doctrine & charter 4.0.0

Security-debt coupling. The 21 SonarCloud security findings (the sole failing quality gate — 17 S6350 subprocess + 3 S2083 path-traversal, all pre-dating any current release candidate) map almost 1:1 onto the degod slices above, so the security backlog rides with this structural remediation — now both scheduled in 4.0.0. The 3 S2083 blockers remain a called-out ~90-min targeted fix that can land independent of any wave.

Non-goals

  • Re-opening the 3.2.x core-domain SSOTs — they are the stabilized foundation 4.0.0 builds on, not scope to re-litigate.
  • The 3.2.7 stabilization tail — doctrine-term renames, profile-load consolidation, perf CI, and dedups ship under milestone 3.2.7, not here.

Success criteria (placeholder — refine when the cycle activates)

  • [ ] Hosted sync holds the no-false-success and no-loss invariants under load; the P0 cluster (#3178 / #3278) is closed and the consent/identity boundary is enforced, not instructed.
  • [ ] CLI auth stays authenticated across the device-flow and machine/CI paths; refresh failures are diagnosed by name (#3322 discharged).
  • [ ] The Team Kitty launch gate (#1091) is met: default hosted URL, named readiness failures, fail-closed-by-default rollout.
  • [ ] Charter authoring/lifecycle (#2519) and the infra ports (#2173) land against the stabilized core with no new shadow path.
  • [ ] The structural strangler spine (committed to 4.0.0 on 2026-09-04) lands or is explicitly re-dispositioned — no epic left implicitly "cycle work" while off a release.

Emergent patches

Declared when the cycle activates (3.2.7 stabilization tail lands first). Following the emergent-milestone model: each patch advances one of the goals above; the milestone stays open until the goals are structurally met.