4.0.0 — Hosted collaboration & the open-core structural finish
Milestone: 4.0.0 (open) ·
Status: declared (not yet active) · Declared: 2026-09-04 ·
Supersedes the retired 3.3.x
declaration for the hosted/experience work · Advances: epics #1800 (SaaS sync &
event-envelope hardening), #1091 (Team Kitty launch gate), #3322 (CLI auth & token-lifecycle
reliability), #2173 (infra-to-logic ports), #2519 (charter authoring & lifecycle), #3549
(event-log integrity).
Why now
A release-queue reconciliation on 2026-08-23 retired the 3.3.x milestone (its open work
re-triaged into 4.0.0 or Product backlog), repurposed the former 3.2.x milestone (#4) into
Product backlog, and split the near-term work into discrete 3.2.6 (stabilization,
code-complete), 3.2.7 (post-reconciliation follow-ups — doctrine-term renames,
profile-load consolidation, perf CI, dedups), and 4.0.0 (this cycle) milestones. 4.0.0
is the largest open milestone (80 open issues) and had no declaration-of-intent, breaking
the project's own release-goals convention (one durable declaration per
milestone). This document is that declaration. The taxonomy re-anchor that surfaced the gap
is recorded in the milestone roadmap's
2026-09-04 addendum.
Theme
With 3.2.x's core-domain single-sources-of-truth substantially in place and 3.2.6 shipped clean, 4.0.0 turns to hosted collaboration and next-generation product capabilities — the hosted Team Kitty surface (sync, consent/identity, auth, launch) and the charter/runtime depth that builds on the stabilized core. It is also the intended landing zone for the open-core structural strangler that 3.2.x exists to finish — committed to this cycle by operator decision (2026-09-04). Same discipline as the prior cycles: no new shadow paths — route or extract onto an existing authority, never build a parallel one.
Goals
G1 — Hosted collaboration (Team Kitty)
Make the hosted surface a coherent, trustworthy product rather than a set of bolt-ons. The durable invariants and sub-areas were held by the SaaS & Hosted Sync domain plan (retired 2026-09-06, Convergence #3881 — the surface re-homed to the authoritative upstream repos); this cycle ships their release-scoped work:
- Sync & event-envelope integrity — sync never reports success while authored state is
stranded; every synced event carries a contract-valid envelope. Epic #1800; load-bearing
P0 #3278 (sync false success while
MissionCreatedstranded). - Consent & identity boundary — only explicitly consenting projects transmit, under one unambiguous project→identity resolution. Load-bearing P0 #3178 (wrong-authority egress); P1s #3197 / #3196 / #3198.
- Auth & token lifecycle — a logged-in CLI stays authenticated, human auth is browser-mediated, machine/CI auth has a supported path, refresh failures are named. Epic #3322 (owns #3279 / #3277 / #3233).
- Hosted rollout & launch gate — fail-closed-by-default rollout, named readiness failures, launch defaults. Epic #1091.
- Event-log integrity — one canonical event store, honestly reported, delivered without silent loss. Epic #3549.
G2 — Next-generation product capabilities
Deepen the governance and runtime surfaces the stabilized core now supports:
- Charter authoring & lifecycle robustness — the author/observe/reproduce paths, charter domain events, deterministic intake. Epic #2519 (moved 3.2.x → 4.0.0 in the reconciliation; see the Doctrine & Charter Domain Plan §3.1).
- Infrastructure-to-logic separation — inject ports for FS, Clock, GitOps, SaaSQueue, Renderer; keep the core pure and stub-testable. Epic #2173 (moved 3.2.x → 4.0.0).
G3 — Finish the open-core structural strangler
The G1/G2 strangler spine the 3.2.x cycle exists to finish — see Structural strangler spine — committed to 4.0.0 — is the structural foundation for 4.0.0's hosted and next-gen work. Committed to 4.0.0 by operator decision (2026-09-04): the spine epics now carry milestone 4.0.0 on the live tracker.
Committed scope (verified milestone 4.0.0, 2026-09-04)
These epics and P0s carry milestone 4.0.0 on the live tracker:
| Item | Role | Goal |
|---|---|---|
| #1800 | Epic: SaaS sync & event-envelope hardening | G1 |
| #1091 | Epic: Team Kitty launch gate | G1 |
| #3322 | Epic: CLI auth & token-lifecycle reliability | G1 |
| #3549 | Epic: event-log integrity | G1 |
| #3278 | P0: sync reports success while MissionCreated stranded |
G1 |
| #3178 | P0: wrong-authority egress (FR-007 not discharged by FR-002) | G1 |
| #2519 | Epic: charter authoring & lifecycle robustness | G2 |
| #2173 | Epic: infrastructure-to-logic separation (ports) | G2 |
Verify live state via gh issue view <n> --repo Priivacy-ai/spec-kitty before acting; the
milestone description carries the one-line pointer back here.
Structural strangler spine — committed to 4.0.0 (2026-09-04)
The open-core structural strangler spine — the G1/G2 structural work the 3.2.x cycle exists to finish — is committed to 4.0.0 by operator decision (2026-09-04). It had sat in Product backlog (validated, but on no committed release — exit criterion 8's anti-drift guard fired in a blind spot, and the work rode into Product backlog silently instead of onto a release). The epics below now carry milestone 4.0.0 on the live tracker:
| Epic | Role | Milestone |
|---|---|---|
| #1619 | mission-execution-context root (P0) | 4.0.0 |
| #1797 | degod / unshim delivery | 4.0.0 |
| #1868 | seam-binding enabler (WS4 / WS6) | 4.0.0 |
| #1746 | Mission Clarity Layer (P1) | 4.0.0 |
| #2160 | coord-artifact authority (P0) | 4.0.0 |
| #1676 | deterministic structured authoring (P0) | 4.0.0 |
| #2466 / #2467 / #2468 | pack ecosystem + extensibility kinds | 4.0.0 |
| #2539 | pack trust / verified distribution | 4.0.0 |
| #645 / #3179 | stable public API surface for doctrine & charter | 4.0.0 |
Security-debt coupling. The 21 SonarCloud security findings (the sole failing quality
gate — 17 S6350 subprocess + 3 S2083 path-traversal, all pre-dating any current release
candidate) map almost 1:1 onto the degod slices above, so the security backlog rides with this
structural remediation — now both scheduled in 4.0.0. The 3 S2083 blockers remain a
called-out ~90-min targeted fix that can land independent of any wave.
Non-goals
- Re-opening the 3.2.x core-domain SSOTs — they are the stabilized foundation 4.0.0 builds on, not scope to re-litigate.
- The 3.2.7 stabilization tail — doctrine-term renames, profile-load consolidation,
perf CI, and dedups ship under milestone
3.2.7, not here.
Success criteria (placeholder — refine when the cycle activates)
- [ ] Hosted sync holds the no-false-success and no-loss invariants under load; the P0 cluster (#3178 / #3278) is closed and the consent/identity boundary is enforced, not instructed.
- [ ] CLI auth stays authenticated across the device-flow and machine/CI paths; refresh failures are diagnosed by name (#3322 discharged).
- [ ] The Team Kitty launch gate (#1091) is met: default hosted URL, named readiness failures, fail-closed-by-default rollout.
- [ ] Charter authoring/lifecycle (#2519) and the infra ports (#2173) land against the stabilized core with no new shadow path.
- [ ] The structural strangler spine (committed to 4.0.0 on 2026-09-04) lands or is explicitly re-dispositioned — no epic left implicitly "cycle work" while off a release.
Emergent patches
Declared when the cycle activates (3.2.7 stabilization tail lands first). Following the emergent-milestone model: each patch advances one of the goals above; the milestone stays open until the goals are structurally met.
Links
- Milestone: https://github.com/Priivacy-ai/spec-kitty/milestone/8 · Convention:
release-goals.md· Prior cycle:3.2.x.md - Retired predecessor declaration:
3.3.x.md(milestone3.3.xclosed 2026-08-23) - Durable domain plans: SaaS & Hosted Sync (retired 2026-09-06, Convergence #3881) · Doctrine & Charter
- Operator execution roadmap + taxonomy re-anchor: 3.2.x Milestone Roadmap