Decisions governing the orchestrator's own design (not the projects it generates — those
get their own docs/adr/ from the templates). Lightweight Michael Nygard format; numbering
is sequential and never reused. Template: the generated
templates/docs/adr/template.md.
| ADR | Title | Status |
|---|---|---|
| 0001 | Three-layer genericity model (profiles, manifest, templates) | Accepted |
| 0002 | Interview-driven intake before generation | Accepted |
| 0003 | Generated repositories are self-governing | Accepted |
| 0004 | Seed profiles for C, C#, VB.NET, JS, PHP, Lua (SQL/CSS/HTML stay secondary) | Accepted |
| 0005 | Seed Scala/Kotlin/Swift/Dart/Ruby + legacy COBOL/Pascal (QBasic deferred) | Accepted |
| 0006 | Spec-correct manifest loader + real-parser gate for emitted YAML | Accepted |
| 0008 | Loader scalar fidelity (quote escaping, chomping) + PyYAML differential gate | Accepted |
| 0009 | CI supply-chain pinning (SHA-pin EADOS-authored workflows, kill @latest, pin+hash PyYAML) | Accepted |
| 0007 | Renderer write-containment, required-field validation, independent CI-YAML gate | Accepted |
| 0010 | Content-hash i18n freshness (squash-merge-proof) | Accepted |
| 0011 | EADOS — phase-based agentic delivery operating system (the pivot) | Accepted |
| 0012 | Rename EAAO → EADOS: repo, path, and bundle migration | Accepted |
| 0013 | Dependabot action-pin auto-remediation (workflow_run template re-sync) |
Accepted |
| 0014 | Inbound-contribution trust model (verify the change, never merge non-owner commits, adopt via co-author) | Accepted |
| 0015 | Web domain (shipped) + enterprise as an orthogonal posture flag, not a domain | Accepted |
| 0016 | Authoring-language model: confirmed doc/comment-language defaults, non-English choices as recorded exceptions | Accepted |
| 0017 | Model & effort routing: advisory-first, capability tiers not model names, dated per-host catalog | Accepted |
| 0018 | Ops & deployment perimeter: ops documents in scope, live infrastructure a recorded non-goal, deploy phase deferred |
Accepted |
| 0019 | Command-surface taxonomy: phases closed, design/audit sub-modes, bounded cross-cutting class, adapters+aliases; manifest required | Accepted |
| 0020 | Rename the brownfield phase refactor → migrate (naming honesty; frees refactor for the code-quality command); phase: refactor a deprecated alias for one minor |
Accepted |
| 0021 | Brownfield adoption route: /eados adopt as init's sibling intake; adoption: manifest block; init → audit/init → migrate legal by data, gated on in-process adoption-recorded |
Accepted |
| 0022 | Interaction policy as data (os/interaction/, ninth spec): confidence tags with evidence criteria, sycophancy denylist as config-overridable data, structured dissent, pushback splits claims-vs-decisions; enforcement ceiling instruct/verify/re-ground |
Accepted |
| 0023 | Scaffold routing surface: manifest items declare signals (never tiers), the renderer derives each item's advisory route through route_advice, the ROADMAP opens with a dated-catalog legend; plain-string items render unchanged |
Accepted |
| 0024 | Provider-agnostic capability routing (extends 0017): two-level provider/host catalog, resolution by capability not name, cost may only choose above the earned floor and never lower it, host identity from evidence with a loud unknown (never model self-report), extra effort level, enforceable catalog freshness |
Accepted |
| 0025 | The phase state writer: a workflow state declares who RECORDS its outcome (delivery_state + the run record) as distinct from who AUTHORS its artifact; held honest by the state-writer-authority gate |
Accepted |