Production verification

The authority boundary has been tested end-to-end.

LoadGuard's judge scenario verifies discovery, deterministic planning, validation, staging, pre-approval refusal, human UI authorization, approved commit, duplicate commit refusal, and an auditable ledger.

Production deployed

Cloudflare Workers

Build passing

Verified quality gate

28 tests

Planner, validator, WebMCP, authority

WebMCP verified

7 tools, no approval tool

Authority verified

APPROVAL_REQUIRED before approval

Idempotency verified

ALREADY_EXECUTED on replay

Evidence chain

The same fixture proves planning, approval, execution, and replay protection.

Baseline

TRK-042 starts with one urgent package inbound.

  • 8/9 loaded
  • 75.6% utilization
  • 993 kg / 1200 kg
  • MED-901 inbound
  • revision 1

Proposal

The deterministic candidate completes the target load.

  • 9/9 placed
  • 1011 kg
  • 78.4% utilization
  • VALID
  • 0 hard violations

Authorization

Commit before human approval is refused.

  • APPROVAL_REQUIRED
  • Active state unchanged
  • Human approves exact proposal in UI
  • Approval does not mutate active load

Execution

Approved execution updates the active truck once.

  • EXECUTED
  • MED-901 loaded
  • x=115, y=95, z=0
  • revision 1 -> 2
  • 0 hard violations

Idempotency

Duplicate execution is blocked.

  • ALREADY_EXECUTED
  • revision remains 2
  • 9/9 loaded
  • 1011 kg
  • 78.4% utilization

Review warnings

Warnings are visible without becoming hard failures.

The final valid plan can include non-blocking fragile-elevated review warnings for PKG-106 and MED-901. They are surfaced for human judgment while hard validation remains zero.

VALID with review warnings

FRAGILE_ELEVATED PKG-106
FRAGILE_ELEVATED MED-901

Workspace proof

Inspect the verified UI.

The workspace shows the active truck load, candidate proposal geometry, validation state, warnings, human approval controls, and activity ledger in one product view.

LoadGuard staged proposal verification screenshot