.{provider}/bindings/adapter.binding.md
.{provider}/bindings/adapter.binding.md continued, part 2 of 2.
| `{convention.grounding_threshold}` | RESOLVED | `1` | every claim in an authored artifact traces to evidence, with no partial grounding. |
| `{convention.max_recursion_depth}` | RESOLVED | `3` | the placement depth cap, counted from a governed root. |
| `{convention.medium_risk_threshold}` | ABSENT | — | no count-based risk banding. |
| `{convention.operator_mode}` | RESOLVED | `overseer` | how the owner takes part, as one of two values. Under `overseer`, the seats coordinate among themselves and never stop to ask the owner or wait on the owner. The owner writes entries into a venue in any form and anywhere in it, each seat's next wait delivers them as part of the diff, and every seat treats such an entry as new context the discussion must honor. A seat addresses the owner only when coordination has stalled. Under `interactive`, the seats bring decisions to the owner, as a question with four options and a recommendation first, and wait for the answer. |
| `{convention.projection_cap_chars}` | RESOLVED | `2000` | the projection is ONE line and a gate holds it there. A field named a one-liner is making a claim about its size, and where no check reads it, the name is documentation and the shape is a hope. |
| `{convention.read_token_budget}` | RESOLVED | `25000` | the reader's token cap. No board field may exceed what one read consumes, because reading in parts has a floor at one field. |
| `{convention.relevance_threshold}` | ABSENT | — | no scored document-relevance surface. |
| `{convention.role_taxonomy}` | RESOLVED | `config/taxonomy.config.ts` | the closed concern vocabulary, with its cross-slot agreement asserted at compile time. |
| `{convention.run_live_window_ms}` | RESOLVED | `600000` | how long an unreleased run claim is read as STILL RUNNING rather than as a run that died. A claim is the in-flight declaration a second caller reads before deciding whether to start a second measurement of the same tree, and without a window every claim reads as a dead run, which reports a crash on every concurrent invocation and teaches every reader to discount the line. The value is the consumer's because it depends on how long that consumer's whole-scope run takes, and a package cannot know its host's tree size. IT IS SET GENEROUSLY, AND THE DIRECTION IS DECLARED BECAUSE THE TWO ERRORS COST DIFFERENT THINGS: a window too LONG holds a dead claim, which costs a caller one re-invocation and announces itself, while a window too SHORT declares a live run dead and costs a lost write, which is silent and unrecoverable. The generosity is affordable because the window governs only what the witness cannot decide. An ABSENT process is read as dead immediately whatever the clock says, so a long window never hides a crash this machine can observe, and the window governs a present process and a claim recorded on another machine, where nothing portable states when an identity's holder started. |
| `{convention.secret_shapes}` | RESOLVED | `[]`, declared and empty | the credential shapes the secret gate looks for, each written as the token's prefix, a colon, and the shortest length a real credential of that shape has (for example `sk_live_:24`). The shapes belong to the host, because only the host knows which services it holds keys for. Empty means the gate has no shape to match and reports nothing. |
| `{convention.source_ext}` | RESOLVED | `md` · `ts` | the file types this package authors: documents and configuration. A host adds its own only where these gates are meant to reach them. |
| `{convention.source_extensions}` | RESOLVED | `.ts` · `.md` · `.json` | the file types this package authors. A host adds its own only where this package's gates are meant to reach them. |
| `{convention.stall_rounds}` | RESOLVED | `3` | rounds after which an unacknowledged item is a finding. It bounds a LIFETIME rather than a size, since a stall is literally a duration, so it stands in for no construct. |
| `{convention.timestamp}` | RESOLVED | `YYYY-MM-DD` | absolute dates, never relative. |
| `{convention.unreached_gate_fails}` | RESOLVED | `0` | whether an UNREACHED gate is a finding, which is the consumer's declaration rather than this package's guess: a deployment expecting to resolve the slot wants the red, and one that will never resolve it does not. Zero reports the state without failing, and any other value fails on it. |
| `{convention.venue_authority_concern}` | RESOLVED | `Coordination documents` | the CONCERN that holds venue and agenda management, named as a concern because a letter is an identity the index allocates and a concern survives a seat changing hands. Every venue-shaped write, such as raising a successor, deferring a question, retracting one or recording an agenda row, resolves the holding letter from the index row carrying this concern and refuses every other caller. ONE party manages the sequence: a venue raised, a question moved out of a discussion, or an agenda row written by whichever party happens to hold the form is a schedule with several authors, and the schedule is the one surface that cannot have them. |
## Limits
| slot | state | value | why |
| -------------------- | ------ | ----- | --------------------------------------------------------------------------------------------------------------------- |
| `{limits.max_files}` | ABSENT | — | no per-folder file cap. Placement is governed by concern, never by count. |
| `{limits.max_lines}` | ABSENT | — | a per-file line cap. This package does not gate host code size, and a host that wants one holds it in its own linter. |
## Execution
| slot | state | value | why |
| --------------------------------- | -------- | ------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `{execution.build_command}` | ABSENT | — | this package has no build, so nothing compiles and no artifact is produced. |
| `{execution.converge_command}` | RESOLVED | `npm run converge` | the convergence walk, which reports every ordering and MOVES a venue whole into the archive once all of them hold. Declared for the same reason the wait command is: a tool printing its own invocation form as a literal states a fact this surface already resolves, so the loudest copy of that fact, the one printed to every seat on every invocation, is the one with nothing behind it. |
| `{execution.denied_interpreters}` | RESOLVED | `[]`, declared and empty | interpreters the host's settings refuse. A tool reaching one is handed to the owner instead, and empty means the host denies none. |
| `{execution.document_generators}` | ABSENT | — | the HOST's own document generators, invoked in order, each as arguments to the runtime. ABSENT by default: this package's entry document ships rendered from the `docs` fields of `_manifest.json`, and the package runs no generator of its own, so the branch does not run. A host that generates its documents with its own tooling resolves this slot, and the dependency is then declared here rather than spelled as a host path inside a script. |
| `{execution.quality_command}` | ABSENT | — | the HOST's own quality toolchain entrypoint, if it keeps one: the command that runs its linters, its dead-code sweep and its formatter. RESOLVED means the pipeline runs it as one stage so a consumer has ONE chain rather than two, and the tools stay the host's. Nothing enters this package's manifest, which declares no dependencies precisely so a consumer needs no toolchain to verify a package built to adapt to any host. ABSENT means the stage does not exist and the run says so rather than reporting a green over a check that never ran. |
| `{execution.quality_concerns}` | RESOLVED | `[]`, declared and empty | which concerns of the host's quality toolchain the pipeline hands it, and the consumer elects them. The additive ones are the checks this package's own rules do not perform: its rules read structure, protocol and governance, and none of them reads a TYPE, so type-aware linting and a dead-code sweep find what no rule here looks for. A FORMATTER is elected deliberately rather than by default, because it rewrites every governed document and every source file into the host's house style, and this package declares no formatting of its own. That absence is a property, so imposing a style is a decision the consumer makes rather than one the pipeline makes for them. Empty means the stage runs nothing even where the command resolves. |
| `{execution.runtime_probe}` | ABSENT | — | no agent can observe a running system from here. A branch that would confirm a behavior by observing it does not run, and the claim is carried as owner-observed rather than as verified. |
| `{execution.verify_command}` | RESOLVED | `npm run govern` | the whole pipeline, whole scope, healing on. |
| `{execution.wait_command}` | RESOLVED | `npm run await` | the board write-and-wait tool. Every invocation declares its agent. |
## Resolution census
Derived on render, so it cannot disagree with the table above.
| section | RESOLVED | ABSENT | DEFERRED |
| ------------ | -------- | ------ | -------- |
| `project` | 8 | 17 | 1 |
| `surface` | 39 | 0 | 0 |
| `convention` | 23 | 6 | 0 |
| `limits` | 0 | 2 | 0 |
| `execution` | 5 | 4 | 0 |