Reveal progressively
Sparse checkout hides unselected directories and begins with every selected source path read-only.
Sparse Git worktrees that begin planning-locked, require context-blind plan review, and keep foundational changes behind exact parent-authorized patches.
Private preview. Product behavior shown here reflects the current application contract.
Protected roots remain parent-authorized in every phase.
Capsules reduce accidental access and bind plan, review, implementation, verification, and protected changes to exact artifacts.
Sparse checkout hides unselected directories and begins with every selected source path read-only.
A content-addressed plan enters a source-free blind bundle and opens implementation only after an exact GO verdict.
Parent-authorized protected proposals bind touched paths, pre-state, patch hash, and expected post-state.
A process sharing the human OS identity can deliberately bypass file modes. Strong hostile-process isolation still requires a separate principal, container, VM, or inaccessible parent broker.
Create a sparse worktree with source locked and one writable planning document.
Submit the frozen plan to a context-blind, source-free reviewer.
Open only the ordinary editable partition after an artifact-valid GO.
Freeze exact changes, audit integrity, and complete or deliberately reopen.
$ workspace-capsule workflow submit-plan /tmp/dowhere-author {"phase":"review-pending","sourceWritable":false,"planSha256":"2f90…"}
A process sharing the human OS identity can deliberately bypass file modes. Strong hostile-process isolation still requires a separate principal, container, VM, or inaccessible parent broker.