Integration recipes

Begin with a read-only or disposable local fixture. Move to a connected workflow only when every required source, executable, trust boundary, and recovery path is available.

A. Consult a local plan before answering

Profile: maude-plan-consultation/v1. An external caller asks Maude for the selected draft's recorded revision and check/lock summary. This credential-free profile uses real caller-created local state, not a substituted owner response. It starts no service and does not validate, accept, authorize, or execute the proposed work.

Run the versioned public-source example for exact prerequisites, source pins, setup, inspection, refusal and recovery instructions. The frozen manifest lists the tested composition; the qualification record separates clean reproduction from component negative controls. Tag publication is recorded on the guide.

your caller → bounded reader → Maude CLI --read-only inspect → your plan store
your caller ← available revision / unavailable reason ← Maude owner projection

The external boundary is the supplied reader, not direct database access or a new SDK. Its ten-second deadline, one-MiB stream limits, schema checks and no-automatic-retry behavior bound the consultation. Inspect availability in its JSON: an unavailable response also exits zero. Keep writers quiescent for a consistent aggregate; record identity does not establish current external conditions or legitimate reliance.

Separate inspection demo, outside this profile

AG-hosted Phosphor offers an independent deterministic display corpus and bounded loopback HTTP reader. Its public-source component demonstration reproduced the generated corpus, an honestly unavailable owner source, owned-server loss, and byte-identical same-corpus recovery. It does not read this Maude store and is not part of the released Maude profile. The display corpus is a fixture, not live state or legitimate reliance.

B. Governed bounded action

Released alpha profile Create one previously absent local file through retained independent review, explicit operator acceptance, exact-work authorization, Docket custody, one authority-neutral executor call, settlement, and read-only inspection. Start with the immutable 0.1.0-alpha.6 guide and manifest.

observation + currentness → exact plan → Nightshift occurrence
  → bounded independent review → explicit operator acceptance
  → AG one-use authorization → Docket custody → local executor
  → settlement → Phosphor inspection → fresh observation required

The qualified occurrence performed one actual 38-byte exclusive file creation. It retained one provider review, one AG spend, one Docket attempt, one successful settlement, and a later read-only observation of the exact bytes. AG then stopped at settled_observation_required; neither success nor inspection grants authority to continue.

The public newcomer command is deliberately credential-free: it clones the immutable release and exact public AG checker, verifies every released evidence digest, reproduces the cross-owner occurrence check, and confirms that a mismatched plan identity refuses. It inspects the real qualified occurrence; it does not pretend to repeat the paid review or effect.

Targeted qualification separately covers an operator/configuration mismatch before review or authority, an indeterminate post-sync/pre-success-record attempt reconciled without another execution, and retained-success response loss without another grant or copy. The release remains specific to the reviewed local-copy contract, named provider route, Linux environment, and local Docket permission profile. It is not a general executor framework or production deployment.

C. Connected disposable cache

Released alpha profile Refresh a disposable cache, check the recorded result, then remove it through a separate authorized run. Start with the immutable 0.1.0-alpha.4 guide and manifest. They connect actual NQ, Pulse, Maude, Nightshift, AG and Docket. Authoring, Standing and the caller-asserted role remain explicit synthetic inputs.

external observation → Pulse support → Maude locked plan
        → Nightshift proposal → AG one-use decision
        → Docket attempt → executor outcome → settlement
        → owner NQ result check → separate teardown decision

The deterministic example completed in an isolated namespace with enumerated public source, pinned public-built component programs, a copied Python environment, selected system tools, fresh local state, and the selected Docker socket. Independent inspection confirmed both successful settlements, NQ admission of the exact recorded result, a fresh same-family observation, and removal of the disposable project. The example uses synthetic authoring, Standing and a caller-asserted role reference; none establishes external provenance. The separate model-assisted tutorial records one bounded OpenRouter proposal, explicit human acceptance, and the same connected execution using the frozen accepted plan. Provider completion did not accept the plan or grant execution permission. Accepted-plan mode checks exact bytes but does not authenticate the accepting person; that acceptance must be established independently.

A newcomer followed the public input-generation path, completed the run using exact public-built artifacts, and inspected the retained results. A separate fresh environment installed the hash-locked public Python dependencies and passed setup validation. Existing-root replay refused before any new stage or Docker call. These checks reused verified public native builds; they do not claim an independent second native compilation.

The pinned Maude inspection, interruption and recovery instructions explain how to inspect the original attempt before another submission. Alpha.4 includes two pre-effect refusal cases, a clean 53-stage public-only run, existing-root refusal, and a separate post-settlement supervisor-interruption case. It does not establish general resume or interrupted-effect recovery. A recorded result is not present cache health, and settlement is not permission to continue. The selected Docker daemon is a trust boundary: retain the image digest, exclusive project name, original records and separate teardown authority.

Additional working example: acquisition and attention

Read a local queue and retain an attention decision connects actual Monitor, NQ, Pulse and Nightshift through an external caller. Public-only reproduction includes duplicate, changed-catalog and stale-state controls. The opt-in local-inbox route delivers one protected file without enabling webhook networking; human receipt remains unestablished. It does not replace the governed-action or connected-cache recipes above.

Saved-check recurrence and local attention

Evaluate a saved SQLite check and deliver local attention uses actual Monitor, NQ and Nightshift with pinned public sources. It preserves maintenance separately from a failed check, reconciles duplicate evaluation and delivery, and inspects retained results. This finite example is not an installed application monitor or a replacement for B/C.

Choosing safely

Return to the composition matrix or inspect the component inventory.