Dashboard
● Gate BLOCKED
System map
10 units · gate BLOCKED · 0 proven / 2 unproven
Green✓
4
0 proven · 2 unproven
Yellow⚠
2
signed, not proven
Red✕
1
contradicts its spec
Unsigned✎
2
awaiting a signature
Pink◆
1
no spec — blocks the gate
A drill-down tree. The box on the left is where you are; its contents branch to the right. Click a container › to zoom into it, click the left box or ↑ Up a level to zoom out, and click a unit to open its spec, code & checks.
Recent changes
Commands
Every
yay command and its flags. Passphrases/keys come from your .env; run yay help in the terminal for the terse version.yay init [dir]
Guided setup, in order: files (+ .gitattributes for auto-merging ledgers) → signing key (+ this clone’s Cell-id shard) → adopt → Brief tags → Constitution → project AI (one provider powering System Plan, Ask & the spec-adversary) → foundation seal. Signing key: local, mobile over your LAN, or mobile over relay.yaylayer.com (off-LAN, end-to-end encrypted).
--key local|mobilesigning-key type (mobile = pair your phone)--relay / --lanmobile transport: hosted relay.yaylayer.com (off-LAN) or your local network--name <you>signer name on every seal--tags <set>Brief-tag starter set (technical, responsibility, component, layer, area, product)--adopt / --no-adoptscaffold specs over existing code--constitution <keys|all>write the Constitution into AI-harness files--plan / --no-planconfigure the project AI (System Plan, Ask, adversary)--provider anthropic|openai|customAI provider (+ --base-url, --model, --api-key)--durablealso keep an encrypted archive of signed source--foundation guarded|strict / --no-foundationfoundation-seal postureyay keygen --name <you>
Create your ed25519 signing key (public → roster, private → encrypted keystore).
--passphrase <p>or the YAY_PASSPHRASE env varyay pair [--name you]
Pair your phone as the signer — scan the QR; the private key stays on the phone. The FIRST pairing (no roster yet) makes the phone the trust root itself, so no local key is ever needed. Served over HTTPS by default.
--name <you>attach the phone key to this identity--relay / --lanroute via relay.yaylayer.com (off-LAN, E2E) or the local network--no-httpsdisable TLS (default: mkcert-trusted cert if available, else self-signed)yay enroll --name X --pubkey <b64>
Enroll another signer via an OWNER-signed roster event.
--role owner|signerrole to grant (default signer)--by <owner>which owner authorizes it--phoneauthorize on an owner’s phone (no local key needed)yay invite "Bob"
Mint a 30-min, one-time link a teammate opens to request to join — they make their key, you get an approval on your phone (verify the 6-digit code, tap Approve). No pubkey to copy. Needs a running dashboard.
--role owner|signerrole to grant on approval (default signer; owner can enroll/revoke others)yay revoke --name X
Revoke a compromised/rotated key (or a whole identity) via an owner-signed event. Past approvals stay attributed; refuses if it would leave no owner.
--pubkey <b64>revoke just this key (omit to remove the whole identity)--phoneauthorize on an owner’s phoneyay reroot
Retire the current trust root and establish a new one — recovery for a lost/compromised root key. A trust discontinuity: re-sign specs and repoint the CI pin afterward.
--phoneroot the new key on your phone (phone-as-genesis)--name <you>new local owner name--forceskip the confirmation promptyay adopt [path]
Scaffold draft (unsigned) spec blocks over existing code.
--drypreview what would be addedyay sign [--cell IDs]
Approve the current specs — appends a signed seal. Uses THIS project’s signing method automatically (phone or local); no flag needed. If a dashboard is running, the request pops up on the phone you already scanned.
--brief "<text>"the signed Brief prose, REQUIRED by default (read-only on the phone: Accept or Send back; prompted if omitted at a terminal)--title "<headline>"a short title over the Brief — the scannable headline in the ledger, clouds and phone--tags "A,B"tag the Brief from the project pool (see yay tags) — required when a pool exists; --no-tags to skip--name "<signer>"sign as / route to that signer — a teammate over relay gets it in their inbox (fire-and-return, returns a request id)--check [id]collect a routed teammate’s signature and write the seal--phone / --localforce the device (default = the project’s method)--no-briefskip the Brief for a trivial re-sign--relay / --lanphone transport override--cell <ids>only these Cells (comma-separated)yay inbox
Print YOUR on-duty relay link (+ QR) — open it on your phone and leave it up to receive approval requests teammates address to you with `yay sign --name "You"`.
yay requests [done <id>]
The AI’s inbox of plain requests queued from the dashboard’s “Request a change” button. The AI turns each into a polished Brief + Cells to sign.
done <id> / clearremove a handled request (or all)yay tags [--set id]
The project’s Brief-tag vocabulary — every Brief is tagged from it, so work can be sorted by concern over time. Six starter sets or a blank custom set; edit here or live in the dashboard Tags tab.
--set <id>switch to a starter set (technical, responsibility, component, layer, area, product) or custom (blank placeholders)add "Tag" / remove "Tag"edit the poolrename "A" "B"relabel a tag — blocked once it is used in a signed Brief (would split history)desc "Tag" "…"set a tag’s descriptionsetslist the six starter sets and their tagsyay policy [--init|--set]
Signing policy — who must sign what (neutral by default). A rule requires a specific person to sign Cells matched by path glob, spec tag, or module; the gate blocks any match they haven’t signed. Edit the draft in the dashboard Policy tab or the file, then --set owner-signs it into the roster (tamper-evident).
--initwrite a commented policy.json template--setowner-sign the draft policy.json into effect (routes to your phone)yay grant [--for 2h] [--count 20]
AUTOPILOT (delegated execution): an owner-signed grant lets the AI approve in-scope, non-sensitive Cells (delegated) unattended until it expires or hits the count. Sensitive / code-pinned Cells always still need a real signature.
--for <dur>time window, e.g. 2h, 90m, 1d (default 2h)--count <n>max delegated approvals (default 20)--cell <ids>scope to named Cells (else all non-sensitive)list / revoke [id]show active grants / stop oneyay ratify [--sign]
List delegated Cells awaiting ratification (produced under a grant, not human-reviewed); --sign signs them for real.
--signsign the delegated approvals for real (human)yay verify [--strict] [-d]
The gate: paint every Cell + run the behavioural prover & mutation grading.
--strictnon-zero exit if blocked (for CI)-d, --detailsprint each spec, code & checks--problemsshow only non-green Cells--no-mutateskip mutation gradingyay test [--test "cmd"]
Run the project’s OWN test suite (package.json "test" / config.test) — the runtime backstop for what per-Cell checks can’t reach. Non-zero exit on failure (for CI).
--test "<cmd>"the command to run (else package.json test)yay adversary [--cell IDs]
Spec-only adversary: an LLM sees ONLY each Cell’s spec (never the code) and writes probes to BREAK it, run against the real code. A break is a genuine spec↔code violation. Needs an LLM key.
--cell <ids>only these Cells--provider …same provider config as the System Planyay plan
AI-synthesize the high-level System Plan → .yaylayer/plan.json.
--provider anthropic|openai|customLLM provider (key from .env)--base-url <url>custom / OpenAI-compatible endpoint (Ollama, LM Studio, vLLM — key optional)--model <m>model idyay map [-o file.html]
Write this HTML site (Map / Files / System Plan / Briefs / Tags / Policy / Signers / Commands).
-o <file>output path--no-planomit the System Plan entirely--replanforce plan regenerationyay dashboard [--port N]
Live control panel + phone relay: serves the map (auto-refreshes) with on-demand buttons — ➕ Request a change (queue a request your AI turns into a Brief to sign), ▷ Preview (run a package.json script — dev server, build — with a live link + Stop), Changes, Run tests, Adversary, Regenerate System Plan — AND routes pair/sign/authorize to the phone you scanned ONCE. Has Briefs, Tags and Policy tabs. Leave it running. HTTPS by default; the phone installs the cert from the /trust page for warning-free https.
--port <n>port (default 48757)--openopen it in your browser--no-httpsdisable TLS (default: mkcert-trusted cert if available, else self-signed)yay gate [dir]
Write the CI gate pipeline for your host and print its one-time branch-protection steps. Not GitHub-only.
--for <platform>github (default), azure, gitlab, bitbucket, gitea, gerrit--hookalso install a local pre-push gate--scope <dir>gate only a subfolder--forceoverwrite existing filesyay protect [--mode …]
FOUNDATION SEAL: owner-sign a baseline of the FIXED core files (Constitution, CI workflow, .gitignore, protocol files) so any later change is REVEALED at verify. Re-run it to RE-SEAL after a legitimate change — the dashboard’s 🛡 Re-seal foundation button does exactly this (approve on your phone).
--mode guarded|strictguarded warns; strict blocks the gate on drift (default guarded)--add / --remove <glob>add/remove a watched path--ignore <glob>exclude an expected-churn path from the seal--offdisable the seal (owner-signed)yay ask "<question>"
Ask your configured system AI about THIS repo (primed with live state — Cells, briefs, grants, rejections, the gate) AND the manual. Same as the dashboard Ask tab. Needs an LLM key in .env.
--provider …override the configured provider/modelyay id
Show THIS working copy’s Cell-id shard and the next id it would mint. New Cells are C-<shard>-n, with a per-clone shard, so ids never collide when branches merge.
yay merge
Run after a git merge/pull: re-verify and list anything the merge left behind — id collisions (only possible for legacy flat ids) and Cells edited on both sides that need re-signing. A botched merge never goes green silently.
yay batch [N|on|off]
How the AI groups small changes into one Brief before asking you to sign. Default on, barrier 5.
<N>set the barrier (ask to close a batch after N small changes)on / offbatching on, or a Brief per changeyay constitution --for <keys>
Write the Constitution where an AI harness auto-reads it.
--for <keys|all>claude, agents, copilot, cursor, windsurf, cline, gemini, generic--listlist the harnessesyay attest [list|verify]
The MACHINE verifier signs its own verdict over the current tree — a chained, capability-versioned attestation. Anyone can re-check it (also at yaylayer.com/verify).
listshow the attestation chainverifyre-check the latest attestation--forceattest even a blocked gate (recorded as such)yay archive [install|--restore]
DURABLE mode: keep an encrypted, sha256-anchored archive of signed source (secret scan + signed tombstones) so provenance survives even if working files are lost.
installadd the git hook that updates the archive--restorerestore signed source from the archive--verifyre-check archive integrity--forget <id>tombstone an entry (signed)yay capability
Show the verifier’s derived capability descriptor (what it can and cannot prove) and flag drift from the signed attestation.
yay reverify [--all] [posture …]
Re-attest the current tree, or --all: replay every preserved (Durable) state through today’s verifier and diff vs its original verdict — a keyless "upgrade report." Never rewrites old Green.
--allthe historical sweep (keyless report)--attestmint signed, append-only reverification records (needs the verifier key)--since <date> · --eligiblefilter the sweep-o <file> · --jsonsave / machine-readable reportposture off|guarded|strictgrandfathering: off (default) · guarded (warn) · strict (block until history is re-verified)yay witness · metrics
Integrity witness (cross-check the attestation chain, spec archive, and git-vs-ledger coverage) · earned-autonomy metrics (how delegated work has held up).
yay status
One-line health summary of the project.
Generated by
yay map · zoomable hierarchy · green = code proven to match a signed spec, pink = no spec · ▲N = Cells that depend on this (blast radius) · unused? = no callers found.