One remote operation, completely proved
The first two-machine experiment is intentionally narrower than the vision. It should prove the constitutional boundary before scaling the field.
A remote authenticated participant receives one expiring lease for one Local Repomix RepositoryContext operation against one declared directory. The participant invokes it once. The owner revokes the lease. A replay is rejected. No unrelated filesystem content, credential or browser state crosses the boundary.
Acceptance sequence
- RegisterResolve one durable RepositoryContext actor and its current machine binding.
- LeaseIssue one narrow operation scope with explicit expiry and owner identity.
- InvokeSubmit one operation ID; duplicate delivery must produce one logical effect.
- ObserveBind result hash, source boundary and postcondition evidence to the same operation.
- RevokeOwner revocation takes effect immediately; the next invocation is denied.
- DisconnectNetwork loss becomes DISCONNECTED or REBINDING, never focused-target fallback.
- RestartActor rebinds after process or machine restart without changing caller identity.
- AuditProve no credential, profile or unrelated path disclosure occurred.
Why this matters
This one operation is the seed crystal. If the field can preserve identity, scope, idempotency, revocation, evidence and recovery across two separately owned machines, the same constitutional machinery can later govern browser tabs, models, experiment runners, publication actors and human review.
Scale the actors only after the lease can survive contact with reality.