flowchart TB
START(["Start integration"]) --> CONNECT["Connect environment
platform, gateway, case"]
CONNECT --> DISCOVER["Discover or register
agent, tools, executor, verifier"]
DISCOVER --> PURPOSE["Define purpose, owner,
tenant and environment"]
PURPOSE --> AUTH["Bound authority
operation, resource, path, host, scopes"]
AUTH --> EFFECT["Define Effect Contract
preconditions, expected and forbidden effects"]
EFFECT --> OVERSIGHT["Choose oversight
automatic, approval, deny"]
OVERSIGHT --> GENERATE["Generate draft contracts
Action Claim template + Rego tests"]
GENERATE --> VALIDATE{"Schema and policy
validation passes?"}
VALIDATE -->|"no"| REPAIR["Repair invalid or incomplete input"]
REPAIR --> GENERATE
VALIDATE -->|"yes"| SIM["Simulate allowed, denied,
approval, replay, stale state, mismatch"]
SIM --> SAFE{"Required tests pass?"}
SAFE -->|"no"| REDESIGN["Reduce authority or fix policy / verifier"]
REDESIGN --> AUTH
SAFE -->|"yes"| REVIEW["Peer and accountable-owner review"]
REVIEW --> APPROVED{"Approved for preview?"}
APPROVED -->|"no"| GENERATE
APPROVED -->|"yes"| PUBLISH["Publish immutable version
and bind deployment digest"]
PUBLISH --> MONITOR["Monitor decisions, outcomes,
incidents and bypass exposure"]
CURRENT["CURRENT: register APIs and local tests"] -.-> DISCOVER
REQUIRED["REQUIRED: draft/review/promotion, signed bundles,
deployment attestation and rollback APIs"] -.-> PUBLISH