You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A Chronicle operator or automation caller needs CLI inspection and admitted repair to preserve the same authority, operation identity, lifecycle, limitations, and evidence as Workbench and the Chronicle API. A local confirmation prompt or success message must not become a separate operations policy.
Desired behavior
Inventory every Chronicle CLI operational read, export, and mutation command.
Map each command to a versioned Chronicle resource/capability contract and explicit admitted profile.
Direct mutation is migrated, limited to an explicit development profile, disabled, or withdrawn until the Chronicle governed-operation contract admits it.
CLI preserves plan ID/revision, operation ID, canonical state, errors, compatibility, progress, reconciliation, and receipt ID/content.
Interactive confirmation binds the exact immutable plan; --yes cannot bypass server authorization, policy, idempotency, or receipt requirements.
Noninteractive mutation fails closed unless an accepted capability/policy explicitly permits it.
Structured output has a versioned schema, bounded size/pagination, classification-aware field policy, redaction/omission reasons, and stable nonzero failure behavior.
Default human output does not expose unrestricted event payloads, read-model instances, failure internals, stack traces, credentials, or sensitive target values.
Event-store/namespace/tenant/resource/action scope and target environment are explicit; ambiguous or stale targeting fails closed.
API/Workbench/CLI conformance fixtures prove the same IDs, state, limitations, and receipts for each admitted subset.
Failure evidence
Exercise stale plan, revoked authorization, unsupported/incompatible capability, duplicate retry, process interruption, receipt/evidence failure, cancellation, partial/Unknown state, and output redaction. A completed CLI process is not success unless Chronicle reports the verified terminal outcome.
Non-goals
Making CLI the owner of Chronicle lifecycle or policy.
Claiming mutation parity for every Workbench/API capability.
Approving production mutation, support, SLA, managed responsibility, or public maturity by issue creation.
Cratis user need
A Chronicle operator or automation caller needs CLI inspection and admitted repair to preserve the same authority, operation identity, lifecycle, limitations, and evidence as Workbench and the Chronicle API. A local confirmation prompt or success message must not become a separate operations policy.
Desired behavior
--yescannot bypass server authorization, policy, idempotency, or receipt requirements.Failure evidence
Exercise stale plan, revoked authorization, unsupported/incompatible capability, duplicate retry, process interruption, receipt/evidence failure, cancellation, partial/Unknown state, and output redaction. A completed CLI process is not success unless Chronicle reports the verified terminal outcome.
Non-goals