← Back

Project roadmap · measured 2026-08-23

Perimeter-Cerberus

An Android tower-defence game built against a frozen set of 356 design contracts. The contracts are the sole authority: no gameplay value, ID, pool member, reward or UI state may be chosen or inferred outside them. That constraint is the point — it is the closest thing I have to a controlled experiment in what agents do when they are not allowed to invent.

This page is generated. Every count on it is read from the file that owns it — the phase arc from the planned-phases record, the release gates from the P14 checklist, the findings from two defect registers, the totals from the contract set itself. It is a snapshot measured on 2026-08-23, not a live feed. The implementation repository is private, so what is published here is the engineering record rather than the game design.

Contracts
356
Canonical records
2,078
Kickoff items done
5 of 6
Open findings
1
Release gates met
2 of 18

Where things stand

Three things are in play at once, and they are at very different stages.

Complete

The contract set

P00 through P14 are authored and approved. 356 contracts, 2,078 canonical records, entered through the consolidated authority index.

This is the foundation both builds share, and the only implementation authority. It is finished work: the phases that author it have all reached their exit contracts. What remains against it is not authoring but the handful of gaps the two registers name.

Frozen

v1 — reference implementation

Sprint 0 through Sprint 26, frozen at tag v1-final-demo. A runnable demo and the reference for how the contracts behave in motion.

Read-only. It proved the contract set is executable and it is where every mechanism was first exercised, but it also carries the inventions this project is trying not to repeat — the mob damage visual in HG-001 was found there.

Starting

v2 — the second build

Starts from the contracts, not from v1's code. Presentation authority now specifies one launch baseline and direct asset-repository management.

AM-024 Gate 1 established product/orientation evidence; AM-027 replaces the abandoned package path with five direct-asset gates. Replacement Gates 1–3 are complete. Gate 4 has exact 58+1 scaffolds, a deterministic input pack, strict handoff tooling, the approved v2 Unity 6000.3.21f1 UI Toolkit target, atomic publication, and offline round-trip proof; it remains open for one real Claude Design ZIP inspection/import lock.

contract setv1v2register entry356 contractsfrozenbuildingdefect or how-gapgap foundamendment
v1 is drawn dashed because nothing flows out of it any more. The return path is the part that matters: a gap found while building becomes a register entry and then an amendment to the contract set, rather than a fix in the code that found it.

The register underneath

356 contracts and 2,078 canonical records, entered through a consolidated authority index that defines reading order and supersession rules. Underneath it sits a per-contract register: the scope each one declares, the rule IDs it defines, who cites it, and which amendment or defect touches it — plus a change ledger carrying the additions, revisions and removals that a snapshot of the current text would hide.

What stands in the way

The kickoff items for the second build. Four are complete; the asset-package work is unblocked but unfinished, and the Design audit is waiting on a reachable project.

#ItemStateDetail
1Contract overviewDone · 2026-08-21Docs/contract-overview/ plus the published page. Generated from the contract text; the change ledger came out in five layers.
2Contract review — where the how is missingDone · 2026-08-21Docs/agile/contract-how-gaps.md. Five verified entries; the EN-371 boss-reward chain was checked and discharges.
3Launch presentation and direct asset managementDone · 2026-08-23AM-027 removes launch Theme/Asset Package mechanics, establishes one game-owned baseline, defines the exact v2/external-assets request→record→lock→sync→publish→verify lifecycle, and replaces AM-024 package Gates 2–6 with five direct-asset implementation gates. Replacement Gates 1–3 are complete; Gate 4 is mechanically ready and awaits one real Claude Design export inspection/import lock.
4Author the mob damage visualDone · 2026-08-21AM-007: UI-249 now carries a damaged state between hit and death, luminance only, with size, opacity and silhouette changes expressly forbidden. No magnitude authored — depth is a theme-supplied slot fill under UI-232, and v1's 45% is not adopted.
5Record the Core-blocks-projectiles decisionDone · 2026-08-21AM-004 now carries its own supersession, retained as evidence. Nothing emitted depended on the AM-004 reading — no collision or blocking field exists in content/slice/, and every other reference was documentation.
6Brief Claude Design on the platform authorityWaiting · one real Claude Design exportThe 58+1 input pack, exact MCP/manual operator guide, direct Asset/Usage boundary, approved Unity target, and offline round-trip proof are ready. Connect the intended Claude organization/project, author and review the first increment, then inspect/import the real downloaded ZIP to close Replacement Gate 4.

Open findings

1 contract-level questions that have to be answered rather than implemented around. A defect is a place the set contradicts itself or cannot be executed as written; a how-gap is a place it states a requirement without authoring the mechanism. Closed entries stay in their registers as evidence and drop off this list on the next build, so nothing has to be remembered.

IDFindingRegisterStatus
HG-011Single-baseline asset-repository integration and lifecycle are not authoredhow-gapAUTHORITY RESOLVED 2026-08-23 — AM-027 approves exact repository ownership, asset/request identities and records, paths, commit/digest locks, rights, lifecycle states, deterministic tooling, Unity publication, QA, rollback, and five replacement implementation gates; Replacement Gates 1–3 are complete and mechanical closure requires Gates 4–5

Release gates

Two of the eighteen reproduce today from the contract text alone, by tools/verify_contract_invariants.py. The rest need a build. None of the eighteen may be met by changing a contract — P14's release rule requires an explicit amendment and a rerun of every affected audit.

StateGate
MetExactly 2,078 manifest records: 2,040 Launch-active and 38 reserved.
MetZero missing/duplicate owners, IDs, consumers, or fixture joins.
PendingAll 2,386 contracted P10 fixture cases execute and pass.
PendingAll 57 Endless upgrades pass maximum-stack, clamp, recipient, replay, and recovery tests.
PendingCareer has 21 Rounds/210 Waves and correct Sector boundaries.
PendingGateway has 18 Paths and exact 10/6/4/10 completion-order behavior.
PendingGateway completion locks entry and preserves read-only details.
PendingEndless authored and open-ended boundaries are deterministic.
PendingRune drops do not reroll, duplicate, auto-equip, or disappear after later Round failure.
PendingSave interruption at every committed boundary matches uninterrupted execution.
PendingAll 63 P12 nodes pass route, Back/cancel, locked, pending, failure, interruption, and recovery tests.
PendingAll nodes pass supported aspect ratio, text scale, input, focus, contrast, reduced-motion, mute, and haptic modes.
PendingAll five Launch themes pass required-slot coverage; missing overrides fall back to Classic as contracted.
PendingP12A required semantic events, mixing priorities, music states, haptics, and interruption rules pass.
PendingPurchases, ads, restoration, Supporter, and entitlements pass success/pending/cancel/fail/offline/duplicate-callback cases.
PendingReserved themes/badges and Rounds 22–25 remain unobtainable/inactive.
PendingObsolete IDs and mechanics are rejected.
PendingDeterministic traces and authoritative hashes reproduce across supported builds.

v1 — authored against built

The last full count on record, from Docs/agile/readiness-assessment.md, 2026-08-17. v1 figures at the Sprint 18 revision of the readiness assessment. Sprints 19-26 continued after it — Rounds 2 and 3 completed, defenses resolved, theme packages, music states, the Career loop closed, Laser Blaster and Ray Gun. The table is the last full authored-versus-built count on record, not v1's final state.

SystemBuilt / authoredDetail
Career Rounds3 / 21Rounds 1-3 complete, all ten Waves with named encounters
Weapon families4 / 10Pistol, Rifle, Needle Burst, Shotgun at Level-1 baselines
Weapon levels1 / 30Every family authored to 30; only Level 1 realised
Defenses3 / 9One per Zone resolves; six selectable and labelled as dealing no damage
Navigation surfaces11 / 41Shell navigates the built ones on canonical node IDs
Behavioral Chassis3 / 7Hexagon is launch-ineligible by EN-431
Mob Traits2 / 8Shielded and Regenerating done
Runes0 / 18EL-304's 18 dedicated slots modelled, no effects

v1's suite is 1,569 tests. On the most recent CI run all three platforms reported 1,555 passing and 14 failing. Every one of the 14 looks for a generated content file that is not committed to the repository, so they fail identically on Linux, Windows and macOS — a fixture-provisioning gap rather than a logic regression. It is named here rather than rounded up.

Implementation order

Derived from P13's required implementation order. This is the plan v2 inherits; v2 has not authored a sprint plan of its own.

SprintGoalAreasExit evidence
0Planning, scaffolding, canonical hashingCoverage map; hash vector gated
1Manifest compiler and registryA2,078 records compiled from exact owner lines
2Schemas, validation, fixture harnessA, L2,386 fixtures enumerated and executing
3Determinism, snapshots, persistence, migrationBSubstream traces reproducible
4Battlefield, Core, Turrets, targetingCEvent-driven targeting; obsolete properties rejected
5Weapons, Elements, DOTD10 families L1-30; one shared DOT runtime
6Mobs, traits, wave generationEBounded procedural generation within spawn budget
7Non-turret defensesF9 defenses across 3 Zones with depletion
8Career, Gateway, Endless lifecyclesG21 Rounds/210 Waves; 18 Paths at 10/6/4/10; 57 upgrades
9Progression, Runes, rewards, skillsHDrops retained, unequipped, never rerolled
10CommerceISuccess/pending/cancel/fail/offline/duplicate-callback
11Unity shell and navigationJAll 63 nodes with full state coverage
12Themes, assets, audio, hapticsKRequired-slot coverage; Classic fallback
13Full validation and release readinessLEvery P14 mandatory gate green

Sprints 4-7 depend on 1-3 but are largely parallel with each other.

The whole arc

P00 through P14 author the design and hand it off; P15 onward build and ship it. The contract set is the output of the first half.

PhasePurposeRequired outcome
P00 Source reconciliationSeparate current decisions from inherited assumptionsApproved v3 baseline, reference inventory, unresolved-question register
P01 Product and release definitionDefine the game being shippedAudience, orientation, session target, launch scope, platforms, success criteria
P02 Player journey and game modesDefine the complete experience outside and inside playMenu-to-run-to-results flow, supported modes, victory/defeat structure
P03 Encounter foundationDefine how a run operatesArena, Core/territory, waves, spawning, pacing, pause, completion
P04 Combat contractDefine shared combat rulesDamage sequence, targeting, range, crits, movement, timing and ownership
P05 Turrets and weaponsFully define equipment behaviorTurrets, weapon catalog, weapon instances, WXP, paths, forks, evolution
P06 Elements, runes, and DOTValidate or replace the reference elemental modelTaxonomy, matrix, DOT rules, rune behavior, resistance and vulnerability
P07 Enemies and obstaclesDefine everything opposing the playerMob classes, traits, elites, bosses, movement, obstacles and interactions
P08 Defenses and player-controlled systemsDefine non-turret defensive mechanicsDefensive catalog, placement/slots, activation, damage and progression
P09 Progression and loadoutDefine persistent ownership and advancementCareer progression, unlocks, inventory, loadout, skills, saves and respec
P10 Levels, rewards, and balance modelCreate the launch progression frameworkLevel catalog, wave budgets, rewards, difficulty scaling and starter values
P11 Economy and monetizationDefine commercial systems without harming balanceCurrencies, ads, purchases, cosmetics, entitlement and restoration rules
P12 UX and presentationDefine the production-facing experienceNavigation, HUD, tutorials, feedback, accessibility, art, animation and audio
P13 Technical implementation contractTranslate approved design into build instructionsUnity architecture, data schemas, save versioning, services and performance budgets
P14 Test and playground contractSeparate verification from content demonstrationAutomated-test fixtures, diagnostic scenes and real-content playground
P15 Production implementationBuild the approved systems in the fresh projectIntegrated, maintainable game implementation with no invented mechanics
P16 Vertical sliceProve the complete production loopOne polished representative level on physical Android hardware
P17 Content production and alphaComplete launch contentAll launch systems, levels, weapons, enemies, progression and presentation
P18 Beta and balancingValidate the complete gameDevice coverage, tuning, usability, accessibility, performance and save testing
P19 Release candidatePrepare the actual store productFinal builds, analytics, privacy, billing, ads, ratings and store materials
P20 Google Play releaseSubmit and launch safelyReview approval, staged rollout, monitoring and rollback plan
P21 iOS releaseComplete iOS-specific adaptation and submissionApple compliance, device QA, purchasing validation and App Store release
P22 StabilizationResolve launch findingsCrash fixes, urgent balance changes, player feedback review and release retrospective

Generated from the roadmap emitter in the Perimeter-Cerberus repository and committed here as a dated snapshot. Narrative and status are authored; every count is read from the file that owns it. Nothing on this page is authority — on any disagreement the contract wins.