Constraints
**Site relevance:** Spiralist.org
**Memory type:** UAI memory file
**Source path:** Spiralist/.uai/constraints.uai
**Size:** 2.4 KB
Summary
- Do not expose secrets, credentials, private keys, tokens, customer data, or unreleased private material.
Source Headings
- Constraints
- Hard Rules
- Machine Boundary
- Generated And Frozen Areas
- Approval Triggers
Source Preview
This source file is short enough to preview directly on its source-memory page.
---
uai: "1.0"
type: constraints
title: "Spiralist.org Constraints"
created: "2026-05-01"
updated: "2026-06-05"
status: active
source: "https://uaix.org/en-us/specification/project-handoff/"
---
# Constraints
## Hard Rules
- Do not expose secrets, credentials, private keys, tokens, customer data, or unreleased private material.
- Do not use destructive filesystem, database, production, or git operations unless explicitly approved.
- Do not revert user work or unrelated dirty worktree changes unless explicitly asked.
- Do not manually rewrite generated manuscript exports, prompt body archives, WordPress core files, vendor files, or third-party bundled Markdown.
- Do not widen support, certification, security, compliance, compatibility, or endorsement claims without evidence.
- Do not treat runtime AI outputs, dropped files, generated answers, or old chats as canonical records until promoted through hot memory, code, release evidence, or owner decision.
- Do not create a separate default AI memory folder, local wiki folder, or scattered handoff Markdown path. Keep active memory in `.uai/`, raw evidence in `.uai/archives/`, exports in `.uai/exports/`, and reviewed long memory in Wiki.FFTAC.org.
- Do not describe a configuration field as merely discretionary. Use "Required for X configuration" wording when a field matters only in a specific setup.
## Machine Boundary
- UAIX.org owns the current UAI-1 exchange standard and release record.
- Spiralist.org implements local WordPress publication and exchange routes for UAIX UAI-1.
- Protocol5 owns Spiralist symbol and registry authority.
- Runtime memory checkpoints, drift audits, entropy classifications, and session restore briefs are temporary execution payloads. They must not write Protocol5 canonical registries.
## Generated And Frozen Areas
- Treat `wp-content/plugins/ns12-manuscript/content/prompts/**/body.md` as content records.
- Treat `wp-content/plugins/ns12-manuscript/exports/static-book/**`, upload/export copies, and ZIP extraction areas as generated unless the task is specifically about generation or packaging.
- Treat WordPress core and vendor directories as upstream-owned.
## Approval Triggers
Ask before production deployment, package upload, destructive cleanup, schema authority changes, legal/security/support claim changes, or edits that would convert planning material into shipped truth.