Decisions
CLI Local Work and Control Plane
Backend provides facts while the CLI performs local repo work
The backend provides typed facts, authenticated metadata, and authoritative moving-channel baseline identity through packages/contract and apps/api.
The CLI performs local repository work: detection, scaffold writes, update checks, manifest handling, and retrieval of the exact baseline identity selected by the control plane. Cache, release inventory, downloads, and bundled content verify bytes; they never redefine stable or substitute another version. Explicit bundled requests remain local and verified. Backend contracts do not mutate target repositories.