v0.21.1 — the three tiers, named
A maintainer dogfooding pass (operating runward from a well-kept coding harness) surfaced that the verification architecture was fully built but never named — and that everything beyond it belongs to the operator, not the CLI. This release names the boundary and locks it by ADR. The deterministic, zero-network gate is unchanged; no CLI change.
- The operator layer stays outside the CLI (ADR-0039). Adoption audits over harness transcripts, operator-side cost telemetry and machine-wide instruction files are the operator's own tooling — never the MIT CLI, which reads the mission repo and nothing else ("local with no data flow", ADR-0031). A voluntary satellite is deferred behind an explicit demand trigger (the ADR-0028 channel-signal watch).
- The three-tier verification doctrine, named. Tier 1 — the deterministic gate (unforgeable, decides phases); Tier 2 — the operator's mechanical hooks (inform and correct, never gate); Tier 3 — advisory review (findings in, operator decides). One partition question: must this check be unforgeable? → runward.dev/docs/concepts/three-tiers
- "Wire your harness" — an operating guide in the honest per-channel format, nothing auto-wired (ADR-0012 holds in full) → runward.dev/docs/operating/wire-your-harness
- Roadmap groomed at v0.21.1; Later gains the official plugin-directory submission; Someday parks the operator-layer satellite behind the demand trigger.
Full changelog: CHANGELOG.md