# Project state Updated: 2026-09-27. This is a current snapshot, not a release diary. Stable commands and invariants are in [AGENTS.md](AGENTS.md); prior snapshots remain in Git. ## Current contracts - React supports full/embedded rendering independently of local/OIDC/upstream auth, with EN/IT UI and immutable session interaction language. See [application shell](docs/architecture/application-shell.md) and [localization](docs/operations/shell-and-localization.md). - PostgreSQL Metadata Catalog owns database identity, binding, schema, descriptions, sensitivity and relationships for all core consumers. Workspace schema v4 contains identity and optional Evidence only. Installation schema v2 is the authored model catalog source. See [overview](docs/architecture/overview.md) and [model configuration](docs/general/pi-configuration.md). - The harness owns workflow persistence; chat is not the durable session record. Memory uses PostgreSQL authority and derived Qdrant dense/BM25 search. Editable Evidence has local archive authority and manual consolidation. File save, search activation and Git publication have distinct outcomes. See [Memory](docs/gestione-memory.md), [Evidence](docs/contracts/curated-evidence-v4.md) and [consolidated release evidence](docs/reports/knowledge-archives-release.md). - Reference preprocessing must not clear Memory. Use the installation-scoped `tht --installation /absolute/path/thothii-installation.yaml workspace preprocess run` and its [contract](docs/contracts/workspace-preprocessing-cli.md). - DWH sessions are read-only. SSH tunnels support database-management diagnostics and metadata synchronization, not NL→SQL session creation; use direct or REST transport for sessions. ## Installation and workspace boundaries Fresh standalone installations follow the manual terminal procedures in [Italian](docs/install/standalone-manual-it.md) or [English](docs/install/standalone-manual-en.md), without an installer or launcher. The [Compose reference](docs/operations/compose-reference.md) is for maintainers, not another quick start. Catalog and Memory migrations are explicit. Descriptors, authentication, provider credentials, certificates and runtime bindings stay in protected installation-local paths. Do not copy secrets into examples or workspace Git. Legacy runtime snapshots may use absolute paths and protected `harness/.env`; do not silently relocate them. PSD authoring is separate at `/Users/mp/projects/tht-workspace-psd`. Its GitHub repository was copied to private Gitea [workspace_psd](https://git.tylconsulting.it/mptyl/workspace_psd), preserving both branches. It is a copy, not automatic synchronization. Running installations were not repointed to a different workspace remote. ## Recorded deployments and server authority Use the ordered [server handoff](docs/operations/server-codex-handoff.md) for coordinated ThothII/Omics upgrades. Omics integration uses GitHub `Dallavilla-Tiziano/omics_portal`, with no Gitea relay prerequisite. Omics uses embedded/upstream identity, not another ThothII OIDC login. Read [upstream authentication](docs/install/authentication-upstream.md) before changes. Last recorded application deliveries (not a fresh runtime attestation): - [Coordinated ThothII/Omics release](docs/reports/2026-09-26-server-release-execution.md): core/frontend `497ab840-preflight`, Omics proxy fix `928f7e9f` with existing web image retained. Automated acceptance passed; on September 27 the operator confirmed browser access, UI controls and session start/stop/resume. Functional browser acceptance passed; remaining extended checks are handed off in the [server acceptance follow-up](docs/reports/2026-09-27-server-acceptance-handoff.md). - [Session dialogs](docs/reports/2026-09-14-session-dialogs-release.md): `b1723c34-session-dialogs-20260914`, frontend-only. - [Session layout/Memory fix](docs/reports/2026-09-14-session-layout-memory-fix.md): `49333a2d-session-memory-fix`, core/frontend. Keep those reports and rollback instructions while operator gates remain open. A later deployment does not prove every earlier acceptance item passed. ## Remaining acceptance and design gates - Fresh-machine Mac, Windows/WSL2 and Linux installation acceptance, including real DWH/model endpoints, remains a separate operator exercise. - Real IdP/portal login, logout, embedded interaction and PSD semantic acceptance follow the [manual matrix](docs/testing/authentication-manual-acceptance.md) and delivery reports; synthetic tests do not close them. - [Security hardening](docs/plans/2026-09-08-security-hardening-prd.md) is a draft. Revalidate SEC01–12 and obtain design approval before implementation or real server/IdP/DWH mutation. - Optional NER remains opt-in; labeled Italian quality, benchmark and licensing acceptance are not implied by document cleanup. - Semantic aliases, value descriptions, synonyms/concepts, dialect and multi-schema extensions remain explicit design work. Current sensitivity delivery follows the Catalog contract; additional policies require their own acceptance. - Legacy database UI fallback (`?db-ui=legacy`, dev/staging) and prototype removal remain subject to owner acceptance. ## Documentation maintenance MkDocs publishes only 20 product/operator pages and five approved assets. Architecture, contracts, ADRs, plans, research, tests and release evidence are excluded from HTML and search. The repository itself is public: editorial exclusion is not confidentiality. The [cleanup record](docs/maintenance/2026-09-15-documentation-cleanup.md) records retired sources and retained gates. Main contains source; Actions generates the `pages` branch. The live site requires the separate explicit deployment described in [public manual publication](docs/operations/public-docs-publication.md).