# casan-harness (package skeleton) Core CASAN harness (gate H1→H7) as a reusable package, independent of domain data. Populated incrementally by Plan-01 (Phase 0→6). During migration, files move here from `.specify/` wave-by-wave; the full harness gate must stay green (`PASS=64 FAIL=0`) after each phase. Layout: - `assets/local-viewer/` — production static UI for the Core Local Assurance Viewer - `scripts/` — bash + powershell gate logic (H1→H7), path resolver `casan-paths.sh` - `security/` — filter/policy rules (prompt-filter, pii-rules, output-policy, ...) - `governance/`, `agentops/` — H5/H6 code - `config/` — runtime policy, registry, model fallback, and tool metadata - `templates/` — spec/plan templates - `tests/` — source-hub verification only; excluded from production installs Core visual reporting is intentionally lazy and zero-dependency: ```bash casan report latest casan view casan report export --format html casan report export --h6 --format html ``` Prompt hooks only write canonical evidence and a small receipt. `casan view` starts a loopback-only, token-protected, read-only Python server on demand. No Node/npm, external font/CDN, Platform service or per-prompt HTML generation is required. Runtime state (logs, audit chain, tenant state) is NOT part of this package — it stays with the app under `CASAN_STATE_ROOT`. Domain data (golden-runs, corpus, input) lives in `apps/okr/domain/` under `CASAN_DOMAIN_ROOT`.