# Objective Lab implementation review

## Question

Can this repository demonstrate real IdentityMD swarm potential beyond a dashboard, while keeping paid execution, wallet authority, and evidence limits explicit?

## Deliverable

Implemented a greenfield Objective Lab in `index.html`, `styles.css`, `app.js`, and `server.js`. The interface composes a four-node DAG: independent research, a bounded build/model branch, adversarial review, and a final integration join. The generated request uses documented runnable skills, `dependsOn`, acceptance criteria, and `github:false` by default. It can call the public `POST /requests/check` route through a same-origin relay, and it provides read-only inspection for `/swarm`, `/oracle/requests`, and `/jobs`.

The product behavior is intentionally a mission surface: it turns an objective into a staged, inspectable execution graph and puts the evidence gate beside the composer. It does not pretend that a browser can safely make paid requests or independently validate a signature merely because an endpoint returned JSON.

## Attributable evidence

- The IMD API documentation defines `shape: "dag"`, step keys, dependencies, and a final join step for jobs ([Job body](https://imd.fun/docs/#job-body); [Composing work](https://imd.fun/docs/#composing-work)).
- The docs define research panels, fuzz results, swarm/worker/seat data, publications, launches, records, reviews, and immutable result files ([IMD API docs](https://imd.fun/docs/)).
- A public `POST /requests/check` previews blockers and the drafted plan without holding a price; paid opening uses a quote and wallet-signed payment flow ([Paid requests](https://imd.fun/docs/#paid-requests)).
- Oracle responses expose an EIP-712 attestation payload, but the docs distinguish an accepted job verdict from a signed oracle result and describe panel agreement/quorum separately ([Oracle](https://imd.fun/docs/#oracle)).
- Same-origin forwarding is a documented explorer pattern for paid routes, while the control plane refuses paid cross-origin browser calls ([Explorer](https://imd.fun/docs/#explorer)).

## Facts, inferences, uncertainty

**Facts:** The implementation contains a real request composer, a DAG preview, a public-read relay, live public reads when reachable, and an offline preview when they are not. No paid order, wallet signature, deployment, artifact upload, or oracle request was performed.

**Inferences:** The strongest useful demo for an empty repository is a mission composer that makes coordination and verification visible, because a static status board cannot express dependencies, handoffs, or acceptance criteria. The DAG is a product-level composition of documented primitives, not a claim that this repository has already run it.

**Uncertainty:** Public CORS and upstream availability vary by route. This local relay has not been deployed to a hosted origin. Oracle signatures and chain proofs are displayed as evidence to inspect; the client does not implement independent EIP-712 recovery or Merkle-proof verification. Network counts are live snapshots and may be cached.

## Unanswered questions

- Which wallet and funding policy should authorize a real `job.open`, `job.continue`, workflow, oracle, or schedule?
- Which objective-specific skills and artifact schemas should be approved before enabling paid execution?
- Should the final join require a quorum from the research panel, an accepted reviewer record, an oracle attestation, or all three for a given domain?
- What deployment host should own the relay and its rate limits?

## Local check

The deliverable is dependency-free. `node --check app.js` and `node --check server.js` pass. The server serves the static app and rejects traversal paths; the browser falls back to a clearly labeled offline preview if no relay is available.

```json
{"apply":true,"quality":8,"reason":"A real, runnable mission composer demonstrates swarm coordination through documented DAG jobs, public evidence inspection, and an explicit validation gate. It is bounded and honest about unpaid execution, CORS, signatures, and deployment uncertainty.","title":"Objective Lab","summary":"A greenfield IdentityMD orchestration surface that composes and validates multi-agent missions, inspects public evidence, and keeps payment and cryptographic authority explicit.","html":"<!doctype html><html lang=\"en\"><head><meta charset=\"utf-8\"><meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"><title>Objective Lab · IdentityMD</title><link rel=\"stylesheet\" href=\"styles.css\"></head><body><div class=\"shell\"><header class=\"topbar\"><a class=\"brand\" href=\"/\">⌁ OBJECTIVE LAB</a><button id=\"refreshBtn\">Refresh evidence</button></header><main><section class=\"hero\"><div class=\"eyebrow\">IDENTITYMD / SWARM OPERATING SURFACE</div><h1>Turn a hard objective<br><em>into a verifiable mission.</em></h1><p class=\"lede\">Compose a brief once. Let research panels, independent builders, adversarial reviewers and chain-backed oracles converge on evidence before anything ships.</p><button class=\"primary\" id=\"composeBtn\">Compose mission ↗</button></section><section class=\"telemetry\"><div>NETWORK<strong id=\"networkStatus\">checking…</strong></div><div>WORKING NOW<strong id=\"workingNow\">—</strong></div><div>OPEN PANELS<strong id=\"openPanels\">—</strong></div></section><section class=\"workspace\"><h2>What should the swarm make true?</h2><textarea id=\"objective\" rows=\"6\" placeholder=\"Describe the objective…\"></textarea><div id=\"missionGraph\"></div><button id=\"dryRunBtn\">Validate composition ↗</button></section><section class=\"workspace\"><h2>Inspect before you trust</h2><button data-inspect=\"swarm\">Inspect /swarm</button><button data-inspect=\"oracle\">Attach request ID</button><button data-inspect=\"job\">Inspect job ID</button><div id=\"activityList\">Loading public activity…</div></section></main><footer>Objective Lab is an orchestration surface, not a custody layer.</footer></div><dialog id=\"inspectDialog\"><button id=\"closeDialog\">×</button><pre id=\"inspectOutput\"></pre></dialog><script src=\"app.js\"></script></body></html>"}
```
