Build
The proposed Spell game.build_candidate@1 runs static and engine tests, performs reproducible
imports where the exact profile proves them, and creates a
content-addressed candidate with source, command, environment, probe, and checksum evidence.
Human review may request a forward repair or accept one PlayableBuildBundle@1; acceptance does
not imply release authority.
The proposed Spell game.prepare_release@1 freezes the candidate, compatibility statement, required evidence, and
consumer handoff without publishing it. Signing, store credentials, upload, staged rollout,
public multiplayer, telemetry, correction, takedown, and remote-copy reconciliation belong to a
future release or distribution application. Foundry neither invents that authority nor records a
distribution receipt for an effect it did not own.
Deletion inventories local build candidates, imports, caches, and derivatives under Foundry custody. An exported handoff is recorded but not silently recalled or reported as deleted.
Proving the build
Use a synthetic local 2D project with networking disabled. Bootstrap one repository, admit one
small visual and music bundle, import them through test adapters, build one playable scene, run one
declared controller scenario, and emit exactly one PlayableBuildBundle@1 with source, build,
test, playtest, and checksum receipts. Signing, upload, store accounts, telemetry export, public
players, and release remain outside the proof.
A separate 3D fixture adds one validated GLB, collision, a baked navigation route, one accepted Kinesis clip and animation controller, one interaction, a headless logic scenario, and one real renderer/hardware playtest receipt. It is not evidence for hostile project execution, open-world streaming, model-driven actors, networking, or another engine profile.