Require explicit approval before planner recovery runs merge, PR, destructive, or external-service actions. - Add pure planner side-effect classification and confirmation request modeling in core. - Route merge/PR recovery decisions to await confirmation instead of autonomous dispatch. - Persist pending confirmation requests and only execute approved controller actions. - Cover confirmation gating with core and engine regression tests and document the policy. Files changed: .changeset/fn-7513-planner-confirmation-gate.md | 7 + docs/architecture.md | 85 ++++++++- docs/settings-reference.md | 2 +- .../src/__tests__/planner-confirmation.test.ts | 125 +++++++++++++ .../core/src/__tests__/planner-recovery.test.ts | 14 +- packages/core/src/index.ts | 7 + packages/core/src/planner-confirmation.ts | 141 ++++++++++++++ packages/core/src/planner-recovery.ts | 103 ++++++++--- ...lanner-recovery-controller-confirmation.test.ts | 205 +++++++++++++++++++++ packages/engine/src/index.ts | 5 + packages/engine/src/planner-recovery-controller.ts | 204 +++++++++++++++++++- packages/engine/src/project-engine.ts | 44 +++++ 12 files changed, 913 insertions(+), 29 deletions(-) Fusion-Task-Id: FN-7513 Fusion-Task-Lineage: 1e3c6640-8a4f-41f6-89dd-41eb9b675b2b Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai>
Changeset Format Guide
Each changeset file in this directory describes one user-facing change for release notes.
Required body format
---
"@runfusion/fusion": minor
---
summary: Add a Command Center productivity control for LOC backfills.
category: feature
dev: Uses the new `fn_backfill_loc` tool; settings key `commandCenter.locBackfill`.
Fields
| Field | Required | Description |
|---|---|---|
summary |
Yes | One line, user-facing, max 120 chars. Describe what changed for the operator. |
category |
Yes | One of: feature, fix, breaking, security, performance, internal. |
dev |
No | Developer or migration detail. Preserved in per-package CHANGELOGs but excluded from distilled release notes. |
Audience
The summary is the only content that appears in end-user release notes by default. Write for Fusion operators — describe behavior, fixes, and what changed. Avoid internal class names, file paths, and implementation detail.
Bump types
patch— bug fixes, internal changesminor— new features, CLI additions, toolsmajor— breaking changes
Validation
Run pnpm check:changesets to validate. The linter runs in the PR-check gate and test:gate. Legacy freeform changesets pass with a warning during the transition period.