# [Product name] — project contract

Version: 1.0. Replace every bracketed field before building.
Free template by PlanSmith: https://plansmith.io/blog/claude-md-template-for-saas
You may adapt this document for your own project.

## Product and scope

- Audience and problem: [who uses this and what they need to complete]
- Core workflow: [start → meaningful user result]
- First release includes: [explicit features]
- Excludes: [features deliberately deferred]
- Open decisions: [question, decision owner, dependent work]

Do not silently implement an unresolved decision. Read existing repository
instructions before proposing changes. Preserve unrelated work.

## Roles, ownership and access

| Role | Records it owns | Allowed actions | Denied actions |
|---|---|---|---|
| [role] | [ownership key] | [actions] | [actions] |

Enforce access on the server for list, detail, mutation, export and attachment
routes. Derive identity from the authenticated session, not a request-supplied
user ID. Define administrator assignment and exceptions explicitly.

## Objects and lifecycles

For each core object specify:
- Stable identifier and owning user/organisation.
- Required fields, unique constraints and relationships.
- Allowed states and transitions, including who may make each transition.
- Effects on related records, notifications, reporting and permissions.
- Duplicate requests, concurrent changes, corrections and reversals.
- Archival/deletion policy and retention decision.

## Delivery sequence

1. Confirm scope, stack, data model and unresolved decisions.
2. Implement identity, ownership and the first complete business workflow.
3. Exercise success, denied access, empty, invalid and repeated-request paths.
4. Add the next approved workflow using the same source records.
5. Deploy the verified revision and repeat the critical journeys on its URL.

Do not claim completion from a build command or screenshot alone. Do not create
fake dashboard totals or success messages disconnected from saved records.

## Acceptance evidence

| Requirement | Actor and fixture | Expected result | Observed result | Evidence |
|---|---|---|---|---|
| [ID and workflow] | [named fictional users/records] | [testable result] | [pass/fail/not tested] | [saved check or screenshot] |

For access tests, prove the authorized actor succeeds before asserting the
unauthorized actor is denied. Test UI and direct API/file paths. Recheck
permissions after relevant lifecycle changes.

Record local verification, deployed verification and remaining limitations
separately. Include persistence after reload, responsive layout, keyboard use,
failure recovery and a backup restore when applicable.

## Project commands and operations

- Stack and versions: [existing stack]
- Install: [command]
- Development: [command and fixed port]
- Build: [command]
- Tests: [commands and what each proves]
- Environment keys: [names only; secrets stay outside this file]
- Migration and rollback: [reviewed procedure]
- Deployment: [target, command and verification URL]
- Backups, background jobs and delivery failures: [owner and runbook]

## Current handoff

Completed: [tested workflows]
Next: [one concrete step]
Blocked/unresolved: [specific issue]
Known limitations: [specific untested or unsupported behavior]
