diff --git a/public/llms.txt b/public/llms.txt
index 3d18709..09d03fb 100644
--- a/public/llms.txt
+++ b/public/llms.txt
@@ -16,6 +16,7 @@ Current packages: crates.io at 0.14.0 (pin `traverse-registry` at `=0.25.0` if y
- [What is real today](https://traverse-framework.com/what-is-real-today.html): citeable snapshot — skill-first, one shared `runtime.wasm`, honest consumers, pre-1.0, no invented customers.
- [What does discover → execute → trace mean?](https://traverse-framework.com/questions/what-does-discover-execute-trace-mean.html): the value loop in plain language — agent proposes, runtime decides.
- [Where does business logic live?](https://traverse-framework.com/questions/where-does-business-logic-live-in-traverse.html): capabilities = non-UI domain rules; hosts = UI + I/O; one concern per package; “apps not ready” ≠ leave logic in the host; utilities teach the pipe, not the ceiling. Narrative: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html).
+- [What does “apps are not ready” mean?](https://traverse-framework.com/questions/what-does-apps-not-ready-mean.html) · [Is Traverse only for tiny utilities?](https://traverse-framework.com/questions/is-traverse-only-for-tiny-utilities.html): help-wanted door phrase (no product-shell PRs); utilities teach the pipe, not a size ceiling; domain packs in scope.
- [What does “the agent proposes; the runtime decides” mean?](https://traverse-framework.com/questions/what-does-agent-proposes-runtime-decides-mean.html): boundary in one page — agents search/plan/suggest; runtime validates, executes or denies, leaves a trace.
- [What is one shared runtime.wasm?](https://traverse-framework.com/questions/what-is-one-shared-runtime-wasm.html): embedders are clients; honest consumer list.
- [The agent freestyled a $2.4M wire. The runtime said no.](https://traverse-framework.com/blog/agent-freestyle-blocked.html): project direction in one scene — agent proposes, runtime decides (deny + trace).
@@ -58,6 +59,7 @@ Current packages: crates.io at 0.14.0 (pin `traverse-registry` at `=0.25.0` if y
- [Security & Permanence Audit](https://traverse-framework.com/security-audit.html): every known finding, its GitHub ticket, and its real status — not a marketing page.
- [FAQ](https://traverse-framework.com/faq.html) and [Questions](https://traverse-framework.com/questions.html): 70+ specific Q&A pages, mostly long-tail but accurate.
- [What is exact-ref model execution?](https://traverse-framework.com/questions/what-is-exact-ref-model-execution.html): signed schema `2.0.0` + `model.sig.json`; host-owned trust; `digits-mlp-1.0.0` (test-only key; prod signing #1567); native+web execute only in v0.14.0 (first landed in v0.12.0). Embedder notes: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) · [Release](https://github.com/traverse-framework/traverse/releases/tag/v0.14.0) · [Announcement #1576](https://github.com/orgs/traverse-framework/discussions/1576).
+- [How do hosts trust signed models?](https://traverse-framework.com/questions/how-do-hosts-trust-signed-models.html): host-owned trust roots gate `register_package`; pin by digest + `model.sig.json`; test-only digits-mlp key; exact-ref execute native+web only — no claimed ONNX generic runner.
- [How does Traverse complement Hugging Face?](https://traverse-framework.com/questions/how-does-traverse-complement-hugging-face.html): Hub = provenance; Traverse = pinned signed client-first capability; not Transformers.js/Hub replacement; no defer promise until a second executor exists.
## Optional
diff --git a/src/pages/questions/can-domain-logic-stay-in-javascript.astro b/src/pages/questions/can-domain-logic-stay-in-javascript.astro
new file mode 100644
index 0000000..b8fbb9d
--- /dev/null
+++ b/src/pages/questions/can-domain-logic-stay-in-javascript.astro
@@ -0,0 +1,48 @@
+---
+import QuestionLayout from '@layouts/QuestionLayout.astro';
+
+const jsonLd = JSON.stringify({
+ '@context': 'https://schema.org',
+ '@type': 'FAQPage',
+ mainEntity: [{
+ '@type': 'Question',
+ name: 'Can domain logic stay in JavaScript forever?',
+ acceptedAnswer: {
+ '@type': 'Answer',
+ text: 'Single-host glue can stay in JavaScript. Shared non-UI rules that must match across hosts belong in Traverse capabilities under discover → execute → trace. Deny-by-default I/O (stdin/stdout JSON today) limits authority, not how rich the rule can be. The React guide’s “never touches Rust/WASM directly” means use the embedder client — not reimplement the business rule in React. One shared runtime.wasm; there is no Python SDK (CLI shell-out only). Check Platforms for honest host status.',
+ },
+ }],
+});
+
+const relatedLinks = [
+ { href: '/questions/where-does-business-logic-live-in-traverse.html', label: 'Where does business logic live in Traverse?' },
+ { href: '/questions/what-does-apps-not-ready-mean.html', label: 'What does “apps are not ready” mean?' },
+ { href: '/questions/can-i-use-traverse-with-react.html', label: 'Can I use Traverse with React?' },
+ { href: '/docs/guides/react-integration.html', label: 'React integration guide' },
+ { href: '/platforms.html', label: 'Platforms' },
+ { href: '/questions/does-traverse-have-a-python-sdk.html', label: 'Does Traverse have a Python SDK?' },
+ { href: '/blog/where-business-logic-lives.html', label: 'Where business logic lives (hosts stay thin)' },
+];
+---
+
+ Short answer: glue that only one host needs can stay in JavaScript. Shared non-UI rules that must behave the same everywhere belong in capabilities — not forever in the React tree “because WASM cannot touch disk.”
+
+ When JS is fine
+ Session wiring, view-model mapping, one-off UI helpers, and host-local adapters that never need to match another OS or client can live in JS/TS. That is normal host work. Traverse does not ask you to WASM every line of a front-end app.
+
+ When it should leave the host
+ If two hosts disagreeing would be a bug — pricing, eligibility, consent, codecs, scorers, export gates — put the rule in a capability under discover → execute → trace. The host calls the capability; it does not re-own the rule. See Where does business logic live in Traverse?
+
+ Deny-by-default I/O is not “keep it in React”
+ Capabilities do not get ambient filesystem or network access. Today’s common boundary is stdin/stdout JSON through the embedder. That limits authority, not how rich the domain rule can be. “WASM can’t open a file, so the rule stays in JS” is the wrong conclusion. Call the capability; keep the host thin.
+
+ What the React guide actually says
+ The React integration guide’s “app never touches Rust/WASM directly” means you go through the published embedder client (traverse-embedder-web). It does not mean reimplement business rules in React components. One shared runtime.wasm everywhere; language SDKs are clients, not second runtimes. There is no Python SDK — Python shells out to the CLI today. Check Platforms before assuming a host is shipped.
+
diff --git a/src/pages/questions/how-do-hosts-trust-signed-models.astro b/src/pages/questions/how-do-hosts-trust-signed-models.astro
new file mode 100644
index 0000000..b83ec84
--- /dev/null
+++ b/src/pages/questions/how-do-hosts-trust-signed-models.astro
@@ -0,0 +1,46 @@
+---
+import QuestionLayout from '@layouts/QuestionLayout.astro';
+
+const jsonLd = JSON.stringify({
+ '@context': 'https://schema.org',
+ '@type': 'FAQPage',
+ mainEntity: [{
+ '@type': 'Question',
+ name: 'How do hosts trust signed models in Traverse?',
+ acceptedAnswer: {
+ '@type': 'Answer',
+ text: 'As of Traverse v0.14.0 (signed Spec 138), model packages use schema 2.0.0 manifests plus a detached Ed25519 model.sig.json. Host-owned trust roots gate register_package / registerPackage; apps never add trust. Pin by digest and signature, never a naked URL. The first trained package digits-mlp-1.0.0 ships with a test-only key; production signing is #1567. Exact-ref execute is native Rust and web only — Swift, Kotlin, and .NET do not execute exact-ref yet. ONNX as a generic runner is not shipped.',
+ },
+ }],
+});
+
+const relatedLinks = [
+ { href: '/questions/what-is-exact-ref-model-execution.html', label: 'What is exact-ref model execution?' },
+ { href: '/blog/traverse-0-14-0-what-changed-for-embedders.html', label: 'v0.14.0: what changed for embedders' },
+ { href: '/questions/how-do-i-verify-a-signed-capability-artifact.html', label: 'How do I verify a signed capability artifact?' },
+ { href: '/questions/what-is-the-wasm-sandbox.html', label: 'What is the WASM sandbox?' },
+ { href: '/platforms.html', label: 'Platforms' },
+];
+---
+
+ Short answer: the host owns the trust roots. Packages enter only through register_package / registerPackage after signature and digest checks against pins the app already declared. A naked URL is never identity.
+
+ Signed packages (v0.14.0)
+ Traverse v0.14.0 lands signed Spec 138: schema 2.0.0 manifests and a detached Ed25519 model.sig.json over the exact model.manifest.json bytes. App manifests pin those bytes (SHA-256), plus target, expected rights, and an optional signer key_id. Embedder notes: what changed for embedders. Announcement: Discussion #1576.
+
+ Host-owned trust roots
+ Trust lists live on the host (TrustedModelKeys on Rust, trustedPublicKeysHex on web). Applications cannot inject keys. Registration verifies the signature against a trusted key, the digest against exactly one pin, and the manifest schema (unknown fields fail closed), rights, target, and limits. Every execute re-hashes cached bytes. Failures stay typed (model_unavailable / model_incompatible) with a stable reason.
+
+ Test-only key vs production
+ The first trained package digits-mlp-1.0.0 is signed with a test-only key so CI and demos can exercise the path. Production model signing is tracked separately as #1567. Do not treat the test key as a production trust root.
+
+ Host honesty
+ Exact-ref execute is implemented on native Rust and the web embedder today. Swift, Kotlin, and .NET embedders do not execute exact-ref models yet — check Platforms. This page is about signed-model trust for Spec 138 exact-ref; it does not claim a generic ONNX runner is shipped. Deeper loop: What is exact-ref model execution?
+
diff --git a/src/pages/questions/index.astro b/src/pages/questions/index.astro
index c83349f..177b920 100644
--- a/src/pages/questions/index.astro
+++ b/src/pages/questions/index.astro
@@ -24,6 +24,9 @@ const groups = [
label: 'Contracts and capabilities',
items: [
['where-does-business-logic-live-in-traverse.html', 'Where does business logic live in Traverse?'],
+ ['what-does-apps-not-ready-mean.html', 'What does “apps are not ready” mean in Traverse?'],
+ ['is-traverse-only-for-tiny-utilities.html', 'Is Traverse only for tiny utilities?'],
+ ['can-domain-logic-stay-in-javascript.html', 'Can domain logic stay in JavaScript forever?'],
['what-is-a-contract-in-traverse.html', 'What is a contract in Traverse?'],
['what-is-contract-driven.html', 'What does "contract-driven" mean in Traverse?'],
['how-do-i-write-a-capability-contract.html', 'How do I write a capability contract?'],
@@ -51,6 +54,7 @@ const groups = [
['what-is-the-capability-registry.html', 'What is the capability registry?'],
['what-is-governed-composition.html', 'What is governed composition in Traverse?'],
['what-is-exact-ref-model-execution.html', 'What is exact-ref model execution in Traverse?'],
+ ['how-do-hosts-trust-signed-models.html', 'How do hosts trust signed models in Traverse?'],
['what-does-the-discover-page-do.html', 'What does the Traverse /discover page do?'],
['how-do-placement-targets-work.html', 'How do placement targets work in Traverse?'],
['what-is-a-trace-artifact.html', 'What is a trace artifact in Traverse?'],
diff --git a/src/pages/questions/is-traverse-only-for-tiny-utilities.astro b/src/pages/questions/is-traverse-only-for-tiny-utilities.astro
new file mode 100644
index 0000000..569e7f4
--- /dev/null
+++ b/src/pages/questions/is-traverse-only-for-tiny-utilities.astro
@@ -0,0 +1,47 @@
+---
+import QuestionLayout from '@layouts/QuestionLayout.astro';
+
+const jsonLd = JSON.stringify({
+ '@context': 'https://schema.org',
+ '@type': 'FAQPage',
+ mainEntity: [{
+ '@type': 'Question',
+ name: 'Is Traverse only for tiny utilities?',
+ acceptedAnswer: {
+ '@type': 'Answer',
+ text: 'No. Utility helpers in the registry teach the publish pipeline and CI gates. They are legitimate, but they are not the product identity and not a size ceiling. “One small capability” means one concern per package. Preferred publishes are business-shaped: pricing, eligibility, scorers, gates, codecs — non-UI domain rules under discover → execute → trace.',
+ },
+ }],
+});
+
+const relatedLinks = [
+ { href: '/questions/where-does-business-logic-live-in-traverse.html', label: 'Where does business logic live in Traverse?' },
+ { href: '/questions/what-does-apps-not-ready-mean.html', label: 'What does “apps are not ready” mean?' },
+ { href: '/blog/where-business-logic-lives.html', label: 'Where business logic lives (hosts stay thin)' },
+ { href: '/questions/what-is-a-wasm-capability.html', label: 'What is a WASM capability?' },
+ { href: '/questions/can-i-use-traverse-for-pricing-logic.html', label: 'Can I use Traverse for pricing logic?' },
+ { href: '/what-is-real-today.html', label: 'What is real today' },
+];
+---
+
+ Short answer: no. Small utility helpers teach the publish pipeline. They are not Traverse’s product identity and not a size limit on what a capability may contain.
+
+ Why utilities exist
+ The registry includes helpers such as slugify, truncate, and email validate. Those packages exercise contracts, digests, CI gates, and the human-reviewed PR path with a small surface. That is useful onboarding. It is not a statement that “real” work stays in the host.
+
+ “One small capability” means one concern
+ When docs say keep a capability small, they mean one concern per package — a clear contract boundary, not “keep the bytes tiny forever.” A pricing rule, an eligibility check, a mesh codec, or an export gate can be substantial and still be one capability. Split by concern when two rules would evolve or authorize differently; do not split because someone equated WASM with toy utils.
+
+ Preferred publishes are business-shaped
+ What we want in the catalog: deterministic decisions, domain transforms, policy gates, scorers, codecs — anything that must match across hosts and leave a trace. Put that under discover → execute → trace. Leave UI, session, and ambient I/O in the host. Narrative: Where business logic lives (hosts stay thin).
+
+ Related misconceptions
+ “Apps are not ready” blocks product-shell PRs, not domain packs — see What does “apps are not ready” mean? Placement in one page: Where does business logic live in Traverse?
+
diff --git a/src/pages/questions/what-does-apps-not-ready-mean.astro b/src/pages/questions/what-does-apps-not-ready-mean.astro
new file mode 100644
index 0000000..71c041e
--- /dev/null
+++ b/src/pages/questions/what-does-apps-not-ready-mean.astro
@@ -0,0 +1,47 @@
+---
+import QuestionLayout from '@layouts/QuestionLayout.astro';
+
+const jsonLd = JSON.stringify({
+ '@context': 'https://schema.org',
+ '@type': 'FAQPage',
+ mainEntity: [{
+ '@type': 'Question',
+ name: 'What does “apps are not ready” mean in Traverse?',
+ acceptedAnswer: {
+ '@type': 'Answer',
+ text: '“Apps are not ready” is a contrib and help-wanted door phrase. It means do not open PRs that port a whole product UI or application shell into Traverse capability repos. It does not mean leave domain logic in the host forever, and it does not mean Traverse is only for tiny utilities. Capability packs — business-shaped WASM capabilities under discover → execute → trace — are in scope. See the print-support pack (registry#596) and Discussion #1374.',
+ },
+ }],
+});
+
+const relatedLinks = [
+ { href: '/questions/where-does-business-logic-live-in-traverse.html', label: 'Where does business logic live in Traverse?' },
+ { href: '/questions/is-traverse-only-for-tiny-utilities.html', label: 'Is Traverse only for tiny utilities?' },
+ { href: '/questions/can-domain-logic-stay-in-javascript.html', label: 'Can domain logic stay in JavaScript forever?' },
+ { href: '/what-is-real-today.html', label: 'What is real today' },
+ { href: '/blog/where-business-logic-lives.html', label: 'Where business logic lives (hosts stay thin)' },
+ { href: '/questions/how-do-i-contribute-to-traverse.html', label: 'How do I contribute to Traverse?' },
+];
+---
+
+ Short answer: “apps are not ready” tells contributors what not to open a PR for — a whole product UI or application shell inside this org’s capability repos. It is sequencing and scope for help-wanted, not a claim that Traverse cannot hold real domain rules.
+
+ What the phrase blocks
+ Help-wanted tickets and contrib notes use “apps are not ready” when the ask would pull a full client shell, product chrome, or multi-screen app into a capability repository. That work belongs with host apps and product teams, not in the registry’s capability packages. Opening that kind of PR burns review time and muddies the contract boundary.
+
+ What it does not mean
+ It does not mean leave non-UI domain logic in JavaScript (or any host) forever. It does not mean Traverse is only for tiny string helpers. Preferred publishes are business-shaped: pricing, eligibility, scorers, codecs, export gates — one concern per package, under discover → execute → trace. Hosts stay thin: UI plus the I/O the capability is allowed to use.
+
+ Capability packs are in scope
+ A pack of related capabilities is exactly the kind of contrib the door wants. The print-support initiative is a living example: codecs, overhang/score/fin/brace rules, export gates — capabilities only, no product shell. Umbrella registry#596; Announcement Discussion #1540.
+
+ Where to read next
+ Placement rules in one page: Where does business logic live in Traverse? Citeable host honesty: what is real today. Broader contrib framing: Discussion #1374.
+
diff --git a/src/pages/questions/what-is-exact-ref-model-execution.astro b/src/pages/questions/what-is-exact-ref-model-execution.astro
index dfa3e45..d1fb44d 100644
--- a/src/pages/questions/what-is-exact-ref-model-execution.astro
+++ b/src/pages/questions/what-is-exact-ref-model-execution.astro
@@ -15,6 +15,8 @@ const jsonLd = JSON.stringify({
});
const relatedLinks = [
+ { href: '/questions/how-do-hosts-trust-signed-models.html', label: 'How do hosts trust signed models?' },
+ { href: '/blog/traverse-0-14-0-what-changed-for-embedders.html', label: 'v0.14.0: what changed for embedders' },
{ href: '/questions/what-is-governed-composition.html', label: 'What is governed composition?' },
{ href: '/questions/what-is-the-difference-between-an-ai-agent-and-the-traverse-runtime.html', label: 'Agent vs Traverse runtime' },
{ href: '/questions/what-is-the-wasm-sandbox.html', label: 'What is the WASM sandbox?' },
diff --git a/src/pages/questions/where-does-business-logic-live-in-traverse.astro b/src/pages/questions/where-does-business-logic-live-in-traverse.astro
index 816de5a..1e452f1 100644
--- a/src/pages/questions/where-does-business-logic-live-in-traverse.astro
+++ b/src/pages/questions/where-does-business-logic-live-in-traverse.astro
@@ -17,6 +17,9 @@ const jsonLd = JSON.stringify({
const relatedLinks = [
{ href: '/blog/where-business-logic-lives.html', label: 'Where business logic lives (hosts stay thin)' },
{ href: '/what-is-real-today.html', label: 'What is real today' },
+ { href: '/questions/what-does-apps-not-ready-mean.html', label: 'What does “apps are not ready” mean?' },
+ { href: '/questions/is-traverse-only-for-tiny-utilities.html', label: 'Is Traverse only for tiny utilities?' },
+ { href: '/questions/can-domain-logic-stay-in-javascript.html', label: 'Can domain logic stay in JavaScript forever?' },
{ href: '/questions/what-does-discover-execute-trace-mean.html', label: 'What does discover → execute → trace mean?' },
{ href: '/questions/what-is-a-wasm-capability.html', label: 'What is a WASM capability?' },
{ href: '/questions/why-put-business-logic-in-webassembly.html', label: 'Why put business logic in WebAssembly?' },