<!-- Author: Dr.-Ing. Babak Sorkhpour, with AI assistance | Version: 6.6.0-beta.3 | Date: 2026-08-06 -->

# Product Guide

## Editions

### Community Developer Preview

For personal and noncommercial evaluation. It demonstrates goal-first orchestration, typed specialist roles, dependency/resource graphs, Ollama Cloud model-specific seats, evidence-bound meetings, deterministic verification, diagnostics and portable capability packs. Company-internal, hosted, production, resale, fork distribution and commercial use require a written licence.

### Enterprise Customer Edition

A private, contract-bound add-on for licensed organisations. It verifies signed Ed25519 entitlements and unlocks the contracted feature set, limits, retention, PMD/ProductX API adapter and customer deployment controls. It never ships issuer private keys and never accesses PMD by raw database or Excel files.

## Operating model

1. Understand the goal through 5W1H and privacy classification.
2. Retrieve validated prior knowledge and ask only missing questions.
3. Compile a typed graph with true data dependencies and resource-lock edges.
4. Bind each agent to an immutable specialist-role contract.
5. Select live-ready providers/models by role fit, effort, privacy, quality and cost/latency telemetry.
6. Run independent analyses; challenge and normalize them into compact domain summaries.
7. Freeze one plan digest; required roles must accept that exact digest.
8. Execute only under task/assignment/ACK/lease policy.
9. Run deterministic tests, independent verification and audit.
10. Persist control state, sealed XLSX projection, knowledge artifacts and sanitised diagnostics.

## Key invariants

- Provider is not a role.
- Installed is not authenticated or live-ready.
- A generic fallback cannot qualify a named adapter.
- Command pass is not meeting acceptance.
- Founder override is recorded and does not rewrite synthesis evidence.
- Empty/meta-only output is not a contribution.
- RAG and Excel are derivatives, not transactional authorities.
- Public/private/customer roots and Git histories are physically separate.
- Required roles—not every installed model—must accept the same plan digest.
- Deterministic code performs hashing, validation, deduplication, scheduling and test evaluation; models are not used for solved plumbing.

## AgentGem-derived capability pattern

The release adopts a general pattern independently implemented in IOT-AI:

```text
secret-safe capture
→ one typed operation contract
→ deterministic neutral archive
→ REST / MCP / OpenAPI materialisation
→ public / unlisted / private / customer classification
```

No AgentGem code, branding, hosted marketplace or monetisation feature is copied or claimed.

## Clean installation

Every command-, script- or prompt-driven installation must use the official transaction. Old managed code/packages are archived after verification; settings, databases, customer data and unknown files are preserved. See `installation.md` and `update.md`.

## Logs

```bash
iot-ai status --logs
```

Linux: `~/.local/state/iot-ai-tech/iot-ai-suite/v1/logs/`
Windows: `%LOCALAPPDATA%\IoT-AI.Tech\IOT-AI-Suite\v1\logs\`

## European compliance posture

The Suite includes technical controls and evidence structures for current Article 4/5/50 duties, GDPR engineering, CRA readiness, NIS2 customer alignment, incident handling and public/private release boundaries. These are technical readiness controls—not legal certification or a blanket claim for every customer deployment. Intended purpose, actor role, sector, model supply chain, customer modifications and high-risk applicability must be assessed per deployment.
