# Reviewed execution - 2.1.0rc9 AIM Core3.3.0rc8 builds native commands and owns validation, credential preparation, runtime discovery, customer locking, cancellation and authoritative results. WebGUI uses only its public aimctl API1.0 and the existing non-root executor. A new run needs review, not a saved plan. Select exact customer/playbook/hosts, declared typed options, check/apply and key mode. Review normalized scope, warnings, credentials and the **declared result contract**. Core source/schema changes invalidate earlier reviews; the worker never silently rebuilds and executes stale scope. Saving remains optional with collision-safe default titles. WebGUI execution policy, allowlist, grants, host limits and optional approval apply independently of Core's add-on opt-in. The executor's OS access is not proof of the browser requester's authority. Native inventory precedence is unchanged. Key mode customer requires the canonical owner-only key; key mode none is not forced password authentication. The worker performs local readiness before offering the owner-only credential modal. Its five-minute empty reservation and sixty-second post-handoff preparation/start window remain. Supplied values use the existing private channel, never job records, argv, environment or journals. The modal preserves deliberate opening, grouped alternative key source, paste/show controls, field clearing and lost-response reconciliation without an automatic second POST. ## Progress and results are separate 1. A bounded structured journal records approved Core metadata independently of viewers. Reopening a running or ended job replays committed events and continues after its durable cursor. IDs correlate tasks/hosts; there is no guessed task total/ETA or future task plan. Raw terminal text and module dictionaries are not retained. See JOURNAL.md. 2. Native target outcomes and final Core status/exit remain authoritative. A final event without a final response cannot establish successful completion. A partially successful host population does not rewrite Core's overall failure. 3. Purposeful operation reports arrive only at finalization and are separately validated against the reviewed contract. They are retained subject to explicit local limits/policy and fetched lazily. See REPORTS.md. A report can be available for a failed run. Missing/invalid required reports after native exit0 yield Core failed/result_validation while native target stats remain unchanged; this is not a password error and never triggers replay. A closed browser is not cancellation. User cancellation stops owned local process groups through Core, not already completed remote changes or independently running asynchronous work. Check mode is not an unconditional no-side-effect guarantee. Trusted playbooks can run controller-local/delegated tasks; both narrow staging exceptions stay enabled. Manual retry creates a new reviewed job and fresh credentials. Changes to mode, key handling, hosts or options are not edits to queued work. No automatic retry or recurring schedule is introduced; the existing explicitly UTC one-shot schedule remains. Only terminal jobs can be deleted. Deletion removes their lifecycle/idempotency/progress/report records and future history contributions, while keeping a compact audit deletion fact. Saved-plan deletion does not remove existing copied job intent. Protected backups are independently retained; deletion is not a promise of physical erasure. Old jobs are not rerun or reconstructed to populate missing evidence.