# Goal: Manual-First Auth Flow Use Krypton Execution to execute `docs/goals/manual-first-auth-flow/PLAN.md`. Core rules: - Treat PLAN.md as the source plan. - Preserve intent, ownership, contract, cutover, evidence, and kill criteria. - Make fresh install and default `vpn` / app connect manual-first. - Keep the installer understandable for a non-IT user: plain wording, manual mode on Enter, optional conveniences explained as choices. - Keep Bitwarden, Touch ID, saved TOTP, autosubmit, and headless mode as explicit opt-in features. - Do not add a new dominant path without deleting, redirecting, demoting, or shimming the displaced Bitwarden/auto-first path. - Capture acceptance evidence from a clean temporary HOME and the menu-bar app contract. - Say "implemented but unproven" if that evidence cannot be captured.