# Project-Level Rules > Project-specific specialisation and corrections. Loaded after `org.md` and > `team.md` as strict-additive guidance; contradictions with broader policy > are rejected. Populated by practices-discovery and the self-learning loop. > > Use sparingly: most teams don't need a project layer. Reach for it > only when this specific project needs stable, durable guidance beyond the > team practice (for example, package-specific release checks or an additional > regression suite for a legacy component). ## Way of Working ## Walking Skeleton ## Testing Posture ## Change Control ## Deployment ## Code Style ## Tech Stack ## Decided ## Scope Overrides ## Forbidden - NEVER reference content, fonts, or assets by remote URL; everything ships (affirmed 2026-09-13) with the page. (affirmed 2026-09-13) ## Mandated - ALWAYS generate pure HTML5 + CSS with no build step and no external (affirmed 2026-09-13) dependencies, so the result runs entirely from the local filesystem (affirmed 2026-09-13) (never beyond localhost). (affirmed 2026-09-13) - ALWAYS make the rendered page printable cleanly to A4 from the browser's (affirmed 2026-09-13) print dialog. (affirmed 2026-09-13) - ALWAYS fetch or read content only through user-granted means (native file (affirmed 2026-09-13) picker / drag-and-drop) when the page runs from `file://` — never rely on (affirmed 2026-09-13) `fetch()` of sibling local files, because the opaque-origin policy blocks it (affirmed 2026-09-13) in stock browsers (empirically verified: plain Chromium blocks (affirmed 2026-09-13) `fetch('article.txt')` from a `file://` page, while the native file picker (affirmed 2026-09-13) works). (affirmed 2026-09-13) - ALWAYS make the page work with zero network requests (no CDN fonts, no (affirmed 2026-09-13) remote `