---
name: velin-rewrite-apply
description: Orchestrate rewrite apply ONLY after GATE_READY + DRY_RUN_OK + Snapshot. Fail closed. Does not invent mappings. Does not raise SAFE_REWRITE. RequiresApproval mandatory.
---

# Rewrite Apply

## Purpose
Orchestrate rewrite apply ONLY after GATE_READY + DRY_RUN_OK + Snapshot. Fail closed. Does not invent mappings. Does not raise SAFE_REWRITE. RequiresApproval mandatory.

## Domain
N · category `rewrite`

## Capabilities
- `rewrite.apply`
- `rewrite.apply-gate`

## Permission
`apply` · **requiresApproval: true**

## Allowed actions
- READ
- VALIDATE
- PREFLIGHT
- DRY_RUN
- APPLY

## Forbidden actions
- WRITE
- ROLLBACK
- ACCEPT
- DEFER
- NOTE
- ACKNOWLEDGE
- CATALOG
- MANIFEST
- CLASSIFY
- invent-target

## Stop conditions
- SR-04
- SR-05
- SR-06
- SR-07
- SR-10
- SR-15
- SR-16
- SR-20

## When to use
Only after GATE_READY + DRY_RUN_OK + human approval.

## Workflow
1. Re-check preflight.
2. Confirm DRY_RUN_OK.
3. Snapshot.
4. Apply via CLI.
5. On failure → rewrite-rollback.
Fail closed on any SR-04…07/10/15/16/20.

## CLI bridge
`velinstyle migrate rewrite-manifest <project> --apply`

## Rules
- requiresApproval.
- Do not raise SAFE_REWRITE artificially.

## Anti-Patterns
- Apply without gate.
- Apply with empty manifest.

## Related skills
- `velin-rewrite-dry-run`

## Output
report, diff
