Skip to content

CANON-TRAJECTORY-AUDIT-01 — Findings

Brief: CANON-TRAJECTORY-AUDIT-01 (read-only recon/audit, dead-window channel) Executor: RTOpacks Alex on Fable 5 (claude-fable-5), session of 2026-07-06 Substrate: HEAD 4bb78437 == origin/main (verified by fetch + rev-parse, 2026-07-06). Working tree carries zero modified/staged tracked files; 224 untracked files in outputs/ (banked docs) are excluded from all findings per the brief. Tree-state rider: SYNC-FLEET-LEDGER-HYGIENE-01 closed branch — satisfied. Progressive-write discipline: this document is written to disk section by section as each completes.


0. Recon record — the enumerated canon set (Checkpoint A)

Enumerated from the repo's own docs index (docs/mkdocs.yml nav, 233 lines) plus the repo-root crossings/ register — not from any path list in the brief. For each entry: path, the document's own currency line, and git last-touch (git log -1 --format=%as) where the two diverge or no in-doc line exists.

Governance spine (hierarchy positions 1–4 per standing-rules)

Doc Path In-doc currency line Git last-touch
Client Spine docs/docs/ops/client-spine.md Last updated: 2026-05-27 (dispositional articulation, three-tier access-control, ADRs 020-023 arc) 2026-05-27 4dabb86b — agrees
WS-PRODUCT-01 docs/docs/workspace/product.md Last updated: 5 June 2026; Status: Living document, authoritative above all module specs 2026-07-04 e7ed7c90 — header lags git by ~4 weeks
Standing Rules docs/docs/ops/standing-rules.md Last updated: 2026-06-01 header, but changelog paragraph runs to 2026-07-04 STANDING-RULES FOLDING 2026-07-05 a18a68a3 — header date stale against own changelog
Architecture Decisions docs/docs/ops/architecture-decisions.md Status: Canonical log; Last updated: 2026-06-27; 63 ADR headings, highest ADR-063 2026-06-29 63b6cfd4 — header lags; body contains 2026-06-28 promotions

Module specs (docs index enumerates 8 app files across 5 modules)

Doc Path In-doc currency line Git last-touch
Studio docs/docs/workspace/apps/studio.md Last updated: 17 April 2026; Living document 2026-04-17 — agrees
People 00 — Obligations docs/docs/workspace/apps/people-00-obligations.md status: settled — the acceptance surface (no date line) 2026-06-17 35141967
People 01 — Model docs/docs/workspace/apps/people-01-model.md status: settled — the People model, whole (no date line) 2026-06-29 f1171f8d
People 02 — Spec docs/docs/workspace/apps/people-02-spec.md status: draft; promoted to canon at Round-1 close (2026-06-28) per its own tail 2026-06-29 f1171f8d
People 03 — Companion docs/docs/workspace/apps/people-03-companion.md status: derived — tracks build state (no date line) 2026-06-29 1999f75a
Radar docs/docs/workspace/apps/radar.md Last updated: 4 July 2026; Living document — deployed state + intent 2026-07-04 e7ed7c90 — agrees
Record docs/docs/workspace/apps/record.md Last updated: 14 April 2026; specced not built 2026-04-15 — agrees
InstaLearn docs/docs/workspace/apps/instalearn.md Last updated: 14 April 2026; foundational thinking 2026-04-15 — agrees

Note: the brief's minimum set says "the six module specs." The repo's own index enumerates eight app files covering five modules (Studio, People×4, Radar, Record, InstaLearn). The index wins per the brief's own recon rule; the count delta is recorded here rather than reconciled.

Product-adjacent canon

Doc Path In-doc currency line Git last-touch
Glossary docs/docs/workspace/glossary.md Version 2.0, Date: 3 June 2026, Status: CANONICAL 2026-06-05 91c48b08 — agrees (±2 days)
Design Foundation docs/docs/design/foundation.md Version 1.35, Status: Canonical; latest changelog row 2026-06-26 (v1.35, §12 email-field rule) 2026-07-03 074c028a — last touch postdates last changelog row
Fence Protocol docs/docs/ops/fence-protocol.md doc_id FENCE-PROTOCOL-01; status: CANON, ratified by Tim 2026-07-01; authored 2026-07-01 NYC 2026-07-01 694cce94 — agrees

Filed crossing artefacts (crossings/, repo root — RTOpacks-side filings of the fence)

All carry authored: frontmatter; none postdate 2026-07-03. Register: crossings/README.md (16,742 bytes, mtime 2026-07-04).

Sent (9): FENCE-RULING-RECORD-01 (2026-07-01) · RTOPACKS-ACK-CONTRACT-PACK-01 (07-01) · RTOPACKS-CONFIRMATION-BLOCK-ENCODING-01 (07-02) · RTOPACKS-CORRECTION-01 (07-01) · RTOPACKS-CORRECTION-02 (07-03) · RTOPACKS-ENGINE-BRIEF-01 (07-01) · RTOPACKS-RESPONSE-MIGRATE-02-PHASE-6-01 (07-03) · RTOPACKS-RESPONSE-TO-ASSESSMENT-01 (07-01) · RTOPACKS-REVIEW-CONTENT-PAYLOAD-01 (07-01)

Received (15): UCCA-ACK-CORRECTION-01 (07-01) · UCCA-ASSESSMENT-RTOPACKS-BRIEF-01 + ADDENDUM-01 (07-01) · ucca-content-payload-schema-v1.json · UCCA-CONTRACT-PACK-01 (07-01) · UCCA-CORRECTION-01 (07-01) · UCCA-CROSSING-NOTE-PACK-SCHEMA-01 (07-03) · UCCA-FENCE-RULING-RECORD-01 (07-01) · UCCA-INPUT-PATH-CONTRACT-PACK-v1.0 (07-01) · UCCA-QR1A-CONTENT-PAYLOAD-SCHEMA-01 · UCCA-REQUEST-BLOCK-ENCODING-01 (07-02) · UCCA-REQUEST-MIGRATE-02-PHASE-6-01 + FILING-NOTE + received-note (07-03) · UCCA-RESPONSE-CONTENT-PAYLOAD-01 (07-01)

Plus crossings/attachments/QR1A-samples/. All are in scope as documents; UCCA-side material beyond these filings is out of scope per fence discipline.

RECON FLAG — PROJECT-BRIEF does not exist

The brief's minimum set names PROJECT-BRIEF. No file by that name exists in the repo working tree, and git log --all -- "*PROJECT-BRIEF*" returns nothing — it has never been committed under that name. The only references are one archived brief (docs/docs/briefs/archive/docs-record-rename-01.md:241, "Updates to PROJECT-BRIEF.md or other governing docs") and one lowercase mention in docs/docs/ops/recon/RECON-FOUNDATION-LENS-01.md:511 ("per project brief"). Nearest functional equivalents in the enumerated set: Client Spine + WS-PRODUCT-01 + STATE.md (repo root, self-dated 2026-04-10, Session 48). Carried to Checkpoint A for Tim to rule on what "PROJECT-BRIEF" denotes; not smoothed over.

Recon observations carried into Section 2 (not findings yet)

  • Three of the four spine docs (WS-PRODUCT-01, standing-rules, architecture-decisions) have in-doc "Last updated" headers that lag their own content and/or git last-touch. Standing-rules' header says 2026-06-01 while its own changelog paragraph records a 2026-07-04 folding.
  • STATE.md at repo root declares itself "canonical session handover — update and commit at end of every session" and is dated 2026-04-10 (Session 48) — ~3 months stale against daily commit activity.
  • mkdocs exclude_docs hides _superseded/ plus two named ops/designs files from the built site while they remain on disk.

Checkpoint A rulings (Tim, 2026-07-06): PROJECT-BRIEF struck from the minimum set (Claude-project-files orientation artefact, never repo-filed) — its repo-absence goes to Section 5, not Section 2. Module-count delta stands as recorded. The three carried recon observations formalise in Section 2. Usage-boundary markers appended per section from here.

Boundary marker — end Section 0. Fable usage %: NOT agent-readable (no tool inside the session exposes the pool; ~/.claude holds no usage file). Markers are placed for Tim to annotate from /status. — [Tim: ____%]


1. Commercial trajectory

Evidence base: four read-only sweeps (billing state, pricing assumptions, queue inventory, onboarding/support/legal), executed 2026-07-06 against HEAD 4bb78437, plus direct reads of WS-PRODUCT-01, client-spine, radar.md. Findings ranked by consequence.

1.1 The most consequential finding: the deployed product is not yet the canon's product

The canon sells a three-module compliance spine whose differentiator is the live connection between modules: "RTOpacks makes the connection automatic, live, and permanent… That is what no other product in the VET sector does" (product.md:105-107), and it stakes the category claim on completeness: "Strip either People or Record away and the product loses its argument… Without People and Record alongside it, Studio is a sophisticated content authoring tool — better than its competitors, but the same category of product" (product.md:127-129).

Against that, the deployed reality at HEAD:

  • Record is not built. "RECORD-SPEC-01 | v0.2 | Record | Spec only — not yet built" (product.md:36). The evidence leg of the spine — the thing an RTO buys compliance software for on audit day — exists as spec.
  • The live cross-module connection is not built. The canDeliver verdict engine is "specified but not yet built in code" (people-03-companion.md:84,140-146); the Studio↔People seam ("can this trainer deliver this unit?") is owed (people-03-companion.md:92); the older build-status section corroborates a "Stub receiver for Studio integration" (product.md:289, itself dated 17 April — see §2 for currency). What is deployed today is three capable modules side by side — which is structurally the fragmentation the canon indicts competitors for (product.md:103).
  • The three named obligation gaps stand. Validation scheduling, third-party monitoring, and the unified review calendar are unresolved surfaces by the canon's own admission (product.md:193-201) — and they are close to a mid-size compliance manager's actual daily pain list.

This is not a claim that the house is off track — the queue (§1.3) points mostly at exactly these gaps. It is the finding that by the canon's own argument, what is deployed today is not yet chargeable as "the compliance spine," and any shortest-path reasoning has to say what is being sold in the interim: Studio-plus-People as a category-competitive authoring/register product, Radar as an intel product, or a founding-customer arrangement priced on the roadmap. The canon does not currently say which. UNSETTLED → §5.

1.2 Shortest path to first paying RTO — the gap map

The path splits into "able to charge" (short) and "able to retain" (the real distance). Concretely, per gap:

Billing rail — days of work plus one external dependency, all gaps known and filed. - Backend is real and dev-proven end-to-end: 59KB of handlers (workers/internal-api/src/billing.ts), hand-rolled Stripe/QB clients (no SDK anywhere — verified zero stripe deps in any package.json), webhook edge worker deployed both envs (workers/billing-callbacks/), dev sandbox webhook confirmed 2xx on signed events (outputs/DEV-BILLING-SECRET-PARITY-01-close.md, git-tracked). - No real production Stripe or QuickBooks account has ever existed — "no prod keys ever issued" (ADR-034, architecture-decisions.md:1248-1269). Prod /billing/webhook 503s by design (stripe.ts:314-315; verified behaviour). Go-live checklist exists (billing.md:719-739; launch-lockdown.md:5-13). - QuickBooks production approval is an external 2–4 week lead time (billing.md:368, Intuit app still "Development (sandbox)") — but QB is books/invoicing, not the charge rail; Stripe alone suffices to take the first payment.

Payment surface — the largest pure build gap on the charge path. - The customer-facing subscribe/card UI was deliberately erased 2026-06-08 (WORKSPACE-BILLING-SURFACE-ERASE-01, commit 8003275d; untracked close doc) as premature and wrong-tier. What remains is a dashed-border "Billing coming soon" placeholder (apps/workspace/app/(workspace)/admin/billing/page.tsx) and zero Stripe.js/Elements anywhere in the frontend (verified by sweep). The canonical billing.md §8 file map still lists the three deleted files — doc is stale on its own surface (→ §2). - Interim note, not a proposal: the admin finance console holds operator-driven payment tooling ("Test Payment", "convert to client" — apps/admin/app/finance/page.tsx:363-394), so a first customer does not strictly wait on the self-serve rebuild.

Onboarding — substantially more built than the canon's reputation for it suggests. - Operator-minted provisioning works (apps/admin/app/orgs/page.tsx → internal-api /org/provision), and a genuine self-serve path exists for Type 1 RTOs: the /claim wizard (email-domain RTO resolution → email-OTP + SMS-OTP → provision → first-admin magic-link seat via the ADR-057 sign-in gate, Accepted and double-proven). The in-workspace 5-step onboarding wizard (confirm org → confirm scope from the TGA mirror → admin profile) is the client-spine's "show-don't-tell" auto-populated client file, built (apps/workspace/…/admin/onboarding/page.tsx). - Gaps: /claim is reachable only from the search overlay — the /plans CTAs dead-end at /auth with a plan= param nothing consumes, and Enterprise is a mailto: (apps/site/app/plans/page.js). Orgs provision plan-less onto a 'trial' default ("billing bolts on later" — apps/site/app/api/signup/route.js:12-13). The admin dashboard's own copy says "Provisioning not yet live" (apps/admin/app/page.tsx:311). No Type 2 / Type 3 path exists in code (signup hard-rejects non-RTO, route.js:25-28) — consistent with Type 1 first, but the spine presents three types with no priority marking (client-spine.md:96-104). - ENTITLEMENTS-MODEL-01 is the named platform gap "triggered alongside client onboarding" (radar.md:105) — pre-revenue full-depth ruling holds until then.

Support posture — thinnest of the four; contains one live trust liability. - Exists: a contact form (apps/site/app/contact/page.js), a mailbox, and an availability disclaimer in the ToS (§7). - Absent (searched): status page, SLA artefact, help centre, escalation path. Meanwhile the Enterprise tier markets "SLA commitments, priority support… dedicated contact" (apps/site/app/plans/page.js:66) and promises "a standard contract" — no such SLA or contract document exists anywhere on disk. A serious evaluator who asks for either exposes the gap immediately. Flagged as a live defect-shaped finding under stop-and-report; not fixed.

Contractual/legal — more real than expected, two defects. - Exists: Terms of Use v1.0 (effective 19 Mar 2026) whose §6 already covers subscriptions/Stripe/suspension; privacy policy; cookie/copyright/accessibility; a 9-vendor sub-processors register; contracting entity defined (UCCA AU Pty Ltd, infrastructure-reference.md:26,237). - Gaps: no standalone subscription agreement/MSA/DPA (whether ToS §6 legally suffices for a first Essential/Pro customer is a legal question this audit cannot settle — UNVERIFIED → §5); and two unreconciled sub-processor lists disagree (trust-docs/docs/legal/sub-processors.md v1.0 vs trust-docs/docs/subprocessors.md, which adds Apple PassKit/Hostinger/Envato with different data-location claims) — a trust-centre integrity defect (→ §2).

Retention — the unpriced gap. Month-2 value for a compliance manager currently rests on Studio authoring plus a manually-populated trainer register. The retention machinery the canon names — live traffic lights, TAS generation, audit folder (Record Ph1-2), canDeliver verdicts (People R2), sector feed (CAPTURE-01) — is all queue. No import path from incumbent artefacts (spreadsheets, Newbery matrices) was found by any sweep (UNVERIFIED as absent — no import surface cited anywhere; → §5), which prices the switching cost at full manual re-entry.

1.3 Queue audit — every queued/shelved item, scored

Scores: R = serves the revenue path · D = serves robustness of what's deployed · E = serves elegance. Source citations in the inventory sweep; scores are this audit's judgement.

Item Score One line
Record Phase 1 (record.md:271-281) R The missing spine leg; unlocks the canon's own category claim (§1.1).
Record Phase 2 — TAS gen, compliance matrix, audit folder (record.md:283-291) R The audit-day artefacts the buyer is actually buying; depends on Ph1 + mature Studio/People data.
Record Phase 3 — benchmarking, CI log (record.md:293-298) E Real value, nothing deployed depends on it, no buyer blocked without it.
People R2: canDeliver engine (people-03:84) R It is the "live connection" differentiator claim; without it the claim is prose.
People R2: Studio↔People seam (people-03:92) R Same finding, the other end of the wire.
People R2: multi-hat multi-valued role (people-02:344-349) R/D Spec itself re-weighted it upward: dominant shape in the micro/small-RTO segment — first-customer-relevant.
People R2: signal language / colour system (people-02:537) E Explicitly "not yet designed"; correctly held.
People R2: USI/OSIR verification (people-02:336) R-later Government lead time; spec's own "start early" note is right and currently unactioned.
People R2: audit ledger report, librarian re-open (people-02:373; people-03:97) D Reads over already-captured events; correctly deferred (NO ORPHAN GRAINS).
Radar L1 Register (radar.md:891) R Free front door, "nearest to done," the onboarding demo surface.
CAPTURE-01 + Sector feed (radar.md:892-893) R The only source of temporal register intelligence (TGA has no change endpoint) and the subscription's heartbeat.
Watchlist + Dossier depth (radar.md:894-895) R The paid tier itself.
Append-only migration (radar.md:898) D Substrate-honesty precondition the paid product cannot ship without; correctly sequenced "precedes or accompanies."
Revision scrubber (radar.md:899) E→R Elegance now, dossier-tier value later; reuse-not-invent keeps its cost honest.
Held-depth marker component (radar.md:899) R The conversion mechanic; cheap because pre-entitlements every tap opens.
Radar-CF on-demand crawl path (radar.md:900) R Crawl-on-onboarding is what keeps the Marketer demo honest at signup.
RADAR-ENRICH-UI-01 (radar.md:906) D Admin-facing; surfaces already-captured data.
Anomaly detection (radar.md:908) E Feed-adjacent someday; nothing waits on it.
RADAR-ENRICH-COMMERCIAL / WhoisXML (radar.md:910) E Paid external API for depth no buyer has asked for yet.
Configurable crawl depth · element-level sitemap analysis (radar.md:912,914) E Instrument refinement.
TGA delivery-notification signal family (radar.md:140-142) R-later Correctly filed as scoping input, no brief auto-opens.
Marketer module (radar.md:88-94) R The stated conversion mechanism (verification asymmetry); demo-tier is one crawl's cost.
InstaLearn Ph1-4 (instalearn.md:285-317) R′ Serves a different revenue path (GenEd stream) — real, but not the shortest path to the first paying RTO.
Studio: Composer + Auditor stages (studio.md:419-421) R The content-production value the engine contract exists for.
Studio: Trainer Mapper (studio.md:422) R Depends on the People seam; sequenced behind it.
Studio: Scenario Player (studio.md:298) E Strategic-stream depth, post-revenue.
Studio banked design staves (banked/, 9 items, all canonical:false) E Correctly banked, not in-flight.
KN arc (banked/studio/STUDIO-KN-ARC.md) E/D Data incomplete, surface stubbed; correctly parked.
Legislation-to-tile register: instruments-as-objects, obligation layer, concordance (legislation-to-tile-method.md:172-174) D Regulatory-transition insurance; becomes R at the next Standards transition, not before.
ENTITLEMENTS-MODEL-01 (radar.md:105) R Explicitly "triggered alongside client onboarding" — correctly gated, must not slip past the trigger.
Launch Lockdown billing gates (launch-lockdown.md:5-13) R Literally the go-live checklist.
IMM-01 Phase 3d (ops/decisions/…PREFLIGHT-PARK…) D Parked into the first-onboarding arc — correct placement.
Data-layer queued briefs 2026-05-17 (briefs/queue/…) D Substrate hygiene; the queue doc is stale — MANDARIN-VIOLATION-01a/b/c since closed (outputs close docs, untracked) (→ §2).
Micro-shelf: SEAT-COUNT-ATOMICITY-01 bank Already shipped as ADR-060 (Accepted 2026-06-27) — stale bank entry (→ §2).
Micro-shelf: REFUSAL-STATE-HARDENING, glass items, KN-KEY-RECONCILE, pf-rescope E/D Correctly banked with named triggers.
STATE.md:68-78 items Stale register (2026-04-10); at least one item (stats-cache) since superseded (→ §2).

Queue verdict: the queue is not serving the house's elegance — the E-scored items are overwhelmingly banked/parked with named triggers rather than in flight, which is discipline working. The honest tension is different: four parallel revenue theses (compliance spine, Radar intel subscription, Marketer, InstaLearn/GenEd) each carry an unbuilt remainder, while the thesis the canon calls the product (the spine) is the one missing its third module. The queue serves revenue; it does not yet declare which revenue first. UNSETTLED → §5.

1.4 The walked-away buyer

Persona: compliance manager at a mid-size RTO (say 20-60 staff, incumbent SMS, NovaCore-style policy library, Newbery-style trainer matrix in Word/Excel). Evaluated seriously; did not buy. Their steelman:

  1. "My problem is audit day, and the audit-day module isn't built." I can see Studio is genuinely better authoring, and the trainer register is clean. But the TAS generator, policy library, Standards mapping, audit folder — the things I'd defend an audit with — are on your roadmap, not in your product. I'd be buying a promise. (Canon's answer: none today — the canon itself concedes the category collapses without Record, product.md:127-129. Unanswered.)
  2. "I'm not allowed to drop anything I already pay for." You are explicitly not an SMS (product.md:135) and not an LMS (product.md:137), so you are additive spend and an additional data-entry surface. SMS Connect is named but I see no evidence it exists (UNVERIFIED build state — no sweep found code), and there's no import path for my existing matrices — so my team re-keys everything by hand. (Canon's answer: partial at best — integration layers are named as modules, product.md:177-179, but nothing deployed answers double-entry today. Unanswered.)
  3. "AI-written content is an audit liability." When the auditor asks my trainer to defend the assessment and the honest answer is "the machine made it," I'm dead. (Canon's answer: strong — this objection is answered better than any other, in writing, at governing-principle level: "the engine raises hands; it never signs," two declared modes on the record, the bar is "good" not "pass" (product.md:231-273), plus a public AI-transparency artefact (trust-docs/docs/compliance/ai-transparency.md). The buyer's objection is anticipated almost verbatim at product.md:251-255. Answered — if the positioning ever reaches them.)
  4. "Three people and a single founder hold my compliance evidence." What happens to my audit trail if you're gone? Where's the SLA? Your Enterprise page promises SLA commitments and a standard contract — I asked for both and they don't exist (plans/page.js:66; searched, absent). No status page. A contact form is the support desk. (Canon's answer: split. Exit risk is genuinely answered — export-portable output is first-class, ADR-010; no-weaponised-lock-in with the door soft on lapse, client-spine.md:48. Vendor-continuity and support-posture risk is unanswered, and the marketing copy actively over-promises against it.)
  5. "Prove the price." $399-699/mo against what I pay the incumbent stack — where's the comparison? (Canon's answer: none filed. No competitive pricing analysis exists anywhere in the canon; the observed-field numbers that could ground one are captured but unsurfaced — §4's territory. RECON NEEDED → §5.)
  6. "Your own gaps list is my job description." Validation cycles, third-party monitoring, the what's-due-this-month calendar — the canon names all three as unowned surfaces (product.md:193-201). Those are the three things I do every week. (Canon's answer: honest internally, absent externally. Unanswered.)

Answered: #3 decisively, #4's exit-risk half, plus data-honesty postures the buyer would discover with use (dated observations, radar.md:111). Unanswered: #1, #2, #5, #6, and #4's continuity half. The pattern in the unanswered set: they are all completeness and continuity objections, not quality objections — consistent with §1.1.

1.5 Pricing assumptions — located, and the finding

Pricing is filed, contrary to the null hypothesis the brief allowed for — but in exactly one operational document, with the strategic canon deliberately pointing away:

  • The numbers: $399/mo Essential (1 seat) · $699/mo Pro (5 seats) · Enterprise custom (100 seats) · $35/mo additional seat · 10% GST (billing.md:32-37,55). Stripe Smart Retries 4/14d dunning (billing.md:66). Studio 1,000 credits/mo (glossary.md:100). Free tier = signup default, no automated paid trial (billing.md:62). Hardcoded UI mirror: essential: "Essential — $399/mo" (apps/workspace/…/admin/billing/page.tsx:44-46).
  • The structure (canon-level, no numbers): per-T4A-seat model with structural non-charged T4/T4B (ADR-021 at architecture-decisions.md:695-725; client-spine.md:291-293; people-02-spec.md:316); reserve-on-invite seats + cooldown as a named future billing lever (ADR-058:2397); graceful-degradation lapse behaviour (ADR-023); Radar "facts free, patterns paid," one subscription, no micro-transactions, held-depth markers not paywalls (radar.md:86,98-101); Record Base/Mid/Top tiering (glossary.md:126,135); InstaLearn platform fee "percentage TBD" twice (instalearn.md:162,214).
  • The deferrals: ADR-021 defers all numbers to "commercial activation planning" (architecture-decisions.md:723); client-spine.md:421 rules pricing explicitly out of the spine's scope as "a downstream decision."

The finding: the house applies CANONICAL-DECISION DISCIPLINE to every architectural commitment, but its price points have never passed through any equivalent gate. $399/$699 entered via an infrastructure reference doc, got hardcoded into a UI, and now also anchor the ToS-adjacent marketing surface — while the document that should own them ("commercial activation planning," named by ADR-021) does not exist. Two internal price-adjacent contradictions already exist: InstaLearn free bundle is 10 courses at instalearn.md:117 and 20 at glossary.md:163; and the plans page sells an Enterprise SLA/contract that isn't real (§1.2). Pricing is currently the least-governed load-bearing commitment in the canon.

Boundary marker — end Section 1. Fable usage %: not agent-readable — [Tim: ____%]


2. Canon coherence

Evidence: full-read coherence sweep of standing-rules + all 63 ADRs + spine + method doc, and a spec-vs-deployed drift sweep against code at HEAD (static only — deploy/DB assertions marked UNVERIFIED). Both sweeps also verified non-defects, recorded at the end to bound the register. Findings ranked by consequence.

Recon note (index-wins rule, second occurrence): the brief says two standing-rules defects are "already known under STANDING-RULES-FOLD-HYGIENE-01 — confirm them." No artefact by that name exists in the repo or git history (repo-wide grep + git log --all --grep, 2026-07-06) — same shape as the PROJECT-BRIEF reference. The defect hunt below ran independently against HEAD; Tim reconciles these finds against the filing he holds. The two most defect-shaped standing-rules finds (2.2 and 2.3 below) are the likely candidates. → §5.

2.1 The position-1 document is the stalest document in the hierarchy

The Client Spine wins all conflicts by rule — and is frozen at 2026-05-27 while everything below it moved:

  • Retired module name used as live. Spine §6 is headed "the six current modules" and maps Documents as an Execute-phase module alongside Record (client-spine.md:263-269). WS-PRODUCT-01 v0.4 (14 May 2026) records Documents as fully retired into Record (product.md:18) — twelve days before the spine was filed. The spine also resolves the brief's own "six module specs" drafting defect: six was counting a module that no longer exists.
  • "25 ADRs" vs 63. client-spine.md:447 advertises the companion ADR log at 25 ADRs; the log ends at ADR-063 (architecture-decisions.md:2580). Every decision since 026 — the client-db split, the opaque cli_ key, the entire People/T4B/seat arc — is invisible from position 1.
  • Latent, not yet contradictory. The coherence sweep verified no ADR contradicts the spine (checked: no-platform-tier↔ADR-008, export↔ADR-010, tiers↔ADR-020) — but the spine's §5/§7 present as open questions things ADRs 032-063 have since closed. Drift today; contradiction the first time someone reads the hierarchy literally.

Which wins: on the Documents/Record point the hierarchy's literal answer (spine wins) would resurrect a retired module name. The spine is the loser-in-fact; product surface is WS-PRODUCT-01's scope (hierarchy position 2 on its own scope). Flagged accordingly: spine §6 carries the defect.

2.2 Duplicate rule with contradictory provenance — BRIEF-DRAFT-SUBSTRATE-VERIFICATION filed twice

standing-rules.md:504 files the rule as added by STANDING-RULES-PROMOTION-02 (2026-05-27), "earned through seven observable applications." standing-rules.md:811 files the same rule again as "(promoted 2026-07-05)… three applications." Two ### entries, one rule, two incompatible promotion histories. Likely FOLD-HYGIENE candidate #1; awaiting Tim's reconciliation against the off-repo filing.

2.3 The currency-header epidemic — the registry violates its own registered rule

METADATA-RECONCILIATION-AT-COMMIT (standing-rules.md:458) requires header currency to track content. At HEAD, in the governing documents themselves:

Doc Header says Content says
standing-rules.md:10 Last updated 2026-06-01 Own changelog runs to 2026-07-04; body rules dated 2026-07-05 (:811,:815) and 2026-07-02 (:375)
architecture-decisions.md:7 Last updated 2026-06-27 ADR-062/063 dated 2026-06-29; evolution paragraph omits 14 ADRs entirely (047-057, 061-063) while documenting 058-060
product.md:7 Last updated 5 June 2026 Own changelog v0.7 dated 1 Jul 2026; footer says 1 July
product.md:283 Build status "as of 17 April 2026" Sits unmarked in a governing v0.7 document; materially wrong (→ 2.6)
STATE.md:6 "update and commit at end of every session"; last updated 2026-04-10 ~3 months of daily sessions since; at least one listed pending item since superseded
standing-rules.md changelog Five body rules have no changelog entry at all (FENCE-ACTORS…, FENCE-DOC-HOUSE-PREFIX, CANONICAL-IDENTITY-AT-FK-BOUNDARIES, + the two 07-05 promotions)

One system-level finding, not six local ones: maintenance-on-write is practised for rule content but not for rule metadata, in exactly the documents whose metadata the rest of the system trusts for currency. (The mkdocs exclude_docs mechanism hiding _superseded/ + two ops/designs files from the built site while they sit on disk, mkdocs.yml:6-9, is the same class at the index layer — EXCLUDE-DOCS-NOT-UNDERSCORE-PREFIX is filed, so this is by-rule, but nothing marks the excluded files as excluded when read on disk.)

2.4 EXECUTION-AUTHORITY carve-out: stale rationale and two inconsistent lift-triggers

The rto-nrt-db destructive-op carve-out is justified at standing-rules.md:110 because the database "has no off-substrate backup yet," and :144 says the carve-out "lifts once a verified off-substrate backup exists." A verified backup now exists — and :112 (ruled RETAIN 2026-07-03) says the carve-out stands until a successful restore drill. The rule simultaneously states a lift-condition that has been met and a ruling that it hasn't lifted, with the rationale sentence still asserting a fact that is no longer true. The 07-03 ruling is the current truth; :110 and :144 are the losers and read as live. This governs destructive-op authority — worth fixing before it's read in a tired moment. Likely FOLD-HYGIENE candidate #2.

2.5 MANDARIN taxonomy: "four" in the frame, five in the body

standing-rules.md:166 frames "the four-category data-layer pattern" and :210 gives the enforcement test as "if it doesn't fit one of the four" — while :176 lists category 5 (Telemetry, added per ADR-028) and the changelog records "grows four → five." The enforcement clause of a load-bearing taxonomy tests against the wrong count.

2.6 Spec-vs-deployed drift — the stale surfaces are the product-doc and the glossary; the fresh docs hold

Where a canonical doc contradicts code at HEAD (spec cite ↔ code cite):

  • People is read-only; canon implies authoring. product.md:289 describes an editable register; people/page.tsx:102-106: "this surface is READ-ONLY. The Add-person flow and all write affordances are stripped."
  • Five compliance dots deployed; canonical spec says four, "never collapsed." people-02-spec.md:257-266 fixes four dimensions; compliance.ts:198-212 + people/page.tsx:233 ship a fifth (WWCC). The non-canonical companion reconciles it (people-03-companion.md:48 — "a suitability fact, not a fifth dimension"); the canonical spec and product.md do not.
  • Deployed compliance code carries the wrong Standards clause anchors the fresh spec's own top-priority redline corrected. people-02-spec.md:172,204-206 (§14 item 1, "highest-priority fix"): vocational competency = 3.2(b), industry currency 3.2(c), T&A 3.2(d). compliance.ts:97,117 still label 3.3, :177 labels 3.2 bare — the exact wrong anchors. Comment-level, but wrong legislative anchors inside a compliance product's compliance engine is not cosmetic. The one place code silently disagrees with a fresh canonical spec.
  • Radar is a live workspace tile; product.md:291 and foundation §20.4 don't know. grid-config.ts:73-78 ships radar un-flagged (RADAR-REGISTER-01 Gate 4, a03fb5c9); foundation.md:2259 still says "current live set is Studio · People."
  • Trainer Mapper spec-vs-spec conflict, edit owed and unmade. studio.md:422 claims Studio computes trainer-to-unit verdicts; people-02-spec.md:286,453 rules the verdict is People's and names the studio.md edit as owed. people-02-spec wins (fresh, explicit redline); studio.md is the loser and still reads wrong at HEAD.
  • Studio's "first-run video, every app" principle vs the deliberately killed button. studio.md:67-68 mandates it as a core design principle; commit 01d47f3d killed the dead intro-video button. A principle contradicted by a later ruling, never amended — a rationale-no-longer-holds instance in a spec.
  • Glossary v2.0 describes a Studio that isn't the deployed one. glossary.md:92,102 (PC-anchor content canvas; recent-sessions landing screen) vs studio/page.tsx:501-576 (two-column scope canvas, no landing screen); the content canvas is explicitly unbuilt (studio.md:415-424).
  • Worker inventory: billing-callbacks exists on disk, absent from inventory.md (undocumented worker); inventory.md:44 says stats-cache has "no on-disk source" — it does (workers/stats-cache/); glmd-ingest still in the active table with no source on disk (half-executed retirement).
  • Carried from §1: billing.md §8 file map lists three erased frontend files; two unreconciled sub-processor lists in the public trust centre; InstaLearn free bundle 10 (instalearn.md:117) vs 20 (glossary.md:163).

2.7 Stale forward-registers — the queue's own records trail reality

  • SEAT-COUNT-ATOMICITY-01 sits in the bank as "not started" while ADR-060 shipped and flipped Accepted 2026-06-27 (architecture-decisions.md:2510) — a done item still queued.
  • The data-layer queued-briefs doc (2026-05-17) lists MANDARIN-VIOLATION-01a/b/c as candidates; their close docs exist in outputs/ (untracked).
  • ADR-status housekeeping: ADR-056's Consequences still asserts "This ADR is Proposed" after its header flipped Accepted (architecture-decisions.md:2270 vs :2187); standing-rules and the ADR log disagree on which trio flipped together (053/054/055 at standing-rules.md:10 vs 054/055/056 at architecture-decisions.md:2290); ADR-058/059/060 status paragraphs open with the word "Proposed —" before recording the flip (append-style, reads contradictory); the doc's own Status enum omits "Proposed" (architecture-decisions.md:16); ADR-053 carries no partial-supersession marker though ADR-054 retired its D2 table.
  • Minor: standing-rules.md:1065 references briefs/backfill-01.md; the file lives at briefs/archive/backfill-01.md.

Verified non-defects (bounding the register)

Governance-hierarchy positions agree across all three docs that state them. No live spine-vs-ADR contradiction found. FOUNDATION-THEME-RECONCILE-01 did run (commit dcd25963, v1.27) and all five ADR-037-flagged sections now correctly describe light-default — the premise that they were still stale is false. People's fresh docs are accurate against code on the lifecycle gate (persons/route.ts:63-120 matches people-02-spec §16 nearly line-for-line), role vocabulary, and ADR-061 redaction. database.md's four conventions all hold. All spot-checked doc references exist on disk except the one noted.

Boundary marker — end Section 2. Fable usage %: not agent-readable — [Tim: ____%]


3. Unknown knowns — tacit rules never written down

Method: mined full git history (300+ commit subjects), sampled 10+ close/gate docs in the untracked outputs/ bank, and checked every candidate against all five canon docs plus the product glossary and CLAUDE.md before listing. Bar: 3+ practised instances AND absent from canon. Seven survive; two hypotheses were falsified and are recorded to prevent re-raising. Ranked by consequence.

3.1 "Shipped ≠ done" — the close-doc anatomy and the obligation ledger

The most consistent ritual in the corpus, filed nowhere. All ~111 -close docs share an unmandated skeleton: a Status line that distinguishes shipped from done ("SHIPPED + EQUALISED… LIVE WALK OWED. Not 'done.'"), a what-shipped block, a PROVEN-vs-OWED verification split, scope-held, banked, gate-status footer — and carry residual obligations in a stable ledger vocabulary: owed, carried, rides the next equalise, banked not actioned. Evidence: outputs/ADMIN-SURFACE-POLISH-01-close.md, outputs/BRICK-4c-01-close.md, outputs/BRIEF-INVITE-EXPIRY-01-close.md, outputs/ACTIVE-CLIENTS-SURFACE-01-close.md (untracked bank). Canon absence: standing-rules body has no close-report rule; "owed"=2 / "carried"=1 as incidental prose only; "rides the next" = 0. Would live: a close-report rule + ledger vocabulary under Brief discipline in standing-rules. This is the discipline that makes the whole obligation-tracking system work; it is currently inheritance-by-imitation.

3.2 SYNC CADENCE — cited by name as canon, defined nowhere

Close docs invoke "SYNC CADENCE" as though it were a filed rule: "no push; rides the next equalise per SYNC CADENCE" (outputs/BRICK-4c-01-close.md); "push HELD per SYNC CADENCE. main still 1 ahead of origin" (outputs/SYNC-FLEET-LEDGER-HYGIENE-01-gate4-confirm.md:4); "not pushed/equalised — run-close SYNC, not per-brief" (outputs/BRIEF-INVITE-EXPIRY-01-close.md). The practice: commit per brick, hold the push, equalise at run-close. Canon absence: no rule of that name or content anywhere; the adjacent EQUALISE-INCLUDES-DEV (standing-rules.md:259) governs what deploys at equalise, not the cadence. A named rule that exists only as folklore is the purest unknown-known in the corpus — the citation format has outrun the filing. Would live: a SYNC CADENCE rule beside (or absorbing) EQUALISE-INCLUDES-DEV.

3.3 The five-gate ladder's semantics

The five-gate pattern is named in canon three times (standing-rules.md:548,556,679) but what the five gates are — Gate 1 read-only audit, 2 design, 3 build/diff on bytes, 4 deploy + cert, 5 close — is enumerated nowhere. The semantics live only in commit-stream practice (253a0b22 "Gate 1: read-only audit" → 340606a1 "Gate 5 close", RADAR-SURFACE-01; same ladder in SYNC-CRON-SELF-FETCH-01, WORKER-ENDPOINT-AUTH-01, OBSERVATORY-TRUTH-01) and in 49/27/15/8 gate-numbered artefacts in outputs/. Only Gate 1's internal sub-split is filed (standing-rules.md:552). Would live: an ops/canonical-work-method.md cross-referenced from the canonical-work cluster.

3.4 Confirm-back (filename + sha256 + bytes) — a rule that lives in a changelog aside pointing at a memory file

18 distinct outputs/ files carry sha256 confirm lines; the discipline is universal at gate handovers. Its only canon presence is the standing-rules changelog line: "Confirm-back tightening reaffirmed (filename + sha256 + bytes per artefact, no exceptions — banked in feedback_done_means_published)" (standing-rules.md:10) — an aside whose authority pointer is a private memory file outside the repo. The inbound half (paste review bytes) is filed in CLAUDE.md:20-28; the outbound confirm-back half is not filed anywhere a future executor without that memory would find. Would live: a body rule in the canonical-work cluster.

3.5 The ops lexicon — load-bearing and defined nowhere

drip, brick, walk, equalise, pour, mint, arc structure how work is scoped, proven, and shipped. Usage in canon itself: architecture-decisions.md — arc 108×, brick 66×, mint 52×, walk 49×, drip 17×, pour 6×; standing-rules.md — arc 73×, brick 8×, equalise 7×. Zero definitions: the glossary (workspace/glossary.md) is explicitly product-scoped and defines none of them; no canon doc carries a definition block (verified by definition-pattern grep). A new executor — or the Opus follow-on pass this very audit schedules — must reverse-engineer the working language from context. Would live: an ops-lexicon appendix to standing-rules or its own ops/ops-vocabulary.md.

3.6 Commit-message grammar

BRIEF-NAME Gate-N <verb>: in-flight · BRIEF-NAME Gate 5 close: at close · docs(adr):/docs(canon): for canon maintenance · Fence inbound:/Fence filing: for crossings — consistent across 300+ commits (4bb78437, 1795589e, f31d914b, 46748ef3 among many). Never stated as a convention anywhere (one incidental citation in a closed brief, IMM-01-Phase-3c-close.md:105, is a mention not a definition). Would live: a commit-grammar note under Brief discipline.

3.7 The output-artefact suffix taxonomy

The brief-naming stem (<MODULE>-<SUBMODULE>-<NN>) is filed, and OUTPUTS-DIRECTORY-CONVENTION (standing-rules.md:912) files outputs/ as a workbench — but the suffix grammar the bank actually runs on (-gate1-findings ×49, -close ×111, -findings ×36, -audit ×19, -cue ×3, -recon, plus dated BANK-<slug>-<YYYY-MM-DD> staging files) is unfiled. Would live: an extension of OUTPUTS-DIRECTORY-CONVENTION.

Falsified candidates (checked, already filed — recorded so no future pass re-raises them)

  • The banked-corpus lifecycle is filed: BANKED-CORPUS RULE, standing-rules.md:858, plus banked/README.md.
  • The brief-naming stem is filed (standing-rules Brief-naming).
  • tap / chambered as ops vocabulary — failed the 3-instance bar (tap in outputs/ is the product gesture, not Tim-approval; chambered has near-zero corpus presence).

Section synthesis: the seven unfiled disciplines are all process disciplines, and all seven have a natural shared home — the gap is not seven scattered rules but one missing document: the canonical work method (gates, cadence, close anatomy, confirm-back, lexicon, grammar, artefact taxonomy). Standing-rules names the pattern's existence; nothing records its content. The house's operating system is currently transmitted by imitation of prior artefacts — which works exactly until the first executor who has no prior artefacts in context. → feeds §5.

Boundary marker — end Section 3. Fable usage %: not agent-readable — [Tim: ____%]


4. Competitive field — substrate-first aggregation

RECON NEEDED — deliberately not run in this session. Per the brief, this section is mechanical aggregation (SMS/LMS vendor detections across rto-footprint-ref, landscape-entity depth in rtopacks-landscape-prod, coverage honesty against the register total, and the unsurfaced-asset finding) and runs as a separate Opus pass appended to this document as a new versioned artefact. Table names above are as quoted in the brief and must be verified against the resource inventory at run time (docs/docs/infrastructure/cloudflare-resource-inventory.md). Read-only aggregation; every number cited to database and table; interpretation stays out of scope for that pass too (Tim + Claude session on the numbers afterwards).

Boundary marker — end Section 4 (stub). Fable usage %: not agent-readable — [Tim: ____%]


5. Questions this audit could not settle

Each with the exact check, document, or decision that settles it.

Product/commercial (from §1): 1. What is sold before Record exists? Studio+People as a category-competitive product, Radar intel subscription, or a founding-customer arrangement priced on the roadmap — the canon takes no position (§1.1). Settles by: a Tim product ruling, filed (WS-PRODUCT-01 amendment or ADR) — a PRIORITY-STATEMENTS-GET-FILED candidate event. 2. Which of the four revenue theses is first? Spine / Radar-intel / Marketer / InstaLearn each carry unbuilt remainders (§1.3). Settles by: the same filed priority statement. 3. Pricing ratification. $399/$699/$35 have never passed a decision gate; ADR-021's "commercial activation planning" artefact does not exist (§1.5). Settles by: creating that artefact and ratifying or revising the working numbers. 4. Does ToS §6 legally suffice for a first paid Essential/Pro customer without a standalone subscription agreement/DPA? Settles by: external legal review — not settleable from the repo. 5. Enterprise over-promise. Plans page sells "SLA commitments" and "a standard contract" that don't exist as artefacts (§1.2). Settles by: Tim's decision — write the artefacts or amend the copy. Flagged as live defect-shaped; untouched per stop-and-report. 6. SMS Connect build state. Named as a module (product.md:177); no sweep found code; absence not exhaustively proven. Settles by: one targeted grep/inventory check, then marking WS-PRODUCT-01 accordingly. 7. Import path for incumbent artefacts (trainer matrices, policy libraries). None found; absence unproven (§1.2 retention). Settles by: targeted check + a product decision on whether onboarding includes import. 8. InstaLearn free bundle: 10 or 20? instalearn.md:117 vs glossary.md:163. Settles by: Tim rules the number; loser doc edited.

Canon (from §2): 9. STANDING-RULES-FOLD-HYGIENE-01 reconciliation. The filing is not in the repo; are §2.2 (duplicate rule) and §2.4 (carve-out lift-trigger) its two known defects, and which of the remainder did it miss? Settles by: Tim reads §2 against the filing he holds; the filing (or its content) gets a repo home. 10. Does the Client Spine get a reconciliation pass? Position 1 is frozen at 2026-05-27 (Documents, 25-ADRs, pre-ADR-032 identity posture). Settles by: Tim schedules (or declines) a spine refresh — RECON-PASS-ON-FOUNDATION-SHIFT is the standing rule that speaks to it. 11. compliance.ts clause anchors (3.3 vs 3.2(b)/(c)/(d)) — live defect in a compliance product's engine comments, flagged not fixed. Settles by: a fix at Tim's sequencing. 12. Org Chart reachability (component exists, no route observed) and UCCA-test-client end-to-end currency — both UNVERIFIED static. Settles by: one live walk each. 13. billing-callbacks deploy state (source on disk, absent from inventory; deployment unverified). Settles by: one wrangler/inventory check + inventory.md row.

Process (from §0/§3): 14. Where does PROJECT-BRIEF live? Ruled a Claude-project-files orientation artefact, never repo-filed; governance references to it (archived brief, recon doc) point at nothing a repo reader can reach. Settles by: Tim rules its home (filed into docs/docs/ops/ vs explicitly project-files-only with a pointer). 15. Does the canonical work method get filed? Seven practised-but-unfiled disciplines with one natural home (§3 synthesis). Settles by: Checkpoint C triage — file, or explicitly discard with reasons. 16. Usage-pool visibility mechanic. Boundary markers could not be self-annotated (not agent-readable). Settles by: Tim annotating from /status, and ruling whether the mechanic stays for future Fable runs. 17. Section 4 scheduling. The Opus aggregation pass awaits its window; table names need run-time verification. Settles by: Tim taps the follow-on pass.


Red-team record

Target: the most consequential finding — §1.1, "the deployed product is not yet the canon's product."

The attack, steelmanned: the finding is a tautology dressed as a discovery. The house knows it is pre-revenue — standing-rules states "a pre-revenue bootstrapped operation with three people and zero customers" in plain text; ADR-034 deliberately fails billing closed; the queue's top items are precisely Record, the People seam, and the Radar ladder. An audit that "finds" the roadmap unbuilt has found nothing: it restates the build plan as if it were a defect, and its chargeability framing is a strawman because nobody proposed charging tomorrow. Under this attack, §1.1 collapses into "the plan is not yet executed," which is not a finding.

Why the attack fails against the finding as written: §1.1 does not claim the house doesn't know its own roadmap. It claims three things the pre-revenue posture does not answer: (a) the canon nowhere states the interim sellable proposition — what the first customer is buying while Record and the live connection don't exist — and that absence is a decision-gap, not a build-gap; (b) the deployed set currently embodies the fragmentation the canon's differentiation argument indicts (three capable modules, connection unbuilt), so the sales argument and the demo contradict each other today in a way the canon doesn't acknowledge anywhere; (c) the posture is not consistently pre-revenue at the surface: the live plans page sells tiers, seat pricing, Enterprise SLAs and a standard contract over a fail-closed rail — commerce theatre the "everyone knows we're pre-revenue" defence cannot explain. The finding survives because it is a canon-coherence finding about an undeclared commercial position, not a complaint that unbuilt things are unbuilt.

What the attack forced: a patch, applied in place. Early drafting of §1.1 leaned on "not chargeable as the compliance spine," which the attack legitimately punctures (chargeability-now was nobody's claim). The section as shipped states the finding as the undeclared interim proposition plus the self-contradicting surface — the form that withstood the attack. The queue-audit verdict (§1.3) was also softened from any "off track" reading to what the evidence supports: discipline is working, the missing piece is a declared sequencing among four revenue theses.

Residual weakness, stated honestly: §1.1's force depends partly on the walked-away-buyer construction (§1.4), which is a reasoned persona, not field data — no real evaluation transcripts exist in the repo to ground it. Section 4's observed-field numbers and any real prospect conversations would either harden or dissolve objections #1/#2/#5. That dependency is declared rather than hidden: it is §5 items 1-2 and the Section-4 pass.

Boundary marker — end of document (pre-publish). Fable usage %: not agent-readable — [Tim: ____%]


CANON-TRAJECTORY-AUDIT-01 findings — RTOpacks Alex on Fable 5, 2026-07-06. Read-only audit; no fixes applied. Section 4 rides the follow-on Opus pass as a new versioned artefact.