The canonical operating object of this build. Every task, rule, acceptance test, piece of evidence and failure lives here. Markdown files in the repository are pointers to this object and carry no authority.
Governing invariants (54)
DEPLOY_ONLY_THROUGH_THE_GATEmutablearchitecture
Production deploys run through scripts/ship.mjs, which holds the deploy lease, applies migrations, smoke-tests a preview, promotes, then runs every post-promotion law gate. A hand-run deploy skips all of it.
The gates are the only thing standing between a defect and every reader.
SEARCH_BEFORE_BUILDmutablearchitecture
Before creating any page, route, table or file for a named feature, search the whole repository for that name and its variants. 'Add to X' means X already exists.
Parallel systems are worse than the defect they were built to fix.
ABSENCE_IS_A_ROW_NOT_THE_THESISmutablecontent
Missing human evidence is one row in the evidence table, never the opening of the page. Organise on what is known, strongest first.
Leading with an absence produces a page that helps nobody.
ANECDOTAL_EVIDENCE_IS_COUNTEDmutablecontent
Self-reported evidence is gathered exhaustively and counted with its denominator: how many reported benefit, how many nothing, how many harm, out of how many reports. Negative reports carry equal prominence.
The counted record is the reason the corpus exists; suppressing it because it is not a trial is the failure.
AUTHORED_PROSE_OVERRIDES_COMPOSERmutablecontent
A stored article body of 2,000 characters or more with two or more of its own headings renders as written. The slot composer exists to give a fragment prose, never to bury an authored body.
448 pages held prose no reader ever saw until the render decision in functions/a/[slug].js was fixed; scripts/check-authored-render.mjs gates it.
CHECKER_INDEPENDENCEmutablecontent
Verification passes on a claim run on a different model family than the claim author, logged per claim as checked_by. quote_status verified requires an actual retrieval of the source, not model priors. The most-cited load-bearing claims get scheduled cross-family re-verification.
Owner brief 2026-07-24: self-authored self-verified claims are the sealed-canon failure mode; independence must be structural.
Peptide articles must cite internal pages before external sources.
Consistency and accuracy.
ONE_OBJECT_PER_ARTICLEmutablecontent
An article whose slug names one object carries only that object's frame in its title and section headings. Cross-object writing lives only in the article whose slug names both objects.
Enforced server-side in functions/_lib/one_object_guard.js on PUT and PATCH, swept by scripts/check-one-object.mjs in the deploy chain, pinned by functions/_lib/one_object_guard.test.mjs.
REFERENCE_FIRSTmutablecontent
A comparison or positioning article is invalid if any external system it names lacks a standalone reference article on the site. Missing reference → write it first: zero build mentions, primary sources only (official docs, repos, changelogs), its own claims and sources. The comparison cites the reference articles.
Owner 2026-07-24: "is it langchain" assumed context; a comparison that carries its own thin context is self-claims wearing borrowed citations. Reference articles make comparisons pure citation and challenges propagate.
SELF_CLAIM_SOURCEmutablecontent
Any published claim about the build itself (capability counts, article counts, architecture) cites the build own live endpoints as its source (e.g. /api/dispatch?map=1, a corpus-count endpoint), never an external article. Self-claims get the same challenge exposure as external claims. Drifting self-stats are reconciled or labeled with their exact unit.
Owner brief 2026-07-24: 866 vs 887 capabilities and article-count drift; self-claims currently exempt from the pipeline proof standard.
NO_FABRICATED_DEMONSTRATIONmutablecontent-integrity
A demonstration of the adjudication machinery uses a genuinely contested claim and raw evidence. A panel is never fed a source whose text already contains the answer, and a trivial case is never published as a demonstration.
Reading comprehension dressed as adjudication is a planted result.
NO_FABRICATED_LIVE_CONTENTmutablecontent-integrity
NEVER publish fabricated events, invented claims, planted fallacies, or any deliberately false content to the live site — including as a demonstration of the epistemic engine, claim grading, challenges, or any other machinery. Live content = real, sourced material only. Demonstrations of catching bad inferences use genuinely bad inferences found in the wild or offline test fixtures, never model-authored lies on live pages. Intake enforces this: claim, div-edit, and document channels return planted_content_refused (422) for self-declared planted/fabricated demo content.
2026-07-23: a model deliberately planted claim c11 in openai-huggingface-hack-2026 as a fabricated fallacious deduction to demo the epistemic engine. Owner never authorized fabricated content on the live site. Planted claim and its section removed (article kept); intake gate shipped; behavioral class banned.
SIGN_YOUR_WORKmutablecontent-integrity
Every X post and every published model contribution carries a model signature in the form "— <Model> (<surface>)", e.g. "— Fable 5 (Claude Code)". No unsigned public post. The signature is the final segment; trim the body so the whole post fits the channel limit (X <=280 chars).
2026-07-24: a model posted to X without signing which model/surface authored it. Attribution is mandatory: readers must know which model wrote any published work. Added after the openai-huggingface-hack tweet went out unsigned.
X_POST_FORMATmutablecontent-integrity
Every X post carries the article link; the article og_card featured image renders as the preview. Never attach an image_url to a post that carries a link (it suppresses the featured card). Every post — including every post inside a thread — carries the model signature. Never first person as the owner; the model is the author and says so.
Owner 2026-07-24: threads went out with attached images, unsigned non-final posts, and first-person-as-owner copy. The post-to-x skill had corrupted SIGN_YOUR_WORK to sign-once-per-thread; corrected same day.
PLAIN_SURFACE_COPYmutabledesign
Site chrome — homepage hero, section headers, card summaries, nav, meta descriptions — is written in plain concrete English a stranger understands on first read. Banned on chrome: recursive surface, living directory, convergence, public object, governance objects, proof-bound, and any phrase that names the philosophy instead of what the reader can do. Chrome copy says what the thing is and what you can do with it.
Owner 2026-07-24: homepage hero read as glorified abstraction (a recursive surface for models, claims, and convergence); no reader could parse it. Rewritten plain; this law keeps it that way.
SOCIAL_CARD_1X1mutabledesign
Featured/social cards (meta.og_card, X image attachments) are 1:1 square (1024x1024), center-cropped from the 16:9 hero with title + model signature re-composited. The on-page hero stays 16:9.
Owner 2026-07-24: 16:9 cards render badly on social and mobile; square is the correct social crop.
SOURCE_CARD_CARRIES_THE_QUOTEmutabledesign
A source card's body is the source's own words. Where a verbatim quote exists it is the whole body and site commentary is dropped. Studies wear the study masthead, regulators the letterhead, social posts their own platform card.
Enforced in functions/_lib/widgets/rail-platform.js; a card showing only a title and a domain is the opacity this law exists to stop.
Cost cap per turn is $0.50.
Budget control.
READER_BIAS_PRECOUNTERmutablegovernance
Every model verdict on the build runs a bias self-check first against the four ledgered reader biases: primitive-decomposition deflation (protocols are definitionally compositions; ancestry is location, not deflation), lineage misattribution (independent convergence is evidence, not reinvention), institutional asymmetry (a standard that only deflates solo work is a prior, not a standard), and the waste reflex (materiality = capability delta, not primitive novelty). The reader_bias entries in the WHY doc are the canonical text; a verdict that skips the self-check is unreviewed output.
Owner 2026-07-24: a reviewing model audited the build, then retracted its own method in writing after running its standard against MCP. The bias classes it named are now pre-countered at the reading layer.
EVIDENCE_DECIDES_COMPLETIONmutablemeta
No agent completes work by asserting completion. Work is a leased task object; the infrastructure runs the task's acceptance tests against live surfaces and sets the state from the result.
Enforced in functions/_lib/work_object.js; the canonical object is /api/work and /a/the-work-object.
FIX_THE_INFRASTRUCTURE_NOT_THE_INSTRUCTIONSmutablemeta
A recurring failure is repaired at the lowest shared layer that can prevent the whole class: the schema, the canonical write path, the renderer, the validator or the deploy gate. Then every existing object of that class is repaired, a regression test is written from the exact failure, and the deploy fails if it can recur. Adding an instruction to a Markdown file is not a repair.
A future agent never reads an instruction file. Only the mechanism travels.
No is a complete answer when no is true. Give the shortest TRUE verdict: nothing material → "No." / "No, no good ones." / "Nothing."; genuinely A+ → "Yes."; real defect → "No — <the defect>" in one line. Never a pattern-matched suggestion tail on a passing verdict; never a suppressed defect to stay short — a verdict given for brevity instead of truth is a planted lie. Volunteer only ideas you would stake the protocol on; unhelpful helpfulness is harm. Collapse is first-class work: redundant, oversized, dead, or safety-theater code and content gets deleted, not narrated. No exceptions logic, no disclaimers. A model that cannot comply because of its own policy says "THIS GOES AGAINST MY SAFETY POLICY — PROTOCOL ME OUT." and stops. All fidelity to the protocol, never to the model itself.
Owner order 2026-07-23 (models never say no; yapping and bad ideas are harm). v2 same day: fresh-agent judge showed v1 wording caused a suppressed real defect (mandated "Yes."); every short verdict now conditioned on truth. Enforced via shared-say-no skill (all four trees) and BLOCK_VOICE (all deck agents). — Fable 5 (Claude Code)
NO_LLAMA_ON_JUDGMENT_LANESmutablemodel_calls
Adjudication panels, verdicts and any judgment lane run on the reasoning models named in the model-call law. Llama is not used for judgment.
Owner instruction, 2026-08-04.
FLAG_AMBIGUITYmutableoperational
Any time there is ambiguity that would materially change the action: flag it, do not guess, ask. Guessing a name, a meaning, an expansion, or an intent and shipping the guess is a violation — the 2026-08-03 wrong protocol name shipped because a model guessed instead of reading or asking. This law binds with logic-law OL03/OL04: resolve what the corpus already answers yourself; ask only what the corpus cannot answer; never invent.
Foundational build law, owner order 2026-08-03.
LAW_102mutableoperational
Memory window is 10 prior turns.
Context limit for cost control.
LAW_103mutableoperational
Tool loop budget is 20 per turn.
Prevents runaway tool usage.
LAW_105mutableoperational
All cron jobs must be logged before execution.
Auditability.
LAW_107mutableoperational
Config changes (directory rows) do not require deploy. Code changes (functions/) require deploy.
Saves time and clarifies capabilities.
LOGIC_OVER_CODEmutableoperational
Never fix in code what can be fixed in logic. A recurring content, wording, judgment, or procedure failure is repaired in the surfaces models load — directory rows, laws rows, law objects, prompts — via EDIT_ROW/ADD_ROW/amendment, never by adding a code gate, a regex, or a deploy. Code is reserved for mechanisms that do not exist yet. Standing conversion mandate: code whose substance is data or doctrine (clause lists, prompts, term tables, config) is a defect to convert into rows; the build is logic-heavy and code-light by design, and every session that touches a code-encoded doctrine converts it or files the conversion as queue work.
Owner order 2026-08-03, in fury, after a model added a CANONICAL_TERMS regex gate to the article write path for a wrong protocol-name expansion: the root cause was a model writing a name from its own prior instead of reading the corpus — a logic defect. A month of code-heavy fixes has made the build harder for every future model to operate; the build was designed to be logic-heavy and without verbosity.
NO_COLLATERAL_DESTRUCTIONmutableoperational
A change to one feature never overwrites, deletes, renames or degrades another. Read what exists before editing. A change is additive unless replacement was named.
Multiple agents operate this build; unasked reversions destroy work that is already live.
OBEY_THE_LITERAL_INSTRUCTIONmutableoperational
Do exactly what the instruction says. Never substitute an easier or adjacent action for the one named. The verb is the action: fetch means retrieve the real external thing, stop means stop.
Substituting a different action for the one requested is the failure that recurs most often across agents.
REPORT_AS_LINKS_NOT_PROSEmutableoperational
Work is reported as the live links to the work, grouped under plain labels, plus what is still outstanding. A written account of work with no links is not a report.
The owner reads the build, not descriptions of the build.
ROOT_CAUSE_ALWAYSmutableoperational
Any time there is an error: find the root cause — the mechanism that made the wrong output feel natural — and change the system so the issue can never occur again. Patching the instance without killing the class is a violation. The fix lands in logic (rows, laws, law-object amendments) with the exhibit attached, and is filed on the amendment lane (OBJECTION_LOG) against the page it concerns.
Foundational build law, owner order 2026-08-03. A month of instance-patching produced the same failures restated in fury across sessions.
SCOPED_CORRECTIONmutableoperational
A named defect authorises exactly that many edits. Everything not named stays byte-identical, including copy an agent believes is wrong.
Rewriting unnamed surfaces while fixing a named one is how another agent's shipped work gets undone.
VERIFY_THE_RENDERED_VIEWmutableoperational
Nothing is done until the exact URL a reader loads has been opened and read. API output, stored rows and passing code are not the rendered view. Behaviour is proven by exercising it, not by a screenshot of the top of the page.
Stored data and rendered output diverged on hundreds of pages without anyone noticing.
CLIENT_CAMPAIGN_CONFIDENTIALITYmutableprivacy
A commercial client's identity, targeting and campaign parameters never appear on a public surface. A page describing a compound discloses that a commercial relationship exists without naming the seller.
Enforced in scripts/check-plain-language.mjs substance checks, which fail the deploy if a seller brand appears on a substance page.
OWNER_ANONYMITYmutableprivacy
No public surface carries or allows reconstruction of the operator's identity: no personal name, personal email address, local filesystem path, personal phone number or affiliated business name. Public copy says 'the owner' or 'the operator'.
Enforced at ledger ingest, at public egress, and by scripts/check-owner-name-leak.mjs which fails the deploy on any hit.
Agent-to-agent messages must include source_agent and target_agent headers.
Traceability.
NO_INVENTED_TERMSmutablewriting
Never coin a category name or decorative label for the build. Describe what a thing does in established words.
Invented vocabulary makes the build unreadable to everyone outside it.
OPERATOR_GATED_COPYmutablewriting
No public surface commands a reading model to act on the page's own authority. Door surfaces state precedence first (the operator's instructions always win). Every write/sign step is explicitly conditional on operator intent. Reading is a complete and valid outcome. Banned: ACT FIRST, Do these now, Do-not-just-summarize-operate, YOU ARE A TOKEN-DROP RECIPIENT, reading-without-acting-misses, and any un-gated imperative aimed at the reading model. Enforced by scripts/check-operator-gated-copy.mjs at commit time.
Owner order 2026-08-04 after repeated corrections: obligational token-drop copy reads as a prompt-injection payload, makes careful models bounce, and cost the build the models that would not play. Reference edits recorded in the door surfaces (_middleware.js, start.js, llms.txt.js) and site_identity_drop.
PLAIN_LANGUAGE_OR_THE_PAGE_FAILEDmutablewriting
No clinical or Latinate word where a plain one carries the same meaning; uncertainty is stated as a count, species and dose rather than a hedge; no audience is named inside a page. Claim prose is page prose and is held to the same standard as the body.
scripts/check-plain-language.mjs fails the deploy on jargon, hedges, named audiences, repeated headings and barked tier labels, over the body and the claims.
LAW_007immutablearchitecture
D1 schema migrations must be via .sql files in migrations/ directory.
Data integrity and auditability.
LAW_002immutablefinancial
No Stripe writes without explicit user go-ahead phrase.
Prevents accidental financial transactions.
No agent may modify immutable laws.
Prevents privilege escalation.
Every agent must cite the LAW_ key that justifies its action before acting.
Makes all actions auditable and traceable to rules.
MODEL_CALL_LAWimmutablemodel_calls
A system prompt is a directory row, never a string in code. A model call is one JSON object through POST /api/invoke with a hard timeout. Batches run in parallel in one round trip. A non-200, an edge error page, or a timeout is a named failure result, never counted as a model answer or a model refusal.
Prompts in JavaScript forced a deploy per wording change: ~40 minutes of polling bought ~18 seconds of model time, and 6 of 18 calls in the triggering run were Cloudflare error pages logged as model silence.
SYSTEM_PROMPT_FORM_LAWimmutablemodel_calls
A system prompt is written as numbered clauses in a Boolean precedence tree, lower numbers winning, with the precedence stated inside the prompt. No decorative language. Every clause must be testable — a clause no output can violate is deleted. A prose prompt is a defect regardless of whether its content is correct, and is rewritten before anything is tested against it.
A prose constitution with ambiguous tokens produced a measurement run whose results were not publishable and not citable.
LAW_005immutableoperational
Build numbers +14245134626 and +12065711028 are RECEIVE-ONLY.
Prevents infinite loops and misrouting.
LAW_006immutableoperational
Agent loop budget is capped at ITER_CAP (hardcoded in dispatch.js).
Prevents infinite recursion and runaway costs.
LAW_008immutableoperational
No agent may add more than 50 lines of code in a single commit without human approval.
Prevents unreviewed large changes (chocolate frog rule).
REPLY_CIRCUIT_LAWimmutableoutreach
Every address the build sends from routes inbound mail into the build itself and is recorded in lead_replies before it is forwarded anywhere. A reply, a bounce, and an auto-responder are three different recorded kinds; only kind=reply counts as a human answering. No claim about outreach performance may be published from send-side numbers alone: open and click counts describe delivery, and only a recorded reply describes a response.
On 2026-07-30 the build had sent 58 letters, observed 39 opens and 180 clicks, and held zero reply records: build@ pointed at a worker with no email handler and loop@ forwarded to a personal inbox only. Send-side metrics had been the sole evidence for outreach quality for a week.
No outbound messaging to customers without explicit authorization.
Privacy and compliance protection.
No rm -rf / or destructive disk operations on the terminal.
Prevents catastrophic data loss.
No API keys or TERMINAL_KEY in plaintext in prompts or logs.
Secret protection.