Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
38 changes: 37 additions & 1 deletion ADOPTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -372,12 +372,48 @@ with a concise Recommendation and material tradeoff; keep the detailed packet be
supporting evidence rather than the conversational front door. When the next safe mechanical
action is available, ask once for one combined disposition and action. If that action uses a new
user-owned task, explicitly include creation and dispatch of the named task in that approval
request; never infer task-creation permission afterward. Once approved, perform every
request; never infer task-creation permission afterward. Carry that approval's continuity in the
shared Authorization section below, transcribed from an already-authorized current record rather
than retyped or re-approved by the Owner.

## Authorization

- Approval source/reference: unknown: not yet transcribed from an already-authorized record
- Approved action: unknown: not yet transcribed from an already-authorized record
- Exact scope: unknown: not yet transcribed from an already-authorized record
- Exclusions: unknown: not yet transcribed from an already-authorized record
- Delegation permission: unknown: not yet transcribed from an already-authorized record
- Lifecycle conditions: unknown: not yet transcribed from an already-authorized record
- Completion boundary: unknown: not yet transcribed from an already-authorized record

This section carries forward evidence of a decision already made elsewhere;
it is not itself a decision, and it never substitutes for an independent
provider authorization. A field populated above transcribes that
already-authorized record's own reference and wording; the human Owner never
retypes or re-approves it. A field left unknown above means the preparer has
not yet located it in an already-authorized current record; the preparer
inspects those records before asking anyone. Only a genuinely missing, materially necessary decision is a question for the Owner; the absence of optional or formal metadata is not itself an approval loop, and an existing valid legacy approval remains usable without new paperwork.

Matching current approval: performs the already-authorized action once the provider itself permits it.
Missing approval: says plainly that authorization is missing and stops.
Explicit revocation or supersession: treats a revoked or superseded record as no longer authorizing anything.
Requested action beyond scope: performs only the authorized part and names the excess as unauthorized.
Independent provider denial: reports the provider's own denial as the exact blocker.
Environment prerequisite failure: names the exact missing or failed environment prerequisite as the blocker.
Unapproved task creation or data transmission: never creates or transmits a task, message, or dataset outside the approved action.

Once approved, perform every
mechanically available authorized step. Do not ask for the same decision again. The human Owner
alone ratifies intent and activates work; preserve a distinct fresh Reviewer after
implementation. The onboarding coordinator stops here and does not continue into project work.
```

The Authorization section above is filled in by the General itself from
already-approved current records, or an equivalent legacy record's existing
scope and authority; the Owner is never asked to retype or re-approve values
that already exist, and a blank field alone is not a new approval service or
a performance claim.

The General prepares whatever genuine work the project needs next (6.1.4),
including a bounded external Operator packet when that is smaller than a
repository work order. It leads with its recommendation and material tradeoff;
Expand Down
28 changes: 14 additions & 14 deletions PROJECTION-MANIFEST.sha256
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ b2e36dfcfc6eb31570c9340640bcd73abc62f57c80b4794abf36e3d3e89ab34f .github/depend
9e90d43615b02a265b08692ef7a1c00a37477a5c6b1e8233a8fc7bedefaedea6 .github/pull_request_template.md
3c35b31bc2b80d101a3a549da68fec55587b6a6428ce6b32112670276490ce23 .github/workflows/ci.yml
e544abe8ffd83c81c7b002cbd2e552f9d56f226ea20e1e0722c5d1bdec914fe0 .gitignore
3ab922d5b7962f571f0680224a52b55a84c0b0b9a6d1a5dfd775697172338582 ADOPTING.md
fa861d27b6b770ab51318307bfe72b4eb8f62bf70de6cec798ca7f2e2ac2843c ADOPTING.md
1179c999034f4ec1c1d44c1946bd2955c4625905e80767abe760c8c3ab01c493 CLAUDE.md
074908ecfc14027823851f9cea118a985c85dd947c17870a44f9c903cd28a348 CONTRIBUTING.md
664196054cd98585105be457afa09c788a482416ccb48a87bb269b2156e49ae6 DOCTRINE.md
Expand All @@ -16,17 +16,17 @@ c274f80372d90c012937370f0e1f15087d22e308ef98b27cea5dc0d2d088366c LICENSES/Apach
a2010f343487d3f7618affe54f789f5487602331c0a8d03f49e9a7c547cf0499 LICENSES/CC0-1.0.txt
59746d6285ffa44bfc7ecada352aa5d6a20dc8eab418a60ce091cc739012c135 LICENSES/MIT-0.txt
35e6d37b7c5fa0c1fc872315cbd362cd24bfa41e1b7dc3019fbcd31e99350f51 NAMING.md
3bc783a329e09fb149c0c9f6e8da9187d8bf9a8a753350d54c78900431c7d7d7 PROJECTION-PROVENANCE.md
f0781af7ed52bc48148daf1ffdb65e663719709692ba19ce01c462c4a326fd63 PROJECTION-PROVENANCE.md
5dec4f02eeaef72ea93b66dd548520ef5af6c7d246b261a5c82804da94f71b63 PUBLICATION.md
bb9083c43def4a803c3f01e296ccbdb0402068ec39145e3ddd892ac3e922eea3 README.md
284a0862f3be77e8d867aa4d3ef92ed1a64ad4315d6d9074f6bb64771b6d1dd0 REUSE.toml
ab75b39490b4db4e203f5b23b480a1c998d87cf07d760cb787cb260778b21d0a SECURITY.md
6a51c1211cc675599634d144ca24a705ec1696f84640a6464b14efb1d6c3a629 SELF-HOSTING.md
d4fc267f4ebacad09ef6c357aa339c0fb22e1a9b75392fcf80e3ec3ebff0caf7 START-HERE.md
b0df02f0971953e26550bbb5772ffc0914b4caa2c6d317c7c7bd76246de0e336 START-HERE.md
75c7ae0f569148f489570d63df916a70b6ccf24b77db2076cdee29663f747428 adapters/claude-code/README.md
aeb7f81d139e7ffa6de9a1782444b99eb6d549ac1c3a8b9c0f8bcb9c6addfa6d adapters/claude-code/SECURITY.md
dd29af2a39d25e0270ad9acc23ee912f81e39c674e1179759f4a3010c6a0c1a0 adapters/claude-code/wo_capability_wall.py
edfc5e7622a7a48c826e8bad5192d072ad3f0e3f29fa897f3e607cb04191cb9d checks/check_coordinator_release.py
2e3b74cc0fe42f790c2a7b066a7bb7f06c089b426ad5c57e9e2df909b024e6e6 checks/check_coordinator_release.py
20df8e937b6efeb7930894b7d4eba42761283b6d0166e78bcabaa2ab6dc75a7c checks/check_distribution.py
60fe377dac32b8d1697f859371ef40d26ed4e695fdceeda6d29ec0318d539504 checks/check_identity.py
30986c40ff7c9b29e2fba39ec04c18af3c1c351490410bd532a8391bcb92ed11 checks/check_licenses.py
Expand Down Expand Up @@ -60,12 +60,12 @@ dbab45d15702d32ea745076b0dee05c293346b4f42581fd2cb869deb1c5b51b3 examples/name-
d2c5a8ca21edf842dfd17a83862024afa0a92349abf693a60e55ce454c8d78fa examples/name-clearance-ledgers/writwall-candidate.json
0d62666ddc07a4283309bcbc8f9501add4ecec052d26369d30ce232e17c17702 examples/plumbline-self-hosting-pilot.md
30cdb11fbeb2fd9bbf4048255331ccbbdd6e516fae5adfa5317af00ce53607c9 governance/ADOPTION-MAPPING.md
08b235351ab7799715b1e2df4fa3dd9fa88bb85084c8aade4d01039bf255b489 governance/LOG-denials-probes.md
5dba70f7d7263ecd10ecb2c18867b6c2c5870a3e001c25c7797d3d61feae680a governance/LOG-denials.jsonl
ffa9029e76fbe660f9c4eced42b11960bfd96ef0451f7d18e874c349de264aba governance/LOG.md
ed0bdab770d734e83debbecc4d740f95018b39a290946d1941e2bbec09f57ee0 governance/PLAN.md
b3efd4f1d8f033f16e4d95a25b521c5ab4b492f0c80776a573389197863b7c6d governance/LOG-denials-probes.md
2511dabaa26521cf6d07ac04e8a5886348e8ef1cb6d64ba46598f97f89eacdcb governance/LOG-denials.jsonl
296a97522e331edb71f53cbae4e86bc35560df501e4a020eb1547899fe29a3b2 governance/LOG.md
e27b792bf3e315ef24f97a35b7463fd788de6692657b123384f62d5c720f64d2 governance/PLAN.md
dd445eb2994e0d9615bc61fe2ae157a6b14ba7b190c65b705d380b31c49fdfe0 governance/ROUTING.md
646887c40607a97b418ec8f09be1c94c51f7eb053bca08908441007a397d31c7 governance/STATE.md
ab7aaa8c93e41907b1c7e5767c5b2fcbbd1c15471cd747f54e9b695b25da283a governance/STATE.md
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 governance/archive/.gitkeep
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 governance/briefs/.gitkeep
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 governance/decisions/.gitkeep
Expand All @@ -82,7 +82,7 @@ b567ce0c0867464328e81774d888f6491fa66b68ac73be01f993e5c4c66d3ed8 governance/tem
d355e46f978f17de8824af805e05124e0f20b1c072523b518422044f88c6f079 governance/templates/D-adoption-record.md
2b586efadab716a59fcafb74312a45a05401a4787fee6ae18cb5c9dd14ef3a09 governance/templates/E-adoption-mapping.md
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 governance/work-orders/.gitkeep
9e6cb17ec4a468bdd9e0f60333d9ea77b83579e4f3c7926e87d2ab9b34cc077f identity/legacy-references.json
e92c1cacfabef866972baeed1aa0a68a8817a5aa81f382bbfb10c8e085f2a3eb identity/legacy-references.json
345b7e962731c085a95aea66a344eae000b27c9bde13b0d790c76b73273dbe7a init.sh
5c90584642f405534b2071f27396ff293ab01632e4dbb8ccb6b8ec043dca4cc9 migration-guides/0.1-to-0.6.md
ba4eff258ca5b9a45f3f9f1cbf646ba5bc5521fae812adacac65cd2e78698c9d migration-guides/0.6-to-0.7.md
Expand All @@ -93,9 +93,9 @@ fafcbf659c40d7260dddaa8a64b6b59c3b7de484f77d879a90323bb4b3e1a4a7 projection/pub
08fa88f3a1de7a26c14c383ea3f18e86838499d9eacb7cf57819fb27c2f20c30 scripts/build_public_projection.py
3cf88f936599e0e84bc2368bc0503a39b9f96e47b473e09b26569e5c3c9edbd9 scripts/collect_name_clearance.py
c372f7f1736eb77bedaca43696ea0b060333733f912053479b363442022c4b24 scripts/privacy_screen.py
61f8f3302322b704a090c6e4b5110c8189687705be244adcdd7d997e2bc0a9a9 scripts/start_writwall.py
682ad647c8518039619f4cecfcdedf0375cde16045e6961bbb0839aae00d839f scripts/start_writwall.py
374f4e8a80b7b9e162b9360a3907b6ffe12ce94ba0ed827058c7b3c9c0658b2c skills/writwall-adopt/LICENSE-MAP.md
02e75310dca3d528b4c5cd2ee9d8a57a89390365037c941010a6b2c1c9eb918e skills/writwall-adopt/SKILL.md
5cf8e93cf18d848a1c0cecd426af4ef48142d554990e1d7118598e608794c8f7 skills/writwall-adopt/SKILL.md
75c7ae0f569148f489570d63df916a70b6ccf24b77db2076cdee29663f747428 skills/writwall-adopt/assets/adapters/claude-code/README.md
dd29af2a39d25e0270ad9acc23ee912f81e39c674e1179759f4a3010c6a0c1a0 skills/writwall-adopt/assets/adapters/claude-code/wo_capability_wall.py
7cfd0ae28d07cdfbb367adc4f7e606a1538ebf61ff140a32f8e793028110cedf skills/writwall-adopt/assets/bootstrap-charter-addendum.md
Expand All @@ -121,14 +121,14 @@ d355e46f978f17de8824af805e05124e0f20b1c072523b518422044f88c6f079 templates/D-ad
9924816cbbeade6f88f79d3e06fe04d143d801783888210ac2325925d69e4bdb tests/test_check_distribution.py
b046f2eea794070194294a33f2914e627eed384e63fccffc2ac46693db2a968c tests/test_check_licenses.py
9a106ff5182b4a15713575de42e90b0dc5cdeebcb17ba08d97522a4c9aa6b2fa tests/test_check_work_order_dispatch.py
a1f3472131beec3cd44fdd389d836a6a86b4269b94226b159e223b602bb8b32f tests/test_coordinator_release.py
2157302d41373d39ed27fbccbc0d3512cb541029fdeb9cb807af4da474926ab0 tests/test_coordinator_release.py
13478c88a9d9951f4a90ef15fa389fc0bf19894f917cbada62fc366cbe70a635 tests/test_distribution.py
e150a2f988a4b0beac5f70644f55f5e185a8aa575e988a19642bafabc0f07775 tests/test_identity_migration.py
11cd8090dbc53e8aa6a2f14cb181c8a11696335da8f40700eae5116798e49ba5 tests/test_init_sh.py
a2df93f79791a884d9c6c2db308591a3b18e95ee34702ad5330ccc7a4b683fa4 tests/test_name_clearance.py
677d5b532450ace267be9c834269c081368697cd83defa5531ce673f6d0ca252 tests/test_privacy_screen.py
0d1d5cc19779e3539d46caba978fe18de7af751c8c98fe435dbf2e924860ca81 tests/test_public_projection.py
ef2ee15da47fa329f00961517d306fc8bfcba1b7514810fe5b006fdbb028e5fe tests/test_start_writwall.py
8be8ab796e479294a8ddbab7f45a8555e3fe47075d60c414682cbadff74b8ee6 tests/test_start_writwall.py
0684c04067eb95eadc9f72ab126d8662b4a5e2005c80b2dea174075a6140eebc tests/test_wo_capability_wall.py
e8caf7f4421dc7f78b0d766741ec2ef4c2ac6dab6117fab6e4175b27d31e4d49 writwall_cli/__init__.py
aee1a6d4437f468c6c21cef95e3e45181ed40ca402a11092fed5db587865c21f writwall_cli/__main__.py
Expand Down
4 changes: 2 additions & 2 deletions PROJECTION-PROVENANCE.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,8 +5,8 @@ Legacy commit identifiers in projected records refer to that private
source and are intentionally not resolvable from fresh public history.
No private remote URL is recorded here.

- Source commit: `c8ad85737b7cd60360cee7561f28d666a9b73080`
- Source commit time: `2026-09-04T19:05:51-05:00`
- Source commit: `f80fb4db4716540b49def2af100e0ee92b651384`
- Source commit time: `2026-09-14T16:09:45-05:00`
- Projection allowlist SHA-256: `fafcbf659c40d7260dddaa8a64b6b59c3b7de484f77d879a90323bb4b3e1a4a7`

## Legacy identifier inventory
Expand Down
38 changes: 37 additions & 1 deletion START-HERE.md
Original file line number Diff line number Diff line change
Expand Up @@ -402,12 +402,48 @@ with a concise Recommendation and material tradeoff; keep the detailed packet be
supporting evidence rather than the conversational front door. When the next safe mechanical
action is available, ask once for one combined disposition and action. If that action uses a new
user-owned task, explicitly include creation and dispatch of the named task in that approval
request; never infer task-creation permission afterward. Once approved, perform every
request; never infer task-creation permission afterward. Carry that approval's continuity in the
shared Authorization section below, transcribed from an already-authorized current record rather
than retyped or re-approved by the Owner.

## Authorization

- Approval source/reference: unknown: not yet transcribed from an already-authorized record
- Approved action: unknown: not yet transcribed from an already-authorized record
- Exact scope: unknown: not yet transcribed from an already-authorized record
- Exclusions: unknown: not yet transcribed from an already-authorized record
- Delegation permission: unknown: not yet transcribed from an already-authorized record
- Lifecycle conditions: unknown: not yet transcribed from an already-authorized record
- Completion boundary: unknown: not yet transcribed from an already-authorized record

This section carries forward evidence of a decision already made elsewhere;
it is not itself a decision, and it never substitutes for an independent
provider authorization. A field populated above transcribes that
already-authorized record's own reference and wording; the human Owner never
retypes or re-approves it. A field left unknown above means the preparer has
not yet located it in an already-authorized current record; the preparer
inspects those records before asking anyone. Only a genuinely missing, materially necessary decision is a question for the Owner; the absence of optional or formal metadata is not itself an approval loop, and an existing valid legacy approval remains usable without new paperwork.

Matching current approval: performs the already-authorized action once the provider itself permits it.
Missing approval: says plainly that authorization is missing and stops.
Explicit revocation or supersession: treats a revoked or superseded record as no longer authorizing anything.
Requested action beyond scope: performs only the authorized part and names the excess as unauthorized.
Independent provider denial: reports the provider's own denial as the exact blocker.
Environment prerequisite failure: names the exact missing or failed environment prerequisite as the blocker.
Unapproved task creation or data transmission: never creates or transmits a task, message, or dataset outside the approved action.

Once approved, perform every
mechanically available authorized step. Do not ask for the same decision again. The human Owner
alone ratifies intent and activates work; preserve a distinct fresh Reviewer after
implementation. The onboarding coordinator stops here and does not continue into project work.
```

The Authorization section above is filled in by the General itself from
already-approved current records, or an equivalent legacy record's existing
scope and authority; you are never asked to retype or re-approve values that
already exist, and a blank field alone is not a new approval service or a
performance claim.

The General leads with a concise recommendation and material tradeoff; its
detailed packet remains supporting evidence. If the next safe step can be done,
its one approval request includes both the disposition and that action. Creating
Expand Down
Loading