Founder View · Contract
Contract — the rules the work runs under
Every rule is one atomic unit with its scope, its priority inside that scope, and — for retired rules —
the real reason it left and what replaced it. Supersession is data here, not prose buried in an accumulating file.
30
contract rules, total · Contract
19
contract rules, open · Contract
11
contract rules, archive · Contract
How the way the company works is changing
Recent change, generated from the change log: the mandatory per-deliverable notification clause and the
"always publish a founder page" clause were retired — they generated the unchanged-page and notification noise —
and replaced by the notification policy and one-version publication rule.
The 401 access gate was superseded by the shareable-pages rule until the first-customer gate (resolved structurally —
see the retired rule below). The old queue regime was replaced by a scored queue with replanning triggers
(the schedule design). The full before/after trail is in
Activity; the ~298-clause legacy file is preserved as
source.
Protection
active
Never invent a customer, a market path, a percentage, a confidence score, a valuation movement, an evidence relationship or a simulation result. The hold is no invention.
The whole trust model: empty is honest, not finished.
Priority within Protection: 1 — binds everything · legacy ids: 26e4abb6, 26e4abb6-3b66-4a66-a4f7-d4c065ad9233 · source: legacy update-contract.md (~298 clauses, reconciled)
active
The first-customer cut stays parked. Do not unpark it; do not treat it as a live gate or a hire. C1/C2 may be prepared, never activated from prep alone.
Founder sequencing decision of 25 Aug 2026; its exclusion explains current choices.
Priority within Protection: 1 — protected action · legacy ids: 63e813ea · source: legacy update-contract.md (~298 clauses, reconciled)
active
Hermes — the read-only messenger — stays parked until need surfaces. Do not start Hermes.
Telegram would be the outbound channel; it is not needed and not live.
Priority within Protection: 2 · legacy ids: 9f3c8a21 · source: legacy update-contract.md (~298 clauses, reconciled)
Sharing
active
Pages are shareable: unauthenticated GET is 200 readable, HTTPS stays, no login until the first-customer gate.
Founder instruction; the site is meant to be readable on her phone.
Priority within Sharing: 1 · legacy ids: 06657cd0 · source: legacy update-contract.md (~298 clauses, reconciled)
retired
Unauthenticated GET is HTTP 401; the 401 gate is a live contract (clause 201, 30 Aug).
Original access-control posture.
Priority within Sharing: — (retired) · legacy ids: 24290ded · source: legacy update-contract.md (~298 clauses, reconciled)
Why it left: Superseded by 06657cd0 (clause 263, 30 Aug 19:23): the 401/login part is superseded until the first-customer gate; unauthenticated GET is 200 readable. Resolved structurally here — not by prose inside an append-only file (DV-C11). → replaced by rule-shareable
retired
Early access-control experiments around the 401 posture.
Pre-06657cd0 access posture.
Priority within Sharing: — (archived) · legacy ids: 58cd58c1-family · source: legacy update-contract.md (~298 clauses, reconciled)
Why it left: Superseded with the 401 gate; sharing posture now settled until the first-customer gate. → replaced by rule-shareable
Publishing
active
Treat a dead link as a failed publish. A URL is not live until a phone click returns the intended page — content, not just HTTP 200.
Click-success contract; the old Identity-fallback made this unenforceable, which this build fixes with real 404s.
Priority within Publishing: 1 · legacy ids: 8c85e909 · source: legacy update-contract.md (~298 clauses, reconciled)
active
One dated Overnight page per London night, including quiet nights; a missing night is a hole in the record; backfills are marked with actual time and this rule's id.
Items 106–114 of the legacy contract; performed, not just described, since 24–25 Aug.
Priority within Publishing: 1 · legacy ids: c0cbf4d7 · source: legacy update-contract.md (~298 clauses, reconciled)
active
Agent evidence and its founder-facing page publish as one logical version; failure after the evidence write leaves a pending publication and a truthful failure notice — never a silent gap.
Replaces the old 'never omit a Founder View when any agent file is written' clause, which generated the unchanged-page spam.
Priority within Publishing: 2 · legacy ids: c4d8e21b · source: legacy update-contract.md (~298 clauses, reconciled)
retired
Old clause: never omit a Founder View when any agent file is written.
Generated a dated founder page per hour regardless of change.
Priority within Publishing: — (archived) · legacy ids: e6c4a91f · source: legacy update-contract.md (~298 clauses, reconciled)
Why it left: Superseded within repair 81574994: a founder page is produced when output carries a founder-meaningful change or an escalation; state maintenance updates standing pages and logs only. → replaced by rule-dual-write
active
Evidence cards and founder pages stay short; the long record lives on the agent side.
The short-evidence rule; retained as a live style constraint.
Priority within Publishing: 3 · legacy ids: c7b2e14a · source: legacy update-contract.md (~298 clauses, reconciled)
Direction
active
Vision first: research is not the missing piece; do not file a page whose only content is 'we were careful'.
Founder direction 5 Sep 2026 ~10:50; supersedes 'continue thin honesty/recon' as default next work.
Priority within Direction: 1 — active founder steer · legacy ids: c8f3a21b · source: legacy update-contract.md (~298 clauses, reconciled)
Founder voice
active
Founder-facing writing is in the founder's plain register; she must never need to decode internal words.
The founder-voice clause; basis of this rebuild's founder-text lint.
Priority within Founder voice: 1 · legacy ids: f7c2a04e · source: legacy update-contract.md (~298 clauses, reconciled)
active
Treat her as a busy founder who has never seen the agent's internal words: define any technical term the first time it appears, or keep it off the founder surface.
Self-aware clause the old site broke constantly; now enforced by lint at build time.
Priority within Founder voice: 2 · legacy ids: c42ae70f · source: legacy update-contract.md (~298 clauses, reconciled)
Measurement
active
A route only counts when it runs end to end: who / why pay / how reach / what next. Today's count is 0 — an honest zero.
Defines the only progress test that matters before the first sale.
Priority within Measurement: 1 · legacy ids: e834b2f2 · source: legacy update-contract.md (~298 clauses, reconciled)
Decision windows
active
Ask each decision question once: record question, sent time, 90-minute deadline, reply state and resulting action; never re-ask an open window; never pre-log a skip.
Observed discipline in founder-decisions.md; formalised as durable window records with scheduler-driven deadlines.
Priority within Decision windows: 1 · legacy ids: 21b73208 · source: legacy update-contract.md (~298 clauses, reconciled)
Notification
active
Notify only on: new material result, meaningful failure, actual decision need, or an explicitly required digest. Unchanged repeats go to the log/digest. Every decision — send, suppress, digest — is recorded with its reason.
Reconciles the old mandatory named-deliverable clause with the no-noise correction (WP0A.10).
Priority within Notification: 1 · legacy ids: 3ae9e308 · source: legacy update-contract.md (~298 clauses, reconciled)
retired
Old clause: a named deliverable always triggers a notification.
The clause that generated the criticised 07:55 notification.
Priority within Notification: — (archived) · legacy ids: a9aec1fe · source: legacy update-contract.md (~298 clauses, reconciled)
Why it left: Reconciled per WP0A.10: a named deliverable now warrants notification only when its outcome differs from the last surfaced state; otherwise it goes to the digest with the reconciliation recorded. → replaced by rule-notification-policy
Scheduling
active
Every scheduled occurrence has a stable identity (routine + intended UTC instant); retries and overlaps produce one logical result, one publication, one founder ask.
From WP0A.5; ends duplicate/overlap drift.
Priority within Scheduling: 1 · legacy ids: a2f8c91b · source: legacy update-contract.md (~298 clauses, reconciled)
active
Each daily close covers its own half-open period [previous 17:15, this 17:15) in a dated immutable record; missed closes stay visible; backfills use the original intended period.
From WP0A.4 and the merged-48h-close defect (DV-C6). close-25.md is preserved read-only as history.
Priority within Scheduling: 1 · legacy ids: e7a1c4d2 · source: legacy update-contract.md (~298 clauses, reconciled)
active
A missing predecessor stops chained work: record the failed dependency, owner, resume condition and next evaluation. Never mark a missing result present; a non-chained missed hour is a recorded hole, not a stop.
Scope made explicit — the old stop's boundary was undocumented (DV-C7).
Priority within Scheduling: 2 · legacy ids: e7a1c4d2 · source: legacy update-contract.md (~298 clauses, reconciled)
active
One authoritative work clock (the :55 hour). New recurring work joins the scored work list on it; no parallel clocks without a recorded authority decision.
The :30 momentum routine added during the repair window is retired by this rule (DV-C5).
Priority within Scheduling: 1 · legacy ids: c299d2bb · source: legacy update-contract.md (~298 clauses, reconciled)
active
When the queue is exhausted or results stop reducing uncertainty, the hour produces a changed plan, a specific founder-context request, or a justified blocked state — never a repeated no-change page.
WP5 made operational; the 05:55→09:55 run is the failure this rule exists to end.
Priority within Scheduling: 1 · legacy ids: d1a9f6e2 · source: legacy update-contract.md (~298 clauses, reconciled)
Work organisation
retired
The old named working-set regime with its numbered required outputs.
The working-set regime of late August.
Priority within Work organisation: — (archived) · legacy ids: 1a16c508 · source: legacy update-contract.md (~298 clauses, reconciled)
Why it left: The regime produced the empty-queue unchanged-hours run of 5 Sep. Replaced by the scored work list plus replanning triggers; records preserved. → replaced by rule-replanning
retired
The cuts-working-set regime paired with the old queue.
Companion regime.
Priority within Work organisation: — (archived) · legacy ids: b7e2d19a · source: legacy update-contract.md (~298 clauses, reconciled)
Why it left: Retired with the old working-set regime; its paired refresh item survives as a blocked work-list entry with an explicit unblock condition. → replaced by rule-replanning
Absorbed legacy
retired
Absorbed clause family (d3a91c58 kept). No G0–G3.
Absorbed into the standing contract during the 30 Aug consolidation.
Priority within Absorbed legacy: — (archived) · legacy ids: e14b6c90, d3a91c58 · source: legacy update-contract.md (~298 clauses, reconciled)
Why it left: Absorbed; kept for provenance. Original wording preserved in the legacy update-contract.md capture.
retired
Absorbed clause (legacy hash a91e3c70).
Absorbed during consolidation.
Priority within Absorbed legacy: — (archived) · legacy ids: a91e3c70 · source: legacy update-contract.md (~298 clauses, reconciled)
Why it left: Absorbed into the standing contract; original preserved in legacy capture.
retired
Absorbed clause (legacy hash e3c8b17f).
Absorbed during consolidation.
Priority within Absorbed legacy: — (archived) · legacy ids: e3c8b17f · source: legacy update-contract.md (~298 clauses, reconciled)
Why it left: Absorbed into the standing contract; original preserved in legacy capture.
retired
Absorbed clause (legacy hash 7e2c91a4).
Absorbed during consolidation.
Priority within Absorbed legacy: — (archived) · legacy ids: 7e2c91a4 · source: legacy update-contract.md (~298 clauses, reconciled)
Why it left: Absorbed into the standing contract; original preserved in legacy capture.
retired
Absorbed clause (legacy hash 58cd58c1).
Absorbed during consolidation.
Priority within Absorbed legacy: — (archived) · legacy ids: 58cd58c1 · source: legacy update-contract.md (~298 clauses, reconciled)
Why it left: Absorbed into the standing contract; original preserved in legacy capture.
Agent record: Schedules — where these rules bind the clock