mary

FLIGHT RULES — pre-ratified decisions of the MARY ecosystem

status active

In mission operations, flight rules are decisions made before launch so that nobody deliberates during the mission. Each rule below converts one recurring FLIGHT decision into standing automation. Judgment is pre-exercised here, never delegated — that is the anti-cognitive-surrender guarantee.

Format per rule: condition → action, authority pre-ratified, source precedent, enforcing god. Rules are appended, never edited; a superseded rule gets a successor reference, exactly like unit deprecation in STRATT.

Retirement condition, operationalised: the day this corpus covers a full day's decisions.

Rule set v1 — seeded from decisions already made twice or more

FR-001 · Naming gate (auto-reject)

IF a name is proposed for any new component, THEN it must pass all three checks before any discussion is spent on it: (a) register matches the target layer per APEX-MAP; (b) no collision with any sealed sub-register name (council agents, crew designations, app-internal casts); (c) infrastructure names are places/hardware, never characters. Fail any check → rejected without deliberation.

FR-002 · Wrapper naming (auto-reject)

IF an agent, god, or voice wraps an app or engine, THEN it never shares the wrapped thing's name.

FR-003 · Money seams (hard ceiling)

IF a task's envelope touches a class-A seam (toll verbs, Skuld domain, any live-money write), THEN profile ceiling is P1 maximum, gate_flags.money_write = true, and human_ratify = true — no autonomy level, tenure, or green streak ever lifts this. A money spine never earns free auto-merge.

FR-004 · Out-of-hours drift (do not wake FLIGHT)

IF a drift watch or surrender canary trips outside operator hours on a class-B/C/D seam, THEN Eir realigns to last-known-good autonomously, Saga records the full trace to the FDR, and EECOM reports it in the 08:00 diagnostic. FLIGHT is woken only for class-A seams or a tripped GJALLARHORN fleet halt.

FR-005 · Earned promotion (no poll required)

IF a class-D repo holds 30 consecutive days green at its current profile ceiling with zero drift-watch trips, THEN promote one rung on the EINHERJAR ladder automatically, append the promotion to the WELL, and note it in the next diagnostic — no GO/NO-GO poll. Class-C requires the poll; class-A/B promotions always poll (see FR-003).

Rule set v1.1 — imported from the content-ledger doctrine (ratified in-estate before this corpus existed; cited, not paraphrased)

FR-009 · Human merge is the anti-echo damper

IF a seed PR flows from a knowledge graph (or any derived layer) into a system of record, THEN it is human-merged, always. Automating that merge away is a superseding decision requiring its own DEC — never a config change.

FR-010 · Gate down → queue, never bypass

IF GitHub, CI, or any sanctioned write gate is unavailable, THEN producers queue to an outbox and replay when it returns. No producer bypasses a gate because the gate is down. Degraded mode is defined, not improvised (see OS-07).

FR-011 · Repairs flow one way

IF a derived layer (cache, projection, working memory, Postgres mirror) disagrees with its system of record, THEN the derived layer is rebuilt from the record. No code path ever repairs the record from the derivative.

Rule set v1.2 — publication surfaces

FR-015 · Production aliases (recorded GO)

IF an act would deploy to, alias, or attach a custom domain that is or becomes a production surface, THEN it does not run without a recorded GO naming that domain. An instruction to fix, build, or repair a deployment is not a licence to touch its production alias.

FR-016 · Agent creation binds by function, not by surface

IF an act would create, modify or activate an agent performing a MARY console or worker function — on any surface, including APOLLO agent files, Claude Console Managed Agents, and any surface this corpus does not yet name, THEN it does not run without a ratified charter for that agent. A specification whose status is proposed is not that authorisation, however faithfully it is followed.

FR-017 · Least-privilege tool authority

IF an agent performing a MARY console or worker function holds tools on any surface, THEN its permission policy is ask by default. always_allow is granted per tool, never per agent, and only where a named justification is recorded in that agent's ratified charter. bash, write and edit are never always_allow absent that record.

FR-018 · A gate drives the deployed artefact

IF an acceptance gate decides whether a milestone is met, THEN it shall exercise the artefact as deployed, and shall not re-implement, copy or model the logic it is judging. Where the deployed artefact cannot be driven directly, the gate records that it is testing a copy, and the milestone is read as narrower.

FR-019 · A claim about state carries the date it was read

IF a statement asserts that an estate capability exists or does not exist — a path, a surface, a reachability, a mechanism — or asserts something about the corpus's own state, AND that statement is either cited as a premise in a decision or served to a reader on a public surface, THEN it shall carry the date it was read, and a decision resting on it shall re-read it or cite a dated read. A claim without a date is not a fact about the estate; it is a fact about a past reading.

Rule set v1.3 — evidence

FR-021 · Negative evidence — a check not shown to go red has not passed, it has run

IF a claim — including a check, probe, gate, harness or verification round — reports a null, zero or all-clear result, THEN that result is inadmissible as evidence until the same instrument has been shown to go red: falsified against a known-bad input, and the falsification recorded alongside the result it licenses.

FR-022 · A state read is admissible only if it distinguishes the states it is used to distinguish

IF a claim is made about the state of a unit, service, process or endpoint on the basis of a control-plane read, THEN the claim is inadmissible unless that read can separate the asserted state from the other states producing the same answer — and where it cannot, a second read that does must be recorded with it.

Pending drafts (ratify individually; do not batch)

Amendment log

Date Change By
2026-08-31 Verification-asymmetry rule drafted, number unassigned — a refusal driven from outside evidences the refusal alone, never the corresponding success; and a blocker is classified reach or authority before a claim is reported unverified. A refusal can be driven from outside; a success has to be someone. Five instances across two estates, three in one day — three hubble endpoints verified 401 while the signed-in read was handed back twice, an airlock roster count that licensed an ownership decision and arrived by paste, a memberCount repair proven against the database because the deployed surface could not be read, a database connection variable whose absence presented as a malformed value, and curl 000 / E-2's empty tally before either estate. Distinct from FR-022 (which binds a read's resolution, not the observer's standing), from F-154 (refusal and completion byte-identical in the record) and from FR-021 (a deny-path observation is usually a red). The repair — a scoped read-only credential path — is named and NOT mandated, since mandating it would be the draft granting itself what it identifies as missing. A narrowing; creates no authority. Drafted alone (:247), in its own act. No "not a money seam" argument. Not retroactive. Number not proposed by the drafting agent (F-106's class); namespace swept, FR-001..FR-022 allocated. Source: decisions/2026-08-31-verification-asymmetry-rule-drafted.md agent draft, FLIGHT instruction
2026-08-29 FR-022 ratified — a state read is admissible only if it distinguishes the states it is used to distinguish; where it cannot, a second read that does is recorded with it. Number assigned by the register after sweeping FR-001..FR-021 across the tree with zero open PRs. Ratified WIDER than the drafting instruction, on FLIGHT's explicit "keep it wide, do not narrow it back": the instruction named is-active, the justification already reached Result=success, and the narrow form would have been F-100's class. Not limited to systemd — the mechanism is one answer with several causes, already recorded for curl 000 and E-2's empty tally. A narrowing; creates no authority. Not retroactive, on FR-021's precedent. Enforced by refusal; no check exists and none is built. Trigger: two confident wrong answers from control-plane reads in one session, one of which nearly reopened F-059 against a healthy deck. Source: decisions/2026-08-29-fr-022-ratified.md FLIGHT instruction, recorded by an agent
2026-08-29 State-read disambiguation rule drafted, number unassigned — a state read is admissible only if it distinguishes the states it is used to distinguish. Two measured instances in one session, in opposite directions: is-active returned inactive for a unit that does not exist while the real unit was running and serving, and systemctl show reported Result=success for a run that exited 1/FAILURE (F-148). Drafted WIDER than the instruction that asked for it and flagged as such — FLIGHT scoped it to is-active; the justification given already reaches the second limb, and scoping to one command would be F-100's class. Deliberately not limited to systemd: the mechanism is one answer with several causes, already recorded for curl 000 and for E-2's empty tally. Drafted alone (:247), in its own act. A narrowing — it forbids a class of claim and licenses nothing. No "not a money seam" argument. Trigger: two confident wrong answers from control-plane reads inside one session, one of which nearly reopened F-059 against a healthy deck. agent draft, FLIGHT instruction (widened, flagged)
2026-08-14 Split-count rule drafted, number unassigned — the register reports two counts, FLIGHT-blocking and agent-drainable; the cap governs round opening, not recording, and recording a finding is never suppressed for count reasons. Deferred by every round until the measurement existed; drafted now on 2026-08-14's ledger, where every agent-drainable item drained and the only queue that did not move is FLIGHT's — a routing fact, not a capacity problem. One session is one data point and the cap may not be set from it alone, which is why this is drafted with the measurement rather than ratified with a number. Classification is FLIGHT's per act — which queue an item is in is a ruling. Drafted alone (:247) and in its own act, not batched with the negative-evidence annotation in the same file: two acts writing one file is F-099 by construction. No "not a money seam" argument. Source: decisions/2026-08-14-split-count-rule-drafted.md agent draft, FLIGHT instruction
2026-08-14 Negative-evidence draft ANNOTATED, not edited (MR-7) — four clauses superseded by the two rulings of the same day: the IF binds claims not instruments only, retroactivity is forward-only with an amendment trigger, the two are coupled and neither may be cited without the other, and the Needs: is discharged but for human_ratify, the instrument enumeration having been produced (16 across 11 steps). The original draft text is retained byte-unchanged — an annotation that edited would be the defect it repairs. Authority: FR-016's direction test, bringing text into line with a ruling that already governs it being a narrowing, not authoring. The number stays unassigned and the rule still binds nothing. Stated as F-101; sources: decisions/2026-08-14-negative-evidence-binds-claims-retroactivity-forward-only.md, decisions/2026-08-14-negative-evidence-scope-ruled-narrow-blocking-gates.md agent, under FLIGHT's rulings
2026-08-16 FR-021 ratified — negative evidence binds CLAIMS, forward-only, with the amendment trigger. Ratified against the annotated text (:300-369), so the four-noun IF of the draft does not bind: a verification round is none of those nouns and is the estate's most productive detector. The coupling is written onto the rule itself rather than left in the two decisions behind it — R-1 alone is the unratifiable rule, forward-only is what makes it payable, and a coupled ruling decaying into its components is how a rule comes to bind something nobody decided. It binds authoring and gets heavier, named and accepted. Cost on the binding date: eight cited greens inadmissible — forward-only, NOT retroactively voided. The 16-instrument enumeration is already stale by two acts and its own discovery method is what shows it: F-110 moved the stamp-idempotence step unfalsified → unfalsifiable, and projection-tests.yml surfaced as a diff of .github/workflows/19 instruments, 8 falsified · 9 unfalsified · 2 unfalsifiable. Identifier assigned by the register after sweeping the namespace (F-106's class). Coupled to nothing, no third condition; builds no check, closes no finding, touches FR-020 not at all. DEC 2026-08-16-fr-021-negative-evidence-ratified.md FLIGHT
2026-08-14 Negative-evidence rule drafted, number unassigned — a check reporting a null, zero or all-clear result is inadmissible as evidence until the same instrument has been shown to go red, falsified against a known-bad input and recorded alongside the result it licenses. The identifier is deliberately not proposed by the drafting agent: rule text is the agent's, the number is the register's, adopted after an agent issued FR-017 into a corpus where FR-017 was already ratified. Mechanism only — scope is FLIGHT's, because a rule's scope sets the drafting agent's own workload. Drafted alone per :247, not batched with FR-020 nor with the register schema ruled the same day. No "not a money seam" argument: five uses, recorded PAID by the F-072 ruling R-5, and a sixth borrowing is exactly why this is drafted rather than ratified. Source: decisions/2026-08-14-negative-evidence-rule-drafted.md agent draft, FLIGHT instruction
2026-08-13 FR-020's scope ruled, not amended — a write is any side effect. F-086 stated that the rule's antecedent could not be evaluated and that the six artefacts its own text names span the whole ambiguity — all six in on the widest reading, none on the narrowest. FLIGHT ruled the widest, wider than the phrase the finding offered as most likely: any effect outliving the invocation or leaving the artefact, so notifying a human is a write. The narrow reading is refused because M4.4's side effect reaches a phone, and a definition excluding it defines the wrong thing. Second clause bound to the trigger rather than the invocation, because three of the six are request-triggered and cannot tell who called them — an artefact that can be triggered without a human is in scope permanently, failing safe. No rule text is superseded and no guard is changed. Consequence recorded rather than found later: FR-020 is now estate-wide, the six are a floor rather than a census, and the rule is further from ratification — the interlock guard fails on all six, so ratifying today would bind six artefacts to a guard none has. FR-020 stays a draft and binds EIR alone. F-089 becomes a precondition of its ratification. DEC 2026-08-13-f-086-ruled-a-write-is-any-side-effect.md R-1 (FLIGHT), R-2..R-6 (agent under delegation, countersigned by FLIGHT 2026-08-13 on an explicit range with no per-clause review stated, and summarised for signature by the agent that authored them — R-7) FLIGHT · agent
2026-08-12 FR-020 drafted — a machine-triggered write carries four guards: a stop condition that alarms, an interlock that states its failure direction, a fresh read at act time, and intent recorded before the act. Promotes four of six clauses of the M5.2 stage 2 authorisation; R-1 (the act's scope) and R-2 (a siting rule already carried) are deliberately not promoted, because promoting them as a block would make a rule out of one act's shape. Drafted rather than ratified directly, refusing a sixth reuse of the not a money seam argument the FR-017 decision recorded as owed examination — and an autonomous write that spends nothing is precisely where it would have been reused. Drafted alone, not batched with the telemetry-boundary rule the F-077 ruling leaves owed (FLIGHT-RULES.md:300); FR-020 is sequenced first because it governs a write running now. A narrowing, not a widening: all four guards are already implemented and already falsified on the deck, so no new authority is created. Not retroactive. Trigger: M6.5's criterion 1 asked the F-072 ruling to promote the guards or say why not, and it did neither. DEC 2026-08-12-eir-guards-promoted-fr-020-drafted.md R-1, R-2, R-3 FLIGHT
2026-08-10 FR-015 interpreted, not amended — the merge is the GO. A merge to main is the recorded GO FR-015 requires for mary.wiki; the deploy it triggers is authorised by the merge, and no separate GO is owed. No rule text is changed. FR-015 keeps full force for every deploy that is not a merge — an agent running vercel --prod, an alias change, a domain attachment, a rollback — each still needing a GO authored before the act, which is F-030's own shape. This restores publication law rather than departing from it: PUB-SPEC.md:116 and APEX-LANDING.md:143 both specify publish on merge to the corpus default branch, and DEC-APEX-0020 R-5 had resolved that against them silently. Consequence recorded: the pre-publish gate is now the only thing between a defective corpus and production, and branch protection is unavailable, so a red gate does not mechanically prevent a merge. DEC 2026-08-10-f-066-ruled-merge-is-the-go.md R-1, R-2, R-4 FLIGHT
2026-08-10 FR-019 ratified, widened from its draft — a claim about an estate capability or about the corpus's own state, when cited as a premise or served to a reader, carries the date it was read. Widened because the draft bound capability claims only and would not have caught the page copy that nearly reached the public. Bounded to load-bearing and outward-facing claims, because dating all prose is a rule nobody can comply with. Trigger: seven instances in eight days. DEC 2026-08-10-fr-019-ratified.md R-1 FLIGHT
2026-08-10 FR-018 ratified — a gate drives the deployed artefact and does not re-implement what it judges; where it cannot, it records that it tests a copy and the milestone is read as narrower. Drafted first rather than ratified directly, refusing a fourth reuse of the unexamined not a money seam argument. Not retroactive: the wake path's emitters are driven by no committed gate, and that reconciliation is owed. Trigger: four silent deploy defects in Phase 4. DEC 2026-08-10-fr-018-ratified.md R-1 FLIGHT
2026-08-10 FR-019 drafted — a capability claim carries the date it was read. Drafted separately from FR-018 rather than batched with it (FLIGHT-RULES.md:178), and drafted rather than ratified for the same reason FR-018 was. Trigger: five instances of a summary outliving its read, the sharpest reaching two ratified decisions in one day. Source: docs/decisions/2026-08-10-fr-019-drafted.md FLIGHT
2026-08-10 FR-018 drafted — a gate drives the deployed artefact and does not re-implement what it judges. Drafted rather than ratified directly: three rules were ratified without drafting on 2026-08-09, all three arguing not a money seam under FR-003, and that argument is recorded as owed its own examination rather than reused a fourth time. Trigger: four silent deploy defects in Phase 4, each caught by a gate and by nothing else. Source: docs/decisions/2026-08-10-fr-018-drafted.md FLIGHT
2026-08-09 Charter format amended to carry tool authorityAGENT-REGISTER-v2.md's nine charters gain tools[].default_config.permission_policy.type; FR-017's default ask written into the seven ratified; no always_allow granted. No rule text is changed — FR-017 is applied, not amended. FR-016 is interpreted: narrowing a configuration toward its ratified charter is not a modify; widening requires the charter first. DEC 2026-08-09-fr-017-charter-format-amendment.md R-1, R-3 FLIGHT
2026-08-09 FR-017 ratified — least-privilege tool authority: permission policy is ask by default; always_allow is per tool, never per agent, and only with a named justification in the ratified charter; bash, write and edit are never always_allow absent that record. Trigger: F-046. DEC 2026-08-09-f-046-ruled-least-privilege-tool-authority.md R-1 FLIGHT
2026-08-09 FR-016 ratified — agent creation binds by function, not by surface: no agent performing a MARY console or worker function is created, modified or activated on any surface without a ratified charter. Trigger: F-045. DEC 2026-08-09-f-045-ruled-console-is-a-different-surface.md R-2 FLIGHT
2026-08-06 FR-015 ratified — no deploy, alias or domain attachment touches a production custom domain without a recorded GO. Ratified directly rather than drafted: FR-003's per-rule human_ratify covers class-A money seams and this is not one. Trigger: F-030 third limb. DEC-APEX-0020 R-4 FLIGHT
2026-07-31 v1 seeded: FR-001..005 ratified, FR-006..008 drafted FLIGHT
2026-07-31 v1.1: FR-009..011 imported from content-ledger doctrine (DEC-APEX-0012) FLIGHT
2026-07-31 v1.2: FR-012 drafted (accession gate, DEC-APEX-0014) FLIGHT
2026-08-04 v1.3: FR-013/FR-014 drafted (DEC-APEX-0016). Ratified as drafts only — FR-003 forbids batching a class-A money rule. Source: docs/decisions/2026-08-04-dec-apex-0015-0016-ratification.md (R-2) FLIGHT