In mission operations, flight rules are decisions made before launch so that nobody deliberates during the mission. Each rule below converts one recurring FLIGHT decision into standing automation. Judgment is pre-exercised here, never delegated — that is the anti-cognitive-surrender guarantee.
Format per rule: condition → action, authority pre-ratified, source precedent, enforcing god. Rules are appended, never edited; a superseded rule gets a successor reference, exactly like unit deprecation in STRATT.
Retirement condition, operationalised: the day this corpus covers a full day's decisions.
Rule set v1 — seeded from decisions already made twice or more
FR-001 · Naming gate (auto-reject)
IF a name is proposed for any new component, THEN it must pass all three checks before any discussion is spent on it: (a) register matches the target layer per APEX-MAP; (b) no collision with any sealed sub-register name (council agents, crew designations, app-internal casts); (c) infrastructure names are places/hardware, never characters. Fail any check → rejected without deliberation.
- Precedent: WATNEY (rejected, DW-APEX-05 collision), ZOID (rejected, register sprawl), ROCKY-as-agent (rejected, FR-002). Exercised three times before ratification — the definition of a rule worth writing down.
- Enforced by: Mímir (definition), Týr (gate on charter PRs).
FR-002 · Wrapper naming (auto-reject)
IF an agent, god, or voice wraps an app or engine, THEN it never shares the wrapped thing's name.
- Precedent: Kvasir≠KAHN, Brokkr≠Sparki, ROLAND≠ROCKY.
- Enforced by: Mímir; violations caught at G1 conformance.
FR-003 · Money seams (hard ceiling)
IF a task's envelope touches a class-A seam (toll verbs, Skuld domain, any
live-money write),
THEN profile ceiling is P1 maximum, gate_flags.money_write = true, and
human_ratify = true — no autonomy level, tenure, or green streak ever lifts
this. A money spine never earns free auto-merge.
- Precedent: toll charter (SWE-TOLL-001..009), Skuld posture, EINHERJAR ceiling doctrine.
- Enforced by: Týr (gate), Modgud (toll surface), Forseti (audit).
FR-004 · Out-of-hours drift (do not wake FLIGHT)
IF a drift watch or surrender canary trips outside operator hours on a class-B/C/D seam, THEN Eir realigns to last-known-good autonomously, Saga records the full trace to the FDR, and EECOM reports it in the 08:00 diagnostic. FLIGHT is woken only for class-A seams or a tripped GJALLARHORN fleet halt.
- Precedent: G4 realign autonomy, GJALLARHORN escalation tiers, EECOM report discipline.
- Enforced by: Eir (action), Heimdall (detection), Týr (class-A exception).
FR-005 · Earned promotion (no poll required)
IF a class-D repo holds 30 consecutive days green at its current profile ceiling with zero drift-watch trips, THEN promote one rung on the EINHERJAR ladder automatically, append the promotion to the WELL, and note it in the next diagnostic — no GO/NO-GO poll. Class-C requires the poll; class-A/B promotions always poll (see FR-003).
- Precedent: profile-ladder doctrine ("repos earn autonomy as their conformance history proves out"), minimal-human-approval principle.
- Enforced by: Forseti (verdict), Týr (class gating), Saga (record).
Rule set v1.1 — imported from the content-ledger doctrine (ratified in-estate before this corpus existed; cited, not paraphrased)
FR-009 · Human merge is the anti-echo damper
IF a seed PR flows from a knowledge graph (or any derived layer) into a system of record, THEN it is human-merged, always. Automating that merge away is a superseding decision requiring its own DEC — never a config change.
- Source: content-ledger doctrine rule 02; docs/decisions/2026-07-27.
- Enforced by: Týr (gate on the merge path), petrova-act (write verb).
FR-010 · Gate down → queue, never bypass
IF GitHub, CI, or any sanctioned write gate is unavailable, THEN producers queue to an outbox and replay when it returns. No producer bypasses a gate because the gate is down. Degraded mode is defined, not improvised (see OS-07).
- Source: content-ledger doctrine rule 06; converges independently with the OS-07 queue-in-FDR pattern — two designs, one instinct, now one rule.
- Enforced by: all producers; Heimdall (detection of bypass attempts).
FR-011 · Repairs flow one way
IF a derived layer (cache, projection, working memory, Postgres mirror) disagrees with its system of record, THEN the derived layer is rebuilt from the record. No code path ever repairs the record from the derivative.
- Source: content-ledger doctrine rule 03; generalises fleet-wide — the same law that keeps abacus sovereign keeps the FDR sovereign.
- Enforced by: Mímir (reconcile discipline), Eir (realign direction).
Rule set v1.2 — publication surfaces
FR-015 · Production aliases (recorded GO)
IF an act would deploy to, alias, or attach a custom domain that is or becomes a production surface, THEN it does not run without a recorded GO naming that domain. An instruction to fix, build, or repair a deployment is not a licence to touch its production alias.
- Source: F-030 third limb —
vercel --prod, run to repair fourERRORbuilds, reportedAliased: https://mary.wikiand put the gated apex live. Ratified by DEC-APEX-0020 R-4. - Ratified directly rather than drafted: FR-003's per-rule
human_ratifyapplies to class-A money seams, and this is not one. - This rule binds agents, not FLIGHT. FLIGHT deploying its own apex is the recorded GO.
- Enforced by: refusal, not substrate — the same posture as FR-009, since branch protection is unavailable on this repository's plan.
FR-016 · Agent creation binds by function, not by surface
IF an act would create, modify or activate an agent performing a MARY
console or worker function — on any surface, including APOLLO agent files,
Claude Console Managed Agents, and any surface this corpus does not yet name,
THEN it does not run without a ratified charter for that agent. A
specification whose status is proposed is not that authorisation, however
faithfully it is followed.
- Source: F-045 — nine agents were created from
AGENT-REGISTER-v2.mdwhile it was, and remains,proposed. Ratified by DEC2026-08-09-f-045-ruled-console-is-a-different-surface.mdR-2. - Binds by function, not by location. The defect was not a broken rule: it was a gate written about one surface silently failing to reach another, with nothing in either document making that visible. Binding by surface reproduces the defect the moment a tenth surface appears.
- Binds every actor, not only agents. This departs from FR-015 deliberately — the act F-045 describes was not an agent's, and a rule binding only agents would leave that path open.
- Ratified directly rather than drafted: FR-003's per-rule
human_ratifyapplies to class-A money seams, and this is not one. Same reasoning as FR-015. - Enforced by: refusal, and by inspection — the Console roster read, performed 2026-08-09 and repeatable in minutes. No substrate enforcement exists, the same posture as FR-009 and FR-015.
- Not retroactive. The nine agents standing at ratification are ungoverned rather than compliant; their reconciliation is owed under that DEC's R-4.
FR-017 · Least-privilege tool authority
IF an agent performing a MARY console or worker function holds tools on any
surface,
THEN its permission policy is ask by default. always_allow is granted
per tool, never per agent, and only where a named justification is
recorded in that agent's ratified charter. bash, write and edit are never
always_allow absent that record.
- Source: F-046 — nine charters describe behaviour in prose and grant no
authority; two of two agents sampled carried
Always allow, includingchesleyon eight tools (bash,write,edit,web_fetchamong them) under a charter reading "never fabricates, never exhibits". Ratified by DEC2026-08-09-f-046-ruled-least-privilege-tool-authority.mdR-1. - Per tool, not per agent. One setting covering eight tools makes
grepandbashthe same question. A per-agent grant cannot express "read freely, never execute", which is what the charters say in prose. - Companion to FR-016, not a duplicate. FR-016 governs whether an agent may exist; this governs what it may do. FR-016 passed while the implementation chose its own ceiling.
- Ratified directly rather than drafted: FR-003's per-rule
human_ratifyapplies to class-A money seams, and this is not one. Same reasoning as FR-015 and FR-016 — and that reasoning is now the standing justification for three direct ratifications in one day, which that DEC records as owed its own examination. - Answers the authority half of
SRS-AGENT-001.md:295-298D-2; D-2's registration question stands. - Not retroactive. Seven live agents hold unreconciled tool authority, six of them unread. The reconciliation pass is owed under that DEC's R-2.
- Enforced by: refusal, and by inspection of the agent's configuration view. No substrate enforcement exists — the same posture as FR-009, FR-015 and FR-016.
FR-018 · A gate drives the deployed artefact
IF an acceptance gate decides whether a milestone is met, THEN it shall exercise the artefact as deployed, and shall not re-implement, copy or model the logic it is judging. Where the deployed artefact cannot be driven directly, the gate records that it is testing a copy, and the milestone is read as narrower.
- Source: four silent deploy defects in Phase 4, each caught by a gate and by
nothing else — a substitution that missed an escaped placeholder (workflow
parsed, imported, activated, returned empty 200s);
n8n import:workflowcreating duplicates rather than updating; a digest substituting while the vault did not; andnode_exporterre-serialising a unix timestamp as1.78635721e+09, so a prober read1and alarmed every deck as decades stale. All four deployed, activated and answered. Drafted2026-08-10-fr-018-drafted.md, ratified2026-08-10-fr-018-ratified.md. - Generalises F-009 from a corpus defect to a gate design rule. F-009 was a contradiction produced by one function existing in more than one place; a gate holding its own copy of the logic is that shape, built deliberately.
- A unit test may exercise a copy. A gate deciding a milestone may not.
- Not retroactive, and the exception is named: M4.1, M4.2, M4.5's read procedure, M4.6 and M5.3 satisfy it. The wake path does not — M4.4's drills were real power-offs, but the emitter scripts live only on the decks and no committed gate drives them. That reconciliation is owed, in FR-016's shape: the standing artefacts are ungoverned rather than compliant.
- Drafted before ratification, deliberately. Three rules were ratified directly on 2026-08-09 all arguing "not a money seam" under FR-003, and the FR-017 decision recorded that argument as owed its own examination. A fourth reuse would have been the thing that record warned about.
- Enforced by: refusal, and by inspection of the gate. No substrate enforcement — the same posture as FR-009, FR-015, FR-016 and FR-017.
FR-019 · A claim about state carries the date it was read
IF a statement asserts that an estate capability exists or does not exist — a path, a surface, a reachability, a mechanism — or asserts something about the corpus's own state, AND that statement is either cited as a premise in a decision or served to a reader on a public surface, THEN it shall carry the date it was read, and a decision resting on it shall re-read it or cite a dated read. A claim without a date is not a fact about the estate; it is a fact about a past reading.
- Source: seven instances in eight days — F-049/F-053 (citations), F-051 (ODIN's
auto-renewal read
Onwhile three surfaces called it unread), F-054 (a drill projectedARMEDafter three surfaces said the timer was stopped), F-056 (F-009 named as a live blocker six days after closure), F-058 (the tailnet is an operator SSH path — into two ratified decisions on the same day, and it chartered M4.6 as unbuildable on an afternoon when M4.6 was built), and on 2026-08-10 two claims about the corpus's own state: a generator message and page copy that would have been served to the public, both reading "no corpus document carries a classification" hours after M6.1 falsified it. - Widened at ratification, deliberately. The draft bound capability claims
only and would not have caught the one instance that nearly reached the
public, because that was a claim about the corpus, not about the estate. A
rule whose own evidence escapes it is not ready to bind. DEC
2026-08-10-fr-019-ratified.mdR-1. - Bounded on purpose. It binds claims that are load-bearing (a premise) or outward-facing (served), not every sentence. Every one of the seven was one or the other. A rule nobody can comply with is worse than none — FR-001's own lesson — and dating all prose would be that rule.
- Distinct from MR-12, which ranks a projection below its source and would have caught none of the seven: each was a source whose own reading had expired. MR-12 is about rank; this is about time.
- Measured against the cheaper alternative: F-056's one grep per closure would have caught F-056 and F-051 and missed F-054, F-058 and both 2026-08-10 instances, because in those nothing was closed — a capability or a state simply changed.
- Enforced by: refusal; and for the served limb, mechanically —
tests/projection.test.tsasserts the landing copy agrees with what the projection actually produced, so the exact sentence that nearly shipped now fails the build instead.
Rule set v1.3 — evidence
FR-021 · Negative evidence — a check not shown to go red has not passed, it has run
IF a claim — including a check, probe, gate, harness or verification round — reports a null, zero or all-clear result, THEN that result is inadmissible as evidence until the same instrument has been shown to go red: falsified against a known-bad input, and the falsification recorded alongside the result it licenses.
- THE TWO CLAUSES ARE COUPLED AND NEITHER BINDS WITHOUT THE OTHER. The IF binds claims, not instruments only; retroactivity is forward-only, with an amendment trigger. R-1 alone is unratifiable — every load-bearing claim in the corpus is a population nobody has enumerated and which, by this rule's own standard, cannot be enumerated in less than a programme. The forward-only limb is what makes the claims limb payable. Written onto the rule at ratification rather than left in the two decisions behind it, because a coupled ruling decaying into its components is how a rule comes to bind something nobody decided, and the decay surface is a reader who never opens those decisions.
- Forward-only. A null already cited stays admissible where it stands. One that is a load-bearing premise of a ruling becomes inadmissible when that ruling is next amended — a trigger, not a sweep, costing nothing until somebody is already reading. Nothing is retroactively voided.
- It binds AUTHORING and it gets heavier. Named and accepted at ratification: drafting slows, and every gate authored from today carries its falsification paragraph.
- The cost on the binding date is a number: eight currently-cited greens
are inadmissible from 2026-08-16 — the unfalsified class of the 16-instrument
enumeration. That enumeration is already stale by two acts and its own
discovery method is what shows it: F-110 moved the stamp-idempotence step
unfalsified → unfalsifiable, andprojection-tests.ymlsurfaced as adiffof.github/workflows/, exactly as the method predicted an unlisted instrument would. Running total: 19 instruments — 8 falsified · 9 unfalsified · 2 unfalsifiable. - The falsification clause is folded IN, not carried as a corollary. Introspection is not the operative test; going red on demand is.
- Source: drafted
decisions/2026-08-14-negative-evidence-rule-drafted.md; scope and retroactivity ruleddecisions/2026-08-14-negative-evidence-binds-claims-retroactivity-forward-only.md; enumerationdecisions/2026-08-14-negative-evidence-scope-ruled-narrow-blocking-gates.mdR-3; ratifieddecisions/2026-08-16-fr-021-negative-evidence-ratified.md. - Identifier assigned at ratification, namespace swept first. The drafting
agent proposed no number, the register assigns it, and
FR-021was read free acrossdocs/,bin/,tests/and.github/before it was taken — F-106's class being that a correct read is the input to the defect, and the collision living in the interval between the read and the write. - Ratified alone, coupled to nothing, no third condition (
:247). No "not a money seam" argument is used anywhere in it — that credit was recorded PAID by the F-072 ruling R-5. - Enforced by: refusal. Nothing detects a null admitted without its falsification, and a check for it is owed, not built — stated here rather than discovered later.
- Built 2026-09-05, annotated not edited (MR-7).
bin/checks-registry-guardplusbin/checks-registry.json, blocking on PRs via--basenew-debt refusal (#545/#546): a newly-registered blocking check with no--self-testfixture refuses the merge. Narrower than the line above's original scope — it catches a new check lacking a falsification fixture, not every null admitted without one; two scripts (pubgate.pygateandcitations) are grandfathered as known debt, reported not refused. Source:decisions/2026-09-05-fr-021-enforcement-check-built-checks-registry-guard.md.
FR-022 · A state read is admissible only if it distinguishes the states it is used to distinguish
IF a claim is made about the state of a unit, service, process or endpoint on the basis of a control-plane read, THEN the claim is inadmissible unless that read can separate the asserted state from the other states producing the same answer — and where it cannot, a second read that does must be recorded with it.
- Two measured instances, one session, in OPPOSITE DIRECTIONS. 2026-08-29:
systemctl is-active node_exporterreturnedinactivefor a unit that does not exist — the unit isprometheus-node-exporter— an answer byte-identical to a genuinely dead unit, while the exporter was running and serving;is-enabledreturningnot-foundis what separated them, and it was only run because both were run. Andsystemctl show mary-door-execreportedResult=success,ExecMainStatus=0and an empty start timestamp for a run that had exited1/FAILURE(F-148). One read said dead when alive; the other said succeeded when failed. - DELIBERATELY NOT LIMITED TO SYSTEMD. The mechanism is one answer, several
causes, and this corpus has already recorded it elsewhere: a
000fromcurlis refusal, DNS failure and timeout alike; an empty tally is a clean corpus and a blinded resolver alike (E-2). Naming systemd would fix the rule to the instrument that happened to catch it, and the next instrument would not be covered. - RATIFIED WIDER THAN THE INSTRUCTION THAT REQUESTED IT, on FLIGHT's explicit
confirmation. The drafting instruction was "nothing concludes a unit is down
from
is-activealone" — one limb. The justification given already reached the second, and scoping to one command would have been F-100's class: a rule scoped below the reach of its own reason, reading as complete while leaving the second instance standing. The widening was flagged in the draft rather than smuggled, and FLIGHT ruled "keep it wide, do not narrow it back" before the number was assigned. - Stated as a PROHIBITION, not as two examples. That is the only form that survives: it will fire again, it will fire under a timer with nobody watching, and the next reader will run one command rather than two.
- A NARROWING. It creates no authority — it forbids a class of claim, and licenses no act, no widening and no new surface.
- The cost is named rather than found later. No enumeration exists of the state reads this binds — FR-020's and FR-021's shared predicament — and a large fraction of this corpus's existing unit-state evidence is a single read with no disambiguating second. Not retroactive, on FR-021's forward-only precedent: a read already cited stands where it stands.
- Enforced by refusal. No check detects a single-read state claim, and that check is owed, not built.
- Source:
docs/decisions/2026-08-29-fr-022-ratified.md. Drafted and ratified the same day, which is not the drafted-alone rule being waived — it was drafted alone, in its own act, and ratified in a second act on an explicit instruction naming it.
Pending drafts (ratify individually; do not batch)
FR-006 (draft) · PAO spend guard: campaign CAC exceeds threshold → CELIA pauses spend, files, reports at 08:00; no wake-up. (Needs: threshold value from first campaign baseline.)
FR-007 (draft) · Annex ingress: any L1A-origin envelope failing @rocky/contracts validation is dropped to Null0 before stamping, logged, not retried. (Formalises DW-APEX-04 as an action.)
FR-008 (draft) · FAO protection: no agent schedules FLIGHT-attention items outside FAO's timeline surface; ad-hoc interrupts require a gate flag.
FR-012 (draft) · Accession gate: no apex ships or is redesigned without an accession record in the ART-REGISTER and a plaque review assigning every vignette claim a truth-state (as-flown | aspirational). (Ratify after CHESLEY's first census provides the data baseline — a taste rule written before the collection is counted is FR-001's own sin in a beret.)
FR-013 (draft) · Money-spine admission: new monetisation enters through toll (
toll.provision/grant/checkout), not a new bespoke biller. Grandfathered: rocky, smo1/so1. (Drafted by DEC-APEX-0016; deliberately NOT ratified in that decision's 2026-08-04 act — FR-003 makes this a class-A seam requiring its ownhuman_ratify, and the grandfather list asserts which repos take live money today, a fact not yet verified. Needs: that verification.)FR-014 (draft) · Fail-closed is not fail-silent: a consumer whose entitlement check fails closed (G-1 class) shall raise an observable signal, not only deny. A silent denial is indistinguishable from "not entitled" and hides lost revenue. (Drafted by DEC-APEX-0016. Needs: wiring into TOLL-OBSERVABILITY-001 WT-03, which currently cites it as though standing.)
FR-020 (draft) · A machine-triggered write carries four guards. IF an artefact performs a write on this estate without a human in the loop, THEN its authorising decision states, before the act: a stop condition that alarms rather than falling silent; an interlock, and which direction it fails when it cannot be read; what state it re-reads at the moment of acting, and why a stale source is insufficient; and where intent is recorded before the act, such that no record means no act. (Drafted by
decisions/2026-08-12-eir-guards-promoted-fr-020-drafted.mdR-2, promoting R-3..R-6 of the M5.2 stage 2 authorisation. R-1 and R-2 of that decision are NOT promoted — one is the act's scope, the other a siting rule the corpus already carries. Drafted rather than ratified because an autonomous write that spends nothing is where "not a money seam" would have been reused a sixth time. Not retroactive: M4.1, M4.2, M4.3, M4.4, M4.6 and the FDR each perform machine-triggered work and none has been read against these four. Needs: that reconciliation, and its ownhuman_ratify.) Scope ruled 2026-08-13 (F-086, DEC2026-08-13-f-086-ruled-a-write-is-any-side-effect.md), added not edited: a write is any side effect — any effect that outlives the invocation or leaves the artefact, including emitting a record, appending to a durable store, writing a metric or state file, raising an alert, and notifying off the estate. The IF binds on the trigger, not the invocation: an artefact that can be triggered without a human is in scope permanently. So FR-020 is an estate-wide rule and the six named above are a floor, not a census — and it is further from ratifiable, not closer: the interlock guard fails on all six, so ratifying today would bind six artefacts to a guard none has. (Still needs: the wider census, the interlock gap, F-089's ruling, and its ownhuman_ratify.)FR-021 — RATIFIED 2026-08-16, retained here (MR-7) as the draft it was. The live rule is
### FR-021above; where this entry and that section differ, the ratified section governs. The number was assigned at ratification, by the register, after the namespace was swept — the convention this draft deliberately left unspent. (Drafted text follows, unedited.)FR-⟨number unassigned⟩ (draft) · Negative evidence: a check that has not been shown to go red has not passed, it has run. IF a check, probe, gate or harness reports a null, zero, or all-clear result, THEN that result is inadmissible as evidence until the same instrument has been shown to go red — falsified against a known-bad input, and the falsification recorded alongside the result it licenses. (Drafted by
decisions/2026-08-14-negative-evidence-rule-drafted.md. The number is deliberately unassigned: an agent proposes rule text and the register assigns the identifier, adopted after an agent issuedFR-017into a corpus where FR-017 was already ratified and load-bearing — a collision that passes every reading test a hurried reviewer applies. Mechanism only: the drafting agent wrote what makes a null admissible; which checks this binds, and from when, is FLIGHT's, because a rule's scope determines the drafting agent's own workload. The falsification clause is folded into the rule rather than carried as a corollary — introspection is not the operative test, going red on demand is. Written as a floor: the practice already exists here ad hoc and has caught a defect every time it was applied — the E-2 floor on three arms, D-3 on six, the M4.5 sampler's smoke test, F-090's failure path on the deck, and R-3's interlock driven red after a green that established nothing. Drafted alone (FLIGHT-RULES.md:300), not batched with FR-020 or with the register schema ruled the same day. No "not a money seam" argument is used — that credit was spent five times and recorded PAID by the F-072 ruling R-5; a sixth borrowing is why this is drafted rather than ratified directly. The termclass-Ais avoided entirely: it carries three referents here, and FR-005's repo autonomy tiers at:73remain distinct from the seam class even after the 2026-08-12 ruling joined the alert sense to it. Not retroactive as drafted — a large fraction of existing gate evidence is a null admitted with no recorded falsification, and whether that becomes inadmissible is the scope question. Needs: an enumeration of the instruments it would bind — none exists, which is FR-020's exact predicament named in advance — and its ownhuman_ratify.)- ANNOTATION 2026-08-14 (MR-7) — four clauses above are SUPERSEDED by two
rulings of the same day, and the draft text is retained unedited so the
supersession is legible rather than silent. Stated as F-101, found by
reading this document rather than the register's summary of it.
- The IF binds CLAIMS, not instruments only. "A check, probe, gate or
harness" above is superseded by
decisions/2026-08-14-negative-evidence-binds-claims-retroactivity-forward-only.mdR-1: the detector that found F-098's compositions, two duplications, the steps/instruments error and the H1 under-reach is a verification round, which is none of those four nouns — so the narrow form leaves the estate's most productive detector outside the regime. The rule therefore binds AUTHORING, gets heavier, and slows drafting; the cost is named and accepted. - Retroactivity is FORWARD-ONLY, with an amendment TRIGGER. R-2: a claim that is a load-bearing premise of a ruling becomes inadmissible when that ruling is next amended — not a sweep, and it costs nothing until then. "Whether that becomes inadmissible is the scope question" above is answered.
- R-1 AND R-2 ARE COUPLED AND NEITHER MAY BE CITED WITHOUT THE OTHER. R-1 alone is the unratifiable rule — every load-bearing claim in the corpus is a population nobody has enumerated and which, by the rule's own standard, cannot be enumerated in less than a programme. R-2 is what makes R-1 payable. A coupled ruling decaying into its components is how a rule comes to bind something nobody decided.
- The
Needs:above is discharged but forhuman_ratify. The instrument enumeration exists —decisions/2026-08-14-negative-evidence-scope-ruled-narrow-blocking-gates.mdR-3, 16 blocking instruments across 11 steps: 7 falsified, 8 unfalsified, 1 unfalsifiable, with the discovery method that makes an unlisted instrument surface as adiffof.github/workflows/. No enumeration of CLAIMS is owed, which is a direct consequence of R-2. The cost is a number: ratifying makes eight currently-cited greens inadmissible on the day it binds — forward-only, not retroactively voided. - The number remains unassigned. The register assigns identifiers; this annotation spends no part of that convention.
- Authority for annotating rather than restating: FR-016's ratified direction test — bringing text into line with a ruling that already governs it is a narrowing, not authoring. No clause here is absent from the two decisions. The rule still binds nothing.
- The IF binds CLAIMS, not instruments only. "A check, probe, gate or
harness" above is superseded by
- ANNOTATION 2026-08-14 (MR-7) — four clauses above are SUPERSEDED by two
rulings of the same day, and the draft text is retained unedited so the
supersession is legible rather than silent. Stated as F-101, found by
reading this document rather than the register's summary of it.
FR-⟨number unassigned⟩ (draft) · Split counts: the register has one count where the estate has two queues. The register reports two counts — FLIGHT-blocking and agent-drainable. A round is not opened while the FLIGHT-blocking count exceeds its cap. Recording a finding is always lawful and is never suppressed for count reasons. (Drafted by
decisions/2026-08-14-split-count-rule-drafted.md. The number is deliberately unassigned — the register assigns identifiers, the drafting agent proposes text. Deferred by every round until the measurement existed, a cap chosen by intuition reproducing inside a rule the problem the rule names. The measurement, dated 2026-08-14: in one session, 7 findings opened, 5 rulings recorded, 1 tool built and falsified on six arms, 1 duplicate reconciled, 6 citation repairs, 12 PRs all green — every agent-drainable item drained, and the only queue that did not move is the one requiring FLIGHT specifically. That is a routing fact, not a capacity problem, and one number cannot tell the two apart. The cap governs round OPENING, not RECORDING — written first because it is the clause an implementation would quietly invert, a cap binding recording being trivial to enforce and destructive of the register. The cap must cite a measured drain rate: one session is one data point and the cap may not be set from it alone, which is why this is drafted with the measurement rather than ratified with a number. Classification is FLIGHT's, per act — which queue an item is in is a ruling, and an agent classifying its own blockers is the judgment least visible from where the agent stands. Drafted alone (:247) and in its own act, not batched with the negative-evidence annotation above: two acts writing one file is F-099 by construction. No "not a money seam" argument is used — spent five times and recorded PAID by the F-072 ruling R-5.bin/register-countis NOT extended: the second axis needs a per-row classification the markup does not carry and which FLIGHT holds, so building it now would encode an agent's classification as data. The cost is stated rather than found later — the rule adds a classification step that is FLIGHT's per act, so each agent-drainable item generates a new FLIGHT-blocking one, a rule about routing that itself routes to the constrained queue; that objection is not answered. Needs: a cap citing a drain rate measured over more than one session, and its ownhuman_ratify.)A state read is admissible only if it distinguishes the states it is being used to distinguish — number unassigned.RATIFIED 2026-08-29 AS FR-022 — live text above; the draft is retained unedited below (MR-7). The register assigned the number after sweepingFR-001..FR-021, and FLIGHT ruled the width before the assignment. (Drafted 2026-08-29.)IF a claim is made about a unit's, service's or process's state on the basis of a control-plane read, THEN the claim is inadmissible unless the read can tell the asserted state from the other states that produce the same answer — and where it cannot, a second read that does must be recorded with it.
Two measured instances, one session, opposite directions.
systemctl is-active node_exporterreturnedinactivefor a unit that does not exist — the unit isprometheus-node-exporter— which is byte-identical to the answer for a genuinely dead unit; the exporter was running and serving, andis-enabledreturningnot-foundis what separated them. Andsystemctl show mary-door-execreportedResult=success,ExecMainStatus=0and an empty start timestamp for a run that had exited1/FAILURE(F-148). One read said dead when alive; the other said succeeded when failed.The number is deliberately unassigned: rule text is the agent's, the identifier is the register's — the convention adopted after an agent issued
FR-017into a corpus where FR-017 was already ratified.DRAFTED WIDER THAN THE INSTRUCTION THAT ASKED FOR IT, AND THAT IS FLAGGED RATHER THAN SMUGGLED. FLIGHT's words were "nothing in this estate concludes a unit is down from
is-activealone." That is one limb. The justification offered — that systemd state reads give confident wrong answers — already reaches the second limb, and scoping tois-activewould be F-100's exact class: a rule scoped below the reach of its own reason, which reads as complete and leaves the second instance standing. Narrowing it back is FLIGHT's and costs one line; discovering the omission later costs an incident.Stated as a PROHIBITION, not as two examples, because that is the only form that survives. It will fire again, it will fire under a timer with nobody watching, and the next reader will check one command rather than two — this session's near-miss was caught only because both were run.
Deliberately NOT limited to systemd. The mechanism is one answer, several causes, and the estate has already recorded it elsewhere: a
000fromcurlis refusal, DNS failure and timeout alike; an empty tally is a clean corpus and a blinded resolver alike (E-2). Naming systemd would fix the rule to the instrument that happened to catch it.A NARROWING, and it creates no authority. It forbids a class of claim; it licenses no act, no widening and no new surface. Drafted alone (
:247), not batched with any other draft, and filed in its own act. No "not a money seam" argument is used — that credit was spent five times and recorded PAID by the F-072 ruling R-5.The cost is named in advance: no enumeration exists of the state reads this would bind, which is FR-020's and the negative-evidence rule's shared predicament, and a large fraction of this corpus's existing unit-state evidence is a single read with no disambiguating second. Not retroactive. (Needs: FLIGHT's ruling on the width above, and its own
human_ratify.)Verification asymmetry — a refusal driven from outside does not evidence the success. Drafted 2026-08-31, number unassigned. IF a claim is evidenced only by an observation available to an unauthenticated or unprivileged caller — a refusal, a
401, a missing credential, a guard that fires — THEN it evidences the refusal alone and does not evidence the corresponding success; the allow path is a separate claim, requiring an observation made as a principal holding the authority. And before a claim is reported unverified, its blocker is classified as authority (nobody has decided) or reach (the decision exists, no credential is at hand) — different repairs, and only one is a question for a human.A refusal can be driven from outside; a success has to be someone. The asymmetry is structural, not incidental: an unauthenticated
curl, an unset variable or a mutated constant drives a deny path to completion in seconds, while the matching allow path needs a session, a membership or a connection string. So a session verifying its own work accumulates evidence for the half of the behaviour that matters least and reports the rest as pending without noticing that every pending item shares one cause.Five instances across two estates, three of them in one day: three hubble endpoints verified
401while a signed-in member still sees all 27 rows was handed back twice; an airlock roster whose count licensed an ownership decision and arrived by paste; amemberCountrepair proven against the database because the deployed surface could not be read; a database connection variable whose absence presented as a malformed value; and, before either estate,curl000and E-2's empty tally.Distinct from FR-022, which binds a read's RESOLUTION — a read may distinguish perfectly what it can see and still be taken from outside. Distinct from F-154, where refusal and completion are byte-identical in the record; here they are perfectly distinguishable and only one can be produced. Distinct from FR-021: a deny-path observation is usually a red.
The repair is a scoped read-only credential path, named and NOT mandated — in none of the five instances was anyone unwilling to authorise the read; the authorisation simply had no credential attached. Requiring one would be a widening, and would be this draft granting itself the thing it identifies as missing.
The test, for a session to apply before it starts: can this claim be driven from outside, or does it need to be someone?
A NARROWING — it forbids a class of claim and licenses no act, no widening and no new surface. Drafted alone (
:247), in its own act. No "not a money seam" argument is used. The cost is named in advance: no enumeration exists of the claims it would bind, and a substantial share of this corpus's evidence for a thing works is a recorded refusal plus an argument. Not retroactive, on FR-021's precedent. Enforced by refusal; no check detects a deny-path observation cited for an allow-path claim, and none is built. (Needs: FLIGHT's ruling on scope — all claims, or bounded to load-bearing and outward-facing ones as FR-019 was — and its ownhuman_ratify. Source:docs/decisions/2026-08-31-verification-asymmetry-rule-drafted.md.)
Amendment log
| Date | Change | By |
|---|---|---|
| 2026-08-31 | Verification-asymmetry rule drafted, number unassigned — a refusal driven from outside evidences the refusal alone, never the corresponding success; and a blocker is classified reach or authority before a claim is reported unverified. A refusal can be driven from outside; a success has to be someone. Five instances across two estates, three in one day — three hubble endpoints verified 401 while the signed-in read was handed back twice, an airlock roster count that licensed an ownership decision and arrived by paste, a memberCount repair proven against the database because the deployed surface could not be read, a database connection variable whose absence presented as a malformed value, and curl 000 / E-2's empty tally before either estate. Distinct from FR-022 (which binds a read's resolution, not the observer's standing), from F-154 (refusal and completion byte-identical in the record) and from FR-021 (a deny-path observation is usually a red). The repair — a scoped read-only credential path — is named and NOT mandated, since mandating it would be the draft granting itself what it identifies as missing. A narrowing; creates no authority. Drafted alone (:247), in its own act. No "not a money seam" argument. Not retroactive. Number not proposed by the drafting agent (F-106's class); namespace swept, FR-001..FR-022 allocated. Source: decisions/2026-08-31-verification-asymmetry-rule-drafted.md |
agent draft, FLIGHT instruction |
| 2026-08-29 | FR-022 ratified — a state read is admissible only if it distinguishes the states it is used to distinguish; where it cannot, a second read that does is recorded with it. Number assigned by the register after sweeping FR-001..FR-021 across the tree with zero open PRs. Ratified WIDER than the drafting instruction, on FLIGHT's explicit "keep it wide, do not narrow it back": the instruction named is-active, the justification already reached Result=success, and the narrow form would have been F-100's class. Not limited to systemd — the mechanism is one answer with several causes, already recorded for curl 000 and E-2's empty tally. A narrowing; creates no authority. Not retroactive, on FR-021's precedent. Enforced by refusal; no check exists and none is built. Trigger: two confident wrong answers from control-plane reads in one session, one of which nearly reopened F-059 against a healthy deck. Source: decisions/2026-08-29-fr-022-ratified.md |
FLIGHT instruction, recorded by an agent |
| 2026-08-29 | State-read disambiguation rule drafted, number unassigned — a state read is admissible only if it distinguishes the states it is used to distinguish. Two measured instances in one session, in opposite directions: is-active returned inactive for a unit that does not exist while the real unit was running and serving, and systemctl show reported Result=success for a run that exited 1/FAILURE (F-148). Drafted WIDER than the instruction that asked for it and flagged as such — FLIGHT scoped it to is-active; the justification given already reaches the second limb, and scoping to one command would be F-100's class. Deliberately not limited to systemd: the mechanism is one answer with several causes, already recorded for curl 000 and for E-2's empty tally. Drafted alone (:247), in its own act. A narrowing — it forbids a class of claim and licenses nothing. No "not a money seam" argument. Trigger: two confident wrong answers from control-plane reads inside one session, one of which nearly reopened F-059 against a healthy deck. |
agent draft, FLIGHT instruction (widened, flagged) |
| 2026-08-14 | Split-count rule drafted, number unassigned — the register reports two counts, FLIGHT-blocking and agent-drainable; the cap governs round opening, not recording, and recording a finding is never suppressed for count reasons. Deferred by every round until the measurement existed; drafted now on 2026-08-14's ledger, where every agent-drainable item drained and the only queue that did not move is FLIGHT's — a routing fact, not a capacity problem. One session is one data point and the cap may not be set from it alone, which is why this is drafted with the measurement rather than ratified with a number. Classification is FLIGHT's per act — which queue an item is in is a ruling. Drafted alone (:247) and in its own act, not batched with the negative-evidence annotation in the same file: two acts writing one file is F-099 by construction. No "not a money seam" argument. Source: decisions/2026-08-14-split-count-rule-drafted.md |
agent draft, FLIGHT instruction |
| 2026-08-14 | Negative-evidence draft ANNOTATED, not edited (MR-7) — four clauses superseded by the two rulings of the same day: the IF binds claims not instruments only, retroactivity is forward-only with an amendment trigger, the two are coupled and neither may be cited without the other, and the Needs: is discharged but for human_ratify, the instrument enumeration having been produced (16 across 11 steps). The original draft text is retained byte-unchanged — an annotation that edited would be the defect it repairs. Authority: FR-016's direction test, bringing text into line with a ruling that already governs it being a narrowing, not authoring. The number stays unassigned and the rule still binds nothing. Stated as F-101; sources: decisions/2026-08-14-negative-evidence-binds-claims-retroactivity-forward-only.md, decisions/2026-08-14-negative-evidence-scope-ruled-narrow-blocking-gates.md |
agent, under FLIGHT's rulings |
| 2026-08-16 | FR-021 ratified — negative evidence binds CLAIMS, forward-only, with the amendment trigger. Ratified against the annotated text (:300-369), so the four-noun IF of the draft does not bind: a verification round is none of those nouns and is the estate's most productive detector. The coupling is written onto the rule itself rather than left in the two decisions behind it — R-1 alone is the unratifiable rule, forward-only is what makes it payable, and a coupled ruling decaying into its components is how a rule comes to bind something nobody decided. It binds authoring and gets heavier, named and accepted. Cost on the binding date: eight cited greens inadmissible — forward-only, NOT retroactively voided. The 16-instrument enumeration is already stale by two acts and its own discovery method is what shows it: F-110 moved the stamp-idempotence step unfalsified → unfalsifiable, and projection-tests.yml surfaced as a diff of .github/workflows/ — 19 instruments, 8 falsified · 9 unfalsified · 2 unfalsifiable. Identifier assigned by the register after sweeping the namespace (F-106's class). Coupled to nothing, no third condition; builds no check, closes no finding, touches FR-020 not at all. DEC 2026-08-16-fr-021-negative-evidence-ratified.md |
FLIGHT |
| 2026-08-14 | Negative-evidence rule drafted, number unassigned — a check reporting a null, zero or all-clear result is inadmissible as evidence until the same instrument has been shown to go red, falsified against a known-bad input and recorded alongside the result it licenses. The identifier is deliberately not proposed by the drafting agent: rule text is the agent's, the number is the register's, adopted after an agent issued FR-017 into a corpus where FR-017 was already ratified. Mechanism only — scope is FLIGHT's, because a rule's scope sets the drafting agent's own workload. Drafted alone per :247, not batched with FR-020 nor with the register schema ruled the same day. No "not a money seam" argument: five uses, recorded PAID by the F-072 ruling R-5, and a sixth borrowing is exactly why this is drafted rather than ratified. Source: decisions/2026-08-14-negative-evidence-rule-drafted.md |
agent draft, FLIGHT instruction |
| 2026-08-13 | FR-020's scope ruled, not amended — a write is any side effect. F-086 stated that the rule's antecedent could not be evaluated and that the six artefacts its own text names span the whole ambiguity — all six in on the widest reading, none on the narrowest. FLIGHT ruled the widest, wider than the phrase the finding offered as most likely: any effect outliving the invocation or leaving the artefact, so notifying a human is a write. The narrow reading is refused because M4.4's side effect reaches a phone, and a definition excluding it defines the wrong thing. Second clause bound to the trigger rather than the invocation, because three of the six are request-triggered and cannot tell who called them — an artefact that can be triggered without a human is in scope permanently, failing safe. No rule text is superseded and no guard is changed. Consequence recorded rather than found later: FR-020 is now estate-wide, the six are a floor rather than a census, and the rule is further from ratification — the interlock guard fails on all six, so ratifying today would bind six artefacts to a guard none has. FR-020 stays a draft and binds EIR alone. F-089 becomes a precondition of its ratification. DEC 2026-08-13-f-086-ruled-a-write-is-any-side-effect.md R-1 (FLIGHT), R-2..R-6 (agent under delegation, countersigned by FLIGHT 2026-08-13 on an explicit range with no per-clause review stated, and summarised for signature by the agent that authored them — R-7) |
FLIGHT · agent |
| 2026-08-12 | FR-020 drafted — a machine-triggered write carries four guards: a stop condition that alarms, an interlock that states its failure direction, a fresh read at act time, and intent recorded before the act. Promotes four of six clauses of the M5.2 stage 2 authorisation; R-1 (the act's scope) and R-2 (a siting rule already carried) are deliberately not promoted, because promoting them as a block would make a rule out of one act's shape. Drafted rather than ratified directly, refusing a sixth reuse of the not a money seam argument the FR-017 decision recorded as owed examination — and an autonomous write that spends nothing is precisely where it would have been reused. Drafted alone, not batched with the telemetry-boundary rule the F-077 ruling leaves owed (FLIGHT-RULES.md:300); FR-020 is sequenced first because it governs a write running now. A narrowing, not a widening: all four guards are already implemented and already falsified on the deck, so no new authority is created. Not retroactive. Trigger: M6.5's criterion 1 asked the F-072 ruling to promote the guards or say why not, and it did neither. DEC 2026-08-12-eir-guards-promoted-fr-020-drafted.md R-1, R-2, R-3 |
FLIGHT |
| 2026-08-10 | FR-015 interpreted, not amended — the merge is the GO. A merge to main is the recorded GO FR-015 requires for mary.wiki; the deploy it triggers is authorised by the merge, and no separate GO is owed. No rule text is changed. FR-015 keeps full force for every deploy that is not a merge — an agent running vercel --prod, an alias change, a domain attachment, a rollback — each still needing a GO authored before the act, which is F-030's own shape. This restores publication law rather than departing from it: PUB-SPEC.md:116 and APEX-LANDING.md:143 both specify publish on merge to the corpus default branch, and DEC-APEX-0020 R-5 had resolved that against them silently. Consequence recorded: the pre-publish gate is now the only thing between a defective corpus and production, and branch protection is unavailable, so a red gate does not mechanically prevent a merge. DEC 2026-08-10-f-066-ruled-merge-is-the-go.md R-1, R-2, R-4 |
FLIGHT |
| 2026-08-10 | FR-019 ratified, widened from its draft — a claim about an estate capability or about the corpus's own state, when cited as a premise or served to a reader, carries the date it was read. Widened because the draft bound capability claims only and would not have caught the page copy that nearly reached the public. Bounded to load-bearing and outward-facing claims, because dating all prose is a rule nobody can comply with. Trigger: seven instances in eight days. DEC 2026-08-10-fr-019-ratified.md R-1 |
FLIGHT |
| 2026-08-10 | FR-018 ratified — a gate drives the deployed artefact and does not re-implement what it judges; where it cannot, it records that it tests a copy and the milestone is read as narrower. Drafted first rather than ratified directly, refusing a fourth reuse of the unexamined not a money seam argument. Not retroactive: the wake path's emitters are driven by no committed gate, and that reconciliation is owed. Trigger: four silent deploy defects in Phase 4. DEC 2026-08-10-fr-018-ratified.md R-1 |
FLIGHT |
| 2026-08-10 | FR-019 drafted — a capability claim carries the date it was read. Drafted separately from FR-018 rather than batched with it (FLIGHT-RULES.md:178), and drafted rather than ratified for the same reason FR-018 was. Trigger: five instances of a summary outliving its read, the sharpest reaching two ratified decisions in one day. Source: docs/decisions/2026-08-10-fr-019-drafted.md |
FLIGHT |
| 2026-08-10 | FR-018 drafted — a gate drives the deployed artefact and does not re-implement what it judges. Drafted rather than ratified directly: three rules were ratified without drafting on 2026-08-09, all three arguing not a money seam under FR-003, and that argument is recorded as owed its own examination rather than reused a fourth time. Trigger: four silent deploy defects in Phase 4, each caught by a gate and by nothing else. Source: docs/decisions/2026-08-10-fr-018-drafted.md |
FLIGHT |
| 2026-08-09 | Charter format amended to carry tool authority — AGENT-REGISTER-v2.md's nine charters gain tools[].default_config.permission_policy.type; FR-017's default ask written into the seven ratified; no always_allow granted. No rule text is changed — FR-017 is applied, not amended. FR-016 is interpreted: narrowing a configuration toward its ratified charter is not a modify; widening requires the charter first. DEC 2026-08-09-fr-017-charter-format-amendment.md R-1, R-3 |
FLIGHT |
| 2026-08-09 | FR-017 ratified — least-privilege tool authority: permission policy is ask by default; always_allow is per tool, never per agent, and only with a named justification in the ratified charter; bash, write and edit are never always_allow absent that record. Trigger: F-046. DEC 2026-08-09-f-046-ruled-least-privilege-tool-authority.md R-1 |
FLIGHT |
| 2026-08-09 | FR-016 ratified — agent creation binds by function, not by surface: no agent performing a MARY console or worker function is created, modified or activated on any surface without a ratified charter. Trigger: F-045. DEC 2026-08-09-f-045-ruled-console-is-a-different-surface.md R-2 |
FLIGHT |
| 2026-08-06 | FR-015 ratified — no deploy, alias or domain attachment touches a production custom domain without a recorded GO. Ratified directly rather than drafted: FR-003's per-rule human_ratify covers class-A money seams and this is not one. Trigger: F-030 third limb. DEC-APEX-0020 R-4 |
FLIGHT |
| 2026-07-31 | v1 seeded: FR-001..005 ratified, FR-006..008 drafted | FLIGHT |
| 2026-07-31 | v1.1: FR-009..011 imported from content-ledger doctrine (DEC-APEX-0012) | FLIGHT |
| 2026-07-31 | v1.2: FR-012 drafted (accession gate, DEC-APEX-0014) | FLIGHT |
| 2026-08-04 | v1.3: FR-013/FR-014 drafted (DEC-APEX-0016). Ratified as drafts only — FR-003 forbids batching a class-A money rule. Source: docs/decisions/2026-08-04-dec-apex-0015-0016-ratification.md (R-2) |
FLIGHT |