Ruling filed verbatim. Drafting authorized by the steward's placement of
REVIEWED-86; application is not, and ~/CLAUDE.md is untouched.
The amendment adds a second paragraph to Constraint 6 and replaces nothing --
both original clauses survive verbatim, the caution is refined rather than
relaxed, and the L2 deferral stands.
Both jurist conditions welded into the text that would actually land, not left
in surrounding commentary, since a future reader cites the doctrine block and
not the discussion of it. Q2: biases that fail to coincide do not cancel, and
the doctrine may never be cited as assurance something WAS caught. Q3: the
jurist and executor do not differ in formation, their separation is the weaker
kind, and neither the doctrine nor its evidence establishes that pair as a check
in the strong sense -- the doctrine naming the configuration that produced it as
the one it does not vouch for.
Steward ruled the open question on `Status: provisional` sitting inside a section
headed "cannot be overridden": retain it. Constraint 6 already carries a temporal
qualifier, so the section is not free of them.
Paste block prepared separately, indented to continue the numbered list. The edit
is the steward's: Constraint 1 names this file and sits under "cannot be
overridden by any session instruction", and the ruling states the steward's own
act is what nothing substitutes for.
PENDING-89 dockets the Q3 correlation review the jurist declined to leave
hypothetical, with the hazard named -- this is the executor measuring whether the
executor is checked, so criteria must be pre-registered and it may be steward-only
work.
Q4 folded into the existing REVIEWED-85 check-in agenda rather than given its own
cadence, per the ruling's reasoning that a new standing review produces another
unread register.
PENDING-86 amended with its third instance: the jurist could not reach
contamination-problem.md while gating an argument that turns on it.
Convergence question closed. The jurist inferred a common source; the steward
confirmed it -- the exchange was shared as context only, and Document A predates
it, so the jurist's language cannot have shaped the proposal. Neither
contamination nor corroboration.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
Measured against the register before acting, and the item survives in direction but not
in numbers or remedy.
Option (d) has been authorized since 2026-07-19 — Stroke 4 of the register's own
authoritative head block — and simply never executed; Stroke 2, the ~25-30 entry
verification-ladder batch-append, is authorized and unexecuted in the same slot.
But Stroke 4's method ("ruled items collapse to verdict lines") cannot achieve the goal:
of 190 table rows, 13 are ruled and 177 are open. Collapsing every ruled row removes ~7%
of the file. The register is not large with settled history; it is large with open
proposals, so the prescribed remedy leaves it over the cap and the loop still broken.
The item's counts are unreliable and so were mine until I stated an inclusion rule; with
one stated, 123 PROPOSED / 8 BUILT / 4 AUTHORIZED over table rows. The item's own
falsifier is not triggered — 166,589 bytes, 177 open, oldest 2026-05-24 — so the
diagnosis stands and only the arithmetic needs restating.
Newly found: one section spans 411 lines and 58% of the file while carrying 33 distinct
dates from 2026-05-24 to 2026-07-19. Five weeks of wrap-appends landed in an existing
section rather than new dated ones, so the register misreports its own chronology and
§1.6's append step is silently mis-filing.
Proposed method, on the MEMORY.md precedent that already worked (213KB -> 17KB): a live
index of open proposals plus a detail archive, ~19 KB, lossless in the working tree,
compacting by form rather than by dropping items. Proposed and not applied: Stroke 4
authorized compaction, not this method, and restructuring the surface that decides what
reaches the steward is PROPOSAL-class by the item's own test.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
Harrison re-gate pilot broke the mechanism before converting a byte, and the
break was constitutional: tier_of() faithfully implements the ratified
evidence-tier table, which enumerates tiers by FORMAT, so 16 born-digital-PDF
canonicals with real ground truth receive a false ABSTAIN. Jurist design-gate
PASSED with two corrections (independence into the constitutional text, NOT by
analogy with V-TEXT which ruled the other way; the demonstration is of two
instruments and the second has no control). REVIEWED-83 placed by the steward.
Also: steward-facing maps given a durable home after one was lost and four more
found unbacked; memory pointers made home-anchored and self-diagnosing.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
A checkable number stated from memory rather than counted. Corrected in the item
and the ledger, and the correction is left visible in the item text — a governance
record that quietly repairs its own numbers teaches the reader to trust numbers
that were never checked.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
The three-party model asks Claude.app to rule on items it cannot read. Steward
confirmed 2026-07-28 that local MCP servers are exposed to the app's *chat*
surface — and always have been, predating Cowork by about a year. My earlier
framing ("chat, not only Cowork") had the relationship backwards: it is "chat,
always; Cowork, only while its loop still runs locally," and local Cowork is the
mode being phased out as default. The jurist chat is therefore the sturdy target.
Five read-only tools. The one a pasted cache can never provide is
governance_item(id): the verbatim body of any item or ruling, across PENDING.md,
PENDING-archive.md and REVIEWED.md. Four refusals are designed in, each with a
control proving the refusal is detectable — no writes (AST-audited), no path
arguments (keys from a fixed enum, so there is no traversal to defend), no second
parser (item_spans is imported, not reimplemented), and not an agent (tools
return data; an agent would return testimony about the substrate instead).
[FIX] to the shared definition while here: item_spans() is now fence-aware. A
'## ' header inside a fenced block is neither an item nor a boundary. Zero such
headers exist today — 17 open items before and after — but governance drafts are
written as fenced markdown carrying '## REVIEWED-N' headers, which is the
steward's own practice, so the next draft would have created a phantom item and
truncated the item containing it. PENDING-82's own fenced JSON block confirms the
fix within the hour.
Not installed. The mcpServers key edits the steward's desktop-app config; the
snippet is in PENDING-82 and the server is inert until someone loads it.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
8abfe88's message read "PENDING.md split 1848→430 + archive", but the archive was
never staged: that commit deleted 1,532 lines from PENDING.md and pushed the
deletion without its destination. The 74 closed governance items survived on disk
and in history only — recoverable, but absent from the record the remote carries.
The commit claimed an integrity it had not enacted.
Verified before committing, not after: every line of
PENDING.md.bak-2026-07-28-pre-split is accounted for in
(PENDING.md UNION PENDING-archive.md) at line granularity — no regex, no parser
notion of "item" — with a same-run positive control (a sentinel absent from the
union must be reported missing) per the Q2 epistemic standard. Three baseline
lines are absent by intent, all in the file header: the stale `Repo: bmf` and
`Branch: fix/replay-durability-contracts` pointers (that branch merged as
c9746ae; HEAD is main — the staleness was flagged in PENDING-78), and the
`Protocol:` line, reflowed. That header rewrite rode along inside 8abfe88
unmentioned; it is logged here rather than left silent.
Second fix, same class: the header asserted "the next item is PENDING-80" while
79, 80, and 81 all exist. Replaced the stated number with the rule that computes
it — a number goes stale, a rule does not.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
PENDING-76 remanded by jurist — required count returned 0 of 11 (the package's own
IV.2 refinement proved its target category empty); executor recommends withdrawal.
PENDING-77 (5 structural defects) and PENDING-78 (.app preferences) released by the
ruling from needing it. Drift check reports contradicted state claims at every wake
and corrects nothing — detection needs no authorization, correction does.
MEMORY.md compacted 20.5KB -> 17.1KB (budget hook); prior Active Session demoted to
MEMORY-reference.md. CLAUDE.md and REVIEWED.md untouched.
Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Xefg5EXwcpd9RMAr63dWrD
REVIEWED-75 (kind-scoping the verification criterion) placed by the steward.
PENDING-75 -> spec v2.7.0 landed with both required corrections (V-SCAN's
distinct criterion preserved; the anti-bypass guard rebound to the property).
PENDING-72 -> spec v2.8.0 landed (voice-purity as the engine-consumable bar),
mechanism built test-first, backfill executed 18/1, gate wired, single-reading-
pass designed. Plus the source_lines FIX: producer + 11 consumers in one
change-set, then corrected again when the base-rate sweep found splitlines()
also wrong (308 lines' disagreement on one canonical).
Ledger records the session's sharpest return: the sweep caught a fix one commit
old, because ratifying a convention by comparing two implementations is
SELECTION, not derivation — I verified the two disagreed, never that either was
right.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Xefg5EXwcpd9RMAr63dWrD
- PENDING-56 (canonical format + sidecar) + PENDING-57 (verbatim gate) filed and carried
through the jurist rulings; REVIEWED-55/56/57 filed.
- REVIEWED-drafts-for-filing: the paste-ready records.
- Symmetria session-ledger: the full A1 -> schema-lock -> B2 -> verbatim-gate arc.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015jYS1tpR4P4NBxui4FSgfv
PENDING-50 ruled+landed; new session memory + index fold (demote-on-promote) + Symmetria ledger returns/open-horizons for the A2 close and the parked verification-architecture question.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Dsqe1x23NgWaRdiFWSotur