# Jurist ruling — PENDING-88, the skill-harvest FIX lane and its hard floor *Filed verbatim by the executor, 2026-08-01, steward-relayed. Design gate PASSED with required conditions. This file is the record of what was ruled; it is not edited or summarised. The executor's response and the verification the ruling requires are in the package Addendum, not here.* --- Before the substance: this is a different category of request from the last two, and I'm treating it that way. The first two were about how a text corpus gets verified. This one is about how much an executor may change, unsupervised, in the files that govern its own future sessions. Same taxonomy, higher bar — the kind of proposal PENDING-1 itself required dual review for, not because the mechanism is exotic, but because of what it's about. **Verification, and where it stops.** I read `~/CLAUDE.md` in full, directly — not corroborated, read. Every Part I quote sourced from it is exact, byte for byte: the four-tier taxonomy, the escalate-unconditionally list, the full governance-contract clause, Constraints 1/5/6, and the PENDING-1 closing note. Confirmed independently: skills are not named anywhere in this file — not on the escalate list, not in the constraints, not anywhere in its 250 lines. That part of Part III's argument is solid. What I could **not** check is the part the whole diagnosis actually turns on: the two `/wrap-up` §1.6 passages and the `/wake-up` §2.a line. Skill files aren't in my reach — `governance_read` covers claude-md, pending, pending-archive, reviewed, app-brief, memory-index, and no more, which is exactly PENDING-86's still-open complaint, now shown to bite a second class of document beyond the chamber constitution. I'll say plainly: I'm ruling on the *inference from* those quotes, not on the quotes themselves. I also notice this package doesn't carry the "mechanically verified by containment, positive control" line the order-attestation package used one day earlier for the same job. Given I can't check it myself, I want it back. **Is the diagnosis real, independent of that gap?** Yes. PENDING-88's own amendment already caught and corrected its first draft's arithmetic (151→123, 26→8) against a stated counting rule, and reported that the falsifier it named for itself — small or recent backlog — did not fire. 177 open items, oldest 2026-05-24, a file at 166,589 bytes against a read cap that `/wake-up`'s own surfacing step needs to clear. That's a dated, checkable, self-corrected measurement, not an assertion. **The question underneath Q1–Q5: does a blanket pre-authorization gate that has stopped being readable still honour "the loop is load-bearing," or has form quietly replaced function?** I think the honest answer is that a gate nobody can see through isn't preserving the loop — it's preserving the appearance of one while the steward's actual awareness has already been lost, silently, for weeks. That cuts toward reform being the more faithful reading of Constraint 5, not a relaxation of it. But it cuts toward a *narrow* reform, and I want more than what's on the table before I'd call this settled. **Q1 — gap, not deliberate.** Agreed, on the timeline evidence given (repo-CLAUDE.md clause added later, not carried back), with the caveat that I can't confirm the dates myself. The alternative reading (skills govern what sessions *do*, not just what they *read*) is coherent enough that it shouldn't be dismissed — but it's already answered by the hard floor's own exclusions, not by keeping the blanket rule. **Q2 — keep the two-clause test, and I'd resist the narrower form even as an option.** The executor's own suggested alternative — collapse to "does it change what the system asserts to be true?" alone — is *less* safe, not more elegant: a change could expand executor latitude without asserting anything new, and a single-clause assertion-only test would wave it through. Keep both clauses, disjunctive, exactly as drafted. **Q3 — the report is not enough alone, and the package already knows this.** Its own words: the failure it must catch is one the executor would be the last to notice. Given that, both halves of the mechanism — wrap report *and* skill-source provenance comment — are mandatory, not a report with a mechanical fallback held in reserve. I'm also adding a third: a running, append-only FIX-lane index, one line per applied change, separate from individual wrap narratives. The register-split executed today is the working model for exactly this — cheap, and it directly guards against the one failure mode this whole proposal exists to fix happening again, one level up, to the changes instead of the proposals. **Q4 — sharpen the floor's catch-all, and tie it to the mechanism that actually broke.** "Anything that would reduce what is surfaced to the steward" is doing real work and is also, as flagged, the clause a self-interested party has the most room to read favourably. Give it an operational form: *any change that removes, defers, or narrows the visibility of an open item, or that could cause a future item to be filed somewhere the steward's surfacing tools don't read, stays PROPOSAL regardless of the test's answer.* That's checkable against the same failure this package measured, rather than a standing judgment call. **Q5 — yes, and for a reason narrower than the PENDING-S2 stretch the package itself declined to lean on.** Not because this is a self-authorization-posture change in general — because it's a change to the integrity of the *surfacing mechanism itself*, the instrument the steward and I both depend on to know what's happening. Defects there get dual review on the same logic PENDING-1 set, not because of the analogy to a doctrinal ruling about deposits. One more condition, not asked for but warranted by what's actually being granted: a bounded check-in. After the first month or the first batch of FIX-lane applications, whichever comes first, steward and jurist review the actual FIX-lane log together — not to re-litigate the principle, but to confirm the self-classification held up in practice before treating the lane as settled rather than provisional. This is what "prefer reversible choices" (your own Decision Heuristics, §4) asks for on a genuinely novel grant, and it costs nothing if the classification turns out to be as clean as today's four examples suggest. Design-gate passed, conditioned on the above. Ready to paste: ``` ## REVIEWED-85 — PENDING-88 — Skill-harvest FIX lane: hard floor sharpened, dual instrument required, provisional pending check-in (design-gate passed with required conditions) **Date:** 2026-08-01 **Decision:** AUTHORIZED — proceed per the ruling, provisionally. Register split (option (d)) unaffected — separately authorized 2026-07-19, correctly executed by the split method rather than the inapplicable collapse method; no action needed here. **Notes:** - **Verification limit, stated up front.** All Part I quotes sourced from `~/CLAUDE.md` (taxonomy, escalate list, governance-contract clause, Constraints 1/5/6, PENDING-1 closing note) independently confirmed exact against the live file. The two `/wrap-up` §1.6 passages and the `/wake-up` §2.a line — the textual basis for Part III's "contradicts itself" claim — could NOT be independently checked; skill files are outside current tool reach. Required before landing: the same mechanical containment-with-positive-control verification the 2026-07-29 package carried, applied to these quotes specifically. - **Q1 — gap, not deliberate distinction — AFFIRMED** on the timeline evidence given, unverified directly. The alternative reading is answered by the hard floor's exclusions, not by retaining the blanket rule. - **Q2 — two-clause disjunctive test — AFFIRMED, and the narrower single-clause alternative is declined.** A latitude-expanding-but-non-assertive change would pass an assertion-only test; keep both clauses. - **Q3 — report + provenance comment BOTH mandatory, and a third instrument added.** A wrap-narrative report alone is insufficient by the package's own admission. Required: (i) wrap report, (ii) skill-source provenance comment, (iii) a running append-only FIX-lane index (one line per applied change: skill · what changed · date), built on the same live-index pattern used for today's register split. - **Q4 — the floor's catch-all clause sharpened.** "Anything that would reduce what is surfaced to the steward" becomes: *any change that removes, defers, or narrows the visibility of an open item, or that could cause a future item to land somewhere the steward's surfacing tools don't read, stays PROPOSAL regardless of the test's outcome.* Tied to the actual failure measured in Part II, not left as an unbounded judgment call. - **Q5 — jurist review applies, narrowly grounded.** Not the stretched PENDING-S2 analogy (correctly declined by the executor itself) — grounded in this touching the integrity of the surfacing mechanism the steward and jurist both depend on, which is the PENDING-1 class of question by its function, not by resemblance. - **New condition — bounded check-in, not asked for in the package.** After the first FIX-lane batch or one month, whichever comes first, steward and jurist review the FIX-lane index together before the lane is treated as settled rather than provisional. Per Constitutional Constraint's own decision heuristic (prefer reversible choices) — costs nothing if the classification holds. - **Hard floor otherwise as proposed — AFFIRMED:** Constraint 1 (CLAUDE.md/REVIEWED.md/L2), authorization-boundary or gate-criteria changes, the escalate-unconditionally list, all untouched and all remain PROPOSAL/ESCALATE regardless of the test's answer. **If AUTHORIZED:** Land the §1.6 edit (classification test + sharpened floor + dual-plus-index instrument) with a provenance comment in `/wrap-up` SKILL.md; no change to `~/CLAUDE.md`. Apply to today's four proposals (ledger section, KG predicate, wake line, reframed question) as the first FIX-lane batch, feeding the check-in review. Tag commits REVIEWED-85. **Awaiting:** steward placement; mechanical verification of the §1.6/§2.a quotes; the bounded check-in once the first batch or one month has passed. ``` --- ## Note on scope of this file A follow-on exchange between steward and jurist accompanied this ruling, covering the contamination problem, Anthropic's published position on recursive self-improvement, and the "differently biased checkers rather than unbiased ones" framing. The jurist's own direction on it: *"relay REVIEWED-85 unchanged. Share the exchange if you want to, but as background the executor reads, not as text that carries any new obligation on its own."* It is therefore **deliberately not filed here** and carries no governed weight. Should any of it become doctrine, that is *"its own item: what exactly gets added, where it lives, and why now, ruled on rather than absorbed by inclusion."*