The actual documents the agents read and work from, shown exactly as they are on disk — not a summary. See the progress view instead · All projects
# PLAN.md — THE GOAL PURGE: retire and archive everything that is not Skippy, the voice app, or the business Hub
**NORTH STAR:** A future agent — or Nick — opening this workspace finds only three live bodies of work: Skippy (with the voice app), and the business Hub. Everything else is archived intact, findable, marked as retired or parked, with no live pointer left anywhere that could pull an agent back into it. Nick's words, 2026-09-04: *"The only thing I want to do is finish the hub and finish Skippy in the voice app. That's all I care about... retire literally everything else... archive anything that's not related to our core goals. So there's no way to go and get lost in this stuff. And then while we're at it, just clean up the ecosystem."*
**FINISH LINE** (written now; the bar never rises mid-drive — when these pass, this plan is DONE and everyone stops):
1. Every row of the §1c inventory (30 items) carries an executed disposition — KEEP · FOLD · PARK · RETIRE-ARCHIVE · DEFER — with its step's proof pasted in `## STEPS`.
2. Every RETIRE-ARCHIVE'd document sits under `projects/_archive/goal-purge-2026-09-04/` with structure preserved, a retirement banner, and zero deletions.
3. No scheduled job fires for a retired capability (disabled-frontmatter proven, plus one kept job proven still firing as the control), and no live family- or Hub-facing job was touched.
4. A two-way search (content grep + suffix-aware filename sweep, both named) finds zero live-surface pointers presenting retired work as live, and a cold checker session that built none of this agrees.
5. `python3 projects/ops/agents/check_plan.py` run against this very file prints PASS, and the postmortem step is written into this file.
**NOTHING IS DELETED BY THIS PLAN.** Irreversible destruction is one of Nick's four approval classes. Every disposition here is a move, a status edit, or a reversible frontmatter switch. No genuine deletion was found necessary; if one ever appears mid-drive it goes to Nick as its own question, never into a step.
**THE PURGE/ARCHIVE TENSION, RESOLVED (read before executing anything):** Nick said "purge" and "archive" in the same breath. Measured tonight: the word "gracie" alone appears 42,968 times across 6,280 files (method: repo-wide case-insensitive content grep, 2026-09-04). Purging every *mention* is therefore impossible and wrong — most mentions are history, logs, and ledgers, which are records, not invitations. What actually gets a future agent lost is a LIVE POINTER: a plan lane that reads open, a board card, a scheduled job, an index row, a canon-table entry. So: **the work is archived intact; the live pointers are purged.** Historical mentions in logs, changelogs, ledgers, memory files and archives stay untouched.
## Already true (the distilled past — facts, not story)
- The workspace already has one archive convention: dated folders under `projects/_archive/` with source-relative structure preserved (the SP programme went there on 2026-08-30) — evidence: `ls projects/_archive/` shows `sp-programme-retired-2026-08-30` and the SMP manifest's `smp-programme-retired-2026-08-30` naming.
- ZION-8 (approvals) is complete and Nick repointed it as the security click-gate — evidence: Nick, 2026-09-04, "zion 8 is done 100% so make it the security gate now" (`projects/ops/REGROUP-SOURCE-2026-09-04.md` §A12).
- The SMP programme (ten lanes) IS the Skippy + voice + Hub + channels build and stays live — evidence: `projects/ops/skippy-master-plan/PLAN-SMP-PROGRAMME.md` §1b root table.
- ZION-17's work belongs to the Hub — evidence: Nick, 2026-09-04, "pm noard enforcement gets wrapped in tot he hub work" (§A12).
- Neeko and the shopping gate have real scheduled-job files on disk today — evidence: `ls projects/ops/skippy-jobs/jobs/` shows `neeko-daily-review-run.mjs`, `neeko-project-doc-sweep-run.mjs`; `projects/ops/skippy-jobs/lib/shopping-agent-add.mjs` exists.
- The wider-Alexa ambition lives at `projects/personal/skippy-app/ALEXA-ACCESS-SPEC.md`; the Alexa CHANNEL adapter is SMP-10 and is kept — evidence: suffix-aware glob for `ALEXA-ACCESS-SPEC*` (one live copy plus worktree copies) and the SMP root table.
- The live failure registry holds 167 entries — evidence: `command grep -c '^|' .claude/skills/plan/references/failure-registry.md` returns 199, minus 16 separators and 16 headers, counted 2026-09-04.
## 0 · Gate Zero receipts (the plan may not exist without these)
- Failure Mode Registry loaded: 2026-09-04, 167 entries (199 pipe rows − 16 separators − 16 headers in `.claude/skills/plan/references/failure-registry.md`); all 167 covered in §4, plus two novel rows.
- Canonical specs loaded: the plan doctrine `.claude/skills/plan/SKILL.md` (including the new §W many-sessions-one-checkout and §Z empty-result rules, re-read 2026-09-04) and its template; `projects/ops/MACHINE-RULES.md`; `projects/ops/PROMPT-SPEC.md` (7-row table); `projects/ops/REGROUP-SOURCE-2026-09-04.md` §A12/§A13 and its KEPT list.
- Ownership check: no retirement/goal-purge project exists — fresh search, two ways: glob for `projects/ops/*retire*` and repo grep for "goal-purge" found no project folder. Nearest neighbours: each programme's own archive manifest (SMP §archive-contract; ZION's own archive steps), each scoped to its own programme only. The 2026-08-30 ruling gave "the ecosystem purge" to ZION-9/Larry; Nick's later 2026-09-04 words retire that lane and order this plan — the conflict is on the confirmation sheet (§1a row 6), resolved by the later word.
- Expected inputs confirmed to exist: `projects/ops/zion/PLAN-ZION-PROGRAMME.md` · `projects/ops/skippy-master-plan/PLAN-SMP-PROGRAMME.md` · the 17 ZION lane plan files and 12 SMP plan files (globbed 2026-09-04) · `projects/ops/skippy-jobs/jobs/` (327 files listed) · `projects/personal/skippy-app/ALEXA-ACCESS-SPEC.md` · `projects/ops/THE-ASSISTANTS.md` · `projects/ops/continuity/PLAN.md` · `projects/ops/agents/check_plan.py`.
- Artifacts this plan's own steps create, declared so their citations below are readable before they exist:
- `projects/_archive/goal-purge-2026-09-04/RETIREMENT-NOTE.md` (CREATED BY STEP 1)
- `projects/ops/retirement/STATE.md` and `projects/ops/retirement/PLAN-CHANGES.md` (CREATED BY STEP 1)
- `projects/ops/retirement/evidence/refcounts-before.txt` and `projects/ops/retirement/evidence/citation-sweep.sh` (CREATED BY STEP 2)
- `projects/ops/retirement/evidence/refcounts-after.txt` (CREATED BY STEP 11)
- PLAN AUTHOR: Boris 3 of 3 (senior-engineer, Fable), dispatched 2026-09-04 on Nick's "boris x 3 on fable 5.1 do the planning".
- COLD READER: none — SINGLE-AUTHOR, UNREVIEWED at write time. STEP 12 is a real cold read of the executed result by a session that built none of it, and its verdict lands in `## STEPS`.
- PROMPT-SPEC scan (P1–P7): P1 fired on "purge" vs "archive" (two readings, two different acts) — resolved above and on the sheet, not guessed. P4 fired on "everything else" — bounded by the KEPT list in §1a row 5. P3 fired on "there are no scehdueld jobs right now because everything is fucked" — treated as Nick's impression, not a measurement; STEP 6 measures the fleet with a control rather than building on the claim. P7 fired on his multi-part 42708 message — split item by item into the §1c dispositions, each citing his exact clause.
## 1 · Goal and definition of done
**What we're doing, one paragraph.** Take the measured inventory of every live lane, project, scheduled job, skill and pointer in this workspace; mark each KEEP, FOLD, PARK, RETIRE-ARCHIVE or DEFER against Nick's 2026-09-04 scope; move retired work intact into one dated archive folder; hand folded work to its named new owner with a dated line; disable (never delete) the scheduled jobs of retired capabilities; and sweep the live surfaces — programme indexes, canon table, board cards, heartbeat rows — so nothing retired still reads as live. Gracie, Neeko and the family app are parked in a resumable state, because "later" is not "never".
- **HOW IT'S USED:** an agent starting any future session reads ACTIVE-WORK, a programme index, or the board, and sees only Skippy/voice/Hub work as live; anyone needing retired material follows the archive note to `projects/_archive/goal-purge-2026-09-04/` and finds it intact. · HOW WE KNOW: STEP 12's cold walk performs exactly this read and returns a verdict.
- **WHAT IT LOOKS LIKE:** one archive folder with a plain-English retirement note at its top; dated status deltas in the two programme indexes; disabled-frontmatter in named job files; this plan's `## STEPS` carrying the proofs. · HOW WE KNOW: each is a named artifact with a runnable proof in §3b.
- **WHERE IT LIVES:** the plan at `projects/ops/retirement/`, opened by the executing sessions; the archive under `projects/_archive/goal-purge-2026-09-04/`; Nick opens only the plain-English report STEP 13 hands him. · HOW WE KNOW: Nick, 2026-09-04, reads handbacks, not plans — same confirmed pattern as the ZION replan's SURFACE row.
- **WHAT IT MUST DO:** (1) every §1c inventory row reaches an executed, proven disposition; (2) nothing is deleted; (3) no live Skippy/Hub/family-facing surface or job breaks; (4) retired capabilities' jobs provably stop firing while a kept job provably still fires; (5) every moved document's live-tree citations are updated in the same pass; (6) a cold checker confirms no retired work reads as live. · HOW WE KNOW: §6 evals, one per capability.
- **NOT in scope:** the ANTI-SCOPE.
- **Security work of any kind** — no vulnerability audit, no credential chase, no hardening, no "while I'm here" security fix. Security is click-gated behind ZION-8 and happens as its own end-phase pass (ZION-14, which this plan DEFERS in place, untouched). Anything security-shaped found mid-step costs one line on the NEXT list.
- **Deleting anything, anywhere** — approval class three; archive-over-delete is the default and the whole method here.
- **Doing, finishing or "quickly fixing" any retired lane's actual work** — a retirement pass that starts repairing the thing it is retiring has lost the plot; one line to the NEXT list.
- **Touching the live OpenBrain store, its MCP engines, the routing tools (`projects/ops/route-build.mjs`, `projects/ops/cheap-task.mjs`), the routing-enforcement hooks, or the file-protection gates** — retired LANES are not retired INFRASTRUCTURE; all of these are running dependencies of the kept goals (measured in §1c) and no step edits them.
- **Undeploying any live site** (Skippy School included) — stopping work is not taking a serving surface away from its users; see §1a row 4.
- **The SMP programme's own build work** — Boris 1 and Boris 2's plans govern finishing Skippy/voice and the Hub QA; this plan only posts dated deltas and handoff lines into the indexes.
- **Trip-over protocol:** a step that finds something outside its fence writes ONE dated handover line to the named owner (the programme index or lane plan that owns it), then returns to its step. Never investigates, never fixes.
## 1a · Critical variables — the confirmation sheet is GENERATED from this table
| # | The variable, in plain words | Value chosen | Alternatives rejected | Class | HOW WE KNOW | Cost if wrong | CONFIRMED |
|---|---|---|---|---|---|---|---|
| 1 | **SURFACE — which screen this lands on, and who opens it** | Live surfaces agents actually read: ACTIVE-WORK, the two programme indexes, the board, the jobs folder; Nick opens only the plain-English report | A new dashboard; a claude.ai artifact | V1 | Nick reads handbacks, never plan files; he ordered "no way to go and get lost in this stuff", which is about what agents open | The purge cleans surfaces nobody reads and leaves the ones they do | Nick, 2026-09-04, "so there's no way to go and get lost in this stuff" (REGROUP-SOURCE §A12) |
| 2 | What "purge" means next to "archive" | Archive the work intact; purge only LIVE POINTERS (open lanes, cards, jobs, index rows); historical mentions in logs/ledgers stay | Literal deletion of every mention (42,968 gracie mentions measured — impossible and destroys records); archiving nothing and only closing lanes | V1 | His same sentence contains both verbs and ends "archive anything that's not related"; deletion is his own approval class three | Either real records are destroyed, or retired work keeps reading as live | Nick, 2026-09-04, "Retire every mention... purge every document, purge every file, archive anything that's not related to our core goals" (§A12), read with his standing archive-over-delete rule, 2026-08-01 |
| 3 | Gracie and Neeko | DEFERRED, not killed: development docs archived with a RESUMABLE banner; Neeko's jobs disabled reversibly; nothing destroyed | Retire them outright; keep their lanes open | V1 | His words name them as sequenced after Skippy, not dropped | Resuming them later means rebuilding from nothing, or they keep generating live work now | Nick, 2026-09-04, "finish skippy then we do gracie and neeko later" (§A12) |
| 4 | The deployed Skippy School site the kids can open | Lane and lesson work RETIRE-ARCHIVED; the already-deployed site keeps serving untouched, no further work on it | Undeploy the site as part of the purge | V1 | "We're not going to do any of the ancillary items right now" stops WORK; he never ordered a takedown, and taking a working surface from its users is not cleanup | The kids lose a tool nobody asked to remove, or agents keep building lessons | Nick, 2026-09-04, "we're not going to do any of the ancillary items right now" (§A12); standing archive-over-delete default, 2026-08-01 |
| 5 | The exact KEPT list | Skippy conversation core + desktop shell + voice app; business Hub incl. board-PM enforcement folded in; one-cloud-copy (continuity item 25); ZION-12 team access; google-sso awaiting switch-on; Slack/Gmail/WhatsApp/Alexa as CHANNELS with a testing phase; ZION-8 as the security gate; family app PARKED | Wider keep-lists (directories lane, weekly report, router lane) — all named done or ancillary by him | V1 | The dispatch brief enumerates it and his 42708 message confirms each item | Something he wants lives in the archive, or something he dropped stays live | Nick, 2026-09-04, the 42708 message: "zion 8 is done 100%... slack gmail whatsapp etc for skippy are pretty much done... the open brain router approval system cleanup audti shopping etc is done IMO / pm noard enforcement gets wrapped in tot he hub work" (§A12) |
| 6 | Who owns the ecosystem purge — two of his own dated rulings differ | This plan executes it now; the 2026-08-30 ruling that gave the purge to the custodian (ZION-9/Larry) is superseded because he retired that lane in the same breath as ordering this purge | Leaving the purge to ZION-9's first custodian run | V1 | Later direct word beats earlier ruling (plan skill §N); both rulings quoted here for him to see on the sheet | Two owners for one purge, or no purge at all | Earlier: Nick, 2026-08-30, ruling 13 "LARRY — approved" (purge = custodian's first run). Later, governing: Nick, 2026-09-04, "cleanup audti... is done IMO" + the §A12 purge order |
| 7 | Where a retired ZION lane's files go | Git-move into `projects/_archive/goal-purge-2026-09-04/` with structure preserved and a banner, matching the SP-programme precedent; the programme index rows stay, marked RETIRED with a dated delta (no stage deleted) | Leave files in place with only a banner (keeps 9 dead plans in the live folder agents open — the exact get-lost risk) | V1 | The 2026-08-30 SP retirement did exactly this and it worked; governance forbids deleting stages from a plan, and a move is not a deletion | The live folder stays cluttered, or governance is breached | Nick, 2026-09-04, "archive anything that's not related to our core goals" (§A12); precedent `projects/_archive/sp-programme-retired-2026-08-30/` |
**Considered and ruled NOT critical** *(the denominator — never demote a variable silently)*:
- The archive folder's exact name — any dated folder under `projects/_archive/` satisfies the convention.
- Which cheap model executes which step — the model matrix and vendor availability at dispatch time decide; §3 names the tiers.
- The order of the disposition steps beyond their stated entry conditions — steps with satisfied dependencies may run in any order.
- Whether disabled job files are also git-moved — frontmatter is the sanctioned kill-switch (MACHINE-RULES rule 8) and moving them could break the daemon's file walk; they stay in place, disabled.
## 1b · Subproject decomposition — could a piece of this ship on its own?
- **SINGLE SUBPROJECT:** one retirement sweep over one workspace with one archive destination and one verification walk; no piece has its own consumer or could be signed off alone — a half-purged workspace fails the North Star exactly as a never-purged one does.
## 1c · THE INVENTORY — every candidate, measured 2026-09-04, with disposition
*Method, stated per §Z: candidates were found by (a) globbing the lane files (`PLAN-SMP-*`, `PLAN-ZION-*`, `STATE-*` — 12 SMP files, 32 ZION files), (b) case-insensitive content greps for each named drop (skippy school · gracie · neeko · alexa · shopping · openbrain · quality/success report), and (c) listing `projects/ops/skippy-jobs/jobs/` (327 files). An exact-name search undercounts — every RETIRE row is re-verified two ways again at execution time (STEP 2), and an empty result is never read as absence.*
| # | Item | What it is, plainly | Disposition | Where the work goes / new owner | Live pointers to purge |
|---|---|---|---|---|---|
| 1 | ZION-1 autorouter lane | The cheap-model routing build lane | RETIRE-ARCHIVE | archive; the live tools `projects/ops/route-build.mjs` and `projects/ops/cheap-task.mjs` stay — every dispatch depends on them | index row → RETIRED; lane files moved |
| 2 | ZION-2 file-protection gates lane | The gates guarding Nick's core instruction files | FOLD | gates keep running untouched; lane doc archived after a dated handoff line names ops/SMP-8 as standing owner | index row → FOLDED |
| 3 | ZION-3 Hub codebase lane | SUPERSEDED 2026-09-04 by PLAN-ZION-19-hub-finish.md — its own first lines say so; it is no longer the Hub build | KEEP IN PLACE, no move | — | — |
| 3a | ZION-19 Finish the Hub | **The** live Hub plan, and the destination for every Hub-bound handoff | KEEP | — | — |
| 4 | ZION-4 Hub audit lane | Report-only QA of the Hub | KEEP | — | — |
| 5 | ZION-5 agent/skills directory lane | The generated directory pages | RETIRE-ARCHIVE | archive lane docs; generated pages stay serving as-is | index row; lane files |
| 6 | ZION-6 OpenBrain build lane | The memory-store migration lane | RETIRE-ARCHIVE ("open brain... is done IMO") | archive lane docs; 🔴 the RUNNING store and the `personal-engine`/`business-engine` MCP front doors are live dependencies of Skippy and are not touched | index row; lane files; the delivery docs folder |
| 7 | ZION-7 scheduled-task fleet lane | The jobs-fleet repair lane | FOLD | SMP-8 Runtime Reliability owns `projects/ops/skippy-jobs/` by root; dated handoff line into the SMP index; Nick's "there are no scehdueld jobs right now" is his impression — SMP-8 re-measures, this plan does not | index row → FOLDED |
| 8 | ZION-8 approval system | Done; now the security click-gate | KEEP (repointed) | — | — |
| 9 | ZION-9 cleanup audit (Larry/Benito) | The custodian sweep lane | RETIRE-ARCHIVE ("cleanup audti... done IMO") | archive lane docs; the `larry`/`benito` agent definitions stay (invoked-by-name only, fire on nothing) | index row; lane files |
| 10 | ZION-10 family app + shopping | Family app surfaces and the shopping gate | RETIRE lane: shopping DROPPED, family app PARKED | shopping libs/tests stay on disk with the parked app; lane files archived; family app resumes after Skippy ("then we deploy the same setup in the hub and family app") | index row; lane files; shopping skill pointer; any shopping job |
| 11 | ZION-11 weekly quality report | The weekly success-report lane | RETIRE-ARCHIVE (named drop) | archive lane docs + `projects/ops/sp13-quality-tracking/`; job disabled | index row; lane files; `projects/ops/skippy-jobs/jobs/sp13-quality-report.mjs` |
| 12 | ZION-12 team access | Mae/Dean/DinDin/Chantelle pushing their own commits | KEEP | — | — |
| 13 | ZION-13 tool adoption lane | Outside-tool decisions | RETIRE-ARCHIVE | archive lane docs; adopted tools' live configs untouched | index row; lane files |
| 14 | ZION-14 end-phase security audit | The security pass Nick promised | DEFER IN PLACE | file stays exactly where it is, untouched, click-gated behind ZION-8; runs when Nick declares the build phase over | none — its row already reads end-phase |
| 15 | ZION-16 Larry disposition gap | Adjunct of the cleanup audit | RETIRE-ARCHIVE | archive with ZION-9 | index row; lane files |
| 16 | ZION-17 board-PM enforcement | Board discipline for agents | FOLD into the Hub ("gets wrapped in tot he hub work") | dated handoff line into **`projects/ops/zion/STATE-ZION-19.md`**; **lane doc STAYS PUT — see the collision note below** | index row → FOLDED |
| 17 | ZION-18 cheap-routing enforcement | The dispatch-hook enforcement lane | RETIRE-ARCHIVE (router "done IMO") | archive lane docs; the live hooks stay armed untouched | index row; lane files |
| 18 | ZION programme index | The lane index itself | KEEP, rewritten in place | carries every disposition as a dated status delta; no stage deleted | — |
| 19 | SMP-1..8, SMP-10 + programme | Skippy core, family surface, vault, desktop, Hub, channels, WhatsApp, runtime, Alexa channel | KEEP (SMP-2 → PARK delta: family app after Skippy) | Boris 1/2 plans drive them | — |
| 20 | SMP-9 Learning Transcript / Skippy School | The kids' lessons app and site | RETIRE-ARCHIVE (named drop) | lane docs archived; `projects/personal/learning-app/` stays on disk; deployed site keeps serving (§1a row 4) | SMP index delta; lane files; any lessons job |
| 21 | Wider Alexa ambitions | `projects/personal/skippy-app/ALEXA-ACCESS-SPEC.md` (kid access, slots) | RETIRE-ARCHIVE | archive; SMP-10 channel adapter unaffected | citations of the spec |
| 22 | Gracie development | Chantelle's assistant — wider build (THE-ASSISTANTS, assistants-replan) | DEFER, RESUMABLE | archive dev docs with RESUMABLE banner; 🔴 her LIVE jobs (progesterone reminder, reps feedback, confirm cards) keep running — a real person consumes them today | canon rows; any open cards |
| 23 | Neeko | The Neeko persona: daily review + project-doc sweep jobs | DEFER, RESUMABLE | jobs disabled via frontmatter (reversible); libs stay on disk; dev docs archived | the two `neeko-*` jobs; any cards |
| 24 | Shopping infrastructure | `projects/ops/skippy-jobs/lib/shopping-agent-add.mjs`, criteria gate, tests, skill | RETIRE (named drop) | code parks on disk with the family app; skill marked retired; jobs (if any found by STEP 2's two-way search) disabled | skill pointer; jobs |
| 25 | OpenBrain delivery docs | `projects/ops/openbrain-delivery/` | RETIRE-ARCHIVE | archive (store untouched, see #6) | citations |
| 26 | One-cloud-copy programme | continuity PLAN item 25 | KEEP | — | — |
| 27 | Google sign-in | `projects/ops/google-sso/` built, awaiting switch-on | KEEP | — | — |
| 28 | `projects/ops/REBUILD-2026-08-21/` leftovers | Old SP/skippy-100 tree whose archive move (an SMP manifest step) has not finished | HANDOFF | one dated line into the SMP programme index — it owns that manifest; this plan does not seize it | — |
| 29 | Retired-lane scheduled jobs | `projects/ops/skippy-jobs/jobs/neeko-daily-review-run.mjs`, `projects/ops/skippy-jobs/jobs/neeko-project-doc-sweep-run.mjs`, `projects/ops/skippy-jobs/jobs/sp13-quality-report.mjs`, plus whatever STEP 2's two-way search adds | DISABLE (frontmatter), never delete | in place, disabled, reversible | the jobs themselves |
| 30 | Live pointers everywhere else | ACTIVE-WORK canon rows, HEARTBEAT rows, board cards, skills/agents presenting retired lanes as live | PURGE (status edits / card closes) | — | swept by STEPS 9–10 |
## 2 · The complete UX map (this becomes the test manifest verbatim)
| Id | Screen / entry point | State (default·empty·error·loading) | Element / interaction | Expected behavior | Navigation from → to |
|---|---|---|---|---|---|
| U1 | the archive home `projects/_archive/goal-purge-2026-09-04/` | default | a future reader opens the folder | the retirement note at its top explains in plain English what was retired/parked, why, on whose words, and how to resume Gracie/Neeko/family app | old citation → archive → note |
| U2 | ZION programme index | default | agent looks for live work | every retired/folded lane row reads RETIRED/FOLDED with a 2026-09-04 delta and an archive pointer; kept lanes read unchanged | index → lane or archive |
| U3 | SMP programme index | default | agent looks for live work | SMP-2 reads PARKED, SMP-9 reads RETIRED, both dated; handoff line re REBUILD leftovers present | index → lanes |
| U4 | ACTIVE-WORK canon table | default | agent checks what is live | zero retired items presented as live | table → owner |
| U5 | a disabled job file | default · disabled | the jobs daemon walks it | `disabled:` frontmatter honoured as step −2; job does not fire; kept control job still fires | daemon → skip |
| U6 | the board | default | agent or Nick reads cards | no open card drives a retired lane | board → card |
| U7 | this plan's `## STEPS` | default · error | executor finds next step; checker re-runs a proof | exactly one next step identifiable; every closed step carries pasted proof | plan → step |
| U8 | Nick's report (STEP 13) | default | Nick reads it | plain English, three labelled blocks, no jargon/paths/codenames; ends with WHAT'S WAITING ON YOU or NOTHING NEEDS YOU | chat |
## 3 · Lanes and frozen contracts
| Lane | Scope (in / out) | Owner | Definition of done | Model (explicit) |
|---|---|---|---|---|
| L1 docs-and-indexes | IN: the two programme indexes' status deltas, retired lane files' git-moves, the archive folder, this plan's folder. OUT: any kept lane's content, anything under `projects/business/business-app/` | this session (Boris 3) dispatching workers | STEPS 1–5, 7–8 proven | executor GLM 5.3 (zai), haiku-tier grunt as the fallback when the outside vendors refuse at dispatch time; checker a separate Sonnet session |
| L2 jobs | IN: `disabled:` frontmatter on the named job files only. OUT: every other file in `projects/ops/skippy-jobs/`, all lib code, the daemon itself | this session dispatching workers | STEP 6 proven with its control | executor GLM 5.3 (zai), haiku grunt fallback; checker a separate Sonnet session |
| L3 pointers-and-proof | IN: ACTIVE-WORK status rows, board card closes via the board tool, citation updates for moved paths, the two-way absence proof. OUT: content edits to any kept plan beyond dated handoff/delta lines | this session dispatching workers | STEPS 9–12 proven | executor GLM 5.3 (zai), haiku grunt fallback; checker a separate Sonnet session; the STEP 12 cold walk is Sonnet in a fresh session |
**Contracts, frozen:** every commit is scoped — `git commit -m "..." -- <paths>` naming exactly the files that step touched (§W; this tree is shared with live sessions tonight). No `git stash`, ever. Re-read every file immediately before writing it. One worker in flight at a time from this session (two peer Boris sessions plus one other agent share the machine budget). Changes to THIS plan's scope land as dated deltas in `projects/ops/retirement/PLAN-CHANGES.md`. Every dispatch carries the §T header verbatim — ROLE from the closed list, REVIEW, RETURN-SIZE, and the MACHINE RULES travel block pasted in substance; a builder brief states "you are a single one-shot dispatch; run commands in the foreground; 'in progress' is never a final answer."
## 3b · Execution map — the Step map, then one STEP block per row
A task is DONE only when its review-ledger row is CLOSED by a reviewer that is not the builder.
**Step map (read this first):**
| Stage | # | Task (step name) | Gate to enter | EXECUTOR (model, from the matrix) | CHECKER (different model — never the builder) | DONE-PROOF (runnable command) | Ends when |
|---|---|---|---|---|---|---|---|
| Plan | 0 | Arm the loop | nothing | the driving session (fable) | sonnet — confirms the loop text below is verbatim from the skill | `command grep -c "ARM THE LOOP" PLAN.md` (run from `projects/ops/retirement/`) | loop armed |
| Framing | 1 | Archive home + note + changes file | nothing | glm (haiku grunt fallback) | sonnet | `ls projects/_archive/goal-purge-2026-09-04/` | note exists, committed scoped |
| Framing | 2 | Two-way re-verification of every RETIRE/DISABLE row | nothing | glm (haiku grunt fallback) | sonnet | `command grep -c "METHOD-A" projects/ops/retirement/evidence/refcounts-before.txt` | evidence file complete |
| Elements | 3 | ZION index dated deltas | STEP 2 evidence for ZION rows | glm (haiku grunt fallback) | sonnet | `command grep -c "2026-09-04" projects/ops/zion/PLAN-ZION-PROGRAMME.md` | deltas landed, scoped commit |
| Elements | 4 | Git-move retired ZION lane files | STEP 3 deltas landed | glm (haiku grunt fallback) | sonnet | `ls projects/_archive/goal-purge-2026-09-04/projects/ops/zion/` | nine lanes' files moved with banners |
| Elements | 5 | SMP deltas + Alexa spec archive + handoff lines | STEP 2 evidence for SMP rows | glm (haiku grunt fallback) | sonnet | `command grep -c "PARKED\|RETIRED" projects/ops/skippy-master-plan/PLAN-SMP-PROGRAMME.md` | deltas + moves landed |
| Elements | 6 | Disable retired-capability jobs, prove with a control | STEP 2's job list | glm (haiku grunt fallback) | sonnet | `command grep -l "disabled:" projects/ops/skippy-jobs/jobs/sp13-quality-report.mjs` | frontmatter present + control fired |
| Elements | 7 | Archive assistants (Gracie/Neeko dev docs), RESUMABLE | STEP 2 evidence | glm (haiku grunt fallback) | sonnet | `ls projects/_archive/goal-purge-2026-09-04/projects/ops/` | docs moved, live jobs untouched |
| Elements | 8 | Archive OpenBrain-delivery + quality-tracking docs | STEP 2 evidence | glm (haiku grunt fallback) | sonnet | `ls projects/_archive/goal-purge-2026-09-04/projects/ops/` | folders moved, store proven untouched |
| Details | 9 | Purge live pointers: canon table, heartbeat, board cards | STEPS 3–8 | glm (haiku grunt fallback) | sonnet | `command grep -ci "RETIRED 2026-09-04" ACTIVE-WORK.md` | pointers read retired/absent |
| Details | 10 | Citation sweep for every moved path | STEPS 4,5,7,8 | glm (haiku grunt fallback) | sonnet | `bash projects/ops/retirement/evidence/citation-sweep.sh` | zero live-tree citations of old paths |
| Tests | 11 | Two-way absence proof, after-counts | STEPS 9–10 | glm (haiku grunt fallback) | sonnet | `command grep -c "METHOD-A" projects/ops/retirement/evidence/refcounts-after.txt` | after-evidence complete |
| Proof | 12 | Cold walk by a fresh session | STEP 11 | sonnet (fresh session — verification, not build) | fable — this session relays the verdict unchanged into STEPS | `command grep -c "COLD WALK VERDICT" PLAN.md` (run from `projects/ops/retirement/`) | verdict lands, PASS or named failures |
| Output | 13 | Plain-English report to Nick | STEP 12 verdict | the driving session (fable) | sonnet — lints the draft with the closing-message checker before send | `command grep -c "REPORT SENT" STATE.md` (run from `projects/ops/retirement/`) | sent |
| Proof | 14 | Postmortem + registry append | STEP 13 | the driving session (fable) | sonnet | `command grep -c "POSTMORTEM" PLAN.md` (run from `projects/ops/retirement/`) | postmortem written into this file |
**Then one block per step:**
### STEP 0 — ARM THE LOOP, BEFORE ANYTHING ELSE.
> **STEP 0 — ARM THE LOOP, BEFORE ANYTHING ELSE.** Set a 5-minute loop. Every time it fires,
> answer these four in order and CORRECT any failure before doing anything else:
> 1. **NORTH STAR** — is what I am doing this minute moving this plan's North Star? If not,
> drop it and take the highest-value unblocked step that does.
> 2. **FAN-OUT** — is my queue full up to the concurrency cap (§T)? Full capacity means the
> cap is reached and a queue of ready work sits behind it — NEVER "launch everything at
> once". Below the cap with ready work → dispatch now. At the cap → queue, don't launch.
> 3. **CHEAP** — are cheap models doing the building? If anything expensive is building,
> move that work down now.
> 4. **BLOCKED** — for anything I have called blocked: name the three concrete things I tried.
> If I cannot, it is not blocked — drive through it now.
> Then keep building. The loop never stops until the FINISH LINE is proven.
(For THIS plan the fan-out cap is deliberately ONE worker in flight from this session — three other sessions share tonight's machine budget, and last night's crush is the reason. That is the cap, not a stall.)
### STEP 1 — Create the archive home, the retirement note, and this plan's changes file
**Enter this step when:** nothing. This is the first step.
**Builder:** GLM 5.3 (zai), haiku-tier grunt fallback · **Checker:** Sonnet, different session
**Files you may touch:** inside `projects/_archive/goal-purge-2026-09-04/`, a new file named RETIREMENT-NOTE.md; inside `projects/ops/retirement/`, new files named STATE.md and PLAN-CHANGES.md (all three declared in §0's created-artifacts list). **Never** any existing file.
**Do exactly this:**
1. Create the folder `projects/_archive/goal-purge-2026-09-04/` and write the retirement note: plain English — what this archive is, Nick's 2026-09-04 words it executes, the disposition table copied from §1c, and per-item resume instructions for Gracie, Neeko and the family app (what to move back, which jobs to re-enable by removing `disabled:`).
2. Create the changes file (header + date) and the state file (current state: not started).
3. Commit scoped: `git commit -m "goal-purge STEP 1: archive home + retirement note" -- projects/_archive/goal-purge-2026-09-04 projects/ops/retirement`.
**PROOF — all must be true:**
- `ls projects/_archive/goal-purge-2026-09-04/` prints `RETIREMENT-NOTE.md`.
- The note names Gracie, Neeko and the family app as RESUMABLE with concrete resume steps. FAILS IF any of the three is missing.
**If it fails:** one line to the overseer; next unblocked step is STEP 2 (independent).
**Checker's job:** re-run the proof yourself; read the note cold and confirm a stranger could resume Gracie from it.
### STEP 2 — Re-verify every RETIRE/DISABLE row two ways, before anything moves
**Enter this step when:** nothing. This is independent of STEP 1.
**Builder:** GLM 5.3 (zai), haiku grunt fallback · **Checker:** Sonnet, different session
**Files you may touch:** inside `projects/ops/retirement/evidence/`, new files named refcounts-before.txt and citation-sweep.sh (declared in §0's created-artifacts list). **Never** any file being inventoried — this step is read-only against the workspace.
**Do exactly this, per §1c RETIRE/DISABLE/DEFER row (items 1, 5, 6, 9, 10, 11, 13, 15, 17, 20, 21, 22, 23, 24, 25, 29):**
1. METHOD-A (content): `command grep -ril "<item's name patterns>"` over `projects/`, `ZION/` and `.claude/` — patterns, not exact names (e.g. `skippy[ -_]?school`, `neeko`, `sp13-quality`, `openbrain`). Record the file list and count under a `METHOD-A` heading.
2. METHOD-B (structure, differently shaped): suffix-aware filename sweep — a glob for the item's filename stems anywhere in the tree (e.g. `*shopping*`, `*neeko*`, `PLAN-ZION-6*`), PLUS a read of the one live surface that would present it (the jobs folder listing for jobs; the programme index for lanes; the board read for cards). Record under `METHOD-B`.
3. For each row, write one DEPENDENCY line: what still calls/reads this item from a KEPT surface. 🔴 A hit on a kept surface is a finding, not a blocker — it changes the disposition to FOLD or adds a citation-update to STEP 10, and the change is a dated delta in the changes file.
4. Write the sweep script: for every path this plan will move, a `command grep -rl` over the live tree excluding `projects/_archive` and `.claude/worktrees`, exiting non-zero if any live citation of an old path remains. Prove it can fail: run it BEFORE any move — it must exit non-zero (the paths are still cited); record that red run in the evidence file.
5. Commit scoped to the two evidence files.
**PROOF — all must be true:**
- `command grep -c "METHOD-A" projects/ops/retirement/evidence/refcounts-before.txt` ≥ 16 and the same count for `METHOD-B` — every row measured both ways. FAILS IF any row has only one method.
- The red run of the sweep is recorded with its non-zero exit. FAILS IF the sweep has never been seen failing.
**If it fails:** the item with a single-method count is re-measured before any step moves it; everything else proceeds.
**Checker's job:** pick three rows at random, re-run both methods yourself, compare counts. A mismatch throws the row's evidence out for re-measurement.
### STEP 3 — Dated dispositions into the ZION programme index
**Enter this step when:** STEP 2's evidence covers the ZION rows.
**Builder:** GLM 5.3 (zai), haiku grunt fallback · **Checker:** Sonnet, different session
**Files you may touch:** `projects/ops/zion/PLAN-ZION-PROGRAMME.md` (status deltas only), its change record. **Never** delete a lane row, a stage, a goal or a capability — governance forbids it; RETIRED is a status, not a removal. **Never** touch ZION-3/4/8/12/14 rows beyond leaving them as they are.
**Do exactly this:**
1. Re-read the index immediately before writing (§W — another session may have edited it tonight).
2. For each §1c ZION row: append a dated status line to the lane's index row — `RETIRED 2026-09-04, Nick's words in REGROUP-SOURCE §A12; work archived under projects/_archive/goal-purge-2026-09-04/` (or FOLDED → named owner, or PARKED, or DEFERRED-IN-PLACE per §1c).
3. Post the two handoff lines: ZION-17 → into `projects/ops/zion/STATE-ZION-19.md` (`board-PM enforcement folds into Hub work per Nick 2026-09-04`); ZION-7 → into the SMP index for SMP-8 (`the jobs fleet is SMP-8's root; fleet repair is its work`). 🔴 NOT into ZION-3's plan: that file was superseded on 2026-09-04 and its own first lines say so, so a handoff posted there reaches nobody.
4. Dated delta in the programme change record; commit scoped to the files touched.
**PROOF:** `command grep -c "2026-09-04" projects/ops/zion/PLAN-ZION-PROGRAMME.md` ≥ 12 (nine RETIRED + two FOLDED + one PARKED). FAILS IF any retired lane's row still reads as open work with no dated disposition.
**If it fails (e.g. the governance gate refuses the write):** do not stall on a ticket — record the prepared deltas in the state file (ungoverned), continue with STEPS 4+ where permitted, and hand Nick the one-line ask in STEP 13.
**Checker's job:** re-run the grep; read three deltas and confirm each cites Nick's words and the archive path.
**Handoff:** the two dated lines in action 3, posted the moment this closes, not batched.
### STEP 4 — Move the retired ZION lane files into the archive
**Enter this step when:** STEP 3's deltas are landed (an index must never point at a hole).
**Builder:** GLM 5.3 (zai), haiku grunt fallback · **Checker:** Sonnet, different session
**Files you may touch:** the plan/state/changes/questions/evidence files of ZION-1, 5, 6, 9, 10, 11, 13, 16, 18 ONLY, and their destinations under `projects/_archive/goal-purge-2026-09-04/` preserving source-relative paths. **Never** ZION-3/4/8/12/14/17/19-owned files, **never** `projects/ops/zion/_regret-registry-164.txt` (a live gate input).
🔴 **RETIREMENT COLLISION, FOUND BY THE CROSS-PLAN COLD REVIEW 2026-09-04 — ZION-17's FILES DO NOT MOVE IN THIS DRIVE, AT ALL.** This plan originally archived `PLAN-ZION-17-board-pm-enforcement.md` and `STATE-ZION-17.md` once their handoff was posted. The Hub plan's STEP 9 **writes into both of those files** and reads `projects/ops/zion/evidence/step12-round12-findings-2026-09-03.txt` beside them, all named in its own file fence. Archiving them mid-drive would silently break a step in a live plan — the precise failure this plan's own dependency rule exists to prevent, and worse than leaving a document where it is. The fold is therefore recorded as an INDEX STATUS CHANGE ONLY; the files stay until the Hub plan closes, and whoever closes it may move them then. Nothing in this drive owns that later move, and that is deliberate rather than an omission.
**Do exactly this:**
1. For each of the nine lanes: check the file is clean of concurrent edits (`git status --porcelain` on that one path — dirty means wait one pass and retry, §W), prepend a banner (`RETIRED 2026-09-04 — archived by the goal purge, Nick's order in REGROUP-SOURCE §A12; nothing here is current instruction`), then `git mv` it to the archive preserving the source-relative path.
2. One scoped commit per lane batch, paths named: `git commit -m "goal-purge STEP 4: <lane> archived" -- projects/ops/zion projects/_archive/goal-purge-2026-09-04`.
**PROOF:**
- `ls projects/_archive/goal-purge-2026-09-04/projects/ops/zion/` lists files for all nine lanes.
- `ls projects/ops/zion/` no longer lists a PLAN or STATE file for the nine retired numbers, and still lists the kept lanes' files. FAILS IF a kept lane's file moved or a retired lane's file remains.
**If it fails:** the failed lane stays in place with its banner; one line to the overseer; the other lanes proceed.
**Checker's job:** re-run both listings; open two archived files and confirm the banner is the FIRST thing a reader sees.
### STEP 5 — SMP deltas, the Alexa wider-ambition spec, Skippy School's lane
**Enter this step when:** STEP 2's evidence covers the SMP/Alexa/school rows.
**Builder:** GLM 5.3 (zai), haiku grunt fallback · **Checker:** Sonnet, different session
**Files you may touch:** `projects/ops/skippy-master-plan/PLAN-SMP-PROGRAMME.md` (dated status deltas + one handoff line only), `projects/ops/skippy-master-plan/PLAN-SMP-2.md` and `projects/ops/skippy-master-plan/PLAN-SMP-9.md` (banner lines only), `projects/personal/skippy-app/ALEXA-ACCESS-SPEC.md` (banner + git mv), archive destinations under `projects/_archive/goal-purge-2026-09-04/`. **Never** any other SMP lane file, **never** anything under `projects/personal/learning-app/` (the app root stays untouched on disk; the deployed site keeps serving per §1a row 4), **never** SMP-10's channel-adapter material.
**Do exactly this:**
1. Re-read each file immediately before writing.
2. SMP index: dated delta lines — SMP-2 `PARKED 2026-09-04 (family app resumes after Skippy — Nick: "finish voice app then we deploy the same setup in the hub and family app")`; SMP-9 `RETIRED 2026-09-04 (Skippy School dropped — Nick, REGROUP-SOURCE §A12); lane docs archived; the deployed site keeps serving untouched`. Plus one handoff line: `the projects/ops/REBUILD-2026-08-21/ leftovers belong to this programme's own archive manifest (SRC rows); completing that move is SMP work, flagged 2026-09-04 by the goal purge`.
3. Banner `projects/ops/skippy-master-plan/PLAN-SMP-9.md` and git-mv it (with its changes file) to the archive under its source-relative path. Banner `projects/ops/skippy-master-plan/PLAN-SMP-2.md` as PARKED in place (its lane resumes; the file stays).
4. Banner and git-mv `projects/personal/skippy-app/ALEXA-ACCESS-SPEC.md` to the archive (`the Alexa CHANNEL lives in SMP-10 and is kept; this wider-access ambition is retired per Nick 2026-09-04`).
5. Scoped commits naming exactly these paths.
**PROOF:**
- `command grep -c "PARKED 2026-09-04\|RETIRED 2026-09-04" projects/ops/skippy-master-plan/PLAN-SMP-PROGRAMME.md` ≥ 2.
- `ls projects/_archive/goal-purge-2026-09-04/projects/personal/skippy-app/` lists the Alexa spec. FAILS IF the learning-app root changed at all (`git status --porcelain -- projects/personal/learning-app` non-empty is a step failure).
**If it fails:** deltas that landed stand; the failed move stays in place with its banner; one line to the overseer.
**Checker's job:** re-run the proofs; confirm SMP-10's files are untouched (`git log --oneline -1 -- projects/ops/skippy-master-plan/PLAN-SMP-10.md` predates today's steps).
### STEP 6 — Disable the retired capabilities' scheduled jobs, with a live control
**Enter this step when:** STEP 2's METHOD-A/B job list exists (the three named jobs plus anything the two-way search added).
**Builder:** GLM 5.3 (zai), haiku grunt fallback · **Checker:** Sonnet, different session
**Files you may touch:** `projects/ops/skippy-jobs/jobs/neeko-daily-review-run.mjs`, `projects/ops/skippy-jobs/jobs/neeko-project-doc-sweep-run.mjs`, `projects/ops/skippy-jobs/jobs/sp13-quality-report.mjs`, plus only files STEP 2's evidence names as retired-capability jobs — frontmatter block only. **Never** `projects/ops/skippy-jobs/jobs/chantelle-progesterone-reminder.mjs`, `projects/ops/skippy-jobs/jobs/chantelle-reps-feedback-sync.mjs`, `projects/ops/skippy-jobs/jobs/chantelle-confirm-cards.mjs` or any other live family/Hub-facing job, **never** any lib code, **never** the daemon.
**Do exactly this:**
1. Add to each named job's frontmatter: `disabled: 2026-09-04 goal-purge — capability retired by Nick's order (REGROUP-SOURCE §A12); re-enable by removing this line` (the filesystem kill-switch MACHINE-RULES rule 8 already honours as step −2 of every task prompt).
2. Control, both directions: after the next daemon cycle, read the daemon's own run log/heartbeat — the disabled jobs show no new run, AND one named kept job shows a fresh run in the same window (the known-good control; without it, silence proves nothing about the switch).
3. Scoped commit naming exactly the job files touched.
**PROOF:**
- `command grep -l "disabled: 2026-09-04 goal-purge" projects/ops/skippy-jobs/jobs/neeko-daily-review-run.mjs projects/ops/skippy-jobs/jobs/neeko-project-doc-sweep-run.mjs projects/ops/skippy-jobs/jobs/sp13-quality-report.mjs` prints all three paths.
- The control evidence (kept job fired, disabled jobs silent, same window) is pasted into STEPS item 6. FAILS IF the kept control did not fire — then the fleet's state, not the switch, is what the silence measured, and the claim is not made.
**If it fails:** if no daemon cycle can be observed (the fleet's true state is SMP-8's to measure), record the frontmatter half as done and the fire-half as NOT MEASURABLE FROM HERE — the daemon cycle, with the SMP-8 handoff line already posted; continue.
**Checker's job:** re-run the grep; read one disabled file and confirm ONLY frontmatter changed (`git diff` on that one path shows no code lines).
### STEP 7 — Archive the assistants' development work, resumable; leave Gracie's live service running
**Enter this step when:** STEP 2's evidence covers §1c rows 22–23.
**Builder:** GLM 5.3 (zai), haiku grunt fallback · **Checker:** Sonnet, different session
**Files you may touch:** `projects/ops/THE-ASSISTANTS.md` and the folder `projects/ops/assistants-replan/` (banner + git mv to archive), destinations under `projects/_archive/goal-purge-2026-09-04/`. **Never** the three chantelle job files named in STEP 6's fence, **never** anything under `projects/ops/skippy-jobs/lib/` (Neeko/Gracie libs stay on disk for resume), **never** any Gracie-serving code path.
**Do exactly this:**
1. Banner both (`DEFERRED 2026-09-04, RESUMABLE — Nick: "finish skippy then we do gracie and neeko later"; resume instructions in the archive's retirement note`), git-mv to the archive preserving paths.
2. Scoped commit.
**PROOF:** `ls projects/_archive/goal-purge-2026-09-04/projects/ops/` lists `THE-ASSISTANTS.md` and `assistants-replan`; `git status --porcelain -- projects/ops/skippy-jobs/lib` shows nothing from this step's commits. FAILS IF any lib file moved.
**If it fails:** banner-in-place instead of move; one line to the overseer.
**Checker's job:** re-run both; confirm the RESUMABLE banner names the resume trigger as "after Skippy, on Nick's word" rather than a date nobody set.
### STEP 8 — Archive the OpenBrain-delivery and quality-tracking doc folders; prove the live store untouched
**Enter this step when:** STEP 2's evidence covers §1c rows 25 and 11, including the DEPENDENCY lines.
**Builder:** GLM 5.3 (zai), haiku grunt fallback · **Checker:** Sonnet, different session
**Files you may touch:** the folders `projects/ops/openbrain-delivery/` and `projects/ops/sp13-quality-tracking/` (banner + git mv), destinations under `projects/_archive/goal-purge-2026-09-04/`. **Never** `projects/personal/health/engine/brain-routing/`, **never** `projects/business/business-app/engine/`, **never** any running store, adapter or MCP registration.
**Do exactly this:**
1. Check STEP 2's DEPENDENCY lines for these folders: if any KEPT surface reads a file inside them (a runbook an engine loads, a config a job reads), that file STAYS and only the rest moves — the §1c disposition narrows via a dated delta in the changes file.
2. Banner + git-mv the folders (or their non-depended remainder) to the archive.
3. Scoped commit.
**PROOF:** `ls projects/_archive/goal-purge-2026-09-04/projects/ops/` lists both folders; after the move, one live probe of each MCP front door (`personal_answer`, `business_narrative_answer` — one benign question each) returns a real answer. FAILS IF either engine's answer path degraded — then the move touched a dependency and the move commit is reverted (reversible by design) before anything else.
**If it fails:** revert the move commit, record the dependency, narrow the disposition with a dated delta.
**Checker's job:** re-run the two MCP probes yourself in a fresh session; a missing tool is an unconfigured machine, not a broken store — say which you observed.
### STEP 9 — Purge the live pointers: canon table, heartbeat rows, board cards
**Enter this step when:** STEPS 3–8 dispositions are landed (a pointer must have somewhere true to point).
**Builder:** GLM 5.3 (zai), haiku grunt fallback · **Checker:** Sonnet, different session
**Files you may touch:** `ACTIVE-WORK.md` (status cells of retired items' rows only), `HEARTBEAT.md` (rows of retired drives only), board cards via `node projects/ops/skippy-jobs/lib/board-report.mjs` (close/annotate verbs only). **Never** another session's live rows; **never** create a new tracker.
**Do exactly this:**
1. Re-read each file immediately before writing (§W — HEARTBEAT is written by everything).
2. ACTIVE-WORK: mark each retired item's row `RETIRED 2026-09-04` with the archive pointer; kept rows untouched.
3. Board: read the board, close or annotate any open card driving a retired lane, citing Nick's 2026-09-04 words; read each change back from the board (a write receipt is a claim).
4. Scoped commits naming exactly the files touched.
**PROOF:** `command grep -ci "RETIRED 2026-09-04" ACTIVE-WORK.md` ≥ 1 per retired item present in that table (count recorded against STEP 2's baseline); the board read-back shows zero open cards for retired lanes, pasted into STEPS item 9. FAILS IF a card claims closed but a fresh board read still shows it open.
**If it fails:** the board tool being unreachable is NOT MEASURABLE FROM HERE — the board tool, recorded with the command's own error text; the file edits still land.
**Checker's job:** fresh board read yourself; diff ACTIVE-WORK's retired rows against §1c.
### STEP 10 — Update every citation of every moved path, in the same pass
**Enter this step when:** STEPS 4, 5, 7, 8 moves are landed.
**Builder:** GLM 5.3 (zai), haiku grunt fallback · **Checker:** Sonnet, different session
**Files you may touch:** any LIVE-tree file whose only needed change is repointing a moved path to its archive path (or marking the reference retired) — each file named in the commit. **Never** files under `projects/_archive/` (history stays as written), **never** `.claude/worktrees/`, **never** generated files (their generators get a NEXT-list line instead — a hand-edited mirror is registry entry 40's failure).
**Do exactly this:**
1. Run the sweep: `bash projects/ops/retirement/evidence/citation-sweep.sh` (built and proven red by STEP 2).
2. For every hit: update the citation to the archive path, or mark it retired-with-pointer; generated files (the org chart, capability pages) get one NEXT-list line naming the generator instead of a hand edit.
3. Re-run the sweep until it exits zero. Scoped commits.
**PROOF:** `bash projects/ops/retirement/evidence/citation-sweep.sh` exits 0 (and was seen exiting non-zero in STEP 2 — a check never seen red is not a check). FAILS IF exit 0 was achieved by narrowing the sweep rather than fixing citations — the checker diffs the sweep script against STEP 2's committed version.
**If it fails:** remaining hits are listed in the state file with owners; the next step proceeds only if the hits are generated-file lines already on the NEXT list.
**Checker's job:** confirm the sweep script is byte-identical to STEP 2's committed version, then re-run it yourself.
### STEP 11 — After-counts: the same two-way measurement, after the purge
**Enter this step when:** STEPS 9–10 are landed.
**Builder:** GLM 5.3 (zai), haiku grunt fallback · **Checker:** Sonnet, different session
**Files you may touch:** inside `projects/ops/retirement/evidence/`, a new file named refcounts-after.txt (declared in §0's created-artifacts list). Read-only otherwise.
**Do exactly this:** repeat STEP 2's METHOD-A and METHOD-B per row, same patterns, same scopes; record counts beside the before-counts; for each row state plainly what remains and why it is legitimate (history, archive, parked code) — a number without its population is registry entry 72's failure. This plan's own files and evidence are a named, subtracted population (an investigation's searches must not contaminate its evidence).
**PROOF:** `command grep -c "METHOD-A" projects/ops/retirement/evidence/refcounts-after.txt` ≥ 16 and the same for `METHOD-B`; every row's remaining-hits line names its population. FAILS IF any row's remainder includes an unexplained live-surface hit.
**If it fails:** the unexplained hit routes back to STEP 9/10 as one more pointer; re-measure only that row.
**Checker's job:** re-run two rows' methods yourself; compare.
### STEP 12 — The cold walk: a session that built none of this tries to get lost
**Enter this step when:** STEP 11's after-evidence exists.
**Builder (executor):** Sonnet, a FRESH session that has seen none of this plan's execution — this is verification-tier work, deliberately not cheap · **Checker:** fable (this session) — relays the verdict UNCHANGED into STEPS under the heading `COLD WALK VERDICT`; a relay that edits the verdict is the self-grading this plan forbids.
**Files you may touch:** none. This step is read-only.
**Do exactly this (the brief to the cold session, verbatim intent):** "Open ACTIVE-WORK, both programme indexes, the board, and the jobs folder. List every piece of work a new agent would believe is LIVE. Then try, honestly, to find a way into any of: the shopping list, the weekly report, Skippy School lessons, the OpenBrain build, the model-router build, the cleanup audit, wider Alexa access, Gracie/Neeko development. PASS = every route ends at a dated retired/parked marker pointing at the archive; FAIL = any route presents retired work as live, named with file and line."
**PROOF:** the verdict, PASS or FAIL with named routes, pasted verbatim under STEPS item 12 beneath the words `COLD WALK VERDICT`. FAILS IF the verdict is FAIL, or if the walk was performed by any session that executed STEPS 1–11.
**If it fails:** each named route becomes one more STEP 9/10 pointer fix; the cold walk re-runs on the named failures only (one check round per §G — no fresh full sweep).
**Checker's job (this session):** relay unchanged, including anything unflattering.
### STEP 13 — Tell Nick, in plain English
**Enter this step when:** STEP 12's verdict is in.
**Builder:** the driving session (fable) · **Checker:** Sonnet — runs the closing-message linter (`node projects/ops/skippy-jobs/lib/check-closing-message.mjs` on the draft) and reads it as a stranger before send.
**Files you may touch:** the state file (final state; write the words `REPORT SENT` with the date when it is).
**Do exactly this:** three labelled blocks (Where this project stands · The goal · What needs you), no jargon, no paths, no codenames; restate what was archived, what was parked and how it resumes, what keeps running (the kids' site, Chantelle's reminders, the memory store), and the one ruling conflict resolved (§1a row 6) so he can overrule it in one word if he wants. End with WHAT'S WAITING ON YOU or NOTHING NEEDS YOU.
**PROOF:** message sent; `REPORT SENT 2026-09-XX` recorded in the state file. FAILS IF the message names an internal codename without explaining it.
**If it fails:** rewrite against the cold-reader test and resend once.
### STEP 14 — Postmortem, in this file, then close
**Enter this step when:** STEP 13 is sent.
**Builder:** the driving session (fable) · **Checker:** Sonnet, different session
**Files you may touch:** this plan file (POSTMORTEM section + STEPS), `.claude/skills/plan/references/failure-registry.md` (append only, four-cell format, only if a genuinely new pattern emerged — "nothing worth extracting" is a good answer).
**Do exactly this:** write `## POSTMORTEM` at the end of this file: what the purge measured wrong at planning time, any disposition that changed mid-drive and why, and whether the archive-the-work/purge-the-pointers split held. Append to the registry only a recurring, non-obvious, codifiable pattern.
**PROOF:** `command grep -c "POSTMORTEM"` on this file (run from `projects/ops/retirement/`, target `PLAN.md`) ≥ 2. FAILS IF the plan closes without the section.
**If it fails:** the lane is not closed — a lane is not closed until its postmortem is written into its own plan file.
## 4 · Regret Check (every registry entry, or the plan is not done)
*167 registry entries counted 2026-09-04, plus two novel rows at the end. Recurring measures, named once and cited by key: **M-2WAY** = every RETIRE/DISABLE decision is measured two differently-shaped ways before and after (STEPS 2, 11; §Z); **M-ARCH** = archive-over-delete, git-mv with structure preserved, banner first, nothing deleted (STEPS 4, 5, 7, 8); **M-CITE** = every moved path's citations updated in the same pass, sweep proven red first (STEPS 2, 10); **M-SCOPED** = scoped commits naming paths, re-read before write, no stash (§3 contracts, §W); **M-CTRL** = every silence claim carries a known-good control (STEP 6's kept-job control; STEP 8's MCP probes); **M-COLD** = a fresh session that built nothing grades the result and the verdict is relayed unchanged (STEP 12); **M-STATUS** = dispositions land as dated status deltas, no stage/goal/capability deleted (STEPS 3, 5, 9); **N/A-NOBUILD** = this plan builds no code, no UI, no store and no pipeline — it moves documents, edits status lines and flips reversible frontmatter.*
| Failure mode (registry entry) | The measure in THIS plan that prevents it | Where it lives |
|---|---|---|
| A second system was built because the first was invisible | Ownership receipt cites the fresh two-way search for an existing purge project; the one prior owner (custodian ruling) is on the sheet | §0, §1a row 6 |
| A capability was declared impossible from a stale or unverified claim | Nick's "there are no scheduled jobs right now" is treated as impression; STEP 6 measures with a control instead of building on it | §0 P3, STEP 6 |
| An absence was asserted without opening the store that would hold it | M-2WAY; the store that would hold each item is named per row | STEPS 2, 11 |
| A known constraint's reason was lost, and it silently capped the product | Every disposition row cites Nick's exact clause; the 08-30 vs 09-04 ruling conflict is quoted on the sheet, both dated | §1c, §1a row 6 |
| An instruction assumed capacity the executor doesn't have | Steps fence to file lists a worker can hold; the inventory is in this one file, not spread across reads | §3b fences |
| Expectations/manifest rows carried no grounding | Every §1c row carries its measurement method and date | §1c header |
| Work was written to a queue no reader ever visits | Every artifact names its reader (archive→future agent; report→Nick; evidence→checkers) | §2 UX map |
| A detector's death was invisible because only its target read it | The citation sweep's red run is recorded where the checker re-reads it, not only where it runs | STEP 2.4 |
| A decision settled once re-opened elsewhere, or two copies of a rule disagreed | The two conflicting purge-ownership rulings are surfaced together, resolved by the later, on the sheet | §1a row 6 |
| A rule constraining the user turned out to be an agent's invention | Every disposition quotes Nick verbatim with date and source line | §1c |
| Remediation was ordered with diagnosis last | STEP 2 (measure) gates every move step (act) | §3b gates |
| A document, label, or comment was believed over the live system | Dispositions rest on tonight's live globs/greps/listings, not on lane files' own status claims | §1c method |
| A proposal was sold on a capability never opened and read | The kill-switch (frontmatter honoured as step −2) is MACHINE-RULES rule 8's own documented mechanism, not an assumed one | STEP 6 |
| A cause was named and acted on without eliminating alternatives | STEP 8's failure branch distinguishes "move broke it" from "engine was already unconfigured" before reverting | STEP 8 |
| The human was asked a question the record already answers | Zero UNCONFIRMED rows; everything is settled from his 2026-09-04 words; STEP 13 asks nothing already answered | §1a |
| A spec and its guard were authored by the same hand and ratified the same defect | The cold walk brief's PASS/FAIL bar is written here at plan time; the walker never saw the execution | STEP 12 |
| Session rules never reached the subagents doing the work | Every dispatch carries the §T header with MACHINE RULES substance pasted, per the skill | §3 contracts |
| One rule was blanket-applied across items needing per-item answers | Five distinct dispositions exist; each row decided per item, not one verb for all 30 | §1c |
| Pattern-matching scoped too loosely produced false connections | Patterns are suffix-aware but per-item, and every remaining hit is classified by population in STEP 11 | STEPS 2, 11 |
| Rules existed but were psychologically dormant at answer-time | STEP 0's loop re-fires the four questions every five minutes | STEP 0 |
| A run exceeded its cost/time ceiling or hung unbounded | One worker in flight, hard; sweeps scoped to named roots, never the home folder | STEP 0 note, §5 |
| A helper was dispatched on a brief with a wrong or missing constraint | Every step block names its never-touch list explicitly for the worker's brief | §3b fences |
| A claim about the user/system was made without its source | Every count in this plan carries its command; every Nick claim its quote and line | throughout |
| A conclusion was drawn from a partial read | M-2WAY; the programme indexes were read, not just globbed | §1c |
| A fact was quoted as current without its date | Every measurement dated 2026-09-04 | §1c, §0 |
| A computed value never reached the persistent record | Evidence files are written to disk before verdicts are composed | STEPS 2, 11 |
| A missing lookup key fell back silently to a wrong default | N/A-NOBUILD: no lookups or defaults are coded here | — |
| A hardcoded identifier broke when the referent was recreated | Archive paths preserve source-relative structure so old citations map 1:1 | M-ARCH |
| A placeholder or wrong-level path shipped as a literal instruction | Every path in this plan was globbed or read tonight; the plan's own future artifacts are declared in §0 | §3b, §0 |
| A UI reported success while the backend silently failed | Board closes are read back from the board, never trusted from the write receipt | STEP 9.3 |
| Mid-session state was assumed unchanged | Re-read immediately before every write | M-SCOPED |
| Uncertainty was silently absorbed instead of marked | NOT MEASURABLE states are named outcomes in STEPS 6 and 9, never converted to pass/fail | STEPS 6, 9 |
| A serial multi-step operation blew its time budget | Steps are independent where dependencies allow; nothing waits on an unneeded predecessor | §3b entry gates |
| An external action went unlogged and became unrecoverable | Every move is a git commit; every board action read back and pasted | M-SCOPED, STEP 9 |
| A tool's own description contradicted house reality and won | The kill-switch semantics come from MACHINE-RULES, not from any job file's own comments | STEP 6 |
| Personal/identifying data exposed, or a record written to the wrong subject | Nothing here opens or quotes records; archives move whole files unread; the report to Nick names no values | anti-scope |
| One instance of a defect class was fixed while its siblings stayed broken | M-CITE sweeps repo-wide for every moved path, not the first hit | STEP 10 |
| A read operation mutated state | STEPS 2, 11, 12 are declared read-only with empty or evidence-only fences | §3b |
| The three biggest absence-claims variants: empty result, broken probe, discarded stderr | M-2WAY + M-CTRL; `command grep` mandated, bare grep banned | STEPS 2, 6, 11 |
| A generated mirror was hand-edited, or its generator never re-ran | Generated files are never hand-edited; their generators get NEXT-list lines | STEP 10.2 |
| Deployed config silently diverged from source config | N/A-NOBUILD: no deploy occurs; the one deployed surface (school site) is explicitly untouched | §1a row 4 |
| A delivery path was reordered and its notification behavior changed | Jobs are disabled, never reordered; live notification jobs are on the never-touch list | STEP 6 fence |
| A critical boundary was config-editable and could be silently widened | N/A-NOBUILD: no boundary code is touched; the file-protection gates are anti-scope | anti-scope |
| A "growing" archive had actually frozen | The archive here is deliberately frozen history; the retirement note says so plainly | STEP 1 |
| Files were archived but their citations kept pointing at them | M-CITE — this entry is the reason STEP 10 exists | STEP 10 |
| A pipeline broke silently and looked identical to a working one | M-CTRL: the kept-job control distinguishes "switch worked" from "fleet is down" | STEP 6 |
| Output was delivered somewhere the intended reader never looks | Nick's report goes to chat, his surface; the archive note sits where the follower of an old path lands | §2 |
| Concurrent sessions clobbered each other's work in a shared file | M-SCOPED: scoped commits, re-read before write, no stash, fences per live lane | §3, §W |
| An enforcement gate covered fewer paths than its rule, or failed open | The citation sweep is proven able to fail before it is trusted green | STEP 2.4 |
| Identity or authority was read from a value the caller supplies | Authority here is Nick's quoted words in a committed source file, not a relayed claim | §1c |
| A new failure state was detected but reached no human | STEP 12's FAIL routes to fixes AND STEP 13 reports what failed to Nick | STEPS 12–13 |
| The builder graded its own work and passed it | M-COLD; checkers never share a session with executors | §3b |
| A check existed that could not fail | Every PROOF names its FAILS-IF; the sweep runs red first | §3b, STEP 2 |
| The review didn't cover the shipped artifact | STEP 12 walks the LIVE surfaces after the last edit; any later edit re-runs the named failures | STEP 12 |
| A narrowing/refactoring change broke the cases that were already correct | Kept lanes are proven untouched (git status checks in STEP 5; fences everywhere) | STEP 5 proof |
| A check's verdict depended on wall-clock, machine load, or a concurrent writer | The daemon-cycle proof names its window and pairs with a same-window control | STEP 6.2 |
| A test existed but nothing ran it | The sweep script is run inside STEP 10's proof, not merely written | STEP 10 |
| An interactive element or view shipped untested / unseen | N/A-NOBUILD: no UI is built; the one UI-adjacent act (board close) is read back | STEP 9 |
| Coverage was reported optimistically | 30/30 inventory rows and 16/16 measured rows are the denominators; anything less is NOT DONE | FINISH LINE 1 |
| A staleness/freshness check used the wrong proxy | Job-fired checks read the daemon's own run log, not file mtimes | STEP 6.2 |
| A quantitative claim shipped without its method | Every number here carries its command (grep counts, glob counts) | throughout |
| Done was declared before the live surface was checked | STEP 12 is the live-surface walk and gates STEP 13 | §3b |
| A biometric/metric overrode the human's stated reality | N/A: no health content is touched; Nick's felt priorities ARE the spec | — |
| A correlation was asserted as a cause | N/A-NOBUILD: no causal claims are made about systems; failures carry controls | — |
| A recommendation repeated something already tried, uncited | The prior purge ruling (custodian, 08-30) is cited, not re-invented | §1a row 6 |
| A wrong record was disclaimed instead of corrected | Stale index rows are corrected with deltas, not bannered around | M-STATUS |
| Open items were re-typed from memory and drifted | The inventory lives in one committed table; steps cite rows, never re-list them | §1c |
| A deliverable was referenced instead of delivered | Nick's report contains the substance itself, zero pointers | STEP 13 |
| A report used names/shorthand only the writer understood | STEP 13's proof fails on an unexplained codename | STEP 13 |
| Commands were sent to a surface that can't run them | Nick's report carries no commands; commands live in this plan for agents | STEP 13 |
| A number was published without the population it was counted over | STEP 11 names each remainder's population (history/archive/parked) | STEP 11 |
| A finding existed only in the session's output and died with it | Evidence files hit disk before any verdict is composed | STEPS 2, 11 |
| The plan named a target with total precision, and the target was wrong | The SURFACE row is V1, settled by Nick's own words about what agents get lost in | §1a row 1 |
| The human approved a summary, and the summary was silent on the deciding variable | The sheet is generated from §1a, which carries the purge-vs-archive and Gracie/Neeko variables explicitly | §1a |
| A project stated its scope and never its anti-scope, and lanes leaked into adjacent work | Six-entry anti-scope, security first | §1 |
| A new rule was written as prose inside its own fix, with nothing enforcing it | The dispositions are enforced by moves/frontmatter/deltas — mechanisms, not sentences | §3b |
| A blocker common to every lane was carved out of all of them and given to nobody | Everything carved out names an owner: fleet→SMP-8, board-PM→Hub, REBUILD leftovers→SMP | §1c FOLD/HANDOFF rows |
| Lanes were built to stop: one pass, land, idle — while fixed ceremony ate the context | Steps carry continuation (next unblocked step) and the loop re-aims every 5 minutes | STEP 0, if-it-fails lines |
| A caveat nobody measured travelled as fact through multiple independent lanes | Every load-bearing count carries its re-measuring command | §1c, Already-true |
| The environment destroyed work silently, and the lane wrote a wrong lesson from it | M-SCOPED; "my change did not stick" is the first diagnosis on any vanished edit | §3, §W |
| A specification described ONE lifecycle in several places, and the copies drifted | Dispositions are defined once in §1c; steps cite rows | §1c |
| A task brief was treated as the plan, and a status checklist as the task list | This plan is the single governing file; the state file is state only | header rule |
| A red-proof failed for a reason unrelated to what it claimed to prove | The sweep's red run is against the real pre-move tree — the exact condition it detects | STEP 2.4 |
| A standing cheap-routing instruction eroded into doing the work directly | Executors are named cheap per step; the loop's question 3 re-checks every 5 minutes | §3b, STEP 0 |
| A plan's second line named a different authority nobody opened | The authorities (REGROUP-SOURCE, MACHINE-RULES, the skill) were read tonight, cited by section | §0 |
| A live bug got three confident wrong diagnoses, two claiming live verification | Failure branches name what distinguishes the hypotheses (STEP 8's control probes) | STEP 8 |
| Fourteen guards stayed green while the live screen showed the wrong thing | STEP 12 reads the surfaces a real agent reads, not this plan's own receipts | STEP 12 |
| An agent was accused of fabrication because a narrow search missed its file | M-2WAY before any "this is unreferenced" conclusion | STEPS 2, 11 |
| A tool's failure verdict was believed without checking the disk | Board and MCP results are read back from the destination, not the tool's message | STEPS 8, 9 |
| A monolithic build too large for one agent | §1b: genuinely single; steps are one-worker-sized with explicit fences | §1b, §3b |
| A rule with no template slot and no machine gate behaved as if it didn't exist | This plan passes the plan gate before execution starts | FINISH LINE 5 |
| A row-quality check counted cells instead of named columns | N/A: no new checker is built; existing gates are used as-is | — |
| Three readers reported wildly different "% complete" | Completion is the FINISH LINE's five items; no free-hand percentage is quoted | FINISH LINE |
| A V2 confirmation opened the WRONG PATH — the plan's own stated location | STEP 2's METHOD-B is a fresh structural search, never opening only the asserted path | STEP 2 |
| A shared coordination file had no per-subproject write fence | HEARTBEAT/ACTIVE-WORK edits are fenced to the retired items' own rows | STEP 9 fence |
| The cheapest decisive test was defined but not RUN early | The citation sweep and refcounts run BEFORE any move | STEP 2 |
| A build agent reported interim status as its FINAL answer | Worker briefs state: one-shot, foreground, "in progress" is not a final answer | §3 contracts |
| A sandbox error was misread as a known machine problem | N/A: no sandboxed browser/build tooling is used; moves are plain file operations | — |
| A mandated tool hit quota and the fallback was improvised | The vendor fallback (haiku grunt) is pre-written into every executor cell | §3, §3b |
| A creation reported success but did not exist on live re-query | Board writes re-queried fresh; git moves verified by listing the destination | STEPS 4, 9 |
| Three wiring gaps invisible to every automated layer | N/A-NOBUILD: no feature wiring; the one integration claim (engines still answer) is probed live | STEP 8 |
| A deployed fix never reached an open browser tab (cache-bust missed) | N/A-NOBUILD: no cache-busted asset is edited; the school site is untouched | anti-scope |
| A correct design decision was mistaken for a bug from ONE identity's view | N/A: no visibility claims across identities are made | — |
| The Updates panel read from a store the write never fed | Read-back-from-destination is the standard for every write here | STEPS 8, 9 |
| A pure QA dispatch was refused twice by the work-type gate | Dispatch headers follow §T verbatim, roles from the closed list | §3 |
| A brief was refused for missing the travel block, with no template to copy | The travel block is pasted into every brief from MACHINE-RULES' own TRAVEL BLOCK | §3 |
| A fix was left syntactically valid but unverified when its tool hit a cap | Every step's proof runs after the edit, by a different session | §3b |
| A failure found only because a fresh pass re-ran the real test | STEP 12 is exactly that fresh pass, mandatory | STEP 12 |
| A data fix applied to ONE of two live copies | STEP 2's METHOD-B catches sibling copies (worktrees excluded by name, counted honestly) | STEP 2 |
| A regression suite silently crashing since a dependency change | The sweep is re-proven red/green inside this drive, not inherited | STEPS 2, 10 |
| Two bodies of work never committed to git anywhere | Every step ends in a scoped commit; the plan itself is committed before execution | §3 |
| A deepening request answered by re-polishing instead of opening sources | The coordinator's two added sources (REGROUP-SOURCE, skill §W/§Z) were opened and cited | §0 |
| A gate covered Write/Edit but not Bash | N/A: no new gate is built | — |
| A parameter default made a branch unreachable under green tests | N/A-NOBUILD | — |
| An atomic write lost a concurrent writer's appended row | Append-only files (HEARTBEAT) are edited by row, re-read first, never rewritten whole | STEP 9 |
| A red-proof claimed without removing the fix and running | The sweep's red run is executed and recorded, not claimed | STEP 2.4 |
| Test files wrote into the REAL production log | N/A: no test harness is written; probes are read-only | — |
| An identity re-derived from a writable file instead of live auth | N/A: no identity code is touched | — |
| A daemon-wide crash handler met an uncaught promise | N/A: no daemon code is touched — frontmatter only, by fence | STEP 6 fence |
| A supersession quietly dropped functionality with no home in the new shape | Every FOLD names precisely what moves and what stays (gates run on, tools run on) | §1c |
| fs.watch assumed a sufficient trigger under concurrent load | N/A: nothing here relies on file-watch delivery | — |
| A plan asserted repo facts it never checked | Every fenced path was globbed/read tonight; §0 lists them | §0 |
| The program fixed what was BROKEN instead of building what was ASKED | The loop's question 1 and the anti-scope's no-repairing-retired-work entry | STEP 0, anti-scope |
| A plan passed every gate and still could not deliver the ask | The FINISH LINE is phrased in Nick's outcome (can't get lost), not in gate outputs | North Star |
| An assistant's account of its own failure was taken as root cause | STEP 12's walker reports what IT saw, not what executors reported | STEP 12 |
| Three verifications real, all three the wrong SCOPE | The cold walk verifies the THING (surfaces), the sweep the CITATIONS, the counts the MENTIONS — scopes named | STEPS 10–12 |
| An orchestrator's confident relay propagated a wrong conclusion | STEP 12's verdict is relayed UNCHANGED; workers may refuse steps contradicting what they see | STEP 12 |
| One writer read a handoff as a gate and serialized behind it | Entry conditions name the specific artifact, never "previous step done" (STEPS 1/2 explicitly independent) | §3b |
| Every failure mode of the file-approval machinery was silent | STEP 3's if-it-fails: work continues ungoverned-side, ask lands with Nick awake — never a stalled ticket | STEP 3 |
| A governance CLI silently dropped flags and its spec documented the broken form | N/A: no CLI is built; existing tools used by their documented verbs | — |
| Plan shape existed as convention, not enforcement | This file passes the machine gate before execution starts | FINISH LINE 5 |
| A six-word punchlist item pointed at exactly the wrong action | Dispositions carry Nick's full clause, never a compressed label | §1c |
| A production secret read as SET when EMPTY | N/A: no secrets are read or written; data floor untouched | — |
| The SAME claim CONFIRMED by a verifier and REFUTED by a breaker — breaker right | STEP 12's brief is adversarial ("try to get lost"), not confirmatory | STEP 12 |
| Reasoning ABOUT a system instead of ASKING it | Live probes (daemon log, MCP answers, board read-back) over inference, throughout | STEPS 6, 8, 9 |
| A hard prerequisite discovered after a decision, with no owner | Dependency lines are written per row BEFORE moves; hits change dispositions via dated deltas | STEP 2.3 |
| A relayed instruction judged only by authenticity, not currency | Nick's 09-04 words are checked against his 08-30 ruling and the later governs, on the sheet | §1a row 6 |
| Two programs found every instrument reporting a state that was not the system's | M-CTRL on every silence; M-COLD on the whole | STEPS 6, 12 |
| A PROOF block still containing template placeholders | Every proof here names literal files, counts and commands; checker re-runs them | §3b |
| Evidence deliberately destroyed is indistinguishable from evidence that never existed | Nothing is destroyed; moves preserve bytes; evidence files are committed | M-ARCH |
| A capability ruled impossible on a query that could not see the answer | M-2WAY exists precisely for this; unreadable stores are UNKNOWN, never empty | §Z, STEPS 2, 11 |
| The instruments used to verify a UI lie in four ways | N/A: the one UI check (board) is a read-back, its instrument named | STEP 9 |
| A step's entry gate satisfied and the step still could not run, with nowhere to say so | The state file carries a RUNNABILITY line per step; if-it-fails branches name the honest states | §3b |
| An automated proof detected failure and the pipeline logged success | Proofs are re-run by checkers reading exit codes themselves, never a wrapper's summary | §3b checker jobs |
| A dispatch gate blocked the defensive pattern its own line prescribed | Known gate quirks are pre-empted by the verbatim §T header on every brief | §3 |
| A fallback made the cutover it protected impossible | N/A: no cutover; the only fallback (haiku) does the same file moves | — |
| An approved instruction correct at approval, harmful at delivery | Each move re-reads live state at execution time; STEP 2 evidence goes stale if the tree moved — the row re-runs | STEPS 2–11 |
| "Fixed the file" / "deployed it" / "user sees it" are three claims | The three scopes are separately proven: files (moves), surfaces (STEP 12), Nick (STEP 13) | STEPS 4–13 |
| Working-tree code read as established behaviour in a multi-session build | Dispositions cite committed sources; uncommitted concurrent edits are §W-handled | §W, §3 |
| Three rounds of honest proofs, user's complaint untouched | STEP 12's bar IS Nick's sentence ("no way to get lost"), verbatim | STEP 12 |
| A local caution escalated into a fleet-wide halt on a non-crisis | Findings get ONE owner line or the NEXT list, never a re-route of other lanes | trip-over protocol |
| Two landed pieces reported missing because no inbox message arrived | Landings are read from files and surfaces, not from message receipt | STEPS 9–12 |
| An acknowledgement (`queued`) read as the outcome | Read-back-from-destination standard | STEPS 8, 9 |
| An overseer bridged a DIFFERENT ruling onto the question | The one bridged ruling here (custodian purge) is surfaced to Nick rather than silently bridged | §1a row 6 |
| An agent offered loosening a guard as one of two equal options | Nothing proposes weakening any gate; refusals route to the state file + Nick | anti-scope |
| A fault that repairs itself faster than reports is invisible to alarms | The daemon-window proof names its window; intermittency routes to SMP-8, the fleet's owner | STEP 6 |
| A relayed approval acted on as if work were outstanding | STEP 9 checks whether a card's work already landed before closing it as retired | STEP 9 |
| An investigator noticed the metric could not detect the thing, and used it anyway | Counts are never the verdict; the cold walk is | STEPS 11–12 |
| An investigation's own searches contaminated the evidence | Before/after counts use identical patterns and scopes; this plan's own files are a named, subtracted population | STEP 11 |
| Three lanes each got a clean answer from a point-in-time probe of an intermittent fault | The job-silence claim is bounded to its window and paired with a control, never generalized | STEP 6 |
| An overseer relayed genuine instructions as authority — one session rightly refused | Workers verify against this committed plan and REGROUP-SOURCE, not the dispatcher's say-so | §3 |
| A file documenting its version history above its code made unanchored searches lie | Banners state RETIRED at the very top; archive files carry no live-instruction text below | STEP 4.1 |
| A commit hash cited as closing evidence resolved to nothing later | Proofs cite re-runnable commands and paths, never bare hashes; any hash cited must be reachable AND pushed at citation time | §3b proofs |
| A step's own PROOF COMMAND over-matched and returned a plausible wrong count | Grep-count proofs pin exact literal strings (e.g. "disabled: 2026-09-04 goal-purge") and name FAILS-IF | §3b |
| A deliberate commit pre-empted by an automatic snapshot bundling unrelated files | Scoped commits immediately after each edit batch, message naming the change; mixed-commit legibility rule from §W | M-SCOPED |
| NOVEL: a lane was retired while something live still depended on it | STEP 2.3's DEPENDENCY line per row gates every move; a kept-surface hit converts RETIRE→FOLD via a dated delta, and STEP 8's live probes catch what the search missed | STEPS 2, 8 |
| NOVEL: a git-move landed while a concurrent session held uncommitted edits to that file | Per-file `git status --porcelain` immediately before each mv; dirty → wait one pass and retry; §W scoped-commit discipline throughout | STEP 4.1, §W |
## 5 · Topology and roles
- **OVERSEER-AUTHORITY:** no seat is named — `projects/ops/OVERSEER-AUTHORITY.md`'s CURRENT HOLDER block reads "2026-08-28: NO SEAT IS NAMED. THIS GRANT IS DORMANT" (read 2026-09-04); this plan's lanes work as if the file did not exist. The four approval classes and the data floor never move on anyone's word regardless.
- Thread layout: one driving thread (this Boris seat), workers dispatched one at a time.
- Overseer: Boris 3 (fable) — unsticks, relays verdicts unchanged, never builds. Lane managers: none (single subproject). Workers: GLM 5.3 (zai) with haiku-tier grunt fallback; checkers Sonnet; cold walk Sonnet fresh.
- State files location: `projects/ops/retirement/STATE.md` and `projects/ops/retirement/PLAN-CHANGES.md` (both declared in §0's created-artifacts list).
- **Board card id:** none yet
- **Artefact consumers:** archive → any future agent following an old path; evidence files → the checkers and STEP 12; deltas → agents reading the indexes; report → Nick. Raise path: `raise-signal` per MACHINE-RULES if genuinely stuck, proven by its own printed row.
- **Write-contention:** L1 owns the indexes and archive moves; L2 owns only job frontmatter; L3 owns pointer rows and evidence. No two lanes share a file. This plan touches NOTHING under `projects/business/business-app/` and, inside `projects/personal/skippy-app/`, exactly one file (the Alexa spec move) — the live Skippy/Hub lanes keep exclusive write on their roots. Checkout proven writable per pass: probe write, read-back, scoped status.
**Per-stage topology — counts DECLARED at plan time:**
| Stage | Overseer | Sub-overseers | Workers |
|---|---|---|---|
| Framing (STEPS 1–2) | 1 | 0 | 1 |
| Elements (STEPS 3–8) | 1 | 0 | 1 |
| Details (STEPS 9–10) | 1 | 0 | 1 |
| Tests/Proof (STEPS 11–12) | 1 | 0 | 1 |
| Output (STEPS 13–14) | 1 | 0 | 0 |
**The walk-away contract:**
- **STATE FILE:** `projects/ops/retirement/STATE.md`
- **HEARTBEAT ROW:** the goal-purge drive row in `projects/personal/skippy-app/ala-state/work-threads.json`, created when the drive registers
- **MORNING-REPORT LINE:** "Goal purge — N of 14 steps proven; retired X of 30 inventory rows; blocked on: <none or named>" in `projects/ops/walkaway/REPORT.md`
## 6 · Evals — what "working" means, decided now
| Capability | Check (exact command or procedure) | Pass looks like |
|---|---|---|
| Every inventory row reaches an executed disposition | count proven rows in `## STEPS` against §1c's 30 | 30/30, each citing its step's proof |
| Nothing deleted | `git log --diff-filter=D --oneline` over this plan's commits | zero deletions outside git-mv pairs (a move shows delete+add with identical content) |
| Retired jobs silent, kept job alive | STEP 6's paired window evidence | disabled: no run; control: fresh run; same window |
| Live engines unharmed | STEP 8's two MCP probes | both return real answers post-move |
| No live pointer to retired work | STEP 12 cold-walk verdict | PASS, verbatim, from a session that built nothing |
| Citations all repointed | `bash projects/ops/retirement/evidence/citation-sweep.sh` | exit 0, after a recorded red run pre-move |
| This plan passes its gate | `python3 projects/ops/agents/check_plan.py` against this file (run from the repo root, target `PLAN.md` in `projects/ops/retirement/`) | PASS |
## NEXT list (found along the way; NOT worked in this drive)
- Regenerate the agent org chart / capability pages after pointer changes, via their own generators (owner: the directory pages' generator, one run).
- If Nick ever wants the Skippy School site taken down, it is one deliberate command through the deploy tool — his word first (§1a row 4).
- The `projects/ops/REBUILD-2026-08-21/` leftover tree: SMP's own archive manifest finishes it (handoff posted in STEP 5).
- Anything security-shaped observed during the sweep: one line here, click-gate first.
## If you get stuck (all steps)
Before writing "blocked": (1) try a concrete workaround, (2) re-read the step's proof requirements — most "stuck" is a misread gate, (3) write one line to the overseer AND the owner of the blocker. Only then log `STEP <N> BLOCKED — tried: <a>,<b>,<c>. Need: <one sentence>.` Then keep working every other unblocked step. Never idle on a blocker.
## Your loop
Every pass: find the lowest-numbered step whose enter gate is proven and which is not yet proven → do it → produce its proof → paste the proof under the matching item in STEPS below → repeat.
## SUMMARY — a few plain-English lines, read by the status generator
Nick asked for one thing: only Skippy, its voice app, and the business Hub stay live; everything else gets put away safely so nobody wanders into it again. This plan lists all thirty pieces of side work by name, says exactly where each one goes, moves the retired paperwork into one dated archive with a plain note explaining how to bring things back, switches off the robots that were still working on dropped projects (reversibly, with proof they stopped and proof the live ones did not), and finishes with a stranger checking that nothing retired still looks alive. Nothing is deleted; Chantelle's reminders, the kids' site, and the memory system keep running untouched.
## STEPS
1. Archive home + retirement note — 0%
DEFINITION OF DONE: the retirement note exists with resume instructions for Gracie, Neeko, family app
PROOF: `ls projects/_archive/goal-purge-2026-09-04/`
2. Two-way re-verification of every RETIRE/DISABLE row — 0%
DEFINITION OF DONE: before-counts cover all 16 rows both ways; sweep script proven red
PROOF: `command grep -c "METHOD-A" projects/ops/retirement/evidence/refcounts-before.txt`
3. ZION index dated dispositions — 0%
DEFINITION OF DONE: 12 dated deltas, no stage deleted, two handoff lines posted
PROOF: `command grep -c "2026-09-04" projects/ops/zion/PLAN-ZION-PROGRAMME.md`
4. Retired ZION lane files moved to archive — 0%
DEFINITION OF DONE: nine lanes' files under the archive with banners; kept lanes untouched
PROOF: `ls projects/_archive/goal-purge-2026-09-04/projects/ops/zion/`
5. SMP deltas + Alexa spec archived + handoffs — 0%
DEFINITION OF DONE: SMP-2 PARKED, SMP-9 RETIRED, Alexa spec moved, learning-app root untouched
PROOF: `command grep -c "PARKED\|RETIRED" projects/ops/skippy-master-plan/PLAN-SMP-PROGRAMME.md`
6. Retired-capability jobs disabled with control — 0%
DEFINITION OF DONE: frontmatter on all named jobs; kept-job control fired in same window
PROOF: `command grep -l "disabled: 2026-09-04 goal-purge" projects/ops/skippy-jobs/jobs/sp13-quality-report.mjs`
7. Assistants dev docs archived RESUMABLE — 0%
DEFINITION OF DONE: THE-ASSISTANTS + assistants-replan in archive; Chantelle's live jobs untouched
PROOF: `ls projects/_archive/goal-purge-2026-09-04/projects/ops/`
8. OpenBrain-delivery + quality-tracking docs archived; store proven live — 0%
DEFINITION OF DONE: folders moved; both MCP engines answer post-move
PROOF: `ls projects/_archive/goal-purge-2026-09-04/projects/ops/`
9. Live pointers purged (canon, heartbeat, board) — 0%
DEFINITION OF DONE: retired rows read RETIRED; fresh board read shows zero open retired cards
PROOF: `command grep -ci "RETIRED 2026-09-04" ACTIVE-WORK.md`
10. Citation sweep green after red — 0%
DEFINITION OF DONE: sweep exits 0, byte-identical to STEP 2's committed version
PROOF: `bash projects/ops/retirement/evidence/citation-sweep.sh`
11. After-counts, populations named — 0%
DEFINITION OF DONE: after-counts complete, every remainder classified
PROOF: `command grep -c "METHOD-A" projects/ops/retirement/evidence/refcounts-after.txt`
12. Cold walk verdict — 0%
DEFINITION OF DONE: fresh session's verdict pasted verbatim under the words COLD WALK VERDICT, or its FAILs fixed and re-walked on the named routes only
PROOF: verdict text under this item
13. Plain-English report to Nick — 0%
DEFINITION OF DONE: three labelled blocks, zero jargon, WHAT'S-WAITING block present
PROOF: REPORT SENT line in the state file
14. Postmortem written into this file — 0%
DEFINITION OF DONE: POSTMORTEM section exists; registry appended only if a new pattern earned it
PROOF: `command grep -c "POSTMORTEM" PLAN.md` run from this plan's own folder
# STATE — Retire and archive everything outside the two goals · created 2026-09-04 ## Current state (rewritten in place — this section only, never appended) **Plan written and cold-reviewed; lane not yet open.** Nothing has been moved, archived or switched off. The plan is `PLAN.md` beside this file, and the inventory it rests on is inside it as §1c — one governing file, per the house rule. A cold cross-plan review on 2026-09-04 read it alongside the Skippy and Hub plans and returned two blocking findings, both now fixed. **What the review corrected here:** 1. **The plan did not know the Hub plan existed.** Its inventory still recorded the old Kanban lane as "the Hub build", but that lane's own file now opens with a marker saying it was superseded on 2026-09-04. One of the steps would have posted a handoff into a file nobody reads. The inventory now carries the real Hub plan as its own KEEP row, and Hub-bound handoffs go to the Hub lane's state file. 2. **A genuine retirement collision, the highest-consequence class.** This plan was going to archive the board-enforcement lane's two documents once their handoff was posted. The Hub plan's STEP 9 *writes into both of those files* and reads an evidence file beside them. Moving them mid-drive would silently break a step in a live plan. **Those files now stay exactly where they are** until the Hub plan closes; the fold is recorded as an index status change only. Nothing in this drive owns the later move, and that is deliberate rather than an omission. ## The scope, settled Nick asked for everything outside Skippy, the voice app and the Hub to be purged and archived. Those two words pull opposite ways, and the measurement settled it: the word "gracie" alone appears in roughly 42,968 places across 6,280 files, so purging every mention would destroy the record. **The resolution is archive the work, purge only the live pointers** — which is also what the standing rules require, since deleting is one of the four things only Nick may authorise. **There is not a single delete anywhere in the plan.** Verified 2026-09-04: no removal commands at all; work moves by a command that preserves full history, and every switch-off is reversible. ## Inventory outcome (detail in the plan's §1c) 30 items measured. Nine lanes retired and archived, three folded into work that continues, the security pass deferred behind Nick's approval click, Skippy School retired, the family app parked rather than retired, Gracie and Neeko archived resumable. Kept: the Hub lanes, the approval system now serving as the security gate, team commit access, the one-cloud-copy work, Google sign-in, and all the Skippy channels. ## Live things the retirement is fenced away from — confirmed still depended upon | Thing | Why it must not move | |---|---| | The routing tools every dispatch uses | Only the *lane* retires; the tools stay in service | | The memory store behind the personal and business assistants | Live behind both front doors; probed after the doc move, reverted on any degradation | | Chantelle's live reminder jobs | Never touched — explicitly out of scope | | The kids' deployed site | Keeps serving them even though its lane retires | | The board-enforcement lane's files | The Hub plan writes into them — see finding 2 above | ## Who is driving this - **Overseer session:** the retirement Fable overseer thread (topology in the plan's §5). - **Lanes re-read this file:** at the start of every step. - **Unowned-blocker owner:** the overseer. ## Questions (open → answered, in place) - Two judgment calls ride the plan's confirmation sheet for a one-word overrule rather than blocking: the kids' site staying deployed, and whether Nick's 2026-09-04 order supersedes an earlier ruling that purging belonged to a different agent. ## Contract-change log - 2026-09-04 — inventory gained the Hub plan as a KEEP row; board-enforcement files removed from every move step for the duration of the Hub drive. Per the cross-plan cold review.