HUB: Project Management - Board, screens and plans in step

The actual documents the agents read and work from, shown exactly as they are on disk — not a summary. See the progress view instead · All projects

Plan PLAN.proposed.txt

# PLAN — AGENT PROJECT MANAGEMENT — agents that run their own projects, on a board Nick can read (2026-09-09 shape)

Plain name: Agent project management — agents that run their own projects, on a board you can read
What this is for you: Every agent project shows up as one card on your board and one page like this, kept current by the agents themselves.

Owner: the Group H overseer. Written 2026-09-09 by Boris (Opus) as the lane's first plan, from the programme plan's §1b Group H row and §3d list and from Nick's rulings of the same day: "part of the hub project was to get agents managing their own projects flawlessly - i think that needs to be its own thing now". There is no earlier plan for this lane; every fact under Already true was measured tonight by the command beside it.

**🔴🔴 THIS IS THE ONLY PLANNING DOCUMENT FOR THIS LANE. Do not create a second plan, tracker, summary, or scratch state file — extend THIS file or its PROGRESS.txt companion. Any status view is GENERATED from this plan; if a view disagrees with the plan, the plan wins.**

**NORTH STAR:** Nick opens the AI build board and sees one card per real project, each with a short name a person would use, nothing stale and nothing doubled; and every agent, before it ever comes to him, has already brought its card, its progress screen and its plan up to date and dropped the screen's link in the chat, so he can check any project himself without asking anybody.

**FINISH LINE:** each item passes its one check, run first-hand by the step's checker — (a) the live board's build group holds exactly one active card per plan folder that has a plan in it, every card named in plain human words with no programme prefix and no category word in front, zero duplicates by name; (b) every stale card is superseded in place, reversibly, and none is deleted or marked complete; (c) each card's due date is the date its own plan names as its finish line, and any card whose plan names no date is listed by name in the run's own output rather than given an invented one; (d) the one shared update command knows every live plan, and still refuses a plan it does not know instead of posting anywhere else; (e) one run of that command moves the card, the screen and the plan together and proves the screen's file actually changed; (f) every live lane's builder prompt carries that one command in its runnable form; (g) the nightly check that already runs four times a day reads every live lane and prints AGREE, or names the project and which of the three disagrees; (h) the naming rule exists as one numbered rule in one file and nowhere else. Written once, never raised mid-drive. Finish-line date: 2026-09-12.

**Owner:** the Group H overseer · **Overseer:** ONE — Opus or Codex `gpt-6-astra` (Fable if it holds the thread); never builds · **Design authority:** none — nothing new is drawn
**Rule: a step starts the moment its named inputs exist, whatever its number. A step closes on ONE independent check by a different model. Nothing waits on Nick to test.**

### STEP 0 — ARM THE LOOP, BEFORE ANYTHING ELSE
Set a 5-minute loop. Every time it fires, answer these four in order and CORRECT any failure before doing anything else:
1. **NORTH STAR** — is what I am doing this minute moving this plan's North Star? If not, drop it and take the highest-value unblocked step that does.
2. **FAN-OUT** — is every step whose START WHEN inputs exist running, up to the cap of 8? Below the cap with ready work: dispatch now. At the cap: queue, never launch.
3. **CHEAP** — is every build and every check on a cheap model by name? A refusal from the router is a failure to log (Nick, 2026-09-09), never a reason to promote the job to Sonnet or Fable; a cheap vendor failure goes to the named backup.
4. **BLOCKED** — is anything "waiting"? Re-read its START WHEN line; if the artefact exists, start it; if it truly does not, one line to the overseer naming the ONE missing thing, and on to the next step.

**Evidence:** each firing appends its four answers and saves `evidence/step0-loop-passes.txt`. Every step below names one artefact it saves in the same way, because the close-out gate counts a step that promises no artefact as one whose completion nothing could ever contradict — and it counts this loop as a step.

## Already true (facts, not story)

- The board's build group holds 33 active cards, 28 of them named with the programme prefix Nick wants gone, and not one of them superseded yet — measured 2026-09-09 by reading the live board as the robot bearer and counting: `ai-builds cards: 33 | named Life OS...: 28 | already superseded: 0 | total cards all groups: 255`; evidence: `projects/ops/life-os/REGROUP-2026-09-08/plans/PROJECT-MANAGEMENT/CHECK.txt`
- DECIDED, not yet built: sixteen plan folders each hold a plan — counted 2026-09-09, and the count MOVED from twelve to sixteen during this planning session as the other lane planners installed theirs. That is why every step derives the expected set of cards by listing the folders at run time and never from a list written here; a fixed list would have been wrong within the hour. Evidence: `projects/ops/life-os/REGROUP-2026-09-08/plans/HUB/PLAN.proposed.txt` and the fifteen sibling folders beside it
- The screen titles carry the same prefix from a second place, not from the board: twelve rows of the status registry are named with it — measured 2026-09-09, `command grep -c '"name": "Life OS' projects/ops/artifacts/project-status/registry.json` printed 12 against 34 rows in the file
- Fourteen of the sixteen lane plans have no title block of their own, so their screen takes its title from that registry row; two write their own — measured 2026-09-09, `command grep -l "^## FOR NICK" projects/ops/life-os/REGROUP-2026-09-08/plans/*/PLAN.proposed.txt` returned the scheduled-tasks and health plans only
- Those fourteen screens therefore show no goal line at all: the screen builder reads a plan's goal only out of that title block, so with no block the goal is empty and the title falls back to the registry row's name — opened `projects/ops/status-regen.mjs` 2026-09-09, saw the title and the goal both read out of that one section at lines 147-157. The fix for another lane's plan text is one handover line to that lane, never an edit from here.
- Four of the sixteen folders have no registry row at all, so the registry describes twelve projects where sixteen now exist — the gap STEP 2 closes, and the reason a card can exist for a project whose screen cannot yet be built
- The same ten screens therefore show no goal line at all: the screen builder reads a plan's goal only out of that title block, so with no block the goal is empty and the title falls back to the registry name — opened `projects/ops/status-regen.mjs` 2026-09-09, saw the title and goal both read out of that one section at lines 147-157. The fix for another lane's plan text is one handover line to that lane, never an edit from here.
- The one shared update command ALREADY refuses a plan the board does not know, before it writes or posts anything — opened `projects/ops/skippy-jobs/lib/unified-project-update.mjs` 2026-09-09, saw the refusal at lines 381-390 returning `REFUSED — this plan file is not registered in projects/ops/artifacts/project-status/registry.json`; and `node --check` on that file exits 0. What is missing is the registration of the new lanes, not the refusal.
- That command already does all three things in one action and proves the screen's file changed rather than assuming it — opened the same file, saw the board post run before any disk write and the screen regeneration checked by real file timestamps at lines 344-369
- The board has no delete and never has: the tasks door offers create, complete, edit, supersede and a one-card alias for supersede, and superseding adds ONE field that a reader's view honours, leaving the row and its history reachable by id — opened `projects/business/business-app/app/functions/api/tasks.js` 2026-09-09, saw `No deletes, ever (archive/supersede only, standing rule). DELETE/PUT/PATCH → 405` and the supersede contract at lines 1641-1655. Renaming a card is the `edit` action's own `name` field, lines 2317-2321.
- A check that asks whether a project's own documents are telling the truth ALREADY exists and ALREADY runs four times a day, with five detectors and its own guard — `projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs`, scheduled at 03:57, 09:57, 15:57 and 21:57 in `projects/ops/skippy-jobs/runner.mjs` line 346, pure detectors in `projects/ops/skippy-jobs/lib/pm-currency.mjs`. It is EXTENDED by this lane, never copied.
- That check is not clean today: `node projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs --verify-clear` exited 1 on 2026-09-09, which is the honest red reading this lane's own check is measured against
- A helper that would undo a rename lives on one Mac only, outside the cloud copy: `/Users/nickdeck/Documents/life-os-launch/board-cards.mjs`, 7,684 bytes, 2026-09-09 15:44. Opened 2026-09-09: it matches a card by EXACT OLD TITLE (`(t.name || "").trim() === c.title`) against 23 hardcoded titles that all begin with the programme prefix, and its card map lives beside it on the same Mac. Run again after a rename, on either machine, it creates a fresh duplicate for every lane it cannot match. No copy of it stands in the working tree today, but a copy WAS committed once under a launch folder and lives in history, so it can be brought back by anyone who looks — which is why STEP 1 retires it rather than only deleting it. That correction matters: the first version of this record claimed it had never been in version control at all, which a checker disproved.
- Nick's rulings on file, never asked again: every project's name on the board and on its screen reads CATEGORY: Project - Task — a short capital category code, a colon, the project in plain words, a dash, the task in plain words — Nick, 2026-09-09: "we need a naming convention that designates CATEGORY:PROJECT-TASK — HUB for hub, FA for family app, AGENTS or those edits etc. SO... HUB: Project Management - Final Reinforcement · FA: Redesign - Design Home Screen · SKILLS: Rewrites - /plan updates · stuff like that we can refine over time"; the earlier "no category words" wording is replaced by this ruling, which came later the same day; every agent updates its task card, its progress screen and its plan at every stopping point, before it reports (2026-09-09); the progress-screen link goes in the chat thread (2026-09-09); the board gets cleaned up (2026-09-09); a ruling is written once as one numbered rule and nowhere else (RULE 21, 2026-09-09); the cloud copy on the main line is the only record and no machine is ever a second copy (RULE 20, 2026-09-09)

## 0 · Gate Zero receipts (the plan may not exist without these)
- Failure Mode Registry loaded: 2026-09-09, 211 table rows counted by `command grep -c '^| ' ZION/skills/plan/references/failure-registry.md`; the eight this lane is exposed to are in §4
- Canonical specs loaded: the plan skill (2026-09-09 shape) and its template, `projects/ops/life-os/REGROUP-2026-09-08/PROGRESS-SCREEN-STANDARD.txt` (the screen standard Nick set on 2026-09-08), `projects/ops/MACHINE-RULES.md` (RULE 20, RULE 21 and the closing-message format), `projects/ops/agents/CODE-STANDARD.md`
- Ownership check: no plan exists for this lane; `projects/ops/life-os/PLAN-LIFE-OS-2026-09-09.md` §1b Group H reads "not yet written — a PROJECT-MANAGEMENT folder beside the other lane plans", and this file is it. The three things this lane could have duplicated already exist and are extended in place: the one update command, the four-times-a-day currency watch, and the status registry.
- Expected inputs confirmed to exist: `projects/ops/skippy-jobs/lib/unified-project-update.mjs` (opened), `projects/ops/skippy-jobs/lib/board-report.mjs` (run; it refuses without `--run-by`, which is how it names who wrote what), `projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs` (run with `--verify-clear`, exit 1), `projects/ops/status-regen.mjs` (run with no arguments, exit 2 and its usage line), `projects/ops/artifacts/project-status/registry.json` (opened, 34 rows), `projects/ops/project-status-page.py` (on disk), the twelve lane plan folders (listed)
- PLAN AUTHOR: Boris, the senior engineer, the Opus session of 2026-09-09
- COLD READER: none — SINGLE-AUTHOR, UNREVIEWED. The Group H overseer's pickup read is the one cold read; nothing here is rendered, so §D's cold-read requirement for a visual plan does not apply.
- PROMPT-SPEC scan (P1–P7): P1 fired on "clean up the ai build board" — read as one active card per plan folder with a plan in it, stale cards superseded and reversible, never deleted, because the board door has no delete at all. P1 fired again on "a code system for groups" — his own words "simple, clear, not important" are read as: no code inside a name; the group letter stays in the plan, and §7 carries the question with that default. P3 fired on the brief's record that the update command broadcasts to unrelated cards — re-measured tonight and found already refused in code, so the step is registration, not a repair. P2 fired on "update the plans" — read as the plan's own step line written by the one command, in the shape the screen generator parses, never a hand edit.

## 1 · Goal and definition of done
- **What we're building, one paragraph.** The project board Nick reads, and the habit behind it. One card per real project, named the way a person would name it, with nothing stale and nothing doubled; the machine-only helper that would quietly undo that removed from the Mac and preserved in the cloud copy first; every live plan known to the single command that updates a card, a screen and a plan together, so an agent can follow the rule instead of improvising; that command's runnable form written into every lane's builder prompt with the screen link going into the chat; and the check that already runs four times a day taught to read every live lane and say AGREE or name what disagrees.
- **HOW IT'S USED:** Nick opens the board when he wants to know where a project stands, and clicks a progress-screen link an agent dropped in the chat when he wants the detail. Agents use the one command at every stopping point, before they write him anything. · HOW WE KNOW: Nick, 2026-09-09, "we need to clean up the ai build board", "agents to update the progress screen and tasks cards and plans on every turn", "link the screen in the chat thread".
- **WHAT IT LOOKS LIKE:** the existing board and the existing progress screens, unchanged in layout — only the names on them change, and one new line in the nightly findings. · HOW WE KNOW: the screen standard of 2026-09-08 already fixes the screen's shape; this lane changes no layout, and the board is the Hub lane's screen.
- **WHERE IT LIVES:** the build group of the board at hub.heroesandsidekicks.io, opened by Nick; each project's progress screen, opened by Nick from a chat link; the one command at `projects/ops/skippy-jobs/lib/unified-project-update.mjs`; the nightly detectors at `projects/ops/skippy-jobs/lib/pm-currency.mjs` and their job at `projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs`; the names on the screens at `projects/ops/artifacts/project-status/registry.json`. · HOW WE KNOW: each path opened 2026-09-09 and named under Already true.
- **WHAT IT MUST DO:** (1) show exactly one active card per plan folder that has a plan in it, each named in plain human words with no programme prefix and no category word in front; (2) supersede every stale card in place, reversibly, and delete or complete none; (3) give each card the due date its own plan names, and name in the output any card whose plan names none rather than inventing one; (4) leave nothing able to re-create the old cards from a list on one machine; (5) let the one command place every live plan, and keep refusing a plan it cannot place instead of posting elsewhere; (6) move the card, the screen and the plan in one action and prove the screen's file changed; (7) carry that command's runnable form in every live lane's builder prompt, with the screen link posted in the chat at every stopping point; (8) read every live lane four times a day and print AGREE or name the project and which of the three disagrees; (9) hold the naming rule as one numbered rule in one file and nowhere else.
- **NOT in scope:** the ANTI-SCOPE — (a) renaming any lane FOLDER: every path in every lane plan, every registry row and every handoff prompt names those folders, so a folder rename breaks all of them at once for a cosmetic gain; the names Nick reads are on the cards and the screens, and that is where they change; (b) security or privacy work of any kind, including who may read a card or a screen — one line in `projects/ops/sp-sec/PLAN.md` and back to work (Nick, 2026-09-09); (c) how the Hub DRAWS a card or a progress screen, and the open director findings on those screens — the HUB lane owns them and closes them in its own STEP 10; (d) the clock itself: this lane adds a detector to a job that already runs, and the SCHEDULED lane owns every schedule, including any change to when that job fires; (e) any card outside the build group — 255 cards exist across all groups and 33 are this lane's business; (f) the other five detectors already inside the nightly check and the programme they were built for; touching them is how a working check gets broken for a rename. Also not in scope because it is already true: making the one command refuse an unknown plan, and giving it its all-three-at-once behaviour.
- **Trip-over protocol:** a lane that finds something outside the fence writes one handover line to its named owner (a security- or privacy-shaped thing: one line in `projects/ops/sp-sec/PLAN.md`), then back to building — never investigates, never fixes.

## 1a · Critical variables — the confirmation sheet is GENERATED from this table

| # | The variable, in plain words | Value chosen | Alternatives rejected | Class | HOW WE KNOW | Cost if wrong | CONFIRMED |
|---|---|---|---|---|---|---|---|
| 1 | **SURFACE — which screen this lands on, and who opens it** | the build group of the board at hub.heroesandsidekicks.io, opened by Nick; and each project's own progress screen, opened by Nick from a link an agent posts in the chat | a new project-overview page; a document he has to go and find; a chat summary with no screen behind it | V1 | he named both surfaces himself in the same message, one to clean up and one to link | he keeps asking people where a project stands, which is the thing this lane exists to end | Nick, 2026-09-09, "we need to clean up the ai build board" and "link the screen in the chat thread" |
| 2 | What a project's name looks like | CATEGORY: Project - Task: a short capital category code from the category table in STEP 1, a colon, the project in plain words, a dash, the task in plain words — "HUB: Project Management - Final Reinforcement" | free-text names; a programme prefix such as "Life OS ·"; a numeric lane code | V1 | he wrote the convention himself with three examples, after first asking for plain names | he reads a board of near-identical names and cannot tell his projects apart, which is today's state | Nick, 2026-09-09: "we need a naming convention that designates CATEGORY:PROJECT-TASK — HUB for hub, FA for family app, AGENTS or those edits etc. SO... HUB: Project Management - Final Reinforcement · FA: Redesign - Design Home Screen · SKILLS: Rewrites - /plan updates · stuff like that we can refine over time" |
| 3 | What "updates its plan" means at a stopping point, and when it happens | one command writes the plan's own step line, posts the matching card update and regenerates the screen, in a single action, BEFORE the agent writes anything to Nick; three separate hand-written updates are not it | the agent updating whichever of the three it remembers; a summary in the chat with the card and screen left behind; a nightly catch-up instead of a per-stop update | V1 | his words name all three things and the timing, and the one command that does all three already exists | he reads a report about work whose card and screen still show last night, which is what made him ask | Nick, 2026-09-09, "agents to update the progress screen and tasks cards and plans on every turn" and "before it comes to him" |
| 4 | Whether the screen link goes in the chat every time or only when he asks | every stopping point, in the chat thread, as the one pointer the closing-message rule allows | only when he asks for it; a link in the card instead of the chat; a folder path instead of a link | V1 | he asked for the link in the thread so he can review without asking | he has to ask for a link every time, which is the asking this lane removes | Nick, 2026-09-09, "link the screen in the chat thread" |

- V1 confirmation reads `<name>, <date>, "<their own words>"` — the date is required.
- V2 confirmation reads `opened <what>, <date>, saw: <what was actually there>`.

**Considered and ruled NOT critical:**
- `which cheap vendor builds which step` — the model matrix decides it; a wrong pick costs one failover, not a different product.
- `whether a stale card is superseded or completed` — settled by opening the board door, not by asking: it has no delete and superseding is the one reversible move, so there is no second answer to choose.
- `where the new detector lives` — inside the job that already runs four times a day; the ownership rule settles it.

## 1b · Subproject decomposition — could a piece of this ship on its own?

| Subproject | End goal (one sentence — what's TRUE when done) | Depends on (named artefact) | Owner | Own PLAN.md path | Confirmation-sheet status |
|---|---|---|---|---|---|
| The board Nick reads | one active card per live plan, named in plain human words, nothing stale, nothing doubled, and nothing left that can re-create the old cards | none — start now | this lane | this file, STEP 1 | §1a signed |
| Every plan the command knows | the one update command places every live plan and still refuses one it cannot place | none — start now | this lane | this file, STEP 2 | §1a signed |
| The stopping-point habit | one command moves card, screen and plan together at every stop, and the screen link is in the chat | the registry rows STEP 2 writes into `projects/ops/artifacts/project-status/registry.json` | this lane | this file, STEP 3 | §1a signed |
| The nightly agreement | the check that already runs four times a day reads every live lane and prints AGREE or names the mismatch | the registry rows STEP 2 writes into `projects/ops/artifacts/project-status/registry.json` | this lane | this file, STEP 4 | §1a signed |
| Polish | the naming rule written once, the screens' plain-language fault count at zero, the lane closed with its leftovers declared | the FRONT steps closed | this lane | this file, STEP 5 to STEP 7 | §1a signed |

**Carve-out rule:** how the Hub DRAWS a card or a progress screen is carved out to the HUB lane, which owns its own STEP 10 for the screens' open findings. Any change to WHEN the nightly job fires is carved out to the SCHEDULED lane, named in §3's contracts. Nothing else leaves this lane's scope.

## 2 · The complete UX map (this becomes the test manifest verbatim)

| Id | Screen / entry point | State (default·empty·error·loading) | Element / interaction | Expected behavior | Navigation from → to |
|---|---|---|---|---|---|
| U1 | The board's build group, opened by Nick | populated | reading the card list | exactly one active card per plan folder that holds a plan; every name plain human words with no programme prefix and no category word in front; zero duplicates by name | board → board |
| U2 | The board's build group, a stale card | stale | none | the card is superseded in place and leaves the active view; its row and history stay reachable by id; nothing is deleted and nothing is marked complete | board → board |
| U3 | The board's build group, a card's due date | dated · undated source | reading the date | the date is the one its own plan names as its finish line; a card whose plan names no date keeps the date it has and is named in the run's output, never given an invented one | board → board |
| U4 | A project's progress screen, opened from the chat link | populated | opening the link | the title is that project's short human name; the step list, the percent and the state pill match the plan's own step record | chat → screen |
| U5 | A stopping-point message in the chat | default | reading the last line | it carries the progress-screen link, and the card, the screen and the plan were already current before it was sent | chat → screen |
| U6 | The one update command, run for a plan the board does not know | refused | running it | it refuses, names the missing registration, and posts to no card at all | command → refusal |
| U7 | The one update command, run for a live plan | accepted | running it | the card update lands, the plan's step line is written, and the screen's own file is proven to have changed | command → all three |
| U8 | The nightly check, four times a day | agree · mismatch | the clock | for every live lane it prints AGREE, or names the project and which of the three — card, screen or plan — disagrees | clock → findings |
| U9 | Any machine other than the one that held the helper | default | looking for a way to create board cards from a local list | there is none; the only route is the shared command, and the retired helper is preserved in the cloud copy | machine → command |

## 2d · DESIGN FIDELITY GATE (plan skill §D — mandatory when the deliverable is looked at)

DESIGN FIDELITY GATE: N/A — nothing is drawn or restyled by this lane. The board and the progress screens keep the look they have; only the words on them change, and the screen's shape is already fixed by `projects/ops/life-os/REGROUP-2026-09-08/PROGRESS-SCREEN-STANDARD.txt` (Nick, 2026-09-08: "this format should be the standard format for our progress screens"). Any change to how either surface is DRAWN belongs to the HUB lane and carries that lane's own gate, locked target and anchor map.

## 3 · Lanes and frozen contracts

| Lane | Scope (in / out) | Owner | Definition of done | Builder (cheap, named) | Backup builder | Checker (different model) | Backup checker |
|---|---|---|---|---|---|---|---|
| The board Nick reads | the card names, the registry names, the active card set, the machine-only helper's retirement / out: any card outside the build group, any lane folder rename | this lane | U1, U2, U3 and U9 pass on a live board read | GLM 5.3 (zai) | DeepSeek | Qwen | Sonnet |
| Every plan the command knows | the registry rows for every live plan, and the guard that an unknown plan is still refused / out: the command's code beyond what it reads from the registry | this lane | U6 passes red and green | DeepSeek | GLM 5.3 (zai) | Qwen | Sonnet |
| The stopping-point habit | the one-command form in every live lane's builder prompt, the chat link, one proven end-to-end run / out: another lane's steps, another lane's plan text | this lane | U5 and U7 pass | Qwen | DeepSeek | GLM 5.3 (zai) | Sonnet |
| The nightly agreement | one new detector inside the job that already runs, and its fixtures / out: a new job, a new clock, the five detectors already there | this lane | U4 and U8 pass | GLM 5.3 (zai) | Qwen | DeepSeek | Sonnet |
| Polish | the naming rule written once, the screens' plain-language faults at zero, close-out / out: anything new | this lane | STEP 5 to STEP 7 closed | DeepSeek | Qwen | GLM 5.3 (zai) | Sonnet |

**Contracts between lanes (FROZEN at plan time — change = dated PLAN-CHANGES.md delta):** a board card is renamed only through the tasks door's own `edit` action and removed from an active view only through its `supersede` action — there is no delete and no second archive · a project's screen title comes from its registry row's name unless its own plan carries a title block, and this lane writes the registry name and never another lane's plan text · the one update command is the ONLY route by which a card, a screen and a plan move together; no lane writes any one of the three by hand · the nightly check gains ONE detector and keeps its five; its schedule belongs to the SCHEDULED lane and this lane never edits a schedule line · the HUB lane owns how both surfaces are drawn and receives a handoff line when the names land · a card's due date comes from its own plan's finish line and is never invented.

**Data floor, binding:** the only reasons a file stays inside are a login, a credential or token or key VALUE, a government ID, or a card, bank or routing number — and the refuser must prove the hit. Plan text, board card names, step records, registry rows and the nightly detectors are not on that list; the board's robot bearer IS, so it is read from the vault at run time by the tools that already do it and never written into a file, a log, a card or this plan. A wall refusing a plan file or a detector is logged as a failure in PROGRESS.txt and the job goes to the named backup vendor, never to Sonnet or Fable.

## 3b · Execution map — FRONT first, POLISH last, one row per step

A task is DONE only when its review-ledger row is CLOSED by a reviewer that is not the builder.

**Step map (read this first) — FRONT rows are what Nick sees or uses; POLISH rows run after the FRONT rows close, or the moment one bites:**

| Stage | # | TIER | Task (step name) | FOR NICK | Needs (named artefact, or `none — start now`) | EXECUTOR (cheap model) | EXECUTOR BACKUP | CHECKER (different model) | CHECKER BACKUP | DONE-PROOF (runnable command) |
|---|---|---|---|---|---|---|---|---|---|---|
| The board Nick reads | 1 | FRONT | The board cleaned up, named CATEGORY: Project - Task, and unable to drift back: the machine-only helper preserved into the cloud copy and removed from the Mac first, then every card renamed, every stale card superseded, every due date taken from its own plan | you open your project board and see one card per real project with a name you would use yourself, nothing stale, nothing doubled, and nothing that quietly puts the old names back | none — start now | GLM 5.3 (zai) | DeepSeek | Qwen | Sonnet | `node projects/ops/skippy-jobs/lib/board-report.mjs --board-audit --lane ai-builds --run-by step1-checker` (a new mode on the existing tool, CREATED BY STEP 1) prints `active cards: <n> · plan folders: <n> · names outside the convention: 0 · duplicate names: 0 · undated sources named: <list>` with the two counts equal |
| Every plan the command knows | 2 | FRONT | Every live plan registered so the one command can place it, and the refusal kept honest: a plan the board does not know is still refused and posts nowhere | an agent's update always lands on your project's own card and never on an unrelated app's card | none — start now | DeepSeek | GLM 5.3 (zai) | Qwen | Sonnet | `node projects/ops/skippy-jobs/lib/unified-project-update.mjs --plan-file projects/ops/life-os/REGROUP-2026-09-08/plans/PROJECT-MANAGEMENT/PLAN.proposed.txt --step 2 --percent 100 --dod "the one update command accepts every plan folder that holds a plan and still refuses one the board does not know" --proof "the same command in dry run: exit 0 for a registered plan, exit 2 for an unregistered file" --verified "<the date and the checker>" --summary "Every live project is now known to the one command that updates a card, a screen and a plan together, so an agent's update always lands on that project's own card and never on an unrelated one." --card ac-ai-builds-agent-project-management --dry-run` exits 0, and the same command with `--plan-file projects/ops/life-os/REGROUP-2026-09-08/PROGRESS-SCREEN-STANDARD.txt` (a real file in a folder that has no board registration and never will, so this half stays negative after every lane is registered) exits 2 naming the missing registration |
| The stopping-point habit | 3 | FRONT | One command, one stop: the card, the screen and the plan move together and the screen link goes in the chat — and every live lane's builder prompt carries that command in the exact form the turn gate accepts | every time an agent stops, your card, your screen and your plan are already current, and the link to look is right there in the chat | the registry rows STEP 2 writes into `projects/ops/artifacts/project-status/registry.json` | Qwen | DeepSeek | GLM 5.3 (zai) | Sonnet | `command grep -L "unified-project-update.mjs" projects/ops/life-os/REGROUP-2026-09-08/plans/*/HANDOFF-PROMPT-FOR-*.txt` prints nothing, and one real run of that command for this plan exits 0 |
| The nightly agreement | 4 | FRONT | The check that already runs four times a day reads every live lane and prints AGREE, or names the project and which of the card, the screen and the plan disagrees | if a project's card, screen and plan ever drift apart, it is caught overnight and named, instead of you finding it | the registry rows STEP 2 writes into `projects/ops/artifacts/project-status/registry.json` | GLM 5.3 (zai) | Qwen | DeepSeek | Sonnet | `node projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs --lanes` (a new mode on the existing tool, CREATED BY STEP 4) prints a line beginning `lanes checked:` reading `lanes checked: <n> · AGREE: <n> · mismatched: 0` and exits 0 |
| Polish | 5 | POLISH | The naming rule written once, as one numbered rule in one file, and nowhere else | nothing you notice; the rule you gave stops being re-explained in five documents | STEP 1 closed | DeepSeek | Qwen | GLM 5.3 (zai) | Sonnet | `command grep -rl "CATEGORY: Project - Task" projects/ops --include="*.md"` prints exactly one path, `projects/ops/MACHINE-RULES.md` |
| Polish | 6 | POLISH | The screens read like a person wrote them: the same nightly pass counts jargon and file paths on every live lane's screen and holds it at zero | nothing you notice; your progress screens keep saying what things mean instead of naming files | STEP 4 closed | DeepSeek | Qwen | GLM 5.3 (zai) | Sonnet | `node projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs --lanes --plain-language` (a new mode on the existing tool, CREATED BY STEP 6) exits 0 and prints `screens checked: <n> · jargon or file paths on a screen: 0` |
| Polish | 7 | POLISH | Close-out: the finish line checked item by item, the postmortem written here, every leftover declared and removed | you get one line saying this is done, and nothing else to read | STEP 1 to STEP 6 closed | GLM 5.3 (zai) | DeepSeek | Qwen | Sonnet | `python3 projects/ops/agents/check_plan.py --gate-progress projects/ops/life-os/REGROUP-2026-09-08/plans/PROJECT-MANAGEMENT/PLAN.proposed.txt` exits 0 |

### §3c · CUT — considered for this lane, overkill for the outcome, recorded once and not worked
- Renaming the lane FOLDERS to match the new card names — every path in every plan, every registry row and every builder prompt names those folders; the gain is invisible to Nick and the cost is every path in the programme.
- A new scheduled job for the agreement check — the check that asks whether a project's documents are telling the truth already runs four times a day; a second clock is the duplicate-system failure this lane is supposed to prevent.
- A new board-audit tool of its own — the board library already holds the token, the card-id and the card-edit functions; the audit is a mode on it.
- A per-turn verification that each stopping-point update actually posted — one check per step, and the nightly agreement pass is the standing answer to drift; a per-turn checker is the checking-on-checking Nick retired.
- A long legend of codes with sub-categories — the category list is the one short table in STEP 1, and it is refined over time on Nick's word ("we can refine over time", 2026-09-09), never silently.
- A dashboard of every card's rename history — git and the board's own row history already hold it, and nobody asked to look.

**Then one block per step, in this exact shape:**

### STEP 1 — The board cleaned up, named CATEGORY: Project - Task, and unable to drift back
**FOR NICK:** you open your project board and see one card per real project, each named the way you wrote it — CATEGORY: Project - Task, like "HUB: Project Management - Final Reinforcement" — nothing stale, nothing doubled, and the board's own door refusing any name in another shape, so it cannot drift back. · **Tier:** FRONT
**Start when:** none — start now.
**Builder:** GLM 5.3 (zai) · **Builder backup:** DeepSeek · **Checker:** Qwen, a different session · **Checker backup:** Sonnet
**Files you may touch:** `projects/ops/skippy-jobs/lib/board-report.mjs` (the new `--board-audit` mode only), `projects/business/business-app/app/functions/api/tasks.js` (ONE name validator on the `create` and `edit` actions for the ai-builds group only, after a dated line into the Hub lane's plan naming it — the Hub lane owns the rest of that file), `projects/ops/skippy-jobs/lib/unified-project-update.mjs` (one refusal on a card name outside the convention, beside STEP 2's refusal), `projects/ops/artifacts/project-status/registry.json` (the `name` field of the life-os rows only), `projects/ops/life-os/REGROUP-2026-09-08/plans/PROJECT-MANAGEMENT/` (this lane's own folder, including the preserved copy of the retired helper and the evidence folder), `/Users/nickdeck/Documents/life-os-launch/board-cards.mjs` (removed, AFTER it is preserved). **Never** another lane's `PLAN.proposed.txt` or `STEPS.json` (each lane owns its own), any card outside the build group, the five detectors in `projects/ops/skippy-jobs/lib/pm-currency.mjs` (STEP 4 adds a sixth beside them).

**Do exactly this:**
1. FIRST, before any rename: copy `/Users/nickdeck/Documents/life-os-launch/board-cards.mjs` and its sibling card map into a `retired` folder inside this lane's own plan folder (created by this step), commit them with a pathspec, and confirm both are tracked. Then remove both from the Mac. Nothing is destroyed: they are in the cloud copy first and the removal is a machine cleanup (RULE 20).
2. Add a `--board-audit` mode to `projects/ops/skippy-jobs/lib/board-report.mjs`, using that file's own `boardToken()` and read path — never a second implementation and never a printed token. It lists the plan folders under `projects/ops/life-os/REGROUP-2026-09-08/plans/` that contain a `PLAN.proposed.txt`, reads the live build group, and prints one line: active cards, plan folders, cards whose name carries a programme prefix or a category word, duplicate names, and the ids of any card whose plan names no finish-line date.
3. Rename each card through the tasks door's `edit` action, `name` field, one card at a time: write one card, pause, read the whole board back, confirm the new name, then the next. Every name reads CATEGORY: Project - Task: a short capital category code from this table, a colon, the project in plain words, a dash, the task in plain words (the task is the plan's own first FRONT outcome in a few words). The categories: HUB (the Hub and its screens, including project management) · FA (the family app) · VOICE (Skippy's voice) · SKIPPY (Skippy on every channel) · BRAINS (what the assistant knows) · HEALTH (the health engine) · FILES (files, the cloud, the workshop) · AGENTS (the agent team, the router, the dispatch gate) · SKILLS (the skills menu) · SCHED (scheduled tasks) · CAPTUS (Jasmin/Captus) · SCHOOL (the kids' school app) · RULES (the rule files) — refined over time on Nick's word, never silently. The sixteen names, one per plan folder, written from each plan's own first FRONT item: HUB: Mission Control - Email and Slack like Gmail · FA: Family App - Calendar sheet, no overdue, faster load · VOICE: Skippy Voice - Usable on your phone this week · SKIPPY: Skippy Channels - Replies and actions everywhere · BRAINS: Assistant Brain - Answers through the free door · HEALTH: Health Engine - One sourced answer on your phone · FILES: Files and Cloud - One cloud copy, nothing on a Mac · FILES: Workshop - Two agents cannot overwrite each other · AGENTS: Agent Team - The seven approved rules landed · SKILLS: Skills Menu - One menu everywhere · SCHED: Scheduled Tasks - The clockwork back on the mini · CAPTUS: Captus Content - Client approval screen · HUB: Project Management - Board, screens and plans in step · AGENTS: Cheap Routing - No job refused for ordinary words · SCHOOL: Kids School - A real curriculum that gets harder · RULES: Rule Files - Every rule once, numbered. A name is never typed twice: it is set once in the status registry row and the card is written from that row.
3b. PUT THE CONVENTION AT THE DOOR, RED FIRST — this is what makes it stick where every earlier attempt was a sentence in a document: in `projects/business/business-app/app/functions/api/tasks.js`, the `create` and `edit` actions refuse a `name` for the ai-builds group that does not match `^[A-Z]{2,8}: [^-]{3,60} - .{3,80}$`, answering 400 with the convention and the offending name quoted; prove it red (a create named "Life OS · anything" returns 400 and the board read-back shows no such card) then green (a create named "HUB: Project Management - Board, screens and plans in step" returns 201 and reads back). Post one dated line into the Hub lane's plan before the edit. Then `projects/ops/skippy-jobs/lib/unified-project-update.mjs` refuses to post to a card whose name fails the same pattern (red-first on a fixture card), and the `--board-audit` line counts `names outside the convention`.
4. Set the same names in the `name` field of the matching rows of `projects/ops/artifacts/project-status/registry.json`, because fourteen of the sixteen lane plans have no title block of their own and take their screen title from that row. A folder with no row yet gets its name when STEP 2 adds the row.
5. Set each card's due date through the same `edit` action to the date its own plan names as its finish line. A plan that names no date: leave the card's date exactly as it is and print that card's id in the audit's `undated sources named` list. Never invent a date.
6. Supersede every stale card in the build group through the tasks door's `supersede_many` action with a `replacement_lane`, in batches of at most 200 ids, all-or-nothing: a card is stale when no plan folder holds a plan for it. Nothing is deleted and nothing is marked complete.
7. Create a card for any plan folder that has no card, one at a time with a pause and a read-back, because back-to-back creates return success and silently lose every other one. Write this lane's own card id into §5 of this file.
8. Run the audit; then run it a second time after invoking the shared update command once, to prove no duplicate reappears.

**Evidence:** the two audit runs' own output, saved `evidence/step1-board-audit.txt`.
**DEFINITION OF DONE:** the live build group holds exactly one active card per plan folder that has a plan in it, every name in the CATEGORY: Project - Task shape with the door proven to refuse any other shape red-then-green, zero duplicates, every stale card superseded rather than deleted, every due date from its own plan or listed as undated, and the machine-only helper preserved in the cloud copy and gone from the Mac.
**PROOF:** `node projects/ops/skippy-jobs/lib/board-report.mjs --board-audit --lane ai-builds --run-by step1-checker` → a line reading `active cards: <n> · plan folders: <n> · names outside the convention: 0 · duplicate names: 0 · undated sources named: <list>` with the two counts equal, run twice with the same result. READ THE PRINTED LINE, NEVER THE EXIT CODE: measured 2026-09-09, this tool exits 0 even on a rejected argument list, so an exit code says nothing here · **FAILS IF:** the outside-convention count or the duplicate count is above zero, the door's red run did not return 400, the two counts differ, the run prints a usage complaint instead of the count line, any card was deleted or marked complete, a due date appears that no plan names, the helper is still on the Mac, or the helper is gone from the Mac without a tracked copy in the cloud

**If the check fails:** the builder fixes and re-checks the named failure until it passes. If this step cannot close from this machine: one line to the overseer naming the ONE missing thing, then the next step whose inputs exist.
**Checker's job:** re-run the PROOF yourself, once. PASS closes the step. Do not accept the builder's pasted output; do not summon anyone else.
**Handoff (if any):** the moment this step closes, post one dated line into `projects/ops/life-os/REGROUP-2026-09-08/plans/HUB/PLAN.proposed.txt`: `STEP 1 closed <date> — every build-board card now reads CATEGORY: Project - Task, the door refuses any other shape, and the stale cards are superseded; the Hub draws them unchanged.`

### STEP 2 — Every live plan registered, and the refusal kept honest
**FOR NICK:** an agent's update always lands on your project's own card, and never on some unrelated app's card. · **Tier:** FRONT
**Start when:** none — start now.
**Builder:** DeepSeek · **Builder backup:** GLM 5.3 (zai) · **Checker:** Qwen, a different session · **Checker backup:** Sonnet
**Files you may touch:** `projects/ops/artifacts/project-status/registry.json` (rows for the life-os plan folders: add the missing ones, and add the `planFile` and `stateFile` pointers where they are absent), `projects/ops/life-os/REGROUP-2026-09-08/plans/PROJECT-MANAGEMENT/evidence/`. **Never** `projects/ops/skippy-jobs/lib/unified-project-update.mjs` (its refusal is already correct — measured 2026-09-09 — and editing it to "add" a refusal is how a working guard gets broken), `projects/ops/status-regen.mjs`, another lane's plan folder.

**Do exactly this:**
1. Take the red reading first and save it: run the update command in dry-run for a plan the board does not know and record the refusal text and exit code into this lane's evidence folder.
2. For every plan folder under `projects/ops/life-os/REGROUP-2026-09-08/plans/` that holds a `PLAN.proposed.txt` and has no registry row, add one row with its slug, its short human name from STEP 1, its directory, `"planFile": "PLAN.proposed.txt"` and `"stateFile": "PROGRESS.txt"`. Surgical edits to the JSON, one row at a time, never a re-dump of the file.
3. For every existing life-os row that carries no `planFile`, add `"planFile": "PLAN.proposed.txt"` and `"stateFile": "PROGRESS.txt"` in the same surgical way, because the screen generator picks a project file by name and a row without pointers resolves by luck rather than by contract.
4. Confirm each new row resolves: run the screen regenerator for that slug and read the exit code.
5. Take the green reading: run the update command in dry-run for THIS plan and confirm exit 0. The words matter, not just the flags: read `evaluateSelfContainment` in that same file before you compose the run, because the summary is judged for whether it stands on its own BEFORE the dry run returns, so a placeholder summary refuses a correctly registered plan and reads exactly like a registration failure.

**Evidence:** the refused run and the accepted run, both with their exit codes, saved `evidence/step2-registration-red-green.txt`.
**DEFINITION OF DONE:** the one update command accepts every plan folder that holds a plan, in dry-run, and still exits 2 with the missing-registration reason for a file the board does not know.
**PROOF:** `node projects/ops/skippy-jobs/lib/unified-project-update.mjs --plan-file projects/ops/life-os/REGROUP-2026-09-08/plans/PROJECT-MANAGEMENT/PLAN.proposed.txt --step 2 --percent 100 --dod "the one update command accepts every plan folder that holds a plan and still refuses one the board does not know" --proof "the same command in dry run: exit 0 for a registered plan, exit 2 for an unregistered file" --verified "<the date and the checker>" --summary "Every live project is now known to the one command that updates a card, a screen and a plan together, so an agent's update always lands on that project's own card and never on an unrelated one." --card ac-ai-builds-agent-project-management --dry-run` → exit 0; then the same command with `--plan-file projects/ops/life-os/REGROUP-2026-09-08/PROGRESS-SCREEN-STANDARD.txt` (a real file in a folder that has no board registration and never will, so this half stays negative after every lane is registered) → exit 2 naming the missing registration · **FAILS IF:** either exit code is wrong, the refusal wording no longer names the registry, any row was added for a folder with no plan in it, or the file was rewritten wholesale instead of edited row by row

**If the check fails:** the builder fixes and re-checks the named failure until it passes. If this step cannot close from this machine: one line to the overseer naming the ONE missing thing, then the next step whose inputs exist.
**Checker's job:** re-run the PROOF yourself, once. PASS closes the step. Do not accept the builder's pasted output; do not summon anyone else.
**Handoff (if any):** none.

### STEP 3 — One command, one stop, and the link in the chat
**FOR NICK:** every time an agent stops, your card, your screen and your plan are already up to date, and the link to look at it is right there in the chat. · **Tier:** FRONT
**Start when:** the registry rows STEP 2 writes into `projects/ops/artifacts/project-status/registry.json`.
**Builder:** Qwen · **Builder backup:** DeepSeek · **Checker:** GLM 5.3 (zai), a different session · **Checker backup:** Sonnet
**Files you may touch:** each lane's builder prompt under `projects/ops/life-os/REGROUP-2026-09-08/plans/` — the one-command paragraph only, appended, changing no step and no ruling — and this lane's own folder. TWO PROMPT NAMES ARE IN USE, measured 2026-09-09: fourteen lanes carry `HANDOFF-PROMPT-FOR-BUILDER.txt` and two carry `HANDOFF-PROMPT-FOR-CODEX-LEAD.txt`, one of which has no builder-named prompt at all, so a pattern matching only the first name silently misses that lane. **Never** any lane's `PLAN.proposed.txt`, `STEPS.json`, `PROGRESS.txt` or `STATE.txt`; **never** the turn gate `projects/ops/skippy-jobs/lib/handback-contract.mjs`.

**Do exactly this:**
1. Read the turn gate's own requirement in `projects/ops/skippy-jobs/lib/handback-contract.mjs` around line 1394 and write the one-command form it accepts: nothing may trail the invocation and nothing may lead it except a change of directory into the repository root. A pipe, a redirect or a trailing echo makes the gate treat the turn as if no update happened.
2. Append one paragraph to every live lane's builder prompt: the exact one-command invocation with that lane's own plan path and card id, the sentence that it runs BEFORE anything is written to Nick, and the sentence that the screen's link is posted in the chat thread as the one pointer the closing-message rule allows.
3. In the same paragraph, add the line about a refused documentation write: file the ticket at once with the ticket tool, never record "needs Nick's keystroke" without filing it.
4. In those same builder prompts, replace any instruction telling the lane to post a step close through the machine-only helper STEP 1 retires, because an instruction pointing at a file that is gone is how a lane stops updating anything at all. SCOPE THIS CAREFULLY — measured 2026-09-09, fifteen files under the programme folder name that helper and they are not the same kind of sentence. Four carry a live instruction to run it, and only two of those four are outside this lane: one lane's own state record, at its "BOARD CARD:" line, and the programme's own skill-update record. The rest merely RECORD that it was used once. Fix the instructions inside the prompts you may touch. For a live instruction sitting in a lane's own state or progress record, post ONE handover line to that lane naming the file and the line, and let that lane change it — never edit it from here. Change nothing that is a historical record: history is append-only and is never rewritten.
5. Prove it end to end on this lane: run the one command for this plan and this step, and read all three results back — the card update, the plan's step line, and the screen file's own changed timestamp.

**Evidence:** both searches' output, the handover lines posted, and the real run's three results, saved `evidence/step3-prompts-and-run.txt`.
**DEFINITION OF DONE:** every lane's builder prompt, under both names in use, carries the one-command form in the shape the turn gate accepts and no longer instructs anyone to use the retired helper; every live instruction found outside those prompts has a handover line posted to its owning lane; and one real run of that command for this plan moved the card, the plan's step line and the screen's own file together.
**PROOF:** `command grep -L "unified-project-update.mjs" projects/ops/life-os/REGROUP-2026-09-08/plans/*/HANDOFF-PROMPT-FOR-*.txt` → prints nothing, and `command grep -rl "board-cards.mjs post" projects/ops/life-os/REGROUP-2026-09-08/plans/*/HANDOFF-PROMPT-FOR-*.txt` → prints nothing; then one real run of `node projects/ops/skippy-jobs/lib/unified-project-update.mjs --plan-file projects/ops/life-os/REGROUP-2026-09-08/plans/PROJECT-MANAGEMENT/PLAN.proposed.txt --step 3 --percent 100 --dod "<this step's done line>" --proof "<this step's proof>" --verified "<date and checker>" --summary "<the fresh summary>" --card ac-ai-builds-agent-project-management` → exit 0 · **FAILS IF:** either search prints a path, a lane whose prompt carries the other name was skipped, the run exits non-zero, the screen's file timestamp did not move, any lane's plan, step record, progress record or state record was edited by this step, or a historical mention of the retired helper was rewritten instead of left alone

**If the check fails:** the builder fixes and re-checks the named failure until it passes. If this step cannot close from this machine: one line to the overseer naming the ONE missing thing, then the next step whose inputs exist.
**Checker's job:** re-run the PROOF yourself, once. PASS closes the step. Do not accept the builder's pasted output; do not summon anyone else.
**Handoff (if any):** the moment this step closes, post one dated line into `projects/ops/life-os/PLAN-LIFE-OS-2026-09-09.md`: `Group H STEP 3 closed <date> — every lane's builder prompt now carries the one command that moves the card, the screen and the plan together.`

### STEP 4 — The nightly check says AGREE, or names what disagrees
**FOR NICK:** if a project's card, screen and plan ever drift apart, it is caught overnight and named, instead of you finding it. · **Tier:** FRONT
**Start when:** the registry rows STEP 2 writes into `projects/ops/artifacts/project-status/registry.json`.
**Builder:** GLM 5.3 (zai) · **Builder backup:** Qwen · **Checker:** DeepSeek, a different session · **Checker backup:** Sonnet
**Files you may touch:** `projects/ops/skippy-jobs/lib/pm-currency.mjs` (one NEW exported detector added beside the five; the five are not touched), `projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs` (the new `--lanes` mode and the detector's wiring), `projects/ops/skippy-jobs/_test-pm-currency-watch.mjs` (fixtures for the new detector, red-first, added to the existing file). **Never** the five existing detectors' logic, `projects/ops/skippy-jobs/runner.mjs` (the schedule belongs to the SCHEDULED lane), `projects/ops/skippy-jobs/lib/stale-project-state.mjs`.

**Do exactly this:**
1. Add one pure detector to `projects/ops/skippy-jobs/lib/pm-currency.mjs`: given a registered project's plan step record, its screen's rendered step list and its card's latest update, return a finding when the three disagree on which step is current or on its percent. Pure functions only — no file reads, no clock, no network, and nothing read from a document is ever executed, matching that file's own stated contract.
2. Add a `--lanes` mode to `projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs` that runs the new detector over every registered life-os row and prints one line BEGINNING `lanes checked:` — lanes checked, AGREE, mismatched — and exits NON-ZERO when mismatched is above zero. Two measured traps to close while you are in this file: today an unrecognised flag is ignored and the ordinary pass runs instead (`--lanes` on 2026-09-09 printed the normal findings line), and the job exits 0 while printing FAIL with 47 findings. So the new mode must be recognised explicitly and must set its own exit code.
3. Wire the new detector into the job's normal four-times-a-day pass beside the five, keeping its existing escalation, its debounce and its `--verify-clear` behaviour untouched.
4. Add fixtures to the existing guard file for the new detector: one for each of the three ways the three can disagree, each proven red before the detector is finished, and one that is deliberately in agreement and must stay quiet.
5. Run the guard file, then run the new mode.

**Evidence:** the new mode's output and each guard fixture's red run, saved `evidence/step4-lanes-agree.txt`.
**DEFINITION OF DONE — AMENDED 2026-09-10 UNDER RULE 28 (Nick, 2026-09-10), AND THE ORIGINAL IS KEPT BELOW SO THE CHANGE IS VISIBLE:** the new mode reads every registered live lane, prints its four counts, names every disagreement it finds, and exits without crashing, and the guard file proves the detector goes red on each of the three ways the three can disagree and stays quiet when they agree. Other lanes' AGREEMENT IS THIS CHECK'S OUTPUT, NOT ITS ENTRY CONDITION.
**SUPERSEDED WORDING, kept deliberately:** "the new mode reads every registered live lane, prints AGREE for each, reports zero mismatches and exits 0". That required every OTHER lane's card, plan and screen to agree before this lane's own finished work could be called done — five lanes disagreed on the day, this lane is forbidden to edit their files, and two of those disagreements were created inside the same hour by those lanes advancing their own rows. RULE 28 (Nick, 2026-09-10) forbids that shape of close condition anywhere: a step is done on its own proofs. The capability is unchanged and nothing is dropped — only the condition for calling it finished.
**PROOF:** `node projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs --lanes` → a line beginning `lanes checked:` reading `lanes checked: <n> · AGREE: <n> · mismatched: <n> · unreadable: <n>` with all four counts present, and no crash (a mismatched count above zero is this check WORKING, not failing — RULE 28) · **FAILS IF:** no line begins `lanes checked:` (the flag was ignored and the ordinary pass ran instead — that is how it behaved on 2026-09-09), the mismatched count is above zero, the exit code is 0 while the mismatched count is above zero, the lanes-checked count is below the number of registered life-os rows, any of the five existing detectors changed behaviour, or the schedule line was edited

**If the check fails:** the builder fixes and re-checks the named failure until it passes. If this step cannot close from this machine: one line to the overseer naming the ONE missing thing, then the next step whose inputs exist.
**Checker's job:** re-run the PROOF yourself, once. PASS closes the step. Do not accept the builder's pasted output; do not summon anyone else.
**Handoff (if any):** the moment this step closes, post one dated line into `projects/ops/life-os/REGROUP-2026-09-08/plans/SCHEDULED/PLAN.proposed.txt`: `Group H STEP 4 closed <date> — the four-times-a-day document check now also reads every live lane's card, screen and plan; its schedule is unchanged and stays yours.`

### STEP 5 — The naming rule written once, and nowhere else
**FOR NICK:** nothing you notice; the rule you gave stops being re-explained in five different documents. · **Tier:** POLISH
**Start when:** STEP 1 closed.
**Builder:** DeepSeek · **Builder backup:** Qwen · **Checker:** GLM 5.3 (zai), a different session · **Checker backup:** Sonnet
**Files you may touch:** `projects/ops/MACHINE-RULES.md` (one new numbered rule appended, nothing else changed). **Never** any other rule file, any skill file, any agent file, this lane's own copy of the rule.

**Do exactly this:**
1. File the ticket first: `node projects/ops/skippy-jobs/lib/request-ticket.mjs projects/ops/MACHINE-RULES.md --reason "the board and screen naming rule, as one numbered rule, per RULE 21"`. It posts an Approve button to Nick's Slack within a minute. Never record "needs Nick's keystroke" without filing it.
2. Append ONE numbered rule, one dated paragraph in plain words: a project's name on the board and on its screen reads CATEGORY: Project - Task — a short capital category code from the one category table (HUB, FA, VOICE, SKIPPY, BRAINS, HEALTH, FILES, AGENTS, SKILLS, SCHED, CAPTUS, SCHOOL, RULES; refined over time on Nick's word, never silently), a colon, the project in plain words, a dash, the task in plain words; the board's own door refuses any other shape; the name is set once in the status registry row and written to the card from there, never by renaming a folder.
3. Search for any other sentence anywhere that says something different about a project's name and remove it, so the rule lives in one place only.

**Evidence:** the one-copy search's output and the ticket's own id, saved `evidence/step5-rule-once.txt`.
**DEFINITION OF DONE:** the naming rule exists as one numbered rule in `projects/ops/MACHINE-RULES.md` and its wording appears in no other file.
**PROOF — AMENDED 2026-09-10, and the original is quoted below:** `command grep -rl "CATEGORY: Project - Task" projects/ops --include="*.md" | command grep -v "/evidence/"` → exactly one path, `projects/ops/MACHINE-RULES.md`
**WHY THE AMENDMENT, so it is not read as lowering the bar:** the original counted every file containing the wording and demanded exactly one. It returns TWO, and the second is `plans/RULE-TRIM/evidence/machine-rules.before-step2.md` — a dated FROZEN ARCHIVE of the rules file itself, taken by another lane as its own evidence before it made a change. Checked rather than assumed: same first line as the live rules file, 554 lines against the live 563. An archive of the rules file is not a second, competing statement of the rule that somebody might read and follow; it is a photograph of the rules file on a past date, and the rule genuinely lives in exactly one live place. The step was being held open waiting for that other lane to rename its archive, which RULE 28 (Nick, 2026-09-10) forbids: a step is done on its own proofs and never waits on another lane. So the proof now excludes frozen evidence archives and still fails if the wording ever appears in a second LIVE document, which is the thing this step actually exists to prevent.
**SUPERSEDED WORDING, kept deliberately:** `command grep -rl "CATEGORY: Project - Task" projects/ops --include="*.md"` → exactly one path · **FAILS IF:** zero paths, more than one path, or the phrase appears twice inside that one file

**If the check fails:** the builder fixes and re-checks the named failure until it passes. If this step cannot close from this machine: one line to the overseer naming the ONE missing thing, then the next step whose inputs exist.
**Checker's job:** re-run the PROOF yourself, once. PASS closes the step. Do not accept the builder's pasted output; do not summon anyone else.
**Handoff (if any):** none.

### STEP 6 — The screens read like a person wrote them
**FOR NICK:** nothing you notice; your progress screens keep saying what things mean instead of naming files. · **Tier:** POLISH
**Start when:** STEP 4 closed.
**Builder:** DeepSeek · **Builder backup:** Qwen · **Checker:** GLM 5.3 (zai), a different session · **Checker backup:** Sonnet
**Files you may touch:** `projects/ops/skippy-jobs/lib/pm-currency.mjs` (one more pure detector), `projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs` (the `--plain-language` flag on the `--lanes` mode), `projects/ops/skippy-jobs/_test-pm-currency-watch.mjs` (its fixtures). **Never** `projects/ops/project-status-page.py`, `projects/ops/status-regen.mjs`, any lane's plan text, `projects/ops/skippy-jobs/lib/check-closing-message.mjs` (its word list is READ, never edited from here).

**Do exactly this:**
1. Add one pure detector that counts, on a live lane's rendered screen text, the things the screen standard forbids: a file path, a function name, a lane code, and the jargon words the existing closing-message linter already lists. Read that linter's list; never keep a second copy of it. An EMPTY goal line counts as a fault too — measured 2026-09-09, fourteen of the sixteen lane screens have none, because the screen builder reads a plan's goal out of a title block those fourteen plans do not carry.
2. Add the `--plain-language` flag to the `--lanes` mode: print screens checked and the fault count, exit 0 only at zero.
3. Add fixtures to the existing guard file, red-first: one screen with a file path, one with a lane code, one clean screen that must stay quiet.
4. Fix the faults it finds by correcting the screen's own source — which is each lane's plan step titles and its short human name, and for another lane's plan text that means one handover line to that lane, never an edit.

**Evidence:** the mode's output and each fixture's red run, saved `evidence/step6-plain-language.txt`.
**DEFINITION OF DONE:** the same nightly pass counts jargon, file paths and lane codes on every live lane's screen and reports zero, with the guard file proving it goes red on each of the three shapes.
**PROOF:** `node projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs --lanes --plain-language` → a line beginning `screens checked:` reading `screens checked: <n> · jargon or file paths on a screen: 0`, and exit 0 · **FAILS IF:** no line begins `screens checked:` (the flag was ignored and the ordinary pass ran instead), the fault count is above zero, the exit code is 0 while the fault count is above zero, a second copy of the jargon word list exists, or a fault was cleared by editing another lane's plan rather than handing it over

**If the check fails:** the builder fixes and re-checks the named failure until it passes. If this step cannot close from this machine: one line to the overseer naming the ONE missing thing, then the next step whose inputs exist.
**Checker's job:** re-run the PROOF yourself, once. PASS closes the step. Do not accept the builder's pasted output; do not summon anyone else.
**Handoff (if any):** none.

### STEP 7 — Close-out
**FOR NICK:** you get one line saying this is done, and nothing else to read. · **Tier:** POLISH
**Start when:** STEP 1 to STEP 6 closed.
**Builder:** GLM 5.3 (zai) · **Builder backup:** DeepSeek · **Checker:** Qwen, a different session · **Checker backup:** Sonnet
**Files you may touch:** this file's POSTMORTEM and STEPS sections, `projects/ops/life-os/REGROUP-2026-09-08/plans/PROJECT-MANAGEMENT/PROGRESS.txt`, `projects/ops/life-os/REGROUP-2026-09-08/plans/PROJECT-MANAGEMENT/STEPS.json`, this lane's evidence folder. **Never** a product file.

**Do exactly this:**
1. Check the finish line's eight items one by one against the closed steps' own proofs, and write the postmortem below.
2. Declare in PROGRESS.txt everything this lane left anywhere, with its size, and remove anything that is not the record: the board read saved during a measurement, any local preview page, any scratch copy.
3. Move this lane's board card to done through the one shared command.

**Evidence:** the finish line checked item by item against each closed step, saved `evidence/step7-finish-line.txt`.
**DEFINITION OF DONE:** each of the finish line's eight items points at a closed step's own dated check, the postmortem is written, and every leftover is declared and removed.
**PROOF:** `python3 projects/ops/agents/check_plan.py --gate-progress projects/ops/life-os/REGROUP-2026-09-08/plans/PROJECT-MANAGEMENT/PLAN.proposed.txt` → exit 0 and no line beginning `REFUSED:`. USE THIS MODE AND NOT `--progress`: measured 2026-09-09, `--gate-progress` printed `REFUSED: 8 of 8 step(s) do not have complete evidence` and exited 1, while `--progress` printed the same words and exited 0 — a plan that gates on the reporting form certifies itself with zero steps done. Its count of eight includes the loop step, and it also refuses while ANY step promises no artefact, which is why every step above names one it saves · **FAILS IF:** the exit code is not 0, any line begins `REFUSED:`, any finish-line item has no closed step behind it, the postmortem is empty, or a leftover is still on the Mac undeclared

**If the check fails:** the builder fixes and re-checks the named failure until it passes. If this step cannot close from this machine: one line to the overseer naming the ONE missing thing, then the next step whose inputs exist.
**Checker's job:** re-run the PROOF yourself, once. PASS closes the step. Do not accept the builder's pasted output; do not summon anyone else.
**Handoff (if any):** the moment this step closes, post one dated line into `projects/ops/life-os/PLAN-LIFE-OS-2026-09-09.md`: `Group H closed <date> — every §3d agent-project-management item true.`

**Step-writing rules:** every step names the literal command and the literal expected output — "verify it works" is a defect · as many steps as the North Star needs, no more · red-first for any fix step · builds and per-step checks on the cheap tier by name; the overseer never builds; the plan is written and the finish line signed off on Anthropic or OpenAI.

## 4 · Regret Check (the registry failures this build is actually exposed to)

| Failure mode (registry entry) | The measure in THIS plan that prevents it | Where it lives (section / artifact / gate) |
|---|---|---|
| A written record of a defect was acted on as if it were the defect, and a working guard was "repaired" | every claim in this plan was re-measured on 2026-09-09 before it was written; the update command's refusal was found already live at lines 381-390, so STEP 2 registers plans and its file fence forbids editing that command at all | Already true; STEP 2 file fence |
| A rename broke a matcher that identified things by their old name, and duplicates appeared | measured: the machine-only helper matches a card by exact old title against 23 hardcoded prefixed titles; STEP 1 preserves and removes it BEFORE any rename, and the audit counts duplicates twice, once after a shared-command run | STEP 1 actions 1 and 8; §2 U9 |
| A second system was built because the first was invisible | the agreement check is one new detector inside the job that already runs four times a day; the board audit is a mode on the board library; the archive is the board door's own supersede action; §3c records each as cut | §3 contracts; §3c; STEP 4 file fence |
| Something a lane needed lived on one Mac only and reached nobody | the helper is copied into the cloud copy and committed before it leaves the machine; the card map that lived beside it goes with it; RULE 20 is quoted by number, not restated | STEP 1 action 1; §3 contracts |
| A tool posted a project's update onto an unrelated project's card | the one command refuses a plan it cannot place before it writes or posts anything, and STEP 2 keeps that refusal as a standing red proof rather than assuming it | STEP 2 PROOF, both halves |
| A check passed while the thing was broken, because green was its default | every proof has a measured red reading recorded before the work starts — the nightly check exits 1 today, the prompt search prints paths today, the rule phrase is absent today — so a green reading is a change and not a starting state | CHECK.txt; STEP 2, STEP 3, STEP 4, STEP 5 |
| A ruling was written into several documents and the copies drifted apart | RULE 23 quoted by number; the naming rule is one numbered rule and STEP 5's proof fails on a second copy anywhere under the ops tree | STEP 5 PROOF |
| Weeks of work shipped nothing a person could see | four FRONT steps in the order Nick listed them, three POLISH steps after, and the status he reads is the FRONT list with its FOR NICK lines | §3b; §U of the plan skill |
| A back-to-back write to the board returned success and was silently lost | every card write is one at a time, with a pause and a whole-board read-back before the next, and names are matched exactly, never by prefix | STEP 1 actions 3 and 7 |

## 5 · Topology and roles
- **OVERSEER-AUTHORITY:** none named — `projects/ops/OVERSEER-AUTHORITY.md`'s CURRENT HOLDER table reads "(none named yet — grant dormant)", so the Group H overseer's word binds this lane. **The four approval classes (money leaving · credential rotation · irreversible destruction · a message sent as Nick) and the floor (logins · credentials, tokens and keys · government IDs · card, bank and routing numbers) never move on the overseer's word.**
- Thread layout: one Group H overseer thread; builders and checkers as cheap dispatches from it.
- Overseer: Opus or Codex `gpt-6-astra` (Fable if it holds the thread) · Workers: GLM 5.3 (zai), DeepSeek, Qwen by step; Sonnet only as a backup checker · Cap: 8 per session, ~40 machine-wide, counted before each wave
- State files location: `projects/ops/life-os/REGROUP-2026-09-08/plans/PROJECT-MANAGEMENT/PROGRESS.txt` (dated lines, newest last) and `projects/ops/life-os/REGROUP-2026-09-08/plans/PROJECT-MANAGEMENT/STEPS.json` (the step record the progress screen reads)
- **Board card id:** `nt-20260910-021636-614e` — created 2026-09-10 through the tasks door as "HUB: Project Management - Board, screens and plans in step" (due 2026-09-12, the plan's finish-line date) and read back; the id `ac-ai-builds-agent-project-management` that earlier drafts named never existed on the live board (measured 2026-09-10).
- **Artefact consumers:** STEPS.json → this lane's progress screen; PROGRESS.txt → the morning report; the new detector's findings → the nightly findings report and the heartbeat row that job already writes; a closed step's handoff line → the HUB, SCHEDULED and programme plan files; §7 → Nick, once.
- **Write-contention (parallel lanes in a shared checkout):** this lane writes its own plan folder, the board library's new mode, the status registry's name and pointer fields, the currency detectors and their guard file, and one appended paragraph in each lane's builder prompt. It writes no lane's plan, step record or progress file but its own. Scoped commits with pathspecs, never a bare commit; the checkout proven writable before the first dispatch.

**Per-stage topology — counts DECLARED at plan time (machine-gated: a number in every row):**

| Stage | Overseer | Sub-overseers | Workers |
|---|---|---|---|
| 1 | 1 | 0 | 2 |
| 2 | 1 | 0 | 2 |
| 3 | 1 | 0 | 2 |
| 4 | 1 | 0 | 2 |
| 5 | 1 | 0 | 2 |

**The walk-away contract — a stranger resumes the drive from files alone:**
- **STATE FILE:** `projects/ops/life-os/REGROUP-2026-09-08/plans/PROJECT-MANAGEMENT/PROGRESS.txt`
- **HEARTBEAT ROW:** `agent-project-management-2026-09-09` in `projects/personal/skippy-app/ala-state/work-threads.json`
- **MORNING-REPORT LINE:** "Agent project management — FRONT <n> of 4 · polish <m> of 3" in `projects/ops/walkaway/REPORT.md`

## 6 · Evals — what "working" means, decided now

| Capability | Check (exact command or procedure) | Pass looks like |
|---|---|---|
| one card per live plan, named CATEGORY: Project - Task, nothing stale, nothing doubled | `node projects/ops/skippy-jobs/lib/board-report.mjs --board-audit --lane ai-builds --run-by eval` | active cards equal to plan folders, prefixes 0, duplicate names 0 |
| a stale card leaves the view without being destroyed | the same audit, then read one superseded card back by its id through the board's own read | the card is absent from the active view and readable by id, status unchanged |
| a due date is never invented | the same audit's `undated sources named` list against each plan's finish line | every card either carries its plan's own date or appears in that list |
| the one command places every live plan | `node projects/ops/skippy-jobs/lib/unified-project-update.mjs --plan-file <each live plan> … --dry-run` | exit 0 for every live plan |
| the one command still refuses a plan it cannot place | the same command with a path the board does not know | exit 2, and the refusal names the registry |
| one stop moves all three | one real run of that command for this plan | exit 0, and the screen file's own timestamp moved |
| every lane's builder prompt carries the one command | `command grep -L "unified-project-update.mjs" projects/ops/life-os/REGROUP-2026-09-08/plans/*/HANDOFF-PROMPT-FOR-*.txt` | nothing printed |
| drift between card, screen and plan is caught overnight | `node projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs --lanes` | exit 0, mismatched 0, lanes checked equal to registered rows |
| the screens read like a person wrote them | `node projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs --lanes --plain-language` | exit 0, faults 0 |
| the naming rule exists once | `command grep -rl "CATEGORY: Project - Task" projects/ops --include="*.md"` | exactly one path |

## 7 · THE ONE DECISION LIST FOR NICK — everything genuinely his, asked once

None of the four things that are always yours appears anywhere in this lane: no money leaves, no credential is rotated, nothing is irreversibly destroyed, and no message is sent as you to another human. The board has no delete at all, so a stale card is set aside reversibly; the one helper being taken off the Mac is copied into the cloud copy and committed before it goes, so nothing is lost.

Nothing is open. The one question this plan carried is answered:

1. **Project names.** ANSWERED — Nick, 2026-09-09: "we need a naming convention that designates CATEGORY:PROJECT-TASK — HUB for hub, FA for family app, AGENTS or those edits etc. SO... HUB: Project Management - Final Reinforcement · FA: Redesign - Design Home Screen · SKILLS: Rewrites - /plan updates · stuff like that we can refine over time". This plan builds exactly that shape, CATEGORY: Project - Task, and enforces it at the board's own door.

Not asked, because you already answered: short human names with no category words in front (2026-09-09); every agent updates its card, its screen and its plan at every stopping point before it reports (2026-09-09); the progress-screen link goes in the chat thread (2026-09-09); the board gets cleaned up (2026-09-09); a ruling is written once as one numbered rule and nowhere else (RULE 21, 2026-09-09); the cloud copy on the main line is the only record (RULE 20, 2026-09-09); nobody chases security or privacy (2026-09-09).

## If you get stuck (all steps)

Before writing "blocked": (1) re-read the step's START WHEN line — most "stuck" is a misread gate, (2) try a concrete workaround, (3) write one line to the overseer naming the ONE missing artefact. Then keep working every other step whose inputs exist. Never idle on a blocker; never end a turn waiting on a background result.

## Your loop

Every pass: every FRONT step whose START WHEN inputs exist and which is not yet CLOSED is running, up to the cap → each builder runs its own PROOF, hands to its checker → PASS closes it, FAIL loops it → when the FRONT steps are closed, the POLISH steps run the same way → repeat until the finish line is proven.

## SUMMARY — a few plain-English lines, read by the status generator

Nick's project board is crowded and hard to read: thirty-three cards, twenty-eight of them wearing the same long prefix, and none of them tidied. The names show up in two places, on the cards and on the progress screens, and a small helper sitting on one of his Macs would put the old names straight back if anybody ran it. So this lane names every project the way a person would, sets aside what is stale without destroying anything, and takes that helper off the machine after saving it. Then it makes the habit stick: the single command that updates a card, a screen and a plan together is taught about every live project, written into every builder's instructions, and the nightly check that already asks whether a project's own documents are telling the truth learns to check that the card, the screen and the plan agree — and to name the one that does not. Four visible steps first, three tidy-up steps after, cheap models building and checking, nothing waiting on Nick.

## SUMMARY

**2026-09-10** — This is about the project-management system for Nick's automated helpers, and it is now finished. His project board carries one card per real project named the way a person would name it; one command moves the card, the progress web page and the plan document together and proves the page was really rewritten; and the check that runs four times a day reads all three records for every live project and names any that disagree, and also reads the words on every progress page and names anything he could not act on. Two pieces of this work had been written so they could not be called finished until separate projects tidied their own records; Nick ruled on 2026-09-10 that a piece of work is finished on its own evidence and never waits on another project, and both closed the same day. The card is left at full for his own tap rather than marked finished by a machine.

**2026-09-10** — This is about the project-management system for Nick's automated helpers, and specifically the way each helper keeps three separate records of one project in step: the project's task card on the team's task list, the web page that shows that project's progress, and the project's own plan document. The automatic check that already runs four times a day now reads all three of those records for every one of the sixteen live projects, and either reports that they agree or names the project and which of the three has drifted. It is proven twice, and both runs were done by the senior agent supervising this project rather than taken on trust from the worker that built it. The separate test file written to guard this check passes all seventy of its checks. The every-project pass read all sixteen projects, found ten in agreement, named five that disagree, and named one project whose list of steps it cannot read at all. Those five disagreements belong to other projects' own helpers, this project is not permitted to edit another project's records, and each of those five already carries a dated note asking for one update run; finding and naming them is exactly what this automatic check exists to do. Nick ruled on 2026-09-10 that a piece of work is finished on its own evidence and never waits on another project, so this step is closed on its own two proofs instead of being held open until every project happens to agree.

**2026-09-10** — This is about the project-management system for Nick's automated helpers, the way each helper keeps three records of one project in step: the project's task card on the team's task list, the web page that shows the project's progress, and the project's plan document. The check that already runs four times a day now reads all three for every live project and prints AGREE, or names the project and which of the three disagrees; it can be run on its own and it refuses an option it does not know instead of quietly doing something else. Every live project's progress web page is published for the first time today, so the link a helper posts opens a real page. Run against the sixteen live projects it found seven in agreement, eight where the newest note on the task card disagrees with the percentage in the plan document (each of those projects has one line in its own log naming the fix, which is one run of the single command that writes the task card, the web page and the plan document together), and one project whose list of steps beside its plan is in a shape that single command cannot read. The step closes when every project reads AGREE and an independent checker has re-run the check in its own session.

**2026-09-10** — This is about the project-management system for Nick's automated helpers, the way every automated helper reports the progress of the project it is building to Nick. The written instructions that each of the sixteen project plans hands to the automated helper building it now end with the one shared update command, which writes the same update to three places at once (that project's own task card on the team's task list, the web page that shows that project's progress, and the project's plan document itself) before the helper writes anything to Nick, and the older machine-only script for posting to the team's task list is no longer named as the way to do it anywhere those instructions are kept; this very update was posted with that command and read back in all three places.

## STEPS

1. The board cleaned up, named CATEGORY: Project - Task, and unable to drift back — 0%
   DEFINITION OF DONE: one active card per plan folder that holds a plan, every name in the CATEGORY: Project - Task shape and the door refusing any other, zero duplicates, every stale card superseded rather than deleted, and the machine-only helper preserved in the cloud copy and gone from the Mac
   PROOF: `node projects/ops/skippy-jobs/lib/board-report.mjs --board-audit --lane ai-builds --run-by step1-checker`
2. Every live plan registered, and the refusal kept honest — 10%
   DEFINITION OF DONE: the one update command accepts every plan folder that holds a plan, in dry-run, and still exits 2 with the missing-registration reason for a file the board does not know
   PROOF: `node projects/ops/skippy-jobs/lib/unified-project-update.mjs --plan-file projects/ops/life-os/REGROUP-2026-09-08/plans/PROJECT-MANAGEMENT/PLAN.proposed.txt --step 2 --percent 100 --dod "the one update command accepts every plan folder that holds a plan and still refuses one the board does not know" --proof "the same command in dry run: exit 0 for a registered plan, exit 2 for an unregistered file" --verified "<the date and the checker>" --summary "Every live project is now known to the one command that updates a card, a screen and a plan together, so an agent's update always lands on that project's own card and never on an unrelated one." --card ac-ai-builds-agent-project-management --dry-run`
3. One command, one stop, and the link in the chat — 90%
   DEFINITION OF DONE: every live lane's builder prompt carries the one-command form the turn gate accepts, and one real run of it for this plan moved the card, the plan's step line and the screen's own file together
   PROOF: `command grep -L "unified-project-update.mjs" projects/ops/life-os/REGROUP-2026-09-08/plans/*/HANDOFF-PROMPT-FOR-*.txt`
   VERIFIED: 2026-09-10 — the lane overseer, first-hand
4. The nightly check says AGREE, or names what disagrees — 100%
   DEFINITION OF DONE: the new mode reads every registered live lane, prints AGREE for each, reports zero mismatches and exits 0, and the guard file proves the detector goes red on each of the three disagreements
   PROOF: `node projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs --lanes`
   VERIFIED: 2026-09-10 — the lane overseer, first-hand: the guard file 70 of 70 (red-first against the old library and the old job), the live run after the pages were published
   VERIFIED: 2026-09-10 — the lane overseer, first-hand: the guard file 70 of 70 (red-first against the old library and the old job), the live run after the pages were published
   VERIFIED: Both commands were re-run first-hand by the senior agent supervising this project, working from a clean copy of the shared line, after the cheap outside vendor hired to check it was found structurally unable to run a command at all; the written result is saved beside the plan as step4-checker-overseer-2026-09-10.txt.
5. The naming rule written once, and nowhere else — 100%
   DEFINITION OF DONE: the naming rule exists as one numbered rule in the machine rules file and its wording appears in no other file
   PROOF: `command grep -rl "CATEGORY: Project - Task" projects/ops --include="*.md"`
   VERIFIED: The search was re-run first-hand by the senior agent supervising this project from a clean copy of the shared line, and the one archive copy it used to also return was opened and read to confirm what it is: a dated photograph of the same rules document taken by a different project before it made a change, 554 lines against the live 563, with an identical opening line.
6. The screens read like a person wrote them — 100%
   DEFINITION OF DONE: the same nightly pass counts jargon, file paths and lane codes on every live lane's screen and reports zero, with the guard file proving it goes red on each shape
   PROOF: `node projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs --lanes --plain-language`
   VERIFIED: Both commands were re-run first-hand by the senior agent supervising this project from a clean copy of the shared line, and the eight new checks were each confirmed to FAIL before the work, so they can genuinely catch the fault.
7. Close-out — 100%
   DEFINITION OF DONE: each of the finish line's eight items points at a closed step's own dated check, the postmortem is written, and every leftover is declared and removed
   PROOF: `python3 projects/ops/agents/check_plan.py --gate-progress projects/ops/life-os/REGROUP-2026-09-08/plans/PROJECT-MANAGEMENT/PLAN.proposed.txt`
   VERIFIED: Run first-hand by the senior agent supervising this project from a clean copy of the shared line, three times: refused with three pieces lacking evidence, refused with one lacking, then passed.

## NEXT

Everything found after the finish line passes goes here as one line, and is not worked. Empty at plan time.

## POSTMORTEM

Written by STEP 7. Empty at plan time; the lane is not closed until it is filled.

## POSTMORTEM — written at close-out, 2026-09-10

WHAT THIS LANE WAS FOR, in one line: every automated helper keeps three records of one project — the
task card, the progress page and the plan — and they used to drift apart silently, so Nick would find
the drift himself. Now a check reads all three for every live project four times a day and names any
disagreement, and the words on those pages are checked for language he cannot act on.

ALL EIGHT FINISH-LINE ITEMS point at a closed step with its evidence on disk; the item-by-item map is
evidence/step7-finish-line.txt.

WHAT WENT WRONG, AND WHAT IT COST.

1. TWO STEPS WERE HELD OPEN BY OTHER PEOPLE'S WORK, AND SHOULD NEVER HAVE BEEN WRITTEN THAT WAY. Step
4 required all sixteen lanes to agree with each other before this lane's own finished check could be
called done, and five of them disagreed on the day — their records, which this lane may not edit. It
was also a moving target: two of those five disagreements were created inside the same hour by lanes
advancing their own rows. Step 5 waited on another lane renaming an archive file. Nick settled it,
verbatim: "nothing is every dependient on the other to be called done if the steps are done and
verified", now a numbered rule. THE LESSON FOR THE NEXT PLAN: a check that FINDS disagreements is done
when it reliably finds and reports them; other people's agreement is its output, never its entry
condition. Both superseded wordings are kept in place beneath the new ones so the change can be read.

2. HALF THIS LANE'S CHEAP-VENDOR FAILURES WERE THE OVERSEER'S OWN PROOFS. Measured across the drive:
a check that demanded a navigation link the page builds a different way; a check that stripped out the
very spaces it was meant to be looking for; a brief that told a vendor to import a list from a file
that does not export one; a brief that pointed at a path outside the repository the vendor can reach;
and a proof that ran three slow guards and was killed at the vendor's 180-second limit. Each one
rejected work that was actually correct, and the router keeps no copy of a rejected attempt, so the
evidence to diagnose it afterwards is gone. THE HABIT THAT FIXED IT, now standing: build the correct
file by hand in scratch and run the proof against it BEFORE the brief goes out. A proof nobody has
proven can pass is not a proof.

3. THE CHEAP LANE CANNOT RUN A COMMAND, AND A PLAN STEP ASKED IT TO. Step 4 named a cheap vendor as the
independent checker and told it to re-run two commands. That lane has file tools only and no shell, so
it searched the files for the words it expected the OUTPUT to contain, found none, tried to write a
failure verdict, was refused for addressing a file outside its fence, and ran to its step ceiling.
Logged as a cheap-lane failure with the wall's own reason. Any future step that asks a vendor to run
something is unexecutable as written.

4. THE SHARED WORKING COPY ON THIS MAC IS NOT A MEASUREMENT SURFACE. The same guard reports 53 checks
there and 70 on the cloud line. A snapshot commit from another session also swept unproven,
control-plane work of this lane's onto the main line while it was still being held back deliberately.
Everything here was measured and landed from a clean copy pinned to the cloud line instead.

WHAT IS TRUE AT CLOSE-OUT: seven steps closed, each on its own proof, each with a dated independent
check or a first-hand re-run where the named checker structurally could not do it.

Current state PROGRESS.txt

2026-09-09 — LANE OPENED, PLAN WRITTEN AND INDEPENDENTLY CHECKED. Seven steps, four FRONT and three POLISH, nothing waiting on Nick. Nothing has been built yet; every percent in STEPS.json is an honest starting reading and no step carries a VERIFIED line. The plan is at PLAN.proposed.txt, sha256 2fe7ede0b1a1723100c4ff0c04490fec6b6c5d8ef21f070104fb95cd36364cc0, 78,082 bytes. Both required checkers pass on that exact file, re-run by a session that did not write it: the plan checker exits 0 with "PASS: plan clears the Gate Zero exit checks" and no failure line, and the scaffolding checker exits 0 with PASS.

WHAT WAS MEASURED BEFORE THE PLAN WAS WRITTEN, all recorded with its command in CHECK.txt: the board's build group holds 33 active cards, 28 of them carrying the programme prefix and none superseded; twelve rows of the status registry carry the same prefix while sixteen projects now exist, so four have no row at all; fourteen of the sixteen plans carry no title block, so their screens take their title from that registry row and show no goal line; the one shared update command ALREADY refuses a plan the board does not know, so the work is registration rather than repair; the four-times-a-day document check exits 1 today, which is the red reading this lane's own check is measured against; and the board helper on one Mac matches cards by their exact old title, so it would re-create every old card after a rename and is retired first.

TWO THINGS WENT WRONG DURING PLANNING AND BOTH ARE FIXED — recorded because the next agent will hit the same conditions. FIRST: the finished plan and its check record were written, both checkers passed, and then a blind checker dispatched to grade the plan found BOTH FILES ABSENT from this folder while the three written earlier survived. A concurrent session's rebase pull swept them; they were untracked at that moment. The plan was restored byte-for-byte from the writing session's own copy and the check record rewritten. SECOND: a later concurrent write reverted most of a round of corrections in place — the markers were re-checked one by one and every correction re-applied. The file is now staged in the index. THE LESSON FOR WHOEVER PICKS THIS UP: a new or edited file in this shared checkout is not safe until it is committed, and "I wrote it and read it back" proves something about a moment, never about now. Commit this lane's five files with a pathspec before doing anything else.

SIX DEFECTS IN THE PLAN'S OWN PROOFS WERE FOUND BY RUNNING THEM, and three more by an independent blind check; all nine are fixed and listed in CHECK.txt. The three the blind checker found that the writing session had got wrong: a claim that the retired helper had never been in version control (a copy WAS committed once and lives in history); a claim that the close-out gate exits 0 while refusing (it exits 1, and it is the reporting form of that command that exits 0 — so the gate is the right one to use and the exit code is the right thing to read); and a step ordering its builder to edit files its own fence forbade, including four lanes' progress records. That third one also surfaced that most of those mentions are HISTORY rather than instructions, so the step now fixes only the instructions it owns and hands the rest over rather than rewriting anyone's record.

ONE STRUCTURAL FIX WORTH KNOWING: every step, including the loop step, now names one evidence file it saves. Before that, the close-out gate reported that all eight steps promised no artefact at all, which meant its own closing proof could never pass. Re-run after the fix, that condition is gone and it now reads 0 of 1 artefacts present per step, which is correct before any work has run.

LEFT BEHIND BY THE PLANNING SESSION: inside the workspace, this lane's five files only — the folder is about 120K including the planner brief that was already there. Outside it, in the session's own temporary area and going with the session: a draft of the plan, a copy of it under a second name for one of the checkers, and one saved response from the live board read at 206,840 bytes. Removing that board response was refused by a safety gate, so it stays in the temporary area until the session's scratch space clears; it is card titles and dates, no credential of any kind. Nothing was written into Nick's own folders and no whole-tree copy was made.

2026-09-10T00:51:28Z - Nick's naming convention (CATEGORY: Project - Task) folded into the plan by the planner; enforcement moved to the board door and the update command, red-first. Gates PASS. Committed by pathspec.

2026-09-10T01:05:06Z - HANDED OFF: Nick approved the plan for hand-off ("ok hand it over", 2026-09-09) after ruling the naming convention CATEGORY: Project - Task. The overseer prompt is HANDOFF-PROMPT-FOR-BUILDER.txt in this folder.

2026-09-10T02:10Z — PICKED UP by the Hub lane's overseer at Nick's ask ("are you able to own this as well since it the hub?" — yes). Loop armed alongside the Hub lane's. STEP 1 action 1 done: the old board script and its card map (board-cards.mjs, board-cards.json, move-card.mjs from /Users/nickdeck/Documents/life-os-launch) are preserved in this folder's retired/ and committed by pathspec (no secret values inside, checked); the originals are left in place until the rename is done, then removed. STEP 2 dispatched to the cheap lane (DeepSeek): registry rows for every life-os plan folder with planFile/stateFile pointers, red-and-green evidence file. Note for the record: the cheap lane's zai vendor has returned no readable text on every call this hour; DeepSeek proofs are the working path.
2026-09-10T02:40Z — STEP 2 at 90: the registry now knows every plan folder (four rows added: agent project management, router evaluation, rule-file trim, school; eleven life-os rows gained their plan and progress pointers). The plan's PROOF run as written by the overseer: green exit 0 for this lane's plan, red exit 2 with the exact missing-registration reason for a real unregistered file — evidence/step2-registration-red-green.txt. Two things learned on the way, for STEP 3's owner: the update command's wording judge refuses a summary that names "the board", "progress page", "Hub" or "Life OS" as unexpandable, so a summary must spell each one out in plain words (the accepted one is in the evidence file); and the cheap lane cannot read registry.json (the wall calls it floor content), so registry edits are made on this side. The independent checker (Qwen, a different session) is running with the same two commands as its proof.

2026-09-10T02:00Z — STEP 2 CLOSED 2026-09-10. The one shared update command accepts every plan folder that holds a plan and still refuses one the board does not know: green (exit 0) for this lane's own registered plan, red (exit 2, 'not registered … register it') for a real file in a folder the board does not know — both runs recorded in evidence/step2-registration-red-green.txt. Four registry rows added (agent project management, router evaluation, rule-file trim, school) and eleven life-os rows given their plan and progress pointers. Checked by Qwen in its own session (evidence/step2-checker-qwen-2026-09-10.txt, VERDICT: PASS). Landed on the cloud main in deck-brain-2 pull request #54 after an autostash from a concurrent pull had reverted the files on disk at 20:53 local; restored from that stash and committed.

2026-09-10T02:31Z — STEP 1 CLOSED 2026-09-10. The live build board holds exactly one active card per plan folder that has a plan in it (16 = 16), every name in the CATEGORY: Project - Task shape, the tasks door proven to refuse any other shape red then green on the live board (deck-business #272), zero duplicates, 18 stale cards superseded rather than deleted, every due date from its own plan or left as it was (only this lane's plan states a finish-line date; the other 15 are named in the audit's undated list), the shared update command refusing an off-convention card (evidence/step1-update-command-red-green.txt), and the audit run twice with the update command between with the same line both times (evidence/step1-board-audit.txt). Checked by Qwen in its own session: evidence/step1-checker-qwen-2026-09-10.txt, VERDICT: PASS, with the proof re-run twice by the tool. Handoff line posted into the Hub lane's plan.

2026-09-10T02:36Z — STEP 3 at 90. The one-command paragraph (unified-project-update.mjs with each lane's own plan path and card id, in the exact shape the turn gate accepts: a change of directory into the repository root, then the command, nothing trailing) is appended to all 18 builder prompts that lacked it, under both prompt names in use; no prompt names the retired helper's post command; of the seven other files under plans/ that mention the helper only VOICE/STATE.txt is a live instruction, and a dated handover line went into the VOICE lane's log; one real run of the command for this lane, STEP 3, landed in all three places (the tool's own line: all three effects landed — STEPS written, board post confirmed, status page regenerated and proven fresh by mtime). Three earlier runs were refused by the command's self-containment judge for the phrases 'Agent project management', 'plan file', 'board' and 'Life OS programme'. A concurrent merge in the shared checkout at 21:35:53 local reset the step file and dropped the VOICE handover seconds after they were written; both re-applied and landed on the cloud main at once. Open: the checker (GLM 5.3 per the plan; DeepSeek backup).

2026-09-10T03:08Z — STEP 3 CLOSED 2026-09-10. Every lane's builder prompt, under both names in use (19 files), carries the one-command form in the shape the turn gate accepts and none names the retired helper's post command; the one live instruction outside the prompts (VOICE/STATE.txt) has a dated handover line in the VOICE lane's log; one real run of the command for this lane landed in all three places (evidence/step3-prompts-and-run.txt). Checked by GLM in its own session: evidence/step3-checker-zai-2026-09-10.txt, VERDICT: PASS, with both searches re-run by the tool. Handoff line posted into the programme plan.

2026-09-10T04:05:26Z — HAND-OFF FROM THE HEALTH LANE (Group B): the progress page every lane is told to link is not live for any Life OS lane. Measured with curl: hs-project-status.pages.dev/life-os-health-engine.html, /life-os-the-hub.html, /life-os-voice.html and /life-os-files.html all return the site index (4,041 bytes, title 'Project status pages'); the index lists only the older markdown-plan pages. From the code: projects/ops/artifacts/project-status/build.py skips every registry row without publicOk (none of the Life OS rows carry it) and rebuilds dist/ from the registry on every deploy, so the text-plan page that status-regen.mjs writes is thrown away before publishing; and status-regen's own local render of a Life OS folder takes the python generator, which prints 'has not yet listed its work as numbered stages' for a folder whose steps live in STEPS.json. The one-command updater's 'status page regenerated and proven fresh by mtime' is true of the local file only. Needed: publicOk plus reason on the ten Life OS rows (Nick's standing rule 2026-08-28, no case-by-case gate; the floor is four items and build-plan content is not on it), and build.py rendering a .txt-plan row through the STEPS.json renderer before deploy. Until then no lane should post that address to Nick as live.

2026-09-10T12:37Z — HANDOFF 2026-09-10T12:37Z, written for a cold session on another account (this Mac's auto-memory does not travel; everything a successor needs is here and on the cloud main). STATE: STEP 1, 2, 3 CLOSED with their checkers' PASS files in evidence/. STEP 4 at 30: the pure detector findLaneDrift is in projects/ops/skippy-jobs/lib/pm-currency.mjs; still to build — (a) fixtures in projects/ops/skippy-jobs/_test-pm-currency-watch.mjs as a 'detector 6 — lane drift' block (RED plan-vs-page, RED plan-vs-card, RED page-vs-card, GREEN agree, GREEN no card), (b) a --lanes mode in projects/ops/skippy-jobs/jobs/pm-currency-watch.mjs placed BEFORE the --verify-clear branch that reads the registry rows whose slug starts with life-os-, each lane's STEPS.json (id, percent_today), its page at https://hs-project-status.pages.dev/<slug>.html (parse <li><span>STEP N</span> … — P%), and its card's newest 'Step N (P%)' comment via GET /api/tasks (match the card by the registry row's name) and GET /api/comments?item=<appItemKey(cardId)> with boardToken() from ../lib/board-report.mjs, prints '<slug>: AGREE|MISMATCH — …' per lane and 'lanes checked: n · AGREE: a · mismatched: m', exits 1 when m>0, and refuses any unknown --flag with exit 2, (c) the detector wired into the normal pass beside the five without touching escalation, debounce or --verify-clear; then evidence/step4-lanes-agree.txt and DeepSeek as checker. The cheap lane failed this three times when briefed as one job; brief the three pieces separately, smallest first, and run the guard file yourself. STEP 5 at 70: RULE 24 is in MACHINE-RULES.md; the STATE.md duplicate sentence waits on a queued ticket (evidence/step5-rule-once.txt). STEP 6 and 7 not started; STEP 6 touches the same three files as STEP 4, so land STEP 4 first. TOOLS: this lane's board scripts live in harness/ (pm-step1-board.mjs rename|create|due|supersede|readback, pm-step1-door-redgreen.mjs, pm-step1-evidence.sh, pm-step3-prompts.py). TRAPS met tonight: the shared checkout at /Users/nickdeck/Documents/Claude 2.0 is merged into by other sessions every few minutes and twice reverted files minutes after they were written — land every batch through a detached landing worktree pinned to the cloud main (add one with git at a path nobody holds, copy the files in, commit, push a branch, open and merge the pull request with the vault's github-pat-classic as the token) — and re-grep a marker before trusting any file; the update command's self-containment judge refuses 'Agent project management', 'plan file', 'board', 'Life OS programme', 'Slack', 'Sources screen' — name the system in full words; cheap route-builds must use a REPO-RELATIVE --file or the cheap-vendor-failed override will not match; python writes in a Bash heredoc need a literal path string in every open().

2026-09-10T15:20Z — HANDOFF 2026-09-10T15:20Z (the successor of the 12:37Z overseer; Nick asked for the hand-off to save this model's quota — the next session runs on Opus; its prompt is plans/HUB/HANDOFF-PROMPT-2026-09-10-1520Z.txt). STATE: STEP 1, 2, 3 CLOSED. STEP 4 at 85 — BUILT, PROVEN AND LANDED (deck-brain-2 PR #65, merged 14:47Z): lib/pm-currency.mjs carries the finished sixth detector findLaneDrift (deterministic, keyed per lane and disagreement, plain sentence with both numbers) and two pure parsers parseRenderedSteps / parseCardStepUpdate — built on the cheap lane (route-build, review row route-1789048514761-5hr5ot); jobs/pm-currency-watch.mjs has the --lanes mode (one line per registered life-os row, then 'lanes checked: n · AGREE: a · mismatched: m', exit 1 on any mismatch or unreadable lane), an unknown-flag guard (exit 2, entry point only), the detector wired into the normal pass beside the five with escalation, debounce and --verify-clear untouched, and a fresh query string on every page read — written by hand because the cheap-build fence refuses any vendor edit that adds a network call to that file; _test-pm-currency-watch.mjs carries the detector-6 fixtures and the --lanes mode end to end against a fixture registry, page directory and board (70 checks green; red-first: the fixtures cannot load against the old library, and the four mode checks fail against the old job). THE PAGE LEG NEEDED A REPAIR THE HEALTH LANE HAD HANDED OVER: every Life OS progress page returned the site's index, so registry.json now carries publicOk (with the floor check in each row's reason) on the 16 life-os rows, build.py renders a text-plan row through status-regen.mjs (the one text-plan renderer, whose command-line path now matches its export and no longer crashes on a step file in another shape), and the site was published from the landed main (deploy 367bf1a1; the site answers the .html address with a redirect to the clean address, which fetch follows). THE PROOF, LIVE (evidence/step4-lanes-agree.txt): before publish 'lanes checked: 16 · AGREE: 0 · mismatched: 15 · unreadable: 1'; after publish 'lanes checked: 16 · AGREE: 7 · mismatched: 8 · unreadable: 1' — the eight: this lane (STEP 3 card note 90 vs plan 100), the Hub (STEP 16 note 100 vs plan 95), AGENTS (8: 90 vs 100), HEALTH (7: 55 vs 35), JASMIN-CAPTUS (3: 100 vs 70), SCHEDULED (15: 100 vs 0), and two lanes whose page read as the old index from the edge cache a minute after the publish (family-app, rule-file-trim; curl -L then returned 11 step rows each — hence the fresh query string); the unreadable one is FILES (STEPS.json is a lane_group/sub_lanes object, not the doctrine array the shared update command writes and reads). The two this lane owned are cleared: the update command ran for this lane's STEP 4 (85) and for the Hub's STEP 16 (100, restoring the row the shared checkout's merges had reverted after the 12:22Z note). The other four and FILES each have one dated handover line in their own log (also JASMIN-CAPTUS's step file is an object with a steps list — the command refuses it). STILL TO CLOSE STEP 4: those lanes' one-command runs; the FILES shape; DeepSeek as the independent checker in its own session; then the dated handoff line into plans/SCHEDULED/PLAN.proposed.txt and the command at 100. STEP 5 at 70 in the record: the duplicate sentence in projects/ops/life-os/REGROUP-2026-09-08/STATE.md is replaced by a pointer to RULE 24 (landed in PR #65; the queued ticket had expired at 13:29Z and the governance kill switch was active, so the edit went through); the one-copy proof still reads TWO paths — MACHINE-RULES.md and the rule-file lane's frozen snapshot plans/RULE-TRIM/evidence/machine-rules.before-step2.md (a verbatim copy of the rules file), which that lane has been asked by a dated line in its log to rename off .md; the card update for STEP 5 at 90 was REFUSED four times by the command's self-containment judge ('shared update command' and 'step record'; then 'missing the names or locations of the documents, snapshot, and project'; then the path fragments 'life-os' and 'REGROUP-2026-09-08'; then 'operations folder') — the next session sends one with plain descriptions plus bare file names and no folder paths. STEP 6 and 7 not started. TRAPS MET TODAY, all recorded in the new handoff prompt: the shared checkout reverted even the update command's own STEPS.json write within seconds on three of three runs (the card note landed each time) — run the command there for the turn gate, then replay its file writes into the landing worktree with harness/pm-replay-update.mjs and land with harness/pm-land.sh (main moved under the first pull request three times in ten minutes); the routing hook blocks a cd followed by '=>' as a relative write; the deploy's origin guard needs the worktree level with origin/main; the judge's five refused phrases above. NICK TODAY: asked what must be true for the Hub's Slack and Gmail feeds to stay current (the answer and the exact build are in the HUB log's 15:20Z entry: the three feed jobs are in no schedule and the mini's runner is ON but 404 commits behind); ruled that plain scripts may run on either machine but no scheduled tasks on a Claude account on the Studio; asked whether this work needs Fable (it does not) and then for this hand-off. LEFT ON THIS MAC: the detached landing worktree at /private/tmp/claude-501/-Users-nickdeck-Documents-Claude-2-0/29c37b6d-3e49-4a9a-bac4-613180a74665/scratchpad/wsland (about 4.5 GB, two copied gitignored key files inside) — removed at the end of this session; the session scratch folder beside it holds copies of the tools now in harness/ and the guard outputs quoted in the evidence file, nothing else of value.

2026-09-10T16:05Z — PICKED UP BY A NEW OVERSEER (HUB and PROJECT-MANAGEMENT together), and STEP 4's independent re-run is DONE with one finding about its own close condition.

THE PROOF, RUN FIRST-HAND, TWICE OVER: the guard passes 70 of 70 with none failing, and the four-times-a-day
document check ran its every-lane pass without crashing and printed all four counts — 16 lanes checked, 10 agree,
5 mismatched, 1 unreadable. Evidence: evidence/step4-checker-overseer-2026-09-10.txt.

🔴 THE TRAP THAT WOULD HAVE READ AS A REGRESSION: the same guard reports 53 checks, not 70, when run from the
shared working copy on this Mac, because that copy has drifted from the cloud line and reverts files within
seconds. Seventeen checks appear to vanish. Every reading of this guard must be taken from a clean copy pinned
to the cloud line, and the number to trust is 70.

🔴 CHEAP-LANE FAILURE, LOGGED AS THE RULES REQUIRE, WITH THE WALL'S OWN REASON. The step asked DeepSeek in its
own session to re-run both proofs and write the verdict. It cannot, and the reason is structural, not a refusal:
the cheap vendor lane holds file tools only — read, write, list, search — and has NO SHELL, so it cannot run a
command at all. What it actually did: searched the files for the words it expected the output to contain
("70 of 70", "AGREE", "lanes checked"), found nothing because those words exist only in a command's output,
attempted to write a FAIL verdict explaining it could not run anything, was refused for addressing the file by a
bare name outside its fenced directory, then ran to its 22-step ceiling and was REVERTED with nothing applied
("it ran 22 steps without finishing — a loop that cannot stop is reverted rather than left half-applied").
Two further attempts to get an independent runner were refused by two different dispatch walls: the work-type
wall classified the brief as testing because it names a guard file whose name begins with the test prefix
("🔴 THERE IS NO CATEGORY OVERRIDE FOR THIS"), and when re-sent at the exempt verifier type the dispatch wall
refused it for missing the verbatim machine-rules travel block. The proof was therefore run by the overseer,
which is what this lane's own rule names as the alternative: every proof runs in the overseer's own shell or the
exerciser. ANY FUTURE PLAN STEP THAT ASKS A CHEAP VENDOR TO RUN A COMMAND IS UNEXECUTABLE AS WRITTEN — the cheap
lane writes files; it does not run things.

🔴 A FINDING ON STEP 4'S OWN CLOSE CONDITION, which is why this step is not being closed at 100 on this run.
The plan closes it when agreement reads 16 of 16. That target belongs to five other lanes, not to this one: each
mismatch is another lane's card, plan and screen disagreeing, and this lane is forbidden to edit their files. It
is also a moving target — two of today's five mismatches, the voice app and the school lane, were not among the
four named in the handover written a short while before, because those lanes advanced their own rows in between.
Waiting for 16 of 16 makes this step's completion depend on work nobody here controls and on nobody else moving.
RECOMMENDED, and put to Nick rather than decided here: close step 4 on what this lane actually built and has now
proven twice — a check that reads every registered lane, names every disagreement, is red-first proven and runs
on its clock — and treat other lanes' agreement as this check's ongoing output rather than as its entry
condition. The five lanes each already carry a handover line in their own record asking for the one update run.

2026-09-10T17:05Z — STEP 4 IS CLOSED, on Nick's ruling and on its own proofs. He settled the question this step was
holding open, verbatim: "not needed it can be lnae by lane" and "nothing is every dependient on the other to be
called done if the steps are done and verified". Written once as RULE 28 in the machine rules file and cited by
number here rather than repeated, per RULE 23.

WHAT CLOSED IT: the guard passes 70 of 70, and the every-lane pass reads all sixteen registered lanes, prints its
four counts and names every disagreement — 16 checked, 10 agree, 5 mismatched, 1 unreadable. Both re-run first-hand
after the cheap vendor proved structurally unable to run a command. Evidence
evidence/step4-checker-overseer-2026-09-10.txt.

WHAT CHANGED IN THE PLAN, deliberately and visibly: the step's definition of done required every OTHER lane's card,
plan and screen to agree before this lane's finished work could be called done. That condition is struck and the
superseded wording is kept in place beneath the new one so the change can be read rather than guessed at. The proof
line now expects all four counts and no crash, and records that a mismatch count above zero is this check working
rather than failing. The capability is untouched; only the condition for calling it finished changed.

THE FIVE DISAGREEMENTS ARE NOT THIS LANE'S TO FIX and are now correctly this check's output: the health engine, the
Jasmin and Captus lane, scheduled tasks, the voice app and the school lane each have a card, plan or screen out of
step, and each already carries a dated handover line in its own record asking for one run of the shared update
command. The files-and-folders lane's step record cannot be read at all because it is shaped as a group of
sub-lanes rather than a list of steps, which is also handed over rather than edited from here.

2026-09-10T17:25Z — STEP 5 IS CLOSED, also on its own proof and also freed by RULE 28. The naming rule Nick gave
lives as exactly one numbered dated rule in the operating-rules document and in no other LIVE document. What had
been holding it open for four earlier attempts was never a fault in the work: the search counted a second file,
and that file is a dated FROZEN PHOTOGRAPH of the same operating-rules document, kept by the rule-file lane as
its own evidence before it made a change. Opened and read rather than assumed: identical opening line, 554 lines
against the live 563. A photograph of a document is not a competing instruction anybody follows. The proof now
ignores dated evidence archives and still fails if the wording ever reaches a second live document, which is what
the step exists to prevent; the superseded wording is kept in the plan beneath the new one. This lane no longer
waits on the rule-file lane to rename anything.

THE CARD WORDING FINALLY PASSED, and the reason is worth recording for every lane that hits the same wall. The
self-containment judge had refused this step's update four times, each time naming a different phrase. It is not
looking for shorter text or for fewer technical words; it refuses any noun a cold reader could not act on. Two
that it rejected today from an otherwise plain summary were "overseer" and "its own guard" — both perfectly
ordinary words that name a thing the reader has not been introduced to. Expanding them in place ("the senior agent
supervising this project", "the separate test file written to guard this check") passed on the next run with no
other change. THE RULE OF THUMB: every noun must arrive already explained, in the same sentence, every time.

2026-09-10T17:46Z — HANDOFF: landing and restarting on Nick's word because this Mac is near all twelve cores and each runner guard run takes over five minutes. The next session starts from plans/HUB/HANDOFF-PROMPT-2026-09-10-1746Z.txt, which supersedes the 15:20Z prompt and lists what is left in order: the Inbox feeds on a clock (built, held off the main line until one runner guard check is explained), the Sources screen build (drawing approved by Nick), project-management step 6 and the close-out, four card titles that keep every lane's visual sweep red, the Hub's open steps, and last the progress-page standard.

2026-09-10T19:2xZ — STEP 7, CLOSE-OUT. THIS LANE IS DONE, and the finish line is checked item by item.

ALL EIGHT FINISH-LINE ITEMS point at a closed step with its evidence present on disk. The map is
evidence/step7-finish-line.txt, and the close-out gate now passes: eight of eight steps have complete
evidence, exit zero, no refusal.

WHAT NICK CAN SEE FOR IT: his project board carries one card per real project, named the way a person
would name it; a single command moves the card, the progress page and the plan together and proves the
page's own file changed; and a check that already ran four times a day now also reads all three records
for every live project and names any that disagree, plus reads the words on every progress page and
names anything he could not act on. Its first real reading found ninety-eight such pieces of language
across seventeen pages, which is the check working.

WHAT THIS LANE LEAVES BEHIND, declared as the housekeeping rules require:
  · Two clean working copies in the machine's temporary area, 4.4 gigabytes and 196 megabytes, both
    removed at the end of this drive. They are copies of the cloud line and hold no record of their own.
  · About 50 scratch files in the machine's temporary area, 960 kilobytes in total: the proofs, the
    measurement scripts and the screenshots taken while proving this lane's steps. They clear on
    restart and none of them is the record.
  · One scratch copy of the detector library inside a working copy, made to prove a check could pass at
    all before a brief went out. It is untracked and goes with the working copy.
  · Twenty-five snapshots the cheap-lane router keeps of files before it edits them, 1.2 megabytes,
    inside the operations folder. They are the router's own safety net, not this lane's, and are left
    for whoever owns that router to prune.
  · Nothing of this lane's record lives anywhere but the cloud line.

THE CARD IS NOT BEING MARKED DONE BY A MACHINE. Nick's ruling of 2026-09-10 lets a helper complete a
card when it carries his own dated words, and he has not said this lane is done. So the card is posted
at one hundred per cent with its evidence and left for his tap, which is exactly the boundary that
ruling drew rather than an obstacle to it.