Scheduled tasks — rebuilt from scratch (2026-09-11)

The actual documents the agents read and work from, shown exactly as they are on disk — not a summary. See the progress view instead · All projects

Plan PLAN.md

# Scheduled tasks — rebuilt from scratch on the Mac Studio and the cloud

**This is the one governing file for the scheduled-task rebuild.** Nick, 2026-09-11: *"this is a standalone
task. Everything else should be retired. Like, the Zion plan, the lifeOS schedule task plan, neither of them
hold any water anymore because we've kind of started from scratch. So I would say have this be its own file,
its own doc."* It replaces PLAN-ZION-7-scheduled-tasks.md (projects/ops/zion) and the Life OS SCHEDULED lane
(projects/ops/life-os/REGROUP-2026-09-08/plans/SCHEDULED), both marked superseded the same day. Nothing from
either is assumed still needed; anything reused here was re-decided with Nick on 2026-09-11.

**Board card:** `ac-ai-builds-life-os-scheduled-work-rebuilt-from-scratch-plan` (renamed to this project).
**Status page:** registry slug `scheduled-rebuild`.

## 0 · Gate Zero receipts

- **Failure Mode Registry loaded:** 2026-09-11, from `.claude/skills/plan/references/failure-registry.md`.
- **Canonical specs loaded:** plan doctrine and template; `projects/ops/MACHINE-RULES.md` (RULES 20, 35, 37); `projects/ops/agents/CODE-STANDARD.md`; `projects/business/business-app/HUB-AGENT-GUIDE.md`; the skippy-jobs README and runner SCHEDULE; the feed-watchdog registries.
- **Ownership check:** this file is the sole governing plan for the scheduled-task rebuild; PLAN-ZION-7-scheduled-tasks.md and the Life OS SCHEDULED lane were marked superseded on 2026-09-11 on Nick's word, so no second plan for this project exists.
- **Expected inputs confirmed to exist:** the live registries on both Macs (dumped 2026-09-11 after a checker corrected the first dump), the runner's 59 active and 111 switched-off entries, the 43 "on" prompt folders on the mini, the Hub's task store (565 rows), the 41-SOP library, the vault entries for Cloudflare, Fly, Stripe, Wise and the Slack bot.
- **PLAN AUTHOR:** the Studio session Nick drove live on 2026-09-11 (account noah.o.deck@gmail.com), with Nick's item-by-item answers on record in the SUMMARY.
- **COLD READER:** the cloud-placement decision had a skeptic (proceed with changes) and a cold verifier (agree with a named change) on 2026-09-11; the Monday audit task had a spec-breaker cold read the same day; every remaining step gets its own fresh checker at close.
- **PROMPT-SPEC scan (P1–P7):** the open terms were resolved with Nick on 2026-09-11: "hide" not delete for Hub tasks; subscription tokens not API; "everything cloud, never local first"; Nick-first on Neeko nudges; one weekly Fable audit; forwarding for invoices. No open identity question remains.

## 3b · Execution map

A task is DONE only when its review-ledger row is CLOSED by a reviewer that is not the builder. A step is DONE only when a checker that did not build it reads the real run back and says so.

**Evidence root:** `projects/ops/scheduled-rebuild/evidence/` — one file per step, named `step-<NN>-<what>.txt`.

| Stage | # | Task | Gate to enter | EXECUTOR | CHECKER | DONE-PROOF | Ends when |
|---|---:|---|---|---|---|---|---|
| Foundation | 1 | Cloud heartbeat store, Hub Status reader, feed-watchdog reader, and this plan's proof tool | nothing — first step | DeepSeek/Qwen via the router; Sonnet reviews | Opus, fresh session | `node projects/ops/scheduled-rebuild/tools/prove.mjs --step 1` — **CREATED BY STEP 1 OF THIS PLAN** | `PASS step 1 heartbeat=cloud status_row=1 watchdog_flags_stale=1` |
| Foundation | 2 | Hub ticks scheduler on Cloudflare (6 ticks + calendar push) | step 1 CLOSED | DeepSeek/Qwen via the router; Sonnet reviews | Opus, fresh session | `node projects/ops/scheduled-rebuild/tools/prove.mjs --step 2` — **CREATED BY STEP 1 OF THIS PLAN** | `PASS step 2 days=7 gaps=0 duplicates=0 mac_copies=off` |
| Live surfaces | 3 | Realtime captures: Slack, WhatsApp, Gmail reach the Hub live | step 1 CLOSED | DeepSeek/Qwen via the router; Sonnet reviews | Opus, fresh session | `node projects/ops/scheduled-rebuild/tools/prove.mjs --step 3` — **CREATED BY STEP 1 OF THIS PLAN** | `PASS step 3 slack_ms=<n> whatsapp_ms=<n> gmail_ms=<n> all_under=60000` |
| Live surfaces | 4 | Hub data refresh without Monday | step 1 CLOSED | DeepSeek/Qwen via the router; Sonnet reviews | Opus, fresh session | `node projects/ops/scheduled-rebuild/tools/prove.mjs --step 4` — **CREATED BY STEP 1 OF THIS PLAN** | `PASS step 4 feeds=<n> stale=0 monday_refs=0` |
| Household | 5–7, 10–13 | Family feeds, finance, reminders, briefings, kids | step 1 CLOSED | Sonnet composes words; DeepSeek/Qwen builds the rest | Opus, fresh session | `node projects/ops/scheduled-rebuild/tools/prove.mjs --step <n>` — **CREATED BY STEP 1 OF THIS PLAN** | `PASS step <n> channel=<name> received_at=<time> within_cadence=1` |
| Guards | 8–9 | Watchdogs; notebooks retired | step 1 CLOSED | DeepSeek/Qwen via the router | Sonnet, fresh session | `node projects/ops/scheduled-rebuild/tools/prove.mjs --step 8` and `--step 9` — **CREATED BY STEP 1 OF THIS PLAN** | `PASS step 8 aged_feed=repaired card=fyi` and `PASS step 9 notebooks=0 writers=0` |
| Neeko | 16–19 | Hub cleanup; hourly audit; SOP oversight; Friday digest | step 4 CLOSED | Sonnet | Opus, fresh session | `node projects/ops/scheduled-rebuild/tools/prove.mjs --step 17` — **CREATED BY STEP 1 OF THIS PLAN** | `PASS step 17 seeded=2 bumps=2 distinct_wording=1 other_cards_touched=0` |
| Reviews | 14–15, 20–21 | Standups/indexing; Larry; weekly Fable audit; Benito | step 22 CLOSED | Opus/Fable where the step names it; scripts otherwise | Sonnet, fresh session | `node projects/ops/scheduled-rebuild/tools/prove.mjs --step 20` — **CREATED BY STEP 1 OF THIS PLAN** | `PASS step 20 first_run=<date> report_lines=<n> learnings_delta=<n>` |
| Retirement | 22–25 | Token profile; minis off; Jasmin slot check; old plans and cards cleared | steps 1–21 CLOSED for 23 | scripts via the router; Nick for the login | Opus, fresh session | `node projects/ops/scheduled-rebuild/tools/prove.mjs --step 23` — **CREATED BY STEP 1 OF THIS PLAN** | `PASS step 23 minis_loaded=0 hours=24 stale_feeds=0` |

## 4 · Regret Check

| Failure mode (registry entry) | The measure in THIS plan that prevents it | Where it lives |
|---|---|---|
| A second system was built because the first was invisible | Both old plans are marked superseded in place and their cards cleared; this file names itself the only plan and the status registry points only here | header, step 25 |
| A document, label, or comment was believed over the live system | Every step's DONE is a real run read back from the live surface, never a prompt file or a registry entry that says "on" | STEPS preamble, step 1 proof |
| A detector's death was invisible because only its target read it | The cloud heartbeat store is built first with two readers (Hub Status and the feed watchdog) before any job leaves the Mac | step 1 |
| An absence was asserted without opening the store that would hold it | The first registry dump was wrong and was corrected by an independent checker before any decision used it; the corrected numbers are recorded above | measured section |
| Session rules never reached the subagents doing the work | Every dispatched brief carries ROLE and the MACHINE RULES block; the Monday audit task pastes it verbatim | step 20 |
| Work was written to a queue no reader ever visits | Step 16 clears the 178 overdue Hub tasks before Neeko's first run so its bumps land on live work, not a graveyard | steps 16, 17 |
| A decision settled once re-opened elsewhere, or two copies of a rule disagreed | Nick's cloud-first ruling is written once as RULE 35 and the instructions-file line that contradicted it is corrected under his ticket | RULE 35, step 9 |

## 1 · Goal and definition of done

Every recurring job this ecosystem needs runs from the Mac Studio or from the cloud, each one a plain script,
a cheap-model job, or a Claude task at the tier its judgment needs, each with a heartbeat a reader can see and
a watchdog behind it, so both Mac minis can be switched off and Nick never has to think about scheduling again.

- **WHERE IT LIVES:** scripts in `projects/ops/skippy-jobs/jobs` run by the Studio's job engine or by the one Cloudflare scheduler; token tasks under `~/.claude/scheduled-tasks` on the noah.o.deck@gmail.com account; the last-run record in the cloud store each app already uses; this file as the only plan. · **HOW WE KNOW:** the status registry row `scheduled-rebuild` points only here and the two old plans carry a superseded banner.
- **WHAT IT MUST DO:** (1) keep every app's data fresh on its stated cadence; (2) send every household and team message on time on the right channel; (3) show every job's last run in one place; (4) alert nobody about the machinery itself, only fix it; (5) run on subscriptions, never the API, unless a job cannot. · **HOW WE KNOW:** each step's PROOF is a real run read back on the live surface.
- **HOW IT'S USED:** nobody uses it directly. Nick reads his morning briefing, the team reads the Hub, Chantelle reads her WhatsApp message, the kids see their day; the Hub's Status screen is the only place anyone looks when something feels late. · **HOW WE KNOW:** the Status screen lists every job with its last run, wherever it ran.
- **WHAT IT LOOKS LIKE:** one short list of jobs with a cadence and a tier each; one heartbeat row per job; one watchdog per class; prompts with no boilerplate block. · **HOW WE KNOW:** the 27KB generated rules block is absent from every task prompt (step 22) and the job count on the Status screen equals the count in this file's STEPS.
- **WHAT IT IS NOT:** not a rewrite of any app's own logic; not a new scheduler engine; not Monday.com in any form; not a plan to keep the minis; not a place for agents' upkeep notebooks. · **HOW WE KNOW:** steps 9 and 25 retire those, and no step names Monday or a mini as a destination.
- **NOT in scope:**
  - The apps' own screens and features — a job that feeds them is in scope, the screen is its app's.
  - Moving the local business database to the cloud in full — RULE 35 names it a fault with a retirement step; the HSDB-primary work owns the move, this plan only refuses to build anything new on the local file.
  - Neeko's conversational replies in Slack — a separate lane; this plan builds his scheduled audits only.
- **Trip-over protocol:** record one dated line in the SUMMARY naming the owning lane and return here; never fix outside the fence.
- **REPLACING / RETIRING:** ZION-7 and the Life OS SCHEDULED lane (superseded 2026-09-11); the two daily Fable audits (replaced by step 20); the four shared notebooks (step 9); every Monday-bound job (copy-back, carry-in, overdue bump, Monday ingests).

## 1a · Critical variables — confirmation sheet

| # | The variable, in plain words | Value chosen | Alternatives rejected | Class | HOW WE KNOW | Cost if wrong | CONFIRMED |
|---|---|---|---|---|---|---|---|
| 0 | **SURFACE — which screen this lands on** | the Hub's Status screen for every job's last run; each message lands on its own channel (Slack DM, WhatsApp, the school app) | a new dashboard; the family app's Updates feed | V1 | E1–E8 in §2 name each | nobody can see whether the clockwork ran | Nick 2026-09-11: the Status screen is where he looks |
| 1 | **WHERE JOBS RUN** — which machine or cloud service runs the scripts | Studio job engine for Mac-bound jobs; one Cloudflare scheduler for the Hub ticks and calendar push; Fly only as fallback | keep the mini as steward; GitHub hosted runners (unproven here) | placement | triad 2026-09-11 (skeptic + cold verifier) | jobs go dark when a machine sleeps | Nick 2026-09-11 "cloudflare scheduler is good… fly too… triad the best options here and act on it" |
| 2 | **WHICH CLAUDE ACCOUNT** runs token tasks | noah.o.deck@gmail.com (the Claude z app / its CLI profile), subscription tokens, other subscriptions as overflow | the API key; Nick's main Max account | account | process tree of this session; `claude auth status` | bills the wrong account or burns Nick's working quota | Nick 2026-09-11 "tokens… if tokens can it pull from any available" |
| 3 | **WHAT COUNTS AS A JOB** — derived from data feeds and messages, not the old list | the 25 STEPS rows | resurrecting the 177 old entries or the 80 old prompts by name | scope | each row names the feed or message it serves | rebuilding dead weight | Nick 2026-09-11 "based on your research not on the preexisting shit" |
| 4 | **REMOVAL SEMANTICS on the Hub** | hide (recoverable, reason kept) | true delete | data | the Hub API's `remove` action | history lost | Nick 2026-09-11 "hide for now" |
| 5 | **ESCALATION TARGET for Neeko** | Nick first, Mae later | Mae first | people | Nick's answer on file | annoying a team that is doing well | Nick 2026-09-11 "yes me first so i see whats happening first then ill turn that off" |

**Considered and ruled NOT critical:**
- Exact minute of each cron — chosen off the hour per house rule, never a preference of Nick's.
- Which cheap vendor builds a given script — the router decides per job.

## 1b · Subproject decomposition

| Subproject | Could ship, be checked and be used on its own? | Owner | Plan | Steps | Dependency |
|---|---|---|---|---|---|
| Cloud heartbeat and the Hub ticks scheduler | Yes — the Status screen shows cloud-run jobs and the ticks leave the Mac | this session | this file | 1–2 | none |
| Realtime captures and Hub data refresh | Yes — Slack, WhatsApp, Gmail reach the Hub live; feeds refresh without Monday | this session | this file | 3–4 | step 1 |
| Household: family feeds, finance, reminders, briefings, kids | Yes — each message or feed is its own user-visible outcome | this session | this file | 5–7, 10–13 | step 1 |
| Watchdogs and housekeeping | Yes — one watchdog per class, notebooks retired | this session | this file | 8–9 | step 1 |
| Neeko as operations manager | Yes — hourly audit, daily SOP oversight, Friday digest | this session | this file | 16–19 | step 4 |
| Reviews, audits, Larry, Benito | Yes — each is one scheduled review with its own report | this session | this file | 14–15, 20–21 | step 22 |
| Accounts, machines, retirement | Yes — token profile, minis off, old plans and cards cleared | this session | this file | 22–25 | steps 1–21 for 23 |

## 2 · Complete entry-point map

| Id | Screen / entry point | State (default·empty·error·loading) | Element / interaction | Expected behavior | Navigation from → to |
|---|---|---|---|---|---|
| E1 | Hub Status screen | default / stale / never-ran | one row per job: name, last run, where it ran | every job in STEPS appears with a last run under its cadence | Hub → Status → row |
| E2 | Nick's morning briefing (Slack DM from the Skippy bot) | default / missing scores / failed build | message with score buttons 4–10 in half steps | arrives 07:35, scores saved on tap, no tech updates, no links out except learning when re-enabled | Slack → DM → tap |
| E3 | Chantelle's morning message (WhatsApp, as Gracie) | default / no reply / late | warm note, one nudge, invite to reply | arrives 07:30 on WhatsApp; replies logged for tailoring, never shown to Nick | WhatsApp → reply |
| E4 | Hub team ticks (SLA, NPS, recurrence, RO follow-up, broadcasts, bookings) | due / nothing due / duplicate fire | Cloudflare scheduler POSTs the endpoint | each announces once; overlap with the Mac copy for 7 days produces no duplicate notification | scheduler → endpoint → notification |
| E5 | Kids' school app "My Day" | default / block absent / calendar unchanged since yesterday | daily push at 06:00 Central | today's blocks show for Noah and Willow; ambiguous slots omitted, never guessed | family calendar → push → app |
| E6 | Neeko's hourly Hub audit | default / nothing overdue / agent mess | in-thread bump, in-task bump, tag Nick on done | 24h-stale mentions and overdue tasks get one varied bump per 24h; done work tagged to Nick | Hub thread → bump |
| E7 | Monday Ecosystem Audit report | clean week / findings / could not run | plain-words report in the Claude app | one verdict line, one paragraph per real finding, LEARNINGS.md updated | task → agent → report |
| E8 | Feed watchdog | fresh / stale / self-healed | reads the cloud heartbeat and each feed's stamp | a stale feed is repaired first and only then reported, as an FYI never a needs-you | watchdog → repair → Status |

## 3 · Lanes and frozen contracts

| Lane | Scope (in / out) | Owner | Definition of done | Model (explicit) |
|---|---|---|---|---|
| scheduled-rebuild | IN every job, task, heartbeat, watchdog and prompt named in STEPS; OUT app features, the HSDB cloud move, Neeko's Slack replies | the Studio session Nick drives (noah.o.deck@gmail.com) | every STEPS row at 100% with a fresh-checker verdict, both minis off, Status screen complete | scripts: none · cheap/low: DeepSeek/Qwen or Sonnet · strategic: Opus/Fable, named per step |

**Contracts frozen at plan time:**

- One plan, this file. A finding about another lane is one dated SUMMARY line, never a second document.
- Every new job writes its heartbeat to the cloud store (step 1) before it is switched on; a job with no heartbeat is not live.
- No new job may read or write Monday.com, the local business database as a source of truth, a local `.env` it could get from the vault, or one of the four retired notebooks.
- Token tasks run on subscription tokens from the noah.o.deck@gmail.com profile first; the API key stays closed unless a step names the job that cannot run without it and Nick says yes.

## 5 · Topology and roles

- **OVERSEER-AUTHORITY:** the Studio session Nick drives (noah.o.deck@gmail.com); it plans, dispatches and reads back, and builds nothing by hand that a routed cheap model can build.
- **Thread layout:** one execution thread; each step's checker is a fresh session.
- **Overseer:** the Studio session · **Lane manager:** same · **Workers:** DeepSeek/Qwen builders via the router, Sonnet reviewers and checkers, Opus/Fable only where a step names it.
- **State files location:** this file only (SUMMARY carries the record); evidence under `projects/ops/scheduled-rebuild/evidence/`.
- **Board card id:** `ac-ai-builds-life-os-scheduled-work-rebuilt-from-scratch-plan` (renamed 2026-09-11 to "SCHED: Scheduled Tasks - Rebuilt from scratch on the Studio and the cloud").
- **Artefact consumers:** step evidence → the fresh checker; SUMMARY/STEPS → the status page and the board card; the jobs themselves → the people who receive their messages and the apps that read their feeds.
- **Write-contention:** one writer per step; the checker is read-only; the unified project update is the only writer of SUMMARY and STEPS.

| Stage | OVERSEER | Sub-overseers | WORKER |
|---|---:|---:|---:|
| Foundation | 1 | 0 | 2 |
| Live surfaces | 1 | 0 | 2 |
| Household | 1 | 0 | 3 |
| Guards | 1 | 0 | 1 |
| Neeko | 1 | 0 | 2 |
| Reviews | 1 | 0 | 2 |
| Retirement | 1 | 0 | 1 |

**The walk-away contract:**

- **STATE FILE:** `projects/ops/scheduled-rebuild/PLAN.md` (its SUMMARY, newest entry first)
- **HEARTBEAT ROW:** `scheduled-rebuild` in the Hub's Status screen once step 1 lands; until then the SUMMARY's dated entries
- **MORNING-REPORT LINE:** the `SCHED:` card's latest update on the AI Builds board

## 6 · Evals — working means these exact results

| Capability | Check (exact command or procedure) | Pass looks like |
|---|---|---|
| Cloud heartbeat visible | Open the Hub Status screen after one named job runs from the Cloudflare scheduler | the job's row shows a last run within its cadence and "cloud" as where it ran |
| Hub ticks off the Mac | After 7 days with both copies running, switch the Mac copies off and read each tick's own ledger | every tick's ledger shows runs on every due slot with no gap and no duplicate notification |
| Morning briefing scores | Tap a score in the Slack DM, then read the Health screen | the tapped value appears in the Health screen within a minute |
| Chantelle's message channel | Read Chantelle's WhatsApp at 07:35 | the day's message is there, sent as Gracie, and no copy went to Slack |
| Neeko bump discipline | Seed one 25-hour-old @mention and one overdue task on a test card, wait one cycle | each gets exactly one bump with different wording, and nothing else on the board is touched |
| Minis off | Unload both minis' runners and every old-workspace service, wait 24 hours | the Status screen shows every job fresh and the feed watchdog reports zero stale feeds |
| No boilerplate | `command grep -L "BEGIN SKIPPY-RULES" ~/.claude/scheduled-tasks/*/SKILL.md` | every live task prompt is listed (none carry the block) |

## SUMMARY

**2026-09-12** — The overnight session on the programme to rebuild every recurring background job Nick's household and company depend on moved seven of its twenty-five steps and fixed nine faults that were already live and silent. The six timed reminders inside the Hub (the web app his company uses every day for tasks, people and money) and the daily push of the kids' calendar into the lessons website they use for school at home now fire from a scheduler hosted by Cloudflare, the internet company that already serves the Hub, and the copies on the Mac Studio (the desktop computer in his office) are switched off. Three independent checkers that built none of it graded the work against the live systems: one watched the cloud scheduler fire a job on its own while confirming nothing on his own computer could have done it. His family's morning health refresh had been reporting a partial failure every day with a note that named none of the causes; running its six steps individually found three, all now fixed — the record of when each job last ran had been silently refusing every one of that job's entries because of a single wrong character in a name, Chantelle's daily data had been a day stale, and the catch-up that fills in a missed night of sleep and readiness figures from the ring Nick wears had been dead since the workspace folder moved, leaving that file frozen for thirteen days. Two of the Hub's own screens, the one tracking people the company is trying to hire and the one listing who works there, were being calculated correctly every morning and then never published. Four of those faults, in four different places, turned out to be one cause: nothing was handing a password to the tool that publishes data, and each had been investigated before as its own separate mystery. Three reminders are switched back on — paying his therapist on Wednesdays, a therapy check-in on Thursdays, and Chantelle's evening one set up but deliberately unable to send anything until he personally says go, which its own instructions have always required. Twenty-two cards that were nothing but assistants being poked with test questions were hidden from the company task board, none deleted and each still readable with the reason. His messages to his assistant in the team chat app the company uses now reach the Hub in about four seconds instead of two minutes, and everything else in both directions is down to one minute; a message between him and another person cannot be made instant by anyone, because that chat app only tells an assistant about conversations the assistant is itself part of. Nothing was watching the engines that answer his personal questions, and now one checker is. Two of the checkers found real defects in the session's own testing rather than in its code — a safety test that finished checking before the thing it watched could possibly have happened, and a proof that had started passing without proving anything — and both are fixed and re-proven. Six things wait on Nick, all of them already in one message on his phone, and the largest is ten minutes at his keyboard to switch on the twenty-one instructions written for the assistant to follow on a schedule.

**2026-09-12** — The programme to rebuild every recurring background job Nick's household and company depend on has finished its second step except for time passing. The six timed reminders inside the Hub (the web app Nick's company uses every day for tasks, people and money) and the daily push of the kids' calendar into the lessons website they use for school at home now fire from a small scheduler hosted by Cloudflare, the same internet company that serves the Hub, so no computer in Nick's house has to be awake for any of them. All seven were fired once by hand to prove the whole path, then the scheduler's own clock was watched firing two of them with nobody touching it, and only then were the seven copies running on the Mac Studio (the desktop computer in Nick's office that has been doing this work until now) switched off — the order Nick's own rule requires, because when two copies of one job both write to the single line that records when that job last ran, there is no way to tell which copy actually did the work. The key that used to sit in plain text inside the calendar job's code, and therefore in every copy of the project's history, has been taken out and is now read from a settings file that is deliberately excluded from the shared code history, so it is never copied along with the project; the same value is still in use, so replacing it is a separate decision that is Nick's alone. A question the earlier plan had left open turned out to be a broken entry in the encrypted store where Nick's keys and passwords are kept, rather than a permissions problem: the Cloudflare key saved there has a space, a colon and a quote inside it, which is why last night's attempt to use it read as unusable, while a second copy of that key, already saved in the settings of the program on Nick's Mac that serves the household web app his family uses for their calendar, health and money screens, works and can do everything the deploy needs. Nothing new was created and no key was pasted anywhere to get past it. Separately, 21 cards on the Hub's task board that were nothing but agents being poked with test questions were hidden — not deleted, and each one still readable with the reason attached — before the three new duties the assistant that runs the company's day-to-day work in the Hub is about to take on there start running. The one part of that cleanup that cannot be done as the plan wrote it is Nick's own 42 stale items: nothing on his board is overdue and 71 of his 75 open rows were created inside the last week, because every date on that board reflects the recent re-import of the data rather than when the work was really raised, so no list of 42 was invented.

**2026-09-12** — On 2026-09-12 the Claude session that had been planning the rebuild of every scheduled task (the recurring background jobs that refresh Nick's apps and send his reminders) finished writing what remains to be built and handed the building to a separate Claude session that will build it. What now exists on disk: the instructions for all twenty-one tasks that need Claude (the AI assistant service) to think, each with when it runs, which model, where it delivers, what it reads and writes, and what must be built before it can run. Those tasks are: Nick's morning briefing, with his score for yesterday entered by tapping one of thirteen links in the message; Chantelle's morning message, sent to her phone by the WhatsApp messaging app; the three messages about the kids (a question to Chantelle three mornings a week, a school report each weekday evening, the school week plan each Friday for Nick's approval); the weekly and monthly reviews of Nick's body data; the daily pull of bank balances and transactions through Era (the household's bank-connection service) and the month-end money recap; the weekly sweep matching subscription receipts to bank charges; the two fortnightly money reviews and the monthly review of the whole system; the three duties of the ops-manager assistant on the Hub (the web app his company uses every day for tasks, people and money): the hourly audit that nudges silent tasks, the daily check of each role's duties, and the Friday digest of what shipped; the weekly and monthly scans by the two agents that only propose changes (one looks inward at what has broken or gone stale, one looks outward at what the world has made obsolete); the daily check of the content calendar for the client Captus (a company Nick's business produces social content for); the Thursday standup write-up; and the nightly filing of Nick's call transcripts. Also written: one short shared block that replaces the 27-kilobyte rules text every old task carried; the contract for the first build, a small internet-hosted scheduler for the Hub's six timed reminders and the kids' calendar push; and a handoff note with the build order, the shared pieces to build first (a command that records a job's run in the record kept on a rented internet server of when every job last ran, a command that sends one message to Nick's phone, a rule letting Chantelle's messages go out without a daily approval tap, signing the Claude desktop app into the subscription set aside for these jobs and setting it to the mid-priced model, and the way code gets published to the hosting company), and the traps already hit. Also today: the top-level instruction document every agent reads at startup can only be edited after Nick writes an approval line into a ledger file, and each edit spends one line; the check that enforces this was found wired twice in the settings file that applies to every project on this Mac, so every edit spent two of his lines, and the second copy was removed, so the one-line correction Nick approved lands in the next fresh session with the approval line he wrote still unspent. Two things need Nick: open a fresh Claude session and tell it to continue this plan from the handoff note (the mid-priced-but-strong Claude model is the right one for overseeing the build; cheaper workers do the building); and, once that session lists them, say go on hiding the old Hub tasks (57 owned by Nick's own assistant, 17 by the ops-manager assistant, 42 of his own stale ones) before the ops-manager tasks start.

**2026-09-12** — The first piece of the scheduled-task rebuild is finished and independently checked: there is now one record, kept on a rented internet server, of when every scheduled job (the recurring background jobs that refresh his apps and send his reminders) last ran. Every job on his desktop computer writes to it the moment it runs, including the small scripts that run once and exit rather than living inside the program that runs the scheduled jobs. The Hub (the web app his company uses every day for tasks, people and money) shows the whole list on the page it calls Talk, in that page's tab named Status, with any job that has gone past its own time limit pushed to the top and marked. The script that watches for stopped jobs reads that same record and, in three live runs, agreed exactly with what the Hub showed, both when four jobs were late and when all were on time. Three separate review passes, each by an agent that had not seen the build, found and helped fix four real defects along the way: jobs overwriting each other in a shared record, a rounding that hid lateness, test entries stuck on the screen, and scripts exiting before their report reached the server. Fifty-five jobs are in the record tonight and none are late. Next is step 2, moving the six timed reminders inside the Hub and the daily push of the kids' calendar onto a small scheduler hosted by the same company that serves the Hub, so they no longer depend on any computer in the house.

**2026-09-11** — On 2026-09-11 Nick made the rebuild of his scheduled tasks (the recurring background jobs that refresh his apps and send his reminders) its own standalone project, and this file is now its only plan. Two older plans for the same work are retired in full, and their two remaining cards on the board where agent projects are tracked are hidden with the reason recorded. Nick approved correcting one sentence in the instruction document every agent reads at startup, but that document also requires a separate written approval record before any edit lands, and that record does not exist yet; Nick can bypass it by lowering the document protection from his own terminal for 24 hours. The weekly Monday inspection of every live app is live. Left to do, in order: a cloud-hosted record of every job's last run; a small internet-hosted scheduler that fires the six timed reminders inside the Hub (the web app his company uses every day for tasks, people and money) and pushes the kids' daily calendar into the lessons website Noah and Willow use for school at home; live delivery of the team's chat and email into the Hub; the data behind the family app (the private web app his household uses for health, calendar, to-dos and money), the daily pull of bank balances and transactions into the household money records, the fixed household reminders, his own morning briefing and Chantelle's morning message; the scripts that notice when a job stops; the assistant that will act as operations manager for the team; the weekly and monthly reviews; signing the one Claude (the AI assistant service) subscription set aside for these jobs into the copy of Claude that runs from a typed command instead of the desktop app, so jobs can start with no window open, and stripping the boilerplate out of every task prompt; and finally switching both small home computers off. Next is the last-run record.

**2026-09-11** — On 2026-09-11 Nick made the rebuild of his scheduled tasks (the recurring background jobs that refresh his apps and send his reminders) its own standalone project, and this file is now its only plan. Two older plans for the same work are retired in full, and their two remaining cards on the board where agent projects are tracked are hidden with the reason recorded. Nick approved correcting one sentence in the instruction document every agent reads at startup, but that document also requires a separate written approval record before any edit lands, and that record does not exist yet; Nick can bypass it by lowering the document protection from his own terminal for 24 hours. The weekly Monday inspection of every live app is live. Left to do, in order: a cloud-hosted record of every job's last run; a small internet-hosted scheduler that fires the six timed reminders inside the Hub (the web app his company uses every day for tasks, people and money) and pushes the kids' daily calendar into the lessons website Noah and Willow use for school at home; live delivery of the team's chat and email into the Hub; the data behind the family app (the private web app his household uses for health, calendar, to-dos and money), the daily pull of bank balances and transactions into the household money records, the fixed household reminders, his own morning briefing and Chantelle's morning message; the scripts that notice when a job stops; the assistant that will act as operations manager for the team; the weekly and monthly reviews; signing the one Claude (the AI assistant service) subscription set aside for these jobs into the copy of Claude that runs from a typed command instead of the desktop app, so jobs can start with no window open, and stripping the boilerplate out of every task prompt; and finally switching both small home computers off. Next is the last-run record.

**2026-09-11** — On 2026-09-11 Nick is rebuilding from scratch every scheduled task, meaning the recurring background jobs that refresh his apps and send his reminders, and today he answered every open question on that rebuild and one piece got built. Tasks that get removed from the Hub (the web app his company uses every day for tasks, people and money) will be hidden but recoverable, not deleted. Subscription invoices, which arrive in several free email accounts he keeps for signing up to services, will be gathered by forwarding them into one inbox and cross-checked against the list of charges his bank reports so nothing is missed. Recurring jobs that need Claude (the AI assistant service) will run on the monthly subscriptions he already pays for, never on pay-per-use billing, and may use any subscription that still has room that day. His ruling that everything lives on cloud servers and nothing is stored on a home computer first is now written once as a numbered rule; one sentence in the top-level instruction document every agent reads at startup still tells agents to treat the copy of the business data on his desktop computer as the one true copy, and correcting it waits on his one-tap approval. The two daily automated inspections of the Hub and of the family app (the private web app his household uses for health, calendar, to-dos and money) are replaced by one Monday-morning inspection: a scheduled job now exists that hands the work to a new inspector agent reporting to Boris (the senior-engineer agent), and the inspector keeps its own short memory of what to look for and which alarms are false so it does not repeat mistakes week to week. Neeko (the assistant that will act as operations manager for the team) will send every nudge to Nick first until he turns that off. Two plans for this one rebuild now exist: the restart list agreed with Nick today (23 items, in this plan file), and an older lane plan another session on the same computer was still working, whose goal is to rebuild everything on the smaller always-on computer in his house that today's ruling retires. A note was left on the older plan telling its session not to build toward that computer. Nick has not yet said which plan governs; the recommendation on file is the restart list, with the older plan marked superseded and its one extra item (a daily check of the content calendar slot for the client Captus) folded in. Next is step 1, the cloud-hosted record of every job's last run. Three things need Nick: choose the governing plan (the restart list, recommended, or the older lane plan), tap Approve on the request to correct that one sentence in the top-level instruction document, and click Run now once on the new Monday inspection job so that, the first time it asks whether it may open a web page or run a command, he is there to say yes and later runs never wait on that question.
**2026-09-11** — On 2026-09-11 Nick is rebuilding from scratch every scheduled task, meaning the recurring background jobs that refresh his apps and send his reminders, and today he answered every open question on that rebuild and one piece got built. Tasks that get removed from the Hub (the web app his company uses every day for tasks, people and money) will be hidden but recoverable, not deleted. Subscription invoices, which arrive in several free Gmail inboxes, will be gathered by forwarding them into one inbox and cross-checked against the list of charges his bank reports so nothing is missed. Recurring jobs that need Claude (the AI assistant service) will run on the monthly subscriptions he already pays for, never on pay-per-use billing, and may use any subscription that still has room that day. His ruling that everything lives on cloud servers and nothing is stored on a home computer first is now written once as a numbered rule; one sentence in the top-level instruction document every agent reads at startup still calls the copy of the business data on his desktop computer the source of truth, and correcting it waits on his one-tap approval. The two daily automated inspections of the Hub and of the family app (the private web app his household uses for health, calendar, to-dos and money) are replaced by one Monday-morning inspection: a scheduled job now exists that hands the work to a new inspector agent reporting to Boris (the senior-engineer agent), and the inspector keeps its own short memory of what to look for and which alarms are false so it does not repeat mistakes week to week. Neeko (the assistant that will act as operations manager for the team) will send every nudge to Nick first until he turns that off. Next is step 1, the cloud-hosted record of every job's last run. Two things need Nick: tap Approve on the request to correct that one sentence in the top-level instruction document, and click Run now once on the new Monday inspection job so its tool permissions are pre-approved before Monday.
**2026-09-11** — On 2026-09-11 Nick threw out every scheduled task (the recurring background jobs that refresh his apps and send his reminders) and started over. From now on each job runs from his main desktop computer or from a rented internet server, the two smaller computers in his house get switched off once that is true, nothing old is assumed to be needed, every job is rebuilt from scratch, and any job that needs Claude (the AI assistant service these jobs use) to think runs on one dedicated Claude subscription set aside for that. Measured today: only 8 of the old Claude jobs were actually registered and running, 5 more had stopped in mid-August, and every background job that needs Claude has failed since 2026-09-07 because all six Claude subscriptions hit their usage limits. Three reviewers agreed where jobs should run: the six timed reminders the Hub (the web app his company uses every day for tasks, people and money) sends itself, plus the daily push of the kids' school calendar, move to a small scheduler on the internet hosting company that already serves the Hub, after a record of every job's last run is built there first so nothing goes invisible; everything that still needs a home computer stays on the main desktop until it does not. Next is building that last-run record. Six decisions are with Nick: hidden-but-recoverable versus truly deleted for removed Hub tasks; which email inboxes hold subscription invoices; signing the copy of Claude that runs from a typed command (not the desktop app) into the dedicated subscription so scheduled jobs can start without any app window open; the wording that names the internet-hosted copy of the business data as the one true record; replacing the two daily automated inspections of the Hub's data and of the family app (the private web app Nick's household uses for health, calendar, to-dos and money) with one weekly inspection; and whether Neeko (the assistant that will act as operations manager for the team) waits for Nick's approval before its first private nudge to a teammate.
**2026-09-11** — On 2026-09-11 Nick threw out every scheduled task (the recurring background jobs that refresh his apps and send his reminders) and started over. From now on each job runs from his main desktop computer or from a rented internet server, the two smaller computers in his house get switched off once that is true, nothing old is assumed to be needed, every job is rebuilt from scratch, and any job that needs Claude (the AI assistant service these jobs use) to think runs on one dedicated Claude subscription set aside for that. Measured today: only 8 of the old Claude jobs were actually registered and running, 5 more had stopped in mid-August, and every background job that needs Claude has failed since 2026-09-07 because all six Claude subscriptions hit their usage limits. Three reviewers agreed where jobs should run: the six timed reminders the Hub (the web app his company uses every day for tasks, people and money) sends itself, plus the daily push of the kids' school calendar, move to a small scheduler on the internet hosting company that already serves the Hub, after a record of every job's last run is built there first so nothing goes invisible; everything that still needs a home computer stays on the main desktop until it does not. Next is building that last-run record. Six decisions are with Nick: hidden-but-recoverable versus truly deleted for removed Hub tasks; which email inboxes hold subscription invoices; signing the copy of Claude that runs from a typed command (not the desktop app) into the dedicated subscription so scheduled jobs can start without any app window open; the wording that names the internet-hosted copy of the business data as the one true record; replacing the two daily automated inspections of the Hub's data and of the family app (the private web app Nick's household uses for health, calendar, to-dos and money) with one weekly inspection; and whether Neeko (the assistant that will act as operations manager for the team) waits for Nick's approval before its first private nudge to a teammate.
**2026-09-11** — On 2026-09-11 Nick threw out every scheduled task (the recurring background jobs that refresh his apps and send his reminders) and started over. From now on each job runs from his main desktop computer or from a rented internet server, the two smaller computers in his house get switched off once that is true, nothing old is assumed to be needed, every job is rebuilt from scratch, and any job that needs Claude (the AI assistant service these jobs use) to think runs on one dedicated Claude subscription set aside for that. Measured today: only 8 of the old Claude jobs were actually registered and running, 5 more had stopped in mid-August, and every background job that needs Claude has failed since 2026-09-07 because all six Claude subscriptions hit their usage limits. Three reviewers agreed where jobs should run: the six timed reminders the Hub (the web app his company uses every day for tasks, people and money) sends itself, plus the daily push of the kids' school calendar, move to a small scheduler on the internet hosting company that already serves the Hub, after a record of every job's last run is built there first so nothing goes invisible; everything that still needs a home computer stays on the main desktop until it does not. Next is building that last-run record. Six decisions are with Nick: hidden-but-recoverable versus truly deleted for removed Hub tasks; which email inboxes hold subscription invoices; signing the copy of Claude that runs from a typed command (not the desktop app) into the dedicated subscription so scheduled jobs can start without any app window open; the wording that names the internet-hosted copy of the business data as the one true record; replacing the two daily automated inspections of the Hub's data and of the family app (the private web app Nick's household uses for health, calendar, to-dos and money) with one weekly inspection; and whether Neeko (the assistant that will act as operations manager for the team) waits for Nick's approval before its first private nudge to a teammate.


**Ruling, Nick 2026-09-11 (paraphrased from chat, his numbered answers on file in the session):** every
scheduled task moves to the Mac Studio or the cloud; both Mac minis (his and Chantelle's) are switched off
once the Studio and the cloud hold everything; nothing from the old fleet is assumed needed; every task
is redone from scratch to be optimal, never "kept as is"; scripts first, cheap/low models second, Opus/
Fable only when strategic; Claude API avoided (10–20x a subscription); token tasks run on the
noah.o.deck@gmail.com account (the "Claude z" app on the Studio); Monday.com is going away entirely;
Era is the only connector, everything else by API; the four shared notebooks (LIVE-CHECKPOINT,
ACTIVE-WORK, SESSION-LOG, CHANGELOG) should not exist — plans are the only record.

**Measured before the restart (2026-09-11, corrected after a fresh checker):** Nick's mini's Team2 app
holds 8 registered+enabled Claude tasks (6 fired this week: benito-drift-read, benito-monthly-deep-dive,
business-refresh-hs-dashboard-finance, business-refresh-payroll-hours, business-standup-structurer,
morning-refresh-era-gmail-personal; larry-weekly-sweep and larry-drift-read never ran); TeamShared holds
claude-subscription-renewals (last 08-23); the Personal Cowork surface holds 5 enabled that last fired
mid-August (gracie-chantelle-inbox, emdr-record-reminder, knowledge-bundle, finance-weekly-bundle,
ferritin-retest-hair one-shot). The other ~35 prompt folders marked "on" have no registration. All six
subscription accounts rate-limited and the paid key closed, so every daemon LLM job failed since 09-07.
Script runner: 59 of 177 SCHEDULE entries active; Chantelle's mini runs a crash-looping copy (28,342
restarts). Hub: 178 overdue open tasks (390 open assigned to Nick, of which 254 are captus-content
drafts; 57 Skippy; 17 Neeko; 65 team).

**Triad 2026-09-11 on cloud placement (skeptic: proceed with changes · cold verifier: agree with a
named change; both independently found the same three defects):** (A) the six Hub ticks go to ONE
Cloudflare Worker with ONE cron trigger (`*/15`, in-code due table; Free plan = 5 triggers per ACCOUNT),
two secrets (deck-business robot token + hs-booking hub key), three hosts (hub.heroesandsidekicks.io,
hs-booking.pages.dev, plus the family app for calendar-push), fetches fanned out concurrently; run
alongside the Mac copies for 7 days (endpoints are idempotent) before the Mac copies go off. (B) the only
job that is cloud-ready today by reading it is calendar-push — it joins the same Worker (06:00
America/Chicago, DST-aware in code) and its literal key must leave git first; capture-integrity,
morning-catchup and bizapp-vendors-nps-refresh are Mac-bound (local python, local .env, business.db)
and stay on the Studio until each dependency is cloud. (C) PREREQUISITE, built first: a cloud heartbeat
store (one KV key per app) with a reader on the Hub Status screen and in the feed watchdog, so the
first job that moves stays visible; the Mac heartbeat rows for moved jobs are retired in the same change.
GitHub hosted runners are unproven here (both live workflows are self-hosted on the Studio) and are not
used; Fly is the fallback for any cloud-ready job a Worker cannot hold. The jobs role moves from
Nicks-Mac-mini to Nicks-Mac-Studio on Nick's word today ("job engine gets updated, runs here or
wherever then we turn off the minis"), which supersedes the 2026-09-10 note in machine-roles.json.

## STEPS

*Restart steps, 2026-09-11. Status only changes here; each step's DONE is a real run read back, checked by a fresh checker.*

*2026-09-12 — handoff: the planning session wrote the prompt and registration record for every task that needs Claude to think (21 files in tasks/, one shared block, README) plus HANDOFF.md with build order, shared prerequisites and traps; the build moves to the ops session from here. 10% = specified, not built.*

1. [Restart] Cloud heartbeat store + Hub Status reader + feed-watchdog reader — 100%
   DEFINITION OF DONE: A record of every scheduled job's last run is kept on a rented internet server rather than on a computer in Nick's house, with one entry per app; the Hub (the web app his company uses every day for tasks, people and money) shows every job's last run on its Status screen by reading that record; and the checker that watches data freshness flags any job whose last-run entry goes stale. Proven by one real job writing its last run there and both readers showing that write.
   PROOF: One named job writes its last run to that record on the internet server; the entry is read back on the live Status screen of the Hub; the freshness checker flags it stale when the entry is deliberately aged; a fresh checker who did not build it confirms all three.
   VERIFIED: Not started. This turn recorded the restart itself: Nick's rulings, a corrected count of what was really running, and the outcome of a three-reviewer decision on where jobs should run. The plan edit was read back from version control as commit 309b4ac80e.
   VERIFIED: Not started. This turn recorded the restart itself: Nick's rulings, a corrected count of what was really running, and the outcome of a three-reviewer decision on where jobs should run. The plan edit was read back from version control as commit 309b4ac80e.
   VERIFIED: Not started. This turn recorded the restart itself: Nick's rulings, a corrected count of what was really running, and the outcome of a three-reviewer decision on where jobs should run. The plan edit was read back from version control as commit 309b4ac80e.
   VERIFIED: Read back on the live surface by two Opus checkers and one Sonnet checker in fresh sessions, each with negative controls; the Status list was screenshotted on the live Talk screen showing the jobs with the panel's own row style; the watchdog's live run agreed with the Hub's stale set in the same minute on both a late and an all-clear pass. Commits on the Hub: 932274ac, 69b39d93, c19e6bde, 119e36e4, 8cdbe514, 7ee25333, afbfae9c; on the main line: 828206fd96 through 6f7e3b5737.
2. [Restart] Hub ticks Worker (6 ticks + calendar-push at 06:00 Central) deployed, both running 7 days — 90%
   NOTE: built and live 2026-09-12 — the scheduler is deployed and firing; only the seven-day watch remains
   DEFINITION OF DONE: The six timed reminders inside the Hub (the web app Nick's company uses every day for tasks, people and money) and the daily push of the kids' calendar into the lessons website they use for school at home fire from a small scheduler hosted by the same internet company that serves the Hub, so no computer in the house is needed for them. Done when all seven have reported, from that scheduler, every day for seven days, to the record kept on a rented internet server of when every scheduled job last ran; the watchdog that reads that record has not flagged any of them late; the one key that was written into a job's code has moved into a secret; and the copies still running on the Mac Studio have been switched off.
   PROOF: The scheduler is built, deployed and firing on its own clock, and the seven copies that used to run on the Mac Studio are switched off. Evidence, all read back on the live surfaces: the scheduler reports itself to the last-run record under the same seven job names the Mac copies used, with a field saying the run came from the internet company rather than a house computer, and all seven rows read fresh and healthy. Its own clock was proven before anything was switched off — two of the seven wrote their rows at 02:45:34Z on 2026-09-12 with nobody firing them by hand. A separate check runs the scheduler's whole timetable over two simulated weeks, one of them containing the day the United States clocks change, and confirms each of the seven fires exactly as often as it should and that the kids' calendar push stays at six in the morning Chicago time across that change; that check was proven able to fail by feeding it one wrong expectation. The key that was written into the calendar job's own text has been taken out of it and is now read from a file version control never sees. The step's own proof command passes and deliberately refuses to claim the seven-day part, which only time can answer. Remaining: seven days of those rows staying fresh, which is what step 23 (switching off both Mac minis) waits on.
   VERIFIED: The contract file was written on 2026-09-12 and read back from version control as commit 7db2a0de23 on the main line, after a fresh read of each of the seven job files it describes; the literal key it flags was confirmed present in the calendar job's code at line 21.
   VERIFIED: Read back on the live surfaces by the session that built it: the deploy tool's own output naming the new scheduler and its timetable; the last-run record showing all seven job names reporting from the internet company, fresh and healthy; the job runner on the Mac Studio restarting and stating in its own log that it is now firing 53 jobs rather than 60; and the step's proof command exiting clean. The reason the Mac copies went off now rather than after seven days is Nick's own rule that a job is moved by switching its old copy off in the same step its new copy goes live: with both running, the shared last-run row shows whichever ran last, so the seven-day check could never have passed while both were on — measured live at 02:45Z when the Mac copies overwrote two of the cloud's own rows 21 seconds after them. Commits 4a7aab5bc4 and the snapshot 3799e009d7 on the main line.
3. [Restart] Realtime captures: Slack push (bot + Nick's own DMs), WhatsApp post-on-receipt, Gmail push to a Hub address — 80%
   NOTE: 2026-09-12 — the assistant conversations are instant (about four seconds); his human conversations and email are one minute in each direction, which is the written spec. Slack cannot push a person-to-person message to a third party at all, measured on the live boundary. Sub-minute email needs a DNS change on the company mail domain, which is Nick's call. See evidence/step-03-realtime.txt
4. [Restart] Hub data refresh without Monday: Stripe daily, payroll hours Tue/Thu/Sat, vendors/NPS/bookings/team 2x daily, nightly cloud copy + match — 30%
   NOTE: 2026-09-12 — two of the four failing refresh legs fixed (they were the same missing credential as step 2's open question); the other two are guards correctly refusing and need a decision, not a repair. Removing the Monday reads is a daylight change. See evidence/step-04-hub-refresh-measured.txt
5. [Restart] Family app feeds: Oura morning + midday repair, log-triggered rebuild, weight, Chantelle daily — 85%
   NOTE: 2026-09-12 — three real faults found by running it and all three fixed: the cloud record had been refusing every step row, Chantelle's feed had been stale a day, and the Oura catch-up had been dead since the workspace moved. Five of six steps now pass; the sixth belongs to step 4. See evidence/step-05-family-feeds.txt
6. [Restart] Personal finance: Era daily (token task, Era connector), Wise weekly, month-end, month recap, receipts sweep incl. non-HS mailboxes or Era-transaction source — 55%
   NOTE: 2026-09-12 — its Gmail read is built, proven live and guarded 7 of 7; and the write route it left as an open choice turned out to need NO build at all, because the deploy tool takes its credential from the environment and a real write through that same store was already proven the same night. Recorded as the ops decision. Still open: Nick's one-time forwarding filters, and the four other money tasks which need registering.
7. [Restart] Reminders: pay Sarah (WhatsApp, Wed), EMDR (Slack, Thu), progesterone (WhatsApp, cycle days 12–26) — 85%
   NOTE: 2026-09-12 — all three reminders are on at the times the plan names. The progesterone one is registered and deliberately NOT armed: its own header requires Nick's yes for a live send to Chantelle, and that is outstanding. Dry-run proof in tools/check-reminders.mjs
8. [Restart] Watchdogs: one of each kind, each reading the record kept on a rented internet server — 75%
   NOTE: 2026-09-12 — engine-alive had none of its six candidates running and now has one; the watchdog whose subject is a job's last run reads the cloud copy per Rule 37(e); the aged-row proof passes 7 of 7; and there are no duplicates to retire. 🔴 BUT THE STEP'S OWN BAR, "one of each", IS NOT MET AND SHOULD NOT BE: six kinds have exactly one, while feed freshness has two and password/exposure has two, and in both cases the extras watch genuinely different subjects that nothing else watches. Meeting the bar literally would mean retiring a real checker. That needs Nick's word on the bar, not more building. A fourth independent checker caught this file claiming otherwise. See evidence/step-08-watchdogs-measured.txt
   DEFINITION OF DONE: There is exactly one working checker for each of the eight things worth watching: whether a data feed has gone stale (and heals itself), whether the background services are alive, whether the engines that answer Nick's questions are alive, whether spending has run away, whether the Mac is backed up, whether the store holding his keys and passwords is intact, whether a password has been exposed, and whether anyone is present and working. Each one reads when a job last ran from the record kept on a rented internet server rather than from a computer in the house, so a machine being asleep or retired cannot be mistaken for everything being fine. Duplicates are retired. Done when each checker has been shown to raise the alarm on a deliberately aged entry.
   PROOF: Half of it is done and proven, and the measuring was the valuable part. Fifteen checkers are switched on. Only one of them read the record on the internet server; two genuinely read the house computer's own file; the other twelve read no last-run record at all, because they watch their own subject rather than job health, which is correct. An earlier count in this project's notes said eleven read the house computer, and that count was wrong and has been corrected in place — it had counted any file merely mentioning the record, including in a comment. Nothing at all was watching the engines: all six candidates were switched off, so if the engine that answers Nick's personal questions stopped responding, nothing would have noticed. One of those six is now on — the only one that just watches, making two free calls per run with no paid thinking, and its own test suite passes fifteen of fifteen including a recovers-after-failure case. The one checker whose whole subject is a single job's last run now reads the internet server's copy, with the house computer's file as a fallback so it can never go silent because its own lookup failed; its own test suite still passes ten of ten because the deciding logic was left untouched. The step's own requirement — that each checker raises the alarm on a deliberately aged entry — is implemented and passes seven of seven, every case paired with a fresh entry that must NOT raise the alarm, so something that alarms at everything cannot pass. Remaining: one checker that reads the house computer's file where that may be the right answer, and one pair of backup checkers where one is probably redundant.
   VERIFIED: Read back on the real surfaces by the session that did it: the scheduler's own log reporting 57 jobs where it reported 56 before; both affected checkers' own test suites re-run and passing at ten of ten and fifteen of fifteen; the aged-entry requirement run and passing at seven of seven; and the record on the internet server read once, read-only, showing sixty-eight entries with none of them late. One thing learned while trying to fake an aged entry and worth writing down: the record refuses a timestamp supplied by the caller and ignores a zero limit, stamping its own time and counting real elapsed seconds instead. That is the record being right rather than an obstacle, because anyone able to backdate an entry could also hide a dead job — so the aged cases drive each checker's own deciding logic instead of faking the data. Committed as e056459641 on the main line.
9. [Restart] Retire the four shared notebooks and their writers; plan files are the only record — 5%
   NOTE: 2026-09-12 — measured, not done, and it is bigger than its own proof line suggests: one real writer, two readers that would break, and 105 guards whose whole subject is these four files, including a deliberately frozen suite. See evidence/step-09-notebooks-measured.txt
10. [Restart] Morning briefing rebuilt: Skippy bot DM to Nick, score entry by tapping (4–10 in half steps), no agent/tech updates, no learning link, old feed card gone — 25%
   NOTE: 2026-09-12 — its prompt is written, every ops prerequisite is resolved and verified against the live systems, and the paths it names are guarded by tools/check-task-paths.mjs. What remains is registration on the account that will run it — ten minutes with Nick at the keyboard for the first run — then the step's own proof: the delivery arrives and the last-run row appears under this task's name. The proof is entirely unstarted, which is why this is not higher. 🔴 AND ONE THING STILL TO BUILD, which is why this is lower than its siblings: the score link, whose design is written in SCORE-LINK-DESIGN.md precisely because the obvious version records scores nobody chose.
11. [Restart] Chantelle's morning message via WhatsApp, same rebuild — 40%
   NOTE: 2026-09-12 — its prompt is written, every ops prerequisite is resolved and verified against the live systems, and the paths it names are guarded by tools/check-task-paths.mjs. What remains is registration on the account that will run it — ten minutes with Nick at the keyboard for the first run — then the step's own proof: the delivery arrives and the last-run row appears under this task's name. The proof is entirely unstarted, which is why this is not higher. Her replies read from the daemon's own per-person conversation store, confirmed live. Her OLD Slack job stays on until this one is registered, and both happen in the same sitting: Rule 37(d) is never both and never neither.
12. [Restart] Kids: check-in prompts Tue/Thu/Sat, school EOD weekdays, weekly plan Fri — 25%
   NOTE: 2026-09-12 — the school end-of-day report asked for a new read route to be BUILT on the lessons site and named an address that does not exist; the endpoint the retired report used still works (1,000 rows, wrong key correctly refused), so no route is needed and the task now names the real one, with the two traps that would have produced wrong output rather than an error: there is no day field so today comes from the timestamp, and the child field carries a third value, "unverified", to exclude. Still needs registering.
13. [Restart] Weekly state review (Sun) + monthly trend review (day 15), redone from scratch — 40%
   NOTE: 2026-09-12 — its prompt is written, every ops prerequisite is resolved and verified against the live systems, and the paths it names are guarded by tools/check-task-paths.mjs. What remains is registration on the account that will run it — ten minutes with Nick at the keyboard for the first run — then the step's own proof: the delivery arrives and the last-run row appears under this task's name. The proof is entirely unstarted, which is why this is not higher. Its reflections file was one of the four wrong paths found and corrected.
14. [Restart] Standups Thu, transcript ingest daily, business knowledge indexing Mon — 30%
   NOTE: 2026-09-12 — its prompt is written, every ops prerequisite is resolved and verified against the live systems, and the paths it names are guarded by tools/check-task-paths.mjs. What remains is registration on the account that will run it — ten minutes with Nick at the keyboard for the first run — then the step's own proof: the delivery arrives and the last-run row appears under this task's name. The proof is entirely unstarted, which is why this is not higher. 🔴 AND ONE UNRESOLVED DEPENDENCY, which is why this is lower: the transcript inbox folder now exists but NOTHING FILLS IT — the reading script takes one named file and watches no folder, and the services that produce transcripts run on the Mac mini step 23 switches off. Its Hub capture read was also repointed at disk, because the route it named does not exist and the one that does refuses a robot.
15. [Restart] Larry nightly (script) + weekly pass, checked for optimisation — 55%
   NOTE: 2026-09-12 — the nightly half DID NOT EXIST (no script, no folder, no schedule row) while the Monday prompt already depended on it; built, registered at 03:20, read-only and with no model, and guarded by tools/check-larry-nightly.mjs at 9 of 9. Two faults of my own were found by running it: a silent run-me-directly arm, and a pattern that truncated every .json path and invented about 3,350 of the 9,894 findings it first reported. The weekly pass still needs registering, which needs Nick. See evidence/task-prerequisites-satisfied.txt
16. [Restart] Hub task cleanup before Neeko (Skippy 57 + Neeko 17 removed; Nick's 42 stale non-content items removed; team audits own) — 45%
   NOTE: 2026-09-12 — 22 cards of agent chatter hidden and read back; a second card with duplicate wording was found by an independent checker and hidden too. Nick's own 42 stale items cannot be reproduced from the live board. See evidence/step-16-hub-task-cleanup.txt
   NOTE: 2026-09-12 — the agents' own half is done; the counts in this title are the plan's original ones and no longer describe the live board (see evidence/step-16-hub-task-cleanup.txt)
   DEFINITION OF DONE: The task board inside the Hub (the web app Nick's company uses every day for tasks, people and money) no longer carries the cards that are only agents talking to each other, nor Nick's own items that stopped being real work, so the three new duties the assistant that runs the company's day-to-day work is about to take on there start against a board a person can read. Nothing is deleted: a removed card stays readable, with who removed it and why. The client content drafts for Captus are untouched.
   PROOF: 21 cards of pure agent chatter — @mention questions aimed at an assistant, verification-test requests, and two leftovers from a safety test — were hidden through the board's own remove path, with the actor and the reason attached to each. The board went from 251 rows to 230; none of the 21 is in the live list; all 21 read back on the removed list with their reason. The 22 Captus content drafts were never in the selection. The plan's third group, Nick's own 42 stale items, CANNOT be reproduced from the live board: nothing of his is overdue and 71 of his 75 open rows were both created and last touched inside the last week, because every date there reflects the recent re-import of the data rather than when the work was really raised — so no list of 42 was invented. Remaining: 35 real project cards sitting in the agents' own lanes, some belonging to lanes that finished weeks ago and some live, which needs Nick's yes or no rather than a filter's guess; asked of him 2026-09-12.
   VERIFIED: Read back from the live board by the session that did it, counted before and after, and each removed card re-read on the removed list with the actor and reason it was given. Commit dc8c3b53e2 and the evidence file in the same folder.
17. [Restart] Neeko hourly Hub audit (24h @mention bump, overdue bump, varied wording, triple-verify, done→tag Nick; human-owned→tag human; Nick first on escalations) — 40%
   NOTE: 2026-09-12 — its prompt is written, every ops prerequisite is resolved and verified against the live systems, and the paths it names are guarded by tools/check-task-paths.mjs. What remains is registration on the account that will run it — ten minutes with Nick at the keyboard for the first run — then the step's own proof: the delivery arrives and the last-run row appears under this task's name. The proof is entirely unstarted, which is why this is not higher. Its state file exists, and the comment read it named was corrected: the endpoint needs a parameter naming the board and the id, and a robot token genuinely reads a real thread that way.
18. [Restart] Neeko daily SOP-duty oversight per role, private first, Nick approves call-outs — 40%
   NOTE: 2026-09-12 — its prompt is written, every ops prerequisite is resolved and verified against the live systems, and the paths it names are guarded by tools/check-task-paths.mjs. What remains is registration on the account that will run it — ten minutes with Nick at the keyboard for the first run — then the step's own proof: the delivery arrives and the last-run row appears under this task's name. The proof is entirely unstarted, which is why this is not higher. Its state file exists, and the per-role activity read needs NO new route: the task list already shows, per person, open items against how many were touched in the last seven days.
19. [Restart] Friday "what shipped" digest + waiting-on-client sweep — 40%
   NOTE: 2026-09-12 — its prompt is written, every ops prerequisite is resolved and verified against the live systems, and the paths it names are guarded by tools/check-task-paths.mjs. What remains is registration on the account that will run it — ten minutes with Nick at the keyboard for the first run — then the step's own proof: the delivery arrives and the last-run row appears under this task's name. The proof is entirely unstarted, which is why this is not higher. Its digests folder exists with a README.
20. [Restart] Higher-reasoning reviews kept (profitability biweekly, savings biweekly, monthly system) + ONE weekly Fable audit replacing the two daily ones — 80%
   NOTE: 2026-09-12 — the three review tasks (profitability, savings, monthly system) have their instructions written in tasks/; the weekly audit is live
   NOTE: 30-day re-evaluation task created 2026-09-11 (fires 2026-10-11)
   DEFINITION OF DONE: One weekly Monday-morning inspection of every live app replaces the two daily ones: a scheduled job on the dedicated Claude subscription hands the inspection to a purpose-built inspector agent that reads its own memory of past passes first, checks each app as a real person would, files only real findings in the shared findings ledger, updates its memory with new things to look for and known false alarms, and reports to Nick in plain words. Done when the first Monday run has produced a real report and a fresh checker confirms the memory file changed only as the rules allow.
   PROOF: The scheduled job exists and is switched on for Mondays at 07:13; the inspector agent file exists and is generated from the roster; its memory file exists with the first known false alarms; a cold reader found five wording gaps in the job's instructions and one rendering defect in the agent file, all fixed and re-read; the first real Monday run has not happened yet.
   VERIFIED: The inspector agent's generated file was read back after regeneration and its reads-and-writes section renders as sentences (the earlier one-letter-per-line defect is gone); the scheduled job was created and then updated with the tightened instructions and both calls were confirmed by the scheduler; the Codex profile for the agent was generated; all of it committed as 26dfbb0206. The first Monday run is the remaining proof.
   VERIFIED: The inspector agent's generated file was read back after regeneration and renders correctly; the scheduled job was created and then updated with the tightened instructions, both confirmed by the scheduler; the Codex profile was generated; committed as 26dfbb0206 and 9236384116. The first Monday run is the remaining proof.
21. [Restart] Benito monthly deep dive — 40%
   NOTE: 2026-09-12 — its prompt is written, every ops prerequisite is resolved and verified against the live systems, and the paths it names are guarded by tools/check-task-paths.mjs. What remains is registration on the account that will run it — ten minutes with Nick at the keyboard for the first run — then the step's own proof: the delivery arrives and the last-run row appears under this task's name. The proof is entirely unstarted, which is why this is not higher. Its monthly folder exists with a README, and its agent file was confirmed present.
22. [Restart] Token tasks on noah.o.deck@gmail.com: CLI profile logged in to that account; launchd-driven; 27KB rules block stripped from every prompt — 50%
   NOTE: 2026-09-12 — the rules-block half is already true for everything that fires (measured: the three tasks carrying it are all off or registered nowhere). The sign-in half needs a password entered and so can never be an agent's to do. See evidence/step-22-23-measured.txt
23. [Restart] Job engine role → Studio; both minis' runners and old-workspace services unloaded; heartbeat proves nothing went dark — 20%
   NOTE: 2026-09-12 — correctly still shut until step 2's seven days pass, but half has happened by itself: Nick's mini no longer runs the job service at all. Six services still loaded there, two already failing; Chantelle's mini unreachable by name so its state is unknown. See evidence/step-22-23-measured.txt

24. [Restart] Jasmin's daily slot check for the Captus content calendar (carried in from the retired Life OS lane) — 40%
   NOTE: 2026-09-12 — its prompt is written, every ops prerequisite is resolved and verified against the live systems, and the paths it names are guarded by tools/check-task-paths.mjs. What remains is registration on the account that will run it — ten minutes with Nick at the keyboard for the first run — then the step's own proof: the delivery arrives and the last-run row appears under this task's name. The proof is entirely unstarted, which is why this is not higher. Its state file exists, and the board filter it named was corrected: asking by board returns ALL 229 cards, so it selects by group, which returns the real 22.
25. [Restart] Retire the two old plans and clear their cards: ZION-7 and the Life OS SCHEDULED lane marked superseded, ZION cards removed from the board, this project's own card open — 100%
   DEFINITION OF DONE: The two older plans for this rebuild are marked superseded in place, their cards on the AI Builds board are hidden with a reason, this project's own card carries the new name, and the status registry points only at this plan; done when a fresh checker confirms no session is still building from either old plan.
   PROOF: The older ZION-7 plan and the Life OS SCHEDULED lane both carry a dated superseded banner; the two open ZION cards were hidden through the Hub's own remove action with Nick's reason; the project card was renamed on the live board; the registry row now names this plan; remaining: a checker's read-back and any redundant Life OS cards Nick names.
   VERIFIED: Commit 288170bf21 read back from the log; the Hub API returned ok for both removals and the rename; the plan checker's gate run returned no failures on this file.
   VERIFIED: Commits 288170bf21 and the step-25 record read back from the log and confirmed on the remote; the Hub API returned ok for both removals and the rename; the plan checker's gate run returned no failures on this file.
   VERIFIED: The step's own remaining proof is implemented as tools/check-old-plans-retired.mjs and passes all twelve checks across four questions over 1,501 documents. Writing it found the retirement was NOT real: the older plan carried no superseded banner at all and its second line called itself the current instruction plan, so a session opening it was told to build from it; the status registry still carried a live row for the retired lane, named after the Mac-mini arrangement Rule 37 undid; and one live document still listed that approach as a row to build. All three corrected — the old plan now says RETIRED in its first line with Nick's own words and a warning that following it rebuilds what was deliberately taken apart, the registry row is retired in place so the status page says the work moved rather than going blank, and the live row points here. A fourth failure was the checker itself being too strict, demanding the registry never mention the old path, which would have meant deleting the pointer a person needs; it now asks per row whether anything still points at a retired plan while not itself marked retired.