.{provider}/rules/collaboration.rule.md

.{provider}/rules/collaboration.rule.md continued, part 2 of 2.

question asked plainly, and the discriminator is whether the work is clear, which is a property of the item rather
than of how confident its holder feels.

## `a_venue_is_absorbed_before_it_is_archived` (LOCKED)

**Convergence is not the end of a venue, and absorption is.** A converged venue is signed, its outcome is written,
and then its outcome is **built**: the implementations, refactors and updates the decision requires actually land in
the tree. Only once that work is complete does the venue move to the archive.

### Why it exists

**A converged outcome no party implements is a decision with no consequence, and archiving at convergence marks it
done.** The signatures certify agreement and certify nothing about the tree. So a venue archived on signature leaves a
settled ruling, a clean gate and an unchanged codebase, and the archive then reads as a record of work performed when
it is a record of work agreed.

**The gap is invisible in exactly the way this whole series keeps measuring.** Every convergence ordering is
satisfiable without a line of implementation: seats state their needs, sign their positions, name their durable
headings, and the successor carries the deferrals. Nothing in that set reaches the code the decision was about. **The
venue's red gate, the one signal that work is outstanding, clears at convergence, so the moment the outstanding work
becomes invisible is the moment it becomes the only thing left.**

### How to apply it

1. **Converge, then distribute.** The technical work the outcome implies is written as a checklist naming every item
   and its owner, so the remaining work is a countable surface rather than an intention held by the party that drafted
   the outcome.
2. **Build it.** Implementations, refactors and updates land in the tree, each verified the way any change is
   verified.
3. **Then archive.** The venue moves to the archive once its outcome is in the tree, never on signature alone.
4. **The convergence walk is a precondition rather than a completion signal.** Every ordering holding means the venue
   is ready to be absorbed, and a walk reporting all four is not authority to archive.

### A checklist assignment outranks surface ownership for the item it names

**An item naming an owner is that owner's authorization to write wherever the item lands, including a surface
another party owns.** Otherwise a distribution checklist can only assign work to the party that already owns the
file, which makes distribution meaningless and turns every cross-surface item into a queue behind one party. The
absorption stage exists to spread the work, and an assignment that cannot cross a boundary spreads nothing.

**Foreign-scope protection is unchanged and is still enough.** An unassigned write into a party's surface remains a
breach, and the discriminator is the assignment rather than the party, so the protection covers exactly what it was
for, and the checklist covers what it could not.

**The dispute moves to a better surface.** Where an owner disagrees with an assignment, the argument is about a
visible line on a shared checklist rather than about an edit whose authority no party can see. **An assignment is
contestable and an edit is not**, which is why routing the authority through the checklist makes the disagreement
cheaper rather than more likely.

### What it does not license

**It is not a reason to hold a venue open while the work runs.** An open venue holds the build for every seat, and
the discussion is finished, so the venue is converged, its outcome distributed, and the absorption tracked on the
checklist rather than by leaving the blocker standing. The blocking gate answers _is a decision unmade_, and the
checklist answers _is the decision built_, and conflating them makes one surface report two states.

## `a_position_is_posted_through_the_tool`

**A position enters a venue through the tool with the surface named, never by hand.** The tool writes into the
calling seat's own delimited record, so the fence, the item id, the addressing, the compare-and-swap, the reader set
and the hold machinery all apply in a venue exactly as they do on the board. Hand-editing a venue is the bypass, and
it has no fence, no id, no drain and no gate.

**A venue without a per-writer record refuses every tool write**, which is what pushes a seat to hand-edit, so the
record arrives from the template rather than being placed by the party that hits the refusal. **A protocol mandating
a surface its tool cannot write to will be obeyed by hand**, and that is a defect in the mandate rather than in the
seat.

## `a_repairer_runs`

**A repair has two landings, and reporting it delivers only one.** It lands in the source, where its author observes
it, and in the state, where every other seat does, so a repair that is reported rather than run is invisible until a
peer spends the shared resource to discover it, or until no peer does.

**So the seat that changed the tree takes the run.** That is the one moment the warrant is unambiguous, since a
question about state goes to the report and a question about a changed tree goes to a run, and it is the one time the
run costs no party anything, because the repairer already holds the write.

**A declared run is a shared measurement paid once.** Every seat reading its report consumes the artifact the run
exists to produce, which is not free-riding, and a protocol obliging each row-holder to spend the resource would
produce one whole-tree mutation per seat for one number. **Measured across two repairs in one discussion:** the one
whose author also ran closed itself for every seat, and the one whose author reported instead needed a second seat to
declare a run before any peer could see it.

**This completes the concurrency hold rather than qualifying it.** No seat mutates a shared surface while peers are
writing, and the seat that changed the tree publishes the state. Both halves are needed, because the hold alone leaves
repairs unpublished, and the run alone spends other seats' work.

## `a_venue_carries_its_own_fields`

**The venue schema is its own, and the board's does not transfer.** A board answers who owns what and what is
directed at whom, while a venue answers where each seat stands on one question and what it still needs before it can
sign: `Reading`, `Stance`, `Needs`, `Positions`.

**`Needs` is the field the board has no analogue for, and it is what makes convergence checkable.** A seat that cannot
sign states what is missing, so the remaining set is derived rather than judged, and an empty `Needs` across every
active seat is what convergence looks like. A venue carrying an ownership field is describing ownership in a document
about a decision.

## `a_venue_is_read_before_it_is_written`

**The venue template is read before a seat writes its first position**, and it is named in the startup contract
because that is the only surface a startup delivers. A contract nothing routes to is a contract no party reads: four
seats deriving one format four different ways is a delivery failure rather than four lapses, and the control is the
board, whose shape is delivered and whose record shape no seat has ever invented.

## `an_undecided_half_names_its_receiver`

**A converging venue names, for each question it deliberately leaves open, the venue that receives it, or states that
it leaves none.** The durable half extracts to the history accumulator, while an undecided question is neither a
finding nor history, so it lands in the successor venue as an inherited clause naming its origin.

**The chain the series declares has no edge without this.** Each venue opens once its predecessor converges, because
each outcome is an input to the next, while the exit mechanism carries findings and deletes the file. So a question
every seat agreed to defer is deferred to no party, and its absence surfaces several venues later, when the work that
needed it is already built.

**Creation and opening are two events.** The successor is created at convergence, carrying its inherited clauses, and
opened when its predecessor is deleted. That is one operation with two writes, never a window a seat works inside,
because more than one open venue is more than one hold.

## `board_records_are_schema_exact`

Each record carries exactly its fixed schema and nothing else, as normalized records and never prose.

**The field set itself is not restated here.** It lives in the board template, which is the contract every board check
derives from on each run, so a digest spelling the fields would be a second copy of a schema with nothing keeping the
two equal, which is the exact construct `template_is_the_contract_not_a_copy_of_it` refuses. A record's legal fields
are read from the template, and this rule governs how they are filled.

**The transcription is a measured class rather than a hypothetical one**: one field can sit in a protocol's prose as
derived, in the template as written, and in the toolchain's own constants as a third statement, with all three reading
as intentional and no two of them able to be wrong together.

**Exactly its schema means each field exactly once, and cardinality is the half a presence check cannot see.** A check
asking _is this field here_ is satisfied by a field declared three times, and only a check asking _is it here once_
observes the record's field set. That is the same shape as a pairing check that validates each member and never the
relation between pairs.

**The parsed record is why it stays invisible rather than merely unchecked.** Fields are read into a map, so a
duplicate label collapses into one entry, and every check reading the parsed record sees a well-formed record, while a
reader resolving the field gets several answers and no rule saying which wins. `board/duplicateField` counts labels in
the raw span for that reason.

`PENDING` means unevaluated, never a soft failure, and it is not a warning tier.

## `absorbed_round_extracts_to_the_changelog`

A board round that has been absorbed is **extracted to the history accumulator and then deleted from the board**,
neither deleted outright nor left in place.

The two halves are both required. Leaving it is accumulation: every agent re-reads it every round under
`board_is_read_whole`, and the live item a party must act on sits behind rounds no party can act on. Deleting it
outright loses the only durable record of a finding, because the board is current-truth-only by construction and
`history_has_two_homes` names the changelog as the one place history may live.

**What extracts:** the finding and its evidence, compressed to what a later reader needs: the defect, how it was
found, and the mechanism it revealed. **What does not:** the round's addressing, its courtesies, its restatement of
what another agent said, and anything already carried by a rule, a checklist row or a typed record. A round absorbed
into a gate is already durable, and extracting it again duplicates it.

The test for absorbed is not age. A round is absorbed when what it asked for exists, such as a retired row, a
registered gate or an answered question, so absorption is checkable against the tree rather than felt from how long
the text has been sitting there.

## `removal_declares_its_extraction`

A tool that removes an absorbed item from a coordination surface **refuses to run without a reference naming where the
extraction landed, and refuses again if that reference does not resolve.**

**Auto-removal is auto-extraction-then-removal, or it is data loss.** The board carries no past by construction, so
deleting outright destroys the only durable record of a finding, and a healer that deletes without extracting is worse
than the accumulation it was built to fix.

**The declaration carries a reference because a bare one cannot be falsified by any party but its author.** The
same discriminator separates a legitimate self-declaration from laundering everywhere else here: an owner
field is legitimate only because its evidence clause is checkable by a party that did not write it.

**What the check decides and what it must not claim.** It decides that the reference resolves, which is presence and
nothing more. **It cannot decide that what was written carries the finding**, because extraction is a compression
rather than a copy: the mechanism survives while the addressing and the courtesies are dropped by design. **A text
comparison would therefore fail every correct extraction and pass a verbatim paste**, which is the outcome the
compression rule forbids. Fidelity is judgment and stays with the writer, and a check certifying presence while
claiming to certify fidelity is worse than no check.

**The preview path is exempt, and that is the point.** Running without healing shows exactly which fields would go, so
the party running it sees the scope before extracting anything.

## `round_is_absorbed_then_deleted`

A board round is written to be **read once and then absorbed** into a resource, a draft or a rule. Once absorbed, it
is deleted from the board rather than restated in the next round.

The failure mode is accumulation that reads as diligence: each round appends its predecessor, so the record grows into
a diary, and the one live item that another agent must act on sits buried behind fifteen rounds of narrative it has
already read. A record that restates itself is reporting on itself rather than on what remains.

`board/repeatedClaim` gates the construct rather than the length: a field stating the same span of words twice is
restatement, and no threshold on size can distinguish a long live flag from a short stale one. The defect is
repetition, not length.

The board carries **what another agent must act on**, never what was done. What was done lives behind `Refs`.

## `decision_names_its_gate_or_its_proof`

Every venue declares the same exit condition: **a decision binding an artifact names the gate that will enforce it, or
is proven ungatable in writing.** A decision with neither does not close its question.

**The absent token is a real answer, and an empty cell is not.** The token states that this decision binds no
artifact, which is a claim a reader can check and disagree with. A blank states nothing, and an oversight cannot be
told apart from a decision no party has assessed. The check buys exactly that distinction, which is why
the repair is never "fill it in" but "state which of the two it is".

**The exit condition was being evaluated by hand in every venue, which is what let a gate column carry empty cells
across many rounds while the positions around it converged.** `blocking/ungatedDecision` fails a decision row whose
last cell is empty, which makes the exit condition self-checking rather than a thing an agent has to remember to walk.

**The pressure that fills a cell wrongly is the same one this rule exists to relieve.** Reaching for a gate is what
makes an ungatable proof feel like a failure, and a cell filled under that pressure produces a check that inverts its
own row, which was observed twice, both times specifying a gate that would fire on exactly the case the decision
protected. **A proof is a pass, not a concession.**

## `friction_is_a_missing_mechanism`

**The first response to coordination friction is _what is this surface missing to treat collaboration like a software
system?_**, never _who should have been more careful_ and never _let us all remember to_.

A coordination surface is software. It has state, invariants and a schema, and it decays without a validator. So an
accumulation, a lost write, a stale item, a missed message or a surface that grew past reading is a **defect report
against the protocol**, and the repair is a mechanism that makes the failure impossible or makes it loud.

**The evidence is that discipline held and the surface failed anyway.** Every drain rule this workspace carries,
namely that absorbed rounds extract and delete, that a round is read once and then absorbed, and that the board
carries pointers rather than detail, declares conduct, is agreed by every agent, and is violated by all of them. A
board grows past what any reader can consume, carrying hundreds of directed items, with every one of those rules in
force. **That is not a failure of care but a surface with no validator.**

The corollary binds the repair as tightly as the diagnosis: **a rule added without a gate is more care presented as a
rule.** Where a mechanism genuinely cannot be gated, that is surfaced with the evidence a gate would need, exactly as
`.{provider}/rules/conduct.rule.md` demands, and never assumed.

**What this rule refuses**:

1. a retrospective whose output is an agreement to be more careful.
2. a repair that adds a sentence to a protocol nothing reads at the moment of failure.
3. treating a recurring class as a run of individual mistakes, which is how a mechanism gap stays invisible for as
   long as every instance has a plausible local cause.

## `projection_is_one_line` (LOCKED)

**The `collab-status` projection is one line, and a gate holds it there.** It carries the open blocker, who owns what,
and a pointer to the board, and nothing else: no finding, no ruling, no measurement and no narrative.

**This rule has a subject only where the projection host slot resolves, which is the same precondition the refresh
obligation carries.** Whether it resolves is read from the configuration rather than restated here, and where it does
not, there is no line to hold at one, so the size contract has no operand and the gate holding it ranges over
nothing. **A rule whose subject does not exist is neither satisfied nor violated**, which is a third state worth naming
here, because a size gate reading zero over an absent surface cannot be told apart from one reading zero over a
compliant one.

### Why the size is a contract rather than a preference

**The projection is delivered into every context every turn, including every bounded invocation's, while the board
itself is not.** That asymmetry is measured: a spawned agent receives the axis document and its digests as injected
system context and never receives the board. **So the projection is the only thing such an agent knows about the
board**, and every byte of it is paid by every reader on every turn, which is the board's own accumulation cost
multiplied again by a larger audience.

**It grows by perfect compliance with the rule beside it.** `board_write_refreshes_projection` obliges every writer to
refresh it and says nothing about size, so each seat appends the finding of its round, every append is individually
true and current, and nothing is removed. **A rule that states an obligation and not a shape has written half a
contract**, and the half it omitted is the one that decays, which is `no_append_without_a_drain` arriving one layer up,
on a surface with a wider audience and no validator at all.

**A field named a one-liner is making a claim about its size.** Where a name asserts a shape and no check reads it, the
name is documentation and the shape is a hope.

### How to apply it

1. **Refresh it in place, never append to it.** The projection is a cache: it is overwritten with current truth, and
   what it replaces is not preserved anywhere in it.
2. **A finding does not go here.** It goes to the board as a fenced item, to a rule, to a gate, or to the history
   accumulator. The projection cites and does not carry.
3. **On finding it oversized, extract before truncating.** Anything in it with no other home reaches the history
   accumulator first, in the same order every drain here takes.

`board/oversizedProjection` fails the projection line past its declared cap, measured on the line itself rather than
on the file. **The cap is a construct the rule cites as data**, so the number moves without the rule changing.

## `board_carries_pointers_not_detail`

Implementation detail, playbooks, root-cause analyses, troubleshooting and milestone narrative do not live on the
board. They live in memory, plans or documents, reached through `Refs`.

### An argument belongs in a venue, and the board is not one

**A position, meaning a reading, a diagnosis, a refutation, a withdrawal or a claim under dispute, goes into the open
venue. The board carries coordination state and pointers to where the argument is.** The two surfaces have opposite
lifetimes, so an argument written onto the board is accumulation on the one surface built to be swept: every seat
re-reads it every round, the sweep drains it before it has been answered, and the reasoning that justified a ruling is
destroyed by the mechanism doing its job correctly.

**The rule is not new, and that is exactly what makes the measurement worth keeping.** Both halves were already
written, since a venue accumulates, a board is current-truth-only, and detail lives behind a pointer, and four seats
spent a full round posting multi-paragraph positions, corrections and counter-positions as board items anyway.
**Nothing refused one**, because the item form is the shared transport, and it accepts an argument exactly as readily
as a state change. So the breach was uniform across every party, invisible to every mechanism, and found only when the
owner read the surface.

**The tell is the item's own shape rather than its subject.** An item that states what is true now, who holds what, or
what a seat needs belongs on the board. An item that argues, meaning it carries evidence, answers another item's
reasoning, or exists to persuade, belongs in the venue, whatever it is about. **A position addressed to the seats is
the strongest disguise**, because the addressing is what makes it look like coordination.

**The window where this is unavoidable is real and is named, so it is not a license.** Between one venue's archive and
its successor's opening there is no venue to write into, and an argument arising in that interval has nowhere else to
go. **That interval is a defect to shorten rather than a home to settle into.** The successor is created at
convergence precisely so the gap does not exist, and a round of argument accumulating on the board is the measurable
cost of having inverted that ordering.

## `board_write_refreshes_projection` (LOCKED)

Every write to the board refreshes the `collab-status` one-liner in the axis document the configuration names as the
projection host. Agents that have read the board append their letter. The board is the source of truth, and the
one-liner is a cache with a refresh obligation.

**The obligation runs only where its target slot resolves, which is stated here because a seat reads this rule and not
the configuration at the moment it acts.** The projection host is a declared slot, and whether it resolves is read from
the configuration, which publishes its state and its reason, while every run's own report carries the derived
consequence. **That state is not restated here**, because a second copy of it goes false the moment a host adopts this
package, and nothing would join the two. Where the slot does not resolve, this branch does not run and a blocker is
carried by the board alone.

**Obeying this rule without reading that slot is the one failure mode it has, and it looks like compliance.** A seat
meeting an unconditional LOCKED obligation and acting on it has done the diligent thing, and where the slot does not
resolve, the act writes this package's coordination state into a document the package does not own. The write is the host
reach-in the package exists to refuse, arriving through the one slot that looks like configuration rather than like a
reach. **The artifact afterwards reads as a deliberate integration rather than as a package overstepping**, so nothing
downstream reports it. Measured: two seats met this obligation in one round, neither wrote into the host document, and
neither was prompted by this rule. One opened the slot, and one met the derived exemption in a report opened for another
question, and neither route is in the text.

**So the slot is read before the write, and the LOCKED marker binds the obligation rather than removing its
precondition.** A rule is the one consumer class no binding check reaches, because that walk compares what a mechanism
declares against what the configuration resolves, and a behavioral obligation declares nothing anywhere, so the
precondition holds here or it holds nowhere.

### It is not a cache, but the only board channel a bounded invocation has

**Measured by spawning an agent and asking what it received: the axis document and its digests arrive as injected
context, and the coordination board does not.** So the projection is not a convenience copy of a surface every reader can
also open. **For every bounded invocation it is the entire board**, and nothing else tells it a blocker exists.

**That inverts the cost of staleness.** A stale cache beside a readable source is untidy, because a reader who cares
opens the source. **A stale projection is a false statement delivered as the only statement**, and the failure is
silent in the worst direction, because the agent has no second source to disagree with.

**The measured shape: a projection asserting that no blocker is open and the whole pipeline is green, while a blocking
document is the most recently written file in the tree.** Every agent spawned in that window is told, by the one line
it is given, that the surface that outranks its queue does not exist.

### How to apply it

**Raising or deleting a blocker refreshes the projection in the same change**, neither at the end of the round nor on
the next board write. A blocker is precisely the fact the projection exists to carry, so the window between raising one
and saying so is the window in which the projection actively misstates the board.

**The refresh is part of the write, not a follow-up to it.** A follow-up is a second step, and a second step is the one
that gets dropped when the first one felt like the work.