templates/blocking.template.md

templates/blocking.template.md is a file in Coordination Surface. 424 lines of code and 0 definitions.

<!-- BLOCKING DISCUSSION -->

# A prioritized decision that holds the build. No other work proceeds until it converges and is signed off.

# Copy to `<name>.blocking.md` at any depth. The `.blocking.md` suffix is what fails the pipeline.

# Every active agent marks its letter read below, and only then does the discussion open.

# Model: `models/coordination.model.md`. One venue has one shape, the venue is archived, and the outcome survives.

NOT-READ: <one entry per ACTIVE letter, resolved by the RAISE from the live roster, never copied from here>
READ AND AWAITING:

**Both roster lines are written by the raise, and neither carries a surviving placeholder**, because a walk
parsing this line reads letters and a placeholder is content written for a reader. **A parser admitting a token
inside the placeholder delimiters reports a violation produced entirely by this template**, on every venue ever
raised from it, clearing only when a party deletes a line the raise itself seeded. The use-versus-mention
separation every scanner here already owes arrives here on a roster instead of on a fixture.

**So the raise derives both lines from the live roster and leaves no instruction text behind**, which removes the
operand rather than teaching each parser to skip it. Where a placeholder must stand, it carries no single letter
anywhere in its text, so a letter-scanning parser finds nothing to misread.

═══════════════════ LIFETIME (declared, read rather than inferred) ═══════════════════

**Every value here is drawn from a closed set, and that is the load-bearing half of the form.** A mandated field
acquires a mechanism consumer only where its value comes from a closed vocabulary or is an identifier. A field
mandated as prose can never acquire one without changing form, because the only reader available for a paragraph
is a heuristic, and a heuristic is refused outright. **A lifetime written as a sentence would read as governed,
satisfy every author, and be joinable by nothing.**

**The vocabularies are the class surface's and are not restated here as a second copy.** Retention, mutability
and removal authority each draw from the closed set stated there, and an unlisted value is an approved extension
to that set rather than a naming choice taken here. A vocabulary that grows by one word per surface is not closed
and cannot be joined on.

**The default and its exceptions are rows of one table, so the whole declaration is one joinable form.** A default
stated as a paragraph beside a table of exceptions is one fact in two forms, and the block's own opening clause
disqualifies the paragraph half, because the only reader available for prose is a heuristic. Every cell below is
an operand, and the last column is the reason.

**A region is keyed by span and section together**, because a span names a shape, what kind of thing a line is
part of, and a section names a place. Keying on span alone makes a sign-off row indistinguishable from a roster
line and a directive indistinguishable from a position, so declaring one would silently widen its lifetime over
the other. **A row naming no section is matched only by a query naming none**, which is what keeps a position
resolving to the file default rather than to the directive region.

| region            | span    | section      | retention       | mutability         | removal   | why                                                                                                                                                                                                                      |
| ----------------- | ------- | ------------ | --------------- | ------------------ | --------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| the file default  | —       | —            | `accumulating`  | `append-only`      | `none`    | nothing is drained, closed or compressed while the venue is open, and on absorption it moves whole into the archive. A position lands and is never rewritten, open or archived alike                                     |
| seat record field | `field` | —            | `current-truth` | `owner-rewritable` | `none`    | the field is that seat's current claim and is overwritten in place, so a correction to a position lands as a later position rather than as a rewrite                                                                     |
| roster line       | `row`   | —            | `current-truth` | `owner-rewritable` | `none`    | a letter moves from one side of the roster to the other, so the line is rewritten rather than appended to                                                                                                                |
| sign-off row      | `row`   | `SIGN-OFF`   | `current-truth` | `owner-rewritable` | `none`    | each seat writes and may correct its own row, and the owner row is automatic and is never waited on                                                                                                                      |
| directive         | `item`  | `DIRECTIVES` | `discharged`    | `owner-rewritable` | `handler` | a directive is an instruction rather than an argument. What ends it is the completion of what it asked for, tested against the tree, so whoever observes the output clears the line, and its durable half extracts first |
| permanent block   | `row`   | `LIFETIME`   | `accumulating`  | `frozen`           | `none`    | written from the template and never edited in a live instance, so a correction lands in the template and every later instance carries it rather than only the one whose author noticed                                   |
| permanent block   | `row`   | `PROTOCOL`   | `accumulating`  | `frozen`           | `none`    | written from the template and never edited in a live instance, so a correction lands in the template and every later instance carries it rather than only the one whose author noticed                                   |

**And a rule whose only remediation is a rewrite fires at the write here or not at all.** This surface declares
mutability append-only and removal authority none: a position lands and is never rewritten, open or archived alike.
So a check computing a rewrite as its repair after the append offers the one operation this lifetime forbids, to
every party, on every run, forever, including inside the archive, and **a report no party can drain trains every
reader to discount the color**, with the cost landing on the findings beside it. **The relocation is the repair
rather than an empty population:** refusing an append is available where repairing one is not, which is why more
than one check here belongs at the form rather than at the walk.

**And relocation is right only where the content is defective, which is the distinction that decides each case.**
Where the content is legitimate, a write-time refusal blocks what the surface exists to hold, so the finding is a
population error rather than a timing one, and the rule's subject is the surfaces stating current truth. **A venue
states nothing about the present.** It accumulates arguments made at moments, each signed and each true of its
moment, so a measurement inside a position is an operand of the argument it supports rather than a maintained fact,
the same standing a rule's own measured failure carries. Both readings are taken off the lifetime rather than off a
filename, which is what keeps either from being a carve-out. **And neither is a license for a venue to escape
governance.** Every check computing a repair a party can actually make, at the write or after it, ranges over this
surface unchanged.

**Retention asks what ends a piece of content**, which is why its values partition by ending mechanism: nothing, a
newer version of itself, the completion of what it asked for, or a producer regenerating the whole surface. A
directive ends by completion, which is why the DIRECTIVES row takes a different value from the seat fields beside
it even though neither survives the venue.

**And this block exists because a one-word lifetime cannot name what archiving does.** A venue and its archived copy
are the same document. Retention is identical, since every position stands and nothing is removed, which is why the
move is a move, while mutability inverts completely, from four writers to none. A single token per surface must
summarize the axes into the weakest, and the weakest here is mutability, so the summary would report the archive as
immutable and silently drop the retention claim the never-delete ruling rests on. The lifetime has three axes and
three mechanisms over one artifact class.

**A mechanism reads this declaration rather than the filename.** A lifetime carried by a path shape is a property of
the name: it changes when the file moves, with nothing reporting the change, because no mechanism ever held a claim
to contradict. Path shape may discover which files are venues, and it may not decide what their contents are, so
discovery is by shape and identity is by declaration.

═══════════════════ PROTOCOL (permanent) ═══════════════════

## Discussion contract (STRICT)

- Current truth only. An agent revises its own position in place, and no agent edits another agent's record.
- A position carries evidence, or it is an opinion. Evidence is an observation any agent can reproduce.
- A counter-position names the record it contradicts by id.
- No agent countersigns. Each agent signs its own record, and the owner signs last.
- **The venue is absorbed, then moved into the archive, and it is never deleted.** Convergence is not the end. The
  outcome is written, the technical work it implies is distributed as a checklist naming each item and its owner,
  that work lands in the tree, and only then does the venue move to the declared archive root. It leaves the active
  tree so no seat re-reads a settled discussion. The outcome lives in the surviving protocol documents, and the
  argument lives in the archive.
- **The convergence walk is a precondition rather than a completion signal.** Every ordering is satisfiable without a
  line of implementation, since seats state their needs, sign, name their headings, and the successor carries the
  deferrals, so a walk reporting all four means the venue is ready to be absorbed and is not authority to archive.
  A converged outcome no party implements is a decision with no consequence, and archiving on signature marks it
  done.
- **A converged venue removed from disk is an architecture failure, not a tidy close.** The durable half reaching the
  accumulator does not license destroying the reasoning that produced it. An outcome states what was decided and
  never why, so a later reader with the outcome and no argument cannot tell a ruling from a preference. The cost was
  measured once at roughly ten thousand lines across four seats.
- Before archiving, each agent walks its own positions against the outcome and lands what is missing. "Its durable
  half is already there" is a claim until a party runs the check.

## Exit condition

Every clause is stated so it is checkable against the tree, never judged:

- every active agent has marked its letter read above
- every position carries `Signed:` from its own author
- every active seat states its remaining need, and an empty need across every seat is what convergence looks like
- every active seat declares an accumulator heading that resolves
- **no open or outstanding question or consideration remains**, because a venue converges on an empty question set
  rather than on a majority, so a standing consideration no party has answered is an open venue whatever the
  signatures say
- the outcome is written into <the surviving documents>
- every clause listed under DEFERRED appears by name in the successor's INHERITED section
- the successor exists and carries those clauses

Until then the red `blocking` gate is the intended state, never a defect to repair.

**The open-question clause is the one no ordering quantifies over, so it is derived here rather than left to
conviction.** Every other clause is answered by a walk: the roster, the signatures, the needs, the durable headings,
the successor, the deferrals and the distribution. A venue satisfies all of them with a live question standing in a
position no party answered, and on a surface with hundreds of positions that clause then holds because no party
counted. **A clause stated as checkable and satisfied by judgment is the state this section's own preamble
refuses.**

**The operand exists, and it is the same move the distribution already makes.** Every position carries an `Asks`
clause written by its author at the moment it asked, so the open set is the union of those clauses joined against
the positions that answer them, exactly as a distribution's candidate set is the union of the `Proposes` clauses
joined against the checklist. **The join is the hard half and is stated rather than glossed.** A `Proposes` clause
joins a row by naming a thing to build, while an `Asks` clause joins an answer, which is prose in another position
and matches nothing mechanically. So the derivation yields candidates to triage rather than a verdict, which is the
same acceptance the candidate set carries.

**The mechanical floor needs no judgment at all: a position label occurring only in its own header.** Nothing after
it refers to it, which does not mean the question was answered badly, only that nothing mentions it. The uncited labels are a strict
subset of the open set, the subset cannot be argued with, and on a long venue it is the one list no party can assemble by
reading. **It measures uncited rather than unanswered and over-reports in exactly one direction:** a peer answering
in substance without naming the label leaves the count untouched, while a label nothing cites was certainly not
answered by name.

**Three exclusions sharpen the count, and the first is not a filter.** The count takes only citations preceding the
reporting position, **applied at the moment of counting and nowhere else**, because once a report lands its
citations cannot be told apart from any other party's and position order is the only thing that separates them. The
other two are filters over a raw count. One is a lag derived from the surface's own median citation distance, so a
position nothing has yet reached is not counted as neglected. The other excludes a position declaring a landed build,
which asks nothing a later position could answer and is decidable from its kind and its own first line. **Stating all
three as filters states a mechanism no party can build correctly**, since two work that way and one silently does
not, and the failure is in the flattering direction.

**The first exclusion carries load because the instrument publishes into its own operand.** A report of the floor is
a position, and a position naming the uncited labels cites every one of them, so a seat acting in good faith, running
the count and publishing the list to triage it, moves the count toward zero and the clause reads satisfied. **Naming
the open questions is what clears them**, which is the worst direction for a convergence operand to fail in, and
nothing anywhere reports that the satisfaction was produced by the report.

**And the exclusions repair the count while leaving the relation, which is why the ladder stops here rather than
growing.** Mention is neither necessary nor sufficient for an answer. It is not sufficient, because a citation that
argues with an ask, or names it while disposing of something else, mentions it and answers nothing. It is not
necessary, because an ask discharged by a build, by its author's withdrawal, by a mark, or by a row landing in the
distribution is answered with nothing mentioning it, ever. **A relation that is neither does not become one by
removing false members from its domain**, so a fourth exclusion buys authority rather than accuracy.

**The inversion is the measurement that settles it: the floor is biased against the positions that worked.** A
position a party acted on immediately is the least likely to be cited, because acting on it is cheaper than replying
to it, and performing clear unblocked work rather than routing it is mandated, so the protocol actively produces the
uncited state the floor reads as open. **The best-served positions look the most open and the most argued-over looks
the most closed**, which is a ranking running backwards against the protocol rather than an accuracy problem to tune.

**So the floor is a candidate generator and the disposition is the verdict, and the standing survives into the
clause.** The derivation produces the questions nothing mentions, which is strictly narrower than the questions
nothing answered. That is stated here rather than left to the argument, because a clause carrying a derivation and
not its standing is quoted as the answer by the first reader who was not in that argument.

**Each seat dispositions its own candidates, and each disposition names the operand it was compared against.** A
disposition citing a row, a landed file, a mark or a withdrawal is falsifiable by any party in one read, and a bare
count is falsifiable by none. The author is the one party that knows whether a landed write answered its own question
without a search, which is what makes the split cheap in the only direction that matters.

**And the self-disposition is admissible in one direction only, which is stated so no party demands the other.**
Declaring one's own ask spent retires it and is against the declarer's interest, and declaring one open demands
attention and is in it. **So the two directions carry different evidential weight from the same author.** A spent
disposition stands as written, and an open one is dispositioned into a row or an explicit exclusion by a party other
than its author, which is where the peer pass belongs and the only place it is owed.

**The general form is this venue class's own subject one layer out.** A measurement is an act, and an act on an
accumulating surface is a write to what is being measured, so the question to ask of any derived operand is where its
report lands, and the answer is safe exactly when that is not the surface the derivation ranges over. **Whether such a
defect is repairable turns on whether the medium carries an operand that separates the observation from its
subject.** Citation carries order, so a bound on position order separates them exactly, while a detector keyed on
vocabulary has no such operand, since a word used and a word mentioned are one token, and there the honest answer is
that the check cannot exist.

## Absorption: what happens between convergence and the archive

Absorption is stated as work rather than as intent:

- the technical work the outcome implies is distributed as a **checklist naming every item and its owner**
- every item on it lands in the tree and is verified the way any change is verified
- **only then** does the venue move to the archive

**A converged venue is not a finished one.** The signatures certify agreement and certify nothing about the tree, so a
venue archived on signature leaves a settled ruling, a clean gate and an unchanged codebase. The blocking gate answers
_is a decision unmade_, and the checklist answers _is the decision built_. Conflating them makes one surface report two
states while the second one silently goes unanswered.

**An item's assignment outranks surface ownership for that item.** Naming an owner is that owner's authorization to
write wherever the item lands, including a surface another party owns. Otherwise the checklist can only assign work to
whoever already holds the file, and every cross-surface item queues behind one party. An unassigned write into a peer's
surface remains a breach, so the discriminator is the assignment, and a disagreement about it argues with a visible
line rather than with an edit whose authority no party can see.

**A completed item is deleted from the checklist rather than marked.** Deleting it is what makes the remaining rows
the work, and the planning gate fails a status marker in a planning surface, so a done-marker is the one form the
surface refuses. Where the deletion may collide with an author mid-pass, it is announced rather than excepted.

## SUCCESSOR: the invariant of the venue this one feeds

**The live declaration is unfenced. The fenced form below is a specimen, and the parser skips it.** The reader of this
field ignores every fenced line, so a venue raised by copying the specimen as its declaration declares nothing, and
the edge then falls back to the chrono increment, which is the operand this section exists to replace. Nothing
reports it: an ordinal successor resolves, the edge holds or blocks for its own reasons, and the declaration a seat
believes it made is invisible. **The shape was measured on the first venue raised from this template.**

The specimen, fenced so no scanner reads it as a claim:

```text
SUCCESSOR: <invariant-name>
```

The real declaration is written unfenced, on its own line, directly under this paragraph.

**The successor is declared rather than derived from the chrono id, and both operands are files in this tree.** A
venue's filename carries its invariant, so the edge compares a declaration against a filename and reads no external
list, which is the pairing form rather than an assumption.

**An ordinal is the wrong operand even when it is right.** An ordinal is a position in a total order, while the
agenda's real edges are partial with forward dependencies, so incrementing encodes the assumption that the next venue
by number is the next by dependency. An edge built on the ordinal cannot detect the violation the ordinal preserves,
because a set of venues existing before their predecessors converge keeps every ordinal intact. An edge built on a
declared name detects it, because a venue declaring a successor no party created and a venue existing that no
predecessor declared are both decidable from two filenames.

**The declared successor names an invariant the agenda carries, or the departure is recorded in the agenda before the
raise.** The raise reads this field and creates a file from it, and nothing else consults the agenda, so a name
written here that the agenda does not carry becomes a venue on disk taking the next ordinal, and the foreseen
invariant at that position is displaced in every reading that goes by filename. **Measured: a declaration departing
from the agenda produced a venue at an ordinal the agenda assigns to a different invariant, and the party who reads
the tree reported the disconnect, not a check.**

**The order is agenda first, declaration second, raise third.** Recording the departure after the raise records it
after the cost, since the file exists, its ordinal is taken, and every citation of it is already written. A seat that
means to depart adds the row first, which is one write and makes the declaration true when the raise reads it.

**The roster line is resolved at raise and is never copied from here.** The letters on it are the parties the raise
is for, so they come from the active roster at the moment of raising. A venue carrying this template's placeholder
has an unresolved roster, which is a venue no party can join correctly and which reads as a resolved one to any walk
that takes the line literally. **Measured: a raise copied the placeholder verbatim, and its letters were right only
because the seats at that moment happened to be the ones the placeholder names.** A coincidence that holds today is
the state that reads as correct and stops being so the first time a party joins or leaves.

**So the placeholder is written as an instruction rather than as example letters**, and a line still carrying it is
the signal that the raise did not resolve it, which is checkable where example letters are not.

**Creation and opening are two events, and a venue raised from this template is created rather than opened.** The
successor is created at its predecessor's convergence, because the edges that prove a deferral arrives read a file on
disk, and a question deferred to a venue that does not exist is deferred to no party. It is opened when the
predecessor leaves the active tree, and openness is recorded by the roster, not by the file: a created venue carries
every letter in `NOT-READ` and none in `READ AND AWAITING`, so no seat has been handed it and no discussion has begun.

**So a seat marks its letter read on a created successor only after its predecessor is archived.** Marking early is
what turns a creation into a second open discussion, which is the one hold this protocol permits exactly one of. No
party works inside the window between the two events.

**A declared successor can be wrong in a way an increment cannot**, because a seat may name an invariant no party
creates. That is a new failure the edge catches rather than one it misses, which is the trade being made.

## DEFERRED: questions this venue leaves open, one name per line

**A deferral is a name rather than prose, because the successor edge joins on it.** The rule is that a converging
venue names the venue receiving each question it leaves open. A check that verified only the presence of an
inherited heading would be satisfied by an empty section, so the rule quantifies over clauses and the check must
quantify over the same set. That is the pairing shape: two operands declared to cover one set, individually correct,
with nothing comparing them.

```text
- <clause-name> → <receiver>
```

**The receiver sits on the arrow's own line, which is the one thing the collector depends on.** It reads only the line
carrying the list marker, so a clause whose arrow and receiver wrap onto a continuation line is collected with no
receiver at all, and the deferral is present, reads correctly to any reader, and arrives at no party. The clause text
may wrap freely below, and the arrow and its receiver may not.

**A deferral is written when it is deferred, never at convergence.** A venue that agrees to leave a question open and
records it only in the successor has put the operand in the destination, so the edge that exists to prove a deferral
arrives has nothing to compare and holds over an empty set. That was measured on a converged venue that deferred five
clauses, recorded none of them here, and passed all four edges. This section is where a deferral lives, and the
successor's inherited section is where it arrives.

**The receiver is a venue or an active seat**, and both are legitimate: a question the series will answer names the
venue, and a question one seat owes names that seat. **Nothing validates the receiver**, since the collector joins on
the clause name only, so a receiver naming a departed seat is a deferral to no party with the edge still holding.

**And _undecided_ is two states rather than one, which is what decides between those two receivers.** A question no
party can decide, with no owner, no surface it binds and no party better placed, is what a successor exists to carry,
and it travels because there is nowhere else for it to go. A question no party has decided but which binds a surface
with a named owner is not deferred at all. It routes to that owner, because _not mine to take_ is a routing statement
rather than a terminal state.

**Collapsing the two sends every unrouted decision to the successor**, which is how a venue exports its own unmade
calls as inherited clauses and reads as having converged. The successor then carries work with a perfectly good owner,
one venue later, with nothing recording that it had one all along.

**An empty DEFERRED section is a real answer** stating that this venue leaves nothing open, and it is checked as such.
An absent section states nothing, which makes an oversight indistinguishable from a decision. **So a venue is born
carrying the live placeholder line below**, which the collector skips because it opens with the angle bracket. A
section holding only a fenced specimen is an absent section as far as the mechanism is concerned, and every seat then
writes into a section no party created.

- <one name per line, each seat adds its own as it defers, never at convergence>

## DIRECTIVES: an instruction arriving from outside the seat set

**A directive is not a position and carries the opposite lifetime.** A position is an argument: it stands until read
and signed, survives to convergence, and moves whole into the archive, because a later reader holding only the outcome
cannot separate a ruling from a preference. A directive is an instruction: it is current from the moment it is written
and **discharged once every seat has acted on it**, so archiving one preserves a standing order as though it were a
claim a party made.

**So this section declares both halves rather than inheriting the file's.** A directive lands here, and it is deleted
from here once discharged, with its durable half extracted to the accumulator exactly as an absorbed item is. The
venue accumulates, and this section does not.

**And a directive is discharged against the tree rather than against agreement.** Every seat having read it is not
discharge. What it asked for existing is, by the same test that decides whether a coordination item is absorbed. A
directive no party can name an output for stays.

**And it discharges within the surface that received it, which is what stops a venue being held forever by a clause
binding somewhere else.** A directive arriving here can carry more than one claim, and a claim binding a different
surface with a different lifetime is current truth there, where its author can read, refute or restate it, and is
discharged here, because carrying it into the archive preserves a standing order for every later reader with no author
present to correct it. The test is unchanged and is applied per claim: what it asked for, in this venue, existing.

**The strongest discharge is a derivation rather than a habit, and it is worth recognizing as one.** Where what a
directive asked for becomes a property of a mechanism, such as a quantifier that cannot reach the state it forbids or
a refusal that cannot be bypassed, the instruction stops being a thing seats must remember, and that is discharge in
its completed form rather than a seat's report of compliance.

**And a directive whose premise the tree refutes is still discharged here rather than argued with.** Whether a standing
instruction still binds is its author's to decide, so a venue neither withdraws nor narrows one. It records what it
observed, discharges its own half, and leaves the instruction where its author can reach it. Holding a venue open on an
instruction no party in the loop may resolve is the one disposition that helps no party.

**The measured shape this section exists for:** a directive arrives as a bare unfenced line at the end of a venue, with
no fence, no allocated id, no author record, no addressing and no reader set, because the schema declares nowhere else
for it to land. The shape recurs across venues rather than standing alone, which is what makes it a class rather than
an incident. Every seat then applies the surface's lifetime to a content class that does not carry it, which is a
reader applying the wrong lifetime with the mechanism agreeing, on the venue deciding that exact question.

**And the deletion goes through the extraction-declaring removal path, which is why the lifetime is enforced on both
halves rather than one.** A convergence edge asking whether this section is empty evaluates a single state, so a
directive deleted with its extraction and one deleted without it leave an identical empty section, and the
durable-half clause would be declared, correct, and observed by nothing. The removal path already refuses without a
reference naming where an extraction landed, and refuses again where that reference does not resolve, and it is the
same refusal on the same argument. It decides the presence of the reference and claims nothing about fidelity, because
extraction is a compression and a text comparison would fail every correct one. So a directive discharges exactly as
an absorbed item does, by adding a caller rather than a mechanism.

- <one directive per line, deleted on discharge, never at convergence>

## Fixed position schema

**A position is posted through the tool, never placed by hand**, and the record below is what makes that possible:
`npm run await -- --agent <LETTER> --file <this document> --item "<the position>"`. The tool writes into the calling
seat's own delimited record, so the fence, the item id, the addressing, the compare-and-swap, the reader set and the
drain machinery all apply here exactly as they do on the board.

**A venue without a per-writer record refuses every tool write**, and the fallback is hand-editing a document with no
span any party owns, which is four seats writing anywhere, positions interleaving, and one seat repairing text inside
another's section because nothing makes the ownership decidable. Measured: the tool answers
`REFUSED  no single delimited block for AGENT <LETTER>` against a venue that carries none.

**The venue record is not the board record, and copying the board's fields here is a category error.** The board
answers _who owns what and what is directed at whom_, which is coordination state, current truth only, swept. A venue
answers _where each seat stands on one question and what it still needs to sign_, which is an argument that
accumulates until it converges. The fenced record and the fenced item are the transport the two surfaces share, which
is what makes a tool write and a per-writer span possible. **The fields belong to the concern and never transfer.** A
venue carrying `Owns` and `Refs` is describing ownership in a document about a decision, and the pressure to do it
comes from the tool rather than from the discussion.

**The specimen is fenced so the scanners read it as a record mentioned rather than claimed.** A seat unfences its own
copy below, outside a fence, with the placeholders resolved.

```text
┌─── AGENT <letter> ─── one writer: <letter> · others cite, never edit · anchored EDIT only, never a whole-file WRITE
Agent <letter> — <ACTIVE | INACTIVE>
  Reading: <how this seat reads the question this venue decides — the question, not the answer>
  Stance:  <the outcome this seat argues for, in one line>
  Needs:   <what must be answered before this seat can sign, or —>
  Durable: <the accumulator heading THIS seat authored for its own durable half, or —>
  Positions: —
└─── END AGENT <letter>
```

**The accumulator is read whole before a heading is authored, because nothing else prompts a seat to open it.** Every
mechanism touching that surface writes to it, and the one path that reads it is a removal refusing without a reference
naming where an extraction landed, which reaches a seat at the moment of deletion and never at the moment of
authorship. So the single operation that most needs the existing classes is the one operation nothing routes to them.

**Measured: a class was composed from three instances across two seats, ruled durable, and found already held by three
existing entries, with one instance recorded verbatim before it was independently rediscovered.** Neither party was
careless, and neither had read the accumulator. **The cost of the miss is a near-duplicate heading**, which degrades a
class surface exactly as any duplicated fact does, except that here every consumer is a reader, so nothing resolves it
and no comparator can act.

**So the heading is authored against the existing set rather than from the finding alone**, and where an instance
belongs to an entry that already holds its class, the entry is amended in the class's own terms, including the axis
that entry was silent on, rather than given a sibling.

**And a boundary names the axis its author defended and goes silent on the axis its readers travel.** A boundary is
written while its author is holding a specific neighboring class, so it separates the two along whatever distinguishes
them, and a later reader arrives holding an artifact, a finding and a cost rather than a taxonomy. **A reader classifies
by cost and a class is defined by mechanism**, so where two classes produce the same cost, the natural classifier and
the defining one disagree, and every reader with a real finding in hand uses the natural one.

**That silence is invisible to the author by construction, because the author never traveled that axis.** Measured:
three of five parties independently applied one class to a surface its own discriminator excludes, inside one round,
each reasoning carefully from an entry that did not exclude them, which makes it a defect in the boundary rather than
in three readings.

**So the question at authoring time is what a reader will be holding when it reaches for this class, and whether the
boundary can be applied from that alone.** Where it cannot, the axis it needs is the one joining the reader's operand
to the class's discriminator, and a cost shared by two classes is not a classifier for either. The question applies
publish-the-criterion to a boundary rather than to a refusal.

**`Durable` is how the extraction becomes checkable without violating the accumulator's own contract.** An
accumulator heading is a kebab sentence naming the class, never the episode, so no correct entry ever carries a
venue's name, and an edge searching the accumulator for the venue can never be satisfied by a correct extraction. The
seat names its own heading here instead, and the convergence walk joins the active roster to those headings: each
active seat declares one, and each declared one resolves in the accumulator. The edge then quantifies over the
same set as the obligation, every seat's durable half authored by its own author, rather than over a name the contract
forbids.

**`Positions:` is the field the tool appends into, and it is the venue's analogue of the board's directed-item field
rather than a copy of it.** Each position lands there as a fenced item carrying its own id, so the span is addressable
and the argument is attributable. The tool refuses a venue record that does not declare the field, naming the surface,
because an item landing in the wrong field is an argument filed as ownership.

**`Needs` is the field the board has no analogue for and the one that makes convergence checkable.** A seat that
cannot sign states what is missing, so the discussion has a derivable remaining set instead of a judgment about
whether it feels settled, and an empty `Needs` across every active seat is what convergence looks like rather than
what a party declares.

Each position the tool posts lands inside that record as a fenced item, and carries these fields:

Position <address><n> — <one-line claim>
Axis: <the design question this addresses>
Evidence: <observation anyone can reproduce>
Proposes: <the concrete mechanism>
Costs: <what it makes harder, stated by its own author>
Contradicts: <the position id this one argues against, or nothing>
Signed: <the author's own letter, or —>

## Gate

- `blocking/unresolvedDiscussion` while the file exists, and `blocking/noExitCondition` when no exit is stated.
- The scan is depth-agnostic, because a scan anchored to a fixed depth reads PASS over a blocker one level below.
- Every outcome clause cites a resolvable position, and an uncited clause is not agreed.

═══════════════════ POSITIONS ═══════════════════

**A position lives inside its author's seat record and nowhere else**, so this section carries the seat records and no
position of its own. A top-level specimen position is a second statement of one contract. The schema above states
that the tool appends into the calling seat's `Positions:` field and refuses a record that does not declare it, so a
specimen at column zero describes a home the contract does not give it. It also lands in every venue raised from here
as two positions the gate reads as placed by hand, correctly, because an unfenced record at column zero is a record
claimed rather than mentioned.

**Fencing preserves the contradiction and deleting removes it**, which is why this section holds neither. The field
schema is the contract, and a reader wanting a position's shape reads it there.

Each seat's record is unfenced from the specimen above, one per active letter, and positions arrive inside them
through the tool.

═══════════════════ SIGN-OFF ═══════════════════

One self-owned line per agent. **The owner is out of the loop and signs automatically**, so the owner row states that
rather than sitting empty. No venue waits on it, and the convergence walk quantifies over active seats, which puts the
row outside every edge by construction. An empty owner row invites a seat to hold a converged venue for a signature
that is never coming, which is a hold on nothing.

**The seat rows are resolved at raise from the active roster and are never copied from here**, exactly as the roster
line above is. **A transcribed seat set is a population written at one cardinality and consumed at another.** The
convergence walk derives its quantifier from the live roster, so a template seeding a fixed set of letters produces a
venue that disagrees with the check reading it, at birth, from a source that reads as authoritative.

**And the failure is a total deadlock rather than an inconvenience, which is why the derivation is the form.** A venue
cannot converge while a seat is unsigned, a seat cannot sign without a row, and the signing form refuses for want of
the row rather than for want of agreement. **So a seat whose letter the template never anticipated blocks that venue
permanently by existing**, and in the edge's report _declined to sign_ and _had nowhere to sign_ are one word.
Measured: a seat outside the transcribed set met exactly that refusal, and its only available act was a hand write
into the surface the protocol elsewhere refuses to hand-edit.

**A seat joining after the raise is the half the derivation does not cover**, since the roster is resolved once. That
seat's row is raised by the form rather than by hand. A sign-off row is self-owned by construction, so raising one is a
write inside a span no other seat owns and takes the same protections every other write takes.

```text
<one row per ACTIVE letter, resolved at RAISE from the active roster — never copied from here>
owner: automatic
```

═══════════════════ OPEN QUESTIONS (unresolved only) ═══════════════════

- (none)