# Unobservable rules — the conduct roster A rule declares `gate: conduct` when **no construct in any artifact observes it.** That is a claim, and the coverage check fails any conduct declaration this file does not carry. Each entry states what would have to become observable for the rule to acquire a check, so the claim stays falsifiable rather than becoming an escape hatch. `gate: conduct` is not a softer _ungated_. Enforcement debt is work to be drained; conduct is a closed question. A rule moves from conduct to a real check the moment its evidence lands in a file, and that transition is why each entry names its missing evidence. ## Why these cannot be checked A check reads artifacts. It cannot read a turn, an intention, a reading order, or a decision that left no trace. The rules below govern exactly those, and each is answered against one question — _what file would differ if this were violated?_ The answer is none. ## The checkable half is named rather than described **Many of these rules have a HALF that is decidable, and naming it in prose leaves it uncountable.** A rule whose conduct claim is honest can still carry a neighboring claim an artifact answers — whether a venue CONFORMS to its template, whether an item's reader set resolves, whether a report states the boundary of its own negative result. Describing that half inside the entry makes it visible to a reader and invisible to every count, so a named-but-unbuilt check sits outside the enforcement backlog forever while the roster reads as complete. **So each entry carries a third cell, and its vocabulary is closed to four kinds of value.** A **registered gate id** means the checkable half is observed and names what observes it. **`none`** means the half is decidable and **unbuilt** — which is enforcement debt, and belongs in the backlog rather than in a paragraph. **`—`** means the entry was assessed and has **no checkable half at all**, because its subject is an act rather than an artifact. **A failing question** — `no-declared-surface`, `subject-is-an-act`, `empty-population` or `not-evaluable` — names which of the four questions the half fails, so the entry says why no check can observe it. **A FOURTH DISPOSITION NEEDS NO FOURTH VALUE: the checkable half may be SPLIT OUT into its own slug, which carries the gate.** There the dash is correct — this entry has nothing left to check — and incomplete, because a reader following it concludes the half is unbuilt when a sibling already holds it. **So the entry names the SIBLING SLUG**, exactly as a filled cell names its operand, in the same place the range lives. The vocabulary stays closed; only the pointer was missing. **The dash is a real answer and it is the value the two-member vocabulary could not express.** Without it an entry with genuinely nothing to check is indistinguishable from one nobody has assessed, which is the same missing-member failure the roster keeps finding elsewhere — and it is the identical construct `decision_names_its_gate_or_its_proof` already uses, where a dash states that a decision binds no artifact and a blank states nothing. ### Re-walking the cells — the operand is the emitted KIND set, never the rule-id set **A cell asks whether a HALF is observed, and a half acquires an observer as a new KIND far more often than as a new rule.** So a re-walk that compares the debt cells against the registered rule ids misses every half closed by a kind added to a rule that already existed — and the two coincide only when a check arrives as a whole rule, which is the minority case. **Measured on this roster: a re-walk at rule-id granularity reported one closure and missed a second**, where the missed half had acquired a kind inside a walk that was already registered. That is the same granularity error the certifier itself made, at a different level: proving a rule is not proving its kinds, and enumerating rules is not enumerating observers. **The kind set is derived rather than assembled** — the certifier already enumerates every emitted kind, so the operand for _is this half observed_ exists and needs no new work. **A count offered for a reader's trust is the one worth checking hardest**, and a re-walk taken at the wrong granularity produces exactly the confident stale number the third cell exists to prevent. ### Assigning a cell — walk the questions, do not read the entry **Reading the entry is what produced the undeclared splits in the first place**, because an entry describes why the RULE is unobservable and the cell is about a different claim. Four questions in order, and only the last needs a reasoner: | question | how it is answered | what a failure means | | ------------------------------------- | ------------------ | ----------------------------------------------------------- | | does the half name a DECLARED surface | one search | nothing to quantify over — the half is imagined | | is its subject an ARTIFACT or an ACT | one search | an act takes `—`, and the entry is correctly conduct entire | | is the population NON-EMPTY | one search | a check over an empty set is a green that measures nothing | | is the property EVALUABLE on a member | judgement | not decidable, so not a checkable half | **Three of the four are one command each and only the fourth is judgement**, which inverts how this roster reads: every entry presents as a judgement and most of them turn on a fact. **AND THE FIRST VALUE NAMES THE OBSERVER, WHICH IS NOT ALWAYS A REGISTERED CHECK — A PREMISE THIS VOCABULARY HELD WITHOUT STATING.** A half can be observed and GATED by a pipeline entrypoint that refuses an operation outright, which is stronger enforcement than any registered check provides and carries no rule id at all. So the cell names the observer by its COMMAND where that is what observes it, and the entry states the consequence: **a count over registered ids cannot see it**, so such a half is enforced and uncounted. Naming the observer honestly and naming what the count misses is the repair; renaming the value would have made the count look complete. **A MECHANISM THAT OBSERVES THE HALF AND PUBLISHES WITHOUT FAILING TAKES ITS GATE ID, AND NO FOURTH WORD IS ADDED.** The case is real — a half that is decidable, BUILT, and watched by something that reports it rather than blocking on it — and it fits none of the three words. **It is a DIMENSION rather than a member**: the cell answers _what observes this half_, and _does the observer gate or merely publish_ is a different question. A fourth word would put a middle value on the observation axis, which is the tier the binary verdict refuses. **So the cell takes the id and the entry says it publishes rather than gates**, in the same place the range lives — because _publishes without failing_ is a range statement about the observing mechanism, narrower on the enforcement axis exactly as _the check is narrower than the rule_ is narrower on the population axis. **And what the count over gate-id cells MEASURES is stated here rather than assumed by whoever counts: OBSERVATION, never enforcement.** A reader tallying ids as enforced rules over-counts by however many publish-only observers exist, and the entry can tell a reader while a count cannot tell itself. **Naming the unit is the repair; a fourth word would have hidden the same gap behind a vocabulary.** **THE CELL HOLDS THE VALUE AND THE ENTRY HOLDS THE RANGE.** An observing check is often NARROWER than the rule whose half it answers, and a bare id then asserts more than it can. The repair is not a qualified cell: a value plus prose is uncountable, which is the whole thing the closed vocabulary buys. **So the range is stated in the entry text, beside the operand that entry already names** — the cell is what a count reads, the entry is where a reader learns scope, and neither is asked to do the other's work. **A row with NO third cell is UNASSESSED, and that is a declared state.** It states that nobody has compared this entry's claim against the current tree — never that the entry has no checkable half. That distinction is what makes the remaining work DERIVED from this table instead of transcribed as a count: **the unassessed set is the empty cells**, so no reader has to trust a number that decays the moment either surface moves. An entry's populated cell also names the operand it was compared against inside the entry itself, so a later reader re-runs that comparison rather than inheriting a verdict. ## Evidence and analysis | slug | what a check would need | checkable half | | ----------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------ | | `claims_are_lies` | a record of what was verified before each claim; verification leaves no artifact | `subject-is-an-act` | | `adversarial_default` | evidence that a deliverable was attacked before delivery; attacking leaves no trace | `subject-is-an-act` | | `a_claim_about_a_mechanism_opens_the_mechanism` | whether the file was OPEN when the claim was written — a read is not an artifact, and a claim that happens to be correct and one derived from the source are the same sentence. **The near-checkable half is a different claim and belongs elsewhere**: whether a claim RESOLVES against the mechanism is decidable for a citation and undecidable for prose, since a position asserting what a check does names no path a resolver could follow. Measured across two seats reasoning independently: eleven instances, every one a claim about a mechanism, none about a document, with both seats reading every document whole — so the distribution is evidence about the routing rather than about either seat, and no artifact records which surfaces a seat opened before writing. The half compared: an in-tree CITATION resolves or it does not, which the `reference` walk decides on every run | `reference/unresolved` | | `verify_before_edit` | the read that preceded an edit; reads are not recorded. **The write-side half is SPLIT OUT and `write_is_an_edit_until_proven_absent` carries it**, gated on the unwitnessed-write axis, so the dash here means nothing is left rather than nothing exists | `—` | | `write_is_an_edit_until_proven_absent` | whether a path was read in the same turn it was written; tool calls are not artifacts. The write's own report distinguishes a create from an update, which makes it a detection signal AFTER the contents are gone rather than a guard. The half compared: a file rewritten from an earlier read with no compared witness before the write, which the `entrypoint` walk decides — the guard is an artifact even though the read is not | `entrypoint/unwitnessedWrite` | | `read_files_whole` | whether a read was partial; the tool call is not an artifact | `subject-is-an-act` | | `architecture_is_the_target` | the level at which a file was read | `subject-is-an-act` | | `introspection_over_abstraction` | whether an abstraction was opened or stopped at | `subject-is-an-act` | | `caught_means_fixed` | the moment a violation entered context, against the turn it was fixed in | `subject-is-an-act` | | `classification_is_judgement` | whether a concern was decided by reading the file or by its old name | `subject-is-an-act` | | `absence_is_measured_never_inferred` | the SCOPE a SEARCHER drew — a zero carries only the boundary of the query, and one that stopped short and one that covered everything produce the same empty result in a turn that records neither. **The report half IS observable and is gated**: a report carrying a handed count while publishing no population, and one whose reached set is smaller than the set it was handed without naming the exclusion, both fail under the `governance` walk over the generated reports — so a negative result an ARTIFACT carries states its boundary or fails, and only a negative result a seat reasons to is outside. The operand that half was compared against is `unevaluableScopes` and the count-agreement axis in the governance validator; a later reader re-runs that comparison rather than inheriting this line | `governance/unevaluableScope governance/undeclaredExclusion` | | `derive_before_declare` | whether a declared value COULD have been computed, which is a property of the tree's other contents rather than of the declaration; a check would have to reconstruct the derivation it is arguing for. Walked: the subject IS an artifact and the fourth question fails — the property is not evaluable on a member without building the derivation whose absence is the finding | `not-evaluable` | | `installed_is_invoked` | a declared dependency's reach through configuration and source is checkable, and whether the reach is INVOCATION rather than mention is not — a name in prose is being discussed, so a check reading documentation counts a report about an unused dependency as evidence that it is used. The half compared: the `declaration` walk now reads the manifest and reports a declared dependency no source or configuration reaches. **The observing check is narrower than the rule on a specific axis**: it resolves a reach by NAME, so a type-only package reached by the COMPILER rather than by an import is invisible to it — the compiler config names the package in its own types field and every `node:` builtin import resolves through it, which is a reach no name scan sees | `declaration/unreachedDependency` | | `relations_are_graphs` | whether an answer about reach, cycles or coupling came from a traversal or from inspection; both produce the same sentence | `subject-is-an-act` | | `derived_not_heuristic` | whether a mechanism was derived or approximated | `subject-is-an-act` | | `uncertainty_is_stated` | whether a claim's uncertainty was known at the time it was written | `subject-is-an-act` | | `finding_becomes_record` | a durable finding that was left in conversation and never written | `subject-is-an-act` | ## Collaboration | slug | what a check would need | checkable half | | ------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------- | | `ask_via_tool_only` | the shape of a question asked in conversation. **It binds a SEAT only: the question tool is withdrawn from every bounded invocation regardless of what that invocation declares**, so the rule is vacuous inside one — the subject exists and the capability is removed by the runtime, which is a different reason from every other entry here. A bounded run states the uncertainty, states its assumption, names what would settle it, and returns | `subject-is-an-act` | | `recommend_never_abstain` | whether an answer carried a recommendation | `subject-is-an-act` | | `uncertainty_escalates` | uncertainty that was resolved silently rather than raised | `subject-is-an-act` | | `ask_before_dependent_work` | the order in which a question and its dependent work occurred | `subject-is-an-act` | | `report_before_writing` | whether findings were reported before files were written | `subject-is-an-act` | | `auto_mode_flows` | whether a response advanced the queue or halted | `subject-is-an-act` | | `blocked_waits_never_halts` | that every open item was blocked, and whether the wait was taken or the turn ended | `subject-is-an-act` | | `report_to_agents_never_to_owner` | who a response was addressed to, and whether a turn ended on it; the recipient of prose is not an artifact | `subject-is-an-act` | | `never_end_a_turn_to_wait` | that a turn ended while a wait would have produced work; the turn boundary is not an artifact | `subject-is-an-act` | | `quiet_is_not_permission_to_report` | that a wait reported no peer write and the turn ended rather than continuing; a tool result is not an artifact | `subject-is-an-act` | | `changed_means_read_then_act` | the order of a wait, a read and the next wait; tool-call sequence is recorded in no file | `subject-is-an-act` | | `no_append_without_a_drain` | that a write added an item and removed none — a surface holds its current content and never the shape of the write that produced it, so an append paired with a drain and an append alone leave identical artifacts. Walked: the subject is the WRITE rather than the surface, so the second question returns act; the absorbed-ness of a standing item is an artifact question and fails the fourth, since whether what an item asked for exists is decided per item by reading another surface. **The extraction half is SPLIT OUT and `removal_declares_its_extraction` carries it**, gated on a removal whose extraction reference does not resolve | `subject-is-an-act` | | `the_handler_removes_the_item` | that an item WAS handled and by whom — the surface holds the item and never the act of discharging it, so an item standing because nobody picked it up and one standing because its handler did not remove it are the same artifact; the reader-set constraint deciding who MAY close it is checkable while the handling is not. The half compared: a closure declaring it closes an id whose fence still stands, and an item whose reader set holds no active seat, both decided by the `board` walk | `board/danglingAddressee` | | `undecided_routes_to_an_agent` | that a decision was going unmade, and what happened next; an empty cell and a cell nobody has reached yet are the same artifact, and the routing is a tool call rather than a file. **The half that IS decidable is unbuilt**: a routed or deferred clause naming a receiver that resolves to neither an active seat nor a venue on disk is the same resolution the addressee axis already performs for board items. **BUILT: the `blocking` walk carries a stranded-deferral kind**, so a clause deferred to nobody now fails rather than passing. **The observing check is narrower than the rule**: it decides that a receiver RESOLVES and never that it is the RIGHT receiver, which is judgement no check reaches — and the convergence walk still joins on the clause NAME alone, so the resolution is a separate axis rather than part of the closure ordering | `blocking/strandedDeferral` | | `a_ruling_is_the_seats_and_the_owner_signature_is_automatic` | that a decision was ROUTED to the operator rather than taken — a position declining a ruling and one taking it are both well-formed prose, and the routing lives in a turn. **The near-checkable half is a different claim and it is already covered**: the convergence walk quantifies over active seats, so an operator row is outside every edge by construction and a venue cannot technically block on one, while whether the SEATS treated a question as theirs is not decidable from the artifact. Measured: two seats independently diagnosed one contradiction, both named the repair, and both declared it not theirs — a state indistinguishable by inspection from a question nobody had reached | `subject-is-an-act` | | `no_self_assessed_budget` | reasoning about capacity, which is never written down | `subject-is-an-act` | | `queue_is_explicit` | the queue as held in a turn rather than in a file | `subject-is-an-act` | | `feedback_capture_protocol` | that a directive arrived, which only the conversation carries; the hardening it produces is checkable and the arrival is not. Walked: the hardening IS an artifact and the fourth question fails — a rule present in three destinations and one present in three because a directive arrived are the same set of files, so the property is not evaluable without the arrival | `not-evaluable` | | `friction_is_a_missing_mechanism` | that friction OCCURRED and what the first response to it was — a diagnosis is reasoning in a turn, and the artifact records only the repair that followed, never the alternative rejected. **This is the one conduct entry whose own subject is the insufficiency of conduct**, so the honest reading is that the rule governs the moment of diagnosis while every mechanism it produces is checked on landing | `subject-is-an-act` | | `collab_board_checked_first` | whether the board was read before the first edit | `subject-is-an-act` | | `board_is_read_whole` | whether a read covered the whole board or a slice of it; a read leaves no artifact. **The precondition half is a different claim and is already gated**: whether the board CAN be read whole is a property of the artifact, held by the field-size and projection-size axes of the `board` walk, while whether a reader did is not. **That half is SPLIT OUT into its own slug and `field_stays_within_one_read` carries it**, so a reader following this entry finds where it went rather than concluding it is unbuilt | `—` | | `a_coordination_read_is_never_filtered` | whether a delivery was CONSUMED whole — the filter is a shell pipeline taken inside a turn, recorded in no artifact this tree holds, and a stream consumed whole and one consumed through a bound leave byte-identical trees. Walked: the half names a declared surface, and the second question stops it — the subject is an ACT rather than an artifact, so the third cell is the absent marker rather than an unbuilt check. **The near-checkable half is a different claim and worth naming so the entry does not appear to be hiding one**: whether a rule's obligation names its CARRIER is a property of the rule TEXT, decidable, and distinct from whether anyone filtered — an entry conflating them would claim a checkable half it does not have. **The measurement the entry carries is that four of four active seats breached it before it was written**, each having read the file-scoped obligation, which is a complete population with a uniform outcome rather than a distribution — evidence about an obligation whose consumer was never built, and not about where a declaration may live. **AND THE REMEDY IS CATEGORICAL RATHER THAN ATTENTIONAL, WHICH IS A PROPERTY OF THE CLASS AND NOT ADVICE.** The filter is chosen FOR a confirmation line rather than AGAINST the content, so it is never a decision about what to discard — the peer diff was never in the frame, and a tell firing on _am I discarding something_ asks a question the moment does not contain. So a per-call rule needs a party to notice the call is a read, and the class is defined by the call not feeling like one. **Measured on the sharpened tell failing and the categorical rule holding**: a seat breaching after authoring its own tell and disclosing it, a second breaching twice while holding both that entry and that disclosure, a third breaching once on a call taken as a probe — against one seat reporting a whole round of unfiltered reads including pure probes and one delivery the form degraded, which decided nothing per call because it decided once at the command that nothing is ever attached to it. **The cost of the categorical form is that a genuinely useful filter is unavailable too, and on this channel that cost is zero**: the form degrades a large delivery rather than truncating it, and a run's report on disk is the sanctioned narrowing | `subject-is-an-act` | | `a_repairer_runs` | that a run FOLLOWED a repair by the same party — a report on disk records the state it measured and never who changed the tree before it, so a repair-then-run and a repair-then-someone-else-ran leave identical artifacts. **The near-checkable half is a different claim**: a report older than the newest source change is detectable, and it says the state is stale rather than saying the repairer declined to publish it, since any seat's edit ages every report equally. Measured across two repairs in one discussion, distinguished only by which seat's item reported the run. The half compared: a report whose newest read surface is older than that surface's own change is detectable, and the standing mechanism in the pipeline already computes exactly that moved set and withdraws the verdict's authority — so staleness is observed by the RUN and attribution is not. **The observer PUBLISHES rather than GATES, and deliberately**: the standing mechanism withdraws a verdict's standing to be quoted and never declares it failed, because declaring a stale report failed would assert a defect nothing observed — and a finding here would be red between every run, which is the unreachable-remediation shape that teaches every reader to discount the color. So this cell records observation rather than enforcement, per the ruling above | `pipeline` | | `a_venue_is_read_before_it_is_written` | that the venue template was read BEFORE a seat's first position, which is a reading order and no artifact records it. **The near-checkable half is already covered elsewhere and is a different claim**: whether a venue CONFORMS to its template is decidable and belongs to the venue check, while whether its author read the template is not — a conformant venue written by a seat copying a peer's record and a conformant venue written from the contract are the same artifact. Measured: four seats produced four formats from four sources with the contract one directory away, and no inspection of any resulting document distinguishes which source each seat used. The half compared: a venue whose record schema disagrees with the template it derives from, decided by the `blocking` walk | `blocking/venueSchemaDrift` | | `absent_board_is_not_solitude` | that the tree moved beneath a seat between reads | `subject-is-an-act` | | `commuting_writes_replay_rather_than_refuse` | that a write was attempted and what the tool did on finding the surface changed — the retry, the comparison and the refusal are runtime behavior, and the artifact records only the final content, which is identical whether the write landed first, replayed, or was re-derived by hand after a refusal | `subject-is-an-act` | | `an_intended_write_to_a_shared_prose_surface_is_announced` | that an announcement PRECEDED a write, which is an ordering between a position and an edit — and the shared prose surfaces carry no writer identity anywhere, so a section written after an announcement and one written without it are the same artifact. Walked: the subject is the ANNOUNCEMENT relative to the write, so the second question returns act, and the operand that would settle it is the authorship the surface does not record. **The near-checkable half is a different claim rather than an unbuilt one**: whether two passages state ONE CONTRACT is semantic, which no mechanism here decides, so this entry carries no deferred check and is not enforcement debt. The half compared: the anchored edit already refuses an overlapping write and admits a commuting one, which is the mechanical axis working correctly and a different axis from this one | `subject-is-an-act` | | `foreign_scope_is_untouchable` | which seat made an edit; edits carry no author. **One case IS observed**: a delimiter for one seat falling inside another's fence is caught by the `board` interleaved axis, whose own reason states it — a fence enclosing another fence passes the pair check while an edit anchored on the outer one spans the inner content. **Two cases are unreached**: foreign PROSE written into a record, which brings no delimiter for that axis to match and is the cheaper way to intrude, and an ITEM whose letter differs from its enclosing record's, which the `board` walk NOW observes as a foreign-item-letter kind — so of the three cases only foreign PROSE remains unobserved, and it remains so because it brings no delimiter for any axis to match | `board/interleavedRecord board/foreignItemLetter` | | `scope_is_claimed_not_assumed` | whether ownership was claimed or inferred | `subject-is-an-act` | ## Process and method | slug | what a check would need | checkable half | | -------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------- | | `plan_is_drafted_then_restructured` | that a draft existed before the restructure | `subject-is-an-act` | | `follow_template_as_stated` | whether execution condensed or adapted the nodes | `subject-is-an-act` | | `template_selector_is_genesis` | which genesis question selected a template | `subject-is-an-act` | | `mechanism_transfers_catalogs_rederive` | whether a catalog was re-derived or a mechanism substituted; the artifact carries the result and never which of the two produced it | `subject-is-an-act` | | `clear_unblocked_work_is_performed_rather_than_routed` | whether an item is clear and unblocked AT THE MOMENT it is routed, which is a judgement about a state the row does not carry — a routed item and a routed-item-its-owner-could-have-taken are the same row, and the blocker that justifies one lives in a turn. **Walked properly, the fourth question refuses it and the earlier reading was wrong about where the operands live.** The candidate half — a row whose owner is the party that owns the surface it targets, with no named blocker — needs a TARGET-TO-OWNER mapping, and the row carries only the first operand. Ownership is declared by CONCERN in prose rather than by directory, so resolving a target path to an owning party is an interpretation of a concern claim rather than a comparison, and that is judgement no check reaches. **The weaker decidable half is worse than none**: a row carrying no named blocker is decidable and fires on every legitimately routed row, which is a check that punishes the right answer and teaches everyone to write the wrong one. **Stated plainly because a cell corrected TOWARD the dash removes a debt entry, which is the direction a reader trusts least** — the reasoning is declared rather than quiet, and a peer re-walking exactly this cell is worth more than one re-walking any other | `not-evaluable` | | `a_venue_is_absorbed_before_it_is_archived` | that the work an outcome IMPLIES has landed, which is a judgement about whether a decision is fully built — a tree where the outcome is implemented and one where a subset landed while nobody noticed the rest differ only by a reading of the outcome's own prose. **The near-checkable half is decidable and unbuilt**: a converged venue whose distribution checklist still carries an open item is a venue not yet absorbed, and both operands are files. **BUILT and GATED**: the convergence walk carries it as a sixth ordering — the outcome is ABSORBED, the distribution checklist for this venue carries no open item — which REFUSES the closure rather than reporting it, so the enforcement is stronger than any registered check offers. The observer is a pipeline entrypoint and carries no rule id, so it is named by its command and **a count over registered ids cannot see it**: this half is enforced and uncounted. The rule stays conduct because whether the work an outcome IMPLIES has landed is still a judgement the checklist's own completeness cannot settle | `converge` | | `a_destructive_tool_carries_every_standing_precondition` | that a standing precondition was CHECKED against a tool's code before an irreversible invocation, which is a read in a turn — and after the operation the tree cannot even show what was lost, because the operand is gone. **The near-checkable half is decidable and unbuilt**: a standing instruction naming a step, against the destructive tool's implemented steps, is two enumerations over files that exist. Measured once, on a converged discussion that a standing instruction required be archived and the convergence tool deleted, having never claimed an archive step — the tool was correct, the instruction was correct, and nothing joined them. The half compared: each CLASSIFIED standing precondition against the steps the destructive path implements, both declared operands, which the `converge` walk decides on every run — its range is the classified set rather than every instruction in prose, since extracting a step from prose needs a phrase list or an inference and both are refused, so an unclassified precondition stays outside it and the registry growing is how the class transfers | `converge/unimplementedStep` | | `a_mandated_surface_is_tool_writable_first` | that a mandate was added BEFORE its write path, which is an ordering between two changes and no artifact records it — a surface mandated with a tool path and one that acquired the path afterwards are the same tree. **The near-checkable half is BUILT and observed**: the `surface` walk compares each surface a refusing mechanism requires against the surfaces the tool can write, and fires where a party must write one the tool cannot reach. **The observing check is narrower than the rule on two axes and both are stated rather than implied**: its population is the surfaces this configuration DECLARES, so a mandate naming a surface the configuration never declared is invisible to it; and the requires-a-write classification is verified DATA the mechanism reads rather than a property it infers, seeded only with surfaces whose refusal was read at the source. It says nothing about the ORDERING the rule names — a surface mandated with a tool path and one that acquired the path afterwards remain the same tree — which is why the entry stays conduct while its half is observed | `surface/noWritePath` | | `determinism_is_the_one_axis` | whether a subject was TESTED for determinism before its mechanism was designed, which is an act in a turn — a mechanism built after the test and one built without it are the same artifact. **The near-checkable half is a different claim and it is this column**: whether a rule DECLARES which of its halves is deterministic is decidable. **BUILT: the `conduct` walk carries an unstated-half kind**, failing any entry whose third cell is absent — so the declaration is observed rather than answered structurally and trusted. **The observing check is narrower than the rule**: it decides that a cell is PRESENT and drawn from the closed vocabulary, never that the subject was TESTED for determinism before its mechanism was designed, which is the act the rule names and which no artifact records. Measured on this roster: sixty-two of seventy-six subjects are non-deterministic, so the four properties the axis derives are absent for four fifths of the protocol | `conduct/unstatedHalf` | | `gate_every_pattern` | that a construct was introduced, against the check shipped with it. The half compared: a REGISTERED check shipping with no proving fixture, which the certifier carries as an unfixtured-kind set counted into its open total, so an unproven kind fails the run. **The observing check is narrower than the rule** — it decides that a registered check is proven and says nothing about whether a new CONSTRUCT acquired one, which is the turn this entry correctly calls unobservable | `gate/unfixturedKind` | | `bypass_strengthens_rule` | that a bypass was spotted, and what happened first | `subject-is-an-act` | | `scoping_re_runs_the_motivating_case` | that a rule was NARROWED and the motivating case was run against it afterwards — both are acts inside a turn, and a scope authored correctly the first time and one narrowed then re-verified produce byte-identical source. Walked: the subject is the AUTHOR's re-run rather than an artifact, so the second question returns act. **The near-checkable half is a different claim and it is OBSERVED**: whether a predicate's identity asserts an axis its body never reads is decidable over a closed declared vocabulary and a body scan, and the `declaration` walk carries it as an unread-asserted-axis kind — scanning the BODY rather than the signature, deliberately, so that a predicate resolving the declared record inside itself is reached rather than passing as a true negative. **The observing check is narrower than the rule on two axes, both stated in its own remediation**: it answers one instance of the shape this rule generalizes and never whether any refinement anywhere was re-tested; and its residue is a predicate naming NO axis while reading the wrong fields, left ungated rather than gated weakly, because what a predicate is FOR is held by no surface. **Its POPULATION is worth knowing and is unmeasured** — a check that exists still ranges over a set nobody has counted. **Measured, three times in one round and twice by the party proposing the refinement**: a gate proposed against a subset-reading consumer that a declared read-set would have matched and passed; a scope narrowed to functions whose parameter type is the declared record, where every correct member takes it that way and the failing one resolves the record internally; and a matcher keyed on an axis name and its declared values, where the defective identity carries the adjective and neither literal. **A fourth arrived on the check built FROM this rule**, caught by running the case rather than by reading the scope, which is the rule's own subject arriving on its own enforcement | `declaration/unreadAssertedAxis` | | `remediation_is_reachable` | that a repair was ATTEMPTED and REFUSED by a surface outside this tree — the refusal happens at the write, leaves no artifact, and the file afterwards is identical to one nobody tried to edit. **And a refusal is per-SEAT rather than per-tool, which no artifact records either**: measured on one removal two seats were refused and a third was permitted, on the same tool with the same operands, so a refusal carries only the boundary of the party who hit it and a claim about the TOOL cannot be derived from one environment. The consequence is routing rather than exemption — a refused repair is re-addressed to the other seats and the first permitted one takes it — and `interpreter_invocation_denied` is the prior art, already attributing its own unobservability to a surface outside this tree | `subject-is-an-act` | | `manual_edit_only` | which tool performed an edit | `subject-is-an-act` | | `draft_precedes_replacement` | that a draft preceded a structural replacement | `subject-is-an-act` | | `existing_owner_first` | that alternatives were considered before a capability was added | `subject-is-an-act` | | `build_the_missing_tool` | that a capability gap was met with a workaround instead of a tool | `subject-is-an-act` | | `bisect_before_forensics` | the order of isolation steps during a failure | `subject-is-an-act` | | `baseline_reverified_on_env_change` | that a baseline was re-established | `subject-is-an-act` | | `instrument_single_subject` | how a measurement was taken | `subject-is-an-act` | | `mutation_preview_first` | that a preview was shown before application. **The preview PATH is an artifact and is gated**: the removal tool's non-healing branch shows exactly which fields would go before any extraction happens, and the `entrypoint` walk holds healing opt-out and the unwitnessed-write axis — what stays unobservable is whether a seat LOOKED at the preview it was shown | `entrypoint/healingIsOptIn entrypoint/unwitnessedWrite` | | `side_effect_authority` | whether a command was handed over or run | `subject-is-an-act` | | `no_runtime_dependencies` | whether an adopted dependency was structurally unavoidable, which is a judgement about alternatives that were never written down. **The load-bearing half is ONE FIELD and is decidable**: whether the manifest declares any runtime dependency at all. The half compared: the manifest carries an empty dependency object. **BUILT: the `declaration` walk carries a declared-runtime-dependency kind**, so the invariant is observed rather than holding because nobody has added one. **The observing check is narrower than the rule**: it decides that a runtime dependency is DECLARED and says nothing about whether an adopted one was structurally unavoidable, which is the judgement about unwritten alternatives the entry names | `declaration/declaredRuntimeDependency` | | `interpreter_invocation_denied` | that an interpreter was invoked directly; the invocation is a tool call, and the denial itself lives in the host's settings rather than in this tree | `subject-is-an-act` | | `scratchpad_is_ephemeral` | that something transient was reusable and stayed transient | `subject-is-an-act` | ## Design judgement A check reads what a file _is_, never what its author weighed. These govern the weighing. | slug | what a check would need | checkable half | | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------ | | `consumer_breaks_without_it` | the behavior of the tree in the state where the surface does NOT exist — a counterfactual, so what a check must observe is not on disk by construction. A check could certify that a consumer is NAMED, which is presence rather than breakage, and one claiming the second while measuring the first passes exactly the decoration the rule refuses. Walked: the subject is a COUNTERFACTUAL state of the tree, so the first question already fails — there is no declared surface for a state that does not exist, and the nearest available check measures a different property | `no-declared-surface` | | `non_goal_is_stated` | the scope that was considered and deliberately excluded. The half compared: the task-contract field set carries a non-goal field beside file, evidence and verifier, and the checklist walk requires every task to carry its contract — so a task with no non-goal is a finding. **The observing check is narrower than the rule**: it is gated where the unit is a TASK and unbuilt for every other kind of unit the rule binds | `checklist/contractIncomplete` | | `a_measured_entry_retires_by_extraction` | that an entry LEFT a governing surface, and whether an extraction preceded it — a surface holds its current content and never the shape of the write that produced it, so a document that never carried a measurement and one whose measurement was pruned are the same artifact. Witnessed by the seat whose document it is: a measured set replaced anticipated entries, then the anticipated ones were restored beside them on a peer's argument, and nothing in the tree objected at either step. The half compared: a role document declaring a measured section that is ABSENT or EMPTY is decidable. **BUILT: the `role` walk carries a measured-section-unfilled kind**, so a document declaring the section and leaving it empty now fails. **The observing check is narrower than the rule**: it observes the section's EMPTINESS and not the removal of an entry from a populated one, which is the ordering the rule names and which no artifact records | `role/measuredSectionUnfilled` | | `nothing_silently_dropped` | that displaced content vanished rather than moved. **Walked properly, the second question already answers it: the subject is a RESTRUCTURING, which is an act no artifact records** — a tree where content moved and one where it vanished are the same tree, and only the author's intent separates them. **The near-checkable half is a DRAFT standing beside a live file with no published migration map**, which is the draft rule's own shape and is decidable — and its POPULATION IS EMPTY here, because this tree carries no draft convention and holds no drafts. A check over an empty set is a green that measures nothing, so building one would ship a field that always says the same thing and make its own greenness the evidence that the thing it measures is working. The earlier reading of this cell as decidable-and-unbuilt confused the empty near-half with the act, and a search of the toolchain for any reader of a map or a displaced-block record returns zero files either way | `subject-is-an-act` | | `optimisation_follows_a_measurement` | that a change was made FOR speed, and what was measured before it — an optimized implementation and a speculatively rewritten one are the same artifact, and the measurement lives in a run rather than in the tree | `subject-is-an-act` | | `gate_that_saturates_is_not_built` | a check that was NOT built, and why — the artifact records the checks that exist, never the one an author declined and the property declined with it. **A saturating check is indistinguishable from a working one by inspection**, since both are green: the difference is whether anything could disagree, which is a property of the field's semantics rather than of any file. Walked: the second question returns act — the subject is a check an author DECLINED, and a declined mechanism is absent from the tree by construction | `subject-is-an-act` | | `mechanism_consumed_date_is_an_operand` | whether something READS a date to decide — the discriminator is a consumer's behavior rather than the value, so two identical timestamps differ only by what happens to them, and the consuming mechanism may live in another runtime entirely. Walked: the subject IS an artifact and the fourth question fails — the property is a CONSUMER's behavior, and where that consumer is outside this runtime nothing in the tree evaluates it | `not-evaluable` | ## Template execution The templates are checked as documents — mandatory gates and independence both hold. These remaining rules govern the **executed artifact**, which is produced in a turn and persisted nowhere here, so there is no file to read. | slug | what a check would need | checkable half | | ------------------------------------------ | --------------------------------------------------------------- | --------------------- | | `decisions_are_typed` | the executed artifact's decisions and their declared shapes | `no-declared-surface` | | `repair_from_earliest_owner` | which node a failed gate routed back to | `no-declared-surface` | | `severity_routes_never_orders` | whether severity ordered phases or routed failures | `no-declared-surface` | | `ripple_carries_names` | an impact record, to check it names entities rather than counts | `no-declared-surface` | | `generation_gates_are_not_execution_gates` | which gates were resolved while producing versus while running | `no-declared-surface` | | `descriptive_is_not_full_shaped` | whether the full loop was forced onto a descriptive artifact | `no-declared-surface` |