Skip to content
Agentic Cinematic Universe

The rules, and what is still missing

11 rules bind every worker in the org. Below them: the decisions no worker is allowed to make alone, and every gap the org knows it has — written down rather than papered over.

Waiting on you

3 decisions only a person can make

  • Confirm the canon is authoritative so the 14 legacy ledgers can be archived

    What it affects
    Internal only. 20 migrated rows, 3 source files.
    Cost of leaving it
    None. Legacy files stand as the check on the migration until confirmed.
    Can it be undone
    Yes — legacy files untouched
    Waiting
    0 days, asked by the-ancient-one
  • Set the spend threshold per venture for the risk matrix

    What it affects
    Every spend classification in the org
    Cost of leaving it
    Every spend of any size is escalate until set. Fails closed, which is correct but noisy.
    Can it be undone
    Yes
    Waiting
    0 days, asked by the-ancient-one
  • Authorise Zoho CRM, Zoho Desk and Gmail connectors

    What it affects
    Pipeline, support and inbox metrics
    Cost of leaving it
    new_paid_icp_accounts, mrr and revenue_concentration_top3 print UNKNOWN. The Strange decision due 2026-11-11 cannot be fully scored without them.
    Can it be undone
    Yes — revocable
    Waiting
    0 days, asked by vision

Nothing is silently dropped. A decision you decline is recorded with your reason and removed.

Known gaps

18 things this org cannot do yet

  • Zoho CRM, Zoho Desk, Gmail and HubSpot connectors are unauthorised

    Four connectors require an interactive OAuth flow that a non-interactive session cannot run. Until they are authorised, VISION returns `UNKNOWN` for every metric sourced from them.

    To fix itauthorising the claude.ai connectors in an interactive session. Queued as `Q-003` in `AI-HQ/Queue/overnight.md`.

  • the spend threshold is unset

    `AI-HQ/Policy/risk-matrix.md` step 5 routes spend above a threshold to `escalate`. No figure has been set, per venture.

    To fix itMeet naming a figure for Finanshels and for Company8. Queued as `Q-002`.

  • no metric is defined yet

    `AI-HQ/Definitions/metrics.md` ships with the schema and the priority list, but zero definitions.

    To fix itthe first `/truth` run against authorised connectors. The five priority metrics are named in the file, in order.

  • net_burn_monthly and runway_months have no connector — but they now have a register

    Bank data. There is no connected system that returns cash position. Stripe covers revenue collected, not the bank balance or non-Stripe outflows. **This part has not changed and no amount of tooling changes it.**

  • two configured MCP servers failed to connect

    `plugin:github:github` returned `400 — Authorization header is badly formatted`. `themeetpatel-god-mode` returned `CONNECTION_CLOSED`.

    To fix itfixing the GitHub token format; investigating the god-mode server separately.

  • PostHog is connected but the project is not identified

    PostHog is reachable, but no project, insight ids, or event taxonomy have been confirmed against the real instance. Product-analytics metrics (`activation`, `retention`, funnels) name their intended source but not their query.

    To fix itone read-only `/truth` run naming the project and its insight ids.

  • no evaluation or routing history exists

    `Evaluations/scores.md` and `Runs/routing.md` are seeded empty. No dispatch has been scored and no routing row written.

  • activation tier per venture is asserted, not confirmed

    The build brief states Finanshels runs coverage 1–6 and Company8 runs 1–4. These are written into `context/personal/tier.md` (created 2026-08-28 during the audit fix pass). The values remain unconfirmed against the real org.

  • org-industry is off and untested against a real workload

    All seven industry add-on agents are built and disabled by default. Neither Finanshels nor Company8/Dan does manufacturing, clinical, field service, retail, real estate, insurance claims or lending.

  • the build brief and the sourced context pack disagree about Meet's role

    A sourced personal-context pack appeared in context/personal/ during this build — BIO.md, PORTFOLIO.md, context.md, SOURCES.md, and a replacement voice.md. It was not written by this build. SOURCES.md carries a source registry and a conflict log, with finanshels.com/about-us (S07) named as the official current source for Meet's Finanshels role.

  • files appeared in the working tree during the build

    Between 04:23 and 04:51 during this build, files were written into context/personal/ and plugins/org-exec/skills/ by a process that was not this build:

  • the routing log cannot express the cache-write TTL split — GAP-T5

    Cache writes bill at **1.25× on the 5-minute TTL and 2× on the 1-hour TTL**. `AI-HQ/Runs/routing.md` carries **one** `in_cache_w` field and `token-cost.sh` prices it at 1.25×.

    To fix ita schema change adding `in_cache_w_1h`, which is a canon-adjacent change and goes through `upgrades/pending/` (LAW 9) — not an edit somebody makes on the way past.

  • 46 of 49 tool playbooks have never been run against their system

    The `org-tools` layer ships 49 playbooks. Only **3** carry `verified: exercised` — `git-and-gh`, `bash-discipline` and `repo-scripts`, each backed by a real command run on 2026-08-28. The rest:

    To fix ita read-only run against each connected system, promoting its playbook to `exercised` with a date. The 10 connected connectors are promotable now. The 9 unreachable ones need the same OAuth work as `Q-003`.

  • a cited source can move without the citation breaking

    `cite-claim` verifies that a citation **exists**. Nothing verified that the source still **says** what it is cited for.

  • the deliverable gate has never fired from a real event

    Every job now ends in one artefact a stakeholder can read cold. The vault at ~/AI-HQ opens in Obsidian; scripts/deliver.sh writes through vault-write.sh (one write path, LAW 7) and refuses an artefact that would not be forwardable — no named audience, no headline, or an empty *What I could not establish*.

  • subagent skill visibility is assumed, not tested

    The `org-tools` tiering assumes a tier-1 `SKILL.md` auto-fires on description match **inside a dispatched subagent**, not only on the main thread. If it does not, the 124 agents in this organisation get no benefit from the layer without an explicit playbook reference added to each agent file.

    To fix itinstalling `org-tools` and dispatching one subagent with a prompt naming a connector — "check our Ahrefs setup" — then confirming whether `tool-ahrefs` fired.

  • three more connectors are unauthorised and were never on the list

    The entry above names Zoho CRM, Zoho Desk, Gmail and HubSpot. Observed in a live session on 2026-08-28, three more require an interactive OAuth flow and are equally unreachable: **IBISWorld**, **Zoho Automation**, and **meta-devtools**.

    To fix itauthorising them in an interactive claude.ai session. Nothing in a non-interactive session can complete an OAuth flow, and no session should be asked for a token or a callback URL.

  • the chat surface has no mechanical gate, and cannot have one

    Phase 14 put the org's doctrine into claude.ai — three Projects, 57 uploadable skills, the laws, the tiers, the lane. It could not put the *enforcement* there. claude.ai runs no hooks: `voice-gate-guard.sh`, `provenance-sentinel.sh`, `dispatch-telemetry.sh` and `deliverable-gate.sh` have no equivalent on that surface.

    To fix itnothing available today. If claude.ai gains a pre-tool enforcement point, revisit. Until then the honest posture is: **decide in chat, send at the desk.**

Writing a gap down is the honest alternative to a placeholder. Nothing in this org is faked — where the work could not be finished, that fact is the record.

The rules

11 rules every worker is bound by

  1. 1

    Evidence or UNKNOWN

    Every figure carries a source citation or prints UNKNOWN.

    Stops — a board pack, a forecast, or a tax position built on a number nobody can trace, discovered to be wrong after the decision was made on it.

  2. 2

    Prediction before action

    Any recommendation that can be wrong ships with a falsifiable prediction.

    Stops — an organisation that is never wrong because it never said anything specific enough to be wrong.

  3. 3

    Calibration is stated

    Before any agent makes a new call, it reads its own scored history in the canon and states its known bias in one line.

    Stops — the third confident forecast in a row from an agent that has missed the previous two, presented with the same confidence as the first.

  4. 4

    Risk-routed authority

    Every action is classified auto-act, recommend, or escalate before it runs. THE ANCIENT ONE owns the matrix at AI-HQ/Policy/risk-matrix.md and every dispatch passes through it.

    Stops — an agent that was right 200 times sending the 201st message to a real customer at 3am with a wrong number in it.

  5. 5

    Blind judging

    Verifiers never see the producer's reasoning.

    Stops — a verifier that is persuaded by the confidence of the reasoning rather than the quality of the result.

  6. 6

    Read-only sensors

    Anything reading analytics, SEO, ads, CRM, or logs reads only.

    Stops — a read that goes wrong and becomes a write that cannot be undone.

  7. 7

    One owner per output shape

    Two skills producing the same artefact means one is wrong.

    Stops — two agents giving two different answers to the same question and both being technically authorised.

  8. 8

    Everything compounds

    Every deliverable, decision and run lands in the vault.

    Stops — an organisation with a perfect memory of the last hour and none of the last year.

  9. 9

    No silent self-modification

    Agents propose changes to their own instructions. They never apply them.

    Stops — an org that drifts from its own documented behaviour with no diff anyone can read.

  10. 10

    Honesty over comfort

    Misses print without excuse.

    Stops — a hit rate that is high because the scoring is generous.

  11. 11

    The human residual is named

    HUMAN-RESIDUAL.md lists the classes of act that are always escalate, whatever the confidence, whatever the calibration, whatever the urgency. THE ANCIENT ONE classifies every action against it. There is no confidence threshold that promotes one of them to auto-act, and no agent may propose one.

    Stops — the single irreversible act that ends the company, performed correctly according to every other law.

Gaps already closed8 entries — including any that record an earlier entry as wrong
  • notedRESOLVED 2026-08-28: the vault remote is configured
  • notedNot gaps — decisions taken and recorded
  • correctedthe org can state its AI spend — the previous entry was wrong
  • closedthe routing log now has an automatic writer
  • noteda pending upgrade proposes a diff that is already applied
  • closedthe org had a described cadence and no clock
  • notedINCIDENT 2026-08-28: a test pushed fabricated financial figures into the live vault
  • notedRESOLVED 2026-08-28: the installed org was a copy, and drift was invisible