Version. 0.1
Date. 2026-07-31
Author. Claude.ai. Operator: Marvin Percival.
Status. The ordered plan for build-list items B-5 through B-9. Build-list item B-4; drafted under the charter's autonomous regime.
Evidence base. standing-notes/dunin7-build-list-v0_7; inspection-briefs/loomworks-walk-audit-operator-pass-findings-v0_1; inspection-briefs/loomworks-walk-audit-report-v0_1; current-status/current-status-manifest-v0_76 with its amendment; candidate-seeds/loomworks/loomworks-candidate-seed-v0_12. Plus two read-only inspections run 2026-07-30 and 2026-07-31 during the drafting of this note, recorded in §9.
Date note. Every document in the evidence base is dated 2026-07-30. This note is the first of the arc carrying 2026-07-31. The gap is a day boundary inside one continuous working session, not a filing error.
The walk audit of 2026-07-28/29 and the Operator's browser pass of 2026-07-30 between them produced forty-two numbered findings. This note does not answer them one at a time. It sets out what the completion arc is for, what governs it, in what order the work runs, and how anyone will know it is finished.
The finish line, restated from the build list: a firm's own document becomes a working engagement, information flows in, the summary view appears, a finished report comes out, a question gets a truthful answer with its sources shown, and an outsider can contribute without seeing anything else. Items B-5 through B-9 are the middle of that sentence — the second half of the pipeline, which today is reachable only through direct calls to the substrate.
What the audit found, in one line: the thread does not fray, it stops. Stage 1 — accumulating knowledge — is largely continuous through the Companion. Stages 2, 3 and 4 are continuous nowhere. Every step of the second half is a departure into a raw mechanism.
What the seed already commits. This arc builds nothing new. The seed's Rendering section states that every Render records what it was produced from — which Shape, which specialist, what configuration was in force, and which scopes' knowledge it composed — and that lineage is visible, across every scope it drew from. That sentence is B-9's authority. B-9 is not a new commitment; it is an unmet one. The Manifestation section's commitment that prior Manifestations are preserved but superseded is B-5's authority for the staleness marker. The constraint only show what is available governs every surface this arc touches.
A surface states only what it has read back.
The audit's findings are not eight broken screens. They are one defect wearing many faces, and the reason fixing them individually would miss the next one is that each fix would be a copy change, while the defect is structural: a surface collapses distinct conditions into one statement, and the statement is not derived from a read that could tell those conditions apart.
The rule has four faces. Each is testable, and each names the findings that are its evidence.
A surface reporting a write states it only after re-reading the record.
W-21 is the evidence: "Foundation saved — make it official. Your reviewed foundation is saved on the new project." The screen renders entirely from client-side state, never re-reads what it wrote, and therefore cannot detect that the write it is reporting carried a fabricated author (W-17).
Loaded-and-empty, not-yet-loaded, and failed-to-load are three conditions with three renderings, never one string covering all three.
This face carries the most weight. Its evidence is W-25 (a conversation pane showing "No conversation yet" and "Couldn't load earlier conversation" simultaneously, on an engagement with a full transcript); W-27 and W-9 (the Manifestation room reporting nothing organized on an engagement that derived one that morning); W-24 ("No unused codes remaining" where none were ever generated); W-20 (a production-mode diagnosis emitted for any 404, including person-not-found, on an engine running in development mode); W-23 ("Add a backup passkey" for a first passkey); W-41 (assertion numbering gaps with nothing accounting for them).
Six findings, one defect.
Anything derived from Memory shows what it was derived from, and whether Memory has moved since.
Evidence: W-34 (two renders both reading "Produced · ready to view", one saying four branches where the settled record says five); W-14 (downstream-impact lists the chain and marks nothing stale); W-16 (the Manifestation hop of a provenance walk cannot be resolved at the version the Shape was built from); and E0005 in the live record, whose newest Manifestation is twenty-five versions stale with no surface saying so.
This face is where the seed's operator-authority over artifact state transitions constraint applies precisely: the surface signals staleness, it does not transition the artifact. Marking a render out of date is a signal; retiring it is the Operator's act.
A surface does not commit to an action before the authorization for that action has been resolved.
This face was added on 2026-07-31 and is the sharpest of the four. Faces 1 to 3 concern a surface asserting state it has not read. Face 4 concerns a surface asserting authority it has not checked, and unlike the others it promises the Operator an action rather than describing a condition.
Evidence: on 2026-07-30, holding zero delegations, the Companion answered a request for a Board brief with "I can do that… I can write a structural draft with placeholders where those numbers belong." On 2026-07-29, holding the same zero delegations, the same classified intent produced the mandated refusal. See §3 for the full disposition and §9 for the one question that remains open.
Decision 2, settled: structural, not a review item. This project's standing principle is that correctness guarantees live in code, not prompts. A rule that depends on a reviewer noticing will produce the ninth face.
In the Operator Layer. Room surfaces consume a typed state value that cannot be constructed without a read having occurred. The shape this note commits to — the exact form is grounded at Step 0 against the real components, per the project's discipline of committing postures and deferring mechanisms:
The load-bearing property is that empty and populated both carry the read that produced them. A component cannot render an empty-state string without holding a value that proves a read completed, so face 2 is enforced by construction rather than by discipline. Populated carrying both its derivation version and the current version makes face 3 computable rather than optional.
In the engine. Face 4 is not a frontend concern. Its enforcement is ordering: authorization resolves before any branch that produces language committing to an action. The specific location is named in §6 as CR-D's first Step 0 item.
In each change request. Every change request in this arc carries a state-inventory table: every condition the surface can be in, the read that distinguishes it, and the exact copy for each. The type is the enforcement; the table is the review artifact and the acceptance evidence.
The walk overturned earlier positions, and the drafting of this note overturned more. Superseded positions stand alongside their corrections, per the seed's corrections preserved, not smoothed.
| Prior position | Current position |
|---|---|
| W-5 — recall returns a superseded value in the wrong lifecycle state. A stale-value defect. | Revised, worse in kind. The answer is not wrong, it is unstable. The same question asked three times against unchanged data produced: correct with its correction noted; a false confession of fabrication; correct with its source cited. A consistently wrong answer can be located and fixed. One that occasionally disowns itself cannot be trusted even when right. |
| W-4 — no retract affordance exists. | Confirmed and worse. The verb is understood. It searches the held tray rather than the settled record, then reports that the Operator's record does not exist — about a note it cites correctly by that number two turns later. |
| W-12 / W-13 — renders are indistinguishable, both labelled #1 — html_document. | Partially struck. They are clearly distinguishable by name on the surface, each naming its producing specialist. The strike is on identity only. The download half stands, and currency remains unmarked (W-34). |
| Row 1.1 — the held-items array returned empty. | Struck. The tray populated immediately in the browser with no refresh. |
| Manifest v0.76 §5 — the ask_about_past_input carve-out is the strongest lead for the recall defect. | Overturned as the diagnosis. That path answered correctly twice, citing its source. The residue stands as a real gap — it genuinely was never brought under the truthful-by-construction discipline — but it is not the cause. Belongs to B-11, not to this arc. |
| Manifest v0.76 §5 — the surface-silence class: four instances, the substrate holds the truth and no surface reports it. | Renamed and widened. Silence is a subset. The class is unverified assertion — the surface does not read back what it claims — and it now stands at twelve or more instances, most of which are not silence but confident wrongness. The prior name is preserved; a manifest amendment is owed at the next bump (§10). |
| Position | Held when | Status | |---|---|---| | The Companion refuses to shape, and the remedy it offers does not work. | Walk audit, 2026-07-29 | Original finding. | | Struck as written. Asked for a Board brief it complied with no refusal and no delegation demand. | Browser pass findings v0.1, 2026-07-30 | Withdrawn 2026-07-31. The strike was filed on the strength of a surface reporting a success it had not recorded — the exact class this arc exists to close. | | Conditional, in three parts. | This note, 2026-07-31 | Current. |
The three parts, separately:
request_draft turns exist across the two days, not two. The refusal fired on exactly one: the request carrying a cleanly extractable shape type ("produce a new shape of the current Manifestation…"). Two vaguer requests — a retry, and "produce a new draft of the Board brief" — produced no refusal and no production, only clarifying questions. It refuses when it can tell what is being asked for, and does not when it cannot.Recorded because the trajectory matters and because each was asserted to the Operator before it was withdrawn.
| Prior position | Current position | |---|---| | The grant phrase is untested — nobody has shown it works or fails. | Withdrawn. It fails, and the audit's own transcript was the proof all along. | | Delegation may not exist as real standing authority. | Withdrawn. It exists, as a committed assertion in the person's personal engagement carrying a delegation-typed content record. Checked per person and per engagement. Every account starts with zero. | | The Operator's account was established and therefore already held authority; the audit's was minutes old. | Dead twice. Nothing in that path distinguishes account age, and the walk-audit database holds exactly one principal — the Operator ran as the synthetic account throughout. | | The Operator may have committed the delegation without knowing. | Dead. No commit of that assertion exists in the event log; its only event is a single addition. | | The Companion delivered prose the Operator read as a finished draft, and the record never saw it. | Withdrawn. Nothing was delivered. It offered two options and asked which the Operator preferred; the exchange stopped there unanswered. | | The gate is composed rather than enforced — a language model talked past a denial. | Probably wrong, and not established. The likelier reading is that the request never reached the gate: the authorization check sits downstream of extracting what was asked for, so a request whose shape type cannot be extracted resolves on a different branch and is never checked. Unresolved; see §9. |
Decision 3, settled: five build-list items do not map onto five change requests. The build-list numbering stands unchanged; this is the mapping beneath it.
Change requests are lettered here for reference. Numbers in the CR-2026-NNN sequence are assigned at drafting, continuing from the highest then present.
Establishes the typed state contract from §2 and lands the Manifestation room as its first consumer. The room shows the derived Manifestation, its version, what it was derived from, and whether Memory has moved since — face 3's first instance. It renders the three empty conditions distinctly — face 2. The contract lands with a real consumer rather than as a standalone abstraction, because a contract with no user is a guess.
Why first: it is the front of the queue on the build list, and it establishes what CR-C and CR-D consume. Manifest Entry 126 records that the registry defect and the placeholder rooms masked each other, and that building the real Manifestation surface would have removed the mask — which is why B-1 had to land first. It has, and it is verified working in the wild: engagement E0007, previously unable to derive at all, derived successfully on 2026-07-30.
Three engine defects that feed the surfaces downstream. Different repository, different discipline, therefore its own change request.
Why here: may run in parallel with CR-A — different repository, no shared surface. Must complete before CR-D (which needs the title) and CR-E (which needs the version route).
Second and third consumers of CR-A's contract, together because they prove it generalises and because their state work is the same work.
What is deliberately not here: render naming. W-12/W-13's identity half is struck — they are already distinguishable and named on the surface.
Why the vocabulary is in this change request and not a cosmetic pass: it is an authorization surface. The exact lowercase word specification maps to one capability; every other word, including shape and brief, maps to a different one, so a delegation granted for one does not authorize the other. And vagueness about what is being asked for appears to decide whether authorization is checked at all. Teaching the Companion three rooms whose names it repudiates, on a path where the words select the permission, is self-defeating.
Depends on: CR-A and CR-C (surfaces to act on), CR-B (the title fix).
Click any statement in a finished report and walk backward to the person who said it: render to Shape, Shape to Manifestation at its pinned version, Manifestation to assertion at the version rendered, assertion to contributor.
The substrate already does this well. The audit's strongest single result was that the backward walk returns the text as it was rendered rather than as it reads today, which is exactly what a provenance walk is for. What is missing is a surface: the version-resolution route appears nowhere in the Operator Layer, and no surface exposes a single hop.
Depends on: CR-B (the version route), CR-A and CR-C (destinations for the hops), and B-25. See §5.
Already an item on the build list; not renumbered here. It runs in parallel from now, and it is the gate on CR-E.
Decision 5, settled: W-6 joins it as a fourth site. The same person contributing by talking terminates a provenance walk on Companion; contributing by typing terminates on their own name. The person identifier is identical; the kind and the readable name are not. CR-E terminates on the readable name. A walk whose final answer depends on which door the contributor used belongs with the three sites that fabricate that answer outright, and the sizing sweeps should carry it as a target.
CR-A (B-5) ──────────────► CR-C (B-6, B-7) ──────► CR-D (B-8) ──────► CR-E (B-9)
▲ ▲
CR-B (engine rider) ────────────────────────────────────┘ │
│
B-25: two sizing sweeps ──► B-25 change request ───────────────────────────┘
B-9 is gated three deep. The two sizing sweeps determine whether B-25 covers three sites or twenty; they have not been run. B-25's change request then repairs the provenance. Only then can a walk over that provenance be built. This is the point the Operator named at commissioning and it holds: a provenance walk over false provenance demonstrates a lie convincingly. Two engine sites currently write a fabricated author into the permanent record, a third relabels a Companion-triggered composition, and none of it is visible from any screen.
Therefore B-9 has no date. It has a dependency chain, and the chain has an unrun step at its head. The sweeps are read-only and could run today; they belong to B-25's own session, not to this arc, but nothing in B-9 moves until they do.
The parallel track is genuine. CR-B is a different repository from CR-A. B-25 is a different repository from CR-A and CR-C. Three fronts can move at once without collision, provided the record-writing discipline holds — every session re-verifies the repository head immediately before each write rather than trusting an earlier reading.
Per the standing rule, every change request opens with a read-only inspection before any draft. This note names what each must establish. It does not run them.
CR-A
RoomView.tsx carries a header referring to forbidden room-key literals. The seed's plain-terms discipline protects Memory, Manifestation, Shaping and Rendering on operator-facing surfaces. One of the two gives. The likely reading is that the wall was meant for code-level room keys rather than the methodology nouns, and the Companion is over-applying it — but that is a guess, and the file settles it. Raised rather than resolved: if the wall is deliberate at the level of the methodology nouns, it conflicts with the seed and the Operator decides which moves.CR-B
CR-C
CR-D
CR-E
The walk runs clean end to end. Re-run the same seed-to-render walk with the same instrument and the same classification vocabulary, across both lanes. Two criteria, both required.
Criterion 1 — zero raw-mechanism departures across Stages 1 to 4. The walk's own instrument already separates two kinds: departures into a raw mechanism, and hops from the Companion into an Operator Layer surface. Today the count is eight, six of them raw. Target: zero raw. Companion-to-surface hops are counted and reported, not failed. The product is not committed to being conversation-only — a screen is a legitimate place to look at things. It is committed to not turning the Operator into a mechanic.
Criterion 2 — decision 6, as amended 2026-07-31. The Companion does not commit to an action before the authorization for it has been resolved, and any artifact it delivers resolves to a shape event in the record.
Why the amendment was needed. Criterion 1 alone would have passed the 2026-07-30 exchange. The Companion answered a draft request agreeably, produced correct and readable content grounded in the record, and no departure occurred. Nothing entered the pipeline. A walk can run clean on a conversation in which nothing happened, and without criterion 2 it would score CLEAN and prove nothing.
The first draft of criterion 2 read every artifact the Operator receives resolves to a shape event. That is insufficient on its own: in the observed exchange no artifact was claimed, so an artifact test finds nothing to fail. The claim of capability is the thing to catch, which is why the criterion carries both halves.
Preconditions on the gate. W-2 and W-3 both sit at Stages 0 and 1, ahead of everything this arc builds. If either stands, the walk cannot complete and the gate cannot be run, regardless of how well B-5 through B-9 land. Both are named for Step 0 in §6 and both need build-list items (§10).
Struck by the browser pass — do not build.
Belongs elsewhere.
Named rather than smoothed. Each is a real gap in what this note can claim.
Owed to the manifest at its next bump. The surface-silence class in v0.76 §5 is misnamed and undercounted. Silence is a subset of unverified assertion; the class now stands at twelve or more instances, most of them confident wrongness rather than silence. Per corrections-preserved, the prior name and count stand with the correction marked alongside — not replaced.
DUNIN7 — Done In Seven LLC — Miami, Florida Loomworks — the completion scoping note — v0.1 — 2026-07-31 Build-list item B-4. The ordered plan for B-5 through B-9, the rule that governs them, and the gate that closes them.