Version. 0.20
Date. 2026-08-03
Status of this document. The single guide we work to. This is the one page the Operator reads at each sitting. Charter v0.1 ratified 2026-07-30; autonomous regime in effect. Day-to-day status lives in current-status/dunin7-status-brief.
Author. Claude.ai; v0.3–v0.4 and v0.10 by Claude Code; the rest by Claude.ai.
Changes from v0.19. B-10 is closed — outside contributors can now be credentialed into an engagement without ever becoming members of it. **And this version answers what next explicitly**, at the top, because the list has grown to the point where the answer is no longer obvious from reading it.
Two things, and the order matters.
First: the three items that stop anyone saying "the tests pass." B-33, B-34 and B-42. All small, all verified small, and together they are worth more than their size — every change request this week has had to record a baseline failure set and compare against it, because neither repository can report a clean run. Fixing that makes every future build's verification simpler and its gate stronger. It is the difference between no new failures against a set I wrote down and it passes.
Then: B-11. The largest thing left on the main line, and the only thing standing between here and the last third of the demonstration — B-12 and B-13 both wait on it. It is big enough to want a clean baseline underneath it, which is the other reason the cluster goes first.
Everything else can wait, and most of it is small enough to slot in whenever a session is short.
It is written for you first. Technical cross-references sit at the end of each line for the sessions.
The highest-numbered version is always the truth — past nine, sort as numbers, not text.
Some numbers are deliberately absent. Where a count grows every time something is built, this list names the mechanism and says to count it at scoping time. A figure written here is wrong before it is read.
The statuses: READY · IN PROGRESS · NEEDS YOU: decision · NEEDS YOU: act · WAITING · DONE · PARKED.
The finish line, in one sentence: the full live demonstration works with no excuses — a firm's own document becomes a working engagement, information flows in, the summary view appears, a finished report comes out, a question gets a truthful answer with its sources shown, and an outsider can contribute without seeing anything else.
B-10 — an outsider can contribute without becoming an insider.
A person who is never a member of an engagement can be given a credential by its Operator, claim it through the ordinary sign-up, and contribute into that engagement. Their contributions land unadmitted, fully attributed to them as a person, and admissible only by members with commit authority. They can see their own submissions and nothing else.
The fence is structural rather than a rule. Membership is what every existing read checks, and a credentialed non-member has no membership — so they are excluded from all of it without a single existing read being changed.
Three real defects were caught by its own acceptance tests, not by review: a revoke that reached across engagements, a query filter that was literally correct and broke the moment something was committed, and a value the system emitted that its own schema did not allow. All three were found by tests written to prove the acceptance criteria — the same pattern that caught a README nobody could follow two days ago.
(CR-2026-157 with its amendment note; engine 3b10ff1, tag cr-2026-157-non-member-contribution-v0_1.)
> One thing worth knowing about how it nearly went. That change request was written before the charter existed and sat unexecuted for a week. A check confirmed every function and line it named still resolved — and it would still have run a migration down-and-up cycle against the live production database, because that fence was written after it was. The code had drifted; the rules had drifted further.
B-1 to B-7. DONE. The four rooms exist: Memory, Manifestation, Shaping, Rendering.
B-8. Teach the Companion the last three rooms. READY — unblocked. (Change request D. First Step 0 item: does a vaguely-worded request skip the authority check entirely?)
B-9. The "show me where this came from" walk. DONE.
B-10. Outside contributors, safely. DONE. See above.
B-11. Make answers truthful. READY — and the recommended next build after the cluster below. The answer isn't wrong, it's unstable: the same question three times gave correct, then a false confession of fabrication, then correct with its source cited. Needs a Step 0 before anything is drafted.
B-12. Make the record searchable. WAITING on B-11. The biggest single piece of engineering on this list. May merge with B-11.
B-13. Ask your engagement. WAITING on B-12.
B-14. Read spreadsheets and slide decks. READY (independent).
B-33. The engine's one broken test. READY — small. One long-standing failure, unrelated to anything built.
B-34. The surface's test run ends in an error state. READY — small. No test fails and the run still exits non-zero, because background requests from shared layout components are left unhandled. Any new screen's test that renders them without mocking adds to the count. No figure here on purpose — count it when you scope it.
B-42. A rule the codebase breaks systemically. READY — small. One code-quality rule is broken across many files, including the room that is the model everything else follows. And lint is not otherwise clean either. No figure here on purpose; it has moved with every room built.
These three are one problem wearing three hats. In each case nobody can read a clean report as clean, because a standing exception has to be held in mind — and a standing exception is how a second failure hides. Worth doing together, and worth counting each afresh when they are.
B-16. Update the foundation document. READY to draft · NEEDS YOU: act (read it first). (Seed v0.13.)
B-17. The portfolio filter. READY. B-18. File the four protocol requirements. READY. B-19. Keep this list alive. IN PROGRESS.
B-25, B-27, B-28, B-29, B-41. DONE.
B-26. Correct the record about door 3. READY (small).
B-30. The trap that caused B-27. READY — small. Never repaired; only the broken door was removed. The test suite cannot see it.
B-31. The post-admission lifecycle investigation. READY to open. An investigation, not a build.
B-32. The re-derive button on the Manifestation screen. READY — small.
B-35. A missing key looks like a crash. READY — small.
B-36. A way to retire a render. READY — small.
B-37. Show when a shape's production has failed. READY — small (engine).
B-38. Bring the Rendering screen onto the shared contract. READY — small.
B-39. Ephemeral agent identities. READY to scope. B-40. Where contributed Markdown should go. READY to scope.
B-43. Walk the other way. READY — costed.
B-44. An untitled draft that has a title. READY — cosmetic.
B-45. One command instead of five. READY — deliberately deferred. Now that the stand-up sequence is written down and proven, wrapping it is available whenever it is wanted.
B-46. Where documents live. READY to scope — small. Implementation notes land in the code repositories; the filing convention says documents live in the record. A session orienting from the record alone cannot find them.
B-47. The issuance screen for contributor credentials. READY — new, small. B-10 built the whole pathway in the engine and deliberately built no screen for it — an Operator can issue a credential only through the interface. Named as a follow-on when it was scoped, and now the follow-on.
B-20. The marketing website. READY. B-22. Package Stele. WAITING (background). B-23. The security story. READY. B-24. Investor-visible FORAY. READY.
Restricted-visibility slices 2–3 · target-hosted visibility · protocol wire-format changes · OVA's remaining standalone role · cross-fund questions · the stray zip file in the record's working tree — every session reports it and leaves it alone; a one-line decision ends that · how many live records carry a fabricated author · whether playground_dev's schema matches what the chain now produces · whether a held shape whose job failed is ever cleaned up.
The restart. Eight change requests, nine merges — one spans both repositories.
| Merged and not deployed | Where | |---|---| | CR-2026-159 — the provenance field | engine | | CR-2026-160 — the Manifestation screen | surface | | CR-2026-161 — the record writes that aren't true | engine | | CR-2026-162 — the lost contribution, and downloads | both | | CR-2026-163 — the Shaping screen | surface | | CR-2026-164 — the provenance walk | surface | | CR-2026-165 — the stand-up sequence | engine | | CR-2026-157 — outside contributors | engine |
B-16. Read seed v0.13 before it commits.
Two decisions on the queue, blocking nothing. Per-statement provenance — clicking a sentence rather than a note, which cannot be built the obvious way because asking the model to cite makes the citations model output. And whether a walk should use the event identifier, which would show the act rather than the record.
Everything else proceeds without you.
DUNIN7 — Done In Seven LLC — Miami, Florida DUNIN7 — the build list — v0.20 — 2026-08-03