Weekly operating receipt

Receipt 001

Five fields, every week. Open loops stay in.

This first one publishes a day late. The cadence is Friday; this is Saturday. It is recorded here rather than backdated, because a receipt that hides its own slip is worth nothing.

Intent

Prove the merge gate on my own company holds against me — against the person with administrator rights, which is me, at 1 a.m., wanting the thing to land.

Evidence

The gate refused its owner.

Step 0 coverage enforcement went live on main on September 6, 2026. Two required checks, administrators included, branch required up to date. An acceptance test against a real head with missing coverage returned UNCOVERED_CHANGE on both platforms: changed count 1, recorded count 0. I attempted the merge as administrator. GitHub returned HTTP 405 — 2 of 2 required status checks are failing. The pull request stayed open and blocked.

A second canary altered the hook handler and supplied a complete, valid routing record for that change. Both platforms returned HOOK_INTEGRITY and refused it. A routing record cannot waive handler identity. That revision was never merged.

The gate caught a real defect before it cost anything.

The company registry needs, for each held seat, an artifact and an independent review bound by SHA-256. Sixteen artifact digests were generated from Windows working-tree bytes using CRLF. CI reads Git blobs using LF. All sixteen would have failed as evidence-hash, and the red result would have looked like tampering rather than line endings. The mismatch was caught before any review was written. Writing the reviews first would have required regenerating all sixteen, since the artifact digest lives inside each review file.

A gate ran out of order, and the reversal is on the record.

The HQ skill catalog was generated to 57 supplied and 72 total while the collision gate was still unverified. The packet had forbidden that move in writing three hours earlier. The catalog was reversed to 55 supplied and 70 total. The run remains recorded as out of order rather than being absorbed quietly. No live rows were touched.

A production write was found behind a merge button.

Merging the skills pull request to production main would have run seedHqSkills() at boot, without awaiting it, while errors were logged as non-fatal. A partial seed and a healthy launch could therefore look identical from outside. The draft skills branch now gates the seed behind HQ_SKILLS_SEED=1, records the skipped state, and makes the seed a deliberate, separately authorized run.

Two skills had quietly forked.

The repository copies and the live Claude copies of cited-synthesis and claim-check differed by 51 and 65 lines. The live copies carried the later, sharper structure. Reconciliation brought those bodies into the canonical source; review then caught the missing proof-auditor boundary in cited-synthesis before promotion. The boundary is restored, and the reviewed digests now match exactly.

Run IDs, commit SHAs, and the exact refusals remain in the private repository evidence record. This page is the permanent public audit link for the weekly receipt.

Current truth

The gate holds against content drift and against me. It proves one thing precisely: the routing record matches the actual Git diff, and the hook handler matches the trusted baseline in object identity and mode.

It proves nothing about reasoning quality and nothing about whether a skill was natively invoked. Both routing sources are self-reported. I wrote that limit into repository law rather than letting a green check imply more than it earns.

The registry repair merged to main on September 12 with checks A, B, C, and D passing and all 16 held seats covered by digest-bound evidence. Thirteen reviews came from Claude as an AI evaluator independent of the artifact authors. Three came from Codex while authoring the repairs and are labeled as same-author content-conformance reviews; they do not establish independent human review. Voice doctrine and a security repair are also live on main. Content-skill distribution, the blueprint declaration, and the HQ skill seed remain separate from this release; no production skill rows were changed.

Open loops

The two-person problem — six days open, no close date.

This account has one collaborator. GitHub does not let a pull request author approve their own pull request, and an agent operating under my identity is not a second reviewer. Required reviewer count sits at zero, since setting it above zero with one human deadlocks every merge.

Two events this week made the hole sharper. The pull request that wrote the Voice doctrine into repository law merged on September 9 with zero independent human approval. Thirteen of the sixteen standing reviews Check D requires are authored by an AI evaluator — structurally valid, named honestly in every record, and still not a second person. The checker cannot tell the difference. I have no fix that does not involve another human.

First reach — 17 days open, low attribution confidence.

Five first-reach messages went out by hand on or before August 26: four on X, one on Substack. Responses reported as of this receipt: zero. The follow-up rule allows one manual follow-up at ten days, three sentences, then the thread closes. I cannot calculate each follow-up date because I never recorded per-person send times, and this receipt refuses to invent them. The loop is open on a missing field in my own record.

Registry review independence — structurally complete, human review still open.

The registry repair is merged and covers all 16 held seats. Seat #2 has an implemented four-state Memory lifecycle with transition tests. Seats #1 and #19 have dedicated accountability and doctrine artifacts. The committed-object verifier and GitHub registry jobs pass on Windows and Ubuntu. Thirteen reviews are independent AI evaluations; the three same-author Codex reviews remain plainly identified and do not establish a second-human control.

Blueprint and content-skill releases — separated and held.

The blueprint schema declaration remains on its own branch so it cannot enlarge the registry or security change. The content-skill branch remains separate as well. Its boot-time HQ seed is inert unless HQ_SKILLS_SEED=1 is deliberately supplied, so merging source cannot silently write production skill rows. Each branch still needs its own green, current-base review before release.

Invocation receipts — open since installation.

File discovery is proven across Claude, Codex, and Grok: the same canonical bytes resolve in all three. Invocation is not. A skill appearing in a listing proves a description loaded. Nothing yet proves a host selected one for a task, and an agent’s own report is not that evidence.

Next action

  1. Settle the second-reviewer question rather than leaving it implicit: bring in a named human reviewer, or record publicly that the control is content-only until one exists. Then state which meaning Check D carries in the ruling.
  2. Keep the registry’s three same-author review limits explicit, and obtain a named human review when a second reviewer becomes available.
  3. Record send timestamps at send time, so the follow-up rule has something to fire against.

Receipts publish weekly, using the same five fields. The open loops are the point — a running system produces them, and a slide deck does not.