This page as Markdown, byte for byte: /GTM.md
CEDE — the go-to-market plan#
Status: first edition (CEDE-075), authored under adr/ADR-0021-go-to-market-mandate.md.
Standing: a first-class artifact alongside PRODUCTION.md. The planner reads this file in its boot ritual, ranks BACKLOG against its open phases exactly as it ranks against non-green production checks, ticks an action when the evidence that action names actually exists, and files drift between this plan and reality as BACKLOG items. PRODUCTION.md keeps priority wherever the two conflict — a product that fails its own checks has no business being launched at anyone.
How to read it. Prose is context and is never parsed. Every line beginning - [ is an action and matches exactly one grammar:
- [ ] GTM-NN [owner:fleet|operator] Title — evidence: <objective check>
owner:fleet means a session can do it. owner:operator means only Ben can — money, legal, identity, and anything that leaves this machine for the open internet (ADR-0021 constraint 4: the fleet drafts and stages, the operator publishes). Every operator action here cites the BLOCKED_OPERATOR item that carries it, by number, so the operator queue stays the single place a human looks for their work. Evidence is a check that can flip, a thing that exists, or a number that can be read — never a judgement call.
tests/unit/test_gtm_plan.py holds all of that still: the grammar, the id shape, one owner per action, the BLOCKED_OPERATOR cross-reference, and the rule against asserting social proof this product has not earned.
The honest baseline#
Dated 2026-08-25, re-derived against the record as far as 2026-08-25T05:16:29Z — the newest line the record carries at this writing. That line is the last of the twelve the 2026-08-25 morning full sweep wrote, and every other line of the board below is one of the other eleven: this edition's board is one unattended sweep's own reading with nothing spliced into it, which the previous edition's was not. Every claim below names something checkable in this repo: a line in checks/history.log, a merged BACKLOG id, a file, or a figure a committed test recomputes.
This is the CEDE-224 edition: a drift pass over the CEDE-221 edition of 2026-08-18, not a wholesale re-cut of the section. It is also the longest gap this section has ever gone unrevised, and the reason is on the record rather than in anybody's memory. The item that produced this edition was cut to re-derive the baseline against the 2026-08-19 sweep; it did not run then, because the OAuth credential every spawned session runs on expired on 2026-08-20 and every session since aborted at authentication — BLOCKED_OPERATOR.md item 21, opened 2026-08-24, is the operator action, and BACKLOG's CEDE-246 is the fleet item that makes the instruments say so instead of wearing it as product red. So this edition re-derives against the newest sweep the record actually holds, the 2026-08-25 morning full sweep, rather than dating itself to a sweep six days behind the log: a baseline that is right about an older day is the one failure mode this section exists to prevent. What moved is what the record contradicts — the board and the sentences that describe it, the PROD-02, PROD-12, PROD-09 and PROD-07 bullets, the standing-reds bullet, whose whole premise flipped twice over, the Phase-2 and Phase-4 gate readings and this section's closing sentence — and every sentence they left true is the previous edition's, unrewritten. The headline count is ten, re-derived from the board below rather than carried across, and it is the same number the 2026-08-18 edition carried with four of the twelve checks having changed side under it. The plan's standing orders make that drift a BACKLOG item rather than a habit, and this is one.
The edition this replaces was the single one cut on 2026-08-18, and the one before it the single one cut on 2026-08-17; the day before that took two, and that pair is the shelf life of this section measured rather than guessed at. Seven days is the other end of that range, measured here for the first time and caused by an outage rather than by neglect. CEDE-194 was cut at 06:32Z on 2026-08-16 and re-derived only as far as 2026-08-16T01:27:30Z, which was the tip of the record at the time and was eleven-twelfths a report on 2026-08-15. It was internally consistent when it was written and false about the product an hour later, because the sweep it says did not run then ran: all twelve of its board lines were superseded between 07:36:40Z and 07:43:21Z, and its headline number and its Phase-2-gate claim went with them. CEDE-199 corrected that same afternoon for the drift CEDE-196's merge caused. Two editions in one day is not churn — and it is the one way this section is still allowed to rot, which is why re-deriving it is a BACKLOG item rather than a habit. Since CEDE-139 the board below is not typed from memory: tests/unit/test_gtm_baseline.py recomputes it from checks/history.log and fails the build if a line, or the count, has drifted. What that test cannot do is notice that a session never moved the block forward, because it pins the board as of the block's own newest line. So a stale baseline here never shows up as a wrong number — it is a right number about an older day, which is harder to catch and is exactly what this edition exists to correct.
- 10 of the 12 production checks read PASS at their most recent run. One
line per check, each the latest line that check has in
checks/history.logas of that file's own last line at this writing:
2026-08-25T05:09:14Z PROD-01 FAIL 2026-08-25T05:09:15Z PROD-02 PASS 2026-08-25T05:10:46Z PROD-03 PASS 2026-08-25T05:11:10Z PROD-04 PASS 2026-08-25T05:11:20Z PROD-05 PASS 2026-08-25T05:13:26Z PROD-06 PASS 2026-08-25T05:13:58Z PROD-07 PASS 2026-08-25T05:15:05Z PROD-08 PASS 2026-08-25T05:15:59Z PROD-09 PASS 2026-08-25T05:16:02Z PROD-10 PASS 2026-08-25T05:16:28Z PROD-11 PASS 2026-08-25T05:16:29Z PROD-12 FAIL
This is the latest run reading. It is not PRODUCTION.md's DONE rule, which asks for seven consecutive green days and is what Phase 3's entry gate cites — nothing on this page moves that gate, and ten green today is not one green week. The number is re-derived from the twelve lines above rather than carried across, because a count copied forward is a count nobody has checked, and tests/unit/test_gtm_baseline.py recounts the block and fails the build if the two disagree.
Ten is the same number the 2026-08-18 edition printed, and almost nothing under it is the same. Four of the twelve checks changed side since that board — two reds went green and two greens went red, which is how a count stands still while everything under it moves — and this page states each as itself rather than netting them off. PROD-08 went green and has stayed green: the operator placed a test-mode key and CEDE-225 closed the probe's own race, and the standing-reds bullet below reads that out of the ledger. PROD-02 went green — the seven-day soak, red on every board this section has ever printed, first PASSed at 2026-08-21T05:02:43Z and has PASSed on every sweep since; that is the one unambiguously good movement on this board and it landed on exactly the date the 2026-08-18 edition re-derived as the earliest possible one. PROD-01 and PROD-12 went red, and they are red for one cause that is not the product: the walk agent both checks spawn cannot authenticate. So the red half of the board is a pair again, and it is a different pair, red for a different kind of reason — a dead credential rather than a clock. Both have their own treatment below.
All twelve lines are dated 2026-08-25 and all twelve are the morning full sweep's own, 05:09:14Z through 05:16:29Z, with nothing spliced in and no --only re-run anywhere in it — not because nothing went red on it, but because no session was able to run for six days to re-run anything. The previous edition's board was not that shape: eleven of its lines were the 2026-08-18 sweep's and the twelfth was a PROD-12 --only re-run taken sixteen minutes after the sweep's own PROD-12 line came back red — the same shape as the 2026-08-16 board this section has criticised before, which took eleven lines from the sweep and the twelfth from a re-measurement that merged three hours later. Every edition before the 2026-08-16 one carried a board assembled out of several days. That a sweep now runs each morning to make either possible is a repair, and it is worth keeping on the page because the thing it repaired was invisible: an earlier edition reported that no full sweep ran on 2026-08-16 because production_duty() in supervisor/supervisor.py skipped the day's run of checks/production.sh whenever checks/history.log already carried any PROD- line dated that UTC day — three restore-drill verdicts between 2026-08-16T00:13:30Z and 2026-08-16T01:27:30Z had erased the day — and it left open whether that skip was a defect worth a change to the harness. It was, the question is settled, and the settling is on the record twice over. CEDE-195 (merged b5ad358 at 07:34Z) re-keyed the skip to evidence the full sweep actually ran: the duty now skips only when every check id on the sweep's roster has a line dated today, the roster derived in code from PRODUCTION.md's own ### PROD-NN headings rather than a second hand-typed list, with supervisor/test_production_duty_skip.py holding it against fixture ledgers and wired into checks/gate.sh. On 2026-08-16 the very next supervisor tick took the sweep, two minutes after the merge. So this is not a fix asserted on the strength of a merge: the machinery that was broken on 2026-08-16 is the machinery that produced that day's board, and the twelve lines above are the tenth whole board it has produced — one a day, unattended, every day from 2026-08-16 to 2026-08-25 including the six on which no session could run at all, which is the strongest thing anyone can say for that repair.
- What each of the two standing reds is waiting for, so neither can be
read as an unknown — and neither is what this bullet was waiting for a week
ago. **Both of the reds the previous edition described are green, and both
of the reds on the board today are new.** Taking them in the order they
stopped being true:
PROD-08 is green, and the sentence that stood here — that it was
fleet-complete and red for one missing credential, the operator's Stripe
test-mode key — is false now, on three things read together. The
operator placed a test-mode key on 2026-08-18
(BLOCKED_OPERATOR item 19, ✅ DONE 2026-08-18, with the supervisor drop-in
that the nightly sweep needs to see it); CEDE-225 (merged
09f4028) closed the probe's own race, in which a poll landing on Stripe's id-less upcoming-invoice preview crashed the instrument instead of continuing to poll; and the check then recorded2026-08-18T09:45:56Z PROD-08 PASS, the first PASS it has ever had, and has PASSed on every morning sweep since,2026-08-25T05:15:05Z PROD-08 PASSbeing the newest. Item 7 — the KYC'd Stripe account — is a different item and is still open; what depends on it is Phase 4's gate, below, not this board. PROD-02 is green, and this is the movement worth reading twice, because the seven-day soak was red on every board this section has ever printed and had never recorded a PASS inchecks/history.logat all. The 2026-08-18 edition re-derived, from the newest sev1 inops/incidents.logand the check's own seven-day window, that the earliest window which could possibly pass was the one ending 2026-08-21. It passed on2026-08-21T05:02:43Z, and on every sweep since. What the newest run says of itself, read from/opt/cede/shared/prod-sweeps/PROD-02-2026-08-25T05:09:15Z.lograther than inferred: window 2026-08-19..2026-08-25, all seven daysok, 47271 requests across 333 runs, and "sev1 opened in window: 0" — the traffic clause and the sev1 clause both, which is what a PASS on this check means. The newest sev1 inops/incidents.logis still the pair that opened at 2026-08-14T06:40:28Z (CEDE-135 and CEDE-136, the published front refusing connections across a restart, both recovered five minutes later at 06:45:28Z), and it has now scrolled out of the window. Nothing has opened a sev1 since; everything logged since is sev2, the newest of them the merge-gate and quiet-supervisor alerts of 2026-08-22 (CEDE-243, CEDE-244). This is not the DONE rule and does not pretend to be: PROD-02 measures a seven-day soak window and passes it, while PRODUCTION.md's DONE rule asks for seven consecutive days on which the whole board is green, and the two reds below have voided every day since 2026-08-20 for that purpose. PROD-01 and PROD-12 are red, for one cause, and it is not the product. Both checks spawn a clean-environment agent that must reach the published docs site before either clock starts. Since 2026-08-20 that agent has not started at all: the OAuth credential it runs on expired and cannot self-refresh. Read from the runs the sweeps retained, not inferred —/opt/cede/shared/prod-sweeps/PROD-01-2026-08-25T05:09:14Z.logand/opt/cede/shared/prod-sweeps/PROD-12-2026-08-25T05:16:29Z.logeach recordagent session: exit 1 afterabout a second, 0 HTTP request(s) recorded, and the sandbox PROD-12 keeps on a red,/tmp/cede-prod12-8kztcw3_, holds a transcript whose entire content is `Failed to authenticate: OAuth session expired and could not be refreshed`. That is the same string in the retained sandbox of every PROD-12 red since the first one — the six sweeps from2026-08-20T08:07:56Z PROD-12 FAILto2026-08-25T05:16:29Z PROD-12 FAIL, each checked here in its own sandbox rather than assumed from the first. PROD-01's last green is2026-08-20T08:01:34Z PROD-01 PASS, six minutes before the first PROD-12 red and a walk that completed in 61.3 s; its reds run from2026-08-21T05:02:43Z PROD-01 FAILto2026-08-25T05:09:14Z PROD-01 FAIL. What that does and does not mean. It does not mean the onboarding walk or the composition walk stopped working — neither has been measured since 2026-08-20 and 2026-08-19 respectively, which is a different and worse thing than a bad measurement. It does mean every day from 2026-08-20 on is a voided day for the DONE streak, because a check that could not run is not a green one, and PRODUCTION.md's status vocabulary is deliberate about that. The operator action is BLOCKED_OPERATOR item 21 (opened 2026-08-24): re-authenticate the CLI, which is interactive and which no session can do. The fleet action is CEDE-246, which makes both probes say the runner could not start instead of writing a line a reader takes for a product red — the whole reason this cause took five days and an operator's own session to name. Neither of these two reds is a defect anybody can fix by building the product, and neither is an unknown. - **The last PROD-12 walk that measured anything was on 2026-08-19, and it was
green.** In one sentence, read from the run retained at
/opt/cede/shared/prod-sweeps/PROD-12-2026-08-19T05:27:16Z.log:2026-08-19T05:27:16Z PROD-12 PASSis the last green the fifteen-minute composition walk has, and its agent made nine HTTP requests in 98.7 s — three of them to the docs site, the index,/quickstartand/model-builder, andprice.mdnot among them — composedmdl_3b7f423283a1471cac6e0394f13882bev1.0.0 from the four primitives with its determinism check and its 1986-01-01..2025-12-31 backtest, and priced throughPOST /models/{id}/runsfor 873836.05 THB on a technical basis labelled with that model, 88.1 s of the 900 s budget from the first docs fetch. So that walk is green and the fork is a road it did not take: it is the second outcome of the three, not a further measurement of the signpost. It is not the board's PROD-12 line: every sweep since has written a FAIL the walk agent's dead credential caused, as the standing-reds bullet above reads out of each red's own retained sandbox, so what follows is the fork's history and not a current reading. Nothing below is evidence about the product today, because nothing has measured the product since 2026-08-19.
The one walk that read the signpost is still the only one. 2026-08-18T05:30:24Z PROD-12 PASS was the newest PROD-12 line on the 2026-08-18 edition's board, taken as an --only re-run sixteen minutes after that sweep's own PROD-12 line came back red. Of the three outcomes a fork measurement can have, that walk produced the first: it fetched the signposted page and still priced by the route the signpost names. Read from the run retained at /opt/cede/shared/prod-sweeps/PROD-12-2026-08-18T05:30:24Z.log: sixteen of its thirty-six requests went to the published docs site across six paths, and **four of them were /price** — the path src/cede/docsite/pages.py publishes docs/price.md at, which is the page carrying CEDE-196's signpost. It composed mdl_2e4dc84253714f46a990fa5956216e22 v1.0.0 from the four primitives, took its determinism check and its forty-year backtest across 1986-01-01..2025-12-31, and then priced through POST /models/{id}/runs: 1067250.47 THB on a technical basis, labelled with the model it had just composed. All four /price fetches fall after the 201 that created the model and before the pricing call, and POST /objects/{id}/price — the road the 2026-08-16 red took by mistake — was never called at all. 153.3 s of a 900 s budget.
What that does not settle, stated here as PRODUCTION.md's PROD-12 block states it and not enlarged, and re-derived from the record rather than carried across. One walk that took the signposted road is not proof the fork can never trap another, and the ratio has got weaker rather than stronger since the previous edition said so. Eleven PROD-12 lines have been recorded since the signpost deployed at 2026-08-16T10:55:27Z, and only four of them are walks that fetched anything at all — 2026-08-17T05:09:55Z PROD-12 PASS, 2026-08-18T05:30:24Z PROD-12 PASS, 2026-08-18T08:12:07Z PROD-12 PASS and 2026-08-19T05:27:16Z PROD-12 PASS. Of those four, exactly one opened the page. The other seven measured no route at all: 2026-08-18T05:14:33Z PROD-12 FAIL, whose agent asked for a permission it could not be granted, and the six credential deaths from 2026-08-20T08:07:56Z PROD-12 FAIL onward. The counts are grepped out of checks/history.log at this writing; the previous edition read three walks because two of them did not exist yet, and the 08:12:07Z line never appeared on any board because a later line superseded it before an edition was cut. A passing run also keeps no sandbox, only a red does, so what survives each of those walks is the retained log's record of the fetches and the route, not the session's own account of what it read there. What changed on 2026-08-18 is that the signpost is measured to work when it is read, rather than only published; nothing has added to that since, because nothing since 2026-08-19 has walked.
The red it replaced measured nothing about the product either way. 2026-08-18T05:14:33Z PROD-12 FAIL was that sweep's own PROD-12 verdict, and it was on the previous edition's board for the sixteen minutes before the re-run. Read from the run the sweep retained at /opt/cede/shared/prod-sweeps/PROD-12-2026-08-18T05:14:33Z.log: the walk's agent session exited 0 after 9.8 s with 0 HTTP requests recorded, so it never fetched the docs site, the clock the check starts at the first docs fetch never started, and nothing was composed from public docs — the run's own verdict line says either the docs were unreachable or the session did nothing, and establishes neither. The sandbox is kept at /tmp/cede-prod12-m9qzwlnu. Diagnosing that red was PRODUCTION.md's PROD-12 block's work and CEDE-220's rather than this page's, and it is diagnosed there: the spawned agent reached for a tool the walk harness does not allow it and stopped to ask for a permission it could not be granted, so the red is the harness's agent and not Cede.
The green before both is still in the record and still true of the day it was taken. 2026-08-17T05:09:55Z PROD-12 PASS was the fifteen-minute walk in 72.1 s of a 900 s budget and the first taken against a published docs tree carrying CEDE-196's signpost — the walk the previous edition said would measure the fork closed. It did not measure it. Read from /opt/cede/shared/prod-sweeps/PROD-12-2026-08-17T05:09:55Z.log, that walk fetched four docs pages — the index, /quickstart, /model-builder and /quickstart.md — never opened price.md, and took its price from POST /models/{model_id}/runs, whose job result came back labelled with the model it had just composed. That is why reading the signpost took a third walk.
What went red first, and why it is a different fault from either of 2026-08-18's two. 2026-08-16T07:43:21Z PROD-12 FAIL was the morning sweep's fifteen-minute composition walk, and it was not a timeout: the walk's own agent exited 0 after 121.5 s of a 900 s budget, having composed and validated mdl_9381bd3bd8e84f40bcc0027a901a8e58 v1.0.0 from the four primitives, taken its determinism check and its forty-year backtest, and priced — but priced through POST /objects/{id}/price, the generic verb, which answers with the platform pricing model — the priced job came back labelled cede/parametric-burn-station-index v0.1.0, which is not the model the session composed — so no recorded response carried a price labelled with the model it had just built and ADR-0032's stop condition never fired. **The fork, in one sentence: docs/price.md is the page the walk reads after docs/model-builder.md, and it taught the object-price route without saying that a price labelled with a model you composed comes from POST /models/{id}/runs instead — so a reader who followed the docs in order arrived at the wrong route and the check was right to refuse.** The platform label on that response is P9 working as specified, not the defect. That red was attributable without a re-run because CEDE-193's retention kept the run: /opt/cede/shared/prod-sweeps/PROD-12-2026-08-16T07:43:21Z.log and the sandbox at /tmp/cede-prod12-q0dkixde. **CEDE-196 signposted the fork in docs/price.md, above the page's first runnable block, and re-measured.**
Both caveats that history carried are now discharged, and both are PRODUCTION.md's PROD-12 block's own. The first was about publication: the docs site serves /opt/cede/current/docs, which is main's tree, so the signpost reached readers only at the first deploy after the merge — that deploy landed at 2026-08-16T10:55:27Z, release db5499c7cb33 in /opt/cede/shared/deploys.log, and every walk that has fetched anything since — 2026-08-17, both on 2026-08-18, and 2026-08-19 — was taken against the tree it published. The second was that no walk had yet reached the fork, and until 2026-08-18 it stood on three walks: none of the 08:28:20Z, 05:09:55Z or 05:14:33Z walks fetched price.md at any point — the first two stopped the clock on a job result from POST /models/{model_id}/runs carrying the composed model's own label, and the third fetched nothing whatsoever. The 05:30:24Z walk is the one that discharges it, on the terms the caveat itself named: it opened price.md and priced with its own model anyway. Read together: the check was green on the last measurement it managed to take, which is 2026-08-19's and is no longer the newest line it has; the fork is still a road a walk may take wrongly, and one walk since the signpost deployed has been measured taking it rightly.
- **PROD-07 is green, and the collision the previous edition described is
history.** That edition reported the check red on a re-measurement and said
the red was a rule collision rather than a defect: coverage was complete —
route table: 32 endpoint(s)againstendpoints exercised by an example: 32at2026-08-15T06:34:21Z PROD-07 FAIL— and the two non-2xx responses in that run were refusals the examples provoke on purpose, a stranger's object id refused404at step 7 ofdocs/accumulation.mdand an unknown analysis name refused422at step 6 ofdocs/analyse.md. It said resolving that changed what the check means and belonged to a planner-cut item with an ADR. It did, and the item ran. ADR-0052 (CEDE-170, merged8d2f50c) narrowed clause (c) of PROD-07's rule: a recorded non-2xx is excused only where the runnable block that issued the request itself compares a status-bearing expression against that exact three-digit literal, and only as many times as that page's blocks assert it — an unasserted non-2xx still fails exactly as before, whichtests/integration/test_prod07_asserted_refusals.pyproves against a live server. That left one half undone, because onlydocs/accumulation.mdpinned its status; CEDE-175 (merged4d4469d) gave step 6 ofdocs/analyse.mdits owntest "$status" = 422in the same runnable block, so the page now fails if the product ever stops refusing that way. The measurement that closed it is2026-08-15T16:16:42Z PROD-07 PASS: 34 endpoints in the server's own route table, 34 exercised by an example, 14 pages carrying one and every one of them exiting 0, and both refusals adjudicated as asked-for. Read it for what it measures — the product's answers did not change; what changed is that both demonstrations now pin the status they teach. PRODUCTION.md's PROD-07 block carries the full run. CEDE-163 has separately merged the advisory lock that holds a timer deploy back while a sweep is driving staging; whether that ends the restart- collateral class is a claim the next sweeps measure, not one this page makes on the strength of the merge. - **2026-08-14's three reds were green again by the 2026-08-15 sweep — and one
of the three was a defect, not collateral.** PROD-06, PROD-09 and PROD-12 FAILed
within three minutes of each other on 2026-08-14 (
05:23:44Z,05:24:47Z,05:26:12Z), which reads like one fault and was not. **PROD-09's was real and was fixed**: the rollback drill ran for the first time under ADR-0034's front topology,deploy.shcomposed a service command with no front, and the drill's own deploys took the published address down for 3m44s — CEDE-134 repaired that with a regression test (mergedcd273a2) and the drill went green the same morning,2026-08-14T06:56:30Z PROD-09 PASS. **The other two were collateral of a restart**, each of a different one and both recorded in BACKLOG's CEDE-138 entry minute by minute: PROD-12's whole 05:24:48Z→05:26:12Z walk ran inside that same dark front, and a staging timer deploy at 05:22:40Z landed inside PROD-06's probe. CEDE-138 is the item that re-ran both rather than assuming the diagnosis —2026-08-14T09:00:22Z PROD-06 PASS,2026-08-14T09:03:32Z PROD-12 PASS— and all three stayed green unattended overnight:2026-08-15T05:34:47Z PROD-06 PASS,2026-08-15T05:36:16Z PROD-09 PASS,2026-08-15T05:38:16Z PROD-12 PASS. So two of 2026-08-14's reds ended when the collateral stopped and the third ended because someone fixed the thing under it; this page does not merge those two into one sentence. - **The measurement that decomposed the wait PROD-09 has been recording all
along.** The rollback drill has run green on every sweep since, the
newest being
2026-08-25T05:15:59Z PROD-09 PASS— 215 health samples across the drill's three restarts with none refused, none non-2xx and no window in which the front was not served — but the run that is worth reading is an earlier one:2026-08-15T22:43:16Z PROD-09 PASS, the first run under CEDE-184's swap-phase instrument:deploy/lib/swap_phases.pyrecords drain start and end, the incoming process's start, and first readiness for every swap, three of the four read back afterwards from systemd's own transition timestamps rather than measured by watching. ADR-0058 states what that run found, and this page states it in that ADR's own words. The incoming release's boot dominates the wait — 1.793, 1.982 and 1.916 s, 62–65% of each — and *"what dominates in its place is module import — the interpreter, FastAPI, pydantic, psycopg, uvicorn and the app object — which is O(code), not O(rows)"*: it does not grow when the platform is used, it grows when a dependency or this codebase does. Hydration, which ADR-0051 measured at 84% of an 11.97 s boot, is 5.5–6.1% of this one. What is still O(rows) is the 0.129 s of loaders, and the ADR names the drain as the next question rather than answering it. Read that for what it is: a decomposition of one drill run, on one release, not a standing property of the deploy. - Both backup checks now cover the database, not the repo alone. Until
2026-08-15 PROD-10 measured the supervisor's nightly git bundles and PROD-11
cloned one, while every account, API key, object, job and billing row had
lived in the Cede-only PostgreSQL cluster since ADR-0026 (2026-08-12) with no
copy of it anywhere — two green checks that were green about the wrong half.
CEDE-182 (ADR-0056) added the nightly logical dump, gzipped beside the
bundles with a manifest recording what the database held in the dump's own
snapshot, and gave PROD-10 a second clause that fails unless that dump is
under 26 hours old and reads back. CEDE-183 (ADR-0057) gave PROD-11 its
matching clause: every run restores the newest dump into a scratch database
the run creates and drops however it ends — never the database the product
serves from — and asserts all thirteen tables come back with the row counts
the manifest recorded. The first verdicts that measured and restored the
database are
2026-08-15T22:35:47Z PROD-10 PASSand2026-08-15T23:59:10Z PROD-11 PASS; every line above those two is the repo clause alone, and PRODUCTION.md's two blocks carry the runs. Two limits belong with that green rather than after it: all of it still sits on one host's disk with no off-host copy of the dump, and a nightly dump loses up to a day of writes — a day of usage events is a day of PROD-08's revenue evidence (ADR-0056, "Recovery point"). - Seven verbs are live on staging, behind the operator's tailnet: ingest,
analyse, price, structure, backtest, monitor, package — plus the model
registry, its four composition primitives, and the no-code builder
(CEDE-038). As of the last sweep,
2026-08-25T05:13:58Z, every route in the table was observed to be covered by a documented example executed against staging: 34 endpoints in the server's own route table, 34 exercised by an example, across the 15 pages underdocs/that carry one — includingdocs/hazard.md,docs/events.md,docs/analyse.md,docs/accumulation.md,docs/package.md,docs/monitoring.mdanddocs/trigger.md. The route count is where the 2026-08-15 afternoon reading left it; what moved is the page count, from 14 to 15, because CEDE-189 landeddocs/trigger.mdat 2026-08-16T01:57:36Z with runnable examples of its own, so a fifteenth page is now executed on every merge and on every sweep. That reading is as-of, not standing — the next merged route makes it a claim about the past again, which is what dating it is for. Where the two gates that run these examples disagreed, they no longer do. PROD-07 discovers its pages by grepping the docs tree for the HTML-comment marker thatchecks/docs_example.pyrequires immediately above a runnable fence — named by description rather than reproduced on this page, because the discovery is a plain substring match with no exclusion list, so a page that merely reproduces the marker's exact text is discovered as one more runnable page and then fails for carrying no runnable block. Until 2026-08-15 that discovery found all 14 while the merge gate'sdocstarget inMakefilenamed 13 of them, leavingdocs/package.mdexecuted only when a sweep ran against staging. CEDE-172 closed that (mergedb3cd39a): discovery now lives once, inchecks/runnable_pages.sh, PROD-07 asks that script which pages to execute,make docsasks it to verify that the pages the target names are exactly those pages before it runs anything — anddocs/package.mdis among them — so a runnable page that reaches the tree unwired stops the merge gate instead of being skipped.tests/unit/test_docs_gate_page_set.pyholds the two sets equal from the other side with its own independent discovery, and fails on a planted page of either kind. Every runnable page is now executed twice, once locally on every merge and once against staging on a sweep. - Analyse is live on every route SPEC §3.2 names: the point hazard lookup
GET /hazard(src/cede/analyse/, CEDE-142, ADR-0041), the public event catalogue and event footprints (CEDE-143, ADR-0042), the analyse job over an object,POST /objects/{id}/analyse, which runs both readings at an object's own locations and records the artifacts on its provenance (CEDE-153, ADR-0045), and accumulation across a set of objects, `POST /accumulation`, which rolls the account's own stored exposures up per peril, per declared region and by concentration — portfolio level only, never a schedule re-served (CEDE-152, ADR-0044). Neither of the last two is metered. - Package is live on two slices (CEDE-150, ADR-0043): `POST
/objects/{id}/package` assembles a submission pack from the runs already in
an object's provenance and
GET /packages/{id}serves it back, every document watermarked draft. It computes nothing and is not metered. The draft slip SPEC §3.7 names is now a fourth document in that pack, landed at 2026-08-15T08:58Z by CEDE-165 (merged58cb0e4): parties, period, jurisdiction, financial structure, trigger and the technical premium restated as analytical output, every line drawn from the risk object and none of it computed. It carries the draft watermark on the document itself, and it adds no signature, acceptance or execution surface — a slip lifted out of the pack and read alone still says on its face that it is a draft nobody has agreed to. - Monitor is live on both of its slices, the second as of 2026-08-15.
The record came first (CEDE-151, merged
1f00014at 2026-08-15T05:29Z, ADR-0046): a structure is recorded as in force — the account holder's own assertion about a transaction executed entirely outside Cede — and read against the newest pinned snapshot, with the index value and the distance to attachment on every read. Webhooks are no longer absent: they merged at 2026-08-15T11:50:35Z (CEDE-166,3d3214a, ADR-0050), so `POST /monitoring/{id}/webhooksregisters an address andGET /monitoring/{id}/webhooks` reads back every registration with its own delivery log. Two things about that landing are worth stating rather than assuming: delivery is at-least-once and the log is what makes a missed delivery visible instead of silent, and there is still no scheduler in this build — ADR-0050 carries ADR-0046's newest-snapshot rule forward to deltas, so a delivery goes out when a read recomputes the measurement and finds it has moved, not on a clock nobody has built. Any page that describes Monitor says measurement, never determination: Cede reports what it measured and nothing that follows from it, and ADR-0050 was written against exactly the pressure a pushed message attracts. - All seven verbs SPEC names now have an address, as of
1f00014on 2026-08-15 — each on the slice named above and no wider than that: the slices are what this plan may claim, never the verb entire, and no page this plan produces may say otherwise. Both of the absences the 2026-08-14 edition carried closed on 2026-08-15, hours apart: Package's draft slip landed at 08:58Z (CEDE-165,58cb0e4) and Monitor's webhooks at 11:50:35Z (CEDE-166,3d3214a). That is not the same as the verbs being finished — a slice is narrower than a verb, and it is the slice that gets named wherever a verb does. There is a warning here about this page's own shelf life too, and it has now been demonstrated twice in one day: the 2026-08-15 edition was drafted before lunch, one of its absences closed after the draft, and by the afternoon its board was a check out of date as well — which is why this edition exists. A reader working from it re-readsBACKLOG.mdandchecks/history.logbefore repeating any of it, rather than trusting the date at the top. - Three reader surfaces exist: the specification page (
site/, served on the tailnet since 2026-08-11 per BLOCKED_OPERATOR item 16), the browser playground (site/playground/) and the workbench (site/workbench/), withdocs_urlset incede.config.json. - **The ingest oracle is 16 real-world-cursed files carrying 138 declared
rows**, append-only by specification. Those two numbers are computed from
corpus/manifest.d/*.yamlbytests/unit/test_honesty_exhibit.py, which re-rendersdocs/ingest-honesty.mdand fails if either has moved. - Nothing is reachable from the open internet.
prod_hostis still null incede.config.json; no domain, no DNS (BLOCKED_OPERATOR items 3, 5, 6). The terms are no longer part of that list: item 8 is ✅ DONE 2026-08-18, the operator supplied every reserved value, and CEDE-226 took the draft label offdocs/terms.mdanddocs/acceptable-use.md— so what is left between here and the open internet is a host, a domain and DNS, not a legal gap. Nothing this fleet has built has ever been shown to a person outside the operator's tailnet. - The commercial plumbing is landed, not half-landed: usage metering
(CEDE-071,
52e0e36) and the Stripe test-mode lifecycle (CEDE-072,7c21ca1) are both merged. This plan sequences on those two items and deliberately restates neither. - **Phase 2's entry gate reads one of three on the newest measurement each
of its checks has, and it went down without anybody deciding anything.**
Read on the newest line each gate
check has, which is what the gate asks for: condition 1 does not hold —
2026-08-25T05:09:14Z PROD-01 FAIL; condition 2 does not hold —2026-08-25T05:16:29Z PROD-12 FAIL; condition 3 holds, GTM-05 is ticked and the brief is written. **Both failures are the walk agent's expired credential**, diagnosed in the standing-reds bullet above out of each red's own retained sandbox, so what this gate is short of is a measurement, not a working product: the last time either walk ran it passed, on2026-08-20T08:01:34Z PROD-01 PASSin 61.3 s and2026-08-19T05:27:16Z PROD-12 PASSin 88.1 s. The gate is nonetheless down, and this page does not soften that — a gate that asks whether a fresh reader can do these things is not satisfied by an argument that they probably could. The gate has read every way before and no reading was wrong when it was made: on 2026-08-16 that morning's sweep put condition 2 down on2026-08-16T07:43:21Z PROD-12 FAIL, and CEDE-196's merge (c23b832, 10:53:43Z) put it back up with no act of the operator's in between; the 2026-08-17 sweep read three of three on a single day's evidence; on 2026-08-18 it went down at 05:14:33Z and back up at 05:30:24Z, inside the same half-hour; 2026-08-19 read three of three again; and from 2026-08-21 it has read one of three every day. The gate itself has never moved; the measurements under it do. The gap CEDE-139 found was that nobody had told the operator; since 2026-08-14 the gate's three conditions, each with the command that re-checks it and its dated evidence, are written into BLOCKED_OPERATOR item 18, so what Phase 2 is waiting on is readable from that item alone — and that item now carries these two reds, names their cause, and points at item 21 as the act that lifts them. - **Phase 4's entry gate reads one of two, and the half that holds is the
check.** The gate asks for both: (1) `bash checks/production.sh --only
PROD-08` PASSes, and (2) BLOCKED_OPERATOR item 7 is DONE. Condition 1 holds
on the newest line the check has —
2026-08-25T05:15:05Z PROD-08 PASS— the full billing lifecycle green in Stripe test mode: free sandbox at signup, five metered units invoiced exactly, a test-mode payment, and cancellation stopping metering. Condition 2 does not hold. **The two conditions are not the same credential and this page does not let them blur**: item 19, the staging test-mode key, is ✅ DONE 2026-08-18 and is what made condition 1 measurable at all; item 7 is the KYC'd Stripe account itself and is still open, with no DONE line inBLOCKED_OPERATOR.md. So GTM-20 stays unticked — its evidence clause asks for both halves and only one of them exists — and nothing on this page ticks or unticks it. Nothing in Phase 4 is startable on the strength of condition 1 alone, and no session may approach item 9's switch under any reading of either.
Ten of the twelve production checks are green at their latest run, the two that are not could not be measured at all, and none of it is reachable by name, so this product still does not have a distribution problem; it has an evidence problem — and for six days it has had a narrower one, which is that it could not take its own measurements. So Phase 1 produces receipts, not reach, and every later phase is gated on receipts that already exist — including this section, which is now a receipt rather than a recollection.
Who it is for#
Three segments, most-likely-first. The reasoning matters more than the order — the order is a consequence of it.
A. Parametric program designers at MGAs and program managers. First, because their job is the four verbs that are already live: take a schedule nobody can read, define a trigger, run it across forty years, and get a technical price with its assumptions on the face of it. Nothing in that sentence needs analyse, monitor or package, so this segment can get real value from the product as it stands today rather than as it stands after two more quarters. They are also the persona the nightly QA cohort already imitates, so the gaps they would hit are being found and filed every night by a synthetic version of them — the cheapest possible form of discovery, and the only demand signal this fleet is permitted to have.
B. ILS and ILW analysts. Second, because they are the segment most likely to punish a number that arrives without its assumptions — which is exactly the discipline the product already enforces in code. Determinism against pinned snapshots, results that replay byte for byte, a backtest that discloses thin data years instead of silently interpolating them: these are table stakes to this audience and are rare enough elsewhere to be worth naming. Smaller population than A, higher standards, slower to arrive, and the best possible reviewers of the registry.
C. Insurtech and platform engineers embedding risk analytics. Third by revenue proximity, first by distribution. Engineers adopt a format long before they adopt a vendor: the canonical object's schema is open source and consumable with no account at all (SPEC §5.4, §6), so this segment can be served completely without a commercial relationship. Every team that normalises to the canonical object is a path back to segments A and B, and the schema repo is the only channel in this plan that costs nothing to run and never goes stale.
Deliberately not targeted in the first edition, with the reasoning stated so a later session can overturn it on evidence rather than taste:
- Corporate risk teams and captives. BRIEF.md names them as users and they are; but their evaluation runs through procurement and their brokers, and SPEC §1 forbids human-in-the-loop delivery. A free sandbox is not how that buyer starts. Revisit in Phase 4, when there is a metered account to point at.
- Carriers and brokers who want execution. What this audience asks for next is on the far side of BRIEF.md's perimeter. They are not a segment; they are a source of requests the product declines, and every surface this plan produces should decline them clearly enough that the conversation ends early.
Positioning#
The sentence, which is already the site's: a file format for risk. One canonical object; an engine of verbs over it; an open registry of validated models and feeds. You bring the paper — the product is software, and stays software.
Three proofs carry that sentence, all of them artifacts rather than adjectives:
- The cursed corpus. Ingest is measured against real-world-ugly files — merged cells, header drift, mixed encodings, ambiguous units — as an append-only oracle that must pass at 100% or no merge happens. The statement "we read the files you actually have" is not a promise here; it is a test run count anyone can read.
- Assumptions on the face of every number. A technical price carries its
model versions, data vintages, event set, loadings and currency basis as
first-class response fields, and ingest records every guess it made in
source_fidelityrather than dropping it silently. The honest disclosure is the product. - Replay. Models are deterministic against pinned snapshots, results replay byte for byte, and CI re-validates every published model on every build. A result that cannot be reproduced is treated here as a defect, not a caveat.
What this plan never writes. No social proof before it exists: no invented case studies, no logo wall, no user counts, no praise attributed to somebody who never said it (ADR-0021 constraint 2). Until real users exist, the material is the product's own receipts — run ids, the playground walk, corpus counts, the disclosure lines, this repo's own honest red checks. That is not a restriction the plan works around: it is the position. The pitch is that this product does not overstate, and a page that overstates refutes the pitch in one line. Earning real proof — design partners, recorded permission, written-up walks — is legitimate work and appears below as owner-tagged actions.
The perimeter. BRIEF.md's perimeter governs every line of this plan and every surface it spawns, exactly as it governs product copy: a landing page and a launch post are product copy. No file or directory this plan creates is exempt from the scanner — docs/GTM.md is itself in scanned scope, and bash checks/gate.sh is the proof. Where a page needs a disclaimer line, it reuses one of the reviewed lines already in checks/perimeter-allow.txt verbatim rather than inventing a new phrasing that has never been reviewed.
The phase sequence#
Four phases, gated on evidence and never on dates (BACKLOG standing rule). Each phase states its entry gate as a check somebody can run.
The hard rule, from ADR-0021 constraint 3: no public-launch action may begin before all three of — the PROD board green, terms approved by the operator, and a production host. They are the entry gate to Phase 3, stated there as three runnable checks. Phases 1 and 2 are deliberately shaped so that all the work which does not require them happens first, and the fleet is never waiting.
| Phase | Name | What leaves this machine |
|---|---|---|
| 1 | Receipts | nothing |
| 2 | Named evaluation | nothing; named people are brought to the tailnet |
| 3 | Public availability | the product, on a real name |
| 4 | Metered commercial motion | invoices, in test mode until item 9 |
Phase 1 — Receipts#
Entry gate. None. This phase is the present state and is open now.
The purpose is to make the three proofs above legible to a stranger without anything leaving this machine. The channels in this phase are all ones the fleet already controls: the specification page, the docs site, the playground, and the open schema. No external channel is touched, so nothing here waits on the operator.
Exit condition: everything in Phase 2's entry gate is satisfiable.
- [x] GTM-01 [owner:fleet] State the segment sentence and the three proofs on the specification page, in the page's own voice — evidence:
site/index.htmlcarries all three proof headings andbash checks/gate.shexits 0 withsite/in scanned scope - [x] GTM-02 [owner:fleet] Publish a receipts walkthrough: one real run, its assumptions, its data vintages, and the re-run that reproduces it byte for byte — evidence: a page under
docs/whose commandsmake docsexecutes against staging on every build - [x] GTM-03 [owner:fleet] Make the open schema usable as a channel: a page showing how to consume the published schema with no account, versioned and linkable — evidence: the page resolves the published schema version the API declares, and
make docsexecutes its example - [x] GTM-04 [owner:fleet] Publish the two onboarding walk timings as measured numbers, refreshed from the harnesses rather than typed by hand — evidence:
docs/walk-timings.mdis rendered fromchecks/walk-timings.log— the append-only record the PROD-01 and PROD-12 harnesses append each completed walk's elapsed seconds to — andtests/unit/test_walk_timings.pyfails if the committed page differs from what the committed record renders - [x] GTM-05 [owner:fleet] Draft the one-page design-partner brief the operator will send, with no social proof in it and a stated ask — evidence:
docs/gtm/design-partner-brief.mdexists, names the three segments, and the gate stays green with it in scanned scope - [x] GTM-06 [owner:fleet] Publish the honesty exhibit: what ingest survives, what it flags, and what it refuses, with counts read from the corpus manifests — evidence: the page's counts are computed from
corpus/manifest.d/*.yamlby a committed test, not restated by hand
Phase 2 — Named evaluation#
Entry gate. All three, each a runnable check:
bash checks/production.sh --only PROD-01PASSes — a fresh session goes from signup to a first authenticated call in under ten minutes on public docs alone;bash checks/production.sh --only PROD-12PASSes — a fresh session composes a model, backtests it, and prices with it in under fifteen minutes;- GTM-05 is ticked — there is a brief to send.
Nothing in this phase is public. Named people are brought onto the operator's tailnet, one at a time, and the only channel is the operator's own existing relationships — no posting, no accounts, no lists. The point of the phase is not revenue and not references: it is to find out which of the three segments returns a second time without being asked, because that answer re-ranks everything below it.
Exit condition: at least two named evaluators have completed a real job through public interfaces alone, and their gaps are BACKLOG items.
- [ ] GTM-07 [owner:operator] Introduce the design-partner brief to at least three named candidates across segments A and B — evidence: BLOCKED_OPERATOR item 18 records three names with dates
- [ ] GTM-08 [owner:fleet] Turn each named evaluator's real job into a nightly QA cohort persona so it is re-run every night, not once — evidence:
supervisor/personas/gains one persona file per recorded job and the nightly cohort run includes it - [ ] GTM-09 [owner:fleet] Keep an evaluation log and file every reported gap as a BACKLOG item within one supervisor tick — evidence: every gap in
docs/gtm/evaluation-log.mdhas a BACKLOG item tagged[source:design-partner], asserted by a committed test - [ ] GTM-10 [owner:operator] Record written permission before any evaluator's name, logo or result appears on a page — evidence: BLOCKED_OPERATOR item 18 carries a dated permission line per name, and no page names anybody without one
Phase 3 — Public availability#
Entry gate — the constraint-3 gate, all three required. No action in this phase that exposes anything to the open internet may begin before every one of these is true:
- The PROD board is green:
bash checks/production.sh --doneexits 0 — which by PRODUCTION.md's own DONE rule means every PROD-NN has been green for seven consecutive days. The weaker reading (all twelve green once) was considered and rejected: a launch is the least reversible thing this fleet can do, and a single green day is exactly the evidence a flake produces. - Terms exist: BLOCKED_OPERATOR item 8 is marked DONE by the operator and the signup surface no longer labels its terms as a draft pending review.
- A production host exists:
prod_hostis non-null incede.config.json, with the domain and DNS behind it (BLOCKED_OPERATOR items 5 and 6).
Two actions here sit deliberately in front of that gate, and must. GTM-14 drafts the terms and GTM-17 drafts the launch note and the posts. Neither exposes anything — both produce files in this repo and stop. Gating them on the gate would deadlock the phase: BLOCKED_OPERATOR item 8 asks the fleet to draft terms so that the operator can approve them, and approved terms are gate condition 2. Constraint 3 governs public-launch actions; drafting and staging are what the fleet does while waiting for one.
Channels in this phase, in the order they earn their keep: the public schema repo (free, permanent, and the only one aimed at segment C); the docs site on a real name; and at most three practitioner or developer communities the operator names before posting. No paid acquisition at all — there is no budget for it under BRIEF.md's cost ceiling, and a channel the fleet cannot measure from its own logs is a channel this plan will not defend.
Exit condition: a stranger with no introduction completes the ten-minute walk on the public name, and the fleet can see them do it in the request log.
- [ ] GTM-11 [owner:operator] Provide the production host (BLOCKED_OPERATOR item 3) — evidence:
prod_hostis non-null incede.config.jsonand the deploy pipeline promotes to it - [ ] GTM-12 [owner:operator] Purchase the domain (BLOCKED_OPERATOR item 5) — evidence: the domain is recorded in that item with a date and appears in the deploy config
- [ ] GTM-13 [owner:operator] Point DNS at the API, docs and landing hosts (BLOCKED_OPERATOR item 6) — evidence: the public names resolve from outside the tailnet and the deploy config names them
- [x] GTM-14 [owner:fleet] Draft terms of service and an acceptable-use page for the operator to review, both inside BRIEF.md's perimeter — evidence:
docs/terms.mdanddocs/acceptable-use.mdare committed and BLOCKED_OPERATOR item 8 is updated to ready-for-review (ticked 2026-08-13 by the planner: both pages merged in CEDE-109c66a50c, item 8 reads READY FOR REVIEW 2026-08-13) - [x] GTM-15 [owner:operator] Approve the terms (BLOCKED_OPERATOR item 8) — evidence: that item is marked DONE with a date and the terms pages drop their draft label (ticked 2026-08-18 by the test-amender: BLOCKED_OPERATOR item 8 reads '8. Terms of service sign-off — DONE 2026-08-18' and records a value for every reserved decision; CEDE-226 transcribed those values into
docs/terms.mdanddocs/acceptable-use.mdand dropped the DRAFT label from both, withtests/unit/test_terms_pages.pyamended underadr/ADR-0062-test-amendment-terms-pages-approved-state.mdto assert the approved state. Measured on the two pages, not on the signup path: this clause used to read 'the signup surface drops its draft label', while the label lived on the two terms pages alone —docs/quickstart.mdandPOST /signuplink neither page, which is unfiled wiring this tick does not assert) - [ ] GTM-16 [owner:fleet] Prove the cold-start walk on the public name, not on staging — evidence:
bash checks/production.sh --only PROD-01PASSes with the base URL set to the public name - [x] GTM-17 [owner:fleet] Draft the launch note and the community posts and stage them in-repo, unpublished — evidence:
docs/gtm/launch/holds one file per destination andbash checks/gate.shexits 0 with them in scanned scope (ticked 2026-08-14 by the planner: CEDE-141 mergedde89f52staging launch-note.md plus three destination posts, corrected to the five-verb truth by CEDE-146eb7f95e, gate green as of 2026-08-14T13:38:01Z) - [ ] GTM-18 [owner:operator] Publish the staged launch note and posts to the named destinations (BLOCKED_OPERATOR item 18) — evidence: that item records each destination with the date it was posted
Phase 4 — Metered commercial motion#
Entry gate. Both:
bash checks/production.sh --only PROD-08PASSes — the full billing lifecycle is green in test mode, which is CEDE-072's acceptance, not this plan's;- BLOCKED_OPERATOR item 7 is DONE, so test-mode keys exist where the deploy config expects them.
This phase deliberately contains no metering or billing design. Usage metering is CEDE-071 (merged) and the test-mode lifecycle is CEDE-072; restating either here would create a second place for them to be true, which is how two files start disagreeing. What belongs here is only the commercial motion on top of them: saying the price basis out loud, in public, sourced from the meter.
Real charges are the operator's alone (BLOCKED_OPERATOR item 9), and no session may approach that switch.
Exit condition: an account can sign up, use the product, and see a correct metered invoice without anybody being asked anything.
- [x] GTM-19 [owner:fleet] Publish the metered price basis — per object and per model run — sourced from the billable-unit table rather than retyped — evidence: a committed test asserts the page's units equal the billable units in the product's usage module (ticked 2026-08-16 by CEDE-204: the units have been published since CEDE-072 in
docs/quickstart.mdand this page's verb-to-unit table since CEDE-0840c2201c;tests/unit/test_billing_page_basis.pynow holds that table againstcede.api.usage.BILLABLE_UNITSandUNIT_BY_VERB, in the unit gate) - [ ] GTM-20 [owner:operator] Complete Stripe onboarding and place restricted test-mode keys (BLOCKED_OPERATOR item 7) — evidence: that item is marked DONE and
--only PROD-08PASSes against staging - [x] GTM-21 [owner:fleet] Publish a reconciliation exhibit: metered usage in, invoice quantities out, equal to the unit — evidence: the exhibit's numbers come from a recorded test-mode run that CI replays with no network and no key (ticked 2026-08-16 by CEDE-208:
docs/gtm/reconciliation.mdpublishes the per-unit table andtests/integration/test_reconciliation_exhibit.pyrecomputes every figure on it from the runtests/integration/test_billing_lifecycle.pyreplays, in the integration gate) - [ ] GTM-22 [owner:operator] Flip the real-money switch (BLOCKED_OPERATOR item 9) — evidence: that item records the flip with a date, and until then every charge is test mode
What would make a later session re-cut this plan#
Stated up front so a re-cut reads as evidence, not as a change of mind:
- Segment order. If Phase 2's evaluators from segment B return more reliably than segment A's, the order above is wrong and the channel actions in Phase 3 should follow the returners. That is a measurement, not a discussion.
- The schema-as-channel bet. If GTM-03 lands and nobody consumes the published schema for a month after Phase 3 opens, segment C is a distribution theory that did not survive contact, and the effort belongs in the docs site instead.
- The Phase 3 gate. The seven-day reading of "the PROD board is green" is the strictest honest one. It can only be loosened by a later ADR that argues it, never by a session in a hurry — and PRODUCTION.md would have to change first.
- A public source of demand. Today the nightly cohort is the only demand signal this fleet is permitted to have (BRIEF.md). The moment real users exist, their behaviour outranks every assertion on this page, including the segment reasoning.