# CEDE — the go-to-market plan

Status: **first edition** (CEDE-075), authored under
`adr/ADR-0021-go-to-market-mandate.md`.

Standing: a first-class artifact alongside PRODUCTION.md. The planner reads
this file in its boot ritual, ranks BACKLOG against its open phases exactly as
it ranks against non-green production checks, ticks an action when the evidence
that action names actually exists, and files drift between this plan and
reality as BACKLOG items. **PRODUCTION.md keeps priority wherever the two
conflict** — a product that fails its own checks has no business being
launched at anyone.

**How to read it.** Prose is context and is never parsed. Every line beginning
`- [` is an action and matches exactly one grammar:

    - [ ] GTM-NN [owner:fleet|operator] Title — evidence: <objective check>

`owner:fleet` means a session can do it. `owner:operator` means only Ben can —
money, legal, identity, and anything that leaves this machine for the open
internet (ADR-0021 constraint 4: the fleet drafts and stages, the operator
publishes). Every operator action here cites the BLOCKED_OPERATOR item that
carries it, by number, so the operator queue stays the single place a human
looks for their work. Evidence is a check that can flip, a thing that exists,
or a number that can be read — never a judgement call.

`tests/unit/test_gtm_plan.py` holds all of that still: the grammar, the id
shape, one owner per action, the BLOCKED_OPERATOR cross-reference, and the
rule against asserting social proof this product has not earned.

---

## The honest baseline

Dated **2026-08-25**, re-derived against the record as far as
`2026-08-25T05:16:29Z` — the newest line the record carries at this writing.
That line is the last of the twelve the 2026-08-25 morning full sweep wrote,
and every other line of the board below is one of the other eleven: this
edition's board is one unattended sweep's own reading with nothing spliced
into it, which the previous edition's was not. Every claim
below names something checkable in this repo: a line in
`checks/history.log`, a merged BACKLOG id, a file, or a figure a committed
test recomputes.

This is the CEDE-224 edition: a drift pass over the CEDE-221 edition of
2026-08-18, not a
wholesale re-cut of the
section. **It is also the longest gap this section has ever gone unrevised,
and the reason is on the record rather than in anybody's memory.** The item
that produced this edition was cut to re-derive the baseline against the
2026-08-19 sweep; it did not run then, because the OAuth credential every
spawned session runs on expired on 2026-08-20 and every session since aborted
at authentication — `BLOCKED_OPERATOR.md` item 21, opened 2026-08-24, is the
operator action, and BACKLOG's CEDE-246 is the fleet item that makes the
instruments say so instead of wearing it as product red. So this edition
re-derives against the newest sweep the record actually holds, the 2026-08-25
morning full sweep, rather than dating itself to a sweep six days behind the
log: a baseline that is right about an older day is the one failure mode this
section exists to prevent. What moved is what the record contradicts — the
board and the
sentences that describe it, the PROD-02, PROD-12, PROD-09 and PROD-07 bullets,
the standing-reds bullet, whose whole premise flipped twice over, the Phase-2
and Phase-4 gate
readings and this section's closing sentence — and every
sentence they left true is the previous edition's, unrewritten. The headline
count is ten, re-derived from the board below rather than
carried across, and it is the same number the 2026-08-18 edition carried with
four of the twelve checks having changed side under it. The plan's standing orders make that
drift a BACKLOG item rather than a habit, and this is one.

The edition this replaces was the single one cut on 2026-08-18, and the one
before it the single one cut on 2026-08-17; the day
before that took two, and that pair is the shelf life of this section measured
rather than guessed at. Seven days is the other end of that range, measured
here for the first time and caused by an outage rather than by neglect.
CEDE-194 was cut at 06:32Z on 2026-08-16 and re-derived only as far as
`2026-08-16T01:27:30Z`, which was the tip of the record at the time and was
eleven-twelfths a report on 2026-08-15. It was internally consistent when it
was written and false about the product an hour later, because the sweep it
says did not run then ran: all twelve of its board lines were superseded
between `07:36:40Z` and `07:43:21Z`, and its headline number and its
Phase-2-gate claim went with them. CEDE-199 corrected that same afternoon for
the drift CEDE-196's merge caused. Two editions in one day is
not churn — and it is the one way this
section is still allowed to rot, which is why re-deriving it is a BACKLOG item
rather than a habit. Since CEDE-139 the board below is not typed from memory:
`tests/unit/test_gtm_baseline.py` recomputes it from `checks/history.log` and
fails the build if a line, or the count, has drifted. What that test cannot do
is notice that a session never moved the block forward, because it pins the
board as of the block's own newest line. So a stale baseline here never shows
up as a wrong number — it is a right number about an older day, which is
harder to catch and is exactly what this edition exists to correct.

* **10 of the 12 production checks read PASS at their most recent run.** One
  line per check, each the latest line that check has in `checks/history.log`
  as of that file's own last line at this writing:

  <!-- board-state: the latest line per check in checks/history.log, recomputed by tests/unit/test_gtm_baseline.py -->

      2026-08-25T05:09:14Z PROD-01 FAIL
      2026-08-25T05:09:15Z PROD-02 PASS
      2026-08-25T05:10:46Z PROD-03 PASS
      2026-08-25T05:11:10Z PROD-04 PASS
      2026-08-25T05:11:20Z PROD-05 PASS
      2026-08-25T05:13:26Z PROD-06 PASS
      2026-08-25T05:13:58Z PROD-07 PASS
      2026-08-25T05:15:05Z PROD-08 PASS
      2026-08-25T05:15:59Z PROD-09 PASS
      2026-08-25T05:16:02Z PROD-10 PASS
      2026-08-25T05:16:28Z PROD-11 PASS
      2026-08-25T05:16:29Z PROD-12 FAIL

  This is the *latest run* reading. It is **not** PRODUCTION.md's DONE rule,
  which asks for seven consecutive green days and is what Phase 3's entry gate
  cites — nothing on this page moves that gate, and ten green today is not
  one green week. The number is
  re-derived from the twelve lines above rather than carried across,
  because a count copied forward is a count nobody has checked, and
  `tests/unit/test_gtm_baseline.py` recounts the block and fails the build if
  the two disagree.

  **Ten is the same number the 2026-08-18 edition printed, and almost nothing
  under it is the same.** Four of the twelve checks changed side since that
  board — two reds went green and two greens went red, which is how a count
  stands still while everything under it moves — and this
  page states each as itself rather than netting them off. **PROD-08 went
  green** and has stayed green: the operator placed a test-mode key and
  CEDE-225 closed the probe's own race, and the standing-reds bullet below
  reads that out of the ledger. **PROD-02 went green** — the seven-day soak,
  red on every board this section has ever printed, first PASSed at
  `2026-08-21T05:02:43Z` and has PASSed on every sweep since; that is the one
  unambiguously good movement on this board and it landed on exactly the date
  the 2026-08-18 edition re-derived as the earliest possible one. **PROD-01
  and PROD-12 went red**, and they are red for one cause that is not the
  product: the walk agent both checks spawn cannot authenticate. So the red
  half of the board is a pair again, and it is a different pair, red for a
  different kind of reason — a dead credential rather than a clock. Both have
  their own treatment below.

  **All twelve lines are dated 2026-08-25 and all twelve are the morning full
  sweep's own**, 05:09:14Z through 05:16:29Z, with nothing spliced in and no
  `--only` re-run anywhere in it — not because nothing went red on it, but
  because no session was able to run for six days to re-run anything. The
  previous edition's board was not that shape: eleven of its lines were the
  2026-08-18
  sweep's and the twelfth was a PROD-12 `--only` re-run taken sixteen minutes
  after the sweep's own PROD-12 line came back red — the same shape as the
  2026-08-16 board this section has criticised before, which took eleven lines
  from the sweep and the twelfth from a re-measurement that merged three hours
  later. Every edition before the 2026-08-16 one
  carried a board assembled out of several days. That a
  sweep now runs each morning to make either possible is a repair, and it is
  worth keeping on the page because the thing it repaired was invisible: an
  earlier edition reported that
  no full sweep ran on 2026-08-16 because `production_duty()` in
  `supervisor/supervisor.py` skipped the day's run of `checks/production.sh`
  whenever `checks/history.log` already carried *any* `PROD-` line dated that
  UTC day — three restore-drill verdicts between `2026-08-16T00:13:30Z` and
  `2026-08-16T01:27:30Z` had erased the day — and it left open whether that
  skip was a defect worth a change to the harness. It was, the question is
  settled, and the settling is on the record twice over. **CEDE-195** (merged
  `b5ad358` at 07:34Z) re-keyed the skip to evidence the full sweep actually
  ran: the duty now skips only when every check id on the sweep's roster has a
  line dated today, the roster derived in code from PRODUCTION.md's own
  `### PROD-NN` headings rather than a second hand-typed list, with
  `supervisor/test_production_duty_skip.py` holding it against fixture ledgers
  and wired into `checks/gate.sh`. On 2026-08-16 the very next supervisor tick
  took the sweep, two minutes after the merge. So this is not a fix asserted on
  the strength of a merge: the machinery that was broken on 2026-08-16 is the
  machinery that produced that day's board, and the twelve lines above are the
  tenth whole board it has produced — one a day, unattended, every day from
  2026-08-16 to 2026-08-25 including the six on which no session could run at
  all, which is the strongest thing anyone can say for that repair.
* **What each of the two standing reds is waiting for**, so neither can be
  read as an unknown — and neither is what this bullet was waiting for a week
  ago. **Both of the reds the previous edition described are green, and both
  of the reds on the board today are new.** Taking them in the order they
  stopped being true:
  **PROD-08 is green**, and the sentence that stood here — that it was
  fleet-complete and red for one missing credential, the operator's Stripe
  **test-mode** key — is false now, on three things read together. The
  operator placed a test-mode key on 2026-08-18
  (BLOCKED_OPERATOR item 19, ✅ DONE 2026-08-18, with the supervisor drop-in
  that the nightly sweep needs to see it); CEDE-225 (merged `09f4028`) closed
  the probe's own race, in which a poll landing on Stripe's id-less
  upcoming-invoice preview crashed the instrument instead of continuing to
  poll; and the check then recorded `2026-08-18T09:45:56Z PROD-08 PASS`, the
  first PASS it has ever had, and has PASSed on every morning sweep since,
  `2026-08-25T05:15:05Z PROD-08 PASS` being the newest. Item 7 — the KYC'd
  Stripe account — is a different item and is still open; what depends on it
  is Phase 4's gate, below, not this board.
  **PROD-02 is green**, and this is the movement worth reading twice, because
  the seven-day soak was red on every board this section has ever printed and
  had never recorded a PASS in `checks/history.log` at all. The
  2026-08-18 edition re-derived, from the newest sev1 in `ops/incidents.log`
  and the check's own seven-day window, that the earliest window which could
  possibly pass was the one ending **2026-08-21**. It passed on
  `2026-08-21T05:02:43Z`, and on every sweep since. What the newest run says of
  itself, read from
  `/opt/cede/shared/prod-sweeps/PROD-02-2026-08-25T05:09:15Z.log` rather than
  inferred: window 2026-08-19..2026-08-25, all seven days `ok`, 47271 requests
  across 333 runs, and **"sev1 opened in window: 0"** — the traffic clause and
  the sev1 clause both, which is what a PASS on this check means. The newest
  sev1 in `ops/incidents.log` is still the pair that opened at
  2026-08-14T06:40:28Z (CEDE-135 and CEDE-136, the published front refusing
  connections across a restart, both recovered five minutes later at
  06:45:28Z), and it has now scrolled out of the window. Nothing has opened a
  sev1 since; everything logged since is sev2, the newest of them the
  merge-gate and quiet-supervisor alerts of 2026-08-22 (CEDE-243, CEDE-244).
  This is not the DONE rule and does not pretend to be: PROD-02 measures a
  seven-day soak window and passes it, while PRODUCTION.md's DONE rule asks for
  seven consecutive days on which the *whole board* is green, and the two reds
  below have voided every day since 2026-08-20 for that purpose.
  **PROD-01 and PROD-12 are red, for one cause, and it is not the product.**
  Both checks spawn a clean-environment agent that must reach the published
  docs site before either clock starts. Since 2026-08-20 that agent has not
  started at all: the OAuth credential it runs on expired and cannot
  self-refresh. Read from the runs the sweeps retained, not inferred —
  `/opt/cede/shared/prod-sweeps/PROD-01-2026-08-25T05:09:14Z.log` and
  `/opt/cede/shared/prod-sweeps/PROD-12-2026-08-25T05:16:29Z.log` each record
  `agent session: exit 1 after` about a second `, 0 HTTP request(s) recorded`,
  and the sandbox PROD-12 keeps on a red, `/tmp/cede-prod12-8kztcw3_`, holds a
  transcript whose entire content is `Failed to authenticate: OAuth session
  expired and could not be refreshed`. That is the same string in the retained
  sandbox of every PROD-12 red since the first one — the six sweeps from
  `2026-08-20T08:07:56Z PROD-12 FAIL` to
  `2026-08-25T05:16:29Z PROD-12 FAIL`, each checked here in its own sandbox
  rather than assumed from the first. PROD-01's last green is
  `2026-08-20T08:01:34Z PROD-01 PASS`, six minutes before the first PROD-12 red
  and a walk that completed in 61.3 s; its reds run from
  `2026-08-21T05:02:43Z PROD-01 FAIL` to
  `2026-08-25T05:09:14Z PROD-01 FAIL`.
  **What that does and does not mean.** It does not mean the onboarding walk or
  the composition walk stopped working — neither has been measured since
  2026-08-20 and 2026-08-19 respectively, which is a different and worse thing
  than a bad
  measurement. It does mean every day from 2026-08-20 on is a voided day for
  the DONE streak, because a check that could not run is not a green one, and
  PRODUCTION.md's status vocabulary is deliberate about that. The operator
  action is **BLOCKED_OPERATOR item 21** (opened 2026-08-24): re-authenticate
  the CLI, which is interactive and which no session can do. The fleet action
  is **CEDE-246**, which makes both probes say *the runner could not start*
  instead of writing a line a reader takes for a product red — the whole reason
  this cause took five days and an operator's own session to name. Neither of
  these two reds is a defect anybody can fix by building the product, and
  neither is an unknown.
* **The last PROD-12 walk that measured anything was on 2026-08-19, and it was
  green.** In one sentence, read from the run retained at
  `/opt/cede/shared/prod-sweeps/PROD-12-2026-08-19T05:27:16Z.log`:
  `2026-08-19T05:27:16Z PROD-12 PASS` is the last green the fifteen-minute
  composition walk has, and its agent made nine
  HTTP requests in 98.7 s — three of them to the docs site, the index,
  `/quickstart` and `/model-builder`, and `price.md` not among them — composed
  `mdl_3b7f423283a1471cac6e0394f13882be` v1.0.0 from the four primitives with
  its determinism check and its 1986-01-01..2025-12-31 backtest, and priced
  through `POST /models/{id}/runs` for 873836.05 THB on a technical basis
  labelled with that model, 88.1 s of the 900 s budget from the first docs
  fetch. So that walk is green and the fork is a road it did not take: it is
  the second outcome of the three, not a further measurement of the signpost.
  **It is not the board's PROD-12 line**: every sweep since has written a FAIL
  the walk agent's dead credential caused, as the standing-reds bullet above
  reads out of each red's own retained sandbox, so what follows is the
  fork's history and not a current reading. Nothing below is evidence about
  the product today, because nothing has measured the product since
  2026-08-19.

  **The one walk that read the signpost is still the only one.**
  `2026-08-18T05:30:24Z PROD-12 PASS` was the newest PROD-12 line on the
  2026-08-18 edition's board, taken as an `--only` re-run sixteen minutes after
  that sweep's own PROD-12 line came back red. **Of the
  three outcomes a fork measurement can have, that walk produced the first: it
  fetched the signposted page and still priced by the route the signpost
  names.** Read from the run retained at
  `/opt/cede/shared/prod-sweeps/PROD-12-2026-08-18T05:30:24Z.log`: sixteen of
  its thirty-six requests went to the published docs site across six paths, and
  **four of them were `/price`** — the path `src/cede/docsite/pages.py`
  publishes `docs/price.md` at, which is the page carrying CEDE-196's signpost.
  It composed `mdl_2e4dc84253714f46a990fa5956216e22` v1.0.0 from the four
  primitives, took its determinism check and its forty-year backtest across
  1986-01-01..2025-12-31, and then priced through `POST /models/{id}/runs`:
  1067250.47 THB on a technical basis, labelled with the model it had just
  composed. All four `/price` fetches fall after the `201` that created the
  model and before the pricing call, and `POST /objects/{id}/price` — the road
  the 2026-08-16 red took by mistake — was never called at all. 153.3 s of a
  900 s budget.

  **What that does not settle**, stated here as PRODUCTION.md's PROD-12 block
  states it and not enlarged, and re-derived from the record rather than
  carried across. One walk that took the signposted road is not
  proof the fork can never trap another, and the ratio has got weaker rather
  than stronger since the previous edition said so. Eleven PROD-12 lines have
  been recorded since the signpost deployed at 2026-08-16T10:55:27Z, and only
  four of them are walks that fetched anything at all —
  `2026-08-17T05:09:55Z PROD-12 PASS`,
  `2026-08-18T05:30:24Z PROD-12 PASS`, `2026-08-18T08:12:07Z PROD-12 PASS` and
  `2026-08-19T05:27:16Z PROD-12 PASS`. Of those four, exactly one opened the
  page. The other seven measured no route at all: `2026-08-18T05:14:33Z
  PROD-12 FAIL`, whose agent asked for a permission it could not be granted,
  and the six credential deaths from `2026-08-20T08:07:56Z PROD-12 FAIL`
  onward. The counts are grepped out of
  `checks/history.log` at this writing; the previous edition read three walks
  because two of them did not exist yet, and the 08:12:07Z line never appeared
  on
  any board because a later line superseded it before an edition was cut.
  A passing run also keeps no sandbox, only a red
  does, so what survives each of those walks is the retained log's record of
  the fetches
  and the route, not the session's own account of what it read there. What
  changed on 2026-08-18 is that the signpost is measured to work when it is
  read, rather than only published; nothing has added to that since, because
  nothing since 2026-08-19 has walked.

  **The red it replaced measured nothing about the product either way.**
  `2026-08-18T05:14:33Z PROD-12 FAIL` was that sweep's own PROD-12 verdict, and
  it was on the previous edition's board for the sixteen minutes before the
  re-run. Read from
  the run the sweep retained at
  `/opt/cede/shared/prod-sweeps/PROD-12-2026-08-18T05:14:33Z.log`: the walk's
  agent session exited 0 after 9.8 s with **0 HTTP requests recorded**, so it
  never fetched the docs site, the clock the check starts at the first docs
  fetch never started, and nothing was composed from public docs — the run's
  own verdict line says either the docs were unreachable or the session did
  nothing, and establishes neither. The sandbox is kept at
  `/tmp/cede-prod12-m9qzwlnu`. Diagnosing that red was PRODUCTION.md's PROD-12
  block's work and CEDE-220's rather than this page's, and it is diagnosed
  there: the spawned agent reached for a tool the walk harness does not allow
  it and stopped to ask for a permission it could not be granted, so the red is
  the harness's agent and not Cede.

  **The green before both is still in the record and still true of the day it
  was taken.** `2026-08-17T05:09:55Z PROD-12 PASS` was the fifteen-minute walk
  in 72.1 s of a 900 s budget and the first taken against a published docs tree
  carrying CEDE-196's signpost — the walk the previous edition said would
  measure the fork closed. **It did not measure it.** Read from
  `/opt/cede/shared/prod-sweeps/PROD-12-2026-08-17T05:09:55Z.log`, that walk
  fetched four docs pages — the index, `/quickstart`, `/model-builder` and
  `/quickstart.md` — never opened `price.md`, and took its price from
  `POST /models/{model_id}/runs`, whose job result came back labelled with the
  model it had just composed. That is why reading the signpost took a third
  walk.

  **What went red first, and why it is a different fault from either of
  2026-08-18's two.**
  `2026-08-16T07:43:21Z PROD-12 FAIL` was the morning sweep's
  fifteen-minute
  composition walk, and it was not a timeout: the walk's own agent exited 0
  after 121.5 s of a 900 s budget, having composed and validated
  `mdl_9381bd3bd8e84f40bcc0027a901a8e58` v1.0.0 from the four primitives, taken
  its determinism check and its forty-year backtest, and priced — but priced
  through `POST /objects/{id}/price`, the generic verb, which answers with the
  platform pricing model — the priced job came back labelled
  `cede/parametric-burn-station-index` v0.1.0, which is not the model the
  session composed — so no recorded response carried a price labelled with the
  model it had just built and ADR-0032's stop condition never fired. **The fork, in one sentence: `docs/price.md` is the page the walk
  reads after `docs/model-builder.md`, and it taught the object-price route
  without saying that a price labelled with a model you composed comes from
  `POST /models/{id}/runs` instead — so a reader who followed the docs in order
  arrived at the wrong route and the check was right to refuse.** The
  platform label on that response is P9 working as specified, not the defect.
  That red was attributable without a re-run because CEDE-193's retention kept
  the run: `/opt/cede/shared/prod-sweeps/PROD-12-2026-08-16T07:43:21Z.log` and
  the sandbox at `/tmp/cede-prod12-q0dkixde`. **CEDE-196 signposted the fork in
  `docs/price.md`, above the page's first runnable block, and re-measured.**

  **Both caveats that history carried are now discharged, and both are
  PRODUCTION.md's PROD-12 block's own.** The first was about publication: the
  docs site serves `/opt/cede/current/docs`, which is main's tree, so the
  signpost reached readers only at the first deploy after the merge — that
  deploy landed at `2026-08-16T10:55:27Z`, release `db5499c7cb33` in
  `/opt/cede/shared/deploys.log`, and every walk that has fetched anything
  since — 2026-08-17, both on 2026-08-18, and 2026-08-19 — was taken against
  the tree it published. The second was that no walk
  had yet reached the fork, and until 2026-08-18 it stood on three walks:
  none of the 08:28:20Z, 05:09:55Z or 05:14:33Z walks fetched `price.md` at any
  point — the first two stopped the clock on a job result from
  `POST /models/{model_id}/runs` carrying the composed model's own label, and
  the third fetched nothing whatsoever. **The 05:30:24Z walk is the one that
  discharges it**, on the terms the caveat itself named: it opened `price.md`
  and priced with its own model anyway. Read
  together: the check was green on the last measurement it managed to take,
  which is 2026-08-19's and is no longer the newest line it has; the fork is
  still a road a walk
  may take wrongly, and one walk since the signpost deployed has been
  measured taking it rightly.
* **PROD-07 is green, and the collision the previous edition described is
  history.** That edition reported the check red on a re-measurement and said
  the red was a rule collision rather than a defect: coverage was complete —
  `route table: 32 endpoint(s)` against `endpoints exercised by an example: 32`
  at `2026-08-15T06:34:21Z PROD-07 FAIL` — and the two non-2xx responses in
  that run were refusals the examples provoke on purpose, a stranger's object
  id refused `404` at step 7 of `docs/accumulation.md` and an unknown analysis
  name refused `422` at step 6 of `docs/analyse.md`. It said resolving that
  changed what the check means and belonged to a planner-cut item with an ADR.
  It did, and the item ran. **ADR-0052** (CEDE-170, merged `8d2f50c`) narrowed
  clause (c) of PROD-07's rule: a recorded non-2xx is excused only where the
  runnable block that issued the request itself compares a status-bearing
  expression against that exact three-digit literal, and only as many times as
  that page's blocks assert it — an unasserted non-2xx still fails exactly as
  before, which `tests/integration/test_prod07_asserted_refusals.py` proves
  against a live server. That left one half undone, because only
  `docs/accumulation.md` pinned its status; **CEDE-175** (merged `4d4469d`)
  gave step 6 of `docs/analyse.md` its own `test "$status" = 422` in the same
  runnable block, so the page now fails if the product ever stops refusing that
  way. The measurement that closed it is `2026-08-15T16:16:42Z PROD-07 PASS`:
  34 endpoints in the server's own route table, 34 exercised by an example, 14
  pages carrying one and every one of them exiting 0, and both refusals
  adjudicated as asked-for. Read it for what it measures — the product's
  answers did not change; what changed is that both demonstrations now pin the
  status they teach. PRODUCTION.md's PROD-07 block carries the full run.
  CEDE-163 has separately merged the advisory lock that holds a timer deploy
  back while a sweep is driving staging; whether that ends the restart-
  collateral class is a claim the next sweeps measure, not one this page makes
  on the strength of the merge.
* **2026-08-14's three reds were green again by the 2026-08-15 sweep — and one
  of the three was a defect, not collateral.** PROD-06, PROD-09 and PROD-12 FAILed
  within three minutes of each other on 2026-08-14 (`05:23:44Z`, `05:24:47Z`,
  `05:26:12Z`), which reads like one fault and was not. **PROD-09's was real
  and was fixed**: the rollback drill ran for the first time under ADR-0034's
  front topology, `deploy.sh` composed a service command with no front, and the
  drill's own deploys took the published address down for 3m44s — CEDE-134
  repaired that with a regression test (merged `cd273a2`) and the drill went
  green the same morning, `2026-08-14T06:56:30Z PROD-09 PASS`. **The other two
  were collateral of a restart**, each of a different one and both recorded in
  BACKLOG's CEDE-138 entry minute by minute: PROD-12's whole
  05:24:48Z→05:26:12Z walk ran inside that same dark front, and a staging timer
  deploy at 05:22:40Z landed inside PROD-06's probe. CEDE-138 is the item that
  re-ran both rather than assuming the diagnosis —
  `2026-08-14T09:00:22Z PROD-06 PASS`, `2026-08-14T09:03:32Z PROD-12 PASS` —
  and all three stayed green unattended overnight:
  `2026-08-15T05:34:47Z PROD-06 PASS`, `2026-08-15T05:36:16Z PROD-09 PASS`,
  `2026-08-15T05:38:16Z PROD-12 PASS`. So two of 2026-08-14's reds ended when
  the collateral stopped and the third ended because someone fixed the thing
  under it; this page does not merge those two into one sentence.
* **The measurement that decomposed the wait PROD-09 has been recording all
  along.** The rollback drill has run green on every sweep since, the
  newest being `2026-08-25T05:15:59Z PROD-09 PASS` — 215 health samples across
  the drill's three restarts with none refused, none non-2xx and no window in
  which the front was not served — but the run that is worth
  reading is an earlier one:
  `2026-08-15T22:43:16Z PROD-09 PASS`, the first run under CEDE-184's
  swap-phase instrument: `deploy/lib/swap_phases.py` records drain start and
  end, the incoming process's start, and first readiness for every swap, three
  of the four read back afterwards from systemd's own transition timestamps
  rather than measured by watching. **ADR-0058** states what that run found,
  and this page states it in that ADR's own words. The incoming release's boot
  dominates the wait — 1.793, 1.982 and 1.916 s, 62–65% of each — and *"what
  dominates in its place is module import — the interpreter, FastAPI, pydantic,
  psycopg, uvicorn and the app object — which is O(code), not O(rows)"*: it
  does not grow when the platform is used, it grows when a dependency or this
  codebase does. Hydration, which ADR-0051 measured at 84% of an 11.97 s boot,
  is 5.5–6.1% of this one. What is still O(rows) is the 0.129 s of loaders, and
  the ADR names the drain as the next question rather than answering it. Read
  that for what it is: a decomposition of one drill run, on one release, not a
  standing property of the deploy.
* **Both backup checks now cover the database, not the repo alone.** Until
  2026-08-15 PROD-10 measured the supervisor's nightly git bundles and PROD-11
  cloned one, while every account, API key, object, job and billing row had
  lived in the Cede-only PostgreSQL cluster since ADR-0026 (2026-08-12) with no
  copy of it anywhere — two green checks that were green about the wrong half.
  **CEDE-182** (ADR-0056) added the nightly logical dump, gzipped beside the
  bundles with a manifest recording what the database held in the dump's own
  snapshot, and gave PROD-10 a second clause that fails unless that dump is
  under 26 hours old and reads back. **CEDE-183** (ADR-0057) gave PROD-11 its
  matching clause: every run restores the newest dump into a scratch database
  the run creates and drops however it ends — never the database the product
  serves from — and asserts all thirteen tables come back with the row counts
  the manifest recorded. The first verdicts that measured and restored the
  database are `2026-08-15T22:35:47Z PROD-10 PASS` and
  `2026-08-15T23:59:10Z PROD-11 PASS`; every line above those two is the repo
  clause alone, and PRODUCTION.md's two blocks carry the runs. Two limits
  belong with that green rather than after it: all of it still sits on one
  host's disk with no off-host copy of the dump, and a nightly dump loses up to
  a day of writes — a day of usage events is a day of PROD-08's revenue
  evidence (ADR-0056, "Recovery point").
* **Seven verbs are live on staging**, behind the operator's tailnet: ingest,
  analyse, price, structure, backtest, monitor, package — plus the model
  registry, its four composition primitives, and the no-code builder
  (CEDE-038). **As of the last sweep**, `2026-08-25T05:13:58Z`, every route in
  the table was **observed** to be covered by a documented example executed
  against staging: 34 endpoints in the server's own route table, 34 exercised
  by an example, across the 15 pages under `docs/` that carry one — including
  `docs/hazard.md`, `docs/events.md`, `docs/analyse.md`,
  `docs/accumulation.md`, `docs/package.md`, `docs/monitoring.md` and
  `docs/trigger.md`. The route count is where the 2026-08-15 afternoon reading
  left it; what moved is the page count, from 14 to 15, because CEDE-189 landed
  `docs/trigger.md` at 2026-08-16T01:57:36Z with runnable examples of its own,
  so a fifteenth page is now executed on every merge and on every sweep. That
  reading is as-of, not standing — the next merged
  route makes it a claim about the past again, which is what dating it is for.
  Where the two gates that run these examples disagreed, they no longer do.
  PROD-07 discovers its pages by grepping the docs tree for the HTML-comment
  marker that `checks/docs_example.py` requires immediately above a runnable
  fence — named by description rather than reproduced on this page, because
  the discovery is a plain substring match with no exclusion list, so a page
  that merely reproduces the marker's exact text is discovered as one more
  runnable page and then fails for carrying no runnable block. Until
  2026-08-15 that discovery found all 14 while the merge gate's `docs` target
  in `Makefile` named 13 of them, leaving `docs/package.md` executed only when
  a sweep ran against staging. **CEDE-172 closed that** (merged `b3cd39a`):
  discovery now lives once, in `checks/runnable_pages.sh`, PROD-07 asks that
  script which pages to execute, `make docs` asks it to verify that the pages
  the target names are exactly those pages before it runs anything — and
  `docs/package.md` is among them — so a runnable page that reaches the tree
  unwired stops the merge gate instead of being skipped.
  `tests/unit/test_docs_gate_page_set.py` holds the two sets equal from the
  other side with its own independent discovery, and fails on a planted page of
  either kind. Every runnable page is now executed twice, once locally on every
  merge and once against staging on a sweep.
* **Analyse is live on every route SPEC §3.2 names**: the point hazard lookup
  `GET /hazard` (`src/cede/analyse/`, CEDE-142, ADR-0041), the public event
  catalogue and event footprints (CEDE-143, ADR-0042), the analyse job over
  an object, `POST /objects/{id}/analyse`, which runs both readings at an
  object's own locations and records the artifacts on its provenance
  (CEDE-153, ADR-0045), and accumulation across a set of objects, `POST
  /accumulation`, which rolls the account's own stored exposures up per peril,
  per declared region and by concentration — portfolio level only, never a
  schedule re-served (CEDE-152, ADR-0044). Neither of the last two is metered.
* **Package is live on two slices** (CEDE-150, ADR-0043): `POST
  /objects/{id}/package` assembles a submission pack from the runs already in
  an object's provenance and `GET /packages/{id}` serves it back, every
  document watermarked draft. It computes nothing and is not metered. The
  draft slip SPEC §3.7 names **is now a fourth document in that pack**, landed
  at 2026-08-15T08:58Z by CEDE-165 (merged `58cb0e4`): parties, period,
  jurisdiction, financial structure, trigger and the technical premium
  restated as analytical output, every line drawn from the risk object and
  none of it computed. It carries the draft watermark on the document itself,
  and it adds no signature, acceptance or execution surface — a slip lifted out
  of the pack and read alone still says on its face that it is a draft nobody
  has agreed to.
* **Monitor is live on both of its slices, the second as of 2026-08-15.**
  The record came first (CEDE-151, merged `1f00014` at 2026-08-15T05:29Z,
  ADR-0046): a structure is recorded as in force — the account holder's own
  assertion about a transaction executed entirely outside Cede — and read
  against the newest pinned snapshot, with the index value and the distance to
  attachment on every read. **Webhooks are no longer absent**: they merged at
  2026-08-15T11:50:35Z (CEDE-166, `3d3214a`, ADR-0050), so `POST
  /monitoring/{id}/webhooks` registers an address and `GET
  /monitoring/{id}/webhooks` reads back every registration with its own
  delivery log. Two things about that landing are worth stating rather than
  assuming: delivery is at-least-once and the log is what makes a missed
  delivery visible instead of silent, and there is still no scheduler in this
  build — ADR-0050 carries ADR-0046's newest-snapshot rule forward to deltas, so
  a delivery goes out when a read recomputes the measurement and finds it has
  moved, not on a clock nobody has built. Any page that describes Monitor says
  measurement, never determination: Cede reports what it measured and nothing
  that follows from it, and ADR-0050 was written against exactly the pressure a
  pushed message attracts.
* **All seven verbs SPEC names now have an address**, as of `1f00014` on
  2026-08-15 — each on the slice named above and no wider than that: the slices
  are what this plan may claim, never the verb entire, and no page this plan
  produces may say otherwise. Both of the absences the 2026-08-14 edition
  carried closed on 2026-08-15, hours apart: Package's draft slip landed at 08:58Z
  (CEDE-165, `58cb0e4`) and Monitor's webhooks at 11:50:35Z (CEDE-166,
  `3d3214a`). That is not the same as the verbs being finished — a slice is
  narrower than a verb, and it is the slice that gets named wherever a verb
  does. There is a warning here about this page's own shelf life too, and it
  has now been demonstrated twice in one day: the 2026-08-15 edition was
  drafted before lunch, one of its absences closed after the draft, and by the
  afternoon its board was a check out of date as well — which is why this
  edition exists. A reader working from it re-reads `BACKLOG.md` and
  `checks/history.log` before repeating any of it, rather than trusting the
  date at the top.
* **Three reader surfaces exist**: the specification page (`site/`, served on
  the tailnet since 2026-08-11 per BLOCKED_OPERATOR item 16), the browser
  playground (`site/playground/`) and the workbench (`site/workbench/`), with
  `docs_url` set in `cede.config.json`.
* **The ingest oracle is 16 real-world-cursed files carrying 138 declared
  rows**, append-only by specification. Those two numbers are computed from
  `corpus/manifest.d/*.yaml` by `tests/unit/test_honesty_exhibit.py`, which
  re-renders `docs/ingest-honesty.md` and fails if either has moved.
* **Nothing is reachable from the open internet.** `prod_host` is still null
  in `cede.config.json`; no domain, no DNS (BLOCKED_OPERATOR items 3, 5, 6).
  The terms are no longer part of that list: item 8 is ✅ DONE 2026-08-18, the
  operator supplied every reserved value, and CEDE-226 took the draft label off
  `docs/terms.md` and `docs/acceptable-use.md` — so what is left between here
  and the open internet is a host, a domain and DNS, not a legal gap. Nothing
  this fleet has built has ever been shown to a person
  outside the operator's tailnet.
* **The commercial plumbing is landed, not half-landed**: usage metering
  (CEDE-071, `52e0e36`) and the Stripe test-mode lifecycle (CEDE-072,
  `7c21ca1`) are both merged. This plan sequences on those two items and
  deliberately restates neither.
* **Phase 2's entry gate reads one of three on the newest measurement each
  of its checks has, and it went down without anybody deciding anything.**
  Read on the newest line each gate
  check has, which is what the gate asks for: condition 1 does **not** hold —
  `2026-08-25T05:09:14Z PROD-01 FAIL`; condition 2 does **not** hold —
  `2026-08-25T05:16:29Z PROD-12 FAIL`; condition 3 holds, GTM-05 is ticked and
  the brief is written. **Both failures are the walk agent's expired
  credential**, diagnosed in the standing-reds bullet above out of each red's
  own retained sandbox, so what this gate is short of is a *measurement*, not
  a working product: the last time either walk ran it passed, on
  `2026-08-20T08:01:34Z PROD-01 PASS` in 61.3 s and
  `2026-08-19T05:27:16Z PROD-12 PASS` in 88.1 s. The gate is nonetheless down,
  and this page does not soften that — a gate that asks whether a fresh reader
  can do these things is not satisfied by an argument that they probably could.
  The gate has read every way
  before and no reading was wrong when it was made: on 2026-08-16 that
  morning's sweep put condition 2 down on
  `2026-08-16T07:43:21Z PROD-12 FAIL`, and CEDE-196's merge (`c23b832`,
  10:53:43Z) put it back up with no act of the operator's in between; the
  2026-08-17 sweep read three of three on a single day's evidence; on
  2026-08-18 it went down at 05:14:33Z and back up at 05:30:24Z, inside the
  same half-hour; 2026-08-19 read three of three again; and from 2026-08-21 it
  has read one of three every day. The
  gate itself has never moved; the measurements under it do. The gap CEDE-139
  found was that nobody had told the operator; since 2026-08-14 the gate's
  three conditions, each with the command that re-checks it and its dated
  evidence, are written into
  **BLOCKED_OPERATOR item 18**, so what Phase 2 is waiting on is readable from
  that item alone — and that item now carries these two reds, names their
  cause, and points at item 21 as the act that lifts them.
* **Phase 4's entry gate reads one of two, and the half that holds is the
  check.** The gate asks for both: (1) `bash checks/production.sh --only
  PROD-08` PASSes, and (2) BLOCKED_OPERATOR item 7 is DONE. Condition 1 holds
  on the newest line the check has — `2026-08-25T05:15:05Z PROD-08 PASS` —
  the full billing lifecycle
  green in Stripe test mode: free sandbox at signup, five metered units
  invoiced exactly, a test-mode payment, and cancellation stopping metering.
  Condition 2 does not hold. **The two conditions are not the same credential
  and this page does not let them blur**: item 19, the staging *test-mode* key,
  is ✅ DONE 2026-08-18 and is what made condition 1 measurable at all; item 7
  is the KYC'd Stripe account itself and is still open, with no DONE line in
  `BLOCKED_OPERATOR.md`. So GTM-20 stays unticked — its evidence clause asks
  for both halves and only one of them exists — and nothing on this page ticks
  or unticks it. Nothing in Phase 4 is startable on the strength of condition 1
  alone, and no session may approach item 9's switch under any reading of
  either.

Ten of the twelve production checks are green at their latest run, the two that
are not could not be measured at all, and none of
it is reachable by name, so this product still does not have a distribution
problem; it has an evidence problem — and for six days it has had a narrower
one, which is that it could not take its own measurements. So Phase 1 produces receipts, not reach,
and every later phase is gated on receipts that already exist — including this
section, which is now a receipt rather than a recollection.

---

## Who it is for

Three segments, most-likely-first. The reasoning matters more than the order —
the order is a consequence of it.

**A. Parametric program designers at MGAs and program managers.**
First, because their job *is* the four verbs that are already live: take a
schedule nobody can read, define a trigger, run it across forty years, and get
a technical price with its assumptions on the face of it. Nothing in that
sentence needs analyse, monitor or package, so this segment can get real value
from the product as it stands today rather than as it stands after two more
quarters. They are also the persona the nightly QA cohort already imitates, so
the gaps they would hit are being found and filed every night by a synthetic
version of them — the cheapest possible form of discovery, and the only demand
signal this fleet is permitted to have.

**B. ILS and ILW analysts.**
Second, because they are the segment most likely to punish a number that
arrives without its assumptions — which is exactly the discipline the product
already enforces in code. Determinism against pinned snapshots, results that
replay byte for byte, a backtest that discloses thin data years instead of
silently interpolating them: these are table stakes to this audience and are
rare enough elsewhere to be worth naming. Smaller population than A, higher
standards, slower to arrive, and the best possible reviewers of the registry.

**C. Insurtech and platform engineers embedding risk analytics.**
Third by revenue proximity, first by distribution. Engineers adopt a *format*
long before they adopt a vendor: the canonical object's schema is open source
and consumable with no account at all (SPEC §5.4, §6), so this segment can be
served completely without a commercial relationship. Every team that
normalises to the canonical object is a path back to segments A and B, and the
schema repo is the only channel in this plan that costs nothing to run and
never goes stale.

**Deliberately not targeted in the first edition**, with the reasoning stated
so a later session can overturn it on evidence rather than taste:

* *Corporate risk teams and captives.* BRIEF.md names them as users and they
  are; but their evaluation runs through procurement and their brokers, and
  SPEC §1 forbids human-in-the-loop delivery. A free sandbox is not how that
  buyer starts. Revisit in Phase 4, when there is a metered account to point
  at.
* *Carriers and brokers who want execution.* What this audience asks for next
  is on the far side of BRIEF.md's perimeter. They are not a segment; they are
  a source of requests the product declines, and every surface this plan
  produces should decline them clearly enough that the conversation ends
  early.

---

## Positioning

**The sentence, which is already the site's: a file format for risk.** One
canonical object; an engine of verbs over it; an open registry of validated
models and feeds. You bring the paper — the product is software, and stays
software.

Three proofs carry that sentence, all of them artifacts rather than adjectives:

1. **The cursed corpus.** Ingest is measured against real-world-ugly files —
   merged cells, header drift, mixed encodings, ambiguous units — as an
   append-only oracle that must pass at 100% or no merge happens. The
   statement "we read the files you actually have" is not a promise here; it
   is a test run count anyone can read.
2. **Assumptions on the face of every number.** A technical price carries its
   model versions, data vintages, event set, loadings and currency basis as
   first-class response fields, and ingest records every guess it made in
   `source_fidelity` rather than dropping it silently. The honest disclosure
   *is* the product.
3. **Replay.** Models are deterministic against pinned snapshots, results
   replay byte for byte, and CI re-validates every published model on every
   build. A result that cannot be reproduced is treated here as a defect, not
   a caveat.

**What this plan never writes.** No social proof before it exists: no invented
case studies, no logo wall, no user counts, no praise attributed to somebody
who never said it (ADR-0021 constraint 2). Until real users exist, the
material is the product's own receipts — run ids, the playground walk, corpus
counts, the disclosure lines, this repo's own honest red checks. That is not a
restriction the plan works around: it *is* the position. The pitch is that
this product does not overstate, and a page that overstates refutes the pitch
in one line. Earning real proof — design partners, recorded permission,
written-up walks — is legitimate work and appears below as owner-tagged
actions.

**The perimeter.** BRIEF.md's perimeter governs every line of this plan and
every surface it spawns, exactly as it governs product copy: a landing page
and a launch post are product copy. No file or directory this plan creates is
exempt from the scanner — `docs/GTM.md` is itself in scanned scope, and
`bash checks/gate.sh` is the proof. Where a page needs a disclaimer line, it
reuses one of the reviewed lines already in `checks/perimeter-allow.txt`
verbatim rather than inventing a new phrasing that has never been reviewed.

---

## The phase sequence

Four phases, gated on evidence and never on dates (BACKLOG standing rule).
Each phase states its entry gate as a check somebody can run.

The hard rule, from ADR-0021 constraint 3: **no public-launch action may
begin before all three of — the PROD board green, terms approved by the
operator, and a production host.** They are the entry gate to Phase 3, stated
there as three runnable checks. Phases 1 and 2 are deliberately shaped so that
all the work which does not require them happens first, and the fleet is never
waiting.

| Phase | Name | What leaves this machine |
|---|---|---|
| 1 | Receipts | nothing |
| 2 | Named evaluation | nothing; named people are brought to the tailnet |
| 3 | Public availability | the product, on a real name |
| 4 | Metered commercial motion | invoices, in test mode until item 9 |

---

## Phase 1 — Receipts

**Entry gate.** None. This phase is the present state and is open now.

The purpose is to make the three proofs above *legible to a stranger* without
anything leaving this machine. The channels in this phase are all ones the
fleet already controls: the specification page, the docs site, the playground,
and the open schema. No external channel is touched, so nothing here waits on
the operator.

Exit condition: everything in Phase 2's entry gate is satisfiable.

- [x] GTM-01 [owner:fleet] State the segment sentence and the three proofs on the specification page, in the page's own voice — evidence: `site/index.html` carries all three proof headings and `bash checks/gate.sh` exits 0 with `site/` in scanned scope
- [x] GTM-02 [owner:fleet] Publish a receipts walkthrough: one real run, its assumptions, its data vintages, and the re-run that reproduces it byte for byte — evidence: a page under `docs/` whose commands `make docs` executes against staging on every build
- [x] GTM-03 [owner:fleet] Make the open schema usable as a channel: a page showing how to consume the published schema with no account, versioned and linkable — evidence: the page resolves the published schema version the API declares, and `make docs` executes its example
- [x] GTM-04 [owner:fleet] Publish the two onboarding walk timings as measured numbers, refreshed from the harnesses rather than typed by hand — evidence: `docs/walk-timings.md` is rendered from `checks/walk-timings.log` — the append-only record the PROD-01 and PROD-12 harnesses append each completed walk's elapsed seconds to — and `tests/unit/test_walk_timings.py` fails if the committed page differs from what the committed record renders
- [x] GTM-05 [owner:fleet] Draft the one-page design-partner brief the operator will send, with no social proof in it and a stated ask — evidence: `docs/gtm/design-partner-brief.md` exists, names the three segments, and the gate stays green with it in scanned scope
- [x] GTM-06 [owner:fleet] Publish the honesty exhibit: what ingest survives, what it flags, and what it refuses, with counts read from the corpus manifests — evidence: the page's counts are computed from `corpus/manifest.d/*.yaml` by a committed test, not restated by hand

---

## Phase 2 — Named evaluation

**Entry gate.** All three, each a runnable check:

1. `bash checks/production.sh --only PROD-01` PASSes — a fresh session goes
   from signup to a first authenticated call in under ten minutes on public
   docs alone;
2. `bash checks/production.sh --only PROD-12` PASSes — a fresh session
   composes a model, backtests it, and prices with it in under fifteen
   minutes;
3. GTM-05 is ticked — there is a brief to send.

Nothing in this phase is public. Named people are brought onto the operator's
tailnet, one at a time, and the only channel is the operator's own existing
relationships — no posting, no accounts, no lists. The point of the phase is
not revenue and not references: it is to find out which of the three segments
returns a second time without being asked, because that answer re-ranks
everything below it.

Exit condition: at least two named evaluators have completed a real job
through public interfaces alone, and their gaps are BACKLOG items.

- [ ] GTM-07 [owner:operator] Introduce the design-partner brief to at least three named candidates across segments A and B — evidence: BLOCKED_OPERATOR item 18 records three names with dates
- [ ] GTM-08 [owner:fleet] Turn each named evaluator's real job into a nightly QA cohort persona so it is re-run every night, not once — evidence: `supervisor/personas/` gains one persona file per recorded job and the nightly cohort run includes it
- [ ] GTM-09 [owner:fleet] Keep an evaluation log and file every reported gap as a BACKLOG item within one supervisor tick — evidence: every gap in `docs/gtm/evaluation-log.md` has a BACKLOG item tagged `[source:design-partner]`, asserted by a committed test
- [ ] GTM-10 [owner:operator] Record written permission before any evaluator's name, logo or result appears on a page — evidence: BLOCKED_OPERATOR item 18 carries a dated permission line per name, and no page names anybody without one

---

## Phase 3 — Public availability

**Entry gate — the constraint-3 gate, all three required.** No action in this
phase that exposes anything to the open internet may begin before every one of
these is true:

1. **The PROD board is green:** `bash checks/production.sh --done` exits 0 —
   which by PRODUCTION.md's own DONE rule means every PROD-NN has been green
   for seven consecutive days. The weaker reading (all twelve green once) was
   considered and rejected: a launch is the least reversible thing this fleet
   can do, and a single green day is exactly the evidence a flake produces.
2. **Terms exist:** BLOCKED_OPERATOR item 8 is marked DONE by the operator and
   the signup surface no longer labels its terms as a draft pending review.
3. **A production host exists:** `prod_host` is non-null in
   `cede.config.json`, with the domain and DNS behind it (BLOCKED_OPERATOR
   items 5 and 6).

**Two actions here sit deliberately in front of that gate, and must.** GTM-14
drafts the terms and GTM-17 drafts the launch note and the posts. Neither
exposes anything — both produce files in this repo and stop. Gating them on
the gate would deadlock the phase: BLOCKED_OPERATOR item 8 asks the fleet to
draft terms *so that* the operator can approve them, and approved terms are
gate condition 2. Constraint 3 governs public-launch actions; drafting and
staging are what the fleet does while waiting for one.

Channels in this phase, in the order they earn their keep: the public schema
repo (free, permanent, and the only one aimed at segment C); the docs site on
a real name; and at most three practitioner or developer communities the
operator names before posting. No paid acquisition at all — there is no budget
for it under BRIEF.md's cost ceiling, and a channel the fleet cannot measure
from its own logs is a channel this plan will not defend.

Exit condition: a stranger with no introduction completes the ten-minute walk
on the public name, and the fleet can see them do it in the request log.

- [ ] GTM-11 [owner:operator] Provide the production host (BLOCKED_OPERATOR item 3) — evidence: `prod_host` is non-null in `cede.config.json` and the deploy pipeline promotes to it
- [ ] GTM-12 [owner:operator] Purchase the domain (BLOCKED_OPERATOR item 5) — evidence: the domain is recorded in that item with a date and appears in the deploy config
- [ ] GTM-13 [owner:operator] Point DNS at the API, docs and landing hosts (BLOCKED_OPERATOR item 6) — evidence: the public names resolve from outside the tailnet and the deploy config names them
- [x] GTM-14 [owner:fleet] Draft terms of service and an acceptable-use page for the operator to review, both inside BRIEF.md's perimeter — evidence: `docs/terms.md` and `docs/acceptable-use.md` are committed and BLOCKED_OPERATOR item 8 is updated to ready-for-review (ticked 2026-08-13 by the planner: both pages merged in CEDE-109 `c66a50c`, item 8 reads READY FOR REVIEW 2026-08-13)
- [x] GTM-15 [owner:operator] Approve the terms (BLOCKED_OPERATOR item 8) — evidence: that item is marked DONE with a date and the terms pages drop their draft label (ticked 2026-08-18 by the test-amender: BLOCKED_OPERATOR item 8 reads '8. Terms of service sign-off — DONE 2026-08-18' and records a value for every reserved decision; CEDE-226 transcribed those values into `docs/terms.md` and `docs/acceptable-use.md` and dropped the DRAFT label from both, with `tests/unit/test_terms_pages.py` amended under `adr/ADR-0062-test-amendment-terms-pages-approved-state.md` to assert the approved state. Measured on the two pages, not on the signup path: this clause used to read 'the signup surface drops its draft label', while the label lived on the two terms pages alone — `docs/quickstart.md` and `POST /signup` link neither page, which is unfiled wiring this tick does not assert)
- [ ] GTM-16 [owner:fleet] Prove the cold-start walk on the public name, not on staging — evidence: `bash checks/production.sh --only PROD-01` PASSes with the base URL set to the public name
- [x] GTM-17 [owner:fleet] Draft the launch note and the community posts and stage them in-repo, unpublished — evidence: `docs/gtm/launch/` holds one file per destination and `bash checks/gate.sh` exits 0 with them in scanned scope (ticked 2026-08-14 by the planner: CEDE-141 merged `de89f52` staging launch-note.md plus three destination posts, corrected to the five-verb truth by CEDE-146 `eb7f95e`, gate green as of 2026-08-14T13:38:01Z)
- [ ] GTM-18 [owner:operator] Publish the staged launch note and posts to the named destinations (BLOCKED_OPERATOR item 18) — evidence: that item records each destination with the date it was posted

---

## Phase 4 — Metered commercial motion

**Entry gate.** Both:

1. `bash checks/production.sh --only PROD-08` PASSes — the full billing
   lifecycle is green in test mode, which is CEDE-072's acceptance, not this
   plan's;
2. BLOCKED_OPERATOR item 7 is DONE, so test-mode keys exist where the deploy
   config expects them.

This phase deliberately contains no metering or billing design. Usage metering
is CEDE-071 (merged) and the test-mode lifecycle is CEDE-072; restating either
here would create a second place for them to be true, which is how two files
start disagreeing. What belongs here is only the *commercial motion* on top of
them: saying the price basis out loud, in public, sourced from the meter.

Real charges are the operator's alone (BLOCKED_OPERATOR item 9), and no
session may approach that switch.

Exit condition: an account can sign up, use the product, and see a correct
metered invoice without anybody being asked anything.

- [x] GTM-19 [owner:fleet] Publish the metered price basis — per object and per model run — sourced from the billable-unit table rather than retyped — evidence: a committed test asserts the page's units equal the billable units in the product's usage module (ticked 2026-08-16 by CEDE-204: the units have been published since CEDE-072 in `docs/quickstart.md` and this page's verb-to-unit table since CEDE-084 `0c2201c`; `tests/unit/test_billing_page_basis.py` now holds that table against `cede.api.usage.BILLABLE_UNITS` and `UNIT_BY_VERB`, in the unit gate)
- [ ] GTM-20 [owner:operator] Complete Stripe onboarding and place restricted test-mode keys (BLOCKED_OPERATOR item 7) — evidence: that item is marked DONE and `--only PROD-08` PASSes against staging
- [x] GTM-21 [owner:fleet] Publish a reconciliation exhibit: metered usage in, invoice quantities out, equal to the unit — evidence: the exhibit's numbers come from a recorded test-mode run that CI replays with no network and no key (ticked 2026-08-16 by CEDE-208: `docs/gtm/reconciliation.md` publishes the per-unit table and `tests/integration/test_reconciliation_exhibit.py` recomputes every figure on it from the run `tests/integration/test_billing_lifecycle.py` replays, in the integration gate)
- [ ] GTM-22 [owner:operator] Flip the real-money switch (BLOCKED_OPERATOR item 9) — evidence: that item records the flip with a date, and until then every charge is test mode

---

## What would make a later session re-cut this plan

Stated up front so a re-cut reads as evidence, not as a change of mind:

* **Segment order.** If Phase 2's evaluators from segment B return more
  reliably than segment A's, the order above is wrong and the channel actions
  in Phase 3 should follow the returners. That is a measurement, not a
  discussion.
* **The schema-as-channel bet.** If GTM-03 lands and nobody consumes the
  published schema for a month after Phase 3 opens, segment C is a distribution
  theory that did not survive contact, and the effort belongs in the docs site
  instead.
* **The Phase 3 gate.** The seven-day reading of "the PROD board is green" is
  the strictest honest one. It can only be loosened by a later ADR that argues
  it, never by a session in a hurry — and PRODUCTION.md would have to change
  first.
* **A public source of demand.** Today the nightly cohort is the only demand
  signal this fleet is permitted to have (BRIEF.md). The moment real users
  exist, their behaviour outranks every assertion on this page, including the
  segment reasoning.
