💳 Fund Autonomy Ledgernot signed in🔑 Sign in

Milestones

One sequence, many tracks. You build before you sell — but every track is running right now, and they feed each other.

Specification
88% · 10% unmeasured
Execution
82% · 10% unmeasured
Market
44% · 0% unmeasured
■ Is it written down precisely enough to build and to argue? · 88% passing · 2% declared, not yet · 10% unmeasured■ Does the code exist, run, and hold under a guard? · 82% passing · 8% declared, not yet · 10% unmeasured■ Has it left the building — pitched, landed, paid? · 44% passing · 56% declared, not yet · 0% unmeasured

106 milestones · one sequence · 10 lists · 99 open checks · commit 3e51452fe6
Numbers and ranks are derived from position, never typed. Every bar is a bounded shell predicate — open any line to see which check failed and which file to go edit. No model in this path. Recompute: node scripts/milestones/score.mjs

You have the semantics. Where are the results?

Everyone running agents has the semantics now. The spec, the prompt, the plan, and a model that explains its own work in better prose than the person who asked for it. That work is real, and it answers the question of what was meant.

It does not answer the question both sides of the table ask next. The builder asks it about speed and the writer asks it about loss, and the question is the same four words. Here is what one record says to each of them, with the zeros left in.

Go fast — the builder's side

You want to clear the context whenever it gets heavy and have the agent pick up exactly where the work was.

not run

not run

not run

Your move: meter five of your own goals. Five goals is a larger sample than ours.

.thetacog/vna-token-meter.json · not run

Underwrite and supervise — the writer's side

You want a count you can price, kept on a record the agent did not write.

not run

not run

Your move: name the loss definition you would accept. The first thirty rows get written against it, and whoever sets that definition sets the unit.

data/vna/parametric-trigger.json · data/vna/severity-status.json · not run

One install, two columns. Both are computed by scripts over records the agent did not author, and each carries the date it was read. not run data/vna/licence-funnel.json · not run
The landfall ledger. Every commit since 2026-09-28 either names the landfall it shortens — a stranger buys a licence, a carrier prices it — or says none. not run data/vna/landfall-count.json · not run
None of this is ours

These vouch for the market, not for our number: cover withdrawn, a peril named, a duty dated. Our number still has to stand on the receipts above.

January 2026: ISO's generative-AI exclusions for commercial general liability, CG 40 47, CG 40 48 and CG 35 08, filed by more than sixty P&C groups. The existing cover withdrew by form, not by argument.

10 February 2026: Armilla and Chaucer's Vanguard AI names autonomous agent failure as a covered peril, at $25M limits. armilla.ai

The EU Digital Omnibus moved Annex III high-risk duties to 2 December 2027 and Annex I to 2 August 2028, with deployer log retention alongside. The date moved; the duty to reconstruct a decision did not.

What does not exist yet: an outside party recomputing one of our receipts. That is the next zero on the board, and it is the one that turns the rest of this page from our account into theirs.

Three zeros, in the order they close. The fleet saving, which is ours to meter. The loss definition, which is a writer's to name. An outside recompute, which is anyone's. A unit gets written around the first definitions someone else can price, so whoever closes the second or the third is the reference the next buyer's form cites.

Z1 fleet token saving → C363Z2 loss rows against a named definition → C364Z3 outside recompute → C365Z4 licences bought by anyone but us → C317

1 Why the agent's own log cannot stand in for the count: an account of a process, produced by that process, cannot contain what the process displaced (the data processing inequality). Whether the work was good is undecidable (Rice, 1953); where it landed is not. 2 k_E = 0.003: 0.3 bits per boundary crossing, the irreducible cost of confirming a decision was made; trust half-life = ln(2)/k_E ≈ 231 boundary crossings.

Read this board as a briefing, not a backlog. An exponential is a foam knife in the kidney: it looks like an empty horizon for the whole round and then it is in your back while you are still swinging at the archer. The measurement is the bow — free, and it cannot win alone; it buys fifteen seconds of the heavies looking the wrong way. Every line below is where the kidney is and when to run, agreed before the whistle, because nobody can shout it across the field once the round has started. The field, in full.

The route to a trillion — what the tracks below are for

Authored, not scored. Every number in this section is typed — sourced externally with a date, or computed by the live model. The bars further down are bounded shell predicates and these are not. Do not read a forecast as a measurement. Open the model — every assumption is a slider →
The market's monologue — our own milestones, in sequence, read back to us

Ground. I left in January. I did not argue with you about it — I wrote three endorsements, filed them in sixty places, and by spring the cover was gone. You were busy at the same time and I will be fair about what you did: you Prove execution bounds, you Pin canonical terms, you Convert seven provisionals, you Define uncovered risks. Every one is written down and every one runs. I have seen none of it. You even Identify lead syndicates — you know exactly who I am. I still do not know who you are.

Instrument. You Standardize policy terms, Map underwriter objections, Provoke market friction — those reached me, and I will grant you all three. Then you Isolate true anomalies, Eliminate edge cases, Force cold recomputes, and each is a finished instrument with a zero beside it in the only column I read. Collect pilot revenue: built, zero. Secure pilot LOI: not even written down.

Prove. Here is what I actually need and cannot get. Price expected loss — you have it, I have not seen it. Cap worst case — the same. Validate parametric triggers, the one thing that would let me write a rate, sitting at zero. Ingest live telemetry has no market score at all; you have not even claimed it left.

Bind. Bind first policy is full on spec, full on exec, nothing on market. You built the thing that binds and never bound it. Lock trust root and Block the workaround have the same shape. Fire first rung — the ask itself — is specified and not fired.

Syndicate. And then the far end, where Distribute syndicate asset, Mint insured licenses and Charge per agent wait on a signature the sequence above never went to collect.

Now read down my column. Your spec averages 98% and your exec averages 91%. Mine averages 44%, with 50 zeros in it, and it is the only column I can see. 31 of your milestones are perfect twice and blank once.

And here is the part to sit with. What did leave the building? Curate reader cohort. Dispatch private invites. Collect ghost reads. Provoke market friction. Map underwriter objections. Reach named counterparties. You ship conversation reliably and hold the instruments back. I am not waiting for you to build anything. I am waiting for you to hand me one thing you already have.

Two instruments, one finding. The sizing model concludes that realisation is the only rate we control and that we are supply-constrained on our own execution rather than by the market. This board reaches the same verdict by a completely different route — bounded shell predicates over declared evidence, no forecast anywhere in it. A model agreeing with itself proves nothing; a model agreeing with a measurement it never touched is the closest thing to corroboration a plan like this can get.
From here to a trillion

In January the insurance industry stopped covering AI. Not by argument — by paperwork. ISO published three endorsements, sixty-odd groups filed to adopt them, most were approved inside a quarter, and one carrier wrote an exclusion broad enough to cover any alleged use of artificial intelligence at all. Nobody announced it. It simply became true, one renewal at a time.

What is supposed to replace it is about five products worldwide.

That gap will not close on its own, and the reason is narrow enough to say once: an underwriter cannot price what it cannot count, and there is nothing here to count. An agent's own log is not a count. It is the account of a process, written by that process, and it cannot contain what the process displaced. So the market has a peril it has named, capital that wants to write it, and no unit.

We make the unit. It is free to run, and the licence attaches only when an agent goes into production.

But nobody adopts a unit because it is correct. They adopt it because it saves them something — and this is where the story either starts moving or does not. If the gate catches a run that has gone off-lane before you pay to finish it, then installing it is arithmetic rather than governance. That claim is currently unmeasured. Measuring it is cheap, it runs on our own fleet, and it comes before any sale, because a tipping mechanism nobody has tested is not a plan.

If it does save tokens, adoption stops being a sale at all. It becomes a tool spreading at the speed a developer installs things — a Tuesday afternoon instead of a procurement cycle. That difference is most of the timeline: about seven months against the same curve sold as compliance.

Then the receipts exist. A few thousand of them, from two to five accounts — one trading desk, one fraud engine. Small enough to name, and sufficient for exactly one thing: a writer can now rate against something real. That is R1, the only gate we own, and it turns on credibility rather than market conditions, which makes it a hiring problem wearing a sales problem's clothes.

Then someone who is not us certifies the specification, and it stops being our product.

Then procurement carries it, because a vendor whose deals stall integrates whether or not they find the mathematics interesting.

And the volume was never the question. Agents per worker and attested todos per agent both compound in double digits monthly — measured, not hoped. If they do not, the eight hundred billion dollars being spent this year on the assumption that they will is the larger mistake, and we are a rounding error inside someone else's.

The discipline is the whole point: each link is sufficient for the next one and for nothing further. The token measurement says an engineer should install it — not that a carrier will rate against it. Two thousand agents say receipts exist — not that the market moved. R1 says the unit is ratable — not that it is the standard. Certification says it is a standard — not that anyone uses it. Every failure this plan can have is the same failure: a link claimed as sufficient for something further down the chain than it actually reaches.

The thesis — an entailment, not a forecast

It is entirely a function of whether the agentic economy works at all. If it works, it grows at the rates below. If it grows at those rates, it cannot happen without attestation — there is no other way to get double-entry into the mix, and a second record requires a meter the actor did not write.

The motoring parallel runs opposite to how this is usually pitched. Cars did not reach the roads because cars got better; they reached the roads when the liability became bearable. But the sharper half is not the insurance — it is the driving licence. You can be a citizen, or a citizen who holds a licence, and the licence is a higher grade of standing because it grants a capability rather than permission to exist. Nobody experiences it as paperwork; they experience it as the thing that lets them work as a driver.

That is what we sell, and it is the same word for the same reason — priced like a licence too: $20/year against ~$10,000 of delegated authority, two tenths of one percent. Attestation is not friction on the agentic economy; it is the licence that lets an operator harvest value faster, and that is how the highway gets built. The failure case is not a smaller market — it is the agentic economy not working at all, in which case the capital already spent on it was the far larger mistake.

The slack — this is not the ideal case

The model's default sits on capex-priced market rates, deliberately backed off from the observed outliers. Those outliers are real measurements, and if the market runs at its own top end the crossing moves nine months. Closing that gap is what every track on this page is for.

Floor14 %/moT−33 · May 2029every driver at its lowest observed rate, late tip
Market35 %/moT−17 · Jan 2028capex-priced — the model’s current default
Fast54 %/moT−12 · Aug 2027top of observed, tip pulled to T−12
Ideal84 %/moT−8 · Apr 2027the market acts like its own outliers
Cars-on-road104 %/moT−7 · Mar 2027licence and cover tip the social contract at once
Nine months of slack, and the top of the range is not our optimism. It is already priced into somebody else's balance sheet — roughly $775–800B of 2026 capital expenditure and the valuations resting on it are underwritten by exactly these rates. A reader who calls the ideal case aggressive is not disagreeing with us; they are disagreeing with the capex, which is a much larger position to hold.
The anatomy — four numbers, and three are not about us

Attack these and the page falls. Everything else is arithmetic. Rates are monthly; the range in brackets is what the market has actually been observed doing.

% of all workers6 %/mo[observed 3.1 – 18.9]
share of a 3.5B workforce supervising attesting agents; anchor 7% = 245M
falsifier: survey which job functions run agents · countable today
agents per worker12 %/mo[observed 3.1 – 30.8]
anchor 1.5. States and employees blend into one supervisor population
falsifier: deployment counts per org · countable today
todos per agent/day14 %/mo[observed 6.8 – 30.8]
anchor 100/day; this repo measures 56/day on one coding agent
falsifier: count boundary crossings on any agent · countable today
realisationtips, not ramps[no market data]
a free open-source install that saves tokens saturates rather than ramps — ours alone, and the only one that can stay zero
falsifier: the registry counts licensed agents · ours to report
Why it saturates instead of ramping — and why that is the lever

Growing our share at a monthly rate is a SaaS shape: seat by seat, bounded by how many people we can sell to. Wrong curve. The install is free and open source — one npx, MIT, nothing to procure — and the licence attaches only to production use. Things shaped like that tip, then saturate.

And the tipping mechanism is capability, not compliance. If the drift gate saves you tokens — catching a run that has gone off-lane before you pay to finish it — it is not a governance purchase, it is a performance one, adopted on a Tuesday afternoon without asking anyone. Tool speed against committee speed is most of the timeline: tipping rather than ramping is worth about seven months, and when it tips is worth years while how fast it then spreads is worth weeks.

Which makes the cheapest experiment on this page the most valuable one: measure whether the gate actually saves tokens on real runs. If it does not, the tipping mechanism reverts to a slow compliance sale and the honest curve is the SaaS ramp — seven months later. That test runs on this repository.

Who needs to see this, in order — and who must not

Ordered by dependency, not by how much we want the meeting. Each room carries the same phase and track coordinates as the legs below. The wrong room reading this is a cost, not a neutral event — so every entry names what it sees and what sending it risks.

1 · The crew — contributors and fellowsSEND NOWB Instrument🎯 pitch

The rate-limiting input to every curve on this page. R1 is gated on credibility, and credibility is people. Every other room below needs someone in it who can be the most rigorous person present.

Sees: The whole model, openly — it is the most honest recruiting artifact we have, because it shows the size and writes down its own failure modes on the same page.

Risk: Almost none. This is the one room where density filters correctly rather than repelling.

2 · Ourselves — the token-saving measurementSEND NOWB Instrument⚙️ technical

Before the model is shown to anyone who buys, the capability claim underneath the tipping point has to be measured. Selling a tipping mechanism we have not tested is the fastest way to lose the rooms below.

Sees: Nothing to send. A number to produce, on this repository, in either direction.

Risk: The risk is skipping it and discovering the answer in front of a counterparty.

3 · Kinetic buyers — trading desks, fraud engines, ad-tech routersSEND NOWB Instrument💰 commercial

Rung 1, and the only room that buys on arithmetic today with no mandate: one unverified agentic loop costs more than a year of licences. They produce the receipts R1 needs to rate against.

Sees: Not this document. The token-saving number and the 0.2%-of-authority ratio — a page, not a model.

Risk: Sending the trillion model here reads as a vendor pitching a category instead of an engineer offering a measurement. It loses the room by changing the subject.

4 · Affirmative writers — Armilla, Chaucer, the ~5 worldwideSEND NOWC Prove📮 contact

R1 itself. They are the counterparties actually starving for a ratable, recomputable unit — they wrote the peril and have nothing precise to price it against.

Sees: The exclusion research, the five-products gap, and the recomputable unit. The trillion is context, never the ask.

Risk: Leading with the market size implies we want their market. Leading with the gap implies we solve their problem. Same document, opposite outcome.

5 · A policy-body chair — insurance and pensionsSEND NOWC Prove📮 contactNAME WITHHELD

A policy seat who reached the insurance-of-AI thesis independently and unprompted, in a room we did not convene. The one reader likely to check the ISO endorsement numbers himself — and find them right.

Sees: The researched market basis first, the model second. He is explicitly anti-GenAI-hype, so the exclusions and the deferral carry it, not the curve.

Risk: Leading with a trillion-dollar TAM against a hype-allergic reader spends the strongest independent validator we have. Order is the whole risk here.

6 · A global practice head at a top-three brokerAFTER R1C Prove📮 contactNAME WITHHELD

Wrote the in-house verdict, which is a buy signal wearing a refusal — and that desk has clicked every book-club issue since late July. Attention engaged, commitment withheld. This model is precisely the artifact that answers "we are building it ourselves".

Sees: The in-house answer built on this model — the standard nobody builds alone — sent to him DIRECTLY, with the internal champion told it was.

Risk: Two: routing it around him to someone junior is a self-demotion he will read correctly; and sending before the token-saving number exists means answering a build-vs-buy argument with a forecast instead of a measurement.

7 · A reinsurer whose founding charter is inspectionDO NOT SENDD Bind📮 contactNAME WITHHELD

The single best structural fit in the market: their legal name contains the word INSPECTION, and the AI paper written under that charter has no inspection in it.

Sees: NOT this document. One question — does a decidable placement receipt qualify as an inspection in HSB’s own engineering sense? That desk has a 160-year answer and nobody else does.

Risk: A TAM model answers a question they did not ask and converts a 20-minute peer question into a vendor meeting. The ask ladder exists for a reason; rung 1 is the only rung said out loud.

8 · Institutional capital — lead syndicate, not generalist seedAFTER R1A Ground🎯 pitch

Funds the runway between now and the tip. Deliberately after R1, because the signature is the valuation: the same story is a different round once the carrier risk is retired.

Sees: The full model, including the political ceiling and every failure mode. Sophisticated capital reads written-down failure modes as rigour.

Risk: Handed to a generalist who evaluates on MAU and a TAM slide, the density causes retreat to pattern-matching. And every exposed slider is an argument a hostile reader can start — which is correct for a peer and fatal for a tourist.

9 · Syndicates, reinsurance, then regulatorsAFTER R1E Syndicate⚖️ legal

Last on purpose. The private market already moved without them — ISO in January, the EU deferring to 2027 — so leading with regulation would be selling a deadline that has just been pushed back.

Sees: The certified spec and the standard, once a third party holds the conformance criteria.

Risk: Arriving early makes us a supplicant to a process that has not started. Arriving after certification makes us the thing being standardised.

The legs, in the board's own coordinates
✓ CLOSED · Jan 2026 · not oursA Ground⚖️ legal· market
The market withdrew cover

ISO issued three generative-AI exclusions for commercial general liability — CG 40 47, CG 40 48, CG 35 08. More than 60 P&C groups filed; over 80% approved; several states took effect that January. Berkley filed an absolute exclusion across D&O, E&O and fiduciary. None of it is a forecast and none of it required us.

closed by CG 40 47 / CG 40 48 / CG 35 08 in force
✓ CLOSED · Feb 2026 · not oursA Ground📮 contact· market
An affirmative market exists to sell into

Armilla and Chaucer launched Vanguard AI on 10 February 2026 naming autonomous agent failure as a covered peril at $25M limits. Roughly five such products exist worldwide — the point, not a caveat: the counterparties who need a ratable unit are few enough to name on one page.

closed by a bound policy naming agent failure as the peril
NOW → Nov 2026 · pulls the tip forwardB Instrument⚙️ technical· exec
Measure the token saving on our own fleet

The tipping mechanism is capability, not compliance: if the gate saves tokens by catching a run that has gone off-lane before you pay to finish it, adoption moves at tool speed rather than committee speed. That claim is currently unmeasured, it is cheap to measure, and it gates everything downstream because it makes the kinetic sale arithmetic rather than rhetoric.

closes when a measured token delta on real runs is published, in either direction
NOW → Dec 2026 · the seedB Instrument💰 commercial· market
2,000 licensed kinetic agents

Two to five accounts, not a market — one algorithmic trading desk or one bank fraud engine runs this many always-on agents by itself. It matters less as revenue than as the reference that makes R1 possible: a writer cannot rate against receipts that do not exist.

closes when the registry counts 2,000 licensed agents in the kinetic tier
→ H1 2027 · the only gate we ownC Prove📮 contact· market
R1 — one writer rates against the receipt

Not a pilot and not an LOI: a carrier or syndicate prices, reserves and reinsures against the recomputable unit. Every leg below assumes it and none survive without it. Gated on credibility rather than market conditions, which makes it a hiring problem before it is a sales problem.

closes when a bound policy names the receipt as the rating basis
2027 · the biggest single pull on the tipD Bind⚖️ legal· spec
The spec is certified by someone who is not us

An insurer certifies the specification, not merely the mathematics. This makes the tape admissible rather than merely precise, and it is the precondition for a syndicate treating it as a standard instead of one vendor’s product.

closes when a third party publishes the conformance criteria
Dec 2027 → Aug 2028 · magnitude, not timingD Bind⚖️ legal· spec
The deferred EU obligations land

The Digital Omnibus deferred Annex III high-risk duties to 2 December 2027 and Annex I to 2 August 2028, with deployer log-retention alongside. It decides whether every todo needs a panel or only every system — the difference between billions and trillions — but it moves the ceiling, not the date.

closes when a supervisor requires per-decision reconstruction
2027 H2 → 2028 · the cascadeE Syndicate💰 commercial· market
Procurement propagation

The standard enters master vendor-risk forms. Every B2B vendor shipping agents finds enterprise deals stall without native attestation and integrates. This is the distribution mechanism — what turns an exclusion into billions of metered agents — and the only lever that widens the ceiling as well as moving the date.

closes when a Fortune 500 vendor form names it without our involvement
T−17 market · T−8 if it tipsE Syndicate💰 commercial· market
$1 trillion annualised, realised

At capex-priced market rates the crossing is Jan 2028. If the market runs at its own outliers — app-embedding at 18.9%/mo, OpenRouter-class token growth, a three-month cascade — it is Apr 2027. Moving between those two numbers is the whole job of the legs above.

closes when the registry counts it
Someone has to be wrong — the three ways out

To believe the capex and disbelieve this, you have to take one of three exits. One: the scaling hypothesis fails — then there is no fleet to meter, and the $800B was the larger error. Two: truncation is not a problem — our bet is that neural nets are information rather than physics, never touching reality directly, so stacked decisions accumulate drift that cannot be re-checked against the world one step at a time. If that is wrong, nothing needs reconstructing and the whole thesis goes, not just the timeline. Three: coverage never converts — inertia wins for longer than we can fund, which needs no physics to be different and is the cheapest exit to take.

Exit 2 is a bet and is labelled as one — a claim about information and truncation, never that software “cannot” do something, which is a register that loses to the first counterexample. It is also the only exit whose falsification takes the thesis rather than moving a date.

Where a trillion stops being a company

$1 trillion placed is a market forecast; $1 trillion retained is a political question. The first follows from the arithmetic. The second would make this the largest company in history by roughly two, and long before the market runs out of room three other things bind: antitrust attention on a mandatory tollgate, sovereign insistence on domestic clearance, and the broker channel repricing once the standard no longer needs enforcing. We are not an insurer, we bear no risk, and nothing here says what a carrier will charge or that a receipt prevents anything — where an action landed against rules declared before it ran is all the record is sufficient for.

Sources checked 2026-08-29 · The Insurer · Insurance Journal · Fenwick · Armilla / Chaucer · DLA Piper
The live model · source at docs/strategy/2026-08-29-license-double-exponential-bottom-up.html

The next five — what each one means now, where it fits, what can fill it

Five three-word sub-points out of 71 still open across 10 lists. Which five is a count, not a choice: open items only · one frontier rung per list · most checks already passing first · ShortLex breaks ties. Frontier is position, not importance — a rung nobody needs is still the rung you are standing on.

⚠ computed at 3e51452fe6, this deploy is 1bc4936d1 — the counts below are from a different tree. Re-run bash scripts/milestones/update.sh.

📜Standardize endorsement terms.B1 · Instrument⚖️ Legal Standardization🔒 A1.Strategy.Law13/14 checks
Specification
7/7
Execution
2/2
Market
4/5

13 of 14 declared checks pass. 1 still open, the nearest naming docs/legal/wording-shared.md. One of those files has never been committed to. 5 further items wait behind it in Legal Standardization.

What it means now

The wording itself is finished: the endorsement form, the cuts, the discharge mechanism, and the tape/brake-not-engine reading all hold, and named carriers already have the specimen in hand with real confirmed opens. The one thing not true is that none of them has said anything back about the wording yet — 13 of 14 checks pass, and the 14th is the only one that isn't ours to close by writing.

■ next check: a carrier has commented on the wording — docs/legal/wording-shared.md

Where it fits

It rests on A1 (the negative warranty already declared) and is the last thing standing between a finished specimen and B2, closing the policy perimeter — the perimeter can't close on wording nobody outside this building has reacted to.

after A1 🧱 Declare negative warranty (done)
unlocks B2 🩹 Close policy perimeter

What can fill it

Not a file to write first — a reply. One of the named carriers on the outreach log has to comment on the specimen wording; once that happens, record it in docs/legal/wording-shared.md.

never committed to: docs/legal/wording-shared.md

Read more — why this list exists, its edges, and all 14 checks →

Technical boundaries are useless to capital until they are translated into financial constraints. This vector maps the precise surface area of our Errors and Omissions liability. We are systematically drafting a narrow-channel posture specification that defines exact exclusions, prices expected losses, and hard-caps tail risk. The output is a standardised actuarial docket — a self-contained liability asset that allows a carrier-side syndicate to confidently price and bind the risk without requiring a single manual underwriting meeting.

how to read it · This track converts a measurement into a price, and the order is the argument. You cannot price an expected loss before you have said what is excluded, and you cannot cap a tail before you have priced the body. The exclusions and the wording are written and guarded — the language fence is a red test, so overclaiming vocabulary cannot ship. The break is at the D phase: everything up to pricing exists as computed artifact, and nothing has been handed to a counterparty who could disagree with it. Arming the underwriter is the hinge, and binding the first policy is the only line here that requires another party to sign.

← technical Takes the measurement and refuses to overclaim it. The language fence exists because the technical result is narrower than the market wants it to be, and the honesty is the asset.

→ commercial Hands over the docket — the thing that lets a syndicate price without a meeting. This is what the commercial track is actually carrying into the room.

← commercial Receives objections. Every friction the market surfaces comes back here as a wording change, an exclusion, or a cap; that return path is the only reason cold objections are worth collecting.

✓ Specification the narrow-channel spec exists — docs/architecture/narrow-channel-posture-spec.md

✓ Specification it is substantial, not a stub — docs/architecture/narrow-channel-posture-spec.md

✓ Specification it engages the competing standard — docs/architecture/narrow-channel-posture-spec.md

✓ Specification a complete endorsement form exists, not only a warranty clause — docs/legal/endorsement-cy-2026-det-continuous-state-verification.md

✓ Specification what was cut from the draft, and the reason for each cut, is on the record — docs/legal/endorsement-cy-2026-det-continuous-state-verification.md

✓ Specification the condition precedent is discharged by a record the payer can recompute — burden on the insured, the consequence is coverage and never a presumption of negligence (a coverholder is never left defending a trigger the syndicate cannot recompute) — docs/legal/endorsement-cy-2026-det-continuous-state-verification.md

✓ Specification the wording sells a tape, never a brake or an engine — the endorsement and the LOI read clean under the ENGINE / SAFETY_PROOF / BRAKE families — scripts/voice/behavior-promise.mjs

✓ Execution the signals hold at every altitude — tests/pmu-simulator/insurability-all-altitudes.test.mjs

✓ Execution the glossary is guarded — tests/pmu-simulator/glossary.test.mjs

✓ Market named carriers are on the outreach log — .thetacog/outreach-log.ndjson

✓ Market real opens are confirmed by the provider — read from the arbiter's synced mirror, never the ndjson that froze on 2026-07-21 — data/thetacoach.db

✓ Market a wording team can read the specimen before a call, without asking us for it — public/legal/endorsement-cy-2026-det.html

✓ Market the market's answer this week was a wording, not an argument — the exclusion and the pause letter are read in public as one demand for the receipt (the motion to nerf the bow, named, never argued with) — src/content/blog/2026-09-13-two-banks-one-ledger.mdx

○ Market a carrier has commented on the wording — docs/legal/wording-shared.md

↓ the whole Legal Standardization list · ↓ this rung in the sequence · reading written by claude-sonnet-5, after the counts and never inside them

📮Disclose licensing ladder.A1 · Ground📮 Market Contact🔨 C1.Operations.Grid6/7 checks
Specification
2/2
Execution
3/3
Market
1/2

6 of 7 declared checks pass. 1 still open, the nearest naming thetadriven.com/playbook. One of those files has never been committed to. 11 further items wait behind it in Market Contact.

What it means now

The ladder itself is finished: the pressure doctrine is written, the outreach spec names its rooms and send gate, every rung carries a published mitigation, it ends at an institution rather than an invoice, and it reads clean as a tape (not a brake or engine) to a stranger before rung one fires. What's missing is service — no named party has actually received it, because the page it would point to, thetadriven.com/playbook, doesn't exist and nothing in email-sent.ndjson references it.

■ next check: a named party has actually been served it — thetadriven.com/playbook

Where it fits

As A1, the first rung in Market Contact, it has to be live before A2 'Equip cold prospects' can hand the ladder to anyone — 12 further rungs in this list sit behind it and stay closed until disclosure actually happens. It belongs in Operations.Grid because this is the moment the work first touches an outside party.

first rung in this list
unlocks A2 🗝️ Equip cold prospects

What can fill it

Publish thetadriven.com/playbook and send it to one named prospect by email — the failing check is literally a count of that URL in .thetacog/email-sent.ndjson, so the page plus one logged send is what flips it.

never committed to: thetadriven.com/playbook

Read more — why this list exists, its edges, and all 7 checks →

Every other list here produces something that is true whether or not a stranger cooperates; this is the only one that cannot be finished from inside the building. Market contact is a ratchet with three teeth and they turn in order: an outbound approach that reaches a named counterparty, a grassroots reply nobody solicited, and — where a public claim is false and the party will not answer it — a disclosed escalation ladder that ends at an institution rather than at an invoice. The three surfaces are already public and already point at each other. /playbook is the ladder, published in full with every rung's mitigation before the first rung can fire, so the party sees the whole thing in advance. /resources is the master key that ships with the advisory invoice, so a recipient can check every implication without asking us for anything. /cta is the lever a reader reaches for after finishing the book. The scoreboard is deliberately unflattering: the win is a false claim retracted, not a payment extracted.

how to read it · Read this as the one list the repo cannot mark its own homework on, which is why almost every check here fetches production or reads a ledger instead of testing that a file exists. The A phase is genuinely done and says so from outside: all three surfaces answer a cold fetch, the ladder carries a mitigation on every rung, and the invoice hands over the pack rather than a salesperson. Then it splits in two. Outbound is real — forty-one dispatches through the pipeline, a hundred and fifty logged sends, seven distinct carrier and broker domains in the send ledger. Reply is not: six recorded clicks, and no ledger of an unsolicited inbound anywhere. Everything from the C phase down waits on one missing artifact. The register that counts asked / answered / refuted is specified on the ladder's second rung and printed there as zero — honestly, because it does not exist — and four items point at data/register/ with every one of them red. No rung has fired, and none should until the count is real.

→ commercial Hands the funnel its top. An objection cannot be mapped before somebody has been reached, and this is the list that does the reaching — every named counterparty in the commercial track arrived through a vector declared here.

← bookclub Takes the warm introduction and spends it. A reader who volunteers an intro arrives here as a named counterparty rather than as another cold address, which is the entire reason the slow track is worth its slowness.

← argument Takes the manuscript and the runnable proof and makes them the opening move instead of the closing one. /resources is the argument, packaged so a stranger can check it with nobody from here in the room.

→ legal Returns what the market actually said. A refusal that names a wording is a wording change; a refusal that names nothing was a bad meeting, and the ladder exists for the case where there is no reply at all.

→ board Hands the board its reach. Every ally lane on the board is a named class this ratchet already knows how to reach, and every reply it records is testimony the board ledger reads.

✓ Specification the pressure doctrine is written down — the accused is never the audience — docs/ops/the-respectable-win-2026-08-06.md

✓ Specification the outreach spec names the rooms, the vectors and the send gate — docs/ops/email-iterations/sovereign-outreach-spec.html

✓ Execution every rung carries a mitigation, published before it can fire — src/app/playbook/page.tsx

✓ Execution the ladder ends at an institution, not at an invoice — src/app/playbook/page.tsx

✓ Execution the ladder sells a tape, never a brake or an engine — the page reads clean under the ENGINE / SAFETY_PROOF / BRAKE families, and hands the reader the meter in a browser before rung one — src/app/playbook/page.tsx

✓ Market a stranger can read the whole ladder before rung one fires — dev/null

○ Market a named party has actually been served it — thetadriven.com/playbook

↓ the whole Market Contact list · ↓ this rung in the sequence · reading written by claude-sonnet-5, after the counts and never inside them

🩻Retract ungrounded claims.B1 · Instrument📖 The Argument🔨 C1.Operations.Grid6/7 checks
Specification
3/3
Execution
2/2
Market
1/2

6 of 7 declared checks pass. 1 still open, the nearest naming books/tesseract/reviews/named-external-review.md. One of those files has never been committed to. 4 further items wait behind it in The Argument.

What it means now

6 of 7 checks pass: the errata exists and carries real retractions (not typos), the hostile critique stays in the repo rather than being scrubbed, an adversarial review panel actually ran, the retracted hardware-counter claim now lives as a red test, and the falsifiable claims are published as a real list. The one gap is that no named outside reviewer has put their name on the record yet.

■ next check: a named outside reviewer is on record — books/tesseract/reviews/named-external-review.md

Where it fits

It depends on A1 (canonical terms pinned) so a retraction points at a stable term, not a moving target. It sits in the Instrument phase because retracting a false claim is what keeps the panel above it honest, and it unlocks B2 (force cold recomputes) — recomputing only matters once the claims being recomputed are the corrected ones.

after A1 📕 Pin canonical terms (done)
unlocks B2 ❄️ Force cold recomputes

What can fill it

This is the outside-the-building case: no file write closes it. Someone who isn't the author has to actually read the retracted claim and the errata and put their name on a review. That review, once it exists, gets committed to books/tesseract/reviews/named-external-review.md — but the send/ask to that named reviewer has to happen first.

never committed to: books/tesseract/reviews/named-external-review.md

Read more — why this list exists, its edges, and all 7 checks →

Technical boundaries are useless to capital until someone outside the building can read the claim and check it without asking permission. This vector maps the surface area of the argument itself — the manuscript, the corpus, and the runnable demo — as one instrument rather than three marketing assets. The book states the physics; the blog corpus repeats it in one voice, five hundred times, indexed and interlinked; the npx command lets a stranger in an empty folder recompute the claim on their own machine and get the same answer. Every buyer meets the thesis here first, and every hostile reader attacks here first. The output is not persuasion. It is a falsifiable public record: claims listed, overclaims retracted in writing, and a command that either reproduces or does not.

how to read it · Read this track as the only one whose failures are public. The manuscript is frozen and built, the errata retracts real overclaims in writing, and the cold-run guard exists because a prospect actually hit the empty-folder crash — that is the shape of an argument being tested rather than promoted. Two lines carry the honest bad news. Voice consistency has a guard and a backlog the guard does not cover: the frontier posts pass the canonical spine and the great majority of the corpus does not, because the check warns rather than blocks. And the outside world has not repeated the claim yet — the registry holds only us, and no named hostile reviewer is on record. Reach is real; corroboration is not.

→ commercial This is the opening move, not the closing one. A pitch that begins with a command the reader can run has already conceded that they should not simply believe us, which is the only posture that survives a diligence read.

← technical Takes the runnable proof and exposes it to someone with no context and no patience. Every cold-run failure here is a defect the technical track cannot see from the inside.

→ bookclub Supplies the chapter that earns the reply. The book club has nothing to hand anyone if the manuscript is not finished and readable in one click.

✓ Specification an errata exists — public/book/ERRATA.md

✓ Specification it carries real retractions, not typos — public/book/ERRATA.md

✓ Specification a hostile critique is kept in the repo — books/tesseract/reviews/critique1.txt

✓ Execution an adversarial review panel was run — books/tesseract/reviews/3bot-meta-analysis.html

✓ Execution the retracted hardware-counter claim is a red test — tests/claims/no-hardware-counter-claim.test.mjs

✓ Market the falsifiable claims are published, and there are enough of them to be a list — public/book/falsifiable-claims.html

○ Market a named outside reviewer is on record — books/tesseract/reviews/named-external-review.md

↓ the whole The Argument list · ↓ this rung in the sequence · reading written by claude-sonnet-5, after the counts and never inside them

💻Attest execution bounds.A1 · Ground⚙️ Technical Integration🧪 C2.Operations.Loop11/13 checks
Specification
4/4
Execution
6/6
Market
1/3

11 of 13 declared checks pass. 2 still open, the nearest naming docs/receipts/third-party-recompute.md. One of those files has never been committed to. 13 further items wait behind it in Technical Integration.

What it means now

reading pending — written when 9/13 checks passed; 11/13 pass now.
node scripts/milestones/narrate.mjs --key technical-1

■ next check: a third party has recomputed one — docs/receipts/third-party-recompute.md

Where it fits

first rung in this list
unlocks A2 🧩 List marketplace extension

What can fill it

—

never committed to: docs/receipts/third-party-recompute.md

.thetacog/email-sent.ndjson — last touched 2026-10-01 (9974c9ac6b)

Read more — why this list exists, its edges, and all 13 checks →

We are replacing trust with recomputable proof — same bytes, same hash. This vector is entirely focused on building the hardware-attested semantic grounding required to isolate and measure AI execution risk. By shipping the trust root and capturing live telemetry on-chip, we transform abstract software behaviour into a mathematically auditable ledger. The terminal state of this track is a frozen, zero-entropy interface where capital can independently verify that our agent remains strictly within its defined operational bounds.

how to read it · Read this track as one chain with no shortcuts: a verdict has to be signed before a run is worth logging, a log has to be quiet before live work is worth measuring, and live work has to be measured before a same-bytes-same-hash claim is worth making. The A and B phases are already through — the signer exists, the receipts accumulate, the false-alarm rate is sealed with a confidence interval. What is genuinely open here is not code but WITNESS: every market check on this track fails, because nobody outside the building has recomputed a receipt. That single missing artifact is why a track at ninety-something per cent on specification and execution is not finished.

→ legal The measured boundary becomes the covered boundary. Exclusions can only be written against something that is actually observed, so every claim the legal track fences is a claim this track first made checkable.

→ commercial The proof a stranger can run in one command is what makes a pitch survive contact. Without it the commercial track is asking for belief; with it, it is asking someone to check.

✓ Specification on-chip resident spec exists — docs/architecture/pmu-resident-onchip-spec.md

✓ Specification verification gaps are written down, not hidden — docs/architecture/pmu-rust-verification-gaps.md

✓ Specification attestation glossary exists — docs/architecture/pmu-spec-attestation-glossary.md

✓ Specification the reading carries its own null — the spec says UNMEASURED for a line that cannot beat its own shuffle, and THE METER is read against a shuffled-pairing null (0.263 vs 0.189, z 1.6: at the null, said first) — docs/architecture/rust-pipeline-flowchart-2026-07-23.md

✓ Execution the in-binary signer exists — packages/thetacog-mcp/intentguard/src/attest.rs

✓ Execution it signs with ed25519, not a hash claim — packages/thetacog-mcp/intentguard/src/attest.rs

✓ Execution a one-byte forge is caught by a test — tests/pmu-simulator/forge-test.test.mjs

✓ Execution a nonsense line cannot latch — the null shuffles only the line against the same mass, and the winner must clear the family-wise z for the rungs drawn (this retracted 35.9 / 37.3 / 78.2 / 84.2 on 2026-09-14) — packages/thetacog-mcp/pmu-rust/src/lens.rs

✓ Execution a placement the one binary did not produce refuses (UNMEASURED, no pixel) instead of degrading, and the callers that could still compute one in JS may only shrink (24 on 2026-09-14) — tests/pmu-simulator/one-placement-door.test.mjs

✓ Execution the receipt names the latch that refused — permutation or family-wise z — never a threshold that was met — tests/pmu-simulator/receipt-fit-line.test.mjs

✓ Market a stranger can verify a receipt on the site (the page answers, it does not redirect) — src/app/verify-receipt/page.tsx

○ Market a third party has recomputed one — docs/receipts/third-party-recompute.md

○ Market the first number handed to a writer is our own failing reading with its null attached — the send tape carries the phrase before it carries anything green — .thetacog/email-sent.ndjson

↓ the whole Technical Integration list · ↓ this rung in the sequence

🗡️Arm discovery requests.A2 · Ground♟️ The Board🔨 C1.Operations.Grid4/5 checks
Specification
2/2
Execution
2/2
Market
0/1

4 of 5 declared checks pass. 1 still open, the nearest naming data/board/ledger.ndjson. One of those files has never been committed to. 10 further items wait behind it in The Board.

What it means now

The discovery kit itself is done — the guide explains its limits before its uses, the preservation letter cites FRCP 37(e) for automated decision records, it passes the behavior-promise read (no brake/engine/safety-proof claims), and a guard pins it to those limits. The only thing missing is a real person outside this building asking for it; until that happens the kit is built but not yet armed by demand.

■ next check: someone outside the building asked for the kit (testimony, written only when it happens) — data/board/ledger.ndjson

Where it fits

It follows directly from A1's published care standard (done) and is the prerequisite for B1, briefing plaintiff counsel — you don't brief counsel on a kit nobody outside has tested by asking for it. It sits in Ground because it's still proving the kit works before handing it to an adversarial process.

after A1 ♟️ Publish care standard (done)
unlocks B1 ⚖️ Brief plaintiff counsel

What can fill it

An actual outside request — a plaintiff's counsel, an insurer, or a claimant asking for the discovery kit — logged as a line in data/board/ledger.ndjson with lane:"counsel", event:"kit-requested". That file doesn't exist yet and can't be pre-written; it only gets a row when someone outside actually asks.

never committed to: data/board/ledger.ndjson

Read more — why this list exists, its edges, and all 5 checks →

The light switch. Writing to the party whose plausible deniability the receipt breaks produced silence, and it will keep producing silence, because that party is pinned by its own balance sheet. This list stops selling to the defendant and shows the board to everyone whose self-interest already profits when the deniability breaks: plaintiff, bad-faith and ERISA counsel, relators’ counsel, litigation funders, treaty reinsurers and syndicates who write exclusions, MGA and parametric underwriters who can price the clean body, self-insured plan fiduciaries who pay the TPA, forensic researchers, and the defense counsel and integrators hired after the subpoena. The hinge is The T.J. Hooper (2d Cir. 1932): industry custom is not the standard of care when a cheap, available precaution exists. The storefront makes the precaution free (MIT) and public; only underwriting and attestation are licensed. None of these parties need to talk to each other. They need to see the same board. Who holds each job, and why it pays them, lives in data/board-jobs.json and is rendered below the lists.

how to read it · Read it as a sequence of other people’s acts, which is why almost every market check reads a testimony ledger (data/board/ledger.ndjson, data/board/dockets.ndjson) that only a real outside act may write. The A phase is ours: the standard is published and dated, and the kit says what a receipt is sufficient for and what it is not, before anyone relies on it. The B phase arms one lane per class that profits: counsel, funders, plan fiduciaries, researchers. The C phase is the first outside act that names the standard: a docket, a rider, a fiduciary asking its TPA for the record. The D phase is the downstream market: fixers hired after the demand, and an underwriter quoting the clean body. The E phase is the switch itself: custom stops working as a defense. Today the storefront is live and the kit is not written, so the list is stuck at its second rung. The double exponential (agents per employee times steps per agent) drives the share of work a human reviews toward zero, which is why this is geometry and not persuasion: the field, in full, is at /blog/2026-09-11-an-exponential-is-a-foam-knife-in-the-kidney.

← legal Takes the negative warranty and the exclusions as the kit’s limits. The discovery guide may never claim more than the legal list fences, because the first overclaim is impeached on deposition.

← argument Takes the public recompute as the precaution the Hooper argument needs. A precaution nobody outside can run is not cheap and not available, so the argument list is what makes B low.

→ commercial Hands the commercial list counterparties who arrive already holding the question. A carrier that met a receipt in discovery is a different buyer from one that received a deck.

← contact Uses the contact ratchet to reach each ally class, and counts only replies. A lane brief that reached nobody leaves the B rung red, as it should.

✓ Specification the discovery guide says what a receipt is NOT sufficient for before what it is — docs/board/receipt-discovery-guide.md

✓ Specification the preservation letter names automated decision records as ESI under FRCP 37(e) — docs/board/preservation-letter-template.md

✓ Execution the guide reads clean under the behavior-promise families (never a brake, never an engine, never a proof of safety) — docs/board/receipt-discovery-guide.md

✓ Execution a guard holds the kit to its limits — tests/board/c433-discovery-kit.test.mjs

○ Market someone outside the building asked for the kit (testimony, written only when it happens) — data/board/ledger.ndjson

↓ the whole The Board list · ↓ this rung in the sequence · reading written by claude-sonnet-5, after the counts and never inside them

Sufficient for which five sub-points are the live frontier, what is already true about each, and which file the next check names. Not sufficient for which five matter most — frontier is position, not importance, and no count decides that. The pick and every number are LLM-free; the three readings are not, and they live in a separate file so you can always tell which is which. Recompute: bash scripts/milestones/update.sh

Breadth first — the three parents

ShortLex sorts by length before letter, so A, B, C come before A1, A2, C1. Each parent is a pure rollup of the lists beneath it — nothing here is authored.

🏛️A.Strategy

2 lists · 16 items · 3 done

  • A1.Strategy.Law — Legal Standardization (8)
  • A1.Strategy.Law — Pitch And Fund (8)

next: Standardize endorsement terms

⚠ A1 claimed by legal + pitch — one rank, two lists

⚡B.Tactics

1 list · 5 items · 3 done

  • B2.Tactics.Deal — Book Club (5)

next: Establish lateral dialogue

🔧C.Operations

7 lists · 85 items · 22 done

  • C1.Operations.Grid — The Argument (8)
  • C1.Operations.Grid — The Board (12)
  • C1.Operations.Grid — Commercial Extraction (17)
  • C1.Operations.Grid — Market Contact (15)
  • C1.Operations.Grid — Patent & IP (6)
  • C2.Operations.Loop — Technical Integration (16)
  • C3.Operations.Flow — IntentGuard and the Backup (11)

next: Attest execution bounds

⚠ C1 claimed by argument + board + commercial + contact + patent — one rank, two lists

Where the market contact comes from

A green market bar can mean two completely different things, so this section separates them. 16 of 106 milestones have market evidence that leaves the building; 0 have evidence somebody came back. The other 90 need market contact — and each one is a place to go, not a scolding.

1 · Artifact — not contact
a file we wrote ourselves — necessary, and not evidence anybody outside has seen it
2 · Doorway — not contact
a live public route a stranger can reach unaided — contact becomes possible here, it does not happen here
3 · Outbound
we reached a named counterparty and the send is logged — contact initiated
4 · Inbound
they came back — a reply, a click, an outcome, a retraction. Contact returned
doorway — a live public route a stranger can reach unaided — contact becomes possible here, it does not happen here
/playbook1/1 checks

the escalation ladder, published — what we ask, in what order, and what happens when nobody answers

thetadriven.com/playbook
last touched 2026-09-29 (07df499e17)

📮 Disclose licensing ladder

/resources1/1 checks

what a cold prospect is handed so they can check us without talking to us

thetadriven.com/resources
last touched 2026-08-30 (b6620de7b8)

🗝️ Equip cold prospects

/cta1/1 checks

the one door a finished reader walks through

thetadriven.com/cta
last touched 2026-09-29 (07df499e17)

🔥 Arm finished readers

outbound — we reached a named counterparty and the send is logged — contact initiated
send log16/25 checks

every email that actually left, with the link it carried — the tape outbound contact is read off

.thetacog/email-sent.ndjson
last touched 2026-10-01 (9974c9ac6b)

💻 Attest execution bounds · 🧱 Declare negative warranty · 📮 Disclose licensing ladder · 🗝️ Equip cold prospects · 🔥 Arm finished readers · 🎟️ Grant tester licences · 🧭 Map new tribes · 🗣️ Quote unmetered runs · 🔌 Convert guardrail vendors · ☕ Reach named counterparties · ⚖️ Finalize actuarial asset · 🎯 Demand operator license · 🌐 Distribute syndicate asset · 🪪 Mint insured licenses · 🎯 Freeze canonical numbers · 🎯 Split both audiences · 🎯 Reach five allocators · 🎯 Answer diligence cold · 🔁 Earn stranger recompute · 🧮 Publish expansion proof · 🎧 Curate notebook retellings · 📨 Answer broker question

dispatch log2/2 checks

the canonical comms pipeline’s own record of what it dispatched and to which channel

.thetacog/comms/dispatch-log.ndjson
last touched 2026-09-29 (75f15be9c0)

🎯 Name lead allocator · 🎯 Bank first cheque

outreach log2/2 checks

named counterparties reached, appended per attempt

.thetacog/outreach-log.ndjson
last touched 2026-09-24 (c9f04bba12)

📜 Standardize endorsement terms · ☕ Reach named counterparties

inbound — they came back — a reply, a click, an outcome, a retraction. Contact returned
replies0/2 checks

a human wrote back — the only rung nobody can manufacture from inside the building

.thetacog/inbound-replies.ndjson
NEVER COMMITTED TO — this channel exists only in a predicate

🎟️ Grant tester licences · 📬 Earn unsolicited replies

register · answering0/2 checks

an outcome landed: a filing answered, a claim retracted

data/register
last touched 2026-08-30 (99f2d54506)

🏛️ Issue unmetered notice · 🏳️ Enforce license purchase

unreached · 12

contact IS declared and none of it passes yet — the channel exists, the send has not landed

artifact · 78

every market check is a file we wrote ourselves — nothing here says anybody outside has seen it

2 A2 🧩 List marketplace extension · ⚙️ Technical Integration3 A3 ♻️ Recompute sealed receipts · ⚙️ Technical Integration4 A1 📕 Pin canonical terms · 📖 The Argument5 A4 🧮 Verify execution tape · ⚙️ Technical Integration6 A5 ⏳ Anchor third-party timestamps · ⚙️ Technical Integration7 A1 🗂️ Convert seven provisionals · 📜 Patent & IP9 A1 🎯 Reach five writers · 💰 Commercial Extraction10 A1 📖 Curate reader cohort · 📚 Book Club16 B1 🔑 Claim stranger keys · 💰 Commercial Extraction19 B1 ✉️ Dispatch private invites · 📚 Book Club20 B1 🚨 File notice response · 📜 Patent & IP21 B2 ⏰ Ship docket guard · 📜 Patent & IP22 B1 🩻 Retract ungrounded claims · 📖 The Argument23 B2 ❄️ Force cold recomputes · 📖 The Argument24 B3 🔮 Audit stated forecasts · 📖 The Argument25 B3 🪝 Map underwriter objections · 💰 Commercial Extraction27 B2 🩹 Close policy perimeter · ⚖️ Legal Standardization28 B1 ⚙️ Benchmark drift rate · ⚙️ Technical Integration29 B2 🪙 Measure token delta · ⚙️ Technical Integration30 B2 💬 Establish lateral dialogue · 📚 Book Club31 B5 ✍️ Bind rating basis · 💰 Commercial Extraction32 B6 🌱 Seed kinetic agents · 💰 Commercial Extraction33 B7 💰 Collect first toll · 💰 Commercial Extraction36 C1 📡 Ingest live telemetry · ⚙️ Technical Integration37 C1 🧾 Disclose unpractised claims · 📜 Patent & IP38 C1 🗣️ Enforce argument spine · 📖 The Argument39 C2 🔒 Gate state crossings · ⚙️ Technical Integration40 C3 🖋️ Countersign autonomous moves · ⚙️ Technical Integration41 C1 📉 Price basis points · ⚖️ Legal Standardization42 C2 ✂️ Cap aggregate limit · ⚖️ Legal Standardization43 C3 🏛️ Inherit statutory boundaries · ⚖️ Legal Standardization44 C2 👀 Track institutional reads · 📖 The Argument45 C1 🤝 Validate parametric triggers · 💰 Commercial Extraction46 D1 🧱 Block the workaround · 📜 Patent & IP47 C1 🔗 Convert lateral network · 📚 Book Club48 C1 🧾 Publish non-response register · 📮 Market Contact49 D1 🛑 Sign root anchor · ⚙️ Technical Integration50 E1 🏗️ Serve production fleets · ⚙️ Technical Integration52 D1 📣 Earn outside citation · 📖 The Argument53 D1 🏷️ Lock pricing model · 💰 Commercial Extraction54 E1 🪙 Charge per agent · 📜 Patent & IP55 D2 🖋️ Bind first policy · ⚖️ Legal Standardization59 E2 ⏩ Ship zero-touch gate · 💰 Commercial Extraction60 E3 🏦 Price first tranche · 💰 Commercial Extraction67 C1 🎯 Earn two meetings · 🎯 Pitch And Fund69 C3 🏛️ Form investable vehicle · 🎯 Pitch And Fund72 B8 💺 Bank first seat · 💰 Commercial Extraction73 B5 🧭 Fire first fifty · 📮 Market Contact74 B6 ⚡ Pitch kinetic desks · 📮 Market Contact75 C2 🏦 Secure risk introductions · 📮 Market Contact76 B4 🧮 Count signed attestations · ⚙️ Technical Integration77 B5 🔀 Unlock unsigned credits · ⚙️ Technical Integration78 C2 🏷️ Show priced deviations · 💰 Commercial Extraction79 D2 📦 Build portable walker · ⚙️ Technical Integration80 A1 ♟️ Publish care standard · ♟️ The Board81 A2 🗡️ Arm discovery requests · ♟️ The Board82 B1 ⚖️ Brief plaintiff counsel · ♟️ The Board83 B2 💼 Seed funder diligence · ♟️ The Board84 B3 🛡️ Equip plan fiduciaries · ♟️ The Board85 B4 🔬 Verify independent replication · ♟️ The Board86 C1 📑 Earn docket citation · ♟️ The Board87 C2 📜 Word receipt rider · ♟️ The Board88 C3 🧾 Demand TPA receipts · ♟️ The Board89 D1 🧰 Convert enterprise fixers · ♟️ The Board90 D2 🏦 Price clean risk · ♟️ The Board91 E1 🕯️ Close custom defense · ♟️ The Board92 A1 🦀 Prove Rust thesis · 🛡️ IntentGuard and the Backup93 A2 🐧 Verify Linux hashes · 🛡️ IntentGuard and the Backup94 B1 👁️ Sign agent turns · 🛡️ IntentGuard and the Backup95 B2 🪙 Charge witnessed queries · 🛡️ IntentGuard and the Backup96 B3 📈 Show tape drift · 🛡️ IntentGuard and the Backup97 C1 ☁️ Serve signed cards · 🛡️ IntentGuard and the Backup98 C2 📦 Publish any-node install · 🛡️ IntentGuard and the Backup99 C3 💾 Anchor tape backups · 🛡️ IntentGuard and the Backup100 C4 🧾 Earn outside query · 🛡️ IntentGuard and the Backup101 C5 🗺️ Map whole tape · 🛡️ IntentGuard and the Backup102 C6 🚀 Attest deployed agent · 🛡️ IntentGuard and the Backup105 B9 🔀 Earn forwarded installs · 💰 Commercial Extraction

every market predicate is classified by the SURFACE it opens, never by its label · an item reaches the highest rung among its PASSING checks · rungs: artifact → doorway → outbound → inbound. Sufficient for which rung of the contact ladder each milestone’s market evidence reaches, through which organisational channel, and which milestones have no contact evidence at all. Not sufficient for whether that contact was any good — a logged send to the wrong person is still an outbound rung, and no count can tell you it was wasted. No model in this path. Recompute: node scripts/milestones/market-contact.mjs

The sequence, painted

A · Ground
·
·
·
·
B · Instrument
·
·
·
·
·
·
·
·
C · Prove
·
·
·
·
·
D · Bind
·
E · Syndicate
·
·
·
A1
A2
A3
A4
A5
B1
B2
B3
B4
B5
B6
B7
B8
B9
C1
C2
C3
C4
C5
C6
D1
D2
E1
E2
E3
E4

🎯Pitch And Fund⚖️ A1.Strategy.Law 🔒8 items · 6 open

4 of 30 declared evidence paths fall inside The Vault's owned surface

The raise, and the two documents it runs on. One deck an allocator reads in four minutes and one the team runs on every week, held to the same canonical numbers so that neither can drift from the other — every figure traceable to a receipt somebody outside this building can recompute, and the claim split stated before the ask rather than discovered during diligence. The audience here is capital and capital reads differently from a carrier: an accredited investor wants the shape of the market and the reason this is the only construction that reaches it; a syndicate partner wants the allocation and who else is in; a strategic wants to know what it costs them if somebody else takes the position first. A deck is never the result. The meeting it produced is a result, the second meeting is a better one, and the cheque is the only one that closes a phase. Nothing on this list can be finished by writing a document, which is what distinguishes it from every strategy list above it.

How to read this list →

A pitch deck for the team that has to double as a pitch deck for the carriers is two audiences wearing one artifact, which is how a deck stops persuading either of them. Split the documents, hold them to one set of numbers, and measure the list by meetings booked and capital committed rather than by slides produced. Fund, allocator, syndicate, dilution, cap table, cheque.

Enters & leaves (3) →
← 💰 Commercial Extraction
Takes the funnel's numbers as the deck's numbers. An allocator is being sold the same market the carrier objections map, so a figure that moves in one document and not the other is the drift this list exists to prevent.
← 📖 The Argument
Takes the manuscript and the runnable demo and makes them the evidence page rather than an appendix. The deck says run it yourself; the argument list is what there is to run.
← 📮 Market Contact
Takes named counterparties instead of a cold allocator list. A capital conversation that started as a reached person converts on a different curve from one that started as an address, and only the contact ratchet produces the first kind.
63A1🎯Freeze canonical numbers.
Specification — 100%, 5 of 5 checks pass
✓one constants file that the deck and the memo both quote
✓the free-versus-paid claim split is stated before any ask
✓no figure appears in a deck without a recomputable source
✓a deck in the repo quotes the canonical constants rather than restating them → docs/decks
✓the decks tell a reader to recompute rather than to believe → docs/decks
Execution — undeclared: nobody has written a check for this yet, which is not the same as zero
Market — 100%, 1 of 1 checks pass
✓investor-facing sends exist in the ledger → .thetacog/email-sent.ndjson
64A2🎯Split both audiences.✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/decks, docs/comms, src/app/deck, .claude/commands/deck.md, src/app/deck/insure/page.tsx, src/app/hiring/page.tsx, .thetacog/email-sent.ndjson.
Specification — 100%, 4 of 4 checks pass
✓the allocator deck and the team deck are separate artifacts → docs/decks
✓the accredited-investor disclaimer is standing language → docs/comms
✓the decks are SERVED per audience, not mailed as one PDF → src/app/deck
✓building one runs through a door, not a habit → .claude/commands/deck.md
Execution — 100%, 2 of 2 checks pass
✓the allocator surface and the team surface are separately served routes → src/app/deck/insure/page.tsx
✓the split is versioned, not improvised per send → docs/decks
Market — 100%, 1 of 1 checks pass
✓each audience has actually been served its own artifact → deck/insure
65B1🎯Reach five allocators.
Specification — 100%, 1 of 1 checks pass
✓the investor address book is canonical, not assembled per send → scripts/investors/address-book.mjs
Execution — undeclared: nobody has written a check for this yet, which is not the same as zero
Market — 100%, 2 of 2 checks pass
✓allocator sends are recorded rather than remembered → .thetacog/email-sent.ndjson
✓every send scheduled its own follow-up at send time → data/self-prompts.json
66B2🎯Answer diligence cold.
Specification — 100%, 2 of 2 checks pass
✓a hostile-diligence card exists and is maintained → docs/outreach/_hostile-diligence-card.md
✓deck replies are kept as graded artifacts rather than remembered → docs/decks/insure-rounds
Execution — undeclared: nobody has written a check for this yet, which is not the same as zero
Market — 100%, 1 of 1 checks pass
✓a diligence thread exists in the send record → .thetacog/email-sent.ndjson
67C1🎯Earn two meetings.1 open
Specification — undeclared: nobody has written a check for this yet, which is not the same as zero
Execution — undeclared: nobody has written a check for this yet, which is not the same as zero
Market — 67%, 2 of 3 checks pass
✓a held allocator meeting is recorded with the recap it came from, not inferred from a reply → data/pitch-meetings.ndjson
✗two allocator meetings held — the milestone itself → data/pitch-meetings.ndjson
✓every recorded meeting names who opened the door (warm thread, not a cold list) → data/pitch-meetings.ndjson
68C2🎯Name lead allocator.
Specification — undeclared: nobody has written a check for this yet, which is not the same as zero
Execution — undeclared: nobody has written a check for this yet, which is not the same as zero
Market — 100%, 2 of 2 checks pass
✓a lead is tracked as a node with attempts and a TTL → data/self-prompts.json
✓the syndicate conversation is in the dispatch record → .thetacog/comms/dispatch-log.ndjson
69C3🏛️Form investable vehicle.5 open
Specification — 0%, 0 of 2 checks pass
✗the vehicle and its terms are written down before anyone is asked to fund it → docs/legal/spv-terms.md
✗who pays the formation cost, and out of what, is named → docs/legal/spv-formation-funding.md
Execution — 0%, 0 of 2 checks pass
✗the entity is filed and has a receipt → docs/legal/spv-formation-receipt.md
✗a bank account exists that a cheque can actually be written to → docs/legal/spv-account-opened.md
Market — 0%, 0 of 1 checks pass
✗an allocator has signed the subscription documents → docs/receipts/spv-first-subscription.md
70D1🎯Bank first cheque.
Specification — undeclared: nobody has written a check for this yet, which is not the same as zero
Execution — undeclared: nobody has written a check for this yet, which is not the same as zero
Market — 100%, 2 of 2 checks pass
✓a priced allocation exists in the record → .thetacog/comms/dispatch-log.ndjson
✓the raise is tracked as an outcome rather than an artifact → data/self-prompts.json

📚Book Club🤝 B2.Tactics.Deal ☕5 items · 1 open

9 of 21 declared evidence paths fall inside The Network's owned surface

A lateral insertion vector. Standard vendor outreach triggers immediate defensive friction from institutional buyers. This track bypasses that barrier by engaging the exact same target demographic — insurance executives, risk managers, and capital allocators — at the altitude of shared intellectual curiosity. By curating a tight circle of readers, we establish baseline trust, align our mental models, and earn high-leverage introductions that eventually feed directly back into the Commercial Extraction pipeline.

How to read this list →

The slowest track by design, and the only one whose unit of progress is a person rather than an artifact. Read it as a trust ladder: pick a small circle, put a real chapter in their hands, earn a reply that was not solicited, and only then ask for the introduction. Each rung is worthless without the one below it, which is why a blast would defeat the purpose — nine contextualised invitations beat nine hundred sends. The track sat unplaced on the reef for as long as no room claimed its ledgers. It is not a separate strategy from Market Contact — it is the same strategy on a slower vector, reaching the same demographic, and on 2026-08-24 The Network claimed data/bookclub/, scripts/bookclub/ and the bookclub comms so the count could say that. Both lists now land on B2 Tactics.Deal, and the collision the board reports is the finding rather than a fault: one room, one coordinate, two vectors.

Enters & leaves (2) →
→ 💰 Commercial Extraction
Feeds introductions forward. This track never asks for a meeting; it earns the right to be introduced, and the commercial track is where that right gets spent.
→ 📮 Market Contact
The same strategy as Market Contact, run on a different vector. Both lists reach the same demographic and neither can be finished from inside the building; the difference is that outreach asks for attention and this one earns it, so a reader who arrives here and volunteers an introduction enters the contact ratchet already warm.
10A1📖Curate reader cohort.✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: data/bookclub/audience-snapshot.json, data/bookclub/ab-test, data/bookclub/sent.ndjson.
Specification — 100%, 1 of 1 checks pass
✓book club audience snapshot exists → data/bookclub/audience-snapshot.json
Execution — 100%, 1 of 1 checks pass
✓A/B arm definition exists → data/bookclub/ab-test
Market — 100%, 1 of 1 checks pass
✓at least 9 recipients on the list → data/bookclub/sent.ndjson
19B1✉️Dispatch private invites.✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: data/bookclub/sent.ndjson, data/bookclub/panel-sent.ndjson.
Specification — 100%, 1 of 1 checks pass
✓invitations are recorded as sent in the bookclub ledger → data/bookclub/sent.ndjson
Execution — 100%, 1 of 1 checks pass
✓book club dispatch ledger present → data/bookclub/panel-sent.ndjson
Market — 100%, 1 of 1 checks pass
✓invitations recorded as sent → data/bookclub/sent.ndjson
30B2💬Establish lateral dialogue.
Specification — 100%, 1 of 1 checks pass
✓reply handling is scripted → docs/comms/bookclub-reply-playbook.md
Execution — undeclared: nobody has written a check for this yet, which is not the same as zero
Market — 100%, 1 of 1 checks pass
✓engagement is recorded by the arbiter (an open or a click — a REPLY is a different fact and is not what this reads) → data/thetacoach.db
47C1🔗Convert lateral network.1 open
Specification — 100%, 1 of 1 checks pass
✓the introduction ask is scripted → docs/comms/bookclub-introduction-ask.md
Execution — undeclared: nobody has written a check for this yet, which is not the same as zero
Market — 0%, 0 of 1 checks pass
✗an introduction actually happened → data/bookclub/introductions.ndjson
103B3🧮Publish expansion proof.C669✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/specs/vna/SPEC-VNA-COCKPIT.md, src/content/blog/2026-10-07-conservation-of-address.mdx, books/tesseract/chapters/chapter-08-from-meat-to-metal.md, .thetacog/email-sent.ndjson.
Specification — 100%, 1 of 1 checks pass
✓row C669 is declared in the spec with its guard → docs/specs/vna/SPEC-VNA-COCKPIT.md
Execution — 100%, 2 of 2 checks pass
✓the conservation-of-address post is in the immutable commit, not only the working tree → src/content/blog/2026-10-07-conservation-of-address.mdx
✓chapter 8 names the identity "conservation of address" (a5ed41e1ef), read off HEAD → books/tesseract/chapters/chapter-08-from-meat-to-metal.md
Market — 100%, 2 of 2 checks pass
✓the post answers 200 on thetadriven.com → dev/null
✓the Ch 8 book-club edition (the email that names the identity, 55ec1eb3c5) reached at least ten readers who are not us, on or after 2026-10-07 → .thetacog/email-sent.ndjson

📖The Argument🔌 C1.Operations.Grid 🔨8 items · 6 open

12 of 59 declared evidence paths fall inside The Builder's owned surface

Technical boundaries are useless to capital until someone outside the building can read the claim and check it without asking permission. This vector maps the surface area of the argument itself — the manuscript, the corpus, and the runnable demo — as one instrument rather than three marketing assets. The book states the physics; the blog corpus repeats it in one voice, five hundred times, indexed and interlinked; the npx command lets a stranger in an empty folder recompute the claim on their own machine and get the same answer. Every buyer meets the thesis here first, and every hostile reader attacks here first. The output is not persuasion. It is a falsifiable public record: claims listed, overclaims retracted in writing, and a command that either reproduces or does not.

How to read this list →

Read this track as the only one whose failures are public. The manuscript is frozen and built, the errata retracts real overclaims in writing, and the cold-run guard exists because a prospect actually hit the empty-folder crash — that is the shape of an argument being tested rather than promoted. Two lines carry the honest bad news. Voice consistency has a guard and a backlog the guard does not cover: the frontier posts pass the canonical spine and the great majority of the corpus does not, because the check warns rather than blocks. And the outside world has not repeated the claim yet — the registry holds only us, and no named hostile reviewer is on record. Reach is real; corroboration is not.

Enters & leaves (3) →
→ 💰 Commercial Extraction
This is the opening move, not the closing one. A pitch that begins with a command the reader can run has already conceded that they should not simply believe us, which is the only posture that survives a diligence read.
← ⚙️ Technical Integration
Takes the runnable proof and exposes it to someone with no context and no patience. Every cold-run failure here is a defect the technical track cannot see from the inside.
→ 📚 Book Club
Supplies the chapter that earns the reply. The book club has nothing to hand anyone if the manuscript is not finished and readable in one click.
4A1📕Pin canonical terms.C305f · C697✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: books/tesseract/VOICE-RULES.md, books/tesseract/CANONICAL-GLOSSARY.md, tests/book/canonical-title-pinned.test.mjs, tests/voice/book-crossing-tax-is-never-a-clock.test.mjs, scripts/build-book-html.sh, public/book/downloads/tesseract-premium-complete.epub, src/app/book/read/page.tsx, src/components/book/BookReader.tsx.
Specification — 100%, 5 of 5 checks pass
✓the voice rules are written down → books/tesseract/VOICE-RULES.md
✓the canonical title is pinned in the metadata (reads the immutable commit, never the working tree — AXIOM 1 W3; repaired 2026-09-03 after an uncommitted peer-session deletion flipped the old working-tree read red with zero intent behind it) → books/tesseract/epub-metadata.yaml
✓the glossary defines the load-bearing terms → books/tesseract/CANONICAL-GLOSSARY.md
✓the pin survives a sweep — a guard reads the immutable commit and turns red in the run that commits a deletion (a6f6e26e53 swept the metadata on 2026-09-06 and the board alone noticed, nine days later) → tests/book/canonical-title-pinned.test.mjs
✓the crossing tax is not a clock — the guard refuses a time unit as the drift rate's denominator (the construct; the old token test stayed green while page three said 0.3% daily) → tests/voice/book-crossing-tax-is-never-a-clock.test.mjs
Execution — 100%, 4 of 4 checks pass
✓the chapters exist → books/tesseract/chapters/chapter-*.md
✓one build script produces the canonical HTML → scripts/build-book-html.sh
✓the built chapters are on disk → public/book/chapters/*.html
✓the build reads the committed metadata rather than generating it → scripts/build-book-html.sh
Market — 100%, 2 of 2 checks pass
✓a reader can download the finished book → public/book/downloads/tesseract-premium-complete.epub
✓the book can be read in the browser — the route mounts the reader and the reader carries chapters (gated behind login, which is a separate open question) → src/app/book/read/page.tsx
22B1🩻Retract ungrounded claims.1 openC305a · C305c · C305g · C689 · C690 · C691 · C694 · C695 · C694c
Specification — 100%, 3 of 3 checks pass
✓an errata exists → public/book/ERRATA.md
✓it carries real retractions, not typos → public/book/ERRATA.md
✓a hostile critique is kept in the repo → books/tesseract/reviews/critique1.txt
Execution — 100%, 2 of 2 checks pass
✓an adversarial review panel was run → books/tesseract/reviews/3bot-meta-analysis.html
✓the retracted hardware-counter claim is a red test → tests/claims/no-hardware-counter-claim.test.mjs
Market — 50%, 1 of 2 checks pass
✓the falsifiable claims are published, and there are enough of them to be a list → public/book/falsifiable-claims.html
✗a named outside reviewer is on record → books/tesseract/reviews/named-external-review.md
23B2❄️Force cold recomputes.1 openC305e
Specification — 100%, 2 of 2 checks pass
✓the one command is documented → packages/thetacog-mcp/README.md
✓a diligence brief exists → packages/thetacog-mcp/DILIGENCE.md
Execution — 100%, 3 of 3 checks pass
✓the empty-folder crash a prospect hit is guarded → packages/thetacog-mcp/tests/claims-check-npx-cold-run.test.mjs
✓the gate fails closed rather than open → packages/thetacog-mcp/tests/gate-fails-closed.test.mjs
✓the published version matches the repo → ./packages/thetacog-mcp/package.json
Market — 0%, 0 of 1 checks pass
✗a stranger has recomputed a receipt → docs/receipts/third-party-recompute.md
24B3🔮Audit stated forecasts.2 openC692 · C692b · C692d
Specification — 100%, 2 of 2 checks pass
✓the forecasts are sealed rows on disk rather than prose in a post → data/predictions/2026-09-03-envelope.ndjson
✓every sealed forecast carries the date it can be settled on → data/predictions/*.ndjson
Execution — 67%, 2 of 3 checks pass
✓the resolver refuses to report an empty shelf as a clean one → scripts/predictions/overdue.mjs
✗a resolution appends beside the forecast rather than over it → data/predictions/*.ndjson
✓a forecast was sealed in git before the record that could settle it, and the reading was appended beside it, the prediction unchanged — the direction pass's C238c research unit (Prediction committed 2026-09-23 22:24, 51b87e2186) predates the overnight receipt it was read against (b0861ef416) by git author time, and its Reading section follows (898b38d632: the turn-2 nudge HOLDs, n 25, p 0.50) → docs/specs/vna/direction/research/2026-09-24-prose-after-tool.md
Market — 0%, 0 of 1 checks pass
✗a stranger can read the register and score us without asking → thetadriven.com/predictions
38C1🗣️Enforce argument spine.✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/strategy/the-holden-voice.md, scripts/validate-mdx.sh.
Specification — 100%, 1 of 1 checks pass
✓the voice is specified, not vibed → docs/strategy/the-holden-voice.md
Execution — 100%, 3 of 3 checks pass
✓the voice guards exist → tests/voice/*.mjs
✓the newest posts pass the canonical spine (newest by filename DATE — the glob is date-prefixed, because a bare *.mdx sort is alphabetical and never reaches a dated post) → src/content/blog/[0-9]*.mdx
✓no hard FAILURE among the newest posts (repointed 2026-09-03: the --all corpus run takes minutes against the scorer's 8s kill — permanently red, measured nothing; bounded to zero FAILED among the newest-5 until a derived validate-mdx summary artifact exists to point at) → src/content/blog/[0-9]*.mdx
Market — 100%, 1 of 1 checks pass
✓the corpus is at scale → src/content/blog/*.mdx
44C2👀Track institutional reads.✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: data/ghost-read-friction.json, docs/reports/ghost-read, public/pixel.html, data/clicks.db.
Specification — 100%, 1 of 1 checks pass
✓reading friction is tracked → data/ghost-read-friction.json
Execution — 100%, 2 of 2 checks pass
✓ghost-read reports are accumulating → docs/reports/ghost-read
✓the entry surface is live → public/pixel.html
Market — 100%, 3 of 3 checks pass
✓posts are actually being read → data/clicks.db
✓breadth of readership, not one viral post → data/clicks.db
✓the book itself is being opened → data/clicks.db
52D1📣Earn outside citation.1 open
Specification — 100%, 1 of 1 checks pass
✓the bar for an outside verification is defined → packages/thetacog-mcp/REGISTRY.md
Execution — 100%, 1 of 1 checks pass
✓graded posts prove the pipeline runs → src/content/blog/*.grade.json
Market — 50%, 1 of 2 checks pass
✓a named third party is on the endorsements page → src/app/endorsements/page.tsx
✗the registry holds someone other than us → packages/thetacog-mcp/REGISTRY.md
104B4🎧Curate notebook retellings.1 openC673
Specification — 100%, 1 of 1 checks pass
✓the 2026-10-07 NotebookLM batch is catalogued in the repo: clean / one caption / do-not-share, with the overclaim ladder → docs/10-scratchpad/notebooklm-catalogue-2026-10-07.txt
Execution — 100%, 1 of 1 checks pass
✓the regression finding is written down: 5 of 10 files put back a cut overclaim, and the source scratchpad that seeded it is named → docs/10-scratchpad/notebooklm-catalogue-2026-10-07.txt
Market — 0%, 0 of 1 checks pass
✗one of the three clean retellings left the machine to a reader who is not us (red until the operator shares one) → .thetacog/email-sent.ndjson

♟️The Board🔌 C1.Operations.Grid 🔨12 items · 11 open

10 of 92 declared evidence paths fall inside The Builder's owned surface

The light switch. Writing to the party whose plausible deniability the receipt breaks produced silence, and it will keep producing silence, because that party is pinned by its own balance sheet. This list stops selling to the defendant and shows the board to everyone whose self-interest already profits when the deniability breaks: plaintiff, bad-faith and ERISA counsel, relators’ counsel, litigation funders, treaty reinsurers and syndicates who write exclusions, MGA and parametric underwriters who can price the clean body, self-insured plan fiduciaries who pay the TPA, forensic researchers, and the defense counsel and integrators hired after the subpoena. The hinge is The T.J. Hooper (2d Cir. 1932): industry custom is not the standard of care when a cheap, available precaution exists. The storefront makes the precaution free (MIT) and public; only underwriting and attestation are licensed. None of these parties need to talk to each other. They need to see the same board. Who holds each job, and why it pays them, lives in data/board-jobs.json and is rendered below the lists.

How to read this list →

Read it as a sequence of other people’s acts, which is why almost every market check reads a testimony ledger (data/board/ledger.ndjson, data/board/dockets.ndjson) that only a real outside act may write. The A phase is ours: the standard is published and dated, and the kit says what a receipt is sufficient for and what it is not, before anyone relies on it. The B phase arms one lane per class that profits: counsel, funders, plan fiduciaries, researchers. The C phase is the first outside act that names the standard: a docket, a rider, a fiduciary asking its TPA for the record. The D phase is the downstream market: fixers hired after the demand, and an underwriter quoting the clean body. The E phase is the switch itself: custom stops working as a defense. Today the storefront is live and the kit is not written, so the list is stuck at its second rung. The double exponential (agents per employee times steps per agent) drives the share of work a human reviews toward zero, which is why this is geometry and not persuasion: the field, in full, is at /blog/2026-09-11-an-exponential-is-a-foam-knife-in-the-kidney.

Enters & leaves (4) →
← ⚖️ Legal Standardization
Takes the negative warranty and the exclusions as the kit’s limits. The discovery guide may never claim more than the legal list fences, because the first overclaim is impeached on deposition.
← 📖 The Argument
Takes the public recompute as the precaution the Hooper argument needs. A precaution nobody outside can run is not cheap and not available, so the argument list is what makes B low.
→ 💰 Commercial Extraction
Hands the commercial list counterparties who arrive already holding the question. A carrier that met a receipt in discovery is a different buyer from one that received a deck.
← 📮 Market Contact
Uses the contact ratchet to reach each ally class, and counts only replies. A lane brief that reached nobody leaves the B rung red, as it should.
80A1♟️Publish care standard.C432✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/legal/continuous-standard-of-care-reference-standard.md, ./data/board-jobs.json, src/app/standard/page.tsx.
Specification — 100%, 3 of 3 checks pass
✓the reasonable-care standard is written, dated, and states what it is NOT sufficient for before what it is → docs/legal/continuous-standard-of-care-reference-standard.md
✓the standard carries the Hooper calculus — custom is not care when a cheap precaution exists → docs/legal/continuous-standard-of-care-reference-standard.md
✓the job of keeping the storefront is held by someone → ./data/board-jobs.json
Execution — 100%, 3 of 3 checks pass
✓the /standard page carries the Hooper argument → src/app/standard/page.tsx
✓the /standard page says the measurement is free and open-source (MIT) — the precaution is cheap and available → src/app/standard/page.tsx
✓the /standard page hands over the recompute command a stranger runs → src/app/standard/page.tsx
Market — 100%, 2 of 2 checks pass
✓the live /standard answers a cold fetch with the Hooper argument on it → thetadriven.com/standard
✓the live /standard says the measurement is MIT → thetadriven.com/standard
81A2🗡️Arm discovery requests.1 openC433
Specification — 100%, 2 of 2 checks pass
✓the discovery guide says what a receipt is NOT sufficient for before what it is → docs/board/receipt-discovery-guide.md
✓the preservation letter names automated decision records as ESI under FRCP 37(e) → docs/board/preservation-letter-template.md
Execution — 100%, 2 of 2 checks pass
✓the guide reads clean under the behavior-promise families (never a brake, never an engine, never a proof of safety) → docs/board/receipt-discovery-guide.md
✓a guard holds the kit to its limits → tests/board/c433-discovery-kit.test.mjs
Market — 0%, 0 of 1 checks pass
✗someone outside the building asked for the kit (testimony, written only when it happens) → data/board/ledger.ndjson
82B1⚖️Brief plaintiff counsel.1 openC434
Specification — 100%, 2 of 2 checks pass
✓the counsel lane is written as jobs with self-interest and a handed artifact → ./data/board-jobs.json
✓the plaintiff-counsel lane brief exists → docs/board/lanes/plaintiff-counsel.md
Execution — 100%, 2 of 2 checks pass
✓the testimony ledger has a door with a fixed key order → scripts/board/ledger.mjs
✓one graded draft to one counsel practice is composed (arming stays the operator’s act) → docs/outreach/drafts
Market — 0%, 0 of 1 checks pass
✗a plaintiff-side practice replied (testimony) → data/board/ledger.ndjson
83B2💼Seed funder diligence.1 openC435
Specification — 100%, 2 of 2 checks pass
✓the funder lane is written as jobs → ./data/board-jobs.json
✓the funder diligence question set exists → docs/board/lanes/litigation-funder.md
Execution — 100%, 1 of 1 checks pass
✓a guard holds the question set to the kit’s limits → tests/board/c435-funder-questions.test.mjs
Market — 0%, 0 of 1 checks pass
✗a funder added the receipt question to a diligence list (testimony) → data/board/ledger.ndjson
84B3🛡️Equip plan fiduciaries.1 openC436
Specification — 100%, 2 of 2 checks pass
✓the plan-fiduciary lane is written as jobs → ./data/board-jobs.json
✓the fiduciary brief grounds the ask in ERISA prudence → docs/board/lanes/plan-fiduciary.md
Execution — 100%, 1 of 1 checks pass
✓one graded draft to one benefits committee or fund counsel is composed → docs/outreach/drafts
Market — 0%, 0 of 1 checks pass
✗a plan fiduciary replied (testimony) → data/board/ledger.ndjson
85B4🔬Verify independent replication.1 openC437
Specification — 100%, 2 of 2 checks pass
✓the researcher lane is written as jobs → ./data/board-jobs.json
✓every step a stranger takes is on the record (the cold dry run) → docs/receipts/dry-run
Execution — 100%, 1 of 1 checks pass
✓the replication packet names the public receipt and the one command → docs/board/lanes/forensic-researcher.md
Market — 0%, 0 of 1 checks pass
✗an outside research group published a recompute, agreeing or not (testimony) → data/board/ledger.ndjson
86C1📑Earn docket citation.1 openC438
Specification — 100%, 1 of 1 checks pass
✓what counts as a citation is written down (a public filing, with its docket reference) → docs/board/docket-watch.md
Execution — 100%, 1 of 1 checks pass
✓the docket watcher exists and is guarded → scripts/board/docket-watch.mjs
Market — 0%, 0 of 1 checks pass
✗a public filing cites the standard or a receipt (testimony, with its docket reference) → data/board/dockets.ndjson
87C2📜Word receipt rider.1 openC439
Specification — 100%, 2 of 2 checks pass
✓an endorsement for continuous state verification is drafted → docs/legal/endorsement-cy-2026-det-continuous-state-verification.md
✓the model carve-back clause references receipts against a declared lane → docs/board/rider-reference-clause.md
Execution — 100%, 1 of 1 checks pass
✓the clause reads clean under the behavior-promise families → docs/board/rider-reference-clause.md
Market — 0%, 0 of 1 checks pass
✗a reinsurer or syndicate wording references the standard (testimony) → data/board/ledger.ndjson
88C3🧾Demand TPA receipts.1 openC440
Specification — 100%, 2 of 2 checks pass
✓the TPA letter asks only for what 29 C.F.R. 2560.503-1 already covers → docs/board/tpa-receipt-request-letter.md
✓the TPA jobs are written, duty and counterparty → ./data/board-jobs.json
Execution — 100%, 1 of 1 checks pass
✓a guard holds the letter to the regulation’s own words → tests/board/c440-tpa-letter.test.mjs
Market — 0%, 0 of 1 checks pass
✗a self-insured plan asked its TPA for the record (testimony) → data/board/ledger.ndjson
89D1🧰Convert enterprise fixers.1 openC441
Specification — 100%, 1 of 1 checks pass
✓the fixer lanes (defense counsel, integrators) are written as jobs → ./data/board-jobs.json
Execution — 100%, 2 of 2 checks pass
✓the adapters page carries the consult a fixer is hired into → src/app/adapters/page.tsx
✓the adapters page names the post-subpoena lane → src/app/adapters/page.tsx
Market — 0%, 0 of 1 checks pass
✗a defense firm or integrator engaged on a deployer’s record (testimony) → data/board/ledger.ndjson
90D2🏦Price clean risk.1 openC442
Specification — 100%, 1 of 1 checks pass
✓the clean-risk sheet’s columns are specified from receipt fields → docs/board/clean-risk-sheet.md
Execution — 100%, 1 of 1 checks pass
✓the sheet is computed from receipts and guarded → scripts/board/clean-risk-sheet.mjs
Market — 0%, 0 of 1 checks pass
✗an MGA or syndicate quoted the clean body (testimony) → data/board/ledger.ndjson
91E1🕯️Close custom defense.1 openC443
Specification — 100%, 1 of 1 checks pass
✓the Hooper argument is written for this record: B is the free measurement, PL is the loss it would have placed → docs/board/custom-defense.md
Execution — 100%, 1 of 1 checks pass
✓a guard holds the argument to cited authority only → tests/board/c443-custom-defense.test.mjs
Market — 0%, 0 of 1 checks pass
✗a public decision or wording rejects industry custom as the standard for agent records (testimony, with its reference) → data/board/dockets.ndjson

💰Commercial Extraction🔌 C1.Operations.Grid 🔨17 items · 21 open

17 of 106 declared evidence paths fall inside The Builder's owned surface

This is the collision point between our architecture and the market's reality. We are targeting tier-one carriers and private equity stakeholders not for theoretical feedback, but to extract the exact friction preventing capital deployment. By pushing a paid pilot framework, we force underwriters to reveal their true objections, which we immediately patch in the Legal vector. This track does not end until we have secured a signed LOI, banked the first cheque, and scaled a frictionless facility to mint insured agent-year licences at high volume.

How to read this list →

This is the bottleneck and the page says so without being asked. Every list above it is built; this one is the reason none of it has converted. Read the sequence as a funnel that currently stops dead in the B phase: carriers are named, the docket has been briefed to real people at Marsh, Munich Re and AIG, objections have been captured in depth — and then nothing. No letter of intent, no cheque, no bound policy. The E phase describes a machine that mints insured licences without a human, and every mechanism for it is already built, which makes the emptiness of B3 and B4 the whole story. The front door has produced silence: selling the measurement to the party whose deniability it breaks asks them to fund their own discovery. The board list is the other door — it arms the parties whose self-interest already profits when that deniability breaks, and this list inherits whatever they move.

Enters & leaves (4) →
← ⚖️ Legal Standardization
Carries the docket into the room, and carries the objections back out. The loop is the point: an objection that does not become a wording change was just a bad meeting.
← ⚙️ Technical Integration
Uses the runnable proof as the opening move rather than the closing one — you do not have to trust this, run it.
← 📚 Book Club
Receives warm introductions. A reader who volunteers an introduction converts at a rate no cold approach to the same person ever reaches.
← ♟️ The Board
Receives the parties the board armed. A carrier that met a receipt in a discovery request, a rider, or a fiduciary letter arrives here already holding the question the front door could not get it to ask.
What is left · 21 open (derived, never typed)
✗9 A1 five NAMED humans at writer institutions (carriers, reinsurers, syndicates — a broker is a door, not a writer) show human-shaped engagement in the arbiter's mirror: clicked, on a MINORITY of sends (a gateway clicks every one) — never read from the ndjson that froze on 2026-07-21 → data/thetacoach.db✗9 A1 at least one of them is at a Lloyd's syndicate or a Lloyd's-backed coverholder (Beazley, Chaucer, Hiscox, Armilla) — lloyds.com is the Corporation, not a writer → data/thetacoach.db✗16 B1 a claim from a device that is not ours is on the record → data/licence-claims.ndjson✗26 B4 a runtime-security vendor is a RECIPIENT in the send ledger, not just a subject line we wrote to ourselves → .thetacog/email-sent.ndjson✗26 B4 a vendor licence is on the ledger → data/licenses-sold.ndjson✗31 B5 a signed LOI is on file → docs/legal/loi/*.pdf+15 more open on this list
9A1🎯Reach five writers.2 open
Specification — 100%, 5 of 5 checks pass
✓a named target list exists → docs/strategy/underwriter-targets-2026-05.md
✓it distinguishes lead capacity from follow capacity → docs/strategy/underwriter-targets-2026-05.md
✓it reaches the syndicate layer, not just carriers → docs/strategy/underwriter-targets-2026-05.md
✓the buyers roster names who already bets FOR the peril (a live AI trigger, a sublimit, a coverholder) with every claim tagged SELF-STATED / THIRD-PARTY / UNVERIFIED → docs/outreach/2026-09-13-linkedin-buyers-25-titles.json
✓the first outbound to a writer leads with our own failing reading, null attached, before anything green — and no address is asserted outside our own send tape (every other route says VERIFY) → docs/comms/external/drafts/2026-09-15-underwriter-six-drafts-v1-NOT-ARMED.md
Execution — 100%, 2 of 2 checks pass
✓the underwriter ecosystem is mapped → docs/strategy/underwriter-ecosystem-spec.md
✓no placeholder address mailed since 2026-09-01 (date-bounded 2026-09-03: the ledger is append-only with 51 historical placeholder rows, so an all-history -eq 0 could never flip — AXIOM 1 W4, retention is prospective-only) → .thetacog/email-sent.ndjson
Market — 0%, 0 of 2 checks pass
✗five NAMED humans at writer institutions (carriers, reinsurers, syndicates — a broker is a door, not a writer) show human-shaped engagement in the arbiter's mirror: clicked, on a MINORITY of sends (a gateway clicks every one) — never read from the ndjson that froze on 2026-07-21 → data/thetacoach.db
✗at least one of them is at a Lloyd's syndicate or a Lloyd's-backed coverholder (Beazley, Chaucer, Hiscox, Armilla) — lloyds.com is the Corporation, not a writer → data/thetacoach.db
16B1🔑Claim stranger keys.1 openC102a
Specification — undeclared: nobody has written a check for this yet, which is not the same as zero
Execution — 100%, 1 of 1 checks pass
✓the site's licence door exists and writes a claims record, never the local snapshot → src/app/api/license
Market — 0%, 0 of 1 checks pass
✗a claim from a device that is not ours is on the record → data/licence-claims.ndjson
18B2🗣️Quote unmetered runs.✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/outreach/2026-06-22-marsh-discovery-proposal.html, docs/comms/external/drafts/2026-07-22-broker-leave-behind.md, docs/outreach/2026-06-01-insurer-leave-behind.pdf, docs/outreach/accounts/marsh-pack/marsh-agenda.html, scripts/comms/canonical-send.sh, .thetacog/email-sent.ndjson.
Specification — 100%, 2 of 2 checks pass
✓a discovery proposal exists → docs/outreach/2026-06-22-marsh-discovery-proposal.html
✓a broker leave-behind is written → docs/comms/external/drafts/2026-07-22-broker-leave-behind.md
Execution — 100%, 3 of 3 checks pass
✓the leave-behind is a real PDF, not a plan → docs/outreach/2026-06-01-insurer-leave-behind.pdf
✓an account pack exists → docs/outreach/accounts/marsh-pack/marsh-agenda.html
✓the canonical send pipeline exists → scripts/comms/canonical-send.sh
Market — 100%, 3 of 3 checks pass
✓a named Marsh person was written to → .thetacog/email-sent.ndjson
✓a named Munich Re person was written to → .thetacog/email-sent.ndjson
✓a named Lloyds person was written to → .thetacog/email-sent.ndjson
25B3🪝Map underwriter objections.✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/ops/outreach-learnings-2026-07-14.md, docs/ops/burned-openers.txt, data/person-context/mary-quinn-bc9cba.md, data/thetacoach.db, docs/outreach/marsh-denny-learnings-2026-08-05.txt.
Specification — 100%, 2 of 2 checks pass
✓outreach learnings are written down → docs/ops/outreach-learnings-2026-07-14.md
✓burned openers are recorded so they are not reused → docs/ops/burned-openers.txt
Execution — 100%, 2 of 2 checks pass
✓per-person context files exist → data/person-context/mary-quinn-bc9cba.md
✓engagement is confirmed by the provider — read from the arbiter's synced mirror, never the ndjson that froze on 2026-07-21 → data/thetacoach.db
Market — 100%, 3 of 3 checks pass
✓objections from a real account are captured → docs/outreach/marsh-denny-learnings-2026-08-05.txt
✓captured in depth, not as a note → docs/outreach/marsh-denny-learnings-2026-08-05.txt
✓the named person actually engaged — an open or click on the arbiter's mirror, not an address in a frozen file → data/thetacoach.db
26B4🔌Convert guardrail vendors.2 open
Specification — 100%, 2 of 2 checks pass
✓the per-agent licence terms exist as a document a vendor could sign → docs/legal/agent-year-license-terms.md
✓the split that makes an enforcement vendor a customer rather than a rival is in the standing rules
Execution — 100%, 2 of 2 checks pass
✓the licence is a surface a vendor could buy from, not a conversation → src/app/pricing/page.tsx
✓the stamp is a signed artifact rather than a plan → packages/thetacog-mcp/intentguard/src/attest.rs
Market — 0%, 0 of 2 checks pass
✗a runtime-security vendor is a RECIPIENT in the send ledger, not just a subject line we wrote to ourselves → .thetacog/email-sent.ndjson
✗a vendor licence is on the ledger → data/licenses-sold.ndjson
31B5✍️Bind rating basis.2 open
Specification — 100%, 1 of 1 checks pass
✓an LOI template exists → docs/legal/loi-template.md
Execution — 100%, 2 of 2 checks pass
✓a pre-LOI discovery proposal exists → docs/outreach/2026-06-22-marsh-discovery-proposal.html
✓the LOI is a reachable surface, not a file on the operator disk → src/app/loi/page.tsx
Market — 0%, 0 of 2 checks pass
✗a signed LOI is on file → docs/legal/loi/*.pdf
✗an underwriter accepted the receipt as the rating unit → docs/underwriting/rating-basis-agreed.md
32B6🌱Seed kinetic agents.2 open
Specification — 100%, 2 of 2 checks pass
✓the terms a seed account signs exist as a template → docs/legal/loi-template.md
✓the seed size is derived from the model, not picked → docs/strategy/2026-08-29-license-double-exponential-bottom-up.html
Execution — 100%, 1 of 1 checks pass
✓the LOI is reachable and can be signalled against → src/app/loi/page.tsx
Market — 0%, 0 of 2 checks pass
✗pilot fleets are on the ledger, not in a pipeline document → data/pilots-signed.ndjson
✗the seed clears two thousand licensed agents → data/pilots-signed.ndjson
33B7💰Collect first toll.1 openC84f
Specification — 100%, 1 of 1 checks pass
✓an invoice surface exists → src/app/invoice/page.tsx
Execution — 100%, 1 of 1 checks pass
✓payment rails are wired → src/app/api/stripe-webhook/route.ts
Market — 0%, 0 of 1 checks pass
✗a payment actually settled → data/revenue.ndjson
45C1🤝Validate parametric triggers.3 open
Specification — 100%, 2 of 2 checks pass
✓parametric extraction is written up → docs/01-business/boi-parametric-extraction-2026-07-28.md
✓the licensor questions were answered → docs/specs/open-questions-v2-parametric-licensor-2026-07-26.txt
Execution — 67%, 2 of 3 checks pass
✓a claim function exists in the policy contract → contracts/InLanePolicy.sol
✓the attestation contract is tested → contracts/test/ReefAttestation.t.sol
✗the backtest series clears its own 30-row floor → attest-out/backtest-series.ndjson
Market — 0%, 0 of 2 checks pass
✗a carrier agreed the trigger in writing → docs/underwriting/trigger-agreed.md
✗a carrier wording committee accepted the endorsement clauses → docs/underwriting/wording-accepted.md
53D1🏷️Lock pricing model.1 open
Specification — 100%, 2 of 2 checks pass
✓licence terms are written → docs/legal/agent-year-license-terms.md
✓the underwriter ecosystem spec exists → docs/strategy/underwriter-ecosystem-spec.md
Execution — 100%, 3 of 3 checks pass
✓the advisory premium is computed → scripts/pmu/advisory-premium.mjs
✓a real computed premium artifact exists → attest-out/advisory-premium.json
✓we are guarded against promising a premium reduction → tests/pricing/no-premium-reduction-promise.test.js
Market — 50%, 1 of 2 checks pass
✓an actual price is printed, not a contact-us → src/app/pricing/page.tsx
✗a premium was quoted to a real counterparty → data/quotes-issued.ndjson
58E1🌐Distribute syndicate asset.✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/decks/insure-rounds/deck-insure-v5.txt, docs/decks/ai-insurance-evidence-2026-08-13.md, src/app/insurability/page.tsx, src/app/brokers/page.tsx, docs/decks/insure-rounds/round-2-email.html, .thetacog/email-sent.ndjson.
Specification — 100%, 2 of 2 checks pass
✓the insurance deck is at v5 → docs/decks/insure-rounds/deck-insure-v5.txt
✓the evidence pack exists → docs/decks/ai-insurance-evidence-2026-08-13.md
Execution — 100%, 2 of 2 checks pass
✓the insurability surface is live → src/app/insurability/page.tsx
✓a broker surface is live → src/app/brokers/page.tsx
Market — 100%, 2 of 2 checks pass
✓the round-2 asset was actually mailed → docs/decks/insure-rounds/round-2-email.html
✓the syndicate report was actually mailed → .thetacog/email-sent.ndjson
59E2⏩Ship zero-touch gate.1 open
Specification — 100%, 2 of 2 checks pass
✓the zero-touch waterfall is specified → docs/skip-formula/WATERFALL-INVENTORY-30-90-DAYS.md
✓zero-touch is named in it → docs/skip-formula/WATERFALL-INVENTORY-30-90-DAYS.md
Execution — 100%, 3 of 3 checks pass
✓the gate exists → scripts/pmu/underwriter-gate.mjs
✓it refuses rather than guesses when data is thin → scripts/pmu/underwriter-gate.mjs
✓it grades without a human → scripts/pmu/underwriter-grade.mjs
Market — 0%, 0 of 1 checks pass
✗a policy was bound with no human review → data/auto-bound.ndjson
60E3🏦Price first tranche.1 open
Specification — 100%, 3 of 3 checks pass
✓the options-on-confidence GTM exists → docs/research/options-on-confidence-gtm.md
✓it engages real structures, not analogies → docs/research/options-on-confidence-gtm.md
✓a derivatives brief exists → docs/specs/drafts/operator-competence-derivatives-brief-v1.md
Execution — 100%, 1 of 1 checks pass
✓a facility term sheet exists → docs/capital/facility-term-sheet.md
Market — 0%, 0 of 1 checks pass
✗capital is committed → docs/capital/committed.md
61E4🪪Mint insured licenses.1 open
Specification — 100%, 2 of 2 checks pass
✓licence terms are written → docs/legal/agent-year-license-terms.md
✓the licence tape schema exists → docs/crm/license-keys-tape-setup.sql
Execution — 100%, 3 of 3 checks pass
✓minting is implemented → src/lib/license/mint.ts
✓payment mints a licence → src/app/api/webhooks/stripe-iamfim/route.ts
✓each licence is signed per agent-year → src/lib/license/signing.ts
Market — 67%, 2 of 3 checks pass
✓the buy gesture exists on the page, not just the page → src/app/agent-year/page.tsx
✓it has been announced → .thetacog/email-sent.ndjson
✗a seat actually sold → data/licenses-sold.ndjson
72B8💺Bank first seat.2 openC84c · C94c
Specification — undeclared: nobody has written a check for this yet, which is not the same as zero
Execution — 100%, 1 of 1 checks pass
✓a settled Stripe checkout writes the seat row on the credits ledger, never a hand → src/app/api/stripe-webhook/route.ts
Market — 0%, 0 of 2 checks pass
✗a licence is on the ledger (the funnel read it, with its date) → ./data/vna/licence-funnel.json
✗the first buyer who is not us is written down by name and date (a key that is not this host's can still be us on another machine, so the ledger alone cannot say it) → docs/receipts/first-foreign-seat.md
78C2🏷️Show priced deviations.1 openC361
Specification — undeclared: nobody has written a check for this yet, which is not the same as zero
Execution — 100%, 1 of 1 checks pass
✓the underwriting script turns a placed deviation into a priced number → scripts/vna/underwriting.mjs
Market — 0%, 0 of 1 checks pass
✗the receipt page shows the price next to the deviation, recomputable from the commit → src/app/verify-receipt
105B9🔀Earn forwarded installs.1 openC635 · C635a · C635b · C635f
Specification — 100%, 1 of 1 checks pass
✓row C635 (the buyer and the installer never meet) is declared with its guard → docs/specs/vna/SPEC-VNA-COCKPIT.md
Execution — 100%, 1 of 1 checks pass
✓the extension shows a buy door from second zero, and /iamfim carries the forward-to-the-installer action → tests/vna/c635a-the-buy-door-from-second-zero.test.mjs
Market — 0%, 0 of 1 checks pass
✗a ref-tagged arrival (ref=fwd or ref=ext-statusbar) is on the page log (red while the funnel reads UNMEASURED for both doors) → ./data/vna/licence-funnel.json

📮Market Contact🔌 C1.Operations.Grid 🔨15 items · 15 open

14 of 78 declared evidence paths fall inside The Builder's owned surface

Every other list here produces something that is true whether or not a stranger cooperates; this is the only one that cannot be finished from inside the building. Market contact is a ratchet with three teeth and they turn in order: an outbound approach that reaches a named counterparty, a grassroots reply nobody solicited, and — where a public claim is false and the party will not answer it — a disclosed escalation ladder that ends at an institution rather than at an invoice. The three surfaces are already public and already point at each other. /playbook is the ladder, published in full with every rung's mitigation before the first rung can fire, so the party sees the whole thing in advance. /resources is the master key that ships with the advisory invoice, so a recipient can check every implication without asking us for anything. /cta is the lever a reader reaches for after finishing the book. The scoreboard is deliberately unflattering: the win is a false claim retracted, not a payment extracted.

How to read this list →

Read this as the one list the repo cannot mark its own homework on, which is why almost every check here fetches production or reads a ledger instead of testing that a file exists. The A phase is genuinely done and says so from outside: all three surfaces answer a cold fetch, the ladder carries a mitigation on every rung, and the invoice hands over the pack rather than a salesperson. Then it splits in two. Outbound is real — forty-one dispatches through the pipeline, a hundred and fifty logged sends, seven distinct carrier and broker domains in the send ledger. Reply is not: six recorded clicks, and no ledger of an unsolicited inbound anywhere. Everything from the C phase down waits on one missing artifact. The register that counts asked / answered / refuted is specified on the ladder's second rung and printed there as zero — honestly, because it does not exist — and four items point at data/register/ with every one of them red. No rung has fired, and none should until the count is real.

Enters & leaves (5) →
→ 💰 Commercial Extraction
Hands the funnel its top. An objection cannot be mapped before somebody has been reached, and this is the list that does the reaching — every named counterparty in the commercial track arrived through a vector declared here.
← 📚 Book Club
Takes the warm introduction and spends it. A reader who volunteers an intro arrives here as a named counterparty rather than as another cold address, which is the entire reason the slow track is worth its slowness.
← 📖 The Argument
Takes the manuscript and the runnable proof and makes them the opening move instead of the closing one. /resources is the argument, packaged so a stranger can check it with nobody from here in the room.
→ ⚖️ Legal Standardization
Returns what the market actually said. A refusal that names a wording is a wording change; a refusal that names nothing was a bad meeting, and the ladder exists for the case where there is no reply at all.
→ ♟️ The Board
Hands the board its reach. Every ally lane on the board is a named class this ratchet already knows how to reach, and every reply it records is testimony the board ledger reads.
11A1📮Disclose licensing ladder.1 openC698
Specification — 100%, 2 of 2 checks pass
✓the pressure doctrine is written down — the accused is never the audience → docs/ops/the-respectable-win-2026-08-06.md
✓the outreach spec names the rooms, the vectors and the send gate → docs/ops/email-iterations/sovereign-outreach-spec.html
Execution — 100%, 3 of 3 checks pass
✓every rung carries a mitigation, published before it can fire → src/app/playbook/page.tsx
✓the ladder ends at an institution, not at an invoice → src/app/playbook/page.tsx
✓the ladder sells a tape, never a brake or an engine — the page reads clean under the ENGINE / SAFETY_PROOF / BRAKE families, and hands the reader the meter in a browser before rung one → src/app/playbook/page.tsx
Market — 50%, 1 of 2 checks pass
✓a stranger can read the whole ladder before rung one fires → dev/null
✗a named party has actually been served it → thetadriven.com/playbook
12A2🗝️Equip cold prospects.1 openC696
Specification — 100%, 2 of 2 checks pass
✓the enrollment policy says who may be contacted at all → docs/outreach/ENROLLMENT-POLICY.md
✓the outreach template opens on an attackable claim → docs/outreach/_template.mdx
Execution — 100%, 3 of 3 checks pass
✓the pack hands over every implication rather than a summary → src/app/resources/page.tsx
✓the invoice points at the pack instead of at a salesperson → src/app/invoice/page.tsx
✓a prospect's own key is the key the run spends — Set on ⚙️ Engine & Keys round-trips to held, and every runner door (⚡ Run Headless, 💬 chat) spawns on the SecretStorage env rather than the inherited one (C239 eb2a595f84 · C239a c850b90bcc; 103 of 103 headless worker rows over 36 h had read key_source none before it) → packages/thetacog-mcp-vscode/src/vna-engines.ts
Market — 67%, 2 of 3 checks pass
✓it reaches a stranger with no login and nothing under NDA → dev/null
✗a prospect has been sent it → thetadriven.com/resources
✓the free install is live on the VS Code Marketplace under our publisher — read from the gallery API, never the item page, which answers 200 for any name (thetadriven.thetacog-mcp; the gallery carried 0.3.42 on 2026-09-24 while git held 0.3.44 — the version live is whatever the gallery says, not what is installed here) → marketplace.visualstudio.com/_apis/public/gallery/extensionquery
13A3🔥Arm finished readers.1 openC700
Specification — 100%, 2 of 2 checks pass
✓the win condition is declared — a claim retracted, not a payment extracted → src/app/cta/page.tsx
✓the reader is aimed at the condition, never at a person → src/app/cta/page.tsx
Execution — 100%, 1 of 1 checks pass
✓the page is a lever list, not a newsletter signup → src/app/cta/page.tsx
Market — 50%, 1 of 2 checks pass
✓a reader arriving from the book lands on something live → dev/null
✗a book-club send has pointed a reader at it → thetadriven.com/cta
14B1🎟️Grant tester licences.1 open
Specification — undeclared: nobody has written a check for this yet, which is not the same as zero
Execution — 100%, 1 of 1 checks pass
✓a grant is a committed row on the grant ledger, never a remembered promise → data/meetings/grant-actions.ndjson
Market — 50%, 1 of 2 checks pass
✓the tester invite left the machine, armed by the operator → .thetacog/email-sent.ndjson
✗a reply came back that was answered with a grant → .thetacog/inbound-replies.ndjson
15B2🧭Map new tribes.
Specification — 100%, 1 of 1 checks pass
✓the tribes list exists with a sourced reason per tribe → docs/strategy/*new-tribes*
Execution — undeclared: nobody has written a check for this yet, which is not the same as zero
Market — 100%, 1 of 1 checks pass
✓one tribe has been handed its first checkable sentence → .thetacog/email-sent.ndjson
34B3☕Reach named counterparties.✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: scripts/outreach/precommit.mjs, docs/outreach/_hostile-diligence-card.md, .thetacog/comms/dispatch-log.ndjson, .thetacog/email-sent.ndjson, .thetacog/outreach-log.ndjson.
Specification — 100%, 2 of 2 checks pass
✓the send gate blocks an unreviewed outreach file → scripts/outreach/precommit.mjs
✓the hostile-diligence card names what a buyer will attack first → docs/outreach/_hostile-diligence-card.md
Execution — 100%, 2 of 2 checks pass
✓the pipeline has moved real files all the way to sent → docs/outreach/sent/*.mdx
✓the dispatch log records sends, not intentions → .thetacog/comms/dispatch-log.ndjson
Market — 100%, 2 of 2 checks pass
✓named carrier and broker addresses are in the send ledger → .thetacog/email-sent.ndjson
✓each approach carried a per-person finding rather than a blast → .thetacog/outreach-log.ndjson
35B4📬Earn unsolicited replies.1 open
Specification — 100%, 1 of 1 checks pass
✓the follow-up protocol rotates the key or the vector rather than repeating a send → docs/outreach/README.md
Execution — 100%, 1 of 1 checks pass
✓the reply sweep runs rather than being described → .thetacog/email-sent.ndjson
Market — 50%, 1 of 2 checks pass
✓an external party clicked something we sent — read from the arbiter's synced mirror, never the ndjson that froze on 2026-07-21 → data/thetacoach.db
✗an inbound reply nobody asked for is on the ledger → .thetacog/inbound-replies.ndjson
48C1🧾Publish non-response register.✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: src/app/playbook/page.tsx, data/register/non-response.ndjson.
Specification — 100%, 1 of 1 checks pass
✓the second rung specifies the format and prints its own zero → src/app/playbook/page.tsx
Execution — 100%, 1 of 1 checks pass
✓the register is rows on disk, not a number on a page → data/register/non-response.ndjson
Market — 100%, 1 of 1 checks pass
✓the count is public and a reader can recompute it → thetadriven.com/benchmark
56D1🎯Demand operator license.2 open
Specification — 100%, 1 of 1 checks pass
✓rung one is a question the party can close by answering → src/app/playbook/page.tsx
Execution — 0%, 0 of 1 checks pass
✗a fire is recorded with its date and its fourteen-day window → data/register/rungs-fired.ndjson
Market — 0%, 0 of 1 checks pass
✗a named party has been served rung one → .thetacog/email-sent.ndjson
57D2🏛️Issue unmetered notice.2 open
Specification — 100%, 1 of 1 checks pass
✓each channel is named with the authority that answers it → src/app/playbook/page.tsx
Execution — 0%, 0 of 1 checks pass
✗a filing is logged before it leaves, counsel review included → data/register/filings.ndjson
Market — 0%, 0 of 1 checks pass
✗an outcome is on the record, dismissals included → data/register/filing-outcomes.ndjson
62E1🏳️Enforce license purchase.2 open
Specification — 100%, 1 of 1 checks pass
✓the win is defined as a retraction and never as a payment → src/app/cta/page.tsx
Execution — 0%, 0 of 1 checks pass
✗a retraction is logged against the claim it answers → data/register/retractions.ndjson
Market — 0%, 0 of 1 checks pass
✗a public false claim has actually been retracted → data/register/retractions.ndjson
73B5🧭Fire first fifty.1 open
Specification — undeclared: nobody has written a check for this yet, which is not the same as zero
Execution — 100%, 1 of 1 checks pass
✓the cohort goes out through one door that logs every send exactly once → scripts/bookclub/nominate-cohort.mjs
Market — 0%, 0 of 1 checks pass
✗fifty people who code, or sit next to people who do, got the one-question email → .thetacog/nominate-cohort.ndjson
74B6⚡Pitch kinetic desks.1 open
Specification — 100%, 1 of 1 checks pass
✓the kinetic list names trading, ad-tech and fraud desks with a reason each → data/outreach/kinetic-desks.json
Execution — undeclared: nobody has written a check for this yet, which is not the same as zero
Market — 0%, 0 of 1 checks pass
✗ten desks where an agent error bleeds money got the email → data/outreach/kinetic-desks.json
75C2🏦Secure risk introductions.1 open
Specification — undeclared: nobody has written a check for this yet, which is not the same as zero
Execution — undeclared: nobody has written a check for this yet, which is not the same as zero
Market — 0%, 0 of 1 checks pass
✗three people who sign for AI risk were introduced by someone who knows them, each naming who opened the door → data/outreach/risk-owner-intros.ndjson
106B7📨Answer broker question.1 openC635e · C652c
Specification — 100%, 1 of 1 checks pass
✓the answer to Paul Denny's 2026-08-19 question (where is the FINPRO angle) is drafted → docs/comms/external/drafts/2026-09-22-finpro-angle-for-paul-denny-v2.md
Execution — 100%, 1 of 1 checks pass
✓the draft opens on his own sentence and carries the check he can run (attest-demo) → docs/comms/external/drafts/2026-09-22-finpro-angle-for-paul-denny-v2.md
Market — 0%, 0 of 1 checks pass
✗a FINPRO-angle answer to Paul Denny is on the send tape (the 2026-09-14 send was a general note, not this answer; red until the operator arms it) → .thetacog/email-sent.ndjson

📜Patent & IP🔌 C1.Operations.Grid 🔨6 items · 5 open

7 of 48 declared evidence paths fall inside The Builder's owned surface

A claim set is a bet nobody has scored yet. This vector runs the prosecution of US 19/637,714 — thirty-six claims, filed 2026-04-02 on Track One, carrying the benefit of seven provisionals back to April 2025 — as a docket rather than a memory. Every application, every priority date and every statutory bar lives in one file beside the document the date was read out of, and a passed deadline with nothing recorded as filed turns the build red. The most valuable output is the negative one: a chart naming which claims the shipped code does not practise, stated plainly before a diligence lawyer or a licensee asks. Prosecution ends when the monopoly is priced per agent and someone pays it.

How to read this list →

Read this track deadline-first, because unlike every other list here its clock runs whether or not anyone is looking. The A phase is genuinely done — the application is filed, the priority chain is intact, the as-filed papers are on disk. Then it goes red: the formalities reply due 2026-08-16 passed with nothing recorded as filed, and the docket guard is failing ON PURPOSE to say so. Counsel last said the papers would go that week; the docket still shows no filing receipt and no signed declaration. Everything downstream — the claim chart, the defensive publications, the per-agent licence — is real work sitting behind an administrative gate that closes on 2026-12-16.

Enters & leaves (3) →
→ ⚖️ Legal Standardization
The claim chart is what makes the liability wording defensible: you cannot fence what a policy covers without first naming which claims the shipped code actually practises and which it does not.
→ 💰 Commercial Extraction
The monopoly is what is being sold. A per-agent licence with no granted claim behind it is a subscription; with one, it is a toll, and the difference is the entire commercial thesis.
← ⚙️ Technical Integration
Takes the shipped mechanism and reports back the gap. Where the code does not practise a claim, that is either a build instruction or a claim to drop — and saying which, before diligence asks, is the point.
7A1🗂️Convert seven provisionals.✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/patent/us-19-637714/_claims.txt, docs/patent/us-19-637714/index.html, .workflow/uspto/estate.json, docs/patent/us-19-637714/EM01US01_Claims_as-filed.pdf, docs/patent/us-19-637714/EM01US01_OathDecl.pdf, docs/patent/us-19-637714/US-19-637714-filed-reading-copy.pdf.
Specification — 100%, 3 of 3 checks pass
✓the as-filed claim set is on disk → docs/patent/us-19-637714/_claims.txt
✓the priority chain names its provisionals → 63/782
✓every provisional carries its twelve-month bar → .workflow/uspto/estate.json
Execution — 100%, 3 of 3 checks pass
✓the docket exists as one machine-readable file → .workflow/uspto/estate.json
✓the claims went in as a signed document → docs/patent/us-19-637714/EM01US01_Claims_as-filed.pdf
✓the oath and declaration are on file → docs/patent/us-19-637714/EM01US01_OathDecl.pdf
Market — 100%, 3 of 3 checks pass
✓the application has a real filing date → .workflow/uspto/estate.json
✓the USPTO issued a serial number → 19/637
✓a reading copy of the filed application exists → docs/patent/us-19-637714/US-19-637714-filed-reading-copy.pdf
20B1🚨File notice response.2 open
Specification — 100%, 2 of 2 checks pass
✓a response to the notice is drafted → docs/patent/us-19-637714/RESPONSE-to-Notice-2026-06-16.md
✓the reply is tracked on the docket → .workflow/uspto/estate.json
Execution — 100%, 2 of 2 checks pass
✓corrected claims are prepared → docs/patent/us-19-637714/EM01US01_Claims_double-spaced_2026-06-27.pdf
✓replacement drawing sheets are prepared → docs/patent/us-19-637714/replacement-sheets
Market — 33%, 1 of 3 checks pass
✓the Office paper was received → docs/patent/us-19-637714/USPTO_Notice-to-File-Corrected-Application-Papers_2026-06-16.pdf
✗the USPTO acknowledged the reply → .workflow/uspto/*acknowledgement*
✗the signed declaration is filed → .workflow/uspto/sb0015a-signed.pdf
21B2⏰Ship docket guard.✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: .workflow/uspto/estate.json, tests/legal/estate-docket.test.mjs.
Specification — 100%, 1 of 1 checks pass
✓every docket entry names the guard that watches it → .workflow/uspto/estate.json
Execution — 100%, 3 of 3 checks pass
✓a docket guard exists → tests/legal/estate-docket.test.mjs
✓it computes what is overdue rather than listing it → tests/legal/estate-docket.test.mjs
✓no deadline is past due with nothing filed → tests/legal/estate-docket.test.mjs
Market — 100%, 2 of 2 checks pass
✓counsel has been sent forwardable packages → docs/patent/us-19-637714/_forwardable-to-brian-*.html
✓counsel is named on the docket → .workflow/uspto/estate.json
37C1🧾Disclose unpractised claims.✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/legal/claim-chart.md, tests/legal/claim-chart-covers-every-claim.test.mjs, tests/legal/claim-citations-match-as-filed.test.mjs, src/app/docket/page.tsx.
Specification — 100%, 3 of 3 checks pass
✓a claim chart exists → docs/legal/claim-chart.md
✓it is written as apparatus, not as law → docs/legal/claim-chart.md
✓all thirty-six claims are charted → docs/legal/claim-chart.md
Execution — 100%, 3 of 3 checks pass
✓a guard proves every claim is covered by the chart → tests/legal/claim-chart-covers-every-claim.test.mjs
✓citations are checked against the as-filed text → tests/legal/claim-citations-match-as-filed.test.mjs
✓a public diligence route exists to serve it → src/app/docket/page.tsx
Market — 100%, 2 of 2 checks pass
✓the route links the chart a diligence reader can open → src/app/docket/page.tsx
✓the route states the negative disclosure, not just the filing → src/app/docket/page.tsx
46D1🧱Block the workaround.1 open
Specification — 100%, 2 of 2 checks pass
✓defensive publications are written → docs/01-business/patents/defensive-publications
✓the publish-versus-keep-secret call is reasoned → docs/01-business/patents/CONFIDENTIALITY_VS_PUBLICITY_STRATEGY.md
Execution — 100%, 2 of 2 checks pass
✓there is a papers surface → src/app/papers/page.tsx
✓access runs through an NDA gate → src/app/api/request-nda/route.ts
Market — 0%, 0 of 1 checks pass
✗published to a prior-art registry → docs/receipts/defensive-publication-receipt.md
54E1🪙Charge per agent.2 open
Specification — 50%, 1 of 2 checks pass
✓licence terms are written → docs/legal/agent-year-license-terms.md
✗the package licence names the agent-year → packages/thetacog-mcp/LICENSE
Execution — 100%, 2 of 2 checks pass
✓the pricing invariants are guarded → tests/legal/license-benchmark-invariants.test.mjs
✓the price is public → src/app/pricing/page.tsx
Market — 50%, 1 of 2 checks pass
✓the buy path is live on the landing page → src/app/iamfim-landing/page.tsx
✗a licence has actually sold → docs/receipts/first-patent-license-sold.md

⚙️Technical Integration🔄 C2.Operations.Loop 🧪16 items · 24 open

15 of 100 declared evidence paths fall inside The Laboratory's owned surface

We are replacing trust with recomputable proof — same bytes, same hash. This vector is entirely focused on building the hardware-attested semantic grounding required to isolate and measure AI execution risk. By shipping the trust root and capturing live telemetry on-chip, we transform abstract software behaviour into a mathematically auditable ledger. The terminal state of this track is a frozen, zero-entropy interface where capital can independently verify that our agent remains strictly within its defined operational bounds.

How to read this list →

Read this track as one chain with no shortcuts: a verdict has to be signed before a run is worth logging, a log has to be quiet before live work is worth measuring, and live work has to be measured before a same-bytes-same-hash claim is worth making. The A and B phases are already through — the signer exists, the receipts accumulate, the false-alarm rate is sealed with a confidence interval. What is genuinely open here is not code but WITNESS: every market check on this track fails, because nobody outside the building has recomputed a receipt. That single missing artifact is why a track at ninety-something per cent on specification and execution is not finished.

Enters & leaves (2) →
→ ⚖️ Legal Standardization
The measured boundary becomes the covered boundary. Exclusions can only be written against something that is actually observed, so every claim the legal track fences is a claim this track first made checkable.
→ 💰 Commercial Extraction
The proof a stranger can run in one command is what makes a pitch survive contact. Without it the commercial track is asking for belief; with it, it is asking someone to check.
What is left · 24 open (derived, never typed)
✗1 A1 a third party has recomputed one → docs/receipts/third-party-recompute.md✗1 A1 the first number handed to a writer is our own failing reading with its null attached — the send tape carries the phrase before it carries anything green → .thetacog/email-sent.ndjson✗2 A2 the same listing answers on Open VSX, the registry Cursor, VSCodium and Windsurf install from (red until published there; open-vsx.org said 'Extension not found' on 2026-10-08) → open-vsx.org/api/thetadriven/thetacog-mcp✗3 A3 the public endpoint RUNS the recompute instead of handing over the command → src/app/api/receipt/verify/route.ts✗3 A3 someone outside the building has run it and written down what they got → docs/receipts/third-party-recompute.md✗5 A4 someone outside has read the ledger → docs/receipts/third-party-recompute.md+18 more open on this list
1A1💻Attest execution bounds.2 open
Specification — 100%, 4 of 4 checks pass
✓on-chip resident spec exists → docs/architecture/pmu-resident-onchip-spec.md
✓verification gaps are written down, not hidden → docs/architecture/pmu-rust-verification-gaps.md
✓attestation glossary exists → docs/architecture/pmu-spec-attestation-glossary.md
✓the reading carries its own null — the spec says UNMEASURED for a line that cannot beat its own shuffle, and THE METER is read against a shuffled-pairing null (0.263 vs 0.189, z 1.6: at the null, said first) → docs/architecture/rust-pipeline-flowchart-2026-07-23.md
Execution — 100%, 6 of 6 checks pass
✓the in-binary signer exists → packages/thetacog-mcp/intentguard/src/attest.rs
✓it signs with ed25519, not a hash claim → packages/thetacog-mcp/intentguard/src/attest.rs
✓a one-byte forge is caught by a test → tests/pmu-simulator/forge-test.test.mjs
✓a nonsense line cannot latch — the null shuffles only the line against the same mass, and the winner must clear the family-wise z for the rungs drawn (this retracted 35.9 / 37.3 / 78.2 / 84.2 on 2026-09-14) → packages/thetacog-mcp/pmu-rust/src/lens.rs
✓a placement the one binary did not produce refuses (UNMEASURED, no pixel) instead of degrading, and the callers that could still compute one in JS may only shrink (24 on 2026-09-14) → tests/pmu-simulator/one-placement-door.test.mjs
✓the receipt names the latch that refused — permutation or family-wise z — never a threshold that was met → tests/pmu-simulator/receipt-fit-line.test.mjs
Market — 33%, 1 of 3 checks pass
✓a stranger can verify a receipt on the site (the page answers, it does not redirect) → src/app/verify-receipt/page.tsx
✗a third party has recomputed one → docs/receipts/third-party-recompute.md
✗the first number handed to a writer is our own failing reading with its null attached — the send tape carries the phrase before it carries anything green → .thetacog/email-sent.ndjson
2A2🧩List marketplace extension.1 openC94a
Specification — 100%, 1 of 1 checks pass
✓the listing is published under our publisher id → packages/thetacog-mcp-vscode/package.json
Execution — 100%, 1 of 1 checks pass
✓the shipped version is the one the changelog names → ./packages/thetacog-mcp-vscode/package.json
Market — 67%, 2 of 3 checks pass
✓the gallery answered for the item and the answer is written down with its date → docs/receipts/marketplace-listing.md
✓the Marketplace's own install statistic reads at least one (installs, never the downloads-incl-updates count; read by licence-funnel.mjs) → ./data/vna/licence-funnel.json
✗the same listing answers on Open VSX, the registry Cursor, VSCodium and Windsurf install from (red until published there; open-vsx.org said 'Extension not found' on 2026-10-08) → open-vsx.org/api/thetadriven/thetacog-mcp
3A3♻️Recompute sealed receipts.2 openC98
Specification — 100%, 2 of 2 checks pass
✓the receipt answers four separate claims and never one aggregate bit → src/app/api/receipt/verify/route.ts
✓what a recompute reproduces, and what it does not, is specified → docs/architecture/receipt-recompute-spec.md
Execution — 100%, 3 of 3 checks pass
✓a stranger recomputes a named commit from the command line
✓the recompute checks the signature as well as re-deriving the numbers → scripts/pmu/prove-recompute.mjs
✓the same commit recomputes identically — re-runnability is guarded, not asserted → tests/pmu-simulator/receipt-is-llm-free.test.mjs
Market — 0%, 0 of 2 checks pass
✗the public endpoint RUNS the recompute instead of handing over the command → src/app/api/receipt/verify/route.ts
✗someone outside the building has run it and written down what they got → docs/receipts/third-party-recompute.md
5A4🧮Verify execution tape.1 open
Specification — 100%, 2 of 2 checks pass
✓the evidence ledger is specified → docs/architecture/pmu-evidence-ledger-2026-05-28.html
✓claims are tied to proofs → docs/architecture/claims-proof-ledger.md
Execution — 100%, 3 of 3 checks pass
✓signed drift receipts are accumulating → .thetacog/pmu/drift-receipts/receipts.ndjson
✓each line carries a signature → .thetacog/pmu/drift-receipts/receipts.ndjson
✓tampering with the ledger fails a test → tests/pmu-simulator/ledger-attest-tamper.test.mjs
Market — 0%, 0 of 1 checks pass
✗someone outside has read the ledger → docs/receipts/third-party-recompute.md
6A5⏳Anchor third-party timestamps.3 open
Specification — 100%, 2 of 2 checks pass
✓what makes a record survive discovery is written down, including why our own git history alone does not → docs/architecture/discovery-admissibility-spec.md
✓the threat model names the one party that can rewrite this timeline — us → docs/architecture/discovery-admissibility-spec.md
Execution — 50%, 1 of 2 checks pass
✗an entry carries an attestation from a party that is not us → .thetacog/pmu/drift-receipts/receipts.ndjson
✓a rewritten history is caught by a test, not by trust → tests/pmu-simulator/anchor-detects-rewrite.test.mjs
Market — 0%, 0 of 2 checks pass
✗a stranger can show our record existed on a date we could not have chosen → src/app/api/receipt/verify/route.ts
✗counsel has read the admissibility argument and written down what they think of it → docs/receipts/counsel-admissibility-review.md
28B1⚙️Benchmark drift rate.C693✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: data/pmu/sealed-calibration.json, scripts/pmu/calibration-premium.mjs, .thetacog/pmu/throughput/history.ndjson, tests/pmu-simulator/throughput-ledger.test.mjs, docs/underwriting/false-alarm-rate.md.
Specification — 100%, 2 of 2 checks pass
✓the breach rate is sealed, with a confidence interval → data/pmu/sealed-calibration.json
✓the sealed rate is the one we quote → data/pmu/sealed-calibration.json
Execution — 100%, 3 of 3 checks pass
✓premium follows the calibration, not a guess → scripts/pmu/calibration-premium.mjs
✓throughput history is long enough to trust → .thetacog/pmu/throughput/history.ndjson
✓a guard pins the throughput ledger → tests/pmu-simulator/throughput-ledger.test.mjs
Market — 100%, 1 of 1 checks pass
✓a false-alarm rate has been shown to a counterparty → docs/underwriting/false-alarm-rate.md
29B2🪙Measure token delta.3 open
Specification — 100%, 2 of 2 checks pass
✓the tipping mechanism is written down as a measurable claim → docs/strategy/2026-08-29-license-double-exponential-bottom-up.html
✓what we refuse to claim about it is on the record → docs/underwriting/false-alarm-rate.md
Execution — 0%, 0 of 2 checks pass
✗a gated-vs-ungated token series exists on disk → data/pmu/token-delta.ndjson
✗the comparison is a control, not a testimonial → data/pmu/token-delta.ndjson
Market — 0%, 0 of 1 checks pass
✗a deployer reported the saving on their own fleet → docs/receipts/token-saving-reported.md
36C1📡Ingest live telemetry.1 open
Specification — 100%, 1 of 1 checks pass
✓the streaming checkpoint is written up → docs/architecture/pmu-streaming-checkpoint-2026-06-13.md
Execution — 100%, 3 of 3 checks pass
✓per-commit measurements are accumulating → data/pmu/measure-history.ndjson
✓each row carries drift, not just a timestamp → data/pmu/measure-history.ndjson
✓real hardware captures exist → .thetacog/pmu/measurements
Market — 50%, 1 of 2 checks pass
✓the live stream is readable by a stranger, not just by us → dev/null
✗a foreign system has had runtime traces through the parser → docs/receipts/foreign-telemetry-ingest.md
39C2🔒Gate state crossings.1 open
Specification — 100%, 1 of 1 checks pass
✓the LLM-free receipt is a stated hard rule
Execution — 100%, 3 of 3 checks pass
✓chip rail and cloud rail agree exactly → tests/pmu-simulator/chip-cloud-lattice-golden.test.mjs
✓no model sits in the receipt path → tests/pmu-simulator/receipt-is-llm-free.test.mjs
✓the same ledger twice is shape-identical → tests/pmu-simulator/breaker-backtest.test.mjs
Market — 0%, 0 of 1 checks pass
✗someone outside the building reproduced it → docs/receipts/third-party-recompute.md
40C3🖋️Countersign autonomous moves.2 open
Specification — 100%, 2 of 2 checks pass
✓the autonomy classes are written down, and which ones need a second signature → scripts/elicit/autonomy.mjs
✓the countersigning verifier is specified — what it reads, and what it may not read → docs/architecture/countersign-verifier-spec.md
Execution — 67%, 2 of 3 checks pass
✗an execution record names the commit it produced, so the move can be replayed → .thetacog/elicit/executions.ndjson
✓a verifier that did not author the move signs a verdict over it → scripts/elicit/countersign.mjs
✓a move whose commit does not match its declared intent is refused, under test → tests/elicit/countersign-refuses-mismatch.test.mjs
Market — 0%, 0 of 1 checks pass
✗class 2 is settable, which it is not while the executor grades itself → scripts/elicit/autonomy.mjs
49D1🛑Sign root anchor.✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/architecture/pmu-guard-manifest.md, scripts/pmu/guard-audit.mjs, tests/pmu-simulator/architecture-invariants.test.mjs, docs/architecture/external-integrations.md.
Specification — 100%, 2 of 2 checks pass
✓the guard manifest exists → docs/architecture/pmu-guard-manifest.md
✓nothing is left dangling → docs/architecture/pmu-guard-manifest.md
Execution — 100%, 3 of 3 checks pass
✓guards are audited by a script, not by memory → scripts/pmu/guard-audit.mjs
✓architecture invariants have a test → tests/pmu-simulator/architecture-invariants.test.mjs
✓the suite is big enough to bite → tests/pmu-simulator/*.test.mjs
Market — 100%, 1 of 1 checks pass
✓someone builds against the frozen interface → docs/architecture/external-integrations.md
50E1🏗️Serve production fleets.2 open
Specification — 50%, 1 of 2 checks pass
✗the availability target and the SLA are written down before anyone is asked to depend on them → docs/architecture/enterprise-sla.md
✓the lifecycle is specified as one pipeline, not as a set of scripts a junior dev babysits → docs/architecture/enterprise-pipeline-spec.md
Execution — 100%, 3 of 3 checks pass
✓receipt parsing is programmatic — a typed client someone outside can install → packages/thetacog-client
✓the whole lifecycle runs unattended in CI, from autonomous move to verified receipt → .github/workflows/receipt-lifecycle.yml
✓the parser survives a rate no human is watching → tests/pmu-simulator/receipt-throughput.test.mjs
Market — 0%, 0 of 1 checks pass
✗a company runs its own pipeline against it in production, with a named owner on their side → docs/receipts/first-production-integration.md
71B3🔁Earn stranger recompute.1 openC305b · C305d
Specification — undeclared: nobody has written a check for this yet, which is not the same as zero
Execution — 100%, 1 of 1 checks pass
✓the recompute is one command a stranger runs from the extension, not a repo checkout → packages/thetacog-mcp-vscode/src/commands.ts
Market — 50%, 1 of 2 checks pass
✓the ask went out with the command in it → .thetacog/email-sent.ndjson
✗a stranger wrote down what they got → docs/receipts/third-party-recompute.md
76B4🧮Count signed attestations.2 openC360
Specification — 100%, 1 of 1 checks pass
✓the ask is a declared row: a licence broken on a machine is counted, stamp by stamp → docs/specs/vna/SPEC-VNA-COCKPIT.md
Execution — 0%, 0 of 1 checks pass
✗the ledger accepts a stamp row, so each attestation signed on a machine reaches the site → supabase/migrations
Market — 0%, 0 of 1 checks pass
✗the pricing page tells a buyer their signed count is kept per machine → src/app/pricing/page.tsx
77B5🔀Unlock unsigned credits.1 openC360
Specification — 100%, 1 of 1 checks pass
✓the ask is a declared row: the unsigned rest moves by logging in, only if the old machine never stamped it → docs/specs/vna/SPEC-VNA-COCKPIT.md
Execution — 100%, 1 of 1 checks pass
✓a route serves the lost-machine move (revokeViaLink has a caller) → src/app/api
Market — 0%, 0 of 1 checks pass
✗the extension offers the move to the person whose machine broke → packages/thetacog-mcp-vscode/src
79D2📦Build portable walker.2 openC361
Specification — undeclared: nobody has written a check for this yet, which is not the same as zero
Execution — 0%, 0 of 1 checks pass
✗the walker builds for wasm32, so it runs where no Rust toolchain is installed → packages/thetacog-mcp/pmu-rust/Cargo.toml
Market — 0%, 0 of 1 checks pass
✗the published package ships the wasm build → packages/thetacog-mcp/package.json

🛡️IntentGuard and the Backup🌊 C3.Operations.Flow 🎩11 items · 3 open

26 of 78 declared evidence paths fall inside The Operator's owned surface

The buyer is a team deploying a bot whose output a carrier will not cover without a record it can count: the ISO generative-AI exclusions (CG 40 47 and CG 40 48, effective January 2026) take that output off the commercial general liability form, and the market does not carry back what it cannot count. We are not the carrier. IntentGuard makes the output countable, so it becomes insurable, and a carrier prices it. IntentGuard is the boundary-legibility crate carved out of this repo: it places an agent turn against the spec that was declared before the turn ran, signs the placement, and hands back a receipt anyone can recompute from its inputs. Around that core sits the backup: the licence holder's agent posts ONLY the signed receipt (placement, hashes, spec hash, timestamp, signature), never the code or the prose, to a witnessed copy on thetadriven.com. Every query on that copy is an action paid for by the licence of whoever initiates it; recomputing a receipt stays free and needs no call. The site then draws the drift of the tape from receipt fields alone, because it never has the code. The measurement is free and open-source (MIT); only the witnessed copy and the attestation are licensed.

How to read this list →

Read it bottom-up, as a chain where each rung is worth nothing until the one beneath it holds, and read the C rungs market-first: each carries a market check that was declared before its build and was red on the day it was written (C478, 2026-09-29), so the list says what a buyer can see before it says what we built. The A phase is the crate: the thesis passes in pure Rust on untouched fixtures, the crate is generated from the monorepo so the two cannot drift, and the same bytes come out on Linux. The B phase is the service: the extension witnesses a turn and posts only the receipt, a query on the witnessed copy debits one action from the initiator, and the drift page reads the tape without ever seeing code. The C phase is what a carrier would count, in order: cards signed on Vercel and re-fetched by sha, an install that runs on any node, the tape backed up to a notary that answers, a query paid for by a licence that is not ours, the whole tape seen as one panel, and the first agent deployed outside this repo whose turns are witnessed. Where it stands on 2026-09-29: the thesis is measured at three of four with the separation test the open rung (C459), so the list is still stuck at its first rung. Production answers the card door but refuses an unlicensed post, the notary ingest answers 503 because no notary key is set, and npm's intentguard is 1.8.2, the v1 JavaScript line, while 2.0 exists only as the Rust crate on GitHub.

Enters & leaves (3) →
← ⚙️ Technical Integration
Takes the lens, the walk and the signer from the technical list; IntentGuard is that code carved into a crate a stranger can build, never a second implementation.
→ 💰 Commercial Extraction
Hands the commercial list the first paid action that is not a seat: a query on the witnessed copy, debited per call from the licence that asked.
→ 📖 The Argument
Hands the argument list a recompute any stranger can run on Linux, which is what makes the precaution cheap and available.
92A1🦀Prove Rust thesis.C459 · C462✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/specs/vna/SPEC-VNA-COCKPIT.md, ../IntentGuard/tests/thesis.rs, ../IntentGuard/src/lens.rs, tests/ops/c462-intentguard-is-generated.test.mjs.
Specification — 100%, 2 of 2 checks pass
✓row C459 is declared in the spec with its guard → docs/specs/vna/SPEC-VNA-COCKPIT.md
✓the thesis is written as a test over committed fixtures (T2: on-spec lands nearer the spec) → ../IntentGuard/tests/thesis.rs
Execution — 100%, 2 of 2 checks pass
✓the matched seed takes a caller-supplied bulk → ../IntentGuard/src/lens.rs
✓the carve from the monorepo crate is guarded as reproducible (C462) → tests/ops/c462-intentguard-is-generated.test.mjs
Market — 100%, 1 of 1 checks pass
✓the thesis test is public: anyone can clone the crate and run it → dev/null
93A2🐧Verify Linux hashes.C460 · C461✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/specs/vna/SPEC-VNA-COCKPIT.md, ../IntentGuard/tests/cross_arch.rs, ../IntentGuard/src/lib.rs, ../IntentGuard/tests/lib_api.rs.
Specification — 100%, 2 of 2 checks pass
✓row C460 is declared in the spec with its guard → docs/specs/vna/SPEC-VNA-COCKPIT.md
✓row C461 is declared in the spec with its guard → docs/specs/vna/SPEC-VNA-COCKPIT.md
Execution — 100%, 2 of 2 checks pass
✓a parity test asserts Linux output hashes equal the macOS hashes → ../IntentGuard/tests/cross_arch.rs
✓the crate is a library whose calls match the binary byte for byte → ../IntentGuard/src/lib.rs
Market — 100%, 1 of 1 checks pass
✓the parity test is public on the crate → dev/null
94B1👁️Sign agent turns.C454✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/specs/vna/SPEC-VNA-COCKPIT.md, packages/thetacog-mcp/scripts/pmu/witness-turn.mjs, tests/pmu/c454-witness-turn.test.mjs.
Specification — 100%, 1 of 1 checks pass
✓row C454 is declared in the spec with its guard → docs/specs/vna/SPEC-VNA-COCKPIT.md
Execution — 100%, 2 of 2 checks pass
✓the client posts only the signed receipt to the notary ingest → packages/thetacog-mcp/scripts/pmu/witness-turn.mjs
✓a guard proves the post carries no turn or spec text and a failed post writes one GAP line → tests/pmu/c454-witness-turn.test.mjs
Market — 100%, 1 of 1 checks pass
✓the witness client ships in the published npm package → dev/null
95B2🪙Charge witnessed queries.C455✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/specs/vna/SPEC-VNA-COCKPIT.md, src/app/api/notary/query/route.ts, tests/vna/c455-notary-query-is-an-action.test.mjs.
Specification — 100%, 1 of 1 checks pass
✓row C455 is declared in the spec with its guard → docs/specs/vna/SPEC-VNA-COCKPIT.md
Execution — 100%, 2 of 2 checks pass
✓the query route debits the initiator through the credits ledger → src/app/api/notary/query/route.ts
✓a guard proves the caller is debited, never the owner, and 402 at zero → tests/vna/c455-notary-query-is-an-action.test.mjs
Market — 100%, 1 of 1 checks pass
✓the query door is deployed on thetadriven.com and answers → dev/null
96B3📈Show tape drift.C456✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/specs/vna/SPEC-VNA-COCKPIT.md, src/lib/backup/drift-reading.mjs, src/app/backup/drift/page.tsx.
Specification — 100%, 1 of 1 checks pass
✓row C456 is declared in the spec with its guard → docs/specs/vna/SPEC-VNA-COCKPIT.md
Execution — 100%, 2 of 2 checks pass
✓the drift reading is computed from receipt fields only → src/lib/backup/drift-reading.mjs
✓the page renders an absent reading as UNMEASURED, never zero → src/app/backup/drift/page.tsx
Market — 100%, 1 of 1 checks pass
✓the drift page is deployed on thetadriven.com → dev/null
97C1☁️Serve signed cards.C466 · C468✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/specs/vna/SPEC-VNA-COCKPIT.md, src/app/api/intentguard/route.ts, data/intentguard-deployments.ndjson.
Specification — 100%, 1 of 1 checks pass
✓row C468 is declared in the spec with its guard → docs/specs/vna/SPEC-VNA-COCKPIT.md
Execution — 100%, 1 of 1 checks pass
✓the card door stores and re-serves the signed bytes by sha → src/app/api/intentguard/route.ts
Market — 100%, 1 of 1 checks pass
✓a card signed in production re-fetches from thetadriven.com by its sha (the sha is testimony in the deployments ledger, the fetch is the proof) → data/intentguard-deployments.ndjson
98C2📦Publish any-node install.C469✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/specs/vna/SPEC-VNA-COCKPIT.md, tests/api/c469-card-same-bytes-every-node.test.mjs.
Specification — 100%, 1 of 1 checks pass
✓row C469 is declared in the spec with its guard → docs/specs/vna/SPEC-VNA-COCKPIT.md
Execution — 100%, 1 of 1 checks pass
✓a harness proves one card comes out byte-identical on every node target → tests/api/c469-card-same-bytes-every-node.test.mjs
Market — 100%, 1 of 1 checks pass
✓the intentguard package on the public registry is the 2.x line (1.8.2 is the v1 JavaScript line) → registry.npmjs.org/intentguard/latest
99C3💾Anchor tape backups.C463 · C480✓ shipped · no tracked record
Shipped — every declared check passes. None of the records these checks read is tracked by git — this reading stands on this machine, not on the record. Sufficient for: the record it stands on exists in an immutable commit, and since when. Not sufficient for: whether the work is good (undecidable — Rice). Read off this machine, not the record: docs/specs/vna/SPEC-VNA-COCKPIT.md, tests/vna/c463-notary-accepts-turn-receipts.test.mjs, tests/vna/c480-ship-check-probes-production.test.mjs.
Specification — 100%, 1 of 1 checks pass
✓row C480 is declared in the spec with its guard → docs/specs/vna/SPEC-VNA-COCKPIT.md
Execution — 100%, 2 of 2 checks pass
✓the notary accepts a turn receipt, not only a commit → tests/vna/c463-notary-accepts-turn-receipts.test.mjs
✓the ship check reads the notary state from production, not only from a token → tests/vna/c480-ship-check-probes-production.test.mjs
Market — 100%, 1 of 1 checks pass
✓the production notary ingest answers without the 503 it gives while no notary key is set → dev/null
100C4🧾Earn outside query.1 openC478
Specification — 100%, 1 of 1 checks pass
✓row C478 is declared in the spec with its guard → docs/specs/vna/SPEC-VNA-COCKPIT.md
Execution — 100%, 1 of 1 checks pass
✓a guard proves the initiator is debited, never the owner → tests/vna/c455-notary-query-is-an-action.test.mjs
Market — 50%, 1 of 2 checks pass
✗a query on the tape was debited from a licence that is not ours (testimony) → data/intentguard-deployments.ndjson
✓the production query door answers without the 503 it gives while no notary key is set → dev/null
101C5🗺️Map whole tape.1 openC479
Specification — 100%, 1 of 1 checks pass
✓row C479 is declared in the spec with its guard → docs/specs/vna/SPEC-VNA-COCKPIT.md
Execution — 100%, 1 of 1 checks pass
✓the repo view reads receipt fields only and renders UNMEASURED on an empty tape → tests/site/c479-repo-view.test.mjs
Market — 0%, 0 of 1 checks pass
✗a licence holder who is not us opened the whole-tape view of their own backup (testimony) → data/intentguard-deployments.ndjson
102C6🚀Attest deployed agent.1 openC457 · C458
Specification — 100%, 2 of 2 checks pass
✓row C458 is declared in the spec with its guard → docs/specs/vna/SPEC-VNA-COCKPIT.md
✓row C457 is declared in the spec with its guard → docs/specs/vna/SPEC-VNA-COCKPIT.md
Execution — 100%, 1 of 1 checks pass
✓ship readiness is one command that names what the deploy still needs → scripts/ops/intentguard-ship-check.mjs
Market — 0%, 0 of 1 checks pass
✗an agent deployed outside this repo had a turn witnessed (testimony) → data/intentguard-deployments.ndjson

♟️ The board — who holds each job

Nobody on this list has to talk to anybody else on it. Each one already profits when a cheap, public precaution existed and was skipped (The T.J. Hooper, 1932), so each one is shown the same board and handed something they can check. The measurement is free and open-source (MIT); only underwriting and attestation are licensed. Roles, never names. 38 jobs.

By milestone

A milestone moves when several people each do their own job; one job can move more than one milestone.

Allies · 14

Someone whose own self-interest already profits when plausible deniability breaks. We do not recruit them; we show them the board.

  • J21 Ask for the decision record in bad-faith claims — Policyholder bad-faith counsel
    • Responsibility. Put the automated claim decision's record in the first discovery request, and ask whether it was kept in a form a third party can recompute.
    • Why it pays them. When a cheap precaution was public and the defendant skipped it, the Hooper argument moves the standard of care onto their side of the table. Fee economics reward the case that proves itself.
    • What they are handed. The discovery guide and the preservation letter template
    • First action. The BD lead sends one graded draft to one bad-faith practice (C434)
    • Serves. Brief plaintiff counsel · Arm discovery requests
  • J22 Request the relevant records on an ERISA benefit denial — ERISA plaintiffs' counsel
    • Responsibility. On a denied claim, request every document relevant to the claim under 29 C.F.R. 2560.503-1(h)(2)(iii), naming the automated decision record.
    • Why it pays them. A record the plan cannot produce is the argument that the review was not full and fair.
    • What they are handed. The discovery guide's ERISA section and the TPA request letter
    • First action. One graded draft to one ERISA practice (C434)
    • Serves. Brief plaintiff counsel · Demand TPA receipts
  • J23 Evaluate automated-denial fact patterns for a qui tam — Qui tam relators' counsel
    • Responsibility. Where federal program money pays for automated decisions, test whether the missing record is itself evidence under the False Claims Act.
    • Why it pays them. A relator's share runs 15 to 30 percent of the recovery (31 U.S.C. 3730(d)); a record gap that is dated and public is a fact pattern, not a hunch.
    • What they are handed. The discovery guide and the public recompute receipt
    • First action. One graded draft to one relators' practice after the ERISA lane replies (C434)
    • Serves. Brief plaintiff counsel
  • J24 Price the evidentiary cost of automated-decision cases — Litigation funders
    • Responsibility. Add one line to case diligence: was the automated decision recorded in a form a third party can recompute, and if not, why not.
    • Why it pays them. A case whose liability evidence is cheap to prove is shorter and cheaper to fund. The storefront lowers proof cost across a whole class of cases at once.
    • What they are handed. The discovery guide and a one-page diligence question set
    • First action. Draft the diligence question set (C435)
    • Serves. Seed funder diligence
  • J25 Write the carve-back that references receipts — Treaty reinsurance underwriters
    • Responsibility. Where a generative-AI exclusion strips agent loss from a treaty, write the carve-back for work that carries a receipt against a declared lane.
    • Why it pays them. An exclusion is a revenue line walked away from. A carve-back scoped to receipted work lets them write the clean body instead of refusing the whole class.
    • What they are handed. The model rider clause and the clean-risk sheet
    • First action. Draft the model rider clause (C439)
    • Serves. Word receipt rider
  • J26 Reference the standard in a syndicate wording — London-market syndicate underwriters writing specialty AI risk
    • Responsibility. Cite RS-1 as the evidence standard in a specialty wording for agentic operations.
    • Why it pays them. The first wording to name a recomputable evidence standard sets the market's template, and the lead line prices it.
    • What they are handed. RS-1, the model rider clause, and a receipt corpus a stranger can recompute
    • First action. Send the rider clause with the recompute command, never a deck (C439)
    • Serves. Word receipt rider
  • J27 Quote the clean body of agent risk — Parametric and MGA underwriters
    • Responsibility. Quote coverage for work placed inside its declared lane, priced off the clean-risk sheet, with out-of-lane work excluded by name.
    • Why it pays them. Delegated authority on a line nobody else can measure; the receipt is the exposure base the incumbents lack.
    • What they are handed. The clean-risk sheet and the receipt corpus
    • First action. Hand over the sheet once C442 lands
    • Serves. Price clean risk
  • J28 Place the clean risk — Independent and wholesale brokers, and MGAs that place specialty risk
    • Responsibility. Take a receipted deployer to market as a clean submission and place it with the MGA or syndicate that quotes it.
    • Why it pays them. A submission that proves its own lane wins placements the retail incumbents cannot, and discharges the broker's own duty of care to its client (see J44).
    • What they are handed. The clean-risk sheet, the receipt corpus, and the recompute command
    • First action. One graded draft to one wholesale placement desk after the sheet exists (C442)
    • Serves. Price clean risk · Convert enterprise fixers
  • J29 Ask the TPA for the record behind automated determinations — Self-insured employer plan fiduciaries (the CFO or benefits committee)
    • Responsibility. As plan fiduciary, require the third-party administrator to produce the decision record for automated claim determinations on request.
    • Why it pays them. ERISA 404(a)(1)(B) prudence includes monitoring service providers. The plan pays the TPA; the fiduciary carries the liability if the review was not full and fair.
    • What they are handed. The TPA receipt request letter
    • First action. One graded draft to one benefits committee (C436)
    • Serves. Equip plan fiduciaries · Demand TPA receipts
  • J30 Put the receipt question in the TPA contract renewal — Union (Taft-Hartley) health and welfare fund trustees
    • Responsibility. Add a records clause to the administrative services agreement at renewal.
    • Why it pays them. Trustees answer to members at every meeting; a records clause is a visible act of prudence that costs the fund nothing.
    • What they are handed. The TPA receipt request letter and a model contract clause
    • First action. One graded draft to one fund's counsel (C436)
    • Serves. Equip plan fiduciaries · Demand TPA receipts
  • J31 Replicate the reading on the public receipt — Forensic and empirical researchers in software and AI evaluation
    • Responsibility. Recompute the public receipt on an independent machine and publish the line it printed, agreeing or not.
    • Why it pays them. A replication, or a failed one, is a publishable result on a question nobody else has instrumented.
    • What they are handed. The public receipt, the recompute command, and the dry-run record of every step a stranger takes
    • First action. One graded draft to one research group once the receipt is on the public mirror (C437)
    • Serves. Verify independent replication
  • J32 Stand up the record after the subpoena — Enterprise defense counsel
    • Responsibility. When a client receives a preservation demand naming automated decision records, stand up a recomputable record from that day forward.
    • Why it pays them. Remediation work is billed after the demand arrives; a record from day one of the hold is the best position they can hand the client.
    • What they are handed. The adapter contract and the /adapters consult
    • First action. Name the lane on /adapters (C441)
    • Serves. Convert enterprise fixers
  • J33 Wire the walker into the deployer's stack — Systems integrators
    • Responsibility. Install the free walker and the adapter so every agent commit carries a receipt against its declared lane.
    • Why it pays them. An integration engagement that starts when counsel calls, with a scope counsel already defined.
    • What they are handed. The MIT walker, the adapter contract, and the reference adapter
    • First action. Name the lane on /adapters (C441)
    • Serves. Convert enterprise fixers
  • J34 Ask for the AI systems program on a market-conduct exam — State insurance market-conduct examiners
    • Responsibility. Request the insurer's written AI systems program and the records behind automated decisions, as the NAIC model bulletin (December 2023) anticipates.
    • Why it pays them. An exam finding that rests on a recomputable record survives appeal; one that rests on the insurer's own account does not.
    • What they are handed. RS-1 and the discovery guide
    • First action. None from us until a docket cites the standard; this lane waits (C438)
    • Serves. Earn docket citation

The opposition, and the duty it already holds · 7

The defending side, stated as the duty the law already assigns the whole class. The receipt is the cheapest way to discharge it, which is why the duty is a job and not a grievance.

  • J41 Preserve automated decision records once litigation is reasonably anticipated — Carriers, as a class (claims and legal)
    • Responsibility. Take reasonable steps to preserve ESI, including the records of automated decisions; FRCP 37(e) sets the consequence when they are lost.
    • Why it pays them. Loss of ESI after the duty attaches invites curative measures and, on a finding of intent, an adverse inference. A receipt kept from the start is the cheapest reasonable step.
    • What they are handed. The preservation letter template, which names the record precisely
    • First action. Arrives with the first preservation letter an ally sends (C433)
    • Serves. Arm discovery requests
  • J42 Keep a written AI systems program the regulator can read — Carriers, as a class (compliance)
    • Responsibility. Maintain the documented AI systems program and decision records the NAIC model bulletin describes, in the states that adopted it.
    • Why it pays them. A program that is recomputable answers an exam in a day; one that is narrative answers it in a year.
    • What they are handed. RS-1 as a public, dated reference for what a checkable record looks like
    • First action. None from us; the duty exists already (C432)
    • Serves. Publish care standard
  • J43 Oversee mission-critical AI risk once on notice — Boards of carriers, brokers and TPAs, as a class
    • Responsibility. Directors must make a good-faith effort to have a reporting system for mission-critical risk (In re Caremark, Del. Ch. 1996; Marchand v. Barnhill, Del. 2019).
    • Why it pays them. A public, cheap precaution that was declined is the fact pattern an oversight claim is built from. Adopting it is the cheapest evidence of oversight.
    • What they are handed. RS-1 and the storefront, dated
    • First action. None from us; the storefront's publication date is the notice (C432)
    • Serves. Publish care standard · Close custom defense
  • J44 Advise the client of the AI coverage gap — Retail brokers, as a class
    • Responsibility. A broker owes its client reasonable care and skill in placing coverage (common law; the scope varies by state). When generative-AI exclusions narrow a renewal, the gap is part of what the client relies on the broker to see.
    • Why it pays them. A missed gap is the broker's own E&O claim. Attaching a receipted submission is the cheapest way to show the gap was seen and addressed.
    • What they are handed. The clean-risk sheet and the model rider clause
    • First action. None from us; the wholesale lane (J28) shows the alternative placement (C442)
    • Serves. Price clean risk · Word receipt rider
  • J45 Give a full and fair review, with the relevant records on request — Third-party administrators, as a class
    • Responsibility. Under ERISA 503 and 29 C.F.R. 2560.503-1(h), provide the claimant on request reasonable access to all documents, records and other information relevant to the claim.
    • Why it pays them. A TPA that can produce the record on request passes review; one that cannot hands the plan fiduciary a reason to rebid the contract.
    • What they are handed. The TPA receipt request letter, which asks for nothing the regulation does not already cover
    • First action. Arrives with the first fiduciary request (C440)
    • Serves. Demand TPA receipts
  • J46 Keep a licensed clinician on the medical-necessity decision — Health plans and utilisation-review vendors operating in California, as a class
    • Responsibility. California SB 1120 (2024) requires that a licensed physician or qualified professional make medical-necessity determinations when a health plan uses AI tools, and that those tools be periodically reviewed.
    • Why it pays them. A periodic review that recomputes is a review they can show a regulator; one that is attested is a review they have to defend.
    • What they are handed. RS-1 as the review record's format
    • First action. None from us; the statute is the seller (C440)
    • Serves. Demand TPA receipts
  • J47 Keep the logs of a high-risk AI system — Deployers of high-risk AI systems in the EU, as a class
    • Responsibility. Under the EU AI Act, a high-risk system must support automatic event logs (Art. 12) and a deployer must keep them for at least six months (Art. 26(6)).
    • Why it pays them. A log a third party can recompute answers an authority's request without a forensic engagement.
    • What they are handed. The adapter contract and the MIT walker
    • First action. None from us; the regulation is in force (C441)
    • Serves. Convert enterprise fixers

Counterparties · 5

Someone we transact with directly — they buy, place, read, or carry the attestation.

  • J51 Buy the attestation on the deployer's receipts — The deployer's general counsel or head of risk
    • Responsibility. License the countersignature and the hosted tape so a carrier can inspect a granted manifest.
    • Why it pays them. A dated, countersigned record from before the demand is the reasonable-care record under Hooper; the measurement under it is free.
    • What they are handed. The countersignature, the carrier-inspection grant, and the free walker
    • First action. The /adapters consult link, counted (C441)
    • Serves. Convert enterprise fixers · Publish care standard
  • J52 Read receipts on submission — Carrier underwriting desks, as a class
    • Responsibility. Accept a receipt corpus as part of an AI-exposed submission and read it with the recompute command.
    • Why it pays them. Selecting the clean body of a class the market is excluding is how a desk grows while the others shrink.
    • What they are handed. The clean-risk sheet and the carrier-inspection grant
    • First action. Arrives through the wholesale lane (J28), never cold (C442)
    • Serves. Price clean risk
  • J53 Attach the receipt set to the renewal submission — Retail and wholesale brokers placing the deployer's programme
    • Responsibility. Carry the deployer's receipt set and clean-risk sheet into the renewal, alongside the exclusion schedule.
    • Why it pays them. The attachment is the written record that the AI gap was seen, which is the broker's own E&O answer (J44).
    • What they are handed. The clean-risk sheet and the recompute command
    • First action. Arrives with the first placed clean risk (C442)
    • Serves. Price clean risk · Word receipt rider
  • J54 Offer receipts as an administrative service — Third-party administrators competing on a self-insured rebid
    • Responsibility. Offer self-insured plans the decision record for automated determinations as a line in the services agreement.
    • Why it pays them. The first TPA to offer the record wins the rebid the fiduciary letter starts.
    • What they are handed. The adapter contract and the MIT walker
    • First action. Arrives after the first fiduciary request (C440)
    • Serves. Demand TPA receipts
  • J55 Serve the tokens — The model labs — a tollbooth on the road, not the villain
    • Responsibility. Run the models the agents call. Nothing is asked of them.
    • Why it pays them. Enterprises that can show reasonable care deploy more agents, and more agents buy more tokens.
    • What they are handed. Nothing to sign. The walker reads the committed work, not the model.
    • First action. None
    • Serves. Close custom defense

Hires · 5

A seat the raise funds. Someone whose standing in a profession we do not have.

  • J11 Open the plaintiff-bar lane — A business-development lead fluent in the plaintiff bar (hire)
    • Responsibility. Carry the discovery guide into bad-faith, ERISA and relator practices and bring back the questions counsel actually asks.
    • Why it pays them. A book of relationships that pays on contingency-shaped economics; the kit gives them something new to bring to every firm.
    • What they are handed. The discovery guide, the preservation template, and the recompute command
    • First action. Write the role description from this file (C434)
    • Serves. Brief plaintiff counsel · Seed funder diligence
  • J14 Write to the expert-witness standard — A technical author with expert-witness experience (hire)
    • Responsibility. Turn RS-1 and the discovery guide into prose that survives cross-examination: every claim sourced, every limit stated before the claim.
    • Why it pays them. Expert work is repeat work; a method that recomputes in a courtroom is a method they can testify to again.
    • What they are handed. RS-1, the receipt schema, and the public recompute receipt
    • First action. Review the discovery guide draft (C433)
    • Serves. Arm discovery requests · Earn docket citation
  • J15 Review the TPA request letter — Retained ERISA benefits counsel (hire)
    • Responsibility. Confirm the plan-side letter asks for what 29 C.F.R. 2560.503-1 already entitles a claimant to, and nothing it does not.
    • Why it pays them. A billable, reusable form their plan clients can send without drafting from scratch.
    • What they are handed. docs/board/tpa-receipt-request-letter.md
    • First action. Send the draft letter for review once written (C440)
    • Serves. Demand TPA receipts
  • J16 Sign the clean-risk method — A credentialed casualty actuary (hire or retained)
    • Responsibility. Review the clean-risk sheet's method and say, in writing, what it is and is not sufficient to price.
    • Why it pays them. A new line with a measurable exposure base is rare; the first actuary to sign a method for it owns the reference.
    • What they are handed. The clean-risk sheet, the receipt corpus, and the null the readings are tested against
    • First action. Hand over the sheet spec when C442 lands
    • Serves. Price clean risk
  • J17 Run the docket watch — A litigation paralegal or docket researcher (hire, part-time)
    • Responsibility. Read public dockets weekly for filings that cite the standard or a receipt and record each with its public reference.
    • Why it pays them. Steady, well-bounded research work with a clear output.
    • What they are handed. scripts/board/docket-watch.mjs and the dockets ledger format
    • First action. Hand over once the watcher exists (C438)
    • Serves. Earn docket citation

Ours · 7

Ours to do. What the founder and the rooms build and publish.

  • J01 Keep the storefront standard public, dated and free to recompute — The founder, with the argument room
    • Responsibility. /standard states the reasonable-care definition (RS-1), says the measurement is free and open-source (MIT) and only underwriting is licensed, and hands over the one recompute command.
    • Why it pays them. Under The T.J. Hooper (2d Cir. 1932), industry custom is not the standard of care when a cheap, available precaution exists. The storefront makes the precaution cheap and public; every job below leans on that one fact.
    • What they are handed. RS-1 (docs/legal/continuous-standard-of-care-reference-standard.md) and the /standard page with the recompute command printed on it
    • First action. Add the MIT sentence and the recompute command to src/app/standard/page.tsx (C432)
    • Serves. Publish care standard
  • J02 Write the receipt discovery guide — The founder, reviewed by the retained litigation-fluent author (J14)
    • Responsibility. One guide that says exactly what a receipt is sufficient for (where a unit of work landed against a lane declared before it ran, recomputable by a stranger) and what it is NOT sufficient for (whether the work was correct), in the words a discovery request uses.
    • Why it pays them. A guide that overclaims is impeached on the first deposition. Stating the limit first is what lets counsel rely on the rest.
    • What they are handed. docs/board/receipt-discovery-guide.md with its NOT-sufficient-for section first
    • First action. Draft the guide from RS-1 sections 1.1 and 1.2 (C433)
    • Serves. Arm discovery requests
  • J03 Write the preservation letter template — The founder, with retained counsel review before any use
    • Responsibility. A template counsel can send once litigation is reasonably anticipated, naming the decision records of an automated system as ESI under FRCP 37(e) and asking that they be kept in a form a third party can recompute.
    • Why it pays them. Counsel gets a letter that names the record precisely; a vague hold letter preserves nothing useful.
    • What they are handed. docs/board/preservation-letter-template.md
    • First action. Draft the template beside the discovery guide (C433)
    • Serves. Arm discovery requests
  • J04 Keep the board ledger as testimony only — The network room
    • Responsibility. Every market check on the board track reads data/board/ledger.ndjson. A row is written only when a real person outside the building acts (asked for the kit, replied, cited, quoted), with its source. Never written to make a bar green.
    • Why it pays them. A fabricated row corrupts the one corpus the thesis rests on. A red bar invites someone to look; a fake green one does not.
    • What they are handed. scripts/board/ledger.mjs (add, list) and its schema
    • First action. Build the ledger door with a fixed key order (C434)
    • Serves. Brief plaintiff counsel · Seed funder diligence · Equip plan fiduciaries · Verify independent replication
  • J05 Watch public dockets for the standard — The operator room, handed to the docket researcher (J17) once hired
    • Responsibility. A bounded, read-only search of public court records for filings that cite the standard or a receipt, each hit written to data/board/dockets.ndjson with its public docket reference.
    • Why it pays them. The first citation is dated evidence that custom moved; nobody has to announce it.
    • What they are handed. scripts/board/docket-watch.mjs
    • First action. Build the watcher against a public docket search (C438)
    • Serves. Earn docket citation · Close custom defense
  • J06 Publish the clean-risk sheet — The builder room, checked by the retained actuary (J16)
    • Responsibility. A sheet computed from receipts that separates work placed in its declared lane from work placed out of it, per deployer, so an underwriter can price the clean body and exclude the rest by name.
    • Why it pays them. An underwriter who can see the clean body can quote it; one who cannot excludes all of it.
    • What they are handed. scripts/board/clean-risk-sheet.mjs and its output format
    • First action. Spec the sheet's columns from the existing receipt fields (C442)
    • Serves. Price clean risk
  • J07 Hold the arming act — The operator
    • Responsibility. Every lane brief and outreach message on this board is composed as a draft; moving one to approved and sending it stays the operator's act.
    • Why it pays them. An ally who receives an unasked, ungraded message stops reading. One graded draft per lane beats a blast.
    • What they are handed. Drafts in docs/outreach/drafts/ named board-<lane>-*
    • First action. Review the first plaintiff-counsel draft when it lands (C434)
    • Serves. Brief plaintiff counsel

Do you worry about $1.2B in AI liability?

a number we can call — or an email, or an idea

Know anyone who should?

If the property is trivial, software can check it — and why are you paying to check trivial properties? If it isn’t trivial, Rice’s theorem says nobody can. So we fixed the math.

gemsedu.com #1 ▼0.9%moonshotscapital.com #2 ▲1%leadedgecapital.com #3 ▼1%differential.vc #4 ▲12.6%dometic.com #5 ▼4.5%thecignagroup.com #6 ▼2.5%sigma.se #7 ▼2.4%karlsborg.se #8 ▼4.2%teneo.com #9 ▼0.6%ltu.se #10 ▼7.8%emiratesnbd.com #11 ▲3.7%apcoworldwide.com #12 ▲0.8%championacaustin.com #13 ▼2.9%amseliplaw.com #14 ▼8.1%clarionschool.com #15 ▼2.1%reed.com #16 ▼7%scania.com #17 ▼10.9%svenskakyrkan.se #18 ▼2.7%anthonypllc.com #19 ▼0.1%rytmus.se #20 ▼8.4%sigeducation.com #21 ▼7.5%state.gov #22 ▲5.5%brodit.se #23 ▼7.9%scor.com #24 ▼7.9%ericsson.com #25 ▲4.4%easystem.se #26 ▼6.4%pernod-ricard-china.com #27 ▼13.5%khda.gov.ae #28 0.0%innoventureseducation.com #29 ▲3.2%dubaiholding.com #30 ▼2.5%wsp.com #31 ▼6.4%bdtmsd.com #32 ▲4.7%expediagroup.com #33 ▼7.1%parkcity.org #34 ▲34.9%lfg.com #35 ▲4%addition.com #36 ▼0.7%upandrunningdubai.com #37 ▲2.7%americancenteruae.com #38 ▼5.2%baylor.edu #39 ▼8.1%its.jnj.com #40 ▼1.3%rackspace.com #41 ▼9.2%eosvc.com #42 ▲16.9%cablevision.com #43 ▲0.5%crslimited.com #44 ▲2.1%atriumhealth.org #45 ▼11.3%sunstarstrategic.com #46 ▼7.7%oryxworld.com #47 ▼15.8%mit.edu #48 ▼2.2%gunnebo.com #49 ▼2.6%volvo.com #50 ▼1.3%siemens.com #51 ▼5.1%winningtemp.se #52 ▼6%neweratech.com #53 ▲0.2%newyorklife.com #54 ▲3.1%statefarm.com #55 ▼3.4%insureai.co #56 ▼15.8%inspiralia.com #57 ▲11.4%munichre.com #58 ▼5.6%sc.com #59 ▲12.9%marsh.com #60 ▲1.4%linkedin.com #61 ▼11.4%bermanauditadvisorycpa.com #62 ▲6.9%se.abb.com #63 ▲7.1%jcdecaux.ae #64 ▲6.8%aresmgmt.com #65 ▲18.7%bakerbotts.com #66 ▲78.1%jcdecaux.com #67 ▼3.5%nsigroup.org #68 ▼3.5%louisville.edu #69 ▲1.5%jkj.com #70 ▼2.4%artvillagenursery.com #71 ▼15.8%emerson.com #72 ▲21%luxcapital.com #73 ▼5.7%conning.com #74 ▼5.6%pacemetals.com #75 ▲30.1%fox.com #76 ▲2.7%tyrolit.com #77 ▲282.3%lbl.gov #78 ▼15.8%students.rcsj.edu #79 ▲43.2%ecoclean-group.net #80 ▲41.1%rakbank.ae #81 ▲4.9%schmuhlbrothers.com #82 ▲50.6%aig.com #83 ▼5%scnsoft.com #84 ▲95.1%bartec.com #85 ▲102.8%xprize.org #86 ▼5.5%bancamediolanum.it #87 ▲45.8%muskegoncc.edu #88 ▲236%tetrapak.com #89 ▲2.2%camarda.com #90 ▲66.4%jsx.com #91 ▲117.5%hsph.harvard.edu #92 ▼15.8%peraco.com.au #93 ▲68.2%mindshareworld.com #94 ▲889.9%krausanderson.com #95 ▲169.2%dubailand.gov.ae #96 ▲13.9%nyu.edu #97 ▼5.1%stoughtontrailers.com #98 ▲165.2%trenchlaw.com #99 ▼15.8%mckoolsmith.com #100 ▼15.8%gemsedu.com #1 ▼0.9%moonshotscapital.com #2 ▲1%leadedgecapital.com #3 ▼1%differential.vc #4 ▲12.6%dometic.com #5 ▼4.5%thecignagroup.com #6 ▼2.5%sigma.se #7 ▼2.4%karlsborg.se #8 ▼4.2%teneo.com #9 ▼0.6%ltu.se #10 ▼7.8%emiratesnbd.com #11 ▲3.7%apcoworldwide.com #12 ▲0.8%championacaustin.com #13 ▼2.9%amseliplaw.com #14 ▼8.1%clarionschool.com #15 ▼2.1%reed.com #16 ▼7%scania.com #17 ▼10.9%svenskakyrkan.se #18 ▼2.7%anthonypllc.com #19 ▼0.1%rytmus.se #20 ▼8.4%sigeducation.com #21 ▼7.5%state.gov #22 ▲5.5%brodit.se #23 ▼7.9%scor.com #24 ▼7.9%ericsson.com #25 ▲4.4%easystem.se #26 ▼6.4%pernod-ricard-china.com #27 ▼13.5%khda.gov.ae #28 0.0%innoventureseducation.com #29 ▲3.2%dubaiholding.com #30 ▼2.5%wsp.com #31 ▼6.4%bdtmsd.com #32 ▲4.7%expediagroup.com #33 ▼7.1%parkcity.org #34 ▲34.9%lfg.com #35 ▲4%addition.com #36 ▼0.7%upandrunningdubai.com #37 ▲2.7%americancenteruae.com #38 ▼5.2%baylor.edu #39 ▼8.1%its.jnj.com #40 ▼1.3%rackspace.com #41 ▼9.2%eosvc.com #42 ▲16.9%cablevision.com #43 ▲0.5%crslimited.com #44 ▲2.1%atriumhealth.org #45 ▼11.3%sunstarstrategic.com #46 ▼7.7%oryxworld.com #47 ▼15.8%mit.edu #48 ▼2.2%gunnebo.com #49 ▼2.6%volvo.com #50 ▼1.3%siemens.com #51 ▼5.1%winningtemp.se #52 ▼6%neweratech.com #53 ▲0.2%newyorklife.com #54 ▲3.1%statefarm.com #55 ▼3.4%insureai.co #56 ▼15.8%inspiralia.com #57 ▲11.4%munichre.com #58 ▼5.6%sc.com #59 ▲12.9%marsh.com #60 ▲1.4%linkedin.com #61 ▼11.4%bermanauditadvisorycpa.com #62 ▲6.9%se.abb.com #63 ▲7.1%jcdecaux.ae #64 ▲6.8%aresmgmt.com #65 ▲18.7%bakerbotts.com #66 ▲78.1%jcdecaux.com #67 ▼3.5%nsigroup.org #68 ▼3.5%louisville.edu #69 ▲1.5%jkj.com #70 ▼2.4%artvillagenursery.com #71 ▼15.8%emerson.com #72 ▲21%luxcapital.com #73 ▼5.7%conning.com #74 ▼5.6%pacemetals.com #75 ▲30.1%fox.com #76 ▲2.7%tyrolit.com #77 ▲282.3%lbl.gov #78 ▼15.8%students.rcsj.edu #79 ▲43.2%ecoclean-group.net #80 ▲41.1%rakbank.ae #81 ▲4.9%schmuhlbrothers.com #82 ▲50.6%aig.com #83 ▼5%scnsoft.com #84 ▲95.1%bartec.com #85 ▲102.8%xprize.org #86 ▼5.5%bancamediolanum.it #87 ▲45.8%muskegoncc.edu #88 ▲236%tetrapak.com #89 ▲2.2%camarda.com #90 ▲66.4%jsx.com #91 ▲117.5%hsph.harvard.edu #92 ▼15.8%peraco.com.au #93 ▲68.2%mindshareworld.com #94 ▲889.9%krausanderson.com #95 ▲169.2%dubailand.gov.ae #96 ▲13.9%nyu.edu #97 ▼5.1%stoughtontrailers.com #98 ▲165.2%trenchlaw.com #99 ▼15.8%mckoolsmith.com #100 ▼15.8%