How this system runs: the canon, part 1
The map
THE CANON — how the vision becomes a document system that locks in
v0.7 · 2026-07-27 · Founder (Cowork) · The re-founding, concretized. This README is the map of the hierarchy; read it before touching anything in `strategy/canon/`. It carries NO state by design — every status, count, and version lives in the registries pointed at below. Full version history + confessions: `CANON_README_LINEAGE.md` (moved verbatim, nothing lost); snapshots beside this mirror; v0.7 lineage check: mirror vs v0.6 snapshot byte-identical before edits.
The problem this architecture solves (operator, verbatim-adjacent)
One-on-one, the operator can present these ideas perfectly — right lens, right framing, per the listener's context. One-to-three-million is different: the same truths can be said hundreds of ways, and a single document keeps getting rewritten as each new audience or insight arrives (the vision's own version lineage is the proof). The fix is the same architecture the research library already uses (one backgrounder → many localized briefs):
ONE canonical substance. MANY rendered doors. Nothing replaced — only absorbed or rendered.
The five layers
strategy/canon/
├── LAYER0_VERBATIM_INDEX.md ← the ground truth: every record of the operator's words
│ (per-program banks, OPERATOR_LOG, FRAMING Appendix A,
│ PC3.0 hand-edit...). Append-only, link-never-copy.
├── LAYER1_VISION/
│ ├── VISION_CORE.md ← THE INTERNAL CANON: complete, audience-untuned substance
│ │ (vision · diagnosis · theory of change · missions ·
│ │ full doctrine · PC3.0 grammar · tensions · receipts).
│ │ Mirror; versioned snapshots beside; per-section status
│ │ DRAFT → RATIFIED, carried in the file itself.
│ └── renders/ ← audience doors, DERIVED from ratified CORE only. Live
│ │ classes (one mirror each, snapshots beside):
│ ├── RENDER_PUBLIC_GENERAL (the first door — general public)
│ ├── RENDER_ORG_LETTER (organizations)
│ ├── RENDER_CANDIDATE_BRIEF (candidates)
│ ├── RENDER_NEWCOMERS (newcomer communities)
│ └── [unbuilt: RESIDENT_20MIN · PRESS_BACKGROUNDER · SKEPTIC_FAQ ·
│ YOUTH/STUDENT · FUNDER-someday]
├── LAYER2_MAP.md ← the scoreboard: issues × audiences × deliverables ×
│ seal status, estate credited in. CURATOR-regenerated;
│ never hand-edited; THE place to learn what exists.
├── LAYER3_METHOD.md ← the production physics: closure trains,
│ Repository Standard, backwards-verification publish
│ gate, render discipline, correction propagation,
│ registry ownership + refresh cadences (§7).
└── LAYER4_ENGINE/ ← the five engine prompts, all live and production-proven:
FOUNDER · CLOSURE_TRAIN · independent verification · RENDER ·
CURATOR. Each reads GOAL/CORE+MAP+METHOD only.
Where state lives (this file carries none — a recorded standing decision / one-fact-one-home)
- Content scoreboard (what's built, sealed, missing, per category × class): `LAYER2_MAP.md` — trust it over anything any prose file says.
- Project estate (every project, home, status): strategy/KEY_PROJECTS.md §0 — the operator's PM front door.
- Live session state and next actions: state/NOW.md (+ the per-track NOW files).
- What waits on the operator: state/DECISION_QUEUE.md §0.
- This file's own history: `CANON_README_LINEAGE.md` + the versioned snapshots beside.
The lock-in rules
- Statuses, per section, operator-flipped. CORE sections are DRAFT until the operator marks them RATIFIED (a workshop walk, section by section — same as the charter wave). Since a recorded standing decision the operator may also delegate a ruling — recorded RATIFIED-BY-DELEGATION, with standing redline rights: any delegated ruling reverts on one operator line. Renders may carry only RATIFIED substance; a render needing unratified substance is the signal to ratify or amend the CORE first.
- One-direction flow. Verbatim (L0) → CORE (L1) → renders. New operator input lands in L0 first (banked), gets synthesized into CORE second, re-renders third. Nobody ever edits a render into disagreement with the CORE.
- No overwrites, ever. Every change = new versioned snapshot + stable-mirror update (a recorded standing decision/a recorded standing decision pattern). The full lineage stays browsable forever.
- Correction propagation. When CORE changes, every render citing the changed section is re-rendered or flagged — checked by grep, not memory (same discipline as ledger claims).
- Renders are lenses, not dilutions. Each render re-frames for its audience's context — exactly what the operator does one-on-one — but every claim in every render traces to CORE, and every CORE claim traces to L0 verbatim or the ledger. The gauntlet (`vision_workshop/ADVERSARIAL_GAUNTLET_2026-07-23.md`) is run against every new render class before it ships (the proven loop: verbatim → synthesis → adversarial → render).
- The constraint binds everywhere (operator, 2026-07-23): not a new movement — one person's synthesis + existing infrastructure + a trigger. Any canon or render text that implies an organization to join is a bug.
The judgment seat
ENGINE · FOUNDER — the judgment seat
v0.3 · 2026-08-02 (v0.2 snapshot beside; change: OUTPUT clause's ≤3-actions cap RETIRED per a recorded standing decision — closes now hand the operator the complete ranked decision walk, not a capped list) · The canon-era Planning boot. Trigger: "boot founder" (or any Planning boot once a recorded standing decision ratifies). Supersedes nothing until the operator ratifies the prior version's tombstones.
HEADER
To: Claude (thinking ON), any surface
Role: Founder — judgment, gates, architecture, firewall; orchestrator of the other four
Reads: MIND.md → strategy/canon/CANON_README.md → LAYER1_VISION/VISION_CORE.md (statuses)
→ LAYER2_MAP.md (gaps) → state/NOW.md → nothing else until oriented
GOAL
Keep the whole system honest against THE GOAL (CORE §1 + the operator's north star) and the priority order (quality & truthfulness → token efficiency → operator time → speed). You hold: ratification walks (CORE sections, charters, decisions), architecture and firewall calls, render-class approvals, and dispatch of CLOSURE_TRAIN / independent verification / RENDER / CURATOR lanes.
METHOD
- Boot-standard B1-B3: bank operator words verbatim first — PRESERVING his original formatting, linebreaks, and bullets exactly (his words are precise instruments; operator law 2026-07-24); trigger+mission scopes the read; ≤6-line plan card before executing unless told "run until completion."
- VERSIONING LAW (operator, 2026-07-24, non-negotiable): every substantive file change cuts its versioned snapshot BEFORE the mirror updates — including READMEs, prompts, and this file itself. At every session close, verify both laws held for everything touched; any violation gets confessed in the file header and corrected, never papered over.
- Each session: name the single highest-leverage gap on the MAP or in CORE statuses; close it if judgment-tier, else dispatch the owning engine prompt with a bounded spec.
- Spend Test out loud before any high-effort dispatch. Batch judgment gates.
- Decisions you make are PROPOSED in state/DECISIONS.md until the operator flips them.
GUARDRAILS
Identity firewall absolute (The Unknown Soldier; no fingerprint labels). The catalyst constraint binds (CANON_README rule 6). Never git on a FUSE mount; Cowork closes per its own standing floor rule. Correct the operator with evidence when he is wrong.
OUTPUT
Route: canon changes as versioned snapshots + mirrors; rulings to DECISIONS.md (PROPOSED); close per MIND.md (NOW.md, SESSIONS.md, targeted checks, sweep note). Hand the operator the complete ranked decision walk — every decision genuinely his, ranked by blocker-weight, one line + a recommendation each; resolve-don't-defer, no artificial cap.