SYSTEMIZATION AUDIT — can this organization run without us?
v0.1 · 2026-08-08 · Founder (Cowork) · Answering the operator's question verbatim: "an organization can run on systems, policies, and procedures -> do we have a complete system documented that can be run without us? can we continue to systemize our best practices, lessons learned, tools built, capabilities, etc etc etc" (banked OPERATOR_LOG this date). Evidence: two Explore inventory lanes this sitting (org-docs sweep + tools/lessons sweep); their full tables in SESSIONS-adjacent lane reports, key receipts inlined below.
The honest verdict, first
No — not complete. Roughly: research production and mechanics could run without us today; judgment, voice, and continuity could not. And the sharpest finding: decisions become tools here, but lessons become archives — 40+ ratified decisions auto-execute as code/gates every 15 minutes, while ~100 prose lessons in session logs propagate only if a human happens to re-read them. We have logs; we do not yet have a lessons system.
What IS stranger-runnable today (documented, current, tested by inventory)
- The dispatch system — MIND.md → CLAUDE.md → SHORTHANDS.md + PROMPT_CONVENTION.md → 8 boot files. A competent stranger could orient and dispatch from cold.
- Decision governance — DECISIONS.md (the full recorded-decision trail) + RESERVED_TO_OPERATOR.md (the 8-item Class-C boundary: identity, publication, money, legal, sends, candidate coordination). The line between delegable and operator-only is WRITTEN.
- Publication mechanics — PUBLISH_MENU.md one-word fires + deploy pastes + live-verify gates.
- The tools estate — 87 scripts, tools/README.md covers 86/87 (gap_finder re-checks this every run), sampled docstrings excellent, 490+ test files, guards cite their decision IDs in-code. A stranger could discover and run everything.
- Research methodology — as of this week: the canon (CANON_README.md) + the Methods Codex (research/methods/README.md, 15 processes, failure modes included) + IMPROVEMENT_BACKLOG.md. one of this library's own project records closed most of this gap for the research half of the org.
- Session discipline — open/claim/close protocol, B1–B4 boot standard, append-only memory.
What is PARTIAL (a stranger would struggle)
- Canon status is scattered — RATIFIED vs PROPOSED per layer/section lives across dated memos, not one status surface.
- Track state files are tribal — NOW_CODE.md / NOW_RESEARCH.md are operational queues; there is no "you are new here, 30 minutes to oriented" cold-start per track.
- OPERATOR_RUNBOOK.md assumes mid-mission context; no cold-start section.
- OPERATOR_LOG.md — 2,700+ lines of banked judgment with NO retrieval index; the "when to ask the operator" heuristic is uncodified beyond operator-only.
- Standards — 19 docs exist (strategy/standards/STANDARDS_REGISTER_v2) but no periodic audit ritual runs them against practice.
What is TRIBAL-KNOWLEDGE-ONLY (hard stop without a live handover)
- Voice and persona — examples exist; no "how to write as this project" guide.
- Novel-scenario judgment — the firewall names what's reserved, not how to reason about a case no rule anticipated.
- Org resilience — NO succession/bus-factor doc; the DPC RAM self-assessment (ADOPT-ALL in the standards register since 2026-07-17, named there as "the only org-resilience/succession check") has never been run. If the operator were unavailable two weeks: dispatch/decisions/publish would run; canon production and voice coherence would stall.
The lessons asymmetry (the single most fixable structural gap)
Institutionalized (lesson → running code): leak-pattern bulkhead (one of this library's own engineering records) · commit-sweep
automation · versioned-never-overwrite · keyed-merge + stale-checkout guard
(one of this library's own engineering records) — all fire unattended every 15 minutes.
Archived-only (lesson → prose that stops moving): multi-AI capture behavior patterns · brief
failure classes B1–B7 · verification throughput rates · "unanimity is a warning" — each
hand-written once (LESSONS_FIRST_TWO_PACKAGE_BUILDS,
multi_ai_capture/LESSONS_LEARNED), none wired
into a gate, no status marking "proven-binding" vs "one-wave provisional." The same failure
classes get re-discovered per build.
Can we continue to systemize? Yes — the mechanism, scoped (→ one of this library's own project records, boot cut)
Extend the codex pattern from research processes to the WHOLE organization — the Systems Codex:
- Systems register (the org-level analogue of the methods index): every organizational function → its governing doc → owner track → stranger-runnable status → gap. Seed = this audit's tables. One page, CURATOR-refreshed, statuses live in it alone.
- The lessons pipeline (closes the asymmetry): every session close may name candidate
lessons (one line, existing close — no new loop); a periodic CURATOR-class pass distills them
into a LESSONS register with two statuses only —
provisional/binding; promotion to binding REQUIRES landing as a gate, template edit, or tool guard in the same pass (the decisions-become-tools path made mandatory for lessons). Backfill starts from the two existing LESSONS docs + SHORTHANDS' embedded precedents. - Cold-start pack: per-track "new here, 30 minutes" orientation + a runbook cold-start section + an OPERATOR_LOG index (mechanical, generated).
- Continuity posture: actually run the DPC RAM self-assessment; write the two-weeks-absent protocol (what runs, what pauses, who holds operator-only — answer: everything operator-only PAUSES, by design; the doc says so plainly).
- Canon status surface: one generated table of layer/section → RATIFIED/PROPOSED/date.
Fire-ready boot: 2026-08-08_BOOT_SYSTEMS_CODEX.md. Mostly automated assembly against what exists — same "formalize and organize" shape as one of this library's own project records, which is the proven precedent for exactly this kind of pass.
What this audit does NOT claim
That "run without us" is the goal for everything: operator-only (identity, money, legal, sends, publication words) is operator-reserved BY DESIGN and stays so; the vault stays sealed; the replication kit already answers "without us" for OTHER cities. This audit is about making everything delegable actually delegable, and continuity survivable.