papa-hq has no ledger. Its root is AGENTS.md, CLAUDE.md, README.md, every decision is a numbered record, and its graduation playbook has no path for an unrecorded decision. hal-hq now matches. The ledger's 41 entries classified as: 10 restating a record, 11 restating design docs, 15 describing how this repository works with the reasoning sitting in a README rather than anywhere citable, 3 small rules with no home, 2 superseded stubs. Mostly a copy — and a hand-maintained index, the exact pattern ADR 0022 had just rejected for the decision index on the grounds it drifted after one addition. Keeping one copy of that while removing another is not a position. It also collided by name with 02-DECISIONS/ in any directory listing. Nothing was dropped. Records 0019-0025 give the repository decisions the reasoning they never had: HQ is its own repository and is public, design has two layers, work moves through playbooks, status lives in frontmatter, issues have a front door, the numbering is the flow, HQ is the source of the constitution. 0026 records the ledger's own removal. The three orphan rules went to how-we-build, where a rule is enforced and keeps the incident that earned it — the package rule was genuinely unwritten anywhere. Two lab decisions stated only in the ledger went into the lab design. "Deliberately not decided" went to the research effort and design document each question actually belongs to. The chronological view the ledger provided is now generated from record frontmatter, which is what it was for. The cost, stated in 0026 rather than glossed: a record is more work than a table row, so the risk is a small decision going unrecorded because nobody wanted to write a document. how-we-build takes rules cheaply, which is the mitigation, not a solution.
1.8 KiB
1.8 KiB
Playbook 05 — Constitution sync
Trigger. how-we-build.md changed a rule that the mesh enforces at
runtime.
Who runs it. Whoever made the change.
Why this playbook exists
The mesh injects a constitution into every eligible design meeting; agents check their output
against it and a constitution-check phase can block a meeting. That text is derived.
how-we-build.md is the source.
Two texts stating the same rules will drift, and the enforced copy winning by default means the reasoned copy quietly stops being true. This playbook is the mechanism that stops that — and, per the repository's own rule, it is how the rule "HQ is the source" is checked.
Steps
- Edit
how-we-build.md. Each rule keeps the reasoning that earned it; the derived page carries the rule alone. - Record the change as a decision — a rule the mesh enforces is architecturally significant. Playbook 02.
- Publish the derived page to the knowledge base under the constitution slug, replacing its body. Keep the section numbering stable: the meeting orchestrator and the review fragments cite sections by number.
- Verify the derived page reads back with the change present. A publish that reported success and did nothing is exactly the failure class this repository exists to name.
- Note the sync in the decision record's Consequences.
Rules
- Never edit the derived page directly. An edit there survives until the next sync and then vanishes, taking its reasoning with it.
- The derived page may only be tightened by per-team override pages, never relaxed.
- If the sync cannot be performed, say so in the record. An unsynced rule is a rule the
mesh does not enforce, whatever
how-we-build.mdsays.