0003 is now superseded by 0056. Nothing is left proposed. Applied: - 06 corrected from ten contexts to seven plus the api, each row now stating why it passes the more-than-one-node test. work, knowledge and stream are named as mesh-hosted rather than dropped; `ai` folds into config; `record` is deferred explicitly rather than listed. Its frontmatter now cites 0055. - how-we-build §4 amended per 0054, and the derived page republished by playbook 05. The sync found the drift the playbook exists to catch: the published §4 and the source did not say the same thing. The source said "four accidents, not four boundaries"; the published page said "one intent expressed four times", and only the published page carried the scope caveat. Same rule, two texts, already diverging. Verified the republish by reading back -- the new rule is present and the old section's body returns nothing -- rather than trusting the success message. The two smaller findings: - 0051 separated the transport identity from the declaring authority. It said the token carries "an address" and "the identity to expect" without saying what the node dials. It dials the broker, so pinning only that would make the control plane's authority transitive and let a compromised broker forge declarations -- which, since the host applies whatever the link delivers, is the whole machine. The token now carries four things, and declarations are signed and verified per declaration. Cost recorded: rotating the signing identity is fleet-wide. - 0026 no longer restates 0022's rule about generated views. 0022's own words are "prose does not restate status; one place, and two is one too many", which is what 0026 was doing to it.
00-META
The northern star. What the mesh is, the environment it runs in, and what changes when it works — plus the engineering practice that holds across everything Novox builds. Every research effort and design decision is checked against this folder.
| File / folder | Purpose |
|---|---|
mission.md |
Vision, mission, and the values that decide arguments |
context.md |
The environment — conditions, not aspirations |
effect.md |
What is different when the work is done |
how-we-build.md |
The rules that hold across the mesh, each one earned. The source of the mesh constitution — the governed page the mesh injects into design sessions is derived from it. |
repos.md |
Where implementation lives, and what each repository owns |
process/ |
The playbooks — how work moves through this repository, for engineers and agents alike |
Rules
- Markdown only.
- Stable by nature. Changes here reflect a genuine shift in intent, not iteration. The one
exception is
how-we-build.md, which changes whenever a rule is earned — and only through its amendment process. - Research and design must be traceable back to what is written here.
- Instance-agnostic. These documents describe the mesh as a concept. No machine names, no counts, no topology.
On the architecture overview in the code repository
The code repository carries an architecture overview predating this folder. It is a useful
description of how the mesh works, and its content now lives — anonymised and checked against
the implementation — in 03-DESIGN/00-as-is/. GENESIS answers why;
that document answered how, which is the design layer's job.
It had also drifted from the implementation in ways worth recording, since both were found by comparing it against the code rather than by anyone noticing:
- It described the pipeline as having a separate builder process and a build stage that packages. Neither was true after 2026-08-04; the documents stayed stale until 2026-08-06 (ADR 0014).
- It listed the mesh as spanning a fixed number of named machines, which is exactly the content this repository cannot carry.
It also lists "symlinks, not copies" as a key design principle, and that is a genuine contradiction rather than a stale detail. The mesh's stated intent is that it creates no symlinks at all — the rule is not merely "only the installer may link", and a founding document elevating linking to a principle points the opposite way from where this is going.
What exists today is that the installer owns and reconciles every link
(ADR 0011) — an as-is fact, recorded in
03-DESIGN/00-as-is/05-runtime-and-installation.md.
Centralising who may link narrowed the incident class; it did not close it. The intent is to
remove the mechanism, recorded as ADR 0018.
A founding document contradicting the direction of travel is precisely the failure this folder exists to prevent.