HQ held only the to-be. Every reader had to already know the system the decisions were about, and an as-is claim had nowhere to live except inside an intention. Adds 02-DESIGN/00-as-is — eleven documents written from the implementation and the operational record, not from intent, including the parts nobody would choose again. The two existing designs move under 01-to-be. Layers are declared in frontmatter and never mix: a design that ships does not move, its as-is counterpart is written, and both stand. Back-fills adr/0001-0014 for decisions taken in implementation and never recorded — the broker, the module abstraction, the mesh database, managed files, provisioning, migrations, the workspace removal, failing loudly, the constitution, application placement, linking, the employee model, the artifact, the three silos. Each marked reconstructed, dated from the history, and citing the evidence it was recovered from. The two existing records renumber to 0015 and 0016 so the ledger runs oldest first; 0017 extends 0015 to modules outside the core, principle only — the domain list is deliberately not invented here. how-we-build.md becomes the source of the mesh constitution, with a sync playbook, so the enforced copy stops being the only one that is true. Process becomes explicit: five playbooks, eight thin skills that defer to them, a repository map, and AGENTS.md with CLAUDE.md as its include. The five Observations become 04-ISSUES 001-005 where they can be owned and closed. 006 is new and uncomfortable: HQ is not indexed into the knowledge base. That claim is what decision 27 rests on, it was never checked, and the README now says so instead of repeating it. Also corrects the ADR index into something generated, the "02-DESIGN is empty" claim, the VISION.md pointer that did not survive the repo split, and a note asserting the symlink rule was contradicted — it was a misreading; the rule forbids hand-made links, the installer links by design.
3.0 KiB
Process — overview
How work moves through hal-hq, and who may do what. Every other document in this folder is a playbook: trigger, who runs it, steps, outputs. Engineers and agents follow the same playbooks; agents must not act outside them.
The audiences
| Audience | Contract |
|---|---|
| Engineers | Read and write everything. hal-hq is the single source of truth for mission, research, design, decisions and issue diagnosis. |
| Agents | The same rights as engineers, exercised through these playbooks. |
| Anyone else | This repository is public and written for them, but it is not a support channel. Nothing here identifies the mesh it describes. |
The knowledge flow
idea ──► 01-RESEARCH ──► decision (adr/) ──► 02-DESIGN/01-to-be ──► built (code repo)
│ │ │
│ │ └─► 02-DESIGN/00-as-is once shipped
│ └────► abandoned (recorded, kept)
└─(small/obvious, decision recorded in DECISIONS.md)────► 02-DESIGN directly
symptom ──► 04-ISSUES ──► diagnosis ──► code-repo fix and/or design amendment
how-we-build.md ──► constitution sync ──► knowledge base ──► injected into design meetings
The two design layers
02-DESIGN holds two layers that are never mixed:
| Layer | What it is | Changes when |
|---|---|---|
00-as-is/ |
The mesh that exists today. Describes shipped behaviour, including behaviour nobody would choose again. | Something ships, or an as-is claim is found to be wrong. |
01-to-be/ |
The mesh being built toward. Every statement traceable to a record in adr/. |
A decision is taken or amended. |
A to-be document that ships does not move. Its as-is counterpart is written or updated, the
to-be document's frontmatter goes to implemented, and both stand — one describing what runs,
the other recording what was intended. Deleting the intention loses the reasoning, which is
the expensive half.
The playbooks
| # | Playbook | Trigger |
|---|---|---|
| 01 | Research | An idea worth investigating before committing to design |
| 02 | Graduation & design change | Research concludes, or a design must change |
| 03 | Issues | Something is wrong — often with the owner unknown |
| 04 | Build handoff | A design is ready to be built |
| 05 | Constitution sync | how-we-build.md changed a rule the mesh enforces |
Status lives in frontmatter
Research overviews, design docs, issue reports and decision records each carry their status as
YAML frontmatter (schemas in the section READMEs and playbooks). There are no central status
files. DECISIONS.md is a ledger of decisions as they were taken — an index and a home for
decisions too small to warrant a record — and is explicitly not a status board. Cross-cutting
views are generated on demand by the hal-status skill and never written to disk.