v0.7.0
File first, govern after (ADR 041, #125).
A capture never waits on a person any more. A name the registry does not know used to park the
capture on a question to its submitter and then on a steward; two of five real notes were cancelled
by their own authors that way. Now the librarian files at once and PROPOSES the entity — a complete
page with approved_by: "" and a proposed registry entry — and a steward approves, merges or
declines it later, from whichever door is nearest, in one governed commit.
⚠ BREAKING CHANGES
- the capture statuses are
queued · claimed · filed · rejected · failed(resolvedsurvives
read-only on old rows).needs_inputandtriageare retired words the queue refuses by name;
rows found in them are returned toqueuedonce at startup, so nothing already captured is lost - the
brain_replyMCP tool is gone — nine tools, pinned by a test.brain_submit's
acknowledgement now names the entities the capture will be filed against and says unknown ones
will be proposed review_queue/review_decidespeak two new item kinds,identity-proposal(item id = the
entity id; verdictsapprove,mergewithinto,decline) andalias-proposal(item id =
<entity id>:<alias>;approve,decline);entity-proposalandparked-captureare read-only
legacy kinds on the rows that carry themstigmergy-queuekeepslist · show · claim · reclaim · purgeand losesrequeue · resolve · reject;stigmergy-entitiesis nowpending · approve · decline · merge · create · regenerate
(proposeis the librarian's job)- the admin console's
queue/{id}/requeue|resolve|rejectroutes are gone;entities/{id}takes a
registry id;entities/decideandentities/createare new. The Captures page is read-only - entity pages carry
approved_by(absent = confirmed before the field existed,""= proposed,
a name = who confirmed it) andproposed_aliases; the registry carriesproposed,
approved_byandproposed_aliases. The knowledge repo's librarian and meeting-distiller briefs,
entity template and linter move with it — both repos ship together
Added
librarian.identity— the proposal writer: folds every new name against the registry with the
birth gate's own fold (a known name becomes a proposed spelling, never a twin), writes the
entity page from every field the reasoning filled, reads the ledger so a declined name is never
proposed twice, and tells the gates exactly what it wrote- the ninth gate,
identity: every write underwiki/entities/is a declared proposal arriving
unconfirmed, or a proposed spelling proved byte for byte — nothing else entities.decide— approve / merge / decline for an identity, approve / decline for a spelling,
oneapplywith preflight, drift refusal, secrets scan, one commit and rollback on a failed push;
remote.decide_via_clonefor the deployed doors,Decided-by:trailer- the inbox is derived from the registry,
pages_indexand the ledger — no new table; proposed
entities are visible in search andlist_entities, marked - the console's Entities desk: each proposal with the registry verdict on its name, merge
candidates, Approve / Merge into… / Decline, proposed spellings, the registry browser, and
Register an entity born confirmed with the live name check - the Slack card for a proposal, with the same three verbs
- the filing report's proposals clause; the digest counts proposals decided
Removed
- the ask-back:
brain_reply, theneeds_input/triagestates, the three dispositions, the
parked-capture mint door,entities.situations, the console's queue drain, the meeting flow's
"reuse the parked distillation" rule (nothing is re-filed, so nothing is re-read)