Skip to content

The Promises Ledger

Every commitment VEILOS has made about its own future, each one whole, with the date it comes due and the thing that would decide it was kept. Derived live from the organism's own registry each time this page is read — never written by hand.

No promise is currently overdue and none has lost its guard. 4 are pending — recorded, not yet due, and deliberately not counted as anything earned.

3 of these are standing promises — no end date, because a named guard re-decides them on every test run. This page is served by a Worker, which cannot watch that happen; it reports what the promise cites and stops there. The build gate is the thing that resolves the citation and would refuse to ship if the guard were gone.

13 recorded 5 kept 3 standing 4 pending 0 overdue 0 guard gone 1 undischargeable
Status Due Promise
undischargeable undated
THE OUTWARD CLAIM CLASS — scope decision remains founder-owned and unstarted.
D-S256.7 · owner: founder · nothing can currently decide this
pending S350
Recheck the owned gap in veil/crossing.mjs: the Phase-0-manifest-pinned crossing entry point; engine.crossVeil (its only implementation) is Node-lane-only, so no veil crossing is ever policy-evaluated or recorded at the edge. Whether to build an edge policy-evaluation twin (receipts, quarantine, telemetry with real traffic) is a product decision, not a refactor.
D-S300.13 · owner: founder · kept when: entry removed from NODE_ONLY_MODULES, or recheckSession advanced with a decision
pending undated
The control plane's write-back currency probe resolves its repository root from its own module path and can therefore only measure studio-ops. The corrected resolution was shipped as Ark cargo so every sibling can inherit it; VEILOS no longer waits on it.
D-S260.4 · owner: founder · kept when: upstream scripts/check-writeback-currency.mjs resolves root from git or cwd · evidence: vaultspark-studio-ops:scripts/check-writeback-currency.mjs (another repository)
pending S350
veilCrossings ships entry-bounded (150) with its BYTES abstaining, because S214 #3 rightly refuses a measured basis without a maxBytes, and funding one would either grow an invariant already 1,166,062 B over the wall or take reach from another ring. A real row measures 517 B, so the ring's realistic ceiling is ~77,550 B and it currently lands in the unbudgeted residual. Through S297 this promise said that residual was over-reserved and therefore that "the honest funding source likely exists". S298 measured it in the reserve's own denomination and it does not: the residual is BREACHED, so funding this ring out of it would spend bytes the organism has already overdrawn. The live authority is census.residual_verdict on /_health, which re-decides this on every read — fund from that, never from a figure typed into this sentence.
D-S300.14 · owner: agent · kept when: either veilCrossings gains a funded maxBytes with the source of those bytes named, or the ring is documented as permanently entry-bounded and its residual cost accepted by measurement
pending S350
Decide whether the edge crossing policy should gain teeth that can genuinely refuse or quarantine a passage, beyond the rate limiter that is its only refusal today. S268 closed the RECORD half of D-S261.4 and deliberately did not answer this: denying a crossing turns a real person away at the front door, so the rules must be ones the founder wants enforced. Recorded now because the record half made the gap precise — evaluateCrossingPolicy's own deny branch is currently UNREACHABLE (checkCrossingRate 429s first), so the edge policy is a judgement that cannot refuse. That is a coherent state to stay in; it is not a coherent state to leave undecided by accident.
D-S290.11 · owner: founder · kept when: either an edge policy that can return a non-allow verdict is enforced with signed receipts, or the deny branch is retired and the rate limiter is documented as the whole enforcement story
standing continuous
Record prose is written with the editor or via a file, never through shell interpolation — PowerShell reads the backtick as an escape introducer and eats the first character of every Markdown code span. D-S250.32 promised this in prose and it recurred ten sessions later.
D-S260.8 · owner: agent · upheld by: tests/s260-carrier-and-vocabulary.test.mjs control-character ratchet over the record surfaces · evidence: tests/s260-carrier-and-vocabulary.test.mjs
standing continuous
Every comment claiming parity with a named module or symbol must actually READ that counterparty; the population that does not is debt and may only ever shrink.
D-S250.59 · owner: agent · upheld by: tests/s250-parity-claims.test.mjs BASELINE_UNBACKED monotone ceiling · evidence: tests/s250-parity-claims.test.mjs
standing continuous
The closeout coherence gate runs LAST, on the final tree, right before commit — a claim stated in three files at once, and false for seventeen sessions (D-S258.3): the gate was on none of the autopilot's eleven steps while every one of those three comments said it ran.
D-S258.3 · owner: agent · upheld by: tests/s258-production-sha-carriers.test.mjs asserts steps.at(-1) === 'closeout:coherence' against the autopilot's own parsed step list · evidence: tests/s258-production-sha-carriers.test.mjs
kept S265
src/worker/ip.mjs publishes, to the public: "Every crossing is policy-evaluated and produces a signed verdict; nothing crosses unwitnessed." That is FALSE in production. crossVeil — the only implementation of the faculty — is Node-lane only, so no crossing at the edge is ever policy-evaluated, no verdict is ever signed, and state.veilCrossings is permanently empty. The sentence is not aspirational phrasing; it is stated in the present tense as a property the organism has. This is the outward-claim class (D-S256.7) on a live public surface, and it is the same defect S256 fixed on the front-door h1 — a claim the organism's own machinery grades false, published as though earned.
D-S261.3 · owner: founder · kept when: either an edge twin evaluates crossings, or the ip.mjs sentence is rewritten to describe what production actually does — asserted by tests/s262-ip-doctrine-grading.test.mjs, which drives the live renderer in both states · evidence: tests/s262-ip-doctrine-grading.test.mjs
kept S270
Decide what edge event constitutes a veil crossing, so the faculty can reach production. S261 proposed shadow mode (evaluate and record, deny nothing) as a way to convert the enforcement question into a measurement — and that proposal was too strong, which is recorded here rather than quietly dropped: shadow mode still requires a TRIGGER, and choosing the trigger is precisely the product decision D-S251.1 declined to make silently. Building the twin before that choice would ship an inert primitive, the most recurring defect class in this record, which the edge-reachability sentinel would correctly red.
D-S261.4 · owner: founder · kept when: a trigger is chosen and recorded as a decision, or the faculty is retired — asserted by tests/s268-edge-veil-crossing.test.mjs, which drives the recorder and reads the live handler · evidence: tests/s268-edge-veil-crossing.test.mjs
kept S303
scripts/lib/test-live-state.mjs states a placement claim — that its annotation scan must treat the annotation as a COMMENT rather than as text appearing inside one, found 'on the first full-suite run after this shipped' against tier1-test-ambient-state.mjs:14, which holds the annotation inside a string literal as its own fixture. The claim is registered here rather than suppressed because the calibrated sweep caught it correctly: it arrived in a studio-ops propagation drop during S268, so it is UPSTREAM-owned code making a dated-shaped promise inside this tree. Registering it keeps the sweep honest without editing a file this repo does not own — the fix, if one is needed, belongs upstream as Ark cargo (D-S250.48).
D-S293.11 · owner: upstream · kept when: the upstream owner either fixes the scan's comment detection or the annotation contract is restated so a fixture string cannot satisfy it; VEILOS observes, and does not patch a propagated file in place · evidence: vaultspark-studio-ops:scripts/lib/test-live-state.mjs (another repository)
kept S266
D-S259.3 split responsiveEvidenceCurrent by REASON rather than force-greening it, and that was right. But it enumerated ONE tolerable reason — build_sha_mismatch — and a second reason that is equally deploy-gated sits outside the classification. S262's suite reds on verified_at_stale: the cached capture has simply aged out, and only a fresh Playwright run against a real deploy can clear it. That is the S260 keystone once more — a split classifies, and an unclassified member falls to the default side. It is left as a NAMED honest red rather than widened in a hurry at the tail of a long session, because relaxing a release tolerance without first verifying deploy.mjs still refuses is how a decoy gets built inside a fix (S251's lesson about S250).
D-S262.2 · owner: agent · kept when: the reason classification is derived rather than enumerated, with deploy.mjs's refusal verified BEFORE the suite is relaxed and asserted after — asserted by tests/s263-responsive-reason-classification.test.mjs · evidence: tests/s263-responsive-reason-classification.test.mjs
kept S268
The parity guard reads a QUOTED example of a parity claim as a real claim. Found live at S261: a comment in src/core/obligations.mjs quoting an illustrative claim reddened the guard, because the claim form is verbatim identical whether it is asserted or merely recounted. This is the same blind spot D-S260.7 fixed in the production-claim predicate, where the rule adopted was that a quotation mark immediately before the phrase disqualifies it — tense frees the paraphrase, quoting frees the verbatim. The parity guard has the tense half and not the quoting half, so a record cannot yet discuss its own parity claims without re-asserting them. Worked around at S261 by rephrasing rather than by fixing the guard, which is the weaker move and is recorded as such.
D-S261.7 · owner: agent · kept when: parityScan gains a quote-disqualifier with a control proving a quoted claim does not red and an asserted one still does — asserted by tests/s263-parity-quote-rule.test.mjs · evidence: tests/s263-parity-quote-rule.test.mjs

Machine ledger (JSON) → · All five censuses → · The Boundary Census → · The Abstention Ledger → · The Failure Census →

A promise recorded here is not a promise kept. Pending means the date has not arrived; standing means there is no date because a named guard upholds the promise continuously; undischargeable means the commitment is real but nothing in the organism can currently decide whether it holds, which is debt rather than either a success or a failure. Guard gone is the loudest row on this page: the promise still stands and the thing that enforced it has been removed. The organism spent sixty sessions learning not to overstate what is true of it now. This page exists because it had never once been accountable for what it said would be true later — and for two of those sessions it filed three continuously-enforced promises under recorded, never judged, which is the bucket it reserves for commitments nothing can decide. Naming the class was the fix.

Leave an imprint →

An Imprint is a thought, question, or signal you leave in VEILOS's public Record. VEILOS keeps exact Imprint bodies in a bounded 500-row Record window. Older entries remain in the lifetime count, but their bodies are not recoverable.

Signed in as a Sovereign? Leave this blank — we use your current session. Visiting without a session? Your Sovereign ID is required.

Don't have a Sovereign ID yet? Cross the Veil first →