General Proposal · Proposed / Non-Authoritative
Architecture Level · HTML-only HDO dogfood variance

Consultant-operative architecture

Cycle-2 decision board for commissioning formal Research, a traceable Consultant semantic candidate and orchestration guideline, progressive-disclosure boot, separately evidenced runtime adoption, interfaces, legacy transition, and delegation controls.

Checkpoint
T101-PH000-AC001-CHECK000
Review cycle
2
Date
2026-07-25
Revision
v0.2.0
Status
Pending HDO disposition
Decision owner
HDO
Current state
0 / 15 dispositioned
Authority boundary. This remediated CHECK000 package remains review material only. Until a durable HDO approving act, package merge, and merge-hash-bound #477 ledger complete the proof path, no child issue may mint and no task may execute. CHECK000 grants no board mutation; delegation reinstatement; legacy retirement; shared, root, external-runtime, or cross-initiative implementation; parent closure; deployment; or client release.
#325 HDO dogfood variance. This single-file HTML is the complete proposal carrier and HDO review surface, grounded only by the linked Analysis. By explicit HDO direction there is no JSON or Markdown companion. The variance is labeled, not concealed, and creates no authority beyond CHECK000 authoring and assurance.
Cycle 2 · all calls pendingCycle-1 HDO directions are retained in the QA / iteration trail as historical input. Every current control is reset for independent HDO disposition; no option is preselected and one lane never implies the state of the other.
Architecture decisions · AD0 / 8 dispositioned
Governance decisions · GD0 / 7 dispositioned
1
Orientation
What is being decided

The Architecture lane decides the Consultant semantic candidate, sibling orchestration directive, shared root boundary, progressive-disclosure skill, runtime adoption, interfaces, guardrails, and per-surface legacy transition. The Governance lane decides the five-task decomposition, exact authority, evidence independence, suspension/revocation, downstream assurance, retirement timing, and WDL commissioning proof. All fifteen cycle-2 calls are pending and independent.

Semantic authority
One T101 candidate
Candidate clauses define Consultant identity, limits, interfaces, and delegation doctrine; final family placement follows #450 compatibility or durable variance.
Operative mechanics
Directive, boot, and projection
A sibling guideline owns orchestration; the skill bootstraps it; root remains shared; T103 owns runtime mechanics.
2
Grounded constraints
What the evidence establishes

Merged and observed evidence

  • PR #476 authorizes CHECK000 package preparation, not activity execution.
  • Closed #277 and PR #556 merge 38df08a2 establish the formal Research v2.2.0 workflow for TK001.
  • PR #470 records split-brain identity, inherited-model failure, absent session boot, and prompt/runtime drift.
  • The #477 July-14 briefing amendment requires normative micro-text verbatim-or-direct and one unified cross-surface brief or explicit alignment check.

Binding limits and current collisions

  • Open #450, #513, and #518 own family architecture, skill/template quality, and Program role/HDO coordination; T101 routes dogfood evidence.
  • Commit d9a91040 introduced a detached Socratic-only in-repo skills/consultant, while the active global Consultant projection also collides.
  • Source reconciliation and runtime adoption are separate authority acts under T103/P-level mechanics.
  • All formerly pre-approved delegation categories remain suspended; legacy profiles remain distinct transition inputs.
3
Prompt-specific judgment
What remains Consultant synthesis

Recommended architecture

One combined T101-STD-001 semantic candidate as #450 dogfood; one sibling Consultant orchestration guideline; a bootstrap/progressive-disclosure skill; concise shared root entrypoints; T103-governed runtime adoption; preserved legacy inputs; and Consultant-side interfaces returning evidence to #518.

Recommended control path

Five sequential slices—Research, standard/guideline, skill/root, runtime/legacy, interfaces/delegation—then HDO GATE001. No default CHECK001 or new standalone downstream EVIDENCE/REVIEW artifacts; implementation cannot reinstate delegation.

4
Architecture comparison
Layered candidate versus collapsed alternatives
CriterionCandidate + sibling directiveThree standardsRoot/skill as authority
Single precedence chainStrong, #450-conditionedCross-file riskRuntime drift
Progressive disclosureDirective → skill bootMixedCollapsed
Runtime rollbackSeparate adoption proofExplicitImplicit
Legacy coveragePer-surface and reversibleFragmentedUnclear
Recommendation: layer the candidate, directive, bootstrap, shared entry, and runtime mechanics instead of treating generated or served text as normative. This is cycle-2 Consultant synthesis; it is not accepted until the HDO dispositions AD-01 through AD-08.
5–6
Independent decision lanes
Architecture and governance dispositions

Each card states a recommendation, reasoning, a genuine alternative with consequence delta, downstream impact, and an evidence boundary. Every control begins pending.

Filter

Architecture lane · AD

What the Consultant-operative architecture should encode · 8 decisions

AD-01Combined standard shapePending
Should one T101 candidate carry the tightly coupled Consultant semantics?

Recommendation

Author one combined T101-STD-001 semantic candidate with internal substandards as T101 dogfood for #450; preserve T101-STD-002/003 lineage and condition final family placement and acceptance on #450 compatibility or an explicit durable variance.

Reasoning

One operative benefits from one precedence and amendment chain without silently establishing Program-wide family precedent.

Alternative + consequence delta

Wait for #450 before authoring, or keep three independent files; waiting blocks useful dogfood while three files create cross-file precedence risk.

Downstream impact

TK001 placement research, TK002 candidate, #450 evidence, SPS lineage, and GATE001 acceptance.

GAP-001 · #450 placement owner
Non-binding illustrative Detail · candidate map
T101-STD-001 candidate → identity/authority | autonomy/evaluation | delegation/interfaces | adoption final family placement → #450 compatibility OR explicit durable HDO variance
Evidence boundary
The combined shape is a T101 candidate and dogfood input; CHECK000 cannot settle #450 or accept the final standard family.
AD-02Authority layeringPending
Which surface owns semantics, directive, boot, shared entry, mechanics, and execution?

Recommendation

T101 candidate = Consultant semantics; sibling Consultant orchestration guideline = operative directive/procedure; skill = bootstrap and progressive disclosure; root = concise shared entry; T103 = instruction/runtime mechanics; portable/global surfaces = distribution/adoption; issues/plans = execution contracts. Route family architecture to #450, skill/template quality to #513, and Program role/HDO architecture to #518.

Reasoning

Distinct layers prevent served or generated state from becoming silently normative and keep WDL a lifecycle router.

Alternative + consequence delta

Treat the skill, root prompt, or WDL as the full Consultant authority; simpler, but overloads owners and creates semantic/runtime drift.

Downstream impact

TK001 placement, TK002 guideline, TK003 boot/root boundaries, T103 adoption, and #450/#513/#518 routes.

GAP-003/004 · routed owners
Non-binding illustrative Detail · authority chain
SemanticsT101 candidate
DirectiveSibling guideline
BootConsultant skill
MechanicsRoot / T103 / runtime
Evidence boundary
#450, #513, #518, and T103 retain their own authority; routing evidence grants T101 no write mandate over those surfaces.
AD-03Root audience splitPending
What belongs in AGENTS.md, CLAUDE.md, the sibling guideline, and the Consultant skill?

Recommendation

Keep universal safety/execution rules and bounded tool mechanics at shared root; put the Consultant directive, persona/protocol, and unsupported-question-channel rules in the sibling Consultant orchestration guideline; have the skill bootstrap that directive. Any root edit requires exact P/T103 authority.

Reasoning

Root files are shared entrypoints, while the guideline is the stable Consultant procedure and the skill supplies progressive disclosure.

Alternative + consequence delta

Make CLAUDE.md the Consultant directive and AGENTS.md the executor directive; visible, but misclassifies shared entrypoints and does not serve all runtimes consistently.

Downstream impact

TK002 guideline, TK003 skill/root scope, exact P/T103 mandate, and cross-harness consistency.

GAP-003 · shared-root boundary
Evidence boundary
CHECK000 can request a bounded future mandate; it does not itself authorize root modification.
AD-04Skill source and runtime adoptionPending
How should the current in-repo and global Consultant collisions be reconciled?

Recommendation

TK001 researches ownership and placement; TK003 may reconcile the detached Socratic-only in-repo skills/consultant introduced by d9a91040 under exact source authority; TK004 separately adopts an approved package to an exact external/global target with target/hash/parity/rollback proof under T103 mechanics.

Reasoning

Source authorship, package distribution, and active runtime adoption are distinct acts; neither current collision may be overwritten implicitly.

Alternative + consequence delta

Directly replace in-repo and global skills, or retain legacy only; direct replacement bypasses ownership and rollback, while legacy-only preserves split-brain behavior.

Downstream impact

TK001 collision research, TK003 source reconciliation, TK004 adoption evidence, and #513/#518 dogfood return.

d9a91040 · runtime readlink · GAP-004
Evidence boundary
Both collisions are observed; CHECK000 authorizes neither source mutation nor active runtime projection.
AD-05Corrected R-05 precedencePending
Can an in-session HDO instruction silently outrank accepted clause text?

Recommendation

Accepted higher-altitude sources govern. An HDO instruction may authorize an explicit, scoped, durable variance or amendment; it does not silently override accepted standards. Material conflict stops affected execution until recorded disposition; suspected stale doctrine is routed, not opportunistically archived.

Reasoning

This corrected R-05 preserves HDO variance authority without destroying auditable precedence.

Alternative + consequence delta

Original R-05 gives an in-session HDO statement automatic precedence; responsive, but permits unrecorded override and ambiguous expiry.

Downstream impact

TK002 candidate wording, TK003 session behavior, variance records, and fail-closed conflict handling.

GAP-002 · P-STD-008-CLAUSE-002D
Evidence boundary
The precedence defect is established; this durable-variance correction remains proposed until HDO disposition and later candidate acceptance.
AD-06Orchestration and briefing enforcementPending
What must the Consultant orchestration directive own and observably enforce?

Recommendation

The sibling Consultant orchestration guideline owns announce-before-spawn; explicit model/effort/scope/permissions/output; required HDO disposition; Fable deny-by-default unless HDO-triggered; normative micro-text quoted verbatim or edited directly when briefing costs more context; and one semantic change spanning surfaces carried by one unified brief or an explicit named alignment check. The skill bootstraps/checks the directive; root holds universal pointers; positive/negative tests establish observable fail-closed enforcement where feasible.

Reasoning

PR #470 shows prose reminders and inherited-model defaults fail; SES003 and the #477 July-14 amendment require one routed procedure with testable briefing invariants.

Alternative + consequence delta

Repeat partial reminders across root files, memories, and skills; low local cost, but no single operative contract, alignment invariant, or negative proof.

Downstream impact

TK002 orchestration guideline, TK003 bootstrap/validation, TK004 runtime regression, and #513/#518 dogfood.

SES003 · #477 July-14 · PR #470
Proposed carry-forward · briefing invariants
announce before spawnexplicit modelFable HDO-triggered onlynormative text verbatim-or-directunified brief or alignment check
Evidence boundary
The guardrails and briefing amendment are durable inputs; CHECK000 does not implement their controls or tests.
AD-07Counterparty interface boundaryPending
How much of other roles belongs inside T101?

Recommendation

Candidate clauses define invariant Consultant-side contracts; guideline/skill references hold concrete packets and runbooks; the Reviewer interface includes all six #354 requirements. Return Consultant-side dogfood and boundary evidence to #518 while leaving non-Consultant identity Program-owned.

Reasoning

The Consultant needs testable interfaces without pre-empting Program role/HDO architecture.

Alternative + consequence delta

Define full counterpart identities inside T101; reduces indirection but exceeds the Consultant-only charter and seizes #518 scope.

Downstream impact

TK005 contracts, #354 coverage, and #518 receiving-owner evidence.

GAP-006 · #354 / #518 boundary
Evidence boundary
Six Consultant-to-Reviewer inputs are accepted; counterpart role identity remains outside this activity.
AD-08Legacy transitionPending
When may an individual legacy Consultant surface redirect or retire?

Recommendation

Map every legacy file to adopted/rejected/preserved content; keep each original live or frozen until replacement content coverage, active adoption, regression checks, link integrity, archive mapping, and reversible rollback are proven for that surface. TK004 may then redirect/archive/deprecate that surface before GATE001. Never delete distinct lineage.

Reasoning

Authorship alone does not prove the active runtime changed or that a safe fallback exists.

Alternative + consequence delta

Bulk archive at task start or retire when replacement is authored; both shorten overlap but risk coverage loss before adoption and rollback proof.

Downstream impact

TK004 per-surface mapping/adoption/retirement and GATE001 unresolved-residue inspection.

GAP-007 · GD-06 threshold
Evidence boundary
No legacy transition is authorized by CHECK000; unresolved surfaces remain preserved and no distinct lineage is deleted.

Governance lane · GD

How commissioning becomes executable and provable · 7 decisions

GD-01Frozen decompositionPending
What sequence should an approving CHECK000 freeze?

Recommendation

Five sequential tasks: TK001 Research/placement; TK002 semantic candidate and orchestration guideline; TK003 skill/root; TK004 runtime/legacy; TK005 interfaces/delegation controls; then HITL GATE001. No default CHECK001.

Reasoning

Formal Research resolves placement and enforcement questions before four end-to-end formalization slices.

Alternative + consequence delta

Keep four implementation-first tasks, or split by every file family; the first omits grounding and the second fragments acceptance and multiplies shared-surface coordination.

Downstream impact

Frozen plan register, post-proof TK001-TK005 issue contracts, sequencing, and GATE001 entry.

GAP-009 · Research v2.2.0
Proposed carry-forward · frozen sequence
TK001Research
TK002Standard / guideline
TK003Skill / root
TK004Runtime / legacy
TK005Interfaces / delegation
GATE001HDO
Evidence boundary
Only the complete approving CHECK000 proof bundle freezes these five rows; issue minting does not authorize execution.
GD-02Cross-surface authorityPending
What later write authority may CHECK000 grant?

Recommendation

Grant only exact named surface authority in the owning child contract. Root P-level and external runtime targets require explicit clauses, owner/parallel-work checks, diff or target/hash proof, reversible rollback, and no credential/session/cache/state movement.

Reasoning

AC001 outcome intent, routing to #450/#513/#518, or package authorship does not imply source-owner, root, deployment, or runtime authority.

Alternative + consequence delta

Infer writes from the activity outcome; faster, but violates ownership boundaries and obscures cross-repository and machine effects.

Downstream impact

Exact TK003 root mandate, exact TK004 external target, and evidence/rollback clauses.

Authority audit · P/T103 owners
Evidence boundary
This proposal asks the HDO to disposition future bounded mandates; it performs and authorizes none of the writes.
GD-03Reinstatement evidencePending
What evidence makes one delegation category eligible for an HDO call?

Recommendation

Require policy encoding, enforcement control, positive and negative tests, trace example, permissions check, regression trigger, suspension/rollback, and independently produced behavioral verification before HDO reinstatement. If the HDO does not later authorize that independent verification, the category remains suspended at GATE001.

Reasoning

Category-level proof prevents one passing surface from masking another gap, while independence cannot be inferred from self-verification.

Alternative + consequence delta

Reinstate the historic table when the skill exists; simple, but all-or-nothing and behaviorally unproven.

Downstream impact

TK005 category matrix, any separately authorized independence work, and GATE001 per-category calls.

GAP-008 · suspended lineage
Evidence boundary
Every category starts suspended. Implementation can reach eligibility only with all evidence, including later-authorized independence; only the HDO can reinstate.
GD-04Regression and revocationPending
What happens when a guardrail breaches or evidence invalidates?

Recommendation

Operationally suspend the affected category pending HDO review; only HDO reinstates, conditions, or revokes. Authority posture is not P-STD-002 work status.

Reasoning

This fails closed while reserving the durable authority act to its owner.

Alternative + consequence delta

Auto-revoke or merely log; the first over-delegates HDO authority, the second fails open.

Downstream impact

Runtime control, incident trace, GATE001 vocabulary.

GAP-008 · authority-state model
Evidence boundary
The state model is proposed; CHECK000 itself cannot reinstate or revoke any category.
GD-05Downstream assurancePending
What assurance is required downstream and for this remediation?

Recommendation

Downstream tasks default to self-verification carried in task/PR/control records plus terminal HDO inspection. Do not mint CHECK001 or new standalone downstream EVIDENCE/REVIEW artifacts unless the HDO later authorizes them. Retain historical CHECK000 assurance; require a fresh full-package adversarial review against the exact cycle-2 PR head for the current commissioning package.

Reasoning

This reduces default artifact weight without treating self-verification as independent delegation evidence or waiving exact-head commissioning review.

Alternative + consequence delta

Mandate independent review and standalone evidence for every downstream task; stronger default independence, but higher cost and contrary to the cycle-1 HDO direction.

Downstream impact

TK001-TK005 acceptance records, current C2 assurance, GATE001 inspection, and separate authorization if category independence is later desired.

HDO C1 direction · current C2 exact-head
Evidence boundary
Historical CHECK000 assurance remains part of lineage, while the remediated package still needs fresh exact-head review; neither is future implementation evidence.
GD-06Retirement timingPending
Who may retire a legacy surface and when?

Recommendation

TK004 may retire an individual surface before GATE001 only after replacement content coverage, active adoption, regression checks, link integrity, archive mapping, and reversible rollback are proven for that surface. Mere authorship is insufficient; unresolved surfaces remain preserved.

Reasoning

Per-surface proof shortens safe overlap without requiring a mandatory wait for GATE001 or removing the live fallback before adoption.

Alternative + consequence delta

Wait for GATE001 for every surface, or retire immediately after authorship; the first extends proven-safe duplication while the second removes fallback without adoption proof.

Downstream impact

TK004 transition records, per-surface proof, GATE001 residue inspection, and rollback preservation.

AD-08 · GAP-007
Evidence boundary
CHECK000 retires nothing; it proposes the exact future TK004 threshold and preserves all unresolved surfaces.
GD-07CHECK000 proof and mint timingPending
What WDL sequence completes commissioning and starts issue custody?

Recommendation

Follow WDL order exactly: record a durable HDO approving act; merge the commissioning package; post the merge-hash-bound #477 ledger; then immediately mint exactly TK001-TK005 from the frozen rows. Minting establishes issue custody only and does not authorize execution.

Reasoning

The durable act carries disposition and conditions, the merge fixes the package, and the ledger binds proof to the merge hash before issue creation.

Alternative + consequence delta

Treat conversation or PR merge alone as approval, or delay minting after the complete bundle; the first breaks proof while the second adds no control value.

Downstream impact

PR checkpoint record, merge order, #477 ledger, immediate TK001-TK005 creation, and separate execution authorization.

P-STD-008 · plan CHECK000 target
Proposed carry-forward · proof sequence
1 · HDO actDurable approving disposition
2 · MergeFix package head
3 · #477Merge-hash ledger
4 · MintTK001–TK005; no execution
Evidence boundary
Until all three proof legs exist, authoring and assurance are the only permitted CHECK000 work; minting after them still is not execution authority.
8
Never hidden
Open residue and gated future work
Authority

Root/shared edits, exact external runtime adoption, T103/P-level changes, and #450/#513/#518 owner surfaces need explicit future task clauses and owner checks; no write authority is inferred from routing or CHECK000.

Delegation

All categories remain suspended. TK005 can establish category evidence, but absent later HDO authorization for independent behavioral verification each category remains suspended at GATE001; only HDO may reinstate, condition, or revoke.

Legacy

Distinct inputs stay preserved until per-surface coverage, active adoption, regression, link integrity, archive mapping, and reversible rollback proof exist. TK004 may then retire only that proven surface; no deletion.

Assurance

No default CHECK001 or new standalone downstream EVIDENCE/REVIEW artifacts. TK001–TK005 self-verify for HDO inspection; current cycle-2 CHECK000 still requires fresh exact-head review and retains cycle-1 assurance history.

Acceptance

CHECK000 commissions and freezes only through its full proof bundle. GATE001 decides candidate/directive acceptance, runtime adoption, unresolved residue, activity closure, and only independently eligible category postures.

Release

No CHECK000 action authorizes task execution, board mutation, credential/session/cache/state movement, deployment, parent closure, or client release.

9
Traceability
Semantic sources and governed handoff

Analysis v0.3.0 is the sole semantic feed for this cycle-2 carrier. Closed #277 / PR #556 merge 38df08a2 supplies Research v2.2.0; open #450, #513, and #518 remain receiving owners, not implied write authority. Copying these paths or the transient review record has no authority effect.

artifacts/tasks/T101/workspace/PH000/AC001/plan_T101-PH000-AC001.md
artifacts/tasks/T101/workspace/PH000/AC001/analysis/analysis_T101-PH000-AC001-CHECK000_consultant-operative-architecture.md
templates/consultant/workspace/guideline_workspace_research.md
artifacts/tasks/T101/workspace/PH000/analysis/analysis_T101-PH000_consultant-agent-model-evidence.md
artifacts/tasks/T101/workspace/PH000/snotes/snotes_T101-PH000-SES003.md
artifacts/tasks/P/standard/standard_P-STD-008_workspace-development-lifecycle-standard.md

HDO controls and exportable cycle-2 decision record

All 15 remediated T101 decisions load pending. Architecture and governance lanes remain independent. “Change” requires an alternative. The transient export records cycle 2 and the exact authority boundary for governed scribing; it creates no JSON or Markdown companion, does not approve CHECK000, and authorizes no issue minting or execution.

Architecture lane

0 Accept · 0 Change · 0 Other · 8 pending

Governance lane

0 Accept · 0 Change · 0 Other · 7 pending