01-projects/printables-product/audit-2026-09-02

Audit C - Scribble Works: charter and ruling alignment

2026-09-02·audit·status: complete
scribble-worksauditcharterrulingsalignment

Audit C - charter and ruling alignment

Method: read the four governing documents, then fetched the live site read-only (home/planner, /browse, /game/color-the-dino/, /account, /privacy, /terms, /faq, /packs/, /shopper/, plus the R2 PDF for color-the-dino). No sign-in, no Customize, no form submitted. Every status below cites a file or a URL.

Grade: DRIFTING. The shipped product tracks the founder's latest [[2026-08-31-product-model-rulings|rulings]] well. It does not track the [[2026-08-31-studio-charter|charter]], and the charter has not been amended to catch up, so the governing document now describes an operation that no longer exists.


Part 1a - charter commitments

# Charter commitment Status Evidence Note
§1 Climb tiers 1-4 Partial live site = tier 1 catalog; Customize + planner live Tier 2 half-built: generation is live but there is no credits ledger and no queue
§1 Work self-arrives; founder is not a task queue Contradicted rounds.md 2026-09-02 daytime: 8 founder rulings (20-28) in one day; escalations.md carries 10 open founder items The overnight round does self-dequeue; daytime is founder-driven hour by hour
§1 Done = critic-gated and deployed Partial rounds.md 05:29: PRs #38-41 filed pending-review, "one tap each to flip live" Five artifacts are gated but NOT deployed, waiting on a founder tap - so "done" in practice means "awaiting founder", the exact state §1 rules out
§1 Between decision pages the studio is silent Contradicted escalations.md 09:00 ET "founder taps owed" list of 6; rounds.md hourly ET timestamps Continuous iMessage loop, not silence
§2 Four role-scoped standing agents (sw-*) Not yet rounds.md round 1: "sw-* fleet agents not running -> in-session subagents"; fleet-manifest lines commented since the 8/31 walk-back The org in §2 was never instantiated; all work ran as Ray's in-session subagents
§2 engineering escalates production deploys / anything that starts a bill - hard gate Contradicted (by standing founder allow, charter never amended) rounds.md: 13 production deploys on 09-02; D1 scribble-works-ugc, D1 scribble-works-accounts, Worker sw-feedback-intake, Turnstile, Resend domain, metered AI Gateway Founder granted "allow merges" / "allow deploys" (09-01) and "ship accounts" (09-02 13:16). Legitimate authority - but the charter's hard gate is now dead text
§2 engineering escalates the $5 Workers Paid flip Implemented escalations.md 09-01 item 5 "still blocked on the $5 Workers Paid click (founder: later)" The one bill-starting item actually held
§2 growth escalates every new external account Implemented escalations.md #8: Twilio held pending "open Twilio" Resend/Turnstile/D1 were done on an explicit founder nod
§2 growth escalates analytics on any child-profile surface Implemented (vacuously) /privacy: "No advertising trackers and no third-party analytics on this site" No child profiles exist yet
§3 The queue is the seam (rung 2+) Not yet engine rail (queue.md, 09-01 20:10): direct synchronous POST to the AI Gateway No Cloudflare Queues, no Durable Object. Latency 7-18s is handled with a client loading state, not a job handle
§3 Page one of every pack is parent-facing Partial (claimed, unverifiable read-only) site footer + FAQ: "Every playset opens with a page for the parent" Playset PDF is assembled client-side; not checkable without submitting
§3 Resend outbound, Email Routing inbound only Implemented rounds.md 13:18: hello@/catch-all -> ben; sign-in mail via Resend Exactly as the charter's correction says
§4 Generation stays local on Max until volume forces the API Contradicted escalations.md 09-01 evening, shopper item 2: "metered API from day one vs 'generation on Max' charter line (default proceed)"; queue.md engine rail; ruling 20 correction Ray logged the conflict, applied its own default, and shipped. No founder ruling on this line is recorded anywhere
§4 Cost of a studio round is unmeasured; that is why the round budget exists Not yet - and made worse queue.md engine rail: gateway "auth on, logs off, cache 0" The one instrument that would price the metered path is switched off. Only per-call estimate on record is the $0.011 shopper figure
§4 Sonnet round-count test (the page's own cheapest fix) Not yet queue.md item 7, still open Never run
§4 Design rule: full-burn contribution must not fall as price rises N/A no price exists Aligned by inaction
§5 / §8b Clearance precedes adoption of the name Contradicted queue.md item 3 "USPTO clearance check - this week, promised to founder" still open; queue item 9 attorney packet DEFERRED. Meanwhile: scribbleworks.co bought, brand in the footer of all 22 PDFs, /privacy + /terms published under the name The charter calls this the expensive-to-reverse decision; adoption ran ahead of the check it named as a precondition
§6 Adult-first, household-scoped account Partial /account and /privacy: one adult, one email, "No kid profiles" Household = 1 adult; spouse invite is a queued follow-up
§6 Child carries birthday, not age band Not yet no child profile exists in production Reconciliation note ([[2026-08-31-product-model-rulings
§6 No ad pixels, no third-party analytics, any rung, ever Implemented (one note) grep of all 7 pages: only external hosts are fonts.googleapis.com / fonts.gstatic.com No trackers. Google Fonts is still a third-party request from a parent's browser - worth self-hosting to make the promise literal
§6 Name and birthday travel least; not in logs Implemented after correction ruling 22 clarification 09:22; live sheet copy "Their name never goes to the AI and is never kept."; /privacy strip rules Ray had told the founder "never reaches the server" at 08:27 and corrected it - the honest outcome
§6 Retention is a TTL; deleting the household really deletes Partial /privacy: "There is no self-serve delete button yet; we do it by hand, and we say so"; queue.md follow-up "Retention sweeper ... not built" Promise made, mechanism not built. The page is honest about the manual path; the 90d/180d TTLs are unenforced
§7 Kill criteria dormant until launch Implemented rounds.md: "Cohort test PARKED by founder" Nothing launched, no clock running
§7 Signal 1 - three rounds with no gate pass Not tripped rounds.md tracker: 0 consecutive Tracked properly
§7 Signal 2 - founder time goes UP Not measured, and the evidence points the wrong way 8 rulings + 6-10 owed taps on 09-02 alone This is the pre-registered signal the studio was supposed to watch and it is the one nobody is watching
§7 Signal 3 - any round needs an unasked-for morning correction Tripped at least twice rounds.md: false "Ray mark" blocker relayed to 4 builders; clock labels off by ~1h, corrected; #49 incident took Customize down 6 min in production Charter says "twice means unattended operation is not earned and the cron reverts to on-demand". Not applied, not discussed
§8c Circuit breaker: <=4 artifacts, 3 critic iterations, branch+PR only, no prod/spend/outbound Implemented for the 4:41 round rounds.md round close 05:29: 4/4, breaker armed, "Nothing merged, nothing deployed, no R2 upload, no spend, no outbound" One disclosed breach: making-change used 5 builder renders (cap 3), flagged in the PR
§8c Two-week cron review ~2026-09-14 Pending charter resolution note Not yet due
QA Printable visual -> design-critic Partial round 1/2 used design-critic; round 2026-09-02 used "Ray independent fresh-eyes critic per PR on the final PNG" The gate map names a specific skill; the overnight round substituted an ad-hoc critic. It worked (4 real blockers caught) but it is not the named gate
QA Rendered PDF -> verify-pdf-output, blocks publication to R2 Not run, ever no mention in rounds.md, queue.md or escalations.md; 22+ PDFs are in R2 The clearest gate-map breach: an entire artifact class shipped to production storage without its named gate
QA Site page -> build-landing-page four-layer + design-critic Partial design/behavior critics cited on #61 and per-PR; no build-landing-page run recorded Home, Browse, game pages, /account, /privacy, /terms all deployed without the four-layer review
QA Deployed behavior -> behavior-critic, source-blind Implemented playset builder (PR #4, 3 cold runs), live maze 5/5, accounts v1, live source-blind checks that caught the #49 outage The gate that is working best
QA Vault note -> verify-vault-write Implemented recommended-playsets spec ITERATE->revised; second-loop note ITERATE->PASS
QA Decision page -> verify-strategic-output Implemented relationship-model doc gated before publish; one fabricated claim caught pre-publish
QA REQUIRED dispatch -> verify-dispatch Partial run on round 1 and the accounts brief (8 blockers folded in); not recorded for the four 09-02 overnight builders or most daytime waves
Design Register split parent/kid Implemented live pages read warm-craft; PDF is its own palette
Design Print previews inside the frame motif Implemented class="frame-paper frame-skew-a sheet" and class="desk" on home, browse, game pages No naked previews found
Design Printables fonts bundled, kid-legible, conventional numerals Implemented pdffonts color-the-dino.pdf: Andika + Andika-Bold embedded, ShortStack as accent Matches contract v2 and ruling 06:16
Design Ray = guide; bubble carries one actionable strategy; no drawn mark; B2 wordmark in footer Implemented PDF text: "Ray says: Outline a part first, then fill it in. Press light for pale, press again for darker." Not a fortune-cookie bubble

Part 1b - numbered rulings 1-28

# Ruling Status Evidence
1 Browse and playset-builder are ONE page Implemented /browse has the tray inline ("Playset 0/6")
2 How-it-works collapses onto Home Implemented /how-it-works/ returns 301
3 Footer FAQ + standard footer pages Implemented footer: FAQ / Privacy / Terms on every page
4 Portal = "Log in / Create account" button, not a nav destination Partial header shows a "Sign in" affordance; /account exists as a page. Button treatment unverified read-only
5 Hamburger nav on mobile Implemented (visibility flagged) drawer markup "Where to?" present on all pages; queue item D still carries an unresolved 375px visibility flag
6 Catalog = games only with mini previews, packs scrapped Implemented /browse lists 22 game cards, no packs; /packs/ now serves the planner
7 Game detail shows a larger view Implemented /game/color-the-dino/ "tap to zoom"
8 Home highlights game TYPES + the skill each builds Implemented "Tracing - Builds Writing & Tracing", "Maze - Builds Logic & Puzzles"
9 Browse needs a better title Partial title is "Browse games" - functional, not the in-voice title queue item B asked for
10 Add-to-playset visible and usable Implemented "Add to playset" on every card and on the detail page
11 Multi-kid, one profile per kid, dashboard rows Not yet /privacy: "No kid profiles ... there is no place in the account to make one" (deliberate, per ruling 27 phasing)
12 The plan IS a screen, paid only; free = one card Not yet no calendar surface on /account
13 Upload -> profile update Not yet founder has not ruled; nothing built
14 Curation free / generation paid Partial-Contradicted planner is open and curation-only (matches); but Customize is gated on a free account (3/day), so generation is not paid - there is no paid tier at all
15 Feature is the "Playset planner", not "shopper" Partial copy is clean ("I'm Ray, the planner"); the /shopper/ route is still live and still the API path name
16 Headline "What does your kid need today?" Implemented live on Home
17 Chips + sentence both feed the picker, one button, no "or" Implemented chips above the box, single "Assemble the playset"
18 Three doors in order: Planner -> Ready-made -> The shelf Implemented Home in exactly that order, with "not sure what to say? start here"
19 Planner must be linked (header, drawer, Home) Implemented "Plan today's playset" in header and drawer
20 Code = zero marginal cost, deterministic; default engine; paywall is a separate question Implemented GENERATED maze (#45); age chip -> code path, sentence -> gateway (#48)
21 UGC promotion pipeline wanted; variants anonymous, standard branding Partial #55 log + classifier merged, #53 first variant built by hand; classifier cadence NOT armed (awaiting founder nod, escalations #6)
22 Retention wording belongs in the policy, not the page Implemented Customize sheet: "Their name never goes to the AI and is never kept." + Privacy link; /privacy carries the detail
23 Ray Data LLC; Florida law; hello@ inbox; classroom use allowed now Implemented /terms: "run by Ray Data LLC (Ray Data Co)", "governed by the laws of Florida", classroom printing allowed, contact hello@scribbleworks.co
24 Feedback text channel via Worker Partial Worker sw-feedback-intake deployed inert; email door live end to end; Twilio still gated on "open Twilio"
25 Accounts v1 first; feedback screened on verified accounts Partial accounts v1 live on production 13:18 ET; feedback screening is feat/accounts-v2-screening, not built
25a All generative endpoints require a verified household; caps, Turnstile, kill switches Implemented /privacy: account "required to have the AI customize a game"; GENERATIVE_REQUIRES_ACCOUNT=true; Turnstile live on /account
26 Planner open (curation only); paid gets fill-on-demand; identities from day one Partial planner open and capped - yes; identities table shipped; fill-on-demand generation not built; relationship decision doc published + gated
27 v1 parents/households, teachers as households, schools later Implemented as plan decision doc + phases; v1 shipped
27a Teachers create classrooms + seats with referral codes Not yet v3 scope
28 /account becomes the members area (members, billing, calendar, privacy controls) Not yet /account is sign-in + email + playset sync only; spec dispatched 13:24 ET
28a Calendar is Mon-Sun with a school-days toggle Not yet no calendar

Part 2 - the top contradictions

  1. Cost model (§4) vs actual gateway usage. The charter's settled premise is "generation stays local on the founder's Max subscription until volume forces the API." Production has been calling a metered AI Gateway (Sonnet for the planner and Customize words, Grok for art) since 2026-09-01. Ray logged the conflict as escalations.md item 2 with "default proceed" and shipped it. No founder ruling reversing the charter line exists in any of the four documents. Worse, the gateway is configured logs off, so the spend the charter said was the one unmeasured risk is now both real and unobservable. §4's own remedy - the Sonnet round-count test - has never been run.

  2. "Done = critic-gated and deployed" is now "gated and waiting for a tap." Five artifacts (fraction-pizza, map-the-room, making-change, word-ladder, colorea-al-unicornio) passed their gates and sit pending-review pending a founder "flip them" - the founder-as-queue state §1 exists to prevent. In the other direction, PR #49 was deployed on mocked tests alone and took Customize down in production for six minutes. Both halves of the sentence are being violated at once.

  3. QA gate map: two artifact classes shipped without their named gate. verify-pdf-output (which the map says blocks publication to R2) has never been run on any of the 22+ PDFs now in R2. build-landing-page four-layer (which the map says blocks production deploy of a site page) has not been run on Home, Browse, the game pages, /account, /privacy or /terms. design-critic was substituted by an ad-hoc "Ray independent fresh-eyes critic" for the whole 2026-09-02 overnight round. The three gates that were honored (behavior-critic, verify-vault-write, verify-strategic-output) are the ones that caught real defects, which is the argument for running the other three rather than against.

  4. The org table's hard gate has been dissolved rather than amended. §2 marks production deploys, bill-starting resources, and anything touching payment as engineering's hard gate. On 2026-09-02 the studio executed 13 production deploys, created two D1 databases and a Worker, provisioned Turnstile and a Resend sending domain, and applied a production migration. Every one traces to an explicit founder word ("allow deploys", "ship accounts") - so this is authorized, not rogue. The problem is that the charter still reads as if the gate is in force. Separately, the four-role org itself was never stood up: the sw-* fleet lines have been commented since the 8/31 walk-back and all work ran as in-session subagents, which means the escalation table describes boundaries between agents that do not exist.

  5. Cadence: the 4:41 round is the compliant part; the day is not. The overnight round is textbook §8c - 4 artifacts, breaker armed, nothing merged, deployed, uploaded or spent. The daytime waves that follow it have no breaker, no artifact cap, and deploy straight to production; 24 PRs merged in one day. The charter has no daytime clause, so the majority of the studio's actual output runs under no written circuit breaker at all.

  6. Copy contradictions the missing gates would have caught.

    • /terms says "no accounts": "The headline: no accounts, no trackers, and your kid's name never reaches an AI model." Accounts shipped the same day; /privacy has a full Accounts section. Terms and Privacy contradict each other on the live site.
    • /faq says "ages 3-4": "Printable games for little learners, ages 3-4", while every other surface says 2-10 and Browse offers five age bands.
    • Ages 2-3 is a dead filter: header "Shop by age -> Ages 2-3" and the Browse facet both exist; the facet count is 0. Ruling 5 moved the floor to 2 in copy without any 2-3 game behind it.
  7. Name adopted ahead of the clearance the charter made a precondition. "Clearance precedes adoption" (§5). Clearance is still queue item 3 ("this week, promised to founder"), the attorney packet is deferred, and in the meantime the name is on a purchased domain, the mail domain, the footer of all 22 PDFs, and two published legal pages. Charter §8b called this the expensive-to-reverse decision; brand surface is accruing against an unchecked mark.

  8. Privacy promises vs features - mostly kept, two loose ends. The site keeps the hard promises: no trackers, no third-party analytics, one cookie only when signed in, name stripped before the model, no kid profiles. Two gaps: the retention sweeper enforcing the 90d/180d TTLs is listed in queue.md as "not built", and deletion is manual-by-email (honestly disclosed, but the charter says "real deletion, not a flag"). Minor: fonts.googleapis.com / fonts.gstatic.com are third-party requests from a parent's browser on every page.


Part 3 - drift in the studio process itself

Part 4 - what the charter says should have been measured by now, and has not

Should be measured Status
Unit cost of a studio round (Max capacity, and now metered gateway spend) Not instrumented. Gateway logs are OFF. The only figure on record is a per-call estimate ($0.011 for a planner call)
Sonnet round-count test vs the Opus baseline of 4 (§4, queue item 7) Never run. The whole Phase-2 cost model rests on the untested assumption it was meant to check
Founder time direction (§7 signal 2) Not measured. Circumstantial evidence points up, not down
Cohort week-1 test / first non-family downloads (the kill criterion's own instrument) Parked by the founder pending "both magic moments felt". Kit ready, counter live, unrun
Ten non-family downloads in 90 days Clock not started - correct, launch not declared
USPTO clearance on "Scribble Works" (queue item 3) Not done, while the name accrues surface daily
Domain price pulls for scribbleworks.com / littlepress.com (queue item 4) Not done; moot for littlepress, still open for the .com upgrade path

The pattern: everything measurable about whether this is working is unmeasured, and everything about how much got built is measured in detail. That is precisely the failure shape §7 named in advance ("output is not the constraint").

Part 5 - is the site in alignment with the charter?

Grade: Drifting.

Split honestly: the product surface is Mostly aligned - the site matches the founder's site-tree, planner, three-door, GENERATED, UGC, entity and retention-wording rulings closely, the design contract is genuinely enforced (frame motif everywhere, bundled Andika in the PDFs, a bubble that carries real strategy, no photoreal children, no trackers), and the privacy page is unusually honest about what is not built. The governance layer is Off - the charter's cost model, hard gate, org table, queue seam, gate map, cadence and clearance-precedes-adoption rule are each either bypassed, substituted, or overtaken by a founder word that was never written back into the document. Net: Drifting, and drifting fast, because velocity is high and the document that is supposed to bound it is a week stale.

The three fixes that would most restore alignment

  1. Re-baseline the charter against what the founder has actually authorized - today. Amend §2 (the engineering hard gate, now covered by standing allow-rules), §4 (generation is metered from day one, not local-on-Max), §8c (write a daytime clause, since most output ships there), and §2's org table (either stand up the sw-* agents or delete the table and say Ray-plus-subagents). A charter contradicted daily by authorized behavior provides no control at all; the fix is to make it true again, not to pretend the gates hold.

  2. Run the two gates that have never run, and fix what they find. verify-pdf-output on the 22 live PDFs before any further R2 publication, and build-landing-page four-layer plus design-critic on the six shipped site pages. Three defects are already visible from the outside and would be caught immediately: /terms claiming "no accounts" while accounts are live, /faq saying "ages 3-4" while everything else says 2-10, and an Ages 2-3 filter with zero games behind it.

  3. Turn the measurement back on before the next build wave. Switch AI Gateway logs on and publish a per-round cost line; run the Sonnet round-count test (queue item 7); and close the USPTO clearance the charter made a precondition of adoption, before more brand surface accrues. Then apply §7 honestly at the 2026-09-14 two-week review, including signal 2 (founder time) and signal 3 (unasked-for corrections have already happened twice).