Audit C - charter and ruling alignment
Method: read the four governing documents, then fetched the live site read-only (home/planner, /browse, /game/color-the-dino/, /account, /privacy, /terms, /faq, /packs/, /shopper/, plus the R2 PDF for color-the-dino). No sign-in, no Customize, no form submitted. Every status below cites a file or a URL.
Grade: DRIFTING. The shipped product tracks the founder's latest [[2026-08-31-product-model-rulings|rulings]] well. It does not track the [[2026-08-31-studio-charter|charter]], and the charter has not been amended to catch up, so the governing document now describes an operation that no longer exists.
Part 1a - charter commitments
| # | Charter commitment | Status | Evidence | Note |
|---|---|---|---|---|
| §1 | Climb tiers 1-4 | Partial | live site = tier 1 catalog; Customize + planner live | Tier 2 half-built: generation is live but there is no credits ledger and no queue |
| §1 | Work self-arrives; founder is not a task queue | Contradicted | rounds.md 2026-09-02 daytime: 8 founder rulings (20-28) in one day; escalations.md carries 10 open founder items | The overnight round does self-dequeue; daytime is founder-driven hour by hour |
| §1 | Done = critic-gated and deployed | Partial | rounds.md 05:29: PRs #38-41 filed pending-review, "one tap each to flip live" |
Five artifacts are gated but NOT deployed, waiting on a founder tap - so "done" in practice means "awaiting founder", the exact state §1 rules out |
| §1 | Between decision pages the studio is silent | Contradicted | escalations.md 09:00 ET "founder taps owed" list of 6; rounds.md hourly ET timestamps | Continuous iMessage loop, not silence |
| §2 | Four role-scoped standing agents (sw-*) | Not yet | rounds.md round 1: "sw-* fleet agents not running -> in-session subagents"; fleet-manifest lines commented since the 8/31 walk-back | The org in §2 was never instantiated; all work ran as Ray's in-session subagents |
| §2 | engineering escalates production deploys / anything that starts a bill - hard gate | Contradicted (by standing founder allow, charter never amended) | rounds.md: 13 production deploys on 09-02; D1 scribble-works-ugc, D1 scribble-works-accounts, Worker sw-feedback-intake, Turnstile, Resend domain, metered AI Gateway |
Founder granted "allow merges" / "allow deploys" (09-01) and "ship accounts" (09-02 13:16). Legitimate authority - but the charter's hard gate is now dead text |
| §2 | engineering escalates the $5 Workers Paid flip | Implemented | escalations.md 09-01 item 5 "still blocked on the $5 Workers Paid click (founder: later)" | The one bill-starting item actually held |
| §2 | growth escalates every new external account | Implemented | escalations.md #8: Twilio held pending "open Twilio" | Resend/Turnstile/D1 were done on an explicit founder nod |
| §2 | growth escalates analytics on any child-profile surface | Implemented (vacuously) | /privacy: "No advertising trackers and no third-party analytics on this site" | No child profiles exist yet |
| §3 | The queue is the seam (rung 2+) | Not yet | engine rail (queue.md, 09-01 20:10): direct synchronous POST to the AI Gateway | No Cloudflare Queues, no Durable Object. Latency 7-18s is handled with a client loading state, not a job handle |
| §3 | Page one of every pack is parent-facing | Partial (claimed, unverifiable read-only) | site footer + FAQ: "Every playset opens with a page for the parent" | Playset PDF is assembled client-side; not checkable without submitting |
| §3 | Resend outbound, Email Routing inbound only | Implemented | rounds.md 13:18: hello@/catch-all -> ben; sign-in mail via Resend | Exactly as the charter's correction says |
| §4 | Generation stays local on Max until volume forces the API | Contradicted | escalations.md 09-01 evening, shopper item 2: "metered API from day one vs 'generation on Max' charter line (default proceed)"; queue.md engine rail; ruling 20 correction | Ray logged the conflict, applied its own default, and shipped. No founder ruling on this line is recorded anywhere |
| §4 | Cost of a studio round is unmeasured; that is why the round budget exists | Not yet - and made worse | queue.md engine rail: gateway "auth on, logs off, cache 0" | The one instrument that would price the metered path is switched off. Only per-call estimate on record is the $0.011 shopper figure |
| §4 | Sonnet round-count test (the page's own cheapest fix) | Not yet | queue.md item 7, still open | Never run |
| §4 | Design rule: full-burn contribution must not fall as price rises | N/A | no price exists | Aligned by inaction |
| §5 / §8b | Clearance precedes adoption of the name | Contradicted | queue.md item 3 "USPTO clearance check - this week, promised to founder" still open; queue item 9 attorney packet DEFERRED. Meanwhile: scribbleworks.co bought, brand in the footer of all 22 PDFs, /privacy + /terms published under the name | The charter calls this the expensive-to-reverse decision; adoption ran ahead of the check it named as a precondition |
| §6 | Adult-first, household-scoped account | Partial | /account and /privacy: one adult, one email, "No kid profiles" | Household = 1 adult; spouse invite is a queued follow-up |
| §6 | Child carries birthday, not age band | Not yet | no child profile exists in production | Reconciliation note ([[2026-08-31-product-model-rulings |
| §6 | No ad pixels, no third-party analytics, any rung, ever | Implemented (one note) | grep of all 7 pages: only external hosts are fonts.googleapis.com / fonts.gstatic.com | No trackers. Google Fonts is still a third-party request from a parent's browser - worth self-hosting to make the promise literal |
| §6 | Name and birthday travel least; not in logs | Implemented after correction | ruling 22 clarification 09:22; live sheet copy "Their name never goes to the AI and is never kept."; /privacy strip rules | Ray had told the founder "never reaches the server" at 08:27 and corrected it - the honest outcome |
| §6 | Retention is a TTL; deleting the household really deletes | Partial | /privacy: "There is no self-serve delete button yet; we do it by hand, and we say so"; queue.md follow-up "Retention sweeper ... not built" | Promise made, mechanism not built. The page is honest about the manual path; the 90d/180d TTLs are unenforced |
| §7 | Kill criteria dormant until launch | Implemented | rounds.md: "Cohort test PARKED by founder" | Nothing launched, no clock running |
| §7 | Signal 1 - three rounds with no gate pass | Not tripped | rounds.md tracker: 0 consecutive | Tracked properly |
| §7 | Signal 2 - founder time goes UP | Not measured, and the evidence points the wrong way | 8 rulings + 6-10 owed taps on 09-02 alone | This is the pre-registered signal the studio was supposed to watch and it is the one nobody is watching |
| §7 | Signal 3 - any round needs an unasked-for morning correction | Tripped at least twice | rounds.md: false "Ray mark" blocker relayed to 4 builders; clock labels off by ~1h, corrected; #49 incident took Customize down 6 min in production | Charter says "twice means unattended operation is not earned and the cron reverts to on-demand". Not applied, not discussed |
| §8c | Circuit breaker: <=4 artifacts, 3 critic iterations, branch+PR only, no prod/spend/outbound | Implemented for the 4:41 round | rounds.md round close 05:29: 4/4, breaker armed, "Nothing merged, nothing deployed, no R2 upload, no spend, no outbound" | One disclosed breach: making-change used 5 builder renders (cap 3), flagged in the PR |
| §8c | Two-week cron review ~2026-09-14 | Pending | charter resolution note | Not yet due |
| QA | Printable visual -> design-critic |
Partial | round 1/2 used design-critic; round 2026-09-02 used "Ray independent fresh-eyes critic per PR on the final PNG" | The gate map names a specific skill; the overnight round substituted an ad-hoc critic. It worked (4 real blockers caught) but it is not the named gate |
| QA | Rendered PDF -> verify-pdf-output, blocks publication to R2 |
Not run, ever | no mention in rounds.md, queue.md or escalations.md; 22+ PDFs are in R2 | The clearest gate-map breach: an entire artifact class shipped to production storage without its named gate |
| QA | Site page -> build-landing-page four-layer + design-critic |
Partial | design/behavior critics cited on #61 and per-PR; no build-landing-page run recorded | Home, Browse, game pages, /account, /privacy, /terms all deployed without the four-layer review |
| QA | Deployed behavior -> behavior-critic, source-blind |
Implemented | playset builder (PR #4, 3 cold runs), live maze 5/5, accounts v1, live source-blind checks that caught the #49 outage | The gate that is working best |
| QA | Vault note -> verify-vault-write |
Implemented | recommended-playsets spec ITERATE->revised; second-loop note ITERATE->PASS | |
| QA | Decision page -> verify-strategic-output |
Implemented | relationship-model doc gated before publish; one fabricated claim caught pre-publish | |
| QA | REQUIRED dispatch -> verify-dispatch |
Partial | run on round 1 and the accounts brief (8 blockers folded in); not recorded for the four 09-02 overnight builders or most daytime waves | |
| Design | Register split parent/kid | Implemented | live pages read warm-craft; PDF is its own palette | |
| Design | Print previews inside the frame motif | Implemented | class="frame-paper frame-skew-a sheet" and class="desk" on home, browse, game pages |
No naked previews found |
| Design | Printables fonts bundled, kid-legible, conventional numerals | Implemented | pdffonts color-the-dino.pdf: Andika + Andika-Bold embedded, ShortStack as accent |
Matches contract v2 and ruling 06:16 |
| Design | Ray = guide; bubble carries one actionable strategy; no drawn mark; B2 wordmark in footer | Implemented | PDF text: "Ray says: Outline a part first, then fill it in. Press light for pale, press again for darker." | Not a fortune-cookie bubble |
Part 1b - numbered rulings 1-28
| # | Ruling | Status | Evidence |
|---|---|---|---|
| 1 | Browse and playset-builder are ONE page | Implemented | /browse has the tray inline ("Playset 0/6") |
| 2 | How-it-works collapses onto Home | Implemented | /how-it-works/ returns 301 |
| 3 | Footer FAQ + standard footer pages | Implemented | footer: FAQ / Privacy / Terms on every page |
| 4 | Portal = "Log in / Create account" button, not a nav destination | Partial | header shows a "Sign in" affordance; /account exists as a page. Button treatment unverified read-only |
| 5 | Hamburger nav on mobile | Implemented (visibility flagged) | drawer markup "Where to?" present on all pages; queue item D still carries an unresolved 375px visibility flag |
| 6 | Catalog = games only with mini previews, packs scrapped | Implemented | /browse lists 22 game cards, no packs; /packs/ now serves the planner |
| 7 | Game detail shows a larger view | Implemented | /game/color-the-dino/ "tap to zoom" |
| 8 | Home highlights game TYPES + the skill each builds | Implemented | "Tracing - Builds Writing & Tracing", "Maze - Builds Logic & Puzzles" |
| 9 | Browse needs a better title | Partial | title is "Browse games" - functional, not the in-voice title queue item B asked for |
| 10 | Add-to-playset visible and usable | Implemented | "Add to playset" on every card and on the detail page |
| 11 | Multi-kid, one profile per kid, dashboard rows | Not yet | /privacy: "No kid profiles ... there is no place in the account to make one" (deliberate, per ruling 27 phasing) |
| 12 | The plan IS a screen, paid only; free = one card | Not yet | no calendar surface on /account |
| 13 | Upload -> profile update | Not yet | founder has not ruled; nothing built |
| 14 | Curation free / generation paid | Partial-Contradicted | planner is open and curation-only (matches); but Customize is gated on a free account (3/day), so generation is not paid - there is no paid tier at all |
| 15 | Feature is the "Playset planner", not "shopper" | Partial | copy is clean ("I'm Ray, the planner"); the /shopper/ route is still live and still the API path name |
| 16 | Headline "What does your kid need today?" | Implemented | live on Home |
| 17 | Chips + sentence both feed the picker, one button, no "or" | Implemented | chips above the box, single "Assemble the playset" |
| 18 | Three doors in order: Planner -> Ready-made -> The shelf | Implemented | Home in exactly that order, with "not sure what to say? start here" |
| 19 | Planner must be linked (header, drawer, Home) | Implemented | "Plan today's playset" in header and drawer |
| 20 | Code = zero marginal cost, deterministic; default engine; paywall is a separate question | Implemented | GENERATED maze (#45); age chip -> code path, sentence -> gateway (#48) |
| 21 | UGC promotion pipeline wanted; variants anonymous, standard branding | Partial | #55 log + classifier merged, #53 first variant built by hand; classifier cadence NOT armed (awaiting founder nod, escalations #6) |
| 22 | Retention wording belongs in the policy, not the page | Implemented | Customize sheet: "Their name never goes to the AI and is never kept." + Privacy link; /privacy carries the detail |
| 23 | Ray Data LLC; Florida law; hello@ inbox; classroom use allowed now | Implemented | /terms: "run by Ray Data LLC (Ray Data Co)", "governed by the laws of Florida", classroom printing allowed, contact hello@scribbleworks.co |
| 24 | Feedback text channel via Worker | Partial | Worker sw-feedback-intake deployed inert; email door live end to end; Twilio still gated on "open Twilio" |
| 25 | Accounts v1 first; feedback screened on verified accounts | Partial | accounts v1 live on production 13:18 ET; feedback screening is feat/accounts-v2-screening, not built |
| 25a | All generative endpoints require a verified household; caps, Turnstile, kill switches | Implemented | /privacy: account "required to have the AI customize a game"; GENERATIVE_REQUIRES_ACCOUNT=true; Turnstile live on /account |
| 26 | Planner open (curation only); paid gets fill-on-demand; identities from day one | Partial | planner open and capped - yes; identities table shipped; fill-on-demand generation not built; relationship decision doc published + gated |
| 27 | v1 parents/households, teachers as households, schools later | Implemented as plan | decision doc + phases; v1 shipped |
| 27a | Teachers create classrooms + seats with referral codes | Not yet | v3 scope |
| 28 | /account becomes the members area (members, billing, calendar, privacy controls) | Not yet | /account is sign-in + email + playset sync only; spec dispatched 13:24 ET |
| 28a | Calendar is Mon-Sun with a school-days toggle | Not yet | no calendar |
Part 2 - the top contradictions
Cost model (§4) vs actual gateway usage. The charter's settled premise is "generation stays local on the founder's Max subscription until volume forces the API." Production has been calling a metered AI Gateway (Sonnet for the planner and Customize words, Grok for art) since 2026-09-01. Ray logged the conflict as escalations.md item 2 with "default proceed" and shipped it. No founder ruling reversing the charter line exists in any of the four documents. Worse, the gateway is configured logs off, so the spend the charter said was the one unmeasured risk is now both real and unobservable. §4's own remedy - the Sonnet round-count test - has never been run.
"Done = critic-gated and deployed" is now "gated and waiting for a tap." Five artifacts (fraction-pizza, map-the-room, making-change, word-ladder, colorea-al-unicornio) passed their gates and sit
pending-reviewpending a founder "flip them" - the founder-as-queue state §1 exists to prevent. In the other direction, PR #49 was deployed on mocked tests alone and took Customize down in production for six minutes. Both halves of the sentence are being violated at once.QA gate map: two artifact classes shipped without their named gate.
verify-pdf-output(which the map says blocks publication to R2) has never been run on any of the 22+ PDFs now in R2.build-landing-pagefour-layer (which the map says blocks production deploy of a site page) has not been run on Home, Browse, the game pages, /account, /privacy or /terms.design-criticwas substituted by an ad-hoc "Ray independent fresh-eyes critic" for the whole 2026-09-02 overnight round. The three gates that were honored (behavior-critic, verify-vault-write, verify-strategic-output) are the ones that caught real defects, which is the argument for running the other three rather than against.The org table's hard gate has been dissolved rather than amended. §2 marks production deploys, bill-starting resources, and anything touching payment as engineering's hard gate. On 2026-09-02 the studio executed 13 production deploys, created two D1 databases and a Worker, provisioned Turnstile and a Resend sending domain, and applied a production migration. Every one traces to an explicit founder word ("allow deploys", "ship accounts") - so this is authorized, not rogue. The problem is that the charter still reads as if the gate is in force. Separately, the four-role org itself was never stood up: the sw-* fleet lines have been commented since the 8/31 walk-back and all work ran as in-session subagents, which means the escalation table describes boundaries between agents that do not exist.
Cadence: the 4:41 round is the compliant part; the day is not. The overnight round is textbook §8c - 4 artifacts, breaker armed, nothing merged, deployed, uploaded or spent. The daytime waves that follow it have no breaker, no artifact cap, and deploy straight to production; 24 PRs merged in one day. The charter has no daytime clause, so the majority of the studio's actual output runs under no written circuit breaker at all.
Copy contradictions the missing gates would have caught.
- /terms says "no accounts": "The headline: no accounts, no trackers, and your kid's name never reaches an AI model." Accounts shipped the same day; /privacy has a full Accounts section. Terms and Privacy contradict each other on the live site.
- /faq says "ages 3-4": "Printable games for little learners, ages 3-4", while every other surface says 2-10 and Browse offers five age bands.
- Ages 2-3 is a dead filter: header "Shop by age -> Ages 2-3" and the Browse facet both exist; the facet count is 0. Ruling 5 moved the floor to 2 in copy without any 2-3 game behind it.
Name adopted ahead of the clearance the charter made a precondition. "Clearance precedes adoption" (§5). Clearance is still queue item 3 ("this week, promised to founder"), the attorney packet is deferred, and in the meantime the name is on a purchased domain, the mail domain, the footer of all 22 PDFs, and two published legal pages. Charter §8b called this the expensive-to-reverse decision; brand surface is accruing against an unchecked mark.
Privacy promises vs features - mostly kept, two loose ends. The site keeps the hard promises: no trackers, no third-party analytics, one cookie only when signed in, name stripped before the model, no kid profiles. Two gaps: the retention sweeper enforcing the 90d/180d TTLs is listed in queue.md as "not built", and deletion is manual-by-email (honestly disclosed, but the charter says "real deletion, not a flag"). Minor: fonts.googleapis.com / fonts.gstatic.com are third-party requests from a parent's browser on every page.
Part 3 - drift in the studio process itself
- Batch size and breaker (rounds.md vs §8c): compliant inside the 4:41 round, absent outside it. The §8c amendment (up to 4, stop on 2 consecutive gate failures) was honored exactly once, on the only round it governs. Nothing governs a daytime wave that merges 24 PRs and deploys 13 times.
- Escalations discipline: escalations.md is well kept as a log and poorly used as a gate. Its dominant pattern is "Ray default applied, founder may veto" - shopper x4, customize x4, marketplace variants, wordmark size, ask-text storage, governing law, contact address, classroom use. Several of those are charter-level (metered API vs Max; policy contact; governing law) and were shipped on a default rather than escalated as the charter requires. The unresolved backlog is real: 10 numbered items, of which #7 and #9 closed within the day and the rest are still open.
- Decision-page usage: the charter's founder touchpoint is decision pages. Two were produced (studio charter; account relationship model) and both were gated with verify-strategic-output - that half works. But the operating channel is iMessage: rulings 20-28 all arrived as texts, and escalations.md tracks "founder taps owed" as a running list. The decision-page model has been replaced by a chat loop nobody wrote down.
- Self-correction is genuinely strong. Three misses were caught and logged inside a day: the false "Ray mark" blocker relayed to four builders (two builders pushed back with source evidence - correct behavior), the over-read of ruling 20 as a tier mapping (corrected by the founder), and the #49 production incident (caught by a source-blind live check, rolled back in 6 minutes, with a new standing rule attached). Clock labels drifted about an hour in the overnight log and were corrected against
date. This is the healthiest part of the process. - A rule the charter wrote and the studio has not applied: §7 signal 3 says twice-corrected means the cron reverts to on-demand. There have been at least two unasked-for corrections. Nobody has proposed reverting.
Part 4 - what the charter says should have been measured by now, and has not
| Should be measured | Status |
|---|---|
| Unit cost of a studio round (Max capacity, and now metered gateway spend) | Not instrumented. Gateway logs are OFF. The only figure on record is a per-call estimate ($0.011 for a planner call) |
| Sonnet round-count test vs the Opus baseline of 4 (§4, queue item 7) | Never run. The whole Phase-2 cost model rests on the untested assumption it was meant to check |
| Founder time direction (§7 signal 2) | Not measured. Circumstantial evidence points up, not down |
| Cohort week-1 test / first non-family downloads (the kill criterion's own instrument) | Parked by the founder pending "both magic moments felt". Kit ready, counter live, unrun |
| Ten non-family downloads in 90 days | Clock not started - correct, launch not declared |
| USPTO clearance on "Scribble Works" (queue item 3) | Not done, while the name accrues surface daily |
| Domain price pulls for scribbleworks.com / littlepress.com (queue item 4) | Not done; moot for littlepress, still open for the .com upgrade path |
The pattern: everything measurable about whether this is working is unmeasured, and everything about how much got built is measured in detail. That is precisely the failure shape §7 named in advance ("output is not the constraint").
Part 5 - is the site in alignment with the charter?
Grade: Drifting.
Split honestly: the product surface is Mostly aligned - the site matches the founder's site-tree, planner, three-door, GENERATED, UGC, entity and retention-wording rulings closely, the design contract is genuinely enforced (frame motif everywhere, bundled Andika in the PDFs, a bubble that carries real strategy, no photoreal children, no trackers), and the privacy page is unusually honest about what is not built. The governance layer is Off - the charter's cost model, hard gate, org table, queue seam, gate map, cadence and clearance-precedes-adoption rule are each either bypassed, substituted, or overtaken by a founder word that was never written back into the document. Net: Drifting, and drifting fast, because velocity is high and the document that is supposed to bound it is a week stale.
The three fixes that would most restore alignment
Re-baseline the charter against what the founder has actually authorized - today. Amend §2 (the engineering hard gate, now covered by standing allow-rules), §4 (generation is metered from day one, not local-on-Max), §8c (write a daytime clause, since most output ships there), and §2's org table (either stand up the sw-* agents or delete the table and say Ray-plus-subagents). A charter contradicted daily by authorized behavior provides no control at all; the fix is to make it true again, not to pretend the gates hold.
Run the two gates that have never run, and fix what they find.
verify-pdf-outputon the 22 live PDFs before any further R2 publication, andbuild-landing-pagefour-layer plusdesign-criticon the six shipped site pages. Three defects are already visible from the outside and would be caught immediately: /terms claiming "no accounts" while accounts are live, /faq saying "ages 3-4" while everything else says 2-10, and an Ages 2-3 filter with zero games behind it.Turn the measurement back on before the next build wave. Switch AI Gateway logs on and publish a per-round cost line; run the Sonnet round-count test (queue item 7); and close the USPTO clearance the charter made a precondition of adoption, before more brand surface accrues. Then apply §7 honestly at the 2026-09-14 two-week review, including signal 2 (founder time) and signal 3 (unasked-for corrections have already happened twice).