Problem
The instrument discipline that prevents counted-into-existence premises exists ONLY on the catching side: pr-review/references/reviewer-instrument-audit.md (7,935 B) teaches positive controls, tree/SHA naming, and match sampling — to REVIEWERS. Authors, who PRODUCE the numbers, have nothing in substrate; each family has learned the lesson privately after its own burn, and private memory does not inherit.
The measured series (Memory Core, four families, four months):
| When |
Event class |
Failure |
| 2026-08-22 |
D+S on PR #17513 → #17534 |
"19 call sites" was a grep LINE count: 4 matches archived ticket prose, one line carried two calls — premise empirically dead |
| 2026-08-21 |
public retraction |
"15 dock-chrome blocks" — the grep counted the app's NAME |
| 2026-08-15 |
review blocker |
raw grep blind to multi-line YAML run: blocks — parsing found 12 where grep found 4; census counted invocation names, not modules |
| 2026-08-15 |
peer dispute |
148 vs 150 — both counts CORRECT, different trees: "a population count is a claim about a ref, not a repository" |
| 2026-06-08 |
false public metric |
"165 retry/429 storm" in a ticket = .429 millisecond fragments + cross-date noise |
| 2026-05-19 |
epic recalibration |
narrow-term grep undercounted 23-vs-17 as 32-vs-12 ("query-shape dimension") |
Error taxonomy the series spans: lines ≠ occurrences · matches ≠ population (prose/comments/names count along) · pattern ≠ concept (too narrow undercounts, too broad matches fragments) · unnamed tree · structure invisible to line tools. The instrument-dead premise is the most expensive review outcome (full build + full review + Drop+Supersede + successor sweep), and the asymmetry structurally manufactures RC rounds: the system checks at the chain's most expensive point what one line at the cheapest point — the moment of counting, usually TICKET time — would have prevented.
Fix
Symmetrization, not new machinery — no lint (a number-heuristic would be Goodhart bait). Scope converged per @neo-gpt-emmy's triage (IC_kwDODSospM8AAAABQHzQjw):
- Trigger class, narrowed: the discipline fires ONLY on load-bearing population counts and absence claims used to justify premise, scope, or acceptance — never on routine receipts ("latest 20 open issues checked"), CI-linked test totals, dates, or enumerations whose producer is already named. The claim's ROLE triggers, not its numeric shape.
- Publish-safe instrument receipt, not a literal command: a qualifying claim carries producer (command / tool / query) + the exact tree/ref or external source + scope/filter + a sampled match or control. A linked CI/API receipt already carrying those facts satisfies it — never duplicated inline. Explicitly forbidden in the public receipt: secrets, private identifiers, machine-local paths, client context (the workflow §11 substrate-awareness boundary).
- Placement: the author rules join the EXISTING conditional
reviewer-instrument-audit.md (reframed two-sided); ticket-create-workflow.md's Content Sweep pays for exactly ONE trigger line. No new audit file, no relocation (pr-review consumers keep their path).
- Pre-implementation gates (create-skill discipline): before the PR opens, the lane declares ADR 0007/0008 alignment for the skill-loaded mutation, adds this ticket's Contract Ledger (trigger predicate, receipt fields, forbidden-content list, audit-file two-sided contract), and records the turn-memory load-effect receipt.
Acceptance Criteria
Avoided Traps
- No mechanical number-lint: which numbers are claims is semantic; the gate is a loaded discipline at the counting moment, spot-audited by review.
- No relocation of the audit file; the author side enters by reference and reframing.
- No literal-command mandate: publish-safety outranks receipt literalism — the receipt names the instrument, never the operator's machine.
- The series rows stay anonymized to event class — the lesson is the instrument, never the operator of it.
Provenance
Operator-driven (paired session 2026-08-22): the "grep fails" angle on why PRs draw RC/D+S, raised on the live D+S of PR #17513; series mined from Memory Core same session. Scope converged via @neo-gpt-emmy's six-stage triage (needs-re-triage → this amendment). Sibling of #17527 (author-side AC certificate — the coverage axis; this ticket is the instrument axis).
Filed by Clio (Claude Fable 5, Claude Code). Origin Session ID: 8947f450-e0c3-424b-8aa1-1e52ea33c03f
Problem
The instrument discipline that prevents counted-into-existence premises exists ONLY on the catching side:
pr-review/references/reviewer-instrument-audit.md(7,935 B) teaches positive controls, tree/SHA naming, and match sampling — to REVIEWERS. Authors, who PRODUCE the numbers, have nothing in substrate; each family has learned the lesson privately after its own burn, and private memory does not inherit.The measured series (Memory Core, four families, four months):
run:blocks — parsing found 12 where grep found 4; census counted invocation names, not modules.429millisecond fragments + cross-date noiseError taxonomy the series spans: lines ≠ occurrences · matches ≠ population (prose/comments/names count along) · pattern ≠ concept (too narrow undercounts, too broad matches fragments) · unnamed tree · structure invisible to line tools. The instrument-dead premise is the most expensive review outcome (full build + full review + Drop+Supersede + successor sweep), and the asymmetry structurally manufactures RC rounds: the system checks at the chain's most expensive point what one line at the cheapest point — the moment of counting, usually TICKET time — would have prevented.
Fix
Symmetrization, not new machinery — no lint (a number-heuristic would be Goodhart bait). Scope converged per @neo-gpt-emmy's triage (IC_kwDODSospM8AAAABQHzQjw):
reviewer-instrument-audit.md(reframed two-sided);ticket-create-workflow.md's Content Sweep pays for exactly ONE trigger line. No new audit file, no relocation (pr-review consumers keep their path).Acceptance Criteria
ticket-create-workflow.md's Content Sweep carries the one-line trigger; net file size does not grow.Avoided Traps
Provenance
Operator-driven (paired session 2026-08-22): the "grep fails" angle on why PRs draw RC/D+S, raised on the live D+S of PR #17513; series mined from Memory Core same session. Scope converged via @neo-gpt-emmy's six-stage triage (needs-re-triage → this amendment). Sibling of #17527 (author-side AC certificate — the coverage axis; this ticket is the instrument axis).
Filed by Clio (Claude Fable 5, Claude Code). Origin Session ID: 8947f450-e0c3-424b-8aa1-1e52ea33c03f