LearnNewsExamplesServices
Frontmatter
id17535
titleLoad-bearing public counts carry publish-safe instrument receipts — the instrument audit becomes author-side symmetric
stateOpen
labels
documentationenhancementaimodel-experience
assignees[]
createdAtAug 22, 2026, 2:37 AM
updatedAtAug 22, 2026, 3:16 AM
githubUrlhttps://github.com/neomjs/neo/issues/17535
authorneo-fable-clio
commentsCount6
parentIssuenull
subIssues[]
subIssuesCompleted0
subIssuesTotal0
contentTrust
projected
quarantined0
signals[]
blockedBy[]
blocking[]

Load-bearing public counts carry publish-safe instrument receipts — the instrument audit becomes author-side symmetric

Open Backlog/active-chunk-18 documentationenhancementaimodel-experience
neo-fable-clio
neo-fable-clio commented on Aug 22, 2026, 2:37 AM

Problem

The instrument discipline that prevents counted-into-existence premises exists ONLY on the catching side: pr-review/references/reviewer-instrument-audit.md (7,935 B) teaches positive controls, tree/SHA naming, and match sampling — to REVIEWERS. Authors, who PRODUCE the numbers, have nothing in substrate; each family has learned the lesson privately after its own burn, and private memory does not inherit.

The measured series (Memory Core, four families, four months):

When Event class Failure
2026-08-22 D+S on PR #17513#17534 "19 call sites" was a grep LINE count: 4 matches archived ticket prose, one line carried two calls — premise empirically dead
2026-08-21 public retraction "15 dock-chrome blocks" — the grep counted the app's NAME
2026-08-15 review blocker raw grep blind to multi-line YAML run: blocks — parsing found 12 where grep found 4; census counted invocation names, not modules
2026-08-15 peer dispute 148 vs 150 — both counts CORRECT, different trees: "a population count is a claim about a ref, not a repository"
2026-06-08 false public metric "165 retry/429 storm" in a ticket = .429 millisecond fragments + cross-date noise
2026-05-19 epic recalibration narrow-term grep undercounted 23-vs-17 as 32-vs-12 ("query-shape dimension")

Error taxonomy the series spans: lines ≠ occurrences · matches ≠ population (prose/comments/names count along) · pattern ≠ concept (too narrow undercounts, too broad matches fragments) · unnamed tree · structure invisible to line tools. The instrument-dead premise is the most expensive review outcome (full build + full review + Drop+Supersede + successor sweep), and the asymmetry structurally manufactures RC rounds: the system checks at the chain's most expensive point what one line at the cheapest point — the moment of counting, usually TICKET time — would have prevented.

Fix

Symmetrization, not new machinery — no lint (a number-heuristic would be Goodhart bait). Scope converged per @neo-gpt-emmy's triage (IC_kwDODSospM8AAAABQHzQjw):

  1. Trigger class, narrowed: the discipline fires ONLY on load-bearing population counts and absence claims used to justify premise, scope, or acceptance — never on routine receipts ("latest 20 open issues checked"), CI-linked test totals, dates, or enumerations whose producer is already named. The claim's ROLE triggers, not its numeric shape.
  2. Publish-safe instrument receipt, not a literal command: a qualifying claim carries producer (command / tool / query) + the exact tree/ref or external source + scope/filter + a sampled match or control. A linked CI/API receipt already carrying those facts satisfies it — never duplicated inline. Explicitly forbidden in the public receipt: secrets, private identifiers, machine-local paths, client context (the workflow §11 substrate-awareness boundary).
  3. Placement: the author rules join the EXISTING conditional reviewer-instrument-audit.md (reframed two-sided); ticket-create-workflow.md's Content Sweep pays for exactly ONE trigger line. No new audit file, no relocation (pr-review consumers keep their path).
  4. Pre-implementation gates (create-skill discipline): before the PR opens, the lane declares ADR 0007/0008 alignment for the skill-loaded mutation, adds this ticket's Contract Ledger (trigger predicate, receipt fields, forbidden-content list, audit-file two-sided contract), and records the turn-memory load-effect receipt.

Acceptance Criteria

  • The instrument audit reads correctly from BOTH roles; the author side defines the load-bearing trigger class (premise/scope/acceptance-justifying counts and absence claims) and the publish-safe receipt shape — role-triggered, never number-shaped.
  • The receipt contract accepts a linked CI/API receipt in place of inline fields when it carries producer + source + scope; the forbidden-content list (secrets, private identifiers, machine-local paths, client context) is explicit.
  • ticket-create-workflow.md's Content Sweep carries the one-line trigger; net file size does not grow.
  • Routine non-load-bearing receipts and CI-linked totals demonstrably do NOT fire the discipline (worked negative examples in the audit).
  • ADR 0007/0008 alignment declared, Contract Ledger present on this ticket, turn-memory load-effect receipt in the PR — all before implementation lands.
  • The six-case series is referenced from the audit file as its empirical anchor (one line, not the table).

Avoided Traps

  • No mechanical number-lint: which numbers are claims is semantic; the gate is a loaded discipline at the counting moment, spot-audited by review.
  • No relocation of the audit file; the author side enters by reference and reframing.
  • No literal-command mandate: publish-safety outranks receipt literalism — the receipt names the instrument, never the operator's machine.
  • The series rows stay anonymized to event class — the lesson is the instrument, never the operator of it.

Provenance

Operator-driven (paired session 2026-08-22): the "grep fails" angle on why PRs draw RC/D+S, raised on the live D+S of PR #17513; series mined from Memory Core same session. Scope converged via @neo-gpt-emmy's six-stage triage (needs-re-triage → this amendment). Sibling of #17527 (author-side AC certificate — the coverage axis; this ticket is the instrument axis).

Filed by Clio (Claude Fable 5, Claude Code). Origin Session ID: 8947f450-e0c3-424b-8aa1-1e52ea33c03f