Write a lifecycle transition (merge_result) |
assets/scripts/lifecycle.sh |
edge declared in lifecycle/lifecycle.toml; atomic write + read-back |
invent an undeclared edge |
| Merge a PR |
assets/scripts/merge.sh (cadence arm 4) |
full authorization set re-read immediately pre-merge; every gate reads green; --match-head-commit |
merge on an empty check_set, a hold, or an unclosed child |
Write a gate verdict (check.<g>) |
assets/scripts/signoff.sh |
the review bead still open; the marker written is the bare lane state (green on approve), and reviewed_oid is the dispatch pin and posted-artifact audit label — bound to no marker and compared to no head, but written back to the review bead and read back before the marker is stamped, since a closed review bead carrying it is what check-gate-marker-provenance resolves the lane against; pre-open, the verdict body read back off the same bead; the dispatch pin still an ancestor of the branch (a rewrite — rebase, amend, force-push, never a fast-forward — refuses both verdicts, clears the pin, and closes the review bead gc.outcome=superseded for gate-ensure to re-pour); the closed bead stamped signoff_verdict=<approve|request-changes> |
--approve a PR (the city never approves its own); write a verdict for a check it did not run; record a verdict on a closed review bead; stamp green over a marker still carrying the pre-migration exception@ shape; stamp a marker the review bead records no reviewed commit for — since the city posts no approval, nothing else could resolve it; pre-open, stamp a marker or file a rework child when the verdict body did not land on the review bead, whose notes are the only copy of it |
Clear a gate marker (check.<g>) |
signoff.sh (its own lane, on REQUEST_CHANGES); pr-facts.sh (every declared gate, when the PR is retargeted); gate-ensure.sh (a marker that both falls outside the lane vocabulary and names a gate check_set does not declare) |
the clearing condition above, read-back verified |
gate-ensure.sh: clear a well-formed lane state — a clear withdraws evidence and cannot assert it |
| Retire a signoff round cap |
pr-facts.sh (cadence arm 5) on a batch of operator feedback; signoff.sh reset <anchor> --reason <why> on a ruling |
a batch id no floor already names, or a recorded reason; a rework ledger that reads, naming at least one round for the floor to come from; the cap's own pairing still standing — merge_hold reading exactly the literal string signoff_cap AND a non-empty signoff_cap=<gate> beside it; no live demand (gc.demand_for=<anchor>) — never the presence of gc.takeaway, which outlives the sitting that stamped it; every key it wrote read back, the retired dispatch tally included |
retire a park no signoff_cap claims, or one a sitting is still waiting on a person for; read a takeaway as a hold; lift the hold without advancing signoff_round_floor (the next pass re-caps); treat an operator's own merge_hold=true as the cap's to retire — only the merge_hold=signoff_cap pairing is |
Depart from an anchor's default check_set |
a human, on a named anchor (the default itself is stamped by mol-refinery-patrol and gate-ensure.sh, neither of which reads the diff) |
the reason recorded in the anchor's notes in the same act; a narrowing only once the PR is open |
be derived from the diff by any dispatcher, formula, or reviewer (operator ruling 2026-08-24, specs/2026-08-review-gates/scope.md) |
| Close a work bead (anchor) |
merge.sh after a verified merge; a human otherwise |
recorded merged_sha (or unverified: sentinel) |
be closed by its own polecat |
| Reopen a wrongly-closed anchor |
lifecycle.sh reopen, invoked by a human or on operator direction |
bead closed while merge_result is a non-closed state (the I5 violation shape) |
reopen a legitimately-closed (merged) or open bead; run from an automated caller |
| Close a review bead |
signoff.sh after a verdict; assets/scripts/review-sweep.sh (cadence arm 7) when there is no verdict to give |
signoff: the verdict recorded and read back. sweep: the anchor closed AND review_branch missing from a branch listing that was actually read |
close a review whose anchor still gates, or whose branch is still on origin; write a gate marker or file a rework child while disposing of one |
| Close a step bead |
the session executing it, via assets/scripts/step-close.sh |
(gc.root_bead_id, gc.step_ref), the molecule named by --root or the gc.session_id stamp — the assignee alone repeats across every molecule an agent ran |
close a step in another molecule; close workflow-finalize |
| Close a visit |
converse, at the end of a sitting |
outcome recorded (gc.outcome) |
close the subject it tracks |
| Close-with-successor (disposition) |
assets/scripts/bead-rehome.sh callers (mechanik, converse, duplicate-sweep.sh) |
every caller: gc.superseded_by + store stamped and read back. duplicate-sweep.sh, per bead: the duplicate_of successor resolves in this store and is closed or shipped; the duplicate recorded no work, proved by work_outcome=no-op or by carrying no work-product key at all; nobody else owns it: unassigned, not in_progress, not a review bead, not a step bead or workflow root, not already pointed at a different successor |
bare-close a re-homed bead; duplicate-sweep.sh: dispose on the duplicate_of stamp alone, or judge a successor that lives in another store |
| File a demand (what a person owes) |
assets/scripts/gc-helm.sh demand (converse at a hold; operators by hand) |
the gated bead resolves; the blocks edge read back off it |
file the demand as a descendant of the bead it gates; report success on an edge that did not land; write a prose hold instead |
| Close a demand |
the sitting that holds it, once the person has answered in the thread |
the answer recorded to the subject's notes (converse step 6) |
close a demand that names an assignee — that one is its assignee's; close the bead the demand gates |
Route work (gc.routed_to) |
gc sling (runtime); direct stamp only where a bare sling would be hijacked (documented at each site). CLEARING it is the release half of a handoff, not a routing decision: every terminal arm of mol-polecat-work — refinery handoff, auto_push=false halt, store-only exit — clears it in the same exit that unassigns the bead |
a clear rides a terminal exit that has already recorded where the work went: a branch handed to the refinery, a branch left ready, or a note naming what was filed |
route across rig stores; clear the route on a bead this session does not hold, or on one it is still working |
| File an escalation |
assets/scripts/escalate.sh (everyone calls it) |
one open visit per escalation_key |
mail (there is no mayor); duplicate an open key |