# Runtime Port (PROTOCOL.md §9.2 / §9.4), emitted by Phase 5 (Stability) at
# evidence_level `signaled`. Declares where this project's long-term knowledge
# lives and — critically — the boundary between tenant memory and runtime memory.

artifact: MemoryMap
phase: stability
version: 1.2
status: working-draft
evidence_level: signaled
track: agency-studio
supersedes: 1.1
revision_note: >
  v1.2 declares the three record paths Phase 7 (Entropy) found to be rendered by
  a surface and written by nobody. Authored by /fw-entropy against
  define/record-integrity-spec.md, not by Stability — the paths are Stability's
  to own and this is an amendment with its provenance stated rather than a quiet
  edit. Closes EntropyAudit E-01, E-02, E-03 (three of four criticals) and
  ConsonanceCheck C-8. Adds nothing else: no path is renamed, no writer is
  removed, and the boundary block is untouched.
  DELIBERATELY NOT TOUCHED — ConsonanceCheck's open items are not pre-empted
  here: C-1 (two incompatible readiness bar structures, both locked), C-2 (the
  inverted "Reading A" and the four residency calendars), C-6 (the 5-day vs
  10-day Tulsa SLA). Editing any of those would bake in one side of an
  unresolved critical.

root: define/

boundary:
  statement: >
    Tenant memory is this repository. Runtime memory is the harness's own store.
    Tenant knowledge — decisions, artifacts, research, canonical language, and
    every record produced by the operating systems specified in
    define/stability-specs.md — is written to this vault and nowhere else.
    Runtime memory holds ways of working, not tenant content.
  tenant_memory: define/ and the rest of this repository
  runtime_memory: the harness's per-project store, outside this repository
  rules:
    - Skills MUST write tenant content to this vault, never to runtime memory.
    - Runtimes MUST NOT auto-promote tenant content into runtime memory without
      explicit user action.
    - Runtime preferences MUST NOT be written into define/.
    - Gitwit-specific facts (people, terms, figures, transcript content) are
      tenant content by definition and are excluded from runtime memory.
  source: AGENTS.md — "Memory boundary (read first)"

structure:
  - path: define/intake/
    role: capture
    contents: >
      Source material as received. The primary transcript, the posting, resumes,
      the Fenwick reference, and superseded framing documents.
    state: live
    written_by: []            # human intake only; no skill writes here
    read_by:
      - design-partner-access
      - readiness-review
      - decision-packet

  - path: define/
    role: wiki
    contents: >
      Phase artifacts — ProjectContext, SignalThesis, AudienceFieldMap,
      stability-specs, and the per-phase summary cards.
    state: live
    written_by: []            # written by phase runs, not by operating skills
    read_by:
      - cohort-grant-calendar
      - readiness-review
      - venture-leader-naming
      - kill-and-reassignment
      - decision-packet
      - design-partner-access
      - informant-practice
      - artifact-register

  - path: define/records/residents/
    role: outputs
    contents: >
      One page per resident (stability-specs §3.4): cohort, grant date,
      assignment, competency evidence, status events, next dated review,
      trajectory. Shared with the talent function.
    state: designed — not instantiated; no cohort exists
    written_by:
      - readiness-review
      - venture-leader-naming
      - kill-and-reassignment
      - cohort-grant-calendar
    read_by:
      - readiness-review
      - venture-leader-naming
      - kill-and-reassignment

  - path: define/records/decisions/
    role: outputs
    contents: >
      The weekly Bentonville→Tulsa packet, every Tier 2 item with its decision
      date, the missed-window log (stability-specs §5.4 D3), and Tier 1
      commitments recorded same-day (D5). Tier vocabulary unified at C-7.
    state: designed — not instantiated
    written_by:
      - decision-packet
      - kill-and-reassignment
      - venture-leader-naming
    read_by:
      - decision-packet
      - cohort-grant-calendar

  # --- added v1.2 (Entropy) -------------------------------------------------
  # Three paths, each one the missing writer behind a surface that already
  # renders. Every field in each is produced by a step in a playbook that
  # already exists; none is a new object in the operating model.

  - path: define/records/ventures/
    role: outputs
    contents: >
      One page per venture (record-integrity-spec §2). Name — the join key three
      views assume exists — stage, design partner, riskiest assumption, named
      validation signal, validation clock, extensions granted,
      formation_date_proposed, formation_date_actual, chargeback end date,
      venture leader and technical lead. Playbooks 03 and 05 produce every
      field; nothing held them.
      WHY THIS EXISTS: formation_date_proposed is the left-hand operand of the
      only blocking interlock in the system (workspace-v3-spec §10). Without it
      the interlock asserts over an empty set, is vacuously true, and renders
      green on the surface always shown to Tulsa — against the one loss
      stability-specs §10 calls irreversible and silent for years.
      RELOCATES NO RIGHT: venture formation stays Tulsa's retained decision
      (stability-specs §9.2). This records the date Tulsa decided.
    state: designed — not instantiated; no venture exists
    written_by:
      - venture-formation
      - kill-and-reassignment
      - venture-leader-naming
    read_by:
      - venture-formation
      - cohort-grant-calendar
      - decision-packet
      - kill-and-reassignment
      - venture-leader-naming
      - readiness-review

  - path: define/records/field-runs/
    role: outputs
    contents: >
      One record per discovery run (playbook 02): dates, design partner,
      residents present, informants, consent stated, findings-returned date,
      hours-to-synthesis. The floor-day count is derived from these and from
      nothing else.
      INFORMANT RECORD RIGHTS (SovereigntyMap SR-5, added the same day the record
      was): declaring this record made informants the named subjects of a durable
      file held by an organisation they have no relationship with. Every prior
      mitigation in this run is about the STUDY, not the RECORD. So the record
      carries, per informant: `credit_preference` (named / unnamed — decision 011
      promises "named credit where they want it, and none where they do not" and
      until now there was no field for which they chose), `consent_covers_record`
      (the playbook 02 conversation gains one clause: that I write down what I saw
      and your name is on it, or not, as you prefer), and `withdrawn_date`. On
      withdrawal the FINDING survives and the ATTRIBUTION does not. Costs nothing,
      needs no Tulsa decision, and is the difference between a record and a file.
      WHY THIS EXISTS: playbook 12 names resident floor-share "the budget
      control" and marks it "Rule-based — automate now," and no record held it —
      so the number deciding whether a cohort's stipends are research capacity
      or overhead was self-reported by the person whose budget it justifies.
      THRESHOLD: floor-share = floor-days / working days, per resident, per
      month. Canonical value >=40% green, 30-39% yellow, <30% red — set from the
      run-shaped week in playbook 11 rather than from an aspiration. C-5 CLOSED;
      playbook 11's old >=3 days/month and playbook 12's old >=50% are both
      retired. FrequencyMap K21 survives as a DIFFERENT and wider metric
      (field-and-venture hours), not a second floor-share threshold.
    state: designed — not instantiated; no cohort exists
    written_by:
      - field-run
      - informant-practice
      - design-partner-access
    read_by:
      - field-run
      - artifact-register
      - design-partner-access
      - decision-packet
      - readiness-review

  - path: define/records/spinouts/
    role: outputs
    contents: >
      One record per spinout (playbook 09): operating-team seats and who filled
      them, founders-common issuance, chargeback taper and its end date, design
      partner credit-at-spinout as delivered.
      WHY THIS EXISTS: ConsonanceCheck C-8 — playbook 09 is the destination of
      the entire status ladder and had no record, no writer and no surface, and
      Phase 6's gap list dropped it. Credited to /fw-consonance; declared here
      because it is the same act as the two above.
    state: designed — not instantiated; no venture has spun out
    written_by:
      - spinout-formation
    read_by:
      - spinout-formation
      - readiness-review
      - artifact-register
      - design-partner-access

  # --- end v1.2 additions ---------------------------------------------------

  - path: define/records/partners/
    role: outputs
    contents: >
      Per design partner: access history, the written blast-radius agreement
      (§6.3 C2), champion identity and exposure notes, credit-at-spinout
      agreement.
    state: designed — not instantiated
    written_by:
      - design-partner-access
    read_by:
      - design-partner-access
      - artifact-register
      - informant-practice
      - decision-packet

  - path: define/registry/artifacts/
    role: outputs
    contents: >
      The artifact register (§8) — insight briefs, product concepts, hypothesis
      maps, experiment plans, prototype briefs. Named, dated, attributed.
      Artifacts survive the ventures they came from (§4.3 K5).
    state: designed — not instantiated
    written_by:
      - artifact-register
      - informant-practice
      - kill-and-reassignment
    read_by:
      - artifact-register
      - readiness-review
      - venture-leader-naming

  - path: define/playbooks/
    role: outputs
    contents: >
      Operational playbooks. Authored by Phase 5's co-skill (/fw-flow) — 11 of
      them, on branch fw-flow. Referenced by skill-manifest.yaml; not written by
      this phase.
    state: authored by Flow on branch fw-flow; resolves on merge
    written_by: []
    read_by:
      - cohort-grant-calendar
      - readiness-review
      - venture-leader-naming
      - kill-and-reassignment
      - decision-packet
      - design-partner-access
      - informant-practice
      - artifact-register

  - path: define/archive/
    role: archive
    contents: >
      Superseded artifacts, retained rather than deleted so a later reader can
      see what changed and when. exploration-brief.md is superseded but held in
      define/intake/ by Phase 1's ranking, not moved.
    state: designed — not instantiated
    written_by: []
    read_by: []

conventions:
  filenames: kebab-case, one subject per file
  frontmatter: >
    YAML with artifact, phase, version, status; locked artifacts carry
    supersedes and revision_note.
  links: relative repository paths, never absolute
  attribution: >
    Every artifact in define/registry/artifacts/ carries an author name and a
    date. Where a resident authored it, the resident's name appears (§8).
  evidence_tags: >
    [source] with timestamp · [inferred] · [assumption]. Inherited from Phase 2
    and used identically in every artifact.

retention:
  - scope: define/registry/artifacts/
    policy: >
      Artifacts outlive their ventures. A killed venture's insight brief stays
      in the register with its author's name (§4.3 K5). Never deleted.
  - scope: define/records/partners/
    policy: >
      Governed by the blast-radius agreement with each champion (§6.3 C2), not
      by a default. Nothing leaves the vault that crosses that agreement.
  - scope: define/records/residents/
    policy: >
      Retained through graduation and after — the record is what supports an
      alum's account of what they did.

indexing: []   # none. This run produces documents, not software; no search or
               # RAG layer is provisioned (PROJECT-CONTEXT, "Tooling").
