From 6d3576a57d1f0be5359aab2d740281bacb7c30f9 Mon Sep 17 00:00:00 2001 From: Remon Panman <228601219+Tradebaas@users.noreply.github.com> Date: Sat, 1 Aug 2026 16:12:33 +0200 Subject: [PATCH] docs(explainer,readme): the page says what Groundwork does, including the proof Audited both front doors against the repo rather than against memory: all 21 skill cards, the gate cards, the six reason tabs, the lifecycle phases and the "what lives where" table. Three things did not match, and the direction of the mismatch matters: two understated what is there, and the third left out the strongest thing in v0.2.0 entirely. The copy route was the omission. Every push already unpacks a fresh copy, walks it to a first guarded commit and throws it away again, which is exactly the claim both documents open with, and neither mentioned it in any wording. It is a gate card now, next to the self-test card whose logic it extends, and one sentence in the README beside the same idea. Both say the build turns red on the commit that broke the route, and neither says the merge is blocked, because the drill is not a required status check: gate and trace are. code-review was wrong, not merely thin. The card said "two axes", which was true before the security axis landed and survived the rebuild that made this page English. It now names the gate-weakening scan, the two always-on axes and the conditional security axis, which is the one a reader on the Safe tab is being promised elsewhere on the same page. comply listed four regimes where the register carries nine, so the card now names the product and cyber security duties too and says the dates are verified against the source. Verified in the rendered page, not in the source: ten gate cards, every icon resolving, the grid landing on five even rows instead of four and an orphan, and both corrected skill cards wrapping inside their card. Counts on the page are derived and unchanged: 21 skills, 21 checks, 19 decisions. Traces-to: SC-11 --- README.md | 5 ++++- index.html | 5 +++-- 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 789dc7c..846c3b0 100644 --- a/README.md +++ b/README.md @@ -103,7 +103,10 @@ records the reasoning. serves, so a sha resolves back to a requirement instead of to someone's memory. The checks test themselves: every gate has to prove it fails on a violation before it is trusted, and `.github/workflows/ci.yml` runs those suites ahead of the checks, because a gate - that isn't tested is false confidence. The same directory holds `node checks/progress.mjs`: a read-only, plain-language + that isn't tested is false confidence. The copy route is tested the same way: on every push, + `node checks/drill.mjs` unpacks a fresh copy, walks it to a first governed commit and throws it + away again, so the promise at the top of this file is checked by machine instead of asserted + (runbook: [docs/operations/evidence-drill.md](docs/operations/evidence-drill.md)). The same directory holds `node checks/progress.mjs`: a read-only, plain-language answer to "what is done and what is left", derived from the brief, the specs and the handoff, with `--all` covering every project you have started this way. Add `--serve` and the same answer opens as a page on this machine only: the goal, the stand, the next step, which file diff --git a/index.html b/index.html index 715a025..99c7179 100644 --- a/index.html +++ b/index.html @@ -770,6 +770,7 @@
'+a[2]+'