Skip to content

Owners of the Workspace Boundary

chant provides the repository specification, which now takes in the domain record kinds and the factory’s rules, and nothing that faces a person. hud renders what chant reads and acts on it for the person in front of it, and behold reads a workspace the same way for the infra plane. studio orchestrates and hosts, which covers running builders with their prompts and publishing a box’s work. A plugin owns only the record kinds a workspace pins from a third party, with their joins. The decision is ws-086 (#3161), which supersedes ws-052 (#2657).

chanthudstudiobeholdplugin
declaration, kinds, members, links, lineage, migrations, init --from, upgraderenderingagent prompts, context bundles, how a builder is runreading a workspace for the infra planerecord kinds a workspace pins from a third party, and their commitJoins
records: schemas, states, seals, pins, supersession, attestation, provenancereview actions as UI (agree, dissent, propose, quorum meter, live sessions)hosting and provisioning: boxes, the lobby, the door, the planter and beds
the read contract: versioned JSON of ls, graph, check, records, status, graph --intent, graph --composites, points, work history, signers, evidence verify, closed reason codesidentity, sessions, who is lookingpublishing a box’s work: the merge, the push and the pull request
commit trailers: Chant-Agent, Chant-Lease, Chant-Run, Chant-Record, Chant-Applied-By, Chant-Applied-At, Chant-Applied-Committhe agent chat, the dev proxy, comment mode
the agent run record: workspace runs, runs start, end and record, the run ledger on chant/lifecyclethe question put to the person at each finding
reader conformance: a reader reads only through the read contract and writes nothing
the publish call: chant workspace box publish, the publisher protocol, and the apply record every publish leaves
writer conformance: a writer writes only through the write contract, and keeps no fact outside the repo
work in progress that survives the box: snapshots under refs/chant/wip/<branch>, kept attempts, work branches and their replication
the writing and verifying commands: approve, records pin, verify, check, gates, ledgers
findings as data
who a person-attributed record or gate approval names: forge identities, signer principals, identity.attribution, signed gates
domain record kinds (contract, evidence, review session, driver, proposal, notes)
decision-point standards: the understand point and the slice-tier inputs
the factory’s rules: readiness, attempts, outcomes, done
the broker protocol: what a broker of box capabilities answers for inference, decide, egress, feedback and fountain, its refusals, and the broker conformance suite
  • chant never listens on a port, never authenticates a person and never renders. test/no-listener.test.ts holds packages/core to the first and to importing no UI or agent-runtime package.
  • hud never parses a record file, never runs git for provenance and never computes drift. It reads only through the read contract and writes only through chant commands. The suite a reader runs to show it ships in @intentius/chant as @intentius/chant/workspace/conformance, for any test runner.
  • The repo is the database (ws-074, #3158). Every durable fact about a workspace, anything a person or agent decided, answered, reviewed, approved, wrote or was attributed with and any configuration of a box or member, is a file in the repo. A tool writes it only through chant’s write commands. Outside the repo a tool keeps only secrets in a broker or vault, telemetry, caches and indexes it can rebuild from the repo, and the substrate’s own runtime state.
  • studio defines no record field and keeps no fact outside the repo (ws-074). Its CI runs the reader and writer conformance suites, the same proof asked of hud (#3159, arugula-salad/studio#338). behold is held to hud’s rules.
  • chant reads a pinned kind’s commitJoins, and the intent graph reports what they join as unit, contract and evidence nodes. chant’s own kinds need no join, because the commit trailers tie a commit to them (ws-075).

This page is generated from docs/data/boundary.yaml, which has one row for each concept. test/boundary-roster.test.ts compares the roster with the closed lists in the code. It fails the build when something in one of those lists has no row, or when a row names something that is not there. A row for a cell of the table above uses the cell’s text as #2657 or #3161 words it. Each hud, studio or behold row names its owner’s repository as the carrier: alecraso/hud, arugula-salad/studio or INTENTIUS/behold.

CategoryWhere the code keeps itchanthudstudiobeholdplugin
boundary cellthe table of #2657, one row per cell165311
workspace commandcommandRegistry in cli/main.ts, and each sub-verb its help names630000
member kindBUILTIN_KIND_NAMES in kinds.ts50000
record kindnone in core; the reference workspace’s and this repository’s kind files, or a kind a workspace pins from a third party70001
member link kindLINK_KINDS in links.ts20000
record link kindRECORD_LINK_KINDS in record-assets.ts20000
intent node kindthe node kinds of intent.schema.json100003
intent edge kindthe edge kinds of intent.schema.json120003
reason codeREASONS in reason-codes.ts, less the finding codes2150000
finding codethe finding codes of intent.schema.json180000
WSP checkWORKSPACE_CHECKS in checks.ts and checks/*.ts500000
hud viewthe hud reader requirements H1 to H11 of #2650011000

Each row follows, in the order of the table above.

CategoryConceptOwnerCarried byWhat
boundary celldeclaration, kinds, members, links, lineage, migrations, init --from, upgradechantdeclaration.schema.json, workspace-kinds.schema.json, workspace-principals.schema.json, .chant/workspace.lock.jsonThe repository specification itself: what a workspace declares, how each member is read, how members join, and where the files came from.
boundary cellrecords: schemas, states, seals, pins, supersession, attestation, provenancechantrecords.schema.jsonHow a record file is validated, sealed, pinned to the files it rests on, superseded and traced to a signed commit.
boundary cellthe read contract: versioned JSON of ls, graph, check, records, status, graph --intent, graph --composites, points, work history, signers, evidence verify, closed reason codeschantls.schema.json, graph.schema.json, check.schema.json, records.schema.json, status.schema.json, intent.schema.json, composites.schema.json, points.schema.json, work-history.schema.json, signers.schema.json, evidence.schema.jsonThe only way a reader sees a workspace: one JSON Schema per document, a contract version and a chant floor.
boundary cellcommit trailers: Chant-Agent, Chant-Lease, Chant-Run, Chant-Record, Chant-Applied-By, Chant-Applied-At, Chant-Applied-Commitchantintent.schema.json, intent-record.schema.jsonThe names a commit uses to point at its agent session, work lease, agent run, records and apply; whoever makes the commit writes them, and chant reads them back (#3149, ws-075).
boundary cellthe agent run record: workspace runs, runs start, end and record, the run ledger on chant/lifecyclechantruns.schema.json, runs-write.schema.json, run-statement.schema.jsonWhat each agent run cost and which commits it made, written by whatever ran the agent and read with totals per work item, decision and principal; chant records runs and never starts one (#3033, ws-076). A runner or steward key can sign a statement over a run, kept in the same ledger (#3192, ws-090).
boundary cellreader conformance: a reader reads only through the read contract and writes nothingchant@intentius/chant/workspace/conformance, @intentius/chant/workspace/conformance/vitestThe suite a reader such as hud runs in its own CI, with any test runner, on a workspace it generates from the fixture that @intentius/chant ships.
boundary cellthe publish call: chant workspace box publish, the publisher protocol, and the apply record every publish leaveschantbox-publish.schema.json, status.schema.jsonA surface asks for a box’s work to be published with one chant call; chant runs the publisher the box block names and checks the commit it made for the Chant-Applied-* trailers, while the merge, push and pull request stay the orchestrator’s (#3165, ws-088).
boundary cellwriter conformance: a writer writes only through the write contract, and keeps no fact outside the repochant@intentius/chant/workspace/conformance, @intentius/chant/workspace/conformance/vitestThe suite a writer such as hud or studio’s factory runs in its own CI: scripted writes through the writer, each one chant command whose changes chant reports, and the amnesia test, which deletes the writer’s private state and expects the same facts back (#3159, ws-074).
boundary cellwork in progress that survives the box: snapshots under refs/chant/wip/<branch>, kept attempts, work branches and their replicationchantwip.schema.json, wip-write.schema.json, declaration.schema.jsonOne ref namespace for checkpoints of a branch’s working tree, which hud’s turn checkpoints and studio’s checkpoints use, replicated with the work branches, kept attempts and ledger to the remote the box block’s replicate names (#3172, ws-085).
boundary cellthe writing and verifying commands: approve, records pin, verify, check, gates, ledgerschantchant approve, chant workspace records pin, chant workspace records new, amend, review and close, chant workspace verify, chant workspace checkEvery change to the repository that carries weight is made or checked by a chant command, so a UI writes only by calling one.
boundary cellfindings as datachantcheck.schema.json, intent.schema.jsonA finding is a node or a row with a closed code, so a reader can draw it and a test can assert it.
boundary cellrenderinghudalecraso/hudDrawing the documents of the read contract for a person.
boundary cellreview actions as UI (agree, dissent, propose, quorum meter, live sessions)hudalecraso/hudThe buttons and meters a reviewer uses; each verdict lands as a pull request that chant then reads.
boundary cellidentity, sessions, who is lookinghudalecraso/hudSigning a person in, knowing who is present, and mapping the session to the forge identity or signer principal it passes to chant’s write commands as —by or —actor (#3163); chant never authenticates a person.
boundary cellwho a person-attributed record or gate approval names: forge identities, signer principals, identity.attribution, signed gateschantdeclaration.schema.json, status.schema.jsonThe forms a person is named by, the declaration’s identity block read at base, and the seal that attests an approval against the signers at base (#3163, ws-080).
boundary cellthe agent chat, the dev proxy, comment modehudalecraso/hudThe interactive surfaces around a workspace, none of which chant serves.
boundary cellthe question put to the person at each findinghudalecraso/hudhud asks and never answers; the finding it asks about comes from chant as data.
boundary celldomain record kinds (contract, evidence, review session, driver, proposal, notes)chantthe reference workspace’s kind files and schemas, named in chant.workspace.json recordsThe record kinds a development model works in, shipped by chant as data and upgraded through lineage; core still ships no kind of its own, and the declaration names the ones a workspace holds (#3148, ws-082, ws-086).
boundary celldecision-point standards: the understand point and the slice-tier inputschantthe reference workspace’s decisions/points.json, points.schema.jsonThe points every factory asks and the inputs each reads, declared once so two orchestrators ask the same question (#3150, ws-086).
boundary cellthe factory’s rules: readiness, attempts, outcomes, donechantfactoryOp in @intentius/chant/op, workspace/factory-rules.ts (#3406)Which work items are ready, which lease outcomes count as attempts, what done means and what happens to an unfinished attempt, as declared and tested behaviour; an orchestrator supplies only execution (#3162, ws-087).
boundary cellrecord kinds a workspace pins from a third party, and their commitJoinsplugina pinned package’s record kind file, its schema and its commitJoins export (intent-joins.ts reads it)A kind chant does not ship, and how a commit is tied to its records; core calls the join and never parses the package’s own trailers, while chant’s trailers join a commit to chant’s kinds (ws-075).
boundary cellagent prompts, context bundles, how a builder is runstudioarugula-salad/studioWhat an agent is told and given, and the builder’s harness (Claude Code in the box, fountainRun); chant hands out data and no prompts (ws-086).
boundary cellhosting and provisioning: boxes, the lobby, the door, the planter and bedsstudioarugula-salad/studioWhere a box runs and how it is reached and credentialed; the box’s configuration it reads from the declaration through the read contract (ws-074, ws-086).
boundary cellthe broker protocol: what a broker of box capabilities answers for inference, decide, egress, feedback and fountain, its refusals, and the broker conformance suitechantbroker-protocol.schema.jsonThe routes, scope words and bodies a broker serves a box on, and the suite a broker such as studio’s lobby or fountain’s runs to show it; chant specifies and checks a broker and runs none (#3164, ws-097).
boundary cellpublishing a box’s work: the merge, the push and the pull requeststudioarugula-salad/studioThe work behind a publish, run as the publisher a box block names; chant runs no push and calls no forge (#3165, ws-086).
boundary cellreading a workspace for the infra planebeholdINTENTIUS/beholdbehold reads a workspace only through the read contract and writes only through chant, under hud’s rules (ws-086).
workspace commandworkspace initchantdeclaration.schema.jsonProposes a chant.workspace.json from the projects under a directory.
workspace commandworkspace lschantls.schema.jsonLists the declaration’s members, the record kinds it names and its example groups, with a reason code for each one that can’t be read.
workspace commandworkspace graphchantgraph.schema.jsonPrints the composed IR of every member, with member links and, given —kind, the records and their links. A member whose stamp, toolchain, command line and environment are unchanged is served from the per-member cache in the user’s cache directory, never written into the workspace (ws-059).
workspace commandworkspace graph --intentchantintent.schema.jsonPrints the intent graph over one region, through the kinds given with —kind or else every kind the declaration names: its commits, the decisions that constrain it, the artifacts they pin, and findings as nodes.
workspace commandworkspace graph --compositeschantcomposites.schema.jsonPrints each composite instance with the components that can deploy it, how each match was made and whether it crossed a member link; an instance with no component is listed with none, and the choice is never made here.
workspace commandworkspace patchchantpatch.schema.jsonPrints the hunks of a range, a work branch or one commit, file by file, cut to a size limit, for a reader that runs no git.
workspace commandworkspace checkchantcheck.schema.jsonChecks the declaration with WSP ids and the lineage lock with reason codes, and prints the result as a read-contract document.
workspace commandworkspace statuschantstatus.schema.jsonShows each member’s releases in one environment from the lifecycle ledgers, read-only.
workspace commandworkspace recordschantrecords.schema.json, records-since.schema.jsonReads the records a record kind locates, or every kind the declaration names, validated against its schema, with provenance and reason codes; with —since, what changed in them between two revisions.
workspace commandworkspace workchantwork-lease.schema.jsonClaims, renews and releases the lease on a work item: a compare-and-set ref with a fencing token and an expiry, pushed to the remote so separate clones coordinate, with each change appended to _leases/<id>.jsonl on chant/lifecycle (#2732, ws-055).
workspace commandworkspace work historychantwork-history.schema.jsonReads one work item’s lease history from _leases/<id>.jsonl in the ledger of the member that owns its work kind, as claims with their token, holder and how each ended, so a runner counts failed attempts without reading git (#2785).
workspace commandworkspace work evidencechantwork-evidence.schema.jsonAttaches one piece of evidence for an acceptance criterion under the lease the caller holds, through records amend: the workEvidence activity as a command, so a writer that is not an Op, such as hud, writes it through chant (#3159).
workspace commandworkspace runschantruns.schema.jsonReads the agent runs in _agent-runs/<id>.jsonl on chant/lifecycle with the commits each made, joined by the run’s own list and its Chant-Run trailer, and totals tokens and cost per work item, decision and principal, listing a run with no cost as unpriced rather than zero (#3033, ws-076).
workspace commandworkspace runs startchantruns-write.schema.jsonAppends an agent run’s start to the run ledger: who it worked for, its session, harness, model, work item and lease. chant records runs and never starts one (#3033).
workspace commandworkspace runs endchantruns-write.schema.jsonAppends a started run’s end: its outcome, tokens, cost with currency and price source, the transcript pinned by hash, and the commits it made with their patch-ids (#3033).
workspace commandworkspace runs recordchantruns-write.schema.jsonAppends a finished run’s start and end in one write, for a caller that reports a run only once it is over (#3033).
workspace commandworkspace runs signchantruns-write.schema.jsonAppends a statement over an ended run to its ledger file: a DSSE envelope over the run record’s hash, its work item, harness, model and commits, signed with a runner or steward key .chant/trust.json lists at base, or signed elsewhere and checked before it is stored (#3192, ws-090).
workspace commandworkspace runs statementchantrun-statement.schema.jsonPrints the agent-run statement and the payload to sign, for a signer whose key is kept elsewhere, such as a lobby, which signs it and hands the envelope back for runs sign (#3192).
workspace commandworkspace runs verifychantrun-statement.schema.jsonJudges each run’s stored statements offline against the runner keys at base and reports which runs are signed; it fails only with —require signed (#3192, studio-035).
workspace commandworkspace boxchantbox-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.jsonA member’s box block through chant: box listing set writes the listing and box factory set the factory, so a tool never edits the declaration itself (#3308, #3600, ws-074), and box publish runs the box’s declared publisher (#3165, ws-088).
workspace commandworkspace box factorychantbox-factory-write.schema.jsonbox factory set <member> changes only the top-level properties of members[i].box.factory in the declaration, in place, keeping its formatting and comments, so whoever plants a box sets where it publishes (factory.publish); honours the write scope and identity rule at base, and never commits (#3600).
workspace commandworkspace box listingchantbox-listing-write.schema.jsonbox listing set <member> changes only members[i].box.listing in the declaration, in place, keeping its formatting and comments, copies a —cover picture into the repository, honours the write scope and identity rule at base, and never commits (#3308).
workspace commandworkspace memberchantmember-write.schema.jsonA declaration’s members through chant, so a lobby keeps its boxes without editing the declaration itself (#3596, ws-074): member add and member remove.
workspace commandworkspace member addchantmember-write.schema.jsonmember add <name> —from <file|-> appends the member’s entry to members in the declaration, in place, keeping its formatting and comments; refuses a name taken, a declaration that would not read, and a collision or literal path between boxes; honours the write scope and identity rule at base, and never commits (#3596).
workspace commandworkspace member removechantmember-write.schema.jsonmember remove <name> removes the member’s entry from members in the declaration, in place, refusing when the declaration would no longer read, and never commits (#3596).
workspace commandworkspace hostchantmember-write.schema.jsonA declaration’s hosts through chant (#3596, ws-074): host set.
workspace commandworkspace host setchantmember-write.schema.jsonhost set <name> —from <file|-> adds the host’s entry to hosts, or replaces the one of that name, in place, refusing a declaration that would not read and a collision or literal path between boxes, and never commits (#3596).
workspace commandworkspace box publishchantbox-publish.schema.jsonbox publish <member> <item> or —records runs the publisher the box block names, with a JSON request on stdin, checks its answer and holds the commit it made to the apply record of ws-075; chant itself never commits, pushes or calls a forge (#3165, ws-088).
workspace commandworkspace lockchantwrite-lock.schema.jsonSays who holds the working tree’s write lock, and takes and releases it for a batch of writes across chant calls run with CHANT_WRITE_LOCK=<token> (#3173, ws-089).
workspace commandworkspace wipchantwip.schema.jsonLists the work-in-progress snapshots under refs/chant/wip/<branch>, newest first, and how far each ref the box’s replicate policy names is from its remote, read locally (#3172, ws-085). hud and studio list checkpoints through it.
workspace commandworkspace wip savechantwip-write.schema.jsonSnapshots the whole working tree, uncommitted records included, onto refs/chant/wip/<branch> through a temporary index, so the index, HEAD and branch never move; pushes when the policy’s on includes save (#3172). hud’s turn checkpoints and studio’s checkpoints are these.
workspace commandworkspace wip restorechantwip-write.schema.jsonPuts the working tree back as a snapshot holds it, after a pre-restore snapshot of how it is, and resets the index to HEAD; the branch never moves (#3172).
workspace commandworkspace wip pushchantwip-write.schema.jsonPushes the work branches, kept attempts, snapshots and ledger branch the box’s replicate policy names to its remote under their own names, never forced, for the host’s schedule (#3172).
workspace commandworkspace wip fetchchantwip-write.schema.jsonOn a replacement box, mirrors the remote’s replicated refs into refs/chant/replica/<remote>/ and creates or fast-forwards the local ones, leaving a checked-out, ahead or forked ref as it is (#3172).
workspace commandworkspace records pinchantchant workspace records pin <path>Prints a file’s path from the workspace root and its sha256, for a decision’s evidence pin.
workspace commandworkspace records newchantrecords-new.schema.jsonWrites one new record in a kind’s directory from validated JSON fields, allocating the next id, and never commits; with —sign, sealed by its author.
workspace commandworkspace records amendchantrecords-amend.schema.jsonSets fields of one record under its schema and the approval rule, refusing a change to an approved record that only a superseding record can make; with —sign it seals the author again, and without it a change removes the author seal.
workspace commandworkspace records reviewchantrecords-review.schema.jsonAppends a dated review verdict to one record, bound to the digest of the record text, with a note required for a dissent, and with —sign an ssh seal by the reviewer. With —session, the session must exist and be open, and the verdict goes on its verdicts list in the same command.
workspace commandworkspace records closechantrecords-close.schema.jsonCloses an open review session in one write: its state, close time and closing commit, and the seal computed by chant’s rule (#2693).
workspace commandworkspace pointschantpoints.schema.jsonLists the decision points each declared answer kind’s points file declares, and the questions asked of them, with the open ones and any model’s answer and confidence (ws-058, #2739).
workspace commandworkspace points askchantpoints-write.schema.jsonAsks a point’s table, model and quorum deciders for one set of inputs and records the answer, proposed when a model gave it; chant calls no model, and a backend’s response is handed in with —response. An ad-hoc point’s question and candidates come with the ask, with —candidates, and the record keeps them as asked (#3403).
workspace commandworkspace points answerchantpoints-write.schema.jsonRecords people’s answer to an open question, or their confirmation of a model’s proposal, once the point’s quorum is met, with their note (#3351).
workspace commandworkspace points retractchantpoints-write.schema.jsonTakes people’s answer back once the point’s quorum is met: the question is escalated to people again, and the answer, its note, and who retracted it, when and why stay in the record’s retractions (#3351, ws-084).
workspace commandworkspace agentchantagent.schema.jsonPrints an agent session from the declaration at base: the members it is bound to, the record kinds and verbs its write scope allows, and the spec records —current prints, so a session that resumes rebuilds its context from the repository alone (#2548, ws-067, ws-101).
workspace commandworkspace verifychantchant workspace verifyChecks the commits in base..head against the signers and roles read from base.
workspace commandworkspace signerschantsigners.schema.jsonShows the signer set’s versions along the base’s first-parent line, each signed by a threshold of the one before, and writes and signs the rotation file for the next version.
workspace commandworkspace evidencechantchant workspace evidenceRunner evidence: an in-toto statement over record hashes in a DSSE envelope, signed by a runner or service key the policy at base lists.
workspace commandworkspace evidence signchantchant workspace evidence signSigns runner evidence over the records a kind locates at a commit, with a runner key, never a signer’s.
workspace commandworkspace evidence verifychantevidence.schema.jsonVerifies runner evidence offline against the runner keys at base, and says whether the records still hash as signed.
workspace commandworkspace pinchantchant workspace pin —jsonPrints the integrity value that pins a plugin loaded by path, and says whether the declared pin matches it.
workspace commandworkspace lineagechantchant workspace lineage —jsonShows each scope in the lineage lock with its template, pin, edited files and open manual steps.
workspace commandworkspace lineage resolvechantchant workspace lineage resolve <path>Closes a manual step once the file has been merged by hand.
workspace commandworkspace upgradechantchant workspace upgradeBrings a lineage scope to a newer template version in a worktree and gates the patch on its digest.
workspace commandworkspace adopt-lineagechantchant workspace adopt-lineage —jsonGives a scope with no lineage one matched against the template’s versions, or moves a directory lineage onto git.
workspace commandworkspace hash-indexchantchant workspace hash-indexComputes the per-version file hashes adopt-lineage matches a scope against, for a template’s CI to publish.
workspace commandworkspace versionschantchant workspace versions —jsonReports the template, chant and lexicon versions of every lineage lock under a directory, by template family.
workspace commandworkspace exportchantchant workspace export —jsonWrites the members that travel, with their lineage and records, into the export member as a workspace of their own, switching host-bound values.
workspace commandworkspace importchantchant workspace import —jsonBrings an export back per file against its recorded hashes, switches host values back, and records the return with the commits the files were made in.
workspace commandworkspace admitchantchant workspace admit —jsonAdds a return’s signers to .chant/trust.json under admitted, so the returned work reads as attested once an admin merges it.
workspace commandworkspace buildchantchant workspace buildBuilds every chant member and example project, each under its own chant.
workspace commandworkspace lintchantchant workspace lintRuns each member’s own lint, with one SARIF run per member.
workspace commandworkspace auditchantchant workspace auditAudits each member’s files on disk with its own audit config, adding a member field to each finding.
workspace commandworkspace member-runchantchant workspace member-runThe internal entry one member’s process runs under when a per-member command fans out; not for readers.
member kindchantchantdeclaration.schema.json, workspace-kinds.schema.jsonA chant project, with a chant.config.ts or chant.config.json in its directory.
member kindworkspacechantdeclaration.schema.json, workspace-kinds.schema.jsonA nested workspace with its own declaration, read by the outer one only through its own chant workspace graph and never written.
member kindotherchantdeclaration.schema.json, workspace-kinds.schema.jsonA directory chant does not read; the entry says why in because.
member kinddesignchantdeclaration.schema.json, workspace-kinds.schema.jsonA data member holding the design artifacts the workspace owns; chant reads its files for record pins and builds nothing.
member kindexampleschantdeclaration.schema.json, workspace-kinds.schema.jsonAn example group: every chant project its glob matches is built and linted.
record kinddecisionchantdocs/design/decisions/decision.kind.mjs, decision.schema.jsonThe decision record chant’s own design and the reference workspace use; the intent graph reads decisions as core nodes. reference/decision-kind specifies it, and a plugin carries a copy (ws-064).
record kindworkchantreference-workspace/work/work.kind.mjs, work.schema.jsonA work item: a record with needs and implements links that people and agents share as one queue with no server. records gives each one ready and blockedBy, and the intent graph reads work items as core nodes (#2683). jhgaylor/chud#78 makes units work items.
record kindanswerchantreference-workspace/answers/answer.kind.mjs, answer.schema.jsonAn answer to a decision point: proposed when a model gave it, answered by a table or a quorum, escalated when people must; one per point, declaration and inputs (ws-058, #2739).
record kindcontractchantreference-workspace/design/contracts/contract.kind.mjs, contract.schema.jsonAn acceptance criterion made formal: its criteria, and its check pinned by hash. Drafted, approved by its reviewers, retired; a work item names the contract it builds, and the commits that serve it cite it as Chant-Record: contract:<id> (#3148, ws-082).
record kindunitplugina record kind file and its schema that a workspace pins from a third party, passed with —kindA unit of work, joined to the commits it produced.
record kindevidencechantreference-workspace/design/evidence/evidence.kind.mjs, evidence.schema.jsonThe result of one run of a contract’s check on a tree, named for the SHA-256 of its bytes and written by records new; a work item cites it as evidence for a criterion (#3148, ws-082).
record kinddriverchantreference-workspace/design/drivers/driver.kind.mjs, driver.schema.jsonA record that groups contracts under one intent, with its design notes in the body (#3148, ws-082).
record kindsessionchantreference-workspace/design/sessions/session.kind.mjs, session.schema.jsonA review session with its agenda, attendance and the verdicts it produced on decisions, contracts and drivers, sealed on close; chud’s numbered session files, such as sessions/S-0001.json, are the shape it started from (#2673), and studio’s design sessions converge on it (#3148, ws-082).
member link kindoutputchantgraph.schema.json, check.schema.jsonA consumer names a producer’s output, matched exactly; the default member link kind.
member link kindtelemetrychantgraph.schema.json, check.schema.jsonA consumer sends its telemetry to a pipeline or exporter of the producer’s collector, with the protocol it states checked against the target (#2558).
record link kindassetchantgraph.schema.jsonA current record pins a file by hash.
record link kindconstrainschantgraph.schema.jsonA current record governs a member or a workspace path.
intent node kindregionchantintent.schema.jsonThe path, and optional line range, the intent graph is over.
intent node kindfilechantintent.schema.jsonA file under a directory region, marked when it is a declared generated file.
intent node kindmemberchantintent.schema.jsonThe member a region, file or link belongs to.
intent node kindcommitchantintent.schema.jsonA commit that touched the region, with its trailers and provenance level.
intent node kindunitpluginintent.schema.jsonA unit of work a plugin’s commitJoins tied to a commit.
intent node kindcontractpluginintent.schema.jsonA contract a plugin’s commitJoins tied to a unit or commit.
intent node kindevidencepluginintent.schema.jsonEvidence a plugin’s commitJoins tied to a contract or unit.
intent node kinddecisionchantintent.schema.jsonA decision record that constrains the region, with its state, provenance and reviews.
intent node kindworkchantintent.schema.jsonA work item that constrains the region, or that one there implements, needs or addresses, with its state, ready and blockedBy (#2683).
intent node kindartifactchantintent.schema.jsonA file a decision pins, with its pin state.
intent node kindlinkchantintent.schema.jsonA member link touching the region’s member.
intent node kindfindingchantintent.schema.jsonA finding with a closed code and the nodes it concerns.
intent node kindrunchantintent.schema.jsonAn agent run that made a commit in the walk, from the run ledger: its harness, model, principal, work item, tokens and cost, or recorded false when only a trailer names it (#3033).
intent edge kindconstrainschantintent.schema.jsonA decision or work item governs a region, file, member, contract or issue, at a named granularity.
intent edge kindpinschantintent.schema.jsonA decision pins an artifact, with the pin’s state.
intent edge kindtouched-bychantintent.schema.jsonA region was changed by a commit, with the lines touched.
intent edge kindproduced-bypluginintent.schema.jsonA commit was produced by a unit, as a plugin’s commitJoins says.
intent edge kindservespluginintent.schema.jsonA unit serves a contract, as a plugin’s commitJoins says.
intent edge kindsupersedeschantintent.schema.jsonA newer decision replaces an older one, derived as records derives it.
intent edge kindwithinchantintent.schema.jsonA commit falls inside a decision’s window, with the state decided when the decision’s own unit made it and decided-by-window when it only falls there; shown for judgment, never a finding. A commit inside a work item’s window has the state worked (#2683).
intent edge kindcites-evidencepluginintent.schema.jsonA unit, contract or decision cites evidence, contributed by a plugin’s commitJoins.
intent edge kindlinkschantintent.schema.jsonA consumer member links to a producer member.
intent edge kindimplementschantintent.schema.jsonA work item carries out a decision (#2683).
intent edge kindneedschantintent.schema.jsonA work item waits on another work item (#2683).
intent edge kindaddressed-bychantintent.schema.jsonA finding is being closed by a work item that came from it or implements the decision it concerns (#2683).
intent edge kindcarrieschantintent.schema.jsonA commit carries a decision or work item its Chant-Record trailer names, or the work item its Chant-Lease was taken on (#3149).
intent edge kindmade-bychantintent.schema.jsonA commit was made by an agent run, joined by its Chant-Run trailer or the run’s own list of commits (#3033).
intent edge kindworked-onchantintent.schema.jsonAn agent run worked on a work item, or on a record it names, as its run record says; the commits it made carry them (#3034).
reason codedeclaration-missingchantagent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, status.schema.json, wip-write.schema.json, wip.schema.jsonNo chant.workspace.json or .jsonc between the directory and the git root.
reason codedeclaration-ambiguouschantagent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, status.schema.json, wip-write.schema.json, wip.schema.jsonBoth chant.workspace.json and chant.workspace.jsonc exist.
reason codedeclaration-unparseablechantagent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, status.schema.json, wip-write.schema.json, wip.schema.jsonThe declaration is not valid JSON, or not valid JSONC for .jsonc.
reason codedeclaration-invalidchantagent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, status.schema.json, wip-write.schema.json, wip.schema.jsonThe declaration does not match its schema, repeats a name, or —member names no entry.
reason codeplacement-invalidchantagent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, status.schema.json, wip-write.schema.json, wip.schema.jsonA member or group match breaks a placement rule.
reason codereader-too-oldchantagent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, status.schema.json, wip-write.schema.json, wip.schema.jsonThe declaration’s minReader is newer than the chant reading it.
reason coderoot-chant-requiredchantagent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, status.schema.json, wip-write.schema.json, wip.schema.jsonThe declaration pins a chant version other than the reader’s, and that chant is not installed at the workspace root.
reason codenot-a-git-repositorychantagent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, evidence.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, records-since.schema.json, records.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, signers.schema.json, status.schema.json, wip-write.schema.json, wip.schema.json, work-evidence.schema.json, work-history.schema.json, work-lease.schema.json—at, or a ledger read, needs a git repository and there is none.
reason coderevision-unknownchantagent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, evidence.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, records-since.schema.json, records.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, signers.schema.json, wip-write.schema.json, wip.schema.json—at names no commit.
reason codelive-at-revisionchantgraph.schema.jsongraph was given —live and —at: a live read is of the account now, not of a revision.
reason codeenvironment-invalidchantstatus.schema.jsonAn environment name that can’t name a ledger directory.
reason codedir-missingchantcomposites.schema.json, graph.schema.json, ls.schema.jsonThe member’s directory does not exist.
reason codeunknown-kindchantcomposites.schema.json, graph.schema.json, ls.schema.jsonNo built-in kind or pinned package supplies the member’s kind.
reason codekind-probe-failedchantcomposites.schema.json, graph.schema.json, ls.schema.jsonThe member’s directory is not what its kind reads.
reason codeno-matcheschantls.schema.jsonAn example group matches no directory holding a chant project.
reason codekind-not-runchantcomposites.schema.json, graph.schema.jsonThe member’s kind is one the per-member commands don’t run, such as other.
reason codecommand-failedchantcomposites.schema.json, graph.schema.jsonThe member’s own command exited with a failure.
reason codeoutput-unreadablechantcomposites.schema.json, graph.schema.jsonThe member’s command printed something that isn’t the document asked for.
reason codeir-version-unsupportedchantcomposites.schema.json, graph.schema.jsonThe member’s IR has a version this chant can’t read.
reason codeledger-unreadablechantstatus.schema.jsonReading the ledger failed, so nothing from it is listed.
reason codeledger-malformedchantstatus.schema.jsonSome lines of the ledger aren’t release records; the rest are listed.
reason codegates-no-ledgerchantstatus.schema.jsonThe checkout has no chant/lifecycle branch, so there is no gate ledger to read.
reason codegates-no-gate-ledgerchantstatus.schema.jsonThe branch has no gate ledger for the member: no run of it has reached a gate.
reason codegates-ledger-unreadablechantstatus.schema.jsonReading the member’s gate ledger failed, so no gate is listed.
reason codestewards-unreadablechantstatus.schema.jsonAn *.op.ts file could not be imported, so a steward it declares may be missing.
reason codestewards-conflictchantstatus.schema.jsonA steward was dropped: its name, or an Op it lists, belongs to another steward.
reason codesteward-runs-unreadablechantstatus.schema.jsonReading an Op’s run ledger failed, so its last run is null.
reason coderecord-unparseablechantintent.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.jsonNo front matter, a YAML error or a value outside the JSON subset of YAML, or for a JSON kind a file that is not one object or repeats a member name.
reason coderecord-schema-invalidchantintent.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.jsonThe record’s front matter, or its JSON object, does not match the kind’s schema.
reason coderecord-id-duplicatechantintent.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.jsonAnother record earlier in path order has the same id.
reason coderecord-supersedes-unknownchantintent.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.jsonA supersedes link names an id no record has.
reason coderecord-supersedes-conflictchantintent.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.jsonA second closed record supersedes a record another one already superseded.
reason coderecord-remediates-unknownchantintent.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.jsonA remediates link names an id no record has.
reason coderecord-remediates-not-closedchantintent.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.jsonA remediates link names a record that isn’t closed; a record still open is amended instead.
reason coderecord-seal-mismatchchantpoints-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.jsonA closed record’s seal is not the whole-file seal of its text now: the record changed after it closed.
reason codesession-seal-mismatchchantpoints-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.jsonA closed session’s seal is not the whole-file seal of its text now: the session changed after it closed, or was sealed by the rule before #2546.
reason codesession-verdict-unknown-recordchantpoints-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.jsonA session’s verdict names a record that none of the session kind’s subject records has.
reason codeasset-driftchantpoints-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.jsonA file the record pins by hash has changed: its bytes no longer hash to the pinned sha256.
reason codeasset-missingchantpoints-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.jsonA file the record pins by hash does not exist in the tree read.
reason codeasset-stalechantpoints-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.jsonA file the record pins is unchanged at the hash a record it supersedes pinned: the decision changed and the artifact did not follow.
reason coderecord-no-evidencechantpoints-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.jsonThe record’s evidence list is empty: it cites nothing and pins no file. Information for a reviewer, never an error.
reason codereview-undigestedchantpoints-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.jsonA verdict names no digest of the text it judged. It still counts, and an amendment does not stop it counting.
reason codesource-transcript-driftchantpoints-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.jsonThe record’s source block pins a transcript by hash, the file it names can be read here, and its bytes hash to something else: it is not the transcript the record means.
reason codework-needs-unknownchantintent.schema.json, records.schema.jsonA work record’s needs list names a work id no record has, so the item stays blocked.
reason codework-implements-unknownchantintent.schema.json, records.schema.jsonA work record’s implements list names a decision id no decision has.
reason codework-needs-cyclechantintent.schema.json, records.schema.jsonA work record needs itself through its needs links, so it can never be ready.
reason codework-implements-undecidedchantintent.schema.json, records.schema.jsonA work record implements a decision whose state is not approved, such as proposed.
reason codework-done-unpinnedchantintent.schema.json, records.schema.jsonA work record is done and its evidence list is empty: nothing shows the work was done.
reason codework-closed-without-datechantintent.schema.json, records.schema.jsonA work record is done or dropped and has no closing date.
reason codework-done-gap-openchantintent.schema.json, records.schema.jsonA work record is done, and the finding it came from still fires on its region. graph —intent raises it, and records does by walking that region.
reason codework-acceptance-unmetchantcheck.schema.json, intent.schema.json, records.schema.jsonA work record is done, and one of its acceptance criteria has no passing evidence of the verification it expects. check fails on it (WSP117).
reason codework-acceptance-self-verifiedchantintent.schema.json, records.schema.json, work-evidence.schema.jsonA passing manual verdict on a work record’s criterion names the record’s implementer, so it does not count: a manual verdict comes from someone else.
reason codework-contract-unknownchantintent.schema.json, records.schema.jsonA work record names a contract that no record of its kind’s contract kind has.
reason codework-contract-undecidedchantintent.schema.json, records.schema.jsonA work record names a contract whose state is not approved, such as a draft.
reason codework-tier-unknownchantintent.schema.json, records.schema.jsonA work record names a builder tier that its kind’s work.tier.tiers does not list.
reason codereview-deciderchantrecords.schema.jsonThe verdict is the decider’s own, and the quorum counts verdicts besides the decider’s.
reason codereview-agentchantrecords.schema.jsonThe reviewer holds the agent role in the trust policy at base.
reason codereview-duplicatechantrecords.schema.jsonA later verdict by the same principal replaces this one. Names are compared after NFKC, trimming and lower-casing.
reason codereview-older-digestchantrecords.schema.jsonThe verdict names a digest other than the record’s text now: the record changed after the verdict.
reason codereview-unattestedchantrecords.schema.jsonAn attestation policy is active at base, and the verdict carries no seal that verifies for its reviewer.
reason codeseal-missingchantrecords.schema.jsonThe verdict, or the record, carries no seal.
reason codeseal-signer-unlistedchantrecords.schema.jsonThe reviewer, or the record’s author, has no key in the signers file at base, so the seal can’t count.
reason codeseal-signature-invalidchantrecords.schema.jsonThe seal is malformed, names a signer other than the reviewer or author, or its signature does not verify over the verdict or record.
reason codeseal-unverifiablechantrecords.schema.jsonNothing here can say whose seal it is: there is no signers file at base, or ssh-keygen is not installed.
reason coderecord-unattestedchantpoints-write.schema.json, points.schema.json, records.schema.jsonA signers file is active at base, and the record names an author whose seal does not verify: it has none, the author has no key in the file, or the signature fails.
reason codechange-uncoveredchantchanges.schema.jsonA path the diff changes is covered by no current decided record and no open work item, by path or by its member.
reason codechange-out-of-scopechantchanges.schema.jsonA record in hand for the change, such as the work item it is for or a decision that item implements, lists a path the diff changes in its out_of_scope.
reason codecomposites-no-chant-memberchantcomposites.schema.jsonNo member of kind chant was read, so nothing declares a composite instance or a component.
reason codecomposites-none-declaredchantcomposites.schema.jsonThe members read declare no composite instance.
reason codecomposites-no-componentchantcomposites.schema.jsonThe members read declare no component, so no composite instance has one.
reason coderuntimes-config-unreadablechantcomposites.schema.jsonThe member’s chant.config.ts could not be read, so only the built-in local runtime is listed, and no environment from the config.
reason coderuntimes-lexicon-unreadablechantcomposites.schema.jsonA lexicon the member’s config lists could not be loaded, so it is not listed as a runtime.
reason codeenvironments-none-declaredchantcomposites.schema.jsonThe member’s chant.config.ts declares no environments, so only local and the environments in its ledger are listed.
reason codeenvironments-ledger-undeclaredchantcomposites.schema.jsonThe member’s ledger has releases in an environment its config’s environments don’t cover, so chant run —env would refuse it and it is not listed.
reason codeenvironments-component-undeclaredchantcomposites.schema.jsonA component declares an environment its member’s chant.config.ts environments don’t cover, so chant run —env would refuse it and it is not listed (#3153).
reason codeenvironments-ledger-unreadablechantcomposites.schema.jsonThe chant/lifecycle branch exists and the member’s ledger environments could not be listed.
reason coderecord-supersedes-pendingchantpoints-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.jsonA supersedes link from a record whose state is weaker than the record it names, so the link has no effect yet.
reason codekind-unreadablechantchanges.schema.json, evidence.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records-since.schema.json, records.schema.json, runs.schema.json, work-evidence.schema.json, work-history.schema.json, work-lease.schema.jsonThe record kind file is missing or could not be imported.
reason codekind-invalidchantchanges.schema.json, evidence.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records-since.schema.json, records.schema.json, work-evidence.schema.jsonThe record kind file exports no recordKind, or its shape is wrong.
reason codeschema-unreadablechantchanges.schema.json, evidence.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records-since.schema.json, records.schema.json, work-evidence.schema.jsonThe schema file the record kind names is missing or is not JSON.
reason codeschema-id-mismatchchantchanges.schema.json, evidence.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records-since.schema.json, records.schema.json, work-evidence.schema.jsonThe schema’s $id differs from the id the record kind names.
reason codeschema-invalidchantchanges.schema.json, evidence.schema.json, intent-record.schema.json, intent.schema.json, points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records-since.schema.json, records.schema.json, work-evidence.schema.jsonThe record schema itself does not compile.
reason codelocation-missingchantchanges.schema.json, evidence.schema.json, intent-record.schema.json, intent.schema.json, points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records-since.schema.json, records.schema.json, work-evidence.schema.jsonThe records directory does not exist, in the tree or at the revision.
reason codewrite-usage-invalidchantbox-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, member-write.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, run-statement.schema.json, runs-write.schema.json, wip-write.schema.json, work-evidence.schema.json, work-lease.schema.json, write-lock.schema.jsonThe command line lacks a value the write needs, or gives one it does not take.
reason codewrite-input-invalidchantbox-factory-write.schema.json, box-listing-write.schema.json, member-write.schema.json, points-write.schema.json, records-amend.schema.json, records-new.schema.json, runs-write.schema.json, work-evidence.schema.jsonThe fields given with —from or —set can’t be read, are not JSON, or are not a JSON object.
reason coderecord-not-foundchantpoints-write.schema.json, records-amend.schema.json, records-close.schema.json, records-review.schema.json, work-evidence.schema.jsonNo record of the kind has the id given.
reason coderecord-id-takenchantpoints-write.schema.json, records-new.schema.jsonThe id given for a new record is already used, by a record or a file name.
reason coderecord-id-unallocatablechantrecords-new.schema.jsonNo id was given and none can be allocated: the records share no single prefix and —prefix names none.
reason coderecord-path-unmatchedchantrecords-new.schema.jsonThe file name made from the record’s id and title does not match the kind’s location.
reason coderecord-closedchantpoints-write.schema.json, records-amend.schema.json, records-close.schema.json, records-review.schema.json, work-evidence.schema.jsonThe record is in a closed state, so nothing in it changes; a new record supersedes it instead.
reason codeamend-id-immutablechantrecords-amend.schema.json, work-evidence.schema.jsonAn amendment changes the record’s id, and ids are never renumbered.
reason codeamend-supersede-insteadchantrecords-amend.schema.json, work-evidence.schema.jsonThe record is approved, and the amendment changes a field the approval rule does not let change in place; a new record supersedes it instead.
reason codereview-unsupportedchantrecords-review.schema.jsonThe kind’s schema has no reviews field, so its records take no review.
reason codereview-note-requiredchantrecords-review.schema.jsonA dissent was given with no note: a dissent needs a reason.
reason codereview-sign-failedchantrecords-review.schema.json—sign was given and no seal could be made: the key can’t be read or used, git names no ssh signing key, or ssh-keygen is not installed.
reason coderecord-sign-failedchantrecords-amend.schema.json, records-new.schema.json, work-evidence.schema.json—sign was given and no author seal could be made: the record names no author, the key can’t be read or used, git names no ssh signing key, or ssh-keygen is not installed.
reason coderecord-state-not-initialchantrecords-new.schema.jsonA record written through chant serve mcp gives a state other than the kind’s first: a new record opens proposed, and a person moves it on.
reason coderatify-quorum-not-metchantrecords-amend.schema.json, records-new.schema.json, work-evidence.schema.jsonThe write puts a record in its kind’s ratified state (reviews.ratified), and the record’s quorum is not met: too few agreeing verdicts count.
reason coderecord-conflictchantrecords-amend.schema.json, records-close.schema.json, records-review.schema.json, work-evidence.schema.json—expect named a digest the record no longer has: another write changed it after the caller read it (#3173).
reason codewrite-lock-timeoutchantbox-factory-write.schema.json, box-listing-write.schema.json, member-write.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, work-evidence.schema.json, write-lock.schema.jsonAnother write held the working tree’s write lock for longer than the write waits; the refusal names the holder (#3173).
reason codewrite-lock-not-heldchantbox-factory-write.schema.json, box-listing-write.schema.json, member-write.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, work-evidence.schema.json, write-lock.schema.jsonCHANT_WRITE_LOCK names a batch’s lock token that no longer holds the working tree’s write lock (#3173).
reason codesource-harvest-not-proposedchantrecords-new.schema.jsonA harvested record (source.via harvest) was written in a state other than the kind’s first: a harvest proposes, and a person decides.
reason codewrite-scope-memberchantbox-factory-write.schema.json, box-listing-write.schema.json, changes.schema.json, member-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, work-evidence.schema.jsonThe write is to a file, or to a record kind, of a member outside the writer’s scope: an agent session writes only the members it is bound to, and writeScope.<class>.members leaves the member out.
reason codewrite-scope-kindchantchanges.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, work-evidence.schema.jsonThe write is to a record kind writeScope.<class>.records does not list, with a verb it does not list for the kind, or deletes a record.
reason codewrite-scope-protectedchantbox-factory-write.schema.json, box-listing-write.schema.json, changes.schema.json, member-write.schema.jsonThe write is to a file writeScope.<class>.protected lists, or one under a directory it lists, outside the top-level keys or JSON Pointers the entry’s except allows (#3146, #3308).
reason codeprincipal-unidentifiedchantbox-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, member-write.schema.json, points-write.schema.json, records-amend.schema.json, records-new.schema.json, records-review.schema.json, wip-write.schema.json, work-evidence.schema.jsonchant.workspace.json at base sets identity.attribution to identified, and the write names a person by a bare name rather than a forge identity, a signer at base, or an agent, runner or service principal (#3163).
reason codewrite-scope-class-unknownchantbox-factory-write.schema.json, box-listing-write.schema.json, changes.schema.json, member-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, work-evidence.schema.jsonThe declaration’s writeScope at base names a principal class no pinned package supplies, and the writer is judged human, so it may be in that class; the write is refused until the package is installed at the pinned version or the entry removed (#3080).
reason codeagent-unknownchantagent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, changes.schema.json, member-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, work-evidence.schema.jsonCHANT_AGENT, or a commit’s Chant-Agent trailer, names an agent session the declaration at base does not declare.
reason codesession-unknownchantrecords-review.schema.json—session names no session of a session kind whose subjects are the record’s kind.
reason codesession-not-openchantrecords-review.schema.json—session names a session in a closed state, which takes no more verdicts.
reason codesince-rev-unknownchantrecords-since.schema.json—since names no commit, or a session with no opening revision and no commit that added it.
reason codesince-session-unknownchantrecords-since.schema.json—since has the shape of a session id and names no commit, and no session the kind or the declaration reads has that id.
reason codesince-session-openchantrecords-since.schema.json—since names a session that is still open, so the comparison runs to the working tree.
reason codeintent-record-unknownchantintent-record.schema.json, intent.schema.jsongraph —intent —record names an id that no record of a decision kind read has.
reason codeintent-symbol-unsupportedchantintent.schema.jsonThe region names a symbol, path#symbol, in a file no symbol resolver reads; a line range still works (#3034).
reason codeintent-symbol-unknownchantintent.schema.jsonThe region names a symbol the file does not declare in the tree read (#3034).
reason codeintent-symbol-ambiguouschantintent.schema.jsonThe region names a symbol that matches more than one declaration in the file; its qualified name picks one (#3034).
reason codeintent-why-no-decisionchantintent.schema.jsonNo current decision governs the region or is carried out by what made its current lines, so why.explained is false and hud offers to record one (#3034).
reason codeintent-why-no-runchantintent.schema.jsonNo agent run is joined to the commits that made the region’s current lines (#3034).
reason codeintent-why-uncommittedchantintent.schema.jsonSome of the region’s lines are not committed yet (#3034).
reason codeintent-why-run-ambiguouschantintent.schema.jsonSome lines come from a commit several agent runs made, and no run’s recorded hunks say which wrote them (#3034).
reason codepatch-path-invalidchantpatch.schema.jsonworkspace patch —path names a path that is not relative and inside the workspace.
reason codeintent-region-invalidchantintent.schema.jsonThe region’s path, or its line range, does not exist in the tree read.
reason codeintent-history-shallowchantintent-record.schema.json, intent.schema.jsonThe repository is a shallow clone, so the region’s history stops at the clone’s boundary.
reason codeintent-plugin-failedchantintent-record.schema.json, intent.schema.jsonA kind file’s commitJoins, which joins commits to units, contracts and evidence, failed for a commit.
reason codesquash-unfollowedchantintent-record.schema.json, intent.schema.json, runs.schema.jsonWith —follow-squash, a squash commit’s pull request ref is not in the clone and could not be fetched from origin, so its original commits are not followed; the read keeps its answer (#3035).
reason codebox-credential-declaredchantcheck.schema.jsonA file in a box member’s directory carries a literal secret: a credential’s shape, or a literal where a credential goes. A variable or secret-manager reference is not one.
reason codebox-capability-unbrokeredchantcheck.schema.jsonA capability in a member’s box block names no broker, so the box would hold its credential.
reason codebox-isolation-collisionchantcheck.schema.json, member-write.schema.jsonTwo boxes on one host resolve to the same port, state path or cookie name, or two ports in one box share an offset.
reason codebox-isolation-literalchantcheck.schema.json, member-write.schema.jsonA host’s stateRoot or a box’s state entry is a literal machine path instead of one derived from an environment reference and the box’s name.
reason codediagram-source-missingchantcheck.schema.jsonA declared diagram names a source, and it does not exist in the tree read.
reason codediagram-render-missingchantcheck.schema.jsonA declared diagram’s render does not exist in the tree read.
reason codediagram-render-driftchantcheck.schema.jsonA declared diagram records a sourceHash, and the source’s bytes now hash to something else: the render is stale for its source.
reason codebox-fountain-callback-undeclaredchantcheck.schema.jsonA box member builds a fountain Box, whose persistent sandbox fountain gives a callback token scoped to its owner, and the member’s box block does not declare the fountain-callback capability brokered by fountain with scope owner.
reason codebox-intent-unknownchantcheck.schema.jsonA box block names an intent, and no record of a declared kind named decision has that id.
reason codebox-intent-unconstrainedchantcheck.schema.jsonThe decision record a box names as its intent constrains no member or path of this workspace: no member: entry for a declared member and no path: entry at, above or inside one’s directory.
reason codebox-nonechantgraph.schema.json, status.schema.jsonNo member’s box block declares services, so the workspace has no box for a host to plant.
reason codebox-severalchantgraph.schema.json, status.schema.jsonMore than one member’s box block declares services, and a planted workspace runs one box.
reason coderotation-unparseablechantsigners.schema.jsonThe rotation file beside the signers file is not JSON.
reason coderotation-invalidchantsigners.schema.jsonThe rotation file does not match its shape: schema 1, a version, the previous set’s digest, a threshold and signatures.
reason coderotation-previous-mismatchchantsigners.schema.jsonThe rotation names a previous digest other than the set it replaces, as a rollback to an older set does.
reason coderotation-threshold-unsatisfiablechantsigners.schema.jsonThe new threshold is more than the number of distinct signers in the new set, so no later rotation could meet it.
reason coderotation-missingchantsigners.schema.jsonThe signer set or its threshold changed and no rotation file signed by the set before it came with the change.
reason codesigners-removedchantsigners.schema.jsonThe signers file was removed. Commits merged before the removal keep the set they were judged by; nothing after it verifies.
reason coderotation-first-versionchantsigners.schema.jsonThe first signer set’s rotation file names a version other than 1, or a previous digest.
reason coderotation-version-skewchantsigners.schema.jsonThe rotation names a version other than the one after the set it replaces, as a replayed or skipped rotation does.
reason codesigners-file-missingchantsigners.schema.jsonThere is no signers file at the base revision, so there is no signer history to read.
reason coderotation-threshold-not-metchantsigners.schema.jsonFewer distinct signers of the set before signed the rotation, in the chant-signers namespace, than that set’s threshold.
reason codetrust-policy-unreadablechantevidence.schema.json, runs-write.schema.jsonThe trust policy at base can’t be read, or its signer history is broken, so no runner key is trusted.
reason codeevidence-statement-invalidchantevidence.schema.jsonThe payload is not an in-toto Statement v1 with chant’s runner-evidence predicate, or has a field the predicate does not define.
reason codeenvelope-invalidchantevidence.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.jsonThe file is not a DSSE envelope: payloadType, payload in canonical base64, and signatures with keyid and sig.
reason codeenvelope-untrustedchantevidence.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.jsonNo signature in the envelope verifies against a runner key the policy at base lists.
reason codeenvelope-unreadablechantevidence.schema.json, runs-write.schema.jsonThe —envelope file can’t be read, or is not JSON.
reason codeevidence-runner-mismatchchantevidence.schema.jsonThe statement names a runner other than the one whose key signed it.
reason codeevidence-payload-typechantevidence.schema.jsonThe envelope’s payload type is not application/vnd.in-toto+json.
reason coderunner-key-unlistedchantevidence.schema.json, runs-write.schema.jsonThe policy at base lists no runner with the key given to evidence sign or runs sign.
reason coderunner-key-invalidchantevidence.schema.json, runs-write.schema.jsonThe key given to evidence sign or runs sign is not an Ed25519 private key in PEM.
reason coderunner-key-is-signerchantevidence.schema.json, runs-write.schema.jsonThe key given to evidence sign or runs sign is a person’s key in the signers file. Evidence and run statements are signed by a service or CI identity.
reason codelock-invalidchantcheck.schema.jsonThe lineage lock can’t be read.
reason codemanual-step-openchantcheck.schema.jsonA scope in the lineage lock has an open manual step.
reason codework-kind-missingchantwork-evidence.schema.json, work-history.schema.json, work-lease.schema.jsonNo work kind to find the item in: —kind names a kind with no work block, or the declaration names no work kind.
reason codework-kind-ambiguouschantwork-evidence.schema.json, work-history.schema.json, work-lease.schema.jsonMore than one declared work kind has a record with the id, so —kind must name one.
reason codework-item-unknownchantchanges.schema.json, work-evidence.schema.json, work-history.schema.json, work-lease.schema.jsonNo work record has the id, so there is nothing to lease.
reason codework-item-closedchantwork-evidence.schema.json, work-lease.schema.jsonA claim on a work item in a closed state, such as done or dropped: there is no work left to claim.
reason codework-criterion-unknownchantwork-evidence.schema.jsonThe work record lists no acceptance criterion with the id the evidence names, or its kind has no acceptance criteria.
reason codelease-heldchantwork-evidence.schema.json, work-lease.schema.jsonSomeone holds a live lease on the work item: another worker, or, for a claim, the same one.
reason codelease-not-heldchantwork-evidence.schema.json, work-lease.schema.jsonNobody holds a live lease on the work item: it expired, was released or was never claimed.
reason codelease-token-mismatchchantwork-evidence.schema.json, work-lease.schema.jsonThe live lease on the work item carries another fencing token than the one given.
reason codelease-racechantwork-lease.schema.jsonAnother writer changed the lease between this command’s read and its write.
reason codelease-push-rejectedchantwork-lease.schema.jsonThe remote refused the lease push: another clone claimed the item first, or the remote could not be reached.
reason coderun-existschantruns-write.schema.jsonruns start or runs record was given a run id the ledger already has.
reason coderun-unknownchantrun-statement.schema.json, runs-write.schema.jsonruns end names a run the ledger has no start for.
reason coderun-endedchantruns-write.schema.jsonruns end names a run whose end is already recorded.
reason coderun-not-endedchantrun-statement.schema.json, runs-write.schema.jsonruns sign or runs statement names a run with no end recorded. A statement is signed over the run’s whole record.
reason coderun-statement-invalidchantrun-statement.schema.json, runs-write.schema.json, runs.schema.jsonThe envelope’s payload is not an in-toto Statement v1 with chant’s agent-run predicate, or has a field the predicate does not define.
reason coderun-statement-signer-mismatchchantrun-statement.schema.json, runs-write.schema.json, runs.schema.jsonThe statement names a signer other than the runner whose key signed it.
reason coderun-statement-mismatchchantrun-statement.schema.json, runs-write.schema.json, runs.schema.jsonA listed runner key signed the statement, and it does not match the run’s record: another run, a record that hashes differently, or another unit, harness, model, provider or principal.
reason codemember-existschantmember-write.schema.jsonmember add names a member the declaration already has, with an entry other than the one given.
reason codemember-unknownchantmember-write.schema.jsonmember remove names a member the declaration does not declare.
reason codefactory-member-unknownchantbox-factory-write.schema.jsonbox factory set names a member the declaration does not declare.
reason codefactory-box-missingchantbox-factory-write.schema.jsonbox factory set names a member whose entry declares no box block, so it has no factory.
reason codelisting-member-unknownchantbox-listing-write.schema.jsonbox listing set names a member the declaration does not declare.
reason codelisting-box-missingchantbox-listing-write.schema.jsonbox listing set names a member whose entry declares no box block, so it has no listing.
reason codelisting-cover-invalidchantbox-listing-write.schema.jsonThe cover can’t be read, is not a PNG, JPEG or WebP picture, is larger than 5 MiB, has a path outside the workspace, or has an extension other than its picture format’s.
reason codepublish-member-unknownchantbox-publish.schema.jsonbox publish names a member the declaration does not declare.
reason codepublish-nonechantbox-publish.schema.jsonbox publish names a member whose box block names no publisher, or which declares no box block.
reason codepublish-refusedchantbox-publish.schema.jsonThe box’s publisher refused (it exited 2): nothing was published, and its message says why.
reason codepublish-failedchantbox-publish.schema.jsonThe box’s publisher could not be run, failed (a nonzero exit other than 2) or ran out of time; its message says what it had done.
reason codepublish-answer-invalidchantbox-publish.schema.jsonThe box’s publisher exited 0 and printed no JSON object, or one box-publish.schema.json does not allow.
reason codepublish-unrecordedchantbox-publish.schema.jsonThe commit the publisher named is not in the repository, or lacks the apply record of ws-075.
reason codewip-no-branchchantwip-write.schema.jsonHEAD is detached, or names a branch with no commit yet, so there is no branch to keep work in progress for.
reason codewip-nonechantwip-write.schema.jsonwip restore was given no snapshot, and the branch has none under refs/chant/wip/<branch>.
reason codewip-snapshot-unknownchantwip-write.schema.jsonwip restore names something that is not a work-in-progress snapshot chant took.
reason codewip-branch-otherchantwip-write.schema.jsonwip restore names a snapshot taken on another branch than the one checked out.
reason codewip-racechantwip-write.schema.jsonAnother writer moved refs/chant/wip/<branch> between this command’s read and its write.
reason codewip-policy-nonechantwip-write.schema.jsonwip push or wip fetch was run, and no box block declares replicate, so there is no remote.
reason codewip-remote-unknownchantwip-write.schema.jsonThe replicate policy names a git remote the checkout does not have; the host adds it, with its credential, before chant pushes.
reason codeci-green-undeclaredchantci-last-green.schema.jsonThe declaration has no ci.green block, so chant does not know which check runs make a commit green.
reason codeci-branch-unknownchantci-last-green.schema.jsonThe checkout has no ref for the branch ci.green names: neither the remote-tracking branch nor a local one.
reason coderuns-no-ledgerchantruns.schema.jsonThe checkout has no chant/lifecycle branch, so there are no agent runs to read.
reason coderuns-ledger-malformedchantruns.schema.jsonSome lines of the agent run ledger aren’t run events; the rest are read.
reason codeanswer-points-unreadablechantintent.schema.json, points-write.schema.json, points.schema.json, records.schema.jsonThe points file the answer kind names can’t be read, or is not valid.
reason codeanswer-point-unknownchantintent.schema.json, points-write.schema.json, points.schema.json, records.schema.jsonThe answer’s point is not declared in the points file the answer kind names.
reason codeanswer-point-changedchantintent.schema.json, points-write.schema.json, points.schema.json, records.schema.jsonThe point’s declaration changed since the question was asked, so the answer is to an older version of the question.
reason codepoints-undeclaredchantpoints-write.schema.jsonNo record kind with an answers block is declared, or given with —kind, so there is no points file to ask.
reason codepoints-invalidchantpoints-write.schema.json, points.schema.jsonThe points file an answer kind names can’t be read, or does not match decision-points.schema.json and the rules checked in code.
reason codepoint-unknownchantpoints-write.schema.jsonNo points file declares the point asked, or the one an answer names.
reason codepoint-inputs-invalidchantpoints-write.schema.jsonThe inputs given to an ask are not a JSON object of the point’s declared inputs.
reason codepoint-candidates-invalidchantpoints-write.schema.jsonAn ad-hoc point was asked without —candidates, a declared point with them, or they are not a question and criteria of the point’s question type (#3403).
reason codepoint-decider-failedchantpoints-write.schema.jsonA model decider that fails closed (unreachable: fail) could not answer, so the ask wrote nothing.
reason codeanswer-not-candidatechantpoints-write.schema.jsonThe people’s answer is not one of the question’s candidates.
reason codequorum-not-metchantpoints-write.schema.jsonToo few of the people who answered count toward the point’s quorum: distinct, not holding the agent role, not the steward that asked, and holding one of its roles when it names any.
reason codeanswer-in-steward-turnchantpoints-write.schema.jsonThe answer was given during a steward’s turn, or by a process it started: a steward never answers a decision point, and a person answers it through hud or at a shell.
reason codeanswer-not-answeredchantpoints-write.schema.jsonpoints retract names a question that has no answer to retract: it is escalated or proposed, and people answer it instead (#3351).
reason codeanswer-field-unsupportedchantpoints-write.schema.jsonThe answer kind’s copy of point-answer.schema.json predates a field the write needs, a note, a retraction or an ad-hoc question’s asked, and chant refuses rather than drop it (#3351, #3403).
finding codeintent-commit-undecidedchantintent.schema.jsonA commit changed the region when no decision constrained it at path granularity.
finding codeintent-commit-barechantintent.schema.jsonA commit names no unit, carries no record through its Chant-Record or Chant-Lease trailer, and has no pull request and no decision covering the region at its time.
finding codeintent-pin-driftedchantintent.schema.jsonA decision’s pinned artifact no longer hashes to the pin.
finding codeintent-pin-missingchantintent.schema.jsonA decision’s pinned artifact does not exist in the tree read.
finding codeintent-pin-stalechantintent.schema.jsonA current decision pins an artifact at the hash a record it supersedes pinned, and the artifact has not changed since: the decision moved on and the artifact did not.
finding codeintent-artifact-unpinnedchantintent.schema.jsonAn artifact decisions in the graph pinned, which no current decision pins.
finding codeintent-decision-superseded-livechantintent.schema.jsonEvery decision constraining the region is superseded.
finding codeintent-decision-provisionalchantintent.schema.jsonThe current decisions constraining the region are all in states their kind does not close, such as decided.
finding codeintent-decision-contestedchantintent.schema.jsonA current decision constraining the region has an open concern: a dissent neither addressed nor withdrawn.
finding codeintent-constraint-coarsechantintent.schema.jsonThe region is constrained only through its member, not by path.
finding codeintent-constraint-lostchantintent.schema.jsonA decision’s path constraint names a path that does not exist in the tree read.
finding codeintent-evidence-unpinnedchantintent.schema.jsonA decision’s evidence has no hash: a URL, or a path with no sha256.
finding codeintent-trailer-unverifiedchantintent.schema.jsonA commit carries a trailer a plugin says claims authorship, and the commit is not attested.
finding codeintent-region-unconstrainedchantintent.schema.jsonNo decision constrains the region at any granularity.
finding codeintent-decision-unimplementedchantintent.schema.jsonA decided decision constrains the region, no work item that is not dropped implements it, and no commit falls in its window.
finding codeintent-work-blockedchantintent.schema.jsonA work item constraining the region has commits in its window while a work item it needs is not done.
finding codeintent-work-open-decided-codechantintent.schema.jsonCommits in the region are a decision’s own work while the work item implementing that decision is still open.
finding codeintent-commit-join-conflictchantintent.schema.jsonA commit joined to an agent run by its Chant-Run trailer or the run’s record has the patch-id of a commit another run recorded, so it is not joined to that run by content (#3036).
WSP checkWSP001 declaration-unreadablechantcheck.schema.jsonThe declaration can be read: it parses, matches the schema and keeps the placement rules.
WSP checkWSP002 kinds-unreadablechantcheck.schema.jsonEvery pinned package’s kinds and principal classes can be read: it is installed at the pinned version, its ./workspace-kinds file is valid kind data, and its ./workspace-principals file is valid class data.
WSP checkWSP003 kind-unknownchantcheck.schema.jsonEvery member’s kind is built in or supplied by a pinned package, and so is every principal class writeScope names (#3080). Unknown kinds and classes fail closed.
WSP checkWSP004 member-dir-missingchantcheck.schema.jsonEvery member’s directory exists.
WSP checkWSP005 kind-probe-failedchantcheck.schema.jsonEvery member’s directory is what its kind reads, such as a chant config for a chant member, and its fields are ones its kind declares, of the declared types (#3151).
WSP checkWSP006 kind-probe-tiechantcheck.schema.jsonNo directory is claimed by two kinds of the same highest precedence. Ties fail.
WSP checkWSP007 kind-outrankedchantcheck.schema.jsonWhen several kinds claim a member’s directory, the declared kind is the one the precedence order picks.
WSP checkWSP008 other-claimedchantcheck.schema.jsonNo other member’s directory is claimed by a registered kind’s probe.
WSP checkWSP009 other-memberchantcheck.schema.jsonA member of kind other is one chant does not read. It is reported so that it stays a decision.
WSP checkWSP010 group-emptychantcheck.schema.jsonEvery example group matches at least one chant project.
WSP checkWSP011 check-settings-invalidchantcheck.schema.jsonThe declaration’s checks and suppress settings name known, configurable WSP ids.
WSP checkWSP071 ownership-stack-sharedchantcheck.schema.jsonNo two chant members set the same ownership.stack. Ownership markers carry no member name, so the stack tells members’ resources and receipts apart.
WSP checkWSP072 flat-ledger-environment-sharedchantcheck.schema.jsonNo two members that write the flat ledger layout (the root member, and members on a chant older than 0.81.0) share an environment name.
WSP checkWSP073 ledger-settings-unreadchantcheck.schema.jsonA chant member’s ownership and environments could not be read from its config without running it, so WSP071 and WSP072 could not compare it.
WSP checkWSP081 generated-declared-twicechantcheck.schema.jsonNo two members record the same generated file, so no member’s regeneration overwrites another’s pipeline.
WSP checkWSP082 generated-outside-memberchantcheck.schema.jsonA member’s recorded generated files sit in its own directory, or are forge CI files at the fixed paths forges read.
WSP checkWSP083 linked-environments-disjointchantcheck.schema.jsonLinked members share at least one environment name, matched exactly, when both name any.
WSP checkWSP091 link-target-unknownchantcheck.schema.jsonEvery member link names another member of the workspace. A link to an unknown name, an example group or the consumer itself fails closed.
WSP checkWSP092 link-kind-unknownchantcheck.schema.jsonEvery member link’s kind is one chant knows. Unknown link kinds fail closed; output is the default, and telemetry is the other.
WSP checkWSP093 link-output-missingchantcheck.schema.jsonEvery member link names an output its producer exposes, matched exactly. A producer that renames an output fails this for every consumer that links to the old name.
WSP checkWSP094 link-unresolvedchantcheck.schema.jsonA member link whose producer’s outputs can’t be read in source is kept, unresolved, and reported.
WSP checkWSP095 join-ambiguouschantcheck.schema.jsonNo inferred join is ambiguous: a parameter that matches outputs of two producers (or two outputs of one) needs a declared link saying which.
WSP checkWSP096 link-duplicatechantcheck.schema.jsonA link is stated once: no consumer lists the same member and output twice.
WSP checkWSP097 outputs-not-listablechantcheck.schema.jsonAn entry lists outputs only when its kind takes them from the entry: other, or a kind from a package. A chant member’s outputs are read from its source, and a nested workspace exposes none.
WSP checkWSP098 link-protocol-misplacedchantcheck.schema.jsonA link states a protocol only when it is a telemetry link: protocol is the OTLP protocol the consumer sends to the producer’s collector, and no other link kind has one.
WSP checkWSP101 generated-driftchantcheck.schema.jsonA generated file is what its generator writes. Declared generators run only with —generated.
WSP checkWSP102 generated-missingchantcheck.schema.jsonEvery declared generated file exists.
WSP checkWSP103 generator-failedchantcheck.schema.jsonA declared generator runs, exits 0 and writes the file.
WSP checkWSP104 generated-hand-writtenchantcheck.schema.jsonAn entry kept by hand is reported with its reason, and its generator is not run.
WSP checkWSP105 generated-not-comparedchantcheck.schema.jsonAn entry not compared with its generator’s output is reported with the reason.
WSP checkWSP106 generated-source-missingchantcheck.schema.jsonEvery source a generated entry names exists.
WSP checkWSP111 record-asset-driftchantcheck.schema.jsonEvery file a current record pins by hash still hashes to the pinned sha256. A changed file asks for the record to be revisited.
WSP checkWSP112 record-asset-missingchantcheck.schema.jsonEvery file a current record pins by hash exists.
WSP checkWSP113 record-asset-stalechantcheck.schema.jsonNo current record pins a file at the same hash as a record it supersedes while the file is unchanged since: when a decision changes, the artifacts it rests on follow.
WSP checkWSP114 records-unreadablechantcheck.schema.jsonThe records of the kind named with —kind can be read.
WSP checkWSP115 record-kind-unloadablechantcheck.schema.jsonEvery record kind the declaration names is a file that exports a valid recordKind, with the schema it names.
WSP checkWSP116 decision-points-invalidchantcheck.schema.jsonEvery answer kind the declaration names has a decision points file that matches decision-points.schema.json, with each input naming a read-contract output, pinned model ids and a chain ending in its one quorum (ws-058).
WSP checkWSP117 work-acceptance-unmetchantcheck.schema.jsonEvery done work item meets its acceptance criteria: each has evidence that names it, passed, and has the verification the criterion expects, and a manual verdict is from someone other than the implementer (#2772).
WSP checkWSP121 box-credential-declaredchantcheck.schema.jsonA box holds no credential: no file in a box member’s directory carries a literal secret, in its declarations, an env or a vault’s defaults. Variable references and secret-manager references (op://, bws://, infisical://) are not secrets.
WSP checkWSP122 box-capability-unbrokeredchantcheck.schema.jsonEvery capability a box declares names the broker that holds its credential and enforces its scope.
WSP checkWSP123 box-isolation-collisionchantcheck.schema.jsonNo two boxes on one host resolve to the same port, state path or cookie name, and no two ports in one box share an offset.
WSP checkWSP124 box-isolation-literalchantcheck.schema.jsonNo host’s state root and no box’s state entry is a literal machine path: state paths derive from an environment reference and the member’s name.
WSP checkWSP131 diagram-source-missingchantcheck.schema.jsonA diagram’s source file, when it names one, exists in the tree read.
WSP checkWSP132 diagram-render-missingchantcheck.schema.jsonA diagram’s render, when it names one, exists in the tree read. Only a mermaid or excalidraw diagram may name none.
WSP checkWSP133 diagram-render-driftchantcheck.schema.jsonA diagram that records a sourceHash is unchanged since its render was made: the source’s bytes still hash to it. Runs no renderer.
WSP checkWSP125 box-fountain-callback-undeclaredchantcheck.schema.jsonA box member that builds a fountain Box declares the callback token fountain gives its persistent sandbox: the fountain-callback capability, brokered by fountain, with scope owner.
WSP checkWSP126 box-intent-unknownchantcheck.schema.jsonThe intent a box block names is the id of a record of a declared kind named decision, the record that says what the box is for.
WSP checkWSP127 box-intent-unconstrainedchantcheck.schema.jsonThe decision record a box names as its intent constrains a member or path of this workspace, with member: and a declared member’s name or a path: entry at, above or inside one’s directory; not necessarily the box’s own member.
WSP checkWSP141 link-live-missingchantcheck.schema.jsonWith —live, a declared member link names an output its producer’s estate publishes now, matched exactly.
WSP checkWSP142 link-live-unresolvedchantcheck.schema.jsonWith —live, a declared member link that could not be resolved against a live read is kept, unresolved, and reported.
hud viewH1hudalecraso/hudReview queue: decided records grouped by area, oldest first, each as a decision card. It reads records —current —json.
hud viewH2hudalecraso/hudDecision page: options side by side with rejected options kept, the supersession chain, amendment history and provenance. It reads records —json, records —at.
hud viewH3hudalecraso/hudReview actions: agree, dissent with a required reason, abstain and propose, each verdict a pull request under the signed-in principal. It reads records, and writes through records review and records new in a pull request.
hud viewH4hudalecraso/hudQuorum meter: counted and not-counted principals with reasons and open concerns. It reads the quorum in records.
hud viewH5hudalecraso/hudReview session: agenda, attendance, presence and follow mode, live meters and a summary of what changed at close. It reads session records, records —since <session id>; writes records new, review —session and close (#2693).
hud viewH6hudalecraso/hudImpact: constrained targets with their live state, and provisional dependants flagged. It reads the constrains lists in records —json, graph —kind, ls, the forge.
hud viewH7hudalecraso/hudEvidence drift: pin states, with the pinned and current artifact side by side. It reads the pins in records.
hud viewH8hudalecraso/hudIntent graph: the region at the centre, with artifacts, decisions and commits in bands and findings drawn as nodes. It reads graph —intent.
hud viewH9hudalecraso/hudAnchor states for constraint paths and pins, and re-anchor as an action that drafts a record. It reads graph —intent, records —constrains.
hud viewH10hudalecraso/hudText from records, commits and comments goes to any agent fenced as data. It reads every document it passes on.
hud viewH11hudalecraso/hudEvery walk answer is kept as a disposition list, so a group can review a walk without redoing it. It reads hud-side state, with the resulting records in git.