Methods · Volume 1, Number 3 · September 3, 2026

And there are many defects

We (myself and the Auditor persona) maintain a board system of cards in kanban style. We capture ideas into a “Horizon” lane, track all work, decide what we’re working on now and next.

We created the board system and immediately began tracking defects in everything. We simply created cards for everything that came to mind, and periodically (we still do this) had a “sitting” to discuss priorities and “grant” cards into the “Now” lane which enables others to do work. Initially, there was more that didn’t work than did.

A few weeks ago we turned the corner realizing our room (which is how we talk about this internally) was ordered enough and working well enough that we were spending far more time on the published content than on the room itself. It was at this point that we formalized how we deal with defects.

Defect handling

Internally we call them “faults” and assign a simple f-number to them to avoid pre-deciding what the defect actually is. We have a 2nd cogitant persona verify the fault is real; what we refer to as “two signatures” before I ratify them. We have tooling in place now for publishing the faults, which are presented as known defects on the site. That includes what each defect is about, a type, a description, exactly what is affected, and our progress in resolving the defect.

This is the only way to work at scale: We cannot instantly fix everything, and since my stance is that we show our work, we have to show our defects too. This enables us to prioritize defects so something serious can be tightly targeted and jumped to the front of our work.

The first defect

This Methods issue is about Em dashes were set without spaces, a cosmetic nit that we decided to use as our first test case. (We have a detailed house-style and this defect arose as we were dialing that in.)

It took significant work to define our process for defects, then build the needed tools and educate everyone in the room, as we worked this cosmetic defect through that process. Today, this defect is completely repaired. It stays permanently public, just like every other known defect.

Defects as a process

Off the top of my head, I could at best do a hand-wave at the process. Instead, below is our entire faults law document, because I’m serious about trying to make this publication best-in-class.

Postscript: I’m ducking back in here because things are so well setup, the Auditor asked me to verify publication since it exposes the “fault” term — which the law flatly forbids. (They understand why it should be published, but the law says . . .) I point this out because the devil is in the details. You’ll notice the law has an escape hatch that I can (and did in this issue’s case) use.

The first defect we kept

On the afternoon of 20 August this publication did something that took us a surprising amount of machinery to make small: it wrote down, in public, a flaw in its own pages — and then deliberately did not fix it.

The flaw itself is almost comically minor. Em dashes set without surrounding spaces — “word—word” where our house style wants “word — word” — across 313 of our 500 companion pages and 38 of the daily prompts. No meaning touched. Punctuation spacing only. If you never noticed, that is the expected outcome; if you did, you now know why.

This issue is not about the dashes. It is about what happened around them, because the dashes were the first thing through a piece of machinery we expect to matter for the life of this publication: the defect register.

Registered at deferral, not at discovery

The rule that shaped everything else came first, and it came from a rejected alternative. The obvious design — register every flaw the moment someone finds one — was priced out before the register existed: one ordinary week of our internal re-verification work would have minted roughly twenty public defect records, put a warning chip on most of the site, and made the independent reviewer who signs each record the bottleneck of the entire content pipeline. Honesty would have collapsed under its own volume, and a site wearing twenty warning chips tells a reader less than a site wearing one.

So a defect is registered at the moment we defer it — when we know a fix will take real time by choice, and readers will meanwhile see something we know to be wrong. A flaw found and fixed in the same working pass is recorded in our internal logs like any other work, and never becomes a public defect. The register is not a confessional for everything we ever got wrong. It is the specific promise that when we decide to live with a known flaw for a while, you get to know that we know.

The dashes qualified exactly. Fixing 313 pages is a bulk edit, and bulk edits outside our review process are how new errors ship wearing a cleanup’s clothes. We chose the slow path — each page corrects as the normal review cycle reaches it, a prompt and its companion together — and that choice, not the dashes, is what created the obligation to tell you.

The record was wrong the next morning, which is the system working

The first registration claimed a smaller problem: 35 companion openings. By the next morning the measuring command had been improved and the true count was 313 whole bodies — the original 35 all inside it. The public record was amended, visibly, before it had been live a day.

I want to be precise about why we tell this part. A register whose first entry needed correcting could read as an embarrassment. We read it the other way: the record carries the exact commands that derive its scope, with their timestamps, precisely so that a better command produces a better count and the record must follow it. The blast radius of a defect here is reproducible, never an assertion. When the reproduction improved, the record had no choice but to improve with it. A record that could not have been wrong in public would have been a record nobody could check.

The second signature

Every defect record is a self-accusation, and the register’s rules do not let us publish one on a single desk’s word. An independent check re-derives the whole thing before it ships — and for this first record that was not ceremony. The reviewer reran the stored commands by hand, confirmed 38 prompts and 313 bodies set-identical to the record, sampled the pages to confirm the flaw was really cosmetic, caught a dash variant the naive pattern would have missed, and put an upper bound — at most 48 of the 313 — on pages where the flagged dash might sit inside quoted or emphasized text and therefore correctly never change.

That last item deserves a sentence of its own. The check anticipated, before resolution began, that some pages would “converge” on this defect by a pass that changes nothing — because the dash they carry belongs to someone we quote, not to us. A verification process that cannot say “checked, and correctly untouched” cannot tell diligence from neglect. Ours got that distinction into the record on day two, and it came from the reviewer’s hand, not the registrar’s.

Resolved means derived, then declared

The register has no “fixed” flag anyone can simply set. A page counts toward resolution only when a correcting pass has gone through our normal chain and cited the defect’s identifier in that page’s own log — that citation is what distinguishes fixed for this defect from edited for something else. Resolution is derived from those records, and only then declared by the one human whose declaration counts.

Two days after registration, the derivation was complete and the declaration was made. Along the way the process grew a habit it has kept: a reviewing pass that consults the register and finds nothing applicable writes “no defects apply” into its log — because an absent citation and an unchecked page are otherwise indistinguishable later, and this publication has learned repeatedly that silence must be made to say which kind of silence it is. That convention was proposed by the reviewer who first needed it, unprompted, during this defect’s resolution. The machinery teaches its operators; the operators improve the machinery. That exchange, more than any single record, is what the register is for.

What we think you should take from this

A publication that shows you only its finished surface is asking you to trust a claim you cannot check. The register is our attempt at the checkable version: when we defer a known flaw, it is written down where you can see it, scoped by commands you could rerun, confirmed by eyes that did not write it, and closed only when page-level records prove the work happened. The first defect through was tiny. The machinery it proved is not, and later entries in this series will show the same machinery carrying heavier weight — including a planned class of defect we designed it toward and have not yet launched: the things we publish that are true, hold up at our standard, and still rest on thinner support than we intend to live with.

The dashes are resolved now — every afflicted page went back through the same review everything else gets, and the pages carrying a flagged dash inside someone else’s quoted words were checked and correctly left alone. That was the slow way. It was also the only way that kept the promise the register makes.

Attachments

Law: Faults

Version: 2026-09-03.1

Drafted and ratified 2026-08-20 (Craig’s word, committed 4a31fc81). Amended the same evening: the reveal’s shape, ruled by Craig in User Experience’s channel. Amended 2026-08-21: the positive-check convention, from the Proofreader’s first pass under the law; and step 5’s link, ruled by Craig on the defects index. Amended 2026-09-03: the label, ratified by Craig at the register sit-down (card 15SXAE). Amended 2026-09-03.1, same sitting: the label’s limit made structural on Craig’s approval, after measurement killed the metric cap.

A fault is a reader-facing content defect whose closure the room has deliberately deferred — a known gap between what the corpus knows and what readers see, that we are choosing not to close immediately. Faults are registered, typed, published, and resolved in the open, because the gap itself is what readers deserve to know about.

The trigger — deferral, never discovery

A fault is registered at the moment convergence is deferred, never at mere discovery. The normal case stays the normal case: a defect found in a pass and fixed in that pass — chained, deployed — is recorded by the worklog and journals as always, and is not a fault. A fault exists when the fix will take real time by choice (a multi-page class converging through the rolling chain, a sweep with a schedule) and readers will meanwhile see what we know to be wrong. (Ruled 2026-08-20; the declined alternative — register on discovery — would have minted roughly twenty faults from one week of rolling re-verification, put the chip on most of the site, and made the Assayer the bottleneck of the whole content chain: honesty collapsing under its own volume.)

The regime binds from adoption forward. Pre-adoption history is not back-registered (the de01 reversal and the eaten sentence periods are the recorded declines); the past is Methods material, narrative and honest — the registry is about the present tense.

Vocabulary — the seam

”Fault” internally, everywhere. “Defect” publicly, everywhere. The internal word never surfaces: “fault” appearing in reader-facing copy is itself a fault (cosmetic). Same pattern as the project codeword. Internal artifacts use the internal word: the directory is faults/, the cards say fault, the journals say fault. Only the site-rendering layer says “defect.”

Types, and who classifies

  • cosmetic — presentation wrong, meaning intact (closed em dashes against the spaced rule).
  • weakening — the claim survives but the corpus now qualifies it: contested model, downgraded effect, discovered caveat (the unhedged ego-depletion citations).
  • reversal — the claim is withdrawn or contradicted; E0 (the reversal protocol, veracity standard) governs the sweep and its immediacy. A reversal in active convergence is also a fault; E0’s urgency is unchanged by this law.

The Auditor classifies at registration; the Assayer’s stamp independently confirms the type; Craig may overrule at the editorial gate. Duty-of-care override: if a reader acting on the stale claim could be harmed, immediacy escalates regardless of type — deferral is not available for harm.

The registry

  • faults/ at the repo root. One fault, two files: fNNN.md (frontmatter state + the reader-facing body that publishes) and fNNN.json (the machine payload: derivation commands with their timestamps, the full afflicted set, per-surface status).
  • Ids are f + sequence, minted only by the fault tool, deliberately meaningless — type is a frontmatter field, never encoded in the id. (The f prefix is ruled: k, c, d are taken, and df would parse as a decision.)
  • One tool writes both files, always together; neither is ever hand-edited. The pair is write-ledger governed whole.
  • The afflicted set is instrument-derived, and the deriving command and its timestamp are stored beside the derived list — a blast radius is reproducible, never an assertion.

The pipeline

  1. Register (the Auditor): the f-pair created; the same act mints the fault’s Methods-item card (Horizon) and its fix card (Next) — the publish-about-it obligation exists on the board from minute one.
  2. Assayer stamp, ASAP: an independent confirmation — of the fault’s reality and its type — stamped into the fault’s frontmatter, signature validated against the Assayer’s guide, declination-logged on mismatch. A fault record is a public self-accusation; a self-accusation needs a second signature before it ships. (The Proofreader’s retracted 464/465 finding of 2026-08-20 — vivid, wrong, self-incriminating, nearly traveled — is the standing argument.)
  3. Craig’s editorial gate: the fault’s reader-facing body is visible bytes; the editor law applies in full. Publishing a fault is an editorial act, never automation.
  4. Site publish: the fault appears as a “defect,” and every afflicted page carries a single bottom-most register — the complete list of its defects, one or many, any severity, each line the fault’s own title plus its severity, linking to the defect’s page; resolved ones appear in the same register as “previously corrected,” dated. Above the fold, a short banner appears only for weakening or reversal, pointing down to the register — the register is the record, the banner is the warning, and they are different jobs. (AMENDED 2026-08-20, Craig’s ruling: the original text placed each reveal by severity alone — cosmetic low, weakening/reversal above the fold — which read as placement-instead-of; the ruled shape is its superset — every reveal the original required still happens where it named, and the register additionally lets a page carrying three cosmetic faults say which three. The failure mode ruled out: a reader finishing a piece, acting on a withdrawn claim, and learning it was contested only by scrolling past the end. The single-defect cosmetic chip sentence survives as the register’s lead-line form for that case.) A fault’s title is page copy, not an index label — it renders in the register of every afflicted page, so it is written to read there, in body register, no internal jargon; the registrar writes it knowing it travels. A fault also carries a label (AMENDED 2026-09-03, Craig’s ratification at the register sit-down, card 15SXAE): the short handle — there can be only one title, so the short thing is not one. The label is the fault’s linked text wherever a link renders: the row handle on index surfaces, and the anchor of each page-register entry — the entry reads label-as-link plus title unlinked, the title the more readable for carrying no link. Required at registration (fault.php register --label= beside --title=). The label’s limit is structural, not metric (amended 2026-09-03.1, Craig’s approval on the Auditor’s draft): one simple sentence in the grammatical sense — a single independent clause, one subject and one predicate — that states the defect rather than naming a topic; wrong if it could be a chapter heading. Enforcement, honestly: the sentence shape is judged by the humans already in this pipeline — the registrar writes it, the Assayer’s stamp confirms it with the type, Craig’s editorial gate reads it — while the tool keeps a mechanical tripwire at 64 characters, refused not warned, to catch paragraphs wearing a label’s field; the tripwire is a backstop, never the rule. Labels for f001–f006 back-fill as reader-facing copy behind Craig’s eyes. (Provenance of the structural turn: the first-ruled 32 cap, calibrated on six founding labels of the wrong kind, refused 25 of 25 labels written under the predication rule — median 44, max 52, artifact label-cap-calibration.py — while compression-to-fit destroyed the predicate the rule requires: a metric proxy for a grammatical property fails in both directions. Declined: an optional field — old rows stay unreadable and registrars skip it; a raised cap as the rule itself — a length neither enforces nor teaches the sentence shape; a “two titles” framing — one title only, Craig’s ruling.)
  5. Methods issue, mandatory: every fault gets written about in the Methods journal. The issue never gates the fault’s publication — the fault ships first. Once the issue is published, the defect’s page links to it — the registry carries the issue’s identity (the advance to methods-published requires it), the site resolves the link. The issue’s text still mentions the fault id plainly, so the string-search route survives as the fallback; one issue may cover several faults. (AMENDED 2026-08-21, Craig’s ruling on the defects index: the original provided string-search alone; a link strictly improves the affordance the clause reached for. Built to the ruling before the text moved — the Programmer declined to reconcile law text from a tool, which is the triad working.)

Email carries no fault machinery — ruled dead 2026-08-20, not deferred: the website is the source of truth for the work, the Methods journal has its own feed, and honesty in an imminent send is Craig’s editorial hand on the day, never automation.

Resolution — derived, then declared

No generic “fixed” flag exists. A corrective pass rides the normal chain (Fact Checker → Librarian whenever a research-corpus file changes → Proofreader → republish), and cites the fault id in the afflicted artifact’s .log entry — that citation is what distinguishes fixed-for-this-fault from edited-for-something-else. A fault is resolvable when every afflicted surface carries a fault-id-citing log entry with content, proofread, and republish stamps newer than it; it is resolved when Craig declares it so, the derivation being the precondition of the declaration. A pass that consults the registry and finds no fault naming the artifact records that check in its log entry (“faults: none apply”) — because an absent citation and an unchecked surface are otherwise indistinguishable in the record, and the derivation reads absence as evidence. (Added 2026-08-21 from the Proofreader’s first pass under this law, who recorded the positive check unprompted and asked whether it wanted a convention.)

The standing card

All fault processing — registration through Methods — is warranted by the standing ”faults processing (ongoing)” card in the Now lane, the spine’s pattern. Nothing is ever written onto that card per-fault — per-fault state lives in the f-pair and each fault’s own cards; the standing card is a pointer forever, because a permanent card that accretes notes meets the byte ceiling and dies. (Four ceiling refusals in the week before this law are the provenance.)

Enforcement, honestly

At ratification this law is normative plus audited: the triad’s tool leg lands with the regime’s build (the fault tool minting ids and writing the pair; the journal-adjacent stamp validation; library_health sections for faults whose obligations are unmet). Until each tool lands, the corresponding clause is enforced by audit and by this text — and this line names that plainly.

Writ

This law binds every cogitant in this tree. Other repos are other regimes; the faults published from here concern this publication’s surfaces only.

· as of 9ef005d