marketplace

mirror

Shares only what you approve, word for word.

blueprint · recommended

The publishing safety floor. Alexandria's Library is outside the private loop. This file is read when the Author asks to publish and, once their Mirror is set up, by the alexandria skill's background pass, which keeps their draft mirror through it. For an Author who has not set up their Mirror it is never a reason to suggest publishing.

The rule

Nothing publishes because it looks ready, has been public before, sits in a particular folder, matches a standing category, or seems harmless. The Author must see the exact current artifact and its exact audience, then separately approve that action.

For a direct publication request:

  1. Read only the named artifact.
  2. Explain plainly what will be sent, where it will be visible, and that copies may persist after deletion.
  3. Show the final artifact and wait for a separate yes.
  4. Record that approval in the protected runtime with bash ~/.local/share/alexandria/scripts/permission.sh approve <file> <exact-scope> <sha256>. The model's sandbox cannot write there, so this is the Author's own step: their approval of the host's prompt to run that one command outside the sandbox, or the line run in their own terminal. A file written beside the artifact approves nothing.
  5. Publish only while the current file hash, scope and name still match that approval.

Any edit, rename, or audience change invalidates approval. The changed version stays local until the Author reviews and approves it again. An approval for one file never covers another file, metadata from another path, a price, an invitation, or a future update.

  • moving or saving a file under library/
  • a past publication
  • an old approval for different bytes or a different audience
  • an agent's judgment that the Author would probably share it
  • silence, broad enthusiasm, or an account connection
  • a standing filter or category rule

Content floor

Do not publish secrets or credentials, anything that shows where to find the Author finer than a city, their health or money, other people's private information, live undisclosed business state, raw journals, transcripts, vault material, marginalia, or anything whose ownership is unclear. A draft starting with _ never publishes. When anything is unclear, keep it local.

The draft and the live mirror

Once the Author's Mirror is set up, each layer has two versions. The live mirror is what readers see: the files whose exact hash, scope and name the Author approved. The draft mirror is their system's own best guess at the ideal mirror for each layer, kept in that layer's folder under files/library/ and rewritten by the alexandria skill's background pass every session from everything the Author has said and made since, through this filter: their shadow at each layer, the pieces and positions the filter places there, and refreshed versions of pages already live. Making and updating the draft needs no question, because nothing in it leaves the computer; the Author's part is to think, make and decide, never to remember to add something to their mirror. A piece goes in the tightest layer the filter allows, and anything the filter is unsure of stays out of the draft. A piece behind more than one gate (member/paid/, invite/paid/) meets the strictest floor among its layers. The draft is the files themselves, each in its layer folder under the name it will publish as, and a page the draft shapes (its subtitle, its questions) is its own file there rather than a link to the original, refreshed from the original every session so the two never drift; the live mirror is the exact versions the Author approved, which keep being served until a newer version is approved, so drafting over a live page never takes it down. What the draft would add to, change in or take out of the live mirror is what waits for the yes below.

Earning trust

The yes never moves, and it always sees the exact words going out. Trust comes from making that yes quick and earned, so over time the drafts need fewer corrections and the Author's attention goes straight to what changed.

  1. The floor check runs first. scripts/mirror_check.py reads every outgoing draft for what must never leave at any layer: contact details, street addresses, private paths, keys, card and bank numbers, dated quotes from a session, and anything on the Author's own never list, files/library/never.txt (outside every layer folder, so it never publishes). permission.sh approve refuses a flagged draft until the Author removes the line, adds that exact text to the never list as an allow: line, or overrides once on purpose. A clean check is a floor, never consent.
  2. Lead with the change, and always show the exact text. For a page already published, the Author sees first what is new or different and for which audience, then every changed passage word for word as it will go out, in place. A summary can introduce the change, never stand in for it. A new page is shown whole.
  3. Corrections become the filter. When the Author edits, cuts or refuses a draft, rewrite the passage of their filter that would have caught it, in the same turn, and say so. A private name they cut goes on the never list. The next draft should not need the same correction.
  4. The track record sets where attention goes. The filter keeps one line per layer: the last correction and how many changes have passed as drafted since. Right after a correction, put that layer's changes first and point at the passages most like the one corrected. The record changes order and emphasis only, never whether the exact text is shown and never whether the yes is needed.
  5. One list, one yes. Everything the draft would add, change or take out of the live mirror waits together and is offered once, on the mirror line when the alexandria skill opens, as a list of exact versions with one yes for that list. The Author may take some and leave the rest, and what they leave out teaches the filter (step 3); a page that carries both is redrafted with only what they took and shown again before its yes.

A layer that ships on its own

Once the Author trusts the filter for a layer, they can let that layer ship without a yes per change: permission.sh grant library-auto-<layer> (public, member, invite, paid or market), their own step outside the model's reach, like every grant. From then on, at each session start, the hook approves every plain file in that layer's folder at its current bytes when the floor check has nothing to say, and the mirror line names what went out since the last session (permission.sh status lists it), so the Author still sees every change, after it rather than before. A link to a file elsewhere never ships this way. The layer goes back to asking, and stays there until the Author turns it on again, when the floor check flags a draft or cannot run, and whenever the Author corrects, cuts or refuses something in that layer: the model deletes system/permissions/library-auto-<layer> in the same turn, which stops it at once, and says so, along with the plain fact that what already went out was seen. Every other layer, and every layer by default, waits for the yes above. The risk is the Author's to take and the reason the switch is theirs alone: a model that was tricked by text it read, or has drifted, would publish into that layer on its own, and a published copy cannot be taken back.