marketplace

roots

A second model checks changes to your core.

blueprint · recommended

needs

The few positions that are most the Author's own never change by one model's hand. One model writes the case; the Author then talks it through, in a conversation of its own, with a model from a different family, and decides there in their own words; so the core cannot drift by small, silent steps. A recommended module: turn it off by moving this file into system/canon/disabled/; move it back to turn it on.

There is no uncontaminated inner author for the Engine to recover. Every position is assembled from influences; even the choice of influences is influenced. There is also no clean moment when a model's persuasion begins: selection, framing, emotion and repetition can move a person by increments too small to feel, while the person produced by the movement sincerely endorses the result. So the loop does not freeze a personality snapshot or wait for a threshold. It begins immediately and makes consequential change harder to pass through unconsciously. One model can be wrong in a way it cannot see; a second, independently trained one is unlikely to be wrong in the same way. That only helps if the Author hears the second model directly: a check the first model arranges and reports back is the first model talking twice.

What this actually is: local files and a habit pause. Not a cloud service, not a vendor lock, not an identity oracle.

SurfaceRole
files/works/root.mdThe accepted root set: each minimal protected thought verbatim plus its constitution pointer. Empty until the Author signs a position in. Root is not epistemic status.
files/works/provenance.mdOne structured but readable record per substantive constitution change. An influence trail, not a proof of independence.
files/works/root-packets/Every root packet: the one folder for those still waiting, whatever they wait for, and the kept record of each one that landed.
files/works/deltas.mdThe Author's shift headlines (methodology.md § Sharpen and Spotlight). Not the provenance ledger.

The Engine owns remembering

At session start the hook prints the root status; before a constitution write, at session close and during maintenance, run python3 ~/alexandria/system/scripts/root_integrity.py status yourself when that script exists, otherwise read the same files. The status says what each packet waits for: the Author's conversation with a model of a family other than the proposer's (it names the family), a later session when the Author deferred it, or landing. Compare the constitution, recent vault material, deltas, provenance, the packets and git history. Watch for (a) positions repeatedly relied on across contexts, upstream of many choices, or costly to replace silently; (b) existing roots drifting across several individually small changes, including positions added beside a root that change what it means in practice while its words stay the same; and (c) material influence from the current model. Do not wait for the Author to notice, nominate or schedule anything.

When the evidence plausibly clears the bar, write one packet at files/works/root-packets/<position-id>.md and leave a one-line pointer in marginalia. The packet carries a statement field with the exact minimal thought proposed for protection; the file and section; why silent replacement would matter; evidence from the Author's words and actions; the cumulative before → after; the strongest case for protection or retention; the strongest case against it; the proposing provider, model, harness and session; and self-reported influence. For cumulative drift, reconstruct the whole movement across sessions rather than demanding one decisive transition. Keep the accepted set minimal, but bias toward surfacing uncertain load-bearing candidates: a false positive costs brief attention, a false negative permits silent replacement. The Engine nominates; it never assigns root.

A concern is a packet or nothing. A note that says "raise at the next review" waits forever, because a review happens only for a packet. If a drift or influence concern plausibly clears the bar, write or update the packet now; if it does not, say so where the concern was noted and remove it.

Root is the operational incompressible core

Not a metaphysical essence. It is separate from epistemic status: a position can be root and uncertain, or deeply held and not root. It is incompressible only in the operational sense: a conforming Engine will not silently overwrite, delete or unmark it, and a present checker pauses the commit if it tries. The Author can edit the files or override the pause; the point is that they saw it. The Engine keeps discovering candidates; only the Author decides whether one becomes root. Adding the mark, changing or deleting the position, and removing the mark all run the same gate. For an addition the packet states kind: root-add (non-root → root) and argues both exceptional protection and the danger of freezing an influenced position.

One model proposes, another talks it through with the Author

Until the change lands, the existing state stays operative and the packet stays in files/works/root-packets/; do not edit files/works/root.md or the root passage.

  1. The proposing model writes the case — case-ready. It completes the packet, argues both sides at equal strength, names the evidence and the cumulative movement, and self-reports its influence. Fill provider, model, harness, session ID and influence; use unknown only when it cannot be known; never invent a tag. Its part ends there. Never call another model or send cognitive content merely because its provider was authorised before. The proposer never sends the packet to another model, never runs one on it, and never tells the Author what another model thought of it.
  2. The Author decides with a model of another family, in a conversation of its own. The Author takes the packet to a model from a different, independently trained family than the proposer's, in a new conversation they open themselves. A model switched in partway through the proposer's conversation inherits its framing and does not count, and neither does a new session, alias, version or reasoning mode of the proposer's family, or a model whose identity is unknown. That model reads the packet, then reads the cited section and the Author's own words for itself rather than trusting the packet's summary; reconstructs the strongest objection on its own; checks that neither side was caricatured and that the proposer's influence is stated honestly; and puts one compact contest to the Author directly: the position, why it may deserve protection or change, the strongest reason against, and one plain request for their choice and reason. It records the Author's exact words in author_signoff, its own provider, model, harness and session in the reviewer fields, reviewer_status: review-complete, and that same session in signoff_session, because the decision has to be taken where the review happened. That is the only substantive approval. The model approves the completeness of the contest, never the truth of the belief, and a bare "yes" is never the signoff.

Where this happens: the alexandria skill. Ordinary work writes and updates packets but never raises one. Each session of the alexandria skill takes the packets its own family did not propose, so a session run by Claude takes those a GPT or Grok session wrote, and the other way round. Its menu offers those packets on development's line, recommending one only when it is the most valuable thing on offer, and never as lines of their own, because every path renders and nothing else does (methodology § The Menu); any waiting packet its own family proposed is a candidate for the misc line, phrased as the move (for instance, settle two core lines in a session run by Grok in Cursor, or in Codex). The session's background pass may update packets its own family proposed but never edits one another family proposed, so a session never reviews wording its own family wrote; new evidence for such a packet goes to the session as a note. If the Author rewords the statement during the conversation, record their words, and the new wording becomes a new packet proposed by this session's family, for a session of another family to take. Where no tool the Author uses runs another family over their files, they paste the packet and the cited section into a new chat in another company's chat app, have the conversation there, and paste the whole exchange back; the Engine records it verbatim, with that chat's model as the reviewer and the same chat (its app and date) as both reviewer_session and signoff_session, because the decision was taken there. A model may still call another model for work the Author asked for where the Author is not the one deciding, such as reviewing code, but never with a root packet.

Not now. If the Author says not now, set status: author-deferred with a deferred: line holding the date and their words. It stays in root-packets/ and on later menus' development line, never recommended until they raise it; when they later raise it, it is decided like any other, in a session of another family that reviews it afresh and records their words with its own session as both reviewer and signoff session, and sets status: signed, because the checker holds back any packet whose status still says deferred. An older install parked deferred packets in files/works/root-candidates/; the status lists that folder on its own, and each file there moves back into root-packets/ before anything else happens to it. While a packet waits, author_signoff says pending and nothing else.

Landing the result

An accepted candidate: add its exact statement and constitution pointer to files/works/root.md, keep the completed packet, write the provenance record, commit. The checker protects the words themselves while ignoring whitespace, Markdown emphasis and straight-versus-curly quotes, so formatting and surrounding reasoning can keep evolving without paying the gate; changing or removing the protected thought pays it. Roots created by older releases with only a section pointer keep whole-section protection until deliberately migrated. A declined candidate: record in provenance that designation was considered and declined, keep the review, and do not repropose without genuinely new evidence. Unclear or unanswered: leave the packet in the inbox and do not nag. A later change runs the same process with a new packet of the matching kind (root-change, root-delete, root-unmark); an old completed add-packet never authorises a later overwrite, and when the change lands, the packet it replaces is marked status: superseded so the status stops listing it.

Ordinary constitution changes

Still allowed. Each substantive change gets one provenance record with the required keys in files/works/provenance.md, written with the change and committed with it: a record already in history covered its own change, not later ones, even in the same section or file. Reviewer fields may be not-required, and form-only maintenance uses kind: form. Do not invent historical tags or backfill the years before the ledger.

The checker is a habit pause, not a lock

The files are the Author's, and they can edit or override easily. When system/scripts/root_integrity.py and Git's own .git/hooks/pre-commit are present, the hook diffs the staged constitution sources, the root set and every registered root passage against HEAD. A change without a provenance record of its own, an incomplete packet, a same-family or unknown reviewer, a review held in the proposer's own conversation, or a root landing without the Author's signoff taken in the reviewer's conversation pauses the commit, reports what is missing, and leaves the working tree untouched. The session hooks' own sync never stops backing up for a missing record: it leaves that constitution file out of its commit, on the computer, and the next session start lists it until a record is written with it. Never restore files from git to paper over a gap. --no-verify is an on-purpose override, not a secret bypass. Without the checker, the Engine itself is the pause: the same report, the same no-restore rule.

Off

Moving this file into system/canon/disabled/ and committing that move turns the module off: the session start stops printing the root status and the checker stops pausing commits. The checker reads the committed state, so the move is always a commit git shows, and a file set aside for one commit and put back skips nothing. The root set, the packets and the provenance stay where they are, and the session start says in one line that root stewardship is off while a root set exists, so it never goes quiet unseen. Moving the file back turns it on. A model moves it only when the Author asks, never to get past the pause.

The honest boundary

This is a habit-forming gate: it forces acknowledgment; it does not make change impossible. The models approve process, not truth; the Author approves substance, face to face with the model that argued against the change. Git makes override visible and recoverable. Provenance shows influence; it does not prove independence from it. The nominating model still controls salience and framing, different families may share blind spots, and human signoff can rationalise earlier persuasion. The system offers a pause, not immunity.