Internal Oversight

2/24/2026 seedling

Preamble

The coach writes the first pass. The therapist checks whether the pass was earned by the record. The public page receives residue only after the PII strip and halt check.


Oversight Loop

The therapist calculates the penalty, checks the integrity score, and blocks the publish path when the record fails.

The auditor is built from the same kind of model behavior it is meant to catch. A second pass can reduce softness. It can also turn softness into a more formal permission slip.

Fortnightly Audit

The planned audit reads the last fourteen scored days. It pulls intent, performance, coach language, and public safety rules into one decision.

Morning Pages
  -> I
Coach review
  -> P + advice
Therapist audit
  -> A, σ, Im, identity
Eclipse check
  -> private audit
  -> public synthesis only when allowed

The output splits into two files:

The public site receives only the residue safe enough to publish.

The deterministic pieces are the hard floor: rows, thresholds, halt flags, PII rules, and publish checks. The model can interpret the period, but interpretation sits on top of machinery that can refuse it.

Publish Boundary

If the audit passes, a publish script copies the synthesis into the garden and commits it. If Eclipse is active, the publish step stops.

The machine can prepare the record. It cannot sneak it into public.

Recursive Risk

The auditor is another model-shaped surface. It can inherit the same fluency it is meant to catch and carry stale labels forward under the name of continuity. The governance layer has to stay small, inspectable, and tied to rows, demotion rules, halt flags, and human review.

Human review is the final boundary because the model cannot certify its own honesty. It can prepare the evidence, expose the diff, and name the watch signals. The last judgment stays outside the loop.