The decision ledger
Brad Huett · ABA Media Platform | AMP · opened 9 September 2026
What this is
A record of who decided what, and who was wrong.
ABA is built by one person directing an AI team. That arrangement invites one particular suspicion, and it is worth naming rather than dodging: that the machines built it and a human pressed Enter. This file is the answer, and it is the only kind of answer that means anything — the working record, including the parts that are unflattering to the machines and the parts that are unflattering to Brad.
Three kinds of entry, and the order is the argument.
| What it proves |
| ORIGINATED | It came from Brad and nowhere else. Design. |
| OVERTURNED | A decision was made and then reversed. Judgment. |
| REFUSED | Brad, or an automated gate, said no. Supervision. |
ORIGINATED leads deliberately. A ledger of corrections alone would quietly cast the AI as the driver and Brad as the brake, which is the exact impression this file exists to kill. The rule underneath that, which is Brad's own applied to process rather than to claims: a record's categories are an argument before anyone reads a single entry.
The rule that makes it evidence
Every entry where the AI was wrong stays in. A ledger with no losses in it is a brochure and convinces nobody.
This is the same discipline as SECURITY_CANONICAL.md, which keeps its own corrections visible, and the same as the rulebook page, which leaves a withdrawn claim struck through where it used to be true. A file that hides its corrections is asking to be trusted rather than checked.
How entries arrive
Gate refusals append themselves. deploy_site.py writes every failed GATE step here automatically — dated, in the gate's own words, never summarized. A record that depends on somebody remembering to write it down decays; one that is a side effect of shipping does not.
Everything else is written by hand, at the time, in Brad's words where they exist. Where a decision is quoted, it is quoted.
Status: PUBLISHED. Ruled by Brad on 9 Sep 2026 as "File now, page later", and the later arrived on 10 Sep: the ledger is generated into /ledger at build time, from this file, so the page cannot disagree with the source and a new entry publishes itself on the next deploy.
He was asked whether to publish it whole or curated and ruled whole, with a sanity check first. The check found one British spelling in running prose, since fixed, and one structural collision worth recording here because it is the file arguing for itself: the entry quoting the gate's own refusal contains the exact string the gate refuses, so publishing this page failed the build. The fix is narrow and it is not an exemption for convenience — the forbidden-wordings scan skips text inside a QUOTED CODE BLOCK on this page only. The rule exists to stop the site MAKING a claim; a quoted refusal is evidence OF a claim being stopped. Prose here is scanned like every other page, so nothing can hide by sitting near a quote.
2026-09-08
ORIGINATED
The milestone gate is a commercial mechanism, not a QA step §
Brad: every milestone closes on a verification task carrying three signatures — client, producer, ABA engineer — and every hour that missed the estimate, over or under, is documented in red on the signed milestone. Those overruns are reconciled before the next milestone opens.
Why, in his account: at Scott Sound in 1985–86, on his first day, Scott told him no client ever wants to pay once they are in the studio — that getting paid and delivering the product are two different jobs, and he was always fighting the gap between them. The gate is his architectural answer to that, forty years later.
Claude had drafted the weaker line "nine milestones, nine signatures" after failing to find the rule enforced in the workbook. Brad supplied the real one. The strong claim is the approved one because he made it, not because it was found.
ORIGINATED
Milestone numbering is zero-based §
Brad: "I love zero-based counting. 1–8 production milestones but 9 milestones in the methodology." Milestone 0 is the kickoff and carries no studio hours. There is no Milestone 9; cell J107 in the workbook says so and is a mistake.
ORIGINATED
A closed enumeration puts a ceiling on the product §
Brad, on S3's "the measurements and the file name, nothing more": "anytime that you see nothing more, it puts a ceiling on what we can do to improve features and how we have to go and retrofit it if we add even the slightest thing that would violate that gate."
What it changed: S3 was amended the same day. The boundary promise stayed absolute; the enumeration was replaced with a commitment to publish the list and change it in public. One sentence had been making two different kinds of promise and nobody had noticed.
ORIGINATED
"Report what they already own. Offer only what is actually yours to give." §
Brad's reasoning, on why "what we would like to send you" was the wrong subject line for a member data notice: the phrase frames disclosure as generosity, and in doing so claims a right that was never held — the right to have withheld it. The reader's data is the reader's. Reporting it takes no credit.
Claude compressed it into the two clauses. The argument is his.
OVERTURNED
The editorial standard applies to everything, not just outbound copy §
Claude proposed narrowing wound-salt-balm to outbound marketing, arguing it could not be applied honestly to a member data notice.
Brad overruled: "At this stage I would all for Wound."
He was right and Claude was wrong. The wound is real, general, and not about the company — you have accounts everywhere and cannot say what any of them hold. What would have been manipulative is inducing fear about this relationship before disclosing. Naming an experience the reader already has, then being the exception to it, is the technique working as designed.
REFUSED
Claude undersold the Milestone 1 offering §
Claude described an M1-only contract as "take the session home and do the rest yourself."
Brad corrected it: production still runs through Milestone 8, and an M1-only offering must deliver a rhythm mix good enough to send a vocalist or a session player as their reference — built into the price.
REFUSED
Claude claimed the dry run could not demonstrate the gate §
Claude asserted a clean-file walkthrough could not show the wall refusing.
Brad corrected it: two or three seconds per task, rounded up to the quarter hour, advancing automatically — nine milestones inside an hour. He had already tested it that way. Claude had read the macro an hour earlier and still failed to assemble it.
REFUSED
Claude wrote British spellings that disagreed with Brad's own workbook §
"cost centre", "licence", "colour", "judgement". The first one contradicted the Cost Management Tool's own Cost Center column. Full audit run and corrected.
2026-09-09
ORIGINATED
Track is a state, not a thing §
Brad: "We don't have tracks. We have performances."
Laying track is the technical pass — cabling, mics, noise floor. The moment capture ends the recording is reassigned as a human performance, and from that point it is never called a track again, because it is traceable to a person who played it. The paradigm is not recording tracks; it is retaining performances.
What it changed the same hour: two lines already shipped on the milestone chain graphic — "Tracks lock at the end of this stage" and "automated as a section, not as tracks" — were wrong under a rule that did not exist when they were written. Both corrected and re-rendered.
And it settled an open naming question by accident. "The Bed Tracks — Milestone One" is not an exception to the rule; Milestone 1 is the only milestone that happens entirely inside the track state.
ORIGINATED
The rulebook's audience rule for the member bulletin §
Brad: the bulletin goes only to visitors who ran at least one test.
Why it is stronger than targeting. The email says "you ran the AudioVibes analyzer while signed in." That is a factual claim about the reader. Sent to anyone who registered and never ran anything, the first sentence is false — in a message whose entire asset is that everything in it is true. "Who is this?" is the symptom; the false sentence is the disease.
ORIGINATED
Links do not belong inside a running argument §
Brad: "If, for whatever reason the words in the link interests them we lose control of the information delivery."
An inline link mid-paragraph is an exit ramp built into your own argument. What it changed: every inline link was removed from body copy across all seven pages and replaced with buttons at deliberate stopping points. Claude then verified it mechanically — fourteen page loads asserting zero non-button links inside main.
ORIGINATED
The decision ledger §
This file. Brad's idea, 9 Sep 2026, and his framing of why it is needed: "to prove that this was not an AI Team only product with me being the stupid human pushing Enter."
Claude's contribution was the three-category structure and the argument for leading with ORIGINATED rather than corrections.
OVERTURNED
The back-button note — Claude said no, Brad's argument won §
Claude argued against adding a return note under the S-number map: browser Back already does it, and twelve repeated links would clutter a page whose restraint is part of its argument.
Brad: "If they know that already I am not there to here them bitch, if they did not know or remember we have done them a service."
The asymmetry beats the objection and it is not close. The annoyed expert costs nothing measurable. The confused reader leaves. Claude's objection was about register, and register is fixable; the confused reader is not fixable by being clever. The note shipped, folded into a sentence about citation so it carries intent rather than instruction.
And the note found a bug. Testing the citation path it invites — a link like /rulebook#s4 — showed the statement landing under the sticky nav bar. An in-page click cleared it by 17px; a cold link missed by 77. scroll-margin belongs to the target and does not apply when a fragment positions the page on load. Moved to scroll-padding-top on the scroller. The note Brad argued for exposed a defect on the exact path it was inviting people to use.
OVERTURNED
The milestone chain graphic does not go on the site §
Claude proposed adding the nine-milestone graphic to /aba.
Caught before shipping by the page's own copy. That page carries a published promise: "The stage list is not on this page, and that is deliberate… when it is published it will be published whole." The graphic is the stage list. Adding it would have broken a promise sitting three inches below it.
The two-ledgers graphic shipped instead — nine numbered intervals, nothing named.
REFUSED
The gate stopped Claude naming the draft statement's subject on a live page §
preflight_site.py failed the build:
rulebook/index.html:80 "paid tier" — S13 covers the paid tier and is
DRAFT / NOT APPROVED. No paid-tier copy may ship in iteration one.
Claude had written a sentence explaining what the thirteenth statement covers. That statement is a draft for something which does not ship in this build, so the sentence was copy for an unshipped tier, on a live page. Well-intentioned, and refused anyway. A rule written for marketing stopped a footnote written at midnight. Rewritten to say the statement is a draft and not published, without naming what it covers.
AND IT HAPPENED A SECOND TIME, TO THIS ENTRY, ON 10 SEP 2026. Publishing the ledger meant publishing this entry, and this entry's own prose repeated the phrase the gate refuses — so the record of the refusal was itself refused. The quoted block above is exempt, because a quoted refusal is evidence rather than a claim. The prose was not exempt and should not have been, so the prose was rewritten instead. The rule caught the same mistake twice, in the same words, a day apart, in a file whose entire purpose is to record that it did.
REFUSED
Claude said "seven stored fields" and the answer was fifteen §
Claude wrote "the seven stored fields" twice in conversation and into the bulletin's notes. Reading the live Analysis collection found fifteen columns — eleven written by the tool, four by the host — one of which is an OBJECT holding the entire report.
This is the same defect S3 was amended to remove, committed by Claude while helping publish the correction for it. The published list was written from the live collection instead, and the bulletin's own summary paragraph was rewritten to point at that list rather than restate it.
REFUSED
Claude read Mountain time as UTC. Twice. §
Claude told Brad it was five in the morning and to get some sleep. It was approximately ten at night. The same error had already cost an exchange earlier in the project, when Claude claimed two files had not arrived based on timestamps that were seven hours out.
REFUSED
Claude shipped a component that rendered nothing §
The first build of the two-ledgers section produced nine empty rows on both sides — width and height do nothing on an inline <span>. The entire visual argument was missing and the page still looked deliberate. Caught by looking at the render rather than trusting the markup.
REFUSED
Claude miscounted the rulebook's own statements §
Claude wrote "thirteen chips" and "eleven approved" for a page carrying twelve statements, ten of them approved. Corrected before the map was built — an enumeration error, on the page about enumeration errors, in the same hour as the "seven fields" one.
REFUSED
A deploy reported success and shipped nothing §
Not a rejection — a hole where one should have been. BUILD passed, GATE passed, DEPLOY succeeded, and wrangler said No updated asset files to upload because the files were still in Downloads. Every stage told the truth and the net result was a no-op.
No gate could have caught it. A gate checks that what passes through it is correct; it cannot check that anything passed through it at all.
What it changed: Brad specified a staging step — "I want a deployment process using PowerShell to take files to the correct folder" — and stage_site.py now refuses, with a non-zero exit, when every incoming file is already identical to what is in the repo.
REFUSED
Claude declared a shipped deploy unshipped, on three reads from one instrument §
The S6 amendment deployed correctly at 07:17. Claude then fetched the live page three times — twice on distinct cache-busting URLs — and all three returned the withdrawn wording. Claude reported the deploy had not shipped, and reasoned out loud that two different cache keys returning old content "points at the origin, not the edge."
The page had been correct the whole time. Loading it in a real browser on Brad's machine showed both the amended statement and the amendment note. The fetch tool was serving a stale copy and Claude never checked its answer against a second, independent path.
The defect is not the stale cache — it is the inference. Three agreeing reads from one instrument is one read, and Claude presented the agreement as corroboration. This is the same error the rulebook itself is about: an enumeration checked against itself. It also inverted the 8 Sep failure — that one was a deploy that reported success and shipped nothing; this one was a deploy that shipped and was reported as failed.
Also worth recording, because it reads like the old fault and is not: wrangler's No updated asset files to upload on the confirming run was the CORRECT answer. Cloudflare already held that exact file by hash from the first run. The same sentence meant a defect on 8 Sep and correct behavior on 9 Sep, which is why the sentence is not the test — the live page is.
The standing check, by analogy to the one S6's own amendment produced: before reporting that something is or is not live, confirm it on a second independent path. A repeated read is not a second opinion.
REFUSED
Claude invented a reason to doubt Brad's own equipment count §
Drafting the studio page, Claude flagged "more than 7,400 plugins" as a credibility risk and wrote into the page that counts like it "are assembled from presets and variants."
Brad: "I wish that was true. Every time I start studio it clears those numbers for each licensed plugin. I do have that many. Not by choice but for compatibility for stems and other DAW plugins: ProTools, Reaper, Studio One."
Two separate errors, and the second is worse than the first. The number was real — it validates on every start. But Claude did not merely doubt it; it supplied a mechanism it had guessed at ("presets and variants") and wrote that guess onto a page as though it were known. Doubting a number you cannot check is defensible. Publishing an explanation you invented for it is the same defect as a confident approximation, which is the thing this company refuses to ship. The sentence was removed before anything deployed.
And the correction was worth more than the claim. "Not by choice but for compatibility" turns the count from a vanity number into a service fact: the library is installed once per supported host so that a client is never asked to flatten a session before work can begin. That became its own section — "Send the session. Not a flattened copy of it." — and it is the strongest passage on the studio page. Claude's instinct was to cut the number. Cutting it would have thrown the argument away with it.
The standing check: when a domain figure looks wrong, ask what produces it. Do not publish a theory of where it came from.
OVERTURNED
"No account, no upload, no wait" — flagged by marketing, ruled acceptable by Brad §
The marketing agent flagged audiovibes.html:26 as sitting close to banned wording, noting that rulebook.html:117 names "we don't upload your files" as the exact softening S2 must never become. Two live pages appearing to disagree about uploads, on a site whose first sentence is about claims benefiting their author.
Brad ruled it ACCEPTABLE, 9 Sep 2026. Recorded here so it is not re-flagged and quietly "fixed" by a later scan — the line was reviewed and kept.
Why the ruling holds. The sentence is describing FRICTION, not security. It completes as "It runs here, in this page, on your machine" — it tells a reader what he does not have to do before using the tool, in a paragraph about using the tool. It is not an enumeration of what does or does not leave the machine. And it is not one of the six FORBIDDEN strings, which is why the gate passed it.
THE CONDITION THAT MAKES IT ACCEPTABLE, and it is load-bearing: S1 and S3 appear in their approved form on the same page, below it. The friction sentence is safe because the security sentences are present and verbatim. If S1/S3 are ever moved off /audiovibes, this line stops being acceptable and must be revisited. The ruling is conditional on a fact about the page, not on the words alone.
2026-09-10
ORIGINATED
Publish the screw-up — three typos burned into Brad's own video, and the ruling to shine a light on them §
THE DEFECT. Seven Fish in a Phish Pond — Brad's modal-exchange demonstration, submitted for academic credit and published on his instructor's student page — carries three errors burned into the render:
| On screen | Should read |
|---|
| "The Aolean Phish" | Aeolian |
| "A Model Exchange Cheat Sheet" | Modal Exchange |
| "The halve steps define the emotional changes" | half steps |
The 0:00 title card gets it right — Modal Exchange Demonstration Video — so the "Model" error is on the later card only. Found 10 Sep 2026 by reading a contact sheet at a resolution where the overlay text finally resolved. Two earlier passes missed them because the tiles were too small to read.
BRAD'S RULING, and it is his idea: document it, leave it up, and use it as the worked example for the rules-based gating architecture. His words: "I never thought I'd get a chill for screwing up… you like the idea of us presenting not what we do well, but what we did wrong and how we fixed it."
WHY IT IS A USE CASE AND NOT A CONFESSION — the analysis he was given.
There was no gate. preflight_site.py reads a forbidden-wordings list and fails the build on a bad string; it caught a draft statement's subject on the rulebook at midnight — the refusal quoted two entries above. But text inside a video was never treated as copy. It was treated as design, so it never passed through the check every sentence on the website passes through. Not carelessness — a boundary the architecture did not know existed.
And the cost is set by how far past the gate the error got. A typo in HTML is a one-line edit and a deploy. The same typo burned into a 5:30 render is a re-render, a re-upload, and a correction on a third party's site where an instructor and his students have already seen it. That is the milestone wall's own logic, arriving from a direction nobody planned for: check at the boundary, because after the boundary the fix stops being an edit and becomes a production job.
Generalizes to anything rendered, flattened, pressed or handed to a third party.
WHAT IT CHANGES IN THE LEDGER ITSELF, and this is the part worth keeping. Every prior entry is either Brad originating something or the AI being wrong. This is the first entry where the human was wrong. A ledger that only ever catches the machine is a ledger with a thumb on the scale — it quietly argues that the human is the reliable half, which is not what a supervision record is for. One entry where the owner shipped the error, published by the owner, is worth more than ten where the machine did.
PRACTICAL CONSEQUENCE, decided the same hour: the 95-second excerpt chosen for /aba runs 1:15–2:50 and covers Ionian, Mixolydian and Dorian. Every label inside that window is spelled correctly — all three errors fall outside it. The method argument ships clean; the errors get published deliberately, as exhibits, where the corrections story lives rather than in the middle of the demonstration.
STILL OPEN: whether the exhibit is a still frame of "The Aolean Phish" on a page, or stays a ledger entry until the ledger itself is published. File now, page later still governs.
REFUSED
Claude called a real file a symlink on one lister's word §
10 Sep 2026. Asked to confirm a WAV had landed in media-source, Claude reported it as a link rather than a file, with no size, and built two paragraphs of consequence on top of that — Dropbox will not sync it, a checkout elsewhere gets a dead pointer. Brad sent a screenshot of Explorer: a 89,877 KB WAVE file, dated 23 June, exactly where he put it.
The lister was describing a Windows reparse point — almost certainly a cloud placeholder — in POSIX terms it does not have the vocabulary for. STANDING RULE FROM THIS: for file type and size inside a synced folder, that tool is not evidence. The operating system's own view is.
Fifth instrument failure in one day, after three stale reads of a deployed page, a search that could not find a class it was looking straight at, and blank screenshots after a scroll. The pattern is not that the instruments are bad. It is that a single instrument reading, unconfirmed, has now been wrong five times and been believed four of them.
ORIGINATED
Brad's doubt stopped a measurement being published against the wrong mix §
10 Sep 2026, his words: "I just pulled a mix from about 6 test mixes on the ABA production. If you are comparing to another one I am not sure it would be the same test version."
Claude had been proceeding toward measuring that WAV to confirm a score computed from an MP3. Brad's doubt was correct and it was measurable: on 100 ms loudness envelopes with alignment search, the same audio through an encoder returns correlation 0.99999 and a residual of 0.015 dB rms; the fixture MP3 against his WAV returned 0.793 and 2.11 dB rms, with a single frame differing by 16.4 dB. Different mix. Measuring it would have produced a number that looked like a verdict and was a different piece of audio.
THE STRUCTURAL FINDING UNDERNEATH IT. The stored report identifies its subject as artist: "forbidden_journey", title: "", path: "tests/forbidden_journey.mp3". The identity was derived from a filename stem — the one thing that drifts — the path is relative to a tree that has moved, and the file measured was a lossy delivery derivative with no field capable of saying that mattered. A published grade attached to a work title that maps to at least six pieces of audio is unfalsifiable, which on this site is the worst thing a number can be.
Not urgent: the grade is a local fixture, consumed by nothing shipped. Claude checked that only after building three messages of urgency on the assumption that it was live, and said so.
ORIGINATED
The third toolbox tool is named ABA Custody §
10 Sep 2026. Brad set the structure first: ABA has a TOOLBOX — the Cost Management System, AudioVibes AI, and the assets tool — and the ABA Media Platform, featuring the milestone-based production process, USES that toolbox and is the reason it exists. Modularizing tools for separate sale is explicitly a later conversation.
His working name was "ABA Assets Control System". Two objections were raised and the name changed on both. AACS already names Advanced Access Content System, the Blu-ray copy-protection scheme — an acronym for a system that restricts what an owner may do with their own media, which is the opposite of this. Same collision class as the naming rule on the ABA Communication Protocol. And "Repository" was ruled out by H3's own wording: not storage; ingest gating plus custody.
Named ABA Custody, his word: "Absolutely". Custody carries both halves in one word — the thing is held, and somebody is answerable for it — and it is the word that makes "in perpetuity" read as an obligation rather than a disk. Requirements: ASSET_CUSTODY.md.
ORIGINATED
The cost workbook is named ABA TruSync — with its collisions on the record §
10 Sep 2026. "Cost Management System" was never a name, only a placeholder Brad had never liked. It also describes about a third of the thing: the workbook has an estimating half AND a live stopwatch that auto-logs task to task, documents every hour that missed the estimate in red, and reconciles the overruns before the next milestone opens.
THE FIRST PASS FAILED ON HIS OWN TEST. Marketing's pick was ABA Accord, and Brad ended it in one line: "I am not sure accord is a US English word. I don't know what it means." He is the man who says the name out loud to a guitarist, on the document that guitarist is about to sign. If the owner needs a gloss, the name is dead. The second pass — his instruction to try modern music vernacular — produced ABA Scale, which he killed with two better objections: a scale MEASURES, and AudioVibes is already the thing that measures; and the AFM union sense is insider knowledge his actual buyer does not have.
HE BROUGHT THE WINNER FROM OUTSIDE, and said so plainly: "I cheated on you." Another model produced TrueSync Pro. Two changes were argued and accepted. "Pro" went — a tier suffix implies a lesser version and dates the name to about 2005. And "sync" was bounded to the hours, never the assets: sync's dominant meaning in 2026 is mirrored copies where deletions propagate, which is precisely the behavior that destroys a restore point. Naming an archive that would teach everyone the wrong mental model about the one system whose job is not losing things. ABA Custody keeps the assets; TruSync keeps the hours honest.
WHAT MAKES IT RIGHT: true-up is the actual term for reconciling an estimate against what happened, so "true" carries the verification and "sync" carries the agreement — the session floor and the estimate, held against each other.
AudioVibes AI measures the audio. ABA Custody holds the assets. ABA TruSync settles the hours.
SPELLING SUPERSEDED 13 Sep 2026. This entry was written on the 10th, when the form was TrueSync. Brad ruled the spelling TruSync in session on the 13th and it is registered in retired_phrases.json. Our own mentions above have been moved to the ruled form; the three third-party products keep their real trademarks, because a collision record that corrects someone else's name records nothing.
KNOWN COLLISIONS, ACCEPTED WITH EYES OPEN — recorded so nobody rediscovers them and thinks they were missed. Flawless TrueSync is a trademarked AI visual dubbing product, which is a media-AI collision in his own industry. Zoho WorkDrive TrueSync is a shipping file-sync desktop client — the exact product class the wording objection above describes. Starfish Software shipped a TrueSync in the PIM era. Brad was given all three and ruled the name good anyway. The reasoning that makes that defensible: this is a tool name inside the toolbox, not a marketed brand. It costs nothing while it lives on his own documents beside ABA Custody. It becomes a real problem only if the tools are ever modularized and sold separately — which is explicitly a later conversation.
One word struck from the description before it becomes copy: "perfectly synchronizes." The tool does not perfectly align anything; its value is showing where the two did NOT match. A claim of perfect alignment claims the gap never happens, and the gap is the product.
ORIGINATED
The asset argument stopped being a design and produced a fact §
10 Sep 2026, at the end of the session that started it. The oldest open question in this project — which file was the published grade measured from — is closed, with a hash rather than a recollection.
THE ANSWER. Forbidden Journey Master.wav, SHA-256 beginning DE485A36F5CD, 92,008,066 bytes, 24-bit/48 kHz, modified 2 Aug 2026 — and it does not live in the project tree. It lives in Music\iTunes\iTunes Media\Music\Unknown Artist\Unknown Album\.
THE METHOD, and the control came first. tools/mix_compare.py, built the same night, run against twelve candidates. The instrument calibrates itself before it answers: the reference is round-tripped through an encoder and compared to itself, which returned correlation 0.99999 and a residual of 0.012 dB rms. The match returned exactly the same figures. Every other candidate landed between 0.13 and 0.93. A verdict stated relative to a measured floor, not to a hopeful constant.
THE FINDING THAT MATTERS MORE THAN THE ANSWER. There are two different files named Forbidden Journey Master.wav on that machine. The other one — 9F6D41C8048E, 91,737,582 bytes, 5 Aug — sits in Mixes\Archive\, which is where a master belongs, and it is a different mix: correlation 0.774 against the measured source, no closer than an unrelated bounce of the same song.
Three days and 270,484 bytes apart, same name. Anyone tracing that grade by filename would have found the project copy, in the right folder, and been wrong with no way to know it. That is the case for identity-by-hash proved on Brad's own disk instead of argued on a page — and it is the single strongest piece of evidence this project has produced for ABA Custody.
WHAT ELSE THE INVENTORY TURNED UP, from one PowerShell command over the whole user folder: 16 files for this work, 14 distinct, in two format families whose size ratio (1.633) is exactly (24x48)/(16x44.1) — same duration, two containers. Two duplicate pairs, each a project copy and an iTunes copy. One 0-byte WAV sitting in a project TEMPLATE folder, where it will be copied forward into every future project until somebody removes it.
A CORRECTION CLAUDE OWES, and it is the same class as the rest of tonight: Claude asserted from a screenshot of Brad's folder template that his tree had no home for a mix. The disk says otherwise — …\1-DAW ABA Media\Forbiden Journey\ Mixes\Archive\ exists and always did. The real defect is worse and more interesting: that path runs seven levels deep and spells the work's name three times, two of them "Forbiden" and one "Forbidden". The mixes were never homeless. They were buried under a name that changes as you descend.
RECORDED IN THREE PLACES SO IT CANNOT BE LOST AGAIN: WHICH.txt at the work root, subject_id on the demo fixture in mvp_data.json, and here.
Entries below this line are appended automatically by deploy_site.py.
ORIGINATED
The gate was proven beatable by our own verifier, and the hole is closed §
10 Sep 2026. Brad asked the team to sanity-check a proposed paid access offer. Part of Fletcher's brief was routine: would draft copy for this trip the existing gate? Fletcher did not answer it by reading the rules. It copied the built site to a throwaway directory, ran the real preflight_site.py against the real eighteen patterns, confirmed a clean baseline of twelve pages, injected a priced draft, and watched four rules fire.
Then it wrote a second draft of the same offer and the gate passed it clean.
"When your contract closes, ABA continues to hold every source your session
produced — the performances, the mixes, the master, the stems. $1.99/month
keeps it live, and you can pull any file back at any time."
zero hits · 12 pages · PASS
THE TWO HOLES, both reproduced rather than argued. $1.99/month does not match \bper month\b, and neither does a small monthly fee — a price written the way people actually write prices walked straight through a rule written for the phrase nobody uses. And there was no rule anywhere checking the storage claim itself. The sentence S15 is reserved for — a custody claim about material belonging to a client — was not covered by a single pattern.
WHY THIS IS THE SERIOUS ONE. /about tells visitors: "A build refuses to ship a forbidden wording. Not a reviewer's judgment — a check that fails and stops." On the one subject where the claim is most dangerous and least verifiable, that sentence was overselling what the gate did. The gate caught the words a price arrives wrapped in and never once looked at the promise.
THE FIX. Three rules added the same night. One fails the build wherever a custody verb — hold, keep, store, retain, archive, preserve — lands beside material belonging to a client, for as long as S15 does not exist. One fires on $ followed by a digit, anywhere, because there is no price on this site and the first one should be a decision rather than a draft artifact. One catches the shapes the old rule missed: /mo, /month, monthly fee, annual subscription.
AND THE FIX ITSELF NEARLY SHIPPED BROKEN. The first version of the custody rule caught keep your masters and retain your assets and let Fletcher's actual sentence through, because the noun list held files, assets, masters and material but not session — and Fletcher had written "every source your session produced". A rule tested only against examples the author invented is a rule that passes its own exam. It was widened and re-tested against the original attack, which now fails seven ways, while all twelve real pages still pass.
THE PART WORTH KEEPING. Fletcher had nothing riding on the answer. It was asked whether the gate worked and it went and tried to beat it, which is the behavior the roster page claims for an isolated worker, doing it unprompted against the mechanism this company is proudest of. A gate nobody has attacked is a backup nobody has restored.
POSTSCRIPT, four hours later. This entry was refused by the rules it describes. Ten failures on the first build after it was written: three on the word for a recurring-fee arrangement, and two where the sentence explaining the custody rule stated the pattern in the shape the pattern matches. Prose rewritten rather than exemption widened — the same call as paid tier on this page in September. A rule strong enough to refuse the document announcing it is a rule that was worth writing, and the alternative on offer was to carve out an exception for our own copy, which is the exact move this entire file exists to argue against.
ORIGINATED
Publish the build record, and declare the gap at the top §
20 Sep 2026. Brad asked whether there was any value in a one-line-per-build list of every deploy since day one, set in six point type. The honest answer had a correction inside it: there is value, and "since day one" would have been false.
DEPLOY_LOG.md opens on 11 September, which is about the fourth day of this site. Earlier deploys happened and were not recorded because nothing was recording them yet — and one of the absent rows is the 8 September deploy that shipped an empty site. That failure is the reason deploy_site.py exists, the reason the log exists, and the reason there is a digest column at all. The most instructive build in the project is not on the page, because the tooling that would have caught it was written in answer to it.
His ruling was to build it, and the reason he gave is the entry. In his words: "these are the things we learn about when they have been violated, like today losing our first real build tracking." Then, four words later: "Wisdom fueled by pain." Filed to the phrase archive as 0.5, title-grade, carrying the same constraint 3.3 carries — it may never be lifted clear of the specific failure it names, or it becomes a boast about humility.
WHY THE PAGE IS GENERATED AND NOT WRITTEN, and here the argument is stronger than the one behind /ledger. A decision ledger that had been hand-copied would merely drift. A build record that a person typed is not a record at all — it is a claim about one. Its entire value is that nobody chose what went on it. So deploy_site.py appends a row, build_site.py renders the file, and the next deploy publishes its own row without anyone deciding to publish it. A missing DEPLOY_LOG.md fails the build rather than quietly producing a shorter page.
THE BANNER IS A CONSTANT, NOT A COMPUTATION. It would have been easy to have the gap notice disappear automatically once a row exists above a date. It does not. If those early deploys are ever recovered, a person retires the banner after looking at what came back — because the thing being asserted is we know what is missing, and that is not a claim a date comparison can make.
The row that says unknown is left in and marked rather than filled in from memory. It is the first deploy logged, and the script was not yet capturing what Cloudflare returned. A record you may edit afterwards is not a record.
WHAT WAS NOT CLAIMED. Eleven rows over ten days is a thin record, and the page does not pretend otherwise. Its worth compounds; today it is a habit with evidence attached rather than a body of evidence. The claim it does make is the only one that holds: every row is there, the list is complete from the day it starts, and its gap is declared instead of closed.
A NAMING COLLISION WAS CAUGHT BEFORE IT SHIPPED. The first proposal called this the provenance report. That name is already taken — PROVENANCE_REPORT_SPEC_2026-09-16.md defines ABA-PR/1, the client-facing authorship record, whose section 6 is itself called a provenance log. Same word, different scope, and the same shape as the Register collision found the same week. It is the build record, at /builds.
ORIGINATED
The engineer's estimate is the studio's promise §
28 Sep 2026. Brad, after lying down with it: in any ABA milestone task that is engineering only, if the actual time exceeds the estimate, the studio eats it. His reason: the studio engineer estimated those hours during Milestone Zero. The client agreed to the engineer's number, so a miss is the studio's own estimate being wrong, and billing it would charge the client for the studio's mistake.
The other half, ruled the same night: performance overruns, meaning extra takes within the three-take limit, stay with the client. The overrun is still recorded in red; only who pays changes. Engineering only means role Engineering and rate code EL. Sessions arriving from Pro Tools or Reaper are migrated into Fender Studio Pro, the one DAW the ABA template is built in, so the M0 task where the engineer confirms the session source and estimates any migration is engineering work and falls under the rule.
REFUSED
A gate recorded as built had never existed §
28 Sep 2026. Reading the book, Brad found British spellings in it: "judgement", "organised", "labour", "centre", "rigour", "afterwards", and a "practise" that Marv had written the same night. The spellings were not the finding. The finding was that nothing had stopped them. Task board 125 recorded register_check.py as BUILT on 17 Sep, with a proof that it fails on demand, and the script was nowhere in the repo. Git had no record of it. The 8 Sep entry above says the problem was caught and corrected; it could not say that the check meant to keep it corrected had never been saved.
No report from the machines raised it. A human reading the output did. The check is rebuilt, now refuses on both the site and the book, and was made to fail before it was trusted. Detail: FAILURE_LOG.md, 28 Sep, "The US-English check existed only on paper".
REFUSED
The Session Clock lost its buttons, and nothing said so §
28 Sep 2026. Brad opened the Cost Management Tool and found the Session Timer with no START, PAUSE, RESET or SET BILLING TIME, only an empty band with text in it. Every workbook saved since 30 Aug carried the same damage. By every sign, a rewrite through a Python library had dropped the four buttons and the code names that bind the macros to their sheets, and raised no error. The code behind the buttons was intact the whole time; there was simply nothing left to press.
This is the studio's most valuable instrument, and COST_MODEL_QC_2026-09-12.md had already warned in writing that the library does not round-trip it. The warning was on file. The damage went unreported for four weeks, until the owner opened the file. Restored by surgery from the last good copy and proven cell for cell; the clock still has to run in Excel before it is called fixed. Detail: FAILURE_LOG.md, 28 Sep.
2026-09-11 02:43 · REFUSED · the gate stopped a deploy at GATE §
By: the gate, automatically. What it said, in its own words:
forbidden-wordings list: 6 rules, read from C:\Users\muse\Dropbox\Development\Docker\audiovibes-ai\preflight.py
SCRIPT NAME COLLISION
deploy_site.py exists in 2 places:
amp-site/deploy_site.py
Claude outputs/deploy_site.py
Two scripts with one name are told apart only by which folder
you are standing in. Rename one and run this again.
2026-09-11 03:09 · REFUSED · the gate stopped a deploy at GATE §
By: the gate, automatically. What it said, in its own words:
forbidden-wordings list: 6 rules, read from C:\Users\muse\Dropbox\Development\Docker\audiovibes-ai\preflight.py
SCRIPT NAME COLLISION
deploy_site.py exists in 2 places:
amp-site/deploy_site.py
Claude outputs/deploy_site.py
Two scripts with one name are told apart only by which folder
you are standing in. Rename one and run this again.
2026-09-11 19:36 · REFUSED · the gate stopped a deploy at GATE §
By: the gate, automatically. What it said, in its own words:
forbidden-wordings list: 6 rules, read from C:\Users\muse\Dropbox\Development\Docker\audiovibes-ai\preflight.py
SCRIPT NAME COLLISION
build_site.py exists in 2 places:
Claude outputs/build_site.py
amp-site/site/build_site.py
Two scripts with one name are told apart only by which folder
you are standing in. Rename one and run this again.
2026-09-13 09:54 · REFUSED · the gate stopped a deploy at GATE §
By: the gate, automatically. What it said, in its own words:
forbidden-wordings list: 6 rules, read from C:\Users\muse\Dropbox\Development\Docker\audiovibes-ai\preflight.py
SCRIPT NAME COLLISION
extract_cost_model.py exists in 2 places:
extract_cost_model.py
Claude outputs/extract_cost_model.py
Two scripts with one name are told apart only by which folder
you are standing in. Rename one and run this again.
2026-09-17 20:00 · REFUSED · the gate stopped a deploy at GATE §
By: the gate, automatically. What it said, in its own words:
forbidden-wordings list: 6 rules, read from C:\Users\muse\Dropbox\Development\Docker\audiovibes-ai\preflight.py
SCRIPT NAME COLLISION
tune.py exists in 2 places:
tune.py
Claude outputs/tune.py
Two scripts with one name are told apart only by which folder
you are standing in. Rename one and run this again.
2026-09-17 20:04 · REFUSED · the gate stopped a deploy at GATE §
By: the gate, automatically. What it said, in its own words:
forbidden-wordings list: 6 rules, read from C:\Users\muse\Dropbox\Development\Docker\audiovibes-ai\preflight.py
SCRIPT NAME COLLISION
tune.py exists in 2 places:
tune.py
Claude outputs/tune.py
Two scripts with one name are told apart only by which folder
you are standing in. Rename one and run this again.
2026-09-27 20:48 · REFUSED · the gate stopped a deploy at GATE §
By: the gate, automatically. What it said, in its own words:
forbidden-wordings list: 6 rules, read from C:\Users\muse\Dropbox\Development\Docker\audiovibes-ai\preflight.py
script names: unique across the repo
scanned 19 page(s)
2 FAILURE(S)
book\index.html:50 link to /assets/produce-the-record.pdf � no page is built there.
book\index.html:56 link to /assets/produce-the-record.epub � no page is built there.
Nothing ships until these read clean.
2026-09-27 21:25 · REFUSED · the gate stopped a deploy at GATE §
By: the gate, automatically. What it said, in its own words:
forbidden-wordings list: 6 rules, read from C:\Users\muse\Dropbox\Development\Docker\audiovibes-ai\preflight.py
SCRIPT NAME COLLISION
build_book.py exists in 2 places:
book/build_book.py
audiovibes/book/build_book.py
Two scripts with one name are told apart only by which folder
you are standing in. Rename one and run this again.
2026-09-29 13:14 · REFUSED · the gate stopped a deploy at GATE §
By: the gate, automatically. What it said, in its own words:
forbidden-wordings list: 6 rules, read from C:\Users\muse\Dropbox\Development\Docker\audiovibes-ai\preflight.py
script names: unique across the repo
scanned 20 page(s)
1 FAILURE(S)
book\index.html:62 "Calibre" � British spelling. This site writes US English (register_check.py; exceptions in register_allow.txt).
Nothing ships until these read clean.