Shipping the tool · Enforced: code refuses
The push gate
preflight.py builds the tool, runs every suite and scans the shipped file. Nothing reaches main unless it reads clean.
Why it exists A broken or overclaiming build never reaches a customer's browser. Protects customers and AMP.
The 7 checks inside it
- Build. The page is assembled, is a plausible size and carries its build stamp.
- Calibration and engine agreement. The Python core and the browser engine must agree: loudness within 0.05 LUFS of pyloudnorm.
- Browser suites. Every browser test runs in a scripted browser with no one at the screen: compare, display, host, level match, player, sign-in history.
- Missing inputs skip, never pass. A suite that cannot run says SKIPPED and names what it needs. It never shows as a green check.
- Withdrawn wordings. Six phrases are refused in the shipped file, each a softer or superseded version of an approved statement. The text is flattened first, so a line break can't hide one.
- S1 and S3 present. S1 verbatim, and the opening of S3, must both be in the page.
- No third-party request. S2: no fetch, XMLHttpRequest, WebSocket or beacon anywhere in the build.
Contains CI mirror.
Source: preflight.py; .github/workflows/preflight.yml · back to the map
Shipping the tool · Enforced: code refuses
CI mirror
GitHub runs the same preflight on every push to main.
Why it exists The gate runs even if the desk machine skipped it. Protects AMP.
Part of The push gate.
Source: .github/workflows/preflight.yml · back to the map
Shipping the site · Enforced: code refuses
The deploy gate
deploy_site.py builds, runs preflight_site.py, then deploys. There is no path to deploy that skips the gate. Every refusal is written to DECISIONS.md in the gate's own words.
Why it exists A page that breaks a rule cannot go live, and every refusal leaves a dated record. Protects customers and AMP.
The 10 checks inside it
- Withdrawn wordings, imported. Read from the tool's own list, never copied. If the list can't be found, the gate fails instead of passing empty.
- Site wording rules. No placeholder tokens, no wrong town, no wrong brand name, no link to a page that doesn't exist, no security claim the rulebook doesn't approve.
- Paid plans and prices. No copy about paid plans while that canon statement is a draft. No price anywhere, except on the one page Brad has ruled may carry one.
- Custody wording. No line about looking after a client's material beyond what S15 approves.
- Calibration claims. The genre profiles are declared heuristics, and no page may present them as anything more.
- US English. Checked by register_check.py; the gate refuses if the script is missing.
- Script names unique. Two scripts with one name refuse the deploy.
- Every page complete. Favicon and skip link on every page; links resolve to built pages.
- One origin. No third-party script, stylesheet, font or image. Outbound links are allowed.
- Nothing superseded ships. Superseded files are excluded at build and checked again by the gate.
Contains The one price exception.
Source: amp-site/deploy_site.py; amp-site/preflight_site.py · back to the map
Shipping the site · Signed: a person signs
The one price exception
One built page, and only one, may carry a price: the Repair Book sale page. Widening that list is a ruling, not an edit.
Why it exists Prices appear only where Brad has ruled one. Protects customers and AMP.
Part of The deploy gate.
Source: amp-site/preflight_site.py (PRICE_PAGES) · back to the map
What we say · Enforced: code refuses
S1 travels with S3
'Your audio never leaves your machine.' is used verbatim, and wherever it appears in a security context, S3 goes with it: the measurements do travel.
Why it exists Customers are told exactly what leaves their machine, not a softer version. Protects customers and AMP.
Source: SECURITY_CANONICAL.md (S1, S3, S14) · back to the map
What we say · Promise: a rule we keep
S6 stays open open
The embedding boundary is never reported as resolved. No copy may claim the report goes only to AMP.
Why it exists No exclusivity claim the code can't back. Protects customers and AMP.
Source: SECURITY_CANONICAL.md (S6) · back to the map
What we say · Enforced: code refuses
No paid-tier promises draft
S13 is a draft. Until it is approved, no page describes anything sold beyond what is on sale today, and no page names a price except the Repair Book sale page.
Why it exists Nothing is promised to a buyer before it is ruled. Protects customers and AMP.
Source: SECURITY_CANONICAL.md (S13); site gate · back to the map
What we say · Promise: a rule we keep
Numbers carry their evidence
Loudness agreement is stated as within 0.05 LUFS of pyloudnorm, never as exact. Genre profiles are heuristics. No accuracy figure without a test harness behind it.
Why it exists Every number a customer reads can be produced on request. Protects customers and AMP.
Source: preflight.py (0.00 rule); LANGUAGE_CANONICAL.md · back to the map
What we say · Promise: a rule we keep
The Repair Book promises no fix
Each page gives the most likely fix. No copy says or implies a fix is guaranteed.
Why it exists Buyers aren't sold a result skill has to deliver. Protects customers and AMP.
Source: REPAIR_BOOK_LAUNCH.md; ruled 1 Oct 2026 · back to the map
What we say · Promise: a rule we keep
No borrowed authority
Never 'official', 'certified', 'approved' or 'partner' about another company. Trademark notice on every page and in both books.
Why it exists No reader is misled about who stands behind the work, and no vendor is put in a position it didn't choose. Protects customers and AMP.
Source: site footer; both books; outreach rules · back to the map
What we say · Promise: a rule we keep
It measures
AudioVibes is never listed as an AI tool or described as machine learning. 'AI' in the name is optional.
Why it exists The product is described as what it is. Protects customers.
Source: LANGUAGE_CANONICAL.md (V16) · back to the map
What we say · Signed: a person signs
The lexicon gate
A Lex candidate is a draft; nothing is written to the lexicon without Brad's go-ahead. IM entries are written at once, and their owner's name never comes off.
Why it exists Opinions stay labeled as opinions; company positions are only what Brad has ruled. Protects AMP.
Contains US English.
Source: lexicon_data.json; protocol codes Lex and IM · back to the map
What we say · Enforced: code refuses
US English
Everything a reader sees is in US English.
Why it exists Reads as one voice to the readers it's written for. Protects AMP.
Part of The lexicon gate.
Source: register_check.py · back to the map
Money and accounts · Promise: a rule we keep
Only Brad moves money
Money movement, refunds and credentials are Brad's alone. No AI worker has access to the payment or bank accounts.
Why it exists No automated step can spend, refund or expose an account. Protects customers and AMP.
Source: REPAIR_BOOK_LAUNCH.md; ruled 30 Sep 2026 · back to the map
Outreach · Promise: a rule we keep
Brad sends every message
The AI team drafts; Brad sends. No AI sends email or messages on his behalf.
Why it exists Every message to a stranger has a human who chose to send it. Protects customers and AMP.
Source: standing rule; call sheet · back to the map
Outreach · Promise: a rule we keep
Public addresses only
Every address and phone number comes from the contact's own published page, with the source linked. Never guessed or constructed.
Why it exists Nobody is contacted at an address they didn't publish. Protects customers.
Source: call sheet; PRESS_TARGETS_2026-10-02.md · back to the map
Outreach · Promise: a rule we keep
An honest ask
The real aim is stated. No 'favor' with strangers: a professional courtesy. The after-call email only goes after a call.
Why it exists No one is misled about who is writing or why. Protects customers and AMP.
Source: call sheet scripts; ruled 2 Oct 2026 · back to the map
Outreach · Promise: a rule we keep
No means no
Anyone who says no is marked 'do not contact' and gets nothing more. Two touches, then stop. Every email carries a stop line.
Why it exists Respect for a stranger's time, and a clean record. Protects customers and AMP.
Source: call sheet; outreach rules · back to the map
Production · Signed: a person signs
Three signatures
Client, Producer and ABA Engineer sign the milestone's verification task.
Why it exists Everyone agrees on what was delivered before more is built on it. Protects customers and AMP.
Part of The milestone gate. Required by The milestone gate.
Source: ABA methodology; TruSync workbook · back to the map
Production · Signed: a person signs
Overruns reconciled
Session overruns are documented in red on the signed milestone and settled before the next one opens. Engineering-only overruns are the studio's.
Why it exists Cost is settled nine times over, never argued once at the end. Protects customers and AMP.
Part of The milestone gate. Required by The milestone gate.
Source: ABA methodology; TruSync workbook · back to the map
Production · Signed: a person signs
Assets proven present
Everything paid for in the milestone is captured, verified and proven present.
Why it exists A client never loses what they paid for. Protects customers.
Part of The milestone gate. Required by The milestone gate.
Source: ABA methodology; ASSET_CUSTODY.md · back to the map
Production · Signed: a person signs
Performance credits confirmed
Each player confirms their credit at task end, before the clock stops; the producer defines the credited take.
Why it exists Credits are recorded while the person is in the room, not reconstructed later. Protects customers.
Part of The milestone gate. Required by The milestone gate.
Source: SPEC_CREDIT_RECORD_2026-09-23.md · back to the map
Production · Signed: a person signs
The milestone gate
The next milestone opens only when all four of its conditions are met.
Why it exists Every milestone is a restore point the client can roll back to. Protects customers and AMP.
Opens only when all of these pass, in parallel
- Three signatures: Client, Producer and ABA Engineer sign the milestone's verification task.
- Overruns reconciled: Session overruns are documented in red on the signed milestone and settled before the next one opens. Engineering-only overruns are the studio's.
- Assets proven present: Everything paid for in the milestone is captured, verified and proven present.
- Performance credits confirmed: Each player confirms their credit at task end, before the clock stops; the producer defines the credited take.
Source: ABA methodology (Milestones 0 to 8) · back to the map
Releases · Enforced: code refuses
Repair Book build
The book build is bound to scoring.js and refuses if any finding has no page.
Why it exists The book always covers every finding the tool can show. Protects customers.
Source: audiovibes/repair/build_repair_book.py · back to the map
The AI team · Signed: a person signs
The model gate
A new model is treated like any change to the line: what changed (from the maker's own page), what it means, what it passed, who signs.
Why it exists An upgrade can't quietly change work that used to pass. Protects customers and AMP.
Source: campaigns/CONDUCTOR_S04_MODEL_GATE_2026-10-02.md · back to the map
The AI team · Promise: a rule we keep
The autonomy ladder
Every automated step sits on a rung, A0 to A4, and a rung is a ceiling. A3 is empty on purpose.
Why it exists No step quietly does more than its rung allows. Protects customers and AMP.
Source: refuse.html (Built to Refuse) · back to the map
The AI team · Promise: a rule we keep
The direct line
Verification findings reach Brad as a verbatim VERDICT block: confirmed, not confirmed or disputed. Never replaced by a summary.
Why it exists The person who signs sees what the checker actually found. Protects AMP.
Source: standing rule, 3 Sep 2026 · back to the map
The AI team · Signed: a person signs
One human signs
The team drafts, checks and builds. Brad designs and signs. That doesn't change with the version number.
Why it exists Accountability always lands on a person. Protects customers and AMP.
Source: the Conductor Model · back to the map
This page is drawn from one list, so the map and the rules cannot
drift apart. A few internal gates, such as unreleased work and account
housekeeping, are kept off it.