Seven stations, each able to refuse
The stations run in order and each takes the previous one's output as input. The useful property is not the sequence — it is that every one of them has something it will not pass along, so a weak claim has to survive seven separate opportunities to be stopped rather than one review at the end.
Research which service to build next, judged on whether it is easy, simple and reliable rather than on whether it sounds impressive. Produces a ranked recommendation with verified price anchors.
Refuses: A recommendation whose price anchors were not fetched from a real published page.
Turn the pick into an evidence-backed seed document: extraction, live research recorded as machine-verified evidence, then a structured output with four-tier provenance tagging on every claim.
Refuses: Any factual claim that does not point at a fetched, hash-pinned page. Three machine-checked ledgers have to reconcile before it can be saved.
Run an adversarial council over the seed. Specialists may only challenge a tagged claim, propose a falsifiable test, or cite a fact they recorded with evidence. They may not assert.
Refuses: An unadjudicated finding. Every challenge is decided before the PRD is assembled, and the result must pass the provenance gate.
Derive the whole design context from the research — tokens, flows, an asset manifest and the assets themselves — so the build is fully specified without asking a subjective question.
Refuses: A design decision with no reference back to a numbered section of the research.
The technical design: schema, row-level security policies, typed interfaces and the testing strategy, written as real code rather than as description.
Refuses: A schema with no policy attached, and a component with no stated test.
Compile everything above into the instruction file a build session actually executes: atomic build steps, a blocker table, non-negotiable rules and a definition of done.
Refuses: A build step that cannot be finished and verified on its own.
Audit the built repository for every environment variable it reads, then produce the ordered cutover: credentials, database, deploy, domain, payments, email, smoke test, rollback.
Refuses: A launch where any referenced secret has no acquisition step — and it ends in a hard gate that has to be passed by a human.
The first business ran 7 of 7 stations, producing 6527 lines of documents and 58 evidence records. The second ran 0.
It was built directly, skipping the document pipeline entirely. That is not a presentation choice about this page — it is measured by checking whether seven filenames exist in that repository, and they do not. Which half of this process actually carries the value is therefore still an open question, and the honest page says so.
20 programs that can stop a release
One command runs all of them, and a partial pass is a fail. Every name and description below is read out of that runner's own GATES array when npm run metrics is run, so this table cannot describe a gate that was deleted or miss one that was added.
They are not redundant. Each is blind to something another one sees — a duplicate photograph fails the design gate and passes Lighthouse; a broken 22px mark passes a full-page baseline and fails an element-scoped one; text over a photograph fails a rasterised contrast check that axe cannot even attempt.
| # | Gate | What it catches | Also in #2 |
|---|---|---|---|
| 1 | publication | no personal contact detail anywhere — PUBLICATION.md | yes |
| 2 | types + build | a type error is a defect that has not happened yet | yes |
| 3 | selftest | the paid path produces a record, and HALTS when a verifier is unavailable | yes |
| 4 | verify_design | duplicate images, missing mark, bare pages, placeholder copy | yes |
| 5 | visual baselines | any unintended pixel change, page-level and element-level | yes |
| 6 | lighthouse | the ten numeric bars in QUALITY_BAR §1, re-derived rather than quoted | yes |
| 7 | scrim contrast | AA for text over photography, which axe cannot see and therefore never fails | yes |
| 8 | record integrity | every published record can say what it examined — bytes, hash, subject, method | yes |
| 9 | rendered text | source syntax leaked into prose — the one defect a frozen baseline certifies | yes |
| 10 | links | every internal link resolves, and og:image, robots.txt and the sitemap name THIS site | yes |
| 11 | discoverable | QUALITY_BAR §7 D1–D8, asserted against the served bytes rather than a source literal | no |
| 12 | deliverability | nothing can be paid for that has no producer, renderer and checker on disk | yes |
| 13 | figures | no number in a published document that nothing on disk counted | yes |
| 14 | honest | every gate's exit code agrees with the verdict it just printed | yes |
| 15 | mutation | the other gates can actually fail, proven by breaking the code on purpose | yes |
| 16 | stripe | what Stripe shows a customer matches what this repo says | yes |
| 17 | complete | a stranger can find it, understand it, buy it, and receive it — provably | yes |
| 18 | pipeline registries | every registry exists and has a station that reads it | yes |
| 19 | pipeline sync | the enforcers that ran are the enforcers under review | yes |
| 20 | ci coverage | every gate here is assigned a CI job, and every gate script on disk is accounted for | yes |
The second business runs 20 of them. The one it does not carry is discoverable, which is a gap rather than a decision. It carries 1 the first does not.
Passing every gate is not the same as being correct, and the project has the receipt for that: a full mutation run against the first business broke its code 243 different ways to find out which breakages the gates would notice, and 226 survived. An earlier run did leave two, both in the gate that decides whether a business is finished — one of which let it print a failure verdict and exit successfully. That is why there is now a gate whose only job is to check that every other gate’s exit code agrees with what it printed.
