Skip to content

STD-ESTATE-001: Estate Mutation Freeze, Separation of Observe/Remediate, and Safe Recovery

Status: Approved Governing Standard
Authority: Thomas P. Scola Jr. — Factory Operating Directive
Date: 2026-09-23
Bead: bc-kn68 / bc-3nhh


1. Prime Directive: Freeze Ad-Hoc Cleanup

The failure loop SEE SOMETHING STRANGE → CALL IT SLOP → DELETE / MODIFY IT IMMEDIATELY is strictly forbidden.

Permanent Operating Invariants:

  1. ESTATE_CLEANUP_FROZEN = YES
  2. Never execute destructive commands without verified classification and explicit governance:
  3. trash, rm, git clean, git rm, git checkout -- ., git restore, git branch -D, bd delete
  4. A discovery agent is strictly an Observer (DETECT, OBSERVE, INVENTORY, MEASURE). It CANNOT mutate.
  5. Mutation requires a separate, authorized Remediation Operation under a claimed Bead and Gas City worktree.

2. Separation of Observe vs. Remediate

               ┌───────────────────────────────┐
               │     factory-estate-audit      │
               │         (READ-ONLY)           │
               └──────────────┬────────────────┘
                              │ Produces Mutation Ledger & Findings
                              ▼
               ┌───────────────────────────────┐
               │    Authority / Human Gate     │
               │          (REVIEW)             │
               └──────────────┬────────────────┘
                              │ Authorizes Scope
                              ▼
               ┌───────────────────────────────┐
               │    factory-estate-remediate   │
               │   (GOVERNED WORKTREE MUTATION)│
               └───────────────────────────────┘

3. The 900+ Formula Deletions Rule

Mass file deletions across multiple Rigs (e.g. .beads/formulas/) are systemic platform events, not localized repository clutter. - Do NOT commit deletions blindly. - Do NOT restore blindly. - Verify upstream Gas City / Beads storage expectations: whether formulas are portable config, Dolt-tracked records, or runtime projections.


4. Worktree and Branch Governance

  1. Worktrees: Do not delete a worktree because it appears stale. A worktree may only be retired when:
  2. BEAD_COMPLETE = YES
  3. UNIQUE_WORK = 0
  4. MR_STATE = MERGED | SUPERSEDED
  5. ACTIVE_SESSION = NO
  6. Feature Branches: A checked-out feature branch is NOT automatically a defect. It is only a defect if CHECKOUT_HAS_NO_ACTIVE_WORK_OWNER or UNIQUE_WORK_IS_STRANDED.