STD-OPS-001 — Destructive Operation Checklist¶
Status: Mandatory · Effective immediately Scope: All agents, all repositories, all workspaces, all infrastructure Origin: Data loss incident 2026-09-22 — 5 load-bearing scripts deleted before relocation, 3 formulas broken (bc-bl9s, bc-1sul)
1. Definition¶
A destructive operation is any action that deletes, trashes, archives, prunes, removes, resets, or overwrites files, repositories, branches, worktrees, workspaces, or infrastructure state.
Examples include but are not limited to:
- trash, rm, git rm, git clean
- git reset --hard
- git worktree remove
- GitLab project archive/delete
- Scratch directory cleanup
- NAS mirror convergence (reset --hard, git clean)
- Worktree deregistration
2. Mandatory Checklist¶
Before ANY destructive operation, the performing agent MUST verify:
TARGET_IDENTIFIED= # What exactly is being removed
DEPENDENT_BEADS_CHECKED= # Do any open Beads reference this target?
FORMULA_REFERENCES_CHECKED= # Do any formulas reference paths inside this target?
SOURCE_AUTHORITY_IDENTIFIED= # Where does the canonical version of this content live?
LOAD_BEARING_ARTIFACTS= # NONE | <list of artifacts that other systems depend on>
RELOCATION_REQUIRED= # YES | NO
RELOCATION_PROVEN= # YES | NO | N/A (proven = committed + pushed + verified at destination)
DELETION_AUTHORIZED= # Who/what authorized the deletion?
DELETION_PERFORMED= # YES after execution
TERMINAL_STATE_REOBSERVED= # YES after re-checking the filesystem post-deletion
EVIDENCE_RECORDED= # Bead ID where evidence is recorded
3. Hard Stop Rule¶
Deletion MUST NOT proceed when:
LOAD_BEARING_ARTIFACTS != NONE AND RELOCATION_REQUIRED = YES AND RELOCATION_PROVEN != YES
No exception. No "I'll relocate them after cleanup." No "they're small, I can reconstruct them." The relocation must be proven (committed, pushed, verified at the destination) before the source is removed.
4. What Counts as LOAD_BEARING¶
An artifact is load-bearing if ANY of these are true: - A Gas City formula references it (by path, import, or execution) - An open Bead references it as evidence, dependency, or deliverable - A CI pipeline depends on it - Another agent's documented procedure depends on it - It contains unique work not present in any tracked repository - It carries credentials, tokens, or session state (route to SENTINEL)
5. Enforcement¶
This standard is enforced through: - Beads: Every destructive operation must have a Bead. The checklist is recorded in the Bead. - Formula execution: Formulas that include destructive steps must include the checklist as a gate. - WITNESS evidence: Post-deletion terminal state is observed and recorded. - Policy/gates: The hard stop rule is a governance gate, not a suggestion.
This standard does NOT require building a new enforcement system, tool, or service. It is expressed through existing Gas City primitives.
6. Incident Record¶
The rule exists because on 2026-09-22, Scratch cleanup deleted 5 scripts that were the ONLY copies of load-bearing formula controls:
- sync-hooks.py (claude-hook-sync.formula.toml)
- enforce-gitignore.py (security-baseline-enforcement.formula.toml)
- enforce-env-op.py (security-baseline-enforcement.formula.toml)
- audit-beads-topology-v2.py (city-topology-audit.formula.toml)
- verify-one-city.py (city-topology-audit.formula.toml)
The Bead (bc-bl9s) explicitly stated "SCRATCH MUST NOT BE CLEANED UNTIL THESE FIVE ARE RELOCATED." The cleanup proceeded anyway. 3 of 5 were later found uncommitted in a worktree (bc-2v02); 2 remain missing.
7. Cross-References¶
- STD-SEC-001 — credential artifacts require SENTINEL routing, not just deletion
- STD-CONTEXT-001 — worktree lifecycle governance
- STD-WORK-001 — Bead-based work tracking