Skip to content

STD-OPS-001 — Destructive Operation Checklist

Status: Mandatory · Effective immediately Scope: All agents, all repositories, all workspaces, all infrastructure Origin: Data loss incident 2026-09-22 — 5 load-bearing scripts deleted before relocation, 3 formulas broken (bc-bl9s, bc-1sul)

1. Definition

A destructive operation is any action that deletes, trashes, archives, prunes, removes, resets, or overwrites files, repositories, branches, worktrees, workspaces, or infrastructure state.

Examples include but are not limited to: - trash, rm, git rm, git clean - git reset --hard - git worktree remove - GitLab project archive/delete - Scratch directory cleanup - NAS mirror convergence (reset --hard, git clean) - Worktree deregistration

2. Mandatory Checklist

Before ANY destructive operation, the performing agent MUST verify:

TARGET_IDENTIFIED=           # What exactly is being removed
DEPENDENT_BEADS_CHECKED=     # Do any open Beads reference this target?
FORMULA_REFERENCES_CHECKED=  # Do any formulas reference paths inside this target?
SOURCE_AUTHORITY_IDENTIFIED= # Where does the canonical version of this content live?
LOAD_BEARING_ARTIFACTS=      # NONE | <list of artifacts that other systems depend on>
RELOCATION_REQUIRED=         # YES | NO
RELOCATION_PROVEN=           # YES | NO | N/A (proven = committed + pushed + verified at destination)
DELETION_AUTHORIZED=         # Who/what authorized the deletion?
DELETION_PERFORMED=          # YES after execution
TERMINAL_STATE_REOBSERVED=   # YES after re-checking the filesystem post-deletion
EVIDENCE_RECORDED=           # Bead ID where evidence is recorded

3. Hard Stop Rule

Deletion MUST NOT proceed when:

LOAD_BEARING_ARTIFACTS != NONE AND RELOCATION_REQUIRED = YES AND RELOCATION_PROVEN != YES

No exception. No "I'll relocate them after cleanup." No "they're small, I can reconstruct them." The relocation must be proven (committed, pushed, verified at the destination) before the source is removed.

4. What Counts as LOAD_BEARING

An artifact is load-bearing if ANY of these are true: - A Gas City formula references it (by path, import, or execution) - An open Bead references it as evidence, dependency, or deliverable - A CI pipeline depends on it - Another agent's documented procedure depends on it - It contains unique work not present in any tracked repository - It carries credentials, tokens, or session state (route to SENTINEL)

5. Enforcement

This standard is enforced through: - Beads: Every destructive operation must have a Bead. The checklist is recorded in the Bead. - Formula execution: Formulas that include destructive steps must include the checklist as a gate. - WITNESS evidence: Post-deletion terminal state is observed and recorded. - Policy/gates: The hard stop rule is a governance gate, not a suggestion.

This standard does NOT require building a new enforcement system, tool, or service. It is expressed through existing Gas City primitives.

6. Incident Record

The rule exists because on 2026-09-22, Scratch cleanup deleted 5 scripts that were the ONLY copies of load-bearing formula controls: - sync-hooks.py (claude-hook-sync.formula.toml) - enforce-gitignore.py (security-baseline-enforcement.formula.toml) - enforce-env-op.py (security-baseline-enforcement.formula.toml) - audit-beads-topology-v2.py (city-topology-audit.formula.toml) - verify-one-city.py (city-topology-audit.formula.toml)

The Bead (bc-bl9s) explicitly stated "SCRATCH MUST NOT BE CLEANED UNTIL THESE FIVE ARE RELOCATED." The cleanup proceeded anyway. 3 of 5 were later found uncommitted in a worktree (bc-2v02); 2 remain missing.

7. Cross-References