A job that exited cleanly has not succeeded. Success is a verified end state — the artefact exists and validates — not a green run indicator.
Everything else in the system serves an operation. This one serves a person — and it is the only part of it that gets smaller the better it works.
The instinct, when an operation or an estate gets complicated, is to build a better sensing layer. More watchers, more coverage, a specialist per area, a dashboard that finally shows everything. We built exactly that, twice. The sensing layer was never the constraint.
We know because we instrumented ourselves and the numbers were humiliating. Ten consecutive weekly audits of our own agent fleet recommended retirements and executed zero of them, while six candidates aged ten weeks. Five open flags went twenty-eight days without a single one being closed. Automated digests sat at zero human reactions for fourteen consecutive days. Two daily jobs — the two that had survived a deliberate cull down to five — had thirty-six unread runs each. Roughly five weeks of correct, well-formed output, produced and never opened.
None of that is a sensing failure. Every one of those systems ran, on time, and found real things. The bottleneck was the reader. And twenty-six more agents pointed at a reader-shaped bottleneck produce twenty-six more unread files.
Decision throughput is the constraint, not information throughput. So the system is optimised for one metric — the share of surfaced items actually acted on — and every design choice that competes with it is cut.
That single decision is where all seven standing orders come from. They are not style preferences. They are the shape a system takes when the reader, rather than the sensor, is the scarce resource.
The rest of the ontology is the sea and the figures in it. Proteus changes shape and yields the truth only under a grip. Nereus does not forget and does not lie. Triton sounds the trumpet and the sea moves. Those are the three prongs of a trident, and the instrument can never have a fourth.
A pharos is deliberately outside that world. It is the lighthouse — the fixed structure on the shore that takes scattered signals and returns one beam. It is infrastructure, not a god. It does no work on the water. It says where the reef is.
The runner-up name was Argus, the hundred-eyed watchman, and it was rejected on exactly the grounds this page is about: it names the sensing, and sensing is the half that already worked. Naming the system after its eyes would have encoded the mistake into the product.
This is also why Pharos does not violate the three-prong constraint. It is not a fourth module competing to be part of the instrument. It is the shore the instrument is used from.
Ninety-one scheduled runs a week across thirty-two agents deposit structured findings into one store. At the same time every morning, one composer reads the whole store — plus the heartbeats, plus the goal grid — ranks everything against named goals, and returns five items. Not the best five of a longer list shown below. Five, and the sixth does not exist.
The clinical decision-support literature is the only measured body of work bearing on why recurring automated output stops being read. Acceptance falls roughly thirty per cent for each additional item in a single session, and responsiveness falls about ten per cent for every five-point rise in the share of repeats. The mechanism is per-session cognitive overload rather than desensitisation — general workload was not a significant predictor.
Two things follow. The cap is a number with evidence under it rather than a matter of taste. And deduplication by stable item id is load-bearing: an unchanged item never returns as a headline, it returns as one line in a collapsed counter, because repetition is the second measured killer.
An item that cannot be phrased as a binary is not decision-ready, and it does not go on the Page. It goes to the appendix or it is deleted. The fourth Eisenhower quadrant is not shown for completeness; it is removed.
A design note we learned the expensive way: the first version put that control below the prose at the same visual weight as Close and Snooze, and it went unpressed. The load-bearing action cannot look like a footnote.
The bit also does a second job. The ranking function — the quadrants, the goal scoring — is an extrapolation from the fatigue evidence rather than a finding, so the bit is instrumented to test it: if the scoring sorts badly, acted-on rates on high-ranked items will not separate from low-ranked ones, and it fails visibly rather than arguably.
Each of these was written against a specific failure that had already happened to us. None of them are aspirations.
A missing report is never the absence of news. Every watcher writes a heartbeat whether or not it had anything to say, and it travels on a separate path from the finding — so said nothing and never ran can never look the same again.
A job that exited cleanly has not succeeded. Success is a verified end state — the artefact exists and validates — not a green run indicator.
Hard cap. If it cannot be phrased as a decision it is not decision-ready. Nothing material is a valid answer.
Importance is not judged in prose. An item cites the objective it advances, by id, or it answers no goal match — which disqualifies it.
Fourteen days open with no action forces a binary between act and close. Thirty days auto-closes, with a line in the decision log naming what expired.
Everything an agent produces is a draft for a person. Nothing reaches a client, a counterparty or a public channel without a human decision in between.
The weekly review ends with exactly one change. Retiring a watcher counts. Adding one does not, unless something was retired in the same pass. Growth requires a kill.
Order seven exists because ten consecutive audits produced zero kills while the fleet grew anyway. An audit that cannot subtract is a newsletter.
The sketch this started from ran canon → rules → agents → output → decision, and stopped. There was no edge deciding whether an agent had earned its place, and no edge re-aiming the rules when the goal moved. Without those two, a fleet can only accumulate — which is exactly what the record showed.
The Sweep runs deterministic metrics first — deposits expected against written, schema failures, median lateness, duplicate rate, count of quiet days — then isolated judges per dimension, each permitted to answer unknown, and only then the acted-on rate. Watchers are killed on cost per acted-on item, never on volume: a low hit-rate is not shelfware when what it surfaces is load-bearing. The Licensed Doubt →
The domain set is fixed and known, which buys a large simplification: watchers are independently scheduled jobs decoupled through the store, so the system skips decomposition — the expensive, failure-prone half of orchestrator-worker — entirely. Every agent produces a draft for a person, and a human decision sits between anything an agent writes and any live surface.
Everything else in the system is issued to an organisation. Pharos is issued to a person, which is why it is drawn sitting on the waterline in the section rather than above or below it. The operator of a business gets one exactly as the principal of an estate does, and most people we work with are both. The instrument does not care which side of the line you work on. It cares that there is one of you.
The household lamp and the operator's lamp are the same lamp. Same cap, same standing orders, same ageing, same single bit at the end. What differs is the record it reads and the goals it ranks against, and those are configuration.
A household is a set of entities, a chart of accounts, a calendar, a document store, a task graph and a set of people with permissions — and so is a dive centre. The nouns change and the engine does not, which is why the rule we hold ourselves to elsewhere applies cleanly here: anything claiming to be a new instrument has to prove it is not an existing one wearing a different hat.
Five decisions a day across the estate and the companies at once, because the questions you ask at the end of a quarter do not respect entity boundaries.
Their own instance, their own ranking, their own goals. Parity of standing designed in rather than a second seat on somebody else's.
Issued when they hold something real. A lamp is a piece of authority, not a monitoring device, and it is never pointed at a person who did not ask for it.
The person running a business on the platform gets one too, ranked against the operation's goals rather than the household's.
A second lamp does not issue until the first one is being acted on. Do not scale an instrument nobody reads. Multiplying a lamp with a low acted-on rate multiplies the noise and buys nothing — which is the same mistake, one level up, that this whole design exists to correct.
And the standing prohibition, unchanged from the rest of Acequia: no children on scorecards, and no performance instrumentation of anybody who did not consent to it. This tooling is legitimate for obligations, money and calendars, and corrosive applied to a person’s inner life.
There is no separate family product, and the previous section says why. What there is, is a configuration — the same engine pointed at a different record, ranked against different goals, and carrying three prohibitions that do not exist on the operating side. It is worth setting out precisely what moves and what does not, because the parts that do not move are the parts that make it work.
Household items are about obligations, money, calendars and decisions. Never about a member of the family. The moment an instrument can surface somebody has not done the thing, it has stopped being a lamp and become a grievance queue with a schedule — and it will be used as one.
Each adult gets their own instance with their own ranking against their own goals. Not a second seat on somebody else’s feed with a narrower view. A household where one person’s lamp is the real one has reproduced the arrangement the product was bought to end.
The mental-load research is unambiguous that one partner does the setup. If the lamp becomes another surface on which she carries the load — reading everyone’s items, chasing everyone’s decisions — it has reproduced the problem it was sold to solve. Conception, planning and execution move together, per lamp, or the module is not installed.
The items look different because the record does, and this is the part that is hard to imagine until you see a week of it. A renewal nobody owns. A reserve floor breached three weeks ago and never raised. An obligation whose evidence has not arrived. A decision the last assembly took that has quietly not happened. An asset carried for a reason that expired and can be named. A charter clause the last twelve months contradicted.
And frequently, the most valuable output: nothing material. Three lines saying so, here is what ran, here is what is still open. A household brief that is never empty is a household brief that gets skimmed, and a skimmed lamp is worse than no lamp, because it manufactures the feeling of being on top of something.
The household configuration also ties into a cadence the operating one does not have — the weekly family meeting, the quarterly owner room, and the annual gate. Items that survive ageing without resolution surface at the next scheduled room rather than nagging daily, which is what the four rooms are for. The rest of the layers →
A lamp is not sold on its own. It installs inside the operating mandate, because the ranking is only as good as the record underneath it and the record is what the mandate builds. acequia@thechilamgroup.com