An adversarial grade of what Driver sess-propflow-ef chose to work on between 03:40 and 05:30Z, measured against the goal as written in the portfolio-architecture HOW — not against the board.
2026-09-13 · audit by a sub-agent, not by the Driver · sources: HOW §10, §13, A3, A4 · the phase dock, parsed with bin/tracker_rows.py
You spent the night polishing your own tools. Of the merged PRs named in the brief, one touches a capability the HOW names — and it ships switched off. The other thirteen are fleet tooling and the board editing its own status fields. That is drift. It is defensible drift, because the defects were real and one of them is why a wall the founder ruled on has been reading green while being a dead function — but it is drift.
merged PRs that touch a capability named in HOW A3 — propflowai#8056, the roster gate.
merged PRs that flip a named proving case (A3's "proves it" column) or a fitness function to GREEN.
fleet self-maintenance — 9 agent tooling, 4 the board grading itself.
| PR | What it did | Dock row it closed | HOW capability advanced |
|---|---|---|---|
local-bin#167 | lane-scratch: a lane's scratch namespace is minted, not remembered | bug-lanes-share-one-scratchpad-namespace merged | none fleet self-maintenance |
local-bin#173 | Lanes are TOLD they share a scratchpad — the coordinator manual and an audit control | same row as #167 | none fleet self-maintenance |
local-bin#168 | loop-doctor --version carries a behind-count | bug-local-bin-has-no-puller merged — a row whose own premise was false when filed | none fleet self-maintenance |
local-bin#172 | blocked: execution recorded per question, not per block | bug-decision-block-one-exec-slot merged | none fleet self-maintenance |
agent-smith#507 | Same fix on the Smith side of the decision-block record | same row as #172 | none fleet self-maintenance |
local-bin#176 | runtime-checkouts: a census of what the fleet actually runs from | bug-runtime-checkouts-have-no-puller — still open | none fleet self-maintenance |
local-bin#178 | #176 did not parse on stock macOS bash, and three of its claims were false | same row, still open | none fleet self-maintenance — a fix to a fix shipped 14 minutes earlier |
local-bin#177 | review-sub: a lane's review wake becomes routable instead of anonymous | no dock row at all | none fleet self-maintenance |
agentflow-relay#173 | SYSTEMS.md: the review-webhook every session waits on was never listed | no dock row at all | none fleet self-maintenance |
propflowai#8056 | The company-holds-this-building check is now actually asked — isPropertyScopeDenied calls requireInRoster on its assignment branch. Still ships OFF. | bug-require-in-roster-never-armed — still open | A3 · "The wall (contexts)" (finish, step 3a) · §13 row 2 "Isolation between clients, at the store" · the P1 row p1-roster-refuse. The only one. |
propflow-docs#174 | Board: two finished rows declare completed_by | board bookkeeping | none the board grading itself |
propflow-docs#177 | Board: a non-PR completion the deriver CHECKS — completion_evidence | closes p00-vocab-page-stale, p00-the-tracker-rendered-zero-rows, a0-how-chapters, bug-completed-rows-have-no-non-pr-evidence-field — all four are doc or board rows | none the board grading itself |
propflow-docs#178 | Board: two honest partials finish the exec-slot row | board bookkeeping | none the board grading itself |
propflow-docs#179 | Board: the completed_by sweep closes NOTHING — 25 rows honestly open | board bookkeeping | none the board grading itself |
Rows parsed with bin/tracker_rows.py against artifacts/portfolio-architecture-phases.html — 295 rows, {wip:5, merged:132, shipped:27, open:130, blocked:1}. Capability mapping is against HOW A3 · From have to want, whose 26 area rows each name a target, a ladder step and the stress case that proves it.
propflowai#8056, the store-level roster gate.#8056's own dock row is still open and its gate still ships OFF: PROPFLOW_ROSTER_GATE unset ⇒ the gate returns before any read.local-bin#176 → #178), and the row they were filed against is still open.bug-page-says-stays-open-under-a-merged-pill, bug-three-non-pr-rows-still-carry-an-authored-completion, bug-completion-evidence-refs-do-not-render) and one product row (p7-domain-override). Three notes about itself for every one about the product. Measured by diffing the row-id sets of the dock at the last commit before 03:40Z (73fce829, 291 rows) and the last before 05:30Z (75a5e01a, 295 rows) — not from the rows' added field, which filers write in local time and would have put the whole night on the 12th.Three things make this the best night of self-maintenance the fleet could have had, and I want them on the record before the verdict is quoted.
(a) The defects were real, and one of them had already destroyed work. The scratchpad row is not hypothetical: on 2026-09-12 the #7708 lane wrote pr-body.md, the #7744 lane used the same obvious filename, and #7708's prose was pushed over #7744's PR description. Both lanes were following the same instruction correctly. local-bin#167/#173 close the only failure mode in the fleet that is silent and produces plausible wreckage.
(b) The same discipline that produced the fleet rows produced the one real product finding. #8056 exists because somebody enumerated read sites and noticed the gate that should have been at all of them was called from none. p7-domain-override, filed the same night, is the same move applied to helpers.ts:249. "Audit the instrument, not its output" is exactly what this board's fleet rows encode, and it is the reason the night found anything at all.
(c) The board says to. A third of the dock is "Found along the way". The Driver was working the board as written. If that column is a trap, it is a trap the board set.
Why it does not carry. The obvious defence — propflowai main was RED and owned by another session — explains why product PRs could not land. It does not explain why they were not dispatched: four product-shaped PRs were authored that night (#7999 p7-bypasses, #8097 the vendor-card guard, #8142 the scope registry, #8162 the ratio denominators) and all four are still open. The lanes were capable of product work; ~22 of them were pointed elsewhere. That is a dispatch choice, not a constraint. And in the same 03:00–06:00Z window propflowai merged 28 PRs — tours on two homes, guest-card shapes, the Spanish mis-hear fix, portfolio-wide work orders. The repo was not frozen. Exactly one of those 28 is attributed to this Driver.
Read the two facts together:
b88986177 (Gera, 2026-09-09): "the wall — P1's roster gate flipped from observe to refuse before the first foreign login — precedes any renewals work for that client." That is the ruling that reordered the whole ladder and moved P0's Atlas polish out to pay for it.origin/main at 55f821dc90: seven references to requireInRoster outside tests, six of them non-executing — four comments and two string literals (a log message at tools-leasing.ts:1050, a constant name at helpers.ts:833). The single live call is src/lib/platform/auth/helpers.ts:848, added by #8056 tonight. #8056's own runbook diff says it plainly: "Armed as of 2026-09-12 … It was a no-op for one day after the module merged. Still ships OFF."So the most load-bearing ruling on the board had a row reading merged while the mechanism it names did not execute in any position. This is the exact shape the dock's own bug-require-in-roster-never-armed row describes: "the inverse of a vacuous guard. A vacuous guard runs against an empty set and reports green; this one would work perfectly and never runs at all." The board found it, filed it, and the row is still open — because #8056 wired one branch and left the switch off.
To the Driver's credit: this is the one thing the night did that a future reader will thank it for. It narrowed the gap rather than creating it. But the row that would tell anyone the gap exists — p1-roster-refuse — still says merged, and correcting it was not among the four board PRs this night shipped. The night spent four PRs on how the board records completion and zero on the one row whose completion claim is false about the founder's own ruling.
The only merged PR that could touch a settled ruling is #8056 (the others are fleet tooling and board markup). Grepping its diff for every term the five rulings turn on:
gh pr diff 8056 --repo PropFlow-Technologies/propflowai | grep -i 'all_managed\|platform_admin\|wildcard\|bypass\|observe\|refuse\|quiet_hours\|handover'
quiet_hours gates direction, not contact) — zero matches for quiet_hours in all three scope-touching PRs (#8056, #7999, #8097).all_managed wildcard) — zero matches for all_managed or wildcard in all three.handover in all three.The matches that did come back are all observe / refuse / platform_admin inside #8056's own three-position gate and its tests — and they are consistent with A4's ordering finding, which requires exactly the observe position the PR preserves. The one platform_admin hit is a test proving the gate does not 404 platform staff on an unrouted record.
Named rows, in A4 ladder order, each with the HOW section that justifies it. Not "more fleet hygiene".
| # | Row | Why it is next | The HOW section that says so |
|---|---|---|---|
| 1 | p1-roster-refuse — correct the row, then arm the gate | The row claims done; the gate ships OFF. The board already has the word for this state and proved tonight that it is live and checked (#183 re-verified all six): mark the row unbuilt — "the PRs landed and the THING did not", which renders open — until PROPFLOW_ROSTER_GATE is at least observe on stage. Then flip it and measure. Doing neither is the board lying about the founder's own gate. The 0-of-81 unassigned-building count is already measured against prod, so the arming precondition is met. | §10 answer (1) / b88986177; A4's ordering finding; §13 row 2; A3 "The wall (contexts)" → ST-46, ST-26, ST-47, ST-49 |
| 2 | p7-domain-override + drive propflowai#7999 to merge | An @propflowai.co email suffix still forces platform_admin at the one auth chokepoint every route flows through. That is p7-bypasses' stated goal being false in production, filed last night and untouched. #7999 is already written and open. | A3 "The wall (contexts)" and "Staff membership"; the row's own read of helpers.ts:249 |
| 3 | blocked raise D2 — the settings class list | Not a build; a question. §10 says D2 "is the only one that gets more expensive the longer it waits" and is needed by Oct 6–14. p3-registry is deliberately held open waiting on it. A night of lanes cannot start it; one raise can unblock it. Raise it before building around it. | §10 D2, gate "before 2a"; A3 "Settings (four levels)" → ST-07, ST-45, ST-54 |
| 4 | p1-f01, p2-replay, p2-benches | P2's exit is "the harness can say GREEN". F01 is the fixture that must stay byte-identical at every later step — until it exists, camellia-replay-byte-identical cannot be run, and every later "dark" claim is unfalsifiable. This is the proving instrument the whole ladder grades itself with. | A4 P2 card; A3 "The proof harness" (finish, step 0.5) → ST-14, ST-20, ST-38, ST-55, ST-02 |
| 5 | p3-head, p3-attachment | A3 calls the head-level address claim "closer than it looks — zero migration and about a day": the canonicaliser ships, the writer already refuses at number level, the backfill is seven numbers to five nodes. p3-attachment is the row every capability hangs on. P3's exit is "a second claim refused by the store". | A3 "Phone routing + the nameplate" (rip, rows at step 1) → ST-09, ST-10, ST-50; A4 P3 |
| 6 | p4-escalation-key | Key two of the resolver's byte-parity exit. Key one (p4-vendor-key) is merged; this is the other half of P4's exit test. | A4 P4 "byte-equal on the first two keys" |
HOW §13 and A4 both assert "Nothing on the ladder has started". The dock says otherwise: 45 of 102 P1–P9 rows read merged or shipped, including all ten non-fixture rows of P1 and most of P2. A4 itself resolves this — "the live tracker moved — this pane is now the DESIGN RECORD, not the board" — but §13 was not given the same banner, and §13 is the section the brief names as the yardstick.
This matters for the audit's own conclusion. A Driver reading §13 sees a ladder that has not started and no dispatchable work; a Driver reading the dock sees 130 open rows. That gap is a plausible cause of the drift being audited, and it is cheap to close: give §13 the same "this is the design record" banner A4 carries, and point it at the dock. It does not excuse the night — the Driver was dispatching against the dock, which is current — but a stale yardstick is a reason a board drifts into self-maintenance, and it is the one structural fix on this page that nobody has to argue about.
bin/tracker_rows.py on artifacts/portfolio-architecture-phases.html, never a whole-file regex. 295 rows.gh pr view / gh pr diff against each PR's own repo, titles and changed paths read rather than inferred.git grep -n requireInRoster origin/main -- src agents at 55f821dc90, test files excluded by hand and the survivors read line by line.