Every control you own lives in one of three contexts. The charter says what this project is about, the harness says how a turn happens, the factory says how work ships. Each holds different levers, changes at a different rate, and answers to a different team. The two boundaries agree almost everywhere, and the one place they disagree is where you spend all your arguments.
Three contexts, the levers in each, and the one-way arrow between them that most designs point backwards.
Six places a gate can physically sit, plus two that sit off the ladder. One rule, shown at three of them.
Where the ownership line follows the context line, where it does not, and the rule that makes the overlap survivable.
What is this repository about?
Claims about one codebase, written by the people inside it. Changes constantly.
How does a turn happen?
The shape of the work the agent does, everywhere it runs. Changes rarely.
How does work ship?
Ordering, gates and the record, shared across every repository. Changes very rarely.
rule · hook · skill
command · agent
predicate · convention
changes constantly
prompt · tool · policy
budget · context
phase
changes rarely
stage · gate · guard
ordering · record
changes very rarely
An eval belongs to none of them and can sit in all three, because it measures what no rule can decide and it changes whenever the thing it measures does. Give it the lifecycle of its subject, never the lifecycle of its context.
A model reads the work and returns a verdict. It decides what no predicate can express, it costs tokens, and it can be wrong in two directions: by missing a violation, and by inventing one.
Code reads the work and settles it. Exact, cheap at every call, and blind to everything it cannot parse. It never surprises you, which is both halves of the trade.
# rung 0 · charter · development writes it, development deletes it "Every outbound HTTP call goes through lib/http. No direct requests." # rung 3d · harness · platform ships the predicate, development registers the rule deny(Edit) if adds_import("requests") and path not under "lib/http/" # rung 4d · factory · platform owns it, and nothing in the turn can reach it stage_gate: grep -rn "^import requests" --include=*.py | reject_outside lib/http
One sentence, and the owner changes twice on the way down. Nobody writes all three, and none of the three files mentions that the other two exist.
What does this thing govern? One project, one turn, or one delivery. I have written before that this line has nothing to do with ownership, and that is still true.
Who can change it, and who gets paged when it is wrong? A second line, laid over the first, and answered by a different fact about your org.
Rules that describe no repository in particular. The tell: a charter nobody has edited in a quarter, in a codebase that ships weekly.
The gate sits inside its own blast radius. The tell: a gate with a perfect record, which usually means it has never been allowed to refuse.
Every other repository inherits an opinion it never asked for. The tell: a policy with one team's service name written inside it.
The harness stops running on a laptop. The tell: a developer cannot answer what their own rules do to a single turn.
This project, a turn, or a delivery. That answer picks the context, and it is a fact about the rule rather than about your team.
That answer picks the owner. Ask it separately, out loud, because the two answers come apart in the harness and nowhere else.
Not whether they would. Whether they can. If they can, you own a convention, and you should stop calling it a gate.
Pick one rule your team argues about. Name the context it governs, then name who gets paged when it is wrong, and write both down where the other team can read them. If those two answers land on the same group, the rule is already home. If they do not, you are in the harness, and now you know what the argument was about.
contexts, families, both ladders
one rule at six rungs, measured
permissions, and where they bite