CARLO BELTRAN · THE RECORD
THE DOCTRINE · PUBLIC INDEX OF THE OPERATING RULES

The rules the machine runs on

Four files govern how the work happens. This is their public index — the full texts ship with the replication kit.

WORKING-WITH-AI.md

Working With AI

The operating manual for how a founder and AI tools divide the work of running companies: the AI operates from written rules while the human supplies judgment, relationships, ground truth, and decisions.

The core stance
The AI is the operating layer of the companies, built on one bet: intelligence keeps getting cheaper, so plain-text data and written principles appreciate while software interfaces and feature backlogs decay.
The human's attention is the scarce resource
The founder's commitments live in a governed personal record whose focus view is capped at three items across all of life and ordered only by his explicit decisions; the AI never silently creates or rearranges his obligations, handles everything it can itself, and no message, post, or change to an external system executes without his fresh, one-use approval of the exact action.
Everything is written for a reader with zero context
Every file and document must be understandable by a stranger or a fresh AI session with no memory of the conversation that produced it.
Long-horizon thought becomes principles, not backlogs
Thinking is stored as either a durable principle or an immediate queue item, nothing in between, because the middle of a backlog is where thinking goes to die.
Building is gated, not default
Every build idea passes an explicit gate before scoping and declares its human-facing interface stack before any architecture; data and verbs are permanent while interfaces are disposable, and surfaces showing confidential records stay local while public-facing surfaces carry zero record data.
The AI writes in the founder's voice
External output is drafted plain and pragmatic in Carlo Beltran's voice, and every outbound file is designed to survive circulation: audit-safe ranges instead of single-point claims, no executable know-how, only publicly known facts about counterparties, client surfaces fed reviewed facts never raw internal logs, and every rendered document inspected for visual breathing room before handoff.
Context is framed the way the human absorbs it
Work is presented as ordered workflows and decision packages, real ventures are kept strictly distinct from experiments, and what was observed is separated from what was assumed.
Tooling follows one preference: APIs over puppetry
When the AI needs data it uses scripts and local APIs rather than screen control, states what it is looking for before opening any tool, and keeps runtimes and dev servers under strict discipline.
Correction is promoted to the shared record, not private memory
A correction that proves durable is written into the shared repository with its reason, and correction flows both ways — when the founder's own words contradict ratified doctrine the AI says so inline and proceeds with the corrected meaning unless he explicitly overrides; a tool's private memory may cache a rule but can never be its only home, and instruction files are re-derived from scratch at every review.
Several AIs, one repository
Multiple AI tools share one repository as the common brain, coordinate through boards and commits rather than private notebooks, hold no standing role assignments, pass a bootstrap gate — read the governing sources, name the canonical home — before creating any venture-facing artifact, and keep every promoted workflow (skill) in one canonical home with harness directories holding only pointers.
TASK-DOCTRINE.md

Task Doctrine

A tool-agnostic method for managing commitments, built on two facts: human attention is single-threaded, and commitments accumulate unless something forces removal.

Laws (invariant)
One noun (the commitment, with exactly four fields), four verbs (admit, rank, act, renew-or-kill), a hard cap on the active set, a record readable in about a minute, removal as the default, and every verdict logged with a one-line reason.
Rulings (edge cases)
Dated rulings settle edge cases: recurring work is a renewable series, waiting on others is a commitment with a nudge date, tooling is codified behind real work never ahead of it, and an agent's silence counts as absence of evidence whenever autonomy is weighed.
Parameters (tunable)
The adjustable numbers — cap size, triage cadence, staleness threshold, and the evidence floor a verb must clear before promotion — are set explicitly and never tuned by an agent for itself.
Agent transfer plan
Each verb climbs an autonomy ladder from human-executes to agent-acts-logged-only, promoted or demoted by measured override rates rather than feel, with a standing floor: anything that creates a commitment to another human stays at propose-only until explicitly promoted in writing.
Health checks
Five questions test any implementation — one record, readable in a minute, sets under cap, things still dying, verdicts landing in the log — and a failed check means the tooling gets fixed while the laws stand.
Current bindings (disposable)
The current implementations — a governed personal record as the only person-level authority, a focus projection capped at three, intake that waits for explicit approval before anything becomes canonical, read-only viewing surfaces, per-venture detail records, append-only decision logs, a weekly triage routine, and pre-written agent seats not yet filled — are all replaceable at will as long as the laws stay intact.
NAMING.md

Naming & File Standard

How everything across the ventures gets named, filed, and managed so that a stranger can understand any record with zero context.

The root rule: zero context required
Every name — file, folder, document, record — must be decodable by a stranger or a fresh AI session; if a name needs the conversation to decode, rename it.
Every business record gets three name layers
Each record carries a permanent internal canonical ID, a human-readable public display name, and a recorded list of every informal or historical alias so nothing is ever orphaned.
Recurring work = series + instance
A repeating engagement is one series with dated instances, so repeat work reads as a single relationship instead of scattered jobs.
Date semantics — never a bare date
Every dated field declares which milestone it records (booked, invoiced, collected, executed), and internal sales figures are kept strictly distinct from the accountant's recognized revenue.
Status = a state machine per document type
Each document type owns its own small set of states instead of one mega-lifecycle, and legacy spellings map into those states at ingestion with originals kept verbatim.
Corrections, not edits
Original records are never edited; a correction is a new record naming the field, old value, new value, authority, and date, so every change stays auditable forever.
Issued IDs — one grammar for everything
Everything the house numbers follows one ID grammar of entity, type, scope, and sequence; numbers are minted only where no natural identity exists, and issued IDs never change — when the grammar evolves, old IDs become recorded aliases rather than being renumbered.
Vocabulary locks and record-layer tiers
Each venture locks its public vocabulary in one place with locked terms copied exactly, and the record architecture itself speaks one word per tier — system of record, register, record, registry, ledger, and disposable projections — each assigned by a defined test never by taste, with off-tier usage corrected inline even when the founder's own wording is the source.
Files and skills — creation, naming, lifecycle
One authoritative home per artifact, date-led names for dated documents, revisions kept in version control rather than filenames, sent files archived byte-exact with an append-only ledger, and skill folders named as the verb they perform.
Ruling discipline — re-derive, never inherit
Any ruling that consolidates or restates existing conventions must re-test every carried-forward element as if proposed new today; already-in-use counts only as a migration constraint.
SENSITIVE-DATA.md

Sensitive Data Doctrine

The rule set that keeps personal data about real people encrypted by default: readable on the working machine, ciphertext everywhere else, enforced automatically at commit time.

The mechanism
Protected files are transparently encrypted at the version-control layer — plaintext in the local working copy so every tool works unchanged, ciphertext in every backup — with the decryption key escrowed off the machine.
Tiers
Data is classed in three tiers: personal data about identifiable people (never stored unencrypted), business-confidential material (private storage only), and ordinary content.
Protected paths
The directories holding people records, raw captured communications, and the founder's personal records are enumerated explicitly and encrypted as a class, with the reason for each recorded.
Enforcement — tool-agnostic
A commit-time gate binds every tool and human identically: it blocks protected files that are not actually encrypted, new people or personal paths not yet covered by a protection rule, and any credential in committed content.
Rules for every session
New sensitive material goes only under already-protected paths, a new sensitive path is protected before its first commit, credentials never enter version control at all, encryption is verified rather than assumed, and filenames themselves are treated as data because names are stored in the clear.
Residuals accepted
Known leftover risks — remnants of pre-encryption history and older filename-level exposure — are written down with their acceptance rationale and a remediation path instead of being silently ignored.
doctrine.md — the same text machines read · download · llms.txt
# The doctrine — public index

## Working With AI (WORKING-WITH-AI.md)

The operating manual for how a founder and AI tools divide the work of running companies: the AI operates from written rules while the human supplies judgment, relationships, ground truth, and decisions.

- **The core stance** — The AI is the operating layer of the companies, built on one bet: intelligence keeps getting cheaper, so plain-text data and written principles appreciate while software interfaces and feature backlogs decay.
- **The human's attention is the scarce resource** — The founder's commitments live in a governed personal record whose focus view is capped at three items across all of life and ordered only by his explicit decisions; the AI never silently creates or rearranges his obligations, handles everything it can itself, and no message, post, or change to an external system executes without his fresh, one-use approval of the exact action.
- **Everything is written for a reader with zero context** — Every file and document must be understandable by a stranger or a fresh AI session with no memory of the conversation that produced it.
- **Long-horizon thought becomes principles, not backlogs** — Thinking is stored as either a durable principle or an immediate queue item, nothing in between, because the middle of a backlog is where thinking goes to die.
- **Building is gated, not default** — Every build idea passes an explicit gate before scoping and declares its human-facing interface stack before any architecture; data and verbs are permanent while interfaces are disposable, and surfaces showing confidential records stay local while public-facing surfaces carry zero record data.
- **The AI writes in the founder's voice** — External output is drafted plain and pragmatic in Carlo Beltran's voice, and every outbound file is designed to survive circulation: audit-safe ranges instead of single-point claims, no executable know-how, only publicly known facts about counterparties, client surfaces fed reviewed facts never raw internal logs, and every rendered document inspected for visual breathing room before handoff.
- **Context is framed the way the human absorbs it** — Work is presented as ordered workflows and decision packages, real ventures are kept strictly distinct from experiments, and what was observed is separated from what was assumed.
- **Tooling follows one preference: APIs over puppetry** — When the AI needs data it uses scripts and local APIs rather than screen control, states what it is looking for before opening any tool, and keeps runtimes and dev servers under strict discipline.
- **Correction is promoted to the shared record, not private memory** — A correction that proves durable is written into the shared repository with its reason, and correction flows both ways — when the founder's own words contradict ratified doctrine the AI says so inline and proceeds with the corrected meaning unless he explicitly overrides; a tool's private memory may cache a rule but can never be its only home, and instruction files are re-derived from scratch at every review.
- **Several AIs, one repository** — Multiple AI tools share one repository as the common brain, coordinate through boards and commits rather than private notebooks, hold no standing role assignments, pass a bootstrap gate — read the governing sources, name the canonical home — before creating any venture-facing artifact, and keep every promoted workflow (skill) in one canonical home with harness directories holding only pointers.

## Task Doctrine (TASK-DOCTRINE.md)

A tool-agnostic method for managing commitments, built on two facts: human attention is single-threaded, and commitments accumulate unless something forces removal.

- **Laws (invariant)** — One noun (the commitment, with exactly four fields), four verbs (admit, rank, act, renew-or-kill), a hard cap on the active set, a record readable in about a minute, removal as the default, and every verdict logged with a one-line reason.
- **Rulings (edge cases)** — Dated rulings settle edge cases: recurring work is a renewable series, waiting on others is a commitment with a nudge date, tooling is codified behind real work never ahead of it, and an agent's silence counts as absence of evidence whenever autonomy is weighed.
- **Parameters (tunable)** — The adjustable numbers — cap size, triage cadence, staleness threshold, and the evidence floor a verb must clear before promotion — are set explicitly and never tuned by an agent for itself.
- **Agent transfer plan** — Each verb climbs an autonomy ladder from human-executes to agent-acts-logged-only, promoted or demoted by measured override rates rather than feel, with a standing floor: anything that creates a commitment to another human stays at propose-only until explicitly promoted in writing.
- **Health checks** — Five questions test any implementation — one record, readable in a minute, sets under cap, things still dying, verdicts landing in the log — and a failed check means the tooling gets fixed while the laws stand.
- **Current bindings (disposable)** — The current implementations — a governed personal record as the only person-level authority, a focus projection capped at three, intake that waits for explicit approval before anything becomes canonical, read-only viewing surfaces, per-venture detail records, append-only decision logs, a weekly triage routine, and pre-written agent seats not yet filled — are all replaceable at will as long as the laws stay intact.

## Naming & File Standard (NAMING.md)

How everything across the ventures gets named, filed, and managed so that a stranger can understand any record with zero context.

- **The root rule: zero context required** — Every name — file, folder, document, record — must be decodable by a stranger or a fresh AI session; if a name needs the conversation to decode, rename it.
- **Every business record gets three name layers** — Each record carries a permanent internal canonical ID, a human-readable public display name, and a recorded list of every informal or historical alias so nothing is ever orphaned.
- **Recurring work = series + instance** — A repeating engagement is one series with dated instances, so repeat work reads as a single relationship instead of scattered jobs.
- **Date semantics — never a bare date** — Every dated field declares which milestone it records (booked, invoiced, collected, executed), and internal sales figures are kept strictly distinct from the accountant's recognized revenue.
- **Status = a state machine per document type** — Each document type owns its own small set of states instead of one mega-lifecycle, and legacy spellings map into those states at ingestion with originals kept verbatim.
- **Corrections, not edits** — Original records are never edited; a correction is a new record naming the field, old value, new value, authority, and date, so every change stays auditable forever.
- **Issued IDs — one grammar for everything** — Everything the house numbers follows one ID grammar of entity, type, scope, and sequence; numbers are minted only where no natural identity exists, and issued IDs never change — when the grammar evolves, old IDs become recorded aliases rather than being renumbered.
- **Vocabulary locks and record-layer tiers** — Each venture locks its public vocabulary in one place with locked terms copied exactly, and the record architecture itself speaks one word per tier — system of record, register, record, registry, ledger, and disposable projections — each assigned by a defined test never by taste, with off-tier usage corrected inline even when the founder's own wording is the source.
- **Files and skills — creation, naming, lifecycle** — One authoritative home per artifact, date-led names for dated documents, revisions kept in version control rather than filenames, sent files archived byte-exact with an append-only ledger, and skill folders named as the verb they perform.
- **Ruling discipline — re-derive, never inherit** — Any ruling that consolidates or restates existing conventions must re-test every carried-forward element as if proposed new today; already-in-use counts only as a migration constraint.

## Sensitive Data Doctrine (SENSITIVE-DATA.md)

The rule set that keeps personal data about real people encrypted by default: readable on the working machine, ciphertext everywhere else, enforced automatically at commit time.

- **The mechanism** — Protected files are transparently encrypted at the version-control layer — plaintext in the local working copy so every tool works unchanged, ciphertext in every backup — with the decryption key escrowed off the machine.
- **Tiers** — Data is classed in three tiers: personal data about identifiable people (never stored unencrypted), business-confidential material (private storage only), and ordinary content.
- **Protected paths** — The directories holding people records, raw captured communications, and the founder's personal records are enumerated explicitly and encrypted as a class, with the reason for each recorded.
- **Enforcement — tool-agnostic** — A commit-time gate binds every tool and human identically: it blocks protected files that are not actually encrypted, new people or personal paths not yet covered by a protection rule, and any credential in committed content.
- **Rules for every session** — New sensitive material goes only under already-protected paths, a new sensitive path is protected before its first commit, credentials never enter version control at all, encryption is verified rather than assumed, and filenames themselves are treated as data because names are stored in the clear.
- **Residuals accepted** — Known leftover risks — remnants of pre-encryption history and older filename-level exposure — are written down with their acceptance rationale and a remediation path instead of being silently ignored.