Example project — Frond is not real.
Authored demo content for a fictional plant-care app, rendered by the same parsers and held to the same invariants as a real project's dashboard. This is the system in use, three months in.
Tiers
A doc's tier says how guarded it is — what it takes to change it, and nothing else. Tier follows from what the doc is about, not from a rank to climb; most docs sit where their subject puts them.
The four tiers
Most guarded first.
strategy/Vision.md)To change it: Structured challenge — logged whether it succeeds or failsWhen to re-check: Every phase open — reading it is the checkdecisions.md, ROADMAPTo change it: Deliberate — it's a promise, so changing it is a decision and lands in decisions.mdWhen to re-check: At phase boundaries, or when building contradicts it · flagged stale after 90dWhich doc sits where: Structure → Docs
What a tier does not mean
Guarded is about changing, not reading.
Read is not review
Bedrock is the most-read tier and the least-changed one — a foundation's whole job is to be the thing every session aligns to. Guarded means hard to change, never rarely consulted. But reading is how a doc earns a re-check: you read the vision at a phase open, and if it no longer matches the world, that mismatch is what a structured challenge is for. When to read is set by each doc's read-when and its mode's opening ritual, not by tier.
Stamping last-reviewed
It records when someone last confirmed the doc is accurate — not when its bytes last changed. A material edit bumps it, and so does a deliberate check that finds nothing to change (the purest case). A mechanical edit — a ref repoint, a rename, a typo, a link fix — does not: you fixed a token, you didn't read the doc.
No clock on bedrock
A vision untouched for 200 days is a foundation holding, not rot; flagging it would nag us to churn the one thing that shouldn't churn. Bedrock has no timer because it has something better: it is read at every phase open, so a foundation that stopped matching the world gets caught by use, not by a calendar.
When a doc moves
Rare — and never silently.
Sinking — earning a deeper tier
nothing starts at bedrock — docs earn their way down by surviving contact. A working draft that gets built against and holds becomes a commitment; a commitment that holds across phases can sink to bedrock. A sink is recorded in decisions.md with a date and what it survived.
Structured challenge — reopening
requires three things stated up front — the reason, what has changed since it settled, and the proposed revision. Challenges are logged in decisions.md whether they succeed or fail. This applies to everything settled, including this system itself. Two guarantees: if we're re-debating something settled without new information, name the tier and move on; if we keep hitting the same wall against a settled thing, the wall is "what changed" — challenge it.
Tiers govern docs, not coding rules — hard gates (if your project defines any) are rules, not tiers. The tier board renders live at /system/tiers with staleness flags; staleness is a signal to review, not an obligation.