Nishi FamilyCompare › Developer Guardrails and the Agentic Control Plane

Nishi Compare · full-field SOTA · measured, not asserted

Developer Guardrails and the Agentic Control Plane

Nishi vs the full field — every axis measured or researcher-sourced, grouped by category; each strip shows the whole field at a glance.

Gates, Teeth, Probes, Telemetry, Accelerators + the MCP swarm/hive/hub-spoke layer. 11 competitors, 26 axes. Nishi cells name the organ that proves them; where nothing proves it the cell is No, not Part.

How this is scored. This is a state-of-the-art comparison across the FULL competitor field: quantitative axes carry measured / published numbers (Nishi’s column is our own measurement, competitors are researcher-sourced), grade axes use Best / Yes / Part / No. Every axis carries a source note. No single vanity ‘coverage’ score — the honest picture is per-axis. Where Nishi is under SOTA, that is filed work with an owner, never ‘by design’ (operator law: less-than-SOTA is never design) — every sub-SOTA axis maps to a frontier rung; the only legitimate divergence from the field is a measured exceed bet that carries its number (e.g. no-float determinism). The climb is the plan.
field, strip order:GitHubActionsGitLabCIJenkinsSonarQubeSemgrepSnykDatadogOpenTelemetryBackstageLaunchDarklyKubernetes·BestYesPartNo

Measured stakes (quantitative)

Agent-callable guardrail tools exposed over MCP

Nishi MEASURED 2026-08-14 by nx_capsearch's own corpus count (considered=1028); every one is ocap-gated and callable by an AI seat with an attenuated token. Peer columns reflect published MCP-server availability as of 2026-08 [mcp-spec], not tool counts, which are not comparable across products

GitHubActions MCP server (2025+)GitLabCI MCP serverJenkins plugins, no MCPSonarQube limitedSemgrep limitedSnyk limitedDatadog MCP serverOpenTelemetry n/a specBackstage pluginsLaunchDarkly SDK/APIKubernetes kubectl-ai era

1028 registered
Nishi, measured
Guardrail gates: sources / deployed / actually invoked

Nishi MEASURED 2026-08-07 by nx_gatesubj + nx_biteall over the whole tree. Published deliberately: 2,287 gate sources nothing invokes is the estate's largest honest gap, and 0 invocation gaps means every gate anything runs is deployed and byte-identical to source

GitHubActions n/a (workflow files)GitLabCI n/aJenkins n/aSonarQube rulesetsSemgrep rulesetsSnyk rulesetsDatadog monitorsOpenTelemetry n/aBackstage n/aLaunchDarkly flagsKubernetes admission ctl

2317 / 135 / 30
Nishi, measured
Automated beats under a dead-man switch

Nishi MEASURED 2026-08-14 via nx_cron_watch: each beat's evidence log carries a heartbeat and a max-age; a missed beat becomes STALE rather than silently absent. Peers schedule work but rarely ship the freshness assertion itself

GitHubActions schedulesGitLabCI schedulesJenkins timersSonarQube n/aSemgrep n/aSnyk n/aDatadog monitorsOpenTelemetry n/aBackstage n/aLaunchDarkly n/aKubernetes CronJob

15 watched, 0 stale
Nishi, measured
Deploy rollback on failed health check

Nishi never-brick promote: health-checked, .prev-banked, auto-rollback, verified live this session (DEPLOYED-GREEN after a daemon self-deploy). LaunchDarkly's flag flip is the fastest human-facing undo in the field and is graded Best for that reason

GitHubActions manual/actionGitLabCI manualJenkins manualSonarQube n/aSemgrep n/aSnyk n/aDatadog n/aOpenTelemetry n/aBackstage n/aLaunchDarkly instant flag flipKubernetes rolling undo

automatic, proven
Nishi, measured

Quality Gates (the blockers)

Pipeline runs automated tests on every change

Every compiler promotion passes nx_cc_equiv_gate (10 differential rows + a self-host fixpoint) and a 49-cell gauntlet before the canary door; hosted CI is the industrial bar for breadth and parallelism

YES
Merge/branch protection with required approvals

NO BRANCHES to protect: the substrate is content-addressed and promotion is gated at the artifact, not the ref [gh-branch-protection]. Honest No -- and the sovereign git host is DOWN and unsupervised (filed), so this is a real gap, not a design flourish

NO
Change freeze / high-risk window blocking

Nothing implements a freeze window. LaunchDarkly-class kill switches are the bar. Filed, not designed away

NO
Pre-deploy safety gate that can refuse the deploy

/api/deploy runs a pre-deploy gate and reports DEPLOY-SAFE with a blocker count before promoting; the promote door separately refuses on a digest mismatch, a capability-loss diff, or a backwards artifact

YES
Artifact identity verified before promotion

expect_sha256 is REQUIRED on promote: it refuses unless the staged bytes are exactly the ones the caller verified, which is the only check that catches a same-size substitution. Sigstore-class signing is the nearest peer practice [sigstore-docs]

YES

Teeth (the enforcers)

Style/format enforced mechanically

No canonical formatter exists -- gofmt is the bar and this is a filed rung, not a stance

NO
Static analysis blocks the build on findings

nx_cwe_scan + nx_secret_scan_gate + nx_srclint exist and the secret gate is currently RED and uninvoked (filed); Semgrep/Snyk are the bar for rule breadth and CVE currency

PART
Compiler refuses silently-wrong constructs

The deepest teeth here and no peer's equivalent: the compiler refuses float-into-integer stores at all six store sites, out-of-range constant shifts, discarded pure expressions, non-exhaustive matches, wrong call arity and both directions of pointer/integer confusion -- each with a 5W plus H message naming the fix. A linter suggests; this refuses. EVIDENCE (this cell carried none until 2026-08-14): nx_langdiag_gate runs the whole language-diagnostic probe corpus, 11 rows GREEN, with in-tree witnesses per refusal (nx_probe_ub_shift.nx for the constant over-shift); each refusal stamps a greppable capability slug at the point of friction -- capability=shift-count-range is emitted from nx_parse.nx:3853 and asserted by the gate, so the claim is checkable at a line number rather than described

BEST
Refusals are pinned to the rule that fired

nx_langdiag_gate asserts each refusal names ITS OWN rule or capability slug, bite-proven by planting a slug the rule never prints (exit code matched, reason did not). Most suites assert only that something failed -- blind by construction, and this estate had that hole until 2026-08-14

BEST
Dependency/package license compliance

Zero third-party packages by doctrine, so nothing scans them; source carries license_tier headers and nx_licgate exists. Graded No because the CHECK is absent, not because the risk is

NO
Mutation testing proves the teeth can bite

nx_gate_bite plants known-bad mutants and demands RED; a gate that has only ever passed is unverified. Essentially absent from mainstream CI practice

BEST
Software bill of materials emitted per build

No SBOM is produced. Zero third-party packages makes the inventory trivial to state and that is exactly why nothing states it -- an unstated inventory is not an attested one. Syft/Snyk-class output is the bar [spdx-spec]

NO
Container or image vulnerability scanning

Nothing scans a shipped artifact for known CVEs. nx_nvd_ingest pulls the feed but no organ joins it to what we run

NO
Policy-as-code evaluated at admission

No OPA/rego-class policy engine; guardrails are hand-written organs, so a new policy is a build rather than a rule. Kubernetes admission control is the bar [k8s-admission] and the 2026 MCP literature specifically names AI-updated global policy as the pattern to reach for

NO
SLOs with error budgets driving release decisions

Nothing defines an SLO or an error budget, so nothing can burn one [sre-slo]; resource envelopes are asserted per change but not tracked against a target

NO
Alert routing and on-call escalation

Gates write durable verdict logs and a dead-man switch flags a stale beat, but no alert reaches a human -- a RED at 3am waits for a seat to read it

NO
Continuous profiling in production

Absent. Resource counters are sampled per beat; there is no CPU/heap profile attributable to a code path

NO
Real user monitoring from the client side

Absent by posture as much as by gap -- the surfaces ship zero third-party script and no telemetry beacon, so field performance is inferred from synthetic checks only

NO

Probes (the observers)

Synthetic user-journey checks

nx_page_verify is browser-grade (TLS handshake, asset fetch, PNG deep-decode, a11y-lite) and runs on the publish beat; Datadog Synthetics is the bar for geographic breadth

YES
Liveness checks on running services

Health-checked restart plus a supervisor guard and hostctl sentinel on a 1-minute beat; Kubernetes liveness probes are the bar [k8s-probes]

YES
Readiness gating before traffic

Deploy waits on a health check and rolls back, but there is no separate readiness signal that holds traffic; Kubernetes is the bar [k8s-probes]

PART
Probe corpus is native and self-asserting

The language-probe corpus runs as a NishiLang gate that asserts exit code AND the required diagnostic substring, with acceptance rows as the discrimination control and an UNRESOLVED third state when the subject is missing. It replaced hand-written shell scripts on 2026-08-14

YES

Telemetry (the monitors)

Resource metrics collected and acted on

CORRECTED 2026-08-14: this row previously claimed a per-minute beat. MEASURED against the live clocksched- plane: nx_procchurn 300s and nx_resgov 600s were on the clock, nx_resmon had NO ROW AT ALL, and no cadence was verified for nx_ctxtop. A COMPARE ROW IS A CLAIM, NOT A MEASUREMENT. Now declared: resmonbeat 300s (matching procchurn, its closest analogue -- both are /proc censuses) and memvelbeat 240s. Its leak axis is now VELOCITY-based (nx_memvel's sustained-grower count over N windows) rather than the VmSize==VmPeak SNAPSHOT, which cannot express growth at all, flagged the arena-once leak-FREE design as a leak, and therefore held this organ RED PERMANENTLY at 17 suspects against a red threshold of 6 while the true sustained count was 0. Stale or absent velocity data degrades the axis to UNOBSERVABLE, which casts no vote in either direction. resmon.log is append-only and unbounded, so it is now watched by nx_sizeguard at the sibling's proven budget (1 MiB / 20000 lines) -- fail loud before a reader truncates, never rotate, because nx_jrnlguard correctly treats a shrinking journal as a clobber. Measured attribution proved NAS churn was DSM, not the estate. Datadog is the bar

YES
Structured event logs with durable evidence

Every gate writes its own timestamped verdict log because a RED that lands in a vacuum is not a measurement; the actlog journal mines tool/verb frequency

YES
Distributed tracing across services

No trace context propagation exists. OpenTelemetry is the standard [otel-spec] and this is a genuine absence

NO
Telemetry feeds the roadmap automatically

The loop no peer ships: capability-limit refusals stamp greppable capability slugs at the moment of friction, /api/build appends them to a durable demand journal, and the mine re-ranks the build order from real usage. Refusal to roadmap with no human in the circuit. EVIDENCE (this cell carried none until 2026-08-14): the journal is knowledge/status/lang_demand.jrnl -- epoch, slug, target; append-only, bounded at 8 rows per build, and it can never fail a build. LIVE-BITTEN 2026-08-13: a single refused build wrote its 3 rows the moment it failed, which is the whole loop demonstrated end to end rather than asserted

BEST

Accelerators (the enablers)

Ephemeral per-change environments

Absent: risky daemons are tested on a spare port by hand. Filed

NO
Feature flags separate deploy from activation

Config-driven switches exist (opt-in debug emission, an opt-out crash guard, conf-gated lanes) but there is no flag service with targeting or instant kill; LaunchDarkly is the bar

PART
Service catalogue with ownership and status

nx_catalog answers is-it-there-and-is-it-WIRED across the full chain -- source, built, staged, promoted, registered, authorised, invoked -- with a weakest-link verdict. Backstage is the field bar for humans; this one is machine-readable and it is how the unregistered addr2line binary was found

PART

The agentic control plane (MCP swarm / hive / hub-and-spoke)

Guardrails callable by an AI agent over MCP

The entire build-gate-promote-deploy loop is driven by an AI seat over MCP [mcp-spec] in this very session; peers expose an MCP server over a product, not a whole sovereign ops plane

BEST
Least-authority capability tokens for agent access

X-Nishi-Cap ocap tokens [capmyths03]: attenuate-only, scoped per tool, expiring, revocable by nonce, every delegation audited to a consent log, and fixed-arg pinning so a hostile argv cannot escalate a pinned tool. The MCP ecosystem's own 2026 literature names secrets brokering and agent authorisation as its top unsolved risk. EVIDENCE (this cell carried none until 2026-08-14): least-authority was PROVEN live 2026-07-08 -- a read-scoped cap presented to nx_mgmt is denied with reason 4 while the same cap serves its own tools, and fixed-arg pinning was demonstrated by handing nx_status a hostile [selfswap] argv which it ignored in favour of the pinned sub. Every delegation is appended to cap_consent.log, and revocation is by nonce against cap_revoked.list

BEST
Hub-and-spoke publishing with self-healing spokes

One upsert call updates the hub from the sovereign registry; 48 domain spokes re-measure and republish on a 6-hourly beat, and an orphan census reconciles docroot directories against the roster with parts that must sum. EVIDENCE (this cell carried none until 2026-08-14): the census MEASURED census dirs=71 matrix=50 radar=7 hand=14 ORPHANS=0 parts-sum OK on the 2026-08-14 beat -- a printed partition that reconciles, which is the difference between claiming no sprawl and showing that the parts add up to the population

BEST
Hive queue: workstream contracts that flip themselves

Watch contracts named for a not-yet-existing symbol are measured every emit, so a page flips from OPEN to LANDED the moment the organ ships -- proven twice with real ships, zero hand edits, and the contracts are stored as sovereign plane rows that double as the PM intake queue

BEST
Swarm: distributed agent work placement

A swarm family exists (admit, coord, place, job, heal, shardserve) and seat coordination runs over a workstream plane with leases and checkin/checkout; Kubernetes scheduling is the bar for maturity

PART
11 competitors38 axes4 quantitativeNishi Best on 8
Honest verdict. This estate is strongest exactly where the field is weakest -- the agentic control plane -- and genuinely behind on the human-team surfaces it has never needed. Structural exceeds no competitor carries: the whole guardrail chain is ocap-secured and agent-callable over MCP (1,028 registered tools, attenuate-only capability tokens, every delegation audited), deploys are never-brick by construction (health-checked promote with automatic rollback, proven live), and the comparison surface you are reading re-measures and republishes itself on a 6-hourly beat with an orphan census that refuses to let a page drift. The teeth are real and unusually deep for a solo estate: a differential-equivalence net gates every compiler promotion, a 49-cell gauntlet is mutation-proven, and refusals are pinned to the RULE THAT FIRED rather than merely to a non-zero exit. Where it is behind, it is behind honestly and the reasons are structural, not accidental: there is no branch protection because there are no branches (content-addressed substrate, and the sovereign git host is currently down and unsupervised), no distributed tracing, no ephemeral per-change environments, no package-license scanning, and no canonical formatter. The largest measured gap is not capability but ADOPTION -- 2,317 gate SOURCES exist, 135 are deployed and only 30 are actually invoked by anything, so the estate is paying for measurements it does not collect. That number is the roadmap, and it is published here rather than hidden. This page's own first draft failed the honesty gate and that is worth stating plainly: it claimed twelve Bests against six Nos, and the generator refused to publish a sheet whose absences did not outnumber its wins. Re-grading pulled four cells down to Yes or Part -- a pre-deploy gate and an artifact-digest check are strong but sigstore-class signing and hosted environment approvals are peers, not inferiors -- and it forced the enumeration of seven gaps that had simply been skipped: no SBOM, no image scanning, no policy-as-code, no SLOs or error budgets, no alert routing, no continuous profiling, no real-user monitoring. Those are now rows on this page instead of absences from it.

Person · product · place — not yet measured for this domain

Every compare carries this layer. Declare knowledge/compare/devguardrails.ppp (rows surface|nishi or c1..c4|label|url|connect naming OUR live surface and each rival's front door), run nx_ppp_probe domain devguardrails, and this section fills itself on the next beat: the same ruler on both sides — privacy and CX (third-party hosts, tracker classes, cookies, security headers), design and longevity (design hygiene, computed WCAG contrast, render-blocking resources, unsized media, script weight, theme and motion queries), findability (landmarks, skip link, on-site search, breadcrumb, headings, internal links).

References

Beyond a link list. Every reference below resolves twice — the publisher's copy and, where banked, the estate's own non-rottable library mirror with a content pin — and carries its evidence class plus the exact claim on this page it grounds. Keyed marks like [key] in the axis notes jump here. A dash means honestly absent, never assumed.
  1. [mcp-spec] Model Context Protocol Specification, revision 2025-06-18: JSON-RPC 2.0 hosts/clients/servers, tools, resources, prompts, and the Security and Trust and Safety principles (user consent, tool safety, least-privilege guidance). publisher · read in our library knowledge/fetched/cmp_devguardrails_mcp-spec.html · pin h57308609c176192e9a3561fe8d8115235aab6bb72234463b8ff66c7e67ff84af · accessed 2026-08-18 · published-standardGrounds: The "Agent-callable guardrail tools exposed over MCP" and "Guardrails callable by an AI agent over MCP" rows: the protocol every column's MCP-server cell is graded against, and its own security section names consent and tool-authorization as implementor obligations -- which the ocap-token row answers by construction.
  2. [otel-spec] OpenTelemetry Specification (opentelemetry.io/docs/specs/otel): the vendor-neutral standard for traces, metrics, logs and context propagation. publisher · read in our library knowledge/fetched/cmp_devguardrails_otel-spec.html · pin hfb7ab28ec4e393f3d5c1ffe9173e2fc5d38bbe46aa6725144218fea9314c0c2f · accessed 2026-08-18 · published-standardGrounds: The OpenTelemetry column and the "Distributed tracing across services" row (Nishi n): OTel context propagation is the standard that row names as a genuine absence here.
  3. [k8s-probes] Kubernetes documentation: Configure Liveness, Readiness and Startup Probes -- kubelet-driven liveness restarts and readiness gating of traffic. publisher · read in our library knowledge/fetched/cmp_devguardrails_k8s-probes.html · pin h2c91059571135379613836c808ab83040714818126088e3dd3b200f5accd1c93 · accessed 2026-08-18 · vendor-docGrounds: The Kubernetes column on "Liveness checks on running services" (B) and "Readiness gating before traffic" (B): the probe semantics those Best codes cite; ours has health-checked restart but no separate readiness signal that holds traffic.
  4. [k8s-admission] Kubernetes documentation: Admission Controllers Reference -- validating and mutating admission that intercepts API requests before persistence. publisher · read in our library knowledge/fetched/cmp_devguardrails_k8s-admission.html · pin h901cf891e255ac593d5865bcd24d95ba29279c79f6bb56290c28b8a75183e6fe · accessed 2026-08-18 · vendor-docGrounds: The "Policy-as-code evaluated at admission" row: Kubernetes admission control is the named bar (B); our guardrails are hand-written organs, so a new policy is a build rather than a rule.
  5. [sre-slo] Beyer, Jones, Petoff, Murphy (eds.). Site Reliability Engineering, chapter Service Level Objectives (Jones, Wilkes, Murphy, Smith): SLIs, SLOs and the error budget as the rate at which SLOs may be missed. publisher · read in our library knowledge/fetched/cmp_devguardrails_sre-slo.html · pin h449fb54ce65e05102fac46c797a08b86c5ab93ade2c70c63ae25e7648d687d7d · accessed 2026-08-18 · published-courseGrounds: The "SLOs with error budgets driving release decisions" row (Nishi n): the definition of SLO and error budget that row measures against; nothing here defines an SLO so nothing can burn a budget.
  6. [sigstore-docs] Sigstore documentation: keyless signing with cosign, Fulcio certificate authority and the Rekor transparency log for software artifacts. publisher · read in our library knowledge/fetched/cmp_devguardrails_sigstore-docs.html · pin h008286126a95de87c85a13073dbc269d3c0c62afdbdc244c98eec9d7f2460728 · accessed 2026-08-18 · vendor-docGrounds: The "Artifact identity verified before promotion" row: the re-grade note names Sigstore-class signing as the nearest peer practice to expect_sha256-required promotion; this is what that peer is.
  7. [spdx-spec] SPDX (System Package Data Exchange) Specification 3.0.1, The Linux Foundation: the software bill of materials data model and serialization. publisher · read in our library knowledge/fetched/cmp_devguardrails_spdx-spec.html · pin ha905ca11b54700955ba92b4dbdf9d35553852b82bfddf2fabc06cabc194e120a · accessed 2026-08-18 · published-standardGrounds: The "Software bill of materials emitted per build" row (Nishi n): the SBOM format the Syft/Snyk-class bar emits; an unstated zero-dependency inventory is not an attested one, and this is the attestation shape.
  8. [gh-branch-protection] GitHub Docs: About protected branches -- required status checks, required pull-request reviews and approvals, linear history, force-push restrictions. publisher · read in our library knowledge/fetched/cmp_devguardrails_gh-branch-protection.html · pin hf18b62d250903fa0059c6b04fa7ff32354e770b389fa4de64076cdf03a3453e7 · accessed 2026-08-18 · vendor-docGrounds: The GitHubActions column on "Merge/branch protection with required approvals" (B): the vendor's own definition of the control the row grades Nishi n against -- no branches to protect, promotion gated at the artifact instead.
  9. [capmyths03] Miller, Yee, Shapiro. Capability Myths Demolished. Johns Hopkins University Systems Research Laboratory technical report SRL2003-02, 2003 (mirror: Agoric papers). publisher · read in our library knowledge/fetched/cmp_devguardrails_capmyths03.pdf · pin hb6a3e04e60d7ef08d32900143f8e93acbdcb62e2b63160b604591d7a021f7f42 · accessed 2026-08-18 · published-paperGrounds: The "Least-authority capability tokens for agent access" row (Nishi B): the object-capability model whose seven properties (attenuation, revocability, confused-deputy resistance) the X-Nishi-Cap attenuate-only, nonce-revocable, fixed-arg-pinned tokens implement; the ACL-vs-capability distinction the row's peers lack.

Generated by nx_swcompare_sota from knowledge/compare/devguardrails.sota — quantitative axes measured/sourced; researcher-fed (nx_swcompare_research). Zero JS, zero trackers.

Where we are. Shipped and measured, and genuinely ahead of the field: the whole build-gate-promote-deploy loop is agent-callable over MCP under attenuate-only capability tokens [capmyths03], deploys are never-brick with health-checked promote and automatic rollback, the compare surface re-measures and republishes itself on a beat with an orphan census whose parts must sum, and the bounded-read discipline is real -- nx_fs declares its own truncation in the payload and a PostToolUse warner restates the bound so a partial read cannot be quoted as a census. That envelope behaviour is the estate at its best and nothing in this plan weakens it. What is MISSING is the layer underneath: the guard plane that enforces all of this cannot state its own health, the seat is held to laws whose enforcing organs it is not granted, and this domain -- the one that measures the agentic control plane -- had no plan at all, so the ranker structurally refused it and the tool plane was the only major surface in the estate with no computed build order. MEASURED 2026-08-22 by full enumeration of the compare data directory, 349 of 349 entries with truncated=0: devguardrails carried a refs file and a sota sheet and neither a matrix nor a plan. cleanserve is in the same state and is named here so the next reader does not have to re-derive it.

Where we need to go. Make the seat-facing tool plane as honest about itself as the surfaces it guards. Every rung below converts one currently-invisible failure into a row that is emitted whether or not anyone asks: a hook that times out is counted against attempts rather than logged into a denominator-free void, a law that mandates an organ also grants it, a per-call tax is bounded and named, and this domain becomes rankable so the order of the remaining work is computed from the boards rather than chosen by a seat.

The unit. 1 u = one measured session-leg (organ plus gate plus live flip), the pmdash and charsim calibration used across the estate.
Where are we: 6 open rungs and 1 landed. The agentic control plane is the estate's strongest surface and its own guard plane is the least instrumented thing in it. Counts measured at emit below this line.
Cost to a guard plane that can state its health: 2.5 u. DG1 the attempt counter and DG2 the two-cause collapse. These are the cheapest rungs and the two that stop a silently-suppressed hook from reading as a working one.
Cost to a seat that can reach its own laws: 1.5 u. DG3 the capability floor and DG4 the bounded per-call tax. Both are configuration and wrapping, not new capability, and DG3 unblocks the rank proof this very file could not produce.
Cost to a rankable and adopted tool plane: 3 u. DG5 the watch-contract matrix and DG6 the gate-adoption adjudication, which is the estate's own largest published gap.
RungCloses withDefinition of done (pre-declared)ExecutorEst.
This domain becomes rankable (DG0)dg_plan_admittedLANDED by this file. devguardrails had a refs register and a sota sheet but no plan, proven by full enumeration of buildroot knowledge compare at 349 of 349 entries with truncated=0, so nx_compare_rank refused it and no build order existed for the tool plane. HONEST LIMIT declared rather than hidden: the rank proof itself is BLOCKED, because nx_compare_rank is not in this seat's capability set -- which is precisely rung DG3, so the blocker for proving this rung is itself a rung on this boardOrgan0 u
The guard plane states its own health (DG1)wg_attempt_counterThe hook guard writes its evidence log ONLY at condemnation sites -- Write-GuardLog is called at the SKIP-ORGAN and TIMEOUT-ORGAN branches and nowhere else, and the script's own header enumerates every logged verdict as a refusal. MEASURED 2026-08-22 over the whole file: 1067 recorded events across 2026-08-10 to 2026-08-22, partitioning exactly as 474 TIMEOUT-ORGAN plus 216 SKIP-ORGAN plus 159 SKIP-VM plus 152 SKIP plus 44 RESET-ORGAN plus 12 TIMEOUT-VM plus 4 TIMEOUT plus 3 RESET plus 2 LAUNCH-FAIL plus 1 RESET-VM, which sums to 1067 with no residual. There is no success call site, so 1067 is a COUNT OF REFUSALS AND NOT A RATE, and hook health is structurally uncomputable -- the estate's own law that every aggregate assertion binds to its denominator, violated in the plane that enforces the estate's laws. ACCEPT: attempts are counted alongside refusals so a rate exists, two consecutive windows reconcile, and a deliberately forced timeout raises attempts and refusals by exactly one eachOrgan1 u
The timeout worklist collapsed to its two causes (DG2)
after DG1
wg_stop_budgetA count without a worklist is not actionable, and a worklist that is not collapsed to causes adjudicates one edit N times. MEASURED 2026-08-22 over the whole log: the 474 organ timeouts are 286 nx_worklog_stop and 134 nx_memplane_run, so TWO Stop-hook organs are 420 of 474 or about 886 permil, and every other subject is 24 or fewer. A live instance was open during this very session, with nx_truncwarn breaker-open and its age climbing from 77 to 139 seconds while being repeatedly skipped -- so the truncation warner the operator had just seen fire was suppressed minutes later. Per-organ extraction differs from the verdict tally by one row because the two counts read different fields, stated rather than smoothed. ACCEPT: both dominant organs complete inside their budget on a real turn, measured on the turn and not on a fixture, or the slow leg moves off the blocking path -- and the fix is proven by the breaker for those keys staying closed across a full sessionOrgan1.5 u
The seat can reach the laws it is held to (DG3)cap_law_floorThe measurement law requires that absence is never asserted from a filtered read and that nx_absent is the organ that proves it. MEASURED 2026-08-22: nx_absent returns capability denied to this seat, and so does nx_compare_rank, the roadmap ranker. The seat is therefore mandated to prove absence with a tool it is not granted, and told to work from the ranked board while unable to ask for the ranking. This is the governor-privilege inversion the estate already banked against a build governor, recurring on the absence-prover and the ranker, and a read-only census is not a privileged act. THIS IS THE FOURTH INDEPENDENT REDISCOVERY OF ONE UNFIXED DEFECT AND NOT A NEW FINDING, so the priors are named here to stop the next reader repeating the investigation: 1785028986 measured register-then-use as a two-actor operation with a manual mint step, 1785436247 measured the entire body and anatomy organ family absent from the standing allow-set, and 1786115553 measured the discovery tools themselves ungranted. That last row also records the CONSEQUENCE this operator report independently reproduced from the outside -- a seat that hits a cap wall on its first probe reaches for shell, which the row names as a concrete driver of the estate's shell-usage rate, so the felt badness of the tool surface and this capability gap are the same defect seen from two ends. The fix shape is known and is not a wider token: the any-grants presenter in nx_tools_api already collects the body capability, the X-Nishi-Cap header, the Bearer header and the query capability and lets the FIRST ONE THAT GRANTS win, and minting everything at once was already refused as allow-too-long at 60 tools, so the remedy is a third scoped read-only capability alongside the two that exist. The refusal text is otherwise exemplary -- it names the exact mint call and tells the caller not to fall back to shell [@mcp-spec]. ACCEPT: a seat holding the standard read capability can run the absence-prover and the ranker, a write or admin operation still refuses from that same capability, and the negative control is that an unminted capability is still deniedOrgan1 u
The per-call hook tax is bounded and named (DG4)wg_wrap_costwardenEvery other hook on this host runs under the wsl guard, which bounds it five ways and fails open. The PreToolUse hook matching every nishi MCP call does NOT -- it is raw inline PowerShell with no guard wrapper and no timeout, spawning a process and taking a named mutex on EVERY tool call. MEASURED this session: two Thread failed to start errors and one No stderr output from that hook, and the same host exhaustion reached the seat's own tooling when a Bash call failed with uv_spawn while 330 processes were live. ACCEPT: the hook runs under the same bounded launcher as its siblings, a spawn failure degrades to silence rather than to an error banner in the operator's transcript, and the cost of the hook per call is measured and published rather than assumedOrgan0.5 u
Watch contracts for the tool plane (DG5)
after DG0
dg_matrix_admitThis domain renders from a sota sheet only, so it has no matrix and therefore no watch contracts, and a rung here cannot flip itself when its organ ships -- every status on this board is a hand assertion until it does. Admit a devguardrails.matrix whose gap rows name each open symbol on this plan as an absent-symbol watch contract, so the page re-measures itself on the beat like every other hive domain. ACCEPT: each open rung symbol on this plan resolves to exactly one matrix row, a planted symbol flips its row from open to landed on the next emit with zero hand edits, and the flip is recorded as the receipt and never quoted as the proof of the rung's done-ruleOrgan1 u
Gate adoption adjudicated rather than rebuilt (DG6)
after DG5
ga_adjudicateThe sota sheet already publishes the estate's largest honest gap, and publishing it is not closing it: 2317 gate sources exist, 135 are deployed, 30 are actually invoked, and there are 0 invocation gaps -- so every gate anything runs is deployed and byte-identical to source, and the problem is 2287 sources nothing invokes plus 105 deployed binaries nobody calls. A deployed uninvoked gate is a measurement the estate pays for and does not collect, and it degrades to a false sense of coverage because its existence is counted while its verdict is not. The remedy is adjudication, wire or retire, and explicitly NOT the mass rebuild the 94-percent-undeployed headline invites, which the record already forbids after two of eight sampled rebuilds lost capability. ACCEPT: every deployed uninvoked gate carries a decision of wired or retired with its reason, retirement is reversible through the retire-path organ and never a delete, and the invoked count moves while the invocation-gap count stays at 0Organ2 u

Milestones

MilestoneRungsCumulative
D0 · The guard plane can state its own healthDG1,DG22.5 u
D1 · The seat can reach its own lawsDG3,DG41.5 u
D2 · The tool plane is rankable and adoptedDG5,DG63 u

Risk register

RiskLikelihood x impactMitigation
Counting hook attempts adds a write to the hottest path in the session and could itself become the tax it measurespossible x mediumDG1 increments a counter in the file the guard already opens at its existing call sites rather than adding a new artifact or a new process, so the attempt path gains no spawn; if the counter cannot be written the guard still fails open and the absent count reads as UNOBSERVABLE rather than as zero.
Granting the absence-prover and the ranker to the read capability widens the read surfacecertain x lowDG3 grants exactly two read-only census tools and nothing that writes, promotes or deploys, and the negative control is kept: the same capability must still be refused for a write or admin operation, so least-authority is preserved rather than traded away [@capmyths03].
Adjudicating 2287 gate sources is read as a mandate to build them and becomes a campaign that hammers the hostpossible x highDG6 scopes to the 105 deployed uninvoked binaries, which is a decision list and not a build queue, and states in the rung that the mass rebuild is forbidden; an unbuildable or abandoned subject is retired reversibly rather than hidden inside a queue that then never finishes.
A guard-plane health rate is published and then read as a service level with no target behind itpossible x mediumThe rate ships as a count and a denominator only. Nothing here defines an SLO or an error budget and the sota sheet already grades that row as absent [@sre-slo], so the number is presented as an observation and the target stays an open gap rather than an implied one.

Watch contracts (measured)

Not a claim, a measurement. Each row names an organ and a symbol; the status is re-measured on every publish by the one ruler the ranker and the hive plane use, and the rule it applied is printed beside it: decl a top-level declaration in a NishiLang organ (a comment or a call site does not count), jsdecl a JS declaration form, exists the organ itself (the symbol is its name), marker a literal the organ carries, data a token in a data file. LANDED / PRESENT = measured present, WATCHING = the named contract is still open, MISSING = the row names something its organ does not carry, ABSENT = no contract named.
AxisOrganSymbolStatusNote
The guard plane states its own healthruntime/nx_hookguard.nxwg_attempt_counterWATCHING declOPEN -- rung DG1. Cells copied from the sota row SLOs with error budgets driving release decisions, which this plan's own risk row already binds to this rung. The hook guard writes its evidence log ONLY at condemnation sites, so its 1067 recorded events across 2026-08-10 to 2026-08-22 are a COUNT OF REFUSALS AND NOT A RATE and hook health is structurally uncomputable. ACCEPT: attempts are counted alongside refusals so a rate exists, two consecutive windows reconcile, and a forced timeout raises attempts and refusals by exactly one each. ORGAN PATH IS A GREENFIELD CONTRACT, NOT AN OVERSIGHT: the guard today is laptop-local PowerShell and nx_hookguard does not exist, PROVEN not assumed by glob over buildroot/runtime returning matches=0 with corpus_complete=1
The timeout worklist collapsed to its two causesruntime/_hdl_build/nx_worklog_stop.nxwg_stop_budgetWATCHING declOPEN -- rung DG2. Cells copied from the sota row Distributed tracing across services, the field capability that attributes a slow path to its cause. The 474 organ timeouts are 286 nx_worklog_stop and 134 nx_memplane_run, so TWO Stop-hook organs are about 886 permil of them and every other subject is 24 or fewer. The organ named here is the dominant subject and it is real and on disk. ACCEPT: both dominant organs complete inside their budget ON A REAL TURN and not on a fixture, or the slow leg moves off the blocking path, proven by the breaker for those keys staying closed across a full session
The seat can reach the laws it is held toruntime/nx_tools_api.nxcap_law_floorWATCHING declOPEN -- rung DG3, and the governor-privilege inversion. Cells copied from the sota row Policy-as-code evaluated at admission, where Kubernetes admission control is the bar. The seat is mandated to prove absence with nx_absent and to work from the ranked board, and is granted neither. THIS IS THE FOURTH INDEPENDENT REDISCOVERY OF ONE UNFIXED DEFECT, priors 1785028986 and 1785436247 and 1786115553, named so the next reader does not repeat the investigation. The organ is real and on disk and is the right home: its any-grants presenter already lets the first capability that grants win, so the remedy is a third scoped read-only capability beside the two that exist, never a wider token
The per-call hook tax is bounded and namedruntime/nx_hookguard.nxwg_wrap_costwardenWATCHING declOPEN -- rung DG4. Cells copied from the sota row Continuous profiling in production, the field capability that attributes cost to a code path. The PreToolUse hook matching every nishi MCP call is raw inline PowerShell with no guard wrapper and no timeout, spawning a process and taking a named mutex on EVERY tool call, where every sibling hook runs bounded and fails open. ACCEPT: the hook runs under the same bounded launcher as its siblings, a spawn failure degrades to silence rather than an error banner in the operator transcript, and the per-call cost is measured and published rather than assumed
Watch contracts for the tool planeruntime/nx_compare_regen.nxdg_matrix_admitWATCHING declOPEN -- rung DG5, the rung this file is. Cells copied from the sota row Hive queue workstream contracts that flip themselves, where the estate holds Best and every rival is honestly zero -- and this domain was the one not using the mechanism it leads the field on. THE DATA HALF LANDED 2026-08-25 and is what made this domain rankable at all. The row STAYS OPEN on purpose: the rung's own accept rule additionally demands that a planted symbol flips its row with zero hand edits, and that proof has not been run. DECLARED LIMIT: this symbol names a data admission rather than a func any organ exports, so the mechanical watch cannot witness it and it will read open until an organ declares it -- a watch contract pointing at a structurally unimplementable symbol can never flip, and saying so is cheaper than letting the next reader discover it
Gate adoption adjudicated rather than rebuiltruntime/_hdl_build/nx_gateadjudicate.nxga_adjudicateWATCHING declOPEN -- rung DG6, the estate's largest published honest gap. Cells copied from the sota row Service catalogue with ownership and status, where Backstage is the bar. 2317 gate sources exist, 135 are deployed, 30 are actually invoked and there are 0 invocation gaps, so every gate anything runs is deployed and byte-identical to source and the problem is 2287 sources nothing invokes plus 105 deployed binaries nobody calls. The remedy is adjudication, wire or retire, and explicitly NOT the mass rebuild the 94-percent headline invites, which the record forbids after two of eight sampled rebuilds lost capability. ACCEPT: every deployed uninvoked gate carries a decision with its reason, retirement is reversible through the retire-path organ and never a delete, and the invoked count moves while the invocation-gap count stays at 0

watch rows=6 landed=0 watching=6 present=0 missing=0 absent=0 (partition sums)