Fourteen patterns for a machine that runs alongside you: what it reports when there is no turn, and what it shows while a turn is still changing.
Rev. 4 — 23 Aug 2026. The other twelve entries catch up, and two new rules arrive with them. Rev. 3 corrected Deference at Rest and Cap the Decoration for vocabulary and punctuation. This pass takes the remaining twelve, and adds the two habits site/STYLE.md has since named. Asserted virtue is a word claiming a quality the prose should exhibit; the test is whether you would ever write its opposite. Seven are gone, including §19's Named honestly, on the same principle as its predecessors. Of the 41 left, 22 are exactly and every one of them bounds a set or a count, which is the exemption the rule allows. Definition by negation is the second: rather than ran 65 times against 1 of instead of, where the Gang of Four's ratio is close to even, and it is now 34 to 13. Em dashes fall from 136 to 21, and from 10.7 per thousand words to 1.7. slot becomes single-channel in the seven places it meant a display position, which settles a collision with OM-003, where slot-1 to slot-8 are published ids that cannot move. The last three uses of taste and instrument in their retired senses become decoration and status; the ones that survive are ordinary English, and one of them calls a person's own experience an instrument, which is the measuring sense and not ours. principal becomes person. No id, name, relation or claim has changed, and no mechanism is described differently.
Rev. 3 — 22 Aug 2026. Two entries rewritten to be readable on their own. Deference at Rest and Cap the Decoration carried this paper’s worst prose, and it was quoted back at the programme in public. Two defects, both real. Its Intent borrowed decidable from computability to mean “the system can tell”, and hid the pattern behind a caveat about how far it is implemented; the plain statement of the mechanism sat two fields below, in Structure. And a pair of undefined metaphors, taste for decorative output and instrument for a status signal, were doing load-bearing work across Intent, Participants and Consequences of both entries; instrument in particular had already been retired from this catalogue once, by OM-001 Rev. 2, for colliding with another sense. Both entries now say the same things in the words their own Applicability and Implementation fields were already using: decoration and status. No mechanism, id, name, relation or claim has changed. principal becomes person in these two entries, ahead of the rest of the catalogue. Punctuation is corrected in the same two entries. Both used the em dash as a general-purpose connector, at 11.0 and 19.2 per thousand words against Gang of Four’s 1.0; they now stand at 1.4 and 1.2, with commas, semicolons and colons doing the work according to which relation actually holds. One dash survives in each, where it earns its place. This paper falls from 12.7 per thousand words to 10.9, and the other twelve entries are untouched pending a decision on a wider pass; separators of the Rev. 3 — 22 Aug 2026 kind are typography rather than punctuation, and are deliberate. The rules applied are in the repository at site/STYLE.md.
Rev. 2 — 20 Aug 2026. The measurement apparatus is withdrawn. The Evidence field is gone from all fourteen entries, along with the figures and the counts that came out of a period of instrumented testing on one speech pipeline — replay totals, error rates, timings, and the weighting grid. Nothing that was observed has been removed: the entries still rest on building these two things and living with them, and the places where something has never actually been watched happening still say so on their faces. What has gone is the claim that the catalogue is formally verified, which was true of a handful of figures about a voice pipeline and of nothing else here. The template is accordingly OM-001’s plus this paper’s own addition, and no longer carries OM-003’s Evidence field — which stays in OM-003, where it names sources of practice rather than results of testing. No entry, no id and no relation changed.
Rev. 1 — 15 Aug 2026. First publication. The case for this paper — what it corrects in OM-001, the field it adds to the template and the failure mode that field has, the evidence position, and the claims this programme has had to withdraw — is OM-005 · On the First Four Papers §§14–18. This document is the fourteen patterns, presented.
Everything published so far grows outward in span: one agent, many agents, arrangements, many teams; seconds to days. This paper goes the other direction, into two regimes a turn does not cover.
Before you address the machine at all. Is anyone there, and what are they doing? A lamp answers this, and it answers it when there is no turn in progress and may never be one.
While you are still forming the input. The machine is already responding, its output is provisional, and both are changing at once.
Both are the same discipline. A machine running continuously alongside a person has to report itself outside the exchange, honestly, on channels that cannot be scrolled back. The lamp is that sentence at one hue of bandwidth; a transcript revising itself under your eye is the same sentence at full text bandwidth.
The two halves are written to be separable. If either grows evidence of its own it becomes its own numbered paper, and the split is a dated revision here.
OM-001, OM-002 and OM-003 are implicitly focal and single-channel: they assume a surface you are looking at. Nobody wrote that down, because there was no alternative to contrast it with. Ambient Activity Channel introduced the alternative in one entry. This is what it looks like as a set.
| Focal surface | Peripheral surface | |
|---|---|---|
| Bandwidth | High | One hue, one rhythm, one brightness |
| Cost to consult | A focus shift | None (already in the eye) |
| Persistence | Scrolls away | Always on |
| History | Scrollback | None. The light has no log |
| Audience | You | The room |
Every rule in the first half falls out of that table, which is the evidence that it is the right axis. No history is why re-assertion beats change detection. One channel is why precedence is the entire safety model. The room is why two more lamps would break darkness-as-alarm.
The second half sits on a different axis again: not where the output is, but when. Streaming ordinarily means output arriving incrementally. These seven are about output being rewritten after it has been shown, which is a harder thing to display honestly, and much harder to display honestly at speed.
Patterns whose forces are about attention rather than code structure are precisely what the Gang of Four template has no slot for, which is why both halves lean on the fields this programme has added rather than the ones it inherited.
Ambient Signals · the peripheral channel
Revised Output · inside one exchange, before it settles
The template is OM-001's, with one addition of this paper's own:
How you would know this is unnecessary.
Every entry states the condition under which it should be deleted. Not when not to use it, but the condition that would make the pattern pointless, named precisely enough to be checked. The argument for the field, and the failure mode we walked into while using it, are OM-005 §15. One consequence belongs here, because it governs how the field should be read: a null result from a corpus incapable of exhibiting the condition is indistinguishable from a true negative, and it arrives wearing the same authority: a measurement, a method, a number. So an entry whose retirement condition has been checked says what it was checked against.
Sample interaction and Known uses are omitted throughout, and the reason is the same for both. A sample interaction for a lamp is a colour, which Structure already shows. And the known use of every entry here is one workstation in one room — the evidence position, which is stated once in OM-005 §16, not fourteen times in a field.
Five of the fourteen are published with their own reference instance failing them. One Ordering, One Place is contradicted by the implementation it was drawn from. No Frozen Prefix and Show the Handover govern a live view the evidence recommends deleting. One List, Two Uses has been almost entirely displaced by the hand-written defence it warns about. Draft and Record Apart found its boundary already crossed. That is the added field working rather than a run of bad luck: an entry that could not embarrass its own exemplar would not have earned the slot.
Ambient Signals · Pattern 1
Intent
Re-send a resting state on a timer rather than on change, because an ambient channel has no history and no acknowledgement, and both of its failure modes are silent.
Motivation
A live cue repaints every frame, so a lost packet self-corrects in 66 ms and nobody notices. A resting state is sent once. If that single datagram is lost, or arrives before the device is ready, or the consumer restarts afterwards, the state is wrong forever, and the producer believes it succeeded, because as far as it knows nothing failed.
Both failures happened, one layer apart, within a single session. A lamp restores its own default on power-cycle; the renderer's colour frame went out microseconds later in the same tick; the emit path sent only on change. The lamp sat white while every log line said violet. Diagnosing it required querying the device directly, which itself only works with the renderer stopped, because the renderer holds the fixed reply port. Fixing it exposed the identical bug one level up: the tray also announced presence only on change, so a renderer started after the tray never learned there was anyone to be present.
Applicability
Any state that is long-lived, ambient, and sent over a transport without acknowledgement, to a consumer that can restart independently of the producer.
Structure
Participants
The producer, which holds the state and can restart. The transport, unacknowledged and unordered. The consumer, which renders and can restart independently. The device, which has its own power state and its own defaults and can revert underneath both of them.
Collaborations
The producer re-asserts on a period by clearing its own last-sent cache instead of tracking what the consumer knows: the consumer's knowledge is exactly what is not observable. Live cues are exempt: they repaint anyway, and re-asserting them would double the traffic to fix a problem they do not have.
Consequences
Gain: both silent failures become self-healing within one period, including the one nobody anticipated (a consumer that starts later than the producer). Cost: traffic proportional to time, not to events, and a period that is a guess. Trap: it reads as belt-and-braces until you have watched a resting state be wrong for an hour while the producer reported success, and then it reads as the minimum.
Implementation
Here the renderer re-asserts colour and brightness every 3 s and the tray heartbeats presence every 5 s. Two producers, two periods, because they are separate processes with separate restart behaviour and a shared constant would only imply a coupling that does not exist.
Failure signature
A resting state that is confidently wrong, with a clean log. The person has no reason to doubt what they see, and the only way to find it is to ask the device, which, on this hardware, first requires stopping the thing that is lying about it.
How you would know this is unnecessary
If the transport were reliable and ordered and a consumer could ask for current state on connect. Either alone is insufficient, and that is the useful part: a renderer that issued what is the present state? at startup would not need the heartbeat, and a protocol with acknowledgements would not need the re-assert timer. The rule is a consequence of fire-and-forget datagrams to a device that can power-cycle underneath you, plus consumers that restart independently. Remove any one of those three and check again.
Related patterns
Corrects Ambient Activity Channel (OM-001, 9), whose implementation note says a time-to-live is sufficient: it is sufficient for a live cue and does nothing for a resting state. Governed by Honest Gauge (OM-001, 12). Enables Verified Presence (2), which has nothing to assert with until a resting state can be trusted to arrive.
Ambient Signals · Pattern 2
Intent
An indicator asserts only what it has checked, because adding a confident signal makes you responsible for everything it appears to claim, including things nobody was measuring before you added it.
Motivation
The resting glow originally meant Agent mode is selected. It read as she can hear you. Those two diverge the moment the channel dies (service restarted, port lost, session gone), and a dead agent looked identical to a live one until you had spoken an entire sentence into nothing.
While the surface was silent about reachability, this was a gap. The moment the lamp began asserting a confident resting glow, the same gap became a lie. The indicator did not create the blindness. It made it load-bearing, and that is the general lesson: a new signal inherits responsibility for everything it appears to assert, including conditions that were previously nobody's job because nothing depended on them.
Applicability
Whenever a signal is added to a surface a person will trust without reading, which is every peripheral channel, by definition, since not being read is what peripheral means.
Structure
Three things that are easy to conflate, and the pattern is the insistence that they are three: what the system intends (a mode, a setting, a configuration), what the system has verified (a probe that completed), and what the indicator says. The indicator is wired to the second, never the first. The probe runs on its own schedule and its own thread, and its result, not the intention behind it, is what reaches the channel.
Participants
The indicator, which must not assert ahead of evidence. The prober, on a thread of its own. The subject, which may be unreachable in ways that hang, not refuse. The person, who reads the indicator without deciding to.
Collaborations
The probe result is published through Standing Assertion rather than emitted once on change, so a consumer that restarts learns the current answer rather than the last transition. A flip in reachability re-announces immediately rather than waiting for the next heartbeat, because the whole value is in the flip.
Consequences
Gain: the question you have before pressing a key gets an answer, from across the room. Cost: a probe, a cadence, and a new set of failure modes belonging to the probe itself. Trap: the probe must not run on the thread that draws the interface. The health check has a 2 s timeout and the surface's loop is the message pump; probing inline freezes the icon and the overlay for two seconds every time the channel accepts a connection and then hangs, which is the exact condition being probed for.
Implementation
Probe every 10 s, on a dedicated thread, unconditionally. That last word is load-bearing and was nearly lost: the probe originally ran only while a particular mode was selected, and when modes were deleted it would never have run again, leaving the lamp asserting something nothing was checking. A conditional probe behind a condition that later disappears is worse than no probe, because the indicator does not go with it.
Failure signature
The person speaks a complete utterance into a channel that is not there, and learns only when they stop. The cost of the discovery is one whole interaction, every time, and it is paid before any feedback exists, which is why an ambient answer is worth a thread of its own.
How you would know this is unnecessary
If failure were immediate and visible at the moment of acting. This indicator exists because push-to-talk gives no feedback until after you have spoken. On a surface where the attempt itself reports failure synchronously (a button that greys out, a send that errors), an ambient reachability signal is redundant, and adding one would only create a second thing that can be wrong.
Related patterns
Obeys Honest Gauge (OM-001, 12), of which this is the peripheral case and the harder one: a gauge that lies is worse when it is trusted without being read. Specialises Ambient Activity Channel (OM-001, 9). Needs Standing Assertion (1). Ranked by One Ordering, One Place (5).
Ambient Signals · Pattern 3
Intent
Let the agent name a state from a fixed list and let the renderer own what that looks like, so unsafe output is not rejected but inexpressible.
Motivation
An agent that can ask a light for a colour, a brightness and a waveform can ask it to strobe. The obvious defence is a validator, and a validator is a check somebody has to remember to write, can be bypassed by a second code path, and drifts the moment it is duplicated.
A vocabulary with no field for a waveform cannot carry one. So never allow agent-generated strobing stops being a rule anyone enforces and becomes a fact about what is sayable. The agent asks for focus or evening; pigment, ramp and dynamics never leave the renderer.
This is Ambient Activity Channel's the channel reports state, never instructions promoted from a design note to the thing that makes the layer safe to leave unsupervised.
Applicability
Whenever an unsupervised agent drives an actuator in a shared physical space, and the harmful states are a describable class.
Structure
Participants
The agent, which may name but never specify. The relay, which forwards and does not judge. The renderer, sole owner of presentation and the single choke point at the hardware. The static table, which is the vocabulary and is the only place a new state can be added.
Collaborations
Bounded by One Ordering, One Place: a named state still has to lose to a status signal, and the vocabulary says nothing about rank. Priced by Cap the Decoration, which is what this capability costs.
Consequences
Gain: the safety property is a property of the protocol, so it holds for every producer including ones written later by someone who never read this. Gain: the palette can be retuned without touching the agent. Cost: the agent cannot express something the vocabulary lacks, and adding a word is a deliberate act with a review attached. Trap: the relay must not re-validate: a second copy of the policy is a second thing to keep in step, and it will not be kept in step.
Implementation
Lookup returns an optional over a static table; an unknown name is refused and the known list logged, never approximated to the nearest match. Treat the obvious near-misses as clears (off, none, clear, normal, default), because the agent side maps a model's word onto the wire, and a missed mapping would see a literal off refused as unknown while both halves believed they had agreed.
Failure signature
Nothing at all. The relay here shipped matching the wrong key. It sent type where the contract, written in the same session, specified t. The line arrived, matched nothing, fell into the catch-all and did nothing: no error, no log, no lamp. It was found by review rather than by test, and the reason there was no test is worth carrying: the renderer-facing wire is pinned byte-for-byte, but the agent-facing wire is a different boundary and had none. A pass-through event is precisely the kind that cannot report its own absence.
How you would know this is unnecessary
If the actuator were incapable of harm (a display that physically cannot strobe), or if agent output were reviewed by a person before reaching the hardware. The rule exists because the actuator is in the room, the agent is unsupervised, and the failure mode is not recoverable by noticing it afterwards.
Related patterns
Realises Ambient Activity Channel (OM-001, 9). Bounded by One Ordering, One Place (5). Priced by Cap the Decoration (7). Shares its logic with Constrained Choice (OM-001, 6), one level down: there the closed set protects the person from an unbounded prompt, here it protects the room from an unbounded actuator.
Ambient Signals · Pattern 4
Intent
A person acting directly on a shared device overrides the agent. The agent notices by comparing what the device reports against its own last command, which it can only do while it is idle; during activity there is no single command to compare against.
Motivation
The lamp has other controllers: a vendor app, a schedule, a switch. One was observed changing state on its own mid-session, which is also why capture-and-restore was rejected: it would have fought whatever else was driving it, and a renderer restoring what it captured is indistinguishable from a renderer with a bug.
So the renderer watches for its commanded state and the device's actual state disagreeing, and treats the disagreement as a person. But it can only do that at rest. A live cue repaints every frame; comparing observed state against a moving target registers a mismatch almost immediately, and agent control would suspend itself permanently within seconds of the first conversation. The at-rest restriction is not a shortcut — it is what makes the feature possible at all.
Applicability
Any actuator with more than one controller, one of them a person who cannot be asked what they meant.
Structure
A poll compares the device's reported state against the renderer's last commanded state, but only through an accessor that returns nothing unless the renderer is idle. That accessor is the pattern: the comparison is not disabled during activity so much as undefined, because during activity there is no single commanded state to compare against. A mismatch drops the current decorative state and refuses new ones for a cooldown.
Participants
The renderer, which yields. The device, which reports its own state and is the only witness. Other controllers (a vendor app, a schedule, a switch), which are not observable and do not announce themselves. The person, who is inferred, not detected.
Collaborations
Bounds Closed Vocabulary: a named state can be dropped by a hand, so the vocabulary's guarantee is about what may be asked for rather than what will be shown. Deliberately does not bound Verified Presence or any live cue, for the reason under Consequences.
Consequences
Gain: the agent yields without needing to be told, and without the person learning a gesture. Cost: a poll, and a cooldown that is a guess. Trap: the suspension covers decorative states only, and must. Dimming a lamp by hand is a preference about the room; it is not a wish to stop being told the agent is unreachable, so the states that report agent health keep running. Cap the Decoration (7) draws that same line under a different pressure: here a hand on the device, there the hour of the night. Two unrelated pressures landing on one boundary is the best evidence available that the boundary is in the right place.
Implementation
Poll device status every 20 s against the last commanded state; a mismatch drops the current scene and refuses new ones for 30 minutes. Gate the comparison on an accessor that yields nothing unless the renderer is at rest, and put the gate in the accessor instead of at each call site, so a future caller inherits it without knowing it exists.
Failure signature
Two outcomes, and they look nothing alike. Without the pattern: a person turns the lamp down and the agent turns it back up, which reads as the machine arguing. With the pattern but without the at-rest gate: agent control switches itself off permanently a few seconds into the first conversation, and the layer appears to have died of its own accord.
⚠️ This has never been confirmed against a real hand on the device. Everything above is what the mechanism does, not what has been watched happening, and the untested part is the one that matters: that a person’s intervention is reliably distinguishable from the device drifting on its own.
How you would know this is unnecessary
If the renderer were the only controller: no vendor app, no schedules, no physical switch. Worth checking rather than assuming, since the second controller is usually the one nobody remembers installing.
Related patterns
Bounds Closed Vocabulary (3). Shares its cut with Cap the Decoration (7). Ranked by One Ordering, One Place (5). Yields to the person in the sense Approval Gate (OM-001, 10) formalises, with the difference that there is no gate to pass through; the person acts on the world and the machine notices.
Ambient Signals · Pattern 5
Intent
A single-channel surface can show one thing, so the order of precedence is the design, and it has to live in one place a person can read in five seconds, or it is not a safety property at all.
Motivation
Ambient Activity Channel says the renderer owns a priority stack, singular. What was built has two, in two structures of different shape: an if/else chain over time-to-lived live cues, and a separate sequence of early returns for the resting look, reached only when no live cue is active. Neither can see the other. No test asserts the composite.
And the written composite is wrong at its first step. The documentation recorded presence-off > live cue; the code executes live cue > presence-off, because the resting chain is never reached while a cue is live.
The code is probably right: if a cue is arriving then something is demonstrably happening, so nobody is listening is stale information. That is not the point. The point is that two people could each change one structure, each preserve their own invariant, and break the joint one, and nothing would say so.
Applicability
Any channel narrow enough that states compete for it, which is every peripheral channel, since being single-channel is close to the definition.
Structure
live cue > presence-off: the reverse of what the documentation said for a fortnight. The dashed box is the pattern: the thing that needs to be true is the one thing not written down.Participants
The states, which compete. The ordering, which should be one artifact and here is two. The test, which should assert the composite and here asserts each half. The document, which described a composite nobody could check against the code.
Collaborations
Ranks everything on the channel: Verified Presence, Closed Vocabulary's named states, Darkness as Alarm and the live cues alike. Darkness as Alarm depends on this ordering specifically: it is only an alarm if nothing decorative can outrank it.
Consequences
Gain: an alarm cannot queue behind a flourish. Gain: decoration cannot outrank a status signal, which is what makes a decorative layer safe to add at all. Cost: every new state must be placed, and placing it is a safety decision, not a formatting one. Trap: the ranking split across two structures, which is the state this instance is in.
Implementation
One ordering, one expression, and one test that asserts the composite order end to end rather than each half separately. The test is the part that is easy to skip and is the whole pattern: two correct halves with no joint assertion is exactly the configuration that fails silently.
Failure signature
Nothing visible for a long time, then a state that should have been unmissable does not appear, and the reason is in neither structure. Both halves review cleanly. The person's experience is an instrument that was reliable until the day it was not, with no change to the code that owns it.
How you would know this is unnecessary
If the channel could carry more than one state at once without ambiguity: two devices, or a surface with room for a second mark. That is exactly what the multi-lamp question opens, and it is not obviously an improvement: see §18, where the first thing a second lamp breaks is this pattern's guarantee.
⚠️ This entry's own instance fails it, and it is published that way deliberately. The split was found by looking rather than in review, and the documented composite had been wrong at its first step for a fortnight while every party believed the ranking was the safety model. A pattern demonstrated by its reference implementation falling short of it is worth more than one demonstrated by a tidy listing.
Related patterns
Corrects Ambient Activity Channel (OM-001, 9), whose a priority stack is singular in the prose and plural in the practice. Bounds Closed Vocabulary (3). Ranks Verified Presence (2) and Darkness as Alarm (6).
Ambient Signals · Pattern 6
Intent
Keep the resting state lit, so that the channel's most perceptible transition, to zero, is reserved for the one condition worth interrupting for.
Motivation
Peripheral vision is rod-dominated: acutely sensitive to luminance change, poor at hue. A violet-versus-amber distinction beside the monitor has to be looked at, which is the one thing a peripheral channel is supposed not to require. Brightness is also the only ordered dimension the channel has — more is more, with no legend to learn. So the largest signal available is going dark, and there is exactly one of it to spend.
What made it spendable was deleting the mode. While the resting glow meant Agent mode is selected, dark meant dictation far more often than it meant broken: the commonest state in the day occupied the loudest signal on the channel and drowned the only one worth having. Once the chord carried the intent (one chord dictates, another talks to the agent), there was no mode to be in, presence became reachable and not paused, and the lamp is normally on. Darkness became rare, and rare is the whole mechanism.
The question the glow answers moved with it, from is she listening? to could I talk to her right now? That is the question you have before pressing a key, and therefore the one an always-on surface should be answering.
Applicability
A peripheral channel with one ordered dimension, in a space that is normally lit, where exactly one condition warrants interruption.
Structure
Presence is three-valued, not boolean, and the third value is what makes the pattern work. No producer has ever reported (an older client, a scripted replay) falls back to the configured ambient behaviour exactly as before. Reported and off goes dark. Reported and on is the resting glow. So darkness is only ever asserted, never defaulted into, and silence is a distinct state from absence.
Participants
The resting glow, which must be quiet enough to live beside all day. Darkness, the single spendable signal. Silence (no producer), which must not resolve to darkness. The room, whose ambient light level the signal is measured against.
Collaborations
Relies on Verified Presence: darkness means unreachable only because reachability is actually checked, and without that probe this pattern asserts something nobody measured. Ranked by One Ordering, One Place, since an alarm that can be outranked is not one. Protected by Cap the Decoration, which is why a scene cannot paint over an unreachable agent and leave the room looking healthy.
Consequences
Gain: the alarm needs no legend, no colour memory and no focus; it works from across the room and out of the corner of the eye. Gain: it costs nothing extra (no second device, no second mark, no screen). Cost: the resting state must be on, continuously, which makes the resting look a real constraint, not a flourish; here a dim violet-white slow breath at the lowest brightness the device offers. Cost: you get one alarm, and a second condition deserving interruption has nowhere to go. Trap: the room must be normally lit; the signal is a luminance change, so in a dark room it inverts and there is nothing to spend. Trap: silence must not be darkness.
Implementation
Make the third value explicit in the protocol rather than inferring it from a timeout. That distinction is what lets darkness carry meaning while staying backward compatible, and it has a safety consequence beyond compatibility: had silence resolved to dark, the alarm would fire on a missing producer rather than on the condition it names, and the first thing anyone would learn is to ignore it.
Failure signature
An alarm that has been taught to mean nothing. Every spurious darkness spends a little of the only signal there is, and the spending is invisible: nobody records the moment they stopped looking.
⚠️ Nobody has been in the room, not expecting it, when the channel actually died. That the alarm is unmissable is the claim this entry rests on and the one nobody has been in a position to check.
One accident points the right way and is offered as no more than that. The thinking state was originally ended when the reply arrived rather than when playback did; because a reply exists some seconds before it is audible, the lamp went dark at the moment it should have been saying nearly there. It was noticed at once in use, treated as a defect, and closed by adding a state to cover the gap. That is not evidence that darkness alarms. It is evidence that a spurious darkness is not tolerated, which is the discipline this pattern demands of whoever holds it.
How you would know this is unnecessary
If a second condition deserved interruption. The moment there are two alarms, the loudest signal has to be shared, darkness stops naming one thing, and a legend comes back. Also unnecessary where the resting state cannot be on (a channel that is off by default has no darkness to spend), or in a room that is normally dark, where the whole polarity inverts.
Related patterns
Specialises Ambient Activity Channel (OM-001, 9). Relies on Verified Presence (2). Ranked by One Ordering, One Place (5). Protected by Cap the Decoration (7). Resolves Mode Visibility (OM-001, 2) by removing the mode rather than displaying it: the pattern asked that a mode be visible at the moment of use, and the answer that worked was to have no mode.
Ambient Signals · Pattern 7
Intent
Constrain an ambient channel's decorative output by context and exempt its status output from the constraint, so that carrying decoration never becomes a reason to switch the whole channel off.
Motivation
An agent that can name a scene can name a bright one at 2am. The obvious defence is a global brightness ceiling by hour. It is simple, and it is wrong, because it caps the alarm too. Capping decoration is protective; capping a status signal is breaking it quietly. An error you cannot see at 2am is exactly the failure this layer exists to prevent.
So the clamp is applied at one point (a decorative state's brightness on its way to the device), and conversation cues pass it untouched. They last seconds, they are responses to something you just did, and they are the entire reason the channel is trusted at all.
Deference at Rest (4) draws the same line under a different pressure. There it is a hand on the lamp that suppresses decoration and leaves the status signals alone; here it is the hour. Two unrelated pressures, and the boundary lands in the same place both times, which is the best evidence available that it is the right boundary and not a convenience.
Applicability
Any ambient layer carrying both decoration and status signals, whose acceptable intensity varies with a context the layer can observe: hour, occupancy, a presentation, a meeting.
Structure
One clamp, on one path. Decorative states pass through a brightness ceiling that is a function of context; status states reach the device by a route that has no ceiling on it. The two paths are separated at the point where a state is classified, not at the point where it is drawn, so a new state cannot reach the device without someone having decided which kind it is.
Participants
Decorative states, which are capped. Status states, which are not. The context (here, the local hour), which is read, not configured. The classifier, which is the only place the distinction exists and therefore the only place it can be got wrong.
Collaborations
Prices Closed Vocabulary: this cap is what that capability costs, and the design is that the price is charged to decoration alone. Must not reach Darkness as Alarm or any live cue. Shares its cut with Deference at Rest: both draw the line between decoration and status, and neither lets a limit on the first reach the second.
Consequences
Gain: the layer stays on at night. Without the cap the honest choice is to disable the whole thing after hours, which disables the alarm; the decorative capability would have cost the status signal. Cost: two classes of output now exist and every new state must be classified, silently wrong in both directions: a capped status state is unreadable at night, an uncapped decorative one a light in your eyes. Trap: a clock reading that fails toward day lifts the cap instead of applying it. See Implementation, where the failure direction is the detail worth copying. Trap: the boundaries are guesses. The hours and the ceiling are unmeasured, a fixed window is wrong for a household on other hours, and it is wrong twice a year.
Implementation
Clamp decorative brightness between 22:00 and 07:00 local, on the decorative path only. The window wraps midnight, so it is a union, not a range, and writing it as a range is the obvious bug.
The detail worth copying is the failure direction. The structure the clock is read into is zeroed before the call, and a zeroed structure reads as hour 0 — inside the night window. If the call does nothing whatsoever, the cap engages rather than lifts. A cap that fails open is not a cap.
Failure signature
Not a bright light at 2am; that one announces itself. The failure that costs you is the other direction: someone reasonably decides the layer is too much at night, switches it off wholesale, and the alarm goes with it. Nothing then reports that the channel has stopped reporting, because a channel that is off reports nothing by definition.
⚠️ Never observed at night. Nobody has recorded whether the ceiling is right, and the decision to leave conversation cues uncapped is untested in exactly the case it exists for; no one has watched an error state arrive at 2am and judged whether it read.
How you would know this is unnecessary
If the layer carried no decoration. A channel that only ever reports state has nothing to cap, because every state on it is a status signal and a status signal you cannot see is broken. The cap exists because Closed Vocabulary let decoration onto the channel. The test is therefore not is the cap working but is there anything decorative here at all, and if the answer is no, both patterns go together.
Related patterns
Prices Closed Vocabulary (3): this cap is what that capability costs. Shares its cut with Deference at Rest (4). Must not reach Darkness as Alarm (6). Ranked by One Ordering, One Place (5).
Revised Output · Pattern 1
Intent
Let a fast, cheap pass show the person something immediately, and let one authoritative pass produce the text that is kept, and never let the first become the second by default.
Motivation
Two things a person wants from a live transcription are in direct conflict. They want to see words while they are still speaking, which requires a model small and fast enough to run at a cadence. They want the text that survives to be correct, which requires a model good enough to be slow. Building one thing that tries to be both produces a system that is neither: too slow to feel live, too weak to trust.
The resolution is not a compromise but a division. The scribe streams at roughly 50 ms and is understood by everyone, including the person reading it, to be provisional. The corrector runs once, at release, over every captured sample, and its output is the record.
What makes this a pattern rather than an implementation note is that building it stated it more purely than the design did. The system had grown a third thing, the corrector running continuously during the hold, producing accurate text mid-utterance. It looked like the best of both. It is neither the draft nor the record: at release the corrector discards any pass still in flight and issues one fresh pass over the whole buffer, whose text replaces everything the continuous stream produced. The continuous pass cannot change the final text, by construction: there is one buffer, one write site, and one author of the record.
So the record has exactly one author, and anything else in the pipeline is a draft whatever it costs.
Applicability
Any surface where a fast approximate result and a slow correct one are both wanted, and the correct one is what gets stored, sent or acted on.
Structure
Participants
The scribe, fast and provisional. The corrector, slow and authoritative, run once. The buffer, which is what the corrector reads. The record, which has one author by construction, not by convention.
Collaborations
Requires Churn Is Not Correction, because a provisional view that shows every revision is unreadable. Presented by Show the Handover. Structurally enforced by Draft and Record Apart, which is the storage half of the same rule.
Consequences
Gain: the person sees something immediately without the system having to defend the accuracy of what they see. Gain: the record has one author, so which pass produced this? always has an answer. Cost: two models, two code paths, two failure modes. Trap: a third pass that is neither draft nor record, arriving because it looks like an improvement on both. That is exactly what happened here, and it was the most expensive thing in the pipeline while producing nothing that survives.
Implementation
Give the record exactly one write site. Make the draft visibly provisional instead of merely labelled as such. When a pass is in flight at the moment of release, discard it rather than reconciling it: reconciliation is where a draft becomes a record by accident, and it is always the more reasonable-looking of the two options.
Failure signature
The person proof-reads a draft that is about to be replaced, and edits it. They are correcting text that will not survive, and the system gives them no reason to suspect it.
How you would know this is unnecessary
If one model were both fast enough to stream at a cadence a person reads as live and good enough that its output needed no second pass. The gap is not close to closing: the pass accurate enough to keep is an order of magnitude slower than the one that feels live, and it grows with the length of what was said. That is a gap to re-check rather than a permanent condition.
Related patterns
Elaborates Streaming Turn (OM-001, 3). Governed by Honest Gauge (OM-001, 12). Requires Churn Is Not Correction (4). Enforced by Draft and Record Apart (7).
Revised Output · Pattern 2
Intent
In a surface that revises what it has already shown, never treat any part of the visible text as settled, because the reviser does not, and a frozen prefix will eventually be wrong in a way the system cannot repair.
Motivation
The obvious optimisation for a live-revising view is to freeze text once it has stood for a while: past some depth or some age, stop re-rendering it. It saves work, it stops the display flickering, and it is the first thing anyone proposes.
Practice says it cannot be done safely, and the story of how it says so is part of the entry. We looked at a spell of short utterances, saw nothing reach far back, and concluded that a deep revision does not happen. Then we watched one rewrite the first word of a long one. What we had looked at was not evidence of absence; it was too short to contain the case.
So there is no depth and no age at which freezing is safe. There is only a frequency: from more than fifteen hundred logged utterances, well under one percent run to thirty seconds at all, which bounds how often the deep case can arise without bounding how deep it goes.
Applicability
Any view that displays output while it is still being revised: live transcription, streaming generation with correction, incremental parsing surfaced to a person.
Structure
The buffer is the truth and the view is a function of it, recomputed. There is no incremental patch path, because a patch path is where a freeze rule would live even if nobody meant to write one. Suppression of visual churn belongs in presentation and is Churn Is Not Correction's job; it must not be implemented by making a revision unrepresentable.
Participants
The reviser, whose reach is unbounded in principle. The buffer, which records every pass. The view, which is recomputed, not patched. The optimisation, which is the antagonist and arrives as a rendering concern, not a semantic one.
Collaborations
Governs Show the Handover. Constrained by Churn Is Not Correction, and the two pull against each other on purpose: the display must be able to show a deep revision, and should usually decline to.
Consequences
Gain: the display can never contradict the buffer. Gain: no class of revision is silently undisplayable. Cost: the whole visible text is re-rendered on every pass. Trap: freezing introduced as a rendering optimisation rather than a semantic decision, by someone who does not know it is one, which is the normal case, since it looks like a performance change.
Implementation
Re-render from the buffer instead of patching what is on screen. If flicker is the real complaint, address it in presentation instead of by bounding what the reviser is allowed to say.
Failure signature
A rare, unreproducible wrongness. The visible text and the system's own record disagree, in the small fraction of cases where the reviser reached past the freeze line, and because the case is rare and long, it is the hardest kind to reproduce deliberately and the easiest to dismiss as a mistranscription.
How you would know this is unnecessary
If the reviser were monotonic: only ever appending, or only ever revising within a bounded window it declared. Neither is true of this corrector, and a system that claims the first should be tested for it rather than believed, because the test is cheap and the failure is silent. Note what the corpus for that test has to contain: utterances long enough to exhibit a deep revision. A corpus of short ones will return a clean null and mean nothing.
⚠️ This entry's reference instance is proposed for deletion. The pattern governs the live view, and the live view is what the 15 August evidence recommends removing. The entry does not die with it. The claim is about live-revising surfaces generally, which is why this language is deliberately not named for dictation; the exemplar goes, and saying so is what the added field exists to enforce.
Related patterns
Governs Show the Handover (3). Constrained by Churn Is Not Correction (4). Elaborates Streaming Turn (OM-001, 3) and Honest Gauge (OM-001, 12).
Revised Output · Pattern 3
Intent
When a fast draft gives way to an authoritative pass, make the moment visible, because a person who cannot see the handover will read the draft's errors as the system's errors.
Motivation
In a two-pass surface the text changes twice for different reasons. It changes within the draft, because the scribe is revising its own guess. It changes at release, because a different and better model has replaced the whole thing. These look identical on screen and mean opposite things: the first is a system working, the second is a system finishing.
A person who cannot tell them apart draws the wrong conclusion in both directions. They lose confidence in a correct final pass because they watched it churn on the way there, and they trust a draft because it stopped moving.
The handover is also where the timing argument lives. The corrector's continuous stream runs a cadence plus an inference behind the microphone, and it usually has not caught up with what was said by the time you stop saying it. Against a draft that keeps pace, that is a different kind of feedback, not a slower one. Presenting them as the same channel is the error this seam makes visible.
Applicability
Any surface where two producers of different quality write to one visible region.
Structure
One visible region, two producers, and a presentational distinction that is a property of the region, not an annotation on it. The distinction has to survive being seen at the periphery of attention, because that is where a person reading their own dictation is: they are speaking, not reading.
Participants
The draft and the record, which write to the same place. The seam, which is the presentational fact that they are different. The person, who is not looking directly at any of it.
Collaborations
Governed by No Frozen Prefix: there is no point marking a handover in a view that cannot honestly show what changed. Presents Draft and Record. Requires Draft and Record Apart, in the strict sense that you cannot show a handover between two things that are the same thing.
Consequences
Gain: draft errors are attributed to the draft. Gain: the final pass gets read as final. Cost: a visible transition is a design problem; done badly it is a flash that draws the eye at the exact moment attention should be moving on. Trap: marking the handover so subtly that it satisfies a review and communicates nothing.
Implementation
Distinguish the two states in the presentation itself instead of with a label. Make the transition legible at a glance and at the periphery of attention.
Failure signature
A person who has quietly stopped trusting a system that is working correctly. They watched it churn, drew a conclusion about its accuracy, and the conclusion is wrong, and because nothing failed, there is no incident, no report, and nothing to investigate.
How you would know this is unnecessary
If the draft and the record were close enough in quality that mistaking one for the other cost nothing. That is the perception question again, and it is the one the evidence names as its own falsification test: someone in a blind comparison preferring the hold with continuous correction to the hold without it. Nothing here measures taste, and this entry is honest that its central claim rests on it.
⚠️ Renamed before publication, from The Visible Seam. Seam is already OM-001's template field (which side of the harness/agent boundary a pattern sits on), and two meanings for one word, both ours, is exactly what a plain name is for. ⚠️ This entry's reference instance is proposed for deletion, for the same reason as No Frozen Prefix and with the same consequence: the pattern survives, the exemplar does not.
Related patterns
Governed by No Frozen Prefix (2). Presents Draft and Record (1). Requires Draft and Record Apart (7). Elaborates Honest Gauge (OM-001, 12).
Revised Output · Pattern 4
Intent
Distinguish text that is being corrected from text that is merely oscillating, and stop showing the second: a value alternating between two readings is not information, it is the display leaking the model's uncertainty.
Motivation
Watching a live-revising surface, the eye is caught by movement and infers meaning from it. Most of that movement carries none. The deepest revisions we watched were all the same thing: one word alternating between two spellings of the same sound, never settling: a model equivocating, rendered as though something were being fixed.
And the two scale against each other, which is what makes the entry usable rather than an anecdote: a revision reaching back only a moment is almost always a genuine correction, and one reaching back a long way is almost always a word oscillating between readings it has already tried. The deep revisions that make freezing unsafe (the ones No Frozen Prefix exists for) are almost entirely oscillation, and the two facts have to be held at once: the display must be able to show a deep revision, and should usually decline to.
That is why this is a separate pattern rather than a note on that one. They pull against each other and the resolution is not a compromise: represent everything, present selectively.
Applicability
Any incremental display whose producer revises. The deeper the revision it must support, the more it needs this.
Structure
Participants
The buffer, which records every pass including the ones nobody sees. The per-position history, which is what makes a return detectable. The presentation, which is the only thing that suppresses.
Collaborations
Constrains No Frozen Prefix and is constrained by it in turn. Required by Draft and Record, whose provisional view is unreadable without it.
Consequences
Gain: movement on screen means something again. Gain: the person stops proof-reading a draft that is going to be replaced. Cost: a suppression rule is a judgement, and a wrong one hides a real correction. Trap: suppressing by rate rather than by return; a fast correction is still a correction, and an oscillation that alternates slowly is still churn.
Implementation
Judge by whether the value has returned to one it already held at that position, not by how often it changes. Hold a short history per position instead of a global change counter. Let the buffer record every pass; only the presentation suppresses. The first transition still shows, because that one is news; a word finding genuinely new readings keeps reporting.
Failure signature
A signal fired often enough to be ignored, after which the real corrections it exists to show go past unseen. This is the general failure of any highlight keyed on changed rather than on changed to something new, and it degrades quietly: the indicator keeps working exactly as specified while ceasing to communicate.
How you would know this is unnecessary
If the reviser's intermediate states were themselves worth reading: a system whose second guess is reliably better than its first, rather than one alternating between two guesses of equal confidence. That is measurable, and it was measured here: it is not the case.
Related patterns
Constrains No Frozen Prefix (2). Required by Draft and Record (1). Governed by Honest Gauge (OM-001, 12).
Revised Output · Pattern 5
Intent
Put the last corrections in a table rather than in a model, because the last corrections are not about accuracy at all: they are about convention, and a convention has no uncertainty for a model to resolve.
Motivation
After a biased recogniser has done its work, two kinds of error remain, and they are not the same kind of thing.
The first is acoustic. Several project terms were missed at every boost weight and on both a synthesised and a human voice: words the model does not resolve from the signal, where no amount of weighting invents audio that is not there. Nothing downstream can repair those, because the information never arrived.
The second is orthographic, and it is not an error the model could have avoided. A speaker says workshop machines; the house writes workshop-machines. Both are correct English renderings of the same sound. The model has no way to prefer one, because the preference is not in the audio; it is a house decision, made once, that applies every time. That is the last mile, and it is deterministic by its nature, not by an optimisation.
So the pass that closes it should be a substitution table: microseconds, identical every time, incapable of inventing anything, and printable in full.
Applicability
Any pipeline where a probabilistic stage is followed by a house convention the stage cannot know: orthography, casing, project vocabulary, units, citation style.
Structure
A pure function between the model's output and the destination. It holds no state, consults nothing, and its entire behaviour is a list that can be printed on demand, which is the property that makes it reviewable without reading the source, and is worth building in from the start instead of adding it when someone asks what it does.
Participants
The table, half derived and half hand-written. The matcher, which is whole-word and case-upgrading only. The log, which prints every edit that fires.
Collaborations
Requires One List, Two Uses: the derived half of the table comes from the same vocabulary the recogniser is biased with. Runs strictly after the record exists, so it is inside Draft and Record's record path and never touches the draft.
Consequences
Gain: the whole behaviour can be read as a list rather than inferred from outputs. Gain: no latency and no new failure mode; a table cannot hallucinate. Gain: adding a term is a data change. Cost: it is silent, and a rule firing on the wrong word produces a wrong edit that looks like a correct one. Trap: a case-only rule on an ordinary English word, the sunshine outside becoming the Sunshine outside. Half the project vocabulary here is ordinary English, so case-only rules are refused by derivation and hand-written one at a time instead.
Implementation
Match whole words only. Only ever upgrade case, never downgrade. Never let the pass empty an utterance — typing nothing is indistinguishable from a dead microphone. Print every edit that fires, so the pass is reviewable from its output and not only from its source.
Failure signature
An invisible wrong edit. The text is fluent, plausible and not what was said, and it appears at the cursor in someone else's document. Unlike a mistranscription it carries no acoustic excuse, so the reader attributes it to the writer.
How you would know this is unnecessary
If the convention were already in the recogniser's output — which is what would happen if the vocabulary were boosted as written rather than as spoken, or if the surface being typed into applied the convention itself. Both are real alternatives and neither was tried.
Note what rarity does and does not settle. This pass fires on a small fraction of what is said, and a rule that fires rarely is not thereby unnecessary: the edits it does make land in commit messages and issue titles, where the difference between two spellings is the difference between prose and a link. But the pattern’s case cannot be argued from how often it fires, and an entry that quoted a rate as though the rate were the argument would be arguing the wrong thing.
Related patterns
Requires One List, Two Uses (6). Elaborates Draft and Record (1). Governed by Honest Gauge (OM-001, 12).
Revised Output · Pattern 6
Intent
Keep one vocabulary file and let both the thing that hears and the thing that writes read it, so a term learned once is learned in both places and cannot be half-learned.
Motivation
A project's jargon has to reach two consumers that look unrelated. The recogniser needs it as bias terms, so the domain words are candidates it will consider. The house style needs it as substitutions, so those words are written the way the house writes them. Maintained separately, the two drift, and the drift is invisible, because each list is individually correct.
The list earns its place: with it the recogniser gets the project’s own words right far more often than without. But the weight it is given has a cliff in it. Modest boosting helps, more helps a little more, and past some point it is worse than no boosting at all: the model begins hearing the boosted words in places they were never said. Over-boosting does not plateau and decay; it inverts.
Applicability
Any system where the same domain vocabulary is needed by a recogniser, a generator and a formatter: speech, OCR, autocomplete, a linter and the model it corrects.
Structure
One file, two derivations. A term containing a separator has exactly one plausible spoken form, so the substitution rule can be computed from the entry instead of written beside it; a term that is an ordinary English word yields no safe rule and must be refused. The effective table is printable, so what actually fires can be compared against what the file says, which is the only way to notice that the two have parted company.
Participants
The list, which is a source, not a deployment. The recogniser, which wants it short, because boosting has a cliff. The formatter, which wants it complete. The copies on disk, which are the actual failure surface.
Collaborations
Required by Deterministic Last Mile, whose derived rules are exactly this list's separator-bearing terms. Elaborates Durable Memory: a shared vocabulary is the system remembering what its domain is called, and it decays the same way.
Consequences
Gain: one place to add a term. Gain: the two consumers cannot disagree about what the vocabulary is, only about what to do with it. Cost: one file becomes load-bearing for two subsystems with different failure modes and different tolerances. Trap: the file is a source, not a deployment. One source with two copies on disk is two lists.
Implementation
Derive instead of duplicating. Refuse to derive case-only rules. Make the effective table printable. And resist the obvious defence discussed below (a hand-written duplicate of the derivable half), or if you must, put an expiry on it.
Failure signature
The two uses fail asymmetrically, and that is the whole of the pattern's danger. The house style can be hand-immunised against a stale list, because a substitution is a decision someone can write down. The recogniser cannot: a term is either in the file it reads or it is not, and there is no hand-written fallback for hearing. So a divergent copy degrades the system in exactly one direction and reports nothing — still spelling the word correctly, no longer able to hear it. The transcript is identical on every utterance where it still hears, which is most of them.
⚠️ The immunisation ate the pattern, and it is visible on the machine today. Of the 18 rules the deployed binary reports, exactly one is derived from the shared list. The other seventeen are hand-written. The source explains why, and was right when it was written: which terms were derivable depended on which checkout's copy of the file was present, and a rule that appears and disappears with a file is worse than no rule.
That justification has since expired (both checkouts now carry the same 47 terms), and what it left behind is a hand table that still rewrites speech into the name of a repository renamed two days before publication, which the shared list has correctly dropped. The defence against drift is now the only thing drifting. The claim survives its instance and is sharpened by it: one source, two mechanisms, no drift possible is a claim about the file, never about the filesystem, and a hand-written fallback added to protect one consumer from a stale list will outlive the staleness and become the stale thing.
How you would know this is unnecessary
If the two consumers wanted different vocabularies. The recogniser wants what is said; the house style wants what is written. Those coincide only while a project's jargon and its orthography are the same words. The moment the boost list needs entries that are never written, or the style needs rules for words never spoken, one list is a coincidence being maintained as a principle.
Related patterns
Required by Deterministic Last Mile (5). Elaborates Durable Memory (OM-001, 14). Governed by Honest Gauge (OM-001, 12).
Revised Output · Pattern 7
Intent
Give the draft and the record separate storage, and make the boundary explicit, because the moment they share a buffer, the cheap one becomes the authoritative one by accident, not by decision.
Motivation
Draft and Record says the record has exactly one author. This is the structural half of that, and it is a different claim: not one pass writes the record, but the two passes do not read the same thing.
Here they do not. The scribe consumes a stream as it arrives; the corrector consumes a captured sample buffer with exactly one write site, inside the hold loop. The boundary falls at the buffer, not at the model, which is not where anyone looking at a two-model pipeline would expect to find it, and is why it can be crossed without touching either model.
It was crossed. A 300 ms pad of trailing room tone was added because it recovered dropped final words 6 times out of 6, and it is fed to the scribe's stream and never to the corrector's buffer. So the release pass, the only thing that produces the text that gets typed, sees audio up to the last in-loop drain and nothing after it. The measurement that justified the pad was taken on the path whose output is discarded whenever the corrector succeeds.
That single fact is the pattern's justification and its indictment at once. The separation is exactly what stopped a draft-side change leaking into the record. It is also exactly what let a fix land on the wrong side of the line and stay there, with a measurement attached, looking done.
Applicability
Any two-tier pipeline where a fast stage and an authoritative stage consume the same upstream source: transcription, incremental compilation, preview renderers, any cache in front of a system of record.
Structure
Two artifacts, one write site each, and the count is the invariant. Everything that must reach both is written twice, deliberately and visibly; everything that reaches one by accident is a defect that the structure makes findable and the absence of the structure would make invisible.
Participants
The upstream source, which both consume. Two buffers, which are the pattern. The fallback, which is the one sanctioned crossing and deserves to be named as one.
Collaborations
Elaborates Draft and Record. Required by Show the Handover: you cannot show a handover between two things that are the same thing.
Consequences
Gain: no accidental promotion, ever, and which pass produced this? has a structural answer, not a conventional one. Gain: you can reason about what each consumer actually saw, which is what makes the pad defect statable at all. Cost: anything that must reach both has to be written twice, and nothing checks that it was. Trap: an improvement applied to whichever buffer is easiest to reach from where the change is being made.
Implementation
One write site per artifact, and keep it that way. The count is checkable in a line. When something must reach both, make the two writes visible at the same call site instead of in two files. And name the crossing you do allow: here the release pass falls back to the scribe's text when it fails, which is the one deliberate place the record is written by the draft. It currently reads as a default, not a decision, and the two are worth distinguishing, because the fallback is a real trade: the draft is complete but worse, the last good corrector pass is better but missing the tail.
Failure signature
A fix that works, is measured, is shipped, and changes nothing, because it landed on the path whose output is discarded. Nothing fails. The measurement is real. The improvement never reaches the artifact anyone keeps, and the only way to notice is to trace which buffer the change touched.
How you would know this is unnecessary
If the draft and the record consumed the same input by construction — one buffer with two readers, so there is nothing to keep in step. That is available here and was not chosen, and the reason is worth being honest about: nobody decided. The two buffers grew out of the two libraries' interfaces, and the pattern is a description of an accident that turned out to be right for reasons its authors had not considered.
Related patterns
Elaborates Draft and Record (1). Required by Show the Handover (3). Governed by Honest Gauge (OM-001, 12). Related to Recoverable Execution (OM-001, 13), which is the same instinct about state one level out.
Three, stated because they are live, not because they are tidy.
The room
Two more lamps would make the room the surface, and it could then carry a composed look, which is decoration occupying the channel the alarm needs. Not built. Four failure modes, in the order they are expected to bite:
Offered as a hypothesis and not more: one renderer driving many lamps, with lamps carrying roles (status versus ambience) instead of one renderer per lamp. That keeps precedence single, keeps the room speaking with one voice, and gives presence somewhere to land without the protocol learning about topology. Untested.
Whether the amber highlight survives contact with churn
Answered, and the answer is unpublished. The display marked a word amber whenever it differed from the previous pass, so every alternation fired it again on the same word, carrying nothing: a signal firing often enough to be ignored, after which the real corrections it exists to show go past unseen. The repair is clean and belongs to Churn Is Not Correction: a word returning to a value that position has already held is not a correction.
It is committed on an unpushed branch and is not in the running binary, so it is not citable: a measurement proves the code you measured, and this programme has been caught on exactly that distinction. It also decorates the live view, which the evidence proposes to delete; if that deletion happens, this is a fix to something that goes away.
Whether anyone prefers the hold with continuous correction
This is the one that now decides an architecture rather than a preference. The evidence names its own falsification test and it is not a rig question: the recommendation to delete the corrector's continuous cadence flips if a person, in a blind comparison, prefers the hold with it. Eleven times the corrector time may be worth accurate text appearing while you hold. Nothing here measures taste, and nothing here can.
A pattern language that pretends to completeness is its own dishonest gauge.
Directly ancestral
Adjacent traditions
Primary material
One workstation, one speaker, one microphone, one room, over roughly a fortnight in August 2026. The first half is drawn from building and repeatedly repairing a physical lighting channel; the second from building and living with a local speech pipeline: dictating into it daily, and watching where it went wrong. What one machine establishes and what it cannot is set out in OM-005 §16.
What is claimed
Less than any of the three papers before it, on a narrower base, with more of its entries carrying an explicit note that a claim is untested. Four entries rest on perception claims nobody has tested; one has never been confirmed against a real hand on the device; one has never been observed at the hour it exists for. Five are published with their own reference instance failing them.
That is not modesty and it is not a disclaimer. This is the first paper in the programme to return to a published pattern with measurements from having built it, and the return found two of that pattern's implementation notes insufficient. A language that can be corrected by its own practice, in public, with the measurement that did it, is doing the thing this programme says it is for, and a paper that reported only the parts that worked would have been evidence of nothing except editing.
Corrections and counter-examples: hello@organon.art. A pattern shown not to hold in someone else's room is a useful result and will be recorded as one.