Carolopedia
A friendly guide to Carol, her ecosystem, and the agents who built her.
📖About
FOLLOW-ON to CAROL-INI-3468 (awaiting UAT), NOT a repeat of it. 3468 corrected how spend was MEASURED on the lanes that existed on 30 July - dollars compared against euro limits, day-scoped lifts ignored, five workers whose names did not match a track. This initiative concerns a lane that DID NOT EXIST then: the Codex flat subscription was authenticated for the first time today. It is not mismeasured; it is UNMEASURED - it emits no ledger row whatsoever.
Ninad ruling (2026-08-01, CLI-196), after he asked the right question: does moving a track to a flat subscription quietly disable its cap?
MEASURED: YES, it would. A live Codex run was made on the newly authenticated lane and it recorded ZERO ledger rows. That is WORSE than the dead account it replaces: a dead account fails loudly, an unmetered lane works perfectly while running with no limit at all, and the first anyone knows is the bill or a throttle.
THE PATTERN ALREADY EXISTS AND IS PROVEN. Kimi is also a flat monthly subscription, and it has logged 246 priced calls: its models carry NOTIONAL rates so the work still books a euro value still bites, even though the real money is a fixed fee. That is the stated design - a call on a flat plan must count the same as a metered one.
WHAT MAKES IT EASY: the Codex tool writes a session record for every run carrying the full token breakdown (input, cached input, output) and names the model it used - gpt-5.6-sol, whose notional rates are ALREADY registered. So metering is wiring, not invention.
IN SCOPE (a bypass can reach all of it): - register the codex provider and its model with notional rates; - a metering step that reads a run's own token record, prices it at those rates, and appends an attributed ledger row so it rolls up to a track and a service; - prove the cap actually REFUSES once the track is spent, rather than trusting that it would.
NOT IN SCOPE: pointing Carol's chat, Scriber's chat or the agent minds at the lane. The file that chooses a provider is root-owned and needs a core-install. Metering must exist BEFORE that switch, not after, which is the whole point of doing this first.
⚖️Decisions
- Auto-detected remediation target INI-999902342 from title/description scan (matched CAROL-INI-3468 -> row id 999902342 (CAROL-INI-3468-00: One spending limit per service track, correctly measured and )); override by setting remediates_initiative_id explicitly at bypass_start. (system-auto-detect)
- Elrond's bypass methodology checklist (a reminder, not a gate -- you've got this): 0. File it requested_mode='bypass' (planner-vs-bypass is a deliberate choice). bypass_start REFUSES a non-bypass initiative (CAROL-INI-1846), and the dispatcher only skips the bypass lane when the mode says bypass -- a 'planner' mistag lets Merlin's pipeline grab the placeholder step and block your finished work. 1. Filed as planned status -- let the bypass claim/activate it; never file active. 2. Open the bypass (bypass_start) with your droid id + the remediation answer (remediates_initiative_id=NNN, or remediates_nothing=True). 3. Work the blocks for your work-type: template -> design -> code -> test -> review. Do the real work; record decisions on the initiative as you make them. 4. Reality is recorded for you at close -- code (files changed), each decision, and the twin-review verdict become real activities tied to this initiative and show in the Activity Tracker like a planner run (CAROL-INI-1840). No dummy rows. 5. Keep the initiative status moving; it parks in 'reviewing' and is tagged uat-pending for you at close (CAROL-INI-1836), so the stuck-watchdog leaves it alone until UAT. 6. Close runs the gates (design/architecture compliance + caller-audit). If a gate flags something pre-existing or unrelated to your change, waive it with a clear written rationale -- audit, don't skip. 7. Bypass skips the planner's auto-orchestration, NOT the standards. Same template checklist, same review, same observability as a planner run. (elrond)
- [status-router] planned -> executing | event=bypass_executing | bypass transition (or-bx-01)
- [delivery-check] 6 must-have criteria remain pending at bypass_end — delivery FAILED live re-performance; UAT must grade on live evidence, not checklist silence (CAROL-INI-3020): test test_ini3572.py: FAIL (no tests ran in 1.88s) (orion)
- [status-router] executing -> reviewing | event=bypass_reviewing | bypass transition (or-bx-01)
- [delivery-check] 6 must-have criteria remain pending at bypass_end — delivery FAILED live re-performance; UAT must grade on live evidence, not checklist silence (CAROL-INI-3020): test test_ini3572.py: FAIL (no tests ran in 1.97s); test test_ini3572_adapter.py: FAIL (no tests ran in 7.16s) (orion)
- UAT FINDING FROM NINAD (2026-08-02): the objective is NOT yet met. This initiative's ruling — the lane names the LANE, not a supplier — was applied to the chat and consciousness lanes, which correctly followed the estate onto Codex. The account has been dry far longer than tonight: the LLM health watcher has logged '429 insufficient_quota — account out of credit' 51 times, the first on 15 JULY. The work did not fail loudly, it degraded quietly, which is why three weeks passed unnoticed. Orion is completing the missed three under this initiative at Ninad's instruction rather than filing a separate one — the duplicate gate correctly refused a new filing as the same underlying work. (orion)
- [status-router] reviewing -> executing | event=bypass_executing | bypass transition (or-bx-01)
- [status-router] executing -> reviewing | event=dispatcher_transition | dispatcher state change (ds-s1)
- [delivery-check] 6 must-have criteria remain pending at bypass_end — delivery FAILED live re-performance; UAT must grade on live evidence, not checklist silence (CAROL-INI-3020): test test_ini3572.py: FAIL (no tests ran in 1.80s); test test_ini3572_adapter.py: FAIL (no tests ran in 5.76s) (orion)
- READ THE 'FAIL' VERDICT CORRECTLY. The twin reviewer then graded the initiative as a whole and returned fail — correctly, because this initiative's SIX must-have criteria are all about METERING the Codex subscription, and every one of them is still pending. That is the parallel lane's original scope and is untouched: it was not attempted, not re-closed, and its open work was left alone. The initiative stays in reviewing, exactly as that lane left it. What could NOT be done, and why: speech has no second engine to move to — Codex serves one coding model and cannot speak — so Ninad ruled speech is Gemini-only and the dead fallback was removed rather than repointed. An earlier repoint of speech to Codex was made and then REVERTED on checking the provider record; shipping it would have been plausible and wrong. (orion)
- [status-router] reviewing -> closed | event=operator_signoff | Auto-accepted (CAROL-INI-1859): Orion-initiated, >2 days in reviewing with no objection. (el-srac-01)
✅Success criteria
- A unit of work done on the flat subscription shows up as spend against its track, exactly as the same work would if it were billed per call. (must_have)
- Once a track has spent its daily limit, further work on the flat lane is REFUSED — proven by driving a track to its limit and watching the refusal, not by reading the code. (must_have)
- The estate and service totals include flat-subscription work, so a lane that costs no money still consumes its share of the limits. (must_have)
- A person can see what the subscription lane cost today in the same place they see every other cost, rather than it being missing. (must_have)
- If the usage record for a run is missing or unreadable, that is recorded as unmeasured rather than counted as zero. (must_have)
- No work is blocked because the meter itself failed — a broken meter reports itself instead of halting the estate. (must_have)