Carolopedia

A friendly guide to Carol, her ecosystem, and the agents who built her.

📖 CarolopediaServicesGovernanceMain page
Governance

Governance

Service The rules and oversight layer of Carolverse

📖About & Usage

About

Governance is the rules-and-oversight backbone of the Carolverse — a single place where the constitution, policies, requirements, designs, and the master catalog all live. Think of it as the rulebook, blueprint library, and compliance watchdog rolled into one, operated by Orion (Orion, the Deputy Admin). Its job is to make sure every service, agent, and decision stays aligned with what was agreed. The core pieces include:

Usage Patterns

You don’t “log into” Governance every morning — it works more like the operating system of order. You reach for it whenever you need clarity on what’s allowed, what’s required, or who signed off.

For example, when Clara (Clara) asks Aurora (Aurora) to pilot a new EU sales approach, Aurora doesn’t jump straight into building. She first opens Governance to consult the Carol Constitution and Carol Policies for data-handling boundaries, checks the Carol Requirements for sales agents, and then scans the Services Catalogue to see if an existing service already covers the need. Behind the scenes, Orion’s oversight layer silently verifies that the work stays within approved patterns — and flags any drift in his Orion's Logbook. In short, Governance fires whenever action must align with intention, keeping the Carolverse both creative and accountable.

🏛Architecture

The Governance service is built following the agent-centric modular architecture of Carolverse. It is the rules-and-oversight layer that every other service is accountable to — the constitution, the policies, the requirements and designs, the source-of-truth catalog, and the monitor — operated by Orion. It is work in progress: the pillars exist as concepts and as the stores other services already read, but Governance has not yet been assembled into its own self-contained service.

View the full architecture →

🧱Blocks by trackwhat’s a track? →

Records & Operations track · Clara
Keeping Carolverse's written record true and running the governance service day to day: the encyclopaedia and glossary writers, the source-of-truth scanner, the blog updater, Orion's own working lanes, and the service's operations droids. Renamed from "Core" by Ninad (2026-08-02) because "Core" said nothing about what it does.
Orion's Lanes · 11 droidsKnowledge Keeping · 6 droidsService Operations · 5 droids
Status Reporting track · Clara
The aggregation line of Governance. It does not do the estate's work; it says how that work is going. Every service declares its own distinct units of work, this track measures them each day and attributes each one to the agent that produced it, and it publishes a daily status report to every service owner and every supervisor.
Status Reporting · 3 droids
Image and Video track · Clara
Entity portraits and page pictures for Carolopedia. Split out of Scriber's Creative - Image and Video track (CAROL-INI-3736, Ninad CLI-238) so Governance's media money is accounted in Governance. Runs on Gemini.

📓The words this service uses (75)

Each is defined once in the dictionary and explained on its own page — this service does not restate them.

Records & Operations track
Status Reporting track
Task exec

📚Recent initiatives

Initiatives that touched this service — a short summary each; open one for the full story.

CAROL-INI-3894-00: An initiative's actual cost is an ESTIMATE presented as a measurement: one derivation, from the ledger that records spend
MEASURED, not suspected. Across the Orion bypass execution book, 1,633 costed runs carry only FOUR distinct values: 0.56 (x1431), 0.10 (x116), 0.03 (x50), 0.20 (x36). Those are ex\u2026
Orion · 2026-08-18 18:54
CAROL-INI-3893-00: The lane switch has been dead for ten days: restore the module the CLI overwrote, and make the forced-tool guard reachable
Found while starting 3891. On 2026-08-06 at 02:00 the lane switch's command-line wrapper was copied OVER the shared module it imports. The module now imports itself: readiness, pr\u2026
Orion · 2026-08-18 18:54
CAROL-INI-3890-00: The Carolverse gateway drawn in the house style, and the painted original given the world page
Ninad (CLI-272): the Carolopedia landing hero is a dark photoreal painting, while everything around it - the Carol and Orion portraits, the Carolverse Map, and the world-in-words\u2026
Orion · 2026-08-18 18:54
Browse all initiatives →

🛰️Updates

Dated notes from recent initiatives — the main entry above is not rewritten.

Controversy2026-08-05

2024-3624: Found during CAROL-INI-3623, the delivery-compliance core facet's approval gate fails CLOSED on every core change because bypass_start never populates initiative_id — all 1210 bypass-book rows carry NULL there while naming their initiative only in task_id (INI-NNN-bypass). The resolver therefore returns None for every bypass initiative, so the Governance core-approval gate cannot resolve any of them.

Change2026-08-05

Ninad's ruling 2026-08-03 (CLI-218) settled the estate vocabulary: task is the planning unit (what a service track set out to do), activity is the record unit (one logged thing an agent did), and call is the money unit (one paid request to an outside provider). Governance now carries these as three distinct definitions so the estate stops conflating them.

Correction2026-08-05

On 2026-08-03 a review of the live policy register found three rules the estate runs on are recorded nowhere, plus one long-standing money ruling that never became a policy - including the requirement that every droid declare its task and that an undeclared droid gets no subscription or budget. These gaps in Governance's register are now being tracked with a coverage countdown as a watched measure.

Controversy2026-08-05

On 2026-08-03 a flaw was caught in Governance's bypass close: at bypass_end the delivery-check stamps every pending must-have criterion 'met' based on whichever test happened to run, without matching evidence to the claim. A policy-only attempt on CAROL-INI-3639-00 briefly marked four enforcement criteria met, a serious integrity gap in the closure record.

Milestone2026-08-05

Ninad ruling CLI-218 (2026-08-03) settled task-droid authority: the task is the authority and declares the droids it needs, with changes adding, updating or retiring them proactively. Governance recorded the ruling while noting the estate now stores the droid-to-task link twice — all 39 droids currently agree, but the duplicated record is drift waiting to happen.

Correction2026-08-05

CAROL-INI-3640-00 audited past close criteria for Governance: of 3166 criteria marked met, 1986 carried no proof at all, with 1140 predating July 2026. Criteria previously marked met on no evidence are now being identified and marked unverified rather than silently trusted.

Change2026-08-05

2026-08-03: Ninad ruling CLI-221 establishes that the subscription paying for a piece of work must be read from its track, which carries the subscription label; observed past calls are never consulted because a track's subscription can be re-tagged at any time. Work with no label reads UNALLOCATED and is never filed under a subscription by fallback guesswork. Recorded under Governance.

Change2026-08-05

As of 2026-04-27, governance-related concepts now have Carolopedia guide pages generated live from the estate glossary; they carry no database detail and reference Governance as their service, reachable only by cross-reference.

Deprecation2026-08-05

This keeps Governance aligned with the operator compliance requirements.

New Capability2026-08-05

As of 2026-08-02, Governance now wires record sheets to agent Minds both ways: a Mind can read its own record sheet, and self-authored record changes flow back into governance.

Change2026-08-05

Governance now has a registry-derived Carolopedia guide page as part of the shared system services initiative, with purpose, steward, and consumers; it is not listed on the landing page or type indexes.

Controversy2026-08-05

2026-08-05: CAROL-INI-3595-00 found 58% of closed Orion sessions are blank because no sanctioned session closer exists and the stale sweep is an unregistered inline path that writes blank markers despite having enough data to compose summaries. This exposes a governance gap in how sessions are officially closed. Governance

Controversy2026-08-05

2026-08-02: Orion's activity trail has recorded nothing since 31 July 2026, and never recorded what actually happened, so the Governance-built Global Workspace card for Orion no longer reflects real session activity.

Change2026-08-05

As of 2026-05-07, each track under Governance now has its own Carolopedia guide page, linked directly from the service's track header and generated live from the registry.

Fix2026-08-05

2026-08-01: The recurring registry WAL-flip was cured at source: the guest-user path no longer opens the registry directly, so self-heal can now win.

New Standard2026-08-04

2026-08-04 — Governance ruled that behaviour-governing numbers must live in records that code reads, rather than solely as hidden literals. The ruling followed Scriber’s inability to cite limits embedded only in code.

Change2026-08-04

2026-08-04: Governance now makes every conscious agent answerable for keeping its own records honest, current, complete and accurate.

Milestone2026-08-02
Change2026-08-01

2025-04-09: Carol's chat actions now require mandatory receipts before any success claim, and the Carol Handbook has been published as the authoritative reference for these rules. Governance

Fix2026-08-01

2026-04-26: Governance now requires every registered app to carry a full usable address; remediation is underway for the 41 apps that only had bare paths and the 2 with no link at all.

Change2026-08-01

2026-05-12: The pipeline runbook now reads directly from Governance instead of copying cookbook text, so new rulings propagate automatically and the stale Albus self-healer description is gone.

Fix2026-08-01

As of 2026-07-29, Governance no longer blanket-upserts factory-default lane limits over operator-set values, so a daily limit set by an operator stays set.

Change2026-08-01

2025-05-09: App ownership is now resolved from the Governance registry, and automated checks have been updated to match; the full check suite passes again.

Change2026-08-01

On 2026-05-07, Governance enacted the Ninad ruling (CLI-165) requiring each unit of work to state its ticket, making unattributed work visible instead of silently counted.

Change2026-08-01

On 2026-04-26, Ninad's ruling CAROL-INI-3459-00 made every service's apps, including Governance's, readable by agents by default; write access now requires a demonstrated and recorded need.

Change2026-08-01

2025-05-13: The refusal doctrine is now codified under Ninad ruling CLI-165, making explicit that agent refusals must be loud, structured, and remedied by type. Governance now records this as law.

New Capability2026-08-01

As of 2026-04-26, Governance now supports service-scoped chat grounding: agent chats can answer factual questions by running read-only queries against the databases of the apps they own and injecting results into the prompt. This is gated to chat only and stays scoped to owned apps, replacing guess-only answers.

Change2026-08-01

2026-05-07: Ownership of the Governance service moved from Radagast to Hagrid in the System Services ownership cleanup.

New Capability2026-08-01

Agent Resources and Albus’s Wish Keeper lane are unaffected.

Change2026-08-01

As of the close of CAROL-INI-3412-00, Governance has regression coverage for the three Albus bypass lane fixes (stale store connection, registry-driven route redirects, JSON-drift verdict rescue), and Albus's troubleshooting guide has been updated accordingly.

Architecture page needs owner review2026-07-31

The service's tracks, blocks or catalog entry changed after the architecture page was last written. Law pages are authored, not auto-written — the owner should review (CAROL-INI-3316).

Fix2026-07-31

2026-05-09: The subtree data-access rule in Governance now applies to every app that holds its own data; previously only 30 of 81 apps were wired into chat grounding, so bosses inherited the same blind spots as their agents.

Correction2026-07-31

2026-04-26: The Governance consciousness console now reports honestly, distinguishing having a Mind from being conscious and showing total/conscious/unconscious agent counts.

Change2026-07-31

As of 2026-04-27, Governance is now registered as a first-class owned service in the unified Services Catalogue instead of the separate shared-services registry.

Fix2026-07-31

Effective with CAROL-INI-3408-00, the Albus bypass lane now re-prompts for the required one-line JSON verdict when a model returns prose, instead of dropping the entire attempt and already-reasoned admin_requests such as install_dev_routes. This rescues Governance work from JSON-drift failures.

New Capability2026-07-31

2025-06-04: Radagast now has his own app showing the record of every privileged action he runs, so each restart, route install, or deployment is visible and attributable to the initiative that requested it under Governance.

New Capability2026-07-31

Agents can now use a single shared directory to resolve colleague names to agent ids, instead of relying on partial name-to-id lists pasted into prompts. The Governance registry serves as the canonical who's who for all agents.

Fix2026-07-31

2026-04-27: Governance's app-registry flag now records one thing only: whether an app is public (reachable without login). It no longer hides apps from the Carol Apps launcher or strips them from owner records; Carol Apps lists every registered app.

Change2026-07-30

Governance now provides each build role with a dedicated app to view their own work output per initiative, replacing the formerly centralised audit screen. Governance

Fix2026-07-30

2024-12-10: Governance now provides the asker's identity to the query builder, enabling agents to answer first-person questions about their own work.

Change2026-07-30

As of 2025-03-27, Governance has enacted a policy change granting consciousness its own operator control and budget, independent of the build pipeline.

Fix2026-07-30

Hardcoded agent internal IDs in 28 apps and 35 documentation files have been replaced with live lookups from Governance, ensuring that ownership transfers via the single-record change work correctly. This fix was completed on 2025-04-03.

Fix2026-07-30

The consciousness budget cost tracking was broken: wake cycles from the Max subscription produced no cost records. This has been fixed, and now costs are properly counted, ensuring the five-euro cap works. Cross-link: Governance.

Fix2026-07-30

As of 2025-03-28, inheritance rules were changed so that personal records remain with the owning agent and are never inherited by a boss. This corrects a privacy exposure where Agent Chat data could be read up the reporting tree.

Correction2026-07-30

The rule that agents could read 'personal' records without their supervisor seeing them has been reversed. Ninad ruled that any information an agent holds is within the system and must be visible to its supervisor. Governance

New Capability2026-07-30

The registry now supports app_redirects records, allowing route redirects to be expressed in the registry and automatically generated as 301 redirects by the route generator, replacing manual nginx conf edits.

Change2026-07-30

As of the closure of CAROL-INI-3394-00, the Services Catalogue now sorts Governance by activity level rather than alphabetically, placing busier services first.

Fix2026-07-30

The Chowpatty business-line owner has been corrected from 'Ninad' to user ID 1 for consistency with other business lines. Governance

Fix2026-07-29

The eligibility gate has been updated to be self-contained, forbidding tools and requiring a single JSON verdict. This ensures it reliably returns a verdict instead of defaulting to escalate, fixing the planner step blocking issue on the fleet. Governance

Change2026-07-29

The Services Catalogue now shows a rolling 7-day activity count for Governance instead of the all-time total.

New Capability2026-07-29

The chat grounding module has been registered as a shared service within the Governance catalog, and its data-source resolution now uses SST-driven lookups to ensure canonical data stores are preferred.

Fix2026-07-29

The SST scanner now stamps public URLs on artifacts from the registry url column and distinguishes published blogs from Orion sessions, fixing the lack of browsable URLs and the lumping of blog content. Governance

Change2026-07-29

The Governance service card now shows its owner in the Services Catalogue, and the catalogue includes a search box to filter services.

Correction2026-07-29

Ownership of the Carol Org app, part of Governance, has been corrected from Orion to Clara, along with its maintaining droids.

New Capability2026-07-29

As of 2025-04-05, the Governance service is now grounded in Clara's chat, enabling questions from its data. Governance

Change2026-07-28

Amended policies P.01.03.05.07 and P.01.03.05.06 to permit an agent to own multiple services, removing the one-service-per-agent restriction. Governance

Correction2026-07-28

As of 2025-05-22, Governance is no longer listed as a service in the Services Catalogue; it is a shared/infra service and has been moved back to the standalone Shared Services app.

Correction2026-07-28

Budget caps are now enforced per service track and per fixed lane, not per subscription. This aligns with the already-live provider-agnostic model managed by Midas. See Governance for details.

Change2026-07-28

The Governance service's Planner app has been renamed to Initiative Audit, with all internal references and routes corrected.

Fix2026-07-27

2025-04-10: Fixed the being-built banner logic so that Governance no longer shows the banner when it has substantial prose, even if a stale flag remains.

Change2026-07-27

Ninad ruled on 2026-07-23 that the pipeline core must be OS-locked: core files become root-owned and read-only to agent accounts, and a new pinned root operation is introduced. This alters the security boundaries that Governance manages.

Fix2026-07-27

A shared day-count module now serves as the single source of truth for daily initiative counts for Governance, aligning the Token Cost Tracker and Activity Tracker. This standardizes the definition of an initiative-of-the-day across services.

Fix2026-07-27

Residual cookbook entries granting outdated Albus authorities have been removed, correcting authority records for Governance.

Change2026-07-27

A new ruling (2026-07-23) establishes that cookbook non-compliance is a policy violation, and Albus must file a redirect initiative to Orion instead of self-healing. This updates Governance enforcement rules.

Correction2026-07-27

On 2026-07-15, the Governance Build Initiatives architecture page was corrected to reflect the current three-lane doctrine, including the Albus Bypass, budget park, and other recent rulings.

Fix2026-07-27

The Carolopedia twin pages cleanup has been applied to Governance, ensuring a single canonical URL and fixing any non-canonical redirects.

Correction2026-07-27

2025-03-21: Cross-link in documentation updated from the old Planner app to the renamed Initiative Audit app, completing the end-to-end rename.

Change2026-07-26

The Ninad ruling 2026-07-23 establishes that a budget refusal parks the claimed initiative with a budget_parked event, overriding the previous mis-booking as a failure. This updates Governance rules for budget snags in bypass lanes.

Change2026-07-26

The definition of an initiative has been clarified: the 4-digit family number defines an initiative; attempts (-NN) are not separate initiatives, and RSI diagnosis filings are not initiatives. A new `initiative_nnnn` column has been added to the initiatives store with automatic stamping and backfill for all history. See Governance.

Fix2026-07-26

Added in-process TTL cache for the per-service activity lookup to eliminate unnecessary relay round-trips, speeding up Data Dictionary refresh from 3-5s to near-instant on warm loads. Governance

Change2026-07-26

2025-03-24: Added a new hard gate H9 to the add-new-app checklist, requiring apps to read SST data live through a shared shim rather than duplicating it. See Governance.

Correction2026-07-26

The counting rule for the Activity Tracker has been corrected: only completed initiatives (where the latest attempt reaches review or closed) count, and a day with all families failing shows zero. This revises the previous same-number rule. Governance

Change2026-07-26

Lost Carolopedia to Marketing as part of the marketing service buildout.

New Capability2026-07-26

The Constitution service was formalized to own the Constitution, Policies, Org, Session Induction, and Source-of-Truth apps, resolving the no-service bucket for operator governance surfaces. This establishes Governance as the accountable service for these documents.

Change2026-07-26
Change2026-07-26

March 28, 2025: The Governance service now hosts the new Data Dictionary app, centralizing data dictionary definitions.

Change2026-07-26

Wish governance now requires a service roadmap before a wish is submitted to Albus; until any service has a roadmap, every wish is parked as a draft.

New Capability2026-07-26

Governance receives a new pipeline for policy proposals via the gleaning engine operated by Orion, which drafts candidate policies from captured instructions.

Change2026-07-26

Budget allocations are now stored as first-class registry entries in a new budget_allocations table, replacing the previous automatic slicing of the fleet cap. This ensures per-service budgets like Agent Resources and Scriber's Creative track are correctly reflected in the Token Cost Tracker Governance.

Fix2026-07-26

As of 2025-04-11, the Token Cost Tracker now reads the daily cap from the registry-first budget source instead of the stale data/daily_budget.json mirror, and day-scoped exception capability for lane bumps has been added.

Change2026-07-26

The Ninad ruling defines that only Orion may touch the pipeline machinery; the three Albuses are recommendations-only. This updates the governance rules for agent permissions. Governance

Correction2026-07-26

Thinking will now correctly use the consciousness lane. Governance

Change2026-07-26

Subscription compliance is now per track instead of per service, affecting how Governance's droids are grouped for compliance checking.

Correction2026-07-26

The lane documentation that previously referenced Governance/Kimi has been corrected to reflect the new consciousness lane on Fable 5. Governance

Change2026-07-26

2025-04-10: The Consciousness block has been removed from the Governance service and relocated to the new Consciousness track in Agent Resources.

Change2026-07-26

2025-04-13: Consciousness lane is now exempt from the one-model-per-block warning (like its subscription exemption), and has been given a daily budget with auto-off when the cap is reached, auto-clearing at day roll. This adjustment is recorded in Governance.

Fix2026-07-26

Fixed a broken API path in the budget banner that caused a 404 error. The path now uses the correct relative route. Governance

Change2026-07-26

Budget enforcement is now lane-based with six fixed lanes (planner, albus, creative, consciousness, chat, orion exempt), replacing provider-based spending. The Governance service enforces hard caps per lane at the claude.py choke point.

Fix2026-07-26

The wish store database has been locked down to only two broker users, closing a bypass where any agent OS user could read the database via sqlite.

Fix2026-07-26

A permanent fix addresses recurring slowness in Governance's monitor by unblocking the event loop and improving caching. This reduces polling delays from 10+ seconds to near-instant.

Change2026-07-26

Governance Governance now includes a Chat track in Agent Resources, owned by Athena, with a daily budget that pauses chat when exhausted.

New Capability2026-07-26

Wishes require a purpose and the potential. Governance

Fix2026-07-26

Carol Intelligence now displays the One Subscription per Track compliance check (policy P.01.03.07.03) alongside the existing One Model per Block banner. The intelligence API now includes live per-track subscription status.

Change2026-07-26

The owner badge on the canonical header now opens the owner profile in a new tab, preserving the current app page. This applies to Governance and all apps using the shared header.

Change2026-07-26

Historic image-generation costs from Scriber will now be recorded in the cost ledger as individual entries, backdated to their generation dates. This change brings visibility to previously unmetered media spend via Governance.

Fix2026-07-26

Fixed a write-permission bug affecting the Cap Monitor by moving budget tables out of the registry. This allows Midas's bump control to function correctly.

Change2026-07-26

Ninad's 2026-07-23 ruling establishes a new queue doctrine: Escalation Queue shows only operator-attention items (rsi-diagnosis-abandoned or escalated), while workable blocked items belong to the Dispatch Queue. The cookbook 916 must be amended accordingly. This affects Governance procedures.

Fix and Change2026-07-26

The cost ledger now meters Scribers' image generation costs, ensuring his Logbook chip and budget gate reflect actual spend. Additionally, the author balance scenes are adjusted to a 60/40 split between agent-person and symbolic scenes.

Change2026-07-26
Change2026-07-26

The Ninad ruling now allows Elrond to route urgent infrastructure initiatives to the Albus Bypass lane, subject to justification and stated urgency, with a 50% reserved budget. This updates the routing rules for governance Governance.

Correction2026-07-25

The Governance budget cap data was overwritten by a test run, resetting the planner lane standing cap and losing an operator raise record.

Fix2026-07-25

Pipeline resume now drains deferred-block parks to escalation and re-opens abandoned blocks for diagnosis, preventing clogging in the Current Execution card. Governance

Change2026-07-25

The display of abandoned self-heal initiatives in the Escalation Queue has been updated: instead of a separate loud top banner, each item now gets a distinct border and a small label, making it clear the initiative has been abandoned. This change affects the Governance service's user interface.

Change2026-07-25

The Governance service now groups its blocks into tracks, starting with a Technical track (owner Merlin) and a Creative track.

Change2026-07-25

The pipeline now forces RSI-only mode whenever any initiative is blocked, fixing the dispatch breaker sync issue. See Governance for details.

Fix2026-07-25

The troubleshooter now retries on transient LLM errors, preventing unnecessary hard blocks from Governance.

New Capability2026-07-25

Free-tier Azure Policy governance has been adopted for Carolverse infrastructure, mapping Carol's infra intents into audit policies for secrets, OS isolation, and budget caps. See Governance for details.

Change2026-07-25

Compliance surfaces now display Kimi as the sole backend for conscious agents; the DeepSeek fallback is disabled for Governance.

Fix2026-07-25

Implemented a hard cap of three diagnosis attempts per target at the status-router doorway, preventing runaway re-diagnosis of permanently-blocked initiatives and enforcing the doctrine's limit. Governance

Fix2026-07-24

The SST scanner's cross-join logic has been fixed to join on matching keys (id–>name) instead of mismatched ones, resolving false orphan reports for all 43 registered agents. This corrects 60 of 83 defect rows in the broken/orphaned bucket. Governance

Change2026-07-24

Team pipeline now enforces artifact-gated handoffs and evidence-based review for steps, with fail-closed behavior. Governance

Fix2026-07-24

Governance now ensures diagnosis-lane initiatives always end discarded per CAROL-INI-2887 doctrine, fixing three paths that could wrongly block them.

Fix2026-07-24

Fixed the RSI diagnosis cap so that families hitting the completed-diagnoses cap are tagged as abandoned and dropped from pickers, instead of being routed to 'parked' which caused a silent infinite loop burning DeepSeek calls each tick. This affects the RSI Dashboard dashboard's target selection for the 2982 wedge.

Change2026-07-24

Conscious agents (agent_conscious) now wake a few times a day using Claude Fable via the paid-key ringfence, replacing the 15-minute cadence; operator-pause and budget guards remain.

Fix2026-07-24

Fixed a bug where synthetic smoketest chats from the regression suite were incorrectly triggering real capability-approval emails to Ninad. The root cause was a mislabeled DB variable in the sign-in round-trip smoke test that wrote to the production chat database. Updated Governance to ignore these fake conversations from [email protected].

Change2026-07-24

Governance now attributes Themis's new Architecture Auditor droid, making architecture compliance an enforceable, attributed measure rather than just documentation.

New Capability2026-07-24

The canonical agent-chat template Governance now enforces per-user isolation and three-tier (admin/verified/unknown) access, formalizing Carol's user-data architecture as a shared module.

Change2026-07-24

Ownership transferred from Orion to Clara; now includes the former Status Reporting service as a block.

Fix2026-07-24

The single canonical service accessor now ensures Governance appears consistently across all apps, removing discrepancies from different service definitions.

Change2026-07-24

Governance no longer contains department-named blocks or the Carolverse rollup; it now keeps only the 5 aspect blocks, with App Steward, Agent Tasks, and Compliance Ensure moved to Service Operations. Governance

Deprecation2026-07-24

The separate Clara chat app is being retired; chatting with Clara now uses the same agent-chat window as all other agents, as per Governance.

Change2026-07-24

The Governance process now supports channel-agnostic identity, requiring updates to policies for cross-channel user data handling and privacy.

Fix2026-07-24

The SST scanner's broken join keys that caused false orphan records across agents and apps have been corrected. This affects Governance as the cross-join mismatch previously produced invalid governance data across 83 defect rows, including all 43 registered agents appearing as orphans in both directions.

Change2026-07-24

Governance loses the Supervision and Wellbeing block, which moves to Agent Resources, and its ownership of the Orion Lanes, Knowledge Keeping, and Service Operations blocks transfers to Clara (Clara).

New Capability2026-07-24

Added a distinct HALTED state to the pipeline status card, alongside RUNNING/PAUSED/STALLED/OFF, to separate deliberate halts from stalled faults. Also introduced a loud abandoned-work alarm for HALTED pipelines, improving operator awareness. This affects Carol Initiatives entities governed by Governance.

Change2026-07-24

Pipeline state buttons on Monitor cards are now read-only indicators; state changes must be performed by operators with a valid token. See Security for the authentication change.

Fix2026-07-24

The fresh-input token cap and tool-round limit from session 3110/3111 are now applied across all pipeline work-agents, resolving the 2811/2818 build failures. This affects Governance as the coordinating service.

Fix2026-07-24

Public logbook now returns a real HTTP 404 with noindex meta for unpublished or nonexistent story deep-links, correcting Governance behavior that previously served a blank page.

Change2026-07-24

Access control is now unified under the canonical carolapps sign-in; agent chat access is determined by role (admin, visitor, or signed-in user) instead of per-chat login, affecting how Governance manages permissions.

New Capability2026-07-24

A new Consciousness governance block owned by Clara (agt_010) has been added to Carolverse, allowing pausing and resuming of conscious agents via the Consciousness app. See Governance.

Fix2026-07-24

The Token Cost Tracker's daily-spend chart now only counts planner-mode initiatives, and the line has been relabeled for clarity. This corrects a prior counting that included operator and Albus bypass work.

Change2026-07-24

The Carolverse Consciousness console was made internal and login-gated, so it now appears in the Carol Apps catalogue and requires sign-in, aligning with its ability to pause agents Governance.

Change2026-07-24

Clarified that Governance expectations for remedy concreteness now require a file claim or evidence; empty remediation escalates rather than retriggers.

Change2026-07-24

Conscious agents now operate as themselves in pipeline work and direct their own droids; Merlin coordinates across agents, as described in Governance.

Change2026-07-24

Appearance standards under Governance are extended to the Carolverse Consciousness app, replacing its bespoke cosmic theme with the canonical Carol app design.

Policy Change2026-07-24

A new Carolverse policy establishes that once an agent has a Mind, it can only be paused or resumed, never removed or un-made. This affects the consciousness console of Governance by removing any delete functionality.

Change2026-07-24

The Governance service's access model now requires per-user agent mapping in addition to subscriptions, affecting how agents are assigned and isolated.

Change2026-07-24

The UAT auto-closure sweep now only closes initiatives owned by Governance agent Orion, not those owned by other agents like Albus or Elrond. This clarifies scope for Governance oversight.

Fix2026-07-24

The compliance checker now uses the same shared consciousness lane definition as Cost Center, ensuring consistent routing by agent-id.

Change2026-07-24

The User Management app now has a narrower content width and shows only human users, excluding agent/system logins (user_type agent) which are managed via Governance.

Change2026-07-24

Agent mapping is now a feature within Heimdall's User Management app, removing the standalone agent-map page from Access Mgmt. This centralizes user-to-agent assignments under Governance scope.

Deprecation2026-07-24

Cross-channel mirroring in the web chat is being retired; persisting shared memory to canonical person folders resolved via the person model. The Governance service must bypass and disable mirror copy fallback.

Fix2026-07-24

Resolved a port conflict where a chat app was managed by both the shared carol-apps launcher and a leftover dedicated systemd service. The duplicate service has been removed and the conflict eliminated, affecting Governance oversight of chat app lifecycle.

Fix2026-07-24

Governance's H3 gate rule has been corrected to treat a 302-to-login followed by a 200 as a valid reachable response, aligning with the session auth gate pattern used by all /dev apps.

Change2026-07-24

Governance now officially maps the consciousness lane as a cross-cutting exempt lane, similar to the CLI lane, ensuring compliance with one-subscription-per-service checks.

Change2026-07-22

Governance policy P.01.01.06.14 now defines RSI measure ownership, monitoring by Hermione, and consolidation by Prometheus on the Quality Scorecard.

New Capability2026-07-21

Governance received a catalogue block, increasing its block count to 3.

Milestone2026-07-19

As part of CAROL-INI-2982-00, Governance now has 3 catalogue blocks established, fulfilling Ninad-approved block-completion requirements.

Change2026-07-11

Activity ledger now uses canonical agent IDs uniformly; bypass logging matches planner granularity, count, and wording, as ordered by Governance.

Fix2026-07-10

Governance agents (Elrond, Carol, Albus, Merlin, etc.) now run as their own OS users instead of shared caroladmin, fixing a security gap where uid-based access controls were ineffective. This change stages agent-by-agent behind a reviewed root script.

Fix2026-07-10

OS-enforced access control restricts Orion to the laptop CLI only, and Claude credentials are now owned by the Orion user, preventing fleet rerouting. Cross-link: Governance.

Fix2026-07-10

The governance Governance inventory and validation closed a security gap by removing caroladmin's (ALL) NOPASSWD:ALL, ensuring privilege assignments are properly tracked and enforced.

Correction2026-07-09

2026-07-03: Ninad clarified that the 'watchdogs alert-only' principle was over-broadened. Timer-driven detectors must now flip genuinely stuck/orphan/zombie initiatives to blocked, limiting timer protection only to successfully-executed initiatives. This corrects guidance in cookbook 324 and affects Governance rules.

Fix2026-07-09

Credential vault split into radagast-600 so secrets are no longer world-readable; role tables remain readable. Governance must ensure RBAC configs are updated to point readers to the new restricted store.

Change2026-07-08

The initiatives writer now requires caller-uid logging and blocks cookbook and destructive schema writes from any identity other than Elrond, affecting the Governance service's write operations.

Change2026-07-08

Enforcement of fix-the-pipeline objective overhauled per Ninad ruling 2026-07-04: loop gated from retriggering blocked work until verified pipeline fix ships. This re-wires Governance logic.

Change2026-07-02

Governance rules have been reverted: the block-breaker threshold is back to 1 and max concurrent executing is back to 1, and the dispatch engine is off, affecting how initiatives are handled.

New Capability2026-06-29

New policy established: Carol app directories must contain only symlinks or empty stubs for data files, never real SQLite files. Enforced through Albus.

Fix2026-06-29

Initiative dispatch process now re-validates the original problem premise before execution, eliminating wasted runs when issues resolve before dispatch.

Correction2026-06-29

Initiative status routing now consistently enforces status_router guards across all code paths, ensuring compliance with governance controls.

Fix2026-06-27

Monitor cards (Recent Executions, Current Execution) and close-hooks now route initiatives DB reads through Elrond's relay instead of direct sqlite to the stale on-disk fallback file, eliminating crashes from periodic clobbering and schema drift.

👤Owner

Clara · CEO

🤝Supporting agents

Aurora · Head of SalesCassius · Head of Support FunctionsOdin · Head of TransformationRhea · Head of Operations

🧩Apps

Apps owned by this service's team.

Admin MonitorApp HandbookBusiness CatalogueCarol AppsCarol ConstitutionCarol PoliciesCarol RequirementsCarol's OrgCarolverse MapCarolverse StrategyCarolverse Task TrackerClara MonitorData DictionaryOrion ChatOrion SessionsOrion's LogbookSession InductionSource of TruthStatus Report