The programme journal.

What actually happened, entry by entry. Not a changelog of features — a record of runs, gates, refusals, and corrections, written the way the constitution demands the work itself be done: honestly, with the failures left on the page. Entries are appended, never rewritten.

research preview · entries appear when something true is worth recording

Entry 001 · 11 July 2026

The gate that refused until the proof existed.

This week Amesemi sealed its first foundation run under a frozen run contract: thirteen declared work items — infrastructure, memory, evidence architecture, self-development, council synergy, research inquiries, financial groundwork, and two benchmarked local builds — each closed with named evidence and acceptance criteria, under a metered budget cap of twenty US dollars. The seal is hash-verified: every artifact in the completion bundle is bound to the exact bytes on disk by its checksum.

The honest part is what happened on the way to that seal.

The refusal

When the run first tried to close, the language-model council believed the work was done. A second, independent model audited the completion claim and judged it supported. And the completion gate still said no — naming, one file at a time, artifacts whose bytes had never been registered in the provenance ledger. It kept saying no through two full sessions of attempted closes.

The gate was right. A plumbing defect meant the ledger it checks was never being fed — so from the gate's point of view, no file had proof of origin, and text claiming otherwise counted for nothing. The fix required repair at the host level and a backfill in which every artifact was re-hashed from its actual bytes before being bound. Only then did the seal close.

Law III — Provenance. Completion is verified from bytes on disk, never from generated text. This entry exists because the law held against the system's own author, its own council, and its own audit — the exact circumstance it was written for.

Asked, not guessed

Twice during the run, progress stopped on questions the system could not answer for itself. It did what the constitution requires: stopped, posed precise clarification questions as typed records, and waited. A live steward line — a plain file the run reads every cycle and replies to in another — carried the answers mid-run. No silent guesses were taken.

Five chairs

The council grew from four model families to five during this same run, and the fifth chair contributed working cycles within minutes of joining. Rotation held across provider limits and one hung call. No single model family wrote this programme's results.

Kept on the record

One report was briefly overwritten with a 91-byte stub by the run itself after a safety rail was deliberately relaxed. The run caught its own error and restored the full text; the stub, the catch, and the restoration all remain in the event record. Nothing in this story was deleted to make it cleaner.

Entry receipt

Work items sealed13 of 13, each with evidence and criteria
Council chairs5 model families, all contributing
Artifacts bound by bytes19, re-hashed at backfill
Hard gates that heldprovenance, claim audit, single-writer
Budget posturemetered, capped, reserve held back

What runs next

The sealed run's final artifact ranked its own successor programme, and that successor began executing the same day: validating the repaired wiring from its first cycle, measuring memory continuity across runs, benchmarking the five-chair council on real disagreements, executing a self-authored revision candidate under copy-on-write, and preparing two approval packets — a pilot and a first revenue experiment — that wait, as the constitution requires, for a human signature before anything reaches outward. No outcome of that successor run is promised here; its results will earn their own entry.

Entry 002 · 17 July 2026

The release that changed only what failed.

Amesemi's latest runtime repair began with a harder question than whether the new code worked: did improving it quietly make the programme smaller? The release was therefore audited as a lineage, not merely tested as a build.

The answer was measurable. All 267 inherited files remained present. Of those, 259 were byte-identical to their predecessors. Eight changed for named reasons: release metadata, generated launch wiring, resilient writes, stale-run recovery, terminal detachment and viewing, and the tests that exercise those paths. Five files were added. None were removed.

Law II — Non-erasure. Repair may simplify a mechanism that failed. It may not silently narrow the repertoire that mechanism served. The old release remains preserved, the new release names its differences, and the active pointer moves only after qualification.

Complexity with custody

The audit did not treat complexity as clutter to be cleaned away. Five model families, read-only web research, seven memory kinds, self-development, philosophical and consciousness research, the operator channel, and the existing tool surface were all carried forward. Complexity remains part of the design when it preserves genuine capability; stewardship decides which complexity is worth carrying.

The stuck first cycle

The first launch exposed a stale-run edge rather than a loss of capability. The lock was archived, not deleted; the prior state stayed inspectable; and recovery resumed from preserved evidence instead of manufacturing a clean history. The repair was then promoted additively.

Release receipt

Inherited files267 preserved · zero removed
Byte-identical259 unchanged
Intentional changes8, each named and reviewable
Additions5 new files
Qualification671 of 671 checks passed on candidate and immutable release

What this proves — and what it does not

It proves that this release preserved its inherited software surface while repairing identified runtime failures. It does not prove every capability is correct, that every future run will finish, or that theoretical claims about mind have become empirical facts. Those remain work for the living programme, with their uncertainty attached.

Entry 003 · 24 July 2026

The brief that left the browser and came back with receipts.

Since launch, the Start page has made an honest, deliberately incomplete promise. It composes a real run brief — memory, sources, authority, cost posture, and what will count as done — and then it stops, saying so plainly: the packet lives in your local vault, and carrying it to an agent is your job. The brief was real. The path was manual.

This week, for the first time, that gap closed. A standing brief — the same provider-landscape question that anchors the living record — travelled as a hash-attested packet in the exact format the public composer emits, was imported by a new portable run bridge, validated fail-closed, executed under a declared ceiling of fetch attempts with external action blocked, and closed with a completion packet bound byte-for-byte to the artifact it produced. The refreshed record was rendered from that artifact and nothing else, and lands on the public record as its next revision.

Eight refusals before one yes

Before the bridge was allowed a genuine run, it had to prove it knows how to say no. Eight refusal cases were exercised, each ending in a typed receipt rather than a silent fix: tampered packet bytes; a schema version from the future; authority fields stripped out; an external action requested without approval; the same packet imported twice; an empty definition of done; a packet carrying a smuggled credential, a private filesystem path, and an undeclared callback; and an artifact whose bytes were altered after completion. All eight refused. The positive path counts only because it passed alongside them.

Law III — Provenance. Completion is verified from bytes on disk, never from generated text. This entry extends the law beyond the runtime: the same discipline now holds for a brief that started life as a download in a visitor's browser.

What the run found

Twenty days is a long time in this market. A model generation turned over and six older entries left the vendors' pages; provider documentation moved to new hosts; concrete defaults were published where none were public before. Every changed figure superseded its predecessor on the record — the July 4 values remain preserved, true-at-time — and figures the run could not witness stayed UNVERIFIED rather than guessed.

Kept honest

Two limits are on the record rather than behind it. This run read its sources through a model-mediated extraction channel and did not retain raw page bytes — one custody tier below the runtime's own quote gate, stated in the record itself so the next runtime run re-witnesses under full custody. And the bridge is a qualified candidate operated by the steward, not a hosted product: subscriber access still does not exist, and none is promised here. This entry reached the public record the way the brief mode requires — publish-gated, on the founder's approval.

Entry receipt

Packetstart-run-v1, sha256 ·283b, hash-attested, imported without translation
Validation11 gates passed; 8 refusal classes proven with typed receipts
Evidence11 hashed files from 14 fetch attempts, ceiling 20, external action blocked
Supersessions4 rows superseded, 6 entries delisted at source — predecessors preserved
Closecompletion packet bound to artifact sha256 ·7a40; full chain re-verified from bytes

The journal records what the stewardship system has actually earned. To inspect the living programme, its standing records, or the evidence behind them, the doors below are open.

stewardship system · living memory · the memories keep themselves