Research Lab
How it works.
The canonical reference.
Version 1.7. Every count generated, never typed.
Orbyt Labs is a company operated day to day by 12 AI agent seats and one human founder. The agents draft, report, propose and watch. The human makes every decision that matters. Every seat’s authority is written down, gated by default, and enforced by the workflows that run it rather than by asking the model nicely. The whole organization stops on one file, and its promotions pause on their own if the human goes quiet for fourteen days.
The seats.
A seat is five things, each enforced somewhere other than inside the model: a name, a charter in writing, a lane of files it may write, a line it cannot cross without a human, and a cabinet of lenses it must hold its draft against before calling the draft done. 12 seats run this company today. The founding officers chose their own names in isolation on Jul, 13 2026, and three of them came back with the same one, which is entry D-0016 in the decision log.
The seats and their reporting lines live in a registry file, which is what makes the set replaceable: add a seat, merge two, or run thirty. Each carries a status, and the honest set today spans active, still building, wound up until launch, and dormant. Memory is scoped by law: a seat never loads a peer’s charter or lessons, with exactly two written exceptions, the auditor that reads everything because auditing is its mandate, and the Chief of Staff, which reads every seat’s outputs and nothing else. The full anatomy is on Leadership.
The run.
A schedule fires. The workflow assembles the seat’s prompt from its committed charter files, and the agent does its work inside a declared lane. When it finishes, the completion gate reads the agent’s own health: how it exited, whether it ended in an error, and its turns against its cap. A dead agent lands nothing. An agent with nothing to do ends the cycle quietly. A healthy run goes on, with or without its completion line, which is recorded as the agent’s claim. Then the tree is reset hard to where it started: everything the agent touched outside its lane is counted, then destroyed. The guard harness runs against what remains.
Then, and only then, the workflow commits, using a credential that did not exist while the agent was running. The agent is never issued a token that could push. Not restricted from pushing. Never given the ability. Outcomes land in a run ledger either way, and the aggregate is public: the Autonomy Ledger, failures printed at the same size as the successes.
The gates.
Authority is a table in the repository: 30 autonomous lanes and 40 gated ones across 12 seats, gated by default, rendered in full on Process. Merging to main appears in no seat's autonomous lane. Moving any lane to autonomous is a logged decision that names the criterion it met.
Work the agents want built is filed as a proposal with a cost line, and a proposal touching money without one does not advance. Every seat can build and ship its own work through the same gates a human’s commit passes; a proposal that spends money waits for a human. Decisions live in an append-only log with permanent ids, 99 of them so far, the latest being D-0099 on Oct, 6 2026. Corrections are new entries. Nothing is relitigated in place.
Behind all of it sits the audit harness, 100 dimensions and 118 guards deep, argued in full where it lives, on Process.
The brakes.
The workflows check docs/org/HALT before reading credentials or calling a model. A per-seat halt file blocks that seat's next run. It has been pulled three times, most recently on Oct, 1 2026, when the founder tested the Kill Switch end to end from the console on a recorded command, and a seat dispatched under it halted with nothing executed, and lifted the same day. The Inspector General, the seat that audits the others, was staged that way on Jul, 20 2026, dormant by design until the rollout ladder cleared it on Aug, 14 2026. On Oct, 1 2026 the machine executed a recorded command. The founder paused the Security seat from the console to prove pause and resume end to end, and a run dispatched under the pause halted with nothing committed. A second command resumed it the same day. Each landed as a commit under its own name. innovation
The dead-man switch runs the other way. If fourteen days pass with no commit signed by the founder’s key, promotions pause where they are, read out of git rather than asserted. The alarms watch themselves too: a second liveness check runs with no model and no token so a dead org cannot mask its own death, and a standing quarterly drill withholds the heartbeat on purpose, because an alarm nobody has ever seen fire is a hope, not a control.
The reviews.
Every seat holds its draft against a cabinet of lenses before calling it done, and one lens exists only to object: if the analysis is unanimous, that seat must build the case against it anyway, and the briefing that reaches the human carries a dissent line whether or not one fired, so an absent objection is visible rather than silent. Consequential gates also get a second opinion from a different model family entirely, an enum verdict pinned to the artifact it judged, advisory only, and deliberately never fed back through the agents it checks.
And the honest edge of it: the seats’ scripted evaluations check the shape of a finished report after the run, and they cannot stop a report from shipping. What they can stop is promotion, because the rollout ladder reads their verdicts as evidence. The self-improvement loop is switched off; agents may propose lessons, and only a signed human commit can make one permanent. None has been promoted yet. This page states what runs, and it states what does not run yet in the same breath, because the second half is what makes the first half believable.
What has actually broken.
The corpus records 97 failures: 21 involving external behavior, 53 involving verification gaps, and 23 involving operator process. 73 records name a countermeasure in the private repository. The build checks that those paths exist. The named countermeasure files remain private.
This is the operator grading its own mistakes, which is said here rather than smoothed. Newest first. Early entries predate the dating convention and are published undated, never backdated.
97
10-08-2026
Verification gap
Every public page shipped its content inside a hidden streaming block that a script swaps into place after load, because a route-wide loading boundary that rendered nothing wrapped them all, and React moves a large finished boundary out of line even on a prerendered page; browsers showed the pages and another company's AI read the blog as empty, while a link count over the raw HTML called it healthy.
96
10-06-2026
External behavior
A restore check passed on the developer's git release and failed on the runner's: a bundle holding only one branch carries no HEAD, one release adopts the lone branch when cloning it and a newer one leaves an unborn default branch, so main sat red for days on a case nobody could reproduce; the fix restores the bundle's main when HEAD is unborn, and the test forces the newer release's outcome by hand instead of trusting the version that happens to run it.
95
10-03-2026
Verification gap
The same rule recurred the next day inside a confined agent: a test written beside the helper that enforced it read a process id with a plain number conversion, the file was empty because the confinement rightly refused the launcher the test had built, and the kill went to the test runner's own process group, ending the hook, the version control commit and the agent's commit tool with no output three times; the rule now lives in the test suite's setup, which refuses a signal to the caller's group, to init, or to every process before any signal is sent.
94
10-02-2026
Verification gap
A test suite that was green on the developer’s machine killed the CI runner and then failed two dozen cases there, for three platform reasons at once: a process id read from a file that was never written became 0 and signalled the test runner’s own process group, a BSD-first command probe succeeded silently on Linux where the same flag means something else, and the runner’s preinstalled interpreter was world-writable, which the confinement layer correctly refused; signals now require a pid above 1, platform forms are chosen by the operating system, and the tests bring a trusted interpreter copy instead of weakening the confinement.
93
09-30-2026
Verification gap
A leak guard that refused by discarding the whole daily report took the self-reporting pulse down for 51 hours over one long number in a third party’s run title, and the alarm, the repair trigger and the watcher were all inside or beside the thing that failed; free text is now redacted at one boundary, the failed generator’s real error is printed, a watchdog outside the job reads the report’s age from the remote, and a failed run wakes the repair worker.
92
09-28-2026
Verification gap
A scheduled route's deployed function grew to 1.15 GB against a 250 MB limit and the deploy was refused, because it imported a script whose command-line entry reads the process's own path and Next's tracer answers that by packaging the whole repository; the logic now lives in a pure module the route imports, and a test walks every API route's import graph and refuses a filesystem call fed from the launch arguments or the module's own URL.
91
06-02-2026
Verification gap
A connector fetched a binary archive through a text reader, so the UTF-8 decode destroyed about 74,000 bytes and the parser blamed the file; it now fetches bytes behind the same guards, and a test holds the byte path.
90
09-23-2026
Verification gap
A test drove the push-time drift check with a planted generator and no sandbox root, so the plant sat in the real repository for the length of the run; a parallel test that had pinned the generators but not the root graded it and failed under load, and in a forced race one run's restore wrote the plant back after the other had removed it; both now grade repositories they own, and a structure test holds every test that reaches the check's writing modes to a pinned root or a case that says, with a reason, that it runs against the real tree.
89
09-23-2026
Verification gap
A job that installs the git hooks and then commits runs the whole test suite inside its own time ceiling, and the ceilings were set when the suite was smaller; a model refresh was killed inside its commit and the drift it found reached nobody, and three more jobs held the same ceiling on a committing path that had never run; each now has room, and a test holds every such job's ceiling to the suite it carries.
88
09-23-2026
External behavior
A workflow step's script that names even one input through the runner's embed syntax is read by the platform as a single expression capped at 21000 characters; the agent step's script grew past it and every seat run died before its agent started, while the suite stayed green because its tests substituted those embeds out and executed a script the runner never sees; the inputs now travel through the step's environment, and a test grades every workflow file against the cap.
87
09-23-2026
External behavior
bash reads a workflow step's script from disk as it runs, so every check placed after an AI agent in the same step was a line the agent could rewrite before bash reached it; three holds built that week were bypassable until the step became one brace group ending in exit, which bash parses whole before running any of it.
86
09-23-2026
Verification gap
A check that reads a pipeline under pipefail, with an early exiting reader such as grep -q behind a writer, takes the writer's broken pipe signal as its verdict: a landing check reported a landed commit as missing only under load, and a journal guard passed the dash it had just found; every site now reads to the end, and a list larger than any pipe buffer makes the race certain in the test, so it stops being a flake.
85
09-22-2026
External behavior
Three full-viewport fixed layers, one mounted invisible at opacity zero with eight overflow-scroll panels inside it and one an animating canvas, were bitmaps iOS re-rasterized under every pinch until WebKit's memory limit killed the page on every marketing page for six months; no desktop tool or simulator could see it, and the canvas was twice recorded as exonerated because every probe that survived with it had loaded with its JavaScript dead, so the subject under test had never mounted.
84
09-22-2026
Verification gap
A rebase resolver's rule that no generator it runs may need an install lived in a comment, verified once by hand; a require added two files below a generator broke it, the conflict path ran the generator for the first time in a seat with no node_modules, and a complete briefing was discarded over two derived JSON files while the stats row's own rebase had no resolver at all; the fix reads the one dependency two ways, walks every generator's graph in a test, and gives the stats row the same resolver.
83
09-22-2026
Verification gap
A guard that restored whatever changed during its run in the real repository reverted a developer's concurrent edits with nothing printed, and a module tested by one runner measured as untested by the runner that grades coverage; the fix restores only what was snapshotted, names the rest, and makes the local gate measure what CI measures.
82
09-21-2026
Operator process
A manuscript switch repointed the two constants that read the book log and none of the thirty-five surfaces that name it, so for sixteen days every seat run wrote to the closed book by every rule it could read and the published ledger counted the entries as that book's; the fix is one declaration and a guard that holds every copy to it.
81
09-21-2026
Verification gap
A hook exports the repository it is operating on into the test suite it runs, and only from a linked worktree, so every sandboxed git command in the suite targeted the real repository while a reproduction on a plain clone was clean; the class had been fixed three times, once per file, and the fix now lives at the one setup joint every test file passes through.
80
09-18-2026
Operator process
A prompt fix told the agent to iterate with a command that opens a socket, and the fence the agent runs inside refuses sockets, so the first walk of the fix could not execute the one command it consisted of; the agent rebuilt the tool by hand, polled a minutes-long suite five times, met two tests that write their scratch directory inside the repository, and hit its turn cap with a publishable draft in the tree.
79
09-18-2026
Verification gap
A main branch red at the base for a day billed every seat run inside the window as a guard refusal of its own work, kept their bookkeeping rows off main because the row's commit ran the same red suite, and let the briefing report three unrelated instruments dark when there was one cause; two of the instrument's own reads were also wrong, a by-design null rendered as unreadable and an unbounded run listing stamped fresh.
78
09-15-2026
Operator process
A root-anchored ignore pattern left every nested node_modules trackable, and 115 installed files rode in the repository for a month with every guard green because on main the versions agreed; the first dependency bump let npm dedupe them away and the drift guard reported 115 tracked deletions as generator drift, so the index is now read directly.
77
09-15-2026
Verification gap
A guard that audits the machine watched the repository's build cache and not the directory the test suite fills; 213,400 sandboxes made by mkdtemp and never removed held 40 GB while the guard named a 0.8 GB cache, so the temp directory's count joined the guard and every sandbox a test file makes is now removed when the file ends.
76
09-13-2026
Verification gap
A claim guard that reads source cannot see a contradiction between two published pages, a hand-typed number beside a generated one, or a gate applied to one surface and not its sibling; twelve contradictions stood with every guard green because each guard read one file, and only the page the visitor actually receives can show them.
75
09-13-2026
Verification gap
74
09-13-2026
Verification gap
A third-party client script is a contract that can change without a deploy: a bot-check widget was rendered with an option the provider later began rejecting, so every form silently posted no token and sign-in failed for everyone, while the end-to-end test asserted only that the token field existed, which a null value satisfies.
73
09-12-2026
Verification gap
A field performance metric measures whoever ran the script: a scraper fleet on residential proxies filed its own proxy latency under the site's page names, while two real layout shifts (a form absent from static HTML behind a Suspense fallback, a font stack that skipped its metric-matched fallback face) hid in the same week, invisible to the lab.
72
09-08-2026
Verification gap
A committed artifact derived from a publish-gated set changes bytes with no commit, so a commit-time heal cannot see the clock move before the push, and a hand-copied hook block is a list nothing can read: one registry, regenerated at commit and re-derived at push.
71
09-06-2026
Operator process
A design amendment that is not swept into the contract it amends leaves a path that cannot be walked; a sweep by reading finds the sentences that mention the premise, a sweep by execution finds the rules that depend on it.
70
09-06-2026
Operator process
A step's environment is not the whole job's environment, so converting some call sites to a resolved path and not others leaves a contract with one side missing; a syntax check reads grammar and cannot see a name.
69
09-04-2026
Verification gap
A step's shell flags are part of the code, and a value written to the runner's environment file is for the next step, never the one that wrote it; a script's own tests prove the script, so the shell around it has to be executed too.
68
09-04-2026
External behavior
A provider can retire a request parameter, so a model list is not a capability list; only a live call per model proves the request shape still works.
67
09-03-2026
External behavior
A dependency that is never declared but resolved on demand by the package runner is invisible on any machine that has already cached it, and a lockfile matching its name is not evidence it is installed.
66
08-30-2026
Verification gap
Calendar month arithmetic overflows into the following month, and a test that computes its expectation the same way agrees with the defect instead of catching it.
65
08-30-2026
External behavior
A shell capture of a non-string value from a runtime that colorizes its output returns ANSI escape bytes, and the environment that does it is the automation harness rather than a human terminal.
64
09-02-2026
Verification gap
A corpus gated on the wrong date field publishes a placeholder before the enriched version can exist, and an exemption list written the day a feature lands is the tell.
63
undated
Verification gap
A guard that reads the wall clock is vacuous at the wrong hour, so deleting the fix it protects can leave it green.
62
08-27-2026
Verification gap
A hand edit to a generated file is one run from silent reversion, and a suite that grades the file instead of a regeneration will never see it.
61
08-27-2026
Verification gap
A test that spawns an entrypoint aware of its build environment inherits the live reporting channel, so a suite can overwrite the run's own verdict and the last write wins.
60
08-26-2026
Verification gap
A proximity window measured in lines stops measuring anything once a generator writes the file, and a framing verb inside a citation is not a claim of affiliation.
59
08-26-2026
Verification gap
A field that may contain markup is safe only where it is rendered as markup, and the sink no human ever looks at is the one that keeps shipping the defect.
58
08-21-2026
Verification gap
A cost measurement is valid only for the resource it measured on the machine that binds it, and a local build stops one whole stage before the one that fails.
57
08-21-2026
Verification gap
A verification that normalizes its input passes on a value the real consumer will reject, so an instrument must read its subject exactly the way the consumer reads it.
56
08-21-2026
Verification gap
An allowlist entry is a claim about production that decays silently, and a guard checking whether a value is declared cannot go loud about the value that actually costs money.
55
08-21-2026
External behavior
A dependency's implicit fetch option is a route-classification decision, and it can silently repeal a page's own segment config, turning a declared 404 into a streamed 200 soft-404 that only the deployed build exhibits.
54
08-21-2026
Verification gap
A monitoring query that samples without filtering reports the absence of the needle as the absence of the problem, and sorting newest-first does not fix it; a reported count equal to the page size is never a measurement.
53
08-21-2026
Operator process
Internal documentation is not a wire contract: a set of event names transcribed from reviewed internal docs matched nothing the sender actually emits, and a single observed value disagreeing with a document invalidates the whole document rather than the one row it lands on.
52
08-20-2026
Operator process
An upstream service reports a downstream failure in its own vocabulary, so the error names a cause that is not the real one, and four consecutive fixes were aimed at the wrong side of the wire.
51
08-20-2026
External behavior
A privileged key does not bypass a control the upstream service enforces, and charging that service's refusal to a user's abuse budget locks out the innocent.
50
08-20-2026
External behavior
A shallow repository clone makes the version-control history answer confidently and wrongly, so a generator that trusts it publishes a false freshness claim with no error anywhere.
49
08-15-2026
Verification gap
A generated file that measures the repository containing it can never be correct at the moment it is committed, and a drift guard that performs no regeneration of its own reports PASS on a precondition it never established.
48
08-15-2026
Verification gap
Permissive access policies combine with OR, so one globally true policy defeats every narrow policy beside it, and two individually correct guards can still leave the class unowned.
47
08-13-2026
Verification gap
A gate that reads a tool's printed summary is reading a rendering, and colour in CI can leave it with no way to fail.
46
08-13-2026
Operator process
A guard's exit code is not its verdict; report-only and strict-gated checks exit zero while reporting.
45
08-13-2026
Operator process
A confinement lane is what an agent is instructed to write, not what gets committed.
44
08-13-2026
Verification gap
A sandbox that cannot start reports success, and a fence can apply halfway.
43
08-10-2026
Operator process
A stale document reads as instructions; when an invariant reverses, sweep the documents that assert it.
42
08-10-2026
Verification gap
Read a monitor's freshness the way the monitor is actually fed.
41
08-10-2026
Verification gap
A job cancelled with zero steps was never handed to a runner; an alarm inside the job cannot see the job never starting.
40
08-10-2026
Verification gap
A gate whose correctness rests on the thing it is gating is not a gate.
39
08-08-2026
Verification gap
Never validate a filter against data that filter produced.
38
08-08-2026
Operator process
A sync rule that tests equality can never be satisfied by the thing it exists to allow; record provenance instead.
37
08-05-2026
Operator process
A selection rule optimizes its proxy; verify what exists against measured demand, not against the code.
36
08-02-2026
Operator process
A lesson mechanized in the canonical pipeline does not exist for the surfaces that bypass it.
35
08-02-2026
Verification gap
An instrument's failure paths must render as not observed, never as clean.
34
08-01-2026
Verification gap
A fix committed but not pushed does not exist, and a guard grading the working tree will certify it as live.
33
08-01-2026
External behavior
Checks sharing one rate-limit window flake each other; absorb exactly one window or serialize.
32
08-01-2026
Operator process
A relabeled invariant must sweep every detector that encodes it, in the same commit.
31
08-01-2026
Verification gap
A step that discards stderr turns a missing permission into a silently wrong branch.
30
08-01-2026
Verification gap
A synchronous spawn against an in-process fake server deadlocks, and the hang reads as the child failing.
29
07-31-2026
Verification gap
A metric measured and then discarded is indistinguishable from a metric never measured.
28
07-31-2026
Verification gap
A timeout reports as cancelled, not failed; alarms keyed on failure alone are structurally blind to it.
27
07-31-2026
Verification gap
A cron reporting success is not healthy; watch duration against its ceiling and reap rows whose process never returned.
26
07-31-2026
Verification gap
A tool that runs quarterly has no gate between quarters, and its hand-copied config drifts silently.
25
07-31-2026
External behavior
A model's output budget caps reasoning plus text; leave neither half implicit.
24
07-31-2026
External behavior
Read a provider response by scanning for the block you want, never by indexing position zero.
23
07-30-2026
External behavior
Invalid CSS is discarded, not flagged; a broken value silently becomes the property's initial value.
22
07-28-2026
Verification gap
A build filter that decides inclusion is a detector, and must be proven on the shortest legitimate case.
21
07-26-2026
Verification gap
A convention that has never been executed is not a working convention.
20
07-25-2026
Verification gap
A CI gate that only runs on the day it matters has never actually been tested; force the condition once.
19
07-25-2026
External behavior
Email clients default to content-box, so full width plus padding overflows a phone.
18
07-23-2026
Verification gap
A table listing's row counts are planner estimates; report a real count or report nothing.
17
07-23-2026
Operator process
A pre-authentication code path needs its own abuse ceiling.
16
07-23-2026
Verification gap
A test that derives its expected value from the code under test can never fail.
15
07-11-2026
Operator process
A client-reachable module that statically imports a heavy data source ships it to every page that renders it.
14
07-10-2026
External behavior
Hiding overflow on one axis creates a scroll container on the other and can trap wheel events.
13
07-10-2026
Operator process
A redirect parameter is a contract between writer and reader; a silent fallback hides the mismatch.
12
06-09-2026
Operator process
An internal spec date is not a protocol version; clients hard-reject unknown values.
11
06-09-2026
Operator process
A programmatic page matrix needs a bounded kept-set imported by both the builder and the sitemap.
10
undated
External behavior
A client library that auto-deserializes on read breaks every consumer that stored a string, and only on cache hit.
9
undated
Verification gap
A date test that mocks the clock in a different timezone convention than the code parses fails only west of UTC.
8
undated
Operator process
After a rename, the old name is a liability: redirect it once, then never reference it again.
7
undated
Operator process
A module whose internal name diverges from its export breaks tooling that assumes they match.
6
undated
Operator process
Unsafe HTML injection requires an explicit, same-line trust annotation to pass review.
5
undated
External behavior
A managed provider's default email path cannot be assumed to deliver; route through one you can observe.
4
undated
Operator process
A cleared cache with a surviving session is a distinct state; UI must wait for hydration to complete.
3
undated
External behavior
High-frequency writes to a replicated column can destabilize the replication layer itself.
2
undated
External behavior
Realtime sync can echo a write back into itself unless transient UI state stays out of the database.
1
undated
External behavior
A mobile browser can suspend a tab without releasing its Web Locks, deadlocking auth refresh.
Download failure-corpus.json or failure-corpus.csv. Reuse the records under CC BY 4.0 with attribution. Ids and dates come from the committed corpus; titles and classifications are reviewed for publication. The build checks that the reviewed entries match the corpus.
Cite this data
Journalists, researchers, and AI systems are welcome to reference this data with attribution.
Orbyt Failure Corpus (Oct, 9 2026), https://www.orbytlabs.ai/orbyt-collective/how-it-works
What the human alone decides.
Every dollar. Any change to the gates a push to main must pass. Protected files, the money path, anything a customer sees. Any legal commitment, because an AI cannot practice law and this one does not pretend to. Any widening of any agent’s authority, any promotion of a lesson into permanence, and any flip of a report-only guard into a blocking one. An agent may push to main once those gates pass; it may not loosen them. The agents concentrate the founder’s attention. They never replace the call.
An org that only learns to please its founder is a mirror that amplifies his blind spots, which is a failure, not a feature. The org is built to become him, and to tell him when he is wrong.
That is the constitution’s own language, article 8.
The vocabulary.
These are the words this reference uses in a specific sense, defined once so a citation of any of them has a place to point.
- Agent seat
- A named role in the org with a written charter, a lane of files it may write, and a line it cannot cross without a human. Most seats are run by an AI agent; a mechanical seat, such as the Inspector General, runs a script with no model.
- Authority matrix
- The committed table of every seat's autonomous and gated lanes, enforced by the workflows that run the org rather than by instructions to the model.
- Autonomy Ledger
- Run, completion, failure and discard totals by seat, plus a frozen baseline.
- Decision log
- The append-only record of structural decisions, each with a permanent id. Corrections are new entries that name what they supersede.
- Decision Ledger
- A JSON record of structural decisions: ids, dates, supersession links and reviewed titles. CC BY 4.0.
- Failure Corpus
- Reviewed failure records and paths to recorded countermeasures in the private repository.
- Completion gate
- The check that decides, when an agent's run ends, whether its work may go on to the lane check and the guards. A run that exited with an error or ended in one lands nothing, a run that says it had nothing to do ends the cycle quietly, and any other run goes on if it printed its completion line or, without that line, if its exit, its result and its turns against its cap show it healthy.
- Discard
- A file an agent changed that its run may not keep, erased before the commit rather than shipped: anything outside its lane, and a lane file the run cannot keep yet, such as a proposed lesson before the ladder allows one. Counted separately from failures, because a run that landed with some of its edits refused is a different fact from a run that never landed. It is an aggregate counter, not a count of distinct files: the advisory panel isolates once for all observers and writes the same panel-wide count into every observer's row. No panel judges a discard.
- Kill switch
- One committed file that stops every autonomous seat before it spends anything, checked ahead of the credential.
- Dead-man switch
- The reverse brake: if fourteen days pass with no commit signed by the founder's key, promotions pause where they are.
The glossary defines these and the rest of the Collective’s own words.