0005 — The Institutional Standards: the third doctrinal layer
A recorded institutional decision, with reasoning and result.
- Authority rank
- 5
- Version
- v1.0
- Adopted
- unrecorded
- Held by
- Stewardship Office
- System
- SYS-10
Source · docs/codices/DECISIONS/0005-institutional-standards.md · registered by rule
Date: 2026-07-31 Status: accepted Extends: 0001 (Codices as supreme authority), 0003 (the Registry), 0004 (Codex 0 as a specification book).
Context
After 0004, Anabasis had two doctrinal layers. Codex 1 says what must endure. Codex 0 and Codices 2–10 say how the institution works, in citable clauses, with a Registry that gates what may be built.
Nothing said how things must be built, or how a reviewer proves a thing was built to standard rather than merely argued for well. The repository had no definition of "done", no conformance instrument outside the Codex 6 UX rubric, and no consistent way to name a deviation. Doctrine that cannot be checked drifts, and an institution intended to last generations cannot rely on the memory of whoever happens to be present.
Large, long-lived organisations avoid fragmentation with three layers: a constitution, an explanation of how the organisation works, and a building code. The third layer was missing.
Decision
1. A Standards layer is established at docs/standards/, indexed by 00-index.md, sitting below the Codices and above decision records and implementation. Eight standards:
| ID | Standard |
|---|---|
| STD-A | Architecture |
| STD-D | Data |
| STD-S | Security |
| STD-I | AI |
| STD-X | Design |
| STD-R | Research |
| STD-F | Financial |
| STD-Q | Quality — the institutional definition of done |
2. The defining rule of the layer: every standard clause is checkable by a reviewer who did not do the work. A clause whose satisfaction cannot be verified by a second person is not a standard; it is principle, and belongs in the governing Codex. This is what distinguishes a Standard from a Codex: a Codex says what is true and why, a Standard says what you must do and how it is verified.
3. Fixed normative vocabulary — must, must not, should, may — defined once in the index and binding across all eight.
4. Waivers are written or they do not exist. A must clause is waived only with what was traded, what repays it, an owner, and an expiry. A must not clause is never waived. A pattern of waivers against one clause is evidence the clause is wrong, and it is amended rather than quietly ignored.
5. STD-Q is the single gate. Nothing reaches a member, client, partner, the public, or production data without passing it. It references the other seven rather than restating them, and it ends in a conformance certificate a reviewer completes.
6. The Codex 6 rubric is not duplicated. STD-X points at docs/codices/CODEX-6/RUBRIC.md and its templates as its scoring instrument.
Reconciliation performed alongside
- 1Chapter 04 gains §04.4.20 Board member and §04.4.21 Guest with their visibility contracts, and two open questions: board decision rights (Chapter 03 currently assigns all decision rights to the two Offices) and guest expiry defaults.
- 2The Registry reserves
AGT-06throughAGT-14— Business, Financial, Writing, Career, Founder, Executive, Knowledge, Curriculum Builder, Risk — as IDs only, each requiring a full Chapter 13 specification before implementation. A separate administrative agent was deliberately not reserved, to keep the number of systems with operational data access small. - 3Chapter 07 gains §07.2.0, the four top-level categories — People, Organizations, Knowledge, Capital — as the data model's organizing frame, with Event and AuditRecord named as cross-category records about the four rather than members of one.
Consequences
Every future change now carries a conformance step. That is a real, permanent cost, paid on every piece of work, and it is the intended trade: it is cheaper than rebuilding what was never specified, and it is what allows a contributor in twenty years to produce work indistinguishable in quality from today's.
The risk accepted is bureaucracy — standards obeyed in form and not in substance. The mitigation is §2.2 of the index: unverifiable clauses are removed. A checklist of unverifiable lines is theatre, and the layer is designed to reject it.
Rejected alternative: folding these rules into Codices 2–10. This is where they nominally lived, and it is why they were unenforceable — they were written as principle, mixed with explanation, with no conformance instrument and no waiver procedure.
Institutional Critic (Codex 10)
- 1Failure at 100x. Eight standards maintained by many hands drift apart and contradict each other. Mitigation: STD-Q is the only gate and references the rest, so contradiction surfaces at the point of use rather than in a document nobody reads; clause numbering is permanent; every amendment is a decision record.
- 2Unverified assumptions. That reviewers will be independent of authors. Unverified while the institution is small and the same person often does both. Named in STD-Q as the review independence rule, with a recorded exception rather than a pretence.
- 3Simpler solution. One combined standards document. Rejected: subject standards are consulted by different people at different moments, and a single file would be read by nobody. The index gives the single entry point instead.
- 4Duplication. Real risk against Codices 5, 6, 7, 8. Handled by the cite-don't-restate rule and by pointing STD-X at the existing rubric rather than reproducing it.
- 5Enterprise view. Strongly favourable. A documented, waivable, auditable building code is what security review, procurement, and partner diligence ask for, and it exists before it is demanded.
- 6First-time contributor. Adds reading before the first commit. Mitigated: read the index, then one subject standard, then STD-Q. Three documents, not eleven.
- 7Legal, operational, security. These are internal engineering documents. The index §8 forbids quoting them as compliance, certification, or audit claims. STD-S materially improves the security posture by making the enforcement obligations checkable.
- 8Debt. The eight standards were authored in parallel and need a cross-reference consistency pass; each carries its own open questions rather than concealing them. Repaid by the consistency pass recorded in this decision's implementation.
- 9Consistency. Nothing here alters Codex 1. §1.2 of the index makes Codex subordination explicit and forbids resolving a Codex-Standard conflict in code.
Codex 8 evaluation
Revenue potential: indirect — enterprise and partner diligence, and the avoided cost of rework. Implementation cost: authoring time; no runtime cost. Maintenance cost: real and permanent, and paid on every change. Operational complexity: adds one required step to every piece of work. Customer value: indirect, through consistency of what they receive. Enterprise value: high. Long-term strategic value: high — this is the layer that keeps the institution recognisably itself as the number of hands grows.