A tool catalogue that grows by enthusiasm becomes a catalogue nobody can grant safely. Over September the catalogue was rebuilt around three disciplines: a shape every tool shares, a definition of done the build enforces, and a budget each endpoint cannot exceed.
Typed families
- Five verbs each The path-based dictionary tools are retired in favour of typed families for database code and server code, each with the same five verbs. A tool is named by what it acts on and what it does, so a grant reads as a sentence.
- One vocabulary per namespace Data, development, quality, test, documentation, objects and administration each keep their own naming rule, guarded by a test.
Definition of done
- Five rules, enforced The first sentence of a tool says what it does; the schema describes every argument and publishes every argument the code reads; the tables the tool reads and writes are declared and checked by a live sweep; the taxonomy page matches the code; and a test asserts one refusal kind.
- Ratcheted At the commit 187 tools lacked a refusal test and 13 read-only tools were refused by the sweep on their own arguments. Both counts are ceilings that can only go down.
- Refusals with a kind Ten kinds, from a missing argument to a failed proof. Every refusal site is classified and the sweep counts an unclassified one as a fault.
A budget per endpoint
- Measured where the tools are The fixed cost of listing an endpoint's tools is measured in tokens and held under a ceiling: 50,000 for development, 23,200 for administration. The largest answers are bounded: lists at 100 rows by default and 1,000 at most.
- Tables declared A ledger of the tables each tool touches, observed by the sweep, guarded on every run, and shown on the catalogue and the roles page.
The number of tools is a fact about the catalogue. The disciplines above are what make the number safe to grant.