The account, and being told

A paid homeowner has somewhere for things to land, so fewer things need pushing at all. One notification cannot be turned off — and it is not really a notification, it is the moment the record says they heard.

1 · What reaches you
Five things are pushed and everything else waits in Now. One of the five cannot be switched off, and the screen says why rather than graying it out and hoping.
Needs them, stated precisely enough to settle the table

An answer is owed, or a fact about their house has changed that they did not already know. Dave's reply passes on the second clause — they went looking for it. Something settled fails it, because they are the ones who settled it.

The locked one explains itself in place

Rather than being hidden or crossed out. It is the inert-capability treatment applied to a switch somebody may not throw: visible, quiet, and with the reason where the reader reaches for it.

Per seat, never per household

A second seat quieting their own notifications must not quiet the first's. It is the same rule as the claim screen: a seat changes what they hold, and never what somebody else does.

2 · The push that is a hearing
Not really a notification. This is the moment the trust ledger records — so its delivery is recorded rather than assumed, and where it cannot be confirmed the ledger says so plainly.
A push that silently fails makes the ledger lie

It would record that they heard on Tuesday evening something they never saw — asserting the exact thing the ledger exists to prove. So heard-at is written from the delivery rather than from the send.

And an unconfirmed hearing beats a fabricated one

Sent Tuesday, not confirmed is worse evidence than a delivery receipt and infinitely better than a timestamp that means nothing. It is visible to both sides, because the builder is the one who will be asked about it.

The tone carries the fact and not an alarm

Nothing has been ordered and nothing is decided. A variance arriving before an invoice is the product working, and the notification that announces it should not read like the thing it exists to prevent.

3 · The account
Profile, device appearance, subscription, log out, delete. Appearance stays available while remote account sections load or fail, because it belongs to this device rather than to the account response.
More than one house is the switch, and there is no switcher

A previous navigation died on a project switcher in the chrome. Houses live under the account because a second house is rare and a permanent control for a rare thing costs every screen a slot. The finished one stays open, which is the whole argument for the paid tier at renewal.

One row per house, never one account plan

Nora sees no ordinary billing row for a house whose payer is Sam. The sole exception is frame 14: after payer-removal cancellation leaves no billing seat, every active owner sees the recovery row. A trial row names its fixed end date and action; it is never collapsed into an account-wide renewal.

A local control survives a remote failure

The Appearance group is drawn above account-owned sections and remains interactive while houses and subscriptions load or fail. On desktop it stays a single vertical group in the Account content column; support copy never collapses into a segmented control.

When this device cannot remember it

Your choice is on for now. HouseChalk couldn't remember this setting.

The active theme does not roll back. The message belongs directly below the group, is announced by a polite status region without moving focus, and clears only after the latest selection is stored.

4 · Moving the subscription
Not a fourth place the asymmetry surfaces — it is where the three do something about it. Reached from the account row above and from the seat screen on mockup 14, and it is the only screen in the product that moves anything from one person to another.
It cannot complete on this screen, and that is the design

A transfer that finishes with one tap hands somebody a recurring charge they did not agree to. So the act is an ask rather than a move: rung 2 says so plainly, the state stays exactly as it was until she enters a card, and frame 15 gives the sender a recoverable pending fact rather than asking memory to hold it.

Three facts and one card, because almost nothing changes

The temptation is to make this screen feel weighty — it is billing, it is the one asymmetry, it reads as important. It is not: the binder, the money, the doors and the ability to remove a seat are identical before and after. Naming the two things that do move is more reassuring than a wall of consequences, and it is also true.

And nothing here mentions a plan or a tier

There is one subscription and it is per house. Putting a price, a term or an upgrade on the screen that moves it would turn a domestic arrangement between two people into a purchase decision, which is the wrong conversation at the wrong moment.

5 · Taking a copy out
Offered on the deletion screen and reachable from the account without one. A binder you cannot get out of is a binder you cannot trust, and the export is the proof that the record is the house's rather than ours.
Not a proprietary archive

PDFs and a spreadsheet, not a JSON dump and not a file only this product can read. The export exists to answer what happens to two years of my house if you go away, and an export that needs the exporter is not an answer to that question.

And it is not the exit

The last callout is there because of where the reader most often arrives from. Frame 7 offers this as the way out of deleting everything, and a screen reached from a deletion flow reads as part of it unless it says otherwise. Taking a copy is an ordinary thing to do in the middle of a build.

Nobody is told

Not Nora, not Dave. An export is a person reading their own record, which is activity rather than a record event — the same line frame 3 draws around read receipts. A notification saying Sam exported the binder would be the first surveillance in the product.

Rung 3 · blocking
6 · When it lapses, on the seat that did not pay
The account lapses, so every seat goes read-only — including seats that never paid and may not know payment exists. Each seat is told once, in its own right.
The binder is still here.
Everything about the house stays readable for as long as you want it: every decision, every color, every paper. Nothing gets deleted.
What stops is adding to it. Sam holds the subscription for this house and it ended on 30 June.
Talk to Sam about it Keep reading
Only the seat that can act on it is told how

Sam's version of this screen has start it again and a payment route. Nora's says who holds it and stops there — because offering her a button that cannot work is worse than not offering one.

And telling her nothing would be worse still

A house that quietly went read-only, with no explanation, is a person concluding the app is broken or that something has happened to the build. The rule is that every seat gets the notice once, properly, in its own right.

Then rung 1, forever

One line, where it is true, never again. That escalation-then-silence is how no nag survives a state that persists indefinitely — a polite banner on every screen for the rest of the account's life is a nag by duration even if it is gentle in tone.

7 · Delete everything, which means everything
The row on frame 3 with a screen behind it at last. Two years of a house is not a thing to lose behind a dialog asking whether you are sure.
It names what is lost rather than asking whether you are sure

Are you sure? is a question nobody has ever answered honestly, because at that moment the reader has no idea what they are being sure about. Three lines naming 47 decisions, the documents and the trust ledger do the work the confirmation was pretending to do. The typing step is for the other failure, the accidental tap, and it is the only part a second dialog could not replace.

A clock, and the clock is Nora

Rung 2, because it interrupts, and it is not an error tone. What is worth interrupting for is not the deletion, which the reader chose, but that a second person on this house loses it without being asked. The way out offered is an export rather than a warning, because taking a copy is the only genuinely useful thing this screen can do for her.

And the destructive action does not take the primary weight

It is a ghost rather than a filled button, and nothing on the screen is emerald. The design system has no red rung and does not acquire one here: the seriousness is carried by the list of what is lost and by the sentence about Nora, never by a color that would make every other screen look calm by comparison.

8 · How you sign in
Behind the third row of Everything else, and the answer to the question this page's closing note used to say was unsettled. A second factor at login is a real option and it is opt-in, per person, and off by default.
Off by default, and that is the ruling rather than a default

The product's posture is that nobody is stopped on the way into their own house — _ds/forms.css says it about the code entry itself, and 13-money says it about the session being the proof. A second factor that shipped on would contradict both, on the surface where the reader has the least to gain from it. What is gated by default is money, not entry.

Per person, because one seat may not set the other's login

Two people on one house differ in exactly one thing and it is the subscription. 24-people makes the same argument on the builder's side: change what somebody can do is a capability, and reaching into how a colleague signs in is a long way past it. An account-wide switch would be a third asymmetry, invented here, for a setting whose whole value is that the person choosing it is the person it protects.

The toggle carries a consequence, and the consequence is the boring part

On the ones you already use, nothing changes. The component rule is that a caption says what happens rather than restating the label, and here what happens is mostly nothing — which is the fact somebody deciding whether to turn this on actually wants. A caption reading Enable two-factor authentication would be the label repeated in worse words.

And this half is the provider's, which is why it is one screen

Login factors belong to Clerk. What the backend needs is not a factor implementation but the ability to read one: authcore.AppUser is {ID, Email, Name}, so today a handler cannot tell whether the caller used a second factor even when the provider demanded one. One field on the neutral contract, the matching read in the shim, and an account flag for the policy to hang off. The consequence gate on 36 · Proving it was you shares the concept and none of the code.

9 · Archive this house
The homeowner gets the same act and the same meaning as the builder: out of the default list, not out of the binder.
A duplicate has a truthful way out

A house created twice can now leave the ordinary chooser without pretending it was finished or deleting a binder. It remains reachable behind the fold.

The other seat is not asked

Archive changes list placement and write posture, not ownership. It is reversible by an owner and keeps every seat's read access intact.

10 · Behind Show archived
A finished house stays in the ordinary list. The archived one is behind a counted fold and can be restored without opening a second account.
Finished stays in daylight

The lake place proves the two timestamps are not aliases. A finished binder remains ordinary until a person separately archives it.

Folded is not absent

The count tells the reader the house still exists before they open the fold. The account chooser can therefore distinguish one active house plus one archived house from one house total.

11 · Still here, still current, read-only
The archived house opens as a binder, not as an error. Its watermark advances; only writing stops.
Not the lapsed state

The tone follows frame 6 because both preserve the binder and stop writes, but the cause and way out differ. Archive is project-scoped and an owner can restore it without payment.

The watermark keeps its promise

On this phone still advances. A frozen archived copy presented as current would turn a list choice into a sync lie.

Q251 · One purchase, an explicit refund amount

Each house is bought with one fee. Philip chooses the refund amount and records a reason; there is no monthly, elapsed-time or usage-based proration. The older subscription controls below do not define the admin refund workflow.

Review the original payment

Show the original purchaser, payment, currency, successful refunds and remaining refundable amount. Pending and uncertain reservations reduce that remaining amount. Refuse zero, negative, wrong-currency and over-balance amounts; concurrent requests cannot reserve the same money twice. A change of billing responsibility does not change the original payment or its refund destination.

Partial, full and still uncertain

A successful partial refund leaves access unchanged. Add successful partials for the same original payment: when they reach its full paid amount, the house becomes read-only and its records remain. Pending, failed and unknown refunds are not successful totals. A lost response stays uncertain until provider reconciliation establishes the result.

Only the purchase funding this house

A refund of an older purchase does not restrict a newer valid purchase. Never add refunds across different payments or infer a house from the current payer. An explicit, recorded goodwill choice can retain access after a full refund; it does not override suspension, deletion or missing membership. A new purchase does not inherit an earlier purchase’s refund restriction.

Scope and evidence

These rules follow Q251 and its one-fee correction. Billing-seat transfer is not account ownership transfer; the latter still needs its own workflow and verification. Source tests and local provider fixtures do not establish a live refund rehearsal.

12 · End this house's subscription
Ordinary cancellation is per house, immediate and explicit about the money HouseChalk will not create.
Provider request, stated as product copy

Cancellation is immediate with invoice_now=false and prorate=false. HouseChalk issues no Refund and requests no final Invoice.

13 · Subscription ended
A confirmed result returns to the account row; it does not pretend the house disappeared.
Confirmed before claimed

An ambiguous provider result remains pending and reconciles in the worker. This result appears only when local and provider state agree. Any-owner restore is reserved for frame 14's payer-removal recovery, where no billing seat remains.

14 · Restore a payerless house
The sole billing-management exception for a nonpayer: after payer-removal cancellation, every active owner may claim the empty billing seat.
Payerless, not ownerless

Every active owner can see this recovery row. On every other canceled project, billing controls remain private to the retained billing owner.

15 · The transfer is waiting
The sender can recover the request from an authenticated route after closing the browser; there is no bearer token or provider identifier in the response.
Recovery without disclosure

The sender read exposes request state, expiry and recipient seat only. SetupIntent, Session and Customer identifiers never cross this screen.

16 · Resume the recipient handoff
An interrupted recipient resumes the same transfer and durable Checkout attempt instead of creating a second claim.
A transfer is a state machine

Pending, provider-ready and finalizing states all have a recovery path. Only verified setup and finalization move the billing seat.

Rung 1 · quiet
17 · Signing in and asking for it back
Frame 7 closes on a promise — until then it comes back the moment you sign in and ask — and no frame drew the asking. The window is a fact about the account rather than about the phone that opened it, so it is here on whichever phone signs in, including one that was nowhere near the deletion.
The window belongs to the account, so every device has to be able to read it

Frame 7 is drawn on the phone that scheduled the deletion, and that phone knows because it holds the answer the write returned. A second phone holds nothing. This frame is the reason /me has to carry the two dates: without a read, a person who signs in somewhere else meets frame 7 again, blank, and the only way back is to ask to delete a second time and be handed the same window as a side effect. That works and it is a terrible sentence to have to write down.

Here the safe act takes the primary weight, and on frame 7 nothing did

Frame 7 refuses a filled button on purpose: the destructive act must not look like the recommended one. Ten frames later the recommended act is the reversal, so it is emerald and it is first. The two screens are the same subject drawn at opposite ends, and the button treatment is the whole difference.

It says nothing about the thirty days being nearly up

No countdown, no color change at day 25, no second push. A person who scheduled this chose it, and a product that spends a month nudging them about it is arguing with a decision it already took. The date is a fact on the screen they came to; that is the whole telling.

Rung 1 · quiet
18 · The line, on every open after
Frame 6 blocks once and its third annotation rules what follows: one line, where it is true, never again. 00-states frame 14 draws that for the builder and nothing drew it for her. It is the same grammar on the screen she actually lands on.
Drawn on Now, and the deck has not ruled that it belongs on Now alone

Corrected 2026-09-04, and the correction is the interesting part. This read "one line on the screen the app opens on, and it is nowhere else — Jobs is his landing exactly as Now is hers." Both halves were wrong. Jobs is not his landing: his level-one doors are Today, Jobs and Send, and Today is the first. And the line is not on one screen anywhere in the deck — there are three .lapsed instances and the other two sit on Jobs (00-states frame 14) and Send (25 frame 5, When his account lapses), which are two different doors.

So the alternative this frame dismissed is the one the deck already draws

The sentence that went with the claim called a line on every read-only screen a nag by duration. Two doors carrying it is that alternative, in miniature and on purpose. It suggests "never again" in frame 6's third annotation is about the escalation — rung 3 once, rung 1 after — rather than about how many screens carry the rung-1 line, which is the reading states.css's own comment supports. On that reading her placement is not Now alone but every door where a write is stopped. Q161 asks, and this frame is the proposal for one of its three answers rather than the answer.

The button is where it always was, and it says why when she reaches for it

Settle it now does not disappear and is not replaced by an explanation. It goes inert, which is the component a lapsed account already shares with every other permission rule in the product. Removing it would make the screen look like a house with nothing to settle, which is the one thing that is not true. Q170 ruled on 2026-09-04 that this is right about the control and wrong about the screen, and corrected the frame by one screen rather than declining it. The component named here is real — HcCommit with a null onCommit and an unavailableReason, which the shell renders in place of the consequence, at fourteen call sites. It is not what Now draws: week_hero.dart builds Settle it now as an HcCta that navigates to /now/decision/:id, and the commit carrying this label is on that screen. So the line goes there, under the control that actually goes inert — which is what “it says why when she reaches for it” asks for, since reaching for it is arriving. Now keeps a live button, because the hero decision is excluded from every other lane and this is its only door.

Nora's line and Sam's line say the same thing and offer different ways out

Frame 6 splits the block by who can act. The rung-1 line does not split: it is a statement of fact, and a fact does not need a different sentence for the person who can fix it. What differs is what she finds when she reaches an inert control, and that is the account screen, which already knows who the payer is.

19 · Asking to be able to tell you
Frame 1 draws five switches already on and nothing in the deck drew the moment they become possible. Q178 ruled 2026-09-05 that the pre-prompt is AF1’s and settled its shape from 02 frame F; the moment is this frame’s, because the microphone has one and a notification does not.
The Hollis House · Kitchen
Your question is with Dave
He usually answers the same dayI can tell you the moment he does, instead of you coming back to look.
Five things, and you choose themAn answer, a date that moved, money over an allowance, something waiting on you, and a change order to sign. Nothing else.
Tell me when he answers I will come back and look

Coming back and looking works. His answer sits on Now either way, and nothing waits on this.

The moment, which is the half the ruling could not supply

02 frame F sits one tap from Talk it through, “at the point where the answer is obviously yes because they have just said they want to talk.” Push has no equivalent, because nobody invokes a notification. So the moment is the nearest true thing: the first act that creates an expectation of being told — here, sending a question to the builder. Settling a decision that leaves somebody else’s move outstanding is the same shape and the same frame. Not first launch, and not the settings screen, where flipping a switch already assumes the permission this asks for.

Our sentence comes before the system’s, for the same reason as the microphone

The platform dialog cannot say which five things, and the five are the whole argument — frame 1’s switches are what this permission is in aid of. Tell me when he answers is what fires the real one, so declining here costs nothing: no system prompt fired, so nothing was permanently refused. That is what makes a second ask possible, and it is why the pre-prompt exists rather than firing the platform dialog bare.

The way out is a door, and it names what still works

I will come back and look carries the same weight as accepting, and the callout says where the answer lands anyway. Frame 1’s copy is the reason this matters more here than on 02: the locked switch says “the moment it reaches you is the moment the record says you were told”, so a person who declines must be able to see that nothing about the record turns on their answer. It does not: the hearing is stamped by delivery, and a house that is never pushed to is never recorded as told.

What this frame does not settle

Which of the five kinds may trigger the moment, and whether a denial is re-askable through a Settings deep link. Both are frame 1’s, beside the switches, and Q178 leaves them there on purpose. A denied state is still undrawn.

Where notifications sit against the privacy line

A notification about another seat is not automatically a breach, and the boundary needs saying or somebody will build a read receipt behind it.

A record event is shared and may be sent. Nora signed change order 004 — it changed the house and the money, and scope is shared.
Activity is private and may not. Nora opened this · Nora has not looked at this · Nora skipped it.

The test is whether the event would still be in the binder a year later. A signature would. An opening would not.

Two-factor, and the sentence this note used to carry

It said the mechanism already existed and only the authority question was open. Both halves of that were wrong, and the second one is now drawn.

The mechanism does not exist. signature_assurance.go declares two auth_method values and reserves a third by name without declaring it, saying why in as many words: nothing writes it, and a value with no writer is the same defect as a column with no writer. There is no code table in any of the 86 migrations. The deck has asserted this mechanism on two pages for months and the backend has never had it. It is drawn properly on 36 · Proving it was you.

The authority question is answered above. Opt-in, per person, off by default, and not something one seat sets for the other. It was never a hard question; it was a question nobody had drawn a screen for, which is a different thing and the reason it sat open.

20 · Contact HouseChalk
A3: available from Account, every onboarding step, and no-house recovery. Authentication is enough; no person or house is required. The email is a reply destination, never identity proof.
Contact HouseChalk

Tell us what happened. You can ask for help before setting up a house.

sam@example.com

Add an address if you want a reply. This does not verify your identity.

What do you need help with?
I cannot finish setting up my house.
21 · Receipt not confirmed
The sent text becomes read-only. Sending disables duplicate taps. An uncertain response retains exactly the original body and request key for retry; no received claim appears here.
Contact HouseChalk

I cannot finish setting up my house.

We could not confirm receipt. Retry sends the same message, so it will not create a second request.

22 · Support message received
Only the confirmed creation receipt reaches this state. It does not promise a reply deadline. Back returns to the interrupted place; a cold-open returns through onboarding's existing routing gate.
Message received

Your message is with HouseChalk. If you added a reply email, we can respond there.

23 · Review a support request
A5 customer verification. Available before onboarding. Request ID and code are typed here, never URL parameters. The code stays only in memory and is cleared when identity changes or the screen closes.
Review a support request

Enter the request ID and verification code supplied by HouseChalk support. Do not enter your password or sign-in code.

Request ID
••••••••
24 · Authorize support
The live review supplies the account and expiry. Failed, expired, consumed, or wrong-identity reviews cannot authorize. An uncertain confirmation requires another review and never claims success.
Review a support request

Cancel pending account deletion

Account: a1

Expires September 9, 2026 at 2:00 PM

Confirming authorizes HouseChalk support to cancel this account’s pending deletion. This confirmation does not cancel deletion itself.

25 · Authorization recorded
Only a verified response establishes authorization. This is not the deletion cancellation receipt.
Review a support request

Authorization recorded. Support can now cancel the pending deletion. Deletion has not been canceled by this confirmation.

26 · Review access removal
A5 exact customer proof for an ownership or payer removal. Names and IDs come from the live reviewed snapshot. No person, project, role, or billing target is editable here.
Review a support request

Remove project access

Project: Hollis House (p1)

Person: Sam (person1)

Seat: seat1 · Current role: Owner

Applying this removal ends all project access for this person.

Applying this removal requests cancellation of the project subscription.

Applying this change cancels 2 pending transfers and withdraws one proposed tag swap.

Expires September 9, 2026 at 2:00 PM

Confirming authorizes HouseChalk support to apply this exact access change. This confirmation does not change project access or billing.

27 · Review access restoration
The proposed role and explicit additional grants are reviewed independently of the prior role. A stale snapshot or unknown grant is refused. Empty grants means only the role's standard access.
Review a support request

Restore project access

Project: Hollis House (p1)

Person: Sam (person1)

Seat: seat1 · Current role: Viewer

Proposed role: Builder

Additional permissions

Change what somebody can do

Expires September 9, 2026 at 2:00 PM

Confirming authorizes HouseChalk support to apply this exact access change. This confirmation does not change project access or billing.

28 · Account access is paused
A6 restricted recovery. Authenticated identity is retained. Unsent work is quarantined on this device; it is neither sent nor silently deleted. Only a fresh explicit recovery response can reopen access. An account-only restriction also offers another available house.
Account access is paused

Your house data is unavailable while this restriction is in place. You can still contact support or review a support verification request.

Unsent work stays on this device while access is paused.

Pending account deletion

Only your current eligible accounts are offered. A closed cancellation window is shown explicitly.

29 · Recovery unavailable
A6 restricted recovery. Authenticated identity is retained. Unsent work is quarantined on this device; it is neither sent nor silently deleted. Only a fresh explicit recovery response can reopen access. An account-only restriction also offers another available house.
Recovery unavailable

We could not check recovery options. Try again when you are connected.

Unsent work stays on this device while access is paused.

Pending account deletion

Only your current eligible accounts are offered. A closed cancellation window is shown explicitly.

30 · Staff diagnosis entry
A7 separate diagnostic origin and main_support.dart only. Staff signs in here with MFA; no credential or token arrives in the URL. A nonsecret context ID is entered after sign-in. This is not reachable through the ordinary customer router.
Staff diagnostic view

Sign in at this isolated origin, then enter the context ID from the admin app.

Email
••••••••

A second-factor code is required when prompted. No customer password is used.

31 · Stored customer timeline
A7 admitted reads: stored settings and the customer timeline. Persistent read-only banner and exit stay outside the scrolling body. Target IDs come only from the server-bound context. No local database, offline queue, device registration, uploads, downloads or ordinary app bootstrap is mounted.
Exit diagnostic view

Read-only diagnostic view

Stored project settings

Person person_demo · Project project_demo

Hollis House

Default lead time: 10 days

Context expires at the server-provided deadline.

Customer timeline

The same stored phase, inspection, draw and visit facts shown to the selected customer. Attendance belongs only to that person. Links and attendance controls are unavailable.

What is available

Stored settings and the customer timeline are available. Timeline actions, calls, other house screens, documents and sync remain unavailable. This view cannot change customer data.

32 · Diagnostic view cleared
A7 late 403, identity change, hard/idle expiry and explicit exit remove customer data and cancel pending responses. A failed exit receipt is never reported as server revocation; the local view is still cleared.
Diagnostic view cleared

Customer data has been removed from this view. If server revocation could not be confirmed, revoke the context in the admin app or let its short expiry end it.

A fresh validated context is required to inspect a project again.