The Record Tabs

Six sections of the binder are not rooms — Money, Papers & permits, People, Care, Plans & drawings, The build so far — and they sit in one quiet list under The house and look alike there. They are not alike. Mockup 41 draws The build so far; these are the other five. People and Plans & drawings are built and routed, Money is built but knows nothing about rooms, and Care is project-wide with a room-shaped hole in it. This page draws all five and says which is which under each phone. Papers & permits was the last door on the dock with no screen behind it at all, and this page used to say mockup 13 drew it, which was never true: 13 is Money.

1 · Money
Not a total. The one allowance that is about to be overrun, then what each room has left, then the quotes that produced those numbers. Amounts and what is left, never a bar and never a fraction.
Already in the code

The allowance, the quote and the line items. decision_allowances is a real table, unique on (project_id, decision_id), and quote_line_items and quote_line_item_decisions ship with it. Category budgets are a JSON string in projects.category_budgets, added by migration 0005.

Nothing stores this yet

The middle card. Nothing about money is scoped to a room today. An allowance hangs off a decision, a quote line has a category and no zone, and the budget categories are a JSON blob rather than a table. Every figure in "What each room has left" is derived, not read.

The derivation itself needs no migration: decision_zones already joins a decision to its spaces. What it needs is a product answer. A line item tagged to decisions in three different rooms has to land somewhere, and the weight column at 0014:74 is nullable and its own comment calls it unused. The rollup at strategies.go:297 divides evenly, which is a placeholder rather than an answer.

2 · People
Who is working on this house, and who to call about what. The synced contact directory supplies the trades below; the household stays one clear drill away instead of being mixed into that directory.
The household exists before there are two

The first card is always present for an owner and opens /house/people/seats. With one owner it is where an invitation starts; with more it expands into the responsibility overview. Household members are not mixed with builders and trades because seats and contacts carry different meanings.

The data boundary

contacts, contact_projects, contact_zones and contact_systems sync for the delivered directory. Active seats and member_tags sync for the delivered household drill. The builder is identified by the builder seat, never guessed from contacts; the person's optional phone is projected through that seat, and the call action is absent when no number was supplied.

Responsibility is entered, never inferred

Project-scoped Room and System assignments supply the scope shown under each name and the routing list. Within an axis, any selected value matches; when both axes are present, both must match. A contact with no assigned scope still appears in the directory but not in routing.

3 · Plans & drawings
The plan set, by sheet number and discipline, the way an architect hands it over. This is the tab closest to shipping, so it is drawn close to what ships: every field on a row is a real column. The last line is the one thing it cannot do.
Built in the rebuild

0041_drawing_reader_p5.sql gives drawing_sets a selected immutable extraction run and gives sheets their number, title, discipline, revision and stated scale. DrawingsScreen reads the API-backed set and sheet projections at /house/plans; no sheet row or storage credential is synced to the phone.

Reading and owner apply are built

P6 can answer a question such as "where is the kitchen?" from retained spaces and cite the exact sheet region. P7 now writes sheet_zones through the explicit owner-only preview/apply decision; P8 still owns replacement when a later revision is selected.

The screen groups by the explicit discipline returned by the selected P5 run. It does not infer discipline from the sheet number, and a read failure never becomes a calm empty filing cabinet.

4 · Care
After move-in. What is coming up, read by room, and what has already been done. The titles come from the canonical maintenance source. Y4 adds the catalog, schedule and immutable completion history that make this frame real.
Canonical content, new schedule

Range hood filter degrease and Fall gutter cleaning are authored rows in data/library/content/maintenance.json. The rebuild has a minimal maintenance_tasks placeholder today. Y4 adds the imported catalog, project schedule, completion ledger and reversal ledger; the client never invents the next date.

Explicit room placement

Catalog definitions receive authored room-archetype relationships, and materialization creates one task per matching classified project zone. A manually added zone with only a label receives no inferred archetype and no room-scoped Care work until it is explicitly classified.

Applicability is a fact, not a guess

House-level work uses The house itself. Definitions that depend on a water softener, radon system, garage door or another unrecorded property feature remain inactive until the later property inventory exists. Empty applicability is never used to show equipment work confidently to every house.

5 · Papers & permits
The binder's second row, and until now the only door on the dock with nothing behind it. A paper is not a file: it has a number, an authority, and a date that either has passed or has not. The tab is those dates, sorted by whether anything is waiting on them.
Already in the code

The file, and only the file. project_documents carries file_id, file_name, mime_type, uploaded_by, uploaded_at, document_type, an extraction status and supersedes_document_id (0001_init.sql:1373-1394). Upload, storage, supersession and the extraction pipeline all work.

Nothing stores this yet

Every field on every row above. A permit number, an issuing authority, an issue date, an expiry, an inspection state and whose move it is are six values and the table has none of them — uploaded_at is when somebody put the PDF in, which is a different date and never the one a permit turns on. And a paper cannot be uploaded in the first place: knownDocumentTypes is a closed set of seven and all seven are plan drawings (documents.go:92-101), so a permit, a contract and a certificate are all refused at the handler.

And the sort is the design, not the data

Waiting first, live second, signed third. The obvious tab is a file list newest-first, which is a folder with a search box — the reason to open this door is almost always is the thing that is holding us up still holding us up, and that question has one answer at the top or it has none. The lead card is the only one that ever changes.

6 · Opening one
Four tabs put documents in front of somebody and none of them drew what happens next. A drawing is a thing you look at on a phone at a job site, which is the hardest place to look at a drawing.
A-1 Floor plan Rev 3 · Dave Marsh, 12 May · 1/4 in. = 1 ft
3 of 9
Save to my phone
The chrome is a strip, not a screen

A drawing at a quarter inch to the foot needs every pixel it can get, so the sheet takes the whole width and everything else is one line under it. What that line carries is the thing a person standing in a half-built house actually needs: which revision this is and who sent it, because the argument on site is almost always that somebody is holding an older sheet.

Three of nine, and it never asks which one

You opened A-1 from a list of nine, so swiping moves through those nine. A viewer that returned you to the list between every sheet would be making you re-answer a question you already answered, and comparing the floor plan against the elevation is most of why anybody opens these at all.

Share it was drawn here and is refused

This strip carried a second ghost CTA until Q150 ruled on it. A sheet leaving as a file hands somebody's plan set to the operating system, where seat removal, archive and account deletion cannot reach it; a sheet leaving as a link is a sixth links.type and a subject column the table has no analog for, on behalf of an affordance the frame's own argument never makes. That argument is about the builder's signal, not about handing a sheet to a third party, so the control is removed rather than left standing as a promise.

Save to my phone is not a failure of the product

It is there because a job site has no signal and a builder asking to see something does not care whose app it is in. The offline rule on 00 says what still works rather than what broke; this is the same idea one step earlier, letting somebody take the thing with them before the signal goes.

Built, and it carries its own way out

AE1 shipped it into a drift table, app-private, so seat removal and account deletion reach it and an archive deliberately does not. Once a sheet is kept the strip says so and offers the release instead — a hold somebody chose needs a way out that is not deleting the app, and 26 frame 4’s “no way to clear this” is about the cache the phone manages rather than about this. It also reads the kept copy when there is no signal, and says out loud that it is not a fresh read: the argument on site is almost always about which revision somebody is holding, and a stored sheet drawn silently would be this app joining that argument on the wrong side. Q238 is the ruling.

7 · The entry point
The thread opens from Plans & drawings and names its source before the first turn. It is not behind the global Ask door.
The Hollis House · Plans & drawings · Rev 3
Ask the plans
Nine sheets in the current set.
HouseChalk What do you want to find in Rev 3?

I will answer from the retained drawing knowledge and show the sheet behind every answer.

Which sheet shows the first floor? Where is the primary bath?

Questions do not change your plans or house record.

Ask about this plan set
Conversation, but source first

The opened revision is the first object on the screen. A candidate set can be asked only after the user deliberately opens it, and every later turn inherits this visible boundary.

A room, not a floating assistant

This conversation lives inside Plans & drawings. It does not follow the user around the app or compete with the three-door dock.

8 · Reading the set
The first question becomes a turn. Durable work appears as the reply being assembled, without a spinner, percentage or denominator.
The Hollis House · Plans & drawings · Rev 3
Ask the plans
Nine sheets in the current set.

Which sheet shows the first floor?

Reading the relevant sheetsYou can leave. This turn will stay in the thread.
Found this plan set
Matched the question to drawing facts
Writing the answer
Checking the cited sheet
Ask another question
The pending work is a reply

The question stays in the transcript while HouseChalk works. The four lines are stages the system owns, with no fake percentage, denominator or spinner.

9 · A cited answer
The answer is short. Its source is not a footnote: it is the next thing on the screen and opens the exact evidence.
The Hollis House · Plans & drawings · Rev 3
Ask the plans
Nine sheets in the current set.

Which sheet shows the first floor?

Answered from Rev 3

A-1 is the first-floor plan. It is the architectural sheet drawn at 1/4 inch to 1 foot.

This identifies the sheet. It does not verify dimensions or anything inferred from scale.

Source for that answer
1 · A-1 Floor planFirst floor plan · 1/4 in. = 1 ft ›
Ask a follow-up about Rev 3
The citation stays with the reply

The source follows the claim in reading order and opens the evidence region. A follow-up keeps the same revision unless the user deliberately starts from another set.

Limitations are product copy

The model is allowed to say less than the question hoped for. The boundary on scale-derived measurements is visible before somebody carries the answer onto the job site.

10 · Opening the citation
The existing full-width sheet viewer gains one temporary evidence region and one citation strip. The drawing still gets nearly all the pixels.
1
A-1 Floor plan Rev 3 · You, 2 March 2026 · 1/4 in. = 1 ft
Supports answer 1

“A-1 · First floor plan · 1/4 in. = 1 ft”

Back to the conversation
A temporary layer, not markup

The region exists because the answer cited it. It does not turn the viewer into an annotation tool, and leaving the question clears the layer.

Same viewer, one new reason to arrive

Frame 6 on the record-tabs page already settled the sheet-first composition. P6 adds evidence to that screen rather than creating a second drawing viewer.

11 · Nothing in this set says
Not found is a supported answer only when every relevant sheet finished indexing. It names the revision and refuses to turn silence into a fact.
The Hollis House · Plans & drawings · Rev 3
Ask the plans
Nine sheets, fully indexed.

What finish is specified for the primary bath floor?

No match in Rev 3 I could not find a specified finish.

The indexed sheets do not name a floor finish for the primary bath.

All relevant sheets were checked

This does not mean a finish has not been chosen somewhere else.

Ask a follow-up about Rev 3
Absence becomes a normal reply

The answer names what this revision does not contain, then keeps the conversation open. It does not say the house has no floor finish or recommend one.

12 · The set is incomplete
A failed or unfinished sheet prevents a whole-set negative. The product names the gap and offers the sheet-level recovery P5 already owns.
The Hollis House · Plans & drawings · Rev 3
Ask the plans
One sheet needs attention.

What finish is specified for the primary bath floor?

Answer blocked I cannot rule it out yet.

A-2 did not finish reading, and it may contain the primary bath note. I will not call the answer missing while that sheet is unknown.

The sheet in the way
A-2 Second floor planReading stopped before evidence was retained.

Retry the sheet before answering this question.

Ask something else about Rev 3
Incomplete is not not found

This is the product rule P6 exists to enforce. A calm empty state here would turn one failed read into a claim about the house.

13 · Reading the missing sheet again
Sheet recovery is its own durable job. The blocked reply stays put while P5 creates a new reading run, and no second question is submitted yet.
The Hollis House · Plans & drawings · Rev 3
Ask the plans
Reading A-2 again.

What finish is specified for the primary bath floor?

Answer blocked I cannot rule it out yet.

A-2 did not finish reading, and it may contain the primary bath note.

The sheet in the way
Reading A-2 againA new reading pass is rebuilding this sheet's retained facts.

You can leave. This recovery will stay with the question.

Ask something else about Rev 3
Recovery does not rewrite the turn

The old question remains anchored to the incomplete run. This panel follows the new P5 run instead of pretending the blocked answer can become complete by refreshing.

No paid answer call yet

Retry A-2 only retries the sheet. HouseChalk waits for an explicit re-ask before it spends another question call.

14 · The sheet is ready to ask again
The recovered run is ready. The old blocked reply remains true about its source, and the next paid question stays behind an explicit action.
The Hollis House · Plans & drawings · Rev 3
Ask the plans
A-2 finished reading.

What finish is specified for the primary bath floor?

Answer blocked I could not rule it out from the earlier reading.
The sheet is ready
A-2 Second floor planThe new reading pass retained this sheet's drawing facts.

The blocked reply stays as it was.

Ask something else about Rev 3
A new source needs a new turn

Ask again creates a linked question against the recovered run. The previous blocked turn remains visible, and the new paid call is deliberate.

15 · The question failed
A retrieval or model failure says it failed. The previous question remains intact, nothing canonical changed, and retry is explicit because the call may cost money.
The Hollis House · Plans & drawings · Rev 3
Ask the plans
Nine sheets in the current set.

Which sheet shows the first floor?

Question stopped I could not finish that question.
Nothing changed

Your plans are still here, and nothing in the house record changed.

Retry the exact request when you are ready.

Ask something else about Rev 3
Failure keeps the question

A failed job is not an empty answer and not a reason to clear the field. The user can retry the exact request or leave it and ask something else.

Retry stays deliberate

The call may incur cost. Nothing silently repeats it just because a screen remained open.

16 · Retrying without erasing the failure
Try again creates a linked turn against the same plan set. The stopped attempt remains visible while the new request moves through truthful stages.
The Hollis House · Plans & drawings · Rev 3
Ask the plans
The first attempt stays in the thread.

Which sheet shows the first floor?

Question stopped I could not finish that question.

Nothing changed

Nothing in the house record changed.

Trying the question again

Which sheet shows the first floor?

Linked retry
Writing the answerUsing retained facts from the same Rev 3 plan set.
Found this plan set
Matched the question to drawing facts
Writing the answer
Checking the cited sheet
Ask something else about Rev 3
Retry is a new turn

The failed question is immutable. Try again creates a linked request against the same retained run instead of resetting the failed row to queued.

The paid repeat is visible

The repeated person bubble records the deliberate action. HouseChalk never silently resubmits a failed provider call.

17 · Nine spaces, two questions
A completed read does not become nine interruptions. Seven clear matches stay quiet; the owner enters one short review for the two spaces below the confidence rule.
The Hollis House · Plans & drawings · Rev 3
I found nine spaces.
Seven are clear. Two need your call before I can put any of them in your binder.
Seven are readyThe plan label and room type agree.
Two need your callOffice and Guest bath each match more than one room type.

I will show you all nine before anything changes in your house record.

Review two spaces
Not now
Silence is the high-confidence state

The seven clear matches are summarized, not confirmed one at a time. The review exists only because two proposals fell below the configured threshold or were ambiguous.

No write on entry

Starting review does not create a zone, a sheet link or a decision. The owner sees one complete preview before the canonical apply.

18 · The first owner choice
The drawing label is kept. The owner is choosing what kind of room that label means in the binder, and this frame captures the state after the owner selects Office.
1 of 2 · A-1 Floor plan
How should I file the Office?
The plan calls it Office. A closet and a full door make the room type less certain.

The name stays Office either way. This only controls what belongs in that space.

Choose the room type

Office

File work-space decisions here.

Bedroom

File sleeping-room decisions here.

Neither of these
Continue
Nothing is preselected

The live screen opens with both choices unselected. This frame shows the result of the owner's tap so the selection treatment is visible; Continue stays unavailable until a choice is made.

Label and type stay separate

The immutable drawing space remains Office. The chosen library room type controls valid decision seeding without rewriting what the sheet says.

19 · The second owner choice
A second low-confidence proposal uses the same one-question screen. The room label remains Guest bath; the owner settles whether it carries full-bath or powder-room decisions.
2 of 2 · A-1 Floor plan
What kind of bath is the Guest bath?
The room name is clear. The fixture symbols are not complete enough to tell which decisions belong there.

The name stays Guest bath. I only need to know which set of decisions fits it.

Choose the room type

Full bath

Includes a tub or shower.

Powder room

Sink and toilet only.

Neither of these
Review all nine
A bounded review

The position marker is honest because the review count is known before the owner begins. A third prompt cannot appear halfway through this run.

Only valid choices are offered

The proposal's retained candidates supply the room types. Neither of these opens a free-form taxonomy picker; the quiet escape handles a genuinely different room.

20 · The whole preview
All nine spaces appear together before the write. The two owner choices are visible in context, and the action names the canonical change rather than saying Continue.
The Hollis House · Rev 3
Nine spaces will go into your binder.
This is the complete list. Rev 3 stays the source after you add it.
First floor · 7
KitchenA-1 Floor plan
MudroomA-1 Floor plan
Great roomA-1 Floor plan
LaundryA-1 Floor plan
Guest bathYour choice · Full bath
OfficeYour choice · Office
GarageA-1 Floor plan
Second floor · 2
Primary bathA-2 Second floor plan
Primary bedroomA-2 Second floor plan

Adding these creates the spaces and only the decisions that fit them. It does not change Rev 3.

Add nine spaces
Back to the two choices
Preview means the whole transaction

Every proposed space is present before apply, not just the uncertain ones. The owner can trace every row back to its sheet and see which two classifications came from them.

One explicit write

Add nine spaces creates the canonical zones, their sheet links and the valid decision set as one owner-authorized operation. Back edits retained choices; closing leaves the proposal untouched.

21 · Applied to the binder
Success returns a house-shaped result, not a technical receipt. The plan revision remains named because it is the provenance for every space that was just added.
The Hollis House · Plans & drawings
Rev 3 is in your binder.
Nine spaces are filed, with the decisions that apply to each one.
Added from Rev 3

9 spaces

47 decisions now sit in the rooms where they belong.

Your two calls
OfficeFiled as an office
Guest bathFiled as a full bath
Open the house
Back to plans
The result is not another review

The success screen names what changed and offers the two places the owner is likely to go. It does not repeat all nine rows after the transaction has already committed.

Provenance survives apply

The canonical spaces keep their Rev 3 proposal and sheet evidence behind them. P8 can later compare a new revision without pretending these were entered manually.

22 · Everyone else can see, not apply
A builder or invited collaborator sees what Rev 3 found and why it is waiting. They do not receive the two prompts or an apply control.
The Hollis House · Plans & drawings · Rev 3
Nine spaces were found.
Seven are clear. Two are waiting for Sam's call.
Seven ready to fileKitchen, Primary bath, Mudroom, Great room, Laundry, Primary bedroom, Garage
Two need the ownerOffice and Guest bath

Only a project owner can choose the room types and add these spaces to the house record.

Back to plans
Authorization shapes the screen

The non-owner can inspect the retained result but cannot submit review decisions or discover an apply endpoint through disabled controls. The action is absent because the permission is absent.

The wait names a person

Sam is the project owner in the pinned fiction. Naming the person who can move this is more useful than a generic permission error.

23 · Apply failed, choices kept
A failed transaction says that nothing canonical changed. The two owner choices remain attached to the proposal so retry does not become repeated work.
The Hollis House · Rev 3
Nothing changed.
I could not add the spaces to your binder. Your two choices are still here.

The house record still has no spaces from Rev 3. Try again when your connection is steady.

Ready to try again
Spaces9 from Rev 3
OfficeFiled as Office
Guest bathFiled as Full bath
Try adding again
Back to plans
Atomic or nothing

A partial apply would be worse than a visible failure: spaces, sheet links and valid decisions commit together. The error therefore reports an unchanged house record, not a fraction.

Recovery does not erase work

The immutable proposal and the owner's two review choices remain available. Retry repeats the apply operation, not the questions.

24 · The read finished with no spaces
A completed run with no retained space proposals is not an apply success and not an error. The plans stay filed, the house record stays unchanged, and there is no empty transaction to submit.
The Hollis House · Plans & drawings · Rev 3
There are no spaces to review in Rev 3.
The plan read finished. It did not return a space I can add to your binder.
Rev 3 stays in Plans & drawingsThe sheets and retained plan read are still here.

Nothing in your house record will change. There is no space list to add from this revision.

Back to plans
Empty is not applied

The run completed, but zero proposals cannot become a successful binder update. This state has no primary action and creates no durable apply command.

The plans are not missing

Rev 3 remains readable in Plans & drawings. The copy names the narrow absence: this retained run produced no space list to review.

25 · A later revision is ready
The later set stays visibly separate from the current binder source. Selecting it adds one owner-only comparison action; it does not make Rev 4 current.
Selection is not adoption

Opening Rev 4 still lets the owner read and ask it. The only new action is Compare; the current marker stays on Rev 3 until an explicit adoption transaction commits.

The dock belongs here

This is still the Plans & drawings tab. The dock disappears only after the owner enters the bounded comparison and decision flow.

26 · What changed in Rev 4
The comparison leads with room meaning, not drawing geometry. Seven rooms still match; three need an adoption rule before any seeded house data can change.
Rev 3 compared with Rev 4
Rev 4 changes three rooms.
Most of the house still matches. Here is the part that needs your call.
Seven rooms still matchTheir names and room types did not move.
The three changes
Guest bath becomes Powder roomSame place, different room type
Pantry is newAdded beside the Kitchen
Garage is no longer shownRev 4 has no matching room

Your Garage work is protected. A later plan cannot erase something you or Nora changed.

Choose what happens
A semantic comparison

Sheet pixels are evidence, not the decision. The owner sees matched, changed, added and absent rooms after the retained runs have been compared.

Protection appears before choice

Garage is absent from Rev 4 but already carries human work. The comparison says it will survive before asking what to do with rooms and decisions that have no choices, answers, notes or files.

27 · Replace, clear or keep
Nothing is preselected in the live screen. This frame shows the Rev 4 update selected so the treatment is visible; every choice keeps work added by a person.
Rev 4 · Your decision
What should happen to the rooms and decisions from Rev 3?
Anything you or Nora changed stays. Your choice only affects rooms and decisions from Rev 3 with nothing saved to them.

Your choices, answers, notes and files stay with you. Rev 4 cannot remove them.

Choose one

Update from Rev 4

Use Rev 4 only for rooms and decisions with no choices, answers, notes or files.

Remove Rev 3 rooms and decisions with nothing saved

This removes only rooms and decisions with no choices, answers, notes or files. It adds nothing from Rev 4.

Keep your current rooms and decisions

Change nothing in your binder. Rev 4 stays in Plans & drawings.

Review this choice
One decision, three meanings

Update makes Rev 4 current and changes only rooms and decisions with no human work. Remove makes Rev 4 current but adds none of its rooms or decisions. Keep leaves Rev 3 current and returns to Plans without a confirmation screen.

Human work always stays

Protection is not a fourth option and not a per-room burden. The server finds choices, answers, notes, files and other human work, rechecks them under lock, and keeps them in all three paths.

28 · Preview the Rev 4 update
The final screen names the complete mutation. It separates what Rev 4 will change from the human work that will survive.
Rev 4 · Replace preview
Rev 4 can update your binder without losing your work.
This is the whole change. Nothing happens until you use the button below.
Will change
Add PantryNew room and the decisions that fit it
Replace Guest bath with Powder roomNo one added a choice, answer, note or file to Guest bath
Will stay
GarageKept because it has a settled choice
Your workEvery choice, answer, note and file
Rev 3Kept as the prior plan source

If anything changes while this preview is open, I will stop and show you the comparison again.

Use Rev 4 and keep your work
Back to the three choices
Exact before irreversible

The preview names additions, replacements, protected exceptions and retained history. The button repeats both adoption and treatment; generic Confirm would hide the consequence.

A changed preview means review again

The preview token covers the comparison and the rooms and decisions with human work. New work invalidates it, so the transaction cannot remove something a person changed while the preview was open.

29 · Preview removing Rev 3 entries with nothing saved
Remove is not tucked into a menu or treated as a secondary spelling of Update. It has its own destructive preview because Rev 4 will become current without adding its rooms.
Rev 4 · Remove preview
Remove the Rev 3 rooms and decisions with nothing saved?
Rev 4 will become current. HouseChalk will not add Pantry, Powder room or new decisions to your binder.
Will be removed
Guest bathNo one added a choice, answer, note or file
Rev 3 decisions with nothing savedNo choices, answers, notes or files
Will stay
Garage and every other room with your workYour work wins over the later plan
Your choices, answers, notes and filesRev 4 cannot remove them
Rev 3Kept as the prior plan source

Pantry and Powder room will stay in the drawing set only. They will not appear as rooms in your binder.

Use Rev 4 and remove these rooms and decisions
Back to the three choices
Remove has a narrow object

The action removes only rooms and decisions HouseChalk created from Rev 3 that still have no human work. It does not remove plan sets, evidence, questions or anything a person changed.

No implied replacement

The preview explicitly says the two Rev 4 rooms stay in Plans & drawings. Otherwise Remove could look like a temporary step before the new plan silently adds them again.

30 · Rev 4 updated entries with nothing saved
The result reports the house-shaped effect and the protected exception. Rev 3 remains available as history rather than disappearing behind the new current marker.
The Hollis House · Plans & drawings
Rev 4 is now in your binder.
Pantry was added. Guest bath became Powder room. Your work stayed put.
Updated from Rev 4
AddedPantry
ReplacedGuest bath with Powder room
KeptGarage, plus every choice, answer, note and file

Rev 3 is still in Plans & drawings as the source that came before this one.

Open the house
Back to plans
Success names the exception

The owner sees not only what changed but that Garage survived. “Everything updated” would be shorter and false.

Revision history is retained

Rev 4 becomes active and Rev 3 points forward to it, but the prior set, selected run, evidence and applications remain readable provenance.

31 · Rev 4 is current, with no new rooms
The Remove result does not borrow the Update success copy. It confirms that the later drawings are current while their new rooms and decisions were deliberately not added.
The Hollis House · Plans & drawings
Rev 4 is current. Rev 3 rooms and decisions with nothing saved are gone.
Your work stayed. No new rooms or decisions were added from Rev 4.
Your remove choice
RemovedGuest bath and Rev 3 decisions with nothing saved
KeptEvery room and decision with your work
Not addedPantry, Powder room and Rev 4 decisions

Rev 3 is still in Plans & drawings as the source that came before this one.

Open the house
Back to plans
Remove does not mean empty house

Human work remains in the binder, so the result names both what was removed and what stayed. The owner is never shown a false blank-slate claim.

The new set is still useful

Rev 4 becomes the active source for viewing and questions even though the owner declined to seed canonical rooms or decisions from it.

32 · Adoption failed, Rev 3 stayed current
A failed transaction preserves the prior active set and every canonical row. The owner’s treatment remains available for an explicit retry.
The Hollis House · Rev 4
Nothing changed.
I could not update the binder. Rev 3 is still current, and your choice is still here.

No plan set, room or decision changed. Try again when your connection is steady.

Ready to try again
Later setRev 4
Your choiceUpdate from Rev 4 and keep your work
KeptEvery choice, answer, note and file
Try updating again
Back to the preview
Atomic or nothing

Activation, supersession and canonical treatment commit together. The error can promise Rev 3 stayed current because no partial state is permitted.

Retry does not reinterpret

The treatment and preview remain durable enough to retry, but any stale protection fingerprint returns to comparison rather than forcing the old preview through.

33 · The update could not be confirmed
This appears only when HouseChalk did not receive a reliable response. It does not claim that the request succeeded or rolled back; checking again can only confirm the same request.
The Hollis House · Rev 4
I could not confirm what happened.
Your request may have reached HouseChalk. Checking again will not run it twice.

Your rooms and decisions are still protected. I need to check the same request before I can tell you what changed.

The request I will check
Later setRev 4
Your choiceUpdate from Rev 4 and keep your work
ProtectedEvery choice, answer, note and file
Check the same request
Back to Plans & drawings
One command, not another try

The implementation reuses a deterministic command key derived from the candidate, treatment and preview token, so route disposal or restart cannot create a second command.

Unknown is not rolled back

An explicit server rollback still uses frame 32. Only a network failure, unreadable response or lost response uses frame 33; this state makes no claim that the request succeeded, rolled back or changed the current set.

34 · The way in
The record gains one action. The list remains the destination, and adding a paper never turns the tab into an upload screen.
The record stays first

The sort from frame 5 does not move: waiting permits, live permits, then ordinary papers. The action follows the record instead of replacing it.

The file picker is the compact entry

On a phone, Add a paper opens the platform file picker immediately. Cancel returns here without creating a route, upload or document.

Write seats only

Owners and builders see the action. A viewer sees the same synced record without an inert or disabled upload control.

One record, not a copy

Contracts, change orders, plans and inspections remain owned by their source flows. Y3 joins inspections to their permits. Y9 brings the other source read models into this tab; this intake never duplicates them as binder documents.

35 · Name the paper
The file is already selected on compact. Desktop reaches this state through one bounded drop zone, never by turning the whole page into a target.
Papers & permits
Add a paper
Choose the file first. Then add the details you know.
Mechanical permit.pdfYour original file is saving · you can leave this screen
Paper type
Permit
Choose Permit when the paper has permit dates and an issuing office.
Paper name
Mechanical permit
Continue
Back
Desktop gets one drop zone

Drop a file here, or choose a file

Only this bordered surface accepts a drop. Clicking it opens the same picker. The rest of Papers remains ordinary navigation.

One file keeps the facts attached

The flow accepts one paper at a time because the next fields belong to that file. Batch selection would create an unlabeled queue and make a permit type easy to attach to the wrong upload.

The choice adapts, not the values

Paper type opens a bottom sheet on compact and an anchored menu on wide. The first set is Permit, Certificate and Other paper. Plans, contracts and change orders stay in their own flows.

The upload remains the source

The existing upload-session lifecycle retains the bytes. Restart keeps only the pending session id and expiry. The app asks for fresh signed PUT details and creates a new OPFS object URL for each web attempt; neither enters Drift. The document writer accepts only a completed upload from this project, and the upload id never reaches sync.

Waiting is not saved

An interrupted upload remains Waiting to upload and retries with the same local task. Papers gains no document row until both upload completion and the idempotent document write succeed.

36 · Add permit details
Only Permit opens this step. A certificate or other paper saves after frame 35 instead of inheriting fields it cannot answer.
Mechanical permit
Add permit details
Add what you know now. You can add the permit number and issue date when the permit arrives.
Issued by
City of Austin
Application date
3 May 2027
Permit number
Add when issued
Who is following up?
Dave
Choose who is following up on your permit. This does not create a task.
Save permit
Back
Pending is a complete state

A permit can be saved with a label and application date before it has a number or issue date. Empty means not issued yet; it does not mean the record failed to load.

Dates are calendars

Application, issue and expiration dates use the platform calendar control. If entered, application cannot follow issue, and issue cannot follow expiration. The field always prints the localized date rather than storing formatted copy.

Following up is not assignment

The name explains who is following up on the permit. It does not create a task, notify that person or claim they accepted responsibility.

The file stays put on failure

If the permit write fails, the completed upload and entered facts remain on this screen. Retry sends the same idempotency key, so it cannot create a second document or permit.

Files are opened, never synced as credentials

Every project seat may ask to open an accessible document. The gateway authorizes the document, issues a short-lived storage URL and marks the response private and no-store. The URL, signed headers, storage key and completed upload id never enter Drift. Only the pending upload session id and expiry survive a restart.

37 · Opening a care task
Compact opens one adaptive detail surface as a bottom sheet. The current occurrence and the immutable completion history stay in one reading order.
One task, one current occurrence

The action carries the observed due date, 18 September 2028. A second device that has already advanced this task receives the changed-task state instead of appending another completion.

History keeps its room

The 18 June entry carries its Kitchen identity and label snapshot. Renaming, reclassifying or deleting the room cannot rewrite where the work was done.

Compact interaction

The sheet focuses this heading on entry, traps focus, reads Close then the two actions, and returns focus to the task row when dismissed. Only an owner or builder in a writable project sees completion actions.

38 · Choosing a completion date
The product asks for a date, not a timestamp. The field opens the same themed platform calendar already used by Papers.
The calendar is the platform component

The mockup draws the HouseChalk field that opens it, not a custom calendar. Compact and desktop use the same date bounds and localized result.

Bounds have two jobs

The client permits a local date through today. The server also requires the date to be on or after closing and no earlier than the latest effective completion for this task.

The wire stays stable offline

The queued assertion stores this date-only value and the observed scheduled due date. It does not replace the payload with a later retry date.

39 · Care before closing
An owner can make Care reachable by recording the day they received the keys. Nothing previews a schedule before that anchor exists.
Owner-only transition

Set closing date is online-only, carries the observed project version, and reconciles the imported catalog in the same locked project transaction.

Silence would make a claim

This state does not draw future chores or a caught-up card. Without a closing date, the system does not know when any interval begins.

Calendar and focus

The action opens the themed platform calendar, announces the selected date, and returns focus here when the calendar closes.

40 · Care before closing, read-only
Builders and viewers receive the same explanation without a disabled control that implies they can set the homeowner's closing date.
No inert affordance

A builder can complete Care work after closing, but cannot author the project's closing date. A viewer can only read. Neither seat sees an unavailable Set closing date button.

Same truth for every seat

The explanation does not change by role. Only the action changes, and absence of authority is expressed by absence of the control.

41 · Caught up for this season
No task is overdue or due in the current fall interval. The settled statement does not pretend the future schedule is empty.
Caught up has a boundary

On 18 September 2028, fall runs through 30 November 2028. This alternate state assumes the September and October work is complete; the December task remains reachable under Later.

Settled, not empty

This is the existing year-two settled pattern — a tick and a sentence on the outline rung, where a sage card used to say it. It reports a useful result and never appears when the canonical query failed.

42 · Completion saved offline
The assertion appears immediately, stays visibly pending, and carries its original principal, seat, occurrence and date until the server acknowledges it.
Pending is not canonical

The local overlay moves the row into Already done, but the server still owns next_due_on. Sync clears the overlay only after both the completion and updated task arrive.

Undo is causal

If delivery never started, Undo removes the local assertion. Once an attempt begins, Undo queues a dependent reversal and first replays the original idempotency key to recover the canonical completion id.

Principal-bound queue

Sign-out or account switch blocks this drain before credentials change. Another person or another seat can never send Sam's queued assertion.

43 · Care could not load
A failed canonical read never becomes a calm empty or caught-up state.
The error arm is a product state

The Care view model keeps loading, data and error separate. It never tells someone their house is caught up because the read failed.

Focus stays put

The spoken state announces once. Try again is a real action, and retry does not move focus into an empty schedule while the read is unresolved.

44 · Completion could not save
The failed assertion remains attached to the task it belongs to. Failure never silently becomes completion.
Actionable failure stays local

Transport and retryable server failures preserve the date, occurrence and idempotency key. Retry sends the same assertion instead of minting a second completion.

Other failures leave this frame

An authorization failure removes the overlay and refreshes membership. An invalid date returns to date selection. A stale occurrence uses frame 45 and is never retried as the old occurrence.

45 · The care task changed
Another device completed the occurrence first. Care refreshes the task and asks the reader to review the new state.
Occurrence identity stopped the duplicate

The server locked the task and rejected the old observed due date without appending history. Sync then supplied the canonical December occurrence.

No blind retry

The optimistic overlay is gone. The changed state announces once without stealing focus, and the reader must open the refreshed task before acting again.

46 · Waiting for restore
Archived houses remain readable. A queued completion pauses without being discarded, retried forever or sent under another account.
Archive is a write barrier

projectWritePosture removes completion, reversal and closing-date actions while the project is read-only or its posture is unknown.

The command waits intact

Restore resumes only the originating principal's drain. The state announcement does not steal focus, and there is no Retry button while archive still blocks the command.

47 · Correcting the closing date
An owner may correct the schedule anchor or remove it while no Care history exists.
Care
Correct closing date
Care starts from the day you received the keys.
Closing date2 June 2027
Save date
Remove closing date
Online owner command

The save carries If-Match for the observed project update and one idempotency key. The project update and Care reconciliation share one project lock and transaction.

Correction respects history

Untouched tasks re-anchor. Recurring work with history stays derived from its latest effective completion, completed one-time work remains retired, and no historical room or completion snapshot changes.

Remove is conditional

Clearing is offered only while no completion exists. It retires catalog tasks as care not started instead of deleting synced rows.

48 · Closing date after care history
A correction cannot move closing beyond the first recorded Care entry, even when that entry was later reversed.
Care
Correct closing date
Closing date22 June 2027Choose a closing date on or before your first care entry.
Choose another date
The first entry sets the ceiling

The fiction's earliest completion is 18 June 2027. The server rejects 22 June with closing_after_care_history before it can make that completion precede closing.

The calendar returns here

The field keeps the rejected selection visible, explains the valid boundary in the reader's terms, and returns focus to date selection.

49 · Closing date cannot be removed
Care history protects the anchor from being erased. Correction remains available.
Care
Correct closing date
Your care history uses this closing date.You can correct the date, but you cannot remove it.Correct closing date
Closing2 June 2027
First care18 June 2027
History is never deleted to clear a date

care_history_exists leaves the closing date, schedule and append-only ledger untouched. The only available next act is a valid correction.

One spoken state

The conflict is announced once, preserves keyboard focus, and contains no disabled Remove action.

50 · Care task on desktop
Desktop keeps the compact sheet's content, reading order and actions, but places them in a centered dialog over the Care page.
Living in it
Care
Nothing needs deciding. A few things come up this season.
Range hood filter degreaseKitchenSeptember
Fall gutter cleaningThe house itselfOctober
Equivalent, not enlarged

The dialog carries the same title, guidance, room, due date, history and actions as frame 37. It does not turn desktop into a second Care information architecture.

Desktop keyboard contract

Focus enters on the heading, remains trapped, closes with Escape, and returns to the invoking task row. The tab order is Close, Mark done today, then Choose another date.

Same authorization

The dialog appears only for an active task in a writable project held by an owner or builder. A retired one-time task opens history-only.

51 · Closing date on desktop
The owner sees the same date contract in a desktop dialog. The field opens the platform calendar instead of a custom HouseChalk calendar.
Living in it
Care
Nothing needs deciding. A few things come up this season.
Range hood filter degreaseKitchenSeptember
One platform calendar

The field launches the themed platform date picker and returns its localized date here. Compact and desktop share the same upper bound and the same first-history ceiling.

Concurrency stays visible

Save carries the project version observed when this dialog opened. If the project changed, Care refreshes rather than overwriting a newer closing date.

Remove obeys history

This action is present only when the project has no completion row. Once history exists, frame 49 replaces it with the explanation and correction path.

52 · Marked done today
The acknowledged completion settles in the record, exposes Undo, and shows the next occurrence returned by the server.
Acknowledged, not merely optimistic

This state appears only after the completion row and updated task arrive from the server. The pending overlay in frame 42 has cleared.

The server advances the schedule

17 December comes from the canonical fold over the completed 18 September occurrence. The device never adds 90 days itself.

Undo names the fact

The action carries the completion id and opens the reversed-history state. It appends a reversal; it never deletes the completion.

53 · Completion undone
Undo restores the occurrence while retaining the completion and reversal in Care history.
Reversal is history

The 18 September completion remains visible with its room snapshot and a linked reversal fact. The record does not pretend the first action never happened.

The occurrence returns

The same scheduled occurrence is active again because its completion no longer participates in the effective fold.

One causal Undo

Only the seat that created the completion may reverse it during the allowed Undo window. A second reversal is refused rather than treated as success.

54 · Marked done today on desktop
Desktop uses the same settled statement, canonical next occurrence and causal Undo without changing the information architecture.
Living in it
Care
Marked done todayYour next range hood cleaning is due 17 December.
Already done
Range hood filter degreaseKitchen · TodayUndo
Later
Same state at a wider measure

The settled message and two record sections reflow into columns. Their order, content and actions remain equivalent to frame 52.

Undo remains explicit

The completed summary stays plain record text. Undo is the only trailing action for the completion just created.

No client date arithmetic

The December occurrence is the gateway result displayed at desktop width, not a second calculation.

55 · Completion undone on desktop
The wider record restores the occurrence and keeps the reversed entry legible beside it.
Living in it
Care
Completion undone.Your 18 September entry stays in your care history.
Kitchen
History
18 September 2028Kitchen · Undone today
History and current state stay distinct

The active September occurrence and the reversed history entry can be read together without treating either as the other.

Same immutable record

Desktop reads the same completion and reversal identities as compact. Width changes presentation, never the ledger.

Focus remains stable

The status announcement does not steal focus. The restored task row is the next reachable action.

Five tabs, five different distances from shipping

They look identical on the contents page. They are not, and the difference is not effort in the abstract, it is which layer is missing.

One dead end worth a line. The appliances table has had a zone_id column since 0001_init.sql:90, and it has no handler, no route and no Dart model. The one place in the schema where a thing is already attached to a room is the one place nothing reads.

Notes on the drawing

Grounded in