System
Four bands, feeds through surfaces, each carrying counts read live off the store — not drawn by hand, so this page cannot describe a system that no longer exists. The containers themselves, and the ontology each one keeps, are the matrix on the home page.
This is the common layer under the containers — the pipeline that produces every other page on this site: sources feed an object store, curation narrows it into collections, and a handful of public surfaces render what has cleared review. Every number below comes from the same view-models that render /sources, /collections and /knowledge — if this page ever disagrees with one of those, that is a bug in this page, not in them.
Two counts of the store are in circulation, and they differ by the 7 source cards. The 423 above is everything in kb/,
cards included — a card describes a container rather than belonging to
one, so /sources attributes 416 objects to containers, and /slices counts that same set as typed objects.
Neither is wrong; they answer different questions, and this note is here so
nobody has to guess which.
Authority — what is source of truth for what
Condensed from docs/governance/SOURCE-OF-TRUTH-MATRIX.md in the
refi-bcn-os workspace, which is canonical — read it there for the full sync
protocol and conflict-resolution rules.
| What | Source of truth | Notes |
|---|---|---|
| KB objects | kb/ (this repo) | One markdown file per object — frontmatter is the fields, the body is the notes. Local files are the source of truth. |
| CRM records | refi-bcn-os data/crm.yaml | The CRM registry stays in the refi-bcn-os workspace; Notion is the pushed mirror — the instance reads the mirror, at build time, read-only. |
| Collections | src/data/collections.yaml | Hand-authored definitions; membership is computed, not stored. |
| Ingest disposition | src/data/sources-disposition.json | Derived from the refi-bcn-os batch rosters and committed — never hand-edited. |
Gates — what stops content leaking
| Gate | What it does |
|---|---|
| publishableKb | Fail-closed: an object publishes only if it is marked in-scope, cleared to reviewed/published maturity, not AI-assisted, and clears its paired public-use boundary tier. |
| dist canary + listing scan | scripts/verify-public-kb.mjs walks the built dist/ tree after every public build, checking for known raw-content canaries; fails the build closed. |
| staticrypt internal lens | The internal review build is encrypted before it leaves the machine; a separate gate asserts exactly one HTML file, a staticrypt marker, and no /_astro references. |
| computed archive-ready verdicts | A source is archive-ready only when all four checks pass: every file is dispositioned, the batch numbers reconcile against the checkout, every high-risk object (Indigenous/TEK, personal, governance-sensitive material) has cleared raw review, and a real signoff is recorded. Any missing input fails the verdict closed — it must never read ready because it has less information, the bug this module was hardened against. |
/slices draws crosscuts over this pipeline — domains by schema, the review funnel, the high-risk queue, and boundary tiers.