One controlled path for every change.
Ledger artifacts change through exactly one path: a Change Intention. A developer or an agent declares what they want to do, and every Change Intention goes through Design Review.
| Step | Item | State |
|---|---|---|
| Actor | Developer or agent | Declared |
| Intent | Add a second payment provider | Proposed |
| Delta | Ledger changes this would cause | In review |
| Review | Design Review, human only | Approved |
Three parts, one gate.
A proposed transition, declared by an actor. A candidate, not a mutation.
A human-only gate, much like a GitHub pull request.
Where approved changes merge.
From intent to the main branch of design.
An actor says what they want to do. rkito captures it as a CHI.
rkito proposes how the Ledger should change as a result.
Design Review is the only function that can authorise the change.
Once approved, it merges into the main branch of design.
Before code, and at the PR.
Code review asks whether code passes. Design review asks whether a decision conforms to intent.
Agents generate code that compiles and still violates a boundary someone drew three sprints ago.