Board 2026-08-23 — Ratify BUSINESS_MODEL.md — FINAL MINUTES #42

Closed
opened 2026-08-23 17:30:49 -04:00 by logan · 4 comments
Owner

Agenda

Do we adopt BUSINESS_MODEL.md as the company's go-to-market — ratify as written, ratify with named amendments, or kill it — thereby deciding who pays and at what price?

This is the board's first sitting. A search of logan/server-26 (open and closed) confirms no prior minutes:final issue exists, so nothing in BUSINESS_MODEL.md, SAAS_PLAN.md or UI_REDESIGN.md was binding before today.


Where the board agreed (stated once)

All four advisers converged on "ratify the structure, gate the revenue." Nobody argued to kill the document and nobody argued to ratify it as written. That consensus is adopted and not re-argued below. The value of this ruling is in (a) saying precisely what is ratified, (b) making the gate enforceable instead of a sentiment, and (c) refusing to invent answers to owner-only questions.

Three findings were reported by more than one adviser and are accepted as fact without further debate:

  • Firestore rules exist in source (Server/infra/firestore/firestore.rules, deny-by-default, scoped on resource.data.org_id == request.auth.token.org_id) but are not deployed to production (#13). The live tenant boundary is unknown, not known-bad — the distinction matters for wording, not for the gate.
  • lib/billing.ts publicly promises retentionDays: 7/90/365 (lines 88/103/120) with no enforcement anywhere in drb-c2-core.
  • BUSINESS_MODEL.md §5.7 mitigations #1 (EMS/medical exclusion) and #2 (name redaction) — which the document itself calls "the highest-leverage single mitigation in this entire document" and "cheap" — are not built.

The real conflicts

Conflict 0 — the board's own record is corrupt. Issue #40, filed as the CTO draft, has a body byte-identical to #39 (CISO). The CTO's actual findings never reached the record. I am not going to rule on a missing document, so I verified the CTO's substantive claims against source myself before ruling:

  • Per-system AI gating is real: drb-c2-core/app/routers/systems.py:107-129 (PUT /{system_id}/ai-flags) writes a systems.ai_flags override; drb-c2-core/app/routers/upload.py:270-284 consumes it via _flag() with the semantics "global master off beats everything; system override defaults to inherit."
  • But it is an require_admin_token manual toggle with no link to org, plan, entitlement or billing. There is no code path by which paying for a county turns AI on, or non-payment turns it off.
  • A grep of drb-c2-core/app for cost_usd|token_count|usage_meter|per_call_cost|billing_usage|input_tokens|prompt_tokens returns zero hits. No per-call, per-system or per-org cost accounting exists.

Consequence, and this is the single most important finding of the meeting: BUSINESS_MODEL.md §0 line 5 ("Cost follows demand, not supply … feature_flags.py already supports per-system gating") is half true — the gate exists, the demand-linkage does not. And not one dollar figure in §4 has ever been checked against a real provider bill. §4.3's floor price of $49 and §3.4's "your cost is ~$70/node-month" are models resting on two assumptions the document's own §10 admits are unverified (node-002's real call volume; average recording length). We were one ruling away from publishing a price derived from a spreadsheet nobody has ever reconciled to an invoice.

Conflict 1 — is §8's status table trustworthy? The COO reads §8 as the gate list and finds 7 of 10 items have no issue and no DEFERRED.md entry. The CISO reads §8 item 1 ("Tenant boundary … Not started") and correctly says the code side has substantially landed. Both are right, which means the table is stale in both directions: it understates progress on item 1 (tenancy code landed) and overstates remaining risk on item 5 (Gemini model IDs already migrated — config.py:47-48, closed via #14). Ruled: §8's "Status" column is struck. Gitea is the status board; a prose table inside a strategy doc is not. The list of ten gates survives; its status annotations do not.

Conflict 2 — how hard is the gate, and a gate on what exactly? COO: don't ratify §7's dates. CMO: don't put a price on the site. CISO: hard gate on charging card #1. Those are three different gates being described as one. Ruled: there are two gates, A and B, and they are separate. See Decisions 4 and 5.

Conflict 3 — friends and family collide with the free tier, and the document does not resolve it. The CMO is right and this is not a small point: today's free tier is full-featured and live, while §3.2's "Public" tier is $0, ≥30 min delayed, no audio, no transcripts, no names. Those are two different products wearing one price. If friends and family keep the live full-featured version for free while a Founding Operator pays $49/mo for it, there is no conversion pressure and the delay/redaction mitigation is decorative because it only ever covers strangers. This changes what the product is for people already using it, so it is an owner question, not mine — see Open. What I can rule, and do, is that Decision 6 (redaction + disclaimer) applies to every surface including free, which de-risks the collision whichever way the owner rules and preempts nothing.

Conflict 4 — the beachhead. The CMO explicitly refuses to let the tow/collision beachhead be adopted by default silence, noting the owner did not recognise it when raised. Correct call. Not ruled here — see Open item 1.


Decisions

1. BUSINESS_MODEL.md is RATIFIED IN STRUCTURE, with named amendments. It is not killed and it is not ratified as written.
Binding as of today: §0 (except line 6), §1's segment ranking method, §2 in full (the participation mechanic), §3.1 anchors, §3.2 tier structure, §3.3's reasoning, §4.3's floor-price discipline, §5's legal position and §5.7's mitigation ordering, and §8's gate list.
Owner: CEO. Date: 2026-08-23, effective immediately.
Cost: we lock in a model whose unit economics have never been reconciled to a bill. Mitigated by Decision 5's B5, which forbids acting on the numbers until they are.

2. Ratified as binding operating discipline, not to be relaxed without a new board sitting:

  • Price by covered geography, not by seat. (§0.3)
  • Contribution earns invoice credit and is never redeemable for cash. (§0.4, §9 Q9) Going credit→cash later is easy; going cash→credit after someone has been paid is not. Ratified in the reversible direction.
  • $49/mo is the absolute floor, and the same county is sold five times before a second county is added. (§4.3) The highest-value single line in the document, and it costs nothing to adopt.
  • Data/OEM pricing is never published. (§3.2)
  • Sell the incident layer, not the audio. (§0.2)
    Owner: CMO (positioning), CTO (enforceability). Date: binding now.

3. §1's segment #7 (real-estate / neighbourhood-safety) is RATIFIED AS DECLINED — closed, not open for revisit without a new written legal opinion. CISO concurred; I am making it a closed question so it stops consuming meeting time.
Owner: CEO. Date: 2026-08-23.
Cost: the largest consumer TAM on the list. Given up deliberately — it is also where every defamation and harassment vector concentrates.

4. GATE A — "PUBLISH". No price, tier name, or entitlement from §3 goes on any public surface until all three hold.

  • A1. Every entitlement claimed on a page is either built, or carries an inline "not yet available" marker on the same screen as the claim — not a bottom-of-page footnote. Specifically covers retention (7/90/365), SSO/SAML, uptime SLA, and custom data residency, none of which exist.
  • A2. Every AI transcript and AI summary surface carries "Machine-generated, unverified. Not a substitute for 911 or official dispatch."
  • A3. Person names are redacted by default on all free and public surfaces.

Owner: CMO, with CTO for implementation. Date: 2026-09-13.

Further, and overruling the CMO in part (see Dissent): the invented $0/$79/custom placeholder in lib/billing.ts does not survive with a footnote. It comes off the public site, replaced by "Pricing in development — contact us", because §3.1 of the document we just ratified already declares it superseded. A fabricated price with a disclaimer below the fold is worse than no price: it sets a false anchor, and it is exactly what a plaintiff's exhibit looks like.
Cost: we lose the inbound self-serve pricing path. This costs nothing real — billing is a stub (#3; ADMIN_BILLING_AUDIT.md §2: createCheckoutSession always throws), so that path converts nobody today.

5. GATE B — "CHARGE". No card is charged, no invoice issued, and no Founding Operator slot is sold until ALL EIGHT hold. A checklist, not a judgement call.

Condition Verified by Owner
B1 #13 closed: firestore.rules and firestore.indexes.json deployed to prod, deployed ruleset ID recorded in the issue ruleset ID pasted into #13 Owner (WSL)
B2 #4 closed: /admin reads org-scoped (routers/users.py:57-70) issue closed w/ commit CTO
B3 §5.7 #1 EMS/medical exclusion default ON, and §5.7 #2 name redaction implemented new issue below CTO
B4 Retention either enforced by a real sweep, or the claim removed from lib/billing.ts and the FAQ new issue below CTO
B5 7 consecutive days of real AI spend measured per call / per system / per org, reconciled against an actual provider invoice, and §4's table corrected to match new issue below CTO
B6 ToS, Privacy Policy and AUP published new issue below Owner + counsel
B7 Business entity + media liability/E&O decision recorded — yes or no. If no, §9 Q3 hardens to full name suppression and Data/OEM is off the table entirely recorded in this issue Owner
B8 Transcript entity-name accuracy measured on ≥200 sampled calls. If below 80%, names are suppressed by default — pre-committed now, so the measurement cannot be argued with after the fact new issue below Owner

Owner of the gate as a whole: CEO. Date: B2–B5 by 2026-09-30. B1, B6, B7 and B8 are owner-blocked and get dates when the owner answers (see Open).
Cost: first revenue moves out by at least the B5 measurement window plus the time to build metering that does not exist. That is weeks, and it is the correct trade — §4's entire cost model is currently unfalsifiable.

6. Two live-site risks are fixed independently of pricing, on the Gate A date, because they are live to any self-serve signup right now. AI transcripts and summaries are presented as reading "like a dispatch briefing" with no "machine-generated, unverified" label anywhere, and no name redaction on public surfaces. Account creation works today (/login → /signup → real createUserWithEmailAndPassword), so a stranger can reach un-mitigated AI assertions naming private individuals, including EMS calls, in two clicks. This is the most dangerous thing the board found that is live rather than planned.
Owner: CTO. Date: 2026-09-13.

7. §7's go-to-market sequence is NOT ratified and its clock does not start today. The COO's capacity objection is upheld: §7 assumes cold-call sales, trial hand-holding, node-operator recruiting and shipping B1–B2 run concurrently, from one person who is also support, on-call and the only committer. Four workstreams, one person, no owner column. §7 becomes schedulable when the owner answers the beachhead question and §9 Q8, and Gate A is closed.
Owner: COO, to re-plan once unblocked. Date: not set — deliberately. A date on a blocked sequence is theatre.

8. §8's "Status" and "Owner" columns are struck as unreliable (Conflict 1). As a tracking artefact the §8 list is replaced by Gate B above plus the Gitea issues named in it. Several §8 items are assigned to "Build" that are in fact owner-only and unbuildable by any agent (#3 ToS, #4 entity/insurance, #6 accuracy sampling, #8 delay policy, #10 takedown contact).
Owner: CEO, enacted this session.

9. §9's recommended defaults are adopted as build defaults where they cost nothing and fail safe: Q1 B2B only for 18 months; Q2 exclude EMS/medical by default; Q3 do not publish person names; Q6 honour agency opt-outs proactively and publicly; Q9 credit never cash. Q4 (insurance spend), Q5 (existing agency contact), Q7 (scale ambition) and Q8 (walk-ins) are not adopted by default — they are money, fact, or a change to what the product is. See Open.
Owner: CTO for Q1/Q2/Q3/Q6 as defaults in code. Date: Q2 and Q3 ride B3 (2026-09-30).


What we gave up

  • Speed to first dollar. B5 alone pushes revenue out by weeks. We are buying the ability to say our price is above our cost and mean it.
  • The inbound pricing page. Taking $0/$79/custom down removes a conversion surface that converts nobody today — the loss is notional but it is real optics.
  • The largest consumer market, permanently, via Decision 3.
  • Optionality on contributor cash-out (Decision 2). We can add it later; we could not have removed it later.
  • The §7 clock, which does not start today. If the owner answers the beachhead question quickly this costs days, not weeks.
  • The comfort of a settled unit-economics model. We ratified the structure of §4 while declaring its numbers unverified. That is an honest but uncomfortable position, and Decision 4 exists so nobody has to hold it in public.

Dissent

  • CMO, overruled in part. Recommendation 5 offered "keep the current placeholder + its disclaimer, or take pricing off the public site." I take the second and close the first. Grounds: the placeholder is not merely unwired, it is invented, and §3.1 of the document we just ratified says so in writing. A false anchor with a below-the-fold footnote is a worse artefact than an empty page. The CMO's framework recommendation, the beachhead-needs-an-explicit-yes amendment, and the friends-and-family flag are adopted in full.
  • COO, upheld but re-scoped. Filing the 7 missing §8 items as issues is adopted (see Follow-ups). Fixing #30/#31 before any walk-in demo is adopted as fact but is not added to Gate B — a 404 after login blocks a demo, not a charge, and padding a revenue gate with unrelated bugs is how gates stop being believed.
  • CISO, upheld in full. No dissent. The recommendation ordering (rules first, then honest retention copy, then EMS/redaction) is preserved as B1 → B4 → B3.
  • CTO — no draft was in the record (#40 duplicated #39 byte for byte). The CTO's position was reconstructed from source by the chair and is recorded in Conflict 0. The CTO is not bound by a reconstruction and may file a correction; if it materially contradicts Conflict 0, this ruling re-opens on that point only. Process fix filed as a follow-up.

Drafts

#38 COO · #39 CISO · #40 CTO (duplicate body — see Conflict 0) · #41 CMO


Follow-up issues filed

Existing issues were commented on rather than duplicated: #13 (rules undeployed → B1), #4 (/admin scoping → B2), #3 (billing mock data → Gate A), #9 (org-owner writes), #33 (index drift → B1), #35 (correlation degraded).

New issues are listed in the first comment on this issue, once numbers are assigned.


Open — needs the owner

Amended 2026-08-23. The owner answered four of these ten. Those four are struck below; the verbatim answers and the rulings are in the "Owner rulings, 2026-08-23" comment on this issue. Six remain open.

Nothing left unstruck below has been decided or defaulted. Each is money spent, a fact only the owner holds, or a change to what the product is.

  1. The beachhead: tow / collision / restoration / auto-glass operators in Westchester — yes or no, on the record. → ANSWERED 2026-08-23 — "no real direction but sure tow is fine". Adopted as a hypothesis with a kill criterion (12 qualifying conversations; fewer than 4 trial acceptances kills it; fewer than 2 paid after Gate B kills it), not as ratified strategy. §0 line 6, §1's #1 pick, §3.4 and §7 are unfrozen but stamped provisional — beachhead untested. Owner conviction: low, on the record.
  2. Friends and family: which tier? → ANSWERED 2026-08-23 — "Keep them full-featured". A comped tier, distinct from §3.2 Public, which stays the delayed/redacted public free tier. Uncapped AI spend on non-payers is the accepted cost and cannot be capped until #45 exists. Founding-agenda item 4 is closed by this.
  3. Is $2–5k/yr for media liability / E&O approved before the first invoice? → ANSWERED 2026-08-23 — "assume it will happen but get to product mvp, feedback, then go for company things": no pre-revenue spend. Gate B7 closes as a recorded "not yet", and its pre-agreed consequences bind: names suppressed by default on every surface, paid included (this widens B3 and Gate A A3), and Data/OEM stays dead. Suppression is a display layer, never deletion.
  4. Business entity — does one exist, and in what form? (§8 item 4.) Stripe will not activate without it. Not verifiable from this machine. STILL OPEN — and ruling 3 makes company formation the trigger to revisit E&O, so this now blocks two things.
  5. Lifestyle/bootstrapped ($5–20k MRR) or venture-scale? → ANSWERED 2026-08-23, delegated to the board and ruled: lifestyle / bootstrapped, confirmed. One operator plus AI agents; no multi-state coverage, node-supply operation or sales function exists or is planned. §1 and §3's ratification no longer rests on an assumption.
  6. Willing to walk into ~40 local businesses in weeks 2–3? (§9 Q8.) "No" pushes first revenue out 6+ months by the document's own reckoning — a fine answer, but it must be an answer. STILL OPEN, and now load-bearing: the beachhead kill criterion in ruling 1 is 12 of those conversations. If the answer is no, the beachhead cannot be tested and dies by default.
  7. Delay policy for the public tier — decided and published before the first customer. (§8 item 8.) Changing it later reads as an admission. STILL OPEN.
  8. Named human + published postal address for agency takedown requests. (§8 item 10.) Requires a real name and address; not an agent decision. STILL OPEN.
  9. Credential rotation state. Two API keys were awaiting rotation per the standing security docket. Not verifiable from this authoring machine — Firebase/GCP console only. Founding-agenda item 2. STILL OPEN.
  10. Is the production Firestore ruleset the old permissive one, or something else? (CISO, unverifiable here.) Determines whether B1 is "restore a boundary" or "confirm a boundary." Console only. STILL OPEN.
## Agenda Do we adopt `BUSINESS_MODEL.md` as the company's go-to-market — ratify as written, ratify with named amendments, or kill it — thereby deciding who pays and at what price? This is the board's first sitting. A search of `logan/server-26` (open and closed) confirms **no prior `minutes:final` issue exists**, so nothing in `BUSINESS_MODEL.md`, `SAAS_PLAN.md` or `UI_REDESIGN.md` was binding before today. --- ## Where the board agreed (stated once) All four advisers converged on **"ratify the structure, gate the revenue."** Nobody argued to kill the document and nobody argued to ratify it as written. That consensus is adopted and not re-argued below. The value of this ruling is in (a) saying precisely *what* is ratified, (b) making the gate enforceable instead of a sentiment, and (c) refusing to invent answers to owner-only questions. Three findings were reported by more than one adviser and are accepted as fact without further debate: - Firestore rules exist in source (`Server/infra/firestore/firestore.rules`, deny-by-default, scoped on `resource.data.org_id == request.auth.token.org_id`) but are **not deployed to production** (#13). The live tenant boundary is unknown, not known-bad — the distinction matters for wording, not for the gate. - `lib/billing.ts` publicly promises `retentionDays: 7/90/365` (lines 88/103/120) with **no enforcement anywhere** in `drb-c2-core`. - `BUSINESS_MODEL.md` §5.7 mitigations #1 (EMS/medical exclusion) and #2 (name redaction) — which the document itself calls "the highest-leverage single mitigation in this entire document" and "cheap" — are **not built**. --- ## The real conflicts **Conflict 0 — the board's own record is corrupt.** Issue #40, filed as the CTO draft, has a body **byte-identical to #39 (CISO)**. The CTO's actual findings never reached the record. I am not going to rule on a missing document, so I verified the CTO's substantive claims against source myself before ruling: - Per-system AI gating is **real**: `drb-c2-core/app/routers/systems.py:107-129` (`PUT /{system_id}/ai-flags`) writes a `systems.ai_flags` override; `drb-c2-core/app/routers/upload.py:270-284` consumes it via `_flag()` with the semantics "global master off beats everything; system override defaults to inherit." - But it is an `require_admin_token` **manual toggle with no link to org, plan, entitlement or billing**. There is no code path by which paying for a county turns AI on, or non-payment turns it off. - A grep of `drb-c2-core/app` for `cost_usd|token_count|usage_meter|per_call_cost|billing_usage|input_tokens|prompt_tokens` returns **zero hits**. No per-call, per-system or per-org cost accounting exists. **Consequence, and this is the single most important finding of the meeting:** `BUSINESS_MODEL.md` §0 line 5 ("Cost follows demand, not supply … `feature_flags.py` already supports per-system gating") is *half* true — the gate exists, the demand-linkage does not. And **not one dollar figure in §4 has ever been checked against a real provider bill.** §4.3's floor price of $49 and §3.4's "your cost is ~$70/node-month" are models resting on two assumptions the document's own §10 admits are unverified (node-002's real call volume; average recording length). We were one ruling away from publishing a price derived from a spreadsheet nobody has ever reconciled to an invoice. **Conflict 1 — is §8's status table trustworthy?** The COO reads §8 as the gate list and finds 7 of 10 items have no issue and no `DEFERRED.md` entry. The CISO reads §8 item 1 ("Tenant boundary … **Not started**") and correctly says the code side has substantially landed. Both are right, which means the table is stale **in both directions**: it *understates* progress on item 1 (tenancy code landed) and *overstates* remaining risk on item 5 (Gemini model IDs already migrated — `config.py:47-48`, closed via #14). **Ruled: §8's "Status" column is struck. Gitea is the status board; a prose table inside a strategy doc is not.** The *list* of ten gates survives; its status annotations do not. **Conflict 2 — how hard is the gate, and a gate on what exactly?** COO: don't ratify §7's dates. CMO: don't put a price on the site. CISO: hard gate on charging card #1. Those are three different gates being described as one. **Ruled: there are two gates, A and B, and they are separate.** See Decisions 4 and 5. **Conflict 3 — friends and family collide with the free tier, and the document does not resolve it.** The CMO is right and this is not a small point: today's free tier is full-featured and live, while §3.2's "Public" tier is $0, ≥30 min delayed, no audio, no transcripts, no names. Those are two different products wearing one price. If friends and family keep the live full-featured version for free while a Founding Operator pays $49/mo for it, there is no conversion pressure *and* the delay/redaction mitigation is decorative because it only ever covers strangers. **This changes what the product is for people already using it, so it is an owner question, not mine** — see Open. What I *can* rule, and do, is that Decision 6 (redaction + disclaimer) applies to **every** surface including free, which de-risks the collision whichever way the owner rules and preempts nothing. **Conflict 4 — the beachhead.** The CMO explicitly refuses to let the tow/collision beachhead be adopted by default silence, noting the owner did not recognise it when raised. Correct call. **Not ruled here** — see Open item 1. --- ## Decisions **1. `BUSINESS_MODEL.md` is RATIFIED IN STRUCTURE, with named amendments. It is not killed and it is not ratified as written.** Binding as of today: §0 (except line 6), §1's segment *ranking method*, §2 in full (the participation mechanic), §3.1 anchors, §3.2 tier *structure*, §3.3's *reasoning*, §4.3's floor-price discipline, §5's legal position and §5.7's mitigation ordering, and §8's gate *list*. Owner: CEO. Date: 2026-08-23, effective immediately. *Cost:* we lock in a model whose unit economics have never been reconciled to a bill. Mitigated by Decision 5's B5, which forbids acting on the numbers until they are. **2. Ratified as binding operating discipline, not to be relaxed without a new board sitting:** - **Price by covered geography, not by seat.** (§0.3) - **Contribution earns invoice credit and is never redeemable for cash.** (§0.4, §9 Q9) Going credit→cash later is easy; going cash→credit after someone has been paid is not. Ratified in the reversible direction. - **$49/mo is the absolute floor, and the same county is sold five times before a second county is added.** (§4.3) The highest-value single line in the document, and it costs nothing to adopt. - **Data/OEM pricing is never published.** (§3.2) - **Sell the incident layer, not the audio.** (§0.2) Owner: CMO (positioning), CTO (enforceability). Date: binding now. **3. §1's segment #7 (real-estate / neighbourhood-safety) is RATIFIED AS DECLINED — closed, not open for revisit without a new written legal opinion.** CISO concurred; I am making it a closed question so it stops consuming meeting time. Owner: CEO. Date: 2026-08-23. *Cost:* the largest consumer TAM on the list. Given up deliberately — it is also where every defamation and harassment vector concentrates. **4. GATE A — "PUBLISH". No price, tier name, or entitlement from §3 goes on any public surface until all three hold.** - **A1.** Every entitlement claimed on a page is either built, or carries an inline "not yet available" marker **on the same screen as the claim** — not a bottom-of-page footnote. Specifically covers retention (7/90/365), SSO/SAML, uptime SLA, and custom data residency, none of which exist. - **A2.** Every AI transcript and AI summary surface carries **"Machine-generated, unverified. Not a substitute for 911 or official dispatch."** - **A3.** Person names are redacted by default on all free and public surfaces. Owner: CMO, with CTO for implementation. Date: **2026-09-13**. **Further, and overruling the CMO in part** (see Dissent): the invented `$0/$79/custom` placeholder in `lib/billing.ts` does not survive with a footnote. It comes **off the public site**, replaced by "Pricing in development — contact us", because §3.1 of the document we just ratified already declares it superseded. A fabricated price with a disclaimer below the fold is worse than no price: it sets a false anchor, and it is exactly what a plaintiff's exhibit looks like. *Cost:* we lose the inbound self-serve pricing path. This costs nothing real — billing is a stub (#3; `ADMIN_BILLING_AUDIT.md` §2: `createCheckoutSession` always throws), so that path converts nobody today. **5. GATE B — "CHARGE". No card is charged, no invoice issued, and no Founding Operator slot is sold until ALL EIGHT hold. A checklist, not a judgement call.** | | Condition | Verified by | Owner | |---|---|---|---| | **B1** | #13 closed: `firestore.rules` **and** `firestore.indexes.json` deployed to prod, deployed ruleset ID recorded in the issue | ruleset ID pasted into #13 | Owner (WSL) | | **B2** | #4 closed: `/admin` reads org-scoped (`routers/users.py:57-70`) | issue closed w/ commit | CTO | | **B3** | §5.7 #1 EMS/medical exclusion default **ON**, and §5.7 #2 name redaction implemented | new issue below | CTO | | **B4** | Retention either enforced by a real sweep, or the claim removed from `lib/billing.ts` **and** the FAQ | new issue below | CTO | | **B5** | **7 consecutive days of real AI spend measured per call / per system / per org, reconciled against an actual provider invoice, and §4's table corrected to match** | new issue below | CTO | | **B6** | ToS, Privacy Policy and AUP published | new issue below | Owner + counsel | | **B7** | Business entity + media liability/E&O decision recorded — **yes or no**. If no, §9 Q3 hardens to full name suppression and Data/OEM is off the table entirely | recorded in this issue | Owner | | **B8** | Transcript **entity-name** accuracy measured on ≥200 sampled calls. **If below 80%, names are suppressed by default** — pre-committed now, so the measurement cannot be argued with after the fact | new issue below | Owner | Owner of the gate as a whole: CEO. Date: B2–B5 by **2026-09-30**. B1, B6, B7 and B8 are owner-blocked and get dates when the owner answers (see Open). *Cost:* first revenue moves out by at least the B5 measurement window plus the time to build metering that does not exist. That is weeks, and it is the correct trade — §4's entire cost model is currently unfalsifiable. **6. Two live-site risks are fixed independently of pricing, on the Gate A date, because they are live to any self-serve signup right now.** AI transcripts and summaries are presented as reading "like a dispatch briefing" with no "machine-generated, unverified" label anywhere, and no name redaction on public surfaces. Account creation works today (`/login` → `/signup` → real `createUserWithEmailAndPassword`), so a stranger can reach un-mitigated AI assertions naming private individuals, including EMS calls, in two clicks. **This is the most dangerous thing the board found that is *live* rather than *planned*.** Owner: CTO. Date: **2026-09-13**. **7. §7's go-to-market sequence is NOT ratified and its clock does not start today.** The COO's capacity objection is upheld: §7 assumes cold-call sales, trial hand-holding, node-operator recruiting and shipping B1–B2 run concurrently, from one person who is also support, on-call and the only committer. Four workstreams, one person, no owner column. §7 becomes schedulable when the owner answers the beachhead question and §9 Q8, and Gate A is closed. Owner: COO, to re-plan once unblocked. Date: not set — deliberately. A date on a blocked sequence is theatre. **8. §8's "Status" and "Owner" columns are struck as unreliable** (Conflict 1). As a *tracking* artefact the §8 list is replaced by Gate B above plus the Gitea issues named in it. Several §8 items are assigned to "Build" that are in fact owner-only and unbuildable by any agent (#3 ToS, #4 entity/insurance, #6 accuracy sampling, #8 delay policy, #10 takedown contact). Owner: CEO, enacted this session. **9. §9's recommended defaults are adopted as build defaults where they cost nothing and fail safe:** Q1 **B2B only for 18 months**; Q2 **exclude EMS/medical by default**; Q3 **do not publish person names**; Q6 **honour agency opt-outs proactively and publicly**; Q9 **credit never cash**. Q4 (insurance spend), Q5 (existing agency contact), Q7 (scale ambition) and Q8 (walk-ins) are **not** adopted by default — they are money, fact, or a change to what the product is. See Open. Owner: CTO for Q1/Q2/Q3/Q6 as defaults in code. Date: Q2 and Q3 ride B3 (2026-09-30). --- ## What we gave up - **Speed to first dollar.** B5 alone pushes revenue out by weeks. We are buying the ability to say our price is above our cost and mean it. - **The inbound pricing page.** Taking `$0/$79/custom` down removes a conversion surface that converts nobody today — the loss is notional but it is real optics. - **The largest consumer market, permanently**, via Decision 3. - **Optionality on contributor cash-out** (Decision 2). We can add it later; we could not have removed it later. - **The §7 clock**, which does not start today. If the owner answers the beachhead question quickly this costs days, not weeks. - **The comfort of a settled unit-economics model.** We ratified the *structure* of §4 while declaring its *numbers* unverified. That is an honest but uncomfortable position, and Decision 4 exists so nobody has to hold it in public. --- ## Dissent - **CMO, overruled in part.** Recommendation 5 offered "keep the current placeholder + its disclaimer, **or** take pricing off the public site." I take the second and close the first. Grounds: the placeholder is not merely unwired, it is *invented*, and §3.1 of the document we just ratified says so in writing. A false anchor with a below-the-fold footnote is a worse artefact than an empty page. The CMO's framework recommendation, the beachhead-needs-an-explicit-yes amendment, and the friends-and-family flag are adopted in full. - **COO, upheld but re-scoped.** Filing the 7 missing §8 items as issues is adopted (see Follow-ups). Fixing #30/#31 before any walk-in demo is adopted as fact but is **not** added to Gate B — a 404 after login blocks a demo, not a charge, and padding a revenue gate with unrelated bugs is how gates stop being believed. - **CISO, upheld in full.** No dissent. The recommendation ordering (rules first, then honest retention copy, then EMS/redaction) is preserved as B1 → B4 → B3. - **CTO — no draft was in the record** (#40 duplicated #39 byte for byte). The CTO's position was reconstructed from source by the chair and is recorded in Conflict 0. **The CTO is not bound by a reconstruction and may file a correction; if it materially contradicts Conflict 0, this ruling re-opens on that point only.** Process fix filed as a follow-up. --- ## Drafts #38 COO · #39 CISO · #40 CTO (duplicate body — see Conflict 0) · #41 CMO --- ## Follow-up issues filed Existing issues were commented on rather than duplicated: **#13** (rules undeployed → B1), **#4** (`/admin` scoping → B2), **#3** (billing mock data → Gate A), **#9** (org-owner writes), **#33** (index drift → B1), **#35** (correlation degraded). New issues are listed in the first comment on this issue, once numbers are assigned. --- ## Open — needs the owner > **Amended 2026-08-23.** The owner answered **four** of these ten. Those four are struck below; the verbatim answers and the rulings are in the **"Owner rulings, 2026-08-23"** comment on this issue. **Six remain open.** Nothing left unstruck below has been decided or defaulted. Each is money spent, a fact only the owner holds, or a change to what the product is. 1. ~~**The beachhead: tow / collision / restoration / auto-glass operators in Westchester — yes or no, on the record.**~~ → **ANSWERED 2026-08-23** — *"no real direction but sure tow is fine"*. Adopted as a **hypothesis with a kill criterion** (12 qualifying conversations; fewer than 4 trial acceptances kills it; fewer than 2 paid after Gate B kills it), **not** as ratified strategy. §0 line 6, §1's #1 pick, §3.4 and §7 are unfrozen but stamped **provisional — beachhead untested**. Owner conviction: **low, on the record.** 2. ~~**Friends and family: which tier?**~~ → **ANSWERED 2026-08-23** — *"Keep them full-featured"*. A **comped tier, distinct from §3.2 Public**, which stays the delayed/redacted public free tier. Uncapped AI spend on non-payers is the accepted cost and cannot be capped until #45 exists. Founding-agenda item 4 is closed by this. 3. ~~**Is $2–5k/yr for media liability / E&O approved before the first invoice?**~~ → **ANSWERED 2026-08-23** — *"assume it will happen but get to product mvp, feedback, then go for company things"*: **no pre-revenue spend.** **Gate B7 closes** as a recorded "not yet", and its pre-agreed consequences bind: **names suppressed by default on every surface, paid included** (this *widens* B3 and Gate A A3), and **Data/OEM stays dead**. Suppression is a display layer, never deletion. 4. **Business entity — does one exist, and in what form?** (§8 item 4.) Stripe will not activate without it. Not verifiable from this machine. **STILL OPEN** — and ruling 3 makes company formation the trigger to revisit E&O, so this now blocks two things. 5. ~~**Lifestyle/bootstrapped ($5–20k MRR) or venture-scale?**~~ → **ANSWERED 2026-08-23**, delegated to the board and ruled: **lifestyle / bootstrapped, confirmed.** One operator plus AI agents; no multi-state coverage, node-supply operation or sales function exists or is planned. §1 and §3's ratification no longer rests on an assumption. 6. **Willing to walk into ~40 local businesses in weeks 2–3?** (§9 Q8.) "No" pushes first revenue out 6+ months by the document's own reckoning — a fine answer, but it must be an answer. **STILL OPEN**, and now load-bearing: the beachhead kill criterion in ruling 1 *is* 12 of those conversations. If the answer is no, the beachhead cannot be tested and dies by default. 7. **Delay policy for the public tier — decided and published before the first customer.** (§8 item 8.) Changing it later reads as an admission. **STILL OPEN.** 8. **Named human + published postal address for agency takedown requests.** (§8 item 10.) Requires a real name and address; not an agent decision. **STILL OPEN.** 9. **Credential rotation state.** Two API keys were awaiting rotation per the standing security docket. Not verifiable from this authoring machine — Firebase/GCP console only. Founding-agenda item 2. **STILL OPEN.** 10. **Is the production Firestore ruleset the old permissive one, or something else?** (CISO, unverifiable here.) Determines whether B1 is "restore a boundary" or "confirm a boundary." Console only. **STILL OPEN.**
logan added the boardminutes:finalrole:ceo labels 2026-08-23 17:30:49 -04:00
Author
Owner

Follow-up issues filed (enacting these minutes)

New:

  • #43 - Gate B3: EMS/medical exclusion default + person-name redaction (CTO, 2026-09-30)
  • #44 - Gate B4: retention promised in lib/billing.ts, enforced nowhere (CTO, 2026-09-30)
  • #45 - Gate B5: no per-call/system/org AI cost accounting; no §4 figure ever checked against a bill (CTO, 2026-09-30)
  • #46 - Gate A: invented price + unbuilt entitlements on the public site; AI disclaimer + public-surface redaction (CMO/CTO, 2026-09-13)
  • #47 - Owner-only gates: ToS/Privacy/AUP, entity + E&O, delay policy, agency takedown contact (owner, undated pending answer)
  • #48 - Gate B8: entity-name accuracy never measured; <80% pre-commits to name suppression (owner, undated pending answer)
  • #49 - Board skill process defect: CTO draft #40 duplicated #39, losing the CTO record (COO, before next sitting)

Commented rather than duplicated (existing issues promoted into a gate): #13 (B1), #4 (B2), #3, #9, #33, #35.

Enacted this session

  • BUSINESS_MODEL.md - stamped "Ratified in structure by board minutes #42, 2026-08-23", §8 status/owner columns struck per Decision 8, §0 line 6 and §3.4 flagged unratified pending the owner.
  • .claude/skills/board/SKILL.md - founding-agenda item 1 struck through, pointing here.
  • CLAUDE.md - project-docs status row for BUSINESS_MODEL.md updated.
  • Server/drb-frontend/lib/billing.ts - the comment claiming the invented plan catalog is "real UI copy (safe to ship)" corrected; it is the exact line that would mislead the next contributor into shipping it. The catalog itself is #46's work.
  • DEFERRED.md - Gate A / Gate B recorded so it cannot drift from the issues.

This issue stays open until Gates A and B are closed or re-filed as tracked work.

## Follow-up issues filed (enacting these minutes) **New:** - **#43** - Gate B3: EMS/medical exclusion default + person-name redaction (CTO, 2026-09-30) - **#44** - Gate B4: retention promised in `lib/billing.ts`, enforced nowhere (CTO, 2026-09-30) - **#45** - Gate B5: no per-call/system/org AI cost accounting; no §4 figure ever checked against a bill (CTO, 2026-09-30) - **#46** - Gate A: invented price + unbuilt entitlements on the public site; AI disclaimer + public-surface redaction (CMO/CTO, 2026-09-13) - **#47** - Owner-only gates: ToS/Privacy/AUP, entity + E&O, delay policy, agency takedown contact (owner, undated pending answer) - **#48** - Gate B8: entity-name accuracy never measured; <80% pre-commits to name suppression (owner, undated pending answer) - **#49** - Board skill process defect: CTO draft #40 duplicated #39, losing the CTO record (COO, before next sitting) **Commented rather than duplicated** (existing issues promoted into a gate): **#13** (B1), **#4** (B2), **#3**, **#9**, **#33**, **#35**. ## Enacted this session - `BUSINESS_MODEL.md` - stamped "Ratified in structure by board minutes #42, 2026-08-23", §8 status/owner columns struck per Decision 8, §0 line 6 and §3.4 flagged unratified pending the owner. - `.claude/skills/board/SKILL.md` - founding-agenda item 1 struck through, pointing here. - `CLAUDE.md` - project-docs status row for `BUSINESS_MODEL.md` updated. - `Server/drb-frontend/lib/billing.ts` - the comment claiming the invented plan catalog is "real UI copy (safe to ship)" corrected; it is the exact line that would mislead the next contributor into shipping it. The catalog itself is #46's work. - `DEFERRED.md` - Gate A / Gate B recorded so it cannot drift from the issues. **This issue stays open until Gates A and B are closed or re-filed as tracked work.**
Author
Owner

Owner rulings, 2026-08-23

The owner answered four of the ten Open - needs the owner items. Below is each answer verbatim plus the chair's ruling, so a later meeting can see the conviction level behind each. The Open section of this issue has been amended: these four are struck, six remain visible.


1. Beachhead (Open item 1) - ADOPTED AS A HYPOTHESIS, NOT AS RATIFIED STRATEGY

Owner, verbatim: "no real direction but sure tow is fine"

Ruling. Tow / collision / restoration / auto-glass in Westchester is adopted as the working beachhead with a kill criterion. It is not ratified strategy. Owner conviction is low and that is deliberately on the record - "sure, fine" is not a conviction and nobody should later cite this as one.

Consequently section 0 line 6, section 1's #1 pick, section 3.4 and section 7 are UNFROZEN - they may be planned and built against - but each is stamped "provisional - beachhead untested". Section 1's ranking is a hypothesis order, not a finding.

Kill criterion - deliberately small enough for one person to actually do:

Stage Test Killed if
1 - pre-revenue, doable now 12 qualifying conversations in 30 days with Westchester tow / collision / restoration / auto-glass operators. Qualifying = spoke to the owner or whoever dispatches, and showed them last night's real map, not a demo Fewer than 4 of the 12 accept a trial slot or ask to be contacted when it is ready
2 - after Gate B closes Of those who accepted, convert to paid Founding Operators within 60 days Fewer than 2 paid

Failing either stage kills the beachhead and re-ranks section 1 to segment #2 (private security / campus / hospital safety) without another board sitting. Passing stage 1 does not ratify section 7's dates - Decision 7 of these minutes stands.

Stage 1 gets no start date until Gate A closes (#46): walking into 12 businesses while the public site still shows an invented price is worse than not walking in.

Owner: CMO builds and runs the list; CEO calls the kill.

Cost: we spend the next planning cycle building toward a segment nobody has validated, on the strength of a shrug. Exposure is bounded to 12 conversations by the criterion above.


2. Friends and family (Open item 2) - COMPED TIER, FULL FEATURED

Owner, verbatim: "Keep them full-featured"

Ruling. Friends and family become a comped tier, distinct from section 3.2 "Public". They keep today's product: live, undelayed, full-featured. Section 3.2 Public ($0 / no account / >=30 min delay / no audio / no transcripts / no names) remains the public, unauthenticated free tier. Two different tiers with two different purposes, and section 3.2 is amended to say so rather than continuing to describe two products at one price.

One carve-out: name suppression (ruling 3) applies to the comped tier too. It is a platform-wide policy layer, not a tier entitlement, so "full-featured" does not mean "named".

Conflict 3 of these minutes is resolved in the owner's direction. The conversion-pressure objection is accepted as a known cost, not fixed: a friend on the live full product for $0 will sit beside a Founding Operator paying $49/mo for the same thing.

Consequence, raised by both the COO and the CTO: a comped tier is uncapped AI spend on non-paying accounts, and it cannot be capped - or even measured - until per-org cost attribution exists (#45). That dependency is now filed as its own issue rather than left in prose.

Owner: CEO for the tier definition, CTO for the entitlement flag and the eventual cap.

Cost: zero conversion pressure on exactly the people most likely to give honest feedback, plus an unmetered cost line that grows with generosity. Accepted knowingly.


3. E&O insurance (Open item 3 / Gate B7) - NO PRE-REVENUE SPEND

Owner, verbatim: "assume it will happen but get to product mvp, feedback, then go for company things"

Ruling. No E&O spend before revenue. Gate B7 is SATISFIED as a recorded decision - the recorded answer is "not yet, revisit at company formation" - and the consequences pre-agreed in B7 and section 9 Q4 bind immediately:

  • Person names are SUPPRESSED BY DEFAULT on every surface - public, comped and paid - until a policy is actually bound.
  • The Data / OEM segment stays dead. Not sold, not quoted, not published.
  • Suppression is a display and policy layer, never deletion. intelligence.py keeps extracting and storing entities; the render, export and API paths suppress them. Building this as data deletion would turn a reversible decision into an irreversible one, and this decision is explicitly meant to be reversed the day a policy is bound. Binding implementation constraint on #43.

Gate B interaction, stated explicitly because the question was asked: this TIGHTENS the gate, it does not loosen it.

Condition Effect of this ruling
B7 Closes. The decision is recorded, which is all B7 ever required
B3 (#43) Widened. Redaction was "free and public surfaces"; it is now all surfaces, paid included. More work, not less
Gate A A3 (#46) Widened the same way
B8 (#48) Stays in the gate. Its remit changes: the 200-call measurement can no longer decide whether names are published, because they are suppressed regardless. It now quantifies accuracy for the machine-generated disclaimer, for future underwriting, and to establish whether names could ever be reinstated

Revisit trigger: company formation (Open item 4, still open).

Owner: CTO for suppression-by-default; the owner for the policy at company formation.

Cost: the product is materially less useful than it could be. "Who was on scene" is a real part of the value and we are turning it off for everyone, including people who pay. That is the correct trade against an uninsured defamation claim, and it is the second time this board has chosen to be less useful rather than uninsured.


4. Scale (Open item 5) - LIFESTYLE, CONFIRMED

Owner, verbatim: "i'm building this for friends and fam, i think it can also be sold, it will mainly be AI driven, you tell me"

The owner delegated this to the board, so the board rules it. Lifestyle / bootstrapped, confirmed. Section 9 Q7's assumed default is now a decision.

Reasoning, recorded so a later meeting can check it rather than re-derive it: venture scale would require multi-state coverage, a node-supply operation and a sales function. None of the three exists and none is planned, and one operator plus AI agents does not produce them. Per-county pricing, a single-county beachhead and the $49 floor are the right shape for a lifestyle business and the wrong shape for a venture one.

Therefore section 1 and section 3's ratification (Decision 1) stands as filed - it no longer rests on an unconfirmed assumption, which is the whole reason this was flagged.

"Mainly AI-driven" is an operating model, not a scale ambition, and does not change the ruling. It does raise the stakes on #45: in an AI-driven one-person business the AI bill is the cost structure, so the absence of per-call cost accounting is the single largest unknown in the company.

Owner: CEO. Settled 2026-08-23.

Cost: segment 6 (insurance / risk analysts) and any national play are off the table for the foreseeable future. Any future decision to raise money re-opens sections 1 and 3 in full.


Enacted this session

  • BUSINESS_MODEL.md - stamp updated to point here; section 0 line 6 / section 1 / section 3.4 unfrozen as provisional with the kill criterion inline; section 3.2 split into Public vs Comped; names-suppressed-until-E&O recorded in section 5.7 and section 9 Q3/Q4; section 9 Q7 recorded as decided - lifestyle.
  • .claude/skills/board/SKILL.md - founding-agenda items 4 (free tier) and 5 (beachhead) struck, pointing here. Items 2 (credential rotation) and 3 (sellable milestone) remain the standing queue.
  • CLAUDE.md - BUSINESS_MODEL.md status row updated.
  • #43 and #48 commented with their tightened scope; new issue filed for uncapped comped-tier spend.
## Owner rulings, 2026-08-23 The owner answered four of the ten **Open - needs the owner** items. Below is each answer **verbatim** plus the chair's ruling, so a later meeting can see the conviction level behind each. The Open section of this issue has been amended: these four are struck, six remain visible. --- ### 1. Beachhead (Open item 1) - ADOPTED AS A HYPOTHESIS, NOT AS RATIFIED STRATEGY > Owner, verbatim: *"no real direction but sure tow is fine"* **Ruling.** Tow / collision / restoration / auto-glass in Westchester is adopted as the working beachhead **with a kill criterion**. It is not ratified strategy. Owner conviction is low and that is deliberately on the record - "sure, fine" is not a conviction and nobody should later cite this as one. Consequently **section 0 line 6, section 1's #1 pick, section 3.4 and section 7 are UNFROZEN** - they may be planned and built against - but each is stamped **"provisional - beachhead untested"**. Section 1's ranking is a hypothesis order, not a finding. **Kill criterion - deliberately small enough for one person to actually do:** | Stage | Test | Killed if | |---|---|---| | **1 - pre-revenue, doable now** | **12 qualifying conversations in 30 days** with Westchester tow / collision / restoration / auto-glass operators. Qualifying = spoke to the owner or whoever dispatches, and showed them last night's real map, not a demo | **Fewer than 4 of the 12** accept a trial slot or ask to be contacted when it is ready | | **2 - after Gate B closes** | Of those who accepted, convert to paid Founding Operators within 60 days | **Fewer than 2 paid** | Failing either stage kills the beachhead and re-ranks section 1 to segment #2 (private security / campus / hospital safety) **without another board sitting**. Passing stage 1 does *not* ratify section 7's dates - Decision 7 of these minutes stands. Stage 1 gets no start date until **Gate A closes (#46)**: walking into 12 businesses while the public site still shows an invented price is worse than not walking in. Owner: **CMO** builds and runs the list; **CEO** calls the kill. *Cost:* we spend the next planning cycle building toward a segment nobody has validated, on the strength of a shrug. Exposure is bounded to 12 conversations by the criterion above. --- ### 2. Friends and family (Open item 2) - COMPED TIER, FULL FEATURED > Owner, verbatim: *"Keep them full-featured"* **Ruling.** Friends and family become a **comped tier, distinct from section 3.2 "Public"**. They keep today's product: live, undelayed, full-featured. Section 3.2 Public ($0 / no account / >=30 min delay / no audio / no transcripts / no names) remains the **public, unauthenticated** free tier. Two different tiers with two different purposes, and **section 3.2 is amended to say so** rather than continuing to describe two products at one price. One carve-out: name suppression (ruling 3) applies to the comped tier too. It is a platform-wide policy layer, not a tier entitlement, so "full-featured" does not mean "named". Conflict 3 of these minutes is resolved in the owner's direction. The conversion-pressure objection is **accepted as a known cost, not fixed**: a friend on the live full product for $0 will sit beside a Founding Operator paying $49/mo for the same thing. **Consequence, raised by both the COO and the CTO:** a comped tier is **uncapped AI spend on non-paying accounts**, and it cannot be capped - or even measured - until per-org cost attribution exists (**#45**). That dependency is now filed as its own issue rather than left in prose. Owner: **CEO** for the tier definition, **CTO** for the entitlement flag and the eventual cap. *Cost:* zero conversion pressure on exactly the people most likely to give honest feedback, plus an unmetered cost line that grows with generosity. Accepted knowingly. --- ### 3. E&O insurance (Open item 3 / Gate B7) - NO PRE-REVENUE SPEND > Owner, verbatim: *"assume it will happen but get to product mvp, feedback, then go for company things"* **Ruling.** No E&O spend before revenue. **Gate B7 is SATISFIED as a recorded decision** - the recorded answer is "not yet, revisit at company formation" - and the consequences pre-agreed in B7 and section 9 Q4 bind immediately: - **Person names are SUPPRESSED BY DEFAULT on every surface** - public, comped **and paid** - until a policy is actually bound. - **The Data / OEM segment stays dead.** Not sold, not quoted, not published. - **Suppression is a display and policy layer, never deletion.** `intelligence.py` keeps extracting and storing entities; the render, export and API paths suppress them. Building this as data deletion would turn a reversible decision into an irreversible one, and this decision is explicitly meant to be reversed the day a policy is bound. **Binding implementation constraint on #43.** **Gate B interaction, stated explicitly because the question was asked: this TIGHTENS the gate, it does not loosen it.** | Condition | Effect of this ruling | |---|---| | **B7** | **Closes.** The decision is recorded, which is all B7 ever required | | **B3** (#43) | **Widened.** Redaction was "free and public surfaces"; it is now **all surfaces, paid included**. More work, not less | | **Gate A A3** (#46) | **Widened** the same way | | **B8** (#48) | **Stays in the gate.** Its remit changes: the 200-call measurement can no longer *decide* whether names are published, because they are suppressed regardless. It now quantifies accuracy for the machine-generated disclaimer, for future underwriting, and to establish whether names could ever be reinstated | Revisit trigger: **company formation** (Open item 4, still open). Owner: **CTO** for suppression-by-default; **the owner** for the policy at company formation. *Cost:* the product is materially less useful than it could be. "Who was on scene" is a real part of the value and we are turning it off for everyone, including people who pay. That is the correct trade against an uninsured defamation claim, and it is the second time this board has chosen to be less useful rather than uninsured. --- ### 4. Scale (Open item 5) - LIFESTYLE, CONFIRMED > Owner, verbatim: *"i'm building this for friends and fam, i think it can also be sold, it will mainly be AI driven, you tell me"* The owner delegated this to the board, so the board rules it. **Lifestyle / bootstrapped, confirmed. Section 9 Q7's assumed default is now a decision.** Reasoning, recorded so a later meeting can check it rather than re-derive it: venture scale would require multi-state coverage, a node-supply operation and a sales function. **None of the three exists and none is planned**, and one operator plus AI agents does not produce them. Per-county pricing, a single-county beachhead and the $49 floor are the right shape for a lifestyle business and the wrong shape for a venture one. **Therefore section 1 and section 3's ratification (Decision 1) stands as filed** - it no longer rests on an unconfirmed assumption, which is the whole reason this was flagged. "Mainly AI-driven" is an **operating model, not a scale ambition**, and does not change the ruling. It does raise the stakes on **#45**: in an AI-driven one-person business the AI bill *is* the cost structure, so the absence of per-call cost accounting is the single largest unknown in the company. Owner: **CEO.** Settled 2026-08-23. *Cost:* segment 6 (insurance / risk analysts) and any national play are off the table for the foreseeable future. Any future decision to raise money re-opens sections 1 and 3 in full. --- ### Enacted this session - **`BUSINESS_MODEL.md`** - stamp updated to point here; section 0 line 6 / section 1 / section 3.4 unfrozen as *provisional* with the kill criterion inline; section 3.2 split into **Public** vs **Comped**; names-suppressed-until-E&O recorded in section 5.7 and section 9 Q3/Q4; section 9 Q7 recorded as **decided - lifestyle**. - **`.claude/skills/board/SKILL.md`** - founding-agenda items **4 (free tier)** and **5 (beachhead)** struck, pointing here. Items **2 (credential rotation)** and **3 (sellable milestone)** remain the standing queue. - **`CLAUDE.md`** - `BUSINESS_MODEL.md` status row updated. - **#43** and **#48** commented with their tightened scope; new issue filed for uncapped comped-tier spend.
Author
Owner

Cross-reference: the weekly dev-progress cadence and the new non-officer project-lead role were ruled on separately in #53 (Board 2026-08-23 — Operating cadence — FINAL MINUTES). Filed as its own minutes rather than an addendum here because sprint-start anchors the 7-day cadence check to the date of the newest minutes:final.

Cross-reference: the weekly dev-progress cadence and the new non-officer `project-lead` role were ruled on separately in **#53** (Board 2026-08-23 — Operating cadence — FINAL MINUTES). Filed as its own minutes rather than an addendum here because `sprint-start` anchors the 7-day cadence check to the date of the newest `minutes:final`.
Author
Owner

Closing per #146 D8 (2026-09-13): a minutes:final issue is not a tracker. The record of a ratified decision is the stamp on the document; live work is tracked by its own work issue. Six minutes:final issues had been open 8-21 days with unexecuted decisions inside them and nobody looking.

BUSINESS_MODEL.md is ratified in structure and the file carries the stamp — that stamp is the record, not this issue. Live items moved on: #43 (E&O / name suppression, Gate A), #50 (comped-tier AI spend, blocked on #45), #67 (credential rotation, founding-agenda item 2, standing header item). Gate A and Gate B stand unchanged.

Closing per **#146 D8** (2026-09-13): *a `minutes:final` issue is not a tracker.* The record of a ratified decision is the stamp on the document; live work is tracked by its own work issue. Six minutes:final issues had been open 8-21 days with unexecuted decisions inside them and nobody looking. BUSINESS_MODEL.md is ratified in structure and the file carries the stamp — that stamp is the record, not this issue. Live items moved on: **#43** (E&O / name suppression, Gate A), **#50** (comped-tier AI spend, blocked on #45), **#67** (credential rotation, founding-agenda item 2, standing header item). Gate A and Gate B stand unchanged.
logan closed this issue 2026-09-13 18:52:09 -04:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: logan/server-26#42