documents, one console, one operator. read the notice on page 00 before first use.
00 notice ·01 the timetable ·02 controls ·03 the pages ·04 faults ·05 care
model tt-7.5 · booklet rev 1 · sep 2026 · no batteries, no build step
this booklet documents the live site. if the site changed, the booklet is wrong, not the site.
documents
16
grid cells
45
instruments
5
live feeds
2
flight rules
8
functions
3
00
before first use
the precautions page. read once, then never again.
tt is a single-operator command centre, not a product and not a client surface. fifteen hand-authored static documents on a cdn. no framework, no router, no build step. you edit html and push. that is the whole machine, and every rule below exists because the machine is that plain.
important · two content systems
the site looks like one thing and is two. the sub-task lock cards hydrate live from notion through /api/tasks, so you change them by editing notion, not the html. the timetable grid is a hardcoded calendar skeleton of 45 cells and it is hand-edited every week. editing the wrong one is the single most common mistake on this site: notion edits will not move a shift, and html edits to a lock card get overwritten on the next fetch.
do notdo not rewrite the grid markup. the 45 data-cell blocks are bespoke hand-authored layout, not generated. a careless reflow breaks the week. do not hardcode secrets into the html: the notion token and the hunt key live in doppler and reach the site as netlify env at deploy time. do not put a green on a dead feed: when the orbit feed is unreachable the gauges say so and stay amber. that is deliberate.
note · reading status
status on this site never rests on colour alone. every pill carries its word: activehand-setlocked. if you cannot read a state in greyscale, that is a bug in the page, not in your eyes.
shippers. // the manualpage 00
contents
fifteen documents · redirects live in netlify.toml
one week, hand-coded, monday to saturday, cross-cut with what each venture owes. everything else on the site is a document you read once. this is the one you drive.
fig. 01 · the main screen, top to bottom
1eco-nav. three spectral marks, top left. cortex, ecosystem map, how to operate. the third one hides the wheel.
2the north star. money outside the salaried floor, per month. three gates, one a month. whichever gate is next owns the week.
3the grid. 45 cells, hand-edited weekly. the legend at its foot names every block colour.
4the instruments. five readouts. two measured, three hand-set, and each says which it is.
5the flight rules. eight pre-commitments, written in daylight, fired on edges.
6the locks. seven venture cards. what is next, per venture, from notion.
7the climb. saved and made against £100k. editable in place, stored in your browser.
8the wheel. five field notes fanned out of the operate mark.
note · the week is hand-set
the grid is a fixed calendar skeleton. it does not know what day it is and it will not update itself. rebuild it at the top of each week, keep the salaried cells intact, and put venture work only where the flight rules allow it.
shippers. // the timetablepage 01
02
the controls
every input the site answers to. the rest is reading.
fig. 02 · the control layout
hover the operate mark
the wheel fans out. five field notes: agent and harness engineering, the production stack, leverage, the engine room, open source. on touch the first tap opens the wheel, the second navigates, a tap outside closes it.
click any swipe link
the veil closes over the page and reopens on the next one. holding cmd, ctrl or shift bypasses it and opens normally, and it is skipped entirely when the system asks for reduced motion.
click edit on the climb
opens the climb dialog. two fields, saved and made, against a £100,000 target. the bar and the percentage repaint on save.
the quick-add buttons
add to the field without typing. they increment the input, they do not save. you still have to press save.
esc · or click the backdrop
closes the climb dialog without saving. cancel does the same thing.
save
writes to your browser, not to the repo. three keys: hk_saved, hk_made, hk_seed_v. another device shows the seeded numbers until you edit them there too.
the eco-nav marks
the three doors off the timetable. the cortex, the ecosystem map, how to operate.
nothing at all
the instruments fetch on load. fleet and demand call the orbit feed once, with caching off. there is no refresh button: reload the page.
important · the seed rule
the climb ships with seeded numbers and a seed version. if you change the seeded figures in the html you must bump the seed version with them, or every browser that already stored the old pair keeps painting it and your edit looks like it did nothing. that exact failure hid a corrected figure for eight weeks.
shippers. // the controlspage 02
03
the instruments and the flight rules
what the console measures, and what it has already decided
five readouts sit under the grid. only two of them measure anything. the other three are typed in by hand and the page says so in its own readout, because a hand-set number wearing a live badge is how a dashboard starts lying.
fleet
live · reads /api/orbit · the oracle worker computes it · falls to amber if the feed is unreachable
measured
demand
live · reads /api/orbit · sends, replies, the queue · an empty queue reads amber, not green
measured
fuel line
hand-set · the balance owed and the handover date · the bank is the oracle, never the inbox
hand-set
throughput
hand-set · one ship a day across the fleet, any bucket, agents count
hand-set
gates
hand-set · which of the three north-star gates is currently open
hand-set
the eight flight rules · decided in daylight
fogged on what to do
north star. whichever gate is next owns the block.
on a shift
no building. read the oracle mail at lunch, close it.
home from a 12 to 8
nothing. tuesday 16:15 is the ship, not tonight.
stuck on a build
skills folder, then arsenal, then code.
agent gone quiet
query engine_control, read updated_by. an agent can pause an agent.
no leads this week
friday p3 is enrichment, not copy. sourcing is the constraint.
a subscription figure drops
check for a declined charge before calling it a saving.
everything at once
open timetable, do the next block, close it.
these are pre-commitments, not panic buttons. they fire on edges only, so nothing gets decided in fog and nothing gets decided at 21:00 after a shift.
the answer to "what is this studio, actually". four buckets, four levels of trust, and the climb to £100k. read it when the shape of the thing has gone blurry, not when you need to know what to do today.
where you actually stand
the honest position, first thing, before the model.
four buckets, one studio
builds (client work, the engine) · software (skills, agents) · kits (packaged, skus) · the flagship (the long game).
four levels, trust compounds up
the ladder a venture climbs before it is allowed to carry weight.
build once, ship it ten times
the leverage argument, stated as the studio's own rule.
the climb to £100k
the same target the timetable's climb widget counts against.
map · manual · timetable
the three-surface model. this booklet is the manual leg of it.
click the moves line
cycles to another one at random. the only control on the page, and it is there to be read, not operated.
the section links
scroll smoothly rather than jumping, so the map keeps its sense of place.
notethis page is a document, not a dashboard. nothing on it fetches, so no number here can go stale in the way a gauge can. if a figure here disagrees with the timetable, the timetable is the newer one.
the oldest of the operating documents and still the one that answers "where does this piece of work go". six sections, each a rule rather than a description.
everything gets routed once
the routing rule. an inbound thing lands in exactly one bay and is not re-litigated.
four bays off one spine
the bays, and what each is allowed to hold.
fleet telemetry, not founder checkboxes
why the console measures the fleet rather than counting your tasks.
the operator stands at the gates
the job description. gates, not throughput.
one job each
one responsibility per surface, per agent, per page.
three lamps, never conflated
the three signal lamps and the discipline of not merging them into one green.
important · this page is datedit still carries the older display typeface that the estate has since retired. the rules on it are current, the styling is not. treat it as a source for routing, not as a styling reference for anything new.
a force-directed map of what the swarm remembers. two layers in one graph: the file-backed half, generated from the agent memory files and their links, and a hand-curated human half (faith, goals, patterns, growth) that has no source file and is authored straight into the page.
// five projections, keys 1 to 5 1 strata · class as altitude, system above and human below ·2 domains · one cluster per class, hubs raised ·3 constellation · a live force field, position is relationship ·4 chronology · by file date ·5 mass · volume against connectedness
1 to 5
morphs the field into that projection. the same memories, re-laid. the readout under the title names the one you are in and what its axes mean.
click a node
opens the inspector and dims everything more than three hops away, so the one memory and its neighbourhood stand out of the field.
shift-click a node
arms a trace from it. the readout changes to tracing from here · shift-click the destination. shift-click a second node and a signal travels the path between them, hop by hop.
t
arms the trace from whichever node is already selected, without going back to the mouse.
esc
clears the trace if one is armed, otherwise closes the inspector. one key, two jobs, in that order.
/ · then type
jumps to the search and filters the field. esc leaves the box. searching fresh is the fastest way to see what the swarm learnt since the last sync.
0
returns the camera to the current projection's own angle, for when you have orbited somewhere useless.
drag · scroll
orbits and zooms the volume. in constellation only, dragging a node moves the node rather than the camera, because that is the one projection where position is meaningful.
the thin rings
a node ringed in its class colour is new since the last sync. no ring is not a problem, it is just older.
important · half of it is generatedregenerate the file-backed half with the sync script. it re-parses every memory file, carries the hand-curated human layer and its edges over, drops nodes whose file is gone, and rings whatever is new. the human layer has nothing on disk to regenerate from, so it must be hand-edited. copy the page into the archive before you regenerate.
every recurring charge, what it costs a month, and a verdict on each. the page is the reference implementation of this whole visual grammar: the panels, pills and rows in this booklet were lifted from it.
the ring and the legend
spend split by category. hovering a legend row lifts it.
the roster rows
each service with its category swatch, its cost, and a state: activeflaggedkilled.
the cut list
each candidate with a verdict, the reasoning, the action, and what it saves. the verdicts are worded, not just coloured.
the ledger
a dated trail of what was actually cancelled, so a saving can be proved rather than claimed.
needs a call · yes / no
the only buttons on the page. a row the audit could not settle asks a question. yes marks it active, no marks it killed, and every total on the page repaints against your answer.
data source
reads /api/subs, which serves the audit file. if that call fails the page falls back to the seed embedded in it and flags that it did.
important · answers are not savedthe review buttons change the page in front of you and nothing else. there is no write back to the audit file. reload and every question is asked again. treat an answer as a what-if you are reading, not a decision you have recorded, and put the real one in the data file.
note · the declined-charge trapa figure dropping is not the same as a saving. check for a declined charge before you bank it, which is why that is one of the eight flight rules.
the technical floor under the studio: languages, runtimes, where things execute and who fetches their parts. eight sections, ending in a glossary.
dispatch heavily, read fluently
the operating posture: you do not need to write every language, you need to read all of them.
one language, three dialects
the javascript family, told apart.
where the code runs
runtimes and package managers, and who fetches what.
three engines, three architectures
the three shapes the estate's services take.
from source to artefact
the build path, end to end.
the pipeline is the product
why the pipeline gets the same care as the thing it ships.
the operator codes through a harness
the harness argument, in its short form.
the terms, at a glance
the glossary. the fastest page on the site for looking one word up.
shippers. // the engine roompage 08
09
the field notes
five documents on the operate wheel · read once, cite often
these are the long-form arguments. they do not change week to week and nothing on them fetches. they are reached from the wheel behind the operate mark, not from the strip.
rev 3 · the score is the model times the harness · a harness is everything you own around a model you rent · ten sections, ending on the rule that shift days are not build days
nine strata · the machine · python · javascript · typescript · the web · shell and git · containers · data and infra · the interview · runnable code samples throughout
the moves · the trail · what gets published and what stays in the house
current
loop engineering
superseded · no file any more, a 301 in netlify.toml sends it to agent and harness engineering · rev 2 is kept verbatim in the archive
redirect
notethe wheel carries six, the manual is the sixth. the dead basics is linked from the body of the timetable rather than the wheel, so if you are hunting for it and the wheel looks short, that is why.
shippers. // field notespage 09
10
the hunt · gated
the-hunt.html · private · 404 to everyone else
the role-hunt board: a target stack with a fit score, status tracked per role, and two hunt windows a week. it is no longer public. it was served openly for a while, and it names things that should not sit on an unauthenticated url, so it now runs behind an edge gate.
the gate
fails closed in every branch. no key configured, a bad key, a thrown error or no cookie all return the same 404 a stranger gets. a 404 rather than a 401 on purpose: a 401 confirms the page exists.
unlocking it
one visit with the key as a query parameter sets a long-lived cookie and redirects to the clean url, so the key never sits in history or leaks through a referer. the key lives in doppler and netlify env only. never put it in a link on a page.
the fit gate
roles are scored and the working threshold is 60. below it, it is not a target.
status per role
kept in your browser under one key per role. it is per-device: the board looks untouched on a machine you have not used.
the windows
two blocks a week. outside them the board is closed, which is the point of it being a board rather than an inbox.
importantthe older copies in the archive stay blocked by a blunt 404 rule, deliberately. a local file permission change does nothing once the cdn has published the file: the block has to live in the site config or the edge function, never on your disk.
shippers. // the huntpage 10
11
the changelogs and the archive
what the studio shipped, and every page it used to be
the changelogs
two dated editions · the later one, taste written down, is the one worth reading twice
kept
the archive
pre-change copies of every rebuilt page · timetable versions, the old cortex, the old bleed, the retired field note, the six-licence manual this booklet replaced
rule
the archive rulecopy the old page into the archive before you rebuild it. not sometimes. the archive is how a rebuild stays reversible on a site with no build step and no component library to diff against.
shippers. // archivepage 11
12
faults and what they mean
the troubleshooting leaf. symptom, cause, what to do.
a lock card says source stale
working as designed. a card only hydrates if its notion rows were touched in the last three days. older than that and the page keeps its static fallback and tells you so. fix it in notion, not in the html, and keep the static fallback honest while you are there.
a lock card says static
that card is not covered by the fetch at all. it is marked rather than silently stamped live, which is the whole point: a blanket green is how a dead per-card fetch goes unnoticed for a month.
orbit feed unreachable
the fleet and demand gauges could not reach the worker. they go amber and say so. this is not a green and must never be read as one. check the worker, then the proxy target.
the climb shows old numbers
your browser has stored values from an earlier seed. either edit them in the dialog on that device, or bump the seed version in the page so every browser takes the new pair once.
the hunt returns 404
that is the gate doing its job. unlock once with the key from doppler. every response carries a gate header, so you can prove from outside that the gate ran rather than a redirect rule having shadowed it.
the oracle page is blank
the console is the worker, proxied at /oracle. if the worker was renamed and the proxy was not, every deploy lands on a worker nothing routes to. the proxy targets and the worker config must always name the same worker. that mismatch went unnoticed for eleven days once.
an edit did not reach the site
env vars are injected at deploy time, not read at request time. set the secret first, push second. pushing first means a live deploy running without it.
the grid looks broken after an edit
the layout is hand-authored markup, so a careless reflow of the cells breaks the week. revert to the archived copy and redo the edit cell by cell.
shippers. // faultspage 12
13
care of the machine
deploying, editing, and the things that will bite
to deploy
push to main. the cdn publishes the repo root. there is nothing to compile and no artefact to build.
to preview locally
run the cdn's dev server so the functions and the synced env come with it. opening the html file directly gives you the page without its feeds.
secrets
doppler only. the notion token and the hunt key are never in the repo and never in the html.
the moving parts
two functions and one edge function: the notion hydration behind /api/tasks, the audit feed behind /api/subs, and the gate in front of the hunt. two proxies point at the oracle worker.
the canonical host
one host serves this site. the old cdn subdomain is redirected permanently so it cannot serve a stale parallel copy.
before a rebuild
copy the page into the archive. then rebuild.
on a phone
the timetable drops its blur on small screens and paints flat fills instead, so the grid scrolls at speed rather than repainting the whole viewport each frame. keep it that way: the effect earns its cost on one modal, not on 45 cells.
when in doubt
the site is fifteen files and a config. read the file.
shippers. // carepage 13
14
the index of terms
the words this console uses that mean something specific
the grid the 45-cell week. hardcoded, hand-edited, not generated.
a block one cell of the week. a period on a day, with a venture colour.
the north star money outside the salaried floor, per month.
a gate one month's single objective. whichever is next owns the week.
an instrument one of five readouts under the grid. two measured, three hand-set.
hand-set typed in by a human. always labelled, never dressed as live.
a flight rule a pre-commitment made in daylight, fired on an edge.
a lock card a venture's next task, hydrated from notion.
source stale the notion rows behind a card are older than the freshness window.
the climb saved and made against £100,000, stored per browser.
the wheel the five field notes fanned out of the operate mark.
the veil the page transition. bypassed by a modifier key and by reduced motion.
the cortex the memory map. half generated, half hand-authored.
the bleed the subscription audit and its cut list.
the oracle the worker that computes the fleet and demand readings.
a field note a long-form argument. static, cited, rarely changed.
the archive a copy of every page as it was before its last rebuild.
fails closed a guard whose default answer is no. the only kind worth having.
everything built across the ventures, laid out like a console trophy list. one profile card, a games row that jumps to each venture, and one ledger per venture. reached from the last mark on the top row.
the tiers
platinum is live with people on it, gold is live, silver shipped inside the studio, bronze got built then parked, locked is still on the bench. tier is a word tag plus a ring style; colour is never the only cue.
+ breakdown
every row opens its receipt: first commit, last touched, commit count, stack, live url. no git means the row says so.
the tally
hand-written numbers above hand-written rows. move a row by editing its class and update the counts; the page carries no script that recounts.
what it is not
not on the marketing site. it lived at shippersstudio.io/record for one night and was moved here on 14 sep 2026; the studio site now 404s that path.
shippers. // the recordpage 15
15
the breakdown
forty seconds over real captures · six beats · narrated
01 the grid ·02 the north star ·03 the instruments ·04 flight rules ·05 the field notes ·06 the close
// the opening lines tt dot shippers studio. the timetable. one week, hand-coded, monday to saturday. the shift cells are locked. on a shift you read the fleet, you don't build. under the grid, the north star. money outside the floor, per month. three gates, one a month. whichever gate is next owns the week.
shippers. // the filmpage 16
the console does not decide anything. it holds the decisions you already made, in daylight, and shows them to you at 21:00 when you would rather make new ones. that is the whole product.
// one last thing on the cortex, type aperture into the search. the whole field stops being a graph and becomes the mark. type anything else and it goes back to work.