From "I want to build a journey" to "it's live on CMS UAT."
One pipe. Four human gates. Nothing reaches the shelf that didn't come through -
and everything that came through is on the record.
G-AG-BG-CG-PUB
an idea + a deckthe shelf
chapter 1 · why
Why a machine? Why not just go make it at the CMS?
1
The CMS is a shelf, not a studio. It stores journeys; it cannot check one.
Nothing in it knows the law - the voice caps, the gate order, the coverage a storyboard
owes a learner, or which of its own assets already exist. A journey uploaded straight to it
is a journey nobody proved.
2
Building a journey is a lawful act. Twenty-five journey rules, per-applet gate
ladders, four human sign-offs. Enforcing that by memory and goodwill fails quietly;
enforcing it by machinery fails loudly, immediately, and before the learner ever sees it.
3
One unwitnessed upload undoes the shelf for everyone. A duplicate sim, a re-uploaded
video, a half-published module - the CMS cannot tell you which hand did it or why.
The machine can, because every hand goes through it.
for creators - leverage, not bureaucracy
The law arrives fresh in your seat - fetched from the last green publish, never from memory.
Normalize, gates, walks - agents you spawn at your own seat. Your deck becomes numbered slides; your journey runs on your own harness; the studio checks the arithmetic.
check_rules tells you first - before a human reviewer has to.
Every staged applet is playable and editable in the browser - the journey page's applet panel opens hosted review-edit on the staged bytes; a save is a ledgered staging, and an edited applet re-gates before it advances. No downloads, any machine.
Your journey is yours to the last door - owned, scoped, published from your own portal click after a reviewer's green.
for reviewers + the estate - nothing un-witnessed
Gates refuse out of order. No G-B before G-A, no publish before green - by construction, not convention.
Review is a named human's word, recorded. Self-review is refused. A superseded verdict says so, forever.
The creator's LLM never touches the publish act. A human clicks; the studio writes.
Update, never duplicate. Existing CMS assets are reused by reference and verified live - a duplicate is a failure, not a warning.
The expectation isn't "go make a journey at the CMS." It's "the CMS only ever
receives finished, lawful journeys - and this machine is the only path that proves it."
chapter 2 · entry
A login becomes a seat.
No estate credentials, no special machine - entry is a login and a paste.
Your CMS identity is your studio identity.
1Sign in at the portalbuildjourney.classrootsedu.in - your CMS UAT login. Who you are there is who you are here:
it stamps every artifact, approval, and download you'll ever make.
2Take the seat cardThe portal hands you your token and the connect command - copy, paste, done.claude mcp add … /mcp
3Fetch the lawThe seat's first act: get_skill("journey-composer") -
the composer skill, served fresh from the studio. Never from memory.
Your Claude Session / Codex Session / Agent at your Computer is now a studio seat -
it reasons, authors, and - through agents it spawns - runs the gates, the walks, the harness;
the studio holds the rules, the record, the verdict arithmetic, and the only publish path.
creatorowns their journeys to the last doorreviewerany peer, on request - never yourselfadminsees all, may supersede - on the record
chapter 3 · command
Twenty-three verbs. One missing on purpose.
Everything a seat can say to the studio. Hover any verb.
know - read the world before touching it
list_journeysEvery journey on the shelf, stage-stamped - draft to published.get_journey_fileRead any artifact from a journey's cloud folder.find_lessonsThe first question of every journey: which lesson(s)? A loose chapter-grade description, free text, or an LO resolves to concrete CMS lessons - the estate's extraction is consumed, never redone.kg_list_losLearning outcomes from the knowledge graph - the LO picker's source.kg_get_loOne learning outcome, in full, with its graph neighbourhood.cms_getRead the live CMS with your own token - allowlisted read paths only, audited per user by construction.get_skillThe law itself - composer, gates, applet rules - served fresh from the last green CI publish.get_versionWhich law version the studio is serving right now.
make - you work in your own folder; what you stage becomes the record
create_journeyMint the folder: manifest, owner stamp, every gate pending.stage_filesThe only door in - text or base64 binaries. Your local folder is disposable; what you stage is the durable record, and only staged bytes can be gated. Identity in every write.download_assetThe one door back to a local disk: explicit, per-call, and every call lands in the ledger.
prove - the seat runs, the studio computes the verdict
check_rulesThe whole law sweeps the journey - run by the studio itself on staged bytes. A missing structure IS a finding - coverage, not vibes.check_sourcesYour ingest agent normalized the sources at your seat; the studio verifies every source is dispositioned in the inventory - nothing silently dropped.submit_gate_reportA fresh gate agent at your seat climbs the ladder per applet; the studio refuses incomplete sets, wrong pins, hash mismatches, or a verdict the numbers don't support.submit_walk_reportA fresh walk agent drives your journey end to end on your seat's harness - zero cuts, zero assists - and the studio checks the arithmetic, not the story.
govern - humans, named and recorded
request_reviewAsk a named peer for the green. Reviewing yourself is refused.review_verdictThe reviewer's word, recorded. An admin may supersede - marked as such, forever.record_approvalA human gate lands in the ledger. Out of order, or without its evidence - refused.grant_accessOwner or admin allow-lists a collaborator onto a journey.list_reviewersWho can give you a green.list_approvalsEvery gate ever signed, by whom, when.rosterAdmins and collaborations - admin-gated.
witness - the seat leaves a trail
log_sessionThe seat's own reasoning log, kept alongside the work it produced.publish_journey ∅Not a tool a creator's seat has. Publish happens on the portal: a human clicks, the studio writes. Your LLM is never part of the publish act.
23 verbs · and the missing one is the point
What more the seat does. The verbs are the
conversation - the work happens at your seat, and the heavy parts run in agents you explicitly
spawn, never in your authoring context: a gate agent per applet climbs the ladder, a
walk agent drives the journey end to end on your local harness, an ingest agent
turns your deck into slides. Each one submits a report the studio verifies deterministically -
it recomputes the hashes from what you staged and does the arithmetic itself. Nothing is
tunneled into: no runner host, no VM, nobody's machine - and a seat never touches git: everything
it runs is fetched from the published law. A fresh machine runs one script - seat-ready -
and gets a lane-by-lane yes, or the exact command that fixes each no. Your folder is temp; the
staged record is forever.
Five planes. Arrows are labeled by what crosses them - a token, a report, a file,
a verdict. The dashed ones are refused by construction.
crosses, witnessedrefused by construction
The broker is the only door. The store remembers everything.
The seat does the heavy lifting - and can only report what it staged. The only line into the CMS starts at a human's click.
chapter 6 · proof
Everything lands in the ledger.
gateG-A recognising-equivalent-ratios · byaswin@…· storyboard played ✓downloadslide-04.webp· bycreator@…· explicit, per-callreviewGREEN· byreviewer@…· requested, named, recordedverdictsuperseded:true· an admin overrode - and it says so, forevergateG-PUB· review green ✓ · asset plan ✓ · all prior gates ✓
Every hand that touched it, in order, forever.
colophon
The philosophy codex says why we teach this way.
This page says why the building of it is governed.
The law this machine enforces is versioned, CI-published, and served fresh to every
seat - no seat ever works from memory of it.
buildjourney.classrootsedu.in · the Journey Studio · classroots