Project · the plan · session S29

Where the work stands

Initiatives → tasks → done. Stamped progress remains readable without JavaScript; the browser re-derives it and doctor independently checks it. This board tracks building Sandpaper, in Sandpaper.

Overall 49/54 · 91%

Phase 0 Make it work for us

18/19 · 95%
A

Three-lens skeleton + IA rebuild

living
  1. Design the three-lens skeleton + plan model (this workflow)S08
  2. Add the data-lens axis to the .entry grammar + brain.js facetS08
  3. Extract tokens → theme.css; de-hardcode the fontsS09
  4. Write product/ + engineering/ lens prose (brain = source of truth)S09
  5. Generated 3-lens portal cover + persistent shell/footerS09
  6. Liberal cross-lens links — every page reaches related lenses (multiple paths to the same place)S09
B

Plan board + derived progress

living
  1. Design the initiative → task → session modelS08
  2. Progress derivation in brain.js (counts task status, fills bars)S08
  3. Seed this build's backlog as the first planS08
  4. Wire the plan into the cover (progress spine + Tier-1 pill)S08
C

Hands — direct manipulation

hands
  1. Edit text in place (contenteditable) → file write, no AIS09
  2. Drag-to-reorder & delete a block → file writeS10
  3. Keyboard path for reorder/delete (drag is mouse-only) — a11y

Phase 1 Package it for distribution

31/35 · 89%
D

Theme consolidation + /theme

reach
  1. One overridable theme.css — brain imports it, the toolbar reads its tokens at runtime · docs stay self-contained (archival) · flipped in the S28 auditS28
  2. /theme command (presets + interactive, derive from a brand hex) · shipped in the skill · flipped in the S28 auditS28
E

CLAUDE.md contract + manifest

reach
  1. Delimited, regenerable contract + the 4 plan ops + lens rules · lives in CLAUDE.md + SKILL.md + /plan; 13 marker regions on the cover · flipped in the S28 auditS28
  2. .sandpaper/manifest.json (books, cid-prefixes, id-counters, theme path) — written by sandpaper initS10
F

The skill — /init, /theme, /plan, /decide, /sync…

reach
  1. /init — harvest repo → interview → generate the first brainS10
  2. Capture commands: /plan /decide /learn /log /stamp /serve /themeS10
  3. /sync — the drift immune system (brain ↔ code reconcile)S10
  4. Auto-update hooks (SessionStart inject + Stop stamp-check) + SKILL.md — brain stays current, no proddingS10
  5. /help (the command index) + /open (launch the dashboard) commandsS10
  6. Smarter /init — wide artifact discovery (specs/logs/docs, not just code) + an interactive wizard (fill gaps + shape the brain)S10
G

Sidecar publish + npm packaging

reach
  1. Always-publishable brain — out-link resolver (source meta · name-checked probe · click-time rewrite) + doctor lint + deploy guideS28
  2. sandpaper.sh landing page (site/) — judged pitch lab · self-stamping hero demo · 4-critic review · OG card · was t-0029, renumbered (id collision)S28
  3. SHIP: sandpaper.sh + brain.sandpaper.sh live — two Vercel projects, domains attached, resolver verified in productionS28
  4. PUBLISHED — @nynb/sandpaper@0.1.0 live on npm; verified via registry + a real npx smoke test · D-017S28
  5. Vercel git integration wired + verified — sandpaper-sitesite/, sandpaper-brainbrain/; w-0205's plain push auto-deployed both, confirmed by the ownerS28
  6. Publish preflight — doctor --publish scans brain/ for secrets · emails · internal URLs before a deploy · from q-privacy
  7. bin/verify-publish.js + CI (.github/workflows/ci.yml) — the tarball-safety checks (no site/, no secrets, size envelope) now run on every push/PR, Node 18/20/22 · D-018S28
  8. Release workflow (.github/workflows/release.yml) — a version tag runs tests → verify-publishnpm publish --provenance → a GitHub Release; plus .github/dependabot.yml for Actions/dep hygiene · D-018S28
  9. /sandpaper:release — versioning as a Sandpaper feature, not a side process: drafts notes + a semver bump from brain/log.html, runs npm version + push · D-018S28
  10. PIPELINE VERIFIED — v0.2.0 published for real with provenance (SLSA attestation confirmed) via release.yml + the new NPM_TOKEN; found + fixed a changelog-extraction awk bug along the way · l-awk-v-escapingS28
  11. The blueprint identity (D-015) — landing + brain reskin, the owner's logomark, SANDPAPER titling · added in the S28 audit; shipped without a taskS28
  12. npx sandpaper install-skill / init / doctor / open (tested e2e on a fresh repo)S10
  13. Brain-aware Sand contract (respect entry grammar / link-never-copy)
  14. Cold-repo /init — partial-scaffold (dimmed deferred chrome) + no-spec data-ref contract · from validation
  15. Self-deriving cover counts — brain.js fills them from the board (retire hand-typed data-count) · verified from canonical pages in ChromiumS32
H

Stats · low prio

reach
  1. A static stamped table (usage · tokens · commits) — no live analytics
I

v0.2.1 — truth + safety sweep

reach
  1. Design and approve the risk-based v0.2.1 stabilization sweepS29
  2. Implement verified server, trust-boundary, concurrency, session, and reload hardeningS30
  3. Make toolbar/direct/undo state truthful and fix the verified UI regressionsS31
  4. Reconcile brain/docs/resolver/doctor and complete self-derived cover state (t-0028)S33
  5. Add regression integration coverage for server, SSE, setup, undo, and fixed failure pathsS32
  6. Verify, stamp, version, and release v0.2.1S37
J

v0.3.0 — Claude + Codex, first-class

reach
  1. Design and approve the provider-neutral Claude + Codex contractS39
  2. Implement provider choice, runners, install/hooks, toolbar identity, and documentationS40
  3. Verify both providers, stamp, version, and release v0.3.0S43

Phase 0 · shipped foundations

Spine — the bridge

spine
  1. Bridge: claude -p stream-json → status chip + change cards
  2. Undo / snapshots · live reload · click-to-scope
  3. Adversarial review — 8 bugs fixed

Brain v1 — service manual + action bar

brain
  1. Scaffold the brain + the manual aesthetic redesign
  2. Serve the folder with the Sand / Sling action bar
  3. Markdown replies · git baseline