Urban Development · internal briefing

Three programs watch the business
so nothing falls through.

They run on our own server and work with what the firm already produces — the group chats, the inbox, the Asana boards, and now a direct line. Three tempos, one goal: what was decided, what is about to be missed, and what you need recorded right now.

Every morning · 7:00

The Sentinel

Keeps the ledger of every date that can hurt us and escalates each one as it approaches. Nothing with a deadline goes unnoticed.

Every week · after the drop

The Weekly

Reads the week's chats and email, finds the decisions, and reconciles them against Asana. Nothing said in chat or email is lost.

Live · any moment

The DM

Text Claw directly: status updates become Asana comments in seconds, facts get remembered firm-wide, tasks get created on your word. Your phone is now an input to the record.

The design in one sentence

Trust follows who wrote the input.

Every permission in the system comes from one question: who typed the words this program is reading? The answer decides what each program is physically allowed to do — not policy, not promises, but what its credentials can and cannot reach.

Outsiders wrote it

Vendor chats, counterparty email — the Weekly's diet. Some of it could one day be hostile, so the reader is caged:

read, summarize, propose
comment (marked as machine)
create, complete or re-date tasks
reach the mailbox itself
send anything as the firm
A principal wrote it

Your DM to Claw. The message is its own approval — you typed it — so this channel may act live:

comment on tasks, in seconds
create tasks — after you confirm
remember facts firm-wide
complete, delete, or move dates
act on anything an outsider said
A human approved it

Proposal batches you've reviewed, and the Sentinel's own ledger writes. The only full-write path, and it runs on trusted input only:

apply approved changes
tag & adopt key dates
read outsider text directly
Why three programs instead of one smarter one? Because these permissions cannot coexist in a single brain. The thing that reads a vendor's words must never hold the pen that writes the record — so the reader, the live channel, and the writer are three separate programs with three separate credentials, and no message can talk its way from one into another.
Program 1 · The Weekly

One week in, four outputs out.

Everything mechanical — parsing, sorting, routing — is done by code that gives the same answer every time. Judgment is saved for the end, where a person approves it.

📥

1 · The week arrives, from two directions

Alex exports the week's chats — every group, voice notes and videos transcribed — and the mail program collects the week's email from senders already on the firm's roster. Email from anyone not on that list is never read at all.

22 chats · ~700 real messages ~60 emails · roster-admitted

Before any email's content is read, its provenance is scored — sender verified cryptographically, sorted into a trust tier. A stranger's prose can never talk itself into a higher tier, because the sorting happens before the prose is opened:

A · known & verified
B · earned trust
L · hand-picked
C · named only
D · counted
read fullyread, flaggedread by consentsubject onlya number
🧭

2 · Every message gets a home

Each message routes to its project — FTL Self-Storage, 770 Lake Road, 5990 SW 135 Terr, the pipeline — by a strict ladder. Higher rungs are more certain and always win:

1
A permit or invoice number A permit belongs to exactly one property — whoever typed it, the message routes there.
2
A street address in the subject "Re: 5990 SW 135th Terrace – Render Request" routes itself — but only for senders we already know.
3
The conversation it continues Reply #12 inherits the route message #1 established — from the same people only. A newcomer to the thread doesn't inherit its trust.
4
The kind of work it describes For ventures with no board of their own (USVI, Puerto Rico): entity paperwork files under the firm, deal work files under the pipeline.
5
What the sender works on Mail from the FTL permit expediter defaults to FTL. A vendor who serves several projects gets no default at all.
6
Unrouted — reported, never guessed If it isn't sure, it says so. An honest gap beats a confident misfile — a misfiled item looks right and is wrong, which is the worst kind.
⚖️

3 · Reconciled against Asana

Every decision, commitment and blocker found in the week is compared to what Asana currently says:

matches a task Enrich it

One dated rollup comment per task per week — each task reads like a project journal.

no task exists Propose it

The Weekly can't create tasks. It writes a proposal; a person approves or rejects each one.

contradicts Asana Flag the drift

"Asana says due the 8th; on the 22nd the vendor said it slipped; nothing was updated." The single most valuable thing it produces.

Claims get graded, not just collected. A vendor asserting something no one inside the firm confirmed is quarantined as an unverified claim. A statement only counts as corroborated when the system can point to a specific verified message from a principal saying the same thing — and that check is done by code that cannot be argued with.

📤

4 · Four outputs, one honest rule

A partner digest to WhatsApp — decisions first, readable in two minutes. Proposal batches for approval. Field notes for context that fits no task. Task comments in Asana. Every automated word is marked NanoClaw-auto — machine writing is never mistaken for a partner's.

The negative signal. The Weekly also verifies that what the firm owes actually went out — the monthly payment applications on FTL are confirmed sent by finding the real document in sent mail, not by taking anyone's word. When nothing went out, the silence itself is the alarm. New capabilities run in shadow mode first: observed for two weeks, contributing nothing, until they earn their seat.
Program 2 · The Sentinel

Every dangerous date, walking toward you.

One ledger of key dates across all projects, checked every morning. Each date sits in a tier based on how close it is after accounting for lead time — an insurance renewal that takes 60 days to negotiate starts escalating 60 days early, not 14.

Quiet
Watch
Alert
Urgent
Breach
far out< 90 days< 30 days< 7 daysoverdue

Quiet dates cost nothing. From Watch onward they appear in the morning digest to the partners' chat, with the owner @-mentioned as urgency rises. One message a day, worst first, never a flood.

The no-silent-snooze rule. Moving a due date without a logged reason is itself an alert. Clearing a date and quietly re-adding it later doesn't work either — the Sentinel watches for that specific move. Deadlines change for reasons, and the reason goes on the record.
It adopts dates by itself. Drag any task into a board's Key Dates section — or text one to Claw — and the next morning's sweep tags it, checks its description for a consequence and a lead time, and starts watching. The ledger grows by placement, not by ceremony.
Insurance renewals — FTL, 770, 5990 — with negotiation lead time, not filing lead time.
Permit clocks — the FTL master permit, the 5990 tree-permit window, expiring sub-permits.
Warranty windows on sold homes — dates that outlive the project and used to outlive our attention.
Annual filings — Florida and USVI. The USVI notice doesn't even arrive in our own mailbox; the ledger remembers anyway, every June.
Program 3 · The DM

Text it, and it's on the record.

The newest program, and the fastest. You already message people about the business all day — now one of those threads writes things down properly. Because everything in your DM was typed by you, this is the one channel allowed to act live.

Status updates land in seconds, not Sunday. The DM routes your sentence with the same machinery the Weekly uses — project names, addresses, permit numbers — finds the right task, and comments. If it isn't sure, it asks you, because you're right there. It never posts to a guessed task.

🧠

"Remember that…" becomes firm memory, not chat memory. Gate codes, lockbox combos, which house has gas — stored in one shared ledger that both your Claw and Andres's Claw answer from. New values supersede old ones, and the full history is kept, so a changed code can always be traced.

📝

Tasks are created on your word — and only top-level. It always shows you the draft first and waits for your yes. It never creates subtasks: subtasks vanish from board views, and this workspace has lost real obligations that way. Everything it makes stays visible.

✍️

Each brother writes as himself. Alex's DM posts under Alex's Asana account, Andres's under his — attribution comes free, and every automated line still carries the NanoClaw-auto marker.

What it can never do, no matter what it's told:
✕ complete a task ✕ delete anything ✕ move a due date ✕ act on a forwarded vendor request

Additive only. It can add to the record; only humans subtract from it — and date moves stay under the Sentinel's no-silent-snooze watch.

The system

How the three fit together.

Asana stays the single source of truth. Everything else is a way in or a way out — and each program also watches the others' health, so a broken program can't fail silently. Silence is never assumed to be good news.

And they hand off to each other. A deadline you text the DM tonight is in the Sentinel's ledger by morning. A task the DM can't create yet becomes a Weekly proposal automatically. The Weekly's digest cites the same tasks the Sentinel escalates. One record, three doors.
Proof

What it has already caught.

All from real runs, this month.

Sentinel · filings The annual report nobody's mailbox would have remembered

A USVI entity's annual report is due every June 30 — miss it and the entity can be administratively dissolved. The renewal notice goes to a relative's mailbox, not ours, and last year's task lived on no board at all. It's in the ledger now, permanently, with lead time that fires before the notice would even arrive.

Weekly · the negative signal It reports what didn't happen

Three separate monthly payment applications go to the owner's rep on FTL. Each month the program verifies each one actually went out — by finding the real document in sent mail. When nothing went out, silence is the alarm.

Weekly · drift flags Chat and Asana disagreed; both sides quoted

Live runs have flagged due dates that slipped in conversation but never moved in Asana — and corrected the program's own earlier false alarms when fuller data arrived. An honest system reports its own mistakes.

Housekeeping 22 buried subtasks recovered

Completing an Asana task silently hides any open subtasks beneath it. A sweep found 22 — including post-closing warranty items on a sold home and a permit response still owed to the city. It's also why the DM refuses to create subtasks at all.

Security Forgery is detected structurally, not by vibes

Someone typing a fake "message from Alex" inside their own chat message, spoofed email authentication, lookalike domains one letter off a real vendor's — each is caught by checks that run before any content is believed, and reported naming the real author.

Method Audited by three independent reviewers before trust

Every new capability is validated against a full year of real data before it may act, then run in shadow mode. A recent audit fixed two dozen defects — most of them failures that would have looked exactly like success, which is precisely why the audits exist.

The rhythm

A week in the life.

Always on: the DM answers any moment · email is collected hourly · shared memory syncs every few minutes · every program's health is checked twice an hour.
Mon
Chat export dropped
Weekly runs → digest + proposals
7:00 Sentinel sweep
Tue
7:00 Sentinel sweep
Wed
7:00 Sentinel sweep
Thu
7:00 Sentinel sweep
nag if no export yet
Fri
7:00 Sentinel sweep
Sat
7:00 Sentinel sweep
Sun
7:00 Sentinel sweep
week closes at midnight

The Sentinel proves itself every day. The Weekly proves itself every week. The DM proves itself every time you use it. And each one watches the others — a broken program cannot fail silently.