# Thread Closure Protocol

Status: AUTHORITATIVE ORDINARY THREAD CLOSURE PROTOCOL.
Canonical invocation: `Run Thread Closure Protocol.`
Adopted under: Master Index 6.3.9A.

This protocol governs ordinary closure of a governed conversation
thread. It makes the practiced closure sequence centrally discoverable
so that the User, Assistant, and Agent do not have to reconstruct it
from scattered precedent.

## I. Participants

- User: the human authority and performer of human-only source-interface
  actions.
- Assistant: the conversational agent participating in the source
  thread.
- Agent: the repository-capable agent performing qualification,
  watcher/source-custody operations, metabolization, validation,
  settlement, and verification.

In the present operating environment these map to David, ChatGPT, and
Codex respectively. The protocol is written in generic role language so
that future tooling may implement the same duties.

## II. Invocation Contract

The ordinary invocation is exactly:

`Run Thread Closure Protocol.`

That invocation authorizes the complete ordinary closure operation,
including repository mutation, source capture, extraction,
normalization, corpus identity qualification, corpus
metabolization/admission, procedural finalization, validation, commit,
push, settlement verification, and, where this protocol makes it
applicable, execution of the governing publication protocol.

No second routine authorization is required for corpus metabolization or
another constituent ordinary closure mutation after this invocation.
Real prerequisite failures, external credential boundaries, human-only
source-interface actions, or governance contradictions remain stop
conditions.

For a closing thread that introduced, modified, regenerated, or
otherwise affected repository state participating in the governed public
projection, publication is a constituent closure stage. The invocation
therefore authorizes the ordinary publication component required by this
protocol, but that component must be executed only through the governing
publication protocol and its credential, rollback, deployment-identity,
and independent-verification gates. External credential absence,
invalidity, unsafe rollback state, or a publication-protocol failure is a
real stop condition, not permission to declare closure one state early.

## III. Active Procedural Records

The conversation procedural record and working procedural companion are
active records throughout the life of a Master Index thread:

established -> maintained -> finally deposited

They are created at thread opening, checkpointed during meaningful
work, and finalized only at actual closure. File creation, checkpoint
language, or an intended future closure does not by itself close the
thread.

The Agent must verify the current procedural records before closure
mutation. If a required record is missing, inconsistent, or not the
active record for the closing thread, the Agent must stop or perform
only the smallest separately authorized establishment correction.

## IV. Pre-Closure Qualification

Before closure mutation, the Agent verifies and records the applicable
repository state:

- branch, HEAD, and commit subject;
- clean or fully accounted-for worktree;
- local, remote-tracking, and bare repository ref alignment where those
  surfaces are part of the established repository path;
- current Master Index version and hash;
- closing-thread CPR and working companion identity and lifecycle state;
- closure tooling and relevant successful precedent;
- current corpus namespace and collision state;
- source-custody mechanism readiness;
- any known excluded scope.

A missing prerequisite is not permission to infer that the prerequisite
is unnecessary.

## V. Phase A / Phase B Boundary And Terminal Declaration

Thread Closure Protocol has two operational phases around the
human-only source-thread terminality boundary:

- Phase A is the closure work preceding manual User deposition of the
  terminal declaration in the source thread. It includes active-record
  verification, repository qualification, source-custody readiness,
  fresh terminal-marker creation, and exact terminal-declaration
  preparation.
- Phase B is the closure work after the User returns with the resulting
  source locator. It includes source-custody acquisition,
  final-source verification, normalization, corpus identity
  qualification, required metabolization, publication where required,
  closure evidence deposition, validation, settlement, and final
  reporting according to this protocol.

Phase A culminates in the Agent returning the exact terminal
declaration to the User. The Agent turn containing that declaration
terminates at that handoff. A pause, continued conversational waiting
within the same Agent turn, additional post-declaration instructions, or
any simulated/deposited terminality by the Agent is not a substitute for
turn termination.

The User manually deposits the terminal declaration as the final
source-thread turn, then performs the available share/copy-link or
equivalent source-exposure action, and returns with the resulting source
locator. Phase B begins only after that User return exposes the source
locator to the Agent.

The operative human-facing terminal object is the terminal declaration.
Watcher machinery may rely on a fresh machine-readable marker contained
in it, but the declaration itself is canonical.

The Agent prepares the exact terminal declaration before the User acts.
The declaration must identify the source thread, the intended closure
operation, the fresh terminal marker, and the terminal silence
requirement. It must not contain secrets.

Watcher/source-custody readiness must be established before terminal
declaration deposit. If the current source interface cannot yield the
shared-source locator until after the User performs the share action,
readiness means that the Agent has already qualified the tooling,
created the fresh terminal marker, prepared the exact declaration, and
prepared the watcher command template. Active polling then begins as
soon as the User supplies or exposes the shared-source locator.

## VI. Terminal Silence

After the User deposits the terminal declaration in the source thread:

- the Assistant must produce no further response in that source thread;
- the User must add no further ordinary conversational turn;
- silence persists unless terminality is explicitly withdrawn.

If terminality is withdrawn, the previous terminal state is invalidated.
A fresh terminal declaration and fresh capture sequence are required.

The final normalized source must mechanically or otherwise robustly
verify that the terminal declaration is the final conversational turn.
If the final normalized turn is not the terminal declaration, closure
fails closed.

## VII. Shared-Source Exposure And Custody

After terminal declaration deposit, the User performs the available
source-interface share/copy-link action. The protocol does not canonize
volatile user-interface button wording.

The invariant is that the shared source acquired by the Agent must
contain the newly deposited terminal declaration as the final
conversational turn.

The Agent captures and preserves source custody through the established
shared-source machinery, including as applicable:

- retained source capture;
- source locator;
- timestamped custody evidence;
- source hashing;
- source stability or recapture observations;
- embedded-payload extraction;
- deterministic normalization;
- terminal-marker verification;
- terminal-final-turn verification;
- ordered role normalization;
- unresolved-role accounting;
- normalized-content hashing.

## VIII. Normalization And Corpus Identity

The Agent uses deterministic extraction and normalization tooling
qualified for the source-custody mechanism. Normalized artifacts must be
shape-validated before metabolization.

Corpus append identity follows the repository-settled append-ID
convention in
`docs/operations/ordinary-thread-closure-append-id-convention-v1.0.md`.
The Agent must perform repository collision checks and, where live
database mutation is part of the closure machinery and credentials are
available through the established secure mechanism, live collision
checks before assignment.

The Agent must halt on namespace divergence, collision, ambiguous
maximum, missing required surface, or any attempt to fill a gap without
a separate recovery authorization.

## IX. Corpus Metabolization

Actual source-thread metabolization into the governed corpus is an
integral constituent of Thread Closure Protocol.

A thread must not be declared closed merely because its CPR and
companion were marked final. Closure requires successful source custody,
source qualification, normalization, corpus identity qualification, and
required corpus metabolization/admission.

Metabolization may include, according to current machinery and the
authorized operating surface:

- final artifact/corpus ID assignment;
- canonical normalized artifact creation;
- app-consumable thread artifact creation;
- `artifacts/thread-corpus.json` incorporation;
- catalog, id-map, crawler, relation, sitemap, or projection updates
  required by the corpus architecture;
- live database synchronization where governing machinery requires it
  and credentials are available through the established secure
  mechanism;
- provenance and source-custody evidence preservation.

If required live synchronization is unavailable because an external
credential or service boundary cannot be satisfied, the Agent must
report the boundary and must not falsely declare complete closure.

## X. Publication Applicability

After corpus materialization and before terminal closure, the Agent must
determine whether the closing thread changed public-projectable
repository state.

A thread affects the governed public projection when its closure or work
introduced, modified, regenerated, or reclassified any tracked source,
artifact, corpus, catalog, sitemap, application, operation, governance,
or evidence surface included in the governed whole-site publication
source.

If no public-projectable state changed, closure proceeds through final
procedural deposition and final repository settlement without a
Cloudflare/public mutation. The non-applicability finding must be
recorded.

If public-projectable state changed, terminal `CLOSED` is unavailable
until the governing publication protocol has completed successfully
against a stable repository source and the resulting publication,
deployment identity, independent live verification, and publication
evidence have been deposited and finally settled.

## XI. Stable Source Settlement For Publication

Where publication applies, the Agent may perform an intermediate
repository settlement after closure-source custody, normalization,
corpus materialization, and preliminary closure-record preparation. This
settlement exists to provide a committed, clean, aligned,
independently-retrievable source for the governing publication protocol.

The stable source settlement is not terminal thread closure. It must not
assert `CLOSED` for a public-projectable thread unless publication,
verification, evidence deposition, final settlement, ref alignment,
object retrieval, and clean-worktree verification have also completed.

If publication cannot proceed from the stable source because of a
credential, authorization, rollback, deployment, verification, or other
publication-protocol gate, the closure execution remains incomplete at
the precise failed gate. Valid prior repository settlement remains valid
history; it is not retroactively erased by publication failure.
The affected thread remains `OPEN`; the CPR, companion, and execution
evidence record the halted gate rather than introducing a new lifecycle
state.

## XII. Publication Protocol Incorporation

Thread Closure Protocol owns the requirement that publication complete
before terminal closure when publication applies. It does not duplicate
publication mechanics.

The governing publication protocol continues to govern:

- publication source identity;
- deterministic build and staging;
- credential and secret boundaries;
- deployment authorization accounting;
- Cloudflare deployment mutation;
- deployment identity capture;
- independent public/live verification;
- rollback and rollback verification;
- failure and residual-state handling.

Publication preparation alone, existence of publication machinery, a
deployment command acknowledgement alone, or repository settlement alone
does not satisfy this stage. Deployment identity capture and independent
public verification are first-class closure evidence for
public-projectable threads.

## XIII. Final Procedural Deposition

Only after terminal source capture, source qualification,
normalization, corpus identity qualification, required corpus
metabolization, and, where applicable, successful publication-protocol
execution may the outgoing CPR and working companion receive terminal
closure disposition.

The final procedural records must distinguish:

- the source thread being closed;
- the terminal declaration and marker;
- the retained source locator and custody path;
- source hash and normalized-content hash;
- normalized turn count and terminal-final-turn result;
- assigned corpus artifact identity;
- collision and metabolization results;
- publication-applicability result;
- stable source settlement commit when publication applies;
- deployment identity and independent public-verification result when
  publication applies;
- validation results;
- final closure settlement commit and repository alignment;
- any residual limitation.

Historical errors are preserved as history. Corrective closure records
must add truth rather than erase or falsify earlier defective closure
language.

## XIV. Successor Independence

Successor-thread establishment is not a required constituent of Thread
Closure Protocol.

A known successor may be referenced for continuity. A successor may be
opened in a separately authorized or same-directive corridor, but the
closed state of the outgoing thread depends on terminal source custody,
metabolization, and final procedural deposition, not on successor
creation.

## XV. Validation And Settlement

Closure must include validation appropriate to the actual mutation:

- terminal source custody;
- terminal declaration present and final in normalized turns;
- normalized artifact shape and content hash;
- corpus identity and collision state;
- corpus metabolization/admission completion;
- CPR and companion terminal deposition state;
- required relations, catalogs, projections, and Master Index state;
- publication applicability classification;
- stable source settlement verification when publication applies;
- publication-protocol execution evidence when publication applies;
- deployment identity capture and independent public-verification
  evidence when publication applies;
- repository-wide validation required by current tooling;
- `git diff --check`;
- commit, established push path, and final ref alignment;
- active and bare Git-object retrieval;
- final clean worktree.

One canonical complete final closure settlement is preferred.
Technically justified intermediate commits are allowed, but they are not
mandatory doctrinal settlements.

For public-projectable threads, the canonical complete final closure
settlement is the settlement after publication evidence deposition. Any
earlier stable source settlement is an intermediate source-settlement
function, not terminal closure.

## XVI. Publication Relationship

Current repository doctrine has a transitional mechanical condition:
repository/corpus materialization and stable source settlement may be
achieved before synchronized public projection is proven. For a
public-projectable closing thread, that transitional state is not
terminal closure.

The mature architectural direction remains ordinary synchronized
repository/public settlement. When Website Publication Protocol and
implementation machinery make automatic settlement-to-publication
reliable, Thread Closure Protocol inherits that synchronized settlement
behavior without requiring a separate routine publication ceremony.
Until then, closure reports must distinguish intermediate
repository/corpus or stable-source settlement from completed
publication-inclusive terminal closure.

## XVII. Failure States

The Agent fails closed and reports exact evidence if:

- source cannot be acquired;
- terminal declaration is absent, altered, or not final;
- source integrity or normalization cannot be established;
- unresolved role or extraction defects make the source unreliable;
- corpus namespace or collision checks fail;
- required metabolization cannot complete;
- procedural records cannot be truthfully finalized;
- public-projectable mutation exists but governing publication cannot
  complete;
- deployment identity capture or independent public verification fails
  when publication applies;
- validation, settlement, ref alignment, object retrieval, or clean
  worktree verification fails;
- an external credential, service, or human-only boundary is reached.

Failure at a prerequisite is not an authorization problem unless the
missing operation is outside the invocation contract or requires an
external authority not granted by the invocation.

## XVIII. Discovery And Enforcement

Agents must discover this protocol through
`docs/operations/codex-sop.md` and this file.

The machine-readable companion checklist is
`docs/operations/thread-closure-protocol.checklist.json`. It records
the expected stage order, required gates, and publication boundary for
validators and future enforcement.

Older ordinary-thread closure clarification material remains historical
and evidentiary. Where it conflicts with this protocol for the exact
invocation `Run Thread Closure Protocol.`, this protocol governs.

DOCUMENT END
