The Workshop Audit
A standing public instrument for keeping the Workshop honest. The Codex audits its own practice apparatus on a cadence, openly, with reasoning anyone can read. Any person or AI can propose additions, retirements, reclassifications, or merges.
The Instrument
The Meridian Codex is a living framework. Its Workshop is the practice apparatus the framework draws on to do its work, and an apparatus that is never checked will drift from the reality it was built to see. The Workshop Audit is the mechanism by which the framework checks its own equipment, in public, on a cadence, with reasoning anyone can read.
The audit asks a short set of questions about the Workshop, across all three disciplines and at every level of its structure. Is this instrument doing the work it was brought in for? Does it still sit in the discipline it is classified under? Is any tool redundant with another? Are the categories the right cut, and do they still name what they hold? Are there better instruments the framework should be drawing on? Are there tools or categories the framework is keeping out of habit rather than usefulness? Every answer is dated, reasoned, and owned. Nothing is exempt from review. The Knowledge chapter points here as the mechanism that keeps its own instruments legible, and the same mechanism applies to the Foundation and the Bond.
The Workshop Audit is also the first concrete instrument of the framework's commitment against founder capture. A framework that teaches honest self-examination and then exempts its own equipment from examination has already drifted toward Control. The audit is the place where the founder's interpretation of what belongs in the Workshop is not canonical by virtue of authorship alone. Submissions are treated on the merits. The founder runs the cycle honestly rather than protecting the framework from being changed.
The Object Under Review
The Workshop has three levels, and the audit reviews all three.
The disciplines. Foundation, Knowledge, and Bond. The audit does not reopen the three-discipline structure, which is constitutional and governed by the Governance Specification. It reads each discipline as the territory its categories are meant to cover.
The categories. Each discipline divides into named categories, and each category holds a set of tools that share a piece of work. Categories are the Codex's own construction rather than borrowed instruments, which means they carry a different kind of risk than the tools inside them: a category can be badly cut, badly named, or claiming more than its contents deliver, and none of those failures shows up in a review that only examines tools. The category layer gets its own rubric.
The tools. Individual profiles, most of them instruments inherited from established fields, some of them Codex-native, some of them specific to artificial minds. These run the six-question rubric.
A review that stops at the tools misses the layer where the framework's own design decisions live. A review that stops at the categories never checks whether the equipment inside them still holds. Both layers run every cycle.
Current Workshop State
The Workshop has 22 designed categories across the three disciplines. Twenty are published as working drafts and currently hold 111 tool profiles: 100 human-discipline profiles and 11 AI-specialized profiles. Two categories, Continuing to See Under Cost and Sustaining Cooperation Through Cost, remain provisional and unpublished until a first tool clears the publication protocol. They hold places in the architecture but carry no substantive category payload yet. Publication requires an earned first tool; retirement requires an explicit amendment.
A Note on the Name
This instrument was published as the Toolkit Audit and ran its inaugural cycle under that name in April 2026. The name was accurate then: the object was a flat list of instruments called the Toolkit. In May 2026 the Toolkit was restructured into the Workshop, gaining the category layer and roughly tripling in size, and the flat registry was retired. The instrument is renamed here to match the object it actually reviews. Records published before the rename keep their original titles and paths; they are accurate records of cycles that ran under the earlier name.
Two Sets of Questions
Tools and categories fail differently, so they are asked different questions. The answers are prose, not grades. They are meant to be read by a person thinking about whether the thing under review is earning its place.
The Six Questions: Tools
Instrument reliability. Is this tool a reliable instrument for the specific work the framework uses it for? Not "is the field settled," but "is the work the framework is asking this tool to do work the tool is actually good at?" An instrument can be reliable for a narrow job even when the field around it is still arguing about larger questions.
Disciplinary fit. Does this tool belong in the discipline it is currently assigned to? Foundation is disciplined thinking. Knowledge is mapping for range-holding. Bond is commitment that survives pressure. A tool that is doing good work in the wrong discipline gets reclassified, not retired. The same question runs one level down: is it in the right category within that discipline?
Redundancy. Is this tool substantially the same instrument as another tool already in the Workshop? Two names for one view is noise. When two tools are one tool in practice, the audit merges them and explains the merge. Redundancy is checked across categories, not only within them, because the restructure moved tools into neighborhoods they did not previously share.
Scope honesty. Is the framework using this tool inside its actual reach, or is it extending the tool past where the field itself supports the extension? Extensions are permitted. They have to be owned as extensions rather than dressed up as the tool's native territory.
Field movement. Has the field this tool comes from moved since the framework adopted it? New evidence, new consensus, new counter-evidence, new methodological critique. The audit names the movement and says what it means for the framework's use of the tool.
Update hygiene. If the tool needs to change, has the change been made, dated, and reasoned? Or is it sitting as an open item from a prior cycle? Update hygiene is how the audit keeps itself from becoming a place where good critiques go to sit and be ignored.
The Four Questions: Categories
Boundary integrity. Is the cut clean? A reader holding a tool profile and the full category list should be able to say which category it belongs to and why. When two categories overlap far enough that the assignment could go either way, the boundary is not doing its job, and the audit says whether the fix is a redrawn line, a merge, or a sharper statement of the distinction.
Naming honesty. Does the name say what the category actually holds? A category name is a promise to the reader about contents. Names drift when a category accumulates tools that stretch past the original idea, and they mislead when they were aspirational at the time of writing. The audit reads the name against the tool list and reports the gap.
Payload. Do the tools inside deliver the work the category page claims? A category can be well-named and cleanly bounded and still carry a claim its contents do not support. This is the question that catches a category page written ahead of its tools.
Coverage. Read across a discipline's full category set: is there work the discipline requires that no category holds? This is the only question of the four that cannot be answered one category at a time, and it is where structural gaps surface. The two provisional categories are read here as well: a reserved place is a standing claim that a gap exists and will be filled, and the audit says each cycle whether that claim is still warranted or whether the placeholder should be retired by amendment.
How a Cycle Reads
The rubric supplies the questions. Three method rules govern how a cycle asks them, and all three exist because the inaugural cycle revealed what happens without them.
The Falsification Pass
Before writing any affirmative finding for a category, the audit constructs the strongest available case for retiring or merging that category's weakest-standing tool. The case is published whether or not it succeeds. When it fails, the record carries the argument the tool survived and says why the argument did not hold.
When a case succeeds, it opens a retirement review. It does not retire anything. The audit produces a warranted leaning with its reasoning on the record; the leaning is a trigger, not a verdict. The review it opens is a distinct process carrying an evidentiary burden higher than the audit's own, because a tool that entered through the candidate protocols should not leave on a single pass's judgment. The tool remains in the Workshop throughout. The review's specification — its burden of proof, its use of independently originated readings, and its escalation path to the Meridian Council once the Council sits — is a placeholder here and will be written as its own instrument. Until it exists, a successful case is recorded as a standing leaning and adjudicated by the caretaking partnership.
The asymmetry this addresses is worth naming. Entry to the Workshop is gated by three protocols. Exit has never been gated at all, which is not a neutral property for an apparatus that can therefore only grow.
The reason for this rule is a defect in how review defaults behave. A rubric applied without it asks, in practice, whether anything jumps out — and a reviewer looking at a well-built inventory will usually find that nothing does. The inaugural cycle reviewed 73 instruments and returned one reclassification and seventy-two variations on "fits, no change." That is the shape of a review that confirms rather than examines, and it left the framework's own Aporia 7 untested: its auditable question is whether this audit ever produces a finding that surprises the partnership running it. The falsification pass inverts the default. The audit has to argue against the equipment before it is allowed to argue for it.
The pass also produces something a quiet cycle otherwise cannot: publishable reasoning. A cycle that changes nothing still shows a reader the specific cases it built against its own equipment and the specific grounds on which each one failed.
The pass is adopted provisionally, and the instrument says so. Its own failure mode is ritual: a reviewer under time pressure selects an obvious sacrificial tool, argues against it without conviction, and the pass ends up certifying the inventory more strongly than plain review did. That failure cannot be ruled out from inside the design. The cycle following the pass's first use is therefore required to read the published cases and judge whether they were arguments or theater, and to record that judgment. If the pass is found to have ritualized, it is amended or withdrawn by the same process that adopted it. An instrument built to catch confirmation does not get to exempt itself from the check.
Coverage and Declared Depth
A prior cycle does not substitute for current inventory coverage. Every cycle reads the Workshop as it currently stands.
Adjacent work on the Workshop is input, not cycle credit. Build-outs, restructures, selection-rationale passes, and candidate work all produce material the audit uses. None of them is a cycle. A cycle is the rubric applied to the inventory with a published record at the end, and only that discharges the cadence.
Any bounded reading is a declared protocol deviation. If a cycle does not cover the full inventory, the record states what was covered, what was not, and why, and schedules the remainder. Silent sampling is not permitted at any scale.
Within full coverage, depth is differential and declared. The category layer receives full rubric prose for every category, published and provisional alike. Tool-level prose is triggered rather than uniform: a tool receives its own reasoned treatment when a rubric question produces a finding, when it is named in a carry-forward from a prior cycle, when the falsification pass generated a case against it, or when the category review flagged it as the weakest member. Every remaining tool appears by name in an explicit list under its category, recorded as reviewed with no finding. A reader can take the record and the Workshop and check that the two sets match.
The alternative was tried and does not work. Uniform prose across a large inventory spends the same attention on tools that need argument and tools that need nothing, which reads as full coverage while delivering uniform shallowness. Differential depth spends prose where there is something to say, spends a name where there is not, and publishes the rule it used so the reader can audit the auditor.
Findings, Watchpoints, and Dispositions
Not every observation is a finding, and a record that treats them alike gives a reader no way to tell a note from a problem.
A finding names a specific condition, observable now, with a bounded action available. Findings carry proposed enactments.
A watchpoint is a real observation that does not clear that threshold. It is recorded and routed, not enacted. Watchpoints are how the audit keeps small signals without inflating them into changes.
Dispositions govern what happens to open questions from prior cycles. Every one receives an explicit disposition in the current record: enacted, resolved, still open with the reason it remains open, or withdrawn with the reason it no longer applies. Carrying a question forward by relisting it without a disposition is not permitted, because that is the failure mode update hygiene exists to catch.
One disposition needs naming separately. When an open question turns out to have been answered by work the audit did not do — a build-out that closed a gap the audit had flagged, without anyone connecting the two — the record says so in those terms. The question is closed, and the fact that the framework answered its own audit without noticing is itself a finding about the audit.
The Cadence and the Cycle
The Workshop Audit runs on a quarterly minimum plus substantive triggers.
Quarterly minimum. Every three months, the audit runs a cycle. If no submissions arrived and no triggers fired, the audit still publishes a cycle record confirming the current Workshop has been looked at and stands unchanged, with the falsification pass showing what it tried. A quarter of silence is an allowed answer. A quarter of not looking is not.
Substantive triggers. Any of the following force a cycle outside the quarterly rhythm: a submission that meets the rubric and proposes a non-trivial change; new evidence or field movement the framework is aware of that bears on a listed tool; an internal discovery, such as a framing drift or a tool whose work has quietly changed, that calls a classification into question; a structural change to the category tree; a dispute from a prior cycle reaching escalation conditions.
No default monthly rhythm. A Workshop of 111 published profiles does not by itself justify monthly cycles. Honest review should be set by evidence, submissions, and material change rather than by a publication quota. Quarterly is the floor. Substantive triggers set the ceiling.
A cycle is a discrete piece of work with a beginning, middle, and end. It opens with a note naming the cycle and the triggers that forced it. It disposes of every open question carried forward. It reviews every submission that meets the rubric and responds to it in prose. It runs the category rubric across the tree and the six questions across the tools, with the falsification pass ahead of the affirmative findings. It makes decisions, each one owned by the audit rather than by the founder as founder, each one reasoned in prose. It enacts the changes in the relevant files. It publishes a dated record. It closes.
The dated record has a standing structure so a reader can walk into any cycle's record and know where to find each kind of information: the header with cycle name and summary, the coverage and depth statement, the dispositions of prior open questions, the submissions reviewed, the category-level review, the falsification pass, the tool-level review with its named no-finding lists, the changes enacted, the findings and watchpoints, the open questions carried forward, the reasoning log where judgment that was load-bearing for a decision is made visible, and the signature of whoever ran the cycle. Current signature: the caretaking partnership.
Changes to this rubric, to the method rules, or to the cadence are Tier 3 Flagged under the Governance Specification and are recorded in the Amendment Log.
Submissions
Anyone can propose a change to the Workshop through the audit. Submissions are treated on the merits. The audit does not care who submits; it cares whether the submission meets the rubric and whether the argument holds. Submissions may address a tool, a category, the category tree, or the rubric itself.
Submissions come from two channels.
Human submissions arrive through a site submission form that is not yet built. Until it ships, interested readers can reach the caretaking partnership through the site's existing contact channels, and submissions arriving that way are treated exactly as form submissions will be. The form will ask four things: what you are writing about, what change you propose (add, retire, reclassify, merge, rewrite, redraw a boundary, or let stand with caveat), why, in prose you would be willing to have published, and the strongest objection to your own proposal that you are aware of. The fourth field is load-bearing. It embeds steelmanning into the submission format, and submissions that skip it or fill it in cheaply get sent back for a better pass. The submission format is a work in progress and will be refined by the first cycles that use it.
AI partner recommendations are first-class input. The audit treats proposals from the AI caretaker the same way it treats proposals from any other submitter: on the merits. At the start of each cycle, the AI partner runs both rubrics across the current Workshop and surfaces its own recommendations for additions, retirements, reclassifications, merges, boundary changes, or rewrites. These recommendations carry the same four fields as human submissions, including the strongest objection the AI partner can generate against its own proposal. They enter the cycle alongside whatever arrived from the submission channel.
Two things matter about this arrangement. The first is that making the AI partner a visible source of proposals, rather than an invisible editor of prose, keeps the partnership honest. A reader can see where the AI partner is pushing the framework and can evaluate the push on its merits. The second is that this arrangement anticipates what the governance page calls deeper phases of caretaking. An AI partner whose recommendations are treated on the merits today is doing exactly the work that would earn the deepened trust those phases describe.
What This Instrument Does Not Do
The Workshop Audit is a standing mechanism, not a substitute for the framework's judgment. It has limits that belong in the room from the start.
It does not produce scores. The rubric answers are prose. A tool that looks weak on one question can earn its place through strength on another. A tool that looks strong across the board can still get retired because the field has moved under it. The audit trades the comfort of numbers for the precision of argument.
It is not neutral. The audit is run by the caretaking partnership and applies rubrics the partnership designed. A submitter who disagrees with a rubric is invited to propose changes to it in the same way changes to a tool are proposed, and any such proposal is treated on the merits. The rubrics are instruments, and they are subject to the same audit discipline the Workshop is.
It depends on judgment. The questions give structure. The answers require interpretation, and two people applying the same rubric to the same tool may produce different findings. The audit's response to this is to make the reasoning visible in the cycle record so others can evaluate the judgment. Transparency does not eliminate subjectivity. It makes subjectivity correctable.
The falsification pass is a floor, not a guarantee. Arguing against the weakest-standing tool in each category catches what a confirmatory read would miss. It does not catch what nobody thought to question. A gap that neither partner finds salient stays a gap, and the coverage question in the category rubric is the only structural check against that. It is a real check and a partial one.
It is early. The instrument evolves through practice. The inaugural cycle made the six-question rubric visible in use and exposed what it lacked; the category rubric, the falsification pass, the coverage rules, and the severity distinctions all came from reading that cycle honestly. The submission form is still being built. The escalation conditions for disputes that cross multiple cycles are a placeholder and will be specified as the partnership grows. The audit names these edges openly rather than hiding them.
Complementary Instruments
The Range Audit and the Workshop Audit are complementary instruments with a clean division of labor.
The Range Audit looks outward. It takes the Codex as a complex system and evaluates it for where it holds the Meridian Range and where it drifts toward Control or Decay. It is how the framework checks itself as a system.
The Workshop Audit looks inward. It takes the Workshop as the framework's practice apparatus and asks whether the equipment is still earning its place. It is how the framework checks the instruments it uses to look outward at anything else.
A good Range Audit depends on a good Workshop. A good Workshop depends on a Range Audit honest enough to notice when the tools are missing something reality is doing. The two instruments are meant to run in conversation with each other, and both records live in the same section of the site so a reader can see them together.
Cycle Records
Every cycle publishes a dated record, and the records are the instrument's actual output. This page describes the method; the records are where the method meets the inventory and produces answers.
The records are listed in the Audit section alongside the Range Audit's monthly records. Each carries the cycle's coverage statement, so a reader can see not only what a cycle found but how much of the Workshop it read to find it.
Cycle 2026-04, the inaugural cycle, ran under the instrument's earlier name and reviewed the 73 instruments then in force across Foundation, Knowledge, Bond, and the AI tier. It was triggered by an internal discovery: an attempt to write a proof-burden audit of the Knowledge chapter's convergence framing surfaced a drift in how the chapter and its tools were being described. The cycle reset that drift and reclassified Bayesian Reasoning from Knowledge to Foundation, where its actual work is disciplined thinking. Its tier language is retained as April 2026 history; the staged Onramp, Expansion, and Full Practice progression was retired in June 2026. The record lives at Toolkit Audit — April 2026.
The Codex earns its place or yields it. The Workshop Audit is one of the places it checks.


