The engine is not the product
Split a broad thesis into an engine and one thing someone can buy, so the product shell can never become a second copy of the evidence store.
The decision
Conduit and Threadout are two systems in two repositories. Threadout is a thin product shell. Conduit is the private evidence and detection authority. The shell asks; the engine decides.
The boundary is not a preference about repository layout. It is one rule: the product shell stores no evidence and runs no detection. Everything else follows from that.
Why the split
A thesis is not a thing anyone can buy. Conduit is broad — preserve intent across the tools work crosses. That is the right size for an engine and the wrong size for a first sale. Threadout is one narrow output of it, sold as one bounded piece of work, and narrowing it that far is what made it shippable in the first place.
Keeping them as one system would have meant the surface someone buys and the authority that decides what is true were the same code, changed together, deployed together, and reasoned about together. They have different clocks. The shell changes when a customer needs something. The engine changes when the judgement changes. Merging them makes every product change a change to the thing the product’s claims rest on.
Why the shell stores nothing
This is the clause I would defend hardest, and it is the one that is cheapest to break later.
A shell that stores evidence starts as a cache. Something is slow, so a copy is kept close to the surface that renders it. The moment that copy exists there are two answers to the same question, and they diverge the first time one of them is written to. From then on the system has no authority — it has two opinions, and whichever one is on screen wins.
There is also a much more ordinary reason. Evidence in this system is other people’s conversations. If a customer asks for it to be gone, the honest answer requires there to be exactly one place it lives. A cache in the shell turns a deletion into a search.
So the shell holds identity, tenancy, and the record of who approved what. It holds an explicit, versioned binding to the engine. It does not hold a single line of anyone’s transcript.
The cost, stated plainly
Two repositories, cross-repo work for anything that spans the seam, and a binding that has to be versioned because two systems now ship on separate clocks. That is real overhead and I pay it every week.
How I will know I was wrong
If I ever find myself adding a table to the shell “just to cache” something the engine already owns, the split has failed and I should say so here rather than quietly widen the shell. The rule is worth nothing if the first performance problem retires it.
← All notes