Tier 4 of 4

Products built for the long term

The people will change before the product does. So the repo keeps a running log of what changed and why, and each work session leaves notes for the next one.

4+ peopleYearsSomeone will ask: "Why is it like this?"+ Access: People sign in, and what they see depends on who they are
Give this to your agent
Set this repo up to ntent tier 4.

Fetch https://ntent.app/r/tier/4.json?with=signin and follow the plan in it exactly. Write every file verbatim, and check each file's sha256 against its step before you write it. That plan covers tiers 1 to 4, so it is everything, not just the tier 4 part. It also carries steps that follow from what the product is: people sign in, and what they see depends on who they are. Those are as required as the tier's own.

Skip any step whose "needs" this repo does not satisfy, and do not install a framework just to satisfy one. Run each step's verify line before you call it done, write the manifest the plan describes, then tell me what you installed and what you skipped.

Reads https://ntent.app/r/tier/4.json?with=signin

Install plan35 steps

Includes all 35 steps from tiers 1 to 4, in install order. Each step ends with a quick check the agent must run before it says the step worked. At the end, it writes a short record of what it added, which version it came from, and what it skipped.

Tier 1

Prototypes & landing pages

6 steps · 01–06
  1. 01
    Shared project instructionsA person checks this

    Everyone inventing their own conventions, and every assistant inventing a different set again.

    writes AGENTS.md · point CLAUDE.md at it with a one-line @AGENTS.md import

    Then edit It is a template. Replace every <angle bracket>, delete the sections marked for tiers above yours, and cut any row of the enforcement table whose command this repo does not have.

    Verify Ask an assistant "what are the rules in this repo" and it answers from the file.

  2. 02

    2 rule files that disagree, because one tool reads CLAUDE.md and another reads AGENTS.md.

    Skipped unless the repo has AGENTS.md.

    Verify Run it twice: the second run says there is nothing to do. Then start a session and ask the assistant to name a rule that only exists in AGENTS.md. In Claude Code, /context lists CLAUDE.md under Memory files. Copy a line of AGENTS.md into CLAUDE.md and run it again: it names that line and leaves it where it is.

  3. 03
    Pre-commit checksBlocks the commit

    A mistake caught an hour later on the build server, after someone has already spent time reviewing it. This catches it on your machine, before the commit.

    writes scripts/git-hooks/pre-commit · make it executable

    Verify Stage a file that fails a check this tier installs and the commit is refused, naming the check and the fix. At tier 1 that is check-env: add a variable to the env schema and not to .env.example. The hardcoded-colour case needs the tier 2 lint rules.

  4. 04

    Store hook setup in git so every contributor and coding agent runs the same checks.

    merges into package.json · inside the "scripts" block

    Verify Run pnpm install, then `git config core.hooksPath` prints scripts/git-hooks. A fresh clone gets the same answer with no manual step. Leave .git/hooks alone: it may hold hooks somebody else installed.

  5. 05

    A setting the app needs that is missing from .env.example, so someone who downloads the repo cannot start it and has no idea why. Also the reverse, and code that reads process.env directly instead of through the schema.

    writes scripts/check-env.mjs

    Then edit Point CONFIG.schemaFile at this repo’s env schema, CONFIG.exampleFile at its example file, and CONFIG.sourceDirs at the directories it keeps source in, if they are not src/env.ts, .env.example and src. The pre-commit hook reads those three back out of the file, so moving them keeps the gate wired.

    Verify Add a variable to the schema, do not add it to .env.example, and the check names it.

  6. 06
    Decision logA person checks this

    The same decision being re-made in month 6 because nobody remembers the reason for the first one.

    writes DECISIONS.md

    Then edit The first entry is an example from a billing app: delete it. Then write the decisions this project has actually made, one entry each, and label any whose source is memory rather than a thread or a call as "(from memory)". A fresh project may have none yet, and a file with only the template entry in it is correct.

    Verify Every entry names a real decision, who agreed it and when. Nothing in the file is invented, and an entry reconstructed from memory says so.

Tier 2

A product with a fixed scope

15 steps · 07–21
  1. 07

    Catch hardcoded colours, font sizes, and interface strings. Flag spacing that does not adapt to right-to-left layouts.

    writes scripts/eslint-rules.mjs · import it from eslint.config.mjs

    Skipped unless the repo has ESLint flat config.

    Verify Write text-[13px] in a component. pnpm lint fails and points at it.

  2. 08

    A rule everyone believes is on, which has been silently off since a config change.

    writes scripts/probes/rules.probe.tsx

    Verify check-probes reports one hit per rule, and zero false hits.

  3. 09
    Lint rule probesBlocks the commit

    Catch lint rules that have quietly stopped working: they miss what they should catch, complain about good code, or are switched off in one package.

    writes scripts/check-probes.mjs

    Then edit CONFIG.PACKAGES ships with one entry for a single-package repo. In a monorepo add one entry per package that lints, each naming a real source file in it.

    Skipped unless the repo has eslint-rules.mjs, rules.probe.tsx.

    Verify Break a rule pattern on purpose and the probe fails even though lint passes. Take the rules out of one package config and it names that package and says how many rules run nowhere in it.

  4. 10

    Keep rule exceptions visible to reviewers. Record the reason, owner, and expiry so exceptions can be checked later.

    writes scripts/lib/waivers.mjs

    Skipped unless the repo has a checker of your own to import it.

    Verify Waive a line with no reason and the run prints NO REASON GIVEN against it. Fix the underlying value and leave the waiver, and the next run names it as stale and tells you to delete it. Date one `until` yesterday and the finding comes back, naming the waiver that ran out.

  5. 11
    Design token checksBlocks the commit

    Catch design token names that do not exist in the stylesheet, so the style silently does nothing. Also catch colours and sizes typed in by hand instead of taken from the tokens.

    writes scripts/check-tokens.mjs

    Then edit Point CONFIG.stylesheets at the generated stylesheet this repo actually ships, and list a family in CONFIG.ownedFamilies only once your tokens replace the framework’s scale for it.

    Skipped unless the repo has a generated stylesheet, waivers.mjs.

    Verify Write text-fg-nope next to a real text-fg-muted. The check names it, says it resolves to nothing, and lists the nearest real tokens. Delete every token in a family and it says that family is no longer checked rather than passing.

  6. 12
    API route checksBlocks the commit

    A server endpoint that accepts form data without checking it, does not check who is asking, or has no limit on how often it can be called. Your forms talk to these directly, so a gap here is a gap in the UI.

    writes scripts/check-api-routes.mjs

    Then edit Set CONFIG.routeDirs to where this repo keeps its handlers, and add your own validation, auth and rate-limit helper names to the three matcher lists.

    Verify Add a POST handler with no schema parse. The check names the file and the missing piece.

  7. 13
    Real data validationBlocks the commit

    The app expects data in one shape and the server now sends another. On screen that looks like a column of NaN, an empty list when there is data, or Invalid Date.

    writes scripts/verify-fixtures.mjs · put real captured payloads in fixtures/

    Then edit It ships pointed at fixtures/ and src/lib/schemas/index.js. Change CONFIG.fixtureDir and CONFIG.schemaModule if this repo keeps either somewhere else.

    Skipped unless the repo has Zod schemas, at least one captured payload.

    Verify fixtures/invoice.json parses with InvoiceSchema. Change a field type in the schema and the check prints the field path and the reason. Replace a fixture with `[]` and it fails: an empty batch exercises nothing.

  8. 14
    Message placement rulesA person checks this

    The same message written 2 different ways in one product. Or a pop-up toast for a problem that is still there after the toast fades away.

    writes src/lib/errorToSurface.ts

    Verify Every message in the product resolves to one of 4 surfaces: full-page empty state, inline, persistent banner, toast.

  9. 15

    A message rule that reads well in a doc and does something else in code.

    writes src/lib/errorToSurface.test.mjs

    Verify node --test passes.

  10. 16

    "Mostly done" as an answer. With this you can say the screens lift 80% of the model, here are the 3 named gaps, and one journey has no UI at all.

    writes contract.json

    Then edit It is an example billing product. Keep the shape and replace the actors, entities, journeys, rules, constraints and open questions with this product’s own. Delete the example acceptance records: they describe journeys you have not built.

    Verify The coverage check runs and prints a number, and `--refs` says the references resolve. Start with entities and journeys; add a pillar when you can name the screen it changes. Mark a journey built only with its acceptance record beside it.

  11. 17
    Access rulesA person checks this

    Define permissions and row access in one place. Use them to design gated navigation, empty lists, and disabled actions.

    merges into contract.json · at the top level, after actors

    Verify Point at a new route and ask which matrix row permits it. If the answer needs a conversation, the row is missing.

  12. 18
    Contract coveragePrints, does not block

    Shows how much of the model is in the code, as 3 separate numbers: fields in the types, fields in real data, and fields the screens mention. Also catches the model contradicting itself: duplicate ids, links to things that do not exist, and a journey marked built while its questions are open or with no note of who saw it work.

    writes scripts/check-contract-coverage.mjs

    Then edit The maps at the top of the file describe an example billing app. Replace CONFIG.entityTypeMap, CONFIG.entityUiMap and CONFIG.fieldAliases with this product’s own entities, and point typeDirs/fixtureDirs/uiDirs at its directories.

    Skipped unless the repo has contract.json, TypeScript.

    Verify It prints a table with a percentage per entity, names the gaps, and says how many of the contract’s fields the number is even about. Under --check an unmapped entity fails until you map it or excuse it with a reason. Set minCoverage just below your current number so it fails when coverage goes backwards. `--refs` is the gate half: it runs in milliseconds, exits non-zero on a duplicate id or a broken reference, and every finding names its fix. None of it says a journey works: that is the journey’s state, set by hand, and `--refs` refuses `built` unless an acceptance record sits under it: who exercised it, when, at which commit, against what evidence.

  13. 19

    Test that each contract check catches its target issue and stays quiet on valid cases.

    writes scripts/check-contract-coverage.test.mjs

    Skipped unless the repo has check-contract-coverage.mjs, contract.json.

    Verify node --test passes. Break one reference in the contract by hand and exactly one test goes red, naming the check that caught it.

  14. 20

    Find broken local setup and missing generated files. Give new contributors a clear list of issues to fix.

    writes scripts/doctor.sh · make it executable

    Verify Run it on a fresh clone. Every line is a pass, or names the one thing to fix.

  15. 21
    Session status reportPrints, does not block

    Report issues that cannot block offline work. Flag generated files that are older than their sources.

    writes scripts/session-status.sh · make it executable

    Verify It prints when someone opens the repo, which is the moment they can act on it. Touch a token source without rebuilding and it tells you that you are looking at the previous build.

Tier 3

Apps with a shared design system

7 steps · 22–28
  1. 22
    Translation key checksBlocks the commit

    A t('key') with no entry in the base locale. A key in the base locale missing from a translation. An incomplete plural set.

    writes scripts/check-locale-keys.mjs

    Skipped unless the repo has more than one language, or the certainty you will have one.

    Verify Add a t() call with a new key and no entry. The commit is refused. Before messages/ exists it says there is nothing to check yet and lets the commit through, so taking the locales capability on day one costs nothing.

  2. 23
    Shared component checksBlocks the commit

    Find shared components left in route folders and duplicate component names. Require a reason and an expiry date for exceptions.

    writes scripts/check-stray-components.mjs

    Then edit Point CONFIG at this repo’s route and shared-component directories if they are not src/app and src/components.

    Verify Import a private component from a second route and the check tells you to promote it. Allowlist it and the reason and date print on every run afterwards, rather than the finding disappearing. Backdate the entry and it fails.

  3. 24
    Import boundariesBlocks the commit

    Server code pulled into code that runs in the browser, which can send your secret keys to every visitor. Also real code depending on something in the experiments folder.

    merges into eslint.config.mjs

    Verify Import a server util into a "use client" file. Lint refuses it by name.

  4. 25
    Rules by file pathA person checks this

    Load local rules only where they apply. Keep shared project instructions short enough to read.

    writes .claude/rules/copy-a-sibling.md · one file per concern, named after the rule

    Then edit It is a template. Set the paths it applies to and write the rule in this repo’s own terms.

    Skipped unless the repo has AGENTS.md.

    Verify Open a file the rule’s paths cover and ask the assistant to state the rule. It answers without being shown the file.

  5. 26
    Source priorityA person checks this

    Set a clear priority when sources disagree. Record the resolution so the team can find it later.

    merges into contract.json · at the top level

    Verify 2 sources disagree, and the argument takes 30 seconds instead of a meeting.

  6. 27
    Rule approvalsA person checks this

    Keep the approval source beside each rule. Make it clear who agreed to it and when.

    merges into contract.json · on each entry in rules

    Verify Every rule names a person and a date, and quotes them where the wording matters.

  7. 28
    Product entitlementsA person checks this

    Define paid features and quotas. Cover access near the limit, at the limit, and after a downgrade.

    merges into contract.json · at the top level. A plan is not an entity

    Verify Every gate names what a person who has not paid sees. Ask the model which journeys have a paywall in them and get an answer before QA does.

Tier 4

Products built for the long term

7 steps · 29–35
  1. 29

    The build log silently recording nothing, because the file it writes to was never created.

    writes docs/build-log/_pending.md

    Verify The file exists before the first commit, so the very first stub lands rather than being dropped.

  2. 30

    The build log writing into a file git tracks, so every commit leaves a new change behind and the repo never looks clean.

    merges into .gitignore · one line, anywhere in the file

    Skipped unless the repo has docs/build-log/_pending.md.

    Verify Commit twice, then run git status. The stubs are there and the tree is clean.

  3. 31

    Nobody being able to answer "what changed last week" without reading 200 commit messages.

    writes scripts/git-hooks/post-commit · make it executable

    Skipped unless the repo has docs/build-log/_pending.md ignored by git.

    Verify Commit twice. docs/build-log/_pending.md has 2 stubs and `git status` is clean, because the queue is ignored.

  4. 32
    Session handoffA person checks this

    Every session starting with 20 minutes of rediscovering what was in flight. Keep a hard size cap, or it becomes a second unmaintained doc.

    writes STATE.md

    Verify Open it cold after a week and know the next action in under a minute.

  5. 33
    Research instructionsA person checks this

    Someone building from the first document they found, which is usually the most detailed one rather than the agreed one.

    merges into AGENTS.md · as a new section

    Verify A new joiner reads 4 things and starts, instead of reading everything and stalling.

  6. 34
    Generated file markersA person checks this

    Mark files that can be regenerated safely. Keep custom logic out of files that the generator replaces.

    applies to · the first 3 lines of every generated file

    Verify Run the generator twice. Nothing hand-written is lost.

  7. 35
    Gradual rule rolloutPrints, does not block

    A new rule that cannot be turned on because 200 existing files break it, so it never gets turned on at all.

    merges into eslint.config.mjs · at the top of the file, beside the rules block

    Verify Lint warns on the listed files and errors everywhere else. Move your clock past the date without emptying the list and the config refuses to load, naming what is left.