Tier 4 of 4
Products built for the long term
The people will change before the product does. So the repo keeps a running log of what changed and why, and each work session leaves notes for the next one.
Set this repo up to ntent tier 4.
Fetch https://ntent.app/r/tier/4.json?with=signin and follow the plan in it exactly. Write every file verbatim, and check each file's sha256 against its step before you write it. That plan covers tiers 1 to 4, so it is everything, not just the tier 4 part. It also carries steps that follow from what the product is: people sign in, and what they see depends on who they are. Those are as required as the tier's own.
Skip any step whose "needs" this repo does not satisfy, and do not install a framework just to satisfy one. Run each step's verify line before you call it done, write the manifest the plan describes, then tell me what you installed and what you skipped.Reads https://ntent.app/r/tier/4.json?with=signin
Install plan35 steps
Includes all 35 steps from tiers 1 to 4, in install order. Each step ends with a quick check the agent must run before it says the step worked. At the end, it writes a short record of what it added, which version it came from, and what it skipped.
Prototypes & landing pages
6 steps · 01–06- 01Shared project instructionsA person checks this
Everyone inventing their own conventions, and every assistant inventing a different set again.
writes AGENTS.md · point CLAUDE.md at it with a one-line @AGENTS.md import
Then edit It is a template. Replace every <angle bracket>, delete the sections marked for tiers above yours, and cut any row of the enforcement table whose command this repo does not have.
Verify Ask an assistant "what are the rules in this repo" and it answers from the file.
- 02
2 rule files that disagree, because one tool reads CLAUDE.md and another reads AGENTS.md.
Skipped unless the repo has AGENTS.md.
Verify Run it twice: the second run says there is nothing to do. Then start a session and ask the assistant to name a rule that only exists in AGENTS.md. In Claude Code, /context lists CLAUDE.md under Memory files. Copy a line of AGENTS.md into CLAUDE.md and run it again: it names that line and leaves it where it is.
- 03Pre-commit checksBlocks the commit
A mistake caught an hour later on the build server, after someone has already spent time reviewing it. This catches it on your machine, before the commit.
writes scripts/git-hooks/pre-commit · make it executable
Verify Stage a file that fails a check this tier installs and the commit is refused, naming the check and the fix. At tier 1 that is check-env: add a variable to the env schema and not to .env.example. The hardcoded-colour case needs the tier 2 lint rules.
- 04
Store hook setup in git so every contributor and coding agent runs the same checks.
merges into package.json · inside the "scripts" block
Verify Run pnpm install, then `git config core.hooksPath` prints scripts/git-hooks. A fresh clone gets the same answer with no manual step. Leave .git/hooks alone: it may hold hooks somebody else installed.
- 05Environment variable checksBlocks the commit
A setting the app needs that is missing from .env.example, so someone who downloads the repo cannot start it and has no idea why. Also the reverse, and code that reads process.env directly instead of through the schema.
writes scripts/check-env.mjs
Then edit Point CONFIG.schemaFile at this repo’s env schema, CONFIG.exampleFile at its example file, and CONFIG.sourceDirs at the directories it keeps source in, if they are not src/env.ts, .env.example and src. The pre-commit hook reads those three back out of the file, so moving them keeps the gate wired.
Verify Add a variable to the schema, do not add it to .env.example, and the check names it.
- 06Decision logA person checks this
The same decision being re-made in month 6 because nobody remembers the reason for the first one.
writes DECISIONS.md
Then edit The first entry is an example from a billing app: delete it. Then write the decisions this project has actually made, one entry each, and label any whose source is memory rather than a thread or a call as "(from memory)". A fresh project may have none yet, and a file with only the template entry in it is correct.
Verify Every entry names a real decision, who agreed it and when. Nothing in the file is invented, and an entry reconstructed from memory says so.
A product with a fixed scope
15 steps · 07–21- 07Design convention lint rulesBlocks the commit
Catch hardcoded colours, font sizes, and interface strings. Flag spacing that does not adapt to right-to-left layouts.
writes scripts/eslint-rules.mjs · import it from eslint.config.mjs
Skipped unless the repo has ESLint flat config.
Verify Write text-[13px] in a component. pnpm lint fails and points at it.
- 08
A rule everyone believes is on, which has been silently off since a config change.
writes scripts/probes/rules.probe.tsx
Verify check-probes reports one hit per rule, and zero false hits.
- 09Lint rule probesBlocks the commit
Catch lint rules that have quietly stopped working: they miss what they should catch, complain about good code, or are switched off in one package.
writes scripts/check-probes.mjs
Then edit CONFIG.PACKAGES ships with one entry for a single-package repo. In a monorepo add one entry per package that lints, each naming a real source file in it.
Skipped unless the repo has eslint-rules.mjs, rules.probe.tsx.
Verify Break a rule pattern on purpose and the probe fails even though lint passes. Take the rules out of one package config and it names that package and says how many rules run nowhere in it.
- 10
Keep rule exceptions visible to reviewers. Record the reason, owner, and expiry so exceptions can be checked later.
writes scripts/lib/waivers.mjs
Skipped unless the repo has a checker of your own to import it.
Verify Waive a line with no reason and the run prints NO REASON GIVEN against it. Fix the underlying value and leave the waiver, and the next run names it as stale and tells you to delete it. Date one `until` yesterday and the finding comes back, naming the waiver that ran out.
- 11Design token checksBlocks the commit
Catch design token names that do not exist in the stylesheet, so the style silently does nothing. Also catch colours and sizes typed in by hand instead of taken from the tokens.
writes scripts/check-tokens.mjs
Then edit Point CONFIG.stylesheets at the generated stylesheet this repo actually ships, and list a family in CONFIG.ownedFamilies only once your tokens replace the framework’s scale for it.
Skipped unless the repo has a generated stylesheet, waivers.mjs.
Verify Write text-fg-nope next to a real text-fg-muted. The check names it, says it resolves to nothing, and lists the nearest real tokens. Delete every token in a family and it says that family is no longer checked rather than passing.
- 12API route checksBlocks the commit
A server endpoint that accepts form data without checking it, does not check who is asking, or has no limit on how often it can be called. Your forms talk to these directly, so a gap here is a gap in the UI.
writes scripts/check-api-routes.mjs
Then edit Set CONFIG.routeDirs to where this repo keeps its handlers, and add your own validation, auth and rate-limit helper names to the three matcher lists.
Verify Add a POST handler with no schema parse. The check names the file and the missing piece.
- 13Real data validationBlocks the commit
The app expects data in one shape and the server now sends another. On screen that looks like a column of NaN, an empty list when there is data, or Invalid Date.
writes scripts/verify-fixtures.mjs · put real captured payloads in fixtures/
Then edit It ships pointed at fixtures/ and src/lib/schemas/index.js. Change CONFIG.fixtureDir and CONFIG.schemaModule if this repo keeps either somewhere else.
Skipped unless the repo has Zod schemas, at least one captured payload.
Verify fixtures/invoice.json parses with InvoiceSchema. Change a field type in the schema and the check prints the field path and the reason. Replace a fixture with `[]` and it fails: an empty batch exercises nothing.
- 14Message placement rulesA person checks this
The same message written 2 different ways in one product. Or a pop-up toast for a problem that is still there after the toast fades away.
writes src/lib/errorToSurface.ts
Verify Every message in the product resolves to one of 4 surfaces: full-page empty state, inline, persistent banner, toast.
- 15
A message rule that reads well in a doc and does something else in code.
writes src/lib/errorToSurface.test.mjs
Verify node --test passes.
- 16
"Mostly done" as an answer. With this you can say the screens lift 80% of the model, here are the 3 named gaps, and one journey has no UI at all.
writes contract.json
Then edit It is an example billing product. Keep the shape and replace the actors, entities, journeys, rules, constraints and open questions with this product’s own. Delete the example acceptance records: they describe journeys you have not built.
Verify The coverage check runs and prints a number, and `--refs` says the references resolve. Start with entities and journeys; add a pillar when you can name the screen it changes. Mark a journey built only with its acceptance record beside it.
- 17Access rulesA person checks this
Define permissions and row access in one place. Use them to design gated navigation, empty lists, and disabled actions.
merges into contract.json · at the top level, after actors
Verify Point at a new route and ask which matrix row permits it. If the answer needs a conversation, the row is missing.
- 18Contract coveragePrints, does not block
Shows how much of the model is in the code, as 3 separate numbers: fields in the types, fields in real data, and fields the screens mention. Also catches the model contradicting itself: duplicate ids, links to things that do not exist, and a journey marked built while its questions are open or with no note of who saw it work.
writes scripts/check-contract-coverage.mjs
Then edit The maps at the top of the file describe an example billing app. Replace CONFIG.entityTypeMap, CONFIG.entityUiMap and CONFIG.fieldAliases with this product’s own entities, and point typeDirs/fixtureDirs/uiDirs at its directories.
Skipped unless the repo has contract.json, TypeScript.
Verify It prints a table with a percentage per entity, names the gaps, and says how many of the contract’s fields the number is even about. Under --check an unmapped entity fails until you map it or excuse it with a reason. Set minCoverage just below your current number so it fails when coverage goes backwards. `--refs` is the gate half: it runs in milliseconds, exits non-zero on a duplicate id or a broken reference, and every finding names its fix. None of it says a journey works: that is the journey’s state, set by hand, and `--refs` refuses `built` unless an acceptance record sits under it: who exercised it, when, at which commit, against what evidence.
- 19
Test that each contract check catches its target issue and stays quiet on valid cases.
writes scripts/check-contract-coverage.test.mjs
Skipped unless the repo has check-contract-coverage.mjs, contract.json.
Verify node --test passes. Break one reference in the contract by hand and exactly one test goes red, naming the check that caught it.
- 20
Find broken local setup and missing generated files. Give new contributors a clear list of issues to fix.
writes scripts/doctor.sh · make it executable
Verify Run it on a fresh clone. Every line is a pass, or names the one thing to fix.
- 21Session status reportPrints, does not block
Report issues that cannot block offline work. Flag generated files that are older than their sources.
writes scripts/session-status.sh · make it executable
Verify It prints when someone opens the repo, which is the moment they can act on it. Touch a token source without rebuilding and it tells you that you are looking at the previous build.
Apps with a shared design system
7 steps · 22–28- 22Translation key checksBlocks the commit
A t('key') with no entry in the base locale. A key in the base locale missing from a translation. An incomplete plural set.
writes scripts/check-locale-keys.mjs
Skipped unless the repo has more than one language, or the certainty you will have one.
Verify Add a t() call with a new key and no entry. The commit is refused. Before messages/ exists it says there is nothing to check yet and lets the commit through, so taking the locales capability on day one costs nothing.
- 23Shared component checksBlocks the commit
Find shared components left in route folders and duplicate component names. Require a reason and an expiry date for exceptions.
writes scripts/check-stray-components.mjs
Then edit Point CONFIG at this repo’s route and shared-component directories if they are not src/app and src/components.
Verify Import a private component from a second route and the check tells you to promote it. Allowlist it and the reason and date print on every run afterwards, rather than the finding disappearing. Backdate the entry and it fails.
- 24Import boundariesBlocks the commit
Server code pulled into code that runs in the browser, which can send your secret keys to every visitor. Also real code depending on something in the experiments folder.
merges into eslint.config.mjs
Verify Import a server util into a "use client" file. Lint refuses it by name.
- 25Rules by file pathA person checks this
Load local rules only where they apply. Keep shared project instructions short enough to read.
writes .claude/rules/copy-a-sibling.md · one file per concern, named after the rule
Then edit It is a template. Set the paths it applies to and write the rule in this repo’s own terms.
Skipped unless the repo has AGENTS.md.
Verify Open a file the rule’s paths cover and ask the assistant to state the rule. It answers without being shown the file.
- 26Source priorityA person checks this
Set a clear priority when sources disagree. Record the resolution so the team can find it later.
merges into contract.json · at the top level
Verify 2 sources disagree, and the argument takes 30 seconds instead of a meeting.
- 27Rule approvalsA person checks this
Keep the approval source beside each rule. Make it clear who agreed to it and when.
merges into contract.json · on each entry in rules
Verify Every rule names a person and a date, and quotes them where the wording matters.
- 28Product entitlementsA person checks this
Define paid features and quotas. Cover access near the limit, at the limit, and after a downgrade.
merges into contract.json · at the top level. A plan is not an entity
Verify Every gate names what a person who has not paid sees. Ask the model which journeys have a paywall in them and get an answer before QA does.
Products built for the long term
7 steps · 29–35- 29
The build log silently recording nothing, because the file it writes to was never created.
writes docs/build-log/_pending.md
Verify The file exists before the first commit, so the very first stub lands rather than being dropped.
- 30
The build log writing into a file git tracks, so every commit leaves a new change behind and the repo never looks clean.
merges into .gitignore · one line, anywhere in the file
Skipped unless the repo has docs/build-log/_pending.md.
Verify Commit twice, then run git status. The stubs are there and the tree is clean.
- 31
Nobody being able to answer "what changed last week" without reading 200 commit messages.
writes scripts/git-hooks/post-commit · make it executable
Skipped unless the repo has docs/build-log/_pending.md ignored by git.
Verify Commit twice. docs/build-log/_pending.md has 2 stubs and `git status` is clean, because the queue is ignored.
- 32Session handoffA person checks this
Every session starting with 20 minutes of rediscovering what was in flight. Keep a hard size cap, or it becomes a second unmaintained doc.
writes STATE.md
Verify Open it cold after a week and know the next action in under a minute.
- 33Research instructionsA person checks this
Someone building from the first document they found, which is usually the most detailed one rather than the agreed one.
merges into AGENTS.md · as a new section
Verify A new joiner reads 4 things and starts, instead of reading everything and stalling.
- 34Generated file markersA person checks this
Mark files that can be regenerated safely. Keep custom logic out of files that the generator replaces.
applies to · the first 3 lines of every generated file
Verify Run the generator twice. Nothing hand-written is lost.
- 35Gradual rule rolloutPrints, does not block
A new rule that cannot be turned on because 200 existing files break it, so it never gets turned on at all.
merges into eslint.config.mjs · at the top of the file, beside the rules block
Verify Lint warns on the listed files and errors everywhere else. Move your clock past the date without emptying the list and the config refuses to load, naming what is left.