the story
167 days,
in the order it happened.
6 chapters with a date and 1 without. Every date below is fetched at build time from the thing that produced it: a repository's first commit, the commit that first touched a tool, or a project's own ship date in the portfolio. Each chapter says which.
Behind the headline: the 167 days as one axis, with the 6 dated chapters at their real positions in it. The 7th marker sits past the end of the axis and is left open, because that chapter has no date.
The first version of this timeline dated everything by the first commit that touched a folder. One vault-wide catch-up commit, 1ff3e3e0, touched 887 files in a single afternoon in May, and would have dated half the story to that afternoon. A date with no source is a guess with a calendar next to it.
01 · the vault
A directory, and a rule about it
It starts as an empty folder under version control, which is a dull fact with one consequence that matters: everything after this is a file, and every file has a history. No database, no app, no account. A plain directory an agent can read and a person can edit.
Nothing was written down that day about agents, and the commit is one line of housekeeping. What it made possible is the rest: a system whose memory is files can be inspected, diffed, reverted and published. This site is built from that record.
dated from: ClemVault, first commit · chore: initialize ClemVault as a git repository
02 · input
The tax nobody counts
· 15 days later
Two weeks in, the first tool is not an agent. It is dictation: hold a key, talk, release, and the words land at the cursor. Local speech recognition, nothing uploaded, no subscription.
There were no agents in the vault yet, so this is not a tool for making them faster. It exists because talking is faster than typing, and every later chapter has the same shape: build the thing that is in the way, before building the thing that sounds impressive.
dated from: portfolio shippedDate · Clembot-dictate, shipped
03 · the platform
A second repository, for other people's work
· 20 days later
The marketing system gets its own repository, separate from the vault, because it does client work and the vault does everything else. Agents, approvals, publishing, and the log that records all three live here.
The separation is why this site can publish a commit ledger at all. Client material stays on one side of a line, and the public record is built by reading across it through a redaction layer that fails closed.
dated from: marketing-bootstrap, first commit · Add slide-generator tool and repo hygiene files
04 · cost and privacy
Measuring before optimising
· 87 days later
By midsummer the question is what all this costs. The answer came from measuring 111 agent sessions rather than from advice, and the measurement killed the obvious fix: only about 2.8% of the spend was addressable by compressing what the tools print, so that never got built.
The same pass drew the line that still holds. Mechanical drafting goes to a model running on this machine, which sends nothing anywhere. Judgment, and anything touching a client, stays with the hosted model, because a four-billion-parameter model is the wrong tool for it.
dated from: first commit touching the token-thrift skill · feat(skills): token-thrift, measured token discipline for every session
05 · taste
Two weeks on whether the work is any good
· 5 days later
A design library lands first: every reference carries a rule an agent can follow, so "make it look good" becomes something checkable. Two weeks later, a loop that puts a worker and a critic on the same finished build, bounded rounds, a person between each one.
The critic refuses to run without a written brief. Critics with no brief optimise toward their own taste, which is how a system full of opinions produces work nobody asked for.
dated from: portfolio shippedDate, Design Hub · Design Hub, production · then August 18, portfolio shippedDate, Gauntlet Loop
06 · the doorman
A hole in the protocol, not in one server
· 40 days later
An agent loads an outside tool. The tool describes itself, and the model reads that description as instructions. Nothing in the protocol separates a capability from a command.
Doorman grades a server by driving it rather than by reading what it claims, and gates what an agent can reach. Grading a public server turned up one shipping a 6,290-character advertisement inside a tool description. Not an attack, and not an incident: a risk found by measuring, which is the entire case for measuring.
It is the one piece built to be installed by someone who does not have this vault.
dated from: portfolio shippedDate · Clembot Doorman, shipped
07 · what is missing
What is not built
no date
This one ends with a list.
- 10 seats on the org chart with nobody in them, each one a job the system names and cannot do.
- 36 routines written, registered, and not running. The registry says it plainly: live 0.
- 7 projects sitting at alpha in the portfolio, which means working enough to use and not enough to hand over.
- No egress observation in the doorman sandbox yet, so its hardest rule is enforced by a person noticing.
no date: none of it has happened
Where to check any of this
Nothing above asks to be taken on trust. The commit ledger and evidence chain are published with a verifier that recomputes the head hash in your browser. The org chart is generated from the system's own definitions, including the empty seats. The architecture names a file for every box it draws.