Tool Engineering.
A machine that carries a real human pain, once it's been found and confirmed worth solving, all the way to a verified product. The builder is never the judge of its own work.
This is the other half of the loop. The Pain Point Pipeline decides what deserves to be built; Tool Engineering is what happens when the deciding is fully separated from the building. A fresh session designs; a separate session tries to knock the design down before a line of code exists to defend it; the session that builds the product is never shown the suite it will be judged against, so there is no way for it to write toward the answer. A human still says yes at a few real decisions: is this worth building, is this the right direction, does the working prototype earn a real build, does the finished thing actually ship. Everywhere else, it runs itself.
Seven stages.
- S0 · Intake — a qualified pain arrives and the conductor gives the product a repo of its own, a real commitment rather than an idea on a list. (Gate G0: I decide it's worth the factory's time at all.)
- S1 · Design — a fresh session, with no memory of anything that came before it, has to write the product direction as an artifact that can be checked rather than simply trusted. (Gate G1: I approve the direction before a line of code exists.)
- S2 · Design-research — the direction gets interrogated, not rubber-stamped: every claim it rests on has to carry a citation, and a separate session's whole job is to try to knock it down.
- S3 · Spec — what survives becomes the buildable contract, the thing every later stage is held to and can be checked against.
- S4 · Validation — a real prototype gets built so there's finally something to react to instead of a plan. (Gate G2: I kill it, pivot it, or let it continue.)
- S5 · Build — the builder writes the actual app with no visibility into the tests it will be judged by, so there is no way to write toward the answer.
- S6 · Verify + ship — a holdout suite that had to fail before the build existed runs against what got built, and only a pass earns the ship. (Gate G3: I approve it for the real world.)
No model decides its own grade.
That single rule is the whole architecture: a stage is only allowed to advance when a code predicate has independently confirmed its artifacts exist and actually pass, never because a model announced its own work was good. Nothing softer than that counts. A gate that can't fail isn't a gate at all, which is why every gate — down to each individual permission rule — carries a test built specifically to fail it.
The builder never gets to see what it's being judged against. The acceptance suite lives entirely outside the product's own repo, walled off from the build session, with a tripwire standing by afterward to audit the transcript for any sign it leaked through. A build can't write toward a test it was never shown. And every stage runs in its own fresh session holding only the permission it strictly needs, so that a read-only stage isn't trusted not to write — it's physically incapable of it.
Four decisions, mine to make.
The factory runs itself for everything in between. At exactly four points it stops outright and waits, because the call on the other side of that pause isn't one it should be trusted to make alone.
Keeping the conductor dumb.
The conductor stays plain Python on purpose, because the instant a model gets to decide whether the work is allowed to proceed, the entire guarantee this factory exists to provide disappears. Everything hard was built around protecting that one constraint: headless sessions that genuinely write files instead of describing writing them, permission profiles enforced as strict deny-complements so a read-only stage can't quietly become something else, a heartbeat that never mistakes a product waiting patiently at a gate for a product that died.
Where it runs. Inside AJO, fed by the Pain Point Pipeline. Currently attended, one stage at a time. Code is private; this page is the record.