This log records meaningful product, architecture, and launch decisions so Lucia remembers why it has its current shape. A decision is dated by the record that carries the founder’s words, never by a Linear status. Company-internal process decisions (fleet, seats, review policy) live in the separately owned Workbench documentation, not here.
2026-09-09 — Lucia and Villa Valentin are written with a plain i
Decision: “We wanti. Always. Never í.” The names are written Lucia and Villa Valentin on every surface: sender names, templates, footers, fixtures, tool descriptions, copy, and documentation.
Why: The sender name on the payment request still carried acutes; the founder ruled the plain form the company standard.
Consequence: One sweep per repository (Engine, Admin, Fieldwork API) with a pin that fails on any í in served copy. The sender display name on the Development Engine is an environment value set by the founder’s hand and is unverified here. Built; founder verdict open on the record.
See: Lucia and Valentin lose the acutes (LUCI-238).
2026-09-09 — No left accent bars; one dress on every element; the Masthead
Decision (no left accent bars): “This ‘left vertical bar’ is becoming a Claude Code default design element and I do not want it in Lucia.” A card or step is set apart by its ground, its stroke, and its type, never by a coloured stripe down its left edge. Joins the no-pill rule as a standing design law (No left accent bars, LUCI-239). Decision (one dress): “We need to get all of the interface elements to match. This is a linear style upgrade.” Housings at 0.3rem with the shared stroke and shadow, buttons at 3–5px, chips at 3px; neverrounded-md or larger on a button, card, field, or chip; dots and beacons stay round; no blur blooms, no heavy shadows, no pills. Cut surface by surface, the CI guard last (Every interface element matches, LUCI-249).
Decision (Masthead): “All pages require a uniform masthead housing unless otherwise ruled on by the founder.” The Masthead is the first housing on a page; its plane is 77px from the viewport top and its rule sits 24px above and below. Retired names: top housing, header band, panel shell, the plate. Exception by founder ruling (2026-09-09 ~9:15 PM PT): the guest record keeps its bare title (Masthead top-housing law, LUCI-262; Payment page dress pass, LUCI-240).
Consequence: Presentation-only children per surface; the admin’s remaining surfaces are not claimed as matching until each child lands. The Fieldwork app and the docked panel take the bars law on their next pass.
2026-09-09 — Three dots in Focus, the orb only in the docked panel
Decision: “I liked the three dots we had before. Users are used to that.” Two in-flight animations, each meaning one thing: three dots in the dashboard’s Focus conversation (“Lucia is typing a reply”); the composing orb only in the docked Lucia panel (“Lucia is working on the house”). Both are Motion Library recipes in one colour family. Context: On 2026-09-07 the founder chose to adopt an existing orb library rather than recreate one (“this is one mechanism/animation/motion library that may be worth adopting quickly and not trying to recreate”). The Lucia Orbit stays the loader wherever Lucia’s avatar is the anchor. See: Lucia shows she is working (LUCI-222), Focus types with three dots (LUCI-244). Built; founder verdict open.2026-09-08 — Resend carries the payment request
Decision: “We really need to add a real email being sent out here.” The guest-facing payment request leaves through Resend in the formatted guest-mail family, beside the booking magic link and the guest agent’s mail. Postmark stays the employee-facing maintenance thread; SMS stays on Twilio. The request ledger records the provider and message id. Follow-on ruling (2026-09-09): every button in the guest-mail family is a centred rectangle with 4–5px corners, never a pill (Guest mail buttons are rectangles, LUCI-237). Verified behavior: Completed 2026-09-09 on the Development Engine; founder proof on 2026-09-08 (“Beautiful.”). Supersedes the waitlist-only scope of the 2026-05-11 Resend decision below without erasing it. See: Payment request rides the Resend template (LUCI-232); Resend Waitlist Outbound Email.2026-09-06 — Real Stripe, test now, live possible but never on by default
Decision: “We should integrate it in a way that can flip to a live site/launch easily. Test now → flip to live.” The payment record carries real Stripe doors executed only on the owner’s tap; oneSTRIPE_MODE setting (test or live) selects the key pair, webhook secret, and Checkout hosts; no code path differs between modes; the live flip is a founder decision.
Companion ruling (payment draft, 2026-09-05 / 06): the payment ask is one gateway task pinned to Fable with no fallback model. If Fable cannot draft, the step says so and offers Copy link only (“quiet and honest”). The no-fallback setting on the Development Engine is set by the founder’s hand and is unverified here.
Consequence: Stripe live mode is not on; production is gated on a later round. Built on Development; founder verdicts open.
See: Quinn’s payment record fixes the payment (LUCI-215), Lucia asks Quinn for a new card (LUCI-210), Lucia couldn’t write the payment ask (LUCI-220).
2026-09-05 — The workspace is the nucleus; the truth closes the step
Decision: The workspace is “the nucleus of the product.” Every step completes inline, with a quick link or the solution opened in place, or by tapping Lucia’s avatar and finishing it in natural language. The truth closes the step, not a Save button. Lucia is beside every step: “I would want to be able to tap her avatar and chat with her about what’s going on.” Consequence: The payment step lost its Save button and gained Send email · Send text · Copy link; a payment item closes only when Stripe truth changes; the payment step and the payment record become one surface. The DAW stays a one-item finisher; the booking page is the working frame (ruled 2026-09-03, Booking page works the arrival, LUCI-182). See: Lucia asks Quinn for a new card (LUCI-210), Lucia beside every step (LUCI-211), Payment step is the payment record (LUCI-219).2026-09-04 — Fable is Lucia’s voice; Focus answers from one brain, no fallback
Decision (2026-09-03 evening, executed 2026-09-04): “I think Anthropic’s models should be her predominant voice.” The Engine gateway resolves the provider from the model id; any task can be pointed at an Anthropic model by configuration. Focus house composition runs onclaude-fable-5-1 on the Development Engine (“Keep Fable on”). The fleet-wide default flip is a founder call not yet made; the default stays gpt-5.6-sol.
Decision (2026-09-04): “But if we can retire it, let’s do it.” The legacy Focus intent-assist router and the refinement pass leave the served Focus route. When the composition cannot answer, Focus says so in one owner-language sentence and offers at most one door it already holds. No fallback model, no menu, no canned “best next move.”
Consequence: The ledger records provider, resolved model, request id, latency, and fallback on every gateway call. The Fieldwork conversation stays on GPT. Supersedes the 2026-07-12 “both surfaces use gpt-5.6-sol” state for the Engine’s Focus composition without erasing that dated record. Built; founder verdicts open.
See: Fable is Lucia’s voice (ALGO-39), Focus answers from one brain (ALGO-40), Focus reads the whole house (LUCI-189).
2026-09-03 — Property time is the only clock; a stay begins at check-in
Decision: “This logic needs to get baked into the product now. This should never be exposed to the property owner.” Every owner-facing day word and clock word is reckoned in the property’s zone and shown as plain local time; no zone names, UTC, offsets, “local time” qualifiers, or ISO timestamps ever surface. The operator’s own clock is never mentioned to the owner either. Companion ruling: a stay begins at check-in (2 PM at the Villa); an open item that threatens a specific stay inside the window before arrival and has had no operator touch escalates as one loud card per arrival. Consequence: Check-in and check-out times are property data set by the owner, never constants inside the Algorithm. Phases shipped across Engine, Admin, and the Fieldwork API on 2026-09-03; founder verdict open. See: Property time is the only clock (ALGO-34), Today means the property’s today (ALGO-30), Unattended near check-in escalates (ALGO-31).2026-09-02 — Signal Stream speaks owner language
Decision: “All engine/dev language replaced for real-world/human language that a property owner would understand.” Every served human-facing string uses the owner’s vocabulary (guest names, dates, money, rooms, vendors), never engine or dev words; one plain sentence that says what to do or what changed; numbers as an owner would say them. Consequence: Rules R1–R10 and an owner-language scan pin the served copy; a copy change is gated by the replay harness showing deltas confined to display fields. Built on Development; founder verdict open. See: Signal Stream speaks owner language (ALGO-29).2026-08-29 — The draft routing law (Fieldwork)
Decision: “Clicking the edit button from that draft always goes to the form. It never goes back to the chat. Chatting with Lucia should always start fresh UNLESS a structured draft card was created by Lucia in the chat.” Leaving chat with unsent text, by any button or by multitasking away, saves a titled draft and clears the composer. No draft ever opens into chat; an edit goes to the manual form; any exception needs the founder’s explicit yes. Consequence: Completed 2026-08-30 and live onluciafieldwork.ai. This is the law Canon Wave 3 names as “the draft routing law.”
See: Leaving chat saves and clears (FILD-133).
2026-08-25 — JetBrains Mono is the machine-truth register
Decision: Machine-truth labels (truth-state and category chips, ranking traces) are set in JetBrains Mono; “founder approved and will be spread around the UI over time where we decide.” Mono is never used for the owner’s words. See: Spotlight labels go mono (LUCI-165), completed 2026-08-25.2026-08-22 — Tips are a TipKit clone
Decision: “Tipkit iOS clone. That’s what we use for our tooltips/design/guides throughout the entire app (and probably the entire platform).” In-app coach marks anchored to first real moments, dismissed with ✕, Next, or Close, seen-state persisted; never an external guide. Design laws bind in full (no pills, 3–4px corners, capture never slowed). See: Tooltip guides in Fieldwork App (FILD-100); the founder’s directive of 2026-08-21 opened the record.2026-08-15 — Legacy docs redirect home
Decision executed:docs.hellolucia.ai and docs.evaluationlabs.ai answer with a permanent (301) redirect to https://helloluciallc.com; no Obsidian-era content is served. This closes the redirect intent of the 2026-06-23 unify-docs decision below.
Verified: Completed 2026-08-15; both roots re-read 2026-09-10.
See: Legacy docs redirect home (HLLC-24); ADR - Unify Docs into Mintlify Library.
2026-07-12 — Keep Engine and Guest Agent model configuration independent
Decision: Lucia Engine and Lucia Guest Agent own separate model-configuration and runtime-verification boundaries. A model value verified for one surface must not be inherited, inferred, or presented as proof for the other. State verified on 2026-07-12: Both surfaces usedgpt-5.6-sol. The Guest Agent selected its model through its own deployment configuration and source fallback; Lucia Engine retained its separately owned configuration and runtime-provenance contract.
Verification policy: Each surface requires its own deployed configuration and provider-returned model evidence. Shared use of the OpenAI Responses API does not collapse the two runtime boundaries.
Compatibility consequence: Guest Agent model upgrades must preserve its prompts, verification flow, routing, schemas, and core SSE event contract (start, token, cta, meta, done) unless a separately authorized change says otherwise. Its embeddings model remains independently configured as text-embedding-3-small.
Historical continuity: The dated 2026-06-04 Guest Agent model-doctrine record and 2026-04-26 model-layer decision remain historical evidence. This decision supersedes the former Guest Agent default for current configuration without erasing those dated decisions.
2026-07-10 — Require runtime provenance for model verification
Decision: Treat runtime and model provenance from the same authenticated Engine response as the evidence contract for Eval Labs model verification. Preserve the stable response envelope while reporting Engine identity and model-path evidence through typed provenance fields. Required evidence: The contract records the configured model, provider-resolved model, whether a model was invoked, whether the response was deterministic-only, whether fallback was used, and per-task outcomes. A successful HTTP response or configured model name alone is not proof that a model ran. Eval Labs policy: The owner-only verification panel evaluates the resolved service, target and Engine environments, Engine commit SHA, configured/resolved model agreement, model invocation, deterministic path, fallback state, successful task evidence, and verification timestamp. New runs persist typed runtime provenance; historical runs without it explicitly say it was not captured and are not backfilled with inference. State verified on 2026-07-10: Eval Labs production verified the authenticated Development model path with configured and provider-resolved modelgpt-5.6-sol, model invoked true, deterministic path false, fallback false, and status Verified.
Routing history: The uninterrupted Staging-target configuration began at 2026-05-04T16:21:35Z and was corrected and live-verified against Development on 2026-07-10. This establishes routing drift, not that every historical run individually used Staging.
Supersession: The 2026-04-26 model-layer decision below remains historical. At this 2026-07-10 verification checkpoint, GPT-5.6 Sol was the Lucia Engine Development default. This decision does not establish the separately configured Guest Agent model; see Current System State for current truth.
Promotion consequence at the 2026-07-10 checkpoint: Eval Labs production targeting Development was not a Staging promotion. The then-current Development commit still required capture and review before any promotion; the package label was not release identity.
2026-06-23 — Unify docs into a Mintlify library
Decision: Migrate both documentation sets (Lucia Canon and Eval Labs Canon) off Obsidian Publish onto a single Mintlify library — two products with a switcher — served athelloluciallc.com, with docs.hellolucia.ai and docs.evaluationlabs.ai redirecting in. The Mintlify library becomes the source of truth for published docs.
Why: A unified library splits and groups the content better and presents both brands as one home. Mintlify’s Products feature fits directly, and the accepted workflow moved canonical authoring to reviewed MDX.
Status: Accepted; implementation in progress (Phase 1 conversion complete and pushed, not yet deployed/live).
Historical status note — 2026-07-10: The two-product and redirect language above records the original decision intent. At this amendment, the canonical library had three products — Lucia, Lucia Fieldwork, and Eval Labs — and the two former Obsidian domains remained live legacy, non-canonical sites without redirects. The amended ADR below records the documentation status verified on that date.
Closed — 2026-08-15: the redirects were implemented and verified (see the 2026-08-15 entry above).
See: ADR - Unify Docs into Mintlify Library
2026-05-11 — Use Resend for waitlist outbound email
Decision: Use Resend for Lucia waitlist outbound welcome emails, while keeping Postmark focused on inbound operational/system email intake. Why: Resend is lightweight, already available, easy to operate, and better suited to this specific public waitlist confirmation path than a heavier marketing platform. Implementation: The Lucia Marketing waitlist service sends the welcome email only after a new signup is stored successfully. Verified behavior:send.hellolucia.ai is verified in Resend, live new-signup email delivery passed, and duplicate signup behavior returns ok:true duplicate:true without sending a second email.
Known gap: The endpoint returns Resend message id/status, but message id and send status are not yet persisted back into Supabase.
2026-04-29 — Add Branding and Identity as a Canon section
Decision: Add a dedicatedBranding and Identity section to the Lucia Canon.
Why: Lucia’s visual identity, color system, voice, and brand guardrails are now first-class source-truth concerns, not side notes.
Consequence: Brand work should be documented in the Canon and treated as connected to product trust, operator calm, and emotional containment.
2026-04-27 — Adopt Canon v1.0 architecture
Decision: Restructure the Lucia Canon around the real system: Foundation, System Architecture, Intelligence, Evaluation, Operations, Infrastructure, Properties, Roadmap, Decisions, Releases, Templates, and Archives. Why: The previous structure mixed doctrine, runtime, intent, Eval Labs, and live transition notes across overlapping folders. Consequence: Old folders are moved into Archives. The new Canon becomes the source of truth.2026-04-27 — Treat Lucia as a dual-surface intelligence system
Decision: Lucia is canonically defined as a dual-surface system.Operator IntelligencecontrolsGuest Intelligence
Why: The Operator System is the control layer today, while Guest Intelligence and concierge flows are downstream execution surfaces.
Consequence: Guest-facing work must not bypass operator truth-state and permission rules.

