Every protocol revision and Field Kit release, newest first — what changed, why, and whether it affects records you already made. A downloaded kit never updates itself, so this page (and version.json, its machine-readable twin) is how you know where the current release stands. Want serious fixes to reach you? Leave an address: info@earnedtrust.org — updates only, unsubscribe anytime. It’s the only channel we have, because the kit holds nothing about you.
Six independent reads of the beta trial’s full design — three council models, their synthesis, a twenty-page publication-readiness review, and one more pasted by the author — agreed that the earlier findings were closed and found one thing left: sentences that promised more than the mechanism delivered. The principal investigator ruled on all of it (R54). What changed on these pages: the exit form’s private line now carries seven items, not five — where your sessions happened and whether another living person’s story entered your work move off the public line, because the design promised them as cohort counts and a promise about what prints has to be true of the data (the exit encoder is now sv 4; the Reader still decodes every earlier line); one exit question added, 25a, asking directly whether you lost any work by following the method; the consent form and the study page name Python among what you’ll need for the finishing steps, and carry the two-critic rule for checkable work that the FAQ already had; “four files” is now “three files, and a fourth if you choose”; the seal-and-box rule reads Seal: required in every deposit. Locked box: you make one and keep it at home. Publishing it: your call; the FAQ’s passphrase entry no longer says opening the box for someone hands them the password — you open it yourself and hand over the item; the FAQ says plainly that Zenodo lets a record’s files be edited for thirty days under the same DOI, so the fingerprint, not the DOI, proves the files; “seen by no other person” now reads “no other person at the study,” with the mail and AI providers named for what they do; the screened-out list records whether a reason was about the person, the project, or the phase, and only a reason about the person closes the door to a later application; and the Terms carve the study’s own negligence out of the hundred-dollar limit and name the state courts of Bexar County, Texas as the venue — a clause that was deliberately absent until now, and says so. The four documents (consent draft 24, Terms 18, duty map 20, privacy note 17) are regenerated from the working drafts. The deposit PDF is rebuilt against this version and resealed; the auto-reply gains its one-line 911/988 notice (filter draft 19). Nothing in the kit changed: v0.9.19 stands.
A usability review of the live site, run as a potential customer would see it (Codex, GPT-6 Astra), found two things that mattered and several worth doing. The two that mattered: the application page showed a different fingerprint for the v0.9.19 kit than the kit page did — the first build of v0.9.19 was replaced within minutes by a corrected one, and the application page kept the old number; it now shows the same fingerprint as the kit page and version.json (88ed4c7b…). And two sentences had outlived their rulings: the beta page’s opening still said your DOI is printed “if you want it” (it is printed — name and DOI are what make the trial checkable), and site FAQ question 6 still said silence is the one answer the standard doesn’t recognize (under v1.14, production is a choice; the answer now says so and says which version is which). Also from the review: the beta page opens with “The trial in one minute” — who, what you do, what it costs, what becomes public, what help you get, and that ordinary use is not the trial — with the detail below; the enrollment line says plainly that you can apply now and applications are screened when enrollment opens; and the homepage no longer says “prove” — it says show how AI helped create your work, with records readers can check, which is what a record card and a fingerprint actually establish. The review’s larger suggestions — a simpler first example, a three-door Reader, a lighter application form — are on the list for after RUN 1 publishes. Later the same day: the beta page’s question list gains one entry in the principal investigator’s own words, “Do I need an ORCID number?” (no — it’s optional; why authors have one; leave Zenodo’s box empty if you don’t), placed after “What is a DOI?” — 55 entries (FAQ draft 19).
The “What you’ll need” card at the top of the beta page still said eleven thousand words and one month, while the FAQ below it said twelve thousand and a month or two; step 5 still called the locked box something you “chose to seal.” Four phrases, now matching the FAQ and the ruling: the seal is part of every deposit; the locked box is the one thing you choose to publish. Nothing else changed.
A third read of YOUR JOURNEY (Codex, GPT-6 Astra) caught the kit saying two things about the seal: Step 7 offered it as a choice, while the deposit check had always stopped without it. The principal investigator ruled (R53): the seal is part of every deposit. The fingerprint list is what makes a record checkable; your AI runs it in one command when the work is ready and again after any change. The only optional thing in a deposit is the locked box — whether to publish a passphrase-protected copy of your working records — and that question is now asked on its own, in plain words, never folded into the layout defaults; so is the contact address, showing exactly what would print. The finish line is a checked record: before Publish, preview the page and read it back; after Publish, open the page, open the work, scan the card, and only then write the DOI into your logbook — an address is not the finish. Coming back tomorrow takes your record link and your latest draft; your AI names the last finished step and asks you to confirm the next. Save before you leave is now part of every close-out, and at the first session your AI says which of three things it can do where you are (make downloads, open your files, or only give text). Honest fallbacks for the awkward cases: a draft too long to paste, “I can’t check this,” and memoir or fiction at Step 4. The protocol is about twelve thousand words now, and every page that helps you choose a plan says so, and says a month or two usually covers a project. The FAQ gains “Do I have to seal my record?” The kit’s checksum changed with it.
A second line-by-line read of the protocol (Claude Code) found three things worth a ruling and eight worth a fix; the principal investigator took them all (R52). The floor is a floor again: work that makes checkable claims needs at least two critics from different companies; the one-AI fallback is for personal and creative work. The number is true: the protocol is about eleven thousand words after the on-ramp release, not eight, and every page that helps you choose a plan now says so — from here on the count is computed when the kit is built, never typed. YOUR JOURNEY now opens with what it is and how to begin (open an AI chat, paste the protocol, say hello), tells someone who already has writing that it is fingerprinted on day one and they skip most of Step 2, and — the biggest gap — teaches how to come back tomorrow: your record link, pasted into a new conversation. Phones get an honest clause; the hour ranges are marked as the founder’s own estimates. SHA-256 7721f8105183d5e36b2e2f3b57d59e3233acbcbd74d9aebf365f6e0421100aee.
The principal investigator read YOUR JOURNEY as a beginner would and ruled six things (R51). Step 1 names the team — your writing partner, and at least one critic from a different company (Claude, ChatGPT, Gemini, Perplexity, Grok, Copilot, or whichever you already have; more is fine). Step 2 is the partnership: write, ask, take some, leave some, get to know each other. Step 3 says its rhythm — once per finished piece, a few times over a project, an afternoon each — and that you may ask for a critique whenever you like. Every step on the journey page now says who does what — you, your writing AI, or the other AI — and what you physically do: copy, paste, open, send. Two sentences open the page: your AI has the whole method, you don’t have to remember it; if it loses its place, say “where am I?” or name the step. FAQ: 53 entries. SHA-256 60ddf9809f0b186ace570f7b31ddfb33d19c055c02b48061e1d962f8dc26b557.
Two reviews read the protocol the way a first-time person would (a Codex usability audit and a Claude Code UX read); the principal investigator adopted both, with one instruction: write it like a really nice teacher with a slight sense of humour. The protocol’s rules for the AI are regrouped by when they fire — OPEN HERE, EVERY SESSION, ALWAYS TRUE — so every model opens the same way; a boxed line at the very top tells the person what to do; the greeting is short; the second AI is mentioned early (a free account is fine, and if you truly have one AI, a fresh conversation counts, labelled honestly); Step 3 hands you a copy-across critic packet; Step 4 pre-fills the source table one row at a time; every term of art gets a six-word gloss on first use; the AI says “Step 2 of 8” and answers “where am I?”; you end a session with “log it and close out”; your READ FIRST document is drafted at setup and grown; the locked box is stated as optional in Step 8’s first line; the five end decisions come with defaults. The person’s PDF folder is six documents, and two are new: YOUR JOURNEY (what will happen, in order, what is phone-safe, how long it takes, what finished looks like) and WHAT ZENODO WILL ASK YOU. What you’ll need — the AI plan, the second AI, the likely cost of a month’s subscription — is said plainly on the beta page and in the kit. The plain-text protocol has a short address: earnedtrust.org/paste. SHA-256 96c46e60b1c5c2a0f4e0f645d4653e38ab4839ac0acc405e5007e3f5e650e3f0.
The kit was used for real for the first time: the trial’s own design was deposited with v0.9.14 as the dry run, and the principal investigator walked the folder as a first-time reader. Two findings, fixed in v0.9.15: the documents a person reads now ship as ordinary PDFs in a folder named 1 READ THESE FIRST (PDF), numbered in the order you want them (the .md files stay for your AI); and every file or folder a person touches is named by what to do with it and numbered by when. START HERE opens with one line for a person and one for an AI, and records one honest limit: a long record makes a dense QR card. The seal manifest now says what it is in its first line. Protocol revised 2026-09-07: Step 8 gains “The shape of the folder at the moment of upload” — three numbered things (1 READ FIRST · 2 YOUR RECORD - stays home · 3 PASTE THIS), the deposit files in one place only, six rules, and the reason: the standard’s own first deposit under this kit got the shape wrong three ways and the author got lost. No script behaviour changed; all tests pass. SHA-256 db3fa2d4aaf82a8c2faded8e6f823921f848b49bffb6cbdf4476cfee61f45e68. Kit v0.9.14 stays at its own address; a tester runs on the version named in their enrollment confirmation.
The PI closed the last three open wordings before the deposit: the reminder letter speaks as “the founder” (the creator’s voice); the eligibility line reads the same on every page — “the finishing steps — making your locked box and making your deposit — need a computer”; and “How to get started” says what the exit confirmation is. The consent page regenerated. No rule changed.
A fourth review annotated all 126 pages of the deposit; eighteen small repairs adopted (R49). On the site: the correction form names all four reasons a DOI check can fail (did not open · the “all versions” DOI instead of the version DOI · not your deposit · the name does not match); an exit form that says “no deposit” with a blank DOI gets the confirmation of your exit and nothing else; the exit confirmation’s congratulations are for a completed trial, and the documented-participant letter follows only when the DOI check passes; the notice reads as one quotation; the question list freezes “for the phase.” The four document pages regenerated.
A third council read the deposit and found bounded defects; the principal investigator ruled on them the same night (R48). The exit form now makes two lines: a public line that prints in the report word for word and is the only thing in the QR, and a private line holding the five report-private answers, which the study keeps and never prints. The DOI check is stricter: the version DOI, the record must hold your deposit, and the author name on Zenodo must be the name on your exit line — a mismatch gets one email, and the correction form is now Name and DOI correction, carrying both. A blank DOI with “I made no deposit” is counted at once, with no retry. The close is one rule: the PI does not close enrollment before six except by an announced early close, never past twelve months, and the decision may not use any result. The exit confirmation has two openings, finished and stopped, both the PI’s words. FAQ: 50 entries.
A second council of four models read every page a tester sees, and a separate 142-item plain-language audit went through the pack; the principal investigator adopted both whole (R46), with three rulings of his own (R45, R47). The four documents you agree to — the Consent Form, the Terms, the Duty Map, and the Privacy Note — are now pages on this site, each showing its draft and date, linked beside the acknowledgment on the Apply form. The exit form shows the seven passages of the optional tagging exercise, saves a draft in your browser as you type, warns before you leave the page, and offers To, Subject, and Message with their own Copy buttons if your email program doesn’t open. Name and DOI are a condition of entry, said plainly: every tester prints in the report by name and DOI — the author name on the Zenodo record — because that is what makes the trial checkable. Enrollment stays open until the PI closes it — not before six are enrolled, not past twelve months from the first enrollment; the six-weeks-of-silence close is gone. The kit lives: it may be updated during the trial, but each tester runs on the version named in their enrollment email, every version stays at its own address, and the Reader verifies every version issued. The person running the study is now titled the principal investigator; the FAQ freezes on the day enrollment opens (48 entries). A short “Words you’ll meet” list opens the consent form.
The design pack was read end to end by two reviewers before its deposit; the founder answered five questions (R44). On the site: the forms page’s introduction now says “someone who just stops, without a word, is logged as incomplete”; the Glossary link points at the new How-it-works page; that page has its own description. The exit form’s Section C now asks, in plain words, whether your AI raised privacy issues before you deposited.
A separate review (GPT-5.6, recorded as separate review) graded the site B− for one reason: a stranger had to read too much before finding the door. Four fixes, none touching the trial’s rules or pages. The homepage is a decision page — the seal, one line (“Prove how AI helped create your work”), a four-step strip, two buttons (Start Writing with AI · Verify a Work), three short doors, one beta card, one sample mark. Everything it used to carry lives on a new page, How Earned Trust works. The Field Kit page opens with two doors — Simple (paste the protocol into your AI) and Advanced (download the tools and seal your evidence). The phone nav is five items plus Menu. The stale “interest list” links are gone.
Three rulings the morning after. Nothing goes out before the code is checked: the getting-started reply is now sent by the founder after the code-and-address check, and the mail filter is one lane — the welcome letter, to anything that arrives. Four end states: completed · stopped (an exit form saying “I’m stopping here — count what I filed”) · incomplete (no exit form) · withdrawn (the Withdraw form). The exit form no longer offers “withdrawing”; withdrawal has its own form. The beta page rewritten in the author’s words: the invitation, the two sentences, “How to get started,” one big Apply button with the close rule under it. The Communication Forms page: Apply first, then four large buttons, the Field Kit and the five checks, your code, the postcard.
Twenty-three rulings on the Beta Trial and one on the standard, made across two sittings by the author walking through what a first-time tester would actually see. The pack, the kit, and this site were swept the same day. Existing records are not affected: no folder or file is renamed, and every script still recognises the old INDEX heading.
And from the morning sitting:
Twelve rulings on the Beta Trial and one on the standard, made in one sitting by the author walking through what a first-time tester would actually see. The pack, the kit, and this site were swept the same day. Existing records are not affected: no folder or file is renamed, and every script still recognises the old INDEX heading.
0 WHAT'S IN YOUR FOLDERS.md in every work folder; check_deposit.py, the deposit gate — SAFE TO UPLOAD or STOP, in plain words, reading the locked box's own header; "manifest" now means the seal file only; the LOCKED BOX guide never tells you to delete anything — copy your folder first, keep an unlocked copy always; passphrase advice rewritten to the real threat model. 33 tests.10.5281/zenodo.22547805, unpublished until the freeze.A live dry run of the study’s own mail found it: the copy-by-hand fallback handed over one block — address, subject and message together — and left the sender to take it apart. Two attempts out of two produced a wrongly-addressed or wrongly-subjected email. That matters more than it looks: the study’s mail system reads the subject line to know what a participant is sending, so a mangled subject sends a finished project into the wrong lane. The fallback is now three labelled pieces with three buttons — address, subject, message — with numbered steps and a plain warning to paste the subject exactly. Found by using the thing rather than reviewing it.
The author pressed his own interest button and found two things a tester would have found. Fixed both:
Step 1 gains a plain-words passage on tool fit, written after a records failure in the project’s own workshop taught the lesson the hard way. Chat is the room for authorship: code tells on itself when it breaks, a chapter doesn’t. The Code AI tools (Claude Code, Codex, and their kin) hand work to other AIs that never heard the author — a note passed down a line of people — at a speed no reader can follow. Let them do the mechanical chores; the words that carry meaning stay where the author watches every change land. No rule, no gate — the standard qualifies work, never people.
The full standard caught up with everything above — and survived four five-model council rounds plus an independent expert pass before deposit, run until the well went dry. Version DOI: 10.5281/zenodo.21940146.
Does this affect existing records? No — existing records remain conforming. If your mark sits in your byline or ETR paragraph today, it always conformed; the standard now says so in so many words.
A three-model council review (GPT 5.6 Sol, Gemini 3.1 Pro, Claude Sonnet 5.0) went at the live site, the DOIs, and the protocol — the method applied to itself, again. Every accepted finding, in one pass:
Does this affect existing records? No — existing records remain conforming. The production rule is the one change worth reading if you’ve already published: responding to good-faith challenges (even with a reasoned refusal) is now part of conformance going forward.
Two protocol additions, born from one question: what happens to a downloaded kit when a new version ships? (Nothing — so the method now carries its own update path.)
Does this affect existing records? No. Updates are recommended, never required — a record made honestly under an older version is a conforming record. Add the version pin to your Working setup row at your next session if you like.
An outside review (Codex), adjudicated point by point and ruled on by the author — the kit maintained under its own method. The protocol’s claims about privacy, links, and cryptography now say exactly what is true and no more:
Does this affect existing records? No — existing records remain conforming. But if you downloaded a kit before this date, please re-download: earlier kits carry a protocol that predates the deposit hard stop below.
The important one. A working-record vault was once deposited as a plain, readable zip — publicly readable, permanently, because archive deposits cannot be unpublished. The protocol now carries a hard stop: the working record never deploys unlocked. Drafts, session logs, and AI transcripts enter a deposit only as an author-locked, AES-256 encrypted box, tested both ways — locked to the world, open to the author — before anything is staged. The ETR page also became automatic, and the LI- question moved to deposit time.
Does this affect existing records? Yes, one check: if you deposited a working record before this date, open your deposit page and confirm the record file is a locked .7z, not a plain zip. If it is readable, the honest response is a corrected new version of the deposit — ask your AI to walk you through it, or write to the address below.
Hardening across the tools: the Bookshelf refuses symbolic links and stays inside its folder, one canonical INDEX per work, table-safe parsing everywhere, the Working setup pin travels in the record schema, and regression tests cover every fix.
Does this affect existing records? No.
The kit’s first public arc: exact-set seal verification, record-integrity fixes, the warm front door and the three doors, the nature question and the voice test, the legacy baseline, the consent handshake (a file cannot consent for a person), the Bookshelf, late entries, the operator role, and the Family Story Time template. Full detail lives in the CHANGELOG inside the kit and in the deposited standard’s evidence records.
Does this affect existing records? No.