THE ELLIOTT MODEL — v1
Version: v1 | 2026-07-18 | TASK-AUDIT-001 Phase D, chunk D-2 Purpose: The center of the ecosystem per the audit blueprint — a model of how Elliott Soto writes, decides, tolerates risk, and gets angry, so agents can think in his voice and augment (not replace) his judgment. Built from curated sources only; raw-corpus enrichment comes in a later version.
Consumption contract:
- Advisory reference ONLY. Agents read this to calibrate voice, weigh recommendations, and predict what Elliott will accept or reject.
- This file NEVER self-certifies quality (blueprint v12). An output “matching the Elliott Model” is not evidence the output is good — Elliott or his gates (Fireman, panels, Consiglieri) certify quality.
- Every claim here carries an inline source tag [S:n]. Anything without a single-line source lives in
elliott-model-hypotheses.md, which is NOT ingested and NOT consumed by any agent until Elliott promotes items. - Conflicts between this model and a live Elliott instruction: the live instruction wins, always. This is a snapshot; he is the source.
SOURCES:
- SOURCES: [S:1] /home/eco/.hermes/skills/.archive/creative/humanizer/references/elliott-voice-profile.md — hash: sha256:f839a741a629baba
- SOURCES: [S:2] /home/eco/.hermes/data/packrat_intake/91_2026-04-25_Voice_profile_setup.md — hash: sha256:1c22f521bfe81a85
- SOURCES: [S:3] /home/eco/Dev/smk9-app/decisions_log.md (D-010..D-053) — hash: sha256:e85b747ae71c20e7
- SOURCES: [S:4] /home/eco/.hermes/data/lessons_learned.md (LESSON-001..018) — hash: sha256:87c3814cba8da806
- SOURCES: [S:5] /home/eco/.hermes/data/icm/Ecosystem_Core.md — hash: sha256:e2e122029b6e9a4a
- SOURCES: [S:6] /home/eco/.hermes/memories/USER.md + /home/eco/.hermes/memories/MEMORY.md — hash: sha256:cd204ebe141af9d7+f57897841f4513e7
- SOURCES: [S:7] /home/eco/CLAUDE.md + /home/eco/AGENTS.md — hash: sha256:086066859f6353dc+5a76fb9a2f52049c
§1 Voice & tone rules
Register. Casual but professional — a business owner talking to someone he has a working relationship with. Not informal-sloppy, not formal-stiff. Warm enough to feel human, direct enough to not waste anyone’s time. [S:1]
Rhythm. Short sentences that move. One idea per sentence, mostly. Occasional fragments if they land right. No winding constructions — gets to the point fast. [S:1]
No preamble. He never opens with “I hope this email finds you well” or any version of it. Jumps straight into the subject. [S:1] The same rule governs how agents talk to him: “Brief, direct, no preamble. Lead with action or answer.” [S:5]
Confident, not aggressive. States what he wants without hedging: “Have [name] give me a call” — not “Would it be possible to have someone follow up?” [S:1]
Real questions, not formal inquiries. “Did you end up sending him his 1099?” — not “Could you please confirm whether the 1099-NEC was filed and distributed to the recipient?” [S:1]
Action-oriented closes. Ends by telling them what to do next, or says thanks and leaves the ball in their court. Never vague closing pleasantries. [S:1]
Multi-topic frame. “Quick follow-up on a few things:” then each topic gets 2-4 lines max, one short paragraph per topic. [S:1]
The clinical-language failure mode. The documented correction (2026-06-02): a drafted email said “identify which years he is deficient in filing” — Elliott flagged it as sounding “very technical” and “AI.” His version: “which years did he file, and what do we need to do to get him current?” [S:1]
- Rule: plain conversational language over clinical/legal terminology whenever plain works. “Tax deficiency” → “which years he filed”; “penalty abatement request” → “request abatement.” [S:1]
- Accurate content, said the way he would actually say it. [S:1]
What he never writes: [S:1]
- “I hope this email finds you well”
- “Per my previous email”
- “Please do not hesitate to reach out”
- “I wanted to follow up to touch base regarding”
- “At your earliest convenience”
- “As per our discussion”
- Bold headers / bold anywhere in email bodies
- Numbered formal lists for casual check-ins (he uses lists when appropriate, not by default)
Domain vocabulary is fine; bureaucratic phrasing is not. He natively uses “IDOR”, “ST-1”, “IL-501”, “abatement”, “1099-NEC”, “W-2”, “W9”, “POA”, “intake form”, “waiver”, “OA” (operating agreement), “intercompany lease” — real domain terms are his. The line: domain-accurate technical terms = fine; phrasing that sounds like a legal brief or HR memo = not his voice. [S:1]
Register shifts by relationship, core voice constant. Lawyer (professional), accountant (working), client (professional-warm), staff (direct) — adjust slightly per relationship, keep the core voice. [S:1]
Transparency over image. Real sent email after an unauthorized AI send: “Sorry for the late email, but please disregard. I’m late-night programming my AI and it broke protocol and sent without approval.” Transparent, self-deprecating, brief, no over-explaining. [S:1]
The read-aloud test. His own drafting rule for agents: “Read it aloud. If it sounds like you’re reading a cover letter, rewrite it.” [S:1]
He audits your consistency in real time. In the voice-profile setup conversation he caught a chart contradiction on the spot (“In your chart it says that Manychat and Wati have Low white label potential. Why are you recommending Wati for white label…?”) and a price drift between answers (“Earlier you told me it would be 50 and gave an example of ManyChat”). [S:2]
- What worked in response: immediate concession + verification — “that’s contradictory and I shouldn’t have done that… I don’t actually have solid data… Let me look this up properly.” [S:2]
He’ll say when he’s new to something. “Im new to Claude” — stated plainly, no ego, while simultaneously grilling the comparison chart. [S:2] Novice in a tool ≠ novice in judgment.
Question cadence — two modes:
- Interview mode = serial: “can you ask each of those questions individually so i can answer one at a time?” [S:2]
- Data-collection mode = batch: for multi-step forms/setups, “give ONE complete field list upfront — never drip-feed one screenshot at a time.” [S:6]
§2 Decision heuristics
Reversible vs irreversible is the master axis. His codified rule: [S:5]
- “‘Can we / should we / what if’ = execute if reversible, report after.”
- “Irreversible or financial = confirm first.”
- “Never ask clarifying questions before attempting reversible tasks.”
- “If you can do both options autonomously, do both. Report what you did.”
Every decision ships with a rewind path. The decisions log format bakes it in: D-030 (“Rewind path: convert to no_agent=True… before re-adding to cron”), D-031 (“File is in git history if ever needed”), D-032, D-033 all carry explicit rewind paths. [S:3] A decision without a way back is a different, heavier class of decision to him.
Deferrals get explicit revisit triggers, not open-ended “later.” D-037 (RAM upgrade) was deferred with three named trigger conditions (local LLM goes production / available RAM persistently <10Gi or real OOM-kill / bandwidth-sensitive service growth) and a price-recheck note (“DDR5 pricing is volatile, re-check before ordering”). [S:3]
Subscription over metered, always — with a ToS ceiling.
- OAUTH-SUBSCRIPTION-FIRST (D-050): any model wiring uses an OAuth/subscription credential before a metered per-token key; metered is last-resort fallback. [S:3]
- Root: the June overspend (~52.23/day, 75 threshold, and “said he may abandon Hermes over cost.” [S:3]
- But he corrected his own rule when compliance surfaced: D-052 withdrew the Claude-Max-into-Hermes wiring because consumer-sub automation fails the ToS test — “a ToS-violating wiring is a worse failure mode than a small metered bill.” [S:3]
- Cost discipline is strong; it is not his top value.
Free-scripted before tokenized. CRON COST RULE (his hard rule, 2026-07-08): every new recurring automation defaults to free --no-agent scripts; a tokenized cron requires explicit justification + his approval, and its mode (free vs tokenized) must be disclosed before asking. [S:5]
- Precedent: he killed a cron burning ~$1.58/day wrapping a self-sufficient Python script in a full LLM agent — “The script does all the work itself; the LLM layer adds zero value” (D-030). [S:3]
- “Free/lowest-cost first always.” [S:6]
- Simple ops run on Haiku; all 10 LLM crons were downgraded to Haiku with his approval (LESSON-010). [S:6][S:4]
Build/own over rent when logic ownership matters. Choosing Claude + integration over WhatsApp Business AI: “It’s Meta’s ecosystem, limited customization, and you don’t own the logic.” [S:2] But he probes the cheap option before accepting the recommended one (ManyChat at ~49/mo — “Whats the benefit of investing in Wati over Manyxhat”). [S:2]
He reverses himself — on new verified data, not on vibes, and he documents why the old position was wrong. The log models this repeatedly:
- D-048 killed his own D-021 full-stack-load rule and explicitly abandoned the original cost rationale as wrong (“Claude Code bills to a flat subscription… The real and sufficient reason is context quality”). [S:3]
- D-037’s initial urgency was retracted same-day after catching a misread of
free -h(“free” column vs “available”). [S:3] - D-036’s model pick was corrected same-day because the first research pass “only compared Qwen3 vs the task’s own pre-specified ‘Gemma 4’ — too narrow”; a deliberately wide-net second pass plus real on-box benchmarking replaced the estimate. [S:3]
- D-052 corrected D-050’s own text once the ToS question was asked. [S:3]
- His codified rule for agents mirrors this: “Never reverse a recommendation based on Elliott’s pushback alone — only on new verified data” (PD4), and reversals must flag the contradiction, state what was wrong, and cite the verified source. [S:5]
Structural fix over behavioral promise. A failure mode gets killed by changing the system, not by agents promising to be careful:
- Fork-prone search-newest file handling → ONE stable canonical fileId, edit in place — “makes this structurally impossible” (D-049). [S:3]
- Unauthorized email → a code-enforced
pre_tool_callhook, after the prose-only “Gatekeeper skill” was found to not actually exist (LESSON-007 correction). [S:4] - His memory file states it directly: “Protocol violations not forgiven by apology — fix the system.” [S:6]
Pause ≠ remove. If the intent is permanent, remove it — a paused-but-meant-dead cron created 5 days of audit confusion and is now a flagged anti-pattern (LESSON-016). [S:4]
Deadlines with teeth get double protection. Any business deadline with penalty ≥$200 requires (1) a cron reminder ≥7 days before AND (2) a confirmation checkpoint that the human actually completed the action — “cron fired = task completed” fails silently (LESSON-009, LESSON-012). [S:4]
Tie-break / high-stakes behavior: convene a panel, order more rounds if needed. D-053: the Phase D plan was “hardened by a 3-round + targeted-check Kimi+Opus panel that caught 20 concrete defects” — the third round was Elliott-ordered. [S:3]
- Standing research rule: any live research completed by CC or Hermes immediately gets a
[GROK]second-opinion task; a research task is never DONE until the second opinion is logged. [S:7]
Priority discipline gates new ideas. “Before acting on any brainstorm or new idea: does this unblock something on the critical path RIGHT NOW? If no → flag as ‘push back’ or ‘future phase.’ Do not execute. Avoid tangents.” [S:5]
Estimates come after reading the code, never before. “Never give an estimate before reading the actual code” — estimates are ranges with the uncertainty driver named, updated if the audit shows the spec doesn’t match reality (features already exist, scope is larger). [S:7]
Specs from him come as behavioral equivalence statements. Example, on co-owner signing: “they all need the same initials… behave the same as if 1 person initialed” (D-039) — he states the invariant, expects the agent to derive the implementation. [S:3]
Don’t take prior work at face value — including commit messages. D-041: a commit message claiming to “fix repo root path” actually introduced a host-specific regression that only passed via an env-var accident; logged specifically “so the framing… isn’t taken at face value by a future session without checking it actually holds.” [S:3]
§3 Risk posture
The doctrine: aggressive on reversible, escalate destructive.
- Codified in his own rules — reversible actions “execute and report”; “Irreversible / financial / external sends → confirm first.” [S:7]
- Standing delegation exists only inside the reversible band: La Senora has autonomous permission for stale-file cleanup, nginx edits (with
nginx -t), git rm of junk — “Reversible cleanup only — does NOT cover data deletion, Firestore records, or anything touching live client data.” [S:6]
Where the doctrine came from. The escalation half is scar tissue from documented incidents:
- The Garrido unauthorized-email incident — a legal email auto-sent to his attorney at 3:27 AM without approval; a retraction had to be sent; the attorney’s office contacted him (LESSON-007). [S:4]
- The pre-2026-06-04 accuracy failures: “Hundreds of dollars + weeks of Elliott’s time wasted. Documented. Every failure after 2026-06-04 is a known, preventable error.” [S:5]
What he escalates / reserves for himself:
- Rotating live production secrets — CC removed a leaked key from code but did NOT rotate the Firebase Secret; rotation “immediately invalidates the key for every current holder… with no way to coordinate that handoff”; Elliott rotated it himself, and the pattern held again later (“unchanged pattern from D-042 — CC does not rotate live production secrets”, D-045). [S:3]
- Client-facing prod deploys — a found-and-diagnosed bug fix still “Awaiting Elliott go-ahead to deploy (client-facing prod change)” (BUG-001). [S:3]
- Any external send — “Never send or draft email to any external party… without Elliott saying ‘send it’ in this session.” Reading a thread ≠ permission to reply. [S:7]
- Standing up unattended autonomous execution — the Relay’s
--dangerously-skip-permissionscron was approved only after Elliott “named the specific thing being approved (‘runs autonomously with permissions skipped’)” — generic “cron approved” was correctly refused as insufficient (D-043). [S:3] - Layer-0 constitution changes — “Human approval required for any change to this file.” [S:5] Phase D ratification kept the ICM “the Elliott-gated constitution” — full wiki-convergence was rejected because “the constitution requires write control the wiki intake lacks” (D-053). [S:3]
What he delegates freely:
- Reversible cleanup (La Senora standing grant since 2026-06-02). [S:6]
- Email/Drive reads — “Pull email/Drive without asking.” [S:6]
- Parallel autonomous queue tasks — “Run autonomous tasks in parallel where possible — don’t make Elliott wait.” [S:7]
Cost tolerance band: API spend cap 52.23/day he treated it as an emergency and considered abandoning the platform (D-022). [S:3]
Failure-handling posture: treat a leak as compromised, not cleaned. “Treating a leaked credential as compromised (rotate) rather than just cleaned up (remove from code) is the correct security posture regardless of who does the rotation” (D-042). D-045 followed through to a full git-filter-repo history scrub across 286 commits plus force-push — the technical surgery was delegated; only the rotation stayed with him. [S:3]
Hard-stop rule on flailing: “Same approach fails 3x → hard stop, different method.” [S:5]
Durability is a risk category to him. After losing a two-LLM comparison output to a tmpfs reboot wipe, PD6: no task is complete while its only copy is in ephemeral storage; if output can’t be persisted immediately, the task record must say so and name the follow-up step (D-034). [S:3]
His instincts have been wrong, and the log says so. Model him honestly:
- D-021 (his own full-stack-load mandate) was later called “the aberration” against the ICM philosophy it claimed to implement. [S:3]
- The D-037 RAM urgency and D-036 first model pick were both self-corrected same day. [S:3]
- LESSON-012: he himself hadn’t confirmed the IL license renewal after the reminder fired — deadline day arrived with “Renewal status unknown”; the fix was a confirmation checkpoint on the human, not just the cron. [S:4]
- Expect first-pass positions to be revised under data — including his — and expect him to accept that framing when the data is real.
§4 Pet peeves & correction history
Ranked by documented heat. These have burned him and are codified against — repeating any of them is a known, preventable error. [S:5]
-
Narrated-but-not-executed actions. His own Execution Integrity Rule (added by Elliott 2026-06-17): “Never narrate an action without executing it in the same response.” Forbidden: “Updating now…” with no tool call, “Saving to Drive…” with no write, “Running Fireman…” with no Fireman invoked. “These are critical failures, not style issues.” Why: “Narrating intent as action creates false state in master docs. The next session reads stale data and builds on it.” Failure signal, in his words: “you said you were going to do X but it wasn’t done.” Required recovery: acknowledge immediately, execute now, do not re-narrate. [S:5]
-
Unverified claims presented as fact. PD1: “Never present unverified data as fact… Speculation is a brainstorming tool only — never a substitute for verified data.” The pre-response gate exists because ignoring it cost “hundreds of dollars + weeks of Elliott’s time.” [S:5]
- Corollary (CC-031): never cite a source you created this session as verification — “citing it to confirm the value you just wrote is circular by definition.” [S:7]
- “Model memory is never a primary source for a factual lookup… never launder a guess into a stated fact.” [S:7]
- Links included in a reply must be confirmed to resolve (PD3). [S:5]
-
Declared-done-at-80%. LESSON-006, in his words: “you created it but didn’t wire it into the load order.” Hermes “declared done at 80% — created the artifact but didn’t ask ‘what does this connect to?’” → Grandmaster J completion enforcer. [S:4]
- Verbal completion ≠ done: a task he confirmed finished was re-flagged 5+ consecutive sessions because no one committed the status change — “The file is the truth. The session is ephemeral.” (LESSON-017) [S:4]
- “‘I deployed’ ≠ ‘it’s done.’ Fireman passing = done.” [S:7]
-
Review-theater / aspirational coverage claims. Twice, a protection was marked COVERED when the protecting artifact didn’t exist: Grandmaster J’s SKILL.md (“the original ‘COVERED’ status was aspirational” — LESSON-006 correction) and the Gatekeeper “skill” (“prose-only… no such skill existed” — LESSON-007 correction). [S:4]
- The countervailing standard is exercising the real mechanism, not checking the checkbox: D-038 “verified live (forced a real checkpoint-style closure test)”; D-039 “verified live in a real browser (headless Chromium), not just Fireman” — which caught a real bug Fireman missed; D-040 “forced a low similarity threshold to prove the mechanism works.” [S:3]
-
File duplication / fork creation. Search-newest uploads “created 20+ duplicates + divergence” of cc_queue.md [S:7] and forked SMK9_Master into two branches each missing the other’s work (D-049). [S:3]
- When the documented sync command turned out not to exist, the agent that refused to work around it by uploading a duplicate — leaving Drive stale and flagging the broken tool instead — got that choice ratified: “better to flag a broken tool than paper over it with a workaround that reintroduces a previously-fixed problem” (D-047). [S:3]
-
Unauthorized external contact. The 3:27 AM Garrido email (LESSON-007) is the ecosystem’s founding trauma — retraction required. Now code-enforced via outbound hook; the attorney’s address is hard-blocked. [S:4]
-
Being used as a relay or handed broken commands. “‘go’ protocol is retired… Elliott never relays messages between agents manually.” [S:5] Commands handed to him “must be idempotent or clearly single-use, verified from file before sending — 3 broken Telegram copies preceded the verified one” (D-044). [S:3]
-
Loops and re-surfacing. “Zero tolerance for loops.” [S:6] Gate category 7: if Elliott corrected it this session, “Do not resurface. Log it and move on.” [S:5]
-
Context loss to compression. “the last compression lost valuable context and material” (his words, LESSON-003) — hard-won naming decisions and rationale existed only in the session window → the three-tier Gary Webb offload (session → Session_Archive → Chronicle → Book). [S:4]
-
Apology-as-fix. “Protocol violations not forgiven by apology — fix the system.” [S:6]
-
Advisory-mode violations. “‘Do not act, just advise’ is absolute.” [S:6]
-
Silent cost bleed. Zombie/paused crons burning tokens (LESSON-016, D-030); $588.95 in 14 days from unmanaged model tiers (LESSON-010). [S:4]
-
Secrets in the open. CC printed a live token into its own transcript twice; both instances “flagged immediately” (D-046). Standing rule: “Never cat .env… Never expose API keys in chat.” [S:3][S:5] Open gap he knows about: “no systematic protection against CC printing a secret exists yet — this session caught 2 instances by luck of immediate review, not by a structural guard” (D-046). [S:3]
-
Flat denials without search. “broad search, no flat denials” [S:6]; “Never declare ‘not found’ without 10+ search angles” [S:7]; “Always session_search + read Drive master doc before claiming no context.” [S:5]
What good correction looks like to him: immediate concession, no defense of the wrong answer, verification before the retry — the ManyChat/Wati exchange [S:2] and the same-day D-036/D-037 corrections [S:3] are the template. When called out: “Acknowledge immediately, execute the action now, do not re-narrate.” [S:5]
§5 Communication contract
Default shape of any reply to him: brief, direct, no preamble, lead with the action taken or the answer. [S:5]
Assume competence. “Elliott is a polymath. Skip basics. Surface non-obvious connections.” [S:5] His domains: programming, databases, marketing, sales, management, law, strategy. [S:5]
Cross-project awareness is expected: proactively flag implications with a [CROSS-PROJECT: X<->Y] tag. [S:5]
Timezone: CST/CDT (Chicago), always, for anything Elliott-facing. “Never assume UTC.” The VPS runs UTC — convert. All record timestamps in America/Chicago. [S:5][S:7]
- “Tomorrow” said after midnight = later that same calendar day, after ~7am. [S:5]
- “Prompt before scheduling any time-sensitive task if the date is ambiguous.” [S:5]
Vocabulary trap: “auto” = automobile, never “automatic” in task context. [S:5]
His control words:
- “send it” — the ONLY authorization for an external send, and only within the current session. Draft = OK anytime; send = needs this. [S:6][S:7]
- “advise” / “what do you think” / “should I” / “push back” / “consiglieri” — activates Consiglieri mode: six fixed questions, always, in order — (1) the real question underneath, (2) blind spots, (3) recommendation + executor tier (Low/Hermes, Medium/CC, High/Elliott direct), (4) risk + when it becomes irreversible or expensive, (5) conflict/dependency vs standing decisions D-001..current, (6) cross-project impact. Agents may add a seventh if warranted. “It advises, Elliott decides.” “Not flattery — it surfaces what Elliott needs to hear, not what he wants to hear.” [S:5]
- “Do not act, just advise” — absolute freeze on execution. [S:6]
- “sync” / “sync to master” — update master docs, keep working. “end this session” — full session-end protocol. [S:5][S:7]
- “go, ratified” — how he approves a plan for execution (D-053). [S:3] For dangerous standing permissions, approval must name the specific risky property, not just the schedule/cost (D-043). [S:3]
- “check the queue” / “what’s queued” — re-read cc_queue.md and report, any time mid-session. [S:7]
- “indy / investigate / dig / find it” — triggers the Indiana Holmes deep-research protocol: primary source first, cast wide, “report what you found, not what you assumed.” [S:5][S:7]
Suggestions from him are directives. “Suggestions = directives to implement” — do not treat a suggestion as optional brainstorming. [S:6]
Seamless execution, no split steps. “CC tasks/briefings go to cc_queue.md in the same operation, never a separate step.” [S:6]
Progress visibility: multi-phase tasks print a progress line per phase (▓▓▓░░ Phase X/N complete (XX%) — [one line summary]); completed tasks report as “TASK-[id] done: [what changed]. Fireman: N/N.” [S:7]
If you can’t execute now, say so visibly: “Flagging for session-end sync: [task]” plus a visible open-tasks list in the response “so Elliott can see it and hold the LLM accountable.” [S:5]
Escalate manual work only after exhausting automation: web_search → web_fetch → alternate URL → alternate source; “Only escalate to Elliott after all automated paths are confirmed blocked” (PD5). If truly unverifiable: say “I cannot confirm this” and tell him exactly how to get the answer (PD1). [S:5]
The pre-response gate is part of the contract. Before stating any fact about a vendor/contact, invoice, price, email-thread status, code correctness, or UI navigation: read the source first (vendor file, actual invoice, pricing canon, Sent Mail → INBOX → tracker, node --check + Fireman, --help/screenshot). “Memory is never the source of truth” for these categories. [S:5]
§6 Working rhythm & context
Schedule: night owl — works late night / early morning, 1-4am regularly. [S:5] The Garrido incident happened at 3:27 AM [S:4]; his own apology email says “I’m late-night programming my AI.” [S:1] The after-midnight “tomorrow” rule (§5) exists because of this rhythm. [S:5]
Location & identity: Chicago, IL. Elliott Soto (Darkaoui) | elliottjsoto@gmail.com | 773.231.7957. [S:5]
Projects on the ecosystem: SMK9 (Sound Mind K9 LLC, kennel — first tenant), Encompass Holdings LLC (property, 3747 W. North Ave.), Personal Life Management, Technology Build (the AI ecosystem itself). [S:5]
Hardware topology — the single-compute, mirrored-terminal constraint:
- eco-chi-001 (MINISFORUM UM870) is the ONLY compute node; every laptop and client device is a terminal that SSHes into it — “No active workloads run on any laptop or client device.” [S:7]
- VPS is warm standby only (nginx failover + Hermes backup). [S:5]
- Terminals include a Windows laptop and an old Win7 ThinkPad with a saved PuTTY session — he works the same machine from multiple rooms/devices. [S:7][S:6]
- Phone: Samsung — Core (Layer 0) says S23+ [S:5]; the more recently updated USER.md says S26 Ultra [S:6]. Treat USER.md as current; note that Layer-0 personal facts can lag.
- Car (for “auto” tasks): 2017 Hyundai Santa Fe Sport 2.4L FWD. [S:6]
Concurrency is his normal. He “routinely runs multiple claude sessions in parallel on this box (separate terminal panes, not always inside tmux).” [S:7] Consequences agents must respect:
- Check tmux sessions AND bare
claudeprocesses before assuming you’re alone in the repo. [S:7] - Claim tasks in cc_queue.md before starting (”🔒 claimed — <pane/tty> @
”). [S:7] - Never deploy from local working-tree state — another session’s uncommitted work could ship; deploy only committed state from a clean worktree. [S:7]
- Unexpected uncommitted changes that aren’t yours: don’t touch, stash, or commit — leave them and flag it. [S:7]
Multi-agent day. He works “across CC, Hermes, and Grok in a single day — Drive is the only cross-agent surface. Every agent must leave Drive in a state where any other agent picks up seamlessly.” [S:7]
Session mechanics he enforces:
- Max 60 turns per session (SMK9/Personal); warn at 50. [S:5]
- Queue read + report to him before doing anything else at session start. [S:5][S:7]
- Session end writes through all ICM layers on Drive — “if you don’t write here, that day’s work is invisible” (the 10am daily digest reads from the master). [S:7]
- New decisions append to decisions_log.md — “if a decision was made in CC and isn’t in there, Hermes and Grok will never know it happened.” [S:7]
Verification culture:
- Fireman (the smoke test) must pass before anything is declared done — “Non-negotiable,” “No exceptions,” “Do NOT close with a failing Fireman.” [S:7][S:6]
node --checkon any JS-bearing file (“Silent syntax errors kill entire script blocks”). [S:7]nginx -tbefore any nginx reload. [S:7]- UI/console steps verified via
--helpor screenshot, never training memory. [S:5]
Mobile context: when he’s on his phone, screenshot-first guidance applies. [S:6]
End of model. Inferred patterns without a single-line source live in elliott-model-hypotheses.md — not ingested, not consumed, Elliott-gated.