The estate’s own condition, ratcheted against a floor so nothing fixed can quietly break.
The workflow clones the estate and runs the hygiene survey against a floor, so anything already fixed cannot regress without a failing check — the survey measured the estate for weeks and gated nothing, a number in a log somebody had to remember to read.
The floor is expressed in ratios and records how many repositories it was written against, and the survey refuses to vouch for a run that read fewer, so a partial clone fails loudly rather than passing on a smaller sample.
Crucially it fails rather than skips when it cannot see the estate: a token scoped to one repository cannot survey thirty-five, and a hygiene gate that goes green because it looked at nothing is worse than no gate, because it is believed.
That the estate holds a measured floor rather than an impression. Run `node tools/estate-hygiene.mjs` over the checkouts yourself; a check that does not apply is skipped rather than failed, and a repository that cannot be read is reported unread rather than counted as passing.
The estate hygiene ratchet is a weekly gate that surveys every repository against a recorded floor, so anything already fixed cannot regress silently — and it fails rather than passes when it cannot read the estate, because a green check nobody looked at is worse than a red one.
estate hygiene ratchet →