node on a clock: it never sees any of this. That is why every SAFETY gate is duplicated
in-process — the identity gate, live-verify, dedup, URL-reality and brand guard live in the pipeline
code itself and hold even when nothing on this tab is watching.verifies script/newsletter claims against the cited sources before approval
pre-script on big topics: cross-checks sources, finds the counter-narrative
final editorial pass: voice, fact-accuracy rules, reputation risk
avatar/voice mode QC: silent fallback, A/V desync, missing AI disclosure
adversarial QC for weekly editions: sourcing, branding, scoped filenames
visual QC on rendered frames
mandatory gate for one-off teasers (born after one teaser shipped broken four times)
reads metrics data, produces numbered reach recommendations
PreToolUse: auto-runs npm run validate before approve/post; blocks on dead links
blocks produce/render when a paid avatar mode lacks its key — fails before billing
blocks an edition run whose cover/config is missing
blocks installing a teaser final.mp4 without a fresh .teaser-qc-passed marker
enforces avatar-qc verdict before an avatar video ships
production-safety rules; gate symmetry; brand gate — read before touching publish code
the multi-edition runbook (cadence, sourcing, verify-before-publish)
avatar/voice mode operating + debugging guide
browser posting playbook (IG crop incident rules)
the QC procedure for bespoke videos
trend-scout (pre-script, optional) → fact-checker → brand-reviewer → avatar-qc (avatar mode only) → human approve — and the launchd path skips straight past all of it, which is the point of the in-process gates.