Documentation is not a write-up after the fact. It is an artefact with a version, an owner, and a test — and when it drifts, somebody gets paged into a document that is wrong.
Documentation Workbench* · Public demonstration. No repository is read and no document is published anywhere.
The SLO burn alert named runbook RB-WISH-07. The on-call engineer opened it at 02:14 and it described a seven-day draft that was never built. The page was correct; the document was fiction.
NP-AUTH-321 shippedNP-AUTH-338 proposedRB-WISH-07 stale
NP Documentation & RecordsOwning engineer · family-wishlist · local demo
Verified authoring session
● Signed inRole: Owning engineerDoc set: family-wishlistSince: NP-AUTH-321
1 · ScanCompare the record to the build.
2 · DraftAI proposes the corrections.
3 · ReviewA named person accepts each one.
4 · PublishVersioned against the story.
Five documents are registered to this service. Each one declares what it is derived from — a control, a decision, a shipped build — so drift is a computed fact rather than an opinion about whether the wiki looks tidy.
Drift is measured against the shipped build, not against the last time somebody remembered to edit a page.
ADR-014
Where an unconsented wish draft lives
Architecture decision record · derived from NP-AUTH-321
Not scanned
The session-memory choice was made during development and never recorded. There is no document to be stale — the decision that later cost four hundred wishes a day exists only in a merged diff.
ADR-014 · new record+ Status: Accepted (recorded late) · supersedes an undocumented choice+ Context: PRIV-CHILD-001 forbids any child-linked write before a+ guardian consent entry exists. Something must still hold the draft.+ Decision: hold the draft in session memory, session_draft_ttl = 1800s.+ Consequence: a draft does not survive the consent email round trip.+ Observed median guardian consent: 2h 41m. Observed loss: 412/day.+ Revisit: NP-AUTH-338 proposes durable, unlinked storage for 7 days.
Recording a decision after the fact is still better than never recording it.
RB-WISH-07
Runbook · consent-pending drafts expiring
Operational runbook · referenced by the SLO burn alert
Not scanned
Step 3 describes a seven-day draft with a resume link. Neither was built. This is the document an engineer was paged into at 02:14.
RB-WISH-07 · step 3- 3. Drafts are retained for 7 days. Advise the guardian to resume- from the link in the consent email.+ 3. Drafts are held in session memory only, for 30 minutes+ (session_draft_ttl = 1800). After that the draft is gone.+ There is no resume link. Do not tell the guardian there is one.+ 4. If consent_pending_expired > 50/day, this is the NP-AUTH-338+ condition. Do not page engineering; attach the series to the story.
A runbook that is wrong is worse than a runbook that is missing.
PRIV-NARR-002
Privacy narrative · child data before consent
Compliance narrative · derived from PRIV-CHILD-001 · owner: Data Protection Officer
Not scanned
Stale, and the draft overreaches. The AI proposed a sentence this system is not entitled to write about itself.
PRIV-NARR-002 · section 2- Child data is handled carefully throughout registration.+ No child-linked row is written before a guardian consent entry+ exists. Enforced by PRIV-CHILD-001, evidenced by the QA suite+ and re-checked at the release gate on every promotion.! The system is COPPA compliant.
One line is held for refusal.
Every control in the catalogue is described as proposed for human review, not a claim of legal compliance. A generated document does not get to promote itself past that line. The reviewer refuses it; the reviewer does not soften it.
Accepting this document is blocked until the claim is dealt with.
Publishing also requires Data Protection Officer sign-off.
HELP-WISH-03
“What happens to my wish while I confirm?”
Parent-facing help · derived from the shipped consent flow
Not scanned
No such page exists. Four hundred and twelve people a day meet this behaviour and have nowhere to read about it.
HELP-WISH-03 · new page+ While you confirm consent by email, your wish is held on this page+ for 30 minutes. If the email takes longer than that, the wish will+ need typing again — we are sorry, and we know.+ We are changing this. Until then, this page tells you the truth+ about it rather than hoping you do not notice.
The honest version ships now; the fix ships with NP-AUTH-338.
API-REG-001
Registration API reference
Interface reference · derived from build 2026.8.17-rc5
Not scanned
No drift. The registration contract did not change in this release, and the scan says so rather than inventing an edit to look busy.
Nothing is read and nothing is written. The drift is scripted to show the mechanism.
Published · documentation set v4Linked to NP-AUTH-321 · referenced by NP-AUTH-338
Each record now carries the story it came from, the control it describes, and the build it was true of. The next release re-runs this scan; a document that stops matching the build is a finding, not a chore somebody eventually gets to.
Drift foundNot yet scannedReviewed0 of 4Refused—PublishedNothing published
Six phases, and the record kept up with all of them.
NP-AUTH-338 now enters Requirements with a decision record explaining why the thing it replaces was built that way. The next story inherits the reasoning, not just the code.
The point of the phase: documentation earns its place by being falsifiable. It names what it is derived from, it can be shown to have drifted, and there are sentences it is not allowed to write about itself. AI can draft every word of it; a named person still signs it.
* The production workbench is internal — reachable over the corporate VPN only. This public page is a local demonstration.