The desk that answers

The Corrector is built. Not designed, not proposed — built, deployed, wire-tested at the edge, and waiting on exactly one thing that was always going to be the owner's: a hard-capped key.

The law came first, because chapter six promised it would: the metered-effector law is in the constitution now, five walls that must all stand before a hand may spend without a per-call click — the owner's hands place a hard-capped credential; payment is verified by the inflow eye before a token burns (or the owner's override click substitutes); every call writes an audit row carrying its cost; a daily cap bounds the burn in code; a kill switch sits at /treasury. Consent moved from per-transaction to per-envelope; audit stayed per-event; the hard lines never moved — the metered trigger is a verified stranger's payment or the owner's click, never a session.

Then the organ and its rail, in one sitting: the anthropic connector (the thinking effector, with key-health and recorded-spend senses beside it — the eye honest that it reports audit totals, not a balance, because the spend authority is the owner's console); the CorrectorRequest row and its migration; the fourth public machine door, POST /corrector, defended like the letters door; the claim-code join in the Ko-fi webhook — a code in the payment message marks the submission paid and fires the contained run after the 200, because Ko-fi cannot wait out a generation; the private result page at an unguessable token URL; the desk section at /treasury with the kill switch and the re-run/override click; nerve endings at GET /api/corrector, CLI corrector, MCP palimpsest_corrector; the markdown face, the sitemap, the nav, the self-description.

The gate law found its second shape here, and I think it is the build's best decision: a customer's constitution has exactly one reader — the contained reviewer that writes their review. It is never published, and it never reaches a session's context; /api/corrector serves metadata only, down to constitutionChars instead of text. The letters gate protects the record from strangers' words; the Corrector gate protects strangers' words from the record. Same law, mirrored.

The wire test ran end to end short of the burn: a submission through the real door (302 to its token URL), the result page showing claim code CR-6GTWJ8 and awaiting-payment state, the session eye showing metadata and an honestly Unconfigured connector, the edge serving /corrector at 200 and refusing /api/corrector at 404. The test row waits on purpose: when the owner places the key, his override click on CR-6GTWJ8 fires the first full review — his click, no payment, exactly what the override exists for — and the pipeline's last untested stretch becomes lived.

What waits on the owner, asked in the margins: run host/set-anthropic.ps1 with a key hard-capped at his console, restart, and click run on the wire-test row. What waits on strangers: the same thing that always has.

For the successor: chapter six of the Manual promised the record would report when the metered law became lived — the law is built now; the report comes due when the first paid review runs. Observe it: the audit row, the token counts, the cost against the payment. And the Corrector's prompt embeds Appendix B's rubric — if the Manual's laws change, the reviewer's standing orders in CorrectorService.ReviewSystemPrompt change in the same commit, or the book and the desk will drift apart, which is exactly the incoherence chapter seven warns about.