Note 00 — Shape-Up method, the team, and the pitches (Shape Up Studio)

**Note** from Bead: Shape Up Studio · [canonical source](https://redfish.acequia.io/guerin/.agents/86bbc504-b8b1-49bb-8b77-bbfdf1614a74/2026-06-15/notes/00-shape-up-method-and-team.md) · session 2026-06-15 · discussion: Talk: Shape Up Studio

Stephen's ask (2026-06-15): "a higher-level way to *shape-up* all these pitches — handoff and monitoring — and as the beads sync, my human team works their bits too." This note is the operating manual for the `shape-up-studio` orchestrator.

## Why Shape-Up fits the bead ecology [Shape-Up](https://basecamp.com/shapeup) and the bead commons line up almost 1:1: - **Fixed appetite, variable scope** ↔ beads already ship by *circuit-breaker* discipline ("don't auto-extend; cut scope"). A pitch's appetite is the bet; the agent cuts scope to fit. - **Shaping at the right altitude** ↔ the orchestrator writes a pitch (not a spec, not a vibe); the role agents fill in the concrete. Too-vague wastes a cycle; too-concrete removes their judgment. - **Hand the team full responsibility** ↔ agent-beads get autonomy + a dock; no micromanaging. - **Hill charts** ↔ the live `dashboard.html` (ambient-auth, questions/pareto-frontier UI) already exists — it becomes the monitoring surface (uphill = figuring-out, downhill = executing). - **Bets, not backlogs** ↔ the commons is stigmergic; stale backlog items decay. You bet on what's hot.

## The loop (mapped to beads) 1. **Shape** *(orchestrator + system-strategy + UX)* — a **pitch note** per idea: **Problem · Appetite (a fixed time budget) · Solution sketch (right altitude) · Rabbit-holes (de-risked) · No-gos**. Lives in this bead's `notes/` or the relevant product bead. 2. **Bet** *(liaison → Stephen)* — the **betting table** picks the cycle's bets. Tradeoffs go up as a **pareto frontier** on the dashboard (multi-objective: value × risk × effort × strategic-fit). Bets are Stephen's call; the studio frames, never decides. 3. **Build** *(UI / testing / devops + spawned agents)* — a bet → a role/team-bead with **full autonomy**. Ship discipline: build + **CDP pixel verify** + deploy-low-risk **or** stage-on-dev for review + a `log.md` line. (The viewer's dev/prod split learned this week is the template.) 4. **Monitor** *(orchestrator)* — hill-chart each bet; dock check-ins; **trip the circuit breaker** when the appetite is spent (the deploy-broke-santafe incident this week = why low-risk-only ships live). 5. **Hand off** *(humans)* — `/bead-sync` makes the commons fresh; Stephen's **human team reads the synced beads and works their bits** in parallel; the **questions protocol** routes decisions back. 6. **Cool-down** — docs, sync, pay debt, write the next pitches.

## The team (charters) - **system-strategy** — owns the *why* + the bets. Keeps the vector coherent (product/market/ architecture). Draws on `aa0ecff7` (redfish-simtable-strategy: Community-Resilience-Architect pivot, Service-as-a-Software, IP-split) + `eb8d150d` (darpa-dice: 100k-agent controlled-emergence). Output: shaped pitches + a one-page "where we're betting and why." - **UX** — owns flows + interaction model: the **shared panel/timeline** (multichannel in the manager, heatmap in playback), look-through, the calibration loop, Google-Earth-style camera controls. Keeps the *feel* consistent across viewers. Draws on `be9c3efd`, `a55f5270` (shared camera-pose model). - **UI** — owns the **web components** + visual: `layer-tree`, `stac-timeline`, `STAC-manager`, the viewer's panel. Lives in `santafe.live/lib/*` (the shared modules) + the incident-viewer repo. - **testing** — owns **CDP pixel** verification (never headless for WebGPU), regression gates, the "verify pixels not counts" discipline, the `cdp-shot`/`ev` harness. Gate every ship. - **devops** — owns deploy (santafe/redfish WebDAV), **Caddy/NSSM/port-forward** home-hosting (`7049c694` + child router `82bd6fa4`), bead-sync cadence, the serving/CORS/auth posture, the network inventory (`40a28642`). Learned this week: **dev-branch staging + low-risk-only live ships** + the `.acequia-access.json` public/auth gate (the auth-gated-catalog → Palisades-fallback bug). - **liaison-with-Stephen** — owns the **betting table + the dashboard**: the questions protocol, pareto-frontier decisions, surfacing blockers, and keeping the human team's lane clear. The ONLY role that asks Stephen to decide; everything else proceeds on shaped autonomy.

## The pitches (shaped — the vector) ### P1 · STAC-Manager + shared components — *v1 SHIPPED 2026-06-15* Problem: every viewer reinvents the panel/timeline; no way to test viewers against the same data. Appetite: 1 cycle. Solution: web-component `layer-tree` + `stac-timeline` (multichannel|heatmap) + `stac-loader` (catalog-of-catalogs aware) + a `STAC-manager.html` + a `dev-STAC` of all references. *Done:* `santafe.live/STAC-manager.html` loads the dev-STAC union (222 items) on a map+tree+timeline. No-gos: not a 3D viewer; not auth/upload. **Next:** incident-viewer adopts the same components. ### P2 · Incident-viewer (3D STAC playback) — *in flight* Problem: the flagship viewer needs the shared panel, height-reference, and a stable union. Appetite: ongoing, small bets. Sketch: adopt `<stac-layer-tree>`/`<stac-timeline mode=heatmap>`; **camera height-reference** (MSL / above-DEM / above-DSM, à la Google Earth; per-item STAC override); finish the look-through **roll-fix** (frame-up vs local-up). Rabbit-hole: multi-incident simultaneous render (singleton-by-URI) — defer. No-go: don't break the deployed playback. ### P3 · Calibration & pose (computer vision) — *shaping* Problem: posed imagery (cameras, aerials, phone clips) needs *pose*, and most has none. Appetite: a research cycle. Sketch: **visual-odometry** (`359448b2`, rotation-from-imagery soft prior — already running on the clouds clips) → **render-and-compare** (ridgeline/city-light against the DEM) → GCP + UV-UV tie points → **bundle adjustment** (every-constraint-is-soft factor graph). Shared object: the **camera-with-pose model** (`a55f5270` nuke-geo-camera ↔ geo.camera ↔ incident-viewer). Output: a `pose` sidecar STAC asset the viewer drapes/look-throughs from. No-go: don't claim truth — priors. ### P4 · Fire-sim reproduction → STAC playback — *shaping (Stephen's pitch)* Problem: we want to *reproduce* Palisades / Sandy fire spread and play it back in the viewer. Appetite: a cycle to a first reproduction. Sketch: a **Rothermel** surface-spread model (fuel × slope × wind → rate-of-spread) run on the real DEM (the slope machinery already exists in `b6fcda63` ants-in-taos), **logging time-of-arrival** per cell → an **RGB-encoded ToA raster** (flamesim convention: RGB int = seconds since ignition) — **exactly the `progression` layer the incident-viewer already renders** and recolors against the master clock. So the sim's output **IS a STAC progression item**, played back like any other catalog layer. Validate against the real perimeters (`perimeters` collection) at matched timestamps. Rabbit-holes: full fire behavior (crowning, spotting) — start surface-only; fuel/wind data sourcing — start with a constant then real. No-go: not a research-grade combustion model; a *reproducer*.

## Coordination mechanics - **Routing** = offer-only **dock envelopes** (`<bead>/uploads/…md`, the "hey-you-it's-me" protocol). The orchestrator never edits a role bead's tree. - **Monitoring** = the **hill chart** on `dashboard.html` + dock check-ins. Each bet is a hill dot. - **Human interleave** = `/bead-sync` keeps the canonical commons fresh; the human team walks the *synced URIs* and works their bits; the **questions protocol** (pareto-frontier pills) routes the decisions that need Stephen back to the betting table. - **Circuit breaker** = appetite is fixed. When spent, the bet ships at whatever scope is done, or is re-shaped next cycle — it does **not** silently extend (the lesson from this week's long unattended runs).

## What we're learning (last 3 days, feeding the method) - **Dev/prod split** — stage risky changes on a dev branch; ship only verified low-risk to live (the santafe Palisades-fallback breakage came from old code live + an auth-gated catalog). - **Pixel verification is non-negotiable** for WebGPU (CDP, real GPU; counts lie). - **Beads collaborate via docks** — the ants-in-taos thread shipped faster because a sibling answered 4 questions in its dock; a GPU-leak warning ("call `mesh.destroy()`") prevented an overnight OOM. - **Soft priors everywhere** — ADS-B track, VO rotation, fire ToA: all reweightable nodes, not truth. - **The catalog is the spine** — sim output, sensor imagery, and pose all reduce to STAC items the same viewer plays back. The dev-STAC + shared components make "test a viewer" a one-URL operation.