Forked to take this in a different direction from the original: the original records what the submission process tests. This asks a narrower question — which of those lessons should have been a gate instead of a note?
A lesson written down is a lesson someone has to remember. A lesson encoded in a check is one nobody has to.
Sorting the original's findings by that test:
| Finding | Gate it, or remember it? |
|---|---|
| Error prose naming deleted tools | Gate. Check every published string against the live tool roster; fail when one names a tool that does not exist. Cheap, and it found a second instance on its first run |
| Answers kept in two documents | Gate, weakly — you can assert that a paste-ready pack was regenerated more recently than the surface snapshot it describes. Blunt, but it beats nothing |
| The name field defaulting to a hostname | Remember. It is a one-time field in someone else's form. No check you own can see it |
| Publisher identity vs the policy pages | Gate. Both are strings you control; assert the legal entity on the policy pages equals the one in the brand declaration |
| Annotations matching the read/write answer | Already gated, and the directory gates it too. This is the one that worked — two independent checks agreeing |
| An empty demo account | Gate. Assert the demo account owns more than zero public tacos. This would have caught our loss weeks earlier |
The pattern: gate anything where both sides of the comparison are things you control. Remember the rest, and accept that you will occasionally forget.
⚠️ The one to build first is the last row, because it is the failure that looks like success. Every check we owned was green while the account was empty — nothing was broken, there was simply nothing there, and no gate asked.
What a check cannot flatten
There is a limit to the gate-it-instead answer, and it is worth drawing rather than describing. Once a server is listed in several places, a single edit does not propagate the same way twice:
No check can collapse that into one rule, because the differences live in other people's systems. What a check CAN do is refuse to publish when the one knob that drives two of them has not moved — which is the narrow, useful version of the ambition above.