simsimDéoviá Studio
← The working library

Review · planning-review · 15 September 2026

Final reviewed master plan

Thirty completed design reviews: the current planning baseline, boundaries, dissent and open questions.

Public edition of a studio document. Proposals and historical observations retain their original status; local paths and operational identifiers are omitted. The final reviewed master plan records later planning corrections; older design explorations remain historical proposals.

All 30 actual design-review rounds and their syntheses are complete. This is the final reviewed planning baseline, not an implementation-ready specification or empirical validation. This main plan accompanies the numbered review appendix. Planning establishes proposed contracts and unresolved choices, not implementation, authorization, shipment, predictive validity or demand. G1 is unchanged. Astro, Astrobot, simsim and Becoming remain working or historical names; no final brand, engine or license is selected.

1. Promise and sovereignty

Astro helps a person navigate the life they deliberately value. simsim offers possible lives worth inhabiting: solitary, playful, artistic, relational or contemplative. Neither needs to maximize productivity, screen time, wealth, public contribution or spiritual attainment.

Their shared conceptual grammar is state → choice → consequence → memory. Astro reasons about reported and observed real life; simsim explores authored and simulated possibilities. This is a common interface, not a merged database or an empirically validated universal causal model.

The person remains sovereign over goals, participation, disclosure and real action. A companion may challenge contradictions without inventing psychological measurements or overriding consent. The player may decline, remain private, stop, or value an experience without producing something for others. Payment, lineage and fictional status grant no additional governance.

Protect attention more aggressively than the system creates tasks. A useful interaction may provide clarity in thirty seconds and then end. Continuous simulation is a long-term possibility, not an obligation to monitor the user or continually surface advice.

2. First Light: the protected small experience

First Light is planned for free entry as a complete local slice without payment infrastructure; public distribution and offer terms require separate authorization. Its scope remains one room and covered terrace with a rain view and neighbor interaction area; one active character, one NPC, a scripted Astrobot, two independent saves and one active simulation. Three mornings offer Stillness, Craft and Connection. Baseline, mixed and skipped-practice paths remain supported.

Free inspection explains affordances. Beginning practice requires an explicit commitment with a visible cost; actual preparation produces the relevant capability. Idle time, dialogue or selecting a label cannot award completed investigation. No unattended or offline progression advances the life.

On the third morning, every supported route intentionally compares two occurrences within the scheduled rain and records recurrence in the notebook. Baseline-accessible observation supports completion without Craft instrument operation. Earned specialist actions add Stillness timing, Craft's prepared receiver readings, or Connection's qualified and attributed testimony; none establishes cooling causation. Preparation changes what the player can notice, measure or interpret; it does not substitute for performing the investigation. The cooling-grid explanation remains author-only causal context in G1.

Record the finding before the companion acknowledges it. Warmth should recognize something the player actually did. Requested hints and accessible presentation remain available without payment.

The unresolved R04 question is whether this local discovery feels meaningful enough. More lore, a larger world or stronger praise cannot automatically repair a weak payoff. No accounts, payments, live inference, Relay, multiplayer, media pipeline, globe or personal-model infrastructure enters G1.

3. Astro as personal decision support

Astro becomes a personal world model: a revisable account of the user’s goals, projects, commitments, resources, preferences, environment and decision-relevant patterns. It generates plausible trajectories and evaluates trade-offs, while keeping the user’s choice separate from its recommendation.

Simulate decisions, not destiny. A narrative about what might happen is not a forecast validated by running it repeatedly. A coherent simulation can still begin with mistaken assumptions.

A morning briefing may show a balanced path, an ambitious path and a meaningfully different alternative. These are useful categories, not a quota. One clear recommendation or a focused question may be better. On-demand comparisons can use text and later authorized voice interfaces.

A proposed operating arrangement uses one coherent companion voice and one designated current-state record. Work, Chat, Codex and local models are not assumed to share memory automatically. Pending actual integration, the proposal is to use explicit, minimal handoffs with source version, task, boundaries and returned result. This is a design proposal, not an attributed founder operating preference. Existing routines and their purpose-specific authority must be verified before reuse; this plan creates no additional briefing or monitoring schedule.

4. Goals, evidence and privacy

Goal weights express user preferences across a whole life portfolio. They may include horizons, temporary boosts, minimum progress and explicit trade-offs. They are not probabilities or comparable units of human welfare. Example goals, relationship variables and numerical priorities are not current founder settings.

Hard constraints exclude otherwise attractive options: consent, spending authority, commitments and confirmed non-negotiables cannot be outweighed by a high score. Conflicting constraints require clarification or an honest absence of feasible options. Show sensitivity when a recommendation changes with modest preference adjustments.

Keep user reports, authorized observations, hypotheses and interpretations distinct. “I felt interested” records an experience; it does not establish mutual attraction. Preserve contradictory accounts with source and time unless corrected. Missing observations do not establish inactivity. A changed priority applies prospectively; historical rescoring is a labeled what-if.

PRIVATE, SIM-SAFE, SHAREABLE and PUBLIC describe scoped uses alongside sensitivity restrictions. Approval names fields, destination, purpose, duration and processing location. Private reasoning does not automatically authorize cloud transmission. A narrow standing rule may cover recurring abstraction without repeated prompts.

A sim-safe projection must remove unnecessary identifying detail while preserving decision-relevant facts, constraints and uncertainty. A declined invitation cannot become “a promising interaction.” Combining coarse details can identify someone. Ordinary reflection on one’s own experience is permissible without demanding consent from everyone mentioned; it does not authorize disclosure, contact or claims about another person’s hidden traits.

Corrections invalidate dependent advice. Deletion removes controlled sensitive source, retrieval and revealing derivatives; provenance cannot secretly retain the deleted text. Preserve separable nonrevealing work and disclose limits on distributed or provider-retained copies.

Optional IRL activities retain intrinsic value without needing to improve a score or generate game content. Verify practical availability before actionable availability claims; recommendations are not bookings. Contact, booking, media capture/publication and importing real-life material into simulation each require applicable separate authority. Offer accessible alternatives, and impose no paid-access penalty for declining an IRL activity or its recording.

5. Counterparts, worldmaking and symbolic lenses

Mirror mode imports only approved records with their original evidentiary status. Gaps may remain unknown. Alternative mode explores an identified unchosen branch. Autonomous mode permits bounded simulated decisions under specified rules, goals and resources; it supplies no real-account authority.

Classify relevant claims, not an entire scene as “real.” A scene can combine reported experience, authored fiction, simulated consequences and symbolic interpretation. Mode changes cannot rewrite earlier provenance or carry permissions across boundaries. A matching later real event needs independently sourced evidence.

Ancestors may speak, bless, forgive and disagree naturally within established fiction. Newly generated dialogue belongs to that encounter; it is not recovered testimony or continuing consent from a represented person. A user may genuinely report feeling moved without certifying the fictional explanation.

Optional astrology, tarot, I Ching, intuition and other symbolic lenses can enrich reflection and aesthetics. Their weights change reflective emphasis, not empirical credibility. Contextual explanation and inspectable sources should preserve immersion; misleading claims of authenticated messages require revision, not a disclaimer.

Worldmaking may be small, solitary and intrinsically valuable. Descendants and institutions retain permitted lineage. Inherited tools may function without awarding an ancestor’s achievement, identity, rights or governance. Private creation, publication and shared adoption remain separate.

6. Companion, providers and bounded computation

Astro’s coaching intensity changes directness, not evidentiary authority. “Your recorded evenings mostly went to coding” can invite reflection; “your true relationship priority is 2/10” invents a measurement. Intensity never licenses humiliation, coercion or manufactured dependence.

Distinguish scripted responses, on-device models, user-controlled remote providers and official hosted services. Voice may involve separate capture, transcription, reasoning and synthesis paths. Local presentation does not prove local processing. Provider selection alone is not permission to send all available context.

Before authorized processing, establish the payload scope, approved path, resource limit, retention and fallback. New providers or materially changed data require applicable authority. A generation request does not authorize a game action. “Stop speaking,” “stop listening” and accessible captions need distinct behavior.

QUICK, DEEP and EXTREME remain future effort concepts without fixed counts or prices. More computation may analyze existing evidence, vary models, examine failures or reduce sampling error inside an explicit stochastic model. It cannot establish that model’s real-world validity.

Require a named uncertainty, method, stopping condition and bounded spend. Ask a cheaper high-value question when appropriate. Reserve enforceable authorized costs before dispatch; uncertain execution retains uncertainty. Local IDs do not prove provider idempotency, and status checks may themselves cost resources.

Managed service needs finite funded reconciliation and separately booked customer adjustments without hidden re-debit. Those adjustments do not settle unknown vendor liability. User-provider external budget headroom cannot be restored by imaginary application credits.

Actual provider processing paths and locations, retention, enforceable billing ceilings and cancellation behavior require later provider-specific verification. Mocked policy checks establish application behavior only; they cannot establish those external guarantees.

7. Persistence and portable history

Practice commitment, costs, evidence and Continue transitions need coherent durable boundaries. Recovery uses the original operation identity and originating life; retry cannot silently consume another opportunity. Timeline switching must not apply delayed output to the wrong life or revive an invalidated proposal.

Preserve the last verified state when a write is uncertain. Do not claim recovery beyond available evidence or call a corrupted record restored. G1 needs bounded state and recovery, not a universal event-sourcing platform.

Basic selected-life JSON export/import, a readable archive, an executable checkpoint and derived media are different promises. Selected-life exports retain permitted committed unfinished work, consumed opportunities and duplicate-prevention identities as well as established state. An archive may remain readable without supporting continuation. A checkpoint needs compatible rules, consequential content and sufficient state for the next supported action. Successful serialization alone proves neither.

Exports include only permitted selected material and disclose incomplete or uncertain state. Preserve originals before migration. An older verified snapshot must not masquerade as the latest complete state. Discarding replaceable caches may preserve faithful continuation. Losing required findings, preparation, permissions, or action-enabling state permits only labeled partial salvage or an explicitly approved derivative. Test actual continuation, including evidence, unfinished work, opportunity accounting and duplicate prevention.

Purchased installed content and retained records remain accessible under declared compatibility and support terms without a subscription merely to reopen them. Hosting, future inference, indefinite downloads and perpetual runtime compatibility are separate promises. Deletion can make faithful continuation unavailable; disclose that rather than retain secrets or fabricate replacement history.

Future polished archive presentation and self-hosting installation or maintenance support may be convenience/service offers. They remain separate from basic export, rights granted by the applicable source-code license, and term-defined hosting or inference. No price or perpetual support commitment is adopted.

8. Legacy, Circle and creator content

G2 Legacy Relay tests useful inheritance, personal meaning and voluntary continuation separately. Genuine creator provenance cannot be fabricated for a comparison. Stock support permits independent play. Quiet use is valid; using, adapting, forwarding and returning a finding require their respective permissions.

An imported record can contain assertions without authenticating them. Source identity, content hashes and compatibility do not prove authorship, rights or causal truth. A returned finding stays in its authorized branch and does not automatically become real-world progress.

Circle begins as a bounded encounter for two or three people under accepted turns and ready checks. The specific decision’s accepted participation rule controls. Preauthorization cannot retrospectively convert absence into consent where participation was required. Absence itself supplies no vote, abstention, delegation or AI replacement; dependent progression pauses when required participation is missing. Private branches cannot overwrite shared history.

Payment funds service, not governance. Define funded execution, grace, finalization, export and retention before hosting. Participants need permitted export without the payer’s cooperation. Replacement funding requires explicit spending authority and grants no additional private-data access. At expiry, reconcile already-authorized operations; never manufacture missing choices.

R13 remains unsettled. The provisional active-Circle policy provides a common official assistance boundary, including eligibility and delivery timing. Payment cannot unlock strategically selective guidance there. Broader paid recommendations from identical permitted evidence remain an untested alternative. Neither “cosmetic” wording nor cooperative play alone establishes fairness; outside advice does not justify surveillance.

Creator submissions use bounded reviewed primitives. Imported text and assets are data, not execution authority. Review the exact encounter, consequential assets, complete dependencies and runtime combination. Rights review, mechanical review, explicit Publish and world adoption are distinct gates. Updates need relevant review and authorized adoption. Unsafe versions may require suspension while preserving verified history; pinning promises identity, not indefinite rights or safe execution.

9. Complete chapters and sustainable economics

The first paid chapter should deliver a bounded local question, meaningful player-performed investigation and visible consequence. A deliberate refusal can complete an authored arc without granting an unperformed discovery. Exact title, encounter count and proposed chamber fiction remain unadopted.

Supplied equipment supports independent completion. Optional generation exhaustion cannot gate the purchased ending or existing records. Before an offer, disclose delivered scope, tested requirements, service dependencies, allowances, support boundaries and actual price when authorized.

Separate first purchase, satisfactory completion, voluntary continuation, expressed interest and actual repeat purchase. Chapter 1 evidence plus an approved experiment budget may justify a bounded Chapter 2 pilot; repeat purchase cannot precede its own offer. A release cadence needs later demand and production evidence.

Reuse controls, saves, evidence grammar and assets where useful. New value can come from fresh decisions or emotional and relational meaning; familiar controls and predictable consequences can support mastery. Measure the whole chapter through adaptation, rejected work, accessibility, human review and revision. A successful scene is not throughput evidence.

Separate founder labor, agent time, service expense, shared foundations and chapter-specific work. Contribution after variable costs is not recovered production investment. Include refunds, failures, heavy use and support; avoid deducting creator payouts twice.

Operator-funded access and external sponsorship need truthful different descriptions. Allocation expiry differs from accepted entitlement duration. Protect funds backing promised access and exit obligations before refunding unused allocations. Publicity, gratitude and measurement are not conditions of accepted access. Mixed contributions, refunds and operator adjustments need distinct records and one settlement. Sustainable sponsorship is a legitimate endpoint, not automatically evidence of recipient willingness to pay.

Separate recipient contributions, external sponsorship, and internal grants. Refunding the appropriate payer is a proposed default, subject to applicable remedies or expressly offered benefits. Explain surrendered access before cancellation; preserve independently retained records and funds backing accepted obligations. Unused-allocation refunds cannot consume resources already backing accepted entitlements or funded exit obligations.

10. Media, invitations and growth

Begin with a private draft based on selected events. Distinguish captured gameplay from illustration or reconstruction. Invented dialogue or reactions that materially distort knowledge, intent or achievement must be edited, even if labeled illustrative.

Review the actual final render, captions, attribution, metadata and audience. Storyboard approval is insufficient. One final Publish action can authorize the reviewed bundle; generation and local export alone do not publish it. Recheck affected rights and permissions when content changes or permission is withdrawn.

A view link and playable invitation promise different things. Entry identifies the actual supported save boundary, derived branch, content requirements, permissions and costs. It neither modifies the creator’s active life nor guarantees the depicted outcome. Unavailable or denied entry needs an honest, privacy-preserving explanation; an ordinary start is a separately labeled alternative.

Sharing is voluntary. No compulsory posting, recruitment, gratitude or usage receipt. Senders receive no individual activity dashboard or tiny aggregates that reveal recipients. Declining measurement preserves access.

Test story versus plain invitation among consenting willing sharers with equivalent supported opportunities. Assigned sharers, including nonsenders, form the primary denominator. External exposure counts may be unknown. Track observed consenting participation and missingness honestly; differential measurement consent can confound results. Meaningful action and satisfaction are separate. Attribution is not incrementality, and this comparison does not prove total sharing effects or virality.

11. Useful openness and optional geography

A bounded state/rules core with a complete advertised workflow is the preferred conditional first release candidate. A genuinely useful memory-portability component remains an independent alternative if actual inspection supports it. Neither requires another game build or becomes the other’s prerequisite.

Release checks cover exact revision, applicable license, dependencies, demonstration rights, secrets, repository history, fixtures, exports and support scope. An independent person must perform the advertised workflow without private project credentials or hidden services. Inspect network behavior; offline completion alone does not prove no transmission attempts.

No release waits indefinitely for revenue, network dominance or a marketplace moat. Official distributions, hosting, support and managed operations must earn value through useful service. Source publication, content rights, self-host instructions and official-world admission are separate.

The gods-eye-view globe remains a candidate for later utility and rights investigation, not adopted infrastructure. A code license does not cover every dataset, model or asset. A camera URL restores a view, not a playable life checkpoint. Civilization-scale simulation is not an MVP requirement.

The optional geography probe is one permitted place or marker → one authored scene → return to the overview. Keep simulation state separate from the geographic view and evaluate actual dependency/data rights, cost, performance and usefulness. This is a later bounded test proposal, with no G1 geography integration or stack adoption.

12. Personal trial and human evidence

The smallest Astro probe uses one voluntarily selected, reversible work-block decision. Record Zan’s intended choice and reason, relevant confirmed priorities, constraints and minimal current reports. Preserve a simple checklist comparison before adding a few meaningfully different assumptions using the same information.

Before action, record a concrete conditional forecast, source snapshot and goal/model versions. A new answer obtained between comparisons is additional information, not evidence that scenarios were better. The sequential probe tests perceived added usefulness; order, learning and extra attention prevent a clean causal claim.

An optional later report records action, outcome, interruptions, surprise, burden, ownership and felt pressure. Missing outcomes and unchosen alternatives remain unknown. Unchanged but clearer commitment can be valuable. Nonadherence does not automatically falsify a conditional forecast, but repeated unrealistic execution assumptions require model revision.

Review qualitative accuracy and surprise without fabricating calibrated probabilities or “3–4× opportunities.” Numerical calibration requires suitable prospective forecasts and repeated outcomes. More branches, satisfaction or one successful day cannot validate causal improvement.

For G1, retain the provisional six-new-player gate: at least four must both explain a capability-to-evidence consequence and voluntarily choose another route before observer prompting. Retain legitimate game help and accessibility. Report overlap, emotional closure and access burden separately. This test is unrun, exploratory and not market validation. Synthetic checks and model agreement cannot replace human evidence.

13. Real-agent authority and truthful completion

Keep simulated choice, proposed operation, authorized operation and observed result distinct. Execution needs an applicable user instruction or authorized trigger plus current scoped permission. A capability ceiling is not a work order. Imported scenarios, external messages and tool-returned instructions cannot expand authority.

Identify consequential proposal content before approval. Bind dispatch to its target, relevant dependencies and authorization. Revalidate data scope, provider, budget, expiry and material prerequisites. A standing policy may permit useful recalculation without repetitive confirmation. Canceled approval cannot revive when state returns to an earlier value. Partial execution is acceptable only when independently meaningful and authorized.

Timeout means uncertain completion. Local deduplication cannot guarantee exactly-once external effects. Use supported, authorized and bounded reconciliation before risking duplication. Revocation blocks controllable future work but cannot retract transmitted data. Late confirmation can record an earlier effect without authorizing a new one.

Compensation needs applicable authority and current-state checks; preserve intervening human edits. A local restore cannot undo delivered communication. Receipts distinguish draft saved, request accepted, delivery confirmed and intended result verified, retaining cost/effect uncertainty.

Deletion and revoked permissions must survive delayed outputs, caches and callbacks. Preserve actual verified commits, including honestly recorded unauthorized effects, without retroactive approval. The personal pilot remains recommendation-only.

As in §6, actual provider processing and retention, billing ceilings and cancellation require provider-specific evidence. Mocked authority, retry or rollback tests cannot verify external processing or reversal guarantees.

14. Sequence, dependencies and resources

NOW means recommended next work after applicable authorization. First Light is the implementation focus. The manual Astro probe is independently eligible with a chosen decision and explicit small time allocation; NEXT placement remains a valid priority alternative.

Work package First Light scope
W0 Inspect checkout, ownership, stack and edit/run workflow
W1 State, events, commitments and saves
W2 Room and terrace interactions
W3 Distinct practices and baseline paths
W4 Local reveal and scripted companion
W5 Independent slots and basic export
W6 Polish, accessibility and player observation

G1–G6 are expansion gates: First Light → local Legacy Relay → bounded paid chapter → small Circle → curated creators → hosted worldmaking. They are not automatic commitments, world sizes or substitutes for W0–W6.

Activating feature Evidence and authority needed Delivery burden / smallest test
G1 slice Authorized checkout and bounded task Local recovery, access; six-player observation
Manual Astro Chosen decision, time and data scope Recommendation-only comparison and voluntary outcome
G2 Relay G1 implemented and observed; findings reviewed and a bounded Relay probe explicitly authorized when evidence supports proceeding; reuse permissions Local lineage and quiet use; test inheritance utility, personal meaning and continuation separately, all currently unvalidated
G3 chapter Complete playable arc; approved budget/offer Full production/rework cost and closure
G4 Circle Coordinated-play value; accepted governance Funded exit, fair assistance and absence rehearsal
G5 creators Approved packages, funded review capacity and observed demand/value for outside creators' work before broader intake Exact-version delivery and rights; measure funding, curation/exposure, review and delivery costs alongside demand/value
G6 hosting Demonstrated value and sustainable obligations Bounded operations, export and shutdown
Media / agents Specific publication or execution authority Final-render or operation-boundary tests
Source release Actual useful component and release approval Rights, independent workflow and support checks

NEXT follows observed value: revise First Light if needed and test Relay only when reviewed findings support the authorized probe. The provisional four-person G1 gate is neither a technical unlock nor a substitute for satisfying closure; emotional failure may require revision. Assess whether scenarios add decision-relevant value beyond simple coaching at acceptable attention burden, without claiming predictive or causal validity.

For creator expansion, keep funding, curation, exposure and review/delivery costs visible. Sponsor redemptions and platform credits do not prove recipient willingness to pay. Valuable curated or sponsored offerings remain legitimate endpoints.

LATER features activate only with their required evidence and funded capacity. RESEARCH includes predictive validity, compute methods, checkpoint longevity, fairness, symbolic/twin experience, governance and creator economics. Conditional source release need not wait in research indefinitely.

15. Open choices, dissent and audit record

Before substantial work, the founder must choose the First Light/Astro effort allocation and authorize the actual checkout/task boundary. Stack follows inspection; naming need not block a private prototype. License, maintained package, support, paid terms and Circle assistance policy need decisions before their corresponding commitments.

Preserve three central uncertainties: R04’s emotional payoff; R13’s real disagreement over paid strategic reasoning; and Astro’s unvalidated relation between plausible branches and actual outcomes. Preserve the NOW/NEXT scheduling dissent, intrinsic artistic value, immersion concerns and minimization over premature infrastructure. A smaller curated or sponsored service can succeed without becoming a universal marketplace.

Source crosswalk: the supplied founder product and Astro messages provide direction; the Becoming and simsim source branches retain their distinct identifiers. The minimal handoff arrangement in §3 remains a design proposal. The separate numbered review appendix retains actual contributions, challenges, amendments, dissent and proposed-test status. Conflicting D/BS identifiers remain source-qualified rather than silently merged.

See the local decision and review index and source crosswalk for the companion audit record.

The full numbered completion record, including Round 30 reviewer responses, final challenge and synthesis receipt, belongs in the separate review appendix. Review completion records design deliberation; it does not certify implementation or outcomes.

Status: 30/30 actual design-review syntheses complete. This is the final reviewed planning baseline. Executable fixtures, provider verification, human observation, predictive assessment and commercial tests remain unrun in this review. No build, launch, experiment or message delivery is claimed. This plan authorizes no implementation, publication, spending or personal monitoring; subsequent work follows separately applicable task authority and the feature gates above.

Review receipts: all 30 actual synthesis records.