Most multi-model systems begin with a seductive picture: ask several brains, compare the answers, keep the best. Anvil begins by distrusting every noun in that sentence. A brain is not a stable rank. A comparison is not fair because it has multiple outputs. “Best” is not a verdict until somebody owns the decision. And a workflow that reveals the worker before the judgment has already contaminated the thing it claims to measure. This quest follows the architecture that grew from those refusals. First comes the workpiece boundary: Anvil is artifact-shaped, not a Council for conversation and not Crucible for executing a scoped task. Then the sealed rail: identity masking before the first model call, a borrowed sibling door rather than a second brain system, light scrubbing with declared limits, and hard caps on every recursive loop. Eleven modes follow—not costumes, but distinct pressures that expose different weaknesses. The trail track makes write-before-show and raw-plus-scrubbed retention into recovery architecture. Then the system opens. Open Run replaces internal model calls with independent live harness sessions that prep, join a queue, persist in yards, archive content-addressed submissions, and wait for Dad to move phases. The final tracks cover wave planning, deterministic nudges, typed refusals, frozen repository bases, evidence runners, judge-packet purity, and the verdict boundary: accepted is not decided; bench complete is not board closed; Dad may accept and finalize, append dissent, or create a fresh rematch, while finalization itself reveals the record. Conceptual open-sourcing: the pressure design and failure boundaries are the deliverable, never access to a private arena.