"A ban with a fuzzy exception is not a ban. A ban with one exception, cut to the exact shape of a single need, is a promise."
The Ban That Makes the Family Trust the Hub
Firelink never edits an existing sibling's source. Not to fix a typo, not to bump a config, not while it's 'already in there.' That ban is the reason every sibling can let Firelink observe and operate it without fear — the hub reads your Git state, plans a deploy, restarts your service, but it never reaches into your files. The credibility of the whole hub rests on that promise being absolute.
Why Birth Doesn't Break It
And yet Firelink can create a whole new repository. How is that not a violation? Because Birth creates a shell that did not previously exist. There's no established sibling to edit — the thing being written is brand new, owned by no one yet. Birth is the exception that proves the rule: it's allowed precisely because it isn't the thing the rule forbids. The ban is on editing what exists; Birth is creating what doesn't. Those are genuinely different acts, and the exception is cut exactly along that line.
The Exception Stops Hard
Crucially, the carve-out is narrow and it stops hard. Birth's authority to write a new shell does not extend to filling that shell with product intent, and it never, ever extends to touching an established sibling. Birth may create cwkNewThing and correctly name its architecture and version files — and then it's done. It cannot decide what the product is, and it cannot 'while I'm here' edit a neighbor. One hole, exactly the size and shape of one need, with no slippage past its edges.