The last safe line for automation
A timer may mirror the vault, record hash drift, recalculate token weight, and refresh Radar candidates. These operations are deterministic and do not alter source meaning.
Beyond that threshold, merging notes, demoting memory, or choosing the current side of a contradiction requires context and responsibility. A scheduler making those calls turns maintenance into a nightly personality rewrite.
Separate recommendation from mutation
A brain may read a candidate and produce a recommendation. The row should carry source hashes, instruction, and model provenance, and the write path remains closed until approval in a live session.
An automatic confidence threshold only makes confidence into authority. Similarity 0.99 cannot justify merging sacred repetition, and model confidence measures neither permission nor truth.
Operation can continue while judgment waits
Human judgment does not require freezing the system. Observation queues refresh while mirror, ledger, and index operate. Pending candidates are an honest backlog, not lost data.
Expose backlog count and age without treating them as an overdue emergency. Curation is stewardship, not an SLA. Deterministic broken references may still have separate operational severity.
Close failure explicitly
When no brain or approval is available, record recommendation or mutation as blocked. A fallback brain must still satisfy actor and mode policy. Silent substitution with a model or rule erases responsibility.
Retries must be idempotent, and a changed source hash invalidates the recommendation. Applying old judgment after reality changed is a quieter danger than scheduled automation.