One signature turns five report-only cleanup instruments into working ones — and ends the per-incident disk asks for good.
The disk died three times today. The fleet writes roughly 400 MB a minute; the only cleaner allowed to act runs once a day and only touches things older than 24 hours. Six purpose-built cleanup instruments watched it happen — five are forbidden to delete by their own headers, every one citing your rule that no agent deletes. The rule is right. What was never built is its other half: a scope you sign once, so the machinery can act inside it without asking. A complete, self-checked cleanup engine has sat finished and uninstalled since June 17. This is an authorization gap, not an engineering gap.
Free space on the machine, from ~/next-arc/disk-watch.log: overnight it drifted 12 → 10 GB with four warnings nobody could act on. At 08:11 it hit 4.3 GB — freeze one. Your manual reap brought it to 55 GB by 10:11. By 13:11 it had burned back down to 12 GB — that hour is the measured 367 MB/min — and at 14:11 it froze again at 5.4 GB. The watcher wrote every line and reclaimed nothing; its own header says "WATCH-ONLY, deletes nothing… Keeper executes all deletions." Full receipts: disk-rootcause-20260826.md.
The pools the machinery may clean, each with an expiry and a hard size cap. (Why both: the compile cache already self-expires at 7 days and still hit 9 GB — a burst writer fills the window faster than the window closes. Age controls the tail; only a cap controls the burst.)
| Pool | Expires | Cap |
|---|---|---|
| Finished sealed-run folders | 2h after the run's evidence is banked | 15 GB |
| Compile cache | 24h | 3 GB |
| Test-fixture books (temp) | 12h | 10 GB |
| Session scratchpads | 2h after the session is provably dead | 20 GB |
| Arc worktrees | on declared lease expiry — never inferred from git state | 25 GB |
Watermarks: below 60 GB free — quiet cleanup of expired items. Below 25 GB — aggressive cleanup plus one notification. The existing 5 GB freeze stays as the floor and should never fire again.
Never touched, ever: the canon repo · the bay's clean mirror · anything a live process holds · live benches and leases · the bay's ledger · and anything registered anywhere — before any delete, the machinery greps every registration surface (hooks, statusline, crontab, launchd, schedule registry, open file handles); any hit means keep and report. That turns this morning's near-miss — a sweep took a live rollback lever — from a lesson someone must remember into a rule the machine enforces.
Internal is 89% full — the capped volume must land on the Extreme SSD (where your August 23 ruling already points) or wait for a reclaim. Signing doesn't block on this; the software layers land first and the volume follows.
The bay's job table says, in its own comment, "nothing deletes." That line is load-bearing doctrine and amending it is exactly what this signature authorizes — the edit routes through warp with its own review, not as a desk drive-by.
"sign" ratifies the policy as written · "sign with changes: …" red-pens any row first · every piece then lands with its own court, and this page records the ratification. Until you sign, nothing deletes anything — today's report-only world continues.