> Public study copy. Original Xavier note path: `00-09 System/02 Vault Governance/02.03 Vault Governance Follow-up Audit 2026-07-04.md`. Secrets/credential-like values, if any, are redacted.

# 02.03 Vault Governance Follow-up Audit — 2026-07-04

> Status: follow-up audit after first cleanup pass
> Scope: Xavier Obsidian vault governance, organization, agility, source routing, link hygiene, and safety boundaries
> Trigger: Paulo asked for a fresh audit after applying the first governance changes and clarifying the need for a personal scratchpad.

## Executive diagnosis

The vault is now in a **healthier operating state** than during the first audit.

The biggest structural problems from the first pass were either fixed or reduced:

- root-level clutter is gone;
- `AGENTS.md` is the only root Markdown file;
- Paulo now has a governed personal scratchpad outside the normal processing pipeline;
- active duplicate Johnny.Decimal IDs are cleared;
- the non-canonical `61 Media` source folder was removed and the YouTube source now lives under canonical `64 Media`;
- obvious direct secret-pattern hits are no longer present;
- unresolved wikilinks dropped from 82 to 25 after safe link cleanup.

The vault is not “too heavy” yet. The current governance debt is more specific:

1. large raw/extracted documents still sit too close to active project/knowledge work;
2. some Voice Lab links remain unresolved because they may refer to future site pages, not Obsidian notes;
3. Source Intake still needs status/TTL discipline;
4. Vault Log and decision registers are valuable but will need compaction/splitting later;
5. templates/tool reference notes contain intentional dummy wikilinks that inflate unresolved-link counts.

## Inventory snapshot after cleanup

- Total Markdown notes: **136**.
- Root Markdown files: **1** — `AGENTS.md` only.
- Active duplicate Johnny.Decimal IDs: **0**.
- Direct secret-pattern hits for known provider/GitHub/private-key patterns: **0**.
- Total wikilinks: **752**.
- Unresolved wikilinks: **25**.
- Source directories now aligned with JDex:
  - `61 Articles`
  - `62 Chats`
  - `63 Documents`
  - `64 Media`
  - `65 Exports`

Area distribution:

- `30-39 Projects`: 73 notes.
- `40-49 Knowledge`: 14 notes.
- `50-59 Operations`: 15 notes.
- `60-69 Sources`: 4 notes.
- `10-19 Dashboard`: 9 notes.
- `00-09 System`: 11 notes.
- `20-29 Inbox`: 4 notes.
- `90-99 Archive`: 5 notes.

## Fixes applied during this follow-up audit

### Root and scratchpad governance

Already applied before this follow-up and verified now:

- `Scrap.md` moved into [[20.99 Paulo Scratchpad - Do Not Process]].
- `coiso.md` removed.
- `Kanban-1783179279765.md` archived as [[Kanban Plugin Test 2026-07-04]].
- Root now contains only `AGENTS.md`.
- `AGENTS.md` explicitly protects Paulo's scratchpad from automatic processing.

### Source folder alignment

Applied in this follow-up:

- Moved [[64.01 YouTube - CEOs Are Regretting Firing People Over AI]] from non-canonical `60-69 Sources/61 Media/` to canonical `60-69 Sources/64 Media/`.
- Removed empty `61 Media` folder.
- Source folders now match JDex.

### Link hygiene

Applied in this follow-up:

- Fixed stale `[[33.09 Draft Core-Guilherme Routing Architecture]]` links to the actual [[33.09 Draft Core-GUI Routing Architecture]].
- Stripped legacy `projects/...` prefixes in ShonenSOL links where the target note already exists under the current Johnny.Decimal structure.
- Stripped legacy `syntheses/...` and some `Content/...` prefixes where the target note exists.
- Converted numeric citation wikilinks in [[31.07 ShonenCollection]] from `[[1]]`-style links into plain `[1]` references.
- Updated `00.01 JDex` last updated date to 2026-07-04.

## Current strengths

## 1. The address system is now cleaner

Active duplicate IDs are gone. The earlier conflict between `37.10 Source Intake` and the approved project extract was resolved by renaming the extract to [[37.14 Approved Thesis Project V9 Extract]].

## 2. Scratchpad exception preserves agility

The scratchpad is important. Paulo needs a place for rough notes that Xavier does not treat as intake.

The current design is good:

- visible and findable in JDex;
- not in root;
- explicitly outside automatic processing;
- still inside the vault for cross-device access.

## 3. Source/provenance model improved

Moving media into `64 Media` closes a real schema mismatch. The YouTube example is now a cleaner pattern:

- raw/provenance media source → `64 Media`;
- reusable concept → `41 Concepts`;
- PhD integration → `37.03` / `37.04` / `37.09`;
- dashboard → pointer only.

## 4. Safety boundary improved

A direct scan for known secret forms found no direct active matches after the earlier sanitization. Some notes contain credential labels or password-manager placeholders, but these are instructions, not visible secret values.

Important caveat: historical sync/backups may still have seen the earlier exposed provider material, so any real active keys that were ever in the vault should still be rotated/revoked.

## Remaining governance debt

## Risk 1 — Large raw notes still live in active work areas

Largest notes include:

- [[37.14 Approved Thesis Project V9 Extract]] — about 108 KB.
- `OSF Form Submission Copy - Voice Lab PhD` — about 50 KB.
- `LPA R Pipeline Study Manual` — about 34 KB.
- [[64.01 YouTube - CEOs Are Regretting Firing People Over AI]] — about 33 KB.
- `LPA OSF Examples for Research Methodology` — about 28 KB.
- `OSF Registration Best Practices and Submission Draft - Voice Lab PhD` — about 23 KB.

This is not urgent, but it matters. Large raw/extract notes make project and knowledge folders feel heavier.

Recommended direction:

- keep `37.14` as a project-facing baseline only if it is actively used;
- if it becomes mostly archival, move the raw extract into `60-69 Sources/63 Documents` and leave a shorter `37.xx Approved Thesis Baseline Summary` in the PhD project folder;
- keep large methodology manuals under Knowledge if actively reusable, but add a concise map/summary note so Paulo does not have to open the long file for orientation.

## Risk 2 — Remaining unresolved links are mostly low-risk, but a few need decision

After cleanup, unresolved wikilinks dropped to 25.

Remaining categories:

- intentional examples in tool/template notes: `Note Name`, `diagram.excalidraw`, `note`, `file`;
- archive-only leftovers: old Excalidraw legacy files and Welcome examples;
- source asset link: `00 Projeto de Tese - Word V9.docx` should probably become a normal file path or a proper asset note;
- Voice Lab page links: `Contribute`, `Ethics & Confidentiality`, `Preliminary Findings`, `About Voice Lab`, and `Funnel/Survey-Questions` may be website/page concepts rather than Obsidian notes;
- one relative source link in `32.17 Website Anti-AI Writing Assessment` should become a normal wikilink to the article note if target naming is confirmed.

Governance decision needed:

- Are website page names supposed to be Obsidian notes, or are they just site navigation labels?
- If they are site pages, avoid wikilinks and use plain text or links to actual content notes.
- If they are content notes, create/rename the corresponding notes deliberately.

## Risk 3 — Intake TTL still needs implementation

The rule exists conceptually, but `37.10 Source Intake` should become stricter.

Suggested minimal format for each intake item:

```markdown
Status: new | triaged | promoted | source-only | needs-verification | archived
Owner: Paulo | Xavier
Source:
Canonical owner:
Next action:
Review by:
```

The goal is to prevent “interesting material” from accumulating without route.

## Risk 4 — Dashboard/link density should be watched

Dashboards are still reasonably concise. Current risk is manageable.

But do not add every new source or concept to dashboards. Prefer:

- dashboards: current state and current links only;
- JDex/maps: navigation;
- source registers/intake: provenance;
- concept/literature maps: intellectual structure.

## Risk 5 — `00.03 Vault Log` is useful but growing

At ~22 KB, it is not a problem yet. But the log already carries a lot of operational history.

Future rule:

- do not log minor edits;
- log meaningful restructuring, decisions, recovery actions, and source/project-state captures;
- consider yearly split once it becomes hard to skim.

## Recommended next actions

## Immediate

1. **Leave scratchpad as-is.** It solves a real user need and should not be treated as governance debt.
2. **Patch `37.10 Source Intake` with status/TTL fields** for future intake entries.
3. **Decide Voice Lab page-link policy:** page names as plain text vs actual Obsidian content notes.
4. **Fix the `37.14` DOCX link** so it points to the real asset path or an asset/source note.

## Near-term

5. **Create a small `60-69 Sources` register** if sources start growing past ~15-20 notes.
6. **Create a short map for large methodology/source notes** so long notes do not become orientation bottlenecks.
7. **Do a focused Voice Lab link cleanup pass**, separate from PhD/source governance.
8. **Review whether `37.14` should remain in Projects or move raw extract to Sources/63 Documents.**

## Current governance conclusion

The vault is currently **agile enough** and much cleaner than before the first audit.

The main principle is holding:

> One information object, one canonical owner; other notes link and record only local implications.

The next risk is not chaos in the folder structure. The next risk is **raw material accumulation**: long extracts, drafts, and source material can slowly make active project folders feel heavy. The answer is not aggressive deletion, but promotion discipline:

- raw/provenance → Sources;
- reusable thinking → Knowledge;
- current work → Projects;
- decisions → registers;
- scratch → Paulo's protected scratchpad;
- tasks → boards;
- procedures → skills.
