Anton Dziatkovskii · ORCID 0000-0001-7408-3054
Preprint, 10 September 2026. Version of record: Zenodo, DOI 10.5281/zenodo.22694070. License CC BY 4.0.
Full text (PDF, 8 pages, 197 KB)DOICode: claude-bible
Experience report, not an evaluation. An operating instruction given to an LLM agent survives one session. Written into the agent's always-loaded configuration file it survives longer, until that file grows past the point where the model reliably attends to all of it, and then it decays silently: nothing errors, the rule simply stops firing. The same instruction given to a second machine, a second agent or a human assistant is a second copy, and copies drift.
This report describes the governance layer run daily in a small production operation and published sanitized as an open repository: rules as one file each with typed frontmatter; precedence by recency and by author (newer beats older, owner-stated rules overturned only by their owner, supersede instead of delete); a routing tree giving each rule exactly one home, with deterministic “every time X” rules leaving prose for hooks; an always-loaded index carrying only trigger, essence and pointer, with the body loaded on demand; a journal of declined decisions with explicit revisit conditions; an intake ritual whose acceptance test is whether a parallel session that never saw the originating conversation would apply the rule unaided; a door quota requiring every rule to name the caller that will invoke it; a separation between writing a rule and compacting the index that holds it; and objection sparring, which turns an agent's refusal into a numbered objection list the principal is invited to rebut.
Two of the nine mechanics exist only because the design failed and the failure was measured. At one audit, 19 of 25 recently added rules had no caller anywhere in the system (76%), and one had sat unused for 42 days. A separate lesson came from a rule the operation could not keep at all: a release cadence tied to the calendar rather than to the work.
Most of this is not novel and the paper says so per mechanic. A novelty ledger names the prior art that already covers each one: policy-as-code, GitOps and infrastructure as code, architecture decision records, the RFC process, agent memory architectures, long-context attention limits, and the AGENTS.md convention, whose comparison the paper states in the convention's favour for single-machine operators. A grounding table separates what a reader can verify in the public repository from unaudited operator instrumentation and from design opinion, one central number is marked self-judged, and the limitations name the design's weakest joint: precedence carries dates, not a logical clock.
Code: github.com/tonydzi/claude-bible (specification, templates, sanitized examples, MIT), docs at tonydzi.github.io/claude-bible. Contact: dzyatkovskiy.a2@gmail.com · ORCID 0000-0001-7408-3054 · github.com/tonydzi · tonydzi.github.io. Corrections and failed reproductions are welcome as issues on the repository.
LLM agents · agent governance · rules as code · policy as code · configuration management · CLAUDE.md · AGENTS.md · prompt engineering · precedence · supersede · declined decisions · decision records · human-agent teams · multi-machine agents · experience report · context window · instruction following · sycophancy · objection sparring
Dziatkovskii, A. (2026). Rules as Files: Governing the Behaviour of LLM Agents Across Sessions, Machines and People. An Experience Report from a Single Production Operation. Preprint. Zenodo. https://doi.org/10.5281/zenodo.22694070
@misc{dziatkovskii2026rulesasfiles,
author = {Dziatkovskii, Anton},
title = {Rules as Files: Governing the Behaviour of LLM Agents Across Sessions, Machines and People. An Experience Report from a Single Production Operation},
year = {2026},
publisher = {Zenodo},
doi = {10.5281/zenodo.22694070},
url = {https://doi.org/10.5281/zenodo.22694070},
note = {Preprint, CC BY 4.0}
}
One text, one DOI: the PDF on this page is the Zenodo file byte for byte. Please cite the DOI.