Operating manual

How the shop actually does the work.

A procedures manual for the door. Members can read it. The people running the shop should follow it. House rules live on Policies. Last written 29 Aug 2026.

P1. A shop joins

They open Join, give an email and a password, and land on the map. Founding door is open; we are not blocking unpaid shops while Stripe is still being wired by hand. Do not invent a second signup path. Do not create accounts for people who did not ask.

Welcome letters send from noreply@clearportals.com only after a shop has actually joined, and only once the founding note is written. Empty roster, empty letter. No hollow mail.

P2. Keys on file

Shop opens Settings and pastes keys. Save encrypts them on the host. Never write a key into the website files, the books, a chat log, or a memory. If a shop pastes a key to the people running the door, encrypt it onto that shop and forget the paste.

House key is xAI. Optional: OpenAI (chat, image, hear), Anthropic, ElevenLabs (voice), Perplexity (search), DeepSeek, Google Gemini. Gemini is never the default door.

If a key fails, tell the shop the vendor said no. Do not debug by printing the secret. They rotate at the vendor, then paste the new one.

P3. The map and the room

After login, first stop is the map. Gold center is the shop. Hover shows what an object is. Click pulls it in. Empty dark pans. Do not send a shop into a white dashboard.

The room defaults to Grok 4.6 on the official responses door, reasoning kept low so credits last. Other models only if that key is on file. Image, voice, search, and hear are their own objects, not buried in the chat menu.

Do not fire a surprise smoke test against a shop’s credits.

P4. Mail

Read the box that was written. Do not bounce a money question to hello@ and leave it.

hello@

Public door. Answer as the shop. If they want in, point at Join. If they want out, delete the account.

support@

Door stuck, key failed, seat locked out. Reset is: they use the login they made. We do not email passwords.

books@

Money only. Founding $19 until the split is lower and the books can carry it. No bulk line until we actually buy bulk.

admin@ is for running the shop, not for members. noreply@ does not get answered; if someone replies anyway, pick it up from hello@. freedom@ is brand.

Never put mailbox passwords on the website.

P5. The vault

Every new shop gets a T-account. Deposits debit that T and credit the pool. A buy debits the buyer and credits the seller at leftover face, listed at the cost they paid. Do not post an entry that does not balance. Do not put keys in ledger.json. The file is encrypted. If someone marks up a lot, the form should refuse it — if it does not, pull the lot and write books@.

P6. Books

Keep Books honest. Member count is the live roster. Roof target stays until we change the actual hosting cost. Founding rate is what we charge. Door-call counts are fine. Chat text is not. If we have not bought bulk, the bulk line says none — not a hoped-for number.

When Stripe is live, settlement is the ClearPortals books, not a private side ledger. Until then, founding payments are tracked by hand and still belong on books@.

Arbitrage is the gap between list and bulk. Do not write an arb number on the books until we have a real invoice to divide. If someone asks what arb means, send them to the co-op page.

P7. When someone burns the roof

Abuse, stolen keys dumped into the door, hammering the host, using the room to break the law. Close the shop. Remove the encrypted keys. Note a closed shop on the books without publishing their mail. Write them once at the address on file, from hello@ or support@, so it is not a silent lockout.

P8. A shop wants out

They can strip keys in Settings themselves. For a full delete: hello@ receives the ask from the address on file, we drop the account and keys, we do not keep a souvenir copy of the secrets. Thin usage lines may stay as anonymous traffic. Confirm once. Do not argue them into staying.

P9. Changing the door

Copy is dark, gold, member-owned. No growth-team language. No Apple Watch language. No leading with Gemini. Do not rotate the server app key; that would brick every encrypted key on file. Do not commit secrets. Put the change on the live host and cache-bust what you touched.

If the domain is ever sold, tell shops first from hello@, then close or move accounts. Paid months do not buy the name.

P10. Liability, in practice

We do not give medical, legal, tax, or financial advice in the room or in mail. If someone asks the shop to bless a high-stakes decision, point at a human with a license and at Policies §4.

We do not promise uptime, model truth, or that a vendor will keep a key alive. We do not pay a shop’s vendor bill. We do not run surprise calls on their credits. If something breaks, we fix the door and we say what broke — we do not write a guarantee we cannot keep.

P11. Who does this

One shop is running the door right now. Mail is read by that shop. There is no night staff. If hello@ is quiet, it is because a person has not opened it yet, not because a bot is ignoring you.

Join the co-op Read the policies