§07 · checklist · design.md §7–8

Every public Downstream artifact.

Graded here against this styleguide itself, not as a generic reference — if a line below is unchecked, it's a real gap in these six pages, not a hypothetical.

as_of 2026-08-10
Checklist itemThis styleguide
Displays an as_of date in mono, on the surface, unhidden. Every stage on every page carries as_of 2026-08-10 in the header, not a tooltip.
Every factual claim is citable, and the citation is visible or one click away. All copy is quoted from design.md, cited by section throughout (e.g. "design.md §3").
Uses status hue only for status, with a mono token or shape alongside it. Every chip pairs color with the OBSERVED/PENDING/MISSED/SILENT/STRUCK token and a shape glyph. §02, §06.
Contains no self-reported confidence, no percentage-certain meter, no "AI" chrome. No confidence bars anywhere. The one probabilistic chart (§06) shows a distribution against ground truth, not a certainty meter.
Makes no recommendation. These pages describe the system; they state no exposure, no buy/sell, no "you should."
Closes with a caveat line in the same weight as the rest of the page. Every page ends with a .footer-caveat — same type scale as body caption, not smaller.
Passes AA at every text size, verified — not assumed. Every color pairing here is a token lifted directly from design.md's own ratio table (§02), which states its ratios. This page has not re-run an independent contrast audit against the rendered DOM — that's a real gap, marked pending rather than checked.
Reads correctly in grayscale. See the grayscale chip demonstration on §02 — status is still legible by token and glyph with hue removed.
Renders with the fallback font stack, no network fonts required. No @font-face, no font CDN, anywhere in tokens.css. Demonstrated explicitly on §03.

"If an artifact fails the first or the fifth, it doesn't ship. Those two aren't style." Both are checked above.

Open design questions

Same convention as the founding memo — written down while they're still cheap to get right. Carried over from design.md §8, unanswered here on purpose.

  • Does the mark need to be a mark at all? Moody's, MSCI, and ICE are wordmarks. A symbol is a bet that Downstream becomes ambient enough to be recognized without its name.
  • How much does the .sh surface diverge? A genuinely mono, terminal-register developer site is a strong signal to exactly the audience that maintains Layer 1 adapters. It's also a maintenance surface.
  • Does the Ledger get its own visual identity? Argument for: it's a public utility that should look institution-neutral. Argument against: the track record is Downstream's asset and detaching it dilutes the thing it exists to prove.
  • What does a wrong forecast look like? Getting this right visually is worth more than any other single decision in the system. If a resolved-wrong Ledger entry is even slightly quieter than a resolved-right one, the whole trust argument leaks.
  • Trademark. The memo flags it: check "Downstream" before anyone gets attached to a mark.