What it does for you: It writes down every accepted Command once, together with its result and the Events it caused, in one local file. If a recorded command is retried, you get the recorded answer back and the decision is not run again. A stale or conflicting command is refused rather than guessed at.

Plate 1, position 1, Plumb with the ledger: a bound ledger with a ribbon bookmark. The plate is shown whole.
How it links: Takes commands from Execution, Guarded verification / recovery, Portfolio and Project guidance · Gives recorded state and history back to them, and read-only views to the Dashboard, whose two commands write through Portfolio and Project guidance.
Honest limits:
- It runs on one machine with one local file. Crash tests used killed processes; power loss is not tested.
- Events are queued in an outbox that nothing delivers yet. Nothing is migrated or trimmed, so the file only grows.
- It remembers its own answers. Anything a caller does outside the journal can still happen twice on a retry.
Status: Accepted local reads and writes (local review, 28 September 2026). This covers local development only, not a release, and the epics it serves remain open.
