# From one controlled Golden Short to a repeatable CartoonOS business Owner: **Head of Content (A0)**. Updated: 2026-09-08. All timelines and numeric thresholds below are proposed operating targets, subject to budget, platform/provider access, reviewer capacity and measured pilot results. ## Business foundation Audience: children 5–8; production language es-419 first; value: original mascot adventures where accurate observation/evidence changes a character's choice. CartoonOS uses one seven-mascot universe: `Lumi · Tiko · Nova · Marina · Rin · Arqueo · Pepe` Lumi remains franchise protagonist. There is **no mandatory production pair**. All seven maintain baseline identity/voice/reference readiness; deep readiness follows the cast selected by the approved story. Maintain one business/project brief with project/channel identity, audience promise, active mascot versions, editorial scope, rights owner, publishing owner, budget currency and reviewer availability. Income is an experiment: platform revenue when eligible; later original educator resources, licensing, partnerships or commissioned production for adults. No revenue is assumed in runway calculations. ## Pilot objective The first system proof is **one controlled Golden Short**, not automatically S01E01 and not automatically Lumi+Tiko. A0 selects the smallest useful cast from the approved story based on: - story objective; - domain fit; - emotional function; - character readiness; - environment/reference readiness; - provider capability; - budget/expected accepted-second economics; - learning value. S01E01 keeps its frozen episode-specific provenance and can follow after the Golden Short proves the production loop. Episode-specific casts never become global architecture. ## Phase A — trust and baseline readiness 1. Confirm current runtime revision and source-of-truth docs. 2. Prove PostgreSQL migrations through current Alembic head and controlled Temporal worker boot. 3. Restore trusted CI execution/required checks when available. 4. Confirm durable object storage/checksum/recovery path. 5. Confirm project/channel/account identities, budget and reviewer capacity. 6. Stabilize baseline visual/voice/reference readiness for **all seven mascots**. 7. Complete one production-ready environment/reference/CameraAnchor bundle. 8. Refresh exact provider/model capability snapshots and live access/credits. This phase does not require every mascot to be deeply production-approved before any work can begin; it requires each mascot to have an honest baseline state and no invisible missing identity. ## Phase B — story-selected Golden Short A0 chooses one 45–90 second package with the smallest useful story-selected cast. Required chain: `Opportunity → Evidence → Scenario Packet → A0 Scenario Approval → Cast/Readiness → ScenePlan/ShotSpec/Continuity/RenderPlan → PromptIR/CompiledVideoRequest → Golden Shot → Golden Sequence → Rough Cut/Audio/Edit → Platform Packaging → A0 Release/Autopost Approval → Publication/Reconciliation → D1/D3/D7` ### Golden Character readiness For every mascot actually used in the Golden Short: - exact active character ID/version; - approved master/reference set; - identity/anatomy/silhouette/expressions QA; - voice audition/binding if speaking; - provider identity/reference binding; - Golden Character Test; - safety/originality/IP QA; - production telemetry enabled. Pair/ensemble motion tests are required only for relationships actually used by the approved story, not as a permanent Lumi/Tiko gate. ### Golden Shot Run one controlled shot first. For the exact shot persist: - ShotSpec/version; - active prompt/compiler version; - capability snapshot; - exact reference set; - provider/model; - compiled request checksum; - attempt/job IDs; - failure/repair data; - cost/runtime; - accepted output asset ID/checksum; - QA result. A successful provider generation is a candidate output, not approved footage. ### Golden Sequence Only after the Golden Shot passes, produce 3–5 connected shots and test: - character continuity; - environment geography/state continuity; - camera/editability; - relationship/eyeline logic; - audio/voice continuity; - attempts per accepted shot; - cost per accepted second. ### Golden Short Assemble the 45–90 second short. A0 approves the final content/release packet only after all hard gates pass. ## Phase C — controlled release and autopost proof Build platform-native renditions only from the approved canonical master. A0 approves what may enter publication/autopost. A6/platform adapters execute independently per platform. Every publication request requires: - approved canonical lineage; - final media checksum; - platform-native packaging; - audience/made-for-kids/disclosure/privacy state; - account authorization; - schedule slot; - publication ID/idempotency key; - A0 release-decision reference; - reconciliation route. A timeout or unknown mutating response is not permission to repost. Reconcile first. Publication is complete only when platform asset ID/final state is persisted. ## Phase D — prove the learning loop Collect D1/D3/D7 observations as actually due. Track: - hold/retention/completion/rewatch/share where available; - returning-viewer/follow-on behavior where available; - hook/cover/title/rendition attribution; - mascot/relationship/environment attribution; - prompt/model/provider version; - first-pass acceptance and attempts; - cost per accepted second; - production cycle time; - publication success/reconciliation latency. A7 proposes a learning with metric definition, cohort/sample, data-through timestamp, uncertainty and alternative explanations. A0 accepts/holds/rejects. The loop is not proven until one accepted learning creates a **versioned change** to a brief, prompt, template, route, cast policy, production rule or priority and that change is used by the next package. ## Phase E — first flagship / S01E01 Only after the Golden Short loop is reconstructable should CartoonOS promote a flagship episode into controlled production. If S01E01 is selected: - preserve its episode-specific cast/provenance; - update its evidence/source IDs to real frozen records; - resolve exact story-selected mascot/voice/reference versions; - use the same Scene-to-Screen, compiled-request, generation, rough-cut, release and learning contracts proven by the Golden Short; - do not infer a global duo policy from its cast. Start with one flagship in production and at most two derivative Shorts queued until review throughput and cost are measured. ## Phase F — repeatability before scale Aim for three consecutive controlled releases whose: - evidence/approvals are complete; - production inputs/outputs are reconstructable; - hard budget/reservations are reconciled; - publication IDs/status are reconciled; - due measurement checkpoints are accounted for; - no unresolved critical safety/IP/factual defects exist. Only then increase throughput, WIP or provider capacity. ## Seven-mascot portfolio health Do not declare a mascot winner from one asset. For every active mascot track: - lead/specialist/support exposure; - sample size and uncertainty; - character/voice/reference QA; - first-pass production acceptance; - cost/accepted second; - matched retention/engagement contribution; - returning-viewer/affinity evidence where measurable; - strongest/weakest domains; - solo/pair/ensemble performance when enough comparable data exists. Sparse exposure is an evidence gap, not proof a mascot is weak. ## Economics and capacity Track cash spend and economic cost separately. Cash may include provider bills, storage, hosting, licensed audio and contractors. Economic cost also includes labor/allocated overhead where the business chooses to model it. Keep credits separate from money. Use authenticated quote/capability data for the exact model parameters. Unknown submit outcomes retain their reservation until reconciled. Optimize **quality-constrained cost per accepted second**, not raw cost/generated second. ## Head of Content daily control A0 daily: 1. reviews fresh opportunities and current blockers; 2. reviews canon/doc/prompt/data freshness affecting active work; 3. selects the highest-value package within WIP/budget constraints; 4. approves/revises/rejects scenario packets; 5. resolves cast/readiness and production priority exceptions; 6. approves platform packages entering publication queues; 7. reviews provider/publication unknown states; 8. records decisions with evidence/reason IDs. ## Weekly operating review - 10 min: trust/runtime/publishing incidents, spend, blocked queue age. - 10 min: cycle time, first-pass acceptance, accepted seconds, failure/repair Pareto. - 10 min: eligible performance cohorts, missing data, mascot/format/packaging evidence. - 10 min: documentation/prompt/canon freshness + one Decision → Result → Learning record. - 5 min: choose the next few tasks within WIP/budget/reviewer limits. A0 owns the decisions; specialists bring the evidence. ## Recovery playbooks | Event | Immediate action | Resume evidence | |---|---|---| | Provider POST timed out | Mark unknown, retain reservation, inspect correlation/job data; do not blindly resubmit | reconciled provider result or reviewed resubmission decision | | Provider outage/rate limit | Pause dispatch; bounded retries/polling; preserve queue/budget | provider health + queue budget verified | | Expiring output | Copy to durable private storage and checksum | verified durable object + provenance | | Wrong facts/unsafe release | Stop related publication; invalidate approval | corrected master + new release approval | | Secret exposure | Revoke/rotate; audit access | new secret reference + limited smoke test | | Database/media loss | Restore in isolated environment and compare manifests/checksums | restore drill record + owner acceptance | ## Scale rule Add workers/provider capacity only when measured queueing, runtime, memory, cost or failure isolation justifies it. Do not add another executive agent for documentation, prompts, autoposting, analytics or character management. Use the A0 control plane plus bounded skills/workers/validators. Permanent rule: **Prove one story-selected Golden Short loop, learn from it, then scale the engine—not a historical duo assumption.**