RULES — Never Break These

For every AI tool and developer

  1. Read docs/ first. Update TASKS.md and MEMORY.md when you finish.
  2. Work on your own branch (for example grok-work), never directly on cetking-one-nextjs. Merge only after Vercel shows a green preview build AND Ravneet has approved it. Full process: RELEASES.md (blue and green sites).
  3. One tool per file at a time. Do not edit the same file two tools are touching.
  4. Bot names, colours, taglines and mascot shapes live only in config/companions.config.ts. Never type a bot name anywhere else, and change that file only with Ravneet's approval. Current lineup: MEMORY.md.
  5. Do not add dependencies without saying why in the commit message.
  6. Small commits. Never a build that fails TypeScript. Run npm run build if you can.

Releases: blue and green (details in RELEASES.md)

  • Green = the live site (cetking-one-nextjs, cetking-platform.vercel.app). Blue = the Vercel preview of your branch.
  • Every site change goes to blue first. Green changes only when Ravneet says "go live".
  • If green breaks, roll back in Vercel first, then fix on blue.
  • Docs-only changes may go straight to green.

Bot isolation (details in ARCHITECTURE.md → Bot isolation model)

  • Each bot works in its own folder. Change one bot without touching the others.
  • A bot may use only its own files and the shared kit. Never import another bot's files; the automatic check blocks it.
  • Every bot page has its own crash wall (error.tsx) and its own on/off switch in config.
  • Bots share information only through the shared student profile or a handover message, never by calling each other's code.
  • Changing a shared part (nav, layout, buttons, login, router, analytics, health) needs a preview check of all six bot pages and home before going live.
  • Every bot has its own tests. A change runs that bot's tests plus a check that all bot pages still open.

Opacity and usernames (details in ARCHITECTURE.md → Opacity and usernames)

  • Students and bots never learn how many users Cetking has: no counts, no "rank N of M", no batch sizes. Outside the top list, show a band ("top 25%").
  • Other students appear only by username (e.g. mickey121), never by real name, phone, ID or centre.
  • A bot knows everything about the student it is talking to, and only anonymised toppers/benchmarks by username about anyone else. Code builds the bot's context; other students' private data and any counts never reach the LLM.
  • Server responses never include real totals or other students' real IDs; errors for "not found" and "not allowed" look the same.
  • Exception: a marketing number Ravneet sets by hand (footer "5,314 users of 2026 batch") is allowed; never compute it from the database.

Safe live changes

  • One change at a time on the live site; check it before the next one goes in.
  • Never paste code into a live editor. Everything goes live from GitHub.
  • Keep the current live version so any change can be undone in one step.

Brand and UI

  • Spell the brand Cetking everywhere students see it.
  • Primary actions use the shared PrimaryButton (components/ui/PrimaryButton.tsx). No one-off CTA buttons. Labels are clear sentence-case actions, never "Click here" or "OK".
  • Never show made-up people as real students (no fake avatars, reviews or testimonials).

Secrets

  • API keys live only in Vercel environment variables. Never in GitHub, chat, screenshots or code.
  • .env.example lists names only, never values.

Data and security (details in SECURITY.md)

  • RLS on every student table. No exceptions.
  • The LLM never writes SQL and never receives other students' data.
  • OTP: max 3 per 10 minutes; 5 wrong tries locks 30 minutes.
  • Cookies: HttpOnly, Secure, SameSite.
  • Free tier uses templates or Groq only. Paid models only for paid tiers.

Product

  • Companion IS the feature, not a helper on top.
  • Every failure shows a playful in-character message with an alternative (lib/health/down-messages.ts), never a raw error.
  • Deploy at off-hours (not evenings, not exam days).
  • Mobile first. All six bots must stay visible together on a phone.
  • Preserve old WordPress URLs (redirects) — never break Google rankings.

Do not touch without Ravneet's approval

  • The OTP system (built separately, PR #114).
  • War Room scoring and leaderboard logic.
  • Pricing, payments, and Razorpay flows.

Source: GitHub cetking-one/docs/RULES.md. Edit the file there; this page updates on the next release.