A traveler reads DelayPilot standing at a gate, tired, minutes before an expensive and irreversible decision. The failure that would destroy this product is not a missing article. It is confident, fluent prose that states a right, a number, or a statistic no regulator source supports. Everything below is a mechanism for making that particular failure hard to commit by accident. Right now, no article has reached the last state, and the reason is on this page rather than hidden behind it.
The seven states
Draft
Not served. There is no page at all.
Every external claim in the body is listed in the claim map against the primary source a reviewer must open to confirm it. No regulatory value is written as prose — each one is a rule slot. The frontmatter is complete: a unique title, a unique description, a one-sentence intent distinct from every other entry, a two-to-four-sentence answer that the page itself renders as the lead, the cited source ids, a reviewed date, a next-review date, and an author who is a role rather than a person. The word floor is met: 900 body words for a guide, 700 for a rights explainer, 400 plus three real data fields for an airport, airline, or route entry. The forbidden-phrase check is clean, and the body opens with the answer rather than a heading or a restatement of the title.
Source review
Not served.
This state does not mean the claims are true. It means every one of them has a named place to be checked, and somebody other than the author now has to open it. To leave, a reviewer has opened each cited source, recorded the date it was verified, and confirmed or rejected every mapped claim. A rejected claim is deleted, not reworded: a claim that survives only as a hedge was never supported. Every rule slot in the entry resolves against a rule set in force for its jurisdiction, or the slot is removed along with the sentence around it.
Legal and factual review
Not served.
The sources are verified and the regulatory claims are awaiting sign-off. To leave, that sign-off is recorded, and the content-quality gate reports zero failures for the entry: word count, source references, a unique title, description, intent and opening, no placeholder token, no duplicate canonical address, freshness, indexable flag, and editorial status. Accessibility and voice review are added where the entry introduces a new component or a new pattern of wording.
Publishable
Served, marked not to be indexed, and carrying a visible line that says it is awaiting final review.
It passes every gate and has not been released. Only a human promotes an entry out of this state — no automated process does, including the one that wrote it. That is why the page is readable by anyone sent the link, invisible to search engines, and honest on its face about which of those two it is.
Published
Served. It is indexable, and may appear in a sitemap, only if it is also marked indexable in its own frontmatter.
Released. An entry leaves this state only by demotion, and demotion is automatic rather than argued.
Review due
Not served. It leaves the sitemap in the same build.
A cited source has passed its review interval. The way back is the source gate again, not an appeal: open every cited source, confirm each claim still holds, record the new verification date, re-run the quality gate, and either refresh the reviewed date or demote further.
Stale
Not served.
A cited source failed re-verification, or a rule set was superseded or withdrawn. Nobody argues a stale page back into the index; the route back is the same re-verification as the first time.
The serving rule, in one place
An entry is generated as a page only at publishable or published. It is indexable, and therefore eligible for a sitemap, only when it is published and marked indexable. In every other state no page is emitted at all, so there is nothing to find, nothing to link to, and nothing to accidentally leave in a sitemap.
Primary sources, or nothing
A rule value is only ever taken from the body that made the rule: the regulator, the official journal, the legislative text, or the aviation authority's own published guidance. News coverage, law-firm commentary, claims-company marketing, forum posts, and aggregator summaries are never the authority for a threshold, an amount, a deadline, or an effective date. They are often how a change is noticed; they are never how it is confirmed.
Each source is a record in a registry, carrying its authority, its canonical address, the date it was last opened, and the date it is next due for review. An article cites the record rather than pasting a link, and the rule set cites the record too — so a correction at the source propagates to every page that depends on it instead of being fixed on one page and missed on four others. A link that rots shows up as a rotten registry entry rather than as a silently wrong sentence.
Each record also carries an evidence class. A secondary record — a press release reporting on a reform, for instance — is filed as a context source. It can support a status note and nothing else. It is never the authority behind an amount, a threshold, an effective date, or any other rule value, and it is never listed beside a regulator as though the two carried the same weight.
How many sources an entry needs
A regulatory or rights page that makes external claims cites two primary records. An explanatory guide that makes external claims cites one. A context source never counts toward either number. The rule exists to stop a page resting on a single fragile citation.
There is one deliberate relaxation, and it is deliberately narrow: where the registry holds only one primary record for a jurisdiction, one is the honest maximum, and the entry says so plainly in its own sources section. That is the position the EU explainer is in today — one primary record, plus a press release filed as context and counted toward nothing. The relaxation exists so that a page can be honest about a thin registry. It must never become a reason to promote a press release to an authority in order to reach a number.
No regulatory value is written as prose
No compensation amount, distance band, delay threshold, notice period, claim deadline, or regulatory effective date is typed into an article. A figure hardcoded into prose keeps rendering confidently after the law changes, and no reader can tell.
Instead the sentence is written around a rule slot: a placeholder naming a jurisdiction and a path into that jurisdiction's rule set, which the page resolves at build time. Three consequences follow, and all three are the point:
- A value is never rendered without its version. The rule-set version and its effective date are displayed beside the number, so a reader can see which edition of the rule they are looking at.
- An entry with a slot that cannot resolve is not served. It does not fall back to a remembered figure and it does not render an empty space; the page simply does not exist until the rule set does.
- The concepts are still explained in words. Named frameworks and how they are built — distance bands, notice periods, arrival delay at the final destination — are described normally. It is the values that come from the rule set, not the ideas.
Entries that make no external claim
An entry whose every claim is about DelayPilot's own behaviour has no external authority to cite, and cites the repository's own documents instead — named as plain text paths, never dressed up as links. Such an entry can reach publishable without a single source fetch, and two limits keep that from becoming a loophole. It may state only what the product does today, or what a written invariant enforces; describing an unbuilt feature as existing is a defect, not a style choice. And the moment it makes one external claim it is not internal any more, and the whole entry goes back to source review.
How language is policed
The list of phrases this product refuses to publish is maintained in exactly one place —docs/VOICE.md §4, owned by the team that owns the product's voice — and it is deliberately not restated here. A rule written down twice is a rule that drifts, and the copy that drifts is always the copy in the second place. What this policy adds is the editorial consequence:
- Every entry passes the automated check before it leaves draft. A hit is a rewrite, never an exemption.
- Near misses count. What is banned is the claim, not the string, so a phrase that says the same thing in different words is the same defect.
- Outcomes are phrased as what may apply, may be available, may qualify, or what a rule can require.
- Rights statuses are limited to five: a rule likely applies, may apply, is not indicated, cannot be determined from what is known, or is a future rule that is not yet in force. None of those means money is due.
- Content does not teach a vocabulary the product refuses to accept. DelayPilot never asks for a booking reference, so its writing does not tell you to find one; it tells you what is actually needed, which is a carrier, a flight number, and a date.
Context is never cause
An airline's or a provider's stated reason for a disruption is reported as that airline's or that provider's statement, never as a finding. Observed weather and airspace status are context. Nearby weather never proves an extraordinary circumstance, a within-control classification, or anything else about who is responsible. Only a verified authority finding is a finding.
The four jurisdictions, and the mistakes each invites
- United States. Five separate layers, written as five separate things: the federal refund rule, voluntary dashboard commitments, denied-boarding rules, enforcement discretion, and the contract of carriage. A general federal cash-compensation right for an ordinary delay or cancellation is never stated or implied. The 2026 enforcement-discretion notice is written as enforcement guidance with a defined scope and window — never as a repeal.
- European Union. Only the framework currently in force is applied. Bands, distance boundaries, the rerouting reduction, notice periods, and delay thresholds all render from the rule set. Extraordinary circumstances is an airline's assertion, subject to determination.
- The 2026 EU reform. Held as adopted and not yet effective until the official publication date and the computed effective date are verified. It is described side by side with the rule in force and applied to nothing — not early, not retroactively. Applying it early is treated as a critical defect.
- United Kingdom. Written from the UK regulator's own guidance, as a framework separate from the EU one. A separate-ticket self-transfer is never described as a protected through journey.
- Canada. The three control categories, and the large-versus-small carrier classification taken from the official source. Proposed reforms are not law and are never written as law.
No invented statistics
No on-time percentage, average delay, "most delayed airport", passenger count, success rate, claim-approval figure, satisfaction score, or savings claim appears in DelayPilot's writing unless it comes from a cited primary source with a date, or from the product's own smoothed estimator shown with its sample size and a note on whether that sample is sufficient, suppressed or widened for small groups.
Specifically ruled out: a round number recalled from memory; a figure from a news summary presented as a regulator's; a percentage from an uncalibrated model; a raw ratio over a small sample; a "typical" or "average" figure with no measurement behind it; and any number whose purpose is to look authoritative. Unknown is a designed state, not a gap to fill — a sentence that needs a statistic it does not have is a sentence that gets deleted. That applies to DelayPilot's claims about itself as forcefully as to anyone else's: no ranking, no accuracy boast, no comparison it has not measured.
Review cadence
Every entry carries a reviewed date and a next-review date, and the interval is set by the most volatile thing it cites:
- 30 days — it cites the 2026 EU reform, the US Department of Transportation's notices page, or either Canadian Transportation Agency page. These are the sources that move.
- 90 days — it cites any other regulatory or external-authority source.
- 180 days — it cites only repository documents, because its claims are about DelayPilot rather than about the law.
Independently of that date, a scheduled job reads the review register and demotes any entry whose cited source has not been verified for 180 days. The register carries, per entry, the slug, the route, the page type, the status, whether it is served, whether it may enter a sitemap, both dates, the cited source ids, the repository references, the rule-set references, the rule slots, and the claim count — so the demotion is mechanical rather than a judgement call.
A review is not a glance. It is: open each cited source, confirm the claim still holds, record the new verification date, re-run the quality gate, and then either refresh the reviewed date or demote the entry.
Corrections and retractions
Errors are fixed in public, and the procedure is the same whoever finds it.
- Critical — a statement of a right, an obligation, an amount, a deadline, or a threshold that is wrong; a future rule applied early; a general US cash-compensation right implied. The entry is demoted to stale in the current build and leaves the sitemap immediately. It is fixed, both review gates are re-run, and it returns with a dated correction note.
- Material — a claim that overstates certainty, a missing condition, a mis-attributed cause, a broken source mapping. The entry is demoted to review due, fixed, and put back through the source gate, with a dated correction note on the entry.
- Minor — typography, a broken internal link, an unclear sentence with no change of meaning. Fixed in place and logged in the entry's history, with no correction note.
Four rules do not bend:
- A correction note names what was wrong, what it now says, and the date. It does not explain the error away.
- Corrected text never silently replaces wrong text on a page about rights. If someone may have acted on the wrong version, the note says so.
- A claim that should never have been published and cannot be repaired is retracted: the claim is removed, the address keeps a page that explains the removal, and a rewritten page is never left at an address that once said something materially different about a right.
- A source that has changed underneath us is a correction trigger, not an invitation to argue that the old wording was defensible.
DelayPilot publishes no contact address today, so there is currently no route for a reader to report an error. That is a gap, it is stated rather than papered over, and this page will name the address on the day one exists.
How this writing is produced
Stated plainly: DelayPilot's articles are drafted with large-language-model assistance under a named editorial role, and every external claim is gated on a human-verifiable primary source before publication. Authorship is attributed to that role. It is never attributed to a private individual, and never to an invented person with a biography to match.
What that commits us to:
- No fabricated expert, byline, photograph, credential, or quotation.
- No generated statistic, review, rating, testimonial, or user count.
- Model output is a draft. The source gate and the legal and factual gate are what make it publishable, and neither can be passed by the model that wrote the draft.
- The drafting tool is never the value proposition. What is trustworthy here is the sourcing discipline, not the software that produced a first sentence.
- Structured data reflects only what is visibly on the page: no author markup naming a person who does not exist, and no ratings, reviews, prices, or awards that were never earned.
Where the content stands today
Twenty-five entries exist — twenty guides and five passenger-rights explainers. Eighteen of them are held at source review for one checkable reason: not one primary source has been opened. The source registry holds twenty-seven records, every one of them marked unreachable with no verification date, because every attempt to fetch a regulator page was refused by the network policy of the environment this site is built in. Its publication gate is closed, no rule set exists or can come into force, and nothing that depends on a rule value may be published.
Six entries have reached publishable. Every one of them makes no claim about any regulator's text — they explain how DelayPilot itself estimates risk, assesses a connection, labels freshness, and reaches a rights status — which is why they clear source review with no external citations at all. They are served, marked not to be indexed, and carry the line that says they are awaiting a final human read.
One entry stays at draft because it describes a feature that does not exist yet. Describing an unbuilt feature as though it were built is the defect the draft state is for.
The consequence is visible rather than hidden: no article has reached published, no article appears in the sitemap, and no rule set is in force. What unblocks it is external — the environment has to allow outbound access to the regulator hosts, or the verification has to run somewhere that already does. Then each source is opened and verified, each mapped claim is confirmed or rejected, the rule sets are published, and the entries move through the remaining states in the order above. Nothing in the writing needs to change for that to happen; the claim map is already the work order.
Related policies
- Terms of use — why passenger-rights output is an estimate rather than a determination.
- Privacy — what reading these pages collects about you.
- Advertising policy — why no advertiser reaches the writing.
- Data sources — the registry these rules cite, and its current state.