# Crawlability passed, and discoverability had not started: evidence note

Date: 2026-09-17

This note supports the /record entry reachability-001. The Essay that carries the
same finding is held for the founder's publish decision and is not on the site at
the time of this note.

What happened. On 2026-09-17 a technical SEO audit of ouroboric.ai (a6c54ec9)
scored six layers. robots.txt carried the expected body. sitemap.xml was valid
XML with 11 locations, all returning 200 and each matching its own canonical.
Every page carried one unique title and one description, with no robots meta tag
and no noindex. The pages were server-rendered, with six record entries in the
static HTML and no JavaScript needed to read them. Every indexable page was
reachable within two clicks, with no orphan. Crawlability, indexability and
rendering passed clean; architecture and structured data passed with minor
issues; page experience came back partial.

Finding F1 was the absence of a discovery path. The live pages carried no
google-site-verification token and no Bing msvalidate token. The domain's DNS TXT
records held a single SPF record and no verification record. Nothing in the
record shows the sitemap was ever submitted, and submission is not observable
from outside. The Wayback Machine's CDX index returned an empty list for the
domain, and a Common Crawl query returned no captures; the audit found no inbound
link. Decision a713e418 named the binding constraint as discovery and authority
rather than crawling, and rejected three alternatives: treat it as a crawl bug
and rewrite robots, sitemap and canonicals; put keyword and content work first;
or assume Google had already indexed the site because the pages return 200.

The change. The audit produced 14 findings, F1 to F14, and the other 13 were
hygiene. That wave shipped: items A1 to A12 (ecd9f09e, ca01787b) were deployed as
deployment 4f9841a2 at commit 331bed10 (private repository), with post-deploy
check 52671161. The wave fixed the source exposure, the duplicate paths, the
sitemap lastmod, the social and structured data, the 404 canonical and the
security headers.

Independent verification (1eeb9f9e, 13:49 to 13:55Z) confirmed the technical
layer, weakened the Bing signal to its generic empty-state text inside a
JavaScript shell, and restored one finding the audit had omitted, a favicon 404
on the record pages. Google's index status was never observed, because a fetch of
the site: query returned a consent interstitial rather than results.

The open items. The discovery layer is outside the repository and belongs to
Josh. The workstream 9eb10efb checkpoint, updated 2026-09-17T14:38:52Z and
reading waiting, lists them: keep Cloudflare HSTS off while enabling Always Use
HTTPS and the www redirect; verify the domain in Google Search Console and Bing
by DNS TXT; submit the sitemap; request indexing; grant the team read access; and
decide the inbound-link strategy.

Sources. Audit a6c54ec9; independent verification 1eeb9f9e; hygiene wave ecd9f09e
and ca01787b; deployment 4f9841a2 at commit 331bed10; post-deploy check 52671161;
decision a713e418; workstream 9eb10efb; gate 028de1c2.

Limit. The discovery layer has never been observed by an agent. Google's index
status is unobserved, sitemap submission is not observable from outside, and the
absent offsite footprint is indicated by two proxies, not proven.
