Skip to content

Brand Principles

Governs the reasoning every other foundation answers to, so that a rule can be traced to a principle and a principle can be traced to what it costs to break.

Status
Approved
Status note
Canonical. The design principles every other foundation answers to; three items are acknowledged and intentionally excluded (§8).
Version
2
Updated
2026-08-26
Approved by
Fernando Kylas
Approved
2026-08-26
Supersedes
Nothing. It replaces a stub that anticipated four sections and stated content for none.
Open items
3 open, 2 resolved, of 5 recorded
Canonical source
foundations/brand-principles.md

Not one principle here was invented. Every one was already being asserted, repeatedly and independently, in the foundations that came first. This chapter was written by reading Typography, Colour, Identity, Grid and Accessibility, counting the arguments they make in common, and naming each one once so it stops being restated. Each principle names the chapters that already carry it.

That order is backwards, and the chapter says so rather than hiding it. Principles should precede the system they govern. These followed it. What that cost and what it bought is §7.2.

What is approved

Fernando Kylas approved Brand Principles on 2026-08-26, the last of the six foundations. The approval covers the design principles the rest of the system answers to: what a principle is here (§1), what the system is for (§2), how it decides (§3), how it knows (§4), how it changes (§5), the deliberate refusals (§6), and the traceability rule that a rule can be traced to a principle and a principle to what it costs to break.

It also approves the chapter's scope, which was the question that held it back. PRINCIPLE-05 asked whether positioning, personality and voice belong here, in a seventh foundation, or permanently outside. They are permanently outside, in a place that was verified to exist and to be maintained, and architecture.md §1.1 now states that boundary instead of this chapter asserting it alone. This chapter is finished.

Three items are acknowledged and intentionally excluded:

No undocumented change may modify the approved principles. A change supersedes a decision in DECISIONS.md, with a reason.

CompanionPurpose
typography.md · colour.md · identity.mdThe three mature chapters these were extracted from
grid-layout-rhythm.md · accessibility.mdThe spatial chapter, and the gate §3.3 and §4.1 must clear
../AGENTS.mdWhere the governance principles of §5 are already enforced
../DECISIONS.mdThe record every principle in §5 is visible in

1. What a principle is here

A principle is not a value, a preference or a slogan. It is a reason that outranks the rule it produced, and the test is blunt: where a rule and a principle conflict, the rule is wrong.

Three properties, and a statement missing any of them is not a principle:

PropertyTest
It explains rather than specifiesA foundation says what. A principle says why, and does not restate the what
It costs something to breakEvery principle below names the failure it prevents, and most name a measured one
It is already load-bearingSomething in the system depends on it. A principle nothing depends on is an opinion

Thirteen principles, in four registers, and the order is deliberate: what the system is for, how it decides, how it knows, and how it changes.


2. What the system is for

2.1 Typography carries the identity

Cover the colour on any page of this system and the identity survives: the low x-height, the geometric evenness, the measure, the rhythm. Reverse it (keep the colour and set the type in Arial) and nothing of the brand remains.

That asymmetry decides how much work each part is given. Colour is the least load-bearing element, so it carries the least. The mark appears once per surface at most, and where it is absent typography is expected to be doing its job. A practice that publishes evidence needs that evidence legible in a photocopy, a greyscale print, a screenshot pasted into someone else's deck, and a dark-mode inbox. Every one of those destroys colour. None destroys typography.

Already in force: colour.md §1 argues it and acts on it; identity.md §1 depends on it to justify a logo that appears less often than in most brands.

Cost of breaking it: a system that leans on colour becomes unusable in the conditions its own readers read it in.

2.2 The system must survive its author

"A brand system earns its name at the moment it stops needing its author."

This is the purpose the other twelve serve. Everything here that resembles bureaucracy (a decision record, a status label, a named approver, a pipeline that fails on drift) exists so someone who was not present can apply the system correctly.

Already in force: identity.md §10 states it. The whole of AGENTS.md implements it.

Cost of breaking it: a brand only its author can apply is a personal style, and it stops being an asset the moment they are unavailable.


3. How the system decides

3.1 Restraint is functional, not aesthetic

Every addition incurs obligations, and they are specific rather than rhetorical. A new hue owes a measured contrast ratio against every ground it can appear on, in both themes; a meaning nothing else already carries; and a reproduction that survives print and greyscale. Two hues is two pairs to prove. Six is thirty.

A spacing value owes the same debt. It must mean something, be distinguishable from its neighbours, and survive every viewport, every canvas and print. So does a type weight.

The evidence that this is practice rather than preference is what the system declines. One accent hue. Three pause values covering 199 measured intervals. Two of thirteen spacing steps never used at all. Five licensed type weights recorded as Not used, each with the reason it was refused.

Already in force: colour.md §1, grid-layout-rhythm.md §1.4, typography.md §4.

Cost of breaking it: every unpaid obligation becomes a defect later, somewhere nobody connects to the addition that caused it.

3.2 An element carries meaning, or it does not appear

Colour communicates meaning or it is not used. Space carries meaning or it is noise. A spacing value that carries no meaning is decoration, and this system does not permit decoration.

This is one principle stated twice in two domains, and the second chapter says so outright: its spatial philosophy is the colour philosophy applied to space. Naming it once is the reason this chapter exists.

Already in force: colour.md §1, grid-layout-rhythm.md §1.

Cost of breaking it: decoration is indistinguishable from signal, so a reader learns to ignore both.

3.3 No single channel carries meaning alone

No colour carries meaning alone. Anything communicated by colour is also carried by text, shape or position. Severity is a square, state a circle, confidence dots, coverage a bar: four channels that never share an encoding, so no two blur in greyscale.

The principle generalises past colour, and the system has already generalised it: a relationship carried only by a spacing value is not a relationship, because it survives only as long as the document structure does. Measured, that failed 22 times before anyone noticed.

The test is subtraction. Remove any single channel (hue, distance, position, weight) and the meaning must still arrive.

Already in force: colour.md §8, accessibility.md §Colour, grid-layout-rhythm.md §12.

Cost of breaking it: the meaning reaches only readers who have every channel, which is not all of them, and never in a photocopy.

3.4 A property belongs to what content is, never to where it sits

Width is a property of what the content is. Prose takes the reading measure because it is read; a table takes the content column because it is scanned. Neither takes a width because of the space available.

The same rule governs naming: a token states a job and never a colour, so grounds can change and jobs cannot. It governs artwork: one logo file inherits its colour from the context that uses it, rather than shipping twenty-one files that can drift from the palette. And it governs relationships: a heading binds to what follows because it is a heading, not because someone wrapped it in the right element.

This principle has the sharpest measured failure in the system. An attribute-less <div> was deciding its most deliberate spatial rule: 22 silent failures in one chapter and none in another, from nothing but whether an author happened to add a wrapper.

Already in force: grid-layout-rhythm.md §1.3, §3.6, §5.4; colour.md §4.1; identity.md §4.1.

Cost of breaking it: the meaning survives only while the structure does, and it breaks silently when the structure changes.

3.5 Fidelity outranks fit

Some content becomes false when it is made smaller. A type specimen set at a given size is that size; a demonstration drawn at a fixed width marks that width. Shrinking it to fit leaves the label truthful and the artefact lying.

So such content keeps its true size and scrolls within its own bounds. Fitting is not the test. Reading is.

Already in force: grid-layout-rhythm.md §3.4; typography.md §8, which restates type per canvas rather than letting a value shrink into invisibility.

Cost of breaking it: the artefact appears to demonstrate something it no longer demonstrates, which is worse than not showing it at all.


4. How the system knows

4.1 Every number names its instrument

No figure appears in this system without the instrument that produced it and the date it was taken. Contrast ratios are computed by WCAG 2.x relative luminance over sRGB. Type metrics were measured from the licensed OTFs. Geometry was measured in a browser. Intervals were measured before they were named.

The consequence is that a reader can re-run any figure, which is the only thing that makes a specification arguable rather than merely stated.

Already in force: all three mature chapters carry it, in the same position, doing the same job. It is the strongest invariant the system has.

Cost of breaking it: an unattributed number cannot be checked, so it cannot be corrected, so it becomes true by repetition.

4.2 A prohibition carries its consequence

Never avoid stretching the mark. Always: the mark's radial symmetry and the wordmark's letterfit both distort, and a geometric sans makes it obvious.

A rule without a consequence is a preference, and a reader is entitled to weigh it. Measured, the system holds this at roughly four prohibition-with-consequence constructions per thousand words, near-constant across three chapters. Nobody designed that number.

Already in force: three of three mature chapters, at a measured density.

Cost of breaking it: an unexplained prohibition is obeyed until it is inconvenient, then broken without anyone knowing what it protected.

4.3 Judgement is disclosed as judgement

Where a figure is an opinion, the chapter says a judgement, not a measurement, in those words. Minimum logo sizes were judged from a rendered ladder. Three density modes were inferred from a page inventory. The page edge's proportional behaviour was read as intentional and labelled as a reading.

Authority is claimed narrowly, and the boundary is drawn by the author rather than left for the reader to find. A system that says which of its numbers are opinions is more trustworthy than one presenting all of them identically, and the disclosure costs nothing but the discipline of noticing.

Already in force: colour.md discloses four, identity.md five, grid-layout-rhythm.md throughout. typography.md discloses none and has judgements, a known gap, PRINCIPLE-01.

Cost of breaking it: an opinion presented as a measurement gets defended as if it were one.


5. How the system changes

5.1 One canonical source per domain, and derived things fail rather than drift

Each domain has exactly one place its rules live. Everything else (a rendered chapter, a report, an export, a publication) is derived, and is corrected from the source rather than the reverse.

Derivation is enforced rather than intended. Pipelines regenerate artefacts from canonical sources and exit non-zero when they no longer match, so drift fails a check instead of being found later by a reader.

The system has already met the failure this prevents: a correction reached a published chapter and never reached its source, in a repository whose second rule is that the source wins.

Already in force: AGENTS.md §3§4, and four --check pipelines.

Cost of breaking it: two sources for one fact, and no way to know which is current.

5.2 Nothing is deleted for being wrong

A superseded value is marked and kept, with a named successor. A resolved open item stays, struck through, with the date and what closed it. A reading that turned out to be incorrect is retained and labelled must not be cited.

The reasoning is the part that has to survive, and a record that deletes its mistakes cannot explain how it arrived anywhere. It also makes correction cheap: an observation labelled as an observation was corrected without argument, because nothing had been staked on it.

Already in force: five of seven foundations, and every entry in DECISIONS.md.

Cost of breaking it: the same decision is re-litigated, because nothing records why it went the way it did.

5.3 Approval is an act performed by a person

Passing review, QA or validation is evidence of readiness. It is not approval. Approval is never implied by silence, by a file existing, by a frame existing in a design tool, or by work looking finished.

One person approves. Everything else proposes.

And locking a rationale is a different act from approving an artefact. A way of thinking about a problem can be settled long before the thing it describes is ready to ship, which is what lets work continue coherently with almost nothing approved.

Already in force: AGENTS.md §1§2, and every status label in the system.

Cost of breaking it: ambiguous approval, which is what makes brand systems rot.


6. What this chapter does not cover

The stub this replaces anticipated four sections. This chapter supplies one of them.

AnticipatedState
Design principlesWritten, above
Positioning: what the practice is, who it is for, what it replacesNot here. Held outside this repository, which owns the visual and spatial system rather than the argument it serves
Personality: traits, each with its not clauseNot here, and the same reason
Voice: how the brand sounds in writingNot here. AGENTS.md §11 governs this repository's own prose and now cites the brand voice guide rather than restating it. The brand's public voice is held outside

Settled on 2026-08-26, and the boundary is no longer this chapter's to assert. architecture.md §1.1 states it: the repository owns the visual and spatial system, and the Notion workspace Digital impact consultancy owns the argument it serves. All three above are held there, positioning in its Marketing pages and personality and voice in its Brand voice guide. This chapter is finished (PRINCIPLE-05), and a chapter titled Brand Principles that covers only the design half now says where the other half is rather than only that it is absent.

Deliberate refusals

Not a principle hereWhy
Warm, direct, premiumThe brand's qualities, held in the Notion Brand voice guide (architecture.md §1.1). They describe a result rather than governing a decision, and no rule traces to them, so they are direction rather than principle. Confirmed current 2026-08-26, superseding the six recorded in HANDOVER.md. PRINCIPLE-03
A value, scale or tokenThose are foundations. A principle carrying a number would be a rule
AccessibilityDeliberately not a principle. It is a gate: §3.3 and §4.1 are the principles, and accessibility.md holds the thresholds they must clear, in all six of its sections since 2026-08-25. Calling it a principle would make it aspirational, and it is not
"Clarity"True of everything here, and therefore decides nothing

7. Design decisions

7.1 Why these were extracted rather than written

Because they were already in force. Thirteen statements were being asserted repeatedly across five foundations, in near-identical language, and one chapter said outright that it was applying another's philosophy to its own domain. Writing new principles would have produced a second set, competing with the one the system actually runs on.

A judgement, not a measurement: the grouping into four registers, and that thirteen is the right number. The recurrences are countable. The naming is mine.

7.2 Why the chapter admits it arrived last

Principles should precede the system. These followed it, and pretending otherwise would be the first violation of §4.3.

What that cost: four foundations were written and one approved without a principle to trace them to, so every rule was justified locally and some arguments were made three times over.

What it bought, and it is not nothing: a principle extracted from five independent instances is demonstrably load-bearing. A principle written first would have been a hypothesis, and the system would have had no way to tell which ones it actually needed. Every principle here has already survived contact with four domains.

7.3 Why there is no hierarchy among them

They do not rank, and no case has yet required one. Where two conflict in practice, that conflict is evidence about a real tension and belongs in DECISIONS.md as a decision, rather than being pre-empted by an ordering invented in advance. PRINCIPLE-02 records the one plausible collision.


8. Open items

8.1 PRINCIPLE-01: Typography discloses no judgements and has them · Open

Its minimum sizes and its tracking curve are judgements, and the chapter presents them like measurements. §4.3 makes that a principle violation rather than a stylistic inconsistency. The fix is to label them, not to re-derive them.

8.2 PRINCIPLE-02: §3.5 and §3.1 can collide · Open

Fidelity outranks fit, and restraint says every addition owes an obligation. A demonstration that must hold its true size costs a rail, a scroll affordance and a second reading mode. No instance has yet been expensive enough to force the trade; the resolution belongs in a decision when one is.

8.3 PRINCIPLE-03: the brand qualities have no home · RESOLVED 2026-08-26

This item recorded premium, minimal, editorial, elegant, quietly confident, highly readable from HANDOVER.md as qualities governed by nothing.

They had a home, and it was not the one cited. The Notion Brand voice guide states the brand in three words: warm, direct, premium. Confirmed current by Fernando on 2026-08-26.

Only premium survives from the list this item quoted, and warm was never in it. The HANDOVER.md six are superseded, not homeless: a later and more considered statement exists, with a dedicated Brand personality page behind it. HANDOVER.md sits in docs/fkpp/, which architecture.md holds as historical evidence never cited as current guidance, so quoting it forward was the defect rather than the absence of a home.

They remain not principles here, and §6's refusal stands unchanged. A quality describes a result; a principle governs a decision. What changes is where the qualities are read from: the workspace's Brand voice guide, per architecture.md §1.1, and never this repository.

8.4 PRINCIPLE-04: five foundations, not seven · Open

These were extracted from Typography, Colour, Identity, Grid and the written half of Accessibility. Spacing and Layout are unwritten. A principle absent here because two chapters are unwritten will look like an omission rather than a gap, and this item is the only thing recording the difference.

8.5 PRINCIPLE-05: positioning, personality and voice are outstanding · RESOLVED 2026-08-26

§6 records what this chapter does not cover, and this item asked whether those three belong here, in a separate foundation, or permanently outside the repository.

Permanently outside, decided by Fernando on 2026-08-26, and the outside was verified rather than assumed. All three are held in the Notion workspace Digital impact consultancy: positioning and messaging in its Marketing pages, and personality and voice in its Brand voice guide, a 24-part reference covering brand overview, purpose and values, personality, tone foundations, writing principles, vocabulary, message pillars, channel guidance, and its own review and maintenance rules.

This chapter is finished. No third chapter is written.

The distinction that settled it is what each thing is consumed by. Every foundation here exists because something consumes it: a stylesheet, a page, a rendered PDF. Positioning is not consumed, it is argued from. Voice is consumed, but by writing rather than by rendering, and it already has a home built for that purpose which is more thoroughly specified than parts of this repository. Absorbing either would be the failure architecture.md §1 names, taken one defensible step at a time.

The boundary moved out of this chapter and into the governing document. It was previously asserted here and nowhere else, which was circular: the chapter that declined to cover positioning was also the only document saying positioning belonged elsewhere. architecture.md §1.1 now states it.


9. In closing

Thirteen reasons, and none of them is a value. What this chapter establishes is that every rule in this system can be traced to something that costs more to break than to keep, and that the tracing runs both ways: a principle with nothing depending on it would have been an opinion, and a rule with no principle behind it would have been a preference.

The practical consequence is a test rather than a rule. Before adding anything to this system (a hue, a spacing value, a weight, a component) ask what obligations it incurs, what it means that nothing else already means, and what survives if any single channel carrying it is removed. Three questions, and most additions fail one of them.

Next: Typography. Principle §2.1 claims typography carries the identity. The next chapter is where that claim is paid for.


10. Provenance