# The exit package: what you keep and how we check it

Canonical URL: https://thorfyn.com/en/notes/the-exit-package

> The documents a client keeps, when the package goes out of date and how the exit test is recorded, read from the code, with the file behind each number.

The documents a client keeps, when the package counts as out of date and how the exit test is recorded, read from the code that runs.

- Running system
- Written by Matheus Pavaneli (https://thorfyn.com/en/about)
- Published Oct 9, 2026
- Reviewed Oct 9, 2026
- 2 min

## What the package holds

Each client has an exit package with a fixed set of documents. Every document has a link, a date and a place where it lives, so the client can see what exists and where.

**4** — architecture notes, runbooks, the access handover and the continuity runbook. (how to check: `packages/site/src/exitFacts.ts`, `DOCUMENT_KINDS`)

## When it counts as out of date

The oldest document sets the age of the package. Past the limit below, the panel marks the package as out of date and names the document that aged.

**30 days** — age of the oldest document past which the panel marks the package as out of date. (how to check: `packages/site/src/exitFacts.ts`, `STALE_DAYS`)

## The exit test

The panel records an exit test: the date, who ran it, the minutes it took, whether it passed or failed, and what got in the way. The person who runs it is not the owner and follows only the continuity runbook. A record cannot be edited; a mistake is fixed with a new record.

**92 days** — window in which a passed exit test counts. After it the test shows as expired. (how to check: `packages/site/src/continuity.ts`, `drillDays`)

A failed test stays failed whatever its age, and a test past its window shows as expired. Every day the system also checks, with no person involved, that the documents are registered and recent and that their links answer. That check does not replace the test: only the test shows that someone else can rebuild the project.

## Leaving

To close the panel, the client confirms that each account is in its own name, removes each access and checks the package, then confirms with a fresh passkey. Closing ends every session; the activity record and the package stay with the client. Reopening takes the client's own confirmation.

## See how access is protected

The security page lists each claim with the file that proves it.

- See the security page: https://thorfyn.com/en/security
- Next note: https://thorfyn.com/en/notes/is-my-ai-built-app-leaking-data
- Questions and requests: hello@thorfyn.com
- Back to the home page: https://thorfyn.com/en
