1Exactly three tiers
- Final Clock runs exactly three separate tiers: $20, $50, and $100.
- Each enrollment belongs to one tier for the season.
- Standings, survival state, and revealed team history remain separated by tier.
2Named enrollment
- An administrator enrolls each participant with a public display name, an optional Admin-only private name, optional Admin-only notes, and one tier.
- The display name is the only participant name used on public standings and revealed history.
- Players do not create accounts or operate an enrollment surface.
3Weekly picks
- An administrator chooses one team for every active participant from the current scheduled games.
- A team used in a settled earlier week cannot be used again for the same player.
- Each save carries the current revision so a stale request cannot overwrite a newer choice.
- Picks remain private until the later of the weekly deadline and the earliest canonical kickoff.
4Deadline and kickoff locks
- Trusted server time decides whether a save is timely.
- A new choice must arrive before the weekly deadline and the selected game's kickoff.
- An existing choice can change only before the kickoff of its originally selected game.
- A save at the exact deadline or kickoff timestamp is rejected.
- The canonical weekly deadline is Wednesday at 6:00 PM Central, interpreted in America/Chicago so the displayed CDT/CST offset follows daylight saving time.
5Results and missed picks
- A schema-validated canonical final automatically settles every dependent submitted pick in one transaction.
- A final win advances the player; a final loss or tie eliminates the player.
- The automatic deadline sweep eliminates an active player without a timely choice.
- Settlement and sync are replay-safe: repeating the same snapshot cannot advance a player or append the same audit event twice.
- A provider correction after settlement is held for protected administrator review and never silently reverses player history.
If live data is missing, stale, malformed, unmatched, or unconfigured, Final Clock fails closed and waits for reviewed exception handling.
6Public board
The public pages are view-only. They publish pool totals, public aliases, standings, a fresh live ticker when canonical games are live, and picks only after the trusted reveal boundary. They contain no participant accounts, private names, administrator controls, provider identifiers, or mutation forms.
7Administration
- Only active administrators may access the private Admin workspace.
- Administrators may enroll participants, manage weekly picks, review private Week 1–18 history, and read the administrative audit.
- Protected correction controls require exact pick and enrollment revisions, an allowlisted reason, confirmation, and a unique operation ID; progression is recomputed deterministically and the original record remains recoverable in audit-safe history.
- Administrators may archive and restore an enrollment with a reason and exact revision. Archive preserves the display name, private details, picks, results, and history; it is not hard deletion.
- Only an owner may add, change, or disable another administrator; the last active owner cannot be disabled or demoted.
- The Admin page is protected on the server and is never part of public navigation.
- Production writes use durable transactional storage and append an administrative audit record.
