CORPUS / 02
States, rules, events, permissions and interfaces.
The programme asks that every idea have a parallel representation in code language: states, rules, events, permissions and interfaces. This page gathers those representations. The code blocks are readable specifications, not running software; where a mechanism is implemented and tested, that is stated.
Version 0.6.0 · updated 2026-10-04 · Reading and measurement cut: 4 October 2026, Bahia time. · Version history
M1
Entities and relative positions
RECORDED FACTS (symbiont), H (host) and SH (the organised relationship) are positions relative to the relationship observed, not species labels. In the founding case, H is a situated person who decides and answers, and S is an artificial system. At other scales, the same company may occupy H of a larger set, and the coordination of one scale may occupy S of the next.
type Position = 'S' | 'H' | 'SH' // relative to the relationship observed
Square Q_n := { S_n, H_n, bridge_S, bridge_H, membrane } // the set observed at scale n
SH_n := coordination of Q_n (not a third executor)
// change of scale
H_(n+1) := Q_n // the whole set becomes the host of the next scale
S_(n+1) := SH_n // the previous coordination becomes the symbiont of the next scale
SH_(n+1) // exists only if there is a new composition
// express human constraint: "the rule can repeat, but it needs a limit"
recursion_limit := IN_PROGRESSM2
Membrane and passage
Governed membrane — Every exchange between core and host must be selective, traceable, revocable and proportional to the function exercised.
Cognitive Constitution of the Symbiont v0.4, §2 (16 Jul 2026)
crosses_membrane(actor) :=
actor == Central // the node that reaches both sides
OR express_act_of_the_founder // recorded human decision
// what the membrane is not
// - not a hierarchy: Central and Operational are peers with bounded assignments
// - not an ACL: access policy and observed permissions are distinct evidence
// - not a status: "status is a label; capability is a membrane"| Transversal plane | Function | Nature |
|---|---|---|
| Π1 · Membrane | S/H boundary: visibility and passage. | holds for every vault; evolves by amendment, not by bucket |
| Π2 · Control and evidence | STOP, lease with heartbeat, effect key, badge, receipt, readback, independent observer. | same |
| Π3 · Square | The infrastructure in which S and H operate: bases, storage, execution, connectors. | same; not a vault |
| Π4 · Cost as data | Every execution records what it cost. | same |
M3
Mission: states, events and invariants
states := DRAFT | AUTHORIZED | IN_EXECUTION | IN_AUDIT | RETURNED | AWAITING_HUMAN_DECISION | BLOCKED
| COMPLETED | CANCELLED | REJECTED | FAILED // terminal
// transitions below: editorial reading of the schema, not the source text
DRAFT ──authorize(human)──► AUTHORIZED
AUTHORIZED ──reserve(lease)──► IN_EXECUTION
IN_EXECUTION ──return(receipt)──► RETURNED
RETURNED ──accept(human)──► COMPLETED | ──refuse──► REJECTED | ──reopen──► AUTHORIZED
* ──needs_decision──► AWAITING_HUMAN_DECISION // silence and elapsed deadlines are not answers
invariants
I1 one hand at a time: short lease with heartbeat; once expired, any AI may resume and complement
I2 unique effect_key per logical effect; a retry reconciles by the original ID before repeating
I3 receipt + readback at the destination: "SUCCEEDED does not prove effect"
I4 executor ≠ reviewer ≠ acceptor; the executor does not approve its own delivery
I5 silence ≠ acceptance; tacit ratification was removed on 3 Oct 2026
I6 whoever takes it, says so: no possession without a valid badgeRECORDED FACTContinuity between executors was promulgated on 27 September 2026 as a canonical amendment, after the founder judged that the queue had become too safe: when one AI took a mission and the conversation died, the others did not resume and the mission stayed stalled, marked as in execution. The amendment introduced a short lease with heartbeat, a returnable checkpoint, batch leases and the rule that a question never blocks: there is a default answer, only in risk classes R0/R1, and delegation becomes a sub-entry.
RECORDED FACTOn 4 October 2026 the queue held 588 missions: 231 completed, 214 returned for review, 73 cancelled, 45 authorised, 11 awaiting human decision, 9 drafts and 5 rejected; none in execution, under audit, failed or blocked at the instant of the count. The full distribution is on the metrics page.
M4
Executor identity
RECORDED FACTThe rule “whoever takes it, says so” requires the executor to identify itself by platform, plan and mode before taking possession of any object. The badge was adopted informally on 28 September 2026 and validated on 29 Sep with a validator that blocks a malformed badge before possession (20 of 20 test cases).
badge := 'cr1' '|' vendor '|' product '|' plan '|' account '|' mode '|' post '|' model '|' execution '|' origin
mode ∈ { interactive, scheduled }
post ∈ { EXECUTOR, ARCHIVIST, TRIAGE, INSPECTOR, PULSE, TECHNICAL-PEER, ... }
execution := 'loc:' local_execution_identifier
origin := 'conversation=' ref ';parent=' parent_mission ';source=' authority_used
// unknown fields receive the literal 'unknown'; they are never inferred
// the validator checks grammar only; account, plan and model are not deducedM5
Time as an architectural dimension
trigger // what fires (clock, event, human request)
routine // the recurring definition
occurrence // the planned instance of a routine at an instant
attempt // the concrete execution of an occurrence; a retry gets its own ID and keeps the occurrence
effect // what changed at the destination, with receipt and readback
delay_policy(occurrence) ∈ { recover, skip_with_receipt, escalate }
// never silently omit late work
// milestones verified as separate facts
configuration_reread < first_run < instruction_used < useful_deliveryRECORDED FACTThis model is why the metrics panel distinguishes, for every routine, whether the configuration was reread, whether the first run was observed and whether there was a useful delivery. On 4 October 2026 the nine per-vault watches of the Central seat had their configuration checked and their first run observed; useful delivery had not yet been evaluated.
M6
Threshold routing
Threshold Doctrine v1.0, validated on 29 September 2026 after a blind test in three rounds between two AIs from distinct vendors, one round of adversarial review and three mechanism trials. It answers the question: when laboratory, when direct execution?
Neither extreme nor middle ground: it is a threshold (barbell). Free below, laboratory above, almost nothing in between.
Threshold Doctrine v0.1 (28 Sep 2026)
unit := situated_action = ⟨ action, context, reach, version ⟩ // never the isolated artefact
T0 authority and scope // precondition: without mandate, NOT_RELEASED
T1 reversibility // detection + interruption + recovery; 7 days is a ceiling, not a guarantee
T2 multiplication // does the action replicate (playbook, loop, integration)?
T3 who pays for the error // Central | team | third party
T4 observability and containment
authorisation(action) := // axis 1: mandate; never mixed with the regime
if ¬T0 → NOT_RELEASED
else → RELEASED
regime(action) := // axis 2: only for a released action; mapping below is inference
if T2 ∨ T3 = third_party → FULL_LAB
else if T1 ∧ T4 → SHORT_LAB or ELASTIC (direct, observed execution)
else → PENDING // human decision
anti-fossilisation locks: laboratory with expiry · self-adjusting gate · budgeted entropy
pilot_parameters: N = 20 cycles as a review trigger (not a demotion); no statistical validationRECORDED FACTThe first-round adversarial review prevented the doctrine from becoming a permission: “the correct unit is action plus context plus reach plus version, not the isolated artefact”, and “the elastoplastic metaphor helps to explain but does not demonstrate safety”. The second round added tests T0 and T4 and defined laboratory as a bounded experiment to reduce decisive uncertainty. The idea of laboratory as a property of the artefact, not a phase of the company, comes from v0.1; the first round corrected the unit to the situated action.
M7
Vaults, planes, currencies and maturity
is_vault(x) :=
receives_own_deposit(x) // currency or versionable object
∧ matures_by_bucket(x) // Mess → Bronze → Silver → Gold → Diamond
∧ has_S_H_pair_when_applicable(x)
∧ has_owner_mission_and_continuity(x)
is_plane(x) := holds_for_all_vaults(x) ∧ ¬receives_currency(x) ∧ defines_invariants(x) ∧ evolves_by_amendment(x)
vaults := { C1 context and cases, C2 method and playbooks, C3 capabilities and agents, C4 coordination and agentic company,
C5 voice and dialogue, C6 possibilities of new contexts, C7 tools and integrations,
C8 architecture and evolution of relations, C9 Moving UP, C10 publications, marketing and traffic }
"Vault N" without a letter := the pair H_N + S_N // each side is written with its letterCurrency 1 := solve a specific case, with a verifiable result, updating the context
Currency 2 := deposit in the playbook how it was solved and what was learned about cases of that kind
Currency 3 := turn learning into repeatable capability (agent)
NO_CURRENCY := a valid outcome; no currency is minted to demonstrate activity
// a currency is what is deposited, never a vault; bucket levels are not new vaults
// "the method travels, the data stays" (canonical two-currencies amendment, 19 Sep 2026)
maturity(object) ∈ { Mess, Bronze, Silver, Gold, Diamond } // per object, not a global seal
Bronze ≠ VALIDATED ≠ CANONICAL ≠ execution_authorisation| Level | Definition recorded for the coordination vault |
|---|---|
| Mess | Scattered initiatives and agents, with improvised coordination. |
| Bronze | A first full cycle works, with human follow-up. |
| Silver | Cycles repeat with responsibilities, records and failure handling. |
| Gold | The operation integrates different functions and incorporates improvements with measured results. |
| Diamond | The company sustains improvement over time, with reliability and autonomy within the defined mandates. |
M8
Epistemic record and the doctrine of evidence
epistemic_record := Fact | Evidence | Inference | Hypothesis | Intuition | Decision // proposal of 18 Jul 2026
review_ruler := FACT (source cited) · DECISION (founder's act) · INFERENCE · PREFERENCE · GAP
// doctrine of evidence and access (14 Sep 2026, candidate)
observation ≠ report ≠ inference ≠ proposal ≠ decision
qualified_negative(x) := "not found in <scope> on <date>" // never "does not exist"
proportional_proof(claim) := strength of proof ∝ consequence of the claim
access_policy ≠ observed_permissions
page_nesting ⇏ ancestors_readRECORDED FACTAn example of application, recorded in a reconciliation of 27 September 2026: “evidence = observed textual divergence; model = proposal to separate measures; hypothesis = benefit of governed adaptation; analogy = elastoplasticity; normative decision = none; publication = none”.
M9
Command by magnitude
Internal decision rule promulgated on 26 August 2026 (doctrine 1.0). Only the principle is published.
normalised_magnitude(v) := 9 if 8.6 ≤ v ≤ 9.4
// 9 is not a result; it is a contextual command
// the direction of the command depends on what is being measured (polarity of the context)
// below 8.6 there is no rejection: there is absence of command
// multilayer: no average, no cancellation between layers
// every recorded value declares its source: ⟨ layer, condition, value, command ⟩
open := { precedence between conflicting layers, meaning of 10 } // deferred to the first real caseM10
Constitutional invariants in force
Cognitive Constitution of the Symbiont v0.4, consolidated on 16 July 2026 and the only constitution in force since 17 Jul, with the canonical two-currencies amendment of 19 Sep. Twenty-one principles; those with theoretical weight are below.
| § | Principle | Recorded text |
|---|---|---|
| 1 | Structural separation, functional integration | The symbiont's core and each host must remain distinct in identity, custody, data, constitution and evolution, but integrated through governed channels of exchange. |
| 2 | Governed membrane | Every exchange between core and host must be selective, traceable, revocable and proportional to the function exercised. |
| 4 | Evolution by expansion | New learning must not automatically overwrite earlier capabilities. |
| 5 | Limited plasticity | The symbiont must adapt its manifestation to the context without losing identity; adaptability has costs of complexity, testing, maintenance and governance. |
| 6 | Accommodation before assimilation | Local solutions must be tested as configurations, modules or conditional protocols before being incorporated into the core. |
| 7 | Evolutionary reserve | Capabilities without current use may remain latent when there is future potential, traceable origin and controllable cost. |
| 11 | Analytical scale | Macro: architecture, containers and relations. Meso: models, flows, properties and patterns. Micro: cases, documents, messages and detailed content. |
| 12 | Cognitive checkpointing | The triggers of macro-stage, evidence volume, time and degradation work as a continuity radar, not as automatic closure. |
| 19 | Epistemic layers of the host | Distinguish the constitutional state in force, the historical state received, the current operational state, the differences between architecture and deployment, and genuinely unknown gaps. |
| 20 | Reading before intervention | Read, mine, extract, organise, confront, debate, validate, deepen and only then execute. |
| amendment | Two currencies, fractal | The two-currencies principle applies fractally to the scales of the programme; Currency 1 solves a case, Currency 2 deposits in the playbook how it was solved. |
M11
Transformation chain (founding document, historical)
context → knowledge → decision → mission → execution → evidence → institutional memory
memories := { constitutional, organisational, operational, episodic, evidentiary, semantic }
principles 8–10:
8. do not confuse metaphor with technical capability
9. make the core work in the host's context
10. grow fractally without multiplying disorder