What is verified on every build
Each check runs when the site is generated and stops the build on a finding, so a commitment that names one is proven rather than asserted. A commitment that names none is guidance, and says so.
The rings
A build passes through these in order and stops at the first that refuses; every refusal names its ring. The checks below run in rings 2 and 3; the others hold the files, the artifact, the prose, the site, its design and the standards.
- ring:0form · Every file of the ground and the ledger is in canonical form.
the loaders, through scripts/ground/format.py
claimed by The ground has one schema, and it is data - ring:1files · Every file, the two law files first, conforms to the declared schema and sits where the registries say it sits.
the loaders, through scripts/ground/schema.py
claimed by The ground has one schema, and it is data - ring:2laws · The registry keeps every law: identity, shape, admission, the relationships and their bounds, the journeys as machines, the measures as calculations, the addresses, and the kernel's names.
scripts/ground/checks.py, the laws in order
claimed by Declare measurement grain before calculation, Make outcome quality, calculation method and attribution inspectable, Keep audience eligibility, preference and permission basis distinct, A journey is a state machine, not a funnel picture, Campaign is the accountable initiative, Separate executable actions, observed events and consumer actor grain, Model offer as the governed value exchange, Scope activation and calculation explicitly in time and geography, Keep concrete creative separate from its classifications, Delivery custody is a named chain, not one vendor field, A metric exists because a question needs it, Creative form is constrained by where it is delivered, Every term is about something in the world, Store one canonical relationship assertion, An identifier names one thing, and never a second, State and intent are read against one ordered lifecycle, A declared path must be walkable, A relationship says what kind of claim it makes, The reverse reading is named, not improvised, An exemplar shows the shape a record takes, Knowledge enters as a term or an assertion, never as a new field, The ground has one schema, and it is data, Cause is read by a declared design, A value a plan fixes is a governed parameter, A move that cannot be counted is a picture, A question the graph answers is declared, and walked, A reading names its unit, and the unit fits its form, A target is a level on a reading, due within a window, A term may be known by other names, and they are labels, not terms, An address is a label's, made once, Everything composed is a composition of known parts, at every level, A view is one concept, over one primitive, A deliverable is a method the industry already writes, Governance and execution share one substrate, A text answers one question, in the reader's words, Prose names only what the registry holds, A road declares its grain, The loop is law, A person is known at a declared level, Every road answers a competency question, A person-level record has a declared shape - ring:3ledger · The knowledge ledger agrees with the ground and with itself: every kind and relationship licensed, every check claimed, every foundation on a standard.
scripts/ground/checks.py, check_foundations
claimed by Provenance and conformance are read apart, A deliverable is a method the industry already writes, A commitment says whether the build proves it - ring:4artifact · The graph conforms to its own schema and names the ground it is a function of.
scripts/build_from_ground.py, before it writes
claimed by The ground has one schema, and it is data - ring:5prose · Every authored file says what the registry says: every named relationship exists, every count is the live count, and no word the model has retired survives anywhere, the site's own copy included.
scripts/ground/contracts.py
claimed by The prose says what the registry says - ring:6site · The built site is the whole graph and nothing else: every page indexed, addressed by a label, self-contained and free of any private name; every structured-data identifier a subject the standards export wrote; every page unfurling to its own card, and every sitemap entry naming that card as its image; every journey with its SCXML twin; the sitemaps held to the graph; a graph under a megabyte. And the host held to the ground: the Worker serving the build as its assets and running first for every request; the allowlist and the redirect list it carries cut from the graph, every address the graph once answered to in the list with the status the law gives it and none of them a page; every endpoint served by the files it names; and the beacon sending to the collector's endpoint and nowhere else; every projection the law declares in the build, served by the files that say they serve it, and named in llms.txt; and the Worker reading the host's caching rules and owed headers from the law, writing none of its own; every answer a question carries a page where the walk is non-empty and nowhere else, its structured data naming exactly the rows the walk reached.
site/scripts/check_build.mjs, after the type check and the build
claimed by An address is a label's, made once, A page is shareable as itself, The operations an agent may drive are declared, A composition a reader manifests has an address, is held before it binds, and enters the ground only by proposal, An answer the graph gives has an address, A text answers one question, in the reader's words, Prose names only what the registry holds, A question in a reader’s words is answered with an address - ring:7design · The built stylesheet keeps the design system: every colour role clears the contrast the design declares on the surface it is read on, every colour token is measured by a pair or declared decorative with a reason, every band's colour clears its floor as chip text on the surfaces it sits on, no retired colour returns, and no type is set below the floor.
site/scripts/check_build.mjs, from site/design/contrast.json
claimed by The design is measured, not asserted - ring:8standards · A SHACL validator and a SPARQL engine that are not this build agree with it.
scripts/standards_prove.py: a gate on every push, and locally whenever the validator is installed
claimed by The model is written in the standards its foundations name, A person-level record has a declared shape - ring:9alignment · The model is aligned to the grammar it descends from.
an audit kept outside this repository
The audit is kept outside this repository, so no commitment here can name what runs it.
The evals
Proofs about the machinery and the record, run beside the rings: that the laws still refuse what they exist to refuse, and that what is committed is what the ground builds.
- eval:lawsthe laws bite · Every law refuses the breakage that is its own to refuse, every law has one, and every refusal the laws, the ledger law and the schema validator can make is reached by at least one: a sentence no breakage reaches is a sentence nobody has proved a gate can still say.
scripts/laws_refuse.py, after any change to the laws, and on every push
claimed by The proof runs without a hand - eval:recordthe record is the build · The committed graph, dates ledger, schemas, standards, editor mapping and the site's types are the build of the committed ground, byte for byte, and nothing a build writes is left uncommitted.
scripts/record_prove.py, on every push, where the tree is a commit
claimed by The proof runs without a hand - eval:hostthe host is the build · What the host serves is the build of a commit the rings passed: the tree clean, the run for that commit green, the build embedding that commit's graph; and once deployed, the origin answering as the build: the ground digest it serves the build's, a page and its files there, every former address answering with the status the law gives it, a bare name sent to its page, an address the graph does not have answering with the site's own page, the collector counting a signal the graph holds and refusing every other method, and the headers the host owes on every response.
site/worker/scripts/deploy.mjs, on every deploy, from a machine or from CI
claimed by The proof runs without a hand - eval:enginethe engine agrees with itself · The binder that runs while the graph is built and the binder that runs in a reader's browser find the same bindings: every pattern bound against the whole model to the same instances and the same rows in every role, the published example among them, and every view bound again from every row it answers from, row for row, and the port of the pattern law beside the browser's engine refuses every way a declared pattern can be broken exactly as the law does, and every question bound again from every row of its root kind finds an answer exactly where the build published one and nothing where it did not.
site/scripts/binder_agrees.mjs, before the site builds, and on every push
claimed by The proof runs without a hand, One engine, and a second runtime of it is a port under proof, The operations an agent may drive are declared, A composition a reader manifests has an address, is held before it binds, and enters the ground only by proposal, An answer the graph gives has an address
citation coverage
Every kind, relationship and deliverable is licensed by a cited rule, every source is cited by at least one rule, and every foundation names, among the cited works, the standard that represents it. · runs in foundation integrity, ring:3
- enforcedProvenance and conformance are read apart
- enforcedA deliverable is a method the industry already writes
admission and shape
Every kind has a valid shape and evidence class, and every row keeps the admission its kind allows: a record names its source, an exemplar names none, and a world record states the public reference it stands on. · runs in registry integrity, ring:2
- enforcedKeep audience eligibility, preference and permission basis distinct
- enforcedKeep concrete creative separate from its classifications
stable identifiers
Kind prefixes are unique, every row keeps the identity convention of its kind, and an identifier once retired is never reused: a kind writes each retirement down with its date and its reason, and every number below its highest is a row or a retirement. · runs in registry integrity, ring:2
- enforcedKeep concrete creative separate from its classifications
- enforcedAn identifier names one thing, and never a second
typed relationships
Every relationship has declared endpoint kinds and a governed cardinality. · runs in registry integrity, ring:2
- enforcedCampaign is the accountable initiative
- enforcedSeparate executable actions, observed events and consumer actor grain
- enforcedModel offer as the governed value exchange
- enforcedScope activation and calculation explicitly in time and geography
- enforcedKeep concrete creative separate from its classifications
- enforcedA journey is a state machine, not a funnel picture
- enforcedDelivery custody is a named chain, not one vendor field
- enforcedA metric exists because a question needs it
- enforcedCreative form is constrained by where it is delivered
- enforcedEvery term is about something in the world
semantic distinction
Vocabulary, constructs, world records, and source-backed records cannot be substituted for one another. · runs in registry integrity, ring:2
canonical graph integrity
Endpoints resolve, relationship triples are unique, and compositions remain acyclic where the model requires it. · runs in registry integrity, ring:2
calculation and projection integrity
Formula inputs, metric composition, cardinality, and plan projections satisfy their declared contracts. · runs in registry integrity, ring:2
- enforcedDeclare measurement grain before calculation
- enforcedMake outcome quality, calculation method and attribution inspectable
governance classification
Every rule declares whether a build check proves it; only an enforced rule names a check, every check is claimed by one, and no commitment or foundation states a count the model does not currently have. · runs in foundation integrity, ring:3
relational claim
Every relationship declares what kind of claim it makes, a hedging verb claims no more than it says, a typing is always constitutive because it says what a thing is, one verb carries one claim, and no claim class sits unused. · runs in registry integrity, ring:2
named inverse
Every relationship names the verb its reverse reading uses; it differs from the forward verb and is never the forward verb wrapped in 'is ... by'. · runs in registry integrity, ring:2
exemplar admission
A source-backed row is a record with a durable source reference or an exemplar of the pattern, never both and never neither; a vocabulary term is never an exemplar; and every exemplar answers to the name the exemplar commitment gives it, so renaming one cannot strand the sentence that threads them. · runs in registry integrity, ring:2
distinct definitions
No two rows of different kinds are defined in the same words, and no definition restates a field the row already carries, so a distinction the model commits to is carried where a reader meets it and nothing the model knows is stored in two places at once. · runs in registry integrity, ring:2
- enforcedDeclare measurement grain before calculation
- enforcedKeep audience eligibility, preference and permission basis distinct
- enforcedA journey is a state machine, not a funnel picture
licensed fields
Every file conforms to the one declared schema before any other law runs: a row carries only the fields the model licenses, and every field has the type and, where the set is closed, the value the schema states, so material arriving from outside cannot introduce structure merely by arriving. · runs in registry integrity, ring:2
- enforcedKnowledge enters as a term or an assertion, never as a new field
- enforcedThe ground has one schema, and it is data
lifecycle ladder
The lifecycle is a single unbroken chain with one first stage and one last, every consumer state is placed on it, and every stage is one some goal advances people toward, so an order a reader leans on cannot quietly become a fork, leave a condition unplaced, or hold a rung nothing pursues. · runs in registry integrity, ring:2
spine integrity
Every row of a kind the model leans on states the relationships that kind exists to carry, so a relationship declared across the registry and asserted nowhere is a failure rather than a thin line on a map. · runs in registry integrity, ring:2
- enforcedA declared path must be walkable
- enforcedCause is read by a declared design
- enforcedA value a plan fixes is a governed parameter
event grain
Every event states the grain it is recorded at, a consumer is named as actor only in an event that is a person's act, and a journey move is triggered only by an event resolvable to one person, so a count of events is never mistaken for a count of people and no move of one person rests on a fact about nobody in particular. · runs in registry integrity, ring:2
journey integrity
Every journey begins at one of its own positions and carries at least one legal move, its positions sit on a contiguous run of rungs, and every position either has a move out or realises a condition another journey leaves from, so no journey is a picture and no position is a dead end. · runs in registry integrity, ring:2
- enforcedA journey is a state machine, not a funnel picture
- enforcedState and intent are read against one ordered lifecycle
- enforcedA declared path must be walkable
move propagation
Every legal move between journey positions is triggered by an event that an instrument observes, and that instrument counts a reading a KPI carries, directly or through the formula that computes it, so a journey that names its moves can also count them and is a model rather than a funnel with arrows; and a move triggered by a window closing belongs to a journey that names the window it counts inactivity over. · runs in registry integrity, ring:2
row participation
Every row of a registry kind is touched by at least one relationship besides its own grounding, and every vocabulary is read by at least one filled relationship, so a record or construct nothing relates to, and a set of terms nothing uses, are failures rather than quiet rows. · runs in registry integrity, ring:2
- enforcedA declared path must be walkable
Pattern integrity
Every pattern's roles name kinds that exist and are named once; every edge is a declared relationship whose ends are its roles' kinds; the shape is connected and crosses no grounding, and a typing only where nothing leads on; a root, where declared, is the first role. A pattern with a root binds from some row, and every kind fills a role in some pattern. · runs in Every pattern is a shape the model can hold, and every kind is in one, ring:2
unit agreement
Every Metric is measured in one Unit that fits every arithmetic form the KPIs reading it take; a quotient is never measured in a count; and a reading in percent or as a ratio that names its numerator directly names a denominator, so a number and its unit leave here together and a share always says what it is a share of. · runs in registry integrity, ring:2
target coherence
A target sets a level for one KPI, quantifies one goal that KPI serves, and is due within one window; a campaign that pursues a target is measured by that target's KPI and supports that target's goal, so a target never promises a reading the campaign does not take or an outcome it does not claim. · runs in registry integrity, ring:2
label integrity
A row has one label and may carry alternate labels; every alternate label is a distinct non-empty name that is not the row's own label and matches no label or alternate label of another row in the same kind, so a name resolves to one term within its kind and a search by any name a term is known under finds it. · runs in registry integrity, ring:2
address integrity
Every page address is made once from a label by the law's own scheme and is distinct from every other; every top-level name the site answers is derived from what declares it, and no kind, endpoint or frame name takes another's; every address the site once answered to, a former label's or a retired identifier's, is distinct from every live address and from every other former one, and no row names its own label as a former one; every projection answers at a declared name, once, and is cut from fields the artifact carries; every operation reads a projection; and every endpoint answers only what its direction allows. · runs in registry integrity, ring:2
- enforcedAn address is a label's, made once
- enforcedEverything composed is a composition of known parts, at every level
kernel integrity
Every kind and relationship the kernel names is one the registries declare: a spine's verbs are verbs its kind states or is reached by, the metric derivation names specifications that exist, the contract-status escape names kinds that exist, and the grounding reaches kinds that exist, and the machine's kinds and verbs and the instrumenting kind are kinds and verbs the registries declare. · runs in registry integrity, ring:2
Gate coverage
Every gate a commitment names is a check, a ring or an eval the law catalogs; and every gate the law catalogs is claimed by an enforced commitment, or says itself why nothing here can claim it. · runs in Every gate is claimed, and every claim resolves, ring:3
Views compose
Every view names declared patterns, all asked from one kind, drawn in a way the law's pattern vocabulary declares, belonging to a declared deliverable, a table as one of its tabs and a job as work that produces it; and some row of that kind answers at least one of them. What a view touches is derived from its patterns, never listed beside them. · runs in Every view binds declared patterns from one kind, ring:2
- enforcedA view is one concept, over one primitive
- enforcedEverything composed is a composition of known parts, at every level
- enforcedA deliverable is a method the industry already writes
Vocabularies are governed
Every block of the law or the kernel that declares `values` says what it governs and which gate holds it, and that gate is one the law catalogs. Where a value carries the condition that selects it, the conditions are total and disjoint: every shape a binding can turn out to be selects exactly one value, and no value is unreachable. A rule stated twice is a rule that drifts, so it is stated here and read from here. · runs in Every governed vocabulary names its gate, and every value is reachable, ring:2
The host answers from the law
The host's caching rules each select by one form of a path, a prefix, a suffix or the endpoints, with exactly one rule for everything else; and the headers the host owes carry distinct names. What a browser may keep and what every response carries are the law's to say, and the Worker reads them rather than restating them. · runs in registry integrity, ring:2
prose answers one question each
Every text the law declares a kind may carry answers one question in one mode: an authored text is held within its span of sentences on every kind that carries it, a derived text is authored on no kind, every text is drawn by the files that say they draw it, each naming it, and the property a text is exported under is a SKOS documentation property. A kind's definition opens with the kind's own noun and never says the model's word for what the reader meets, and the nouns are distinct across kinds. · runs in registry integrity, ring:2
references resolve
Every reference in prose resolves to exactly one governed thing, a kind by its name or anything else by its identifier, and never to the text's own subject; the texts references are read from are fields the schema and the ledger declare. A reference is a name, never an assertion: the build draws it as a link and lists it on the target, and a pair of rows a text joins that the registry does not is listed as proposed and written nowhere. · runs in registry integrity, ring:2
grain integrity
Every relationship declares the grain it is asserted at, and a record road, a fact only an instance carries, is bounded below by zero, is required by no spine, and is walked by no question. The registry asserts a vocabulary road and holds it to its bound; a record road is the registry's declaration of a join a record must be able to make, and treating it as either an unfinished road or a fact about the kinds is the drift this refuses. · runs in registry integrity, ring:2
- enforcedA road declares its grain
the loops close
Every pattern the kernel names as a loop is a shape whose edges form one cycle over all of its roles, and the model instantiates it: at least one set of rows stands to one another all the way round. A loop is how the model says its gears connect; a loop that does not close is a picture, and one nothing stands in is a promise. · runs in registry integrity, ring:2
- enforcedThe loop is law
- enforcedA value a plan fixes is a governed parameter
moves are identified
The kernel's resolution names a kind the registry declares, a specification on which the instrumenting kind declares its level, and a row of that kind at which nobody is told apart; and every event that triggers a move is observed by at least one instrument identifying above that level. A move counted only by instruments that cannot tell one person from another is a move nobody made. · runs in registry integrity, ring:2
record shapes hold
Every pattern declares its grain. A record shape is a shape, walks at least one record road, and is the registry's declaration of a join a record must make, a person-level record in every case but the campaign roll-up, so the registry instantiates it by nothing and the standards export writes it as a shape without a target. A vocabulary pattern walks no record road, because a record road holds no rows to answer from. · runs in registry integrity, ring:2
- enforcedA person-level record has a declared shape
- enforcedA value a plan fixes is a governed parameter
roads are walked
Every relationship the registry declares, other than the grounding every kind makes, is walked by at least one pattern of its grain: a vocabulary road by a question or a shape, a record road by a record shape. A road no pattern walks answers no competency question, and a grammar that grows ahead of what is asked of it is the drift this refuses. · runs in registry integrity, ring:2
- enforcedEvery road answers a competency question
- enforcedA value a plan fixes is a governed parameter
the hierarchy holds
A tactic stands within its campaign and an action within its tactic. For each containment the kernel declares, along the road that makes one the child of the other, the child narrows what the parent declares, a window, a geography, an audience, and never widens it, or keeps what the parent honours, a preference, a permission basis, and never drops it. A parent that declares nothing binds nothing, and the same road declared at two levels can no longer contradict itself. · runs in registry integrity, ring:2