Foundation · Structural
Derivation
Asks What is stored, and what is worked out?
What a structure asserts and what it computes. Store what could be derived and you keep two versions of one fact with no rule for which wins; derive what should have been asserted and the claim disappears the moment the derivation changes. Deciding this per fact is what keeps a model from disagreeing with itself.
In this model Each relationship is asserted once in its canonical direction. Reverse readings, the verb table and the foundations map are computed on every build and stored nowhere.
Represented by
The engineering standards that state this foundation directly, among the works the commitments stand on.
- PROV-O: The PROV OntologyW3C
- Declaring the GrainKimball Group
Commitments it asks for — 15
- enforcedDeclare measurement grain before calculation
- enforcedStore one canonical relationship assertion
- enforcedMake outcome quality, calculation method and attribution inspectable
- enforcedA metric exists because a question needs it
- enforcedThe reverse reading is named, not improvised
- enforcedA move that cannot be counted is a picture
- enforcedA reading names its unit, and the unit fits its form
- enforcedA target is a level on a reading, due within a window
- enforcedThe model is written in the standards its foundations name
- enforcedThe proof runs without a hand
- enforcedA page is shareable as itself
- enforcedOne engine, and a second runtime of it is a port under proof
- enforcedGovernance and execution share one substrate
- enforcedThe operations an agent may drive are declared
- enforcedA value a plan fixes is a governed parameter
What the build enforces — 20
- registry integritycalculation and projection integrity
Formula inputs, metric composition, cardinality, and plan projections satisfy their declared contracts. - registry integritydistinct definitions
No two rows of different kinds are defined in the same words, and no definition restates a field the row already carries, so a distinction the model commits to is carried where a reader meets it and nothing the model knows is stored in two places at once. - registry integritycanonical graph integrity
Endpoints resolve, relationship triples are unique, and compositions remain acyclic where the model requires it. - registry integritytyped relationships
Every relationship has declared endpoint kinds and a governed cardinality. - registry integritynamed inverse
Every relationship names the verb its reverse reading uses; it differs from the forward verb and is never the forward verb wrapped in 'is ... by'. - registry integritymove propagation
Every legal move between journey positions is triggered by an event that an instrument observes, and that instrument counts a reading a KPI carries, directly or through the formula that computes it, so a journey that names its moves can also count them and is a model rather than a funnel with arrows; and a move triggered by a window closing belongs to a journey that names the window it counts inactivity over. - registry integrityunit agreement
Every Metric is measured in one Unit that fits every arithmetic form the KPIs reading it take; a quotient is never measured in a count; and a reading in percent or as a ratio that names its numerator directly names a denominator, so a number and its unit leave here together and a share always says what it is a share of. - registry integritytarget coherence
A target sets a level for one KPI, quantifies one goal that KPI serves, and is due within one window; a campaign that pursues a target is measured by that target's KPI and supports that target's goal, so a target never promises a reading the campaign does not take or an outcome it does not claim. - ring:8the standards ring
A SHACL validator and a SPARQL engine that are not this build agree with it. - eval:lawsthe laws bite
Every law refuses the breakage that is its own to refuse, every law has one, and every refusal the laws, the ledger law and the schema validator can make is reached by at least one: a sentence no breakage reaches is a sentence nobody has proved a gate can still say. - eval:recordthe record is the build
The committed graph, dates ledger, schemas, standards, editor mapping and the site's types are the build of the committed ground, byte for byte, and nothing a build writes is left uncommitted. - eval:hostthe host is the build
What the host serves is the build of a commit the rings passed: the tree clean, the run for that commit green, the build embedding that commit's graph; and once deployed, the origin answering as the build: the ground digest it serves the build's, a page and its files there, every former address answering with the status the law gives it, a bare name sent to its page, an address the graph does not have answering with the site's own page, the collector counting a signal the graph holds and refusing every other method, and the headers the host owes on every response. - eval:enginethe engine agrees with itself
The binder that runs while the graph is built and the binder that runs in a reader's browser find the same bindings: every pattern bound against the whole model to the same instances and the same rows in every role, the published example among them, and every view bound again from every row it answers from, row for row, and the port of the pattern law beside the browser's engine refuses every way a declared pattern can be broken exactly as the law does, and every question bound again from every row of its root kind finds an answer exactly where the build published one and nothing where it did not. - ring:6the site ring
The built site is the whole graph and nothing else: every page indexed, addressed by a label, self-contained and free of any private name; every structured-data identifier a subject the standards export wrote; every page unfurling to its own card, and every sitemap entry naming that card as its image; every journey with its SCXML twin; the sitemaps held to the graph; a graph under a megabyte. And the host held to the ground: the Worker serving the build as its assets and running first for every request; the allowlist and the redirect list it carries cut from the graph, every address the graph once answered to in the list with the status the law gives it and none of them a page; every endpoint served by the files it names; and the beacon sending to the collector's endpoint and nowhere else; every projection the law declares in the build, served by the files that say they serve it, and named in llms.txt; and the Worker reading the host's caching rules and owed headers from the law, writing none of its own; every answer a question carries a page where the walk is non-empty and nowhere else, its structured data naming exactly the rows the walk reached. - Every governed vocabulary names its gate, and every value is reachableVocabularies are governed
Every block of the law or the kernel that declares `values` says what it governs and which gate holds it, and that gate is one the law catalogs. Where a value carries the condition that selects it, the conditions are total and disjoint: every shape a binding can turn out to be selects exactly one value, and no value is unreachable. A rule stated twice is a rule that drifts, so it is stated here and read from here. - registry integrityThe host answers from the law
The host's caching rules each select by one form of a path, a prefix, a suffix or the endpoints, with exactly one rule for everything else; and the headers the host owes carry distinct names. What a browser may keep and what every response carries are the law's to say, and the Worker reads them rather than restating them. - registry integrityspine integrity
Every row of a kind the model leans on states the relationships that kind exists to carry, so a relationship declared across the registry and asserted nowhere is a failure rather than a thin line on a map. - registry integritythe loops close
Every pattern the kernel names as a loop is a shape whose edges form one cycle over all of its roles, and the model instantiates it: at least one set of rows stands to one another all the way round. A loop is how the model says its gears connect; a loop that does not close is a picture, and one nothing stands in is a promise. - registry integrityroads are walked
Every relationship the registry declares, other than the grounding every kind makes, is walked by at least one pattern of its grain: a vocabulary road by a question or a shape, a record road by a record shape. A road no pattern walks answers no competency question, and a grammar that grows ahead of what is asked of it is the drift this refuses. - registry integrityrecord shapes hold
Every pattern declares its grain. A record shape is a shape, walks at least one record road, and is the registry's declaration of a join a record must make, a person-level record in every case but the campaign roll-up, so the registry instantiates it by nothing and the standards export writes it as a shape without a target. A vocabulary pattern walks no record road, because a record road holds no rows to answer from.