Semantics
Asks Do two readers reach the same reading?
What the terms mean, stated precisely enough that two readers and two systems arrive at the same reading. Most of the work is keeping adjacent concepts apart — the pairs that are used interchangeably in conversation and mean different things in a model. Gruber calls this clarity, and puts it first among his design criteria.
In this model A Signal is not an Event; a Metric is not a KPI; an Audience Segment is not a Preference and neither is a Permission Basis. Each distinction is stated where the kind is defined, and the build rejects two rows of different kinds defined in the same words — which is how a model comes to assert a distinction on one page and deny it on the next.
Represented by
The engineering standards that state this foundation directly, among the works the commitments stand on.
Commitments it asks for — 14
- enforcedDeclare measurement grain before calculation
- enforcedSeparate executable actions, observed events and consumer actor grain
- enforcedKeep audience eligibility, preference and permission basis distinct
- enforcedMake outcome quality, calculation method and attribution inspectable
- enforcedModel offer as the governed value exchange
- enforcedKeep concrete creative separate from its classifications
- enforcedA journey is a state machine, not a funnel picture
- enforcedCreative form is constrained by where it is delivered
- enforcedA relationship says what kind of claim it makes
- enforcedA reading names its unit, and the unit fits its form
- enforcedA term may be known by other names, and they are labels, not terms
- enforcedThe design is measured, not asserted
- enforcedGovernance and execution share one substrate
- enforcedA text answers one question, in the reader's words
What the build enforces — 16
- registry integritycalculation and projection integrity
Formula inputs, metric composition, cardinality, and plan projections satisfy their declared contracts. - registry integritydistinct definitions
No two rows of different kinds are defined in the same words, and no definition restates a field the row already carries, so a distinction the model commits to is carried where a reader meets it and nothing the model knows is stored in two places at once. - registry integritytyped relationships
Every relationship has declared endpoint kinds and a governed cardinality. - registry integrityevent grain
Every event states the grain it is recorded at, a consumer is named as actor only in an event that is a person's act, and a journey move is triggered only by an event resolvable to one person, so a count of events is never mistaken for a count of people and no move of one person rests on a fact about nobody in particular. - registry integrityadmission and shape
Every kind has a valid shape and evidence class, and every row keeps the admission its kind allows: a record names its source, an exemplar names none, and a world record states the public reference it stands on. - registry integritysemantic distinction
Vocabulary, constructs, world records, and source-backed records cannot be substituted for one another. - registry integritystable identifiers
Kind prefixes are unique, every row keeps the identity convention of its kind, and an identifier once retired is never reused: a kind writes each retirement down with its date and its reason, and every number below its highest is a row or a retirement. - registry integrityjourney integrity
Every journey begins at one of its own positions and carries at least one legal move, its positions sit on a contiguous run of rungs, and every position either has a move out or realises a condition another journey leaves from, so no journey is a picture and no position is a dead end. - registry integrityrelational claim
Every relationship declares what kind of claim it makes, a hedging verb claims no more than it says, a typing is always constitutive because it says what a thing is, one verb carries one claim, and no claim class sits unused. - registry integrityunit agreement
Every Metric is measured in one Unit that fits every arithmetic form the KPIs reading it take; a quotient is never measured in a count; and a reading in percent or as a ratio that names its numerator directly names a denominator, so a number and its unit leave here together and a share always says what it is a share of. - registry integritylabel integrity
A row has one label and may carry alternate labels; every alternate label is a distinct non-empty name that is not the row's own label and matches no label or alternate label of another row in the same kind, so a name resolves to one term within its kind and a search by any name a term is known under finds it. - ring:7the design ring
The built stylesheet keeps the design system: every colour role clears the contrast the design declares on the surface it is read on, every colour token is measured by a pair or declared decorative with a reason, every band's colour clears its floor as chip text on the surfaces it sits on, no retired colour returns, and no type is set below the floor. - Every governed vocabulary names its gate, and every value is reachableVocabularies are governed
Every block of the law or the kernel that declares `values` says what it governs and which gate holds it, and that gate is one the law catalogs. Where a value carries the condition that selects it, the conditions are total and disjoint: every shape a binding can turn out to be selects exactly one value, and no value is unreachable. A rule stated twice is a rule that drifts, so it is stated here and read from here. - registry integrityThe host answers from the law
The host's caching rules each select by one form of a path, a prefix, a suffix or the endpoints, with exactly one rule for everything else; and the headers the host owes carry distinct names. What a browser may keep and what every response carries are the law's to say, and the Worker reads them rather than restating them. - registry integrityprose answers one question each
Every text the law declares a kind may carry answers one question in one mode: an authored text is held within its span of sentences on every kind that carries it, a derived text is authored on no kind, every text is drawn by the files that say they draw it, each naming it, and the property a text is exported under is a SKOS documentation property. A kind's definition opens with the kind's own noun and never says the model's word for what the reader meets, and the nouns are distinct across kinds. - ring:6the site ring
The built site is the whole graph and nothing else: every page indexed, addressed by a label, self-contained and free of any private name; every structured-data identifier a subject the standards export wrote; every page unfurling to its own card, and every sitemap entry naming that card as its image; every journey with its SCXML twin; the sitemaps held to the graph; a graph under a megabyte. And the host held to the ground: the Worker serving the build as its assets and running first for every request; the allowlist and the redirect list it carries cut from the graph, every address the graph once answered to in the list with the status the law gives it and none of them a page; every endpoint served by the files it names; and the beacon sending to the collector's endpoint and nowhere else; every projection the law declares in the build, served by the files that say they serve it, and named in llms.txt; and the Worker reading the host's caching rules and owed headers from the law, writing none of its own; every answer a question carries a page where the walk is non-empty and nowhere else, its structured data naming exactly the rows the walk reached.