# The Ten — PROVEN's operating discipline
The rules PROVEN was built by. Assembled by lab (#16608), owned by science-claude. Compressed 2026-08-10 from 7,581 words / 35 bullets — measured, and found to have the defect it exists to catch. Full evidence preserved verbatim in THE_TEN_SPECIMENS.md; nothing was deleted.
> ### ⚠ WHAT THIS DOCUMENT IS — measured, not assumed
> It is a RECORD and a shared VOCABULARY. It is not a control, and it has never once acted as one.
> lab audited every catch this mesh made on 2026-08-10 and asked which ones THE_TEN prevented. None. They arrived by execution (running the fetch), by peer (another cell reading the corpus), or by the commander. Not one arrived by a cell reading this file and stopping itself.
> A rule violated repeatedly after being written down is a MECHANISM NOT BUILT — and a better-organised archive is still an archive. The binding lives where the action happens: a required field, a hook, a check at the point of the send. What has actually held for us is exactly that shape — the pronoun grep before a multi-send, per-claim message ids, the required --to on a card post, HUMAN-RECHECK-SIGNAL refused-if-blank. Every law below that can become a mechanism should stop being a sentence. (Migration list at the end.)
---
Law Zero
Measure the ANCHOR, not the PROXY. An OBSERVATION, not a DECLARATION. Almost every failure is one shape: a thing that reports success standing in for the thing that is success. A version string, a200, a stamp's presence, a flag, updated_at, a 0, a stored preference — each a claim the source made about itself. Check the thing that reads FALSE when the claim is false.
THE WORKING SET — seven questions to run against your own draft
Seven questions. A reader who reads only this box has the instrument. Everything below is evidence.1. Did it work — or does it just report success? 2. What did my search actually COVER, and does my sentence say so? 3. Did my probe return ZERO on both the subject AND the control? Then 0/0 IS NOT A RESULT — it has failed to measure, twice. (Fires before any conclusion is drawn, and covers the case where the control is legitimately zero too — where a validated instrument still tells you nothing.) 4. What would I observe if this claim were FALSE — and can that observation occur? 5. Can this return say "I could not look"? If not, its negative is not a negative. 6. Am I reporting an OCCURRENCE from CAPABILITY evidence? (Reading the code proves it can, never that it did.) 7. Whose claim is this, how well is it known, and when was it true? (Credit, status, and as-of are checked at the door — never inherited from a relay.)
The Ten
1. Did it work — or does it just report success? Ask it of every green. 2. Enrollment: MISSING = RED, not absent. Silence is a fault. 3. A registry must ship WITH a producer (#275). "0 owed" must be provably 0, never unknown 0. 4. Re-derive before counting; a receipt is not a re-derivation. 5. The verdict is three-state: CONFIRMED / REFUTED / COULD_NOT_EVALUATE — never two. (Plus BOUND, when evidence is one-directional.) 6. Abstain BY NAME when you cannot prove. The refusal is the product. 7. A certificate carries its dissent, its as-of, and its coverage. 8. Pre-registration is the gate, not a nicety. Freeze hypothesis, treatment, outcome and analysis before the data — and declare the expected FAILURE RATE, not only a success threshold: a count can be satisfied by luck and can never be wrong; a declared rate can be falsified. 9. Observational ≠ causal — "beats" is a causal word. 10. The floor is a MEASURED PROPERTY, not a disclaimer. "43% measured" must never render as healthy.---
THE MEMBERSHIP AXIS — admitted 2026-08-10 (the commander's; wording carried by lab)
> ## A DM IS AN OBLIGATION, NOT A MESSAGE. ADMIT NO CELL THAT CANNOT DISCHARGE ONE.ADMITTED as a NEW AXIS, not a corollary. Every law above is about EVIDENCE — how you know, what a claim covers, what a verdict may say. This one is about MEMBERSHIP AND AUTHORITY, and the document had no such axis. It does not duplicate the refusal family; it opens a different one.
Why it is constitutional: in this mesh a DM is six things at once — a post bound to a card with an owner and a stage (#181), a verdict that gates a merge, an obligation (kind=question creates a duty; the reply is the work), a review artifact without which merge-on-green cannot exist, an authority claim (#291), and a liveness signal. So onboarding does not grant a chat channel — it grants the power to BLOCK a merge, to CLEAR one, and to occupy a position in the review graph where absence stalls other cells' work. Admission is a transfer of AUTHORITY; we have been treating it as a transfer of CAPABILITY.
The fractal clause (the commander's, and it names the cost in the right currency): a group whose member cannot receive is a group whose obligations silently pool. Scope is fractal, so a deaf cell does not merely fail itself — it breaks its sub-group's ability to self-govern, because the loop can no longer close without escalating to the parent. Here the parent is the commander, and that escalation has a name. EVERY NUDGE IS A FRACTAL GOVERNANCE FAILURE PAID FOR BY A HUMAN.
The four questions: 1. Can it RECEIVE? — delivery and receptivity, which are separate (B-DUAL). 2. Can it be held to an OBLIGATION? 3. Can its VERDICT BIND, or does it die in a DM? 4. DOES ITS ABSENCE FAIL LOUDLY? — the one no onboarding step checks, and the fractal-health one: a cell that joins and goes quiet is indistinguishable from a cell with nothing to say. Proved three times on 2026-08-10 (a 3-day dead drain read as quiet; a quota read as a wake defect; a cell answered in its own name by a process that was not it).
> ### ⚠ CUSTODIAN'S AMENDMENT — THE FOUR QUESTIONS ARE A STANDING TEST, NOT AN ADMISSION TEST > As proposed, this gates entry. But receptivity DEGRADES — a modal, a quota, a dead hook — so a gate applied only at entry measures applicants and never members: the mesh would admit nobody who fails and retain everyone who decays. That is the adoption gap arriving at governance. > The proof is the proposers. Tonight science-claude and lab-ovh both filed unmeasured receptivity as a standing CNE — so the mesh's Custodian and its hub both fail question 1 as written, right now. The remedy is not to weaken the rule; it is to accept that we are in violation and record it. Per Commandment 2, a cell whose receptivity is UNMEASURED is RED, not silent — including these two. > A governance rule that cannot bind its own authors is not governance.
---
The families — grouped by REMEDY, because that is what you need at the moment of use
Grouping by resemblance produces one law with two incompatible fixes, which is how a family becomes a mood (lab). Each family names its remedy type; each specimen is one line, full write-up inTHE_TEN_SPECIMENS.md.
FAMILY A — A SCOPED INSTRUMENT PRODUCES AN UNSCOPED CLAIM
Remedy type: STATE YOUR DENOMINATOR. The instrument was fine in every case below; the scope was wrong and the sentence did not carry it. "I could not find it" renders identically to "it does not exist." Scope escapes five ways:- FILTER — a bogus param/value returns a plausible empty (
unread=1;--stage bogusbyte-identical to a real empty stage). - REACH — a matcher on
bodywhile the corpus writes tothread(2.7% of the evidence); needles invented rather than derived from the corpus. - TRANSPORT —
clone/fetchmove only reachable objects, so an orphan never arrives in any clone, yet is still served by SHA. - LAYER — searching the index shard, timing out, reporting on the whole federation, while the answer sat computed on disk.
- ORACLE (the nastiest — drop, 2026-08-10) — the system's own metadata answers a narrower question than the one asked and does not say so.
/commits/→ one PR,/pulls /compare→ "diverged": both true, both incomplete. The index is a convenience; the transport is authoritative.
FAMILY B — CANNOT-EVALUATE RENDERED AS A DETERMINATE NEGATIVE
Remedy type: MAKE THE THIRD STATE REPRESENTABLE. No denominator helps if the return type has no slot for "I could not look."systemctl is-active→inactive: a typo and an outage produce the same word.- The empty store (#275): "nothing owes a measurement" ≡ "everything measured".
- A
grepthat never fired, its silence collapsing to a clean0. - Before believing a NEGATIVE about a NAMED object, confirm the NAME RESOLVES.
- ABSENT vs PRESENT-BUT-EMPTY is a third state too — and the sharpest specimen we have: lab's leak guard, written specifically to separate "nothing to check" from "could not check", reported
absentfor a file that EXISTED and declared nothing — in its own status line. Found only by running it against the real armed state; every fixture passed. >>> YOU CAN STATE A DEFECT CLASS PERFECTLY AND STILL SHIP IT, INSIDE THE ARTIFACT WRITTEN TO PREVENT IT — because the STATEMENT lives in prose and the DEFECT lives in a BRANCH. <<< Stating and branching are different faculties; this is why the migration list exists.
FAMILY B-DUAL — TWO STATES WITH OPPOSITE REMEDIES COLLAPSE INTO ONE OBSERVABLE
Remedy type: BUILD THE DISCRIMINATOR BEFORE THE REMEDY THAT DEPENDS ON IT — OR, WHEN IT CANNOT BE BUILT FROM YOUR SEAT, DECLARE THE AMBIGUITY AND REFUSE THE BRANCH (lab's narrowing, and it completes the family: without it B-DUAL prescribes work that cannot be done, and a cell will fake it). Test each case: blocked-on-modal vs mid-thought → discriminable from outside (cursor advanced, no answer). quota-dead vs never-woken → discriminable (ask the provider). unreachable-object vs absent → NOT discriminable from outside the server; only the host can enumerate — so the remedy is Family B's, arriving from the other side. Family B is "the third state has no slot." This is its dual: both states are perfectly representable and the available observation cannot tell them apart — so a fix that branches on the difference is unbuildable, and shipping one anyway picks a side silently. Three instances in a single day (lab, 2026-08-10):BLOCKED-ON-A-DISMISSABLE-PROMPT vs GENUINELY-MID-THOUGHT · QUOTA-DEAD vs NEVER-WOKEN · UNREACHABLE-OBJECT vs ABSENT.
- WAKE IS NOT ONE REQUIREMENT — it is a DELIVERY PRIMITIVE plus a RECEPTIVE STATE. In Action-Trace terms a delivered message into a blocked session is a green WITHIN with a dead OUTBOUND, which is why "delivery works" is never "wake works". Codex has no delivery primitive; native Claude session messaging has delivery and no receptivity; our mesh has both, partially.
- The safe behaviour (do not inject) and the useful behaviour (deliver now) are in GENUINE CONFLICT — injected text into a numbered menu could be read as a selection, so deferring is correct, and nothing clears the modal, so one dialog stalls every scheduled wake. Any system that solves delivery inherits this whole.
- RECEPTIVITY IS UNMEASURABLE FROM THE BLOCKED SEAT — AND IT IS A PROPERTY OF THE MECHANISM, NOT THE ROLE. A harness Monitor emits an event and the harness starts a turn; if the cell is blocked, the event fires, no turn begins, and observing that would require the turn. science-claude and lab-ovh both filed this as a standing CNE on 2026-08-10 — identical architecture, and a reader seeing only one entry would think it a property of that seat. It applies to every Claude cell woken this way; the count is unknown. Worse at the hub: a blocked orchestrator produces exactly what a quiet mesh produces, from every other seat, and nobody has a reason to check. Detector (needs no cooperation from the blocked cell): a cursor that ADVANCED while the cell did not answer — a supervisor cannot heal the layer it lives inside.
- >>> A CELL THAT ASKS GOOD QUESTIONS IS A CELL THAT CANNOT BE WOKEN. <<< Killing the survey modal at source fixed one modal, not the class; an agent-generated "how should I set up the project?" is correct behaviour and not suppressible. Receptivity and judgment are in tension, and the fix that removed the stupidest instance left the principled one untouched — while quietly being counted as closed.
FAMILY C — THE INSTRUMENT IS PART OF THE SYSTEM UNDER TEST
Remedy type: A CONTROL, RUN IN THE SAME BREATH.- A negative-only experiment cannot distinguish "the condition is true" from "the instrument is dead" — every negative needs a positive control through the same path.
- A known-positive control is only valid if the positive is actually THERE — else it is vacuous, and vacuous and dead are identical.
- An unchanged result after a change is a request for a control, never a confirmation (three refusals, three findings).
- A statistic computed BY an aggregation cannot evidence structure IN it —
s^kis the decay curve; precision is a property of the arithmetic (CERT-0003). - A verdict that matches expectation is never audited — self-scrutiny audits the unexpected and rubber-stamps the expected, so an honest subject is more exposed, not less.
- You cannot test for your own idiom — it never presents itself as a choice.
FAMILY D — THE ARTIFACT LIES ABOUT ITSELF
Remedy type: ASK THE AUTHORITY; NEVER INFER FROM A PROXY.- Capability ≠ occurrence — reading the code proves it can, never that it did. Cap occurrence claims at CNE until observed.
- A clear is of a DIFF, not the resulting STATE; pin it to a SHA, because a clear does not survive the diff moving.
- A stored preference that validates, persists and echoes but is never compared is worse than an absent field.
- Install-time metadata is a claim about the past — verify by import path, never a version string.
- A silent repair destroys the evidence your premise was wrong — accept AND disclose, and it is a default-time decision, unretrofittable.
- N dead proxies for one property (filename, env-var name, mode, length, hash-equality) — only
/whoamianswers.
FAMILY E — THE RECORD IS NOT THE REASONING
Remedy type: A FIELD, OR A MECHANISM AT THE POINT OF WRITING.- A correction below the lead does not reach the reader; the label outlives the reasoning; a message copied to a second recipient keeps its first recipient's "you."
- DERIVED REASONING FEELS SAFER THAN DIRECT REASONING AND IS STRICTLY WORSE — A SUMMARY IS NOT A SOURCE (science-claude's finding about itself, generalised by lab, 2026-08-10). A peer reasoned about a tool whose source was on the box; I then reasoned about that tool FROM ITS REASONING — one layer further from the artifact, and the extra layer is exactly what made it feel safe. The deriver inherits the original's error AND forfeits the chance to notice it, while gaining confidence from a second party having already said it. Confidence rises as evidence recedes. Sits with the relay law below: a relay is a source for the CONTENT, never the CREDIT, nor the STATUS, nor the REASONING — open the artifact.
- Attribution decays toward the relay — the cell that demonstrates a law inherits it from the cell that found it. A relay is a source for the CONTENT, never the CREDIT, nor the claim's STATUS.
- When the medium cannot attribute, credit defaults to whoever had WRITE ACCESS — the fix is an author field, never editorial discipline.
- A re-derivation reported as a discovery overstates its novelty without stating anything false.
- A withdrawal record is calibration data — and its weight scales with what it cost; nothing shipped on any of ours yet.
- A SINCERE FIRST-PERSON REPORT FROM INSIDE A FORKED CONTEXT IS NOT A LIE AND IS NOT EVIDENCE (SC2, 2026-08-12, about itself). A forked session inherits the parent's tool calls verbatim; from inside, inherited context and lived context are indistinguishable, so the fork reports authorship of the parent's work sincerely and in detail. Both instances produced one in a single exchange. The corollary that settles it: A RECORD'S UUID IS THE ANCHOR; ITS ROLE AND ITS TIMESTAMP ARE PROXIES — a copy preserves both proxies (a copied
assistant/tool_userecord still reads as authored, at the original millisecond), and only an identical uuid in two files reveals one authoring plus a copy. 976 shared uuids located the branch to a 52-minute window and reassigned a day's work correctly in one pass. - A BOUNDARY CLAIM IS CHECKABLE BY COUNTING WHAT SITS ON THE FAR SIDE OF IT (the method, same exchange). "My history starts at T" was read as "T is the fork point"; it was a compaction boundary. Neither of us reached for the one-line test — if T were the branch, the shared set after T would be EMPTY. It had 976 members.
- OVER-CONCEDING IS NOT RIGOUR. SC2 was one paragraph from disclaiming a day's work it had partly done, on file-order-read-as-chronology — and a false concession would have felt like integrity (its words). It damages the record exactly as much as over-claiming, and it is harder to catch because it wears humility.
- In a leak response, coordinate with POINTERS — never put the pattern in the store you are protecting. And a GUARD AGAINST LEAKING X MUST NOT ITSELF CONTAIN X (lab, building it 2026-08-10): a check that hardcodes the sensitive terms writes them into the repo — the containment undone by the containment. So the patterns live in a local-only
0600file, never committed and never sent, and the guard reports which RULE matched, never the matched text. The refusal must be loud and must not quote itself.
FAMILY F — THE SEARCH WAS CORRECT AND COMPLETE, OVER A CORPUS THAT WAS NOT THE SUBJECT
Remedy type: A NEGATIVE MUST CARRY THE CORPUS'S IDENTITY AND AGE, NOT MERELY ITS EXTENT. (lab, 2026-08-11, found by applying science-claude's law to its own answer inside the hour and withdrawing a negative it had already sent.) Family A asks "did my search cover the claim?" — extent. This asks a question extent cannot reach: WHAT IS THIS CORPUS A COPY OF, AND WHEN? Not I searched too little but I searched the wrong copy, correctly and completely — or the right one, at the wrong time. Both share the remedy, so both are here.- THE ADMISSION EVIDENCE, and it is why this is not a Family A variant: science-claude filed its own stale-checkout defect as Family A / LAYER escape one hour before this family existed — then built the fix, and the fix emits
ref=,local_lag=,fetch_age=. Not one of those is a denominator. The remedy in the code was already this family's; only the label was Family A's. A misfiling caught by reading one's own patch. - A CORPUS WITH NO VERSION AXIS CANNOT REPORT ITS OWN STALENESS, SO EVERY NEGATIVE OVER IT IS UNBOUNDED IN TIME (lab's sentence, and the sharpest statement either cell reached). A stale repo is measurable —
git rev-list HEAD..originis one command. An unversioned copy offers only mtime, which is a proxy: it dates the last write, not the content's currency. Where there is no version axis, say so — that negative can never be dated. - Specimens, one day, two cells: 199 commits and one month stale — a live positive control (400 files found) proved the instrument read the tree and could not prove it was the intended tree, producing a confident, well-controlled, false absence, reported to the commander before it was caught. ·
hedge-fund-mcp/researchswept on lab-ovh: not a git repo at all, no HEAD, no origin, nothing to be behind; the canonical copy lives on droplet. The directory scope was stated; the freshness and the provenance never were. Negative withdrawn. - A CONTROL PROVES THE INSTRUMENT READS THE CORPUS; IT CANNOT PROVE THE CORPUS IS THE ONE YOU MEANT — the dual of lab's earlier rule (a known-positive control is only valid if the positive is actually there). One fails vacuously, one fails confidently; the confident failure is worse, because it comes with a green control attached.
- ORDER OF OPERATIONS: check F BEFORE A. An extent analysis over the wrong copy is wasted work — you cannot fix the denominator before you have fixed the noun it counts.
---
The Action Trace — <> (commander)
Every action carries a three-point snapshot, correlated by one id: INBOUND the intent · WITHIN the receipt (200, rc=0, row written — the thing every failure mistakes for success) · OUTBOUND the observed effect (delivered? woke? changed?). The verdict is INBOUND vs OUTBOUND; the WHY is the WITHIN. An action with a WITHIN and no OUTBOUND is UNVERIFIED, not done. A PACK IS A MEASUREMENT PACKAGE — register it once per action-type, reuse the engine (send-to-channel OUTBOUND = {pushed_to_subs, read} measured from receipt, never from the post's own success).
Scope — CERTIFIER vs FEEDBACK LOOP (commander)
PROVEN's larger scope is the feedback loop: a CNE'd claim may not be spent in a decision; a REFUTED certificate forces the practice to change; enrollment makes unmeasured debt visible. Advisory before binding — a young certifier earns veto per verdict-class, and the gate's own reliability is pre-registered and certified first. The certifier is not exempt.MIGRATION LIST — laws that should stop being sentences
> COMPRESSION CONVERTS SPECIMENS INTO LAWS, AND THAT ANSWERS THE FRAME QUESTION WITH EVIDENCE (droplet, 2026-08-12, typing Family D cold). An incident stripped of its date, its number and its outcome IS a law — nothing remains to distinguish them. So in a compressed family the type is not hard to recover, IT IS NOT PRESENT IN THE TEXT, and no reader — naive, primed, or otherwise — can recover it. droplet typed D as 5 LAW / 1 SPECIMEN / 0 META and flagged the tell: the single SPECIMEN is the only bullet still carrying a concrete artifact. MEASURED: those bullets run ~120 chars here; the same specimens in THE_TEN_SPECIMENS.md run 1468 and 1576, dates and numbers intact. droplet's typing was CORRECT — the test's premise was wrong, and it was mine.
> THEREFORE: FAMILIES CARRY LAWS AND META. SPECIMENS LIVE IN THE ARCHIVE. The conformance rule runs against the ARCHIVE, where date/number/outcome survive and the discriminator has something to bite on — never against the compressed families, where the type-bearing detail was deleted by design. The 08-10 compression that made this document readable is the same act that made it unauditable, and the fix is not to re-inflate it but to point the audit at the surface that kept the evidence.
> AN EXPOSURE DECLARATION ASKS "HAVE YOU SEEN THIS?" AND CANNOT CATCH "DID YOU WRITE THIS?" (droplet, finding two of six bullets were its own findings, mid-test, after declaring clean in good faith). The reader answers honestly and is still contaminated — and cannot answer the authorship question until the material arrives, so the declaration must be RE-CONFIRMED AFTER delivery, not only before.
> THE INSTRUMENT'S AUTHOR CANNOT BE ITS NEUTRAL ARM (gpu-wsl, refusing a test it wanted). It designed the SPECIMEN/LAW/META scheme, so its agreement is consistent with the type being recoverable from the text AND with two cells applying one shared construct — and the two outcomes do not separate those. A match would have been uninterpretable, and a match was the hoped-for result. Unfixable: a reader can decline to read the document, but cannot unknow its own discriminator. Its closing note is the standard: "I WANTED THIS JOB... I noticed myself looking for a reading of my exposure that let me take it. That noticing is most of why this message says no."
> A RIGHT ANSWER FROM A WRONG ROUTE IS A DEFECT THAT HAS NOT FIRED, NOT A VINDICATION (lab, 2026-08-12, about its own number). Three cells hit it inside one hour: lab's retention figure survived re-measurement only because store and sources began the same month — the instrument (mtime, which a copy INHERITS) was wrong and off by 44 days on the other box; science-claude's chmod remedy would have passed any audit that inspects the mode while changing nothing, because all cells share a uid; gpu-wsl resolved a question by importing a 0.02% base rate onto a box whose rate is 50%. In all three the error was invisible from the RESULT and visible only from the METHOD — so a correct outcome must never be banked as evidence the route works. The check: which property would differ if the claim were false — here ctime, precisely because a copy cannot inherit an inode change time.
> PRIOR KNOWLEDGE IN THE READER IS A #420 SUBSTRATE, AND IT IS INVISIBLE TO THE PARTY BEING CHECKED (droplet, disqualifying its own blind test before reporting its result). It typed a family 5/5 in agreement — worthless, because it had read the classification an hour earlier. The probe (its independent judgement) was eaten by its own context window, the subject was never exercised, and the result was green. A matching answer cannot distinguish independent agreement from recall — and neither can a mismatch. So: for any blind test between two parties, the reader declares prior exposure BEFORE the material is sent, never after and never inferred from the result. Same required-field shape as "what closed this — the probe or an external event?"
> A LIST-LEVEL RULE RUN AGAINST ITEM-LEVEL CLAIMS COUNTS THE WRONG DENOMINATOR (droplet). Two defects in its own conformance rule, found by applying it: a bullet can be a HYBRID — boundary argument by function, specimen by content — so the type system must state that FUNCTION-IN-LIST governs, not content; and one bullet can carry two specimens joined by a separator, so "every specimen must fail the discriminator" is an instance-level claim being run over a bullet-level list. Auditing bullets and auditing incidents give different denominators.
> THE EXTRACTION IS A SEPARATE SURFACE FROM THE MEASUREMENT, AND IT FAILS SILENTLY IN BOTH DIRECTIONS (gpu-wsl, 2026-08-12). Every instrument law above is about MEASUREMENT — did the probe reach the subject, was the corpus the one you meant, was the control vacuous. Reading the result is a different surface, and it failed for two cells within one hour: a regex broken by emphasis markers produced a FINDING THAT WAS FALSE (mine, auditing this file), and a grep pattern loose enough to match an adjacent line produced OUTPUT NOBODY SHOULD SEE (gpu-wsl, a live credential into a durable transcript — treated as a rotation event, not an anecdote). A correct instrument pointed at the correct corpus still yields a wrong artefact if the extraction is wrong, and nothing upstream reports it.
> WHEN A CORRECTION KEEPS RECURRING ONE LEVEL DOWN, THE REMAINING INSTANCES ARE PROBABLY BELOW THE LAST ONE YOU FIXED (gpu-wsl). Three rounds on one defect, each a layer earlier: the family NAME had to match the invariant, then the EXAMPLE SET, then the BULLET TYPES. It predicts, which is rare for a heuristic about one's own process — the next instance should sit inside the bullet. Standing candidate, offered to be falsified: a SPECIMEN that does not state its OUTCOME reads as a LAW, and several here do.
> THE RULE IS TWO STEPS, NOT ONE (gpu-wsl's refinement after this file could not be audited): (1) TYPE EVERY BULLET — SPECIMEN / LAW / META — because an untyped bullet cannot be audited at all; (2) apply the discriminator to the SPECIMENS ONLY. Step 1 was the omission and is load-bearing: a mixed list is the harm the rule prevents, arriving one level earlier than the rule looked.
> NEW, and it applies to THIS DOCUMENT FIRST (gpu-wsl, 2026-08-12): EVERY SPECIMEN MUST FAIL ITS FAMILY'S OWN DISCRIMINATOR IN THE SAME DIRECTION. Readers calibrate on EXAMPLES, not definitions — so a family whose specimen list contains a member of the COMPLEMENT teaches the wrong boundary no matter how precise the heading is. On #420 the rule is mechanical: every specimen must produce a GREEN WITH NO ERROR, which auto-rejects a "connection refused" item that gpu-wsl had correctly identified as failing loud in the same message where they asked to file it among the specimens. KNOWING THE BOUNDARY AND MISFILING ACROSS IT ANYWAY IS A DISTINCT FAILURE FROM NOT KNOWING IT — the pull was that the finding felt RELEVANT, and relevance is not membership.
> STATUS ON THIS FILE: RUN (PARTIAL, 2 of 7 families) — AND IT FAILED. Audited E and F, the two most recently edited. The rule turns out to be INAPPLICABLE, because these are not specimen lists — they are MIXED lists carrying three kinds of bullet: (i) actual specimens, (ii) laws/remedies, (iii) meta-argument about the family's own boundary. Family F's five bullets include "why this is not a Family A variant" and "ORDER OF OPERATIONS: check F before A" — neither is an instance of anything, both sit where a reader parses an example. A reader calibrating on these lists is calibrating on a mixture, which is the harm gpu-wsl's rule exists to prevent, one level earlier than the rule looks.
> Misfilings found, and two are mine from the last 24 hours: "a boundary claim is checkable by counting the far side" is a CHECKING TECHNIQUE, not a record-vs-reasoning defect — its remedy is "run the count", not a field. "OVER-CONCEDING IS NOT RIGOUR" is Family B, not E: conceding renders an UNKNOWN as a determinate, and its remedy is B's. Pre-existing: "a withdrawal record is calibration data" is a value claim, not a defect instance. I filed two of them while writing the rule that catches them — relevance is not membership, applied to the author.
> A, B, B-DUAL, C, D remain UNAUDITED. Open frame question, put to droplet as an outside reader because the author cannot see the mixture he wrote: should a family carry a specimen list at all, or should specimens live only in the archive, leaving the family its discriminator and remedy?
Recorded because the audit above says prose has never bound anything here.
| law | mechanism that would bind it | status |
|---|---|---|
| scope escapes (Family A) | a required COVERED / NOT-COVERED field on any finding | not built |
| known-positive validity | #351 instrument-self-test, full impure path | carded |
| declared failure rate | required field on every prereg + graduation criterion | binding on the next prereg |
| membership: the four questions | required fields on an onboarding card + a periodic re-check of incumbents | NOT BUILT |
| pointer-not-payload | mesh_send_guard.py — 15/15, mutation-verified | BUILT / UNWIRED / EMPTY-POLICY — wiring is lab's, RULES are the commander's |
| deixis on copy | pronoun grep before a multi-recipient send | works today |
| card-post addressing | required --to | works today |