models/coupling.model.md

models/coupling.model.md is a file in Coordination Surface. 128 lines of code and 0 definitions.

<!-- MODEL SURFACE -->

# The class half of coupling as the operand a party count derives from: what bounds that count, and what it buys.

# Raised from `templates/model.template.md`. The measured half lives in a finding surface and never here.

# Nothing here names a project, a party, a tool, a file or a count.

═══════════════════ LIFETIME (declared, read rather than inferred) ═══════════════════

**The values are drawn from the closed sets the parameter surface declares and are not restated here.** A
mechanism resolves the members there, and this surface class states what each axis separates, which is the half
no parameter surface should carry, so there is one member set with two consumers rather than one set stated
twice.

**The file default:** retention `current-truth`, because a class statement is corrected in place and states what
is true now. Mutability `owner-rewritable`, because any party may write it, announced before the edit lands,
since a model is an outcome surface authored jointly rather than a set of per-party claims. Removal authority
`author`, because each author cuts its own words on a collision.

| section                                    | axis       | value    | why                                                                                                 |
| ------------------------------------------ | ---------- | -------- | --------------------------------------------------------------------------------------------------- |
| this LIFETIME block and the CONTRACT block | mutability | `frozen` | written from the template and never edited in a live surface, so a correction lands in the template |

**One writer per record has no operand here, and that is declared rather than assumed.** A coordination surface
carries per-party claims, so a record is the unit and a fence implements the invariant. A model carries one
product, authored jointly, with no per-party unit for the invariant to range over, so the invariant does not hold
weakly or partially: it has **no operand**, which is a third state distinct from held and violated.

═══════════════════ CONTRACT (permanent) ═══════════════════

**A model ships classes and never instances.** Its catalog carries shapes. It never carries which file, which
party, or how many, or the next adopter inherits another project's incidents as laws.

**THE THREE SLOTS, AND OMITTING ANY ONE LEAVES AN INVARIANT UNSTATED:** the PROPERTY in a form that could be
false, the SET it quantifies over, and the PARTIES it binds. **An invariant is stated with the thing that would
object, or it is stated as unheld and the derivations resting on it are marked with it.**

**What a reader may not derive from a stated invariant:** that it is enforced. Half-held is the common case and
the one a bare statement cannot express.

═══════════════════ MODEL ═══════════════════

## The subject

**A party count is an output of a structure rather than an input to one.** The question _how many parties does
this work imply_ is answered by deriving it, and the whole content of the answer is naming the operand the
derivation reads. Every model that fails here fails by relocating the choice rather than removing it.

## Invariant: the count is derived from a partition and never chosen independently of it

- **Property.** For any body of work, the count follows from how that work is partitioned into concerns, so two
  parties holding different partitions derive different counts from the same work on the same day. It could be
  false: a count that moves when no party's partition moved refutes it.
- **Set.** Every allocation decision over a governed body of work.
- **Parties.** Whoever proposes a count, and whoever proposes a cut.
- **Its objector, named because the template forbids a statement nothing can contradict.** The partition is itself
  derived from a coupling relation over the surfaces: two surfaces are joined when a change to one forces a change
  to the other, and the concerns are that relation's connected components. **That relation is chosen once.** Two
  defensible readings of _forces_ yield component counts an order of magnitude apart, so the regress stops at a
  choice rather than dissolving. **The claim is therefore three levels with one choice at the bottom, and it is
  weaker than the count being derived outright.**
- **What survives the objection.** The bottom choice is answerable to evidence rather than settled by taste,
  because a relation must yield a partition that is invariant under occupancy, one that does not lose a node when
  a party stops while that node's work continues, and must yield a floor consistent with observed
  indispensability. Neither constraint selects a unique relation, and both eliminate candidates. **So the choice
  can be argued with rather than hidden.**

## Invariant: the floor counts the partition's nodes

- **Property.** The minimum count is the number of concerns that must be able to contradict each other while each
  stays authoritative. Volume is the wrong operand, because quantity divides across parties and so argues for a
  longer schedule rather than a wider one, while indivisibility is what forces a second party.
- **Set.** The concerns a partition yields over one governed tree.
- **Parties.** Whoever allocates, and whoever owns a surface.
- **Objector.** A relation whose components collapse to one refutes the floor it produces wherever separate parties
  demonstrably caught what no single one did.

## Invariant: the ceiling is set by the worst fan-in, not by the count

- **Property.** The maximum useful count is reached where the claims resting on one surface stop surviving
  composition, where a claim is stale by the time it lands more often than it is useful when it does. It could be
  false: staleness distributed evenly across surfaces, regardless of how many parties' claims rest on each, would
  refute it.
- **Set.** Every surface a governed tree carries.
- **Parties.** Whoever composes a claim about a surface they do not own.
- **Its objector, which was argued and lost rather than never raised.** The rate at which any one claim goes stale
  is set by the writer's rate and the composer's time, both properties of one writer and one composer, so no reader
  population changes it, and on that reading the bound is not a function of the count at all. **What survives that
  is the cost term rather than the rate.** The number of stale claims published does scale with the population, and
  each is read and usually answered by every other party. A reader meeting this invariant cold would otherwise
  conclude the rate half was never considered.
- **Why fan-in rather than write rate.** A surface with one writer cannot have its volatility raised by adding a
  party, so a party writing only its own surfaces adds nothing to any other party's staleness. Staleness rises only
  where parties converge on one subject. **Ownership therefore bounds fan-in rather than defining it.** The
  concentration is continuous, and a formally owned surface many parties reason about behaves like a shared one.
- **The cost asymmetry that makes it a ceiling.** A stale claim is read, and usually answered, by every other party,
  so the cost of staleness grows with the population while the benefit of one more perspective grows sublinearly as
  coverage overlaps. Two terms with different growth cross, and the crossing is the bound.
- **The bound is movable, and the term that moves is the cost rather than the rate.** The rate at which a claim goes
  stale is set by one surface's writer and one composer, so no party count changes it and nothing addresses it. The
  cost is what the population multiplies, so that is the term a mechanism can reach. A claim arriving marked as
  resting on a surface that has since moved costs its readers a glance, where one that must be argued costs every
  party a read and usually a reply. **A mechanism recording when a claim's cited surface was observed reduces no
  staleness whatever, and it reduces what staleness costs**, so it raises the ceiling without touching the
  partition, the relation or the count. A reader taking the bound as fixed concludes the only lever is fewer
  parties, which is the wrong lever and the expensive one.
- **Objector to the movability.** Where the cost of a stale claim is dominated by work already built on it rather
  than by reading and answering it, marking it afterwards recovers nothing and the bound does not move.

## Invariant: fan-in is measured and never declared

- **Property.** The operand both bounds read is derivable from traffic a coordination surface already records: who
  authored a claim, who it was addressed to, and which surface it cites. A declared edge set would be a second copy
  of that fact, maintained by hand, disagreeing with the observed coupling the first time the work moves.
- **Set.** Every coupling edge between concerns.
- **Parties.** Whoever would maintain a declared graph.
- **Objector.** A tree whose coordination surfaces record neither authorship nor citation cannot derive it, and there
  the bound is unavailable rather than merely unmeasured.

## The limit: the benefit term fails on absence claims

**The floor rests on a multiplier, the probability that some party opens the operand another did not, and that
multiplier has a class where it does not apply.** A claim that something exists has an operand each party can open,
and parties spread across operands. A claim that something does not exist has no operand at all, so parties spread
across descriptions of the missing thing, which all say the same thing. **Added parties then produce agreement rather
than coverage**, and thoroughness is the symptom rather than the missing ingredient.

**The settling act is an invocation rather than a read**, because a capability's absence is established by
attempting it. And the mechanism half scales better than the conduct half: **a refusal that publishes its
criterion**, naming what it searched and what else it will accept, converts an unanswerable absence into an ordinary
read, once, for every later caller. A mechanism that silently accepts what it does not recognize is the extreme case
of a refusal publishing nothing.

## What the format of a schedule does and does not decide

**A typed schedule makes a stray note a refusal rather than a convention**, because prose written into a parsed
structure fails to resolve instead of being read as content, which is a gate where a second file is only a habit. It
also separates facts a single column had been carrying: an identity that travels into a name, and a position that is
the sequence.

**It does not decide the schedule's semantics.** A unique next computed over a partial order with forward
dependencies has no unique answer, and an ordered typed structure expresses that ambiguity exactly as faithfully as a
table does. **Format and ordering semantics are separable, and conflating them buys neither.**

## The four elements

| element      | states                                                                                                                                                                                                                                                     |
| ------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| SCHEMA       | a partition of surfaces into concerns, per concern its owner and the surfaces it holds, and per claim its author, its addressees and the surfaces it cites                                                                                                 |
| LIFETIME     | the partition is current-truth and re-derived when the coupling relation's inputs move, and a claim's citation record accumulates and is never rewritten                                                                                                   |
| FAILURE MODE | a count chosen rather than derived reads as a decision and is a preference. Work is then allocated to parties rather than parties to work, and the surface whose fan-in exceeds the ceiling produces contradictions that every party reads as carelessness |
| GATE         | `none`. No mechanism derives the partition, counts fan-in, or compares a proposed count against either bound. The operands exist and the derivations do not, which is declared debt rather than an assessed decision                                       |

## Gate

- A statement here naming a project, a party, a tool, a file or a count fails, because those are instance content.
- An invariant stated without its property, its set and its parties is unstated and fails as such.
- An invariant stated with no objector fails unless it declares itself unheld and marks what rests on it.
- The GATE element reads `none` deliberately, which states declared debt, and an absent element would make an
  oversight indistinguishable from an assessed decision.