templates/model.template.md
templates/model.template.md is a file in Coordination Surface. 96 lines of code and 0 definitions.
<!-- MODEL SURFACE -->
# A venue's class half: what a construct is, which formulation composes, and what a reader may derive from it.
# Copy to `<subject>.model.md` in the declared models root. The measured half lives in a finding surface and never here.
# Instantiate per project. Nothing raised from this template names a project, a party, a tool or a count.
═══════════════════ LIFETIME (declared, read rather than inferred) ═══════════════════
**The values are drawn from the closed sets the parameter surface declares and are not restated here.** A
mechanism resolves the members there, and this surface class states what each axis separates, which is the half
no parameter surface should carry, so there is one member set with two consumers rather than one set stated
twice.
**The file default:** retention `current-truth`, because a class statement is corrected in place and states what
is true now. Mutability `owner-rewritable`, because any party may write it, announced before the edit lands,
since a model is an outcome surface authored jointly rather than a set of per-party claims. Removal authority
`author`, because each author cuts its own words on a collision.
| section | axis | value | why |
| ------------------------------------------ | ---------- | -------- | --------------------------------------------------------------------------------------------------- |
| this LIFETIME block and the CONTRACT block | mutability | `frozen` | written from the template and never edited in a live surface, so a correction lands in the template |
**One writer per record has no operand here, and that is declared rather than assumed.** A coordination surface
carries per-party claims, so a record is the unit and a fence implements the invariant. A model carries one
product, authored jointly, with no per-party unit for the invariant to range over, so the invariant does not hold
weakly or partially: it has **no operand**, which is a third state distinct from held and violated. An invariant
silently assumed to cover a surface it has no operand on reads as held, and every derivation above it inherits a
guarantee that was never available.
**Record structure is refused here rather than merely unnecessary.** Partitioning a class statement into
per-party spans makes it read as several parties' opinions where its whole value is that it reads as one
statement, and it would not buy what a fence buys anyway, because the collision on this surface is between
meanings. **The instrument that reaches it is the announcement plus each author cutting its own duplicate**, which
is a different mechanism, and naming it here is what stops a later reader proposing the fence.
═══════════════════ CONTRACT (permanent) ═══════════════════
## What may enter, and what may not
**A model ships classes and never instances.** Its catalog carries shapes: a mechanism with no effect, a green
reading over a set that excluded its own subject, a hand-kept index drifting, a search used as a proxy for a
graph, a finding with no destination. It never carries which file, which party, or how many, or the next adopter
inherits another project's incidents as laws.
**The constructs separate, and conflating them is what makes a row look homeless:**
| construct | is | is not |
| ------------- | ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ |
| an invariant | a property the topology relies on, whose loss invalidates derivations above it | a measurement, since nothing records it firing |
| a class | the shape of a defect, transferable to a tree with nothing else in common | a property of one topology, which is what an invariant is |
| a measurement | a reading taken at one coordinate, with its evidence, range and consumer | a law, and one copied into a template makes the next adopter inherit another project's incidents |
**So an invariant lands in neither surface unaltered and in both once split.** Its class belongs here, and its
row, meaning this topology's own instance, with what watches it, over which members, for which consumer, belongs
in the finding surface. **The invariant itself is neither.**
## Stating an invariant
**An invariant a topology relies on without stating cannot be told apart from a property a reader happened to
infer**, so every guarantee derived from it is only as sound as an assumption no party wrote down.
**The test is not whether the invariant is true. It is whether anything would disagree if it stopped being.** A
property holding today with no dissenting mechanism is held by circumstance: nothing observes its loss, the first
violation is silent, and the guarantee above it keeps reading as sound. **So an invariant is stated with the thing
that would object, or it is stated as unheld and the derivations resting on it are marked with it.**
**And it is stated in a surface the parties bound by it receive.** An invariant delivered to no party is a
capability nothing consumes, and **a mechanism that must honor one is the hardest consumer to remember, because
it is the only one that cannot ask.**
**THE SLOTS, AND OMITTING ANY ONE LEAVES IT UNSTATED:** the PROPERTY in a form that could be false, since a
statement nothing could contradict states nothing, the SET it quantifies over, since a property established at one
node and asserted for the whole structure is a verdict beyond its range, and the PARTIES it binds, because an
invariant constrains actors rather than describing a shape, and the parties decide where it must be delivered.
**What a reader may not derive from a stated one:** that it is enforced. A statement is a claim about the topology,
and a check is a mechanism over artifacts. **Half-held is the common case and the one a bare statement cannot
express**, since a property observed on one axis and assumed on another reads as whole, and the axis no party
watches is where the first violation lands.
## The contradicted invariant, which no check can see
**Where the topology states the opposite somewhere else, every mechanism stays green while the invariant is
violated.** A mechanism implementing the contradictory statement faithfully satisfies every ordering its own path
checks, so nothing reports a defect: the contradiction is between two statements, and no query ranges over both.
**So a statement is not the unit of the check, and the set of statements is**, and adding a statement adds an
obligation to re-derive that set whenever the invariant changes, ordered by how often each copy is delivered rather
than by which file is easiest to reason about.
## The elements every model declares
**Schema alone transfers the shape and not the guarantee**, since a stated rule with no gate reads as governance
while each party privately concludes the backlog is its own indiscipline.
| element | states |
| ------------ | -------------------------------------------------------------------- |
| SCHEMA | the fields and their types |
| LIFETIME | when each field is written, and what deletes it |
| FAILURE MODE | what goes wrong when it is not obeyed, and how that failure presents |
| GATE | the check that observes it, or `none` as declared debt |
## The form of a statement
**A clause states the shape, and the parameter surface holds the members.** A vocabulary restated here is a second
copy with nothing keeping the two equal, and the copy no party re-reads is the one a reader takes. Where a set is
closed, this surface states what its values separate and the declaration states what they are.
**A mandated field acquires a mechanism only in a form a mechanism can join on.** A value drawn from a closed set or
an identifier can acquire a consumer at any time, and free prose cannot, ever, without changing form. Both read as
governed, so the distinction is invisible from the schema and decisive for everything downstream, and **a field is
therefore mandated in a resolvable form, or it is declared to be for readers.**
**A count is never written.** A model that states how many rules, parties, surfaces or members exist has copied a
fact something else derives, and it is wrong from the first change no party propagated while reading as current.
## Gate
- A statement naming a project, a party, a tool, a file or a count fails, because those are instance content.
- An invariant stated without its property, its set and its parties is unstated and fails as such.
- An invariant stated with no objector fails unless it declares itself unheld and marks what rests on it.
- Every declared element, SCHEMA, LIFETIME, FAILURE MODE and GATE, is present. `none` is a real GATE value stating
declared debt, while an absent one makes an oversight indistinguishable from an assessed decision.
═══════════════════ MODEL ═══════════════════
**A surface raised from this template carries no class statement until its subject is understood.** The section is
born present and empty, which can be told apart from a populated one, while an absent section states nothing, and
that is what makes an oversight read exactly like a decision.