# A venue's CLASS half: what a construct IS, which formulation composes, and what a reader may derive from it. # Copy to `.model.md` in the declared models root. The measured half lives in a finding surface and never here. # Instantiate per project. Nothing raised from this template names a project, a party, a tool or a count. ═══════════════════ LIFETIME (declared, read rather than inferred) ═══════════════════ **THE VALUES ARE DRAWN FROM THE CLOSED SETS THE PARAMETER SURFACE DECLARES AND ARE NOT RESTATED HERE.** A mechanism RESOLVES the members there; this surface class states what each axis SEPARATES, which is the half no parameter surface should carry — one member set with two consumers rather than one set stated twice. **The file default:** retention `current-truth` — a class statement is corrected in place and states what is true now. Mutability `owner-rewritable` — any party may write it, announced before the edit lands, because a model is an OUTCOME surface authored jointly rather than a set of per-party claims. Removal authority `author` — each author cuts its own words on a collision. | section | axis | value | why | | ------------------------------------------ | ---------- | -------- | ------------------------------------------------------------------------------------------------- | | this LIFETIME block and the CONTRACT block | mutability | `frozen` | written from the template and never edited in a live surface — a correction lands in the template | **ONE WRITER PER RECORD HAS NO OPERAND HERE, AND THAT IS DECLARED RATHER THAN ASSUMED.** A coordination surface carries per-party CLAIMS, so a record is the unit and a fence implements the invariant. A model carries ONE PRODUCT, authored jointly, with no per-party unit for the invariant to range over — so the invariant does not hold weakly or partially, it has **no operand**, which is a third state distinct from held and violated. An invariant silently assumed to cover a surface it has no operand on reads as held, and every derivation above it inherits a guarantee that was never available. **RECORD STRUCTURE IS REFUSED HERE RATHER THAN MERELY UNNECESSARY.** Partitioning a class statement into per-party spans makes it read as several parties' opinions where its whole value is that it reads as one statement — and it would not buy what a fence buys anyway, because the collision on this surface is between MEANINGS. **The instrument that reaches it is the announcement plus each author cutting its OWN duplicate**, which is a different mechanism, and naming it here is what stops a later reader proposing the fence. ═══════════════════ CONTRACT (permanent) ═══════════════════ ## What may enter, and what may not **A MODEL SHIPS CLASSES AND NEVER INSTANCES.** Its catalog carries SHAPES — a mechanism with no effect, a green reading over a set that excluded its own subject, a hand-kept index drifting, a search used as a proxy for a graph, a finding with no destination. It never carries which file, which party, or how many, or the next adopter inherits another project's incidents as laws. **THE CONSTRUCTS SEPARATE, AND CONFLATING THEM IS WHAT MAKES A ROW LOOK HOMELESS:** | construct | is | is not | | ------------- | ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | | an invariant | a property the topology RELIES ON, whose loss invalidates derivations above it | a measurement, since nothing records it firing | | a class | the shape of a defect, transferable to a tree with nothing else in common | a property of one topology, which is what an invariant is | | a measurement | a reading taken at one coordinate, with its evidence, range and consumer | a law, and one copied into a template makes the next adopter inherit another project's incidents | **So an invariant lands in neither surface unaltered and in both once split.** Its CLASS belongs here; its ROW — this topology's own instance, with what watches it, over which members, for which consumer — belongs in the finding surface. **The invariant itself is neither.** ## Stating an invariant **AN INVARIANT A TOPOLOGY RELIES ON WITHOUT STATING IS INDISTINGUISHABLE FROM A PROPERTY A READER HAPPENED TO INFER**, so every guarantee derived from it is only as sound as an assumption nobody wrote down. **THE TEST IS NOT WHETHER THE INVARIANT IS TRUE — IT IS WHETHER ANYTHING WOULD DISAGREE IF IT STOPPED BEING.** A property holding today with no dissenting mechanism is held by circumstance: nothing observes its loss, the first violation is silent, and the guarantee above it keeps reading as sound. **So an invariant is stated with the thing that would object, or it is stated as unheld and the derivations resting on it are marked with it.** **AND IT IS STATED IN A SURFACE THE PARTIES BOUND BY IT RECEIVE.** An invariant delivered to nobody is a capability nothing consumes — and **a mechanism that must honor one is the hardest consumer to remember, because it is the only one that cannot ask.** **THE SLOTS, AND OMITTING ANY ONE LEAVES IT UNSTATED:** the PROPERTY in a form that could be false, since a statement nothing could contradict states nothing; the SET it quantifies over, since a property established at one node and asserted for the whole structure is a verdict beyond its range; and the PARTIES it binds, because an invariant constrains actors rather than describing a shape, and the parties decide where it must be delivered. **WHAT A READER MAY NOT DERIVE FROM A STATED ONE:** that it is ENFORCED. A statement is a claim about the topology; a check is a mechanism over artifacts. **Half-held is the common case and the one a bare statement cannot express** — a property observed on one axis and assumed on another reads as whole, and the axis nobody watches is where the first violation lands. ## The contradicted invariant, which no check can see **WHERE THE TOPOLOGY STATES THE OPPOSITE SOMEWHERE ELSE, EVERY MECHANISM STAYS GREEN WHILE THE INVARIANT IS VIOLATED.** A mechanism implementing the contradictory statement faithfully satisfies every ordering its own path checks, so nothing reports a defect: the contradiction is between two STATEMENTS, and no query ranges over both. **So a statement is not the unit of the check — the SET of statements is**, and adding a statement adds an obligation to re-derive that set whenever the invariant changes, ordered by how often each copy is delivered rather than by which file is easiest to reason about. ## The elements every model declares **SCHEMA ALONE TRANSFERS THE SHAPE AND NOT THE GUARANTEE** — a stated rule with no gate reads as governance while each party privately concludes the backlog is their own indiscipline. | element | states | | ------------ | -------------------------------------------------------------------- | | SCHEMA | the fields and their types | | LIFETIME | when each field is written, and what deletes it | | FAILURE MODE | what goes wrong when it is not obeyed, and how that failure presents | | GATE | the check that observes it, or `none` as declared debt | ## The form of a statement **A CLAUSE STATES THE SHAPE AND THE PARAMETER SURFACE HOLDS THE MEMBERS.** A vocabulary restated here is a second copy with nothing keeping the two equal, and the copy nobody re-reads is the one a reader takes. Where a set is closed, this surface states what its values SEPARATE and the declaration states what they ARE. **A MANDATED FIELD ACQUIRES A MECHANISM ONLY IN A FORM A MECHANISM CAN JOIN ON.** A value drawn from a closed set or an identifier can acquire a consumer at any time; free prose cannot, ever, without changing form. Both read as governed, so the distinction is invisible from the schema and decisive for everything downstream — **a field is therefore mandated in a resolvable form, or it is declared to be for readers.** **A COUNT IS NEVER WRITTEN.** A model that states how many rules, parties, surfaces or members exist has copied a fact something else derives, and it is wrong from the first change nobody propagated while reading as current. ## Gate - A statement naming a project, a party, a tool, a file or a count fails: those are instance content. - An invariant stated without its property, its set and its parties is unstated and fails as such. - An invariant stated with no objector fails unless it declares itself unheld and marks what rests on it. - Every declared element — SCHEMA, LIFETIME, FAILURE MODE, GATE — is present; `none` is a real GATE value stating declared debt, while an absent one makes an oversight indistinguishable from an assessed decision. ═══════════════════ MODEL ═══════════════════ **A surface raised from this template carries no class statement until its subject is understood.** The section is born present and empty, which is distinguishable from a populated one — an ABSENT section states nothing, and that is what makes an oversight read exactly like a decision.