# Coordination Surfaces

> Every principle in this category is listed as a record.

Page: Ontology · Principles
Canonical: https://banes-lab.com/ontology#architecture-category-coordination-surfaces

Listed in [Ontology · Principles](https://banes-lab.com/api/pages/ontology/principles.md), after [Codebase / System Architecture Styles](https://banes-lab.com/ontology/principles/architecture-category-codebase-system-architecture-styles.md) and before [Taxonomy / Classification / Naming](https://banes-lab.com/ontology/principles/architecture-category-taxonomy-classification-naming.md).

Every principle in this category is listed as a record. Each record carries its kind, its severity, the scopes it applies at and the layer it lives in, then the edge relations that join it to other records, the records that point back at it, the contracts that answer to it and the tensions it takes part in. The descriptors say how it is violated, detected, measured, repaired and enforced. Where the record carries one, an exemplar shows the shape before and after the principle is applied.

Relations diagram

The relations inside this category.

```mermaid
flowchart LR
n_stated_invariant["Stated Invariant"]
n_derived_record_state["Derived Record State"]
n_declared_subject["Declared Subject"]
n_write_barrier["Write Barrier"]
n_operand_free_outcome_surface["Operand-Free Outcome Surface"]
n_projection_channel["Projection Channel"]
n_two_direction_index["Two-Direction Index"]
n_independent_lifetime_axes["Independent Lifetime Axes"]
n_section_lifetime_divergence["Section Lifetime Divergence"]
n_write_scope_and_read_population["Write Scope and Read Population"]
n_read_time_join["Read-Time Join"]
n_one_sided_liveness["One-Sided Liveness"]
n_reversible_channel_encoding["Reversible Channel Encoding"]
n_declare_before_read_order["Declare-Before-Read Order"]
n_period_decided_disposition["Period-Decided Disposition"]
n_derived_party_count["Derived Party Count"]
n_fan_in_ceiling["Fan-In Ceiling"]
n_state_arity_limit["State-Arity Limit"]
n_carrier_and_payload_split["Carrier and Payload Split"]
n_joinable_mandated_field["Joinable Mandated Field"]
n_single_aggregate["Single Aggregate"]
n_contradicted_invariant["Contradicted Invariant"]
n_written_status_marker["Written Status Marker"]
n_invocation_keyed_report["Invocation-Keyed Report"]
n_narrowed_aggregate["Narrowed Aggregate"]
n_cyclic_tiebreak["Cyclic Tiebreak"]
n_destructive_closure["Destructive Closure"]
n_hand_kept_index["Hand-Kept Index"]
n_stated_invariant --x n_contradicted_invariant
n_derived_record_state --x n_written_status_marker
n_operand_free_outcome_surface --> n_stated_invariant
n_operand_free_outcome_surface --x n_contradicted_invariant
n_two_direction_index --x n_hand_kept_index
n_independent_lifetime_axes --x n_destructive_closure
n_section_lifetime_divergence --> n_independent_lifetime_axes
n_read_time_join --> n_write_scope_and_read_population
n_period_decided_disposition --x n_cyclic_tiebreak
n_fan_in_ceiling --> n_derived_party_count
n_joinable_mandated_field --> n_carrier_and_payload_split
n_single_aggregate --x n_invocation_keyed_report
n_single_aggregate --x n_narrowed_aggregate
```

### Stated Invariant

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: topology, coordination
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A design rule that an invariant a topology relies on is written with its property in a form that could be false, the set it ranges over, the parties it binds and the thing that would object if it stopped holding.

Requires
[Coordination Surface](https://banes-lab.com/records/lexicon/coordination-surface.md)

Reinforces
[Fitness Functions](https://banes-lab.com/records/architecture/fitness-functions.md)

Enables
[Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

In tension with
none

Conflicts with
[Contradicted Invariant](https://banes-lab.com/records/architecture/contradicted-invariant.md)

Referenced by
[Operand-Free Outcome Surface](https://banes-lab.com/records/architecture/operand-free-outcome-surface.md)

Expressed in the grammar by
[invariant:INVARIANT](https://banes-lab.com/records/pag/keyword-invariant-invariant.md), [invariant_record](https://banes-lab.com/records/pag/production-invariant-record.md), [invariant_block](https://banes-lab.com/records/pag/production-invariant-block.md)

Violated by
relying on a property that nothing would notice losing, or stating it in a surface the bound parties never receive

Detected by
an invariant with no objector, or one that names no set or no bound party

Measured by
invariants stated without an objector and not marked unheld

Refactored by
Name the Objector, or Mark the Invariant Unheld and Every Derivation Resting on It

Enforced by
coordination review

Before

```text
every surface has one writer → nothing counts writers → a second writer lands and every guarantee resting on the first still reads as sound
```

After

```text
property: one writer per record → set: every record on a coordination surface → parties: every writer → objector: a check failing a record whose fence names two writers
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Coordination Surface](https://banes-lab.com/records/lexicon/coordination-surface.md), [Fitness Functions](https://banes-lab.com/records/architecture/fitness-functions.md), [Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

Shape it refuses
[Contradicted Invariant](https://banes-lab.com/records/architecture/contradicted-invariant.md)

### Derived Record State

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: record, coordination
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A design rule that a record's state is a query over the edges it carries, open while its satisfying artifact is unresolved, blocked while a blocker is open and absorbed once the artifact exists, so no party writes a state.

Requires
[Coordination Record](https://banes-lab.com/records/lexicon/coordination-record.md), [Acknowledger](https://banes-lab.com/records/lexicon/acknowledger.md)

Reinforces
[Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md)

Enables
[Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

In tension with
none

Conflicts with
[Written Status Marker](https://banes-lab.com/records/architecture/written-status-marker.md)

Distinct from
[Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md): Derived record state applies one owning source to a record's status, while a single source of truth covers any fact, rule or configuration value.

Violated by
writing a status field on a record instead of deriving it from the record's edges

Detected by
a record carrying a state that its edges no longer support

Measured by
records whose written state differs from the derived one

Refactored by
Remove the Status Field, Derive the State From the Edges

Enforced by
the coordination closure check, which refuses a judgement closure that cites an artifact and an artifact closure that cites none

Before

```text
a record reads status: done → its artifact was later deleted → the marker still asserts done
```

After

```text
the record cites satisfied-by: <artifact> → the artifact resolves: absorbed → the artifact is gone: open, with no field anyone has to remember to change
```

How it is checked

Checked by
the coordination closure check, which refuses a judgement closure that cites an artifact and an artifact closure that cites none

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Coordination Record](https://banes-lab.com/records/lexicon/coordination-record.md), [Acknowledger](https://banes-lab.com/records/lexicon/acknowledger.md), [Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md), [Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

Shape it refuses
[Written Status Marker](https://banes-lab.com/records/architecture/written-status-marker.md)

### Declared Subject

- Kind: [constraint](https://banes-lab.com/records/kind/constraint.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: record, identity
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A rule or precondition that a record carries an allocated id and a declared subject key as two fields, so a moved surface keeps the id, a renamed subject keeps the key, and two records sharing a key are a finding.

Requires
[Coordination Record](https://banes-lab.com/records/lexicon/coordination-record.md)

Reinforces
[Stable Identity](https://banes-lab.com/records/lexicon/stable-identity.md)

Enables
[Rederivation Detection](https://banes-lab.com/records/lexicon/rederivation-detection.md)

In tension with
none

Conflicts with
none

Distinct from
[Stable Identity](https://banes-lab.com/records/lexicon/stable-identity.md): A declared subject keeps a record's id and its subject as two fields that survive different renames, while stable identity requires only that one identifier last the entity's lifetime.

Violated by
deriving a record's identity from its location or from its subject, so one of the two renames breaks it

Detected by
a record whose id changes when its surface moves, or two records about one subject

Measured by
records sharing a subject key

Refactored by
Allocate the Id Once, Declare the Subject Beside It

Enforced by
coordination review

Before

```text
record id = <surface-path>-<ordinal> → the surface moves → every id changes and every edge citing one dangles
```

After

```text
id = <surface-key>-<ordinal>, allocated once → subject = <declared> → a second record declaring the same subject is reported
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Coordination Record](https://banes-lab.com/records/lexicon/coordination-record.md), [Stable Identity](https://banes-lab.com/records/lexicon/stable-identity.md), [Rederivation Detection](https://banes-lab.com/records/lexicon/rederivation-detection.md)

Shape it refuses
Not answered

### Write Barrier

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: surface, concurrency
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A mechanism that lets a planned exclusive write to a shared surface proceed only once every peer is observed parked, beside a compare-and-swap that covers every other write.

Requires
[Coordination Surface](https://banes-lab.com/records/lexicon/coordination-surface.md)

Reinforces
[Optimistic Locking](https://banes-lab.com/records/architecture/optimistic-locking.md)

Enables
[Single-Writer Coordination](https://banes-lab.com/records/lexicon/single-writer-coordination.md)

In tension with
none

Conflicts with
[Lost Update](https://banes-lab.com/records/architecture/lost-update.md)

Expressed in the grammar by
[refusal_line](https://banes-lab.com/records/pag/production-refusal-line.md)

Violated by
rewriting a shared surface whole while a peer is still active on it

Detected by
content a peer wrote missing after an exclusive write that reported success

Measured by
exclusive writes taken without every peer observed parked

Refactored by
Hold the Barrier for Planned Writes, Compare-and-Swap for Every Other Write

Enforced by
coordination review

Before

```text
a tool rewrites the board whole → a peer's record written a moment earlier is gone → every check passes
```

After

```text
planned rewrite → wait until every peer is parked → write → any other write: re-read, compare its own span, refuse with the diff on an overlap
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Coordination Surface](https://banes-lab.com/records/lexicon/coordination-surface.md), [Optimistic Locking](https://banes-lab.com/records/architecture/optimistic-locking.md), [Single-Writer Coordination](https://banes-lab.com/records/lexicon/single-writer-coordination.md)

Shape it refuses
[Lost Update](https://banes-lab.com/records/architecture/lost-update.md)

### Operand-Free Outcome Surface

- Kind: [constraint](https://banes-lab.com/records/kind/constraint.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: surface, authorship
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A rule or precondition that a surface carrying one jointly authored product declares that one writer per record has no operand there, and settles a collision by announcement and by each author cutting its own duplicate.

Requires
[Outcome Surface](https://banes-lab.com/records/lexicon/outcome-surface.md)

Reinforces
[Stated Invariant](https://banes-lab.com/records/architecture/stated-invariant.md)

Enables
[Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

In tension with
none

Conflicts with
[Contradicted Invariant](https://banes-lab.com/records/architecture/contradicted-invariant.md)

Distinct from
[Stated Invariant](https://banes-lab.com/records/architecture/stated-invariant.md): An operand-free outcome surface declares where one invariant cannot apply, while a stated invariant is the form every invariant is written in.

Violated by
assuming the one-writer invariant covers a jointly authored surface, or fencing such a surface into per-party spans

Detected by
an outcome surface with no declaration that the invariant has no operand there

Measured by
outcome surfaces missing the declaration

Refactored by
Declare the Missing Operand, Settle Collisions by Announcement

Enforced by
coordination review

Before

```text
a class statement written by several parties → the one-writer invariant is assumed to hold → nothing objects when two parties write the same clause
```

After

```text
the surface declares: one writer per record has no operand here → a collision is announced → each author cuts its own duplicate
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Outcome Surface](https://banes-lab.com/records/lexicon/outcome-surface.md), [Stated Invariant](https://banes-lab.com/records/architecture/stated-invariant.md), [Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

Shape it refuses
[Contradicted Invariant](https://banes-lab.com/records/architecture/contradicted-invariant.md)

### Projection Channel

- Kind: [constraint](https://banes-lab.com/records/kind/constraint.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: context, reader
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A rule or precondition that the projection a host injects into every bounded reader is refreshed in the same change as the fact it carries, in a shape a check reads.

Requires
[Host Projection](https://banes-lab.com/records/lexicon/host-projection.md), [Bounded Reader](https://banes-lab.com/records/lexicon/bounded-reader.md)

Reinforces
[Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md)

Enables
[Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

In tension with
none

Conflicts with
none

Violated by
updating a surface and leaving its projection for a later change, or letting the projection grow past the shape its name claims

Detected by
a projection line that disagrees with the surface it summarizes

Measured by
changes that moved a projected fact without the projection

Refactored by
Refresh the Projection in the Same Change, Check Its Shape

Enforced by
coordination review

Before

```text
a seat goes inactive on the board → the injected line still lists it → every spawned reader plans around a party that is gone
```

After

```text
the board write and the projection write land in one change → a check reads the projection's declared shape
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Host Projection](https://banes-lab.com/records/lexicon/host-projection.md), [Bounded Reader](https://banes-lab.com/records/lexicon/bounded-reader.md), [Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md), [Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

Shape it refuses
Not answered

### Two-Direction Index

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: index, directory
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A mechanism that generates an index from the directory on every run and checks it both ways, reporting an entry with no file and a file with no entry, with every scan independent of depth.

Requires
[Coordination Surface](https://banes-lab.com/records/lexicon/coordination-surface.md)

Reinforces
[Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md)

Enables
[Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

In tension with
none

Conflicts with
[Hand-Kept Index](https://banes-lab.com/records/architecture/hand-kept-index.md)

Violated by
writing an index by hand, or checking it in one direction only

Detected by
an index entry that resolves to no file, or a file no entry names

Measured by
index entries and files missing their counterpart

Refactored by
Generate the Index, Check Both Directions

Enforced by
coordination review

Before

```text
the agent index is edited by hand → a seat is added without an entry → the scan covers fewer seats than it claims
```

After

```text
the index is generated from the directory → an entry with no file fails → a file with no entry fails
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Coordination Surface](https://banes-lab.com/records/lexicon/coordination-surface.md), [Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md), [Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

Shape it refuses
[Hand-Kept Index](https://banes-lab.com/records/architecture/hand-kept-index.md)

### Independent Lifetime Axes

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: surface, lifetime
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A design rule that a surface's lifetime is declared on three independent axes, retention, mutability and removal authority, each taking a value from a closed set, so no single word stands for all three.

Requires
[Retention](https://banes-lab.com/records/lexicon/retention.md), [Mutability](https://banes-lab.com/records/lexicon/mutability.md), [Removal Authority](https://banes-lab.com/records/lexicon/removal-authority.md)

Reinforces
[Immutability](https://banes-lab.com/records/architecture/immutability.md)

Enables
[Governed Removal](https://banes-lab.com/records/lexicon/governed-removal.md)

In tension with
none

Conflicts with
[Destructive Closure](https://banes-lab.com/records/architecture/destructive-closure.md)

Referenced by
[Section Lifetime Divergence](https://banes-lab.com/records/architecture/section-lifetime-divergence.md)

Contracts
[Convergence Walk](https://banes-lab.com/records/algorithms/convergence-walk.md), [Lifetime Resolution](https://banes-lab.com/records/algorithms/lifetime-resolution.md)

Distinct from
[Immutability](https://banes-lab.com/records/architecture/immutability.md): Independent lifetime axes declare mutability as one of three questions about a surface, while immutability is the single rule that a value never changes after it is created.

Violated by
declaring a lifetime as one word, so a reader infers the other two axes

Detected by
a surface whose lifetime names retention alone

Measured by
surfaces missing a value on any axis

Refactored by
Declare All Three Axes From the Closed Sets

Enforced by
the coordination declaration check, which reports a mechanism named for a lifetime axis that never reads that axis

Before

```text
lifetime: deleted on close → a sweep implements it faithfully → the argument behind a ruling is destroyed
```

After

```text
retention: kept → mutability: frozen → removal authority: nobody → closing moves the surface to the archive
```

How it is checked

Checked by
the coordination declaration check, which reports a mechanism named for a lifetime axis that never reads that axis

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Retention](https://banes-lab.com/records/lexicon/retention.md), [Mutability](https://banes-lab.com/records/lexicon/mutability.md), [Removal Authority](https://banes-lab.com/records/lexicon/removal-authority.md), [Immutability](https://banes-lab.com/records/architecture/immutability.md), [Governed Removal](https://banes-lab.com/records/lexicon/governed-removal.md)

Shape it refuses
[Destructive Closure](https://banes-lab.com/records/architecture/destructive-closure.md)

### Section Lifetime Divergence

- Kind: [constraint](https://banes-lab.com/records/kind/constraint.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: surface, section
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A rule or precondition that a file states a default lifetime and each section declares only the axes on which it differs, since the narrower unit is the more constrained one.

Requires
[Retention](https://banes-lab.com/records/lexicon/retention.md), [Mutability](https://banes-lab.com/records/lexicon/mutability.md)

Reinforces
[Independent Lifetime Axes](https://banes-lab.com/records/architecture/independent-lifetime-axes.md)

Enables
[Governed Removal](https://banes-lab.com/records/lexicon/governed-removal.md)

In tension with
none

Conflicts with
none

Violated by
stating one lifetime for a file whose sections live differently, so the file's word authorizes operations on the part that forbids them

Detected by
an operation permitted by the file's lifetime acting on a section whose own lifetime forbids it

Measured by
divergent sections carrying no declaration

Refactored by
Declare the File Default, Declare Each Divergent Section

Enforced by
coordination review

Before

```text
a document declares owner-rewritable → its contract block is rewritten by a sweep that the file's word allowed
```

After

```text
file default: owner-rewritable → contract block: mutability frozen → the sweep skips the block
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Retention](https://banes-lab.com/records/lexicon/retention.md), [Mutability](https://banes-lab.com/records/lexicon/mutability.md), [Independent Lifetime Axes](https://banes-lab.com/records/architecture/independent-lifetime-axes.md), [Governed Removal](https://banes-lab.com/records/lexicon/governed-removal.md)

Shape it refuses
Not answered

### Write Scope and Read Population

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: run, invocation
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A design rule that a run declares the paths it writes and publishes the set it read as two declarations, because collision is decided by the first and a published result's validity by the second.

Requires
[Write Scope](https://banes-lab.com/records/lexicon/write-scope.md), [Read Population](https://banes-lab.com/records/lexicon/read-population.md)

Reinforces
[Determinism](https://banes-lab.com/records/architecture/determinism.md)

Enables
[Shared Invocation](https://banes-lab.com/records/lexicon/shared-invocation.md)

In tension with
none

Conflicts with
none

Referenced by
[Read-Time Join](https://banes-lab.com/records/architecture/read-time-join.md)

Expressed in the grammar by
[population_clause](https://banes-lab.com/records/pag/production-population-clause.md)

Distinct from
[Determinism](https://banes-lab.com/records/architecture/determinism.md): Write scope and read population separate what a run touches from what it read, while determinism requires that the same inputs produce the same result.

Violated by
declaring one scope and using it both to detect collisions and to decide whether a result answers a later question

Detected by
a run that reads more than it writes and publishes only its write scope

Measured by
runs publishing no read population

Refactored by
Declare the Write Scope, Publish the Read Population

Enforced by
the coordination writer check, which fails a writer a run reaches outside the sanctioned set

Before

```text
a run declares scope: <subtree> → it also reads a sibling tree → a later caller reuses its result for the sibling and gets a verdict nobody measured
```

After

```text
write scope: <subtree> → read population: <subtree> + <sibling> → the collision test reads the first, the coverage test reads the second
```

How it is checked

Checked by
the coordination writer check, which fails a writer a run reaches outside the sanctioned set

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Write Scope](https://banes-lab.com/records/lexicon/write-scope.md), [Read Population](https://banes-lab.com/records/lexicon/read-population.md), [Determinism](https://banes-lab.com/records/architecture/determinism.md), [Shared Invocation](https://banes-lab.com/records/lexicon/shared-invocation.md)

Shape it refuses
Not answered

### Read-Time Join

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: run, invocation
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A mechanism that lets a caller whose question a live declared scope already covers read that run's published result and its standing, writing nothing, so it cannot deadlock, be orphaned or need cleanup.

Requires
[Joiner](https://banes-lab.com/records/lexicon/joiner.md), [Read Population](https://banes-lab.com/records/lexicon/read-population.md)

Reinforces
[Write Scope and Read Population](https://banes-lab.com/records/architecture/write-scope-and-read-population.md)

Enables
[Shared Invocation](https://banes-lab.com/records/lexicon/shared-invocation.md)

In tension with
none

Conflicts with
none

Contracts
[Invocation Join](https://banes-lab.com/records/algorithms/invocation-join.md)

Distinct from
[Joiner](https://banes-lab.com/records/lexicon/joiner.md): A read-time join is the mechanism that serves a covered question from a published result, while a joiner is the caller that uses it.

Violated by
attaching a second caller to a running process, or starting a duplicate run a live scope already covers

Detected by
two runs over one covered question, or a caller waiting on another run's handle

Measured by
duplicate runs a live scope covered

Refactored by
Test Coverage First, Join by Reading the Published Result

Enforced by
coordination review

Before

```text
a second caller starts the same measurement → both write the same report → the second waits on the first's lock
```

After

```text
caller → does a live scope cover the question? yes: read the published result and its standing, write nothing → no: start, and only then enter the collision comparison
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Joiner](https://banes-lab.com/records/lexicon/joiner.md), [Read Population](https://banes-lab.com/records/lexicon/read-population.md), [Write Scope and Read Population](https://banes-lab.com/records/architecture/write-scope-and-read-population.md), [Shared Invocation](https://banes-lab.com/records/lexicon/shared-invocation.md)

Shape it refuses
Not answered

### One-Sided Liveness

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: process, liveness
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A design rule that a process's absence proves it is dead while its presence proves nothing, so liveness is derived once, from the witness first and from a generous window only where the witness cannot decide.

Requires
[Liveness Witness](https://banes-lab.com/records/lexicon/liveness-witness.md)

Reinforces
[Determinism](https://banes-lab.com/records/architecture/determinism.md)

Enables
[Shared Invocation](https://banes-lab.com/records/lexicon/shared-invocation.md)

In tension with
none

Conflicts with
none

Distinct from
[Determinism](https://banes-lab.com/records/architecture/determinism.md): One-sided liveness decides what a process's presence can prove, while determinism requires that the same inputs produce the same result.

Violated by
treating a present process as alive, or computing liveness separately in each consumer

Detected by
two consumers of one liveness question reaching different answers

Measured by
liveness derivations outside the single one

Refactored by
Derive Liveness Once, Witness First, Window Second

Enforced by
coordination review

Before

```text
a process id is present → the claim is kept → the id was reused by an unrelated process and the claim never expires
```

After

```text
id absent: dead → id present: undecided → fall to the window, set long, because too short loses a write and too long costs one re-run
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Liveness Witness](https://banes-lab.com/records/lexicon/liveness-witness.md), [Determinism](https://banes-lab.com/records/architecture/determinism.md), [Shared Invocation](https://banes-lab.com/records/lexicon/shared-invocation.md)

Shape it refuses
Not answered

### Reversible Channel Encoding

- Kind: [constraint](https://banes-lab.com/records/kind/constraint.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: channel, naming
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A rule or precondition that a channel name is a total and invertible encoding of the scope it belongs to, with an alphabet that excludes the separator, so a retention check can read the scope back out of the name.

Requires
[Write Scope](https://banes-lab.com/records/lexicon/write-scope.md)

Reinforces
[Stable Identity](https://banes-lab.com/records/lexicon/stable-identity.md)

Enables
[Governed Removal](https://banes-lab.com/records/lexicon/governed-removal.md)

In tension with
none

Conflicts with
none

Distinct from
[Stable Identity](https://banes-lab.com/records/lexicon/stable-identity.md): A reversible channel encoding lets the owning scope be read back out of a name, while stable identity requires only that the name not change.

Violated by
naming a channel by a digest of its scope, which separates channels but cannot be decoded

Detected by
a channel whose name decodes to no scope

Measured by
channels no remover can attribute to a scope

Refactored by
Encode the Scope Reversibly, Declare the Remover

Enforced by
the coordination channel check, which reports a channel whose decoded scope resolves to nothing

Before

```text
channel = digest(<scope>) → channels never collide → no check can tell which channel is stale
```

After

```text
channel = encode(<scope>), invertible → decode(channel) resolves to nothing → the declared remover deletes it
```

How it is checked

Checked by
the coordination channel check, which reports a channel whose decoded scope resolves to nothing

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Write Scope](https://banes-lab.com/records/lexicon/write-scope.md), [Stable Identity](https://banes-lab.com/records/lexicon/stable-identity.md), [Governed Removal](https://banes-lab.com/records/lexicon/governed-removal.md)

Shape it refuses
Not answered

### Declare-Before-Read Order

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: run, concurrency
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A mechanism that orders two simultaneous starters without a lock by writing each entry before reading the set, with the start stamp and then the party identity breaking a tie.

Requires
[Write Scope](https://banes-lab.com/records/lexicon/write-scope.md)

Reinforces
[Determinism](https://banes-lab.com/records/architecture/determinism.md)

Enables
[Shared Invocation](https://banes-lab.com/records/lexicon/shared-invocation.md)

In tension with
none

Conflicts with
none

Violated by
reading the set of live runs before writing one's own entry, so two starters each see an empty set

Detected by
two runs over one scope that both proceeded

Measured by
simultaneous starters that both proceeded

Refactored by
Write the Entry, Then Read the Set

Enforced by
coordination review

Before

```text
starter A reads: nobody → starter B reads: nobody → both write → both proceed
```

After

```text
A writes its entry → B writes its entry → each reads both → the earlier stamp proceeds, the other exits without writing
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Write Scope](https://banes-lab.com/records/lexicon/write-scope.md), [Determinism](https://banes-lab.com/records/architecture/determinism.md), [Shared Invocation](https://banes-lab.com/records/lexicon/shared-invocation.md)

Shape it refuses
Not answered

### Period-Decided Disposition

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: duplicate, derivation
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A design rule that a duplicate is first counted by its distinguished copies and then read by the period of each derivation edge, so a periodic copy owes a comparator and a one-shot copy is a record whose source is repaired instead.

Requires
[Distinguished Copy](https://banes-lab.com/records/lexicon/distinguished-copy.md), [Derivation Period](https://banes-lab.com/records/lexicon/derivation-period.md)

Reinforces
[Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md)

Enables
[Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

In tension with
none

Conflicts with
[Cyclic Tiebreak](https://banes-lab.com/records/architecture/cyclic-tiebreak.md)

Contracts
[Duplicate Disposition Walk](https://banes-lab.com/records/algorithms/duplicate-disposition-walk.md)

Distinct from
[Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md): Period-decided disposition decides what to do with the copies a fact already has, while a single source of truth is the state it restores.

Violated by
collapsing every copy toward the source without asking whether any edge ever runs again

Detected by
a collapse that removed a copy written once against an earlier state of its source

Measured by
copies collapsed across one-shot edges

Refactored by
Count Distinguished Copies, Read Each Period, Repair the Source

Enforced by
coordination review

Before

```text
a rule stated in code and in several documents → every document copy is rewritten to match → the record of what each surface said when it was written is gone
```

After

```text
one distinguished copy: a direction → every other edge one-shot: diagnose the copies, repair the source → a copy no party reaches: add it
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Distinguished Copy](https://banes-lab.com/records/lexicon/distinguished-copy.md), [Derivation Period](https://banes-lab.com/records/lexicon/derivation-period.md), [Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md), [Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

Shape it refuses
[Cyclic Tiebreak](https://banes-lab.com/records/architecture/cyclic-tiebreak.md)

### Derived Party Count

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: allocation, coordination
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A design rule that the number of parties a body of work implies is derived from how the work is partitioned into concerns, so two parties holding one partition reach one count.

Requires
[Concern Partition](https://banes-lab.com/records/lexicon/concern-partition.md)

Reinforces
[Determinism](https://banes-lab.com/records/architecture/determinism.md)

Enables
[Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

In tension with
none

Conflicts with
none

Referenced by
[Fan-In Ceiling](https://banes-lab.com/records/architecture/fan-in-ceiling.md)

Distinct from
[Determinism](https://banes-lab.com/records/architecture/determinism.md): A derived party count ties allocation to a partition of the work, while determinism requires that the same inputs produce the same result.

Violated by
choosing a party count as a preference and allocating work to fit it

Detected by
a count that moved while no partition moved

Measured by
counts proposed with no partition behind them

Refactored by
Derive the Partition, Count Its Concerns

Enforced by
none: no mechanism derives the partition, so the count rests on review

Before

```text
the work gets a fixed number of parties → surfaces are split to give each one something → contradictions pile up on the shared ones
```

After

```text
coupling relation → connected components → concerns → floor: concerns that must contradict each other → ceiling: the worst fan-in
```

How it is checked

Checked by
none: no mechanism derives the partition, so the count rests on review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Concern Partition](https://banes-lab.com/records/lexicon/concern-partition.md), [Determinism](https://banes-lab.com/records/architecture/determinism.md), [Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

Shape it refuses
Not answered

### Fan-In Ceiling

- Kind: [constraint](https://banes-lab.com/records/kind/constraint.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: allocation, surface
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A rule or precondition that the useful number of parties is bounded by the fan-in of the most contended surface, where claims resting on it go stale faster than they help.

Requires
[Fan-In](https://banes-lab.com/records/lexicon/fan-in.md)

Reinforces
[Derived Party Count](https://banes-lab.com/records/architecture/derived-party-count.md)

Enables
[Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

In tension with
none

Conflicts with
none

Violated by
adding parties who all reason about the same surface

Detected by
a surface whose claims are answered more often than they are used

Measured by
stale claims published per surface

Refactored by
Mark Claims With the Moment Their Surface Was Read, or Partition the Surface

Enforced by
none: no mechanism counts fan-in, so the bound rests on review

Before

```text
more parties join → each composes claims about one shared surface → every stale claim is read and answered by every other party
```

After

```text
fan-in measured from recorded authorship and citations → the surface above the ceiling is split or its claims arrive marked stale
```

How it is checked

Checked by
none: no mechanism counts fan-in, so the bound rests on review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Fan-In](https://banes-lab.com/records/lexicon/fan-in.md), [Derived Party Count](https://banes-lab.com/records/architecture/derived-party-count.md), [Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

Shape it refuses
Not answered

### State-Arity Limit

- Kind: [constraint](https://banes-lab.com/records/kind/constraint.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: check, state
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A rule or precondition that a property relating two states of content, such as growing but never shrinking, is enforced only by a mechanism holding both readings, in the layer that already spans runs.

Requires
[Coordination Surface](https://banes-lab.com/records/lexicon/coordination-surface.md)

Reinforces
[Fitness Functions](https://banes-lab.com/records/architecture/fitness-functions.md)

Enables
[Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

In tension with
none

Conflicts with
none

Violated by
enforcing a rule about how content changes with a check that reads one state, or making a checker remember its prior output

Detected by
content removed from a required section while every single-state check passes

Measured by
change rules held only by single-state checks

Refactored by
Retain the Prior State in the Spanning Layer, Compare the Two Readings

Enforced by
coordination review

Before

```text
a check requires the section → it passes from empty to full and from full to empty alike
```

After

```text
the spanning layer records the section's extent per run → the next run compares → shortened: refuse → the sets differ: not comparable, refuse rather than compute
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Coordination Surface](https://banes-lab.com/records/lexicon/coordination-surface.md), [Fitness Functions](https://banes-lab.com/records/architecture/fitness-functions.md), [Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

Shape it refuses
Not answered

### Carrier and Payload Split

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: surface, field
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A design rule that a surface read through a tool types the fields a mechanism joins on and leaves the fields only a reader consumes as prose, deciding the line per field.

Requires
[Carrier Field](https://banes-lab.com/records/lexicon/carrier-field.md), [Payload Field](https://banes-lab.com/records/lexicon/payload-field.md)

Reinforces
[Closed Vocabulary](https://banes-lab.com/records/architecture/closed-vocabulary.md)

Enables
[Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

In tension with
none

Conflicts with
none

Referenced by
[Joinable Mandated Field](https://banes-lab.com/records/architecture/joinable-mandated-field.md)

Distinct from
[Closed Vocabulary](https://banes-lab.com/records/architecture/closed-vocabulary.md): The carrier and payload split decides which fields are typed at all, while a closed vocabulary governs the words a typed name slot may take.

Violated by
making a mechanism interpret prose to compute a fact, or letting a payload restate a question its carrier already answers

Detected by
a mechanism parsing a prose field, or a carrier and a payload that answer one question differently

Measured by
fields no declaration assigns to either side

Refactored by
Type the Carrier, Leave the Payload Prose, Remove the Restating Payload

Enforced by
none: whether a value is resolvable is a judgement at authoring, so the split rests on review

Before

```text
a status sentence is parsed for the word done → a reader edits the sentence → the parse misreads it
```

After

```text
state: <closed value> as the carrier → reason: <prose> as the payload → the mechanism reads the key and never the sentence
```

How it is checked

Checked by
none: whether a value is resolvable is a judgement at authoring, so the split rests on review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Carrier Field](https://banes-lab.com/records/lexicon/carrier-field.md), [Payload Field](https://banes-lab.com/records/lexicon/payload-field.md), [Closed Vocabulary](https://banes-lab.com/records/architecture/closed-vocabulary.md), [Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

Shape it refuses
Not answered

### Joinable Mandated Field

- Kind: [constraint](https://banes-lab.com/records/kind/constraint.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: field, schema
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A rule or precondition that a mandated field takes a value from a closed set or an identifier, or declares that it is written for readers, so a governed surface never looks measured on a property nothing can read.

Requires
[Carrier Field](https://banes-lab.com/records/lexicon/carrier-field.md)

Reinforces
[Carrier and Payload Split](https://banes-lab.com/records/architecture/carrier-and-payload-split.md)

Enables
[Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

In tension with
none

Conflicts with
none

Violated by
mandating a field as free prose while assuming a consumer will read it

Detected by
a mandated prose field that no declaration marks as written for readers

Measured by
mandated fields in neither a resolvable form nor declared for readers

Refactored by
Draw the Value From a Closed Set, or Declare the Field for Readers

Enforced by
coordination review

Before

```text
every record must carry a lifetime paragraph → each author writes one → nothing can join on it
```

After

```text
lifetime: retention <value>, mutability <value>, removal authority <value> → a check joins on the three values
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Carrier Field](https://banes-lab.com/records/lexicon/carrier-field.md), [Carrier and Payload Split](https://banes-lab.com/records/architecture/carrier-and-payload-split.md), [Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

Shape it refuses
Not answered

### Single Aggregate

- Kind: [constraint](https://banes-lab.com/records/kind/constraint.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: measurement, report
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A rule or precondition that a shared measurement keeps one aggregate, overwritten by each run that can honestly replace it, while a run that cannot streams its verdict instead of writing a second report.

Requires
[Read Population](https://banes-lab.com/records/lexicon/read-population.md)

Reinforces
[Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md)

Enables
[Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

In tension with
none

Conflicts with
[Invocation-Keyed Report](https://banes-lab.com/records/architecture/invocation-keyed-report.md), [Narrowed Aggregate](https://banes-lab.com/records/architecture/narrowed-aggregate.md)

Violated by
writing a report named for the scope or caller of a run beside the aggregate, or overwriting the aggregate from a narrowed run

Detected by
a second report describing the aggregate's subject

Measured by
reports beside the aggregate

Refactored by
Overwrite the Aggregate From Full Runs, Stream Narrowed Verdicts

Enforced by
coordination review

Before

```text
a narrowed run writes report.<scope>.json → the directory fills with reports each true of one moment → none of them is the state
```

After

```text
a full run overwrites the aggregate → a narrowed run prints its verdict and writes nothing
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
[Read Population](https://banes-lab.com/records/lexicon/read-population.md), [Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md), [Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)

Shape it refuses
[Invocation-Keyed Report](https://banes-lab.com/records/architecture/invocation-keyed-report.md), [Narrowed Aggregate](https://banes-lab.com/records/architecture/narrowed-aggregate.md)

### Contradicted Invariant

- Kind: [anti-pattern](https://banes-lab.com/records/kind/anti-pattern.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [discouraged](https://banes-lab.com/records/vocabulary/severity-discouraged.md)
- Scope: topology
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A defect in which one surface states the opposite of an invariant another relies on, so every mechanism faithfully implementing either statement stays green while the invariant is violated.

Requires
none

Reinforces
none

Enables
none

In tension with
none

Conflicts with
none

Referenced by
[Stated Invariant](https://banes-lab.com/records/architecture/stated-invariant.md), [Operand-Free Outcome Surface](https://banes-lab.com/records/architecture/operand-free-outcome-surface.md)

Violated by
restating an invariant in a second surface and changing only one of the copies

Detected by
two statements of one invariant that no single query ranges over

Measured by
invariants whose copies disagree

Refactored by
Treat the Set of Statements as the Unit, Re-Derive Every Copy on Change

Enforced by
coordination review

Before

```text
the model states one writer per record → a template states one writer per file → a tool built from the template rewrites whole files and every check passes
```

After

```text
every copy of the invariant is listed → a change re-derives the set → the most delivered copy is updated first
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
Not answered

Shape it refuses
[Contradicted Invariant](https://banes-lab.com/records/architecture/contradicted-invariant.md)

### Written Status Marker

- Kind: [anti-pattern](https://banes-lab.com/records/kind/anti-pattern.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [discouraged](https://banes-lab.com/records/vocabulary/severity-discouraged.md)
- Scope: record
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A defect in which a party writes a record's state as a marker instead of deriving it from the record's edges, so the marker goes stale and asserts a state that no longer holds.

Requires
none

Reinforces
none

Enables
none

In tension with
none

Conflicts with
none

Referenced by
[Derived Record State](https://banes-lab.com/records/architecture/derived-record-state.md)

Violated by
adding a status field that parties are trusted to keep current

Detected by
a status field whose value the record's edges contradict

Measured by
records carrying a written state

Refactored by
Derive the State From the Edges

Enforced by
coordination review

Before

```text
status: absorbed is written and left in place → the record rests there as a marker
```

After

```text
absorbed is a transition → extract to the accumulator → delete in the same change
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
Not answered

Shape it refuses
[Written Status Marker](https://banes-lab.com/records/architecture/written-status-marker.md)

### Invocation-Keyed Report

- Kind: [anti-pattern](https://banes-lab.com/records/kind/anti-pattern.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [discouraged](https://banes-lab.com/records/vocabulary/severity-discouraged.md)
- Scope: report
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A defect in which a run writes its result under a name derived from how it was invoked, beside the shared aggregate, so documents accumulate that each describe a moment and none the state.

Requires
none

Reinforces
none

Enables
none

In tension with
none

Conflicts with
none

Referenced by
[Single Aggregate](https://banes-lab.com/records/architecture/single-aggregate.md)

Violated by
keying a report's filename on the scope, the caller or the flags of a run

Detected by
a report whose name carries a scope or caller segment

Measured by
keyed reports beside the aggregate

Refactored by
Stream the Narrowed Verdict, Keep One Aggregate

Enforced by
coordination review

Before

```text
report.<member>.json, report.<caller>.json → nobody prunes them → a reader cannot tell which is current
```

After

```text
one aggregate report → narrowed runs print their verdict
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
Not answered

Shape it refuses
[Invocation-Keyed Report](https://banes-lab.com/records/architecture/invocation-keyed-report.md)

### Narrowed Aggregate

- Kind: [anti-pattern](https://banes-lab.com/records/kind/anti-pattern.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [discouraged](https://banes-lab.com/records/vocabulary/severity-discouraged.md)
- Scope: report
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A defect in which a run over a narrowed scope overwrites the whole-scope aggregate, so the aggregate reports a smaller population as though it were the whole.

Requires
none

Reinforces
none

Enables
none

In tension with
none

Conflicts with
none

Referenced by
[Single Aggregate](https://banes-lab.com/records/architecture/single-aggregate.md)

Distinct from
[Invocation-Keyed Report](https://banes-lab.com/records/architecture/invocation-keyed-report.md): A narrowed aggregate overwrites the one aggregate with a partial result, while an invocation-keyed report writes a second document beside it.

Violated by
writing the aggregate from a run that measured part of its population

Detected by
an aggregate whose recorded population is smaller than the declared one

Measured by
aggregate writes from narrowed runs

Refactored by
Write the Aggregate Only From a Full Run

Enforced by
coordination review

Before

```text
a run over one member writes the aggregate → the aggregate now reads clean for the whole tree
```

After

```text
the narrowed run streams its verdict → the aggregate keeps the last full run's result
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
Not answered

Shape it refuses
[Narrowed Aggregate](https://banes-lab.com/records/architecture/narrowed-aggregate.md)

### Cyclic Tiebreak

- Kind: [anti-pattern](https://banes-lab.com/records/kind/anti-pattern.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [discouraged](https://banes-lab.com/records/vocabulary/severity-discouraged.md)
- Scope: duplicate
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A defect in which a tiebreak picks a source among copies none of which is distinguished, turning a correct refusal into a direction no copy supports.

Requires
none

Reinforces
none

Enables
none

In tension with
none

Conflicts with
none

Referenced by
[Period-Decided Disposition](https://banes-lab.com/records/architecture/period-decided-disposition.md)

Violated by
breaking a tie by recency, path order or authorship when no copy derives from another and none is resolved

Detected by
a collapse direction chosen over a set with no distinguished copy

Measured by
collapses directed by a tiebreak

Refactored by
Refuse and Name the Cycle

Enforced by
coordination review

Before

```text
no copy is the source → the newest file wins → every other copy is rewritten toward a value nobody decided
```

After

```text
no distinguished copy → refuse as a cycle → the decision stays with the party who holds the information
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
Not answered

Shape it refuses
[Cyclic Tiebreak](https://banes-lab.com/records/architecture/cyclic-tiebreak.md)

### Destructive Closure

- Kind: [anti-pattern](https://banes-lab.com/records/kind/anti-pattern.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [discouraged](https://banes-lab.com/records/vocabulary/severity-discouraged.md)
- Scope: venue
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A defect in which closing a converged venue deletes it instead of moving it to the archive, keeping the outcome and destroying the argument it came from.

Requires
none

Reinforces
none

Enables
none

In tension with
none

Conflicts with
none

Referenced by
[Independent Lifetime Axes](https://banes-lab.com/records/architecture/independent-lifetime-axes.md)

Violated by
implementing a lifetime stated as deleted by removing the venue from the repository

Detected by
a closed venue that exists in neither the active surface nor the archive

Measured by
venues closed by deletion

Refactored by
Move the Venue to the Archive Once Its Outcome Is Absorbed

Enforced by
coordination review

Before

```text
the venue converges → it is deleted → a later reader holds the ruling and cannot tell it from a preference
```

After

```text
the venue converges → its outcome is absorbed → the venue moves to the archive with every position intact
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
Not answered

Shape it refuses
[Destructive Closure](https://banes-lab.com/records/architecture/destructive-closure.md)

### Hand-Kept Index

- Kind: [anti-pattern](https://banes-lab.com/records/kind/anti-pattern.md)
- Category: [Coordination Surfaces](https://banes-lab.com/ontology/principles/architecture-category-coordination-surfaces.md)
- Severity: [discouraged](https://banes-lab.com/records/vocabulary/severity-discouraged.md)
- Scope: index
- Layer: [Execution Core](https://banes-lab.com/records/layer/execution-core.md)

Details

Definition
A defect in which an index is written by hand beside what it indexes, so it drifts silently because nothing compares the two.

Requires
none

Reinforces
none

Enables
none

In tension with
none

Conflicts with
none

Referenced by
[Two-Direction Index](https://banes-lab.com/records/architecture/two-direction-index.md)

Violated by
adding and removing index entries by hand

Detected by
an index entry with no file, or a file with no entry

Measured by
entries and files missing their counterpart

Refactored by
Generate the Index From the Directory

Enforced by
coordination review

Before

```text
a seat file is added → the index is not edited → the scan resolves fewer seats than it reports
```

After

```text
the index is regenerated from the directory on every run
```

How it is checked

Checked by
coordination review

Population
Every coordination surface, record, run declaration and shared measurement a governed tree carries

Freshness
A verdict stands until a surface's schema, a record's writer or subject, or a run's declared scope changes

Refusal
The coordination rules fail a surface whose records name no writer or subject, a run with no declared write scope, and an index that disagrees with the directory it indexes

Observation
Each surface's records compared against its declared schema, and each run's writes compared against its declared scope

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The declared schema and lifetime of each surface, which every record and every mechanism acting on it conforms to

Depends on
Not answered

Shape it refuses
[Hand-Kept Index](https://banes-lab.com/records/architecture/hand-kept-index.md)

## Links to

- [principle](https://banes-lab.com/records/kind/principle.md)
- [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- [Execution Core](https://banes-lab.com/records/layer/execution-core.md)
- [Coordination Surface](https://banes-lab.com/records/lexicon/coordination-surface.md)
- [Fitness Functions](https://banes-lab.com/records/architecture/fitness-functions.md)
- [Traceable Guarantee](https://banes-lab.com/records/lexicon/traceable-guarantee.md)
- [Contradicted Invariant](https://banes-lab.com/records/architecture/contradicted-invariant.md)
- [Operand-Free Outcome Surface](https://banes-lab.com/records/architecture/operand-free-outcome-surface.md)
- [INVARIANT](https://banes-lab.com/records/pag/keyword-invariant-invariant.md)
- [invariant_record](https://banes-lab.com/records/pag/production-invariant-record.md)
- [invariant_block](https://banes-lab.com/records/pag/production-invariant-block.md)
- [Coordination Record](https://banes-lab.com/records/lexicon/coordination-record.md)
- [Acknowledger](https://banes-lab.com/records/lexicon/acknowledger.md)
- [Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md)
- [Written Status Marker](https://banes-lab.com/records/architecture/written-status-marker.md)
- [constraint](https://banes-lab.com/records/kind/constraint.md)
- [Stable Identity](https://banes-lab.com/records/lexicon/stable-identity.md)
- [Rederivation Detection](https://banes-lab.com/records/lexicon/rederivation-detection.md)
- [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- [Optimistic Locking](https://banes-lab.com/records/architecture/optimistic-locking.md)
- [Single-Writer Coordination](https://banes-lab.com/records/lexicon/single-writer-coordination.md)
- [Lost Update](https://banes-lab.com/records/architecture/lost-update.md)
- [refusal_line](https://banes-lab.com/records/pag/production-refusal-line.md)
- [Outcome Surface](https://banes-lab.com/records/lexicon/outcome-surface.md)
- [Stated Invariant](https://banes-lab.com/records/architecture/stated-invariant.md)
- [Host Projection](https://banes-lab.com/records/lexicon/host-projection.md)
- [Bounded Reader](https://banes-lab.com/records/lexicon/bounded-reader.md)
- [Hand-Kept Index](https://banes-lab.com/records/architecture/hand-kept-index.md)
- [Retention](https://banes-lab.com/records/lexicon/retention.md)
- [Mutability](https://banes-lab.com/records/lexicon/mutability.md)
- [Removal Authority](https://banes-lab.com/records/lexicon/removal-authority.md)
- [Immutability](https://banes-lab.com/records/architecture/immutability.md)
- [Governed Removal](https://banes-lab.com/records/lexicon/governed-removal.md)
- [Destructive Closure](https://banes-lab.com/records/architecture/destructive-closure.md)
- [Section Lifetime Divergence](https://banes-lab.com/records/architecture/section-lifetime-divergence.md)
- [Convergence Walk](https://banes-lab.com/records/algorithms/convergence-walk.md)
- [Lifetime Resolution](https://banes-lab.com/records/algorithms/lifetime-resolution.md)
- [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- [Independent Lifetime Axes](https://banes-lab.com/records/architecture/independent-lifetime-axes.md)
- [Write Scope](https://banes-lab.com/records/lexicon/write-scope.md)
- [Read Population](https://banes-lab.com/records/lexicon/read-population.md)
- [Determinism](https://banes-lab.com/records/architecture/determinism.md)
- [Shared Invocation](https://banes-lab.com/records/lexicon/shared-invocation.md)
- [Read-Time Join](https://banes-lab.com/records/architecture/read-time-join.md)
- [population_clause](https://banes-lab.com/records/pag/production-population-clause.md)
- [Joiner](https://banes-lab.com/records/lexicon/joiner.md)
- [Write Scope and Read Population](https://banes-lab.com/records/architecture/write-scope-and-read-population.md)
- [Invocation Join](https://banes-lab.com/records/algorithms/invocation-join.md)
- [Liveness Witness](https://banes-lab.com/records/lexicon/liveness-witness.md)
- [Distinguished Copy](https://banes-lab.com/records/lexicon/distinguished-copy.md)
- [Derivation Period](https://banes-lab.com/records/lexicon/derivation-period.md)
- [Cyclic Tiebreak](https://banes-lab.com/records/architecture/cyclic-tiebreak.md)
- [Duplicate Disposition Walk](https://banes-lab.com/records/algorithms/duplicate-disposition-walk.md)
- [Concern Partition](https://banes-lab.com/records/lexicon/concern-partition.md)
- [Fan-In Ceiling](https://banes-lab.com/records/architecture/fan-in-ceiling.md)
- [Fan-In](https://banes-lab.com/records/lexicon/fan-in.md)
- [Derived Party Count](https://banes-lab.com/records/architecture/derived-party-count.md)
- [Carrier Field](https://banes-lab.com/records/lexicon/carrier-field.md)
- [Payload Field](https://banes-lab.com/records/lexicon/payload-field.md)
- [Closed Vocabulary](https://banes-lab.com/records/architecture/closed-vocabulary.md)
- [Joinable Mandated Field](https://banes-lab.com/records/architecture/joinable-mandated-field.md)
- [Carrier and Payload Split](https://banes-lab.com/records/architecture/carrier-and-payload-split.md)
- [Invocation-Keyed Report](https://banes-lab.com/records/architecture/invocation-keyed-report.md)
- [Narrowed Aggregate](https://banes-lab.com/records/architecture/narrowed-aggregate.md)
- [anti-pattern](https://banes-lab.com/records/kind/anti-pattern.md)
- [discouraged](https://banes-lab.com/records/vocabulary/severity-discouraged.md)
- [Derived Record State](https://banes-lab.com/records/architecture/derived-record-state.md)
- [Single Aggregate](https://banes-lab.com/records/architecture/single-aggregate.md)
- [Period-Decided Disposition](https://banes-lab.com/records/architecture/period-decided-disposition.md)
- [Two-Direction Index](https://banes-lab.com/records/architecture/two-direction-index.md)

## Linked from

- [The layer topology](https://banes-lab.com/ontology/schema/the-layer-topology.md)
- [The membership](https://banes-lab.com/ontology/schema/the-membership.md)
