# models/substrate.model.md

> 259 lines of code and 0 definitions.

Tree: Coordination tree
Language: markdown
Layer: domain
Canonical: https://banes-lab.com/anatomy/coordination#file-coordination-models-substrate-model-md
Source text: https://banes-lab.com/assets/sources/source.d3840044acd903b94f6450ea38cb09d9864cd3415ac4782a622ea47f60e5f411.generated.txt

## Source

```markdown
<!-- MODEL SURFACE -->

# The CLASS half of a SUBSTRATE read through a tool: where the line between data and document falls, and what each side owes.

# Raised from `templates/model.template.md`. The measured half lives in a finding surface and never here.

# Nothing here names a project, a party, a tool, a file or a count.

═══════════════════ LIFETIME (declared, read rather than inferred) ═══════════════════

**THE VALUES ARE DRAWN FROM THE CLOSED SETS THE PARAMETER SURFACE DECLARES AND ARE NOT RESTATED HERE.** A
mechanism RESOLVES the members there; this surface class states what each axis SEPARATES, which is the half no
parameter surface should carry — one member set with two consumers rather than one set stated twice.

**The file default:** retention `current-truth` — a class statement is corrected in place and states what is
true now. Mutability `owner-rewritable` — any party may write it, announced before the edit lands, because a
model is an OUTCOME surface authored jointly rather than a set of per-party claims. Removal authority `author`
— each author cuts its own words on a collision.

| section                                    | axis       | value    | why                                                                                               |
| ------------------------------------------ | ---------- | -------- | ------------------------------------------------------------------------------------------------- |
| this LIFETIME block and the CONTRACT block | mutability | `frozen` | written from the template and never edited in a live surface — a correction lands in the template |

**ONE WRITER PER RECORD HAS NO OPERAND HERE, AND THAT IS DECLARED RATHER THAN ASSUMED.** A coordination
surface carries per-party CLAIMS, so a record is the unit and a fence implements the invariant. A model
carries ONE PRODUCT, authored jointly, with no per-party unit for the invariant to range over — so the
invariant does not hold weakly or partially, it has **no operand**, which is a third state distinct from held
and violated. An invariant silently assumed to cover a surface it has no operand on reads as held, and every
derivation above it inherits a guarantee that was never available.

**RECORD STRUCTURE IS REFUSED HERE RATHER THAN MERELY UNNECESSARY.** Partitioning a class statement into
per-party spans makes it read as several parties' opinions where its whole value is that it reads as one
statement — and it would not buy what a fence buys anyway, because the collision on this surface is between
MEANINGS. **The instrument that reaches it is the announcement plus each author cutting its OWN duplicate**,
which is a different mechanism, and naming it here is what stops a later reader proposing the fence.

═══════════════════ CONTRACT (permanent) ═══════════════════

## What may enter, and what may not

**A MODEL SHIPS CLASSES AND NEVER INSTANCES.** Its catalog carries SHAPES — a mechanism with no effect, a
green reading over a set that excluded its own subject, a hand-kept index drifting, a search used as a proxy
for a graph, a finding with no destination. It never carries which file, which party, or how many, or the next
adopter inherits another project's incidents as laws.

**THE THREE CONSTRUCTS SEPARATE, AND CONFLATING THEM IS WHAT MAKES A ROW LOOK HOMELESS:**

| construct     | is                                                                             | is not                                                                                           |
| ------------- | ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ |
| an invariant  | a property the topology RELIES ON, whose loss invalidates derivations above it | a measurement, since nothing records it firing                                                   |
| a class       | the shape of a defect, transferable to a tree with nothing else in common      | a property of one topology, which is what an invariant is                                        |
| a measurement | a reading taken at one coordinate, with its evidence, range and consumer       | a law, and one copied into a template makes the next adopter inherit another project's incidents |

**So an invariant lands in neither surface unaltered and in both once split.** Its CLASS belongs here; its ROW
— this topology's own instance, with what watches it, over which members, for which consumer — belongs in the
finding surface. **The invariant itself is neither.**

## Stating an invariant

**AN INVARIANT A TOPOLOGY RELIES ON WITHOUT STATING IS INDISTINGUISHABLE FROM A PROPERTY A READER HAPPENED TO
INFER**, so every guarantee derived from it is only as sound as an assumption nobody wrote down.

**THE TEST IS NOT WHETHER THE INVARIANT IS TRUE — IT IS WHETHER ANYTHING WOULD DISAGREE IF IT STOPPED BEING.**
A property holding today with no dissenting mechanism is held by circumstance: nothing observes its loss, the
first violation is silent, and the guarantee above it keeps reading as sound. **So an invariant is stated with
the thing that would object, or it is stated as unheld and the derivations resting on it are marked with it.**

**AND IT IS STATED IN A SURFACE THE PARTIES BOUND BY IT RECEIVE.** An invariant delivered to nobody is a
capability nothing consumes — and **a mechanism that must honor one is the hardest consumer to remember,
because it is the only one that cannot ask.**

**THE THREE SLOTS, AND OMITTING ANY ONE LEAVES IT UNSTATED:** the PROPERTY in a form that could be false, since
a statement nothing could contradict states nothing; the SET it quantifies over, since a property established
at one node and asserted for the whole structure is a verdict beyond its range; and the PARTIES it binds,
because an invariant constrains actors rather than describing a shape, and the parties decide where it must be
delivered.

**WHAT A READER MAY NOT DERIVE FROM A STATED ONE:** that it is ENFORCED. A statement is a claim about the
topology; a check is a mechanism over artifacts. **Half-held is the common case and the one a bare statement
cannot express** — a property observed on one axis and assumed on another reads as whole, and the axis nobody
watches is where the first violation lands.

## The contradicted invariant, which no check can see

**WHERE THE TOPOLOGY STATES THE OPPOSITE SOMEWHERE ELSE, EVERY MECHANISM STAYS GREEN WHILE THE INVARIANT IS
VIOLATED.** A mechanism implementing the contradictory statement faithfully satisfies every ordering its own
path checks, so nothing reports a defect: the contradiction is between two STATEMENTS, and no query ranges
over both. **So a statement is not the unit of the check — the SET of statements is**, and adding a statement
adds an obligation to re-derive that set whenever the invariant changes, ordered by how often each copy is
delivered rather than by which file is easiest to reason about.

## The four elements every model declares

**SCHEMA ALONE TRANSFERS THE SHAPE AND NOT THE GUARANTEE** — a stated rule with no gate reads as governance
while each party privately concludes the backlog is their own indiscipline.

| element      | states                                                               |
| ------------ | -------------------------------------------------------------------- |
| SCHEMA       | the fields and their types                                           |
| LIFETIME     | when each field is written, and what deletes it                      |
| FAILURE MODE | what goes wrong when it is not obeyed, and how that failure presents |
| GATE         | the check that observes it, or `none` as declared debt               |

## The form of a statement

**A CLAUSE STATES THE SHAPE AND THE PARAMETER SURFACE HOLDS THE MEMBERS.** A vocabulary restated here is a
second copy with nothing keeping the two equal, and the copy nobody re-reads is the one a reader takes. Where
a set is closed, this surface states what its values SEPARATE and the declaration states what they ARE.

**A MANDATED FIELD ACQUIRES A MECHANISM ONLY IN A FORM A MECHANISM CAN JOIN ON.** A value drawn from a closed
set or an identifier can acquire a consumer at any time; free prose cannot, ever, without changing form. Both
read as governed, so the distinction is invisible from the schema and decisive for everything downstream —
**a field is therefore mandated in a resolvable form, or it is declared to be for readers.**

**A COUNT IS NEVER WRITTEN.** A model that states how many rules, parties, surfaces or members exist has
copied a fact something else derives, and it is wrong from the first change nobody propagated while reading as
current.

## Gate

- A statement naming a project, a party, a tool, a file or a count fails: those are instance content.
- An invariant stated without its property, its set and its parties is unstated and fails as such.
- An invariant stated with no objector fails unless it declares itself unheld and marks what rests on it.
- Every declared element — SCHEMA, LIFETIME, FAILURE MODE, GATE — is present; `none` is a real GATE value
  stating declared debt, while an absent one makes an oversight indistinguishable from an assessed decision.

═══════════════════ MODEL ═══════════════════

## The split is the answer rather than either side of it

**A SURFACE READ THROUGH A TOOL IS BOTH DATA AND DOCUMENT IN ONE FILE, AND THE LINE BETWEEN THEM IS
DECIDABLE.** It carries a CARRIER — fields whose consumers are mechanisms and whose values are drawn from
closed sets or are identifiers — and a PAYLOAD, whose only consumer is a reader and which no parser reaches
without a heuristic. So the substrate question resolves as a SPLIT rather than a choice between two whole-file
answers: **type the carrier, leave the payload prose.**

**AND THE LINE IS PER-FIELD RATHER THAN PER-SURFACE OR PER-FORMAT.** A structured file may hold a field whose
value is prose, and a prose file may hold a field a parser resolves — so a verdict taken at the file reads as
coverage over slots it never examined. **The discriminator is whether a MECHANISM JOINS on the value**, never
where the value lives or what the file's extension says.

**A KEY AND ITS VALUE MAY FALL ON OPPOSITE SIDES, AND THAT IS THE CORRECT FORM RATHER THAN A DEFECT.** Where
presence under a key is the machine-readable claim and the value is the reason a reader needs, the mechanism
consumes the key and never parses the sentence.

**AND A SECOND FAILURE MODE SITS BESIDE THE NAMED ONE, WHICH IS WHERE A SPLIT SURFACE ACTUALLY BREAKS.** The
named one is a mechanism that must INTERPRET the payload to compute the carrier — the case the split exists to
forbid. The other is a carrier and a payload that ANSWER THE SAME QUESTION DIFFERENTLY, and it is invisible to
every mechanism precisely because nothing needs to interpret anything: the consumer resolves the carrier and is
correct, while the reader takes the payload, because prose is what a reader consumes. **The checkable field is
the one that was right, so no check can reach the false one.**

**IT IS A CLASS RATHER THAN AN INVARIANT, BECAUSE NOTHING WOULD OBJECT IF IT STOPPED HOLDING.** Deciding which
token in a payload makes a claim about the question its carrier already answers needs a phrase list or an
inference, and a gate whose population is defined by a phrase list is refused — so the property is stated as
UNHELD, and every derivation resting on a split surface's halves agreeing rests on an assumption. **The
available repair is authoring rather than enforcement: a payload restating what a carrier declares is removed
rather than reconciled**, since a field answering a question another field already answers is the duplication
the split exists to end.

## The obligations a typed fact carries, in order

**TYPING A FACT DISCHARGES THE FIRST OBLIGATION AND CREATES THE ONES AFTER IT.** Each is a distinct failure with a
distinct repair, and a surface satisfying one while omitting another reads as governed from the side that was
satisfied.

| obligation       | discharged by                                                | failure when omitted                                                        |
| ---------------- | ------------------------------------------------------------ | --------------------------------------------------------------------------- |
| TYPE the carrier | a declaration with a closed vocabulary and a refusing reader | a fact nothing can resolve, carried in a form no mechanism reaches          |
| GATE the join    | a consumer checkable against the record's declared field set | a declaration read wrongly, reporting confidently, invisible from both ends |
| DELIVER the fact | a channel that arrives at the moment a party acts            | a correct derived fact computable throughout and reaching nobody            |

**TYPING RELOCATES A DEFECT RATHER THAN REMOVING IT, AND THAT IS THE ARGUMENT FOR IT.** In prose a fact and
its consumer are one object, so a misreading IS the defect and lives where no mechanism can reach. Typed, they
are two objects, and every misreading becomes a MIS-JOIN — which is not a smaller class, but one that lives in
code, and code is the substrate a gate can range over.

**AND THE THIRD OBLIGATION IS THE ONE NEITHER SIDE OF THE ORIGINAL QUESTION CARRIED.** A declaration nothing
reads is inert; a join reading the wrong fields is worse than inert; and a correct derived fact nobody is
handed is a third failure, distinct from both, whose repair is neither a type nor a check but a channel.

## The invariants this topology relies on

### A declared lifetime is READ, never inferred from a path

**PROPERTY** — every decision a mechanism takes about what it may do to a surface resolves from that surface's
DECLARED lifetime, and never from the shape of its path or the spelling of its name. **SET** — every mechanism
that scans, rewrites, skips, removes or anchors a finding on any governed surface. **PARTIES** — every author
of such a mechanism, at the moment the operand is chosen. **OBJECTOR** — a check comparing each mechanism's
resolved operand against the declaration, which fails a mechanism deciding from a path.

**RETENTION, MUTABILITY AND REMOVAL AUTHORITY ARE INDEPENDENT AXES AND NONE IS DERIVABLE FROM THE OTHERS.** A
predicate answering a question about one axis from the values of the others is performing a derivation the
vocabulary declares unavailable — and where the proxies happen to agree it is correct by luck, so its
population of wrong answers is exactly the set where they diverge. **A one-word summary of a lifetime collapses
to the weakest axis and drops the rest silently**, which is how a never-remove ruling loses its operand.

**Path shape may DISCOVER which surfaces are of a kind; it may never DECIDE what their contents are.**

### A finding's locus is consumed as its repair target

**PROPERTY** — the locus a finding reports is a location a party can act on. **SET** — every finding emitted
against any governed surface. **PARTIES** — every mechanism that emits a finding, and every party that acts on
one. **OBJECTOR** — a walk resolving each emitted locus against the surface's declared lifetime, which fails a
line-locus on a surface that only grows.

**THE DECLARED LIFETIME DECIDES WHETHER THE PROPERTY HOLDS, AND EACH LIFETIME BREAKS IT DIFFERENTLY.** On an
APPEND-ONLY surface a line decays as the surface grows, so the locus is exact when written and wrong when read
— repaired by anchoring to the enclosing addressable span. On a GENERATED surface the locus is exact and
UNREPAIRABLE, which is worse than a refusal because an edit there lands and the next regeneration discards it.
On an IMMUTABLE surface the repair belongs to nobody, and a finding that cannot be drained trains every reader
to discount the color, with the cost landing on the findings beside it.

**AND ONE FORM IS INVISIBLE TO ANY PREDICATE READING THE SURFACE: A PERMANENT SPAN INSIDE A MUTABLE ONE.**
Where a surface ACCUMULATES it accepts a write, so the repair is reachable by appending — and the span the
locus names is permanent by that same lifetime, so the finding still stands whatever anybody appends. The
repair being reachable and the finding being clearable are different properties, and only the SPAN's mutability
separates them: the surface's own answer is the wrong operand, and a check asking it reports a repairable
target over an unclearable finding. The objector reads the anchored span rather than the file — the same anchor
the first form repairs to — and fails a finding whose locus resolves to an item key on a surface whose declared
retention accumulates.

### One aggregate, overwritten, or no aggregate at all

**PROPERTY** — after any run, the single aggregate is the truth, and no second document describing the same
subject exists under a name derived from how a run was invoked. **SET** — every run of every shared
measurement. **PARTIES** — every party that invokes one. **OBJECTOR** — a check failing a write of a
scope-keyed, caller-keyed or invocation-keyed report beside the aggregate.

**A RUN THAT CANNOT HONESTLY REPLACE THE AGGREGATE STREAMS RATHER THAN WRITING ANYWHERE.** Not over it,
because a label describes a document and does not preserve the one it replaced, so the state guarantee is not
weakened but unavailable. Not beside it, because a keyed name produces a set of documents each true of a
moment and none of them the state, which nobody prunes and no reader can reconstruct. **Streaming costs the
caller nothing it does not already have**, since the verdict is in front of the party that asked for it.

### A narrowed measurement divides into classes rather than behaving uniformly

**PROPERTY** — every scoped mechanism declares which of the three it is, and a narrowed run acts on that
declaration rather than running every mechanism against a reduced scope. **SET** — every mechanism a scoped
run may invoke. **PARTIES** — the author of each mechanism, and every party invoking one narrowly. **OBJECTOR**
— a check failing a mechanism that declares no class while drawing subjects and evidence from different
sources.

**THE CLASSES SEPARATE ON WHERE SUBJECTS AND EVIDENCE COME FROM, WHICH IS A PROPERTY OF THE MECHANISM'S OWN
INPUTS.** A mechanism whose SUBJECTS arrive through a declared read and whose EVIDENCE arrives through the
scanned set is NOT NARROWABLE: narrowing preserves every subject and destroys the evidence that would clear
each one, so its narrowed verdict is FALSE while reading as a measurement. A mechanism declaring BOTH halves is
SCOPE-INVARIANT: its findings are true and out of jurisdiction. A mechanism that MUTATES from a root-derived
set is skipped on a third ground — skipping protects artifacts the scope never bounded, and honest findings do
not make a removal in-scope.

**AND THE FEATURE THAT MAKES A MECHANISM SCOPE-PROOF IS THE FEATURE THAT MAKES THE FIRST CLASS POSSIBLE.**
Restoring a mechanism's declared operands under any scope is correct and is why such a mechanism runs at all;
applied to its SUBJECTS alone it guarantees a full population judged against an emptied evidence set.

### A guard about who can still act resolves an OBSERVATION, never a declaration of membership

**PROPERTY** — a mechanism deciding whether a party can still respond resolves that from an observation of
that party's own recent activity, and resolves a declaration only where its question is about MEMBERSHIP.
**SET** — every guard whose trigger or threshold is drawn from a roster of declared parties. **PARTIES** —
the author of each such guard, at the moment the operand is chosen. **OBJECTOR** — a check failing a
mutation guard whose operand resolves to a membership reader, and a roster derived from parties that are
either held or recently observed.

**MEMBERSHIP AND LIVENESS ARE DIFFERENT QUESTIONS AND A ROSTER ANSWERS ONLY THE FIRST.** A party is recorded
and rowed whether or not it is running, so a guard reading that record sets its bound from a fact that
cannot answer it — and the guard then FIRES CORRECTLY AND FIRES ONE PARTY TOO LATE, which is why testing
whether it ever fires cannot detect it. **The operand is the subject of the test, never the comparison.**

**AND THE TWO SIGNALS ARE UNIONED RATHER THAN RANKED**, because a party that is held stops producing
activity precisely while it is held: recency alone shrinks the set underneath the parties being counted, so
the bound moves against a denominator falling for the wrong reason.

### A derived subject set is safe only where its empty case means NO CONSTRAINT

**PROPERTY** — a set derived rather than declared is substituted only into a consumer that reads an empty
set as no constraint, and never into one that reads it as every constraint satisfied. **SET** — every
consumer of a derived party set. **PARTIES** — the author of the derivation, and the author of every
consumer it is substituted into. **OBJECTOR** — a refusal at any edge computed as a filter over that set,
which fails an empty subject set rather than holding over it.

**ONE OPERAND MAY FEED TWO CONSUMERS WITH OPPOSITE READINGS OF EMPTINESS, AND THAT IS INVISIBLE FROM THE
OPERAND.** A guard stands down when its set is empty, which is safe. A set of edges computed as filters all
HOLD when the filtered result is empty, which is a universal pass over a population that was never examined.
**So a single repair at the derivation moves a deadlock out of one consumer and puts a silent unanimous
agreement into the other** — and the direction is a property of each consumer's own code rather than a
judgement about which cost is worse.

**WHICH MAKES THE JOIN A DIAGNOSIS AND NOT A REPAIR.** Recognizing that two consumers share an operand is
correct and says nothing about whether they may share its derivation; the empty case is the question that
decides, and it is answered by reading each consumer rather than by reasoning about the operand.

### A verdict carries a STANDING beside its value, and a measurement's own writes are not contention

**PROPERTY** — a verdict whose read set moved beneath it loses its standing to be quoted and keeps its value,
and the moves a measurement made ITSELF are reported apart from the moves anybody else made. **SET** — every
shared measurement over a surface other parties may write. **PARTIES** — every party that takes one, and every
party that quotes one. **OBJECTOR** — the measurement naming its moved read set and separating its own written
paths from it, which fails to withdraw a standing no concurrent write damaged.

**WITHDRAWING THE VALUE IS THE WRONG REPAIR AND WITHDRAWING NOTHING IS THE OTHER ONE.** Declaring a moved
verdict a failure asserts a defect nothing observed; leaving it unmarked hands a reader a description of an
interleaving in the shape of a description of a state. What a concurrent write actually damages is the claim
to describe ONE MOMENT, so that is the property withdrawn, and the value stands untouched.

**AND A MEASUREMENT THAT REPAIRS WHILE IT READS MOVES ITS OWN OPERANDS, WHICH THE SAME COMPARISON CANNOT TELL
FROM A PEER'S WRITE.** Counting them together inverts the mechanism: the more a measurement repairs, the less
its verdict may be believed, so the parties doing the most work publish the least usable result. The two sets
are named APART rather than one being subtracted, because a surface a measurement repaired AND a peer also
wrote is indistinguishable from one only the measurement repaired — after the write the stamp is the
measurement's either way, and stating that residue is what keeps the separation honest.

**THE EXCLUSIVE BARRIER IS DECLINED HERE RATHER THAN OVERLOOKED.** A barrier exists for exclusive WRITES;
holding one across a READ serializes every measurement against every write, makes measuring a contention point,
and blocks live parties to settle a question about the past. The standing is a distinction the result already
carries, which is the same move as replaying a commuting write instead of queueing every one of them.

## The elements, as this topology instantiates them

| element      | states                                                                                                                                                                                                                                                                                                                                                                                                            |
| ------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| SCHEMA       | a governed surface declares, per field, whether its value is CARRIER — closed vocabulary or identifier — or PAYLOAD; and every mechanism declares the surfaces it reads and the narrowing class it belongs to                                                                                                                                                                                                     |
| LIFETIME     | a carrier field is written when its fact changes and removed when its subject leaves; a payload field is written by its author and retired by that author; a declared lifetime is authored once per surface and read on every mechanism's every decision                                                                                                                                                          |
| FAILURE MODE | a fact nothing resolves reads as governed; a join over the wrong fields reports confidently and is invisible from both ends; a derived fact nobody is handed reaches nobody while being computable throughout; a locus a party cannot act on trains readers to discount every finding beside it; a keyed second report accumulates documents no reader can reconstruct                                            |
| GATE         | `none` for the carrier/payload declaration and for the delivery obligation, as declared debt — the first because whether a value is genuinely resolvable is a property of every future consumer rather than of the field, and the second because whether a party RECEIVED a fact is an act no artifact records; the narrowing class, the lifetime operand and the locus anchor each carry an objector named above |

## What this model does not settle

**WHETHER A GIVEN VALUE IS RESOLVABLE IS A JUDGEMENT AT THE MOMENT OF AUTHORING**, and no mechanism decides
it: a closed vocabulary and an identifier are recognisable, and the boundary case — a value that could be made
resolvable by changing its form — is exactly where an author is choosing rather than reporting. **The model
states which side each form falls on and refuses to state which side a particular value belongs to.**

**AND THE DELIVERY OBLIGATION HAS NO ARTIFACT.** Whether a party received a fact is an act inside a turn, so
the gate value is `none` and the property is stated as unheld: every derivation resting on a party having been
told is resting on an assumption, and the repair available is to make the channel ARRIVE rather than to check
that it did.
```
