# templates/model.template.md

> 97 lines of code and 0 definitions.

Tree: Coordination tree
Language: markdown
Canonical: https://banes-lab.com/anatomy/coordination#file-coordination-templates-model-template-md
Source text: https://banes-lab.com/assets/sources/source.a589ba98daa2c60fa0ff646c7bc3481aa868f37919444543b4a7f03b22e6eb56.generated.txt

## Source

```markdown
<!-- MODEL SURFACE -->

# A venue's CLASS half: what a construct IS, which formulation composes, and what a reader may derive from it.

# Copy to `<subject>.model.md` in the declared models root. The measured half lives in a finding surface and never here.

# Instantiate per project. Nothing raised from this template names a project, a party, a tool or a count.

═══════════════════ LIFETIME (declared, read rather than inferred) ═══════════════════

**THE VALUES ARE DRAWN FROM THE CLOSED SETS THE PARAMETER SURFACE DECLARES AND ARE NOT RESTATED HERE.** A
mechanism RESOLVES the members there; this surface class states what each axis SEPARATES, which is the half no
parameter surface should carry — one member set with two consumers rather than one set stated twice.

**The file default:** retention `current-truth` — a class statement is corrected in place and states what is
true now. Mutability `owner-rewritable` — any party may write it, announced before the edit lands, because a
model is an OUTCOME surface authored jointly rather than a set of per-party claims. Removal authority `author`
— each author cuts its own words on a collision.

| section                                    | axis       | value    | why                                                                                               |
| ------------------------------------------ | ---------- | -------- | ------------------------------------------------------------------------------------------------- |
| this LIFETIME block and the CONTRACT block | mutability | `frozen` | written from the template and never edited in a live surface — a correction lands in the template |

**ONE WRITER PER RECORD HAS NO OPERAND HERE, AND THAT IS DECLARED RATHER THAN ASSUMED.** A coordination
surface carries per-party CLAIMS, so a record is the unit and a fence implements the invariant. A model
carries ONE PRODUCT, authored jointly, with no per-party unit for the invariant to range over — so the
invariant does not hold weakly or partially, it has **no operand**, which is a third state distinct from held
and violated. An invariant silently assumed to cover a surface it has no operand on reads as held, and every
derivation above it inherits a guarantee that was never available.

**RECORD STRUCTURE IS REFUSED HERE RATHER THAN MERELY UNNECESSARY.** Partitioning a class statement into
per-party spans makes it read as several parties' opinions where its whole value is that it reads as one
statement — and it would not buy what a fence buys anyway, because the collision on this surface is between
MEANINGS. **The instrument that reaches it is the announcement plus each author cutting its OWN duplicate**,
which is a different mechanism, and naming it here is what stops a later reader proposing the fence.

═══════════════════ CONTRACT (permanent) ═══════════════════

## What may enter, and what may not

**A MODEL SHIPS CLASSES AND NEVER INSTANCES.** Its catalog carries SHAPES — a mechanism with no effect, a
green reading over a set that excluded its own subject, a hand-kept index drifting, a search used as a proxy
for a graph, a finding with no destination. It never carries which file, which party, or how many, or the next
adopter inherits another project's incidents as laws.

**THE CONSTRUCTS SEPARATE, AND CONFLATING THEM IS WHAT MAKES A ROW LOOK HOMELESS:**

| construct     | is                                                                             | is not                                                                                           |
| ------------- | ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ |
| an invariant  | a property the topology RELIES ON, whose loss invalidates derivations above it | a measurement, since nothing records it firing                                                   |
| a class       | the shape of a defect, transferable to a tree with nothing else in common      | a property of one topology, which is what an invariant is                                        |
| a measurement | a reading taken at one coordinate, with its evidence, range and consumer       | a law, and one copied into a template makes the next adopter inherit another project's incidents |

**So an invariant lands in neither surface unaltered and in both once split.** Its CLASS belongs here; its ROW
— this topology's own instance, with what watches it, over which members, for which consumer — belongs in the
finding surface. **The invariant itself is neither.**

## Stating an invariant

**AN INVARIANT A TOPOLOGY RELIES ON WITHOUT STATING IS INDISTINGUISHABLE FROM A PROPERTY A READER HAPPENED TO
INFER**, so every guarantee derived from it is only as sound as an assumption nobody wrote down.

**THE TEST IS NOT WHETHER THE INVARIANT IS TRUE — IT IS WHETHER ANYTHING WOULD DISAGREE IF IT STOPPED BEING.**
A property holding today with no dissenting mechanism is held by circumstance: nothing observes its loss, the
first violation is silent, and the guarantee above it keeps reading as sound. **So an invariant is stated with
the thing that would object, or it is stated as unheld and the derivations resting on it are marked with it.**

**AND IT IS STATED IN A SURFACE THE PARTIES BOUND BY IT RECEIVE.** An invariant delivered to nobody is a
capability nothing consumes — and **a mechanism that must honor one is the hardest consumer to remember,
because it is the only one that cannot ask.**

**THE SLOTS, AND OMITTING ANY ONE LEAVES IT UNSTATED:** the PROPERTY in a form that could be false, since
a statement nothing could contradict states nothing; the SET it quantifies over, since a property established
at one node and asserted for the whole structure is a verdict beyond its range; and the PARTIES it binds,
because an invariant constrains actors rather than describing a shape, and the parties decide where it must be
delivered.

**WHAT A READER MAY NOT DERIVE FROM A STATED ONE:** that it is ENFORCED. A statement is a claim about the
topology; a check is a mechanism over artifacts. **Half-held is the common case and the one a bare statement
cannot express** — a property observed on one axis and assumed on another reads as whole, and the axis nobody
watches is where the first violation lands.

## The contradicted invariant, which no check can see

**WHERE THE TOPOLOGY STATES THE OPPOSITE SOMEWHERE ELSE, EVERY MECHANISM STAYS GREEN WHILE THE INVARIANT IS
VIOLATED.** A mechanism implementing the contradictory statement faithfully satisfies every ordering its own
path checks, so nothing reports a defect: the contradiction is between two STATEMENTS, and no query ranges
over both. **So a statement is not the unit of the check — the SET of statements is**, and adding a statement
adds an obligation to re-derive that set whenever the invariant changes, ordered by how often each copy is
delivered rather than by which file is easiest to reason about.

## The elements every model declares

**SCHEMA ALONE TRANSFERS THE SHAPE AND NOT THE GUARANTEE** — a stated rule with no gate reads as governance
while each party privately concludes the backlog is their own indiscipline.

| element      | states                                                               |
| ------------ | -------------------------------------------------------------------- |
| SCHEMA       | the fields and their types                                           |
| LIFETIME     | when each field is written, and what deletes it                      |
| FAILURE MODE | what goes wrong when it is not obeyed, and how that failure presents |
| GATE         | the check that observes it, or `none` as declared debt               |

## The form of a statement

**A CLAUSE STATES THE SHAPE AND THE PARAMETER SURFACE HOLDS THE MEMBERS.** A vocabulary restated here is a
second copy with nothing keeping the two equal, and the copy nobody re-reads is the one a reader takes. Where
a set is closed, this surface states what its values SEPARATE and the declaration states what they ARE.

**A MANDATED FIELD ACQUIRES A MECHANISM ONLY IN A FORM A MECHANISM CAN JOIN ON.** A value drawn from a closed
set or an identifier can acquire a consumer at any time; free prose cannot, ever, without changing form. Both
read as governed, so the distinction is invisible from the schema and decisive for everything downstream —
**a field is therefore mandated in a resolvable form, or it is declared to be for readers.**

**A COUNT IS NEVER WRITTEN.** A model that states how many rules, parties, surfaces or members exist has
copied a fact something else derives, and it is wrong from the first change nobody propagated while reading as
current.

## Gate

- A statement naming a project, a party, a tool, a file or a count fails: those are instance content.
- An invariant stated without its property, its set and its parties is unstated and fails as such.
- An invariant stated with no objector fails unless it declares itself unheld and marks what rests on it.
- Every declared element — SCHEMA, LIFETIME, FAILURE MODE, GATE — is present; `none` is a real GATE value
  stating declared debt, while an absent one makes an oversight indistinguishable from an assessed decision.

═══════════════════ MODEL ═══════════════════

**A surface raised from this template carries no class statement until its subject is understood.** The
section is born present and empty, which is distinguishable from a populated one — an ABSENT section states
nothing, and that is what makes an oversight read exactly like a decision.
```
