The external signal: custody, judgement, and the seam that keeps the mechanism exportable
Accepted
Context
Publications, talks, tool releases and other projects' decisions arrive continuously, and each one raises the same four questions: what does it have to do with this project, where does the project sit relative to it, does anything have to change, and does anything have to be said. Those questions have been answered here seven times, entirely by hand, and the answers landed in six different places with no record that the reading ever happened.
MEASURED 2026-08-05 — the seven, and where each one went:
Faros · Acceleration Whiplash -> spine.ncl evidence_hooks + campaign + narrative ES/EN Talisman · Context is a property -> evidence_hooks + the-context-you-declare.{es,}.md Böckeler/Fowler · Harness eng. -> evidence_hooks + glossary/lexicon vocabulary adoption + pi.dev, replit judged (not competitors; pi = carrier) + an implementable remainder that became .coder/2026-07-21-verify-state-harness-design.plan.md HOPE / Nested Learning -> narratives/external-cms-amnesiac-scholar.md + proofs/proof-amnesiac-scholar.ncl Keystone (tacoda.dev) -> positioning/competitors/keystone-harness.ncl MAAD seven sins -> narrative + campaign — and it is NOT external: it is an idea posed in session, with no artefact to point at Datomic · XTDB · TerminusDB · Neo4j-> buried in ADR-023 alternatives_considered[].why_rejected
Four defects follow from doing this by hand, and each one is visible in the list above.
1. NO RECORD OF THE READING. A reading whose verdict is "this does not touch us" produces nothing, so the judgement is paid again the next time the same work circulates. Only the readings that generated an artefact left a trace; the ones that did not are gone. This is the amnesiac-scholar problem the project already publishes about, applied to its own intake.
2. THE JUDGEMENT IS NOT QUERYABLE. ADR-023 assessed four knowledge-graph databases and concluded that bitemporality "covers a subset of the substrate's properties but not multi-actor signed operations or external attestation". That is a competitor analysis of record, and it cannot be reached by any query: it lives inside a prose field of one ADR. The inverse edge — which external signal provoked a decision — does not exist at all.
3. THE EVIDENCE IS RENTED. The sources are Medium and Substack posts, gated PDFs, and pages that could not be fetched at all, whose content entered through the session as pasted text. `evidence_hooks[].source` records a URL and nothing else. A live public claim resting on a URL is a claim that expires when someone else's hosting decision expires. The single counter-example proves the rule is known and unapplied: outreach/presentations/refs/ holds the Faros PDF, its SHA-256, and literal quotes with section locators, under a declared rule — "una cifra que no esté en esta tabla no se dice en la sala". It is scoped to one talk, it is prose, and no mechanism reads it.
4. THE CUSTODY THAT EXISTS SITS ON THE WRONG SIDE OF A BOUNDARY. That refs/ directory lives in outreach/ — a Primary declared public with a GitHub mirror. Measured 2026-08-05, and the measurement corrects an earlier reading of this same defect: the artefacts are NOT tracked (`git status` reports `?? presentations/refs/`), so nothing has been replicated anywhere. They are also NOT ignored. A gated third-party report is therefore one `git add -A` away from a public host, and no declaration anywhere stands between the two. The defect is not that it happened; it is that nothing would refuse it, and that the file's visibility is decided by which repo the talk that needed it happened to be written in.
And a fifth defect that is about exportability rather than about the readings. The obvious fix — a mode that reads a publication and produces a post — would encode ontoref's doors, hooks, narratives and hero images into the mechanism itself, making it useless to every other ontoref-governed project. The parts are not equally general: recognising that a signal is a rival, a canon, or a gap in what the project has built is universal; turning that recognition into a bilingual narrative behind the `developer` door is opinionated, local, and correctly so.
Decision
An encounter with an external signal is split into THREE artefacts with three different owners, three different visibilities, and one direction of reference.
CUSTODY refs/<source-id>/ what arrived, byte for byte JUDGEMENT .ontoref/positioning/sources/<source-id>.ncl what we concluded PROCESS .coder/ how we got there
The judgement references the custody by id and digest. Nothing references the process: `.coder/` is session memory and is never cited as a source of record.
1 · CUSTODY — `refs/`, a new Primary member
`refs/` is declared in constellation.ncl as `category = 'Primary`, `mirror = 'Never`. Per ADR-062 the repo driver is a distinct publication boundary — remote AND visibility — and custody of third-party artefacts is its own boundary for a reason unrelated to every other member: the material is not ours to republish. It is not the spine's (ADR-077 makes the spine repo public precisely because the spine is the project's own self-description), and it is not vault's (vault is SOPS/age private strategy; mixing regimes would force decryption to cite a number).
refs/<source-id>/ capture.ncl title · publisher · accessed_at · sha256 url | identifier : the stable address — a url for a web artefact, an identifier (ISBN, DOI) for a published work origin : 'External | 'Internal capture_method: 'Download | 'Fetch | 'PastedIntoSession | 'SessionExtract | 'Transcribed source.{pdf,html,md,txt} | extract.md
`capture_method` is declared, never inferred. `'PastedIntoSession` is the honest type for content that entered through a conversation because the page could not be fetched: the digest covers what was pasted, not what the server holds, and the record says so rather than presenting the two as equivalent evidence. `'SessionExtract` (2026-08-06) is a bounded excerpt of one of our own sessions, origin 'Internal. `'Transcribed` (2026-09-02) is a bounded, hand-typed transcription of the passages quoted from a published work we may not hold — a book, a print-only paper: the digest covers the transcription, never the work, the address is the work's `identifier`, and the quote's locator is a page. For such a work the custody logic inverts and the rule does not: the address is what stays and needs no copy; the fragment quoted is what custody is owed to.
2 · JUDGEMENT — `positioning/sources/<source-id>.ncl`
Public, queryable, and it carries the analysis: `claims[]` (each with its literal text, its locator, and the capture it is drawn from), `linked_nodes[]`, `tensions_engaged[]`, a verdict, and `consequences` naming what the verdict produced across positioning, backlog, adrs and the registry.
QUOTATION IS NOT REDISTRIBUTION. Bounded literal quotes with locators live in the public judgement — that is what a citation is, and it is what makes the claim checkable by a reader. What stays in custody is the ARTEFACT: the full text, the PDF, the captured page.
THE VERDICT BELONGS TO THE CLAIM, NOT TO THE SOURCE. The Fowler reading settles this on its own: one session produced vocabulary adopted whole, a judgement that pi.dev and replit are not competitors, a reading of pi.dev as a potential carrier, and an implementable remainder. A source carries a set of claim-level verdicts and a derived primary verdict.
'Evidence market data that substantiates a claim the project already makes 'Canon vocabulary or a frame adopted whole rather than argued with 'Convergent the same problem reached by another route 'Rival a system occupying the space 'Carrier neither rival nor canon — a potential vehicle for reach 'Challenge the signal shows something the project has NOT built 'Adjacent read, judged, touches nothing
Six of the seven are outward-facing. `'Challenge` is not: it routes to the backlog, to an `adr?` evaluation, and to whatever gate the resulting work needs. It returns to the outward surface only afterwards, as a validated proof. The most valuable verdict is the one that produces no content.
3 · THE SEAM — `'Base` mechanism, `'Project` routing, delegation by Q&A
The mode `assess-signal` is `scope = 'Base`: fix the source and its digest, extract claims verbatim with locators, map them to the graph, apply ondaod, emit a claim-level verdict from the closed vocabulary, persist the record. Every ontoref-governed project inherits exactly that.
What each verdict BECOMES is `scope = 'Project`, and the mode reaches it the way `generate-article` already reaches publication: the `route` step consults the project's own Q&A howto rather than describing the routing itself. The Base mode declares what must happen; the project's entry declares how, and a project with no site, no doors and no narratives is not made to grow them.
The vocabulary is what keeps the seam honest: a verdict names a RELATION TO THE SUBJECT, never an artefact. `'PostWorthy` or `'HookMaterial` would silently make the mechanism unexportable while still typechecking.
4 · THE RULE THAT GIVES IT TEETH
The talk's own rule generalises and becomes machine-checked instead of remembered:
A CLAIM THAT IS NOT IN THE SOURCE RECORD IS NOT PUBLISHED.
It is the counterpart of what `generate-article` gained when its publish step stopped self-reporting and let `check-posts-served.nu` decide.
5 · MIGRATION IS PART OF THE DECISION
The seven readings above are migrated: custody into refs/, judgement into sources/, and the `.coder/` files stay where they are, uncited. The migration is the schema's only real test — the verdict vocabulary was derived from these seven, and two of them (MAAD's internal origin, Fowler's multiple verdicts) already broke an earlier draft of it.
Constraints
- Hard The refs member declares mirror = 'Never. Third-party custody is canonical on the private forge and is replicated nowhere.
- Hard No source judgement cites a .coder/ path as its evidence. Session memory is process, never the record.
- Hard Every literal quote in a source judgement names both where it occurs in the artefact and the capture whose digest covers it.
- Hard A capture with origin = 'External carries a non-empty sha256 and a declared capture_method.
- Hard A capture with origin = 'External names a stable address — a non-empty url, or a non-empty identifier (ISBN, DOI) — and a 'Transcribed capture always names an identifier.
- Hard The verdict vocabulary contains no term naming a project surface (post, hook, door, narrative, campaign).
- Soft Every factual claim a publication attributes to an external source resolves to a claim in that source's judgement record.
- Hard assess-signal is declared scope = 'Base and its steps name no ontoref-specific surface; routing is reached by Q&A delegation.
Alternatives considered
- No custody: keep referencing sources by URL — rejected: It is the status quo and it is already failing. The corpus is Medium and Substack posts, a gated PDF, and pages that could not be fetched at all — content that exists in this project only because it was pasted into a session. A published claim resting on someone else's hosting decision is a claim with an expiry date nobody controls, which contradicts sufficient-verification at the exact point where the project is most exposed: outward, in public.
- Custody inside vault/, reusing the existing vault-never-mirrored constraint — rejected: It reuses a rule but merges two custody regimes with nothing in common. vault is SOPS/age-encrypted private strategy; refs is unencrypted third-party material held for citation. Merging them means decrypting to check a quote, and it puts material we merely hold under the same boundary as material that would damage the project if it leaked — which erodes the meaning of that boundary in both directions.
- Custody in the spine repo at the constellation parent (ADR-077) — rejected: ADR-077 makes the spine repo PUBLIC on purpose: the spine is the project's declared self-description, and routing it privately would make cross-project verification-by-witness impossible. Custody has the opposite visibility requirement. And ADR-077's tracked extent is 'what belongs to no member' — refs earns a member precisely because it has a boundary of its own, so it is not that residue.
- Leave custody where it is, in outreach/presentations/refs/ — rejected: It is scoped to one talk, it is prose no mechanism can read, and it sits inside a Primary declared public with a GitHub mirror — so the arrangement redistributes a gated report as a side effect of where the work happened. The content of that directory is right; its location, form and visibility are all wrong.
- Name the member resources/, as first proposed — rejected: code/install/resources/ already exists and means something else — installed protocol templates. Two directories named resources with unrelated meanings in one constellation is a collision that costs a reader every time. refs/ is the name the existing precedent already uses for exactly this content.
- One mode that reads a signal and produces a post, with project-specific branches inside it — rejected: It is the shortest path and it destroys exportability. Doors, hooks, bilingual narratives and hero images would enter the mechanism as conditionals, the verdict vocabulary would drift toward naming artefacts, and no consumer project could run it. ADR-076's 'Base/'Project seam and generate-article's Q&A delegation already solve this without a branch.
- Record the assessment in reflection/ as an act rather than in positioning/ — rejected: The act is already recorded — a mode run under .coder/agent/runs/. What is missing is the CONCLUSION as a durable fact, and every consumer of that fact (evidence_hooks, competitors, narratives, proofs, differentiators) is in positioning. Splitting the fact from its five consumers to honour a category distinction would fragment the surface without making any query easier.
- Require an external artefact for every assessment — rejected: It would have rejected the MAAD reading, which had no external artefact — it was an idea posed in session — and which nevertheless produced a narrative and a campaign. The entry contract is a FIXED LOCATOR you can return to, not a URL; origin = 'Internal with the session content in custody satisfies it honestly.
Anti-patterns
- Verdict that names an artefact — Extending the verdict vocabulary with a term that names what the signal will become here — 'PostWorthy, 'HookMaterial, 'DoorEvidence. It typechecks, it reads naturally, and it converts a protocol mechanism into one project's marketing intake without any error being raised.
- Citation without custody — Publishing a figure, quote or claim attributed to an external source that exists only as a URL. The claim is live and public; its evidence is on someone else's server under someone else's retention policy.
- .coder/ as the source of record — Citing a session file as the evidence for a public claim, because the analysis really was done there and extracting it is work. It makes the record depend on a private, rewritable tree that the spine repo does not even track.
- Custody inherits the visibility of its neighbours — A third-party artefact is saved next to the work that needed it, and silently acquires that member's remote and mirror. Nobody decides to republish anything; the topology decides.
- One verdict per source — Collapsing a reading to a single judgement because the artefact is a single thing. The richest signals carry several claims that land differently, and the collapse discards whichever ones do not fit the primary verdict.
- Intake as a content mill — Treating every interesting signal as a publication opportunity, so the mechanism's default output is a post. It converts the project into a commentator on other people's work and spends the outward surface on reach that qualifies nobody.
Related ADRs
ADR-023 · ADR-035 · ADR-048 · ADR-062 · ADR-070 · ADR-072 · ADR-074 · ADR-076 · ADR-077