Territory carries weight, a context face is a probed capability, and a membrane's permeability is derived from the territory a change lands in — so a premise cannot move without a ratified cast

Proposed

ontoref
SPLIT FROM ADR-119 on 2026-09-21. ADR-119 was written as four additions; its first

Context

SPLIT FROM ADR-119 on 2026-09-21. ADR-119 was written as four additions; its first (refutation travels with the check) was ready to implement and the other three were not, and `adr validate` gates every constraint of an ADR the moment it is 'Accepted. Accepting the whole record would have turned seven Hard constraints on at once, over fixtures that do not exist. The refutation stays in ADR-119; the three additions below, and the custody question, move here unchanged in substance, still 'Proposed.

The measurements are ADR-119's, from the same consumer (DD-eca, block 7):

1. «RATIFIED» MEANS «SIGNED WITH A KEY THE AGENT CAN REACH». All six SOWs in DD-eca's `.governance/` verify with `minisign -V -p .governance/witness.pub`, that public key is byte-identical to `~/.minisign/witness.pub` AND to this repository's own `.governance/witness.pub` (measured with `cmp`, 2026-09-21), and the matching secret key sits at `~/.minisign/witness.key`, mode 0600, owned by the same user every agent process runs as. ADR-066 ⛓G-3 declares every signature «a separate, human-executed, out-of-band act». The property is declared and not enforced.

2. THE PREMISE CHANGE NEVER MET A MEMBRANE. «Package for five platforms» collided with a premise («the daemon runs on the same machine»): a `'FrameBreakingQuestion`. A membrane's opening condition reads only project FSM state (`ontology/schemas/gate.ncl`: `max_tension_dimensions`, `pending_transitions`, `core_stable`), never WHERE a change lands. The agent absorbed the signal silently inside execution, which is not its level.

3. A DEGENERATE CONTEXT WITNESSED BOTH FACES. Developing against `localhost` collapses the distinction the design depends on — daemon and client on one machine, one filesystem, one key. The original plan wrote a localhost artefact as a design property («the daemon has access to both folders»); the agent generalised the other way from a localhost measurement.

Decision

THREE ADDITIONS, EACH REUSING A SEAM THAT ALREADY EXISTS.

(1) TERRITORY CARRIES WEIGHT. Territory is already the protocol's: rung 4 of the ladder (ADR-111, `territory-and-criterion`). What rung 4 does not yet say is how much a given reach COSTS to move. A constraint (ADR) and a contract (SOW) may declare

weight | [| 'Bearing, 'Ordinary, 'Free |] | default = 'Ordinary

over the scope they already declare. 'Bearing is the type: inside one ratified SOW it does not mutate; changing it is a CAST — a successor SOW naming `predecessor_sow`, ratified (ADR-097 already resolves supersession this way; this makes it the ONLY way a bearing claim moves). 'Ordinary is checked where it applies. 'Free carries no harness. Weight is what `ontoref governs <path>` reports alongside the constraints governing a path.

(2) A FACE IS A CAPABILITY, SO A DEGENERATE CONTEXT IS 'Declared UNKNOWN. A bearing claim whose truth depends on context names its faces as `needs`: a capability such as `face-separated-host` whose probe succeeds only where the faces are actually distinct. On localhost the probe fails and the claim reports unknown 'Declared instead of a pass earned by co-location. No new mechanism: ADR-088's `needs`, applied to context.

(3) PERMEABILITY IS DERIVED FROM WHERE THE CHANGE LANDS. A membrane's existing `protects` names territories. Sensors — the diff of a turn or commit, capability witness drift, bus events, declared signals — are routed to territory by the same derivation `governs` uses:

lands in permeability protocol outcome 'Bearing Low Challenge execution stops; only a ratified successor proceeds (the cast) 'Ordinary Medium Absorb proceeds if its checks, WITH refutation, pass 'Free High Observe proceeds, recorded a signal intersecting 'Bearing Closed (to execution) Challenge the decision leaves the executor and reaches a human

The membrane stays advisory where it is a Spiral question about the project; it becomes refusing only for the 'Bearing row, and only for execution.

WHAT THIS DOES NOT DECIDE: how the ratifying key is kept out of an agent's reach. The constraint `ratification-needs-a-human-act` records the property and why it is not gateable from inside the process it protects.

Constraints

  • Hard A change to a 'Bearing contract of a ratified SOW is admitted only as a successor SOW whose `predecessor_wo` names it and whose signature verifies; editing the ratified file in place invalidates it.
  • Hard A claim that names a face capability in `needs` reports unknown 'Declared in a context whose face probe fails, never pass.
  • Hard A change routed to 'Bearing territory yields permeability Low and protocol Challenge for execution; the same membrane yields Absorb for 'Ordinary and Observe for 'Free.
  • Hard The key that ratifies a SOW or signs a receipt cannot be used by an agent process without a human act (passphrase, hardware presence, or a separate OS identity).

Alternatives considered

  • Declare invariants: rules that never change — rejected: Collapses the Spiral and cannot express a property with two faces (remote service in infrastructure, localhost in development) that must hold in both without either being «the» truth.
  • Run every check at the end of every agent turn — rejected: A gate that always fires stops discriminating and becomes a reflex skip. Checks are selected by the territory the turn's diff lands in, which is the derivation `governs` already performs.
  • Keep these three additions inside ADR-119 — rejected: Acceptance gates every constraint of the record at once (`reflection/modules/validate.nu` filters on 'Accepted). Refutation was ready and these were not; one record would have forced accepting unimplemented Hard constraints or leaving the ready one unaccepted.

Anti-patterns

  • Everything declared 'Bearing — Every claim is marked bearing so nothing can move without a ratified cast. The harness becomes friction that never turns into gravity, and the reflex that follows is to route around it.
  • A localhost pass recorded as a design property — A claim about separation (service vs client, server vs working folder) is evaluated where the two are the same machine and its pass is carried into a plan or a receipt as if it held everywhere.
  • A frame-breaking signal resolved by the executor — A new requirement collides with a bearing premise and the executor resolves the collision inside the work instead of raising it to the membrane.

Related ADRs

ADR-119 · ADR-066 · ADR-088 · ADR-097 · ADR-111

Perspectives
Was this useful? Rate it
Got something to add? Tell me what you think, what you'd suggest, or whether we should keep exploring this topic.
· reads

We use cookies to help this site function, understand service usage, and support marketing efforts. Cookie Policy for more info.