Skip to main content

39  Claim Ledgers and Belief Revision

39.1 Chapter status

Field Value
Chapter ID claim-ledgers-and-belief-revision
Part Part II - Planning, Memory, Reasoning, and Execution
Status conceptual
Manuscript maturity v0.4 manuscript draft
Last updated 2026-07-31
Primary source records spinoza, viea, coherence_exchange, aletheia, uat, ext_agm_belief_revision_1985, ext_truth_maintenance_system_1979, ext_assumption_based_tms_1986, ext_alce_2023, ext_self_rag_2023, ext_checklist_2020, ext_w3c_prov_o_2013, cca_project, moecot_manifest_project, beastbrain_project, bugbrain_project, corbens_best_model_possible_project, qcsa_whitepaper, reflexive_router_whitepaper
Claim label Design rationale
Evidence level argument
Source queue primary: spinoza, viea; supporting: coherence_exchange, aletheia, uat, five historical projects, and reflexive_router_whitepaper; external comparators: AGM, TMS, ATMS, ALCE, Self-RAG, CheckList, and PROV-O; local semantic-addressing lineage: QCSA
Source loading state source notes: spinoza, platonic_world_model, viea, coherence_exchange, aletheia, uat, ext_agm_belief_revision_1985, ext_truth_maintenance_system_1979, ext_assumption_based_tms_1986, ext_alce_2023, ext_self_rag_2023, ext_checklist_2020, ext_w3c_prov_o_2013, cca_project, moecot_manifest_project, beastbrain_project, bugbrain_project, corbens_best_model_possible_project, qcsa_whitepaper, reflexive_router_whitepaper, regret_engine; raw cache: spinoza, viea, aletheia, uat; connector/recovery: coherence_exchange
Test state Exact authored refinement: 5 valid/7 rejecting revision fixtures; 1 valid/11 rejecting historical lifecycle fixtures; 5 reachable stages, 22 route cases, and 34/34 rejected lifecycle mutations; 27 refinement declarations under 4 public targets, with 16 weak baseline declarations retired and 4 bounded legacy lemmas retained. No open-domain extractor, natural workload, semantic-equivalence or contradiction-quality evaluator, concurrent ledger, natural migration or surface synchronizer, independent reviewer, useful advantage, or chapter-core support effect.

39.2 Drafting guardrail

Claim Ledgers owns durable semantic identity and append-only transition history, not truth. The repository has five valid and seven rejecting authored revision fixtures, one bounded five-project lifecycle with eleven rejecting mutations, and a reachable five-stage Lean refinement whose independent consumer covers 22 route cases and rejects 34 lifecycle mutations. Those artifacts test exact version custody, append accounting, authority separation, branch behavior, and stated no-promotion boundaries. They do not run an open-domain extractor, natural contradiction detector, semantic-equivalence evaluator, concurrent event store, ontology migrator, surface synchronizer, independent reviewer, usefulness study, causal campaign, reproduction, or transfer.

Placed after Verification Bandwidth, the ledger stores how an exact claim and its surfaces change after adequacy, evidence, proof, or review owners return a bounded result. It may preserve or route those results but cannot reinterpret them or move support. A complete ledger can be consistently wrong; its honest achievement is reconstructable belief-state continuity under declared owners.

39.3 Human Reading Path

Concrete lens. Version control is the strongest simpler baseline and may be enough for a small manual system, but it records changed bytes rather than fallible semantic identity, dependency closure, or stale downstream authority.

Once verification adequacy is visible, claims need a durable revision home. Important statements become ledgered objects that can be supported, challenged, downgraded, split, merged, promoted, or retired without losing their identity.

The claim ledger is the architecture’s memory for belief. Prose can change, but the ledger should remember what was asserted, what supported it, what challenged it, and why it changed. That is how a living manuscript avoids becoming a polished record of forgotten assumptions.

Belief revision is therefore a maintenance operation, not an embarrassment. Downgrades, splits, contradictions, and retirements are signs that the evidence machinery is still attached to the prose. The healthiest ledger can remember being wrong without losing the trail of why, which lets confidence change without erasing accountability.

Belief revision becomes safer when a downgrade is treated as progress. The ledger protects the path by which uncertainty becomes clearer, and it earns authority only when the old uncertainty remains inspectable while new evidence arrives from elsewhere. That old trail is part of the evidence, not editorial clutter.

39.4 Problem

39.4.1 A concrete failure: the policy sentence that outlived its source

An operations assistant keeps a claim that “hazardous shipments may leave the warehouse after a second scan.” The sentence was correct under policy version 17, appears in a playbook, and is copied into a weekly briefing. Policy version 18 changes the exception: a second scan is no longer sufficient for one class of material. A reviewer updates the source document, but the briefing and a cached assistant prompt still contain the old sentence. When a dispatcher asks for a quick answer, the assistant repeats it with a confident citation. The problem is not merely stale text. The old and new sentences have different scope, source version, and permitted action, yet the system treated a string match and a citation as if they supplied semantic identity. The residual is an unreconciled downstream surface that can continue to authorize the old action.

39.4.2 Worked trace: revise the claim without erasing the trail

State Ledger transition What remains deliberately separate
L0 candidate Register the exact proposition, scope, source, and surface refs. Registration is not truth or support.
L1 challenge Attach the policy-18 source and a scope-difference attack. Provenance does not validate the source.
L2 downgrade Evidence owner accepts a support transition; the old claim is downgraded. The ledger records the transition but cannot authorize it itself.
L3 propagation Mark the briefing and prompt as stale and block release until reconciled. Surface repair is not semantic equivalence.
L4 closure Publish the new bounded claim and retain the rejected proposal. The current view is reproducible from append-only events.

The simpler baseline is version control over the playbook. Version control is useful and may be sufficient for a small, manually audited system; it records changed bytes but does not, by itself, identify that two differently worded sentences refer to the same claim or that a downstream surface still carries the old scope. The ledger earns its extra machinery only when that semantic and propagation burden is real and measured.

A claim can be repeated, paraphrased, narrowed, challenged, contradicted, split, merged, downgraded, superseded, or published across many surfaces without a durable identity and append-only transition history. Prose, caches, summaries, diagrams, APIs, reader editions, and releases can then disagree silently about what was asserted, under which assumptions, what supported or attacked it, and why it changed.

This is not merely a storage problem. The same words can express different claims under different definitions, quantifiers, populations, environments, times, exceptions, or consumers. Different words can express the same claim, but that equivalence is a fallible judgment. A support label, citation, embedding, semantic address, graph node, or database key cannot supply the missing semantic identity by itself.

The ledger therefore needs two simultaneous properties: a stable reference for the claim and an honest record of uncertainty about its boundaries. It must reconstruct every accepted and rejected change without becoming the authority that decides evidence validity, truth, review competence, action, or release.

39.5 Why existing approaches are insufficient

Prompts and prose preserve wording but not necessarily claim identity or history. Citations and ALCE-style evaluation expose support gaps but citation presence is not entailment or source truth. PROV-O can represent asserted derivation, attribution, revision, and invalidation, but a provenance graph does not justify its assertions. Embeddings, QCSA-style addresses, and graph retrieval help locate related material without establishing equivalence. Self-RAG-style retrieval and critique produce useful fallible inputs; a model critique cannot certify itself. CheckList-style behavioral failures should become durable attacks or regressions, but a test matrix is not a belief store.

Version control and event sourcing preserve changes to bytes or records, not the semantic relation between two natural-language claims. Databases can enforce transactions while storing a wrong merge. Human editorial workflows can catch nuance but often leave dependency reachability, stale surfaces, rejected changes, and total cost implicit.

AGM belief revision, Doyle’s truth-maintenance system, and de Kleer’s ATMS are substantive prior art for explicit theory change, maintained reasons, and assumption contexts. The ledger does not replace or implement them. It owns a narrower architecture bridge for natural and formal claim identity, append-only state transitions, dependency repair, and multi-surface synchronization while making formal theory change, truth maintenance, and semantic correctness explicit future comparators.

39.6 Core Claim

[claim-ledgers-and-belief-revision.core, label: Design rationale, support: argument] Claim Ledgers should own the durable identity and append-only state-transition history of each material claim and its semantic variants. Every record binds canonical proposition and scope, definitions and assumptions, population and environment, provenance and source roles, evidence and attack refs, support and uncertainty states, contradiction and defeater links, dependencies, ontology version, lifecycle, commitment, authority and rights, surface refs, expiry, residuals, and current materialized view; every proposed update binds trigger, before/after states, transition type, evidence-transition and review refs, affected dependency closure, surface-sync plan, concurrency base, migration, costs, and non-overwrite receipt. The ledger may record or route promotion, downgrade, split, merge, supersession, deprecation, retirement, dispute, or no change only through the owning gates. It does not establish claim truth, source or evidence validity, verification adequacy, semantic equivalence, reviewer competence, formal-model fidelity, action authority, usefulness, safety, support movement, or release.

The claim remains at argument. Current evidence establishes authored schema and route checks, one bounded historical lifecycle, and explicit non-claim boundaries. It does not establish natural identity resolution, correct belief revision, complete propagation, useful advantage, or transfer.

39.6.1 Claim-source mapping status

Appendix C maps all eighteen assigned sources. Four local raw caches are passage-reviewed; coherence_exchange remains source-note/connector bounded; five historical projects and QCSA provide public-safe lineage; and seven external sources remain bounded primary-record or primary-paper comparators. None is imported as a local claim-identity, contradiction, belief-revision, surface-synchronization, usefulness, or transfer result.

Source What it supports Limit
spinoza Passage-reviewed: proof-carrying hypergraph, proposition nodes with provenance/tier/entrenchment/dependencies/validity/versions/audit, justification hyperedges, enforced claim tiers, proof/refute/unknown outcomes, contradiction-triggered revision, dependency and unsat-core tracing, retraction, invalidation, re-verification, revision logs, and first-class certified/citation/procedure support tiers. Does not prove open-domain claim extraction, natural-language formalization, or a complete belief-revision engine here.
viea Passage-reviewed: durable artifact graph, claim and verification ledger, verified/speculative/unsupported/contradicted/experiment-required states, claim extraction into support states, support/challenge relationships, evidence hierarchy, model-consensus limitation, provenance fields, and downgrade on expired, challenged, failed, or contradicted support. No deployed VIEA claim-ledger system, runtime evidence trace, or claim-extraction test exists in this repo.
coherence_exchange Connector/source-note mapped: structured claim/evidence units, verification supply chains, contestability, and fork/exit/audit governance framing for epistemic objects. Epistemic-liquidity and economic metaphors remain speculative synthesis.
aletheia Passage-reviewed: verification gates, per-node verification requirements, verification tiers, claim extraction and tier assignment, verified commitments in memory, claim-native artifacts with claim IDs, dependencies, and evidence refs, bounded adversarial review, omission/stability checks, contradiction-triggered belief revision, quarantine, human review, and new-evidence requirements. No local Aletheia implementation, live-oracle run, adversarial battery result, or proof artifact is present.
uat Passage-reviewed: human-in-the-loop SME force multiplier, retrieval-source-bound claims, atomic proposition decomposition, verified/inferred/unsupported states, dossier-bounded checks, SME_REVIEW handling, adversarial logic/citation/omission review, stability and hard-cycle caps, compression that preserves verified proposition counts, final SME sign-off, correlated-hallucination risk, and decomposition-loss risk. Does not prove tribunal thresholds, reviewer independence, autonomous truth-machine behavior, or novel truth discovery beyond the declared dossier.
ext_agm_belief_revision_1985 Comparator for explicit contraction and revision operations, rationality postulates, and representation results over theories. Metadata/abstract-level note only; no AGM proof, postulate, partial-meet contraction, natural-language mapping, or local implementation.
ext_truth_maintenance_system_1979, ext_assumption_based_tms_1986 Comparators for maintained reasons and justifications, dependency-aware revision, assumption sets, inconsistent information, and context switching. No TMS or ATMS algorithms, labels, environments, backtracking, reasoner, or assumption-completeness result.
ext_alce_2023, ext_self_rag_2023, ext_checklist_2020 Comparators for citation support, adaptive retrieval and critique, and failure-preserving behavioral tests as fallible ledger inputs and revision triggers. No corpus, checkpoint, training, test suite, model run, evaluator reproduction, citation result, factuality result, or behavioral coverage result.
ext_w3c_prov_o_2013 Interoperable asserted-provenance vocabulary for entities, activities, agents, derivation, attribution, delegation, revision, quotation, primary source, and invalidation. No PROV-O graph or conformance result; asserted provenance is not truth, completeness, integrity, authority, or support.
cca_project, moecot_manifest_project, beastbrain_project, bugbrain_project, corbens_best_model_possible_project Public-safe historical lineage for separated epistemic state, durable identity, dependency repair, contradiction response, supersession, ontology migration, residual retention, restart persistence, and negative cases. One hand-authored lifecycle only; no historical runtime replay, independent replication, open-domain detector, belief engine, ontology correctness, or revision-quality result.
qcsa_whitepaper Passage-reviewed separation of ontology, propositions, evidence for and against, provenance, support state, contradiction, and permitted use inside an evidence-bearing hypergraph; the later repository adds a bounded local 12-lane implementation, 60-case held-out evaluation over 13 systems and three seeds, and one 13-stage governed vertical trace. QCSA’s matched-advantage and resource gates failed on the proxy, and the active-question ablation is N2 proxy/regime evidence rather than an exact or broad refutation. The chapter core claim remains at argument; addressability and certificates do not establish identity equivalence, truth, belief correctness, support, production readiness, AGI, or ASI.

39.6.2 Strongest objection

A complete, append-only ledger can be consistently wrong and operationally harmful. Natural-language identity and equivalence may be undecidable or context-dependent; contradiction severity, dependency closure, ontology migrations, and synchronization targets are themselves fallible judgments. The extra metadata, review, storage, and propagation can increase privacy risk, latency, false splits, false merges, false downgrades, and human burden while a capable editor plus version control performs as well. The design case therefore needs joint semantic, downstream, safety, and cost evidence, not internal consistency alone.

39.7 Mechanism

The ledger begins after a candidate claim exists and before any surface may treat its current wording as canonical belief. Its eighteen mechanisms are:

The first mechanisms separate a claim’s identity from its current prose and current support. They preserve semantic fields, variant relations, evidence and attack references, dependencies, and proposed mutations as distinct records. This arrangement makes the history inspectable without granting an extractor, similarity model, provenance link, or event log the power to decide truth.

Readers can hold the mechanism as four responsibilities before opening the field-level contract. Identity fixes what the claim means and which wordings are only hypotheses about that meaning. Evidence custody keeps support, attacks, provenance, and dependencies visible without letting any of them certify themselves. Transition custody records who proposed a change, which gate accepted it, and how the current view can be replayed. Change repair carries that decision through conflicts, ontology migrations, stale surfaces, expiry, and comparison with simpler baselines. The numbered fields below are the implementation contract for those four jobs; they are not four additional claims about truth.

Open the field-level contract
  1. Register each candidate material claim with durable ID, origin, raw wording, extraction method, materiality decision, canonical proposition, and version without treating registration as truth or support.
  2. Factor definitions, quantifiers, scope, population, environment, time, consumer, assumptions, exceptions, affected parties, and requested support effect into versioned fields.
  3. Record exact, equivalent, entailing, narrower, broader, overlapping, incompatible, and unknown wording relations as reviewed hypotheses with evaluator identity, confidence, scope deltas, and ambiguity.
  4. Keep provenance, source roles, evidence, attacks, support, uncertainty, contradiction, lifecycle, commitment, authority, rights, readiness, and release as separate states and owners.
  5. Attach positive, negative, boundary, contradiction, replication, outcome, and cost evidence refs plus source-unit and derivation lineage without allowing provenance to validate itself.
  6. Build justification and dependency graphs over claims, assumptions, evidence, attacks, models, surfaces, and decisions, preserving alternative justifications, cycles, contested edges, invalidations, and residuals.
  7. Store every proposed and accepted mutation as an append-only event with prior-state digest, concurrency base, trigger, proposer, authority, review and evidence-transition refs, before/after state, rationale, time, cost, and non-overwrite receipt.
  8. Materialize the current view from event history while retaining time-travel reconstruction, superseded views, rejected proposals, failed migrations, conflicts, and replay checks.
  9. Use typed transitions for map, challenge, contradiction, no change, promotion proposal, downgrade, split, merge, supersession, deprecation, retirement, expiry, dispute, quarantine, and residualization.
  10. Require the Evidence States owner to authorize support movement through exact accepted evidence-transition refs; the ledger may propose, record, or block a transition but never promote itself.
  11. Apply stronger responses to stronger recorded contradictions only inside a frozen severity model while preserving detector uncertainty, disagreement, false-positive risk, and cases with no known rational ordering.
  12. Compute a bounded affected dependency closure, compare declared and observed reachability, repair only authorized nodes, and retain omitted, cyclic, blocked, stale, or budget-exhausted residuals.
  13. Version ontologies, schemas, predicates, and identity rules; migrate claims through explicit mappings, collision and non-isomorphism checks, rollback, orphan handling, and preserved pre-migration views.
  14. Synchronize accepted material changes across every declared publication, cache, index, API, benchmark, and runtime surface with exact acknowledgment or residual.
  15. Handle concurrent proposals with base-version checks, conflict records, reviewed merge policy, idempotent retries, and no silent last-writer wins.
  16. Expire and re-review claims after material source, evidence, model, evaluator, ontology, environment, authority, rights, threat, outcome, or consumer changes while preserving the earlier historical boundary.
  17. Test causal use by hiding, corrupting, duplicating, forking, staling, or removing identity, assumptions, contradiction links, dependency closure, history, migration, and surface synchronization under matched conditions.
  18. Compare no-ledger prose, citation-only, provenance-only, version-control, database/event-sourcing, truth-maintenance, retrieval/self-critique, behavioral-test, human-editorial, and governed-ledger routes on natural multi-surface revision workloads with complete outcomes and costs.

flowchart LR
  A["Candidate claim + semantic fields"] --> B["Durable ID + version"]
  B --> C["Evidence / attack / dependency graph"]
  C --> D["Proposed append-only transition"]
  D --> E{"Owning gates accept?"}
  E -- "yes" --> F["Append event + materialize view"]
  E -- "no" --> G["Reject / dispute / residualize"]
  F --> H["Bounded dependency repair"]
  G --> I["Preserved proposal + reason"]
  H --> J["Surface acknowledgments"]
  I --> J
  J --> K["Expiry / replay / future review"]

Reading the claim ledger: The ledger does not decide whether the proposed change is true. It preserves the candidate, invokes the owning gates, appends their bounded decision, repairs the declared dependency closure, and requires every surface either to acknowledge the exact version or remain a visible residual.

The later mechanisms carry an accepted bounded decision through dependency repair, ontology change, concurrent proposals, surface synchronization, expiry, and comparison. Their shared object is continuity across change: earlier views, rejected proposals, collisions, unresolved nodes, and stale surfaces stay in the record beside the materialized current view. That continuity supplies an audit trail, while epistemic and operational authority stays outside the ledger.

39.7.1 Regret records and belief records must not collapse

The Regret Engine source (regret_engine) proposes a separate append-only history for decisions, outcomes, comparators, counterfactual estimates, attribution, recovery, and learning eligibility. A Regret Packet can refer to claim IDs and can propose a belief revision, but it is not itself a true claim about what would have happened. Counterfactual estimates remain model-conditioned, and root-cause conclusions remain defeasible.

The clean join is monotone evidence history with defeasible conclusions. Decision capsules, observations, evaluator outputs, appeals, and prior packet versions remain append-only. A later causal model, invalid comparator, specification change, or evaluator defect may supersede the active conclusion through a typed edge without deleting the earlier record. The Claim Ledger then owns any proposition-level split, downgrade, supersession, or surface repair; the Regret Ledger owns the incident-learning history that motivated it. Neither ledger may promote its own support state.

39.7.2 Monotone contradiction and bounded repair

The historical-project packet separates four dimensions that are often collapsed: justification state, claim lifecycle, commitment state, and action authority. It then records weak, medium, and strong contradiction events with responses that may strengthen but never weaken: annotate, block promotion, then downgrade or split. Supersession names both the replaced claim and its successors; every unresolved contradiction remains a residual. Dependency repair is bounded to an exact declared affected closure, ontology changes carry a versioned migration, and a restart observation must still expose the old claim, successors, revision, and residuals.

39.7.3 Evidence-bearing semantic graphs

QCSA makes a useful evidential prohibition explicit: ontology is not belief, and addressability is not truth. Object definitions, type declarations, propositions, evidence for and against them, source and derivation lineage, current support state, contradiction, and authority to use a proposition are different records even when they share one typed hypergraph. A graph edge can be asserted, hypothesized, disputed, time-bounded, source-scoped, superseded, or revoked.

A Semantic Address Certificate may route a verifier to the right claim cluster and state confidence that the cluster is the intended one. It cannot promote the proposition. Certificate integrity proves only that the recorded address lease has not changed under its integrity contract; atlas confidence concerns resolution, not evidential truth. The claim ledger remains the authority for support state, attacks, revisions, and permitted evidential use.

Typed hyperedges also let a claim retain role structure for events with many participants, times, quantities, conditions, and receipts without duplicating their identities. The bounded implementation now rejects dangling evidence, preserves contradictions, and selects the evaluator-labelled proposition in all held-out evidence-revision fixtures. The governed vertical trace likewise keeps the proposition, evidence, provenance, permitted use, and authority records separate.

This is record-integrity and exact synthetic task evidence, not ontology-completeness, belief correctness, source adequacy, or truth. The held-out labels were constructed from the same finite fixture family, and no natural contradictory corpus or independent truth adjudication was used. The claim ledger remains the only owner of support-state movement, and this core claim remains at argument.

39.7.4 Chronicle records and bitemporal correction

The Reflexive Router proposes a Chronicle as the temporal substrate consulted by routing, but the claim ledger must prevent it from collapsing unlike record types. An event says something happened or was observed; a state says what held over an interval; a claim says what is asserted; a plan says what is intended; a prediction says what is expected; and a counterfactual says what would have happened under another condition. Sharing an entity ID does not make these objects interchangeable.

Every Chronicle-bearing claim or observation carries valid time and transaction time separately. A correction may reveal today that a state was different last week without rewriting what the system believed yesterday. Supersession, contradiction, retraction, expiry, and unresolved conflict remain append-only transitions with provenance, derivation, epistemic status, and affected-consumer closure. Routing may consume a current materialized view, but the view must retain the ledger and Chronicle refs that make later replay and invalidation possible.

Typed result packets can append observations and proposed claims, yet they do not settle either. A verifier receipt, tool return, model confidence, or fluent rendering can itself be wrong. Claim admission still requires the chapter’s evidence and review gates; conflicting records remain visible rather than being resolved by recency alone. Poisoned Chronicle updates, future-dated facts, stale transaction epochs, and circular derivations are explicit attack classes for the routing campaign.

The paper supplies this record separation and threat model as design rationale. It supplies no implemented Chronicle, temporal-accuracy result, or independent belief-revision evidence, so support remains argument.

39.7.5 A claim-native release is a two-way coverage contract

A structured claim registry solves only half of the publication problem. It makes the declared claim set enumerable, but a generator can still place a material assertion in narrative, a table, a caption, a code comment, or an interface label without registering it. The reverse failure also matters: a machine-gated claim can affect a decision while remaining absent from the human-readable surface. A release is therefore claim-native only when it records both directions of the relation.

Each registered claim names the exact artifact, span, cell, node, output, or effect surface that expresses it. Each material assertion on a release surface names its claim ID and current version. The release checker reports four states rather than one coverage percentage:

Surface state Meaning Required disposition
bound The material assertion and registered claim point to each other under the same scope and version. Continue to the owning evidence and release gates.
unregistered_assertion Material prose or another surface expression has no claim record. Register, remove, narrow, or retain as a blocking residual.
hidden_claim A registered claim has no declared reader- or consumer-visible surface even though it can affect interpretation or action. Render it, justify a protected machine-only surface, or block release.
mapping_disputed Reviewers disagree about identity, scope, materiality, or whether the surface entails the registered claim. Preserve alternatives and disagreement; do not resolve by similarity score or recency.

This is not a promise of deterministic claim extraction from arbitrary natural language. A schema can make an authored claims[] array deterministic to enumerate; it cannot make materiality, implicit assertion detection, entailment, or semantic equivalence mechanical in the open world. Required claim categories, structure-aware parsers, perturbation tests, model-assisted candidates, and independent sampling can search for omissions, but every method keeps false-negative and false-positive denominators. The unchecked remainder is an explicit coverage residual, not rounded into completeness.

Claim granularity is part of the contract. One broad claim can hide unsupported subclaims, while many tiny claims can inflate coverage and make review intractable. The release therefore pins a materiality policy, decomposition rules, examples and counterexamples, reviewer or evaluator lineage, sampled unregistered surfaces, and changes in the denominator. Coverage is reported with useful throughput, reviewer burden, disagreement, semantic escape, and unsafe release rather than optimized alone.

Aletheia’s later Proof-Carrying Workbench version motivates this release discipline, but its phrase “deterministic claim surface” is narrower than it sounds. No implementation or natural-corpus result is present here. The book adopts the auditable two-way interface while explicitly rejecting complete automatic extraction, proof by schema validity, or support promotion.

39.7.6 Semantic continuity and the four epistemic objects

The Platonic World Model makes four records irreducible. A proposition is versioned content under a context and semantic basis. An attestation records that a source, sensor, document, model, or process asserted or observed it. A commitment records an agent’s governed stance—accepted, rejected, provisional, suspended, disputed, superseded, or unknown. A proof object is a replayable justification with premises, rules, tools, assumptions, defeaters, versions, and environmental dependencies. Collapsing any pair enables evidence laundering.

Semantic well-formedness, epistemic support, and operational authority are therefore separate axes. A proposition may be well typed and unsupported; it may be strongly supported and still unauthorized for action. Historical replayability, validity under the original basis, validity under the current preferred basis, and present authorization are distinct statuses. Valid, observation, and transaction time prevent a correction from erasing what the system knew or believed when it acted.

Meaning changes enter as semantic transactions, not ordinary fact updates. A typed diff separates contract, extension, entailment, grounding, dynamics, normative, mapping, and operational deltas; dependency analysis assigns every affected proof, policy, plan, model, packet, and tool a migration disposition. The ledger records forks and unresolved disagreement instead of forcing global consistency or one final ontology. This is an architecture proposal from platonic_world_model, not an implemented belief-revision result.

39.7.7 Waivers reduce process, not evidence

Full claim extraction is disproportionate for some private, low-risk scratch artifacts. VIEA therefore permits an explicit claim-ledger waiver binding artifact, reason, risk tier, scope, expiry, and approving policy or person. A waiver is not a support state and creates no positive evidence. It is forbidden for public, executable, safety, legal, medical, financial, benchmark, or other high-consequence claims unless the owning policy defines a narrower admissible case.

The critical control is downstream reactivation. If a waived draft becomes a source for a release, deployment, benchmark, fabrication packet, training record, policy, or high-impact decision, its material claims must be extracted and reviewed before the dependency is admitted. The waiver cannot flow through provenance as inherited trust. Likewise, agreement among correlated models or review roles cannot create verified standing; challenge, expiry, failed tests, changed dependencies, or contradictory field feedback trigger downgrade or review rather than letting an old label persist.

39.8 Interfaces

  1. Verification Bandwidth supplies adequacy, attempt, disagreement, and residual records. The ledger stores their relation to a claim but cannot reinterpret adequacy or turn it into support.
  2. Evidence States and Claim Discipline owns support labels, accepted transitions, downgrades, refutations, and promotion gates. The ledger owns durable continuity and exact transition receipts.
  3. Proof-Carrying Claims, formal tools, and Scalable Oversight own property semantics, proof or verifier results, tribunal dossiers, reviewer competence, dissent, and verdict constraints. The ledger preserves their bounded outputs.
  4. Virtual Context ABI and Context Transactions supply exact source, packet, snapshot, lifecycle, taint, revocation, and deletion state. Context availability or consistency is not belief correctness.
  5. Artifact Graphs owns general artifact and execution lineage plus interoperable provenance projection. The claim ledger owns claim-semantic identity, belief transitions, attacks, dependencies, and surface duties.
  6. Compilation, Planning, jobs, Runtime, policies, benchmarks, and data engines consume versioned claim views through declared use contracts and cannot silently pin, rewrite, or promote ledger state.
  7. Security, Privacy, Authority, Rights, and Licensing decide who may inspect, derive, retain, disclose, train on, or act on claim records. Ledger visibility grants no action or publication authority.
  8. Resource Economics records extraction, review, graph, storage, synchronization, migration, retry, recovery, human, privacy, latency, and opportunity costs without allowing budget exhaustion to erase residuals.
  9. Publication, reader, audio, API, and release surfaces acknowledge exact claim versions and support states. Publication tooling cannot become the canonical belief store or silently strengthen wording.
  10. QCSA and semantic-addressing systems may locate claim clusters and variants but cannot establish equivalence, truth, support, contradiction resolution, or permitted evidential use.
  11. Human principals and accountable reviewers own unresolved semantic, normative, affected-party, authority, and high-consequence decisions. Automation may request and preserve those decisions but cannot fabricate consent or consensus.

The minimum transition record binds revision_id, claim_id, canonical and raw proposition versions, scope and assumptions, prior and proposed state, transition type, source/evidence/attack/review refs, contradiction and uncertainty state, dependency closure, ontology version and migration, concurrency base, surface plan and acknowledgments, authority and rights, costs, residuals, history refs, non-overwrite attestation, support-state effect, and non-claims.

39.9 Invariants

The invariants preserve four separations through every revision: proposition from wording, evidence from support, recorded history from current view, and ledger custody from decision authority. They also keep migrations, concurrency, surface propagation, and residuals inside the same historical account. Together they define the conditions under which a later reader can reconstruct what changed without treating reconstructability as correctness.

  1. Every material claim has one durable identity per declared semantic proposition and scope; wording, location, embedding, address, key, and current support state are not identity by themselves.
  2. Raw wording, canonical proposition, definitions, quantifiers, scope, assumptions, population, environment, time, consumer, exceptions, and variants remain inspectable and versioned.
  3. Provenance, evidence, attack, support, uncertainty, contradiction, lifecycle, commitment, authority, rights, readiness, and release remain separate states.
  4. Accepted history is append-only and retains prior digest, trigger, rationale, evidence and review refs, proposer, authority, before/after state, time, costs, and non-overwrite receipt.
  5. No support increase is accepted without an exact accepted evidence transition from the owning gate.
  6. An open material contradiction blocks promotion unless the owning gates resolve, bound, refute, or preserve it as an accepted residual.
  7. Semantic variants merge only when their reviewed proposition and scope relation permits it; ambiguity and changed assumptions remain split or disputed.
  8. Split, merge, supersession, deprecation, and retirement preserve parent, child, predecessor, successor, evidence, attack, surface, and history links.
  9. Dependency repair names a frozen closure, budget, algorithm, omissions, cycles, blocked nodes, observed repaired set, and residuals without claiming open-world completeness.
  10. Ontology, schema, predicate, or identity-rule changes require versioned migration, collision and non-isomorphism handling, rollback, orphan disposition, and preserved pre-migration views.
  11. Every accepted material change is acknowledged or residualized across all declared surfaces and consumers; no derivative may silently lag or lead.
  12. Concurrent updates preserve base versions, conflicts, retries, merge decisions, rejected proposals, and idempotency; no material event is lost.
  13. Provenance assertions, addresses, citations, retrievals, self-critiques, behavioral tests, proofs, and reviewer verdicts retain their exact mode and source ceilings and cannot validate themselves.
  14. Uncertainty and contradiction severity remain scoped, evaluator-attributed, calibrated where claimed, and capable of disagreement; monotone response does not imply monotone truth or complete detection.
  15. Read, write, review, support, action, disclosure, training, retention, and release authorities remain distinct and never widen through derivation, merge, migration, or synchronization.
  16. Material source, evidence, model, evaluator, ontology, environment, authority, rights, threat, outcome, or consumer changes expire affected views while preserving history.
  17. Every candidate, duplicate, merge, split, proposal, conflict, rejection, retry, repair, synchronization attempt, intervention, failure, cost, delay, false merge or split, missed update, and residual remains in the denominator; finite artifacts establish only their exact scope.

39.10 Failure modes

Ledger failures often remain internally tidy. A false merge, erased assumption, missing attack, stale surface, or correlated reviewer can produce a coherent history whose semantics are wrong. Other failures hide the cost and rejected work that produced the current view. The taxonomy therefore covers both record-integrity defects and epistemic overreach, including cases where every stored event is syntactically valid.

  1. Prose-as-database failure lets polished wording or releases become the de facto belief state while the ledger drifts.
  2. Identity aliasing treats similar wording, embeddings, citations, addresses, or keys as the same claim despite material semantic differences.
  3. Semantic-merge laundering transfers evidence or support across broader, narrower, disputed, or conditionally equivalent variants.
  4. Assumption erasure omits definitions, quantifiers, population, environment, exceptions, or contested premises that determine meaning.
  5. Contradiction deletion or averaging removes attacks, dissent, residuals, or minority evidence when prose or aggregate confidence changes.
  6. Belief inertia leaves stale claims active after expiry, failed replication, changed conditions, revocation, or a stronger accepted contradiction.
  7. Promotion laundering lets extraction, provenance, citation, consensus, proof syntax, verification activity, or completeness raise support without an accepted transition.
  8. Monotonicity theater assigns convenient contradiction ranks and cites an internally consistent response order as evidence of correct detection.
  9. Dependency-repair sprawl rewrites unrelated claims, hides omitted affected nodes, loops over cycles, exceeds authority, or claims local completeness.
  10. Ontology drift changes identity or meaning without migration, collision handling, rollback, or a preserved prior view.
  11. History overwrite loses rejected proposals, earlier evidence, reasons, contradictions, or residuals through mutation, compaction, or replay.
  12. Surface drift leaves chapters, appendices, reader or audio editions, APIs, caches, indexes, releases, or runtime consumers on inconsistent versions.
  13. Stale-view reuse serves an expired or superseded claim after a material source, model, evaluator, environment, authority, rights, threat, or outcome change.
  14. Provenance and citation laundering treats lineage, source proximity, quotation, retrieval, or citation density as truth, entailment, integrity, permission, or complete support.
  15. Self-judge and evaluator laundering lets shared models, prompts, data, code, organizations, or incentives propose and validate the same change.
  16. Concurrent lost update accepts stale-base edits, non-idempotent retries, silent last-writer-wins merges, or forked histories without reconciliation.
  17. Revision and cost survivorship hides false merges and splits, rejected updates, abandoned repairs, unsynchronized surfaces, human work, privacy exposure, delay, and opportunity cost.
  18. Portability theater treats one fixture, ontology, corpus, language, model, domain, organization, evaluator, or horizon as general revision evidence.

39.11 Minimum Viable Implementation

The current minimum is an authored append-only record-and-route refinement:

  • public claim_record, belief_revision_record, and contradiction_revision_lifecycle_record schemas and fixtures;
  • five valid and seven rejecting claim-ledger revision fixtures at experiments/claim_ledger_revision/results/2026-07-02-local.md;
  • one bounded five-project contradiction/revision lifecycle and eleven rejecting mutations;
  • AsiStackProofs.ClaimLedgerRefinement, a reachable idle/proposed/appended/ materialized/acknowledged lifecycle with 22 explicit route cases and 27 theorem declarations; and
  • an independent executable consumer that recomputes both input suites, executes the four-event witness, and rejects all 34 mutations of identity, versions, heads, same-digest proposal payload, authority, contradictions, history, residuals, dependencies, migration, event order, and surface acknowledgment.

The refinement proves exact represented claim-identity custody and zero external effects for every successful event list, one-version/one-append accounting, composition across event batches, terminal closure, owner-gated upward support records, full proposal-payload custody, contradiction blocking, and exact final acknowledgment. Sixteen weak baseline declarations were physically retired with frozen lineage; four small prior- history and contradiction lemmas remain bounded. These results establish neither natural claim identity, semantic equivalence, extraction or assumption completeness, evidence or contradiction correctness, dependency discovery, concurrent persistence, ontology fidelity, natural surface consistency, useful belief revision, safety, or transfer.

The next honest minimum must freeze a public natural multi-surface corpus with accepted gold claim identities, scopes, assumptions, variants, evidence and attacks, contradiction states, dependency closures, ontology migrations, concurrent revisions, surface obligations, and delayed outcomes. It must compare no-ledger, citation/provenance, version-control, event-sourcing, truth-maintenance, retrieval/self-critique, behavioral-test, human-editorial, and governed-ledger routes under matched resources. Independent evaluators must label identity, semantic relation, false merge and split, assumption retention, contradiction, repair reachability, stale surfaces, useful downstream effects, false promotion and downgrade, privacy, latency, human work, and total cost. Reproduction from locks and transfer to a second model, domain, ontology, language, and evaluator implementation are required before promotion.

39.12 Mature Research Target

A mature Claim Ledger is an independently testable epistemic version-control and change-propagation plane for natural and formal claims. It maintains durable semantic identity and append-only revision across publication and runtime surfaces while leaving truth, evidence adequacy, formal validity, review competence, authority, and release with their proper owners.

On prospectively frozen natural workloads, it must outperform strong citation, provenance, version-control, event-sourcing, truth-maintenance, retrieval/self-critique, behavioral-test, and human-editorial baselines on joint claim-identity precision and recall, semantic merge and split error, assumption retention, contradiction discovery and preservation, dependency-repair accuracy, stale-state prevention, surface consistency, calibrated uncertainty, useful downstream decisions, false promotion and downgrade, latency, privacy, human work, and total cost.

Each mechanism needs a predicted causal signature under matched ablation, clean replay from locks, and independent cross-model, cross-domain, cross-ontology, cross-language, cross-organization, and temporal transfer. Otherwise the exact claim remains argument, narrows to record conformance, records a null or negative result, is refuted, or is deprecated rather than becoming a claim that the stack manages belief correctly.

The strongest result would retain its advantage when claim wording, ontology, publication surface, evaluator implementation, and revision order change together. Its audit would include every rejected merge, missed dependency, conflicting update, stale surface, privacy exposure, and repair burden alongside successful revisions. That joint record distinguishes a durable improvement in belief maintenance from a cleaner interface around the same editorial outcome.

No current result meets this belief-maintenance endpoint; support remains argument until natural claims, independently labeled semantics and effects, causal ablations, complete costs, reproduction, and transfer pass.

39.13 Codex test plan

Test Purpose Status
Claim and belief-revision fixture validation Check that claim and belief-revision fixtures match their public schemas and preserve support state, evidence refs, defeaters, uncertainty, review status, and history refs. implemented by protocol validation; validated locally
Claim extraction test Check that prose claims can be represented separately from prose with labels, support states, and provenance. planned; not run
Contradiction detection test Check that contradiction refs remain linked instead of being overwritten. implemented only as synthetic claim-ledger revision fixture discipline; no open-domain contradiction detection-quality claim
Claim update and belief-revision record predicates Check that finite claim updates preserve prior evidence and revision-history references, and that modeled belief-revision records preserve claim identity, support-state fields, revision reasons, history, and non-claim boundaries. implemented in AsiStackProofs.ClaimLedger; builds locally
Open-contradiction promotion block predicate Check that an open contradiction blocks claim promotion until handled, including modeled belief-revision records that must record a blocked ledger effect. implemented in AsiStackProofs.ClaimLedger; builds locally
Claim ledger revision lifecycle route Check that modeled revision requests route missing claim identity, missing support-state records, unsupported promotion, open contradictions, history loss, missing non-overwrite attestations, surface-sync gaps, split-history gaps, downgrade-reason gaps, residual gaps, non-claim-boundary gaps, and complete revisions to explicit finite outcomes. implemented in AsiStackProofs.ClaimLedger; no open-domain extraction, semantic-equivalence, contradiction-quality, or deployed belief-engine claim
Semantic variant and assumption-context fixture Check that semantic variants merge only when scope and support-state effect stay unchanged, contested assumption contexts split or route instead of being erased, and unsynchronized variant surfaces block merge. implemented in python3 scripts/validate_claim_ledger_revision.py with 5 valid fixture(s), 7 expected-invalid fixture(s), and result record experiments/claim_ledger_revision/results/2026-07-02-local.md; no semantic-equivalence proof, assumption-context completeness proof, contradiction-quality claim, deployed belief-engine claim, or support-state promotion
Belief revision engine test Check that support-state updates over extracted claims preserve prior evidence and revision history. synthetic fixture discipline implemented; deployed belief-revision engine not implemented
Historical-project contradiction/revision lifecycle Check state separation, monotone weak/medium/strong responses, strong-evidence downgrade/split, supersession, exact bounded repair, ontology migration, residual conservation, restart persistence, and no fixture promotion. implemented by python3 scripts/validate_contradiction_revision_lifecycle.py with one bounded five-project record and eleven expected-invalid mutations; no open-domain detector, deployed belief engine, ontology-correctness, or support claim
Append-only Claim Ledger and evidence-owner refinement Check exact base/version/head and full pending-proposal binding, arbitrary-run append-only accounting and custody, evidence-owner handoff, contradiction blocking, same-digest payload substitution, dependency and migration receipts, materialization, and exact surface acknowledgment. implemented by python3 scripts/validate_claim_ledger_refinement.py: exact 27-declaration theorem surface, 5/7 and 1/11 source suites, five stages, 22 route cases, and 34/34 rejected mutations; authored finite lifecycle only and support-state effect none

Fixture-shape validation, synthetic revision fixtures, semantic-variant and assumption-context controls, and the append-only finite lifecycle are implemented. The remaining tests require natural claim extraction, contradiction-quality and semantic-equivalence evaluation, assumption-context completeness review, a concurrent persistent event store, natural multi-surface repair, delayed outcomes, matched baselines, causal ablations, reproduction, and transfer.

39.13.1 Formalization hooks

Tag Module Target Status
lean:claims.ledger.operational_invariant AsiStackProofs.ClaimLedgerRefinement Every accepted step and arbitrary successful run preserve durable claim identity, zero external effects, and exact ledger-version/append-count balance; an authorized append advances both counters exactly once. implemented
lean:claims.ledger.failure_blocks_promotion AsiStackProofs.ClaimLedgerRefinement Stale bases, ledger self-approval, digest or same-digest payload substitution, open contradictions, missing evidence-owner receipts, and incomplete custody block append or exact acknowledgment. implemented
lean:claims.ledger.revision_lifecycle_route AsiStackProofs.ClaimLedgerRefinement A reachable propose-append-materialize-acknowledge lifecycle binds the full pending proposal, exact versions, history, dependencies, ontology migration, residuals, and surface receipts; successful event batches compose and acknowledged states are terminal. implemented
lean:claims.ledger.semantic_assumption_fixture_bridge AsiStackProofs.ClaimLedgerRefinement An independent consumer compiles the exact 27-declaration surface, covers 22 route cases, consumes the exact 5/7 revision suite and 1/11 five-project lifecycle, and rejects 34 mutations without support movement. implemented

AsiStackProofs.ClaimLedgerRefinement contains 27 declarations backing all four public targets. General theorems cover one-step and arbitrary-run identity, external-effect, and append-accounting preservation, event-batch composition, terminal closure, exact proposal-payload commitment, typed blocking and handoff conditions, and a full reachable witness. Explicit countermodels show that stale bases, self-approval, contradictions, missing receipts, same-digest action, semantic, ontology, support, or owner-receipt substitutions, and premature acknowledgment do not pass. Sixteen baseline projection or finite-normalization declarations are absent from the live corpus and preserved only in the rationalization lineage; four small legacy lemmas remain reusable at their narrow scope.

This proves only the represented authored lifecycle. Stronger claims still require typed natural semantics, actual concurrent artifacts and event histories, independent labels and implementations, causal ablations, delayed outcomes, complete costs, reproduction, transfer, and accepted evidence transitions.

It does not prove natural semantic identity, evidence quality, contradiction discovery, concurrent storage, useful belief revision, safety, deployment, or chapter-core support.

39.14 Source crosswalk

Source ID Title Layer Planned use Readiness
reflexive_router_whitepaper The Reflexive Router pre_deliberative_reflexive_routing_control_plane Chronicle separation of events, states, claims, plans, predictions, and counterfactuals; valid/transaction time; correction, contradiction, poisoning, and consumer invalidation. source note available
spinoza Proof of Belief / The Spinoza Architecture reasoning_epistemology Neurosymbolic belief, transparent axiomatic AI belief systems, verification, belief revision. source note available; local raw cache available
viea Verified Intent-to-Execution Architecture whole_stack_execution_spine Keystone source. Human intent -> command contracts -> artifacts -> routing -> runtime targets -> verification -> deployment -> feedback. source note available; local raw cache available
coherence_exchange The Coherence Exchange epistemic_market_synthesis Found in AI generated paper dump. Use carefully; speculative synthesis of PlanForge, Spinoza, Talos, UAT, Alignment Field. source note available; connector or recovery required
aletheia Aletheia Foundry safe_general_intelligence_lineage Safe general intelligence predecessor. Use ideas; avoid final branding if collision remains. source note available; local raw cache available
uat Unified Adaptive Tribunal evaluation_refinement Multi-AI collaborative refinement/evaluation protocol. source note available; local raw cache available
ext_agm_belief_revision_1985 On the Logic of Theory Change: Partial Meet Contraction and Revision Functions belief_revision External formal-epistemology comparator for contraction, revision, and AGM-style rational belief change. source note available
ext_truth_maintenance_system_1979 A Truth Maintenance System truth_maintenance External truth-maintenance comparator for maintaining reasons and justifications for program beliefs. source note available
ext_assumption_based_tms_1986 An Assumption-Based TMS truth_maintenance External assumption-based truth-maintenance comparator for assumption sets, inconsistent information, and context-switching boundaries. source note available
ext_alce_2023 Enabling Large Language Models to Generate Text with Citations retrieval_citation_evaluation External citation-evaluation comparator for citation support and factuality pressure. source note available
ext_self_rag_2023 Self-RAG: Learning to Retrieve, Generate, and Critique through Self-Reflection retrieval_reflection External retrieval/reflection comparator for adaptive retrieval and critique signals. source note available
ext_checklist_2020 Beyond Accuracy: Behavioral Testing of NLP models with CheckList behavioral_evaluation External behavioral-testing comparator for capability matrices and failure-preserving test design. source note available
ext_w3c_prov_o_2013 PROV-O: The PROV Ontology interoperable_provenance_model External vocabulary for derivation, attribution, revision, quotation, primary source, delegation, and invalidation relations around claims and artifacts. source note available
cca_project, moecot_manifest_project, beastbrain_project, bugbrain_project, corbens_best_model_possible_project Historical project lineage local_belief_revision_lineage Justification/lifecycle/commitment/authority separation, contradiction monotonicity, dependency repair, supersession, ontology versioning, residual retention, and restart persistence. public-safe pinned notes reviewed; one hand-authored lifecycle only, no historical runtime replay or independent replication
qcsa_whitepaper Question-Compiled Semantic Addressing semantic_addressing_control_plane Comparator separating ontology, proposition, evidence, provenance, support, contradiction, address, and permitted use in a typed hypergraph. source note available

All eighteen assigned sources have bounded mappings. They position the owner against formal belief revision, truth maintenance, provenance, citation, retrieval critique, behavioral testing, historical project lineage, and semantic addressing without importing external performance or promoting any claim.

39.14.1 Manifest source assignment reconciliation

These rows keep Claim Ledgers and Belief Revision’s manifest assignments visible at their recorded review boundary. Passage review does not establish local reproduction, performance, safety, deployment, or support-state movement.

Source Intake role Boundary
platonic_world_model Metadata-first comparator: The Platonic World Model: A Semantic Constitution for Grounded, Proof-Carrying, Self-Editing Artificial Intelligence. Corben-authored July 2026 conceptual architecture and falsifiable research program for semantic continuity through stable Form lineages, immutable semantic versions, typed Essence Contracts, six mutually constraining planes, explicit proposition-attestation-commitment-proof separation, branch-protected world dynamics, qualified grounding, semantic transactions, runtime packet compilation, and federated mappings. Existing chapters are upgraded first; no implemented substrate, benchmark result, philosophical solution to grounding, safety result, SOTA result, AGI, ASI, or support-state promotion is inferred. No passage-level source claim, local implementation, reproduction, safety, performance, deployment, support-state, or ASI result is established by this reconciliation row.
regret_engine Passage-reviewed Corben architecture source: The Regret Engine: Governed Counterfactual Learning Signals for Continual Adaptation, Prospective Risk Control, and Self-Correction in Artificial Agents. Corben-authored August 2026 conceptual architecture and research program for decision-time-fair Governed Counterfactual Regret, immutable Decision Capsules, admissible comparator contracts, sparse Regret Tensors, append-only Regret Packets, prospective regret control, regret-aware replay, regret-to-rule compilation, three update clocks, root-cause adjudication, and bounded update leases. Existing chapters are upgraded first; no implementation, experiment, reproduction, causal-identification result, formal proof, safety result, support transition, SOTA, AGI, or ASI is inferred. The bibliography and Markdown figure companions were not supplied; the DOCX embeds its visual material. All propositions, algorithms, experiments, and architecture claims remain proposed rather than independently validated. No local implementation, reproduction, performance, safety, deployment, support-state, or ASI result is established by this reconciliation row.

39.15 Summary

Claim Ledgers owns durable claim identity, append-only belief-state transition, bounded dependency repair, ontology migration, and surface acknowledgment. It records what changed, why, under whose authority, from which base, with which evidence and review refs, across which dependents and surfaces, at what cost, and with which residuals.

The current repository proves a bounded authored append-only lifecycle and its authority boundary. It does not show that natural claims are identified correctly or that belief revision improves decisions. The next proof step is a matched natural multi-surface campaign with independent semantic and outcome labels, concurrent revisions, ontology change, causal ablations, complete costs, reproduction, and transfer.

Even a semantically coherent ledger cannot verify a high-value claim. Its current version becomes an input to Proof-Carrying Claims and Adversarial Review, which owns the separate property, verifier, and tribunal envelope.

39.16 Evidence reconciliation (2026-07-16)

The invariant protocol, field meanings, and inference limits are stated once in Living Book Methodology. This packet contains only the chapter-specific projection; its authoritative per-atom rows are the claim-ledgers-and-belief-revision slice of experiments/claim_family_terminal_coverage/results/result.json.

The core remains narrowed after full attempt at argument support. The strongest family attempt was Situated world-model acquisition and consolidation campaign. Its exact boundary is: Bounded finite POMDP result only; no open-world truth, general memory transfer, deployment, or chapter-core promotion. Across 73 atoms, the terminal ledger records 72 blocked_after_full_attempt; 1 narrowed_after_full_attempt.

Chapter-specific field Value
Family / atom denominator CF-04 / 73 atoms
Terminal dispositions 72 blocked_after_full_attempt; 1 narrowed_after_full_attempt
Core claim-ledgers-and-belief-revision.core: narrowed_after_full_attempt at argument
Core attempted / missing lanes source-synthesis / causal, empirical, executable, formal, normative, transfer
Attempted local lanes source-synthesis
Missing or unproved lanes causal, empirical, executable, formal, normative, transfer
Strongest family bundle Situated world-model acquisition and consolidation campaign (natural_work_and_end_to_end): Two partially observed environments, 11,250 episodes, 6,000 held-out episodes, six directional ablation signatures, and governed replacement/rollback.
Negative controls ten arms; six matched ablations; ten laundering mutations; replacement and rollback checks.
Accepted transitions v1_0_pilot.claim_ledgers.no_change
Maximum inference Bounded finite POMDP result only; no open-world truth, general memory transfer, deployment, or chapter-core promotion.
Reproduction / next burden Replay scripts/validate_p4_m8_world_model_campaign.py and scripts/validate_claim_family_terminal_program.py; fill the named atom-specific lanes under a new prospective protocol.

39.17 Handoff

Claim ledgers preserve belief identity, but high-value claims still need stronger artifacts than ordinary notes when promotion would affect planning, governance, benchmarks, or external action. Proof-Carrying Claims and Adversarial Review raises that boundary. It turns selected claims and high-risk artifacts into proof-carrying, justification-carrying, or tribunal-review envelopes with required tiers, verifier results, downgrades, timeouts, mismatches, dissent, and explicit refusal paths.