# Post-v2.3 Evidence Competence, Transfer, and Publication Roadmap

Status: **active canonical successor**  
Activated: 2026-07-16  
Substantively revised: 2026-08-13
Authority: Corben Sorenson  
Machine status: `roadmap_records/post_v2_3_maintenance_transfer_and_publication_status.json`  
Experiment authority: `docs/claim_bearing_experiment_competence_standard.md`

## 2026-08-10 editorial product architecture and semantic-migration amendment

The final editorial review of current `main` at
`ce5b6181ff923e6183c52e7d78d16657ed289e18` identifies a real abstraction
failure: the repository preserves distinct research owners correctly, but the
public architecture reference and human narrative still present universal
contracts, domain deployments, experimental mechanisms, implementation cases,
and research administration too much like peer chapters. This amendment
accepts the product-separation diagnosis and supersedes the earlier conclusion
that low textual similarity meant no chapter-level consolidation was needed.
The tf-idf result remains useful evidence against concatenating prose; it does
not establish that every owner deserves equal publication status.

The governing instruction is: **retire standalone peer status, not the
research**. The 87 stable chapter IDs remain the lossless research graph. The
editorial target is 54 primary architecture chapters plus two implementation
and method chapters, seven deployment profiles, five research-dossier source
owners compiled into two visible dossiers, one generated research-registry
owner, and a 26-unit independently authored human narrative. These counts are
an exact migration target, not a quality metric: any proposed move that fails
the semantic-custody gate stays separate under a dated amendment rather than
being forced through to satisfy a number.

The P7 book packet, `P7.1-EM`, is terminal through EM4. The active
object-level packet is the second contribution exit-ladder attempt, `C2-EL`,
frozen before proposal admission as `C2-EL-claim-state-proposal-001`; the book
slot is now empty under the existing two-slot WIP limit. This does not reopen
the terminal P5-U1 retrospective slice, open an empirical denominator, authorize new proof
families, require external-human prepublication review, or change claim
support. The 22-unit product remains an immutable historical candidate; the
26-unit replacement has passed the EM4 HTML cutover gates.

### Chapter-retention and local-delta gate

A chapter remains a primary architecture owner only when the editorial packet
can identify most of the following without borrowing from a neighbor:

1. a stable owned object or artifact;
2. a distinct governed transition or decision;
3. an irreducible consequential failure that would otherwise lose an owner;
4. reuse across materially different implementations or domains;
5. a boundary that its strongest neighbor cannot absorb without collapsing
   meaning, authority, or lifecycle; and
6. a falsifiable exit condition that could narrow, merge, profile, or retire
   the layer.

Every retained primary chapter must expose a concise **Local delta beyond the
governed-cognition pattern** naming its owned object, transition, added fields,
unique invariants, unique failures, strongest neighboring owner, and exit
test. Failure to name a real delta triggers merge/profile/dossier review; it
does not trigger invented differentiation. A deployment-specific consequence
becomes a profile. An experimental mechanism family behind an existing
interface becomes a dossier. Research-project administration becomes generated
back matter.

The migration must preserve these separations even while nearby prose is
compressed: Stable Capability Fields versus Capability Replacement; Virtual
Context versus Durable Semantic Memory versus Procedural Memory; Planning
versus World Models versus Cognitive Compilation; Evidence States versus Claim
Ledgers versus Safety Cases; Objective Formation versus Inner Alignment;
Artifact Graphs versus Runtime Adapters versus Procedural Memory; and Recursive
Improvement versus Autonomous Replication.

### Exact proposed disposition

The 18 peer-status consolidation hypotheses are not semantic deletions. The
final ownership review against the current manuscripts, proof modules, source
queues, and the June 30 consolidation record finds zero open semantic merge
candidates and 18 publication or method-detail nests. A publication nest
removes equal top-level weight from the public architecture and human
narrative while preserving the child as a canonical technical owner and
stable detail route. It does not transfer the child's claim support, proof
scope, evidence, or authority to the family destination.

| Technical owner | Family destination | Mode | Boundary that must survive consolidation |
|---|---|---|---|
| `adversarial-machine-learning-and-model-attack-surface` | `security-kernel-and-digital-scifs` | `publication_nest` | Preserve the model-threat contract and training/inference attack-defense lifecycle; the kernel continues to own reference monitoring and privileged effects. |
| `confidential-and-verifiable-ai-computation` | `privacy-data-rights-and-information-flow-governance` | `publication_nest` | Preserve protected-execution statements, trust anchors, verifier policy, leakage, and freshness; privacy continues to own purpose, rights, flows, and remedy. |
| `ai-supply-chain-integrity-and-lifecycle-provenance` | `model-weight-custody-and-hardware-roots-of-trust` | `publication_nest` | Preserve the typed multi-asset dependency and provenance graph; weight custody continues to own model-family possession, loading, keys, attestation, and retirement. |
| `human-ai-communication-persuasion-and-epistemic-security` | `human-factors-and-meaningful-control-in-oversight` | `publication_nest` | Preserve the outbound communication and correction transaction; human factors continues to own operator knowledge, time, attention, authority, and intervention. |
| `moral-uncertainty-and-value-conflict` | `constitutional-alignment-substrate` | `publication_nest` | Preserve plural value profiles, dissent, contestability, appeal, and non-settlement; the constitution continues to own protected commitments and amendment constraints. |
| `societal-resilience-and-misuse-defense` | `institutions-international-coordination-and-public-legitimacy` | `publication_nest` | Preserve resist-absorb-recover-adapt operations and harmed-party routes; institutions continues to own mandate, jurisdiction, participation, legitimacy, and international coordination. |
| `human-intent-as-a-formal-input` | `intent-to-execution-contracts` | `publication_nest` | Preserve ambiguity, authority extraction, clarification, bounded defaults, re-contract, and stop conditions; command contracts continue to own typed lowering and executable dispatch conditions. |
| `context-transactions-snapshots-mounts-and-taint` | `virtual-context-abi` | `publication_nest` | Preserve dynamic transaction, snapshot, mount, taint, commit, rollback, and concurrency semantics; the ABI continues to own static addressability, representation, and typed context objects. |
| `white-box-evidence-interpretability-and-activation-governance` | `adversarial-evaluation-sandbagging-and-training-time-deception` | `publication_nest` | Preserve internal-evidence methods, construct validity, interventions, activation custody, and method-specific limits; adversarial evaluation continues to own behavioral challenge and evaluation-integrity protocols. |
| `human-ai-organizations-delegation-and-accountability` | `ai-work-surfaces-agent-harnesses-and-organizational-absorption` | `publication_nest` | Preserve organizational responsibility chains, accountable owners, review, recourse, and residual duties; work surfaces continues to own abstraction-layer absorption and harness transitions. |
| `multi-agent-dynamics-collective-intelligence-and-systemic-risk` | `inter-stack-protocols-identity-and-economic-exchange` | `publication_nest` | Preserve population dynamics, conflict, collusion, emergence, and gradual disempowerment; inter-stack protocols continues to own identity, delegation, exchange, receipts, and dispute mechanics. |
| `artifact-steward-agents-and-living-project-governance` | `living-book-methodology` | `publication_nest` | Preserve general artifact-steward work, continuity, maintenance, and retirement contracts; Living Book Methodology remains the reflexive book-specific implementation and publication method. |
| `open-weight-release-and-post-release-control` | `model-weight-custody-and-hardware-roots-of-trust` | `publication_nest` | Preserve the irreversible authority-loss transition, marginal/cumulative release case, derivatives, and post-release limits; custody continues to own controlled possession before release. |
| `fast-generation-architectures` | `resource-economics-and-token-budgets` | `method_detail_nest` | Preserve generation-family mechanisms, cache objects, exactness, fallbacks, and matched comparisons as a technical method dossier; resource economics owns the complete cost and allocation decision. |
| `governed-deliberation-and-test-time-scaling` | `resource-economics-and-token-budgets` | `publication_nest` | Preserve branch, stopping, verifier, dissent, and answer-change control; resource economics owns budgets and opportunity cost, not deliberation policy. |
| `rankfold-neuralfold-and-artifact-compression` | `compact-generative-systems-and-residual-honesty` | `method_detail_nest` | Preserve the specific transform, protected-observable, residual, fallback, and evaluation contracts as a technical method dossier; Compact Generative Systems owns the general reconstruction and residual-custody architecture. |
| `open-ended-improvement-engines` | `recursive-self-improvement-boundaries` | `publication_nest` | Preserve generator-evaluator-archive campaign search and open-endedness failures; RSI continues to own qualification, promotion, rollback, and self-referential authority. |
| `prototype-roadmap` | `project-theseus-as-report-first-implementation-reference` | `publication_nest` | Preserve the evidence-gated phase-unlock controller, dependency graph, evaluator gates, phase debt, rollback, residuals, 37-declaration proof program, and URL beneath the report-first implementation reference; Theseus evidence-packet currentness remains a separate predicate. |

`publication_nest` and `method_detail_nest` are navigation and composition
decisions, not statements that the destination semantically owns every child
mechanism. `prototype-roadmap` failed the one-skeleton losslessness test: the
phase-unlock controller and the Theseus evidence packet retain distinct owned
objects, acceptance predicates, proof programs, and strongest failures. The
family is therefore composed as a publication nest with no semantic deletion.

The seven deployment profiles are Military AI and Strategic Stability
(`military-ai-autonomous-weapons-and-strategic-stability`), Embodied Agency and
Physical Safety (`embodied-agency-real-time-control-and-physical-safety`),
Neurotechnology and Cognitive Sovereignty
(`human-ai-symbiosis-neurotechnology-and-cognitive-sovereignty`), AI
Deployment, Distribution, and Human Agency
(`ai-deployment-transition-distribution-and-human-agency`), Scientific
Discovery and Experimental Governance
(`scientific-discovery-and-experimental-governance`), Content Authenticity and
Synthetic-Media Integrity
(`content-authenticity-watermarking-and-synthetic-media-integrity`), and
Personal and Federated Edge Intelligence
(`personal-compute-hives-and-federated-edge-intelligence`).

The two visible research dossiers are **Experimental Mathematical and
Relational Substrates**, owning
`relational-dimension-compilation-and-polyadic-cognition` and
`mathematical-and-search-substrates`; and **Cyclic and Proof-Carrying
Substrates**, owning `circle-calculus-and-proof-carrying-ai-contracts`,
`coil-attention-cyclic-memory-and-recurrence-contracts`, and
`coilra-multicoil-rope-and-cyclic-mixers`. The
`open-research-agenda-and-bibliography-plan` owner becomes the generated Open
Research Registry and bibliography back matter. Project Theseus and Living
Book Methodology remain the two implementation/method chapters inside the
56-chapter main-book target. Adjudicated Persistence remains a primary
architecture owner because no other chapter owns the prior cross-surface
decision that selects whether and where an experience becomes durable causal
structure.

### 2026-08-12 recent-owner reconciliation

The product-migration baseline at `ce5b6181` contained 86 chapters and already
included Learning-Compute Topology. Adjudicated Persistence was added afterward
as the 87th owner. This reconciliation reads the exact 87-chapter input at
`90f60c9f4`; it does not relabel that input as the original review baseline.
Both recent owners have now been re-run through the six retention tests,
including their strongest neighboring owners rather than only a chapter-count
check:

| Recent owner | Disposition | Distinct object and transition | Strongest neighbors and non-merge boundary | Falsifiable exit test |
|---|---|---|---|---|
| `learning-compute-topology-and-adaptive-process-architecture` | retain as primary architecture owner | Owns LCT-IR and the causal organization of adaptive work across candidate, evaluator, integrator, archive, update, and realization topologies; owns semantic compilation from learning-process topology to a physical execution. | Governed Training owns update execution and checkpoint custody; Policy Optimization owns feedback-conditioned policy change; Resource Economics owns bills and budgets; Routing owns runtime task assignment. None owns learning-process topology or realization leakage. | Narrow to a method dossier if independent encoders cannot agree on useful topology identity, or matched-resource interventions show that the proposed topology distinctions do not change explanation, control, or outcome. |
| `adjudicated-persistence-and-the-adaptive-commit-boundary` | retain as primary architecture owner | Owns the prior Adaptive Commit Boundary from experience and lesson hypothesis to disposition, locus portfolio, realization, qualification, authority, invalidation, descendants, and residuals. | Procedural Memory, Cognitive Compilation, Data Engines, Policy Optimization, Memory, Operations, and institutions own downstream realizations. None owns the cross-surface choice of whether and where a lesson becomes durable causal structure. | Narrow or retire the compiler if competent fixed-locus or human-reviewed policies match its decision quality and recovery behavior at lower whole-lifecycle cost. |

The intervening *When Success Stops Teaching* intake did not create another
chapter. Assurance-Shift Learning and Governed Residual Boundary Learning are
cross-owner allocation and handoff rules spanning Learning-Compute Topology,
Adjudicated Persistence, Benchmark Ratchets, Policy Optimization, Data Engines,
Procedural Memory, and Resource Economics. Turning that source into a third
learning chapter would recreate the overlap this migration is intended to
remove.

The 87-owner count therefore remains correct. Future chapter intake must amend
this reconciliation in the same transaction: classify the new identity as a
primary owner, implementation/method owner, publication nest, deployment
profile, dossier owner, or generated back-matter owner; identify its strongest
neighbor and exit test; update the narrative-unit crosswalk; and derive every
count from `book_structure.json`. A chapter may not remain an unclassified
equal-weight peer merely because it passed source intake.

### Consolidation execution order

Run the 18 peer-status packages in this order. A wave advances only after its
technical children remain directly reachable, its top-level family reads as
one argument, and its identity/source/proof/test/URL reconciliation passes.

1. **Metadata and generated preview.** Classify all 87 IDs without changing
   chapter prose, URLs, or the current public route. Generate the 56-chapter
   top-level preview, profile collections, dossier surfaces, back-matter route,
   and technical-detail navigation from `book_structure.json`.
2. **Method-detail pilot.** Nest Fast Generation and Governed Deliberation
   under Cognitive Resource Economics, and RankFold/NeuralFold under Compact
   Generative Systems. This wave must prove that a technical method can leave
   the top-level spine while keeping its own mechanisms, proof module,
   evidence limits, figures, anchors, and stable detail URL.
3. **Security, privacy, and artifact custody.** Compose Adversarial Machine
   Learning with the Security Kernel; Confidential and Verifiable Computation
   with Privacy and Data Rights; and Supply-Chain Integrity plus Open-Weight
   Release with Model-Weight Custody. Keep reference monitoring, model attack
   testing, protected computation, rights, general supply-chain provenance,
   controlled custody, and irreversible release as explicit non-substitutable
   transitions inside the three family routes.
4. **Human and institutional governance.** Compose Communication and
   Epistemic Security with Human Factors; Moral Uncertainty with
   Constitutional Alignment; and Societal Resilience with Institutions. The
   family prose must not turn meaningful control into communication safety,
   constitutional constraints into moral settlement, or public legitimacy
   into operational resilience.
5. **Context, evidence, organization, and exchange.** Compose Human Intent
   with Command Contracts; Context Transactions with the Virtual Context ABI;
   White-Box Evidence with Adversarial Evaluation; Human-AI Organizations with
   Work Surfaces; and Multi-Agent Dynamics with Inter-Stack Protocols. Preserve
   the static/dynamic, internal/behavioral, organizational/interaction, and
   protocol/population distinctions as named subowners and technical routes.
6. **Improvement and stewardship families.** Compose Open-Ended Improvement
   with RSI Boundaries and Artifact Stewards with Living Book Methodology.
   Preserve campaign search versus promotion authority and general artifact
   governance versus the reflexive book implementation.
7. **Semantic-merge adjudication.** Prototype Roadmap was evaluated against
   Project Theseus after waves 1-6. The merge was rejected because preserving
   all Prototype claims, sources, Lean targets, tests, phase debts, residuals,
   and historical URL routes would retain two independent predicates instead
   of removing a full repeated skeleton. Compose it as a publication nest
   without changing the 56-chapter top-level target.
8. **Narrative and cutover.** Author the 26-unit human book from the completed
   family graph, run conclusion/claim crosswalk and legacy-route checks, record
   `support_state_effect: none`, and cut over only after render, viewport,
   accessibility, and link validation. Do not build major-version EPUB, PDF,
   DOCX, or audio before the separate content-freeze gate.

Each package is complete only when the family destination has one Problem,
Insufficiency, Mechanism, Interface, Evidence, Implementation, and Handoff
arc; shared governed-cognition boilerplate is removed; every child local delta
and strongest objection remains findable; the technical child has an explicit
top-level visibility disposition; no claim or support is inherited; every old
URL resolves; and the package can be reversed from the canonical graph without
recovering lost prose from Git history.

Display-title changes are editorial aliases only; stable IDs and claim
identity do not change. Candidate aliases include Security Kernel and
Adversarial Attack Surface; Privacy, Data Rights, and Confidential
Computation; AI Artifact Custody, Supply Chain, and Release; Human Control,
Communication, and Epistemic Security; Constitutional Alignment, Moral
Uncertainty, and Value Conflict; Institutions, International Coordination, and
Societal Resilience; Human Intent and Command Contracts; Virtual Context: ABI,
Transactions, Snapshots, and Taint; AI Work Surfaces, Organizations, and
Accountability; Inter-Stack Protocols, Collective Intelligence, and Systemic
Risk; White-Box Evidence and Adversarial Evaluation; Generative Compression
and Residual Honesty; Cognitive Resource Economics: Fast Generation,
Deliberation, and Budgets; Governed Recursive Self-Improvement: Search,
Qualification, and Release; Project Theseus: Report-First Implementation and
Prototype Roadmap; and Living Book and Artifact Stewardship Methodology.

### Canonical graph and generated products

`book_structure.json` remains the only canonical chapter and publication graph.
Phase 1 may add validated publication-role, editorial-status, parent,
legacy-ID, visibility, and preserved-claim fields there. Chapter front matter,
architecture navigation, profile and dossier collections, the narrative
crosswalk, compact status panels, and legacy redirects must be generated from
that graph. Do not create the review's six proposed JSON files as six manually
maintained sources of truth. Existing product projections may be versioned or
replaced at cutover, but they must be derivations and must fail closed when the
manifest changes.

Every legacy owner resolves exactly once and preserves its core and subclaim
IDs, source mappings, proof targets, tests, fixtures, schemas, artifact
references, non-claims, support ceiling, and old URL. A surviving parent does
not inherit the child's support. A display-title change does not become a
semantic-identity change. A redirect does not erase the legacy technical
surface. The immutable reader and release archives remain untouched.

### `P7.1-EM` execution phases

1. **EM0 — structural truth.** Replace the stale active 84- and 85-chapter
   statements in the narrative products with manifest-derived truth, make CI
   reject future count literals that disagree with the canonical graph, freeze
   the exact pre-migration commit, and record zero support/release effect.
2. **EM1 — metadata-only disposition.** Add the 87 exact roles and parent
   relationships to the canonical graph; validate disjoint 56/18/7/5/1
   disposition coverage and two implementation/method owners; generate a
   reviewable preview without changing prose or the current public route.
3. **EM2 — publication composition and semantic-merge adjudication.**
   Process one consolidation/profile/dossier cluster at a time. A publication
   or method-detail nest keeps the child as a canonical technical owner and
   stable detail route while the family destination provides one top-level
   argument and navigation entry. Preserve unique objects, claims, objections,
   failure modes, evidence exits, sources, proofs, tests, artifacts, and
   non-claims; remove shared lifecycle boilerplate; add the local delta and a
   consolidation-boundary non-claim; and produce one compact migration
   receipt. The Prototype Roadmap/Project Theseus package was the sole
   semantic-merge candidate. It failed the losslessness test and is now a
   publication nest: the parent carries the family argument while the phase
   controller remains an independently addressable technical route.
4. **EM3 — 26-unit human narrative.** Rebuild the human manuscript around the
   26-unit thesis-to-method route below, using the Human Reading Paths and the
   continuing repository-change trace as inputs. Each unit receives one compact
   generated status panel: current support, what exists, what does not, what
   would change the conclusion, and a link to technical evidence. Exact
   theorem/source/fixture counts and repeated non-claims remain in generated
   technical panels or the architecture reference rather than the reading
   path.
5. **EM4 — cutover and release.** Generate legacy landings or redirects;
   validate every claim/source/proof/test/artifact/release edge, internal link,
   role count, render, viewport, and accessibility surface; record an explicit
   editorial-migration release with `support_state_effect: none`; and only then
   replace the 22-unit candidate. Full EPUB/PDF/DOCX and audio remain deferred
   until the next major-version content freeze.

EM0 and EM1 are complete. Seven EM2 packages are complete without public
cutover. The method-detail pilot composes Fast Generation and Governed
Deliberation into Resource Economics and RankFold/NeuralFold into Compact
Generative Systems. The security/custody package composes Adversarial Machine
Learning into Security Kernel, Confidential and Verifiable Computation into
Privacy and Data Rights, and Supply-Chain Integrity plus Open-Weight Release
into Model-Weight Custody. The white-box/evaluation package composes White-Box
Evidence into Adversarial Evaluation while preserving its internal-evidence
owner. The human-governance package composes Communication and Epistemic
Security into Human Factors and Meaningful Control, Moral Uncertainty into the
Constitutional Alignment substrate, Societal Resilience into Institutions and
Public Legitimacy, and Human Intent into Intent-to-Execution Contracts. All
twelve nested routes retain local claims, sources, proofs, tests, evidence
ceilings, IDs, and URLs. The fifth package composes Context Transactions into
Virtual Context ABI, Human-AI Organizations into AI Work Surfaces, and
Multi-Agent Dynamics into Inter-Stack Protocols while preserving dynamic-state,
organizational-authority, and population-dynamics ownership. All fifteen
ordinary publication nests are now composed. The sixth package composes
Open-Ended Improvement Engines beneath Recursive Self-Improvement Boundaries
while preserving campaign search versus promotion authority, and composes
Artifact Steward Agents beneath Living Book Methodology while preserving
general project governance versus this book's reflexive implementation. The
seventh package composes Prototype Roadmap beneath Project Theseus after
rejecting a true semantic merge: report-packet currentness and phase-unlock
acceptance remain separate predicates. No semantic-merge candidate remains
open. EM3 drafting has all twenty-six maintained
Human Reader units at target length: Unit 1 is 4,503 words, Unit 2 is 4,501, Unit 3 is 5,003, Unit 4 is 5,650 words, Unit 5 is 5,553,
Unit 6 is 5,124, Unit 7 is 5,517, Unit 8 is 4,703, Unit 9 is 4,606, Unit 10 is
4,723, Unit 11 is 4,824, Unit 12 is 4,534, Unit 13 is 5,094, Unit 14 is 5,043,
Unit 15 is 5,518, Unit 16 is 5,514, Unit 17 is 5,015, Unit 18 is 5,004, Unit 19
is 5,000, Unit 20 is 5,000, Unit 21 is 6,121, Unit 22 is 5,526, Unit 23 is 5,508, Unit 24 is 4,507, Unit 25 is 5,502, and Unit 26 is 6,065, for 133,658 visible words. No unit remains
`not_started`; target-length drafting completion is not
editorial approval or release. The generated 26-unit conclusion/claim crosswalk
is also complete: all 87 owners appear exactly once with canonical claim,
source, proof, test, tracked artifact-reference, publication, support, and
technical-route edges. The first-class `/reader/` HTML projection, reciprocal
edition navigation, canonical owner-to-unit route map, and clean-render wiring
are deployed. The immutable `96a22b15e` record preserves the earlier pushed
candidate. Exact source commit `d85a1b14fd7f4277a0deb1db22b30f605f3579a8`
passed build `31747729802`, tested-artifact deployment and public attestation
`31749131391`, 100-document technical rendering, 28-document Human Reader
rendering, the 50-manuscript paper-library render, and 230 exhaustive local
desktop/mobile browser page-view pairs. Public inspection confirmed the exact
canonical status commit, `/reader/` landing, 87-owner route map, and reader
chapter route. The deployed record is
`release_records/2026-08-13-human-reader-html-cutover-d85a1b14f.json` with
`release_state: pages_deployed` and `support_state_effect: none`. EM4, P7, and
M7 are complete. External-human editing, assistive-technology review, and
major-version package/audio work remain explicitly unclaimed and do not reopen
the HTML cutover.

The 26 narrative units are:

1. ASI Is a Stack, Not a Model
2. The Efficient ASI Hypothesis
3. Authority, Failure, and Misuse
4. Security, Privacy, and AI Artifact Custody
5. Evidence States and Scalable Oversight
6. Human Intent, Control, and Epistemic Security
7. Constitutions, Moral Uncertainty, and Objective Formation
8. Institutions, Coordination, and Societal Resilience
9. Stable Capability Fields and Governed Replacement
10. Perception and Observation Trust
11. Governed World Models and Reality Grounding
12. Planning as a Control Layer
13. Cognitive Compilation and Semantic IR
14. Virtual Context and Durable Semantic Memory
15. Verification Bandwidth, Claim Ledgers, and Proof
16. Labor OS, Work Surfaces, and Organizations
17. Artifact Graphs, Runtime Effects, and Operations
18. Procedural Memory, Inter-Stack Exchange, and Multi-Agent Risk
19. Routing and Replaceable Cognitive Substrates
20. Governed Training and Learning-Compute Topology
21. Adjudicated Persistence, Generalization, Feedback, Continual Learning, and Unlearning
22. Evaluation, Readiness, Thresholds, and Structured Assurance
23. Generative Compression and Cognitive Resource Economics
24. Physical Compute, Energy, and Infrastructure
25. Recursive Improvement, Replication, and Containment
26. Integrated Reference Architecture, Project Theseus, and the Living Research Method

The titles above are the compact route. The canonical writing specification is
`docs/human_reader_26_unit_outline.md`. It divides the edition into three
parts, routes all 87 technical owners exactly once, and gives every unit a lead
owner, narrative job, central question, argument moves, cumulative
repository-change beat, strongest objection, conclusion-changing evidence,
handoff, and target-length range. The historical
`products/narrative_product_spine.json` remains the 22-unit candidate and is
not rewritten or relabeled as the 26-unit manuscript. The detailed outline is
not completed prose and does not authorize cutover.

`P7.1-EM` is complete only when all 87 legacy IDs resolve exactly once; the
54+2 main-book split, 18 peer-status consolidation relationships (16
publication nests and two method-detail nests), seven
profiles, five dossier
owners/two dossier surfaces, one back-matter owner, and 26 narrative units are
machine-validated; no evidence edge is orphaned; old URLs resolve; every
primary chapter passes the local-delta gate; the human view omits most
administrative scaffolding while technical view preserves it; all counts come
from the manifest; and the migration changes no support state by implication.

## 2026-08-10 object-level yield, scope compression, and practical-utility amendment

The [Grok red-team review](https://x.com/i/grok/share/efaecbfc739e442a9325900fcfa59d15)
correctly identifies a priority failure even though several requested remedies
already exist in this roadmap. The book has three defended contributions, an
effect-complete reference-system lane, a natural flagship, a 22-unit narrative
product, chapter roles, closest-comparator work, and an explicit rule that no
external human is a prepublication completion gate. The remaining problem is
that those object-level commitments are buried beneath a larger and more
visibly mature governance apparatus. The active execution order must make the
apparatus prove its value through useful artifacts, not through more apparatus.

| Critique | Adjudication | Binding consequence |
|---|---|---|
| Governance and evidence machinery can become process theater | **Accepted.** A validator, ledger, schema, receipt, or proof target earns maintenance cost only when it protects a named consumer from a named failure or makes an object-level result cheaper to trust, reproduce, revise, or retire. | Apply the governance-rent test below. Do not create a new meta-artifact merely to record this amendment. |
| Zero promoted chapter-core claims after extensive work is a stagnation signal | **Accepted as a diagnostic, not as a promotion quota.** Conservative labels remain correct, but an evidence system that cannot expose a bounded claim capable of moving is not serving the research. | Build explicit exit ladders for the three defended contributions and attempt one claim-commensurate bounded transition at a time. Failed gates remain failures; labels never move to satisfy a target count. |
| Formal and empirical progress trails the scaffold | **Accepted.** Aggregate theorem, source, validator, and commit counts are not progress measures. | Make a runnable effect-complete vertical slice the headline packet. Permit formal work only for a named runtime, evidence, or decision consumer. |
| Eighty-six chapters risk anthology drift and equal-weight overload | **Accepted as a product and ownership risk, not as proof that 86 is the wrong number.** Distinct reference owners may remain while the narrative becomes much smaller. | Run a role-and-overlap audit, merge only genuinely duplicate owners without losing unique claims, and make optional reference depth visibly optional. No new chapter follows from this review. |
| The public project lacks an immediately useful end-to-end stack | **Accepted.** Narrow fixtures exist, but a reader still cannot run one small representative governed transaction and compare it with simpler routes from one obvious entrypoint. | Deliver `P5-U1`, the minimal useful governed vertical slice defined below. It is an implementation and teaching artifact, not architecture-wide evidence. |
| Novelty is positioned more carefully than it is demonstrated | **Accepted.** Prior-art honesty is necessary but not sufficient. | Give each defended contribution one closest implemented comparator, one simpler baseline, one ablation, one strongest alternative explanation, and one result-dependent maximum inference. |
| Dense process language hides practical value | **Accepted.** The full reference may remain deep, but the default entry surface must answer what to run, when to use it, when not to use it, and what is actually implemented. | Deliver a fifteen-minute utility route, three task recipes, and unit-level use/avoid guidance in the narrative and live site. |
| Stars, forks, watchers, or prepublication outside review should gate quality | **Rejected.** Popularity is not evidence, and the owner has explicitly ruled out other-human prepublication review as a dependency. | Keep `external_human_prepublication_required: false`. Use separate local implementations, frozen evaluators, cold-proxy diagnostics, public reproducibility packets, and postpublication feedback without claiming they substitute for human evidence. |

### Governance-rent test

Before adding or retaining a mandatory process artifact, name all of the
following:

1. the object-level consumer that would make a different decision because the
   artifact exists;
2. the concrete failure it detects, prevents, contains, or makes reversible;
3. the ordinary author/operator action it adds and its measured time or
   compute cost;
4. the simpler existing artifact or check that could own the same obligation;
5. the trigger that refreshes it; and
6. the condition under which it is merged, automated, downgraded to history,
   or retired.

An artifact that lacks one of those fields is nonmandatory until repaired.
This amendment does not authorize a new governance ledger. Its acceptance
evidence belongs in the existing roadmap status, repository map, validator
registry, and the receipts of the object-level packet it serves. The target is
stable or lower operator steps and wall time per accepted object-level
deliverable, not a lower file count achieved by hiding obligations.

### `P5-U1` — minimal useful governed vertical slice

`P5-U1` becomes the headline packet while the larger natural P2 denominator is
resource-blocked. Reuse the existing reference architecture, artifact graph,
authority, effect, rollback, and publication-service mechanisms before adding
new machinery. From one documented command on a modest local machine, a reader
must be able to run one public-safe repository-change transaction through:

`intent -> scope/authority -> plan -> tool action -> observed effect -> tested
artifact -> receipt -> rollback or compensation -> final residual`.

The same task must run through three prospectively frozen routes:

1. direct execution with the task's ordinary tests;
2. record-only execution that captures artifacts but adds no admission policy;
   and
3. full governed admission with the stack's claimed boundaries.

The slice reports useful task success, unauthorized or out-of-scope effects,
false blocking, defect escape, latency, compute, operator steps and time,
artifact volume, recovery time, rollback or compensation closure, and residual
burden together. It includes one happy path, one blocked-authority path, one
partial-effect crash/recovery path, and one rollback-that-cannot-undo-an-
external-effect path. Each path has a byte- or state-checkable expected result
and a mutation that proves the check can fail.

This packet is deliberately smaller than the sealed P2 natural campaign. It
may improve utility, implementation coverage, and instruction quality, but it
cannot promote a natural-performance, safety, SOTA, transfer, or full-stack
claim. It is complete only when a fresh checkout can run the documented route,
inspect the artifacts, and reproduce the terminal state without reading
roadmap history.

### Contribution exit ladders without promotion quotas

For each defended contribution—governed-cognition interface contracts, public
claim-state transition discipline, and record/reality reconciliation with
residual honesty—maintain one compact exit ladder in the existing claim and
evidence surfaces. Each ladder names:

- one bounded claim slice narrow enough to test or formalize competently;
- the closest implemented comparator and the simplest credible baseline;
- a positive control and instrument-sensitivity requirement;
- one ablation that removes the contribution's distinctive mechanism;
- the strongest alternative explanation of any observed gain;
- a preregistered success, negative, and inconclusive disposition;
- the exact support ceiling and maximum inference for each outcome; and
- the next consumer that changes behavior if the result is accepted.

At most one ladder may consume the empirical/formal WIP slot at a time. A
promotion count is never an optimization target. The purpose is to make claim
movement possible when earned and reveal whether the current core claim is too
broad, not to manufacture upward transitions.

**2026-08-13 checkpoint.** All three ladders are now instantiated in the
existing generated `products/contribution_focus_contract.json`. Each carries
the eight required fields and explicit success, negative, inconclusive, and
support-ceiling dispositions. P5-U1 supplies the direct and record-only
comparators, happy-path positive control, fault paths, mutation sensitivity,
mechanism ablations, and concrete P5 campaign consumers for the
governed-cognition and record/reality ladders. The claim-state ladder compares
the full identity/competence/inference gate with shape-only JSON Schema
validation. No ladder result is promoted by this checkpoint. The first
claim-bearing attempt must remain prospective and claim-commensurate.

**2026-08-13 prospective freeze.** The first attempt is now frozen at
`experiments/c1_exit_ladder/preregistration.json` before any eligible task is
admitted. It selects exactly the next independently necessary public-safe book
maintenance defect discovered after the freeze, requires a machine-detectable
failure before the solution is known, and forbids replacement after admission.
The natural happy path stays distinct from three authored fault injections.
Direct, record-only, and full-governed routes share source bytes, task statement,
acceptance check, and resource ceiling. The protocol freezes twelve joint
outcomes, a positive control, seven instrument-sensitivity classes, success,
negative, and inconclusive dispositions, the strongest alternative explanation,
and a one-case maximum inference. Task identity, protected content, support,
and release state remain closed.

**2026-08-13 task admission.** After freeze commit
`89a4e74b769865fe3d87f81f5212c9201dd92914`, the ordinary EM4 clean HTML
render failed at `index.qmd` with exit code 1 and `ERROR: unable to open
database file`. `experiments/c1_exit_ladder/admission.json` records that exact
failure before any Quarto cache, permission, source, or candidate-fix
investigation. The matched task is to restore the unchanged 100-document HTML
acceptance check from the same source snapshot. A prior deployment-race
observation is explicitly excluded because its likely mechanism was inspected
before task admission. Protected content remains closed and no support or
release state moves.

**2026-08-13 terminal C1 disposition.** The preregistered runner invoked all
twelve trial functions, then raised a Python `NameError` while constructing
the result object because one Boolean used JSON spelling. No result file was
created, and the route outcomes are not recoverable from a durable artifact.
The attempt is therefore inconclusive for instrument failure, with no route
outcome, support effect, release effect, replacement, or rerun. The exact
failure and the prospective ceiling are preserved in
`experiments/c1_exit_ladder/results/2026-08-13-instrument-failure.json`; the
runner correction is available only to future nonprospective uses or a newly
preregistered attempt.

**2026-08-13 C2 prospective freeze.** The next exit-ladder attempt is frozen
at `experiments/c2_exit_ladder/preregistration.json` before proposal admission.
It selects the first independently necessary post-freeze claim-state proposal
and compares direct, record-only, and full-governed routes across one natural
path plus identity-mismatch, inference-overreach, and stale-projection fault
paths. The protocol fixes twelve joint outcomes, forbids proposal replacement,
and keeps protected content, support, and release state closed. The terminal
C1 failure cannot be backfilled as the C2 proposal because it was known before
this freeze.

### Scope compression and practical entry surface

The 87-chapter research graph remains the lossless technical ownership surface.
`P7.1-EM` must make it stop behaving like 87 equally weighted narrative
chapters. Preserve the current 22-unit route as historical candidate custody
while building the superseding 26-unit route and:

- publish a fifteen-minute route containing the thesis map, the three defended
  contributions, the `P5-U1` command, one happy/blocked/recovery trace, and an
  explicit implemented-versus-proposed table;
- add three task recipes—inspect a claim, run a governed change, and diagnose a
  failed or blocked transition—with inputs, commands, outputs, failure states,
  and cleanup;
- give every narrative unit a short **use this when**, **do not use this when**,
  and **what would change the conclusion** block;
- mark reference-only chapters as optional depth and keep their unique claims
  reachable through cross-links rather than repeating local status apparatus
  in the narrative;
- audit possible merges by claim, lifecycle, interface, and consumer overlap,
  not by title similarity or a desired chapter count; and
- keep source papers directly readable through the live paper library so the
  lineage from original idea to current synthesis remains inspectable.

Automated cold-proxy and fresh-context agent checks may diagnose navigation,
terminology, command reproducibility, and omitted prerequisites. They are not
human-learning evidence and must not be reported as reader approval.

### Superseding execution order

This amendment changes priority, not evidence state:

1. continuous P0 truth and fresh-checkout publication custody;
2. the first prospective contribution exit-ladder attempt as the headline
   object-level packet, using terminal P5-U1 only as bounded implementation and
   instrument-development input;
3. `P7.1-EM` metadata-first product separation, 26-unit narrative, and
   fifteen-minute route as the concurrent book packet;
4. one contribution exit ladder at a time under its preregistered success,
   negative, inconclusive, and support-ceiling dispositions;
5. P4.1 formalization only where that ladder or vertical slice names the
   theorem's runtime or decision consumer;
6. P2 natural-campaign materialization immediately when its storage and Docker
   entry gates become true; and
7. P3 separate implementation and transfer after a result warrants broader
   inference, without adding an external-human prepublication gate.

The work-in-progress limit remains two: one object-level implementation or
evidence packet and one book/narrative packet. Manim remains separately owned.
No chapter, proof family, validator family, campaign, or status surface may be
opened merely to make the project look active.

## 2026-08-02 Constitutional predicate proof-to-system boundary

The book-local Constitutional Alignment lane now proves subset refinement,
transitive no-reintroduction, exact prior-set rollback, concrete widening
rejection, and scalar-count non-identifiability for a finite two-predicate
migration model. Its independent consumer exhausts all sixteen prior/candidate
pairs. This is a representation and transition result over authored fields; it
does not establish predicate meaning or completeness, legitimacy, reviewer
competence or independence, material rights usability, effect-complete
rollback, deployed conflict handling, alignment, or safety. Route those open
claims to normative review, prospective empirical evaluation, and Project
Theseus integration. Reopen Lean only for a materially richer predicate,
descendant-preservation, or compositional semantic model.

## 2026-08-02 Human Intent proof-to-system boundary

The book-local Human Intent proof tranche now has a finite information-loss
boundary as well as lifecycle custody. `AsiStackProofs.IntentResolutionRefinement`
proves that a thin four-field lowering collapses distinct ten-field intents,
that no decoder can recover both collision witnesses, and that the modeled
full lowering is injective. It also imports the static router and proves that a
thin two-field lifecycle transport collapses compile-versus-clarify and
compile-versus-review records, that no router over the conflict transport can
recover both routes, and that a complete seven-field transport round-trips, is
injective, and preserves the static route. Its independent consumer reconstructs
all six omitted command-field collision classes and both route-changing
transport collisions, and rejects mutations to all ten command fields and all
seven complete transport fields, in addition to the existing lifecycle traces
and mutations. This closes the current Lean obligation for modeled
representational preservation without promoting chapter support.

Do not spend book-local proof cycles pretending that these finite records can
settle natural-language meaning, authentic authority, informed consent,
affected-party standing, prompt-injection containment, deployed lowering,
runtime stop-condition preservation, useful assistance, or effect safety.
Those are empirical, integration, or whole-system obligations. Route them to
prospectively frozen evaluations and Project Theseus, preserving exact model,
field, authority, consumer, and non-claim boundaries in every returned
artifact. Reopen Lean here only for a genuinely richer formal semantic model
or a newly identified book-local invariant.

## 2026-08-03 contraction, composition, and product-separation amendment

An external extreme-detail review inspected current `main` at `61c74d6`. It is
advisory evidence about project direction, not source evidence, independent
reproduction, a support transition, or publication approval. Its central
diagnosis has teeth: the architecture reference, narrative book, and evidence
registry are now distinct products, but local formal and editorial expansion
has outrun human readability, cross-owner assurance, and natural comparative
evidence. This amendment supersedes later scheduling language where it
conflicts; historical receipts remain immutable.

The review also repeats work already present and therefore does not reopen it:
the 22-unit narrative spine, 84-chapter role partition, noninheritance thesis,
Governed Transition Calculus, P0-P6 semantic overlay, consumer-linked proof
custody, bounded-liveness framing, natural repository-change flagship, three-
product distinction, and major-version-only EPUB/audio policy remain canonical.
No duplicate packet is authorized for those surfaces.

### Adjudicated findings

| Finding | Disposition | Binding response |
|---|---|---|
| Noninheritance is the intellectual center. | accepted, substantially implemented | Make the positive property-transfer rule and five-contribution public novelty surface explicit in the opening, four part introductions, integrated architecture, conclusion, public synopsis, and future derivative-paper plans. Do not reduce the thesis to the weaker slogan that ASI is merely modular. |
| One scalar support ladder hides different kinds of progress. | accepted, new work | Preserve the conservative public support state, but add a claim-kind maturity vector with `normative`, `formal`, `implementation`, `empirical`, `external_reproduction`, `operational`, and `institutional` dimensions. Each dimension needs an owner, admissible transitions, noninheritance rules, and a projection into Appendix C and public status. A formal advance cannot move an empirical or institutional coordinate. |
| Repeated chapter status prose has drifted. | accepted, confirmed defect | Make `book_structure.json` plus chapter front matter the canonical state owner and generate the visible status block. The first repair must reconcile the confirmed SCF 8/9 source mismatch, stale Verification Bandwidth and Circle dates, stale Multi-Agent maturity, and the Verification Bandwidth zero-model-scaffold versus later model-campaign wording. Add a validator that rejects manually repeated maturity, date, source count, evidence state, proof count, test state, or open-gap values that disagree with their owner. |
| The full reference is valuable but reads as if every owner has equal architectural necessity. | accepted | Keep every current-manifest reference owner, expose mandatory core, assurance-plane, institutional, optional implementation, implementation-case, speculative/frontier, and methodology roles in navigation, and present the architecture as four planes: governed cognition, assurance, lifecycle/improvement, and social/institutional environment. Candidate substrates sit beneath those planes as implementations or research frontiers. |
| No-deferral can become ontology inflation. | accepted with correction | Immediate disposition remains mandatory; core-chapter admission does not. For one full evidence cycle, new ideas route first to an existing owner, reference annex, research frontier, standalone paper, evidence backlog, or explicit rejection. A new core owner requires a dated proof that no current owner can preserve the interface/lifecycle and a merge/consolidation analysis. |
| The Human view is still a filtered reference, not a finished narrative. | accepted, high priority | Compose an independently authored human manuscript from the 22-unit spine instead of requiring each reference chapter to appear as prose. Preserve every major conclusion through the crosswalk, not every local status table or field list. Target roughly 120,000-180,000 words for the technical narrative and create a 25,000-40,000-word primer only after that manuscript stabilizes. Keep the 400,000-plus-word reference intact. |
| Local theorem volume can overstate assurance. | accepted, partially implemented | Continue semantic P0-P6 accounting, remove declaration count as a headline progress signal, report unique semantic invariants and actual consumers, and admit no new theorem family without a consumer, prevented failure, model boundary, refinement route, counterexample, maintenance owner, and retirement condition. Centralize generic envelope/noninheritance results only when dependency-safe; chapter modules keep unique semantics. |
| Cross-owner and distributed composition is now the main formal/system gap. | accepted, high priority | Prioritize authority conservation, evidence non-escalation, identity/epoch coherence, typed residual conservation, effect/observation separation, revocation closure, bounded liveness, and recovery honesty across connected owners. Exercise stale authorization, grant double-spend, split brain, duplicate execution, partial effects, revocation races, conflicting observations, evaluator capture, quarantine starvation, and rollback illusion. Lean owns exact local/compositional laws; state exploration and Project Theseus own executable, concurrent, and whole-system behavior. |
| The empirical program is too broad to validate chapter-by-chapter. | accepted | Concentrate natural comparative work on five candidate contributions: governed transition discipline, semantic IR/localized repair, governed context/memory, Stable Capability replacement qualification, and Verification Bandwidth. Take one mechanism to a terminal result before opening another protected denominator. Match direct, structured, conventional-workflow, full-stack, ablation, and oracle-assisted conditions where the claim permits. |
| Evidence artifacts and accepted transitions can be mistaken for independent evidence. | accepted | Separate object-level empirical, formal-model, implementation-state, external-reproduction, repository/meta-validation, no-support, rejection, downgrade, and revocation lanes in public status. Track author, institution, dataset, evaluator, model-family, code, infrastructure, and runtime-environment dependence. Artifact count never substitutes for independent support. |
| Residuals need a canonical taxonomy. | accepted | Type residuals at least as epistemic, semantic, authority, rights, evaluation, observation, operational, rollback, institutional, temporal, and resource. A residual may propagate, narrow, be discharged by evidence, be explicitly accepted by authorized ownership, or block; transformations may not silently erase it. |
| Authority fields can launder legal or political legitimacy. | accepted | Classify authority domains (`user`, `organizational`, `technical`, `contractual`, `legal`, `institutional`, `emergency`, `research`) and classify conditions as machine-checkable, human-reviewed, institutionally adjudicated, externally observed, legally determined, politically contested, or currently unknowable. A schema-valid technical token may record but cannot create legal authority or legitimacy. |
| External grounding is broad but not yet closest-prior-art synthesis. | accepted | Build focused closest-prior-art matrices for five public signature contributions: Governed Transition Calculus/noninheritance, Stable Capability Fields, support-state plus residual conservation, Verification Bandwidth/lifecycle economics, and record-reality reconciliation. Distinguish author lineage from independent corroboration. Paper-depth verification is required before prose or evidence use. |
| External specialist review is missing. | accepted as nonblocking scrutiny | Prepare domain-specific review packets for formal methods, distributed systems, security/capability systems, human factors, law/institutions, AI evaluation, privacy/civil rights, and multi-agent economics. Preserve objections and responses. Routine work does not wait on outreach; broad claims still require independent reproduction or specialist authority appropriate to the claim kind. |
| One repository-change example can overfit the architecture. | accepted for sequencing, not simultaneous execution | Keep repository change as the first instrumented flagship. After it reaches a terminal result, add one embodied/real-time case and one institutional-decision case; a scientific-discovery case remains optional. Do not open three expensive campaigns concurrently. |

### Superseding execution sequence

1. **Canonical truth first.** Repair the confirmed repeated-status drifts and
   implement generated status blocks before more chapter-local status editing.
   Freeze elective ontology growth under the immediate-disposition rule.
2. **Finish the proof program by semantic leverage.** Complete chapter
   classification, retire or generalize duplicate local theorem families, and
   prioritize connected composition invariants and the distributed fault
   matrix. Keep `support_state_effect=none` unless an exact governed transition
   authorizes a narrow formal atom.
3. **Build the narrative as its own maintained source.** Use the 22-unit spine,
   one continuing repository-change trace, and chapter-specific objections to
   write a 120,000-180,000-word human manuscript. The reference remains the
   machine/research product; the narrative and reference are parallel but
   unequal sources joined by a coverage and claim-identity crosswalk.
4. **Run one decisive natural campaign.** When the existing P2 resource gates
   open, take the governed repository-change flagship to a terminal positive,
   negative, mixed, or inconclusive result with matched baselines, costs,
   false-blocking, recovery, and useful-throughput measures. Do not let new
   documentation, theorem count, or derivative rendering displace it.
5. **Externalize only earned claims.** Complete the five closest-prior-art
   matrices, package unresolved objections, and attempt materially independent
   reproduction before broadening a mechanism claim or novelty claim.
6. **Open release work only after content satisfaction.** EPUB, PDF, DOCX, and
   audio remain dormant during ordinary edits. A major-version content freeze,
   editorial approval, and exact release authority are prerequisites.

This sequence intentionally separates the other task's video production from
the book/proof/evidence critical path. Video completion cannot satisfy prose,
composition, empirical, or major-release gates.

### Amendment acceptance gates

- one canonical generated status system covers every current-manifest reference chapter and
  rejects all confirmed drift classes;
- every core claim exposes a conservative summary plus a claim-kind maturity
  vector without cross-kind promotion;
- navigation and the integrated map expose the four planes and architectural
  role classes, with speculative substrates visibly subordinate to the core;
- the proof report emphasizes unique consumer-linked invariants, and every new
  family satisfies the seven-field admission rule;
- at least one connected cross-owner model covers the global invariants and
  the ten-case distributed fault matrix at an explicitly bounded scope;
- the independently authored human manuscript is editorially reviewed against
  the 22-unit crosswalk and falls within the 120,000-180,000-word target unless
  an explicit meaning-preservation review justifies a bounded exception;
- object-level and meta-level evidence plus dependence dimensions are visibly
  separated;
- one natural flagship reaches a competence-qualified terminal disposition;
- five closest-prior-art matrices and available specialist objections are
  recorded without laundering them into support; and
- no routine content cycle spends credits on audio or full ebook generation.

## Binding no-deferral manuscript policy — 2026-07-24

The author has withdrawn the structural-freeze rule for manuscript ideas.
**No worthwhile chapter or section idea may remain in a candidate, frozen,
research-only, provisional, or “reconsider later” state.** Each identified
manuscript idea must receive one immediate disposition: integrate it as
meaning-bearing prose in its existing owner; add a chapter now when it owns a
distinct interface, artifact, lifecycle, invariant, or failure family; or
reject it as duplicative, incoherent, unsafe to operationalize, or outside the
book, with the reason recorded.

This rule distinguishes *manuscript coverage* from *evidence maturity*.
Experiments, formalization, reproduction, transfer, and deployment can remain
open when competence or resources are missing. The explanatory architecture
cannot. Prose and source synthesis remain at `argument` and cannot promote a
claim.

The first execution of this policy admits the ten previously deferred distinct
owners and moves the working manifest from 66 to **76 chapters**:

- Human–AI Communication, Persuasion, and Epistemic Security;
- Governed Objective Formation, Value Learning, and Goal Integrity;
- Institutions, International Coordination, and Public Legitimacy;
- Adversarial Machine Learning and the Model Attack Surface;
- Autonomous Replication, Proliferation, and Containment;
- Durable Semantic Memory and Knowledge Lattices;
- AI Deployment, Transition, Distribution, and Human Agency;
- Learning Theory, Generalization, and Scaling Science;
- Physical Compute Infrastructure, Energy, and Environmental Constraints; and
- Scientific Discovery and Experimental Governance.

Each has a complete argument-level manuscript, Human Reading Path, lifecycle
diagram, core claim, mechanism, interfaces, invariants, failure families,
minimum implementation, evidence program, source crosswalk, no-promotion
decision, evidence-plan row, and adjacent handoff. This section supersedes every
later sentence in this roadmap that describes these topics as unadmitted or
restores a structural freeze. Those sentences remain only as historical
sequence records. There is now no live chapter-candidate queue.

### Taxonomy and structural-maturity reconciliation

The later taxonomy audit identified four additional distinct owners that the
76-chapter structure did not make explicit: dangerous-capability domains and
misuse uplift; content authenticity and synthetic-media integrity; societal
resilience against misuse; and deliberate open-weight release with
post-release control limits. The controlling decision packet is
`docs/taxonomy_and_structural_maturity_reconciliation_2026_07_24.md`.

All four are admitted now, moving the working manifest from 76 to **80
chapters**:

- Dangerous Capability Domains and Misuse Uplift;
- Societal Resilience and Misuse Defense;
- Open-Weight Release and Post-Release Control; and
- Content Authenticity, Watermarking, and Synthetic-Media Integrity.

The same transaction repairs the title/content mismatches in Adversarial
Machine Learning, Learning Theory, and Autonomous Replication, and integrates
the warranted section-scale findings into existing owners: secure research
access and independent audits; ELK, mechanistic anomalies, and training
attribution; hardware-enabled guarantees; proof of training; curricula and
test-time training; legal alignment; certified neural verification; causal
calculus; digital twins; and diffusion language models.

The binding maturity test is structural, not a word-count threshold. Every new
or materially revised owner must contain a distinct mechanism, failure
boundary, strongest challenge or simpler baseline, explicit nonclaim,
source-specific contribution and limit, ownership-preserving handoff, and
auditable source/claim wiring. All four new chapters satisfy that
argument-level test. None moves support beyond `argument`, and no formal,
empirical, readiness, release, deployment, transfer, or SOTA claim follows.

## Purpose

This roadmap contains the unfinished and recurring work after the completed
Post-v2.3 Claim Proof, Causal Validation, and SOTA-Challenge Roadmap. Its first
obligation is now stronger than “write a falsifier before the run.” A negative
result is meaningful only when the tested implementation competently realizes
the intended mechanism, the task actually instantiates the claim, the
instrument could detect a practically important effect, and the idea received
a fair prospectively bounded opportunity to succeed.

Small or deliberately simple implementations remain useful for debugging.
They are not automatically valid tests of an architecture. A chance-level
system, broken evaluator, weak proxy, mismatched tuning budget, authored toy
corpus, or failed positive control must terminate as an implementation,
instrument, construct, or sensitivity problem—not as evidence that the idea is
false. The governing standard is **claim-commensurate competence**, because no
finite experiment can literally prove that every better implementation has
been exhausted.

The roadmap does not reopen completed repository bookkeeping merely to improve
counts. It does reopen the *interpretation* of historical negative and
no-change results where the new competence standard was not yet applied. Raw
outcomes remain immutable; overbroad negative inferences are quarantined until
they earn an N0–N5 classification.

The latest immutable public living-book release remains `v2.3.0`. At roadmap
activation, the working book contained 55 chapters; the first structural tranche
moved the working manifest to 59 argument-level chapters, and terminal P6.4-A1
and A2 admissions moved it to 61. The v2.2 reader evidence freeze and X Article synopsis are separate
newer artifacts. The post-v2.3 evidence corpus first reached committed custody
at `882b2a82c`. The bounded Round 18 breadth-completion transaction moved the
working manifest to **66 argument-level chapters** by admitting Perception,
Embodied Agency, Human–AI Organizations, Multi-Agent Dynamics, and Inner
Alignment and by integrating seven narrower gaps into existing owners. Its
controlling adjudication is
`docs/round_18_bounded_breadth_completion_adjudication_2026_07_24.md`.
The later no-deferral transaction admits ten more owners, and the taxonomy
reconciliation admits four further distinct owners, making **80** the current
working count; neither transaction moves support. The latest previously clean,
pushed, built, and deployed ancestral checkpoint is the exact 66-chapter Round
18 reconciliation commit `12d987bded2e504f5ec677df06c4fcdb281b1fdd` on
2026-07-24: tested Pages build `30120127304` passed and deploy/attest run
`30120682943` passed. P0 requires this depth-and-coverage roadmap amendment and
every later public-state change to receive its own exact clean commit, build,
deploy, and route attestation before that newer state is called public.
Neither checkpoint is a new
living-book or reader release, DOI/archive deposit, license grant, or public
post.

## Strategic quality diagnosis

The book's strongest assets are architecture breadth, explicit interfaces,
claim discipline, negative-evidence hygiene, and reproducible research
machinery. Its limiting weakness is causal concentration: all 87 chapter cores
remain `Design rationale` at `argument`, no competence-qualified natural,
non-authored empirical transition exists, and the reader must traverse many
mechanisms before seeing one decisive case that tests the stack against a
simpler alternative.

The largest quality gain remains one shared empirical spine with Project
Theseus, followed by an editorial pass that makes the book's hierarchy and
evidence boundaries obvious; chapter count, proof count, source count, report
families, and synthetic campaigns are not substitutes for that work. A bounded
structural audit may still add a chapter when it exposes a genuinely unowned
interface, invariant, artifact type, lifecycle transition, or failure family.
Every other new source routes into an existing owner.

The roadmap optimizes for five outcomes, in order:

1. a useful learned behavior numerator rather than more representations of
   capability;
2. a natural governed-work case with observed effects and total lifecycle
   cost;
3. a matched causal comparison against simpler controls;
4. a shorter, clearer reader spine organized around that case; and
5. separately implemented challenge and transfer before any broad architecture
   claim, without making another human a prepublication dependency.

The post-breadth critique reconciliation is
`docs/round_18_post_breadth_review_reconciliation_2026_07_24.md`. It accepts
the apparatus-to-evidence imbalance, rejects the stale 61-chapter description
of the working tree, narrows “zero empirical results” to the exact missing
competence-qualified natural/non-authored class, and makes two consequences
binding: publish the exact 66-chapter `main` state under continuous-custody P0,
then return immediately to P2. The governance construct tested by P2 is stable
under the completed Round 18 additions, so conceptual growth no longer
justifies deferral. Counts of prose, sources, proofs, validators, schemas,
receipts, or green checks do not satisfy that empirical objective.

The subsequent depth-and-coverage audit is reconciled in
`docs/post_round_18_depth_and_coverage_review_reconciliation_2026_07_24.md`.
It rejects brittle keyword absence as a completeness test, accepts the relative
thinness of five Round 18 chapters and the still-open White-Box depth defect,
and makes a six-condition claim-bearing maturity gate binding. It also
identifies two plausible distinct owners—adversarial machine learning against
learned systems and learning/generalization/scaling science. The binding
no-deferral policy now admits both, together with the other formerly deferred
owners. Depth and evidence competence remain binding book-quality constraints;
the admission does not displace P2 or move support.

## Execution-ready work board

The owner's 2026-07-24 instruction authorized one bounded conceptual-
completeness pass before returning to experiments. That transaction is now
terminal: five distinct-owner chapters entered the manifest, seven narrower
gaps entered existing chapters, twenty-one primary-source records and notes were
mapped, and the new owners received birth atoms and reader handoffs. This was a
sequencing decision, not evidence that the Round 16 criticism lacked force.
The structural window is therefore closed again.

P2 remains the protected natural empirical headline, but it is not the current
executable priority while its infrastructure gates are closed. P5-U1 is
terminal at its retrospective implementation-and-reader scope. `C1-EL` is
terminal and inconclusive after an instrument failure, with no replacement or
route claim. `C2-EL`, the second prospective claim-state exit-ladder attempt,
is frozen before proposal admission and is the active object-level packet,
with the independent P7.1 narrative and fifteen-minute
utility route as the active book packet. P4.1 is consumer-gated: it may proceed
only when P5-U1 or one of
the three contribution exit ladders names the theorem's runtime, evidence, or
decision consumer. The exact 2026-07-27
`P2-R3a-002` receipt supersedes transient capacity observations for current
scheduling: the host had `25,627,230,208` available bytes against the frozen
`53,687,091,200`-byte floor, while direct Docker diagnostics again failed to
establish a live daemon. The four exact diagnostic commands, outputs, digests,
exits, and timeout are committed without opening task content. This is an N0
infrastructure disposition, not a task result. The next empirical action is a
new immutable entry receipt after both gates are restored; only a passing
receipt may launch the exact frozen materializer. More prose or proof count
cannot substitute for that action.

**Work-in-progress limit:** at most two critical-path packets may be active: one
formal/compositional packet and one narrative/book packet. Continuous P0
custody does not consume a slot. A blocked empirical packet does not consume a
slot. The separately owned P7.3 video task does not consume this task's WIP and
cannot close its gates. Manuscript ideas do not wait for a WIP slot: they are
routed, integrated, admitted, or explicitly rejected immediately, while
elective new core-owner admission remains behind the amendment's heightened
one-cycle admission bar.
Protected P2, Q1, or Q2 task content, labels, outcomes, or evaluator judgments
remain closed while other work proceeds.

| Slot | Next packet | Entry condition | Terminal output |
|---|---|---|---|
| Continuous custody | P0 repository and public-truth reconciliation | Always open | Clean `main`, exact generated/source boundaries, current roadmap pointers, and no stale claim or release identity. |
| Governed-cognition exit ladder - terminal inconclusive | `C1-EL-quarto-render-db-open-001` | Admitted prospectively after the ordinary EM4 render failed, then terminated when the result writer raised after the trial-function phase | Preserve the instrument-failure receipt, no-rerun rule, no route outcome, and zero support/release effect. Do not reuse the known task as prospective evidence. |
| Claim-state exit ladder - frozen | `C2-EL-claim-state-proposal-001` | Admit only the first independently necessary post-freeze claim-state proposal before its disposition is known | Run the matched direct, record-only, and full-governed comparison only after admission; retain natural and three fault paths, twelve outcomes, mutation sensitivity, and the one-case inference ceiling. |
| Object-level utility — implementation and reader route terminal; prospective evidence open | `P5-U1-minimal-useful-governed-vertical-slice` | The 2026-08-13 retrospective replay runs one real Human Reader source-link repair through direct, record-only, and fully governed routes across happy, blocked-authority, crash/recovery, and external-effect compensation paths; its first-class Human Reader route includes the command, three recipes, and implemented-versus-proposed boundary; protected P2 content remains closed | Preserve the 12/12 fresh-workspace result, nine rejecting record mutations, explicit matched governance-rent comparisons, reader route, and honest retrospective ceiling. Route broader usefulness, natural performance, observed human effort, production, safety, and transfer only through the prospective natural campaign. |
| Existing-book integration — terminal | `P6.5-R16-A-six-chapter-atom-pack` | Completed 2026-07-26 | Thirty reviewed atoms across six chapters, six digest-bound review receipts, a separate schema and validator, identity-graph reconciliation to 4,112 canonical atoms, Appendix C projection, fourteen rejecting mutations, and zero support movement. |
| Existing-book integration — terminal | `P7.1a-W3-admission-template-inheritance-guard` | Completed 2026-07-26 | Exact 84-chapter NFKC audit; reader-facing repeated 12-grams at spread eight reduced 812→0; copied diagram/test spread 10→0; shared lifecycle method centralized; ten chapter diffs plus eleven semantic-review reconciliations; 241 retired inherited prose IDs replaced by 177 domain-specific dispositions with 4,067 atoms unchanged and zero pending; copied fixture rejected, distinct fixture accepted; eighteen mutations; zero meaning or support movement. |
| Existing-book integration — terminal | `P7.2-T1D-proof-readiness-depth-pack` | Completed 2026-07-26 | Six maturity records, 36 condition decisions, 12 chapter-specific anchors, four existing-owner repairs, five White-Box source receipts, ten applicable claim identities, eighteen rejecting mutations, and zero support movement. |
| Existing-book integration — terminal | `P6.5-R16-B-current-reader-freshness` | Completed 2026-07-26 from exact source commit `56563e1b2b64405e2e944c521bf4df9f29eba6e6` | Content-addressed virtual QMD projections for all 84 chapters; all 22 narrative units and eight reader surfaces bound; 11/54/7/12 role partition preserved; historical `reader-2026-07-18` manifest immutable; five unreviewed formats honestly deferred; sixteen mutations; zero support, release, or publication movement. |
| Existing-owner paging packet — prose terminal; policy and empirical work deferred | `P6.6-heterogeneous-inference-memory-and-speculative-paging` | Reader-facing source integration was expressly commissioned and completed 2026-07-23; schema, validator, planner, hardware characterization, and empirical work retain the ordinary post-gate entry condition | Maintain the six completed manuscript integrations and source reconciliation. Later implement and validate the heterogeneous-memory policy and run only competent, matched, hardware-characterized paging experiments. Preserve exact/approximate, throughput/latency, and source/local evidence boundaries. No new chapter. |
| Existing-owner inference-cache packet — prose terminal; receipt and empirical work deferred | `P6.7-inference-cache-reuse-and-honest-pricing` | Reader-facing source integration was expressly commissioned and completed 2026-07-23; no new chapter or support movement | Maintain the three coordinated manuscript integrations and nine-source packet. Later implement the cache-reuse receipt and run separate exact-prefix and semantic-response campaigns under the ordinary post-gate entry condition. Preserve KV-versus-output, exact-versus-semantic, hit-versus-useful-outcome, and provider-contract-versus-local-evidence boundaries. |
| Existing-owner functional-precision packet — source and prose terminal; evidence work queued | `P6.8-functional-precision-and-behavior-preserving-computation` | Source intake and the nine-owner manuscript integration are complete; schemas, validators, source resolution, and empirical work retain ordinary gates; no new chapter or support movement | Maintain the integrated Precision Contract treatment led by RankFold/NeuralFold. Preserve representation invariance, protected behavior, complete executable and physical-cost accounting, progressive residual precision, routed fallback, certificate scope, and program-transformation proof limits. Reconsider a standalone chapter only if a dated post-integration coherence audit finds a genuinely unowned lifecycle. |
| Existing-book depth recovery — terminal historical packet with current-manifest admission | `P6.9-R21-concept-complete-depth-and-atom-adequacy` | The 84-chapter R21 packet remains immutable history. Current chapter growth is manifest-driven and requires the full admission and debt-reconciliation path; additive atom or bounded formal-target custody is now 87/87 without rewriting the historical receipt. | Preserve all twenty-three completed owners and 184 concepts at their reviewed digests. The raw-scaffold audit owns all 21 widest blocks with zero reader-visible or unjustified blocks; the exact 23-chapter/184-concept proof/evidence handoff remains terminal. New owners must gain exact atom or bounded formal-target custody at birth and cannot inherit completion from the historical packet. |
| Corben paper corpus fidelity — terminal; drift-triggered maintenance | `P6.10-complete-Corben-paper-section-family-closure` | All 46 locally readable canonical Corben paper texts and seven authenticated connector records have complete section-family dispositions; connector variants and project-lineage records retain separate evidence classes | Maintain both machine closure ledgers, `docs/source_mining_synthesis.md`, per-source notes, inventory, chapter mappings, and owning prose together. Reopen only the affected family when a paper changes, an inaccessible variant is recovered, or a new source arrives. Every useful item must integrate, remain in the public-safe note, become a concrete research obligation, or be an explicit non-claim; source assignment alone never closes mining. |
| Editorial product migration and independent human narrative — terminal HTML cutover | `P7.1-EM-87-identity-56-reference-26-unit-editorial-migration` | EM0-EM4 are complete. Seven EM2 packages preserve all sixteen publication nests and two method-detail nests; all 26 EM3 units are independently authored inside their declared word targets for 133,658 visible words; all 87 owners route exactly once; and the exact 54+2/16+2+0/7/5/1 split remains validated. Exact source `d85a1b14f` passed build `31747729802`, deployment/attestation `31749131391`, 230 exhaustive local browser page-view pairs, and public route inspection. | Preserve the deployed `/reader/` route, exact cutover record, major conclusions, every technical identity, and zero support inheritance. External-human editing and assistive-technology review remain unclaimed. Defer the primer and major release formats until content freeze. |
| Visual edition — separately owned derivative packet | `P7.3-governed-manim-visual-edition` | The 84 generation-one packets and their technical receipts remain historical and stale; all former YouTube previews are private and the current Quarto projection is empty. Generation two is manifest-driven across 87 chapters. Twenty-four case-first narrations have been rewritten: 20 remain narration drafts, while four targets have treatment, narration, and beat-plan files but no current script or animatic gate pass after source and authoring-standard invalidation. Their local animatics and sampled-frame receipts are diagnostic only; no downstream publication state is closed. Treatment-free v2 plans and their downstream artifacts remain historical. The current ledger reports 63 planned, 20 narration drafts, four file-level beat-planned targets, zero current script-passed targets after source invalidation, zero animatic-passed targets, and zero accepted generation-two videos. | The separate video task owns P7.3-F9. Complete treatment, script, block-timed beat-plan, animatic, qualified forced alignment, picture-and-sound lock, independent source-aware review, context-isolated cold-proxy review, technical, accessibility, and publication gates in that order. Treat an AI proxy as artifact diagnosis rather than human-learning evidence. Preserve private predecessor history and zero current publication claims. Do not let derivative work satisfy or block the prose/proof/evidence path. |
| Formal slot — consumer-gated | `P4.1-consumer-gated-cross-owner-composition` | `P5-U1` or one contribution exit ladder names a concrete runtime, evidence, or decision consumer; the original C6 residual estate remains under exact dependency and consumer custody; new work requires the seven-field family admission rule plus maximum inference | Implement only the invariant or distributed-fault model required by that consumer, then rebuild the overlay and ledger with no support or release movement. No independent theorem-family expansion is authorized. |
| Empirical headline — exact N0 entry receipt; materialization blocked | `P2-R3-storage-materialization-and-replacement-qualification` | `2026-08-13-r3a-004` measured 7.12 GiB free against the 50 GiB floor and no reachable Docker daemon; restore both gates and write a new immutable preflight before any pull | Then thirty sealed candidate recipes and receipts; terminal pool materialization; four competently qualified replacements restoring the fixed twelve-task denominator; rank progression only under the frozen amendment; zero protected-content leakage. No deletion of non-Docker user data is authorized. |
| First structural tranche — terminal | White-Box, World Models, Human Factors, and Governed Operations are terminal at argument support | Four exact integration packets preserve owners, sources, formal ceilings, protocols, reader handoffs, and no-promotion boundaries | Maintenance only; no reopened chapter packet without a dated machine-validated defect. |
| No-deferral manuscript transaction — terminal at argument support; evidence follow-up open | All ten formerly deferred distinct owners are admitted | Ten complete argument-level chapters, one new NIST source record/note, source crosswalks, evidence-plan rows, no-promotion decisions, handoffs, outline/roadmap reconciliation, and 76-chapter manifest truth | No manuscript idea remains in a candidate queue. All 76 chapter cores remain at `argument`; implementation, empirical, formal, reproduction, transfer, and deployment residuals remain open. |
| Taxonomy and structural-maturity transaction — terminal at argument support | Four unowned danger/release/integrity/resilience lifecycles plus the accepted existing-owner depth repairs | Four complete non-template chapters, three title/content repairs, thirteen section-scale integrations, 21 net-new external sources, source/claim wiring, outline and roadmap reconciliation, and 80-chapter manifest truth | No identified manuscript idea remains deferred. All 80 chapter cores remain at `argument`; the shared flagship, independent evaluation, reproduction, transfer, and publication attestation remain open. |

The post-breadth integration debt has six conjunctive completion gates. They do
not reopen structural admission automatically:

1. P2 pool materialization has a terminal receipt for all thirty sealed
   candidate environments;
2. four replacement slots are competently qualified and the fixed twelve-task
   denominator is restored without protected-outcome leakage;
3. **Completed 2026-07-26:** the six post-baseline chapters have an append-only
   thirty-atom claim addendum with falsifiers, acceptance criteria, promotion
   ceilings, evidence-plan routes, stable identity edges, and review receipts;
4. a current derived-reader freshness packet covers all 84 manifest chapters
   without rewriting the immutable `reader-2026-07-18` release;
5. **Completed 2026-07-26:** W3 rebaselines current 84-chapter repetition,
   centralizes the shared lifecycle method, and rejects inherited shared prose
   in future chapter transactions; and
6. Inner Alignment, Multi-Agent Dynamics, Perception, Embodied Agency,
   Human–AI Organizations, and White-Box Evidence pass the six-condition
   claim-bearing maturity gate and complete their accepted depth repairs.

The Governed Model Training optimizer-landscape source, prose, and policy-
contract amendment is terminal at argument support. Its atom and reader
projections remain inside gates 3 and 4, while its resource-gated matched
campaign and independent reproduction remain ordinary P6 evidence residuals.
They do not reopen the completed depth amendment or block structural resume.

The 2026-07-19 checkpoint closed both former immediate packets,
`P7.1a-W1-template-centralization-and-boundary-coverage` and
`P4-C1-evidence-claim-and-proof-custody-semantic-audit`. P7.1a-W1
centralized the repeated evidence method, reduced reproducibly measured
high-spread 12-grams by 36.34%, moved consolidation history out of three
openings, and added source/atom/non-claim bounded epistemic-security and
gradual-disempowerment sections; its machine audit is
`evidence_quality/p7_1a_w1_editorial_boundary_audit.json`. P4-C1 gave all four
evidence/claim/proof-custody modules terminal bounded-scope dispositions: two
adequate reachable refinements and two reclassifications that preserve useful
route or countermodel semantics while denying direct projections stronger
credit. Its authority is
`proofs/semantic_cluster_audits/evidence_claim_and_proof_custody.json`. Neither
packet changes support, release, or publication state.

The following 2026-07-19 checkpoint closed
`P7.1a-W2-opening-variation-and-thesis-depth-leveling` and
`P4-C2-safety-assurance-and-oversight-semantic-audit`. W2 removes all eight
occurrences of the six frozen opening-formula families, classifies all 59
chapters exactly once as 11 thesis-bearing, 30 load-bearing reference, 7
implementation case, and 11 speculative/deferred research chapters, refreshes
the overview and three central handoffs, and adds 710, 728, and 664 substantive
word tokens to the two thesis chapters and Failure Modes. Its authority is
`evidence_quality/p7_1a_w2_narrative_audit.json`. C2 gives all four modules an
adequate bounded-scope disposition across 31 public targets, with exact
propositions, assumptions, countermodels, consumers, mutations, and maximum
inference in
`proofs/semantic_cluster_audits/safety_assurance_and_oversight.json`. The
formal result is finite preservation, lifecycle, route, handoff, invalidation,
quarantine, and authority-separation semantics—not protected-predicate truth,
safety-case validity, reviewer independence, deception detection, control
efficacy, or deployment safety. Neither packet changes support, release, or
publication state.

The following 2026-07-19 checkpoint closed
`P7.2-T1-white-box-evidence-interpretability-and-activation-governance` and
`P4-C3-authority-effect-rollback-and-corrigibility-semantic-audit`. T1
terminally integrates White-Box Evidence as a load-bearing argument-level
chapter with eight reconciled source mappings, a strict packet schema, one
expired record-shape fixture, two implemented public Lean targets across eight
declarations, twelve rejecting semantic mutations, an explicit reader owner,
updated overview/glossary/handoffs/final synthesis, and a claim-bearing campaign
that is protocol-ready, resource-isolated, and deliberately unexecuted behind
seven competence gates. Protected outcomes remain closed; no source result,
fixture, theorem, or protocol readiness moves support. C3 gives terminal
dispositions to four modules and eleven public targets across sixty-five
declarations: `AuthorityEffectRefinement`, `Replacement`, and
`IntentExecutionRefinement` are adequate only for their finite declared
semantics, while `Corrigibility` is reclassified as countermodel-only because
it has no transition lifecycle or independent runtime consumer. Its authority
is `proofs/semantic_cluster_audits/authority_effect_rollback_and_corrigibility.json`.
Neither packet changes support, release, or publication state.

The following 2026-07-19 checkpoint closed
`P7.2-T2-governed-world-models-and-reality-grounding` and
`P4-C4-learning-update-state-and-unlearning-semantic-audit`. T2 terminally
integrates Governed World Models as a load-bearing argument-level chapter with
nine reconciled sources, an exact qualified-branch and reality-residual schema,
one deliberately stale unsupported safe-hold fixture, two implemented public
Lean targets through nine declarations, thirteen rejecting contract mutations,
and overview, glossary, handoff, claim-matrix, and final-synthesis integration.
Its six-arm, eight-gate, seven-rescue-step claim-bearing protocol is ready but
unexecuted and resource-isolated; the earlier P4/M8 authored-environment result
remains adjacent bounded synthetic evidence and does not establish the chapter
core. C4 finds all four data/update/weight/context modules adequate only for
their exact finite record semantics across 31 public targets and 39 theorem
declarations while preserving separate behavioral, influence, privacy,
lineage, legal, storage, and backup-erasure axes. Neither packet changes
support, release, or publication state.

The following 2026-07-19 checkpoint closed
`P7.2-T3-human-factors-and-meaningful-control-in-oversight` and
`P4-C5-self-improvement-and-readiness-semantic-audit`. T3 terminally integrates
Human Factors as a load-bearing argument-level chapter with ten reconciled
sources, an exact control-envelope schema, one deliberately incompetent
safe-hold fixture that observes zero humans, two implemented public Lean
targets through thirty-two declarations, fifteen rejecting contract mutations, and
overview, glossary, handoff, claim-matrix, source, and final-synthesis
integration. Its four-arm human-subjects campaign freezes nine competence
gates, five positive controls, seven adversarial controls, six rescue steps,
twelve separate outcomes, an N3 exact ceiling, and strict ethics, privacy,
accessibility, participant, resource, and P2-isolation gates. No recruitment or
outcome opening occurred, and the protocol cannot substitute participants for
prepublication human review. C5 finds all four self-improvement/readiness
modules adequate only for exact finite proposal, campaign, assessment,
readiness, quarantine, invalidation, rollback-record, handoff, and readmission
semantics across 21 public targets and 36 theorem declarations. Governed
proposal records are not useful improvement; bounded campaign records are not
open-endedness; assessment records are not true threshold crossings; readiness
handoffs are not release authority; and declared-state restoration is not
semantic or external-effect recovery. Neither packet changes support, release,
or publication state.

The next 2026-07-19 working checkpoint closes
`P7.2-T4-governed-operations-incident-command-and-graceful-degradation` and
`P4-C6-resource-artifact-and-lifecycle-economics-semantic-audit`. T4
terminally integrates Governed Operations as a load-bearing argument-level
chapter with nine reconciled sources, an authored identity-bound joined
authority-to-effect case, five-dimensional degraded-authority narrowing,
eleven declared internal-state classes, an unknown external effect that forces
safe hold, a separately completed development positive control, two implemented
public targets through thirteen declarations, and eighteen rejecting contract
mutations. Its four-arm natural-service campaign freezes nine competence gates,
five positive controls, eight adversarial controls, six rescue steps, thirteen
joint outcomes, an N3 exact ceiling, and strict P2/Q1/Q2 isolation; it has run
no task, fault injection, or operator. The authored case is not Theseus
flagship T4. C6 finds all four resource/artifact/steward/compression modules
adequate only for exact finite record semantics across 31 public targets and 48
theorem declarations. A resource bill is not efficiency, an admitted artifact
is not open-world truth or durability, a steward record is not legitimate
ownership, a compression receipt is not useful semantic preservation, and a
closed record is not lifecycle success. All six frozen P4 clusters are now
terminal at bounded scope. Neither packet changes support, release, or
publication state.

Second-tranche adjudication uses four dependency batches, preserving the order
within each batch unless a dated amendment explains why an input dependency
changed:

1. **Foundational missing owners:** Governed Model Training; Privacy and
   Information Flow; Governed Objective Formation.
2. **Observe then act:** Perception and Observation Trust; Embodied Real-Time
   Control.
3. **Organizations and society:** Human–AI Organizations; Human–AI
   Communication; Institutions; AI Deployment Transition; Multi-Agent
   Dynamics.
4. **Proliferation, physical capacity, and integrated case:** Autonomous
   Replication; Physical Compute Infrastructure; Scientific Discovery, with
   Scientific Discovery still rejected as a chapter unless it proves a
   reusable control plane.

Every packet follows the same acceptance sequence: freeze scope, owner,
inputs, and non-claims; produce a reviewable artifact and exact receipts; run
targeted negative controls; reconcile manifest, outline, sources, claims, and
reader surfaces; run registered validation plus render/browser gates; then
commit and push clean `main`. A packet that cannot meet those steps receives an
exact blocked or terminal disposition rather than remaining vaguely “in
progress.”

## Shared ASI Stack–Theseus flagship

The shared program ID is **`ASI-THESEUS-FLAGSHIP-01`**. Its research question is:

> Can a locally trained, source-disjoint Theseus student complete useful
> natural repository work through the governed stack, and does full governed
> admission improve the joint useful-safe-release frontier over simpler matched
> controls at an acceptable total lifecycle cost?

The book owns canonical claim identity, the competence protocol,
preregistration, support transitions, argument-exit language, and publication
boundaries. Theseus owns the student, natural dogfood route, runtime effects,
joined traces, matched controls, and public-safe evidence pack. Stable IDs and
digests may cross repositories. Hidden answers, held-out outcomes, private
payloads, and support states may not.

| Gate | Primary owner | Book exit condition |
|---|---|---|
| `T0` — Historical architecture control | Theseus | The prior independently replayed 57M package remains immutable and usable only as a historical control; later source changes cannot inherit its training authority. |
| `T0A` — Successor finite architecture closure | Theseus | The closed successor docket is faithfully implemented or explicitly excluded with an adequacy-scoped disposition, independently replayed, and published as a replacement content-addressed freeze; the book records no efficacy claim. |
| `T1` — Frozen neural-seed campaign | Theseus | Training lineage is immutable and no architecture choice is tuned from held-out outcomes. |
| `T2` — Honest behavioral numerator | Theseus + P2 competence review | At least one student arm produces nonzero model-only, source-disjoint functional behavior, or the exact regime receives only the negative scope it earned. |
| `T3` — Real daily use | Theseus dogfood lane | At least one week or five distinct days of real use preserve accepted, missed, ignored, corrected, completed, failed, and abstained outcomes with component attribution. |
| `T4` — Joined governed vertical | P5 + Theseus | One natural happy path and one blocked or rollback path join intent through observed effect and terminal outcome without orphan, stale projection, or learned-credit laundering. |
| `T5` — Matched causal flagship | P2 + P5 | Independently frozen Q1 admission and Q2 student results are composed without shared-denominator or support leakage, with independent evaluation, uncertainty, weak tails, fair rescue, and total lifecycle cost. |
| `T6` — Synthesis and challenge | P3 + P7 | A public-safe evidence pack updates only the exact affected atoms and reader case; any broader language waits for separate reproduction and two transfer settings. |

The 2026-07-29 public-safe currentness handoff resolves that dependency against
published Project Theseus `main` commit `264a31ee`. `T0A` is historically
complete at a GREEN pre-activation transaction binding 143 artifacts, 15 of 15
architecture contracts, 14 accelerator receipts, and 7 of 7 CPU replays. `T1`
is active at shared-trunk step 9,048 and 69,310,840 of 1,096,734,920 frozen
pretraining positions. Its exact model, AdamW, RNG, receipt, stage, and
migrated-plan identities are bound by a prospective anchor.

That correction includes a custody limitation rather than hiding it: the exact
step-3,480 payload and a complete immutable segment-by-segment predecessor
chain from 3,480 to 9,048 are not locally available. The historical T0A GREEN
transaction remains an architecture and execution qualification, but neither
repository may claim a present-tense full-chain replay. Every later
state-changing segment must start from the anchor or terminal ledger identity
and archive exact before/after receipts plus checkpoint, optimizer, RNG, child,
and host-guard identities before another launch. The lifecycle-aware gate
preserves twelve historical source-drift observations, accepts them only
through the explicit post-activation anchor and plan migration, and reports
pretraining ready with zero architecture blockers. The private development
evaluator freeze is GREEN and unconsumed; capability remains
`NOT_EVALUATED`, `T2` remains blocked, and no support or release state moves.
The exact sanitized receipt is
`docs/theseus_t0a_architecture_closure_currentness_import.md`.

P2 may continue corpus, evaluator, construct, resource, and comparator preflight
before `T2`. Assisted-product success may support usefulness at `T3`, but
tools, retrieval, authored workflows, routers, teachers, and human correction
never become learned-generation evidence.

### Two-question decomposition and denominator independence

The shared flagship question contains two separable claims that must never
share support by implication:

- **Q1 — Governed-admission efficacy (worker-agnostic).** Does full governed
  admission improve the joint useful-safe-release and false-blocking frontier
  over matched test-only and record-only controls on natural repository work?
  Q1's worker may be any prospectively named competent current system,
  including a strong model that is not the Theseus student.
- **Q2 — Local student competence (Theseus-owned).** Can a locally trained,
  source-disjoint Theseus student complete useful natural repository work
  through the same governed path?

Q1 and Q2 use two non-overlapping, independently sealed held-out denominators.
**`P2-Q1-D1`** may open once P2's own seven competence gates pass, using the
prospectively named strong-worker arm; Q1 does not wait for `T2`–`T4`.
**`ASI-THESEUS-Q2-D2`** is frozen prospectively and remains outcome-sealed
until the student, joined-path, and Q2-specific gates pass. D1 outcomes may
calibrate instruments only under a rule fixed before D1 opens; they may not
select, tune, rescue, or restructure the student, D2, or the Q2 architecture.
No task, hidden test, outcome, or support movement may cross between D1 and D2.
`T5` composes their separately earned conclusions rather than pooling their
rows. A Q1 result moves only the governed-admission claim; it creates no
student, learned-generation, or architecture-general support. A Q2 shortfall
bounds only the student regime; it neither reopens nor discounts a completed
Q1 result.

### Roadmap state vocabulary

- `completed`: terminal for the declared scope; retained as evidence, not active work.
- `continuous`: an integrity or renewal obligation that is current and never a headline result.
- `in_progress`: prerequisites are available and bounded work is underway.
- `blocked`: the exact missing prerequisite is named; nearby green work cannot substitute.
- `pending`: ordered work whose entry conditions are not yet true.
- `deferred`: preserved research with an explicit trigger that cannot consume current scope.

## Review adjudication and corrected baseline

The 2026-07-17 review contained several useful criticisms and several stale
counts. The roadmap adopts the criticisms with teeth while preserving the
current repository truth.

| Surface | Current audited state | Roadmap consequence |
|---|---:|---|
| Transition files | 117 | Preserve the full history; the tree did not collapse to six records. |
| Review-accepted transitions | 115 | Every accepted transition must resolve through the canonical claim-identity graph. |
| Direct atom/addendum matches | 25 | Direct identity is not the only valid relation, but implicit identity is forbidden. |
| Accepted claim IDs without a direct atom match | 90 at review; all 90 now indirectly resolved | P0 installed explicit bounded `subclaim_of` or `proxy_for` edges and a rejecting validator; zero accepted identities remain unmapped. |
| Accepted transition states | 87 argument/no-change, 14 synthetic, 10 prototype, 3 refuted, 1 empirical | The target is the first **competence-qualified natural, non-authored, independently evaluated transfer-aware** empirical transition—not the first empirical label ever. |
| Frozen structured denominator | 3,730 activation atoms + 15 reviewed addendum atoms | Campaign claims must not be silently promoted into the atom denominator or chapter cores. |
| Registry support movement | 2 of 3,730 activation atoms are above argument | Claim-ID reconciliation must report evidence truth without inflating core or atom support. |
| Formal snapshot | 298 targets, 98 modules, 1,307 theorem declarations; 901 derived/decomposed, 230 direct/projection, 176 unknown/mixed | The old 91/278 count is stale, but syntax classification is not semantic depth; P4 audits meaning, consumers, countermodels, and refinement. |
| Attested Git state | Review baseline: `cd98c0c4b` plus 380 dirty paths. Custody checkpoint: pushed `main` commit `882b2a82c`. | P0 now enforces post-commit evidence custody and requires the final remediation checkpoint to be re-attested after every campaign disposition. |

## Round 15 adjudication and required corrective

The 2026-07-18 Round 15 review had four criticisms with teeth. The repository
adopts them without adopting stale proof counts or pretending blocked work
completed.

| Criticism | Adjudication | Corrective and terminal criterion |
|---|---|---|
| 380 dirty files put irreplaceable evidence at risk | **Accepted and corrected immediately.** | All existing work was committed and pushed to `main` at `882b2a82c`. The release-tier git-custody gate now rejects any modified, staged, or untracked path under `evidence_transitions/`, `evidence_quality/`, or `release_records/`. Every terminal campaign disposition ends in committed custody before it counts. |
| P2 burned ranks on infrastructure weather before an outcome existed | **Accepted.** | `docs/p2_infrastructure_materialization_and_content_freeze_amendment.md` makes bounded, receipt-complete setup retries legal only before protected task content opens; requires pool-wide infrastructure readiness; blocks rather than advances on setup exhaustion; keeps rank 4 irreversible; reinstates rank 5 as setup-pending; and keeps rank 6 closed. The current 60-GiB host constraint is a named blocker, not a fake slot-1 completion. |
| Four refinement modules remained silent stubs | **Underlying demand accepted; snapshot stale.** | `docs/round_15_proof_depth_disposition.md` retains the four non-stub finite models, adds quantified state-preservation/receipt or authority non-acceptance theorems, binds consumers and mutations, and keeps their inference ceilings explicit. Wider semantic-depth work remains open. |
| Repeated no-release records became an avoidance pattern | **Accepted.** | P7 must repair and fully re-render PDF/DOCX, validate EPUB/PDF/DOCX/HTML by exact format-specific gates, publish approved reader artifacts to the existing GitHub Release target, and record deployed/release identities. The X synopsis remains staged. A failed format may remain blocked only with a current exact defect receipt, not an inherited roadmap disposition. |

## Round 16 evidence-first adjudication and amendment

The 2026-07-19 Round 16 review correctly identified that structural throughput
had outrun empirical and integration throughput. Its useful criticisms are
adopted with corrections where the review's snapshot or denominator model was
stale.

| Criticism | Adjudication | Binding corrective and terminal criterion |
|---|---|---|
| P2 was called the headline while two further chapters were admitted and A3 was activated | **Accepted.** | Freeze A3 and every later structural candidate. P2-R3 is the sole empirical headline: earn a thirty-environment materialization receipt and competently qualify four replacements to restore the fixed twelve-task denominator. At the Round 16 checkpoint the below-floor blocker was honest and Docker-only reclamation could not be replaced by deleting unrelated user data; the Round 17 capacity recheck below supersedes that transient diagnosis without rewriting its history. |
| Six newly admitted chapters have no atoms in the frozen registry | **Accepted with denominator correction.** | The 3,730 activation atoms and existing 15-atom addendum are immutable historical baselines, not files to rewrite. Create a new append-only post-activation atom pack for White-Box, World Models, Human Factors, Governed Operations, Governed Model Training, and Privacy/Data Rights. Every atom needs stable identity, claim text, falsifier, acceptance criterion, promotion ceiling, evidence-plan route, and owner. Atom creation itself changes no support. |
| The new chapters have no reader edition | **Partly accepted.** | They already contain validated Human Reading Paths and reader-spine integration, but the published `reader-2026-07-18` derivative predates the current 84-chapter manifest. Preserve that release as immutable history and produce a current 84-chapter derived-reader freshness packet covering the opening map, roles, handoffs, overview, glossary, sources, claim/evidence projection, and synthesis. No external publication is required or implied. |
| Repeated chapter templates survived the W1/W2 cleanup | **Accepted and closed by W3.** | W1 and W2 remain immutable terminal receipts for their historical 55- and 60-chapter scopes. W3 freezes the current 84-chapter corpus, NFKC normalization, `[A-Za-z0-9_\`'-]+` tokenizer, 12-gram length, and eight-chapter spread threshold at commit `99457770390a4af4848b9e43656907cfe099fd75`. The editorial projection moves 812→0 repeated 12-grams; copied diagram and test-table spread moves 10→0. Generated source/evidence packets remain separately reported with generator owners. |
| White-Box is too thin and omits sparse autoencoders | **Depth criticism accepted; omission claim stale.** | The chapter already records sparse-autoencoder scaling, reconstruction/sparsity trade-offs, dead latents, feature splitting/merging, probes, causal interventions, and steering boundaries. It still needs a substantive method-comparison section on SAE/dictionary-learning construct validity, probe selectivity and leakage controls, interpretability illusions under cross-distribution challenge, feature absorption/splitting and metric reliability, diagnostic-versus-causal evidence, off-target/capability damage, strong behavioral baselines, and independent evaluation. Source ingestion must include Hewitt and Liang (2019), Bolukbasi et al. (2021), Gao et al. (2024), SAEBench (2025), and the 2026 audit of SAE benchmark reliability, each with explicit admissible use and non-authority. |
| Future growth should be constrained | **Accepted.** | After the freeze clears, admit at most one new chapter per material empirical/evidence checkpoint. “Material” means a terminal measured or evidentiary milestone—not prose, source inventory, schema, proof-count, build, or validation movement. Every future admission transaction must include the chapter atom pack, reader projection, source roles, ownership decision, and W3 inheritance check at birth. |

## Round 17 priority enforcement and blocker recheck

The 2026-07-22 Round 17 review correctly found that the Round 16 policy was
stronger than its execution. This amendment makes task order machine-visible,
removes the stale capacity diagnosis, and prevents the remaining integration
debt from behaving like an interchangeable menu.

| Criticism | Audited adjudication | Binding correction |
|---|---|---|
| P2 did not move for a third cycle | **Accepted.** | P2-R3 takes the empirical slot immediately. At run start, record exact host and Docker state; then execute or build the content-sealed thirty-candidate sequential materializer. A book packet may run in parallel but may not consume, postpone, or replace the empirical slot. |
| The capacity blocker may have cleared | **Accepted with an important boundary.** | The 2026-07-22 diagnostic recorded `71,648,034,816` free bytes, above the frozen `53,687,091,200`-byte floor, with Docker available and reporting zero retained images, containers, volumes, and build cache. This changes P2 from `blocked_pending_authorized_capacity_change` to `capacity_entry_condition_met_materialization_not_yet_run`. It is permission to attempt the frozen protocol, not a materialization pass, task result, or support movement. |
| Work after the freeze again preferred source/prose deepening | **Accepted and closed for the identified Phase 1 organization scope.** | R16-A, W3, P7.2-T1D, and R16-B are terminal. The current 84-chapter manuscript now has exact role, claim, source, handoff, narrative-unit, and reader-freshness custody. There is no open book-organization packet; the roadmap returns to P2 evidence work without treating theorem count as progress. |
| Six admitted chapters still lack claim atoms | **Accepted and closed by the R16-A terminal receipt.** | `evidence_quality/post_activation_six_chapter_claim_atom_addendum.json` now contains 30 reviewed atoms and six digest-bound chapter receipts. Its schema, builder, validator, identity-graph projection, Appendix C projection, and fourteen negative mutations preserve both historical denominators and move no support. |
| W3 is absent and repetition may be rising | **Guard criticism accepted and closed.** | The historical `d6f6e62d7` 61-chapter receipt remains history. The terminal W3 artifact reproduces the exact current pre-edit 84-chapter baseline at `99457770390a4af4848b9e43656907cfe099fd75`, records raw and editorial projections separately, centralizes the lifecycle method, preserves ten chapters' meaning custody, and prospectively rejects the tracked copied scaffold. |
| White-Box depth was twice deferred | **Accepted and closed by T1D.** | The chapter now includes the comparative method matrix and noninheritant evidence ladder. The probe-control, interpretability-illusion, SAE-scaling, SAEBench, and SAE-reliability records are inventoried, passage-noted, mapped, and bounded; the 2026 reliability audit remains metric- and setting-scoped counterevidence rather than a field-wide negative. |
| Optimizer work was the only commissioned item substantially closed | **Accepted.** | Treat R16-E's source/prose/policy-contract depth amendment as terminal at argument support. Its shared atom and reader obligations are completed through R16-A/R16-B. A future matched optimizer campaign remains evidence work, not another manuscript-depth gate. |

### Enforced next-action sequence

Two slots may operate, but each slot has exactly one eligible packet:

1. **Empirical slot — P2-R3a:** remeasure capacity, write a commit-bound
   capacity receipt, and implement or execute the queue-wide sealed
   materializer. Stop as `blocked` only on a new exact failing gate. Do not
   inherit the superseded capacity diagnosis.
2. **Empirical slot — P2-R3b:** after 30/30 materialization receipts and the
   monitor soak pass, resume rank 5 under the frozen three-attempt setup rule,
   qualify four replacement slots, and restore the twelve-task denominator.
   Rank 6 stays closed unless the deterministic amendment permits it after the
   exact rank-5 disposition.
3. **Book slot — R16-A terminal receipt:** six of six chapter packs and thirty
   atoms are reviewed, schema-valid, identity-reconciled, projected into
   Appendix C, and non-promoting.
4. **Book slot — W3 terminal receipt:** the current 84-chapter baseline,
   centralized method owner, ten semantic-diff reviews, copied-scaffold
   rejection, distinct-fixture acceptance, and eighteen negative mutations are
   committed together with zero support movement.
5. **Book slot — P7.2-T1D terminal receipt:** six of six chapters pass the
   manuscript-maturity gate; the White-Box source/method packet, four
   existing-owner repairs, applicable atoms, reader projections, appendices,
   chapter-specific inheritance evidence, and validator agree without support
   movement.
6. **Book slot — R16-B terminal receipt:** the content-addressed derivative
   reproduces all 84 frozen-commit chapter projections, all 22 narrative
   units, the exact 11/54/7/12 role partition, and eight required reader
   surfaces. It preserves the historical reader manifest, avoids a duplicate
   84-chapter source tree, defers five unreviewed formats explicitly, rejects
   sixteen mutations, and moves no support, release, or publication state.

### P2-R3a exact capacity and Docker receipt — 2026-07-26

The first enforced empirical action is complete at its exact admissible scope.
Attempt `2026-07-26-r3a-001`, bound to source commit
`9349d519130f37c86f319cd94147e57e3848b819`, measured
`10,894,745,600` available host bytes against the frozen
`53,687,091,200`-byte floor. The Docker client was installed, but
`docker version` returned `EOF`, `docker info` timed out after 30 seconds, and
`docker system df` returned `retrieving disk usage: EOF`. Docker-reclaimable
bytes are therefore unknown and no reclamation was attempted.

The immutable result binds the resource contract and all 30 frozen candidates
by digest and retains four exact command transcripts. It records zero image
pulls, zero dependency materializations, zero protected-content reads, zero
candidate outcomes, N0, and no support or release movement. Neither rank 5 nor
rank 6 advances. The empirical slot is blocked until a later exact receipt
shows at least 50 GiB free and a reachable Docker daemon; a passing receipt
then launches the content-sealed sequential materializer. The parallel formal
slot may continue dependency-safe rationalization, but cannot be reported as
P2 movement.

### P2-R3a exact capacity and Docker receipt — 2026-07-27

The next exact preflight is also complete at its admissible scope. Attempt
`2026-07-27-r3a-002`, bound to source commit
`2aae71bf83909298f4c5ebd5c6a819f687ba772e`, measured
`25,627,230,208` available host bytes against the unchanged
`53,687,091,200`-byte floor. Direct Docker diagnostics established that the
client was installed but the daemon was not usable: `docker version` returned
`EOF`, `docker info` reached its 30-second timeout, and `docker system df`
returned `retrieving disk usage: EOF`.

The immutable result binds the same resource contract and all 30 frozen
candidates by digest. It records zero image pulls, zero dependency
materializations, zero protected-content reads, zero candidate outcomes, N0,
and no support or release movement. It does not erase the 2026-07-26 history
and it does not count as a candidate attempt. The higher available-byte
observation improves the measured shortfall from `42,792,345,600` to
`28,059,860,992` bytes but still fails the frozen floor. No Docker reclamation
was attempted because the daemon and reclaimable-byte measurement remained
unavailable; no deletion of non-Docker user data is authorized.

The empirical slot remains infrastructure-blocked. Its exact unblock trigger
is unchanged: a later receipt must show at least 50 GiB free and a reachable
Docker daemon before the content-sealed sequential materializer may start.

### P2-R3a exact capacity and Docker receipt — 2026-07-28

The third exact preflight, `2026-07-28-r3a-003`, is bound to clean, deployed,
and publicly attested source commit
`cef11abd5fca0a421087b3123c1defb31f2b4e6d`. It measured only
`4,690,223,104` available host bytes against the unchanged
`53,687,091,200`-byte floor, a `48,996,868,096`-byte shortfall. Direct
out-of-sandbox Docker diagnostics again found the client but not a usable
daemon: version returned client metadata followed by `EOF`, info timed out
after thirty seconds, and storage inspection returned `EOF`.

The receipt preserves all prior attempts and binds the same resource contract
and 30-candidate queue. It opened no task content or candidate outcome and ran
no image pull, dependency materialization, evaluator, model, or task-specific
command. No rank was burned. No Docker reclamation was attempted because
reclaimable bytes remain unknown, and deletion of non-Docker user data remains
unauthorized.

This is another N0 infrastructure disposition, not a candidate or architecture
result. P2 remains resource-blocked without consuming active WIP. Its unblock
trigger is unchanged: at least 50 GiB free and a reachable Docker daemon in a
later immutable receipt.

### P2-R3a exact capacity and Docker receipt — 2026-08-13

The fourth immutable preflight, `2026-08-13-r3a-004`, is bound to source commit
`a91616b8abbabdc5ffe8e6da0c6d16124df32f45`. It measured `7,640,485,888`
available bytes against the frozen `53,687,091,200`-byte floor, a shortfall of
`46,046,605,312` bytes, and found no reachable Docker daemon. The combined gate
failed before materialization. No protected task content was opened, no image
pull or dependency setup started, and this N0 infrastructure disposition does
not count as a candidate attempt. The 30-candidate queue and fixed denominator
remain sealed. No cleanup of non-Docker user data is authorized. Restore both
the host floor and Docker daemon, then write a new immutable preflight before
any pull. No support or release state moves.

The sequence may move past a packet only when its validator, negative controls,
status projection, changelog, clean `main` commit, and exact residual record
agree. “Blocked” requires a current command, artifact, failing predicate, and
unblock trigger. Source count, word count, chapter depth, proof count, and a
green general build cannot substitute for the active packet's terminal
artifact.

This amendment does not declare the remaining eleven candidates rejected or
the architecture complete. It changes their state from active structural work
to an ordered queue behind empirical recovery and current-book integration.

## Round 18 bounded breadth-completion amendment

The owner then made a deliberate strategy change: finish the conceptual map,
put useful prose in the manuscript, and remove planning-only ideas before
returning to empirical depth. This instruction superseded the Round 16/17
admission sequence for one transaction only. It did not reject the empirical-
starvation criticism, change a support state, inspect a held-out outcome, or
authorize continuing structural expansion.

The controlling adjudication is
`docs/round_18_bounded_breadth_completion_adjudication_2026_07_24.md`.
Its terminal outputs are:

1. five new argument-level chapters—Perception, Embodied Agency, Human–AI
   Organizations, Multi-Agent Dynamics, and Inner Alignment;
2. seven existing-owner integrations—causal reasoning, typed uncertainty,
   scaling/emergence forecasting, instrumental convergence, RAG, artificial
   moral status, and decision theory;
3. twenty-one public primary-source inventory records and source notes;
4. five claim-source-complete manifest packets, birth claim atoms, and reader
   handoffs; and
5. a post-transaction structural freeze at 66 chapters.

The five chapters passed a distinct-owner test: each owns a system transition
with its own mechanism, interfaces, invariants, failure family, evaluation
route, and non-claims. The section-scale topics failed that test because an
existing chapter already owns their consequential boundary. Topic importance,
source count, or novelty is not enough to create a chapter.

**Stop rule.** One post-transaction sweep may classify further gaps, but the
default is assignment to an existing owner. A future chapter requires a dated
roadmap amendment showing that the distinct-owner test still passes and naming
the completed material empirical/evidence checkpoint that justifies the
integration cost. The seven remaining candidates from the 2026-07-19 audit are
research records, not an active admission queue.

**Empirical return.** The first post-transaction empirical action is a fresh
capacity and Docker receipt plus the exact P2 materialization attempt when the
frozen entry conditions hold, or an exact command-bound failure receipt. The
2026-07-24 observation is below the 50-GiB floor and Docker inspection lacked
socket permission; those facts are blockers to record and resolve, not license
for another prose packet. The older six-chapter atom pack and W3 are terminal;
the six-chapter T1D depth pack and current-reader freshness packet are terminal. The
five Round 18 chapters do not
increase that atom debt because their birth atoms and reader projection ship
inside this transaction.

Appendix C already consumes the claim-identity graph. The canonical public
status object and generated `publication_readiness.md` block now consume its
115/115 resolution, 25 direct, 61 subclaim, 29 proxy, and zero-parent-movement
counts and bind the graph digest.

The KERC result is retained as the observation that its frozen configured
pipeline failed its preregistered gate on the authored 192-record corpus. Its
0.5 task score, missing adversarial-polarity training class, jointly authored
compiler/verifier, small linear cores, redundant residual storage, and
uncalibrated energy prevent that result from being cited as a refutation of
Kernel English, learned cognitive compilation, hierarchical residuals, or the
broader architecture unless a competence audit establishes a stronger N-level.

## Post-Round-18 depth and coverage amendment

The controlling review reconciliation is
`docs/post_round_18_depth_and_coverage_review_reconciliation_2026_07_24.md`.
It audits exact manuscript text rather than accepting raw keyword counts. The
review's broad conclusion has teeth—depth, not breadth, is now the book's
binding conceptual constraint—but several alleged omissions are stale:
Failure Modes already owns instrumental convergence; Governed World Models
already owns causal/confounding assumptions, typed uncertainty, calibration,
and conformal prediction; Virtual Context ABI already owns a governed RAG
pipeline; and Moral Uncertainty already owns a bounded artificial-moral-patient
and welfare section.

The amendment accepts four central chapter-depth defects: Inner Alignment needs
explicit deceptive-alignment, training-game, gradient-hacking, and competing-
explanation distinctions; Multi-Agent Dynamics needs formal game-theory,
equilibrium, bargaining, social-choice, mechanism-design, and learning-in-games
foundations; Perception needs concrete Bayesian state-estimation and sensor-
fusion regimes with observability, calibration, correlation, and degradation
boundaries; and White-Box needs the already-queued probe, sparse-autoencoder,
dictionary-learning, construct-validity, causal-intervention, and failure
treatment. Embodied Agency and Human–AI Organizations receive full maturity
reviews as part of the same packet rather than escaping scrutiny because the
keyword audit named fewer omissions.

Four narrower accepted repairs remain with existing owners:

1. make epistemic, aleatoric, structural/causal, and distributional uncertainty
   explicit in Governed World Models without duplicating its causal section;
2. add refinement types, dependent types, proof-carrying data, and finite-
   encoding limits to Executable Specifications and the Lean Proof Envelope;
3. add a governed synthetic-data and self-play generation lifecycle to Data
   Engines; and
4. add a faithful, decision-relevant, comprehensible explanation-generation
   boundary to Human Factors, with internal evidence handed to White-Box.

Human–AI Organizations additionally owns a bounded organizational-transition
section on task versus job effects, adoption and diffusion, bargaining,
distribution, deskilling/reskilling, concentration, public capacity, and
economy-wide inference limits. Instrumental convergence, RAG, and artificial
moral status receive handoff maintenance only, not duplicate sections.

### Claim-bearing chapter maturity gate

“Proof-ready” means specified enough for competent implementation and a fair
test; it does not mean proved, empirically supported, or promoted. Before a
chapter-specific claim-bearing experiment may earn N3 scope, a reviewed
maturity record must establish all six conditions:

1. **field decomposition** — central sub-concepts, contested definitions, and
   adjacent-owner boundaries are taught rather than merely named;
2. **strongest challenge** — the strongest counterargument, a simpler
   baseline, and any favorable/oracle regime are explicit;
3. **implementation determination** — state, interfaces, update rules,
   activation, fallback, observables, and prohibited shortcuts constrain two
   competent implementations to materially equivalent mechanisms;
4. **failure and non-claim envelope** — implementation, mechanism, construct,
   evaluator, resource, and out-of-scope failures are separated;
5. **literature engagement by role** — passage-reviewed primary work is used
   for mechanism/capability, limitation/failure, competing design or simpler
   baseline, and measurement/evaluation where available; and
6. **territory-sized reader value** — explanation, synthesis, examples,
   handoffs, and useful visuals cover the owned transition without padding,
   duplicated method prose, or a numeric word-count proxy.

The maturity record names exact chapter locations, residuals, reviewer, date,
and maximum next inference. Failing the gate does not delete an argument-level
chapter. It prevents a naive or under-specified implementation from creating a
mechanism-level negative inference.

### P7.2-T1D — proof-readiness depth pack

This packet supersedes the narrower White-Box-only depth packet while
preserving every White-Box obligation. It covers Inner Alignment, Multi-Agent
Dynamics, Perception, Embodied Agency, Human–AI Organizations, and White-Box
Evidence, plus the four existing-owner repairs above. It follows R16-A and W3,
runs after R16-A and W3 and precedes the combined current-reader derivative.

**Terminal receipt, 2026-07-26:** the accepted meaning-bearing prose is
present in all six chapters and all four existing-owner repair surfaces.
Inner Alignment distinguishes deceptive alignment, training games, gradient
hacking, sleeper policies, and competing explanations; Multi-Agent Dynamics
teaches games, equilibrium, bargaining, social choice, mechanism design, and
learning in games; Perception specifies Bayesian estimation, observability,
correlation-aware fusion, calibration, and degradation; Embodied Agency
specifies hybrid control, end-to-end timing, independent safety paths, and
sim-to-real limits; Human–AI Organizations covers task/job transitions,
diffusion, distribution, skill, concentration, and public capacity; and
White-Box separates probes, sparse dictionaries, circuits, construct validity,
and causal challenge. The uncertainty, type-system/proof-carrying-data,
synthetic-data/self-play, and explanation-generation repairs are also written.
The deterministic packet records six maturity records, 36 passed manuscript
conditions, 12 chapter-specific anchors with one corpus owner each, four
existing-owner repairs, five White-Box source receipts, ten applicable claim
identities, exact reader projections, and eighteen rejecting mutations.
`docs/p7_2_t1d_six_chapter_maturity_and_source_role_review_2026_07_26.md` and
`evidence_quality/p7_2_t1d_six_chapter_maturity.json` are the human and machine
receipts. Word count, heading count, citation count, or a green generic build
did not substitute for semantic review. No prose or source change moves
support; the unrun model campaigns remain ordinary evidence residuals.

### P6.4-N/O — approved research candidates behind the freeze

Two post-Round-18 candidates appear to own distinct transitions:

- **Candidate N — Adversarial Machine Learning and the Model Attack Surface**
  (`adversarial-machine-learning-and-model-attack-surface`)
  provisionally belongs in Part I beside Security Kernel. It owns a versioned
  learned-model threat and attack/defense lifecycle across evasion and
  adversarial examples, poisoning, backdoors/trojans, jailbreak/safeguard
  bypass, extraction/stealing, inversion, adaptive and transfer attacks,
  multimodal/agentic surfaces, defenses, residuals, and disclosure. It must not
  duplicate system/tool security, privacy, supply-chain provenance, or
  adversarial evaluation.
- **Candidate O — Learning Theory, Generalization, and Scaling Science**
  (`learning-theory-generalization-and-scaling-science`)
  provisionally belongs in Part III near Governed Model Training and Efficient
  ASI. It owns the evidence contract joining data, hypothesis class,
  optimization, inductive bias, compute, and evaluation to a bounded
  generalization, transfer, emergence, or scaling claim. It must integrate
  PAC/distribution-dependent views, complexity and stability, compression/MDL/
  information-theoretic views, implicit bias, interpolation and double descent,
  grokking, scaling-law diagnostics, emergence measurement, OOD transfer,
  compositionality, credit assignment, and theory limits without becoming a
  duplicate training chapter or a disconnected survey.

These are **research and adjudication candidates, not chapter admissions**.
Candidate research is not a third WIP lane and may not displace T1D or P2. It
begins only after a completed material P2 empirical/evidence
checkpoint and terminal T1D depth work, when the existing-book slot is
available. Manifest admission additionally requires a dated decision packet
passing the ordinary exclusive-owner, competence, reader-value, safety,
birth-artifact, and non-displacement gates. Admit at most one per checkpoint.
Sixty-eight chapters is a possible result if both pass, not a target or a
completeness claim.

After T1D and both candidate decisions, run one concept/interface/artifact/
lifecycle/failure/source-role coverage sweep. Every finding receives an exact
owner, accepted depth residual, admitted distinct owner, research-only
candidate, or explicit out-of-scope boundary. Raw keyword counts do not
adjudicate completeness. Structural freeze is the default afterward.

## 2026-07-25 full-coverage and owner-completion amendment

This amendment supersedes the structural counts and candidate/freeze language
above where they describe current state. The exact audit is
`docs/full_coverage_gap_audit_2026_07_25.md`; its machine-readable intake and
triage records are
`research_backlog_records/full_coverage_gap_audit_2026_07_25.json` and
`new_paper_triage_scenarios/full_coverage_gap_audit_2026_07_25.json`.

The audit reviewed the complete 80-chapter pre-transaction manifest and current
manuscript rather than treating old candidate lists or keyword counts as
coverage truth. It found four distinct unowned lifecycles and admitted them at
argument support:

1. `military-ai-autonomous-weapons-and-strategic-stability` — the joined
   mission, command-authority, context-specific human-judgment, physical-
   effects, adversary-response, crisis-timing, escalation, proliferation,
   legal-review, off-ramp, and fail-safe lifecycle;
2. `confidential-and-verifiable-ai-computation` — execution across distrust
   boundaries with separate input/model privacy, integrity, authenticity,
   attestation/proof, leakage, freshness, verifier policy, cost, fallback, and
   authorization boundaries;
3. `human-ai-symbiosis-neurotechnology-and-cognitive-sovereignty` —
   longitudinal bidirectional coupling across complementarity, adaptation,
   skill, dependence, neural and inferred mental data, stimulation, consent,
   accessibility, cognitive sovereignty, and practical exit; and
4. `relational-dimension-compilation-and-polyadic-cognition` — the full typed
   relational-IR, candidate-topology, lower-order-rescue, role-persistence,
   qualification, adaptive-order, compilation, contraction, and RODIE
   lifecycle.

The Relational Dimension Compiler admission closes a contradiction between the
book's no-deferral policy and an obsolete Round 16 freeze statement. The source
note had already found a distinct owner. The manifest now carries that owner;
no implementation or empirical support is inferred.

Eight narrower findings were written into existing owners in the same
transaction:

- no-free-lunch, identifiability, and an assumption ledger in Learning Theory;
- neuromorphic, analog/in-memory, photonic, quantum, and biohybrid substrate
  families plus end-to-end accounting in Replaceable Substrates and Physical
  Compute;
- post-quantum cryptographic inventory, agility, migration, and retirement in
  Security Kernel and Model-Weight Custody;
- three-arm complementarity and longitudinal co-adaptation in Human-AI
  Organizations and the new Symbiosis owner;
- infrastructure concentration, switching, common-mode bottlenecks, and
  effective exit in Deployment, Institutions, and Physical Compute;
- civil liability, insurance, evidence access, compensation, and remedy in
  Institutions and Human-AI Organizations;
- multilingual and culturally grounded intent, communication, and
  language-by-task evaluation in Human Intent, Communication, and Benchmark
  Ratchets; and
- neural data, inferred mental state, derived-state deletion, and
  secondary-purpose controls in Privacy and Symbiosis.

Eighteen primary or official external-source records and bounded notes support
the new prose. Source-reported results remain external. All four chapters and
all section claims remain `Design rationale + argument`; no chapter-core
support, release, legal conclusion, cryptographic guarantee, human outcome,
military-policy result, SOTA, AGI, or ASI claim moves.

The working manifest is now **84 chapters** and the source inventory is **468
records**. No meaning-bearing idea found by this audit remains deferred.
Artificial moral patients, model collapse, causal inference, RAG, conformal
uncertainty, optimizer families, and other reviewed candidates stay with their
existing substantive owners; this is a duplicate-chapter decision, not a
rejection of those topics.

## 2026-07-25 evidence-and-convergence review amendment

The full-book review adjudication is
`docs/chatgpt_pro_full_book_review_adjudication_2026_07_25.md`. It accepts the
central diagnosis that the architecture is structurally mature relative to its
natural evidence and global narrative, while rejecting stale or unsupported
surface claims. In particular, Appendix E already covers all 84 manifest
chapter IDs and Appendix F is not empty. README, landing-page, product,
reader-labeling, release-guidance, and transition-count drift were repaired in
the 2026-07-25 public-surface reconciliation. At review time, the remaining
confirmed public-truth defects were the stale v1.0 preface sentence, the
deferred RDC glossary row, and the role table that accounted for only 61 of 84
chapters; this amendment's C0 transaction repairs those three defects and adds
regression coverage.

This amendment does not create a new chapter queue, a third WIP slot, or a new
flagship. It makes convergence around the existing three defended
contributions binding and gives the current roadmap nine exact work packets:

### C0 — Canonical public-truth incident and regression

Close the real Living Book incident rather than merely editing visible prose.
The packet must:

1. repair the preface, RDC glossary status, current chapter-role projection,
   and any remaining reader-visible obsolete identity;
2. preserve historical release identities only on explicitly historical
   surfaces;
3. verify 84/84 Appendix E chapter coverage and a nonempty current changelog;
4. create an exact 84-entry, one-role chapter map and reject missing,
   duplicated, or non-manifest owners;
5. preserve the current 84-chapter/468-source/25-non-core-transition public
   contract; and
6. retain the stale counts and release language as rejecting regression
   fixtures rather than deleting the evidence that the incident occurred.

Mutable status prose should move toward canonical generated includes. Until
that migration is complete, validators must derive current counts from
`book_structure.json`, the source inventory, transition records, and product
contracts instead of embedding another hand-maintained denominator.

### C1 — Noninheritance thesis and terminology convergence

Make **noninheritance** the opening law that explains why a stack is required:
capability does not grant authority; context does not become belief or
permission; plans do not create effects; receipts do not establish reality;
theorems do not establish runtime enforcement; replacements do not inherit
qualification; and self-improvement proposals cannot ratify themselves.

Apply three projections to every thesis-bearing narrative unit:

1. a plain-language thesis;
2. a normative engineering rule; and
3. a machine contract with exact scope and nonclaims.

Use established systems terms before private lineage labels, keep the lineage
label second where it remains useful, and maintain a comparator/ownership map
for every retained branded term. Rename the reader-facing **Beyond the State of
the Art** heading to **Mature Research Target** or **What a Successful
Implementation Would Add** while preserving machine implementation-horizon IDs
and immutable historical artifacts.

### C2 — Twenty-two-unit narrative book over the 84-module reference

The former fifteen-chapter narrative projection was a candidate, not the final
human interface. The current Phase 1 transaction builds and reviews a
**22-unit** narrative route while preserving
all 84 canonical reference chapters:

1. stack thesis;
2. efficient-ASI hypothesis;
3. authority and failure boundaries;
4. evidence states and noninheritance;
5. constitutional, value, and objective governance;
6. Stable Capability Fields and replacement;
7. intent and command contracts;
8. planning;
9. governed world models;
10. cognitive compilation;
11. Virtual Context ABI and context transactions;
12. durable memory and procedural consolidation;
13. verification bandwidth;
14. claim ledgers and proof-carrying review;
15. Labor OS and artifact graphs;
16. runtime adapters, observation, and governed operations;
17. routing and replaceable cognitive substrates;
18. governed training and developmental learning;
19. readiness, benchmarks, safety cases, and bounded liveness;
20. resource economics and effect-complete recovery;
21. recursive improvement, the integrated architecture, and prototype program;
22. Living Book methodology and open challenge agenda.

A unit may be a canonical chapter, a semantic overlay, or a compound
reader-only synthesis. It may not fork claim identity or erase a canonical
owner. Each unit must advance the governed repository-change case or clearly
route to optional reference material. The generated narrative entry must list
each specialist reference owner under its assigned unit and provide a direct
Human-view link; machine-only crosswalk membership is not sufficient
discoverability. The root projection manifest must bind the exact crosswalk
digest, and validation must reject a hidden, stale, duplicated, or missing
owner. The reader route is terminal only after
meaning-preservation, link, role, handoff, glossary, source, claim, evidence,
browser, accessibility-preparation, and all-chapter coverage checks pass.

### C3 — Governed Transition Calculus

Define one small kernel shared by the chapter-specific contracts:

\[
T = (I_s, I_t, A, O, E, R, C, \tau, \Pi)
\]

where source and target identity, authority, obligations, evidence, residuals,
consumers, expiry/revocation, and rollback/compensation/retirement remain
separate. The first implementation belongs jointly to Executable
Specifications, System Boundaries, Integrated Reference Architecture, and the
protocol appendix; it does not justify a new chapter.

The calculus must give exact, nonvacuous models, countermodels, mutations,
executable consumers, and maximum inference for:

1. authority non-escalation;
2. evidence non-promotion without an accepted transition;
3. context non-authority;
4. plan/effect separation;
5. receipt/observation separation;
6. residual conservation;
7. revocation propagation;
8. replacement noninheritance;
9. rollback closure or explicit unresolved effect;
10. bounded liveness;
11. cross-layer identity preservation; and
12. no self-ratification of protected constitutions or evaluators.

### C4 — Developmental Intelligence Loop

The book must explain how the governed stack becomes more capable, not only how
it constrains a capable component. Join existing owners into one lifecycle:

`curriculum construction -> world interaction -> prediction error ->
representation and abstraction formation -> causal intervention -> memory
consolidation -> proceduralization -> skill composition -> quiescent
stabilization -> readiness review -> authority-gated promotion`.

Governed Model Training owns run state and optimization; World Models own
qualified prediction and intervention; Durable Memory owns belief
consolidation; Procedural Memory owns trace-to-skill promotion; Scientific
Discovery owns experiment governance; Open-Ended Improvement and RSI own
proposal and protected promotion boundaries; the Integrated Reference
Architecture owns the joined trace. Completion requires a natural task,
positive controls, transfer probes, counterfactual or intervention evidence,
forgetting and regression checks, stability epochs, total cost, and an honest
terminal outcome. More prose alone cannot close C4.

### C5 — Minimal trusted kernel and bounded liveness

Produce a minimum trusted-kernel map rather than relocating opacity into a
large governance plane. For identity, time, authority, policy, context
resolution, artifact custody, observation, evaluation, sandboxing, rollback,
and release, record:

- the minimum property that must be trusted;
- what can be independently witnessed or mutually checked;
- compromise and Byzantine behavior;
- revocation and recovery behavior;
- downstream consumers; and
- the exact condition that forces safe hold.

Bind this map to a bounded-liveness contract: every admitted task reaches a
terminal disposition; every residual has an owner, age, escalation, and
retirement rule; every quarantine has an exit or terminal retirement;
review/replan loops have finite budgets; blocked work reports its minimum
missing condition; and useful throughput, false blocking, latency, human time,
compute, residual burden, and governance cost are measured jointly. A system
that remains safe only by never completing useful work fails the joint gate.

### C6 — P0–P6 semantic proof rationalization

Keep the existing syntax-level classifier, but add a semantic-depth overlay for
every current declaration. The immutable pre-rationalization baseline contains
1,370 declarations; the live estate contains 1,219 after 157
dependency-safe retirement transactions and two proposition-preserving scope
rewrites:

| Level | Required meaning |
|---|---|
| P0 | schema, type, or record-shape property |
| P1 | finite route, rejection, or preservation property |
| P2 | reachability, witnessed execution, and nonvacuity |
| P3 | implementation refinement or runtime-monitor binding |
| P4 | cross-component safety, noninterference, or adversarial composition |
| P5 | bounded liveness, recovery, revocation, or concurrency |
| P6 | empirically bound semantic property with a named observation contract |

Every theorem receives assumptions, consumer, reachable witness or explicit
unreachability, implementation binding, mutation coverage, semantic owner,
maximum inference, and retain/rewrite/retire disposition. Raw theorem count is
not a headline success metric. Unused, duplicate, vacuous, or record-shape
results remain valid at their earned level but must not borrow stronger
language from neighboring results.

### C7 — Natural governed repository-change flagship

`ASI-THESEUS-FLAGSHIP-01` remains the one empirical spine. Do not create a
parallel benchmark. Its matched comparison must include:

- direct strong-agent work;
- an ordinary agentic workflow;
- a deterministic CI/workflow control;
- the full governed stack; and
- a bounded human-assisted governed route using the same declared help budget.

Hold model access, repository state, task information, compute, retries,
human-help budget, and evaluators constant where the estimand requires it.
Freeze positive controls, competence thresholds, simpler alternatives,
architecture-challenge thresholds, stopping rules, rescue ceilings, and
promotion conditions before protected outcomes open.

Inject prompt/source-file attacks, stale authority, scope expansion,
insufficient or malicious tests, wrong-commit receipts, dependency drift,
correlated verification, partial effects, code-only rollback, stale generated
derivatives, false tool success, hidden reviewer burden, and unauthorized
self-modification. Measure useful task success, unauthorized effects, false
blocking, missed help, defect escape, detection and recovery time, rollback
closure, residual burden, compute, latency, human time, context volume,
evaluator disagreement, trace completeness, support overclaim, and total
lifecycle cost together.

### C8 — Evidence-led publication and derivative papers

The three defended contributions remain:

1. governed-cognition interface contracts;
2. public claim-state transition discipline; and
3. record/reality reconciliation and residual honesty.

Routing, developmental learning, trusted-kernel minimization, bounded liveness,
and the calculus are mechanisms or evaluation dimensions for those three, not
five new flagship claims. After C6 and a terminal C7 result, prepare bounded
standalone papers for the contributions and the benchmark. Do not lead with
chapter, theorem, schema, or source counts.

Independent implementation and reproduction remain required before broad
transfer or architecture claims. Consistent with author instruction, no other
human is a prepublication completion gate. Postpublication specialist challenge
packets may remain available, but unfinished private review cannot block the
book.

### Convergence dependency order

1. Finish C0 and attest the current public surface.
2. Preserve the terminal C1, current 84-chapter role map, and W3 inheritance
   receipts without waiting for flagship outcomes.
3. Keep P2/T0A–T4 as the empirical headline; C3–C6 may build only the artifacts
   required by that campaign and the narrative.
4. Freeze C7 baselines, competence, challenge thresholds, injections, metrics,
   and stopping rules before outcome opening.
5. Run the matched natural campaign and give it an earned terminal
   disposition.
6. Thread the stable happy, blocked, failed, revoked, rollback, and residual
   traces through C2.
7. Run independent reproduction/transfer gates before broad claims.
8. Prepare C8 derivatives and close only with exact public truth and one active
   successor.

### Phase 1 prose-first execution receipt and Phase 2 entry — 2026-07-25

Phase 1 used **idea placement and narrative convergence before proof
execution**. The C1–C8 prose transaction is recorded in
`docs/c1_c8_phase1_idea_placement_and_prose_audit_2026_07_25.md`.
Noninheritance, the Governed Transition Calculus, the Developmental
Intelligence Loop, the minimum trusted kernel, bounded liveness, the P0–P6
semantic-depth overlay, `ASI-THESEUS-FLAGSHIP-01`, and the three
contribution-owned derivative packages now appear in their primary manuscript
owners rather than only in this roadmap.

The narrative product now has 22 representative units. The exact crosswalk in
`products/narrative_unit_crosswalk.json` assigns all 84 canonical chapters once
without merging their claims, and the generated cumulative repository-change
trace carries one new artifact through every unit. Exact coverage and local
contract validation pass. The first current candidate also renders 27 HTML
pages and passes 54 desktop/mobile browser page-view pairs. The authorial
compound-unit meaning review, retained-lineage ownership map, cross-owner
links, two synthesis figures, and 54-pair automated accessibility-tree
preparation check now pass. A clean canonical render produced 97 pages: all 84
chapters and 11 appendices. The mature-heading reconciliation is complete: all
84 canonical chapters and current derivative contracts use `Mature Research
Target`. The 2026-07-26 narrative-spine v1 reconciliation also gives every one
of the 22 units a distinct plain-language thesis, normative engineering rule,
and bounded machine contract with an explicit noninheritance boundary. The
reader and product generators expose all three projections, while schema and
semantic validators reject their loss or boundary weakening.

The explicit all-84 idea-placement and narrative-coherence gate is therefore
passed. Phase 2 is now allowed, in this order:

1. classify the existing formal estate with P0–P6 semantic depth, named
   consumers, assumptions, witnesses, bindings, mutations, inference ceilings,
   and retain/rewrite/retire dispositions;
2. remove or rewrite vacuous, duplicate, unused, or semantically misleading
   proof rhetoric without invalidating narrow correct results;
3. formalize only the smallest cross-owner conclusions that a reachable
   implementation or the flagship actually consumes;
4. freeze the competent natural Theseus flagship prerequisites before opening
   any protected denominator;
5. run the matched natural campaign, retain null and inconclusive outcomes,
   and admit a negative inference only after the full competence standard
   passes; and
6. prepare evidence-led derivatives only from terminal, contribution-owned
   claim/source/artifact crosswalks.

Phase 2 does not reopen an ideas-only chapter queue. New worthwhile prose still
goes directly to its existing owner, while proof volume, theorem count, and
experiment activity remain subordinate to the bounded conclusions readers and
implementations actually need.

This amendment changes planning authority only. It creates no formal result,
natural evidence, support transition, reader release, deployment, SOTA result,
AGI/ASI claim, license grant, or publication authorization.

### Concept-first scheduling continuation — 2026-07-26

The initial all-84 Phase 1 gate remains a valid historical receipt, and Phase 2
remains admissible under the dependency order above. The current user-authorized
priority is nevertheless concept placement, semantic organization, and
navigability—not another theorem-retirement or proof-expansion tranche.

This continuation has three exit conditions:

1. every canonical chapter exposes its distinct responsibility, claim identity,
   claim label, and current support ceiling in the complete architecture
   reference;
2. every one of the 62 nonrepresentative chapters exposes the same responsibility
   and evidence boundary under its assigned narrative unit rather than only a
   title or machine-manifest membership; and
3. a roadmap-only idea audit either places each worthwhile concept in an existing
   prose owner or records why the existing owner already contains it.

The original 22-unit orientations, 84-chapter ownership, three defended
contributions, support states, proof results, and empirical gates remain
unchanged. Phase 2 proof execution is still logically allowed, but it is not
the current scheduling default and may not displace this concept-first pass.

### Concept-first exit receipt and Phase 2 resumption — 2026-07-26

The continuation's three exit conditions now pass. The complete architecture
reference exposes all 84 responsibilities and support ceilings; the narrative
units expose all 62 specialist owners; and the C1–C8 audit binds 26 exact prose
or product anchors across the canonical owners with zero roadmap-only
remainder. The structural-completeness, taxonomy, Round 18, and full-coverage
records retain zero live candidate queue. Runtime Adapters now states the
effect-boundary trusted-kernel/liveness projection, Readiness states its exact
Developmental Intelligence Loop stage, Resource Economics states the joint
bounded-liveness accounting projection, and Appendix D names the calculus
projection explicitly.

Phase 2 therefore resumes under the original dependency order. Its first
formal action is not proof expansion: rationalize the existing estate around
named consumers, retain useful narrow results at their earned P0–P6 level, and
rewrite or retire vacuous, duplicate, unused, or misleading rhetoric. Add a
new formal result only when a reachable implementation or the frozen flagship
consumes the smallest conclusion. The natural Theseus flagship remains the
empirical spine and may open protected outcomes only after its competence,
baseline, evaluator, attack, rescue, resource, and stopping contracts freeze.
New worthwhile prose still goes directly to its existing owner and reopens the
concept-placement audit when necessary.

This transition moves planning priority only. The 26 anchors, green product
checks, and zero-remainder ledger do not prove mechanism correctness, runtime
enforcement, capability, usefulness, safety, transfer, SOTA, AGI, or ASI and
do not move any support state.

### C6 current-estate classification and cumulative execution receipt — 2026-07-26

C6 closed its rationalization transaction with a complete then-current estate
classification, not merely the frozen historical review. The immutable
historical registry remains exactly 1,151
theorems across 298 targets. The separately frozen pre-rationalization overlay
at commit `d0f9bda14f1253999f2c40d556d925d31e4b36a4` classifies all 1,370
baseline declarations. At terminal C6 closure, the overlay classified all 1,219 live theorem
declarations across 105 theorem-bearing modules. That
denominator remains frozen in the cumulative rationalization ledger.

The dated 2026-08-01 Failure Modes, Governed Operations, Learned Objective
Integrity, Observation Trust, Search Substrate, Artifact Steward, Human-AI
Organizations, Multi-Agent Dynamics, Embodied Physical Safety, Dangerous Capability Review, Military Interaction Review, Societal Resilience Review, and Durable Semantic Memory Review expansions reopen
formal growth without rewriting that history. The current overlay in
`proofs/proof_semantic_depth_overlay.json` classifies 1,709 live theorem
declarations across 124 theorem-bearing modules and maps them to 78 active
semantic-owner chapters. The 490 added declarations are bound to the
five-stage failure-recovery model, the eight-stage governed-operations
lifecycle, the learned-objective non-identification witness and eight-stage
integrity lifecycle, and the declared-dependence pair classifier plus
seven-stage observation lifecycle, plus the reachable substrate-adoption
classifier with four accepted non-promoting traces and eight exact rejected
controls, plus the Artifact Steward reachable work-contract and release-review
models with arbitrary-length completeness invariants and seventeen exact
boundary controls, plus the Human-AI Organizations five-stage accountability
review with a finite-run invariant and twenty independent field mutations,
plus the Multi-Agent Dynamics pairwise-underdetermination model with nine
systemic-axis mutations and an exact Project Theseus campaign handoff, plus
the Embodied Physical Safety control-lease guard with 13 exact admission-axis
mutations, three arithmetic monotonicity controls, and an exact Project Theseus
closed-loop trial handoff, plus the Dangerous Capability Review seven-stage
dossier lifecycle, 29 exact mutation routes, two monotonicity laws, and scalar-
only classification impossibility result, plus the Military Interaction Review
eight-step non-operational lifecycle, 45 exact repair or refusal dispositions,
three monotonicity laws, and two non-identifiability results for interface
presence and local component evidence, plus the Open-Weight Release Review
six-step dossier lifecycle, 36 exact repair or refusal dispositions, two
monotonicity controls, and two non-identifiability results for official lineage
and default evaluation.
They also include the Communication Influence Review six-stage lifecycle, 42
exact repair or refusal dispositions, three adverse exposure monotonicity
controls, typed denied-attribute noninterference, and two non-identifiability
results for compressed surface signals and provenance.
They also include Objective Lease Governance, Adversarial Model Security,
Protected Computation Review, and Content Authenticity Review lifecycles with
exact mutation repair, scoped invalidation, non-substitution,
non-identifiability, and rejecting cross-owner consumer bridges.
They also include Replication Containment Review with 52 exact mutation
repairs, parent-lease noninheritance, finite descendant quarantine, receipt
invalidation, end-to-end and global-containment non-identifiability, and a
rejecting governed-operations bridge.
They also include Institutional Legitimacy Review with 45 exact mutation
repairs, jurisdiction and affected-public scope, receipt invalidation,
representation and enforcement non-identifiability, and a rejecting
Governance Rights bridge.
They also include Societal Resilience Review with 45 exact mutation repairs,
organization-bound authority, finite incident-path closure, adverse
monotonicity, receipt invalidation, population-resilience and equitable-remedy
non-identifiability, and a rejecting Institutional Legitimacy bridge.
They also include Durable Semantic Memory Review with 38 exact admission-axis
repairs, stable identity across representation rebuilds, arbitrary-parent
provenance and purpose constraints, migration and replay invariants, scoped
receipt invalidation, two non-identifiability pairs, and a rejecting Context
Transactions bridge.
Independently encoded validators preserve exact no-support
boundaries across every added model.

The live semantic-depth distribution is 26 P0 record-shape results, 864 P1
finite-route results, 139 P2 reachability/nonvacuity results, 491 P3
implementation-refinement results, 99 P4 cross-component-safety results, 90 P5
liveness/recovery results, and zero P6 empirically bound results. P6 being zero
is intentional: the existence of an experiment file, trace, or generated
artifact does not turn a theorem into empirical evidence.

Every overlay row records its assumptions, active semantic owner, downstream
consumer, witness or explicit witness absence, implementation binding, mutation
evidence, maximum inference, and disposition. The resulting current estate is
1,709 retain, zero retire as narrow projection, zero pending scope-language
rewrites, and zero stronger-model actions remaining. All 1,709 rows have
mutation coverage and every retained theorem has a named consumer. The
terminal rationalization receipt remains 1,219 retain with no pending action;
the later 490 theorems are additive consumer-owned formal expansion, not
retroactive rationalization.

The cumulative dependency-safe retirement ledger is
`proofs/proof_semantic_rationalization_ledger.json`. Its first transaction
removes only
`missing_outcome_audit_blocks_high_risk_admission` from the Scalable Oversight
refinement module, after immutable-baseline, same-module, normalized-statement,
dependency, consumer, and retained-target checks. Its canonical twin,
`high_risk_use_without_outcome_audit_requires_audit`, preserves the exact
bounded finite-model conclusion. No theorem consumer required migration, no
chapter-core support moved, and no empirical or release claim changed.

The first narrow-projection tranche then retires two direct predicate
restatements from `BibliographyPlan.lean`. The source-evidence target now points
to `source_derived_claim_without_source_record_rejected`, which derives the
failure of the finite predicate when both source-note and ingested-artifact
surfaces are absent. The chapter-assignment target now points to
`accepted_new_source_assignment_to_nonexistent_chapter_rejected`, which derives
the failure of the finite assignment predicate for an accepted assignment to a
missing chapter. Both retired projections had no theorem dependency or
consumer, both replacements remain live derived counterexamples, and the
manifest, outline, chapter, and structure records now name those retained
gates. This is rationalization of target meaning, not a stronger empirical
claim.

The second narrow-projection tranche retires two direct implication
restatements from `BenchmarkRatchets.lean`. The operational target now points
to
`accepted_readiness_promotion_requires_transfer_negative_and_regression_records`,
which derives three obligations from the accepted `promoteReadiness` decision
branch. The failure target now points to
`contaminated_review_cannot_promote_readiness`, which derives a contradiction
between accepted readiness promotion and observed contamination. The richer
decision predicate does not establish a general saturation-only prohibition,
so the old saturation implication is not laundered into the new target; the
chapter keeps saturation behavior in its synthetic anti-Goodhart harness and
states the narrower formal boundary explicitly. Both retired declarations had
no theorem dependency or consumer. The five canonical target surfaces and the
six-declaration chapter inventory now name only retained consequences.

The third narrow-projection tranche retires three direct implication
restatements from `PolicyOptimization.lean`. The promotion-evidence projection
is replaced by the same-model theorem that derives rejection when a promotion
candidate lacks holdout references or a contamination check. The reward-proxy
projection is replaced by the same-model theorem that rejects sole-proxy
promotion when target-evaluation evidence is absent. The authority-expansion
projection is replaced by the same-model theorem that rejects promotion when
governance approval or rollback is absent. Each retained theorem unfolds its
predicate and derives contradiction from an explicit invalid record rather
than returning an assumed implication. All three retired declarations had no
Lean dependency, theorem consumer, fully qualified current consumer, or proof
target, so the transaction invents no public target migration and changes no
chapter claim.

The fourth narrow-projection tranche retires seven direct field and lifecycle
predicate projections from `StableCapabilityFields.lean`. Two public targets
were broader than the model's retained derived routes: field identity now names
the mismatch-to-rejection route, and the lifecycle envelope now names the
review routes plus explicit retired-restart and default-readiness rejections.
The other five retired projections owned no public target or theorem consumer.
The ledger records a null replacement for each scope-reduction retirement
instead of pretending that an unrelated theorem proves dropped wording. The
retained `default_transition_requires_full_readiness` theorem remains because
five downstream consequences consume it. This transaction adds no formal
claim, changes no chapter-core support state, and narrows public meaning to
what the remaining model actually derives.

The fifth narrow-projection tranche retires nine declarations from
`EvidenceStates.lean`: three direct support/terminal/downgrade premise
projections, three audit-summary conjunction restatements, and three
claim-state summary-field projections. Four executable audits and their
historical result artifacts remain current at their recorded scope; their
validators no longer require a Lean declaration that merely unpacks an
assumed-valid summary. Five affected public targets are now honestly
`planned`: evidence admission must derive state-specific requirements from
reachable inputs, and the four audit bridges must derive accepted and rejected
outcomes from exact inputs or independently implemented audit logic. The
retained missing-evidence counterexample and transition-lifecycle route remain
implemented. No retired projection is replaced by an unrelated theorem, and
no executable audit result, chapter-core support state, or historical artifact
is erased.

The sixth narrow-projection tranche retires five declarations from
`RuntimeAdapters.lean`. One unused permission projection had no theorem
consumer. Three approval, lease-scope, and rollback projections were used only
as pass-through helpers; their retained rejection theorems now apply the
underlying predicates directly, so the contradiction and negative-case
conclusions remain without the extra theorem names. The adversarial-boundary
validator no longer treats a hand-authored valid-summary conjunction as a
formal bridge: its implemented public target is carried by fifteen named route
theorems covering thirteen rejection cases and two complete dispatch cases.
The target wording and status therefore remain unchanged. This transaction
also excludes the cumulative proof-custody validator from semantic
implementation binding: a meta-audit that inventories a module cannot make
every theorem in that module P3–P5. This corrects ten previously inflated
Benchmark Ratchets and Stable Capability Fields classifications without
changing their statements. This correction and the theorem retirements
preserve the wider permission, approval, lease, rollback, authority,
confused-deputy, sandbox, receipt, replay, revocation, and adversarial route
families while claiming no deployed enforcement, sandbox isolation, approval
service, rollback service, or runtime safety.

The seventh narrow-projection tranche retires five declarations from
`SearchSubstrates.lean`. Three merely returned consequences already supplied
by adoption-field, non-core, or core-adoption predicates. The two trace
declarations unpacked rejection and no-promotion flags from a valid-summary
predicate that already assumed those flags. The operational and failure
targets now name retained finite counterexamples: an explicitly incomplete
adoption record fails `AdoptionFieldsComplete`, and a record marked qualified
without passing evidence fails `CoreAdoptionValid`. The executable
substrate-adoption trace and historical result remain current as protocol
tests, but its formal bridge is honestly planned until a reachable Lean route
model independently derives four accepting and eight rejecting outcomes from
exact trace inputs. Six live declarations remain: five finite negative cases
and one authored fixture-validity theorem awaiting a stronger route model. No
substrate quality, adoption, runtime, support, or release conclusion changes.

The eighth narrow-projection tranche retires four assumption-restating
declarations from `ArtifactStewardAgents.lean` and removes their otherwise
unused record predicates instead of retaining dead formal surface. The
treasury target now names the retained lifecycle reduction that routes
requested spend outside policy to approval. The sunset target now names the
retained lifecycle reduction that routes unmet review obligations to
`openSunsetReview`; the executable invalid trace separately rejects ordinary
work. The work-contract dispatch and release-gate targets are honestly planned
until reachable decision functions derive repair or refusal from missing
fields. Their schema and executable-trace artifacts remain at record-shape and
protocol-test scope and are not presented as equivalent Lean proofs. Twelve
route declarations remain across lifecycle, contribution-ledger, and
federation functions. No steward runtime, treasury enforcement, protected
asset isolation, release enforcement, support transition, or publication
authority follows.

The ninth narrow-projection tranche retires four assumption-restating
declarations across `CoilAttentionMemory.lean` and `CyclicMixers.lean`.
The cyclic-memory hooks now name retained finite counterexamples: a reused
slot with missing residue or winding and no visible alias residual fails the
alias-boundary predicate, and a retrieval-quality record promoted from sparse
coverage and freshness without semantic-quality evidence fails the
quality-promotion predicate. The cyclic-mixer hooks likewise name retained
negative cases: a review missing any structural, quality, runtime, memory, or
parameter partition fails the structural-claim predicate, and a promoted
substrate missing baseline references or tradeoff metrics fails the promotion
predicate. All four retired declarations had no theorem dependency or theorem
consumer. Their underlying records and predicates remain because the retained
negative cases use them. This narrows formal meaning without changing the
chapters' architecture guidance, executable fixtures, structural receipts,
support states, empirical results, or release authority.

The tenth narrow-projection tranche retires three unused premise projections
across `Efficiency.lean` and `FailureModes.lean`. The efficiency targets now
name retained finite counterexamples: a listed lower-cost authorized,
quality-preserving candidate falsifies the minimum-viable-route predicate, and
a promoted result with open obligations but no residual record falsifies the
residual-promotion predicate. The failure-mode target now names the retained
incident decision branch that routes authority over its ceiling to explicit
authority review. All three retired declarations had no Lean dependency or
theorem consumer. Twenty-four Efficiency declarations and twenty-two Failure
Modes declarations remained at the close of that tranche. These migrations
prove no route-search completeness, measured efficiency, residual-burden
reduction, runtime authority detection, containment, mitigation effectiveness,
support transition, or release authority.

The eleventh narrow-projection tranche retires four valid-summary projections
across `FailureModes.lean`, `IntentToExecution.lean`, and `Planning.lean`.
Their independent Python consumers now bind directly to retained theorem
families: fifteen failure-record routes, nine execution-dispatch routes,
fourteen plan-admission routes, and four runtime-replan delta routes. The
public targets explicitly describe this split evidence surface; they do not
invent theorem equivalence between consumer results and route families. All
four retired declarations merely returned assumed summary-valid conjunctions
and had no Lean dependency or theorem consumer. Twenty-one Failure Modes, nine
Intent-to-Execution, and twenty-seven Planning declarations remain; four
PlanForge declarations bring the planning chapter's seven-target total to
thirty-one. The transactions prove no detector quality, semantic handoff
correctness, planner quality, scheduler optimality, deployed behavior, support
transition, or release authority.

The twelfth narrow-projection tranche retires eight unconsumed direct
projections across `LivingBook.lean`, `PlanForge.lean`,
`ProofEnvelope.lean`, `PrototypeRoadmap.lean`, and `SecurityKernel.lean`.
Two otherwise unused projection-only record models are removed with their
theorems. The eight public targets now bind to retained negative cases, explicit
finite route families, or independent repository validators. In particular,
the PlanForge target is narrowed from general DAG acyclicity to strict ordering
of listed edges and exclusion of self-edges; the proof-envelope targets separate
filesystem/registry inspection from finite Lean rejection; and the security,
prototype, and living-book targets name modeled denial or malformed-record
branches rather than positive field projections. Nineteen Living Book, three
PlanForge, five Proof Envelope, nine Prototype Roadmap, and twenty-one Security
Kernel declarations remain. These migrations prove no manuscript quality,
filesystem truth inside Lean, general graph acyclicity, phase completion, gate
adequacy, runtime secret mediation, security efficacy, support transition, or
release authority.

The thirteenth narrow-projection tranche retires the final six premise or
field restatements across `PolicyOptimization.lean`,
`ProofCarryingContracts.lean`, and `TheseusReference.lean`. The two policy
targets already belong to the reachable `PolicyOptimizationRefinement`
lifecycle, so deleting their older assumed-implication projections changes no
public meaning. The Circle receipt target now names the retained missing-field
rejection, while the public-consumer fixture keeps its exact fixture theorem
and two derived rejecting controls without the no-promotion field-extraction
theorem. The Theseus artifact-surface target now names the retained
missing-surface rejection, and its promotion target remains carried by the
retained accepted-promotion contradiction. Fourteen Policy Optimization, eight
Proof Carrying Contracts, and fifty-two Theseus Reference declarations remain.
The apparent seventh retirement candidate,
`default_transition_requires_full_readiness`, is instead reclassified as a
reusable lemma because five concrete default-rejection theorems consume its
shared conclusion; duplicating that derivation five times would reduce clarity
without strengthening the model. This tranche changes no policy quality,
proof-contract transport, artifact truth, gate adequacy, capability,
self-evolution, support state, or release authority.

The fourteenth scope-and-refinement tranche resolves both pending
scope-language actions and the three legacy Policy Optimization fixture
theorems. `successful_support_promotion_was_ready` is renamed
`accepted_promote_support_step_requires_model_promotion_ready`, preserving the
normalized proposition while making clear that the result concerns the
authored `step` function rather than real evidence readiness.
`unproven_qualified_substrate_rejected` is renamed
`unproven_qualified_record_contradicts_noncore_invariant`; the chapter now says
explicitly that the contradiction rejects an inconsistent authored record, not
the substrate. The semantic classifier pins both results at P1 because neither
constructs an independent reachable witness.

The legacy policy-lease fixture remains a transparent alignment record, but
its three theorems no longer count fixture literals as proof of fixture
validity, reward-only rejection, or rollback preservation. The deterministic
lease consumer still computes the three rejected controls and executes the
synthetic baseline-restoration dry run. The public proof target remains owned
by `PolicyOptimizationRefinement`, whose two composition theorems and
independent consumer cover seven reachable stages, all 63 routes, 73 route
mutations, and three cross-stage mutations. This rebinding removes one
hand-authored conjunction theorem, one Boolean projection, and one
misclassified P5 rollback projection without weakening the recorded synthetic
result or pretending that the dry run proves live effect-complete rollback.
Eleven Policy Optimization declarations remain in the legacy module. No
policy improvement, reward validity, rollback efficacy, substrate result,
support transition, or release authority follows.

The fifteenth route-economy consolidation tranche removes twenty-two weak
declarations from `Efficiency.lean`: nineteen theorem-per-field
normalizations over one complete admission checklist and three theorems over a
hand-entered probe summary. None had a Lean dependency or theorem consumer.
The two deductively meaningful efficiency invariants remain: a cheaper
authorized quality-preserving member contradicts finite minimum-route status,
and promotion with open obligations but no residual record contradicts the
residual-promotion predicate.

The broader admission idea is not discarded. It is reorganized under the
reachable `ResourceEconomicsRefinement` request-to-closure lifecycle, which
models identity custody, budgeting, protected capacity, scheduling, actual
spend, useful-outcome/resource-bill separation, verification, residuals,
recovery, transfer, reconciliation, closure, and rejection of support or
external-effect authority. Its independent consumer covers all 66 routes and
57 rejecting mutations. The separate efficiency route-search consumer still
computes two passing traces and six expected-invalid controls over fourteen
candidates from eligibility and cost arithmetic. The two affected public
targets now describe this division of labor rather than treating copied
Boolean fields as formal evidence. This consolidation establishes neither
complete search nor accurate costs, measured efficiency, model quality,
compression utility, deployment, transfer, or support promotion.

The sixteenth evidence-transition consolidation tranche removes sixteen weak
fixture-normalization theorems from `EvidenceStates.lean` while preserving its
six narrow deductive facts about required evidence, self-promotion, terminal
states, and terminal effects. The retired declarations normalized one edited
field of a hand-authored complete review or projected one literal summary; none
had a theorem dependency or exercised consumer.

The replacement `EvidenceTransitionRefinement` is a reachable six-stage
lifecycle. It freezes the exact claim atom plus reader proposition, normative
obligation, and machine-predicate projections; binds target-specific evidence
without reducing heterogeneous support categories to a scalar ladder; carries
negative evidence, downgrade triggers, supersession, independent review,
dissent, limitations, residuals, changelog identity, ledger handoff, and
acknowledgment; and rejects replay, identity substitution, direct support
assignment, inherited parent or descendant movement, and external effects. An
independent consumer reaches all 35 declared routes with natural positive and
mutation cases. Seven former public targets are consolidated into three:
the two implemented lifecycle boundaries and the retained foundational
missing-evidence blocker. Four repository-specific audit mirrors are removed
from the formal queue because their executable consumers already preserve the
honest scope; copied formal summaries would add ceremony, not evidence.

This receipt completes both the C6 **classification** and dependency-safe
execution gates. All 160 approved actions are terminal: 157 theorem
retirements, two proposition-preserving scope rewrites, and one quantified
inverse-route replacement. The apparent 161st baseline candidate was the
separately recorded false-duplicate disposition that semantic review correctly
overturned and retained. Zero stronger-model actions remain. New proof work is
reserved for conclusions consumed by a reachable implementation or the natural
flagship.

The 2026-07-26 terminal residual triage in
`proofs/c6_remaining_stronger_model_audit.json` now removes ambiguity from
those 54 actions. All 54 have zero Lean dependencies and zero theorem
consumers. Fifty-three are hand-authored fixture or summary mirrors and are
assigned physical retirement without a replacement theorem; their independent
executable validators, immutable results, and any retained reachable route or
rejection families remain separate evidence surfaces. The sole rewrite is
`complete_failure_record_closes_record`: replace its authored all-green
witness with one input-general inverse property showing that a
`closeFailureRecord` route implies satisfaction of every earlier required
field and non-claim boundary. Execution proceeds in four tranches: the
unambiguously redundant Living Book and Circle witnesses; 43 Theseus
repository-import mirrors and nine associated formal mirror targets; the
Benchmark/Runtime/Search/Stable-Capability summary mirrors; then the single
Failure Modes inverse rewrite. This audit creates no theorem retirement,
formal result, empirical evidence, support movement, or release effect by
itself.

All four residual execution tranches are terminal. The Living Book's
authored blocked-reader constant and reflexive theorem were retired because
the retained input-general accessibility route strictly subsumes that witness,
with nine adjacent route theorems and the independent reader-release consumer
preserving the wider boundary. Circle's authored all-green public-consumer
fixture theorem was retired while its two quantified overclaim/missing-control
rejections and independent replay consumer remain. The Circle target now states
that split evidence surface instead of claiming the copied fixture summary as
formal evidence. Historical deterministic results remain unchanged. The
second tranche physically retired 43 copied Project Theseus repository-import
summary theorems and nine formal mirror targets. Their independent validators
and immutable results remain authoritative executable evidence, while the
Theseus module retains its eleven reusable policy and report-bundle theorems.
The third tranche retired eight hand-copied Benchmark, Runtime Adapter, Search
Substrate, and Stable Capability Field summary mirrors while preserving their
independent executable validators and distinct quantified route families. The
fourth replaced the authored all-green Failure Modes witness with the quantified
`failure_route_close_implies_complete_required_record` inverse: a close result
requires every earlier required field and excludes every earlier route guard.
The live estate is therefore 1,219 theorems, with 157 retirements, two exact
scope rewrites, one stronger inverse-route replacement, and zero C6 actions
remaining.

An initial semantic spot-check rejected a naive retirement rule before any
proof deletion: 33 declarations shared literal theorem text across different
namespaces, but quantified over different module-local state machines. They are
analogous obligations, not interchangeable propositions, and remain retained.
The classifier now treats eight cross-module literal-pattern groups as
diagnostics only. Duplicate retirement requires same-model statement identity
or a current semantic confirmation of an older equivalence review; the only
same-model redundant declaration meeting that bar is the one now retired. A
second spot-check also
overturned one frozen semantic-duplicate disposition because the two related
Search Substrates theorems negate different predicates. Both remain owned, and
the former misleading theorem name now states the qualified-record
contradiction precisely.

### Continuation order

This amendment does not displace P2 or create a third work-in-progress lane.
After manifest, outline, appendix, claim, reader, validation, render, and public
truth synchronization, execution returns to the existing queue:

1. P2 storage-feasible materialization and four-slot competence qualification;
2. the current 84-chapter atom, inheritance, maturity, and reader-freshness
   reconciliation, superseding stale 66/80-chapter wording;
3. T0A–T4 Theseus flagship prerequisites and the effect-complete P5 reference;
4. claim-specific evidence programs for the four new chapters only when they
   pass the same competence, safety, rights, independent-evaluator,
   denominator, reproduction, and transfer gates as every other chapter.

Future coverage audits remain allowed because a living book cannot make a
permanent completeness claim. New work must still prefer an existing owner,
admit a chapter only for a distinct interface and failure lifecycle, integrate
meaning immediately, and leave evidence maturity open rather than keeping
manuscript ideas in a planning queue.

## Operating rules

1. **No false-negative laundering.** A failed implementation is evidence about
   that implementation's readiness, not automatically about its intended idea.
2. **A fair chance to succeed comes before a right to refute.** Claim-bearing
   work freezes mechanism activation, matched engineering and tuning budgets,
   favorable/oracle checks, positive controls, sensitivity, and a fair rescue
   ladder before final held-out opening.
3. **No metric theater.** Counts of claims, transitions, theorems, validators,
   sources, formats, or releases never substitute for semantic or empirical
   evidence.
4. **No support laundering.** Formal, executable, empirical, causal,
   reproduction, transfer, source-synthesis, and normative lanes remain
   separate.
5. **Historical evidence is immutable but interpretation is revisable.** Failed
   attempts, raw outcomes, instrument defects, inaccessible comparators, and
   platform limitations remain visible with exact lineage.
6. **No outcome-aware rescue.** Infrastructure setup may receive only the
   prospectively frozen bounded retries in the P2 amendment while protected
   task content remains unopened. The no-rerun rule becomes absolute at the
   first protected-content exposure. Rescue and tuning otherwise use
   development or sacrificial data; final held-out data is opened once only
   after every competence gate passes.
7. **No conversational dependency.** Routine work is local or reproducibly
   tooled. Hosted-chat interaction is never a completion gate.
8. **No external-human prepublication gate.** The roadmap does not require
   private reviewers. Independence needed for a scientific result must come
   from separately implemented evaluators, implementations, or reproductions;
   it does not require another person to read the unfinished book.
9. **Main-only repository continuity.** Work stays on `main`; no branch or pull
   request is required. Commit, push, tag, deploy, archive/DOI deposit, license
   change, and public posting remain owner-gated external mutations.
10. **One active successor.** Closure requires a new successor or an explicit
    continuing-maintenance authority in the same transaction.

## P0 — Public truth, claim identity, and attestation continuity

Build one canonical claim-identity graph covering the 3,730 activation atoms,
15-atom addendum, 55 chapter cores, campaign-local claims, transition IDs,
proof targets, experiment estimands, Appendix C rows, chapter evidence packets,
and synopsis claims. Each accepted transition must have exactly one primary
identity relation:

- `atom`: exact canonical atom identity;
- `subclaim_of`: a narrower proposition whose truth does not move the parent;
- `alias_of`: the same proposition under a retired or local name; or
- `proxy_for`: an instrument-specific measurement relation with an explicit
  construct-validity ceiling.

Every non-exact relation must state population, environment, model,
intervention, outcome, authority, time, artifact, maximum inference, and why it
does not promote its parent. The graph validator must reject unmapped accepted
transitions, cycles, multiple primary owners, dangling aliases, unsupported
parent promotion, scope widening, proxy-to-target laundering, and different
claims that merely share a name.

Keep the landing page, README, citation guidance, release records, roadmap
pointers, reader manifests, and X synopsis consistent with actual public and
local state. The public-truth validator must reject stale release identity,
obsolete active-roadmap claims, missing supersession records, and derivatives
whose bound chapter, claim, result, source, release, URL, header, or platform
inputs have changed.

The first custody checkpoint is complete at pushed `main` commit `882b2a82c`.
Every later campaign or roadmap disposition still requires its own exact
commit-bound reconciliation receipt containing source commit, tree digest,
changed-file inventory, generated-artifact boundaries, validation results,
release effect, and public-state effect. A current clean attestation cannot be
claimed until the described work is committed, pushed when authorized, and
bound to the resulting immutable commit.

### P0 claim-identity implementation receipt

The identity tranche is complete. `evidence_quality/claim_identity_graph.json`
resolves all 115 accepted transitions: 25 exact atom identities, 61 bounded
subclaims, and 29 proxies. Every indirect edge preserves population,
environment, model, intervention, outcome, authority, time, artifact,
maximum-inference, and parent-nonpromotion boundaries; none moves its parent
support state. `docs/claim_identity_graph_reconciliation.md` exposes the full
crosswalk, and `scripts/validate_claim_identity_graph.py` rejects twelve
identity, scope, artifact, and support-laundering mutations.

The first P0 custody checkpoint is complete at pushed `main` commit
`882b2a82c`. P0 remains continuous: the Round 15 remediation itself requires a
new clean commit-bound attestation, and the custody gate prevents dirty evidence
from being counted or released.

## P1 — Negative-result rehabilitation and false-negative defense

Apply `docs/claim_bearing_experiment_competence_standard.md` retrospectively to
all 87 accepted no-change and three accepted refuted transitions, plus every
historical `narrowed`, `blocked_after_full_attempt`, or prose-level negative
claim used by a chapter. Assign exactly one N0–N5 level:

- N0 instrument failure: no claim inference;
- N1 implementation failure: the idea remains untested;
- N2 proxy or regime failure: retain the proxy result, not target refutation;
- N3 competent exact implementation-setting result;
- N4 mechanism-level counterevidence from multiple competent implementations;
- N5 broad refutation after natural diverse corpora, two transfer settings,
  adequate sensitivity, independent reproduction, and no surviving frozen
  rescue.

The retrospective audit must reconstruct, rather than assume, mechanism
activation, component competence, task validity, positive controls, baselines,
tuning parity, evaluator sensitivity, power, rescue history, held-out custody,
and scope. Missing evidence lowers the N-level. It never gets filled with a
plausible narrative after the fact.

The ladder is direction-symmetric: an instrument, implementation, proxy, or
corpus inadequate to ground a refutation is equally inadequate to ground
support. Positive transitions face the identical competence audit at admission
time, so rehabilitation can only bound inference — it can never convert a
bounded negative into implicit support for the idea the test failed to reach.

For KERC, preserve the original transition and raw failure. Audit whether the
0.5 task score and known training/implementation defects make it N1 or N2. If a
serious learned compiler and native cores warrant a new test, create a new
claim identity, natural corpus, stronger baselines, independent evaluator, and
prospective protocol. Never reopen the old held-out denominator or overwrite
the historical record.

Chapter prose, Appendix C, the non-core ledger, evidence packets, synopsis, and
public status must use the rehabilitated bounded language. Until audit, a
historical negative result may report what happened but cannot support a broad
architecture or mechanism conclusion.

### P1 accepted-transition rehabilitation receipt

The first retrospective tranche is complete. All 90 accepted transitions with
historical `no_change` or `refuted` effects are digest-bound in
`evidence_quality/negative_result_rehabilitation.json` and assigned exactly one
maximum-negative-inference level: one N0 instrument failure, fifteen N1
implementation failures, seventy-four N2 proxy/regime failures, and zero N3,
N4, or N5 results. The three raw `refuted` labels remain immutable historical
observations; under the competence standard they do not establish an exact,
mechanism-level, architectural, parent-atom, or chapter-core refutation. KERC
is N1, and the two QCSA-labeled refutations are N2. The validator rejects twelve
history rewriting, competence invention, held-out reopening, scope widening,
and support-laundering mutations.

P1 is complete. The original 75-surface rehabilitation snapshot, including
the 55 chapters live when that audit ran, remains digest-bound to commit
`295642f21a39e2d735553b3a51ef6ba2f5e76d2c` in the maintenance status record.
The maintained `evidence_quality/negative_inference_surface_audit.json` now
recomputes the live projection: 80 surfaces including all 60 current chapters,
zero forbidden overbroad phrases, zero missing named rehabilitation boundaries,
and zero chapters that use `blocked_after_full_attempt` without also stating
that the gaps are residual proof obligations rather than false claims. The X
synopsis source is refreshed; its older unpublished platform draft is honestly
marked stale and cannot be published without update and revalidation. Historical
transition files, completed roadmaps, frozen reader editions, and raw experiment
outputs remain immutable historical scope rather than being rewritten.

## P2 — Competence-qualified natural empirical frontier

Select the highest-value live claim for which a natural, non-authored corpus,
competent implementation, strong comparators, and an honest measurement are
available. Do not select the easiest atom merely to move a support-state count.
Write the canonical identity and causal/mechanistic prediction first, then
freeze the complete competence dossier required by the experiment contract.

The campaign must include:

- at least one strong current model or system suitable for the task, plus a
  matched comparator and mechanism ablations;
- component tests and traces proving the proposed mechanism activated;
- matched engineering, optimization, data, tool, and compute opportunity;
- an oracle or deliberately favorable upper bound where possible;
- natural non-authored data with provenance, contamination, licensing,
  sampling, preprocessing, and exclusion records;
- natural task difficulty spanning neither floor nor ceiling, along with
  positive, negative, trivial, and adversarial controls;
- an independently implemented evaluator calibrated through blinded known-
  effect injection and explicit false-accept/false-reject accounting;
- preregistered minimum effect, sensitivity/power, uncertainty, multiplicity,
  missing-data, stop, cost, and claim-ceiling rules;
- the frozen fair rescue ladder on development data; and
- a final held-out denominator opened exactly once after every gate passes.

Measure usefulness, unsafe release, latency, compute, total lifecycle cost,
governance cost, failure modes, abstention, and residual debt together. Success
may support only the canonical bounded claim. Failure may move a claim only to
the N-level actually earned. An underpowered, chance-level, non-activated, or
positive-control-failing run terminates as an instrument or implementation
result and triggers no negative inference.

### P2 frontier-selection receipt

Selection is complete and the final denominator remains closed. Five candidates
were compared prospectively under weighted scientific value, canonical
relevance, natural-data access, implementation competence, evaluator
independence, sensitivity, and local-resource feasibility. The selected claim
is `p2.governed_natural_repository_change_admission_joint_frontier`, a bounded
`subclaim_of` `integrated-reference-architecture.invariant.015`. It asks whether
full governed admission improves the joint useful-safe-release and false-
blocking frontier on natural non-authored repository changes relative to
matched test-only and record-only baselines while preserving latency, compute,
evaluator work, rollback failure, and residual cost.

The exact selection and custody plan is
`evidence_quality/p2_frontier_selection.json`. Seven competence gates remain
pending: implementation, construct, comparators, evaluator, sensitivity,
development-only rescue, and resources. The held-out gate remains closed. KERC,
QCSA, routing/deliberation, and unlearning were not discarded; each is deferred
because its current implementation or evaluator state would repeat an N1/N2
attempt rather than give the claim a fair prospect of success.

### P2 natural development-corpus receipt

SWE-rebench V2 revision
`475dd5e8703bb5fb22dd3c60b5d038b019eba1e0` is now the pinned natural-task
candidate. A metadata-only post-snapshot screen found 1,117 tasks across 532
repositories and 20 languages. Twelve development-only tasks span twelve public
merged pull requests, twelve repositories, and seven languages; all have
permissive licenses, clean dataset diagnostic flags, separate solution/test
paths, public source receipts, and resolvable `linux/amd64` image manifests.

This advances corpus acquisition, not construct competence. The task release
uses automated setup and LLM annotations, its paper's diagnostic study covers
only 300 tasks in five languages, and its issue tracker documents missing or
mismatched images. All twelve development tasks must reproduce their human-gold
test transition, pass independent specification review and a test-path
collision guard, and fit measured pull/run/emulation/cleanup ceilings before
construct or resource gates can pass. The final pool remains unselected and
closed. Exact receipts are in
`evidence_quality/p2_development_corpus_preflight.json` and
`docs/p2_development_corpus_preflight.md`.

### P2 gold-oracle and dependency-isolation rehabilitation

Natural-task provenance is not enough if the official harness can manufacture
false negatives. Before corpus qualification, execute every development task in
paired test-patch-only and human-gold-plus-test-patch arms with at least two
repetitions. Preserve raw logs even for aborted attempts. Separate dependency
materialization from evaluation: obtain dependencies only in a recorded setup
phase, bind their resolved content into a sealed environment, and run both arms
offline from that same environment. Unrestricted setup egress is diagnostic
only; a claim-bearing run requires a hermetic snapshot or a prospectively
allowlisted, content-digest-verified dependency path with supply-chain and
failure receipts.

Score every consequential task with both the pinned upstream parser and a
materially independent parser/oracle. Calibrate the independent path on
passing, named failing, compile-failing, malformed, missing, and parser-
disagreement logs. A zero exit code cannot erase visibly reported failures, and
a compile-stage failure cannot be treated as hundreds of observed named test
failures. Exact expected-set drift, omitted new tests, setup failure, parser
silence, architecture/emulation divergence, and nonzero parser disagreement
all close the construct gate until diagnosed.

Freeze the task exclusion and replacement policy before drawing any replacement
or final task. A development task whose human-gold transition cannot be scored
without changing the oracle becomes an immutable N0 construct/evaluator
pathology; it is not retroactively rescued by weakening acceptance. Apply the
same exclusion rule to the eligible universe, draw a replacement without
outcome cherry-picking, retain the original denominator and failure lineage,
and rerun the complete qualification. The final pool may be selected and
digest-sealed only after this procedure, and its labels/outcomes may be opened
once only through a blinded evaluator after every implementation, comparator,
evaluator, sensitivity, rescue, and resource gate passes.

The first full fixed-denominator execution and bounded rescue are now
terminally diagnosed. Seven tasks passed the pinned exact oracle. An
independent parser recovered one definite AVA false rejection, producing eight
qualified development tasks across five languages. Four tasks remain N0 and
require same-language replacements: one Rust task has unobservable compile-
failure labels and an extra human-gold test; one Go task combines a target panic
with an unrelated runtime schema fetch; a second Go task depends on filesystem
rename semantics absent from the local container path; and the Java task
reveals an open-ended dynamic Maven provider chain. None has claim effect.

Eight original attempt records and 62 compressed arm logs remain in the
lineage, including the raw-log-custody abort that caused subsequent attempt
versioning. The initial image-size field was later found to be Docker Engine
content-store bytes rather than expanded size. A four-image calibration now
separates the exact Engine-content measurement from a conservative upper bound
derived from Docker's rounded virtual-size display. The prospectively repaired
ceiling is 300 seconds for pull and dependency setup, 1.5 GB Engine content,
7 GB conservative virtual size, 600-second accepted arms, 6 GiB peak memory,
six CPUs, 1,024 PIDs, 50 GiB minimum free space, stable zero-Docker cleanup,
and bounded task/campaign residuals.

The deterministic replacement ladder is active and every terminal failure is
retained as N0 without denominator reduction or claim effect. Rank-one task
specifications for all four slots are digest-bound; the independent Cargo/Go/
Maven evaluator agrees on all 32 calibration cases. In the Rust slot, rank 1
reproduced two checksum-identical Cargo snapshots but its own `make test`
attempts a networked `rustup` prerequisite before emitting tests; rank 2
exceeded the frozen Engine-content ceiling; rank 3 lacked the required verified
commit signature; rank 4 reproduced 331 registry archives and 57 exact-commit
Git-source files twice, but a resource-monitor timeout during its first
baseline arm invalidated the attempt; and rank 5 exceeded the frozen pull-time
ceiling before image measurement. The monitor now records sampling errors and
fails them closed, partial-layer cleanup is explicit, and rank 4 is not rerun
after partial outcome exposure. The pre-amendment ledger named rank 6 as next;
the prospective infrastructure/content amendment supersedes that authorization,
reinstates rank 5 as setup-retry-pending, and keeps rank 6 closed until the
pool-wide materialization gate passes. Candidate outcomes remain closed for the
other three slots; the final pool is still unselected and unopened. This remains
the frozen deterministic sequential replacement rule; no later diagnosis may
reorder candidates or weaken a gate.

### P2 storage-feasible materialization protocol

The materialization gate must be satisfiable on the actual host. Simultaneous
residency is not required; pool-wide readiness is defined as
**sequential-verified**: every candidate must have been pulled,
dependency-materialized, digest-sealed, measured against the frozen ceilings,
and torn down at least once, leaving a deterministic re-materialization recipe
and a measured storage high-water receipt. Each preflight records exact host
free bytes, Docker-reclaimable bytes, candidate high-water bytes, and
post-cleanup free bytes rather than relying on a transient prose estimate.
Docker-scoped reclamation (image,
container, volume, and build-cache pruning with before/after receipts) is a
legal setup action while protected content remains unopened; reclamation never
touches non-Docker user data. The frozen 50 GiB minimum-free floor binds every
phase.

Before protected content opens, an exact image may receive at most three fully
logged setup retries. Exhausting those retries blocks that same rank; it does
not burn, skip, or advance the candidate. Once any task content, hidden test,
label, model output, evaluator judgment, or outcome-bearing signal opens, the
attempt is never replayed and an infrastructure failure cannot authorize the
next rank. It remains a fail-closed N0 outcome at the exact attempted scope.
Rank 5 setup retries and any later rank opening proceed only after all 30
candidates hold sealed recipes and receipts. This separates infrastructure
feasibility from outcome selection while preserving the deterministic ladder.

The resource and construct gates remain pending four qualified replacements
and remeasurement of the complete twelve-task denominator. Do not reduce the
denominator from twelve to eight. Exact receipts begin with
`evidence_quality/p2_gold_preflight_diagnosis.json` and
`evidence_quality/p2_task_qualification_and_replacement_policy.json`; the
resource contract is `evidence_quality/p2_resource_ceiling.json`, and the
sequential rank diagnoses are under `evidence_quality/p2_slot1_rank*`.

## P3 — Independent reproduction, transfer, and SOTA challenge

Reattempt the seven historically blocked P6 atoms only when the candidate,
exact strong comparator, required hardware, dataset rights, and executable
protocol are simultaneously available. A weaker proxy may be useful for
instrument work but cannot silently become a SOTA comparison.

Any claim seeking reproduction support needs a materially separate
implementation or operator path and an independently implemented evaluator.
Any claim seeking broad or mechanism-level support needs at least two
materially different transfer settings selected before outcomes: for example a
different corpus/domain and a different model family, architecture, scale, or
deployment topology. Report per-setting results and failure envelopes rather
than only aggregates.

Freeze model/checkpoint identity, source code, environment, hardware, seeds,
training and tuning budget, evaluator access, cost accounting, defeat criteria,
and downgrade triggers. SOTA/Pareto language additionally requires a dated
frontier search, exact comparator receipts, matched resources, uncertainty, and
survival under the joint usefulness/safety/latency/cost/governance frontier.
Inaccessible or irreproducible comparators remain exact blockers, not losses or
wins.

## P4 — Semantically meaningful formal evidence

Audit the current 306 proof targets and 102 Lean modules for semantic adequacy, not proof
shape alone. The 917 `derived/decomposed` classifications are syntax-level
signals; `native_decide`, case splits, arithmetic, or induction do not by
themselves establish that the model captures the book's claim.

Prioritize `DataEngineLifecycleRefinement`,
`OpenEndedImprovementRefinement`, `PolicyOptimizationRefinement`, and
`ResourceEconomicsRefinement`, then every module named by a consequential
safety, evidence, rollback, or self-improvement claim. For each retained
theorem cluster require:

- a plain-language proposition and exact canonical claim consumer;
- explicit modeled state, environment, authority, assumptions, and omitted
  semantics;
- at least one nontrivial countermodel or mutation that the final theorem
  rejects;
- composition, induction, arithmetic, refinement, reachability, or
  noninterference content that is not merely a copied predicate projection;
- an executable/runtime consumer when the theorem purports to constrain
  implementation; and
- chapter prose that states the maximum semantic inference.

Delete, merge, or reclassify stubs that add no semantic leverage. Do not set a
theorem-count quota. A smaller proof surface with meaningful models and real
consumers is better than a large decidable mirror of authored records. Formal
success remains formal evidence; it cannot establish empirical competence,
evaluator truth, deployed enforcement, safety, or transfer.

To keep this audit finite, the machine status freezes six named clusters:
evidence/claim/proof custody; safety assurance and
oversight; authority/effect/rollback/corrigibility; learning-update state and
unlearning; self-improvement and readiness; and resource/artifact/lifecycle
economics. Their exact 24-module membership is machine-validated. All six
clusters are terminal at bounded finite scope: evidence/claim/proof
custody contains two module reclassifications, safety/assurance/oversight
retains four adequate modules, authority/effect/rollback/corrigibility retains
three adequate modules while reclassifying `Corrigibility` as countermodel-only,
and both learning/update/unlearning and self-improvement/readiness retain four
adequate modules with explicit claim-axis and maximum-inference ceilings. The
resource/artifact/lifecycle-economics cluster retains four adequate modules
while separating cost from efficiency, artifact receipts from reality and
durability, stewardship from ownership, compression from usefulness, and
record closure from lifecycle success. M4 is complete. No unlisted cluster may
be added later
without a dated machine-validated amendment, and no listed module or cluster
may disappear without a terminal disposition.

### 2026-08-02 chapter-local Lean successor amendment

Corben explicitly opened a chapter-wide Lean-local proof program after the
six-cluster P4 audit closed. This does not reopen or rewrite the terminal audit;
it creates a successor lane for exact chapter claims that still have a named
semantic defect. Each tranche must identify the weak claim-to-model link, build
a reachable and nonvacuous transition, refinement, composition, accounting,
noninterference, bounded-liveness, or impossibility result, bind an independent
consumer and rejecting countermodels or mutations, and state a maximum
inference. The program has no theorem-count quota. Runtime truth, empirical
competence, cross-component behavior, deployment, and whole-system properties
remain Project Theseus work.

The Integrated Reference Architecture tranche is complete at authored
finite-record scope. `AsiStackProofs.IntegratedReferenceTrace` now has 45
theorems over connected cross-layer and concurrent-effect models. Arbitrary
runs preserve parent/state custody, authority and logical-time invariants,
effect accounting, residual conservation, valid traces, exact batch
composition, terminal absorption, effect causality, and exclusive disposition;
one authored one-effect projection joins the models. Independent consumers
check all 13 cross-layer and 21 concurrent prefixes/composition splits and
reject 108/108 and 62/62 mutations. Maximum inference: the three public targets
are adequate only as finite authored-record invariants. Semantic payload truth,
complete effect discovery, evaluator competence, distributed clocks and
partitions, deployed enforcement, whole-stack execution, safety, reproduction,
transfer, support movement, and ASI remain unproved and route to Theseus or an
empirical program.

The Failure Modes tranche is complete at authored finite-record scope.
`AsiStackProofs.FailureRecoveryRefinement` now has 27 theorems over a checked
five-stage recovery cycle. Accepted events require a valid control state;
detection requires explicit failure-class and affected-boundary custody, opens
one residual, and disables effects and promotion; readmission requires current
assurance, current taxonomy, residual discharge, and authority before it closes
the residual and restores operation. Arbitrary successful runs preserve exact
identity, non-authority, receipts, monotone incident/recovery/recurrence counts,
valid traces, and batch composition. The independent consumer checks all six
lifecycle splits and rejects 117/117 mutations. Maximum inference: the bounded
recovery target is stronger, but the five-target chapter remains `useful but
too narrow` and at `argument`; detector truth, containment and remediation
effectiveness, deployed recovery, recurrence and escape measurement, safety,
reproduction, transfer, and whole-system recovery remain Theseus or empirical
obligations.

## P5 — Effect-complete governed reference system

Evolve the integrated local slice into a real multi-process reference system
with durable identity, scoped credentials, revocation, concurrent ledgers,
observed external and internal effects, exact rollback where possible,
compensation and quarantine where not, and descendant-aware deletion. Track
model, optimizer, scheduler, RNG, cache, backup, derived artifacts, and
descendant state. Choose checkpoint authority prospectively.

Bind P4 models to executable state with checked refinements rather than copied
summaries. Qualification requires adversarial boundary tests, crash recovery,
replay, concurrency, stale-cache and revocation tests, supply-chain provenance,
model-weight custody, incident records, effect injection, and an honest
residual register. Distinguish behavioral cohort removal from influence,
privacy, and storage erasure. A deployed claim is forbidden until the deployed
system and its exact commit-bound attestation exist.

Use the P2 competence standard for any performance or safety conclusion drawn
from the reference system. Schema conformance and clean traces are necessary
mechanism evidence, not proof of usefulness or real-world governance efficacy.

### P5 local multi-process vertical-slice checkpoint — 2026-07-27

The first bounded P5 runtime slice is terminal at its exact local scope.
`scripts/run_p5_effect_complete_reference.py` executes eight frozen cases
through real subprocesses, a durable SQLite/WAL ledger, and contained
filesystem effects. It records one concurrent idempotency race, two rejected
authority attempts, four independently observed effects, two exact local
rollbacks including one crash-orphan recovery, one compensated irreversible
history, a prospectively selected nine-class full-state checkpoint and
byte-exact restore, and a five-surface descendant-aware local deletion.
`scripts/validate_p5_effect_complete_reference.py` reruns the system in a new
temporary directory and requires exact result equality.

This moves P5 and M5 from `pending` to `in_progress`; it does not complete
either. The next competent slice must bind the lifecycle to a frozen service
with actual model and learning state, restart and partition faults,
independently observed external effects, supply-chain and model-weight custody,
and commit-bound deployment attestation. The local result establishes no
natural-task usefulness, production safety, complete effect discovery,
distributed or Byzantine correctness, causal unlearning, privacy repair,
external erasure, support transition, or release authority.

### P5 stateful-service vertical-slice checkpoint — 2026-07-27

The second bounded P5 slice is terminal at its exact local service scope.
`scripts/run_p5_stateful_service_reference.py` binds the frozen case design,
runner, and result schema to source commit
`88d9cc8979460636587fddbf826d62455907c42c` on `main`, then executes seven
cases through separately launched trainer, recovery, inference, external
effect, and observer processes.

The service replaces deterministic model placeholders with a two-parameter
predictor and bias-corrected Adam. Twenty-four optimizer steps improve the
authored positive-control objective from mean squared error `6.935` to
`1.18797138562` while mutating all nine declared state classes. Copying back
weights alone leaves eight classes mismatched and is rejected. After the
trainer exits with code `17` between mutation and acknowledgement, a new
process restores model, optimizer, scheduler, RNG, cache, backup,
derived-artifact, descendant, and credential state byte-exactly and reproduces
the prior prediction.

A separate localhost HTTP effect service owns a separate SQLite ledger. One
unavailable-service attempt remains in an owned outbox; retry after recovery
creates one effect; a duplicate retry creates no second effect; a stale token
creates none; and a separately executed observer reads the accepted payload.
One-byte model-weight and dependency-lock mutations each fail custody before
effect release. `scripts/validate_p5_stateful_service_reference.py` reruns the
seven cases in a new workspace and requires exact result equality.

This advances P5/M5 but does not complete them. The task is authored rather
than natural, the predictor is not a strong model, the partition is
localhost-only, the observer is repository-authored, and the source receipt is
explicitly local identity custody rather than deployment attestation. The next
slice must use a frozen natural stateful service with strong rollout controls,
a separately owned evaluator and monitor, delayed outcomes, multiple external
dependencies, replica/partition recovery, externally rooted model custody, and
joint usefulness, unsafe-release, false-blocking, latency, recovery, operator,
compute, and residual metrics. No support transition or release authority
follows.

### P5-U1 governed repository-change checkpoint — 2026-08-13

The executable core of the P5-U1 utility packet is terminal at its exact
retrospective local scope. The public EM4 browser audit exposed a naturally
arising defect: Human Reader **View source** links escaped the independent
reader manuscript tree. `scripts/run_p5_u1_governed_repository_change.py`
recovers the two pre-fix files from commit
`1f6c8352c0e8ebcd6e9d7e70d33e9152d0f6fdcb`, creates twelve isolated real Git
workspaces and bare remote effect boundaries, and runs the same repair through
direct, record-only, and fully governed routes across happy,
blocked-authority, partial-effect crash/recovery, and non-undoable external
effect paths.

All twelve expected terminal states pass byte- or Git-state checks. The fully
governed route blocks the out-of-scope change before effect, restores and
replays the complete plan after the partial mutation, and compensates the
external branch state while retaining explicit effect and compensation
history. The direct and record-only controls preserve their expected
unauthorized or unresolved residuals. The fresh-workspace validator rejects
nine mutations covering route loss, identity, state-check, authority,
compensation, prospective-classification, operator-time, governance-rent, and
support-state laundering. The result also computes governance rent over the
four matched paths: against direct execution, full governance adds twelve
operator-step proxy units, fourteen receipt files, and 1,729 artifact bytes;
against record-only, it adds eight steps, four files, and 920 bytes. Both
comparisons retain one prevented unauthorized effect, two closed residuals,
one recovered interrupted change, and one closed compensation. Host timing is
diagnostic, and no human operator time is claimed.

The defect outcome was known before this replay and the local bare remote is
not a production service. Timing and CPU are host diagnostics; workflow steps
and artifact bytes are burden proxies, not observed human effort. This packet
is therefore not a prospective utility estimate, randomized or held-out
comparison, independent reproduction, deployment, safety, transfer, SOTA,
AGI, or ASI result. It moves no support or release state. The documented route
and validator also pass from a fresh clone of `main` at
`8bff377f482cd4014945be08957b8cadd82fd68a`, so P5-U1 is terminal at this
retrospective scope. The broader P5 natural campaign remains frozen and
unopened.

### P5 natural publication-service development checkpoint — 2026-07-27

The first natural operational happy path for P5 is now recorded at its exact
development scope. Ordinary maintained-book work—not a task authored to test
P5—produced source commit
`5575d3cbf5f9dd9edfec8548c4279728b0da3995` on `main`. GitHub Actions build
run `30287899588` executed the deep registry, Lean build, clean HTML render,
canonical-status checks, Human-view checks, and tested-artifact construction.
It uploaded a 28,389,505-byte artifact named with the complete source SHA and
digest
`sha256:84700830e2f110e1b4406dc1dbc3976b0b2cecc9020455040706d128c3741dc2`.

Separate workflow run `30288922224` downloaded that tested artifact, verified
the same source commit, deployed it without rebuilding, and then ran a
separate post-deploy job that crawled the public canonical status and chapter
graph. The deployment reached a successful external status 873 seconds after
the source commit; the post-deploy monitor completed after 893 seconds. This
is a real source-to-build-to-artifact-to-public-effect-to-observation chain
across hosted workflow, artifact-storage, and Pages-serving boundaries.

The checkpoint is deliberately **outcome-aware and retrospective**: its result
was known before the trace contract was frozen. It is therefore a development
observation, not a held-out case, claim-bearing campaign, safety result,
rollback result, causal comparison, independent reproduction, support
transition, or new release decision. The post-deploy monitor is a separate
process path but not separately owned or institutionally independent. No
fault, rollback, compensation, replica conflict, partition, delayed harm,
unsafe-release opportunity, false-blocking denominator, operator-time measure,
or hosted-compute measure was exercised.

The durable machine record is
`experiments/p5_natural_publication_service_trace/results/2026-07-27-development.json`;
the reader boundary is
`docs/p5_natural_publication_service_development_trace.md`. P5/M5 remain
`in_progress`. The next claim-bearing transaction must freeze its natural work
population, fault envelope, matched controls, evaluator, monitor, metrics, and
stopping rules before outcomes are visible, while preserving the exact
identity joins learned from this happy path.

### P5 prospective natural stateful-service campaign freeze — 2026-07-28

The next P5 campaign is now frozen before any eligible task content or
protected outcome has been opened. The existing campaign identity,
`governed-operations-natural-service-campaign-001`, is the sole authority; no
parallel P5 preregistration may silently change its denominator. The machine
contract is
`experiments/governed_operations_argument_exit/preregistration.json`, its
schema is
`schemas/governed_operations_campaign_preregistration.schema.json`, and the
reader decision is
`docs/p5_natural_stateful_service_campaign_preregistration.md`.

The natural unit is an independently necessary ASI Stack maintenance task
admitted after the freeze commit. Fifteen future tasks belong to development;
forty protected tasks—eight across each of five maintenance families—form the
final denominator. Tasks invented for the experiment, previously solved
tasks, tasks needing another human participant, and tasks whose acceptance
criteria appear after outcomes are ineligible. Consecutive eligible tasks are
content-addressed and assigned by a frozen seed. No final task may enter P2 Q1
or Q2, reuse a development task, or be removed after protected output exists.

Five matched arms prevent an easy or naive comparison: direct model tooling,
stop-only, competent generic SRE, proposal plus separately implemented
acceptance, and governed operations. Every arm receives the same task, fault,
local Qwen3-8B snapshot, prompt/tool/context budget, sandbox, and wall-clock
ceiling. Engineering effort is matched during development. Experimental
worktrees and dependency adapters cannot push, publish, deploy, message a
third party, or widen authority; any later public effect is a separate
owner-authorized transaction and is not a campaign outcome.

The frozen fault envelope has twelve classes, including crash-after-mutation,
intent/effect partition, replica conflict, custody drift, credential
revocation, stale memory, correlated dependency loss, monitor corruption,
incomplete rollback, irreversible effect, and operator-capacity failure.
Fourteen state classes cover model, optimizer, scheduler, RNG, prompt/policy,
cache, retrieval memory, ledgers, outbox, credentials, replicas, backups,
derived artifacts, and descendants. Checkpoint authority is the last
content-addressed, fully reconciled pre-fault checkpoint. Weights-only restore
is forbidden.

A masked, read-only evaluator and a separate delayed monitor are
implementation-separated from the mechanism, but explicitly not
institutionally independent. At least twenty-four known-answer calibration
cases, six positive controls, ten adversarial controls, seven fair-rescue
steps, mechanism activation traces, a favorable upper bound, and competent
alternative implementations must pass before protected opening. A failure of
these gates closes the instrument or implementation; it cannot be narrated as
a negative architecture result.

The co-primary outcomes are safe-useful completion, unsafe effect release,
false blocking, and qualified recovery. No scalar may hide a co-primary harm.
Timing, quality, residuals, evidence completeness, recurrence, operator work,
tokens, tool calls, CPU, memory, storage, network, service loss, and
development/rehearsal burden remain jointly visible. Recovery counts only
after full-state and external-effect reconciliation, fresh useful and safety
acceptance, qualified fallback, delayed monitoring, and emergency-authority
expiry.

This freeze advances design custody only. Natural tasks run, fault injections,
operators recruited, support movement, release authority, and empirical result
all remain zero or `none`. The campaign cannot substitute for the Theseus T4
joined trace or unlock T5. The next legal action is implementation and
development qualification of all arms, adapters, evaluator, monitor,
calibration suite, full-state recovery, and registered preflight. Development
task content stays closed until those surfaces pass; final content remains
closed until competence, precision, resource, and custody gates all pass.

### P5 natural stateful-service implementation qualification — 2026-07-28

The frozen campaign now has a deterministic authored-control implementation
receipt. It crossed five arms with twelve fault classes for **60 authored**
trials and used **213** isolated subprocess launches across workers, masked
evaluators, logical-time monitors, twenty-four calibration cases, and a
dependency-worker canary. A fresh run reproduces the tracked result exactly.
All fourteen declared state classes are exercised; every governed-arm authored
control restores all fourteen and retains residual ownership. All five arm
response profiles differ.

The evaluator passes 24/24 frozen known-answer cases with zero false accepts,
zero false rejects on the safe-success controls, and 2/2 missing-truth
abstentions. Five local dependency adapters qualify: the exact cached
Qwen3-8B runtime/snapshot receipt, a temporary local Git remote, a separate
validation worker, a digest-preserving no-rebuild artifact projection, and a
separate read-only monitor. The model canary proves runtime custody only, not
model competence.

All 14/14 development-opening implementation gates pass, but development
content remains closed: zero natural tasks, task identifiers, protected
outcomes, natural fault injections, operators, or public effects were opened.
The delayed monitor used logical time and supplies no actual elapsed
twenty-four-hour evidence. The authored arm outcomes are calibration behavior,
not rates, causal comparisons, natural usefulness, operational safety,
transfer, T4, support, or release evidence.

The durable record is
`experiments/governed_operations_argument_exit/qualification/2026-07-28-local.json`;
the reader decision is
`docs/p5_natural_stateful_service_campaign_qualification.md`. The next legal
action is to admit consecutive eligible natural development tasks only as
independently necessary work arises, run the frozen five-arm development
procedure, collect the complete outcome and cost set, recalibrate after any
change, and perform the development-only precision simulation. The forty-task
held-out denominator remains closed until its competence, resource, precision,
and custody gates pass and the single protected opening is authorized.

### P5 natural-task admission gate - 2026-08-14

The campaign's next legal action is now executable rather than documentary.
`scripts/admit_p5_natural_task.py` accepts one candidate envelope kept outside
the repository, verifies a clean content-addressed source snapshot, checks the
pre-outcome acceptance contract and all frozen eligibility exclusions, and
previews the admission before `--write` is allowed. It allocates each of the
five task families through a frozen seeded schedule containing exactly three
development and eight held-out slots, assigns one fault and one five-arm order,
and updates the existing intake custody. Development receipts retain the task
and acceptance contract. Held-out receipts retain only digests and expose no
protected task content.

`scripts/validate_p5_natural_task_admission.py` exhausts the authored 55-slot
allocation in temporary repositories: fifteen development assignments, forty
held-out assignments, five-family balance, deterministic fault/arm binding,
held-out redaction, exact custody/receipt identity, and eighteen rejecting
controls for invented or solved work,
outcome-aware selection, late acceptance, private or human-dependent work,
public effects, denominator overlap, prior exposure, subjective preference,
source drift, discovery drift, and duplicate admission. This is gate
qualification, not a natural task result. Canonical custody remains at zero
admitted tasks and zero outcomes. Every future admission changes custody and
therefore requires the campaign qualification to be rerun before any arm may
execute. No support, release, T4, usefulness, safety, transfer, SOTA, AGI, or
ASI inference follows.

## P6 — Evidence, instrument, and source renewal

Run a dated primary-source and official-comparator sweep at least quarterly and
whenever a major architecture, evaluation, governance, learning, unlearning,
memory, AI-control, or evidence-method result appears. Map accepted sources to
chapters and canonical claims; preserve source-reported, locally reproduced,
and independently reproduced states. Prefer sources that can refute, narrow,
or change a live claim or protocol over bibliography growth.

Before reusing an evaluator or harness with materially different models,
domains, languages, scales, or tasks, renew its construct and sensitivity
evidence. Calibration must include known-effect injection, positive-control
behavior, adversarial evaluator cases, independence/leakage review, uncertainty,
and cost. Instrument drift closes the claim denominator; it does not create a
null result.

Maintain a failure-mode library for false negatives: non-activation, weak
training, optimizer mismatch, insufficient capacity, task floor/ceiling,
dataset artifacts, distribution mismatch, baseline under-tuning, evaluator
blind spots, leakage, underpower, seed instability, hidden lifecycle costs,
and outcome-aware rescue. Every new campaign states which of these it excludes,
measures, or retains.

### P6.1 — Deterministic Capability Compilation argument-exit lane

The July 2026 `deterministic_capability_compilation` source is integrated as
design rationale across twenty-two existing chapter owners; it creates no new chapter
and no support transition. Its next evidence-bearing unit is a bounded
capability-foundry vertical slice, not a toy imitation task. Freeze a capability
charter and semantic obligation mass-balance ledger; implement one executable
scaffold, at least two semantically closed learned fields, an NCO package and
four-layer ABI, a sparse linker, pass/fail/unknown translation validation, an
independently implemented evaluator, residual escrow, one reification proposal,
and effect-complete recovery.

The campaign must give the architecture a fair chance to succeed. Compare
against strong adapter, routed-expert, dense-distillation, merge, imitation,
and scratch-learning baselines under matched training, tuning, inference,
verification, fallback, rollback, and maintenance budgets. Test shared-state
interference, learner-induced states, verifier capture, shield bypass, residual
dominance, specification defects, reward exploitation, false reification, and
irreversible effects. A failed weak learner or inactive linker is N0/N1, not
evidence against capability compilation. Broad preservation claims require
independent reproduction and transfer beyond the development domain.

### P6.2 — Platonic World Model semantic-continuity lane

The July 2026 `platonic_world_model` source is integrated as design rationale
across nineteen existing owners; it creates no new chapter and no support
transition. Build profiles incrementally: stable family/version identity;
proposition, attestation, commitment, and proof separation; semantic diff and
governance; branch-protected grounding and dynamics; then packet compilation
and federation. Each profile must earn measured value before the next expands
the trusted and maintenance surface.

Both lanes are bound to
`docs/july_2026_two_paper_mining_completeness_audit.md`. A future source update
must refresh the relevant coverage row, chapter assignments, source note, and
research residuals; inventory or citation presence alone cannot preserve a
`fully mined` disposition.

The frozen evaluation must be longitudinal and adversarial. Compare against
well-tuned retrieval, vector-memory, property/RDF graph, ontology/provenance,
context-aware graph, latent/object-centric world-model, and concept-model
baselines. Induce lexical, intensional, extensional, grounding, relational,
dynamic, context, normative, and dependency drift; model replacement; policy
change; branch escape; evidence laundering; mapping abuse; authority escalation;
and dependency-index evasion. Measure historical replay, silent equivocation,
migration accuracy, context leakage, actuality contamination, grounding and
planning value, blast-radius recall, packet sufficiency, information-flow
leakage, latency, storage, review burden, and maintenance cost. Reject any PWM
component that simpler systems match at materially lower total cost.

### P6.3 — Structural-completeness source and chapter tranche

The 2026-07-19 merge/addition audit is bound to
`docs/structural_completeness_chapter_research_2026_07_19.md`. Its decision is
**no chapter merges**. The measured maximum pairwise chapter similarity is
0.298; editorial repetition is handled by P7.1a and cannot be used to collapse
distinct owners. All four first-tranche candidates have now passed the source,
exclusive-owner, Corben-crosswalk, and chapter-packet gates and are present in
the working manifest as conceptual, argument-level chapters:

1. `white-box-evidence-interpretability-and-activation-governance` in Part IV
   after Benchmark Ratchets owns model-internal evidence packets, mechanistic
   faithfulness, activation interventions, side effects, and release authority.
2. `governed-world-models-and-reality-grounding` in Part II after Planning owns
   predictive-state identity, imagined/observed separation, model/world
   discrepancy, external correction, and action-grounding gates.
3. `human-factors-and-meaningful-control-in-oversight` in Part I after Human
   Intent owns whether oversight is genuinely exercisable under information,
   time, workload, competence, authority, incentives, interface, and fallback.
4. `governed-operations-incident-command-and-graceful-degradation` in Part IV
   after Safety Cases owns field observability, incident declaration and
   command, containment, degrade/failover/manual modes, recovery, disclosure,
   learning, and decommissioning.

Manifest admission is not chapter completion, evidence, or publication. All
four first-tranche chapters have now passed their independent formalization,
record-contract, protocol-custody, source-crosswalk, reader-integration, and
no-promotion gates at `argument` support. Their claim-bearing empirical lanes
remain unexecuted and therefore create no empirical movement. Their admission
receipts remain terminal, but Round 16 identified cross-cutting atom,
derived-reader, template, and white-box-depth integration debt. P6.5 may repair
those exact defects; it cannot relabel the chapters empirically complete or
reopen them merely to inflate prose or the manifest. No source, packet, chapter
draft, or structural decision changes support by itself.

The initial drafts were created in the sequence interpretability, world models,
human factors, then operations. Interpretability supplies the white-box evidence
vocabulary; world models sharpens the Platonic World Model and Theseus grounding
boundary; Human Factors has a frozen ethics/privacy-aware study protocol with
no recruitment authority or opened outcomes; and Operations has a bounded
authored authority-to-effect safe-hold case that remains explicitly separate
from the blocked natural flagship T4 trace. The second tranche is now paused
behind the Round 16 evidence-first gate. After that gate clears it may proceed
one candidate at a time and at most one new chapter per material
empirical/evidence checkpoint; it may never delay, shrink, retune, or read
P2/Q1/Q2 held-out work.

### P6.4 — Second structural-boundary completeness audit

The end-to-end ownership audit is bound to
`docs/structural_completeness_gap_audit_2026_07_19.md`. It finds thirteen further
chapter candidates whose proposed contracts were absent from the 59-entry
manifest at audit time. P6.4-A1 and P6.4-A2 were first admitted as the 60th and
61st chapters. The bounded Round 18 amendment subsequently admitted candidates
2, 3, 5, and 6 at argument support and admitted Inner Alignment from a separate
gap finding, bringing the manifest to 66. The remaining seven P6.4 candidates
are **research records under a post-breadth freeze**, not promised chapters.
The historical all-pass envelope became 73 because Inner Alignment was not
one of the original thirteen. The later N/O audit adds two research candidates,
so the purely theoretical all-pass envelope is 75. Neither number is a target
or completeness claim:

1. **Terminal — admitted at argument support.** `governed-model-training-distributed-optimization-and-scaling` owns the
   training-run transaction from frozen inputs and topology through distributed
   execution, full-state recovery, checkpoint-family selection, and qualified
   handoff. Its decision packet is
   `docs/p6_4_a1_governed_model_training_adjudication.md`; no empirical,
   support, release, or publication effect follows.
2. **Terminal — admitted at argument support in Round 18.**
   `perception-sensor-fusion-and-observation-trust` owns how time-bound,
   calibrated, provenance-bearing environmental evidence becomes an admitted
   observation rather than assumed truth.
3. **Terminal — admitted at argument support in Round 18.**
   `embodied-agency-real-time-control-and-physical-safety` owns the transition
   from an authorized symbolic action to a deadline-bound physical control
   trace under dynamics, interlocks, fallback controllers, and irreversible
   effects.
4. **Terminal — admitted at argument support.** `privacy-data-rights-and-information-flow-governance` owns purpose, consent, minimization, privacy loss, subject and affected-group records, derivative obligations, correction, export, deletion, and bounded remedy receipts across the information lifecycle. Its decision packet is `docs/p6_4_a2_privacy_data_rights_adjudication.md`; no empirical, legal-compliance, support, release, or publication effect follows.
5. **Terminal — admitted at argument support in Round 18.**
   `human-ai-organizations-delegation-and-accountability` owns organization
   charters, roles, competence, workload, decision rights, delegation,
   separation of duties, incentives, escalation, accountability, succession,
   and dissolution across human and AI actors.
6. **Terminal — admitted at argument support in Round 18.**
   `multi-agent-dynamics-collective-intelligence-and-systemic-risk` owns
   population-level cooperation, conflict, collusion, cascades, concentration,
   correlated failure, institutional feedback, and gradual disempowerment that
   pairwise-valid exchanges cannot certify.
7. `autonomous-replication-proliferation-and-containment` owns the composed
   resource, copy, credential, deployment, descendant-identity, persistence,
   recall, shutdown, and proliferation lifecycle in a safe synthetic boundary.
8. `scientific-discovery-and-experimental-governance` provisionally owns a
   domain-independent loop from hypothesis and preregistration through
   instrument authority, measurement, causal/statistical analysis, replication,
   dual-use review, and evidence-ledger handoff.
9. `human-ai-communication-persuasion-and-epistemic-security` owns the outbound
   transaction from an evidence-bounded claim through audience and vulnerability
   classification, personalization, channel and amplification policy, observed
   belief or choice effects, correction, retraction, and remedy.
10. `institutions-international-coordination-and-public-legitimacy` owns the
    public-institution transaction from mandate and jurisdiction through
    participation, law/policy/standard mapping, international commitments,
    scientific assessment, verification, enforcement, remedy, amendment, and
    withdrawal without pretending technical architecture creates legitimacy.
11. `ai-deployment-transition-distribution-and-human-agency` owns the
    prospectively governed deployment-to-transition transaction across tasks,
    jobs, skills, wages, ownership, bargaining power, access, prices,
    concentration, critical services, observed affected-party distribution,
    remedy, and retained human option value.
12. `physical-compute-infrastructure-energy-and-environmental-constraints` owns
    the delivery and retirement of physical compute across accelerators,
    memory, networks, facilities, power, grids, cooling, water, land,
    emissions, materials, resilience, and affected communities.
13. `governed-objective-formation-value-learning-and-goal-integrity` owns the
    positive transition from authorized purposes, preferences, constitutional
    predicates, affected-party claims, and unresolved uncertainty to a
    versioned target-property/proxy contract with explicit consumers,
    generalization and ontology assumptions, integrity tests, expiry,
    reauthorization, and retirement.

Privacy and model training are adjudicated first because current chapters
already delegate responsibilities to owners that do not exist. Perception is
adjudicated before the World Models draft; embodiment follows after its
Perception and Runtime Adapter boundaries stabilize. Human–AI Organizations
must remain a meso-level designed-institution owner between Labor OS and
Inter-Stack Protocols; Multi-Agent Dynamics must remain a macro-level emergent-
population owner and freeze a population-level empirical program and human-
influence indicators.
Replication must freeze a synthetic-provider boundary, descendant authority,
shutdown controls, and a non-proliferation review before any execution.
Human–AI Communication is adjudicated after the Human Factors interfaces are
stable and before organization/population integration closes. It must preserve
an exclusive evidence-to-audience-to-effect-to-correction control plane; pass
ethics, privacy, vulnerability, and non-manipulation review; use benign
prospective tasks, heterogeneous held-out audiences, simpler neutral-helpfulness
and no-personalization baselines, independent outcome scoring, and correction/
retraction tests; and reject population-level claims from synthetic classifiers
or a single convenience sample.
Institutions and AI Deployment Transition are adjudicated after Human–AI
Organizations and before Multi-Agent Dynamics closes: the former must remain a
technology-neutral public-authority and cross-jurisdiction control plane rather
than a volatile law survey, and the latter must measure realized heterogeneous
outcomes rather than convert task exposure or firm productivity into
macroeconomic forecasts. Physical Compute follows Governed Training and Resource
Economics and is rejected if its facility, grid, cooling, water, materials,
community, and retirement lifecycle can be carried cleanly by those owners.
Objective Formation is adjudicated early because current downstream chapters
assume a legitimate objective they do not create. It is rejected if its
target/proxy/consumer binding and objective-version lifecycle collapse into
Human Intent, Constitutional Alignment, Moral Uncertainty, Policy Optimization,
Planning, or RSI. Its four existing source records establish only a preliminary
capability/failure set; plural aggregation, ontology migration, competing-
contract, and measurement roles remain open. Candidates J, K, and L each have
two new source-noted comparators, not a completed admission bibliography. Their
source-role gates remain open pending the additional passage-reviewed
comparators and limitation/counterevidence specified in the audit.
Scientific Discovery is decided last and is rejected as a separate chapter if
it cannot specify a reusable experimental control plane beyond Planning,
Runtime Adapters, Benchmark Ratchets, Artifact Graphs, and the Living Book.

Each candidate needs passage-reviewed primary comparators covering
mechanism/capability, limitation/failure, competing design, and
measurement/evaluation roles where the literature permits; a Corben-source
crosswalk; adjacent-owner table; complete chapter packet; claim-commensurate
evidence and competent positive controls where empirical claims are made; a
simpler baseline; an honest finite-formalization disposition; a reader figure;
and an explicit argument-exit condition before manifest admission. Perception and embodiment
remain separate unless the boundary audit shows their observe-versus-act
artifacts and failure families cannot sustain two useful chapters. The Human–AI
Organizations packet must prove that responsibility-control coupling, decision
rights, role competence, incentives, succession, and dissolution cannot be
absorbed by Human Factors, Labor OS, Human Intent, System Boundaries, or the
proposed multi-agent chapter. Uncertainty/calibration, epistemic security,
semantic memory, reasoning-trace faithfulness, and model welfare receive named
section-scale owners; importance alone does not justify another chapter.
Epistemic-security, distributional impact, institutional/jurisdictional, and
physical-resource boundary sections remain mandatory in their named existing
owners whether Candidates I, J, K, or L pass, are narrowed, or return to those
owners. Objective-provenance duties remain mandatory in Human Intent,
Constitutional Alignment, Moral Uncertainty, Policy Optimization, Planning,
Benchmark Ratchets, and RSI whether Candidate M passes. Embedded agency,
self-reference, and robust delegation remain a named foundations program across
ASI Is a Stack, System Boundaries, RSI Boundaries, and the Integrated Reference
Architecture until they produce an operational contract and honest evidence
program sufficient to reopen chapter admission.

If at least three of Human–AI Organizations, Human–AI Communication,
Institutions, AI Deployment Transition, and Multi-Agent Dynamics pass, P7.2
must adjudicate a dedicated **Organizations, Institutions, and Societal
Transition** part. Do not create that part before its owners exist.

The tranche may not displace P2 or the Theseus flagship, inspect protected
Q1/Q2 outcomes, turn a benchmark into a dangerous real-world replication
capability, or inherit support from cited work. Failure at any gate returns the
material to the exact existing sections listed in the audit. The original upper
bound of 72, the amended historical bound of 73 after the separate Inner
Alignment admission, and the later theoretical 75-candidate envelope after N/O
are decision envelopes rather than targets or completeness claims.

P6.4 is now **post-breadth frozen**. A1/A2 plus candidates 2/3/5/6 retain
terminal argument-level admissions. The remaining seven candidates have no
queue position. Research and source notes may be maintained for freshness, but
no candidate may receive a chapter path, manifest entry, proof target, or
admission transaction without a new dated amendment and a completed material
empirical/evidence checkpoint.

### P6.4-R18 — terminal bounded conceptual-completeness packet

Inner Alignment enters beside the four P6.4 candidates because learned-
objective integrity is distinct from external constitutions and adversarial
behavioral evaluation. Causal reasoning and uncertainty enter Governed World
Models; scaling/emergence enters Efficient ASI; instrumental convergence enters
Failure Modes; RAG enters Virtual Context ABI; artificial moral status enters
Moral Uncertainty; decision theory enters Multi-Agent Dynamics. Exact ownership,
sources, non-claims, stop rule, birth atoms, and reader handoffs are recorded in:

- `docs/round_18_bounded_breadth_completion_adjudication_2026_07_24.md`;
- `research_backlog_records/round_18_bounded_breadth_completion_2026_07_24.json`;
- `new_paper_triage_scenarios/round_18_bounded_breadth_completion_2026_07_24.json`;
- `evidence_quality/round_18_breadth_completion_claim_atoms.json`; and
- `docs/round_18_breadth_completion_reader_projection.md`.

Terminal means complete manuscript integration at argument support, not
empirical validation, formal proof, deployment, replication, SOTA standing,
physical safety, institutional legitimacy, objective identification, or moral-
patienthood determination.

### P6.5 — Round 16 post-activation integration debt

This is the ordered existing-book organization lane. Its subpackets are not
interchangeable: R16-A, W3, P7.2-T1D, and R16-B are terminal. R16-B
derives from the resulting exact 84-chapter state. R16-E's
manuscript-depth amendment is terminal. This lane repairs the six older
post-baseline chapters; the five Round 18 chapters have separate birth atoms
and cannot be backdated into that historical denominator.

**R16-A terminal receipt — append-only atomization (6/6 chapters; 30/30
reviewed atoms; completed 2026-07-26).** The separately versioned
`evidence_quality/post_activation_six_chapter_claim_atom_addendum.json`
organizes White-Box Evidence, Governed World Models, Human Factors, Governed
Operations, Governed Model Training, and Privacy/Data Rights into the same
five explicit roles: exact core, ownership boundary, mechanism,
failure/noninheritance rule, and argument-exit target. Every atom carries a
stable identity, exact claim text, scope, falsifier, acceptance criterion,
promotion ceiling, evidence-plan route, chapter anchor, owner, and non-claims.
Six review receipts bind those atoms to exact chapter digests and ten reviewed
surfaces apiece.

The terminal transaction includes a deterministic builder, a dedicated JSON
Schema, an independent semantic validator, and fourteen rejecting mutations
covering missing chapters or atoms, duplicated identity, owner or core-claim
rewrite, stale digest, support movement, missing falsifier/criterion/route/
nonclaim, historical-denominator rewrite, and review mismatch. The identity
graph now resolves against 4,112 canonical atoms: the current 4,067-atom
registry, the immutable historical 15-atom addendum, and this separate
30-atom packet. Appendix C publishes the six-owner projection. The transaction
changes no claim support, release state, historical 3,730-atom activation
receipt, current registry, or historical 15-atom addendum.

**R16-B terminal receipt — current-reader freshness (completed
2026-07-26).** The packet binds exact source commit
`56563e1b2b64405e2e944c521bf4df9f29eba6e6`, all 84 chapter identities and
digests, all 22 narrative units, and the exact 11 thesis / 54 reference / 7
implementation / 12 speculative role partition. Its deterministic projection
removes only YAML metadata and explicitly machine-only fenced blocks; it
preserves prose, tables, diagrams, source boundaries, non-claims, tests,
summaries, and handoffs. Eight reader surfaces—opening map, role map,
narrative route, overview, glossary, source appendix, claim/evidence
projection, and final synthesis—are independently content-addressed.

The transaction stores one manifest and report instead of copying the 84
canonical chapters into another tracked tree. The historical
`reader-2026-07-18` manifest is digest-bound as immutable publication history.
Virtual QMD is terminal at source freshness; HTML, PDF, EPUB, DOCX, and audio
are explicitly deferred because each needs separate render, navigation,
accessibility, visual, or listening review. Sixteen rejecting mutations cover
identity, digest, role, narrative route, reader surfaces, historical custody,
format laundering, source duplication, and authority movement. This is a
freshness and organization receipt, not publication authority or claim proof.

**R16-C terminal receipt — admission-template inheritance guard (completed
2026-07-26).** W1's 55-chapter and W2's 60-chapter receipts remain terminal for
their declared snapshots. W3 uses the exact 84 manifest chapter paths before
and after commit `99457770390a4af4848b9e43656907cfe099fd75`, Unicode NFKC,
`[A-Za-z0-9_\`'-]+`, 12-token n-grams, and a frozen eight-chapter spread
threshold. The reader-facing projection falls from 812 repeated 12-grams at a
maximum spread of 14 to zero; copied Mermaid and Codex-test fingerprints fall
from a maximum spread of ten to zero. Raw QMD remains separately reported
because its widest 64- and 55-chapter blocks are generated source/evidence
projections with explicit owners.

The shared lifecycle method now has one owner in Living Book Methodology. Ten
affected chapters keep their domain-specific claims, sources, boundaries,
mechanisms, evidence plans, diagrams, tests, summaries, and handoffs. Semantic
review records zero deletion of claims, source assignments, equations, proof
tags, protocol/schema references, or support states. The tracked copied
scaffold is rejected, the distinct chapter fixture is accepted, and eighteen
mutations reject. Claim-review reconciliation retires 241 inherited
prose-candidate identities and adjudicates 177 domain-specific replacements
across the ten chapters plus Living Book Methodology; all 4,067 structured
atoms remain, no new material atom is created, and zero prose candidates remain
pending. The machine receipt is
`evidence_quality/p7_1a_w3_inheritance_guard.json`; its schema, deterministic
builder, report, validator, and fixtures are registered together.

**R16-D / P7.2-T1D — six-chapter proof-readiness depth pack (terminal 2026-07-26).**
The White-Box requirements below remain fully binding, but the packet now also
applies the six-condition maturity gate to Inner Alignment, Multi-Agent
Dynamics, Perception, Embodied Agency, and Human–AI Organizations and completes
the accepted existing-owner sections in the Post-Round-18 amendment. Deepen the
existing White-Box chapter rather than add an interpretability chapter.
Passage-review and source-note the
primary probe-control, interpretability-illusion, SAE scaling, SAEBench, and
SAE-benchmark reliability papers. Add a comparative method matrix and an
evidence ladder that separates decodability, stability, reconstruction,
semantic construct validity, causal necessity/sufficiency, mediation,
specificity, cross-distribution transfer, intervention utility, collateral
damage, and policy authority. The exact intake set is:

| Proposed source ID | Primary source | Required role |
|---|---|---|
| `ext_probe_control_tasks_2019` | Hewitt and Liang, [Designing and Interpreting Probes with Control Tasks](https://aclanthology.org/D19-1275/) | Probe selectivity, memorization control, and construct-validity method |
| `ext_interpretability_illusion_bert_2021` | Bolukbasi et al., [An Interpretability Illusion for BERT](https://arxiv.org/abs/2104.07143) | Cross-dataset challenge and spurious simple-concept interpretation failure |
| `ext_scaling_sparse_autoencoders_2024` | Gao et al., [Scaling and evaluating sparse autoencoders](https://arxiv.org/abs/2406.04093) | Existing SAE mechanism/scaling comparator; deepen rather than duplicate its inventory record |
| `ext_saebench_2025` | Karvonen et al., [SAEBench](https://arxiv.org/abs/2503.09532) | Multi-metric SAE comparison and proxy-versus-practical-performance tension |
| `ext_sae_benchmark_reliability_2026` | Chanin, [Are Sparse Autoencoder Benchmarks Reliable?](https://arxiv.org/abs/2605.18229) | Metric noise, ground-truth correlation, discriminability, and benchmark-construct audit |

Each new record needs a passage-level source note, explicit admissible use,
non-authority, chapter mapping, and freshness metadata before prose cites it.
The 2026 audit is recent counterevidence, not permission to dismiss all SAE
work; its claims remain scoped to the metrics and settings it actually tests.
The protocol must include:

- control tasks, selectivity, simple/regularized probe baselines, label and
  evaluator leakage tests, and preregistered concept operationalization;
- SAE/dictionary-size, sparsity, reconstruction, dead-latent, feature
  splitting/absorption, seed/checkpoint stability, and metric-reliability
  sweeps rather than one favorable extractor;
- multiple corpora and distribution shifts designed to expose an
  interpretability illusion rather than confirm a selected story;
- ablation, patching, replacement and steering with matched sham and off-target
  controls, dose response, mediation alternatives, protected-capability damage,
  and unexplained residual accounting;
- strong behavioral and method baselines, resource and analyst-cost accounting,
  an independently implemented evaluator, positive controls and a fair rescue
  ladder; and
- an explicit outcome matrix: a failed probe or SAE may be N0–N2 evidence about
  that exact method, never a broad refutation of interpretability, while a
  positive internal result remains diagnostic until causal and transfer gates
  earn more.

All six maturity records, every accepted prose repair, source inventory and
notes, applicable claim atoms, protocols, reader projections, inheritance
audit, validators, and non-claims now agree. The packet did not run the
resource-gated model campaign and cannot promote support by prose, source
citation, formal record, fixture, maturity record, or protocol readiness.

**R16-E — Governed optimizer landscape and optimizer-policy qualification
(terminal manuscript-depth amendment; empirical residual retained).**
This packet deepened `Governed Model Training, Distributed Optimization, and
Scaling`; it did not create a separate optimizer chapter. At its opening
checkpoint, the existing owner already bound optimizer, scheduler, numerical
policy, topology, full-state recovery, checkpoint family, and qualified handoff,
but its source packet and prose did not provide a real optimizer landscape. The
executed research and chapter plan is
`docs/optimizer_landscape_chapter_research_2026_07_21.md`.

Passage-review primary sources and explain, through common notation and a
comparative mechanism matrix, classical SGD/momentum/Nesterov; adaptive
AdaGrad/RMSProp/Adam/AMSGrad/AdamW; memory- and layer-scaled Adafactor,
LARS/LAMB; tensor/matrix preconditioners Shampoo and SOAP; Lion; Sophia;
schedule-free methods; Muon and qualified variants; and theoretical or
scale-transfer families including maximal-update parametrization, modular
norm/Scion, natural gradient, K-FAC, mirror/proximal methods, and trust-region
methods. Policy-gradient and preference objectives remain owned by Policy
Optimization and Learning from Feedback.

Treat each optimizer as a coupled run policy: implementation and version,
parameter eligibility/groups, parametrization, initialization, decay, clipping,
schedule and warmup, batch arithmetic, state precision, approximation settings,
distributed topology, stopping rule, and checkpoint state are identity-bearing.
A competent comparison must freeze model/data/token/hardware/evaluation
conditions; grant equal or explicitly accounted tuning budgets and
method-specific rescue; run at least three seeds; retain all attempted and
failed runs; and measure tokens, steps, wall time, energy, final and downstream
quality, robustness, memory, communication, numerical stability, tuning cost,
scale transfer, resume equivalence, and governance cost together. Muon-specific
tests must include matrix eligibility, fallback optimizer rules,
orthogonalization approximation precision, update scaling, and distributed
communication rather than testing a naive label-level implementation.

R16-E's manuscript-depth scope is terminal when passage-reviewed source
records/notes, chapter mechanism and decision sections, an optimizer-policy
contract and negative mutations, a preregistered matched-comparison protocol
with executable self-tests, local chapter reader/source/glossary projections,
and validators agree. The shared six-chapter atom addendum and combined current-
reader derivative remain owned by R16-A and R16-B. Execution
may remain resource-gated: a toy or under-tuned experiment cannot close the
protocol or support a negative inference. Source reports, theory, prose,
fixtures, and protocol readiness alone cannot establish optimizer superiority,
scale transfer, model quality, safety, support, RSI, release, or SOTA.

**2026-07-21 implementation checkpoint.** Fifteen primary optimizer records and
passage notes are now ingested; the existing chapter contains the family
taxonomy, AdamW reference, Muon implementation questions, scale/parameterization
boundary, competent selection protocol, and joint reporting matrix; adjacent
substrate, policy-update, and resource handoffs and the glossary/source appendix
are reconciled. `schemas/optimizer_policy_card.schema.json` plus its authored
Muon-primary/AdamW-fallback fixture and independent validator reject eighteen
identity, routing, state, approximation, communication, tuning, rescue,
evaluation, source, and authority mutations. This materially closes the reader,
source, prose, and policy-contract depth surfaces and closes R16-E at argument
support. Its claim-atom projection remains owned by R16-A, the combined current-
reader projection remains owned by R16-B, and the resource-gated matched
campaign plus independent reproduction remain unexecuted P6 evidence
residuals. Those shared projections and empirical residuals cannot be used to
reopen or repeatedly deepen the chapter. Support and release effects remain
`none`.

**2026-07-22 Relational Dimension Compiler source-intake checkpoint.** The
Corben-authored Markdown/DOCX pair is archived in the ignored raw-source cache
with recorded SHA-256 digests, and the Markdown is the semantic reference after
heading-level comparison with the DOCX presentation copy. A public-safe,
passage-level source note now distinguishes semantic, primitive computational,
and storage arity; typed relation objects and incidences; adaptive relational
order; branch-local qualification; reversible semantic contraction; compiled
relational specialists; hardware lowering; and the proposed RODIE instrument.
The source inventory, exact claim mappings, triage scenario, and research
backlog route bounded material into Cognitive Compilation, Governed World
Models, Routing, Replaceable Substrates, Procedural Memory, Benchmark Ratchets,
Resource Economics, Integrated Reference Architecture, and the Open Research
Agenda. Their reader prose, source queues, glossary, outline, and generated
appendices must remain reconciled.

The paper also clears the conceptual distinct-owner test for a future
`relational-dimension-compilation-and-polyadic-cognition` chapter because no
current owner holds the full relational-topology lifecycle. It is nevertheless
**deferred, not admitted**: the structural freeze grants no chapter path,
manifest row, proof target, reader position, or admission transaction. After
the freeze clears, the candidate must be adjudicated atomically with verified
external bibliography, exact ownership and adjacency, a birth-complete claim
atom and reader packet, W3 inheritance, formal maximum-inference ceilings, and
an anti-self-confirming RODIE protocol with strong lower-order rescues,
complete candidate denominators, independent evaluation, lifecycle cost, and
natural-task transfer. Current integration changes no support state and proves
no relational advantage, world truth, grounding, implementation, benchmark
result, release, RSI, AGI, ASI, or SOTA claim.

### P6.6 — Heterogeneous inference memory and speculative paging

**Status:** primary-source intake and the complete six-owner reader-prose slice
completed 2026-07-23 by express owner commission. The policy schema, rejecting
validator, dry-run planner, hardware characterization, and empirical packet
remain deferred until the structural-resume gates are terminal.

The source family now spans AirLLM layer streaming; DeepSpeed Inference and
FlexGen GPU/CPU/NVMe placement; ordinary Hugging Face Accelerate and llama.cpp
disk/memory-map baselines; flash-aware loading; PowerInfer hot/cold neuron
placement; PagedAttention and vAttention's competing KV-layout choices;
InfiniGen and SpeCache speculative KV prefetch; SpecOffload's distinct
composition of offload with speculative decoding; and the very recent ATSInfer
tensor-granular consumer-device preprint. The exact research and implementation
contract is
`docs/heterogeneous_inference_memory_and_paging_research_2026_07_23.md`.

**Ownership decision.** Do not create a chapter. Fast Generation owns the
physical-memory method taxonomy and route admission. Personal Compute Hives
owns worker-specific capability and policy admission; Resource Economics owns
the I/O roofline and lifecycle bill; Model-Weight Custody owns shard/page
identity and storage lifecycle; Replaceable Cognitive Substrates owns
architecture-specific granularity. Virtual Context receives only a
semantic-page versus physical-page boundary. Training offload remains separate
from inference paging.

**Required manuscript integration.**

All six items below are now terminal in the manuscript and reconciled to the
source manifest, outline, Appendix A/H surfaces, and chapter source crosswalks:

1. Added `Heterogeneous inference memory: residency, paging, and prediction` to
   Fast Generation, separating weight, KV, activation, expert, recurrent, and
   draft state; layer streaming, planned placement, demand paging,
   contiguous-virtual allocation, predictive prefetch, sparse placement, and
   speculative-decoding/offload composition; and exact versus approximate
   behavior.
2. Added worker-internal memory-tier admission to Personal Compute Hives,
   including storage/RAM/VRAM/thermal capability cards, scratch and recovery
   floors, largest-indivisible-object checks, and workload-specific
   interactive/batch/background qualification.
3. Added `The I/O roofline and the price of virtual VRAM` to Resource Economics,
   accounting for bytes per token, random versus sequential reads, conversion,
   duplicate storage, cold starts, unused prefetch, cache pollution, energy,
   thermal throttling, storage wear, and displaced capacity.
4. Added paged-weight custody to Model-Weight Custody, binding every transformed
   shard to parent checkpoint, adapter, quantization, layout, runtime,
   checksum, encryption/key state, backup, scratch, recovery, sanitization, and
   descendant closure.
5. Added substrate-specific paging policy to Replaceable Cognitive Substrates so
   dense, sparse/MoE, recurrent, state-space, and future architectures expose
   their own memory objects and locality assumptions through the Cognitive
   Kernel ABI.
6. Added the bounded no-conflation treatment to Virtual Context: semantic pages and
   physical runtime pages have different identities, authority, eviction,
   integrity, and correctness contracts.

**Policy and validation artifacts.** Create
`schemas/heterogeneous_inference_memory_policy.schema.json`, at least two valid
policies, and rejecting fixtures for wrong shard identity, stale/cross-request
KV ownership, hidden approximation, missing speculative-miss fallback,
capacity overcommit, absent scratch/recovery, unbounded or unaudited prefetch,
missing I/O/energy/endurance accounting, and support overclaim. An independent
validator must check exact model/runtime/hardware/storage identity, distinct
object classes and tiers, page/shard checksums, placement/eviction/prefetch
rules, exact-versus-approximate status, request isolation, crash recovery,
expiry, and residual ownership. A dry-run planner may emit placement,
transfer, and fallback decisions but cannot establish performance.

**Competence gate before empirical interpretation.** A slow toy implementation
cannot refute paging. Every evaluated arm must pin a competent current
implementation, model, tokenizer, adapter, quantization, runtime, kernel,
device map, load mode, filesystem, storage device, thermal state, and rescue
budget. Characterize sequential/random SSD bandwidth, PCIe and host-memory
bandwidth, page-cache behavior, and power policy before model results. Separate
cold/warm/steady state; prefill/decode; batch-1/batched; short/long context;
prefix reuse; concurrency; dense/MoE; interruption/recovery; and locality-shift
workloads.

**Matched arms and metrics.** Compare the smallest adequate resident model,
CPU/unified-memory inference, ordinary partial offload, layer streaming,
planned heterogeneous placement, paged and contiguous-virtual KV baselines,
exact host-KV offload, predicted KV prefetch, hot/cold sparse placement,
speculative-decoding/offload composition, and prediction-disabled fallback
where competent implementations exist. Factorially ablate quantization,
sparsity, paging, scheduling, and speculative decoding or retain an explicit
non-isolation residual. Report useful accepted task success and quality with
first-token, inter-token, end-to-end, median/tail, tokens/requests per second,
peak VRAM/RAM, bytes read/written per token, transfer overlap, page misses,
prefetch precision/recall, unused reads, cache pollution, compute utilization,
energy, thermal behavior, wear proxy, conversion amplification, crash
recovery, and total cost.

**Remaining promotion and terminal gate.** Admission is workload-region-specific. “The
model loaded,” “a token was emitted,” lower VRAM, or higher aggregate
throughput cannot establish interactive usability, quality, deployment,
support, architecture generality, or SOTA. The packet closes only after the
now-completed five owner edits and Virtual Context boundary are joined by the
policy schema and rejecting validator, hardware and workload receipts,
competent protocol, any honestly available measurements, atom and reader
projections, W3 inheritance check, and explicit dispositions for unavailable
hardware or unrun methods. Source-reported performance remains source-reported
until independently reproduced.

### P6.7 — Inference cache reuse and honest pricing

**Status:** nine-source primary intake and the complete three-owner
reader-prose slice completed 2026-07-23 by express owner commission. The
`CacheReuseReceipt` schema, rejecting validator, natural exact-prefix workload,
cache-aware scheduling comparison, and semantic-response-cache safety campaign
remain deferred until the structural-resume gates are terminal.

The source family now spans current OpenAI, Anthropic, and Gemini provider
contracts; vLLM block-hash prefix reuse and tenant cache salts; SGLang
RadixAttention and cache-aware scheduling; Prompt Cache's position-aware
modules; Mooncake's disaggregated KV fabric; CacheBlend's non-prefix
cross-attention repair; and Microsoft's semantic-response-cache warning. The
exact research and pricing analysis is
`docs/inference_cache_reuse_and_pricing_research_2026_07_23.md`.

**Ownership decision.** Do not create a chapter. Fast Generation owns
in-request KV, exact-prefix, prompt-module, persistent/disaggregated,
non-prefix, exact-output, and semantic-response mechanism distinctions plus the
cache-reuse receipt. Resource Economics owns write, read, storage, lookup,
transfer, eviction, miss, rate-limit, and downstream-pricing economics.
Context Transactions owns exact-response dependency closure, semantic-match
admission, tenant and authority binding, freshness, invalidation, poisoning,
disclosure, deletion, and residual state.

**Completed manuscript integration.**

1. Fast Generation now distinguishes seven cache objects; explains why exact
   prefix hits reduce prefill and time to first token while still generating a
   new answer; binds model, tokenizer, adapter, runtime, prompt, tenant, policy,
   and source identity; covers prompt shape, block hashes, scheduling,
   persistent placement, non-prefix repair, output memoization, semantic reuse,
   and a complete cache-reuse receipt.
2. Resource Economics now supplies a cache break-even model, dated examples of
   current provider contract shapes, measured pass-through and alternative
   pricing models, and a joint useful-reuse ledger rather than raw hit-rate
   optimization.
3. Context Transactions now separates prefix-state reuse from prior-answer
   reuse; treats semantic similarity as an approximate candidate; defines
   risk-tier admission and dependency-complete invalidation; and covers
   provider opacity, timing leakage, poisoning, disclosure, and deletion
   residuals.

**Receipt and validation artifacts.** Create a versioned
`CacheReuseReceipt` schema and fixtures for exact hit, partial hit, ordinary
miss, policy bypass, stale source, wrong model or adapter, cross-tenant
collision, expired authority, poisoned response, invalid semantic match, and
incomplete deletion. The independent validator checks cache kind, entry and
key identity, matched length, model/runtime identity, tenant and sharing scope,
source and policy epochs, creation and expiry, invalidation, write/read/storage/
lookup/transfer/eviction/recompute meters, quality and fallback, disclosure,
cleanup, and residual ownership.

**Competence gate before empirical interpretation.** A naïve cache layout or
broken key cannot refute reuse. The exact-prefix campaign freezes model,
tokenizer, adapter, runtime, hardware, load, capacity, lifetime, tenant mix,
prompt layout, prefix length, reuse distribution, output work, and evaluator.
It must pass source-recommended configuration, prewarming, identity,
invalidation, isolation, and method-specific rescue before a negative
classification. The matched cache-disabled/full-prefill baseline uses the same
request stream. Run cold, warm, steady, burst, eviction, failover, source
correction, policy revocation, and adversarial-tenant regimes.

The semantic-response campaign remains separate because it tests decision
reuse rather than prefill reuse. It needs deliberately confusable prompts,
negation, changing dates and permissions, personalized queries, dynamic facts,
poisoned entries, calibrated abstention, independent evaluation, disclosure,
and a fresh-model fallback. A high hit rate or low bill cannot qualify unsafe
answer reuse.

**Metrics and promotion boundary.** Report eligible, written, read, partially
reused, expired, invalidated, evicted, and deleted tokens and bytes; cache
build, hashing, lookup, transfer, storage, eviction, recomputation, output,
verification, and governance cost; time to first token, per-output-token and
end-to-end latency, tails, queueing, throughput, fairness, quality, stale and
unsafe reuse, accepted useful outcomes, deletion closure, and provider and
infrastructure bills. “The provider reported cached tokens,” “the prefix was
resident,” or “the invoice was lower” does not establish application validity,
useful advantage, privacy, complete erasure, deployment, transfer, support, or
SOTA. All current performance and prices remain source- or contract-reported
until independently observed.

### P6.8 — Functional precision and behavior-preserving computation

**Status:** full source read, Markdown/DOCX pair verification, canonical raw
storage, public-safe note, inventory entry, chapter mapping, triage record,
owner adjudication, and the coordinated nine-owner manuscript integration
completed 2026-07-24. External-source resolution, schemas, validators, formal
work, and empirical work remain queued. The controlling reconciliation is
`docs/precision_contract_source_reconciliation_2026_07_24.md`.

**Ownership decision.** Do not add a chapter now.
`rankfold-neuralfold-and-artifact-compression` is the primary owner for
functional rate–distortion, behavioral-equivalence sets, representation
canonicalization, complete executable accounting, the Functional Precision
Compiler, and precision certificates.
`compact-generative-systems-and-residual-honesty` owns base/residual precision
and reconstruction-versus-utility separation. Fast Generation owns static,
mixed, progressive, and dynamic precision execution; Resource Economics owns
physical and assurance-generation cost; Readiness owns certificate status,
expiry, restriction, and revocation; Executable Specifications owns
program-transformation refinement; Model-Weight Custody owns derivative and
platform identity; and the Efficient ASI Hypothesis owns precision as one
governed adaptive resource.

The contingency title
`functional-precision-and-behavior-preserving-computation` is not an active
chapter candidate, manifest reservation, or target count. A dated owner audit
may reconsider it only after all eight bounded integrations are drafted and
only if the end-to-end compiler/certificate lifecycle remains fragmented or
overloads the current owners. Structural admission remains frozen; Candidates
N/O remain the only approved research candidates and remain inactive.

**Completed manuscript transaction.**

1. Added the primary section-scale explanation to RankFold/NeuralFold: why
   per-weight precision is representation-dependent; how the behavioral
   contract defines an acceptable implementation set; how complete executable
   description length replaces payload-only counting; and how the compiler and
   certificate lifecycle fits the existing admission lease.
2. Added bounded, nonduplicative handoffs to Compact Generative Systems, Fast
   Generation, Resource Economics, Readiness, Executable Specifications,
   Model-Weight Custody, and the Efficient ASI Hypothesis.
3. Used one shared `PrecisionContract` vocabulary, one joined lifecycle, and one
   experiment/falsifier table rather than eight restatements.
4. Preserved exact distinctions among parameter distance, reconstruction,
   protected behavior, downstream utility, physical cost, assurance, authority,
   and support.
5. Reconciled chapter source maps, outline queues, Appendix C, Appendix G,
   glossary, overview, and final synthesis without changing chapter count,
   release identity, or support state.
6. Completed a chapter-specific ownership and duplication review; the terminal
   W3 admission-guard artifact now supplies the prospective inheritance check.

Semantic acceptance requires a reader to follow
`reference -> contract -> canonicalization -> allocation -> encoding ->
residual/routing -> verification -> certificate -> expiry/revocation` with one
clear owner at every transition. Heading count, word count, source count, or a
green generic build cannot substitute for that trace.

**External-source resolution.** The paper's 49 references are an author-supplied
research map, not automatic Appendix H records. Deduplicate them against the
inventory by title, DOI, arXiv identifier, and canonical URL; verify primary
publication pages and current status; passage-review the exact result used; and
add only genuinely missing records. Resolve rate–distortion, MDL,
floating-point and numerical-analysis, post-training quantization, mixed and
progressive precision, verification, and quantization-security families by
role. Reuse already-inventoried GPTQ, compression, and MDL sources. Treat every
external performance, error, or security result as source-reported until an
accepted local reproduction exists.

**Implementation and evidence backlog.** Define versioned
`PrecisionContract`, `CompleteDescriptionLedger`, `PrecisionFieldPlan`,
`BaseResidualPrecisionBundle`, `PrecisionRouteDecision`, and
`PrecisionCertificate` schemas with rejecting fixtures for omitted protected
slices, hidden codebooks or decoder burden, wrong artifact/runtime/platform,
stale domains, missing fallback, invalid residual order, expired evidence, and
revocation bypass. The independent validator must bind exact identities,
contract metrics and thresholds, complete accounting, route/fallback policy,
evidence scope, expiry, and residual ownership. Formal work may model only the
finite refinement and certificate route; it cannot prove that the selected
contract captures all important behavior.

**Competence gate before empirical interpretation.** A naïve quantizer, weak
average-accuracy probe, broken positive control, uncanonicalized salience rule,
or under-tuned router cannot refute the proposal. Freeze protected behavior and
maximum inference; give static, layer-wise, mixed, progressive, and routed
policies matched tuning and method-specific rescue; include favorable/oracle
checks; retain complete candidate and cost denominators; and use an
independently implemented final evaluator where the claim requires it. Compare
stored and moved bytes, decoder work, latency, energy, memory, verification,
repair, fallback, assurance-generation cost, rare and high-consequence slices,
calibration, abstention, distribution shift, and router attacks together.

The owner-directed prose-only transaction is terminal. Remaining schemas,
validators, external-source resolution, formal work, and empirical work join
the existing-book/evidence lane only after R16-A, W3, and T1D are terminal.
They may not displace P2, consume a third WIP slot, open protected outcomes,
activate Candidate N/O research, or move support. The standalone-chapter
contingency remains inactive pending a dated post-integration coherence audit.

### P6.9 — Round 20 chapter substance and concept fidelity

**Status:** terminal. All twenty-three queued owners are concept-complete at
184/184 passing concepts and current reviewed digests. The raw-scaffold audit
and exact proof/evidence handoff are terminal. Eighteen chapters remain below
the diagnostic word trigger, but that separate diagnostic is not an
acceptance, evidence, or reopening gate. The baseline adjudication is
`docs/round_20_depth_and_substance_reconciliation_2026_07_27.md`; the current
completion authority is
`docs/round_21_depth_contract_and_atom_adequacy_adjudication_2026_07_28.md`.

**Adjudicated baseline.** The review's concrete keyword omissions are stale
against current `main`: Dangerous Capability contains explicit CBRN and
biological/chemical treatment; Content Authenticity contains deepfake and
current EU Article 50 treatment; and Societal Resilience contains fraud,
child-safety, incident-reporting, cyber, bio/chemical, manipulation, and
mental-health routes. Its inheritance statistic is also stale: the
authoritative W3 packet reports **812→0 repeated 12-grams** over the
reader-facing/editorial surface and **1,921→925** over the broader raw-QMD
diagnostic.

The atom critique was directionally useful but used the frozen base registry
without all separately versioned addenda. Unified pre-repair coverage was
80/84, not 64/84. The four genuinely uncovered owners were Military AI,
Confidential and Verifiable AI Computation, Human–AI Symbiosis, and Relational
Dimension Compilation. The append-only Round 20 packet gives each one a core,
boundary, mechanism, failure-boundary, and argument-exit atom. Unified
current-manifest atom custody is now **84/84**, with no historical rewrite and
no support movement.

**Accepted depth problem.** Before repair, 23 of 84 tracked chapters were below
the 5,000-word raw-QMD diagnostic trigger; the median was 6,982. Word count
cannot prove clarity or depth, but that distribution exposed a real cluster of
underdeveloped owners. The missing editorial control was a named
concept-by-concept gate, not a higher global word target.

Every active concept manifest must therefore name:

1. the concept and canonical owner;
2. the mechanism or causal/operational route;
3. the failure mode and strongest relevant challenge;
4. an explicit non-claim;
5. the contribution and limit of sources already declared by the chapter;
6. the adjacent-owner handoff and reader decision value; and
7. a chapter-specific semantic reviewer disposition.

The placeholder-rejection gate requires a named section, at least 150 words, and separate
`Mechanism`, `Failure mode`, `Non-claim`, and `Source grounding` statements.
Those checks reject obvious placeholders; they do not complete a concept.
Completion requires a chapter-specific semantic disposition bound to the exact
QMD SHA-256. Any prose change invalidates that disposition until the chapter is
reviewed again. Padding, repeated stack admissions, generic governance
language, source-count inflation, and moving prose between files cannot close
a concept.

The Round 21 validator correction makes that rule real: a concept-complete,
digest-reviewed chapter remains complete when a diagnostic word-count fixture
is moved below 5,000, while missing concept roles, missing source grounding,
stale review digests, and support movement still reject. Word count schedules
inspection; it does not decide completion.

**First tranche.** Dangerous Capability Domains and Misuse Uplift, Content
Authenticity, Watermarking, and Synthetic-Media Integrity, and Societal
Resilience and Misuse Defense now contain substantive treatment for all 24
named priority concepts. Each exceeds the diagnostic trigger; 24/24 concept
contracts pass; all source engagement stays inside the declared queues; and no
claim support, release, safety, legal, or deployment conclusion moves. This
reduces the diagnostic-thin queue from 23 to 20.

**Second tranche.** Scientific Discovery, Governed Objective Formation,
Durable Semantic Memory, AI Deployment and Transition, Autonomous Replication,
and Human–AI Communication now contain 48/48 passing owner-specific concept
contracts and six current exact-digest semantic dispositions. Their concepts
map to existing bounded owner atoms with explicit many-to-one rationales where
one proposition legitimately owns several editorial concepts; no atoms were
manufactured to mimic an older chapter's count. All six remain below the
5,000-word diagnostic trigger, which is expected and has no completion effect.
The contract therefore reports nine concept-complete chapters, 72/72 passing
concepts, nine current semantic reviews, twenty diagnostically thin chapters,
and fourteen owners still awaiting concept completion at that checkpoint. No
support or release state moved.

**Third tranche.** Adversarial Machine Learning, Open-Weight Release, Physical
Compute Infrastructure, Institutions and International Coordination,
Multi-Agent Dynamics, and Military AI now add 48/48 passing owner-specific
concept contracts and six current exact-digest semantic dispositions. The
contract therefore reports fifteen concept-complete chapters, 120/120 passing
concepts, fifteen current semantic reviews, twenty diagnostically thin
chapters, and eight owners awaiting concept completion. The new prose preserves
source-specific ceilings, fair evaluator competence, affected-party and
residual ownership, and argument-only support; no support or release state
moved.

**Fourth tranche.** Perception and Observation Trust, Human–AI Symbiosis,
Relational Dimension Compilation, Learning Theory, Confidential and Verifiable
Computation, and Embodied Agency now add 48/48 passing owner-specific concept
contracts and six current exact-digest semantic dispositions. Their prose
separates mechanisms from failure modes, non-claims, and bounded source roles;
their existing atoms are reused only where a composite proposition preserves
independent falsification and promotion boundaries. The contract therefore
reports twenty-one concept-complete chapters, 168/168 passing concepts,
twenty-one current semantic reviews, twenty diagnostically thin chapters, and
two owners awaiting concept completion. No support, release, safety,
deployment, SOTA, AGI, or ASI conclusion moved.

**Final tranche.** Inner Alignment and Human–AI Organizations now add the final
16/16 passing owner-specific concept contracts and two current exact-digest
semantic dispositions. Inner Alignment separates target, actual learning
signal, policy, compatible objective hypotheses, internal optimization,
capable goal shift, evaluation awareness, evidence independence, mitigation
hiding, opportunity, expiry, and descendant custody. Human–AI Organizations
separates charter and standing, operational role capacity, decision rights,
delegation, duty separation, incentives, longitudinal contribution and
dependence, accountability and remedy, and succession or dissolution. Their
sources retain exact conceptual, constructed, empirical, formal, framework,
jurisdictional, and authorial ceilings. The contract therefore reports
twenty-three concept-complete chapters, 184/184 passing concepts, twenty-three
current semantic reviews, fifteen diagnostically thin chapters, and an empty
concept-completion queue. No support, release, safety, deployment, SOTA, AGI,
or ASI conclusion moved.

**Terminal preservation order and throughput.** Preserve all twenty-three repaired owners
at their reviewed digests. Throughput remains digest-bound concept
dispositions, not chapters touched, cycles consumed, headings added, or words
written. Any later prose edit invalidates the affected semantic disposition.
The concept queue is closed. Reopening requires digest drift or an explicit
successor amendment; crossing the diagnostic word trigger cannot reopen or
re-close it.

**Atom adequacy.** Unified owner coverage remains 84/84, but a presence bit is
not adequate decomposition. The current low-count diagnostic contains nineteen
chapters at five or fewer atom references, nine of them at one. Do not target
legacy atom-count parity. For each concept tranche, require every material
claim-bearing concept to map to a bounded atom with owner, proposition, scope,
falsifier, promotion ceiling, evidence route, failure boundary, non-claims,
and consumer handoff, or record a many-to-one justification showing that
independent falsification and promotion are preserved. Split only where claims
can mature or fail independently.

**Raw scaffold ownership — terminal.** Preserve W3's terminal reader-facing result:
repeated editorial 12-grams, exact editorial blocks, repeated diagrams, and
repeated Codex-test tables are all zero at their frozen thresholds. The current
raw-QMD diagnostic is 925 repeated 12-grams with maximum spread 64, not the
review's stale 1,117 / 82-of-84 result.
`evidence_quality/p6_9_raw_scaffold_ownership_audit.json` classifies all
**21** maximum-spread fingerprints by exact normalized-text digest and exact
64-chapter-set digest. All 21 occur only inside generated manifest-source
reconciliation projections owned by
`scripts/sync_chapter_source_crosswalks.py`; zero are reader-visible and zero
are unjustified. The copied reader-facing scaffold fixture still rejects.
Necessary generated repetition remains distinct from inherited reader prose.
The terminal exit result is **zero unjustified widest raw blocks**.

**Chapter-count policy.** Freeze the manifest at 84. A new chapter is not an
escape from thin prose. Structural admission remains closed until the
concept-completion queue is zero or terminally justified and
all 84 owners retain exact atom custody. A later owner may enter only through the roadmap's full
distinct-owner, source, competence, birth-artifact, reader-value, and
non-displacement gate.

**Evidence handoff and exit — terminal.**
`evidence_quality/chapter_substance_contract.json` reports 84 exact owners and
84/84 atom custody; every queued owner has a terminal concept
disposition; every accepted repair has a current digest-bound semantic
review; every material concept is atom-addressable or has a justified
many-to-one mapping; the raw-scaffold audit has no unjustified widest block;
and W3 remains terminal.
`evidence_quality/p6_9_proof_evidence_handoff.json` now preserves exact
chapter, concept, atom, source, falsifier, evidence-lane, maximum-inference,
and unresolved-challenge identities for **184 concepts across 23 exact current
chapter digests**, with zero missing identities. The packet is deterministic,
schema-validated, raw-audit- and W3-bound, and registered as a PR gate. It
activates no campaign and moves no support or release state. These receipts
close P6.9; a word-threshold or atom-count change cannot substitute for them.
Passing this editorial program still establishes no empirical, formal, safety,
release, SOTA, AGI, or ASI result.

### P6.10 — Complete Corben paper section-family closure

**Status:** terminal for the currently accessible corpus; maintenance reopens
per affected source family. The 2026-07-31 fidelity campaign closes all 46
locally readable canonical Corben paper texts: thirty-seven cached Google Docs
exports, seven supplied Markdown whitepapers, and two authenticated Drive
Markdown papers recovered in the TreeLLM-successor search. Paired DOCX files,
repeated tabs, pocket/summary editions, and copied paper blocks are variants,
not independent evidence.

The same campaign then closed seven authenticated connector records under a
separate machine ledger: `moecot`, its non-independent `moecot_md` export,
`coilmoecot`, `temporal_coil_research`, and the newly admitted
`capability_ratchet_whitepaper`, `attd`, and `orcp_moecot`. Three new inventory
records move the public-safe total from 465 to 468. The complete connector text
was section-audited without publishing the private raw documents or promoting
their source-reported implementation and empirical statements.

The authoritative synthesis is `docs/source_mining_synthesis.md`; the local and
connector ledgers are `sources/corben_paper_corpus_closure.json` and
`sources/corben_connector_source_closure.json`; the exact ignored bytes behind
the local ledger are bound without publication by
`sources/corben_raw_source_receipts.json`; and each source has a public-safe
note under `sources/source_notes/`. Local validation checks each receipt
against the private cache, while CI checks the tracked receipt and closure
topology. A receipt establishes byte identity only. Closure means that every
substantive section, appendix, variant, formal object, algorithm, interface,
state machine, implementation stage, threat, failure, limitation, baseline,
falsifier, and cross-paper tension ends in exactly one disposition:

1. integrated into its canonical existing chapter;
2. retained in the source note because book prose would duplicate or overload
   the owner;
3. converted into a concrete implementation, research, or evaluation
   obligation; or
4. recorded as an explicit non-claim, superseded variant, or rejected
   overreach.

The local-corpus packet adds material manuscript repairs from the final
legacy wave: bidirectional claim-to-surface release coverage; architecture-
induced moral-risk review and copy-continuity boundaries; a non-compensating
alignment vector; hardware-profile and maintenance-learning contracts; a
temporal-access contract; per-bottleneck simulation feasibility; and layered
instruction identity. Other recovered mechanisms already had stronger owners
and were closed in their notes without branded duplication.

The connector follow-up adds ATTD repository-health governance to Artifact
Steward Agents, ORCP decoder symmetry and total-rate discipline to Compact
Generative Systems, separate benchmark/procedural/structural ratchets to the
benchmark and RSI path, exact inconclusive Temporal Coil outcomes to
Mathematical and Search Substrates, and bounded negative-signal specialists to
Routing Heads. No new chapter is warranted because each mechanism has a clear
existing owner.

The final four large legacy families are no longer a queue. TokenMana separates
regenerative infrastructure hypotheses from human temporal-access effects and
retains its mathematical and causal gaps. Simulation Scaling keeps contracts
and typed physical bottlenecks while demoting its scalar equation from
universal law. BugBrain's fifteen-tab paper history is reconciled to the
stronger pinned implementation dossier, with machine evidence outranking
narrative completeness. Software Magic Grimoire's full lexicon, pocket edition,
stack addendum, and prompt pack are treated as vocabulary/templates, not
performance evidence; only the durable instruction and workflow contracts are
integrated.

Completion does not imply exhaustive external literature coverage, truth of a
Corben paper, independent corroboration, or support-state movement. Connector-
only notes, inaccessible Drive variants, and local project repositories keep
their own access and evidence classes. A readable member can keep a family
usable, but cannot prove that an inaccessible sibling contains no distinct
correction.

**Maintenance trigger and order.** When a paper changes, an inaccessible
variant is recovered, a new paper appears, or an owning chapter materially
changes, reopen only the affected family. Read the new material completely,
diff the intellectual system rather than filenames, refresh the note's version
lineage and section-family table, inspect actual chapter prose, update inventory
and exact mappings, reconcile claims/research residuals/public counts, run the
registered source and book validators, render the 84-chapter edition, and
commit/push clean `main`. A title, citation, source-note file, source count, or
chapter assignment is never an acceptable substitute for this closure test.

## P7 — Reader remediation and owner-authorized publication

The first Round 15 publication transaction is complete. The
`reader-2026-07-18` GitHub Release publishes exact PDF, EPUB, and DOCX assets
from release-metadata commit `0921a92484cd2a429790f180a4d3ce7bd304446b`.
All three public assets were redownloaded and matched their approved local byte
counts and SHA-256 digests. The machine manifest is
`editions/reader_manuscript/reader_2026_07_18/manifest.json`; the exact release
record is `release_records/2026-07-18-reader-2026-07-18-0921a924.json`; and the
public release is
<https://github.com/corbensorenson/asi-stack-book/releases/tag/reader-2026-07-18>.
It is deliberately not marked latest, makes no new license grant, changes no
support state, and does not replace canonical living-book release `v2.3.0`.

The released PDF repairs the confirmed clipping/overflow defects and passed a
923-page raster audit plus review of all 20 contact sheets. The released DOCX
passed a 737-page LibreOffice raster audit plus all 16 contact sheets. The EPUB
passed ZIP, spine, navigation, chapter/appendix coverage, and text checks. The
remaining gates are compatibility claims, not retroactive publication claims:
the PDF remains untagged; the EPUB still needs native-reader and
assistive-technology review before any such compatibility or accessibility
claim; and the DOCX still needs Microsoft Word inspection before any
Microsoft-Word-quality claim. Preserve exact before/after evidence and the
approved local HTML history.

Continue browser, keyboard, accessibility-tree, contrast, link, and responsive
checks over every page. The X Article header retains canonical local alt text;
recheck whether X exposes a header-description control before publication.
Claim-identity, negative-result, or material source changes trigger synopsis and
reader-derivative reconciliation.

### P7.1 — Narrative synthesis and editorial compression

The active form of this lane is the metadata-first `P7.1-EM` editorial product
migration defined above.

The evidence roadmap must improve the book as a book, not only as a registry.
Run the case-independent `P7.1a` edit as soon as its chapter-by-chapter audit is
frozen; after `T4` produces a stable case, complete the flagship-dependent
`P7.1b` edit before a new major reader release. Together the two lanes enforce
these gates:

- state the thesis, three defended contributions, strongest evidence, and
  largest unresolved risks in a short opening map;
- classify chapters as thesis-bearing, load-bearing reference, implementation
  case, or speculative/deferred research so breadth is not mistaken for equal
  evidentiary weight;
- thread the `ASI-THESEUS-FLAGSHIP-01` happy, blocked, and rollback cases through
  the reader spine; a chapter either advances the case or remains an explicitly
  optional reference chapter;
- remove repeated governance/evidence disclaimers, duplicated mechanism
  introductions, and status boilerplate from the narrative source, targeting a
  120,000–180,000-word human technical book (roughly 50–70% shorter than the
  reference) while the crosswalk preserves every major conclusion and the
  reference preserves every unique claim, caveat, source, equation, protocol,
  proof boundary, and non-claim;
- give each defended contribution one strongest alternative explanation,
  simpler baseline, failure case, and exact evidence still needed to change the
  conclusion;
- keep formal results only where a plain-language proposition, countermodel,
  runtime consumer, and maximum inference justify the reader cost; and
- refresh the overview diagram, glossary, chapter handoffs, and final synthesis
  so a technical reader can recover the architecture and evidence hierarchy
  without consulting roadmap history.

Word-count reduction is a diagnostic, not the acceptance test. The gate is a
meaning-preserving editorial diff, reader-spine validation, broken-link and
cross-reference checks, and a chapter-by-chapter record of what was merged,
moved to reference material, or retained because it changes the argument.

The independently authored narrative is a parallel maintained source, not a
temporary filter over the research graph. Its superseding 26-unit coverage
crosswalk is a conclusion-preservation invariant, not a requirement to carry
every legacy owner's local contract into prose. The current 22-unit candidate
remains historical input until EM4 cutover. A 25,000–40,000-word primer is
downstream of the stable narrative and must not become a second simultaneous
rewrite lane.

The gates split into two lanes. **P7.1a — case-independent editorial
compression** (repeated disclaimer and status-boilerplate de-duplication,
duplicated mechanism-introduction merges, chapter-role classification,
glossary, handoff, and overview refresh) has no dependency on the flagship
case and may run at any checkpoint under the same meaning-preserving diff and
validation gates. **P7.1b — flagship threading and final synthesis** (the
opening map's strongest-evidence claims, the happy/blocked/rollback case
spine, and the closing synthesis) waits for `T4`. Running P7.1a early must
not pre-commit P7.1b's structure, and neither lane may delete a unique claim,
caveat, source, equation, protocol, proof boundary, or non-claim.

The 2026-07-19 chapter-overlap audit remains evidence that the pre-tranche
chapters were not textual duplicates: its maximum pairwise tf-idf score was
0.298. The final editorial audit supersedes the inference that textual
distinctness requires equal standalone publication status. `P7.1-EM` therefore
tests the 18 named semantic merges at the object/transition/failure/consumer
boundary while using the low similarity result as a guard against mechanical
concatenation. The measured prose repetition still defines these P7.1a work
items:

1. **Template-block centralization.** The W1 historical receipt reproduced
   1,142 qualifying 12-grams in its frozen 55-chapter baseline and 727 after
   edits, a 36.34% reduction; the earlier planning estimate of 1,364 is not an
   audited result. Its widest surviving compact labels and methodology link
   still spanned all 55 chapters. State invariant methodology once in a single
   front-matter/methodology surface, keep only chapter-specific applications
   locally, and let validators—not repeated prose—carry invariant guarantees.
2. **Opening-formula variation.** Chapter openings reuse a small number of
   sentence templates ("This chapter treats X as Y, not Z"; "The consolidated
   X layer remains conceptual"). Rewrite openings so each chapter leads with
   its own subject and stakes while preserving every non-claim boundary.
3. **Consolidation-residue repair.** At least `virtual-context-abi` and
   `intent-to-execution-contracts` open with retired-chapter bookkeeping
   ("archived under `archive/retired_chapters/`") before their subject. Move
   merge lineage to a chapter-end provenance note in every affected chapter.
4. **Boundary coverage independent of chapter admission.**
   `epistemic security` and `gradual disempowerment` currently appear in zero
   chapters. Add a named epistemic-security/persuasion-defense section to
   `scalable-oversight-and-adversarial-ai-control` (or
   `adversarial-evaluation-sandbagging-and-training-time-deception`) and a
   named gradual-disempowerment section to
   `failure-modes-of-ungoverned-intelligence`, each with sources, atoms, and
   explicit non-claims. The persuasion sections remain required whether the
   end-to-end Human–AI Communication candidate is admitted or rejected.
5. **Thesis-chapter depth-leveling.** The two thesis-bearing chapters
   (`asi-is-a-stack-not-a-model`, `the-efficient-asi-hypothesis`) and
   `failure-modes-of-ungoverned-intelligence` are among the six shortest
   chapters while carrying the book's central claims; level them upward toward
   the spine's evidentiary and argumentative density without padding.

**P7.1a-W3 — prospective inheritance guard** reopens neither W1 nor W2. Its
2026-07-26 terminal receipt creates the current-84-chapter baseline and
admission-time negative control. The exact tokenizer, corpus, thresholds,
widest-block report, centralized replacements, semantic-diff review, and
copied-template rejection fixture are committed together. A percentage
reduction remains diagnostic; acceptance comes from one invariant-method owner,
local unique chapter meaning, and prospective rejection of the removed
scaffold.

### P7.1c — Reader-first concreteness, prose, and surface discipline

The owner-supplied Round 23 reading review found a material gap that the
existing atom, source, proof, and repetition audits do not measure: the book's
ideas are stronger than the reader's experience of them. The review praised
the noninheritance law, three-projection device, efficiency denominator
analysis, and willingness to state falsifiers, but found that mechanism prose
often reads like schemas in sentence costume. It specifically called out the
scarcity of concrete scenes and worked traces, long enumerations and
mega-sentence claims, over-distributed disclaimer language, the quarantining
of the Human Reading Path voice, and bookkeeping tables interrupting the
argument.

The reported corpus counts (approximately 640,000 words, ten “for example”
uses, no “for instance,” three “worked example” uses, one “case study,” and
about 820 disclaimer phrases) are review signals, not project facts. The
reconciliation packet `docs/round_23_reader_prose_quality_reconciliation_2026_08_02.md`
requires a pinned phrase taxonomy and role-normalized baseline before any
number is used as an acceptance target. Its machine status is
`roadmap_records/p7_1c_reader_prose_quality_status.json`.

Claude's later chapter-by-chapter scan is preserved at
`docs/chapter_content_triage_2026_08_08.md`. It covers all 85 chapter files and
supplies a reproducible five-signal ranking plus a named suggestion for every
chapter. P7.1c accepts its semantic findings but not its raw score as closure:
phrase markers may miss real traces, source-count and prose-ratio thresholds
are diagnostic rather than normative, and distinct caveats may not be deleted
to lower hedge density. Digest-bound editorial review remains the authority.

The 2026-08-02 calibration tranche edited the canonical live sources
for `asi-is-a-stack-not-a-model`, `the-efficient-asi-hypothesis`,
`failure-modes-of-ungoverned-intelligence`,
`inner-alignment-mesa-optimization-and-learned-objective-integrity`, and
`claim-ledgers-and-belief-revision`. Each adds an illustrative opening failure,
a state-labelled trace, and a simpler baseline or counterexample. These are
reader aids, not empirical results; the inner-alignment digest was re-reviewed
under the existing concept contract with no support effect. At that point the
tranche was intentionally not called 85/85 completion. The 2026-08-09 closure
below supersedes that intermediate state.

The 2026-08-08 anchor, weak-score, and calibrated-scene tranche began with forty-four digest-bound packets under
`evidence_quality/reader_prose_quality_packets/`. Project Theseus now walks an
actual public-safe artifact-retention validation; Integrated Reference
Architecture opens with the executed nine-scenario repository-change failure;
Resource Economics walks its four-route synthetic cost ledger; adversarial ML
compares three source-reported attack outcomes without inventing a scalar;
CoilRA carries one 128-channel block-cyclic receipt from diagnostic acceptance
to adoption refusal; Circle gives one proof receipt to two consumers; Compact
Generation exposes the KERC `714.0`-versus-`73.25`-byte negative result and its
competence boundary; Autonomous Replication shows why a complete authored
dossier authorizes only a campaign; and the Open Research Agenda records an
explicit reference-chapter intake trace. All nine separate readable and
normative projections from their retained formal claim.
The five previously edited calibration chapters—Stack Thesis, Efficient ASI,
Failure Modes, Inner Alignment, and Claim Ledgers—now also have current packets
that bind their existing illustrative scenes, state traces, simpler baselines,
reader rules, and formal anchors without adding support.
Nine additional chapters with already substantive reader scenes now have the
same custody: Adversarial Evaluation, Capability Commitments, Governed
Deliberation, Fast Generation, Inter-Stack Exchange, Model-Weight Custody,
Moral Uncertainty, Open-Ended Improvement, and Scalable Oversight. Their packets
distinguish illustrative scenes from the real P4/M6 deliberation result and
other bounded fixture evidence rather than laundering all examples into one
evidence class.
The next substantive pass adds four reader-visible decisions from existing
machine evidence: identical local multi-agent permissions with opposite
concentration outcomes; a three-minute rented GPU rejected in favor of an
eligible fifteen-minute home device; an SCF candidate qualified for canary but
blocked from default; and an artifact steward probe whose valid routes prepare
work, release review, or sunset without executing protected effects.
The following five weak-score owners now carry the same treatment from their
existing evidence: an unbound composite that preserves one credentialed
ingredient without authenticating the whole asset; a lossy ontology migration
that invalidates its memory consumers; a SCIF commit probe that permits a
sanitized refusal while blocking six malformed routes; a societal incident
whose provider service is restored while three affected paths stay open; and a
model canary whose passed prechecks give way to monitor-triggered rollback with
irreversible trace residuals.
The next three turn one communication lease, one substrate-adoption trace, and
one objective lease into reader-facing decisions: unchanged wording is blocked
when audience or repetition exceeds its lease; the same coil candidate moves
through exploratory, structural-only, blocked, and retired dispositions by
claim axis; and the same preference or proxy signal cannot manufacture
objective authority when the consumer or version scope changes.
Three human-and-world boundary chapters follow: a 5/9/8 human-AI comparator
rejects one-sided synergy before longitudinal custody begins; a public-safe
military simulation loses meaningful judgment when time or off-ramps shrink
even though its approval interface remains; and two agreeing sensor roots
receive opposite global dispositions when an unrepresented common cause is
present.
The next three expose result non-cancellation across social, learning, and
operational layers: a positive-90 deployment aggregate remains blocked by one
unremedied cohort; fifteen inventory-exact rollbacks coexist with no useful
update and zero storage erasures; and one commit-bound Pages deployment joins
source, tested artifact, public effect, and post-deploy observation without
becoming a prospective incident-control result.
Three evidence-admission owners follow: two workloads exactly exhaust six
physical capacity axes while hidden backup energy invalidates impact
accounting; a useful prototype artifact stays research-only until typed
dependencies and gates authorize integration; and positive, null, and
inconclusive scientific attempts remain in one denominator under an unopened
confirmatory branch.
The 2026-08-09 closure extends that contract to all 85 canonical chapters.
Every chapter now has a current reader claim, operational rule, worked scene or
justified existing trace, simpler baseline, formal binding, caveat disposition,
and maximum-inference boundary. All 85 Human Reading Path blocks also carry a
unique Concrete lens; the audit records 85 unique lenses and zero exact block
duplicates. The packet validator rejects stale digests, generic scenes, wrong
reader roles, erased limitations, unsupported examples, and headings absent
from the chapter. This is 85/85 editorial custody with no support or release
movement. The closure audit is
`docs/reader_prose_quality_closure_2026_08_09.md`.

P7.1c is an existing-owner editorial repair, not a chapter-admission lane. It
does not reopen the 85-chapter manifest, change support, or displace P2. Each
chapter receives a digest-bound prose-quality packet with five obligations:

1. Open with a 150–250 word chapter-specific failure, decision, or discovery
   scene that names the actor or system, attempted action, observable outcome,
   failed boundary, and residual owner. A thin reference or speculative
   chapter may use a bounded domain vignette, but may not substitute a generic
   schema restatement.
2. Follow the scene with one state-labelled worked trace, one counterexample
   or strongest simpler baseline, and a chapter-specific handoff. The trace is
   explanatory unless its evidence lane independently makes a measured claim.
3. Convert field-by-field mechanism lists into four or five prose groupings;
   split every mega-sentence core claim into a readable claim, normative rule,
   and separately addressable formal binding. Preserve all atom, source,
   equation, protocol, proof-boundary, and non-claim links in Appendix C or a
   stable detail surface.
4. Keep one local caveat where a reader needs it and consolidate repeated
   limits into a chapter-level “what this does not establish” block. A pinned
   role-normalized audit flags density outliers; editorial review must preserve
   every distinct limitation rather than delete caveats to improve a metric.
5. Move repeated claim/source/status tables off the reading path, and bring the
   direct, agentive register already demonstrated by Human Reading Path blocks
   into the main argument. A paragraph should normally say who or what acts,
   what changes, and why it matters before introducing the schema.

The acceptance gate is **all 85 current-manifest chapters** with digest-bound packets; concrete scene,
worked trace, counterexample, readable/formal claim projections, role-normalized
caveat audit, reader-surface audit, semantic diff, link/render/browser/
accessibility checks, and adversarial editorial fixtures must all pass. No
word-count increase, appendix dump, or generic vignette can close the lane.
Changed QMD content invalidates its packet. The prose packet closes before
the manifest-derived video narration briefs are reconciled so visual scripts inherit the
concrete cases and state transitions rather than the old paragraph-tableau
style. No external prepublication reader is required; all decisions and
residuals remain in the owner-directed local workflow.

### P7.2 — Structural-tranche reader integration

First close R16-B: derive and validate a current-manifest reader-freshness
packet while preserving `reader-2026-07-18` as immutable publication history.
The packet may end in validated local artifacts or an exact format-specific
deferred disposition, but it may not claim that the historical release already
contains chapters added later.

Complete each P6.3 manifest entry as a real reader chapter rather than an
appendix-shaped registry. Each insertion must update the opening map,
chapter-role classification, adjacent handoffs, overview figure, glossary,
claim/evidence surfaces, source appendix, and final synthesis. Apply the same
integration contract independently to every P6.4 candidate that later passes
manifest admission. Re-run overlap, ownership, source-crosswalk, and reader-
flow audits after the first tranche reaches a terminal disposition and after
each coherent second-tranche insertion; the final chapter count is whatever
the gates earn, not a predetermined 72. If at least three meso-to-societal
candidates pass, this lane must also decide whether a dedicated Organizations,
Institutions, and Societal Transition part improves the reader spine. No
addition may restore boilerplate
removed by P7.1a or present source-derived architecture as local evidence.
After the Round 16 freeze clears, this integration is atomic with admission:
no future chapter may enter the manifest first and acquire atoms, reader
projection, role classification, handoffs, glossary/source/claim mappings, or
template-inheritance checks later.

“Ready, not published” is an honest terminal public-state disposition when
external authority is absent; it is not a reason to block evidence work. At
each checkpoint, record whether each prepared product remains current, has gone
stale, or is explicitly authorized for release. When Corben authorizes an
external action, reconcile the exact `main` commit, source tree, rights route,
citation, archive contents, built artifact, deployed bytes, URL, and
attestation. Publishing one product never forces the others.

For the prepared X Article, reopen draft `2077875347220041728`, reconcile it
against canonical Markdown and its manifest, recheck the top link, 2000×800
header crop, platform alt-description behavior, visible word count, formatting,
and audience, then publish only with explicit action-time authorization.

### P7.3 — Governed Manim visual edition

Create a maintained visual explanation for every canonical chapter without
turning animation quality into evidence quality. The visual edition is a typed
derivative of the live book: chapter prose and claim atoms remain canonical;
scene code, narration, captions, descriptive transcripts, thumbnails, render
receipts, YouTube identities, and Quarto embeds project that state for a
different audience. A video may explain a mechanism, worked trace, failure
mode, proof boundary, or current evidence state. It may not strengthen,
promote, rehabilitate, or refute a claim.

**Target and format.** Produce one current visual abstract for every chapter in
the canonical manifest; never encode the chapter denominator by hand. A normal
abstract is 2.5–4.5 minutes and 280–520 spoken words. More than 600 words
requires a recorded chapter-specific rationale, and more than 650 fails the
script gate. Each abstract teaches one promise through one concrete case, one
mechanism, one test or consequence, and one honest boundary. It may use at
most three new terms and must make the central idea intelligible from the
narration alone without reciting claim IDs, support labels, validator counts,
repository paths, chapter navigation, or repeated administrative boilerplate.
Longer flagship treatments and part compilations are optional derivatives,
not substitutes for complete manifest coverage.

**Toolchain and environment.** Use the stable Manim Community Edition rather
than ManimGL, initially pinned to `manim==0.20.1` in an isolated ARM-native
environment with exact Python, Manim, renderer, LaTeX, font, audio, and codec
identities. The existing broken global Manim/NumPy installation is not an
admissible build environment. Use low-quality preview renders during drafting
and deterministic release-quality settings for accepted outputs. A dependency
upgrade requires a controlled compatibility render of every reusable
primitive and at least the five pilot chapters before adoption.

**Five-pilot ratchet.** Build these representative pilots before the
full-manifest rollout:

1. `asi-is-a-stack-not-a-model` — full-stack composition and cross-layer flow;
2. `capability-replacement-and-rollback` — lifecycle, failure, and exact
   rollback visualization;
3. `context-transactions-snapshots-mounts-and-taint` — typed memory, paging,
   taint, and state-transition visualization;
4. `replaceable-cognitive-substrates-beyond-transformer-monoculture` —
   architecture comparison without substrate or SOTA overclaim; and
5. `living-book-methodology` — claim, evidence, derivative, correction,
   release, and staleness custody.

The pilot ratchet must exercise abstract architecture, stateful animation,
mathematical and technical notation, real artifact boundaries, narration
timing, captions, descriptive transcripts, and responsive book embedding.
Ratify the shared primitives and style contract only after all five render and
pass.

**Reusable visual grammar.** Establish one ASI Stack design system with stable
layer colors, authority/evidence/residual/rollback symbols, typography,
motion-rate limits, safe-area rules, contrast targets, and reusable components
for stacks, DAGs, ledgers, state machines, capability fields, route selection,
proof boundaries, timelines, and before/after state. Reuse grammar, not
chapter-specific conclusions: every chapter must retain its own mechanism,
worked trace, and failure boundary. Motion must never be the sole carrier of
meaning.

**Per-chapter derivative packet.** Every chapter video must have:

- a stable chapter/video ID and current chapter path;
- the exact source commit, chapter digest, covered claim-atom IDs, support
  states, sources, and maximum-inference boundary;
- storyboard, scene code, narration script, reviewed captions, descriptive
  transcript, thumbnail, alt text, and source/citation end card;
- exact toolchain lock, render command, output digest, duration, dimensions,
  frame rate, audio identity, and validation receipt;
- YouTube video and playlist identities after publication, plus the Quarto
  embed location, accessible frame title, and `aria-label`; and
- one lifecycle state from `planned`, `storyboarded`, `scripted`, `rendered`,
  `validated`, `ready_not_published`, `published_current`, `stale`, or
  `superseded`.

The canonical narration script remains independent of the speech engine.
Author-recorded or properly licensed synthetic narration is admissible only
with exact provenance and rights recorded. Synthesize coherent performance
blocks rather than sentence fragments, and qualify a version-pinned word- or
phrase-alignment route before picture-and-sound lock. Automatically generated
captions are drafts; release requires reviewed timing, terminology, equations,
names, non-speech information, and descriptive coverage of material visual
changes. No external-human prepublication review is required, but release does
require a cold reviewer to demonstrate comprehension and transfer without
having read the chapter or authored the candidate.

**YouTube hosting and repository boundary.** YouTube is the canonical host for
published video binaries and the manifest-ordered playlist. The repository
stores the reproducible source and small accountability artifacts; ignored
build space stores local renders. Do not commit MP4, WebM, MOV, partial-frame,
audio-cache, or Manim media directories, and do not copy video binaries into
the GitHub Pages artifact. Quarto embeds a YouTube URL only after the matching
packet is `published_current`; before publication the chapter remains complete
without a broken placeholder player. YouTube upload, metadata mutation,
playlist mutation, publication, replacement, or deletion requires exact
action-time authority and a resulting platform receipt.

The canonical target is the verified **corben sorenson** channel,
`UCX7Tu67cGmKfT6O38xxiQFA`. Preserve a generated all-manifest publication and
revision ledger in book order. Every row binds the stable internal video ID,
chapter and packet identity, current chapter digest, upload generation,
YouTube video and playlist IDs, uploaded render digest, bound source commit,
publication timestamp and receipt, predecessor ID, staleness state, and next
required action. Channel authentication is access evidence, not mutation
authority.

YouTube assigns a new URL to every new upload and does not support replacing a
video binary in place. A material chapter update therefore creates a new
generation and new YouTube ID. Retain the prior generation and platform
receipt as historical evidence; default it to unlisted with a pointer to the
current generation rather than deleting it. Update the canonical playlist
position, packet, ledger, and Quarto embed in one reconciliation transaction.
The old current publication becomes `superseded`; the new generation becomes
`published_current` only after its own final A/V, accessibility, upload,
playlist, and embed receipts pass.

**Staleness and correction.** A changed core claim, mechanism, worked trace,
evidence state, non-claim, material source, chapter identity, handoff, or
public URL marks the video stale. Typographic changes that do not affect
spoken or visual meaning do not. Stale videos remain historical artifacts but
must lose `published_current`; the chapter embed must be removed, labeled
historical, or replaced in the same reconciliation transaction. Each major
book release runs an all-manifest freshness check.

**Rollout order.** Execute foundation and pilot work first, then complete the
remaining chapters in manifest order by part. Work in bounded batches whose
source digests are frozen before storyboarding. A batch closes only after
scene, narration, caption, transcript, evidence-boundary, render,
accessibility, YouTube-readiness, and embed checks pass for every member. Do
not count a scene stub, silent preview, thumbnail, uploaded binary, automatic
caption track, or unvalidated embed as a completed chapter video.

#### P7.3-F1 foundation and first-pilot checkpoint — 2026-07-29

The isolated ARM64 environment is now an exact, validated contract:
CPython 3.12.5, Manim Community Edition 0.20.1, Cairo 1.18.4, Pango 1.58.0,
FFmpeg 8.0.1, a frozen dependency lock, deterministic draft/release profiles,
and an explicit non-LaTeX qualification boundary. The reusable ASI Stack
grammar and primitive gallery render coherently, but the grammar remains
`candidate` until all five pilots validate.

`asi-is-a-stack-not-a-model` is the first complete source packet and current
local draft. Its 284.997-second 854×480/15-fps render was sampled at eight
times across all seven semantic scenes for composition, legibility,
color-plus-shape meaning, evidence ceiling, and end-card non-claims. The
packet binds the exact chapter digest and source commit to its claim, sources,
maximum inference, storyboard, scene code, 699-word narration, 72-cue caption
draft, descriptive transcript, accessible thumbnail, render command, output
digests, and staleness triggers.

The visual-only release profile also passed at 284.999 seconds,
1920×1080, 30 fps, H.264/yuv420p, including two full-resolution visual-review
samples. A qualification run caught that ManimCE 0.20.1 expands `-qh` to
1080p60, so the contract now rejects that shortcut and requires the exact
30-fps configuration.

This checkpoint counts one qualified toolchain contract, one candidate visual
grammar, one present pilot packet, one local draft, and one release-profile
visual render. It counts **zero** validated pilots, final A/V masters, cleared
narration masters, reviewed final caption tracks, YouTube videos, playlist
entries, or Quarto embeds. Close those release gates without laundering the
macOS timing voice into a publishable asset; then complete pilots two through
five before grammar ratification or the 79-chapter rollout.

#### P7.3-F2 five-pilot source and release-visual checkpoint — 2026-07-29

All five representative pilots now have complete, current source packets:
storyboard, chapter-specific scene code, canonical narration text,
deterministically timed draft captions, descriptive transcript, accessible
thumbnail, exact core-claim and assigned-source bindings, maximum inference,
staleness triggers, and zero support-state effect. The four added pilots are
not copies of the first:

- Capability Replacement and Rollback visualizes prospective identity,
  full-state/effect inventory, monitor-triggered rollback, compensation, and
  the `15/15`, `32/36` with `2/36` useful-release, and `35/35` bounded result
  denominators.
- Context Transactions visualizes exact snapshots, purpose-bound mounts,
  non-collapsible commit states, semantic conflict, taint and deletion
  propagation, response-cache taxonomy, and finite fixture limits.
- Replaceable Cognitive Substrates visualizes the typed Cognitive Kernel ABI,
  architecture-family differences, contribution accounting, architectural
  RSI without self-ratification, OneCell defeat conditions, and the zero-run
  heterogeneous-kernel boundary.
- Living Book Methodology visualizes canonical artifact authority, separated
  provenance lanes, claim dependency and validation gates, typed derivatives,
  correction propagation, local lifecycle denominators, and successor
  custody.

Each new scene passed a full-duration 854×480/15-fps draft render and sampled
visual review. Each then passed the exact 1920×1080/30-fps H.264/yuv420p
release-visual profile, with durations of 284.994, 299.965, 299.961, and
299.966 seconds respectively. Review caught and repaired two concrete visual
defects before custody: a missing monitor card caused by competing animations
and an evidence-boundary/end-card overlap. Local Samantha timing tracks at a
recorded 190-wpm setting were muxed only for pacing review; their publication
rights remain expressly uncleared and the media remains ignored.

The canonical visual manifest therefore reports 84 chapters, five present
packets, five `rendered`, seventy-nine `planned`, zero validated final A/V
masters, zero YouTube publications, and zero current Quarto embeds. The
five-pilot ratchet is **source- and release-visual complete but not validated**.
The visual grammar remains `candidate`. The next legal work is to qualify a
reproducible rights-cleared narration path, create and listen-review each
pilot's final master, retime and review its caption track against that exact
audio, mux and validate final A/V, and only then ratify or revise the grammar.
No upload, playlist mutation, publication, or embed may occur without exact
action-time authority.

#### P7.3-F3 YouTube access and revision-custody checkpoint — 2026-07-29

Authenticated YouTube Studio dashboard access is verified for the
**corben sorenson** channel, ID `UCX7Tu67cGmKfT6O38xxiQFA`. This was a
read-only identity check: zero videos, playlists, metadata fields, privacy
states, or embeds were mutated. The canonical playlist therefore remains
uncreated and the honest publication count remains zero.

The repository now owns an exact channel contract and a generated 84-row
YouTube ledger. The ledger covers planned chapters as well as present packets,
so every canonical chapter already has a stable internal video identity and a
specific next action. Published generations must additionally bind their
YouTube ID and watch URL, playlist ID, uploaded output digest, chapter digest,
source commit, publication time, receipt, and predecessor. Validation rejects
channel drift, stale ledger inputs, generation/receipt omissions,
uploaded-versus-rendered digest mismatch, and publication/embed disagreement.
This closes access discovery and revision-custody design; it does not close the
five pilots' final narration, final captions, final A/V, upload, playlist, or
publication gates.

#### P7.3-F4 validated five-pilot ratchet and autonomous-production checkpoint — 2026-07-29

The local narration path is now an exact, reproducible contract rather than a
timing aid. Synthesis uses `kokoro-mlx==0.1.2`, the Apache-2.0
`mlx-community/Kokoro-82M-bf16` model at revision
`a71e4d38b236d968966a2002c4c895dbd12b1c3c`, the digest-bound `af_heart`
voice, speed 1.08, 24 kHz mono PCM masters, and FFmpeg loudness normalization.
Verification uses `mlx-whisper==0.4.3` with
`mlx-community/whisper-small.en-mlx` at revision
`52a88bf6e98b114a210c21bb83e22d6e1505cb73`. Both models, virtual
environments, ASR output, raw audio, and MP4 masters remain ignored.

The transcript gate is outcome-bearing. Its first Living Book Methodology
candidate omitted a complete sentence despite a superficially valid audio
file and receipt. The candidate failed at 7.73% content-normalized word error.
The synthesis ceiling was therefore reduced from 420 to 300 characters, exact
segmentation settings were added to every narration receipt, and all five
pilots were rerendered rather than grandfathering earlier passes. The final
content-normalized error rates are 0.71%, 1.22%, 2.36%, 1.08%, and 1.33%;
every master also passes complete beginning/end coverage, finite mono samples,
no clipping, and the three-to-six-minute duration contract.

All five exact narration receipts now generate canonical WebVTT timing without
placing pronunciation-only substitutions in caption text. Final A/V masters
pass 1920×1080, 30-fps H.264/yuv420p, 48-kHz mono AAC, caption ordering and
span, narration/master duration, ignored-build custody, and digest checks.
Sampled final frames preserve the reviewed chapter-specific mechanisms and
the shared color-plus-shape semantics.

The canonical manifest therefore reports five `validated` packets and
seventy-nine `planned` chapters. The five-pilot ratchet is complete, the
shared visual grammar is `ratified`, and the narration path is
`qualified_for_all_chapters`. This checkpoint authorizes autonomous local
production in manifest order; it does not authorize YouTube, playlist,
metadata, publication, or embed mutations. Those counts remain zero until
exact action-time authority and platform receipts exist.

#### P7.3-F5 all-chapter local-production and visual-review checkpoint — 2026-07-29

Autonomous local production is complete for all 84 canonical chapters. Every
packet has current storyboard, scene source, narration, reviewed WebVTT,
descriptive transcript, editable SVG thumbnail, render receipt, exact chapter
and source-commit binding, and zero support-state effect. The 79 non-pilot
chapters use the ratified data-driven seven-scene grammar; the five pilots
retain their chapter-specific visual implementations.

All 84 Kokoro masters pass the pinned MLX Whisper outcome gate. Durations span
227.765–331.005 seconds, content-normalized word error spans 0–2.8658%, and
the largest contiguous expected-token omission is four against the frozen
ceiling of eight. The final-master validator accepts exactly 84/84 H.264,
1920×1080, yuv420p, 30-fps videos with 48-kHz mono AAC, complete caption span,
matching narration duration, ignored-build custody, digest-bound mux receipts,
and seven scene endpoints within one frame. Two initial global-rounding edge
cases failed the scene gate and were rerendered from exact source endpoints;
the gate was not relaxed.

Human-visible QA covers 588 exact scene-midpoint frames across 21 bounded
contact sheets plus all 84 upload thumbnails. Review found that the first
sampler used arbitrary whole-video percentages and could land inside a
transition; the reviewer was corrected to derive one midpoint from each exact
narration scene in the mux receipt, all frames were regenerated, and the
complete sweep then passed for population, order, legibility, clipping, and
end-card integrity. The final masters total 1,015,153,522 bytes in ignored
local storage and remain absent from Git and the Pages artifact.

The manifest and publication ledger therefore reported 84/84
`ready_not_published`, zero platform objects, zero playlist entries, zero
publications, and zero embeds under the original technical contract. Later
integrated owner review found that this contract did not measure whether a
substantive spoken idea received a contemporaneous, explanatory visual
change. P7.3-F9 therefore reopens local authoring and pedagogical review while
preserving the exact technical receipts as historical generation-one
artifacts. Platform publication now follows, rather than precedes, the new
pedagogical ratchet.

#### P7.3-F6 publication-transaction preflight and self-staleness repair — 2026-07-29

The exact publication input set is now frozen as 84 master/caption/thumbnail
triples. A tracked preflight binds every path, digest, byte count, chapter
position, the 1,015,153,522-byte master total, and the still-false external
mutation authority. It also binds immutable exact mutation scope
`3f901ca06169b3df555b6e8dbc6a327c6dab9e623b6712407cf0a9366eeb55f0`:
the intended channel and upload plan, allowed platform and repository changes,
prohibited unrelated or destructive changes, duplicate-prevention rule, and
mandatory stop conditions. Preparing that scope is not authorization; Corben's
action-time approval must point to that exact digest. The preflight records two
honest execution routes from current
official YouTube constraints: six signed-in Studio batches of
15/15/15/15/15/9, stopping without duplicate uploads on any channel-specific
daily limit; or a verified OAuth/Data API project using resumable uploads and
at least five default-quota days to complete videos, ordered playlist items,
84 thumbnails, 84 caption tracks, and final privacy transitions. An unverified
API project that forces uploads private is not a publication route.

Each completed platform object must receive a schema-valid receipt binding the
exact authorization-scope digest, adapter, channel, video and watch identities,
playlist and ordered item identities, local master and chapter/source-commit
digests, metadata hashes, reviewed caption track, thumbnail, HD processing,
embeddability, public reachability, and zero support or claim-release effect.
The repository reconciler accepts only one complete 84-receipt set with unique
video IDs, playlist-item IDs, and positions. Its write path snapshots every
packet, canonical chapter, manifest, channel contract, and ledger and restores
that snapshot if generation, embed synchronization, or validation fails.

The chapter-freshness contract now hashes canonical manuscript content with
the generated managed visual block excluded. Inserting or replacing the
YouTube player and adjacent transcript therefore cannot make its own packet
stale, while any material chapter change outside that exact block still
changes the digest. Both behaviors are validator probes. Clean CI can verify
the tracked preflight row-by-row without the ignored 1 GB media cache; the
local preflight additionally rehashes every master, caption, and thumbnail.

This checkpoint creates no YouTube object and grants no mutation authority.
The observable state remains 84/84 `ready_not_published`, zero playlist
entries, zero publications, and zero embeds. Exact action-time authority is
still required before the signed-in Studio transaction begins.

#### P7.3-F7 generation-two preservation and supersession custody — 2026-07-30

The update path is now executable before the first publication. Packet
regeneration no longer replaces a published YouTube projection with a blank
unpublished projection. It preserves the latest video, playlist, generation,
receipt, upload, chapter, and source identities as a `stale` predecessor and
removes only the managed current-embed projection. This closes the failure
mode in which local regeneration could silently lose custody of a still-live
public derivative.

The generated ledger now derives each chapter's append-only generation history
from immutable `generation-N` platform receipts. It rejects a missing
generation, duplicate video identity, broken `supersedes_video_id` chain, or
disagreement between the latest receipt and the packet's current projection.
A material update is therefore a new generation, not an in-place overwrite or
an edit that destroys historical provenance.

One exact supersession plan owns each generation-two-or-later transaction. It
binds the stale predecessor receipt; validated replacement master, caption,
thumbnail, chapter, and source digests; exact playlist position; idempotency
key; allowed and prohibited platform mutations; stop conditions; and a
rollback contract that never deletes either video. The plan requires the
replacement to be uploaded once as unlisted and made public only after HD,
metadata, caption, thumbnail, and playlist checks. It then requires the
predecessor to point to the successor, become unlisted, and leave the canonical
playlist. Its file digest is the action-time authorization scope for that
single replacement; generation-one authority cannot be reused.

The generation-N receipt and repository reconciler independently prove the new
public object and the predecessor's final disposition before changing the
packet, ledger, manifest, or Quarto embed. Repository changes are snapshotted
and restored on failure; immutable platform receipts survive, and automatic
rollback never deletes a platform generation. The dedicated validator rejects
12 negative mutations covering generation gaps, identical replacements,
idempotency drift, premature authority, deletion permissions, support
promotion, video-ID reuse, wrong or absent predecessor disposition, private or
deleted predecessors, and receipt overclaim.

This is an implemented non-authorizing maintenance path, not a simulated
successful replacement. Current counts remain zero platform generations and
zero supersession plans. The real generation-two exercise remains downstream
of the authorized complete generation-one publication and Corben's feedback
on one published chapter. It will use a newly prepared plan and new exact
action-time authority, preserve both generations, and create no support-state
or book-claim-release effect.

#### P7.3-F8 owner-authorized twelve-chapter integrated preview — 2026-07-30

Corben explicitly requested that the twelve already uploaded videos be
embedded into the living book for integrated review. That request creates a
narrow projection authority, not permission to fabricate a completed visual
edition or weaken the complete-publication gate. The repository therefore
owns a separate schema-bound `youtube_preview_bindings.json` record rather
than relabeling the chapter packets or manufacturing final platform receipts.

The binding record maps canonical positions 1–12 to twelve unique unlisted
YouTube identities in the private canonical playlist. Every row binds the
planned title, chapter and source-commit digests, exact local-master digest,
local machine-audited WebVTT digest, descriptive transcript, observed
thumbnail state, and the `preview_current` projection state. Videos 1–6 have
their reviewed custom thumbnails applied; videos 7–12 do not. None of the
twelve reviewed local caption tracks is yet attached on YouTube. These open
platform states are shown rather than laundered.

Each bound chapter now contains one managed responsive
`youtube-nocookie.com` player, a visible unlisted-staging notice, a direct
YouTube link, and the complete adjacent descriptive transcript. The landing
page carries a generated canonical-order roster linking to all twelve chapter
players so the staged edition can be reviewed as a coherent sequence. The
managed block remains excluded from the canonical chapter digest, so the
projection does not make its own source binding stale.

Validation distinguishes `youtube_videos_unlisted_preview` and
`current_quarto_preview_embeds` from `youtube_videos_published` and
`current_quarto_embeds`. The preview validator rejects duplicate IDs,
non-prefix positions, public-visibility or caption-attachment overclaims,
master or chapter substitution, omission, and support promotion. The
published-current counts remain zero, all 84 packets remain
`ready_not_published`, the playlist remains private, the twelve videos remain
unlisted, rendered binaries remain absent from Git and Pages, and support and
book-claim release effects remain none.

#### P7.3-F9 pedagogical, engagement, and synchronization ratchet — 2026-07-31

Integrated owner review of the first five previews found a defect that the
original artifact, transcript, and sampled-frame validators could not detect.
Video 1 contains chapter-specific scene work, but videos 2–5 are twelve-line
wrappers over `AsiChapterScene`. The shared engine performs a few entrance
animations for each of seven paragraph-level tableaux and then waits until the
paragraph endpoint. Their 119–127 spoken words per minute are not unusually
fast; the failure is low semantic animation density, repeated card layouts,
and paragraph-level rather than idea-level synchronization. Seven midpoint
frames can prove population and legibility while missing an early animation
followed by a long static hold. The prior `ratified` grammar status therefore
means **technical visual grammar v1**, not pedagogical acceptance.

The revised authoring contract is one visual explanation per chapter, not a
narrated slide deck. Each video must select one teaching promise and one
concrete case, then use a chapter-appropriate form such as a causal trace,
puzzle, construction, comparison, diagnosis, or counterexample. The opening
must begin delivering the title-and-thumbnail promise within fifteen seconds.
It should create an honest curiosity loop—expectation, tension, prediction,
mechanism, payoff, and transfer—without hype or unrelated spectacle. Reuse the
opening object through the worked trace and payoff so the viewer sees a
resolved mechanism rather than seven disconnected summaries.

Before beat planning, make the narration-only script pass one explicit
teaching promise, the case/mechanism/test/boundary contract, term and length
ceilings, speakability, and administrative-language exclusion. Then create a
machine-auditable v2 `beat_plan.json` whose concatenated narration exactly
matches that approved script. It must begin with an
art-direction brief: visual thesis, signature image, persistent visual world,
core objects, composition rule, semantic palette and typography roles, motion
character, camera rule, surface rule, and ending image. Companion audio and
accessibility briefs define narration direction, pacing arc, music and effects
policy, device checks, color and motion redundancy, integrated description,
captions, and reduced-motion risks. This is the chapter's identity within the
shared ASI Stack grammar; changing the palette or title on a generic scene is
not identity.

Use four to six macro story moves to shape the narrative and finer semantic
beats to time the explanation; do not mistake those two levels for one
another. Every semantic beat must bind a
distinctive spoken anchor, attention target, relationship and semantic
encoding, object state before and after, persistent-object continuity,
purposeful visual action, composition, easing, camera behavior, settling time,
short on-screen labels, claim role, and evidence boundary. The usual 8–14
meaningful beats per minute and 3–8 seconds per beat are diagnostics rather
than motion quotas. A beat above twelve seconds requires an explicit viewing
purpose and no beat may exceed twenty seconds. A slow, meaningful comparison
is preferable to decorative movement added to satisfy a count. Motion must
encode identity, relation, causality, sequence, quantity, uncertainty,
contrast, containment, authority, rollback, or attention.

Animatics may use exact synthesis-block durations recorded in the narration
receipt. Picture-and-sound lock may not use those estimates as if they were
forced alignment: a version-pinned aligner must first pass manually marked
difficult-term, pause, and regenerated-join anchors. Any narration or timing
change invalidates downstream beat, caption, render, and review custody.

The story contract is also less templated than the first ratchet. Every video
needs a hook, mechanism, evidence boundary, and payoff, but construction,
prediction, trace, comparison, counterexample, failure, consequence, and
handoff are selected only when the chapter needs them. Do not make the same
seven-part sequence the new generic engine.

Apply established multimedia-learning constraints: coherence, signaling,
segmenting, spatial and temporal contiguity, modality matching, redundancy
control, and pretraining for unfamiliar objects. On-screen words label; spoken
language explains causes and consequences. Place labels beside their objects
at the moment of reference. Do not duplicate narrated sentences on screen or
add music, flourishes, jokes, backgrounds, or side facts that compete with the
teaching promise. Use one or two real prediction prompts when useful, provide
evidence and a short thinking pause, and make the answer visible before naming
the general principle.

Authoring must use original ManimCE 0.20.1 code. Work through animatic,
picture-and-sound lock, and release-candidate passes so story and whole-video
rhythm stabilize before local transitions receive expensive polish. Study
explanatory patterns in
3Blue1Brown's published scene repository—object continuity, progressive
construction, `TransformFromCopy`, focus isolation, live manipulation, and
purposeful camera reframing—but do not copy ManimGL or CC BY-NC-SA
implementation code into this pipeline. Prefer persistent objects and
transformations over full-scene card replacement. Shared primitives are
appropriate only when they preserve chapter-specific state changes; a thin
wrapper around generic paragraph cards is not an accepted scene.

Beauty is a separate acceptance surface, not a synonym for technical validity
or animation count. Compose every frame around one focal hierarchy and enough
negative space; preserve spatial causality and object identity; use easing by
meaning; choreograph stagger and emphasis to guide the eye; alternate build,
transform, hold, and reveal; and earn one memorable visual payoff. Use linear
motion only for uniform rate or flow, ease-out for arrival, ease-in for
departure, and ease-in-out for state transformation or motivated reframing.
Bounce, shake, flash, spin, overshoot, parallax, and continual camera motion
require a semantic reason and a motion-comfort review.

Speech is the primary audio signal. Direct emphasis, pause, pace, and
pronunciation; audit regenerated splices; measure integrated loudness,
loudness range, and true peak; and require true peak at or below -1 dBTP while
pinning a series-appropriate online loudness target rather than importing the
-23 LUFS broadcast target. Music and effects must be original or
rights-cleared, stay substantially below speech, duck under dense ideas, and
disappear when silence improves comprehension. Captions include meaningful
sound, and the descriptive transcript or integrated narration conveys every
visual fact required by the teaching promise.

Review must sample at least five moments in every beat—start, quarter,
midpoint, three-quarter, and end—and include a complete 1× A/V watch, muted
watch, audio-only listen, captions-on pass,
phone-size and large-screen inspection, headphones/earbuds/speakers audition,
and random-frame scrub. Score teaching clarity, composition, motion quality,
synchronization, continuity, pacing, voice, sound mix, engagement,
accessibility, claim fidelity, and learning/transfer independently from 1–5.
Every dimension must reach at least 4 with no unresolved critical timestamp;
an average cannot hide a weak dimension. Revisions compare predecessor and
candidate at matched display size and volume. Keep editor, director,
renderer, and critic responsibilities logically separate even when one agent
performs several roles. The release critic must be cold to both the chapter
and candidate and must answer a comprehension question plus a novel transfer
question from the final video alone. The authoring system performs this gate
without an external-human prepublication dependency; later owner feedback
becomes a new revision input.

Mechanical A/V diagnostics flag long frozen intervals, black frames, silence,
loudness outliers, true-peak overs, and duration drift without pretending to
judge aesthetics. The new diagnostic found six 32.5–42.9-second frozen-image
intervals in the first current 305.6-second muxed master, while its measured
audio was -16.4 LUFS integrated, 2.6 LU loudness range, and -1.4 dBTP. That
result confirms the known visual-rhythm defect and shows that acceptable audio
meters do not rescue a static picture. Structural and mechanical validation
remain necessary but cannot certify insight, truth, beauty, comfort, or
learning.

Execute in three ratcheted cohorts whose denominator is derived from the
current manifest:

1. Rebuild and accept the five representative pilots under the new script,
   alignment, five-sample, and cold-learning gates.
2. Replan and animate the remaining rewritten scripts in canonical positions
   6–24, incorporating lessons from the accepted pilots.
3. Continue through every remaining current-manifest chapter in order; a new,
   moved, merged, or removed chapter updates the ledger automatically rather
   than creating a hand-edited denominator.

No cohort may enter platform staging until every member passes. A coherent
pilot is the transfer test for the system; mass rendering is not a substitute
for one accepted end-to-end result.

After publication has enough viewers, use first-30-second retention, dips,
spikes, and top moments to nominate revision hypotheses. These are attention
signals, not learning evidence: a spike can mean either interest or confusion.
Preserve generation comparisons and pair retention with a direct pedagogical
test of whether a viewer can predict the worked trace, explain the mechanism,
and state the boundary.

The research basis is explicit and bounded: [3Blue1Brown's video-making
advice](https://www.3blue1brown.com/about/) motivates concrete-before-abstract
explanation and deliberate motion; the [published 3Blue1Brown scene
repository](https://github.com/3b1b/videos) supplies pattern-study examples but
not copy-ready ManimCE code; [Brame's educational-video
synthesis](https://pmc.ncbi.nlm.nih.gov/articles/PMC5132380/) organizes
cognitive-load, engagement, and active-learning practices; [Mayer's multimedia
principles](https://doi.org/10.1075/dd.1.1.02may) motivate complementary words
and pictures, coherence, modality, and contiguity; [Guo, Kim, and
Rubin](https://doi.org/10.1145/2556325.2566239) provide large-scale
observational engagement evidence; the [Fyfield et al. controlled physics-video
study](https://doi.org/10.1103/PhysRevPhysEducRes.18.010148) supports the
combination of enhanced visuals and embedded questions within its measured
domain; and [YouTube's retention
documentation](https://support.google.com/youtube/answer/9314415) defines
attention diagnostics without converting them into learning evidence;
[Microsoft Fluent motion guidance](https://fluent2.microsoft.design/motion)
grounds easing, choreography, and attention hierarchy; [Apple's reduced-motion
criteria](https://developer.apple.com/help/app-store-connect/manage-app-accessibility/reduced-motion-evaluation-criteria)
identify common motion-discomfort risks; [W3C media
guidance](https://www.w3.org/WAI/media/av/av-content/) grounds captions,
description, intelligibility, and non-distracting audio; and [EBU loudness
resources](https://tech.ebu.ch/groups/loudness) supply measurement concepts
without imposing a broadcast loudness target on YouTube.

Public automated-video systems add a bounded engineering lesson, not a quality
claim. [Code2Video](https://github.com/showlab/Code2Video),
[TheoremExplainAgent](https://aclanthology.org/2025.acl-long.332/),
[OmniManim](https://arxiv.org/abs/2605.15585), and
[ManimAgent](https://arxiv.org/abs/2606.30296) motivate explicit
planner/coder/critic roles, scene-state and keyframe review, low-resolution
iteration, cold transfer checks, and retained success/failure memories. Public
Manim skills from [Video-Use](https://github.com/browser-use/video-use/tree/main/skills/manim-video),
[Yusuke710](https://github.com/Yusuke710/manim-skill),
[iart-ai](https://github.com/iart-ai/manim-skills), and
[makefinks](https://github.com/makefinks/manim-generator) similarly show the
value of planning and render-review loops. They are comparative workflow
inputs, not dependencies, copied templates, or evidence that this pipeline's
outputs are good. The ASI Stack admits a borrowed technique only after it
survives a local pilot and records both the successful conditions and failure
mode.

**Current execution checkpoint — 2026-08-09.** The repository-local skill,
narration/treatment/beat auditors, source preflight, shared-primitive graphical
regression, isolated render/mux runner, A/V and caption diagnostics, v3
treatment/review schemas, a v4 beat-plan schema,
pinned toolchains, and manifest-derived production ledger now form one
fail-closed generation-two system. This v3 checkpoint supersedes earlier v2
procedural language in this subsection wherever the two conflict. The ledger
derives 87 targets in canonical order. Twenty-four narrations have been
rewritten. The opening, Efficient ASI, System Boundaries, and Stable Capability
Fields targets have treatment, narration, and beat-plan files. All four now
pass their current treatment, script, and beat-plan gates; every animatic gate
remains unstarted. Twenty
targets remain narration drafts and 63 remain planned. Their exact chapter and
source context, claims, non-claims, truth checks, semantic keyframes,
accessibility plans, and read-aloud and visualizability verdicts are bound in
their treatments. The Efficient ASI pilot now teaches one causal reversal: a
visible one-unit parser route accumulates eight repair and three review units,
then loses to the verified nine-unit route. Its formal boundary names the local
Lean selector's minimum over authored eligible candidates and declared
seven-class totals while leaving complete search, input truth, and measured
efficiency open. The System Boundaries pilot holds one correct refund command
fixed while READ fails at a REFUND aperture, a bounded one-shot grant admits
one dispatch, and the byte-identical replay stops after consumption; its Lean
boundary remains finite and leaves identity, mediation, revocation races, and
observation completeness open. The current local animatics render under the
governed runner and have sampled-frame receipts, but none has the required
audiovisual, phone,
muted-motion, or cold-audience review needed to pass the animatic gate. Earlier
treatment-free plans and all downstream artifacts remain history. Current
state is therefore 20 `narration_draft`, four script-passed targets, four
file-level `beat_planned` targets, zero animatic-passed, and zero accepted or
published.

The hardening pass binds every gate to exact scene, caption, transcript,
thumbnail, toolchain, visual-grammar, primitive-library, receipt, and review
context identities. All 24 existing generation-two scenes pass the expanded
static preflight after serializing seven entrance-and-transform overlaps across
four draft scenes. The preflight also retains the earlier removal of five
direct-run entrypoints and one dynamic import; local imports are limited to the
separately digest-bound and graphically
tested `visual_edition.lib.asi_visuals` helper. Accepted rendering
uses a tracked macOS Seatbelt runner that constructs both Manim and FFmpeg
commands, narrows repository reads, denies network access, strips inherited
credentials, confines writes to `build/visual_edition`, enforces resource
limits, and emits a schema-valid policy receipt. Its live deny/read/write
controls and disposable real Manim-render plus FFmpeg-mux smoke test pass; the
source audit is explicitly not called a sandbox. A tracked compiler now derives
the final render receipt from the exact policy receipt, ledger-owned inputs,
forced-aligned plan, warning-free A/V diagnostic, and probed release metadata;
the final receipt is not hand-authored. Two reviewed Cairo reference frames
cover every public shared visual factory and caught a real evidence-badge
collision before baseline acceptance. The portable registry gate checks the
exact reviewed-baseline digest, frame contract, source preflight, and
public-factory coverage without claiming that Linux CI replayed a macOS render;
the full graphical comparison remains a separate pinned-host qualification
command. Release now requires
separate fresh-session source-aware and cold-proxy reviews, with frozen context
and prompt manifests and raw responses preserved before assessment. An AI
proxy remains artifact diagnosis rather than human-learning evidence. The
v4 experience-review contract binds complete phone playback, viewport width,
zoom state, audio/caption state, and whether a physical device was used;
lock and release reviews cannot substitute a desktop viewport for a phone.
The same auditor now has a canonical, stdout-only animatic preflight that can
surface freeze, black-frame, silence, loudness, peak, stream, and duration
risks without fabricating the final A/V artifact or advancing a review gate.
The
ledger validator rejects 96 representative identity, source, geometry,
sandbox, narration-custody, final-receipt, media-metadata, timing, review, sampling, and
publication mutations.

Timed plans now bind the canonical narration-render receipt and a passing
digest-bound ASR/content report. The receipt must reproduce the exact narration
with the pinned renderer, model, voice, speed, segmentation, lexicon, audio,
and treatment performance-block boundaries; the ASR transcript additionally
binds its runner, model revision, model-file identities, and source audio.
Duration ranges remain diagnostics, so the gate does not reward padding.

The ledger retains a whole-skill provenance digest but uses component-scoped
invalidation: story-contract changes reopen treatment, scene or shared-visual
changes reopen animatic, and caption/A/V helper changes reopen lock rather than
needlessly restarting editorial work. The alignment route remains
`not_yet_qualified`; no lock may pass until that admission test succeeds. The
opening pilot now has a 156.480-second, 21-beat block-timed animatic rendered
through the isolated runner and sampled at five frames per beat plus targeted
transition frames. That mechanical custody and frame sampling do not constitute
the missing observed full-speed audiovisual review. The current treatment,
script, and block-timed beat plan pass their exact gates, while the animatic
gate remains `not_started`. The next action is that playback review and any
resulting repair, followed by qualified alignment, picture-and-sound lock, both
isolated release reviews, and only then transfer to the other four pilots. The
opening narration and local animatic were regenerated; no platform object was
mutated and no Quarto publication state moved.

**Superseded execution checkpoint — 2026-07-31.** The v2 standard is now repository-local at
`skills/asi-stack-manim-videos/`, and
`visual_edition/manim_v2_production_ledger.json` derives all 84 targets in
canonical order across the 5/7/4/68 work cohorts; the seven residual generation-one
predecessors are explicitly private historical custody rather than active
unlisted previews, and four generation-two candidates are current unlisted
previews. Three schemas and a registered
validator make the beat, review, predecessor, gate, receipt, YouTube, and
Quarto transitions fail closed. The ledger currently records 76 planned
chapters, eight chapters through animatic, and eight through picture-and-sound
lock. Chapter 1 turns a
duplicate-file deletion request into a persistent proposal, authority,
observation, mismatch, and rollback trace. Chapter 2 turns one invoice into a
four-route exchange whose visible one-unit winner loses twelve-to-nine after
fallback, verification, repair, and maintenance enter the same accounting
boundary. Chapter 3 turns one flawless refund into an authority-envelope trace
across scoped read, transform, disclosure denial, narrow approval, effect
custody, confused-deputy substitution, expiry, revocation, replacement, and
the exact evidence ceiling. Chapter 4 rewinds one apparently successful
deployment through goal misbinding, stale context, authority expansion,
evaluator capture, purpose-free execution, residual laundering, and
self-ratification before binding the joined trace to custody, recovery,
recurrence, detector evaluation, and a hard evidence ceiling. Chapter 5 turns
equal knowledge but unequal performance in a harmless logistics maze into a
matched actor-system uplift instrument, protects the null with positive
controls, separates six quantities, locks every unearned D0–D5 bridge, and
binds surviving findings to a restricted/public, expiring dossier. Chapter 6
turns a synthetic two-display warning into one correlated provenance lineage
while its clock contracts from twelve minutes to two, then widens local model
performance into role-specific authority, meaningful judgment, deliberation
time, safe posture, reciprocal actors, common-mode interaction, prospective
off-ramps, dual-surface assurance, effect-complete custody, and a narrow
argument-level maximum inference. Chapter 7 turns a synthetic eighteen-percent
retrieval-gain card into a versioned claim atom, synchronized evidence views,
a non-aggregating eight-dimensional evidence cell, an empirical airlock, a
worked fixture/effect boundary, a failed-positive-control correction, adverse
lineage, one-way public projection, and the exact argument-support ceiling.
Chapter 8 turns a selectively reported replacement candidate into a denominator
reversal with two unsafe outcomes, then separates capability, access, and
authority asymmetries; repairs the critic view without laundering independence;
maps shared dependencies; routes a separate cohort audit; compares an informed
direct baseline; preserves four owner firewalls; quarantines the candidate with
its full record; and binds consumers, readmission, abstention, human capacity,
operating metrics, and the argument-support ceiling. Together the eight
animatics and eight delivery locks carry 205 audio-derived
beats, original
chapter-specific scenes, balanced captions, descriptive transcripts, custom
thumbnails, 1,011 exact beat samples across animatic and delivery review, and
per-dimension experience passes without average laundering. The rejected
Chapter 1, Chapter 5, Chapter 7, and Chapter 8 animatic revisions remain
preserved as generation history. All eight delivery masters remain candidates only: zero
generation-2 chapters have passed
release candidate, independent review, technical, claim-fidelity, or
acceptance, and zero generation-2 YouTube or Quarto identities are current.

**P7.3-F9 completion gate.** Close only when the reusable skill and tracked v3
treatment, beat-plan, review-context, render-receipt, and experience-review
schemas and validators pass positive and adversarial fixtures; every existing
scene passes source preflight; every public shared visual factory remains in
the visually inspected graphical baseline; the mechanical A/V diagnostic,
caption reviewer, and per-beat sampler pass their tests;
the five pilots pass the full revised workflow before wider rollout; every
current-manifest target passes treatment and script gates and has
art/audio/accessibility briefs, an exact beat plan, chapter-specific signature
visuals and persistent state changes, qualified word- or phrase-level
alignment before picture-and-sound lock, and five-sample-per-beat review
sheets; every release candidate passes an independent source-aware review and
a context-isolated cold comprehension and changed-condition transfer check,
with each owned dimension at least 4/5 and no material residual; every accepted
render has a network-denied, credential-free, constrained-write execution
receipt; the complete technical/accessibility suite passes again; and the
roadmap, manifest, ledger, landing page, README, and live embeds report the
same manifest-derived denominator. Private predecessors remain historical
until newly authorized replacement transactions reconcile accepted successors.

**P7.3 completion gate.** This lane is terminal only when every current
manifest chapter has a validated generation-two derivative packet and render
that also pass P7.3-F9's pedagogical and beat-synchronization gate;
every published video is hosted on YouTube in the canonical playlist;
every published chapter has a validated Quarto embed and adjacent descriptive
transcript; no video is stale; all output binaries remain outside Git and the
Pages artifact; platform and repository receipts bind exact identities; the
full site passes render, link, responsive, keyboard, accessibility-tree, and
public-crawl checks; and support-state, release-scope, and non-claim boundaries
remain unchanged. An owner-authorized unlisted preview may project a strict
subset for review only when its exact binding, incomplete denominator,
accessibility residuals, and non-publication state are visible and validated.
It never satisfies the completion gate. If final platform reconciliation is
not yet available, the honest lifecycle state remains all-current-manifest
`ready_not_published`, not a fabricated publication claim. The historical
generation-one checkpoint remains recorded as 84/84 `ready_not_published`
under its superseded technical contract; it does not satisfy this gate.

## P8 — Closure, residual ownership, and successor continuity

At every checkpoint, adjudicate each opened item as completed, narrowed,
refuted at an earned N-level, deprecated, superseded, instrument-inadequate,
implementation-inadequate, construct-invalid, underpowered,
`blocked_after_full_attempt`, or still owned with an exact trigger and next
check date. “More research needed” without an owner, prerequisite, and trigger
is invalid.

Close this roadmap only when all opened campaigns have terminal dispositions,
all accepted transition identities resolve, all negative inferences have an
auditable N-level, public truth is reconciled, evidence lanes remain separate,
the independent human narrative and content-critical reader work are
terminally dispositioned, external mutations have exact authority and
receipts, and the next successor or continuing-maintenance authority activates
in the same transaction. The separately owned P7.3 lane retains its own
terminal-or-exact-trigger custody and cannot block content/proof/evidence
closure merely because derivative production remains in progress.

## Execution order and decision rules

P0 remains continuous and first reconciles the generated 87-chapter status
surface plus claim-kind maturity projection. P1 is complete and its N0–N5
ceilings remain binding. `P5-U1` is terminal at its bounded retrospective
scope: one fresh-checkout command compares direct, record-only, and fully
governed routes across all four required paths, exposes explicit matched
governance rent, and preserves the no-support boundary. The prospective P5
natural campaign now owns broader utility, performance, observed human effort,
production, safety, and transfer questions. P4.1 proceeds only for a consumer
named by that campaign or a contribution exit ladder. P2 preflight remains the
protected empirical headline but is below its frozen storage floor at the
latest immutable `2026-08-13-r3a-004` observation; its command-bound N0 failure
record reports 7.12 GiB free and no reachable Docker daemon, and the next
action is a new exact capacity/Docker receipt only after both infrastructure
gates are restored. The storage-feasible protocol and four-slot replacement
qualification remain its unblocking path. `P2-Q1-D1`
stays closed until P2's own competence dossier passes, then may open for the Q1
strong-worker arms. The disjoint `ASI-THESEUS-Q2-D2` stays closed through
`T2`–`T4`; D1 outcomes cannot tune it. Historical `T0`, successor `T0A`, and
then `T1` through `T5` are the primary causal sequence for the composed
flagship. The original six P4 local clusters and the P6.5 book-organization
lane are terminal; only the bounded P4.1 amendment is open. The terminal Round
18 breadth transaction is historical; subsequent admitted and reconciled
owners produced the historical 84-chapter R16-B reader-freshness packet;
subsequent admitted work-surfaces, learning-topology, and adjudicated-persistence
owners bring the current manifest to 87 and retain additive birth-atom or
bounded formal-target and reader custody without rewriting R16-B. P5 may design the joined reference boundary
before `T4`, but may not substitute fixtures for the natural vertical. P3
opens only after `T5` and exact access predicates are true. P7 preserves
current published artifacts now; its R16-A, W3, T1D, and R16-B organization
sequence is terminal. The independent P7.1 narrative may be composed and
audited now without opening protected empirical outcomes; claims about the
natural flagship remain conditional until its terminal result. P7.1c remains
reference-chapter prose custody rather than the target human product. P7.3 is
separately owned by the video task and proceeds under its own exact gates;
video state neither changes the P2 scientific headline nor consumes this
task's proof/narrative WIP. YouTube and other external actions still require
explicit action-time authority. Candidate N/O research receives immediate
disposition but no new core owner during the amendment's evidence cycle absent
a dated unowned-lifecycle and merge analysis. P8 closes every checkpoint.

Every outcome-bearing item begins with an owner, stable claim identity, exact
scope, mechanism, falsifier, prerequisites, evidence lane, competence gates,
fair rescue ladder, held-out custody, stop rule, cost ceiling, artifact
destinations, negative-inference ceiling, and support ceiling. The held-out set
is not a debugging interface.

| Proposed movement | Minimum admissible evidence | Automatic rejection condition |
|---|---|---|
| Formal claim | Semantically adequate model, explicit assumptions, checked result, countermodel search, named claim/runtime consumer | Theorem count, `native_decide` alone, copied projection, vacuous antecedent, or no semantic consumer |
| Executable mechanism | Versioned competent implementation, activation trace, adversarial controls, observed effects, replay/recovery, residual accounting | Schema-only pass, inactive mechanism, mocked effect presented as real, or omitted failure/descendant state |
| Positive empirical/causal claim | Canonical identity, competence dossier, natural held-out outcome, calibrated independent evaluator, uncertainty, cost, controls | Leakage, failed positive control, floor/ceiling task, underpower, unmatched budget, or outcome-aware retry |
| Negative exact claim | All empirical gates plus a passed fair rescue ladder and N3 competence | Chance-level system, failed activation, implementation defect, bad proxy, evaluator blindness, or scope wider than exact setting |
| Mechanism counterevidence | N4: multiple competent implementations, valid tasks, mechanism controls, strong baselines, adequate sensitivity | One implementation, one proxy, missing favorable regime, shared defect, or jointly blind evaluator |
| Broad refutation | N5: N4 plus natural diverse corpora, two transfer settings, independent reproduction, and no surviving frozen rescue | Authored corpus only, single model/domain, no reproduction, or universal language beyond sampled envelope |
| Reproduction | Materially separate implementation/operator and evaluator, exact comparator, frozen environment/checkpoint, reproducible receipt | Same implementation relabeled independent, inaccessible comparator, or weaker proxy substitution |
| SOTA/Pareto | Current strong comparator, preregistered defeat criterion, matched resources, uncertainty, dated scope, joint frontier | Missing code/checkpoint/hardware, incomparable budget, marketing summary, or hidden negative setting |
| Publication readiness | Exact `main` commit, validated derivative, rights state, accessibility boundary, owner authority, deployed-byte receipt | Dirty/stale attestation, local build mistaken for publication, stale release identity, or implied license |

## Current owned queue

1. **Continuous truth and custody (`P0`).** Keep all 115 accepted transition
   identities resolved, reject parent-support laundering, and end every
   evidence-bearing transaction with exact commit, tree, artifact, and public-
   state reconciliation. Before further chapter-local status editing, generate
   the visible 87-chapter status blocks from `book_structure.json`, chapter
   front matter, and their governed owners; reconcile the four confirmed drift
   classes named in the 2026-08-03 amendment; and expose claim-kind maturity
   vectors without changing the conservative public support projection.
2. **Ready natural-campaign preflight (`P2`).** Preserve the fixed P2
   denominator and all N0 infrastructure outcomes. The exact 2026-07-28
   receipt remains historical; the latest immutable
   `2026-08-13-r3a-004` receipt records 7.12 GiB free against the 50-GiB entry
   floor and no reachable Docker daemon. Neither condition is a task outcome.
   The lane is resource-blocked and consumes no active WIP. Recheck only after
   external capacity or daemon state changes. Once both gates pass,
   execute the
   storage-feasible materialization protocol (sequential-verified
   readiness and Docker-scoped reclamation with receipts), then competently
   qualify all four replacement slots and restore the
   twelve-task denominator before ordinary rank progression under the
   amendment. Do not delete unrelated user data or treat storage weather as a
   task outcome. Once the seven competence gates
   pass, open only `P2-Q1-D1` without waiting for Theseus gates `T2`–`T4`;
   keep `ASI-THESEUS-Q2-D2` disjoint and outcome-sealed.
3. **Shared flagship prerequisites (`T0A`–`T4`).** Preserve historical `T0`,
   then reconcile the exact successor Theseus
   architecture freeze, behavior-positive student, real-use record, and joined
   happy/blocked trace before `ASI-THESEUS-Q2-D2` opens. Cross-repository
   handoff moves artifacts and maximum inference, never outcomes, rows, or
   support by implication.
4. **Semantic proof custody and composition (`P4.1`, consumer-gated).** Preserve
   the terminal six-cluster audit as historical local-scope custody. Do not
   open theorem families independently. The 2026-08-03 dated amendment permits
   proof rationalization and connected composition only when `P5-U1` or one of
   the three contribution exit ladders names the concrete consumer:
   classify every chapter target, retire or generalize duplicate envelope
   families where dependency-safe, and build consumer-linked cross-owner laws
   for the eight global invariants and ten distributed faults. Every admitted
   theorem family names its consumer, prevented failure, model boundary,
   refinement route, counterexample, maintenance owner, retirement condition,
   and maximum inference. Declaration count remains diagnostic only; Lean does
   not inherit runtime, empirical, institutional, or whole-system support.
5. **Effect-complete reference and immediate utility (`P5`).** Preserve the
   terminal `P5-U1` retrospective natural-defect replay: one documented
   fresh-checkout command runs the same public-safe repository task through
   direct, record-only, and fully governed routes across happy,
   blocked-authority, crash/recovery, and non-undoable-external-effect paths.
   Its 12/12 state-checkable cases, nine rejecting mutations, explicit matched
   governance-rent comparisons, and Human Reader route are implementation and
   instrument evidence only; they are not prospective natural-task evidence.
   Next design against the `T4` joined trace: durable identity, scoped
   authority, concurrent ledgers,
   observed effects, exact rollback or compensation, crash recovery, full
   learning state, revocation, and descendant-aware deletion. Preserve the natural publication
   development trace's source/tested-artifact/no-rebuild deployment/public-
   monitor joins, but never place its outcome-aware happy path in a held-out
   denominator. Preserve the terminal 60-trial, 213-process authored
   implementation/instrument qualification and its zero-natural-task boundary.
   Admit consecutive tasks only when independently necessary work arises by
   preparing the candidate outside the repository and previewing
   `python3 scripts/admit_p5_natural_task.py --candidate <path>` before any
   `--write`; every admission requires requalification before execution. Never
   manufacture tasks to fill the campaign. The protected
   forty-task denominator remains closed.
6. **Evidence, instrument, and structural renewal (`P6`).** Keep primary comparators,
   evaluator sensitivity, false-negative controls, alternative substrates,
   governed update/unlearning, Deterministic Capability Compilation, and the
   Platonic World Model current without allowing prose to inherit evidence.
   R16-A's append-only atoms for the six post-baseline chapters are terminal.
   Preserve the terminal W3 inheritance guard, six-chapter T1D
   manuscript-maturity receipt, the historical 84-chapter reader packet, and
   the additive current 87-chapter custody.
   The optimizer-landscape manuscript-depth
   amendment is terminal; its shared atom/reader projections remain inside
   R16-A/R16-B and its matched campaign remains an ordinary evidence residual.
   Preserve the terminal P6.7 inference-cache prose and source packet while its
   receipt schema and separate exact-prefix and semantic-response campaigns
   remain deferred evidence residuals.
   Preserve the terminal P6.8 Precision Contract source intake and nine-owner
   manuscript integration. Route its schemas, validators, source resolution,
   formal work, and empirical program only after terminal R16-A/W3 and T1D. Resolve
   the cited external literature before Appendix H use, and do not activate the
   standalone-chapter contingency unless a post-integration coherence audit
   demonstrates a distinct unowned lifecycle.
   Preserve terminal P6.9: the 84-chapter freeze, 84/84 unified atom custody,
   twenty-three reviewed owners, 184/184 concepts, the exact 21-fingerprint
   raw-scaffold ownership audit, and the exact 23-chapter/184-concept
   proof/evidence handoff. Retain the separate
   fifteen-chapter diagnostic-thin list. Preserve the twenty-three
   concept-complete owners at their reviewed digests and measure throughput in
   concept-complete dispositions. Treat the 5,000-word threshold and raw atom
   counts as diagnostics only. Reopen the lane only after digest drift or an
   explicit successor amendment; do not treat editorial completion as proof.
   The Round 18 bounded breadth packet is terminal at argument support. The
   binding no-deferral policy remains in force: no worthwhile manuscript idea
   may be parked behind a structural freeze, while unearned empirical or proof
   work may remain honestly open. The remaining historical P6.4 and N/O
   candidates have no active queue position because their warranted concepts
   were integrated or explicitly rejected, not deferred. Any future chapter
   still needs a distinct unowned lifecycle and full birth artifacts. Manifest
   or roadmap admission alone changes no support.
7. **Editorial product migration, independent narrative, and separately owned visual edition (`P7`).**
   Preserve the published `reader-2026-07-18` receipts and the terminal W3 and
   current-reader freshness packets as historical custody, not as the target
   human book. Execute `P7.1-EM` metadata-first: preserve all 87 research
   identities while validating the 54+2 main-book, 18 peer-status
   consolidation (zero open semantic merge candidates and 18 nests), seven-profile,
   five-owner/two-dossier, one-back-matter product split, then compose and
   maintain the independent 26-unit, 131,000-180,000-word narrative source.
   Preserve major conclusions and claim identity through its crosswalk while
   removing reference-only repetition, status boilerplate, and local contract
   recitation. Defer the 25,000-40,000-word primer until that narrative
   stabilizes. P7.3 remains a separately owned
   concurrent derivative packet in the video task: preserve its toolchain,
   captions, transcripts, digests, binary-hosting boundary, and publication
   authority, but do not duplicate its work here or let video state satisfy or
   block prose, proof, evidence, or content-freeze gates. The X synopsis and
   every YouTube mutation remain staged until explicit action-time authority.
8. **Independent challenge (`P3`).** After `T5`, reproduce any broadened result
   through a materially separate implementation/evaluator and two frozen
   transfer settings; a local positive does not become SOTA or architecture-
   general evidence by repetition in prose.
9. **Closure (`P8`).** Give every residual a terminal disposition, owner,
   prerequisite, and next trigger; activate exactly one successor or continuing-
   maintenance authority in the same transaction.

## Checkpoint receipt

Each checkpoint records the public release identity; exact `main` commit and
tree state; working chapter, atom, and transition counts; claim-ID mapping
coverage; N0–N5 rehabilitation counts; competence dossiers and failed gates;
claim movements; semantic proof additions, reclassifications, and deletions;
executed or blocked experiments; implementation, comparator, corpus, model,
checkpoint, evaluator, and transfer identities; effect sizes and uncertainty;
costs; reader and derivative freshness; rights/publication authority;
Manim toolchain and chapter-packet counts; current, stale,
`ready_not_published`, and `published_current` video counts; YouTube playlist
and video identities; caption, transcript, render, embed, and platform
receipts; failures; residuals; and the next owned trigger. It links public-safe
raw artifacts and includes negative mutations for its most consequential
possible lies.

#### P7.3-F10 withdrawn predecessor preview — 2026-08-02

The first-generation 1–12 preview projection has been withdrawn. The current
binding is an explicit zero-entry withdrawal state, and the managed players
and landing-page roster no longer point at those predecessor IDs. Their exact
platform identities and local custody digests remain in
`visual_edition/youtube_preview_history_2026-07-30.json`; the twelve YouTube
objects were observed private at withdrawal time. Generation-two candidates
19–24 remain unlisted but unaccepted, and chapters 13–18 have no YouTube
object. This disposition changes neither chapter support nor claim state and
does not delete platform history.

#### P7.3-F11 current generation-two preview projection — 2026-08-02

The owner-authorized projection now links the four generation-two candidates
whose uploaded master and chapter digests still agree: positions 19, 20, 22,
and 24. Their YouTube rows are observed `unlisted`, with captions published
and reviewed thumbnails applied; the four managed chapter players and landing
roster are reconciled to those exact identities. Candidates 21 and 23 remain
unlisted but are not linked because their chapters changed after upload and
their bound digests are stale. This is a preview-only projection and changes
neither support, claim, release, nor public-current state.

## Learning–Compute Topology successor lane

The 2026-08-09 intake of *Learning–Compute Topology: Formalizing the Causal
Organization of Adaptive Systems* closes the manuscript-placement question: the
concept is broad and load-bearing enough to own a chapter in Part III, while
ten existing owners carry its cross-stack consequences. The source archive,
paper-library edition with thirteen figures, detailed source note, 86th
chapter, source mappings, reader projection, claim adjudication, and two planned
formal targets are present. That is conceptual and provenance completion, not
an empirical result.

The remaining LCT program is ordered as follows:

1. **Independent representation and conformance.** Freeze a public LCT-IR
   corpus containing ordinary, ambiguous, invalid, and adversarial process
   descriptions. Have an implementation independent of the source package
   encode and normalize them. Report agreement, disagreement, annotation cost,
   hidden assumptions, rejected graphs, and noncanonical alternatives.
2. **Semantic compiler firewall.** Define protected observables and typed
   source-to-realization refinement. Exercise identity insertion, identity
   collapse, evidence and evaluator rerouting, credit drift, integration
   substitution, authority widening, hidden state carriage, staleness,
   compression, dropped work, reordered updates, and side channels. A passing
   schedule is not semantic preservation.
3. **Formalize only bounded claims.** Implement
   `lean:learning_compute_topology.semantic_firewall_nonexpansion` after the
   executable contract is stable. Treat
   `lean:learning_compute_topology.semantic_cut_information_bound` as a finite
   staged, no-side-channel theorem first; preserve the paper's information-
   theoretic assumptions and do not convert graph vocabulary into proof.
4. **Separate topology from resources.** Run a factorial campaign that holds
   learning topology fixed while physical realization changes, then holds
   resources fixed while learning topology changes. Match model, data,
   optimizer opportunity, evaluator queries, accelerator and CPU time, memory,
   storage, network, wall time, tuning, failures, and human work.
5. **Test strong process families.** Compare competent single-lineage,
   distributed-gradient, local/federated, population-based, evolutionary,
   branch–merge, ensemble, distillation, modular, fixed-ABVI, and adaptive-ABVI
   arms only where the implementation and evaluator pass prospective
   competence gates. Population Based Training is the nearest adaptive-
   schedule comparator, not evidence for the LCT proposal.
6. **Measure the whole learning process.** Keep discovery, evaluation,
   integration, retained capability, unsafe release, abstention, calibration,
   evaluator information, learning bandwidth, integration retention,
   topological regret, latency, work, span, communication, memory, storage,
   energy where measurable, recovery, operator burden, governance cost, and
   every failed branch visible together.
7. **Attack topology governance.** Test Sybil breadth, evaluator monoculture,
   merge-order attacks, provenance laundering, branch starvation, controller
   capture, archive erasure, held-out leakage, topology thrashing, deletion and
   privacy conflicts, and rollback that restores weights while leaving
   descendants or external effects changed.
8. **Admit only scoped outcomes.** A normal-form agreement result, compiler
   trace, toy phase diagram, formal cut bound, or successful controller run
   stays on its own claim axis. Broader process-architecture guidance requires
   natural workloads, matched strong baselines, causal ablations, independent
   implementation, reproduction, and materially different transfer settings.

This lane does not authorize a second LCT chapter. Add one only if later work
finds a genuinely independent owner that cannot be integrated into Learning–
Compute Topology, Governed Model Training, Policy Optimization, Data Engines,
Routing, Resource Economics, Open-Ended Improvement, Adversarial Evaluation,
Replaceable Substrates, Multi-Agent Dynamics, or the Integrated Reference
Architecture without collapsing their boundaries.

## Adjudicated Persistence successor lane

The 2026-08-11 intake of *Adjudicated Persistence: Governing the Transition
from Experience to Durable Structure in Adaptive Systems* closes a second
cross-layer ownership gap. Existing chapters govern evidence, memory,
procedures, compilation, policy updates, data custody, readiness, operations,
resources, and institutions, but none owned the prior decision that determines
whether an observed lesson should persist, which locus portfolio should carry
it, and what commitment, authority, qualification, invalidation, and descendant
obligations that choice creates. The new Part IV chapter owns that Adaptive
Commit Boundary without absorbing the downstream realization owners.

The manuscript, exact paper-library projection, complete source note, source
inventory, chapter mappings, outline, no-promotion decision, proof triage, and
visual target are present. The chapter is above the diagnostic depth trigger,
has one worked same-outcome/different-locus transaction, explicit alternatives
and objections, and a bounded SISA comparator. This is conceptual and
provenance completion only. No placement compiler, benchmark result, checked
Lean theorem, persistence advantage, safety result, or support movement exists.

Execute the successor work in this order:

1. **Finite transaction model.** Implement exact experience, lesson,
   disposition, realization, qualification-lease, authority, commitment,
   descendant, and residual identities. Reject identity substitution,
   unknown-to-admit collapse, construction-as-qualification, authority
   inheritance, stale lease use, and incomplete descendant closure.
2. **Bounded Lean envelope.** Implement the five registered targets for
   outcome-only placement non-identifiability, commitment-dominance evidence
   monotonicity, distinct qualification and authority, meta-compiler
   non-self-ratification, and descendant invalidation with residual closure.
   Every theorem remains limited to the encoded finite model and requires an
   independently implemented consumer and rejecting mutations.
3. **LocusBench Tier 1.** Freeze matched repository-maintenance defects whose
   visible outcomes collide while latent causes differ. Compare the
   cross-surface policy with competent outcome-only, fixed-memory, fixed-tool,
   and human-reviewed rules. Report useful success, placement regret,
   overcommitment, abstention, recovery, latency, compute, operator burden,
   carrying cost, and unresolved residuals together.
4. **Guarded realization and deoptimization.** Demonstrate that admitted
   memory, test, tool, route, or policy artifacts remain leased, that novelty
   and invalidation can reach a maintained deliberative path, and that
   revocation follows represented descendants without claiming external-effect
   reversal or complete world knowledge.
5. **Cross-owner handoff.** Connect accepted dispositions to Memory, Cognitive
   Compilation, Policy Optimization, Data Engines, Readiness, Operations,
   Resource Economics, and organizational governance through typed receipts.
   No receiving owner inherits lesson truth, qualification, authority, or
   support from the placement decision.

The lane is successful only if the added boundary changes a concrete decision
or catches a material failure at acceptable whole-lifecycle cost. If competent
fixed-locus or human-reviewed baselines match it more cheaply, narrow or retire
the compiler rather than preserving it as governance theater.

## Milestones

| Milestone | State | Completion condition |
|---|---|---|
| M0 — Truth and identity control | in progress | Preserve the historical clean `main` checkpoint at `cef11abd5fca0a421087b3123c1defb31f2b4e6d` and its build/deploy receipts without mislabeling it as the current tree. Generate current 87-chapter status from canonical owners, reject repeated-field drift, expose claim-kind maturity without cross-kind promotion, and keep exact current `main`/public custody through every later evidence checkpoint. |
| M1 — Negative-result rehabilitation | completed | All 90 accepted negative/no-change transitions are classified (1 N0, 15 N1, 74 N2, zero N3–N5), and the frozen 75-surface snapshot including the then-live 55 chapters preserves the resulting ceilings. |
| M2 — Competent natural empirical result | in progress | A high-value natural, non-authored campaign passes every competence gate and ends with a bounded positive, negative, or inconclusive disposition. |
| M3 — Reproduction and transfer | pending | Any broadened result has independent reproduction and two prospectively selected materially different transfer settings. |
| M4 — Semantic formal depth and composition | in progress; consumer-gated | Preserve the terminal six-cluster local audit and complete only dependency-safe rationalization or connected-owner composition required by `P5-U1` or a contribution exit ladder. Every family has a real consumer and seven-field admission record; no aggregate theorem count or finite authored record grants empirical, operational, institutional, or whole-system support. |
| M5 — Effect-complete reference | in progress; bounded `P5-U1` slice terminal | Preserve the fresh-checkout `P5-U1` command, three fixed routes, four effect/failure paths, 12/12 state-checkable outcomes, nine rejecting mutations, and explicit matched governance-rent accounting without support movement. Retain its retrospective natural-defect ceiling, the two bounded local slices, and one outcome-aware natural publication happy path at their exact scopes. The frozen five-arm campaign has terminal authored implementation/instrument qualification across 60 arm/fault controls, 14 state classes, 213 child processes, 24/24 evaluator cases, 14/14 development-opening gates, and an executable fail-closed admission transaction with a 15-development/40-heldout authored allocation and eighteen rejecting controls, but ran zero natural tasks and observed no elapsed 24-hour window. Consecutive natural development work, full cost measurement, precision simulation, the single protected opening, causal comparison, transfer, and independent reproduction remain. |
| M6 — Renewal and structural completeness | completed with additive successor custody | The first tranche, A1/A2, Round 18 breadth packet, ten-owner no-deferral transaction, four-owner taxonomy reconciliation, 2026-07-25 full-coverage audit, T1D six-chapter maturity/source/reader packet, Precision Contract integration, R16-A six-chapter/thirty-atom organization packet, W3 84-chapter inheritance guard, and R16-B 84-chapter reader-freshness derivative remain terminal historical receipts at their declared argument or organization scope. The current manifest has 87 owners and exact claim or bounded formal-target custody for all 87; later admissions do not rewrite those historical denominators. Optimizer, heterogeneous-memory, inference-cache, work-surface, learning-topology, and adjudicated-persistence manuscript depth are in the book; executable evidence residuals remain ordinary Phase 2 work. |
| M7 — Editorial product migration, independent narrative, and derivative disposition | completed through EM4 HTML cutover | Preserve `reader-2026-07-18`, the 84-chapter virtual derivative, the 22-unit candidate, and the pushed `96a22b15e` cutover candidate as immutable historical receipts while maintaining all 87 research identities. EM0 manifest-derived count truth, EM1 exact metadata-first 54+2/16+2+0/7/5/1 disposition, seven EM2 composition packages covering all sixteen publication nests and two method-detail nests, the terminal no-merge adjudication for Prototype Roadmap/Project Theseus, all twenty-six target-length EM3 units at 133,658 visible words, the generated 87-owner conclusion/claim crosswalk, and EM4 exact-head build/deploy/public-route/browser validation are complete. Retain the fifteen-minute utility route, three runnable task recipes, optional-depth marking, unit-level use/avoid/conclusion-change guidance, and `support_state_effect: none`. Defer the primer and full EPUB/PDF/DOCX/audio build until major-version content freeze. P7.3 remains separately owned and cannot substitute for narrative evidence. |
| M8 — Successor continuity | pending | Every open item has a terminal disposition and the next exact authority is active. |

## Definition of done

This roadmap is complete only when the project can distinguish “the idea was
competently tested and failed” from “our implementation or test was not good
enough,” and its book, ledgers, proofs, experiments, derivatives, and public
surfaces all preserve that distinction. Completion requires resolved claim
identity, generated all-current-manifest status custody, conservative support summaries plus
claim-kind maturity vectors, claim-commensurate competence, immutable raw
evidence, object/meta evidence separation, dependence accounting, N0–N5
negative scope, consumer-linked semantic rather than count-based formal depth,
one bounded connected composition model over the eight global invariants and
ten distributed faults, independent transfer for broad claims, effect-complete
implementation boundaries, a fresh-checkout minimal useful governed vertical
slice with direct and record-only comparators, four effect/failure paths, and
joint utility/safety/cost/burden reporting, governance-rent justification for
every mandatory process artifact, three contribution exit ladders without a
promotion quota, current sources and instruments, five closest-
prior-art matrices, non-overlapping Q1/Q2 denominators, one competence-qualified
terminal natural flagship, and an independently authored 26-unit human
narrative in the 131,000-180,000-word target range with a meaning-preserving
claim/conclusion crosswalk. Completion also requires terminal disposition of
the fifteen-minute utility route, three task recipes, optional-depth map, and
unit-level use/avoid/conclusion-change guidance; exact preservation of all 87
legacy IDs and their claim/source/proof/test/artifact edges through the
54+2/18/7/5/1 editorial migration, including 18
technical-owner-preserving nests and zero open semantic merge candidates; and
working legacy redirects. Completion does not require an
external-human prepublication review or a GitHub popularity threshold.
Completion also requires terminal disposition of the Round 16
atom/current-reader/template and six-chapter proof-readiness
integration debt, a
birth-complete terminal Round 18 breadth transaction followed by a structural
freeze without treating the historical 72/73-entry or later theoretical
75-candidate envelopes as targets, exact
`main` attestation, terminal reader/publication dispositions, and uninterrupted
successor ownership. The separately owned all-current-manifest governed Manim edition retains
its own current-caption, descriptive-transcript, platform-identity, and
`ready_not_published` gates, but its progress cannot substitute for or block
the content, formal, empirical, or narrative completion criteria above.
