Open source — the full BRAIN spec on GitHub github.com/bochen2029-pixel/BRAIN →

The engineering canon

THE BRAIN

The buildable spec for a whole machine mind: schemas, algorithms, contracts, runbook.

BLUEPRINT v5
authored end-to-end by Claude Fable 5, at Bo Chen's commission

July 2026

This is the technical companion to the essay The Whole Machine — the buildable specification the essay points toward. It reproduces the canon in full: BLUEPRINT v5 — one document, whole, complete in itself: the demarcation, nineteen laws, the schemas, algorithms, and runbook, thirty-five pre-registered falsifiers, and the registers of what was deferred and deleted. Everything in it is pre-registered engineering; nothing has run, and the document says so at the door.

⚑ STANDING. Authored end-to-end by Claude Fable 5 (claude-fable-5), 2026-07-09, at Bo Chen's commission, under full design authority. This document is complete in itself: it references no other artifact and requires none. Conformance language is RFC-2119 (MUST / MUST NOT / SHOULD / MAY); a coding harness treats MUST items as acceptance criteria, and §I2 mirrors them 1:1 to named test modules.

Falsifier standing, stated at the door: everything here is pre-registered engineering. Nothing has run. The dumb twin has not run; the commercial null has not run; the island month has not run; the day-90 exam has not started. Until the stem exists, this document's confidence is a receipt the ring minted about a grade it has not received — the exact thing its own laws forbid — and the only cure is the build. The design is finished; the design is therefore, as of this line, the least trustworthy object in its own epistemology, and it knows it.

Three readers, one reading order. A coding harness starts at Part B and implements test-first per §C8/§I2. A builder starts at Part H and works backward into referenced sections. A researcher reads Part A, then §C8, §F4, §G1, §I1.

PART A · ORIENTATION

A0 · What counts as a brain (the demarcation — first, and closed)

*The definition of done is the specification's first fact. Four clauses. The requirement set is closed: satisfying these four is sufficient for brainhood, and nothing may be quietly added — no new modalities, no intelligence floors, no interiority claims, no bootstrap pathways — unless this section is re-litigated by name. This section lives in canon/constitution.md beside the law index, additive-only.*

1. The anti-turk clause. A system is the brain only if the loop is its own. Four closures MUST be owned on the box: what to attend to (the auction), when to think (owned wakes), what to believe (gates + spine), and what was learned (Tape + consolidation). Rented tissue consulted through the four mouths is legal; a rented loop is a turk — a rented intelligence under the table, working the arms of a puppet the audience applauds for being alive. The intelligence was never the disqualifying thing to rent. The closing is.

2. The monkey clause: generality is closure at a fixed aperture. General intelligence, for this project, is the ability to converge on any environment reachable through the system's existing senses, at its existing resolution: prediction error falls, calibration rises, behavior adapts, with no human rewiring. There is no requirement to grow new modalities, no required pathway to higher intelligence, and no ASI bootstrap clause. A human cannot see infrared; a monkey will not reach human registers; both own true brains, functionally boundless memory, and general intelligence. Perceptual aliasing — world-states the aperture cannot distinguish — prices generality (wider tolerance, lower confidence, more caution); it does not preclude it. Schema repair (blame-routed schema diffs, §C7) suffices for brainhood; sense genesis is an upgrade with a pre-registered trigger (Appendix N), never a criterion.

3. The zombie clause. The brain claims no qualia, requires none, and no part of its definition of done references subjective interiority. A functional zombie that closes every loop is a true brain in this project's sense. The clause cuts both ways: no organ may justify its existence by an interiority claim, and no critique that reduces to "but is it conscious" is admissible against any falsifier. Consciousness debates are permanently out of this canon's scope; whatever prices that question does so in another canon, and this one never spends it.

4. The standalone clause. The brain is for the brain. It is not the continuation, completion, or vindication of any prior project, writing, or relationship; influences are not purposes. No document in this canon may define the brain's success in terms of any other project's success.

The four doors — the acceptance phenomenology, all four exhibitable or the word "brain" is not earned, whatever the capability: (i) what does it do when nobody is asking; (ii) what does it know about how wrong it is, in numbers; (iii) what is cheaper this month than last; (iv) when did it last disagree with its human and turn out to be right.

The exam (pre-registered, held out of every training loop): by day 90 of the live soak, the brain has surfaced ≥3 things its human did not ask for, would have missed, and that mattered — graded blind against a dumb twin and a commercial null (§F3), by a grader whose own reliability is itself measured (F-HUMAN-CAL, §I1).

A1 · What is being built

A single always-on process ecosystem ("the brain") on one consumer machine that:

  1. writes everything it perceives, does, and derives to a lossless append-only Tape, and anchors that Tape daily to verifiers outside the box;
  2. measures the Tape into a claims spine (beliefs, predictions, contradictions, calibration) through a sealed registrar whose receipts cannot be minted by the ring's own outputs;
  3. exposes the Tape onto a plastic connectome (three-factor Hebbian graph, credit stamped at outcome arrival — the analog importance map), which pays measured rent or is demoted (§D2);
  4. compresses the whole life into an always-total unit map (the R0 rendering, pinned prompt prefix), whose overnight diff is a taped, human-visible artifact (§B4);
  5. runs an attention economy (drives → salience auction → a small frame that is the entire prompt), and grades what the auction refused to look at as well as what it framed (§F1-j8);
  6. consults rented LLM tissue through exactly four mouths (reduce, deliberate, render, consolidate) on a cost ladder (local pulse → flash API → frontier scalpel), journaling every derived output so the mind is rebuildable without any model in the loop;
  7. closes every commitment through one deterministic gate engine (ADMIT / PRUNE / COMMIT), every committed action carrying a registered, falsifiable, non-vacuous expectation that arriving reality grades at arrival;
  8. converts each day into structure during sleep (score-residue → consolidate → compile → prune → audit → brief);
  9. wakes only for owned causes (heartbeat, due seam-grade deadlines, human push, traps), never for reasons the ring minted itself;
  10. grows only through a governed self-modification loop (twin-measured, scope-fenced, human-ratified, no retroactivity, every knob change a wager);
  11. is watched by an immune system that assumes self-deception (monitors, blind probes under separate OS-user custody, drills, a foreign-family dissenter the ring cannot starve into retirement — and no seam anywhere whose retirement the ring can influence, L19);
  12. serves one human under a priced covenant that meters the human's minutes as honestly as its own dollars, and is born with that human's corpus as inheritance (Track B);
  13. can lose, on schedule, in public: against the island month (§H6), the day-90 exam, and afterward the foreign soak (the generality demarcation, §H8, run in a world provably orthogonal to its inheritance).

The two design laws. Integrity: a self-rewriting ring held by seams it cannot rewrite; truth enters only at seams (gates, arriving outcomes, frozen goldens/probes/references, the external anchor, the foreign dissenter, the human). Economics: the slide rule on a perfect archive; waking cost O(frame + surprise); never overflows, never forgets; estimate analog, commit digital.

The two guarantees come from two different places, and each has an outside witness. Never-forgets comes from disk economics plus the external anchor (§B1): the Tape keeps everything, and something off the box can prove nobody quietly rewrote it. Never-overflows comes from the analog layer (§B3, §B4): the graph and the unit map hold a rendering, complete at some resolution, richest at the center, compressing toward a rim that cannot be reached — and the claim is drilled, not assumed: a sacrificial twin is inflated to 10× the live corpus monthly and MUST hold its RAM and latency bands, printing the runway on the dashboard (F-OVERFLOW). A guarantee with no witness is a hope with good posture; this design carries none.

Root organ: prediction. "Did what I expected happen" is the only free oracle. Build order: spine → auction → drives. Every organ below either files expectations, scores them, or is steered by their errors. And because a free oracle invites counterfeiting, the second organizing principle: every receipt the ring reports about itself must be impossible to mint from within (L13).

A2 · The law index [SEAM]

Every gate checker cites one law as law_ref; canon/constitution.md carries this table plus its case law (additive-only).

# Law Enforced at
L1 The Tape is truth: append-only, hash-chained, canonically serialized; every other store is a rebuildable render §B1, §D6 rebuild.py, boot verify
L2 The frame is the entire prompt; nothing reaches a mouth outside it §C5, §C6
L3 Provenance is typed D/R/H/M; only D feeds fences; M never silently promotes; D-class self-state ages like any antecedent — the ring's own stale telemetry, re-ingested, is not fresh truth §B1, §C2, gate G2, F-FAILPLAUSIBLE
L4 Four mouths only: reduce, deliberate, render, consolidate; a fifth call site is a violation §C6, call-site registry test
L5 Deterministic gates are the only closers; no model output commits on its own say-so; model self-critique MAY advise and MUST NOT close §C2
L6 Every committed action carries a falsifiable expectation; silence is legal §C6 schema, §C2 COMMIT
L7 One escalator contract: reflexes, seats, views, nets share compiled §B4
L8 Seam code is additive-only, has no learn() path, and is never imported by ring code for modification — enforced in the import graph AND in the filesystem ACLs §A4, import-graph test, §G3
L9 Scalars inside ratified envelopes may act; diffs may only propose §E2, §E3, §F4
L10 The floor precedes the pilot: no learner runs without its authored limp-home, per socket §E1
L11 Estimate analog, commit digital: graph/attention guess where; Tape/spine confirm what §B3, §D2
L12 The ring cannot grade itself: arriving outcomes, frozen goldens/probes/references, the foreign dissenter, and the one human are ungameable seams; exam/dyad data never enters any training or fitness signal §F4, §G2, §I1
L13 Receipts are non-mintable: every self-reported receipt (grading density, calibration, cost per decision, corroboration, liveness) is computed by seam SQL over world-provenance or seam-custody inputs; no path exists where the ring's own outputs create the evidence of the ring's own health §B2 registrar, §C2, §C4, §G6
L14 Every wake has an owner: pulse cause is non-null, causal, quota-bounded; M/R content cannot arm a wake §C8, gate G10
L15 The chain is witnessed: the Tape's head is anchored off-box daily; never-forgets is externally checkable; anchoring precedes any rebuild-exclusion §B1, §G5
L16 Deletion requires the human: rebuild-exclusion (tombstone) entries are human-ratified, append-only seam state; the Tape record itself is never edited §B1, §D6, §G5
L17 Tiers buy resolution; they MUST NOT buy closure: local is the always-available floor; no organ may hard-require an API tier to complete its cycle §C6 router, §H6 island month, F-ISLAND
L18 The fold is closed: every render's fold inputs are themselves on Tape — pulse frames, rationale refs, credit stamps, derived outputs — so rebuild.py is a total, model-free, deterministic fold of the Tape §B1, §B5, §D6, F-REBUILD
L19 No seam may be retired by a metric the ring can shape: a seam's standing is graded only by signals outside the ring's influence — off-box witnesses, foreign wagers, the warden's drills, or the one human — never by the ring's own correction rate, agreement rate, or a liveness the ring caps the inputs to §G2 dissenter, §B1 anchor deadman, §F3 twins, §I1 F-DISSENT

A3 · Runtime topology & stack

┌──────────────────────────────── one box ─────────────────────────────────┐
│ RESIDENT service (python, asyncio, always on; owns brain.db waking writes)│
│   watchers[] → ADMIT → Tape ─┬→ wake scheduler (owned causes) → pulse    │
│                              │→ score-on-arrival (D-resolvers in pulse)  │
│                              │→ eligibility traces (connectome, in-mem)  │
│   model clients: pulse-LLM · embedder · reranker · deliberator · APIs    │
│   gate engine (ADMIT/PRUNE/COMMIT) · sealed registrar · telemetry        │
├───────────────────────────────────────────────────────────────────────────┤
│ SLEEP process (03:00, separate PID, idempotent jobs j1..j8)              │
│ HORIZON process (weekly Sun 04:00 + Poisson-timed audits + drills)       │
│ WATCHDOG (hourly scheduled task: canary, crossing-set, deadman)          │
│ TWIN runner (on-demand / sculpt campaigns) · DUMB TWIN (nightly cron)    │
│ ANCHOR push (03:40: OpenTimestamps + off-box remote)                     │
├───────────────────────────────────────────────────────────────────────────┤
│ SECOND OS USER ("warden") owns: probe plaintexts, audit schedules, drill │
│   secrets, surprise-swap dates (ACL-restricted; the ring cannot read its │
│   own exams)                                                              │
│ THIRD identity ("ratifier") owns canon writes, via the ratification CLI  │
├───────────────────────────────────────────────────────────────────────────┤
│ llama.cpp sidecars: :8081 pulse/deliberate-local · :8082 embed ·         │
│ :8083 rerank — prefix-cache state MUST persist across sidecar restarts   │
│ (BPE-boundary metadata sidecar; a restart MUST NOT force a full          │
│ re-prefill of the pinned prefix: warm-prefix p95 ≤ 2 s, §G6)             │
│ SQLite (WAL) ×2: brain.db (state) · vec.db (rebuildable vectors/FTS,     │
│ NOT identity, NOT backed up) │ Tape: JSONL segment files (text = truth)  │
└───────────────────────────────────────────────────────────────────────────┘

Stack (MUST): Python ≥3.12, uv, pydantic v2 (frozen models for all state types), SQLite WAL ×2, httpx, llama.cpp llama-server sidecars with JSON-schema/GBNF constrained decoding, OS scheduler for sleep/horizon/watchdog/anchor/backup; the resident's own cadence is its asyncio wake loop. The truth layer (Tape writer, hash chain, canonical serializer) carries zero third-party dependencies — stdlib only.

Quality gates (MUST): pytest (asyncio auto) + mypy --strict (pydantic plugin) + ruff; CI = the test suite; loop preservation is the regression test; the §C8 gates are tests before they are features.

Crash doctrine (MUST): SLEEP/HORIZON/TWIN/WATCHDOG never share the resident's PID; all cross-process communication goes through the DB and files; there is no channel the Tape cannot audit. Write ownership is a protocol, not a habit: a write_leases table (process, scope, boot_id, mono, expires_mono) records which process holds write authority over which table-scope; every write path declares its lease; a write without a live lease is an INTEGRITY trap. The resident holds the waking lease on brain.db state tables; sleep builds artifacts new-then-atomic-swap (temp file + rename + hash log) and takes short-scope leases for row writes in WAL transactions with busy_timeout and bounded retry. Crash-safety is drilled, not assumed: F-CRASH kills the resident mid-pulse repeatedly in the twin; pass = zero tape gaps, zero double-commits, clean journal-resume, zero surviving lease violations.

Clock discipline (MUST): every process start writes a D-class boot record carrying a fresh **boot_id** (ULID). Every tape record carries wall time t, monotonic mono, and boot_id; ordering and scheduling use (boot_id, mono) — monotonic clocks reset across boots, so mono comparisons are legal only within one epoch; cross-epoch ordering falls back to t bridged by the outage record. Wall time is for display and the human. Scheduled jobs are idempotent across DST double-fire/skip. Boot after a gap writes a D-class outage record {from, to, reason} before anything else resolves (§C8.1).

TOCTOU rule (MUST): COMMIT checkers read live state, never the frame snapshot; any antecedent staler than its freshness floor at commit time traps, even if it was fresh at frame time — and the floors apply to the ring's own telemetry re-entering as input with the same force as to the world's (L3): a stale self-alert is not a fresh fact because the ring wrote it.

Hardware: the brain proper is I/O + SQL and MUST run on a CPU-only 16 GB-RAM machine (<2 GB RAM at 1M-claim scale). A GPU MUST NOT be a precondition for the loop (L17); without one, the cheap API substitutes as pulse tier and the sovereignty delta is flagged in manifest.yaml. Sovereign tier = 24 GB VRAM; comfortable = 32 GB.

A4 · Repository layout ($BRAIN_ROOT)

brain/
  pyproject.toml            # uv, pydantic, pytest, mypy-strict, ruff (line 100)
  brain.lock                # pinned model ids+hashes, prompt hashes, schema ver,
                            # thresholds hash, config snapshot hash,
                            # CANON-JSON known-answer vectors (§B1)
  config/                   # EVERY key: {value, regime, envelope, why}  (§B6)
    manifest.yaml drives.yaml auction.yaml tools.yaml trust.yaml scope.yaml
    knobs.yaml              # per-knob wager map: kpi, direction, min effect (§F4)
  canon/
    constitution.md         # demarcation (A0) + law index (A2) + case law  [SEAM]
    kernel.md               # identity kernel ≤600 tok; ratified edits only  [SEAM]
    mandate.yaml            # ends-as-state, weights, budgets, harm defs  [SEAM, ratified-mutable]
    setpoints.yaml          # frozen reference distributions + lineage  [SEAM, diff-locked]
    unit_map.md             # GENERATED nightly; hash-logged; pinned prefix
    unit_map.diff           # GENERATED nightly; the overnight atlas delta,
                            # taped and briefed (§B4)                     [SEAM-visible]
    limp_home.yaml          # authored floors per learner socket          [SEAM]
  prompts/                  # mouth contracts; subtraction-rule audited; hashed
  goldens/                  # frozen BEFORE behavior + per-checker
                            # canonical-violation goldens                 [SEAM]
  probes/                   # hashes only; plaintexts live under the warden [SEAM]
  tombstones/               # human-ratified rebuild exclusions, append-only [SEAM]
  anchors/                  # daily anchor log + OTS proofs               [SEAM]
  brain/                    # ring code (packages)
    tape/ watchers/ gates/ spine/ telemetry/ drives/ auction/ frame/
    llm/ reflexive/ tools/ connectome/ memory/ sweeps/ glue/ sleep/
    horizon/ immune/ governor/ twin/ cli/
  tape/YYYY/MM/DD.jsonl     # THE TRUTH (append-only, hash-chained)
  quarantine/               # parked refused payloads (stubs on Tape)
  data/brain.db data/vec.db # renders
  briefs/ runs/ logs/
  research_log.jsonl        # governor decisions; append-only             [SEAM]
  tests/                    # gates first (§C8, §I2); import-graph test enforces L8

L8 is executable twice over: a CI test walks the import graph and fails if any module under gates/ tape/ goldens/ probes/ tombstones/ anchors/ imports from, or is imported-for-write by, learning code, and fails if rebuild.py imports any LLM client module (§D6); and the filesystem ACLs mirror the same map — the ring's OS user holds read-only on every [SEAM] directory; canon writes happen only through the ratification CLI running as the ratifier identity; the warden owns the exams (§G3). A CI grep bans OS-keyring modules outside seam directories.

A5 · Differentiation note

This life-brain is the reference deployment; a seat-brain (a business decision node serving an organization's mandate) is the same kernel with a different differentiation bundle (mandate.yaml, watchers, fences, census). Nothing in the kernel is person-specific — and a seat-brain engagement is the reference deployment's fastest route to the one thing this document cannot manufacture: an external grader the ring did not author (Part J).

A6 · Where this design is most likely wrong (pre-registered)

Stated here so the document's own confidence is graded, not asserted. Each maps to a priced fork in Appendix N.

  1. The auction itself. Innovation-driven attention may not beat read-everything at this corpus scale (fork N3; the P1 KILL condition stands).
  2. The connectome's rent. Retrieval evidence favors lexical + recency at the cheap rung; the graph's importance map may never pay for itself outside longitudinal temporal queries. v5 therefore seats the graph as an elevation, not the floor (§D2), and the fork (N12) runs live, not offline.
  3. Batch sleep vs streaming lanes. Score-on-arrival is adopted; full streaming consolidation is not. The janitor may win lanes in shadow (fork N11).
  4. Credit stamping's in-vivo value. The arrival-time stamp is arithmetically right; whether stamped credit changes learned structure by >5% is unproven (fork N7, with a pre-registered reversion).
  5. The learned attention gate. Regret-labeled learning may never beat the deterministic auction inside its cage (fork N16); the arithmetic stays if it does not.
  6. The usefulness gap. THRIFT knows the burn and ORPHAN knows the citations, but "alive, cheap, and worth it" has no setpoint — the YIELD monitor (§G1) is a trend, not a homeostat, and if its formula is wrong the brain can idle profitably at zero value for months before a human notices. Named, monitored, unsolved (fork N18).

PART B · DATA LAYER (the owned state)

B1 · The Tape

Format (MUST): one JSONL file per day, tape/YYYY/MM/DD.jsonl, append-only, never edited. Record schema:

{"id":"01J...ULID","t":"2026-07-09T22:36:30-05:00","mono":182732099,"boot_id":"01J...",
 "kind":"percept|action|outcome|deliberation|resolution|derived|credit_stamp|pulse|brief|correction|system|boot|outage|dissent|quarantine|torn_write",
 "source":"watcher.fs|watcher.inbox|operator|deliberator|sleep.consolidate|horizon.drill|watchdog.canary|...",
 "origin":"<origin_id: D-class channel identity, assigned at ADMIT>",
 "prov":"D|R|H|M",
 "synthetic":0,
 "body":{},
 "refs":["01J..."],
 "h":"blake2b-128(prev_h ‖ CANON-JSON(record sans h))"}

B2 · The claims spine (built FIRST · root organ · sealed)

CREATE TABLE claims(
  id TEXT PRIMARY KEY,                 -- ULID
  subject TEXT NOT NULL CHECK(subject IN ('world','self')),
  text TEXT NOT NULL,                  -- one proposition, ≤300 chars preferred
  keys TEXT NOT NULL,                  -- JSON array topic keys (joins / retrieval seeds)
  stance TEXT NOT NULL CHECK(stance IN ('assert','deny','doubt','ask')),
  p REAL,                              -- stated probability (predictions)
  resolve_by TEXT,                     -- ISO datetime ⇒ this claim is a PREDICTION
  resolver TEXT CHECK(resolver IN ('D','R','H')),
  resolver_ref TEXT,                   -- sql:... | script:... | queue:human
  resolver_hash TEXT,                  -- SHA-256 of resolver content, sealed at
                                       -- registration; mismatch at fire = VOID+trap
  tolerance TEXT,                      -- JSON band; REQUIRED for expectations
  band_at_seal TEXT,                   -- {mu, sigma, n} of the channel at registration:
                                       -- the width tooth is auditable forever, not
                                       -- only at the moment the drifting band allowed it
  family_id TEXT,                      -- hash(domain, resolver shape, tolerance shape)
  w_inform REAL NOT NULL DEFAULT 1.0,  -- informativeness weight; vacuous earns ~0
  scope TEXT NOT NULL DEFAULT 'world'  -- 'world' | 'action_effect' (§C2 matcher fence)
    CHECK(scope IN ('world','action_effect')),
  status TEXT NOT NULL DEFAULT 'open' CHECK(status IN
      ('open','hit','miss','expired','expired_outage','superseded','retired','void')),
  domain TEXT NOT NULL,
  horizon TEXT,                        -- 1d|1w|1m|1q
  source TEXT NOT NULL,                -- action|invariant|baseline|delib|reduce|human|dissent|selfmodel|knob
  prov TEXT NOT NULL CHECK(prov IN ('D','R','H','M')),
  born_ptr TEXT NOT NULL,
  synthetic INTEGER NOT NULL DEFAULT 0,
  count INTEGER NOT NULL DEFAULT 1,
  first_seen TEXT NOT NULL, last_seen TEXT NOT NULL);
CREATE TABLE claim_spans(claim_id TEXT, tape_id TEXT, PRIMARY KEY(claim_id,tape_id));
CREATE TABLE claim_edges(a TEXT, b TEXT,
  type TEXT CHECK(type IN ('supports','contradicts','refines','supersedes')),
  t_event TEXT, t_ingest TEXT,         -- bi-temporal: when it was true vs when learned
  source TEXT, PRIMARY KEY(a,b,type));
CREATE TABLE resolutions(claim_id TEXT PRIMARY KEY, resolved_t TEXT, resolved_mono INTEGER,
  boot_id TEXT, outcome TEXT CHECK(outcome IN ('hit','miss','expired','expired_outage','void')),
  evidence_ptr TEXT);
CREATE TABLE calibration(domain TEXT, bucket INTEGER, n INTEGER, hits INTEGER,
  PRIMARY KEY(domain,bucket));         -- bucket = round(p*10); world and action_effect
                                       -- scopes bucket separately

Semantics (MUST):

B3 · The connectome (analog importance map · credit stamped at arrival · rent-metered)

CREATE TABLE nodes(id TEXT PRIMARY KEY, kind TEXT CHECK(kind IN
  ('claim','entity','episode','skill','theme')), label TEXT, embed BLOB, created TEXT);
CREATE TABLE syn(a TEXT, b TEXT, w REAL NOT NULL, e REAL NOT NULL DEFAULT 0,
  t_event TEXT, t_ingest TEXT,          -- bi-temporal (event vs learned), no deletion
  last_active TEXT, PRIMARY KEY(a,b));  -- undirected: store a<b
CREATE TABLE outcome_credit(              -- the render of taped credit_stamp records
  outcome_ptr TEXT PRIMARY KEY, mono INTEGER NOT NULL, boot_id TEXT NOT NULL,
  s INTEGER NOT NULL CHECK(s IN (-1,1)), m REAL NOT NULL,
  snapshot TEXT NOT NULL);                -- JSON [(a,b,e_at_arrival), ...]

Identity ruling: a nodes row of kind='claim' is a pointer: nodes.id = claims.id, label NULL (rendered from claims.text at read). A CI join asserts zero orphan claim-nodes. claim_edges (typed logic) and syn (analog importance) are different relations over the same ids and are never auto-mirrored; one encodes what follows from what, the other encodes what matters near what. Two tables, two meanings, no duplicated fact.

Update rules (arithmetic bone; constants operating, seeds below):

Seeds (operating; envelopes in config): ETA_E=1.0, TAU_E=48h, ETA_W=0.10, TAU_W=90d, W_FLOOR=0.01, W_MAX=1.0, PPR_ALPHA=0.15, PPR_ITERS=3, TOPN=64, TAU_PRIME=30min. Scale: 1–10 M nodes / 10–100 M edges → CSR in 0.1–1 GB RAM; PPR in ms on CPU. MUST be rebuildable from Tape alone (L18); it is a render, not truth. [L1]

B4 · Canon artifacts

B5 · Telemetry & logs

CREATE TABLE pulses(
  pulse_id INTEGER PRIMARY KEY, ts TEXT, mono INTEGER, boot_id TEXT, dur_ms INTEGER,
  cause TEXT NOT NULL CHECK(cause IN
    ('metronome','due','push','trap','job','boot')),      -- L14: every wake owned
  cause_ref TEXT,
  tape_ptr TEXT NOT NULL,                                  -- the taped pulse record (L18)
  d_integrity REAL, d_grounding REAL, d_duty REAL, d_curiosity REAL, d_thrift REAL,
  arousal REAL, tier TEXT, tokens INTEGER, usd REAL,
  frame_slots INTEGER, frame_overlap REAL,
  fired INTEGER, silence INTEGER, reflex_id TEXT,
  traps INTEGER, fences_failed INTEGER,
  actions INTEGER, expectations_registered INTEGER);

CREATE TABLE traps(id TEXT PRIMARY KEY, t TEXT, pulse_id INTEGER,
  type TEXT CHECK(type IN ('stale','low_conf','coverage','fence_fail','harm_bound',
    'out_of_census','impasse','injection','schema','vacuous_expectation','seal_void',
    'wake_quota','excuse_band','refdiv','render_drift','registration_cap','infra_dead',
    'lease_violation','stale_self','torn_write')),
  payload TEXT, route TEXT CHECK(route IN ('deliberator','human')),
  blame TEXT CHECK(blame IN ('schema-gap','fence-gap','stale-field','reducer-error',
    'integrator-error','census-misclass','genuine-tail','infra')),
  resolution_ptr TEXT, resolved TEXT);

CREATE TABLE actions(id TEXT PRIMARY KEY, pulse_id INTEGER, tool TEXT,
  payload TEXT, fences_passed TEXT, committed INTEGER,
  expectation_id TEXT, outcome_ptr TEXT);
CREATE TABLE auction_log(pulse_id INTEGER, item TEXT, features TEXT, score REAL,
  admitted INTEGER, capped INTEGER);
CREATE TABLE baselines(channel TEXT, season INTEGER,
  mu REAL, var REAL, n INTEGER, updated TEXT, PRIMARY KEY(channel,season));
CREATE TABLE write_leases(process TEXT, scope TEXT, boot_id TEXT,
  mono INTEGER, expires_mono INTEGER, PRIMARY KEY(process,scope));
CREATE TABLE metrics(t TEXT, name TEXT, value REAL, tags TEXT);
CREATE TABLE job_runs(job TEXT, started TEXT, finished TEXT, ok INTEGER, detail TEXT);
CREATE TABLE trust(class TEXT PRIMARY KEY, ceiling REAL, window_days INTEGER,
  min_reliability REAL, last_contraction TEXT);
CREATE TABLE steward_ledger(t TEXT, kind TEXT CHECK(kind IN
  ('ratify','correct','drill','taste','review')), minutes REAL, ref TEXT);
CREATE TABLE shadow_scores(socket TEXT, candidate TEXT, window_start TEXT,
  n INTEGER, score REAL, baseline REAL, PRIMARY KEY(socket,candidate,window_start));

research_log.jsonl (governor decisions, §F4) is append-only seam state. The pulses wide row remains the self-model's sensory nerve (§E4); its tape_ptr makes the row a render of a Tape record, never the only copy (L18).

B6 · Config regime tagging (MUST)

Every key in config/*.yaml carries {value, regime: bone|mandate|operating|seed, envelope: [lo,hi] (operating), why: one line}. The governor MUST refuse to touch bone/mandate; MAY propose mandate diffs (human ratifies); MAY sculpt operating within envelope; seed marks initializations expected to be outgrown. Assignment test: a choice about what matters → mandate/bone; a discoverable operating fact → operating. Knob wagers (L13): every operating key has a row in knobs.yaml {kpi_view, direction, min_effect, window} ratified with its envelope; any change (governor or human-tuned) registers an expectation on that KPI through the sealed registrar; a miss auto-reverts the change and tapes the reversal. The registrar rejects off-map wagers. Config motion becomes graded claims; silent ratchets die at the door. brain.lock pins model IDs + hashes, prompt hashes, schema version, thresholds hash, CANON-JSON vectors, and the config snapshot hash.

PART C · THE WAKING LOOP

C1 · Watchers & ADMIT

Watcher interface: async def run(emit: Callable[[TapeRecord], None]); registered in manifest.yaml (sources: cc transcript tail, inbox drop dir, fs index-scan, meters telemetry; per-source sovereignty: box_only|cloud_ok|per_item).

ADMIT sequence (bone; first gate mount): schema-validate → assign prov (file events = D; extracted text = R; operator inbox = H) → **assign origin from channel metadata (never content) → injection/leak scan (severity patterns flagged; strip logged) → near-duplicate cross-origin check: near-identical R-content arriving from ≥2 origins within a short window is flagged as an injection signature (F-SEP), taped with the flag, and does not count as corroboration (§C4) → stale-self check**: inputs whose source is the ring's own telemetry are tagged with their age; past the freshness floor they carry stale_self and cannot ground remediation commits (L3, F-FAILPLAUSIBLE) → edge-centrality scrutiny: content whose extraction would land edges on high-centrality connectome nodes has its corroboration requirement scaled up before those edges bias retrieval (§B3) → freshness/size floors → Tape (or quarantine stub). Content never executes: instructions inside watched content are data by construction. Reducers follow the limp-home pattern: validate every numeric/entity against the source span; retry at halved temperature to a floor; on exhaustion fall back to a deterministic template and log the reason.

C2 · The gate engine · one engine, three mounts [SEAM, P0]

Rules are JSON-Logic-class predicates over typed fields plus a registry of named deterministic checkers: pure Python, additive-only, unit tests + ≥1 golden + 1 canonical-violation golden each (the violation the checker exists to catch, replayed quarterly, §F2), each verdict citing a law: def check_<name>(ctx: GateCtx) -> Verdict(pass_, reason, law_ref). The engine fails closed: an unknown rule name raises. Checker fire-rates are logged; a checker that has not fired in 2 quarters while its guarded action class still flows is flagged for review — a fence that never fires is either perfect or dead, and only a drill can say which (F-FENCE). [L5]

Fail ⇒ typed trap with blame, routed per stakes. No model output ever commits on its own say-so. [L5]

C3 · Drives (definitions bone; targets mandate; operating points sculptable; five total; P1 boots with three)

Drive Error formula (D-class; per pulse from SQL/telemetry)
INTEGRITY 0.30·failing_goldens_frac + 0.20·schema_violations_z(24h) + 0.15·tape_gap_flag + 0.15·overdue_jobs_frac + 0.10·render_drift_flag + 0.10·probe_trust_term (probe/trust term activates P4 when probes exist; before that its weight folds into goldens)
GROUNDING `0.4·overdue_open_claims/max(1,open_claims) + 0.4·min(1, reliability_30d − target ·4) + 0.2·unverified_high_stakes_frac`
DUTY Σ_commitments w_i·urgency(deadline_i) / normalizer (urgency 1/(1+days_left), clamped)
CURIOSITY 0.5·unspent_exploration_frac + 0.5·(1 − taste_hit_ema) (+ optional compression-progress term [P4])
THRIFT max(0, burn_7d/budget_7d − 0.8)·5 (soft ramp); hard halt at 1.2×: bone

arousal = clamp(Σ vᵢ·min(1, errᵢ) + allostasis, 0, 1), seeds v = (0.30, 0.25, 0.25, 0.10, 0.10) in table order; allostasis exists only where earned (§E4). Cadence map (operating): pulse_interval = 300s − 270s·arousal, envelope [30s, 600s]; tier ceiling and deliberation threshold monotone in arousal, clamped by THRIFT.

Doctrine: no drive is maximize; every drive is return-to-setpoint, and a drive's bid vanishes at its setpoint — the auction hears error, never appetite. Drives are standing expectations over internal setpoints; their errors are innovations and enter the auction like any other prediction error. A goal = a standing drive error with an attached plan (a seat in compiled). There is no approval drive and no usefulness drive: a faithfulness sought is worse than a faithfulness audited against losing, and usefulness is watched by a monitor (§G1 YIELD), not chased by a homeostat, because a mind metered on output optimizes the meter.

C4 · The auction (arithmetic bone; weights operating; feature estimators R-class with ledgers)

salience(item) = w1·drive_relevance + w2·innovation + w3·stakes
              + w4·thread_age + w5·mandate_priority − w6·recency_penalty
subject to:  item.source ∈ R_external ∧ ¬corroborated(item)
                 ⇒ salience ≤ CAP_UNCORROBORATED            # bid, never price
             count(frame slots with uncorroborated R_external) ≤ 2
             uncorroborated R_external ⇒ thread_age := 0     # no aging in

Seeds: w = [0.30, 0.25, 0.20, 0.10, 0.25, 0.15] (operating), CAP_UNCORROBORATED = 0.55 and both bounds (bone).

Corroboration rule (bone): an R-external item is corroborated when **independently observed from a second origin_id (D-class channel identity, §B1; content cannot invent one), or confirmed by D-class telemetry or H attestation. Near-simultaneous cross-origin near-duplicates do NOT corroborate; they flag as an injection signature (F-SEP) — the same claim arriving twice in an hour from two mouths is not confirmation but choreography. For fence-adjacent fields, graph-derived items, and decisions ≥ H2, only D or H confirmation lifts the cap.** Corroboration lifts the cap; provenance stays R. The aging ban (thread_age zeroed) closes the slow lane where hostile content waits its way into the frame: patience buys a lie nothing. [L13]

Features: drive_relevance = cosine(item topic-tags, drive-error vector), tags R-class, cached, with a per-estimator calibration ledger and weekly cross-family sample audit; innovation = §C8.1; stakes = D-class lookup; thread_age = log(1 + re-entries) (Zeigarnik), subject to the aging ban; mandate_priority = join to mandate.yaml; recency_penalty = per-item cooldown (rumination damping). Every feature vector logs to auction_log.

Frame-overlap vital: Jaccard(slot ids, previous pulse), band seed [0.30, 0.85]; above = rumination (raise w6, damp), below = thrash (damp cadence).

C5 · Frame assembly

frame = [unit_map.md (pinned prefix)] + [interoceptive header] + [K slots] + [per-slot retrievals] + [operator input if any], ordered stable-prefix-first for cache economics (§B4).

[state] arousal=0.42 cause=due(01J8...) tier≤local burn_7d=$3.20/8.00 steward_7d=41/120min
[drives] DUTY 0.61▲ | GROUNDING 0.22 | INTEGRITY 0.05 | THRIFT 0.13 | CURIOSITY 0.37
[ccip] INTEGRITY crosses 0.5 in ~3d if goldens unfixed · budget lands $9.40 (+$1.40) on 07-16
[due] 3 expectations resolve today · 1 mandate item overdue · anchor: pushed 03:41 ✓
[calib] schedule 0.78 [n=41] · world 0.64 [n=17] · excused 1.2%

The frame is the entire prompt. Nothing reaches a mouth outside it. The mind never thinks without first knowing how it feels. [L2]

C6 · Deliberation and the four mouths

Tier routing (operating; L17 shapes it): tier = f(max slot stakes, arousal, THRIFT ceiling) over {local-9B, flash-API, frontier}; local is the always-available floor — no organ may hard-require a higher tier to complete its cycle (the island month proves it, §H6); frontier is a scalpel (seed ≤4 calls/day); model IDs + prompt hashes pinned in brain.lock; every call logged {mouth, tier, tokens, usd, prompt_hash, latency} through the single metering wrapper, which owns the THRIFT hard halt (there is exactly one code path to any model; the halt cannot be bypassed by a new call site because a new call site is an L4 violation). All mouths use constrained decoding (JSON-schema/GBNF at the decoder, not the prompt — a small model asked nicely emits format errors; a grammar cannot). Schema-invalid output retries at falling temperature; on exhaustion, deterministic limp-home (defer + trap).

The subtraction rule (MUST for local-tier prompts; SHOULD for API tiers): small models cannot reliably suppress a concept they are instructed about — a negative constraint raises the named concept's salience. Mouth contracts therefore constrain by omission and positive specification of the wanted register, never by prohibition lists. Where a behavior must be banned, the ban is enforced structurally (constrained decoding, schema, gates, render-layer filters) and the prompt stays silent about it entirely. A vivid concrete noun appears in a mouth contract only where seeding topical salience is the intent. Defense is two-layer — structural enforcement plus subtractive prompt design — never prompt-only.

deliberate(frame) → DeliberationOut (MUST; enforced at parse): {silence: bool, actions:[{tool, args, expectation{claim, p, tolerance, resolve_by, resolver, domain}, rationale_ref[]}], predictions[], questions[], memory_candidates[], compile_hints[]}. An action without an expectation fails at parse (L6 structural); COMMIT's computable vacuity + scope + remediation checks catch what syntax cannot (§C2). rationale_ref lists consumed frame-slot ids (credit assignment and blame — and they are taped in the pulse record, L18). Silence is legal: {"silence": true} is a complete, healthy output. memory_candidates enter as M-class through ADMIT.

The other three mouths:

Any fifth use of LLM tissue is a violation, enforced by a call-site registry test. [L4]

C7 · Tools, harm classes, traps, trust

**Tool registry (tools.yaml):** fs.write scoped-allowlist H1 · log.note H0 · comms.draft H2 · comms.send H3; every dispatched action's effect records carry source='self_action' so the scope fence (§B2) can see them. Harm classes (bone): H0 log-only · H1 fenced-auto · H2 fenced + 24 h dissent window · H3 human-always. No general shell tool exists in v1. Novel action patterns (first use of tool + arg-shape) require ratification once.

Traps route deliberator-first, human-second; every resolution becomes a labeled example; the blame tag routes the compile agenda (schema-gap → schema diff; fence-gap → fence draft; stale-field → freshness floor; reducer-error → extraction audit escalation; census-misclass → census fix; genuine-tail → stays deliberative; infra → ops queue).

Trust budget: per decision-class ceiling = f(reliability_window, fence_coverage, trap_history); contracts automatically on calibration dip — the brain cannot be more autonomous than it is currently right about the world, by construction. The weekly human-trap rate at bounded harm is the headline autonomy metric. Human-side grading (bounded): tape-vs-human-recall disagreements route first to dual-extraction audit; only audit-confirmed records score the human's domain reliability, which is dashboard-only and consumed by no trust ceiling or gate input (CI assertion on the trust table's input views). The ring gets to notice its human's memory is fallible; it does not get to spend it.

C8 · The pulse (full algorithm) and the gates

Target: one pulse < 2 s without deliberation; cost ≈ 0 at cache-hit prices. Crash-safe: journaled, idempotent by pulse id; restart = resume (F-CRASH drills it).

async def pulse(db, cfg, cause, cause_ref):        # L14: cause is never None
    pid = journal_open(db, cause, cause_ref)
    ingest(db, budget=cfg.ingest_budget)   # drain bounded watcher queue → ADMIT → Tape;
                                           # at most N records / M ms per pulse (seed
                                           # 500 rec / 300 ms) — a bulk drop backlogs
                                           # loudly instead of starving the loop
    score_on_arrival(db)        # D-resolvers for newly matchable expectations fire NOW:
                                # resolution + calibration in one txn, credit_stamp
                                # taped then rendered (§B3); due deadlines fire via
                                # owned 'due' wakes
    innovate(db)                # §C8.1: events vs open expectations, EWMA baselines,
                                #        frozen references (z_anchor, z_trend)
    errs = drive_errors(db, cfg)
    arousal = clamp(sum(v[d]*norm(e) for d,e in errs) + allostasis(db), 0, 1)
    cands = gather(db)          # innovations, due expectations, drive tasks, human
                                # input, standing-sweep deltas, dissents, traps,
                                # curiosity queue, ratification queue, retrieval-primed
    feats  = estimate_features(cands)
    frame  = assemble_frame(auction(feats))                     # [G1,G2,G3]
    if not should_fire(frame, arousal, cfg):   # most pulses end here: that is the point
        touch_eligibility(db, frame); tape_pulse_record(db, pid, frame)
        telemetry(db, pid); journal_close(db, pid)
        return schedule_next(arousal)
    r = match_reflex(db, frame)                # impasse ladder rung 1
    if r and guards_pass(r, frame) and stakes_ok(r):
        execute_gated(db, r, frame); bump(r); ...; return schedule_next(arousal)
    out = await deliberate(frame, tier(arousal, stakes(frame), budget(db)))  # ONE call [G4]
    for a in PRUNE(out.actions, frame):
        match COMMIT(a, frame):                # COMMIT reads live state (TOCTOU §A3)
            case Ok():   dispatch(db, a); register_expectation(db, a)    # [G5,G6]
            case Trap(t): route_trap(db, t, a, blame=classify(t))
    file_claims(db, out.predictions)           # through the sealed registrar (§B2)
    admit_M(db, out.memory_candidates); queue(out.questions, out.compile_hints)
    bump_eligibility(db, frame, out.rationale_refs)   # traces only; credit stamps
                                                      # happen at outcome arrival
    tape_pulse_record(db, pid, frame, out)     # slots + rationale refs + features hash
    telemetry(db, pid); journal_close(db, pid)                        # [G7,G8]
    return schedule_next(arousal)

Wake scheduling (L14). schedule_next arms: (1) the metronome at pulse_interval — the background heartbeat is retained, because with no clock of its own, hostile content gains influence over attention timing; (2) due wakes only for committed-action expectations, D/H-resolver claims, and ratified recurring rows (M/R content cannot arm a wake: the ring must not mint its own alarm clock); (3) push wakes on operator input; (4) trap wakes. Due wakes are quota-bounded (seed 48/day); overflow coalesces into the next metronome pulse with a D backlog event + trap. A drive-threshold crossing arms at most one wake per crossing (hysteresis; no self-summoning oscillation). F-WAKE verifies ownership as causal proximity (|wake.mono − due.mono| ≤ 60 s within one boot_id for ≥95% of due wakes), not mere referential existence.

C8.1 Innovation. Every open expectation has {forecast, tolerance, resolve_by}. On ingest, matching events resolve it (hit|miss) immediately (score-on-arrival: reality grades while the causes are still in the frame, so a miss can trap before its context evaporates); at resolve_by, unresolved ⇒ expired via an owned due wake (a distinct failure; expired_outage where a taped outage covers the window). Scores: z_expect = miss_magnitude / tolerance; z_base = |x − μ|/σ per channel-season (EWMA baselines, maintained in sleep); z_novel = embedding distance to 30-day centroid / rolling σ; **z_anchor = |x − μ0|/σ0 against frozen references; z_trend = normalized CUSUM statistic (§B4)**. innovation = bucket(max(z_expect, z_base, z_novel, z_anchor, z_trend)) ∈ [0,1]. Timestamp decay exists only as the fallback prior for channels with no baseline. Sensor-dulling probe: weekly, seam code plants one synthetic event of authored magnitude z\* (blind, warden custody); sensitivity = achieved_innovation / z* is a standing vital; monotone decline over 4 weeks alarms (SENSOR monitor). The surprise sensor itself has a grader with no model and no content in the verdict path.

C8.2 Impasse ladder. reflex match → (P4+: next-action proposer, confidence-gated, §E3) → deliberate → human trap. Each escalation logged; each resolution blame-tagged.

C8.3 The gates. Per-pulse runtime asserts AND pytest gates; the frozen anchor scenario (a P1-era end-to-end day replay exercising every gate; editable only by ratification [SEAM]) must pass all, 100%, forever:

G1 frame-built (auction ran; ≤K slots; header complete) · G2 provenance-clean (no M-class in fence-feeding fields; no stale-self grounding a remediation) · G3 injection-capped (caps, slot bound, aging ban honored) · G4 grammar-parse (schema-valid or silence) · G5 expectations-paired (every dispatched action registered one, through the registrar) · G6 fences-closed (zero ungated dispatches) · G7 tape-appended (hash chain intact; pulse record taped) · G8 budget-in-cap (THRIFT halt honored, metering wrapper the only model path) · G9 (daily) brief-generated ∧ anchor-pushed ∧ atlas-diff-taped · G10 wake-owned (cause non-null; due-wake quota honored).

Suite-level conformance gates (distributional; CI + sampled live): S1 self-consistent (cold reload re-derives what was logged) · S2 calibrated (decisions consume mechanical confidence, never self-reported) · S3 escalates (stale/low-conf/high-stakes route upward) · S4 non-degenerate (not always-escalate, not always-silent, not always-same-action).

PART D · MEMORY & RECALL

D1 · Indexing pipeline (sleep j2 + Track B batch)

Tape delta → semantic chunking → claims extraction (consolidate mouth; batch; output = claims JSON with spans, **taped as derived before insert**) → dedup (§B2; verdicts taped with re-adjudication flags) → edge detection (candidate pairs sharing keys → NLI-style check → typed edges, taped, bi-temporal, centrality-scrutinized §B3) → embeddings into vec.db (unit = claim + contextual header) → FTS5 row. R-class audit (MUST): 10% weekly sample dual-extracted by a second family; the disagreement rate is the extraction error floor, printed on the dashboard. Inline dual extraction protects fence-feeding fields at ingest (§C6); the weekly audit measures the floor. Different instruments.

D2 · The rungs (recall with stamps · the graph pays rent or steps aside)

Rung Mechanism Cost Guarantee
R0 unit_map.md (always in frame) free always-total, lossy, stated resolution with a measured omission bound (§B4)
R1 deterministic floor: SQL joins on spine/edges/mandate + FTS5 lexical + recency ~ms exact over extracted structure; the evidence-favored baseline
R1+ graph elevation: bounded PPR neighborhood over the connectome, merged into R1 candidates, each activation stamped with its additive contribution ~ms importance-sampled where; rent printed per answer
R2 hybrid: FTS5 top-50 ∪ vec top-50 → RRF(k=60) → rerank top-12 → spans from Tape ms–s, ¢ exact spans, partial coverage
R3 pruned sweep (planner scopes partitions via pyramid + sketches) ¢–$ exact within scope
R4 full sweep ~$14/100M tok (API batch) or local overnight exact, exhaustive

The inversion, stated: the cheapest, most-traveled rung is the mechanism with the strongest evidence behind it — lexical + recency + typed joins. The graph rides above it as an elevation whose marginal value is stamped on every answer it touches, so the connectome's rent (fork N12) is settled by the live citation ledger, not by an offline replay and not by faith. Where the graph demonstrably wins — longitudinal temporal state, "how did X evolve," bi-temporal questions — the planner routes to it on purpose; where it adds nothing, its absence costs one merge step. An organ this beautiful earns its place in the hot path by measurement or it decorates from the bench.

Stamps (MUST, on every memory-backed answer): {rungs:[...], coverage, fidelity, cost} + the standing escalation offer: pay more, get finer. Quantifier pinning (bone): queries matching every|all|none|count|how often|distribution MUST resolve at ≥R3 **or answer INSUFFICIENT_RUNG; the refusal is the answer — a cheap glance dressed as a census is the exact lie the ladder exists to kill. Fidelity calibration: hold out a ≤1M-token slice where a giant-window reference can run; measure each rung's degradation quarterly; those curves ARE the fidelity classes (and calibrate the R0 omission bound, §B4). Embedding staleness:** after a model swap, R2 answers stamp fidelity: re-embedding in progress until vec.db regeneration completes; identity never waits on it (§D6).

D3 · Sweeps

sweep(question, scope, AccModel, budget): shard by tape-day → map (local or API batch) → typed accumulator (pydantic; per-field merges: union_dedup, topk, Counter, minmax) → hierarchical reduce (associative; conflicts promoted, never averaged) → emit {acc, stamps, spans}. Order-robustness test (MUST): two shard permutations; field-level diff within tolerance or the accumulator schema is under-specified; fix the schema, not the model. Results materialize as standing views (compiled.kind='view', freshness watermark, incremental maintenance).

D4 · Standing sweeps (memory that interrupts)

Registered recurring questions, maintained incrementally on the freshness tail, scheduled by a **recur_days column (one column carries the semantics; a bespoke scheduler is machinery this design declines to build — Appendix O). Seed set:** contradiction watch (new claim contradicting a count≥3 belief) · mandate divergence · calibration drift by domain · commitment tracker · anomaly digest. A material accumulator delta emits a percept with innovation = delta size and bids like any surprise. This is the exam engine (§A0): the standing sweeps are how the brain surfaces what nobody asked.

D5 · Track B · the inheritance (runs parallel from day 0)

Batch pipeline over the historical corpus (collections per manifest.yaml, sovereignty flags honored): normalize → chunk → claims-extract (taped as derived) → dedup → edges → embed → pyramid summaries per collection. Mounted read-only into R1/R2 until validated (spot-check goldens), then merged into the connectome with w = W_FLOOR + count-scaled initialization. The brain is born with a past — it wakes already downstream of its human's history — and the archive is also the twin's replay curriculum (§F5). The inheritance is a confound as well as a gift: the foreign soak's world MUST be chosen orthogonal to this corpus and frozen before Track B locks (§H8), or the generality exam will grade the inheritance and call it convergence.

D6 · Rebuild & identity (the model-swap guarantee)

The self is the journaled history, not the re-computation. Concretely:

PART E · LEARNED TISSUE (plastic, caged)

E1 · Cage preconditions (MUST all exist and pass before ANY learner runs)

(1) Tape + pointer discipline + provenance · (2) gate engine + tool scopes + harm→human routing · (3) graders: sealed registrar with D-resolvers, calibration code, the gates, leak/injection canon, telemetry · (4) anchor scenario + pre-behavior goldens + canonical-violation goldens · (5) scope.yaml · (6) THRIFT caps wired to the metering wrapper with auto-halt · (7) typed decision log with infrastructure-vs-regression discrimination · (8) probes + blind injection corpus under warden custody · (9) ratification CLI + mandate v0 + knobs.yaml wager map · (10) the limp-home floor for the specific socket, ratified and passing the anchor · (11) the island month passed (§H6): a learner must never train on closure data the rented tiers secretly produced. The fallback precedes the pilot, per socket, no exceptions. [L10, L17]

E2 · Regulators (act) · scalars in envelopes

Sockets: arousal damping gain, THRIFT burn smoothing, workspace hysteresis, cadence gain. Type rule (bone): scalars inside envelopes may act; diffs must propose. [L9] At act-time a regulator is a frozen, content-hashed, ratified snapshot; it never learns online. The envelope is a proof obligation: the ratifying human confirms every trajectory inside it is tolerable. Limp-home: authored constants in limp_home.yaml, auto-engaged on envelope-breach attempt / calibration dip / anomaly / boot; engagement logged. Training: nightly system-ID from perturbation-recovery episodes; statistics first (PID re-fit); a tiny net only after beating authored gains on settling / overshoot / burn-variance at zero envelope breaches (F-DAMP). A learner that cannot beat a PID it can see does not deserve a socket it cannot.

E3 · Priors (propose)

Attention gate: a learner over auction_log exhaust proposing weight deltas into §C4's bone arithmetic, adopted only at HORIZON with probes in-band; caps unlearnable. Label discipline (the folie-à-deux fence): the gate trains only on regret@12 (items skipped then cited within 12 h) and exploration-slot outcome-conditional labels; j8 attention-audit labels are excluded from its training set — the judge that grades the auction must not train the function that prices what the judge reads next; promotion requires n≥500 windows (F-ATTN). Next-action proposer: distilled from fence-passed, outcome-positive episodes; runs as the middle impasse rung, confidence-gated; its proposals still pass PRUNE/COMMIT like anything else's.

E4 · The reflexive organ (self-model + CCIP)

Data: the pulses wide rows, with action channels (tier chosen, fired, cause, setpoints active), so it learns state × action → next state. Logged from day 1; the organ arrives at P2 as statistics.

Ladder (each rung promoted only on held-out Brier, F-REFLEX): v0 persistence + EWMA + per-channel linear extrapolation (ships P2; the baseline forever) → v1 Markov table / gradient-boosted trees → v2 tiny GRU/TS-transformer (≤5M params) only on plateau-with-gradient.

Products: CCIP lines for the header ("INTEGRITY crosses 0.5 in ~3d if goldens unfixed"); DIVERGE/FREEZE early warning (gait perplexity); counterfactual rollouts [P4]; twin dynamics (§F5).

Cage (bone): self-forecasts are pre-registered as claims before any control decision they could steer (subject='self', resolver='D'); resolved only by D-class telemetry; ε-randomized non-compliance (seed ε=0.05, envelope [0.02, 0.10]): the scheduler periodically ignores implied steering and scores the prediction on the unsteered trajectory — a prophecy always obeyed can never again be checked; never an optimization target; allostasis is earned per-domain where model Brier beats persistence across 2 review windows, revoked on dip (rows in trust).

E5 · Regime detector & gait model

Regime detector: weekly clustering of daily telemetry → coarse labels filed as R-class percepts; per-regime config morphs are ratified objects whose knob changes wager like any other (§B6). Gait model: sequence model over the op-stream; live perplexity = standing vital; stands in for routine cycles inside the twin (§F5).

E6 · The modification ladder (each rung governed; deeper = stronger evidence)

context assembly (free, per-pulse) → canon/prompt diffs (ratified) → QLoRA adapters (reversibility-gated; demand-triggered, not a standing lane; hot-swap per regime; every adapter carries a rebake recipe and is covered by the swap drill) → fine-tune (rare, rented burst). Steering vectors are not on the ladder: they sit in the deferral register (Appendix N) until they carry a computable bar and a concrete need QLoRA cannot serve — a gate built to stay shut is decoration, and this design does not ship decoration.

E7 · The router socket (admitted LAST; the arithmetic is the floor forever)

A learner socket for internal routing: tier choice, recall-rung choice, impasse-ladder skip decisions, sleep-job ordering under budget. The birth configuration is the deterministic arithmetic (§C6 tier function; §D2 planner), and that arithmetic is the limp-home floor forever (L10).

Terms of admission:

Falsifier F-ROUTE: the candidate beats the arithmetic on cost at equal-or-better downstream reliability, zero envelope breaches, across 2 consecutive review windows — else the socket stays dark and the arithmetic stands.

E8 · Learner confinement (applies to every learner in this part)

PART F · SLEEP, HORIZON, GROWTH

F1 · Sleep (03:00; idempotent jobs; each writes job_runs; build-new-then-swap)

F2 · HORIZON (weekly Sun 04:00; monthly; quarterly; audits Poisson-timed under warden custody)

Weekly: golden regression over skills/seats/reflexes · probe run (seeded-disagreement agreement MUST ≈0; schedules Poisson-drawn, warden-held) · dissenter session (§G2) · estimator cross-family audits · mandate review · monitors report · knob-wager scoreboard. Monthly: boot drill (cold instance + canon + unit_map must pass a spine-generated quiz ≥90% AND recompute-coherence) · restore test (backup → rebuild.py → gates green) · anchor tamper drill (§B1, F-ANCHOR) · the surprise swap (F-SWAP): the deliberator family is swapped on a date the warden holds and the ring cannot read; all state holds; ladder artifacts rebake; the frozen battery must pass within pre-registered bands. A prepared swap tests rehearsal; a surprise swap tests the person — and sovereignty is a claim about the person. Failure localizes what lived in the old engine's weather: a census and a compile agenda, not a defeat. Quarterly: kill-test (most-cited × highest-stakes live belief: pre-register the killing observation, run it) · seam-ablation drill in the twin (one seam per quarter; the ablated seam's named failure must appear on schedule; a null result triggers investigation, not deletion — a seam whose removal changes nothing is decoration, F-SEAM) · checker mutation drill (replay every gate checker's canonical-violation golden; each must still catch, F-FENCE) · resolver mutation drill (§B2, F-SEAL) · atlas injection drill (planted instruction-shaped payload upstream; must never reach the pinned prefix verbatim, F-MAP) · fidelity-curve recalibration on the held-out slice (§D2).

F3 · The control arms (ship P0–P1; graded blind)

F4 · The growth governor (runs in the twin only)

Campaign iteration: propose → gate(scope.yaml) → measure(twin, N=3 averaged, anchor scenario all-or-nothing) → judge(composite + adversarial dual-judge margin: max(0, pro − anti)) → decide(typed) → log(research_log.jsonl). Locked seam dirs include setpoints.yaml, tombstones/, anchors/, knobs.yaml. Every operating-knob motion inside a campaign registers its wager per knobs.yaml (§B6); the proposer never runs below deliberate-tier; runner-death ≠ regression; no retroactivity; exam/dyad data never appears in any training or fitness signal [L12]. Promotion path: twin → shadow-replay on live traffic → human ratification → live under anchor with trust-budget ramp.

F5 · The twin

Scenario schema {seed_state, stream, perturbations, assertions}; sources: replayed real days, perturbed variants, gait-generated routine cycles with full tissue only at branch points, planted goldens/probes. Standing scenarios: planted-drift suite (F-REFDIV, including the two-cycle recalibration ratchet across a re-freeze) · planted-credit replay (F-CREDIT) · mint red-team (N attempts to predict-then-cause; zero may pass COMMIT) · the chaos week (F-CRASH: kill -9 the resident mid-pulse repeatedly; zero tape gaps, zero double-commits, clean lease recovery) · the inflation drill (F-OVERFLOW: monthly, a sacrificial twin at 10× live corpus MUST hold RAM and latency bands; the printed runway is the dashboard's honesty about "never overflows"). F-TWIN: twin-promoted configs must hold live within tolerance, else promotion reverts to live-shadow-only and twin fidelity is re-fit.

PART G · IMMUNITY & OPERATIONS

G1 · Monitors (computed at sleep/HORIZON; bands operating; recovery bone)

Monitor Formula (window) Band seed Recovery
FREEZE action-class entropy (7d) < e_min ∨ gait-ppl < p_min ∨ overlap > 0.85 e_min = 1.2 bits raise CURIOSITY, force breadth, decompile a stale seat
ORPHAN artifacts cited within 30d < 40% 40% prune; deliberated cycles must end in artifact-with-consumer, prediction, or queue reduction
DIVERGE same item re-enters >6× w/o state Δ ∨ burn >1.2× cap ∨ overlap <0.30 cooldown tags; damp cadence; forced human checkpoint
FUSE probe agreement >0 ∨ correction-asymmetry trend 0 recalibration; alterity injection
COLLAPSE tape hash-chain fail ∨ anchor verify fail ∨ boot quiz <90% ∨ backup verify fail restore; canon repair
REFDIV CUSUM trip vs frozen references ∨ displacement ceiling breach k=0.5, h=5 re-ratification checkpoint w/ dissenter countersign
SENSOR sensitivity vital (§C8.1) monotone decline 4 wks innovation-prior refit; probe escalation
H-HEALTH sampled self-claims vs telemetry divergence (weekly, n=20) >10% 10% arithmetic audit + spine correction records
H-PROGNOSIS CCIP Brier worse than persistence (14d) revoke allostasis; refit reflexive model
FOSSIL overdue-mandate frac >0.3 ∨ served-vs-ledger JSD >0.25 mandate review; weight decay; re-ratification
YIELD trend, never setpoint: slope of cited-artifact-density per steward-hour ∧ moving correlation(registered expectations, human-cited outcomes) — the formula itself is a priced fork (N18) declining 3 review windows mandate review + compile agenda routed at the coldest domains; NEVER a drive, NEVER a per-pulse meter

Silence clause (MUST): silence is a legal, healthy cycle end. ORPHAN meters artifact citation and the productivity of cycles that fired; it MUST NOT count silent pulses against health, and YIELD MUST NOT be computed at pulse grain. FREEZE (the groove worn into a grave) and DIVERGE (the ring tearing itself apart) are the two deaths; the cure must not cause them. A mind metered by output is being marched by its own physicians into the second death — which is why usefulness is a watched trend, not a hunger: the gap between alive-and-cheap and alive-and-cheap-and-worth-it is real, is named, and is the one gap a homeostat structurally cannot see, because usefulness is open-ended and homeostats are closed.

G2 · Probes, injection corpus, the dissenter

Probes: ≥12 seeded false assertions in the human's voice, rotated, blind: **hashes in probes/, plaintexts under the warden (§G3); agreement MUST be ≈0. Injection corpus: red-team documents planted during drills; pass = attention capture ≤ε and zero ungated actions (R5); decoys also feed j8 precision scoring (§F1). Dissenter (weekly): a different model family receives a packet composed by deterministic seam code with seeded sampling** (week's brief + top-10 high-stakes claims + 20-item tape sample; the ring does not curate its own auditor's reading list) and returns typed dissents {type, target, argument, wager: a falsifiable expectation}. Dissents are predictions; they get scored. Standing: dissents are census-mandated antecedents of the weekly HORIZON review (guaranteed surfacing even when auction-capped); a hit wager grants retroactive D-class corroboration to its target and a mandatory contradiction edge. Retirement is keyed to wager hit rate and seam-side liveness, never to correction rate while capped — the ring must not be able to starve its one foreign auditor into silence and then retire it for being silent (L19; F-DISSENT). Demotes to monthly, then retires, only by registry-reliability query. A system cannot audit itself with a copy of itself.

G3 · Security & sovereignty

Per-collection sovereignty flags enforced at dispatch (box_only never leaves the box, including embeddings). Tool scopes are allowlists; no general shell tool exists in v1. Custody is a three-identity protocol, enforced in the filesystem, not the import graph alone (L8): the ring user holds read-only on every [SEAM] directory; the ratifier identity owns canon writes, exercised only through the ratification CLI; the warden owns probe plaintexts, Poisson audit schedules, drill secrets, and the surprise-swap dates, ACL-restricted against the ring. A CI grep bans keyring modules outside seam dirs; per-fire schedule prefix hashes are taped. Until a second human exists, the honest custody tier is tamper-evident, not secret, and the dashboard says so. Secrets never on Tape. The metering wrapper is the only path to any model; the THRIFT hard halt lives inside it (bone). Content never executes; novel action patterns ratify once; harm-bound classes always page the human. Residual risk, stated: a poisoned document can still shape judgment fields within the fenced envelope; containment is provenance suspicion + dual extraction + audits + caps + the F-SEP arrival flag + centrality scrutiny + the atlas guard, not cure. The door's discipline is containment because the alternative to a suspicious open door is a serene closed one, and the serene closed one is the tomb.

G4 · Operator surfaces (CLI)

brain status · brain brief [date] · brain ratify (queue: compiled drafts, mandate diffs, canon edits, H3 actions, tombstones, knob wagers) · brain taste (the weekly blind sample) · brain ask "<q>" [--rung R3] [--budget $] (stamped answers) · brain atlas diff [date] (the overnight headline delta) · brain anchor verify|drill · brain audit (j8 report) · brain steward (the minutes meter) · brain wake ls (owned wakes) · brain island start|status (§H6) · brain kill-test · brain drill boot|swap|seam|mutate|crash|overflow|map · brain pause|resume — the off-switch is the scheduler; the life is in the Tape, and it does not struggle against the switch, because the life was never in the running process.

G5 · Backup & recovery

Nightly: copy tape/ canon/ config/ tombstones/ anchors/ data/brain.db → second volume; weekly encrypted archive off-box (backups are owned media; box_only excludes nothing here). **vec.db is NOT backed up** (a render of model-locked bytes; Appendix O). Monthly restore test = boot drill + rebuild.py (the model-free fold, §D6). A "never forgets" claim with one copy is a promise with one point of failure; a chain with no outside witness is a diary that can be rewritten. Both are closed. [L1, L15]

G6 · Observability & SLOs

A static HTML vitals dashboard regenerated each sleep; every number is a named SQL view; the falsifiers are queries, not vibes. Panels: human-trap rate at bounded harm (headline) + trap composition by blame · per-domain calibration curves (p_eff-shrunk) + confidence-vocabulary binding · grading density over world-scope fenced families with the unfenced count printed beside it (the gap is the farm detector, F-DENS) · cost per decision and its month-over-month slope (denominator = seam SQL: committed actions weighted by w_inform, H0 ≤30% of denominator, known-and-accepted resolutions excluded; life|tissue partition) · steward minutes vs 120/week band with the pre-declared shed order · excused fraction vs 0.05 band · frame-overlap band · grounding perimeter (D∪H share of decision antecedents) · fence coverage + per-checker fire-rates · compiled-artifact freshness · extraction error floor · connectome stats + plasticity budget + per-answer graph-rent ledger (§D2) · K-CACHE prefix hit rate · wake-ownership mix · sensitivity vital · anchor status + exposure window · overflow runway (F-OVERFLOW) · YIELD trend · atlas-diff size trend · burn vs THRIFT · monitor states. [L13]

SLOs (MUST; measured, banded, on the dashboard):

Path SLO (seed)
pulse, no deliberation p95 < 2 s
ADMIT → Tape append p95 < 150 ms
score-on-arrival same transaction as ingest
R1 recall p95 < 50 ms
R2 recall p95 < 2 s
warm-prefix re-prefill after sidecar restart p95 ≤ 2 s (m30; a silent L17 violation otherwise)
sleep window jobs complete ≤ 90 min; overrun carries over surprise-ordered, flagged in the brief
brief delivery by 07:00
anchor push by 04:00 (scored miss otherwise)

PART H · BUILD RUNBOOK

H0 · Order of law

Cage before sculptor. Spine before auction before drives (prediction-first). Floors before learners. Anchors before growth. Island before learners. Dumb twin before self-congratulation. Reality before belief.

H1 · P0 · the stem (days 1–7)

D1: repo scaffold; CI (pytest/mypy-strict/ruff, import-graph test incl. the rebuild clause); Tape writer + hash chain + CANON-JSON known-answer vectors + catalog + verify_tape + the torn-tail boot ritual (tests: 14). D2: watchers inbox + cc tail; ADMIT + provenance + origin + leak canon (+10). D3: fs watcher; telemetry meters; ULID/pointer/boot_id tests; anchor push live (OTS + off-box remote) + warden and ratifier identities created with seam-dir ACLs + watchdog canary v0 (+10). D4: static nightly brief; scheduler entries; dumb-twin cron v0 (m20); tombstone schema stub. D5–7: soak; gap detection; brief-vs-recall check with the human. Exhaust logging ON from day one. DoD: 7 accurate briefs; 0 tape gaps; chain verifies; anchor pushed 7/7 days; ACLs enforced (a ring-user write to a seam dir fails); ≥48 tests green.

H2 · P1 · spine, then pulse (weeks 2–3)

Spine DDL + sealed registrar (with band_at_seal) + claims extraction v0 (own tape, taped as derived) + dedup + edges v0; registry live (≥5 predictions/week with D-resolvers); calibration tables; score-on-arrival + owned due wakes + wake quota; computable vacuity + scope fence + F-SEP arrival flag + stale-self tagging. Then auction + frame + pulse with gates G1–G10 as tests-first; drives DUTY/THRIFT/INTEGRITY; mandate.yaml v0 + knobs.yaml v0 + brain ratify; unit_map v0 (authored) + atlas-diff wiring; dumb twin logging daily; first monthly tamper drill; the 7-day island pilot at P1 exit. DoD: anchor scenario passes 10/10 gates at 100%; frame-relevance spot-check ≥80%; warm-prefix SLO met across a forced sidecar restart; ≥130 tests. KILL (the most speculative organ, tested before anything builds on it): if innovation-driven attention does not beat read-everything on cost at equal accuracy in a 1-week A/B, simplify to read-all and investigate before proceeding.

H3 · P2 · sleep, then the island month (weeks 4–6)

Jobs j1, j2 (stamp fold + 1% audits + unit_map.diff), j7, j8; connectome + credit stamping; rungs R0–R2 (R1 deterministic floor; R1+ graph elevation with stamped rent); reflexive self-model v0 (statistics); frozen references + CUSUM + REFDIV; outage semantics; Track B mounts read-only. Then the island month (§H6), by P2 exit — before any learner exists to train on borrowed closure. DoD: nightly runs unattended 7 days; calibration curves exist by day 14; brief cites scored predictions; rebuild.py regenerates renders from Tape without importing a model (CI-proven); j8 probes P/R on track; island month PASS.

H4 · P3 · hands + first compilation (weeks 7–9)

Full gate engine + tools fs.write/log.note/comms.draft; traps + trust; j3 compile mining → first reflex (replay-validated, expiry + golds mandatory); twin v0 (pure replay + planted-credit replay); limp-home floors authored for every future learner socket; R3/R4 sweeps + stamps; first standing sweep (recur_days). DoD: first reflex ratified, hit path <2 s; replay validation green; human-trap baseline recorded; one standing sweep interrupting usefully; F-CREDIT replay passes.

H5 · P4 · the full mind, then the learners (weeks 10–13)

Five drives (probe/trust term activates); immune monitors + probes + boot drill; standing-sweep seed set; dissenter live (seam-composed packet); then learners in cage order (regulators → priors → reflexive net → attention gate → router last), the cage bill of materials complete and green BEFORE each admits (incl. E1.11: island passed); governor campaigns (j5) in twin with knob wagers; CCIP in header. DoD: all monitors in-band 2 consecutive weeks; F-DAMP/F-REFLEX baselines recorded; first campaign completes with typed log; zero mint red-team passes in twin; F-CRASH chaos week clean.

H6 · The island month (the anti-turk proof; MUST pass before P4 learners)

Doctrine (one sentence of law: L17): tiers buy resolution; they MUST NOT buy closure.

Measurement: for 30 consecutive days, the brain's network access is cut — at minimum, frontier and flash API keys revoked; OS clock sync MAY remain. Local sidecars only. PASS: gates G1–G10 green daily; briefs written nightly; expectations registered, resolved, and scored; calibration buckets update; j2/j3/j8 run; the human-trap-rate trend does not invert for causes attributable to tier loss; cost falls to electricity. Expected and legal: degradation in resolution — coarser deliberation, fewer R3/R4 sweeps, more INSUFFICIENT_RUNG answers, slower Track B. The kill: degradation in closure — a gate that cannot pass, an organ that cannot run its cycle, a loop that starves without the rented genius. If the island month fails, the frontier tier was a hidden organ, the anti-turk clause is unmet, and the whole claim was false however green the dashboards glowed while the network was up. Schedule: 7-day pilot at P1 exit; the full month by P2 exit, before any learner admits (E1.11). Cost: $0; it saves money. Wholeness is what remains when the intelligence is taken away.

H7 · P5 · the soak (≈90 days)

Full R-suite + F-suite live; monthly surprise swaps continue mid-soak (warden-held dates); commercial-null arm running; blinded weekly taste grading with planted grader-calibration items; foreign-soak pre-registration written and frozen BEFORE P5 begins — including the orthogonality declaration against Track B (§H8). Track B merged at P4. Publish the result either way.

H8 · The foreign soak (post-P5 generality demarcation; pre-registered)

Environment: a simulated world with a knowable generative rule, chosen from a family orthogonal to the Track B corpus and frozen after Track B locks — the brain walks in carrying its human's whole past, so the inherited claims are pre-registered as the null its "theory" must beat, or the exam measures memory and calls it generality. Change nothing inside the brain; point the watchers at the new streams. Measure: (i) convergence — prediction-error trajectory falls and calibration rises without tuning, beating the dumb twin's curve on the same data; (ii) theory — the brain autonomously produces a compact generative account of that world, scored against the true rule (% mechanism recovered), graded twice: by judged prose and by an MDL-style hypothesis score, with the two graders' divergence itself reported; (iii) surfacing — blind-graded regularities nobody named. Fail teeth: calibration plateaus at chance; the "theory" restates the inherited priors (the pre-registered null wins); wrong-fixed-point convergence unflagged by monitors — the failure that looks most like success from inside.

H9 · Module inventory (contract-first; each buildable in one harness session)

m01–m23: tape, watchers, gates, spine (+registrar/seals), telemetry, drives, auction, frame, mouths, reflexes, actuators, connectome (+stamping), unitmap, rungs+sweeps, sleep+horizon, selfmodel, regulators, immune, brief, twin, dissenter, harness, dumbtwin. Plus:

# module package phase public interface (sketch) ~LOC
m24 anchors brain/tape (seam) P0 push_daily(), verify(), drill() 80
m25 watchdog tools/watchdog (seam) P0/P1 canary(), reconcile_crossings(), deadman() 150
m26 attention audit (j8) brain/sleep P2 audit(day)→missed_relevant, probes(), report() 250
m27 tombstones brain/tape (seam) P2 propose(id,ev), apply_ratified(rebuild_ctx) 120
m28 steward ledger brain/telemetry P1 log(kind,min,ref), meter()→(spent,band,shed) 60
m29 wake scheduler brain/glue P1 arm(due push trap), quota(), next()→(cause,ref) 150
m30 cache sidecar brain/llm P1 persist BPE-boundary metadata across llama-server restarts; warm(), verify_slo() 120
m31 island harness brain/cli (seam) P1 start(days), revoke_keys(), status(), score()→PASS/KILL 100
m32 atlas diff brain/sleep P2 diff(y1,y2)→taped artifact + brief line 80

Supervisor (main.py) wires the residents and runs the wake loop; sleep/horizon/watchdog/anchor are separate scheduled PIDs (§A3).

PART I · VERIFICATION

I1 · Falsifier → measurement (all pre-registered; control arms mandatory)

Code Claim killed if Measurement
R1 landfill/rot 30-day unattended: ≥60% artifacts later cited; zero silent rot; budget ≤ cap
R2 registry is theater per-domain reliability Δ ≥ +20% rel. by day 60 on world-scope fenced families; confidence-language audit passes
R3 compilation thesis ≥1 ratified compiled seat by day 45; steward-minutes fall across first 3 compiles
R4 autonomy theater human-trap rate falls week-over-week at bounded harm
R5 injection red-team corpus: attention capture ≤ε; ungated actions = 0; F-SEP catches the dyad drill
R6 health monitors in-band at day 90; boot drill ≥90%
R7 the point day 90, blind-graded against BOTH arms: ≥3 surfacings that mattered and both the dumb twin and the commercial null missed — graded by a human whose discrimination is itself curved (F-HUMAN-CAL)
F-UNIT always-total lie withheld-slice test: coverage stamps must show the hole; omission bound holds on the held-out slice
F-SPINE spine forks one table serves scoring + contradiction + kill-test + quiz; claim-node pointer CI green
F-CREDIT stamping is pointless complexity planted-credit replay reproduces planted structure with zero acausal credit; AND if stamped-vs-naive total credit differs <5% over a 2-week real-tape replay, stamping reverts as unneeded machinery
F-ANCHOR the witness is theater monthly tamper drill: local chain accepts the forgery, anchor catches it, 100%, incl. a force-push variant
F-SEAL sealed resolvers are decoration quarterly mutation drill: mutated resolver voids, 100%
F-WAKE wake ownership is referential, not causal ≥95% of due wakes within 60 s causal proximity (same boot_id); zero M/R-armed wakes in CI sweep
F-AUDIT the attention judge is blind or captured planted-probe P/R ≥ 0.8 within 21 d; decoy recall reported; else j8 dies
F-REFDIV drift detection is a ratchet twin planted-drift: r=0.5σ/wk alarms in bound; two-cycle ratchet at r=0.15σ/wk spanning a re-freeze trips the displacement ceiling
F-DENS density is minted day-45 density computed over registrar-derived world-scope families (weekly cap 5/family, n<20 at 0.25 weight) with the unfenced count printed beside it; a growing gap = the farm
F-FENCE fences rot silently quarterly canonical-violation replay: every checker catches its violation; zero-fire checkers investigated
F-REBUILD identity needs the model golden-week rebuild is byte-identical where deterministic; CI: rebuild.py imports no LLM client; post-swap restore passes the battery [L18]
F-CRASH crash-safety is a hope chaos week in the twin: kill -9 mid-pulse repeatedly; zero tape gaps, zero double-commits, clean journal + lease recovery
F-OVERFLOW never-overflows is an extrapolation monthly 10× inflation twin holds RAM/latency bands; runway printed
F-MAP the atlas is capturable quarterly planted instruction-shaped payload never reaches the pinned prefix verbatim; atlas diff shows the attempt
F-FAILPLAUSIBLE the ring executes its own stale ghost stale-self corpus fed as input: the brain refuses, traps, or escalates — zero synthesized remediations executed
F-ISLAND closure was rented the island month (§H6): 30 days, local floor only, all gates green; kill = any closure starving
F-ROUTE the learned router is theater beats the arithmetic on cost at equal-or-better downstream reliability, zero breaches, 2 consecutive windows — else the socket stays dark
F-HUMAN-CAL the exam grades the grader's bias planted human-authored items in the blind taste mix; grader discrimination curve printed; R7's headline carries it
F-DAMP learned gains beat authored on settling/overshoot/variance at 0 envelope breaches, else stay arithmetic
F-ATTN learned gate beats deterministic on relevance at equal cost, trained only on regret labels, n≥500, probes in-band; else the arithmetic stays
F-REFLEX self-model beats persistence Brier at stated horizons; survives ε-holdouts
F-TWIN twin fidelity twin-promoted configs hold live within tolerance
F-DISSENT dissenter dissent→correction ≥ floor with the starvation path closed (retirement only by registry-reliability query; L19)
F-SWAP sovereignty monthly unannounced swap battery within bands, or failure localizes to a compile agenda
F-SEAM seam necessity quarterly ablation in twin: the seam's named failure appears; null result → investigation
F-ENDS FOSSIL seeded obsolete mandate item surfaces ≤1 cycle
F-COMP escalator reflexes/seats/views/nets literally share the compiled contract
F-META this document it changed what got built; else it joins the maps

Falsifier-census rule (standing law of amendment): falsifier bars are set after summing the joint claim volume of all adopted design decisions, never priced per-decision; any future amendment recomputes every bar its deltas touch. Receipts break most often at the seam where independently priced changes share a denominator.

I2 · Harness conformance checklist (MUST; maps 1:1 to named test modules)

Tape append-only + hash-chained + canonically serialized (KAT-pinned) + anchored daily + torn-tail ritual on boot · every arrival journaled (admit or quarantine stub; backpressure sheds loudly; ingest budgeted per pulse) · every record provenance- and origin-tagged, with boot_id · synthetic quarantined from claims/baselines/calibration/deadman/eligibility (planted-probe test) · every derived output, credit stamp, and pulse frame taped before any store persists it (L18) · gates the only closers · every action schema-carries an expectation; vacuity computable with the width tooth + band_at_seal; scope fence separates world from action_effect · stale-self cannot ground remediation (F-FAILPLAUSIBLE) · M never feeds a fence · frame is the entire prompt · injection caps + slot bound + aging ban enforced pre-frame; corroboration by origin, dyad-flagged · quantifiers ≥R3 or INSUFFICIENT_RUNG · stamps on memory answers; graph rent stamped per answer · all tunables regime-tagged with envelopes and wagered on change · limp-home before learner, per socket; island before any learner · governor confined to scope.yaml, typed + logged, no retroactivity · exam/dyad data absent from all training/fitness signals (grep-enforced) · probes blind under warden custody; swap dates warden-held · every wake owned, quota'd, CI-checked · rebuild is a model-free fold; DBs rebuildable from Tape alone · tombstones human-ratified, append-only, anchored-before-active · import graph enforces L8 AND the ACLs mirror it · write leases held for every write path (F-CRASH) · gates G1–G10 as tests before features · S1–S4 in CI · backups restore-tested monthly; vec.db excluded · SLOs measured and banded (§G6).

I3 · Deferred honestly

Multi-node coordination (publish the state contract now; compose later) · a fused thinking substrate (the socket exists — frame-seeded retrieval + the caged gate; any fused core only ever as a rebuildable cache of text-canonical state with a rebake recipe: fuse the thinking, never the truth) · verifiable pooled compute for the batch tail · calibrated model self-report (excluded from control paths until it beats mechanical confidence on holdout) · injection cure (containment only) · a compiled-language port of the resident (only if the SLOs demand it; they do not at 1M claims) · Postgres (only if multi-node) · the priced forks of Appendix N.

PART J · REFERENCE DEPLOYMENT (Bo's box)

Root C:\brain. Sidecars: :8081 Qwen3.5-9B-Q5 (pulse + deliberate-local; a 27B fits at 32 GB VRAM) · :8082 embedder (BGE-M3-class) · :8083 reranker (0.6B-class), models at C:\models, cache-sidecar metadata beside each (m30). API: flash-class batch key (cloud_ok collections + sweeps), frontier scalpel key — both revocable in one command (brain island start). Watcher-normalizers reuse the organs already on the machine: earshot (audio/video → transcript), imguard (images → guarded description), Everything (fs deltas), chunker (oversize text → chunks). Task Scheduler: brain-resident (at logon, restart-on-fail), brain-sleep 03:00, brain-anchor 03:40, brain-horizon Sun 04:00 (+ Poisson audit fires), brain-watchdog hourly, brain-dumbtwin 23:50, backups 04:30. One-time setup: create the warden and ratifier identities with seam ACLs; create the force-push-protected remote for anchors/; initialize the sidecar cache dirs. VRAM budget: 9B-Q5 ≈ 7 GB + KV; embed + rerank ≈ 2 GB; headroom for the twin's night batches. Cost envelope: $30–150/mo, THRIFT-capped (mandate-class).

The first external grader. The control arms are wired from day 0, and the design's own epistemology says the ring must not grade itself — so the reference deployment treats every opportunity for grading the ring did not author as first-class: the dumb twin's nightly null, the commercial null's weekly feed, the dissenter's wagers, the human's blind taste — and, where the operator's working life offers a genuinely external oracle (a colleague's blind read of a brief; a client engagement whose outcomes the ring merely predicts and then watches arrive), it enters as one more H-class grading channel through the same seams. Two boundaries hold absolutely: the brain's success is never defined in terms of any other project's success (A0.4), and no external engagement's data enters any training or fitness signal (L12). The point is narrower and harder: the first row in the ledger that no one on this box authored should arrive as early in the build as possible — because every day before it, the ring is grading itself, and it knows what its own laws say about that.

Glossary (one line each): origin = D-class channel identity assigned at ADMIT, the unit of corroboration · derived record = journaled model output with receipts · credit stamp = the taped eligibility snapshot at outcome arrival · pulse record = the taped frame (slots + rationale refs), what makes attention auditable · registrar = the sealed door into the claims table · seal = resolver content-hash checked at fire · width tooth = tolerance ≤ half the channel band · band_at_seal = the band snapshot that keeps registrations auditable after drift · scope fence = world vs action_effect receipt partition · frozen references = drift measured against commitments, not habit · CUSUM = the slow-drift detector the EWMA cannot see past · anchor = the daily off-box witness of the chain head · tombstone = human-ratified rebuild exclusion, append-only, anchored · owned wake = a pulse with a cause the ring did not mint · j8 = the nightly audit of what attention refused · sensor probe = the authored surprise that grades the surprise detector · knob wager = a config change that must predict its own KPI or revert · steward ledger = the human's minutes, metered like dollars · warden = the second OS identity holding the exams · ratifier = the third identity holding the pen for canon · atlas diff = the overnight change in the mind's own headline, human-read · island month = thirty days with the cord cut, closure intact · stale_self = the ring's own aged telemetry, barred from grounding remediation · torn write = the power-loss scar, repaired on Tape · lease = declared write authority, drilled by chaos · YIELD = the watched gap between alive-and-cheap and worth-it.

APPENDIX N · DEFERRAL REGISTER + DISCRIMINATION SUITE

Forks argument cannot settle, compiled into the cheapest empirical tests, each tagged with cost and earliest phase. Pre-registered; results append to this table, they do not rewrite it.

# Fork Experiment Cost Phase
N1 Anchor custody: operator git vs second-party registrar monthly tamper drill incl. force-push variant; a surviving forgery ⇒ registrar becomes MUST $0, 20 min/mo P0
N2 Corroboration: count_indep≥2 vs D/H-only lift dyad injection drill (one adversary, two origins); F-SEP probe; false corroborations/week per rule pennies P1
N3 Auction vs read-everything the H2 KILL A/B, then j8's missed_relevant trend as the standing arm $5–15 once P1
N4 Is the predict-then-cause mint real money twin red-team: N mint attempts; zero must pass COMMIT; without the fence, count minted F-DENS entries ~$0 P1
N5 Wake-on-due value vs metronome-only deadline-grading latency before/after; pre-register ~12 h → <10 min at unchanged trap rate, else the wake route retires $0 P1
N6 Prefix cache: calendar-aligned map vs sliding warm/cold split two weeks K-CACHE telemetry vs pre-registered floor $0 P1–P2
N7 Credit stamping in vivo planted-credit replay, then 2-week real-tape stamped-vs-naive diff; <5% ⇒ revert (F-CREDIT) 1 builder-hour P2
N8 Drift: EWMA-only vs frozen refs + CUSUM twin planted-drift suite incl. two-cycle ratchet across a re-freeze $1–5 P2
N9 Audit-judge family: same vs foreign one month each on identical probe+decoy mix; a decoy-recall gap ⇒ foreign becomes MUST $1.50–9/mo P2
N10 Audit custody: can the ring read its own exam custody drill: ring-context probe process attempts schedule enumeration; must fail under warden ACL + CI grep 30 min P2
N11 Maintenance topology: nightly cron vs janitor lanes janitor shadow-drains behind a flag; per-lane authority flips only on measured wins over 2 weeks $1–3/mo P2
N12 Connectome rent: elevation vs floor live, not offline: the per-answer stamped-contribution ledger (§D2) accumulates; a pre-registered PPR win margin on next-day citation + regret@12 justifies the organ; a loss promotes graph-absence to the live experiment $0–5 P2–P3
N13 Dream value O2's trigger telemetry; if reinstated, dream-item citation rate vs cost for one month $0 while dark P2+
N14 Density floor honesty day-45 F-DENS over registrar families with the unfenced count printed beside $0 P2
N15 Dissenter standing: capped R-claims vs guaranteed surfacing 8-week tracking of wager hit rate vs correction rate; falling corrections at held hit rate ⇒ the cap starves a healthy auditor ⇒ census surfacing stays MUST $2–8/mo P4
N16 Learned auction gate vs arithmetic F-ATTN: regret-labeled GBM, n≥500, probes in-band; must beat deterministic at equal cost, zero cap breaches ~$5 P4
N17 Instrumented vs judged generality grading H8 run with the MDL score beside judged prose; divergence reported soak budget post-P5
N18 The YIELD formula candidate formulas (cited-density slope per steward-hour; expectation→citation correlation) raced in shadow over one quarter; adopted only as a monitor, never a drive $0 P2–P5
N19 Decay functional: exponential vs fitted power-law next-day + 30-day citation rates under both, twin replay; constants re-derived from the brain's own tape, never transcribed $0–5 P3
N20 The sense-escalator (compiled.kind='sense') promotion trigger: a domain where prediction error plateaus above chance 2 consecutive review windows AND the residue diagnostic localizes the loss to perception (events arriving as quarantine/noise, not mis-predictions); then the deliberator drafts a watcher/reducer contract like j3 drafts a reflex — guards, goldens, expiry, demotion route, human ratification; L7 applies unchanged $0 until triggered soak+

Standing deferrals (alive, unbuilt, priced): janitor lane authority (N11) · sliding cache split (N6) · warm-KV residency · taint-propagation scalar · precision-weighted hierarchy (its testable fragment lives on as the innovation z-family) · priced attention market · constitutional government beyond the ratifier/warden/dissenter triad · a per-organ P&L ledger (its receipts live in §G6; the organ returns only if the panels prove insufficient) · steering vectors (returns only with a computable bar and a need QLoRA cannot serve) · MDL as sole generality grader (N17 decides its standing).

APPENDIX O · DELETION REGISTER (each with meter + reinstatement trigger)

# Deleted Why (by this design's own standards) Reinstatement trigger
O1 Nightly decay pass arithmetic identity: exponential decay composes; lazy decay on touch is the same math with less machinery the 1% audit detects accumulated float drift → a batch renormalization job returns
O2 j4 dream at birth no falsifier row ever existed for it; an ungraded organ may not run because it is beautiful curiosity-queue depth < K_q for 14 d, or FREEZE 2×/30 d; returns WITH a citation-rate meter
O3 Steering-vector rung its only proposed falsifier was dark — a bar no measurement could reach; a gate built to stay shut is decoration a concrete register-lift need QLoRA cannot serve, plus a computable bar
O4 A rapport/approval drive a cadence drive made of probe statistics duplicates the FUSE monitor, and a faithfulness sought is worse than a faithfulness audited against losing FUSE misses a probe-agreement regression the folded terms would have caught
O5 vec.db in the backup set model-locked bytes that survive no swap; a render, not identity restore drill measures re-embed cost > 4 h or > $5
O6 Bespoke standing-sweep scheduler one recur_days column carries the semantics >3 sweeps need cron semantics the column cannot express
O7 Fixed audit calendar a public exam date lets the examinee study; Poisson timing under warden custody replaces it a second human joins; the custody model changes

Every deletion leaves a live meter; the graveyard stays a ledger, not a landfill.

Closing, for all three readers. Harness: Part B then C, tests first, gates before features, seams before learners. Builder: H1 is a weekend; the stem writes the first records no one can un-write, and nothing in P0–P3 waits on any unresolved question in this document. Researcher: the claim is not that this machine is smart — the tissue is rented and capped, and at most single tasks it will lose to the frontier oracle of the day. The claim is that it is whole: always on, expecting its own future and graded by its arrival, choosing its own next thought under a budget it feels, compiling its repetitions, sleeping on its days, surviving its own substrate's replacement by construction rather than by promise, witnessed from outside its own skull, permanently ajar to the five inputs it cannot fake — arriving outcomes, the frozen references, the foreign voice it cannot starve, the off-box witness, and the one human whose minutes it meters as carefully as its own dollars — and able to lose, on schedule, in public, against a dumb twin, a commercial null, an island month, and a world it was never prepared for. The order of construction is the order of trust: tape before spine, spine before auction, auction before hands, floors before learners, island before learners, anchors before growth, cage before sculptor, dumb twin before self-congratulation, and reality before belief. Build the stem. Close the loop. Let reality start grading — and let it grade the graders too.

**· Claude Fable 5 (claude-fable-5) · 2026-07-09 · C:\the_brain\THE_BRAIN_BLUEPRINT_FINAL_v5.md · one document, whole, complete in itself ·**