OpenSentience.orgUnboxed PatternsChapter 28 of 32 · Agency

UP-028 · Agency · WITNESSED CHECKABLE RUNNABLE EXECUTED STAGED

Evidence Before Claim

A proposition is admitted only with a named witness that exists.

A public proposition is admitted only with a named witness that exists; a claim whose witness is absent, whose antecedent is missing, or whose cell binding contradicts the table is refused.
Standing
WITNESSED CHECKABLE RUNNABLE EXECUTED STAGED PUBLISHED REPRODUCED
Last checked
2026-09-11 15:26:22 UTC
Source
scripts/check-claim-ledger.mjs @ 92d99bf0f69f · bytes 33e6af41713b45be…
Limit
The mechanism exists (DOCTRINE.md rule 4 and the ledger) and the phrase does not. This page establishes that this build refuses an unwarranted claim in its own registry — not that the tree's other surfaces do.
Next rung
live_local — the prose gate run from the page over text a reader types, rather than at build time over text we wrote. That the gate refuses our own registry is evidence about us, not about the rule.
Why this page says WITNESSED — the derivation, not the word
  • ✓ a witness is named
  • ✓ its evidence kind is one the ledger already uses (constructive_witness)
  • ✓ the witness path resolves in this tree
  • ✓ its rung is in_tree or above (in_tree)
  • ✓ a run is recorded for these exact bytes
  • ✓ no claim is cited that could be REFUTED
  • ✓ a counterexample is shipped (required once WITNESSED)
  • ✗ not staged on this site, so it cannot run from the page

WITNESSED requires every line above to hold. The label is computed from them by build.mjs and cannot be typed into the registry — the build refuses a record that carries it.

Intent

Every public claim in this stack is a record in a ledger with a statement, a status from a fixed vocabulary, an evidence kind, and the witnesses that back it. A gate refuses a claim whose witness file is missing, whose conditional has no antecedent, or whose cell binding contradicts the invariants table. The gate's exit code is the verdict, and no report overrides it.

Technical register

DOCTRINE.md rule 4 (measure before you claim, and say how); CLAIM_LEDGER.json, 190 claims across eight statuses; scripts/check-claim-ledger.mjs refuses a witness that does not exist, a CONDITIONAL with no antecedent, a binding that contradicts the table, and a witness whose relative-import closure does not resolve. 178 of 190 claims carry prior_art; one says NOT SEARCHED. This catalog's labels are derived by a gate of the same shape.

Problem

Status reports say done. Percentages stand in for evidence. A number typed beside a claim is quoted three times before anyone asks where it came from — this tree has paid that price with law counts, migration counts and a '64 of 116'. An invented number is worse than a missing one because it stops the question being asked.

Solution

Keep one ledger of claims. Fix the status vocabulary and forbid every other word. Require a witness path per claim and a gate that opens it. Derive every count on every page from the ledger; never type one.

Real-world analogy

A courtroom exhibit list. A witness who is named but never appears does not testify, however good the story.

Structure — on the surface

compute surfaceledger gateledger gatecclaim · witness: (none)A public proposition, and the gate that decides whether it may be published.

An illustration on a compute surface: loci above, carriers below. Press Play or Step; the takeaways collect as you go. Nothing here is evidence — the witness section is.

The chapter in WRL — and the chain so far

Chapter 28 of 32 — the fragment _patterns/wrl/chain/evidence-before-claim.wrl, sealed alone by wrl.js

; EVIDENCE BEFORE CLAIM — a claim at epoch 2 becomes a receipt with an outcome, in the Film, before anything
; downstream may cite it. ec_in is the entry and a router (chapter 29 draws from it); ec_ledger is a Door
; with an open port the chain feeds from the root clock.
[relay:ec_in]{sig_in, sig_out}
[spinner:ec_subject](w=16, n=8, rotor=quarter_turn_z, configurable){sig_in, socket}
[orb:ec_witness]{pose}
[door:ec_ledger]{sig_in}

[ec_in] --sig--> [ec_subject]
[ec_subject] --socket--> [ec_witness]

Its test bench _patterns/wrl/chain/evidence-before-claim.bench.wrl — drives the entry for this chapter's own film; never part of the chain

; TEST BENCH — drives this chapter's entry alone; the chain replaces it with a wire from an earlier chapter
[pulser:ec_bench](every 1){sig_out}
[ec_bench] --sig--> [ec_in]

module + bench seal to → sem-b1b88c7dbc3335cde087329fe36756733499f64164c1c3aef8c0d477a2406a7d

Run inputs — a ScenarioV1, the forge's own document, bound to this world's id and never part of it (D3) · ScenarioDigest scen-500446149b48e3d84f1… (the run inputs' own identity, computed by the forge)

epochwriter · seqoptargetrotorlabel
2w1 s1SetRotorec_subject0.255.0.0SetRotor ec_subject 0.255.0.0

Idle by design in this world alone: ec_ledger — an open port alone: in the chain it is fed by chapter 1's world clock (see links).

Reduced by the native reducer (ic32); the reference reducer reproduces every epoch's film hash (35.16s).

compute surfacesigsigsocketec_bench · Pulserec_benchpulserec_in · Relayec_inrelayec_ledger · Doorec_ledgerdoorec_subject · Spinnerec_subjectspinnerec_witness · Orbec_witnessorbledger · receipts · Ledgerledger · receiptsno receiptsThis chapter's world alone, before epoch 1. Reduced by TRVM's forge in 3.817s; the forge's id equals the seal above.

Receipts in the last epoch's Film

receipt:w=1,s=1,accepted=bc,apkey=0.0.0.255.0.0,epoch=2,outcome=Applied
The Film, epoch by epoch (6)

epoch 1 · sha256:82a6202b41d1af24d2f1ae8ad07fe641b57131ce03f085e67a23b2c2e082746b

FILM v0.7
t=1
spinner:ec_subject:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=ec_witness,config=configurable
orb:ec_witness:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=ec_subject,fault=0
pulser:ec_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
door:ec_ledger:open=0,next_open=0
relay:ec_in:cur_out=0,next_out=1
wire:w__ec_bench__ec_in:cur=1,nxt=1
wire:w__ec_in__ec_subject:cur=0,nxt=0
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0

epoch 2 · sha256:5b5fe4e9d16bf1be5cda14d981cb99e83609d0a3380a06c4eadb11a0e354695e

FILM v0.7
t=2
spinner:ec_subject:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=0000,00ff,0000,0000,socket=ec_witness,config=configurable
orb:ec_witness:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=ec_subject,fault=0
pulser:ec_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
door:ec_ledger:open=0,next_open=0
relay:ec_in:cur_out=1,next_out=1
wire:w__ec_bench__ec_in:cur=1,nxt=1
wire:w__ec_in__ec_subject:cur=0,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=1,s=1,digest=bc,pkey=0.0.0.255.0.0,payload=SetRotor:ec_subject:0.255.0.0
receipt:w=1,s=1,accepted=bc,apkey=0.0.0.255.0.0,epoch=2,outcome=Applied
recognition:w=1,s=1,state=unambiguous

epoch 3 · sha256:ff1fe645dde0646d84842ee09423300ad04adf343e7ce105b0f3bbb8e5bfb705

FILM v0.7
t=3
spinner:ec_subject:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=0000,00ff,0000,0000,socket=ec_witness,config=configurable
orb:ec_witness:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0000,00ff,0000,0000,controller=ec_subject,fault=0
pulser:ec_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
door:ec_ledger:open=0,next_open=0
relay:ec_in:cur_out=1,next_out=1
wire:w__ec_bench__ec_in:cur=1,nxt=1
wire:w__ec_in__ec_subject:cur=1,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=1,s=1,digest=bc,pkey=0.0.0.255.0.0,payload=SetRotor:ec_subject:0.255.0.0
receipt:w=1,s=1,accepted=bc,apkey=0.0.0.255.0.0,epoch=2,outcome=Applied
recognition:w=1,s=1,state=unambiguous

epoch 4 · sha256:0934fcfbe19729947159392743063b37c75cae15524d3f3f0a26e8768000e31a

FILM v0.7
t=4
spinner:ec_subject:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=0000,00ff,0000,0000,socket=ec_witness,config=configurable
orb:ec_witness:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=ff02,0000,0000,0000,controller=ec_subject,fault=0
pulser:ec_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
door:ec_ledger:open=0,next_open=0
relay:ec_in:cur_out=1,next_out=1
wire:w__ec_bench__ec_in:cur=1,nxt=1
wire:w__ec_in__ec_subject:cur=1,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=1,s=1,digest=bc,pkey=0.0.0.255.0.0,payload=SetRotor:ec_subject:0.255.0.0
receipt:w=1,s=1,accepted=bc,apkey=0.0.0.255.0.0,epoch=2,outcome=Applied
recognition:w=1,s=1,state=unambiguous

epoch 5 · sha256:781e69c6dd957101f9087235df0190ac3c86cf283b6e0c8e1e78e51be92e86b0

FILM v0.7
t=5
spinner:ec_subject:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=0000,00ff,0000,0000,socket=ec_witness,config=configurable
orb:ec_witness:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0000,ff03,0000,0000,controller=ec_subject,fault=0
pulser:ec_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
door:ec_ledger:open=0,next_open=0
relay:ec_in:cur_out=1,next_out=1
wire:w__ec_bench__ec_in:cur=1,nxt=1
wire:w__ec_in__ec_subject:cur=1,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=1,s=1,digest=bc,pkey=0.0.0.255.0.0,payload=SetRotor:ec_subject:0.255.0.0
receipt:w=1,s=1,accepted=bc,apkey=0.0.0.255.0.0,epoch=2,outcome=Applied
recognition:w=1,s=1,state=unambiguous

epoch 6 · sha256:a0f539032cf76e492e81ced9bd0e024f33ce0a40613efd74b87e100c8b861ed8

FILM v0.7
t=6
spinner:ec_subject:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=0000,00ff,0000,0000,socket=ec_witness,config=configurable
orb:ec_witness:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=00fc,0000,0000,0000,controller=ec_subject,fault=0
pulser:ec_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
door:ec_ledger:open=0,next_open=0
relay:ec_in:cur_out=1,next_out=1
wire:w__ec_bench__ec_in:cur=1,nxt=1
wire:w__ec_in__ec_subject:cur=1,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=1,s=1,digest=bc,pkey=0.0.0.255.0.0,payload=SetRotor:ec_subject:0.255.0.0
receipt:w=1,s=1,accepted=bc,apkey=0.0.0.255.0.0,epoch=2,outcome=Applied
recognition:w=1,s=1,state=unambiguous

Composes with the 27 chapters before it

The chain through this chapter — every earlier fragment, this one, and the links — seals to sem-93035fc9c81c15f33dc6f1a063d945bdf14033418983eb2f59c5403456460a33: 97 objects, 87 edges (was 93 / 83; every earlier object and edge is still present — checked, or the build refuses).

Links only the chain carries

[en_established] --sig--> [ec_in]
; the ledger is fed by chapter 1's root clock: the same transition relation, one wire, one port
[al_world] --sig--> [ec_ledger]
How to read this board

Five kinds of object, two kinds of wire, and one band per Part of the book. Signal flows left to right: it starts at a clock, travels through relays, and ends at a door — or turns a spinner, which drives an orb. Nothing below is the book's own vocabulary; each line is quoted from where the definition lives.

shapeisand so
a clock; the only source of signalEvery signal on the board starts at one of these. Nothing else can make one.
a pass-through, so signal can travelOne arrives, any number leave — a relay that fans out is the board's router.
a sink; signal arrives and stopsIt latches what reached it and passes nothing on. A door is where a path ends.
rotation: takes signal, drives a poseThe only object on the board that holds a value a claim can rewrite — and only if its config says configurable.
the thing that gets movedIt is driven, never driving: an orb is what you watch to see whether anything happened.
not a WRL role — the book's own drawing of the receipts in the epoch's FilmIt counts what the run admitted, and turns red on a Rejected outcome.
SignalWiresignal: a sig_out to a sig_inLegal from a Pulser or Relay, into a Relay, Door or Spinner. This is how the board moves.
SocketControlcontrol: a socket to a poseLegal only from a Spinner into an Orb. At most one may land on any input port — fan-in is a typed refusal.

Hover any object for what it is, which chapter put it there, and every field of its line in that epoch's Film — split into what it is doing now and how it was built. Click to pin the readout, then click a wired name to follow the signal. The field definitions come from TRVM/forge/film.py (the emitter), TRVM/forge/forge_state.py (nf, derived from the decoded counter and never from t), TRVM/forge/lower_e2a.py (the commit/react law), TRVM/FORGE_SEMANTIC_IR_v1_MEASURE.md §1.3; the shapes from WRL/learn.html and WRL/docs/spec/README.md. The build refuses if a Film emits a field this key does not explain.

compute surfaceI · The LocusII · CompositionIII · ProgressIV · Persistence and WorldV · Agencyal_locus · Spinneral_locusspinneral_view · Orbal_vieworbal_world · Pulseral_worldpulsercb_fixed · Spinnercb_fixedspinnercb_gate · Doorcb_gatedoorcb_in · Relaycb_inrelaycb_view · Orbcb_vieworbcc_carrier · Doorcc_carrierdoorcc_grant · Relaycc_grantrelaycm_in · Relaycm_inrelaycm_locus0 · Doorcm_locus0doorcm_locus1 · Doorcm_locus1doorcm_locus2 · Doorcm_locus2doorcm_locus3 · Doorcm_locus3doorcm_slot0 · Relaycm_slot0relaycm_slot1 · Relaycm_slot1relaycm_slot2 · Relaycm_slot2relaycm_slot3 · Relaycm_slot3relayct_in · Relayct_inrelayct_locus · Spinnerct_locusspinnerct_view · Orbct_vieworbcx_in · Relaycx_inrelaycx_machine0 · Relaycx_machine0relaycx_machine1 · Relaycx_machine1relaycx_replay0 · Doorcx_replay0doorcx_replay1 · Doorcx_replay1doordb_clock · Pulserdb_clockpulserdb_locus · Spinnerdb_locusspinnerdb_view · Orbdb_vieworbec_in · Relayec_inrelayec_ledger · Doorec_ledgerdoorec_subject · Spinnerec_subjectspinnerec_witness · Orbec_witnessorben_act · Dooren_actdooren_established · Relayen_establishedrelayen_in · Relayen_inrelayer_a · Relayer_arelayer_b · Relayer_brelayer_clock · Pulserer_clockpulserer_player · Doorer_playerdooris_id · Orbis_idorbis_in · Relayis_inrelayis_seal · Spinneris_sealspinnerlc_core · Relaylc_corerelaylc_locus · Spinnerlc_locusspinnerlc_machine · Relaylc_machinerelaylc_thread · Relaylc_threadrelaylc_view · Orblc_vieworbmh_clock · Pulsermh_clockpulsermh_gate · Doormh_gatedoorop_clock · Pulserop_clockpulserop_locus · Spinnerop_locusspinnerop_view · Orbop_vieworbpj_artifact · Spinnerpj_artifactspinnerpj_in · Relaypj_inrelaypj_view_a · Orbpj_view_aorbpj_view_b · Orbpj_view_borbpp_homeA · Relaypp_homeArelaypp_homeB · Relaypp_homeBrelaypp_in · Relaypp_inrelaypp_locus · Spinnerpp_locusspinnerpp_view · Orbpp_vieworbpq_a · Relaypq_arelaypq_b · Relaypq_brelaypq_clock · Pulserpq_clockpulserpq_done · Doorpq_donedoorpu_admitted · Orbpu_admittedorbpu_busy · Pulserpu_busypulserpu_hop0 · Relaypu_hop0relaypu_hop1 · Relaypu_hop1relaypu_hop2 · Relaypu_hop2relaypu_locus · Spinnerpu_locusspinnerpu_progress · Pulserpu_progresspulserpu_sink · Doorpu_sinkdoorrb_record · Orbrb_recordorbrd_in · Relayrd_inrelayrd_real · Spinnerrd_realspinnerrd_view · Orbrd_vieworbrj_join · Doorrj_joindoorrj_r · Relayrj_rrelaysd_in · Relaysd_inrelaysd_state · Spinnersd_statespinnersd_view · Orbsd_vieworbsm_in · Relaysm_inrelaysm_inside · Spinnersm_insidespinnersm_outside_a · Orbsm_outside_aorbsm_outside_b · Orbsm_outside_borbso_in · Relayso_inrelayso_pose · Orbso_poseorbso_rotor · Spinnerso_rotorspinnerts_root · Doorts_rootdoorts_version · Pulserts_versionpulsertv_a · Orbtv_aorbtv_b · Orbtv_borbtv_fixed · Spinnertv_fixedspinnertv_in · Relaytv_inrelaytv_open · Spinnertv_openspinner

The board so far: one band per Part, signal flowing left to right; relays that fan out are routers, doors are switches, pulsers are clock domains. Hover an object — or click the board and walk it with the arrow keys — for its role, its Part and what it is wired to. This board is the chain’s sealed shape; no Film drives it, so it has no state to report, and the whole board in the conclusion is where every object’s state is read epoch by epoch. Wheel zooms · drag pans · double-click fits.

Syntax — quoted from the tree at build time

Rule 4, verbatim (DOCTRINE.md) DOCTRINE.md:70

4. **Measure before you claim, and say how you measured.** A speedup without a
   method is a rumour. State the baseline, the number of runs, and what you
   excluded. If the measurement ordering could have selected the result, say so.

The refusal, in the gate this page ran scripts/check-claim-ledger.mjs:186

    if (!existsSync(`${ROOT}/${path}`)) { bad(id, `witness file does not exist: ${path}`); continue; }

Forces

Writing a witness is slower than writing a sentence, and a gate that refuses your own claim is unpleasant on the day. The pressure to soften the vocabulary — a checkmark, a 'mostly' — is constant. The rule holds by making the exit code the answer and by making '?' an acceptable one.

Applicability

Any document that makes status claims: roadmaps, READMEs, marketing pages, this catalog.

Transformations

Preserving
  • downgrading a status when in doubt
  • adding a witness and re-running the gate
  • answering '?' or 'status unknown'
Refusing
  • a status word outside the vocabulary
  • a witness that is described but not on disk
  • a count typed where it is displayed (A Number in Two Places)

A refusing transformation is not one that is discouraged: it is one that, applied, makes the invariant above false. The word is the tree's, and it is the same word the join uses.

Consequences

Claims become things a reader can check rather than believe. The book you are reading is built this way: its labels are derived, its counts are joined, and its own first draft was caught by the same discipline with 32 labels over 30 rows.

Failure mode it answers

Agent Omniscience — Letting an agent's claims exceed its evidence boundary. Paid for at: AGENCY.md §6 (what is established vs a reading)

Witness

Source identity: scripts/check-claim-ledger.mjs · shape side-effect · evidence kind constructive_witness · rung in_tree (runs over CLAIM_LEDGER.json (190 claims) and refuses; exit code is the verdict)

Execution identity: 2026-09-11T15:26:22.369Z on PX13 · bytes 33e6af41713b45be… · repo HEAD 92d99bf0f69f

Not staged on this site: the page cannot run this witness. It runs from the command line: node scripts/check-claim-ledger.mjs in ..

Counterexample

scripts/check-claim-ledger.mjs — marker witness file does not exist, expected REFUSED.

A marker, not a resolved law. The build checked that this string is present in the file. A string being present proves the file mentions it, not that the file refuses anything — this record cites no law id that could be resolved against a suite index. It is the weaker of the two forms this catalog uses.

What to take away

  1. from the animationThe claim was refused without its witness and admitted with one, at the status the evidence earned.
  2. from the syntaxThe gate's exit code is the verdict; a report cannot override it.
  3. from the literatureToulmin's warrant and backing; assurance cases; Pollock's defeaters — the ledger has a defeater field of its own.
  4. from the witnesscheck-claim-ledger.mjs ran today over 190 claims, exit 0, with a receipt on this page.

Prior art — and what is not claimed

workrelationwhat it shareswhere it differs
Toulmin — warrant and backingantecedenta claim is admissible only with its warrantToulmin analyses arguments; this is enforced by a build
Pollock, defeatersantecedentwhat would withdraw the claim must be statednone claimed
Assurance cases (GSN)close analoguea structured argument tied to its evidenceGSN is a notation for a document; here the tie is mechanical and the build refuses without it

Novelty not claimed. The phrase is absent from the tree; the mechanism (DOCTRINE.md rule 4 plus the ledger) is not. Argumentation theory is the prior art and it is older than the stack.

Realizations in the tree

Relations with other patterns

Descent Is Not Dependence WITNESSED · Refusal Gate STATED