Record at a Boundary
A record describes a locus at a boundary; it never is the locus.
- Standing
- WITNESSED CHECKABLE RUNNABLE EXECUTED STAGED PUBLISHED REPRODUCED
- Last checked
- 2026-09-11 15:27:41 UTC
- Source
scripts/check-messaging-language.mjs@92d99bf0f69f· bytes4c1baac1ee7b0a39…- Limit
- States an obligation about one boundary. It does not establish that any boundary in the tree is drawn in the right place, and satisfying it at one boundary implies nothing about the composition of two.
- Next rung
live_local— A check that reads a boundary's declared record and refuses a field that crosses it undeclared. None exists; without one this stays STATED.
Why this page says WITNESSED — the derivation, not the word
- ✓ a witness is named
- ✓ its evidence kind is one the ledger already uses (counterexample)
- ✓ the witness path resolves in this tree
- ✓ its rung is in_tree or above (in_tree)
- ✓ a run is recorded for these exact bytes
- ✓ no claim is cited that could be REFUTED
- ✓ a counterexample is shipped (required once WITNESSED)
- ✗ not staged on this site, so it cannot run from the page
WITNESSED requires every line above to hold. The label is computed from them by build.mjs and cannot be typed into the registry — the build refuses a record that carries it.
Intent
Records carry the locus's fields — world, authority, evidence, certificate — and it is tempting to say the record is the agent. It is not. A record does not observe, does not act, and does not participate in the transition relation, which is exactly what active means. The correct sentence names the boundary at which the record was taken.
Technical register
AGENCY.md §1 corollary: agent ≠ agent record, as world ≠ world serialization. Any sentence of the form 'X carries the locus fields, therefore X is a locus' is the error; the correct form is 'X records / certifies / bounds the locus at <boundary>'. Enforced as the lint class RECORD_IS_LOCUS over eight declared targets including this registry.
Problem
The factory page's first draft said the Assembly record — which carries world, authority, evidence and certificate — is the active locus. It collapsed the exact distinction the definition exists to draw, one screen after drawing it. The same collapse produces 'the database row is the user' and 'the checkpoint is the process'.
Solution
Give every record a boundary: the point in the world's history at which it was taken and by whom. Write locus sentences with an active verb and record sentences with records / certifies / bounds. Put the retired phrasings in a lint list and run it over every surface that talks about agency, including the surface that lists the retired phrasings.
Real-world analogy
A passport describes a traveller at the border where it was stamped. Nobody boards the traveller's flight by holding the passport, and nobody says the passport went to Lisbon.
Structure — on the surface
An illustration on a compute surface: loci above, carriers below. Press Play or Step; the takeaways collect as you go. Nothing here is evidence — the witness section is.
The chapter in WRL — and the chain so far
Chapter 2 of 32 — the fragment _patterns/wrl/chain/record-at-a-boundary.wrl, sealed alone by wrl.js
; RECORD AT A BOUNDARY — a record is a projection taken at a boundary; it never acts. rb_record has NO
; controller here: in the chain it is fed by chapter 1's locus. A pose is a record of a rotor at the socket.
[orb:rb_record]{pose}module + bench seal to → sem-49b97d6fb3786d8d6045e7155a5863a17df830a31fc919aed9d660d0ff30d7ca
Run inputs — a ScenarioV1, the forge's own document, bound to this world's id and never part of it (D3) · ScenarioDigest scen-66ce95db624331b0364… (the run inputs' own identity, computed by the forge)
No claims: the world runs on its clocks alone for 6 epochs.
Idle by design in this world alone: rb_record — has no controller alone: in the chain it is fed by chapter 1's locus (see links).
Reduced by the native reducer (ic32); the reference reducer reproduces every epoch's film hash (0.004s).
The Film, epoch by epoch (6)
epoch 1 · sha256:1b856e45be36971931031faae813b639c983fbe3944a0e87b5d3d31d8d5e92fc
FILM v0.7 t=1 orb:rb_record:policy=forge_motor_widemac_tz_sat_v1,quat4,w=8,n=4,pose=10,00,00,00,controller=,fault=0 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 2 · sha256:8af5534f16c9199114492a7148a33d2711b530126575e699d8b6d90bcb452536
FILM v0.7 t=2 orb:rb_record:policy=forge_motor_widemac_tz_sat_v1,quat4,w=8,n=4,pose=10,00,00,00,controller=,fault=0 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 3 · sha256:2a57aa3f8ddf3b9ee450dd595e0c9b6afacfa8925cd0cec5e48f481ac345925a
FILM v0.7 t=3 orb:rb_record:policy=forge_motor_widemac_tz_sat_v1,quat4,w=8,n=4,pose=10,00,00,00,controller=,fault=0 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 4 · sha256:7791076640459cc965c58b8bd133f00743fd0b9f2e7c565e687e9667ba1e77b3
FILM v0.7 t=4 orb:rb_record:policy=forge_motor_widemac_tz_sat_v1,quat4,w=8,n=4,pose=10,00,00,00,controller=,fault=0 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 5 · sha256:35f3ce9f50f917b3fa071bb4260d1f6bc337f0dfafc499ae6832024efa3e79e7
FILM v0.7 t=5 orb:rb_record:policy=forge_motor_widemac_tz_sat_v1,quat4,w=8,n=4,pose=10,00,00,00,controller=,fault=0 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 6 · sha256:681b973d21defcfe0f64c09aa6f55d9ea2c0e8d871ffdbd63ca4f0d2b2c5d7d4
FILM v0.7 t=6 orb:rb_record:policy=forge_motor_widemac_tz_sat_v1,quat4,w=8,n=4,pose=10,00,00,00,controller=,fault=0 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
Composes with the 1 chapter before it
The chain through this chapter — every earlier fragment, this one, and the links — seals to sem-530dc1a3e5ad1d19942868b1be34afe64d606c4c10d5af7eed5e987e81664c6b: 4 objects, 3 edges (was 3 / 2; every earlier object and edge is still present — checked, or the build refuses).
Links only the chain carries
; the record records chapter 1's locus, at the socket boundary — fan-out from one socket is unrestricted [al_locus] --socket--> [rb_record]
How to read this board
Five kinds of object, two kinds of wire, and one band per Part of the book. Signal flows left to right: it starts at a clock, travels through relays, and ends at a door — or turns a spinner, which drives an orb. Nothing below is the book's own vocabulary; each line is quoted from where the definition lives.
| shape | is | and so |
|---|---|---|
| a clock; the only source of signal | Every signal on the board starts at one of these. Nothing else can make one. | |
| a pass-through, so signal can travel | One arrives, any number leave — a relay that fans out is the board's router. | |
| a sink; signal arrives and stops | It latches what reached it and passes nothing on. A door is where a path ends. | |
| rotation: takes signal, drives a pose | The only object on the board that holds a value a claim can rewrite — and only if its config says configurable. | |
| the thing that gets moved | It is driven, never driving: an orb is what you watch to see whether anything happened. | |
| not a WRL role — the book's own drawing of the receipts in the epoch's Film | It counts what the run admitted, and turns red on a Rejected outcome. | |
| SignalWire | signal: a sig_out to a sig_in | Legal from a Pulser or Relay, into a Relay, Door or Spinner. This is how the board moves. |
| SocketControl | control: a socket to a pose | Legal only from a Spinner into an Orb. At most one may land on any input port — fan-in is a typed refusal. |
Hover any object for what it is, which chapter put it there, and every field of its line in that epoch's Film — split into what it is doing now and how it was built. Click to pin the readout, then click a wired name to follow the signal. The field definitions come from TRVM/forge/film.py (the emitter), TRVM/forge/forge_state.py (nf, derived from the decoded counter and never from t), TRVM/forge/lower_e2a.py (the commit/react law), TRVM/FORGE_SEMANTIC_IR_v1_MEASURE.md §1.3; the shapes from WRL/learn.html and WRL/docs/spec/README.md. The build refuses if a Film emits a field this key does not explain.
The board so far: one band per Part, signal flowing left to right; relays that fan out are routers, doors are switches, pulsers are clock domains. Hover an object — or click the board and walk it with the arrow keys — for its role, its Part and what it is wired to. This board is the chain’s sealed shape; no Film drives it, so it has no state to report, and the whole board in the conclusion is where every object’s state is read epoch by epoch. Wheel zooms · drag pans · double-click fits.
Syntax — quoted from the tree at build time
The corollary, verbatim (AGENCY.md §1) AGENCY.md:63
> **agent ≠ agent record**, exactly as **world ≠ world serialization**.
The lint class that enforces it, from the rules the gate runs scripts/messaging-rules.json:91
"id": "RECORD_IS_LOCUS",
"why": "AGENCY.md §1. A record describes, identifies, constrains or certifies a locus; it does not observe or act, so it is not one. agent != agent record, exactly as world != world serialization.",
"instead": "\"X records / certifies / bounds the locus at <boundary>\".",
"scope": [
"sites",
Forces
Records are what you can hold, hash, sign and ship; loci are what act. Everything durable about a locus reaches you as a record, so the record is always the nearer thing to point at. The pattern asks for one more clause — at which boundary — and that clause is what stops a snapshot being mistaken for a life.
Applicability
Any system that persists, snapshots or certifies an acting thing: agent ledgers, factory records, world serializations, checkpoints. Especially copy about such systems, where the collapse is one adjective away.
Transformations
- taking a record of a locus at any boundary
- certifying a locus from its records
- re-establishing a locus from records — a continuity question, not an identity assertion
- 'X carries the locus fields, therefore X is a locus'
- attaching an evidence rung to a definition
- letting a record observe or act in prose
A refusing transformation is not one that is discouraged: it is one that, applied, makes the invariant above false. The word is the tree's, and it is the same word the join uses.
Consequences
Continuity becomes askable: a successor may re-establish what a record says, and whether it did is a test, not a sentence. The cost is a lint that occasionally refuses your own registry — as it did here, twice, until the counterexample lines were quarantined by rule id.
Failure mode it answers
Record Is Locus — Inferring that X is a locus because X carries the locus fields. Paid for at: AGENCY.md §1 corollary; caught on review of the factory page
Witness
Source identity: scripts/check-messaging-language.mjs · shape lint · evidence kind counterexample · rung in_tree (the gate runs over 8 declared targets and exits non-zero on a hit)
Execution identity: 2026-09-11T15:27:41.066Z on PX13 · bytes 4c1baac1ee7b0a39… · repo HEAD 92d99bf0f69f
Not staged on this site: the page cannot run this witness. It runs from the command line: node scripts/check-messaging-language.mjs in ..
Counterexample
A sentence the ontology gate rejects: an assembly is a locus
— expected REFUSED.
What to take away
- from the animationThe record stayed at the boundary while the locus kept transitioning; the sentence that made them one was refused.
- from the syntaxThe rule is a substring list with a stated reason and an 'instead' — a lint you can point at your own prose.
- from the literatureMap ≠ territory, and Parnas's interface/implementation split, applied to identity rather than modules.
- from the witnessThe gate ran over eight targets with this registry among them; the counterexample sentence is one it rejects.
Prior art — and what is not claimed
| work | relation | what it shares | where it differs |
|---|---|---|---|
| Parnas, information hiding (1972) | antecedent | the split between what a thing is and what it shows at its edge | Parnas splits interface from implementation for modules; this splits identity from its serialization |
| Korzybski, map ≠ territory | close analogue | the representation is not the thing | a general semantic caution, not a rule a build can enforce |
Novelty not claimed. The distinction is old. The contribution is making it refusable at a specific boundary rather than stating it as advice.
Realizations in the tree
- AGENCY.md §1 corollary
- AmpersandBoxDesign/site/index.html §02
Relations with other patterns
Active Locus definition