Refusal Gate
Below material sufficiency the page is not written, and the reason is published.
- Standing
- STATED CHECKABLE RUNNABLE EXECUTED STAGED PUBLISHED REPRODUCED
- Last checked
- never run
- Source
- none — this record cites no check
- Limit
- The Academy refusal log is MOCK (ACADEMY.md:79) and does not count. alkeyword's refusal rule is the live instance, and it is one instance in one lane.
- Next rung
in_tree— a refusal log in this catalog that can fail. The Academy's is MOCK (ACADEMY.md:79) and does not count; alkeyword's is live and is one instance in one lane, neither of them here.
Why this page says STATED — the derivation, not the word
- ✗ a witness is named
- ✗ its evidence kind is one the ledger already uses
- ✗ the witness path resolves in this tree
- ✗ its rung is in_tree or above
- ✗ a run is recorded for these exact bytes
- ✓ no claim is cited that could be REFUTED
- ✗ a counterexample is shipped (required once WITNESSED)
- ✗ not staged on this site, so it cannot run from the page
WITNESSED requires every line above to hold. The label is computed from them by build.mjs and cannot be typed into the registry — the build refuses a record that carries it.
Intent
A correct agent sometimes advances the system by not acting. A generator that writes a page from thin material produces something that reads well and cites nothing; the gate refuses it and publishes why. The refusals are the feature no autoblog can copy. A check that can be satisfied by constructing its own argument is not a check.
Technical register
alkeyword's refusal rule (alkeyword.com/docs/spec/README.md §3.2), inherited by Academy's Read layer without relaxation. The Academy refusal log is a MOCK: real format, illustrative entries, counts not measured against a live crawl (ACADEMY.md). Its worked example: a statistics page held because the corpus contradicted itself on a law count (103 vs 116), resolved by running both suites. This book's registry runs a gate of the same shape.
Problem
Content generators never refuse. Every prompt yields a page; the pages that had nothing behind them look exactly like the ones that did. Readers learn to trust none of them.
Solution
Define material sufficiency. Trace every factual sentence to a source span. Refuse below the threshold and publish the reason in the same place the page would have been. Keep the refusal log measured, or label it MOCK.
Real-world analogy
A newspaper that prints, in the space where a story would have run, 'we could not confirm this' — and is read for exactly that reason.
Structure — on the surface
An illustration on a compute surface: loci above, carriers below. Press Play or Step; the takeaways collect as you go. Nothing here is evidence — the witness section is.
The chapter in WRL — and the chain so far
Chapter 29 of 32 — the fragment _patterns/wrl/chain/refusal-gate.wrl, sealed alone by wrl.js
; REFUSAL GATE — the page is a Door; material must pass rg_sufficiency (a relay, and a router) to open it.
; rg_in is the entry, fed by the evidence router.
[relay:rg_in]{sig_in, sig_out}
[relay:rg_sufficiency]{sig_in, sig_out}
[door:rg_page]{sig_in}
[rg_in] --sig--> [rg_sufficiency]
[rg_sufficiency] --sig--> [rg_page]Its test bench _patterns/wrl/chain/refusal-gate.bench.wrl — drives the entry for this chapter's own film; never part of the chain
; TEST BENCH — drives this chapter's entry alone; the chain replaces it with a wire from an earlier chapter
[pulser:rg_bench](every 1){sig_out}
[rg_bench] --sig--> [rg_in]module + bench seal to → sem-17af9a11c5b42eba0f1f374dc608638a58cae1c09bc4a6945e31be0604e430c0
Run inputs — a ScenarioV1, the forge's own document, bound to this world's id and never part of it (D3) · ScenarioDigest scen-886cdaf007dc64a8089… (the run inputs' own identity, computed by the forge)
No claims: the world runs on its clocks alone for 7 epochs.
Reduced by the native reducer (ic32); the reference reducer reproduces every epoch's film hash (0.006s).
The Film, epoch by epoch (7)
epoch 1 · sha256:cc36aad4354c2a95320b36e064315ffcbe2d8d6d2301116a604bdc192001906f
FILM v0.7 t=1 pulser:rg_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 door:rg_page:open=0,next_open=0 relay:rg_in:cur_out=0,next_out=1 relay:rg_sufficiency:cur_out=0,next_out=0 wire:w__rg_bench__rg_in:cur=1,nxt=1 wire:w__rg_in__rg_sufficiency:cur=0,nxt=0 wire:w__rg_sufficiency__rg_page:cur=0,nxt=0 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 2 · sha256:1089e75754cb00e441f5d42a77d0ca563338d9ac263295e289ce09045de8cdf7
FILM v0.7 t=2 pulser:rg_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 door:rg_page:open=0,next_open=0 relay:rg_in:cur_out=1,next_out=1 relay:rg_sufficiency:cur_out=0,next_out=0 wire:w__rg_bench__rg_in:cur=1,nxt=1 wire:w__rg_in__rg_sufficiency:cur=0,nxt=1 wire:w__rg_sufficiency__rg_page:cur=0,nxt=0 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 3 · sha256:b27c0595c5b43e61446b2ca5f156f58baa56062d5fdc210b6366af76c279263b
FILM v0.7 t=3 pulser:rg_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 door:rg_page:open=0,next_open=0 relay:rg_in:cur_out=1,next_out=1 relay:rg_sufficiency:cur_out=0,next_out=1 wire:w__rg_bench__rg_in:cur=1,nxt=1 wire:w__rg_in__rg_sufficiency:cur=1,nxt=1 wire:w__rg_sufficiency__rg_page:cur=0,nxt=0 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 4 · sha256:5fed49f61ea7923a157d12bff80dfad94b9776f7734b67e941e11eed9795ed8e
FILM v0.7 t=4 pulser:rg_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 door:rg_page:open=0,next_open=0 relay:rg_in:cur_out=1,next_out=1 relay:rg_sufficiency:cur_out=1,next_out=1 wire:w__rg_bench__rg_in:cur=1,nxt=1 wire:w__rg_in__rg_sufficiency:cur=1,nxt=1 wire:w__rg_sufficiency__rg_page:cur=0,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 5 · sha256:984e0671d77832e21a028e87440c34e874c81a6d2baca70ddfc2d0958ad0fe69
FILM v0.7 t=5 pulser:rg_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 door:rg_page:open=0,next_open=1 relay:rg_in:cur_out=1,next_out=1 relay:rg_sufficiency:cur_out=1,next_out=1 wire:w__rg_bench__rg_in:cur=1,nxt=1 wire:w__rg_in__rg_sufficiency:cur=1,nxt=1 wire:w__rg_sufficiency__rg_page:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 6 · sha256:9200aad23cafd43d6bf7ddbcdbb0f0c1251920fd82724b08a418e3f0baf86973
FILM v0.7 t=6 pulser:rg_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 door:rg_page:open=1,next_open=1 relay:rg_in:cur_out=1,next_out=1 relay:rg_sufficiency:cur_out=1,next_out=1 wire:w__rg_bench__rg_in:cur=1,nxt=1 wire:w__rg_in__rg_sufficiency:cur=1,nxt=1 wire:w__rg_sufficiency__rg_page:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
epoch 7 · sha256:8205b104efbfddd7b0ad63c09ac1ae36e0db53db416c79b0cb3391f2a7c38f3b
FILM v0.7 t=7 pulser:rg_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 door:rg_page:open=1,next_open=1 relay:rg_in:cur_out=1,next_out=1 relay:rg_sufficiency:cur_out=1,next_out=1 wire:w__rg_bench__rg_in:cur=1,nxt=1 wire:w__rg_in__rg_sufficiency:cur=1,nxt=1 wire:w__rg_sufficiency__rg_page:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
Composes with the 28 chapters before it
The chain through this chapter — every earlier fragment, this one, and the links — seals to sem-8c80e9196256af425a8c497f16978a674c7b97bfd339ecb5d16cf88582815135: 100 objects, 90 edges (was 97 / 87; every earlier object and edge is still present — checked, or the build refuses).
Links only the chain carries
[ec_in] --sig--> [rg_in]
How to read this board
Five kinds of object, two kinds of wire, and one band per Part of the book. Signal flows left to right: it starts at a clock, travels through relays, and ends at a door — or turns a spinner, which drives an orb. Nothing below is the book's own vocabulary; each line is quoted from where the definition lives.
| shape | is | and so |
|---|---|---|
| a clock; the only source of signal | Every signal on the board starts at one of these. Nothing else can make one. | |
| a pass-through, so signal can travel | One arrives, any number leave — a relay that fans out is the board's router. | |
| a sink; signal arrives and stops | It latches what reached it and passes nothing on. A door is where a path ends. | |
| rotation: takes signal, drives a pose | The only object on the board that holds a value a claim can rewrite — and only if its config says configurable. | |
| the thing that gets moved | It is driven, never driving: an orb is what you watch to see whether anything happened. | |
| not a WRL role — the book's own drawing of the receipts in the epoch's Film | It counts what the run admitted, and turns red on a Rejected outcome. | |
| SignalWire | signal: a sig_out to a sig_in | Legal from a Pulser or Relay, into a Relay, Door or Spinner. This is how the board moves. |
| SocketControl | control: a socket to a pose | Legal only from a Spinner into an Orb. At most one may land on any input port — fan-in is a typed refusal. |
Hover any object for what it is, which chapter put it there, and every field of its line in that epoch's Film — split into what it is doing now and how it was built. Click to pin the readout, then click a wired name to follow the signal. The field definitions come from TRVM/forge/film.py (the emitter), TRVM/forge/forge_state.py (nf, derived from the decoded counter and never from t), TRVM/forge/lower_e2a.py (the commit/react law), TRVM/FORGE_SEMANTIC_IR_v1_MEASURE.md §1.3; the shapes from WRL/learn.html and WRL/docs/spec/README.md. The build refuses if a Film emits a field this key does not explain.
The board so far: one band per Part, signal flowing left to right; relays that fan out are routers, doors are switches, pulsers are clock domains. Hover an object — or click the board and walk it with the arrow keys — for its role, its Part and what it is wired to. This board is the chain’s sealed shape; no Film drives it, so it has no state to report, and the whole board in the conclusion is where every object’s state is read epoch by epoch. Wheel zooms · drag pans · double-click fits.
Syntax — quoted from the tree at build time
The rule Academy inherits, in its own words (ACADEMY.md) ACADEMY.md:59
without relaxation.** Below material sufficiency, the page is not written and the reason is stated. Publishing the refusals is a feature: it is the thing no autoblog can copy.
Forces
A refusal is a visible gap on a site that wants to look complete. Sufficiency needs a definition — source spans per factual sentence — that costs the generator most of its throughput. And a mock log that reads as measured is a refusal gate lying about itself.
Applicability
Generated documentation, grounded articles, this catalog's thin records.
Transformations
- holding a page until a contradiction in the corpus is resolved
- publishing a refusal where a page was expected
- writing from a single sentence
- a refusal log that reads as measured when it is illustrative
A refusing transformation is not one that is discouraged: it is one that, applied, makes the invariant above false. The word is the tree's, and it is the same word the join uses.
Consequences
What is published can be trusted because what was not published is visible. The honest status: STATED — the live instance is alkeyword's; the log that would witness it here is a mock.
Failure mode it answers
Agent Omniscience — Letting an agent's claims exceed its evidence boundary. Paid for at: AGENCY.md §6 (what is established vs a reading)
Witness
No witness. This pattern is STATED — the tree has no check for its invariant.
Counterexample
No counterexample shipped (required only when WITNESSED).
What to take away
- from the animationThe thin page was refused with its reason published; the sourced one was written.
- from the syntaxThe gate lives in the alkeyword spec §3.2 and is inherited without relaxation.
- from the literaturePopper: a claim that cannot be refused is not a claim; fail-closed defaults in security.
- from the witnessSTATED: the Academy refusal log is MOCK and this page says so; the thin records in this catalog are the same discipline applied to itself.
Prior art — and what is not claimed
| work | relation | what it shares | where it differs |
|---|---|---|---|
| Fail-closed defaults | antecedent | the safe outcome on missing information is refusal | none claimed |
| Popperian falsifiability as an admission rule | close analogue | admit only what could be refused | philosophy of science, applied here to a build gate |
Novelty not claimed. Fail-closed is a first principle of security engineering. The Academy refusal log is MOCK (ACADEMY.md:79); alkeyword's refusal rule is the live instance, and only that one counts.
Realizations in the tree
- ACADEMY.md §Read
- alkeyword.com/docs/spec/README.md §3.2
Relations with other patterns
Evidence Before Claim WITNESSED · Refusing Join WITNESSED