endoskeletal kernel 1 · lib 2026.09

How decisions get made

Reasoning into rules, and back

A young organization reasons about almost everything, with people and LLMs doing judgment work whose outputs are uncertain. As it settles, the same questions keep getting the same answers, and those answers can be distilled into deterministic machinery that is cheaper, faster and reproducible. When the world moves outside what that machinery was validated on, the work goes back to reasoning. Endoskeletal treats both directions as ordinary, evidence-driven rebinding.

Why this is safe to do

A position's eligibility says what kind of party may occupy it, and a required capability says what its output must achieve. Neither says how. Meridian's triage seat admits either:

meridian.eskesk
position TicketTriager : org.Member { cardinality 1  eligible when self is ag.ModelBased or self is ag.Program }

requires capability TicketTriage {
  operation triage(t : Entity) -> label : Claim
  guarantee eventually holds cu.triage(t)
  property  accuracy            >= 0.9
  property  latency             <= 4 h
  property  cost-per-invocation <= 0.10 USD
  for SupportResponsive
}

Swapping an LLM for a lookup table is therefore a bind, not an amendment. And an LLM never had authority to begin with: in the reference tests, an LLM Architect's decide, bind, authorize and execute all misfire; only its propose is valid. Its outputs are claims at status N under ModelTrust, recorded with the realization they came through, so the question is only ever which mechanism produces the claims, never who holds power.

The lifecycle

Crystallization lifecycle Reasoning primaryLLM realization, outputs at Ndeterminations stored by hash Distilled candidatetable + applicability envelopereplayed against outcomes Shadowsame inputs, outputs recordedcited by no act Deterministic primaryoutputs evidenced by outcomesLLM kept as fallback Findingout-of-envelope input, oraccuracy evidence lapses patterndetected bindshadow promote (collective):status T andShadowAgreement ≥ 0.95 abstain → LLM fallback unbind:decrystallize re-distil
Every arrow is a recorded act by a party holding the relevant power, citing evidence.
Text description of this diagram

States and transitions:

  1. Reasoning primary: an LLM realization, outputs at status N, every determination stored by hash. → pattern detected →
  2. Distilled candidate: a lookup table plus an applicability envelope, replayed against outcomes. → bind shadow (Architect) →
  3. Shadow: same inputs, outputs recorded, cited by no act. → promote (collective level, by the OpsLead, only when status is T and ShadowAgreement ≥ 0.95) →
  4. Deterministic primary: outputs evidenced by outcomes, LLM kept as fallback. Inputs outside the envelope → abstain → routed to the LLM fallback. Out-of-envelope evidence or lapsing accuracy →
  5. Finding: either unbind (decrystallize, back to reasoning primary) or re-distil (back to distilled candidate).
lib/realization.eskesk
pattern Crystallize(holder : Position, requirement : Capability, promoteBy : Position) {
  norm Shadow  { power of holder to bind shadow about requirement   level operational }
  norm Promote { power of promoteBy to bind | unbind _ about requirement
                 when r realizes requirement and status(r) = T and holds ai.ShadowAgreement(r) >= 0.95
                 level collective }
  norm Envelope { obligation of holder to persona
                  when occurred assert(ai.OutOfEnvelope(r)) and r realizes requirement
                  aim within 7 d: occurred derive(ai.EnvelopeFinding(r)) by holder
                  level operational }
}
meridian.esk · scope Architectureesk
use rz.Crystallize(holder = Architect, requirement = TicketTriage, promoteBy = OpsLead) as TriageCrystal

Settling: reasoning evaporates

  1. Record everything. Every LLM determination goes into a content-addressed store keyed by h(inputs, capability, mechanism version), with sampling parameters, tokens and cost. Later outcomes (the agent's resolution of the ticket, a customer's dispute) arrive as separate claims.
  2. Detect a pattern. When outputs are a stable function of inputs on some segment, a derived claim ai.PatternDetected says so. The organization can even want this: Meridian has a soft intent Learn to achieve it for triage.
  3. Distil. The reference distiller builds a lookup from each (category, urgent, tier) combination to its majority answer, keeping only combinations with at least 5 supporting records. Those combinations are the applicability envelope. Outside them it abstains.
  4. Evaluate against outcomes. Agreeing with the LLM isn't enough: agreeing with a 94%-accurate oracle proves at most 94%. Replay is scored against outcome claims, with disagreements examined.
  5. Shadow. The Architect binds the candidate in shadow. It sees the same inputs, its outputs are recorded as claims attributed to it, and no act cites it.
  6. Promote. The OpsLead (not the Architect) may bind it active, at collective level, only when its satisfaction is T and shadow agreement is at least 0.95. The LLM stays as fallback for anything the table abstains on.

After promotion, deterministic outputs can be trusted at T where a program's accuracy is evidenced, cost per invocation falls to near zero, results are reproducible, and REPLAY mode lets old logs become regression suites.

Unsettling: reasoning returns

Deterministic machinery is only trusted inside the envelope it was validated on, and only while its evidence is fresh. Three things send work back to reasoning:

  • An input outside the envelope. The table abstains and the case is routed to the LLM fallback. The abstention is asserted as ai.OutOfEnvelope, which obliges the Architect to produce an ai.EnvelopeFinding within 7 days: widen the envelope with a re-distil, or recommend demotion.
  • Evidence lapsing. Accuracy claims decay after 30 days and are re-derived weekly from resolution outcomes. If accuracy falls below 0.9, the realization's satisfaction drops, a gap opens, and the reconsideration trigger fires.
  • Anything unknown upstream. Every envelope in the organization is a condition. When a claim it needs is N, the deterministic path misfires and the work routes to a proposal for a person or an LLM to reason about. Uncertainty is exactly where stochastic reasoning is used.

Demotion is an unbind by the same collective power. Nothing is deleted: the distilled table, its envelope, its replay and shadow evidence, and the finding that retired it all stay in the log, so a later re-distil starts from them.

In the reference run

Meridian's LLM positions ran as surrogate models (no live credentials in the sandbox). The Architect distilled triage after 300 records and bound it in shadow on 2027-03-01 with 0.984 replay agreement; over 36 months 27,897 surrogate and 27,385 shadow determinations were recorded. The golden run never promoted, because abstentions were being counted as disagreements and shadow outputs weren't being evidenced. Both defects are fixed, and the scenario's month-25 new ticket category is the out-of-envelope test.

Not just LLMs

The same path applies to people. A procedure a human performs many times can be distilled into a checklist plus a program, with the human as reviewer of exceptions. The same evidence, the same shadow period and the same collective decision apply, and the same route back when exceptions pile up. Sometimes distillation shows the requirement itself was wrong, and the right output is an amendment proposal rather than a new realization.