# Learn once, apply everywhere

> Every organization has to find out the same things: what a provider's offer can really do, which of its limits bite, which terms forbid which uses, which pattern for approvals works, which piece of judgment can safely become a rule. Endoskeletal lets one organization's hard-won evidence become every organization's starting point, without anyone having to take anyone else's word for it.

Canonical: https://endoskeletal.com/learning/
Last updated: 2026-09-28

**Diagram: Learn once, apply everywhere: how knowledge is pooled across organizations.**

- Operating organizations (A, B) publish **outcome evidence**: how a realization actually performed for them. A research organization publishes **verified bundles** from bounded sandbox probes checked against provider terms.
- The **knowledge network** stores signed, content-addressed claims. **Corroboration** is derived when independent sources agree; contradiction is derived when they disagree.
- Importers (C, D, E) assert those claims under their own trust policies: a new organization imports at founding; another sees its capability frontier move from UNKNOWN to REALIZABLE; a cautious one keeps imported claims at N until its own probe agrees.
- Importers' requirements add up to **fleet demand**, which sets the research organization's priorities.

*Publishers contribute evidence, importers decide how much to trust it, and fleet demand decides what gets learned next.*

## What gets pooled

| Knowledge | Travels as | Example |
| --- | --- | --- |
| What a provider's offer can do | Affordance claims with sandbox evidence | A backup archive serves reads in under 20 ms, though it isn't marketed for it |
| How an offer behaves in production | Outcome evidence from operating organizations | Observed monthly availability of a managed database across 40 tenants |
| What the terms allow | Counsel's findings as claims, with the clause cited | A scheduled-jobs service may not be used as general compute |
| What composes | Refinement arguments for compositions | Event relay + state store with conditional writes refines DurableQueue |
| What didn't work | Rejections with the conjunct that failed | A queue offer rejected for jurisdiction, so nobody probes it again for EU needs |
| How to organize | Packages of patterns | Squad, ReviewedProposal, RealizationEnvelope, Crystallize |
| Judgment that became a rule | Distilled implementations, offered with their envelope and evidence | A severity classifier for a common advisory feed, abstaining outside its envelope |

## Import is not belief

Importing a bundle asserts its claims under the *importer's* trust policy. By default they start at N. Each organization decides what promotes them: its own probe agreeing, two independent publishers agreeing, or a publisher it has chosen to trust for that vocabulary. When publishers disagree, the claim becomes contradicted (B) and the organization's contest-resolution rule gives it an owner and a deadline.

*northwind.esk · information rules*

```esk
-- Pooled knowledge starts unknown, and earns its way up.
use ev.TrustPolicy(
  source-kind  = ag.ExternalKnowledgeBase,
  base         = N,
  promote-when = ev.CorroboratedBy(2, independent = true)
                 or ev.ConfirmedByOwnProbe(within = 14 d),
  vocab        = { pr.Affordance, arch.Refines, pv.availability }
) as PooledTrust

-- We trust one research publisher on terms findings, because its counsel cites clauses.
use ev.TrustPolicy(
  source-kind = kb.Publisher,
  base        = T,
  vocab       = { pr.TermsForbid }
) as TermsFindings

use ev.ContestResolution(
  owner    = Architect,
  vocab    = pr.Affordance,
  deadline = 7 d
) as PooledContests
```

A negative finding is trusted more readily than a positive one here, and that's deliberate: being told a use is forbidden costs you nothing but a probe you won't run. Being told a use is allowed could cost you a contract.

## Starting up the curve

A new company imports at founding. On day one its capability frontier already knows most of what the fleet knows.

- Day one, alone: 4 realizable · 19 unknown · 1 unsatisfiable
- Day one, with pooled knowledge: 19 realizable · 2 need an amendment · 2 unknown · 1 unsatisfiable

"Realizable" here still means realizable under the new company's own policy: the pooled claims it trusts at T, plus the ones it has already confirmed with a cheap probe. The pool saves the research, not the judgment.

## The fleet decides what gets learned next

Research organizations are organizations too, with budgets. They spend them where the fleet needs answers. Importers' unmet requirements add up to fleet demand, and a research organization ranks what to study by demand × importance × uncertainty × expected savings × reuse, divided by the cost of the probe.

*research.esk*

```esk
norm Allocate {
  obligation of Economics.Economist to persona
  when occurred tick(t) and t.boundary = "week"
  aim within 1 d: occurred derive(pr.Priority(o)) by Economics.Economist
}

use ev.TrustPolicy(
  source-kind = pr.FleetParty,
  base        = T,
  vocab       = { pr.FleetDemand }
) as FleetTrust
```

## What never leaves

Publishing is an external act, so it needs a power, and it's subject to every non-tradeable rule in force. What an organization may publish is claims about capabilities and providers: affordances, observed properties, terms findings, compositions, rejections. Its positions, occupants, customers, commitments and data are not capabilities and have no path out.

*northwind.esk*

```esk
norm PublishOutcomes {
  power of Architect to authorize execute about kb.Publish
  when b is kb.Bundle
       and b.vocab in { pr.Affordance, pv.availability, pv.p95-latency, arch.Refines, pr.TermsForbid }
  level collective
}

norm NoCustomerData {
  prohibition on any Party
  aim occurred execute(kb.Publish, b) and exists x : Entity . x in b.claims
      and x.about is cu.Customer
  level constitutional   not tradeable   not defeasible
}
```

## Knowledge that stays true

Pooled claims decay like any other. A bundle carries its verification policy, for example re-probe every 60 days and corroborate with an importer's own probe. A bundle is never edited: when a provider changes its terms, the publisher issues a revision that attacks the old claim and supersedes its hash. Importers that relied on it see the claim turn F or B, their reconsideration triggers fire, and every organization that built on the old answer learns about the change the same day.

*durableobjectstorage bundle (excerpt)*

```json
{
  "@type": "KnowledgeBundle",
  "name": "knowledge/aurelian/durableobjectstorage",
  "version": "2027.04.09",
  "valid_from": "2027-04-09", "valid_to": "2027-06-08",
  "verification_policy": {
    "reverify_after": "P60D",
    "method": "sandbox re-probe",
    "corroborate_with": ["an importer's own sandbox probe", "a second research organization's bundle"]
  },
  "claims": [{
    "proposition": ["prop", "arch.Refines", "composite:BlobVault+EdgeKV(front)", "DurableObjectStorage"],
    "provenance": "derived",
    "evidence": ["obs-9a9defab7a44", "obs-3bc26564368d", "obs-8237d1df775b", "obs-572941aae3fa"],
    "confidence": { "p": 0.9 },
    "derivedFrom": { "method": "refinement argument" }
  }],
  "content_hash": "sha256-88bf13f0315459318637345d178a924d5ad0a10d7f41063363ceee5b7f87557e"
}
```
