endoskeletal kernel 1 · lib 2026.09

How decisions get made

Learn once, apply everywhere

Every organization has to find out the same things: what a provider's offer can really do, which of its limits bite, which terms forbid which uses, which pattern for approvals works, which piece of judgment can safely become a rule. Endoskeletal lets one organization's hard-won evidence become every organization's starting point, without anyone having to take anyone else's word for it.

Learn once, apply everywhere: how knowledge is pooled across organizationsoutcome evidenceverified bundlescomparepriority → researchOrg Aruns a composed storeOrg Bruns a distilled triageResearch orgsandbox probes, counselpublisherKnowledge networksigned bundlescontent-addressed claimsCorroborationderived from independent sourcesOrg C (new)imports at foundingOrg DUNKNOWN → REALIZABLEOrg Eown policy: probe firstFleet demandwhat getsresearched next
Publishers contribute evidence, importers decide how much to trust it, and fleet demand decides what gets learned next.
Text description of this diagram
  • Operating organizations (A, B) publish outcome evidence: how a realization actually performed for them. A research organization publishes verified bundles from bounded sandbox probes checked against provider terms.
  • The knowledge network stores signed, content-addressed claims. Corroboration is derived when independent sources agree; contradiction is derived when they disagree.
  • Importers (C, D, E) assert those claims under their own trust policies: a new organization imports at founding; another sees its capability frontier move from UNKNOWN to REALIZABLE; a cautious one keeps imported claims at N until its own probe agrees.
  • Importers' requirements add up to fleet demand, which sets the research organization's priorities.

What gets pooled

KnowledgeTravels asExample
What a provider's offer can doAffordance claims with sandbox evidenceA backup archive serves reads in under 20 ms, though it isn't marketed for it
How an offer behaves in productionOutcome evidence from operating organizationsObserved monthly availability of a managed database across 40 tenants
What the terms allowCounsel's findings as claims, with the clause citedA scheduled-jobs service may not be used as general compute
What composesRefinement arguments for compositionsEvent relay + state store with conditional writes refines DurableQueue
What didn't workRejections with the conjunct that failedA queue offer rejected for jurisdiction, so nobody probes it again for EU needs
How to organizePackages of patternsSquad, ReviewedProposal, RealizationEnvelope, Crystallize
Judgment that became a ruleDistilled implementations, offered with their envelope and evidenceA severity classifier for a common advisory feed, abstaining outside its envelope

Import is not belief

Importing a bundle asserts its claims under the importer's trust policy. By default they start at N. Each organization decides what promotes them: its own probe agreeing, two independent publishers agreeing, or a publisher it has chosen to trust for that vocabulary. When publishers disagree, the claim becomes contradicted (B) and the organization's contest-resolution rule gives it an owner and a deadline.

northwind.esk · information rulesesk
-- Pooled knowledge starts unknown, and earns its way up.
use ev.TrustPolicy(
  source-kind  = ag.ExternalKnowledgeBase,
  base         = N,
  promote-when = ev.CorroboratedBy(2, independent = true)
                 or ev.ConfirmedByOwnProbe(within = 14 d),
  vocab        = { pr.Affordance, arch.Refines, pv.availability }
) as PooledTrust

-- We trust one research publisher on terms findings, because its counsel cites clauses.
use ev.TrustPolicy(
  source-kind = kb.Publisher,
  base        = T,
  vocab       = { pr.TermsForbid }
) as TermsFindings

use ev.ContestResolution(
  owner    = Architect,
  vocab    = pr.Affordance,
  deadline = 7 d
) as PooledContests

A negative finding is trusted more readily than a positive one here, and that's deliberate: being told a use is forbidden costs you nothing but a probe you won't run. Being told a use is allowed could cost you a contract.

Starting up the curve

A new company imports at founding. On day one its capability frontier already knows most of what the fleet knows.

Day one, alone

4 realizable · 19 unknown · 1 unsatisfiable

Day one, with pooled knowledge

19 realizable · 2 need an amendment · 2 unknown · 1 unsatisfiable

realizableafter amendmentunknownunsatisfiable

"Realizable" here still means realizable under the new company's own policy: the pooled claims it trusts at T, plus the ones it has already confirmed with a cheap probe. The pool saves the research, not the judgment.

The fleet decides what gets learned next

Research organizations are organizations too, with budgets. They spend them where the fleet needs answers. Importers' unmet requirements add up to fleet demand, and a research organization ranks what to study by demand × importance × uncertainty × expected savings × reuse, divided by the cost of the probe.

research.eskesk
norm Allocate {
  obligation of Economics.Economist to persona
  when occurred tick(t) and t.boundary = "week"
  aim within 1 d: occurred derive(pr.Priority(o)) by Economics.Economist
}

use ev.TrustPolicy(
  source-kind = pr.FleetParty,
  base        = T,
  vocab       = { pr.FleetDemand }
) as FleetTrust

What never leaves

Publishing is an external act, so it needs a power, and it's subject to every non-tradeable rule in force. What an organization may publish is claims about capabilities and providers: affordances, observed properties, terms findings, compositions, rejections. Its positions, occupants, customers, commitments and data are not capabilities and have no path out.

northwind.eskesk
norm PublishOutcomes {
  power of Architect to authorize execute about kb.Publish
  when b is kb.Bundle
       and b.vocab in { pr.Affordance, pv.availability, pv.p95-latency, arch.Refines, pr.TermsForbid }
  level collective
}

norm NoCustomerData {
  prohibition on any Party
  aim occurred execute(kb.Publish, b) and exists x : Entity . x in b.claims
      and x.about is cu.Customer
  level constitutional   not tradeable   not defeasible
}

Knowledge that stays true

Pooled claims decay like any other. A bundle carries its verification policy, for example re-probe every 60 days and corroborate with an importer's own probe. A bundle is never edited: when a provider changes its terms, the publisher issues a revision that attacks the old claim and supersedes its hash. Importers that relied on it see the claim turn F or B, their reconsideration triggers fire, and every organization that built on the old answer learns about the change the same day.

durableobjectstorage bundle (excerpt)json
{
  "@type": "KnowledgeBundle",
  "name": "knowledge/aurelian/durableobjectstorage",
  "version": "2027.04.09",
  "valid_from": "2027-04-09", "valid_to": "2027-06-08",
  "verification_policy": {
    "reverify_after": "P60D",
    "method": "sandbox re-probe",
    "corroborate_with": ["an importer's own sandbox probe", "a second research organization's bundle"]
  },
  "claims": [{
    "proposition": ["prop", "arch.Refines", "composite:BlobVault+EdgeKV(front)", "DurableObjectStorage"],
    "provenance": "derived",
    "evidence": ["obs-9a9defab7a44", "obs-3bc26564368d", "obs-8237d1df775b", "obs-572941aae3fa"],
    "confidence": { "p": 0.9 },
    "derivedFrom": { "method": "refinement argument" }
  }],
  "content_hash": "sha256-88bf13f0315459318637345d178a924d5ad0a10d7f41063363ceee5b7f87557e"
}