How decisions get made
Learn once, apply everywhere
Every organization has to find out the same things: what a provider's offer can really do, which of its limits bite, which terms forbid which uses, which pattern for approvals works, which piece of judgment can safely become a rule. Endoskeletal lets one organization's hard-won evidence become every organization's starting point, without anyone having to take anyone else's word for it.
Text description of this diagram
- Operating organizations (A, B) publish outcome evidence: how a realization actually performed for them. A research organization publishes verified bundles from bounded sandbox probes checked against provider terms.
- The knowledge network stores signed, content-addressed claims. Corroboration is derived when independent sources agree; contradiction is derived when they disagree.
- Importers (C, D, E) assert those claims under their own trust policies: a new organization imports at founding; another sees its capability frontier move from UNKNOWN to REALIZABLE; a cautious one keeps imported claims at N until its own probe agrees.
- Importers' requirements add up to fleet demand, which sets the research organization's priorities.
What gets pooled
| Knowledge | Travels as | Example |
|---|---|---|
| What a provider's offer can do | Affordance claims with sandbox evidence | A backup archive serves reads in under 20 ms, though it isn't marketed for it |
| How an offer behaves in production | Outcome evidence from operating organizations | Observed monthly availability of a managed database across 40 tenants |
| What the terms allow | Counsel's findings as claims, with the clause cited | A scheduled-jobs service may not be used as general compute |
| What composes | Refinement arguments for compositions | Event relay + state store with conditional writes refines DurableQueue |
| What didn't work | Rejections with the conjunct that failed | A queue offer rejected for jurisdiction, so nobody probes it again for EU needs |
| How to organize | Packages of patterns | Squad, ReviewedProposal, RealizationEnvelope, Crystallize |
| Judgment that became a rule | Distilled implementations, offered with their envelope and evidence | A severity classifier for a common advisory feed, abstaining outside its envelope |
Import is not belief
Importing a bundle asserts its claims under the importer's trust policy. By default they start at N. Each organization decides what promotes them: its own probe agreeing, two independent publishers agreeing, or a publisher it has chosen to trust for that vocabulary. When publishers disagree, the claim becomes contradicted (B) and the organization's contest-resolution rule gives it an owner and a deadline.
-- Pooled knowledge starts unknown, and earns its way up.
use ev.TrustPolicy(
source-kind = ag.ExternalKnowledgeBase,
base = N,
promote-when = ev.CorroboratedBy(2, independent = true)
or ev.ConfirmedByOwnProbe(within = 14 d),
vocab = { pr.Affordance, arch.Refines, pv.availability }
) as PooledTrust
-- We trust one research publisher on terms findings, because its counsel cites clauses.
use ev.TrustPolicy(
source-kind = kb.Publisher,
base = T,
vocab = { pr.TermsForbid }
) as TermsFindings
use ev.ContestResolution(
owner = Architect,
vocab = pr.Affordance,
deadline = 7 d
) as PooledContestsA negative finding is trusted more readily than a positive one here, and that's deliberate: being told a use is forbidden costs you nothing but a probe you won't run. Being told a use is allowed could cost you a contract.
Starting up the curve
A new company imports at founding. On day one its capability frontier already knows most of what the fleet knows.
Day one, alone
4 realizable · 19 unknown · 1 unsatisfiable
Day one, with pooled knowledge
19 realizable · 2 need an amendment · 2 unknown · 1 unsatisfiable
realizableafter amendmentunknownunsatisfiable
"Realizable" here still means realizable under the new company's own policy: the pooled claims it trusts at T, plus the ones it has already confirmed with a cheap probe. The pool saves the research, not the judgment.
The fleet decides what gets learned next
Research organizations are organizations too, with budgets. They spend them where the fleet needs answers. Importers' unmet requirements add up to fleet demand, and a research organization ranks what to study by demand × importance × uncertainty × expected savings × reuse, divided by the cost of the probe.
norm Allocate {
obligation of Economics.Economist to persona
when occurred tick(t) and t.boundary = "week"
aim within 1 d: occurred derive(pr.Priority(o)) by Economics.Economist
}
use ev.TrustPolicy(
source-kind = pr.FleetParty,
base = T,
vocab = { pr.FleetDemand }
) as FleetTrustWhat never leaves
Publishing is an external act, so it needs a power, and it's subject to every non-tradeable rule in force. What an organization may publish is claims about capabilities and providers: affordances, observed properties, terms findings, compositions, rejections. Its positions, occupants, customers, commitments and data are not capabilities and have no path out.
norm PublishOutcomes {
power of Architect to authorize execute about kb.Publish
when b is kb.Bundle
and b.vocab in { pr.Affordance, pv.availability, pv.p95-latency, arch.Refines, pr.TermsForbid }
level collective
}
norm NoCustomerData {
prohibition on any Party
aim occurred execute(kb.Publish, b) and exists x : Entity . x in b.claims
and x.about is cu.Customer
level constitutional not tradeable not defeasible
}Knowledge that stays true
Pooled claims decay like any other. A bundle carries its verification policy, for example re-probe every 60 days and corroborate with an importer's own probe. A bundle is never edited: when a provider changes its terms, the publisher issues a revision that attacks the old claim and supersedes its hash. Importers that relied on it see the claim turn F or B, their reconsideration triggers fire, and every organization that built on the old answer learns about the change the same day.
{
"@type": "KnowledgeBundle",
"name": "knowledge/aurelian/durableobjectstorage",
"version": "2027.04.09",
"valid_from": "2027-04-09", "valid_to": "2027-06-08",
"verification_policy": {
"reverify_after": "P60D",
"method": "sandbox re-probe",
"corroborate_with": ["an importer's own sandbox probe", "a second research organization's bundle"]
},
"claims": [{
"proposition": ["prop", "arch.Refines", "composite:BlobVault+EdgeKV(front)", "DurableObjectStorage"],
"provenance": "derived",
"evidence": ["obs-9a9defab7a44", "obs-3bc26564368d", "obs-8237d1df775b", "obs-572941aae3fa"],
"confidence": { "p": 0.9 },
"derivedFrom": { "method": "refinement argument" }
}],
"content_hash": "sha256-88bf13f0315459318637345d178a924d5ad0a10d7f41063363ceee5b7f87557e"
}