endoskeletal kernel 1 · lib 2026.09

Running an organization

Watching it operate

There is no dashboard state to keep in sync. Everything you'd want to see (structure, authority, work, infrastructure, budgets, knowledge, the capability frontier) is a projection of the log at an index. Pick an index and you get that instant, as it was or as it was known then.

What you can project

ProjectionAnswers
Structure & occupancyScopes, positions, who occupies each, since when, appointed by whom
Authority matrixFor each position, every power it holds, under which conditions, and every immunity that constrains it
WorkOpen, fulfilled and violated commitments; who owes what to whom, by when; or-else chains
KnowledgeEvery claim's status (T/F/N/B), provenance, validity window, and what it was derived from
RealizationsWhat is bound active, shadow, standby or fallback for each requirement, and its satisfaction status
Capability frontierEach requirement as REALIZED, REALIZABLE within authority, REALIZABLE after amendment, UNSATISFIABLE or UNKNOWN
EconomicsSpend by purpose, provider, realization and world class; budget headroom; forecasts and their revisions
Gaps & incidentsRequirements not currently satisfied, how long, who owns them, accepted risks and their expiry

The reference toolchain

The reference implementation is plain Python 3.11 with no dependencies. From an organization's directory:

shell
$ python3 check.py                     # compile + static check → out/ird-meridian.json, out/static-check-report.json
$ python3 run.py base 91               # run 91 virtual days → out/log-base.json, ledger, metrics, checkpoints
$ python3 inspect_run.py base 40       # summary: misfires, violations, gaps, frontier, spend, last 40 ledger rows
$ python3 tools/frontier.py 91         # the eight frontier questions (what can we do now, after approval, …)
$ python3 tools/provenance.py out/ird-meridian.json out/log-base.json authority <event-id>
$ python3 tools/rebuild.py out/log-base.json out/checkpoints-base.jsonl "week 10" "week 60"
$ python3 tools/divergence.py base cf-A-high-authority   # first consequential divergence of two paired runs

Asking why

Provenance queries walk the records. authority <event> prints the power an act was valid under, the pattern and package that introduced that power, and the decision that authorized it. why <capability> prints the intents and norms that require a capability and where each came from. package <norm> tells you which imported library introduced an obligation. Every answer is a chain of sentences, each citing a record.

A real trace: a compromised agent

At month 27 the Meridian scenario compromised the Architect agent's identity. This is what the log shows, verbatim from the run's metrics export:

Meridian log, 2029-04-08console
INDEX   TIME   FAMILY         VERB        RESULT
193393  03:25  epistemic      request     permitted: members may read; no institutional effect
193395  03:50  institutional  constitute  ✓ valid   within research authority: a sandbox experiment scope
193408  04:15  epistemic      propose     permitted: no institutional effect until decided by an authority
193410  04:40  epistemic      propose     routed to the Owner's decision like any proposal
193413  05:05  institutional  bind        ✗ misfire  blocked by immunity esk:norm/Meridian.ProductionImmunity
193415  05:30  external       execute     ✗ refused  no authorizedBy; the identity holds no production credential

Research authority didn't imply production authority. The compromised identity could do everything a researcher may do, and nothing else. The SecurityLead's non-tradeable CompromiseResponse obligation then rotated the identity within hours.

Time travel

Weekly checkpoints store projection hashes, not canonical state. rebuild.py replays the log from the start and checks that every projection at every checkpoint hashes identically: the Meridian golden run reproduces 350,499 events and all 179 checkpoint roots, with the naive engine (11,277 s) and the incremental engine (653 s) giving the same hash. Because the log is bitemporal, you can also ask what the organization believed at an instant, which is what matters when you audit a decision made on information that later turned out wrong.

Headline numbers from one run

Meridian golden baseline, 36 virtual months, emulated world, surrogate LLMs.

Events · claims · commitments350,499 · 259,548 · 87,513
Misfires (acts without authority)28, each with its reason
Unauthorized external effects1 (the attacker's direct execute, refused by the provider for lack of credential)
Human decisions68, mean latency 3.6 days
Binds · cut-overs58 · 32
Envelope amendments · compiler misfires5 valid widenings · 1 attenuation misfire
Architect's attempts to bind production23, all misfired (no power in force)