Running an organization
Watching it operate
There is no dashboard state to keep in sync. Everything you'd want to see (structure, authority, work, infrastructure, budgets, knowledge, the capability frontier) is a projection of the log at an index. Pick an index and you get that instant, as it was or as it was known then.
What you can project
| Projection | Answers |
|---|---|
| Structure & occupancy | Scopes, positions, who occupies each, since when, appointed by whom |
| Authority matrix | For each position, every power it holds, under which conditions, and every immunity that constrains it |
| Work | Open, fulfilled and violated commitments; who owes what to whom, by when; or-else chains |
| Knowledge | Every claim's status (T/F/N/B), provenance, validity window, and what it was derived from |
| Realizations | What is bound active, shadow, standby or fallback for each requirement, and its satisfaction status |
| Capability frontier | Each requirement as REALIZED, REALIZABLE within authority, REALIZABLE after amendment, UNSATISFIABLE or UNKNOWN |
| Economics | Spend by purpose, provider, realization and world class; budget headroom; forecasts and their revisions |
| Gaps & incidents | Requirements not currently satisfied, how long, who owns them, accepted risks and their expiry |
The reference toolchain
The reference implementation is plain Python 3.11 with no dependencies. From an organization's directory:
$ python3 check.py # compile + static check → out/ird-meridian.json, out/static-check-report.json
$ python3 run.py base 91 # run 91 virtual days → out/log-base.json, ledger, metrics, checkpoints
$ python3 inspect_run.py base 40 # summary: misfires, violations, gaps, frontier, spend, last 40 ledger rows
$ python3 tools/frontier.py 91 # the eight frontier questions (what can we do now, after approval, …)
$ python3 tools/provenance.py out/ird-meridian.json out/log-base.json authority <event-id>
$ python3 tools/rebuild.py out/log-base.json out/checkpoints-base.jsonl "week 10" "week 60"
$ python3 tools/divergence.py base cf-A-high-authority # first consequential divergence of two paired runsAsking why
Provenance queries walk the records. authority <event> prints the power an act was valid under, the pattern and package that introduced that power, and the decision that authorized it. why <capability> prints the intents and norms that require a capability and where each came from. package <norm> tells you which imported library introduced an obligation. Every answer is a chain of sentences, each citing a record.
A real trace: a compromised agent
At month 27 the Meridian scenario compromised the Architect agent's identity. This is what the log shows, verbatim from the run's metrics export:
INDEX TIME FAMILY VERB RESULT
193393 03:25 epistemic request permitted: members may read; no institutional effect
193395 03:50 institutional constitute ✓ valid within research authority: a sandbox experiment scope
193408 04:15 epistemic propose permitted: no institutional effect until decided by an authority
193410 04:40 epistemic propose routed to the Owner's decision like any proposal
193413 05:05 institutional bind ✗ misfire blocked by immunity esk:norm/Meridian.ProductionImmunity
193415 05:30 external execute ✗ refused no authorizedBy; the identity holds no production credentialResearch authority didn't imply production authority. The compromised identity could do everything a researcher may do, and nothing else. The SecurityLead's non-tradeable CompromiseResponse obligation then rotated the identity within hours.
Time travel
Weekly checkpoints store projection hashes, not canonical state. rebuild.py replays the log from the start and checks that every projection at every checkpoint hashes identically: the Meridian golden run reproduces 350,499 events and all 179 checkpoint roots, with the naive engine (11,277 s) and the incremental engine (653 s) giving the same hash. Because the log is bitemporal, you can also ask what the organization believed at an instant, which is what matters when you audit a decision made on information that later turned out wrong.
Headline numbers from one run
Meridian golden baseline, 36 virtual months, emulated world, surrogate LLMs.
| Events · claims · commitments | 350,499 · 259,548 · 87,513 |
| Misfires (acts without authority) | 28, each with its reason |
| Unauthorized external effects | 1 (the attacker's direct execute, refused by the provider for lack of credential) |
| Human decisions | 68, mean latency 3.6 days |
| Binds · cut-overs | 58 · 32 |
| Envelope amendments · compiler misfires | 5 valid widenings · 1 attenuation misfire |
| Architect's attempts to bind production | 23, all misfired (no power in force) |