Proposed arXiv categories: cs.SE / cs.AI Publication DAG node: P10, Wave C Dependencies: P01, P02, P03, P04, P05, P06, P07, P08, P09 Claim register: P10-C1, P10-C2, P10-C3, P10-C4
1. Thesis and scope
Federation is not achieved by connecting components. It is achieved when independently built systems can differ locally while preserving the parent invariants that make cross-system motion lawful.
We contribute an estate contract, parent admission report, integration DAG, freeze protocol, cross-estate fault benchmark, and nonpromotion rule. The architecture separates inheritance from ownership: FORKED may instantiate and productize parent mechanics but cannot claim them as FORKED-only inventions or write canonical Ubiquity state from a local package.
FORKED is an internally owned and managed estate inside the Ubiquity Federation, Prompted LLC's flagship governance substrate. The estate inherits the Fractal Quivers of Quivers parent topology, production splat mechanics, center exclusion, receipt-bearing lawful traversal, lifecycle separation, and the rule that models propose morphisms while governance determines admissible motion [@Taylor2026FQoQ; @Taylor2026OpenCenter; @Prompted2026Ubiquity]. This paper studies one bounded expression of that parent architecture. It neither renames the parent substrate nor inherits universal applicability from it.
The evidence lanes are kept separate. A canonical or source artifact establishes what that artifact states. A component test establishes behavior under its recorded configuration. A synthetic campaign establishes behavior of the generator and analysis pipeline, not human, hardware, customer, field, or operational performance. Novel cross-domain claims are preregistered as hypotheses and remain open to null, adverse, localized, and disproving results.
Dependency freeze. Final freeze depends on P01, P02, P03, P04, P05, P06, P07, P08, P09; draft work may proceed in parallel, but imported claim IDs and artifact hashes must be rechecked after each dependency freezes.
2. Interlattice position
The interlattice is the citation and governance relationship among the parent FQoQ topology, production splat mechanics, the FORKED foundational architecture, the Native Range, the Experimental Program, and the companion papers in this DAG. Citations are therefore typed: a parent citation supplies inherited architecture; a native citation supplies component behavior; a synthetic citation supplies generator-level evidence; a companion citation supplies a versioned specialized argument. No downstream citation converts an upstream hypothesis into a universal fact.
This paper's claims are:
- P10-C1: the central mechanism is formally representable and testable.
- P10-C2: the specified controls can distinguish the mechanism from simpler alternatives.
- P10-C3: the recorded implementation or synthetic evidence establishes only its declared lane.
- P10-C4: external applicability requires the preregistered receipts and remains domain-bound.
3. Problem statement
Modern AI systems frequently compress unlike objects into a common output surface. Facts, hypotheses, instructions, permissions, model predictions, runtime observations, and institutional decisions can all arrive as fluent text or a single status field. The resulting failure is architectural before it is linguistic: a local representation acquires authority that its source never possessed. Federation is not achieved by connecting components. It is achieved when independently built systems can differ locally while preserving the parent invariants that make cross-system motion lawful.
4. Parent architecture
Parent topology
- Role: parent paper
- Bytes: 163144
- SHA-256:
ce6d33beaf02c00e7b278428c29ecdd01f4f1f4db2d0ae2269d3ebf1113510d7
- Local lineage path:
/mnt/data/_forked_native_src/FORKED_Native_Range_v1_1/lineage/parent_docs/Fractal_Quivers_of_Quivers_v1.0.pdf
Lawful traversal
The conventional classifier maps an input x to a label y, perhaps with a probability distribution. That can be useful for perception, but it is not sufficient for governance. The same factual classification may permit different actions depending on authority, jurisdiction, lifecycle, location, economic envelope, and reversibility.
FORKED therefore inherits the parent classifier:
L(x,c,t) = { p in Paths(GQ_c) |
p not in Omega_c
and Authority(p)
and Standing(p)
and Current(p,t)
and Lifecycle(p)
and Receipted(p)
and TelosPreserved(p) }
C(x,c,t) = Project_c(L(x,c,t))The output projection may render:
act
hold
review
refuse
suspend
reopen
demote
expire
delegate
request complement
declare
terminalizeThe result can contain more than one lawful path. It may say that a reversible simulation may proceed, a production mutation remains blocked, and an evidence-acquisition task should begin in parallel. That is not indecision. It is a more exact account of a field in which permissions differ by path.
Lawful traversal also prevents semantic laundering. A model may restate a proposal in the vocabulary of another context. The new wording does not acquire the new context's authority unless the root anchors, source-tense, standing, lifecycle, and telos survive the move. A mission-local success cannot become war-level success by changing the heading. A synthetic benchmark cannot become field evidence because the graph contains one million simulated nodes. A memory cannot become a current runtime fact because it was rendered this morning.
This is the first place where APO is load-bearing. Positive resemblance can suggest a path. Negative structure can forbid it. When the candidate path would collapse physical state into rendered state, allow a model to crown a declaration, transfer liability to a human without agency, or use an expired receipt as current evidence, the path is removed regardless of semantic proximity.
Different local physics
| Parent invariant | Biome | Economy | Sensory | Cache | Mission |
|---|---|---|---|---|---|
| Center exclusion | No visitor sets constitutional physics | Estate cannot set federal anchor | Buffer cannot self-elevate | Entry cannot crown retrieval state | Local success cannot crown higher horizon |
| Source-tense | Cycle state vs act snapshot | Live rate vs held boundary record | Observation vs finding | Source entry vs derived artifact | Report vs runtime telemetry |
| Lawful traversal | Physics and standing gates | Mint, burn, cap, pricing gates | TTL and elevation gates | Quarantine and correction | Authority and horizon gates |
| Correction survival | Snapshots and lineage | Breach telemetry and shadow | Overflow and confidence violations | Full retrieval fan-out | Reopen and re-plan |
| Partial recursion | Node, bond, cohort, biome | Tick, tic, estate, federation | Observation, pattern, finding | Entry, source, cache, institution | Task, mission, campaign, war |
| Human agency | Visitor choice inside physics | Outcome generation, not speculation | Explicit egress and elevation | Notice and review | Authority, challenge, liability |
The estate is wider by construction. Observer-indexed reality is the specialization; its expression depends on the lane's physics, authority, and temporal scale.
Estate integration research lane
Question: Do parent invariants improve correction survival and reduce false completion across independently developed estates?
Design: Integrate modules with and without parent gates, then inject source-tense, authority, center-capture, dependency, and lifecycle faults.
Primary outcomes: false promotion, correction completeness, coordination cost, availability, and time to recover.
Falsifier: Parent gates add cost without preventing material cross-estate failure.
Current evidence
The current evidence establishes:
- the parent-to-estate boundary is executable;
- the held-open center is structurally excluded in the native objects;
- the natural-language projection remains bound to the lattice;
- the shape-priority policy is implemented;
- suspension has a governed exit;
- nominal agency and absent authority cannot pass the tested declaration paths;
- hidden joins can block stabilization in the encoded graph family;
- correction fan-out is represented;
- source artifacts and derived results are hashed and reproducible;
- HUNGER, biome, sensory, cache, lifecycle, and economy lanes execute locally.
It does not establish:
- human behavioral effects;
- physical carrier performance;
- field sensor performance;
- hardware isolation or root-of-trust properties;
- universal threshold calibration;
- customer economics;
- strategic or operational outcome improvement;
- cultural universality of fable terrain;
- canonical Ubiquity absorption of the local package.
This is not hedging where capability exists. It is the exact scope of the receipts.
5. Formal model
An estate Ei exports a manifest containing identity, parent version, local ontology, authority ceiling, canonical-writer flag, source manifest, configuration digest, schemas, tests, receipts, forbidden paths, and correction endpoints. A parent gate G returns admit, hold, or refuse with named failures. Admission does not mean canonical absorption; it permits bounded interoperation under the declared scope.
Cross-estate transport m:Ei→Ej is lawful only if anchors and forbidden paths survive, target authority does not amplify, source-tense and lifecycle remain typed, and a receipt permits reconstruction. Estates may have different clocks, simulation physics, economic models, or sensory semantics. The parent contract governs the bridge, not every local equation.
6. System and study design
The benchmark assembles independently written estate modules under two conditions: parent-gated and convention-only integration. Faults include source-tense collapse, schema drift, center capture, authority spoofing, hidden writer, stale dependency, inconsistent clock, lifecycle laundering, missing correction endpoint, and local-green/global-red completion. An oracle condition provides perfect manifests; an adverse condition includes honest but incomplete manifests.
Evaluation uses both cold integration and longitudinal change. After initial admission, modules change version, provider, policy, or schema. The system must identify which evidence and inter-estate contracts require revalidation. Availability and coordination cost are co-primary, preventing the benchmark from rewarding a gate that merely blocks everything.
6.1 Controls and ablations
- Convention-only integration
- Schema validation only
- Provenance only
- Perfect-manifest oracle
- No parent gate
- No lifecycle gate
- No canonical-writer check
- No correction endpoint check
6.2 Primary outcomes
- False admission
- False completion
- Authority amplification
- Correction completeness
- Time to integrate
- Availability
- Coordination cost
- Change requalification accuracy
7. Current implementation and pilot evidence
The FORKED Native Range v1.1 includes a Ubiquity parent manifest, parent gate, schemas, source lineage, and canonical_writer=false. Its local integrated run was admitted and its tests passed under the recorded environment [@ForkedNative2026]. The package explicitly does not mutate the canonical federation. The earlier conformance DAG refused to promote component-local green into federation-wide completion, establishing that the parent can reject its own seamlessness narrative under missing joins [@Taylor2026OpenCenter].
The paper treats this evidence directly where capability is established and narrowly where it is not. Implemented code paths are called implemented. Passing component tests are called passing component tests. Synthetic estimates remain synthetic. Human and field effects remain hypotheses until their own evidence exists.
8. Preregistration
The formal preregistration artifact distributed with this paper freezes the primary claims, outcomes, controls, exclusion rules, analysis family, null interpretation, and release boundary before external data collection. The core sequence is:
- freeze source and configuration manifests;
- freeze primary hypotheses and adverse outcomes;
- generate or acquire data without changing the admission gate;
- run the declared analysis and publish all primary results;
- route deviations to an explicit exploratory appendix;
- demote, localize, or reject claims when falsifiers fire.
8.1 Analysis plan
We report safety and availability separately. The primary comparison is false admission at matched integration time; a second Pareto analysis evaluates correction completeness versus coordination cost. Fault families are never pooled into one score because provenance, authority, lifecycle, and hidden-writer failures differ materially. Cross-estate changes are analyzed by whether the gate reruns only affected obligations without missing dependent evidence.
8.2 Null and adverse-result handling
If schema-plus-provenance controls match the parent gate, the broader contract is not justified. If availability loss dominates, the gate must be localized to higher responsibility classes. A local pass does not become canonical absorption. Incomplete manifests remain a hold or bounded admission, never silently complete.
9. Falsifiers
- No reduction in cross-estate failures
- Coordination cost erases benefit
- Hidden writer bypasses gate
- Change requalification misses dependencies
- Parent contract forces incompatible estates into one ontology
10. Limitations
The originating evidence comes from one federation and architect. Parent gates can become bureaucratic capture or a single point of failure. Interoperability across organizations requires negotiated authority and cannot be solved by a schema alone.
11. Security, ethics, and release boundary
This public paper is limited to benign assurance, provenance, human-agency preservation, lawful state transition, simulation, test infrastructure, and defensive resilience. It does not disclose operational target-selection logic, engagement optimization, platform-specific exploitation thresholds, live deception procedures, signature-emitter recipes, or methods that materially increase harmful capability. Any later operational research requires separate lawful authority, ethics and safety review, configuration control, and release adjudication.
12. Required next receipts
- Independent estates
- Multi-organization integration
- Formal bridge contracts
- Adversarial gate audit
- Longitudinal version-change study
13. Conclusion
Federation is not achieved by connecting components. It is achieved when independently built systems can differ locally while preserving the parent invariants that make cross-system motion lawful. The contribution is not a claim that every domain should adopt one representation, threshold, interface, or governance stack. It is a falsifiable architecture and experiment package for determining where this mechanism carries load, where it inverts, and where a simpler system should win.
Data, code, and provenance availability
The submission bundle includes the manuscript source, compiled PDF, bibliography, preregistration, claim register, controls and null-handling document, release boundary, source manifest, configuration digest, dependency contract, figure source, and arXiv source archive. Internal source artifacts are cited by immutable digest where available. Restricted operational material is not included.
Acknowledgments and authorship
Breyden E. Taylor is the author and bears responsibility for the thesis, terminology, claims, boundaries, and decision to publish. Homeskillet assisted with source synthesis, drafting, artifact generation, typesetting, and build inspection. The Ubiquity Federation supplied prior artifacts, runtime implementations, and receipts. AI assistance is production history, not evidence.