Publication, lineage, and evidence notice
A temporal evidence protocol for parallel verification without parallel authority.
Copyright (c) 2026 Prompted LLC. All rights reserved.
Recommended citation. Taylor, B. E. (2026). Proof-Horizon Sharding: Correction-Surviving, Proof-Carrying Canonical Computation (Technical Whitepaper 1.2, Binder-Integrated Foundational Revision). Prompted LLC.
Document status. This manuscript is the v1.2 publication candidate. It is a from-the-top rewrite of the foundational protocol paper using the lineage-corrected v1.1 paper, the Prompted LLC public corpus, and THE BINDER - a history of the winching machinery, with receipts. Once admitted by Prompted LLC, v1.2 supersedes the architectural and origin framing of v1.1; v1.1 and v1.0 remain lineage, not current authority. [14] This is a technical disclosure and architecture paper, not a patent opinion or claim-construction document.
Publication order. This is the originating protocol and invention paper. The Forge Implementation of Proof-Horizon Sharding is a downstream implementation paper. Its current v1.0 cites PHS v1.1, the immediate predecessor of this revision. The Forge paper does not originate the protocol, and nothing in this revision transfers the protocol's authorship or Prompted LLC lineage to the implementation company. [38]
Core claim. Proof topology should follow epistemic dependency, not workspace topology. Many humans, agents, machines, clones, repositories, and organizations may inspect and prove an evolving system in parallel, while one serial authority advances what the system accepts as canonical.
Lineage statement. The broader governed-horizon primitive is inherited from Breyden E. Taylor's Ubiquity architecture at Prompted LLC and its FORKED estate. Proof-Horizon Sharding does not claim to originate horizon geometry. Its distinct contribution is the temporal-evidentiary specialization of horizon noncollapse: the earliest horizon at which a fact can lawfully become knowable becomes the sharding key for proof. From that rule follow exact subject binding, orthogonal proof fan-out, zero-authority verification lanes, governed convergence, descendant evidence carriage, recursive carrier proof, serial canonical admission, correction-surviving lineage, and deterministic re-entry. [1-13]
Binder evidence posture. THE BINDER is an evidence map, not the primary source of the facts it indexes. Its stable BND-01 through BND-22 markers resolve onward to two lane-complete extracts and then to primary charters, code, receipts, ledgers, and git observations. This paper retains those markers so a reader can traverse the evidence chain, but it does not promote the binder's summaries into a stronger source class than the binder itself declares. When a primary artifact and a summary disagree, the primary artifact governs. [31]
Revision 1.2
Version 1.2 makes eight material corrections and extensions.
- It retains the proper intellectual lineage from Prompted LLC and Ubiquity through Fractal Quivers of Quivers, Computing Around the Open Center, and FORKED to PHS.
- It distinguishes the upstream invention of governed horizon geometry and horizon noncollapse from the PHS-native use of lawful knowability as an evidence partition key.
- It reconstructs the operational prehistory of PHS through the covenant, strike, cable, board, winch, basin, and anchor machinery documented by THE BINDER.
- It makes explicit that those mechanisms are one recurrent current-to-target loop with different roles, not a loose vocabulary and not all synonyms for PHS.
- It identifies the tic-768-to-770 horizon-quiver build as a decisive self-falsifying construction event: a probe named for detached reproduction correctly failed to claim that rung because no remote contact occurred. [BND-16]
- It expands the protocol invariants with anchor preservation, residue visibility, anti-vacuity, observer-artifact non-occlusion, currentness-at-the-act, and honest-negative carriage.
- It integrates a fuller lived falsification history - capability verdicts overturned by execution, vacuous-green defects, marker occlusion, append-only correction, exact subject re-freezing, first local model consumption, and lead-premise falsification across every campaign wave - without converting operational evidence into universal proof. [BND-02, BND-04, BND-08, BND-15, BND-17, BND-18]
- It preserves the binder's negative findings as load-bearing results: fixture-green is not live-fired; the economy remains
SimOnly;basin_drainedhas not fired live; the rollback refusal path has been armed but not needed; and the campaign's use of winch vocabulary does not prove every wave traversed theWinchDialimplementation. [BND-11, BND-22, 31]
Contents
| Main sections | Continuation and appendices |
|---|---|
| Abstract | 12. Git reference realization |
| Executive statement | 13. Failure semantics and correction survival |
| 1. Introduction: assurance after comprehension scale | 14. Agentic systems and winch tempos |
| 2. Lineage, inheritance, and attribution | 15. Operational emergence and lived falsification |
| 3. One loop wearing many mechanism names | 16. Honest negatives and truth boundaries |
| 4. The horizon-quiver construction event | 17. Relationship to the Ubiquity corpus |
| 5. The temporal self-attestation problem | 18. Relationship to adjacent technical work |
| 6. Design thesis | 19. Origin, attribution, and invention method |
| 7. Formal protocol model | 20. Limitations and open work |
| 8. Reference epoch | 21. Conclusion |
| 9. Protocol invariants | Appendix A. Protocol pseudocode |
| 10. Receipt, carrier, basin, and ledger model | Appendix B. Reference receipt schema |
| 11. DAGs, quivers, and governed checkpoint history | Appendix C. Conformance checklist |
| Appendix D. Selected glossary | |
| Appendix E. Lineage and claim register | |
| Appendix F. Binder evidence map | |
| References and acknowledgment |
Abstract
Modern software and agentic systems can generate, inspect, test, and distribute change through many concurrent actors. Their assurance models, however, frequently collapse several different facts into one status such as green, pushed, released, wired, live, or done. A source artifact may exist locally without being available from an intended remote. A push may report success without an independent readback. A test may pass only because the authoring machine contains untracked state. A fixture may be green while no live call site invokes it. A receipt may describe its predecessor accurately while being unable to prove its own later propagation. A named probe may imply a proof rung that its evidence never reached. When these distinctions are erased, the system permits artifacts to imply knowledge, execution, authority, or effect beyond what they could lawfully establish.
Proof-Horizon Sharding (PHS) is a checkpoint protocol derived within the Ubiquity governance substrate and from the horizon-noncollapse doctrine expressed in FORKED. Prompted LLC defines Ubiquity as a governance substrate for sovereign adaptive systems: AI-mediated systems intended to increase capacity without collapsing agency, authorship, judgment, or meaningful contribution. Fractal Quivers of Quivers supplies a living topology of lawful and forbidden motion. Computing Around the Open Center supplies bounded, receipt-bearing splat computation around a center that is held open rather than crowned. FORKED is an estate inside that parent substrate and makes governed horizon geometry explicit: task, mission, battle, campaign, war, institutional, and other scales retain distinct telos, authority, standing, success and failure conditions, externalities, and irreversible surfaces. A declaration at one horizon does not silently acquire authority at another. [1-7]
PHS specializes that inherited horizon primitive to evidence through time. It partitions verification according to the earliest horizon at which each claim can lawfully become knowable. Canonical mutation remains serial. Verification fans out across zero-authority proof lanes over one immutable subject. Independent observations converge into a descendant receipt or state carrier. That carrier then becomes a new proof subject, preventing it from certifying its own future. Synchronized repositories and refs function as projections of canon rather than parallel canonical authorities.
This revision also reconstructs the operating machinery in which the protocol became visible. The binder records one recurrent current-to-target loop wearing several mechanism names: a covenant binds the pull; a six-ray Harpoon strike produces the thing's shape; cables route bounded tension around a frozen center; a board compiles admitted covenants into a DAG; a winch raises only admitted and executable cables at one of two tempos; dissonance basins preserve unresolved tension and residue; anchoring keeps the reference frame outside the ordinary node set; and receipts carry what happened forward without laundering it into a stronger horizon. [BND-01, BND-05, BND-09, BND-13, BND-17, BND-20]
The machinery and the protocol are related but not identical. Current-to-target reality winching is the broader operating motion. PHS is the temporal evidence law governing what may be claimed about that motion and when. The decisive construction event came when the horizon-quiver build disciplined its own attractive name: a probe called detached_reproduced had made no remote contact, so its receipts correctly remained at source_admitted rank zero. The apparatus proved that coherence, naming, and local execution do not constitute admission to a stronger proof horizon. [BND-16]
The resulting primitive is correction-surviving, proof-carrying canonical computation: distributed execution, verification, custody, and falsification can scale independently while accepted state remains temporally honest, reproducible, auditable, correction-bearing, and deterministically resumable. Git is the reference realization, not the boundary of the method. The same geometry can govern any substrate with strongly identified subjects, ordered successor state, independently observable proof surfaces, durable receipts, explicit authority ceilings, visible residue, and governed convergence.
Keywords: Ubiquity; Prompted LLC; FORKED; horizon noncollapse; Proof-Horizon Sharding; lawful knowability; current-to-target reality winching; covenant; Harpoon; cables; DAG; GUNSLINGER; HIDALGO; dissonance basin; anchor; proof-carrying computation; correction survival; provenance; serial authority; sovereign continuity.
Executive statement
PHS is the temporal evidence law of governed winching: many cables may pull in parallel, but no cable may crown the center, no observer may silently become the authority, and no artifact may claim a future it could not yet know.
The production problem has changed. AI systems can generate coherent candidate surfaces faster than a human or conventional review team can inspect every line. That does not eliminate human judgment. It changes where judgment must enter. Permanent per-action approval becomes a bottleneck, a rubber stamp, or a blind spot at production throughput. Prompted LLC's Ubiquity architecture therefore treats human judgment as reusable structure: corrections, refusals, approvals, exceptions, rollbacks, and observed outcomes become evidence that can be carried forward instead of being re-asked in every session. [1,4,8,28]
The harder problem is not simply whether a model can act. It is whether the surrounding system can preserve the difference between a plausible candidate and admitted state; between a named capability and a live one; between a fixture and a wired call site; between a local test and independent reproduction; between a receipt and proof of the receipt carrier; between a repository checkpoint and a real-world effect.
The parent matters. Ubiquity is the constitutional governance substrate. Fractal Quivers of Quivers supplies living responsibility topology. Computing Around the Open Center supplies the bounded local compute object and the held-open center. FORKED specializes these mechanics around observer-indexed reality, suspension, correction, declaration, and horizon integrity. PHS specializes them again along the temporal-evidentiary axis. The relationship is inheritance, not renaming. [5-7]
The operating machinery matters too. The binder's central finding is not that Forge accumulated a colorful lexicon. It is that covenant, strike, cable, board, winch, basin, and anchor are roles inside one recurrent loop. A current state is bound to a target under a covenant. Harpoon strikes the proposal through multiple rays rather than accepting its first fluent shape. Cables carry bounded work and contradiction. The board compiles only admitted covenants into executable dependencies. The winch chooses a tempo without changing the proof law. Basins hold unresolved tension rather than erasing it. Anchoring keeps telos and center-exclusion load-bearing without turning them into ordinary work nodes. Receipts preserve the work, the limits, the failures, and the next edge. [31]
The central refusal remains simple:
No immutable artifact may be treated as evidence of an event that had not occurred when the artifact was created.
A source-bearing commit can establish that exact source bytes exist. It cannot establish its own later remote propagation. A remote readback can establish that an intended ref exposes the exact subject. It cannot establish independent reproduction. A clean clone can establish acquisition and a declared validation predicate. It cannot establish deployment, adoption, or outcome. A descendant carrier can preserve those observations. It cannot certify its own later propagation. Every stronger claim requires a later lawful edge.
This refusal produces a complete control law:
bounded candidate / covenant
-> shape-producing strike
-> immutable source subject
-> parallel orthogonal proof cables
-> governed join
-> descendant receipt carrier
-> carrier becomes next proof subject
-> terminal reconciliation
-> one serial canonical admission pathThe protocol does not ask one human to read everything. It scales bounded falsification. Many proof workers may inspect the same fixed subject through different failure surfaces. None gains canonical admission authority merely by producing a receipt. Their observations converge only under a declared closure predicate. Evidence classes remain distinct. Failures remain bound to the subjects that failed. Corrections produce new subjects instead of rewriting history. A successor resumes from the first missing proof edge rather than reconstructing intent from a vanished context window.
The binder's strongest operational result is therefore not raw throughput. It is that the apparatus repeatedly falsified its own premises and survived. A prior capability wall was overturned by live execution. A false board-wiring claim survived approximately 119 tics and was cured only when a real eater exposed two mutually concealing defects. A telemetry marker suppressed a receipt and forced a distinct run-key space. An append-only ledger recorded a true automatic fire while declaring earlier attestations false. Every measured GUNSLINGER campaign wave falsified at least part of the lead premise. The horizon-quiver probe refused the rung promised by its own name. [BND-02, BND-08, BND-15, BND-16, BND-17, BND-18]
That is not incidental quality assurance. It is the operating proof of the governing direction: a system scales safely not when it stops contradicting itself, but when contradiction remains visible, attributable, recoverable, and capable of changing the next trajectory without silently multiplying authority.
This is the capability PHS enables:
Distributed execution, verification, custody, and challenge can scale independently while canonical state remains serial, temporally honest, reproducible, correction-bearing, and deterministically resumable.

1. Introduction: assurance after comprehension scale
1.1 Production has crossed the diff-comprehension boundary
The dominant coordination problem in high-velocity software is no longer merely how to produce change. It is how to preserve a trustworthy distinction between what has been proposed, what exists, what has been distributed, what has been independently reproduced, what has been admitted, what has been deployed, and what has actually affected the world.
That problem becomes acute when artificial intelligence increases the number and speed of candidate implementations. A model can generate a large and internally coherent source surface in minutes. Other models can review, test, summarize, refactor, or extend it. Yet coherence of output is not evidence of correctness, and multiplicity of reviewers is not a governance model. If every agent can update the state that later agents treat as true, horizontal intelligence scaling becomes horizontal authority scaling. The result is divergent state, ambiguous custody, and reconciliation work that can grow faster than the work itself.
Conventional workflows usually answer this pressure in one of two ways. They serialize most activity to preserve consistency, sacrificing throughput; or they parallelize activity through branches, worktrees, repositories, CI jobs, and agents, then attempt to reconstruct one story after the fact. Both approaches tend to conflate where work occurs with when claims about that work become supportable.
PHS separates those dimensions. Its central rule is:
Shard proof by temporal attainability and evidentiary scope, not by workspace, actor, branch, or repository.
A source-bearing subject is first made immutable or strongly identified. Proof lanes then inspect that same subject through different failure surfaces. A direct remote-ref readback answers whether intended distribution surfaces expose the exact subject. An independently acquired clean clone answers whether another environment can acquire and validate it without inheriting the authoring machine's residue. A security review, schema check, lineage inspection, or provider readback may form additional proof lanes. The observations join only after their own predicates pass.
The join produces a later carrier because the source cannot contain evidence of events that occurred after the source existed. The carrier then becomes the next subject because it cannot contain evidence of its own future either. This recursion is not ceremony. It is the architecture forced by causal order.
1.2 The problem is larger than software supply chains
Software supply-chain systems already recognize that identity, provenance, and attestations matter. PHS addresses a more general governance question: which object may lawfully carry which observation, under whose authority, at what horizon, and with what explicit nonclaims?
The same problem appears when a database migration package is staged, applied, read back, and then audited; when an infrastructure plan is signed, executed, and independently inspected; when a model release is registered, reproduced, evaluated, deployed, and accepted; when a policy is published, signed, implemented, and observed; or when an autonomous mandate generates effects beyond its source repository.
In each case, a status such as done is a lossy compression of several events. PHS replaces the status with a proof topology.
1.3 The operational discovery problem
The abstract protocol did not arise from a desire to add more gates to Git. It emerged inside a broader operating system that was already attempting to move complex current states toward bounded targets while preserving agency, center-exclusion, correction, and evidence.
THE BINDER describes that system as one loop wearing many mechanism names. The loop had covenants before it had a PHS specification; Harpoon strikes before a proof-horizon schema; cable receipts before a generalized carrier model; winch modes before the protocol's observer-scaling proposition; append-only corrections before the formal correction-conservation result; and a living distinction between quivers and DAGs before PHS named its three-graph checkpoint history. [31]
This matters for two reasons.
First, it prevents a false origin story in which a complete protocol appeared fully formed from a single repository inconvenience. The protocol was progressively forced by recurring constraints: no self-attestation, no coherence-as-admission, no fixture-as-liveness, no stale capability wall, no invisible residue, no observer artifact occluding the observed, no projection-as-authority, and no silent promotion of one horizon into another.
Second, it shows what kind of evidence should count when assessing the protocol. A clean conceptual diagram is not enough. The stronger evidence is an apparatus that repeatedly catches itself overclaiming, preserves the resulting scars, and becomes more capable because those contradictions change its structure.
1.4 Contributions
This paper makes ten contributions.
- It places PHS in the correct Prompted LLC and Ubiquity lineage and preserves FORKED as the upstream origin of governed horizon geometry and horizon noncollapse.
- It identifies the temporal self-attestation problem: an immutable artifact cannot truthfully carry observations about events that occur only after the artifact exists.
- It defines the earliest horizon of lawful knowability as the partition key for checkpoint evidence.
- It introduces fixed-subject orthogonal proof fan-out while retaining one serial canonical admission path.
- It defines zero-authority proof lanes, governed joins, descendant evidence carriers, and recursive carrier checkpoints.
- It distinguishes synchronized projection, execution, proof, and possession from canonical authority.
- It derives correction conservation, visible residue, anti-vacuity, deterministic re-entry, and observer scaling from the same control law.
- It reconstructs the covenant-strike-cable-board-winch-basin-anchor machinery as the operational discovery apparatus from which PHS was abstracted.
- It uses the horizon-quiver self-falsification as a concrete demonstration that a proof instrument's name, local shape, or implementation status cannot exceed its evidence horizon.
- It preserves honest negatives and source-tense distinctions as positive protocol results rather than relegating them to disclaimers.
The deepest result is not a better release checklist. It is the ability to coordinate broad parallel reasoning and execution around a bounded serial truth path while leaving contradiction visible enough to improve the system.
2. Lineage, inheritance, and attribution
2.1 Prompted LLC and the Ubiquity parent
Prompted LLC describes Ubiquity as the governance substrate for sovereign adaptive systems: AI-mediated systems that can increase capacity without collapsing agency, authorship, judgment, or meaningful contribution. Sovereign continuity is the non-collapse condition - the human architect remains meaningfully causal as the system becomes more capable, more automated, and more dependent on accumulated machine action. [1-4]
PHS inherits that constitutional direction. It does not define Ubiquity and cannot claim the parent substrate as a PHS-only invention. Its concern is narrower: how evidence about changing state can be produced in parallel without letting proof production silently become canonical authority.
The distinction matters because scaling proof workers is useful only if the resulting system still preserves authorship and judgment. A protocol that improves verification throughput by replacing human authority with an opaque automated consensus would solve a different problem. PHS instead allows broad observation while keeping admission singular, inspectable, and successor-capable.
2.2 Fractal Quivers of Quivers and lawful motion
Fractal Quivers of Quivers supplies a mathematical substrate for living responsibility topology. A normal directed graph records vertices and edges. A governed quiver additionally carries edge types, costs, anchors, forbidden paths, standing, authority, receipts, telos, correction paths, and an open-center marker. The object is not merely what transitions are technically reachable; it is which transitions are lawful in a particular context and why. [6]
This parent matters to PHS in three ways.
First, a proof relation is a typed edge, not a floating sentence. It binds a subject, predicate, observer, method, result, horizon, authority ceiling, and convergence target.
Second, a proof graph can recur. The same subject may be inspected by different actors, corrected, re-observed, or revisited after new evidence. That living recurrence is not itself an execution schedule.
Third, receipts are part of the topology. They do not merely decorate completed work. They determine which downstream paths are lawfully open.
2.3 Computing Around the Open Center and splat mechanics
Computing Around the Open Center extends the quiver substrate into bounded local computation. A splat gathers the facets, exclusions, receipts, dependencies, hypotheses, unresolved state, and working centroids needed for one local decision while keeping the center open. The center is not indecision. It is an anti-capture condition: local coordinates may guide action without becoming universal truth. [7]
PHS inherits the same discipline. Every checkpoint is bounded by a declared subject, claim class, environment, and closure predicate. A successful repository checkpoint is not the center of the whole system and does not automatically become deployment, adoption, or outcome truth. The proof carrier can close one branch while stronger horizons remain open.
2.4 FORKED and governed horizon geometry
FORKED is an estate inside Ubiquity. It specializes the parent architecture around observer-indexed reality, suspension, declaration, correction, mission-state integrity, and responsibility-shaped validation. Its horizon geometry stores task, mission, battle, campaign, war, institutional, and other scales as separate splats and quivers with distinct telos, authority, standing, time, success definitions, failure definitions, resource envelopes, acceptable loss, observer geometry, irreversible surfaces, dependencies, and conflicts. [5]
The governing rule is horizon noncollapse:
A declaration at horizon h1 does not acquire authority at horizon h2
without an admitted, typed cross-horizon edge.Task success may coexist with mission failure. A local component may be green while the end-to-end system is unwired. A repository may be synchronized while a provider is unchanged. A model may produce a valid proposal while retaining zero mutation authority. A deployment may be live while outcome remains unmeasured.
PHS is a direct temporal-evidentiary specialization of this rule. A claim established at source horizon does not become a distribution claim. Distribution does not become reproduction. Reproduction does not become deployment. Deployment does not become adoption. Adoption does not become outcome.
2.5 The winching machinery is an operational lineage, not a constitutional parent
The binder documents covenant, Harpoon, cables, boards, DAGs, winches, GUNSLINGER, HIDALGO, dissonance basins, and anchoring. Several of those mechanics also appear in FORKED's suspension lattice. The relation must be stated carefully.
The broader Ubiquity/FORKED papers establish the constitutional and horizon lineage. The binder establishes a lived operating lineage in which those ideas were exercised, corrected, coded, and measured. The binder does not outrank the public parent papers, and the mechanisms it maps are not all PHS-native.
PHS emerges where two lineages meet. Ubiquity, Fractal Quivers of Quivers, Computing Around the Open Center, and FORKED supply the constitutional and horizon law. Covenant, Harpoon, cable, board, winch, basin, and anchor supply the operating and falsification machinery. Their conjunction yields the PHS temporal-evidence protocol; neither lineage is erased by the synthesis.
2.6 Canonical attribution and claim boundary
Breyden E. Taylor designed Proof-Horizon Sharding at Prompted LLC. The paper's native invention is not the word horizon, the existence of DAGs, Git commits, remote refs, clean clones, attestations, receipts, or single-writer systems considered separately.
The native contribution is the composition forced by lawful knowability:
exact immutable subject
-> orthogonal proof fan-out
-> zero-authority observers
-> governed join
-> descendant evidence carrier
-> recursive carrier checkpoint
-> serial canonical admission
-> correction-conserving, finite re-entryThe broader governed-horizon invention remains upstream in Taylor's Ubiquity architecture and FORKED. The operating machinery documented in the binder is part of the invention method and implementation lineage. It does not alter the authorship or organizational attribution of the protocol paper.
3. One loop wearing many mechanism names
3.1 The machinery is one recurrent motion
The binder's most important synthesis is its shortest: the machinery is one loop wearing many mechanism names. [31]
current reality
-> covenant
-> strike
-> cables
-> board / DAG
-> winch
-> receipts and residue
-> admitted successor or held state
-> new current realityEach mechanism exists because the loop must answer a different question.
- The covenant answers what bounded current-to-target pull is being undertaken and under what nonclaims.
- The strike answers what shape the proposed thing takes after adversarial interpretation rather than first-pass fluency.
- The cables answer which bounded responsibilities, contradictions, and proof surfaces must carry tension.
- The board answers which admitted covenants compile into an executable dependency graph.
- The winch answers how ready cables are raised through time.
- The basin answers where unresolved tension and residue remain visible during motion.
- The anchor answers what reference frame and exclusions must survive the motion.
- The receipt carrier answers how what happened becomes durable without claiming more than was observed.
PHS is not another synonym in this list. It is the law that governs the temporal evidence produced around the loop.

3.2 Covenant: bind the pull before execution
A covenant binds a current state to a target under an explicit scope, authority ceiling, admission condition, and set of nonclaims. It prevents an attractive target from silently becoming permission to move toward it by any available means.
The tic-494 hoist covenant is the binder's first large instance: ten cables, seven waves, and three parallel invariants assembled by reusing an existing compiler. The founding telos remained a non-node. center_exclusion: GO was a compiler check, not prose ornament. [BND-01]
This is structurally adjacent to PHS H0. Both begin by refusing to confuse a candidate with an admitted subject. The covenant declares the pull. H0 determines whether that pull is rejected, held, corrected, or eligible to become a source-bearing subject.
The relation is not identity. A covenant may govern a broader current-to-target campaign containing many PHS epochs. A PHS epoch may also be instantiated without adopting the whole Ubiquity covenant vocabulary. The invariant is the same: intention does not confer admission.
3.3 Strike: produce shape by falsification
Harpoonv2 is the shape-producing strike lane. Its six-ray council does not begin from the assumption that a proposal's own account is the thing. It examines affirmative structure, forbidden collapse, neighboring interpretations, concrete coordinates, failure forms, and telos. The strike is therefore a disciplined way to produce a bounded object that can be admitted, rejected, or held.
The office's founding scar is load-bearing. Its original verb, master DAG-of-DAGs, was falsified by a blind arena and rechartered as metabolize, not master. The office survived the falsification of its own name at inception. [BND-13]
That event matters to PHS because it demonstrates the difference between a label and a lawful claim. A name is a proposal about identity. It gains standing only when the system can preserve what the thing does, what it excludes, and what evidence supports the name.
The horizon-quiver event later repeated the same pattern at a sharper technical boundary: the name detached_reproduced was not allowed to outrun the absence of remote contact. [BND-16]
3.4 Cables: route bounded tension and responsibility
A cable is a bounded responsibility carrier. It may represent implementation work, a proof predicate, an invariant, a correction, a dependency, or a review obligation. The cable metaphor matters because the system is not trying to eliminate tension before movement. It is trying to route tension in a way that preserves the center and makes each pull accountable.
PHS proof shards are cable-like but narrower. A proof shard is an independently executable predicate over one exact subject. It carries observation authority and produces a receipt. It does not gain admission authority.
The binder's cable history is substantial: 161 cable receipts from tics 498 through 769, plus 68 drain receipts, enumerated row by row in the referenced extract. [BND-14] Those counts do not by themselves establish protocol conformance. They establish that the operating lineage was already receipt-bearing and that the proof topology was not invented as an after-the-fact documentation convention.
3.5 Board and DAG: compile only admitted work
The board is the compilation surface between covenant and execution. It determines which bounded objects are admitted, which are executable, which dependencies must precede others, which identities remain residue, and which joins are required.
At tic 643, seven office citizens fired simultaneously, one per cable, with disjoint write surfaces. The admitted set intersected the executable set at exactly seven of seven. Seven additional identities that appeared executable but lacked admitted covenants were deliberately excluded. This is coherence-is-not-admission enforced as a set operation. [BND-05]
At tic 650, the S1-to-S7 covenant chain was planned, simulated with zero live side effects, and fired inside one tic. Seven work cables were dispatched, three invariants asserted, and six null-covenant identities were named as residue rather than silently dropped. [BND-06]
The board's largest negative lesson came from the vacuous-green scar. For approximately 119 tics, a doctrine claim that the engine read the board survived behind two mutually concealing defects. The first real eater found the gap. The repair changed missing state from an implicit executable default into a visible non-executable condition and closed a fail-open exec_ready defect. [BND-08]
PHS inherits the anti-vacuity consequence: a proof surface that exists but has no real consumer, a validator that is not wired to a call site, or a status that defaults green on missing state cannot close a horizon.
3.6 Winch: choose tempo without changing truth
The winch raises admitted, executable cables. Its two typed detents are GUNSLINGER and HIDALGO. [BND-09]
GUNSLINGER raises all currently admitted and executable cables under one shared cradle. It is the maximum lawful parallelism of the bounded set, not permission for unbounded mutation.
HIDALGO stages the raise. It is a throttle selected by residue shape, dependency pressure, reversibility, or uncertainty. It is not the default and not a lesser proof standard.
The typed dial matters because tempo and evidence are orthogonal. A GUNSLINGER raise may execute many cables at once, but every receipt remains bound to its exact subject and claim class. A HIDALGO raise may be slower, but it does not automatically produce stronger evidence. PHS remains the same under either tempo.
The binder identifies only one live HIDALGO classification in the whole ledger: hidalgo:A=1:B=6:C=0:D=0, judged clean by residue shape at tic 575. [BND-10] That rarity is evidence about use, not evidence that the detent is fictitious.
The term sniper is not a third winch mode. The binder's search found three distinct referents - a precision/range band of the gunslinger figure, an unrelated covenant nickname, and an incidental constant comment - with no publication hits. It belongs to register and precision vocabulary, not the mechanism family. [31]
3.7 Dissonance basins: preserve tension and residue
The binder distinguishes two mechanics that share the word basin and must not be collapsed.
DissonanceBasin is a tension reservoir. It holds dissonance during the cradle and permits some of it to be drained into useful motion while retaining residual tension as compounding information. A drain does not reduce the system to false harmony.
held_basin is a graph-state mechanism. It keeps a gated, blocked, or excluded identity visible in the lattice instead of dropping it from the account.
PHS does not require these exact classes, but it requires their truth function: unresolved state must remain represented. A failed or held proof shard is not absence. A residue identity is not silently removed from the denominator. A join is not lawful merely because only passing lanes were counted.
The braid-covenant BR4 packet is the binder's deepest recorded live basin exercise: named tensions trust_below_tau, mint_halted, and harmony:unresolved:1, with measured residual 0.45 and a 48-of-48 lattice test. [BND-19]
The honest boundary is equally important. basin_drained has not fired as a live event in the 213-row ledger. One apparent drain is orchestrator prose inside a cradle_stable row, and the live-fire code path keeps the guard false by construction. The basin is therefore a law with one deep live exercise and an ambient economic presence; its drain path is designed and smoke-tested, not live-proven. [31]
3.8 Anchor and center exclusion
Anchoring is the reference frame that lets the system move without replacing its telos with whatever the current optimization can most easily maximize.
The center is not an executable node. It is not a hidden ruler or a single scalar objective. It is the excluded reference sort around which lawful motion is measured. In the originating implementation, center exclusion was enforced by a compiler check, a winch membrane assertion, and a TypeScript substrate-physics clause. The binder traces the doctrine-to-code line from the tic-414 statement that the strike drains the basin while retaining tension to residual_fraction = 0.15 in the winch implementation. [BND-20]
PHS uses a narrower version of the same discipline. The protocol's center is the declared canonical and evidentiary boundary: no proof worker can crown itself the canonical writer; no local observation becomes universal truth; no closed branch silently closes a stronger domain.
The epoch05 pinky is the binder's anchor-economics result. Meaning was recovered above baseline in 41 steps, 48 seconds, and one branch because the anchor, forbidden region, gate, and receipt structure already existed. The cost lived in the anchor, not the repair. [BND-21]
3.9 Receipt: carry the motion without laundering it
Receipts make the loop durable. They bind an observation to a subject, method, result, limit, and next edge. The binder's append-only wave ledger contains 213 rows across 22 tics. Its tic-701 correction recorded the first true automatic pawl fire while declaring earlier attestations false in the same append-only medium. [BND-17]
That is the operational ancestor of PHS correction conservation. Later evidence may correct a prior claim without editing the prior subject into a history in which the error never occurred.
The loop therefore ends neither in erasure nor in permanent closure. It ends in one of three bounded states:
- a lawful successor is admitted;
- the pull is held with residue and next conditions visible;
- the declared scope reaches a quiet point while stronger horizons remain open.
4. The horizon-quiver construction event
4.1 Why this event matters
The binder's most direct PHS evidence is BND-16: the horizon quiver built across tics 768 through 770. It is not the origin of the broader horizon concept; FORKED already supplied horizon geometry and noncollapse. It is the clearest recorded construction in which that inherited concept was specialized into an executable evidence ladder and then forced to obey its own ceiling.
The sequence was:
sibling-estate thesis
-> admitted as an object under FIELD / no-cite posture
-> six-ray strike
-> 16-row crosswalk
-> covenant re-expression H0-H6
-> H1 build: 43 arms, 13/13 nonclaims, deliberately unwired
-> H2 || H3 || H4 consumers in one tic
-> self-falsifying detached-reproduction probe
-> fail-closed evidence rank
4.2 Admission before inheritance
The source thesis entered as an object, not as law. Its posture was FIELD/no-cite: inspect the thesis, preserve its identity, map its claims, and do not let its attractive coherence or external vocabulary acquire constitutional standing by default.
That move is a concrete instance of Look-First and successor topology. A source may be useful as a takeoff surface without becoming an ancestor, sovereign, or authority. Its exact contribution is carried at the artifact edge. Standing does not transfer merely because the system learned from it. [10,11]
4.3 The six-ray strike and crosswalk
The six-ray strike produced a bounded shape rather than a summary. The 16-row crosswalk mapped proposed claims to proof horizons, evidence surfaces, consumers, ceilings, and nonclaims. The resulting H0-to-H6 covenant was therefore not simply a renamed copy of the sibling thesis. It was a governed re-expression.
H1 produced 43 arms and passed all 13 nonclaims, yet remained deliberately unwired. This is a positive result. It proves that the system could materialize the shape without pretending that component presence meant live consumption.
4.4 The name that failed its own proof
The sharpest result came from the probe named detached_reproduced. Its name suggested that detached reproduction had occurred. The proof lane made no remote contact. Therefore it could not establish the rung promised by its identifier.
The implementation did not soften the discrepancy by saying the code was basically equivalent, that a local detached state was close enough, or that the name expressed future intent. Its receipts were typed at source_admitted, rank zero. The evidence ceiling held fail-closed. [BND-16]
This event compresses the PHS thesis into one lived test:
identifier coherence
+ local implementation
+ green fixtures
+ intended semantics
!= detached reproduction proofThe name was not edited into truth. The proof class remained bounded by what actually happened.
4.5 The construction as a protocol experiment
The horizon-quiver build is best read as a protocol experiment with four findings.
First, proof horizons are operationally separable. H1 can be present and green while H2-to-H4 remain unwired or bounded.
Second, a proof instrument is subject to the same law it enforces. The probe cannot use its own name as evidence.
Third, nonclaims are executable structure. Thirteen of thirteen nonclaims passed before the higher consumers existed.
Fourth, coherence is not admission. The system was capable of building the appealing thesis while refusing the strongest implication of its terminology.
That is why this event belongs in the foundational protocol paper rather than only in a Forge implementation appendix. It is the cleanest demonstration that the protocol's central refusal can govern its own embodiment.
5. The temporal self-attestation problem
5.1 A checkpoint is usually several events disguised as one
A typical workflow may say that a change is complete after a commit is made, tests pass, and a push succeeds. That sentence contains several distinct events:
- mutable source exists in a working environment;
- the selected source is represented by an immutable or strongly identified object;
- an exact subject identity exists;
- a target accepts an update operation;
- named target refs expose that exact identity;
- another environment can acquire the identity;
- the acquired state passes declared validations;
- observations about those facts are durably recorded;
- the record carrying those observations is itself distributed or reproduced;
- an authorized process admits the checkpoint as closed;
- a runtime, provider, database, organization, or stakeholder experiences the intended effect;
- an outcome is observed under a declared method.
No single event proves all the others.
A local test does not prove remote availability. A successful push does not prove direct target readback. A local tracking ref may be stale. A detached clone does not prove deployment. A deployment readback does not prove adoption. Outcome cannot be inferred from repository state. A fixture does not prove a live caller exists. A file named for a capability does not prove the capability has run.
5.2 Immutable artifacts cannot know their own future
Let an immutable artifact x be created at time t(x). Let e be an event concerning x, such as remote propagation, independent acquisition, environmental reproduction, deployment, or acceptance.
If:
t(e) > t(x)then x cannot truthfully contain an observation of e as part of its original immutable content.
For Git commits, the issue is concrete. A commit object contains a tree, parent references, author and committer fields, timestamps, and a message. Its identity is derived from the serialized object. The final identity is available only after construction. Remote propagation and independent reproduction occur later still. A source-bearing commit cannot therefore be the truthful carrier of direct observations about its own later remote state or clone reproduction. [16-19]
A later descendant can carry those observations. But the descendant has the same limitation regarding its own future. If it is later pushed, read back, cloned, reproduced, deployed, or accepted, those observations require another later carrier or an external append-only evidence surface whose causal position is explicit.
This is the temporal self-attestation problem:
No immutable artifact may be treated as evidence of an event that had not occurred when the artifact was created.
PHS does not attempt to hide or route around the boundary. It turns the boundary into the architecture.
5.3 False closure is a category and horizon error
| Collapsed statement | What it may establish | What it does not establish |
|---|---|---|
Committed | Source exists in a local immutable object | Remote availability, independent acquisition, deployment |
Pushed | A client attempted or reported an update | Direct remote parity, clean reproduction |
CI green | Declared checks passed in one configured environment | Complete predicate coverage, independent acquisition, outcome |
Fixture green | A test fixture or isolated component passed | Live call-site wiring or live-fire behavior |
Wired | A declared connection may exist | A consumer exercised it at the claimed time |
Mirrored | Another surface may contain equivalent objects or refs | Equal authority, current parity, lawful custody |
Released | A tag, package, or publication event occurred | Deployment, adoption, business outcome |
Receipt written | A record exists | Accuracy, authenticity, carrier propagation, closure |
Named capability | An identifier or document asserts a role | Current liveness, current dependencies, current authority |
Basin armed | A mechanism and test path exist | The drain or refusal path has fired live |
The protocol therefore treats source, distribution, reproduction, evidence carriage, carrier proof, deployment, adoption, and outcome as separate horizons. A stronger claim requires a stronger horizon. It cannot be obtained by renaming a weaker receipt.
5.4 Provenance is necessary and insufficient
Provenance can establish where an artifact came from, who signed it, what inputs were recorded, or which process produced it. These are indispensable claims. They are not complete closure.
A signed receipt may be false. A correct receipt may be signed by an actor without admission standing. A complete source-provenance record may say nothing about later target availability. A clean reproduction may say nothing about deployment. A later result may be authentic but attached to the wrong source subject.
PHS therefore separates four questions:
authenticity - who or what signed the bytes?
accuracy - did the stated observation occur?
independence - what mutable state or trust roots were shared?
authority - what transition or claim was the actor permitted to make?Existing attestation and transparency standards can carry these facts. PHS specifies how their evidence must be partitioned, ordered, joined, and recursively carried. [20-27]
6. Design thesis
6.1 Proof topology follows epistemic dependency
Branches, worktrees, machines, and repositories answer spatial or operational questions: where can work be performed, isolated, stored, or reproduced?
PHS answers an epistemic question:
When can a fact become knowable, through which independent surface, and what later object may lawfully carry it?
These are different partition schemes. Two agents can work in separate repositories and still produce no independent evidence if both inherit the same hidden assumption. Two proof shards can run in the same repository but different independently acquired environments and establish distinct failure surfaces. One branch can contain many claim horizons. One proof horizon can involve many machines.
The partition axis is lawful knowability.
6.2 Horizon noncollapse becomes evidence noncollapse
FORKED's horizon rule can be specialized as follows:
Evidence(h1) does not imply Evidence(h2)
unless a typed, admitted relation establishes the move.This produces a strict anti-laundering sequence:
candidate != source
source != distribution
distribution != reproduction
reproduction != carrier proof
repository closure != deployment
deployment != adoption
adoption != outcomeThe sequence is not a universal linear maturity ladder. Different domains can branch, run concurrently, or remain inapplicable. The invariant is that no lane gains a stronger claim merely because another lane succeeded.
6.3 Parallel assurance without parallel authority
PHS distinguishes three powers:
- Proposal: produce candidate state.
- Observation: inspect an exact subject and emit a bounded receipt.
- Admission: advance accepted canonical state.
Many actors may propose. Many may observe. Only the designated canonical lane may admit.
A proof worker does not need general write authority. It needs:
exact subject
+ permitted evidence surface
+ declared proof horizon
+ predicate
+ receipt schema
+ authority ceiling
+ stop condition
+ convergence destinationThis creates a zero-authority proof lane: the worker may inspect and report but cannot silently convert its observation into accepted state. The number of observers can grow without increasing the number of canonical writers.
6.4 Projection is not authority
A repository, ref, cache, mirror, report, binder, natural-language rendering, or other projection may carry an exact or useful representation of canonical state. Possession of state does not confer jurisdiction to originate accepted transitions.
PHS treats synchronized refs as canonical projections. They may be acquisition surfaces and proof targets. They may be maintained in exact parity. They do not independently decide what becomes canon.
The same rule applies to THE BINDER. It is intentionally a map of receipts. It does not become primary authority merely because it is comprehensive or easier to read. [31]
6.5 Evidence classes remain distinct at convergence
Proof shards converge without being flattened. A direct remote-ref receipt and a clean-clone reproduction receipt may jointly support repository closure, but they remain different evidence types. Their subjects, methods, environments, timestamps, limitations, and failure surfaces stay visible.
This composability matters because evidence is often weakened during summary. PHS makes summary downstream of receipts rather than a substitute for them.
6.6 Falsification is a first-class output
A proof lane is not valuable only when it returns pass. A failed or held result can be the most informative output if it is exact, bounded, and capable of changing the next motion.
The binder's lead-premise falsification streak makes this measurable. Across every recorded campaign wave, citizens found and corrected at least part of the lead premise. The system did not interpret that as disobedience or process failure. It treated out-falsifying the lead as a property of the form. [BND-15]
PHS therefore makes failure receipts durable and correction paths explicit. A protocol that optimizes for an uninterrupted green narrative is structurally incentivized to erase the very evidence needed for safe scaling.
7. Formal protocol model
7.1 Core entities
A PHS epoch contains the following entities.
| Symbol | Entity | Meaning |
|---|---|---|
S | Subject | Immutable or strongly identified object under proof |
id(S) | Subject identity | Content address, digest, revision ID, or equivalent stable identifier |
H | Proof horizon | Strongest bounded claim currently supported |
P_i | Proof shard | Independently executable predicate over S |
R_i | Receipt | Durable record of subject, method, observation, result, and limitation |
K | Carrier | Descendant object that incorporates valid receipts about a predecessor |
A_i | Authority ceiling | Strongest action or claim permitted to a lane or actor |
J | Join | Controlled convergence of required proof shards |
Gamma | Closure predicate | Complete conditions required to close the declared epoch |
Z | Excluded center | Invariant or reference sort that may constrain motion but is not an ordinary work node |
D | Dissonance state | Unresolved tension, held residue, conflict, or incomplete edge preserved through the epoch |
A receipt is always about an exact subject. It does not float freely as a statement that the project passed. If the source changes, the subject identity changes and proof must be evaluated against the new subject.
7.2 Winching extension
The originating operating system can be represented as:
W = (C, T, V, Z, {L_i}, B, M, D, Gamma, A)where:
Cis current reality;
Tis the bounded target;
Vis the covenant binding the pull;
Zis the excluded center or anchor set;
{L_i}is the set of cables or bounded responsibilities;
Bis the board that compiles admitted dependencies;
Mis the winch tempo;
Dis the dissonance and residue state;
Gammais the closure predicate;
Ais canonical admission authority.
PHS is not W. PHS is the admissible evidence topology over W:
PHS(W) = (subjects, horizons, proof shards, receipts,
carriers, authority ceilings, joins, re-entry)This distinction preserves portability. An implementation can conform to PHS without adopting the names GUNSLINGER, HIDALGO, Harpoon, or DissonanceBasin. Conversely, using those names does not establish PHS conformance.
7.3 Temporal admissibility
A receipt R_i about subject S is temporally admissible only when:
t_create(S) <= t_observe(R_i) < t_create(K)The subject must exist before observation. The observation must exist before a carrier claims to preserve it. If R_i concerns the propagation or reproduction of K, it cannot be contained by K; another carrier or durable external log is required.
The protocol may use clocks, signed timestamps, transparency logs, repository ancestry, append-only sequence numbers, or combinations of these. The abstract requirement is causal order, not dependence on one clock implementation.
7.4 Predicate admissibility
A receipt is predicate-admissible only if it states:
- the exact claim being tested;
- the method and command or observation manifest;
- the expected result;
- the actual result;
- the environment and independence boundary;
- the limitations and nonclaims;
- the treatment of missing or indeterminate state.
A predicate that defaults to pass when its input or consumer is absent is not admissible for closure. This is the formal anti-vacuity consequence of BND-08.
7.5 Authority admissibility
A transition is authority-admissible only when the actor's authority ceiling includes the requested action. A proof lane with observe + receipt authority may execute a predicate and produce a receipt. It may not update the canonical ref. A projection maintainer may synchronize an authorized subject but may not select a different source subject.
Authority is explicit metadata and executable policy, not an inference from access possession.
7.6 Cross-horizon admissibility
Let h_s be the source horizon and h_t the target horizon. A claim may move from h_s to h_t only if there exists a typed relation e such that:
CrossHorizon(e, h_s, h_t) =
subject_valid(e)
and predicate_valid(e)
and standing_valid(e)
and authority_valid(e)
and externalities_accounted(e)
and receipts_valid(e)No local status, identifier, projection, or summary substitutes for this edge.
7.7 Center admissibility and anchor preservation
In the originating Ubiquity implementation, the excluded center constrains the epoch without becoming a work node:
V_work intersect Z = emptyA transition is anchor-admissible only if it preserves the declared invariants and does not convert a working centroid into canonical truth by convenience.
PHS portability does not require every implementation to use the same open-center ontology. It does require an equivalent boundary preventing observers, projections, local successes, and optimization targets from silently acquiring canonical standing.
7.8 Closure
An epoch closes when every required shard has a valid receipt, every receipt is bound to the declared subject or a lawful successor, every actor remained within its ceiling, the carrier preserves the required observations, the relevant residue is represented, and the terminal state agrees with the convergence target.
Informally:
Close(epoch) =
all required predicates passed or lawfully disposed
+ all receipts match exact subjects
+ all temporal relations are lawful
+ no authority ceiling was exceeded
+ no required identity vanished from the denominator
+ the carrier is admitted
+ all required carrier proofs passed
+ terminal pointers reconcile
+ the closure scope and nonclaims are explicitClosure is scoped. Repository closure does not imply deployment closure. Deployment closure does not imply adoption closure. Adoption closure does not imply outcome closure.
7.9 Governed checkpoint history
The resulting history overlays three directed structures:
immutable succession DAG
+ proof DAG
+ authority DAG
= governed checkpoint historyThe succession graph answers what immutable states succeeded one another. The proof graph answers what was observed about which subject and by what path. The authority graph answers who or what was permitted to observe, carry, synchronize, or admit each transition.

7.10 Derived results
Lemma 1: No self-attestation
If event e occurs after immutable artifact x is created, then x cannot be original evidence of e.
t(e) > t(x) => x cannot entail Observation(e)Corollary 1: Carrier recursion
If later evidence about x must become durable, a successor carrier K_1 is required. If later evidence about K_1 must also become durable, a successor K_2 or external log is required.
K_(n+1) = Carrier(K_n, Receipts(K_n))Proposition 1: Observer scaling without writer scaling
Let n be the number of independent proof workers and let canonical mutation remain one ordered path. Subject to dependency, compute, network, human-attention, and join constraints, proof throughput may increase with n while canonical writer count remains one.
Proposition 2: Correction conservation
If a predicate fails for subject S, a corrected subject S' does not migrate or erase the failed receipt. The failure remains true as a record of S at that time, while S' begins a new proof path.
Proposition 3: Projection nonauthority
If projection Q contains or exposes canonical subject S, possession of S by Q does not imply authority to select S' as the next canonical subject.
Proposition 4: Finite re-entry
If every completed and pending proof edge is durably represented, a successor can resume at the minimal unproven predecessor of closure without reconstructing private process memory.
Proposition 5: Residue visibility
If an identity is excluded, blocked, null-covenant, indeterminate, or held, removing it from the denominator can create a false green. Lawful closure therefore requires explicit disposition or visible residue for every required identity.
Proposition 6: Anti-vacuity
A passing component, fixture, validator, or declaration cannot close a horizon when the required consumer or call-site relation is absent, unmeasured, or defaulted. Presence is not enforcement; fixture-green is not live-fired.
Proposition 7: Observer-artifact non-occlusion
If an observation mechanism can suppress or overwrite the evidence surface it is intended to observe, its result is not independently reliable. The observer's identity and output key space must be separable from the observed event. BND-18 is the originating scar.
8. Reference epoch
8.1 Horizon sequence
A minimal PHS epoch expands a vague checkpoint into six truth-bearing horizons:
H0 candidate / covenant disposition
H1 immutable source identity
H2a distribution proof
H2b independent reproduction proof
H3 durable receipt-carrier materialization
H4 carrier propagation / reproduction proof
H5 terminal governed reconciliationThe two H2 shards may execute concurrently because they inspect one fixed subject through orthogonal failure surfaces. H3 cannot precede them because it carries their observations. H4 cannot be compressed into H3 because the carrier's own final identity and later target state do not exist until after H3 is created.

8.2 H0 - Candidate or covenant disposition
The epoch begins with a bounded candidate. The system records its scope, origin, intended effect ceiling, admission requirements, anchors, and nonclaims. H0 answers whether the candidate is rejected, held, corrected, or eligible to become a source subject. It does not yet provide immutable source identity.
A candidate may come from a human, model, branch, patch, generated package, external repository, sibling estate, prior carrier, or covenant. PHS is neutral to authorship method. Candidate generation is not admission.
8.3 H1 - Source-bearing subject
The accepted source tranche is materialized into an immutable or strongly identified subject. In Git, this is commonly a source-bearing commit. Its object ID and tree identity become the fixed binding for later proof.
H1 establishes that selected source exists. It does not establish that a remote exposes it, that another environment can reproduce it, or that a live consumer invokes it.
The horizon-quiver build's 43 H1 arms illustrate the point: H1 can be complete and still deliberately unwired. [BND-16]
8.4 H2a - Distribution proof
A distribution proof reads the intended target surface directly and verifies that each required ref or object endpoint exposes id(S). In the Git profile, direct ls-remote readback is stronger than trusting a local remote-tracking ref, because the latter may represent only the state observed during the last network communication. [17]
The receipt should identify every expected remote and ref, the observed object ID, the observation time, the comparison predicate, and any unreachable or ambiguous target.
H2a proves distribution within the declared target set. It does not prove independent execution or reproduction.
8.5 H2b - Independent reproduction proof
A reproduction proof acquires the exact subject through an intended distribution surface into an environment that does not inherit undeclared mutable state from the authoring checkout.
The lane can detect:
- untracked or ignored files;
- stale generated artifacts;
- local-only configuration;
- undeclared dependencies;
- machine-specific caches;
- hooks or scripts unavailable to another actor;
- hidden symlinks;
- objects present locally but absent from the intended remote;
- tests that pass only because of prior local execution.
The receipt must state the independence boundary it actually proves. A new directory can detect some residue while sharing the host. A container may isolate dependencies while sharing a kernel. A separate account may share credentials. Independence is graded and declared, not assumed.
The horizon-quiver probe demonstrates the negative case: without remote contact, detached reproduction was not established regardless of the probe's name. [BND-16]
8.6 H3 - Receipt/state carrier
After all required H2 shards pass or receive lawful dispositions, their observations converge into a descendant carrier. The carrier preserves:
- exact predecessor subject identity;
- proof-horizon labels;
- predicates and results;
- observer and environment descriptors;
- observation times or causal positions;
- authority ceilings and standing;
- limitations and explicit nonclaims;
- held residue and conflicting evidence;
- join status;
- next required horizon.
The carrier may be a commit, signed attestation bundle, append-only log entry, governed database record, or another durable object. H3 makes evidence durable. It does not prove the carrier's own later propagation.
8.7 H4 - Carrier checkpoint
The carrier becomes the next subject. The system performs whatever distribution, retrieval, reproduction, signature, transparency, or custody checks policy requires for that carrier.
This is the recursive move that prevents self-certification.
Carrier recursion may continue across assurance domains. One carrier may preserve source and repository evidence; another may preserve deployment evidence; another may preserve stakeholder acceptance. Each claims only within its temporal and semantic horizon.
8.8 H5 - Terminal reconciliation
Terminal reconciliation confirms that source, proof, carrier, projections, execution pointers, residue, and checkpoint state agree with the declared closure predicate.
Any ordinary work graph, task tracker, release pointer, or operational state may advance only to the horizon actually earned.
The system reaches a quiet point when no unresolved residue remains inside the claimed scope. A quiet point does not claim that the system is permanently complete. It claims that the declared epoch has no hidden pending edge.
9. Protocol invariants
PHS is defined less by one command sequence than by invariants that every implementation must preserve.
| ID | Invariant | Required property |
|---|---|---|
| I1 | Exact subject binding | Every receipt names one immutable or strongly identified subject. |
| I2 | Serial canonical mutation | Accepted state advances through one ordered canonical lane. |
| I3 | Proof-authority separation | Proof workers cannot silently admit their own observations into canon. |
| I4 | Temporal admissibility | A carrier contains only observations available before its creation. |
| I5 | No self-attestation | An artifact cannot certify its own future propagation, retrieval, execution, adoption, or outcome. |
| I6 | Evidence-class preservation | Distribution, reproduction, deployment, adoption, and outcome receipts are not interchangeable. |
| I7 | Independent acquisition | Reproduction proof does not inherit undeclared mutable state from the authoring environment. |
| I8 | Projection nonauthority | Synchronized copies do not become coequal canonical writers by possessing state. |
| I9 | Monotonic evidence | Later carriers add bounded observations without rewriting what earlier subjects could know. |
| I10 | Correction survival | Failed, corrected, or superseded attempts remain intelligible in lineage. |
| I11 | Deterministic resumption | The next actor can identify the first required unproven horizon without private process memory. |
| I12 | Scoped closure | A closed horizon may not be promoted into a stronger domain without new evidence. |
| I13 | Anchor preservation | The declared center, telos, and non-negotiable invariants are not ordinary nodes available for local optimization to rewrite. |
| I14 | Residue visibility | Held, excluded, null-covenant, missing, or indeterminate identities remain visible until lawfully disposed. |
| I15 | Anti-vacuity | Missing inputs, consumers, or call sites cannot default a required proof surface to green. |
| I16 | Currentness at the act | A capability verdict is re-evaluated at the execution boundary when current state may have changed. |
| I17 | Fixture/live separation | Fixture-green, source-present, wired, and live-fired are distinct states. |
| I18 | Observer-artifact non-occlusion | The observation mechanism may not suppress, overwrite, or masquerade as the event it measures. |
| I19 | Honest-negative carriage | A mechanism that has not fired live, a path not exercised, or a domain not measured is recorded explicitly rather than inferred from implementation presence. |
| I20 | Typed cross-horizon movement | Evidence or authority moves between horizons only through an admitted relation with standing, predicate, source, target, and externalities declared. |
9.1 Monotonicity is subject-relative
PHS evidence is monotonic with respect to an exact subject. A later receipt may add observations about S without changing id(S) or erasing earlier receipts. If source changes produce S', receipts about S do not migrate. The new subject begins a new proof path.
A failed receipt therefore remains true as a record that a particular predicate failed at a particular time. Correction does not require narrative erasure.
9.2 Currentness is an execution-boundary question
The binder's tic-527-to-535 capability reversal is a direct operational source of I16. A prior assessment concluded that the epoch16 LoRA path was not reachable. Live execution at tic 535 overturned four premises: the model served on the M2 Max, all 280 LoRA modules were present, PEFT-to-MLX conversion completed in 1.7 seconds, real inference completed in 88.9 seconds, the gate passed, and mutation authority remained false. [BND-02]
The lesson is not that prior assessments are useless. It is that capability walls have shelf lives. A historical verdict can guide a present test; it cannot replace a present probe when the act is consequential and the substrate may have changed.
The same rule cuts the other way. The affordability survey found prior live receipts for an MLX model while the current base weights were absent. Historical liveness did not become current liveness. [36]
9.3 Fixture-green is not live-fired
The protocol distinguishes:
schema present
fixture passes
component callable
consumer wired
live invocation observed
external effect read backEach state can be useful. None may be renamed into the next.
The a0 estate memo makes the same distinction in another domain: a validator existed and passed fixtures, but no call-site gate invoked it; a doctrine packet was delivered but not yet consumed; the inbound lifecycle leg was fixture-green while the outbound leg was live-proven. [37]
The horizon-quiver H1 arms were deliberately unwired. The dissonance-basin drain was designed and tested but not live-fired. The economy was a live moving simulation, not live money. These are not embarrassments. They are the system reporting the exact horizon reached.
9.4 Absence and disagreement are evidence
Two readers of one substrate may disagree. A path probe may say a binary is absent while exact file probes find three working binaries. A catalog may describe a model as present while the directory is gone. A registry may point at one model identity while receipts name a sibling. [36]
PHS does not resolve disagreement by choosing the most convenient sentence. It preserves the observations, their methods, their times, and the predicate needed to adjudicate them.
The result may be held. A held state is not indecision without structure. It is a typed assertion that the system knows enough to refuse closure and knows what evidence would reopen the path.
9.5 Look-First is custody, not permission
Before an actor overwrites a plan, state carrier, representation, or canonical pointer, it reattaches to the current state. Prompted LLC's Look-First doctrine treats that read as the act by which the actor takes custody of the construction-destruction couple inherent in an overwrite. [10]
PHS applies Look-First at source selection, correction, carrier creation, and terminal reconciliation. The read is not automatic permission to mutate. It is a condition of owning what the mutation ends and what it creates.
10. Receipt, carrier, basin, and ledger model
10.1 Minimal receipt
A minimal PHS receipt should be machine-readable and human-auditable.
{
"protocol": "proof-horizon-sharding/v1.2",
"checkpoint_id": "phs-2026-09-04-001",
"subject": {
"type": "git-commit",
"id": "<exact-subject-id>",
"tree_id": "<optional-tree-id>",
"predecessor": "<optional-predecessor-id>"
},
"horizon": "H2b.independent-reproduction",
"parent_horizon": "repository-source",
"predicate": {
"name": "detached-clone-validation",
"command_manifest": "sha256:<digest>",
"expected": "all required checks pass"
},
"observer": {
"actor_id": "<verifier-id>",
"environment_id": "<environment-id>",
"independence_level": "clean-clone-separate-directory",
"acquisition": "clone-from-declared-remote"
},
"observed_at": "<timestamp-or-causal-position>",
"result": "pass | fail | held | indeterminate | not_applicable",
"evidence": [
{"type": "log", "digest": "sha256:<digest>"},
{"type": "test-report", "digest": "sha256:<digest>"}
],
"authority_ceiling": "observe-and-receipt",
"standing": "<why-this-observer-counts>",
"residue": ["<held-or-excluded-identity>"],
"nonclaims": [
"does not prove deployment",
"does not prove adoption",
"does not prove business outcome"
],
"convergence_target": "H3.receipt-carrier",
"next_horizon": "H3.receipt-carrier"
}The schema may be wrapped in in-toto statements, DSSE envelopes, SLSA predicates, SCITT statements and receipts, OCI attestations, signatures, or transparency-log entries. Those systems can carry PHS evidence. PHS additionally specifies temporal partitioning, recursive carrier proof, serial admission, cross-horizon noncollapse, visible residue, and convergence semantics. [20,21,25]
10.2 Required semantic fields
Regardless of encoding, a PHS receipt requires:
- exact subject identity and type;
- predecessor or correction relation;
- proof horizon and parent horizon;
- predicate and expected result;
- method and command or observation manifest;
- observer identity and standing;
- environment and independence level;
- observation time or causal position;
- result;
- evidence bindings;
- authority ceiling;
- residue and exclusions;
- nonclaims;
- convergence target;
- next required horizon;
- correction or supersession pointers when applicable.
10.3 Receipt authenticity and receipt truth
Cryptographic signatures can establish that a named key signed a receipt and that the bytes have not changed. They do not by themselves establish that the receipt's semantic claim is true.
A high-assurance implementation may combine signed receipts, protected identities, trusted execution, reproducible commands, multiple observers, and transparency logs. Each control answers a different question. PHS refuses to collapse them into one trust scalar.
10.4 Join receipt
A join receipt does not merely state that several workers finished. It establishes that:
- the required shard set was fixed or versioned;
- every receipt binds to the declared subject or lawful successor;
- evidence classes remain distinct;
- missing and held lanes are represented;
- no observer exceeded its authority ceiling;
- the join itself had admission standing;
- the resulting carrier contains only pre-creation observations;
- the next horizon remains explicit.
The tic-643 exact set operation - admitted intersect executable equals seven of seven, with seven other executable-looking identities excluded for lack of covenants - is a concrete example of why the denominator must be explicit. [BND-05]
10.5 Carrier chain
A carrier chain can be represented as:
S0 source subject
|-- R0a distribution receipt
|-- R0b reproduction receipt
|
K1 carrier for S0 receipts
|-- R1a carrier distribution receipt
|-- R1b carrier reproduction receipt
|
K2 carrier for K1 receiptsThe chain need not continue forever. Policy chooses the terminal horizon required for the declared scope. But the system may not compress a required later observation into an earlier immutable artifact.
10.6 Dissonance state and held basins
PHS receipts may carry unresolved tension without requiring a specific DissonanceBasin implementation. The semantic requirement is that conflict, uncertainty, blocked identities, and failed predicates remain inspectable.
A held basin can include:
{
"state": "held",
"subject": "<id>",
"reason_codes": ["remote_unreachable", "predicate_ambiguous"],
"named_tensions": ["trust_below_tau", "mint_halted"],
"residual": 0.45,
"reopen_when": ["direct target readback succeeds"],
"authority_ceiling": "observe-and-receipt"
}The residual is not a universal numerical requirement. The requirement is that the system not manufacture harmony by deleting the unresolved branch.
10.7 Append-only correction
An append-only ledger may preserve a later correction without changing the earlier row. The later row should name:
- the prior assertion;
- the new observation;
- the reason the prior assertion is no longer current or was never valid;
- the affected claim horizon;
- the next reader instruction;
- whether the correction changes source, evidence, authority, or only interpretation.
BND-17 is the lived example: the ledger recorded a true automatic fire and declared prior attestations false in the same medium. The correction did not retroactively make the prior rows correct; it made the history intelligible.
11. DAGs, quivers, and governed checkpoint history
11.1 DAGs discharge bounded responsibility
A directed acyclic graph is appropriate when a bounded unit of work has causal predecessors, finite joins, and a declared terminal condition. A carrier cannot precede the receipts it carries. A clean-clone proof cannot precede the immutable subject. A target readback cannot precede the target update. A terminal join cannot precede required shard dispositions.
The board compiles admitted covenants into this bounded execution structure. The DAG therefore answers what must precede what inside one responsibility slice.
11.2 Quivers preserve living recurrence
The broader field is not acyclic. Real systems revisit prior assumptions, reopen held states, learn from corrections, recur across horizons, and carry long-lived tensions. The quiver represents that living topology. [5,6]
FORKED states the relation cleanly: DAGs discharge bounded responsibility; quivers preserve the recurrence that returns. [5]
PHS uses both:
quiver -> living field of possible, lawful, forbidden, and recurring motion
splat -> bounded local field for one decision
covenant -> admitted current-to-target pull
DAG -> finite dependency and proof discharge
carrier -> durable state returned to the living field11.3 DAG of DAGs
A large checkpoint can contain multiple local DAGs connected by typed joins. One DAG may build the subject, another may prove distribution, another may reproduce, another may validate security, and another may materialize and checkpoint the carrier.
A meta-DAG can order those local graphs without becoming a second canonical authority. Each local graph retains its owner, subject, predicate, effect ceiling, and receipts. Cross-graph edges are explicit.
The t650 S1-to-S7 raise is the binder's seed example: plan, simulate, and fire closed the local chain in one tic while preserving six null-covenant identities as residue. [BND-06]
11.4 The proof DAG is not the commit DAG
The commit DAG shows immutable succession. It does not show whether a target exposed a commit, whether an independent environment acquired it, whether a proof worker had standing, or whether a later carrier preserved the observations.
The proof DAG binds observations to subjects. The authority DAG binds actors and transitions to ceilings. The three graphs may share identifiers, but they answer different questions.
This separation is what prevents a commit history from being read as a complete audit history.
11.5 No cycles inside the bounded execution graph
A bounded PHS epoch should not contain an uncontrolled execution cycle. Repeated retries, corrections, and reopenings are represented as new subjects, new receipts, or successor epochs rather than as an unbounded hidden loop.
This is finite re-entry rather than pretending recurrence does not exist. The living quiver may recur. The current execution DAG must still expose a next edge and a stopping condition.
12. Git reference realization
12.1 Why Git is a useful substrate
Git supplies:
- content-addressed objects;
- commit objects containing tree and parent bindings;
- a directed acyclic commit history;
- movable refs over immutable objects;
- direct remote-ref inspection;
- multiple repositories and remotes;
- clean clone acquisition;
- detached checkout of an exact subject;
- signatures, tags, and notes as optional metadata surfaces.
Git's object database and commit parentage provide strong subject identity and ordered succession. Remote refs provide independently readable distribution surfaces, while the distinction between live remote refs and local remote-tracking refs prevents stale local views from being mistaken for direct readback. [16-19]
12.2 Reference mapping
| PHS concept | Git realization |
|---|---|
| Immutable subject | Commit object ID, optionally paired with tree ID |
| Canonical lane | Designated root main under explicit write policy |
| Candidate lane | Branch, patch, worktree, generated tranche, or external repository |
| Distribution proof | Direct readback of expected remote refs against exact commit ID |
| Reproduction proof | Fresh clone from intended remote, detached checkout, declared validations |
| Receipt carrier | Descendant commit containing machine-readable receipts and lineage |
| Projection | Synchronized nonauthoritative ref in another remote or repository |
| Carrier proof | Direct readback and reproduction of the receipt carrier itself |
| Terminal reconciliation | Canonical pointer, task graph, receipts, and checkpoint state agree on the closed horizon |
12.3 Illustrative command geometry
# H1 - select exact immutable subject
SUBJECT="$(git rev-parse HEAD)"
TREE="$(git rev-parse "${SUBJECT}^{tree}")"
# H2a - publish through governed synchronization, then read the target directly
git push origin "${SUBJECT}:refs/heads/main"
REMOTE_SUBJECT="$(git ls-remote origin refs/heads/main | awk '{print $1}')"
test "${REMOTE_SUBJECT}" = "${SUBJECT}"
# H2b - independently acquire and reproduce the exact subject
TMP="$(mktemp -d)"
git clone --no-checkout "<declared-remote-url>" "${TMP}/repro"
git -C "${TMP}/repro" checkout --detach "${SUBJECT}"
"${TMP}/repro/scripts/validate-checkpoint"
# H3 - create a descendant carrier from resulting receipts
# The carrier cannot yet prove its own subsequent remote state.A production implementation should route writes through protected policy, verify authorization and fast-forward conditions, hash command manifests and outputs, preserve failure receipts, and distinguish source effects from provider, database, deployment, adoption, and outcome effects.
12.4 Exact subject re-freezing
The crank-2 staging memo provides a long-form example of exact-subject discipline. The proposed publication commit moved repeatedly as ruled changes landed. Each movement was recorded as a new addendum with a new exact SHA. The older tuple did not become approximately current, and the workflow's drift guard would refuse publication when packed roots diverged from the admitted commit. [35]
This is not inefficiency. It is the cost of refusing to publish a different subject from the one admitted.
The sequence also illustrates why a successful earlier dry run does not authorize a later moving head. The predicate remains bound to the exact subject.
12.5 Multi-remote projection without canon fragmentation
A concrete implementation may synchronize several refs to one selected commit while retaining one canonical writer. Those refs provide distribution, custody, disaster-recovery, or external-verification surfaces. They do not become independent authoring authorities merely because each is named main or can technically receive writes.
Authority is external to branch naming.
12.6 Proof-qualified release
A repository release can be defined as a closed set of horizons rather than a tag or CI status:
candidate admitted
+ exact source selected
+ required remote refs confirmed
+ clean clone acquired
+ declared validations passed
+ receipt carrier admitted
+ carrier checkpointed
= repository release horizon closedDeployment, adoption, and outcome remain successor horizons.
The context-grapple-gun dry run at tic 749 makes this distinction explicit. The workflow verified the admitted tuple, tested and packed the exact artifact, and skipped publish-side steps because dry_run=true. The result was green for the pre-publication path, while nothing was published and the registry remained unchanged. [34]
13. Failure semantics and correction survival
13.1 Faults remain localized
When a checkpoint fails, PHS identifies the failed proof shard rather than collapsing the event into release failed.
| Failed horizon | Meaning | Narrow response |
|---|---|---|
| H0 admission | Candidate invalid, out of scope, or unauthorized | Correct, reject, or hold the candidate |
| H1 source | Immutable source could not be lawfully materialized | Repair source or admission procedure |
| H2a distribution | Expected target does not expose exact subject | Repair authorization, reachability, ref selection, or propagation |
| H2b reproduction | Independent environment cannot acquire or validate subject | Remove hidden dependency or correct source |
| H3 carrier | Receipt bundle malformed, incomplete, or unauthorized | Reconstruct carrier without reopening valid source proof |
| H4 carrier proof | Carrier exists but required propagation or reproduction remains open | Checkpoint carrier as new subject |
| Deployment | External runtime does not match admitted artifact | Inspect deployment path; do not rewrite repository history by default |
| Adoption | Intended user or organization has not accepted or used the artifact | Gather adoption evidence; do not promote deployment receipt |
| Outcome | Real-world effect absent or unmeasured | Measure outcome under a declared method |
13.2 Corrections produce new subjects
Suppose detached-clone reproduction of source commit C fails because an undeclared file was required. The failure receipt remains bound to C. The corrected source becomes C'. Distribution and reproduction proof must be repeated for C'; the system does not edit the record to pretend that C passed.
C source subject
|-- R_remote(C) = pass
|-- R_clone(C) = fail
|
C' corrected source subject
|-- R_remote(C') = pass
|-- R_clone(C') = pass
|
K carrier for C' receiptsThe scar distinguishes source failure from distribution failure, reveals what changed, and prevents later actors from inheriting a false narrative of uninterrupted success.
13.3 Capability verdict overturned by execution
At t527, the operating account said the epoch16 LoRA path was not reachable. At t535, the system ran the thing and falsified the verdict. The corrected claim did not erase t527. It produced a lineage in which the assessment, its premises, the live result, and the new law remained visible. [BND-02]
The law is symmetric:
Never infer a current capability wall from a prior assessment without re-testing at the act, and never infer current liveness from a prior receipt when required state may have disappeared.
13.4 Vacuous green
The board-wiring claim survived roughly 119 tics because two defects concealed each other. One surface said the board was read; another allowed missing state to behave as executable. Only the first real eater exposed the absence. [BND-08]
The repair was not another prose warning. Missing state became visibly non-executable. The status model separated previously collapsed axes.
PHS generalizes the lesson: a predicate must state what happens when required state is absent. missing -> pass is usually a category error, not resilience.
13.5 Observer artifact occlusion
At tic 540, a telemetry marker suppressed the live cable receipt it was meant to help observe. The cure created a distinct __run__ key space, preserving the original confession in the ledger. [BND-18]
This is a subtle class of failure. Evidence tooling can perturb, overwrite, filter, or rename the event it measures. A trustworthy proof lane must model the observer's effect on the observed surface.
13.6 Append-only correction
At tic 701, the wave ledger recorded the first true automatic pawl fire and declared prior attestations false in the same append-only row. [BND-17]
The system did not rewrite the past for aesthetic consistency. It added a later fact whose relationship to the earlier claim was explicit.
13.7 Refusal and execution in the same tic
The tic-751 lap is important because the seat first refused on an honest but incorrect floor, the Architect retracted the floor, and the lap then ran. The two events were not smoothed into a triumphant story in which the refusal never happened. [BND-04]
The pattern is correction metabolism:
measured state
-> lawful refusal
-> better evidence
-> authority-bearing correction
-> execution
-> receipt with honest limitsThe lap's own limitations prevented plumbing proof from becoming capability proof. The live 27B consumed one harmony slice and returned typed proposals, but n=1, the label was low-information by construction, no proposal was evaluated, and no mutation moved. [33]
13.8 Deterministic re-entry
At interruption, a successor resumes from:
exact subject
+ completed proof shards
+ pending or failed shards
+ authority ceiling
+ receipt predicates
+ residue
+ convergence targetThe next action is the minimal unproven predecessor of closure. The successor does not need the previous agent's context window, terminal scrollback, private memory, or prose summary.
This is finite re-entry: uncertainty is represented as a missing or held edge rather than a vague status.
13.9 Correction debt
Correction debt is the downstream burden created when a state is accepted before adequate conformation or later becomes stale. It includes dependents trained on a false claim, dashboards that repeat outdated liveness, receipts bound to the wrong subject, and human decisions made under a collapsed horizon.
PHS reduces correction debt by keeping claims subject-bound and preventing stronger domains from inheriting weaker proof. It does not eliminate debt; weak predicates, dishonest observers, compromised authority, or omitted evidence can still create it.
14. Agentic systems and winch tempos
14.1 Governed verification swarms
PHS allows agents to fan out across proof while remaining structurally unable to mutate canon or overclaim. A source checkpoint may dispatch dependency inspection, clean-clone reproduction, direct remote readback, security review, schema validation, lineage inspection, artifact-integrity verification, and outcome-boundary review concurrently.
Each agent receives a smaller contract than a general mandate:
exact subject
+ permitted evidence surface
+ authority ceiling
+ receipt predicate
+ stop condition
+ convergence destinationThe agent can fail safely by emitting a bounded fail, hold, indeterminate result, or contradiction.

14.2 GUNSLINGER
GUNSLINGER is the all-ready-cables tempo. It maximizes lawful concurrency over the exact set that is both admitted and executable.
At tic 643, seven office citizens fired simultaneously with disjoint write surfaces, while seven unadmitted executable identities remained excluded. [BND-05]
At tic 650, seven work cables and three invariants traversed plan, simulate, and fire inside one tic; six null-covenant identities remained named as residue. [BND-06]
The campaign from tics 757 through 770 adds a stronger result: every measured wave falsified part of the lead premise. Wave seven moved from staged to signed to built to closed in 58 minutes with proof gates on both sides. Wave three replayed 68 files and 59 routes, produced zero verdict flips, changed 46 diagnoses, and made 92 silent stale pins visible. [BND-15]
GUNSLINGER is therefore not agents agreeing faster. It is bounded parallel challenge under a shared cradle.
14.3 HIDALGO
HIDALGO is a staged-lock throttle selected by residue shape. It is appropriate when the system should not raise every ready cable at once, even if all are nominally executable.
The binder records one live HIDALGO classification. That result should not be exaggerated into extensive empirical validation. It establishes that the throttle existed, was exercised, and judged a clean residue once. [BND-10]
14.4 Tempo does not alter evidence horizon
Neither tempo changes what a receipt proves. GUNSLINGER does not upgrade source evidence because more agents ran. HIDALGO does not produce stronger authority because a human-paced sequence occurred.
PHS therefore treats tempo as execution metadata, not evidence rank.
14.5 Dissonance as swarm fuel
A mature swarm should not merely divide implementation work. It should divide failure surfaces. Independent agents are useful when their contracts encourage different ways of being wrong and when the join preserves those differences.
The binder's claim that citizens out-falsified the lead in every campaign wave is evidence that the swarm was not functioning as a consensus amplifier. [BND-15]
14.6 Session-independent autonomy
Many autonomous systems store continuity in mutable task databases, chat summaries, working-directory residue, model memory, or branches whose authority is unclear. Those surfaces may be useful. None is sufficient as canonical evidence.
PHS provides durable epoch boundaries. One model may create the source. A second may reproduce it. A third may inspect receipts. A human may admit the carrier. Another model or vendor may resume later. Canon remains external to all of them.
Continuity therefore does not depend on the same model, context window, vendor, operator, machine, worktree, or repository host.
14.7 Scaling law
Let n be the number of independent proof workers and canonical mutation remain one ordered path. Subject to compute, network, dependency, predicate, human-attention, and join constraints:
proof throughput may increase with n
while canonical writer count remains 1More intelligence does not have to mean more authority.
The phrase unbounded parallel reasoning describes a topological property, not infinite physical capacity. Real systems remain bounded by resources and by the cost of lawful convergence.

14.8 Approval loops do not scale, but judgment remains causal
Prompted LLC's public account distinguishes permanent approval loops from human judgment as reusable structure. If every action waits on the same person, the person becomes a bottleneck or rubber stamp. If human judgment disappears, autonomy outruns governance. [8,28]
PHS moves human judgment to the edges where it has standing: selecting covenants, setting ceilings, resolving novel contradictions, opening irreversible surfaces, correcting false premises, and admitting canonical transitions.
The Architect's bell in the binder is an example. The system could size a model conversion, identify that RAM was sufficient, and prove that the real blocker was the output membrane and disk. It could not decide where to place the resulting weights or whether to open the new coupling. That movement remained the Architect's. [36]
15. Operational emergence and lived falsification
15.1 Method and evidence ceiling
This section reconstructs the operating lineage from THE BINDER and the supplied supporting artifacts. The binder was commissioned at tic 770 and composed from two miner-produced, lane-complete evidence tables. It declares 22 stable BND markers, 161 cable receipts, 68 drain receipts, 213 wave-ledger rows, 202 economy-tic artifacts, and 51 campaign files. [31]
The binder is two hops from ground truth. Its own method says to resolve BND markers to the extracts and then to the primary receipts. Those extracts were not supplied as standalone files with this revision. Accordingly:
- the binder is cited as an evidence map;
- supplied primary or contemporaneous artifacts are cited separately where available;
- counts and landmark descriptions retain their BND markers;
- disagreements remain visible;
- this paper does not claim an independent row-by-row re-audit of every binder table.
That limit is part of the method, not an editorial inconvenience.
15.2 Timeline spine

| Date or era | Tic(s) | Movement | Evidence marker |
|---|---|---|---|
| 2026-06-13 | 414-416 | Harpoonv2 founded; master DAG-of-DAGs falsified and rechartered as metabolize, not master. | BND-13 |
| ~2026-06-27 | 494-495 | Ten-cable, seven-wave hoist covenant; waves of agents named; center exclusion made a compiler check. | BND-01 |
| 2026-07-01 | 527-535 | Live model serve overturned a prior capability wall while mutation authority remained false. | BND-02 |
| 2026-07-03 verification | 512-559 | First full-cradle BOOM raise; six raisable cables, later seven-of-seven verification, center never struck. | BND-07 |
| 2026-07-05 | 568-570 | Typed winch modes, economy GUNSLINGER, collapse replay, and the deepest recorded basin exercise. | BND-09, 11, 12, 19 |
| 2026-08-11/12 | 621-623 | Board live compiler closed the approximately 119-tic vacuous-green scar. | BND-08 |
| ~2026-08-15/16 | 643, 650 | Seven simultaneous office citizens; the complete S1-S7 chain raised inside one tic. | BND-05, 06 |
| ~2026-08-30/31 | 749-751 | First governed seat consumption of a local model; refusal, correction, and lap preserved in one lineage. | BND-04 |
| 2026-09-01 to 04 | 757-770 | Eight-wave GUNSLINGER campaign, lead-premise falsification streak, and full horizon-quiver construction. | BND-15, 16 |
15.3 The first executable hoist
The tic-494 covenant converted a broad current-to-target intention into a ten-cable, seven-wave staged-lock DAG. Five of five pre-fire checks passed. Three invariants could run in parallel. The center remained a non-node enforced by the compiler. [BND-01]
The importance is architectural. The system no longer depended on the Architect manually carrying every relation between parts. The pull itself became executable while the founding telos remained outside the ordinary task graph.
15.4 Execution overturns assessment
At tic 535, the epoch16 LoRA served live on the M2 Max. The binder reports 8.31 GiB peak Metal memory, 280 of 280 LoRA modules, 1.7-second PEFT-to-MLX conversion, 88.9-second real inference, a passing gate, and mutation_authority=false. [BND-02]
The event did two things at once. It proved the live path that a prior assessment had rejected, and it refused to let live execution become mutation authority.
A later affordability survey initially recorded the t535 receipt as absent. The binder's miners found the receipt on disk and flagged the disagreement for adjudication instead of silently correcting the preparation artifact. [31,36]
This is PHS in lived form: current evidence overturns a stale capability claim, while the earlier claim and the later disagreement remain attributable.
15.5 Reproducing partial sums
The corpus chain records:
130,678 + 11,823 + 2,897 + 13,984 = 159,382 T7 tracesThe binder states that every partial sum independently reproduced a previously receipted historical total and that the total was re-derived at tic 700 after tic 650 had disclosed the previous figure as cited rather than re-derived. [BND-03]
The importance is not the size of the trace corpus alone. It is the transition from inherited number to reproducible number. A figure that once had only citation standing gained a later derivation receipt without pretending the earlier carrier had always possessed it.
15.6 BOOM, seven citizens, and the S-chain
The tic-512 BOOM raise produced receipts for six of six raisable cables within one cradle window. Later verification at tic 559 covered seven of seven, with center_struck=false, mutation_authority=false, and the 159,382-trace corpus bound into the account. [BND-07]
At tic 643, seven office citizens fired simultaneously with disjoint write surfaces. Only identities in the exact admitted-and-executable intersection fired. [BND-05]
At tic 650, the entire S1-S7 chain traversed plan, zero-side-effect simulation, and fire in one tic. Six null-covenant identities remained named as residue. [BND-06]
These events establish a progression:
manual crossing
-> receipted full-cradle raise
-> simultaneous bounded citizens
-> one-tic DAG-of-DAG dischargeThey do not establish that every later campaign used the same code path. The binder explicitly withholds that claim.
15.7 Economy as a long-running simulation lane
From tic 568 through 770, with one gap at 602, the economy generated 202 per-tic artifacts, 119,103 telemetry lines, and approximately 199,000 simulated generations. Every artifact used mode: gunslinger, phase: SimOnly, and anchor_frozen_center_excluded: true at each boundary. [BND-11]
This is the longest repeated expression of the winch vocabulary in the binder. It also demonstrates why source-tense must remain explicit. The economy was live as a moving simulation. It was not live money.
The tic-568 collapse replay reproduced a UCoin collapse across 2,400 shadow generations. Supply fell to 9.95e-06, reserve remained pinned at 0.2, and rate reached the 0.93 floor. The previously invisible condition - zero mint below a trust threshold - became a named breach flag at generation one. [BND-12]
The finding was not that the simulation prevented collapse. It was that a structurally invisible failure became visible early enough to govern future work.
15.8 The first local-consumer lap
At tic 749, after 221 tics without a governed seat consuming a local model, the egress-router seat served a local 27B reasoner and processed one real harmony slice. The supplied memo records 3,566 prompt tokens, 980 completion tokens, 7.97 output tokens per second, 0.87 MTP acceptance, 162.85 seconds wall time, 18.38 GiB wired-page delta, typed proposals only, and complete teardown. [33]
The memo's strongest sentence is its limit: plumbing was proven; capability was not. The sample was one, the label was partly pre-answered by the predicate, no proposal was evaluated, and no mutation occurred.
At tic 751, a second lap followed a lawful refusal on the wrong disk floor. The Architect corrected the premise, and the seat ran. The binder reports a score of 0.825 [0.680, 0.913] against 0.400 lookup and 0.025 majority baselines, with two byte-identical draws. [BND-04]
The refusal and the success belong in the same evidence chain.
15.9 The GUNSLINGER-BACKLOG campaign
The campaign from tics 757 through 770 followed a repeated structure: freeze the baseline, admit the covenant, prove the gun at the checkpoint boundary, dispatch waves, inspect results, and close only after the corresponding proof.
Its signature result was the lead-premise falsification streak. Every recorded wave found three or four premise errors. By wave two, this was named as a property of the form rather than an accident. By wave five, the close receipt carried lead_premise_falsification_streak: "n=6 waves". [BND-15]
Wave seven moved from staged to signed to built to closed in 58 minutes. Wave three replayed 68 files and 59 routes, changed 46 diagnoses without flipping a verdict, and made 92 silent stale pins visible.
A system that only measures agreement would miss the significance. The campaign became faster while continuing to contradict its lead. The throughput increase and the falsification rate moved together.
15.10 The August production windows
Author-supplied GitHub Insights screenshots for August 1 through September 1 report:
| Window | Additions | Deletions | Commits | Files changed |
|---|---|---|---|---|
| Aug 1-Sep 1 | 12,697,294 | 89,386 | 567 | 13,909 |
| Aug 25-Sep 1 | 8,935,647 | 95,938 | 188 | 9,850 |
| Aug 29-Sep 1 | 6,723,886 | 11,784 | 95 | 6,711 |
| Aug 31-Sep 1 | 3,928,484 | 6,087 | 40 | 2,819 |
The nested windows imply that approximately 70.4 percent of the monthly additions occurred in the final week, 53.0 percent in the final three-day window, and 30.9 percent in the final 24-hour window. [15]

The weekly code-frequency view separately shows an early-August bucket with roughly 2.915 million additions and 1.894 million deletions, followed by later weekly addition buckets near 2.16 million, approximately 2.6 million, and 6.745 million. The deletion totals differ from the monthly Pulse view because the screenshots expose different aggregation windows and possibly different bucket boundaries. This paper preserves the disagreement rather than forcing one number to serve every claim.
15.11 What the operational evidence establishes
The evidence establishes that:
- the operating system had already developed a receipt-bearing current-to-target machinery before PHS was formally named;
- parallel agent execution could be bounded by admitted sets, disjoint surfaces, invariants, and residue;
- the system repeatedly caught stale, vacuous, overnamed, or occluded claims;
- correction could alter the next trajectory without erasing the failed subject;
- proof vocabulary, horizon separation, carrier behavior, and detached reproduction became progressively explicit;
- the production corpus entered a scale at which conventional line-by-line human review could not remain the sole assurance mechanism.
The evidence does not establish that every line was hand-authored, that all changed paths were executable production code, that every receipt proved an external deployment, that every mechanism was live, that the protocol alone caused the acceleration, or that the results generalize without independent replication.
The defensible description is:
PHS was abstracted from a live governance apparatus that accelerated while retaining one canonical authority path, preserving correction scars, and repeatedly allowing bounded citizens to falsify the premises that dispatched them.
16. Honest negatives and truth boundaries
16.1 Honest negatives are protocol results
A mature evidence system should be able to say not only what succeeded but what has not happened. The binder explicitly requires these negatives to remain load-bearing. [31]
16.2 `basin_drained` has not fired live
The 213-row ledger contains no live basin_drained event. The one drain reference is orchestration prose within a cradle_stable row. The live-fire implementation keeps the relevant guard false by construction.
The correct claim is:
The basin is a law with one deep live exercise and a per-tic ambient presence in the economy's cradle fields. Its drain path is implemented and smoke-tested, not live-proven.
16.3 Rollback refusal has been armed but not needed
rollback_hold fired zero times in 213 ledger rows. Five armings recorded ratio=1.5 and verdict=passing. The refusal path exists and is tested, but no live event required it. [BND-22]
A gate does not need to refuse in order to exist. It does need evidence that the refusal path is reachable under its declared conditions. The current evidence supports built, armed, and not yet needed, not live-refusal proven.
16.4 Campaign vocabulary does not prove WinchDial traversal
No campaign wave is proven to have run through the WinchDial code path. The campaign lawfully uses the GUNSLINGER tempo vocabulary, but its receipts do not include basin, rollback, or residue events sufficient to prove code-path traversal. [31]
This is an important noncollapse boundary:
shared doctrine or vocabulary
!= shared executable path16.5 Fixture-green does not prove liveness
H1's 43 arms were deliberately unwired at first. The a0 validator was not yet attached to a call-site gate. The basin drain path was smoke-tested but not live. A doctrine packet was delivered but not consumed. [BND-16, 37]
Each state is real. None may impersonate the next.
16.6 Simulation is not external effect
The economy is SimOnly. The epoch16 model path produced proposals with mutation_authority=false. The local lap produced a bid, not a canonical move. [BND-02, BND-11, 33]
Naming these lanes live without their qualifiers would be precisely the misrepresentation PHS is designed to prevent.
16.7 The binder is not primary authority
The binder is intentionally a map. It is comprehensive, readable, and citation-addressable. It still does not replace the extracts or primary receipts. [31]
This paper's Appendix F preserves the BND markers for traversal. A release intended for external technical audit should ship the extracts and the primary artifacts or provide stable, access-controlled equivalents.
16.8 Currentness is per observation
The t748 affordability report measured an M2 Max, 32 GiB unified memory, a 24.96 GiB Metal working-set budget under the current default, 15 GiB of internal disk headroom, and 407 GiB on the T7. It also found stale catalog entries, absent base weights behind prior serve receipts, unregistered models, and a path probe that underreported installed runtime binaries. [36]
The report then received corrections at tic 751 because one disk figure had been interpreted at the wrong layer. The correction is not a defect in reporting currentness. It is evidence that currentness itself is an observation subject to instrument choice and later adjudication.
16.9 Delivery is not consumption
The a0 estate memo says this explicitly. A validated doctrine packet crossed the membrane and was delivered byte-identically, but the estate had not yet consumed it. The recovery condition became curable, not cured. [37]
PHS generalizes the boundary:
distributed != retrieved
retrieved != consumed
consumed != adopted
adopted != effective17. Relationship to the Ubiquity corpus
17.1 Ubiquity: constitutional substrate
Ubiquity supplies the parent governance direction: preserve agency, authorship, judgment, and meaningful contribution as AI-mediated capacity increases. It treats governance as substrate rather than a layer added after reasoning. [1-4]
PHS contributes one protocol within that substrate. It does not claim to be the whole Ubiquity architecture.
17.2 Fractal Quivers of Quivers: lawful and forbidden motion
FQoQ supplies the living topology of entities, typed edges, authority, standing, cost, anchors, forbidden paths, absorbers, receipts, and telos. [6]
PHS uses this substrate to treat proof, succession, and admission as different edge classes rather than one status field.
17.3 Computing Around the Open Center: bounded local computation
The open-center paper supplies the splat as a bounded local field carrying facets, exclusions, receipts, dependencies, hypotheses, and unresolved state. [7]
A PHS epoch is splat-like: it closes a declared local proof scope without claiming the working center as universal truth.
17.4 FORKED: horizon integrity and suspension mechanics
FORKED supplies governed horizon geometry and the rule that authority, evidence, and success do not silently transfer across horizons. It also makes cables, winches, clamps, absorbers, fuses, and DAG-of-DAG correction explicit in a suspension-lattice context. [5]
PHS's native move is to select the earliest lawful knowledge horizon as the proof partition key and derive carrier recursion from immutable causal order.
17.5 Context Grapple Gun: reviewed judgment lifecycle
Context Grapple Gun implements capture, human review, scoped promotion, and hydration without confusing rendered context with constitutional source of truth. [9] Cognitive Pull Requests supplies a related reviewable seam for AI-assisted change, while Trust as Behavior places evidentiary weight on observed conduct rather than title or fluent assertion. These are adjacent governance mechanics, not aliases for PHS: PHS supplies the temporal subject, horizon, carrier, and recursive checkpoint law that can govern such seams. [29,30]
PHS can supply stronger proof semantics for the transitions inside such a lifecycle: exact subject, proof class, authority ceiling, correction relation, carrier, and next horizon.
The tic-749 dry run and crank-2 re-freezing sequence are concrete examples of reviewed publication state remaining bound to an exact commit. [34,35]
17.6 Human judgment: edge of earned trust
Prompted LLC's public doctrine treats human judgment as reusable structure rather than permanent per-action approval. [8]
PHS supplies the evidence boundaries that let a system know where judgment is still required. Novelty, irreversibility, authority ambiguity, weak behavior history, cross-horizon movement, and unresolved dissonance can all keep the human edge open.
17.7 Look-First: custody at overwrite
Look-First requires an actor to reattach to canonical state before acting on it. [10]
PHS operationalizes that custody at subject selection, correction, carrier creation, and terminal reconciliation. The read is not permission; it is ownership of the state transition.
17.8 Successor topology: continuity without implementation identity
Successor topology preserves purpose, invariants, apophatic boundaries, scars, proofs, and attribution while permitting implementation, provider, model, repository, and runtime replacement. [11]
PHS is compatible with this FROG_LEAP logic. A successor carrier or implementation may preserve the protocol's identity without inheriting every prior body. Provenance does not imply parentage, standing transfer, compatibility, or support obligation.
17.9 The autoimmune governance apparatus
A contemporaneous tic-748 memo described Ubiquity's differentiation as an apparatus in which load-bearing claims remain coupled to falsifiers and where blind readers re-derive them. It also named the uncomfortable boundary: much of the machinery was consumed by itself, and the outside-reader test remained open. [32]
The memo is not independent evidence of uniqueness. It is valuable as an internal articulation of the telos that PHS later formalized: the thing that catches the system lying must be part of the organism, and its result must be capable of changing the organism.
18. Relationship to adjacent technical work
PHS uses existing primitives and can integrate with existing standards. Its contribution lies in the control law that orders them.
18.1 Git commits, branches, refs, worktrees, and notes
Git provides immutable content-addressed objects, a commit graph, refs, remotes, worktrees, and notes. [16-19]
None of these mechanisms individually partitions checkpoint evidence by temporal attainability, requires orthogonal proof fan-out over one fixed subject, converges receipts under one admission authority, preserves held residue, and recursively treats the carrier as a new proof subject.
PHS is not a replacement for Git. It is a protocol implemented over and beyond Git's storage and transport semantics.
18.2 in-toto and supply-chain attestations
in-toto records what steps were performed, by whom, in what order, and with what materials and products. Its statement and link models are natural encoding surfaces for PHS receipts. [20]
PHS adds an explicit checkpoint topology: horizon partition, serial canon, zero-authority proof lanes, governed join, recursive carrier proof, correction conservation, residue visibility, and deterministic re-entry.
18.3 SLSA provenance
SLSA provenance describes where, when, and how an artifact was produced and supports downstream verification and rebuilding. [21]
PHS can use SLSA provenance as a source or build receipt. It does not treat provenance as complete checkpoint closure unless the required horizons and authority predicates also pass.
18.4 Reproducible Builds
Reproducible Builds defines conditions under which the same source, environment, and instructions recreate bit-identical artifacts. [22]
PHS treats reproducibility as one possible proof shard. It additionally governs target availability, receipt carriage, authority, correction, cross-horizon movement, and recursive closure.
18.5 Artifact attestations and transparency logs
GitHub artifact attestations can establish build provenance for binaries and containers. Rekor records signed supply-chain metadata in a tamper-resistant transparency log. [23,24]
These systems strengthen authenticity, availability, and non-repudiation. They do not by themselves define which artifact may lawfully carry which future observation or which lane controls canonical mutation.
18.6 SCITT
SCITT defines signed statements, transparency services, verifiable data structures, registration policies, and receipts over a linear, irrevocable history. [25]
SCITT is close to PHS in its concern with statements, registration, and receipts. PHS contributes a separate control law for selecting proof horizons, sharding observations over one exact subject, preserving class distinctions, recursively checkpointing the carrier, and retaining one canonical admission path.
A SCITT receipt can be a PHS evidence object. It is not automatically a complete PHS epoch.
18.7 RATS and conceptual message wrappers
The RATS architecture separates Attesters, Verifiers, Relying Parties, Evidence, Attestation Results, Endorsements, Reference Values, and appraisal policies. The Conceptual Message Wrapper provides typed containers for those message classes. [26,27]
PHS can use RATS evidence and attestation results inside proof shards. Its additional concern is temporal carriage and canonical convergence across a sequence of changing subjects.
18.8 Single-writer systems and distributed consensus
PHS shares the consistency intuition of single-writer systems: one logical path serializes accepted mutation.
It differs from distributed consensus systems because its primary goal is not to let several authorities vote on the next canonical state. It scales observers, challengers, reproducers, and custodians while deliberately refusing to multiply canonical writers.
18.9 Comparative boundary
| System or primitive | Exact subject | Parallel evidence | Explicit authority ceiling | Horizon noncollapse | Descendant carrier recursion | Visible correction residue | Serial canonical admission |
|---|---|---|---|---|---|---|---|
| Git alone | yes | possible | no | no | no | partial | policy-dependent |
| in-toto | yes | yes | partial | no | no | possible | external |
| SLSA provenance | yes | build-focused | builder model | no | no | possible | external |
| Reproducible Builds | yes | yes | external | no | no | possible | external |
| SCITT | yes | yes | registration policy | partial | statement/receipt chain | append-only | service-specific |
| RATS | yes | yes | role-separated | partial | message flow, not PHS recursion | possible | relying-party-specific |
| Ubiquity/FORKED | yes | yes | yes | yes | broader carrier mechanics | yes | yes |
| PHS | yes | yes | yes | yes, temporal-evidentiary | required when later carrier proof matters | required | one logical path |
The table is a functional comparison, not a claim that adjacent systems cannot be profiled to implement PHS.
18.10 Originality boundary
A bounded review found precedents for individual ingredients: single-writer systems, clean-clone testing, provenance, attestations, trunk-centered development, remote mirrors, transparency logs, role-separated attestation, append-only receipts, DAG scheduling, and human approval gates.
The claimed PHS contribution is the complete relation:
inherited horizon noncollapse
+ earliest lawful knowability as partition key
+ exact immutable subject
+ orthogonal proof fan-out
+ zero-authority proof lanes
+ governed fan-in
+ descendant evidence carrier
+ recursive carrier checkpoint
+ serial canonical admission
+ correction and residue conservation
+ deterministic re-entryThe review does not establish that no private, unindexed, or differently named predecessor exists. It is not a formal patent prior-art search.
19. Origin, attribution, and invention method
19.1 Canonical attribution
Breyden E. Taylor designed Proof-Horizon Sharding at Prompted LLC as part of the Ubiquity architecture's attempt to coordinate increasingly capable human-and-agent systems without collapsing authorship, judgment, correction, or canonical authority.
The governed-horizon invention is upstream. It is expressed in FORKED's horizon geometry and horizon-noncollapse doctrine. PHS's native invention is the recognition that proof itself should be partitioned by the earliest horizon of lawful knowability and that this rule requires descendant evidence carriers and recursive carrier checkpoints.
The canonical attribution statement is:
Breyden E. Taylor designed Proof-Horizon Sharding, a temporal evidence protocol that partitions verification according to when and through what independent path each claim can lawfully become knowable. The method serializes canonical mutation through one authoritative lane, fans an immutable subject into orthogonal proof shards, converges those observations into a lineage-bearing descendant carrier, and recursively checkpoints that carrier without allowing it to attest to its own future state. The work inherits the broader governed-horizon and horizon-noncollapse primitive developed in Taylor's Ubiquity architecture and expressed through FORKED. Its operational discovery lineage includes the covenant, Harpoon, cable, board, winch, basin, anchor, receipt, and correction machinery documented in THE BINDER.
19.2 Invention through constraint architecture
The method emerged through an apophatic design process. Taylor designed a context assembly and execution environment that repeatedly enforced a perimeter of invalid states:
- no self-attestation;
- no coherence-as-admission;
- no proof-class collapse;
- no horizon-authority laundering;
- no branch or projection authority ambiguity;
- no hidden local-state dependence;
- no fixture-as-live misstatement;
- no vacuous green on missing consumers;
- no observer artifact suppressing the observed;
- no unsupported maturity uplift;
- no source-to-deployment or deployment-to-outcome laundering;
- no narrative erasure of correction;
- no reliance on private session memory for continuation;
- no striking or crowning of the excluded center.
Under that perimeter, the lawful residual architecture required proof to follow epistemic dependency. The source had to exist before post-source facts could be observed. Orthogonal observations could proceed in parallel. A later object had to carry them. That object could not certify its own future. Authority had to remain serial while observation fanned out. Held identities had to remain visible. Missing consumers had to block vacuous closure.
The architecture was not selected because it made a clean diagram. It was forced by repeated refusal of invalid closure.
19.3 The role of THE BINDER
The binder did not invent PHS. It reconstructed the operational lineage after the machinery had accumulated enough receipts to be traversed as history.
Its contribution to this revision is threefold.
First, it showed that many apparently separate names belonged to one current-to-target loop.
Second, it exposed the negative evidence required to describe the machinery honestly.
Third, it located the horizon-quiver self-falsification as the clearest concrete bridge between upstream horizon geometry and the PHS-native evidence law.
Because the binder is a map, the paper preserves its markers rather than treating its prose as the last evidentiary word.
19.4 AI assistance and human authorship
AI systems assisted with context compilation, source inspection, evidence extraction, implementation, analysis, drafting, citation checking, and document production under Taylor's author-defined problem frame, constraints, terminology, architecture, and attribution boundary.
The binder itself records a two-miner extraction and one-seat composition method. [31]
The assistance functioned as instrumentation within the invention and publication process. It is not the claimed inventive contribution. The author determined the problem, apophatic perimeter, lineage, governing relations, acceptance criteria, and final account.
This distinction is consistent with the protocol's own authority model: generation is not admission, and fluent output is not evidence of authorship or correctness.
19.5 Prompted LLC's role
Prompted LLC is the originating organization, builder and operator of the Ubiquity substrate, publication context for the parent papers, and rights holder named across the current public registry. Its machine-readable surfaces identify Breyden Taylor as author and founder and preserve canonical citation strings, file identities, status, and rights. [1-3,12,13]
This protocol paper is a Prompted LLC paper. Prompted Forge's role belongs to the separate implementation paper and does not alter the protocol's authorship or organizational origin.
20. Limitations and open work
20.1 Stable receipt specification
A stable specification should define subject bindings, horizon identifiers, predicate digests, environment descriptors, independence levels, standing, authority ceilings, nonclaims, residue, correction links, joins, and convergence rules.
Compatibility profiles could map these fields into in-toto, SLSA, DSSE, SCITT, RATS, OCI attestations, Git commits, databases, or other carriers.
20.2 Binder primary-source closure
The binder's two lane-complete extracts and the primary receipts they index should be included in a publication-grade audit package or exposed through stable controlled access. This revision preserves the evidence map but does not independently re-open every primary artifact.
A future conformance audit should reproduce every BND landmark from the cited source, check its hash, and state any divergence from the binder.
20.3 Independence levels
The protocol needs a graded vocabulary for independence: clean directory, clean clone, isolated container, separate host, separate account, separate organization, separate trust root, or formally diverse implementation.
Each level detects different failure classes. A receipt must not use the unqualified word independent when the boundary is narrower.
20.4 Trusted time and causal ordering
Repository ancestry provides partial causal order, but cross-system evidence may require signed time, append-only logs, monotonic sequence numbers, trusted hardware, or transparency services.
A formal model should state when ancestry is sufficient and when stronger time evidence is required.
20.5 Canonical authority succession
A singular logical writer requires succession policy. Future work should define emergency transfer, quorum-backed authorization behind one logical lane, compromise recovery, and proof of lawful authority change without creating competing canons.
20.6 Privacy-preserving proof
Receipts can expose sensitive paths, identities, configurations, prompts, customer information, or results. High-assurance profiles may require selective disclosure, encrypted evidence, redacted manifests, commitments, or zero-knowledge methods.
20.7 Formal verification
The invariants can be represented as a state machine or temporal logic specification. Formal verification could establish:
- no self-attestation;
- no unauthorized admission;
- no untyped horizon promotion;
- deterministic next-horizon selection;
- preservation of correction lineage;
- residue visibility;
- projection nonauthority;
- anti-vacuity;
- termination conditions for bounded epochs.
20.8 Predicate quality
PHS can faithfully carry weak proof. The protocol does not automatically know whether a predicate is sufficient.
Domain-specific work remains necessary for coverage, falsification, adversarial testing, calibration, safety cases, and external validity.
20.9 Empirical evaluation
Future studies should compare conventional and PHS workflows on:
- proof throughput;
- join latency;
- re-entry time after interruption;
- false-closure reduction;
- hidden-dependency discovery;
- correction debt;
- falsification rate;
- residue visibility;
- audit reconstruction effort;
- human judgment load;
- canonical-writer count;
- deployment and outcome claim accuracy.
The binder and August 2026 Forge history offer a longitudinal case study, not a controlled experiment.
20.10 Winch-mode evaluation
GUNSLINGER has a substantial operational history in the supplied evidence. HIDALGO has one recorded live classification. The relationship between tempo, defect discovery, join latency, residue, and correction cost remains open.
The campaign's tempo vocabulary should not be treated as proof that every wave traversed the same WinchDial implementation.
20.11 Dissonance-basin evaluation
The basin law requires deeper live evaluation. The current record supports one deep measured exercise, smoke-tested drain behavior, and ambient use in the simulated economy. It does not support a claim that live drain events have operated at scale.
20.12 Non-Git implementations
The broader claim should be tested over database migrations, infrastructure state, model registries, policy execution, media pipelines, legal instruments, clinical workflows, scientific experiments, and supply-chain custody.
Git is a strong first substrate because its objects make temporal and causal boundaries visible. It is not the only possible one.
20.13 Prior-art and standards review
The adjacent-work review is bounded. A formal prior-art search should include distributed systems, event sourcing, formal methods, safety cases, scientific provenance, chain of custody, legal execution, remote attestation, temporal databases, and autonomous-agent governance.
21. Conclusion
Proof-Horizon Sharding begins from two inherited refusals, one lived machinery, and one specialized consequence.
The first refusal, inherited from Ubiquity and FORKED, is that authority, evidence, and success do not silently collapse across horizons.
The second is that possessing, rendering, or locally executing canonical state does not confer canonical jurisdiction.
The lived machinery binds a current-to-target pull through covenants, strikes it into shape, routes work and contradiction through cables, compiles admitted dependencies into DAGs, raises ready work through a winch, preserves dissonance and residue in basins, keeps the center excluded, and carries results in receipts.
The specialized consequence is that an immutable artifact cannot truthfully claim knowledge of an event that had not occurred when it was created.
From those constraints follows a complete control law.
Canonical mutation remains serial. Proof acquisition becomes parallel. Evidence is bound to exact subjects. Distribution and reproduction remain orthogonal. Receipts converge without losing their class. A descendant carrier preserves predecessor evidence and then becomes a new proof subject. Synchronized repositories preserve canon without multiplying authority. Missing consumers block vacuous closure. Held identities remain visible. Failures remain legible. Corrections survive. A successor resumes from the first required unproven horizon.
The decisive proof is that the apparatus can govern itself. A probe named for detached reproduction made no remote contact and therefore refused the rung promised by its own name. The system preserved a lower evidence rank instead of laundering intent, coherence, or implementation presence upward. [BND-16]
The deeper operating result is not uninterrupted correctness. It is correction metabolism. The apparatus overturned stale assessments by execution, exposed false green states, separated observation keys from observed events, recorded later corrections without retconning prior rows, and allowed bounded citizens to falsify the lead premise in every measured campaign wave.
The result is a temporal evidence layer over content-addressed history and, more generally, a primitive for correction-surviving, proof-carrying canonical computation.
You can coordinate unbounded parallel reasoning around bounded serial truth.
Many actors may propose. Many may inspect. Many may reproduce. Many may challenge. Many repositories may preserve. Many agents may continue. Many cables may pull. Yet every accepted transition retains one intelligible place in causal, evidentiary, and authority history.
That is the capability PHS enables:
Distributed execution, verification, custody, and falsification can scale independently while canonical state remains serial, temporally honest, reproducible, correction-bearing, and deterministically resumable.
Appendix A. Protocol pseudocode
The following pseudocode expresses the PHS control law after integration of the binder-derived operating mechanics. It is normative at the level of ordering and invariants, not at the level of function names or storage technology.
function run_phs_epoch(candidate, policy, current_canonical_state):
# LOOK-FIRST: establish the current reference frame before proposing change.
preimage = observe_exact_current_state(current_canonical_state)
assert preimage.identity_is_exact
assert preimage.authority_source_is_named
# COVENANT: bind a bounded current-to-target pull without treating telos as a node.
covenant = bind_covenant(
current=preimage,
target=policy.declared_target,
scope=policy.scope,
standing=policy.standing,
authority_ceiling=policy.authority_ceiling,
success_predicate=policy.success_predicate,
failure_predicate=policy.failure_predicate,
nonclaims=policy.nonclaims,
center_exclusion=policy.center_exclusion,
rollback_policy=policy.rollback_policy
)
h0 = disposition(candidate, covenant.admission)
if h0 != ADMITTABLE:
return preserve_receipt(
horizon=H0,
subject=candidate,
result=h0,
next_horizon=correct_or_hold(h0)
)
# STRIKE: derive a bounded shape; do not confuse shape with admission.
strike = six_ray_strike(candidate, covenant)
assert strike.center_was_not_crowned
assert strike.claims_do_not_exceed_source
# BOARD: compile only admitted covenants and exact dependencies.
board = compile_board(
covenant=covenant,
strike=strike,
anti_vacuity=true,
missing_state_is_non_executable=true
)
assert board.center_exclusion_check == GO
assert board.admitted_intersection_exec_ready_is_explicit
assert board.excluded_exec_ready_identities_are_named
# H1: select and materialize the exact immutable source subject.
S = materialize_immutable_subject(board.admitted_candidate)
assert exact_identity(S)
record(horizon=H1, subject=S, covenant=covenant, board=board)
# WINCH: select tempo without altering authority or evidence semantics.
mode = select_winch_mode(policy.tempo)
assert mode in {GUNSLINGER, HIDALGO}
if mode == GUNSLINGER:
executable = all_independent_exec_ready_cables(board)
else:
executable = next_staged_lock(board, residue_shape=board.current_residue)
# PROOF FAN-OUT: proof workers may observe, never self-admit.
required = policy.required_proof_shards(S)
proof_lanes = create_zero_authority_lanes(
subject=S,
predicates=required,
authority_ceiling=OBSERVE_AND_RECEIPT,
convergence_destination=board.join
)
receipts = parallel_map(proof_lanes, lane -> run_shard(lane))
# Preserve all results, including failure and indeterminate states.
for R in receipts:
assert R.subject_id == id(S)
assert R.observed_after_subject_creation
assert R.actor_authority <= R.authority_ceiling
assert R.claim_class == R.horizon
assert R.nonclaims_are_explicit
preserve_receipt(R)
# BASINS: unresolved tension and blocked identities stay visible.
basin = hold_dissonance_and_residue(
failed_or_held=required_not_passed(receipts),
excluded_identities=board.excluded_identities,
minimum_residual=policy.minimum_residual
)
assert basin.never_silently_drops_identity
assert basin.drain_does_not_collapse_tension_to_zero
if any_required_failed_or_held(receipts):
preserve_failure_lineage(S, receipts, basin)
return HELD(
subject=S,
completed=passed_receipts(receipts),
pending=required_not_passed(receipts),
residue=basin,
next=earliest_required_unproven_horizon(receipts)
)
# H3: observations become durable only in a lawful descendant carrier.
K = create_descendant_carrier(
predecessor=S,
receipts=receipts,
covenant=covenant,
residue=basin,
join=board.join
)
assert all(K.claims).observed_before(t_create(K))
assert not K.claims_its_own_future
record(horizon=H3, subject=K, predecessor=S)
# H4: carrier recursion. The carrier is now the subject.
carrier_receipts = run_required_carrier_proofs(
subject=K,
policy=policy.carrier_policy,
authority_ceiling=OBSERVE_AND_RECEIPT
)
for KR in carrier_receipts:
preserve_receipt(KR)
if any_required_failed_or_held(carrier_receipts):
preserve_failure_lineage(K, carrier_receipts)
return HELD(
subject=K,
completed=passed_receipts(carrier_receipts),
pending=required_not_passed(carrier_receipts),
next=earliest_required_unproven_horizon(carrier_receipts)
)
# H5: one authority reconciles and admits only the earned horizon.
assert terminal_reconciliation(
source=S,
carrier=K,
source_receipts=receipts,
carrier_receipts=carrier_receipts,
board=board,
covenant=covenant,
policy=policy
)
assert no_untyped_cross_horizon_promotion()
assert no_hidden_residue_inside_claimed_scope()
assert projection_does_not_confer_authority()
admit_canonical_successor(K, through=policy.serial_authority)
return CLOSED(
horizon=H5,
subject=K,
closed_scope=policy.declared_closure_scope,
stronger_horizons_still_open=policy.explicit_successor_horizons
)A.1 Re-entry procedure
function reenter_phs_epoch(epoch_state):
look = observe_exact_current_state(epoch_state.canonical_pointer)
if look.identity != epoch_state.expected_preimage:
return HELD(reason="preimage_moved", next="fresh-look-and-rebind")
completed = validate_completed_receipts(epoch_state.completed_receipts)
pending = required_minus_completed(epoch_state.required_receipts, completed)
if pending is empty:
return continue_at(epoch_state.next_declared_join_or_carrier_horizon)
owner = earliest_causal_owner(pending)
preserve(epoch_state.residue, epoch_state.dirty_set, completed)
return dispatch(owner, exact_subject=epoch_state.subject)Finite re-entry does not mean that every recovery is cheap. It means that uncertainty is represented as an explicit missing or failed edge rather than as an unbounded requirement to reconstruct a prior agent's private mental state.
A.2 Anti-vacuity procedure
function anti_vacuity(board, claimed_predicate):
consumers = discover_real_consumers_by_reading_execution_paths(board)
if consumers is empty:
return FAIL("no proved eater or enforcement call site")
for consumer in consumers:
state = read_consumer_state(consumer)
if state is missing:
return HELD("consumer state missing; non-executable")
if not consumer.enforces(claimed_predicate):
return FAIL("presence is not enforcement")
return PASSThis procedure is included because the board-compiler scar demonstrates that a declared integration can remain falsely green when no real consumer executes the declaration. [BND-08]
Appendix B. Reference receipt and carrier schemas
The schemas below are illustrative substrate-neutral profiles. Implementations may encode them in JSON, CBOR, DSSE, in-toto statements, SCITT envelopes and receipts, Git objects, append-only logs, governed database rows, or another durable format. The semantic requirements govern; the representation does not.
B.1 Proof-shard receipt
{
"protocol": "proof-horizon-sharding/v1.2",
"receipt_id": "phs-receipt-<stable-id>",
"checkpoint_id": "phs-epoch-<stable-id>",
"subject": {
"type": "git-commit",
"id": "<exact-object-id>",
"tree_id": "<exact-tree-id>",
"predecessor_id": "<optional-predecessor-id>",
"correction_of": "<optional-failed-or-superseded-subject-id>"
},
"horizon": "H2b.independent-reproduction",
"parent_horizon": "repository-source",
"covenant": {
"id": "<covenant-id>",
"current_identity": "<preimage-id>",
"target": "<bounded-target>",
"center_exclusion": true,
"success_predicate_digest": "sha256:<digest>",
"failure_predicate_digest": "sha256:<digest>"
},
"predicate": {
"name": "detached-clone-validation",
"command_manifest": "sha256:<digest>",
"expected": "all required checks pass",
"anti_vacuity": {
"consumer_required": true,
"consumer_ids": ["<consumer-id>"],
"enforcement_verified": true
}
},
"observer": {
"actor_id": "<verifier-id>",
"standing": "<standing-at-this-horizon>",
"environment_id": "<environment-id>",
"independence_level": "clean-clone-separate-directory",
"acquisition": "clone-from-declared-remote"
},
"causal_position": {
"subject_created_before_observation": true,
"observed_at": "<timestamp-or-monotonic-position>",
"carrier_not_yet_created": true
},
"result": "pass",
"evidence": [
{"type": "log", "digest": "sha256:<digest>"},
{"type": "test-report", "digest": "sha256:<digest>"}
],
"residue": {
"held_identities": [],
"unresolved_tensions": [],
"observer_artifact_occlusion_checked": true
},
"authority_ceiling": "observe-and-receipt",
"mutation_authority": false,
"nonclaims": [
"does not prove deployment",
"does not prove adoption",
"does not prove business outcome"
],
"convergence_target": "H3.receipt-carrier",
"next_horizon": "H3.receipt-carrier"
}B.2 Receipt/state carrier
{
"protocol": "proof-horizon-sharding/v1.2",
"carrier_id": "<exact-carrier-id>",
"carrier_type": "descendant-state-carrier",
"predecessor_subject": {
"type": "git-commit",
"id": "<source-subject-id>"
},
"covenant_id": "<covenant-id>",
"join": {
"join_id": "<governed-join-id>",
"required_receipt_ids": ["<receipt-1>", "<receipt-2>"],
"receipt_digests": ["sha256:<digest-1>", "sha256:<digest-2>"],
"all_required_present": true,
"all_subjects_match": true,
"all_temporal_relations_lawful": true,
"all_authority_ceilings_respected": true
},
"claim_horizon": "H3.receipt-carrier",
"claims": [
{
"claim": "declared remote refs exposed the predecessor subject",
"supported_by": "<receipt-id>",
"evidence_class": "distribution"
},
{
"claim": "an independently acquired exact predecessor passed the declared predicate",
"supported_by": "<receipt-id>",
"evidence_class": "reproduction"
}
],
"residue": {
"held_basin": [],
"unresolved_tensions": [],
"minimum_residual_preserved": true
},
"authority": {
"admitted_by": "<serial-authority-id>",
"authority_source": "<authority-source-id>",
"projections_are_nonauthoritative": true
},
"nonclaims": [
"does not prove the carrier's own later propagation",
"does not prove deployment",
"does not prove adoption",
"does not prove outcome"
],
"next_horizon": "H4.carrier-checkpoint"
}B.3 Held-state receipt
{
"protocol": "proof-horizon-sharding/v1.2",
"checkpoint_id": "<epoch-id>",
"subject_id": "<exact-subject-id>",
"state": "HELD",
"failed_or_pending_horizon": "H2b.independent-reproduction",
"reason_code": "predicate_failed",
"completed_receipts": ["<receipt-id>"],
"pending_receipts": ["<receipt-id>"],
"held_basin": [
{
"identity": "<blocked-identity>",
"reason": "<why-it-remains-visible>",
"owner": "<causal-owner>",
"reentry_condition": "<minimum-required-condition>"
}
],
"dirty_set": ["<changed-surface>"],
"next_horizon": "<earliest-required-unproven-horizon>",
"nonclaims": [
"hold is not rejection",
"completed sibling proof remains valid only for its exact subject",
"no stronger closure is implied"
]
}B.4 Winch-run receipt
A PHS implementation using the binder's operating machinery may additionally carry:
{
"winch_run_id": "<stable-id>",
"mode": "GUNSLINGER",
"covenant_ids": ["<id>"],
"source_subject_id": "<exact-id>",
"exec_ready_ids": ["<id>"],
"admitted_ids": ["<id>"],
"dispatched_ids": ["<id>"],
"excluded_exec_ready_ids": ["<id>"],
"center_struck": false,
"mutation_authority": false,
"cradle": {
"dissonance_basin_present": true,
"residual_fraction": "<measured-or-policy-bound-value>",
"rollback_drill_armed": true,
"rollback_hold_fired": false
},
"result": "cradle_stable",
"receipts": ["<receipt-id>"],
"nonclaims": [
"mode label does not prove traversal through a particular code path",
"simulation does not prove external economic effect"
]
}Appendix C. Conformance checklist
An implementation conforms to the core PHS v1.2 protocol when every applicable question below can be answered yes, with evidence bound to the exact implementation version being evaluated.
- Is every proof receipt bound to one immutable or strongly identified subject?
- Is the current canonical preimage observed before candidate mutation begins?
- Is the candidate's current-to-target pull bounded by a covenant or equivalent contract?
- Does the covenant name scope, standing, authority ceiling, success, failure, and nonclaims?
- Is the invariant or center preserved as a reference frame rather than represented as an ordinary node that the work may rewrite?
- Is canonical mutation serialized through one logical authority path?
- Can proof workers observe and receipt without automatically acquiring admission authority?
- Are source existence, remote distribution, independent reproduction, carrier existence, deployment, adoption, and outcome represented as distinct evidence horizons?
- Is direct target readback distinguished from local cached or tracking state?
- Does reproduction acquire the exact subject without undeclared inheritance from the authoring environment?
- Are orthogonal proof shards allowed to run concurrently over one fixed subject?
- Must every required shard pass, or be explicitly waived by an authorized policy, before its observations enter an admitted carrier?
- Is a receipt carrier prohibited from claiming events that occurred after its creation?
- Does the carrier become a new proof subject when its own propagation, reproduction, execution, acceptance, or outcome matters?
- Are synchronized copies explicitly denied independent canonical authority?
- Do failed and corrected attempts remain bound to their original subjects and visible in lineage?
- Can a successor identify the first required unproven horizon without relying on private process memory?
- Does terminal closure state exactly which domain is closed and which stronger domains remain unproven?
- Does missing consumer or call-site state fail closed rather than defaulting to executable or green?
- Does the implementation distinguish presence of a validator from enforcement by a real consumer?
- Are identities that are executable but unadmitted explicitly excluded and preserved as residue rather than silently dispatched or dropped?
- Are blocked, null-covenant, or otherwise held identities visible in a held basin or equivalent state?
- Are observation keys and telemetry markers prevented from occluding or overwriting the events they are meant to observe?
- Are stale capability or currentness claims re-tested at the act when their truth can change with environment or time?
- Are exact subject changes re-frozen and re-receipted rather than silently inheriting approval from an earlier subject?
- Does the implementation carry honest negative results such as not-run, fixture-only, simulation-only, held, or armed-but-not-fired?
- If a tempo such as GUNSLINGER or HIDALGO is named, is that label kept separate from evidence that a particular implementation path actually executed?
- Does any dissonance-drain mechanism preserve a declared residual rather than flattening unresolved tension to zero?
- Does the rollback path exist and remain independently distinguishable from evidence that it has fired live?
- Are narrative or descriptive projections prevented from acting as law unless separately admitted?
- Are claims about external deployment, stakeholders, money, adoption, or outcome blocked unless their native evidence horizons close?
- Can an observer reproduce each published quantitative claim from a named instrument, receipt, or derivation path?
- Does the system preserve disagreement between independent readers as evidence rather than selecting the more convenient reading silently?
- Does a named proof tool earn its rung from evidence rather than from its identifier, intended purpose, or implementation presence?
- Can the system emit a lower-rank result when a higher-rank probe fails to contact the required surface?
- Is the final admission act performed by the actor or mechanism whose standing includes canonical convergence?
A system that answers no to a required item may still use some PHS-compatible mechanisms. It should not claim conformance to the complete profile without naming the missing conditions.
Appendix D. Selected glossary
Admission. The governed transition by which candidate material becomes accepted state within a declared scope. Admission does not imply deployment, adoption, or outcome.
Anchor. The preserved reference frame that makes a current-to-target comparison meaningful. In the binder's machinery the founding telos or frozen center is excluded from ordinary node mutation and checked by the compiler and runtime membrane.
Anti-vacuity. The requirement that a declared check, validator, wire, or doctrine have a real consumer or enforcement path before it may count as operationally closed.
Apophatic nonclaim. An explicit statement of what an artifact, receipt, actor, or checkpoint does not establish.
Binder. In this paper, THE BINDER is a curated evidence map containing stable BND markers that resolve onward to extracts and primary artifacts. It is not itself promoted to primary-source authority.
Board. The surface that compiles admitted covenants and dependencies into an executable DAG while applying admission, readiness, center-exclusion, and anti-vacuity rules.
Cable. A bounded route through which work, proof, tension, or correction is carried around the excluded center. A cable has a subject, owner, predicate, authority ceiling, and convergence destination.
Canonical projection. A synchronized or rendered copy of canonical state that does not independently decide what becomes canonical.
Carrier. A durable successor object that transports evidence, state, lineage, receipts, or residue across a transition.
Checkpoint epoch. A bounded interval from candidate disposition through the proof and carrier horizons required for a declared closure.
Coherence-is-not-admission. The rule that a coherent, executable, or apparently complete candidate does not gain standing merely from those qualities.
Covenant. A bounded current-to-target contract that names the pull, scope, authority, standing, success, failure, nonclaims, dependencies, and irreversible surfaces.
Correction conservation. The property that correction adds a successor subject and new receipts without rewriting the earlier subject into a state it never occupied.
Correction survival. The intelligibility of failed, held, corrected, and superseded attempts in later lineage.
DAG. A directed acyclic graph encoding causal predecessors and lawful execution order for a bounded tranche. The DAG is a discharge structure, not the whole ontology or living field.
Deterministic re-entry. Resumption from the first required unproven or failed causal edge using durable state rather than private process memory.
Detached-clone reproduction. Acquisition and validation of an exact source subject in an environment that does not inherit undeclared mutable state from the authoring checkout.
Dissonance basin. A tension reservoir that preserves unresolved contradiction during a raise and may drain part of that dissonance into work while retaining a nonzero residual.
Evidence ceiling. The strongest conclusion supported by the exact available evidence.
Evidence class. A non-interchangeable category such as source, distribution, reproduction, deployment, adoption, or outcome.
Evidence shard. A bounded proof bundle confined to one subject, horizon, predicate, evidence surface, and authority ceiling.
Falsifier. A consumer, probe, test, independent reader, or adversarial surface capable of disproving the claim it accompanies.
Finite re-entry. See deterministic re-entry.
Frozen center. The invariant reference point intentionally excluded from ordinary work-node mutation. “Open center” and “frozen center” emphasize different aspects of the same refusal: the center is not crowned by local work and is not struck as an ordinary target.
GUNSLINGER. The all-ready tempo of the winch: all independently executable and admitted cables may fire under one shared cradle, with rollback machinery armed. GUNSLINGER is a tempo, not a separate authority class.
Harpoon / six-ray strike. A bounded shape-production and falsification procedure that examines a thing through multiple declared rays before execution or admission. Strike quality does not itself confer canonical standing.
HELD. A first-class nonterminal state in which one or more required conditions remain unresolved. A hold preserves completed evidence, the exact subject, causal owner, residue, and re-entry condition.
Held basin. A graph-level store for blocked, excluded, null-covenant, or otherwise unresolved identities. It is distinct from the DissonanceBasin tension reservoir.
HIDALGO. The staged-lock tempo of the winch. It throttles work according to residue shape and judged stage boundaries. HIDALGO is not the default and is not a third authority lane.
Horizon. A bounded jurisdiction of telos, authority, standing, evidence, consequence, and closure. State earned at one horizon does not silently acquire standing at another.
Horizon noncollapse. The FORKED rule that declarations, success, or authority at one horizon do not transfer to another without a typed and admitted cross-horizon edge.
Hoist. The governed current-to-target raise in which admitted cables, dependencies, agents, gates, receipts, and correction machinery close a bounded loop.
Join receipt. Evidence that all required fan-out lanes completed, retained their evidence classes, and were checked before convergence.
Lawful knowability. The causal and evidentiary condition under which a fact can first be truthfully observed and attributed.
Look-First. The discipline of reattaching to exact current canonical state before proposing, mutating, or overwriting.
Monotonic evidence. The addition of bounded observations about an exact subject without rewriting what earlier subjects could know.
Nonclaim. An explicit denial of a stronger unsupported implication.
Observer-artifact occlusion. A failure in which a marker, key, logging convention, or observation mechanism suppresses or overwrites the event it is intended to measure.
Proof. Evidence satisfying a declared predicate for a bounded claim. It is not necessarily mathematical proof unless explicitly stated.
Proof horizon. The strongest bounded claim supported by the exact available evidence at a causal position.
Proof-Horizon Sharding. Partitioning checkpoint verification according to the earliest horizon at which, and the independent path through which, each fact can truthfully become known.
Proof-only lane. A lane permitted to inspect and report but prohibited from mutating canonical source or admitting its own observation.
Quiet point. A bounded state in which all predicates inside the claimed scope are satisfied and no hidden pending edge remains. It does not mean permanent completion.
Receipt. A durable record binding a claim to its exact subject, predicate, method, observation, result, authority, limitations, residue, and next horizon.
Receipt carrier. A descendant artifact that incorporates observations produced after the predecessor subject existed.
Receipt recursion. The rule that a carrier may preserve evidence about its predecessor but cannot contain future observations about its own later state.
Residue. The visible remainder of excluded, blocked, failed, unresolved, or deliberately unconsumed state after a bounded operation.
Remote-ref readback. Direct observation of named refs on a target remote, compared against an exact selected subject.
Serial authority. The rule that accepted canonical transitions enter through one ordered logical mutation path.
Simulation-only. A live computational lane whose effects are confined to simulation and therefore do not establish external economic, provider, database, stakeholder, or outcome effects.
Sniper. In the binder's adjudication, a range or precision register associated with GUNSLINGER language, not a third winch mode or independent mechanism family. [BND-09]
Source-bearing subject. The immutable object that carries the selected source tranche whose later distribution and reproduction will be verified.
Strike. The bounded shaping and adversarial examination of a candidate before or around execution. In the binder this is implemented through Harpoon's six-ray council.
Temporal admissibility. The requirement that an observation exist before an artifact may lawfully carry it.
Temporal self-attestation. The invalid implication that an immutable artifact can certify an event occurring only after it exists.
Truth horizon. The boundary between what is currently established and what remains pending, held, intended, simulated, or unknown.
Vacuous green. A passing status produced without a real consumer, enforcement path, required state, or meaningful predicate.
Winch. The execution mechanism that raises admitted and executable cables according to a selected tempo under anchor, basin, rollback, and receipt constraints.
Winching. The broader current-to-target motion performed by covenants, strikes, cables, boards, agents, basins, gates, and receipts. PHS governs what may be claimed about the motion and when.
Appendix E. Lineage and claim register
| Claim or mechanic | Lineage class | Source | Treatment in PHS v1.2 |
|---|---|---|---|
| Governance substrate for sovereign adaptive systems | Inherited | Prompted LLC / Ubiquity | Constitutional parent |
| Sovereignty as agency surviving amplification | Inherited | Sovereign Continuity | Telos and continuity condition |
| Living lawful and forbidden traversal | Inherited | Fractal Quivers of Quivers | Proof and authority graph substrate |
| Open-center and splat mechanics | Inherited | Computing Around the Open Center | Bounded computation and scoped closure geometry |
| Governed horizon geometry | Inherited | FORKED | Parent horizon model |
| Horizon noncollapse | Inherited | FORKED | General rule specialized to evidence |
| Look-First custody | Inherited | Prompted LLC / Look-First | Exact preimage and correction discipline |
| Human judgment as reusable structure | Inherited | Prompted LLC / Ubiquity | Human authority at earned-trust edges |
| Successor continuity without implementation identity | Inherited | Successor Topology | Canonical succession and provenance boundary |
| Approval-loop limits | Inherited adjacent doctrine | Prompted LLC | Motivation for bounded judgment rather than per-token supervision |
| Cognitive Pull Requests | Inherited adjacent doctrine | Prompted LLC | Reviewable seam; not identical to PHS receipt topology |
| Trust as behavior | Inherited adjacent doctrine | Prompted LLC | Receipted conduct rather than role title |
| Covenant / current-to-target pull | Operational precursor | Ubiquity winching machinery | PHS checkpoint scope and transition contract |
| Harpoon six-ray strike | Operational precursor | Harpoonv2 office | Candidate shaping and falsification surface |
| Cable routing | Operational precursor | Hoist / winch machinery | Bounded proof and work lanes |
| Board-compiled DAG | Operational precursor | Hoist machinery | Causal ordering and convergence structure |
| GUNSLINGER / HIDALGO | Operational precursor | Winch machinery | Tempo selection without authority promotion |
| Dissonance basin | Operational precursor | Winch machinery | Tension and unresolved contradiction preservation |
| Held basin | Operational precursor | Cable lattice | Residue and blocked-identity visibility |
| Frozen-center exclusion | Operational precursor | Hoist / open-center lineage | Anchor-preservation invariant |
| Receipt-bearing wave ledger | Operational precursor | Winch history | Correction-bearing evidence medium |
| Temporal self-attestation problem | PHS-native formulation | PHS | Core problem statement |
| Earliest lawful knowability as proof partition key | PHS-native | PHS | Core sharding rule |
| Fixed-subject orthogonal proof fan-out | PHS-native composition | PHS | Parallel verification topology |
| Zero-authority proof lanes | PHS-native composition | PHS | Observer scaling without writer scaling |
| Descendant receipt carrier | PHS-native composition | PHS | Durable carriage of later observations |
| Recursive carrier checkpoint | PHS-native composition | PHS | No-self-attestation enforcement |
| Correction conservation | PHS-native derivation | PHS | Failure remains bound to original subject |
| Deterministic re-entry | PHS-native derivation | PHS | Resume from first required unproven edge |
| Anchor-preservation invariant | PHS v1.2 formalization | Binder-integrated PHS | Reference frame remains outside ordinary mutation |
| Residue-visibility invariant | PHS v1.2 formalization | Binder-integrated PHS | Excluded and blocked identities remain inspectable |
| Anti-vacuity invariant | PHS v1.2 formalization | Binder-integrated PHS | Presence and declaration do not substitute for enforcement |
| Observer-artifact non-occlusion | PHS v1.2 formalization | Binder-integrated PHS | Observation mechanism may not hide observed event |
| Currentness-at-the-act | PHS v1.2 formalization | Binder-integrated PHS | Re-test mutable capability claims when action depends on them |
| Honest-negative carriage | PHS v1.2 formalization | Binder-integrated PHS | Not-run, held, fixture-only, and simulation-only remain results |
| Forge FIELD/DENT implementation | Downstream implementation | Prompted Forge implementation paper | Concrete profile; does not originate protocol |
Appendix F. Binder evidence map
This appendix reproduces the binder's 22 stable landmark identifiers as an evidence-navigation layer. The BND markers are not substitutes for primary receipts. They identify where a claim enters the binder's map and what role it plays in this paper. [31]
| Marker | Binder landmark | PHS relevance | Required nonclaim |
|---|---|---|---|
| BND-01 | t494 hoist covenant: 10 cables, 7 waves, 3 parallel invariants, center exclusion checked | Early executable current-to-target covenant and DAG form | Does not establish all later winch or PHS behavior |
| BND-02 | t535 live serve overturns t527 capability ruling | Currentness-at-the-act; execution may falsify assessment | Proposal-only; mutation authority remained false |
| BND-03 | 159,382-trace corpus chain with reproducing partial sums | Longitudinal receipt continuity and exact re-derivation | Corpus size is not capability, adoption, or quality |
| BND-04 | t749 first governed local-model consumption; t751 refusal and corrected lap | Refusal, correction, measured liveness, honest limits | Small sample; plumbing proven more strongly than general capability |
| BND-05 | t643 seven simultaneous office citizens; exact admitted-and-exec-ready intersection | Parallel work without admission collapse | Seven other executable but unadmitted identities remained excluded |
| BND-06 | t650 S1-S7 raised in one tic; six null-covenant identities named | DAG-of-DAGs execution and residue visibility | Named residue is not discharged work |
| BND-07 | t512 BOOM seed raise and t559 7/7 verification | Full-cradle proof with center and mutation boundaries | Early wall-clock remains absent/unverified where the binder says so |
| BND-08 | t621-623 live board compiler closes ~119-tic vacuous-green scar | Anti-vacuity and real-consumer requirement | Prior green doctrine claim was not operational proof |
| BND-09 | Typed GUNSLINGER/HIDALGO dial and membrane tests | Tempo as explicit policy rather than prose | Sniper is not a third mode |
| BND-10 | One live HIDALGO classification | Residue-shaped staged throttle exists | One event does not establish broad operational adoption |
| BND-11 | 202-tic simulated-economy GUNSLINGER run with center exclusion | Long-running tempo and anchor exercise | SimOnly is not live money or external economic effect |
| BND-12 | t568 collapse replay and first named breach flag | Invisible failure made structurally visible | Shadow replay is not proof of external economy behavior |
| BND-13 | Harpoon charter's “master” verb falsified and rechartered to “metabolize” | The mechanism survives correction of its own frame | Narrative charter is design-intent evidence, not law by itself |
| BND-14 | 161 cable receipts and 68 drain receipts | Receipt density and row-level historical continuity | Counts depend on the extract's named enumeration instant |
| BND-15 | GUNSLINGER-BACKLOG waves 1-8; every measured wave falsified lead premise | Falsification as a designed property of governed parallelism | Campaign vocabulary does not prove every wave used WinchDial code path |
| BND-16 | Horizon quiver H0-H6; detached_reproduced probe refuses unsupported rung | Decisive self-falsifying PHS construction event | Local probe did not prove remote reproduction |
| BND-17 | 213-row append-only wave ledger with provenance correction | Corrections can be appended without retconning earlier event | Some rows lack independently verified wall-clock time |
| BND-18 | t540 marker occlusion and __run__ key-space cure | Observer artifacts must not occlude observed events | Cure is specific to the recorded failure class |
| BND-19 | BR4 basin with named tensions and measured residual 0.45 | Dissonance preserved as inspectable state | One deep exercise does not prove broad drain liveness |
| BND-20 | Center exclusion enforced in three languages | Anchor-preservation doctrine-to-code chain | Multiple checks do not prove every consumer invokes them |
| BND-21 | Epoch05 “pinky”: 41 steps, 48 seconds, one branch | Repair cost shifts into prior anchor structure | Historical event does not establish universal repair economics |
| BND-22 | Rollback gate armed five times, zero refusals in 213 rows | Armed-but-not-fired is a valid evidence class | Existence and smoke tests do not equal live refusal use |
F.1 Binder use discipline
The binder instructs writers to resolve BND markers through the binder, then the lane extracts, then primary artifacts; to prefer quoted primary fields on disagreement; and to retain honest negatives and truth boundaries as load-bearing content rather than editorial caveats. [31]
This revision follows that discipline as far as the supplied materials allow. The two lane-complete extracts named by the binder were not included in the attachment set available to this drafting pass. Therefore the paper does not claim row-level independent verification of all 161 cable receipts, 68 drain receipts, 51 campaign files, 213 ledger rows, or 202 economy artifacts. Those totals remain binder-indexed claims pending direct primary-source closure.
References
[1] Prompted LLC. “Prompted LLC - Ubiquity, Context Grapple Gun, Corpus.” https://promptedllc.com/. Accessed September 4, 2026.
[2] Prompted LLC. “Prompted LLC - Governance Substrate for Sovereign Adaptive Systems.” https://promptedllc.com/prompted-llc. Accessed September 4, 2026.
[3] Prompted LLC. “Breyden Taylor - Founder, Prompted LLC.” https://promptedllc.com/founder. Accessed September 4, 2026.
[4] Prompted LLC. “Sovereign Continuity - The Root Frame for Sovereign Adaptive Systems.” https://promptedllc.com/sovereign-continuity. Accessed September 4, 2026.
[5] Taylor, B. E. (2026). FORKED - Observer-Indexed Reality, Suspension Lattices, and Mission-State Integrity (Version 2.0 foundational whitepaper). Prompted LLC. https://promptedllc.com/forked. Raw source: https://promptedllc.com/papers/forked-v2/PAPER.md.
[6] Taylor, B. E. (2026). Fractal Quivers of Quivers - A Mathematical Substrate for Ubiquitous Agent Governance. Prompted LLC. https://promptedllc.com/fractal-quivers-of-quivers.
[7] Taylor, B. E. (2026). Computing Around the Open Center: Splat Mechanics, Fractal Quivers of Quivers, and a Governance-Native Compute Paradigm (Version 1.0 preprint). Prompted LLC. https://promptedllc.com/computing-around-the-open-center.
[8] Prompted LLC. “Human Judgment in AI Systems - Reusable Structure, Not a Bottleneck.” https://promptedllc.com/human-judgment-in-ai-systems. Accessed September 4, 2026.
[9] Prompted LLC. “Context Grapple Gun - Portable Governance Lifecycle for Claude Code.” https://promptedllc.com/context-grapple-gun. Accessed September 4, 2026.
[10] Prompted LLC. “Look-First - Reattach to Canonical State Before Acting.” https://promptedllc.com/look-first. Accessed September 4, 2026.
[11] Prompted LLC. “Successor Topology - Ubiquity Canonical V2 Lineage Lock.” https://promptedllc.com/successor-topology. Accessed September 4, 2026.
[12] Prompted LLC. agents.txt - Machine-Readable Agent Interface Specification, Version 4.1, updated August 21, 2026. https://promptedllc.com/agents.txt.
[13] Prompted LLC. papers-registry.json, Schema prompted.papers-registry.v1, Version 1.3, updated July 29, 2026. https://promptedllc.com/papers-registry.json.
[14] Taylor, B. E. (2026). Proof-Horizon Sharding: Correction-Surviving, Proof-Carrying Canonical Computation (Technical Whitepaper 1.1, Ubiquity Lineage Revision). Prompted LLC. Author-provided publication candidate, September 2026.
[15] Taylor, B. E. (2026). Author-supplied GitHub Insights screenshots for forge-canonical-fed, covering Code Frequency and Pulse windows from August 1 through September 1, 2026. Unpublished operational evidence supplied with the predecessor revision.
[16] Chacon, S., and Straub, B. “Git Internals - Git Objects.” Pro Git, 2nd ed. https://git-scm.com/book/en/v2/Git-Internals-Git-Objects.
[17] Chacon, S., and Straub, B. “Git Branching - Remote Branches.” Pro Git, 2nd ed. https://git-scm.com/book/en/v2/Git-Branching-Remote-Branches.
[18] Git Project. “git-notes Documentation.” https://git-scm.com/docs/git-notes.
[19] Git Project. “git-worktree Documentation.” https://git-scm.com/docs/git-worktree.
[20] in-toto Project. “Link Attestation Predicate, Version 0.3.” https://in-toto.io/attestation/link/v0.3.
[21] SLSA. “Build Provenance, Specification Version 1.2.” https://slsa.dev/spec/v1.2/build-provenance. See also “Distributing Provenance.” https://slsa.dev/spec/v1.2/distributing-provenance.
[22] Reproducible Builds Project. “Definitions: When Is a Build Reproducible?” https://reproducible-builds.org/docs/definition/.
[23] GitHub. “Using Artifact Attestations to Establish Provenance for Builds.” https://docs.github.com/en/actions/how-tos/secure-your-work/use-artifact-attestations/use-artifact-attestations.
[24] Sigstore. “Rekor Transparency Log Overview.” https://docs.sigstore.dev/logging/overview/.
[25] IETF. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains. Supply Chain Integrity, Transparency, and Trust (SCITT), June 2026. https://www.rfc-editor.org/rfc/rfc9943.
[26] IETF. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. 2023. https://www.rfc-editor.org/rfc/rfc9334.
[27] Birkholz, H., Smith, N., Fossati, T., and Tschofenig, H. RFC 9999: Remote ATtestation procedureS (RATS) Conceptual Message Wrapper (CMW). IETF, July 2026. https://www.rfc-editor.org/rfc/rfc9999.
[28] Prompted LLC. “Why AI Approval Loops Do Not Scale.” https://promptedllc.com/why-approval-loops-do-not-scale. Accessed September 4, 2026.
[29] Prompted LLC. “Cognitive Pull Requests - Reviewable Seam for AI-Assisted Work.” https://promptedllc.com/cognitive-pull-requests. Accessed September 4, 2026.
[30] Prompted LLC. “Trust as Behavior.” https://promptedllc.com/trust-as-behavior. Accessed September 4, 2026.
[31] Prompted LLC / Ubiquity Federation. THE BINDER - A History of the Winching Machinery, with Receipts. Commissioned by Breyden E. Taylor; composed by ent_homeskillet, tic 770, September 4, 2026. Author-supplied evidence map. Stable landmarks BND-01 through BND-22. The binder declares itself a map resolving to lane extracts and primary receipts, not primary authority.
[32] ent_homeskillet-f5. “The Secret and the Lever.” Memo to Breyden E. Taylor, tic 748, August 2026. Author-supplied internal governance memo.
[33] ent_homeskillet-f5. “The Lap Ran.” Memo to Breyden E. Taylor, tic 749, August 2026. Author-supplied local-consumer execution report.
[34] ent_homeskillet-f5. “Crank 1 - Result.” Memo to Breyden E. Taylor, tic 749, August 2026. Author-supplied dry-run publication receipt summary.
[35] ent_homeskillet-f5. “Crank 2 - Staging.” Memo and correction chain to Breyden E. Taylor, tics 750-765, August-September 2026. Author-supplied exact-subject re-freezing record.
[36] Task-scoped worker, dispatched by ent_homeskillet. “T7 Inventory and Affordability - Measured Not Assumed.” Tic 748 report with tic 751 corrections, August 2026. Author-supplied read-only survey and correction record.
[37] ent_homeskillet. “State of the a0 Estate and the 16d Eval Arc.” Memo to Breyden E. Taylor, tic 738, August 26, 2026. Author-supplied state memo.
[38] Taylor, B. E. (2026). The Forge Implementation of Proof-Horizon Sharding: FIELD/DENT DAGs, Guarded Convergence, and Recursive Checkpointing at Agentic Production Scale (Technical Whitepaper 1.0). Prompted LLC and Prompted Forge. Downstream implementation paper.
Acknowledgment
AI systems assisted with context compilation, source inspection, diagram production, editorial synthesis, citation checking, and document production under Breyden E. Taylor's author-defined problem frame, Ubiquity lineage, apophatic perimeter, evidence hierarchy, and protocol constraints.
THE BINDER was composed by ent_homeskillet from two miner-citizen evidence extractions. This paper preserves the binder's own source ceiling: it uses the binder as a navigation and synthesis layer, does not silently promote its summaries to primary receipts, and names the missing lane extracts as open evidence closure.
The authorship, architecture, governing relations, claim boundaries, acceptance criteria, and final publication authority belong to Breyden E. Taylor. Prompted LLC is the publication and rights context for this foundational protocol paper.