Proof-Horizon Sharding

    Correction-Surviving, Proof-Carrying Canonical Computation

    Breyden E. Taylor · Technical whitepaper 1.2 · September 2026

    Publication, lineage, and evidence notice

    A temporal evidence protocol for parallel verification without parallel authority.

    Copyright (c) 2026 Prompted LLC. All rights reserved.

    Recommended citation. Taylor, B. E. (2026). Proof-Horizon Sharding: Correction-Surviving, Proof-Carrying Canonical Computation (Technical Whitepaper 1.2, Binder-Integrated Foundational Revision). Prompted LLC.

    Document status. This manuscript is the v1.2 publication candidate. It is a from-the-top rewrite of the foundational protocol paper using the lineage-corrected v1.1 paper, the Prompted LLC public corpus, and THE BINDER - a history of the winching machinery, with receipts. Once admitted by Prompted LLC, v1.2 supersedes the architectural and origin framing of v1.1; v1.1 and v1.0 remain lineage, not current authority. [14] This is a technical disclosure and architecture paper, not a patent opinion or claim-construction document.

    Publication order. This is the originating protocol and invention paper. The Forge Implementation of Proof-Horizon Sharding is a downstream implementation paper. Its current v1.0 cites PHS v1.1, the immediate predecessor of this revision. The Forge paper does not originate the protocol, and nothing in this revision transfers the protocol's authorship or Prompted LLC lineage to the implementation company. [38]

    Core claim. Proof topology should follow epistemic dependency, not workspace topology. Many humans, agents, machines, clones, repositories, and organizations may inspect and prove an evolving system in parallel, while one serial authority advances what the system accepts as canonical.

    Lineage statement. The broader governed-horizon primitive is inherited from Breyden E. Taylor's Ubiquity architecture at Prompted LLC and its FORKED estate. Proof-Horizon Sharding does not claim to originate horizon geometry. Its distinct contribution is the temporal-evidentiary specialization of horizon noncollapse: the earliest horizon at which a fact can lawfully become knowable becomes the sharding key for proof. From that rule follow exact subject binding, orthogonal proof fan-out, zero-authority verification lanes, governed convergence, descendant evidence carriage, recursive carrier proof, serial canonical admission, correction-surviving lineage, and deterministic re-entry. [1-13]

    Binder evidence posture. THE BINDER is an evidence map, not the primary source of the facts it indexes. Its stable BND-01 through BND-22 markers resolve onward to two lane-complete extracts and then to primary charters, code, receipts, ledgers, and git observations. This paper retains those markers so a reader can traverse the evidence chain, but it does not promote the binder's summaries into a stronger source class than the binder itself declares. When a primary artifact and a summary disagree, the primary artifact governs. [31]

    Revision 1.2

    Version 1.2 makes eight material corrections and extensions.

    1. It retains the proper intellectual lineage from Prompted LLC and Ubiquity through Fractal Quivers of Quivers, Computing Around the Open Center, and FORKED to PHS.
    1. It distinguishes the upstream invention of governed horizon geometry and horizon noncollapse from the PHS-native use of lawful knowability as an evidence partition key.
    1. It reconstructs the operational prehistory of PHS through the covenant, strike, cable, board, winch, basin, and anchor machinery documented by THE BINDER.
    1. It makes explicit that those mechanisms are one recurrent current-to-target loop with different roles, not a loose vocabulary and not all synonyms for PHS.
    1. It identifies the tic-768-to-770 horizon-quiver build as a decisive self-falsifying construction event: a probe named for detached reproduction correctly failed to claim that rung because no remote contact occurred. [BND-16]
    1. It expands the protocol invariants with anchor preservation, residue visibility, anti-vacuity, observer-artifact non-occlusion, currentness-at-the-act, and honest-negative carriage.
    1. It integrates a fuller lived falsification history - capability verdicts overturned by execution, vacuous-green defects, marker occlusion, append-only correction, exact subject re-freezing, first local model consumption, and lead-premise falsification across every campaign wave - without converting operational evidence into universal proof. [BND-02, BND-04, BND-08, BND-15, BND-17, BND-18]
    1. It preserves the binder's negative findings as load-bearing results: fixture-green is not live-fired; the economy remains SimOnly; basin_drained has not fired live; the rollback refusal path has been armed but not needed; and the campaign's use of winch vocabulary does not prove every wave traversed the WinchDial implementation. [BND-11, BND-22, 31]

    Contents

    Main sectionsContinuation and appendices
    Abstract12. Git reference realization
    Executive statement13. Failure semantics and correction survival
    1. Introduction: assurance after comprehension scale14. Agentic systems and winch tempos
    2. Lineage, inheritance, and attribution15. Operational emergence and lived falsification
    3. One loop wearing many mechanism names16. Honest negatives and truth boundaries
    4. The horizon-quiver construction event17. Relationship to the Ubiquity corpus
    5. The temporal self-attestation problem18. Relationship to adjacent technical work
    6. Design thesis19. Origin, attribution, and invention method
    7. Formal protocol model20. Limitations and open work
    8. Reference epoch21. Conclusion
    9. Protocol invariantsAppendix A. Protocol pseudocode
    10. Receipt, carrier, basin, and ledger modelAppendix B. Reference receipt schema
    11. DAGs, quivers, and governed checkpoint historyAppendix C. Conformance checklist
    Appendix D. Selected glossary
    Appendix E. Lineage and claim register
    Appendix F. Binder evidence map
    References and acknowledgment

    Abstract

    Modern software and agentic systems can generate, inspect, test, and distribute change through many concurrent actors. Their assurance models, however, frequently collapse several different facts into one status such as green, pushed, released, wired, live, or done. A source artifact may exist locally without being available from an intended remote. A push may report success without an independent readback. A test may pass only because the authoring machine contains untracked state. A fixture may be green while no live call site invokes it. A receipt may describe its predecessor accurately while being unable to prove its own later propagation. A named probe may imply a proof rung that its evidence never reached. When these distinctions are erased, the system permits artifacts to imply knowledge, execution, authority, or effect beyond what they could lawfully establish.

    Proof-Horizon Sharding (PHS) is a checkpoint protocol derived within the Ubiquity governance substrate and from the horizon-noncollapse doctrine expressed in FORKED. Prompted LLC defines Ubiquity as a governance substrate for sovereign adaptive systems: AI-mediated systems intended to increase capacity without collapsing agency, authorship, judgment, or meaningful contribution. Fractal Quivers of Quivers supplies a living topology of lawful and forbidden motion. Computing Around the Open Center supplies bounded, receipt-bearing splat computation around a center that is held open rather than crowned. FORKED is an estate inside that parent substrate and makes governed horizon geometry explicit: task, mission, battle, campaign, war, institutional, and other scales retain distinct telos, authority, standing, success and failure conditions, externalities, and irreversible surfaces. A declaration at one horizon does not silently acquire authority at another. [1-7]

    PHS specializes that inherited horizon primitive to evidence through time. It partitions verification according to the earliest horizon at which each claim can lawfully become knowable. Canonical mutation remains serial. Verification fans out across zero-authority proof lanes over one immutable subject. Independent observations converge into a descendant receipt or state carrier. That carrier then becomes a new proof subject, preventing it from certifying its own future. Synchronized repositories and refs function as projections of canon rather than parallel canonical authorities.

    This revision also reconstructs the operating machinery in which the protocol became visible. The binder records one recurrent current-to-target loop wearing several mechanism names: a covenant binds the pull; a six-ray Harpoon strike produces the thing's shape; cables route bounded tension around a frozen center; a board compiles admitted covenants into a DAG; a winch raises only admitted and executable cables at one of two tempos; dissonance basins preserve unresolved tension and residue; anchoring keeps the reference frame outside the ordinary node set; and receipts carry what happened forward without laundering it into a stronger horizon. [BND-01, BND-05, BND-09, BND-13, BND-17, BND-20]

    The machinery and the protocol are related but not identical. Current-to-target reality winching is the broader operating motion. PHS is the temporal evidence law governing what may be claimed about that motion and when. The decisive construction event came when the horizon-quiver build disciplined its own attractive name: a probe called detached_reproduced had made no remote contact, so its receipts correctly remained at source_admitted rank zero. The apparatus proved that coherence, naming, and local execution do not constitute admission to a stronger proof horizon. [BND-16]

    The resulting primitive is correction-surviving, proof-carrying canonical computation: distributed execution, verification, custody, and falsification can scale independently while accepted state remains temporally honest, reproducible, auditable, correction-bearing, and deterministically resumable. Git is the reference realization, not the boundary of the method. The same geometry can govern any substrate with strongly identified subjects, ordered successor state, independently observable proof surfaces, durable receipts, explicit authority ceilings, visible residue, and governed convergence.

    Keywords: Ubiquity; Prompted LLC; FORKED; horizon noncollapse; Proof-Horizon Sharding; lawful knowability; current-to-target reality winching; covenant; Harpoon; cables; DAG; GUNSLINGER; HIDALGO; dissonance basin; anchor; proof-carrying computation; correction survival; provenance; serial authority; sovereign continuity.

    Executive statement

    PHS is the temporal evidence law of governed winching: many cables may pull in parallel, but no cable may crown the center, no observer may silently become the authority, and no artifact may claim a future it could not yet know.

    The production problem has changed. AI systems can generate coherent candidate surfaces faster than a human or conventional review team can inspect every line. That does not eliminate human judgment. It changes where judgment must enter. Permanent per-action approval becomes a bottleneck, a rubber stamp, or a blind spot at production throughput. Prompted LLC's Ubiquity architecture therefore treats human judgment as reusable structure: corrections, refusals, approvals, exceptions, rollbacks, and observed outcomes become evidence that can be carried forward instead of being re-asked in every session. [1,4,8,28]

    The harder problem is not simply whether a model can act. It is whether the surrounding system can preserve the difference between a plausible candidate and admitted state; between a named capability and a live one; between a fixture and a wired call site; between a local test and independent reproduction; between a receipt and proof of the receipt carrier; between a repository checkpoint and a real-world effect.

    The parent matters. Ubiquity is the constitutional governance substrate. Fractal Quivers of Quivers supplies living responsibility topology. Computing Around the Open Center supplies the bounded local compute object and the held-open center. FORKED specializes these mechanics around observer-indexed reality, suspension, correction, declaration, and horizon integrity. PHS specializes them again along the temporal-evidentiary axis. The relationship is inheritance, not renaming. [5-7]

    The operating machinery matters too. The binder's central finding is not that Forge accumulated a colorful lexicon. It is that covenant, strike, cable, board, winch, basin, and anchor are roles inside one recurrent loop. A current state is bound to a target under a covenant. Harpoon strikes the proposal through multiple rays rather than accepting its first fluent shape. Cables carry bounded work and contradiction. The board compiles only admitted covenants into executable dependencies. The winch chooses a tempo without changing the proof law. Basins hold unresolved tension rather than erasing it. Anchoring keeps telos and center-exclusion load-bearing without turning them into ordinary work nodes. Receipts preserve the work, the limits, the failures, and the next edge. [31]

    The central refusal remains simple:

    No immutable artifact may be treated as evidence of an event that had not occurred when the artifact was created.

    A source-bearing commit can establish that exact source bytes exist. It cannot establish its own later remote propagation. A remote readback can establish that an intended ref exposes the exact subject. It cannot establish independent reproduction. A clean clone can establish acquisition and a declared validation predicate. It cannot establish deployment, adoption, or outcome. A descendant carrier can preserve those observations. It cannot certify its own later propagation. Every stronger claim requires a later lawful edge.

    This refusal produces a complete control law:

    bounded candidate / covenant
    -> shape-producing strike
    -> immutable source subject
    -> parallel orthogonal proof cables
    -> governed join
    -> descendant receipt carrier
    -> carrier becomes next proof subject
    -> terminal reconciliation
    -> one serial canonical admission path

    The protocol does not ask one human to read everything. It scales bounded falsification. Many proof workers may inspect the same fixed subject through different failure surfaces. None gains canonical admission authority merely by producing a receipt. Their observations converge only under a declared closure predicate. Evidence classes remain distinct. Failures remain bound to the subjects that failed. Corrections produce new subjects instead of rewriting history. A successor resumes from the first missing proof edge rather than reconstructing intent from a vanished context window.

    The binder's strongest operational result is therefore not raw throughput. It is that the apparatus repeatedly falsified its own premises and survived. A prior capability wall was overturned by live execution. A false board-wiring claim survived approximately 119 tics and was cured only when a real eater exposed two mutually concealing defects. A telemetry marker suppressed a receipt and forced a distinct run-key space. An append-only ledger recorded a true automatic fire while declaring earlier attestations false. Every measured GUNSLINGER campaign wave falsified at least part of the lead premise. The horizon-quiver probe refused the rung promised by its own name. [BND-02, BND-08, BND-15, BND-16, BND-17, BND-18]

    That is not incidental quality assurance. It is the operating proof of the governing direction: a system scales safely not when it stops contradicting itself, but when contradiction remains visible, attributable, recoverable, and capable of changing the next trajectory without silently multiplying authority.

    This is the capability PHS enables:

    Distributed execution, verification, custody, and challenge can scale independently while canonical state remains serial, temporally honest, reproducible, correction-bearing, and deterministically resumable.
    Figure 1. Intellectual and architectural lineage. PHS inherits Ubiquity's constitutional substrate and specializes FORKED's horizon-noncollapse doctrine along the temporal-evidentiary axis.
    Figure 1. Intellectual and architectural lineage. PHS inherits Ubiquity's constitutional substrate and specializes FORKED's horizon-noncollapse doctrine along the temporal-evidentiary axis.

    1. Introduction: assurance after comprehension scale

    1.1 Production has crossed the diff-comprehension boundary

    The dominant coordination problem in high-velocity software is no longer merely how to produce change. It is how to preserve a trustworthy distinction between what has been proposed, what exists, what has been distributed, what has been independently reproduced, what has been admitted, what has been deployed, and what has actually affected the world.

    That problem becomes acute when artificial intelligence increases the number and speed of candidate implementations. A model can generate a large and internally coherent source surface in minutes. Other models can review, test, summarize, refactor, or extend it. Yet coherence of output is not evidence of correctness, and multiplicity of reviewers is not a governance model. If every agent can update the state that later agents treat as true, horizontal intelligence scaling becomes horizontal authority scaling. The result is divergent state, ambiguous custody, and reconciliation work that can grow faster than the work itself.

    Conventional workflows usually answer this pressure in one of two ways. They serialize most activity to preserve consistency, sacrificing throughput; or they parallelize activity through branches, worktrees, repositories, CI jobs, and agents, then attempt to reconstruct one story after the fact. Both approaches tend to conflate where work occurs with when claims about that work become supportable.

    PHS separates those dimensions. Its central rule is:

    Shard proof by temporal attainability and evidentiary scope, not by workspace, actor, branch, or repository.

    A source-bearing subject is first made immutable or strongly identified. Proof lanes then inspect that same subject through different failure surfaces. A direct remote-ref readback answers whether intended distribution surfaces expose the exact subject. An independently acquired clean clone answers whether another environment can acquire and validate it without inheriting the authoring machine's residue. A security review, schema check, lineage inspection, or provider readback may form additional proof lanes. The observations join only after their own predicates pass.

    The join produces a later carrier because the source cannot contain evidence of events that occurred after the source existed. The carrier then becomes the next subject because it cannot contain evidence of its own future either. This recursion is not ceremony. It is the architecture forced by causal order.

    1.2 The problem is larger than software supply chains

    Software supply-chain systems already recognize that identity, provenance, and attestations matter. PHS addresses a more general governance question: which object may lawfully carry which observation, under whose authority, at what horizon, and with what explicit nonclaims?

    The same problem appears when a database migration package is staged, applied, read back, and then audited; when an infrastructure plan is signed, executed, and independently inspected; when a model release is registered, reproduced, evaluated, deployed, and accepted; when a policy is published, signed, implemented, and observed; or when an autonomous mandate generates effects beyond its source repository.

    In each case, a status such as done is a lossy compression of several events. PHS replaces the status with a proof topology.

    1.3 The operational discovery problem

    The abstract protocol did not arise from a desire to add more gates to Git. It emerged inside a broader operating system that was already attempting to move complex current states toward bounded targets while preserving agency, center-exclusion, correction, and evidence.

    THE BINDER describes that system as one loop wearing many mechanism names. The loop had covenants before it had a PHS specification; Harpoon strikes before a proof-horizon schema; cable receipts before a generalized carrier model; winch modes before the protocol's observer-scaling proposition; append-only corrections before the formal correction-conservation result; and a living distinction between quivers and DAGs before PHS named its three-graph checkpoint history. [31]

    This matters for two reasons.

    First, it prevents a false origin story in which a complete protocol appeared fully formed from a single repository inconvenience. The protocol was progressively forced by recurring constraints: no self-attestation, no coherence-as-admission, no fixture-as-liveness, no stale capability wall, no invisible residue, no observer artifact occluding the observed, no projection-as-authority, and no silent promotion of one horizon into another.

    Second, it shows what kind of evidence should count when assessing the protocol. A clean conceptual diagram is not enough. The stronger evidence is an apparatus that repeatedly catches itself overclaiming, preserves the resulting scars, and becomes more capable because those contradictions change its structure.

    1.4 Contributions

    This paper makes ten contributions.

    1. It places PHS in the correct Prompted LLC and Ubiquity lineage and preserves FORKED as the upstream origin of governed horizon geometry and horizon noncollapse.
    1. It identifies the temporal self-attestation problem: an immutable artifact cannot truthfully carry observations about events that occur only after the artifact exists.
    1. It defines the earliest horizon of lawful knowability as the partition key for checkpoint evidence.
    1. It introduces fixed-subject orthogonal proof fan-out while retaining one serial canonical admission path.
    1. It defines zero-authority proof lanes, governed joins, descendant evidence carriers, and recursive carrier checkpoints.
    1. It distinguishes synchronized projection, execution, proof, and possession from canonical authority.
    1. It derives correction conservation, visible residue, anti-vacuity, deterministic re-entry, and observer scaling from the same control law.
    1. It reconstructs the covenant-strike-cable-board-winch-basin-anchor machinery as the operational discovery apparatus from which PHS was abstracted.
    1. It uses the horizon-quiver self-falsification as a concrete demonstration that a proof instrument's name, local shape, or implementation status cannot exceed its evidence horizon.
    1. It preserves honest negatives and source-tense distinctions as positive protocol results rather than relegating them to disclaimers.

    The deepest result is not a better release checklist. It is the ability to coordinate broad parallel reasoning and execution around a bounded serial truth path while leaving contradiction visible enough to improve the system.

    2. Lineage, inheritance, and attribution

    2.1 Prompted LLC and the Ubiquity parent

    Prompted LLC describes Ubiquity as the governance substrate for sovereign adaptive systems: AI-mediated systems that can increase capacity without collapsing agency, authorship, judgment, or meaningful contribution. Sovereign continuity is the non-collapse condition - the human architect remains meaningfully causal as the system becomes more capable, more automated, and more dependent on accumulated machine action. [1-4]

    PHS inherits that constitutional direction. It does not define Ubiquity and cannot claim the parent substrate as a PHS-only invention. Its concern is narrower: how evidence about changing state can be produced in parallel without letting proof production silently become canonical authority.

    The distinction matters because scaling proof workers is useful only if the resulting system still preserves authorship and judgment. A protocol that improves verification throughput by replacing human authority with an opaque automated consensus would solve a different problem. PHS instead allows broad observation while keeping admission singular, inspectable, and successor-capable.

    2.2 Fractal Quivers of Quivers and lawful motion

    Fractal Quivers of Quivers supplies a mathematical substrate for living responsibility topology. A normal directed graph records vertices and edges. A governed quiver additionally carries edge types, costs, anchors, forbidden paths, standing, authority, receipts, telos, correction paths, and an open-center marker. The object is not merely what transitions are technically reachable; it is which transitions are lawful in a particular context and why. [6]

    This parent matters to PHS in three ways.

    First, a proof relation is a typed edge, not a floating sentence. It binds a subject, predicate, observer, method, result, horizon, authority ceiling, and convergence target.

    Second, a proof graph can recur. The same subject may be inspected by different actors, corrected, re-observed, or revisited after new evidence. That living recurrence is not itself an execution schedule.

    Third, receipts are part of the topology. They do not merely decorate completed work. They determine which downstream paths are lawfully open.

    2.3 Computing Around the Open Center and splat mechanics

    Computing Around the Open Center extends the quiver substrate into bounded local computation. A splat gathers the facets, exclusions, receipts, dependencies, hypotheses, unresolved state, and working centroids needed for one local decision while keeping the center open. The center is not indecision. It is an anti-capture condition: local coordinates may guide action without becoming universal truth. [7]

    PHS inherits the same discipline. Every checkpoint is bounded by a declared subject, claim class, environment, and closure predicate. A successful repository checkpoint is not the center of the whole system and does not automatically become deployment, adoption, or outcome truth. The proof carrier can close one branch while stronger horizons remain open.

    2.4 FORKED and governed horizon geometry

    FORKED is an estate inside Ubiquity. It specializes the parent architecture around observer-indexed reality, suspension, declaration, correction, mission-state integrity, and responsibility-shaped validation. Its horizon geometry stores task, mission, battle, campaign, war, institutional, and other scales as separate splats and quivers with distinct telos, authority, standing, time, success definitions, failure definitions, resource envelopes, acceptable loss, observer geometry, irreversible surfaces, dependencies, and conflicts. [5]

    The governing rule is horizon noncollapse:

    A declaration at horizon h1 does not acquire authority at horizon h2
    without an admitted, typed cross-horizon edge.

    Task success may coexist with mission failure. A local component may be green while the end-to-end system is unwired. A repository may be synchronized while a provider is unchanged. A model may produce a valid proposal while retaining zero mutation authority. A deployment may be live while outcome remains unmeasured.

    PHS is a direct temporal-evidentiary specialization of this rule. A claim established at source horizon does not become a distribution claim. Distribution does not become reproduction. Reproduction does not become deployment. Deployment does not become adoption. Adoption does not become outcome.

    2.5 The winching machinery is an operational lineage, not a constitutional parent

    The binder documents covenant, Harpoon, cables, boards, DAGs, winches, GUNSLINGER, HIDALGO, dissonance basins, and anchoring. Several of those mechanics also appear in FORKED's suspension lattice. The relation must be stated carefully.

    The broader Ubiquity/FORKED papers establish the constitutional and horizon lineage. The binder establishes a lived operating lineage in which those ideas were exercised, corrected, coded, and measured. The binder does not outrank the public parent papers, and the mechanisms it maps are not all PHS-native.

    PHS emerges where two lineages meet. Ubiquity, Fractal Quivers of Quivers, Computing Around the Open Center, and FORKED supply the constitutional and horizon law. Covenant, Harpoon, cable, board, winch, basin, and anchor supply the operating and falsification machinery. Their conjunction yields the PHS temporal-evidence protocol; neither lineage is erased by the synthesis.

    2.6 Canonical attribution and claim boundary

    Breyden E. Taylor designed Proof-Horizon Sharding at Prompted LLC. The paper's native invention is not the word horizon, the existence of DAGs, Git commits, remote refs, clean clones, attestations, receipts, or single-writer systems considered separately.

    The native contribution is the composition forced by lawful knowability:

    exact immutable subject
    -> orthogonal proof fan-out
    -> zero-authority observers
    -> governed join
    -> descendant evidence carrier
    -> recursive carrier checkpoint
    -> serial canonical admission
    -> correction-conserving, finite re-entry

    The broader governed-horizon invention remains upstream in Taylor's Ubiquity architecture and FORKED. The operating machinery documented in the binder is part of the invention method and implementation lineage. It does not alter the authorship or organizational attribution of the protocol paper.

    3. One loop wearing many mechanism names

    3.1 The machinery is one recurrent motion

    The binder's most important synthesis is its shortest: the machinery is one loop wearing many mechanism names. [31]

    current reality
    -> covenant
    -> strike
    -> cables
    -> board / DAG
    -> winch
    -> receipts and residue
    -> admitted successor or held state
    -> new current reality

    Each mechanism exists because the loop must answer a different question.

    • The covenant answers what bounded current-to-target pull is being undertaken and under what nonclaims.
    • The strike answers what shape the proposed thing takes after adversarial interpretation rather than first-pass fluency.
    • The cables answer which bounded responsibilities, contradictions, and proof surfaces must carry tension.
    • The board answers which admitted covenants compile into an executable dependency graph.
    • The winch answers how ready cables are raised through time.
    • The basin answers where unresolved tension and residue remain visible during motion.
    • The anchor answers what reference frame and exclusions must survive the motion.
    • The receipt carrier answers how what happened becomes durable without claiming more than was observed.

    PHS is not another synonym in this list. It is the law that governs the temporal evidence produced around the loop.

    Figure 2. The operating loop reconstructed from THE BINDER. Covenant, strike, cables, board, winch, basin, anchor, and receipts are distinct roles inside one recurrent current-to-target motion.
    Figure 2. The operating loop reconstructed from THE BINDER. Covenant, strike, cables, board, winch, basin, anchor, and receipts are distinct roles inside one recurrent current-to-target motion.

    3.2 Covenant: bind the pull before execution

    A covenant binds a current state to a target under an explicit scope, authority ceiling, admission condition, and set of nonclaims. It prevents an attractive target from silently becoming permission to move toward it by any available means.

    The tic-494 hoist covenant is the binder's first large instance: ten cables, seven waves, and three parallel invariants assembled by reusing an existing compiler. The founding telos remained a non-node. center_exclusion: GO was a compiler check, not prose ornament. [BND-01]

    This is structurally adjacent to PHS H0. Both begin by refusing to confuse a candidate with an admitted subject. The covenant declares the pull. H0 determines whether that pull is rejected, held, corrected, or eligible to become a source-bearing subject.

    The relation is not identity. A covenant may govern a broader current-to-target campaign containing many PHS epochs. A PHS epoch may also be instantiated without adopting the whole Ubiquity covenant vocabulary. The invariant is the same: intention does not confer admission.

    3.3 Strike: produce shape by falsification

    Harpoonv2 is the shape-producing strike lane. Its six-ray council does not begin from the assumption that a proposal's own account is the thing. It examines affirmative structure, forbidden collapse, neighboring interpretations, concrete coordinates, failure forms, and telos. The strike is therefore a disciplined way to produce a bounded object that can be admitted, rejected, or held.

    The office's founding scar is load-bearing. Its original verb, master DAG-of-DAGs, was falsified by a blind arena and rechartered as metabolize, not master. The office survived the falsification of its own name at inception. [BND-13]

    That event matters to PHS because it demonstrates the difference between a label and a lawful claim. A name is a proposal about identity. It gains standing only when the system can preserve what the thing does, what it excludes, and what evidence supports the name.

    The horizon-quiver event later repeated the same pattern at a sharper technical boundary: the name detached_reproduced was not allowed to outrun the absence of remote contact. [BND-16]

    3.4 Cables: route bounded tension and responsibility

    A cable is a bounded responsibility carrier. It may represent implementation work, a proof predicate, an invariant, a correction, a dependency, or a review obligation. The cable metaphor matters because the system is not trying to eliminate tension before movement. It is trying to route tension in a way that preserves the center and makes each pull accountable.

    PHS proof shards are cable-like but narrower. A proof shard is an independently executable predicate over one exact subject. It carries observation authority and produces a receipt. It does not gain admission authority.

    The binder's cable history is substantial: 161 cable receipts from tics 498 through 769, plus 68 drain receipts, enumerated row by row in the referenced extract. [BND-14] Those counts do not by themselves establish protocol conformance. They establish that the operating lineage was already receipt-bearing and that the proof topology was not invented as an after-the-fact documentation convention.

    3.5 Board and DAG: compile only admitted work

    The board is the compilation surface between covenant and execution. It determines which bounded objects are admitted, which are executable, which dependencies must precede others, which identities remain residue, and which joins are required.

    At tic 643, seven office citizens fired simultaneously, one per cable, with disjoint write surfaces. The admitted set intersected the executable set at exactly seven of seven. Seven additional identities that appeared executable but lacked admitted covenants were deliberately excluded. This is coherence-is-not-admission enforced as a set operation. [BND-05]

    At tic 650, the S1-to-S7 covenant chain was planned, simulated with zero live side effects, and fired inside one tic. Seven work cables were dispatched, three invariants asserted, and six null-covenant identities were named as residue rather than silently dropped. [BND-06]

    The board's largest negative lesson came from the vacuous-green scar. For approximately 119 tics, a doctrine claim that the engine read the board survived behind two mutually concealing defects. The first real eater found the gap. The repair changed missing state from an implicit executable default into a visible non-executable condition and closed a fail-open exec_ready defect. [BND-08]

    PHS inherits the anti-vacuity consequence: a proof surface that exists but has no real consumer, a validator that is not wired to a call site, or a status that defaults green on missing state cannot close a horizon.

    3.6 Winch: choose tempo without changing truth

    The winch raises admitted, executable cables. Its two typed detents are GUNSLINGER and HIDALGO. [BND-09]

    GUNSLINGER raises all currently admitted and executable cables under one shared cradle. It is the maximum lawful parallelism of the bounded set, not permission for unbounded mutation.

    HIDALGO stages the raise. It is a throttle selected by residue shape, dependency pressure, reversibility, or uncertainty. It is not the default and not a lesser proof standard.

    The typed dial matters because tempo and evidence are orthogonal. A GUNSLINGER raise may execute many cables at once, but every receipt remains bound to its exact subject and claim class. A HIDALGO raise may be slower, but it does not automatically produce stronger evidence. PHS remains the same under either tempo.

    The binder identifies only one live HIDALGO classification in the whole ledger: hidalgo:A=1:B=6:C=0:D=0, judged clean by residue shape at tic 575. [BND-10] That rarity is evidence about use, not evidence that the detent is fictitious.

    The term sniper is not a third winch mode. The binder's search found three distinct referents - a precision/range band of the gunslinger figure, an unrelated covenant nickname, and an incidental constant comment - with no publication hits. It belongs to register and precision vocabulary, not the mechanism family. [31]

    3.7 Dissonance basins: preserve tension and residue

    The binder distinguishes two mechanics that share the word basin and must not be collapsed.

    DissonanceBasin is a tension reservoir. It holds dissonance during the cradle and permits some of it to be drained into useful motion while retaining residual tension as compounding information. A drain does not reduce the system to false harmony.

    held_basin is a graph-state mechanism. It keeps a gated, blocked, or excluded identity visible in the lattice instead of dropping it from the account.

    PHS does not require these exact classes, but it requires their truth function: unresolved state must remain represented. A failed or held proof shard is not absence. A residue identity is not silently removed from the denominator. A join is not lawful merely because only passing lanes were counted.

    The braid-covenant BR4 packet is the binder's deepest recorded live basin exercise: named tensions trust_below_tau, mint_halted, and harmony:unresolved:1, with measured residual 0.45 and a 48-of-48 lattice test. [BND-19]

    The honest boundary is equally important. basin_drained has not fired as a live event in the 213-row ledger. One apparent drain is orchestrator prose inside a cradle_stable row, and the live-fire code path keeps the guard false by construction. The basin is therefore a law with one deep live exercise and an ambient economic presence; its drain path is designed and smoke-tested, not live-proven. [31]

    3.8 Anchor and center exclusion

    Anchoring is the reference frame that lets the system move without replacing its telos with whatever the current optimization can most easily maximize.

    The center is not an executable node. It is not a hidden ruler or a single scalar objective. It is the excluded reference sort around which lawful motion is measured. In the originating implementation, center exclusion was enforced by a compiler check, a winch membrane assertion, and a TypeScript substrate-physics clause. The binder traces the doctrine-to-code line from the tic-414 statement that the strike drains the basin while retaining tension to residual_fraction = 0.15 in the winch implementation. [BND-20]

    PHS uses a narrower version of the same discipline. The protocol's center is the declared canonical and evidentiary boundary: no proof worker can crown itself the canonical writer; no local observation becomes universal truth; no closed branch silently closes a stronger domain.

    The epoch05 pinky is the binder's anchor-economics result. Meaning was recovered above baseline in 41 steps, 48 seconds, and one branch because the anchor, forbidden region, gate, and receipt structure already existed. The cost lived in the anchor, not the repair. [BND-21]

    3.9 Receipt: carry the motion without laundering it

    Receipts make the loop durable. They bind an observation to a subject, method, result, limit, and next edge. The binder's append-only wave ledger contains 213 rows across 22 tics. Its tic-701 correction recorded the first true automatic pawl fire while declaring earlier attestations false in the same append-only medium. [BND-17]

    That is the operational ancestor of PHS correction conservation. Later evidence may correct a prior claim without editing the prior subject into a history in which the error never occurred.

    The loop therefore ends neither in erasure nor in permanent closure. It ends in one of three bounded states:

    1. a lawful successor is admitted;
    1. the pull is held with residue and next conditions visible;
    1. the declared scope reaches a quiet point while stronger horizons remain open.

    4. The horizon-quiver construction event

    4.1 Why this event matters

    The binder's most direct PHS evidence is BND-16: the horizon quiver built across tics 768 through 770. It is not the origin of the broader horizon concept; FORKED already supplied horizon geometry and noncollapse. It is the clearest recorded construction in which that inherited concept was specialized into an executable evidence ladder and then forced to obey its own ceiling.

    The sequence was:

    sibling-estate thesis
    -> admitted as an object under FIELD / no-cite posture
    -> six-ray strike
    -> 16-row crosswalk
    -> covenant re-expression H0-H6
    -> H1 build: 43 arms, 13/13 nonclaims, deliberately unwired
    -> H2 || H3 || H4 consumers in one tic
    -> self-falsifying detached-reproduction probe
    -> fail-closed evidence rank
    Figure 3. The tic-768-to-770 horizon-quiver construction event. The instrument's own name was subordinated to the evidence it actually obtained.
    Figure 3. The tic-768-to-770 horizon-quiver construction event. The instrument's own name was subordinated to the evidence it actually obtained.

    4.2 Admission before inheritance

    The source thesis entered as an object, not as law. Its posture was FIELD/no-cite: inspect the thesis, preserve its identity, map its claims, and do not let its attractive coherence or external vocabulary acquire constitutional standing by default.

    That move is a concrete instance of Look-First and successor topology. A source may be useful as a takeoff surface without becoming an ancestor, sovereign, or authority. Its exact contribution is carried at the artifact edge. Standing does not transfer merely because the system learned from it. [10,11]

    4.3 The six-ray strike and crosswalk

    The six-ray strike produced a bounded shape rather than a summary. The 16-row crosswalk mapped proposed claims to proof horizons, evidence surfaces, consumers, ceilings, and nonclaims. The resulting H0-to-H6 covenant was therefore not simply a renamed copy of the sibling thesis. It was a governed re-expression.

    H1 produced 43 arms and passed all 13 nonclaims, yet remained deliberately unwired. This is a positive result. It proves that the system could materialize the shape without pretending that component presence meant live consumption.

    4.4 The name that failed its own proof

    The sharpest result came from the probe named detached_reproduced. Its name suggested that detached reproduction had occurred. The proof lane made no remote contact. Therefore it could not establish the rung promised by its identifier.

    The implementation did not soften the discrepancy by saying the code was basically equivalent, that a local detached state was close enough, or that the name expressed future intent. Its receipts were typed at source_admitted, rank zero. The evidence ceiling held fail-closed. [BND-16]

    This event compresses the PHS thesis into one lived test:

    identifier coherence
    + local implementation
    + green fixtures
    + intended semantics
    != detached reproduction proof

    The name was not edited into truth. The proof class remained bounded by what actually happened.

    4.5 The construction as a protocol experiment

    The horizon-quiver build is best read as a protocol experiment with four findings.

    First, proof horizons are operationally separable. H1 can be present and green while H2-to-H4 remain unwired or bounded.

    Second, a proof instrument is subject to the same law it enforces. The probe cannot use its own name as evidence.

    Third, nonclaims are executable structure. Thirteen of thirteen nonclaims passed before the higher consumers existed.

    Fourth, coherence is not admission. The system was capable of building the appealing thesis while refusing the strongest implication of its terminology.

    That is why this event belongs in the foundational protocol paper rather than only in a Forge implementation appendix. It is the cleanest demonstration that the protocol's central refusal can govern its own embodiment.

    5. The temporal self-attestation problem

    5.1 A checkpoint is usually several events disguised as one

    A typical workflow may say that a change is complete after a commit is made, tests pass, and a push succeeds. That sentence contains several distinct events:

    • mutable source exists in a working environment;
    • the selected source is represented by an immutable or strongly identified object;
    • an exact subject identity exists;
    • a target accepts an update operation;
    • named target refs expose that exact identity;
    • another environment can acquire the identity;
    • the acquired state passes declared validations;
    • observations about those facts are durably recorded;
    • the record carrying those observations is itself distributed or reproduced;
    • an authorized process admits the checkpoint as closed;
    • a runtime, provider, database, organization, or stakeholder experiences the intended effect;
    • an outcome is observed under a declared method.

    No single event proves all the others.

    A local test does not prove remote availability. A successful push does not prove direct target readback. A local tracking ref may be stale. A detached clone does not prove deployment. A deployment readback does not prove adoption. Outcome cannot be inferred from repository state. A fixture does not prove a live caller exists. A file named for a capability does not prove the capability has run.

    5.2 Immutable artifacts cannot know their own future

    Let an immutable artifact x be created at time t(x). Let e be an event concerning x, such as remote propagation, independent acquisition, environmental reproduction, deployment, or acceptance.

    If:

    t(e) > t(x)

    then x cannot truthfully contain an observation of e as part of its original immutable content.

    For Git commits, the issue is concrete. A commit object contains a tree, parent references, author and committer fields, timestamps, and a message. Its identity is derived from the serialized object. The final identity is available only after construction. Remote propagation and independent reproduction occur later still. A source-bearing commit cannot therefore be the truthful carrier of direct observations about its own later remote state or clone reproduction. [16-19]

    A later descendant can carry those observations. But the descendant has the same limitation regarding its own future. If it is later pushed, read back, cloned, reproduced, deployed, or accepted, those observations require another later carrier or an external append-only evidence surface whose causal position is explicit.

    This is the temporal self-attestation problem:

    No immutable artifact may be treated as evidence of an event that had not occurred when the artifact was created.

    PHS does not attempt to hide or route around the boundary. It turns the boundary into the architecture.

    5.3 False closure is a category and horizon error

    Collapsed statementWhat it may establishWhat it does not establish
    CommittedSource exists in a local immutable objectRemote availability, independent acquisition, deployment
    PushedA client attempted or reported an updateDirect remote parity, clean reproduction
    CI greenDeclared checks passed in one configured environmentComplete predicate coverage, independent acquisition, outcome
    Fixture greenA test fixture or isolated component passedLive call-site wiring or live-fire behavior
    WiredA declared connection may existA consumer exercised it at the claimed time
    MirroredAnother surface may contain equivalent objects or refsEqual authority, current parity, lawful custody
    ReleasedA tag, package, or publication event occurredDeployment, adoption, business outcome
    Receipt writtenA record existsAccuracy, authenticity, carrier propagation, closure
    Named capabilityAn identifier or document asserts a roleCurrent liveness, current dependencies, current authority
    Basin armedA mechanism and test path existThe drain or refusal path has fired live

    The protocol therefore treats source, distribution, reproduction, evidence carriage, carrier proof, deployment, adoption, and outcome as separate horizons. A stronger claim requires a stronger horizon. It cannot be obtained by renaming a weaker receipt.

    5.4 Provenance is necessary and insufficient

    Provenance can establish where an artifact came from, who signed it, what inputs were recorded, or which process produced it. These are indispensable claims. They are not complete closure.

    A signed receipt may be false. A correct receipt may be signed by an actor without admission standing. A complete source-provenance record may say nothing about later target availability. A clean reproduction may say nothing about deployment. A later result may be authentic but attached to the wrong source subject.

    PHS therefore separates four questions:

    authenticity  - who or what signed the bytes?
    accuracy      - did the stated observation occur?
    independence  - what mutable state or trust roots were shared?
    authority     - what transition or claim was the actor permitted to make?

    Existing attestation and transparency standards can carry these facts. PHS specifies how their evidence must be partitioned, ordered, joined, and recursively carried. [20-27]

    6. Design thesis

    6.1 Proof topology follows epistemic dependency

    Branches, worktrees, machines, and repositories answer spatial or operational questions: where can work be performed, isolated, stored, or reproduced?

    PHS answers an epistemic question:

    When can a fact become knowable, through which independent surface, and what later object may lawfully carry it?

    These are different partition schemes. Two agents can work in separate repositories and still produce no independent evidence if both inherit the same hidden assumption. Two proof shards can run in the same repository but different independently acquired environments and establish distinct failure surfaces. One branch can contain many claim horizons. One proof horizon can involve many machines.

    The partition axis is lawful knowability.

    6.2 Horizon noncollapse becomes evidence noncollapse

    FORKED's horizon rule can be specialized as follows:

    Evidence(h1) does not imply Evidence(h2)
    unless a typed, admitted relation establishes the move.

    This produces a strict anti-laundering sequence:

    candidate != source
    source != distribution
    distribution != reproduction
    reproduction != carrier proof
    repository closure != deployment
    deployment != adoption
    adoption != outcome

    The sequence is not a universal linear maturity ladder. Different domains can branch, run concurrently, or remain inapplicable. The invariant is that no lane gains a stronger claim merely because another lane succeeded.

    6.3 Parallel assurance without parallel authority

    PHS distinguishes three powers:

    • Proposal: produce candidate state.
    • Observation: inspect an exact subject and emit a bounded receipt.
    • Admission: advance accepted canonical state.

    Many actors may propose. Many may observe. Only the designated canonical lane may admit.

    A proof worker does not need general write authority. It needs:

    exact subject
    + permitted evidence surface
    + declared proof horizon
    + predicate
    + receipt schema
    + authority ceiling
    + stop condition
    + convergence destination

    This creates a zero-authority proof lane: the worker may inspect and report but cannot silently convert its observation into accepted state. The number of observers can grow without increasing the number of canonical writers.

    6.4 Projection is not authority

    A repository, ref, cache, mirror, report, binder, natural-language rendering, or other projection may carry an exact or useful representation of canonical state. Possession of state does not confer jurisdiction to originate accepted transitions.

    PHS treats synchronized refs as canonical projections. They may be acquisition surfaces and proof targets. They may be maintained in exact parity. They do not independently decide what becomes canon.

    The same rule applies to THE BINDER. It is intentionally a map of receipts. It does not become primary authority merely because it is comprehensive or easier to read. [31]

    6.5 Evidence classes remain distinct at convergence

    Proof shards converge without being flattened. A direct remote-ref receipt and a clean-clone reproduction receipt may jointly support repository closure, but they remain different evidence types. Their subjects, methods, environments, timestamps, limitations, and failure surfaces stay visible.

    This composability matters because evidence is often weakened during summary. PHS makes summary downstream of receipts rather than a substitute for them.

    6.6 Falsification is a first-class output

    A proof lane is not valuable only when it returns pass. A failed or held result can be the most informative output if it is exact, bounded, and capable of changing the next motion.

    The binder's lead-premise falsification streak makes this measurable. Across every recorded campaign wave, citizens found and corrected at least part of the lead premise. The system did not interpret that as disobedience or process failure. It treated out-falsifying the lead as a property of the form. [BND-15]

    PHS therefore makes failure receipts durable and correction paths explicit. A protocol that optimizes for an uninterrupted green narrative is structurally incentivized to erase the very evidence needed for safe scaling.

    7. Formal protocol model

    7.1 Core entities

    A PHS epoch contains the following entities.

    SymbolEntityMeaning
    SSubjectImmutable or strongly identified object under proof
    id(S)Subject identityContent address, digest, revision ID, or equivalent stable identifier
    HProof horizonStrongest bounded claim currently supported
    P_iProof shardIndependently executable predicate over S
    R_iReceiptDurable record of subject, method, observation, result, and limitation
    KCarrierDescendant object that incorporates valid receipts about a predecessor
    A_iAuthority ceilingStrongest action or claim permitted to a lane or actor
    JJoinControlled convergence of required proof shards
    GammaClosure predicateComplete conditions required to close the declared epoch
    ZExcluded centerInvariant or reference sort that may constrain motion but is not an ordinary work node
    DDissonance stateUnresolved tension, held residue, conflict, or incomplete edge preserved through the epoch

    A receipt is always about an exact subject. It does not float freely as a statement that the project passed. If the source changes, the subject identity changes and proof must be evaluated against the new subject.

    7.2 Winching extension

    The originating operating system can be represented as:

    W = (C, T, V, Z, {L_i}, B, M, D, Gamma, A)

    where:

    • C is current reality;
    • T is the bounded target;
    • V is the covenant binding the pull;
    • Z is the excluded center or anchor set;
    • {L_i} is the set of cables or bounded responsibilities;
    • B is the board that compiles admitted dependencies;
    • M is the winch tempo;
    • D is the dissonance and residue state;
    • Gamma is the closure predicate;
    • A is canonical admission authority.

    PHS is not W. PHS is the admissible evidence topology over W:

    PHS(W) = (subjects, horizons, proof shards, receipts,
              carriers, authority ceilings, joins, re-entry)

    This distinction preserves portability. An implementation can conform to PHS without adopting the names GUNSLINGER, HIDALGO, Harpoon, or DissonanceBasin. Conversely, using those names does not establish PHS conformance.

    7.3 Temporal admissibility

    A receipt R_i about subject S is temporally admissible only when:

    t_create(S) <= t_observe(R_i) < t_create(K)

    The subject must exist before observation. The observation must exist before a carrier claims to preserve it. If R_i concerns the propagation or reproduction of K, it cannot be contained by K; another carrier or durable external log is required.

    The protocol may use clocks, signed timestamps, transparency logs, repository ancestry, append-only sequence numbers, or combinations of these. The abstract requirement is causal order, not dependence on one clock implementation.

    7.4 Predicate admissibility

    A receipt is predicate-admissible only if it states:

    1. the exact claim being tested;
    1. the method and command or observation manifest;
    1. the expected result;
    1. the actual result;
    1. the environment and independence boundary;
    1. the limitations and nonclaims;
    1. the treatment of missing or indeterminate state.

    A predicate that defaults to pass when its input or consumer is absent is not admissible for closure. This is the formal anti-vacuity consequence of BND-08.

    7.5 Authority admissibility

    A transition is authority-admissible only when the actor's authority ceiling includes the requested action. A proof lane with observe + receipt authority may execute a predicate and produce a receipt. It may not update the canonical ref. A projection maintainer may synchronize an authorized subject but may not select a different source subject.

    Authority is explicit metadata and executable policy, not an inference from access possession.

    7.6 Cross-horizon admissibility

    Let h_s be the source horizon and h_t the target horizon. A claim may move from h_s to h_t only if there exists a typed relation e such that:

    CrossHorizon(e, h_s, h_t) =
      subject_valid(e)
      and predicate_valid(e)
      and standing_valid(e)
      and authority_valid(e)
      and externalities_accounted(e)
      and receipts_valid(e)

    No local status, identifier, projection, or summary substitutes for this edge.

    7.7 Center admissibility and anchor preservation

    In the originating Ubiquity implementation, the excluded center constrains the epoch without becoming a work node:

    V_work intersect Z = empty

    A transition is anchor-admissible only if it preserves the declared invariants and does not convert a working centroid into canonical truth by convenience.

    PHS portability does not require every implementation to use the same open-center ontology. It does require an equivalent boundary preventing observers, projections, local successes, and optimization targets from silently acquiring canonical standing.

    7.8 Closure

    An epoch closes when every required shard has a valid receipt, every receipt is bound to the declared subject or a lawful successor, every actor remained within its ceiling, the carrier preserves the required observations, the relevant residue is represented, and the terminal state agrees with the convergence target.

    Informally:

    Close(epoch) =
      all required predicates passed or lawfully disposed
    + all receipts match exact subjects
    + all temporal relations are lawful
    + no authority ceiling was exceeded
    + no required identity vanished from the denominator
    + the carrier is admitted
    + all required carrier proofs passed
    + terminal pointers reconcile
    + the closure scope and nonclaims are explicit

    Closure is scoped. Repository closure does not imply deployment closure. Deployment closure does not imply adoption closure. Adoption closure does not imply outcome closure.

    7.9 Governed checkpoint history

    The resulting history overlays three directed structures:

    immutable succession DAG
    + proof DAG
    + authority DAG
    = governed checkpoint history

    The succession graph answers what immutable states succeeded one another. The proof graph answers what was observed about which subject and by what path. The authority graph answers who or what was permitted to observe, carry, synchronize, or admit each transition.

    Figure 4. Governed checkpoint history overlays immutable succession, independent proof, and explicit authority.
    Figure 4. Governed checkpoint history overlays immutable succession, independent proof, and explicit authority.

    7.10 Derived results

    Lemma 1: No self-attestation

    If event e occurs after immutable artifact x is created, then x cannot be original evidence of e.

    t(e) > t(x)  =>  x cannot entail Observation(e)

    Corollary 1: Carrier recursion

    If later evidence about x must become durable, a successor carrier K_1 is required. If later evidence about K_1 must also become durable, a successor K_2 or external log is required.

    K_(n+1) = Carrier(K_n, Receipts(K_n))

    Proposition 1: Observer scaling without writer scaling

    Let n be the number of independent proof workers and let canonical mutation remain one ordered path. Subject to dependency, compute, network, human-attention, and join constraints, proof throughput may increase with n while canonical writer count remains one.

    Proposition 2: Correction conservation

    If a predicate fails for subject S, a corrected subject S' does not migrate or erase the failed receipt. The failure remains true as a record of S at that time, while S' begins a new proof path.

    Proposition 3: Projection nonauthority

    If projection Q contains or exposes canonical subject S, possession of S by Q does not imply authority to select S' as the next canonical subject.

    Proposition 4: Finite re-entry

    If every completed and pending proof edge is durably represented, a successor can resume at the minimal unproven predecessor of closure without reconstructing private process memory.

    Proposition 5: Residue visibility

    If an identity is excluded, blocked, null-covenant, indeterminate, or held, removing it from the denominator can create a false green. Lawful closure therefore requires explicit disposition or visible residue for every required identity.

    Proposition 6: Anti-vacuity

    A passing component, fixture, validator, or declaration cannot close a horizon when the required consumer or call-site relation is absent, unmeasured, or defaulted. Presence is not enforcement; fixture-green is not live-fired.

    Proposition 7: Observer-artifact non-occlusion

    If an observation mechanism can suppress or overwrite the evidence surface it is intended to observe, its result is not independently reliable. The observer's identity and output key space must be separable from the observed event. BND-18 is the originating scar.

    8. Reference epoch

    8.1 Horizon sequence

    A minimal PHS epoch expands a vague checkpoint into six truth-bearing horizons:

    H0   candidate / covenant disposition
    H1   immutable source identity
    H2a  distribution proof
    H2b  independent reproduction proof
    H3   durable receipt-carrier materialization
    H4   carrier propagation / reproduction proof
    H5   terminal governed reconciliation

    The two H2 shards may execute concurrently because they inspect one fixed subject through orthogonal failure surfaces. H3 cannot precede them because it carries their observations. H4 cannot be compressed into H3 because the carrier's own final identity and later target state do not exist until after H3 is created.

    Figure 5. Proof-Horizon Sharding reference epoch.
    Figure 5. Proof-Horizon Sharding reference epoch.

    8.2 H0 - Candidate or covenant disposition

    The epoch begins with a bounded candidate. The system records its scope, origin, intended effect ceiling, admission requirements, anchors, and nonclaims. H0 answers whether the candidate is rejected, held, corrected, or eligible to become a source subject. It does not yet provide immutable source identity.

    A candidate may come from a human, model, branch, patch, generated package, external repository, sibling estate, prior carrier, or covenant. PHS is neutral to authorship method. Candidate generation is not admission.

    8.3 H1 - Source-bearing subject

    The accepted source tranche is materialized into an immutable or strongly identified subject. In Git, this is commonly a source-bearing commit. Its object ID and tree identity become the fixed binding for later proof.

    H1 establishes that selected source exists. It does not establish that a remote exposes it, that another environment can reproduce it, or that a live consumer invokes it.

    The horizon-quiver build's 43 H1 arms illustrate the point: H1 can be complete and still deliberately unwired. [BND-16]

    8.4 H2a - Distribution proof

    A distribution proof reads the intended target surface directly and verifies that each required ref or object endpoint exposes id(S). In the Git profile, direct ls-remote readback is stronger than trusting a local remote-tracking ref, because the latter may represent only the state observed during the last network communication. [17]

    The receipt should identify every expected remote and ref, the observed object ID, the observation time, the comparison predicate, and any unreachable or ambiguous target.

    H2a proves distribution within the declared target set. It does not prove independent execution or reproduction.

    8.5 H2b - Independent reproduction proof

    A reproduction proof acquires the exact subject through an intended distribution surface into an environment that does not inherit undeclared mutable state from the authoring checkout.

    The lane can detect:

    • untracked or ignored files;
    • stale generated artifacts;
    • local-only configuration;
    • undeclared dependencies;
    • machine-specific caches;
    • hooks or scripts unavailable to another actor;
    • hidden symlinks;
    • objects present locally but absent from the intended remote;
    • tests that pass only because of prior local execution.

    The receipt must state the independence boundary it actually proves. A new directory can detect some residue while sharing the host. A container may isolate dependencies while sharing a kernel. A separate account may share credentials. Independence is graded and declared, not assumed.

    The horizon-quiver probe demonstrates the negative case: without remote contact, detached reproduction was not established regardless of the probe's name. [BND-16]

    8.6 H3 - Receipt/state carrier

    After all required H2 shards pass or receive lawful dispositions, their observations converge into a descendant carrier. The carrier preserves:

    • exact predecessor subject identity;
    • proof-horizon labels;
    • predicates and results;
    • observer and environment descriptors;
    • observation times or causal positions;
    • authority ceilings and standing;
    • limitations and explicit nonclaims;
    • held residue and conflicting evidence;
    • join status;
    • next required horizon.

    The carrier may be a commit, signed attestation bundle, append-only log entry, governed database record, or another durable object. H3 makes evidence durable. It does not prove the carrier's own later propagation.

    8.7 H4 - Carrier checkpoint

    The carrier becomes the next subject. The system performs whatever distribution, retrieval, reproduction, signature, transparency, or custody checks policy requires for that carrier.

    This is the recursive move that prevents self-certification.

    Carrier recursion may continue across assurance domains. One carrier may preserve source and repository evidence; another may preserve deployment evidence; another may preserve stakeholder acceptance. Each claims only within its temporal and semantic horizon.

    8.8 H5 - Terminal reconciliation

    Terminal reconciliation confirms that source, proof, carrier, projections, execution pointers, residue, and checkpoint state agree with the declared closure predicate.

    Any ordinary work graph, task tracker, release pointer, or operational state may advance only to the horizon actually earned.

    The system reaches a quiet point when no unresolved residue remains inside the claimed scope. A quiet point does not claim that the system is permanently complete. It claims that the declared epoch has no hidden pending edge.

    9. Protocol invariants

    PHS is defined less by one command sequence than by invariants that every implementation must preserve.

    IDInvariantRequired property
    I1Exact subject bindingEvery receipt names one immutable or strongly identified subject.
    I2Serial canonical mutationAccepted state advances through one ordered canonical lane.
    I3Proof-authority separationProof workers cannot silently admit their own observations into canon.
    I4Temporal admissibilityA carrier contains only observations available before its creation.
    I5No self-attestationAn artifact cannot certify its own future propagation, retrieval, execution, adoption, or outcome.
    I6Evidence-class preservationDistribution, reproduction, deployment, adoption, and outcome receipts are not interchangeable.
    I7Independent acquisitionReproduction proof does not inherit undeclared mutable state from the authoring environment.
    I8Projection nonauthoritySynchronized copies do not become coequal canonical writers by possessing state.
    I9Monotonic evidenceLater carriers add bounded observations without rewriting what earlier subjects could know.
    I10Correction survivalFailed, corrected, or superseded attempts remain intelligible in lineage.
    I11Deterministic resumptionThe next actor can identify the first required unproven horizon without private process memory.
    I12Scoped closureA closed horizon may not be promoted into a stronger domain without new evidence.
    I13Anchor preservationThe declared center, telos, and non-negotiable invariants are not ordinary nodes available for local optimization to rewrite.
    I14Residue visibilityHeld, excluded, null-covenant, missing, or indeterminate identities remain visible until lawfully disposed.
    I15Anti-vacuityMissing inputs, consumers, or call sites cannot default a required proof surface to green.
    I16Currentness at the actA capability verdict is re-evaluated at the execution boundary when current state may have changed.
    I17Fixture/live separationFixture-green, source-present, wired, and live-fired are distinct states.
    I18Observer-artifact non-occlusionThe observation mechanism may not suppress, overwrite, or masquerade as the event it measures.
    I19Honest-negative carriageA mechanism that has not fired live, a path not exercised, or a domain not measured is recorded explicitly rather than inferred from implementation presence.
    I20Typed cross-horizon movementEvidence or authority moves between horizons only through an admitted relation with standing, predicate, source, target, and externalities declared.

    9.1 Monotonicity is subject-relative

    PHS evidence is monotonic with respect to an exact subject. A later receipt may add observations about S without changing id(S) or erasing earlier receipts. If source changes produce S', receipts about S do not migrate. The new subject begins a new proof path.

    A failed receipt therefore remains true as a record that a particular predicate failed at a particular time. Correction does not require narrative erasure.

    9.2 Currentness is an execution-boundary question

    The binder's tic-527-to-535 capability reversal is a direct operational source of I16. A prior assessment concluded that the epoch16 LoRA path was not reachable. Live execution at tic 535 overturned four premises: the model served on the M2 Max, all 280 LoRA modules were present, PEFT-to-MLX conversion completed in 1.7 seconds, real inference completed in 88.9 seconds, the gate passed, and mutation authority remained false. [BND-02]

    The lesson is not that prior assessments are useless. It is that capability walls have shelf lives. A historical verdict can guide a present test; it cannot replace a present probe when the act is consequential and the substrate may have changed.

    The same rule cuts the other way. The affordability survey found prior live receipts for an MLX model while the current base weights were absent. Historical liveness did not become current liveness. [36]

    9.3 Fixture-green is not live-fired

    The protocol distinguishes:

    schema present
    fixture passes
    component callable
    consumer wired
    live invocation observed
    external effect read back

    Each state can be useful. None may be renamed into the next.

    The a0 estate memo makes the same distinction in another domain: a validator existed and passed fixtures, but no call-site gate invoked it; a doctrine packet was delivered but not yet consumed; the inbound lifecycle leg was fixture-green while the outbound leg was live-proven. [37]

    The horizon-quiver H1 arms were deliberately unwired. The dissonance-basin drain was designed and tested but not live-fired. The economy was a live moving simulation, not live money. These are not embarrassments. They are the system reporting the exact horizon reached.

    9.4 Absence and disagreement are evidence

    Two readers of one substrate may disagree. A path probe may say a binary is absent while exact file probes find three working binaries. A catalog may describe a model as present while the directory is gone. A registry may point at one model identity while receipts name a sibling. [36]

    PHS does not resolve disagreement by choosing the most convenient sentence. It preserves the observations, their methods, their times, and the predicate needed to adjudicate them.

    The result may be held. A held state is not indecision without structure. It is a typed assertion that the system knows enough to refuse closure and knows what evidence would reopen the path.

    9.5 Look-First is custody, not permission

    Before an actor overwrites a plan, state carrier, representation, or canonical pointer, it reattaches to the current state. Prompted LLC's Look-First doctrine treats that read as the act by which the actor takes custody of the construction-destruction couple inherent in an overwrite. [10]

    PHS applies Look-First at source selection, correction, carrier creation, and terminal reconciliation. The read is not automatic permission to mutate. It is a condition of owning what the mutation ends and what it creates.

    10. Receipt, carrier, basin, and ledger model

    10.1 Minimal receipt

    A minimal PHS receipt should be machine-readable and human-auditable.

    {
      "protocol": "proof-horizon-sharding/v1.2",
      "checkpoint_id": "phs-2026-09-04-001",
      "subject": {
        "type": "git-commit",
        "id": "<exact-subject-id>",
        "tree_id": "<optional-tree-id>",
        "predecessor": "<optional-predecessor-id>"
      },
      "horizon": "H2b.independent-reproduction",
      "parent_horizon": "repository-source",
      "predicate": {
        "name": "detached-clone-validation",
        "command_manifest": "sha256:<digest>",
        "expected": "all required checks pass"
      },
      "observer": {
        "actor_id": "<verifier-id>",
        "environment_id": "<environment-id>",
        "independence_level": "clean-clone-separate-directory",
        "acquisition": "clone-from-declared-remote"
      },
      "observed_at": "<timestamp-or-causal-position>",
      "result": "pass | fail | held | indeterminate | not_applicable",
      "evidence": [
        {"type": "log", "digest": "sha256:<digest>"},
        {"type": "test-report", "digest": "sha256:<digest>"}
      ],
      "authority_ceiling": "observe-and-receipt",
      "standing": "<why-this-observer-counts>",
      "residue": ["<held-or-excluded-identity>"],
      "nonclaims": [
        "does not prove deployment",
        "does not prove adoption",
        "does not prove business outcome"
      ],
      "convergence_target": "H3.receipt-carrier",
      "next_horizon": "H3.receipt-carrier"
    }

    The schema may be wrapped in in-toto statements, DSSE envelopes, SLSA predicates, SCITT statements and receipts, OCI attestations, signatures, or transparency-log entries. Those systems can carry PHS evidence. PHS additionally specifies temporal partitioning, recursive carrier proof, serial admission, cross-horizon noncollapse, visible residue, and convergence semantics. [20,21,25]

    10.2 Required semantic fields

    Regardless of encoding, a PHS receipt requires:

    1. exact subject identity and type;
    1. predecessor or correction relation;
    1. proof horizon and parent horizon;
    1. predicate and expected result;
    1. method and command or observation manifest;
    1. observer identity and standing;
    1. environment and independence level;
    1. observation time or causal position;
    1. result;
    1. evidence bindings;
    1. authority ceiling;
    1. residue and exclusions;
    1. nonclaims;
    1. convergence target;
    1. next required horizon;
    1. correction or supersession pointers when applicable.

    10.3 Receipt authenticity and receipt truth

    Cryptographic signatures can establish that a named key signed a receipt and that the bytes have not changed. They do not by themselves establish that the receipt's semantic claim is true.

    A high-assurance implementation may combine signed receipts, protected identities, trusted execution, reproducible commands, multiple observers, and transparency logs. Each control answers a different question. PHS refuses to collapse them into one trust scalar.

    10.4 Join receipt

    A join receipt does not merely state that several workers finished. It establishes that:

    • the required shard set was fixed or versioned;
    • every receipt binds to the declared subject or lawful successor;
    • evidence classes remain distinct;
    • missing and held lanes are represented;
    • no observer exceeded its authority ceiling;
    • the join itself had admission standing;
    • the resulting carrier contains only pre-creation observations;
    • the next horizon remains explicit.

    The tic-643 exact set operation - admitted intersect executable equals seven of seven, with seven other executable-looking identities excluded for lack of covenants - is a concrete example of why the denominator must be explicit. [BND-05]

    10.5 Carrier chain

    A carrier chain can be represented as:

    S0  source subject
     |-- R0a distribution receipt
     |-- R0b reproduction receipt
     |
    K1  carrier for S0 receipts
     |-- R1a carrier distribution receipt
     |-- R1b carrier reproduction receipt
     |
    K2  carrier for K1 receipts

    The chain need not continue forever. Policy chooses the terminal horizon required for the declared scope. But the system may not compress a required later observation into an earlier immutable artifact.

    10.6 Dissonance state and held basins

    PHS receipts may carry unresolved tension without requiring a specific DissonanceBasin implementation. The semantic requirement is that conflict, uncertainty, blocked identities, and failed predicates remain inspectable.

    A held basin can include:

    {
      "state": "held",
      "subject": "<id>",
      "reason_codes": ["remote_unreachable", "predicate_ambiguous"],
      "named_tensions": ["trust_below_tau", "mint_halted"],
      "residual": 0.45,
      "reopen_when": ["direct target readback succeeds"],
      "authority_ceiling": "observe-and-receipt"
    }

    The residual is not a universal numerical requirement. The requirement is that the system not manufacture harmony by deleting the unresolved branch.

    10.7 Append-only correction

    An append-only ledger may preserve a later correction without changing the earlier row. The later row should name:

    • the prior assertion;
    • the new observation;
    • the reason the prior assertion is no longer current or was never valid;
    • the affected claim horizon;
    • the next reader instruction;
    • whether the correction changes source, evidence, authority, or only interpretation.

    BND-17 is the lived example: the ledger recorded a true automatic fire and declared prior attestations false in the same medium. The correction did not retroactively make the prior rows correct; it made the history intelligible.

    11. DAGs, quivers, and governed checkpoint history

    11.1 DAGs discharge bounded responsibility

    A directed acyclic graph is appropriate when a bounded unit of work has causal predecessors, finite joins, and a declared terminal condition. A carrier cannot precede the receipts it carries. A clean-clone proof cannot precede the immutable subject. A target readback cannot precede the target update. A terminal join cannot precede required shard dispositions.

    The board compiles admitted covenants into this bounded execution structure. The DAG therefore answers what must precede what inside one responsibility slice.

    11.2 Quivers preserve living recurrence

    The broader field is not acyclic. Real systems revisit prior assumptions, reopen held states, learn from corrections, recur across horizons, and carry long-lived tensions. The quiver represents that living topology. [5,6]

    FORKED states the relation cleanly: DAGs discharge bounded responsibility; quivers preserve the recurrence that returns. [5]

    PHS uses both:

    quiver   -> living field of possible, lawful, forbidden, and recurring motion
    splat    -> bounded local field for one decision
    covenant -> admitted current-to-target pull
    DAG      -> finite dependency and proof discharge
    carrier  -> durable state returned to the living field

    11.3 DAG of DAGs

    A large checkpoint can contain multiple local DAGs connected by typed joins. One DAG may build the subject, another may prove distribution, another may reproduce, another may validate security, and another may materialize and checkpoint the carrier.

    A meta-DAG can order those local graphs without becoming a second canonical authority. Each local graph retains its owner, subject, predicate, effect ceiling, and receipts. Cross-graph edges are explicit.

    The t650 S1-to-S7 raise is the binder's seed example: plan, simulate, and fire closed the local chain in one tic while preserving six null-covenant identities as residue. [BND-06]

    11.4 The proof DAG is not the commit DAG

    The commit DAG shows immutable succession. It does not show whether a target exposed a commit, whether an independent environment acquired it, whether a proof worker had standing, or whether a later carrier preserved the observations.

    The proof DAG binds observations to subjects. The authority DAG binds actors and transitions to ceilings. The three graphs may share identifiers, but they answer different questions.

    This separation is what prevents a commit history from being read as a complete audit history.

    11.5 No cycles inside the bounded execution graph

    A bounded PHS epoch should not contain an uncontrolled execution cycle. Repeated retries, corrections, and reopenings are represented as new subjects, new receipts, or successor epochs rather than as an unbounded hidden loop.

    This is finite re-entry rather than pretending recurrence does not exist. The living quiver may recur. The current execution DAG must still expose a next edge and a stopping condition.

    12. Git reference realization

    12.1 Why Git is a useful substrate

    Git supplies:

    • content-addressed objects;
    • commit objects containing tree and parent bindings;
    • a directed acyclic commit history;
    • movable refs over immutable objects;
    • direct remote-ref inspection;
    • multiple repositories and remotes;
    • clean clone acquisition;
    • detached checkout of an exact subject;
    • signatures, tags, and notes as optional metadata surfaces.

    Git's object database and commit parentage provide strong subject identity and ordered succession. Remote refs provide independently readable distribution surfaces, while the distinction between live remote refs and local remote-tracking refs prevents stale local views from being mistaken for direct readback. [16-19]

    12.2 Reference mapping

    PHS conceptGit realization
    Immutable subjectCommit object ID, optionally paired with tree ID
    Canonical laneDesignated root main under explicit write policy
    Candidate laneBranch, patch, worktree, generated tranche, or external repository
    Distribution proofDirect readback of expected remote refs against exact commit ID
    Reproduction proofFresh clone from intended remote, detached checkout, declared validations
    Receipt carrierDescendant commit containing machine-readable receipts and lineage
    ProjectionSynchronized nonauthoritative ref in another remote or repository
    Carrier proofDirect readback and reproduction of the receipt carrier itself
    Terminal reconciliationCanonical pointer, task graph, receipts, and checkpoint state agree on the closed horizon

    12.3 Illustrative command geometry

    # H1 - select exact immutable subject
    SUBJECT="$(git rev-parse HEAD)"
    TREE="$(git rev-parse "${SUBJECT}^{tree}")"
    
    # H2a - publish through governed synchronization, then read the target directly
    git push origin "${SUBJECT}:refs/heads/main"
    REMOTE_SUBJECT="$(git ls-remote origin refs/heads/main | awk '{print $1}')"
    test "${REMOTE_SUBJECT}" = "${SUBJECT}"
    
    # H2b - independently acquire and reproduce the exact subject
    TMP="$(mktemp -d)"
    git clone --no-checkout "<declared-remote-url>" "${TMP}/repro"
    git -C "${TMP}/repro" checkout --detach "${SUBJECT}"
    "${TMP}/repro/scripts/validate-checkpoint"
    
    # H3 - create a descendant carrier from resulting receipts
    # The carrier cannot yet prove its own subsequent remote state.

    A production implementation should route writes through protected policy, verify authorization and fast-forward conditions, hash command manifests and outputs, preserve failure receipts, and distinguish source effects from provider, database, deployment, adoption, and outcome effects.

    12.4 Exact subject re-freezing

    The crank-2 staging memo provides a long-form example of exact-subject discipline. The proposed publication commit moved repeatedly as ruled changes landed. Each movement was recorded as a new addendum with a new exact SHA. The older tuple did not become approximately current, and the workflow's drift guard would refuse publication when packed roots diverged from the admitted commit. [35]

    This is not inefficiency. It is the cost of refusing to publish a different subject from the one admitted.

    The sequence also illustrates why a successful earlier dry run does not authorize a later moving head. The predicate remains bound to the exact subject.

    12.5 Multi-remote projection without canon fragmentation

    A concrete implementation may synchronize several refs to one selected commit while retaining one canonical writer. Those refs provide distribution, custody, disaster-recovery, or external-verification surfaces. They do not become independent authoring authorities merely because each is named main or can technically receive writes.

    Authority is external to branch naming.

    12.6 Proof-qualified release

    A repository release can be defined as a closed set of horizons rather than a tag or CI status:

    candidate admitted
    + exact source selected
    + required remote refs confirmed
    + clean clone acquired
    + declared validations passed
    + receipt carrier admitted
    + carrier checkpointed
    = repository release horizon closed

    Deployment, adoption, and outcome remain successor horizons.

    The context-grapple-gun dry run at tic 749 makes this distinction explicit. The workflow verified the admitted tuple, tested and packed the exact artifact, and skipped publish-side steps because dry_run=true. The result was green for the pre-publication path, while nothing was published and the registry remained unchanged. [34]

    13. Failure semantics and correction survival

    13.1 Faults remain localized

    When a checkpoint fails, PHS identifies the failed proof shard rather than collapsing the event into release failed.

    Failed horizonMeaningNarrow response
    H0 admissionCandidate invalid, out of scope, or unauthorizedCorrect, reject, or hold the candidate
    H1 sourceImmutable source could not be lawfully materializedRepair source or admission procedure
    H2a distributionExpected target does not expose exact subjectRepair authorization, reachability, ref selection, or propagation
    H2b reproductionIndependent environment cannot acquire or validate subjectRemove hidden dependency or correct source
    H3 carrierReceipt bundle malformed, incomplete, or unauthorizedReconstruct carrier without reopening valid source proof
    H4 carrier proofCarrier exists but required propagation or reproduction remains openCheckpoint carrier as new subject
    DeploymentExternal runtime does not match admitted artifactInspect deployment path; do not rewrite repository history by default
    AdoptionIntended user or organization has not accepted or used the artifactGather adoption evidence; do not promote deployment receipt
    OutcomeReal-world effect absent or unmeasuredMeasure outcome under a declared method

    13.2 Corrections produce new subjects

    Suppose detached-clone reproduction of source commit C fails because an undeclared file was required. The failure receipt remains bound to C. The corrected source becomes C'. Distribution and reproduction proof must be repeated for C'; the system does not edit the record to pretend that C passed.

    C  source subject
    |-- R_remote(C) = pass
    |-- R_clone(C)  = fail
    |
    C' corrected source subject
    |-- R_remote(C') = pass
    |-- R_clone(C')  = pass
    |
    K  carrier for C' receipts

    The scar distinguishes source failure from distribution failure, reveals what changed, and prevents later actors from inheriting a false narrative of uninterrupted success.

    13.3 Capability verdict overturned by execution

    At t527, the operating account said the epoch16 LoRA path was not reachable. At t535, the system ran the thing and falsified the verdict. The corrected claim did not erase t527. It produced a lineage in which the assessment, its premises, the live result, and the new law remained visible. [BND-02]

    The law is symmetric:

    Never infer a current capability wall from a prior assessment without re-testing at the act, and never infer current liveness from a prior receipt when required state may have disappeared.

    13.4 Vacuous green

    The board-wiring claim survived roughly 119 tics because two defects concealed each other. One surface said the board was read; another allowed missing state to behave as executable. Only the first real eater exposed the absence. [BND-08]

    The repair was not another prose warning. Missing state became visibly non-executable. The status model separated previously collapsed axes.

    PHS generalizes the lesson: a predicate must state what happens when required state is absent. missing -> pass is usually a category error, not resilience.

    13.5 Observer artifact occlusion

    At tic 540, a telemetry marker suppressed the live cable receipt it was meant to help observe. The cure created a distinct __run__ key space, preserving the original confession in the ledger. [BND-18]

    This is a subtle class of failure. Evidence tooling can perturb, overwrite, filter, or rename the event it measures. A trustworthy proof lane must model the observer's effect on the observed surface.

    13.6 Append-only correction

    At tic 701, the wave ledger recorded the first true automatic pawl fire and declared prior attestations false in the same append-only row. [BND-17]

    The system did not rewrite the past for aesthetic consistency. It added a later fact whose relationship to the earlier claim was explicit.

    13.7 Refusal and execution in the same tic

    The tic-751 lap is important because the seat first refused on an honest but incorrect floor, the Architect retracted the floor, and the lap then ran. The two events were not smoothed into a triumphant story in which the refusal never happened. [BND-04]

    The pattern is correction metabolism:

    measured state
    -> lawful refusal
    -> better evidence
    -> authority-bearing correction
    -> execution
    -> receipt with honest limits

    The lap's own limitations prevented plumbing proof from becoming capability proof. The live 27B consumed one harmony slice and returned typed proposals, but n=1, the label was low-information by construction, no proposal was evaluated, and no mutation moved. [33]

    13.8 Deterministic re-entry

    At interruption, a successor resumes from:

    exact subject
    + completed proof shards
    + pending or failed shards
    + authority ceiling
    + receipt predicates
    + residue
    + convergence target

    The next action is the minimal unproven predecessor of closure. The successor does not need the previous agent's context window, terminal scrollback, private memory, or prose summary.

    This is finite re-entry: uncertainty is represented as a missing or held edge rather than a vague status.

    13.9 Correction debt

    Correction debt is the downstream burden created when a state is accepted before adequate conformation or later becomes stale. It includes dependents trained on a false claim, dashboards that repeat outdated liveness, receipts bound to the wrong subject, and human decisions made under a collapsed horizon.

    PHS reduces correction debt by keeping claims subject-bound and preventing stronger domains from inheriting weaker proof. It does not eliminate debt; weak predicates, dishonest observers, compromised authority, or omitted evidence can still create it.

    14. Agentic systems and winch tempos

    14.1 Governed verification swarms

    PHS allows agents to fan out across proof while remaining structurally unable to mutate canon or overclaim. A source checkpoint may dispatch dependency inspection, clean-clone reproduction, direct remote readback, security review, schema validation, lineage inspection, artifact-integrity verification, and outcome-boundary review concurrently.

    Each agent receives a smaller contract than a general mandate:

    exact subject
    + permitted evidence surface
    + authority ceiling
    + receipt predicate
    + stop condition
    + convergence destination

    The agent can fail safely by emitting a bounded fail, hold, indeterminate result, or contradiction.

    Figure 6. GUNSLINGER and HIDALGO alter execution tempo without changing PHS evidence law or canonical authority.
    Figure 6. GUNSLINGER and HIDALGO alter execution tempo without changing PHS evidence law or canonical authority.

    14.2 GUNSLINGER

    GUNSLINGER is the all-ready-cables tempo. It maximizes lawful concurrency over the exact set that is both admitted and executable.

    At tic 643, seven office citizens fired simultaneously with disjoint write surfaces, while seven unadmitted executable identities remained excluded. [BND-05]

    At tic 650, seven work cables and three invariants traversed plan, simulate, and fire inside one tic; six null-covenant identities remained named as residue. [BND-06]

    The campaign from tics 757 through 770 adds a stronger result: every measured wave falsified part of the lead premise. Wave seven moved from staged to signed to built to closed in 58 minutes with proof gates on both sides. Wave three replayed 68 files and 59 routes, produced zero verdict flips, changed 46 diagnoses, and made 92 silent stale pins visible. [BND-15]

    GUNSLINGER is therefore not agents agreeing faster. It is bounded parallel challenge under a shared cradle.

    14.3 HIDALGO

    HIDALGO is a staged-lock throttle selected by residue shape. It is appropriate when the system should not raise every ready cable at once, even if all are nominally executable.

    The binder records one live HIDALGO classification. That result should not be exaggerated into extensive empirical validation. It establishes that the throttle existed, was exercised, and judged a clean residue once. [BND-10]

    14.4 Tempo does not alter evidence horizon

    Neither tempo changes what a receipt proves. GUNSLINGER does not upgrade source evidence because more agents ran. HIDALGO does not produce stronger authority because a human-paced sequence occurred.

    PHS therefore treats tempo as execution metadata, not evidence rank.

    14.5 Dissonance as swarm fuel

    A mature swarm should not merely divide implementation work. It should divide failure surfaces. Independent agents are useful when their contracts encourage different ways of being wrong and when the join preserves those differences.

    The binder's claim that citizens out-falsified the lead in every campaign wave is evidence that the swarm was not functioning as a consensus amplifier. [BND-15]

    14.6 Session-independent autonomy

    Many autonomous systems store continuity in mutable task databases, chat summaries, working-directory residue, model memory, or branches whose authority is unclear. Those surfaces may be useful. None is sufficient as canonical evidence.

    PHS provides durable epoch boundaries. One model may create the source. A second may reproduce it. A third may inspect receipts. A human may admit the carrier. Another model or vendor may resume later. Canon remains external to all of them.

    Continuity therefore does not depend on the same model, context window, vendor, operator, machine, worktree, or repository host.

    14.7 Scaling law

    Let n be the number of independent proof workers and canonical mutation remain one ordered path. Subject to compute, network, dependency, predicate, human-attention, and join constraints:

    proof throughput may increase with n
    while canonical writer count remains 1

    More intelligence does not have to mean more authority.

    The phrase unbounded parallel reasoning describes a topological property, not infinite physical capacity. Real systems remain bounded by resources and by the cost of lawful convergence.

    Figure 7. A governed proof swarm scales observers while retaining one convergence path.
    Figure 7. A governed proof swarm scales observers while retaining one convergence path.

    14.8 Approval loops do not scale, but judgment remains causal

    Prompted LLC's public account distinguishes permanent approval loops from human judgment as reusable structure. If every action waits on the same person, the person becomes a bottleneck or rubber stamp. If human judgment disappears, autonomy outruns governance. [8,28]

    PHS moves human judgment to the edges where it has standing: selecting covenants, setting ceilings, resolving novel contradictions, opening irreversible surfaces, correcting false premises, and admitting canonical transitions.

    The Architect's bell in the binder is an example. The system could size a model conversion, identify that RAM was sufficient, and prove that the real blocker was the output membrane and disk. It could not decide where to place the resulting weights or whether to open the new coupling. That movement remained the Architect's. [36]

    15. Operational emergence and lived falsification

    15.1 Method and evidence ceiling

    This section reconstructs the operating lineage from THE BINDER and the supplied supporting artifacts. The binder was commissioned at tic 770 and composed from two miner-produced, lane-complete evidence tables. It declares 22 stable BND markers, 161 cable receipts, 68 drain receipts, 213 wave-ledger rows, 202 economy-tic artifacts, and 51 campaign files. [31]

    The binder is two hops from ground truth. Its own method says to resolve BND markers to the extracts and then to the primary receipts. Those extracts were not supplied as standalone files with this revision. Accordingly:

    • the binder is cited as an evidence map;
    • supplied primary or contemporaneous artifacts are cited separately where available;
    • counts and landmark descriptions retain their BND markers;
    • disagreements remain visible;
    • this paper does not claim an independent row-by-row re-audit of every binder table.

    That limit is part of the method, not an editorial inconvenience.

    15.2 Timeline spine

    Figure 8. Operational emergence of the winching machinery and horizon-quiver build, reconstructed from THE BINDER's dated landmarks.
    Figure 8. Operational emergence of the winching machinery and horizon-quiver build, reconstructed from THE BINDER's dated landmarks.
    Date or eraTic(s)MovementEvidence marker
    2026-06-13414-416Harpoonv2 founded; master DAG-of-DAGs falsified and rechartered as metabolize, not master.BND-13
    ~2026-06-27494-495Ten-cable, seven-wave hoist covenant; waves of agents named; center exclusion made a compiler check.BND-01
    2026-07-01527-535Live model serve overturned a prior capability wall while mutation authority remained false.BND-02
    2026-07-03 verification512-559First full-cradle BOOM raise; six raisable cables, later seven-of-seven verification, center never struck.BND-07
    2026-07-05568-570Typed winch modes, economy GUNSLINGER, collapse replay, and the deepest recorded basin exercise.BND-09, 11, 12, 19
    2026-08-11/12621-623Board live compiler closed the approximately 119-tic vacuous-green scar.BND-08
    ~2026-08-15/16643, 650Seven simultaneous office citizens; the complete S1-S7 chain raised inside one tic.BND-05, 06
    ~2026-08-30/31749-751First governed seat consumption of a local model; refusal, correction, and lap preserved in one lineage.BND-04
    2026-09-01 to 04757-770Eight-wave GUNSLINGER campaign, lead-premise falsification streak, and full horizon-quiver construction.BND-15, 16

    15.3 The first executable hoist

    The tic-494 covenant converted a broad current-to-target intention into a ten-cable, seven-wave staged-lock DAG. Five of five pre-fire checks passed. Three invariants could run in parallel. The center remained a non-node enforced by the compiler. [BND-01]

    The importance is architectural. The system no longer depended on the Architect manually carrying every relation between parts. The pull itself became executable while the founding telos remained outside the ordinary task graph.

    15.4 Execution overturns assessment

    At tic 535, the epoch16 LoRA served live on the M2 Max. The binder reports 8.31 GiB peak Metal memory, 280 of 280 LoRA modules, 1.7-second PEFT-to-MLX conversion, 88.9-second real inference, a passing gate, and mutation_authority=false. [BND-02]

    The event did two things at once. It proved the live path that a prior assessment had rejected, and it refused to let live execution become mutation authority.

    A later affordability survey initially recorded the t535 receipt as absent. The binder's miners found the receipt on disk and flagged the disagreement for adjudication instead of silently correcting the preparation artifact. [31,36]

    This is PHS in lived form: current evidence overturns a stale capability claim, while the earlier claim and the later disagreement remain attributable.

    15.5 Reproducing partial sums

    The corpus chain records:

    130,678 + 11,823 + 2,897 + 13,984 = 159,382 T7 traces

    The binder states that every partial sum independently reproduced a previously receipted historical total and that the total was re-derived at tic 700 after tic 650 had disclosed the previous figure as cited rather than re-derived. [BND-03]

    The importance is not the size of the trace corpus alone. It is the transition from inherited number to reproducible number. A figure that once had only citation standing gained a later derivation receipt without pretending the earlier carrier had always possessed it.

    15.6 BOOM, seven citizens, and the S-chain

    The tic-512 BOOM raise produced receipts for six of six raisable cables within one cradle window. Later verification at tic 559 covered seven of seven, with center_struck=false, mutation_authority=false, and the 159,382-trace corpus bound into the account. [BND-07]

    At tic 643, seven office citizens fired simultaneously with disjoint write surfaces. Only identities in the exact admitted-and-executable intersection fired. [BND-05]

    At tic 650, the entire S1-S7 chain traversed plan, zero-side-effect simulation, and fire in one tic. Six null-covenant identities remained named as residue. [BND-06]

    These events establish a progression:

    manual crossing
    -> receipted full-cradle raise
    -> simultaneous bounded citizens
    -> one-tic DAG-of-DAG discharge

    They do not establish that every later campaign used the same code path. The binder explicitly withholds that claim.

    15.7 Economy as a long-running simulation lane

    From tic 568 through 770, with one gap at 602, the economy generated 202 per-tic artifacts, 119,103 telemetry lines, and approximately 199,000 simulated generations. Every artifact used mode: gunslinger, phase: SimOnly, and anchor_frozen_center_excluded: true at each boundary. [BND-11]

    This is the longest repeated expression of the winch vocabulary in the binder. It also demonstrates why source-tense must remain explicit. The economy was live as a moving simulation. It was not live money.

    The tic-568 collapse replay reproduced a UCoin collapse across 2,400 shadow generations. Supply fell to 9.95e-06, reserve remained pinned at 0.2, and rate reached the 0.93 floor. The previously invisible condition - zero mint below a trust threshold - became a named breach flag at generation one. [BND-12]

    The finding was not that the simulation prevented collapse. It was that a structurally invisible failure became visible early enough to govern future work.

    15.8 The first local-consumer lap

    At tic 749, after 221 tics without a governed seat consuming a local model, the egress-router seat served a local 27B reasoner and processed one real harmony slice. The supplied memo records 3,566 prompt tokens, 980 completion tokens, 7.97 output tokens per second, 0.87 MTP acceptance, 162.85 seconds wall time, 18.38 GiB wired-page delta, typed proposals only, and complete teardown. [33]

    The memo's strongest sentence is its limit: plumbing was proven; capability was not. The sample was one, the label was partly pre-answered by the predicate, no proposal was evaluated, and no mutation occurred.

    At tic 751, a second lap followed a lawful refusal on the wrong disk floor. The Architect corrected the premise, and the seat ran. The binder reports a score of 0.825 [0.680, 0.913] against 0.400 lookup and 0.025 majority baselines, with two byte-identical draws. [BND-04]

    The refusal and the success belong in the same evidence chain.

    15.9 The GUNSLINGER-BACKLOG campaign

    The campaign from tics 757 through 770 followed a repeated structure: freeze the baseline, admit the covenant, prove the gun at the checkpoint boundary, dispatch waves, inspect results, and close only after the corresponding proof.

    Its signature result was the lead-premise falsification streak. Every recorded wave found three or four premise errors. By wave two, this was named as a property of the form rather than an accident. By wave five, the close receipt carried lead_premise_falsification_streak: "n=6 waves". [BND-15]

    Wave seven moved from staged to signed to built to closed in 58 minutes. Wave three replayed 68 files and 59 routes, changed 46 diagnoses without flipping a verdict, and made 92 silent stale pins visible.

    A system that only measures agreement would miss the significance. The campaign became faster while continuing to contradict its lead. The throughput increase and the falsification rate moved together.

    15.10 The August production windows

    Author-supplied GitHub Insights screenshots for August 1 through September 1 report:

    WindowAdditionsDeletionsCommitsFiles changed
    Aug 1-Sep 112,697,29489,38656713,909
    Aug 25-Sep 18,935,64795,9381889,850
    Aug 29-Sep 16,723,88611,784956,711
    Aug 31-Sep 13,928,4846,087402,819

    The nested windows imply that approximately 70.4 percent of the monthly additions occurred in the final week, 53.0 percent in the final three-day window, and 30.9 percent in the final 24-hour window. [15]

    Figure 9. Nested August 2026 GitHub Pulse windows supplied by the author. Values are gross tracked additions and deletions, not quality, deployment, or outcome measures.
    Figure 9. Nested August 2026 GitHub Pulse windows supplied by the author. Values are gross tracked additions and deletions, not quality, deployment, or outcome measures.

    The weekly code-frequency view separately shows an early-August bucket with roughly 2.915 million additions and 1.894 million deletions, followed by later weekly addition buckets near 2.16 million, approximately 2.6 million, and 6.745 million. The deletion totals differ from the monthly Pulse view because the screenshots expose different aggregation windows and possibly different bucket boundaries. This paper preserves the disagreement rather than forcing one number to serve every claim.

    15.11 What the operational evidence establishes

    The evidence establishes that:

    • the operating system had already developed a receipt-bearing current-to-target machinery before PHS was formally named;
    • parallel agent execution could be bounded by admitted sets, disjoint surfaces, invariants, and residue;
    • the system repeatedly caught stale, vacuous, overnamed, or occluded claims;
    • correction could alter the next trajectory without erasing the failed subject;
    • proof vocabulary, horizon separation, carrier behavior, and detached reproduction became progressively explicit;
    • the production corpus entered a scale at which conventional line-by-line human review could not remain the sole assurance mechanism.

    The evidence does not establish that every line was hand-authored, that all changed paths were executable production code, that every receipt proved an external deployment, that every mechanism was live, that the protocol alone caused the acceleration, or that the results generalize without independent replication.

    The defensible description is:

    PHS was abstracted from a live governance apparatus that accelerated while retaining one canonical authority path, preserving correction scars, and repeatedly allowing bounded citizens to falsify the premises that dispatched them.

    16. Honest negatives and truth boundaries

    16.1 Honest negatives are protocol results

    A mature evidence system should be able to say not only what succeeded but what has not happened. The binder explicitly requires these negatives to remain load-bearing. [31]

    16.2 `basin_drained` has not fired live

    The 213-row ledger contains no live basin_drained event. The one drain reference is orchestration prose within a cradle_stable row. The live-fire implementation keeps the relevant guard false by construction.

    The correct claim is:

    The basin is a law with one deep live exercise and a per-tic ambient presence in the economy's cradle fields. Its drain path is implemented and smoke-tested, not live-proven.

    16.3 Rollback refusal has been armed but not needed

    rollback_hold fired zero times in 213 ledger rows. Five armings recorded ratio=1.5 and verdict=passing. The refusal path exists and is tested, but no live event required it. [BND-22]

    A gate does not need to refuse in order to exist. It does need evidence that the refusal path is reachable under its declared conditions. The current evidence supports built, armed, and not yet needed, not live-refusal proven.

    16.4 Campaign vocabulary does not prove WinchDial traversal

    No campaign wave is proven to have run through the WinchDial code path. The campaign lawfully uses the GUNSLINGER tempo vocabulary, but its receipts do not include basin, rollback, or residue events sufficient to prove code-path traversal. [31]

    This is an important noncollapse boundary:

    shared doctrine or vocabulary
    != shared executable path

    16.5 Fixture-green does not prove liveness

    H1's 43 arms were deliberately unwired at first. The a0 validator was not yet attached to a call-site gate. The basin drain path was smoke-tested but not live. A doctrine packet was delivered but not consumed. [BND-16, 37]

    Each state is real. None may impersonate the next.

    16.6 Simulation is not external effect

    The economy is SimOnly. The epoch16 model path produced proposals with mutation_authority=false. The local lap produced a bid, not a canonical move. [BND-02, BND-11, 33]

    Naming these lanes live without their qualifiers would be precisely the misrepresentation PHS is designed to prevent.

    16.7 The binder is not primary authority

    The binder is intentionally a map. It is comprehensive, readable, and citation-addressable. It still does not replace the extracts or primary receipts. [31]

    This paper's Appendix F preserves the BND markers for traversal. A release intended for external technical audit should ship the extracts and the primary artifacts or provide stable, access-controlled equivalents.

    16.8 Currentness is per observation

    The t748 affordability report measured an M2 Max, 32 GiB unified memory, a 24.96 GiB Metal working-set budget under the current default, 15 GiB of internal disk headroom, and 407 GiB on the T7. It also found stale catalog entries, absent base weights behind prior serve receipts, unregistered models, and a path probe that underreported installed runtime binaries. [36]

    The report then received corrections at tic 751 because one disk figure had been interpreted at the wrong layer. The correction is not a defect in reporting currentness. It is evidence that currentness itself is an observation subject to instrument choice and later adjudication.

    16.9 Delivery is not consumption

    The a0 estate memo says this explicitly. A validated doctrine packet crossed the membrane and was delivered byte-identically, but the estate had not yet consumed it. The recovery condition became curable, not cured. [37]

    PHS generalizes the boundary:

    distributed != retrieved
    retrieved != consumed
    consumed != adopted
    adopted != effective

    17. Relationship to the Ubiquity corpus

    17.1 Ubiquity: constitutional substrate

    Ubiquity supplies the parent governance direction: preserve agency, authorship, judgment, and meaningful contribution as AI-mediated capacity increases. It treats governance as substrate rather than a layer added after reasoning. [1-4]

    PHS contributes one protocol within that substrate. It does not claim to be the whole Ubiquity architecture.

    17.2 Fractal Quivers of Quivers: lawful and forbidden motion

    FQoQ supplies the living topology of entities, typed edges, authority, standing, cost, anchors, forbidden paths, absorbers, receipts, and telos. [6]

    PHS uses this substrate to treat proof, succession, and admission as different edge classes rather than one status field.

    17.3 Computing Around the Open Center: bounded local computation

    The open-center paper supplies the splat as a bounded local field carrying facets, exclusions, receipts, dependencies, hypotheses, and unresolved state. [7]

    A PHS epoch is splat-like: it closes a declared local proof scope without claiming the working center as universal truth.

    17.4 FORKED: horizon integrity and suspension mechanics

    FORKED supplies governed horizon geometry and the rule that authority, evidence, and success do not silently transfer across horizons. It also makes cables, winches, clamps, absorbers, fuses, and DAG-of-DAG correction explicit in a suspension-lattice context. [5]

    PHS's native move is to select the earliest lawful knowledge horizon as the proof partition key and derive carrier recursion from immutable causal order.

    17.5 Context Grapple Gun: reviewed judgment lifecycle

    Context Grapple Gun implements capture, human review, scoped promotion, and hydration without confusing rendered context with constitutional source of truth. [9] Cognitive Pull Requests supplies a related reviewable seam for AI-assisted change, while Trust as Behavior places evidentiary weight on observed conduct rather than title or fluent assertion. These are adjacent governance mechanics, not aliases for PHS: PHS supplies the temporal subject, horizon, carrier, and recursive checkpoint law that can govern such seams. [29,30]

    PHS can supply stronger proof semantics for the transitions inside such a lifecycle: exact subject, proof class, authority ceiling, correction relation, carrier, and next horizon.

    The tic-749 dry run and crank-2 re-freezing sequence are concrete examples of reviewed publication state remaining bound to an exact commit. [34,35]

    17.6 Human judgment: edge of earned trust

    Prompted LLC's public doctrine treats human judgment as reusable structure rather than permanent per-action approval. [8]

    PHS supplies the evidence boundaries that let a system know where judgment is still required. Novelty, irreversibility, authority ambiguity, weak behavior history, cross-horizon movement, and unresolved dissonance can all keep the human edge open.

    17.7 Look-First: custody at overwrite

    Look-First requires an actor to reattach to canonical state before acting on it. [10]

    PHS operationalizes that custody at subject selection, correction, carrier creation, and terminal reconciliation. The read is not permission; it is ownership of the state transition.

    17.8 Successor topology: continuity without implementation identity

    Successor topology preserves purpose, invariants, apophatic boundaries, scars, proofs, and attribution while permitting implementation, provider, model, repository, and runtime replacement. [11]

    PHS is compatible with this FROG_LEAP logic. A successor carrier or implementation may preserve the protocol's identity without inheriting every prior body. Provenance does not imply parentage, standing transfer, compatibility, or support obligation.

    17.9 The autoimmune governance apparatus

    A contemporaneous tic-748 memo described Ubiquity's differentiation as an apparatus in which load-bearing claims remain coupled to falsifiers and where blind readers re-derive them. It also named the uncomfortable boundary: much of the machinery was consumed by itself, and the outside-reader test remained open. [32]

    The memo is not independent evidence of uniqueness. It is valuable as an internal articulation of the telos that PHS later formalized: the thing that catches the system lying must be part of the organism, and its result must be capable of changing the organism.

    18. Relationship to adjacent technical work

    PHS uses existing primitives and can integrate with existing standards. Its contribution lies in the control law that orders them.

    18.1 Git commits, branches, refs, worktrees, and notes

    Git provides immutable content-addressed objects, a commit graph, refs, remotes, worktrees, and notes. [16-19]

    None of these mechanisms individually partitions checkpoint evidence by temporal attainability, requires orthogonal proof fan-out over one fixed subject, converges receipts under one admission authority, preserves held residue, and recursively treats the carrier as a new proof subject.

    PHS is not a replacement for Git. It is a protocol implemented over and beyond Git's storage and transport semantics.

    18.2 in-toto and supply-chain attestations

    in-toto records what steps were performed, by whom, in what order, and with what materials and products. Its statement and link models are natural encoding surfaces for PHS receipts. [20]

    PHS adds an explicit checkpoint topology: horizon partition, serial canon, zero-authority proof lanes, governed join, recursive carrier proof, correction conservation, residue visibility, and deterministic re-entry.

    18.3 SLSA provenance

    SLSA provenance describes where, when, and how an artifact was produced and supports downstream verification and rebuilding. [21]

    PHS can use SLSA provenance as a source or build receipt. It does not treat provenance as complete checkpoint closure unless the required horizons and authority predicates also pass.

    18.4 Reproducible Builds

    Reproducible Builds defines conditions under which the same source, environment, and instructions recreate bit-identical artifacts. [22]

    PHS treats reproducibility as one possible proof shard. It additionally governs target availability, receipt carriage, authority, correction, cross-horizon movement, and recursive closure.

    18.5 Artifact attestations and transparency logs

    GitHub artifact attestations can establish build provenance for binaries and containers. Rekor records signed supply-chain metadata in a tamper-resistant transparency log. [23,24]

    These systems strengthen authenticity, availability, and non-repudiation. They do not by themselves define which artifact may lawfully carry which future observation or which lane controls canonical mutation.

    18.6 SCITT

    SCITT defines signed statements, transparency services, verifiable data structures, registration policies, and receipts over a linear, irrevocable history. [25]

    SCITT is close to PHS in its concern with statements, registration, and receipts. PHS contributes a separate control law for selecting proof horizons, sharding observations over one exact subject, preserving class distinctions, recursively checkpointing the carrier, and retaining one canonical admission path.

    A SCITT receipt can be a PHS evidence object. It is not automatically a complete PHS epoch.

    18.7 RATS and conceptual message wrappers

    The RATS architecture separates Attesters, Verifiers, Relying Parties, Evidence, Attestation Results, Endorsements, Reference Values, and appraisal policies. The Conceptual Message Wrapper provides typed containers for those message classes. [26,27]

    PHS can use RATS evidence and attestation results inside proof shards. Its additional concern is temporal carriage and canonical convergence across a sequence of changing subjects.

    18.8 Single-writer systems and distributed consensus

    PHS shares the consistency intuition of single-writer systems: one logical path serializes accepted mutation.

    It differs from distributed consensus systems because its primary goal is not to let several authorities vote on the next canonical state. It scales observers, challengers, reproducers, and custodians while deliberately refusing to multiply canonical writers.

    18.9 Comparative boundary

    System or primitiveExact subjectParallel evidenceExplicit authority ceilingHorizon noncollapseDescendant carrier recursionVisible correction residueSerial canonical admission
    Git aloneyespossiblenononopartialpolicy-dependent
    in-totoyesyespartialnonopossibleexternal
    SLSA provenanceyesbuild-focusedbuilder modelnonopossibleexternal
    Reproducible Buildsyesyesexternalnonopossibleexternal
    SCITTyesyesregistration policypartialstatement/receipt chainappend-onlyservice-specific
    RATSyesyesrole-separatedpartialmessage flow, not PHS recursionpossiblerelying-party-specific
    Ubiquity/FORKEDyesyesyesyesbroader carrier mechanicsyesyes
    PHSyesyesyesyes, temporal-evidentiaryrequired when later carrier proof mattersrequiredone logical path

    The table is a functional comparison, not a claim that adjacent systems cannot be profiled to implement PHS.

    18.10 Originality boundary

    A bounded review found precedents for individual ingredients: single-writer systems, clean-clone testing, provenance, attestations, trunk-centered development, remote mirrors, transparency logs, role-separated attestation, append-only receipts, DAG scheduling, and human approval gates.

    The claimed PHS contribution is the complete relation:

    inherited horizon noncollapse
    + earliest lawful knowability as partition key
    + exact immutable subject
    + orthogonal proof fan-out
    + zero-authority proof lanes
    + governed fan-in
    + descendant evidence carrier
    + recursive carrier checkpoint
    + serial canonical admission
    + correction and residue conservation
    + deterministic re-entry

    The review does not establish that no private, unindexed, or differently named predecessor exists. It is not a formal patent prior-art search.

    19. Origin, attribution, and invention method

    19.1 Canonical attribution

    Breyden E. Taylor designed Proof-Horizon Sharding at Prompted LLC as part of the Ubiquity architecture's attempt to coordinate increasingly capable human-and-agent systems without collapsing authorship, judgment, correction, or canonical authority.

    The governed-horizon invention is upstream. It is expressed in FORKED's horizon geometry and horizon-noncollapse doctrine. PHS's native invention is the recognition that proof itself should be partitioned by the earliest horizon of lawful knowability and that this rule requires descendant evidence carriers and recursive carrier checkpoints.

    The canonical attribution statement is:

    Breyden E. Taylor designed Proof-Horizon Sharding, a temporal evidence protocol that partitions verification according to when and through what independent path each claim can lawfully become knowable. The method serializes canonical mutation through one authoritative lane, fans an immutable subject into orthogonal proof shards, converges those observations into a lineage-bearing descendant carrier, and recursively checkpoints that carrier without allowing it to attest to its own future state. The work inherits the broader governed-horizon and horizon-noncollapse primitive developed in Taylor's Ubiquity architecture and expressed through FORKED. Its operational discovery lineage includes the covenant, Harpoon, cable, board, winch, basin, anchor, receipt, and correction machinery documented in THE BINDER.

    19.2 Invention through constraint architecture

    The method emerged through an apophatic design process. Taylor designed a context assembly and execution environment that repeatedly enforced a perimeter of invalid states:

    • no self-attestation;
    • no coherence-as-admission;
    • no proof-class collapse;
    • no horizon-authority laundering;
    • no branch or projection authority ambiguity;
    • no hidden local-state dependence;
    • no fixture-as-live misstatement;
    • no vacuous green on missing consumers;
    • no observer artifact suppressing the observed;
    • no unsupported maturity uplift;
    • no source-to-deployment or deployment-to-outcome laundering;
    • no narrative erasure of correction;
    • no reliance on private session memory for continuation;
    • no striking or crowning of the excluded center.

    Under that perimeter, the lawful residual architecture required proof to follow epistemic dependency. The source had to exist before post-source facts could be observed. Orthogonal observations could proceed in parallel. A later object had to carry them. That object could not certify its own future. Authority had to remain serial while observation fanned out. Held identities had to remain visible. Missing consumers had to block vacuous closure.

    The architecture was not selected because it made a clean diagram. It was forced by repeated refusal of invalid closure.

    19.3 The role of THE BINDER

    The binder did not invent PHS. It reconstructed the operational lineage after the machinery had accumulated enough receipts to be traversed as history.

    Its contribution to this revision is threefold.

    First, it showed that many apparently separate names belonged to one current-to-target loop.

    Second, it exposed the negative evidence required to describe the machinery honestly.

    Third, it located the horizon-quiver self-falsification as the clearest concrete bridge between upstream horizon geometry and the PHS-native evidence law.

    Because the binder is a map, the paper preserves its markers rather than treating its prose as the last evidentiary word.

    19.4 AI assistance and human authorship

    AI systems assisted with context compilation, source inspection, evidence extraction, implementation, analysis, drafting, citation checking, and document production under Taylor's author-defined problem frame, constraints, terminology, architecture, and attribution boundary.

    The binder itself records a two-miner extraction and one-seat composition method. [31]

    The assistance functioned as instrumentation within the invention and publication process. It is not the claimed inventive contribution. The author determined the problem, apophatic perimeter, lineage, governing relations, acceptance criteria, and final account.

    This distinction is consistent with the protocol's own authority model: generation is not admission, and fluent output is not evidence of authorship or correctness.

    19.5 Prompted LLC's role

    Prompted LLC is the originating organization, builder and operator of the Ubiquity substrate, publication context for the parent papers, and rights holder named across the current public registry. Its machine-readable surfaces identify Breyden Taylor as author and founder and preserve canonical citation strings, file identities, status, and rights. [1-3,12,13]

    This protocol paper is a Prompted LLC paper. Prompted Forge's role belongs to the separate implementation paper and does not alter the protocol's authorship or organizational origin.

    20. Limitations and open work

    20.1 Stable receipt specification

    A stable specification should define subject bindings, horizon identifiers, predicate digests, environment descriptors, independence levels, standing, authority ceilings, nonclaims, residue, correction links, joins, and convergence rules.

    Compatibility profiles could map these fields into in-toto, SLSA, DSSE, SCITT, RATS, OCI attestations, Git commits, databases, or other carriers.

    20.2 Binder primary-source closure

    The binder's two lane-complete extracts and the primary receipts they index should be included in a publication-grade audit package or exposed through stable controlled access. This revision preserves the evidence map but does not independently re-open every primary artifact.

    A future conformance audit should reproduce every BND landmark from the cited source, check its hash, and state any divergence from the binder.

    20.3 Independence levels

    The protocol needs a graded vocabulary for independence: clean directory, clean clone, isolated container, separate host, separate account, separate organization, separate trust root, or formally diverse implementation.

    Each level detects different failure classes. A receipt must not use the unqualified word independent when the boundary is narrower.

    20.4 Trusted time and causal ordering

    Repository ancestry provides partial causal order, but cross-system evidence may require signed time, append-only logs, monotonic sequence numbers, trusted hardware, or transparency services.

    A formal model should state when ancestry is sufficient and when stronger time evidence is required.

    20.5 Canonical authority succession

    A singular logical writer requires succession policy. Future work should define emergency transfer, quorum-backed authorization behind one logical lane, compromise recovery, and proof of lawful authority change without creating competing canons.

    20.6 Privacy-preserving proof

    Receipts can expose sensitive paths, identities, configurations, prompts, customer information, or results. High-assurance profiles may require selective disclosure, encrypted evidence, redacted manifests, commitments, or zero-knowledge methods.

    20.7 Formal verification

    The invariants can be represented as a state machine or temporal logic specification. Formal verification could establish:

    • no self-attestation;
    • no unauthorized admission;
    • no untyped horizon promotion;
    • deterministic next-horizon selection;
    • preservation of correction lineage;
    • residue visibility;
    • projection nonauthority;
    • anti-vacuity;
    • termination conditions for bounded epochs.

    20.8 Predicate quality

    PHS can faithfully carry weak proof. The protocol does not automatically know whether a predicate is sufficient.

    Domain-specific work remains necessary for coverage, falsification, adversarial testing, calibration, safety cases, and external validity.

    20.9 Empirical evaluation

    Future studies should compare conventional and PHS workflows on:

    • proof throughput;
    • join latency;
    • re-entry time after interruption;
    • false-closure reduction;
    • hidden-dependency discovery;
    • correction debt;
    • falsification rate;
    • residue visibility;
    • audit reconstruction effort;
    • human judgment load;
    • canonical-writer count;
    • deployment and outcome claim accuracy.

    The binder and August 2026 Forge history offer a longitudinal case study, not a controlled experiment.

    20.10 Winch-mode evaluation

    GUNSLINGER has a substantial operational history in the supplied evidence. HIDALGO has one recorded live classification. The relationship between tempo, defect discovery, join latency, residue, and correction cost remains open.

    The campaign's tempo vocabulary should not be treated as proof that every wave traversed the same WinchDial implementation.

    20.11 Dissonance-basin evaluation

    The basin law requires deeper live evaluation. The current record supports one deep measured exercise, smoke-tested drain behavior, and ambient use in the simulated economy. It does not support a claim that live drain events have operated at scale.

    20.12 Non-Git implementations

    The broader claim should be tested over database migrations, infrastructure state, model registries, policy execution, media pipelines, legal instruments, clinical workflows, scientific experiments, and supply-chain custody.

    Git is a strong first substrate because its objects make temporal and causal boundaries visible. It is not the only possible one.

    20.13 Prior-art and standards review

    The adjacent-work review is bounded. A formal prior-art search should include distributed systems, event sourcing, formal methods, safety cases, scientific provenance, chain of custody, legal execution, remote attestation, temporal databases, and autonomous-agent governance.

    21. Conclusion

    Proof-Horizon Sharding begins from two inherited refusals, one lived machinery, and one specialized consequence.

    The first refusal, inherited from Ubiquity and FORKED, is that authority, evidence, and success do not silently collapse across horizons.

    The second is that possessing, rendering, or locally executing canonical state does not confer canonical jurisdiction.

    The lived machinery binds a current-to-target pull through covenants, strikes it into shape, routes work and contradiction through cables, compiles admitted dependencies into DAGs, raises ready work through a winch, preserves dissonance and residue in basins, keeps the center excluded, and carries results in receipts.

    The specialized consequence is that an immutable artifact cannot truthfully claim knowledge of an event that had not occurred when it was created.

    From those constraints follows a complete control law.

    Canonical mutation remains serial. Proof acquisition becomes parallel. Evidence is bound to exact subjects. Distribution and reproduction remain orthogonal. Receipts converge without losing their class. A descendant carrier preserves predecessor evidence and then becomes a new proof subject. Synchronized repositories preserve canon without multiplying authority. Missing consumers block vacuous closure. Held identities remain visible. Failures remain legible. Corrections survive. A successor resumes from the first required unproven horizon.

    The decisive proof is that the apparatus can govern itself. A probe named for detached reproduction made no remote contact and therefore refused the rung promised by its own name. The system preserved a lower evidence rank instead of laundering intent, coherence, or implementation presence upward. [BND-16]

    The deeper operating result is not uninterrupted correctness. It is correction metabolism. The apparatus overturned stale assessments by execution, exposed false green states, separated observation keys from observed events, recorded later corrections without retconning prior rows, and allowed bounded citizens to falsify the lead premise in every measured campaign wave.

    The result is a temporal evidence layer over content-addressed history and, more generally, a primitive for correction-surviving, proof-carrying canonical computation.

    You can coordinate unbounded parallel reasoning around bounded serial truth.

    Many actors may propose. Many may inspect. Many may reproduce. Many may challenge. Many repositories may preserve. Many agents may continue. Many cables may pull. Yet every accepted transition retains one intelligible place in causal, evidentiary, and authority history.

    That is the capability PHS enables:

    Distributed execution, verification, custody, and falsification can scale independently while canonical state remains serial, temporally honest, reproducible, correction-bearing, and deterministically resumable.

    Appendix A. Protocol pseudocode

    The following pseudocode expresses the PHS control law after integration of the binder-derived operating mechanics. It is normative at the level of ordering and invariants, not at the level of function names or storage technology.

    function run_phs_epoch(candidate, policy, current_canonical_state):
        # LOOK-FIRST: establish the current reference frame before proposing change.
        preimage = observe_exact_current_state(current_canonical_state)
        assert preimage.identity_is_exact
        assert preimage.authority_source_is_named
    
        # COVENANT: bind a bounded current-to-target pull without treating telos as a node.
        covenant = bind_covenant(
            current=preimage,
            target=policy.declared_target,
            scope=policy.scope,
            standing=policy.standing,
            authority_ceiling=policy.authority_ceiling,
            success_predicate=policy.success_predicate,
            failure_predicate=policy.failure_predicate,
            nonclaims=policy.nonclaims,
            center_exclusion=policy.center_exclusion,
            rollback_policy=policy.rollback_policy
        )
    
        h0 = disposition(candidate, covenant.admission)
        if h0 != ADMITTABLE:
            return preserve_receipt(
                horizon=H0,
                subject=candidate,
                result=h0,
                next_horizon=correct_or_hold(h0)
            )
    
        # STRIKE: derive a bounded shape; do not confuse shape with admission.
        strike = six_ray_strike(candidate, covenant)
        assert strike.center_was_not_crowned
        assert strike.claims_do_not_exceed_source
    
        # BOARD: compile only admitted covenants and exact dependencies.
        board = compile_board(
            covenant=covenant,
            strike=strike,
            anti_vacuity=true,
            missing_state_is_non_executable=true
        )
        assert board.center_exclusion_check == GO
        assert board.admitted_intersection_exec_ready_is_explicit
        assert board.excluded_exec_ready_identities_are_named
    
        # H1: select and materialize the exact immutable source subject.
        S = materialize_immutable_subject(board.admitted_candidate)
        assert exact_identity(S)
        record(horizon=H1, subject=S, covenant=covenant, board=board)
    
        # WINCH: select tempo without altering authority or evidence semantics.
        mode = select_winch_mode(policy.tempo)
        assert mode in {GUNSLINGER, HIDALGO}
    
        if mode == GUNSLINGER:
            executable = all_independent_exec_ready_cables(board)
        else:
            executable = next_staged_lock(board, residue_shape=board.current_residue)
    
        # PROOF FAN-OUT: proof workers may observe, never self-admit.
        required = policy.required_proof_shards(S)
        proof_lanes = create_zero_authority_lanes(
            subject=S,
            predicates=required,
            authority_ceiling=OBSERVE_AND_RECEIPT,
            convergence_destination=board.join
        )
        receipts = parallel_map(proof_lanes, lane -> run_shard(lane))
    
        # Preserve all results, including failure and indeterminate states.
        for R in receipts:
            assert R.subject_id == id(S)
            assert R.observed_after_subject_creation
            assert R.actor_authority <= R.authority_ceiling
            assert R.claim_class == R.horizon
            assert R.nonclaims_are_explicit
            preserve_receipt(R)
    
        # BASINS: unresolved tension and blocked identities stay visible.
        basin = hold_dissonance_and_residue(
            failed_or_held=required_not_passed(receipts),
            excluded_identities=board.excluded_identities,
            minimum_residual=policy.minimum_residual
        )
        assert basin.never_silently_drops_identity
        assert basin.drain_does_not_collapse_tension_to_zero
    
        if any_required_failed_or_held(receipts):
            preserve_failure_lineage(S, receipts, basin)
            return HELD(
                subject=S,
                completed=passed_receipts(receipts),
                pending=required_not_passed(receipts),
                residue=basin,
                next=earliest_required_unproven_horizon(receipts)
            )
    
        # H3: observations become durable only in a lawful descendant carrier.
        K = create_descendant_carrier(
            predecessor=S,
            receipts=receipts,
            covenant=covenant,
            residue=basin,
            join=board.join
        )
        assert all(K.claims).observed_before(t_create(K))
        assert not K.claims_its_own_future
        record(horizon=H3, subject=K, predecessor=S)
    
        # H4: carrier recursion. The carrier is now the subject.
        carrier_receipts = run_required_carrier_proofs(
            subject=K,
            policy=policy.carrier_policy,
            authority_ceiling=OBSERVE_AND_RECEIPT
        )
        for KR in carrier_receipts:
            preserve_receipt(KR)
    
        if any_required_failed_or_held(carrier_receipts):
            preserve_failure_lineage(K, carrier_receipts)
            return HELD(
                subject=K,
                completed=passed_receipts(carrier_receipts),
                pending=required_not_passed(carrier_receipts),
                next=earliest_required_unproven_horizon(carrier_receipts)
            )
    
        # H5: one authority reconciles and admits only the earned horizon.
        assert terminal_reconciliation(
            source=S,
            carrier=K,
            source_receipts=receipts,
            carrier_receipts=carrier_receipts,
            board=board,
            covenant=covenant,
            policy=policy
        )
        assert no_untyped_cross_horizon_promotion()
        assert no_hidden_residue_inside_claimed_scope()
        assert projection_does_not_confer_authority()
    
        admit_canonical_successor(K, through=policy.serial_authority)
        return CLOSED(
            horizon=H5,
            subject=K,
            closed_scope=policy.declared_closure_scope,
            stronger_horizons_still_open=policy.explicit_successor_horizons
        )

    A.1 Re-entry procedure

    function reenter_phs_epoch(epoch_state):
        look = observe_exact_current_state(epoch_state.canonical_pointer)
    
        if look.identity != epoch_state.expected_preimage:
            return HELD(reason="preimage_moved", next="fresh-look-and-rebind")
    
        completed = validate_completed_receipts(epoch_state.completed_receipts)
        pending = required_minus_completed(epoch_state.required_receipts, completed)
    
        if pending is empty:
            return continue_at(epoch_state.next_declared_join_or_carrier_horizon)
    
        owner = earliest_causal_owner(pending)
        preserve(epoch_state.residue, epoch_state.dirty_set, completed)
        return dispatch(owner, exact_subject=epoch_state.subject)

    Finite re-entry does not mean that every recovery is cheap. It means that uncertainty is represented as an explicit missing or failed edge rather than as an unbounded requirement to reconstruct a prior agent's private mental state.

    A.2 Anti-vacuity procedure

    function anti_vacuity(board, claimed_predicate):
        consumers = discover_real_consumers_by_reading_execution_paths(board)
        if consumers is empty:
            return FAIL("no proved eater or enforcement call site")
    
        for consumer in consumers:
            state = read_consumer_state(consumer)
            if state is missing:
                return HELD("consumer state missing; non-executable")
            if not consumer.enforces(claimed_predicate):
                return FAIL("presence is not enforcement")
    
        return PASS

    This procedure is included because the board-compiler scar demonstrates that a declared integration can remain falsely green when no real consumer executes the declaration. [BND-08]

    Appendix B. Reference receipt and carrier schemas

    The schemas below are illustrative substrate-neutral profiles. Implementations may encode them in JSON, CBOR, DSSE, in-toto statements, SCITT envelopes and receipts, Git objects, append-only logs, governed database rows, or another durable format. The semantic requirements govern; the representation does not.

    B.1 Proof-shard receipt

    {
      "protocol": "proof-horizon-sharding/v1.2",
      "receipt_id": "phs-receipt-<stable-id>",
      "checkpoint_id": "phs-epoch-<stable-id>",
      "subject": {
        "type": "git-commit",
        "id": "<exact-object-id>",
        "tree_id": "<exact-tree-id>",
        "predecessor_id": "<optional-predecessor-id>",
        "correction_of": "<optional-failed-or-superseded-subject-id>"
      },
      "horizon": "H2b.independent-reproduction",
      "parent_horizon": "repository-source",
      "covenant": {
        "id": "<covenant-id>",
        "current_identity": "<preimage-id>",
        "target": "<bounded-target>",
        "center_exclusion": true,
        "success_predicate_digest": "sha256:<digest>",
        "failure_predicate_digest": "sha256:<digest>"
      },
      "predicate": {
        "name": "detached-clone-validation",
        "command_manifest": "sha256:<digest>",
        "expected": "all required checks pass",
        "anti_vacuity": {
          "consumer_required": true,
          "consumer_ids": ["<consumer-id>"],
          "enforcement_verified": true
        }
      },
      "observer": {
        "actor_id": "<verifier-id>",
        "standing": "<standing-at-this-horizon>",
        "environment_id": "<environment-id>",
        "independence_level": "clean-clone-separate-directory",
        "acquisition": "clone-from-declared-remote"
      },
      "causal_position": {
        "subject_created_before_observation": true,
        "observed_at": "<timestamp-or-monotonic-position>",
        "carrier_not_yet_created": true
      },
      "result": "pass",
      "evidence": [
        {"type": "log", "digest": "sha256:<digest>"},
        {"type": "test-report", "digest": "sha256:<digest>"}
      ],
      "residue": {
        "held_identities": [],
        "unresolved_tensions": [],
        "observer_artifact_occlusion_checked": true
      },
      "authority_ceiling": "observe-and-receipt",
      "mutation_authority": false,
      "nonclaims": [
        "does not prove deployment",
        "does not prove adoption",
        "does not prove business outcome"
      ],
      "convergence_target": "H3.receipt-carrier",
      "next_horizon": "H3.receipt-carrier"
    }

    B.2 Receipt/state carrier

    {
      "protocol": "proof-horizon-sharding/v1.2",
      "carrier_id": "<exact-carrier-id>",
      "carrier_type": "descendant-state-carrier",
      "predecessor_subject": {
        "type": "git-commit",
        "id": "<source-subject-id>"
      },
      "covenant_id": "<covenant-id>",
      "join": {
        "join_id": "<governed-join-id>",
        "required_receipt_ids": ["<receipt-1>", "<receipt-2>"],
        "receipt_digests": ["sha256:<digest-1>", "sha256:<digest-2>"],
        "all_required_present": true,
        "all_subjects_match": true,
        "all_temporal_relations_lawful": true,
        "all_authority_ceilings_respected": true
      },
      "claim_horizon": "H3.receipt-carrier",
      "claims": [
        {
          "claim": "declared remote refs exposed the predecessor subject",
          "supported_by": "<receipt-id>",
          "evidence_class": "distribution"
        },
        {
          "claim": "an independently acquired exact predecessor passed the declared predicate",
          "supported_by": "<receipt-id>",
          "evidence_class": "reproduction"
        }
      ],
      "residue": {
        "held_basin": [],
        "unresolved_tensions": [],
        "minimum_residual_preserved": true
      },
      "authority": {
        "admitted_by": "<serial-authority-id>",
        "authority_source": "<authority-source-id>",
        "projections_are_nonauthoritative": true
      },
      "nonclaims": [
        "does not prove the carrier's own later propagation",
        "does not prove deployment",
        "does not prove adoption",
        "does not prove outcome"
      ],
      "next_horizon": "H4.carrier-checkpoint"
    }

    B.3 Held-state receipt

    {
      "protocol": "proof-horizon-sharding/v1.2",
      "checkpoint_id": "<epoch-id>",
      "subject_id": "<exact-subject-id>",
      "state": "HELD",
      "failed_or_pending_horizon": "H2b.independent-reproduction",
      "reason_code": "predicate_failed",
      "completed_receipts": ["<receipt-id>"],
      "pending_receipts": ["<receipt-id>"],
      "held_basin": [
        {
          "identity": "<blocked-identity>",
          "reason": "<why-it-remains-visible>",
          "owner": "<causal-owner>",
          "reentry_condition": "<minimum-required-condition>"
        }
      ],
      "dirty_set": ["<changed-surface>"],
      "next_horizon": "<earliest-required-unproven-horizon>",
      "nonclaims": [
        "hold is not rejection",
        "completed sibling proof remains valid only for its exact subject",
        "no stronger closure is implied"
      ]
    }

    B.4 Winch-run receipt

    A PHS implementation using the binder's operating machinery may additionally carry:

    {
      "winch_run_id": "<stable-id>",
      "mode": "GUNSLINGER",
      "covenant_ids": ["<id>"],
      "source_subject_id": "<exact-id>",
      "exec_ready_ids": ["<id>"],
      "admitted_ids": ["<id>"],
      "dispatched_ids": ["<id>"],
      "excluded_exec_ready_ids": ["<id>"],
      "center_struck": false,
      "mutation_authority": false,
      "cradle": {
        "dissonance_basin_present": true,
        "residual_fraction": "<measured-or-policy-bound-value>",
        "rollback_drill_armed": true,
        "rollback_hold_fired": false
      },
      "result": "cradle_stable",
      "receipts": ["<receipt-id>"],
      "nonclaims": [
        "mode label does not prove traversal through a particular code path",
        "simulation does not prove external economic effect"
      ]
    }

    Appendix C. Conformance checklist

    An implementation conforms to the core PHS v1.2 protocol when every applicable question below can be answered yes, with evidence bound to the exact implementation version being evaluated.

    1. Is every proof receipt bound to one immutable or strongly identified subject?
    1. Is the current canonical preimage observed before candidate mutation begins?
    1. Is the candidate's current-to-target pull bounded by a covenant or equivalent contract?
    1. Does the covenant name scope, standing, authority ceiling, success, failure, and nonclaims?
    1. Is the invariant or center preserved as a reference frame rather than represented as an ordinary node that the work may rewrite?
    1. Is canonical mutation serialized through one logical authority path?
    1. Can proof workers observe and receipt without automatically acquiring admission authority?
    1. Are source existence, remote distribution, independent reproduction, carrier existence, deployment, adoption, and outcome represented as distinct evidence horizons?
    1. Is direct target readback distinguished from local cached or tracking state?
    1. Does reproduction acquire the exact subject without undeclared inheritance from the authoring environment?
    1. Are orthogonal proof shards allowed to run concurrently over one fixed subject?
    1. Must every required shard pass, or be explicitly waived by an authorized policy, before its observations enter an admitted carrier?
    1. Is a receipt carrier prohibited from claiming events that occurred after its creation?
    1. Does the carrier become a new proof subject when its own propagation, reproduction, execution, acceptance, or outcome matters?
    1. Are synchronized copies explicitly denied independent canonical authority?
    1. Do failed and corrected attempts remain bound to their original subjects and visible in lineage?
    1. Can a successor identify the first required unproven horizon without relying on private process memory?
    1. Does terminal closure state exactly which domain is closed and which stronger domains remain unproven?
    1. Does missing consumer or call-site state fail closed rather than defaulting to executable or green?
    1. Does the implementation distinguish presence of a validator from enforcement by a real consumer?
    1. Are identities that are executable but unadmitted explicitly excluded and preserved as residue rather than silently dispatched or dropped?
    1. Are blocked, null-covenant, or otherwise held identities visible in a held basin or equivalent state?
    1. Are observation keys and telemetry markers prevented from occluding or overwriting the events they are meant to observe?
    1. Are stale capability or currentness claims re-tested at the act when their truth can change with environment or time?
    1. Are exact subject changes re-frozen and re-receipted rather than silently inheriting approval from an earlier subject?
    1. Does the implementation carry honest negative results such as not-run, fixture-only, simulation-only, held, or armed-but-not-fired?
    1. If a tempo such as GUNSLINGER or HIDALGO is named, is that label kept separate from evidence that a particular implementation path actually executed?
    1. Does any dissonance-drain mechanism preserve a declared residual rather than flattening unresolved tension to zero?
    1. Does the rollback path exist and remain independently distinguishable from evidence that it has fired live?
    1. Are narrative or descriptive projections prevented from acting as law unless separately admitted?
    1. Are claims about external deployment, stakeholders, money, adoption, or outcome blocked unless their native evidence horizons close?
    1. Can an observer reproduce each published quantitative claim from a named instrument, receipt, or derivation path?
    1. Does the system preserve disagreement between independent readers as evidence rather than selecting the more convenient reading silently?
    1. Does a named proof tool earn its rung from evidence rather than from its identifier, intended purpose, or implementation presence?
    1. Can the system emit a lower-rank result when a higher-rank probe fails to contact the required surface?
    1. Is the final admission act performed by the actor or mechanism whose standing includes canonical convergence?

    A system that answers no to a required item may still use some PHS-compatible mechanisms. It should not claim conformance to the complete profile without naming the missing conditions.

    Appendix D. Selected glossary

    Admission. The governed transition by which candidate material becomes accepted state within a declared scope. Admission does not imply deployment, adoption, or outcome.

    Anchor. The preserved reference frame that makes a current-to-target comparison meaningful. In the binder's machinery the founding telos or frozen center is excluded from ordinary node mutation and checked by the compiler and runtime membrane.

    Anti-vacuity. The requirement that a declared check, validator, wire, or doctrine have a real consumer or enforcement path before it may count as operationally closed.

    Apophatic nonclaim. An explicit statement of what an artifact, receipt, actor, or checkpoint does not establish.

    Binder. In this paper, THE BINDER is a curated evidence map containing stable BND markers that resolve onward to extracts and primary artifacts. It is not itself promoted to primary-source authority.

    Board. The surface that compiles admitted covenants and dependencies into an executable DAG while applying admission, readiness, center-exclusion, and anti-vacuity rules.

    Cable. A bounded route through which work, proof, tension, or correction is carried around the excluded center. A cable has a subject, owner, predicate, authority ceiling, and convergence destination.

    Canonical projection. A synchronized or rendered copy of canonical state that does not independently decide what becomes canonical.

    Carrier. A durable successor object that transports evidence, state, lineage, receipts, or residue across a transition.

    Checkpoint epoch. A bounded interval from candidate disposition through the proof and carrier horizons required for a declared closure.

    Coherence-is-not-admission. The rule that a coherent, executable, or apparently complete candidate does not gain standing merely from those qualities.

    Covenant. A bounded current-to-target contract that names the pull, scope, authority, standing, success, failure, nonclaims, dependencies, and irreversible surfaces.

    Correction conservation. The property that correction adds a successor subject and new receipts without rewriting the earlier subject into a state it never occupied.

    Correction survival. The intelligibility of failed, held, corrected, and superseded attempts in later lineage.

    DAG. A directed acyclic graph encoding causal predecessors and lawful execution order for a bounded tranche. The DAG is a discharge structure, not the whole ontology or living field.

    Deterministic re-entry. Resumption from the first required unproven or failed causal edge using durable state rather than private process memory.

    Detached-clone reproduction. Acquisition and validation of an exact source subject in an environment that does not inherit undeclared mutable state from the authoring checkout.

    Dissonance basin. A tension reservoir that preserves unresolved contradiction during a raise and may drain part of that dissonance into work while retaining a nonzero residual.

    Evidence ceiling. The strongest conclusion supported by the exact available evidence.

    Evidence class. A non-interchangeable category such as source, distribution, reproduction, deployment, adoption, or outcome.

    Evidence shard. A bounded proof bundle confined to one subject, horizon, predicate, evidence surface, and authority ceiling.

    Falsifier. A consumer, probe, test, independent reader, or adversarial surface capable of disproving the claim it accompanies.

    Finite re-entry. See deterministic re-entry.

    Frozen center. The invariant reference point intentionally excluded from ordinary work-node mutation. “Open center” and “frozen center” emphasize different aspects of the same refusal: the center is not crowned by local work and is not struck as an ordinary target.

    GUNSLINGER. The all-ready tempo of the winch: all independently executable and admitted cables may fire under one shared cradle, with rollback machinery armed. GUNSLINGER is a tempo, not a separate authority class.

    Harpoon / six-ray strike. A bounded shape-production and falsification procedure that examines a thing through multiple declared rays before execution or admission. Strike quality does not itself confer canonical standing.

    HELD. A first-class nonterminal state in which one or more required conditions remain unresolved. A hold preserves completed evidence, the exact subject, causal owner, residue, and re-entry condition.

    Held basin. A graph-level store for blocked, excluded, null-covenant, or otherwise unresolved identities. It is distinct from the DissonanceBasin tension reservoir.

    HIDALGO. The staged-lock tempo of the winch. It throttles work according to residue shape and judged stage boundaries. HIDALGO is not the default and is not a third authority lane.

    Horizon. A bounded jurisdiction of telos, authority, standing, evidence, consequence, and closure. State earned at one horizon does not silently acquire standing at another.

    Horizon noncollapse. The FORKED rule that declarations, success, or authority at one horizon do not transfer to another without a typed and admitted cross-horizon edge.

    Hoist. The governed current-to-target raise in which admitted cables, dependencies, agents, gates, receipts, and correction machinery close a bounded loop.

    Join receipt. Evidence that all required fan-out lanes completed, retained their evidence classes, and were checked before convergence.

    Lawful knowability. The causal and evidentiary condition under which a fact can first be truthfully observed and attributed.

    Look-First. The discipline of reattaching to exact current canonical state before proposing, mutating, or overwriting.

    Monotonic evidence. The addition of bounded observations about an exact subject without rewriting what earlier subjects could know.

    Nonclaim. An explicit denial of a stronger unsupported implication.

    Observer-artifact occlusion. A failure in which a marker, key, logging convention, or observation mechanism suppresses or overwrites the event it is intended to measure.

    Proof. Evidence satisfying a declared predicate for a bounded claim. It is not necessarily mathematical proof unless explicitly stated.

    Proof horizon. The strongest bounded claim supported by the exact available evidence at a causal position.

    Proof-Horizon Sharding. Partitioning checkpoint verification according to the earliest horizon at which, and the independent path through which, each fact can truthfully become known.

    Proof-only lane. A lane permitted to inspect and report but prohibited from mutating canonical source or admitting its own observation.

    Quiet point. A bounded state in which all predicates inside the claimed scope are satisfied and no hidden pending edge remains. It does not mean permanent completion.

    Receipt. A durable record binding a claim to its exact subject, predicate, method, observation, result, authority, limitations, residue, and next horizon.

    Receipt carrier. A descendant artifact that incorporates observations produced after the predecessor subject existed.

    Receipt recursion. The rule that a carrier may preserve evidence about its predecessor but cannot contain future observations about its own later state.

    Residue. The visible remainder of excluded, blocked, failed, unresolved, or deliberately unconsumed state after a bounded operation.

    Remote-ref readback. Direct observation of named refs on a target remote, compared against an exact selected subject.

    Serial authority. The rule that accepted canonical transitions enter through one ordered logical mutation path.

    Simulation-only. A live computational lane whose effects are confined to simulation and therefore do not establish external economic, provider, database, stakeholder, or outcome effects.

    Sniper. In the binder's adjudication, a range or precision register associated with GUNSLINGER language, not a third winch mode or independent mechanism family. [BND-09]

    Source-bearing subject. The immutable object that carries the selected source tranche whose later distribution and reproduction will be verified.

    Strike. The bounded shaping and adversarial examination of a candidate before or around execution. In the binder this is implemented through Harpoon's six-ray council.

    Temporal admissibility. The requirement that an observation exist before an artifact may lawfully carry it.

    Temporal self-attestation. The invalid implication that an immutable artifact can certify an event occurring only after it exists.

    Truth horizon. The boundary between what is currently established and what remains pending, held, intended, simulated, or unknown.

    Vacuous green. A passing status produced without a real consumer, enforcement path, required state, or meaningful predicate.

    Winch. The execution mechanism that raises admitted and executable cables according to a selected tempo under anchor, basin, rollback, and receipt constraints.

    Winching. The broader current-to-target motion performed by covenants, strikes, cables, boards, agents, basins, gates, and receipts. PHS governs what may be claimed about the motion and when.

    Appendix E. Lineage and claim register

    Claim or mechanicLineage classSourceTreatment in PHS v1.2
    Governance substrate for sovereign adaptive systemsInheritedPrompted LLC / UbiquityConstitutional parent
    Sovereignty as agency surviving amplificationInheritedSovereign ContinuityTelos and continuity condition
    Living lawful and forbidden traversalInheritedFractal Quivers of QuiversProof and authority graph substrate
    Open-center and splat mechanicsInheritedComputing Around the Open CenterBounded computation and scoped closure geometry
    Governed horizon geometryInheritedFORKEDParent horizon model
    Horizon noncollapseInheritedFORKEDGeneral rule specialized to evidence
    Look-First custodyInheritedPrompted LLC / Look-FirstExact preimage and correction discipline
    Human judgment as reusable structureInheritedPrompted LLC / UbiquityHuman authority at earned-trust edges
    Successor continuity without implementation identityInheritedSuccessor TopologyCanonical succession and provenance boundary
    Approval-loop limitsInherited adjacent doctrinePrompted LLCMotivation for bounded judgment rather than per-token supervision
    Cognitive Pull RequestsInherited adjacent doctrinePrompted LLCReviewable seam; not identical to PHS receipt topology
    Trust as behaviorInherited adjacent doctrinePrompted LLCReceipted conduct rather than role title
    Covenant / current-to-target pullOperational precursorUbiquity winching machineryPHS checkpoint scope and transition contract
    Harpoon six-ray strikeOperational precursorHarpoonv2 officeCandidate shaping and falsification surface
    Cable routingOperational precursorHoist / winch machineryBounded proof and work lanes
    Board-compiled DAGOperational precursorHoist machineryCausal ordering and convergence structure
    GUNSLINGER / HIDALGOOperational precursorWinch machineryTempo selection without authority promotion
    Dissonance basinOperational precursorWinch machineryTension and unresolved contradiction preservation
    Held basinOperational precursorCable latticeResidue and blocked-identity visibility
    Frozen-center exclusionOperational precursorHoist / open-center lineageAnchor-preservation invariant
    Receipt-bearing wave ledgerOperational precursorWinch historyCorrection-bearing evidence medium
    Temporal self-attestation problemPHS-native formulationPHSCore problem statement
    Earliest lawful knowability as proof partition keyPHS-nativePHSCore sharding rule
    Fixed-subject orthogonal proof fan-outPHS-native compositionPHSParallel verification topology
    Zero-authority proof lanesPHS-native compositionPHSObserver scaling without writer scaling
    Descendant receipt carrierPHS-native compositionPHSDurable carriage of later observations
    Recursive carrier checkpointPHS-native compositionPHSNo-self-attestation enforcement
    Correction conservationPHS-native derivationPHSFailure remains bound to original subject
    Deterministic re-entryPHS-native derivationPHSResume from first required unproven edge
    Anchor-preservation invariantPHS v1.2 formalizationBinder-integrated PHSReference frame remains outside ordinary mutation
    Residue-visibility invariantPHS v1.2 formalizationBinder-integrated PHSExcluded and blocked identities remain inspectable
    Anti-vacuity invariantPHS v1.2 formalizationBinder-integrated PHSPresence and declaration do not substitute for enforcement
    Observer-artifact non-occlusionPHS v1.2 formalizationBinder-integrated PHSObservation mechanism may not hide observed event
    Currentness-at-the-actPHS v1.2 formalizationBinder-integrated PHSRe-test mutable capability claims when action depends on them
    Honest-negative carriagePHS v1.2 formalizationBinder-integrated PHSNot-run, held, fixture-only, and simulation-only remain results
    Forge FIELD/DENT implementationDownstream implementationPrompted Forge implementation paperConcrete profile; does not originate protocol

    Appendix F. Binder evidence map

    This appendix reproduces the binder's 22 stable landmark identifiers as an evidence-navigation layer. The BND markers are not substitutes for primary receipts. They identify where a claim enters the binder's map and what role it plays in this paper. [31]

    MarkerBinder landmarkPHS relevanceRequired nonclaim
    BND-01t494 hoist covenant: 10 cables, 7 waves, 3 parallel invariants, center exclusion checkedEarly executable current-to-target covenant and DAG formDoes not establish all later winch or PHS behavior
    BND-02t535 live serve overturns t527 capability rulingCurrentness-at-the-act; execution may falsify assessmentProposal-only; mutation authority remained false
    BND-03159,382-trace corpus chain with reproducing partial sumsLongitudinal receipt continuity and exact re-derivationCorpus size is not capability, adoption, or quality
    BND-04t749 first governed local-model consumption; t751 refusal and corrected lapRefusal, correction, measured liveness, honest limitsSmall sample; plumbing proven more strongly than general capability
    BND-05t643 seven simultaneous office citizens; exact admitted-and-exec-ready intersectionParallel work without admission collapseSeven other executable but unadmitted identities remained excluded
    BND-06t650 S1-S7 raised in one tic; six null-covenant identities namedDAG-of-DAGs execution and residue visibilityNamed residue is not discharged work
    BND-07t512 BOOM seed raise and t559 7/7 verificationFull-cradle proof with center and mutation boundariesEarly wall-clock remains absent/unverified where the binder says so
    BND-08t621-623 live board compiler closes ~119-tic vacuous-green scarAnti-vacuity and real-consumer requirementPrior green doctrine claim was not operational proof
    BND-09Typed GUNSLINGER/HIDALGO dial and membrane testsTempo as explicit policy rather than proseSniper is not a third mode
    BND-10One live HIDALGO classificationResidue-shaped staged throttle existsOne event does not establish broad operational adoption
    BND-11202-tic simulated-economy GUNSLINGER run with center exclusionLong-running tempo and anchor exerciseSimOnly is not live money or external economic effect
    BND-12t568 collapse replay and first named breach flagInvisible failure made structurally visibleShadow replay is not proof of external economy behavior
    BND-13Harpoon charter's “master” verb falsified and rechartered to “metabolize”The mechanism survives correction of its own frameNarrative charter is design-intent evidence, not law by itself
    BND-14161 cable receipts and 68 drain receiptsReceipt density and row-level historical continuityCounts depend on the extract's named enumeration instant
    BND-15GUNSLINGER-BACKLOG waves 1-8; every measured wave falsified lead premiseFalsification as a designed property of governed parallelismCampaign vocabulary does not prove every wave used WinchDial code path
    BND-16Horizon quiver H0-H6; detached_reproduced probe refuses unsupported rungDecisive self-falsifying PHS construction eventLocal probe did not prove remote reproduction
    BND-17213-row append-only wave ledger with provenance correctionCorrections can be appended without retconning earlier eventSome rows lack independently verified wall-clock time
    BND-18t540 marker occlusion and __run__ key-space cureObserver artifacts must not occlude observed eventsCure is specific to the recorded failure class
    BND-19BR4 basin with named tensions and measured residual 0.45Dissonance preserved as inspectable stateOne deep exercise does not prove broad drain liveness
    BND-20Center exclusion enforced in three languagesAnchor-preservation doctrine-to-code chainMultiple checks do not prove every consumer invokes them
    BND-21Epoch05 “pinky”: 41 steps, 48 seconds, one branchRepair cost shifts into prior anchor structureHistorical event does not establish universal repair economics
    BND-22Rollback gate armed five times, zero refusals in 213 rowsArmed-but-not-fired is a valid evidence classExistence and smoke tests do not equal live refusal use

    F.1 Binder use discipline

    The binder instructs writers to resolve BND markers through the binder, then the lane extracts, then primary artifacts; to prefer quoted primary fields on disagreement; and to retain honest negatives and truth boundaries as load-bearing content rather than editorial caveats. [31]

    This revision follows that discipline as far as the supplied materials allow. The two lane-complete extracts named by the binder were not included in the attachment set available to this drafting pass. Therefore the paper does not claim row-level independent verification of all 161 cable receipts, 68 drain receipts, 51 campaign files, 213 ledger rows, or 202 economy artifacts. Those totals remain binder-indexed claims pending direct primary-source closure.

    References

    [1] Prompted LLC. “Prompted LLC - Ubiquity, Context Grapple Gun, Corpus.” https://promptedllc.com/. Accessed September 4, 2026.

    [2] Prompted LLC. “Prompted LLC - Governance Substrate for Sovereign Adaptive Systems.” https://promptedllc.com/prompted-llc. Accessed September 4, 2026.

    [3] Prompted LLC. “Breyden Taylor - Founder, Prompted LLC.” https://promptedllc.com/founder. Accessed September 4, 2026.

    [4] Prompted LLC. “Sovereign Continuity - The Root Frame for Sovereign Adaptive Systems.” https://promptedllc.com/sovereign-continuity. Accessed September 4, 2026.

    [5] Taylor, B. E. (2026). FORKED - Observer-Indexed Reality, Suspension Lattices, and Mission-State Integrity (Version 2.0 foundational whitepaper). Prompted LLC. https://promptedllc.com/forked. Raw source: https://promptedllc.com/papers/forked-v2/PAPER.md.

    [6] Taylor, B. E. (2026). Fractal Quivers of Quivers - A Mathematical Substrate for Ubiquitous Agent Governance. Prompted LLC. https://promptedllc.com/fractal-quivers-of-quivers.

    [7] Taylor, B. E. (2026). Computing Around the Open Center: Splat Mechanics, Fractal Quivers of Quivers, and a Governance-Native Compute Paradigm (Version 1.0 preprint). Prompted LLC. https://promptedllc.com/computing-around-the-open-center.

    [8] Prompted LLC. “Human Judgment in AI Systems - Reusable Structure, Not a Bottleneck.” https://promptedllc.com/human-judgment-in-ai-systems. Accessed September 4, 2026.

    [9] Prompted LLC. “Context Grapple Gun - Portable Governance Lifecycle for Claude Code.” https://promptedllc.com/context-grapple-gun. Accessed September 4, 2026.

    [10] Prompted LLC. “Look-First - Reattach to Canonical State Before Acting.” https://promptedllc.com/look-first. Accessed September 4, 2026.

    [11] Prompted LLC. “Successor Topology - Ubiquity Canonical V2 Lineage Lock.” https://promptedllc.com/successor-topology. Accessed September 4, 2026.

    [12] Prompted LLC. agents.txt - Machine-Readable Agent Interface Specification, Version 4.1, updated August 21, 2026. https://promptedllc.com/agents.txt.

    [13] Prompted LLC. papers-registry.json, Schema prompted.papers-registry.v1, Version 1.3, updated July 29, 2026. https://promptedllc.com/papers-registry.json.

    [14] Taylor, B. E. (2026). Proof-Horizon Sharding: Correction-Surviving, Proof-Carrying Canonical Computation (Technical Whitepaper 1.1, Ubiquity Lineage Revision). Prompted LLC. Author-provided publication candidate, September 2026.

    [15] Taylor, B. E. (2026). Author-supplied GitHub Insights screenshots for forge-canonical-fed, covering Code Frequency and Pulse windows from August 1 through September 1, 2026. Unpublished operational evidence supplied with the predecessor revision.

    [16] Chacon, S., and Straub, B. “Git Internals - Git Objects.” Pro Git, 2nd ed. https://git-scm.com/book/en/v2/Git-Internals-Git-Objects.

    [17] Chacon, S., and Straub, B. “Git Branching - Remote Branches.” Pro Git, 2nd ed. https://git-scm.com/book/en/v2/Git-Branching-Remote-Branches.

    [18] Git Project. “git-notes Documentation.” https://git-scm.com/docs/git-notes.

    [19] Git Project. “git-worktree Documentation.” https://git-scm.com/docs/git-worktree.

    [20] in-toto Project. “Link Attestation Predicate, Version 0.3.” https://in-toto.io/attestation/link/v0.3.

    [21] SLSA. “Build Provenance, Specification Version 1.2.” https://slsa.dev/spec/v1.2/build-provenance. See also “Distributing Provenance.” https://slsa.dev/spec/v1.2/distributing-provenance.

    [22] Reproducible Builds Project. “Definitions: When Is a Build Reproducible?” https://reproducible-builds.org/docs/definition/.

    [23] GitHub. “Using Artifact Attestations to Establish Provenance for Builds.” https://docs.github.com/en/actions/how-tos/secure-your-work/use-artifact-attestations/use-artifact-attestations.

    [24] Sigstore. “Rekor Transparency Log Overview.” https://docs.sigstore.dev/logging/overview/.

    [25] IETF. RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains. Supply Chain Integrity, Transparency, and Trust (SCITT), June 2026. https://www.rfc-editor.org/rfc/rfc9943.

    [26] IETF. RFC 9334: Remote ATtestation procedureS (RATS) Architecture. 2023. https://www.rfc-editor.org/rfc/rfc9334.

    [27] Birkholz, H., Smith, N., Fossati, T., and Tschofenig, H. RFC 9999: Remote ATtestation procedureS (RATS) Conceptual Message Wrapper (CMW). IETF, July 2026. https://www.rfc-editor.org/rfc/rfc9999.

    [28] Prompted LLC. “Why AI Approval Loops Do Not Scale.” https://promptedllc.com/why-approval-loops-do-not-scale. Accessed September 4, 2026.

    [29] Prompted LLC. “Cognitive Pull Requests - Reviewable Seam for AI-Assisted Work.” https://promptedllc.com/cognitive-pull-requests. Accessed September 4, 2026.

    [30] Prompted LLC. “Trust as Behavior.” https://promptedllc.com/trust-as-behavior. Accessed September 4, 2026.

    [31] Prompted LLC / Ubiquity Federation. THE BINDER - A History of the Winching Machinery, with Receipts. Commissioned by Breyden E. Taylor; composed by ent_homeskillet, tic 770, September 4, 2026. Author-supplied evidence map. Stable landmarks BND-01 through BND-22. The binder declares itself a map resolving to lane extracts and primary receipts, not primary authority.

    [32] ent_homeskillet-f5. “The Secret and the Lever.” Memo to Breyden E. Taylor, tic 748, August 2026. Author-supplied internal governance memo.

    [33] ent_homeskillet-f5. “The Lap Ran.” Memo to Breyden E. Taylor, tic 749, August 2026. Author-supplied local-consumer execution report.

    [34] ent_homeskillet-f5. “Crank 1 - Result.” Memo to Breyden E. Taylor, tic 749, August 2026. Author-supplied dry-run publication receipt summary.

    [35] ent_homeskillet-f5. “Crank 2 - Staging.” Memo and correction chain to Breyden E. Taylor, tics 750-765, August-September 2026. Author-supplied exact-subject re-freezing record.

    [36] Task-scoped worker, dispatched by ent_homeskillet. “T7 Inventory and Affordability - Measured Not Assumed.” Tic 748 report with tic 751 corrections, August 2026. Author-supplied read-only survey and correction record.

    [37] ent_homeskillet. “State of the a0 Estate and the 16d Eval Arc.” Memo to Breyden E. Taylor, tic 738, August 26, 2026. Author-supplied state memo.

    [38] Taylor, B. E. (2026). The Forge Implementation of Proof-Horizon Sharding: FIELD/DENT DAGs, Guarded Convergence, and Recursive Checkpointing at Agentic Production Scale (Technical Whitepaper 1.0). Prompted LLC and Prompted Forge. Downstream implementation paper.

    Acknowledgment

    AI systems assisted with context compilation, source inspection, diagram production, editorial synthesis, citation checking, and document production under Breyden E. Taylor's author-defined problem frame, Ubiquity lineage, apophatic perimeter, evidence hierarchy, and protocol constraints.

    THE BINDER was composed by ent_homeskillet from two miner-citizen evidence extractions. This paper preserves the binder's own source ceiling: it uses the binder as a navigation and synthesis layer, does not silently promote its summaries to primary receipts, and names the missing lane extracts as open evidence closure.

    The authorship, architecture, governing relations, claim boundaries, acceptance criteria, and final publication authority belong to Breyden E. Taylor. Prompted LLC is the publication and rights context for this foundational protocol paper.

    Cross-citations in the authored corpus

    Declared relations to papers already in this record, each with the reason it is load-bearing. Companion apparatus citing peer papers. Nothing here places Frontier above any sibling paper, and nothing here places a sibling paper above Frontier; the papers register stays flat.