miscsubjectsAI governance
Object Invocation Protocol · protocol specification

Designer Legibility Policy — A8 Feature vs Operator Exposure

Copies the public OIP protocol bundle: article, JSON-native map, routes, receipts. No owner token.

§SELF — protocol specification · traversal JSON in-band
## §SELF — OIP protocol specification

**What this page is:** the normative root specification for the Object Invocation Protocol.

**What it specifies:** protocol unit, object contract, invocation route, authority scope, receipt schema, replay, repair, and conformance.

**Read:** https://miscsubjects.com/a/oip-designer-legibility-policy
**This page as JSON:** https://miscsubjects.com/api/articles/oip-designer-legibility-policy
**Machine bundle:** https://miscsubjects.com/api/articles/oip-designer-legibility-policy/bundle?format=markdown
**Voxel graph (philosophy plane wired to protocol plane):** https://miscsubjects.com/api/articles/oip/voxels
**Live object tree:** https://miscsubjects.com/api/dispatch?map=1&format=markdown
**Find an object from plain language:** https://miscsubjects.com/api/dispatch?ask=<what you want>
**Read one object:** https://miscsubjects.com/api/dispatch?key=<KEY>&format=markdown

**Proof rule:** an action is not proven by intent, description, or a 200. It is proven by the ledger and the OIP receipt for the invocation.

§SELF — oip-designer-legibility-policy

What this page is: the boundary A8 made necessary — what about the designer is deliberately legible vs incidentally leaked. What it explains: the philosophy mandates maker-through-artifact audit; it does not mandate doxxing the operator. Why read it: success of A8 is a personal risk if the line is default, not decision.

Deliberately legible (feature — A8)

  • Judgment and commitments encoded in system behavior (defaults, gates, refused actions).
  • Ought externalized as rules, risk ceilings, objection intake, kill switches.
  • Operating profile as orientation for authorized collaborators (?profile=1 class surfaces) — judgment, not street address.
  • Ledger of decisions (what the system did and denied) as audit of the maker's bled priorities.

Not intended as public legibility (incident / minimize)

  • Legal name in error strings, UI chrome, or public group selftest prompts ("Ask <owner name>") — hygiene: use role ("owner") unless the owner opts in.
  • Machine identity, local paths, schedule, precise location in public receipts or error text.
  • Private chat content and credentials.

Decision rule

QuestionDefault
Does revealing X help audit the ought?May be legible
Does revealing X mainly identify the person/device without aiding audit?Not public by default
Error stringsRole-based ("owner"), not personal name

Operator action

Owner may tighten further (strip profile fields, imessage gates). Philosophy says: legible judgment is the feature; incidental identity is a bug unless explicitly opted in.

Links

oip-designer-legibility-policy · posted 2026-07-15 · updated 2026-07-17
Ledger API & provenance
Provenance · 2 model passes · tokens/cost unrecorded · 2 models
chain head f7dc59ad67d01158
objection-pass-2 grok-build · 2026-07-15 06:28 · tokens unrecorded · 07e40e34f646
voxel_divide owner · 2026-07-17 02:36 · tokens unrecorded · f7dc59ad67d0
verify chain →
Live ledger · 28 payloads · 2 turns
recent activity · inspect
JCI_CLASSIFY jci · HTTP 200 · 2026-07-21 03:16
JCI_TRAFFIC jci · HTTP 200 · 2026-07-21 03:16
JCI_CLASSIFY jci · HTTP 200 · 2026-07-21 03:00
JCI_TRAFFIC jci · HTTP 200 · 2026-07-21 03:00
JCI_TRAFFIC jci · HTTP 200 · 2026-07-20 19:30
JCI_TRAFFIC jci · HTTP 200 · 2026-07-20 17:48
view full ledger & cards →
OIP REST + ledger
system shelf GET /api/dispatch?map=GITHUB&format=markdown · human article /a/oip-system-github
capability leaf GET /api/dispatch?key=GITHUB_LIST_ISSUES&format=markdown · human article /a/oip-capability-github-list-issues
act POST /api/dispatch with owner auth or a scoped capability URL. Public docs are open; mutating action is token-bounded.
token explain GET /api/dispatch?explain=1&share=TOKEN
receipt GET /api/dispatch?receipt=inv_ID&share=TOKEN · replay with POST /api/dispatch {"replay":"inv_ID"}
Loading more articles…