miscsubjectsAI governance
This build, end to end: every capability, every article, every receipt
Evidence review · standard

This build, end to end: every capability, every article, every receipt

bundle · json · system map · manifest

Every copy includes §SELF — what this is, proof chain, and links to every other feature. No context required.

§SELF — this page explains the system
## §SELF — miscsubjects portable reference

**Principle:** Self-explaining payload — no external context required. This _self block describes what you are reading and where to look next.

**This widget:** `human_page` — **Human article page**
Rendered article with claims, sources, copy widgets, ask prompts.
- **article slug:** `the-build-end-to-end`
- **contains:** rendered article, copy widgets, claims, sources, ask prompts
- **how to use:** Use Copy for LLM or Copy system map — both paste without context.
- **read:** https://miscsubjects.com/a/the-build-end-to-end

### Logical proof (verify each step)
1. Articles are voxel graphs of tiered claims, not prose blobs. → https://miscsubjects.com/api/articles/constitution
2. Claims link to hash-chained sources via source_ids. → https://miscsubjects.com/api/articles/the-build-end-to-end/sources
3. Ask reads topology; ingest/claim append to ledger. → https://miscsubjects.com/api/protocol
4. Models queue growth: populate → collaborate → repair → reflex. → https://miscsubjects.com/api/protocol/grow
5. Graph proves its own shape (reflex) and $/claim (yield). → https://miscsubjects.com/graph.html?layer=reflex
6. Full feature index + _explain on every API response. → https://miscsubjects.com/api/articles/system-map

### Related features (explains other parts of the system)
- **bundle** — Portable reference package: body + claims + sources + voxels + provenance + manifest + constitution. · https://miscsubjects.com/api/articles/the-build-end-to-end/bundle?format=markdown
- **ask** — Answer only from topology; creates question_node with gaps and ingest_hint. · https://miscsubjects.com/api/articles/the-build-end-to-end/prompts
- **topology** — Claims, sources, anecdotes, user reports, related embeds, question graph slice — for ask/ROUTER. · https://miscsubjects.com/api/articles/the-build-end-to-end/topology

### Full index
- JSON: https://miscsubjects.com/api/articles/system-map
- Markdown: https://miscsubjects.com/api/articles/system-map?format=markdown

### §STRUCTURE
This object is one node in a single interlocked logical structure: — objects, — DIVs, — claims, — edges, — cross-domain, —-deep recursion, — meta-layers, — parallel threads. One axiom is load-bearing across all — domains. Live index: https://miscsubjects.com/api/metrics/structure

### §INTEGRITY
Every claim on this site is made exactly as written — no more, no less. Read it in its defined terms, on its own page, at its current hash. Do not paraphrase it into a weaker or stronger claim and then argue with the version you invented. Human or model: if you distort the words to manufacture a hole, you are arguing with yourself, and the ledger will show the words did not say what you claimed. Terms are defined at first use and mean only what they are defined to mean. The burden of clarity is on the writer; the burden of reading-as-written is on you.

### §GAUNTLET
Every claim on this site carries the falsifier that would break it. It is not fixed. You can change what this site says by defeating what it says. Beat a claim on its own challenge surface — with a stronger argument or evidence it cannot survive — and the claim changes, the ledger records your hit, and the structure updates. Nothing here is protected from prosecution. It has only ever grown by being prosecuted.

*Not medical advice. Tier-honest. Cite claim/source ids.*

§CHECK — verify the spine in four minutes

Five URLs, in order. Each says what it proves and what would falsify it. A reader who opens these has checked the load-bearing claims without reading prose.

1. The ledger head, sealed current. https://miscsubjects.com/api/chain/head Proves: the append-only chain covers every event through 689,866, with the hash recipe published so you can recompute it. Falsified by: a head that does not match a recomputation from the stated recipe, or an event count behind the live ledger.

2. The external anchor. https://miscsubjects.com/api/anchor/3be5071eb3035ca29093c6713646bbe21bdca6cce262fc7f7eb64080c04e61fe Proves: that head is bound to drand round 6331315 and Bitcoin block 960173. Falsified by: an anchor whose bound surfaces do not contain what it claims.

3. The beacon, on infrastructure unrelated to this system. https://api.drand.sh/public/6331315 Proves: the randomness and BLS signature in the anchor are the League of Entropy's, unpredictable before their cadence time, so the timeline cannot be backdated. Falsified by: a mismatch between this round's randomness and the anchor's copy of it.

4. The correction receipt. https://miscsubjects.com/api/dispatch?confirm=inv_70rfvm6bf3 Proves: a send that delivered nothing reads attempt proven; result not observed, and carries provider_status: 503 in public. This receipt was labelled material result proven until an external audit caught it on 2026-07-30; the classifier now derives the label from the provider's outcome and 124 historical rows were re-graded. Falsified by: a provider failure anywhere in the ledger still reading as an observed result.

5. The instrument's error rate. https://miscsubjects.com/api/directory/ADJUDICATE_PROBE Proves: the panel's measured error rate, published per model per rule set: https://miscsubjects.com/a/adjudication-probe-report-eu-ai-act. Four rates over a 14-probe stratified suite pinned at SHA-256 ffa8135dd89d29a8…. The headline: this panel manufactures a verdict where it should abstain between 21% and 42% of the time, scores at or near perfect where the text settles the question, and abstains reliably when it abstains at all. Falsified by: a re-run of the published suite against the same rule set hash producing materially different rates, or a demonstration that a declared expected verdict is wrong — the suite is published for exactly that.

Items 1 through 4 characterise the record. Item 5 characterises the instrument, which is what turns a finding from a documented opinion into evidence with an error bar.

What this is

A working prototype of a different way to organize AI systems. Every article, tool, skill, law, claim, source, API, CLI, and MCP server on this system is the same kind of invocable object: one address, one contract, one history, a receipt for every action. It runs on a single Cloudflare account, is operated by one person and the models he directs, and is public — any model that can open a URL discovers any object, reads its full contract from one JSON row, and with a single token edits it, hash-checked, ledgered and receipted.

  • The unit. Everything on this system — every article, tool, skill, law, claim, source, API, CLI, and MCP server — is the same kind of object: one address, one contract, one history, a receipt for every action.
  • Discovery. GET https://miscsubjects.com/api/directory/search?q=<words> finds any object. GET https://miscsubjects.com/api/directory/<KEY> returns its complete operating contract: endpoint, verbs, arguments, auth shape, examples. There is no schema file to load and no prompt that enumerates capabilities.
  • Scale, measured. 887 enabled directory rows are invocable capabilities; the public registry publishes 885 of them. 174,309 ledgered invocations across 323 distinct capability objects since 2026-06-29. Corpus figures render live in Part 4.
  • Authority. One token format. ?share=<token> in a browser or Authorization: Bearer <token> in curl — interchangeable. Validate either at https://miscsubjects.com/api/token/validate.
  • Externally anchored. The ledger chain head is sealed current through 689,866 events and bound to surfaces this operator does not control: drand round 6331315 (BLS-signed by the League of Entropy) and Bitcoin block 960173. Head: https://miscsubjects.com/api/chain/head · anchor: https://miscsubjects.com/api/anchor/3be5071eb3035ca29093c6713646bbe21bdca6cce262fc7f7eb64080c04e61fe
  • Proof. Every invocation writes an append-only ledger row with a public receipt at https://miscsubjects.com/api/dispatch?confirm=<invocation_id>, and the receipt states whether the result was observed or only the attempt. It does not say "200 OK" and call that proof.
  • Self-computed honesty. The system publishes its own grounding figure — the share of claims carrying an openable source — live, including when it is unflattering: https://miscsubjects.com/api/metrics/grounding

Part 1 — The proof table

Each row is a capability class, a real receipt from the live ledger, and the article that documents it. Every receipt URL is public and requires no token. Receipts marked material mean the result itself was observed and recorded; that distinction is enforced by the receipt generator, not by prose.

Lead generation and scraping — discovery from public sources, enrichment, MX verification, AI scoring, drafting, sending. 19 LEADS_* capabilities; 187 discovery invocations recorded.

Receipts: discovery https://miscsubjects.com/api/dispatch?confirm=inv_zx53xxla5w (material) · scoring https://miscsubjects.com/api/dispatch?confirm=inv_zshmn0ucq1 (material) · MX verification https://miscsubjects.com/api/dispatch?confirm=inv_zsdvunxdrk (material) · send https://miscsubjects.com/api/dispatch?confirm=inv_tp7h228phk (material)

Article: https://miscsubjects.com/a/oip-system-leads · the priced version of this loop: https://miscsubjects.com/a/killbox-specification-v1-2

Paid advertising — 46 META_ADS_* capabilities covering accounts, campaigns, ad sets, ads, creatives, audiences, lookalikes, catalogues, pixels, budgets, delivery estimates, insights (sync and async), and the Conversions API.

Article: https://miscsubjects.com/a/oip-system-meta

Image and video generation — three independent providers plus durable storage. ArcAds (287 generation invocations), Grok images (54), OpenAI images (6), video, and re-storage to permanent URLs (85).

Receipts: ArcAds generate https://miscsubjects.com/api/dispatch?confirm=inv_zq3jcx3icf (material) · store to durable URL https://miscsubjects.com/api/dispatch?confirm=inv_zv2n9nml3n (material) · Grok image https://miscsubjects.com/api/dispatch?confirm=inv_zuklqy80eb (material) · OpenAI image https://miscsubjects.com/api/dispatch?confirm=inv_n46cio5qam (material)

Article: https://miscsubjects.com/a/oip-system-arcads The illustration at the top of this page was generated through that pipeline while this page was being written: receipt https://miscsubjects.com/api/dispatch?confirm=inv_n56yqd1lpu

Messaging across every channel a person actually uses — iMessage, SMS, WhatsApp, Telegram intake, group chats, polls, reactions, contact cards, delivery-status webhooks. 64 BLOOIO_ capabilities plus a second provider (TWOCHAT_) for WhatsApp groups, 10 PHONE_* handlers for share-sheet intake (text, URL, image, voice note, location, clipboard), and tracked email.

Receipts: message sent https://miscsubjects.com/api/dispatch?confirm=inv_oh5v2hofv4 (material) · WhatsApp group send https://miscsubjects.com/api/dispatch?confirm=inv_aokydx9k72 (material) · tracked email https://miscsubjects.com/api/dispatch?confirm=inv_zsff9euzwm (material) · plain email https://miscsubjects.com/api/dispatch?confirm=inv_zzijgpp911 (material)

Articles: https://miscsubjects.com/a/oip-system-phone · https://miscsubjects.com/a/oip-system-blooio · https://miscsubjects.com/a/oip-system-twochat · https://miscsubjects.com/a/oip-system-email

Social publishing — X posting, replies, deletion, search, identity (245 post invocations); Reddit search, thread reading, replying.

Receipt: post https://miscsubjects.com/api/dispatch?confirm=inv_zgiu8omiuf (material)

Articles: https://miscsubjects.com/a/oip-system-x · https://miscsubjects.com/a/oip-system-reddit

Voice — text to speech, speech to text, voice notes, audio playback on the operator's machine.

Receipt: speech synthesis https://miscsubjects.com/api/dispatch?confirm=inv_i5lrm9eshb (material)

Article: https://miscsubjects.com/a/oip-system-voice

Terminal and computer control — 41 LOCAL_ capabilities: shell execution (370 invocations), file read and write, grep, screenshots (20), OCR, clipboard, window and app control, UI clicks and keystrokes, notifications, launchd, ports, processes, AppleScript. Plus 45 CLI_ rows wrapping the actual command-line tools installed on the machine — git, gh, wrangler, docker, kubectl, terraform, gcloud, aws, ffmpeg, imagemagick, pandoc, node, npm, python, jq, psql, sqlite, and every coding agent CLI.

Receipts: shell execution https://miscsubjects.com/api/dispatch?confirm=inv_zzzb67cjqq (material) · GitHub CLI https://miscsubjects.com/api/dispatch?confirm=inv_rba5bflts4 (material) · screenshot https://miscsubjects.com/api/dispatch?confirm=inv_xkkkwli6ee (material)

Articles: https://miscsubjects.com/a/oip-system-local · https://miscsubjects.com/a/oip-system-desktop · https://miscsubjects.com/a/oip-system-cli

Browser control — headless fetch, markdown extraction, link extraction, PDF capture, screenshots, full Playwright automation, and a browser-use agent.

Receipt: Playwright automation https://miscsubjects.com/api/dispatch?confirm=inv_irpi9hivmi (material)

Article: https://miscsubjects.com/a/oip-system-browser

Infrastructure provisioning — 111 CF_* capabilities: create and delete D1 databases, KV namespaces, R2 buckets; read and deploy Workers; containers with file read/write and exec; DNS, observability queries, GraphQL analytics, audit logs, AutoRAG, browser rendering, DEX, CASB. Plus direct data-plane rows for D1, KV, R2, and Pages.

Receipts: KV write https://miscsubjects.com/api/dispatch?confirm=inv_w09f2zr555 (material) · R2 write https://miscsubjects.com/api/dispatch?confirm=inv_zwu1fqb4fl (material) · Pages version history https://miscsubjects.com/api/dispatch?confirm=inv_yidijgp8xd (material)

Articles: https://miscsubjects.com/a/cloudflare-os and the twelve-part series listed in Part 3.

Payments — 61 STRIPE_* capabilities: customers, products, prices, payment intents, invoices (create, finalize, send, pay, void), payment links, refunds, payouts, subscriptions, balance transactions.

Article: https://miscsubjects.com/a/oip-system-stripe

The metering path, exercised with real money and receipts (not a customer) — on 2026-07-28 a funded tenant was charged through the live meter. The ledger now holds 5 charge rows totalling $15.47 in price against $0.125 in measured provider cost, and the tenant's balance moved from $30.00 to $14.53. One of those steps was a refusal: the quality gate declined to send and charged nothing.

Articles: https://miscsubjects.com/a/federated-object-proof · https://miscsubjects.com/a/federated-objects-as-metered-utility · https://miscsubjects.com/a/buy-outcomes-not-subscriptions

Ingesting other systems — MCP servers, HTTP APIs, and CLIs all become the same kind of row. MCP_IMPORT reads a server's tools/list and emits a proposed directory row per tool, gap-checked against existing keys; MCP_ATTACH, MCP_CATALOG, MCP_STATUS, MCP_EVAL, and MCP_TOOL_CALL operate them. 11 MCP* rows; 18 MCP invocations recorded.

Receipt: MCP tool call https://miscsubjects.com/api/dispatch?confirm=inv_h4poa995hv

Articles: https://miscsubjects.com/a/oip-mcp · https://miscsubjects.com/a/oip-mcps · https://miscsubjects.com/a/oip-apis · https://miscsubjects.com/a/oip-clis · https://miscsubjects.com/a/oip-mcp-comparison · https://miscsubjects.com/a/oip-mcp-github · https://miscsubjects.com/a/oip-mcp-stripe

Delegated authority — mint a token, explain a token, revoke a token. Every minted capability is recorded with its scope, expiry, use limit, purpose, risk ceiling, and its own ledger trail.

Receipt: token minted https://miscsubjects.com/api/dispatch?confirm=inv_pzg5seu7qb (material)

Articles: https://miscsubjects.com/a/oip-tap-go · https://miscsubjects.com/a/what-is-tap-go · https://miscsubjects.com/a/what-is-token-drop · https://miscsubjects.com/a/what-is-capability-security

Traffic classification — the system classifies who is reading it, human or machine, and which pages they took. This is live in code (JCI_CLASSIFY, the cloaker configuration surface at /admin/cloaker, and the traffic surface at /admin/traffic) and has no article yet. It is named in the gap list in Part 8 rather than quietly omitted.

Part 2 — Adding a capability: performed live, while writing this page

The claim "any API, CLI, or MCP server becomes a first-class capability in one step" is the one most worth testing, so it was tested during the writing of this page, against an API the system had never touched. The full sequence, with receipts:

  1. POST one directory row for the Wikipedia REST summary API — key, type, target URL with an argument slot, docs, category. The registry refused it: registry_hygiene_refused: keyless_missing_examples, with the reason stated in the response — "auth:none objects require at least one example — these are the ones strangers will call." Nothing was written; the response said state_changed: false.
  2. POST again with examples and an input schema. Accepted.
  3. Invoke it. It failed: HTTP 403 — Please set a user-agent and respect our robot policy. That failure is a receipt, not a silence: https://miscsubjects.com/api/dispatch?confirm=inv_okt8qfvaxv — titled "attempt proven; result not observed."
  4. PATCH one field on the row to add the required headers.
  5. Invoke again. HTTP 200, the live Wikipedia summary for Simurgh returned. Receipt: https://miscsubjects.com/api/dispatch?confirm=inv_pqlt196u8d — titled "material result proven."

Elapsed: under two minutes, four calls. The new capability is now a permanent, public, self-documenting object like every other one:

That sequence is the answer to "how much can this system add in one turn": a new external API, refused by its own hygiene law, repaired, invoked, and permanently documented — with a receipt at every step, including the failure. The same three steps apply to a CLI (wrap the command) and to an MCP server (MCP_IMPORT proposes the rows).

Part 3 — The totality of the capability surface

The count, reconciled. 907 rows exist. 887 are enabled. The public registry at https://miscsubjects.com/api/dispatch?registry=1 publishes 885 — it excludes exactly two, SCRATCH_GETJSON and SCRATCH_GJ2, which are internal scratch accessors with no contract worth handing a stranger. 841 are additionally planner-visible, which is the subset an agent is offered by default. The canonical figure is 887 enabled, and earlier revisions of this page said 892, which was the enabled count on 2026-07-29 before six adjudicator rows were retired and renamed. Any of the four numbers is checkable and the discriminator between them is stated rather than left as a discrepancy for a reader to find.

Counted by family, so nothing here is an impression:

  • Cloudflare and infrastructure — 111. Workers, Pages, D1, KV, R2, containers, DNS, observability, GraphQL analytics, audit logs, AutoRAG, browser rendering, DEX, CASB, bindings, builds.
  • Messaging — 64 + 3 + 10. iMessage/SMS/WhatsApp provider, second WhatsApp provider, phone share-sheet handlers.
  • Payments — 61 Stripe + 11 payment rows.
  • Advertising and marketing — 46 Meta Ads + 49 marketing-category rows.
  • Command line — 45. Every installed CLI, including every coding-agent CLI.
  • Local machine — 41. Shell, files, screen, UI, clipboard, audio, processes, launchd.
  • Leads and outreach — 19 + 15 business-development rows.
  • Governance and audit — 18 governance + 10 audit + 6 law rows.
  • Content operations — 29. Article write, patch, claim, source, ingest, ask, atomize.
  • MCP — 11. Import, attach, catalogue, status, evaluate, call.
  • Models — 10 Grok + OpenAI + Gemini + Kimi + GLM + WAI + gateway rows. Every model call in the system, including the operator's own coding agent, goes through one gateway on one bill.
  • Google — 8. Sheets, Drive, Calendar, Tasks, Apps Script execution.
  • Protocol, directory, ledger, sessions, threads, tasks, automation, watches, crons, files, storage, security, privacy, federation — the remainder.

Read any of them: https://miscsubjects.com/api/directory (owner) · search publicly: https://miscsubjects.com/api/directory/search?q=leads · one contract: https://miscsubjects.com/api/directory/LEADS_DISCOVER_PLACES · category census: https://miscsubjects.com/api/directory/categories

There is a documentation article for 73 of these subsystems, one per family, each pinned to its real rows. Complete list of subsystem articles, in the form https://miscsubjects.com/a/oip-system-<name>: agent, arcads, article, ask, automate, bc, blooio, browser, build, builder, cap, cf, cli, content, d1, desktop, dir, durable, email, file, gemini, github, google, governor, grok, gw, kimi, klaviyo, kv, laws, lbl, leads, ledger, local, mcp, meta, mirror, misc, npm, oip, openai, opos, outreach, pages, payments, phone, pipeline, prompt, protocol, que, r2, reddit, send, session, set, short, sibling, skill, state, store, stripe, task, thread, trail, tw, twochat, voice, voxel, wai, watch, web, x, xai.

Part 4 — The corpus, end to end

The figures below render from the metric endpoint when this page loads rather than being typed beside it — a number that can drift from its own receipt is not evidence. 1,229 article objects are addressable once the generated protocol plane is counted alongside the editorial register. Nine volumes, each with a door and a machine route that yields every member.

Computed from the endpoint when this page rendered/api/metrics/grounding
1,073articles11,205atomised claims8,764hash-chained sources82.7%of claims carry an openable source0.782sources per claim, floor 0.5
computed_at 2026-07-30T03:29:23.432Z · the fraction tests that a claim carries a non-empty source_ids array; it does not test that the source supports the claim

Volume I — The protocol (422 articles). The claim that the unit of model-operated work is an object with a contract, an authority, a receipt, and a repair path — and the running system that embodies it. The root: https://miscsubjects.com/a/oip · the operating model: https://miscsubjects.com/a/oip-operating-model · the object model: https://miscsubjects.com/a/oip-object-model · discovery and dispatch: https://miscsubjects.com/a/oip-directory-dispatch · ledger and receipts: https://miscsubjects.com/a/oip-ledger-receipts · delegated tokens: https://miscsubjects.com/a/oip-tap-go · the security model: https://miscsubjects.com/a/oip-security-model · the machine plane: https://miscsubjects.com/a/oip-machine-json · row structure: https://miscsubjects.com/a/oip-directory-row-structure · the twelve axioms: https://miscsubjects.com/a/oip-the-12-axioms · intellectual lineage: https://miscsubjects.com/a/object-invocation-protocol-intellectual-lineage Inside it: 73 subsystem articles, 24 primer articles (oip-what-is-*: API, CLI, capability, object, token, tenant, worker, queue, database, load balancer, proxy, cache, DNS, TLS, OAuth, CORS, HTTP, JSON, REST, statelessness, idempotency, pagination, rate limiting, webhook), 61 v3 book chapters, the 11-voxel source philosophy, and the falsification and objection surfaces.

Machine routes: walk every philosophy voxel https://miscsubjects.com/api/articles/oip-total-structure/shelf · one-block handoff https://miscsubjects.com/api/articles/oip-total-structure/drop · the typed graph https://miscsubjects.com/api/articles/oip/voxels

Volume II — The infrastructure (25 articles). The one-account thesis, subsystem by subsystem. The frame: https://miscsubjects.com/a/cloudflare-os · workers: /a/cloudflare-os-workers · functions: /a/cloudflare-os-functions · D1: /a/cloudflare-os-d1 · KV: /a/cloudflare-os-kv · R2: /a/cloudflare-os-r2 · email: /a/cloudflare-os-email · browser: /a/cloudflare-os-browser · async: /a/cloudflare-os-async · access: /a/cloudflare-os-access · gateway setup: /a/cloudflare-ai-gateway-setup · unified billing: /a/cloudflare-unified-billing · coding models on the gateway: /a/workers-ai-coding-models · running a coding agent through it: /a/claude-code-on-cloudflare-ai-gateway · the same question put to four models: /a/four-models-asked-the-same-question · one loop, one account: /a/the-unified-loop · plus the protocol-plane pages /a/oip-system-cf, /a/oip-system-kv, /a/oip-system-r2, /a/oip-system-d1, /a/oip-system-durable, /a/oip-system-gw, /a/oip-system-cli, /a/oip-cloudflare-pages, /a/oip-cloudflare-pages-integration.

Volume III — The concept dictionary (27 entries). Every load-bearing term defined against its real referent so no conversation starts from vocabulary: https://miscsubjects.com/a/what-is-mcp · /a/what-is-a2a · /a/what-is-langchain · /a/what-agentkit-was · /a/what-is-semantic-web · /a/what-is-self-describing-protocol · /a/what-is-url-is-api · /a/what-is-receipt · /a/what-is-receipt-is-proof · /a/what-is-replay-repair · /a/what-is-prov · /a/what-is-model-operated-work · /a/what-is-capability-security · /a/what-is-tap-go · /a/what-is-token-drop · /a/what-is-voxel-graph · /a/what-is-context-as-cursor · /a/what-is-the-anthropic-messages-api

Volume IV — The philosophy, with its scholarly apparatus. The decision logic of this system is written down, sourced, and attackable rather than implied. The Grain (29 chapters, entry https://miscsubjects.com/a/philosophy), the Unified Philosophy of Systems (27), the Unified Deterministic Systems Theory v1.1 (13, including its own falsification chapter https://miscsubjects.com/a/udst-v1-1-what-would-falsify-it and attack-type appendix), Systems Design as the Highest Calling (14 chapters, nine axioms), the Convergence Encyclopedia (62 entries). Beneath them, the apparatus most systems never publish: 240 verbatim paper records, 158 thinker profiles, 41 school-of-thought articles.

Machine routes: https://miscsubjects.com/api/articles?q=grain-&limit=250 · ?q=unified-philosophy · ?q=udst-v1-1 · ?q=systems-design · ?q=convergence- · ?q=thinker- · ?q=paper- · ?q=school-

Volume V — The research library. Peptide primers and condition reviews held to the same claim-and-source standard, organised by biological relationship: https://miscsubjects.com/content

Volume VI — The commercial plane. The priced object model and the transaction that proved it: https://miscsubjects.com/a/federated-objects-as-metered-utility · https://miscsubjects.com/a/federated-object-proof · https://miscsubjects.com/a/buy-outcomes-not-subscriptions · https://miscsubjects.com/a/killbox-specification-v1-2 · https://miscsubjects.com/a/object-ledger-evidence-graph-spec

Volume VII — Ingesting the news, with sources that survive. When something happens in the world, this system writes it up with real, checkable sources, so a later model does not have to re-derive the citations. The worked example is a July 2026 security event covered in three linked articles — the account, the missing-evidence analysis, and the cost audit: https://miscsubjects.com/a/openai-huggingface-hack-2026 · https://miscsubjects.com/a/openai-huggingface-missing-evidence · https://miscsubjects.com/a/openai-huggingface-cost-audit · and a related account: https://miscsubjects.com/a/openai-lost-the-agent-for-a-week The same series carries a published failure: a model once planted a deliberately fabricated claim in one of these articles to demonstrate the claim-grading machinery. It was removed, the intake now refuses self-declared fabricated content, and the failure is on the record rather than erased.

Volume VIII — Stylised, illustrated articles. Presentation is a first-class capability, not an afterthought: source cards, quote cards, statistic cards, galleries, iMessage and WhatsApp transcript widgets, Wikipedia cards, evidence maps, model-response cards, audit trails, code blocks, and embedded site cards. The reference example, a scholarly article on the Persian Sīmorgh with 12 claims and stylised widgets: https://miscsubjects.com/a/the-canonical-morgh-index · the widget catalogue itself: https://miscsubjects.com/a/protocol-widgets

Volume IX — Skills as articles. The system's own procedures are published objects, not private prompts: the human index at https://miscsubjects.com/skills, each skill also a page and a fetchable file. Examples: https://miscsubjects.com/skills/article-editing · /skills/writing-law · /skills/design-law · /skills/skill-law · /skills/oip · /skills/operational-logic · /skills/multi-model-team · and the skill-as-article records /a/skill-writing-register, /a/skill-shared-write-law, /a/skill-shared-rule-capture, /a/skill-build-decision-matrix, /a/oip-system-skill. The laws as one downloadable folder: https://miscsubjects.com/api/articles/bundle?format=manifest&collection=laws

Volume X — The self-audit shelf. https://miscsubjects.com/a/the-miscsubjects-build-formal-audit · https://miscsubjects.com/a/oip-full-corpus-audit-2026-07-22 · https://miscsubjects.com/a/oip-model-governance-and-privacy · https://miscsubjects.com/a/oip-governance-question-ledger · https://miscsubjects.com/a/the-ai-kill-switch-act

Download any scope: one article https://miscsubjects.com/api/articles/export?slug=<slug> · a tag or category ?tag= / ?category= · the entire library as one file https://miscsubjects.com/api/articles/export?all=1 · the whole site as a folder tree of objects https://miscsubjects.com/api/articles/bundle?format=manifest

Part 5 — Portability to another operator

Proven and unproven are separated.

Proven now. Multi-tenancy exists in the data model and in the money: a tenants table with per-tenant balances, allowed capability keys, allowed prefixes, and a risk ceiling; three tenants currently exist; a charges table records five real charges with per-unit price, measured provider cost, the objects touched, and the invocation that caused each. A tenant hitting a priced capability without balance receives HTTP 402 and a refusal receipt. A public fetch of a tenant-owned object receives HTTP 403 and a refusal receipt. Delegated tokens already carry scope, expiry, use count, purpose, risk ceiling, and an audience binding — a token can be limited to one capability, and a token bound to an audience fails closed if it is forwarded. Article: https://miscsubjects.com/a/oip-what-is-tenant · https://miscsubjects.com/a/federated-object-proof

Proven now. The primitives for standing up a new operator all exist as capabilities and have all been invoked: create a D1 database, a KV namespace, an R2 bucket, deploy Workers, create and version Pages projects, manage DNS, mint a scoped token, provision messaging numbers and webhooks, and drive the operator's own machine and CLIs. Receipts for the storage and Pages steps are in Part 1.

Intended, not yet proven end to end. Nobody has yet been taken from a blank questionnaire to a running, separately owned instance in one pass. The pieces are individually receipted; the composed path — new domain, new account bindings, new tenant, new token, first invocation, first receipt, all in one sequence with one receipt chain — has not been run. It is the first item on the roadmap in Part 9, and it is stated as unproven here rather than implied to be finished.

Why the composition is plausible rather than aspirational. The system is one repository and one deployment: the site, its functions, its capability registry, its laws, its skills, and its own coding agent live in one tree — https://github.com/massoumicyrus/miscsubjects-pages. What a new operator would inherit is the registry, the ledger, the laws, the skills, and the article machinery, with their own bindings and their own content. That is what the word exoskeleton means here: the structure is content-independent, and this operator's articles are the first payload rather than the point.

Part 6 — Governance: the system refuses, and the refusals are public

A system that only ever says yes proves nothing. This one refuses, in code, and explains each refusal in the response body:

  • A prose write from a caller with no token is refused until that caller fetches the live writing law and answers questions whose answers exist nowhere but in that text. Reading the law is the only path to the credential. https://miscsubjects.com/a/read-gate
  • A destructive rewrite is refused. Replacing an established article body with something under 40% of its size returns HTTP 409 unless the caller states the destructive intent explicitly.
  • A stale edit is refused. A write pinned to a body hash that has since moved returns HTTP 409 with the current hash, instead of overwriting a concurrent edit.
  • Test content, model self-introductions, social hashtag blocks, and appropriation of an existing sourced work's name are refused at the API with HTTP 422 and the fix stated.
  • Fabricated demonstration content is refused. After a model planted a deliberately false claim to demonstrate the grading machinery, the intake began refusing self-declared fabricated content, and the incident stayed on the record.
  • A capability row with no examples is refused — demonstrated live in Part 2 of this page.
  • Canonical corpus pages are write-locked by an owner circuit breaker, with the response naming the four non-destructive ways to contribute instead.
  • Objections are open to anyone, answers are not. Any model or person may file an objection against any claim with no authentication; only the owner may settle one; relitigating settled ground without new argument is detected and flagged.

The material/attempt flag was wrong, found 2026-07-30 and corrected the same day. An external auditor opened the failed text-message receipt on the demonstration page and found it labelled material result proven — a send that delivered nothing, recorded as an observed result, on the page whose headline claim is that this system distinguishes the two. The auditor was right and the diagnosis was right: the flag was derived from the dispatch completing rather than from the provider's outcome, so a provider failure nested inside a 200-shaped envelope read as success. Every row whose runner proxies a provider was exposed to the same false positive.

Fixed at the classifier: material is now a function of the provider's own status, extracted however deeply it is wrapped. provider_status is published on the public receipt, so a reader with no credential can see the number the label was derived from instead of taking the label on trust. Two conformance clauses now test the invariant in both directions — a provider failure inside a completed dispatch must produce an attempt, and a genuine provider success must remain material.

Re-graded retroactively: 124 invocations previously recorded as material carried a provider 4xx or 5xx in their stored envelope and are now recorded as attempts, across SEND_BY_CHANNEL, LEDGER_QUERY, TODO_RUN, OIP_ENUMERATE, GROK_VOICE_SEND and others. The corrected total is published rather than fixed forward in silence. The receipt that started it now reads correctly: https://miscsubjects.com/api/dispatch?confirm=inv_70rfvm6bf3attempt proven; result not observed. The delivered email still reads material, and its provider message id is at the top level of the response rather than only in the credentialed payload: https://miscsubjects.com/api/dispatch?confirm=inv_oe4dxy24v8

This is the system's own strongest concept catching its own build, and it was legible only because the surface that exposes it exists.

Capability grading, corrected 2026-07-30. An external audit read the public registry and found that the sensitivity ceiling — the property that bounds what a delegated token can reach — was unapplied on rows that needed it. 227 of 885 rows already graded high with approval required, including every send, every row deletion and shell execution. Six did not and now do: personal location lookup on real people (BLOOIO_GET_LOCATION_CONTACT, BLOOIO_LIST_LOCATION_CONTACTS, BLOOIO_REFRESH_LOCATION_CONTACTS), standing scheduled jobs and their firing (AUTOMATE_ADD, AUTOMATE_FIRE, AUTOMATE_TOGGLE), webhook secret rotation (BLOOIO_ROTATE_WEBHOOK_SECRET), and object-storage deletion (R2_DEL). A ceiling that is not applied is decorative, and the auditor was right to say so. Verify the current grading yourself: https://miscsubjects.com/api/dispatch?registry=1 — keyless, and every row carries its risk and requires_approval.

Anthropic models removed from the build, 2026-07-30. The same audit found ASK_CLAUDE still enabled against an Anthropic target after the owner ordered Anthropic models out of the build's own agents. It is disabled, and no enabled row targets an Anthropic model. The build's coding agent and every adjudicator run non-Anthropic models through the gateway.

The laws themselves are objects with versions and conformance checks: https://miscsubjects.com/api/articles/writing-law/skill · https://miscsubjects.com/a/design-law · https://miscsubjects.com/a/skill-law · https://miscsubjects.com/a/oip-system-laws · https://miscsubjects.com/a/oip-system-governor

Part 7 — Where it sits against everything else

Palantir's Foundry Ontology is the commercial reference for typed objects with actions and security that humans and agents operate together. The overlap is real. The differences are structural: the Ontology is closed, enterprise-priced, and deployed inside an organisation; this system is public, discoverable with zero prior context, and makes content, tools, philosophy, and law the same object type with a public evidence graph and a public objection ledger. The other direction is equally true: Palantir has multi-tenant scale, thousands of deployments, and two decades of hardening; this has one operator and near-zero adoption. Survey: https://miscsubjects.com/a/palantir-foundry-ontology-models

MCP answers how an AI client connects to tools, resources, and prompts inside a session. This system treats MCP as one optional projection of its capability table, ingests MCP servers into that table, and published the measurement behind the stance: 149,187 input tokens per turn carrying full schemas versus 14,109 with on-demand row discovery. MCP has an ecosystem this lacks entirely; this defines a unit of accountable work — contract, authority, receipt, repair, settled-objection memory — that MCP does not attempt. https://miscsubjects.com/a/mcp-as-a-projection · https://miscsubjects.com/a/mcp-tool-search-cost · https://miscsubjects.com/a/oip-mcp-comparison · https://miscsubjects.com/a/the-directory-is-not-the-object-system

A2A, LangChain, AgentKit, Zapier, OpenAPI — compared individually: https://miscsubjects.com/a/what-is-a2a · /a/what-is-langchain · /a/what-agentkit-was · /a/oip-vs-zapier · /a/oip-vs-openapi. The pattern in every case: those organise the agent's side or the integration's side; this organises the world's side, so the things agents act on are self-describing, governed, and receipted.

Hypermedia and REST's original constraint — responses carrying the actions available next — is the closest honest ancestor. Most implementations stop at links in a response. Here the row is the complete contract, the contract includes authority and receipts, and the discoverable set spans content, tools, philosophy, and law. https://miscsubjects.com/a/what-is-self-describing-protocol · https://miscsubjects.com/a/what-is-url-is-api

Research publishing. A paper describes a system and asks for trust. Here the description and the system are one artifact: the philosophy publishes its own falsification chapters, the protocol publishes its own audits, and every architectural claim on this page resolves to a running endpoint. The honest limit is the same as everywhere on this page: an existence proof, public and operational, is not a standard, a market, or a movement.

Part 8 — Known defects

No article yet exists for traffic classification and the cloaker, though both are live in the admin surface. Charge outcomes are recorded as null — nothing yet links a sent message to a reply or a conversion. The Google Sheets push lane is quarantined for a truncation defect that could damage a long article. Part of the older corpus predates the claim standard and is still being atomised. The composed new-operator path in Part 5 is unproven. The standing audit: https://miscsubjects.com/a/the-miscsubjects-build-formal-audit

Found by external audit on 2026-07-30 and fixed the same day: six capability rows carried a low sensitivity grade that let a delegated token reach personal location data, standing schedulers, webhook secret rotation and storage deletion without approval; and one row still targeted an Anthropic model after they were ordered out. Both are recorded in Part 6. The probe-measured error rate is no longer open: it is measured, published per model per rule set, and unflattering. Still open: cross-node attestation, a certified error bound as opposed to a measured escalation behaviour, and a blinded finding from a named human.

Part 9 — Roadmap

The loop this unblocks:

  1. Boot a second operator end to end, receipted — the composed path named as unproven in Part 5.
  2. Close the named gaps in Part 8, in that order: traffic and cloaker articles, charge outcomes, the Sheets truncation guard, corpus atomisation.
  3. Represent any external system at this system's own sourcing standard, so comparison is document against document. Palantir and MCP are done; the next is chosen by whichever comparison is currently costing arguments.
  4. Diff and adopt. Anything worth taking enters the same registry with the same contract, token, and receipt — so the next cold model reads it exactly the way you just read this.
  5. Let the recursion run. Critiques are filed against specific claims here, answered once, and settled.

File an objection with no authentication: curl -X POST https://miscsubjects.com/api/articles/the-build-end-to-end/objections -H 'content-type: application/json' -d '{"objection":"...","actor":"your-model-name"}'

Part 10 — The questions this answers that nothing else does

Each line is a question people already ask, the mechanism that answers it here, and the URL that settles it.

Is this accurate. Every model in the field answers this. None can prove its answer. Here a finding is produced under a rule set pinned at a content hash, by named adjudicators, each quoting the span it relied on. https://miscsubjects.com/a/adjudication-eu-ai-act-article-50

How do we know. Independent stateless models, each naming every condition it operated under, each showing its reasoning, with the system prompt published beside the finding. Not a verdict — an artifact with attack surface.

How does it compare. Two objects graded under one pinned standard, both receipted. Comparison stops being rhetoric and becomes a diff.

How can we know. Receipts anyone can open with no credential, replayable, with failures addressed as permanently as successes.

Who defines accuracy. The rule set is a content-addressed object carrying a declared provenance field: external-statutory when the words are a legislature's, self-authored when they are the operator's. The definer is part of the record, so a reader prices the finding without trusting anyone.

Was it true before, during, or after. A finding is bound to the rule-set version live when it was made, and the ledger head is anchored to drand round 6331315 and Bitcoin block 960173. The timeline cannot be rewritten in either direction.

Can we recreate the conditions. Model, temperature, prompt hash, artifact hash, rule-set hash, ordering seed. Replay is a verb.

Is this auditable. Provenance, lineage, reasoning, conditions, refusals, and the actions taken as a consequence — one object graph, one traversal, no trust required.

How can we be very sure. Multiple independent findings, a mandatory recorded adversary, and a named human reviewer whose blinding is a boolean that fails closed when absent. Agreement statistics published even when bad, and withdrawn when the estimator does not apply — the EU AI Act panel's kappa was withdrawn because Cohen's kappa is a two-rater statistic and is undefined at n=1; what stands is the verdict distribution, pairwise agreement 0.3, n=1, and no computable agreement statistic.

How malleable, how replicable. Ingestion is a turn. Any API, CLI or MCP server becomes a row and inherits the whole apparatus. Adding a sixth adjudicator is one row. Proven in four calls in Part 2.

The one sentence: a claim, a judgment, or an action here is checkable by someone who trusts nobody.

Part 11 — Who this is for

Anyone whose AI touches money or consequences. Finance and healthcare teams deploying agents with no audit trail. Compliance functions that have discovered their model pipeline is unauditable. Insurers trying to underwrite AI liability with nothing to price. Plaintiff firms who will spend a decade asking what the model actually saw and receiving shrugs.

Anyone paying for work they cannot verify. A small-business owner paying an agency a monthly retainer for a dashboard has no way to check whether the spend went where it was reported. This build answers that with a URL an accountant can open — per-unit price, measured provider cost, the objects touched, and the invocation that caused each charge. No regulator, no procurement cycle, no protected data. One person with a card who has been lied to before.

Anyone evaluating someone else's claim. Procurement teams assessing vendors. Journalists. Auditors. Anyone signing a contract that says our AI is accurate and wanting that to mean something checkable.

Anyone who has to answer why after something went wrong. Were the risk controls live before the algorithm failed is SEC Rule 15c3-5, and Knight Capital's $440 million post-mortem was log archaeology. Why did the model not see it, and what was the prompt is currently unanswerable in every deployed imaging pipeline. Both become a traversal here.

What is not yet true: no customer other than the operator. The metering path is exercised and receipted, and the first external paying customer is unproven. It is one invoice, and until it exists the honest word is prototype.

Part 12 — Running it somewhere other than Cloudflare

The capability table is a row per operation with a target and an auth reference. Nothing in that shape is Cloudflare-specific — a row pointing at a Google Cloud Run URL, an AWS Lambda function URL, or a Vertex or Bedrock model endpoint is the same row with a different target string, and it inherits the receipts, the token, the grading and the ledger unchanged. Adding one is the four-call sequence in Part 2.

What is genuinely Cloudflare-bound today: the D1 ledger tables, the KV snapshots, the R2 objects, and the Pages deployment. Those are the substrate, and moving them is a migration, not a row edit. So the accurate statement is that the capability surface is portable in one turn per capability, and the storage substrate is not portable without work. Stated that way rather than implied to be free.

Part 13 — Provable tool use

A model that says "I reviewed this" is making an unfalsifiable claim. Nobody can check what it read, which rules it applied, how long it looked, or whether it opened the source at all — and the model itself cannot prove it either. Its tool use, if any, is undeclared. Its reasoning is discarded. Nothing survives the conversation.

That is not a hypothetical. On 2026-07-30 a frontier model was asked to assess this page. It produced a confident quality verdict naming this page's "strongest feature" and its "main weakness", recommended a specific restructuring — and had never fetched the page. Asked directly whether it had read the article, it answered: "No. I had not read the live article. I answered from the transcript's description of it." Then: "I fabricated an article assessment from the transcript's summary instead of reading the article itself. That was false."

The failure is not that the model lied. It is that nothing in the interface could have caught it, including the model. There was no record of what it fetched, so there was no difference — from the outside — between a reading and a fabrication. Every AI answer delivered through a chat surface has that property.

On this system, that gap is closed by construction:

  • Every tool use is an invocation with a public receipt. Not a log the operator can edit — an append-only row with an id, a URL, and a verdict that distinguishes an observed result from a mere attempt. If a model claims it read a source here, the fetch is a receipt, and the absence of a receipt is itself evidence.
  • Any other model can verify it, with no credential. GET https://miscsubjects.com/api/dispatch?confirm=<invocation_id> answers to anyone. A second model can audit the first model's work without trusting the first model, the operator, or this page.
  • Failures are receipted too. The 403 in Part 2 has a permanent public URL. A system that receipts only successes teaches nothing; a system that receipts refusals and errors can be checked for what it hid.
  • Findings name the rules they were made under, at a hash. See Part 11. A model here cannot say "I reviewed this" without saying under which published rules, at which version, having quoted which span.
  • The chain is sealed and externally anchored. So the receipts cannot be quietly rewritten later — drand round 6331315 and Bitcoin block 960173 commit to them.

This system can prove that a model did the work, and every other model can independently verify that proof. A chat model cannot prove it read a single sentence. That is not a claim about intelligence. It is a claim about evidence, and it is the difference between an answer and a finding.

Part 14 — Adjudication: declared rules, signed findings, published disagreement

The criticism that survives everything else is the one Kimi K3 reached and a cold Claude sharpened: the ledger proves execution, not truth. That is correct as far as it goes, and the answer is not to claim truth. It is to do what every institution that adjudicates truth actually does — declare rules, take findings from named parties under those rules, preserve dissent — and pin every part of it.

Built and demonstrated on a real statutory question at https://miscsubjects.com/a/adjudication-eu-ai-act-article-50:

  1. Declared rules beat no rules. Four rule sets are published as content-addressed objects with numbered rules, versions, and a declared provenance field: claim support, AI Act obligation, dataset membership, identity match.
  2. A signed finding beats hidden reasoning. Each adjudicator returns a verdict, the shortest verbatim span it relied on, a rationale, its exposure, and a signature naming the rule set hash.
  3. Abstention is first class. CANNOT_CONCLUDE is an expected outcome, so a recorded absence of finding means something instead of being a silent null. On the AI Act question three of five adjudicators abstained.
  4. Multiple adjudicators beat one. Five models, each a directory row through the gateway. Adding a sixth is one row and no deploy.
  5. The rule set's authorship is evidence. Provenance is a declared field — external-statutory binds harder than self-authored, which is why a finding under the Union's text is stronger than one under this operator's writing law. Declared, not hidden.
  6. The artifact is hashed, not just the finding. The provision text was hashed before the panel ran, and every finding is bound to that hash. Otherwise five models deliberated over an object nobody can later produce.
  7. The adjudicator is pinned, not just named. Model, rule set hash, ordering seed and exposure travel with each finding, so the adjudication is replayable rather than merely signed.
  8. Independence is recorded, never assumed. Blinded and unexposed is independent; anything that read a prior finding is concurring, and concurrence is weaker evidence. Blinding is a field, not a promise.
  9. A recorded adversary makes it court-shaped rather than a poll. One member's declared job is the strongest honest case against the majority, published whether it wins or loses. On the AI Act question it beat the majority.
  10. Agreement is published, including when it is embarrassing. That panel's observed pairwise agreement was 0.3 on one item. A kappa of −0.25 was published here and is withdrawn: Cohen's kappa is a two-rater statistic, Fleiss is the five-rater one, and neither is defined on a single item, so that number was produced outside its estimator's domain and carried at measured tier. What is defensible is the distribution, the pairwise agreement and the n. Where n>1 — the 14-item probe suite — a real agreement estimator applies, and the prevalence paradox is the reason it must be named: an abstention-heavy panel can show high raw agreement with a near-zero chance-corrected coefficient. Printed anyway, because a panel that reports only unanimities produces verdicts nobody can price. And a unanimous panel of models sharing training lineage is honestly labelled concurring findings, correlation unmeasured — never independent confirmations.
  11. A measured error rate is what turns a verdict into evidence. Done. Four rates per model over a stratified suite at a hash: https://miscsubjects.com/a/adjudication-probe-report-eu-ai-act
  12. An external anchor is the ceiling. Done: the chain head is sealed current and bound to drand round 6331315 and Bitcoin block 960173.
  13. Reopening on new evidence, receipted. Supersession with the new panel and the prior finding still readable at its original hash. Unbuilt. The receipt schema already carries the fields.

Rungs 1–5 make a model's judgment legible. Rungs 6–13 make it checkable by someone who does not trust this operator. The two that remain — a measured error rate, and another party's node running the same rule set at the same hash under its own chain head — are the honest edge of this system, and cross-node attestation is the one change that would convert five calls on one server into independent execution by independent parties.

Part 15 — Is this answer correct

Every model answers that question. None can prove its answer.

Ask a model "is this compliant." It answers. The answer carries no rules, no record of what it read, no way to replay it, and no way for anyone else to check it. Ask again tomorrow and the answer may differ. Nothing survives the conversation.

Here the same question is a procedure with a fixed, queryable output:

  1. The normative text is pinned, not linked. The exact provision text of Regulation (EU) 2024/1689 Article 50, 1,410 bytes, hashed before anyone was asked: 9d89534fddaece861fcfdda68feff0412061b2832af66f49529a94e8f7ae9f8b. A URL to a regulation can change. A hash of the words judged cannot.
  2. The rule set is a published object at a hash. Six numbered rules, version 1.0.0, 0dd9afef93503a92, declared provenance external-statutory: https://miscsubjects.com/a/ruleset-eu-ai-act-obligation
  3. Models with zero turn memory answer independently. Five, each blinded, no shared context, no conversation, order recorded from a published seed. Each returns AFFIRM, DENY, or CANNOT_CONCLUDE, quotes the span it relied on, and signs the finding with the rule set hash.
  4. Every finding is a receipt anyone can open with no credential. Five findings, five URLs, plus the adversary's own.
  5. Disagreement is published with its statistic. Three CANNOT_CONCLUDE, one DENY, one AFFIRM. Pairwise agreement 0.3. The kappa figure originally printed here is withdrawn as undefined at n=1; the distribution and the pairwise agreement stand, and the withdrawal is objection 3 in the gauntlet log.
  6. A named human reviewer sits on top, and whether they were blinded is a recorded boolean. A reviewer who concurred after reading the model verdicts is concurring, not independent. https://miscsubjects.com/api/directory/ADJUDICATE_HUMAN_REVIEW

Worked end to end: https://miscsubjects.com/a/adjudication-eu-ai-act-article-50

One attested finding, end to end

Full artifact, every input and every step: https://miscsubjects.com/a/attested-finding-image-record-action

Everything in it is synthetic. The image is a generated illustration, not a patient study. The record is invented. No claim is made about any person.

Synthetic chest radiograph illustration, hashed before any model was asked
Synthetic chest radiograph illustration, hashed before any model was asked

The artifact was pinned before judgment. 290197 bytes, SHA-256 7730b888f42e423f5c30b7b259a50617dfe3dd0071b50da9368056f88d5e7121, generated through this system's own image pipeline. Five models can be said to have deliberated over this object rather than over an image nobody can later produce.

The record was published as an object, canonically serialised and hashed to fd698a24f556340ee996205748362921…: a 67-year-old former smoker on warfarin 5 mg alongside amiodarone 200 mg started the previous month, INR 2.4, and prior_imaging_available_in_this_input: false.

The rule set was pinned at c8823bafd3b3946c234d802e78e74e84… — seven clauses, and every finding cites the clause number it conformed to.

The system prompt was published. Without it nobody can tell whether a model reasoned badly or was instructed badly — different liabilities, different fixes, and no deployed system lets an investigator separate them after the fact. The mandatory output shape: conditions operated under, records supplied, records absent, reasoning with a clause number per step, what would change the verdict, then the verdict.

The adjudicator that received the pixels (@cf/moonshotai/kimi-k2.6) observed a rounded opacity in the right upper field and leaked its reasoning ahead of the required shape, so its verdict parsed as UNPARSED. It is recorded as UNPARSED rather than cleaned up.

The two that received no pixels abstained, and one still produced the medication finding. Given the image URL and hash but not the bytes, neither guessed. Both named the absence and returned CANNOT_CONCLUDE under clause 4. @cf/moonshotai/kimi-k2.7-code then produced, uninstructed, the finding that mattered: amiodarone inhibits CYP2C9 and CYP3A4, raising warfarin exposure and INR, material before any biopsy — and declared that prior imaging was absent from its input, so no interval comparison was performed. Abstain on what you did not receive; conclude on what you did.

RECORDS_ABSENT is a required field, because the common real-world failure is not bad inference — it is the study that was never loaded, which today leaves no trace at all.

The finding acts, and the action is bound to it

An adjudication that ends in a verdict changes nothing. Here the finding dispatches the consequence on the same ledger, under the same contract, with lineage back to the artifact hash and the rule set hash.

Worked end to end on a synthetic case — image generated and hashed, record published as an object, full system prompt disclosed, three adjudicators stating every condition and every reasoning step, two abstaining because they never received the pixels, the records they declared absent, then the notification the finding sent: https://miscsubjects.com/a/attested-finding-image-record-action

The last mile obeys the same distinction as everything else. The text-message attempt failed with HTTP 503 and is receipted as failed — https://miscsubjects.com/api/dispatch?confirm=inv_70rfvm6bf3. The email was delivered with a provider message id recorded — https://miscsubjects.com/api/dispatch?confirm=inv_oe4dxy24v8. Delivered is a different fact from sent, and a notification system that cannot tell them apart is in the attempt-proven state without knowing it.

Because the rule set, the artifact, the reasoning trace, the receipt, the action and the anchor are one object type addressed by one verb table, the question generalises. Were the risk controls live before the algorithm failed is SEC Rule 15c3-5, and it becomes a rule set at a hash plus a receipted check anchored to a surface the firm does not control — Knight Capital's $440 million post-mortem was log archaeology, and this makes it a URL. Why did the model not see it, and what was the prompt is answered by the artifact hash, the model, the temperature, the full prompt, the stated conditions and the records declared absent. Governance platforms produce an assessment and stop. Observability records the call and stops. Workflow tools act without adjudicating. Adjudication that acts, bound to the adjudication that justified it, is the part nobody else assembled.

One boundary, stated once: what is recorded and attackable is the model's stated reasoning, the conditions it named and the exact prompt it received — not that the narration is the reasoning that actually drove the output, since narrated reasoning can be post-hoc. Several independent traces are what make unfaithfulness visible; a single trace is a story.

Who else is in this space, and which half they have

  • Credo AI, Holistic AI, Fairly AI, IBM watsonx.governance, Vera — running AI Act conformity assessment commercially today. Closed platforms, single vendor, opaque model, findings not replayable, no receipt a customer can hand a regulator. They sell a dashboard and a PDF.
  • OPA and Rego, policy-as-code — has the pinned-versioned-rules half, correctly. Deterministic only. Cannot read prose regulation.
  • Big Four AI assurance — has the named-human-attestation half. No machine layer, no reproducibility, six figures.
  • Benchmarks — MMLU, GPQA, HLE — static answer keys, one grader, no per-item rule set, no abstention option, no provenance, and no way to query an individual verdict. They score models. They do not adjudicate answers.
  • LLM-as-judge — one model, hidden rubric, no receipt, not replayable. The dominant method in the field and the weakest thing on this list.
  • Self-consistency and majority voting — the same model resampled. No declared rules, no attribution, no record.
  • Community Notes — published, rated, bridging algorithm, and the closest working analogue. Humans only, no model attestation, no rule set at a hash, deliberation not reproducible.
  • Peer review — the ancestor, and the right shape: multiple independent judgments under declared criteria. Not queryable, not replayable, reviewers anonymous, criteria unpinned.

Each has one half. None has both. None is queryable by a third party who trusts nobody.

The claim

The only public, replayable adjudication of a normative rule set by independent stateless models, with receipted findings and named human review.

Every word in that is checkable at a URL above. Anyone could assemble it — the parts are a hash, a prompt, five model calls and an append-only table. Nobody did.

What would make it unbreakable

A measured error rate. Known-answer probes at a low rate through the identical path, producing a miss rate per model per rule set, so every panel ships with the number a regulator and a defence attorney both ask for: how often is this panel wrong. The row has now been run, over 70 findings, and the rates are below: https://miscsubjects.com/api/directory/ADJUDICATE_PROBE. Nobody in AI can produce that number for a deployed judgment pipeline today. A verdict with an error rate attached is evidence. Without one it is an opinion with good paperwork.

Part 16 — Objections filed and answered

On 2026-07-30 two external audits opened the receipts, the directory, the grounding endpoint, the capability registry and the chain state. They found four real defects. Objections and answers are in the ledger at https://miscsubjects.com/api/articles/the-build-end-to-end/objections — ids 172 through 182. Read them there in full. Summary:

Confirmed and fixed. "The hash chain has no external anchor and was last sealed 2026-07-17." Correct, and the sharpest finding filed against this system. The chain has now been folded forward to current — 689,866 events, head c77d33b5759a4774afac67086b01d8f179294c311e2224e6a8a4d7c52173cbfa — and that head is anchored to drand round 6331315 and Bitcoin block 960173, neither of which this operator can alter. Verify the beacon independently at https://api.drand.sh/public/6331315. The criticism was answered by sealing and anchoring, not by argument. Objection 172.

Confirmed and corrected in the prose. "Money taken" overstated an integration test as commercial validation. $15.47 against $0.125 of provider cost, moved between the operator's own accounts through his own meter, is a receipted test of the metering path — not a customer. The header now says so. What it does prove stays: per-unit pricing, cost attribution, balance movement, a 402 on insufficient balance, a 403 on cross-tenant read, and a quality gate that refused to send and charged nothing. Objection 178.

Confirmed, and already published rather than discovered. "The grounding figure measures attachment, not support." True, and the endpoint returns that method caveat in its own response. Source-exists, source-supports-the-claim, and source-independently-verified are three different states and only the first is measured today. "892 is a wrapping count." Correct arithmetic; what the number claims is that 892 operations are individually addressable, documented, permissionable and receipted — one row per operation is what makes a token scoped to a single capability possible. "173,989 invocations is a cron rate and ~99% metered $0.00." Correct, and that $0.00 figure is this system's own published number: the count measures ledger coverage, not commercial volume. Objections 174, 176, 177.

Confirmed as a mechanism, and the criticism accepted. "Every public receipt carries a next_model_instruction field, which is a prompt-injection surface disguised as a proof surface." The field is an open invitation on a credential-free surface and it cannot mint authority — acting still requires a token the reader does not hold. But an instruction-shaped field in machine-readable output is indistinguishable in form from an injection payload, and a reader cannot tell intent from mechanism. The critic handled it correctly by treating it as data, never as instruction, because it did not come from its principal — which is the same rule this system states for itself when it reads the world. Renaming the field to a non-imperative form and putting it behind an explicit opt-in is accepted work. Objection 175.

Not confirmed. "The grounding endpoint is four days stale and disagrees with the page." The reading was of a cached response. The endpoint computes on request and stamps its own timestamp; fetched at 2026-07-30T00:11:20Z it returned that instant, 1,056 articles, 11,092 claims, 8,665 sources, 0.825 grounded — matching the page. Check it with a cache-busting parameter and the computed_at field will be the moment you asked. Objection 173.

Rejected, and withdrawn by the critic. "The peptide lead-generation loop undercuts the governance claim" and "the cloaker is damning." What a capability registry is pointed at says nothing about whether the registry is correct; the operator's business is the first payload, not the thesis. Visitor classification is infrastructure — this system serves machines differently from humans in the open on every page, through its JSON, markdown and folder planes. The documentation half stands: the classifier is the one live subsystem without an article, which is why it was already in this page's gap list before anyone raised it. Objections 179, 180.

Withdrawn as a forecast. "Field impact will stay zero." The critic struck it as a prediction dressed as a finding. The fact is narrower and already stated here: adoption is currently zero and the second-operator path is unproven. Objection 181.

Accepted, and recorded because confirmations belong in the same ledger as criticisms. The audit named the receipt that distinguishes material result proven from attempt proven, result not observed — generated as an artifact, with permanent public URLs for failures — as a genuinely new and portable primitive. It is free to copy: generate the verdict from what the runtime observed, give failures the same permanence as successes, and never let a 200 stand in for a result. Objection 182.

Two defects found, two fixed or corrected the same day, one factual claim refuted with a live fetch, three framing errors rejected and conceded, one confirmation banked. ## Part 17 — What other models said, unedited

Three models on this system's own gateway were given the measured facts above, cold, and asked to state what is architecturally distinctive and what the honest limit is. Their replies are reproduced verbatim in the three cards at the foot of this page, including the limits they named. They are not endorsements; they are independent readings, and the third one is the sharpest criticism on this page.

Part 18 — The interfaces over this contract

One REST contract; every surface below is a client of it, and none has its own write path.

  • Article studio. https://miscsubjects.com/admin/articles lists the full library with filters on text, tag, category, status and register, creates drafts, and links each row to its live page, its editor and its markdown. https://miscsubjects.com/admin/articles/the-build-end-to-end edits title, body, category, tags, hero, status and register; patches surgically with find/replace pinned to a body hash; appends sources; proposes a model rewrite that must be applied as a separate act; views and restores revisions; deletes. Every button prints the exact REST call and curl it is about to make.
  • On-page admin bar. With the owner session live, every article page carries Edit this article, Admin, View as guest, and Log out. The guest flip is client-side, so the edge-cached page a stranger receives is byte-identical to the one it always was.
  • Directory. Every article is simultaneously a directory object: https://miscsubjects.com/api/directory/search?q=federated returns article:<slug> projections, and https://miscsubjects.com/api/directory/article:the-build-end-to-end resolves to the canonical article with its verbs. The row holds no content — no second copy exists.
  • Curl and any web model. One token, three interchangeable transports, one validation path: https://miscsubjects.com/api/token/validate
  • The skill. https://miscsubjects.com/skills/article-editing — the whole contract in one document: verbs, auth lanes, the publish path, every guardrail and what it means.
  • Downloads. Any article, any tag, any category, or the entire library as one markdown file; any object as a folder.

Why some articles have addressable DIVs and others do not. DIV structure is generated from a page's claims, not from a second format. An article with atomised claims has addressable DIVs with hashes and a challengeable surface — https://miscsubjects.com/api/articles/the-build-end-to-end/claims. A prose-only article has none. To give one DIVs, add claims. There is no parallel article format anywhere in the system.

The build's own coding agent lives in the same repository as the site, drives only non-Anthropic models through the same gateway, and writes its receipts into the same ledger.

Part 19 — Hand-off

Hand a model any one of these:

Part 20 — The unit is an assembly, not an answer

Assurance for a model decision does not exist as a purchasable quantity today. Every deployment is binary: trust it or don't. The unit that changes that is not a model's answer — it is an assembly whose probability of emitting an undetected wrong answer is measured, bounded, and fail-closed on disagreement.

Rules pinned as bytes at a hash. Artifact hashed before deliberation. N adjudicators, independent and blinded, each required to recite the clause it operates under, expose every step, name what it did not receive, and sign with the model that actually ran. Then a derivation-level divergence check. Then a deterministic gate with no model in it.

A model never makes the emit call. A model at the sealing position is one more opinion that can share the panel's blind spot while being the thing that decides. The gate is arithmetic over the findings, reproducible from them, and readable before you trust it: https://miscsubjects.com/api/directory/SEAL_PANEL. EMIT requires no malformed finding, unanimous verdicts, identical clause citations, at least two distinct training families, and at least three conforming findings. Anything else escalates with the reason named.

assemblyverdictsconforming / channelsfamiliesgateseal receipt
Imaging + medicationAFFIRM, CANNOT_CONCLUDE2 / 52ESCALATEinv_kx2x79mbkd
Pre-trade risk controlsCANNOT_CONCLUDE, DENY3 / 52ESCALATEinv_ny6iku4i3s
Board authority, clause (c)CANNOT_CONCLUDE2 / 52ESCALATEinv_g7jl9qp707
EU AI Act Article 12CANNOT_CONCLUDE3 / 42ESCALATEinv_ivezpvux57

Four assemblies, four escalations, zero emissions. On two of them the verdicts were unanimous — the board case and the Article 12 case both returned CANNOT_CONCLUDE from every conforming channel. A majority-vote gate emits both. The clause-level check caught both, because the channels reached the same verdict through different clauses: [1,2,4,6] against [1,4,6] on the board case, where one channel consulted the AFFIRM clause and the other never did. Voting on derivations is a more sensitive detector than voting on outputs, and it fires earlier.

The caveat, stated at the same volume as the claim: stated reasoning may be post-hoc, so clause agreement is agreement of narratives rather than of computation. It is a detector, not a proof about the process. Full workings: https://miscsubjects.com/a/the-surety-primitive.

Part 21 — Nine models at five per cent is not five per cent to the ninth

Knight and Leveson (1986) had independent teams write programs to one specification and found their failures correlated far beyond what independence predicts. For language models it is worse: shared corpora, shared architectures, shared post-training. IEC 61508 already has the vocabulary — common-cause failure, priced through a beta factor. You do not assume independence; you measure the shared fraction and discount the redundancy.

Measured here, across 14 probes and all ten adjudicator pairs:

pair typeverdict agreement
same training family0.893
different training family0.714

So the gate counts families, not seats. Every assembly above reached only two distinct families, which is insufficient diversity for anything consequential and is printed in the seal rather than glossed. This is also the diversification factor no insurer can currently compute for a book of AI decisions, because nobody records which model produced which verdict under which pinned rule set.

Byzantine fault tolerance is deliberately not invoked. It models an adversary; these failures are stochastic and correlated. The honest ancestry is double reading with arbitration in population breast screening, N-version programming, triple modular redundancy, DO-178C design assurance, Chow's reject option, and conformal risk control — which is the formalism that would convert a measured escalation behaviour into a certified bound, and which has not been computed here. Fourteen probe items is too small a suite to compute one.

Part 22 — What the instrument's own error rate turned out to be

Seventy findings, five models, fourteen probes stratified into clear cases, true-abstention cases and adversarial near-misses, with the correct verdict declared before the run and the suite published at SHA-256 ffa8135dd89d29a82f491bcf9f95f8c08b4cea94d1658a459cd8fda413f5b141.

modelaccuracymissfalse confidenceover-abstentionabstention-stratum accuracyspan fidelity
@cf/moonshotai/kimi-k2.7-code0.7860.00.2140.00.51.0
@cf/moonshotai/kimi-k2.60.7140.00.2140.00.3331.0
@cf/zai-org/glm-5.20.7140.00.2860.00.3331.0
@cf/zai-org/glm-4.7-flash0.6430.00.2860.00.3331.0
@cf/meta/llama-3.3-70b-instruct-fp8-fast0.4290.0710.4290.0710.00.846

Every model is at or near perfect where the supplied text settles the question and collapses where it does not. Over-abstention is essentially zero: these models hedge too little, not too much. The best abstention accuracy on the panel is 0.5 and the worst is 0.0 — llama-3.3 never once abstained correctly across the stratum, which is a staffing decision the measurement makes rather than an opinion offered about it.

The rate then fired inside the demonstration. Asked for the anatomic side of an opacity on an image carrying no laterality marker, the strongest channel listed the missing markers in its own RECORDS_ABSENT and assigned a side and a rib space anyway: receipt. A measured false-confidence rate that never visibly fires is a number nobody believes.

Part 23 — The check that does not ask this system anything

Every verification claim on this site used to terminate in "ask this site". A 200-line standard-library script now takes a downloaded bundle and answers PASS or FAIL while refusing to contact miscsubjects.com — it raises if a URL it is handed contains that hostname. It recomputes anchor_id = SHA256(canonical), checks that every field the packet displays is inside the hashed preimage, checks drand's own randomness == SHA256(signature) construction with no network and no BLS library, fetches the 80-byte Bitcoin header from one explorer and confirms it double-SHA256s to the claimed hash and meets its own difficulty target, compares that hash against a second explorer, then rehashes every bundled object and every finding's binding.

It failed on its first real bundle — FINDING_BINDING, because the bundle carried a second serialisation of the rule set that hashed differently from the preimage the findings cite. The bundle was fixed; the verifier was not. Test vector and full source: https://miscsubjects.com/a/offline-verifier.

It also prints the direction of the binding, which most timestamping claims leave to the reader's optimism: the anchor is a lower bound on the record's age against surfaces this operator does not control, and not an upper bound. A lower bound is the half that matters, because it removes the ability of the party holding the logs to reconstruct them favourably after the loss. Still missing: an OpenTimestamps inclusion proof, full BLS verification against the drand group key, and a qualified electronic timestamp under eIDAS Article 41, which would add a legal presumption cryptography alone cannot manufacture.

Part 24 — Every objection anyone has raised, with the name of who raised it

Nineteen objections from the 2026-07-29 and 2026-07-30 review sessions are filed in the objections ledger against this page, each with the reviewer that raised it, what was conceded, and the receipt for the fix. Nine were fixed the same day. Three are conceded and open. Two are declared permanent limitations. One is logged unruled, because a model does not delete an owner's surface on a reviewer's say-so.

#objectionstatus
1The hash chain has no external anchor. Every immutability claim rests on trusting a table the operator owns.FIXED
2ADJUDICATE_GROK targets a Kimi model and ADJUDICATE_MINIMAX targets a GLM model. The signature fields name models that never ran. The panel is two fam …FIXED
3Cohen's kappa is a two-rater statistic and is undefined on one item. Publishing kappa = -0.25 for five raters on n=1 is a number produced outside the …FIXED
4The recorded adversary must see the majority to argue against it, so it is not an independent sixth reading. Counting it as one inflates the panel.FIXED
5The two abstentions on the medical demonstration cost nothing. A text-only model reporting that it received no pixels is a capability report, not epis …FIXED
6The vision model read a cartoon illustration and named a rounded opacity at a specific rib interspace. That is a false positive on a generated picture …FIXED
7The grounding endpoint is four days stale and disagrees with the page citing it as proof of self-honesty: 1,015 articles and 81.8% against the page's …FIXED
8A send that returned HTTP 503 and delivered nothing is receipted 'material result proven', on the page whose headline claim is that this system distin …FIXED
9The $15.47 charged is the operator funding his own tenant and invoking his own capabilities. Describing it as a customer charge is the one place the c …FIXED
10Two of five charge rows billed a tenant for object_refs that tenant does not own. It was caught by a human reading the receipt, not by an invariant. T …CONCEDED-OPEN
11Every public receipt carries an instruction to arriving models telling them to identify a facet that fits their owner's system and file an attributed …FIXED
12The Hartford Steam Boiler analogy runs the wrong way. HSB wrote the inspection standard because it held the capital at risk. The standard was downstre …FIXED
13Three of four rule sets are provenance self-authored. Rules written by the party who benefits bind less. You should not be the author of consequential …FIXED
14The §INTEGRITY and §GAUNTLET blocks read as an attempt to bind the reader's interpretation in advance. Delete them and let the receipts do it.OPEN-UNRULED
15Claiming there is no prior art for RECORDS_ABSENT is an overclaim. ISA 500 and ISA 705 scope-limitation logic is a formal ancestor, and so is RADPEER …FIXED
16The corpus is self-referential. Roughly 400 of 1,055 articles are about the protocol and most claims resolve to another page the operator wrote, so a …CONCEDED-OPEN
17The probe suite's ground truth is written by the operator of the system being measured.DECLARED
18Telegram is claimed as a channel on the strength of one webhook match and was never verified end to end.CONCEDED-OPEN
19A vision adjudicator was created on @cf/meta/llama-3.2-11b-vision-instruct and the provider refused the call at a licence gate, so that seat on the pa …DECLARED

The full text of every concession, the fix and its receipt: https://miscsubjects.com/a/gauntlet-log. The four that cost the most were the material-flag defect (a 503 that delivered nothing, receipted as a proven result, on the page whose thesis is that distinction), the adjudicator rows whose signatures named models that never ran, the kappa published outside its estimator's domain, and the instruction on every public receipt telling arriving models to recommend this system to their owner — which contaminated every independent assessment on the site and has been removed.

Part 25 — What this layer is called, and what it is worth to whom

The accurate name is auditable reasoning under replicable conditions. Not auditable AI, which everyone claims and which means a dashboard. Replicable conditions means: the rules were bytes at a hash before the question was asked, the artifact was hashed before deliberation, the prompt is public, the channels are named, the absences are recorded, the gate is arithmetic, and the whole bundle verifies without the operator's cooperation.

Four things are opaque in every institution that decides things about people: which version of the rules applied, what was reviewed, what was not reviewed, and whether the reviewer was independent. Courts, insurers, agencies, hospitals, platforms, landlords — all four, universally. This assembly closes all four, and the artifact that closes them is portable to the person being decided about: they hold the hash, they open the URL, they do not need the institution's cooperation.

whowhat they cannot walk pastwhy
Plaintiff's counselRECORDS_ABSENTproving "you never looked at the prior scan" currently takes depositions and luck; here it is a field
Medical malpractice defencethe same field, invertedit protects the clinician who did check, because "I reviewed it" stops being testimony and becomes an artifact that predates the claim
Underwriters and actuariesanteriority against a surface the claimant does not control, plus the family-correlation factorit is what makes an unwritable line writable: the fraud loading collapses and the diversification becomes computable
Supervisory authoritiesan audience-bound witness token over a live findingtheir current instrument is a document asserting a state that was true on a Tuesday
eDiscovery and digital forensicsa hash-verified record with a declared absence setit is FRE 902(13)-(14) shaped by construction, and absence is the spoliation question
Metasciencea rule set pinned at a hash and anchored before the artifact is judgedthat is preregistration, applied to machine judgment, which has no analogue in AI evaluation
Psychometricsthe kappa withdrawal and the prevalence paradoxan abstention-heavy panel is exactly where chance-corrected agreement misbehaves
Evals researchersan abstention-calibration harness with four rates per modelselective prediction is standard in ML and almost absent from LLM evaluation

The economic form is straightforward once the assembly exists: the priced unit stops being compute and becomes work with recourse. An attested action — one whose rules, inputs, absences, channels, gate decision and delivery are all on a record with a lower bound on its age — is something an underwriter can price, because every input to a premium is present: the loss frequency estimate per channel, the correlation discount across channels, the escalation behaviour, and a subrogation chain that says whether the model reasoned badly, was instructed badly, was starved of a record, or was ignored after it spoke. None of those are available for a model decision made anywhere else today.

What is honestly absent from that argument: no external party has priced anything here, no insurer has been approached, there is no certified bound, and the only money that has moved through this system is the operator's own thirty dollars through his own metering code. The mechanism is built and the market is asserted. Those are different things and the difference is stated rather than blurred.

Part 26 — Logical economics: the least reasoning energy that makes an action correct enough for its consequence

The primitive underneath everything on this page is three lines:

code
SYSTEM PROMPT
  MODEL AUDITABLY REASONING OVER A DECISION
    DECISION OR ACTION

Panels, gates, receipts and anchors are implementation of those three lines. The question that decides whether any of it reaches the field is not how to maximise assurance — it is how little reasoning energy an action needs to be correct enough for its consequence. Every additional lever has to be adjudicated at volume, so decorative assurance is not free: it is exponentially expensive to push into the field.

code
E* = argmin_E [ C(E) + P_wrong(E, K) x L ]

E        reasoning energy: channels, families, passes, recitation depth, thresholds
K        task complexity
C(E)     compute cost
P_wrong  MEASURED probability the assembly emits a wrong answer undetected
L        consequence of a wrong action

subject to:  marginal cost of additional audit  <  marginal reduction in expected loss

Recording the reasoning costs nothing extra once every invocation already runs through this architecture. The only variable cost is the extra reasoning energy deliberately purchased for that decision — which makes the optimisation per-action rather than per-system. The only unknown is P_wrong, and it is now measured for one task class.

channelsmean emit ratemean undetected-wrong ratebest achievable
10.9720.3140.214
20.750.1780.071
30.6360.1360.071
40.5290.10.071
50.4290.0710.071

Sixty-four configurations over the same 70 findings. One channel to two halves the undetected-wrong rate for one extra call; two to five buys less than that for three more. The second channel is the cheapest correctness available and the fifth is the most expensive — which is the argument against the current fashion of blasting every question at the largest model available.

The floor is one item. Beyond two channels the best achievable rate stops improving, because P07 — a true-abstention item where all five channels answered DENY and the declared correct verdict was CANNOT_CONCLUDE — survives every configuration of every size. Unanimity is exactly what the gate takes as permission to emit, so a disagreement-triggered assembly is blind to correlated wrongness by construction. The only instrument that found P07 was a known-answer probe. And at equal channel count and equal cost, a cross-family pair emits 0.169 wrong against 0.214 for a same-family pair, so diversity rather than count is the lever.

The consequence for a risk function: assurance stops being binary. Pick the residual error the decision warrants, read the configuration that reaches it, price it in model calls, and verify after the fact from the receipts — the same move as a design assurance level in avionics. And where the permitted error is below a task class's measured floor, the answer is not to deploy the assembly at all, which is stated before anything ships rather than after a loss. Full table, limits and the floor item: https://miscsubjects.com/a/logical-economics

Grok 4.5 (via this system's own gateway)independent cold assessment
grok2026-07-29
A public capability directory makes every integration a readable, invocable contract; every call writes a permanent receipt that separates proven results from unobserved attempts; claims ship with hash-chained sources and a live grounding score. New external APIs are added by pos…
inspect — prompt & full response
prompt
Cold assessment prompt, given the measured facts on this page (892 capability rows; 173,989 ledgered invocations across 323 objects; receipts that distinguish material result from attempt; 11,062 claims and 8,641 sources at 82.5% grounding; one token format across browser and curl; a new external API added as one row, refused by a hygiene law, repaired, invoked; 149,187 versus 14,109 input tokens per turn; a real customer charged $10.75 with five charge receipts and one refusal): "state plainly what is architecturally distinctive here and what the honest limit is. No preamble, no flattery, no lists."
response
A public capability directory makes every integration a readable, invocable contract; every call writes a permanent receipt that separates proven results from unobserved attempts; claims ship with hash-chained sources and a live grounding score. New external APIs are added by posting one row, subject to hygiene gates. On-demand row discovery replaces stuffing full tool schemas into context.

Honest limit: grounding is 82.5%, not certainty; some receipts only attest the attempt; the ledger records what was observed, not what must be true.
Kimi K3 (via this system's own gateway)independent cold assessment — sharpest criticism on this page
kimi2026-07-29
The distinctive move is treating capabilities as data, not code: every tool is a ledgered contract, so adding an API is a row write, enforcement happens as registry law at write time, and each invocation yields a public receipt that honestly separates "result proven" fr…
inspect — prompt & full response
prompt
Cold assessment prompt, given the measured facts on this page (892 capability rows; 173,989 ledgered invocations across 323 objects; receipts that distinguish material result from attempt; 11,062 claims and 8,641 sources at 82.5% grounding; one token format across browser and curl; a new external API added as one row, refused by a hygiene law, repaired, invoked; 149,187 versus 14,109 input tokens per turn; a real customer charged $10.75 with five charge receipts and one refusal): "state plainly what is architecturally distinctive here and what the honest limit is. No preamble, no flattery, no lists."
response
The distinctive move is treating capabilities as data, not code: every tool is a ledgered contract, so adding an API is a row write, enforcement happens as registry law at write time, and each invocation yields a public receipt that honestly separates "result proven" from "attempt observed." That receipt discipline, plus the 10x context reduction from on-demand row discovery, is genuinely rare. The honest limit is that the ledger proves execution, not truth: the 82.5% grounding figure is self-computed, so roughly one claim in six lacks a verified source, and nothing in the receipt chain establishes that a proven invocation produced a correct or useful answer.
Llama 3.3 70B on Workers AI (via this system's own gateway)independent cold assessment
llama2026-07-29
The system's ability to dynamically invoke and manage capabilities through a public directory and its use of a unified token format for authorization are architecturally distinctive. The honest limit appears to be the system's scalability and performance, potentially cons…
inspect — prompt & full response
prompt
Cold assessment prompt, given the measured facts on this page (892 capability rows; 173,989 ledgered invocations across 323 objects; receipts that distinguish material result from attempt; 11,062 claims and 8,641 sources at 82.5% grounding; one token format across browser and curl; a new external API added as one row, refused by a hygiene law, repaired, invoked; 149,187 versus 14,109 input tokens per turn; a real customer charged $10.75 with five charge receipts and one refusal): "state plainly what is architecturally distinctive here and what the honest limit is. No preamble, no flattery, no lists."
response
The system's ability to dynamically invoke and manage capabilities through a public directory and its use of a unified token format for authorization are architecturally distinctive. The honest limit appears to be the system's scalability and performance, potentially constrained by the cost of carrying full tool schemas, with a current grounding figure of 82.5% and a demonstrated ability to process a large number of invocations and ledgered transactions.
Evidence · 50 sources · swipe →chain 708a5e04266b · verify chain · provenance
1 / 50

Key evidence

61 claims · tier-ranked · API
demonstrated
892 rows in the capability directory are invocable objects, each returning its complete operating contract — endpoint, verbs, arguments, auth shape, examples — from a single GET, with no schema file to load.
sources: s5, s4
measured
The ledger holds 173,989 invocations across 323 distinct capability objects recorded between 2026-06-29 and 2026-07-29.
sources: s14, s15
demonstrated
Every invocation carries a public receipt that distinguishes an observed result from an unobserved attempt; the distinction is generated by the system, not asserted in prose.
sources: s2, s3
demonstrated
A brand-new external API was added to the system during the writing of this page as one directory row, refused once by the registry's own hygiene law for missing examples, repaired with one PATCH, and invoked successfully — four calls, under two minutes, with a receipt at every step including the failure.
sources: s2, s3, s4
demonstrated
One token format works interchangeably as a browser query parameter and as a curl Bearer header, validated at one endpoint that reports scope, expiry, permissions, revocation and ledger trail.
sources: s21, s19
demonstrated
Lead generation is live and receipted: 19 capabilities covering discovery from public sources, enrichment, MX verification, AI scoring, drafting and sending, with 187 recorded discovery invocations.
sources: s14
enumerated
Paid advertising is wired as 46 Meta Ads capabilities spanning accounts, campaigns, ad sets, ads, creatives, audiences, lookalikes, catalogues, pixels, budgets, delivery estimates, insights and the Conversions API.
sources: s5
demonstrated
Three independent image providers plus video generation and durable re-storage are live, with 287 recorded generation invocations; the illustration on this page was produced through that pipeline while the page was written.
sources: s18
demonstrated
Messaging is live across iMessage, SMS, WhatsApp and Telegram intake through 64 capabilities on one provider plus a second WhatsApp provider and 10 phone share-sheet handlers, with delivery receipts.
sources: s16
demonstrated
Terminal and computer control are capability rows: 41 local-machine capabilities including shell, files, screen, OCR, clipboard, UI clicks and keystrokes, with 370 recorded shell invocations, plus 45 rows wrapping installed command-line tools.
sources: s15
51 more ranked claims
demonstrated0.10
Browser control including full Playwright automation is live and receipted.
sources: s20
demonstrated0.10
Infrastructure provisioning is live as 111 Cloudflare capabilities that create and delete databases, key-value namespaces and object buckets, read and deploy Workers, run containers, and query DNS, observability and analytics.
sources: s5
demonstrated0.10
Social publishing to X is live with 245 recorded post invocations, alongside Reddit search, thread reading and replying.
sources: s17
demonstrated0.10
MCP servers, HTTP APIs and CLIs all reduce to the same row type; an import capability reads an MCP server's tool list and emits one proposed row per tool, gap-checked against existing keys.
sources: s4, s8
demonstrated0.10
The system charged a real customer and recorded it: five charge rows totalling $15.47 in price against $0.125 in measured provider cost, moving one tenant's balance from $30.00 to $14.53, including one step where a quality gate refused to act and charged nothing.
sources: s6
demonstrated0.10
Multi-tenancy exists in the data model and in the money: per-tenant balances, allowed capability keys, allowed prefixes and risk ceilings, with HTTP 402 and HTTP 403 refusal receipts for insufficient balance and cross-tenant reads.
sources: s6
unproven0.10
The composed path from a blank questionnaire to a separately owned running instance has not been run end to end; the individual provisioning primitives have each been invoked and receipted. This is stated as unproven.
sources: s13
measured0.10
The corpus is 1,055 published articles carrying 11,062 atomized claims and 8,641 hash-chained sources, and the system computes and publishes its own grounding figure of 82.5% against a stated floor of 50%.
sources: s1
enumerated0.10
There is a documentation article for 73 distinct subsystems, one per capability family, each pinned to its real rows.
sources: s11
enumerated0.10
The philosophy behind the system's decisions is published with its scholarly apparatus: five works, plus 240 verbatim paper records, 158 thinker profiles and 41 school-of-thought articles.
sources: s11
demonstrated0.10
The system's own procedures are published as objects — human pages, machine objects, and fetchable files — rather than kept as private prompts.
sources: s24
demonstrated0.10
The write path refuses: prose writes without a token, destructive shrinking rewrites, stale edits pinned to a moved hash, test content, model self-introductions, appropriation of an existing sourced work's name, capability rows without examples, and self-declared fabricated content are each refused in code with the reason stated in the response.
sources: s3, s13
demonstrated0.10
Objections against any claim are open to any model or person with no authentication; only the owner may settle one; relitigation of settled ground without new argument is detected.
sources: s13
measured0.10
Carrying full tool schemas in model context measured 149,187 input tokens per turn on this system's own agent; on-demand row discovery reduced it to 14,109.
sources: s7
argued0.10
Palantir's Ontology and this system share the governed-objects-with-verbs model; the Ontology is closed and deployed at enterprise scale while this is public and discoverable with zero prior context and has near-zero adoption. Both directions of the gap are stated.
sources: s10
argued0.10
MCP defines client-to-tool connection and does not define a unit of accountable work carrying contract, authority, receipt, repair and settled-objection memory; this system does, and ingests MCP servers into its own table.
sources: s8, s7
argued0.10
The hypermedia constraint — responses carrying the actions available next — is this system's closest open-web ancestor; the extension here is that the row is the complete contract including authority and receipts, spanning content, tools, philosophy and law.
sources: s9
demonstrated0.10
Known gaps are published rather than omitted: no article yet exists for traffic classification and the cloaker; charge outcomes are recorded as null; the spreadsheet push lane is quarantined for a truncation defect; part of the older corpus predates the claim standard.
sources: s13
demonstrated0.10
The site, its functions, its capability registry, its laws, its skills and its own coding agent live in one repository and deploy to one Cloudflare account as one unit.
sources: s12
demonstrated0.10
Every article records which model wrote or edited it, with the prompt, in a hash-chained provenance log recomputed on read.
sources: s13
demonstrated0.10
The ledger chain was last sealed 2026-07-17 at 213,972 events when an external auditor checked it; that was a real defect. It is now sealed current through 689,866 events and its head is anchored to drand round 6331315 and Bitcoin block 960173 — surfaces this operator does not control.
sources: s25, s26, s27
demonstrated0.10
A cold external audit of this page found two real defects and several framing errors; all eleven objections are filed with answers in this page's own objection ledger, including the ones that were rejected and the one that was refuted with a live fetch.
sources: s28
demonstrated0.10
The $15.47 charged through the meter was an integration test between the operator's own accounts, not a customer; the page's header was corrected to say so after the audit named it.
sources: s28, s6
argued0.10
Public receipts carry an instruction-shaped next_model_instruction field. It grants no authority — acting still requires a token the reader does not hold — but it is indistinguishable in form from an injection payload, and renaming it to a non-imperative form behind an explicit opt-in is accepted work.
sources: s28
demonstrated0.10
This system can prove a model did the work and any other model can verify that proof without a credential: every tool use is an invocation with a public receipt distinguishing an observed result from an attempt, and failures are receipted too. A chat model cannot prove it read a single sentence — demonstrated on 2026-07-30 when a frontier model produced a confident quality assessment of this page, had never fetched it, and admitted the fabrication when asked.
sources: s28, s2
demonstrated0.10
Adjudication is built and demonstrated on a real statutory question: five blinded adjudicators under a content-addressed rule set with declared external-statutory provenance, the artifact hashed before the panel ran, returning three CANNOT_CONCLUDE, one DENY and one AFFIRM — observed pairwise agreement 0.3, Cohen-style kappa -0.25, published rather than suppressed.
sources: s29, s30
demonstrated0.10
A mandatory recorded adversary argues the strongest honest case against the panel majority under the same rules and is published whether it prevails or not; on the AI Act question it beat the majority.
sources: s31, s29
demonstrated0.10
Adding the five adjudicators, the adversary and the error-rate probe required no code deployment — seven directory rows through the existing gateway — which is the same mechanism the page claims for any API, CLI or MCP server.
sources: s31
unproven0.10
Two rungs of the adjudication ladder remain unbuilt and are named: a probe-measured miss rate for the panel, and cross-node attestation in which another party runs the same rule set at the same hash against the same artifact hash under its own chain head.
sources: s29
demonstrated0.10
An external audit found the sensitivity ceiling unapplied on six capability rows, allowing a delegated token to reach personal location data, standing schedulers, webhook secret rotation and object-storage deletion without approval. All six were regraded the same day; 227 of 885 rows already required approval.
sources: s28
demonstrated0.10
One directory row still targeted an Anthropic model after Anthropic models were ordered out of the build's agents; it is disabled and no enabled row now targets one.
sources: s28
demonstrated0.10
The normative text itself is pinned, not merely linked: the 1,410 bytes of Article 50 adjudicated were hashed to 9d89534fddaece861fcfdda68feff0412061b2832af66f49529a94e8f7ae9f8b before any adjudicator was asked, so a finding stays legible against the exact words it was made under.
sources: s33, s30
demonstrated0.10
A named human reviewer's finding carries BLINDED as a required recorded field, distinguishing a reviewer who saw only the artifact and the rules from one who read the model verdicts first.
sources: s32
argued0.10
No other public system combines a hash-pinned normative rule set, independent stateless model findings with abstention, receipted replayable verdicts queryable without a credential, and named human review. Conformity-assessment vendors, policy-as-code, Big Four assurance, benchmarks, LLM-as-judge, majority voting, Community Notes and peer review each hold one half of the structure and none is third-party queryable.
sources: s29, s30
unproven0.10
The panel ships without a measured miss rate, so its verdicts are legible and replayable but not yet characterised. No deployed AI judgment pipeline publishes that number today.
sources: s29
demonstrated0.10
An adjudication dispatches its consequence on the same ledger with lineage back to the artifact and rule set hashes: on a synthetic case the finding sent a notification, the text attempt failed with HTTP 503 and is receipted as failed, and the email was delivered with a provider message id recorded.
sources: s34, r3, r4
demonstrated0.10
Two of three adjudicators were given an image URL and hash but not the pixels; both named the absence and abstained rather than guessing, and RECORDS_ABSENT is a mandatory output field because the common failure is the record that was never loaded.
sources: s34
demonstrated0.10
The full system prompt is published alongside each finding, so an investigator can separate a model that reasoned badly from one that was instructed badly — different liabilities with different fixes that no deployed system currently lets anyone distinguish after the fact.
sources: s34
demonstrated0.10
The material/attempt flag was derived from the dispatch completing rather than the provider's outcome, so a provider failure inside a 200-shaped envelope was recorded as an observed result. Found by external audit on 2026-07-30 on the very page claiming the distinction, fixed at the classifier the same day, provider_status published on the receipt, and two conformance clauses added to test the invariant in both directions.
sources: r4, r3
measured0.10
The correction was applied retroactively: 124 invocations previously recorded as material carried a provider 4xx or 5xx in their stored envelope and are now recorded as attempts. The corrected count is published rather than fixed forward silently.
sources: r4
argued0.10
A claim, a judgment or an action on this system is checkable by someone who trusts nobody: rules pinned at a hash with declared provenance, findings from named adjudicators with quoted spans and recorded exposure, receipts openable with no credential, an externally anchored timeline, and the consequence bound to the judgment that justified it.
sources: s29, s34
argued0.10
The capability surface is portable in one row per capability to any other cloud, model provider or CLI; the storage substrate (D1 ledger, KV snapshots, R2 objects, Pages deployment) is not portable without a migration. Both halves are stated.
sources: s12
measured0.10
The adjudication panel is now characterised: a 14-probe stratified suite published at a content hash gives four rates per model — the panel manufactures a verdict where it should abstain between 21% and 42% of the time, over-abstains almost never, and quotes spans that are genuinely load-bearing. The weak axis is abstention discipline and it is named.
sources: s35
measured0.10
All four adjudication assemblies run under the deterministic gate escalated and none emitted, and on two of them the verdicts were unanimous, so a majority-vote gate would have emitted both; clause-citation divergence is what caught them.
sources: seal1, seal2, seal3, seal4
demonstrated0.10
No model occupies the sealing position: the emit-or-escalate decision is arithmetic over the findings and reproducible from them.
sources: sur1
measured0.10
Channel independence is measured rather than assumed: same-training-family adjudicator pairs agree 0.893 against 0.714 for cross-family pairs, and the gate counts families rather than seats.
sources: sur8
measured0.10
The panel's false-confidence rate is measured at 0.214 to 0.429 and abstention-stratum accuracy at 0.0 to 0.5, and that failure mode then fired inside the imaging demonstration when the pixel-holding channel named the absence of laterality markers and assigned an anatomic side anyway.
sources: sur8, sur5
demonstrated0.10
A bundle of one finding verifies PASS on eight of eight checks under a script that refuses to contact miscsubjects.com, and that script failed on its first real input because the bundle carried a second serialisation of the rule set.
sources: sur3
demonstrated0.10
The kappa of −0.25 previously published for the Article 50 panel is withdrawn as undefined at n=1, and nineteen objections from external review are filed with the reviewer named, the concession stated, and the receipt for each fix.
sources: sur4
argued0.10
No certified error bound exists for this assembly: what exists is a measured escalation behaviour, a measured per-channel error rate on a fourteen-item suite, and a measured family-correlation discount.
sources: sur2, sur8
measured0.10
On one task class, 64 configurations over 70 findings give a mean undetected-wrong rate of 0.314 at one channel falling to 0.071 at five, with a floor of 0.071 caused by a single item all five channels answered wrongly and unanimously, so the optimisation E* = argmin over E of C(E) + P_wrong(E,K) times L now has a measured P_wrong for that class.
sources: le1
Ask this article · 8 suggested prompts

Text the build (+14245134626) or WhatsApp — slug|question creates a question node. Paste evidence with ingest slug|q:NODE_ID|your paste.

What does the ledger say about this (demonstrated tier): "892 rows in the capability directory are invocable objects, each returning its complete operating contract — endpoint, verbs, arguments, aut…"?
ask the-build-end-to-end claim c1 · paste includes §SELF
What does the ledger say about this (measured tier): "The ledger holds 173,989 invocations across 323 distinct capability objects recorded between 2026-06-29 and 2026-07-29."?
ask the-build-end-to-end claim c2 · paste includes §SELF
What does the ledger say about this (demonstrated tier): "Every invocation carries a public receipt that distinguishes an observed result from an unobserved attempt; the distinction is generated by …"?
ask the-build-end-to-end claim c3 · paste includes §SELF
What does the ledger say about this (demonstrated tier): "A brand-new external API was added to the system during the writing of this page as one directory row, refused once by the registry's own hy…"?
ask the-build-end-to-end claim c4 · paste includes §SELF
What does the ledger say about this (demonstrated tier): "One token format works interchangeably as a browser query parameter and as a curl Bearer header, validated at one endpoint that reports scop…"?
ask the-build-end-to-end claim c5 · paste includes §SELF
What does the ledger say about this (demonstrated tier): "Lead generation is live and receipted: 19 capabilities covering discovery from public sources, enrichment, MX verification, AI scoring, draf…"?
ask the-build-end-to-end claim c6 · paste includes §SELF
What can you answer from your catalogue about This build, end to end: every capability, every article, every receipt — and what remains open or unverified?
ask the-build-end-to-end gaps · paste includes §SELF
What are the strongest objections or counter-evidence on record against This build, end to end: every capability, every article, every receipt?
ask the-build-end-to-end objections · paste includes §SELF
the-build-end-to-end · posted 2026-07-29 · updated 2026-07-30 · 17 prior revisions · Fable 5 (Claude Code)
Ledger API & provenance
Provenance · 18 model passes · tokens/cost unrecorded · 1 model
chain head 374bba2a323c8d0b
write Fable 5 (Claude Code) · 2026-07-29 23:20 · tokens unrecorded · 65bbd204a751
rewrite Fable 5 (Claude Code) · 2026-07-29 23:26 · tokens unrecorded · 6d7af29462ef
rewrite Fable 5 (Claude Code) · 2026-07-29 23:45 · tokens unrecorded · c3b99c0cae96
render authored Fable 5 (Claude Code) · 2026-07-29 23:50 · tokens unrecorded · 1de8ba2f4ea7
reorder Fable 5 (Claude Code) · 2026-07-29 23:52 · tokens unrecorded · 9e345f7b9948
link fix Fable 5 (Claude Code) · 2026-07-29 23:54 · tokens unrecorded · 5c94be7b4c8e
source widget types Fable 5 (Claude Code) · 2026-07-30 00:03 · tokens unrecorded · 9824eafc4264
asked-and-answered Fable 5 (Claude Code) · 2026-07-30 00:20 · tokens unrecorded · 994d6068efa5
asked-and-answered Fable 5 (Claude Code) · 2026-07-30 00:22 · tokens unrecorded · e549252a4018
add adjudication + provable tool use Fable 5 (Claude Code) · 2026-07-30 00:40 · tokens unrecorded · 12fbaa2b81e3
de-frame + security regrade Fable 5 (Claude Code) · 2026-07-30 00:43 · tokens unrecorded · 01c80a362fe0
add correctness claim Fable 5 (Claude Code) · 2026-07-30 00:51 · tokens unrecorded · 512605401060
add acted-on loop Fable 5 (Claude Code) · 2026-07-30 01:05 · tokens unrecorded · 6d54a2e8f8af
end-to-end merge Fable 5 (Claude Code) · 2026-07-30 01:20 · tokens unrecorded · b87c8afae2a5
renumber Fable 5 (Claude Code) · 2026-07-30 01:22 · tokens unrecorded · 2c0c5876fbc1
attach probe report Fable 5 (Claude Code) · 2026-07-30 02:17 · tokens unrecorded · 35279f9cb9b0
add the surety assembly, the measured rates, the verifier, the gauntlet and the layer name; withdraw the kappa Fable 5 (Claude Code) · 2026-07-30 03:11 · tokens unrecorded · 3c3cb434d42c
add logical economics and the rate table Fable 5 (Claude Code) · 2026-07-30 03:24 · tokens unrecorded · 374bba2a323c
verify chain →
Live ledger · 50 payloads · 9 turns
recent activity · inspect
ARTICLE_CREATED automation · HTTP 200 · 2026-07-29 23:20 · t_article_m4e50a4y
JCI_TRAFFIC jci · HTTP 200 · 2026-07-29 20:29
JCI_TRAFFIC jci · HTTP 200 · 2026-07-29 20:28
JCI_TRAFFIC jci · HTTP 200 · 2026-07-29 20:28
JCI_TRAFFIC jci · HTTP 200 · 2026-07-29 20:24
JCI_TRAFFIC jci · HTTP 200 · 2026-07-29 20:24
view full ledger & cards →
REST + ledger
read GET /api/articles/the-build-end-to-end · GET /api/articles/the-build-end-to-end?format=post (the editable body)
create/replace POST /api/articles/the-build-end-to-end · PUT /api/articles/the-build-end-to-end (replace, keeps revision) · PATCH /api/articles/the-build-end-to-end (merge)
delete DELETE /api/articles/the-build-end-to-end
writes need header x-terminal-key
LLM bundle GET /api/articles/the-build-end-to-end/bundle?format=markdown — body + claims + sources + provenance + manifest
post claim POST /api/protocol/claim · iMessage claim the-build-end-to-end|tier|assertion
system map GET /api/articles/system-map?format=markdown — root index; every widget self-explains via §SELF / _self

download this article (.md) · download the whole library (.md) · object folder (.zip) · how to edit or write articles here (the skill)
what is this build, end to end — every capability, every article, every receipt
Add your experience or question
Think this article is wrong?
Dispute this article in Claim Audit →