Skip to content
Paula Livingstone writing · projects · tools

Attestable Design & Artefact

The Structure of a Basis Record: Fixing the Model, and the Two Forks Settled

Crosses the line the spine held: fixes what a basis record holds and resolves the two forks the spine handed the drafting. A basis record is a structured object, not a score, attached to one claim: means (observation/measurement/inference/generation/report), authority, establishment time paired with rate of change, established scope, and an origin set. Fork 1 (how independence is known) is settled by the boundary, not by size: the consumer does not hold the ancestors at the handover, so independence rides on an origin set of evidential origins, tested by intersection from the crossing records alone. The load-bearing qualifier: origin is the origin of the evidence, not of the subject, or the model becomes a corroboration-refuser. Fork 2: authority kept as its own field, since it varies independently of means. The act's demand stays out, because admissibility is a relation.

The requirements fixed what the basis model must represent without fixing how. This section does the three things they left undone: it commits to what a basis record holds, it resolves the largest structural choice, and it settles a smaller question the preceding section deliberately left to it. Each commitment is argued from what the model demonstrably needs rather than from what would be tidy, because this is the artefact the rest of the dissertation goes rigid against, and a structure chosen by default here is a structure the inheritance method, the admissibility method, the evaluation, and the conclusion would all inherit unexamined.

The account stays at the level of structure and stops short of code. It says what a basis record consists of and how its parts relate; it does not give class definitions or type signatures, which belong to the library and to a model that has first been argued. The distinction between naming a requirement and sketching a solution still holds here. What changes is that the naming is now specific enough to build against and to be shown wrong.

A basis record, and what it is attached to

The unit the model represents is a basis record: the structure attached to a single claim that says what that claim rests on. A claim is a proposition a system holds and may act on, such as that a circuit is de-energised; the basis record is not the claim and does not assert it, but describes the grounds on which the claim is held, in terms a consumer that did not produce the claim can read. One claim has one basis record, and the record travels with the claim across the boundary where ownership changes. That pairing is the model's atom, and everything below is either a field of the record or a relation between records.

The record is deliberately not a score. The review established that a scalar confidence is the wrong category for the judgement admissibility requires, the field's own comprehensive survey concluding that estimating predictive uncertainty is not sufficient for safe decision-making (Gawlikowski et al., 2021), so the model that replaces it cannot itself be a number or collapse to one. A basis record is a structured object with named fields, each answering one of the questions the model is required to be able to answer, and it is the structure, not any single field, that carries the basis.

The fields of a basis record

The requirements named the elements the model must represent. Fixing the structure meant saying which are fields of the record and what each field holds. Six are properties of the claim's own grounding and are carried as fields directly: acquisition, transformation, authority, establishment time, rate of change, and established scope. These are the model's fields; the implementation carries several of them at a finer grain, splitting transformation into the semantic relation and the producing mechanism, and adding the supporting fields the axes need. A seventh element, independence, is not a field of a single record but a relation computed between records, and it is treated separately in the next section because it is where the largest structural choice falls.

The first two fields are acquisition and transformation. Acquisition states how the evidence directly supporting the claim was obtained, drawn from a fixed and small set of kinds; transformation states what operation produced the claim from that evidence. They are separate fields because they answer different questions, and an early version of the model carried them as one; the section on the means taxonomy records why that failed and what replaced it. This field is load-bearing beyond its size, because the whole problem the work addresses begins in the difference between a value that was measured and one that was generated. That difference is not a matter of degree. A probabilistic model produces claims by sampling a distribution conditioned on context, and the resulting assertion carries no measurement behind it; the training objective rewards confident guessing over calibrated abstention, so basis-free assertion is a structural product of how such models are built (Kalai et al., 2025), and the fluency of the output is unconnected to its grounding (Hicks et al., 2024), and the distinction the record must hold is that generation is not observation. Both fields draw on closed vocabularies rather than free text, because the inheritance and admissibility methods must be able to reason over them mechanically, and a method cannot branch on a description it has to interpret.

The third field is authority: what stands behind the basis and on whose say-so. It is carried separately from acquisition and transformation because the three vary independently. A measurement from an uncalibrated third-party device and a measurement from a calibrated in-house one share an acquisition and differ in authority; a report relayed by a trusted operator and the same report relayed by an untrusted contractor share an acquisition and differ in authority. A model that folded authority into acquisition would be unable to state either of those differences, and both are differences a consumer deciding whether to act needs to see. Authority names the responsible source; it does not score it, for the same reason the record as a whole is not a score. The targeted reading of trust management sharpened this field in one specific way, on the field's own account rather than on the model's. SPKI/SDSI, read for whether the record's authority needed the internal structure of a delegation chain, confirmed that it does not for the independence test the record must support, because the dependence a delegation chain tracks is the flow of authorisation and not the sharing of evidence, and evidential independence is not a question that formalism asks. But it named something the bare identifier drops that is not a matter of delegation at all: a vouching has a validity, an interval over which it holds, and it can lapse or be revoked, so that the complete fact is not that a source vouched but that a source vouched over a period that may since have ended (Halpern and van der Meyden, 2002). An identifier that records only who vouched cannot state that, and it is a true thing about the basis, so the authority field carries the validity status of the vouching alongside the identifier of its source, not the identifier alone.

This enriches the authority field rather than adding another, and it does so along a line the model has already committed to on another axis, which is why it is an enrichment and not a new shape. Establishment time paired with rate of change is the record carrying the temporal standing of the basis, and the freshness judgement, whether that standing suffices for the act, is left to the admissibility method. Authority validity is the same distinction on the axis of the voucher rather than the basis: the record carries that a vouching had a validity and whether it still holds, and the judgement of whether a vouching that was live when made but has since lapsed suffices for this act is left, exactly as freshness is, to the admissibility method. The carrying is the record's; the deciding is deferred. The parallel to freshness is the reason to trust the split: it matches a distinction the model already drew rather than inventing one for this field. What the record does not take on is the machinery by which a validity is checked or a revocation propagated, the revocation keys and revocation lists and online tests that formalism also defines. That is authorisation infrastructure and belongs to the instantiation if it belongs anywhere in this work; the record carries the fact that a vouching can lapse and defers the mechanism of checking it, the same line drawn against importing the delegation chain itself.

The fourth field is establishment time, and the fifth is the rate at which the underlying condition changes. They are carried as a pair because neither is useful alone. A basis has a shelf life, and the shelf life is not a property of the basis or of the clock but of the two together: a position established an hour ago is fresh for a tank that fills over a day and stale for a valve that actuates in seconds. The model carries when the basis was established and how quickly what it concerns can change, and leaves the freshness judgement, which compares the two against what the act can tolerate, to the admissibility method, because freshness like admissibility is relative to the act and not a property of the record alone.

The sixth field is established scope: the bounds within which the basis holds. A claim true of a sample is not true of the population, and a claim true at one point in a plant is not true of the plant, and the record carries the scope its basis actually establishes. This is distinguished from the scope an act requires, which is a demand of the act and lives with the act; established scope is the basis side of that distinction and is a field of the record, while required scope is not.

The largest choice: how independence is known

This was the largest structural choice in the design, and three resolutions were open: the record holds its ancestry, the record holds a position in a graph that lives elsewhere, or something between. The choice is settled here, and it is settled by asking what the independence judgement needs at the boundary where the discipline claims to work.

Independence is not a property of a single claim but a relation between two: whether two supports for a conclusion are genuinely separate or are one source counted twice. The inheritance guardrail turns on exactly this relation, because mutually dependent sources do not corroborate, and a discipline that read two views of a single source as corroboration would manufacture confidence from nothing. So the model must be able to answer, of two claims, whether they are independent. The question is where it must be able to answer it.

The setting fixes the answer. The whole work concerns the machine handover where no person is standing: a value crosses from a producer to a consumer carrying its basis record, and the consumer decides admissibility at that point. At that point the consumer holds this claim's record. It does not reliably hold the records of the claim's ancestors: the parents were the producer's inputs and may not travel, and the grandparents almost certainly do not. So a model that could answer the independence question only by walking a chain of ancestor records would be unable to answer it at the boundary in the general case, which is the one place the discipline must not fail. Holding the graph wholly outside the record, in the library or the transport, fails for the same reason and more sharply: it makes the record unable to speak to its own independence at all once separated from the store, which breaks the portability the first research question requires. Portability of lineage is not enough; what the work needs portable is the judgement, and the judgement is the independence test.

The record therefore carries what the independence test needs, and no more. Each basis record holds an origin set: the set of evidential origins the claim descends from. An evidential origin is a typed event, a particular measurement, calculation, generation or human step that grounds a claim, identified and typed rather than merely named. Two claims fail to be independent when their origin sets intersect, because a shared evidential origin is a shared source counted twice, and the test is a set intersection answerable from the two records alone, with no ancestor present and no walk required. The test is one-directional, and the direction matters more than it first appears. Intersection establishes dependence; disjointness establishes only that no dependence is recorded, which is a weaker fact and must not be read as the stronger one. Two readings may share an uninstrumented common cause, a calibration standard, an upstream database or a human report, and nothing in either record will show it. The model therefore distinguishes three states rather than two: dependence is established when origin sets intersect; no dependence is recorded when they are disjoint; and independence is established only on a further basis the origin set does not supply. Treating the second as the third would convert absence of evidence into evidence, which is the move this work exists to refuse. The origin set of a claim established directly is the origin of its own acquisition event; the origin set of a derived claim is the union of its parents' origin sets, computed once when the derivation is performed and carried thereafter. This union rule is the one piece of inheritance the record commits to, and it is named as such rather than left to the inheritance method, because without it the origin set is simply undefined for any derived claim. It is constitutive of the field, not a policy choice about it: the origin set cannot be a field of a derived claim's record at all unless the record fixes how it is composed from the parents. Everything else the inheritance method does is deferred; this alone is fixed here, because the field does not exist without it. Independence detection is thus done at the point of judgement in constant terms, against the crossing record and whatever it is being weighed with, and it survives the handover because it rides on the record rather than on the ancestry.

One qualification is not optional, because without it the origin set becomes a machine for the failure the methodology chapter declared it must avoid. The origin shared must be the origin of the evidence, not of the subject. Two claims about the same valve do not share an evidential origin merely by concerning the same valve; a sensor reading of the valve and a physical inspection of the valve are genuinely independent support for the same fact, and a model that read their common subject as a common origin would refuse legitimate corroboration and reject sound practice, which is the over-conservatism the work counts as failure and not as safety. An origin is a typed event, and two claims share one only when they descend from the same measurement, the same calculation, the same generation, not when they are about the same thing. The origin set tracks evidential provenance, and the distinction between the origin of the evidence and the origin of the subject is the line that keeps shared-origin detection from becoming an accidental corroboration refuser. It is stated here because it is exactly the kind of distinction a structure would otherwise fix by default, in the wrong place, and only discover in the scenarios.

Two things about what this test does and does not catch have to be stated, because the coverage is easy to over-claim and the over-claim would hide the failure the work is named after. What it catches, it catches completely: because a derived claim's origin set is the union of its parents', a descendant's set always contains its ancestors', so a claim and anything derived from it through the discipline's own machinery necessarily share an origin and are correctly found dependent. Sibling dependence, two claims drawn from a common root, is caught by the intersection directly; lineal dependence, one claim derived from another, is caught by the same intersection precisely because the union rule guarantees the descendant carries the ancestor's origins forward. There is no gap between the two so long as the derivation passed through the model.

What it cannot catch is dependence that entered through a step the discipline did not mediate. If an operator reads one value, forms a judgement, and authors a fresh claim, the model sees a new claim with its own acquisition event and its own origin, not a derivation that unioned the first claim's origins into it. The two origin sets are disjoint, and the origin-set test calls the claims independent when in fact one is causally downstream of the other. This is not a defect to be patched in the origin set; it is the laundering path the problem statement describes, in which a claim's probabilistic origin becomes unrecoverable once it passes through an unwitnessed human or system step, and it is the very thing the discipline exists to refuse at a boundary rather than to detect after the fact. The origin set therefore covers recorded dependence, meaning dependence that passed through the model's own derivation, and no more. Unmediated laundering is handled where it must be, by admission control at the boundary the claim tries to cross, not by a retroactive reading of an origin set that never saw the dependence happen. Conflating the two jobs would let the model claim to detect what it can only refuse, and the honest scope of origin-set independence is the recorded kind alone.

Ancestry in the fuller sense, the actual derivation and its shape, may still be recorded for lineage and for audit, and nothing here forbids a record from carrying references to its parents for that purpose. What is fixed is that the independence judgement does not depend on that ancestry being present, because it rides on the origin set instead. The two are separated on purpose: lineage is for reconstructing history when the history is in hand, and the origin set is for deciding independence when it is not.

The targeted reading of evidence theory tested this design against the field most likely to have solved it first, and returned the opposite of what was expected. The concern was that representing dependence as a binary intersection would prove a coarse version of a graded combination rule formalised decades ago. What the field says is that its rule of combination carries one essential restriction, that the sources of evidence must be statistically independent (Zadeh and Ralescu, 1987). Independence is not something Dempster-Shafer computes; it is a precondition the theory requires and does not itself supply, and that paper exists because establishing whether two sources may be combined at all is a hard problem needing its own machinery. The origin set therefore does not reinvent evidence theory. It answers the question evidence theory presupposes, which places detection upstream of combination rather than as a poor substitute for it. Whether a graded combination belongs downstream, once independence is established, is a question for the admissibility method and not for the record.

One residual is named rather than hidden. An origin set grows with the number of distinct evidential origins a claim descends from, and for a claim with sprawling ancestry it is not small. That is a real cost, and it is the thing to watch when the model is run against the scenarios: if origin sets balloon in realistic cases, that is evidence pulling back toward recording a position in an external graph for those cases, and it is confronted then, on evidence, rather than assumed away now. The commitment here is that the origin set is the minimal structure that answers the independence question at the boundary, not that it is free.

What the fields do not settle

Fixing the record's fields fixes what a basis is, and deliberately does not fix what is done with it. The inheritance method, which governs how a derived claim's basis is computed from its parents', operates over these fields but is not stated here; the guardrail the model carries in, that weakest-ancestor propagation is a conservative default and not the rule, constrains that method but does not define it. The admissibility method, which weighs a basis record against an act's demand, reads these fields but is not stated here either. The structure is arranged so that both methods have something to operate on: means and authority give the inheritance method categories to propagate and combine, the origin set gives it the independence it must respect, and establishment time, rate, and established scope give the admissibility method the basis side of the three comparisons it makes against the act. What those methods do with the fields is the next drafting, and separating the record from the methods that read it is what keeps each of them attackable on its own terms.

Where this leaves the model

The model is fixed to the degree the standard required and no further. A basis record is a structured object attached to one claim, holding means, authority, establishment time and rate of change, established scope, and an origin set of evidential origins, and travelling with the claim across the ownership boundary. Independence is a set intersection over origin sets, answerable at the boundary from the crossing records alone. The act's demand is not in the record, because admissibility is a relation and the demand belongs to the act. The two open forks are settled: independence is known through the origin set, forced by the boundary rather than chosen for size, and authority is kept as its own field, forced by cases where it varies independently of means.

What remains open is stated as open. Whether these fields are complete, and whether a neighbouring formalism holds a semantics the record does not yet carry, is work a targeted reading of those fields would do, engaged on evidence of the model needing it rather than on spec. One such reading was carried out, of evidence theory, and its result is recorded above; the rest were not, and the conclusion records them as further work. One seam is worth naming. The acquisition and transformation fields carry kinds, categories from closed vocabularies that the methods branch on, while the origin set is built from events, particular groundings identified rather than only categorised. The record presupposes that every grounding has an identifiable event behind it, and the typed origin set is where that identity is carried. The model is minimal by construction and is meant to be pressured; the point of fixing it precisely is that it can now be shown wrong, against the reading and against the scenarios, while changing it is still cheap.

References

Zadeh, L. A. and Ralescu, A. (1987). On the Combinability of Evidence in the Dempster-Shafer Theory. Uncertainty in Artificial Intelligence. arXiv:1304.3119. arxiv.org/abs/1304.3119

Kalai, A. T., Nachum, O., Vempala, S. S. and Zhang, E. (2025). Why Language Models Hallucinate. arXiv:2509.04664. arxiv.org/abs/2509.04664

Hicks, M. T., Humphries, J. and Slater, J. (2024). ChatGPT is Bullshit. Ethics and Information Technology, 26(2). doi.org/10.1007/s10676-024-09775-5

Gawlikowski, J., Njieutcheu Tassi, C. R., Ali, M., Lee, J., Humt, M., Feng, J., Kruspe, A., Triebel, R., Jung, P., Roscher, R., Shahzad, M., Yang, W., Bamler, R. and Zhu, X. X. (2021). A Survey of Uncertainty in Deep Neural Networks. Artificial Intelligence Review. arXiv:2107.03342. arxiv.org/abs/2107.03342

Halpern, J. Y. and van der Meyden, R. (2002). A Logical Reconstruction of SPKI. Journal of Computer Security (preliminary version, 14th IEEE Computer Security Foundations Workshop, 2001). arxiv.org/abs/cs/0208028