The model and its methods have been fixed in prose. This section states them formally enough to be tested, and no further. The purpose is not a semantics of evidence: it is to name the domains, define the functions over them, and state the properties an implementation must preserve, so that the properties become executable tests rather than intentions.
One thing is deliberately not defined, and its absence shapes everything below. There is no ordering over bases. A recent generation and an older measurement are not comparable, and no scale exists on which one is stronger. Every property below is therefore stated over individual axes or over what a record must preserve, and never over a global standing. An earlier version of this work said a derived claim may hold a stronger basis. That claim has been withdrawn rather than qualified: implementing it established that there was no operation to implement.
Domains and functions
Let B be the well-formed basis records and D the well-formed action demands. A verdict is drawn from admit, refuse and undetermined. For each axis i the demand may constrain, an axis evaluation returns pass, fail, unknown, or not-required, and admissibility is a function from a basis and a demand to a verdict.
Well-formedness is a precondition and not a verdict, and three conditions that an earlier draft of this section ran together have to be kept apart, because they arise in different places and warrant different responses.
A record may be structurally invalid: corrupt, missing a required element, internally inconsistent. It does not enter the function. Malformation is not epistemic uncertainty, and returning undetermined for a broken input would convert a defect in transport into an honest gap in knowledge.
A record may be well-formed and carry semantics the reader cannot interpret: a later schema version, or a vocabulary value the reader does not know. This is not a defect in the record and not a gap in the basis. It is a limitation of the evaluating implementation, and the correct response is to decline to adjudicate rather than to adjudicate. The distinction matters because the record may be entirely sound and the claim entirely admissible to a reader that understands it.
And a record may be well-formed, fully interpretable, and epistemically incomplete: it genuinely does not carry what an axis requires. That is what undetermined is for.
The three converge on one rule at the boundary and diverge in what they report. None of them may produce an admission. Uninterpretable semantics in particular must never be resolved favourably, because a reader's ignorance would otherwise become a producer's permission, and a demand refusing generated ancestry would admit a generated claim on an old reader that could not see the mechanism. No fourth verdict is needed for this: the admissibility function is defined only over records a reader can interpret, so declining to adjudicate happens before the function rather than inside it. An enforcement point maps a declined adjudication to whatever it maps a refusal to, blocking or alarming as the act warrants, and never to passing the value on.
The properties
Exactly one verdict. Every well-formed pair yields one verdict, never two and never none.
Conjunction, with failure dominant. The verdict is refuse when any constrained axis fails; undetermined when none fails and at least one constrained axis is unknown; admit when every axis is pass or not-required. Failure dominates unknown, because a claim that fails a requirement fails it whatever else is unavailable, and the unknown axes remain in the trace for diagnosis.
Unknown never satisfies. An unknown value on a constrained axis cannot produce a pass, and unknown and not-required remain distinct throughout. This is the property most of the failures below turn on.
Demand monotonicity, where comparable. Where one demand is no weaker than another on every axis, an admission under the stricter implies an admission under the weaker, and a refusal under the weaker implies a refusal under the stricter. Comparability is defined per axis: a smaller accepted-mechanism set is stricter, a shorter tolerance is stricter, a required scope containing another is stricter, and constraining a previously unconstrained axis is stricter. Demands strengthened on one axis and weakened on another are incomparable, and the property makes no claim about them. No corresponding property is stated over bases, because bases have no such ordering.
Origin conservation. A derived claim's origin set is the union of its evidential parents' origins, less any explicitly elided, plus any fresh origins of its own. Every parental origin absent from a child is therefore accounted for by exactly one of two facts: it was not an evidential parent, or it was elided by a recorded decision. There is no third route by which an origin disappears.
Origin types are immutable. An origin that survives a derivation keeps its identity, acquisition, semantic relation and mechanism unchanged. A later step may add a typed event; it may not rewrite a generation as a calculation, an inference as a restatement, or an unknown semantic relation as verified preservation.
Elision travels and is refusable. Every ancestry reset is carried in the record, naming the removed origins and their kinds, the ground on which they were judged causal rather than evidential, what made that judgement, and the basis warranting it. A demand may refuse because an elision occurred, because its warrant is inadequate, or because its warrant is unknown. The property makes elision visible; it does not make it correct.
Dependence vetoes; disjointness does not license. Intersecting origin sets establish dependence, and dependence forbids elevation. Disjoint origin sets establish only that no dependence is recorded, which removes the veto and grants nothing. Elevation additionally requires independence to be established on a basis the record does not itself supply.
No axis is elevatable. No claim acquires a better standing on any axis merely by having more parents, by having parents with disjoint origins, by being produced deterministically, by having a well-regarded producer, or by being recent. Nor does it acquire one by an explicit event: there is no operation that raises a descriptive field, and a record carrying a marker asserting that standing was lifted is refused. This began as a constraint on when elevation is permitted and became a prohibition, because building it established that nothing was being elevated.
Composition adds support and rewrites nothing. An independently established support may be added to a basis. The origin sets union; every descriptive field of every support is left exactly as it was. Two reports do not become a measurement, and two independent authorities do not make either more authoritative.
A changed verdict follows a changed basis. Where a claim was inadmissible for an act and is later admissible for that same act, the difference is a represented change to what the claim rests on, reached through composition, fresh acquisition, verification or explicit reset. No admissibility status is stored on a claim, so a verdict is always the result of evaluating a basis rather than a property read off one.
Transformation preserves every dimension. A step that changes the semantic relation does not change the mechanism, and a step that changes the mechanism does not change the semantic relation. Generated restatement remains generated. Generated inference remains both. A deterministic extraction over generated input does not become a calculation over measurements. Preservation claimed without verification remains semantically unknown.
Duplicates and order are inert. Origins form a set, so the same origin supplied twice is the same origin, and no corroboration or added authority arises from repetition. Derivation is indifferent to the order of its parents where the derivation is otherwise identical.
The trace is sound and complete. Every axis reported as failed did fail, every axis that failed is reported, every axis reported unknown was constrained and unavailable, and every constrained unknown is reported, with the compared values preserved. An admission records the comparisons that passed. This is what makes a verdict auditable rather than merely categorical.
Two properties the pressure test forced
Running the twelve attacking cases against the list above found two places where it was silent, and both are admissions rather than refusals, which is the direction that matters.
An empty demand is invalid. Silence on an axis is permission, which is right, because a demand that quietly required what it did not state would refuse claims for reasons its author never gave. Applied to a demand that constrains nothing at all, the same rule admits everything, and the properties above do not forbid it. So an empty demand does not fail admissibility; it fails validation, on the ground that an act whose evidential requirement is nothing has not stated a requirement. That is a well-formedness condition on demands, and it leaves the silence rule intact for demands that constrain at least one axis.
Interpretation loss cannot weaken a record. A record written against a later vocabulary may reach a reader that does not know one of its fields. If that field were treated as not stated, and not-stated means unconstrained, a demand refusing generated ancestry would admit a generated claim because the reader could not see the mechanism. That is the laundering path arriving through version skew, and nothing else in this list prevents it. Compatibility is therefore part of the trust boundary rather than a transport concern: a valid record reaching an old reader must never be weakened by what that reader failed to understand. The reader declines to adjudicate, as above, and the claim remains adjudicable by any reader that understands it.
What these are for
Each property is a test before it is a claim. Exactly-one-verdict and the conjunctive combination are truth tables. Monotonicity, duplicate inertness and parent-order indifference are property-based tests over generated records. Origin conservation, type immutability and trace fidelity are checked on every derivation the implementation performs. Serialisation round-trips, schema-version skew and malformed input are tests the library must pass before any scenario is run against it, because a discipline that cannot survive its own transport has not established anything about admissibility.
What this is not is a semantics of evidence. No lattice of standing is defined, no logic of justification is developed, and the incomparability of bases is left as it is rather than resolved by imposing an order that the model does not have and the domain does not supply.