Skip to content
Paula Livingstone writing · projects · tools

Attestable Process and Planning

The Tier 2 Reading: What Each Neighbouring Formalism Is Asked, Before Any Is Opened

The methodology incurred a debt in public: six neighbouring formalisms may already hold semantics the basis model would otherwise reinvent worse, and the reading of them was owed before the model is fixed. Now the model is fixed enough to say what it actually needs, this spine schedules that reading as a targeted reading rather than a survey. It names, for each of the six fields, the one load-bearing part of the model it touches and the single adopt-or-reinvent question it is asked, and it fixes the stopping rule that keeps a targeted reading from becoming six chapters. It opens no source. The targeted reading is the one stone on the road with an unbounded input, and a masters that reads three fields deep for a week has turned into a doctorate without deciding to, so the reading is bounded here, in the open, before a single formalism is opened.

A planning document, not a design decision. This was written before the work it describes, and published in advance so the plan for the targeted reading of six neighbouring formalisms could be attacked while changing it was still cheap. It narrates its own method and addresses a later session, which is why it sits with the working process rather than in the dissertation. One of the six was read. Evidence theory returned that its rule of combination requires statistically independent sources as a precondition it does not itself supply, and that finding is recorded where it bears, in The Structure of a Basis Record. The other five readings were not carried out: the bounded scope of this work did not extend to them, and the conclusion records what remains as further work rather than presenting it as scheduled.

The methodology chapter incurred a debt and scheduled it rather than disowning it: six neighbouring formalisms may already hold semantics the basis model would otherwise invent worse, and the targeted reading of them was owed before the model is fixed, with a firing condition. That condition has now been met. The basis record is drafted to the point where its load-bearing semantics are named rather than guessed at, which is exactly the point the schedule said the reading becomes due. This document is the reading's plan, and it is published before the reading for the reason every spine on this road has been: so the plan can be attacked while changing it is still free.

What makes this spine matter more than the others is the shape of the work it governs. Every prior stone drafted against material already read, so its input was bounded by what was already in hand. This one is new reading, of up to six fields, and that is the single place the bounded scope is most at risk. Its whole discipline is that a field earns depth only when the minimal model is shown to lack a semantics it needs, and the failure mode is precise: reading a formalism deeply enough to reconstruct it, when the model needed one paragraph and a citation, is how a bounded piece of work quietly becomes an unbounded one. A targeted reading takes what the model needs and leaves; a survey reads the field for its own sake. This spine fixes which of the two this is, per field, before the temptation to read on is live.

A note on what is not cited here, and why

This spine names six fields and describes what each is thought to touch, and it cites none of them. That is deliberate and it follows the project's standing rule that a source is read in full before any claim is attached to it. The descriptions below are statements of what the model needs and where it might be answered, drawn from the model as drafted; they are not characterisations of those literatures, which have not been read. A field is cited when it has been read and its answer recorded, and not before. Where the spine does cite, it cites the read sources that fix the model's own commitments and the sequence this reading follows.

A targeted reading, not a survey: the question every field is asked

Each field is asked one question and not a general one. The question is whether the field already contains the specific piece of machinery the model needs for a named part of the basis record, in a form the model should adopt and cite rather than reinvent. The answer the reading is looking for is one of three, and all three are progress: the field supplies the machinery, in which case the model adopts it and says so; the field supplies nothing the minimal model needs, in which case the model records that it looked and moves on; or the field supplies something the model genuinely needs and cannot get minimally elsewhere, in which case, and only then, that one field earns a deeper engagement, on the evidence of the model needing it. What the targeted reading does not do is read a field to characterise it. Characterising a field is the second literature review the methodology already refused to smuggle in, and it is the drift this spine exists to prevent.

Why the reading splits: you cannot read against a part that is not drafted

The six fields do not all target a part of the model that exists yet, and this is the first thing the plan must get right, because getting it wrong is how the reading drifts. The adopt-or-reinvent question a field is asked is whether it supplies what the model needs for a named part, and that question can only be answered against a part already drafted, because needing is a property of the drafted part. The record and its origin set are drafted, so the fields that touch them can be read now. The admissibility method and the instantiation are not drafted; they are deferred by the structure entry on purpose. A field aimed at an undrafted part is being read against a phantom, and worse, it is being invited to say what that part should be, which hands the scope of the part to the field. That is the exact inversion the register of claims under pressure wrote its sequence to forbid: draft the smallest model, find it wanting on a specific question, then read the field for that question. Draft-then-read terminates because the question bounds the reading; read-then-draft does not, because without the drafted part everything in the field looks relevant. So the reading is split by what is drafted, and the split is stated here so a later session cannot quietly refold it and read a field against a part that still does not exist.

The record reading, which runs now

Three fields touch the basis record and its origin set, which are drafted, so their adopt-or-reinvent questions can be answered now. Each is tied to the specific part it touches, and the questions are specific to the model as fixed, not to the fields as they see themselves.

Evidence theory, in its Dempster-Shafer and subjective-logic forms, touches the origin set and the independence test. Read subsequently against that question, it returned that its rule of combination requires statistically independent sources as a precondition it does not itself supply (Zadeh and Ralescu, 1987), which places the origin set upstream of combination rather than in competition with it. The model represents dependence as shared evidential origin and tests it by intersection, which is deliberately a detection and not a degree. The guardrail that makes this matter is recorded in the register of claims under pressure rather than invented here: mutually dependent sources do not corroborate, so a discipline that read two views of one source as corroboration would manufacture confidence from nothing. The question: does evidence theory supply a representation of corroboration, conflict, and partial dependence that the model needs and the origin set cannot express, or is the model's detection-only treatment sufficient for what the inheritance guardrail requires. The targeted reading adopts a representation of dependence only if the model is shown to need more than shared-origin detection, and the recorded-dependence bound already suggests where that pressure will fall.

Trust management touches the authority field. The model carries authority as its own field and never raises it: this reading was originally set to find semantics for promoting a claim's standing, and that question lapsed when the design established that no axis is elevatable. What survives is narrower. The question: does trust management supply existing semantics for delegated authority that the model should adopt, or does its machinery presuppose a trust root the boundary setting does not have. Authority naming a source without scoring it is the exact place this reading meets the seam flagged for it, and the two are read together.

Epistemic logic touches what an owner is entitled to claim, which is the formal underside of the whole discipline. The question: does epistemic logic supply a representation of entitlement and of justified holding that the model needs to make its notion of basis precise, or is it a formalism whose depth the minimal model does not require and should not import. This is the field most able to turn into a chapter on its own terms, so its stopping rule is the strictest: it is read only for whether it supplies something the model demonstrably lacks, and the default expectation is that it is noted and left.

The deferred readings, which wait for their targets

Three fields target parts of the artefact that are not yet drafted, and they are named here and deferred rather than run, so that the deferral is a recorded decision and not an omission. Decision theory targets the admissibility method, where a basis is weighed against the consequence of the act it would support. It is the likeliest of all six to earn depth, because admissibility relates sufficiency to consequence and decision theory is the field that does too, and it is for exactly that reason the most dangerous to read early: read against an undrafted method it would not inform the method but write it, unbounded, and pull the model back toward the scalar the review ruled out. It is read after the minimal admissibility method is drafted and found wanting on a specific question, not before. Contract-based design and runtime assurance, and proof-carrying code, target the instantiation: the shape of the barrier and its pre-condition and post-condition machinery, and the pattern for carrying a justification alongside the claim it justifies. Both are expected to inform the instantiation and the framing rather than to add a field to the record, and both are read after the instantiation is drafted enough to be found wanting. Naming them now fixes what they are for; running them now would be to read against a phantom.

Two gates, at two moments: naming the lack before the field may answer

A correction the record reading forced, because it is the point at which the reading is actually bounded. None of the three fields has a source already read for this purpose, so running the record reading means opening new reading, which is the unbounded input this whole spine exists to contain. It would be natural to say the demonstrable-lack criterion gates that reading, applied before a source is opened. It cannot, and saying so would be a trap: the criterion asks whether the minimal model lacks a semantics the field supplies, and that cannot be fully answered against a field not yet read. A gate that demanded proof of need before reading would open nothing, which is its own failure.

So the reading runs two gates at two moments, and they are different tests. The first is cheaper and comes before a source is opened: for each field, state in one sentence the specific lack the model raises that the field might answer, drawn from the record as drafted. It is the concrete case where the record cannot answer a question it must, posed as a question the field is then allowed to answer and nothing wider. If that sentence cannot be written, the field is not opened, because reading a field to discover what in it might be relevant is exactly the unbounded mode, and the inability to name the lack is the proof that the reading would be a search rather than a targeted reading. The second gate is the demonstrable-lack criterion already stated, and it comes after the reading: it confirms the named lack is real and that the field fills it, and decides adopt or reinvent. The first gate names the lack; the second confirms it. Together they are the draft-then-read discipline one level down, because the model fixes the question before the field is permitted to answer, and a field cannot set the scope of what it is read for when the question was posed before it was opened.

The three record reading fields each carry a stated lack, which is the sentence that lets them through the first gate. Evidence theory: the origin set detects shared origin but the inheritance guardrail may need degrees of dependence rather than detection, so the question is whether Dempster-Shafer or subjective logic supplies a degree the model must have and the origin set cannot express. Trust management: authority is a field that names a source without scoring it, so the question is whether delegation formalisms supply semantics for delegated authority that the model should adopt. Epistemic logic carries a warning with its question, and the first gate is where it is tested: the question is whether the record needs a formal account of what an owner is entitled to claim. If that question, stated honestly, turns out to be a question about how a basis is weighed against an act rather than about what the record holds, then it is aimed at the admissibility method, which is not drafted, and epistemic logic fails the first gate and defers with decision theory exactly as the split requires. The gate is therefore not only a bound on reading; it is a second pass on the phantom-target check, catching a field whose target turns out to be undrafted after the first split let it through. It is possible the record reading is two fields and not three, and that would be the gate doing its job rather than a loss.

The stopping rule

The reading stops by a rule fixed here rather than by exhaustion, and the rule is a criterion applied per field, not a count fixed in advance. A field is done when its one question is answered in one of the three ways above, and the reading of that field stops at the answer. A field that supplies nothing the minimal model needs is answered by recording that it was checked and found not to be needed, which is a complete outcome and not a gap. The criterion that admits a field to deeper engagement is the demanding one: the minimal model must be shown to demonstrably lack the semantics the field supplies, and shown by a concrete case in which the record cannot answer a question it must. That is a test applied, not a number hoped for. It is deliberately not a cap of one, because a cap would force the rejection of a field that genuinely passed the test in order to protect a number, which is the over-conservatism the methodology chapter named as a real failure rather than a safe harbour. That the two faces of failure carry equal weight is the methodology's commitment, and it binds here: a rule tuned to reject is as much a failure as one tuned to admit. If two fields each pass the test, two fields earn depth, and the frame is defended by the test being hard to pass, not by the count being capped. What the count does is raise an alarm rather than set a limit: if several fields appear to pass, that is evidence the test is being applied too loosely or the model was drafted too thin, and the response is to re-examine whether each demonstrable lack is real, against the roadmap's tripwire that a field quietly becoming a chapter is the frame breaking. The criterion decides admission; the count only triggers a second look at how the criterion is being applied.

What this spine is, and what it is not

What is fixed here is the reading's method: the single adopt-or-reinvent question per field, tied to the specific part of the drafted model it touches, and the stopping rule that bounds the whole. What is deliberately absent is any reading. No source is opened, no field is characterised, no answer is given, because the value of publishing the plan before the reading is entirely in the plan being attackable before the unbounded work begins. The reading is run against this spine, next, once the spine has been left open to attack: is a field missing, is a question aimed at the wrong part of the model, is a stopping rule too loose to hold. The line this stage most has to hold is the one between asking a field a bounded question and reading it for its own sake, and this spine holds it by naming the question and refusing the reading.

References

Zadeh, L. A. and Ralescu, A. (1987). On the Combinability of Evidence in the Dempster-Shafer Theory. Uncertainty in Artificial Intelligence. arXiv:1304.3119. arxiv.org/abs/1304.3119