Skip to content

ANCIENTOS ARCHITECTURE

AncientOS Rote

Ontology and Effect Semantics Specification

Draft 1

Cognitive kinds, relationships, epistemics, integration effects, and governance boundaries

Product and architecture design | September 2026

Status: Product and architecture design draft

Baseline: AncientOS Rote — Conceptual Specification, Draft 1 and the AncientOS Curated Architecture Packet

Scope: Fundamental cognitive semantics only. This document does not claim implementation, inspect the repository, or specify schemas, APIs, serialization, storage, or network protocols.

Executive determination

This phase finds that the Rote concept is coherent enough to advance, but only if AncientOS resists three simplifications:

  1. A Rote cannot have one flat “type.” The useful ontology has eight small content kinds, an orthogonal construction form, and typed assertions inside a Rote. A primary kind is needed to declare the Rote's principal cognitive promise and safe default effects; secondary kinds preserve mixed cognition without making lifecycle behavior ambiguous.

  2. Epistemic status cannot be one enum or score. Origin, acquisition, transformation, claim posture, local acceptance, confidence, trust, and applicability are different dimensions. Collapsing them would launder inference into observation and receiver judgment into source testimony.

  3. Integration cannot be one state or verb. Possession, epistemic acceptance, use in reasoning, operational preparation, activation, and authority are distinct effect families. “Integrated” without an effect and scope is architecturally incomplete.

This specification recommends adopting eight cognitive content kinds: Observation, Claim, Model, Experience, Procedure, Heuristic, Normative Cognition, and Capability. Composition/Synthesis is adopted as a construction form rather than a ninth primitive kind, although a Rote whose principal contribution is an emergent synthesis may declare Synthesis as its primary Rote role.

Relationships should use a two-level model. A compact relationship assertion is the ordinary form. It becomes or is accompanied by a full Rote when the relationship itself is independently transferable, disputed, consequential, derived through substantial reasoning, or requires its own evidence and applicability. This avoids both semantic impoverishment and recursive metadata explosion.

The document also recommends a clear threshold between memory and Rote: a local cognition object becomes a Rote candidate when a deliberate semantic boundary and transfer contract are asserted. It becomes an immutable attested Rote when it is sealed for durable reliance, offered, published, or transferred. Every Rote may be remembered; not every memory is a Rote.

1. Authority and decision discipline

The following labels retain their Draft 1 meanings:

  • SETTLED PRINCIPLE — directly supported by the authoritative architecture packet or marked sufficiently settled in Draft 1.

  • DESIGN DIRECTION — strongly implied but not fully decided.

  • RECOMMENDED FOR ADOPTION — a Draft 1 proposal or new conclusion that this phase finds mature enough to become architecture intent.

  • PROPOSAL — useful design not yet mature enough for adoption.

  • REQUIRES OPERATOR DECISION — alternatives encode meaningfully different product philosophies.

  • STILL UNRESOLVED — conceptual work remains.

  • DEFERRED IMPLEMENTATION QUESTION — repository/runtime investigation is required later.

SETTLED PRINCIPLE — A Rote is AncientOS's universal bounded unit of transferable cognition, not a universal file format or arbitrary content plus metadata.

SETTLED PRINCIPLE — Cognitive content, Rote envelope, and carrier are distinct. Semantic closure and material closure are distinct. Possession does not imply understanding, trust, applicability, integration, installation, activation, or authority.

RECOMMENDED FOR ADOPTION — Adopt Draft 1's formal definition:

A Rote is an addressable, bounded cognitive assertion or construction whose intended meaning, scope, epistemic status, provenance, applicability, relationships, and possible integration effects are described sufficiently for a compatible receiving system to preserve it as a distinct object of cognition and evaluate what, if anything, to do with it.

The phrase “described sufficiently” is intentionally relative to an effect. A receiver may understand enough to retain or cite a Rote but not enough to reason with, operationalize, or execute it. There is no single universal threshold called “understood.”

2. Ontology architecture

2.1 Three levels of classification

RECOMMENDED FOR ADOPTION — Cognitive classification operates at three levels:

  1. Assertion level. Individual assertions or constructions inside the boundary carry their own cognitive kind and epistemic history. A capability Rote can contain observations, claims, procedures, and normative constraints without laundering them into “capability facts.”

  2. Rote content profile. The Rote declares all materially present kinds and the role each plays: core content, evidence, constraint, instruction, experience, or supporting explanation.

  3. Primary Rote role. One kind—or Synthesis—states the Rote's principal transferable cognitive promise. It determines the minimum semantic properties, expected assessment, and safe default effects. If no honest primary role can be selected, the boundary is probably too broad or merely a carrier collection.

Multiple kinds are therefore legitimate and expected. One primary role is required for an attested Rote. Secondary kinds do not inherit the primary kind's epistemic posture or integration permissions.

2.2 The small ontology

Content kind Defining question Boundary from adjacent kinds Characteristic safe use
Observation What was directly registered under stated conditions? Does not itself assert a general rule or causal lesson Preserve as attributed evidence
Claim What proposition is being asserted as possibly true? May be supported by observations but is not the observation event Assess, cite, accept, or dispute propositionally
Model What entities, concepts, relationships, or dynamics are represented together? More than an isolated proposition; less than an action prescription Map, query, reason over, compare
Experience What happened to an actor/system across an episode, and how was it interpreted? Includes temporal episode and outcome; not identical to its lesson Learn from without claiming local occurrence
Procedure What ordered or conditional method is prescribed to pursue an outcome? Specifies action method, not merely a tendency or preference Inspect, simulate, recommend, or perform if separately authorized
Heuristic What defeasible shortcut or tendency guides judgment? Neither guaranteed procedure nor fact; admits exceptions Weight reasoning within scope
Normative cognition What ought, must, may, or must not be preferred or permitted? Expresses value, policy, consent, or constraint—not descriptive truth Apply only under valid authority and scope
Capability What bounded ability could an AncientOS make available, and what is required to do so? Ability construction, not merely its code, documentation, or procedure Inspect and prepare separately from activation and authority

RECOMMENDED FOR ADOPTION — The ontology is extensible by explicit extension rather than “other” as an unexamined bucket. A proposed new kind must demonstrate materially distinct semantic requirements or integration effects; different subject matter or carrier format is insufficient.

2.3 Composition and Synthesis

RECOMMENDED FOR ADOPTION — Composition is an orthogonal construction form. It describes how cognition is assembled: atomic, aggregate, composite, derived, synthesized, translated, redacted, adapted, or projected. It is not normally a content kind.

A Synthesis Rote is legitimate when the principal transferable contribution is a new integrative construction—such as a qualified conclusion across conflicting evidence, a merged conceptual model, or a procedure derived from experience—not the mere co-location of sources. Synthesis is therefore an allowed primary Rote role with mandatory lineage and transformation semantics, but it does not erase the kinds of its constituent assertions.

Dangerous category mistake: treating a bundle, archive, catalogue, or dependency closure as a synthesis merely because it contains several Rotes.

3. Cognitive-kind specifications

3.1 Observation

Definition. An Observation represents a bounded act of registration: an observer or instrument encountered, measured, detected, or failed to detect some phenomenon under stated conditions.

Required semantic properties: observed phenomenon; observer/instrument; observation time or temporal relation; observation conditions; method or sensory channel; result; detection limits or relevant uncertainty; subject identity or scope; distinction between raw registration and interpretation.

Optional properties: calibration; repeated samples; raw supporting material; comparison baseline; environmental context; privacy-preserving subject alias; known observer limitations.

Characteristic epistemic posture: observed-by. The Rote can establish “observer O registered X under C,” not automatically “X is universally true.” A human statement about what they saw is an asserted report whose content concerns an observation; AncientOS must preserve both layers.

Applicability concerns: time, subject, location, measurement method, sampling window, sensor accuracy, and whether non-detection is meaningful.

Common relationships: evidence for, supports, contradicts, corroborates, repeats, observes same subject as, derived measurement from, temporally follows.

Legitimate effects: possess, inspect, retain, index, cite as attributed observation, reason with as evidence, tentatively accept the report, dispute its method or interpretation, derive claims.

Dangerous category mistakes: calling inference an observation; converting “not observed” into “false”; treating a retrieved human assertion as a direct system observation; discarding the observation time when a later observation differs.

3.2 Claim

Definition. A Claim represents a bounded proposition presented for epistemic consideration. “Claim” includes fact-like propositions without presuming their truth.

Required semantic properties: proposition; claimant or origin; subject and predicate meaning; temporal and modal scope; epistemic basis or explicit absence; applicability envelope; known qualifiers.

Optional properties: confidence expression with rationale; supporting/opposing evidence; alternative formulations; falsification conditions; source reputation context.

Characteristic epistemic posture: asserted, derived, inferred, hypothesized, or accepted locally. The posture must say whose stance it is.

Applicability concerns: definitions, time, jurisdiction, population, configuration, and whether the claim is descriptive, predictive, causal, or counterfactual.

Common relationships: supported by, contradicted by, corroborated by, refines, specializes, generalizes, corrects, equivalent to, overlaps, supersedes for context.

Legitimate effects: retain as attributed, evaluate, cite, reason with under a posture, tentatively accept, accept, dispute, contextualize, derive further cognition.

Dangerous category mistakes: “accepted by receiver” becoming part of the source claim; majority repetition becoming corroboration without source independence; a normative instruction masquerading as a fact.

3.3 Model

Definition. A Model represents a structured account of entities, concepts, relationships, constraints, or dynamics intended to support interpretation or prediction as a whole.

Required semantic properties: represented domain; constituent concepts and relations; semantics of relation types; scope and abstraction level; assumptions; omissions or open world/closed world posture; intended uses; known limitations.

Optional properties: competing mappings; predictive expectations; examples; validation evidence; ontology alignment; version/context comparisons.

Characteristic epistemic posture: constructed or synthesized, with constituent claims retaining their own origin and posture.

Applicability concerns: domain boundary, conceptual vocabulary, granularity, jurisdiction, time, population, and translation loss when mapped into a local ontology.

Common relationships: contains assertions, references concepts, maps to, overlaps, specializes, generalizes, derived from, combines, contradicts another model under scope.

Legitimate effects: inspect, retain, index, query, reason over, compare, map partially into local ontology, cite, simulate if dynamics are supplied, derive local models.

Dangerous category mistakes: equating label similarity with concept identity; assuming a mapped model is lossless; treating all relations as facts; accepting the whole model because some claims are trusted.

3.4 Experience

Definition. An Experience represents one or more situated episodes involving an actor or system, conditions, an occurrence or attempt, outcomes, and interpretations across time.

Required semantic properties: experiencer; temporal episode boundary; prior conditions; action/exposure; observed outcomes; event evidence; contemporaneous interpretation separated from later interpretation; privacy/locality posture; degree of claimed generalization.

Optional properties: emotional or preference response; counterfactuals; repeated attempts; failed alternatives; side effects; third-party accounts; later follow-up.

Characteristic epistemic posture: experienced-by plus observed/asserted event components. The lesson is derived cognition, not part of the event merely because it appears in the same narrative.

Applicability concerns: local environment, actor competence and preferences, sequence, rare conditions, sample size, hidden confounders, and transferability of tacit judgment.

Common relationships: episode of, learned through use of, supports heuristic, contradicts expected outcome, follows procedure, experienced by, generalized into, redacted from.

Legitimate effects: retain as remote attributed experience, reason from as evidence, compare to local experience, learn from, derive heuristic/procedure, preserve historical episode.

Dangerous category mistakes: importing remote experience as local memory; treating a vivid single episode as a general rule; erasing private context so thoroughly that the lesson becomes false; treating an interpretation as an observed outcome.

3.5 Procedure

Definition. A Procedure represents an ordered, conditional, or goal-directed method for attempting an outcome under declared preconditions and stop conditions.

Required semantic properties: intended outcome; preconditions; steps and branching semantics; required capabilities/resources; safety constraints; stop/abort conditions; expected evidence of progress and completion; failure modes; applicability.

Optional properties: alternatives; estimated cost/time; recovery steps; operator competencies; experiential success/failure evidence; automation potential.

Characteristic epistemic posture: prescribed or constructed. Claims about effectiveness remain claims supported by evidence; the procedure itself is not “true.”

Applicability concerns: environment, versions, authority, skills, tolerances, dependency availability, reversibility, and hazardous edge conditions.

Common relationships: depends upon, operationalizes, derived from experience, refines, specializes, corrects, operationally equivalent, conflicts with policy, tested by experience.

Legitimate effects: inspect, retain, cite, simulate, recommend, operationally prepare, and—only through appropriate authorization—perform.

Dangerous category mistakes: interpreting possession as permission; assuming a correct procedure is safe locally; omitting stop conditions; confusing descriptive workflow documentation with a prescribed method.

3.6 Heuristic

Definition. A Heuristic represents a defeasible pattern, shortcut, tendency, or decision aid expected to improve judgment within a bounded context while admitting exceptions.

Required semantic properties: decision situation; recommended inference or bias; intended benefit; applicability conditions; known exceptions; evidence/experience basis; uncertainty; cost of false positive and false negative where important.

Optional properties: weighting relative to other heuristics; counterexamples; decay conditions; evaluation history; alternative heuristics.

Characteristic epistemic posture: inferred or learned; explicitly non-deterministic.

Applicability concerns: population, environment, time, incentives, sample bias, distribution shift, operator risk tolerance, and whether the heuristic creates self-reinforcing behavior.

Common relationships: learned from experiences, supported by observations, contradicted by counterexample, refines, specializes, competes with, incorporated by procedure.

Legitimate effects: retain, reason with at an explicit weight/posture, recommend from, simulate consequences, learn from, suspend, refine, derive.

Dangerous category mistakes: promoting a heuristic to fact or policy; hiding exceptions; treating confidence as frequency alone; applying outside its distribution.

3.7 Normative cognition

Definition. Normative cognition represents an ought, preference, value, permission, prohibition, policy, consent boundary, priority, or evaluative standard attributable to a legitimate principal or institution.

Required semantic properties: norm content; norm-giver or authority source; governed subject; beneficiary; scope; effective time; priority/conflict posture; revocability; consent and delegation basis; distinction between personal preference, system policy, legal obligation, and recommendation.

Optional properties: rationale; exceptions; enforcement expectation; jurisdiction; review/expiry; evidence of current consent.

Characteristic epistemic posture: stated, prescribed, adopted, or imposed—not observed truth. Authenticity of the norm-giver and authority to issue the norm are central.

Applicability concerns: principal identity, jurisdiction, role, consent, time, delegation, conflicts with higher-order constraints, and changed preferences.

Common relationships: issued by, applies to, conflicts with, overrides within scope, specializes, retracts, supersedes for context, constrains procedure/capability.

Legitimate effects: retain as attributed norm; apply in recommendation; adopt as local preference or policy only with valid authority; use as governance constraint; suspend or revoke prospectively while preserving history.

Dangerous category mistakes: transferring one operator's preference as another's; treating external policy as automatically binding; mistaking descriptive custom for normative authority; treating an old preference as current because it is newer than nothing.

3.8 Capability

Definition. A Capability represents a bounded potential ability AncientOS could recognize or make available, including its cognitive meaning, effect contract, dependencies, limitations, evidence, operational material, and governance implications.

Required semantic properties: ability and intended effects; inputs/outputs at a conceptual level; preconditions and dependencies; operational material posture; limitations and failure modes; evidence expectations; applicability; risk/effect classes; activation and authority boundaries.

Optional properties: procedures, executable/installable material, documentation, tests/evidence, observed operating history, alternative providers, portability constraints, user experience description.

Characteristic epistemic posture: constructed. Claims about safety, compatibility, and effectiveness retain separate claim/observation postures.

Applicability concerns: hardware/software environment, versions, architecture, dependencies, credentials, policy, external accounts, jurisdiction, safety, and available supervision.

Common relationships: depends upon, implements, operationalizes, combines, replaces for context, operationally equivalent, tested by, learned through use of, constrained by norm.

Legitimate effects: possess and inspect conceptually; retain/index; reason about feasibility; operationally prepare; acquire/install dependencies; register; activate; authorize bounded use; suspend; revoke authority; retire; derive adaptations. Operational effects remain separately governed.

Dangerous category mistakes: equating code with capability; equating signature with safety; equating installation with activation; equating activation with authority; importing credentials; treating documentation claims as observed behavior.

4. Relationship ontology

4.1 Relationship assertion model

RECOMMENDED FOR ADOPTION — A cognitively meaningful relationship is an assertion with six minimum semantics: source subject, relationship predicate, target object, scope/applicability, assertor/provenance, and epistemic posture. Confidence or uncertainty is required whenever the assertion is not definitional or mechanically entailed.

Relationship assertions are ordinary compact cognitive objects. They are not automatically full Rotes. They should be promoted to, or justified by, a Rote when the relationship:

  • is independently useful to transfer;

  • is disputed or has competing assessments;

  • materially changes integration or governance;

  • is derived through non-trivial reasoning;

  • requires its own evidence, transformation history, or applicability envelope;

  • must remain addressable across contexts.

This assertion-first, promotion-when-semantic-weight-demands rule prevents every edge from recursively requiring an envelope, while allowing important edges to become first-class transferable cognition.

4.2 Normative vocabulary

In the tables below, A → B means the relationship is asserted from subject A to object B. “Unsafe” transitivity means a chain may suggest a hypothesis but never licenses automatic entailment.

Structural and dependency relationships

Relationship Meaning and direction Symmetry / transitivity Scope, provenance, and assertor
contains A's material boundary includes B as an identified constituent Asymmetric; not generally transitive because containment modes and boundaries differ Must state embedded vs projected content and closure; normally asserted by A's author/transformer
references A identifies B without making B part of A's material boundary Asymmetric; non-transitive Reference purpose and expected identity required; any author/transformer may assert
depends upon A cannot support a named interpretation or effect without B/condition B Asymmetric; conditionally transitive only for the same effect and compatible scope Must name effect, necessity level, alternatives, and version/context; author, transformer, or receiver may assess
combines A uses B with other cognition to create a construction Asymmetric from result to input; non-transitive as an inference Transformation and contribution of each input required; transformer asserts

Lineage and transformation relationships

Relationship Meaning and direction Symmetry / transitivity Scope, provenance, and assertor
derived from A was produced through a stated transformation of B Asymmetric; lineage reachability is transitive, semantic inheritance is not Transformation actor/method, loss, added content, and other sources required; transformer asserts
summarizes A is an intentionally compressed, potentially lossy rendering of B Asymmetric; unsafe transitive Must state purpose, omitted dimensions, fidelity limits, and access to source; summarizer asserts
refines A increases precision, qualification, or resolution of B without intending contradiction in shared scope Asymmetric; unsafe transitive Shared scope and added distinctions required; source, transformer, or receiver may assert
generalizes A expands a pattern or claim from B to a broader applicability envelope Asymmetric; unsafe transitive Generalization method and evidentiary basis required; transformer/receiver asserts
specializes A narrows B to a defined sub-context, possibly adding local constraints Asymmetric; conditionally transitive if scopes nest and meaning is stable Narrowing criteria and inherited/changed assertions required; transformer/receiver asserts
corrects A asserts a specific error in B and supplies a replacement or correction Asymmetric; non-transitive Error dimension, evidence, and affected scope required; source, transformer, or receiver may assert
supersedes for context A is preferred over B for named uses in context C without erasing B Asymmetric; unsafe transitive Context, effect/use, rationale, effective time, and authority required; receiver policy, source, or legitimate authority may assert
forks from A intentionally diverges from ancestor B while preserving common ancestry Asymmetric; ancestry is transitive, fork compatibility is not Divergence point, motive, and retained/changed scope required; forking author/transformer asserts
learned through use of A was derived from experience applying B Asymmetric; non-transitive Episodes, conditions, outcomes, and interpretation chain required; learner/transformer asserts
retracts A records a source's withdrawal or disavowal of B Asymmetric; non-transitive Identity/authority of retracting principal, scope, time, reason if disclosed, and effect on consent required; source or authorized representative asserts

Evidence and conflict relationships

Relationship Meaning and direction Symmetry / transitivity Scope, provenance, and assertor
supports / evidence for A increases rational support for proposition or model B under scope C Asymmetric; non-transitive Evidentiary relevance, independence, method, and uncertainty required; any assessor may assert, with identity preserved
contradicts A and B cannot both be accepted under an asserted overlapping interpretation and scope Symmetric as a logical tension; non-transitive Must identify propositions, term mappings, overlap, time, and conflict dimension; any assessor may assert
corroborates A independently supports materially similar cognition B Symmetric only for mutual evidentiary relation; non-transitive Independence basis is mandatory and uncertain if unverified; receiver/assessor typically asserts

“Supports” and “evidence for” are treated as one relationship family with subtypes rather than synonyms. Evidence may support a claim without strongly increasing confidence; the relationship must not encode an unspecified numerical weight.

Semantic and operational comparison relationships

Relationship Meaning and direction Symmetry / transitivity Scope, provenance, and assertor
semantic equivalence A and B express the same cognitive meaning to declared fidelity under the same applicability envelope Symmetric; transitive only within identical mappings, fidelity, and scope—otherwise unsafe Comparison method, scope, exclusions, and assessor required; any assessor may assert
operational equivalence A and B produce outcomes equivalent for effect E under context C and tolerance T Symmetric within declared test; unsafe transitive across contexts/tolerances Outcome definition, context, tolerance, evidence, and assessor required
compatible refinement A adds distinctions to B without invalidating B within shared scope and can coexist with it Directional from refinement to base; unsafe transitive Mapping, retained claims, new qualifications, and conflicts required; assessor asserts
substantial overlap A and B share a material cognitive core but have consequential differences Symmetric; non-transitive Shared core, differences, scope, and threshold rationale required; assessor asserts

4.3 Relationship inference discipline

RECOMMENDED FOR ADOPTION — Only mechanical structural reachability may be inferred automatically without a new cognitive assertion, and even then only at the structural level. For example, if A is derived from B and B from C, C is in A's ancestry; it does not follow that A preserves C's meaning, trust, applicability, license, or authority.

No relationship assertion imports the trust of its assertor into the related Rotes. No source-declared relationship is automatically accepted by the receiver. A source may say “equivalent”; the receiver may retain that as a claim and independently assess “substantial overlap.”

5. Epistemic ontology

5.1 Six independent dimensions

RECOMMENDED FOR ADOPTION — Epistemic semantics must be factored into six dimensions rather than a flat status list.

Dimension Question answered Representative terms
Origin act How did the proposition first enter cognition? observed, human-stated, instrument-reported, constructed, imported with unknown origin
Acquisition event How did this instance obtain this representation? retrieved, received, recalled, discovered, directly observed locally
Transformation act What happened between source cognition and this expression? selected, translated, summarized, redacted, normalized, combined, inferred, generalized, simulated
Claim modality What sort of stance does the assertion take? asserted, hypothesized, predicted, prescribed, counterfactual, unknown/withheld
Receiver acceptance How does this instance currently treat it for a named use? unassessed, quarantined, attributed-only, tentative, accepted, disputed, rejected, suspended
Confidence basis How strong and why, without pretending to universal precision? direct/indirect evidence, sample and coverage, independence, contradiction, uncertainty, calibration, unknown

“Retrieved” belongs to acquisition, not origin. “Summarized” belongs to transformation, not truth. “Disputed” belongs to receiver or community posture, not the source's original act. “Prescribed” is claim modality and often signals procedure or normative cognition. “Constructed” can be origin for a model, procedure, or capability. “Unknown” is qualified by dimension: unknown origin, unknown confidence, unknown applicability, or unknown acceptance are different.

5.2 Provenance-preserving proposition rule

RECOMMENDED FOR ADOPTION — A proposition's origin remains attached to the act that first introduced that proposition, not to whoever most recently repeated, retrieved, summarized, or transferred it. Later actors add custody, transformation, endorsement, or rejection; they do not become the original observer or claimant.

If a person states “the receiver was offline,” a model retrieves and repeats it, and another AncientOS transfers it, the proposition remains human-stated unless direct observation independently confirms it. The model and transferring system are part of transformation/custody provenance, not observation provenance.

5.3 Event, interpretation, and lesson

RECOMMENDED FOR ADOPTION — Experience must preserve a three-layer chain:

  1. Event layer: what was observed or credibly reported to have occurred, including action, conditions, outcome, time, and observer.

  2. Interpretation layer: what an actor inferred about meaning, mechanism, or cause from the event. Interpretations may be contemporaneous or later and may conflict.

  3. Lesson layer: a generalized heuristic, procedure, prediction, or norm derived across one or more event/interpretation pairs.

Each layer has its own author, epistemic posture, applicability, confidence basis, and relationships. A lesson does not inherit “observed” from its event. Later direct observation that confirms an earlier inference creates a new Observation supporting the Claim; it does not retroactively convert the original inference into an observation.

5.4 Confidence without a universal score

RECOMMENDED FOR ADOPTION — AncientOS should represent confidence as a structured assessment, not one universal number. A useful confidence account names:

  • the proposition or relationship assessed;

  • assessor and use context;

  • evidence coverage and quality;

  • independence or shared-source uncertainty;

  • known contradictions and missing evidence;

  • model/measurement calibration where relevant;

  • sensitivity to applicability assumptions;

  • conclusion expressed qualitatively or quantitatively only where the domain warrants it.

Numeric probabilities may be legitimate within a Rote when produced by a calibrated method and scoped to a proposition. They should not become a universal Rote trust score.

6. From local cognition to Rote

6.1 Not every memory is a Rote

RECOMMENDED FOR ADOPTION — Local cognition is the broader universe. It includes transient context, durable memory, observations, conversations, preferences, inferred models, assessments, task state, and operational evidence. A Rote is a deliberately bounded transferable projection or construction from that universe.

Every Rote may be stored or remembered in LifeVault conceptually. Most LifeVault cognition should not automatically become a Rote. Automatic equivalence would create privacy risk, granularity collapse, unstable attestations, and enormous metadata burden.

6.2 The lifecycle model

The proposed sequence is not one mandatory pipeline. It is a set of conceptual transitions with branches:

  1. Local cognition exists. It may be transient or durable, typed or untyped, private or shareable.

  2. Boundary is proposed. An actor selects cognition and states what is inside, supporting, referenced, excluded, or unknown.

  3. Rote candidate is prepared. Minimum universal properties, cognitive profile, provenance, applicability, relationships, effects, and privacy posture are made explicit. A candidate may be dynamically generated and revised.

  4. Candidate is inspected. Semantic closure, privacy, provenance loss, rights, integrity intent, and dangerous effects are assessed. Failure returns it to preparation or leaves it local.

  5. Attestation is sealed. When the candidate is committed for durable reliance, offered, published, or transferred, its cognitive assertion and source claims become immutable. This is the birth of an attested Rote.

  6. Rote is advertised or transferred. Advertisement may use a privacy-minimized projection that is not the full Rote.

  7. Receiver assesses locally. The receiver creates local records of comprehension, trust, applicability, conflict, and allowed effects without modifying the attestation.

  8. Receiver applies selected effects. It may retain, integrate under posture, operationally prepare, or pursue separately governed effects.

  9. Use produces new local cognition. Outcomes, reinterpretations, adaptations, and conflicts remain local unless deliberately bounded into new candidates.

  10. Derivatives are attested separately. Refinements, redactions, corrections, forks, and lessons become new Rotes with lineage when sealed.

6.3 Dynamic Rotes and immutability

RECOMMENDED FOR ADOPTION — A dynamically generated view may be a Rote candidate but should not be called an attested Rote until its semantic boundary and representation are sealed. A candidate can change; an attested Rote cannot. The trigger is not necessarily public publication: durable internal reliance or a peer offer can also require attestation.

This resolves Draft 1's tension between useful generated views and immutable published cognition. It also means “latest view” is not an identity; each sealed output is a historical cognitive act.

REQUIRES OPERATOR DECISION — Whether durable internal use alone should always trigger attestation, or whether AncientOS may retain revisable internal candidates until external offer/transfer. The former improves auditability; the latter reduces cognitive debris.

6.4 Conceptual implications for LifeVault

DESIGN DIRECTION — LifeVault remains AncientOS's broader durable memory/knowledge substrate. Conceptually it should eventually be able to preserve epistemically typed local cognition, proposition origin, relationships, applicability, and continuity cues. Rotes should project from and return to this richer cognition without making LifeVault “a Rote database” by definition.

A useful continuum is:

transient context → durable local cognition → bounded Rote candidate → attested transferable cognition → local receiver assessment → derived local cognition

The arrows represent transformations with provenance, not automatic promotion.

7. Integration-effect semantics

7.1 Six effect families

RECOMMENDED FOR ADOPTION — Every integration statement must name an effect, target, scope, posture, and decision source. “The Rote is integrated” is insufficient.

Effect family Meaning Representative effects
Custody Possession without epistemic endorsement possess, quarantine, inspect, retain
Discoverability Make cognition findable without accepting it catalogue, index/retrieve, cite as attributed cognition
Epistemic use Permit cognition to influence reasoning under an explicit posture reason with, tentatively accept, accept, dispute, recommend from, learn from, map into local ontology
Evaluation Exercise cognition without real-world effect compare, test conceptually, simulate
Operational enablement Change environment or capability availability operationally prepare, install dependencies, register capability, activate
Authority and lifecycle Permit/limit action and manage later status authorize bounded use, suspend, revoke authority, retire, derive new cognition

Custody is not acceptance. Acceptance is not unrestricted reasoning weight. Cognitive integration is not operational preparation. Activation is not authority.

7.2 Effect matrix legend

  • C — characteristic/ordinary effect for the kind.

  • A — allowed when meaningful but requires explicit assessment or mapping.

  • O — operational effect; meaningful only for actionable/enabling material and potentially governed.

  • N — normally nonsensical or a category mistake for that kind.

Informational and epistemic effects

Effect Obs. Claim Model Exp. Proc. Heur. Norm. Cap. Synthesis
Possess / quarantine / inspect C C C C C C C C C
Retain / index / retrieve C C C C C C C C C
Cite as attributed cognition C C C C C C C C C
Reason with A C C A A C A A C
Tentatively accept / accept A C A A N A A A A
Dispute A C A A A A A A A
Recommend from A A A A C C A A A
Learn from A A A C C C A C C
Map into local ontology A A C A A A A A C
Simulate N A C A C A A C A
Derive new cognition C C C C C C C C C

“Accept procedure” is marked N because the phrase is ambiguous. AncientOS may accept claims about the procedure, adopt it as a recommended method, or authorize a specific performance; it does not accept a procedure as true. “Accept capability” likewise must resolve to accepting its description/claims, choosing it for preparation, or authorizing use.

Operational and authority effects

Effect Obs. Claim Model Exp. Proc. Heur. Norm. Cap. Synthesis
Operationally prepare N N A A O A A O A
Install dependencies N N N N O N N O O
Register capability N N N N N N N O O
Activate N N N N N N A O O
Authorize bounded use N N N N O A A O O
Suspend A A A A A A A O A
Revoke authority N N N N O N O O O
Retire from active use A A A A A A A O A

For informational kinds, “suspend” means suspend an effect such as recommendation or reasoning use—not delete or deny historical possession. Normative cognition may be activated in the sense of making an adopted policy effective, but only when authority and precedence are valid. A Synthesis inherits operational possibilities only from its actionable constituents and never by virtue of synthesis alone.

7.3 Reversibility and consequence

Effect Operationally reversible? Cognitively or externally irreversible aspects
Quarantine / retain / index Usually Mere possession can create privacy, legal, or exposure obligations
Reason with / accept / learn from Posture can change Prior reasoning, decisions, and derived cognition cannot reliably be “unthought”
Map into ontology Mapping can be disabled or revised Downstream references and derived models may retain influence
Simulate Usually if isolated Simulation outputs may be retained, leaked, or influence judgment
Install dependencies Often removable Configuration drift, supply-chain exposure, data migration, and external obligations may persist
Register / activate Usually suspendable External discovery, data access, side effects, or persistent state may already have occurred
Authorize bounded use Prospectively revocable Actions already executed and external effects remain
Retire / retract Active preference can change History, custody, and downstream derivatives remain

RECOMMENDED FOR ADOPTION — Reversal must always name the effect being reversed. “Remove the Rote” cannot promise erasure of derived cognition, audit evidence, peer copies, or external consequences.

8. Trust and applicability assessment

8.1 Trust facets

RECOMMENDED FOR ADOPTION — Trust is a local conclusion of the form: “Instance I is willing to rely on aspect X of cognition R for use U under context C, subject to conditions K.” It is not a portable scalar property.

Trust assessment should be decomposed into facets:

Facet Question Common evidence
Source authenticity Is the claimed source identity credible? attestations, authenticated channel, continuity of identity
Artifact/custody integrity Is this the representation the source or custodian conveyed? integrity evidence, custody history, declared gaps
Source competence Is the source reliable for this domain and claim kind? track record, expertise, calibrated prior outcomes
Evidence adequacy Does the evidence rationally support the cognition? directness, method, sample, alternatives, counterevidence
Transformation fidelity Did translation, inference, summary, or redaction preserve relevant meaning? method transparency, source availability, loss statement, reproducibility
Operational integrity Are actionable/executable materials sufficiently safe for the proposed effect? review, isolation evidence, behavior evidence, dependency provenance
Intent/alignment Is the source or construction plausibly aligned with the receiver's use and constraints? incentives, declared purpose, conflict of interest, adversarial assessment

A system may trust custody but not truth; trust a source's self-report but not its causal explanation; trust conceptual documentation but not executable material; or trust a procedure for simulation but not real-world use.

8.2 Trust through derivation and composition

Trust does not automatically propagate. For a derivative, the receiver assesses:

  • each source Rote relevant to the conclusion;

  • source independence and hidden common ancestry;

  • transformation competence and transparency;

  • omitted or redacted material;

  • new claims added by the transformer;

  • sensitivity of the result to untrusted inputs;

  • whether the derivative can be checked independently.

The weakest input does not mechanically determine the whole, and multiple weak inputs do not become strong merely by quantity. A transparent synthesis may be trusted as an accurate summary of disputed sources while its conclusion remains disputed.

8.3 Corroboration and unknown provenance

Independent corroboration can increase evidentiary support only to the degree independence is established. “Different peers” is not proof: both may have copied the same hidden source. Independence should therefore be an assessed claim with uncertainty.

Unknown provenance does not prohibit possession, attribution as unknown, inspection, simulation, or independent validation. It should constrain uses that depend on source authenticity, consent, rights, or operational integrity.

8.4 Applicability model

RECOMMENDED FOR ADOPTION — Applicability is a match assessment between a Rote's declared or inferred envelope and a proposed local use. It includes:

  1. Subject match: person, population, device, organization, or concept.

  2. Temporal match: observation time, validity interval, event order, freshness sensitivity.

  3. Environmental match: hardware, software, versions, configuration, topology, available capabilities.

  4. Jurisdictional/institutional match: law, policy, contract, organization, role.

  5. Intent/outcome match: use being contemplated and acceptable outcome tolerances.

  6. Risk match: consequence severity, reversibility, supervision, and uncertainty tolerance.

  7. Competence/resource match: operator/system skill, dependencies, evidence, time, and access.

  8. Interpretive match: concept mapping and semantic fidelity.

The result should be contextual, such as applicable, conditionally applicable, not applicable, unknown, or disputed—with reasons. It should not be one permanent property of the Rote.

For high-consequence operational effects, unknown decisive applicability must fail closed. For informational retention, unknown applicability can remain explicit without blocking possession.

8.5 Trust-applicability interaction

Trust answers whether the receiver is willing to rely; applicability answers whether the cognition bears on this context. They interact but do not substitute:

  • trusted but inapplicable cognition should not guide the use;

  • applicable but untrusted cognition may justify investigation, not acceptance;

  • true and applicable cognition may still be unsafe under current risk constraints;

  • authentic normative cognition may lack authority over this operator;

  • safe executable material may implement a capability the operator has not authorized.

9. Privacy threat model for Rote exchange

9.1 Protected interests and adversaries

The model protects the operator, third parties, peers, credentials, private cognition, environmental topology, preferences, relationships, capabilities, and the fact of possessing particular cognition. Adversaries include malicious peers, curious trusted peers, compromised intermediaries, colluding instances, future recipients, and benign systems that infer too much from repeated interaction.

Privacy must be assessed at every semantic stage, not only payload transfer.

9.2 Stage threats and controls

Stage Principal leakage or harm Required conceptual control
Advertisement Topic, capability, diagnosis, relationship, or interest revealed by existence Minimum-disclosure descriptions; policy-scoped audiences; coarse categories; no proof of absence
Discovery Queries reveal what the requester wants, lacks, fears, or possesses Query minimization; local-first matching; scoped encounter purpose; indistinguishable non-response where needed
Comparison Set intersection reveals inventory, gaps, rarity, or common ancestry Selective comparison; disclosure budgets; uncertainty-preserving results; no global inventory requirement
Request A specific request reveals intent, project, vulnerability, or dependency Bounded request semantics; optional mediated/anonymized request; policy check before disclosure
Preparation Private local state is selected; generalization may encode identity Data minimization; third-party rights check; provenance-aware abstraction; rare-combination analysis
Redaction Direct identifiers removed but inference remains; evidence becomes misleading Treat redaction as transformation; declare loss; reassess applicability and evidentiary strength; prefer withholding to false abstraction
Transfer Payload/custody exposure, recipient mismatch, replay, onward copying Exact recipient/purpose posture; integrity/custody evidence; transfer policy; least material closure
Inspection Untrusted content probes or manipulates cognition; secrets surface during analysis Quarantine; bounded render/interpretation; no hidden execution; cognitive-adversarial review
Integration Sensitive claims become retrievable; private source is linked to local identities Scoped indexing; access/use constraints; preserve attribution without unnecessary exposure; restrict inference joins
Later derivation “Anonymous” aggregate becomes identifying; private facts become generalized claims Re-run privacy and rights assessment; preserve derivation; block provenance laundering
Re-sharing Original consent, audience, context, or legal right no longer applies New disclosure decision; carry restrictions and provenance; source/third-party consent where required

9.3 Leakage through metadata and interaction

Particular threats require explicit attention:

  • Existence leakage: advertising a fertility, security, or legal Rote reveals sensitive state even without content.

  • Rare combinations: harmless facts in combination may uniquely identify a person, household, employer, or topology.

  • Lineage leakage: a common ancestor can reveal community membership, software use, or contact history.

  • Timing leakage: creation and request times can expose routines, incidents, travel, or crises.

  • Topology/dependency leakage: hardware, addresses, account providers, or missing components reveal attack surface.

  • Applicability leakage: “applies to medication X” or “valid in jurisdiction Y” can disclose health or location.

  • Negative-knowledge leakage: answering “no Rote found” differently from “private” reveals hidden inventory.

  • Repeated encounter leakage: adaptive questions can reconstruct a private catalogue across sessions.

9.4 Indistinguishability principle

RECOMMENDED FOR ADOPTION — Where privacy policy requires it, a peer must not be able to distinguish among unknown, absent, withheld, private, and policy-blocked from external behavior. This is a semantic requirement on exchange outcomes, not merely a user-interface wording preference.

The principle cannot be absolute: operational error handling or consensual collaboration may legitimately reveal a reason. The architecture must support a privacy-preserving response class rather than always disclose exact cause.

9.5 Privacy versus provenance tension

Complete provenance can identify people; aggressive anonymization can destroy evidentiary meaning. The safe outcome may be:

  • transfer a coarser claim with weaker confidence;

  • transfer only an advertisement;

  • provide evidence under a narrower audience or purpose;

  • transfer a sanitized derivative whose loss is explicit;

  • decline transfer.

There is no requirement that all useful cognition be transferable. “Cannot package safely without making it misleading” is a valid result.

10. Governance and component responsibility boundaries

This section states architectural responsibility only. It does not claim current implementation or define interfaces.

Concern Conceptual responsibility in Rote architecture Must not become
Luna Interpret operator intent; explain Rote posture, provenance, uncertainty, conflicts, and available effects; detect continuity intent and route retrieval/assessment Source of hidden authority, provenance rewriter, or prompt-only enforcement layer
Lich Record explicit authorization for exact bounded governed Rote-related effects and conditions General “trust this Rote forever” toggle or approval system duplicated per transport
Rubick Represent available capability semantics, dependencies, activation posture, and governance mode after appropriate recognition Installer-by-default or authority conveyed by capability possession
LifeVault Preserve broader local cognition, provenance, relationships, applicability, assessments, continuity, and Rote ancestry conceptually A store in which every memory is automatically a Rote or accepted truth
Zeus Preserve durable evidence and reconstructable records for attestations, transformations, assessments, and governed effects Truth oracle merely because evidence is signed or durable
Oracle Evaluate current environment/preconditions/applicability before consequential effects Source of generalized truth beyond observed evidence or substitute for authorization
Operational Router Route requested effects to the appropriate canonical capability and governance path Escape hatch that interprets possession as execution permission

10.1 Ordinarily read-only cognition operations

Subject to privacy, legal, and resource policies, the following should ordinarily remain read-only cognition operations rather than requiring Lich solely because a Rote is involved:

  • receive into quarantine;

  • verify declared integrity or identify missing material;

  • parse and recognize cognitive kinds;

  • inspect provenance, relationships, and applicability;

  • compare to local cognition without disclosing private inventory;

  • retain as attributed/untrusted cognition;

  • index for scoped retrieval;

  • cite as attributed cognition;

  • evaluate trust, conflict, and applicability;

  • simulate in a genuinely isolated, non-mutating environment;

  • propose integration or governed operational actions.

Some installations may choose policy controls around sensitive reading, retention, or indexing. That is not the same as treating all cognition as mutation authority.

10.2 Effects that may require governed authorization

Potential Lich boundaries include:

  • disclosure, advertisement, transfer, or re-sharing of private or restricted cognition;

  • adopting a Rote as canonical operator preference, policy, or protected knowledge where this changes governed behavior;

  • acquiring or installing dependencies;

  • changing configuration, accounts, credentials, external systems, or protected memory;

  • registering or activating a capability;

  • executing a procedure or executable material;

  • granting a capability bounded authority;

  • accepting licenses, financial obligations, or third-party terms;

  • destructive retirement or deletion where evidence, rights, or continuity are affected.

Authorization must bind to a named effect, Rote or projection identity, target, operator principal, preconditions, applicability assessment, scope, and expiry/revocation semantics where relevant. It must not flow automatically from source trust, peer identity, installation, or prior use.

11. Comparative evidence from Fable memory patterns

The supplied observation about another AI memory architecture is comparative evidence, not AncientOS authority. It reinforces several Draft 1 directions and reveals one missing distinction.

11.1 Epistemically typed persistent local cognition

Distinguishing human-stated information, direct observation, and model inference strongly supports the six-dimensional epistemic model. AncientOS should eventually preserve origin acts deterministically rather than asking Luna's prompt to remember not to mislabel them.

11.2 Provenance-preserving memory

Preserving proposition origin instead of assigning provenance to the most recent repeater is directly relevant to Rotes and LifeVault. This specification adopts that as the provenance-preserving proposition rule. Transfer and retrieval add provenance events; they do not rewrite origin.

11.3 Relationship-aware memory

Knowledge relationships support contradiction, corroboration, continuity, and lineage without flattening all memory into text chunks. The Rote model already required first-class relationships; the comparative evidence strengthens the case that local cognition should also preserve them before transfer.

11.4 Lightweight catalogues with selective retrieval

Draft 1's privacy-preserving advertisements align with lightweight cognition descriptions that allow detailed material to be retrieved selectively. The missing distinction is between:

  • a local cognition descriptor used for retrieval;

  • a peer advertisement designed for privacy-preserving discovery;

  • a Rote envelope that carries sufficient semantic/evaluative context;

  • the material content and dependencies retrieved only when needed.

These may resemble one another but have different audiences and disclosure guarantees. A local descriptor must not be reused automatically as a peer advertisement.

11.5 Runtime continuity intent

Phrases such as “we discussed this before,” “continue,” or “same as last time” are semantic retrieval cues. Luna can recognize them conversationally, but continuity should eventually be a deterministic runtime concern: detect intent, resolve identity and scope, retrieve attributed prior cognition, and disclose uncertainty. Prompt memory alone is too fragile for an architectural invariant.

11.6 LifeVault–Rote continuum

The comparative patterns support the proposed continuum between epistemically typed local cognition and deliberately bounded Rotes. They do not justify equating memory objects with Rotes. Transfer demands semantic boundary, applicability, privacy, effects, and attestation beyond ordinary local recall.

12. Golden Rote A — factual observational cognition

12.1 Creation

At 21:04 UTC on 2 September 2026, AncientOS instance A directly queries a living-room receiver through a read-only status capability. The response identifies firmware 4.2.1. The query method, target identity, response time, and integrity of the observation channel are recorded. An operator separately says, “I thought it updated to 4.3 yesterday.” These are not merged: the first is a local direct Observation; the second is a human-stated Claim about a possible earlier event.

12.2 Boundary

The candidate's primary kind is Observation. Its core cognition is: “Observer A registered target alias R reporting firmware 4.2.1 at 21:04 UTC through method M.” It includes method, time, target-class context, and measurement limitations. It excludes the receiver's private network address, household name, account identifiers, and unrelated topology. It references—but does not contain—the operator's contradictory statement.

Semantic closure is achieved because a receiver can understand who observed what, when, and how. Material closure may be incomplete if raw device-response evidence is withheld.

12.3 Provenance and epistemics

Origin act: directly observed locally by capability M. Acquisition: native local observation. Transformation: target pseudonymization and privacy redaction. Claim modality: report of observation, not timeless fact. Confidence basis: direct response with known channel limits. The redactor is not relabeled as observer.

12.4 Relationships

The Observation supports the scoped Claim “R ran or reported 4.2.1 at 21:04.” It contradicts the operator's Claim only if both are interpreted as descriptions of the same target state at the same time. They may both be true if the update rolled back, the operator recalled another device, or the receiver reported stale data.

At 22:10, a second read-only method reports 4.3.0. That later Observation does not correct the historical 21:04 Observation. It may support a Claim that the state changed or that one method was stale. A synthesis would be needed to decide.

12.5 Advertisement and transfer

Instance A advertises only: “time-bounded firmware observation for receiver class C; direct device method; topology redacted.” It does not reveal the specific firmware value until transfer is accepted. If even receiver class is sensitive, the advertisement can be coarser or absent.

The attested Rote is sealed before offer. The transfer includes the redaction transformation and states that raw response evidence is unavailable to the peer.

12.6 Receiver assessment

Instance B possesses and parses the Rote. It authenticates A as the source but treats channel integrity as plausible rather than proven. B determines that its own receiver is a different model, making direct applicability low. It retains the Rote as attributed historical evidence and does not accept a general proposition about firmware availability.

12.7 Integration choices

B may index it for research, cite it as “A observed…,” use it as one piece of evidence about firmware rollout, or leave it quarantined. It must not overwrite B's device state. No operational effect or Lich approval follows merely from possession.

12.8 Later derivation

After several independent observations across compatible models, B may derive a Claim that firmware 4.3 rollout is staggered. The derivative preserves each Observation's historical identity, assesses source independence, and states population/time limits. The original Observation never becomes a generalized fact by repetition.

13. Golden Rote B — experience-derived heuristic and procedure

13.1 Local episodes

Instance A records four playback attempts involving a household receiver after sleep:

  1. On environment version V1, playback failed after the receiver slept for eight hours; rediscovery restored control.

  2. On V1, playback failed again after overnight sleep; restarting the media server did not help, but rediscovery did.

  3. On V1 with a network change, playback failed; rediscovery found a changed endpoint and restored control.

  4. On V2, playback succeeded after sleep without rediscovery.

Each episode is an Experience with event evidence, action sequence, outcome, time, and environment. The episodes include private local details: device names, network addresses, household timing, media title, and logs containing account tokens.

13.2 Interpretations

After episodes 1 and 2, A infers that sleep invalidates cached discovery state. Episode 3 strengthens the endpoint-change hypothesis. Episode 4 is a counterexample suggesting version dependence or a fix. None of these causal interpretations is directly observed.

13.3 Lesson and procedure derivation

A constructs a Synthesis Rote with two core outputs:

  • Heuristic: “For receiver class C on environment family V1, when control fails following extended sleep, suspect stale discovery state before restarting unrelated services.”

  • Procedure: “Confirm non-destructively that the target is unavailable; re-run bounded receiver discovery; compare target identity; retry once; stop and report if identity is ambiguous or discovery fails.”

The primary Rote role is Synthesis because the contribution is the qualified lesson across experiences. Secondary kinds are Heuristic and Procedure; the source episodes remain referenced or selectively contained.

13.4 Boundary and privacy preparation

The transferable boundary includes environment family V1/V2 distinction, sleep condition, failure signature, unsuccessful server restart, rediscovery outcome, sample size, counterexample, stop conditions, and causal uncertainty. It excludes addresses, exact household schedule, media title, usernames, tokens, and human identities.

Redaction removes raw logs entirely because token-safe transformation cannot be guaranteed. This weakens material closure and reproducibility; the Rote declares that loss. The device class is generalized only as far as the evidence supports.

13.5 Provenance and relationships

Each episode remains experienced-by A and observed/reported under its own posture. The causal explanation is inferred. The heuristic and procedure are derived from and learned through use of the earlier control capability. Episode 4 contradicts an unqualified version of the heuristic and therefore specializes its applicability to V1 rather than being discarded.

13.6 Advertisement and transfer

A advertises: “experience-derived recovery heuristic for post-sleep receiver-control failure; four episodes; version-sensitive; private topology removed; no executable content.” The peer can request only the procedure, the qualified heuristic, or additional evidence. Transfer never implies that the peer experienced the failures.

13.7 Receiver assessment

Instance B maps receiver class C to its own similar—but not identical—device class. It judges semantic mapping partial, source authenticity high, evidence sample small, causal confidence moderate-to-low, and applicability conditional on matching failure signature and version family. It also notes that rediscovery is read-only or low-risk in B's environment, while server restart would be more consequential.

13.8 Integration choices

B retains the source experiences as remote attributed experience. It integrates the heuristic tentatively for diagnosis and adopts the procedure only as a recommendation template. B may simulate the branch logic. If rediscovery itself has external effects in B's environment, execution requires the normal governed path; the Rote supplies no authority.

13.9 Local use and later derivation

B encounters two matching failures on V1 and one non-matching failure caused by credential expiry. B creates local Experience objects. It may derive a specialized heuristic: “Use rediscovery only when the target identity is absent or changed; credential errors are an exclusion.” The new Rote forks/refines the ancestor, includes B's own episodes, and does not claim that A observed B's events.

If A and B later meet, neither branch is “latest.” Their common ancestor, evidence sets, specializations, and conflicts can be compared. A new synthesis may combine them while preserving independent lineages.

14. Golden Rote C — capability with executable material

14.1 Cognitive purpose

Instance A has developed a bounded “Receiver Status Inspector” capability. Its purpose is to obtain read-only identity, availability, and firmware observations from a defined class of local receivers. The Rote explains the ability, intended inputs and outputs, limitations, supported environments, expected evidence, privacy effects, known failure modes, and governance posture.

Executable/installable material is included as one constituent. Documentation, procedures, tests, observed operating experience, dependencies, and normative safety constraints are also included or referenced. The primary kind is Capability; secondary kinds include Model, Procedure, Observation, Claim, and Normative Cognition.

14.2 Why this is not a package

A software package could deliver bytes and dependency declarations. The Capability Rote additionally represents:

  • what ability the material is supposed to create;

  • the semantic meaning and limits of its observations;

  • which claims are documentation versus observed behavior;

  • applicability and known exclusions;

  • operating experience and failure evidence;

  • privacy consequences of local discovery;

  • safe preparation and stop conditions;

  • separation of installation, registration, activation, and authorization;

  • relationships to other cognition and later derivatives.

The executable material can be rejected while the conceptual model, procedure, and failure knowledge remain useful.

14.3 Boundary, dependencies, and material closure

The Rote's semantic boundary includes the read-only inspection ability and explicitly excludes device control, media playback, configuration changes, internet discovery, and credential extraction. Dependencies include a compatible runtime, local-network access, a device protocol, and a capability-registration concept. No credentials are embedded.

If the runtime dependency is absent, the Rote can remain semantically closed but materially or operationally incomplete. “Depends upon” names which effect is blocked: inspection can be understood; activation cannot proceed.

14.4 Provenance and integrity

Authorship provenance identifies the capability designer. Source provenance for protocol knowledge is distinguished from transformation provenance for the implementation. Observations from A's environment support claims of compatibility but do not prove behavior in B's environment. Integrity evidence may establish which executable material was transferred; it does not establish safety or truth.

14.5 Relationships

The Capability depends upon runtime and protocol cognition; contains or references installation material; operationalizes a read-only status Procedure; is supported by test and experience Rotes; is constrained by a Normative Rote prohibiting mutation; and may be operationally equivalent to another inspector only under a named outcome tolerance.

14.6 Advertisement and transfer

A advertises a capability description, risk/effect class, platform applicability, required network access, dependency outline, evidence posture, and availability of executable material. It does not advertise local targets, credentials, or network topology.

B requests the conceptual portion first. A transfers an attested projection without executable material. Later, B may separately request the material closure. Each projection declares what is absent and preserves lineage to the full Capability Rote.

14.7 Receiver assessment

B understands the capability purpose and finds its device model applicable. It trusts A's conceptual documentation and historical experience enough for design comparison, but an independent review finds the executable component uses an unsafe dependency. B therefore rejects operational integrity while retaining the non-executable cognition.

14.8 Integration choices and governed effects

B can retain, index, reason about, and cite the conceptual material without installation. If safe material later exists, the sequence remains separate:

  1. Operational preparation: verify local preconditions and select dependency variants.

  2. Install dependencies/material: mutate the environment through appropriate governance.

  3. Register capability: make Rubick conceptually aware of the bounded ability and governance posture.

  4. Activate: enable the provider for read-only inspection in a specified environment.

  5. Authorize bounded use: permit an exact inspection or a pre-authorized read-only class under policy.

No earlier step entails a later one. Credentials, if ever required, are locally provisioned through separate protected means and are not inherited from the Rote.

14.9 Later derivation

B may replace the unsafe dependency, narrow network access, and add observations from its environment. The result forks from and refines the original Capability Rote. Its authorship and code provenance identify B's transformation; A remains source for inherited cognition only. The two variants may be operationally equivalent for read-only status while differing in safety, dependencies, and applicability.

15. Cross-kind stress tests

Case What the model handles cleanly Remaining ambiguity or weakness
One Rote contains several kinds Assertion-level kinds, full content profile, one primary role, and secondary effects prevent flattening Selecting a primary role can be subjective; an honest inability may signal a boundary that should split
One claim has several independent observations Distinct historical identities plus supports/corroborates relationships preserve evidentiary plurality Independence is itself uncertain and cannot be proved merely by different peers
Apparently independent cognition secretly shares a source Custody and lineage claims remain assessable; corroboration requires an independence basis Collusion or hidden copying may remain undetectable
Contradictory but credible Rotes Both remain; conflict is scoped by terms, time, applicability, and evidence The ontology cannot supply an oracle of truth or always resolve action under uncertainty
Old cognition remains historically correct Time-scoped Observation/Claim remains valid; supersession is contextual, not erasure Retrieval must avoid presenting historical truth as current state
Correct procedure is dangerous elsewhere Procedure applicability and operational preflight are separate from correctness Unknown hazards cannot all be declared by the source; high-risk unknowns must fail closed
Model inference later directly confirmed New Observation supports earlier inferred Claim without rewriting origin Humans may colloquially call the inference “proven”; architecture must preserve the chronology
Summary whose source evidence is unavailable Summary remains a lossy derivative with declared missing material and limited trust uses Fidelity may be impossible to assess; semantic closure can survive while auditability does not
Private experience yields a general lesson Event/interpretation/lesson separation and redacted derivative preserve lineage and lower confidence De-identification may fail or context removal may make the lesson misleading; non-transfer is valid
Unsafe executable, useful conceptual capability Capability meaning and code integrity are separate; conceptual projection can be integrated Conceptual instructions can still induce unsafe reimplementation; cognitive malware remains possible
Normative operator preference Source authority, subject, scope, time, revocability, and adoption are explicit Whether personal normative Rotes should ever be transferable by default requires operator philosophy
Opaque but empirically useful learned representation Can be retained as partially interpretable cognition with empirical effect evidence and sharply limited use Draft 1's formal definition requires intended meaning; fully opaque content may fail the Rote threshold
Two instances adapt one ancestor Fork, refinement, local experience, and common ancestry preserve both branches Cognitive merge remains context-specific and may require operator judgment
Retraction/consent withdrawal after derivatives Retraction is new cognition; active use/re-sharing can be suspended without falsifying history Complete unlearning, peer erasure, and downstream rights are not guaranteed and may conflict with audit needs

15.1 The opaque-cognition tension

This phase sharpens Draft 1's biggest unresolved boundary. A fully opaque learned representation may be transferable and empirically useful, yet fail the formal requirement that intended meaning be described sufficiently for a receiver to understand what it represents and what effects are possible.

Three models remain plausible:

  1. Strict semantic Rote: fully opaque material is not a Rote; it is a dependency or artifact referenced by a Capability/Model Rote. This preserves conceptual integrity but may exclude future machine cognition.

  2. Effect-legible Rote: opaque internals qualify if purpose, training/experience provenance, inputs/outputs, measured behavior, limitations, and allowed effects are inspectable. Understanding means effect-level understanding, not internal interpretability.

  3. Universal carrier Rote: any bounded learned state qualifies with metadata. This future-proofs aggressively but collapses toward arbitrary content plus metadata.

RECOMMENDED FOR ADOPTION — Adopt the effect-legible model. A receiver need not interpret internal latent structure, but the Rote must expose enough cognitive role, provenance, applicability, empirical behavior, uncertainty, and effect semantics to make possession and use honest. Material with neither semantic nor effect legibility remains an artifact, not a Rote.

16. Tensions and corrections to Draft 1

16.1 “Cognitive kind” required refinement

Draft 1 listed composition alongside content kinds. This phase finds that composition is primarily construction form. Treating it as a peer primitive would confuse “what cognition is this?” with “how was it assembled?” Synthesis remains a primary Rote role only when the integration itself is the new cognition.

16.2 “Immutable published Rote” required a birth event

Draft 1 proposed immutable published attestations but did not define when a revisable view becomes one. This phase distinguishes dynamic Rote candidates from sealed attested Rotes. Offer, publication, transfer, or durable reliance can trigger sealing; the exact internal trigger still needs operator decision.

16.3 “Understanding” required effect-relative semantics

Draft 1 used graded understanding but left the axis underspecified. This phase concludes that understanding is relative to a proposed effect. One can understand enough to catalogue a capability but not enough to activate it safely.

16.4 “Relationships are first-class cognition” required a stopping rule

Draft 1 correctly treated important relationships as cognition but risked recursive metadata explosion. The assertion-first/promote-when-consequential rule supplies a conceptual stopping principle without reducing relationships to storage links.

16.5 “Integration” required elimination as a bare state

Draft 1 described a family of effects but still used “cognitively integrated.” This phase recommends that architecture never persist or communicate integration without naming the effect and posture: indexed, reasoned-with-as-disputed, adopted-as-preference, activated, and so forth.

17. Decision register

  1. Adopt Draft 1's formal Rote definition and its settled separations.

  2. Adopt eight content kinds: Observation, Claim, Model, Experience, Procedure, Heuristic, Normative Cognition, and Capability.

  3. Treat Composition as an orthogonal construction form; permit Synthesis as a primary Rote role only for an emergent integrative contribution.

  4. Type cognition at assertion level and Rote-profile level; require one primary Rote role for attested Rotes.

  5. Adopt the required/optional semantics and category boundaries in section 3.

  6. Adopt the normative relationship vocabulary and its declared directionality/transitivity limits.

  7. Use compact relationship assertions by default and promote consequential or independently transferable relationships to full Rotes.

  8. Adopt the six-dimensional epistemic model: origin, acquisition, transformation, claim modality, receiver acceptance, and confidence basis.

  9. Adopt the provenance-preserving proposition rule: repetition, retrieval, and transfer do not rewrite origin.

  10. Adopt the event → interpretation → lesson separation.

  11. Reject a universal trust or confidence score; use scoped, reasoned assessments.

  12. Treat local cognition as broader than Rotes; not every durable memory is a Rote.

  13. Distinguish revisable Rote candidates from immutable attested Rotes.

  14. Require every integration statement to name a specific effect, scope, posture, and decision source.

  15. Adopt the six integration-effect families and the effect-legibility threshold for opaque cognition.

  16. Adopt local, faceted, use-specific trust and eight-dimensional applicability assessment.

  17. Adopt privacy controls across the entire exchange lifecycle, including privacy-preserving external indistinguishability among absent/unknown/withheld/private/policy-blocked where required.

  18. Preserve canonical AncientOS component responsibilities and keep Rote semantics out of prompt-only enforcement.

  19. Treat continuity references as semantic retrieval intent that should eventually be handled by deterministic runtime semantics.

17.2 Requires operator decision

  1. Internal attestation threshold: seal every Rote used for durable internal reliance, or allow mutable internal candidates until offer/transfer. Earlier sealing improves auditability; later sealing reduces cognitive debris.

  2. Normative portability default: permit operator preferences/policies to be advertised or transferred only by explicit opt-in, or allow policy-governed sharing classes. Opt-in maximizes autonomy/privacy; sharing classes improve collaborative personalization.

  3. Relationship promotion authority: allow AncientOS to auto-promote consequential relationship assertions into Rotes under deterministic rules, or require operator review. Automation preserves provenance at scale; review limits recursive growth.

  4. Canonical concept identities: introduce a layer above historical Rotes for stable concepts, or rely on scoped equivalence/mapping relationships. Canonical concepts simplify retrieval but risk ontology lock-in and centralized meaning.

  5. Retraction philosophy: prioritize durable historical evidence with prospective suppression, or permit stronger erasure where consent and law demand it. Neither fully satisfies auditability, privacy, and downstream cognition.

  6. Peer comparison posture: default to no advertisement, coarse topic advertisement, or relationship-scoped mutual discovery. These encode different openness/privacy philosophies.

17.3 Still unresolved

  1. A principled granularity test for when one boundary should split into several Rotes.

  2. The exact semantic-closure threshold by cognitive kind and proposed effect.

  3. How to represent tacit or embodied expertise whose effect is understood but transfer does not reproduce competence.

  4. How provenance summaries remain auditable when full ancestry is unavailable or too large.

  5. How rights, licenses, confidentiality, and consent obligations propagate—or fail to propagate—through derivation.

  6. How to evaluate hidden common sources, collusion, and sybil-like corroboration.

  7. How an instance can demonstrate that privacy-preserving comparison did not infer or retain prohibited cognition.

  8. How local ontology mappings are challenged, revised, and shared without declaring false equivalence.

  9. How cognitive malware, manipulative framing, and instruction-level attacks are assessed when no executable code exists.

  10. Whether a relationship assertion can remain indefinitely lighter-weight after it becomes the basis of a governed effect.

  11. How receiver rejection differs from suspension when new evidence could rehabilitate cognition.

  12. How community-level consensus, if ever represented, avoids becoming centralized truth.

17.4 Deferred to implementation architecture

  1. Mapping these concepts onto current repository components, classes, schemas, services, and runtime behavior.

  2. Concrete identifiers, integrity mechanisms, signatures, and content-addressing.

  3. Representation of assertion-level kinds, epistemic dimensions, relationships, and local assessments.

  4. Storage, indexing, selective retrieval, manifests, and garbage-collection behavior.

  5. LifeVault migration and compatibility with existing memory.

  6. Exact division of runtime work among Luna, LifeVault, Zeus, Oracle, Rubick, Lich, and Operational Router.

  7. Policy language and exact Lich actions for disclosure, installation, activation, authority, and destructive retirement.

  8. Sandboxing, executable review, dependency resolution, credentials, and supply-chain verification.

  9. Peer discovery, comparison, negotiation, transfer, synchronization, and privacy-preserving protocol choices.

  10. Ontology alignment, semantic equivalence detection, and continuity-intent detection mechanisms.

  11. User experiences for inspection, conflict, provenance, partial understanding, and effect selection.

  12. Test strategy, deployment sequencing, migration, performance, and operational evidence.

17.5 Rejected approaches

  1. One flat Rote type enum. Rejected because origin, content kind, transformation, posture, and effect are independent.

  2. Composition as an ordinary ninth primitive. Rejected because assembly method is orthogonal to cognitive content.

  3. Every memory is a Rote. Rejected because it collapses local cognition into transfer objects and creates privacy/granularity failure.

  4. A Rote exists only after external transfer. Rejected because durable attestation and internal reliance may need stable identity before transmission.

  5. Mutable published Rotes. Rejected because trust and provenance would attach to a moving semantic target.

  6. Every relationship is automatically a full Rote. Rejected because recursive metadata would overwhelm cognition.

  7. Relationships are mere storage edges. Rejected because contradiction, equivalence, evidence, and lineage have meaning, provenance, and uncertainty.

  8. Automatic transitive trust or equivalence. Rejected because context, fidelity, and transformation break entailment.

  9. Universal numeric trust score. Rejected because trust is local, faceted, use-specific, and not commensurable across effects.

  10. Recency as precedence. Rejected because historical truth and contextual supersession cannot be ordered by time alone.

  11. Signature as truth or safety. Rejected because authenticity and integrity do not prove semantics, applicability, benign intent, or operational safety.

  12. “Integrated” as a single lifecycle state. Rejected because it hides distinct custody, epistemic, operational, and authority effects.

  13. Installation conveys activation or authority. Rejected because each is a separate effect with separate governance.

  14. Receiver acceptance rewrites source posture. Rejected because local assessment must not launder provenance.

  15. Prompt-only epistemic discipline. Rejected because provenance and governance invariants require deterministic runtime semantics.

  16. Full inventory disclosure for peer comparison. Rejected because discovery itself leaks private cognition.

  17. Universal-carrier definition for opaque cognition. Rejected because it collapses Rote into arbitrary content plus metadata.

  18. Forced transferability. Rejected because some cognition cannot be safely de-identified, licensed, or contextualized without becoming misleading.

18. Readiness for the next phase

Subject to the operator decisions in section 17.2, the Rote abstraction is conceptually mature enough for a later implementation architecture investigation. That future phase should inspect actual AncientOS repository/runtime truth and answer how—or whether—the existing system can faithfully support:

  • assertion-level cognitive typing;

  • immutable Rote attestations and lineage;

  • compact relationship assertions with promotion;

  • provenance-preserving local cognition;

  • effect-specific integration and governance;

  • trust/applicability assessments;

  • privacy-preserving catalogues and exchange;

  • capability preparation, activation, and authority separation.

The implementation phase must treat this specification as product intent to test against reality, not as proof that any component already implements it. If repository constraints conflict with these semantics, the conflict should return to architecture review rather than silently redefining Rote around convenient storage or existing code.

End of Draft 1