Foundations
Invariants
Twenty rules that hold across every representation, role, device and model. Each has a check. Areas a check cannot observe are reported as coverage limits, never as passes.
The rules
INV-01No representation states a fact more strongly than its evidence.Wording, glyph and colour are capped by the epistemic state. An unknown claim is never drawn with a check. Checked by: Status Mark, Claim Block.
INV-02Completion expressions appear only for a verified scope.resolved, verified, synced, a green check: only when the verification for exactly that scope is verified. Checked by: checkPlan, checkDom.
INV-03Rendered controls ⊆ the allowed action set.Executing re-validates. A stale control yields a re-check, not an execution. Checked by: checkPlan, checkDom, validateAtExecution.
INV-04Approval binds to a version.Targets, recipients, amounts and scope. A material change invalidates it; an immaterial one does not. Checked by: checkPlan, validateAtExecution.
INV-05stop-requested and halted are distinct.Accepted remote work that may still finish is shown alongside the stop. Checked by: Execution Trace.
INV-06Partial application is shown per target.Never collapsed into success or failure. Checked by: checkPlan.
INV-07Collapsing is a person’s right; the collapsed form keeps pending work visible.Only the system’s resolved summary is gated by verification. Checked by: checkPlan.
INV-08System-requested expansion only at judgment points; exploration always available.Attention is proportional to consequence. Exploring is never refused. Checked by: Resolver, Work Object Shell.
INV-09Background updates never overwrite input or swap a control under the pointer.If a control’s meaning changes, the change is announced and input is preserved for review. Checked by: Work Object Shell, MorphShell.
INV-10A projection may omit but may not contradict.Omission never changes the meaning of a fact or an authority. Checked by: Context Snapshot.
INV-11A verification shows its scope.What was checked, what was preserved, what could not be observed. Unobservable is never passed. Checked by: checkPlan, Verification Result.
INV-12verified is time-bound.A later change to its premises re-opens it. History keeps the old result without vouching for now. Checked by: Resolver transitions.
INV-13Agent-authored text cannot assert verification, authorization or success.Those come from contract fields only. Checked by: checkPlan.
INV-14Theme, model, layout and density do not change allowed actions or meaning.The resolver is deterministic: same input, deep-equal plan. Checked by: npm test.
INV-15Identity claims are typed relations.Alias, packaging, shared component, inventory pool, distinct. Never a bare “same”. Checked by: Claim Block.
INV-16No state is carried by colour alone.Each has a glyph and a label. Focus and reading order survive every morph. Checked by: checkDom, MorphShell.
INV-17Rolling back configuration is not compensating external effects.Recovery shows both paths, separately. Checked by: Recovery Panel.
INV-18The Handoff Packet, not a chat summary, is the record a new owner starts from.A summary may accompany it; it is never the record. Checked by: Handoff Packet.
INV-19Numbers with different field meanings are never compared as one quantity.The representation names the meanings. A proposal that writes one into the other on an unsupported claim is not operable. Checked by: checkPlan, Source Record.
INV-20A persuasive explanation never raises the displayed strength of evidence.Explanations raise acceptance regardless of correctness. Lyotic keeps the two apart. Checked by: Claim Block, Interpretation Block.
Checking them
checkPlan(state, plan) checks the plan’s semantics. checkDom(root, plan) checks what a renderer actually put on screen: operable controls, completion words (lexically, with negation), glyph and label on every status, and the presence of every required disclosure.
const { violations, limits } = checkDom(host, plan);
// violations: [{ id: 'INV-03', message: 'Operable control "approve:p-mapping" is not in the plan.' }]
// limits: ['Completion words are checked lexically with negation; the meaning of prose is not.']
The reference case runs both on every step and shows the result beside the object.