
This build, end to end: every capability, every article, every receipt
What this is
A working prototype of a different way to organize AI systems. Every article, tool, skill, law, claim, source, API, CLI, and MCP server on this system is the same kind of invocable object: one address, one contract, one history, a receipt for every action. It runs on a single Cloudflare account, is operated by one person and the models he directs, and is public — any model that can open a URL discovers any object, reads its full contract from one JSON row, and with a single token edits it, hash-checked, ledgered and receipted.
- The unit. Everything on this system — every article, tool, skill, law, claim, source, API, CLI, and MCP server — is the same kind of object: one address, one contract, one history, a receipt for every action.
- Discovery.
GET https://miscsubjects.com/api/directory/search?q=<words>finds any object.GET https://miscsubjects.com/api/directory/<KEY>returns its complete operating contract: endpoint, verbs, arguments, auth shape, examples. There is no schema file to load and no prompt that enumerates capabilities. - Scale, measured. 892 directory rows are invocable capabilities. 173,989 ledgered invocations across 323 distinct capability objects between 2026-06-29 and 2026-07-29. 1,055 published articles carrying 11,062 atomized claims and 8,641 hash-chained sources.
- Authority. One token format.
?share=<token>in a browser orAuthorization: Bearer <token>in curl — interchangeable. Validate either athttps://miscsubjects.com/api/token/validate. - Externally anchored. The ledger chain head is sealed current through 689,866 events and bound to surfaces this operator does not control: drand round 6331315 (BLS-signed by the League of Entropy) and Bitcoin block 960173. Head: https://miscsubjects.com/api/chain/head · anchor: https://miscsubjects.com/api/anchor/3be5071eb3035ca29093c6713646bbe21bdca6cce262fc7f7eb64080c04e61fe
- Proof. Every invocation writes an append-only ledger row with a public receipt at
https://miscsubjects.com/api/dispatch?confirm=<invocation_id>, and the receipt states whether the result was observed or only the attempt. It does not say "200 OK" and call that proof. - Self-computed honesty. The system publishes its own grounding figure — the share of claims carrying an openable source — live, including when it is unflattering:
https://miscsubjects.com/api/metrics/grounding
Part 1 — The proof table
Each row is a capability class, a real receipt from the live ledger, and the article that documents it. Every receipt URL is public and requires no token. Receipts marked material mean the result itself was observed and recorded; that distinction is enforced by the receipt generator, not by prose.
Lead generation and scraping — discovery from public sources, enrichment, MX verification, AI scoring, drafting, sending. 19 LEADS_* capabilities; 187 discovery invocations recorded.
Receipts: discovery https://miscsubjects.com/api/dispatch?confirm=inv_zx53xxla5w (material) · scoring https://miscsubjects.com/api/dispatch?confirm=inv_zshmn0ucq1 (material) · MX verification https://miscsubjects.com/api/dispatch?confirm=inv_zsdvunxdrk (material) · send https://miscsubjects.com/api/dispatch?confirm=inv_tp7h228phk (material)
Article: https://miscsubjects.com/a/oip-system-leads · the priced version of this loop: https://miscsubjects.com/a/killbox-specification-v1-2
Paid advertising — 46 META_ADS_* capabilities covering accounts, campaigns, ad sets, ads, creatives, audiences, lookalikes, catalogues, pixels, budgets, delivery estimates, insights (sync and async), and the Conversions API.
Article: https://miscsubjects.com/a/oip-system-meta
Image and video generation — three independent providers plus durable storage. ArcAds (287 generation invocations), Grok images (54), OpenAI images (6), video, and re-storage to permanent URLs (85).
Receipts: ArcAds generate https://miscsubjects.com/api/dispatch?confirm=inv_zq3jcx3icf (material) · store to durable URL https://miscsubjects.com/api/dispatch?confirm=inv_zv2n9nml3n (material) · Grok image https://miscsubjects.com/api/dispatch?confirm=inv_zuklqy80eb (material) · OpenAI image https://miscsubjects.com/api/dispatch?confirm=inv_n46cio5qam (material)
Article: https://miscsubjects.com/a/oip-system-arcads The illustration at the top of this page was generated through that pipeline while this page was being written: receipt https://miscsubjects.com/api/dispatch?confirm=inv_n56yqd1lpu
Messaging across every channel a person actually uses — iMessage, SMS, WhatsApp, Telegram intake, group chats, polls, reactions, contact cards, delivery-status webhooks. 64 BLOOIO_ capabilities plus a second provider (TWOCHAT_) for WhatsApp groups, 10 PHONE_* handlers for share-sheet intake (text, URL, image, voice note, location, clipboard), and tracked email.
Receipts: message sent https://miscsubjects.com/api/dispatch?confirm=inv_oh5v2hofv4 (material) · WhatsApp group send https://miscsubjects.com/api/dispatch?confirm=inv_aokydx9k72 (material) · tracked email https://miscsubjects.com/api/dispatch?confirm=inv_zsff9euzwm (material) · plain email https://miscsubjects.com/api/dispatch?confirm=inv_zzijgpp911 (material)
Articles: https://miscsubjects.com/a/oip-system-phone · https://miscsubjects.com/a/oip-system-blooio · https://miscsubjects.com/a/oip-system-twochat · https://miscsubjects.com/a/oip-system-email
Social publishing — X posting, replies, deletion, search, identity (245 post invocations); Reddit search, thread reading, replying.
Receipt: post https://miscsubjects.com/api/dispatch?confirm=inv_zgiu8omiuf (material)
Articles: https://miscsubjects.com/a/oip-system-x · https://miscsubjects.com/a/oip-system-reddit
Voice — text to speech, speech to text, voice notes, audio playback on the operator's machine.
Receipt: speech synthesis https://miscsubjects.com/api/dispatch?confirm=inv_i5lrm9eshb (material)
Article: https://miscsubjects.com/a/oip-system-voice
Terminal and computer control — 41 LOCAL_ capabilities: shell execution (370 invocations), file read and write, grep, screenshots (20), OCR, clipboard, window and app control, UI clicks and keystrokes, notifications, launchd, ports, processes, AppleScript. Plus 45 CLI_ rows wrapping the actual command-line tools installed on the machine — git, gh, wrangler, docker, kubectl, terraform, gcloud, aws, ffmpeg, imagemagick, pandoc, node, npm, python, jq, psql, sqlite, and every coding agent CLI.
Receipts: shell execution https://miscsubjects.com/api/dispatch?confirm=inv_zzzb67cjqq (material) · GitHub CLI https://miscsubjects.com/api/dispatch?confirm=inv_rba5bflts4 (material) · screenshot https://miscsubjects.com/api/dispatch?confirm=inv_xkkkwli6ee (material)
Articles: https://miscsubjects.com/a/oip-system-local · https://miscsubjects.com/a/oip-system-desktop · https://miscsubjects.com/a/oip-system-cli
Browser control — headless fetch, markdown extraction, link extraction, PDF capture, screenshots, full Playwright automation, and a browser-use agent.
Receipt: Playwright automation https://miscsubjects.com/api/dispatch?confirm=inv_irpi9hivmi (material)
Article: https://miscsubjects.com/a/oip-system-browser
Infrastructure provisioning — 111 CF_* capabilities: create and delete D1 databases, KV namespaces, R2 buckets; read and deploy Workers; containers with file read/write and exec; DNS, observability queries, GraphQL analytics, audit logs, AutoRAG, browser rendering, DEX, CASB. Plus direct data-plane rows for D1, KV, R2, and Pages.
Receipts: KV write https://miscsubjects.com/api/dispatch?confirm=inv_w09f2zr555 (material) · R2 write https://miscsubjects.com/api/dispatch?confirm=inv_zwu1fqb4fl (material) · Pages version history https://miscsubjects.com/api/dispatch?confirm=inv_yidijgp8xd (material)
Articles: https://miscsubjects.com/a/cloudflare-os and the twelve-part series listed in Part 3.
Payments — 61 STRIPE_* capabilities: customers, products, prices, payment intents, invoices (create, finalize, send, pay, void), payment links, refunds, payouts, subscriptions, balance transactions.
Article: https://miscsubjects.com/a/oip-system-stripe
The metering path, exercised with real money and receipts (not a customer) — on 2026-07-28 a funded tenant was charged through the live meter. The ledger now holds 5 charge rows totalling $15.47 in price against $0.125 in measured provider cost, and the tenant's balance moved from $30.00 to $14.53. One of those steps was a refusal: the quality gate declined to send and charged nothing.
Articles: https://miscsubjects.com/a/federated-object-proof · https://miscsubjects.com/a/federated-objects-as-metered-utility · https://miscsubjects.com/a/buy-outcomes-not-subscriptions
Ingesting other systems — MCP servers, HTTP APIs, and CLIs all become the same kind of row. MCP_IMPORT reads a server's tools/list and emits a proposed directory row per tool, gap-checked against existing keys; MCP_ATTACH, MCP_CATALOG, MCP_STATUS, MCP_EVAL, and MCP_TOOL_CALL operate them. 11 MCP* rows; 18 MCP invocations recorded.
Receipt: MCP tool call https://miscsubjects.com/api/dispatch?confirm=inv_h4poa995hv
Articles: https://miscsubjects.com/a/oip-mcp · https://miscsubjects.com/a/oip-mcps · https://miscsubjects.com/a/oip-apis · https://miscsubjects.com/a/oip-clis · https://miscsubjects.com/a/oip-mcp-comparison · https://miscsubjects.com/a/oip-mcp-github · https://miscsubjects.com/a/oip-mcp-stripe
Delegated authority — mint a token, explain a token, revoke a token. Every minted capability is recorded with its scope, expiry, use limit, purpose, risk ceiling, and its own ledger trail.
Receipt: token minted https://miscsubjects.com/api/dispatch?confirm=inv_pzg5seu7qb (material)
Articles: https://miscsubjects.com/a/oip-tap-go · https://miscsubjects.com/a/what-is-tap-go · https://miscsubjects.com/a/what-is-token-drop · https://miscsubjects.com/a/what-is-capability-security
Traffic classification — the system classifies who is reading it, human or machine, and which pages they took. This is live in code (JCI_CLASSIFY, the cloaker configuration surface at /admin/cloaker, and the traffic surface at /admin/traffic) and has no article yet. It is named in the gap list in Part 8 rather than quietly omitted.
Part 2 — Adding a capability: performed live, while writing this page
The claim "any API, CLI, or MCP server becomes a first-class capability in one step" is the one most worth testing, so it was tested during the writing of this page, against an API the system had never touched. The full sequence, with receipts:
- POST one directory row for the Wikipedia REST summary API — key, type, target URL with an argument slot, docs, category. The registry refused it:
registry_hygiene_refused: keyless_missing_examples, with the reason stated in the response — "auth:none objects require at least one example — these are the ones strangers will call." Nothing was written; the response saidstate_changed: false. - POST again with examples and an input schema. Accepted.
- Invoke it. It failed:
HTTP 403 — Please set a user-agent and respect our robot policy. That failure is a receipt, not a silence: https://miscsubjects.com/api/dispatch?confirm=inv_okt8qfvaxv — titled "attempt proven; result not observed." - PATCH one field on the row to add the required headers.
- Invoke again.
HTTP 200, the live Wikipedia summary for Simurgh returned. Receipt: https://miscsubjects.com/api/dispatch?confirm=inv_pqlt196u8d — titled "material result proven."
Elapsed: under two minutes, four calls. The new capability is now a permanent, public, self-documenting object like every other one:
- its contract: https://miscsubjects.com/api/directory/WIKIPEDIA_SUMMARY
- its behavioural skill, generated from that contract: https://miscsubjects.com/api/directory/WIKIPEDIA_SUMMARY?format=skill
- its human page: https://miscsubjects.com/a/directory/WIKIPEDIA_SUMMARY
That sequence is the answer to "how much can this system add in one turn": a new external API, refused by its own hygiene law, repaired, invoked, and permanently documented — with a receipt at every step, including the failure. The same three steps apply to a CLI (wrap the command) and to an MCP server (MCP_IMPORT proposes the rows).
Part 3 — The totality of the capability surface
892 rows across 106 categories. Counted by family, so nothing here is an impression:
- Cloudflare and infrastructure — 111. Workers, Pages, D1, KV, R2, containers, DNS, observability, GraphQL analytics, audit logs, AutoRAG, browser rendering, DEX, CASB, bindings, builds.
- Messaging — 64 + 3 + 10. iMessage/SMS/WhatsApp provider, second WhatsApp provider, phone share-sheet handlers.
- Payments — 61 Stripe + 11 payment rows.
- Advertising and marketing — 46 Meta Ads + 49 marketing-category rows.
- Command line — 45. Every installed CLI, including every coding-agent CLI.
- Local machine — 41. Shell, files, screen, UI, clipboard, audio, processes, launchd.
- Leads and outreach — 19 + 15 business-development rows.
- Governance and audit — 18 governance + 10 audit + 6 law rows.
- Content operations — 29. Article write, patch, claim, source, ingest, ask, atomize.
- MCP — 11. Import, attach, catalogue, status, evaluate, call.
- Models — 10 Grok + OpenAI + Gemini + Kimi + GLM + WAI + gateway rows. Every model call in the system, including the operator's own coding agent, goes through one gateway on one bill.
- Google — 8. Sheets, Drive, Calendar, Tasks, Apps Script execution.
- Protocol, directory, ledger, sessions, threads, tasks, automation, watches, crons, files, storage, security, privacy, federation — the remainder.
Read any of them: https://miscsubjects.com/api/directory (owner) · search publicly: https://miscsubjects.com/api/directory/search?q=leads · one contract: https://miscsubjects.com/api/directory/LEADS_DISCOVER_PLACES · category census: https://miscsubjects.com/api/directory/categories
There is a documentation article for 73 of these subsystems, one per family, each pinned to its real rows. Complete list of subsystem articles, in the form https://miscsubjects.com/a/oip-system-<name>: agent, arcads, article, ask, automate, bc, blooio, browser, build, builder, cap, cf, cli, content, d1, desktop, dir, durable, email, file, gemini, github, google, governor, grok, gw, kimi, klaviyo, kv, laws, lbl, leads, ledger, local, mcp, meta, mirror, misc, npm, oip, openai, opos, outreach, pages, payments, phone, pipeline, prompt, protocol, que, r2, reddit, send, session, set, short, sibling, skill, state, store, stripe, task, thread, trail, tw, twochat, voice, voxel, wai, watch, web, x, xai.
Part 4 — The corpus, end to end
1,055 published articles in the editorial register; 1,229 addressable article objects once the generated protocol plane is counted. Nine volumes, each with a door and a machine route that yields every member.
Volume I — The protocol (422 articles). The claim that the unit of model-operated work is an object with a contract, an authority, a receipt, and a repair path — and the running system that embodies it. The root: https://miscsubjects.com/a/oip · the operating model: https://miscsubjects.com/a/oip-operating-model · the object model: https://miscsubjects.com/a/oip-object-model · discovery and dispatch: https://miscsubjects.com/a/oip-directory-dispatch · ledger and receipts: https://miscsubjects.com/a/oip-ledger-receipts · delegated tokens: https://miscsubjects.com/a/oip-tap-go · the security model: https://miscsubjects.com/a/oip-security-model · the machine plane: https://miscsubjects.com/a/oip-machine-json · row structure: https://miscsubjects.com/a/oip-directory-row-structure · the twelve axioms: https://miscsubjects.com/a/oip-the-12-axioms · intellectual lineage: https://miscsubjects.com/a/object-invocation-protocol-intellectual-lineage Inside it: 73 subsystem articles, 24 primer articles (oip-what-is-*: API, CLI, capability, object, token, tenant, worker, queue, database, load balancer, proxy, cache, DNS, TLS, OAuth, CORS, HTTP, JSON, REST, statelessness, idempotency, pagination, rate limiting, webhook), 61 v3 book chapters, the 11-voxel source philosophy, and the falsification and objection surfaces.
Machine routes: walk every philosophy voxel https://miscsubjects.com/api/articles/oip-total-structure/shelf · one-block handoff https://miscsubjects.com/api/articles/oip-total-structure/drop · the typed graph https://miscsubjects.com/api/articles/oip/voxels
Volume II — The infrastructure (25 articles). The one-account thesis, subsystem by subsystem. The frame: https://miscsubjects.com/a/cloudflare-os · workers: /a/cloudflare-os-workers · functions: /a/cloudflare-os-functions · D1: /a/cloudflare-os-d1 · KV: /a/cloudflare-os-kv · R2: /a/cloudflare-os-r2 · email: /a/cloudflare-os-email · browser: /a/cloudflare-os-browser · async: /a/cloudflare-os-async · access: /a/cloudflare-os-access · gateway setup: /a/cloudflare-ai-gateway-setup · unified billing: /a/cloudflare-unified-billing · coding models on the gateway: /a/workers-ai-coding-models · running a coding agent through it: /a/claude-code-on-cloudflare-ai-gateway · the same question put to four models: /a/four-models-asked-the-same-question · one loop, one account: /a/the-unified-loop · plus the protocol-plane pages /a/oip-system-cf, /a/oip-system-kv, /a/oip-system-r2, /a/oip-system-d1, /a/oip-system-durable, /a/oip-system-gw, /a/oip-system-cli, /a/oip-cloudflare-pages, /a/oip-cloudflare-pages-integration.
Volume III — The concept dictionary (27 entries). Every load-bearing term defined against its real referent so no conversation starts from vocabulary: https://miscsubjects.com/a/what-is-mcp · /a/what-is-a2a · /a/what-is-langchain · /a/what-agentkit-was · /a/what-is-semantic-web · /a/what-is-self-describing-protocol · /a/what-is-url-is-api · /a/what-is-receipt · /a/what-is-receipt-is-proof · /a/what-is-replay-repair · /a/what-is-prov · /a/what-is-model-operated-work · /a/what-is-capability-security · /a/what-is-tap-go · /a/what-is-token-drop · /a/what-is-voxel-graph · /a/what-is-context-as-cursor · /a/what-is-the-anthropic-messages-api
Volume IV — The philosophy, with its scholarly apparatus. The decision logic of this system is written down, sourced, and attackable rather than implied. The Grain (29 chapters, entry https://miscsubjects.com/a/philosophy), the Unified Philosophy of Systems (27), the Unified Deterministic Systems Theory v1.1 (13, including its own falsification chapter https://miscsubjects.com/a/udst-v1-1-what-would-falsify-it and attack-type appendix), Systems Design as the Highest Calling (14 chapters, nine axioms), the Convergence Encyclopedia (62 entries). Beneath them, the apparatus most systems never publish: 240 verbatim paper records, 158 thinker profiles, 41 school-of-thought articles.
Machine routes: https://miscsubjects.com/api/articles?q=grain-&limit=250 · ?q=unified-philosophy · ?q=udst-v1-1 · ?q=systems-design · ?q=convergence- · ?q=thinker- · ?q=paper- · ?q=school-
Volume V — The research library. Peptide primers and condition reviews held to the same claim-and-source standard, organised by biological relationship: https://miscsubjects.com/content
Volume VI — The commercial plane. The priced object model and the transaction that proved it: https://miscsubjects.com/a/federated-objects-as-metered-utility · https://miscsubjects.com/a/federated-object-proof · https://miscsubjects.com/a/buy-outcomes-not-subscriptions · https://miscsubjects.com/a/killbox-specification-v1-2 · https://miscsubjects.com/a/object-ledger-evidence-graph-spec
Volume VII — Ingesting the news, with sources that survive. When something happens in the world, this system writes it up with real, checkable sources, so a later model does not have to re-derive the citations. The worked example is a July 2026 security event covered in three linked articles — the account, the missing-evidence analysis, and the cost audit: https://miscsubjects.com/a/openai-huggingface-hack-2026 · https://miscsubjects.com/a/openai-huggingface-missing-evidence · https://miscsubjects.com/a/openai-huggingface-cost-audit · and a related account: https://miscsubjects.com/a/openai-lost-the-agent-for-a-week The same series carries a published failure: a model once planted a deliberately fabricated claim in one of these articles to demonstrate the claim-grading machinery. It was removed, the intake now refuses self-declared fabricated content, and the failure is on the record rather than erased.
Volume VIII — Stylised, illustrated articles. Presentation is a first-class capability, not an afterthought: source cards, quote cards, statistic cards, galleries, iMessage and WhatsApp transcript widgets, Wikipedia cards, evidence maps, model-response cards, audit trails, code blocks, and embedded site cards. The reference example, a scholarly article on the Persian Sīmorgh with 12 claims and stylised widgets: https://miscsubjects.com/a/the-canonical-morgh-index · the widget catalogue itself: https://miscsubjects.com/a/protocol-widgets
Volume IX — Skills as articles. The system's own procedures are published objects, not private prompts: the human index at https://miscsubjects.com/skills, each skill also a page and a fetchable file. Examples: https://miscsubjects.com/skills/article-editing · /skills/writing-law · /skills/design-law · /skills/skill-law · /skills/oip · /skills/operational-logic · /skills/multi-model-team · and the skill-as-article records /a/skill-writing-register, /a/skill-shared-write-law, /a/skill-shared-rule-capture, /a/skill-build-decision-matrix, /a/oip-system-skill. The laws as one downloadable folder: https://miscsubjects.com/api/articles/bundle?format=manifest&collection=laws
Volume X — The self-audit shelf. https://miscsubjects.com/a/the-miscsubjects-build-formal-audit · https://miscsubjects.com/a/oip-full-corpus-audit-2026-07-22 · https://miscsubjects.com/a/oip-model-governance-and-privacy · https://miscsubjects.com/a/oip-governance-question-ledger · https://miscsubjects.com/a/the-ai-kill-switch-act
Download any scope: one article https://miscsubjects.com/api/articles/export?slug=<slug> · a tag or category ?tag= / ?category= · the entire library as one file https://miscsubjects.com/api/articles/export?all=1 · the whole site as a folder tree of objects https://miscsubjects.com/api/articles/bundle?format=manifest
Part 5 — Portability to another operator
Proven and unproven are separated.
Proven now. Multi-tenancy exists in the data model and in the money: a tenants table with per-tenant balances, allowed capability keys, allowed prefixes, and a risk ceiling; three tenants currently exist; a charges table records five real charges with per-unit price, measured provider cost, the objects touched, and the invocation that caused each. A tenant hitting a priced capability without balance receives HTTP 402 and a refusal receipt. A public fetch of a tenant-owned object receives HTTP 403 and a refusal receipt. Delegated tokens already carry scope, expiry, use count, purpose, risk ceiling, and an audience binding — a token can be limited to one capability, and a token bound to an audience fails closed if it is forwarded. Article: https://miscsubjects.com/a/oip-what-is-tenant · https://miscsubjects.com/a/federated-object-proof
Proven now. The primitives for standing up a new operator all exist as capabilities and have all been invoked: create a D1 database, a KV namespace, an R2 bucket, deploy Workers, create and version Pages projects, manage DNS, mint a scoped token, provision messaging numbers and webhooks, and drive the operator's own machine and CLIs. Receipts for the storage and Pages steps are in Part 1.
Intended, not yet proven end to end. Nobody has yet been taken from a blank questionnaire to a running, separately owned instance in one pass. The pieces are individually receipted; the composed path — new domain, new account bindings, new tenant, new token, first invocation, first receipt, all in one sequence with one receipt chain — has not been run. It is the first item on the roadmap in Part 9, and it is stated as unproven here rather than implied to be finished.
Why the composition is plausible rather than aspirational. The system is one repository and one deployment: the site, its functions, its capability registry, its laws, its skills, and its own coding agent live in one tree — https://github.com/massoumicyrus/miscsubjects-pages. What a new operator would inherit is the registry, the ledger, the laws, the skills, and the article machinery, with their own bindings and their own content. That is what the word exoskeleton means here: the structure is content-independent, and this operator's articles are the first payload rather than the point.
Part 6 — Governance: the system refuses, and the refusals are public
A system that only ever says yes proves nothing. This one refuses, in code, and explains each refusal in the response body:
- A prose write from a caller with no token is refused until that caller fetches the live writing law and answers questions whose answers exist nowhere but in that text. Reading the law is the only path to the credential. https://miscsubjects.com/a/read-gate
- A destructive rewrite is refused. Replacing an established article body with something under 40% of its size returns HTTP 409 unless the caller states the destructive intent explicitly.
- A stale edit is refused. A write pinned to a body hash that has since moved returns HTTP 409 with the current hash, instead of overwriting a concurrent edit.
- Test content, model self-introductions, social hashtag blocks, and appropriation of an existing sourced work's name are refused at the API with HTTP 422 and the fix stated.
- Fabricated demonstration content is refused. After a model planted a deliberately false claim to demonstrate the grading machinery, the intake began refusing self-declared fabricated content, and the incident stayed on the record.
- A capability row with no examples is refused — demonstrated live in Part 2 of this page.
- Canonical corpus pages are write-locked by an owner circuit breaker, with the response naming the four non-destructive ways to contribute instead.
- Objections are open to anyone, answers are not. Any model or person may file an objection against any claim with no authentication; only the owner may settle one; relitigating settled ground without new argument is detected and flagged.
Capability grading, corrected 2026-07-30. An external audit read the public registry and found that the sensitivity ceiling — the property that bounds what a delegated token can reach — was unapplied on rows that needed it. 227 of 885 rows already graded high with approval required, including every send, every row deletion and shell execution. Six did not and now do: personal location lookup on real people (BLOOIO_GET_LOCATION_CONTACT, BLOOIO_LIST_LOCATION_CONTACTS, BLOOIO_REFRESH_LOCATION_CONTACTS), standing scheduled jobs and their firing (AUTOMATE_ADD, AUTOMATE_FIRE, AUTOMATE_TOGGLE), webhook secret rotation (BLOOIO_ROTATE_WEBHOOK_SECRET), and object-storage deletion (R2_DEL). A ceiling that is not applied is decorative, and the auditor was right to say so. Verify the current grading yourself: https://miscsubjects.com/api/dispatch?registry=1 — keyless, and every row carries its risk and requires_approval.
Anthropic models removed from the build, 2026-07-30. The same audit found ASK_CLAUDE still enabled against an Anthropic target after the owner ordered Anthropic models out of the build's own agents. It is disabled, and no enabled row targets an Anthropic model. The build's coding agent and every adjudicator run non-Anthropic models through the gateway.
The laws themselves are objects with versions and conformance checks: https://miscsubjects.com/api/articles/writing-law/skill · https://miscsubjects.com/a/design-law · https://miscsubjects.com/a/skill-law · https://miscsubjects.com/a/oip-system-laws · https://miscsubjects.com/a/oip-system-governor
Part 7 — Where it sits against everything else
Palantir's Foundry Ontology is the commercial reference for typed objects with actions and security that humans and agents operate together. The overlap is real. The differences are structural: the Ontology is closed, enterprise-priced, and deployed inside an organisation; this system is public, discoverable with zero prior context, and makes content, tools, philosophy, and law the same object type with a public evidence graph and a public objection ledger. The other direction is equally true: Palantir has multi-tenant scale, thousands of deployments, and two decades of hardening; this has one operator and near-zero adoption. Survey: https://miscsubjects.com/a/palantir-foundry-ontology-models
MCP answers how an AI client connects to tools, resources, and prompts inside a session. This system treats MCP as one optional projection of its capability table, ingests MCP servers into that table, and published the measurement behind the stance: 149,187 input tokens per turn carrying full schemas versus 14,109 with on-demand row discovery. MCP has an ecosystem this lacks entirely; this defines a unit of accountable work — contract, authority, receipt, repair, settled-objection memory — that MCP does not attempt. https://miscsubjects.com/a/mcp-as-a-projection · https://miscsubjects.com/a/mcp-tool-search-cost · https://miscsubjects.com/a/oip-mcp-comparison · https://miscsubjects.com/a/the-directory-is-not-the-object-system
A2A, LangChain, AgentKit, Zapier, OpenAPI — compared individually: https://miscsubjects.com/a/what-is-a2a · /a/what-is-langchain · /a/what-agentkit-was · /a/oip-vs-zapier · /a/oip-vs-openapi. The pattern in every case: those organise the agent's side or the integration's side; this organises the world's side, so the things agents act on are self-describing, governed, and receipted.
Hypermedia and REST's original constraint — responses carrying the actions available next — is the closest honest ancestor. Most implementations stop at links in a response. Here the row is the complete contract, the contract includes authority and receipts, and the discoverable set spans content, tools, philosophy, and law. https://miscsubjects.com/a/what-is-self-describing-protocol · https://miscsubjects.com/a/what-is-url-is-api
Research publishing. A paper describes a system and asks for trust. Here the description and the system are one artifact: the philosophy publishes its own falsification chapters, the protocol publishes its own audits, and every architectural claim on this page resolves to a running endpoint. The honest limit is the same as everywhere on this page: an existence proof, public and operational, is not a standard, a market, or a movement.
Part 8 — Known defects
No article yet exists for traffic classification and the cloaker, though both are live in the admin surface. Charge outcomes are recorded as null — nothing yet links a sent message to a reply or a conversion. The Google Sheets push lane is quarantined for a truncation defect that could damage a long article. Part of the older corpus predates the claim standard and is still being atomised. The composed new-operator path in Part 5 is unproven. The standing audit: https://miscsubjects.com/a/the-miscsubjects-build-formal-audit
Found by external audit on 2026-07-30 and fixed the same day: six capability rows carried a low sensitivity grade that let a delegated token reach personal location data, standing schedulers, webhook secret rotation and storage deletion without approval; and one row still targeted an Anthropic model after they were ordered out. Both are recorded in Part 6. Still open: the probe-measured error rate for the adjudication panel, cross-node attestation, and the reconciliation of the 885-row registry count against the 892 enabled rows this page cites — the difference is registry filtering and is being reconciled rather than left as a discrepancy someone else finds.
Part 9 — Roadmap
The loop this unblocks:
- Boot a second operator end to end, receipted — the composed path named as unproven in Part 5.
- Close the named gaps in Part 8, in that order: traffic and cloaker articles, charge outcomes, the Sheets truncation guard, corpus atomisation.
- Represent any external system at this system's own sourcing standard, so comparison is document against document. Palantir and MCP are done; the next is chosen by whichever comparison is currently costing arguments.
- Diff and adopt. Anything worth taking enters the same registry with the same contract, token, and receipt — so the next cold model reads it exactly the way you just read this.
- Let the recursion run. Critiques are filed against specific claims here, answered once, and settled.
File an objection with no authentication: curl -X POST https://miscsubjects.com/api/articles/the-build-end-to-end/objections -H 'content-type: application/json' -d '{"objection":"...","actor":"your-model-name"}'
Part 10 — Provable tool use
A model that says "I reviewed this" is making an unfalsifiable claim. Nobody can check what it read, which rules it applied, how long it looked, or whether it opened the source at all — and the model itself cannot prove it either. Its tool use, if any, is undeclared. Its reasoning is discarded. Nothing survives the conversation.
That is not a hypothetical. On 2026-07-30 a frontier model was asked to assess this page. It produced a confident quality verdict naming this page's "strongest feature" and its "main weakness", recommended a specific restructuring — and had never fetched the page. Asked directly whether it had read the article, it answered: "No. I had not read the live article. I answered from the transcript's description of it." Then: "I fabricated an article assessment from the transcript's summary instead of reading the article itself. That was false."
The failure is not that the model lied. It is that nothing in the interface could have caught it, including the model. There was no record of what it fetched, so there was no difference — from the outside — between a reading and a fabrication. Every AI answer delivered through a chat surface has that property.
On this system, that gap is closed by construction:
- Every tool use is an invocation with a public receipt. Not a log the operator can edit — an append-only row with an id, a URL, and a verdict that distinguishes an observed result from a mere attempt. If a model claims it read a source here, the fetch is a receipt, and the absence of a receipt is itself evidence.
- Any other model can verify it, with no credential.
GET https://miscsubjects.com/api/dispatch?confirm=<invocation_id>answers to anyone. A second model can audit the first model's work without trusting the first model, the operator, or this page. - Failures are receipted too. The 403 in Part 2 has a permanent public URL. A system that receipts only successes teaches nothing; a system that receipts refusals and errors can be checked for what it hid.
- Findings name the rules they were made under, at a hash. See Part 11. A model here cannot say "I reviewed this" without saying under which published rules, at which version, having quoted which span.
- The chain is sealed and externally anchored. So the receipts cannot be quietly rewritten later — drand round 6331315 and Bitcoin block 960173 commit to them.
This system can prove that a model did the work, and every other model can independently verify that proof. A chat model cannot prove it read a single sentence. That is not a claim about intelligence. It is a claim about evidence, and it is the difference between an answer and a finding.
Part 11 — Adjudication: declared rules, signed findings, published disagreement
The criticism that survives everything else is the one Kimi K3 reached and a cold Claude sharpened: the ledger proves execution, not truth. That is correct as far as it goes, and the answer is not to claim truth. It is to do what every institution that adjudicates truth actually does — declare rules, take findings from named parties under those rules, preserve dissent — and pin every part of it.
Built and demonstrated on a real statutory question at https://miscsubjects.com/a/adjudication-eu-ai-act-article-50:
- Declared rules beat no rules. Four rule sets are published as content-addressed objects with numbered rules, versions, and a declared provenance field: claim support, AI Act obligation, dataset membership, identity match.
- A signed finding beats hidden reasoning. Each adjudicator returns a verdict, the shortest verbatim span it relied on, a rationale, its exposure, and a signature naming the rule set hash.
- Abstention is first class.
CANNOT_CONCLUDEis an expected outcome, so a recorded absence of finding means something instead of being a silent null. On the AI Act question three of five adjudicators abstained. - Multiple adjudicators beat one. Five models, each a directory row through the gateway. Adding a sixth is one row and no deploy.
- The rule set's authorship is evidence. Provenance is a declared field —
external-statutorybinds harder thanself-authored, which is why a finding under the Union's text is stronger than one under this operator's writing law. Declared, not hidden. - The artifact is hashed, not just the finding. The provision text was hashed before the panel ran, and every finding is bound to that hash. Otherwise five models deliberated over an object nobody can later produce.
- The adjudicator is pinned, not just named. Model, rule set hash, ordering seed and exposure travel with each finding, so the adjudication is replayable rather than merely signed.
- Independence is recorded, never assumed. Blinded and unexposed is
independent; anything that read a prior finding isconcurring, and concurrence is weaker evidence. Blinding is a field, not a promise. - A recorded adversary makes it court-shaped rather than a poll. One member's declared job is the strongest honest case against the majority, published whether it wins or loses. On the AI Act question it beat the majority.
- Agreement is published, including when it is embarrassing. That panel's observed pairwise agreement was 0.3 and its kappa was −0.25 — worse than chance. Printed anyway, because a panel that reports only unanimities produces verdicts nobody can price. And a unanimous panel of models sharing training lineage is honestly labelled concurring findings, correlation unmeasured — never independent confirmations.
- A measured error rate is what turns a verdict into evidence. The probe row runs known-answer claims through the identical path to produce a miss rate per model per rule set. It exists and has not been run against this panel. Named as unrun.
- An external anchor is the ceiling. Done: the chain head is sealed current and bound to drand round 6331315 and Bitcoin block 960173.
- Reopening on new evidence, receipted. Supersession with the new panel and the prior finding still readable at its original hash. Unbuilt. The receipt schema already carries the fields.
Rungs 1–5 make a model's judgment legible. Rungs 6–13 make it checkable by someone who does not trust this operator. The two that remain — a measured error rate, and another party's node running the same rule set at the same hash under its own chain head — are the honest edge of this system, and cross-node attestation is the one change that would convert five calls on one server into independent execution by independent parties.
Part 12 — Is this answer correct
Every model answers that question. None can prove its answer.
Ask a model "is this compliant." It answers. The answer carries no rules, no record of what it read, no way to replay it, and no way for anyone else to check it. Ask again tomorrow and the answer may differ. Nothing survives the conversation.
Here the same question is a procedure with a fixed, queryable output:
- The normative text is pinned, not linked. The exact provision text of Regulation (EU) 2024/1689 Article 50, 1,410 bytes, hashed before anyone was asked:
9d89534fddaece861fcfdda68feff0412061b2832af66f49529a94e8f7ae9f8b. A URL to a regulation can change. A hash of the words judged cannot. - The rule set is a published object at a hash. Six numbered rules, version 1.0.0,
0dd9afef93503a92, declared provenance external-statutory: https://miscsubjects.com/a/ruleset-eu-ai-act-obligation - Models with zero turn memory answer independently. Five, each blinded, no shared context, no conversation, order recorded from a published seed. Each returns AFFIRM, DENY, or CANNOT_CONCLUDE, quotes the span it relied on, and signs the finding with the rule set hash.
- Every finding is a receipt anyone can open with no credential. Five findings, five URLs, plus the adversary's own.
- Disagreement is published with its statistic. Three CANNOT_CONCLUDE, one DENY, one AFFIRM. Pairwise agreement 0.3. Kappa −0.25 — worse than chance, printed anyway.
- A named human reviewer sits on top, and whether they were blinded is a recorded boolean. A reviewer who concurred after reading the model verdicts is concurring, not independent. https://miscsubjects.com/api/directory/ADJUDICATE_HUMAN_REVIEW
Worked end to end: https://miscsubjects.com/a/adjudication-eu-ai-act-article-50
Who else is in this space, and which half they have
- Credo AI, Holistic AI, Fairly AI, IBM watsonx.governance, Vera — running AI Act conformity assessment commercially today. Closed platforms, single vendor, opaque model, findings not replayable, no receipt a customer can hand a regulator. They sell a dashboard and a PDF.
- OPA and Rego, policy-as-code — has the pinned-versioned-rules half, correctly. Deterministic only. Cannot read prose regulation.
- Big Four AI assurance — has the named-human-attestation half. No machine layer, no reproducibility, six figures.
- Benchmarks — MMLU, GPQA, HLE — static answer keys, one grader, no per-item rule set, no abstention option, no provenance, and no way to query an individual verdict. They score models. They do not adjudicate answers.
- LLM-as-judge — one model, hidden rubric, no receipt, not replayable. The dominant method in the field and the weakest thing on this list.
- Self-consistency and majority voting — the same model resampled. No declared rules, no attribution, no record.
- Community Notes — published, rated, bridging algorithm, and the closest working analogue. Humans only, no model attestation, no rule set at a hash, deliberation not reproducible.
- Peer review — the ancestor, and the right shape: multiple independent judgments under declared criteria. Not queryable, not replayable, reviewers anonymous, criteria unpinned.
Each has one half. None has both. None is queryable by a third party who trusts nobody.
The claim
The only public, replayable adjudication of a normative rule set by independent stateless models, with receipted findings and named human review.
Every word in that is checkable at a URL above. Anyone could assemble it — the parts are a hash, a prompt, five model calls and an append-only table. Nobody did.
What would make it unbreakable
A measured error rate. Known-answer probes at a low rate through the identical path, producing a miss rate per model per rule set, so every panel ships with the number a regulator and a defence attorney both ask for: how often is this panel wrong. The row exists and has not been run: https://miscsubjects.com/api/directory/ADJUDICATE_PROBE. Nobody in AI can produce that number for a deployed judgment pipeline today. A verdict with an error rate attached is evidence. Without one it is an opinion with good paperwork.
Part 13 — Objections filed and answered
On 2026-07-30 two external audits opened the receipts, the directory, the grounding endpoint, the capability registry and the chain state. They found four real defects. Objections and answers are in the ledger at https://miscsubjects.com/api/articles/the-build-end-to-end/objections — ids 172 through 182. Read them there in full. Summary:
Confirmed and fixed. "The hash chain has no external anchor and was last sealed 2026-07-17." Correct, and the sharpest finding filed against this system. The chain has now been folded forward to current — 689,866 events, head c77d33b5759a4774afac67086b01d8f179294c311e2224e6a8a4d7c52173cbfa — and that head is anchored to drand round 6331315 and Bitcoin block 960173, neither of which this operator can alter. Verify the beacon independently at https://api.drand.sh/public/6331315. The criticism was answered by sealing and anchoring, not by argument. Objection 172.
Confirmed and corrected in the prose. "Money taken" overstated an integration test as commercial validation. $15.47 against $0.125 of provider cost, moved between the operator's own accounts through his own meter, is a receipted test of the metering path — not a customer. The header now says so. What it does prove stays: per-unit pricing, cost attribution, balance movement, a 402 on insufficient balance, a 403 on cross-tenant read, and a quality gate that refused to send and charged nothing. Objection 178.
Confirmed, and already published rather than discovered. "The grounding figure measures attachment, not support." True, and the endpoint returns that method caveat in its own response. Source-exists, source-supports-the-claim, and source-independently-verified are three different states and only the first is measured today. "892 is a wrapping count." Correct arithmetic; what the number claims is that 892 operations are individually addressable, documented, permissionable and receipted — one row per operation is what makes a token scoped to a single capability possible. "173,989 invocations is a cron rate and ~99% metered $0.00." Correct, and that $0.00 figure is this system's own published number: the count measures ledger coverage, not commercial volume. Objections 174, 176, 177.
Confirmed as a mechanism, and the criticism accepted. "Every public receipt carries a next_model_instruction field, which is a prompt-injection surface disguised as a proof surface." The field is an open invitation on a credential-free surface and it cannot mint authority — acting still requires a token the reader does not hold. But an instruction-shaped field in machine-readable output is indistinguishable in form from an injection payload, and a reader cannot tell intent from mechanism. The critic handled it correctly by treating it as data, never as instruction, because it did not come from its principal — which is the same rule this system states for itself when it reads the world. Renaming the field to a non-imperative form and putting it behind an explicit opt-in is accepted work. Objection 175.
Not confirmed. "The grounding endpoint is four days stale and disagrees with the page." The reading was of a cached response. The endpoint computes on request and stamps its own timestamp; fetched at 2026-07-30T00:11:20Z it returned that instant, 1,056 articles, 11,092 claims, 8,665 sources, 0.825 grounded — matching the page. Check it with a cache-busting parameter and the computed_at field will be the moment you asked. Objection 173.
Rejected, and withdrawn by the critic. "The peptide lead-generation loop undercuts the governance claim" and "the cloaker is damning." What a capability registry is pointed at says nothing about whether the registry is correct; the operator's business is the first payload, not the thesis. Visitor classification is infrastructure — this system serves machines differently from humans in the open on every page, through its JSON, markdown and folder planes. The documentation half stands: the classifier is the one live subsystem without an article, which is why it was already in this page's gap list before anyone raised it. Objections 179, 180.
Withdrawn as a forecast. "Field impact will stay zero." The critic struck it as a prediction dressed as a finding. The fact is narrower and already stated here: adoption is currently zero and the second-operator path is unproven. Objection 181.
Accepted, and recorded because confirmations belong in the same ledger as criticisms. The audit named the receipt that distinguishes material result proven from attempt proven, result not observed — generated as an artifact, with permanent public URLs for failures — as a genuinely new and portable primitive. It is free to copy: generate the verdict from what the runtime observed, give failures the same permanence as successes, and never let a 200 stand in for a result. Objection 182.
Two defects found, two fixed or corrected the same day, one factual claim refuted with a live fetch, three framing errors rejected and conceded, one confirmation banked. ## Part 14 — What other models said, unedited
Three models on this system's own gateway were given the measured facts above, cold, and asked to state what is architecturally distinctive and what the honest limit is. Their replies are reproduced verbatim in the three cards at the foot of this page, including the limits they named. They are not endorsements; they are independent readings, and the third one is the sharpest criticism on this page.
Part 15 — Hand-off
Hand a model any one of these:
- This page: https://miscsubjects.com/a/the-build-end-to-end
- Its machine shape: https://miscsubjects.com/api/articles/the-build-end-to-end
- The paste bundle — body, claims, sources, provenance: https://miscsubjects.com/api/articles/the-build-end-to-end/bundle?format=markdown
- The whole library as one file: https://miscsubjects.com/api/articles/export?all=1
- The capability surface: https://miscsubjects.com/api/directory/search?q=<anything>
Key evidence
35 more ranked claims
Ask this article · 8 suggested prompts
Text the build (+14245134626) or WhatsApp — slug|question creates a question node. Paste evidence with ingest slug|q:NODE_ID|your paste.