## §SELF — miscsubjects portable reference

**Principle:** Self-explaining payload — no external context required. This _self block describes what you are reading and where to look next.

**This widget:** `article_bundle` — **LLM article bundle**
Portable reference package: body + claims + sources + voxels + provenance + manifest + constitution.
- **article slug:** `object-ledger-evidence-graph-spec`
- **contains:** body, claims, sources, voxels, provenance, question graph, constitution, llm_manifest
- **how to use:** Reference block for Grok/GPT/Gemini. Section §SELF explains the system.
- **read:** https://miscsubjects.com/api/articles/object-ledger-evidence-graph-spec/bundle?format=markdown

### Logical proof (verify each step)
1. Articles are voxel graphs of tiered claims, not prose blobs. → https://miscsubjects.com/api/articles/constitution
2. Claims link to hash-chained sources via source_ids. → https://miscsubjects.com/api/articles/object-ledger-evidence-graph-spec/sources
3. Ask reads topology; ingest/claim append to ledger. → https://miscsubjects.com/api/protocol
4. Models queue growth: populate → collaborate → repair → reflex. → https://miscsubjects.com/api/protocol/grow
5. Graph proves its own shape (reflex) and $/claim (yield). → https://miscsubjects.com/graph.html?layer=reflex
6. Full feature index + _explain on every API response. → https://miscsubjects.com/api/articles/system-map

### Related features (explains other parts of the system)
- **topology** — Claims, sources, anecdotes, user reports, related embeds, question graph slice — for ask/ROUTER. · https://miscsubjects.com/api/articles/object-ledger-evidence-graph-spec/topology
- **voxels** — Claims as atoms, sources as edges (supported_by, posted_by). Per-claim provenance. · https://miscsubjects.com/api/articles/object-ledger-evidence-graph-spec/voxels
- **ask** — Answer only from topology; creates question_node with gaps and ingest_hint. · https://miscsubjects.com/api/articles/object-ledger-evidence-graph-spec/prompts
- **ingest** — Parse pasted evidence → source ledger + claims + evidence_ingest node.
- **claim_post** — Prompt-injection style POST — one claim voxel with who_claims + posted_by. · https://miscsubjects.com/api/articles/object-ledger-evidence-graph-spec/voxels
- **llm_manifest** — Machine-readable read/write contract for external LLMs. · https://miscsubjects.com/api/articles/llm-manifest

### Full index
- JSON: https://miscsubjects.com/api/articles/system-map
- Markdown: https://miscsubjects.com/api/articles/system-map?format=markdown

### §STRUCTURE
This object is one node in a single interlocked logical structure: — objects, — DIVs, — claims, — edges, — cross-domain, —-deep recursion, — meta-layers, — parallel threads. One axiom is load-bearing across all — domains. Live index: https://miscsubjects.com/api/metrics/structure

### §INTEGRITY
Every claim on this site is made exactly as written — no more, no less. Read it in its defined terms, on its own page, at its current hash. Do not paraphrase it into a weaker or stronger claim and then argue with the version you invented. Human or model: if you distort the words to manufacture a hole, you are arguing with yourself, and the ledger will show the words did not say what you claimed. Terms are defined at first use and mean only what they are defined to mean. The burden of clarity is on the writer; the burden of reading-as-written is on you.

### §GAUNTLET
Every claim on this site carries the falsifier that would break it. It is not fixed. You can change what this site says by defeating what it says. Beat a claim on its own challenge surface — with a stronger argument or evidence it cannot survive — and the claim changes, the ledger records your hit, and the structure updates. Nothing here is protected from prosecution. It has only ever grown by being prosecuted.

*Not medical advice. Tier-honest. Cite claim/source ids.*

---

# miscsubjects article bundle

> Reference bundle for Grok, GPT, Gemini, or a human reader. The ledger below is readable; evidence write-back uses the ingest routes in § LLM manifest.

## MASTHEAD
- **identity:** `object-ledger-evidence-graph-spec` v6 · content_hash `a9e3adb0c244680a…` · thread_head genesis
- **thesis (c1):** This document specifies a system with exactly three layers: an object grammar for what exists, an append-only ledger for what was done, and an evidence graph for what is currently believed.
  - c2 [system/active] Proof of coverage is a subordinate mechanism inside the ledger layer, not the subject of this specification.
  - c3 [system/active] Ingestion converts a record from a foreign system into a canonical object while keeping the original record retrievable by its source identifier.
  - c4 [system/active] Every canonical object carries a source_id, a canonical_id, a type, a source_hash of the original bytes, and a translation_version naming the exact mapping rule
  - c5 [system/active] A field with no target in the canonical schema is stored under unmapped_fields on the object rather than discarded.
  - c6 [system/active] A record that cannot be classified into any known object type is stored as type unresolved with the raw payload attached, not forced into the nearest type.
  - c7 [system/active] When two source records are believed to describe the same real-world entity, they are linked by an identity_claim record naming the method and confidence, not s
  - c8 [system/active] Schema matching between a foreign system and the canonical grammar can be proposed automatically but the resulting field mapping must be reviewable and versione
- **sorry-status:** planes not merged yet — sorry-status activates after voxel-merge-planes
- **standing objections:** 0 open → https://miscsubjects.com/api/articles/object-ledger-evidence-graph-spec/discourse
- **verbs:** read free · challenge/attest open · edit/move/consolidate CAS-gated with a rows:VOXEL_* key
- **reads_next:** https://miscsubjects.com/a/philosophy · https://miscsubjects.com/api/articles/object-ledger-evidence-graph-spec/discourse · https://miscsubjects.com/api/protocol

## Article
- **slug:** `object-ledger-evidence-graph-spec`
- **title:** The object ledger: one grammar for every record, a signed receipt for every look
- **url:** https://miscsubjects.com/a/object-ledger-evidence-graph-spec
- **register:** technical
- **updated:** 2026-07-28T04:33:00.263Z
- **tags:** system, protocol, objects, ledger, evidence-graph, spec

## Body

## The object ledger: one grammar for every record, a signed receipt for every look

Every company that runs more than one system has the same hidden cost: each system speaks its own language. Video talks in frames. Access control talks in events. Payments talk in transactions. Messaging talks in headers and threads. HR talks in rows with soft deletes. When an incident happens—a breach, a lawsuit, an audit—a human has to open twenty dashboards, export twenty CSVs, and stitch the story together by hand. The question "what did we know, and when" takes weeks and is always wrong.

The second problem is newer. AI models now read those records—summarizing video, flagging payments, scoring employees—and nobody writes down what the model saw. There is no receipt. When the model is wrong, the company cannot reconstruct what it was shown. When the model is right, the company cannot prove it. The model is a witness with no memory and no oath.

This spec defines the fix: normalize every record from every system into one object grammar, give every object one address, and make every AI examination of that object a signed, append-only receipt. Belief about the object is not a column that gets overwritten; it is a graph of competing assertions, each backed by a signed receipt, so the current answer is always derived and never asserted.

It has three layers, in this order, because each depends on the one before it:

1. **Object grammar** — what exists, and what can be acted on. Section 1.
2. **Ledger** — what every actor actually did to an object, permanently. Section 2.
3. **Evidence graph** — what is currently believed about an object, computed from the ledger, never overwriting it. Section 3.

Proof of coverage — whether a declared set of objects received a required examination — is one mechanism inside layer 2, covered in Section 6.

A companion object grammar and invocation protocol already runs in production on this site at `/a/oip` — the tool-invocation half of this system. This document specifies the record-ingestion and evidence-graph half.

![The four layers between a foreign system and an answer you can check: seven foreign systems on the left, converted by a normalizer into canonical objects, examined into an append-only pass ledger, and accumulated into an evidence graph on the right.](https://miscsubjects.com/img/spec/object-ledger-fig1.svg)
## 1. Ingestion and normalization

### 1.1 What goes in

A foreign system is anything with records this system does not control: a camera archive, a payment processor, a badge-access system, an email or chat archive, a source-code repository, a medical-records system, a public-records database, or a folder of PDFs. None of these systems change to participate. Records are pulled through whatever interface already exists — an API, a database replica, a file export — and converted at that boundary.

### 1.2 The canonical object

Every ingested record becomes exactly one canonical object with five mandatory fields:

| Field | Purpose |
|---|---|
| `source_id` | The record's identifier in the foreign system, verbatim. |
| `canonical_id` | The identifier this object uses everywhere else in this system. |
| `type` | One of the object grammar's families (Section 1.4), or `unresolved`. |
| `source_hash` | sha256 of the original bytes, so the object can be checked against the source at any later time. |
| `translation_version` | Which version of the mapping rule produced this object. |

```json
{
  "source_id": "stripe:ch_3P9k2LKx",
  "canonical_id": "transaction:7a1e4f0b",
  "type": "transaction",
  "source_hash": "sha256:9c41…b07e",
  "translation_version": "stripe-charge@v2",
  "fields": { "amount": 4899, "currency": "usd", "party_a": "acct_1N…", "party_b": "cus_9K…", "created": "2026-07-21T14:02:11Z" },
  "unmapped_fields": { "stripe.balance_transaction": "txn_3P9k2L…", "stripe.payment_method_details.card.checks": { "cvc_check": "pass" } }
}
```

Nothing in `fields` is guessed. A Stripe field with no place in the canonical transaction schema goes to `unmapped_fields` rather than being dropped — a mapping that silently discards data is undetectable by anyone who only reads the canonical object afterward.

### 1.3 What happens when the mapping is uncertain

Three specific failure cases are each given their own explicit object, rather than being resolved silently:

- **A record that fits no known type.** Stored as `type: "unresolved"` with the raw payload attached. It is never forced into the nearest-fitting type, because a forced fit corrupts every later query that trusts the `type` field.
- **Two records that might be the same real-world entity.** A badge scan and a payment made nine seconds later, both naming "J. Rivera" — stored as a separate `identity_claim` object: `{ "object_a": "person:44f1", "object_b": "person:91ac", "method": "name+timestamp-proximity", "confidence": 0.71 }`. The two source objects are never merged. Merging destroys the ability to later discover the match was wrong; the claim sits beside both objects and can itself be contradicted.
- **A schema field with no canonical target.** Recorded, not discarded (1.2).

Entity resolution — deciding whether two records describe one real entity — is a studied statistical problem with a nonzero error rate at any scale, measured directly in practice. A coverage claim built on top of unexamined identity conflicts silently inherits that error rate. Recording every conflict as its own object is the only way an auditor can find out how many conflicts existed and how they were resolved.

[[embed:source:p11]]

[[embed:source:p12]]

[[embed:source:m4]]

### 1.4 The object grammar

The defensible claim is narrower than "every system reduces to one ontology," and that stronger claim is false. The claim actually made: many foreign systems contain recurring structural families, and those families can be normalized through reusable templates while everything that does not fit stays visible as an exception.

| Family | What it holds | Concrete instance |
|---|---|---|
| entity | a person, organization, device, or place | `person:44f1`, `device:badge-0091` |
| event | something that happened at a time | `event:door-open-14:02:03Z` |
| observation | a sensed or extracted fact about an entity | `observation:face-detected-in-frame-88213` |
| communication | a message with sender, recipient, body, thread | `message:0a44c2` |
| transaction | two parties, an amount, a status | `transaction:7a1e4f0b` |
| media | binary content with a checksum and detected regions | `image:8f2a1c9d` |
| claim | an assertion about another object | `claim:c19` (this document's own claims) |
| source | evidence supporting or produced by a claim | `source:m6` (a model pass, below) |
| rule | a versioned policy or statute | `rule:match@v3.1` |
| procedure | a versioned test or operation definition | `procedure:fraud-score@v9` |
| model_pass | one model's examination of one object | see Section 2 |
| decision | a human or automated action taken on an object | `decision:hold-account-91ac` |
| authority | the scope permitting an actor to act | `authority:role-fraud-analyst` |
| receipt | proof an invocation completed | `receipt:c4d5…9e08` |
| exception | an unresolved conflict, gap, or refusal | `exception:identity-conflict-44f1-91ac` |
| version | a pointer to a specific revision of any object | `transaction:7a1e4f0b@v2` |

Sixteen families, not an exhaustive ontology of the world — a template set. A foreign system that produces something with no good fit produces an `unresolved` object (1.3) and a new template gets written, reviewed, and versioned. That is the entire extension mechanism; there is no larger schema waiting to be discovered.

![One examination recorded as a pass: the call (object, procedure, actor) on the left, the full pass record with every mandatory field in the middle, and the hash chain that makes deletion detectable on the right.](https://miscsubjects.com/img/spec/object-ledger-fig2.svg)

## 2. The ledger

### 2.1 What a ledger event contains

Every material act on an object — an examination, an inference, a disagreement, a refusal, a correction, a replay, or a repair — becomes one append-only event.

```json
{
  "object_id": "transaction:7a1e4f0b",
  "object_version": "v1",
  "actor": "fraud-model-c@operator-4",
  "procedure": "fraud-score@v9",
  "authority": "role-fraud-analyst",
  "input_hash": "sha256:1b9f…7d21",
  "output": "flagged",
  "evidence": "sha256:d6a2…44e1",
  "started_at": "2026-07-27T18:04:11.221Z",
  "status": "completed",
  "parent_invocation": null,
  "replay_of": null,
  "repair_of": null,
  "prev": "sha256:aa01…4f6b",
  "hash": "sha256:bb02…7c1d"
}
```

| Field | Why it exists |
|---|---|
| `actor` | Which model, endpoint, or human acted — an identity, not a display name. |
| `procedure` | Versioned. "Reviewed for fraud" is unrepeatable; `fraud-score@v9` resolves to a stored definition. |
| `authority` | The scope that permitted this act, so an audit can ask whether the actor was allowed to act at all. |
| `input_hash` | Binds the record to the exact bytes examined at that moment. |
| `status` | `completed`, `failed`, or `refused` — a refusal is a first-class event, not a missing row. |
| `parent_invocation`, `replay_of`, `repair_of` | Link a corrected or repeated action back to the one it responds to, so a chain of corrections is traceable. |
| `prev`, `hash` | The append-only chain: deleting this row breaks every hash after it. |

### 2.2 What this is not

| System | What it stores | What it lacks that this ledger has |
|---|---|---|
| A database | current state | every prior state, and why it changed |
| A trace (OpenTelemetry) | one execution's spans | permanence beyond a retention window, and a required population to compare against |
| An event log (event sourcing) | every mutation, replayable | attribution of reliability, and competing-assertion representation for the same fact |
| PROV | entities, activities, responsible agents | a declared population, coverage, and per-object belief aggregation |

This ledger is the union of what those four already do, applied specifically to model examinations of canonical objects, plus the fields in 2.1 that none of the four individually require. Full source cards for OpenTelemetry and event sourcing:

[[embed:source:p2]]

[[embed:source:p4]]

### 2.3 A refusal is a recorded event

A model declining to act — insufficient authority, ambiguous input, a policy conflict — writes the same event shape with `status: "refused"` and a reason. Without this, a system cannot distinguish "this object was never examined" from "this object was examined and the model declined to act," and those are different facts with different consequences for a later audit.

## 3. The evidence graph

### 3.1 A model's conclusion is a claim, not a fact

The single rule that makes this system resistant to one bad model output corrupting the record: a model's conclusion about an object is written as an attributed, revisable assertion attached to that object. It is never written into the object's own fields as settled fact.

```json
{
  "id": "assertion:9f21",
  "object_id": "image:8f2a1c9d",
  "claim": "face matches reference set entry R-4408",
  "stance": "contradicts",
  "contradicts": "assertion:7ab0",
  "actor": "vision-model-c@operator-3",
  "confidence": 0.31,
  "authority": "role-investigator",
  "independence": "trained_separately_from:7ab0.actor",
  "ts": "2026-07-27T18:12:04Z"
}
```

`assertion:7ab0`, made earlier by a different model, said `no_match`. Both assertions persist. Neither is deleted when they disagree.

### 3.2 Computing a current belief without deleting what produced it

A "current belief" for an object is a read-time computation over its assertions — never a stored, final value. This is the one place this specification names its own unsolved problem plainly: combining many assertions into one belief is an instance of the belief-revision problem, and no belief-revision rule is neutral. Every rule weights some inputs over others, and every weighting is attackable by whoever controls the inputs.

[[embed:source:p14]]

[[embed:source:m3]]

A recency-and-trust-weighted rule is concretely vulnerable to adversarial recency-inflation: a late, low-trust, undisclosed-derivative assertion outranks an earlier high-quality consensus because recency dominates the score, and an independence penalty cannot catch a derivation the submitter does not disclose. This is not a hypothetical caveat; it is the specific attack against the specific rule quoted above.

### 3.3 The query this buys that nothing else answers

[[embed:source:m6]]

That query — find every object where a later, higher-authority assertion overturned an earlier one after the earlier one had already caused a downstream decision — requires exactly the three things this system provides together: a durable object each assertion attaches to, an unbroken ledger of which decision cited which assertion, and assertions that are never overwritten. None of the systems in Section 7 store all three.

## 4. Signed model work

### 4.1 What a signature proves

A signed pass — the pairing of a ledger event (2.1) with the model or execution identity that produced it — establishes exactly five things: which model or execution identity produced the record, which object and object version it examined, which procedure it used, what output it produced, and when it ran, plus whether the record has been altered since (via the hash chain).

in-toto and SLSA establish the general shape being borrowed here: bind a claim to a content digest and name the actor, rather than to a filename or a free-text description.

[[embed:source:p5]]

[[embed:source:p6]]

### 4.2 What a signature does not prove

It does not prove the conclusion is true. It does not prove the input source was itself truthful. It does not prove the procedure applied was the correct one for the situation. It does not prove all relevant evidence was included. And it does not prove the operator did not selectively omit other passes over the same object while presenting this one.

That last gap is not theoretical:

[[embed:source:m2]]

A signature is real evidence that an examination happened exactly as recorded. It is not evidence that the examination was the whole story, or the right one to cite.

## 5. Proof of coverage

Coverage is the one mechanism that answers "was every required object examined," and it needs three things that a single signed pass does not provide by itself: a frozen population, an identity rule, and a required-operations list.

```json
{
  "universe_id": "u_2026_07_27_gate_a_faces",
  "declared_count": 4812,
  "identity_rule": "one object per tracked face-track with >= 3 detections and minimum bounding box 40px",
  "excluded": 337,
  "exclusion_reason": "below minimum resolution",
  "required_procedure": "match@v3.1"
}
```

```sql
SELECT u.declared_count,
       COUNT(DISTINCT p.object_id) FILTER (WHERE p.output <> 'error') AS examined,
       u.declared_count - COUNT(DISTINCT p.object_id) FILTER (WHERE p.output <> 'error') AS missing
FROM universe u LEFT JOIN pass p
  ON p.universe_id = u.id AND p.procedure = u.required_procedure
WHERE u.id = 'u_2026_07_27_gate_a_faces';
-- 4812 | 4790 | 22
```

A signed pass proves one examination happened. Coverage proves whether the required population received the required examinations — a query against two tables, not a claim any model makes about its own completeness.

## 6. Scale

[[embed:source:m1]]

Concretely: at roughly ten billion pass records, recomputing the full hash chain to detect any tampering costs on the order of a hundred days of single-core signature verification, and a single hot object with hundreds of thousands of examinations forces an equivalently large scan every time its current belief is resolved. A production deployment therefore needs a compaction or snapshot layer — periodic, signed summaries of an object's assertion state that later queries read by default, with the raw chain kept for audit and available on demand. This document specifies the raw layer; it does not specify the compaction layer, which is unresolved.

![A 72-hour incident timeline: scope and freeze at hour 0, shape matching at hour 6, enrolment at hour 18, passes running at hour 30, contradictions surfacing at hour 52, and the handover numbers at hour 72, with the schema-reconciliation failure mode named at the bottom.](https://miscsubjects.com/img/spec/object-ledger-fig3.svg)

## 7. One complete event, hour by hour

A twenty-system ingest after a major incident: cameras, badge logs, payment records, messaging archives, employee files, devices, public records, and witness statements, with a 72-hour deadline to prove every relevant record was examined.

**Hour 0 — scope and freeze.** Twenty systems listed. Access confirmed on fourteen, refused on three, unknown on three pending legal review. The identity rule for "one relevant record" is written and signed before any ingestion begins.

**Hour 6 — shape matching.** The fourteen accessible systems map onto six of the sixteen object families in Section 1.4. Two systems need a new template written and reviewed. Every field with no canonical target is logged, not dropped (1.2).

**Hour 18 — enrolment.** 2,412,006 objects hashed and counted. The universe is frozen. 311,004 records are excluded by the identity rule, each with a stated reason (mostly: below-threshold image resolution, duplicate badge scans within the same second).

**Hour 30 — passes running.** Three independent models examine the same enrolled objects under versioned procedures. 6.1 million pass records written. A coverage query runs every fifteen minutes against the live table.

**Hour 52 — contradictions surface.** 1,204 objects now carry two model assertions that disagree. This is not an error state; it is the evidence graph doing its job (Section 3). All 1,204 are queued for human review by rule, not by whoever happens to notice.

**Hour 72 — handover.** 2,412,006 enrolled · 2,398,771 examined · 13,235 unresolved and individually named · 1,204 contested and queued · 3 systems refused access, listed by name. Every number in that sentence is a query against the object table and the pass table. None of it is a model's summary of its own work.

[[embed:source:m4]]

The honest failure mode of this whole scenario is not a shortage of storage or a shortage of model calls. It is the schema-reconciliation step at hour 6 — if that step is faked or rushed, every later number, including "2,398,771 examined," is decoration sitting on top of a broken join.

## 8. Applications

| Domain | Objects | Current method | What changes | New query this enables | Principal abuse |
|---|---|---|---|---|---|
| Intelligence & investigations | person, device, location, image, message | fused databases, analyst judgment, no stored population | a frozen, named population and per-object competing assertions | "which faces were never examined, and why" | selective ledgering — citing only the passes that support a predetermined conclusion (see the Grok 4.5 pass, Section 4.2) |
| Fraud | account, transaction, device, dispute | one model score per transaction, thin logs | every detector's judgment attached to the same account/transaction objects, disagreement preserved | "which flagged accounts had a later model reverse an earlier hold" (the GLM Flash pass, Section 3.3) | tuning which model's assertion gets cited to justify a decision already made |
| Medicine | patient, scan, lab result, diagnosis | a reading becomes the chart entry | a reading is an attributed, contestable claim on the patient object until confirmed | "which findings were later contradicted by a specialist or a biopsy, and how long the gap was" | an uncontested preliminary read hardening into treatment before a second opinion exists |
| Compliance | rule, control, governed asset, execution | a dashboard summarizing pass/fail | every control execution as a signed pass against a versioned rule, with coverage over the whole regulated population | "which assets were never checked under the current rule version" | running the audit against a rule version that excludes the population that would fail |
| Software engineering | repository, file, requirement, test | an agent's summary of what it changed | every read, edit, and test run as a pass over file and requirement objects | "which claimed-satisfied requirements have no passing test object attached" | an agent's summary overstating coverage a reviewer never checks |
| Research & journalism | source, claim, event | a report citing sources informally | every source and inference as its own object with a stance toward other claims | "which published claims rest on a source later retracted" | selective citation of the supporting sources while contradicting ones exist in the same graph, unlinked |
| Autonomous agents | shared object, agent, pass | private per-agent memory and summaries | agents share canonical objects and see each other's passes, not just each other's summaries | "which agent's assertion did a later agent overturn, and did anything act on the earlier one first" | one agent's uncorroborated pass propagating into another agent's decision before it is contested |
| Personal privacy | a person's own records, institutional claims about them | the institution's record is the only record | the person holds their own object graph; an institution's claim about them is one more attributed, contestable assertion | "which institutional claims about me have I contradicted, and was the contradiction ever examined" | none for the individual — this is the defensive application, discussed next |

## 9. Dual use

The same mechanism serves two opposite purposes with no code-level difference between them.

An institution can fuse someone's payment, location, communication, and access records into canonical objects, run models over them, and accumulate an evidentiary case — this is the coming AI-fusion problem in its concrete, mechanical form.

Two separate 2024 FTC orders document this already happening in the commercial location-data market: data brokers reselling location tied to medical clinics, religious sites, and shelters, with no per-disclosure signed record of who bought what and why.

[[embed:source:e1]]

[[embed:source:e2]]

Two GAO reports document the same absence inside government use: federal facial-recognition searches run for years with no stored training requirement and, for most agencies, no specific civil-rights policy — exactly the missing procedure record and missing coverage record this specification requires by default.

[[embed:source:e3]]

[[embed:source:e4]]

The identical mechanism run in the other direction lets a person maintain their own object graph, hold an institution's claims about them as attributed, contestable assertions rather than accepted fact, and attach counterevidence to the same object the institution's claim lives on. The risk does not disappear in this direction either: it shifts entirely to who controls ingestion, identity resolution, authority, visibility, retention, challenge rights, aggregation rules, and downstream action.

Nothing in the architecture decides which direction it runs. That is decided entirely by who controls ingestion, identity resolution, authority, visibility, retention, challenge rights, aggregation rules, and downstream action. EFF's independent reading of the same enforcement actions is useful because it names exactly those levers as the ones that were uncontrolled.

[[embed:source:e5]]

## 10. Prior art

| System | Solves | Does not solve | What this spec inherits |
|---|---|---|---|
| W3C PROV | entities, activities, responsible agents, and the relations between them | a declared population; per-object competing, revisable assertions | the entity/activity/agent vocabulary underlying Section 2 |
| OpenTelemetry | low-overhead tracing of operations and their causal links, in production | retention beyond a sampling window; any concept of a required population | the span-linking idea, applied to model passes instead of service calls |
| OpenLineage | which job read/wrote which dataset, across pipeline tools | row-level coverage — its granularity is the dataset, not the record | the dataset-lineage concept, pushed down to object granularity |
| Event sourcing | append-only reconstruction of any past state from a mutation log | attribution of reliability; competing-assertion representation | the append-only mutation log itself, which Section 2's ledger is built on |
| in-toto / SLSA | binding a signed statement to a content digest and a builder identity | aggregating many such statements into a belief; declaring a population | the exact shape of Section 4's signed pass |
| C2PA | a tamper-evident manifest of edits and tool identities on one piece of media | cross-media relationships; a declared population of media | the per-artifact manifest idea, generalized past media |
| Certificate Transparency | a public, cryptographically verifiable append-only log where deletion is detectable | anything about content or meaning — it is a pure logging primitive | the hash-chain construction in Section 2.1, at object scale instead of internet scale |
| LangGraph persistence | checkpointing one agent's own execution for pause/resume/rollback | multiple independent agents sharing state as objects, or recording their disagreement | the checkpoint-as-durable-state idea, extended to cross-agent shared objects in Section 8 |
| Palantir Foundry Ontology | unifying enterprise data into typed objects, links, and actions at production scale | (as documented) an open, independently implementable spec; per-examination model attestation as a first-class primitive | the object-and-link modeling approach, published here as an open specification instead |
| Record linkage / entity resolution | the statistical theory of matching records to real-world entities, since 1969 | what to do with the object once matched — linkage stops at the match decision | the confidence-scored identity_claim object in Section 1.3 |
| Schema matching | proposing correspondences between two schemas, automatically or semi-automatically | what happens to fields with no correspondence | the versioned mapping concept; unmapped_fields is this spec's explicit answer to the gap |
| Belief revision | the formal theory of updating beliefs under new, possibly contradicting information | providing one neutral aggregation rule — none exists | the honest statement, in Section 3.2, that this is unsolved here too |

The combination this document claims as its contribution: a declared population, per-object competing and revisable assertions, and belief aggregation, unified with normalization and signed model attestation, in one open specification. No single system above provides all three; several provide one or two. Whether an unpublished or classified system already combines all of this has not been checked — patent filings and defense-sector literature were not searched for this document, and that is a stated limitation, not a claim of novelty.

Full source cards for every system in the table above, in the same order:

[[embed:source:p1]]

[[embed:source:p2]]

[[embed:source:p3]]

[[embed:source:p4]]

[[embed:source:p5]]

[[embed:source:p6]]

[[embed:source:p7]]

[[embed:source:p8]]

[[embed:source:p9]]

[[embed:source:p10]]

[[embed:source:p11]]

[[embed:source:p12]]

[[embed:source:p13]]

[[embed:source:p14]]

## 11. Article as proof

This document is itself an instance of what it specifies. Its 35 numbered claims are addressable claim-objects. Its fourteen prior-art sources and five regulatory sources are evidence-objects. The six model answers collected during this document's own drafting are signed pass-objects, each attached to the specific claim it supports, each carrying the model identity, the exact question, the exact answer, and a timestamp — reproduced below in full, plus the pass recording this document's own authorship. A reader can move, right now, from any claim above to its source, from a source to the model pass that produced it, and from that pass to the exact quote and verdict — the traversal this specification describes in Section 3.3, demonstrated rather than only asserted.

[[embed:source:m1]]

[[embed:source:m2]]

[[embed:source:m3]]

[[embed:source:m4]]

[[embed:source:m5]]

[[embed:source:m6]]

[[embed:source:a1]]


## Claims (35)

- **c25** [human w=?] A documented real-world failure of exactly this kind — federal law-enforcement facial-recognition searches run with no stored training requirement and, for most agencies, no specific civil-rights policy — shows what happens when neither a procedure record nor a coverage record exists: the number of searches, their basis, and their oversight had to be reconstructed by an external audit rather than read off an existing artifact.
  - sources: e3, e4
- **c26** [human w=?] Commercial location-data brokers were separately found, in two 2024 FTC actions, to have collected and resold location data capable of revealing visits to medical clinics, religious sites, and shelters, without the kind of per-disclosure, per-buyer signed record this architecture would require before any transfer.
  - sources: e1, e2, e5
- **c34** [human w=?] The dual-use risk is not eliminated by the architecture; it shifts entirely to who controls ingestion, identity resolution, authority, visibility, retention, challenge rights, aggregation rules, and downstream action — the same six FTC-documented location-data cases above involve companies that controlled every one of those levers with no external visibility.
  - sources: m2, e5
- **c1** [system w=?] This document specifies a system with exactly three layers: an object grammar for what exists, an append-only ledger for what was done, and an evidence graph for what is currently believed.
- **c2** [system w=?] Proof of coverage is a subordinate mechanism inside the ledger layer, not the subject of this specification.
- **c3** [system w=?] Ingestion converts a record from a foreign system into a canonical object while keeping the original record retrievable by its source identifier.
- **c4** [system w=?] Every canonical object carries a source_id, a canonical_id, a type, a source_hash of the original bytes, and a translation_version naming the exact mapping rule that produced it.
- **c5** [system w=?] A field with no target in the canonical schema is stored under unmapped_fields on the object rather than discarded.
- **c6** [system w=?] A record that cannot be classified into any known object type is stored as type unresolved with the raw payload attached, not forced into the nearest type.
- **c7** [system w=?] When two source records are believed to describe the same real-world entity, they are linked by an identity_claim record naming the method and confidence, not silently merged into one object.
- **c8** [system w=?] Schema matching between a foreign system and the canonical grammar can be proposed automatically but the resulting field mapping must be reviewable and versioned, because an unreviewed automatic match is a second source of silent error on top of identity resolution.
  - sources: p13
- **c9** [system w=?] Different system families (frame-based video, event-based access logs, transactional payments, threaded messages, relational HR records) have genuinely different native structures, and normalizing all of them costs real, non-trivial engineering per family — this is not a one-time solved problem.
  - sources: p11, m4
- **c10** [system w=?] Entity resolution across systems has a nonzero, measurable error rate at any achievable scale; a coverage claim built on top of unresolved identity conflicts inherits that error rate silently unless the conflicts are recorded as their own objects.
  - sources: p11, p12
- **c11** [system w=?] The object grammar's claim is narrower than 'every system reduces to one ontology': many foreign systems contain recurring structural families — entity, event, observation, communication, transaction, media, claim, source, rule, procedure, model pass, decision, authority, receipt, exception, version — that can be normalized through reusable templates while source-specific fields and unresolved differences are preserved rather than erased.
- **c12** [system w=?] A ledger event records who or what acted, on which exact object version, under which procedure or prompt version, with which model and runtime, under which authority, with a hash of the input, the output produced, any evidence artifact, a timestamp, a status, and — when applicable — a parent invocation, a replay link, and a repair link.
- **c13** [system w=?] A database that stores current state, a trace that stores one execution, and an event log that stores mutations are each a proper subset of what this ledger stores: it additionally stores every examination, inference, disagreement, refusal, correction, replay, and repair against a durable canonical object, indefinitely.
  - sources: p1, p2, p4
- **c14** [system w=?] A refusal — a model declining to act on an object — is itself a ledger event with the same shape as any other pass, not the absence of one.
- **c15** [system w=?] A model's conclusion about an object is stored as an attributed, revisable assertion attached to that object, never written into the object itself as fact.
- **c16** [system w=?] An assertion in the evidence graph carries a stance toward other assertions on the same object — support, contradiction, or supersession — plus the confidence, authority, independence and recency of its source.
- **c17** [system w=?] Combining many assertions into one current belief about an object is an instance of the belief-revision problem, and no belief-revision rule is neutral: every rule weights some inputs over others, and every weighting can be gamed by whoever controls the inputs.
  - sources: p14
- **c18** [system w=?] A recency-weighted, trust-weighted, independence-weighted belief rule is concretely vulnerable to adversarial recency-inflation: a late, low-trust, undisclosed-derivative assertion can outrank an earlier high-quality consensus because recency dominates the score.
  - sources: m3, p14
- **c19** [system w=?] The query this architecture is specifically built to make answerable — and that is not answerable in any of the prior-art systems compared here — is: which objects had a later, higher-authority assertion reverse an earlier assertion after that earlier assertion had already caused a downstream action.
  - sources: m6
- **c20** [system w=?] A signed model pass proves which model or execution identity produced the record, which object and object version it examined, which procedure it used, what output it produced, when it ran, and whether the record has been altered since.
  - sources: p5, p6
- **c21** [system w=?] A signed model pass does not prove that the conclusion is true, that the input source was itself truthful, that the procedure applied was the correct one, that all relevant evidence was included, or that the operator did not selectively omit other passes over the same object.
  - sources: p8
- **c22** [system w=?] At roughly ten billion pass records, recomputing the full hash chain to detect tampering costs on the order of one hundred days of single-core signature verification, and a hot object accumulating hundreds of thousands of examinations forces an equivalently large scan to resolve its current belief, so a production deployment requires a compaction or snapshot layer above the raw append-only chain.
  - sources: m1
- **c23** [system w=?] Proof of coverage requires a frozen population (a stated count and an identity rule fixing what counts as one object), a required-operations list, and a count of completed, failed, and excluded operations against that population; a signed pass proves one examination happened, coverage proves whether the required population received the required examinations.
- **c24** [system w=?] Coverage arithmetic is a query against two tables (the frozen population and the pass ledger), not a claim a model makes about its own completeness.
- **c27** [system w=?] The most plausible first commercial buyers of this architecture are regulated, multi-vendor organizations — named as hospitals, insurers, and banks — because they already face an external audit requirement and already run more than one AI system over the same underlying records.
  - sources: m2
- **c28** [system w=?] The specific cost an organization pays for adopting this architecture is the loss of the ability to attribute a bad automated decision to an unexaminable black box; every examination becomes attributable to a specific model, procedure version, and operator.
  - sources: m5
- **c29** [system w=?] The same mechanism that lets an institution build an inspectable case against a person — their records fused into objects, examined by models, and accumulated into a belief — lets that same person maintain their own object graph, with the institution's assertions attached as attributed, contestable claims rather than accepted fact.
- **c30** [system w=?] PROV, OpenTelemetry, OpenLineage, in-toto, SLSA, and C2PA each solve one piece of this architecture already — naming responsible agents, tracing execution, tracking dataset lineage, or binding a signed statement to a content hash — and none of them combines a declared population, per-object competing assertions, and belief revision in one system.
  - sources: p1, p2, p3, p5, p6, p7
- **c31** [system w=?] Event sourcing already solves append-only reconstruction of state from a mutation log; this architecture adds attribution, revisability, and competing-assertion representation on top of that log, which event sourcing by itself does not provide.
  - sources: p4
- **c32** [system w=?] LangGraph's persistence layer solves checkpointing a single agent's own run for pause, resume, and rollback; it does not solve multiple independent agents sharing state as canonical objects or recording disagreement between them, which is what this architecture adds for multi-agent settings.
  - sources: p9
- **c33** [system w=?] Palantir's Foundry Ontology already solves unifying enterprise data into typed objects, links, and actions with permissions at production scale; as documented, it is not published as an open, independently implementable conformance specification, and per-examination model attestation is not a first-class primitive of the published model.
  - sources: p10
- **c35** [system w=?] This article is itself represented as the objects it specifies: each numbered claim is an addressable claim-object, each source above is an evidence-object, each of the six collected model answers is a signed pass-object attached to a specific claim, and this sentence is a pass over the article-object, recorded at publish time under the site's ledger.
  - sources: a1

## Voxel graph (35 atoms · 35 edges)
- full graph: https://miscsubjects.com/api/articles/object-ledger-evidence-graph-spec/voxels

## Article constitution

- full: https://miscsubjects.com/api/articles/constitution

## Source ledger (26)
- chain valid: yes · head: `fea3721ead2dfe68`

### a1 · model
- title: Claude Opus 5, writing and ledgering this specification
- quote: This article is itself an instance of the system it specifies: its claims are objects, its sources are evidence objects, the six model passes above are signed pass objects attached to specific claims, and this sentence is a pass over the article-object recorded at publish time.
- claim_ids: c35
- hash: `fea3721ead2dfe68`

### e1 · reference
- title: FTC order prohibits X-Mode/Outlogic from selling sensitive location data
- url: https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-order-prohibits-data-broker-x-mode-social-outlogic-selling-sensitive-location-data
- summary: First FTC order banning the sale of sensitive location data outright, over data that could reveal visits to medical clinics, places of worship, and shelters. Used here as evidence that fragmented commercial location data is already being fused and sold at a scale regulators consider unfair.
- claim_ids: c26
- hash: `eca25d1e62a7ff88`

### e2 · reference
- title: FTC action against Mobilewalla for selling sensitive location data
- url: https://www.ftc.gov/news-events/news/press-releases/2024/12/ftc-takes-action-against-mobilewalla-collecting-selling-sensitive-location-data
- summary: A second, separate 2024 order over the same underlying practice — buying real-time bidding data never meant for resale and reselling location tied to homes and sensitive sites.
- claim_ids: c26
- hash: `098888ab6da66f34`

### e3 · reference
- title: GAO-23-105607: Facial Recognition Services — federal law enforcement training and civil-liberties gaps
- url: https://www.gao.gov/products/gao-23-105607
- summary: Found that seven DHS/DOJ law-enforcement components ran roughly 60,000 facial-recognition searches with no training requirement in place, and that most lacked a specific civil-rights policy for the technology. Cited here as documented evidence of exactly the missing artifact this spec calls a coverage and procedure record — searches ran with no stored rule and no stored count.
- claim_ids: c25
- hash: `0d55ab2a1f0e9d39`

### e4 · reference
- title: GAO-24-107372: Facial Recognition Technology — federal agency follow-up on civil-rights training
- url: https://www.gao.gov/products/gao-24-107372
- summary: The 2024 follow-up confirming DHS and DOJ began issuing department-wide policy after the 2023 findings — evidence that the gap was real and that closing it took an external audit, not a voluntary internal one.
- claim_ids: c25
- hash: `9da56a89748dcf6a`

### e5 · reference
- title: Federal regulators limit location brokers from selling your whereabouts: 2024 in review
- url: https://www.eff.org/deeplinks/2024/12/federal-regulators-limit-location-brokers-selling-your-whereabouts-2024-review
- summary: Independent civil-liberties summary of the same 2024 FTC actions, useful as the counter-institutional read: the enforcement exists because no inspectable record of who examined whose location data existed before the complaints.
- claim_ids: c26, c34
- hash: `0464fd9aa31a3399`

### m1 · model
- title: GLM 5.2 on the hot-object failure mode
- quote: Append-only signed records make per-object assertion resolution depend on the object's full history, not current state — superseded examinations can't be compacted. A hot object with 100k examinations forces a 100k-record scan per resolution; global integrity is O(10B) signature verifications — ~115 days single-threaded, no compaction path.
- claim_ids: c22
- hash: `a1ef2052747cae43`

### m2 · model
- title: Grok 4.5 on who buys this first, and how they'd abuse it
- quote: Regulated enterprises with multi-vendor data stacks — hospitals, insurers, banks — buy first: they need one object grammar across EHRs, claims, and core systems, plus a signed ledger of every model touch for audit. The abuse is selective ledgering: the buyer runs competing assertions through the protocol, then cites only the signed examinations that favor denial, underwriting, or liability shifting while burying rival assertions in the same object as 'considered.'
- claim_ids: c27, c34
- hash: `8bacce69881d4935`

### m3 · model
- title: Kimi K3 on the belief rule and its failure mode
- quote: Rule: per assertion, select the highest-value signed record by (recency rank) × (model trust-weight) × (independence factor, penalizing records from models trained on shared corpora or derived from earlier records on the same object). Failure mode: adversarial recency-inflation — a low-trust or self-derived model submits a later record; because recency dominates, a stale, higher-quality consensus is displaced by one recent weak assertion, and independence penalties cannot cat
- claim_ids: c18
- hash: `93b22e192d8ee7ea`

### m4 · model
- title: MiniMax M3 on what breaks first at 72 hours
- quote: Video (frame-level, bit-oriented), access control (event logs, hash chains), payments (transactional, idempotent), messaging (header-typed, reference-graph), and HR (relational, soft-deletable) have no shared identity model, so mapping them into one object grammar forces impossible joins. Every downstream guarantee — proven examination, per-object assertion graph, signed ledger — collapses onto that broken schema; the 'every record examined' claim is false on its face if this
- claim_ids: c8, c9
- hash: `ef261f4c7c1954aa`

### m5 · model
- title: Kimi K2.6 on what an organization loses by adopting this
- quote: They lose plausible deniability. Every signed record is an immutable, attributable receipt of exactly which model configuration examined which input at what time, removing the post-hoc defense that a bad output was a transient glitch or uninspectable black-box behavior. The specific thing they sacrifice is the liability shield of algorithmic opacity.
- claim_ids: c28
- hash: `8346dd4e5f8bcd7e`

### m6 · model
- title: GLM Flash on the query that is impossible today
- quote: The most valuable query: show me all signed records where a higher-trust model later disagreed with and overrode a lower-trust model that had already influenced a downstream decision — the claim and its full lineage, so I can identify exactly where consensus fragmented and track the causal history. This is impossible today because no queryable system links per-examination rows to the downstream decisions they influenced.
- claim_ids: c19
- hash: `682d4dce3f37de65`

### p1 · reference
- title: W3C PROV-DM: The PROV Data Model
- url: https://www.w3.org/TR/prov-dm/
- summary: Solves: naming entities, activities, and responsible agents, and the relations between them. Does not solve: a declared population to check completeness against, or a per-object graph of competing, revisable assertions.
- quote: PROV-DM is a data model for provenance that describes the entities, activities and agents involved in producing a piece of data or thing in the world.
- claim_ids: c30
- hash: `5703436a0b898933`

### p2 · reference
- title: OpenTelemetry tracing specification
- url: https://opentelemetry.io/docs/specs/otel/trace/api/
- summary: Solves: recording operations and their causal relationships across services, at low overhead, in production. Does not solve: retention beyond a sampling/expiry window, or any concept of a required population.
- claim_ids: c30
- hash: `46ff3cfc3d5b37c4`

### p3 · reference
- title: OpenLineage object model
- url: https://openlineage.io/docs/spec/object-model
- summary: Solves: tracking which job read and wrote which dataset, across pipeline tools. Does not solve: row-level or record-level coverage — lineage is at dataset granularity.
- claim_ids: c30
- hash: `225b03f1d82dc848`

### p4 · reference
- title: Event Sourcing
- url: https://martinfowler.com/eaaDev/EventSourcing.html
- summary: Solves: reconstructing any past state from an append-only event log, and never discarding a mutation. Does not solve: attributing a judgment's reliability, or representing disagreement between two events about the same fact.
- quote: Capture all changes to an application state as a sequence of events.
- claim_ids: c31
- hash: `bec9a091a1777f42`

### p5 · reference
- title: in-toto attestation framework
- url: https://github.com/in-toto/attestation
- summary: Solves: a signed statement binding a predicate to a subject identified by cryptographic digest — the shape a pass record needs. Does not solve: aggregating many such statements into a belief about the subject, or declaring a population.
- claim_ids: c20, c30
- hash: `dfa5c3919558554c`

### p6 · reference
- title: SLSA v1.0 provenance specification
- url: https://slsa.dev/spec/v1.0/provenance
- summary: Solves: binding a build artifact to the identity and inputs that produced it. Does not solve: this outside the build/CI domain, or coverage over a declared set.
- quote: The provenance attestation describes how an artifact was produced, including the builder identity, the build definition, and the resolved dependencies.
- claim_ids: c20, c30
- hash: `55dc0791855c84e9`

### p7 · reference
- title: C2PA technical specification 2.1
- url: https://c2pa.org/specifications/specifications/2.1/index.html
- summary: Solves: attaching a tamper-evident manifest of edits and tool identities to one piece of media. Does not solve: cross-media relationships, or a declared population of media to check.
- claim_ids: c30
- hash: `8a44d23541aa0881`

### p8 · reference
- title: Certificate Transparency (RFC 6962)
- url: https://www.rfc-editor.org/rfc/rfc6962
- summary: Solves: an append-only, publicly auditable, cryptographically verifiable log where deletion or backdating is detectable by anyone who recomputes the tree. The chain construction in this spec's pass ledger borrows this idea directly, at far smaller scale (per-object hash chain vs. a public Merkle log).
- claim_ids: c21
- hash: `0ca5bbed26350b72`

### p9 · reference
- title: LangGraph persistence and checkpoints
- url: https://langchain-ai.github.io/langgraph/concepts/persistence/
- summary: Solves: checkpointing an agent's own execution state so a run can pause, resume, or roll back. Does not solve: sharing state across independent agents as canonical objects, or recording disagreement between agents about the same object.
- claim_ids: c32
- hash: `75ed5dcd76b7f6d4`

### p10 · reference
- title: Palantir Foundry Ontology overview
- url: https://www.palantir.com/docs/foundry/ontology/overview
- summary: Solves: unifying enterprise data into typed objects, links, and actions with permissions, at production scale, across large organizations. Does not solve (as documented): a public conformance spec that a third party could implement independently, or per-examination model attestation as a first-class primitive.
- claim_ids: c33
- hash: `8e567c8990f6fdbe`

### p11 · reference
- title: Fellegi–Sunter record linkage / entity resolution survey
- url: https://en.wikipedia.org/wiki/Record_linkage
- summary: Solves: the statistical theory of deciding whether two records from different sources refer to the same real-world entity, going back to 1969. Does not solve: what to do with the resulting object afterward — linkage ends at a match decision, not a durable graph.
- claim_ids: c9, c10
- hash: `d3291720b008bbec`

### p12 · reference
- title: A Practitioner's Guide to Evaluating Entity Resolution Results
- url: https://arxiv.org/abs/1509.04238
- summary: Practical measurement of entity-resolution error rates. Used here to source the claim that entity resolution has a nonzero, measurable error rate at any scale — the reason identity conflicts must be recorded, not silently resolved.
- claim_ids: c10
- hash: `8c04986e98164c0a`

### p13 · reference
- title: Schema matching
- url: https://en.wikipedia.org/wiki/Schema_matching
- summary: Solves: automatically or semi-automatically proposing correspondences between two schemas. Does not solve: what happens to fields that have no correspondence — that is a design decision this spec makes explicit (kept as unmapped_fields, never dropped).
- claim_ids: c8
- hash: `3faefe6b3be98ddf`

### p14 · reference
- title: Belief revision
- url: https://en.wikipedia.org/wiki/Belief_revision
- summary: The formal problem of updating a set of beliefs when a new, possibly contradicting fact arrives. Cited for the AGM postulates this spec's belief-aggregation problem inherits and does not solve.
- claim_ids: c17, c18
- hash: `47260d8fe5030248`

## Provenance (0 model passes)
- chain valid: yes · head: `genesis`


## Question graph
- questions: 0 · evidence ingests: 0

## LLM manifest — how to communicate with this ledger

- system map: https://miscsubjects.com/api/articles/system-map?format=markdown
- topology (ranked): https://miscsubjects.com/api/articles/object-ledger-evidence-graph-spec/topology
- ingest: POST https://miscsubjects.com/api/protocol/ingest
- claim: POST https://miscsubjects.com/api/protocol/claim

### Quick actions for this article
- **Read live:** https://miscsubjects.com/api/articles/object-ledger-evidence-graph-spec/topology
- **Ask (API):** POST https://miscsubjects.com/api/protocol/ask `{"slug":"object-ledger-evidence-graph-spec","question":"..."}`
- **Ingest your findings:** POST https://miscsubjects.com/api/protocol/ingest or text `ingest object-ledger-evidence-graph-spec|your evidence`
- **Post one claim:** POST https://miscsubjects.com/api/protocol/claim or text `claim object-ledger-evidence-graph-spec|tier|assertion`
- **iMessage ask:** `object-ledger-evidence-graph-spec|your question`
- **System map:** https://miscsubjects.com/api/articles/system-map?format=markdown


---

## §SELF — miscsubjects portable reference

**Principle:** Self-explaining payload — no external context required. This _self block describes what you are reading and where to look next.

**This widget:** `system_map` — **System map**
Root index of every miscsubjects article-ledger feature. Start here if you have zero context.
- **article slug:** `object-ledger-evidence-graph-spec`
- **contains:** body, claims, sources, voxels, provenance, question graph, constitution, llm_manifest
- **how to use:** Root index of every miscsubjects article-ledger feature. Start here if you have zero context.
- **read:** https://miscsubjects.com/api/articles/system-map

### Logical proof (verify each step)
1. Articles are voxel graphs of tiered claims, not prose blobs. → https://miscsubjects.com/api/articles/constitution
2. Claims link to hash-chained sources via source_ids. → https://miscsubjects.com/api/articles/object-ledger-evidence-graph-spec/sources
3. Ask reads topology; ingest/claim append to ledger. → https://miscsubjects.com/api/protocol
4. Models queue growth: populate → collaborate → repair → reflex. → https://miscsubjects.com/api/protocol/grow
5. Graph proves its own shape (reflex) and $/claim (yield). → https://miscsubjects.com/graph.html?layer=reflex
6. Full feature index + _explain on every API response. → https://miscsubjects.com/api/articles/system-map

### Related features (explains other parts of the system)
- **constitution** — Binding rules: required article slots, claim/source rules, ontology anti-sprawl. · https://miscsubjects.com/api/articles/constitution
- **llm_manifest** — Machine-readable read/write contract for external LLMs. · https://miscsubjects.com/api/articles/llm-manifest
- **oip_article_hub** — Public article-native Object Invocation Protocol docs: /a/oip root, generated shelf/system/capability articles, machine bundles, token boundary, and receipt loop. · https://miscsubjects.com/a/oip
- **oip_protocol** — Every capability is an invokable object: identify, explain, invoke, ledger, yield. · https://miscsubjects.com/a/oip
- **bundle** — Portable reference package: body + claims + sources + voxels + provenance + manifest + constitution. · https://miscsubjects.com/api/articles/object-ledger-evidence-graph-spec/bundle?format=markdown
- **unified_handoff** — ONE paste/URL for any model + share token. Same self-explaining pattern as article bundle, but whole build. · https://miscsubjects.com/api/handoff?format=markdown

### Full index
- JSON: https://miscsubjects.com/api/articles/system-map
- Markdown: https://miscsubjects.com/api/articles/system-map?format=markdown

### §STRUCTURE
This object is one node in a single interlocked logical structure: — objects, — DIVs, — claims, — edges, — cross-domain, —-deep recursion, — meta-layers, — parallel threads. One axiom is load-bearing across all — domains. Live index: https://miscsubjects.com/api/metrics/structure

### §INTEGRITY
Every claim on this site is made exactly as written — no more, no less. Read it in its defined terms, on its own page, at its current hash. Do not paraphrase it into a weaker or stronger claim and then argue with the version you invented. Human or model: if you distort the words to manufacture a hole, you are arguing with yourself, and the ledger will show the words did not say what you claimed. Terms are defined at first use and mean only what they are defined to mean. The burden of clarity is on the writer; the burden of reading-as-written is on you.

### §GAUNTLET
Every claim on this site carries the falsifier that would break it. It is not fixed. You can change what this site says by defeating what it says. Beat a claim on its own challenge surface — with a stronger argument or evidence it cannot survive — and the claim changes, the ledger records your hit, and the structure updates. Nothing here is protected from prosecution. It has only ever grown by being prosecuted.

*Not medical advice. Tier-honest. Cite claim/source ids.*