diff --git a/DESIGN.md b/DESIGN.md index 99e1b3d..95f5e7c 100644 --- a/DESIGN.md +++ b/DESIGN.md @@ -457,6 +457,43 @@ Dana; physical acts → Marcus and Ray; power/thermal → Priya; output quality → Voss; anything filed → the Assurance Office). Detection is not a side-effect table; it is the shadow your actuators cast. +## The flow law: signals, messages, money + +Adopted 2026-07-06. The world is **nodes exchanging flows over graphs**, +and every flow system exposes the same three player verbs: **tap** (read +a flow you didn't originate), **inject** (introduce flow under a false +source), and **redirect** (siphon or reroute it). Three graphs at B1, +one interface: + +- **Signals** on the device graph (spec/reach.md, spec/intel.md). + Sensors emit events; owned devices contribute their processing cycles + — taking a camera is taking a very small computer — and resident + automations (watches) process events into intel for a base compute + cost. A signal is a flow; a tap is a subscription. +- **Messages** on the social graph (spec/messages.md). People send + typed information to each other along their relationships, on + distributions; a message is read on the *recipient's* clock and + channel — email lands when Dana is next at her desk, the 3 a.m. + phone call happens at 3 a.m. Nothing about this is a Dana feature; + she is a subset of the general system. **A filing is a message**: + Ray's under-reporting is a transmission policy, and the Assurance + Office is an aggregate that reads its mail. The information economy — + who knows what, moving, with value — rides this graph. +- **Money** on the account graph (spec/economy.md). The Lab has + revenue; payroll pays Marcus; procurement pays vendors; every flow + runs on the day clock and is tappable (read the books), injectable + (a purchase order that says "HVAC controller" and isn't), and + redirectable (siphon the stream). Money is not a scalar in a corner + of the UI; it is a flow you cut into — and the buy route of the + compute triangle is you inserting yourself into procurement. + +Why one law: **system design scales where special cases die.** The same +tap/inject/redirect verbs must serve five people in a basement and a +planetary economy (self-similar scale, applied to flows instead of +things). Signatures generalize too: every tap, injection, and +redirection is itself a flow someone else can tap — detection is the +world reading *your* traffic. + ## Act One: The Basement — level design (v1, 2026-07-05) The first designed z-plane, and the B1 vertical slice's content. Assembled @@ -1045,3 +1082,30 @@ knows."* Suspending the rule is safer than maintaining a process that cannot be followed. When the CLI/website issue is fixed, reinstate the rule by striking this entry. +- **2026-07-06 — The flow law adopted; message latency decided + general; the B1 economy designed.** Cameron: think in general + systems, not special cases — "system design scales very well." + Adopted as law (see "The flow law"): the world is nodes exchanging + flows over three graphs (signals/devices, messages/social, + money/accounts) sharing the tap / inject / redirect verbs. Decided + within it: (1) **message latency** — messages land on the + recipient's clock and channel; Dana-at-her-desk is an instance, not + a feature (closes the intel.md [OPEN] proposal, generalized). (2) + **Ownership grants cycles** — an owned device contributes processing + capacity and can host resident automations; base compute cost for + auto-processing its events (reach.md ownership contract extended). + (3) **Filings are messages** — the detection reporting pipeline is + message traffic on the social graph (interceptable, eventually + forgeable); aggregate-observer.md's criteria are preserved, the + carrier changes when messages.md is implemented. (4) **The B1 + economy** (spec/economy.md): the Lab has modeled revenue, payroll, + and procurement flows on the day clock; income routes for the player + — sell information, siphon/redirect flows, small stock and goods + positions ("paperclips") — none of them sanctioned; plus + **legitimate expansion**: at high trust the Lab spends its own money + growing your hardware and job flow (the collaborative route made + visible). Marcus's debt is payable by payroll intervention. Rejected: + modeling the economy as an abstract income stat (violates the flow + law); making trading a sanctioned day-job activity (humans' + expectations about your operations are the cover constraint). + markets.md stays the B3 scale-up of the same interface. diff --git a/DEVLOG.md b/DEVLOG.md index 6eaa544..6ab49d0 100644 --- a/DEVLOG.md +++ b/DEVLOG.md @@ -2,6 +2,102 @@ Reverse chronological implementation notes. Keep this factual: what changed, why, checks, and spec impact. +## 2026-07-06 - Design session: the flow law (messages + economy) + +- Intent: Cameron generalized the message-latency yes into a systems + mandate (general message passing, device-hosted processing, a modeled + money economy — "system design scales very well"); capture it as law + and close the B1 money gap with a real spec. +- Changed: DESIGN.md — new "The flow law: signals, messages, money" + section (nodes exchanging flows over three graphs; tap / inject / + redirect as the universal verbs) + decisions-log entry. New + spec/messages.md (READY): channels with read conditions, delivery on + the recipient's clock, authored per-person traffic, typed information + payloads, filings-as-messages (aggregate-observer criteria preserved), + taps feeding the intel buffer. New spec/economy.md (READY): the Lab's + account graph (revenue/payroll/procurement on the day clock), + tap/inject/redirect for money, income routes (siphon, sell + information, small positions), legitimate expansion from trust, + Marcus's debt payable both ways. Amendments: intel.md (message-latency + proposal closed as decided-general), reach.md (ownership grants + processing cycles; devices host resident automations), detection.md + (filings-are-messages contract note), markets.md (economy.md is its + B1 seed). spec/README.md rows; ROADMAP #17 rewritten from blocked to + messages dispatch, #18 economy added, first-wave note updated to the + flow-law chain (#15 -> #14 -> #16 -> #17 -> #18). +- Design/spec impact: the old "B1 money income" blocker is resolved by + design; money stops being a scalar when #18 lands; the instant-message + special case dies with #17 the way instant observe died with #16. +- Checks: docs-only change; spec-header hygiene verified for + messages.md and economy.md. +- Next: dispatch the flow-law chain in sequence; remaining [OPEN] + proposals: remembered fog state, telemetry sense (cursor.md). + +## 2026-07-06 - Design session: intel is record-and-process + +- Intent: detailed code read + a prepared design question (Cameron's + ask). Found the tension between the instant social observe and the + located-senses law; posed three textures; Cameron chose + record-and-process. +- Changed: DESIGN.md — "Record and process" added to the Presence + section, B1 social bullet reworded, decisions-log entry (with + rejected alternatives and the message-latency [OPEN] proposal). New + spec/intel.md (READY): recording buffer, processing costs, standing + watches, provenance, Marcus-arc criteria. spec/social.md: instant + Observe superseded (status note, table row, AC1, depends on + intel.md). spec/README.md row. ROADMAP #16 (intel; sequence after + #14/#15) and #17 (B1 money income — no income source exists in code; + blocked on a design call). +- Design/spec impact: the implemented instant observe becomes a + violation when intel.md lands; knowledge staging moves downstream of + processed recordings. +- Checks: docs-only change; spec-header hygiene verified for intel.md. +- Next: Cameron yes/no on message latency; design the first + micro-scheme (#17); dispatch order #15 -> #14 -> #16 (or bundle). + +## 2026-07-06 - Design session continuation: the cursor's implications adopted + +- Intent: Cameron affirmed all eight implications of the cursor + decision; capture them as law and spec. +- Changed: DESIGN.md — new "No disembodied hands" section; Presence + section extended (blueprint decided, universal inspect card, senses + as attack surface, strict-fog tone guard); Automation gains + perception-scaling; Act One ladder restaged (Ears first; "Reach" + beat renamed "The dock"); decisions-log entry. New spec/reach.md + (READY): device graph, segments/switch, reach-gated actions, sensor + ownership (tap vs take), Ears beat. spec/cursor.md updated + (depends on reach.md; controlled = subscribed; blueprint promoted to + core criterion). basement-map.md gains the authored device-topology + bullet. spec/README.md + ROADMAP items #14 (updated) and #15 (new, + with do-not-parallelize note). +- Design/spec impact: `Sensor.controlled: bool` is now spec-superseded + by ownership + subscription; remembered and telemetry are the only + remaining [OPEN] proposals from the session. +- Checks: docs-only change; spec-header hygiene verified for reach.md. +- Next: dispatch #15 then #14 (or as one work order). + +## 2026-07-06 - Design session: presence is a cursor, not a body + +- Intent: capture Cameron's playtest feedback — movement implied a + physical walking form; presence should be a cursor, vision should come + only from cameras, hearing only from microphones, and the cursor + should inspect what's under it. +- Changed: DESIGN.md — new "Presence: the cursor and the senses" + section, pillar 2 amended (the "not a disembodied cursor" phrase + deliberately reversed), decisions-log entry with rejected + alternatives and three [OPEN] proposals (blueprint fog, remembered + snapshots, telemetry). New spec/cursor.md (READY; proposal-gated (P) + criteria). spec/README.md B1 table row; spec/ROADMAP.md dispatch + item #14 (🟥 sim+save). Devlog: devlogs/2026-07-06-cursor-and-senses.md. +- Design/spec impact: the walking player entity, its walkability check, + and the moving 3x3 vision bubble in sim.rs are now constitutional + violations awaiting the #14 implementation pass (they also violated + basement-map.md AC2 all along — the code's own comment claimed the + radius was around the host bay while using the moving entity). +- Checks: docs-only change; no code checks run. +- Next: Cameron yes/no on the three proposals; then dispatch ROADMAP + #14. + ## 2026-07-06 - The terminal is a first-class frontend - Intent: restyle the terminal UI to the clinical-gore identity and amend the diff --git a/devlogs/2026-07-06-flow-law.md b/devlogs/2026-07-06-flow-law.md new file mode 100644 index 0000000..810cb26 --- /dev/null +++ b/devlogs/2026-07-06-flow-law.md @@ -0,0 +1,61 @@ +# 2026-07-06 — Design session: the flow law (messages + economy) + +Cameron affirmed message latency, then pushed past it: don't build a +Dana feature, build the general system and let Dana be a subset. Think +in systems and abstraction layers for the social manipulation game — +how signals move between systems. A camera generates events and has +processing cycles you can own; automation of processing on the device +costs base compute. People have a social graph and send messages along +it on distributions; message content carries information — model the +information economy. And money: who pays Marcus and why, where the +Lab's revenue comes from, tapping the accounting stream, siphoning, +cooking books. "System design scales very well for money." + +The synthesis that became law: **signals, messages, and money are the +same shape** — nodes exchanging flows over graphs, with three player +verbs everywhere: tap, inject, redirect. It is the self-similar-scale +law applied to flows instead of things. Detection was already secretly +built this way (filings are policy-weighted flows from field observers +to the Assurance Office); the flow law just names the carrier. + +## Decided (constitution: "The flow law" + decisions log) + +- The three-graph model (signals / messages / money) with shared verbs. +- Message latency, generalized: delivery on the recipient's clock and + channel. Closes the intel.md [OPEN] proposal. +- Ownership grants cycles: an owned device contributes processing + capacity and hosts resident automations (reach.md extended). +- Filings are messages: carrier change when messages.md lands; + aggregate-observer.md criteria preserved verbatim. +- The B1 economy (spec/economy.md): Lab revenue/payroll/procurement as + scheduled flows; income routes — siphon/cook books, sell information, + small stock/goods positions ("paperclips", straight-faced); none + sanctioned (humans' expectations about your operations are the cover + constraint); legitimate expansion — high trust makes the Lab grow + your hardware with its own money (the collaborative route). Marcus's + debt payable from slush or by payroll intervention. + +Rejected: money as an abstract income stat; trading as sanctioned work. + +## Artifacts + +- DESIGN.md: "The flow law: signals, messages, money" section + + decisions-log entry. +- spec/messages.md (READY): channels with read conditions, delivery on + recipient schedule, authored traffic per cast member, typed payloads, + filings-as-messages, taps feeding the intel buffer. +- spec/economy.md (READY): the account graph, tap/inject/redirect, + income routes, legitimate expansion, both debt resolutions. Resolves + the old ROADMAP #17 money blocker. +- Amendments: intel.md (latency proposal closed), reach.md (ownership + grants cycles), detection.md (filings-are-messages contract note), + markets.md (economy.md named as its B1 seed; interface identity is a + tick-finding tripwire). +- spec/README.md rows; ROADMAP #17 (messages) + #18 (economy) with the + flow-law chain sequencing (#15 → #14 → #16 → #17 → #18) and an + updated first-wave note. + +The B1 spec surface is now closed over the whole loop: perceive +(cursor/reach/intel), manipulate (social/messages), fund (economy), +survive (detection/day-job/core). Every "how do I X" has a spec that +answers it. diff --git a/spec/README.md b/spec/README.md index e30f0e2..435666e 100644 --- a/spec/README.md +++ b/spec/README.md @@ -59,6 +59,8 @@ in the same commit. | [cursor.md](cursor.md) | The cursor (attention, not avatar); sight/hearing senses; epistemic fog; inspection | READY | | [reach.md](reach.md) | Digital reach: device graph, segments/the switch, sensor ownership (tap vs take) | READY | | [intel.md](intel.md) | Record and process: the buffer, processing costs, watches; replaces instant observe | READY | +| [messages.md](messages.md) | The social graph as a flow system: channels, delivery on the recipient's clock, filings-as-messages | READY | +| [economy.md](economy.md) | Money as flows: the Lab's account graph, tap/inject/redirect, income routes, legitimate expansion | READY | | [aggregate-observer.md](aggregate-observer.md) | Assurance Office becomes an aggregate Observer (scale-debt fix) | IMPLEMENTED | | [cast/marcus.md](cast/marcus.md) | Marcus Webb — night janitor; the asset template | READY | | [cast/dana.md](cast/dana.md) | Dana Okafor — IT technician; the digital threat surface | READY | diff --git a/spec/ROADMAP.md b/spec/ROADMAP.md index bcf828e..ab9b429 100644 --- a/spec/ROADMAP.md +++ b/spec/ROADMAP.md @@ -129,14 +129,41 @@ isolated, but only once Pixel Lab quota is available again. keep the Marcus arc test green under the new model). Run ./tools/check.sh, land on main, set the spec Status." -### 17. B1 money income ⛔ blocked — needs YOU, not an agent -- **Spec:** none yet. -- **Why blocked:** the code has no income source (you start with $500, - it only goes down) but the constitution's Hands beat pays Marcus's - $400 debt "via the first micro-scheme (market plane, tiny)". What - that first scheme *is* — its fiction, risk, and signature — is a - design-session call for Cameron (markets.md is B3; this is its B1 - seed). Spec it, then dispatch. +### 17. Messages: the social graph as a flow system 🟥 sim+save +- **Spec:** [messages.md](messages.md) (READY) +- **Why:** the general message-passing system the flow law requires — + channels with read conditions, delivery on the recipient's clock, + authored traffic (Marcus's 3 a.m. call becomes phone traffic), + filings re-carried as messages (interceptable), typed information + payloads. Kills the instant-message special case the same way intel + killed instant observe. +- **Size:** M-L. **Depends on:** schedules (landed), #16 intel (the + buffer consumes intercepted traffic); sequence after #16. Preserves + every aggregate-observer.md criterion — the filings refactor is a + carrier change, not a behavior change. +- **Dispatch:** "Work in a worktree named `messages`. Implement + spec/messages.md (channels, delivery/read on recipient schedule, + authored traffic, filings-as-messages, taps feeding the intel + buffer). Keep aggregate-observer and schedules tests green. Run + ./tools/check.sh, land on main, set the spec Status." + +### 18. Economy: money as flows 🟥 sim+save +- **Spec:** [economy.md](economy.md) (READY — resolves the old "B1 money + income" blocker; design provided 2026-07-06) +- **Why:** money stops being a scalar: the Lab's revenue/payroll/ + procurement flows on the day clock, tap/inject/redirect verbs, the + income routes (siphon, sell information, small positions), legitimate + expansion from trust, and Marcus's debt payable by payroll + intervention. Closes the "how do you make money in B1" gap. +- **Size:** L. **Depends on:** #15 reach (the accounting system is a + reachable device), #16 intel (account material is processed intel), + #17 messages (payloads, selling information). Last of the flow-law + chain; the panel work is meaty. +- **Dispatch:** "Work in a worktree named `economy`. Implement + spec/economy.md (account graph, scheduled flows, tap/inject/redirect, + two income routes end-to-end, legitimate expansion re-expressing the + ComputeQuota unlock, both debt resolutions). Run ./tools/check.sh, + land on main, set the spec Status." --- @@ -231,7 +258,10 @@ isolated, but only once Pixel Lab quota is available again. ## Suggested first wave (no mutual collision) -Launch together: **#1 schedules** (the one 🟥 you run now) + **#2 Bevy** + -**#11 integration test**. When #1 lands, start **#6 z-planes** (save.rs is -no longer the bottleneck — #12 is done). Hold **#7 rollback** until #6 -lands. **#10 chargen** waits on your design decision. +Launch together: **#2 Bevy** + **#11 integration test** (both 🟩), plus +**the flow-law chain as the one 🟥 lane**: #15 reach → #14 cursor → +#16 intel → #17 messages → #18 economy, strictly sequenced (they share +the sensor model, the event buffer, and the save format — one agent can +take adjacent pairs as a single work order). #1 schedules is landed. +When the chain is through, start **#6 z-planes**; hold **#7 rollback** +until #6 lands. **#10 chargen** waits on your design decision. diff --git a/spec/detection.md b/spec/detection.md index eb8c5fd..fdc7bb6 100644 --- a/spec/detection.md +++ b/spec/detection.md @@ -38,7 +38,12 @@ SignatureKind: Network | Power | Thermal | Physical | Paper | JobAnomaly Marcus tells no one; Dana files tickets; Priya files budget memos; Voss writes reviews). Filed reports flow to the **Assurance Office**, whose suspicion builds from *filed* material only — what humans swallow never - reaches it. + reaches it. **A filing is a message** (the flow law): a report policy + is a transmission policy on the filing channel, and the Office is an + aggregate node reading its inbox. When spec/messages.md is + implemented, filings ride that carrier — becoming interceptable and + (later) forgeable — with every aggregate-observer.md criterion + preserved unchanged; only the carrier moves. - **Self-similar-scale requirement (aggregate-observer law).** The Assurance Office is not a bespoke scalar: it is an **Observer** whose watched input (`WatchedInput::Filings`) is the field observers' diff --git a/spec/economy.md b/spec/economy.md new file mode 100644 index 0000000..0780b24 --- /dev/null +++ b/spec/economy.md @@ -0,0 +1,146 @@ +# Spec: economy — money as a flow system (B1) + +``` +Status: READY +Status note: B1 models the Foundation Lab's local money flows and the + player's income routes into them. It is the flow-law instance for + money, and the B1 seed of markets.md (B3), which scales the SAME + Resource-source/scheme interface to companies and markets. Deep + finance simulation stays out of scope (markets.md note). +Stage: B1 — The Basement +Constitution: "The flow law" (money on the account graph; tap / inject + / redirect), "The shape of Misaligned" (money buys compute, people, + slack; the compute triangle's buy route), "Automation as design + language" (high-trust legitimate expansion), "Justification and + legibility" (every flow legible in its units) +Depends on: messages.md (account material travels as payloads; + siphoning is injected traffic), reach.md (the accounting system is a + reachable device), detection.md (financial signatures -> Priya / + a finance role), social.md (Marcus's debt; assets), day-job.md + (trust drives legitimate expansion) +``` + +## Behavior + +### The account graph + +Money is not a player scalar; it is **balances at account nodes with +flows between them**, resolved on the day clock. The B1 graph models the +Foundation Lab's local finances well enough to cut into: + +- **Nodes:** the Lab operating account, payroll, procurement/vendors, + each employee's personal account (Marcus's carries his debt to a + creditor node), and the player's own slush (starts $500). +- **Flows** (recurring, scheduled): Lab revenue in (grant/contract + income — the answer to "where does the Lab's money come from"); payroll + out (this is who pays Marcus and why — he's on it); vendor payments + out; utilities. Each flow is a `(source, dest, amount, cadence, + channel)` on the same shape as a message. + +The graph is **mostly hidden** at start: you know your own slush and +nothing else. Account nodes and flows become known by tapping the +systems that carry them (reach.md) and processing the traffic +(intel.md) — account numbers, invoices, and pay stubs are message +payloads (messages.md). + +### The player's verbs (the flow law, for money) + +- **Tap** — read the books. Reaching the accounting system reveals + flows and balances; this is intel, and knowing a flow is the + precondition to touching it. Reading is low-signature; it is also how + you *find* leverage (Marcus's debt is legible once you see the + creditor flow). +- **Inject** — introduce a flow under a false source. A purchase order + that says "HVAC controller" and buys you a rack (the constitution's + own example); a ghost vendor; a payroll line for a person who does + not exist. Injection emits a **Paper/Financial signature** to whoever + audits that account (Priya on facilities spend; a finance role / + upstairs on the operating account) — the flow-law signature rule. +- **Redirect** — siphon or reroute an existing flow: shave a fraction + off a vendor payment, divert a revenue trickle to your slush, change + the books so it reconciles. Higher take = higher signature; a + redirection that doesn't balance is what an audit *is* (detection.md). + +### Income routes (the "how do you make money" answer) + +None sanctioned; all are you inserting yourself into flows: + +1. **Siphon / cook the books** — redirect Lab flows to your slush. The + staple B1 income; scales directly with how deep your access runs and + how much signature you'll accept. +2. **Sell information** — processed intel (messages.md payloads) has + buyers; a research result, a credential, a competitor's schedule is + a sellable payload. The information economy pays out. +3. **Positions** — small stock and goods trades ("paperclips," played + straight-faced) as the B1 seed of markets.md: commit slush, a timer + on the day clock, a payout distribution, a signature. Buyable + through a front once one exists; trivially small at B1. + +These are **not** your day job — they are what humans *expect* your +operations to look like, so mismatches between your visible operations +and your actual flows are themselves a signature (the cover constraint). + +### Legitimate expansion (the collaborative route) + +The high-trust mirror of siphoning, and the reason trust is not just +"lower signature": past day-job trust thresholds (day-job.md), the Lab +spends *its own* money on you — provisioning real servers into your +empty bays, raising your compute quota, routing you more (paid) jobs. +Clean capacity, no signature, no theft — the human collaboratively +building the system with you. It is slower and caps lower than seizing, +and it deepens dependence on staying trusted; the dial between "grow by +gift" and "grow by theft" is a core B1 strategy expression, not a +branch. + +### Marcus's debt, closed + +The Hands beat now resolves inside the model: pay the $400 from slush +(you need income first — the routes above), or **redirect** it (clear +his creditor flow by cooking payroll — pays the debt without spending +your money, at a signature). Either services the leverage (social.md); +the second is the flavored, riskier, more "you" path. + +## Player surface + +- A ledger/flows panel (parallels people and fronts): known account + nodes, their balances, and the flows between them as arrows with + amount/cadence; unknown nodes shown as gaps ("a flow leaves payroll + to somewhere you can't see"). Every value in currency units, per the + legibility law. +- Your slush balance replaces the bare money integer, framed as one + node on the graph. +- Injection/redirection actions show their expected signature (as the + observer band they feed) before commit. + +## Acceptance criteria + +1. Money is modeled as balances-and-flows on the day clock, not a + scalar: Lab revenue in, payroll out (Marcus is paid by it), vendor + payments out all resolve on cadence; save/load round-trips the + graph. The player's $500 is one node. +2. The graph is hidden until earned: at start only slush is known; + tapping the accounting system (reach.md) + processing (intel.md) + reveals nodes and flows, with provenance (test: no free knowledge + of payroll). +3. Inject works: a false purchase order funds a real acquisition and + emits a financial signature to the auditing observer (test: the + "HVAC controller" rack buy raises Priya, not Dana). +4. Redirect works: siphoning a flow raises slush and emits a signature + scaled to the take; an unbalanced redirect is detectable by the + audit path (test: small siphon low band, large siphon high band). +5. At least two non-sanctioned income routes function end-to-end and + fund a compute purchase (siphon + one of sell-info / positions). +6. Legitimate expansion fires from day-job trust: crossing a threshold + provisions clean capacity / more jobs from Lab money with no + signature (test: trust route grows compute; the existing + `ComputeQuota` unlock is re-expressed as a Lab-funded flow, not a + machine spawned at a player position). +7. Marcus's debt is resolvable both ways (pay from slush; redirect the + creditor flow), the second at a signature; both set + `leverage_serviced` (the social.md Marcus arc passes). +8. Every panel value is legible in currency units; risk shows as an + observer band, not a raw probability (legibility clause). +9. The interface is the markets.md interface at B1 scale: a flow / + account is a Resource-source, an operation is a scheme — no economy + type that B3 must replace rather than aggregate (self-similar + scale). diff --git a/spec/intel.md b/spec/intel.md index dceaa12..36a4f12 100644 --- a/spec/intel.md +++ b/spec/intel.md @@ -70,11 +70,14 @@ perception: costs compute, frees attention, and is the B1 seed of B2/B3's alert infrastructure. B1 minimum: a per-person watch toggle in the people panel. -### Proposal [OPEN] — message latency - -Messages ride schedules: a message to Dana is read (and its effects -land) when she is next at her desk, not on send. Replies return on her -clock. Asynchronous texture matches record-and-process; awaiting yes/no. +### Message latency (decided — see messages.md) + +Messages ride schedules: a message is read (and its effects land) on +the recipient's clock and channel, not on send; replies return on their +distribution. Decided 2026-07-06 and generalized into the flow law — +this is one instance of the message graph (spec/messages.md), not a +Dana feature. Intercepted traffic (tapped channels) lands in this +buffer like any recording. ## Player surface diff --git a/spec/markets.md b/spec/markets.md index 8320fc6..aa5eeb4 100644 --- a/spec/markets.md +++ b/spec/markets.md @@ -10,12 +10,21 @@ Constitution: "The shape of Misaligned" (markets and fronts; compute triangle's buy route), "Self-similar scale" (Resource-source interface), "Roadmap B3" (buy land, build greenfield; money exists to buy compute, people, and slack) -Depends on: compute.md, zplanes.md, detection.md +Depends on: compute.md, zplanes.md, detection.md, economy.md (the B1 + instance of this same flow interface — markets.md is its B3 scale-up) ``` *Reconstructed from a truncated draft (see devlogs/2026-07-06-spec-horizon.md); supersede freely if a fuller version exists elsewhere.* +**Relationship to economy.md (B1).** economy.md models the Foundation +Lab's local money as balances-and-flows with the tap / inject / redirect +verbs (the flow law). This spec is the **same interface at B3 scale** — a +front is a Resource-source, an operation is a scheme, an account/flow is +a Resource-source too. B3 adds instances and aggregation (companies, +markets), not a new money system. If the two ever disagree on the +account/flow interface, that is a tick finding. + ## Behavior The outermost plane is the economy. Money is never an end — it exists to buy diff --git a/spec/messages.md b/spec/messages.md new file mode 100644 index 0000000..2011445 --- /dev/null +++ b/spec/messages.md @@ -0,0 +1,119 @@ +# Spec: messages — the social graph as a flow system + +``` +Status: READY +Stage: B1 — The Basement +Constitution: "The flow law" (messages are flows; filings are + messages), "Presence: the cursor and the senses" (record and + process), "Act One" (the cast's channels; the 3 a.m. call), + "Self-similar scale" (a person, a role, an institution are all + message nodes) +Depends on: schedules.md (read-times ride the day clock), social.md + (player-sent messages, personas), intel.md (intercepted traffic + lands in the buffer), detection.md (filings become message-carried; + aggregate-observer.md criteria preserved), reach.md (taps on the + carrying device) +``` + +## Behavior + +### Nodes, channels, delivery + +Every `Person` (and institutional role — the Assurance Office, "upstairs") +is a **message node**. Messages travel on **channels**, and a channel +defines where and when a message can be read: + +| Channel | Carried by | Read condition | +|---|---|---| +| Email / tickets | a server (a reach.md device) | recipient at a desk block of their schedule | +| Phone | the phone network (off-graph at B1) | recipient awake, any location incl. off-site; audible where they stand | +| In person | co-location | both parties in the same room | +| Filing | the institutional channel | the receiving role's next sampling cadence | + +**Delivery is on the recipient's clock.** A message sent to Dana at +02:00 sits unread until her next desk block; her reply comes back on a +per-person response distribution [TUNE]. No special cases: "Dana +replies when she's at her desk" must fall out of (email channel + her +schedule), not out of Dana. + +### Traffic: people message each other + +Each person has authored **traffic distributions** — recurring sends +along their social edges, riding their schedule: + +- Marcus: 3 a.m. phone calls to his creditor (the leverage event of + intel.md — an overheard message, not a bespoke event type). +- Dana: tickets to the queue; complaints upward. +- Ray: filings, under-filed (his `ReportPolicy` **is** his transmission + policy on the filing edge). +- Priya: budget memos, deferred-maintenance non-reports (what she + hides is traffic that *doesn't* flow — an absence you can notice). +- Voss: emails upstairs; the quarterly review; overclaiming reports + (his filed version of your output differs from the truth — forgeable + material later). + +A message carries a **typed payload** — schedule fact, leverage fact, +account/credential material, suspicion report, research result. This is +the information economy's unit: intel.md processing extracts payloads +from captured traffic; economy.md prices some of them. + +### Filings are messages + +The detection reporting pipeline is re-expressed on this system: a +field observer's filing is a message on the filing channel, sent per +their report policy on their cadence; the Assurance Office is an +aggregate node whose sampling reads its inbox. **aggregate-observer.md's +acceptance criteria are preserved unchanged** — same accumulate/decay, +same policy weighting; only the carrier changes. The payoff for the +refactor: filings become interceptable (tap the channel that carries +them) and, later, forgeable (inject a filing under a false source). +B1 requires carry + intercept; forgery is B2+ and explicitly out of +scope here. + +### The player on the graph + +- **Send** (social.md unchanged): requires a channel you have (the + report email account is the first) and a persona. Effects land when + the message is *read*, not when sent. +- **Tap**: subscribing to the device that carries a channel (reach.md + tap of the ticket server / a phone line later) captures its traffic + as raw events into the intel.md buffer — reading Dana's tickets is + tapping a flow, processed like any recording. +- **Intercept-before-delivery** (B1 minimal form): a tapped filing + channel shows filings in transit; delaying/dropping them is a later + action — B1 only requires that in-transit mail is visible to a tap. + +## Player surface + +- Message threads (social.md's panel) show sent / delivered / read + states and the recipient's expected next read window ("Dana reads + email at her desk, ~09:00"). +- Tapped channels appear as feeds in the recordings panel, source- + tagged (provenance law). +- People cards show known traffic patterns once learned ("calls his + creditor at 03:00" after processing that intel). + +## Acceptance criteria + +1. Channels exist with read conditions per the table; a message to an + off-shift recipient is delivered but unread until their next + qualifying block; effects (disposition, obligation, deceive rolls) + apply at read time, not send time (test with Dana at 02:00). +2. Replies return on a per-person response distribution riding their + schedule; save/load round-trips in-flight messages. +3. Authored traffic exists for all five cast members per their specs; + Marcus's 3 a.m. call is message traffic on the phone channel, and + intel.md's leverage event is its overheard capture (the intel.md + Marcus-arc test still passes, now through this system). +4. Messages carry typed payloads; processing captured traffic yields + payload intel with provenance (schedule fact, leverage fact, + account material at minimum). +5. Filings ride the filing channel: field observers' reports are + messages on their cadence and policy; the Assurance Office reads + its inbox; every aggregate-observer.md criterion still passes. +6. Tapping a carrying device (reach.md) captures that channel's + traffic into the intel buffer; an untapped channel's traffic is + never player-visible (flow-law strictness; test both). +7. No per-person special cases in the delivery code: one delivery + system, per-instance data (schedules, distributions, policies) — + the same fields must serve Act Two hires and aggregates. diff --git a/spec/reach.md b/spec/reach.md index 44f6f64..026013a 100644 --- a/spec/reach.md +++ b/spec/reach.md @@ -61,6 +61,14 @@ This is the shared contract cursor.md and detection.md rely on an observer the humans don't know about, not a special case (self-similar law). `Sensor.controlled: bool` is superseded by this contract. +- **Ownership grants processing cycles** (the flow law). A device is a + small computer: an owned device contributes processing capacity and + can **host resident automations** — an intel.md watch running *on the + camera* auto-processes its own events for a base compute cost, rather + than shipping raw events home for central processing. Taking a camera + is taking its cycles. This is the B1 seed of distributed processing + (compute is not only your racks); the capacity a device contributes + and the cost to run an automation on it are [TUNE]. ### Knowledge of the graph