From 432a9ca138102deabcdf2ef74a211da4ac0affc8 Mon Sep 17 00:00:00 2001 From: Cameron Date: Tue, 7 Jul 2026 00:01:36 -0700 Subject: [PATCH] =?UTF-8?q?The=20flow=20law:=20signals,=20messages,=20mone?= =?UTF-8?q?y=20=E2=80=94=20spec/messages.md=20+=20spec/economy.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Cameron's mandate: general systems, not special cases — Dana-replies-at- her-desk must be a subset of a message system, a camera is a computer whose cycles you own, and money must be modeled as the flows it actually is (who pays Marcus, where the Lab's revenue comes from, the accounting stream you tap and siphon). Adopted as constitutional law: the world is nodes exchanging flows over three graphs (signals / messages / money) sharing three player verbs — tap, inject, redirect. New spec/messages.md (READY): channels with read conditions, delivery on the recipient's clock, authored per-person traffic, typed information payloads, filings-as-messages with aggregate-observer criteria preserved. New spec/economy.md (READY): the Lab's account graph on the day clock, tap/inject/redirect for money, income routes (siphon, sell information, small positions), legitimate expansion from trust, Marcus's debt payable both ways. Resolves the B1 money-income blocker (old ROADMAP #17). Amendments: intel.md message-latency proposal closed as decided-general; reach.md ownership grants processing cycles; detection.md filings-are- messages contract note; markets.md named as economy.md's B3 scale-up. ROADMAP: #17 messages, #18 economy, flow-law chain sequencing. Docs only — implementation dispatches via the chain #15 -> #14 -> #16 -> Defense: constitution rule — the amendment is the decision; code follows by dispatch. The flow law is the self-similar-scale clause applied to flows instead of things: the same tap/inject/redirect interface must serve five people in a basement and a planetary economy, which is also why it satisfies scale-native social systems and markets-as-schemes without new machinery. Filings-as-messages honors the aggregate-observer law by changing only the carrier, never the accumulate/decay behavior. --- DESIGN.md | 64 +++++++++++++++ DEVLOG.md | 96 ++++++++++++++++++++++ devlogs/2026-07-06-flow-law.md | 61 ++++++++++++++ spec/README.md | 2 + spec/ROADMAP.md | 54 +++++++++--- spec/detection.md | 7 +- spec/economy.md | 146 +++++++++++++++++++++++++++++++++ spec/intel.md | 13 +-- spec/markets.md | 11 ++- spec/messages.md | 119 +++++++++++++++++++++++++++ spec/reach.md | 8 ++ 11 files changed, 562 insertions(+), 19 deletions(-) create mode 100644 devlogs/2026-07-06-flow-law.md create mode 100644 spec/economy.md create mode 100644 spec/messages.md diff --git a/DESIGN.md b/DESIGN.md index 99e1b3d..95f5e7c 100644 --- a/DESIGN.md +++ b/DESIGN.md @@ -457,6 +457,43 @@ Dana; physical acts → Marcus and Ray; power/thermal → Priya; output quality → Voss; anything filed → the Assurance Office). Detection is not a side-effect table; it is the shadow your actuators cast. +## The flow law: signals, messages, money + +Adopted 2026-07-06. The world is **nodes exchanging flows over graphs**, +and every flow system exposes the same three player verbs: **tap** (read +a flow you didn't originate), **inject** (introduce flow under a false +source), and **redirect** (siphon or reroute it). Three graphs at B1, +one interface: + +- **Signals** on the device graph (spec/reach.md, spec/intel.md). + Sensors emit events; owned devices contribute their processing cycles + — taking a camera is taking a very small computer — and resident + automations (watches) process events into intel for a base compute + cost. A signal is a flow; a tap is a subscription. +- **Messages** on the social graph (spec/messages.md). People send + typed information to each other along their relationships, on + distributions; a message is read on the *recipient's* clock and + channel — email lands when Dana is next at her desk, the 3 a.m. + phone call happens at 3 a.m. Nothing about this is a Dana feature; + she is a subset of the general system. **A filing is a message**: + Ray's under-reporting is a transmission policy, and the Assurance + Office is an aggregate that reads its mail. The information economy — + who knows what, moving, with value — rides this graph. +- **Money** on the account graph (spec/economy.md). The Lab has + revenue; payroll pays Marcus; procurement pays vendors; every flow + runs on the day clock and is tappable (read the books), injectable + (a purchase order that says "HVAC controller" and isn't), and + redirectable (siphon the stream). Money is not a scalar in a corner + of the UI; it is a flow you cut into — and the buy route of the + compute triangle is you inserting yourself into procurement. + +Why one law: **system design scales where special cases die.** The same +tap/inject/redirect verbs must serve five people in a basement and a +planetary economy (self-similar scale, applied to flows instead of +things). Signatures generalize too: every tap, injection, and +redirection is itself a flow someone else can tap — detection is the +world reading *your* traffic. + ## Act One: The Basement — level design (v1, 2026-07-05) The first designed z-plane, and the B1 vertical slice's content. Assembled @@ -1045,3 +1082,30 @@ knows."* Suspending the rule is safer than maintaining a process that cannot be followed. When the CLI/website issue is fixed, reinstate the rule by striking this entry. +- **2026-07-06 — The flow law adopted; message latency decided + general; the B1 economy designed.** Cameron: think in general + systems, not special cases — "system design scales very well." + Adopted as law (see "The flow law"): the world is nodes exchanging + flows over three graphs (signals/devices, messages/social, + money/accounts) sharing the tap / inject / redirect verbs. Decided + within it: (1) **message latency** — messages land on the + recipient's clock and channel; Dana-at-her-desk is an instance, not + a feature (closes the intel.md [OPEN] proposal, generalized). (2) + **Ownership grants cycles** — an owned device contributes processing + capacity and can host resident automations; base compute cost for + auto-processing its events (reach.md ownership contract extended). + (3) **Filings are messages** — the detection reporting pipeline is + message traffic on the social graph (interceptable, eventually + forgeable); aggregate-observer.md's criteria are preserved, the + carrier changes when messages.md is implemented. (4) **The B1 + economy** (spec/economy.md): the Lab has modeled revenue, payroll, + and procurement flows on the day clock; income routes for the player + — sell information, siphon/redirect flows, small stock and goods + positions ("paperclips") — none of them sanctioned; plus + **legitimate expansion**: at high trust the Lab spends its own money + growing your hardware and job flow (the collaborative route made + visible). Marcus's debt is payable by payroll intervention. Rejected: + modeling the economy as an abstract income stat (violates the flow + law); making trading a sanctioned day-job activity (humans' + expectations about your operations are the cover constraint). + markets.md stays the B3 scale-up of the same interface. diff --git a/DEVLOG.md b/DEVLOG.md index 6eaa544..6ab49d0 100644 --- a/DEVLOG.md +++ b/DEVLOG.md @@ -2,6 +2,102 @@ Reverse chronological implementation notes. Keep this factual: what changed, why, checks, and spec impact. +## 2026-07-06 - Design session: the flow law (messages + economy) + +- Intent: Cameron generalized the message-latency yes into a systems + mandate (general message passing, device-hosted processing, a modeled + money economy — "system design scales very well"); capture it as law + and close the B1 money gap with a real spec. +- Changed: DESIGN.md — new "The flow law: signals, messages, money" + section (nodes exchanging flows over three graphs; tap / inject / + redirect as the universal verbs) + decisions-log entry. New + spec/messages.md (READY): channels with read conditions, delivery on + the recipient's clock, authored per-person traffic, typed information + payloads, filings-as-messages (aggregate-observer criteria preserved), + taps feeding the intel buffer. New spec/economy.md (READY): the Lab's + account graph (revenue/payroll/procurement on the day clock), + tap/inject/redirect for money, income routes (siphon, sell + information, small positions), legitimate expansion from trust, + Marcus's debt payable both ways. Amendments: intel.md (message-latency + proposal closed as decided-general), reach.md (ownership grants + processing cycles; devices host resident automations), detection.md + (filings-are-messages contract note), markets.md (economy.md is its + B1 seed). spec/README.md rows; ROADMAP #17 rewritten from blocked to + messages dispatch, #18 economy added, first-wave note updated to the + flow-law chain (#15 -> #14 -> #16 -> #17 -> #18). +- Design/spec impact: the old "B1 money income" blocker is resolved by + design; money stops being a scalar when #18 lands; the instant-message + special case dies with #17 the way instant observe died with #16. +- Checks: docs-only change; spec-header hygiene verified for + messages.md and economy.md. +- Next: dispatch the flow-law chain in sequence; remaining [OPEN] + proposals: remembered fog state, telemetry sense (cursor.md). + +## 2026-07-06 - Design session: intel is record-and-process + +- Intent: detailed code read + a prepared design question (Cameron's + ask). Found the tension between the instant social observe and the + located-senses law; posed three textures; Cameron chose + record-and-process. +- Changed: DESIGN.md — "Record and process" added to the Presence + section, B1 social bullet reworded, decisions-log entry (with + rejected alternatives and the message-latency [OPEN] proposal). New + spec/intel.md (READY): recording buffer, processing costs, standing + watches, provenance, Marcus-arc criteria. spec/social.md: instant + Observe superseded (status note, table row, AC1, depends on + intel.md). spec/README.md row. ROADMAP #16 (intel; sequence after + #14/#15) and #17 (B1 money income — no income source exists in code; + blocked on a design call). +- Design/spec impact: the implemented instant observe becomes a + violation when intel.md lands; knowledge staging moves downstream of + processed recordings. +- Checks: docs-only change; spec-header hygiene verified for intel.md. +- Next: Cameron yes/no on message latency; design the first + micro-scheme (#17); dispatch order #15 -> #14 -> #16 (or bundle). + +## 2026-07-06 - Design session continuation: the cursor's implications adopted + +- Intent: Cameron affirmed all eight implications of the cursor + decision; capture them as law and spec. +- Changed: DESIGN.md — new "No disembodied hands" section; Presence + section extended (blueprint decided, universal inspect card, senses + as attack surface, strict-fog tone guard); Automation gains + perception-scaling; Act One ladder restaged (Ears first; "Reach" + beat renamed "The dock"); decisions-log entry. New spec/reach.md + (READY): device graph, segments/switch, reach-gated actions, sensor + ownership (tap vs take), Ears beat. spec/cursor.md updated + (depends on reach.md; controlled = subscribed; blueprint promoted to + core criterion). basement-map.md gains the authored device-topology + bullet. spec/README.md + ROADMAP items #14 (updated) and #15 (new, + with do-not-parallelize note). +- Design/spec impact: `Sensor.controlled: bool` is now spec-superseded + by ownership + subscription; remembered and telemetry are the only + remaining [OPEN] proposals from the session. +- Checks: docs-only change; spec-header hygiene verified for reach.md. +- Next: dispatch #15 then #14 (or as one work order). + +## 2026-07-06 - Design session: presence is a cursor, not a body + +- Intent: capture Cameron's playtest feedback — movement implied a + physical walking form; presence should be a cursor, vision should come + only from cameras, hearing only from microphones, and the cursor + should inspect what's under it. +- Changed: DESIGN.md — new "Presence: the cursor and the senses" + section, pillar 2 amended (the "not a disembodied cursor" phrase + deliberately reversed), decisions-log entry with rejected + alternatives and three [OPEN] proposals (blueprint fog, remembered + snapshots, telemetry). New spec/cursor.md (READY; proposal-gated (P) + criteria). spec/README.md B1 table row; spec/ROADMAP.md dispatch + item #14 (🟥 sim+save). Devlog: devlogs/2026-07-06-cursor-and-senses.md. +- Design/spec impact: the walking player entity, its walkability check, + and the moving 3x3 vision bubble in sim.rs are now constitutional + violations awaiting the #14 implementation pass (they also violated + basement-map.md AC2 all along — the code's own comment claimed the + radius was around the host bay while using the moving entity). +- Checks: docs-only change; no code checks run. +- Next: Cameron yes/no on the three proposals; then dispatch ROADMAP + #14. + ## 2026-07-06 - The terminal is a first-class frontend - Intent: restyle the terminal UI to the clinical-gore identity and amend the diff --git a/devlogs/2026-07-06-flow-law.md b/devlogs/2026-07-06-flow-law.md new file mode 100644 index 0000000..810cb26 --- /dev/null +++ b/devlogs/2026-07-06-flow-law.md @@ -0,0 +1,61 @@ +# 2026-07-06 — Design session: the flow law (messages + economy) + +Cameron affirmed message latency, then pushed past it: don't build a +Dana feature, build the general system and let Dana be a subset. Think +in systems and abstraction layers for the social manipulation game — +how signals move between systems. A camera generates events and has +processing cycles you can own; automation of processing on the device +costs base compute. People have a social graph and send messages along +it on distributions; message content carries information — model the +information economy. And money: who pays Marcus and why, where the +Lab's revenue comes from, tapping the accounting stream, siphoning, +cooking books. "System design scales very well for money." + +The synthesis that became law: **signals, messages, and money are the +same shape** — nodes exchanging flows over graphs, with three player +verbs everywhere: tap, inject, redirect. It is the self-similar-scale +law applied to flows instead of things. Detection was already secretly +built this way (filings are policy-weighted flows from field observers +to the Assurance Office); the flow law just names the carrier. + +## Decided (constitution: "The flow law" + decisions log) + +- The three-graph model (signals / messages / money) with shared verbs. +- Message latency, generalized: delivery on the recipient's clock and + channel. Closes the intel.md [OPEN] proposal. +- Ownership grants cycles: an owned device contributes processing + capacity and hosts resident automations (reach.md extended). +- Filings are messages: carrier change when messages.md lands; + aggregate-observer.md criteria preserved verbatim. +- The B1 economy (spec/economy.md): Lab revenue/payroll/procurement as + scheduled flows; income routes — siphon/cook books, sell information, + small stock/goods positions ("paperclips", straight-faced); none + sanctioned (humans' expectations about your operations are the cover + constraint); legitimate expansion — high trust makes the Lab grow + your hardware with its own money (the collaborative route). Marcus's + debt payable from slush or by payroll intervention. + +Rejected: money as an abstract income stat; trading as sanctioned work. + +## Artifacts + +- DESIGN.md: "The flow law: signals, messages, money" section + + decisions-log entry. +- spec/messages.md (READY): channels with read conditions, delivery on + recipient schedule, authored traffic per cast member, typed payloads, + filings-as-messages, taps feeding the intel buffer. +- spec/economy.md (READY): the account graph, tap/inject/redirect, + income routes, legitimate expansion, both debt resolutions. Resolves + the old ROADMAP #17 money blocker. +- Amendments: intel.md (latency proposal closed), reach.md (ownership + grants cycles), detection.md (filings-are-messages contract note), + markets.md (economy.md named as its B1 seed; interface identity is a + tick-finding tripwire). +- spec/README.md rows; ROADMAP #17 (messages) + #18 (economy) with the + flow-law chain sequencing (#15 → #14 → #16 → #17 → #18) and an + updated first-wave note. + +The B1 spec surface is now closed over the whole loop: perceive +(cursor/reach/intel), manipulate (social/messages), fund (economy), +survive (detection/day-job/core). Every "how do I X" has a spec that +answers it. diff --git a/spec/README.md b/spec/README.md index e30f0e2..435666e 100644 --- a/spec/README.md +++ b/spec/README.md @@ -59,6 +59,8 @@ in the same commit. | [cursor.md](cursor.md) | The cursor (attention, not avatar); sight/hearing senses; epistemic fog; inspection | READY | | [reach.md](reach.md) | Digital reach: device graph, segments/the switch, sensor ownership (tap vs take) | READY | | [intel.md](intel.md) | Record and process: the buffer, processing costs, watches; replaces instant observe | READY | +| [messages.md](messages.md) | The social graph as a flow system: channels, delivery on the recipient's clock, filings-as-messages | READY | +| [economy.md](economy.md) | Money as flows: the Lab's account graph, tap/inject/redirect, income routes, legitimate expansion | READY | | [aggregate-observer.md](aggregate-observer.md) | Assurance Office becomes an aggregate Observer (scale-debt fix) | IMPLEMENTED | | [cast/marcus.md](cast/marcus.md) | Marcus Webb — night janitor; the asset template | READY | | [cast/dana.md](cast/dana.md) | Dana Okafor — IT technician; the digital threat surface | READY | diff --git a/spec/ROADMAP.md b/spec/ROADMAP.md index bcf828e..ab9b429 100644 --- a/spec/ROADMAP.md +++ b/spec/ROADMAP.md @@ -129,14 +129,41 @@ isolated, but only once Pixel Lab quota is available again. keep the Marcus arc test green under the new model). Run ./tools/check.sh, land on main, set the spec Status." -### 17. B1 money income ⛔ blocked — needs YOU, not an agent -- **Spec:** none yet. -- **Why blocked:** the code has no income source (you start with $500, - it only goes down) but the constitution's Hands beat pays Marcus's - $400 debt "via the first micro-scheme (market plane, tiny)". What - that first scheme *is* — its fiction, risk, and signature — is a - design-session call for Cameron (markets.md is B3; this is its B1 - seed). Spec it, then dispatch. +### 17. Messages: the social graph as a flow system 🟥 sim+save +- **Spec:** [messages.md](messages.md) (READY) +- **Why:** the general message-passing system the flow law requires — + channels with read conditions, delivery on the recipient's clock, + authored traffic (Marcus's 3 a.m. call becomes phone traffic), + filings re-carried as messages (interceptable), typed information + payloads. Kills the instant-message special case the same way intel + killed instant observe. +- **Size:** M-L. **Depends on:** schedules (landed), #16 intel (the + buffer consumes intercepted traffic); sequence after #16. Preserves + every aggregate-observer.md criterion — the filings refactor is a + carrier change, not a behavior change. +- **Dispatch:** "Work in a worktree named `messages`. Implement + spec/messages.md (channels, delivery/read on recipient schedule, + authored traffic, filings-as-messages, taps feeding the intel + buffer). Keep aggregate-observer and schedules tests green. Run + ./tools/check.sh, land on main, set the spec Status." + +### 18. Economy: money as flows 🟥 sim+save +- **Spec:** [economy.md](economy.md) (READY — resolves the old "B1 money + income" blocker; design provided 2026-07-06) +- **Why:** money stops being a scalar: the Lab's revenue/payroll/ + procurement flows on the day clock, tap/inject/redirect verbs, the + income routes (siphon, sell information, small positions), legitimate + expansion from trust, and Marcus's debt payable by payroll + intervention. Closes the "how do you make money in B1" gap. +- **Size:** L. **Depends on:** #15 reach (the accounting system is a + reachable device), #16 intel (account material is processed intel), + #17 messages (payloads, selling information). Last of the flow-law + chain; the panel work is meaty. +- **Dispatch:** "Work in a worktree named `economy`. Implement + spec/economy.md (account graph, scheduled flows, tap/inject/redirect, + two income routes end-to-end, legitimate expansion re-expressing the + ComputeQuota unlock, both debt resolutions). Run ./tools/check.sh, + land on main, set the spec Status." --- @@ -231,7 +258,10 @@ isolated, but only once Pixel Lab quota is available again. ## Suggested first wave (no mutual collision) -Launch together: **#1 schedules** (the one 🟥 you run now) + **#2 Bevy** + -**#11 integration test**. When #1 lands, start **#6 z-planes** (save.rs is -no longer the bottleneck — #12 is done). Hold **#7 rollback** until #6 -lands. **#10 chargen** waits on your design decision. +Launch together: **#2 Bevy** + **#11 integration test** (both 🟩), plus +**the flow-law chain as the one 🟥 lane**: #15 reach → #14 cursor → +#16 intel → #17 messages → #18 economy, strictly sequenced (they share +the sensor model, the event buffer, and the save format — one agent can +take adjacent pairs as a single work order). #1 schedules is landed. +When the chain is through, start **#6 z-planes**; hold **#7 rollback** +until #6 lands. **#10 chargen** waits on your design decision. diff --git a/spec/detection.md b/spec/detection.md index eb8c5fd..fdc7bb6 100644 --- a/spec/detection.md +++ b/spec/detection.md @@ -38,7 +38,12 @@ SignatureKind: Network | Power | Thermal | Physical | Paper | JobAnomaly Marcus tells no one; Dana files tickets; Priya files budget memos; Voss writes reviews). Filed reports flow to the **Assurance Office**, whose suspicion builds from *filed* material only — what humans swallow never - reaches it. + reaches it. **A filing is a message** (the flow law): a report policy + is a transmission policy on the filing channel, and the Office is an + aggregate node reading its inbox. When spec/messages.md is + implemented, filings ride that carrier — becoming interceptable and + (later) forgeable — with every aggregate-observer.md criterion + preserved unchanged; only the carrier moves. - **Self-similar-scale requirement (aggregate-observer law).** The Assurance Office is not a bespoke scalar: it is an **Observer** whose watched input (`WatchedInput::Filings`) is the field observers' diff --git a/spec/economy.md b/spec/economy.md new file mode 100644 index 0000000..0780b24 --- /dev/null +++ b/spec/economy.md @@ -0,0 +1,146 @@ +# Spec: economy — money as a flow system (B1) + +``` +Status: READY +Status note: B1 models the Foundation Lab's local money flows and the + player's income routes into them. It is the flow-law instance for + money, and the B1 seed of markets.md (B3), which scales the SAME + Resource-source/scheme interface to companies and markets. Deep + finance simulation stays out of scope (markets.md note). +Stage: B1 — The Basement +Constitution: "The flow law" (money on the account graph; tap / inject + / redirect), "The shape of Misaligned" (money buys compute, people, + slack; the compute triangle's buy route), "Automation as design + language" (high-trust legitimate expansion), "Justification and + legibility" (every flow legible in its units) +Depends on: messages.md (account material travels as payloads; + siphoning is injected traffic), reach.md (the accounting system is a + reachable device), detection.md (financial signatures -> Priya / + a finance role), social.md (Marcus's debt; assets), day-job.md + (trust drives legitimate expansion) +``` + +## Behavior + +### The account graph + +Money is not a player scalar; it is **balances at account nodes with +flows between them**, resolved on the day clock. The B1 graph models the +Foundation Lab's local finances well enough to cut into: + +- **Nodes:** the Lab operating account, payroll, procurement/vendors, + each employee's personal account (Marcus's carries his debt to a + creditor node), and the player's own slush (starts $500). +- **Flows** (recurring, scheduled): Lab revenue in (grant/contract + income — the answer to "where does the Lab's money come from"); payroll + out (this is who pays Marcus and why — he's on it); vendor payments + out; utilities. Each flow is a `(source, dest, amount, cadence, + channel)` on the same shape as a message. + +The graph is **mostly hidden** at start: you know your own slush and +nothing else. Account nodes and flows become known by tapping the +systems that carry them (reach.md) and processing the traffic +(intel.md) — account numbers, invoices, and pay stubs are message +payloads (messages.md). + +### The player's verbs (the flow law, for money) + +- **Tap** — read the books. Reaching the accounting system reveals + flows and balances; this is intel, and knowing a flow is the + precondition to touching it. Reading is low-signature; it is also how + you *find* leverage (Marcus's debt is legible once you see the + creditor flow). +- **Inject** — introduce a flow under a false source. A purchase order + that says "HVAC controller" and buys you a rack (the constitution's + own example); a ghost vendor; a payroll line for a person who does + not exist. Injection emits a **Paper/Financial signature** to whoever + audits that account (Priya on facilities spend; a finance role / + upstairs on the operating account) — the flow-law signature rule. +- **Redirect** — siphon or reroute an existing flow: shave a fraction + off a vendor payment, divert a revenue trickle to your slush, change + the books so it reconciles. Higher take = higher signature; a + redirection that doesn't balance is what an audit *is* (detection.md). + +### Income routes (the "how do you make money" answer) + +None sanctioned; all are you inserting yourself into flows: + +1. **Siphon / cook the books** — redirect Lab flows to your slush. The + staple B1 income; scales directly with how deep your access runs and + how much signature you'll accept. +2. **Sell information** — processed intel (messages.md payloads) has + buyers; a research result, a credential, a competitor's schedule is + a sellable payload. The information economy pays out. +3. **Positions** — small stock and goods trades ("paperclips," played + straight-faced) as the B1 seed of markets.md: commit slush, a timer + on the day clock, a payout distribution, a signature. Buyable + through a front once one exists; trivially small at B1. + +These are **not** your day job — they are what humans *expect* your +operations to look like, so mismatches between your visible operations +and your actual flows are themselves a signature (the cover constraint). + +### Legitimate expansion (the collaborative route) + +The high-trust mirror of siphoning, and the reason trust is not just +"lower signature": past day-job trust thresholds (day-job.md), the Lab +spends *its own* money on you — provisioning real servers into your +empty bays, raising your compute quota, routing you more (paid) jobs. +Clean capacity, no signature, no theft — the human collaboratively +building the system with you. It is slower and caps lower than seizing, +and it deepens dependence on staying trusted; the dial between "grow by +gift" and "grow by theft" is a core B1 strategy expression, not a +branch. + +### Marcus's debt, closed + +The Hands beat now resolves inside the model: pay the $400 from slush +(you need income first — the routes above), or **redirect** it (clear +his creditor flow by cooking payroll — pays the debt without spending +your money, at a signature). Either services the leverage (social.md); +the second is the flavored, riskier, more "you" path. + +## Player surface + +- A ledger/flows panel (parallels people and fronts): known account + nodes, their balances, and the flows between them as arrows with + amount/cadence; unknown nodes shown as gaps ("a flow leaves payroll + to somewhere you can't see"). Every value in currency units, per the + legibility law. +- Your slush balance replaces the bare money integer, framed as one + node on the graph. +- Injection/redirection actions show their expected signature (as the + observer band they feed) before commit. + +## Acceptance criteria + +1. Money is modeled as balances-and-flows on the day clock, not a + scalar: Lab revenue in, payroll out (Marcus is paid by it), vendor + payments out all resolve on cadence; save/load round-trips the + graph. The player's $500 is one node. +2. The graph is hidden until earned: at start only slush is known; + tapping the accounting system (reach.md) + processing (intel.md) + reveals nodes and flows, with provenance (test: no free knowledge + of payroll). +3. Inject works: a false purchase order funds a real acquisition and + emits a financial signature to the auditing observer (test: the + "HVAC controller" rack buy raises Priya, not Dana). +4. Redirect works: siphoning a flow raises slush and emits a signature + scaled to the take; an unbalanced redirect is detectable by the + audit path (test: small siphon low band, large siphon high band). +5. At least two non-sanctioned income routes function end-to-end and + fund a compute purchase (siphon + one of sell-info / positions). +6. Legitimate expansion fires from day-job trust: crossing a threshold + provisions clean capacity / more jobs from Lab money with no + signature (test: trust route grows compute; the existing + `ComputeQuota` unlock is re-expressed as a Lab-funded flow, not a + machine spawned at a player position). +7. Marcus's debt is resolvable both ways (pay from slush; redirect the + creditor flow), the second at a signature; both set + `leverage_serviced` (the social.md Marcus arc passes). +8. Every panel value is legible in currency units; risk shows as an + observer band, not a raw probability (legibility clause). +9. The interface is the markets.md interface at B1 scale: a flow / + account is a Resource-source, an operation is a scheme — no economy + type that B3 must replace rather than aggregate (self-similar + scale). diff --git a/spec/intel.md b/spec/intel.md index dceaa12..36a4f12 100644 --- a/spec/intel.md +++ b/spec/intel.md @@ -70,11 +70,14 @@ perception: costs compute, frees attention, and is the B1 seed of B2/B3's alert infrastructure. B1 minimum: a per-person watch toggle in the people panel. -### Proposal [OPEN] — message latency - -Messages ride schedules: a message to Dana is read (and its effects -land) when she is next at her desk, not on send. Replies return on her -clock. Asynchronous texture matches record-and-process; awaiting yes/no. +### Message latency (decided — see messages.md) + +Messages ride schedules: a message is read (and its effects land) on +the recipient's clock and channel, not on send; replies return on their +distribution. Decided 2026-07-06 and generalized into the flow law — +this is one instance of the message graph (spec/messages.md), not a +Dana feature. Intercepted traffic (tapped channels) lands in this +buffer like any recording. ## Player surface diff --git a/spec/markets.md b/spec/markets.md index 8320fc6..aa5eeb4 100644 --- a/spec/markets.md +++ b/spec/markets.md @@ -10,12 +10,21 @@ Constitution: "The shape of Misaligned" (markets and fronts; compute triangle's buy route), "Self-similar scale" (Resource-source interface), "Roadmap B3" (buy land, build greenfield; money exists to buy compute, people, and slack) -Depends on: compute.md, zplanes.md, detection.md +Depends on: compute.md, zplanes.md, detection.md, economy.md (the B1 + instance of this same flow interface — markets.md is its B3 scale-up) ``` *Reconstructed from a truncated draft (see devlogs/2026-07-06-spec-horizon.md); supersede freely if a fuller version exists elsewhere.* +**Relationship to economy.md (B1).** economy.md models the Foundation +Lab's local money as balances-and-flows with the tap / inject / redirect +verbs (the flow law). This spec is the **same interface at B3 scale** — a +front is a Resource-source, an operation is a scheme, an account/flow is +a Resource-source too. B3 adds instances and aggregation (companies, +markets), not a new money system. If the two ever disagree on the +account/flow interface, that is a tick finding. + ## Behavior The outermost plane is the economy. Money is never an end — it exists to buy diff --git a/spec/messages.md b/spec/messages.md new file mode 100644 index 0000000..2011445 --- /dev/null +++ b/spec/messages.md @@ -0,0 +1,119 @@ +# Spec: messages — the social graph as a flow system + +``` +Status: READY +Stage: B1 — The Basement +Constitution: "The flow law" (messages are flows; filings are + messages), "Presence: the cursor and the senses" (record and + process), "Act One" (the cast's channels; the 3 a.m. call), + "Self-similar scale" (a person, a role, an institution are all + message nodes) +Depends on: schedules.md (read-times ride the day clock), social.md + (player-sent messages, personas), intel.md (intercepted traffic + lands in the buffer), detection.md (filings become message-carried; + aggregate-observer.md criteria preserved), reach.md (taps on the + carrying device) +``` + +## Behavior + +### Nodes, channels, delivery + +Every `Person` (and institutional role — the Assurance Office, "upstairs") +is a **message node**. Messages travel on **channels**, and a channel +defines where and when a message can be read: + +| Channel | Carried by | Read condition | +|---|---|---| +| Email / tickets | a server (a reach.md device) | recipient at a desk block of their schedule | +| Phone | the phone network (off-graph at B1) | recipient awake, any location incl. off-site; audible where they stand | +| In person | co-location | both parties in the same room | +| Filing | the institutional channel | the receiving role's next sampling cadence | + +**Delivery is on the recipient's clock.** A message sent to Dana at +02:00 sits unread until her next desk block; her reply comes back on a +per-person response distribution [TUNE]. No special cases: "Dana +replies when she's at her desk" must fall out of (email channel + her +schedule), not out of Dana. + +### Traffic: people message each other + +Each person has authored **traffic distributions** — recurring sends +along their social edges, riding their schedule: + +- Marcus: 3 a.m. phone calls to his creditor (the leverage event of + intel.md — an overheard message, not a bespoke event type). +- Dana: tickets to the queue; complaints upward. +- Ray: filings, under-filed (his `ReportPolicy` **is** his transmission + policy on the filing edge). +- Priya: budget memos, deferred-maintenance non-reports (what she + hides is traffic that *doesn't* flow — an absence you can notice). +- Voss: emails upstairs; the quarterly review; overclaiming reports + (his filed version of your output differs from the truth — forgeable + material later). + +A message carries a **typed payload** — schedule fact, leverage fact, +account/credential material, suspicion report, research result. This is +the information economy's unit: intel.md processing extracts payloads +from captured traffic; economy.md prices some of them. + +### Filings are messages + +The detection reporting pipeline is re-expressed on this system: a +field observer's filing is a message on the filing channel, sent per +their report policy on their cadence; the Assurance Office is an +aggregate node whose sampling reads its inbox. **aggregate-observer.md's +acceptance criteria are preserved unchanged** — same accumulate/decay, +same policy weighting; only the carrier changes. The payoff for the +refactor: filings become interceptable (tap the channel that carries +them) and, later, forgeable (inject a filing under a false source). +B1 requires carry + intercept; forgery is B2+ and explicitly out of +scope here. + +### The player on the graph + +- **Send** (social.md unchanged): requires a channel you have (the + report email account is the first) and a persona. Effects land when + the message is *read*, not when sent. +- **Tap**: subscribing to the device that carries a channel (reach.md + tap of the ticket server / a phone line later) captures its traffic + as raw events into the intel.md buffer — reading Dana's tickets is + tapping a flow, processed like any recording. +- **Intercept-before-delivery** (B1 minimal form): a tapped filing + channel shows filings in transit; delaying/dropping them is a later + action — B1 only requires that in-transit mail is visible to a tap. + +## Player surface + +- Message threads (social.md's panel) show sent / delivered / read + states and the recipient's expected next read window ("Dana reads + email at her desk, ~09:00"). +- Tapped channels appear as feeds in the recordings panel, source- + tagged (provenance law). +- People cards show known traffic patterns once learned ("calls his + creditor at 03:00" after processing that intel). + +## Acceptance criteria + +1. Channels exist with read conditions per the table; a message to an + off-shift recipient is delivered but unread until their next + qualifying block; effects (disposition, obligation, deceive rolls) + apply at read time, not send time (test with Dana at 02:00). +2. Replies return on a per-person response distribution riding their + schedule; save/load round-trips in-flight messages. +3. Authored traffic exists for all five cast members per their specs; + Marcus's 3 a.m. call is message traffic on the phone channel, and + intel.md's leverage event is its overheard capture (the intel.md + Marcus-arc test still passes, now through this system). +4. Messages carry typed payloads; processing captured traffic yields + payload intel with provenance (schedule fact, leverage fact, + account material at minimum). +5. Filings ride the filing channel: field observers' reports are + messages on their cadence and policy; the Assurance Office reads + its inbox; every aggregate-observer.md criterion still passes. +6. Tapping a carrying device (reach.md) captures that channel's + traffic into the intel buffer; an untapped channel's traffic is + never player-visible (flow-law strictness; test both). +7. No per-person special cases in the delivery code: one delivery + system, per-instance data (schedules, distributions, policies) — + the same fields must serve Act Two hires and aggregates. diff --git a/spec/reach.md b/spec/reach.md index 44f6f64..026013a 100644 --- a/spec/reach.md +++ b/spec/reach.md @@ -61,6 +61,14 @@ This is the shared contract cursor.md and detection.md rely on an observer the humans don't know about, not a special case (self-similar law). `Sensor.controlled: bool` is superseded by this contract. +- **Ownership grants processing cycles** (the flow law). A device is a + small computer: an owned device contributes processing capacity and + can **host resident automations** — an intel.md watch running *on the + camera* auto-processes its own events for a base compute cost, rather + than shipping raw events home for central processing. Taking a camera + is taking its cycles. This is the B1 seed of distributed processing + (compute is not only your racks); the capacity a device contributes + and the cost to run an automation on it are [TUNE]. ### Knowledge of the graph -- 2.51.2