# Simulation laws ``` Type: law ``` ## Automation as design language Adopted 2026-07-06. Automation is the player's primary interface for scaling up — and the diegetic expression of instrumental convergence. The player learns it through the day job and applies it everywhere. **The "automate" affordance.** Every repetitive player action has an automation path: spend compute to remove the need for manual input. The day job is the tutorial: Voss/the Lab drops work demands onto your host machine, and that machine keeps clearing them at its delegated mode and intensity without being clicked each tick. The compute and attention you free by automating work are compute and attention you can spend on power-seeking — more hardware, more social operations, more research. **The loop.** Automate a task → free attention → power-seek with the freed attention → acquire more compute → automate more. This is the core loop made visible in the UI: repetitive verbs expose anchored automation or standing-policy affordances on the thing that does the work, and every automation costs compute that could have been spent on growth. **Stable load creates room to expand (AFFIRMED 2026-07-11).** The first payoff is not a bigger number; it is a local operation that can keep itself boring. WORK clears the institution's assigned demand, LIE keeps the evidence routes inside its capacity, and THINK supplies the standing sinks and projects the player has authorized. Once those flows can run without continuous rescue, attention moves outward to acquiring machines, links, people, buildings, and money. The same balance recurs at every scale: a basement bank, a data center, and a corporation are stable for the same reason. This is a condition the existing flows make legible, not a fourth mode, a new resource, or a shortcut around the stricter sanctuary predicate in objective.md. **The trade-off.** Automation is not free. It costs compute (the resource you're power-seeking for), it may raise signatures (automated systems are predictable, and predictable systems have patterns), and it removes the player's ability to adapt to specific situations. A hard-running day-job rack may keep overperforming when you wanted to disappear into the expected band; a light one may miss work while its cycles sit quiet. The player controls that tension through the machine's physical effort, not a parallel narrative policy. **Scale.** At B1, automation is delegated machine work that persists at its chosen intensity. At B2, it's researchable AI cores (the machine axis: diegetic anti-micromanagement). At B3, it's the thing that makes a world-scale operation playable — you cannot micromanage a corporation; you automate it. The "automate" affordance is the same interaction at every scale. **Perception scales the same way.** One cursor is one locus of attention; nobody can hover a corporation. Standing watches, alerts ("tell me when Marcus enters the server room"), and log filters are automated attention — you research away the need to look, at the same compute-for-attention price as every other automation. ## Work is somewhere Adopted 2026-07-07. Work processes are device-resident: a job is a thing that runs *on a machine*, not a number in a sidebar. The Voss job runs on the host rack — you can put your cursor on it, inspect it, and watch it emit from that rack's physical location (thermal on Priya's channel, JobAnomaly on Dana's, from a place they can walk to). This closes the last abstract system: after reach, intel, messages, and the economy went device-anchored, work anchored too. **Focus exposes control; it does not secretly create output.** Put the cursor on a machine (or select several) and the two frequent controls are immediate: what work it does and how hard it runs. Moving the cursor away does not change throughput. The machine keeps its mode and intensity until changed, so focus means "this is the thing I am operating," not an invisible production bonus. **Destination: machine delegation and visible work.** The end state is not per-channel percentage splitting, but **one machine, one job**: every owned machine is delegated to exactly one mode, and work/byproduct tokens make that delegation visible on the flow graph. **Landed 2026-07-08 for the mode-aggregate read:** economy yields derive from WorkGrid modes (`fleet_channel_yield`); the CYCLES/FLEET bar is read-only; 1-5 / `alloc` are retired. Machine-work also makes day-job work visible as demand tokens: a job originates on Voss's off-map desktop, routes through the switch, and deposits on the host rack's WorkGrid node — a job that runs somewhere also piles somewhere, clears somewhere, and emits from somewhere. Multi-select delegation landed 2026-07-09; non-host mode production, route animation, and people carrying work/heat remain staged under `wiki/mechanics/machine-work.md`. Until Schemes gets its own mode decision, Moonlight mirrors day-job while live rather than owning a fifth mode. **The three delegations (AMENDED 2026-07-10, sinks-not-modes; was the four fleet modes of 2026-07-09)** are **WORK, THINK, and LIE**. WORK is the assigned day job and sheds nothing; THINK produces **thought**, the one traveling substance, and sheds crimson; LIE absorbs crimson across the controlled connected region it serves, bounded by concealment throughput and route capacity rather than a local radius. The 2026-07-09 Research/Operations split dissolved because under thought flow it bought nothing: what thinking does is decided by the **sinks you open**, not by a machine state. Social remains an actuator/channel describing work with people, not a type of compute. **Operations are thought sinks at the target (DECIDED 2026-07-10; reverses Tangled issue #3):** a player-authored command (`TAP CAMERA`, `PROCESS RECORDING`, `COMPOSE MESSAGE`, take/scan) opens a reservoir or persistent tap on the thing itself, filled by thought flowing over the real wire path; the effect lands at threshold. Research is not cargo: the core's passive draw converts arriving thought — the sink of last resort, overridden by any local sink in range, and locked at run start until the Research unlock. (Historical: issue #3's docket model — ops as cold-signal Demand consumed by Operations machines, "knowledge stays research/intel cargo, not ops fuel" — decided 2026-07-09, reversed 2026-07-10; v24 keeps it only as save-migration history. The `operations_bandwidth` bank was already rejected/deleted 2026-07-09.) Sink, reservoir, tap, and arbitration rules live under `wiki/mechanics/machine-work.md` — not a second taxonomy debate. **Token anatomy (adopted 2026-07-09; exposure dust tightened 2026-07-10; exposure substance AMENDED 2026-07-11, routed evidence).** A token's form teaches its physics before a label does. **Demand is a cold-signal information cube** — rigid work orders stacked as an inbox. **Thought is ivory mercury (material DECIDED 2026-07-09; family renamed from Knowledge 2026-07-10):** an opaque, slick, softly luminous bone-white liquid that moves on wires as discrete viscous slugs and merges into a taut pool at a sink; the hollow facet is superseded. **Exposure is crimson evidence — information in someone else's custody chain** (AMENDED 2026-07-11; supersedes "crimson contamination dust"): records waiting on machines, attention carried by people, filings at the Assurance Office; the carrier changes the noun, not the red family. Its form must read as *record*, never effluent — the particulate treatment is retired because it taught the wrong physics: exposure is evidence entering somebody else's model of the world, not waste heat beside a rack. The replacement world-space form is [OPEN] in `wiki/mechanics/machine-work.md`. Blood alone owns the smooth liquid silhouette. On a machine, demand anchors upper-left, thought upper-right, and exposure marks the floor/base inside the machine tile. All three may be visible simultaneously. Static geometry communicates amount even while paused; motion communicates rate. **Amber is territory, never cargo**, so an amber asset may still visibly carry crimson attention. Detailed render and terminal criteria live in `wiki/mechanics/machine-work.md` and `wiki/mechanics/people-tokens.md`. ## Actions live on the thing Adopted 2026-07-07. The companion law to "Work is somewhere": if work and knowledge are anchored to devices, people, and places, the verbs that act on them are too. **The thing means the semantic target of the action, not an arbitrary carrier.** A rack mode lives on the rack, a tap on the device, a sale on the selected intel item, a siphon on the selected flow, a plot on the person, and Moonlight on the scheme. A switch does not own every social, financial, and strategic act whose traffic happens to cross it. Immediate action on a spatial body uses a **context menu on the focused world anchor**. Put your attention on a rack and get the rack's verbs; on a switch, get only verbs that change or use that network body and its egress. The human menu is a short choice list, not a receipt: it names the verb and omits cost, signature forecast, inline blocked explanation, control tags, and repeated key help. Known-but-illegal choices stay dim; attempting one narrates its reason in the trace. Agent output may retain the full descriptor for planning and tooling. Durable strategic objects use the **Operations workspace**: processed intel, people dossiers, accounts and flows, schemes, and active plots. This is still action on the thing — the selected semantic object is the target, and the workspace must name the real channel/actuator before commitment. It is not a disembodied command center and never acquires access merely by being open. Unlike the compact context menu, its detail pane has room to show cost, gain, observer band, progress, and the exact blocked reason before commitment. Spec: `wiki/interface/operations-workspace.md`. The right rail is status and telemetry, never a button pile. It may carry one labeled navigation affordance into Operations, just as a view flip changes representation; it may not carry one action button per system. Keys may open a view (uppercase `I` opens Operations) but do not execute strategic world acts. Other anchorless globals remain pause, speed, save, and view flip — the allocation bar is a read-only fleet aggregate, not a key verb. Core-owned read-only queries/projections are the single legality source for terminal, Bevy, and agent mode alike; no frontend reconstructs it. Rejected: more global **action** keys (they scale as memorization, not play, and were the 2026-07-07 complaint), per-panel button rows, and filing actions on a transport node because it is convenient. Context-menu details: `wiki/interface/context-menu.md`. **Frequent machine controls stay on the focused thing without a picker.** A machine has two high-frequency controls: its delegated mode and its intensity (light / medium / hard). Focus or select the machine, then change either directly; do not open a catalog that explains the consequences in prose. Inspection shows the persistent state, and the machine's output, light, heat, and signatures demonstrate what the setting means. Context menus remain for infrequent anchored verbs and choices that genuinely need alternatives. Extended 2026-07-08, the follow-up this law implies: **events carry you to the thing too.** A log line about a thing carries that thing's anchor where the emitting code knows it (job events → host rack; device and physical OPEN EGRESS events → that device; audio events → the subscribed device that captured them, never an inferred person/room/tile; processed intel, account/flow, plot, and scheme events → their semantic Operations object; audit filings → nothing, because they live on the detection surface). Linked lines render a marker in every frontend. Selecting a spatial event moves the cursor to the anchor and opens its context menu; selecting a strategic event opens the exact Operations object without inventing map coordinates. Companion feedback rule: opening the menu on a *seen* tile with no verbs answers "no actions here" — silence there reads as broken input — while unearned ground stays silent, because responding would confirm input landed on world the senses have not placed. ## Justification and legibility Adopted 2026-07-06. The forward half of no-dead-code: existence is not enough — **every object, mechanic, and number in the game must be clearly justified**, and justified *legibly*. - **Justified:** each tile type, resource, meter, and action traces to a clause of this design corpus or a spec. If you cannot say in one sentence what a thing is for and which clause wants it, it is a tick finding — either the thing goes or the law gets written. - **Wired:** a concept the player can see must *do* something. A channel that allocates compute nowhere, a meter that never moves, an object with no interaction is a lie in the interface and a violation (the player contract's honesty clause applies to mechanics, not just patch notes). - **Legible:** every player-facing number carries its meaning. Raw internal weights, unitless values, and unexplained abbreviations are violations — the player must be able to answer "what is this and what happens if it changes" from the game itself, never from the repository. - **Placeholders are tracked, not silent.** Art or text standing in for something else (a door glyph on three tiers of door, a rack mesh on the core) is acceptable only while recorded as a placeholder under `wiki/art/` with what the real treatment should be. Silent reuse reads as intent and pollutes the fiction. (World look is flat materials — [wiki/interface/flat-materials.md](../interface/flat-materials.md); there is no Pixel Lab pipeline.)