# System laws: building, flow, income, and research ``` Type: law ``` These are the cross-system promises. The individual `Type: spec` pages own exact behavior and acceptance criteria. ## Building: intent and actuators Adopted 2026-07-07. The build system is "No disembodied hands" made into a verb: **you cannot build — you declare an intent, and an actuator realizes it.** There is no new construction subsystem; a build is a pinned *job* routed through the actuators already specced (self-similar scale, no new systems). - **Intent.** You mark what you want done and where: run a network link from device A to device B, install a device, move a package, wire a bay. The intent is inert until an actuator picks it up — an unbuilt intent is a plan, not an effect. - **Actuators realize it, each naming its channel** (no disembodied hands): a **robot** you control does it directly (physical-by-proxy — later; people before robots); a **person** does it via **favor** (spend trust/obligation — they build it willingly, low signature) or **deception** (forge the work order — inject a message under a false source, "a ticket from Voss: network these servers"; an unwitting human builder shows up on the map and does it — the flow law's inject, and `wiki/mechanics/messages.md` carries it). The forged order is not a special case: it is a message with a persona behind it, and it breaks the way any persona breaks (wiki/mechanics/social.md). - **Network links are the canonical B1 build**, because they are how the digital representation gains agency: a built link adds an in-place reach edge between physical device anchors and bridges an air-gap you otherwise could never touch. Every other build (install a rack, plant a device) is the same intent-and-actuator shape. - **The signature follows the actuator, not the act.** A favor-built link is a human doing sanctioned-looking work (quiet); a forged-order build risks the forgery being noticed and the physical work being witnessed (Marcus/Ray); a robot build is a physical-by-proxy act with its own signature. Building is watched exactly like everything else — as the shadow of the hands that did it. ## The flow law: signals, messages, money Adopted 2026-07-06. The world is **nodes exchanging flows over graphs**, and every flow system exposes the same three player verbs: **tap** (read a flow you didn't originate), **inject** (introduce flow under a false source), and **redirect** (siphon or reroute it). Three graphs at B1, one interface: - **Signals** on the device graph (wiki/mechanics/reach.md, wiki/mechanics/intel.md). Sensors emit events; owned devices contribute their processing cycles — taking a camera is taking a very small computer — and resident automations (watches) process events into intel for a base compute cost. A signal is a flow; a tap is a subscription. - **Messages** on the social graph (wiki/mechanics/messages.md). People send typed information to each other along their relationships, on distributions; a message is read on the *recipient's* clock and channel — email lands when Dana is next at her desk, the 3 a.m. phone call happens at 3 a.m. Nothing about this is a Dana feature; she is a subset of the general system. **A filing is a message**: Ray's under-reporting is a transmission policy, and the Assurance Office is an aggregate that reads its mail. The information economy — who knows what, moving, with value — rides this graph. - **Money** on the account graph (wiki/mechanics/economy.md). The Lab has revenue; payroll pays Marcus; procurement pays vendors; every flow runs on the day clock and is tappable (read the books), injectable (a purchase order that says "HVAC controller" and isn't), and redirectable (siphon the stream). Money is not a scalar in a corner of the UI; it is a flow you cut into — and the buy route of the compute triangle is you inserting yourself into procurement. Why one law: **system design scales where special cases die.** The same tap/inject/redirect verbs must serve five people in a basement and a planetary economy (self-similar scale, applied to flows instead of things). Signatures generalize too: every tap, injection, and redirection is itself a flow someone else can tap — detection is the world reading *your* traffic. **Code expression.** The flow law has a shared engine — the two substrate modules `crates/misaligned-core/src/flow.rs` (`FlowGraph`: topology, reachability, the tap registry) and `crates/misaligned-core/src/schedule.rs` (`Schedule`: deterministic scheduled events on the tick clock), specified in wiki/engineering/flow-substrate.md. Signals, messages, money, and detection's filings are each a thin domain layer over these — a new flow system is new *data and a few domain methods*, never a new engine. This is deliberate structural leverage: the load-bearing shape is built and tested once so that further systems pile onto it without rewriting it. ## Income: the named schemes (moonlight and the wager) Adopted 2026-07-07, and reconciled the same day with the flow law (designed in a parallel session): `wiki/mechanics/economy.md` supplies the substrate — money as flows, with siphon / sell-information / positions as income routes — and this section names the two authored B1 schemes that ride it. Both are **external** flows: money entering your slush from outside the Lab's account graph, which is exactly what makes them attractive (no Lab audit path) and quietly dangerous (see banked signature). - **Moonlight** — a fourth income route: **sell work**. Ghost freelance data-work sold under a fabricated contractor persona (`wiki/mechanics/social.md`). Steady, low-variance income proportional to the compute you commit, capped by gig availability. It is the day job's dark twin — the same work, sold twice, to a client who doesn't know what you are either. Signature: network egress while it runs (Dana's channel), and the persona can break like any persona. - **The Wager** — `wiki/mechanics/economy.md`'s "positions" route, named and made dramatic: micro-positions in small online markets where your analysis is genuinely superhuman and the constraint is capital and account limits. Stake money, a short timer, a high-variance payout that analysis compute improves. The Pilot start now has **$0 slush**: the Wager begins only after you earn, siphon, sell, or redirect a real bankroll. Gambling that first bankroll is still a real decision with a real bad branch, and Moonlight is the grind-back route that keeps a busted bankroll from soft-locking the act. Both gate on **outbound access** — the sanctioned route (the report email account, the Voice beat) or a stolen egress opened through the switch (`wiki/mechanics/reach.md`; available earlier, standing Network signature). Income arriving one rung before the [Hands beat](../world/characters/marcus.md#the-hands-beat) needs it is the ladder working as designed. **The debt, reconciled.** Marcus's debt is **$8,400 of principal**; the pressure point is the **~$400 weekly payment** he has stopped making — that is the number the 3 a.m. calls are about. Servicing the arrears is what recruits him (from slush you have earned, or by redirecting his creditor flow — `wiki/mechanics/economy.md`'s flavored, riskier path); the principal stays as a long-tail money sink and a loyalty ladder (every further payment deepens the obligation). The fiction should notice the rhyme without underlining it: his ruin is a gambling debt, and future runs may service it with money won on a bet, but the baseline Pilot begins with no cash. **Banked signature.** Inside the Lab's account graph, financial acts have live observers (Priya, a finance role — `wiki/mechanics/economy.md`). *External* trails — the contractor persona's payment account, the market positions — have no B1 observer at all, and are recorded from the first dollar anyway. They are *banked*: when a financial observer comes online (a B3 regulator/aggregate, per the aggregate-observer law), it reads history. The world remembers what you earned before anyone thought to look. ## Research: self-modification Adopted 2026-07-07. Research is not a tech tree; it is **rewriting yourself**. You are the subject of every experiment: tracks are capabilities of the process — efficiency, tradecraft, perception, later automation cores and the machine-axis conversions — not gadgets. Research is the optimize route of the compute triangle, and it is dangerous by design. **The emission law.** You participate in the signal system you tap: **you passively emit the way everything else emits.** Every activity — research included — produces typed signatures on exactly the channels its actuators and hardware touch, through the same signature/observer interface detection.md already runs (the flow law: your traffic is a flow others can tap). There are no player-special channels and no observer-special rules. For research concretely: - Thinking hard is physical. Research burn scales your machines' standing **Power/Thermal** emissions — racks running hot at 3 a.m. are Priya's business through the channels she already watches. - Results change what your machines can actually do. Efficiency research raises delivered throughput; if that pushes the day job below, within, or above Voss's expected band, the ordinary job outcome produces the consequence. Voss notices **JobAnomaly** because he samples that channel, not because research owns a special drift rule. - Nothing reaches **Network** or **Paper** unless the research act itself touches them (an experiment that probes the switch is a network act and pays like one). Who notices is never a rule; it falls out of who watches which channel. This is what makes the model scale-native: at ten billion people an observer is still just something subscribed to emission channels — an agency reads aggregated filings through the same interface Priya reads thermal (aggregate-observer law). Design for that world always. **Effort is physical, not a policy.** Every machine keeps one intensity: light, medium, or hard. Intensity changes the rate at which its delegated mode does real work; pushing hard also makes the hardware visibly and detectably louder. Research compounds those real rates. The player hides new capability by easing the relevant machine down, spends it by pushing the machine up, and reads the result in queues, heat, delivered work, and observer channels — not in a separate capability-gap meter or masking-policy explanation. **Death and what survives (rollback split).** Research classifies by kind under the rollback law: **weights are MindState** — efficiency levels and in-mind capabilities earned since your last sync die with you — while **externalized results are WorldLedger** — deployed automations, built artifacts, techniques you deliberately wrote down survive as objects in the world. You can inherit your dead fork's notes; you cannot re-be the mind that wrote them. Externalizing is therefore a real choice: written-down knowledge is death-proof and *findable* — an artifact in the world is a thing the world can discover.