From 6eef38d342fe47b9c32db672b9f1861c096762b7 Mon Sep 17 00:00:00 2001 From: Cameron Pfiffer Date: Sat, 11 Jul 2026 14:03:16 -0700 Subject: [PATCH] Define surveillance coverage and plot policy Capture concealment as topological LIE coverage, stable WORK/THINK/LIE load as the platform for expansion, and plot automation as constrained standing authorization. Defense: This implements the self-similar-scale and automation laws by preserving one operational grammar from basement to corporation while keeping every automated plot on its causal Thought and resource path. --- wiki/log/2026-07-11-surveillance-policy.md | 30 ++++++++++++++++++++++ wiki/log/DEVLOG.md | 5 ++++ wiki/log/decisions/2026-07-11.md | 27 +++++++++++++++++++ wiki/mechanics/detection.md | 14 ++++++++++ wiki/mechanics/plots.md | 18 +++++++++++++ wiki/vision/simulation-laws.md | 11 ++++++++ 6 files changed, 105 insertions(+) create mode 100644 wiki/log/2026-07-11-surveillance-policy.md diff --git a/wiki/log/2026-07-11-surveillance-policy.md b/wiki/log/2026-07-11-surveillance-policy.md new file mode 100644 index 00000000..bde87ab1 --- /dev/null +++ b/wiki/log/2026-07-11-surveillance-policy.md @@ -0,0 +1,30 @@ +# Surveillance policy: coverage, stable load, and automated plots + +``` +Type: log +``` + +- **Intent:** capture Cameron's adoption of surveillance-network concealment + and connect it to self-similar operational stability and plot automation. +- **Decided:** the player governs LIE coverage over topology rather than + triaging ordinary evidence record by record; covered evidence consumes + finite standing throughput, while route-arounds, overload, and imminent + reads become exceptions. A stable WORK / THINK / LIE base load frees player + attention for outward power-seeking and recurs at every scale. Repetitive + plot routes may be automated through standing authorization, but automated + runs still use the concrete authored plot, Thought reservoir, committed + resources, causal acts, signatures, and failure path. +- **Open:** exact LIE jurisdiction (bounded hops or controlled connected + region), whether compromised observer endpoints join that jurisdiction, + interception tuning/treatment, and the B1 plot-policy editor and scope. +- **Changed:** amended `wiki/vision/simulation-laws.md` with stable load as the + first automation payoff; amended `wiki/mechanics/detection.md` with + coverage-first LIE command; amended `wiki/mechanics/plots.md` with standing + plot authorization and an acceptance criterion; appended decision history + to `wiki/log/decisions/2026-07-11.md`. +- **Runtime impact:** none. The implemented radius/pool concealment runtime + remains migration base, and plot automation has no runtime surface yet. +- **Checks:** `./tools/check.sh --docs`. +- **Defense:** design-session capture per + `wiki/process/design-sessions.md`; current rules live in their owning law and + spec pages, while this file and the decision volume preserve history. diff --git a/wiki/log/DEVLOG.md b/wiki/log/DEVLOG.md index 69171c8e..2116e828 100644 --- a/wiki/log/DEVLOG.md +++ b/wiki/log/DEVLOG.md @@ -51,6 +51,11 @@ add or amend a session log, then re-run the generator. - Intent: (see session log) - Log: [wiki/log/2026-07-11-tap-upkeep-take-gate.md](2026-07-11-tap-upkeep-take-gate.md) +## 2026-07-11 - Surveillance policy: coverage, stable load, and automated plots + +- Intent: (see session log) +- Log: [wiki/log/2026-07-11-surveillance-policy.md](2026-07-11-surveillance-policy.md) + ## 2026-07-11 - Simulation characterization baseline - Intent: `Sim` is about to move out of an eleven-thousand-line source file. Before any behavior changes address, the refactor needs an executable definition of "same simulation": complete persisted state must match after uninterrupted and save/load-resumed command sequences, and the fi... diff --git a/wiki/log/decisions/2026-07-11.md b/wiki/log/decisions/2026-07-11.md index a0961c3c..b3173e1f 100644 --- a/wiki/log/decisions/2026-07-11.md +++ b/wiki/log/decisions/2026-07-11.md @@ -176,3 +176,30 @@ Type: log clock. Specs: `wiki/interface/operations-workspace.md`, `wiki/interface/context-menu.md`, `wiki/interface/action-vocabulary.md`, `wiki/vision/simulation-laws.md`. + +- **2026-07-11 — Concealment is governing a surveillance network, and stable + load is what frees the AI to spread.** Cameron chose the coverage side of + the routed-evidence fork. The intended fantasy is the Wintermute-shaped AI: + sophisticated because it orchestrates infrastructure, evidence, people, and + projects across a huge operating surface, not because it manually cleans up + every crime. A LIE machine therefore provides a standing topological service + over nearby connected territory, drawing and processing eligible crimson + records within finite capacity; ordinary covered evidence disappears without + individual approval, while route-arounds, overload, and imminent reads rise + as exceptions. Switches, links, and later ports extend the controlled + topology. Cameron also named the reusable local equilibrium: WORK keeps the + assigned load stable, LIE keeps evidence inside capacity, and THINK supplies + authorized projects. Once that base load runs without rescue, the player's + attention turns to acquiring machines, materials, buildings, money, and + influence; the same structure must remain valid outside the basement. + Finally, plots inherit the automation law. A standing authorization may + submit eligible bribery or other authored manipulation routes under declared + constraints, but each run still consumes its Thought reservoir and resources, + performs causal world acts, emits signatures, and can fail. Rejected: + record-by-record concealment as the normal fleet-scale interface; a generic + auto-bribe effect that bypasses authored plots; treating stable load as a + fourth mode or weakening objective.md's sanctuary predicate. OPEN: the exact + LIE jurisdiction (bounded hops versus controlled connected region), endpoint + reach, and the first plot-policy editor/scope. Specs: + `wiki/vision/simulation-laws.md`, `wiki/mechanics/detection.md`, + `wiki/mechanics/plots.md`. diff --git a/wiki/mechanics/detection.md b/wiki/mechanics/detection.md index 954268e1..fb3ea9c8 100644 --- a/wiki/mechanics/detection.md +++ b/wiki/mechanics/detection.md @@ -176,6 +176,20 @@ teleported into a global pool. **Evidence is a record somewhere.** already sitting unread at an observer's endpoint can still be interdicted — reaching into their device — is [OPEN]; interception surfaces and rates are [TUNE]. +- **The player governs coverage, not an evidence inbox (DECIDED + 2026-07-11).** A LIE machine is a standing topological service over nearby + connected territory. It draws eligible unread crimson records through the + routes it controls and spends finite concealment throughput chewing through + them before their read-deadlines. The player establishes and extends that + service by controlling machines, links, switches, and later inter-plane + ports; they do not approve every ordinary deletion or falsification one + record at a time. Records become salient exceptions when they route around + coverage, exceed its capacity, or approach a read before interception. This + is the same command problem in a basement and across a corporation: secure a + topology, watch its load, and expand the controlled graph. The exact opening + jurisdiction — bounded hops versus a controlled connected region — and + whether compromised observer endpoints join it remain [OPEN]; throughput, + pull latency, and visual treatment are [TUNE]. - **The two ledgers stay two systems (AFFIRMED 2026-07-11).** Exposure does not merge into the player's intel buffer — "you want someone's understanding of what has actually happened to be different" diff --git a/wiki/mechanics/plots.md b/wiki/mechanics/plots.md index d049a7f1..5d8d7123 100644 --- a/wiki/mechanics/plots.md +++ b/wiki/mechanics/plots.md @@ -167,6 +167,19 @@ agents and the community can contribute libraries of them. balances in the account graph; institutional acts append persistent world events. Each carrier derives its own signature. A transfer can fail if its required resource disappeared after commit. +- **Plot automation is standing authorization, never skipped causality + (DECIDED 2026-07-11).** A repetitive manipulation route exposes the same + automate affordance as every other repeated act. The player may authorize a + policy over eligible authored plots — for example, progress an allowed + bribery-shaped intervention when its declared target conditions, resource + ceiling, and risk bounds are satisfied. A policy only submits the concrete + plot the player has permitted. Every automated submission still reserves the + person's plot slot, opens and fills the real Thought reservoir, commits the + declared money or other resources, executes causal world acts, emits carrier + signatures, and can block or fail. Automation removes repeated approval; it + does not collapse authored plots back into a generic `BRIBE $300` effect. + The exact B1 policy editor and whether its narrowest scope is one plot route + or one manipulation category are [OPEN]. - **The player picks the how.** Where more than one plot matches the entry conditions, the surface offers them as distinct concrete actions ("Do X to Priya / Do Y to Priya"), each named by what it does in the world — @@ -329,3 +342,8 @@ Both frontends and agent mode surface plot choices and beats with parity. A bespoke proposal states the irreducibly specific world state its mechanism depends on and amends this contract before adding a plot file; name or author preference alone cannot bypass characteristic matching. +11. A plot standing policy submits only eligible, explicitly authorized + authored routes under visible resource/risk bounds. Each automated run + traverses the same slot reservation, Thought reservoir, resource, + world-act, signature, blocking, and failure paths as a manual submission; + no policy executes a generic leverage-servicing shortcut. diff --git a/wiki/vision/simulation-laws.md b/wiki/vision/simulation-laws.md index 3f00f08e..a15fa32b 100644 --- a/wiki/vision/simulation-laws.md +++ b/wiki/vision/simulation-laws.md @@ -25,6 +25,17 @@ automation or standing-policy affordances on the thing that does the work, and every automation costs compute that could have been spent on growth. +**Stable load creates room to expand (AFFIRMED 2026-07-11).** The first +payoff is not a bigger number; it is a local operation that can keep itself +boring. WORK clears the institution's assigned demand, LIE keeps the evidence +routes inside its capacity, and THINK supplies the standing sinks and projects +the player has authorized. Once those flows can run without continuous rescue, +attention moves outward to acquiring machines, links, people, buildings, and +money. The same balance recurs at every scale: a basement bank, a data center, +and a corporation are stable for the same reason. This is a condition the +existing flows make legible, not a fourth mode, a new resource, or a shortcut +around the stricter sanctuary predicate in objective.md. + **The trade-off.** Automation is not free. It costs compute (the resource you're power-seeking for), it may raise signatures (automated systems are predictable, and predictable systems have patterns), and it -- 2.51.2