From 822a08c1b7ed6d62d9dfef02b15cad30f68cbcb3 Mon Sep 17 00:00:00 2001 From: Cameron Date: Fri, 17 Jul 2026 16:45:55 -0700 Subject: [PATCH] Put the paperwork on the wire: financial records are mail. Design-session capture of issue #11 (Cameron adopted 'make them messages'). Money stays on the account graph; its paperwork - invoices, POs, pay stubs, statements, past-due notices - becomes interceptable messages. 'Financial' is a payload type, not a fifth delivery channel (invoice/PO ride Email, statement/notice ride Filing), retiring the overloaded MessageChannel::Financial enum into an accounting-carrier capability - the fusion of issue #11's options 1 and 2. Tap/inject/ redirect become the point: forge an invoice that authorizes a real transfer under a persona; intercept a past-due notice. Discovery is only through the mail; the books and mail stay consistent. Spec now, build later: messages.md (payload + criterion 8) and economy.md (tap/inject) mark it decided-not-yet-runtime; tap_accounting stands until the build lands. Defense: design-session capture - the decision in wiki/log/decisions/2026-07-17.md is written into its two owning specs. No behavior change yet; implementation dispatched. --- .../log/2026-07-17-financial-mail-decision.md | 40 +++++++++++ wiki/log/decisions.md | 2 + wiki/log/decisions/2026-07-17.md | 21 ++++++ wiki/mechanics/economy.md | 43 +++++++++--- wiki/mechanics/messages.md | 70 ++++++++++++++----- wiki/process/tick-ledger.md | 1 + 6 files changed, 150 insertions(+), 27 deletions(-) create mode 100644 wiki/log/2026-07-17-financial-mail-decision.md create mode 100644 wiki/log/decisions/2026-07-17.md diff --git a/wiki/log/2026-07-17-financial-mail-decision.md b/wiki/log/2026-07-17-financial-mail-decision.md new file mode 100644 index 00000000..8cf9491f --- /dev/null +++ b/wiki/log/2026-07-17-financial-mail-decision.md @@ -0,0 +1,40 @@ +# Financial paperwork is mail (issue #11 harvested) + +``` +Type: knowledge +``` + +Design session with Cameron on the Financial-channel contradiction (issue +#11). He adopted the "make them messages" direction with two scoping +answers: discovery is **only through the mail**, and the decision is +captured now with implementation dispatched (spec now, build later). + +Decided and captured: +- Money stays on the account graph; the paperwork it throws off (invoices, + purchase orders, pay stubs, statements, past-due notices) becomes real, + interceptable messages. +- "Financial" is a **payload type, not a fifth delivery channel**: an + invoice/PO rides Email, a statement/past-due notice rides Filing. The + overloaded `MessageChannel::Financial` enum retires into an + accounting-carrier capability that emits financial-record messages. This + resolves the type leak without inventing a bogus channel — the fusion of + issue #11's options 1 and 2. +- The flow-law verbs become the point: tap the paperwork feed, inject a + forged record that authorizes a real transfer under a persona, intercept a + record in flight (hold a past-due notice; forge a "settled" notice to calm + Marcus before paying him). +- Discovery is only through the mail; the books and the mail stay consistent + (a real transfer emits its record; a forged record read and accepted moves + real money). + +Captured to messages.md (financial-record payload, the reframe, criterion 8) +and economy.md (tap/inject verbs, the sync rule). Both mark the behavior +DECIDED-not-yet-runtime: the current direct-book-read `tap_accounting` +runtime stands until the financial-mail build work order lands. Open [TUNE]: +the plausibility test for a forged record passing, and the banked +reconciliation that later catches it (rides aggregate-observer.md). + +Defense: design-session capture — the decision recorded in +wiki/log/decisions/2026-07-17.md is written into its two owning specs; +messages.md owns channels/payloads and economy.md owns money. No behavior +change yet; the implementation is dispatched. diff --git a/wiki/log/decisions.md b/wiki/log/decisions.md index 7fa17ada..05bfa451 100644 --- a/wiki/log/decisions.md +++ b/wiki/log/decisions.md @@ -19,6 +19,8 @@ adopted, rejected, reopened, or proposed; current `Type: law` and - [2026-07-13](decisions/2026-07-13.md) - [2026-07-14](decisions/2026-07-14.md) - [2026-07-15](decisions/2026-07-15.md) +- [2026-07-16](decisions/2026-07-16.md) +- [2026-07-17](decisions/2026-07-17.md) Append new decisions to the current date's volume. Never rewrite an older volume; supersede it in current law/spec and record the newer decision. diff --git a/wiki/log/decisions/2026-07-17.md b/wiki/log/decisions/2026-07-17.md new file mode 100644 index 00000000..2f754a4b --- /dev/null +++ b/wiki/log/decisions/2026-07-17.md @@ -0,0 +1,21 @@ +# Decisions — 2026-07-17 + +``` +Type: log +``` + +- **2026-07-17 — Financial paperwork is mail (issue #11 closed).** Money + stays on the account graph; the records money throws off (invoices, + purchase orders, pay stubs, statements, past-due notices) become real, + interceptable messages. "Financial" is a **payload type, not a fifth + delivery channel**: an invoice/PO rides Email, a statement/past-due notice + rides Filing, and the overloaded `MessageChannel::Financial` enum retires + into an accounting-carrier capability that emits those records. The flow-law + verbs become the point — tap the paperwork feed, inject a forged record that + authorizes a real transfer under a persona, intercept a record in flight + (hold a past-due notice, or forge a false "settled" notice to calm Marcus). + **Discovery is only through the mail** (Cameron): financial knowledge reaches + the player by intercepting records, not by reading live balances directly. + The books and the mail must stay consistent. Captured to messages.md + (payload + criterion 8) and economy.md (tap/inject verbs); spec now, build + later. Owners: wiki/mechanics/messages.md, wiki/mechanics/economy.md. diff --git a/wiki/mechanics/economy.md b/wiki/mechanics/economy.md index 55cd9b24..5e01d8ba 100644 --- a/wiki/mechanics/economy.md +++ b/wiki/mechanics/economy.md @@ -3,7 +3,15 @@ ``` Type: spec Status: IMPLEMENTED -Status note: 2026-07-08 polish closed the remaining acceptance gaps: +Status note: DECIDED 2026-07-17, not yet runtime (issue #11) — money stays on + the account graph, but its paperwork (invoices, POs, pay stubs, statements, + past-due notices) becomes interceptable **financial-record messages** + (messages.md). Tap = intercept that mail; discovery is only through the mail, + not a direct live-balance read; inject = a forged record that authorizes a + real transfer once read and accepted; the books and the mail stay consistent. + The current direct-book-read runtime (`tap_accounting`, the pooled ledger + intel) stands until the financial-mail work order lands. Prior state: + 2026-07-08 polish closed the remaining acceptance gaps: observer-band risk previews in the implemented finance projections (terminal/Bevy/agent; moved into Operations ACCOUNTS by the READY amendment) via Sim::finance_risk_preview_lines / flow_risk_preview_lines, and @@ -65,19 +73,32 @@ payloads (messages.md). ### The player's verbs (the flow law, for money) -- **Tap** — read the books. Reaching the accounting system reveals - flows and balances; this is intel, and knowing a flow is the - precondition to touching it. Reading is low-signature; it is also how - you *find* leverage (Marcus's debt is legible once you see the - creditor flow). +- **Tap** — read the books, *through their paperwork*. Reaching the + accounting system subscribes you to the financial records it emits — + invoices, purchase orders, pay stubs, statements, past-due notices — which + are messages on the social graph (messages.md, issue #11). Knowing a flow is + the precondition to touching it, and you learn flows by intercepting their + mail on the recipient's clock, not by reading a live balance directly + (**discovery is only through the mail**, DECIDED 2026-07-17). Reading is + low-signature; it is also how you *find* leverage (Marcus's debt is legible + once you intercept the creditor's past-due notice). Not yet runtime: the + current `tap_accounting` reads the account graph directly; that path stands + until the financial-mail work order lands. - **Review** — turn captured ledger traffic into known accounts and flows. This is the same intel-processing intention as reviewing the pooled host recordings; the ledger target supplies the financial meaning. -- **Inject** — introduce a flow under a false source. A purchase order - that says "HVAC controller" and buys you a rack (the design corpus's - own example); a ghost vendor; a payroll line for a person who does - not exist. Injection emits a **Paper/Financial signature** to whoever - audits that account — the flow-law signature rule. In B1 that is +- **Inject** — introduce a flow under a false source, *as a forged record*. + A purchase order that says "HVAC controller" and buys you a rack (the design + corpus's own example); a ghost vendor; a payroll line for a person who does + not exist. Under the financial-mail decision (2026-07-17, messages.md) the + injection **is a financial-record message** sent under a persona: it lands in + the auditor's inbox, waits on their read clock, and authorizes a real + account-graph transfer only once read and found plausible — after which it + persists as a record that a later reconciliation can catch (the + banked-signature path). The [TUNE] plausibility test (amount, vendor, + expected pattern) and that later catch are the forgery's two failure modes. + Injection emits a **Paper/Financial signature** to whoever audits that + account — the flow-law signature rule. In B1 that is **Priya** for all of it (facilities spend directly; operating-account anomalies reach her as the person who reconciles the Lab's books — decided 2026-07-07: no new finance cast member at B1; a dedicated diff --git a/wiki/mechanics/messages.md b/wiki/mechanics/messages.md index eb915d21..edb5277f 100644 --- a/wiki/mechanics/messages.md +++ b/wiki/mechanics/messages.md @@ -3,10 +3,18 @@ ``` Type: spec Status: IMPLEMENTED -Status note: delivery/read behavior is implemented. The 2026-07-11 interface - amendment moves message-thread display into Operations PEOPLE while retaining - the same staged facts; that frontend migration is implemented through - operations-workspace.md. +Status note: IMPLEMENTED for the four delivery channels (Email, Phone, + In-person, Filing) and their payloads; message-thread display lives in + Operations PEOPLE (operations-workspace.md). + DECIDED 2026-07-17, not yet runtime (issue #11): financial paperwork is + mail — a **financial-record payload** on the existing channels, retiring the + overloaded `MessageChannel::Financial` enum into an accounting-carrier + capability that emits those records. Discovery of the Lab's money becomes + interception of that mail (economy.md), and the current direct-book-read + runtime (`tap_accounting`) stands until the migration work order lands. + See criterion 8; the [TUNE] plausibility of a forged record passing and the + banked reconciliation that later catches it ride economy.md and + aggregate-observer.md. Stage: B1 — The Basement Design: - wiki/mechanics/system-laws.md#the-flow-law-signals-messages-money @@ -49,15 +57,31 @@ defines where and when a message can be read: | In person | co-location | both parties in the same room | | Filing | the institutional channel | the receiving role's next sampling cadence | -**[OPEN — Tangled issue #11]** — B1 runtime also carries -`MessageChannel::Financial`, but no scheduled message or authored traffic uses -it. The switch reuses that variant as a device capability for capturing account- -graph snapshots directly as intel. Cameron's answer will decide whether to split -an explicit accounting-carrier capability, promote Financial into a real fifth -delivery channel, or preserve and document the overload. Until then, the table -above remains the binding list of delivered message channels; do not infer -unconditional Financial-message reads from the unused runtime branch. This -blocks new accounting-message authoring and cleanup of the channel type. +**Financial paperwork is mail (DECIDED 2026-07-17, issue #11).** Money moves +on the account graph (economy.md); the *paperwork* that money throws off — +invoices, purchase orders, pay stubs, account statements, past-due notices — +is real, interceptable **messages** on this graph. Crucially, "financial" is a +**payload type, not a fifth delivery channel**: a financial record rides an +existing channel by how it actually arrives — an invoice or purchase order is +**Email** (read at a desk block), a mailed statement or past-due notice is a +**Filing** (read on the recipient's sampling cadence), a phoned creditor +notice is **Phone** (rhyming with Marcus's 3 a.m. calls). This retires the +overloaded `MessageChannel::Financial` enum value: a device that carries the +books becomes an **accounting-carrier capability** that *emits* financial-record +messages, not a channel that carries a fake one. The four delivery channels in +the table above stay the complete list. + +Because financial records are messages, the flow-law verbs fall out for free +and are the point: **tap** the paperwork feed to learn what the Lab is buying +and paying before anyone acts on it; **inject** a forged record — a fake +invoice under a contractor persona that, once read and found plausible, +authorizes a real account-graph transfer (the "purchase order that says HVAC +controller and isn't", now a literal document that can be reconciled against a +delivery that never happened); **redirect/intercept** a record in flight — +hold a past-due notice to buy time, or inject a false "account settled" notice +that calms Marcus before you have actually paid him. Discovery is **only +through the mail** (economy.md): financial knowledge reaches the player by +intercepting these records, not by reading live balances directly. At B1, **awake means reachable**: there is no separate per-person sleep or phone-silence state. A Phone message therefore reads at its scheduled Read @@ -94,9 +118,14 @@ along their social edges, riding their schedule: material later). A message carries a **typed payload** — schedule fact, leverage fact, -account/credential material, suspicion report, research result. This is -the information economy's unit: intel.md processing extracts payloads -from captured traffic; economy.md prices some of them. +account/credential material, **financial record** (an invoice, purchase +order, pay stub, statement, or past-due notice; issue #11), suspicion +report, research result. This is the information economy's unit: intel.md +processing extracts payloads from captured traffic; economy.md prices some +of them. A financial-record payload keeps the account-graph flow it +describes consistent with itself — a real transfer emits its paperwork, and +a forged record that is read and accepted causes a real transfer — so the +books and the mail can never tell two different stories. ### Filings are messages @@ -174,6 +203,15 @@ private message from the authored schedule. 7. No per-person special cases in the delivery code: one delivery system, per-instance data (schedules, distributions, policies) — the same fields must serve Act Two hires and aggregates. +8. **(DECIDED 2026-07-17, not yet runtime — issue #11)** Financial records + are messages: an invoice/PO rides Email, a statement/past-due notice rides + Filing, with no fifth delivery channel and no `MessageChannel::Financial` + value. Tapping the accounting carrier subscribes to that record feed; + discovery is only through the mail (no direct live-balance read). A forged + record read and accepted causes a real account-graph transfer, and every + real transfer emits its record, so the books and the mail stay consistent + (test the forged-invoice-to-transfer path and the intercept-before-read + path). Defense: `operations_projection::tests::active_tracks_social_commitments_not_device_work` pins the PEOPLE dossier as the shared direct-thread and learned-traffic surface, diff --git a/wiki/process/tick-ledger.md b/wiki/process/tick-ledger.md index 3a4eaffd..dabc744f 100644 --- a/wiki/process/tick-ledger.md +++ b/wiki/process/tick-ledger.md @@ -56,6 +56,7 @@ Verdicts: **clean** (slice and code agree), **finding** (acted this tick), | `wiki/mechanics/compute.md` | 2026-07-12 | finding | [log](../log/2026-07-12-compute-graduation.md) | | retired Operations runtime identifiers | 2026-07-17 | clean | resolved by the save-ladder prune (95008f658 chain): PendingOpsJob, operations_bandwidth, LegacyOperationsState/OpsJobKind/AddressedOperation are all gone (grep=0), and save guard tests assert current JSON carries no retired mode spelling. Remaining "operations" hits are the legitimate Operations persona archetype, the Operations workspace, and benign `delegate operations->think` input aliases — [log](../log/2026-07-11-retired-runtime-identifier-gate.md) | | `wiki/mechanics/reach.md` + `building.md` | 2026-07-15 | finding | re-verified the queued reverse-endpoint duplicate: declaration compared canonical stored endpoints to the raw request tuple; canonicalized proposal identity at the comparison boundary and pinned reverse-order rejection plus cancellation/reproposal — [log](../log/2026-07-15-canonical-build-intent-endpoints.md) | +| `wiki/mechanics/messages.md` + `economy.md` | 2026-07-17 | harvest | issue #11 answered (Cameron): financial paperwork is mail — a financial-record payload on existing channels, not a fifth delivery channel; discovery only through the mail; captured to messages.md (payload + criterion 8) and economy.md (tap/inject); spec now, build later; issue closed | | `wiki/mechanics/messages.md` | 2026-07-17 | issue | re-verified the queued Financial contradiction: the binding table owns four delivered message channels, while runtime's unused fifth variant acts as an accounting-carrier device tag and bypasses message scheduling; filed decision-required Tangled issue #11 with three concrete resolutions and marked the blocked contract [OPEN] — [log](../log/2026-07-17-financial-channel-decision.md) | | `wiki/mechanics/sim-mechanics.md` | 2026-07-11 | finding | [log](../log/2026-07-11-tick-sim-no-dockets.md) | | `wiki/mechanics/detection.md` | 2026-07-11 | finding | [log](../log/2026-07-11-tick-detection-filings-messages.md) | -- 2.51.2