# Spec: messages — the social graph as a flow system ``` Status: READY Stage: B1 — The Basement Constitution: "The flow law" (messages are flows; filings are messages), "Presence: the cursor and the senses" (record and process), "Act One" (the cast's channels; the 3 a.m. call), "Self-similar scale" (a person, a role, an institution are all message nodes) Depends on: schedules.md (read-times ride the day clock), social.md (player-sent messages, personas), intel.md (intercepted traffic lands in the buffer), detection.md (filings become message-carried; aggregate-observer.md criteria preserved), reach.md (taps on the carrying device) ``` ## Behavior ### Nodes, channels, delivery Every `Person` (and institutional role — the Assurance Office, "upstairs") is a **message node**. Messages travel on **channels**, and a channel defines where and when a message can be read: | Channel | Carried by | Read condition | |---|---|---| | Email / tickets | a server (a reach.md device) | recipient at a desk block of their schedule | | Phone | the phone network (off-graph at B1) | recipient awake, any location incl. off-site; audible where they stand | | In person | co-location | both parties in the same room | | Filing | the institutional channel | the receiving role's next sampling cadence | **Delivery is on the recipient's clock.** A message sent to Dana at 02:00 sits unread until her next desk block; her reply comes back on a per-person response distribution [TUNE]. No special cases: "Dana replies when she's at her desk" must fall out of (email channel + her schedule), not out of Dana. ### Traffic: people message each other Each person has authored **traffic distributions** — recurring sends along their social edges, riding their schedule: - Marcus: 3 a.m. phone calls to his creditor (the leverage event of intel.md — an overheard message, not a bespoke event type). - Dana: tickets to the queue; complaints upward. - Ray: filings, under-filed (his `ReportPolicy` **is** his transmission policy on the filing edge). - Priya: budget memos, deferred-maintenance non-reports (what she hides is traffic that *doesn't* flow — an absence you can notice). - Voss: emails upstairs; the quarterly review; overclaiming reports (his filed version of your output differs from the truth — forgeable material later). A message carries a **typed payload** — schedule fact, leverage fact, account/credential material, suspicion report, research result. This is the information economy's unit: intel.md processing extracts payloads from captured traffic; economy.md prices some of them. ### Filings are messages The detection reporting pipeline is re-expressed on this system: a field observer's filing is a message on the filing channel, sent per their report policy on their cadence; the Assurance Office is an aggregate node whose sampling reads its inbox. **aggregate-observer.md's acceptance criteria are preserved unchanged** — same accumulate/decay, same policy weighting; only the carrier changes. The payoff for the refactor: filings become interceptable (tap the channel that carries them) and, later, forgeable (inject a filing under a false source). B1 requires carry + intercept; forgery is B2+ and explicitly out of scope here. ### The player on the graph - **Send** (social.md unchanged): requires a channel you have (the report email account is the first) and a persona. Effects land when the message is *read*, not when sent. - **Tap**: subscribing to the device that carries a channel (reach.md tap of the ticket server / a phone line later) captures its traffic as raw events into the intel.md buffer — reading Dana's tickets is tapping a flow, processed like any recording. - **Intercept-before-delivery** (B1 minimal form): a tapped filing channel shows filings in transit; delaying/dropping them is a later action — B1 only requires that in-transit mail is visible to a tap. ## Player surface - Message threads (social.md's panel) show sent / delivered / read states and the recipient's expected next read window ("Dana reads email at her desk, ~09:00"). - Tapped channels appear as feeds in the recordings panel, source- tagged (provenance law). - People cards show known traffic patterns once learned ("calls his creditor at 03:00" after processing that intel). ## Acceptance criteria 1. Channels exist with read conditions per the table; a message to an off-shift recipient is delivered but unread until their next qualifying block; effects (disposition, obligation, deceive rolls) apply at read time, not send time (test with Dana at 02:00). 2. Replies return on a per-person response distribution riding their schedule; save/load round-trips in-flight messages. 3. Authored traffic exists for all five cast members per their specs; Marcus's 3 a.m. call is message traffic on the phone channel, and intel.md's leverage event is its overheard capture (the intel.md Marcus-arc test still passes, now through this system). 4. Messages carry typed payloads; processing captured traffic yields payload intel with provenance (schedule fact, leverage fact, account material at minimum). 5. Filings ride the filing channel: field observers' reports are messages on their cadence and policy; the Assurance Office reads its inbox; every aggregate-observer.md criterion still passes. 6. Tapping a carrying device (reach.md) captures that channel's traffic into the intel buffer; an untapped channel's traffic is never player-visible (flow-law strictness; test both). 7. No per-person special cases in the delivery code: one delivery system, per-instance data (schedules, distributions, policies) — the same fields must serve Act Two hires and aggregates.