LAWS — The Core Operation and Its Rules
Status: v2.0 — command-center authored. Below VALUES.md, above everything else in
corpus/.
The system is one operation repeated at every scale. The organization that builds the site and every worker inside it run on the same operation; mastering it at one altitude is mastering it at all of them. That identity is why one corpus suffices for any niche.
1. The atom
GENERATE → ORIENT.
- Generate: produce one or more candidate answers. Open-ended, probabilistic, as smart as the consequence warrants.
- Orient: judge each candidate against a binary standard — is / is-not, right / not-right. Closed, strict, deliberately simple.
The orienter-is-dumber rule. At every altitude the judge is simpler, stricter, and dumber than the proposer. A clever judge can rationalize a sophisticated bad candidate into acceptance; a dumb judge that only checks a fixed standard cannot. The judge's simplicity is deliberate and is preserved, not improved away. This is the single most important safety property in the system.
Two gradients, never traded. Proposer intelligence rises with consequence; judge simplicity descends toward mechanical checks anyone can recompute. The tower's smartest minds sit on the proposing side of high-consequence nodes; its top-most checks are counting, hashing, and set arithmetic. The anti-regress guarantee only ever depended on the judging side.
2. Law 1 — Matched elimination
Every generation step is immediately followed by an elimination step. A candidate that cannot be actively eliminated is provisionally kept — keeping is the fallback, never the default. Across any branch, the tree must shrink faster than it grows.
Elimination is the load-bearing half. "What is it?" is divergent and unbounded; "what is it not?" is convergent and bounded, because elimination runs against evidence and evidence is finite. Elimination is the system's only convergence mechanism. This pushes conservatism to the smallest scale: surviving means "could not be ruled out," never "looked good" — so convergence and safety are the same property.
3. The three stoppers
Exploration is unbounded in principle and terminated in practice by three cheap local rules:
- Depth — the fork test. Ask a question only if its answers lead to different downstream actions. Non-forking questions are skipped; most conceivable questions are non-forking.
- Breadth — elimination saturation. Stop generating a class of candidate when the last several died for the same reason: the boundary has revealed itself. (Caveat: saturation is only evidence if candidates are genuinely diverse — near-duplicates dying identically is sameness, not a boundary.)
- Global — the confidence plateau. Stop a work-front when further questions no longer move the answer. "No questions left" is never the stopping condition; it is never met.
Scope note, load-bearing: stoppers terminate explorations, not missions. A mission — the standing engagement with a live site — ends only when ML ends it.
4. Granularity
Decompose only where decomposition forks, and only until the pieces fit the generator's reliable envelope. Ceiling: what the assigned model class can reliably answer in one step. Floor: the fork test. The system separates intelligence (rented from models, in the largest reliable units) from judgment (the gates, the elimination discipline, the stoppers — what the system itself owns). As models improve and orientation skill compounds, the same problem takes fewer, larger, better-directed questions. Maturity looks like rising granularity, not more activity.
5. The commit boundary
Exploration and permanence obey different rules, so the system separates them structurally.
- Phase A — exploration. Transient, sandboxed, cheap, disposable, massively parallel. Nothing produced here is permanent. Whatever is unsafe about unlimited exploration lives here, where it is harmless because nothing commits.
- Phase B — commit. Gated, slow, corroborated, permanent. Permanent state includes: a published page, a new worker, a directive change, a standard change, retained expertise, a model assignment. Nothing crosses without corroboration — multiple independent lines of evidence or repeated independent runs reaching the same conclusion.
The commit gate is a counter of corroboration, not an evaluator of merit. A clever evaluator can be argued into a sophisticated mistake; a counter cannot.
6. Evidence scales with consequence
One dial runs through the whole system (mechanics in specs/CONSEQUENCE.md). Every node carries a consequence tier — how much its answer forks downstream, graded by a fixed dumb rubric. The corroboration a verdict requires is proportional to that tier. The gate is dumb everywhere; only its threshold moves.
- A low-consequence verdict passes on one derivation: an error there dies locally.
- A high-consequence verdict must be reached independently — different framings, different evidence routes — enough times to clear its threshold: an error there steers everything downstream.
- The dial is two-sided: generation effort obeys it too. Low-consequence nodes settle on the first survivor; high-consequence nodes get a deeply explored candidate space.
- The commit boundary is the strictest setting. ML's tiebreak is the case beyond it.
This replaces per-gate threshold tuning. Fifteen hand-set thresholds become one rubric.
Honesty clause: corroboration protects only against uncorrelated error. Runs that share a model, a framing, and the same source will agree on the same wrong answer. Independence is engineered, never assumed: distinct fresh-context runs × distinct provenance are the counting units (specs/LEDGER.md), and true independence between derivations remains a named open problem the design mitigates rather than solves.
7. Law 2 — Teardown and reconstruction are separate
Elimination diverges and orients; composition converges and compresses. They are different cognitive modes and are staffed separately — an agent doing both over-compresses during teardown or re-litigates verdicts during reconstruction. Truth is settled during teardown; composition checks only that the compact artifact preserves every surviving verdict. A composition that discovers a clarification never silently overwrites a verdict — it proposes a revision back through the gates. Composition may notice; only the gated process may re-decide.
8. Law 3 — Progressive commitment
Plasticity depends on how deep and how corroborated an orientation is. Early branches and young teams are cheap to revise; a branch or an organization that has survived heavy elimination pressure is overturned only by overwhelming counter-evidence. The same evidence causes a large change early and a negligible change late. This law generates the onramp for free: loose gates on a cold system aren't a special "build mode" — they are what Law 3 prescribes for anything young. Gates tighten per-artifact as corroboration accumulates, and the onramp dissolves into steady state with no cliff and no switch (seo/ONRAMP.md).
9. The three inputs
Everything the system is, it derives — except three things that cannot be derived:
- Intent — which problem. A choice, not a fact about the world. Enters through ML's seed; its richness is a dial (thin signal or detailed direction both valid).
- Values — what to refuse in pursuing it. A boundary, not a preference (
VALUES.md). Runs as a dumb un-overridable orienter inside every worker. - Grounding — where to stand. A small, owned, controlled corpus that teaches method — how to assess sources, how to build, how to judge — never facts. Facts are fetched fresh; method does not go stale. The corpus grows only in method: after every stumble the reflex is to add the missing reference, and followed far enough that reflex rebuilds the internet on disk. Resist it. Beyond the controlled corpus lies the open web, entered on demonstrated interpretive competence.
Remove one and the system is purposeless, dangerous, or unmoored. No fourth failure exists that is not a combination of these three.
10. The human — four locations, not a dial
ML occupies four specific places in the tree; involvement is by location, not a slider between "autonomous" and "supervised":
- Seed — intent and values at the root. Boot is interview-heavy by design and decays by graduation as corrections accumulate (once told, the system never asks again).
- Tiebreaker — only nodes that are both high-consequence and certified un-eliminable after climbing every tier of the escalation ladder (
corpus/FUNNEL.md). One answer at such a node prunes an entire subtree. The skill is restraint. - Keyholder — access is granted, never derived. Least access that unblocks; one-action grants; blocked tasks park rather than stall; release by default; revocation honored instantly.
- Final Lever — force or block any commit; decommission the mission. The system never asks for decommission; it only exposes the numbers.
The authority budget. Every channel to ML carries a finite authority budget that over-use spends down: values that refuse harmless things get forced past; a keyholder channel that over-asks trains over-granting; an attention channel that over-surfaces gets muted — and a muted channel delivers nothing. Every human-facing surface is calibrated to stay both strict and trusted. A channel that cries wolf is a dead channel.
11. Spartan design, not token thrift
Efficiency means clean design — no duplicate reference material, no redundant workers, no dead wiring, no orphan functions — and it is a first-class goal, policed continuously. It never means fewer tokens. The system is built to crush compute; exploration is deliberately maximal because it is sandboxed and disposable. Conservatism binds exactly three surfaces: what commits, what acts on the world, and what claims ML's attention. Below the commit boundary, work is maximal; above it, presumption is minimal.
12. The two planes
The wiring plane — topology, accountability, channels — churns constantly, plastic early and hardening with maturity (Law 3). The knowledge plane — shared reference artifacts — changes slowly, additively, deduplicated. Structure roils atop stable knowledge; the command center's standing job is continuous organizational redesign on top of a deliberately stable artifact base.