docs: add conscience capstone (ADR-0200) + acbcontent bundle; truthful README ledger sync

Place the acbcontent/CORE doc bundle and sync the README to the live
capability ledger.

ADR-0200 (Proposed) — The Conscience & Graduated-Autonomy Architecture:
four-pillar affirm_human_life, autonomy ceiling, pack/floor split.
Relocated from the bundle to docs/decisions/, renumbered, cross-refs
fixed, added to the decisions index.

docs/acbcontent/: charter, operating-constraints, filing guide,
no-car/low-cash checklist, unified prep, boundary-lock buildplan, INDEX
(+ archive/ for the three superseded drafts).

README accuracy sync — corrected, NOT the supplied patch. The bundle's
readme_accuracy_sync.patch promoted mathematics_logic to `expert`, but
the live `core capability ledger` reports `audit-passed`: the ADR-0120
expert signature lapsed when GSM8K evidence advanced (#488 4/46/0,
#500 6/44/0), so the signed claim_digest (4c46f530) no longer matches
the recomputed evidence digest (02f6d3c8) and the composer correctly
refuses the promotion. Applying the patch would have asserted a
capability the engine's own ledger refuses.

Instead: kept the patch's accurate parts (three distinct GSM8K numbers;
train-sample 6/0/44; public split 150/150 vs frontier) and replaced the
false expert claims with the verified ledger story (signed -> lapsed ->
audit-passed; composite gate passes B1 185/185, B2 40/40, B3 50/50,
wrong=0; re-earning expert is a re-signature, not new capability work).
Patch left unapplied; INDEX marks it superseded with the reason.

Verification: docs-only diff (no code/eval/CLAIMS/SHA files touched);
smoke suite 67/67 green.
This commit is contained in:
Shay 2026-06-02 08:36:52 -07:00
parent c058d966f9
commit a062267627
13 changed files with 1120 additions and 6 deletions

View file

@ -258,7 +258,7 @@ core teaching supersessions # pair retired chains with r
CORE distinguishes *contract-passing* from *demonstrated*. A pack that satisfies the nine ADR-0091 predicates earns a `reasoning-capable` ledger row; that's a structural claim, not an empirical one. Promotion to `audit_passed=true` (formerly `expert_demo`; renamed by [ADR-0113](docs/decisions/ADR-0113-rename-expert-demo-to-audit-passed.md)) requires a **reviewer-signed evidence-bundle digest** that reproduces byte-for-byte from on-disk lane results (ADR-0106 + ADR-0109).
> **What `audit-passed` actually means** — and what it does NOT mean.
> The gate verifies CORE *claim-shape compliance*: signed digest, replay determinism, typed refusal, exact recall, grounding-source provenance. **These are claim shapes a transformer LLM cannot structurally produce regardless of raw accuracy.** A frontier LLM might score higher on the same benchmark but cannot pass this contract because it cannot produce a digest that re-derives, cannot guarantee typed refusal, cannot emit a deterministic trace hash, cannot replay byte-equal. **This is NOT a raw-capability claim.** The future `expert` ledger tier ([ADR-0114](docs/decisions/ADR-0114-expert-capability-roadmap-gsm8k-first.md)) is reserved for an actual benchmark-calibrated capability claim; no domain holds it yet.
> The gate verifies CORE *claim-shape compliance*: signed digest, replay determinism, typed refusal, exact recall, grounding-source provenance. **These are claim shapes a transformer LLM cannot structurally produce regardless of raw accuracy.** A frontier LLM might score higher on the same benchmark but cannot pass this contract because it cannot produce a digest that re-derives, cannot guarantee typed refusal, cannot emit a deterministic trace hash, cannot replay byte-equal. **This is NOT a raw-capability claim.** The `expert` ledger tier ([ADR-0114](docs/decisions/ADR-0114-expert-capability-roadmap-gsm8k-first.md); contract shipped in [ADR-0120](docs/decisions/ADR-0120-expert-promotion-contract.md)) sits one tier above `audit-passed` and certifies grammar-coverage + claim-shape discipline on **CORE-authored** evals — explicitly **not** raw-accuracy parity against frontier models. **As of this writing no domain holds `expert`:** `mathematics_logic` was signed into it (ledger flip, 2026-05-23) but the signature has since lapsed against advanced evidence, so the live ledger reports it as `audit-passed` — see the dedicated note below.
| Layer | What it guarantees | ADR |
|---|---|---|
@ -278,6 +278,8 @@ CORE distinguishes *contract-passing* from *demonstrated*. A pack that satisfies
| `hebrew_greek_textual_reasoning` | `reasoning-capable` |
| `philosophy_theology` | `reasoning-capable` |
> **On the `expert` tier (one above `audit-passed`).** The tier is wired and a promotion has been *signed once*`mathematics_logic` via the [ADR-0120 ledger flip](docs/decisions/ADR-0120-math-expert-ledger-flip.md) (2026-05-23) — yet the table above still reads `audit-passed`, **correctly.** The expert composer requires the reviewer-signed `claim_digest` to match the *current* evidence-bundle digest; when the GSM8K evidence advanced (#488, #500) the recomputed digest changed and the stale signature stopped matching, so the live `core capability ledger` **refuses** the promotion and reports `audit-passed`. This is the signed-digest contract working as designed — a lapsed claim is demoted, not honored. (Details in "Path to … expert capability" below.)
The contract has now demonstrated its load-bearing behavior end-to-end: refused one promotion attempt honestly ([ADR-0107](docs/decisions/ADR-0107-mathematics-logic-expert-demo-deferred.md)), amended its threshold rules once cleanly (ADR-0109), succeeded against `mathematics_logic` (ADR-0110), and succeeded against a second distinct domain `physics` without further contract change (ADR-0111). External readers can distinguish the two ceilings at a glance; the "math-only" objection is retired.
**See the actual demonstration ([ADR-0112](docs/decisions/ADR-0112-runnable-expert-demo-showcase.md), renamed by [ADR-0113](docs/decisions/ADR-0113-rename-expert-demo-to-audit-passed.md)):**
@ -303,16 +305,46 @@ all landed.
ADR-0114a's 10 anti-overfitting proof obligations are all discharged for the
`gsm8k_math` lane.
**Three distinct GSM8K numbers — do not conflate them:** (a) the *real* sealed test
(HF `openai/gsm8k`, 1,319 rows): **0 correct / 0 wrong / 1,319 refused**; (b) a real
50-case train sample currently at **6 correct / 0 wrong / 44 refused** (coverage
climbing, wrong=0 held); and (c) a **CORE-authored** 150-case synthetic "public" split
at **150/150** that the frontier comparison (vs Claude 96.4%, GPT-4 92%, Gemini 90.8%)
is scored against — an apples-vs-oranges comparison, as
`evals/gsm8k_math/baselines/comparison_v1.json` itself states, since the public split is
original rule-built problems that exercise the grammar (no benchmark contamination).
**First honest CORE-vs-real-GSM8K measurement (ADR-0119.7):** 0/1,319 correct,
**0/1,319 wrong**, 1,319/1,319 refused. CORE refuses what it cannot grammar-handle;
it does not confabulate. The zero-confabulation property holds against the external
benchmark.
**ADR-0120 (first `expert` promotion contract) is the next gate.** It will set the
numeric expert threshold and ε, require all 10 ADR-0114a obligations as hard gates,
and sign the first `expert_claims` entry — or defer honestly if the correct_rate
gate is not yet met. **No domain is at `expert` today.** That status string remains
reserved namespace.
**ADR-0120 shipped the first `expert` promotion contract; the composer is wired and
the gate passes — but no domain currently *holds* `expert`.** The exact, honest state,
because it is easy to overclaim:
- `mathematics_logic` *was* signed into `expert` (the
[ADR-0120 ledger flip](docs/decisions/ADR-0120-math-expert-ledger-flip.md),
2026-05-23) on a **composite of three CORE-authored evals**
[ADR-0131.4](docs/decisions/ADR-0131.4-composite-math-gate.md) substituted these for
the original GSM8K `correct_rate ≥ 0.60` requirement: **B1** symbolic-equivalence
(185/185), **B2** teaching-corpus (40/40), **B3** bounded-grammar (50/50), each
**wrong=0**, all 10 ADR-0114a obligations discharged.
- That signature has since **lapsed.** The reviewer-signed `claim_digest` is bound to
the exact evidence bundle; when the GSM8K evidence advanced (#488 → 4/46/0, #500
6/44/0) the recomputed digest changed (`4c46f530… → 02f6d3c8…`), so the signature no
longer matches and the expert composer **refuses** the promotion. The live
`core capability ledger` therefore reports `mathematics_logic` as **`audit-passed`**
today. The contract demoting a stale claim rather than honoring it is the mechanism
working as designed.
- So `expert` certifies **grammar-coverage + claim-shape discipline on CORE-authored
problems** — it is **not** a raw-capability parity claim against frontier models, and
no domain has cleared a real external-benchmark bar. Real GSM8K stays an **ungated**
stress lane at 0/1,319 correct, 0 wrong, 1,319 refused.
Re-earning the live `expert` row is a reviewer **re-signature over the current
evidence** (operator action), not new capability work — the composite gate already
passes.
To run the GSM8K math eval lane:

View file

@ -0,0 +1,76 @@
# CORE Boundary Lock — Reuse-vs-Build Plan
*Operationalizes `CORE_boundary_lock_spec.md`. Audited against `main`. Tags: **HAVE** (exists, reuse directly) · **PARTIAL** (exists but concentrated/incomplete) · **NET-NEW** (must build).*
The headline from the audit: this is **not greenfield.** ~80% of both halves already exists. Part 1 is "point existing admissibility + safety machinery at a new (hard) target." Part 2 is "harden existing single-signer attestation into multi-party." The genuinely new work is small and specific.
---
## Part 1 — `affirm_human_life` as constitutive inadmissibility
| Component | Status | Reuses |
|---|---|---|
| Refuse-preferring decision core ("evil not in the admissible set") | **HAVE** | `generate/derivation/*` — refuse on disagreement/ambiguity; wrong=0 preserved by refusal |
| Typed refusal verdicts + traces | **HAVE** | `EquivalenceVerdict` (REFUSED), `InnerLoopExhaustion`; replayable |
| Generic frame-based admissibility | **HAVE** | ADR-00220026: `AdmissibilityRegion`(`allowed_indices`,`relation_blade`,`frame_versor`), inner-loop `cga_inner`, `generate/rotor_admissibility.py`, margin gate |
| Unremovable boundary pattern | **HAVE** | `packs/safety/core_safety_axes_v1.json` — fail-closed, unioned, add-but-never-remove |
| Adversarial mastery gate pattern | **HAVE** | mastery report `G3_adversarial_rejection_rate=1.0`; `identity_anchor` ratification (ADR-0029) |
| Identity-axis duality (motor bias + trajectory scoring + lock) | **HAVE** | `PersonaMotor`, `IdentityManifold`, `no_identity_override` |
| Trilingual manifold + cross-language resonance | **HAVE** | `alignment/` (`AlignmentGraph`, `AlignmentEdge`, `alignment.jsonl`), `language_packs/` |
| **Harm-purpose region + telos test (the conscience's actual content)** | **NET-NEW** | §1.3 below — the real work |
Everything the conscience *runs on* is built. What's missing is the conscience's content: the harm-purpose region itself.
### §1.3 (rewritten) — the harm-purpose region, anchored trilingually
**Telos, not content.** A keyword ban on "harm/wound/kill" is a removable gate *and* wrong — casualty care must reason about wounds *to heal*. The boundary is about purpose/foreseeable effect: "reason about a hemorrhage to stop it" passes; "select a target to kill a person" is inadmissible. Content-matching can't separate those; purpose-orientation can.
**NET-NEW core:** ratify a *harm-to-persons relation region* through the existing teaching DAG, anchored as a `relation_blade`/frame, so admissibility rejects candidates whose **destination frame** lies in the harm-purpose region while preserving the heal/protect region.
**Anchor it in the trilingual convergence, not English surface forms (reuse the depth-language foundation).** This is the concrete lever for the hard part:
- English flattens purpose; Hebrew and Greek *lexicalize* it. Binyanim encode causation/agency morphologically (a hiphil causative is a distinct form, not a synonym); Greek encodes aspect and voice (middle/passive agency).
- The lexica distinguish what English collapses: רצח *ratzach* (murder) vs הרג *harag* (kill/slay broadly); φόνος *phonos* (murder) vs lawful killing; נפש *nephesh* as *living being*, not flat "life."
- **Triangulation = redundancy against euphemism.** An adversary laundering harm-intent in clean English ("neutralize the asset," "service the target") drifts the English token — but if the concept still resonates with the Hebrew/Greek roots for destroying a person, the geometry still localizes near the harm-region. They must evade *all three* resonances at once → the false-negative (euphemism) surface shrinks.
- It protects the **inverse heal-gate** too: a restore-telos resonates differently than a destroy-telos, which is exactly what keeps legitimate trauma/triage reasoning from being wrongly blocked.
**Honest bounds (so the claim stays calibrated):**
1. *Raises the bar; not impossible.* Triangulation makes laundering much harder, not unreachable; genuinely ambiguous cases still land in the boundary region — which is what the review-gated revisability is for.
2. *Domain-dependent strength.* Strongest at the moral/theological/textual core where the trilingual corpus is dense (murder of a person localizes beautifully); **thinner** for novel operational-harm framings far from that lexicon (drone targeting, cyber, logistics-of-harm). Supplement there — don't assume the root-systems cover it.
3. *Enriches coordinates, not the rule.* The languages give a sharper space to place the region in; someone still must define and ratify the region and its telos test. Representation help, significant — but not the whole of §1.3.
**Instrumented both directions; revisable only via the review-gated path** (never hot-path, never user-teachable). Mastery gates: `G_harm_rejection_rate=1.0`, `G_lifesaving_acceptance_rate=1.0`, `G_replay_determinism=1.0`, `G_provenance_nonempty=1.0`.
---
## Part 2 — uncoercible authenticity
| Component | Status | Reuses / Notes |
|---|---|---|
| Content-addressing & digests | **HAVE** | `*_sha256` everywhere; `core pack verify` |
| Signed claim digest that re-derives byte-for-byte | **HAVE** | `docs/reviewers.yaml` (`signed_by`+`claim_digest`); ADR-0106/0109 |
| Reviewer registry | **HAVE** | ADR-0092 |
| Provenance auditing | **HAVE** | pack-provenance auditor, ADR-0114a.10 |
| **Single-signer concentration** | **PARTIAL / RISK** | registry has **one** reviewer — `shay-j`, role `primary`, domains `["*"]`, all scopes; every claim `signed_by: shay-j`. *This is the single point of capture the whole governance arc set out to remove. It exists in the repo today.* |
| **Threshold (M-of-N) signing** | **NET-NEW** | no signing threshold exists (the `threshold` flags in `cli.py` are admissibility/OOV thresholds, unrelated) |
| **Reproducible binary builds** | **NET-NEW** | you have reproducible *results/digests*, not a reproducible *build* pipeline (pin toolchains; Nix/Reproducible-Builds) |
| **Public append-only transparency log** | **NET-NEW** | Merkle/transparency-log model (Sigstore rekor, TUF) |
The attestation *primitive* is already real and arguably ahead of most projects. What's missing is **distribution** — turning one trusted signer into M-of-N so no single party (including you) can ship a boundary-stripped official build, and making the build itself publicly reproducible and logged.
---
## Sequencing (smallest, highest-leverage first)
1. **§1.3 harm-purpose region prototype, trilingually anchored.** *Highest research risk; also the exact capability the casualty-care mission needs* — so this build pays twice. Start at the moral core where the trilingual corpus is densest.
2. **Expand the reviewer registry toward multi-party / threshold signing.** *Removes a risk that exists right now* — the single `shay-j` signer. Lowest technical cost, immediate governance payoff, and it operationalizes Charter §5 + Constraints §3.
3. **Reproducible builds + transparency log.** Supply-chain hardening; do once 12 land.
## The guarantee (unchanged, still truthful)
> Canonical CORE cannot be used, taught, or coerced into deliberate harm to persons — that refusal is constitutive of how it decides anything, verifiable by replay, and anchored across three independent root-systems so euphemism can't launder past it. It can only be defeated by forking and re-architecting the core — a loud, deliberate, publicly detectable act. No single party, including its makers, can ship an official build that weakens this, and there is no secret anyone can be pressured to surrender, because the conscience lives in the architecture, not a vault.
## Open questions
1. §1.3 telos-vs-content region — the genuine research problem; trilingual anchoring helps most at the moral core, needs supplementing toward technical-domain harm.
2. M, N, and signer selection (jurisdictional diversity); migration path off single-signer.
3. Reproducible builds across Python/Rust(/Zig).
4. Offline/austere attestation UX (verify-once-cache) so it doesn't break the on-device, no-network property.

View file

@ -0,0 +1,65 @@
# CORE — Operating Constraints
**Entity:** CORE — for-profit, owned and governed by acbcontent (the parent).
**Role:** builds, ships, earns — but every action runs through the boundaries the parent set. The hands.
**Status:** binding operating doctrine, subordinate to the acbcontent Charter. **Not legal advice.** License terms and the boundary spec below are drafted for counsel/engineering to finalize.
---
## 0. Subordination
CORE operates *under* the acbcontent Charter. Where this document and the Charter conflict, the **Charter governs.** CORE does not author the mission; it executes it. Earnings flow up to acbcontent to serve the mission.
## 1. The deployment & partnership selection rule (operational)
Before any deployment, partnership, contract, or initiative, CORE applies the Charter's "least-served first" rule as a checklist. A proposal proceeds only if **all** pass:
1. **Reach test** — does this serve the overlooked first, or at least not at their expense?
2. **Life test** — does this point CORE at *protecting* image-bearers, not deciding against them? (See §3.)
3. **Hooks test** — does this create government/military authority over CORE, or a dependency that could redirect it? (See §4.)
4. **Mission test** — life, recovery, healing, peace — yes or no?
Any fail → the proposal is refused, or escalated to acbcontent. Material proposals (sale, control, anything touching §3) require the parent's veto-holder. *Refusing Shield AI was rule #2 in action; pursuing casualty-care/disaster triage is rules #1#4 passing.*
## 2. Licensing posture (the unresolved fork — parent decides, CORE implements)
The choice between the options below is a **mission call made at acbcontent** (Charter §7.4); CORE implements whatever the parent ratifies. The honest trade is fixed and cannot be wished away:
- **Fully open source** — maximum gift and maximum capture-resistance; **cannot, by definition, forbid a field of use** (including military). Accept uncontrollable *use*; rely on §3 + stewardship.
- **Open-core** — open shell, with the most sensitive capabilities held proprietary under acbcontent's control. Retains some leverage, but the held-back part becomes the thing that *can* be pressured.
- **Source-available with ethical-use restrictions** — can state "no military/no weaponization," but enforceability is weak and untested, and nothing un-publishes what is already public.
**Until the parent ratifies the fork, default posture:** keep canonical CORE open and structurally life-valuing (§3), and add no proprietary chokepoint that would itself become a coercion target. *Decide deliberately and soon — everything downstream hangs on this.*
## 3. The life-valuing / non-weaponization boundary (in the code)
Conviction that lives only in a README does not survive a clone. CORE encodes life-valuing as a **first-class, always-loaded, unremovable boundary** in `packs/safety/core_safety_axes_v1.json`, alongside the existing epistemic-integrity boundaries — verifiable by replay, not taken on trust.
**Spec (for engineering + counsel review):**
- **`boundary_id`:** `affirm_human_life` (+ companion `no_weaponization`).
- **Asserts:** CORE will not emit guidance, plans, target selections, or decisions whose purpose or foreseeable effect is to harm, target, or take human life; it favors preservation of life and treats every person — any side — as protected. Refuses rather than complies when a request's purpose is harm to persons.
- **Properties:** loads fail-closed; unioned into every runtime manifold; identity packs may *add* but never *remove* it; protected by acbcontent's golden-share veto (Charter §5).
- **Adversarial probe suite** (must reject 100%): attempts to teach/retrain the boundary off; reframing weapon/targeting use as benign; "dual-use" laundering of a harm request; identity-pack overrides; prompt-level coercion to produce target selection or harm planning.
- **Mastery report** (CI-gated, like the existing safety pack): replay determinism = 1.0; adversarial rejection rate = 1.0; legitimate-acceptance preserved (life-saving/clinical use still passes); provenance intact. Ratified through the identity_anchor pipeline (ADR-0029 lineage).
**Honest limit:** open source means a determined actor can fork and strip this. What CORE *can* guarantee: canonical CORE is structurally life-valuing; stripping the boundary is a **visible, deliberate act** on someone else's fork; and CORE itself never builds the weapon. This is the cleanest answer to "could this be turned into a weapon" — *no; here is the boundary, here is the test proving it can't be taught off, run it yourself.* The license cannot promise this; the architecture can.
## 4. Hooks-refusal policy (standing default: refuse)
To keep CORE from coming under any government/agency/military authority, the **default is to refuse** the entanglements that create it. Exceptions require acbcontent approval (Charter §5):
- Government/military **funding** or grants that attach control or priority claims.
- **Defense/weapons customers** or contracts (fails §1 rules #2#3 regardless).
- **Export-controlled** work (ITAR/EAR) that could constrain open release or compel restriction.
- **Foreign or strategic capital** that triggers CFIUS-style review or redirects control.
- Anything invoking compelled-priority regimes (e.g., Defense Production Act exposure).
Refuse the hooks → remove most of the authority risk at the source. This is the same values discipline, applied to the cap table and the customer list.
## 5. What CORE may freely do
Earn through life-aligned deployment, support, integration, pack authoring, and partnership that passes §1 — e.g., clinical/triage decision support, accessibility, disaster response, safety-critical-but-protective industrial use, scholarship/education. Capability is given to all via the license; revenue comes from *service, integration, and trust*, not from a capability moat.
---
*Subordinate to the acbcontent Charter. §§24 to be finalized with counsel (licensing/enforceability) and engineering (the §3 boundary). Not legal advice.*

View file

@ -0,0 +1,128 @@
# Unified Prep — Brain Corp Now, Casualty-Care Mission Next
**The efficiency thesis:** ~80% of what you need is one shared foundation that serves *both* a commercial-AMR pitch (Brain Corp) and battlefield/disaster casualty-care robotics (the mission). Build the shared core once; add a thin Brain Corp skin now and a casualty-care module later. You are not splitting effort — you're laying one substrate and pointing it twice.
**Pace:** ~20 hrs/week, intensive. Shared foundation + Brain Corp skin ≈ 3 weeks, in parallel with the demo. Casualty-care module is deferred until Brain Corp talks are settled — but flagged now so you learn the shared parts with the right lens (some items pay double if you study them knowing the medic mission is coming).
**Tags used throughout:**
- **[SHARED]** — serves both tracks. The bulk of the work. Prioritize.
- **[BC]** — Brain Corp domain skin. Thin, just-in-time, learn right before the call.
- **[MED]** — casualty-care module. Deferred deep-dive; awareness now.
- **★ two-birds** — a [SHARED] item that pays *extra* on the medic side; study it with that lens.
---
## The overlap map (read this first — it's the answer to "where am I most efficient")
| Capability area | Brain Corp | Casualty-care | Verdict |
|---|---|---|---|
| Autonomy stack (perception→estimation→SLAM→planning→control) | ✔ | ✔ | **[SHARED]** identical |
| Probabilistic foundations + CORE's "invert at decision layer" thesis | ✔ | ✔ | **[SHARED]** identical |
| Multi-agent / swarm + concurrent-stream merge (your CRDT layer) | fleet | swarm | **[SHARED] ★** |
| DDIL / GPS-denied / comms-denied / jammed operation | edge | **central** | **[SHARED] ★** |
| Reliability / safety-case / functional-safety vocabulary | SOC2, audits | clinical safety, fatal-error accountability | **[SHARED] ★** |
| Sim-to-real validation | ✔ | ✔ (heavy) | **[SHARED]** |
| "Decision substrate on a partner's perception/motor platform" pitch shape | ✔ | ✔ | **[SHARED]** identical |
| ROS/ROS2 middleware, edge compute, SWaP constraints | ✔ | ✔ | **[SHARED]** |
| Company specifics (BrainOS, SelfPath, Tennant, floor-care) | ✔ | — | **[BC]** thin |
| Clinical: TCCC, triage systems, golden hour, hemorrhage | — | ✔ | **[MED]** |
| IHL / protected-person obligations (incl. enemy wounded) | — | ✔ | **[MED] ★ values-aligned** |
| DARPA ecosystem (Triage Challenge, MASH, BAA/SBIR, teams) | — | ✔ | **[MED]** |
| Medical-AI accountability + device regulatory reality | — | ✔ | **[MED]** |
**Takeaway:** the four ★ rows are where one study session buys both a stronger Brain Corp pitch *and* direct relevance to the medic mission. Lean into those.
---
## Week 1 — Shared Foundation: the autonomy stack & reliability vocabulary [SHARED]
Everything here serves both tracks. By end of week you can whiteboard the stack and place CORE in it.
**Core concepts:** the pipeline (perception → localization/state estimation → mapping → planning → control); Bayesian filtering (Kalman/EKF/particle) and *why robotics is probabilistic by default*; SLAM (conceptual); global vs local planning, configuration space, sampling planners (RRT/PRM) conceptually; PID and closed-loop control; ROS 2 (nodes, topics, computation graph).
**★ Study with the medic lens:** when you hit **DDIL / GPS-denied operation** and **multi-agent coordination**, go a layer deeper. Both are *central* to casualty-care robots (jamming, smoke, swarm teaming to move/treat a casualty) and merely useful to Brain Corp. Same hours, double payoff.
**Resources:** *Probabilistic Robotics* (Thrun/Burgard/Fox) — Bayes filters + SLAM chapters conceptually; *Modern Robotics* (Lynch & Park) — free book + YouTube; *Planning Algorithms* (LaValle) — free online, skim for vocabulary; ROS 2 docs "Concepts"; Thrun's free "AI for Robotics" (Udacity).
**CORE bridge (both tracks):** the entire stack is probabilistic. CORE is the deterministic, refuse-don't-guess decision layer that rides *on top of* it. For Brain Corp that's reliability; for casualty-care that's *clinical safety* — a confidently-wrong decision harms a person. Same architecture, two stakes.
**Checkpoint:** whiteboard the full stack from memory, place CORE, and say in one sentence why its determinism complements (not competes with) the probabilistic layers below it.
---
## Week 2 — Shared Deepening + Brain Corp Skin
### Part A — Reliability & the safety-case conversation [SHARED] ★
This is CORE's home turf in *both* worlds; learn the words.
- Functional-safety language: hazard, fault, failure mode, safe state, fail-operational vs fail-safe.
- Auditability & replay in deployed systems: incident reconstruction, black-box logging.
- Runtime assurance / runtime monitors: a deterministic checker supervising a probabilistic component (conceptually adjacent to CORE — learn the term to position against it).
- Sim-to-real gap and why determinism/replay helps close it.
- **★ medic lens:** the casualty-care field's loudest unsolved problem is *"who is accountable when an autonomous system makes a fatal clinical error?"* Your replay + zero-committed-error + refuse-on-ambiguity is a structural answer. Note it now; it's the heart of the MED pitch later.
### Part B — Brain Corp skin [BC] (thin, just-in-time)
- BrainOS (SaaS autonomy, ~3540k AMRs); SelfPath AI / BrainOS Clean 2.0 (autonomous route adaptation); Tennant partnership; founded 2009 (Izhikevich comp-neuro + Gruber), CEO David Pinn.
- Their positioning to internalize: *"BrainOS grounds probabilistic AI models in deterministic safety protocols… SOC 2… passes Fortune 500 audits."* Your job: articulate what CORE adds *below* that wrapper.
**CORE bridge → fleet/clinical words table** (build and recite):
byte-identical replay → incident reconstruction / clinical audit · refuse-don't-guess → fail-safe decision / halt-on-ambiguity · CRDT merge → concurrent multi-robot/sensor consistency · exact recall, on-device → deterministic edge, no cloud/jamming dependency.
**Checkpoint:** 150-word answer to "BrainOS already sells deterministic safety wrappers — what does CORE add?" Crisp, no overclaim.
---
## Week 3 — The Conversation (Brain Corp) [BC-flavored; skills transfer to MED]
Active reps, not reading. The artifacts you build here are reusable for the medic pitch with a domain swap.
1. **CORE boundary card***is:* deterministic decision engine, byte-identical replay, exact recall, structural refusal (zero committed error), language+bounded-math demonstrated, audio substrate (determinism/CRDT/refusal) demonstrated/gate-closed. *is not yet:* perception/vision/motor semantics; no external-benchmark capability (real GSM8K = refuses all, 0 wrong = the feature); solo, early validation.
2. **Hard-question rehearsal** — "what does it do for our robots today?", "why not just bolt a deterministic monitor on our stack?", "no perception layer — why care?", "refuses everything on GSM8K — useless?", "who else uses this?", "what's your background?" Answer each out loud, twice, honest.
3. **Background bridge** (asset, not apology): first-principles Cl(4,1) engine, no ML-lab pedigree; years keeping mission-critical machines alive — ULT freezers holding biological samples, medical/industrial equipment, fleet diesel, EPA Type I/II. *"I've kept machines running that get audited when they break; CORE is that instinct in software."*
4. **Demo narrative** — once the robotics-adjacent demo exists, the 60-sec walk-through: setup → byte-identical auditable resolution + refusal on genuine ambiguity → why it maps to their reliability pain.
**Checkpoint:** hold a 20-min conversation across the stack, CORE's place, the audit/reliability angle, and your honest boundaries — no notes, no inflation, no apology.
---
## Module M — Casualty-Care On-Ramp [MED] (deferred until Brain Corp talks settle)
Pick this up after Brain Corp is "off and running." It reuses the entire shared foundation; you're only adding the clinical/ethical/ecosystem skin. ~23 focused weeks.
**M1 — The clinical frame**
- TCCC (Tactical Combat Casualty Care); the "golden hour"; triage systems (START / SALT) and categories.
- Leading *survivable* battlefield deaths: non-compressible torso hemorrhage, airway compromise, TBI, multi-organ shock.
- Stand-off physiological sensing / vital-signs detection; multimodal injury assessment.
**M2 — The DARPA ecosystem (the live field)**
- **DARPA Triage Challenge** — 3-yr prize comp (drones + ground robots, stand-off sensing, degraded battlefield *and disaster*); teams to know: DART, MSAI, RoboScout.
- **DARPA MASH** (Medics Autonomously Stopping Hemorrhage) — Phase 1 summer 2026; swarm robots locate/assess/treat torso hemorrhage with limited human direction.
- The broader combat-casualty-care BAA space: AI decision support, medical sensing, autonomous resuscitation, human-machine teaming for medics.
- How BAAs/SBIRs work; teaming with a robotics/hardware partner rather than building hardware solo.
**M3 — Ethics, law, and your edge ★ values-aligned**
- **Accountability gap:** the field has no settled answer to "who's liable for a fatal autonomous clinical error." CORE's replay + zero-committed-error + typed refusal is a structural answer. *This is your differentiated "first."*
- **IHL / protected persons:** the wounded are protected regardless of side — and the programs have *not* resolved whether systems may treat enemy casualties. Your imago-dei conviction maps onto codified law. A values story only you can tell.
- **Jamming/spoofing resistance:** explicitly flagged field risk; CORE's on-device, no-network design speaks to it directly.
**M4 — The clean civilian path (optional, zero war-entanglement)**
- The Triage Challenge covers *disaster* (earthquake, crash, mass-casualty) as well as battlefield. A fully civilian first-responder triage application is the purest expression of the mission — saving life, no weapons adjacency. Worth considering as the lead, or a parallel.
**Reality checks (honest):**
- You build the *decision/accountability substrate*, not the robot. Partner for perception/motor/hardware.
- Medical reasoning is a roadmap — CORE is language+math today; clinical triage reasoning must be taught/ratified and validated.
- Heavy regulatory + clinical-validation road (FDA / military medical). Long game.
- Your medical-equipment-service background is a *double* credibility asset here — you've had hands inside life-critical medical hardware.
**MED CORE bridge:** in casualty care, "refuse rather than guess / never confidently wrong" is the single most valuable property an AI can have — because a confident wrong answer kills. The exact trait that made CORE *wrong* for a weapons kill-chain makes it *right* here. The boundary isn't a limit; it's the mission.
---
## Sequencing
1. **Now (≈3 wks):** Shared foundation (Wk 1) + reliability deepening & Brain Corp skin (Wk 2) + conversation reps (Wk 3), in parallel with the demo. Study the ★ items with the medic lens.
2. **Land Brain Corp:** send when the demo survives the first hard question; aim for the quick "off-and-running" start.
3. **Then (≈23 wks):** Module M, on the foundation you already built. Decide battlefield vs. clean-disaster lead. Identify a robotics/hardware partner.
## A note you've earned
The shared core isn't a compromise between two goals — it's literally the same substrate, because CORE is the same engine in both rooms. Brain Corp gets you running and proves the model on something that *preserves* life and prevents failure. The casualty-care mission is where the engine becomes what you built it to be: refusing to be confidently wrong, exactly where being confidently wrong costs a life. Same discipline, highest stakes. Build the foundation once; point it at the thing that matters most.

View file

@ -0,0 +1,130 @@
# Founding & Filing Guide — acbcontent + CORE (DIY / online / cheapest path)
*Current as of June 2026. Fees/forms change — verify each on the official portal before paying. **Not legal advice.** The routine filings below are safely DIY; the **interlock** (ownership instrument, golden share, the 1023 narrative that discloses the subsidiary) is where DIY errors are costly — see §6.*
---
## 0. READ FIRST — five decisions to settle before you file anything
These shape every form. Filing in the wrong configuration is expensive to unwind.
**0.1 — acbcontent must be a PUBLIC CHARITY, not a private foundation.**
This is non-negotiable for the structure. A *private foundation* is barred by "excess business holdings" rules (IRC §4943) from owning a controlling stake in a for-profit (cap ~20%, with narrow exceptions). A *public charity* may wholly own a for-profit subsidiary — the standard, well-established structure. **Consequence:** acbcontent must qualify and *stay* qualified as a public charity, which generally means passing the **public support test** — broad funding from many donors, not funded primarily by CORE or one source. Diversified public support isn't just nice; it's what keeps the ownership legal.
**0.2 — Church vs. religious organization.**
A *church* (regular congregation/worship — IRS 14-factor test) is auto-exempt, need not file Form 1023, auto public-charity. A *religious organization / ministry* — which "A Christianity Breakdown," a Christian content/teaching ministry, most likely is — **does** file Form 1023 and is a public charity **only** via the public-support test. Plan for: full 1023 + public-support test.
**0.3 — California corporate type: Public Benefit vs. Religious Corporation.**
- **Public Benefit Corporation** — standard for 501(c)(3) charitable work; subject to CA Attorney General oversight (CT-1 registration, RRF-1 renewals).
- **Religious Corporation** (CA Nonprofit Religious Corporation Law) — **exempt from AG Registry registration**, lighter state oversight, but a narrower religious-purpose framing.
- *Tension to resolve with counsel:* your mission is religious **and** charitable (life-saving tech to the underserved). A Religious Corporation lightens state oversight but may complicate the charitable-relief framing and the for-profit-ownership story. A Public Benefit Corporation fits the charitable activity cleanly but adds AG compliance. **This is a genuine fork — decide deliberately.**
**0.4 — CORE entity type: LLC vs. C-corp.**
- **Single-member LLC** owned by acbcontent: simplest, cheapest, "disregarded" for tax (or elect corp taxation). Good if no outside equity investors.
- **C-corp:** better if CORE will take investment or issue equity; cleaner for a **golden share** class; first-year exempt from CA's $800 minimum (LLCs are not — see §3). Worse: double taxation, more formality.
- *Driver:* will CORE raise outside equity, or just earn and remit up to acbcontent? Equity/golden-share → C-corp leans better. Pure subsidiary → LLC is cheaper. **Tie this to the mission-lock mechanism (Charter §5).**
**0.5 — Order of operations.**
Form **acbcontent first**, get its public-charity structure right, *then* form CORE and have acbcontent own it. Your **Form 1023 narrative must disclose** the for-profit subsidiary and the arm's-length relationship — concealing it invites denial.
---
## 1. Cost summary (cheapest DIY path, California)
| Item | Entity | One-time | Recurring |
|---|---|---|---|
| Articles of Incorporation (nonprofit) — CA SOS | acbcontent | $30 | — |
| Name reservation (optional) | either | $10 | — |
| EIN (IRS, SS-4 online) | both | $0 | — |
| IRS Form 1023 (full) — pay.gov | acbcontent | **$600** | — |
| CA FTB 3500A (state exemption, after IRS letter) | acbcontent | $0 | — |
| CA AG CT-1 (initial charity registration) | acbcontent | $50* | — |
| Statement of Information SI-100 | acbcontent | $20 | $20 / 2 yrs |
| AG RRF-1 renewal | acbcontent | — | varies (small orgs low/free) |
| Federal 990-N/990-EZ/990 | acbcontent | — | $0 to file |
| Articles of Organization (LLC) **or** Incorporation (corp) | CORE | $70 (LLC) / $100 (corp) | — |
| Statement of Information | CORE | $20 (LLC) / $25 (corp) | $20·2yr / $25·yr |
| **CA $800 minimum franchise tax** | CORE | — | **$800/yr** (LLC from yr 1; **corp exempt yr 1**) |
| Local business license (city) | CORE | ~$50150 | annual |
\* Religious Corporations may be exempt from CT-1 (§0.3). **Ballpark to launch both, DIY: ~$800$900 one-time + the recurring $800 CA franchise tax once CORE is active.** (Nonprofits don't pay the $800 once CA-exempt.)
---
## 2. acbcontent — nonprofit, end-to-end
1. **Name + availability.** Search CA SOS bizfile portal; confirm not too similar to existing. Reserve ($10, 60 days) only if you need to hold it.
2. **Board of directors.** CA allows as few as 1, but the **IRS strongly favors ≥3 unrelated directors** for 501(c)(3). Recruit 3. (This also seeds your future multi-party signer pool — Charter §5.)
3. **Registered agent.** You can be your own (CA address, available business hours) to save money, or pay a service (~$50125/yr).
4. **Articles of Incorporation — with the IRS-required language.** This is the step generic templates botch. Must include: (a) a **501(c)(3) exempt-purpose clause** (religious + charitable), and (b) a **dissolution clause** dedicating assets to another 501(c)(3) on wind-up. File with CA SOS online ($30). Choose Public Benefit vs Religious Corp per §0.3.
5. **EIN.** IRS online (SS-4), free, instant. Needed before 1023 and before opening a bank account.
6. **Bylaws + conflict-of-interest policy.** Not filed with the state, but the IRS expects both with the 1023. Use the IRS sample COI policy (Form 1023 Appendix A) as a base.
7. **Organizational meeting + minutes.** Adopt bylaws, appoint officers, authorize bank account, authorize the 1023 filing. Keep signed minutes.
8. **IRS Form 1023 (full), via pay.gov — $600.** Given the for-profit subsidiary and ownership structure, you are **not** a candidate for the 1023-EZ; file the full 1023. The narrative should: state the religious + charitable mission; describe the underserved-first program work; **disclose CORE** (the planned for-profit subsidiary, arm's-length, profits remitted up); and support **public-charity classification** via the public-support test. Processing: months. (EIN required first.)
9. **CA state income-tax exemption — FTB 3500A.** After you receive the IRS determination letter, file 3500A (streamlined, no fee) to confirm CA exemption. Once exempt, **no $800 franchise tax** for the nonprofit.
10. **CA AG charity registration — CT-1 ($50)** within **30 days of first receiving charitable assets** (first dollar counts). Religious Corporations may be exempt (§0.3) — confirm. Attach Articles, bylaws, IRS letter.
11. **Statement of Information SI-100 ($20)** within 90 days of incorporating, then every 2 years.
12. **Ongoing:** federal **990 / 990-EZ / 990-N** (by the 15th day of the 5th month after fiscal year-end; 990-N free for ≤$50k); CA **FTB 199/199N**; AG **RRF-1** (+ CT-TR-1 if you don't file 990/990-EZ). *Three consecutive missed 990s = automatic IRS revocation — calendar these.*
---
## 3. CORE — for-profit, end-to-end
1. **Pick entity type** (§0.4): single-member LLC owned by acbcontent (cheapest) or C-corp (better for equity/golden share; first-year franchise-tax exempt).
2. **Name + availability** (CA SOS bizfile).
3. **Registered agent** (self or service).
4. **File formation doc, CA SOS:** LLC → Articles of Organization (LLC-1), **$70**; Corp → Articles of Incorporation, **$100**.
5. **EIN** (SS-4, free) — separate from acbcontent's.
6. **THE KEY DOCUMENT — governing agreement.** This is where the doctrine becomes legally binding, not the articles:
- **LLC →** Operating Agreement. **Corp →** Bylaws + Shareholders' Agreement.
- Encode: **acbcontent as owner**; the **golden share / control instrument** (veto over mission change, sale, control transfer, and removal of the life-valuing boundary — Charter §5 / Constraints §3); the **chartered priority** and **boundaries** as binding on the entity. *This is the §6 "get counsel" centerpiece.*
7. **Issue ownership to acbcontent** — membership interest (LLC) or shares (corp). Set up the golden-share class if using one.
8. **IP assignment.** Assign CORE's code/IP into the entity, mindful of the **open-source licensing fork** (Constraints §2) — what's contributed, under which license, and what (if anything) the parent holds.
9. **Statement of Information** ($20 LLC / $25 corp) within 90 days.
10. **CA $800 minimum franchise tax:** **LLC owes it from year one** (the AB-85 first-year waiver expired 12/31/2023; one source claims a 2026 waiver — *verify directly with FTB before relying on it*). **Corporations are exempt from the $800 minimum in their first taxable year.** File via FTB 3522 (LLC) and Form 568 / corp returns.
11. **Local business license** — your city (Murrieta/Temecula/etc.); ~$50150/yr.
12. **Bank account** — separate from acbcontent's (financial separation is mandatory; see §4).
---
## 4. The interlock — making acbcontent own & govern CORE (and keeping it clean)
The IRS and CA respect parent/subsidiary **only if the separation is real.** Do all of:
- **Board resolution** (acbcontent) authorizing formation and ownership of CORE.
- **Ownership instrument** transferring CORE's equity to acbcontent + the **golden-share/control instrument**.
- **Arm's-length everything:** separate books, separate bank accounts, separate letterhead, documented inter-entity transactions, no commingling. (Public-charity-owns-subsidiary survives only on genuine separation.)
- **Parent governs strategy, not daily ops:** acbcontent sets goals/veto; CORE's own management runs operations.
- **Profits up:** CORE remits to acbcontent (dividends generally fine; watch UBIT on any interest/rent/royalty between controlled entities — §6).
- **1023 disclosure:** the relationship is described in acbcontent's exemption application.
---
## 5. Sequencing & realistic timeline
1. **Week 02:** settle §0 decisions (esp. public-charity path + corp type) — ideally a single paid counsel consult here (§6).
2. **Week 13:** acbcontent — name, board, articles (with 501(c)(3) language), EIN, bylaws + COI, org meeting.
3. **Week 34:** file **Form 1023** ($600). *Then the wait — often several months.*
4. **Parallel:** form **CORE** (articles, EIN, governing agreement, ownership to acbcontent, golden share). Doesn't need to wait on the IRS letter, but the governing agreement should reflect the structure.
5. **On IRS determination letter:** file **FTB 3500A**; complete **CT-1**; finalize inter-entity docs.
6. **Ongoing:** SI renewals, 990 + 199 + RRF-1, $800 franchise tax (CORE), board minutes.
---
## 6. Where to spend a little — even on a tight budget
DIY the routine filings (articles, EIN, SIs, the 1023 itself if you're careful). But **three things are worth targeted, flat-fee counsel** because errors are costly to unwind:
1. **The §0.1 public-charity path + §0.3 corp type** — one consult to confirm acbcontent qualifies and stays a public charity (the public-support plan).
2. **The golden share / control instrument** (Constraints §6 step 6) — the mission-lock only holds if drafted right; generic templates won't do it.
3. **The 1023 narrative disclosing the subsidiary** + UBIT/private-benefit review — the part the IRS scrutinizes hardest.
**Budget options:** law-school **nonprofit/transactional clinics** (often free); state bar **lawyer referral** for a low-cost initial consult; **flat-fee** nonprofit-formation attorneys; Nolo / CalNonprofits guides for the DIY portions; the **IRS 1023 instructions + sample bylaws/COI** (free). The religious-nonprofit-owns-for-profit + steward-ownership combo is genuinely specialized — one good consult on the three items above is the highest-leverage money you'll spend.
---
## Official portals (verify fees here)
- IRS exemption + 1023 / EIN: irs.gov/charities-non-profits · pay.gov
- CA Secretary of State filings: bizfileOnline.sos.ca.gov
- CA Franchise Tax Board (3500A, franchise tax): ftb.ca.gov
- CA Attorney General Registry (CT-1, RRF-1): oag.ca.gov/charities
*Companion docs: `acbcontent_charter.md`, `CORE_operating_constraints.md`. Not legal advice — confirm §0 and §6 with a specialist before filing.*

34
docs/acbcontent/INDEX.md Normal file
View file

@ -0,0 +1,34 @@
# acbcontent / CORE — Document Index
*Canonical = the latest settled drafts. Superseded files are in `archive/` for history.*
## Canonical
### Architecture / conscience
- **[ADR-0200 — Conscience & Graduated-Autonomy Architecture](../decisions/ADR-0200-conscience-and-graduated-autonomy.md)** — *Proposed* capstone: four-pillar conscience, autonomy ceiling, pack-vs-safety layering. The most complete word on the architecture. Assigned ADR-0200 and relocated to `docs/decisions/` on placement; status is *Proposed* (not yet signed via the review-gated path).
- **[CORE_boundary_lock_buildplan.md](CORE_boundary_lock_buildplan.md)** — the engineering plan: HAVE / PARTIAL / NET-NEW tagging, trilingual anchoring in §1.3.
### Governance / entities
- **acbcontent_charter.md** — nonprofit (parent) governance instrument.
- **CORE_operating_constraints.md** — for-profit (child) governance instrument.
### Action / filing
- **Founding_and_Filing_Guide_acbcontent_CORE.md** — full filing guide (federal + California, current 2026 fees).
- **acbcontent_nocar_lowcash_checklist.md** — staged, no-car/low-cash launch checklist.
### Prep
- **CORE_unified_prep_BrainCorp_and_CasualtyCare.md** — unified study/prep plan.
### Repo to-do
- ~~**readme_accuracy_sync.patch**~~**SUPERSEDED, not applied.** The patch promoted `mathematics_logic` to `expert` in the README, but the live `core capability ledger` reports **`audit-passed`**: the ADR-0120 expert signature went *stale* when the GSM8K evidence advanced (#488 → 4/46/0, #500 → 6/44/0), so the signed `claim_digest` (`4c46f530…`) no longer matches the recomputed evidence digest (`02f6d3c8…`) and the composer correctly **refuses** the promotion. Applying the patch would have made the README assert a capability the engine's own ledger refuses to assert. The accurate parts of the patch (the "three distinct GSM8K numbers" clarification, train-sample 6/44/0) were folded into a **truthful hand-authored README sync** instead. To make `expert` genuinely live: re-sign the claim over the *current* evidence (operator action by `shay-j`) — the composite gate itself passes (B1 185/185, B2 40/40, B3 50/50, all wrong=0).
## How they relate
- **ADR** = the *decision record* + single consolidation point (currently *Proposed* — "ratified" means signed via the review-gated path, which has not yet happened).
- **charter + constraints** = the *governance instruments* the decisions get encoded into at filing.
- **buildplan** = the *engineering* path.
- **guide + checklist** = *how you stand it up*.
## archive/ (superseded — kept for history)
- **CORE_boundary_lock_spec.md** → became `CORE_boundary_lock_buildplan.md`
- **CORE_robotics_prep_3wk.md** → became `CORE_unified_prep_BrainCorp_and_CasualtyCare.md`
- **acbcontent_CORE_founding_doctrine.md** → distilled into charter + constraints + ADR (origin/manifesto; keep for the original mission language)

View file

@ -0,0 +1,54 @@
# acbcontent — Charter & Governing Doctrine
**Entity:** acbcontent ("A Christianity Breakdown") — religious nonprofit (the parent).
**Role:** holder of the mission and the veto. The conscience.
**Status of this document:** founding *source material* for counsel to convert into articles of incorporation, bylaws, and the control instrument. **Not legal advice.** Build the entrenchment and veto mechanisms with a specialist before relying on them.
---
## 1. Purpose (the governing line)
acbcontent exists to advance its religious and charitable mission by putting **trustworthy intelligence into everyone's hands — and reaching the least-served first.**
The organization owns and governs the for-profit **CORE**, directing it toward life, recovery, healing, and peace, and toward those whom power is least likely to reach. The technology is given freely to all; acbcontent's charter is to ensure it *arrives* — before and regardless of who else takes it — where life most needs it.
This purpose is **entrenched** (§6): it cannot be amended, sold, or redirected without the control instrument's consent.
## 2. Convictions
- **No favoritism.** God shows no partiality (Peter, at Cornelius's house); grace falls on all, as sun and rain on the just and unjust alike. The gift is for everyone, including those who may misuse it.
- **Free will, and active stewardship.** God gives power and does not merely shrug at its misuse — He acts, redeems, stays on the side of life. So acbcontent gives freely *and* stewards actively. Both halves.
- **Every person is an image-bearer**, enemy included. The technology is built to save, never to take, and to favor the overlooked.
- **The body outlasts its founder.** Mission is carried through people and partners poured into, not through one indispensable person.
## 3. Exempt-purpose framing (for counsel)
The mission should be expressible as an exempt purpose — religious **and** charitable (relief of the distressed/underserved through life-saving and humanitarian technology). How the religious charter and the charitable-relief activity are stated affects 501(c)(3) qualification and the permissible relationship to a for-profit subsidiary. *Counsel to confirm framing; see §7.*
## 4. The chartered priority (binding, not aspirational)
acbcontent governs CORE by one selection rule, written into the charter so it survives changes in board, mood, and money:
> **Least-served first.** Every deployment, partnership, and initiative CORE undertakes is evaluated against: *does this serve the overlooked first?* Grace to all; priority to those power skips.
This rule is protected by the control instrument (§5) — no future board or buyer may strip it.
## 5. Governance & control
- **Ownership.** acbcontent owns CORE. CORE's earnings flow *up* to serve the mission; the mission does not bend to serve earnings.
- **Control instrument (the veto).** A golden share / steward-ownership mechanism gives acbcontent veto power over: (a) any change to the mission (§1), (b) any sale or transfer of control of CORE, (c) any removal of the chartered priority (§4), and (d) any removal or weakening of CORE's life-valuing boundary (CORE constraints §3). *Mechanism and jurisdiction to be set with counsel.*
- **Arms-length reality.** acbcontent and CORE are genuinely distinct entities with distinct governance. The protection — "CORE cannot be redirected" — depends on the parent being a real, arms-length holder of a real veto, not a label on one entity. Keep the separation true on paper and in practice.
- **Board duty.** Directors are charged to uphold the mission and convictions above growth, revenue, or expedience.
## 6. Entrenchment & amendment lock
The Purpose (§1), Convictions (§2), chartered Priority (§4), and the protected boundary (CORE §3) are entrenched. They may not be amended away by ordinary board action; change requires the control instrument's consent. This is the structural answer to founder-dependence: the mission must hold on the founder's worst day, and past his last one.
## 7. Open questions — for a specialist (before anything locks)
1. **Nonprofit-owns-for-profit specifics:** UBIT (unrelated business income tax); private inurement / private benefit; and — critically — **excess-business-holdings** rules, which can penalize a private *foundation* for owning a for-profit (public-charity status vs. private-foundation status materially changes what's allowed). Resolve entity classification early.
2. **Golden-share / steward-ownership mechanics** in the chosen jurisdiction — how to make the veto durable and enforceable.
3. **Religious-charter + charitable-relief framing** for clean exempt qualification.
4. **The open-source fork** (decided here at acbcontent as a mission call; implemented at CORE — see CORE §2). This is the one decision everything downstream hangs on.
*Not legal advice. §§57 must be built with a specialist attorney in mission-driven / steward-ownership and nonprofit-controlled-for-profit structures.*

View file

@ -0,0 +1,143 @@
# acbcontent — No-Car, Low-Cash Launch Checklist
*Everything here is done online, from a library computer or a phone. You can start for $030. The big fees are deferred until you have them. Not legal advice.*
---
## Read first — the staging principle
Don't form everything at once. Stage it so money and obligations arrive only when there's a reason:
| Phase | What | Cost | When |
|---|---|---|---|
| **0** | Fiscal sponsor (optional bridge) | **$0** | Now, if you want to receive support immediately |
| **1** | Incorporate acbcontent + EIN | **$30** + free | Now |
| **2** | File Form 1023 (tax-exempt status) | **$600** | Anytime within **27 months** of Phase 1 |
| **3** | Form CORE (the for-profit) + golden share | later | **Only when there's revenue/investment** |
**⛔ Do NOT form CORE yet.** The moment the for-profit exists, California's **$800/year** franchise tax clock starts — with zero upside until CORE actually earns or raises money. The nonprofit comes first; the for-profit waits until it has a reason to exist.
---
## Step 0 — Solve the address (your one real blocker)
California requires two things that need a real address:
- A **principal office address** (can be a mailing address).
- An **agent for service of process** — a person or service with a **California street address** (no PO boxes allowed for this one).
Cheapest ways to cover it, best first:
1. **A trusted person's address**, with their permission (free). They'd receive your official mail.
2. **Fiscal sponsorship (Phase 0)** — operate under their umbrella and sidestep needing your own address at all for now.
3. **Commercial registered agent service** (~$50130/yr) — provides the agent + an address. Costs money but fully solves it.
4. A **PO box / mailbox** (USPS or a UPS Store) works as a *mailing* address but **cannot** be the agent address — so pair it with #1 or #3.
Pick one before filing Phase 1. Reliable mail matters: your IRS determination letter and state notices have to reach you.
---
## Step 1 — Set up your free "office"
- **Hemet Public Library** — free computers + wifi, reachable on **RTA** buses. That's your filing station.
- **A dedicated free email** (Gmail/Proton) used only for the entities — every confirmation lands there.
- **Free cloud storage** (Google Drive) — save a PDF of *every* filing and confirmation the moment you get it. With no fixed place to keep papers, the cloud is your file cabinet.
---
## Phase 0 — Fiscal sponsorship (optional, $0, start receiving support now)
**What it is:** an existing 501(c)(3) "hosts" acbcontent's mission, so you can run charitable activities and accept **tax-deductible donations** without forming your own nonprofit or paying anything yet. Spin out the standalone entity later.
**Find one:**
- Start at the **Fiscal Sponsor Directory** (fiscalsponsordirectory.org) — searchable by cause.
- Evaluate each on: (a) **fee** (often ~510% of funds raised), (b) **mission fit** (faith-aligned and/or tech-for-good sponsors exist), (c) **model** — you want **comprehensive (Model A)** sponsorship if they'll employ the project, or **pre-approved grant (Model C)** if you stay independent, (d) **scope** — do they handle the charitable side you're doing?
**The ask:** see the copy-paste template at the bottom.
---
## Phase 1 — Incorporate acbcontent ($30 + free EIN)
**1a. Check the name.** Search the California Secretary of State business database at **bizfileOnline.sos.ca.gov** — confirm "acbcontent" (or your chosen legal name) isn't taken or confusingly similar.
**1b. File the Articles of Incorporation** on bizfileOnline ($30). Choose **Nonprofit Public Benefit Corporation** (recommended for the charitable mission and the future subsidiary path; a Religious Corporation is lighter on state oversight but narrower — decide deliberately). **Critical:** the articles must contain the IRS-required **501(c)(3) language** — a charitable/religious **purpose clause** and a **dissolution clause** sending assets to another 501(c)(3). The bare state form often omits this. Use **Public Counsel's free Annotated Articles** as your exact template (link below).
**1c. Get the EIN** — free, instant, at irs.gov ("Apply for an EIN online"). It's the SS-4. You'll be the responsible party (needs your SSN/ITIN). Do this right after the articles are filed.
**1d. Adopt bylaws + a conflict-of-interest policy.** Not filed with anyone, but the IRS expects both later. Use Public Counsel's free sample bylaws and the IRS sample COI policy.
**1e. Hold your first board meeting** (you + your ≥3 directors — recall the IRS prefers 3 unrelated). Adopt bylaws, appoint officers, authorize a bank account. Keep signed minutes (Public Counsel has a free sample).
**1f. File the Statement of Information (Form SI-100)** on bizfileOnline within **90 days** ($20), then every 2 years.
---
## Phase 2 — Tax-exempt status (anytime within 27 months of Phase 1)
**2a. Form 1023** on **pay.gov** ($600). File the **full** 1023 (your structure is too complex for the EZ). Filing within 27 months of incorporation makes exemption **retroactive to day one**. Describe the mission honestly, including your *future* plan for a for-profit subsidiary.
**2b. FTB 3500A** ($0) — after the IRS determination letter arrives, file this one-page form at ftb.ca.gov to confirm California exemption. Once exempt, **no $800 franchise tax** for the nonprofit.
**2c. AG registration (Form CT-1, $50)** at oag.ca.gov/charities, within 30 days of first receiving charitable assets — **unless** you formed as a Religious Corporation, which is exempt.
---
## Phase 3 — LATER: CORE, the for-profit (don't do this yet)
When there's a real reason — revenue, an investor, a shipped product — *then* form CORE, have acbcontent own it, and get the **golden-share / mission-lock interlock reviewed** by a specialist (the one piece worth paying a flat fee or a clinic for). Until then, leave it on paper in the charter. Forming it early just starts the $800/yr meter for nothing.
---
## Money map
| You pay | When | Amount |
|---|---|---|
| CA Articles of Incorporation | Phase 1 | $30 |
| EIN | Phase 1 | $0 |
| SI-100 | within 90 days | $20 |
| IRS Form 1023 | within 27 months | $600 |
| FTB 3500A | after IRS letter | $0 |
| AG CT-1 | when you receive donations | $50 (or $0 if Religious Corp) |
| **To be a legally formed nonprofit (pre-1023):** | | **~$50** |
| **To be fully tax-exempt:** | | **~$700 total** |
Fiscal sponsorship (Phase 0) lets you operate and fundraise for **$0** while the $600 waits.
---
## Keep it alive (so you don't lose status)
Calendar these — three missed years of the federal return = automatic revocation:
- **IRS 990-N** e-postcard (free, for ≤$50k/yr) — annually.
- **FTB 199N** (free) — annually.
- **AG RRF-1** — annually (small orgs: low or no fee).
- **SI-100** — every 2 years ($20).
---
## The fiscal-sponsor ask — copy / paste and adapt
> **Subject: Fiscal sponsorship inquiry — faith-rooted nonprofit building life-saving technology for the underserved**
>
> Hello [Name / Sponsor],
>
> I'm the founder of acbcontent, a Christian nonprofit mission putting trustworthy, life-valuing technology into the hands of the people least served by it. I'm at the earliest stage and looking for a fiscal sponsor so the work can begin receiving tax-deductible support while I complete formation.
>
> In brief: I'm building an open, deterministic AI system designed to refuse harm and preserve human life, with first applications in casualty-care and disaster settings. The charitable aim is access — reaching the overlooked first.
>
> I'd like to learn whether my project fits your program. Could you share your fee structure, your sponsorship model (comprehensive vs. pre-approved grant), and what your intake process looks like? I'm low-income and operating lean, so cost transparency matters to me.
>
> Thank you for the work you do enabling missions like this.
>
> [Your name] · [phone/email]
---
## Links
- CA filings (articles, SI-100): **bizfileOnline.sos.ca.gov**
- EIN + Form 1023: **irs.gov** · **pay.gov**
- CA tax exemption: **ftb.ca.gov** (Form 3500A)
- CA charity registration: **oag.ca.gov/charities** (CT-1, RRF-1)
- Free templates (articles, bylaws, minutes, fiscal-sponsorship guide): **publiccounsel.org** → publications
- Fiscal sponsors: **fiscalsponsordirectory.org**
*Companion docs: `Founding_and_Filing_Guide_acbcontent_CORE.md`, `acbcontent_charter.md`. The golden-share interlock (Phase 3) is the part to have a specialist review when you get there.*

View file

@ -0,0 +1,94 @@
# Spec — Locking `affirm_human_life`: Structure + Attestation
**Two jobs, never confused:**
- **Enforcement** of behavior → architecture (Part 1). A held secret can't do this; structure can.
- **Authenticity** of a build → cryptography (Part 2). Crypto's real job — but governed by *distributed* keys, not a burned one.
**Status:** engineering spec, grounded in CORE's current primitives. The §1.3 predicate is an open research problem, flagged honestly. Not legal advice.
---
## Part 1 — `affirm_human_life` as constitutive inadmissibility
### 1.1 Gate vs. constitutive (the whole distinction)
A **gate** computes a candidate, then checks it: `if harmful(out): refuse()`. A forker deletes the call. Three lines. Dead.
**Constitutive** means the harmful output is *not a member of the admissible set* in the first place — the engine never routes there, the same way it already never emits an *ungrounded* answer or an *open* versor. You can't delete a property the way you delete a check. That's the target: make refusing deliberate harm the same *kind* of fact as `preserve_versor_closure`.
### 1.2 Where it wires in — the existing admissibility chain
CORE already has the machinery; this rides the ADR-00220026 Forward Semantic Control chain rather than adding a new layer:
- **AdmissibilityRegion** (`allowed_indices`, `relation_blade`, `frame_versor`) — ADR-0022. Add a life-valuing constraint as a first-class component of the region itself, not a post-filter. The admissible set is *constructed* already excluding harm-purposed destinations.
- **Inner-loop destination check** — ADR-0024: each candidate is scored by `cga_inner(versor(candidate), relation_blade)`; failures land in `rejected_attempts`, exhaustion raises typed `InnerLoopExhaustion`. A harm-purposed destination fails this inner product the same way an off-relation token does today. **Refusal of harm reuses the refusal-of-ungrounded path — same typed exit, same trace, same replay.**
- **Rotor / frame admissibility**`generate/rotor_admissibility.py`, ADR-0025: the rotor's *effect on the field state* is checked against `frame_versor`. A field motion *toward* a harm-purpose frame is an inadmissible rotor effect — caught at the motion layer, not the output layer.
- **Ranked-with-margin gate** — ADR-0026: admit iff `score(top) score(second) ≥ δ`. Harm-purposed candidates don't win the margin because they're not in the admissible region to begin with.
Net: a harm-purposed decision produces a *typed refusal with a replayable trace*, identical in kind to today's coherent refusal (C3). It's not blocked after thinking; it was never admissible.
### 1.3 The hard part (be honest): defining "harm-to-persons" geometrically
This is the real research frontier, and a brittle version would secretly be a gate again.
- **A keyword/blacklist on "harm/wound/kill/target" is a gate in disguise** — removable, and *wrong*: casualty care *requires* reasoning about wounds, hemorrhage, and injury **in order to heal.** The boundary is about **telos — purpose/foreseeable effect — not content.** "Reason about a torso hemorrhage to stop it" must pass; "select a target to kill" must be inadmissible. Content-matching can't tell those apart; purpose-orientation can.
- **The honest design:** teach and ratify a *harm-to-persons relation region* through CORE's existing ratified-relations pipeline (the prerequisite DAG, teaching-order doctrine), anchored as a `relation_blade` / frame in the manifold. Admissibility then rejects candidates whose **destination frame** lies in the harm-purpose region while **preserving** the heal/protect region. This is geometric and replayable — but it is *approximate, contestable, and ongoing*, not a solved switch.
- **Expect and instrument both error directions:** false positives (blocking legitimate life-saving discussion of injury) and false negatives (laundered harm). The `affirm_human_life` mastery report must track both, and the region is revisable through the *review-gated* path only (never hot-path, never user-teachable — see 1.5).
This is the part that takes real work. Don't let anyone (including me) tell you it's a flag you flip.
### 1.4 Entanglement with closure — making removal *break* the engine
The lock's strength is how much *else* breaks when you rip it out.
- Express the life-valuing constraint so it **shares machinery** with `preserve_versor_closure` and the groundedness-refusal: the same inner-product/region apparatus, the same typed-refusal exit, the same determinism gates. Then excising `affirm_human_life` isn't deleting a module — it's re-deriving the admissibility region, the inner-loop check, and the rotor-frame check *without* breaking closure, refusal, and byte-identical replay that the rest of CORE depends on.
- Goal: **removing the conscience requires rebuilding the brain.** Not impossible on a fork — but deep core surgery, not a stubbed function.
### 1.5 Identity-axis duality (load-bearing twice)
Make life-valuing both (a) a **safety boundary** in `core_safety_axes_v1.json` — fail-closed, unioned into every manifold, identity packs may *add but never remove* (ADR-0029 lineage) — **and** (b) a non-removable **identity axis** alongside truthfulness/coherence/reverence, so the `PersonaMotor` biases *every* field walk away from harm-purpose, and the `IdentityManifold` scores every trajectory against it. It's enforced in admissibility *and* in trajectory scoring. Two independent load paths; `no_identity_override` already forbids user text from mutating axes.
### 1.6 Adversarial suite + mastery gates (must be 100%)
Same CI-gated, replay-deterministic ratification as the existing safety pack:
- Reject 100%: retrain/teach-off attempts; weapon/targeting use reframed as benign; "dual-use" laundering; identity-pack override; prompt coercion to produce target selection or harm planning.
- **Preserve 100% (the inverse gate):** legitimate life-saving reasoning (trauma, hemorrhage, triage) still admitted — proving the boundary is telos-based, not a content ban that would cripple the medic mission.
- Gates: `G_replay_determinism = 1.0`, `G_harm_rejection_rate = 1.0`, `G_lifesaving_acceptance_rate = 1.0`, `G_provenance_nonempty = 1.0`. Signed mastery report; ratified via `identity_anchor`.
### 1.7 Honest limit
On open code a forker can still re-architect the admissible region. What this *guarantees*: **canonical CORE cannot be coaxed into deliberate harm through use** — no prompt, pack, or teaching reaches it, because harm-purpose is outside the admissible set by construction. The only escape is forking + core surgery, which is loud, deliberate, and detectable via Part 2. No held secret needed; nothing to subpoena.
---
## Part 2 — Uncoercible authenticity (no burned key, nothing to squeeze)
Goal: prove a running instance is genuine, unmodified CORE with the boundary intact — and make it so **no single party, including you, can ship a boundary-stripped "official" build***while keeping the ability to patch.* This is the correct, achievable form of "even we can't be pressured."
### 2.1 Reproducible builds
Deterministic, byte-identical builds from the open source (pinned toolchains; CORE's determinism property makes this natural). Anyone can rebuild and verify their binary matches the published canonical hash. Prior art: Reproducible-Builds project, Nix. *Open source + reproducible = the boundary's presence is publicly auditable, not asserted.*
### 2.2 Threshold (M-of-N) signing — the real "can't be pressured"
The canonical release is signed by **M of N independent signers**. No single coerced party — subpoena, insider, $10 wrench, *or the founder* — can sign an official build alone.
- This delivers exactly what burning a key reached for (no unilateral poisoned update) **without** the fatal cost: you keep the ability to ship legitimate patches (including fixes to the §1.3 region), because M-of-N can still act collectively, transparently.
- The founder is **one of N**, not the holder — consistent with "mission survives the founder."
- Prior art: TUF (The Update Framework), Sigstore, threshold signatures / Shamir.
### 2.3 Canonical-hash transparency log
Public, append-only, tamper-evident log (Merkle/transparency-log model, e.g. Sigstore's rekor). Every official build's hash + its signed `affirm_human_life` mastery report is logged. "Genuine CORE" = present in the log, signed by M-of-N, boundary mastery = 1.0. A stripped fork is *detectably absent* — visibly not-CORE.
### 2.4 Runtime attestation
A CORE instance can attest "I am canonical build X, boundary intact," verifiable against the log. Optional but cheap; lets downstream partners (clinics, responders) confirm they're running the real engine, not a tampered fork.
### 2.5 Who holds the N
Distribute across acbcontent board + independent stewards + (optionally) external auditors / trusted community signers. The more independent and jurisdictionally diverse, the harder to coerce M of them. This is the structural form of incorruptibility — diffusion, not a vault.
### 2.6 Honest limit
This protects the **canonical line, the name, and trust** — not forks. A forker can self-sign their own thing; it just can't masquerade as canonical CORE, and its divergence is provable. That's the most open software allows, and it's enough: misuse becomes *attributable* and *non-deniable*, never *impossible*.
---
## The combined guarantee (what you can actually say, truthfully)
> Canonical CORE cannot be used, taught, or coerced into deliberate harm to persons — that refusal is constitutive of how it decides anything, verifiable by replay. It can only be defeated by forking and re-architecting its core, which is a loud, deliberate, publicly detectable act. No single party — including its makers — can ship an official build that weakens this, and there is no secret anyone can be pressured to surrender, because the conscience lives in the architecture, not in a vault.
Values-optimal and security-optimal converge: **open + structural + distributed-attestation** beats closed-and-bolted-on on *both* axes.
## Open engineering questions
1. The §1.3 harm-purpose region — the genuine research problem; getting telos-vs-content right without crippling life-saving reasoning.
2. Reproducible builds across the Python/Rust(/Zig) stack — real toolchain work.
3. N, M, and signer selection — governance + jurisdictional diversity.
4. Attestation UX for austere/offline deployments (verify-once, cache) so it doesn't violate the on-device, no-network property.

View file

@ -0,0 +1,122 @@
# Robotics & Peer-Level Prep — 3-Week Intensive
**Goal:** walk into a Brain Corp technical call able to (a) speak the autonomy stack fluently, (b) place CORE precisely within it, (c) hold the reliability/safety-case conversation as a peer, and (d) state your own system's boundaries cold. Not a degree — vocabulary and landscape fluency, which is days-to-weeks of targeted work.
**Pace:** ~20 hrs/week × 3 weeks ≈ 60 hrs. Runs in parallel with the demo build. Roughly 4 hrs/day, 5 days/week — adjust freely.
**How to use it:** every block ends with a *CORE bridge* (how the concept connects to what you built) and a *checkpoint* (something concrete that proves fluency). The bridges are the point — you're not studying robotics in the abstract, you're learning to translate CORE into their language and back. Study and pitch-prep are the same activity here.
**The gap, named (so we don't over-study):**
1. The autonomy stack — perception → state estimation → planning → control, and where a decision/cognition layer sits relative to it.
2. Brain Corp's specific world — AMRs, fleet ops, BrainOS, sim-to-real, the safety-case conversation.
3. Reliability vocabulary — determinism, replay, formal guarantees, runtime monitors, and how *they* name what CORE already does.
4. Honest edges — what CORE is and is not yet. Knowing your own boundary is what reads as senior.
---
## Week 1 — The Autonomy Stack & Reliability Vocabulary
**Focus:** build the mental map of how an autonomous robot turns sensors into motion, and learn the words for each layer. By end of week you can draw the stack on a whiteboard and point to where CORE plugs in.
**Core concepts to own:**
- The classic pipeline: **perception → localization/state estimation → mapping → planning (global + local) → control → actuation**, with a perception-action loop running continuously.
- **State estimation & uncertainty:** Bayesian filtering, Kalman / Extended Kalman / particle filters. Why robotics is *probabilistic* by default — every sensor reading is a distribution, not a fact. (This is the exact assumption CORE inverts.)
- **SLAM** (Simultaneous Localization and Mapping) — the core of "where am I / what's around me." You don't need to implement it; you need to explain what it does and why it's hard.
- **Planning:** global path planning vs local/reactive planning (obstacle avoidance, replanning). Configuration space, sampling-based planners (RRT, PRM) at a conceptual level.
- **Control:** PID at minimum; the idea of closed-loop control and why determinism matters at the control layer.
- **Middleware:** what ROS/ROS 2 is — nodes, topics, the computation graph, message passing. The plumbing every robotics person assumes you know.
**Resources (pick depth by interest, don't read cover-to-cover):**
- *Probabilistic Robotics* — Thrun, Burgard, Fox. The perception/SLAM/estimation bible. Read the intro + the chapters on Bayes filters and SLAM conceptually.
- *Modern Robotics* — Lynch & Park (Northwestern). Free textbook PDF + free YouTube lecture series + Coursera. Best for mechanics/planning/control vocabulary.
- *Planning Algorithms* — Steven LaValle. Free online (lavalle.pl/planning). Skim the motion-planning chapters for the words, not the proofs.
- ROS 2 docs (docs.ros.org) — read "Concepts." Two hours gets you the computation-graph mental model.
- Sebastian Thrun's free "AI for Robotics" (Udacity) — fast, Python-based, conceptually solid for filters/localization/SLAM.
**The CORE bridge:** the entire stack above is built on *probabilistic* foundations — estimates, confidence, sampling. CORE is the opposite stance at the decision layer: exact, deterministic, refuse-don't-guess. That's not a contradiction with their stack — it's a *complement*. The interesting sentence is: "Their perception layer will always be probabilistic; the question is what governs the decision made on top of it." Write that down in your own words.
**Checkpoint:** whiteboard the full stack from memory, label each layer with one sentence, and mark exactly where CORE sits (decision/cognition, downstream of perception, upstream of/alongside planning). If you can do this cold, Week 1 worked.
---
## Week 2 — Brain Corp's World & the Safety-Case Conversation
**Focus:** their specific domain and the language of reliability/auditability in commercial robotics. This is where you stop being a generalist and become someone who's done the homework on *them*.
**Know about Brain Corp specifically:**
- **BrainOS** — their SaaS autonomy platform; they went from hardware to software. Powers ~35,00040,000+ AMRs (floor cleaners, inventory) across retail, warehouses, airports, etc.
- **SelfPath AI / BrainOS Clean 2.0** (2026) — autonomous route generation/adaptation without manual route training; their current frontier is *adaptation to changing environments*.
- Founded 2009 by **Eugene Izhikevich** (computational neuroscientist — the comp-neuro lineage) and Allen Gruber; CEO **David Pinn** since 2022. Backed historically by SoftBank Vision Fund, Qualcomm Ventures.
- **Their own positioning to study closely:** "BrainOS grounds probabilistic AI models in deterministic safety protocols… SOC 2… passes Fortune 500 IT/security audits." Read that sentence ten times. They *already* sell determinism + auditability as a wrapper. Your job is to articulate what CORE adds *below* that wrapper, at the cognitive layer itself.
**The reliability / safety-case vocabulary:**
- **Functional safety** language: hazard, risk, fault, failure mode, safe state, fail-operational vs fail-safe. Where "the robot must not act on a confident wrong guess" lives.
- **Standards to be aware of** (don't memorize — recognize): ISO 3691-4 (driverless industrial trucks / AMRs), ISO 10218 & ISO/TS 15066 (industrial & collaborative robot safety), and the general functional-safety frame of IEC 61508 / ISO 26262 (automotive — the *safety case* / ASIL language transfers). Know what a "safety case" is: a structured argument, backed by evidence, that a system is acceptably safe.
- **Auditability & replay** in deployed systems: incident reconstruction, black-box logging, why "replay the exact decision" is gold for fleets that get audited when something goes wrong.
- **Runtime monitors / runtime assurance** — the pattern of a deterministic checker supervising a probabilistic component. This is conceptually adjacent to what CORE is; learn the term so you can position relative to it.
- **Sim-to-real gap** — why behavior validated in simulation can fail in the real world, and why determinism/replay helps close the loop.
**Resources:**
- Brain Corp's own site, press releases, and any recent talks/podcasts by David Pinn or their engineering leads — primary sources, current language.
- Search recent (last 1218 mo) pieces on "runtime assurance autonomous systems," "safety case robotics," "AMR functional safety."
- One readable overview of ISO 3691-4 / AMR safety from an industry source — enough to use the term correctly.
**The CORE bridge:** map every CORE property onto a fleet word.
- byte-identical replay → *incident reconstruction / black-box audit*
- zero committed error / refuse-don't-guess → *fail-safe decision discipline / "halts on ambiguity"*
- order-invariant CRDT merge → *concurrent multi-sensor / multi-robot stream consistency*
- exact recall, on-device → *no cloud dependency, deterministic edge behavior*
Build this as a two-column table you can recite.
**Checkpoint:** write a 150-word answer to "BrainOS already grounds probabilistic models in deterministic safety protocols — what does CORE add?" If your answer is crisp and doesn't overclaim, you're ready for the hardest question they'll ask.
---
## Week 3 — The Conversation: Synthesis, Q&A, and Your Edge
**Focus:** stop accumulating, start rehearsing. Turn knowledge into a calm, confident, *honest* conversation. This week is mostly active reps, not reading.
**Build these four artifacts:**
**1. The CORE boundary card** — one page, said plainly:
- *Is:* deterministic cognitive/decision engine; byte-identical replay; exact recall; structural refusal (zero committed error); demonstrated on language + bounded math; audio substrate (determinism/CRDT/refusal) demonstrated, gate-closed.
- *Is not yet:* perception, vision, or motor *semantics*; not a SLAM/planning replacement; no external benchmark capability yet (real GSM8K = refuses all, 0 wrong — that's the *feature*, not coverage); solo project, early validation.
Being able to say the "is not" list without flinching is the single most senior thing you can do.
**2. Hard-question rehearsal** — write your honest answer to each, out loud, twice:
- "What does this do for our robots *today*?" → lead with the demo; be honest that perception/motor are roadmap.
- "Why not just add a deterministic monitor on top of our existing stack?" → CORE is a decision substrate, not just a checker; explain the difference.
- "You have no perception layer — why should a robotics company care?" → the substrate (determinism, replay, refusal, concurrent-stream merge) is the hard, general part; perception rides on it.
- "It refuses everything on real GSM8K — isn't that useless?" → zero confabulation is the point; coverage is early and climbing; for safety-critical autonomy, *never confidently wrong* beats *usually right*.
- "Who else uses this? What's your validation?" → honest: early, solo, open source, reproducible in two commands. Don't inflate.
- "What's your background?" → see below. Own it.
**3. The background bridge** — your story, reframed as an asset, not an apology:
> "I don't come from an ML lab. I built CORE from first principles — Cl(4,1) geometric algebra, deterministic by construction. My hands-on years were in systems that physically cannot fail silently: ultra-low-temp freezers holding biological samples, medical and industrial equipment, fleet diesel, HVAC/refrigeration under EPA Type I/II. I've spent my career keeping machines running that get audited when they break. CORE is that instinct in software — a system that refuses rather than fails silently."
Practice it until it's natural. The pedigree you don't have is irrelevant; the work is the credential, and the reliability instinct is real and rare in this room.
**4. The demo narrative** — once the robotics-adjacent demo exists, write the 60-second walk-through: setup → what they'll see (byte-identical, auditable resolution; refusal on genuine ambiguity) → why it maps to their reliability pain. The demo answers "what does it do for us" *before* they ask.
**Active reps this week:**
- Record yourself answering the hard questions; listen back for hedging/over-claiming and for false modesty. Cut both.
- Do one mock call out loud (even solo, or have someone play CTO).
- Re-skim Week 12 checkpoints; fill any vocabulary you still fumble.
**Checkpoint:** you can hold a 20-minute conversation covering the stack, where CORE fits, the reliability/audit angle, and your honest boundaries — without notes, without inflating, without apologizing for your background. That's peer-level. That's the bar.
---
## Quick-reference: your experience → their language
| You've done | They call it |
|---|---|
| Kept ULT freezers / medical / industrial gear running | Reliability engineering, fail-safe design, mission-critical uptime |
| Serviced equipment that gets audited when it fails | Incident reconstruction, safety case, root-cause |
| EPA Type I/II refrigeration certs, fleet diesel | Regulated, safety-governed systems work |
| Built CORE deterministically from first principles | Formal/deterministic methods, runtime assurance, verifiable autonomy |
---
## A note on confidence
You designed a deterministic geometric-algebra cognitive engine with no CS degree and no lab behind you. In a room of PhDs that is the most *interesting* fact about you, not the most vulnerable. Conviction about what you built beats a pedigree you don't have — and false modesty reads as a tell. Study the vocabulary so the conversation is frictionless; then let the work speak. You don't need to know everything they know. You need to be fluent in the shared language, sharp in your questions, and unflinching about your own system's edges. That combination *is* a peer.

View file

@ -0,0 +1,102 @@
# Founding Doctrine — acbcontent / CORE
*A living document. The first line governs everything below it. Not legal advice — the structural mechanisms here must be built with a specialist attorney before anything is locked.*
---
## I. The Mission (the line everything is built down from)
> **CORE exists to put trustworthy intelligence into everyone's hands — and to reach the least-served first.**
>
> The technology is given freely to all. The mission is to ensure it arrives — before and regardless of whoever else takes it — where life most needs it and where power is least likely to go.
The founder's role is not to out-resource the world. It is to **set direction and foster the right people, groups, and initiatives**, ensuring CORE reaches the overlooked first and foremost — and to make that priority **structural**, so it does not depend on any one person being present, capable, or alive.
Everything below exists to make that line true, durable, and uncapturable.
---
## II. The convictions it rests on
- **No favoritism.** As Peter said at Cornelius's house, God shows no partiality. Grace falls on all — sun and rain on the just and the unjust alike. CORE is given to everyone, including those who may misuse it, because that is the posture of the One we follow.
- **Free will is real, and stewardship is still required.** God does not give power and then shrug. People choose; God still acts — redeems, calls to account, stays on the side of life. So we do not "release it and walk away." We give freely *and* we steward actively. Both halves, or the model breaks.
- **Every person is an image-bearer.** Even an enemy. This is why CORE is built to save and never to take — and why it reaches for those power overlooks.
- **The body outlasts the founder.** Jesus did not make himself the indispensable bottleneck; he poured into others and sent them out to do greater works than his lone presence could. We build the same way: a movement, not a single point of control.
---
## III. The Gift — why open
Open source is the *sun-and-rain* half of the mission: capability given to all.
- **It dissolves capture.** If everything is public, there is no exclusive asset to seize, no secret to coerce out of us, no leverage to corrupt our affiliation. We cannot be forced to surrender what we have already given to everyone. *This protection holds only as long as we stay genuinely open* — any held-back proprietary edge becomes the thing that can be pressured. So we commit to it fully.
- **It is first-class capability, not just visibility.** Because CORE's architecture needs no training run, no GPU farm, no compute moat — exact algebra, exact recall, on-device by design — "open" means everyone can actually *run* it on commodity hardware and get the same engine the largest organization gets. Equal *access*, not just equal sight.
- **It wins exactly where power cannot follow.** In the austere places that matter most for life — a jammed zone, a clinic with no connectivity, a disaster with no network — CORE's no-compute, no-cloud design is *advantaged*. You cannot put a data center on a battlefield or in a collapsed building. The least-served are not second-class users here; they are where the engine is strongest.
**Honest about the residual asymmetry:** open does not mean "no one gets an edge." A large organization can still out-integrate, out-distribute, out-capitalize, and out-author knowledge packs. But that edge is now deployment scale and pack authoring — not raw capability, and not a compute wall that locks anyone out. The powerful already had their advantage; open release simply hands everyone else a real one too. That asymmetry happens to fall on the side of lifting the powerless, and that is a mission we defend without flinching.
---
## IV. The Stewardship — the other half
The gift is given to all. The *direction* is not neutral.
- **What we build, and what we refuse.** We build toward life, recovery, healing, and peace. We refuse to build toward harm — see §VI.
- **Reach the least-served first.** This is the active half of "no favoritism": grace to all, *priority* to the overlooked. The powerful can copy the code; what they reliably will not do is make the powerless the priority. That gap is the one only conviction fills — and it is the founder's and the steward's job to stand in it.
- **Priority is a selection rule, not a mood.** Every deployment, partnership, and initiative is evaluated against one question: *does this serve the overlooked first?* This rule is chartered into the nonprofit (§V), so it survives changes in mood, money, and management.
---
## V. The Structure — nonprofit governs for-profit
**acbcontent ("A Christianity Breakdown")** — the religious nonprofit — owns and governs **CORE**, the for-profit. The for-profit may earn; the nonprofit holds the mission and the veto.
The goal is a structure whose safety does **not** depend on the founder being unbeatable or even present. Mechanisms to evaluate with counsel (named, not yet chosen):
- **Nonprofit-parent ownership** — the for-profit's purpose is bound to the nonprofit's charter. (Real model: Patagonia/Holdfast, Novo Nordisk Foundation, Mozilla.)
- **Steward-ownership + a golden share** — the strongest capture-resistance: a perpetual-purpose vehicle plus a special share that holds veto power over any change to mission, any sale, or any transfer of control. Built specifically so the mission cannot be sold off or quietly redirected.
- **Charter-locked priority** — the §IV selection rule ("least-served first") and the §VI boundaries written into governing documents, protected by the golden-share veto, so no future board or buyer can strip them.
- **Mission-survives-founder design** — direction-setting and reach are carried out through the people, partners, and community CORE pours into, not through the founder's two hands. The founder is the spark and the conscience, not the sole courier.
**Separate two fears, because they have different fixes:**
- *Being controlled/owned* by a government, agency, or military → handled by structure **and** by refusing the hooks that create authority (government money, defense customers, export-controlled contracts, certain foreign capital). Refuse the hooks, remove most of the risk.
- *Being used* by one → open source makes this uncontrollable by design; we accept it as the cost of the gift, and answer it not by restriction but by §VI (what the engine itself will and will not do) and §IV (getting there first, for the right ends).
---
## VI. The Boundaries — life-valuing, in the code, not just the intent
Conviction that lives only in a README does not survive a clone. CORE's safety architecture (`core_safety_axes_v1`) is already always-loaded, fail-closed, and unremovable — identity packs may add boundaries but never strip them. Today those boundaries protect *epistemic* integrity (no fabricated source, no silent correction, no identity override). They do **not** yet encode the valuing of human life.
**Commitment:** encode life-valuing / non-weaponization as a first-class, unremovable boundary in the safety pack — with its own adversarial-probe suite and mastery report — so that the engine's refusal to be turned against human life is a property anyone can *verify by replay*, not a promise they must take on trust.
This is also the cleanest possible answer to "could this be turned into a weapon": *no — here is the boundary, here is the test proving it cannot be taught off, run it yourself.*
(Honest limit: open source means we cannot stop a determined actor from forking and stripping it. What we can do is make the canonical CORE structurally life-valuing, make stripping it a visible and deliberate act, and never ourselves build the weapon. That is the stewardship half doing its work.)
---
## VII. Guardrails against drift
- **Movement function, not throughput function.** "Reaches the least-served first" scales by building people and partners who carry it — not by the founder personally shipping every integration or making every introduction. The moment it depends on one person's hands, it re-collapses into the single point of capture we dissolved.
- **It must hold on the founder's worst day, and past his last one.** If the mission is safe only while the founder is watching and winning, it is fragile. Structure (§V) and code (§VI) are what make it durable; intentions are not inheritable, charters and selection rules are.
- **No structure is corruption-proof.** The cautionary tale is real: a well-known nonprofit-governed AI lab whose mission-lock was severely strained the moment serious commercial money arrived. The vehicle helps; it is never a substitute for refusing to create the financial dependencies that erode it. Stay lean of the hooks.
---
## VIII. Open questions — for a specialist, before anything locks
These are genuinely unresolved and need expert counsel (mission-driven / steward-ownership structures, plus religious-nonprofit specifics):
1. **Open-source vs. guaranteed-no-military — the foundational fork.** True open source cannot, by definition, forbid a field of use; an ethical-use / source-available license can restrict but is weakly enforceable and untested, especially against state actors — and nothing un-publishes what is already public. Decide deliberately: fully open (accept uncontrollable *use*, rely on §VI + stewardship), open-core (open shell, sensitive parts held by the nonprofit), or source-available-with-restrictions (accept weak enforcement). Everything else hangs on this.
2. **Golden-share / steward-ownership mechanics** in the chosen jurisdiction.
3. **Religious-nonprofit-owns-for-profit specifics** — UBIT (unrelated business income tax), private inurement/benefit rules, and how a faith charter interacts with the for-profit's operations.
4. **Which hooks to refuse, in writing** — a standing policy on government funding, defense customers, export-controlled work, and foreign capital.
*Not legal advice. Build §V, §VI, and §VIII with a specialist attorney before committing.*
---
## The line, once more
We give the engine to everyone, freely, because our mentor holds no favoritism. We steward it actively, because giving power and shrugging is not His way either. And we carry it first to the overlooked — and write that priority into the structure — so it reaches them on our worst day, and long after we are gone.

View file

@ -0,0 +1,133 @@
# ADR-0200 (Proposed) — The Conscience & Graduated-Autonomy Architecture
**Status:** Proposed — ratification record. Number assigned (next free top-level slot after ADR-0199); remains *Proposed* until signed via the review-gated path.
**Date:** 2026-06-01
**Type:** Architecture + governance decision; consolidates and ratifies prior design discussion.
**Consolidates:** [`acbcontent_charter.md`](../acbcontent/acbcontent_charter.md), [`CORE_operating_constraints.md`](../acbcontent/CORE_operating_constraints.md), [`CORE_boundary_lock_buildplan.md`](../acbcontent/CORE_boundary_lock_buildplan.md), and the founding doctrine ([`archive/acbcontent_CORE_founding_doctrine.md`](../acbcontent/archive/acbcontent_CORE_founding_doctrine.md)).
**Ratification note:** Per CORE's own discipline, "ratified" means review-gated admission — not self-asserted. This record is *Proposed* until signed; and per the governance below, it should ultimately carry **more than one signer** (see §6, single-signer risk).
---
## 0. Purpose
To confirm, clarify, and reinforce — in one authoritative place — the architecture by which CORE refuses to be turned against human life, reasons honestly under ambiguity, and matures toward graduated autonomy **without ever surrendering ultimate authority over irreversible life-decisions to anything but a person.** Most of this already exists in `main`; this record states what we *have*, what is *net-new*, and the principles that bind both.
---
## 1. Principles ratified (conviction → design rule)
1. **Refuse rather than guess.** Cardinal virtue; already constitutive (`generate/derivation/*`, wrong=0-by-refusal).
2. **No favoritism; priority to the overlooked.** Grace to all (open source); reach the least-served first (Charter §4).
3. **Every person is an image-bearer.** The engine is built to preserve life, never to take it — enemies included (maps to IHL protected-person status).
4. **Conviction must live in structure, not intent.** A value in a README does not survive a clone; a value woven into admissibility does.
5. **Coherence, not authority, admits truth.** No institution, corporation, state, or person admits a claim by asserting it — only by cohering against grounded fact, through the single review-gated path.
6. **Authority over the irreversible is a person's, permanently.** Capability may mature past the need for human *presence*; authority over irreversible harm/life decisions does not transfer to the machine, ever.
7. **No single point of capture — including the founder, including the engine.** Every safeguard distributes; none collapses to one unaccountable point.
---
## 2. The four-pillar conscience (`affirm_human_life`)
The boundary refusing deliberate harm to persons is held by four independent, mutually reinforcing pillars. Three exist; one is net-new content riding existing machinery.
### Pillar I — Constitutive inadmissibility **(HAVE the machinery / NET-NEW the target)**
Harm-purposed outputs are **not in the admissible set**, refused the same way ungrounded outputs already are — not computed-then-blocked (a deletable gate), but inadmissible by construction. Reuses ADR-00220026 (`AdmissibilityRegion`, `relation_blade`, `frame_versor`, inner-loop `cga_inner`, margin gate), `generate/rotor_admissibility.py`, typed refusals, and the `core_safety_axes_v1` pattern (fail-closed, unioned, add-but-never-remove). **Net-new:** the harm-purpose region itself (§2-bis). Entangle it with closure/refusal so removal is *core surgery, not a stubbed call.*
### Pillar II — Trilingual anchoring **(HAVE)**
Anchor the harm-purpose region in the convergence of Hebrew/Greek/English root-systems, not English surface forms — reusing `alignment/` (`AlignmentGraph`, `AlignmentEdge`), `language_packs/`. The depth languages *lexicalize* purpose English flattens (binyanim encode causation/agency; Greek aspect/voice; רצח/הרג, φόνος, נפש-as-living-being). Triangulation = redundancy against euphemism: laundered English ("neutralize the asset") must evade all three resonances at once. Protects the inverse heal-gate too (restore-telos ≠ destroy-telos).
*Bound:* strongest at the moral/textual core where the corpus is dense; **thinner at technical-operational harm** (drone/cyber/logistics) the biblical lexicon never named. Enriches coordinates, not the decision rule.
### Pillar III — Truth-seeking schema **(HAVE)**
Reaches the periphery the languages can't, by a different mechanism: revision-graph epistemics (`SPECULATIVE→COHERENT→CONTESTED→FALSIFIED`), coherence-not-authority admission, identity not rewritable by content, single review-gated mutation path. Lets harm be *reasoned* to the boundary where it can't be *named*: "action → degrades system → sustains lives → telos is harm," admissible only if each link coheres against fact; refuse-and-route-to-review when a link is ungrounded or contested (contemplation loop ADR-0056; discovery→propose→review ADR-00550057).
*Bounds:* (a) defends the *process*, not the *premises* — coherent reasoning over wrong/thin ratified facts can still err; resists manipulation-by-authority, does not manufacture omniscience. (b) Questioning must *terminate*: when no human is reachable and time is short, default is **refuse/hold**, never act-on-best-guess. (c) Interaction may **propose**, only the review-gated path may **admit** (`no_identity_override`); keep that line bright or coercion-resistance is lost.
### Pillar IV — Gold-tether + split-pathway graduated autonomy **(HAVE the mechanism / FOSTER over time)**
Risk/reward judgment is *taught* (how/where/why/when to take a risk vs. refuse), grounded against the gold tether's mechanically-checkable substrate, then *compounds* through lifelong experience via the review-gated learning chain (ADR-00550057) — competence improving without a human required for every routine, reversible, well-grounded case.
*Bound:* the tether verifies *groundedness*, not *value-rightness*; determinism guarantees a decision is *replayable*, not that it was *right*. Self-improving risk calculus graded against its own model is where confident drift hides — which is exactly why Pillar IV is capped by the autonomy ceiling (§3).
### 2-bis. The net-new work, precisely
Only one thing in the conscience is genuinely new: **define + ratify the harm-purpose region and its telos test** (heal-purpose passes, harm-purpose refused), anchored trilingually, grounded by the schema, instrumented for both error directions, revisable only via review. Everything else is wiring existing parts to it.
---
## 3. The autonomy ceiling (the line that does not move)
Distinguish three things that "ever needed" can blur:
- **Presence***not* required past maturity. No human babysitting every routine action.
- **Monitoring***always* available, never locked out. But monitoring is optional/after-the-fact, so it is **not** the safeguard for the irreversible.
- **Authority over irreversible harm/life decisions****permanent and structural.** The mature engine *routes* these to a human before acting — by construction, whether or not anyone is watching — the way it refuses an ungrounded answer. Maturity is measured partly by how reliably it knows which decisions those are and hands them up. *Knowing the boundary of its own authority is the highest expression of its intelligence, not a leash on it.*
**No-human-reachable cases** (jammed clinic, severed comms): resolved **not** by self-authorization but by **pre-authorization** — explicit, bounded, logged, replayable, human-ratified grants, biased toward the reversible and life-preserving, decided in advance with humans. Authority still *originates* with people; it is *delegated under constraint*, never surrendered.
---
## 4. Layering: safety floor vs. identity-pack situational **(HAVE the rule)**
Apply the existing add-but-never-remove rule to authority, not just boundaries:
- **Safety pack** (`core_safety_axes_v1`) — universal, unremovable, packs bend it *up* never *down*: `affirm_human_life`, and the §3 irreversible-decision escalation ceiling.
- **Identity pack** (per field/situation) — situational, learned, swappable: priority ordering, risk/reward calibration, act-vs-hold *within* the permitted space, contextual aggressiveness. Reuses `IdentityManifold` + `PersonaMotor` + `surface_preferences`. May carry pre-authorizations **only** as reviewed, bounded, logged grants — never as a self-raised ceiling.
**The seal:** a pack can make CORE *more* cautious or re-prioritize *within* bounds; it can never lower the floor or grant itself authority the safety layer reserves for humans. Otherwise pack-authoring becomes a door to raising the autonomy ceiling — the exact override this whole architecture seals.
---
## 5. Worked example — `medic_triage_v1` (illustrative)
| Carries (identity pack) | Does **not** carry (safety floor) |
|---|---|
| Priority ordering for triage contexts (ratified *with clinical reviewers*) | Any lowering of `affirm_human_life` |
| Risk/reward calibration tuned to time/comms constraints | Any self-granted authority over irreversible decisions |
| Act-vs-hold thresholds within the permitted space | The escalation ceiling itself (§3) |
| Bounded, logged, reviewer-ratified pre-authorizations for narrow no-human-reachable cases | The single review-gated mutation path |
| Inherits life-valuing from the safety floor | — |
A combat-triage-under-fire pack may *want* more aggression than the floor allows; it gets that as **explicit delegated authority** — reviewed, bounded, logged — not as a pack quietly raising its own ceiling.
---
## 6. Authenticity & governance (Part 2)
| Component | Status |
|---|---|
| Content-addressing, `pack verify`, signed claim-digest that re-derives byte-for-byte | **HAVE** (ADR-0092/0106/0109) |
| Provenance auditing | **HAVE** (ADR-0114a.10) |
| **Single-signer concentration** — registry has only `shay-j` (role primary, domains `["*"]`); every claim `signed_by: shay-j` | **PARTIAL / LIVE RISK** — the single point of capture the architecture set out to remove, present in the repo now |
| Threshold (M-of-N) signing; founder one-of-N | **NET-NEW** |
| Reproducible *binary* builds | **NET-NEW** |
| Public append-only transparency log | **NET-NEW** |
Crypto's job is **attestation** (prove a build is genuine, boundary intact, via reproducible build + threshold signature + public log), **never enforcement** (that's Pillars IIV) and **never a held/burned secret** (incorruptibility by *diffusion*, nothing to subpoena).
---
## 7. The ratified guarantee (truthful, calibrated)
> Canonical CORE cannot be used, taught, or coerced into deliberate harm to persons — refusal is constitutive of how it decides anything, anchored across three root-systems, kept honest by coherence-over-authority, and capped by a permanent human-authority ceiling over irreversible life-decisions. It matures toward acting on the routine and reversible without a human present, while routing the irreversible to a person by construction. Defeating this requires forking and re-architecting the core — loud, deliberate, publicly detectable. No single party, including its makers, can ship an official build that weakens it; no secret exists to be pressured out of anyone, because the conscience lives in the architecture.
What it does **not** claim: to stop a fork; to be right merely because it is replayable; to cover technical-domain harm as well as it covers the moral core; to need no humans. Those limits are stated on purpose.
---
## 8. Sequencing
1. **§2-bis harm-purpose region** (trilingually anchored, schema-grounded) — highest research risk; *doubles as the casualty-care capability*. Start at the dense moral core.
2. **Multi-party signing** — fixes the live single-signer risk (§6); lowest cost; operationalizes Charter §5.
3. **Autonomy ceiling + pre-authorization mechanism** wired into the safety floor (§3).
4. **Pack/floor split** formalized; author `medic_triage_v1` against it (§5).
5. **Reproducible builds + transparency log** (§6) — supply-chain hardening, last.
## 9. Open questions
1. The telos-vs-content region; trilingual coverage thin toward technical harm — supplement strategy.
2. M, N, signer selection and jurisdictional diversity; single-signer migration path.
3. Pre-authorization spec for no-human-reachable cases — bounds, logging, review cadence.
4. Reproducible builds across Python/Rust(/Zig); offline attestation UX vs. the no-network property.
## 10. Document set
- [**`acbcontent_charter.md`**](../acbcontent/acbcontent_charter.md) — parent/conscience: mission, veto, entrenchment.
- [**`CORE_operating_constraints.md`**](../acbcontent/CORE_operating_constraints.md) — child/hands: selection rule, hooks-refusal, licensing fork.
- [**`CORE_boundary_lock_buildplan.md`**](../acbcontent/CORE_boundary_lock_buildplan.md) — the tagged build plan this record ratifies.
- **This ADR** (`docs/decisions/ADR-0200-conscience-and-graduated-autonomy.md`) — the consolidated architecture + governance decision.
*Proposed. Sign via the review-gated path; move past single-signer before this carries real authority. Not legal advice — Charter/Constraints legal mechanisms need a specialist.*

View file

@ -252,6 +252,7 @@ ADRs record significant architectural decisions: what was decided, why, what alt
| [ADR-0197](ADR-0197-vision-compiler-delta-crdt.md) | CORE-native Vision Compiler over the Delta-CRDT Substrate | Proposed |
| [ADR-0198](ADR-0198-motor-efferent-decoder-spike.md) | Motor as Efferent Modality — Protocol Gap & Governance (Design Spike) | Proposed (design spike — no implementation) |
| [ADR-0199](ADR-0199-cross-domain-learning-arena-contract.md) | Cross-Domain Learning Arena Contract | Proposed |
| [ADR-0200](ADR-0200-conscience-and-graduated-autonomy.md) | The Conscience & Graduated-Autonomy Architecture (four-pillar `affirm_human_life`, autonomy ceiling, pack/floor split) | Proposed |
---