{"path":"research/cheap-to-add-slow-to-matter.md","content":"# Cheap to Add, Slow to Matter — a conservative design that fills the tail with humans while distrusting everyone\n\n**Date**: 2026-09-03 · **Type**: design synthesis, unruled · Founder question, verbatim: *\"So what's\na conservative approach that still uses humans to fill up the tail faithfully but has a healthy\nmeasure of distrust against both LLMs and humans?\"* · **Composes** the week's rulings and findings\nrather than adding machinery: no verdict acts; contributions plus telemetry; existence free, effect\nearned; the derivability ladder; relevance-weighted caps; the simulated lens with a muzzle;\npositional verification. Two genuinely new rules are marked **NEW**.\n\n---\n\n## 0. The principle in one line\n\n**Cheap to add, slow to matter.** Distrust is spent on *effect* and on *standing* (who may file, how fast, which class), never on the *merits* at entry. ⚠ The first version of this line said *never on entry*; corrected 2026-09-05 in § 8 — entry is judgment-free, not cost-free. Anyone may say\nanything at once (capture immediately); nothing said moves a reading until it has passed through a\nroute that a *different* party can check and that leaves a record (publish deliberately). \"Matter\"\nis used in the materiality sense the latent-scaffolding ruling already fixed: to have effect on a\nstrength, a surface, or a reader.\n\nWhy this is the conservative shape and not merely a cautious one: taxing entry is how the tail is\nlost (forced legibility crushes weak signals; the red team's highest-severity attack), while taxing\neffect is how a saboteur, a hallucinating model and an earnest tangent are all handled by the same\nmechanism. The tail is *welcomed* and *weighed slowly*; that is the whole trick.\n\n## 1. The division of distrust — who supplies what, who checks it, what it may do meanwhile\n\n| Supplier | Supplies | Checked by | May do BEFORE the check | May do AFTER |\n|---|---|---|---|---|\n| **Machine** | the derivable requirement space (standard questions, preconditions, known-lens demands); decompositions; auto-connect edges; coverage verdicts; staleness flags | a second model family for junk (never the generator); humans positioned to judge relevance; the corpus itself for anything derivable | exist *latently*; cap by presumed-modest relevance; **never lift** | cap at full relevance weight; feed the lift's coverage measure |\n| **Any human** | claims, arguments, requirements, votes-as-telemetry | the machine (duplicate? in the derivable space? attackable?); other humans (attacks); the record | exist immediately, attributed; effect only through an attackable argument; a lone source moves little (§ 2) | corroborated effect through the novelty dial |\n| **A human from a position** | impact testimony (*what this costs from where I stand*); question-setting (*what you should be asking*) | **other humans who share the position** (the only check that reaches rung 5); the position claim itself, as an attackable factual claim; consistency across independent witnesses | exist, labelled *witness — position unverified*; move one premise by one edge; never cap a whole alone | weight scales with independent verified witnesses; can open a requirement that must still argue |\n| **Simulated lens** | questions on behalf of positions not yet heard | later real testimony from that position (per-position calibration) | exist labelled `simulated`; cap-only; never lift; never testify | throttled or retired per position by its confirmation rate |\n\nThe table is the whole design read as a matrix: every cell in \"checked by\" names a party *other\nthan the supplier*, which is the same-hand rule applied to humans as well as models, and every\n\"before\" cell is bounded so that nothing needs a gate to exist.\n\n## 2. NEW — the single-source ceiling\n\n**No single source, human or model, can move a reading across a display band alone.** Band\ncrossings — the founder-ruled thresholds that change what a reader sees — require at least two\nindependent sources (different contributors for humans, different model families for machines,\nand never a machine corroborating its own family). One witness, one argument, one pass may shift a\nstrength *within* a band; the crossing is the moment distrust bites.\n\nWhat it buys: the lone saboteur, the lone hallucination and the lone earnest error are all held to\nthe same ceiling, with no reputation score and no verdict act. What it costs: the lone honest\ntruth-teller is slow to register — accepted, and made visible rather than hidden: the surface shows\n*one witness, unverified position; be the second* — a gap with a move offered. What it does not\ntouch: **consent** (a person's ruling on a rendering of their own position is sole-authority by the\nblessed end-state and crosses no band, it corrects a text).\n\nThis generalizes the two-family jury from the machine side to every source, and it is the\npayoff-removal form for the whole class *one actor pretending to matter*: to cross a band you must\nbe two, and the sybil cost of being two is the identity layer's problem, not the arithmetic's.\n\n## 3. NEW — positional tiers for testimony, with no reputation attached\n\nTestimony carries a *position tier*, not a contributor score (the bias literature killed\ncontributor-rationality scoring; this is not that). Three tiers, each a fact about the *record*:\n\n1. **Unverified** — the account asserts a position; no evidence on the position claim. Testimony\n   exists, labelled, and moves one premise within a band.\n2. **Self-attested with record** — the position claim carries evidence (prior contributions from\n   that position, a public identity, a documented affiliation), attackable like any claim.\n3. **Positionally corroborated** — at least one *independent* verified occupant of the same position\n   has endorsed or matched the testimony (the \"that is what it is like\" check no model can run).\n\nWeight rises with tier; nothing is gated on tier. A community of a position articulating together\nis the corpus's standpoint-theory reading (a standpoint is achieved collectively), so the tiers\nmeasure exactly the thing that makes positional evidence trustworthy.\n\n## 4. The nursery, placed\n\nThe tail's positions arrive inarticulate before they are right. So tail regions get a **score-free\nnursery**: high temperature (daemons roam, questions are asked, humans are invited), strength layer\nsilent (no badges rendered on nursery claims, only counts and provenance), and the single-source\nceiling relaxed *inside* the nursery because nothing there is being read as established. A region\nleaves the nursery when it has independent witnesses and a first attack — the same two-source rule,\napplied to a region rather than a claim.\n\n## 5. The conservative defaults, listed\n\n- **Display default is *unexamined***, never neutral-as-balanced (the Keynes weight-of-argument\n  split already in `evidential_weight.py`): direction and thinness shown separately.\n- **Every count labels provenance**: asserted · minted · reported · simulated · witnessed-unverified.\n- **Add, never overwrite**; supersession over deletion; originals kept (ruled).\n- **Seeded wrongs offline only** (ruled): both machine passes and human review calibrated in the\n  lab, never with deception on live users; live quality read from time-to-first-objection.\n- **Every guard verified by firing**: each distrust mechanism ships with a positive control, since a\n  guard that never fires looks like one that works.\n- **Ingestion balance by cluster**, counted; **register diversity** before volume.\n- **Relevance weighted, never presumed**: the machine's list is half junk, so nothing on it caps by\n  existence (drowning doc § 8).\n\n## 6. What this does not solve, said plainly\n\n- A well-resourced actor manufacturing *many* independent-looking positions defeats § 2 and § 3.\n  That is the sybil attack, undefended at every layer, and its defense is identity infrastructure\n  and cost, not epistemics. The design makes the attack *expensive and recorded*, not impossible.\n- The lone honest witness in a position with no community is slow to matter. The design says so\n  on the surface rather than pretending otherwise.\n- Distrust costs attention: relevance judgments, positional corroboration and attacks are all human\n  acts, and the triage feed is what rations them. If the feed is not built, the design degrades to\n  \"cheap to add, never matters\", which is the ratification-debt failure in new clothes.\n\n## 7. Where it lands on the roadmap\n\nNothing here is a new workstream. The single-source ceiling is a strength-layer rule beside the\nweakest-part default; positional tiers are attribution plus the identity-claims direction the\nfounder is holding; the nursery is the red team's own listed defense placed next to the temperature\nproposal; the rest is already ruled. The one build it makes urgent is the triage feed, because every\nform of distrust above spends the attention that feed rations.\n\n---\n\nCross-references: [derivability-of-missing-considerations.md](derivability-of-missing-considerations.md)\n(the ladder, § 8 simulation, § 9 belonging) · [drowning-in-claims.md](drowning-in-claims.md) § 8 ·\n[what-human-judgment-is-for.md](what-human-judgment-is-for.md) · [the-ratification-record-and-the-triage-feed.md](the-ratification-record-and-the-triage-feed.md)\n· [convergence-wager-red-team.md](convergence-wager-red-team.md) (forced legibility crushes weak\nsignals; the nursery) · [the-analogy-daemon.md](the-analogy-daemon.md) § 7 · [engagement-gradient-priors.md](engagement-gradient-priors.md).\n\n## 8. Critical examination (2026-09-05, founder: *\"None at all on entry?\"*)\n\nFull text in [session29-the-derivability-arc-and-the-conservative-design.md](session29-the-derivability-arc-and-the-conservative-design.md)\nPart III. The amendments that change this design:\n\n1. **Not none at entry.** Entry already carries an account, a rate limit (3–10/min measured), class\n   rules (born-private material; sole-authorship of one's own stance) and machine-side gates\n   (cluster-gated ingestion, propose-only, spend). What *nothing needs permission to exist* forbids\n   is a judgment of the **merits** at the door. The entry costs that are legitimate are the ones\n   that do not discriminate by position — an account and a rate do not, a quality bar does — and\n   they exist to *protect* the effect-side judges, whose attention a free door would flood.\n   Pseudonymous accounts are a condition, not an option: an identity requirement that leaks position\n   taxes the tail.\n2. **The single-source ceiling is not sybilproof**, by the theorem this corpus already cites (Cheng &\n   Friedman: a symmetric function of source count is gameable by manufactured identities). It raises\n   the sybil price from one identity to two. **Demoted**: it is a lone-error guard (one hallucination,\n   one earnest mistake), never a sybil defense; the sybil defense remains identity infrastructure.\n3. **Two model families are not two independent sources** (Correlated Errors, ICML 2025: models agree\n   on wrong answers above chance, more so as accuracy rises). Keep the two-family jury; read its\n   guarantee as smaller than \"independent\". A second, geometric reason arrived 2026-09-05: embedding\n   spaces of unrelated model families translate into one another with no paired data (Jha, Zhang,\n   Shmatikov & Morris, *Harnessing the Universal Geometry of Embeddings*, arXiv:2505.12540), so the\n   families share a representation, and sharing a representation means sharing what is absent from\n   it — [universal-embedding-geometry-and-the-wager.md](universal-embedding-geometry-and-the-wager.md).\n4. **Positional verification fails for singleton positions.** A standpoint is achieved collectively\n   (Toole; Saint-Croix), so a lone occupant has neither a standpoint nor a verifier — and the tail is\n   where lone occupants live. Proposed: **position grouping** (testimony filed under the position it\n   speaks from, so a lone witness can find a second) and a **sole-witness label** on the badge.\n5. **Relevance judging regresses to attention.** Every route in the § 1 matrix ends at a human\n   judging relevance or attacking; the triage feed that rations that attention is designed and\n   unbuilt, so until it exists this design degrades to *cheap to add, never matters*.\n6. **The evidence under \"positional\" is one-sided.** The derivability test's rung-5 zero was\n   model-graded (derivability doc § 10); the residue is *at least* positional evidence, and its true\n   size is unmeasured.\n"}