{"path":"research/graph-daemons-design-space.md","content":"# Graph Daemons: The Design Space\n\n**Date**: 2026-08-17\n**Status**: Design space, nothing decided. The vision is the founder's and long-standing; this document works out what it would require and where it would go wrong.\n**Prompted by**: the founder — *\"since far back I've imagined that background agents/daemons could be run on loops perhaps as Temporal workflows/activities that function kind of like enzymes or T-cells or roaming philosophers mending and filling up the graph… Has to be approached carefully and with deep thought of course. But I believe this can be a gamechanger when the time is right.\"*\n\n---\n\n## 1. Is it documented? Only as a clause\n\nIt appears inside the registered prediction of 2026-08-15 — *\"perhaps soon various internal agentic auto/schedule triggered LLM agent workflows that continually help in structuring and understanding and cleaning up the main arguments/graph/ontology\"* — and nowhere as a design. This document is its first home.\n\n**Both metaphors already have homes in this corpus, and both yield real constraints rather than decoration.** That is the useful surprise.\n\n---\n\n## 2. The enzyme constraint, which is exact\n\n[david-deutsch-deep-research-non-zero-sum-economics.md](david-deutsch-deep-research-non-zero-sum-economics.md) already carries constructor theory's definition: *\"enzymes are constructors — they catalyse reactions without being consumed.\"* Two constraints fall straight out.\n\n**A constructor retains the capacity to act again**, so a daemon must be **idempotent**: running it twice must not double its effect. A daemon that mints a claim on every pass manufactures duplicates, which is the claim-sameness problem arriving as a write amplifier.\n\n**And the deeper one, from what an enzyme actually does.** An enzyme lowers the activation energy of a reaction that was *already thermodynamically favourable*. It changes the **rate**, never the **equilibrium**. Carried over precisely:\n\n> **A daemon may only accelerate a change a human would have made anyway. It may never change what the graph would converge to.**\n\nThat is a sharp, testable line. Surfacing an implicit premise a reader would have accepted is catalysis. Deciding that a residue is `fittingness` is moving the equilibrium. An enzyme that shifted the equilibrium would be a poison, and the metaphor says so.\n\n---\n\n## 3. The T-cell metaphor is a warning in this corpus, not an endorsement\n\n[memetic-immune-system.md](memetic-immune-system.md) already uses T-cells, and it uses them for something else: intellectuals who function as a memeplex's immune defence, **\"pre-digesting intellectual challenges for their in-group, sparing regular members from engaging with full complexity.\"**\n\n**A daemon that pre-digests does exactly that to Deliberus's own readers**, which is the interpassivity failure [worldview-lenses.md](../worldview-lenses.md) already warns about: the machine performs the scrutiny so the human does not have to, and the human feels informed. The corpus's own T-cell analysis is therefore an argument for keeping daemons *upstream of* the descent rather than in place of it.\n\nImmunology supplies a second constraint worth keeping. T-cells require **co-stimulation** — two independent signals before acting — and the reason is precisely autoimmunity: a single signal is not enough to justify attacking tissue. Carried over: **a daemon acts only when two independent detectors agree.** The corpus already runs this shape in the stance instrument, which reports `near_identical` and `reported_asymmetry` separately rather than combining them into one score.\n\n**Correction, 2026-08-18: the word carrying the weight is *independent*, and it is not free.** Anthropic's multi-agent research measured **low-variance conformity** — *\"18 out of 30 agents decided to create a git branch with the exact same branch name\"* — which means **two instances of the same model are not two detectors.** They are one detector sampled twice, and their agreement is nearly uninformative, which is exactly the autoimmunity co-stimulation exists to prevent. The rule survives with a condition: **the two signals must differ in mechanism or in model family, not merely in invocation.** The stance instrument satisfies this by accident and is the pattern to copy, since embedding cosine and lexical syntax are genuinely different mechanisms. Same source revises the spend gate too: the failure measured was not a runaway daemon but a runaway *population* — *\"high-frequency (30 times per second) polling daemons\"* producing 2.4 million job requests against 117 accepted — so the ceiling has to be global rather than per-daemon. Full reading: [the-scrutiny-gap.md](the-scrutiny-gap.md) § 5.\n\nThe autoimmune failure mode is concrete here: a scrutiny daemon that flags too eagerly attacks the corpus's own healthy material, and every false flag spends the one resource the project cannot replace, which is a reader's willingness to look.\n\n---\n\n## 4. What may be committed, what must be proposed, what must never happen\n\nThe discriminator that survives scrutiny is **reversibility plus attributability**, and it produces three tiers.\n\n**Committable.** Reversible without loss, attributable to a named daemon with a recorded rationale, and it changes **no strength and no human-authored content**. Backfilling a missing embedding. Adding a similarity edge. Normalising an attribution to a canonical entity with the original retained. Recomputing a derived instrument reading. Raising a flag.\n\n**Propose-only.** Anything that mints a claim, merges concepts, classifies a terminus, creates a support or attack edge, or decomposes. All of these either author content nobody asserted or move strengths, and the corpus has already chosen propose-only twice, in the terminus classifier and the stance instrument. Those are the precedent, not the exception.\n\n**Never.** Deleting human content. Changing a vote. Resolving a contested concept. Retyping a residue a human typed. Publishing anything.\n\n**The load-bearing consequence: a daemon that writes to the graph is an unattributed author.** Every claim here carries provenance, and a daemon-created claim is asserted by nobody — which is the phantom-asserter problem already flagged for minted claims, arriving continuously and at machine scale. **So the proposal layer is not a nicety, it is the thing that makes the tier system expressible at all**, and it does not exist yet.\n\n---\n\n## 5. Preconditions, and one of them is already approved\n\nSix, roughly in dependency order:\n\n**A proposal layer** with review, accept, reject and expiry. Nothing daemon-shaped is safe without it.\n\n**The ontology constraint layer** already approved for Deliberus. Daemons writing to the graph is precisely the case where a validator that checks the *coherence of a result* earns its keep, since the writer is not a person who will notice. **This gives the approved ontology work a concrete motivation beyond hygiene.**\n\n**Provenance for non-human authors**, extending the attribution work so a daemon is a first-class named source and every published count can separate human from machine. The count-safe summary already exists and has no caller.\n\n**An undo path.** Reversibility is asserted in the tier table above and is not currently implemented anywhere.\n\n**A spend gate.** Billing-off is a normal operating mode here, so a loop making LLM calls needs the fail-fast gate and durable spooling the corpus already specifies, or a quiet outage becomes a silent stall.\n\n**And the strength layer settled first.** [strength-layer-audit.md](strength-layer-audit.md) found the badge reading the wrong direction, an incentive that pays for splitting, and conjunction indistinguishable from corroboration. **A daemon optimising against a broken measure is worse than no daemon**, because it does so tirelessly.\n\n---\n\n## 6. What the daemons would be, if specialised by instrument\n\nThe natural decomposition is one daemon per existing honesty instrument, because each already knows what it is looking for and each already reports rather than decides.\n\n| Daemon | Looks for | Tier |\n|---|---|---|\n| **Staleness** | Premises and termini that have aged past their evidence | Flag — and it is the **first inhabitant of the temporal rung**, documented as entirely unbuilt |\n| **Completeness** | Sorry frontiers, unsupported value premises | Flag, with the standing rule that no gap is shown without a move offered |\n| **Reuse** | Descents that could have terminated in existing material | Propose, and it must match **structurally, never by identity** |\n| **Stance conflict** | Agreement edges spanning authors in documented opposition | Flag, already propose-only |\n| **Straw man** | A source's rendering of a position against what that side actually asserts | Propose; blocked on claim-sameness |\n| **Coherence** | Contradictions the graph can compute but nobody has looked at | Flag |\n\n**Staleness is the strongest first candidate**: it fills a documented structural hole, it needs no claim-sameness, it is flag-tier so it cannot corrupt anything, and it makes the residue map honest by turning a snapshot into something that can expire.\n\n---\n\n## 7. Autonomy, context, and when to interrupt a human\n\n**Autonomy follows the split the corpus already forged: the LLM decides *what*, deterministic code decides *when*.** A daemon's model call classifies; thresholds, schedules, debounce and dedup live in code. Tuning a prompt is never the fix for a cadence problem.\n\n**Context follows the arsenal-and-harness rule.** A daemon's model is context-blind and must be briefed like a subagent: a deterministic projection of the relevant subgraph in the cacheable prefix, today's date, and the specific question. Not the whole graph, which is both unaffordable and worse — a daemon given everything will find patterns everywhere, which is the autoimmune failure again.\n\n**Interruption is governed by rules this project already paid for.** The background-task discipline is unambiguous: any looping background task with side effects needs a hard maximum lifetime, an exit tied to the specific work, and an inventory at launch. And the notification rebuild settled the register: **interrupts only, everything else to a daily digest.**\n\nSo: a daemon **never pings for a proposal**. Proposals accumulate in a queue the human visits. A ping is reserved for something irreversible, something contested, or a daemon that has stopped — which is the confession channel applied to the daemons themselves, and a silent daemon must be as visible as a noisy one.\n\n**Should they pause?** Yes, and the trigger is worth naming rather than left to judgement: **a daemon pauses when its proposal-rejection rate crosses a threshold.** A daemon whose suggestions keep being declined is miscalibrated, and continuing to run is spending the reader's attention to no purpose. That is measurable, it needs no human to notice, and it is the mechanism version of the autoimmunity brake.\n\n---\n\n## 8. The question this design does not settle\n\nEvery daemon above is defensive — it flags, it proposes, it repairs. The founder's phrase was **\"roaming philosophers\"**, which is not that. A philosopher does not just mend the graph; it *asks something nobody asked*.\n\nThat is a genuinely different tier, and the enzyme constraint bites hardest there: a daemon that opens a new line of inquiry is changing what the graph converges to, not accelerating it. It may still be right to build. But it is a different decision from the six above, it should not arrive by drift from them, and it is the one place where a daemon would be doing the thing the project exists to invite humans to do.\n\n---\n\n## Cross-references\n\n[strength-layer-audit.md](strength-layer-audit.md) (the measure a daemon would optimise against, currently broken) · [memetic-immune-system.md](memetic-immune-system.md) (T-cells as pre-digesters, the warning) · [david-deutsch-deep-research-non-zero-sum-economics.md](david-deutsch-deep-research-non-zero-sum-economics.md) (constructors and enzymes) · [worldview-lenses.md](../worldview-lenses.md) (interpassivity) · [fractal-scales-and-temporal-frame.md](fractal-scales-and-temporal-frame.md) (the temporal rung a staleness daemon would inhabit) · [world-models-and-the-ontology-revival.md](world-models-and-the-ontology-revival.md) (the constraint layer that becomes a precondition here)\n"}