{"path":"research/legibility-under-power-red-team.md","content":"# Legibility Under Power: A Political Red-Team\n\n**Date**: 2026-07-10\n\n**Nature of this document**: AI-conducted adversarial research in the project's tradition of engaging every serious critique of its own foundations at full strength. The prior red-team ([convergence-wager-red-team.md](convergence-wager-red-team.md)) attacked the wager's epistemology: obfuscated arguments, convergence-illusion, aggregation impossibilities, value pluralism. This document attacks from a different direction: political philosophy, power, and strategic behavior. The question is not \"is the wager true?\" but \"what does a reasoning-legibility machine do to power, and what does power do to it?\"\n\nEach hole is stated at full strength, then honestly assessed against what the existing design already answers:\n\n- the **Legibility Rule** (\"In the official Deliberus layer, a move counts only insofar as it can be represented as a challengeable graph object with an explicit role\")\n- the **sacredness brake** (a person's own stated values are never decomposed uninvited)\n- the **provenance split** (source text vs authored input)\n- the **admission-vs-adjudication separation** (contribution admission broad and pluralistic; public adjudication structured and challengeable)\n- **challengeable system verdicts** and the **counter-instrument suite** (disagreement preservation, completeness oracle, residue map)\n\nWhat remains open is said plainly.\n\n---\n\n## Hole 1: Seeing Like a Graph (legibility is a technology of power)\n\n### The hole, at full strength\n\nJames C. Scott's *Seeing Like a State* ([Yale University Press](https://www.jstor.org/stable/j.ctvxkn7ds); [full text](https://theanarchistlibrary.org/library/james-c-scott-seeing-like-a-state)) is the standing indictment of every project that promises to make a complex human domain readable. Its core finding: legibility has never been a neutral epistemic good. States made societies legible in order to administer them: \"Legibility is a condition of manipulation.\" And the maps were never innocent representations: \"They did not successfully represent the actual activity of the society they depicted, nor were they intended to; they represented only that slice of it that interested the official observer\" (p. 3).\n\nThe cadastral map did not merely describe land tenure; allied with power, it remade land tenure in its own image. What the grid could not represent (commons, overlapping use rights, seasonal arrangements) ceased to exist officially, and then, under administration, often ceased to exist at all.\n\nDeliberus proposes a cadastral map of reasoning. The Legibility Rule is explicit that whatever cannot be represented as a challengeable graph object with an explicit role does not count in the official layer. That is not an accidental bias; it is the rule's content. Scott's second concept names what falls outside the grid: metis, \"the kind of knowledge that can come only from practical experience,\" the practical, contextual, embodied knowledge that resists formalization by nature. The lineage runs through Oakeshott's practical knowledge and Polanyi's tacit dimension: \"we can know more than we can tell\" (*The Tacit Dimension*, 1966).\n\nConsider what that class contains. A master negotiator's sense that a room is not ready. An elder's narrative that encodes three generations of ecological observation. A survivor's testimony whose force is inseparable from its telling. Each of these is a reason, and none of them survives conversion to decontextualized atomic claims with its warrant intact. When the official record must be graph-legible, narrative, oral, embodied, ceremonial, and emotional reasoning styles become second-class by definition, and the communities whose epistemic traditions are organized around them become second-class participants.\n\nThis has already happened in a courtroom, which is the closest existing institution to an official reasoning layer. In *Delgamuukw v. British Columbia*, the trial judge dismissed the Gitxsan adaawk and Wet'suwet'en kungax, stating he was \"unable to accept adaawk, kungax and oral traditions as reliable bases for detailed history\" ([Canadian Encyclopedia](https://thecanadianencyclopedia.ca/en/article/delgamuukw-case)). The same judgment preferred the evidence of Crown anthropologists who had never spoken with the peoples in question over anthropologists who had, on the ground that closeness might bias them: the form-requirements of the official record systematically favored distance over knowledge. It took the Supreme Court of Canada (1997) to rule that \"the laws of evidence must be adapted\" so that oral histories could be \"placed on an equal footing with the types of historical evidence that courts are familiar with\" ([Wikipedia](https://en.wikipedia.org/wiki/Delgamuukw_v_British_Columbia)). Deliberus is writing an evidence law for public reason. The same failure is available to it, at scale, with no Supreme Court above it.\n\nThe Strevens comparison the project leans on makes the problem sharper, not softer. The iron rule of science (only empirical argument counts in official scientific communication) succeeded because nature adjudicates: form-compliance is disciplined by experiments that can refuse to cooperate. The Legibility Rule has no external oracle. In politics, the pushback against a well-formed graph object comes only from other humans inside the same form. The selection pressure that made the iron rule truth-tracking is absent, so the form itself does normative work, and controlling the form is controlling the outcome.\n\nFinally, the enclosure reading. The commons being enclosed is informal public reasoning itself. An enclosure does not need to prohibit the old practices; it only needs to make the enclosed format the one that counts. The moment any institution consumes the graph as its record of reasons, non-participation becomes official reasonlessness. And the map is readable asymmetrically: the powerful can consume the map of everyone's reasoning without ever submitting their own reasoning to it.\n\n### What the design already answers\n\nMore than most projects in this genre. The admission-vs-adjudication separation means narrative and testimony are admitted raw; the machine performs the formalization (\"structure is output, not input\"), so the entry fee is not personal fluency in atomic articulacy. The second dogfood run showed polemic extracting as attributed, checkable claims rather than being rejected at the door. Lifecycle states let immature or minority positions persist without deletion. The sacredness brake exempts a person's own stated values from uninvited dissection. These are real, Scott-aware choices.\n\n### What remains genuinely open\n\n1. **Scrutiny is single-register.** The CQ descent is the only official form of scrutiny, so a position whose warrant lives in testimony or practice scores as underived even when its home community has scrutinized it for generations in another register. \"Admitted\" is not \"able to win.\"\n2. **Extraction loss for non-propositional content is unmeasured.** The disagreement-preservation instrument measures flattening between positions; nothing measures what conversion to claim-form strips from within a register. Metis is, by definition, exactly what the instrument cannot see.\n3. **The enclosure completes at adoption time, not design time.** Nothing in the architecture prevents the downstream dynamic Scott documents: the map, once institutional, remakes the territory. A commitment that the graph informs rather than constitutes official standing would have to bind the consumers of the graph, and the platform has no mechanism that binds consumers.\n4. **The \"equal footing\" question cannot be litigated in-graph.** Whether testimony counts as evidence-for, and how much, is a normative decision currently made in code, where *Delgamuukw*'s question cannot even be raised.\n\n---\n\n## Hole 2: Constructive Ambiguity (some agreements survive only unspoken)\n\n### The hole, at full strength\n\nDiplomacy has a term for deliberately not making disagreement legible: constructive ambiguity, associated with Kissinger, meaning the deliberate use of imprecise language on a sensitive issue so that all parties can sign. UN Security Council Resolution 242 omitted the definite article on purpose: \"withdrawal of Israeli armed forces from territories occupied in the recent conflict,\" not \"the territories,\" a wording \"vague enough to ensure acceptance by the entire council\" ([Palquest](http://www.palquest.org/en/highlight/164/resolution-242-22-november-1967)). Both principal drafters, Lord Caradon and Arthur Goldberg, later confirmed the omission was intentional ([JCFA](https://jcfa.org/article/security-council-resolution-242/)). Caradon's statement on adoption day is a monument of diplomatic irony: \"I am sure that it will be recognized by us all that it is only the resolution that will bind us, and we regard its wording as clear.\"\n\nThe Good Friday Agreement institutionalized the same move. Its constructive ambiguity let nationalists and unionists put incompatible constructions on the same text, and scholars credit exactly this with making agreement possible: Mitchell argues the ambiguity \"was inherent to the process\" (\"Cooking the fudge,\" *Irish Political Studies* 24(3), 2009; see also [Anderson 2009](https://www.noeltanderson.com/publications/ajia2009.pdf)). Paul Dixon defends the peace process's \"honourable deception\" as necessary political skill ([Dixon, *Political Studies* 2002](https://journals.sagepub.com/doi/abs/10.1111/1467-9248.00004)). The critics state the cost in Deliberus's own vocabulary: Dingley objects that the Agreement was \"a form of words all could sign up to because each could interpret them differently,\" implying the parties \"were not in agreement\" at all. That is precisely what a Deliberus extraction would prove, publicly, with typed edges.\n\nThe legal-theory generalization is Sunstein's incompletely theorized agreements: well-functioning legal systems produce agreement amidst pluralism precisely because participants \"agree on the result and on relatively narrow or low-level explanations for it\" while refusing to theorize further, and this refusal is \"an important source of social stability\" and a way for diverse people to demonstrate mutual respect ([Sunstein, *Harvard Law Review* 108:1733, 1995](https://chicagounbound.uchicago.edu/journal_articles/8407/)). His illustration: people converge on protecting religious liberty from mutually incompatible groundings (social peace, dignity, utility, theology), and the convergence is stable because the groundings stay unexamined.\n\nNote the inversion: Sunstein's practitioners also descend to particulars, but they descend in order to stop theorizing at the point of agreement. Deliberus's completeness oracle treats every unexpanded ground as a sorry-frontier: it is a machine for finishing exactly the theorization that functioning pluralism deliberately leaves unfinished.\n\nThe mechanism of harm is common knowledge. Parties to a fudge typically know privately that their readings diverge; what the fudge prevents is the divergence becoming common knowledge that demands response (on publicity as a common-knowledge generator, Chwe, *Rational Ritual*, Princeton UP 2001). Run the Good Friday Agreement through the pipeline and the graph would display, publicly, with a residue map, precisely the incompatible constructions the text was engineered to hold in superposition. Nobody involved could any longer pretend not to know.\n\nThe recent scholarship is honest that ambiguities decay on their own: \"once institutionalized, ambiguities contain an immanent potential to develop into structural contradictions if the balance of political power shifts\" ([Peace Review 2023](https://www.tandfonline.com/doi/full/10.1080/10402659.2023.2218812)). That sharpens the hole rather than blunting it: ambiguity buys time, and the parties manage the timing of its collapse. A public completeness oracle transfers control of that timing to whoever chooses to run the extraction. Anyone can detonate the fudge; the platform prices the detonation at one URL submission.\n\n### What the design already answers\n\nLess than for any other hole. The sacredness brake protects a person's own stated values, not treaties, party platforms, or coalition texts. The provenance split actually cuts the wrong way here: a peace agreement pasted as a source text auto-opens the full weighing descent by design. The permissive-zone residue type gives the ontology a way to say \"deliberately left open,\" which is a real representational asset. Admission-vs-adjudication means nobody is forced to submit an agreement, and undecided verdicts exist. That is the full inventory.\n\n### What remains genuinely open\n\n1. **No concept of load-bearing illegibility.** The ontology cannot represent \"this ambiguity is doing work, and decomposing it has costs borne by identifiable parties.\" A system whose founding wager is that decomposition reveals shared care has no category for the case where decomposition destroys a cooperative equilibrium.\n2. **Third-party decomposition is ungoverned.** The consent logic of the sacredness brake (the person whose values they are controls the descent) has no analogue for collective texts: the parties to an agreement have no standing over whether someone else runs it through the machine and publishes the residue map.\n3. **The oracle's verdicts carry an unexamined rhetorical valence.** \"Incompletely theorized\" reads as an indictment (\"they never really agreed\") even when incompleteness was the diplomatic achievement. When is a fudge a bug and when is it civic technology? The platform currently cannot ask the question, and its instruments all default to \"bug.\"\n\n---\n\n## Hole 3: Weaponized Decomposition (the sea lion gets an API)\n\n### The hole, at full strength\n\nDemanding endless justification is already a mature harassment tactic with a name. Sealioning is \"pursuing people with relentless requests for evidence, often tangential or previously addressed, while maintaining a pretense of civility and sincerity,\" and it has been \"likened to a denial-of-service attack targeted at human beings\" ([Wikipedia](https://en.wikipedia.org/wiki/Sealioning)). Amy Johnson's Berkman Klein essay notes the tactic's dual harm: it \"works both to exhaust a target's patience, attention, and communicative effort, and to portray the target as unreasonable.\" The comic's author named the underlying entitlement: \"the notion that any random patient stranger should feel entitled to as much of someone's attention as they want.\"\n\nNora Berenstain gave the phenomenon its philosophical account: \"Epistemic exploitation occurs when privileged persons compel marginalized persons to educate them about the nature of their oppression\" ([Berenstain, *Ergo* 3, 2016](https://quod.lib.umich.edu/e/ergo/12405314.0003.022/--epistemic-exploitation?rgn=main;view=fulltext)). Her markers of the phenomenon map onto a claim graph with uncomfortable precision:\n\n- the labor is \"unrecognized, uncompensated, emotionally taxing, coerced epistemic labor\"\n- it is structured by a double bind: answer and be drained, or decline and appear to concede\n- it operates under \"the default skepticism of the privileged,\" which demands ever more labor\n\nBrandolini's law states the economics: \"The amount of energy needed to refute bullshit is an order of magnitude bigger than that needed to produce it\" ([Brandolini's law](https://en.wikipedia.org/wiki/Brandolini%27s_law)).\n\nDeliberus builds the sea lion into the architecture. Every claim is \"currently undecomposed,\" invitable deeper forever: no-copout-axioms guarantees there is always another why. Critical questions are generated on tap; open CQs are visible as sorry markers; the completeness oracle will publicly score a position \"derivationally incomplete\" if its holder declines to keep answering. The harasser no longer needs to feign civility: the platform issues the demands in a perfectly civil machine voice, and the target's refusal is converted into a legible, quotable epistemic deficit. That is Berenstain's double bind, formalized and put on the permanent record.\n\nThe labor asymmetry then does the political work. Harassment empirically concentrates on marginalized speakers, so their positions attract the most hostile descent-pressure. Positions held by people with less time, training, and energy accumulate open CQs. The graph then displays exactly those positions as under-scrutinized or failing scrutiny. The badge measures answering capacity and calls it epistemic quality. One click for the challenger, an evening for the defender, forever: Brandolini's ratio, institutionalized, with a public scoreboard.\n\nThe hole's strongest concrete form: run the completeness oracle against an opponent's position, screenshot the sorry-frontier, publish it as \"they cannot defend their view.\" The instrument was built to invite deepening; nothing about it prevents its use as a portable delegitimization certificate.\n\n### What the design already answers\n\nThis is where the design has its best answers, and they should be stated fairly.\n\n1. **The inversion principle**: the machine does the decomposition labor and offers taps, not essays, so answering a CQ is designed to cost far less than composing a justification from scratch. This genuinely attacks the Brandolini ratio at the margin.\n2. **CQ volume is scheme-driven, not attacker-driven**: critical questions are minted by the pipeline from argument schemes, and mint-time dedup prevents the same question being spammed as many objects. An attacker cannot currently flood a claim with a thousand bespoke demands.\n3. **The sacredness brake plus invitation model**: a person's own stated values receive invitations rather than uninvited dissection.\n4. **Admission-vs-adjudication discipline**: an unanswered CQ leaves a claim open rather than refuted, and verdict maturity is separated from answering speed.\n5. **No assigned obligation to answer**: claims are lifecycle-staged; silence is a state, not a verdict.\n\n### What remains genuinely open\n\n1. **Unanswered-question semantics is the whole game, and it is undecided.** If open CQs depress computed or perceived strength, flooding-by-descent works as an attack. If they do not, obfuscated positions ignore all criticism at no cost (the prior red-team's Attack E). There is no safe setting of this dial, only a chosen tradeoff, and the design has not chosen, stated, or instrumented it.\n2. **No attention-budget model exists.** There is no accounting of answering labor, no distinction between a scheme-minted CQ asked once and the same doubt re-raised adversarially at every node of a subtree, and no notion of who has already answered what across contexts. \"Previously addressed\" is the sealion's signature, and cross-linking only partially defuses it.\n3. **Berenstain's deepest point is not answerable by UX.** Converting marginalized people's claims about their own oppression into public objects that anyone may put a descent-demand on IS the exploitation surface. The platform lowers the cost of demanding justification toward zero while the cost of providing the human part (the testimony, the re-litigation of one's own standing) stays fully human. Politeness of the interface does not touch this.\n\n---\n\n## Hole 4: The Deliberative Frame Itself (Young, Sanders, and the rational refusal)\n\n### The hole, at full strength\n\nThe deliberative frame was indicted from inside democratic theory before this platform existed. Lynn Sanders: \"Some citizens are better than others at articulating their arguments in rational, reasonable terms,\" and the connotations deliberation carries (\"rationality, reserve, cautiousness, quietude, community, selflessness, and universalism\") \"probably undermine deliberation's democratic claims\" ([Sanders, \"Against Deliberation,\" *Political Theory* 25(3), 1997](https://journals.sagepub.com/doi/10.1177/0090591797025003002); discussion at [Peter Levine](https://peterlevine.ws/?p=21890)). Her jury evidence shows the deeper wound: some speakers are discounted no matter how good their reasons, because epistemic authority is socially distributed before any argument is evaluated, and prejudice does not present itself in deliberation as a bad argument that better arguments can catch. Her remedy was testimony, a genre deliberation-first designs demote.\n\nIris Marion Young's \"Activist Challenges to Deliberative Democracy\" ([*Political Theory* 29(5), 2001](https://journals.sagepub.com/doi/10.1177/0090591701029005004); [PDF](http://poli375engage.pbworks.com/f/3072534.pdf)) escalates through four challenges:\n\n- **Exclusive procedures**: the fora themselves are unequally accessible.\n- **Internal exclusion**: formal inclusion is not enough; the privileged register silences differently-voiced participants who are nominally in the room.\n- **Constrained alternatives**: under existing power, \"there is little difference among the alternatives debated\"; the agenda arrives pre-shrunk.\n- **Hegemonic discourse**: the deepest challenge; deliberation proceeds on \"premises and terms of discourse that make it difficult to think critically\" about the structures everyone is inside.\n\nYoung's activist refuses deliberation rationally: entering concedes the agenda, the terms, and a false presumption of equal standing under structural inequality.\n\nApplied here: a reasoning graph is the deliberative frame with every dial at maximum. Not just \"give reasons,\" but give reasons in atomic, decontextualized, scheme-classified, scored form, on a permanent attributed record. Each of Young's challenges recurs, upgraded:\n\n- **Agenda**: the graph is corpus-shaped, and corpus selection (which texts get extracted, which debates get maps) is the new agenda-setting power, currently exercised by whoever submits and whoever built the pipeline.\n- **Terms**: Walton's scheme taxonomy, the claim-type ontology, and the residue typology ARE \"premises and terms of discourse,\" and they are contestable only in code, outside the graph. The frame cannot be attacked from inside the frame, which is precisely Young's structural point.\n- **Standing**: once any institution consumes the graph as its record of reasons, the activist's rational refusal becomes maximally expensive, because refusal now equals official reasonlessness (\"they have no arguments in the graph\").\n- **Legitimation**: the platform can function as what Young called deliberation's co-optation surface: \"we ran the objections through the system\" as a ritual for decisions already made elsewhere.\n\n### What the design already answers\n\nThe design is unusually Sanders-aware. Structure-is-output-not-input, voice input, and machine formalization directly attack the articulacy fee: the platform, not the citizen, pays the translation cost into deliberative register. Testimony and polemic are admitted and represented rather than rejected (dogfood run 2's finding that advocacy prose extracts as attributed, checkable claims). Disagreement is preserved as a first-class output rather than dissolved into consensus. Beginner-readability is a stated product contract. Against 1990s deliberation designs, this is a generational improvement.\n\n### What remains genuinely open\n\n1. **Sanders's objection recurs one level up, at scoring.** The articulacy fee was moved out of admission and into survival: claims survive CQ descent in proportion to the answering resources behind them (Hole 3), and the QBAF badge then certifies a resource inequality as an epistemic ranking. Machine-assisted answering narrows this but is itself unequally accessible and unequally trusted.\n2. **Corpus-as-agenda is untouched.** There is no representation of what is missing from the graph, and absence is the oldest form of agenda power. An instrument for \"whose questions have no map here\" does not exist.\n3. **The hegemonic-discourse challenge lands intact.** The taxonomies are unchallengeable in-graph. A Young-style activist cannot file a graph object that contests the legitimacy of scheme-classification itself and have it bind anything.\n4. **Deliberative-washing has no defense.** Nothing prevents an institution from citing graph-processed deliberation as legitimation while ignoring its content, and the platform's prestige grows either way. That incentive structure is exactly what Young's activist predicted.\n\n---\n\n## Hole 5: Strategic Gaming (astroturf graphs, sacred shields, residue-typing as a weapon)\n\n### The hole, at full strength\n\nTreat the graph as a target and every mechanism becomes an attack surface.\n\n**(1) Astroturfed corpora.** AI-powered influence operations are operational reality: OpenAI reports disrupting over 40 covert networks since February 2024, generating personas, bios, articles, and coordinated comment floods, from state-linked operations to commercial spam farms ([OpenAI threat reporting](https://openai.com/global-affairs/an-update-on-disrupting-deceptive-uses-of-ai/); [June 2025 update](https://openai.com/global-affairs/disrupting-malicious-uses-of-ai-june-2025/)). The consistent finding so far is low breakout to authentic audiences (\"For these operations, better tools don't necessarily mean better outcomes,\" per lead investigator Ben Nimmo). But a claim graph changes the target: an influence operation no longer needs an audience, only a corpus. Seed a dozen web-published pseudo-sources, submit them for extraction, and auto-connect will discover and link the mutually supporting claim clusters, with formally clean provenance, because they are real URLs really asserting these things. The graph has no model of source credibility or source independence, so a manufactured literature and a real one look identical at the edge level.\n\n**(2) Brigading votes and challenges.** The precedent the project's prior red-team cited hopefully now has a published attack analysis. On Community Notes, \"a small minority (5-20%) of bad raters can strategically suppress targeted helpful notes, effectively censoring reliable information,\" with two attacker types distinguished: indiscriminate disruptors and coordinated raters targeting notes of a particular bias ([St Andrews, arXiv 2511.02615](https://arxiv.org/abs/2511.02615)). X responded in 2025 by adding anomalous-correlation detection that treats coordinated rating blocs as a single voice. Deliberus's single-axis agree/disagree voting is strictly weaker than the bridging mechanism that was successfully attacked, and it has no coordination detection at all.\n\n**(3) Laundering by form.** Wikipedia's hardest moderation problem is not vandalism but civil POV pushing: process-fluent actors advancing an agenda entirely within the rules until opponents exhaust ([Wikipedia:Civil POV pushing](https://en.wikipedia.org/wiki/Wikipedia:Civil_POV_pushing)). A graph that certifies structure (typed edges, answered CQs, scheme compliance) hands fringe positions a rigor costume: \"it is in the graph, fully derived, green badge\" is the new \"peer-reviewed\" for positions that assembled their own review.\n\n**(4) QEM claim-farming.** The published gradual semantics satisfies rationality postulates against honest profiles, not adversarial ones. Subclaim energy is additive under saturation, so minting many mediocre supporting subclaims moves strength until saturation binds, and no adversarial cost analysis of the semantics has been published: what it costs, in claims and accounts, to move a target badge by a given amount is currently unknown, including to the project.\n\n**(5) Adversarial sacralization.** The sacredness brake creates an incentive gradient: declare it sacred and it cannot be decomposed uninvited. The sacred-values literature shows sacralization is partly strategic and highly contagious: framing an issue as sacred makes compromise read as taboo (Tetlock, \"Thinking the unthinkable,\" *Trends in Cognitive Sciences* 7(7), 2003, [doi](https://doi.org/10.1016/S1364-6613(03)00135-9)); material offers on sacralized issues backfire into moral outrage (Ginges, Atran, Medin & Shikaki, *PNAS* 104(18), 2007, [doi](https://doi.org/10.1073/pnas.0701768104)); and negotiation analysis must constantly distinguish genuinely sacred values from pseudo-sacred positions strategically dressed as sacred (Atran & Axelrod, \"Reframing Sacred Values,\" *Negotiation Journal* 24(3), 2008, [doi](https://doi.org/10.1111/j.1571-9979.2008.00182.x)). The brake also protects asymmetrically across ideologies: traditions that state their cores in sacred register get immunity, while traditions that state their cores as tradeoffs (utilitarian, technocratic) get fully decomposed. The platform thereby subsidizes one moral rhetoric over another.\n\n**(6) Residue-typing as delegitimization.** \"Your position bottoms out in a fittingness residue\" is a new dismissal move: \"merely subjective\" wearing a formal costume. Typing is powerful in both directions (the platform's own dogfood run demoted a value-dressed claim to empirical), which means the type label is a prize worth fighting over. The fixed type taxonomy is an unmarked hinge (the prior red-team's Attack F) that adversaries will litigate rhetorically outside the graph while exploiting inside it.\n\n### What the design already answers\n\nThe provenance split does real work against sacralization-gaming: the brake covers a person's own authored values, while public source texts auto-open descent, so a lobby cannot paste its platform and declare it sacred. Terminus verdicts are grounded in challengeable verdict-claims, the LLM classifier is propose-only, and undecided is a first-class outcome: typing at least has a contest surface. OAuth raises sybil cost above zero; rate limits exist; mint-time dedup blocks the crudest spam. The confession-principle culture (instruments that can falsify, forensics rows, counter-instruments) is the right posture for detecting gaming, and the disagreement-preservation instrument shows the project ships adversarial self-measurement rather than only promising it.\n\n### What remains genuinely open\n\n1. **No coordination defense exists at any layer**: no anomalous-correlation detection on votes, no coordinated-challenge detection, no source-reputation or source-independence modeling against manufactured literatures. The state of the art (bridging-based ranking) is both absent here and itself demonstrably attackable, which means \"add bridging\" is necessary but not sufficient.\n2. **The semantics has never been costed against adversarial minting.** Until an attack-cost curve is published, the badge's integrity is an assumption, and the project's own norms say unmeasured integrity claims should be presumed optimistic.\n3. **The sacred/pseudo-sacred boundary is self-declared at zero cost in authored mode.** Any mechanism that prices or audits sacralization contradicts the brake's pastoral purpose; any that does not invites the shield exploit. This is a genuine value tension inside the design, not an oversight, and it should be decided as one.\n4. **Laundering does not require fooling the scores.** The aesthetic of graph-rigor is itself the prize, and no instrument measures citation-of-the-graph-as-authority in the wild.\n\n---\n\n## Hole 6: The Permanent Attributed Record (graphs remember, people change)\n\n### The hole, at full strength\n\nInstitutions that want honest reasoning pay for it with illegibility, and they know exactly what they are buying. The Chatham House Rule: \"participants are free to use the information received, but neither the identity nor the affiliation of the speaker(s), nor that of any other participant, may be revealed,\" maintained since 1927 because \"it allows people to speak as individuals, and to express views that may not be those of their organizations, and therefore it encourages free discussion\" ([Chatham House](https://www.chathamhouse.org/about-us/chatham-house-rule)). Deliberus's official layer is the anti-Chatham-House: role-explicit, attributed, permanent, machine-readable, scored.\n\nThe chilling effect of far weaker conditions is measured: traffic to privacy-sensitive Wikipedia articles dropped sharply and durably after the June 2013 surveillance revelations, and that was reading, not attributed public reasoning ([Penney, *Berkeley Tech. L.J.* 2016](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2769645)).\n\nThe record's afterlife is the sharper problem. People change their minds; the graph remembers the 2026 assertion under your name into every future context: employer screens, visa decisions, adversary opposition files, and the training corpora of every model that reads the deliberately agent-readable surface. Fourcade and Healy's *The Ordinal Society* (Harvard UP 2024) names the regime this feeds: a society that \"stratifies individuals through a myriad of differentiated methods of matching, scoring and classification,\" where \"an individual's eigencapital is calculable from all of the digital information available about them\" and \"advantages accrue to those who accumulate it,\" with a \"lumpenscoretariat\" filtered into the worst provision at the bottom ([review and quotes](http://www.wipsociology.org/2025/03/04/class-power-and-digital-technology-a-review-of-fourcade-and-healy-the-ordinal-society/)). A scored, attributed public reasoning record is the purest eigencapital instrument yet proposed: it scores the quality of your mind, by name, forever.\n\nThe design deepens its own exposure. The stranger test decontextualizes claims on purpose, which means every claim is pre-formatted for hostile quotation, stripped of the context that made it reasonable to say. Exploratory speech (\"let me try this thought\") and on-the-record assertion are different speech acts; a platform that converts the first into the second by default will select for participants who are either safe or shameless, and the convergence it then measures inherits that selection (the prior red-team's chilling-effects point, now with the mechanism named).\n\n### What the design already answers\n\nReal, partial answers exist. The lifecycle model includes superseded: recanting is representable, and default public retrieval already holds back raw, draft, and superseded material. Conversational drafts are non-public by default; \"capture immediately, publish deliberately\" is a stated product contract. A tiered pseudonymity model (anonymous reading, pseudonymous voting, reputation-gated submission) is planned. The provenance split distinguishes \"I assert\" from \"this text asserts,\" which limits accidental self-attribution.\n\n### What remains genuinely open\n\n1. **Supersession is not de-attribution.** The fossil remains queryable by design, because the graph's epistemic value to the project (temporal reasoning history) and its threat to users (permanent record) are the same property. No design can have one without the other; the design has not yet said which it chooses when they conflict.\n2. **Planned is not shipped.** Today every contribution is bound to a real Google identity, and the agent-readable surface simultaneously maximizes harvestability of that attributed record by parties bound by none of the platform's norms. The exposure is live now; the mitigation is a roadmap item.\n3. **No public deletion policy, no right-to-recant statement, no data-minimization commitment**, and no answer to jurisdictional erasure rights for reasoning records.\n4. **The deepest version has no clean answer anywhere.** The platform needs attributed persistence to do its job (provenance is its integrity layer against Hole 5), so the chilling effect is not a bug to fix but a cost to govern, and governing it means choosing which users the platform is willing to lose.\n\n---\n\n## Hole 7: The Operator Problem (who governs the reasoning layer)\n\n### The hole, at full strength\n\nSeth Lazar's account of algorithmic intermediaries states the general condition: they do not just relay social relations, they constitute them (\"algorithmic intermediaries actively shape the social relations that they constitute\"), and their governance raises \"new challenges for political philosophy concerning the justification of authority, the foundations of procedural legitimacy, and the possibility of justificatory neutrality\" ([Lazar, \"Governing the Algorithmic City,\" *Philosophy & Public Affairs* 53(2), 2025](https://onlinelibrary.wiley.com/doi/10.1111/papa.12279); [arXiv](https://arxiv.org/abs/2410.20720)). His power taxonomy applies directly: power over (shaping what individuals can officially say and how it scores), power between (enabling some users to exert pressure on others: Hole 3), power through (reshaping, over time, what a society counts as a reason). Lazar also predicts we will increasingly \"interact more with AI-generated summaries of other people's speech than with those people directly,\" which is a literal description of a claim graph.\n\nDeliberus proposes to be the algorithmic intermediary for the reasoning relation itself, and here Scott inverts. The graph makes users' reasoning maximally legible; the operator's constitutive moves (pipeline prompts, model choices, the scheme taxonomy, the residue-type enum, the semantics selection, corpus curation) live in code and deployment: legible in principle to those who read repositories, challengeable in-graph by no one. The Legibility Rule, applied reflexively, indicts its own home: the platform's most consequential official moves are not represented as challengeable graph objects with explicit roles. Add the current sociology: a solo-operated instrument proposing to host civic epistemics is a single point of capture, legal compulsion, acquisition, or abandonment.\n\nThe recent deliberation-technology literature supplies the remaining critiques. The technosolutionism analysis of the European Citizens' Panels and Google's Habermas Machine argues that \"introducing technology as a 'solution' to 'fix' 'problems' reinforces depoliticisation and disintermediation,\" sidelining mass politics in favor of infrastructure defaults ([Journal of Deliberative Democracy](https://delibdemjournal.org/article/id/1839/)): moving disagreement from politics, where power is negotiated, into code, where defaults rule. And the empirical \"AI penalty\" finding: \"technical utility does not automatically lead to public acceptance\"; participants discount deliberative outcomes when AI mediates, opening \"a new deliberative divide\" between those who accept AI mediation and those who refuse it ([Government Information Quarterly 2025](https://www.sciencedirect.com/science/article/pii/S0740624X25000735); [arXiv](https://arxiv.org/pdf/2503.07690)). The refusers' reasoning is then simply absent, and the graph's \"convergence\" measures the acceptors: a selection effect at the level of trust in the medium itself.\n\n### What the design already answers\n\nOpen source with a permissive posture makes exit-by-fork real, which is the strongest single check on operator power that exists here. The challengeable-verdict pattern proves the design knows official judgments need contest surfaces. The confession principle and the counter-instrument norm (\"counter-instruments that can only confirm are decoration\") constrain the operator's story about the system, and the instrument-independence gap (honesty checkers sharing a model class with what they check) is already named in the project's own analysis rather than hidden.\n\n### What remains genuinely open\n\n1. **The prior red-team's \"publish the kernel\" remedy remains unshipped**: no versioned, public epistemic constitution declaring the semantics choice, taxonomies, classifier models, and their amendment process. Until it exists, the Legibility Rule holds users to a standard the platform does not hold itself to, and that asymmetry is the oldest shape of illegitimate rule.\n2. **Fork rights without data rights are thin.** Contributors have no stated portability right over their own contributions, so exit is exit into an empty graph.\n3. **No governance story beyond the operator**: no user standing, no amendment procedure, no answer to \"who may change what counts as a residue type, and how would we know.\"\n4. **The depoliticization critique has no instrument.** Nothing measures whether graph adoption displaces rather than informs political negotiation, and the platform's incentives run toward celebrating adoption wherever it occurs.\n\n---\n\n## The Holes, Ranked\n\nSeverity is damage to the mission if unaddressed; tractability is how realistically the current architecture can address it.\n\n| # | Hole | Severity | Tractability | Fatal if | Manageable if |\n|---|------|----------|--------------|----------|---------------|\n| 1 | Weaponized decomposition: answering-labor asymmetry, oracle as harassment certificate (H3) | High | Medium | Open-CQ semantics punishes non-answering; descent-pressure concentrates on marginalized users and the badge certifies it | Attention-budget accounting; explicit published unanswered-question semantics; oracle output framed as invitation state, not deficit verdict |\n| 2 | Adversarial sacralization + asymmetric brake protection (H5) | High | Medium | Sacred declarations become free immunity; sacred-register ideologies gain structural advantage | Provenance split holds; sacred/pseudo-sacred handling designed openly as a value tension with named costs |\n| 3 | Coordination gaming: astroturfed sources, vote brigading, claim-farming (H5) | High | Medium-High | Manufactured literatures and bloc behavior move badges before defenses exist | Source-independence modeling; coordination detection; published adversarial cost curves for the semantics |\n| 4 | Single-register scrutiny: metis and testimony admitted but unable to win (H1) | High | Low-Medium | Institutional adoption makes graph-illegible reasoning officially reasonless | Multiple scrutiny registers; extraction-loss instrumentation; adoption doctrine that the graph informs rather than constitutes standing |\n| 5 | Constructive-ambiguity detonation: third-party decomposition of load-bearing fudges (H2) | High (low frequency, high blast) | Medium | A functioning agreement is publicly decomposed and the common-knowledge shift collapses it | Load-bearing-ambiguity concept in the ontology; standing rules for collective texts; permissive-zone residue used as a first-class peace category |\n| 6 | Permanent attributed record live before pseudonymity ships (H6) | Medium-High | High | Chilling selection effects poison both participation and the convergence measurement | Ship pseudonymity tiers; publish deletion/recant policy; separate exploratory from on-record speech acts explicitly |\n| 7 | Operator illegibility: no published kernel, no governance, solo point of failure (H7) | Medium-High | High | The platform demands legibility it does not practice; capture or abandonment inherits the graph | Versioned epistemic constitution; data-portability rights; minimal amendment process |\n| 8 | Scored deliberative exclusion: Sanders's objection recurring at the badge layer (H4) | Medium-High | Low | Badge strength correlates with answering resources, not truth, at population scale | Resource-controlled audits of badge outcomes; machine-assisted answering as an equalization commitment |\n| 9 | Residue-typing as delegitimization rhetoric (H5) | Medium | Medium | \"Just a fittingness residue\" becomes the graph-native dismissal idiom | Type verdicts framed as claims with challengeable grounds (exists); public norms that typed residue means live disagreement, not disqualification |\n| 10 | Deliberative-washing and depoliticization (H4, H7) | Medium | Low | Institutions cite graph-processed input as legitimation while deciding elsewhere | Honest scope claims; instrumentation of how the graph is cited; refusal to sell legitimacy |\n\n---\n\n## What Survives\n\nAn honest red-team reports what it could not break.\n\nThe admission-vs-adjudication separation, the provenance split, the sacredness brake, challengeable verdicts, and the confession-principle culture are not decoration: hole after hole above, they supplied the strongest available answer, and several answers are genuinely ahead of the deliberative-technology field. Machine-borne formalization against Sanders's articulacy fee, provenance against sacralization-gaming, and challengeable type verdicts against typing-as-weapon are design moves the critiqued literature mostly does not imagine.\n\nThe counter-instrument norm generalizes cleanly to this document's findings. Answer-burden accounting, extraction-loss measurement, adversarial cost curves for the semantics, coordination detection, a load-bearing-ambiguity flag, and a published epistemic constitution are all buildable instruments, and most convert a hole into a measurement, which is the project's home move.\n\nTwo binds do not convert, and they should be carried consciously rather than filed as backlog.\n\nFirst, the attention asymmetry. Infinite invitability plus finite human answering capacity has no safe configuration, only tradeoffs between punishing silence (which arms harassers) and ignoring silence (which arms obfuscators). Whatever is chosen is a political choice about whose labor the graph spends, and it should be chosen and published as one.\n\nSecond, the authority asymmetry. The graph can inform power but cannot bind it, while the more official the graph becomes, the more expensive refusal becomes for exactly the people Young's activist speaks for. Scott's lesson was never that maps are useless; it was that the map-maker must know, permanently, that the map serves whoever can read it and remake the territory. A reasoning commons that intends otherwise needs governance, standing, and self-binding rules as first-class architecture, not as culture. The culture is currently better than the architecture.\n"}