{"path":"research/session29-the-derivability-arc-and-the-conservative-design.md","content":"# Session 29: The Derivability Arc and the Conservative Design\n\n**Dates**: 2026-08-31 → 2026-09-05 · **Type**: session record — the reasoning chain, the founder's\nverbatim words, the corrections, and the critical examination he asked for at the end. Written\n2026-09-05 on the instruction *\"Document all our progress and reasoning and insights and findings\nthus far, before and then also after answering the above questions.\"* Part I is the \"before\"; Part\nIII is the \"after\". The docs this arc produced are listed in Part IV; this file chronicles, they\nhold the substance.\n\n---\n\n## Part I — the arc, as it happened\n\n### 1. Where it started: the whisper, and \"don't we need humans for this?\"\n\nThe padding-defense ruling (2026-08-31, option C) made untagged decomposition children aggregate by\ntheir weakest part. Building four example trees to test it surfaced an accident: strength flows\n**down** at full force (a failing required part caps the whole) but **up** only in a whisper\n(three parts at 0.9 lift their parent to 0.507). The principled reading found afterwards was that\nlifting assumes the parts *exhaust* the whole, which nothing checks. The founder:\n\n> *\"This confuses me. I always thought the system somehow inherently had 'dealt with' this. That\n> the badge/evidence score of a mother claim was maybe somehow implicitly assuming that all parts\n> had been brought to bear. But we probably do need to 'check' this, however that's done best.\n> Don't we need humans for this? Isn't this the reserved-for-humans responsibility of ensuring we're\n> not in any frame lock-in? Or do you imagine us not even needing humans for that?\"*\n\nThe first answer split \"is anything missing?\" into three levels: do the children say everything\nthe parent's **sentence** says (machine-checkable); is a consideration missing that **nobody\nwrote** (coherent absence); is the sentence **the wrong frame** (frame lock-in). Levels two and\nthree were declared human-reserved. The thinking-together turn that followed (*\"Help me think\nabout this. Think deeply.\"*) added the piece that survived everything after: the whisper's\n**direction** is principled even though its size is not — one failing part refutes a whole\nregardless of completeness, established parts confirm it only under closure, which is Popper's\nasymmetry in arithmetic — so the lift after coverage should be a **raised up-weight, never a hard\nequality**.\n\n### 2. The saboteur's door, and the founder's rule\n\nThe founder's next challenge, verbatim: *\"the irreplaceable human value and action also still\ndefinitely makes them able to game and manipulate the system, right? Unless the similarity\nsensitivity and auto merge can somehow defeat any human saboteurs.\"* The answer: yes — min did not\nremove a payoff, it **relocated** one. Padding-to-inflate stopped paying; asserting-requirements-\nto-deflate started. Merge and similarity catch redundancy-shaped gaming and cannot touch this\nnovelty-shaped one. The defense drafted: a requirement is itself a claim with its own strength, and\nthe cap flows through that strength. The sorting rule offered — a part the parent's sentence\n*entails* caps automatically; a non-entailed part must argue — was the sentence the founder would\nknock down next.\n\nThe same turn produced a global directive at his instruction, after a menu had offered him an\noption its own author thought unwise:\n\n> *\"There should be a rule or at least a strong encouragement in Claude.md about never even\n> presenting decision alternatives for me that don't seem to you to be wise.\"* · *\"I agree fully\n> with everything you gave me in your last response, which was thoughtful. That thinking should have\n> been done before presenting me with stupid decision alternatives.\"*\n\nForged as *Decision menus carry only options you would endorse — finish thinking before you ask*.\n\n### 3. The derivability test\n\n> *\"'since a genuinely missing consideration is by definition not derivable from the sentence' — Now\n> I'm feeling dubious about this. Reason about ten different random real example arguments found\n> online. Think extremely deeply about this.\"*\n\nThirteen real arguments were fetched (a Reddit jobs thread, a tuition dispute, the Nigerian fuel\nsubsidy, the seed-oil essay, two monolith posts, two return-to-office pieces, two rent-vs-buy\nessays, the DN Debatt SiS reform, Heather and Turchin on Rome, a Hacker News nuclear thread, an\nanti-EV piece). For each, the considerations a strong critic would raise were listed and graded on\na six-rung ladder of \"derivable from\": the sentence's words · what the words mean · the inference\ntype's critical questions · domain knowledge · a known rival frame · nothing in any corpus. Tally:\n**47 considerations, 0 graded corpus-absent**; the four things graded unreachable were **evidence**\n(what SiS placement feels like; what subsidy removal costs a Lagos household), not considerations.\nThe sentence was withdrawn corpus-wide; the human-reserved residue was re-described as\n**positional**: evidence from where a person stands, concentrated in the tail where text is thin.\n(Part III revisits the tally's zero and finds it was produced by a grader that cannot see it.)\n\nConsequences filed the same day: the deflation defense re-cut to the *derivable requirement space*\n(uniform pre-population makes selective scrutiny pay nothing); the lift's coverage measure became\nthe established fraction of that space; the founder's `bayesianalgorithms.com` resource (Terenin)\nfiled with Pandora's Box as the descent and reservation values as the lift's principled form; a\nconsolidated register of unruled decisions and open loops written into `TODO.md`.\n\n### 4. Perceiving possibility, and the human-seeded channel\n\nA Facebook thread the founder shared (Manu Herrán on creativity as *perceiving possibility*, with\nHofstadter raised in the comments) was read against the analogy machinery. The post's own governing\nanalogy came out **Conditional** under the four-check test; Hofstadter and Copycat entered the corpus\nfor the first time, with the daemon design recognized as Copycat re-described and Copycat's\n*temperature* proposed as the missing piece. Rama Ganesan's comment (*\"AI does not make unexpected\nconnections\"*) became a design element:\n\n> *\"Very useful, document this idea.\"* — the human-seeded channel, now § 7 of `the-analogy-daemon.md`.\n\n### 5. Lived experience, backfill, and the machine-only path\n\n> *\"Positional? What does that mean?\"* → *\"Ah- the lived experience, otherwise known as\"* → *\"Very\n> important. Hmm. Pondering this. To some extent we could backfill millions of lived experiences from\n> online data. But yeah\"*\n\nThe backfill idea was parked with three catches: online testimony is the head of lived experience,\nnot the tail; private posters never consented; and it yields evidence with one channel missing,\nnever attunement. Then: *\"Ok so recap. How would we get closer to confirming the whole, without\nhumans in the loop (until a somewhat later phase)?\"* — answered as a six-step machine-only path\nending in a badge label for **absent positional evidence**, so a machine-complete claim never reads\nas fully established.\n\n### 6. The truth-up, the failed explanation, and the research check\n\n*\"Do a documentation truth-up.\"* Four lies fixed (a stale ledger count, a stale lean, two missing\ntopic rows), the Weakest Link page republished, and one canon line flagged for the founder rather\nthan touched. Then the explanation of the ladder failed him:\n\n> *\"'47 missing considerations'? What are those? Did you ever explain this to me? 'Literal content'?\n> WTF does that mean/refer to? Jesus Christ. Listen to yourself.\"*\n\nRe-explained with one running example (the tuition father) and no shorthand. *\"Do some light\nresearch to shed more light on all this\"* produced four sharpenings from the literature: the\nmachine's candidate questions are roughly half junk and it over-rates its own (CQs-Gen 2025);\nreasoning models detect a missing premise and then do not act on it (Fan et al. 2025); the tail is\ndocumented by name (Santurkar et al. 2023; Tao et al. 2024); and standpoint epistemology splits the\npositional residue into evidence *and* question-setting (zetetic deference).\n\n### 7. Simulation, belonging, the flood, and the conservative design\n\n*\"Can we not prompt models to simulate the perspectives of the tail?\"* — yes for questions, no for\ntestimony; eight constraints, the load-bearing three being simulate-to-ask-never-to-testify, its own\n`simulated` provenance kind, cap-only never lift (Wang et al. 2025; Cheng et al. 2023; Cummins 2025).\n\n> *\"I guess you can go ahead with the canon tweak for now. But. I still feel a tension re the\n> saboteur etc. How can we know which human contributions belong or don't?\"*\n\nThe canon principle *An act's value is not its rung* was re-pointed at the two positional acts,\nprovisionally, in his words. The belonging question was answered: **we do not know, and the design\ndoes not need to** — existence is free, effect is earned, and **positional contributions are\nverified positionally**. His next worry was not fakery but noise:\n\n> *\"Sybil attack? What's that again? What I'm imagining is drowning in irrelevant content/text.\n> Which can definitely destabilize and confuse and derail.\"*\n\nThat forced a correction: requirements inside the derivable space do **not** cap automatically —\nthe machine's own list is half junk — so the cap is weighted by **relevance strength**, presumed\nmodest for a standard question, argued for anything else, closable by an attackable *not\napplicable*. The founder then asked for the synthesis:\n\n> *\"So what's a conservative approach that still uses humans to fill up the tail faithfully but has\n> a healthy measure of distrust against both LLMs and humans?\"*\n\nFiled as `cheap-to-add-slow-to-matter.md`: distrust spent on effect never on entry; a\ndivision-of-distrust matrix; two new rules (the single-source ceiling; positional tiers for\ntestimony); the score-free nursery placed.\n\n## Part II — the corrections made in this arc, for the record\n\n| Corrected claim | Replaced by | Where fixed |\n|---|---|---|\n| \"a genuinely missing consideration is by definition not derivable from the sentence\" | derivable from the sentence plus meaning, scheme, domain and known frames; the residue is positional evidence | derivability doc; weakest-link § 9d; fractal-scales; TODO |\n| a part the sentence *entails* caps automatically | the cut is the derivable requirement space, not entailment | weakest-link § 9d; TODO stack item 3 |\n| a requirement inside the derivable space caps automatically | cap weight = relevance strength, never existence | drowning § 8; derivability § 4 |\n| the whisper item's lean \"park with the whisper standing\" | coverage-checked lifting, raised-not-total, cap through argued relevance | TODO |\n| \"the highest-value human judgment is *what argument is missing here*\" (canon) | the two positional acts; the absence act stays low-rung and human-performable | CLAUDE.md § Principles (provisional, his words) |\n| this session's own \"distrust spent on effect, *never* on entry\" | judgment-free at entry, not cost-free — see Part III | cheap-to-add § 8 |\n| this session's own \"47 graded, 0 corpus-absent\" read as a measurement of absence | a one-sided probe: a model cannot see its corpus's absences — see Part III | derivability § 10 and every surface that quoted the zero |\n\n## Part III — the critical examination (2026-09-05)\n\n> *\"None at all on entry? What's unclear or not obvious about this topic/situation/idea? Critically\n> examine our assumptions and rank them from weakest to strongest, according to the evidence at\n> hand, before proceeding. Help me see this clearly: what's the load-bearing idea/s? One bridging\n> analogy. Competing perspectives if relevant. And after you have answered that: what doesn't fit\n> neatly into that view?\"*\n\n### III.1 \"None at all on entry?\" — no, and the design already says so\n\nThe one-liner *distrust on effect, never on entry* overstated its own design. Entry in Deliberus\nalready carries costs: an account (Google OAuth), a rate limit (measured 3–10 requests per minute),\nclass rules (named-person material is born private; a rendering of your position has one possible\nauthor), and on the machine side cluster-gated ingestion, propose-only tiers and spend gates. What\n*nothing needs permission to exist* actually forbids is a **judgment of the merits** at the door — a\nratify-to-publish gate, a quality bar, a moderator's read. The correct sentence is: **entry is\njudgment-free, not cost-free; the entry costs are the ones that do not discriminate by position**\n(an account and a rate do not; a quality bar does). This matters because the effect-side judges are\npaid in attention, and a flood at a free door taxes exactly them — so some entry-side rate control\nis what *protects* the effect gate rather than contradicting it.\n\n### III.2 What is unclear or not obvious\n\n1. **\"Entry\" is several doors.** The lifecycle tiers (raw → draft → candidate → canonical) mean\n   entry into raw is free and entry into canonical *is* the effect gate. The sentence conflated\n   them.\n2. **\"Effect\" is under-defined.** Effect on strength, on surfaces, on readers' attention, and on the\n   machine's own later passes (a junk claim becomes a candidate for auto-connect) are four different\n   things, and only the first is what the arithmetic gates.\n3. **\"Independent sources\" is doing all the work in the single-source ceiling** and is the one thing\n   the corpus admits it cannot verify (sybils; correlated model families).\n4. **Who judges relevance** is a model with a measured habit of over-rating its own candidates\n   (75–85% labelled useful against 44% actual). The relevance gate is only as good as an unbuilt\n   human check, so the design bottoms out in triage attention, which is also unbuilt.\n5. **Positional verification needs peers**, and the tail is where a position may have one occupant.\n\n### III.3 Assumptions, ranked weakest → strongest by the evidence at hand\n\n1. **Weakest — \"0 of 47 missing considerations were corpus-absent.\"** The grader was a model. A\n   model cannot recognise a consideration its corpus lacks: it either does not generate it (and so\n   never lists it as missing) or it generates it (and so it was never corpus-absent). The test is\n   **biased toward zero by construction** — a never-ask-a-mind-to-audit-its-own-frame violation at\n   the heart of the finding. The four \"evidence\" items were the same grader's judgment of what it\n   lacked. What survives: the listed considerations matched what human commenters in the same\n   threads actually raised (the teacher reductio; the Hacker News portfolio reframe), which is an\n   external check on recall at rungs 2–4 and says nothing about rung 5. Correct reading: *a model\n   reached every consideration human commenters also raised.* Whether a positioned human would raise\n   what the model cannot generate is untested, and untestable by any model-graded design. The\n   instrument that would test it: hand the same thirteen arguments to people from the affected\n   positions and count what they raise that the model did not.\n2. **\"The single-source ceiling handles saboteurs and hallucinations alike.\"** It rests on\n   independence, which is undefended; and by Cheng & Friedman's own theorem (already cited in the\n   weakest-link doc) **a symmetric function of source count is not sybilproof** — the ceiling raises\n   the sybil price from one identity to two, which is nothing. It survives as a *lone-error* guard\n   (one hallucination, one earnest mistake), not as a sybil defense.\n3. **\"Two model families are two sources.\"** Correlated Errors (ICML 2025): models agree on wrong\n   answers more than chance, and the correlation rises with accuracy. The two-family jury is a real\n   improvement and a much smaller one than \"independent\" implies.\n4. **\"Relevance strength can be computed and gates the cap.\"** A second-family judge helps and is\n   unmeasured for this task; the literature says the generator's own judge is biased toward\n   *useful*. Assumed, not shown.\n5. **\"Positional verification works.\"** Standpoint theory says a standpoint is achieved\n   *collectively*, which means a lone occupant of a position has neither a standpoint nor a\n   verifier. The mechanism fails exactly where the tail lives.\n6. **\"Lived experience is what the machine cannot supply.\"** Supported by several current studies\n   (Wang et al.; Santurkar et al.; the standpoint literature) — on current models; the boundary\n   moves as models are trained on more testimony and retrieval-anchored personas improve.\n7. **\"The lift should be raised, never total.\"** Principled (Popper's asymmetry; confirmation\n   holism); no empirical test; the number is a recorded parameter without a value yet.\n8. **Strongest — \"min removes the padding payoff\"** (a theorem plus a measurement: three parts and\n   twelve score the same) and **\"merge catches redundancy-shaped gaming, never novelty-shaped\"**\n   (nearly definitional). Also strong on design grounds though untested on live humans:\n   *existence free, no verdict acts* — no instrument here has met a motivated stakeholder.\n\n### III.4 The load-bearing ideas\n\n- **Existence versus effect.** Nothing needs permission to exist; effect is earned through a route\n  a *different* party can check and that leaves a record. Everything else in the design is a way of\n  spending distrust on effect.\n- **Verification is positional.** The machine checks the derivable; only people who share a\n  position can check testimony from it. This is the genuinely new piece of the arc, and it carries\n  the hole named in III.3 (5).\n- **Payoff relocation.** Every defense moves the payoff rather than removing it; the design question\n  is always *what still pays, and is that exactly the behaviour we want?* The arc found two\n  relocations (padding → deflation; deflation → tangent) by asking that question.\n\n### III.5 One bridging analogy — the rules of evidence\n\nA court lets anyone **file** (existence is free of merits-judgment), but not for free: you need the\nright to bring the claim — what lawyers call standing, which is *position* as an entry requirement —\nand you pay a filing fee and face a docket (rate). **Weight is decided at trial**, by rules of\nadmissibility and by cross-examination (attack). **Expert testimony is qualified by peers of the\nsame expertise** (positional verification). And the analogy carries the design's failure as\nfaithfully as its shape: the Frye and Daubert standards admit expert evidence on *general acceptance\nin the relevant community*, so a genuinely **novel** expertise has no community to accept it and is\nexcluded — the tail problem, stated in law's own words a century ago. The court also names what\nthis design lacks: a **judge** who rules on relevance is a role, not a model, and courts fund it.\n\n### III.6 Competing perspectives\n\n- **The moderation view (Wikipedia).** \"Anyone can edit\" survived only with reverts, patrolling and\n  page protection — entry gates on contested pages. The founder's own edit-war anchor cuts both ways:\n  Wikipedia's answer to persistence-wins was *more* entry control, not less. Deliberus's reply is that\n  add-never-overwrite removes the single state edit wars need; the competing view says a flood still\n  needs a door.\n- **The earned-entry view (Community Notes).** The production example the corpus praises gates\n  *writing* notes on rating history — distrust at entry, on a judged record. That is the strongest\n  counter-example to \"none at entry\", and it works because the record is behaviour, not content.\n- **The skin-in-the-game view.** Stake to post (prediction markets, bonded proposals). Honest and\n  position-neutral in principle, and it excludes the poor — the tail again, by wealth rather than\n  articulacy.\n- **The Bayesian view.** The single-source ceiling is a blunt proxy for dependence-aware\n  aggregation; the novelty dial already in design is the principled version. Choosing between a\n  hard ceiling (robust, crude, not sybilproof) and a graded discount (needs similarity estimates,\n  also not sybilproof) is a real fork the arc did not name.\n- **The standpoint view.** Positional verification is right *and* incomplete: standpoints are\n  collective achievements, so the design must host the achieving — grouping testimony by position\n  so lone voices find peers — or it privileges the already-organised over the unorganised.\n\n### III.7 What does not fit neatly\n\n1. **The headline zero.** The arc's most-quoted number was produced by a grader structurally unable\n   to produce any other. The canon re-pointing rested partly on it; the softer claim (a model\n   reaches what commenters raise) still supports the re-pointing, but the \"0 corpus-absent\" phrasing\n   is withdrawn on every surface that carried it.\n2. **The tail has no peers.** The design's novel mechanism is weakest where its purpose is\n   strongest. Design consequence, proposed: **position grouping** (testimony filed under the position\n   it speaks from, so a lone witness can find a second) and a **sole-witness label** on the badge —\n   the standpoint literature's consciousness-raising as infrastructure.\n3. **The ceiling is not sybilproof**, by a theorem the corpus already cites. Rename its job.\n4. **Model families are correlated**, so \"two sources\" on the machine side is a smaller guarantee\n   than the rule reads.\n5. **Relevance judging regresses to attention.** Every route in the division-of-distrust matrix ends\n   at a human judging relevance or a human attacking, and the surface that rations that attention —\n   the triage feed — is designed, unbuilt. Until it exists the design degrades to *cheap to add,\n   never matters*, which is ratification debt in new clothes.\n6. **Entry costs are position-neutral only if pseudonymous accounts are allowed.** An identity\n   requirement that leaks position (real names) taxes exactly the people the tail needs.\n\n## Part IV — the docs this arc produced or changed\n\nNew: `what-the-necessary-default-changes.md` · `weakest-link-arithmetic-and-the-merge-hunch.md` ·\n`the-irit-harvest.md` · `derivability-of-missing-considerations.md` ·\n`perceiving-possibility-and-the-analogy-organ.md` · `cheap-to-add-slow-to-matter.md` · this file ·\nthe Weakest Link artifact. Changed: `the-analogy-daemon.md` (§ 7), `what-human-judgment-is-for.md`\n(calibration note), `drowning-in-claims.md` (§ 8), `fractal-scales-and-temporal-frame.md` (payoff\nrelocation), `active-inference-context-acquisition-and-deliberus.md` (Terenin), `polis-deep-dive.md`,\n`lowering-the-cost.md`, `support_semantics.py` docstring, `CLAUDE.md` (topic rows; frontier bullets;\none canon line, provisional), `TODO.md` (the consolidated register; the decision stack), the blessed\nglossary (~120 entries, five added this arc), and one global directive.\n\nOpen founder calls carried forward, in dependency order: the lift (restated: coverage over the\nderivable space, raised-not-total, cap through argued relevance) · latent requirements in the cap by\nrelevance strength · payoff relocation as the law's sharpened form · the two conservative rules\n(single-source ceiling, now demoted to a lone-error guard; positional tiers) · position grouping and\nthe sole-witness label (new) · whether to keep the provisional canon re-pointing on the softened\nevidence.\n"}