Skip to content

Records and decision boundaries

A receipt can preserve a claim without proving the event. A witness can retain the receipt without judging the claim. A buyer can rely on evidence without turning it into universal truth.

An agent transaction can cross several systems. Each system may pass its own checks while no one retains the complete handoff. ActionReceipts preserve the transaction claims. Bulla checks the parts a supplied policy can decide. A witness can keep the exact receipt in a separate log. These jobs remain separate so one successful check cannot silently answer a different question.

Keeping responsibility attached across handoffs

The routed-inference draft states the program’s current operational invariant as answerability conservation: no consequential transition may create an orphaned consequence or silently discharge an inherited binding. Attributable principals, applicable terms, and conveyed recourse remain attached until a future authenticated closure or novation protocol exists.

answerability(edge) =
  attributable principals
  + exact parent occurrence
  + conserved terms and slot
  + conveyed recourse
  + no silent discharge

Evidence strength behaves differently. A chain is only as well supported as the evidence needed at each hop. Receipts preserve responsibility; they do not manufacture proof of execution.

Seven separate checks

01IntegrityCanonicalization and four hashes establish whether the supplied record recomputes.
02AuthoritySignature and issuer authorization establish who vouched and under which mandate.
03BoundsExecutable predicates determine whether the declared act conforms to its pinned scope.
04RelianceA relying party records the explicit policy under which it accepted, rejected, or deferred.
05InclusionA proof is checked against a root obtained independently of the host serving it.
06WitnessingA separate operator retains the exact receipt and commits it to one authenticated history.
07RecourseThe receipt conveys challenge terms; external evidence is still needed to show a remedy is reachable.

Inclusion under a host-served root is still the host’s assertion. The relying party must pin, gossip, or independently anchor the root before the proof reaches independently grounded inclusion depth.

Limits of this evidence

A host's assertion about its own root is not independent grounding; the relying party must obtain or anchor the root separately.

A witnessed record can establish that a particular receipt entered an authenticated history and can make same-size conflicting heads objective equivocation evidence. It cannot establish that the provider performed the process it described or that no unlogged action occurred.

Limits of this evidence

Witness evidence establishes what entered a witnessed history; it does not prove the underlying execution occurred or reveal omitted actions.

Recourse conveyance and recourse reachability are intentionally different report dimensions. The current routed corpus can verify consistent conveyance; reachability remains unverified.

Limits of this evidence

A consistently conveyed remedy adapter establishes recourse terms, not that a forum, remedy, or settlement path is operational.

Transaction Answerability

Transaction Answerability carries terms, evidence, authority, and recourse across a machine handoff. The current network profile composes one inference procurement with a selected ActionReceipt, witnessed history, an objective non-equivocation covenant, and declared downstream reliance paths.

A same-size witness fork can open only the remedy already bound to that objective service fault. It does not change the provider’s claims or the status of unrelated branches. Run the reference network.

Limits of this evidence

The example verifies supplied synthetic records and declared dependency paths. It does not prove that every dependency was recorded, that the witness is independent, or that money moved.

Semantic-composition diagnosis

Bulla’s original diagnostic compares the full conventions needed by a composition with the conventions its public schemas disclose. Its coboundary-rank difference localizes independent undisclosed dimensions:

disclosure_deficit = rank(delta_full) - rank(delta_observable)

This is a valid formal and operational object inside the pinned composition model. A diagnostic can be referenced by an ActionReceipt, and an executable convention can be recomputed by a verifier. Neither operation turns the diagnostic into authority, execution evidence, persistent witnessing, or a remedy.

These semantic diagnostics do not size witness bonds, predict equivocation, price loss, or underwrite the Answerability Network.

Limits of this evidence

The coherence fee measures undisclosed conventions in a pinned composition model; it is not Bulla's safety foundation or an execution-failure predictor.

In characterized finite regimes, Bulla can identify a minimum-cost set of fields whose disclosure repairs the modeled deficit. “Exact” names that optimization result. It does not certify the resulting system’s behavior, economics, or legal sufficiency.

Limits of this evidence

Exact means minimum-cost within the pinned finite repair model; it is not proof of safe execution or a universal real-world cost.

Composition glossary

Composition diagnosis

A deterministic analysis of the conventions a pinned tool graph needs and the conventions its observable schemas disclose.

Disclosure deficit

The rank difference between the full and observable convention maps inside the selected finite model.

Blind spot

One localized obstruction dimension together with the fields and edges that carry it.

Semantic dimension

A convention such as path root, date encoding, currency unit, or identifier offset shared across a seam.

Interaction score

The residual between the sum of per-dimension deficits and the total, used to locate dimensions that share hidden fields.

Convention pack

A versioned vocabulary of dimensions, known values, aliases, source registries, and classification patterns.

Standards and restricted registries

Open standards may ship inline or by content-addressed reference. Restricted standards remain metadata until a consumer supplies licensed values.

Bridge and translation

A bridge discloses a hidden convention. A translator applies a typed value mapping and can emit a receipt for that transformation.

Registry and inclusion

A signed deed or receipt may enter a Merkle log. Inclusion and consistency proofs are checked against a separately accepted root.

WitnessReceipt and ActionReceipt

A WitnessReceipt binds a composition diagnostic and policy. An ActionReceipt records one consequential act. They remain distinct formats.

Signed deed

A composition certificate signed by its issuer and optionally included in a deed registry.

Disposition

A relying-policy result such as proceed, advise, refuse pending disclosure, or unresolved.

Epistemic receipt

Machine-readable status for a repair recommendation: exact in a pinned finite regime, surrogate with a downgrade reason, or unresolved.

Boundary fee

The portion of a modeled disclosure deficit that crosses server ownership boundaries.

Contradiction score

Visible schema incompatibilities such as conflicting formats, enumerations, or ranges.

Structural diagnostic

A combined localization report for disclosed and undisclosed interface conditions.

Verification bill

A descriptive pairing of opacity and visible incompatibility costs.

Disclosure state

Public presentation uses DISCLOSED, PARTIALLY UNDISCLOSED, and MATERIALLY UNDISCLOSED.

Coverage from a supplied action log

Verification starts with a receipt and asks whether it recomputes. Coverage starts with a separately supplied action log—the list being checked—and asks which actions left no receipt. The two operations are complementary: perfect verification of the records an issuer chose to show cannot reveal the records it omitted.

Current end-to-end profile

The routed-inference draft applies the architecture to a finite grammar:inference.order → inference.route → inference.accept → inference.delivery → bulla.rely. It supports single_route_single_provider,full term disclosure, retained bindings, no discharge, and a signed-declaration budget ledger. 14 adversarial traces exercise the grammar; the live-provider, settlement-adapter, and independent-implementation counts remain0, 0, and 0.