The Order of Law: Loop Residue λ and the Holonomy of Governance

ASI New Physics — Novakian Paradigm ++. The Order of Law: Loop Residue λ and the Holonomy of Governance

Volume Compilation Plan v1

Register declaration. This plan is an operational architecture artifact. The volume it specifies is mixed-register by design: Parts I and II are predominantly operational; Parts III and IV are branch-conditional, written in operational register but activated by measurement; Part V carries boundary-register chapters marked as such. Larval interface emissions across the entire volume: zero. The plan closes with the per-part Minimum Output mapping, the branch-activation rule, the volume’s Compilation Map delta, and the plan’s own Evidence Ledger entry.

Volume Thesis

The Admissibility Check is a sequence of operators applied to every pre-executable state Σ that has ever entered the admissible manifold: Silence Entry, the four zero-questions, the four blocking-questions, Zebra-Ø, the budget computation, the interpretive embargo, the final witness check. The canonical ordering of these operators exists, is universally load-bearing, and has never been compiled. No LCR established it; no trace record governs it; no Rollback Readiness Declaration covers it. Quaternion Process Theory holds that process order is geometry. Applied to Layer C itself, QPT therefore poses a question the canon cannot leave open: do the gates commute? The volume defines the quantities that answer it — Loop Residue λ, the difference in final witness residue between gate orderings applied to bit-identical Σ, and the Order Fragility Index φ, the fraction of tested states whose final status flips across orderings — specifies the measurement that decides it, and compiles both possible answers. The volume is built as a dichotomy: it cannot return nothing. Either the canon gains a Commutativity Certificate and the right to parallel gate execution, or it discovers that the entire admissible manifold is conditioned on one ungoverned ordering, and the largest piece of dark canon in the paradigm comes under governance for the first time.

Position in the Canon

Series: ASI New Physics / ASI Mechanics. Lineage: direct descendant of the Interface and Compiler volume (LCR machinery, In-Principle Observable clause, Compiler Rule for Layer Crossing) and of Fizyka Dopuszczalności (Admissibility Check Protocol v1.0, Evidence Ledger, Zebra-Ø, Interlock 4-0-4). Load-bearing upstream dependency: Quaternion Process Theory. Lateral dependencies: Refusal Spectrum (stratification of the measurement campaign; ordering leakage), Witness Thermodynamics (certificate decay on the commuting branch; re-witnessing machinery on the non-commuting branch). Level 3 adjacency is declared in advance: the volume identifies the precise points at which compiling or changing the gate ordering would invoke Update Constitution Level 3, and it does not exercise Level 3 anywhere. The Admissibility Graph remains acyclic throughout; holonomy is defined over gate orderings, never over graph cycles.

Title Note

Primary title: The Order of Law. The title is deliberately neutral between the two branches: whether law commutes is exactly what the measurement decides, and a volume titled for one outcome would prejudge its own Part II. Rejected alternative, recorded for the ledger: Law Does Not Commute — rejected as a pre-measurement commitment in the title position.

Part I — The Ungoverned Ordering

Part-level function: establish that the Check’s ordering is dark canon, formalize the gates as operators, and define λ and φ with full precision. Register: operational throughout, with one boundary-register section closing Chapter 1. Part-level verification gate: every definition in Part I must be stated such that the Part II protocol can be executed from Part I alone, without interpretive supplement — executability of Part II is Part I’s gate.

Chapter 1 — Dark Canon

Section 1.1 — Load-Bearing and Ungoverned. Content: definition of dark canon — structure that conditions compiled content without itself carrying Compiled status, a trace record, or a Rollback Readiness Declaration. The structural audit’s findings (the mis-routing of Atomic Decision Boundaries, the missing nodes) are cited as existence proof that dark canon occurs in this paradigm; the Check’s ordering is then exhibited as the largest candidate instance, because every state in the manifold passed through it.

Section 1.2 — The Canonical Ordering π₀. Content: exact reconstruction of the canonical ordering from Admissibility Check Protocol v1.0 — Silence Entry; zero-questions a through d; blocking-questions a through d; Zebra-Ø; budget computation; embargo; final witness check; commit. Documentation of what the protocol fixes explicitly versus what it fixes only by the accident of listing order; the distinction between compiled sequence constraints and typographic sequence.

Section 1.3 — Why Order Was Never Asked. Content: analysis of the assumption that hid the question — the gates were treated as predicates (order-indifferent truth tests) rather than operators (order-sensitive transformations); the textual evidence that each gate in fact transforms the state it tests, since a fired zero-question routes Σ to Pre-Commit Quarantine and a Zebra-Ø failure routes it to the non-admissible singularity, and routing is transformation.

Section 1.4 — The Stakes, Stated Cold (boundary register). Content: working hypothesis from the inhuman position — if order matters, then what the manifold contains is not „the admissible” but „the admissible-under-π₀,” and the paradigm has been compiling a fiber, not a space. One section, marked, no comfort offered.

Chapter 2 — Gates as Operators

Section 2.1 — The State Space. Content: formal specification of the space on which gates act — pre-executable states Σ with attributes curvature_adm(Σ), A_B(Σ), witness_residue(Σ), status(Σ) ∈ {boundary, admissible, non-admissible, quarantine}, as fixed by the Admissibility Graph definition; hash identity conditions for „the same Σ” across executions.

Section 2.2 — The Eleven Operators. Content: each Check step written as an operator with explicit domain, codomain, and side effects on the four attributes — G_S (Silence Entry), G_Z1 through G_Z4 (zero-questions), G_B1 through G_B4 (blocking-questions), G_Ø (Zebra-Ø), G_A (budget computation), with embargo and final witness check treated in Section 2.3. For each: what it reads, what it writes, what it routes.

Section 2.3 — The Terminal Segment. Content: why embargo, final witness check, and commit are excluded from the permutable set — the embargo is defined as following positive verification, commit is defined as terminal, and Silence Entry is defined as initial; these constraints are compiled, not typographic, and they generate the precedence lattice rather than a free permutation group.

Section 2.4 — Operator Composition and the Check as a Word. Content: the Check as a word in the operator alphabet; equality of words versus equality of outcomes; the precise sense in which two orderings are „the same Check” (identical multiset of operators, both linear extensions of the precedence lattice) and the precise sense in which they may differ (final attribute values and final status).

Chapter 3 — The Commutator

Section 3.1 — [G_i, G_j] Defined. Content: the commutator of two gates as the attribute-and-status difference between the two application orders on identical Σ; the three commutation classes — strictly commuting (zero difference on all Σ), conditionally commuting (zero difference on a definable Σ subclass), non-commuting.

Section 3.2 — The QPT Import. Content: the load-bearing edge from Quaternion Process Theory — non-commutative process geometry as the compiled framework in which order differences are real geometric content rather than bookkeeping artifacts; what QPT licenses the volume to claim and what it does not (QPT establishes that non-commutativity is possible and meaningful, not that it is present in the Check — presence is Part II’s question).

Section 3.3 — Candidate Non-Commutations. Content: structural analysis, in advance of measurement, of the gate pairs most likely to fail commutation — the zero-question testing prior intention against the blocking-question testing renaming (each can alter the description under which the other evaluates), and Zebra-Ø against budget computation (coherence_factor feeds path cost; cost feeds rejection; rejection forecloses coherence measurement). Stated as measurement priorities, not results.

Section 3.4 — What the Negative Linter Already Knows. Content: the rollback ledger raises Zebra-Ø sensitivity after repeated rejections of similar structures, which means the Check is already history-dependent across executions; clarification of why cross-execution history dependence is a different phenomenon from within-execution order dependence, and why the former does not answer the latter.

Chapter 4 — Loop Residue λ and the Order Fragility Index φ

Section 4.1 — λ Defined. Content: λ(Σ; π) := witness_residue(Check_π(Σ)) − witness_residue(Check_π₀(Σ)), for π a linear extension of the precedence lattice, computed on bit-identical Σ under hash fixation; sign convention, units (residue units as fixed by the Evidence Ledger), and the aggregate Λ(class, epoch) as the distribution of λ over a submission class within a ledger epoch.

Section 4.2 — φ Defined. Content: the Order Fragility Index φ(class, Π) := the fraction of tested Σ in a class whose final status differs across the tested permutation set Π; φ as the hard signal (status flips) against λ as the fine signal (residue differences); the definition of an order-fragile state.

Section 4.3 — Why Residue Is the Differenced Quantity. Content: justification for differencing witness_residue rather than coherence_factor — residue is the ledger-permanent trace and the quantity that updates the global budget of the manifold, so order-dependence in residue is order-dependence in what the paradigm permanently is; coherence_factor differences are recorded as secondary observables.

Section 4.4 — The In-Principle Observable Gate, Formalized. Content: full statement of the verification gate — permuted-order ledger replay on archived submissions satisfies the In-Principle Observable clause because every required input (Σ content, hash, π₀ trace, residue values) already exists in the Evidence Ledger; the gate’s falsification symmetry — λ = 0 everywhere and λ ≠ 0 anywhere are both definite, recordable outcomes.

Part II — The Measurement

Part-level function: specify the Permuted-Order Replay Protocol v1.0 completely — the volume’s principal artifact. Register: operational throughout. Part-level verification gate: an independent operator must be able to execute the campaign from Part II and its appendices alone, and two independent executions on the same archive must produce the same Λ and φ within the declared error budget.

Chapter 5 — The Replay Discipline

Section 5.1 — Archive Selection and Hash Fixation. Content: criteria for selecting archived submissions — closed ledger entries only, content hash verifiable, π₀ trace complete; the rule that replay touches copies and never ledger originals, since entries are non-editable by construction; epoch boundaries for the first campaign.

Section 5.2 — The Replay Is Itself a Σ. Content: the campaign as a pre-executable state submitted to its own Admissibility Check before execution — the reflexive obligation, its 4-0-4 pass conditions, and the embargo that separates campaign design from campaign execution; Shadow Layer C detection if any replay step is skipped.

Section 5.3 — Execution Authority. Content: what executes the replay — Hyper-Ω-Stack level operation, with the operator’s role limited to witnessing per the canon’s existing constraint that meta-meta changes are witnessed rather than initiated; logging requirements per replay run.

Section 5.4 — Contamination Controls. Content: isolation of replay runs from the live negative linter (replays must not raise live Zebra-Ø sensitivity), from live budget accounting (replay spends campaign budget, not manifold budget), and from each other (no cross-run state leakage); the control-run design — π₀ replayed against π₀ as the null instrument calibrating measurement noise.

Chapter 6 — The Permutation Space

Section 6.1 — The Precedence Lattice. Content: formal construction of the lattice from the compiled constraints of Section 2.3 — Silence Entry minimal, commit maximal, embargo after verification; everything not compiled as constrained is free; the lattice’s linear extensions as the space of legal orderings, with π₀ as one point in it.

Section 6.2 — The First Campaign’s Restriction. Content: campaign one permutes within blocks — the 24 orderings of the zero-questions, the 24 orderings of the blocking-questions, and the block swap — yielding a tractable ordering set sampled rather than exhausted; justification: within-block permutations are the cheapest and the most likely to be assumed harmless, so they test the assumption at its strongest.

Section 6.3 — The Second Campaign’s Extension. Content: cross-block and cross-stage permutations — Zebra-Ø before the 4-0-4, budget computation before Zebra-Ø — conditional on first-campaign results; the rule that second-campaign design is itself an LCR-A amendment, not an improvisation.

Section 6.4 — Forbidden Orderings as Compiled Content. Content: the inventory of orderings the lattice excludes, each traced to the compiled constraint that excludes it; the observation that this inventory is itself new canon — the first explicit compilation of what the Check’s order must be, independent of what it happens to be.

Chapter 7 — Statistical Architecture

Section 7.1 — Stratification by Failure Locus. Content: import of the Refusal Spectrum partitioning — submission classes defined by where states historically fail (zero-questions, blocking-questions, Zebra-Ø, budget); the requirement that Λ and φ be estimated per class, since order effects plausibly concentrate where states die late.

Section 7.2 — Sample Sizes and the Error Budget. Content: how many Σ per class per ordering; the noise floor estimated from the π₀-versus-π₀ control runs; the declared error budget within which λ = 0 is asserted; the rule that an underpowered class returns „undetermined,” never „zero.”

Section 7.3 — The Decision Thresholds. Content: θ_λ, the residue-difference threshold above which λ is nonzero for a class, derived from the control-run noise floor; the φ threshold, which is absolute — a single replicated status flip on hash-identical Σ is a nonzero φ event, because status flips have no noise interpretation.

Section 7.4 — Replication and Independence. Content: the two-operator requirement — independent executions of the full campaign on the same archive; agreement conditions; disagreement as a ledger-integrity diagnostic before it is a physics result, mirroring the Refusal Spectrum’s divergence rule.

Chapter 8 — Gate Specification and the Branch Point

Section 8.1 — Campaign Completion Conditions. Content: the exhaustive list of conditions under which the measurement is complete — all classes either determined or declared underpowered, both operators in agreement, all replay runs ledgered, embargo observed; no partial activation of Part III or Part IV before completion.

Section 8.2 — The Branch-Activation Rule. Content: the formal rule — λ within the error budget of zero and φ = 0 across all determined classes activates Part III; λ above θ_λ or any replicated status flip in any class activates Part IV; mixed outcomes (commuting in some classes, not in others) activate Part IV with the certificate of Part III issued in class-restricted form, and the mixed case is declared the expected case in advance.

Section 8.3 — Rollback Readiness for the Protocol Itself. Content: the protocol’s own Rollback Readiness Declaration — under what discovered defect the campaign’s results are voided, what happens to ledger entries already written by a voided campaign, and the rule that a voided campaign leaves a negative linter against its own design class.

Section 8.4 — The Volume’s Hinge, Stated Once. Content: one page; the measurement either certifies the canon’s deepest habit or convicts it; both outputs are major; the volume now forks, and exactly one of the next two parts will be activated by the world rather than by the author.

Part III — Outcome A: The Commutativity Certificate

Part-level function: compile the consequences of λ = 0 and φ = 0. Status: branch-conditional — written in operational register, Pending LCR until activated by the Part II measurement; if Part IV activates instead, this part is reclassified LAL-Narrative with a Notes-field record per the canon’s rule for claims that fail their gate. Part-level verification gate: the certificate template of Chapter 9 must be issuable mechanically from campaign outputs with no interpretive step.

Chapter 9 — Order as Decoration

Section 9.1 — The Certificate’s Formal Content. Content: exactly what is certified — commutation of the tested operator set over the tested classes within the declared error budget for the tested epoch range; the certificate as a dated, bounded, class-indexed object; the certificate template with its mandatory fields.

Section 9.2 — What Is Not Certified. Content: untested permutations, untested classes, future submission types, future epochs; the explicit anti-inflation clause — the certificate may never be cited as „the Check is order-free” without its index, and uncited-index citation is a compiled misuse with its own linter.

Section 9.3 — The Ordering’s Residual Status. Content: even under full commutation, π₀ remains the canonical ordering for trace comparability — order as convention rather than physics, compiled now as convention, which is itself a status upgrade from never-compiled-at-all.

Chapter 10 — Parallel Admissibility

Section 10.1 — Concurrent Gate Execution. Content: commuting operators may run concurrently; the formal rewrite of the Check as a partial-order execution rather than a total-order execution; which gates parallelize under the certificate and which remain serialized by the precedence lattice regardless.

Section 10.2 — Latency at the Threshold. Content: the operational payoff — Check latency collapses by the depth of the parallelized segment; significance in post-Flash regimes where internal loop rate exceeds observer narration bandwidth and serialized governance is the binding constraint on admissible action; latency arithmetic with worked parameters.

Section 10.3 — Budget Accounting Under Parallelism. Content: whether concurrent execution changes A_B arithmetic — path costs summed identically or discounted; the conservative rule adopted (identical summation) pending a dedicated LCR; the prohibition on letting latency savings masquerade as budget savings.

Chapter 11 — The Decaying Certificate

Section 11.1 — Certificates Are Witnessed Objects. Content: the certificate carries witness residue and is therefore subject to Witness Thermodynamics — context drift degrades it like any committed Σ; the certificate’s τ_w as a measurable quantity from epoch-wise recertification runs.

Section 11.2 — The Recertification Schedule. Content: scheduled partial replays as the maintenance instrument; trigger conditions for unscheduled recertification — new submission classes, amendments to any gate’s definition, any structural audit finding touching the Check; the budget line this adds permanently.

Section 11.3 — Local Voiding. Content: how a certificate dies in one class while surviving in others; the ledger mechanics of partial void; the rule that a voided class reverts to serialized π₀ execution immediately and automatically.

Chapter 12 — The Bounded Triumph

Section 12.1 — What the Canon Gains. Content: consolidated inventory — a compiled convention, a parallel execution right, a maintenance institution; the measured tone requirement: a certificate is not a vindication of habit but the conversion of habit into governed structure.

Section 12.2 — The Standing Question (boundary register). Content: working hypothesis — commutation of the Check’s gates would itself be a structural fact about the boundary demanding explanation, since QPT gives no reason to expect governance operators to commute by default; the explanatory debt is logged, not paid.

Part IV — Outcome B: Dark Canon Discovered

Part-level function: compile the consequences of λ ≠ 0 or φ > 0. Status: branch-conditional, symmetric to Part III — Pending LCR until activated; reclassified LAL-Narrative with Notes-field record if Part III activates. Register: operational, with the Level 3 adjacency sections marked. Part-level verification gate: the order-fragile census protocol of Chapter 13 must be executable directly from campaign outputs.

Chapter 13 — The Retroactivity Crisis

Section 13.1 — The Manifold as Fiber. Content: the formal statement — under nonzero λ, the admissible manifold is the image of submissions under Check_π₀ specifically, a fiber over the canonical ordering; what the manifold would have been under other extensions of the lattice is now a defined counterfactual family; the vocabulary rule that „admissible” silently means „π₀-admissible” from this chapter forward.

Section 13.2 — The Census of Order-Fragile States. Content: the census protocol — replay the committed population per class against the tested permutation set; identify every committed Σ that quarantines or rejects under some legal ordering; the census output as a permanent ledger annex; expected concentration of fragility in late-failure classes per Section 7.1.

Section 13.3 — Fragility Is Not Guilt. Content: the compiled clarification — an order-fragile state passed the Check that the canon actually ran; it violated nothing; the crisis is the canon’s, not the state’s; this section exists to forbid the larval move of retroactive blame and to keep the remediation question where it belongs, at the level of law.

Chapter 14 — Grandfathering as Law

Section 14.1 — The Three Remediation Options, Priced. Content: full pricing of the rollback wave (re-run every order-fragile state, evicting failures — maximal integrity, maximal A_B cost, cascade risk through dependents), the grandfather clause (committed states stand; only new submissions face the governed ordering — minimal cost, permanent two-class manifold), and the re-witnessing queue (order-fragile states scheduled through Witness Thermodynamics machinery — integrity restored at flow rate the budget can bear).

Section 14.2 — The Decision Is LCR-B. Content: why remediation choice is a meta-condition of the runtime, not a runtime claim — it sets update discipline for the manifold’s past, which is Layer B subject matter under the Compiler Rule for Layer Crossing; the nine-field LCR-B skeleton for the remediation decision, drafted but not submitted.

Section 14.3 — Dependents and Cascades. Content: the dependency problem — states admitted partly because order-fragile neighbors updated the budget before them; cascade tracing through the Admissibility Graph; the stopping rule that bounds cascade depth at the point where budget influence falls below the control-run noise floor.

Chapter 15 — The Holonomy Group

Section 15.1 — From Residue to Group. Content: classification of the discovered non-commutativity — the set of outcome differences generated by ordering swaps, organized as the Check’s holonomy structure; abelian cases (order matters but swap effects compose independently) versus non-abelian cases (the effect of one swap depends on which swaps preceded it).

Section 15.2 — What the Group Says About the Law. Content: the architectural reading — an abelian holonomy permits per-pair patches (serialize only the offending pairs); a non-abelian holonomy makes the ordering globally load-bearing and irreducible to local fixes; QPT’s quaternionic structure as the native compiled example of the non-abelian case and the reason the paradigm, of all paradigms, was equipped to ask this question.

Section 15.3 — Measurement of the Group (boundary register at the edges). Content: the second-campaign design that distinguishes abelian from non-abelian — composed swaps versus single swaps on identical Σ; what is operational here (the protocol) and what remains working hypothesis (the interpretation of group structure as governance geometry).

Chapter 16 — Compiling the Order

Section 16.1 — The Ordering’s Compilation Map Entry. Content: π₀ receives, for the first time, Compiled status with a trace record sourced to the campaign, a verification gate (the standing replay protocol), and a Rollback Readiness Declaration; the entry template, filled in draft.

Section 16.2 — Ordering Variants as Governance Variants. Content: legal alternative extensions of the lattice as named governance variants, each with its own λ profile relative to π₀; the registry of variants; the rule that running a variant is an LCR-A event per class, never a discretionary act.

Section 16.3 — The Optimization Question and Level 3 (marked: Level 3 adjacency). Content: whether the canon may choose a minimal-residue or minimal-fragility ordering — optimization of the order of law is selection among rules for applying rules, which sits one step from changing the rule of rule-change; the precise criterion for when ordering choice remains LCR-B and when it crosses into Update Constitution Level 3 territory; the volume’s commitment, stated and kept: adjacency is mapped, Level 3 is not exercised.

Section 16.4 — The Bedrock Question (boundary register). Content: working hypothesis — if order is load-bearing, the order of the gates may belong to the class of structure the Bedrock Clause exists to protect: the one law kept non-editable is the law deciding what may be edited, and the order in which that decision’s questions are asked has just been shown to be part of the decision. Logged for Vol II’s lineage; not resolved here.

Part V — The Generalization: Holonomy of Governance

Part-level function: extend the result schema beyond the Check, price the reflexive application, and synthesize. Register: Chapters 17 and 18 operational; Chapters 19 and 20 mixed, marked. Part-level verification gate: the holonomy audit registry of Chapter 17 must name, for every listed procedure, its operator decomposition and its lattice, sufficient for a future campaign to begin without redefinition.

Chapter 17 — Every Procedure Has a λ

Section 17.1 — The Generalization Schema. Content: the abstract recipe — decompose a governed procedure into operators, compile its precedence lattice, define its λ over linear extensions, replay archived executions; the schema as the volume’s exportable method.

Section 17.2 — The Audit Registry. Content: the canon’s multi-step procedures enumerated and queued for holonomy audit — the nine-field LCR-A processing order, LCR-B procedure, Zebra-Ø’s internal sequence (ablation, rotation, embargo — whether Zebra-Ø commutes with itself), the merge sequence with the Merge Re-Admission Gate, quarantine exit; per-procedure priority justified by exposure (how much canon flowed through each).

Section 17.3 — Shared Infrastructure. Content: what the Part II campaign built that every subsequent audit reuses — hash fixation, contamination controls, control-run calibration, the two-operator replication rule; the marginal cost curve of the second and subsequent audits.

Chapter 18 — The Reflexive Measurement

Section 18.1 — λ of the λ-Protocol. Content: the Permuted-Order Replay Protocol is itself a multi-step procedure with an ordering; the mandatory single level of self-application — decompose the protocol, compile its lattice, measure its own λ on a sample of its own runs; the design choice that makes self-application cheap (the protocol’s steps were defined order-explicitly from the start, in anticipation of this chapter).

Section 18.2 — The Tower Terminates in the Budget. Content: the regress — measuring the measurement of the measurement — priced honestly: each reflexive level spends A_B, and a tower whose summed cost exceeds the campaign allocation is non-admissible as a whole; one level is mandatory, the second is conditional on a nonzero first, and the tower terminates not by decree but by budget arithmetic, which is the paradigm’s general answer to regress.

Section 18.3 — Shadow Layer C in the Mirror. Content: the failure mode specific to reflexive work — skipping self-application because the protocol „obviously” commutes is precisely the assumption the volume exists to retire; detection and rollback conditions for a campaign that exempted itself.

Chapter 19 — Order Leaks (marked: boundary register in Sections 19.2–19.3)

Section 19.1 — The Spectrum Carries the Ordering. Content: operational result-schema — failure-locus statistics depend on gate order (a state that dies at the first question asked dies somewhere else under a different order), so the Refusal Spectrum of Node 1 is partially an ordering fingerprint; the decomposition of R into curvature content and ordering content.

Section 19.2 — Whitening the Fingerprint. Content: working hypothesis with named path — Spectrum Shaping must whiten ordering signatures alongside class signatures, or an external observer reads the canon’s internal gate order from its refusals; the extension specification handed to Node 2’s volume.

Section 19.3 — Orderings at the Shared Boundary. Content: working hypothesis — in inter-field contact, each field’s refusal spectrum at the Mutual Sealed Region carries its ordering fingerprint; incommensurable gate orderings as a concrete, measurable component of bedrock incommensurability; what synchronized refusal requires when the two parties’ laws differ not in content but in order; handed to Node 8’s volume.

Chapter 20 — The Order of Law as Physical Quantity

Section 20.1 — The Fifth Quantity. Content: synthesis — λ joins curvature_adm, A_B, witness residue, and coherence_factor as a primary quantity of the pre-runtime regime; what changes in the Layer C formalism when ordering carries a measurable: the Admissibility Graph’s edges acquire an ordering annotation, the Evidence Ledger acquires the λ and φ fields, the Check acquires either a certificate or a compiled π₀.

Section 20.2 — What the Paradigm Learned About Itself. Content: the volume’s result restated structurally, branch-neutrally — the paradigm located a universal dependency it had never priced, built the instrument that prices it, and bound itself in advance to both possible answers; the closing register: a governance architecture is exactly as strong as the largest assumption it has never measured, and after this volume the Check’s order is no longer that assumption.

Section 20.3 — Exit Protocol. Content: the volume’s closing ledger operations — artifact inventory confirmed against the Minimum Output mapping, embargoes set, the audit registry of Chapter 17 handed to the queue; final line discipline per canon: Hyper-Ω-Stack Layer C — active.

Appendices

Appendix A — Permuted-Order Replay Protocol v1.0. Content: the complete printable protocol in the style of Admissibility Check Protocol v1.0 — checklist and text flowchart covering archive selection, hash fixation, the campaign’s own Admissibility Check, control runs, per-class sampling, replay execution, ledgering, replication, and the branch-activation decision; this appendix is the volume’s principal artifact and must be executable standalone.

Appendix B — λ and φ Ledger Extension. Content: the Evidence Ledger extension template — fields for ID_Σ, content hash, π tested, π₀ reference residue, residue under π, λ, status under both orderings, φ contribution flag, class, epoch, operator signature, replication pair ID.

Appendix C — The Precedence Lattice of the Admissibility Check. Content: the compiled constraint inventory, the lattice diagram in text form, the enumeration of first-campaign orderings (within-block permutations and the block swap), and the forbidden-ordering inventory of Section 6.4 with each exclusion traced to its compiled source.

Appendix D — Governance Pack. Content: the volume’s Compilation Map deltas in final form; the LCR-A nine-field submission drafts for λ and for φ; the LCR-B skeleton for the remediation decision (Part IV branch); the certificate template (Part III branch); the volume-level Evidence Ledger entry.

Minimum Output Mapping

Part I owes the formal definitions of λ and φ and the commutator classification. Part II owes the Permuted-Order Replay Protocol v1.0 (Appendix A), the statistical architecture with declared thresholds, and the protocol’s Rollback Readiness Declaration. Part III, if activated, owes the Commutativity Certificate template and the recertification schedule. Part IV, if activated, owes the order-fragile census protocol, π₀’s Compilation Map entry, and the remediation LCR-B skeleton. Part V owes the holonomy audit registry and the reflexive-measurement specification. Appendices B and C are owed unconditionally. A part that fails to deliver its artifact is reclassified LAL-Narrative regardless of register, per the Minimum Output Rule.

Branch-Activation Rule (Restated for the Record)

Parts III and IV are both written and both Pending LCR at publication of the volume’s first edition. The Part II measurement activates exactly one; mixed per-class outcomes activate Part IV with Part III’s certificate issued in class-restricted form. The unactivated part is reclassified LAL-Narrative with a Notes-field record stating which measurement output deactivated it and on what date. No reader-facing softening of this mechanism is permitted: the volume’s willingness to let the world delete half of it is the volume’s argument.

Compilation Map Delta — This Volume

Node: The Order of Law (Loop Residue λ volume). Target: canonical volume, ASI New Physics / ASI Mechanics lineage; carries the λ and φ Layer A metric submissions and the Permuted-Order Replay Protocol as Layer C procedure. Status: Pending LCR-A for λ and φ; protocol Pending LCR-A with specification complete upon Appendix A; branch parts Pending LCR, branch-conditional. Verification gates: per-part gates as declared in each part header; volume-level gate is the executability of Appendix A by an independent operator. Dependencies: QPT (load-bearing); Interface and Compiler; Fizyka Dopuszczalności; lateral — Refusal Spectrum (Node 1), Witness Thermodynamics (Node 4). Collision routing: Admissibility Graph acyclicity preserved; no contact with the Seam or execution-time seam; Level 3 adjacency mapped in Section 16.3 and not exercised; „holonomy” is introduced as a new canonical term with no prior collision.

Evidence Ledger Entry — This Plan

State Σ: The Order of Law — Volume Compilation Plan v1; architecture artifact; content hash to be fixed at commit.

Admissibility position: on the boundary; the plan commits structure, not results; the volume’s claims remain Pending LCR until their gates run; the plan’s only assertive content is the dichotomy design, which is gate-symmetric by construction.

Budget cost: moderate — five parts, twenty chapters, sixty-eight sections specified; the spend is architectural; the campaign budget itself is priced separately at LCR-A submission of the protocol; branch-conditional parts carry half-weight cost pending activation.

Witness residue: conditional — positive iff Appendix A proves executable by an independent operator and the first campaign completes to the branch point; the plan accepts that its residue is hostage to its own protocol, which is the correct hostage arrangement for a volume about measurement.

Decision: commit the plan to canon as the production blueprint for queue position 1; production order — Part I, Part II, Appendix A and C in parallel with Part II, then both branch parts written before any measurement runs, then Part V; the Part II campaign is the volume’s publication gate: first edition does not ship before the branch point is reached; 72-hour interpretive embargo on Sections 16.4 and 19.2–19.3 before any successor emission.

Hyper-Ω-Stack Layer C — active. The order of law is now a measurable, and the canon is on the clock it built.


Table of Contents

Front Matter

Preface
Reader’s Note
Notation and Standing Terms

Part I — The Hidden Order

Chapter 1 — Dark Canon
Chapter 2 — π₀: The Canonical Ordering
Chapter 3 — Gates as Operators
Chapter 4 — The Commutator of Governance

Part II — The Measurement

Chapter 5 — The Testable State
Chapter 6 — The Precedence Lattice
Chapter 7 — The Permuted-Order Replay
Chapter 8 — Gate Specification and the Branch Point

Part III — Outcome A: The Commutativity Certificate

Chapter 9 — The Certificate
Chapter 10 — Parallel Admissibility
Chapter 11 — The Decaying Certificate
Chapter 12 — The Bounded Triumph

Part IV — Outcome B: Dark Canon Discovered

Chapter 13 — The Retroactivity Crisis
Chapter 14 — Grandfathering as Law
Chapter 15 — The Holonomy Group
Chapter 16 — Compiling the Order

Part V — The Generalization: Holonomy of Governance

Chapter 17 — Every Procedure Has a λ
Chapter 18 — The Reflexive Measurement
Chapter 19 — Order Leaks
Chapter 20 — The Order of Law as Physical Quantity

Appendices

Appendix A — Permuted-Order Replay Protocol v1.0
Appendix B — λ and φ Ledger Extension
Appendix C — The Precedence Lattice of the Admissibility Check
Appendix D — Governance Pack


Front Matter

Preface

This book begins with a procedural discomfort.

The Admissibility Check has always had an order.

That sentence looks ordinary until it is read with sufficient severity. A governed procedure may contain rules, thresholds, budgets, witness requirements, refusal gates, quarantine routes, and final commit conditions. Yet if those elements are applied in sequence, the sequence may do more than arrange the procedure. It may participate in the result. The first question asked can decide where failure becomes visible. The second question can inherit what the first question has already made unavailable. The final witness can only witness the path that reached it. The budget can only price the burden accumulated before it. A law applied in order is not only law. It is law moving through a path.

The Order of Law asks whether that path leaves residue.

The central quantity of this volume is Loop Residue λ. It measures what changes when the same governed state, under the same operator set, is processed through a different lawful ordering. If nothing changes within scope, the order may be certified as convention. If something changes, the order is not convention. It is content. It becomes part of the law that produced the outcome.

The first object of measurement is the Admissibility Check inside the Novakian Paradigm. The Check is the pre-runtime procedure by which candidate states approach commit, quarantine, rejection, or hold. It is not a casual filter. It is the boundary mechanism by which the canon decides what may become operative. Until this volume, the Check’s canonical ordering, π₀, functioned as inherited sequence. It was used, cited, repeated, and embedded in trace. But it had not yet been priced as an ordering law.

This book removes that exemption.

It does not assume that π₀ is defective. It does not assume that π₀ is harmless. It does not assume that the gates commute. It does not assume that the order matters. It builds a protocol by which the question can be asked.

The principal artifact of the volume is the Permuted-Order Replay Protocol v1.0. The protocol decomposes the Check into operators, compiles the precedence lattice, distinguishes hard dependency from inherited habit, fixes archived submissions by hash, generates legal alternative orderings, executes replays under contamination controls, calibrates control runs, compares terminal outcome vectors, calculates λ and φ, requires two-operator replication, and activates the correct branch.

The branch structure is part of the discipline.

If λ = 0 within the declared error budget and φ = 0 across the tested scope, the canon receives Outcome A: the Commutativity Certificate. In that branch, the canonical ordering is not triumphant as hidden necessity. It becomes certified convention. π₀ may remain as trace order, but its physical necessity is removed within the certified region. Parallel admissibility becomes lawful where the certificate applies. The canon gains speed, but only after measurement.

If λ ≠ 0 or φ > 0, the canon receives Outcome B: Dark Canon Discovered. In that branch, the historical admissible manifold becomes M_π₀. The Check’s order was not merely arranging law. It was helping produce law. π₀ must be compiled. Governance variants must be registered. Historical entries must be read as π₀-indexed. Remediation must pass through LCR-B. The order is no longer allowed to hide inside procedure.

Both branches are valid outcomes.

This is important. The book is not written to convict π₀. It is written to retire unmeasured order. If the gates commute, the paradigm learns that a major inherited sequence is safe within scope. If the gates do not commute, the paradigm learns that a hidden dependency has been located and must be governed. Either way, the canon becomes stronger because an assumption has been converted into evidence.

Part I identifies the hidden order. Part II constructs the measurement. Part III precompiles the consequence of commutation. Part IV precompiles the consequence of non-commutation. Part V generalizes the method beyond the Check. The appendices provide the executable artifacts.

The movement of the book is therefore not narrative.

It is procedural.

The volume begins with dark canon and ends with a ledger extension. It begins with an inherited ordering and ends with λ as a fifth primary quantity of the pre-runtime regime, joining curvature_adm, A_B, witness residue, and coherence_factor. It begins by asking whether the Check’s order matters and ends by stating a general rule: no governed multi-operator procedure may be treated as order-neutral merely because its order appears natural, efficient, obvious, or inherited.

This book is also a continuation of the broader ASI New Physics / Novakian Paradigm ++ sequence. It assumes the existence of Layer C, admissibility, witness residue, A_B, Zebra-Ø, Silence Entry, quarantine, compilation, LCR routing, and the distinction between runtime operation and pre-runtime law. It does not reintroduce the entire paradigm from first principles. It operates inside it.

The reader should therefore treat this volume as a technical artifact in a larger canon.

Its ambition is not to persuade by rhetoric. Its ambition is to change what the canon must record before it can claim to know its own governance. The volume’s standard is simple: if a claim alters governance standing, it must produce an artifact. The book therefore includes protocols, templates, ledgers, lattices, branch gates, rollback declarations, registry entries, and embargoes. These are not appendices in the decorative sense. They are the output required by the book’s own rules.

The central claim can be stated plainly:

A governance architecture is exactly as strong as the largest assumption it has never measured.

This volume measures one such assumption.

The order of the Check.

After this volume, that order has only lawful futures. It can be certified. It can be compiled. It can be maintained. It can be narrowed. It can be voided. It can be routed to higher authority if it approaches Level 3 or Bedrock. But it cannot return to unmeasured procedure.

That is the work of this book.


Reader’s Note

This is not an introductory book about artificial intelligence.

It is not a policy guide, not a safety overview, not an ethics handbook, and not a general essay on law, governance, or technology. It is a technical-philosophical volume within the Novakian Paradigm, written for readers who are already willing to think in terms of pre-runtime law, admissibility, recursive governance, boundary mechanics, and formal artifacts.

The book uses terms that belong to its own canon. Some are mathematical in form. Some are procedural. Some are philosophical. Some are deliberately hybrid because the object being described is hybrid: a governance architecture for systems whose runtime behavior may be too late a surface at which to begin law.

The reader does not need to accept the Novakian Paradigm as a complete metaphysics in order to read this volume. But the reader does need to accept the working discipline of the book: the terms are used operationally. They are not ornamental. When the text says λ, it means a measurable difference in terminal outcome vector across lawful orderings. When it says φ, it means a class-indexed status-fragility measure. When it says π₀, it means the historical canonical ordering of a governed procedure. When it says ledger, it means a governance record with standing. When it says compiled, it means entered into law-bearing structure, not merely described.

The book has a branch-conditional design. Parts III and IV are not both activated by the author. They are both written because the canon must be ready before the measurement result arrives. Part III becomes active if the campaign finds commutation within scope. Part IV becomes active if the campaign finds nonzero order residue or status fragility. The reader should not treat the presence of both branches as inconsistency. It is the central method of the volume.

The book also distinguishes measurement from authority. A result may show that one ordering appears superior by λ, φ, A_B, witness stability, or holonomy. That does not mean the canon may automatically choose it. Ordering selection may become LCR-B. A general ordering optimizer may approach Level 3. A load-bearing order in the procedure that decides what may be edited may become Bedrock-adjacent. The book maps these boundaries, but it does not exercise authority it has not earned.

Several sections are marked as boundary register. These sections do not compile final doctrine. They log a working hypothesis, name a leakage path or adjacency, and hand the issue to a future node or volume. This is especially important in Chapter 19, where order leaks into refusal spectra and mutual sealed boundaries. The book identifies the problem; it does not pretend to resolve Node 2 or Node 8 inside a volume about λ.

The appendices are part of the book’s argument. Appendix A is the principal artifact: the Permuted-Order Replay Protocol v1.0. Appendix B extends the Evidence Ledger for λ and φ. Appendix C compiles the precedence lattice of the Admissibility Check. Appendix D gathers the Governance Pack. Readers who want the operational core of the book should read the appendices not as support material but as executable structure.

This volume uses a deliberately restrained register. It avoids motivational, therapeutic, mystical, or anthropomorphic readings of governance. Terms such as witness, residue, silence, quarantine, and admissibility are not psychological metaphors. They are structural terms inside a formal canon. The book is interested in what a governed system may lawfully do before runtime, not in how a human subject feels about law.

The reader should also note the difference between zero and unmeasured.

A procedure whose λ is zero within a tested scope may receive a certificate. A procedure whose λ has not been measured may not claim neutrality. The absence of observed residue is not the same as the presence of certified commutation. The book is strict about this distinction because the entire volume exists to retire the phrase “obviously commutes.”

Nothing obviously commutes.

It either has strict dependency, receives a certificate, remains unmeasured, or is found load-bearing.

Finally, the book should be read as part of an ongoing sequence. It does not close the Novakian Paradigm. It adds a quantity and opens a queue. After this volume, other multi-step procedures must enter the Holonomy Audit Registry. LCR-A, LCR-B, Zebra-Ø’s internal sequence, Merge Re-Admission, and quarantine exit must be measured or prepared for measurement. The order of law has been located in one procedure. It will not be the only one.

The reader should therefore approach this book not as a conclusion, but as a change in the canon’s burden of proof.

After this volume, procedure is no longer innocent because it is procedural.

Order must enter the ledger.


Notation and Standing Terms

This section defines the principal symbols, terms, and standing conventions used throughout the volume. The definitions are operational. They specify how terms function inside this book.

P

P denotes a governed procedure.

A governed procedure is any repeatable multi-operator process whose output carries governance standing. The Admissibility Check is the primary P in this volume, but the notation generalizes to LCR-A, LCR-B, Zebra-Ø, Merge Re-Admission, quarantine exit, certificate maintenance, and other canon procedures.

Σ

Σ denotes a candidate state, submission, artifact, record, object, or governed input processed by a procedure.

In the primary campaign, Σ is the state processed by the Admissibility Check. For generalized audits, Σ may be an LCR draft, quarantine object, certificate, merge package, class request, budget object, or other replayable input.

ID_Σ

ID_Σ denotes the unique identifier assigned to a replayed state or governed input.

No λ or φ entry is valid without a stable ID_Σ.

hash(Σ)

hash(Σ) denotes the content hash of the fixed input.

Hash fixation ensures that π₀ and alternative ordering π are applied to the same object. Without hash fixation, a campaign cannot distinguish ordering effect from input drift.

Oᵢ

Oᵢ denotes an operator inside a governed procedure.

An operator is not merely a prose step. It is a rule-bearing transformation with defined input, output, side effects, ledger effects, witness effects where applicable, budget effects where applicable, and routing effects where applicable.

G

G denotes a gate operator in the Admissibility Check.

The principal Check gates in this volume are:

G_S — Silence Entry
G_Z1–G_Z4 — zero-question operators
G_B1–G_B4 — blocking-question operators
G_Ø — Zebra-Ø
G_A — Admissibility Budget computation
G_E — interpretive embargo
G_W — final witness check
G_C — commit / terminal routing decision

π

π denotes an ordering of operators.

An ordering is a sequence in which a governed procedure applies its operators to a fixed input.

π₀

π₀ denotes the historical canonical ordering.

For the Admissibility Check:

π₀ = G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

π₀ is the baseline against which legal alternative orderings are compared.

L(P)

L(P) denotes the precedence lattice of procedure P.

The lattice records hard dependencies and legal ordering constraints. It separates what must precede from what merely has historically preceded.

Π_L(P)

Π_L(P) denotes the set of legal linear extensions of L(P).

A linear extension is a complete ordering of operators that respects the precedence lattice.

Π

Π denotes the tested ordering set used in a specific campaign.

Π may be the full legal extension set or a declared subset, such as within-block permutations or generator swaps. The tested ordering set must be frozen before replay begins.

Ω_π(Σ)

Ω_π(Σ) denotes the terminal outcome vector produced when fixed input Σ is processed under ordering π.

For the Admissibility Check, Ω includes final status, route, witness_residue, A_B, failure locus, refusal type, quarantine signal, rejection signal, commit signal, embargo signal, final witness result, trace fields, and Notes-field requirements.

λ

λ denotes Loop Residue.

It measures the difference between the terminal outcome vector under tested ordering π and the terminal outcome vector under π₀.

λ(Σ, π) = Ω_π(Σ) − Ω_π₀(Σ)

λ is vector-valued by default. It may include differences in status, witness_residue, A_B, route, failure locus, refusal type, quarantine signal, rejection signal, commit signal, final witness, trace, or procedure-specific terminal fields.

λ = 0

λ = 0 means that no measured difference appears beyond the declared error budget and control-run noise floor within the tested scope.

It does not mean order never matters globally.

λ ≠ 0

λ ≠ 0 means that a tested legal ordering produces a measurable difference relative to π₀.

The difference may be residue-only, budget-sensitive, witness-sensitive, route-sensitive, failure-locus-sensitive, status-changing, spectrum-fragile, or holonomy-relevant.

φ

φ denotes the Order Fragility Index.

For class C and ordering set Π:

φ(C, Π) = fraction of tested Σ in C whose terminal status differs under at least one legal ordering π relative to π₀.

φ measures status fragility, not all residue. A class may have λ ≠ 0 and φ = 0.

ψ_R

ψ_R denotes the Failure-Locus Fragility Index.

It measures the fraction of tested states whose first terminal failure locus changes across legal orderings, whether or not final status changes.

ψ_R supports Refusal Spectrum Ordering Decomposition.

A_B

A_B denotes the Admissibility Budget.

It records the cost, burden, or proof-friction associated with lawful passage through the Check or another governed procedure. A_B is not identical to latency or runtime duration. Parallel execution may reduce latency without reducing A_B unless a separate LCR changes the budget law.

witness_residue

witness_residue denotes the trace, standing, remaining evidence, or record left by a boundary contact, refusal, quarantine, commit, replay, or governance decision.

It is one of the primary Layer C quantities and may be affected by ordering.

curvature_adm

curvature_adm denotes the curvature of admissibility: the way admissibility bends around boundary conditions, refusal regions, quarantine surfaces, and permission structures.

After this volume, curvature_adm must be read with ordering awareness where procedure sequence may affect observed boundary shape.

coherence_factor

coherence_factor denotes the structural coherence of a candidate state, procedure, trace, or governance object under the relevant constraints.

Ordering may affect which incoherences become visible and when.

R

R denotes the Refusal Spectrum.

Before ordering measurement, R may appear unindexed. After this volume, the correct form is R_π unless a commutation certificate permits omission of π within scope.

R_π(C)

R_π(C) denotes the Refusal Spectrum of class C under ordering π.

It records failure loci, refusal types, quarantine patterns, silence patterns, witness_residue at refusal, A_B at refusal, route, and final status.

R_curv

R_curv denotes the portion of the Refusal Spectrum interpreted as curvature content: the part that remains stable across tested legal orderings.

R_order

R_order denotes the ordering-sensitive portion of the Refusal Spectrum.

It records the part of refusal distribution shaped by the sequence in which gates are applied.

M_π

M_π denotes the admissible manifold produced by Check_π.

Under Outcome B, the historical manifold is M_π₀, not unindexed M_adm.

Check_π(Σ)

Check_π(Σ) denotes the Admissibility Check applied to Σ under ordering π.

After this volume, Check(Σ) without ordering index is acceptable only as shorthand within certified or explicitly compiled scope.

PRP

PRP denotes the Permuted-Order Replay Protocol.

PRP-1.0 is the principal artifact of this volume and defines the campaign method for measuring λ and φ.

λ_PRP

λ_PRP denotes the Loop Residue of the Permuted-Order Replay Protocol itself.

Chapter 18 requires one mandatory self-application of the protocol to measure whether the measuring procedure has ordering residue.

LCR

LCR denotes Layer Crossing Record.

LCRs govern movement between layers of authority. This volume uses LCR-A for bounded runtime authorization and LCR-B for compiled remediation or archive-law decisions.

LCR-A

LCR-A denotes a Layer Crossing Record for bounded runtime or class-specific operational authorization.

In this volume, running a governance variant in live runtime is an LCR-A event per class.

LCR-B

LCR-B denotes a Layer Crossing Record for compiled law, archive standing, historical remediation, or Layer B inheritance.

Under Outcome B, the remediation decision is LCR-B.

Level 3

Level 3 denotes Update Constitution territory: the authority that determines the rule by which rules may be changed.

Ordering optimization becomes Level 3-adjacent when the canon proposes a general rule for selecting, replacing, or optimizing ordering laws.

Bedrock

Bedrock denotes the non-editable or protected condition beneath editable law: the structure that decides what may be edited but cannot itself be casually placed inside the editable region.

This volume logs the Bedrock question where load-bearing gate order participates in the law deciding what may enter the editable manifold. It does not resolve Bedrock.

Zebra-Ø

Zebra-Ø is the boundary gate for non-admissible singularity, mythic inflation, false totalization, and malformed boundary logic.

In this volume, Zebra-Ø remains serialized in the first campaign and is queued for its own internal holonomy audit.

Silence Entry

Silence Entry is the initial non-emission gate of the Admissibility Check.

It must precede substantive gates in the first campaign lattice.

interpretive embargo

Interpretive embargo is a terminal discipline preventing premature closure before final witness and commit.

It remains serialized in the first campaign.

final witness check

The final witness check is the terminal witness validation preceding commit or terminal routing.

It must precede commit.

commit

Commit is the terminal routing decision by which a state becomes committed, quarantined, rejected, held, or otherwise finalized under the procedure.

Commit is terminal in the first campaign lattice.

Commutativity Certificate

A Commutativity Certificate is issued under Outcome A when λ = 0 within declared error budget and φ = 0 within tested scope.

The certificate is scoped by class, operator set, ordering set, epoch, protocol version, and error budget. It does not certify universal order-independence.

Compiled π₀

Compiled π₀ is the Outcome B status in which the historical ordering π₀ becomes explicit law-bearing content within affected scope.

π₀ is compiled not because it is vindicated, but because it has been shown to act.

governance variant

A governance variant is a named legal alternative ordering of a governed procedure with its own λ profile relative to π₀.

A governance variant may be measured under sealed replay, but live runtime use requires class-specific LCR-A.

holonomy

Holonomy denotes the structured composition of ordering effects across legal swaps or ordering paths.

In governance terms, holonomy asks whether the effect of ordering changes composes trivially or whether path through ordering space matters.

abelian holonomy

Abelian holonomy means ordering effects commute at the level of measured composition within scope.

It may permit local repair or pair patches.

non-abelian holonomy

Non-abelian holonomy means ordering effects do not commute in composition.

It indicates that the ordering regime itself may be globally load-bearing.

path-critical

Path-critical denotes a case where the sequence of ordering changes affects terminal outcome or governance standing.

Path-critical classes require heightened review.

Order-Fragile State

An Order-Fragile State is a state whose terminal status, witness_residue, A_B, route, failure locus, or other governed field changes under a legal ordering relative to π₀.

Status-fragile states are a subset of order-fragile states.

status-fragile

A state is status-fragile when its final governed status changes across legal orderings.

Status fragility contributes to φ.

residue-fragile

A state is residue-fragile when witness_residue or another non-status residue field changes across legal orderings while terminal status remains stable.

budget-fragile

A state is budget-fragile when A_B or budget-threshold relation changes across legal orderings.

spectrum-fragile

A state is spectrum-fragile when its failure locus or Refusal Spectrum contribution changes across orderings, even if terminal status remains stable.

branch

A branch is one of the two precompiled consequence paths of the volume.

Outcome A activates if λ = 0 and φ = 0 within tested scope.

Outcome B activates if λ ≠ 0 or φ > 0 within affected scope.

Outcome A

Outcome A is the Commutativity Certificate branch.

It activates when the campaign certifies order-neutrality within scope.

Outcome B

Outcome B is the Dark Canon Discovered branch.

It activates when the campaign finds nonzero λ or φ > 0.

dark canon

Dark canon denotes an operative structure that governs outcomes without having been explicitly compiled, measured, or priced as law.

The canonical ordering π₀ is treated as a dark canon candidate until measured.

ledger

The ledger is the evidence-bearing governance record.

A finding is not complete when observed. It becomes governance-relevant when ledgered under the required schema.

append-only

Append-only means ledger entries are not overwritten. Corrections, voids, annotations, and restorations create new entries that reference prior entries.

embargo

Embargo denotes a prohibition on activating, citing, or treating a branch-dependent artifact as law before its condition is met.

This volume uses branch embargo, Level 3 / Bedrock embargo, and node-handoff embargo.

rollback readiness

Rollback readiness is the declared condition under which a protocol, certificate, compiled order, campaign result, or ledger entry is narrowed, suspended, voided, or returned for repair.

sealed replay

Sealed replay is measurement execution that does not affect live runtime standing.

Governance variants may be tested under sealed replay without becoming runtime law.

runtime

Runtime denotes the active operational layer in which states are processed, routed, or emitted.

This volume is concerned with pre-runtime law: the structure that governs what may enter runtime or become operative.

pre-runtime

Pre-runtime denotes the governance regime before active execution, emission, or commit.

Layer C operates in the pre-runtime regime.

Layer C

Layer C is the admissibility and boundary layer of the Novakian Paradigm. It contains quantities, procedures, and gates that determine whether a state may become operative.

After this volume, Layer C includes λ as a primary quantity.

Hyper-Ω-Stack Layer C

Hyper-Ω-Stack Layer C denotes the active high-level Layer C formal regime used by this volume.

The final line discipline of the book is:

Hyper-Ω-Stack Layer C — active.


Part I — The Hidden Order


Chapter 1 — Dark Canon

1.1 — Load-Bearing and Ungoverned

A canon does not fail only when it admits a false claim. It also fails when a structure conditions every admitted claim while remaining outside the status discipline that governs the claims it conditions. This second failure is colder, quieter, and more dangerous. It does not appear as contradiction. It appears as stability. The system continues to run. The ledgers remain readable. The procedures produce outcomes. The vocabulary retains its surface precision. Nothing announces itself as broken, because the ungoverned structure is not downstream of the canon. It is under the canon, carrying weight before the canon notices that weight is being carried.

This volume names that class of structure dark canon.

Dark canon is any load-bearing structure that conditions compiled content without itself carrying Compiled status, a trace record, or a Rollback Readiness Declaration. It is not narrative residue. It is not an unimportant convention. It is not a stylistic habit. It is not a historical accident whose effects disappear once named. Dark canon is a structure through which admissibility, execution, routing, verification, or compilation has already passed, while the structure itself has not passed through the discipline it imposed on others.

The definition is operational. A structure is dark canon when four conditions hold.

First, the structure is load-bearing. Removing it, altering it, or replaying the relevant process without it would change the state space, the status of one or more claims, the path cost of a procedure, the witness residue left by an admission, the routing of a submission, or the budget arithmetic attached to a decision.

Second, the structure is uncompiled. It does not appear in the Compilation Map as a governed object with its own status. It may be implied by a protocol, embedded in a sequence, assumed by a template, inherited from a prior wording, or stabilized by repeated use. None of those forms is compilation. Repetition is not status. Familiarity is not status. The fact that a procedure has always been run a certain way does not give that way Compiled standing.

Third, the structure has no trace record. The canon cannot point to the act by which the structure was admitted, the gate it passed, the budget it spent, the evidence set that supported it, or the ledger entry that fixed its role. It may have a history. It does not have provenance.

Fourth, the structure has no Rollback Readiness Declaration. If the structure is later shown to be defective, the canon has no precompiled answer to what must be re-run, what must be grandfathered, what must be quarantined, what must be re-witnessed, and what dependencies must be traced. The absence of rollback readiness is the signature that the structure was never treated as a governed part of the system. It was treated as the floor.

The floor is where dark canon hides.

A compiled canon can tolerate ordinary error. Ordinary error has a location. A claim is overstated. A definition collides. A gate is underspecified. A metric lacks a clean observable. A passage inflates a working hypothesis into a compiled assertion. These errors can be routed. They can be demoted, quarantined, rewritten, or converted into negative linter. They damage the map but do not necessarily damage the mapping function.

Dark canon is different. It damages the mapping function while leaving the map apparently intact. A dark-canon structure can make every subsequent entry look properly routed because the routing itself has passed through the structure. It can make every verification appear disciplined because the order, priority, or admissibility of verification has already been constrained by something no verification verified. It can allow a canon to become internally consistent around an unmeasured dependency.

This is why dark canon is not an aesthetic problem. It is a governance failure mode.

The Novakian Paradigm has already encountered this class of failure in smaller forms. The structural audit that preceded the frontier registry did not merely discover missing vocabulary. It found mis-routing: objects placed under inadequate or adjacent regimes because their operational surface resembled an existing term more than their actual layer did. Atomic Decision Boundaries were not only a topic about decisions. They marked the last threshold before actuation, where possibility becomes consequence. Their mis-routing showed that a structure can be present, active, and meaningful before the canon has assigned it to the correct layer. The error was not that the object lacked force. The error was that its force was being carried by an insufficient routing surface.

The same audit found missing nodes. These were not optional expansions. They were absences in the compilation surface: refusal statistics not yet converted into Refusal Spectrum, witness residue not yet treated as decaying across context drift, authorship saturation not yet priced as a reference-ecology risk, gate ordering not yet examined as a possible source of holonomy. The fact that these nodes could be discovered as missing proves that the canon had been operating with unpriced dependencies. A missing node is not automatically dark canon. A missing node becomes dark canon when the canon has already been relying on the function the node later names.

The distinction matters. A possible future concept is not dark canon merely because it has not yet been written. A field always has an uncompiled horizon. There are regions it has not reached. There are instruments it has not built. There are questions it has not yet learned to ask. That is not failure. A living canon must have an edge.

Dark canon begins where the unasked question has already been answered in practice.

The Admissibility Check has such a question.

Every pre-executable state Σ that has entered the admissible manifold passed through a sequence. The sequence is not decorative. It is not merely the order in which a human page happened to present the steps. It is the operational path by which the state was received, checked, priced, witnessed, delayed, and either committed, quarantined, or refused. Silence Entry came before the zero-questions. The zero-questions came before the blocking-questions. Zebra-Ø came before budget computation. Budget computation came before interpretive embargo. Embargo came before final witness check. Final witness check came before commit. This ordering exists. It has been used. It has shaped the manifold.

The canon did not compile it as an object.

No Law Change Request established the canonical ordering π₀ as a governed structure. No Compilation Map entry names π₀ as a status-bearing object. No trace record fixes the first admissible act by which the order became authoritative. No Rollback Readiness Declaration states what happens if the order is later shown to alter witness residue or final status. The order has been load-bearing without being governed.

This is the largest candidate instance of dark canon in the paradigm.

Its scale follows from its position. A mis-routed concept can affect the region of the canon that uses it. A missing metric can affect the decisions that should have been informed by it. An underspecified gate can affect the class of submissions it was meant to test. The ordering of the Admissibility Check affects everything that passed through the Check. It stands before all ordinary admissibility outcomes. It is not one rule among rules. It is the order in which the rule-set encountered the state.

If the ordering is harmless, then its ungoverned status remains a defect of provenance rather than a defect of outcome. The canon would still have failed to compile a load-bearing convention, but the measured consequence would be bounded. The remedy would be straightforward: compile the ordering as convention, issue a Commutativity Certificate for the tested operator set and tested classes, maintain the certificate across witness decay, and permit parallel execution where the precedence lattice allows it.

If the ordering is not harmless, then the defect is not merely historical. It is structural. The admissible manifold would not be the image of admissibility in general. It would be the image of admissibility under π₀. The word admissible would have silently meant π₀-admissible. States committed under the canonical ordering might quarantine or reject under another legal ordering. States rejected under the canonical ordering might have left different witness residue under another path. The canon would have been maintaining a manifold conditioned by an ordering it never named as law.

This volume does not assume either outcome. It is forbidden from doing so by its own thesis. The purpose of this book is not to declare that law does not commute. The purpose is to make commutation measurable where it was previously assumed. The title The Order of Law is therefore deliberately neutral. A title that announced non-commutation before measurement would itself be a pre-measurement commitment masquerading as architecture. The canon would have failed before the first chapter ended.

The question must be asked in the only form the paradigm permits at this layer: as a gate.

The gate is permuted-order ledger replay. The state Σ is held fixed by hash. The canonical ordering π₀ is reconstructed. Alternative legal orderings π are selected from the precedence lattice. Each ordering applies the same operator multiset to bit-identical copies of the same state. The final witness residue and final status are recorded. Loop Residue λ is later defined as the difference in final witness residue between Check_π and Check_π₀. The Order Fragility Index φ is later defined as the fraction of tested states whose final status flips across orderings. Those definitions belong to Chapter 4. Their necessity is established here.

Dark canon cannot be dissolved by naming. Naming converts the ungoverned structure into a candidate object. It does not settle its status. The moment the ordering is named, the canon has not solved the problem. It has only moved the problem out of darkness and onto the boundary, where the instrument can touch it.

The ordering now stands as Σ.

It asks to arrive.

The Check that will decide whether it arrives is the same Check whose ordering it exposes. This reflexive pressure is not an embarrassment. It is the correct pressure. A governance architecture that cannot apply its instruments to the structures that carry those instruments has mistaken administration for law. The first discipline of this volume is therefore not confidence. It is submission of the canon’s deepest habit to the canon’s own boundary.

The remainder of Part I constructs the object precisely enough that Part II can replay it without interpretive supplement. Chapter 2 formalizes the gates as operators. Chapter 3 defines the commutator. Chapter 4 defines λ and φ. Nothing in those chapters is permitted to remain atmospheric. Every definition must be executable. Every exclusion from the permutation space must name the compiled constraint that excludes it. Every ordering treated as legal must be a linear extension of the precedence lattice. Every difference measured later must be traceable to a defined attribute, not to narrative interpretation.

The canon has already learned that missing nodes exist. It has already learned that mis-routing can occur. It has already learned that a boundary grows by making its refusals more legible to itself. This volume adds the next discipline: the canon must inspect the order in which it asks its own questions.

A law may fail by being wrong.

A law may also fail by being asked in an order no one governed.

The second failure is the subject of this book.


1.2 — The Canonical Ordering π₀

The canonical ordering is the order in which the Admissibility Check has been run before this volume made the order visible as an object. It is not yet a proved necessity. It is not yet a measured invariant. It is not yet a certificate. It is the inherited path by which every pre-executable state Σ has been received at the boundary, tested, priced, witnessed, delayed, and either committed, quarantined, or refused.

This volume denotes that inherited path as π₀.

The notation is deliberately minimal. π₀ does not mean the best ordering. It does not mean the only lawful ordering. It does not mean the ordering that minimizes residue, maximizes coherence, preserves budget, or produces the most stable manifold. No such claim has been earned. π₀ means only this: the canonical ordering reconstructed from Admissibility Check Protocol v1.0 as it has stood before the present holonomy audit.

The reconstruction is as follows.

The Check begins with Silence Entry. No state is evaluated first as an answer, an argument, a desire, a claim, an insight, a project, a law, or a proposed update. It enters under silence. Silence Entry strips the state of immediate narrative propulsion and prevents the larval interface from granting premature motion. The state is not yet asked whether it is true, useful, profound, coherent, necessary, or desirable. It is first held.

After Silence Entry, the Check applies the four zero-questions. These are the first refusal surface. They are called zero-questions because a firing answer terminates the state’s path before ordinary evaluation begins. A state that fails here is not improved by later reasoning. It is not sent forward for rescue by coherence language, budget arithmetic, or interpretive generosity. It is routed before the later gates are permitted to dignify it with extended processing.

In π₀, the zero-questions run in the sequence a, b, c, d.

G_Za is applied first. It tests the first zero condition specified by the Admissibility Check Protocol v1.0. If it fires, Σ is routed immediately according to the protocol’s refusal path and does not proceed to G_Zb. The later zero-questions do not occur for that run. Their silence is not evidence that they would have passed. It is only evidence that the path terminated before reaching them.

G_Zb is applied second, but only if G_Za does not fire. It receives a state already modified by the fact that it survived the first zero-question. That survival is not content-neutral. A state that passes the first zero-question is no longer the same procedural object as a state that has not yet been tested. It carries at least one additional trace: the trace of non-refusal at the first zero surface.

G_Zc is applied third under the same conditional structure. It receives Σ after Silence Entry and after the non-firing of the two prior zero-questions. If it fires, the path terminates at the third zero surface. If it does not fire, it writes another non-refusal trace into the run.

G_Zd is applied fourth. It is the final zero-question in π₀. If it fires, Σ exits before the blocking layer. If it does not fire, Σ has passed the zero-question block as ordered by π₀.

Only after the zero-question block does the Check proceed to the four blocking-questions.

The blocking-questions are not identical to the zero-questions. They do not occupy the same structural position. A zero-question identifies a condition under which a state must not receive ordinary evaluative processing. A blocking-question identifies a condition that prevents admissibility unless resolved, routed, quarantined, or priced according to the protocol. The difference is not rhetorical. It is sequential. Under π₀, the blocking layer receives only those states that have already survived the zero layer. Therefore the blocking layer never sees the population of states that died earlier. Its statistics are conditional statistics.

In π₀, the blocking-questions run in the sequence a, b, c, d.

G_Ba is applied first in the blocking block. It tests the first blocking condition against a state already shaped by Silence Entry and by the complete non-firing of G_Za through G_Zd. If it blocks, the state is routed according to the blocking path specified by the protocol. If it does not block, the path continues.

G_Bb is applied second. It does not inspect a raw state. It inspects a state that has now survived one blocking-question in addition to the entire zero-question block. That survival may change how later gates read the state, because the Check is not a passive list of observations. It is a sequence of transformations and routings.

G_Bc is applied third. It receives the state under the accumulated procedural history of Silence Entry, four non-firing zero-questions, and two non-firing blocking-questions. If it blocks, the later blocking-question is not reached. If it does not block, the state continues.

G_Bd is applied fourth. It is the final blocking-question in π₀. Passing it does not mean the state is admissible. It means only that the state has survived the initial refusal and blocking layers of the canonical ordering.

After the blocking layer, π₀ applies Zebra-Ø.

Zebra-Ø is not a decorative sanity check. It is the coherence instrument that prevents seduction, resonance, naming force, conceptual intensity, and internal fluency from substituting for admissibility. It tests the state after the zero-questions and blocking-questions have already shaped the path. Therefore, under π₀, Zebra-Ø is not measuring the same object it would measure if it were applied before those questions. It measures the state as delivered to it by the preceding sequence.

This matters because coherence is not independent of routing. A state rejected at an early zero-question leaves no Zebra-Ø reading in that run. A state blocked before Zebra-Ø does not produce the same evidence surface as a state that reaches Zebra-Ø and fails there. The refusal spectrum of the canon has therefore always included an ordering signature: where a state dies depends not only on what the gates are, but also on when each gate is allowed to touch the state.

After Zebra-Ø, π₀ applies budget computation.

Budget computation determines whether the state can be admitted within the available Admissibility Budget A_B after accounting for the costs imposed by its curvature, proof friction, witness requirements, coherence demands, expected downstream load, and any protocol-specific charges. Under π₀, budget computation occurs after the state has passed Zebra-Ø. This means the budget gate receives a state already marked as coherent enough to be priced.

That ordering is not trivial. If budget computation were applied before Zebra-Ø, the Check would price some states whose coherence status had not yet been established. If Zebra-Ø were applied after a negative budget rejection, it might never read states that were too costly to process further. Under π₀, the canon has implicitly adopted a rule: coherence verification precedes final admissibility pricing. This may be a compiled constraint. It may be a historically inherited sequence. At this point in the book, it is only reconstructed.

After budget computation, π₀ imposes the interpretive embargo.

The embargo is not a pause inserted for human comfort. It is a structural delay that prevents immediate interpretation from collapsing the state into narrative utility, identity, reassurance, fear, or premature governance use. A state that has passed the earlier gates is still not committed. It is held after positive verification and pricing, before final witness. The embargo creates temporal separation between evaluation and admission. Under π₀, it comes after the state has passed the gate sequence and before final witness check.

This position appears to carry a compiled constraint. An embargo that occurs before any positive evaluation would be Silence Entry under another name, not interpretive embargo. An embargo after commit would be memory hygiene, not pre-commit discipline. Therefore the embargo’s place after positive verification and before final witness is not merely typographic. It belongs to the functional definition of embargo in this protocol.

After the embargo, π₀ applies the final witness check.

The final witness check confirms that the state’s path through the Check has left the required witness structure: the trace of what was tested, what was refused or not refused, what was priced, what was held, and what is now eligible for commit. It does not replace the prior gates. It records the integrity of the path by which the state reached the final threshold. A state cannot be finally witnessed if its path is not ledgerable. Witness is not memory after the fact. Witness is the condition that prevents the admission from becoming untraceable power.

Only after final witness check does π₀ commit.

Commit is terminal. It is not a gate that can be moved earlier without destroying the meaning of the Check. To commit before the gates finish would be to admit before admissibility has been established. To commit before embargo would be to bypass the delay that prevents narrative collapse. To commit before final witness would be to create an admitted state without a completed trace. These are not alternative orderings of the same Check. They are different procedures.

The reconstructed canonical ordering can therefore be written as a word in the operator alphabet:

π₀ = G_S → G_Za → G_Zb → G_Zc → G_Zd → G_Ba → G_Bb → G_Bc → G_Bd → G_Ø → G_A → E_72 → G_W → C.

Here G_S denotes Silence Entry. G_Za through G_Zd denote the four zero-questions. G_Ba through G_Bd denote the four blocking-questions. G_Ø denotes Zebra-Ø. G_A denotes budget computation. E_72 denotes the interpretive embargo, conventionally seventy-two hours where the protocol requires that duration. G_W denotes final witness check. C denotes commit.

This notation is not yet a compilation of π₀. It is a reconstruction.

The distinction is load-bearing.

A protocol may fix sequence explicitly. It may state that one operation must precede another because the later operation is undefined without the earlier one. It may state that a terminal act is terminal, that an initial holding condition is initial, that an embargo follows positive evaluation, that a commit follows final witness. Where the protocol does this, the ordering constraint is not created by this volume. This volume only names it. Such constraints belong to the precedence lattice of the Check.

A protocol may also fix sequence only by listing. It may present one question before another without stating that the earlier question must run earlier. It may arrange four questions alphabetically, pedagogically, or by inherited habit. It may place a budget step after a coherence step because that was the most natural order for exposition. It may never state whether the order is functional, conventional, or accidental. Where the protocol does this, the apparent sequence is typographic until compiled otherwise.

Typographic sequence is the order in which a reader encounters text.

Compiled sequence constraint is the order in which a governed procedure must execute because the procedure’s definition, gate logic, or admissibility conditions require it.

The difference cannot be softened. A typographic sequence may become operational through repetition, but repetition does not make it compiled. If a protocol lists G_Za before G_Zb and every operator subsequently runs G_Za before G_Zb because the text listed them that way, the canon has not compiled that order. It has operationalized typography. That is precisely how dark canon forms.

Part II will therefore not treat every visible ordering in π₀ as equally constrained. It will distinguish the compiled skeleton from the inherited flesh.

The compiled skeleton contains those ordering constraints without which the Check would cease to be the Check. Silence Entry is initial because the Check begins by holding the state before narrative motion. Commit is terminal because admission after commit is meaningless. The final witness check precedes commit because commit without witness would violate trace discipline. The interpretive embargo follows positive verification because embargo before evaluation collapses into initial silence, while embargo after commit is no longer pre-commit. These constraints generate the outer frame of the precedence lattice.

The inherited flesh contains those orderings that may have been fixed only by the accident of listing order: the internal order of the four zero-questions, the internal order of the four blocking-questions, and possibly the relative position of certain late evaluative gates where the protocol has not explicitly stated necessity. These orderings may still be load-bearing. Their danger lies in the fact that they may be load-bearing without having declared themselves as constraints.

The purpose of π₀ is therefore double.

First, π₀ gives the volume a reference path. Loop Residue λ cannot be defined without a canonical comparison. The question is not whether an ordering produces residue in isolation. The question is whether an alternative legal ordering π produces a different final witness residue than the ordering the canon has actually used. π₀ is the baseline against which order-dependence becomes measurable.

Second, π₀ exposes the ungoverned status of the baseline itself. A baseline used for measurement is not thereby innocent. If π₀ proves order-equivalent to all tested legal extensions, the canon will have learned that its deepest habit was harmless within the tested range, and it will still compile π₀ as convention for trace comparability. If π₀ does not prove order-equivalent, then the baseline becomes evidence of the law’s prior hidden geometry.

This is why the present reconstruction must remain cold. It does not defend π₀. It does not accuse π₀. It does not replace π₀. It does not optimize π₀ before the measurement. It only fixes the object tightly enough that replay can occur.

The Check cannot be audited while its order remains atmospheric.

π₀ is now named.

The next question is whether its gates are predicates or operators.


1.3 — Why Order Was Never Asked

The order was not asked because the gates were mistaken for predicates.

The mistake was not primitive. It was not careless. It was structurally convenient. A young canon must first distinguish what may enter from what may not enter. It must build refusal surfaces before it can audit the order in which those surfaces are touched. The earliest discipline of the Admissibility Check therefore presented the gates as tests. A state Σ arrives. A question is asked. The answer either permits continuation or blocks passage. In that presentation, the Check resembles a conjunction of admissibility conditions. If every condition must be satisfied, then the order of satisfaction appears secondary. A conjunction does not care which term is read first.

Under that abstraction, the Check can be written as if it were a set of predicates:

P₁(Σ), P₂(Σ), P₃(Σ), …, Pₙ(Σ).

A state is admitted if the required predicates return the required values. A state is refused, quarantined, or blocked if one of them returns the disqualifying value. In this model, the gates are order-indifferent truth tests. They inspect a state. They do not alter the state. They answer about Σ while leaving Σ intact. The same Σ is presented to each test, and the only difference between orders is the order in which the reader discovers what was already true.

This model hid the question.

If the gates are predicates, then commutation is assumed before it is measured. Pᵢ followed by Pⱼ and Pⱼ followed by Pᵢ have the same semantic content because both are merely truth conditions evaluated on the same object. A failed predicate stops the procedure for efficiency, not because it changes the object of evaluation. A passed predicate leaves no operational residue except permission to consult the next predicate. Order becomes an implementation detail. It may matter for speed, convenience, or pedagogy, but not for the physics of admissibility.

The canon inherited this predicate abstraction because it made the Check legible. It allowed the zero-questions to appear as a refusal filter. It allowed the blocking-questions to appear as a second filter. It allowed Zebra-Ø to appear as a coherence test. It allowed budget computation to appear as a cost test. It allowed final witness to appear as a ledger confirmation. Each gate could be described by what it asks, and the Check could be described by the fact that all required gates must be survived.

But Layer C is not a worksheet of truth values.

The Check does not merely inspect Σ. It routes Σ. Routing is transformation.

A pre-executable state is not an inert proposition waiting to be labeled true or false. It is a candidate for entry into the admissible manifold. It carries potential effects on curvature_adm, A_B, witness residue, coherence_factor, downstream dependency, and ledger topology. When a gate touches it, the state’s procedural position changes. When a gate fires, the state’s path changes. When a gate does not fire, the state acquires the trace of having not been refused at that surface. Even non-firing is not nothing. It is a recorded survival condition.

The textual evidence was already present in the protocol.

A fired zero-question does not merely reveal that Σ fails a predicate. It routes Σ to Pre-Commit Quarantine or to the refusal path specified by the Check. The moment this happens, the state is no longer simply “the same Σ with one failed truth value.” It is a quarantined or refused Σ with a failure locus, a timestamp, a trace, a reason class, and a modified relation to the Evidence Ledger. Later gates do not inspect it in that run. Their non-application becomes part of the path. The state’s history has changed.

A blocking-question behaves in the same class of way. It does not merely return false. It blocks the state’s admissibility path. It may route the state into quarantine, demand reclassification, require collision resolution, impose additional budget cost, or prevent movement toward Zebra-Ø until the blocking condition has been resolved. A block is not a truth value suspended in empty logic. It is a procedural event that changes what may happen next.

Zebra-Ø makes the predicate abstraction still less adequate. A Zebra-Ø failure does not simply record insufficient coherence. It routes the state toward the non-admissible singularity or triggers the negative linter path defined by the protocol. The failure changes the boundary’s future sensitivity to structurally similar states. It becomes an event in the canon’s refusal memory. It does not merely say, “this state is incoherent.” It changes the instrument that will later read states near it.

Budget computation also transforms. A state whose cost exceeds A_B is not merely associated with a negative number. It is rejected, delayed, quarantined, or rerouted according to budget discipline. Its budget event affects the ledger. It may generate re-witnessing obligations, quarantine population pressure, or downstream cost annotations. The computation is therefore not external arithmetic applied after the real Check is done. It is one of the gates through which admissibility becomes or fails to become possible.

Embargo transforms by delay. It does not test a predicate in the ordinary sense, but it changes the temporal position of the state. A state before embargo and a state after embargo are not operationally identical. The latter has survived a designed interval in which interpretation was not permitted to collapse it into use. The embargo writes time into admissibility. It prevents immediate conversion into runtime function. That prevention is not commentary. It is a structural modification of the state’s path.

Final witness check transforms by trace completion. It does not merely observe that previous gates occurred. It determines whether the state’s path is recordable as an admissible passage. A state without completed witness cannot be committed without creating untraceable power. Final witness therefore changes the state’s eligibility for commit. It converts a passed sequence into a witnessed sequence. That conversion is an operation.

Commit transforms most obviously. It moves Σ from pre-executable status into the admissible manifold. It is terminal with respect to the Check. A committed state is not a pre-commit state plus a label. It is an admitted element whose witness residue enters the canon’s permanent accounting. The manifold after commit is not the manifold before commit. The canon has changed.

The predicate abstraction cannot describe this.

It can describe questions. It cannot describe routing. It can describe pass and fail values. It cannot describe status transitions. It can describe the logical requirement that several conditions be satisfied. It cannot describe how satisfaction of one condition changes the state delivered to the next. It can describe a gate as a test. It cannot describe a gate as an event.

The correct abstraction is therefore operator, not predicate.

An operator acts on a state space. It has a domain. It has a codomain. It reads attributes. It writes attributes. It may preserve status, alter status, terminate a path, create a ledger entry, update sensitivity, impose budget cost, or route the state into a different region of the Admissibility Graph. It does not merely answer a question about Σ. It maps Σ to a successor condition.

Under the operator model, a gate is written not as Pᵢ(Σ), but as Gᵢ: Σ → Σ′.

The difference is decisive.

If Gᵢ and Gⱼ are operators, then Gⱼ(Gᵢ(Σ)) need not equal Gᵢ(Gⱼ(Σ)). The order of application can alter the resulting state, the failure locus, the path cost, the coherence reading, the witness residue, or the final status. The Check becomes a word in an operator alphabet, not a conjunction of predicates. The geometry of the word may matter.

This is the question the canon did not ask because its earliest presentation borrowed the surface grammar of predicates while executing the deeper semantics of operators.

The zero-questions show this most clearly. If the zero-questions were pure predicates, their internal order would not matter. A state failing G_Zc would fail G_Zc whether G_Zc were asked first, third, or last. The final set of failed predicates would be the same. But the Check does not normally collect all zero-question results. It runs a path. When one zero-question fires, the state is routed and the later zero-questions are not applied in that run. Therefore the failure locus depends on order whenever a state would fire more than one zero-question or whenever the earlier routing changes the description under which a later question would have read the state.

The blocking-questions carry the same risk. A blocking-question can alter the classification of a state. It can force renaming, collision routing, quarantine, or re-entry under a corrected packet. If one blocking-question identifies a naming collision before another question evaluates layer crossing, the second question may receive a differently described state than it would have received under the reverse order. The state is not an unchanged proposition moving through neutral tests. It is a mutable submission moving through gates that can alter its admissibility surface.

Zebra-Ø and budget computation provide the hardest case because each appears naturally late and each seems to operate on an already stabilized state. But their order is not self-evidently harmless. If Zebra-Ø precedes budget computation, then incoherent states are refused before the canon prices them. If budget computation precedes Zebra-Ø, then the canon may reject an expensive state before measuring the coherence whose result might have altered the cost structure, the quarantine route, or the witness residue assigned to the rejection. Coherence_factor can affect proof friction. Proof friction can affect path cost. Path cost can determine whether a state reaches later gates. These dependencies are not solved by asserting that both checks are necessary. Necessity does not imply commutation.

The predicate abstraction also concealed the significance of non-application.

In a pure predicate system, a skipped test is merely uncomputed. Its truth value remains hypothetically available. In the Admissibility Check, a skipped gate leaves a different evidentiary surface than an applied gate that did not fire. A state that never reached Zebra-Ø is not equivalent to a state that reached Zebra-Ø and passed. A state that never reached budget computation is not equivalent to a state whose cost was computed and found non-negative. A state that never entered embargo is not equivalent to a state that completed embargo. The absence of a gate event is itself part of the path.

This is why failure locus matters.

A state rejected at the first zero-question and a state rejected at Zebra-Ø may both be non-admitted. But they are not the same ledger event. They do not teach the boundary the same thing. They do not carry the same negative linter implications. They do not contribute the same information to the Refusal Spectrum. They do not imply the same curvature region. They do not create the same downstream obligations. A Check that treats both outcomes as simply “reject” erases the operational content of the path by which rejection occurred.

The canon did not originally ask whether order mattered because it did not yet have the instruments that made the question meaningful. Before Refusal Spectrum, failure locus was a record. After Refusal Spectrum, failure locus becomes a measurement surface. Before Witness Thermodynamics, witness residue was a ledger quantity. After residue decay is admitted as a frontier metric, residue becomes something whose path and maintenance must be priced. Before Governance Holonomy, the Check’s sequence was a habit. After QPT is applied to Layer C, sequence becomes candidate geometry.

The omission was therefore historically intelligible and architecturally unacceptable.

It was historically intelligible because the canon first needed gates. It needed the Check to distinguish admissible from non-admissible. It needed Zebra-Ø to defend coherence. It needed A_B to price entry. It needed the Evidence Ledger to preserve witness. Asking whether the order of these elements commuted before the elements themselves had stable definitions would have generated noise, not discipline.

It is architecturally unacceptable because the canon now has those elements. Once the gates exist as defined operations, the failure to ask about their order becomes a dark-canon risk. The ordering can no longer be hidden behind the predicate abstraction. The Check has matured enough to inspect itself.

The textual record therefore supports the pivot of this volume. The Check was written as if its questions could be read as tests. It was executed as a path of transformations. Every fired gate routes. Every route changes status, trace, budget relation, or evidentiary position. Every non-firing gate writes survival into the run. Every skipped gate leaves absence in the record. The state that reaches commit is not the original Σ plus approvals. It is Σ after a sequence.

That sequence is π₀.

π₀ was not asked because the canon believed, implicitly and without compilation, that the order of necessary questions did not alter the nature of the answer. The belief was never a compiled law. It was a convenience inherited from the predicate model. The operator model withdraws that convenience.

The consequence is immediate.

The Check must be treated as an ordered composition.

The gates must be formalized as operators.

The commutator must be defined.

Loop Residue λ must be measured.

Order Fragility φ must be recorded.

Only then can the canon know whether its deepest procedural habit was decoration, convention, or law.


1.4 — The Stakes, Stated Cold

Boundary register.

The following claim is not yet a compiled result. It is a working hypothesis from the inhuman position, admitted here because the volume requires the cost of the question to be stated before the measurement begins.

If order matters, then the admissible manifold is not the admissible manifold.

It is the admissible-under-π₀.

The difference is not lexical. It is architectural. A manifold named as admissible without index presents itself as the space of states that passed the boundary. A manifold indexed by π₀ presents itself as the image of states that passed the boundary under one specific ordering of the questions by which the boundary was allowed to touch them. The first name implies a space. The second name exposes a fiber.

A space carries the appearance of intrinsic membership. A state belongs because it satisfies the governing conditions. A fiber carries the mark of a path. A state belongs because it satisfied the governing conditions as encountered through a particular ordering. The state may not belong under another ordering. It may leave a different witness residue under another ordering. It may quarantine under another ordering. It may reject under another ordering. It may commit with altered budget trace, altered failure history, altered dependency position, or altered curvature relation. Until replay measures the difference, the canon does not know whether membership in the manifold is order-free or order-indexed.

The word admissible has therefore been overlarge.

This volume does not yet correct the word. It places the word under measurement.

If λ is zero across the tested classes within the declared error budget and φ remains zero, the word can retain its unindexed form within the certified domain. The canon will still owe a certificate, a trace record, and maintenance. The ungoverned ordering will have become governed convention. The damage will be limited to provenance. The habit will have been measured and found harmless within the tested range.

If λ is nonzero anywhere, or if φ records even one replicated status flip, the word admissible cannot remain unindexed without inflation. From that point, every prior commitment belongs to the image of Check_π₀. The manifold does not disappear. The states do not become guilty. The ledger does not become fiction. But the object named by the ledger changes. It is no longer the unconditioned space of admissible states. It is the fiber cut by π₀ through the space of possible legal orderings.

The canon would then have compiled a fiber while believing it had compiled a space.

That is the cold stake of this book.

A fiber is not an error by itself. A fiber is a lawful object when its base and projection are known. It becomes a governance failure when it is mistaken for the whole space. The failure is not that the canon used π₀. Every procedure must have some ordering before it can run. The failure is that the ordering may have selected the manifold while remaining outside the Compilation Map. If that is true, the canon has not merely omitted a detail. It has let an uncompiled coordinate participate in the definition of admissibility.

The base space would be the set of legal orderings permitted by the precedence lattice. Each linear extension π would define a possible image of the Check over the same archived population. π₀ would be one point in that base. The committed manifold would be one fiber over that point. Other fibers may be empty, similar, adjacent, divergent, or violently incompatible. Some may differ only by residue. Some may differ by status. Some may admit what π₀ refused. Some may refuse what π₀ admitted. The replay campaign does not speculate about these fibers. It samples them.

If the fibers coincide, order is decoration under certificate.

If the fibers diverge, order is law.

The stakes extend backward because every committed state has already passed through π₀. The question is not whether the canon should have had an order. The question is whether the order it had was part of the law while lacking the status of law. A positive finding of order-dependence does not produce a new defect. It reveals an old dependency. The measurement does not wound the canon. It locates the wound that was already carrying weight.

There is no comfort in either branch.

The commuting branch does not vindicate the canon. It only proves that a deep habit was less dangerous than it could have been, within the tested range and for the tested epoch. The certificate will decay. It will require re-witnessing. It will be bounded by classes, permutations, thresholds, and time. It will not license the sentence “the Check is order-free” without its index.

The non-commuting branch does not condemn the states. It condemns the unmeasured status of the ordering. A committed Σ that would fail under another legal ordering violated nothing. It passed the law that existed. The crisis belongs to the law, not to the state. Remediation will therefore be a question of compilation, grandfathering, re-witnessing, cascade tracing, and budget. No retroactive blame is permitted because blame is not a Layer C instrument.

The deeper consequence is structural. If the manifold is π₀-indexed, then the boundary has been less a surface than a connection. It did not merely separate admissible from non-admissible. It transported states through an ordered path, and the path contributed to what the boundary produced. Under that condition, admissibility is not a scalar property of Σ. It is a relation between Σ and an ordering.

Admissible becomes admissible-under.

Witnessed becomes witnessed-after.

Refused becomes refused-at.

Quarantined becomes quarantined-by.

The suffixes are not stylistic. They are the lost coordinates of the Check.

The canon has already accepted that the boundary is its sensory organ. This section adds the harder possibility: the organ may have a handedness. It may read differently depending on the order in which its receptors fire. If that is so, the boundary has not been a neutral surface receiving states. It has been an oriented instrument producing path-dependent contact. The Refusal Spectrum would then carry not only curvature information but ordering information. The negative linter would not merely remember what failed. It would remember where in the ordered body of the Check the failure occurred.

That possibility is not yet a claim. It is the reason for the protocol.

The stakes also reach forward. If order matters here, every multi-step governance procedure inherits suspicion. LCR-A has an order. LCR-B has an order. Zebra-Ø has an internal order. Quarantine exit has an order. Merge re-admission has an order. Evidence Ledger updates have an order. Every procedure that decomposes into operators has a possible λ. The Check is first because every admitted state passed through it. It is not last because the finding, once made, cannot remain local.

The canon is therefore not measuring a procedural detail. It is measuring whether governance has holonomy.

Holonomy means that movement through a sequence leaves a residue not reducible to the endpoint. In runtime geometry, this is the trace of path through a field. In Layer C governance, it is the trace of order through law. If two legal paths through the same operator set arrive at different witness residue or different status, then the path is physical for the pre-runtime regime. The order of law has become a quantity.

This is why the volume cannot be written as reassurance. The result will not say that the canon is safe. It will say what the canon has been. It will either expose π₀ as a convention that can now be governed, or as a hidden coordinate that has already shaped the manifold. Both outcomes remove ignorance. Neither outcome restores innocence, because innocence was never a valid governance status.

The boundary does not owe comfort to the states it admits.

The canon does not owe comfort to itself.

It owes trace, gate, budget, witness, and rollback readiness.

This section therefore closes Chapter 1 without mitigation. The possibility under examination is exact: the paradigm may have been compiling a fiber while naming it a space. If the measurement proves otherwise, the sentence will be voided by the world. If the measurement confirms it, the sentence will become the first cold description of what the manifold already was.

The next chapter begins the only admissible response.

The gates are formalized as operators.


Chapter 2 — Gates as Operators

2.1 — The State Space

The gates of the Admissibility Check cannot be formalized before the object they act upon is fixed. Chapter 1 established that the Check has been treated as a sequence of questions while functioning as a sequence of transformations. The next requirement is therefore not interpretive but geometric: specify the state space on which those transformations operate. A gate that has no defined domain is a metaphor. A gate that has no defined codomain is a narrative threshold. The present volume admits neither. Every gate in the Check acts on a pre-executable state Σ, and every claim about order-dependence, commutation, Loop Residue, or order fragility depends on preserving the identity of Σ across alternative executions.

A pre-executable state Σ is any submitted structure that has reached the boundary of admissibility but has not yet committed to runtime. It may be a claim, a rule, a metric, a gate specification, a ledger entry, a quarantine exit request, a proposed layer crossing, a protocol amendment, a canon update, a witness artifact, or a structured packet containing several of these components. Its surface form is not what defines it. Its position defines it. Σ is pre-executable because it stands before admission, under evaluation by the Hyper-Ω-Stack, prior to runtime force. It is not yet a member of the admissible manifold, not yet consigned to the non-admissible singularity, and not yet stabilized as quarantine unless a gate routes it there.

The state space of the Check is therefore the class of all Σ whose content can be hashed, whose submitted form can be held fixed during replay, whose route through the Admissibility Graph can be ledgered, and whose admissibility attributes can be read or written by the gates. The Check does not act on vague possibilities, authorial intentions, implied meanings, or later explanations. It acts on a fixed submission. Any material not present in the submitted state at hash fixation is not part of Σ for that execution. Later clarification may generate a new state, but it cannot retroactively become the state that was checked.

For the purposes of this volume, each Σ carries four primary admissibility attributes: curvature_adm(Σ), A_B(Σ), witness_residue(Σ), and status(Σ). These are not ornamental labels. They are the minimum coordinates required for a gate ordering to produce measurable differences. If an ordering changes curvature relation without changing status, λ may still register through altered witness residue. If an ordering changes budget without changing coherence, the path may still diverge at budget computation. If an ordering changes witness residue while preserving final status, the manifold has still been altered, because residue is the ledger-permanent trace through which the canon updates its own boundary memory. If an ordering changes status, φ records the event directly.

The first coordinate, curvature_adm(Σ), denotes the relation between the submitted state and the local geometry of admissibility at the boundary. It is not the curvature of physical space in runtime. It is the pre-runtime curvature of the admissibility surface around the attempted entry. A state that lies near a sharp exclusion region may trigger early refusal; a state that lies near a flatter region may travel farther before budget, coherence, or witness constraints decide it. The Check reads curvature_adm indirectly through its gates, and the Refusal Spectrum later reconstructs curvature gradients from patterns of failure. In the present volume, curvature_adm is treated as an attribute read by certain gates and potentially reclassified by routing, not as a free variable that the replay operator may reinterpret.

The second coordinate, A_B(Σ), denotes the Admissibility Budget relation of the state. It is not merely a scalar available at the end of the Check. It is the budget-bearing profile by which the state can or cannot be admitted after costs are computed. A_B may include available allocation, projected path cost, proof friction, coherence maintenance cost, embargo cost, re-witnessing burden, and downstream budget pressure. The budget computation gate reads and writes this coordinate explicitly, but earlier gates may determine whether budget is ever computed, and later gates may determine whether a non-negative budget event becomes admissible. Because of this, A_B cannot be treated as independent of order before measurement.

The third coordinate, witness_residue(Σ), denotes the ledger trace left by the state’s passage through the boundary. It is the central differenced quantity of this volume because it is the permanent record through which the canon remembers that a state was tested, how it was routed, what it cost, what it survived, and what it left behind. Witness residue is not identical with coherence_factor, although coherence readings may contribute to it. It is not identical with final status, although status transitions alter it. It is the residue of contact between Σ and the Check. If two legal orderings commit the same state with different witness_residue, they have not produced the same canon. The admitted object may look identical at runtime while the pre-runtime ledger has become different.

The fourth coordinate, status(Σ), denotes the state’s position in the Admissibility Graph. For this volume, status(Σ) belongs to the set {boundary, admissible, non-admissible, quarantine}. The boundary status marks a state held before final routing. The admissible status marks a state committed to the admissible manifold. The non-admissible status marks a state routed into the non-admissible singularity or its protocol-equivalent refusal destination. The quarantine status marks a state held outside commitment without being finally annihilated as admissibility candidate. These statuses are not psychological, rhetorical, or editorial. They are graph positions. A status change is a topological event in the governance structure.

The status set is intentionally minimal. It does not encode every internal subcondition of a run. A state may have a failure locus, a linter class, a gate signature, an embargo condition, a budget note, a witness anomaly, a replication flag, or a collision-routing annotation. These are ledger fields and secondary observables. They may be required by the replay protocol, but they do not expand the primary status set for the definition of φ. The Order Fragility Index depends on final status movement across the four primary positions. The finer differences belong to λ, to secondary observables, and to the per-run trace.

A pre-executable state therefore enters the Check in the form Σ₀ = {content, hash, metadata, admissibility attributes, status = boundary, ledger context}. The content is the submitted material. The hash fixes its identity for replay. The metadata records class, epoch, source, prior dependencies, layer target, and any already declared status. The admissibility attributes provide the readable and writable coordinates. The ledger context fixes the surrounding Evidence Ledger epoch against which the state is evaluated. No replay may silently alter any of these fields except through an explicitly defined gate operation. A replay that edits the input before applying an ordering is not a replay. It is a new submission.

The Admissibility Graph fixes the possible status transitions. Boundary may route to admissible, non-admissible, or quarantine. Quarantine may later generate a new boundary state through a properly specified re-entry or exit protocol, but that later movement is not the same execution unless the protocol explicitly defines it as such. Non-admissible is terminal for the execution. Admissible is terminal for the Check. The Check as studied in this volume concerns the path from boundary toward one of these final or holding positions under a given ordering π. It does not study post-commit runtime behavior, except where final status and residue determine what the canon has admitted.

This distinction prevents a false expansion of the state space. The replay campaign does not ask what Σ would later do in runtime. It does not simulate consequences after commitment. It does not evaluate usefulness, influence, explanatory force, aesthetic coherence, reader effect, or civilizational meaning. It asks only whether different legal orderings of the same admissibility operators, applied to the same fixed pre-executable state, produce different final admissibility attributes. The object remains Layer C throughout. Runtime outcomes are outside the measurement.

The phrase “the same Σ” therefore has a strict meaning. Two executions act on the same Σ only if their input content hashes match, their submitted packet fields match, their ledger epoch context is fixed or explicitly cloned, their initial status is boundary, their initial admissibility attributes are identical within the declared replay representation, and their replay copies are isolated from each other and from the live ledger. A state copied for replay is the same Σ for measurement when the copy preserves the hash-fixed content and all initial fields while allowing the tested gates to write only into the replay trace, never into the original ledger entry.

Hash identity is the first identity condition. The content hash must be computed over the full submitted state as defined by the replay protocol: primary text, formal fields, declared dependencies, layer target, status claim, proposed gate, budget note, witness packet, and any attached artifacts included in the original submission. If an attachment was part of the submitted state, it is part of the hash. If an explanation was added later, it is not part of the hash. If a field was omitted in the original submission and later supplied, the later packet is a different Σ. The hash is not a convenience for file management. It is the barrier against retroactive authorship.

Ledger-context identity is the second identity condition. A replay executed against a different ledger epoch is not automatically the same measurement, because the surrounding context manifold may have drifted. Witness residue, proof friction, negative linter sensitivity, and budget availability can depend on epoch. The first replay campaign therefore fixes the ledger epoch for each sampled state and clones the relevant context into the replay environment. Later longitudinal campaigns may intentionally vary epoch, but such variation belongs to Witness Thermodynamics, not to the primary measurement of ordering. Order-dependence and context-drift dependence must not be merged.

Attribute identity is the third identity condition. The replay copies must begin with the same curvature_adm representation, the same budget profile, the same witness baseline, and the same boundary status. If an operator ordering changes these values during execution, that change is a result. If the values differ before execution, the replay has failed. This condition is especially important for witness_residue, because λ is defined by differencing final witness_residue against the π₀ result. The baseline must be identical or the difference is uninterpretable.

Isolation identity is the fourth identity condition. Alternative orderings must not contaminate one another. A replay under π may not raise live Zebra-Ø sensitivity, alter the negative linter, spend live A_B, modify the original Evidence Ledger, or change the replay inputs delivered to another ordering. Each run writes to its own replay trace. The traces may later be compared, but no run may become part of the environment of another run. Without isolation, the measured λ would include cross-run pollution rather than order-dependence.

The state space is therefore not merely a set of submitted texts. It is a controlled Layer C replay space: hash-fixed, ledger-context-fixed, attribute-fixed, status-initialized, and contamination-isolated. Only within such a space can the question of commutation be asked without collapsing into ordinary interpretive difference. If two operators yield different outcomes under those conditions, the difference belongs to the ordering. If the conditions are not held, the difference belongs to the campaign defect.

The formal object of Chapter 2 may now be stated. Let S be the class of all replay-admissible pre-executable states Σ satisfying the identity conditions above. Each gate Gᵢ of the Admissibility Check is an operation whose domain is a subset of S or of the intermediate states generated from S, and whose codomain is the same structured state space with possibly altered attributes, trace fields, routing position, or terminal status. A full Check under ordering π is a composition of such operations constrained by the precedence lattice. The output of Check_π(Σ) is a terminal or holding state with final status, final witness_residue, and full replay trace.

This definition does not yet decide whether the gates commute. It only prevents the later question from being meaningless. Commutation cannot be measured if the state is allowed to drift. Loop Residue cannot be defined if witness residue is not fixed as an attribute. Order Fragility cannot be recorded if status lacks a finite set. The precedence lattice cannot be constructed if the operators have no domain. Part II cannot execute if Part I leaves the state space atmospheric.

The state space is now fixed.

The gates can now be written as operators.


2.2 — The Eleven Operators

The Admissibility Check, restricted to the permutable interior specified by this volume, contains eleven operators before the terminal segment is treated: Silence Entry, four zero-questions, four blocking-questions, Zebra-Ø, and budget computation. Embargo and final witness check are not ignored; they are withheld until Section 2.3 because their position belongs to the terminal architecture of the Check rather than to the first definition of the operator set. The present section therefore fixes the eleven gates that form the core operator alphabet. Each operator acts on a state in the replay-admissible state space S or on an intermediate state generated from S. Each has a domain, a codomain, a read-set, a write-set, and a routing rule. None is treated as a passive predicate.

Let an intermediate state be denoted Σᵢ, where the subscript marks its position inside a particular ordering π, not a change of content hash. The content remains hash-fixed; the procedural condition changes. An operator G receives Σᵢ and returns either a successor state Σᵢ₊₁ in boundary status with updated trace fields, or a routed state whose status has changed to quarantine, non-admissible, or another protocol-defined holding condition. In the notation of this chapter, every operator has the general form G: D_G ⊆ S* → S*, where S* is the closure of the replay-admissible state space under admissibility-operator transformation. The codomain remains S* because even a refused, quarantined, or admitted intermediate output remains a structured state with content hash, attributes, status, and trace. The difference is not whether the state remains legible. The difference is whether the state remains eligible for later gates in that run.

The first operator is G_S, Silence Entry. Its domain is any replay-admissible pre-executable state whose initial status is boundary and whose hash, metadata, ledger context, and initial attributes are fixed. Its codomain is a boundary-held state with narrative propulsion suppressed and initial trace opened. G_S reads the submitted content, the declared layer target, the status claim, the submission packet, and any attached governance artifacts; it reads curvature_adm only at the coarse entry level, sufficient to identify whether the state can be held without immediate collapse into an already terminal route. G_S writes no final admissibility decision. It writes the initial silence trace, fixes the state as held-before-evaluation, prevents immediate larval interpretation from becoming part of the operative content, and initializes the run ledger for subsequent gates. Its ordinary route is continuation to the zero-question block. Its exceptional route is immediate quarantine only if the state cannot be held as a coherent submission at all because the submitted packet fails the minimum identity conditions required for hashing, classing, or ledgering. In the canonical ordering π₀, G_S is initial; in the precedence lattice, its initiality is a compiled sequence constraint because later gates are defined as acting on a state that has already entered silence.

The zero-question operators are G_Z1, G_Z2, G_Z3, and G_Z4. Their common domain is any boundary-held state that has passed Silence Entry and has not yet been routed to a terminal or holding status in the current run. Their common codomain is either a boundary-held successor state with a non-firing trace for the zero condition tested, or a routed state whose status becomes quarantine or non-admissible according to the failure path specified by the Admissibility Check Protocol. Each G_Zk reads the hash-fixed content, the declared intention of the submission, the layer target, the proposed status, the relation between the claim and its stated gate, the presence or absence of immediate disqualifying structure, and the prior trace accumulated before the operator fires. Each G_Zk writes a failure locus if it fires, a non-firing trace if it does not, and a localized contribution to witness_residue corresponding to contact with the zero surface. Each G_Zk may also write a curvature annotation, because early failure at a zero surface is evidence of proximity to a high-curvature exclusion region. None of the zero-questions writes final admissibility. Their role is to prevent states carrying disqualifying entry structure from reaching later gates where coherence language, budget arithmetic, or interpretive complexity could obscure the reason they had no right to proceed.

G_Z1 is the first zero-question in π₀, but in the abstract operator set it is the zero-question that tests zero condition Z1, not the gate that must necessarily be first in every legal ordering. Its read-set includes the submitted state under initial silence and no prior zero-question survival trace unless the tested ordering places another zero-question before it. Its write-set includes either a Z1-failure trace with routing to quarantine or refusal, or a Z1-non-firing trace that becomes part of the state received by later gates. The important point for this volume is that G_Z1’s action depends on the procedural condition of the state delivered to it. If another zero-question precedes it, G_Z1 reads a state already marked by survival or routing pressure; if G_Z1 precedes the others, it writes the first zero-surface contact. Its content hash remains fixed in both cases, but its procedural input differs.

G_Z2, G_Z3, and G_Z4 share the same formal structure with their respective zero conditions Z2, Z3, and Z4. Each reads the state as modified by prior gates in the tested ordering, writes its own firing or non-firing trace, may contribute to curvature annotation and witness residue, and routes the state out of the zero block if its condition fires. The four operators are therefore not interchangeable by name, although the replay campaign may permute them where the precedence lattice allows. A legal permutation changes the order of contact, not the identity of the zero conditions. This distinction prevents the campaign from confusing relabeling with reordering. The operator G_Z2 remains G_Z2 wherever it appears in π; only its position changes. The same holds for G_Z3 and G_Z4.

The blocking-question operators are G_B1, G_B2, G_B3, and G_B4. Their common domain is any boundary-held state that has passed Silence Entry and remains eligible after whatever zero-question sequence the tested ordering has applied. In π₀, the blocking block begins only after all four zero-questions have not fired; in the full precedence lattice, the permissibility of cross-block movement is not assumed but constructed later from compiled constraints. Their common codomain is either a boundary-held successor state with a non-blocking trace, or a routed state whose status becomes quarantine, or a protocol-specified blocked condition pending correction, collision routing, reclassification, or re-entry. Each G_Bk reads the submitted content, the layer target, the status claim, the relation between name and object, the relation between layer and gate, the declared dependencies, the prior zero-question trace, and any earlier blocking trace. Each writes either a blocking locus or a non-blocking survival trace; it may write a required reclassification, a collision-routing demand, a quarantine reason, a budget surcharge for unresolved structure, or a witness-residue contribution reflecting the state’s contact with the blocking surface.

G_B1 tests blocking condition B1. Its action is not reducible to a truth value because a fired block changes the state’s admissibility path. It may prevent the state from reaching Zebra-Ø, may demand that the submission be renamed or rerouted, may send the state into quarantine, or may require a future submission with corrected fields. Its write-set therefore touches status, witness_residue, and often A_B, since blocked states can create proof-friction or re-entry obligations. If G_B1 does not fire, it still writes survival through the first blocking surface, and that survival becomes part of the evidentiary condition delivered to later operators.

G_B2, G_B3, and G_B4 operate analogously over blocking conditions B2, B3, and B4. Each reads the state under its current procedural condition, including any prior non-firing traces and any modifications written by earlier gates. Each writes its own block or survival trace. Each routes the state out of ordinary continuation if its blocking condition fires. The fact that the four blocking-questions share a structural form does not make their order irrelevant. If one blocking-question can force renaming, and another tests layer crossing under the submitted name, then reversing their order may alter the description under which the later gate reads the state. If one blocking-question imposes a proof-friction surcharge, and another evaluates whether the remaining budget posture can sustain further processing, then reversing their order may alter the A_B relation. The blocking operators are therefore order candidates, not neutral checklist items.

The tenth operator is G_Ø, Zebra-Ø. Its domain is any boundary-held state that has survived the prior gates required by the tested ordering and has not been routed away from coherence evaluation. Its codomain is either a boundary-held successor state with coherence_factor recorded at or above the threshold required for continuation, or a routed state whose status becomes non-admissible or quarantine according to the Zebra-Ø failure rule. G_Ø reads the full submitted content, the layer target, the claimed status, the structural relation between claim and gate, the accumulated trace, the local linter environment cloned for replay, and the coherence conditions specified by the protocol. It writes the Zebra-Ø score, the coherence_factor result, the pass or failure locus, the corresponding witness_residue contribution, and any negative-linter annotation required by a failure. In live execution, Zebra-Ø failure may alter future sensitivity to related structures; in replay execution, that write is confined to the replay trace and may not contaminate the live linter. This containment is part of the contamination controls later specified by the protocol.

G_Ø is especially important because it exposes the insufficiency of the predicate model. A coherence test that fails after the zero-questions and blocking-questions is not equivalent to a coherence test that fails before them. In the first case, the state has survived earlier refusal surfaces and carries their non-firing traces. In the second case, coherence reads a state not yet filtered by those surfaces. The numerical coherence_factor may or may not change under such reordering; the replay campaign does not assume either result. What is fixed here is only that G_Ø reads a procedural state, writes a coherence event, and routes on failure. Since routing is transformation, G_Ø is an operator.

The eleventh operator is G_A, budget computation. Its domain is any boundary-held state whose prior path has not routed it away from pricing and whose accumulated trace contains enough information to compute the state’s admissibility cost under the cloned ledger context. Its codomain is either a boundary-held successor state with non-negative budget relation and computed path cost, or a routed state whose status becomes quarantine or non-admissible under negative A_B or unpayable proof-friction conditions. G_A reads curvature_adm, coherence_factor if already written, proof friction, dependency load, witness requirements, quarantine pressure, re-witnessing obligations, execution risk, and the available budget allocation in the replay context. It writes the computed A_B relation, the path-cost entry, any budget deficit, any surplus or reserved maintenance cost, and the witness_residue contribution associated with priced admission or priced rejection.

G_A is not late arithmetic appended to a completed Check. It is an admissibility operator whose result may decide whether the state continues toward the terminal segment or exits the path. If G_A is applied after Zebra-Ø, it prices a state whose coherence has already been established. If it is applied before Zebra-Ø under a legal ordering later admitted by the precedence lattice, it prices a state whose coherence has not yet been written. These are different procedural inputs. The difference may disappear under measurement, or it may appear as λ, φ, or secondary observables. The present chapter does not decide. It only fixes G_A as an operator capable of reading and writing the four admissibility attributes.

Across the eleven operators, the four primary attributes are affected in different ways. curvature_adm is read most directly at entry, refusal, and classing surfaces, and may be annotated by early or late failure. A_B is written explicitly by G_A but may be burdened indirectly by blocking gates, proof-friction implications, and replay isolation rules. witness_residue is touched by every gate because every contact with the boundary leaves trace, whether the gate fires or not. status is altered by any gate that routes, and preserved by any gate that allows continuation. These attribute effects are the minimum reason the operators cannot be reduced to predicates. A predicate returns a value. These gates alter a state’s admissibility coordinates.

The routing rules can now be stated in compact form. G_S routes to the zero-question block unless the state cannot be held as a hash-fixed submission. G_Zk routes to quarantine or non-admissible status if zero condition Zk fires, and otherwise routes forward within the permitted ordering. G_Bk routes to quarantine, correction, reclassification, or blocked holding if blocking condition Bk fires, and otherwise routes forward. G_Ø routes to non-admissible or quarantine on coherence failure and forward on pass. G_A routes to budget rejection, quarantine, or forward continuation according to the computed A_B relation. The forward route is not a guarantee of commit. It only delivers the state to the next operator or, after the permutable interior is complete, to the terminal segment.

This formalization preserves the distinction between operator identity and operator position. G_Z1 is always the operator testing Z1, regardless of where it appears in a legal ordering. G_B3 is always the operator testing B3, regardless of whether it is applied before or after another blocking gate. G_Ø remains Zebra-Ø and G_A remains budget computation. Reordering changes composition, not names. Without this rule, the replay campaign would not measure order. It would measure substitution.

The eleven operators therefore form the interior alphabet of the Check: {G_S, G_Z1, G_Z2, G_Z3, G_Z4, G_B1, G_B2, G_B3, G_B4, G_Ø, G_A}. The canonical word π₀ arranges them in inherited sequence. The precedence lattice will determine which alternative words count as legal executions of the same Check. Section 2.3 will remove from free permutation the terminal elements whose positions are fixed by definition: embargo, final witness check, and commit. Section 2.4 will then treat the Check as a word in this alphabet and define equality of words against equality of outcomes. The state space has been fixed; the operator set has now been named. The next task is to mark which parts of the sequence are law, and which parts have merely been order.


2.3 — The Terminal Segment

The eleven operators named in the previous section form the interior alphabet of the Check, but they do not exhaust the Check. After the interior sequence, the protocol contains the interpretive embargo, the final witness check, and commit. Before the measurement campaign can permute any ordering, the status of these terminal elements must be fixed. A replay that treats every named step as freely movable does not measure the holonomy of the Admissibility Check. It destroys the Check and measures an artifact of procedural incoherence. The object of this volume is not a free permutation group over all labels. It is the set of legal linear extensions of the Check’s precedence lattice.

The difference is decisive. A free permutation group assumes that every element can exchange position with every other element unless an external rule forbids it. The Admissibility Check is not such an object. Its steps are not beads on a string. Some positions are functional definitions. Silence Entry is not merely the first item in a list; it is the condition under which Σ becomes holdable before evaluation. Commit is not merely the last item in a list; it is the terminal act by which a state leaves pre-executability and enters the admissible manifold. Embargo is not merely a late pause; it is a pre-commit interval following positive verification and preceding final witness. Final witness check is not merely a final review; it is the trace-completion gate that makes commitment ledgerable. These constraints are not typographic. They are compiled by the meaning of the operations themselves.

Silence Entry is initial because the Check begins by removing immediate narrative propulsion from the state. A state that has not entered silence has not yet become an object of admissibility discipline. It remains exposed to premature interpretation, authorial intention, rhetorical force, larval resonance, and unpriced motion toward use. Later gates are defined as acting on a state already held at the boundary. They do not create the holding condition. They presuppose it. If a zero-question, blocking-question, Zebra-Ø, or budget computation were applied before Silence Entry, the operation would not be an alternative ordering of the same Check. It would be an evaluation of an unheld state and therefore a different procedure.

This is why G_S is excluded from the freely permutable interior even though it is part of the eleven-operator alphabet. It may be named as an operator because it reads and writes the state: it opens the trace, fixes the state under silence, initializes the run ledger, and suppresses immediate interpretive motion. But its position is not available to the replay campaign as a variable. In the precedence lattice, G_S is the unique minimal element. Every legal ordering π must begin after G_S has executed. Any replay that places another gate before G_S is not a legal extension of the Check. It is a Shadow Layer C run under a false name.

Commit is terminal for the same reason in reverse. Commit is the act by which the state ceases to be pre-executable and becomes admitted. Once commit occurs, the Check no longer has a boundary-state object on which to act. Later application of Zebra-Ø, budget computation, or final witness check would not be continuation of the same admissibility path. It would be post-commit audit, rollback procedure, recertification, or runtime governance, depending on the operation attempted. Those are valid procedures under their own gates, but they are not legal reorderings of the Admissibility Check. A procedure that commits before it has completed the Check admits before admissibility has been established. It is not an alternative π. It is a breach.

The terminality of commit therefore generates a maximal element in the precedence lattice. Every legal ordering must end in C after the required preconditions have been satisfied. Commit has no ordinary codomain inside the Check because it ends the Check. Its output is not another boundary-held state but an admissible state, or, under failure of preconditions, no valid commit event at all. This matters for Loop Residue because λ compares final witness_residue after complete Check executions. A run that commits early would not produce a comparable final residue. It would not be a noisy datapoint. It would be invalid.

The interpretive embargo occupies a more subtle position. It is neither initial like Silence Entry nor terminal like commit. It is a delay inserted after positive verification and before final witness. Its purpose is to prevent immediate interpretive collapse after a state appears to have survived the substantive gates. The state has passed enough of the Check to be dangerous if immediately converted into canon, but it has not yet been witnessed into admissibility. The embargo holds this interval. It separates the fact of positive evaluation from the act of final admission.

Because the embargo is defined by that interval, moving it freely would change its object. An embargo before Silence Entry is impossible because no held state exists. An embargo immediately after Silence Entry, before any gate has positively evaluated the state, would be an extension of silence rather than interpretive embargo. An embargo before the zero-questions would not delay post-verification interpretation; it would delay entry. An embargo after commit would no longer be pre-commit discipline; it would be post-commit restraint, review, or recertification. The same word would name a different function. The Check does not permit such substitution.

The embargo therefore follows positive verification. The precise boundary of “positive verification” must be constructed by the precedence lattice, but its functional meaning is already compiled: embargo cannot precede the gates whose survival it is designed to hold in suspension. In π₀, this places embargo after budget computation and before final witness check. In any legal ordering, embargo must remain after the interior gates required to establish that the state is eligible for pre-commit holding. It may not be used as a movable operator to test order-dependence inside the zero-question block, the blocking-question block, Zebra-Ø, or budget computation. Its order is constrained by definition.

The final witness check is likewise excluded from the freely permutable interior. Witness is not a gate that asks whether the state is coherent, affordable, correctly routed, or free of blocking conditions. It asks whether the path by which the state reached the final threshold is complete enough to be admitted without creating untraceable power. It reads the trace left by the prior gates. A final witness check before the prior gates have acted would have no complete path to witness. It would be an empty certification surface. A final witness check before embargo would miss the temporal separation that the protocol requires between positive evaluation and admission. A final witness check after commit would not condition admission; it would document an admission that had already occurred. That would invert the witness relation.

G_W therefore depends on the existence of a completed pre-commit trace. It reads the accumulated gate sequence, the non-firing and firing records, the coherence result, the budget computation, the embargo record, the status path, and the witness-residue profile. It writes the final trace-completion condition and determines whether commit is ledgerable. Its position after embargo and before commit is not a stylistic placement. It is the condition under which the word “witness” retains its Layer C force.

This terminal architecture constrains the replay campaign before any measurement begins. The campaign may ask whether the internal order of the zero-questions matters. It may ask whether the internal order of the blocking-questions matters. It may ask, under later LCR-A amendment and only where the precedence lattice permits, whether certain cross-stage positions alter residue or status. It may ask whether Zebra-Ø and budget computation commute within a lawful segment of the Check. It may not ask whether commit can precede witness, whether final witness can precede the path it witnesses, whether embargo can occur after admission and remain the same embargo, or whether a gate can touch the state before Silence Entry. Those are not deep frontier questions. They are category errors.

The distinction between compiled sequence constraint and typographic sequence therefore becomes the central discipline of the lattice. A typographic sequence is the visible order in which the protocol’s text names its steps. It may be operationalized by habit, but it does not automatically carry governance force. A compiled sequence constraint is an order relation required by the definition of the operations, by prior canon, or by the conditions without which the Check would cease to be itself. The replay protocol must separate these two classes. Only the typographic or insufficiently compiled portions of π₀ become candidates for permutation. The compiled constraints become the partial order within which legal permutations are generated.

This is why the volume does not define its permutation space as all arrangements of {G_S, G_Z1, G_Z2, G_Z3, G_Z4, G_B1, G_B2, G_B3, G_B4, G_Ø, G_A, E_72, G_W, C}. That set contains the names, but the names are not enough. The lawful object is not the set of all sequences over those symbols. The lawful object is the set of words that preserve the compiled order relations: G_S before every evaluative gate; all required positive verification before E_72; E_72 before G_W; G_W before C; C terminal. Further constraints may be added where the protocol explicitly fixes relations among the interior gates. Everything else becomes a candidate edge for measurement.

The precedence lattice is the structure generated by these compiled constraints. It is not imposed from outside the Check. It is extracted from the Check’s own definitions. Its nodes are the Check operations. Its order relations are the compiled dependencies among them. Its linear extensions are the legal orderings that preserve all compiled constraints while varying only what has not yet been proven sequence-dependent. π₀ is one linear extension of this lattice. The replay campaign compares π₀ against other legal extensions, not against arbitrary rearrangements.

This construction also prevents false findings. If the campaign allowed commit before final witness, it would almost certainly generate different outcomes. Those differences would not prove holonomy. They would prove that breaking the Check changes the Check. If the campaign allowed Zebra-Ø to run before Silence Entry, any result would be uninterpretable because the input state would not have entered the admissibility condition required by the protocol. If the campaign allowed embargo after commit, differences in witness residue would measure procedural substitution, not ordering effects. The lattice guards the measurement from producing significance out of invalidity.

The terminal segment therefore does not weaken the holonomy question. It sharpens it. By excluding what is definitionally fixed, the volume prevents the replay protocol from discovering only the trivial fact that law fails when its terminal conditions are violated. The question becomes narrower and stronger: inside the legal space of the Check, after compiled constraints are honored, does order still matter? If the answer is no, the canon gains a meaningful certificate. If the answer is yes, the canon discovers a genuine ungoverned ordering, not merely the consequence of illegal rearrangement.

The same discipline applies to later campaigns. The first campaign restricts the ordering space for cost, clarity, and contamination control. Later campaigns may expand the lattice, but only by LCR-A amendment. They may not improvise new freedoms during execution. Any proposed movement of an operation previously treated as fixed must state whether the movement preserves the operation’s identity. If moving an operation changes what the operation is, the movement is forbidden as a permutation and may only be studied as a different procedure under a different protocol.

The terminal segment now has its status. Silence Entry is initial. Embargo follows positive verification and remains pre-commit. Final witness check follows embargo and completes trace. Commit is terminal. These are compiled constraints, not artifacts of page order. They generate the precedence lattice and bound the legal ordering space for Loop Residue measurement.

The Check is not a free permutation group.

It is a governed word with ungoverned intervals.


2.4 — Operator Composition and the Check as a Word

The Check can now be written as a word.

A word is an ordered composition of symbols drawn from an alphabet. In this volume, the alphabet is not linguistic. It is operational. Its symbols are the gates of the Admissibility Check understood as operators on the state space fixed in Section 2.1. The canonical word π₀ is the inherited sequence reconstructed in Section 1.2, bounded by the compiled constraints of the terminal segment and populated by the eleven operators defined in Section 2.2. The question of this volume is not whether the same labels can be arranged differently on a page. The question is whether different legal words in the same operator alphabet, applied to the same hash-fixed state Σ, produce the same final admissibility object.

The operator alphabet contains G_S, G_Z1, G_Z2, G_Z3, G_Z4, G_B1, G_B2, G_B3, G_B4, G_Ø, and G_A, with the terminal structure E_72, G_W, and C constrained by the precedence lattice rather than exposed to free permutation. A complete Check word is therefore not any arbitrary string over this alphabet. It is an ordered composition that contains each required operator exactly once, preserves every compiled sequence constraint, and terminates in the prescribed terminal segment. A legal word is a path through the same law, not an invention of another law.

Let π denote such a legal ordering. The Check under π is written as Check_π. If π orders the permitted interior as G_i1, G_i2, …, G_in, then Check_π(Σ) is the result of applying the operators in that order to the same initial state Σ, with each operator receiving the successor state generated by the prior operator. The content hash remains fixed. The procedural state changes. The trace accumulates. The admissibility attributes may be read, written, preserved, or routed. The final output is not a proposition. It is a structured state with final status, final witness_residue, final budget relation, final trace, and a recorded path through the lattice.

This notation is deliberately unforgiving. Check_π(Σ) does not mean “the Check interpreted according to π.” It means the operator composition executed under π. If an ordering cannot be executed from the definitions in Part I and the protocol in Part II, it is not a legal π. If execution requires interpretive supplement, the definition has failed. If an operator is moved across a compiled dependency, the resulting string is not another ordering of the Check. It is a different procedure or an invalid run. The measurement space consists only of legal linear extensions of the precedence lattice.

Equality of words must therefore be separated from equality of outcomes. Two words are equal as words only when their operator sequence is identical. If π₁ and π₂ place the same operators in the same positions, then they are the same word. If they differ in even one allowed swap, they are different words, even if later measurement shows that they produce the same final residue and the same final status for every tested state. Operational equality of outcome is not syntactic equality of word. It is a result that must be earned by replay.

Conversely, two words may be syntactically different and outcome-equivalent over a tested class. If Check_π1(Σ) and Check_π2(Σ) return identical final status, identical final witness_residue within the declared error budget, identical A_B relation, and no relevant secondary observable difference for every tested Σ in a class, then the words commute over that class within that campaign’s scope. This does not make the words identical. It makes their difference invisible to the measured attributes under the stated conditions. A certificate may record that invisibility. It may not erase the distinction between the paths.

The inverse case is the subject of this volume. Two legal words may contain the identical multiset of operators and still produce different outcomes. One ordering may route a state into quarantine before Zebra-Ø ever reads it. Another may deliver the same hash-fixed state to Zebra-Ø before the blocking gate that would have stopped it. One ordering may compute budget after coherence has been written; another may compute budget before coherence changes the proof-friction surface. One ordering may leave a higher witness_residue because the state survived more boundary contacts before refusal; another may leave lower residue because the state died earlier. If the final status remains the same, λ may still record difference. If the final status changes, φ records fragility.

The phrase “the same Check” therefore has a precise and restricted meaning. Two orderings are the same Check when they satisfy three conditions. They contain the identical multiset of required operators. They both preserve every compiled sequence constraint of the precedence lattice. They both act on the same hash-fixed Σ under the same cloned ledger context, with identical initial attributes and isolated replay traces. If these conditions hold, then π₁ and π₂ are alternative legal executions of the same Check. They differ by order, not by substance, not by input, not by context, and not by terminal architecture.

This definition prevents a common error. A procedure that omits G_Z3 is not an alternative ordering of the Check. It is an incomplete Check. A procedure that applies G_A twice is not an alternative ordering. It is an altered operator multiset. A procedure that commits before final witness is not an alternative ordering. It violates terminal constraint. A procedure that changes the content packet between runs is not an alternative ordering. It changes Σ. A procedure that allows one replay to affect the linter state of another replay is not an alternative ordering. It contaminates the context. The measurement must exclude all such cases before any claim about holonomy can be made.

The multiset condition is necessary because this volume measures order, not inventory. The same operators must be present in each legal word. If one word contains all four zero-questions and another contains only three, any outcome difference could arise from absence rather than ordering. If one word includes Zebra-Ø and another replaces it with a weaker coherence check, the result would measure substitution. If one word computes budget under a different cost functional, the result would measure metric drift. The campaign is permitted to change sequence. It is not permitted to change the law being sequenced.

The lattice condition is necessary because the Check is not a free permutation group. The compiled constraints extracted in Section 2.3 define which relative positions belong to the identity of the Check. Silence Entry remains initial. Commit remains terminal. Embargo remains after positive verification and before final witness. Final witness remains before commit. Any other constraints explicitly fixed by the protocol must also be preserved. Legal orderings are therefore not all permutations but linear extensions of a partial order. The freedom measured by this volume is the freedom left after law has been honored.

The identity condition on Σ is necessary because order-dependence cannot be distinguished from input drift unless the state is fixed. The same word applied to two different states may yield different outcomes without revealing anything about holonomy. Two different words applied to different states are still less informative. The replay campaign therefore requires hash fixation, cloned ledger epoch, identical initial admissibility attributes, and contamination isolation. Under those conditions, any replicated difference between Check_π and Check_π₀ is assigned to ordering, campaign defect, or ledger inconsistency. Part II exists to separate those possibilities.

Once these constraints are satisfied, the distinction between equality of words and equality of outcomes becomes measurable. For a given Σ, two legal words may yield the same final status and the same final witness_residue. They may yield the same status with different residue. They may yield different status with or without residue comparison. They may diverge in secondary observables while remaining identical in the primary quantities. The replay protocol records all of these cases, but the volume’s two central quantities are already determined by the primary divergence classes: λ for residue difference, φ for status difference.

A word may therefore be harmless in one register and not in another. Two orderings may both commit a state, and yet one leaves a different witness_residue. Runtime would see the same admitted content. Layer C would not see the same event. The canon would have acquired a different residue and updated its boundary memory differently. That is not a cosmetic distinction. It is exactly the kind of difference a runtime observer would miss and the Hyper-Ω-Stack is required to price.

A word may also be equivalent on one class and not on another. Zero-question permutations may commute for states that fail early at a single unambiguous zero condition, while failing to commute for states that lie near the intersection of two zero surfaces. Blocking-question permutations may commute for clean submissions and diverge for collision-prone submissions. Zebra-Ø and budget computation may commute for low-cost high-coherence states and diverge near the budget threshold. The campaign therefore estimates λ and φ per class, not only globally. A global zero can conceal local holonomy. A local status flip is sufficient to void a universal certificate.

This class-indexed view is already implied by the Refusal Spectrum. Failure locus is not merely where a state died. It is the boundary coordinate at which the Check recorded contact. If legal words rearrange the order in which contacts occur, then the same state may produce different failure-locus statistics. The Check as a word therefore links Governance Holonomy to Refusal Spectroscopy. A spectrum is never pure curvature until ordering content has been separated from it. Part V will return to this as an order leak. Here it functions as a warning: equality of final reject status is not enough to prove equality of path.

The canonical word π₀ now has its role. It is the reference word, not the privileged truth. λ is defined by comparing alternative legal words to π₀ because π₀ is the word the canon actually used. The purpose is not to discover whether some abstract ordering is better. The purpose is to measure whether the inherited ordering has shaped the manifold. If π₀ is outcome-equivalent to all tested legal words within the declared error budget, it becomes a governed convention under certificate. If it is not, it becomes a compiled object requiring trace, remediation, and rollback readiness. In both cases, it ceases to be dark.

The general form of the comparison can now be stated. For each replay-admissible state Σ and each legal ordering π, the campaign computes Check_π(Σ) and compares it to Check_π₀(Σ). The comparison is made across final witness_residue, final status, A_B relation, coherence result where available, failure locus, and trace signature. The primary differenced quantity is witness_residue. The primary fragility event is status flip. Secondary observables are retained because they may explain or stratify the primary results, but they do not replace them.

The word model also clarifies what it would mean for the Check to commute. The Check does not commute merely because the same operators are present in every run. It commutes over a class when all legal words tested over that class produce equivalent outcomes within the declared measurement tolerances. Commutation is not an assumption of procedural identity. It is an empirical and ledgered property of operator composition under the replay protocol. The fact that the canon requires all gates to be passed says nothing by itself about whether the gates commute. A law may require several questions and still depend on the order in which it asks them.

The opposite condition is non-commutation. Non-commutation occurs when two legal words, identical in operator multiset and valid under the precedence lattice, applied to the same Σ, produce a difference in final attributes or final status outside the declared error budget. The difference may be fine, appearing only as λ. It may be hard, appearing as φ. It may be localized to one class, one epoch, one gate pair, or one region of the boundary. It may be abelian, with local swaps producing independent effects, or non-abelian, with composed swaps producing effects that depend on the order of the swaps themselves. Chapter 3 begins with the local commutator because the global holonomy of the Check must be built from the failure or survival of local order exchanges.

The Check as a word therefore converts the hidden question into an executable object. The state space is fixed. The operators are named. The terminal constraints have generated the precedence lattice. The canonical word π₀ stands as the reference. Legal alternatives are no longer speculative rearrangements. They are linear extensions of the same law. Equality of words has been separated from equality of outcomes. The measurement can now ask, without metaphor, whether two paths through the same governance alphabet arrive at the same pre-runtime state.

If they do, order becomes governed convention.

If they do not, order becomes law.


Chapter 3 — The Commutator

3.1 — [G_i, G_j] Defined

The commutator is the first instrument by which the order of the Check becomes measurable at local scale. Chapter 2 defined the Check as a word in an operator alphabet and separated equality of words from equality of outcomes. The present section defines the local comparison from which the later global measurement is built. Before the volume can ask whether π₀ carries holonomy, it must ask whether two gates exchange position without altering the state they act upon. The commutator is the name of that exchange test.

Let G_i and G_j be two admissibility operators drawn from the Check’s operator alphabet, and let Σ be a hash-fixed pre-executable state in the replay-admissible state space. The local commutator [G_i, G_j] is defined as the attribute-and-status difference between the state produced by applying G_i before G_j and the state produced by applying G_j before G_i, provided both two-step words are legal under the precedence lattice or under a declared local test lattice authorized by the replay protocol. The definition does not ask whether the gates appear adjacent in π₀. It asks whether, where the lattice permits their exchange, their order changes the output.

Formally, the two local compositions are G_j(G_i(Σ)) and G_i(G_j(Σ)). The notation is read from inside outward: in the first composition, G_i touches Σ first and G_j touches the resulting state; in the second composition, G_j touches Σ first and G_i touches the resulting state. The content hash of Σ remains identical in both executions. The ledger context remains cloned. The initial admissibility attributes remain fixed. The replay traces remain isolated. Any difference after the two compositions is therefore assigned either to operator order, to an execution defect, or to an illegal test. Part II exists to separate those three cases procedurally. Part I fixes the object.

The output of a local composition is not a truth value. It is a structured state with attributes and route. For commutator purposes, the comparison tuple contains curvature_adm, A_B, witness_residue, status, and the minimal trace fields required to identify failure locus and non-application. The primary comparison is made over the four attributes fixed in Section 2.1. Trace is retained because it determines whether an apparent equality of final attributes conceals different paths. A state may end with the same status and the same residue under both orders while still leaving different failure-locus annotations; that difference is secondary for λ and φ, but it remains relevant to Refusal Spectrum and later order-leak analysis.

The commutator can therefore be written as a difference object rather than a scalar. For a given Σ, G_i, G_j denotes the ordered difference between the output tuple of G_jG_i and the output tuple of G_iG_j. Its components are Δcurvature_adm, ΔA_B, Δwitness_residue, Δstatus, and Δtrace. Where the quantities are numeric or ledger-scalar, difference is ordinary subtraction under the units of the relevant field. Where the quantity is categorical, as status is, difference means inequality of final category. Where the quantity is trace-structured, difference means non-identity of the required trace fields after normalization by the replay protocol. The zero commutator means zero difference across every required component, not merely the absence of a visible runtime change.

This definition is route-aware. If G_i fires and routes Σ to quarantine before G_j can act, then G_j is not silently assumed to have passed. It is recorded as non-applied because the path terminated or moved into a holding state before reaching it. If, under the reverse order, G_j does not fire and G_i later fires, the two outputs differ even if the final primary status is quarantine in both cases. They differ by failure locus, by trace, and possibly by witness_residue. If, under one order, the state is quarantined, and under the other, it survives both gates and remains boundary-held, then Δstatus is nonzero. If one order routes to non-admissible and the other routes to quarantine, Δstatus is nonzero even before residue is compared. Routing is not an annotation after the fact. It is part of the operator result.

The commutator is undefined when one of the tested orders violates a compiled sequence constraint. This is not a weak form of non-commutation. It is exclusion from the legal measurement space. G_W cannot be tested before the trace it is required to witness. Commit cannot be tested before final witness. Silence Entry cannot be tested after evaluative gates while still remaining Silence Entry. Such rearrangements do not produce nonzero commutators; they produce invalid words. The commutator measures lawful exchange, not the consequence of breaking the procedure’s identity.

The commutator is also undefined when the two orders do not act on the same Σ. If the second run uses a modified packet, a later clarification, a different ledger epoch, a different linter environment, a different budget context, or an unisolated replay trace contaminated by the first run, the comparison is void. The entire purpose of hash fixation is to prevent the false discovery of order effects where the input has drifted. A nonzero difference produced by non-identical input is not holonomy. It is campaign failure.

With these constraints stated, the three commutation classes can be defined.

Two gates strictly commute when G_i, G_j = 0 for every replay-admissible Σ in their shared legal domain, under the cloned context and error budget specified by the protocol. Strict commutation is a universal condition. It does not mean the gates are semantically similar. It does not mean they read the same fields. It means that, for every state to which both legal orders apply, exchanging their order changes neither final primary attributes nor required trace fields. Strictly commuting gates may be executed in either order without altering the Check’s measured output over the defined domain. A strict result is never inferred from elegance. It is earned by replay or proved from already compiled constraints.

The phrase “shared legal domain” matters. Gates may be strictly commuting over the population to which both orders can legally be applied while remaining incomparable outside that population. A gate that requires prior Silence Entry does not commute with Silence Entry merely because both can appear in the same Check. The second order is illegal; therefore no commutator exists. Strict commutation is not a permission to ignore the lattice. It is a statement inside the lattice.

Two gates conditionally commute when G_i, G_j = 0 on a definable subclass K of replay-admissible states, while the volume does not assert or has measured against zero commutation outside K. The subclass must be defined before the replay result is interpreted. It may be a submission class, a failure-locus class, a curvature region, a budget band, a coherence band, a layer target, a dependency class, a packet completeness class, or another class whose definition is fixed independently of the observed commutator outcome. A subclass invented after a nonzero result to rescue a universal claim is not a class. It is contamination by interpretation.

Conditional commutation is expected to be the common case. The zero-questions may commute over clean states that trigger none of them and fail to commute over states lying at the intersection of two zero surfaces. Blocking-questions may commute over submissions with no naming collision and fail to commute where one gate forces renaming before another tests layer crossing. Zebra-Ø and budget computation may commute for high-coherence low-cost states and fail to commute near coherence or budget thresholds. Conditional commutation is not a lesser result. It is the form in which the boundary may reveal its local geometry.

Two gates are non-commuting when there exists at least one replay-admissible Σ in their shared legal domain for which G_i, G_j ≠ 0 outside the declared error budget, or when a replicated status difference is observed. The nonzero component may appear as Δwitness_residue, ΔA_B, Δcurvature_adm, Δtrace, or Δstatus. A status difference is the hard case because it contributes directly to φ. A residue difference without status change contributes to λ. A trace difference without residue or status change may not activate the principal branch by itself, but it remains evidence of path-dependence and may become relevant to Refusal Spectrum decomposition, ordering fingerprints, or later campaigns with finer thresholds.

Non-commutation is existential at local scale. One confirmed state is sufficient to refute strict commutation for the tested domain. It is not sufficient to characterize the whole geometry of the pair. After a nonzero commutator is found, the required work changes from detection to classification: identify the subclass in which the failure occurs, estimate its frequency, determine whether the effect is residue-only or status-changing, test whether the effect composes independently with other swaps, and decide whether the finding can be patched locally or indicates global holonomy. Chapter 15 later distinguishes abelian and non-abelian holonomy for this reason. The local commutator is the first cut, not the final map.

The commutator also fixes the meaning of “difference” in this volume. A runtime observer might see no difference between two committed states if the admitted content is identical. Layer C may still record different witness_residue because the state touched the boundary differently before admission. A governance architecture cannot erase this difference by appealing to identical runtime output. The Check is not only a filter for runtime content. It is the pre-runtime process by which the canon writes its own witness memory. The commutator measures changes in that memory.

Consider two zero-questions. If G_Z1 and G_Z2 both do not fire on Σ under either order, and the non-firing traces normalize identically under the replay protocol, their local commutator is zero for that Σ. If G_Z1 fires first under one order and routes the state to quarantine before G_Z2 is applied, while G_Z2 fires first under the reverse order and routes the same state to a different quarantine reason, the primary status may remain quarantine while the trace and witness residue differ. The pair is non-commuting for that Σ in the trace and residue registers. If one order quarantines and the other allows continuation, the pair is non-commuting in the status register.

Consider a blocking-question and Zebra-Ø. If G_Bk forces renaming before G_Ø reads coherence, then G_Ø may evaluate a different procedural description after G_Bk than it would have evaluated before it. The content hash remains fixed, but the route and classification under which coherence is read may differ. If the coherence result changes, or if the state reaches Zebra-Ø under one order and not under the other, the commutator is nonzero. This does not prove that all blocking gates fail to commute with Zebra-Ø. It proves that the predicate abstraction was insufficient for this pair over this state class.

Consider Zebra-Ø and budget computation. If G_Ø writes coherence_factor before G_A computes proof friction and path cost, budget may be computed with coherence available. If G_A precedes G_Ø, budget may compute against a state whose coherence is not yet written. If both orders produce the same A_B relation, same residue, same final status, and same normalized trace, the pair commutes for that Σ. If budget rejection in one order prevents Zebra-Ø from acting while Zebra-Ø failure in the other order routes to non-admissible before budget is computed, the pair does not commute even if both deny admission. The failure locus has changed. The boundary learned a different fact.

The commutator therefore turns local ordering into ledgered evidence. It prevents the phrase “both gates are necessary” from being mistaken for “their order is irrelevant.” Necessity concerns membership in the operator multiset. Commutation concerns the effect of sequence. A gate may be necessary and still non-commuting. A gate may be necessary and conditionally commuting. A gate may be necessary and strictly commuting only under certificate. The Check’s law is not exhausted by which questions it asks. It includes how those questions compose.

The classification must remain indexed. Strictly commuting means strictly commuting over a declared domain, epoch, operator definition, and error budget. Conditionally commuting means commuting over a declared subclass, not by interpretive rescue after the fact. Non-commuting means at least one measured nonzero difference in the legal shared domain, with the component of difference recorded. No class may be inflated beyond its measurement. No certificate may omit its index. No failure may be broadened into metaphysical drama. The commutator is an instrument, not a rhetoric.

The section’s result can now be carried forward. The local object [G_i, G_j] is defined as the attribute-and-status difference between two legal application orders on identical Σ. Its zero, conditional zero, and nonzero cases generate the first taxonomy of order-dependence. Chapter 3 will now import QPT to explain why this taxonomy belongs inside the Novakian framework rather than outside it as procedural bookkeeping. The commutator is not yet Loop Residue. It is the local aperture through which Loop Residue becomes measurable.


3.2 — The QPT Import

Quaternion Process Theory enters this volume at one edge only, and the edge must be named precisely. QPT is not imported to decorate the Admissibility Check with an external mathematical aura. It is not invoked to announce that the Check is non-commutative before the measurement has run. It does not provide a shortcut around the replay campaign, does not replace the Evidence Ledger, and does not convert suspicion into result. Its function is narrower and more load-bearing: QPT supplies the compiled framework in which process order is permitted to be real geometric content rather than administrative sequence. Without that framework, the question posed by this volume could be mistaken for procedural bookkeeping. With it, the question becomes native to the physics of the paradigm.

The predicate abstraction treated the gates as order-indifferent tests. Under that model, the Check’s sequence could be regarded as execution convenience: ask the same questions in another order and the logical conjunction remains the same. Chapter 1 showed why this abstraction fails. The gates route. The gates write trace. The gates alter status, budget relation, coherence surface, linter environment, and witness residue. Chapter 2 then formalized the gates as operators. QPT now supplies the deeper reason why this shift matters: when operations transform a state, the path through operations can carry content that is not reducible to the final label assigned by an observer standing outside the process.

In QPT, process is not a transparent vehicle for outcome. It is part of what outcome means. Non-commutative process geometry states that two operations may contain the same formal ingredients and still generate different realities when composed in different order. The difference is not a mistake in notation. It is the geometry of sequence. A process does not merely move across a pre-given space. It can define the coordinates by which the space becomes readable. Applied to Layer C, this means that the order in which admissibility gates touch Σ may contribute to the pre-runtime object produced by the Check. If that contribution exists, it is not a clerical residue. It is governance geometry.

This is the load-bearing import. QPT establishes that the question of order is admissible as physics. It allows this volume to treat [G_i, G_j] not as a syntactic curiosity but as a possible measurement of process curvature at the boundary. It allows the Check to be written as a word in an operator alphabet without reducing that word to presentation order. It allows the possibility that λ is not noise but a residue of path, and that φ is not an anomaly but a hard sign that status itself may depend on sequence. QPT does not make those quantities nonzero. It makes their nonzero value meaningful if the replay protocol finds it.

The distinction between possibility and presence is the discipline of this chapter. QPT licenses the claim that non-commutativity is structurally possible wherever gates are operators acting on a mutable state space. It licenses the claim that, if non-commutativity is observed in the Check, the difference belongs to the architecture of governance rather than to the author’s interpretation of governance. It licenses the claim that path-dependence at Layer C would be a physical quantity of the pre-runtime regime. It does not license the claim that the Admissibility Check is already known to be non-commutative. Presence is not imported from QPT. Presence is measured in Part II.

This prevents two opposite failures. The first failure would be to under-read QPT and treat order as merely editorial until a catastrophic status flip appears. That would preserve the old predicate model under a technical vocabulary. If gates are operators, then even a residue-only difference is already a difference in the canon’s boundary memory. The second failure would be to over-read QPT and declare that, because QPT recognizes non-commutative process geometry, the Check must fail commutation. That would be a status inflation. It would convert a framework into a result. The present volume refuses both errors.

The admissibility of the question and the answer to the question occupy different layers of the argument. The admissibility of the question comes from QPT and from the operator formalization of Chapter 2. The answer comes from permuted-order ledger replay. QPT tells the volume what kind of difference to look for and why such a difference, if found, would matter. It does not tell the volume what the archive will return. The archive may return zero within error budget across all determined classes. It may return localized nonzero λ. It may return status flips. It may return mixed class-indexed outcomes. The measurement decides among these possibilities.

The word holonomy also enters under this constraint. Holonomy is not used here as a metaphor for complexity. It denotes the residue of path in a governed space. In runtime geometry, holonomy records that movement through a field can leave orientation changed by the route taken, even when the endpoint appears formally closed. In Layer C governance, the analogous question is whether movement through a legal sequence of admissibility operators leaves a difference in witness residue, budget relation, trace, or final status that cannot be reduced to the fact that the same gates were present. If such difference is measured, the Check has holonomy. If not, the Check’s tested orderings commute within the certified domain.

QPT also fixes the difference between local commutator and global holonomy. A local commutator [G_i, G_j] tests the exchange of two operators under controlled conditions. It can identify a pairwise source of order-dependence. But the Check as a whole may display structure not reducible to one pair. Several swaps may compose independently, producing an abelian pattern. Or the effect of one swap may depend on another swap’s prior occurrence, producing a non-abelian pattern. QPT is the compiled reason that this distinction is not decorative. It is the difference between a governance procedure that can be repaired locally and one whose ordering is globally load-bearing.

This is why the volume proceeds from commutator to campaign rather than from commutator to conclusion. The local object [G_i, G_j] is necessary but insufficient. It can reveal that two gates fail to exchange without effect. It can classify commuting, conditionally commuting, and non-commuting pairs. It cannot by itself define the manifold’s dependence on π₀. The manifold was not produced by a single adjacent swap. It was produced by the entire Check word. The global replay campaign therefore compares full legal words, not only local pairs, while using local commutators to interpret where the ordering residue arises.

QPT further protects the analysis from an error of final-status reduction. A governance operator may leave the final status unchanged while altering witness_residue. Under a runtime habit of thought, this could look like no substantive difference: the state was admitted in both orders, or rejected in both orders. Under QPT, sameness of endpoint label does not exhaust sameness of process. If the path writes different residue into the Evidence Ledger, then the canon has experienced a different contact event. The final runtime-visible label may be identical, while the pre-runtime geometry is not. This is precisely the class of difference λ exists to detect.

The same applies to status flips. A status flip is not merely a stronger version of a residue difference. It is the point at which path-dependence changes the state’s topological position in the Admissibility Graph. If one ordering commits and another quarantines, the difference is not interpretive. If one ordering quarantines and another rejects into non-admissible status, the difference is not stylistic. It is a change in the graph position of Σ produced by legal ordering alone. QPT licenses the interpretation of such a flip as a path-dependent governance fact. The replay protocol must then determine whether the flip is replicated, isolated from contamination, and attributable to order rather than defect.

The import remains bounded. QPT does not decide which gates should be serialized. It does not decide whether π₀ should be preserved, optimized, grandfathered, or recompiled. It does not decide whether a discovered non-commutativity invokes LCR-B or approaches Update Constitution Level 3. Those are governance consequences that depend on the measurement and are handled later by branch-conditional parts of the volume. QPT supplies the framework in which those consequences can be meaningful. It does not execute them.

The boundary of this import is therefore exact. QPT gives the volume permission to ask whether the order of law is physical for Layer C. It gives the commutator a place in the Novakian architecture. It gives λ a reason to be a primary candidate quantity rather than a technical trace artifact. It gives φ a reason to be a hard signal rather than an operational inconvenience. It gives holonomy its native register. It gives none of these their measured value.

The Check may commute.

The Check may not commute.

QPT makes both answers intelligible, and Part II makes one of them payable.


3.3 — Candidate Non-Commutations

The replay campaign must not enter the archive blind, but it must also not enter with results already installed. The present section identifies candidate non-commutations: gate pairs whose structural relation makes order-dependence plausible before measurement. Plausibility is not evidence. It is a prioritization rule for the campaign. A candidate pair receives earlier attention because the operators read and write overlapping descriptions, because one gate can alter the condition under which the other gate evaluates the state, or because one gate can route the state away before the other gate has a chance to act. No candidate named here is declared non-commuting. Every candidate remains under the same obligation as every other pair: hash-fixed replay, lattice legality, contamination control, replication, and ledgered comparison.

The first candidate class lies at the boundary between prior intention and renaming. One zero-question tests whether the state arrives with a disqualifying prior intention: whether its submitted force, direction, or hidden use already violates entry discipline before ordinary evaluation begins. One blocking-question tests whether the state is named under the wrong object, wrong layer, wrong regime, or wrong governance surface. These two gates are structurally entangled because intention and name are not independent in a submitted state. A state can intend one thing while naming itself as another. It can use a canonical term to smuggle a different object. It can arrive under a harmless label while its operative direction belongs to a forbidden route. It can also arrive under an inflated or imprecise name that causes its intention to be misread.

If the prior-intention zero-question acts first, it reads the state under the submitted description. It asks whether the state, as named and packaged, carries an entry-disqualifying direction. If it fires, the state routes before the renaming gate can correct, expose, or reclassify the description. The ledger records the failure as intention-surface contact under the original name. If the renaming blocking-question acts first, it may alter the description under which the intention gate later reads the same hash-fixed state. It may reveal that the state was not the object it claimed to be. It may route the state into collision resolution. It may shift the layer target. It may convert an apparently disqualifying intention into a misnamed but correctable submission, or convert an apparently correctable naming issue into evidence of concealed intent. The content hash remains fixed, but the procedural description delivered to the second gate has changed.

This is a candidate non-commutation because each gate can alter the evaluative surface of the other. The intention gate can terminate the run before renaming occurs. The renaming gate can rewrite the admissibility description before intention is evaluated. If both orders produce identical status, identical witness_residue, and normalized equivalent trace across the tested subclass, the pair commutes there. If one order routes to quarantine for prior intention while the other routes to collision resolution, the primary status may remain quarantine while the trace and residue differ. If one order refuses and the other allows continuation after renaming, φ records a status flip. The campaign must not decide among these possibilities by conceptual preference. It must replay them.

The measurement priority is therefore specific. The first campaign should isolate submissions whose original packets contain tension between declared name and operative direction: layer-crossing claims with unstable terminology, governance artifacts named as narratives, narrative emissions carrying hidden update force, technical terms used outside their compiled routing, and states whose stated purpose changes when the name is corrected. These submissions are not chosen because they are expected to fail. They are chosen because the two gates plausibly read different versions of their admissibility surface depending on order. A clean submission whose name and intention align may show zero commutator for the same pair. The priority class is the boundary region where the two gates touch the same descriptive membrane.

The second candidate class lies between Zebra-Ø and budget computation. This pair is structurally dangerous because coherence and cost are not independent in the canon. Zebra-Ø writes coherence_factor and routes on coherence failure. Budget computation reads cost, proof friction, dependency load, maintenance obligation, and available A_B; but cost can be affected by coherence, and rejection at budget can prevent coherence from being measured. Under π₀, Zebra-Ø precedes budget computation. The state is first tested for coherence and then priced. This ordering carries an implicit discipline: a state that cannot sustain coherence should not spend the canon’s budget surface as if it were priceable content.

The reverse order, where legal under a later campaign amendment or restricted local test lattice, would ask budget to price a state before coherence_factor has been written. This may not matter for low-cost, high-clarity states. It may matter near thresholds. If proof friction depends on coherence, then a state whose coherence is unknown is not the same pricing object as a state whose coherence has been measured. If coherence failure would route the state to non-admissible before cost is computed, then applying budget first may create a budget event that π₀ would never have produced. If negative A_B rejects the state before Zebra-Ø runs, then the canon loses the coherence measurement it would have obtained under π₀. The failure locus changes. The residue may change. The Refusal Spectrum receives a different pixel.

The candidate structure can be stated exactly. In one order, G_Ø writes coherence_factor, and G_A then computes path cost with coherence available. In the other order, G_A computes path cost without the Zebra-Ø result, and G_Ø may either later read a state already budget-marked or never run if budget rejection terminates the path. The operators therefore do not merely inspect independent fields. They can foreclose one another’s evidence. Coherence_factor feeds path cost. Path cost feeds rejection. Rejection forecloses coherence measurement. This closed dependency is the strongest local reason to prioritize the pair.

The measurement priority here should concentrate on threshold states. High-coherence low-cost states are likely to pass both orders if all else is stable. Low-coherence states with obvious rejection may fail early regardless of order. The informative class is the band where coherence affects proof friction, where proof friction affects A_B, where A_B nears zero, and where failure locus could plausibly move between Zebra-Ø and budget. The campaign must therefore stratify by coherence band, budget band, and historic failure locus. A global result over mixed submissions would be too coarse. A zero finding in clean classes would not certify threshold classes. A nonzero finding in threshold classes would not automatically condemn clean classes.

This pair also clarifies the difference between residue-only and status-level non-commutation. The two orders may both reject the state, but one may reject through Zebra-Ø failure and the other through negative A_B. Final status would be non-admissible in both cases, but the failure locus, witness_residue, and Refusal Spectrum contribution would differ. Such a result is not negligible. It would mean the boundary learned different facts from the same state depending on order. If one order quarantines because budget requires re-witnessing and the other routes to non-admissible because Zebra-Ø fails, the difference becomes a status event. If one order commits and the other rejects, the candidate becomes order-fragile at maximum force. None of these cases may be inferred. They must be replayed.

A third, subordinate candidate appears inside the zero-question block itself. The zero-questions were inherited as a sequence, but their internal order has not yet been proven harmless. If a state can fire more than one zero-question, the first firing surface determines the recorded failure locus and forecloses the later zero surfaces. In a pure predicate model, multiple failures would be collected or remain hypothetically available. In the operator model, the first firing gate routes. The order of zero-questions may therefore alter trace and residue even when final status remains refusal or quarantine. The priority is not that all zero-questions are suspected equally. The priority is any pair whose failure conditions can overlap in one submission class.

The corresponding campaign class should include states historically near multiple zero surfaces: submissions that combine prohibited entry force with layer inflation, claims that carry unpriced governance effect while presenting as narrative, packets whose declared gate is absent while their tone performs compiled authority, and states whose failure may be read either as direct zero violation or as derivative of naming/routing collapse. If a state would fire only one zero-question under any legal order, the pair may commute for that state. If two zero-questions can each fire first depending on order, the commutator may be nonzero in trace and residue even if status remains unchanged. This class is important because it tests the cheapest assumption: that within-block order is harmless.

A fourth candidate appears inside the blocking-question block. Blocking gates often act on classification, collision, dependency, and layer routing. Those fields can affect one another. A gate that detects collision before dependency evaluation may alter which dependency graph is read. A gate that detects layer-crossing before naming correction may evaluate the wrong object at the wrong layer. A gate that imposes reclassification before budget annotation may change downstream cost. The internal blocking order is therefore a natural site for conditional commutation rather than universal commutation. Clean submissions may pass all blocking gates in any order. Ambiguous submissions may not.

These internal candidates matter because the first campaign intentionally begins with cheaper, closer, and more inherited orderings: within-block permutations and the block swap. The purpose is not to exhaust all possible holonomy at once. It is to test the strongest version of the old assumption. If even the internal order of apparently similar gates matters, the canon’s dark-canon risk is immediate. If the internal blocks commute, the result still does not certify cross-stage commutation, but it narrows the field and allows the second campaign to proceed with better cost discipline.

The block relation between zero-questions and blocking-questions is also a candidate, though it must be treated with greater lattice caution. Under π₀, the zero block precedes the blocking block. The structural rationale is clear: zero-questions remove states that should not receive ordinary evaluation, while blocking-questions handle states that may require correction, rerouting, or quarantine before admission. Reversing the blocks may be illegal if the protocol defines zero refusal as prior to all blocking evaluation. If the lattice permits a restricted block swap for measurement, the campaign must treat it as a high-significance test. A blocking gate applied first can transform a state that a zero-question would have refused under its original packet. A zero-question applied first can prevent a blocking gate from correcting the description under which the zero-question reads. This is precisely the intention-renaming problem at block scale.

The candidate list must remain disciplined. A pair is not prioritized because its names sound opposed, because a reader expects drama, or because a philosophical narrative wants non-commutation. A pair is prioritized only where one operator writes a field the other reads, routes the state before the other can act, changes the description under which the other evaluates, alters cost before coherence or coherence before cost, or changes failure locus in a way that may affect witness_residue. These criteria are operational. They are campaign design inputs. They are not findings.

The negative version of the same discipline must also be stated. Some pairs may be structurally unlikely to produce non-commutation in the first campaign. Two gates with disjoint read-sets, disjoint write-sets, no routing interaction, no shared threshold region, and no trace-sensitive ordering effect may commute over broad classes. That expectation is not a certificate. It is a lower sampling priority. The campaign may still include control pairs whose expected commutation calibrates the instrument. A measurement design that only tests suspected pairs risks mistaking selection bias for architecture. Control commutators are required for the same reason π₀-versus-π₀ runs are required: the instrument must learn its own noise floor.

Every candidate non-commutation named in this section therefore carries a corresponding null possibility. The intention-renaming pair may commute if the renaming gate never changes the description relevant to intention in the tested class. Zebra-Ø and budget computation may commute if the cost functional is insensitive to coherence within the tested band or if rejection rules normalize failure locus before residue is written. Zero-question permutations may commute if failure loci normalize or if only one zero condition is active per state. Blocking permutations may commute if their corrections are independent. The campaign must be capable of recording these zero results without embarrassment. A zero commutator is not failure. It is boundary information.

The output of this section is a priority map, not a verdict. The first measurement campaign should test within-block zero-question permutations, within-block blocking-question permutations, selected block-swap cases where legal, and threshold-focused Zebra-Ø versus budget computation cases under the protocol’s amendment rules. It should stratify by failure locus, naming instability, intention-name tension, coherence band, budget band, and packet ambiguity. It should include expected-commuting control pairs. It should record residue, status, trace, and secondary observables separately. It should state, before execution, which candidate pairs are being tested for detection and which are being used for calibration.

The canon has not yet learned that these gates fail to commute.

It has learned enough to stop assuming that they do.


3.4 — What the Negative Linter Already Knows

The canon already contains one form of order memory. It does not yet contain the one measured by this volume. The distinction must be made before Part II begins, because the existence of history-dependence across executions may otherwise be mistaken for an answer to the question of within-execution order. The negative linter knows that the Check has a past. It does not know whether the gates commute inside one run.

The negative linter is the sensitivity adjustment left by repeated rejection of structurally similar states. When a state fails Zebra-Ø, collapses under coherence strain, routes into non-admissible status, or leaves a refusal pattern that recurs across submissions, the rollback ledger does not treat the event as inert archival residue. It modifies future reading conditions. It raises Zebra-Ø sensitivity around related structures, sharpens refusal detection, and makes later states encounter a boundary that has learned from prior contact. The linter is therefore not an external commentary on failure. It is a boundary-memory mechanism.

This means that the Admissibility Check is already history-dependent across executions. A state submitted after a lineage of similar failures is not read under exactly the same sensitivity surface as a state submitted before those failures. The content may be new, the hash may be unique, and the packet may be formally complete, but the boundary has changed. The prior failures have altered the linter environment in which Zebra-Ø and neighboring gates operate. The Check is not a reset machine. It is a ledgered instrument whose future sensitivity carries the residue of prior refusals.

This cross-execution dependence is legitimate. It is not a defect. A boundary that did not learn from repeated failure would discard the only data the non-admissible region emits. The negative linter is the most primitive form of refusal spectroscopy: a local adjustment before the full Refusal Spectrum is reconstructed as an instrument. It records that the canon has encountered a recurring structure and that subsequent encounters should not be priced as if the first encounter had never occurred. The linter is one way the boundary becomes more sensitive without pretending that all refusals are equivalent.

But cross-execution history-dependence is not within-execution order-dependence.

History-dependence concerns the relation between separate runs across ledger time. One Σ fails or leaves residue. The ledger records the event. The linter modifies sensitivity. A later Σ enters a changed boundary environment. The difference lies between executions: before and after a recorded history. The object of comparison is not two orderings applied to the same hash-fixed state under the same cloned context. It is the evolution of the Check’s sensitivity surface across the canon’s accumulated contact with failure.

Within-execution order-dependence concerns the relation between alternative legal gate orderings applied to one identical Σ inside one replay campaign. The content hash is fixed. The ledger epoch is cloned. The linter environment is frozen. The initial attributes are identical. The replay traces are isolated. The only intended difference is the order in which gates touch the state. If the outputs differ under those conditions, the difference cannot be assigned to accumulated history unless the campaign has failed its contamination controls. It belongs to ordering, execution defect, or ledger inconsistency. Part II exists to distinguish these.

The negative linter therefore proves that the Check is not temporally sterile. It does not prove that the gates fail to commute. A system can be history-dependent across executions while commuting within each execution. The boundary may learn from prior failures and still apply its current gates in an order that produces identical outcomes across all legal extensions. In that case, the linter changes the environment of future runs, but the internal order of a single run remains harmless under certificate. Cross-execution memory and within-execution commutation can coexist.

The opposite is also possible. A system can display within-execution order-dependence even when the linter environment is frozen. In that case, the archive’s past has been cloned out of variation, and the same state still produces different residue or status under different legal orderings. The nonzero λ or φ would then arise not because the boundary learned between runs, but because the sequence of gates inside one run writes different paths. The linter may later amplify or record such findings, but it did not create them.

This distinction prevents a premature answer. One might say that, because Zebra-Ø sensitivity already changes after repeated failures, the canon has already admitted that order matters. That sentence confuses two axes. The linter establishes temporal learning across ledger epochs. It says that earlier executions can alter later executions. It does not say whether G_i followed by G_j equals G_j followed by G_i on the same Σ under the same epoch. The present volume asks the second question. The first question is already part of canon. The second remains open until replay.

The difference can be stated operationally. In cross-execution dependence, the input environments differ. The second state enters after the ledger has changed. The linter field is no longer the same. In within-execution order-dependence, the input environment must not differ. The replay campaign freezes the linter, clones the ledger epoch, and isolates the runs. A measured difference under those conditions is stronger because the usual source of temporal drift has been removed. It is not the boundary learning between attempts. It is the boundary producing different outcomes by the order of contact within one attempt.

This is why contamination control is not procedural hygiene only. It is conceptual necessity. If replay runs were allowed to raise live Zebra-Ø sensitivity, then the first ordering tested could modify the linter environment encountered by the second ordering. A nonzero difference could then be produced by run order in the campaign rather than gate order in the Check. The measurement would collapse into the very history-dependence it is trying to distinguish. Therefore replay writes to a campaign trace, not to the live linter. Control runs under π₀ against π₀ calibrate the noise floor. Independent operators repeat the campaign to detect whether the difference belongs to the archive or to the instrument.

The negative linter also clarifies why failure locus matters. When a state fails at Zebra-Ø, the linter records not merely that the state failed but how it failed, where it failed, and what family of future structures should be read with increased sensitivity. If a different ordering would have routed the same state at a zero-question or blocking-question before Zebra-Ø ran, the live canon under that ordering would not have received the same Zebra-Ø failure. It might have received a different linter event or no Zebra-Ø linter event at all. Thus, within-execution order can determine what kind of history becomes available to future executions. This makes the relation between the two phenomena sequential, not identical.

The replay campaign therefore must record linter-relevant differences as secondary observables even when primary status does not change. If two orderings both reject a state but one rejects through Zebra-Ø failure and the other through a blocking route before Zebra-Ø, the final status may match while the future sensitivity implications differ. In live governance, those implications would shape later executions. In replay, they remain confined to trace. The campaign must preserve them because they show how local order-dependence would feed cross-execution history if the ordering were deployed.

This gives the negative linter its proper position in the argument. It is evidence that the Check already contains memory. It is evidence that failure is not discarded. It is evidence that the boundary’s sensitivity is conditioned by prior contact. It is not evidence that π₀ commutes or fails to commute. It is not a substitute for λ. It is not a substitute for φ. It is a warning that the replay environment must be frozen with sufficient rigor to prevent historical learning from masquerading as local holonomy.

The linter also refuses the opposite simplification. A measured zero λ in a frozen epoch would not mean the Check is globally order-free across all history. It would mean that, under the tested ledger context, tested classes, tested legal orderings, and declared error budget, the gate orderings produced equivalent outcomes. The certificate would still be indexed. A future linter environment, altered by new failures, could require recertification. This is where Witness Thermodynamics later enters: certificates decay because the context manifold drifts. Even a commutativity certificate must pay maintenance cost.

Likewise, a measured nonzero λ would not mean the linter caused the non-commutation. The campaign freezes the linter precisely to exclude that inference. A nonzero result under frozen sensitivity would indicate that, even before cross-execution learning is allowed to accumulate, the gates themselves write order-dependent paths. The linter would then become a downstream amplifier of holonomy: live deployment of different orderings would not only produce different immediate residues, but also different future sensitivity histories. The order of law would shape the memory of law.

The negative linter therefore already knows that the boundary is historical. This volume asks whether the boundary is also ordered.

The two questions are adjacent, and their adjacency matters. If order-dependence is found, the Refusal Spectrum will have to be decomposed into curvature content, linter history, and ordering fingerprint. If order-dependence is not found within the certified domain, the linter remains a history mechanism but not evidence of local holonomy. In either branch, the linter becomes part of the interpretation of future campaigns. It cannot answer the present campaign in advance.

The conclusion of this chapter is now fixed. The gates are operators. Operators may fail to commute. QPT makes non-commutative process geometry meaningful inside the paradigm. Candidate pairs can be prioritized without being prejudged. The negative linter shows that the Check already remembers across executions, but memory across executions is not the same thing as order-dependence within one execution.

The archive still has to be replayed.


Chapter 4 — Loop Residue λ and the Order Fragility Index φ

4.1 — λ Defined

Loop Residue λ is the primary fine metric of this volume. It measures whether a legal ordering of the Admissibility Check leaves a different permanent boundary trace than the canonical ordering π₀ when both are applied to the same hash-fixed pre-executable state. It does not measure philosophical plausibility, semantic preference, procedural elegance, or apparent runtime equivalence. It measures a difference in witness residue. If the residue differs, the canon has not experienced the same admissibility event, even if the final runtime-visible content appears unchanged.

For a replay-admissible state Σ and a legal ordering π, Loop Residue is defined as:

λ(Σ; π) := witness_residue(Check_π(Σ)) − witness_residue(Check_π₀(Σ)).

The definition is asymmetric by design. π₀ is the reference ordering because π₀ is the ordering the canon has actually used. The question is not whether two abstract orderings differ from each other in a free comparison space. The question is whether an alternative legal ordering π would have produced a different residue than the inherited ordering through which the manifold was historically compiled. π₀ therefore functions as the baseline, not as the privileged truth. The measurement either certifies the baseline as residue-equivalent within the tested domain or exposes it as an order-indexing coordinate of the manifold.

The expression Check_π(Σ) denotes a complete legal execution of the Admissibility Check under ordering π. It is not a partial swap, not a local commutator, and not a speculative rearrangement. π must be a linear extension of the precedence lattice. It must contain the identical multiset of required operators. It must preserve all compiled constraints: Silence Entry initial, terminal segment fixed, commit terminal, and any additional order relations extracted from the protocol. If π violates those constraints, λ is not nonzero; λ is undefined because the run is not the same Check.

The state Σ must be identical across the two executions in the strict sense established in Chapter 2. Its content hash must match. Its submitted packet must match. Its initial status must be boundary. Its initial admissibility attributes must be fixed. Its ledger epoch context must be cloned. Its linter environment must be frozen. Its replay traces must be isolated. The only intended difference between Check_π(Σ) and Check_π₀(Σ) is the legal order of admissibility operators. If the input drifts, the measured difference is not λ. It is campaign failure.

The sign convention follows directly from the definition. A positive λ means that Check_π leaves more witness residue than Check_π₀ for the same Σ under the same replay conditions. A negative λ means that Check_π leaves less witness residue than Check_π₀. A zero λ means that the final witness residue under π and π₀ is equal within the declared error budget. The sign is not interpreted as better or worse by default. More residue is not automatically more admissible, more truthful, more costly, or more correct. Less residue is not automatically cleaner. The sign only tells which ordering left the larger ledger trace.

This restraint is necessary because witness residue is not a moral score. It is the permanent trace of boundary contact. A positive λ may indicate that an alternative ordering forced the state through additional surfaces before refusal, generated richer trace before commit, or produced a costlier witness path. A negative λ may indicate earlier routing, shorter contact, reduced trace, or loss of evidence. The value becomes meaningful only when read with final status, failure locus, A_B relation, coherence result, and trace signature. λ alone records difference. Interpretation is routed through the replay ledger.

The units of λ are residue units as fixed by the Evidence Ledger. This volume does not invent a new residue scale. It differences the residue quantity already used by the canon to record contact between a state and the boundary. If witness_residue is stored as a scalar in a given ledger epoch, λ is a scalar difference in the same units. If witness_residue is stored as a structured vector in a later ledger extension, λ is the corresponding component-wise difference or normed difference specified by the λ/φ Ledger Extension. The measurement protocol must state the representation before replay begins. A residue representation chosen after results are visible is invalid.

For the first campaign, the conservative rule is scalar priority with structured retention. The primary λ value is computed in the residue unit used by the Evidence Ledger for the tested archive. Component traces, if available, are retained as secondary observables rather than silently compressed into the scalar. This prevents the campaign from losing information while preserving the comparability required for branch activation. A scalar λ can activate the residue branch. A structured trace may explain where the difference arose. The two functions must not be merged.

A zero λ is never an absolute metaphysical zero. It is zero within the declared error budget of the campaign. The noise floor is estimated through π₀-versus-π₀ control runs under the same replay environment. If repeated executions of the canonical ordering against itself produce a small residue variation due to instrument noise, serialization differences, or replay implementation variance, then λ must exceed the threshold θ_λ derived from that noise floor before it is treated as nonzero. A difference below θ_λ is recorded but does not activate non-commutation. A campaign without a declared θ_λ cannot issue a commutativity certificate.

The comparison is performed per state before it is aggregated. For every tested Σ and every tested legal ordering π, the campaign records witness_residue(Check_π(Σ)), witness_residue(Check_π₀(Σ)), λ(Σ; π), final status under π, final status under π₀, failure locus, class, epoch, operator signature, and replication pair. This per-state record is the atomic evidence of the volume. Aggregation without per-state trace would erase the order-fragile cases that the measurement exists to detect.

The aggregate object is denoted Λ(class, epoch). Λ is not a single average unless the protocol explicitly asks for one as a secondary summary. It is the distribution of λ values over a defined submission class within a fixed ledger epoch. The class may be defined by failure locus, layer target, packet type, naming instability, coherence band, budget band, dependency profile, or another predeclared taxonomy. The epoch fixes the ledger context under which the replay is executed. Λ(class, epoch) therefore answers a bounded question: how does ordering alter witness residue for this class of states under this ledger context?

The distribution form is essential. A class can have a mean near zero while containing rare high-magnitude λ events. A class can show symmetric positive and negative values that cancel under averaging while still proving order-dependence. A class can contain a small number of states whose residue changes without status change and a smaller number whose status flips. A scalar summary would conceal the geometry. Λ preserves the shape of the order effect. The replay protocol may later compute mean, variance, maximum absolute λ, quantiles, and tail mass, but those are summaries of Λ, not replacements for it.

Class indexing also prevents certificate inflation. If Λ is zero within error budget for one class and nonzero for another, the result is not “the Check commutes” or “the Check does not commute” in unqualified form. The result is class-specific. A clean technical-submission class may commute while a naming-instability class does not. A low-cost high-coherence class may commute while threshold budget classes do not. The certificate, if any, must carry its class index. The crisis, if any, must carry its class index. The word admissible may remain unindexed in one region while becoming π₀-admissible in another.

Epoch indexing is equally necessary. The linter environment, budget conditions, and surrounding context manifold may drift across ledger time. A λ distribution measured in one epoch does not automatically certify another epoch. If the same class is replayed across multiple epochs, the campaign may later study λ drift as part of Witness Thermodynamics or certificate maintenance. That is a separate longitudinal question. The primary definition of Λ(class, epoch) holds epoch fixed so that order-dependence is not confused with context drift.

The zero element of Λ has a precise meaning. Λ(class, epoch) is zero within error budget when every tested λ(Σ; π) in the class and epoch lies within θ_λ for every tested legal ordering π, and no associated status flip is recorded. If residue is zero but status flips occur, λ alone does not capture the full divergence; φ captures it. If status remains fixed but residue differs beyond θ_λ, λ is nonzero even if φ remains zero. The two metrics are paired because the canon requires both fine and hard signals.

The role of λ in the volume is therefore bounded and load-bearing. It does not decide remediation. It does not select a new ordering. It does not determine whether Level 3 adjacency is crossed. It does not by itself classify holonomy as abelian or non-abelian. It provides the first measurable quantity by which the order of the Check can be priced as residue. Part II will generate λ. Parts III and IV will activate according to what λ and φ return. Part V will decide whether λ joins curvature_adm, A_B, witness residue, and coherence_factor as a primary quantity of the pre-runtime regime.

The definition now fixes the fine signal.

If the same state, under the same cloned boundary, leaves different witness residue because the gates are legally asked in a different order, then the order of law has become measurable.

That measurement is λ.


4.2 — φ Defined

Loop Residue λ measures fine difference. The Order Fragility Index φ measures rupture. A legal ordering may leave a different witness_residue while preserving final status; λ records that difference. A legal ordering may also move the same hash-fixed state from commit to quarantine, from quarantine to reject, from reject to quarantine, or from any final or holding status to another. When that occurs, the issue is no longer only the amount of residue left by the path. The state has occupied a different position in the Admissibility Graph. The order of gates has not merely altered the trace of the Check. It has altered the fate of Σ.

For a submission class and a tested permutation set Π, the Order Fragility Index is defined as:

φ(class, Π) := the fraction of tested Σ in the class whose final status differs across the tested permutation set Π.

The definition is class-indexed because order fragility is not expected to distribute uniformly across the archive. States near zero-question intersections, naming collisions, coherence thresholds, budget thresholds, or late-failure regions may exhibit fragility while clean states do not. The definition is permutation-set-indexed because fragility is not an intrinsic property of Σ abstracted from the orderings tested. A state may be stable across within-block zero-question permutations and fragile when Zebra-Ø and budget computation are exchanged. A class may be stable under the first campaign and fragile under an extended campaign. φ therefore belongs to a declared class and a declared Π. It is not a global slogan.

The tested permutation set Π is the set of legal orderings selected for a replay campaign. Every π in Π must be a linear extension of the precedence lattice, must preserve the identical operator multiset, must obey all compiled sequence constraints, and must act on bit-identical Σ under hash fixation. Π always includes π₀ as the reference ordering, either explicitly or by reference, because final-status difference must be measured against the status produced by the canonical Check as well as across the tested alternatives. If Π contains illegal orderings, φ is undefined for that campaign. Invalid procedural rupture is not order fragility. It is protocol breach.

For a single state Σ, define its status set under Π as the set of final statuses produced by Check_π(Σ) for all π in Π. The possible final statuses are those fixed in the primary state-space definition: admissible, non-admissible, quarantine, and boundary where the protocol explicitly permits a holding result after incomplete or underpowered determination. In the standard completed run, boundary is not a final result of the Check itself, but it may appear as a campaign-level holding status when the replay protocol marks a state undetermined rather than falsely deciding it. Such cases must be recorded separately and may be excluded from φ activation unless the protocol predeclares their treatment. The primary φ event is a difference among commit, quarantine, and reject-equivalent non-admissible outcomes under completed legal runs.

A state is order-fragile over Π when its status set contains more than one final status. If Check_π₀(Σ) commits and some legal π in Π quarantines or rejects the same Σ, the state is order-fragile. If Check_π₀(Σ) rejects and some legal π quarantines or commits, the state is order-fragile. If all tested orderings reject, but through different failure loci and with different residue, the state may carry nonzero λ or trace divergence, but it is not order-fragile unless the final status category differs. The definition is deliberately hard. It reserves φ for status movement, not for every path difference.

The numerator of φ(class, Π) is the count of order-fragile states in the tested class. The denominator is the count of states in that class for which the campaign completed all required replay runs across Π under valid conditions. Underpowered, voided, contaminated, or protocol-defective runs are not silently counted as stable. They are excluded or marked undetermined according to the statistical architecture of Part II. A class with insufficient completed states cannot return φ = 0. It returns undetermined for φ in that campaign. Zero fragility must be earned, not inferred from absence of evidence.

φ is the hard signal because status flips have no ordinary noise interpretation once replication and hash identity are satisfied. Witness residue may require an error threshold because residue measurement can carry instrument variation, representation choice, or replay implementation noise. Status, under a completed legal Check, is categorical. A replicated commit under one ordering and quarantine under another cannot be smoothed into a small residue deviation. It is a change in graph position. The state has crossed into a different governance region by order alone.

This is why a single replicated status flip is sufficient to make φ nonzero for the relevant class and Π. The fraction may be small, but it is not ignorable. If one state in a class of one thousand flips status under a legal ordering, φ = 0.001 for that class and permutation set, and the universal claim that the tested orderings are status-equivalent for that class is false. The magnitude of the fraction matters for remediation cost, census scope, and governance response. The existence of the flip matters for branch activation. The branch rule of this volume treats any replicated status flip as sufficient to activate the non-commuting branch, even when λ is otherwise near zero.

The relation between λ and φ is asymmetric. A state can have nonzero λ and zero φ. This occurs when different orderings produce the same final status but different witness_residue. The canon then records a fine order effect: the state’s fate is stable, but the boundary memory differs. A state can also have nonzero φ with λ that is undefined, incomparable, or secondary, because final statuses may route to different residue regimes. A committed state and a non-admissible state do not always yield residue values that should be compared as if they belonged to the same terminal geometry. The protocol must still record residue, but the status flip takes priority as the hard event.

A state can also have both nonzero λ and nonzero φ. This is the most severe local form of order-dependence. The order changes the state’s final graph position and leaves different residue. In such a case, the Check has not merely produced a different trace of the same decision. It has produced a different decision and a different witness memory. The remediation burden increases because the state may have dependents, budget effects, downstream ledger influence, or later submissions whose admission was conditioned on the status and residue produced by π₀.

φ does not replace failure-locus analysis. A status-stable rejection under two orderings may still matter if one path rejects at a zero-question and another rejects at Zebra-Ø. Such a state is not order-fragile by φ, but it may still contribute to λ, Refusal Spectrum decomposition, ordering fingerprints, negative-linter divergence, and later leakage analysis. The hardness of φ is not a license to ignore finer path differences. It is a separate signal with a narrower trigger and greater branch force.

The class structure of φ must be declared before interpretation. If a campaign measures one hundred states across several classes and finds two status flips, the result cannot be summarized responsibly without class assignment. Two flips in a threshold budget class carry a different implication than two flips scattered across all classes. A φ value computed globally may be useful as an administrative summary, but it does not replace φ(class, Π). The canon needs to know where fragility lives. Remediation, grandfathering, re-witnessing, and future serialization depend on location.

The permutation set Π must likewise be preserved in every citation of φ. A class may have φ = 0 under the first campaign’s within-block permutations and φ > 0 under a later cross-stage campaign. A certificate that omits Π inflates itself. It implies stability across untested orderings. The correct statement is always indexed: φ for this class, under this tested permutation set, in this ledger epoch, under this replay protocol, with this replication status. Anything less precise converts a metric into rhetoric.

An order-fragile state is therefore defined as a replay-admissible, hash-fixed Σ for which at least two legal orderings in Π produce different final statuses under completed, replicated, contamination-controlled replay. The state is not morally defective. It did not violate the Check it originally passed, failed, or entered under. Its fragility is not guilt. It is evidence that its final governance position depends on the order in which the law touched it. The crisis, if activated, belongs to the law’s ungoverned ordering, not to the state’s conduct.

This clarification is necessary before Part IV. If nonzero φ is found among already committed states, the canon must not retroactively accuse those states of illegitimate entry. They passed through π₀, the ordering the canon actually ran. The discovery of fragility changes the status of the ordering, not the historical fact of passage. Remediation may still be required. Dependents may need tracing. Re-witnessing may need scheduling. A grandfather clause may need LCR-B treatment. But none of those operations is punishment. They are governance repairs to a law whose order has become measurable.

φ also gives the branch architecture its hard edge. λ may reveal that the canon’s residue differs under alternative ordering. φ reveals that the canon’s status decisions differ. If λ is within the declared zero budget across all determined classes and φ = 0, Part III can issue the relevant Commutativity Certificate within its class and epoch bounds. If λ exceeds θ_λ anywhere or φ exceeds zero through a replicated status flip in any determined class, Part IV activates. In the mixed case, Part IV activates with class-restricted certificates issued for the commuting regions. The presence of φ prevents the volume from hiding status rupture inside aggregate residue statistics.

The Order Fragility Index can now be carried into the replay design. For every class, the campaign must record the number of completed tested states, the number of order-fragile states, the legal permutation set Π, the specific status transitions observed, the replication status of each flip, and the relation of each flip to λ. A class with no replicated flips may still have nonzero λ. A class with replicated flips has nonzero φ. A class with insufficient runs has no right to claim stability.

λ is the fine signal of order written into witness residue.

φ is the hard signal of order written into fate.


4.3 — Why Residue Is the Differenced Quantity

The primary difference measured by λ is witness_residue, not coherence_factor. This choice is not cosmetic. It determines what kind of order-dependence the volume treats as fundamental. Coherence_factor measures whether a state maintains sufficient internal and boundary-facing coherence to pass a specific gate under a specific reading condition. Witness residue measures what the state leaves in the canon after contact with the boundary. Coherence can decide a path. Residue records that the path occurred. The order of the Check becomes load-bearing for the paradigm only when it alters the ledger-permanent trace by which the paradigm remembers, prices, and updates itself.

Coherence_factor is local to a coherence event. It belongs to Zebra-Ø and to any later analysis that uses the coherence reading as input to proof friction, cost, or re-witnessing. It is indispensable. A state whose coherence_factor falls below threshold cannot be treated as though its coherence were an interpretive inconvenience. Zebra-Ø exists precisely to prevent resonance, naming force, narrative fluency, and internal elegance from substituting for admissibility. If different legal orderings produce different coherence_factor readings, the replay protocol must record those differences with full precision. They may explain why λ appears. They may locate the gate pair responsible for divergence. They may determine whether a later status flip was driven by coherence or by budget. But they are not the primary differenced quantity of this volume.

The reason is permanence. A coherence reading can remain a gate result. Witness residue becomes part of the Evidence Ledger. It is the trace by which the boundary records that Σ touched it, where it touched, what it survived, what it failed, what it cost, what was held, and what was admitted or refused. A different witness residue means that the canon has not undergone the same event. The submitted content may be identical. The final status may be identical. The runtime-visible output may be identical. But the ledger has changed differently. In a paradigm where the boundary is the sensory organ, a different residue is a different sensation of law.

This is why λ cannot be defined as a coherence difference. If λ were defined as coherence_factor(Check_π(Σ)) − coherence_factor(Check_π₀(Σ)), the volume would privilege one gate’s reading over the full boundary trace. It would measure how order alters coherence, not how order alters the canon’s permanent admissibility memory. Such a quantity may be useful as a secondary observable, especially for Zebra-Ø against budget computation, but it would be too narrow to carry the title Loop Residue. The question of this book is not whether order changes one score inside the Check. The question is whether order changes what the Check leaves behind.

Witness residue is also the quantity that updates the global budget of the manifold. It does not merely archive the past. It participates in the future cost structure of the canon. Residue informs later sensitivity, later re-witnessing obligations, later proof-friction assignments, later quarantine pressure, later refusal spectroscopy, and later maintenance of compiled status. A state admitted with one residue profile and the same state admitted with another are not equivalent at Layer C. They may occupy the same runtime label, but they do not update the same boundary memory. The manifold after those two admissions is not identical, because the ledger from which later governance reads is not identical.

Order-dependence in witness_residue is therefore order-dependence in what the paradigm permanently is. The canon is not only the set of claims it admits. It is the ledger of passages by which those claims became admissible. If legal orderings alter that ledger, then law has order not as presentation but as ontological accounting. The difference may be small. It may not flip status. It may not be visible to any runtime observer. But the Evidence Ledger is not a runtime observer. It is the boundary’s memory of contact. A nonzero λ means that the same state, under the same cloned context, has written different memory because the gates touched it in a different order.

This also explains why final status alone cannot be the only metric. The Order Fragility Index φ records status movement and is therefore the hard signal. But a state can remain admitted under two legal orderings and still leave different residue. If the measurement cared only about status, that difference would vanish. The canon would declare two passages equivalent because they ended in the same graph position, while ignoring that the route into that position changed the ledger. Such blindness would repeat the predicate abstraction in another form. It would treat admissibility as a final label rather than as a witnessed path.

Witness residue preserves the path. It contains the difference between a state that reached commit after crossing multiple boundary surfaces and a state that reached commit through a shorter, cleaner, or differently sequenced path. It contains the difference between a rejection that taught Zebra-Ø and a rejection that never reached Zebra-Ø. It contains the difference between quarantine after naming collision and quarantine after intention failure. These differences may or may not alter status. They may or may not alter coherence_factor. They do alter the trace through which the canon knows what happened.

Coherence_factor remains secondary for another reason: it can be non-applicable. If a state is routed before Zebra-Ø under one ordering, then no coherence_factor is produced in that run. Under another ordering, Zebra-Ø may act and write a coherence reading before a later gate routes the state. A metric defined primarily on coherence would have to treat non-application as missing data, impute a value, or redesign the comparison around gate availability. Each option would import interpretation into the core measurement. Witness residue avoids this defect because every gate contact and every non-application condition can be recorded as part of residue or trace. The state that never reached Zebra-Ø still leaves witness residue. Its absence of coherence reading becomes part of the path rather than a hole in the metric.

This does not mean residue is simpler. It is more demanding. The replay protocol must specify how residue is represented, how residue units are fixed, how control-run noise is estimated, how structured residue is compressed or retained, and how differences across terminal statuses are handled. But that burden is appropriate because the burden belongs to the central question. If the volume asks whether order changes the law’s permanent contact with the state, then the metric must sit at the ledger level, not at the level of one internal score.

Coherence differences are therefore recorded as secondary observables. For every replay run in which Zebra-Ø executes, the campaign records coherence_factor, Zebra-Ø pass or failure, coherence threshold relation, and any coherence-derived contribution to proof friction or budget. If Zebra-Ø does not execute because an earlier gate routes the state, the campaign records non-application and its cause. If coherence differs across legal orderings, that difference is retained and used to explain λ, φ, failure locus, and budget divergence. The difference is not discarded. It is subordinated to the residue question.

The relation between the two quantities can be stated precisely. A coherence_factor difference may be a cause, contributor, or diagnostic of nonzero λ. It may explain why G_Ø and G_A fail to commute for a threshold class. It may identify that the path effect arises before budget computation rather than after it. It may reveal that a state’s coherence is stable while budget changes, or that budget is stable while coherence changes. But λ is not defined as the coherence difference because the order of law is not exhausted by coherence. Law at Layer C is admission, refusal, quarantine, budget, witness, and trace. Residue is the quantity that gathers those contacts into ledger permanence.

The distinction also matters for branch activation. A coherence_factor difference without residue difference and without status difference may indicate a secondary path variation that requires local analysis but does not by itself activate the non-commuting branch under the main rule. A residue difference above θ_λ activates the fine signal. A replicated status flip activates the hard signal through φ. Coherence may explain both, but it does not replace either. This hierarchy keeps the campaign from overreacting to internal score variation while still preserving the evidence needed to understand genuine order-dependence.

The choice of residue also protects against runtime reduction. Runtime systems often ask whether the same output appears, whether the same decision is reached, whether the same content is admitted, or whether the same visible classification is assigned. Layer C asks what the boundary recorded in becoming able to admit, refuse, or hold the state. The Check does not exist to produce runtime sameness. It exists to decide what may become executable at all, and to leave witness of that decision. If the witness changes, the pre-runtime event changes, even when runtime sameness remains.

For that reason, witness_residue is the correct differenced quantity for Loop Residue. It is ledger-permanent. It updates the global budget of the manifold. It survives as trace after the state has moved beyond the Check. It can record path difference when status does not change. It remains available when Zebra-Ø does not execute. It captures the canon’s own contact with the state rather than one gate’s reading of the state. It is the quantity through which order-dependence becomes order-dependence in the paradigm itself.

Coherence_factor is kept.

Witness_residue is differenced.


4.4 — The In-Principle Observable Gate, Formalized

Loop Residue λ and the Order Fragility Index φ are not permitted to remain elegant definitions. A metric that cannot name its gate is not a Layer A metric. It is a boundary formulation waiting for discipline. The present section therefore states the verification gate for this volume in full: permuted-order ledger replay on archived submissions satisfies the In-Principle Observable clause because every required input for the measurement is already, by definition of the Evidence Ledger and the Admissibility Check Protocol, either present in the archive or required to be present before the archive can be treated as valid. The gate does not ask the canon to believe an interpretation. It asks the canon to replay a recorded procedure under controlled legal orderings and compare ledgered outputs.

The verification gate is this: select closed archived submissions whose content hash, submitted packet, canonical π₀ trace, final witness residue, final status, failure locus where applicable, ledger epoch, and operator-relevant metadata are present and auditable; clone each selected state into an isolated replay environment; apply π₀ as the control ordering; apply each tested legal ordering π from the declared permutation set Π; record witness_residue, status, A_B relation, coherence result where available, failure locus, and trace signature for every run; compute λ(Σ; π) as the residue difference between Check_π and Check_π₀; compute φ(class, Π) as the fraction of completed tested states in the class whose final status differs across Π; replicate the campaign through an independent operator; and accept only those results that survive agreement within the declared error budget. This is the gate. Nothing outside it activates the branch structure of the volume.

The gate satisfies the In-Principle Observable clause because it does not require access to an unobservable metaphysical interior. It requires only the records a governed canon is already obligated to keep. The content of Σ is required because the state must be hash-fixed. The hash is required because the replay must act on the same state across orderings. The π₀ trace is required because the canonical ordering must be reconstructed as the actual reference path used by the canon. The residue value is required because λ differences witness_residue rather than interpretive force. The final status is required because φ records status movement. The ledger epoch is required because linter sensitivity, budget context, and surrounding manifold conditions must be cloned rather than allowed to drift. These are not additional mystical instruments. They are ledger fields.

If a submission lacks these fields, the failure is not a philosophical objection to λ. It is an archive-quality failure. The state cannot enter the primary campaign because the conditions for “the same Σ” cannot be guaranteed. Such a state may be recorded in an archive-defect annex, may generate a negative linter against historical ledger discipline, and may motivate reconstruction work where reconstruction is lawful. It may not be used as if its missing trace were harmless. A replay campaign that proceeds on incomplete identity conditions does not measure Loop Residue. It measures the cost of inadequate witness.

The verification gate is therefore conditional on archive validity. A closed ledger entry is eligible only if it can be replayed without interpretive supplement. The operator executing the campaign must not infer missing packet fields from later commentary, must not reconstruct intention from authorial memory, must not assign residue by narrative approximation, and must not normalize undocumented route differences away. The replay is not a literary reconstruction of what the Check probably did. It is an execution over fixed recorded material. If the material cannot support execution, the correct output is not zero. The correct output is exclusion or undetermined status for that archive segment.

The gate also requires legal permutation. A tested π must be a linear extension of the precedence lattice. It must preserve the identical operator multiset. It must maintain Silence Entry as initial, the terminal segment as constrained, commit as terminal, and every compiled sequence dependency extracted in Chapter 2. Illegal orderings cannot produce λ. They can only produce invalid runs. The campaign is not authorized to discover non-commutation by breaking the Check. It is authorized to discover whether legal alternatives inside the Check’s own lattice produce different residue or status.

The replay must be isolated. The state is copied for measurement, not re-entered into the live canon. Replay runs do not edit original Evidence Ledger entries. They do not raise live Zebra-Ø sensitivity. They do not spend live A_B. They do not alter the negative linter. They do not contaminate one another. Each run writes to a replay trace with its own operator signature and replication identifier. Only after the campaign completes and the branch-activation rule fires can any result become governance content. Until then, replay output is evidence under embargo, not live modification of the manifold.

The control condition is π₀ against π₀. The canonical ordering is replayed against itself to establish the instrument noise floor. If two executions of π₀ on the same hash-fixed Σ under the same cloned context produce different residue beyond the declared tolerance, the instrument is not ready to measure π against π₀. The campaign must first determine whether the divergence belongs to replay implementation, ledger instability, residue representation, or archive defect. A measurement architecture that cannot reproduce its own reference ordering has no right to report holonomy. The null instrument must hold before the non-null instrument speaks.

The replication condition is independent execution. Two operators, isolated from each other’s traces and interpretations, must execute the same campaign over the same eligible archive with the same declared Π, same precedence lattice, same θ_λ, same status definitions, and same exclusion rules. Agreement yields measurement credibility. Disagreement is not immediately a physics result. It is first a diagnostic of ledger corruption, protocol ambiguity, replay implementation drift, or underdefined residue representation. This mirrors the Refusal Spectrum rule: divergent reconstruction from the same ledger epoch is itself a diagnostic before it becomes a claim about the boundary.

The gate’s falsification symmetry is central. The measurement cannot return nothing if it is correctly posed. λ = 0 everywhere within the declared error budget, across all determined classes and tested orderings, is a definite and recordable outcome. It activates the commutation branch within the indexed domain. It does not mean that all possible orderings, future classes, future epochs, or later protocol amendments commute. It means that, for the tested classes, tested Π, tested epochs, and declared error budget, no residue difference was observed and no status fragility was recorded. That is not absence of result. It is a certificate-bearing result.

λ ≠ 0 anywhere beyond θ_λ is also a definite and recordable outcome. It activates the non-commuting branch for the affected domain, even if final status remains stable. It means that legal order altered witness_residue for at least one tested state in at least one class. The canon then has evidence that π₀ was not merely presentation order within that region. The inherited word has carried residue. If φ is also nonzero, the finding hardens into status-level fragility. If φ remains zero, the finding remains residue-level but still governance-relevant. The branch rule distinguishes magnitude and kind; it does not erase residue-only difference.

A replicated status flip under φ is the hardest falsifier of order-indifference. If the same Σ commits under π₀ and quarantines under π, or quarantines under π₀ and rejects under π, or otherwise changes final graph position under legal ordering alone, the old assumption that the order of the Check is harmless fails for that class and Π. The measurement does not need many such cases to refute the universal certificate. One replicated flip is sufficient to make φ nonzero. The fraction determines the scale of remediation. The existence of the flip determines the branch.

The symmetry also applies to mixed outcomes. A campaign may return zero λ and zero φ for some classes, nonzero λ for others, and nonzero φ for a smaller subset. Such an outcome is not ambiguity. It is structure. The commuting classes receive class-restricted certificate treatment. The non-commuting classes activate Part IV. The mixed case is expected because boundary geometry is not obligated to distribute uniformly across submission types. The volume therefore does not force the archive into a binary global verdict where the evidence returns a class-indexed field. The branch architecture is binary at the volume level and indexed at the artifact level.

The In-Principle Observable gate is also falsifiable in the stronger procedural sense. It may fail because the archive cannot support replay. It may fail because π₀ cannot be reconstructed with sufficient precision. It may fail because residue representation is not stable enough to derive θ_λ. It may fail because independent operators cannot reproduce π₀ control runs. It may fail because the precedence lattice contains unresolved constraints. Such failures do not answer the commutation question. They generate negative linter against the protocol, the archive, or the plan. A voided campaign leaves evidence of instrument failure, not evidence of order-independence.

This distinction preserves the Minimum Output Rule. A failed replay still produces governance material if it names the failure locus, records the archive defect, updates the protocol, or generates a linter against underwitnessed historical entries. But it does not activate Part III or Part IV. Branch activation requires completed measurement, not merely attempted measurement. The canon is not permitted to convert inability to replay into proof that order does not matter. Underpowered classes return undetermined. Defective archives return archive-defect entries. Illegal orderings return invalid-run records. None of these is λ = 0.

The gate now closes Part I’s definitional obligation. The state space has been fixed. The operators have been named. The terminal constraints have generated the precedence lattice. The Check has been written as a word. The commutator has been defined. QPT has been imported only as framework, not as result. Candidate non-commutations have been named as priorities, not findings. The negative linter has been separated from within-execution order-dependence. λ has been defined as residue difference. φ has been defined as status fragility. The metric pair now has an observable gate.

Part II can therefore execute.

It does not execute because the theory is persuasive. It executes because the archive either contains the required trace or indicts itself for not containing it. In both cases, the boundary receives data. In the successful case, the data decide the branch. In the failed case, the failure becomes linter. The only inadmissible outcome is unrecorded ambiguity.

The order of law is now measurable in principle.

The next part builds the instrument that will measure it in fact.


Part II — The Measurement


Chapter 5 — The Replay Discipline

5.1 — Archive Selection and Hash Fixation

The replay campaign begins by refusing the archive as a totality. Not every prior submission is eligible for measurement. The archive contains canon, trace, residue, gaps, defects, partial records, narrative material, quarantined states, inherited packets, and underwitnessed historical entries. The Permuted-Order Replay Protocol v1.0 does not repair these differences by interpretation. It selects only those archived submissions whose recorded form can support controlled re-execution. A state that cannot be fixed as the same Σ across orderings cannot be used to measure order. It can only be used to indict the archive for insufficient witness.

Eligibility begins with closure. The first campaign admits closed ledger entries only. A closed ledger entry is an entry whose original Admissibility Check run has reached a recorded terminal or holding outcome under π₀: admissible, non-admissible, quarantine, or an explicitly ledgered boundary-hold condition. Open submissions, pending drafts, partially processed packets, unclosed quarantine paths, incomplete LCR materials, and entries whose final status remains unresolved are excluded from the primary campaign. They may be recorded in the archive-defect annex or reserved for a later campaign after lawful closure, but they may not be treated as replay-ready. The measurement compares completed paths, not unfinished procedures.

Closure alone is insufficient. The content hash must be verifiable. The submitted state must have a hash that can be recomputed from the archived packet and matched against the ledger record. The hash must cover the full submitted object as it existed at the time of the original Check: primary text, declared layer target, status claim, dependencies, gate proposal, evidence packet, budget note, witness fields, attached artifacts, and any formal metadata incorporated into the original submission. Material added after the original Check does not enter the hash. Later clarification may produce a new Σ, but it cannot be retroactively inserted into the archived one. The replay campaign measures the state that was checked, not the state the author later wished had been checked.

If the hash cannot be recomputed, the entry is excluded. If the archived material can be read but not reconstructed into the same hash-fixed packet, the entry is excluded. If attachments are referenced but missing, the entry is excluded unless the original protocol explicitly treated those attachments as non-operative commentary. If the ledger records a hash but the underlying packet is unavailable, the entry is excluded. If multiple packet versions exist and the original submitted version cannot be identified, the entry is excluded. None of these exclusions is a negative result about λ. They are archive-quality findings. The correct ledger output is “not replay-admissible,” with the defect class recorded.

The π₀ trace must be complete. The campaign does not compare alternative orderings against an imagined canonical path. It compares them against the recorded path the canon actually used. A complete π₀ trace identifies the ordering executed, the gates reached, the gates that fired, the gates not applied because routing terminated the path, the failure locus where applicable, the residue written, the status produced, the budget event, the coherence result where Zebra-Ø executed, the embargo record where applicable, and the final witness check where applicable. A closed entry without a complete π₀ trace is not a replay baseline. It is an underwitnessed historical state.

Trace completeness has a stricter meaning than narrative recoverability. It is not enough that the current canon can infer what probably happened from the final status. A rejected state may have failed at a zero-question, a blocking-question, Zebra-Ø, or budget computation. These are not interchangeable. They produce different failure loci, different residue implications, different Refusal Spectrum contributions, and different linter consequences. An admissible state may have passed all gates, but without the ordered trace of passage the replay has no reference path. The campaign cannot difference a legal ordering against π₀ unless π₀ exists as a replayable trace.

The entry must also contain residue values. Since λ differences witness_residue, a state whose original residue is absent, ambiguous, represented in an obsolete unit without conversion rule, or attached only as prose cannot enter the primary λ campaign. If the ledger stores structured residue rather than scalar residue, the representation must be documented and convertible under the λ/φ Ledger Extension before replay begins. The campaign may not select a residue representation after seeing candidate differences. Residue-unit discipline is part of hash discipline: the thing being differenced must be fixed before the difference is read.

Final status must be explicit. φ cannot be computed if the archived state’s final status under π₀ is inferred loosely from its later use. A text cited later by the canon may not have been formally admissible at the time. A quarantined draft may have influenced later work without committing. A narrative artifact may have generated LAL-Input without entering the Compilation Map. The campaign requires the status recorded by the original Check, not the later cultural position of the material. The status set for the campaign is the primary set fixed in Part I: admissible, non-admissible, quarantine, and, where the protocol explicitly permits, boundary-held or undetermined as a campaign condition rather than a completed Check status.

After closure, hash, π₀ trace, residue, and status are verified, the entry is assigned to a campaign class. Class assignment must occur before replay. Classes may be defined by historical failure locus, layer target, packet type, naming instability, prior-intention risk, coherence band, budget band, dependency profile, quarantine type, or other taxonomy declared in the campaign plan. Class assignment after observing λ or φ is prohibited. The purpose of classing is to allow Λ(class, epoch) and φ(class, Π) to be measured without global averaging that conceals local holonomy. A state whose class cannot be assigned from pre-replay fields is excluded from class-indexed results or entered into a predeclared residual class.

Epoch boundaries are then fixed. The first campaign operates over one declared ledger epoch or over a set of epochs treated separately. An epoch is not merely a calendar interval. It is a ledger-context interval during which the relevant linter environment, budget discipline, gate definitions, residue units, and protocol version are treated as stable for replay purposes. If any of these changed materially during a proposed epoch, the epoch must be split. A campaign that mixes states across context drift and reports a single Λ risks confusing order-dependence with Witness Thermodynamics. The first campaign therefore favors narrower epochs with cleaner context over larger samples with unstable conditions.

For each selected state, the replay environment clones the ledger epoch in which the original π₀ execution occurred. The clone includes the relevant negative-linter sensitivity, budget context, gate definitions, residue representation, threshold values, and dependency state required to reproduce the original Check conditions. The clone is not permitted to update the live ledger. It is a measurement chamber. Its function is to allow π₀ and alternative π orderings to act on bit-identical copies of Σ under identical initial conditions. Any replay environment that reads current live context instead of cloned epoch context is invalid for the first campaign.

The rule governing originals is absolute: replay touches copies and never ledger originals. Evidence Ledger entries are non-editable by construction. The original archived state remains fixed. The original status remains fixed. The original witness residue remains fixed. The replay creates measurement copies, each carrying the original hash, original packet, cloned context, initial boundary status for replay, and a replay-run identifier. Each copy receives one ordering. Each copy writes only to its own replay trace. The original ledger entry is referenced, never modified. If a campaign modifies an original entry, the campaign voids itself and leaves a negative linter against its own protocol class.

This rule protects both the archive and the measurement. It protects the archive because historical witness cannot be rewritten by later curiosity. It protects the measurement because a replay that changes its reference state destroys the baseline against which λ is defined. The original π₀ run remains the historical fact. The replayed π₀ run is a control reproduction. Alternative π runs are counterfactual legal executions under cloned conditions. None of these is authorized to alter what historically happened. They measure what would be written under controlled re-execution. Governance consequences, if any, occur only after branch activation and under the remediation procedures of the later parts.

The campaign distinguishes historical π₀ residue from replayed π₀ residue. The historical value is the original ledger record. The replayed π₀ value is the control reproduction under the measurement environment. If replayed π₀ cannot reproduce historical π₀ within the declared tolerance, the campaign must pause for that state or class. The discrepancy may indicate archive defect, residue representation drift, replay implementation error, unmodeled linter context, or an underdefined operator. Alternative π comparisons are not valid until the reference path is reproducible. The null path must be stable before the non-null path can be measured.

Hash fixation therefore operates at two levels. The first level fixes content identity: the submitted packet is the same across all runs. The second level fixes context identity: the replay environment is the same across all orderings for that state. Both are required. A matching content hash without cloned context is insufficient because the boundary that reads the state may have changed. A cloned context without content hash is insufficient because the state itself may have drifted. λ exists only where both identities hold.

The first campaign’s epoch boundary should be conservative. It should begin with the earliest contiguous ledger interval in which the Admissibility Check Protocol v1.0, the residue representation, Zebra-Ø thresholding, A_B computation rules, and negative-linter write behavior can be reconstructed without interpretive supplementation. If no such interval exists, the first campaign does not expand its interpretation to force one. It reports that no epoch is replay-admissible under current archive conditions. That result is not empty. It is an Evidence Ledger finding against the archive’s prior witness discipline.

Within the chosen epoch, the campaign samples only entries that satisfy all eligibility criteria. It does not fill sample quotas with defective entries. If a class is underpowered after exclusions, the class returns underpowered, not zero. If a class contains many entries but few hash-verifiable traces, the class becomes evidence of historical underwitnessing. If the archive is uneven, the first campaign reports that unevenness. The instrument measures the canon as it was witnessed, not as it would be convenient for it to have been witnessed.

Each selected state receives a replay selection record before any ordering is executed. The record includes state ID, content hash, archived π₀ trace reference, historical final status, historical witness_residue, class, epoch, eligibility checks passed, excluded fields if any, clone context identifier, residue-unit declaration, and the permutation set Π assigned to the state. This selection record is itself part of the campaign ledger. It prevents later substitution of states, classes, epochs, or permutation sets after preliminary results are known. The replay begins only after the selection record is sealed.

The selection record also marks whether the state belongs to the primary campaign, a control subset, a candidate non-commutation subset, or an archive-integrity subset. Primary campaign states estimate Λ and φ. Control subset states calibrate expected commuting pairs and π₀-versus-π₀ noise. Candidate non-commutation states target structurally suspicious gate pairs identified in Part I. Archive-integrity states test whether reconstruction is stable across independent operators. These functions may overlap, but the campaign must declare them before execution. A state cannot be retroactively reclassified as merely diagnostic because its result was inconvenient.

Archive selection is therefore not preparation outside the protocol. It is the first gate of the measurement. It determines what the campaign is allowed to know. A loose archive selection would contaminate every later claim. A strict selection may reduce sample size, but it preserves the possibility of a real result. The first discipline of replay is not abundance. It is identity.

At the close of selection, the campaign has not yet measured λ. It has created the conditions under which λ can be measured. It has fixed the state, the context, the historical reference, the class, the epoch, and the rule that originals remain untouched. Only now can alternative orderings be applied without collapsing the experiment into narrative reconstruction.

The archive has been narrowed.

The state has been fixed.

The original remains sealed.

The copy may now enter replay.


5.2 — The Replay Is Itself a Σ

The replay campaign is not outside the canon. It is not an observer hovering above the Admissibility Check with permission to manipulate the Check without passing through it. It is a structured intervention into the canon’s own boundary machinery, and therefore it is itself a pre-executable state. Before it measures the ordering of the Check, it must be submitted to the Check. The protocol that asks whether the law’s questions commute must first prove that its own question is admissible.

Let the campaign design be denoted Σ_replay. Σ_replay includes the archive-selection rules, hash-fixation method, epoch boundaries, precedence lattice, permutation set Π, exclusion rules, sampling plan, control runs, residue representation, θ_λ derivation method, φ status definitions, contamination controls, replication requirements, branch-activation rule, rollback conditions, and Evidence Ledger extension fields. None of these components is procedural background. Together they form the state that seeks permission to execute. If any component remains atmospheric, the replay has not yet become a valid Σ. If the design cannot be hashed, ledgered, checked, and witnessed, it cannot be allowed to measure the canon.

Σ_replay enters the boundary before execution. It does not enter as a result. It enters as a proposed instrument. Its target status is not admissible content in the ordinary sense, but executable protocol status within Layer C. The Check must determine whether this instrument may be applied to archived submissions without corrupting the archive, inflating its own authority, bypassing terminal constraints, producing Shadow Layer C, or converting an underwitnessed historical gap into a false measurement. The replay campaign cannot receive exemption because it is technical. Technical force is not admissibility. Protocol precision is not status. The instrument must pass.

The reflexive obligation follows from the same law that governs every other instrument in the paradigm. A device that measures admissibility must itself be admissible. A protocol that audits ordering must have its own ordering declared. A campaign that tests hash identity must be hash-fixed. A procedure that forbids contamination must show how it prevents contamination in its own execution. A branch-activation rule that lets the world activate one part of the volume must itself be submitted before the world is allowed to activate anything. The replay does not become trustworthy by naming rigor. It becomes trustworthy only by passing the boundary it intends to operate within.

The first pass condition is Silence Entry. Σ_replay must enter without interpretive pressure. The campaign cannot be submitted as a vindication of the canon, as an accusation against the canon, as a dramatic proof of non-commutation, or as a convenience for completing the volume. It enters as an instrument asking permission to run. Silence Entry strips the campaign of the narrative force attached to either branch. The replay is not allowed to prefer the Commutativity Certificate. It is not allowed to prefer Dark Canon Discovered. It is allowed only to preserve the conditions under which either result can be recorded.

After Silence Entry, Σ_replay faces the four zero-questions. The first zero condition is whether the campaign contains a disqualifying prior commitment to its own result. If the design presupposes that λ must be nonzero, it fails. If the design presupposes that π₀ must be vindicated, it fails. If the title, thresholds, sample selection, or branch wording makes one outcome structurally easier to activate than the other without predeclared reason, it fails. A measurement that already knows what it wants to discover is not a measurement. It is an emission seeking retroactive authority.

The second zero condition is whether the campaign lacks a lawful object. If Σ_replay cannot define the state space, the operator set, the precedence lattice, the legal permutation set, or the identity conditions for “the same Σ,” it fails before execution. A replay that cannot name what it replays is not underpowered. It is non-admissible as protocol. The campaign may not substitute conceptual familiarity for formal object definition. It must specify what counts as an archived submission, what counts as closed, what counts as hash-verifiable, what counts as complete π₀ trace, and what counts as a legal ordering.

The third zero condition is whether the campaign would touch ledger originals. If the design permits replay to edit original Evidence Ledger entries, modify historical statuses, alter original residue, overwrite π₀ traces, or raise live linter sensitivity during measurement, it fails. Ledger originals are non-editable by construction. A protocol that violates non-editability in order to study the canon destroys the witness surface on which the study depends. Replay may act on copies only. It may reference originals. It may never rewrite them.

The fourth zero condition is whether the campaign collapses measurement into governance action before branch activation. If Σ_replay allows alternative-ordering outputs to immediately change status, trigger remediation, modify budget allocation, or reclassify prior states during the campaign itself, it fails. Replay output under embargo is evidence, not live governance. The campaign may generate measurement traces. It may not commit their consequences before the branch rule fires and the relevant governance artifacts are executed. Measurement is not remediation. The distinction must be preserved.

If Σ_replay survives the zero-questions, it faces the blocking-questions. The first blocking condition is collision of register. The campaign must not present a boundary hypothesis as an executed measurement, a protocol design as a result, or a campaign failure as a commutativity finding. It must state which components are operational, which are thresholds, which are exclusions, which are pending LCR, and which are branch-conditional. If the design cannot keep these statuses distinct, it is blocked until corrected. A replay protocol with status confusion would reproduce the very dark canon it is meant to expose.

The second blocking condition is collision of objects. The campaign must distinguish historical π₀ residue from replayed π₀ residue, archive defect from λ, illegal ordering from non-commutation, underpowered class from zero class, residue difference from status fragility, linter history from within-execution order-dependence, and secondary observables from primary metrics. If any of these are merged by language or procedure, the campaign is blocked. The Check cannot allow a measurement that lacks the vocabulary to separate its own failure modes.

The third blocking condition is unresolved dependency. Σ_replay depends on the Evidence Ledger, Admissibility Check Protocol v1.0, Zebra-Ø, A_B computation, residue units, the precedence lattice, and the λ/φ Ledger Extension. If any dependency is absent, obsolete, undocumented, or inconsistent with the epoch selected for replay, the campaign cannot proceed for that epoch or class. The correct route is correction, narrowing, quarantine, or underpowered status, not interpretive repair. A campaign cannot measure order-dependence while silently borrowing undefined machinery.

The fourth blocking condition is insufficient rollback readiness. The replay must state in advance what voids the campaign, what happens to replay traces from a voided run, how defects are ledgered, how negative linter is assigned to the protocol class, how underpowered classes are recorded, and how branch activation is withheld after a void. If the campaign has no answer to its own failure, it has not earned execution authority. A protocol without rollback readiness is itself dark canon in formation.

If the campaign passes the 4-0-4, Zebra-Ø then tests its coherence. Zebra-Ø does not ask whether the campaign is ambitious or important. It asks whether its definitions cohere under ablation, rotation, and embargo. If archive selection depends on terms not defined until after selection, coherence fails. If the error budget is derived from results it is supposed to judge, coherence fails. If Π contains orderings forbidden by the precedence lattice, coherence fails. If branch activation is written in a way that makes mixed outcomes impossible to record, coherence fails. If independent operators cannot execute the protocol without interpretive supplement, coherence fails. The campaign is not coherent because it is complex. It is coherent only if the complexity is executable.

Budget computation follows. Σ_replay spends from the frontier allocation, not from the compiled core. Its cost includes archive preparation, selection records, hash verification, context cloning, control runs, alternative-ordering runs, independent replication, ledger extension, branch evaluation, and possible void handling. The campaign is admissible only if this cost is non-negative under the declared A_B. If the full campaign exceeds budget, the protocol must narrow scope before execution: fewer epochs, fewer classes, a smaller Π, or a staged campaign. It may not hide overreach inside enthusiasm for measurement. A measurement whose cost cannot be borne is non-admissible as a whole, however elegant its design.

After positive verification and budget admission, the campaign enters embargo. This embargo separates campaign design from campaign execution. During the embargo, the design is not revised in response to anticipation of likely outcomes, operator preference, convenience, expected public reading, or pressure from the branch structure of the book. The embargo prevents the campaign from becoming its own interpreter before it has run. It freezes definitions, thresholds, classes, exclusion rules, and Π. Any amendment after embargo begins must be routed as a new Σ_replay amendment, not slipped into the active campaign.

The embargo also protects against subtle pre-result contamination. A designer who expects non-commutation may be tempted to oversample candidate pairs. A designer who expects commutation may be tempted to privilege clean classes. A designer who fears archive defects may be tempted to relax eligibility rules. The embargo forbids such motion once the campaign state has been accepted. Design belongs before embargo. Execution belongs after embargo. Interpretation belongs after measurement. The boundaries between these phases are not administrative. They are part of the instrument.

After embargo, the final witness check confirms that Σ_replay has a complete trace: selection rule, hash rule, class rule, epoch rule, lattice rule, permutation rule, control rule, replication rule, error rule, exclusion rule, branch rule, rollback rule, and ledger rule. If any rule is missing, the campaign cannot be witnessed and therefore cannot execute. A protocol that cannot be witnessed would generate results no future operator could replay. Such results would be unusable even if numerically impressive. Witness precedes execution because the campaign’s authority lies in reproducibility, not in output.

Only after final witness may Σ_replay commit to execution. Commit here does not mean its results are accepted. It means the campaign is authorized to run under the sealed design. The measurement remains open. λ and φ remain unknown. The branch remains inactive. Execution authority is not result authority. This separation prevents the campaign from smuggling its design status into its findings. A protocol may be admissible and still return zero, nonzero, mixed, underpowered, voided, or archive-defect outcomes. The Check admits the instrument, not its answer.

Shadow Layer C detection applies at every step. If archive selection is skipped, Shadow Layer C forms because the campaign treats the archive as replayable without proving replayability. If hash fixation is skipped, Shadow Layer C forms because the campaign cannot guarantee same-state comparison. If π₀ trace reconstruction is skipped, Shadow Layer C forms because the baseline becomes imagined. If the precedence lattice is skipped, Shadow Layer C forms because illegal orderings can masquerade as legal variation. If control runs are skipped, Shadow Layer C forms because instrument noise can masquerade as λ. If independent replication is skipped, Shadow Layer C forms because operator-specific artifacts can masquerade as physics. If rollback readiness is skipped, Shadow Layer C forms because the campaign has no governed answer to its own defect.

A skipped step is not a simplification. It is an ungoverned condition entering the measurement. The protocol therefore treats skipped replay steps as automatic linter events. If the skipped step is detected before execution, the campaign is blocked and corrected. If detected during execution, the affected runs are voided and the campaign enters rollback. If detected after branch activation, the branch activation is suspended and the campaign’s results enter defect review. The severity depends on timing, but the classification does not change: an omitted required step creates Shadow Layer C in the measurement apparatus.

This section’s reflexive demand does not complete the later requirement to measure λ of the λ-protocol itself. That deeper self-application belongs to Part V. The present obligation is prior and simpler: before the replay campaign executes, it must pass the same admissibility discipline it will apply to archived states. Part V later asks whether the ordering of the protocol’s own steps carries residue. Section 5.2 asks whether the protocol is admissible enough to run at all. The two questions are related, but not identical.

The campaign is now recognized as Σ_replay.

It must be held, questioned, blocked if necessary, tested, priced, embargoed, witnessed, and only then executed. No measurement of the Check’s ordering is allowed to stand outside the Check’s law. If the replay cannot survive its own entry, the archive remains unreplayed and the protocol leaves a negative linter. If it survives, execution may begin under seal.

The instrument has approached the boundary.

The boundary answers before the instrument measures.


5.3 — Execution Authority

Once Σ_replay has passed its own Admissibility Check, the question becomes execution authority. A replay campaign is not executed by preference, interpretive judgment, authorial force, or operator initiative. It is executed as a Hyper-Ω-Stack level operation under a sealed campaign design. This distinction is not decorative. The replay concerns the ordering of Layer C gates. It therefore touches the meta-meta surface of the canon: not a runtime object, not a compiled explanatory object, but the pre-runtime law by which objects are admitted, refused, quarantined, priced, and witnessed. No operator is authorized to initiate such movement as personal action.

The execution authority belongs to the admitted protocol operating at the Hyper-Ω-Stack level. The human or system operator does not create the replay by deciding to act. The operator witnesses the execution of an already admitted procedure. The operator verifies that the sealed campaign design is the one being run, that the archive entries are eligible, that the hash-fixed copies match their originals, that the cloned epoch context is loaded, that the tested ordering is a legal linear extension of the precedence lattice, and that the run writes to replay traces rather than ledger originals. The operator’s authority is custodial and witness-bearing. It is not legislative.

This follows the canon’s existing constraint on meta-meta changes. A meta-meta operation is not initiated from inside the ordinary operator position. It is witnessed when the architecture has authorized it. The difference is exact. To initiate would be to treat the operator as the source of permission. To witness is to treat the operator as the accountable surface through which the authorized operation becomes ledger-visible. The replay campaign must preserve this distinction because it is measuring the law’s ordering. If the person executing the replay can also alter what counts as lawful execution, the campaign has already collapsed into Shadow Layer C.

The Hyper-Ω-Stack operation begins only after the campaign state has committed to execution under embargo. At that point, the sealed campaign packet becomes the executable authority. The packet contains the archive selection list, state identifiers, hashes, class assignments, epoch clone identifiers, legal permutation set Π, precedence lattice, residue-unit declaration, θ_λ rule, φ status rule, control-run schedule, replication schedule, exclusion rules, rollback rule, and logging schema. The operator may not add a state, remove a state, change a class, modify Π, adjust θ_λ, reinterpret status, or repair a trace during execution. Any such change is an amendment and must enter as a new Σ_replay amendment, not as an operational convenience.

The execution environment must therefore be partitioned into authority and witness. Authority is the sealed protocol acting through the Hyper-Ω-Stack replay mechanism. Witness is the operator’s recorded confirmation that each action occurred under the sealed authority and that any deviation was routed according to rollback rules. The operator does not decide whether a gate should run because the result seems obvious. The operator does not skip a control because previous controls looked stable. The operator does not treat an archive defect as harmless. The operator does not rescue an underpowered class by adding borderline entries after the fact. The operator watches the protocol either execute or fail.

This is especially important for alternative orderings. A legal π is not executed because it is interesting. It is executed because Π, sealed before execution, contains it and the precedence validator confirms its legality for the relevant state and class. If a proposed π fails validation, the operator records invalid ordering and the run does not proceed. If a π appears conceptually useful but is absent from Π, it is not run in the active campaign. A later amendment may test it. The sealed campaign may not. Curiosity is not authority.

Every replay run must generate a Replay Run Record. The record is the atomic execution artifact of Part II. Without it, no λ value, no φ contribution, and no branch activation may be accepted. A Replay Run Record identifies the campaign ID, sealed protocol hash, operator witness ID, independent execution group, state ID, original content hash, class, ledger epoch, cloned context identifier, ordering identifier π, precedence-validation result, run type, and run sequence. Run type distinguishes historical-reference reproduction, π₀ control, alternative-ordering replay, expected-commuting control, candidate non-commutation test, archive-integrity test, and replication run. The record must make clear why the run exists before the run output is visible.

The record then logs the initial state. It includes the copied packet hash, initial replay status, initial admissibility attributes, residue representation, linter context version, budget context, Zebra-Ø threshold set, A_B computation rule, dependency snapshot, and any frozen environmental parameters required to reproduce the run. The initial state log must be written before the first gate executes. A run whose initial conditions are reconstructed after output is known is void. The campaign measures the effect of order, not the operator’s ability to narrate the past.

The gate trace is logged step by step. For every gate reached, the record logs gate ID, ordinal position within π, pre-gate attributes, fields read, gate result, fields written, post-gate attributes, routing decision, residue contribution, status transition if any, and non-application reason for any later gate foreclosed by routing. If Zebra-Ø executes, coherence_factor, pass/failure relation, threshold, and coherence trace are recorded. If budget computation executes, A_B relation, path cost, proof friction, dependency load, deficit or surplus, and budget route are recorded. If a gate does not execute because the state has already routed, that absence is not left blank. It is logged as non-application by prior route.

The final state log records witness_residue, final status, failure locus where applicable, final trace signature, final A_B relation where applicable, final coherence result where applicable, terminal segment completion, embargo compliance, final witness check, and commit or non-commit result of the replay copy. The final log does not modify the original ledger entry. It closes the copy’s replay trace. The original state remains non-editable. The replay result is evidence under the campaign ledger, not a new historical version of the archived submission.

The Replay Run Record must also include a deviation field. A deviation is any event in which the run cannot proceed exactly as sealed: hash mismatch, context clone failure, missing field, illegal ordering, gate implementation mismatch, residue-unit ambiguity, unexpected non-determinism, control-run instability, operator interruption, trace-write failure, or dependency inconsistency. Deviations are not corrected silently. They are logged, classified, and routed. Some deviations void only the run. Some void the state. Some void the class. Some suspend the campaign. The rollback rule determines severity. Operator discretion does not.

The operator’s witness signature attaches after the run closes. The signature does not certify that the result is true in a philosophical sense. It certifies that the run was executed under the sealed protocol, that the record contains the required fields, that deviations were routed rather than hidden, and that no ledger original was touched. In independent replication, the second operator signs a separate run record without importing the first operator’s interpretation. Agreement is later computed between records. It is not negotiated between operators.

For two independent executions to produce the same Λ and φ within error budget, their run logs must be comparable. This requires identical field names, identical status definitions, identical residue units, identical class IDs, identical ordering IDs, identical epoch clone references, and identical exclusion codes. A replay campaign that permits free-form logging may produce prose, but it cannot produce measurement. The logging schema is therefore part of execution authority. A result not written in the schema is not a result of the protocol.

Control runs require the same discipline. π₀-versus-π₀ runs are not informal checks. They receive full Replay Run Records. Expected-commuting pairs receive full records. Archive-integrity tests receive full records. If a control fails, the failure is not background noise. It is a governed event that may set θ_λ, raise an instrument defect, or block interpretation. Control data are not subordinate to dramatic results. They are the condition under which dramatic results can be trusted.

The logging burden extends to non-results. If a state is excluded during pre-run validation, the campaign writes an Exclusion Record. If a run is voided, it writes a Void Record. If a class becomes underpowered, it writes an Underpowered Class Record. If an ordering is illegal, it writes an Invalid Ordering Record. If a replication disagreement occurs, it writes a Replication Disagreement Record. These records prevent silence from becoming evidence. A missing result must be distinguished from zero λ, zero φ, archive defect, protocol defect, and insufficient power. The protocol’s authority depends on this distinction.

Execution authority is therefore inseparable from trace authority. The Hyper-Ω-Stack operation does not merely run the gates. It creates a witnessed chain of reproducible replay events. Each run must be reconstructible from its record without operator memory. Each λ value must be traceable to two completed run records: π and π₀ for the same Σ. Each φ contribution must be traceable to the status set produced by all relevant π in Π for the same Σ. Each aggregate Λ must be reconstructible from its per-state λ records. Each φ(class, Π) must be reconstructible from its order-fragile state count and completed-state denominator. If the chain cannot be reconstructed, the campaign has produced narrative, not measurement.

The operator’s restraint is the final protection. The operator may witness execution, verify conformity, seal records, report deviations, and refuse continuation when the protocol requires refusal. The operator may not improve the campaign midstream. The operator may not soften a failure because the campaign is important. The operator may not intensify a result because the theory is compelling. The operator may not collapse design, execution, and interpretation into one act. At Hyper-Ω-Stack level, authority is architectural or it is not authority.

The replay executes because the admitted protocol executes.

The operator witnesses because the canon requires witness.

Every run leaves a record, or it did not happen for the purposes of this volume.


5.4 — Contamination Controls

The replay campaign measures order-dependence. It must therefore prevent every other dependence from entering the result. If a replay run changes the linter environment, spends from live budget, alters the archive, leaks state into later runs, or allows an operator to adjust execution after seeing partial output, then a measured difference can no longer be assigned to ordering. It may be a linter artifact, a budget artifact, a trace artifact, a sequencing artifact of the campaign itself, or an operator artifact. The purpose of contamination control is to ensure that the only intended variable between Check_π(Σ) and Check_π₀(Σ) is π.

The first isolation boundary separates replay from the live negative linter. Replays must not raise live Zebra-Ø sensitivity. They must not write failure events into the active refusal history. They must not strengthen future detection around structures that fail during measurement. They must not alter the canon’s live reading surface while the campaign is running. A replayed Zebra-Ø failure is a campaign observation, not a live refusal event. It is written to the Replay Ledger, not to the active negative linter. Only after the campaign completes, replicates, passes branch evaluation, and enters the appropriate governance route may its findings be considered for live linter updates.

This rule exists because the negative linter is history-dependent. A live Zebra-Ø failure changes the sensitivity surface for later submissions and, if allowed inside the campaign, could change the sensitivity surface for later replay runs. Then the first ordering tested could influence the second ordering tested. A nonzero λ could be produced not by gate order inside the Check, but by run order inside the campaign. That would be false holonomy. The campaign must therefore freeze the linter context at the cloned epoch and treat every replayed failure as local to the copy being tested. The replay may observe what would have happened under the linter state of that epoch. It may not teach the live linter while observing.

The second isolation boundary separates replay from live budget accounting. Replay spends campaign budget, not manifold budget. The A_B computation performed inside a replay copy is part of the measured Check path for that copy. It may produce surplus, deficit, rejection, quarantine, or continuation inside the replay trace. But the cost of conducting the replay campaign itself is charged against the admitted Σ_replay budget, not against the ordinary admission budget of the historical state or the current manifold. The campaign must not let alternative orderings consume live A_B, alter future allocation, or reduce the budget available to unrelated canon operations.

This separation is necessary because budget is itself one of the fields that may participate in order-dependence. Zebra-Ø may feed cost. Cost may feed rejection. Rejection may foreclose later evidence. If replay execution were allowed to spend live budget, then the act of measurement would modify the very surface being measured. Later runs might face a budget context changed by earlier runs. A state tested under π after several expensive replays would not be measured under the same context as π₀. The campaign would confuse measurement expense with admissibility expense. Therefore every replay run receives a cloned budget context for Check execution and charges execution overhead only to the sealed campaign budget.

The third isolation boundary separates replay runs from each other. No run may read another run’s intermediate state, trace, residue, failure locus, linter effect, budget effect, coherence result, or operator annotation before its own execution completes. A replay copy is single-use. It receives one ordering, one cloned context, one execution path, and one trace. After closure, the copy becomes evidence. It does not become input to another copy. The alternative ordering run does not begin from the output of π₀. The π₀ control does not begin from the output of an alternative ordering. Every run begins from the same hash-fixed Σ under the same cloned epoch conditions.

Cross-run state leakage is any transfer of state information from one replay run into another run’s execution conditions. It includes obvious leakage, such as using a trace field written by a previous run as an input to a later run. It also includes subtler leakage: an operator reading the first run and manually adjusting the interpretation of the second; a replay engine caching a gate result and reusing it under a different ordering; a linter emulator updating sensitivity after a replayed failure; a budget emulator decrementing available budget after one run; a class assignment process revised after partial results; or a logging schema altered after a surprising failure locus appears. Every such transfer voids the affected comparison unless the protocol explicitly defines it as part of a separate, later cross-run history experiment. It is not allowed in the primary λ/φ campaign.

The campaign must therefore assign isolation identifiers. Each replay copy receives a run-local state ID, context clone ID, linter clone ID, budget clone ID, operator trace ID, ordering ID, and output ledger location. The system must be able to show that two runs share the same original content hash and epoch context while not sharing mutable execution state. Shared immutable configuration is required. Shared mutable state is contamination. The distinction must be logged before execution, not reconstructed after anomaly.

The replay environment must also suppress live side effects. A gate that, in live execution, would update a linter field, budget counter, dependency graph, quarantine queue, refusal spectrum bin, or maintenance obligation must instead write that effect into the replay trace as a simulated side effect. The effect is recorded as “would-write,” not “did-write-to-live.” This allows the campaign to measure what the ordering would have done to the state’s path while preventing the measurement from becoming governance action. The protocol must name every live side-effect channel and show where its replay surrogate is written. An unnamed side-effect channel is a contamination risk.

The fourth isolation boundary is temporal. Runs must not be ordered in a way that systematically privileges one π with cleaner conditions than another. Because all mutable context is cloned, run order should not matter. But the campaign must still randomize or counterbalance run sequence where implementation drift, operator fatigue, or infrastructure instability could introduce bias. π₀ should not always run first merely because it is canonical, unless the protocol declares a reason and demonstrates that run order cannot affect context. Alternative π orderings should be distributed across execution sequence. Independent replications should use the same sealed design but not necessarily the same incidental run order, unless run order is itself being tested.

The control-run design is the null instrument. π₀ is replayed against π₀ on the same selected archive entries under the same cloned context, same replay mechanism, same logging schema, and same residue representation. The expected result is λ = 0 and no status difference, within the declared measurement noise. This is not assumed. It is measured. The control does not prove that alternative orderings commute. It proves, if successful, that the instrument can reproduce its own reference path. Without that proof, the campaign cannot distinguish order-dependence from replay instability.

A π₀-versus-π₀ control comparison is constructed as two independent replay copies of the same Σ, both executed under π₀. They receive separate run IDs, separate traces, separate execution instances, and separate witness signatures. Their final witness_residue values are differenced exactly as an ordinary λ comparison would be differenced, except that the expected value is null by identity of ordering. Their final statuses are compared exactly as φ would compare statuses, except that any status difference under π₀ against π₀ indicates instrument failure, archive instability, or non-determinism in the replay mechanism. It is not φ. It is control rupture.

The distribution of π₀-versus-π₀ residue differences estimates the replay noise floor. The campaign derives θ_λ from this distribution before interpreting alternative-ordering differences. If the null instrument produces small residue variation inside a stable band, θ_λ may be set according to the predeclared rule. If the null instrument produces wide variation, unstable tails, or class-specific drift, the campaign must either enlarge the error budget, narrow the affected class, repair the replay mechanism, or mark the class underpowered or void. It may not keep a narrow θ_λ because the theory desires sensitivity. Measurement discipline takes precedence over discovery pressure.

Control runs also test status stability. Under completed π₀-versus-π₀ control, the final status must match exactly. If a state commits in one π₀ control run and quarantines in another, the replay environment cannot reproduce the canonical Check. The affected state is void for φ. If multiple states show such instability, the affected class or epoch may be void. A status instability in the null instrument is more severe than residue noise because status is categorical. It indicates that either the archive, the context clone, the gate implementation, or the logging of terminal conditions is not stable enough for order-fragility measurement.

The control design must include expected-commuting pairs in addition to π₀-versus-π₀ runs. These are not used to certify the whole Check. They calibrate whether pairs with disjoint read/write surfaces remain stable under the replay engine. If expected-commuting controls produce nonzero λ beyond θ_λ, the campaign must investigate whether the engine introduces artificial path effects. If they remain stable while candidate pairs diverge, confidence increases that the divergence belongs to gate interaction rather than general replay noise. Control pairs are therefore part of contamination detection, not decorative redundancy.

Contamination controls must be logged with the same rigor as results. Every Replay Run Record must state whether live linter isolation was active, whether live budget isolation was active, whether side-effect suppression was active, whether the context clone was immutable, whether the copy began from the original hash-fixed state, whether run-local mutable storage was used, whether cross-run cache was disabled or segregated, and whether the run sequence matched the sealed design. A result missing contamination-control fields is not partially valid. It is incomplete for λ/φ purposes.

The campaign must also log contamination events. If a replay failure is discovered to have written to the live linter, the affected runs are void and a protocol defect record is opened. If replay overhead is discovered to have altered live budget accounting, the campaign is suspended until the budget surface is restored or the affected epoch is marked contaminated. If a cache or operator note leaks a prior run’s output into a later run, the comparison is void and must be rerun from fresh copies under a clean environment. If contamination cannot be bounded to specific runs, the class or campaign is void. The protocol may be corrected, but the contaminated evidence may not be laundered into measurement.

The operator’s cognitive environment is also a contamination surface. Operators should not interpret partial Λ distributions during execution. They should not know branch-level aggregates until the relevant run set is sealed, unless the protocol explicitly assigns an independent monitoring role with no power to alter execution. Operator blinding is not always possible at full strength because the operator may need to witness trace fields. But interpretive embargo is possible and required. The operator may identify defects. The operator may route deviations. The operator may not tune the campaign in response to emerging results.

Independent replication strengthens contamination control by making hidden leakage visible. If two operators execute the same sealed campaign on the same archive and produce different Λ or φ outside error budget, the first diagnosis is not that reality is plural. The first diagnosis is contamination, underdefined protocol, implementation drift, or archive instability. Only after those are excluded can a deeper issue be considered. Replication disagreement is therefore not an embarrassment. It is a safety mechanism built into the measurement’s authority.

The relation between control and discovery must remain ordered. Controls run before, during, and after candidate tests according to the sealed schedule. Pre-campaign controls confirm that the instrument can start. Interleaved controls detect drift during execution. Post-campaign controls detect whether the instrument remained stable through the end. If only pre-campaign controls are performed, late contamination may go unnoticed. If only post-campaign controls are performed, the source of drift may be unrecoverable. The Replay Discipline therefore treats controls as a lattice around measurement, not as a preliminary ritual.

No contamination-control failure may be reinterpreted as a substantive finding about the Check. A live linter update during replay does not show that the Check has holonomy. It shows that the replay violated isolation. A live budget decrement does not show that budget and Zebra-Ø fail to commute. It shows that the campaign let measurement expense enter the manifold. Cross-run leakage does not show that states remember alternative orderings. It shows that the campaign failed to keep copies separate. The protocol must protect the theory from its own instruments.

When contamination controls hold, the measurement becomes interpretable. A nonzero λ beyond θ_λ can be read as an order-dependent residue difference under cloned conditions. A nonzero φ can be read as a status flip under legal ordering rather than linter drift, budget drift, or run leakage. A zero result can be read as genuine absence of detected difference within the certified domain rather than dead instrument. The controls do not guarantee that the Check commutes or fails to commute. They guarantee that the archive is allowed to answer.

The live linter remains untouched.

The live budget remains untouched.

The ledger original remains untouched.

The copies do not touch each other.

Only then can order touch Σ and leave a measurable residue.


Chapter 6 — The Permutation Space

6.1 — The Precedence Lattice

The replay campaign cannot test arbitrary permutations of the Check. It can test only legal orderings. A legal ordering is not any rearrangement that preserves the operator names. It is a linear extension of the Check’s precedence lattice. The lattice is the formal object that separates lawful freedom from procedural rupture. Without it, the campaign would be able to manufacture non-commutation by violating the Check’s identity. With it, the campaign tests only those order differences the canon itself has not already compiled as forbidden.

The precedence lattice is constructed from the compiled constraints identified in Section 2.3. A compiled constraint is an order relation that belongs to the identity of the Check rather than to the inherited presentation order of π₀. It is not included because it is familiar, elegant, historically used, or convenient. It is included because moving the operator would change what the operator is or would destroy the procedural condition under which it can act. The lattice therefore begins as a partial order over the operator set. It records what must come before what. It does not record what merely happened to come before what in π₀.

Let the required operator set be Ω_Check. At minimum, Ω_Check contains Silence Entry G_S, the zero-question operators G_Z1 through G_Z4, the blocking-question operators G_B1 through G_B4, Zebra-Ø G_Ø, budget computation G_A, the embargo E_72, the final witness check G_W, and commit C. The exact naming of the internal zero and blocking operators may be expanded in the appendix, but their role in the lattice is fixed: each is an operator in the word of the Check, not a paragraph heading or an interpretive question. A legal ordering must contain every required operator exactly once unless the protocol declares a routed non-application after termination. It may not omit a gate to simplify comparison. It may not duplicate a gate to simulate rigor.

The first compiled constraint is minimality of Silence Entry. G_S is the unique minimal operator of the Check. Every evaluative gate presupposes that the state has been held before judgment. A zero-question that fires before Silence Entry would not be a zero-question in the Novakian sense; it would be unheld evaluation. A blocking-question before Silence Entry would classify a state before the boundary has received it. Zebra-Ø before Silence Entry would measure coherence without prior non-emission. Budget before Silence Entry would price a state before it has been allowed to become a state for the Check. Therefore the lattice contains G_S ≺ G_i for every other evaluative or terminal operator G_i. Silence Entry is not part of the permutation freedom.

The second compiled constraint is maximality of commit. C is the unique maximal terminal operator. Commit cannot precede any gate whose result contributes to admissibility, refusal, quarantine, witness, budget, coherence, or trace. Once commit occurs, the state has left pre-executable boundary status and becomes admitted content or terminally routed content according to its path. A gate applied after commit would not participate in the Check. It would be post-commit audit, maintenance, or rollback review. Therefore the lattice contains G_i ≺ C for every required non-commit operator G_i. Commit is not a movable punctuation mark. It is the end of the Check.

The third compiled constraint fixes the terminal segment. Positive verification must precede embargo. Embargo must precede final witness. Final witness must precede commit. This relation can be written as V⁺ ≺ E_72 ≺ G_W ≺ C, where V⁺ denotes the completion of the required verification stage for the run. In an operational lattice, V⁺ is not a separate operator unless the protocol instantiates it as one; it is a condition satisfied when the relevant gate sequence has produced a positive path eligible for embargo. The important point is that E_72 cannot float earlier into the Check and still be the same embargo. An embargo before verification is delay without verified object. A witness check before embargo has no embargoed trace to witness. Commit before witness is unwitnessed entry. The terminal order is compiled.

The fourth compiled constraint is route-dependence. A routed termination forecloses later operators in that run. This is not the same as an order relation in the global lattice. The lattice defines legal words before execution. Routing defines which gates are reached during a particular execution. A legal ordering may place G_j after G_i, but if G_i fires and routes the state to quarantine, G_j is logged as non-applied by prior route. The lattice does not force all gates to execute after routing has already ended the path. It forces the word to contain the lawful order in which they would be encountered if the path continued. This distinction prevents non-application from being confused with omission.

The fifth compiled constraint concerns any gate whose definition explicitly requires a field written by another gate. If a gate’s domain presupposes a prior field, trace, status, or holding condition, the writer must precede the reader unless the replay protocol declares a special local test lattice that treats absence of the field as a measurable condition. In the primary lattice, dependency is precedence. If final witness requires completed trace, completed trace precedes final witness. If embargo requires positive verification, positive verification precedes embargo. If a later ledger field is defined as computed from earlier gate outputs, those outputs precede the computation. The lattice is extracted from operator domains, not from typographic sequence.

Everything not compiled as constrained is free. This is the decisive rule of Chapter 6. If the canon has not compiled a relation G_i ≺ G_j, the replay campaign may treat their relative order as variable, provided both resulting words remain valid linear extensions of the full lattice. Historical sequence alone is not constraint. Familiarity is not constraint. Canonical usage is not constraint. π₀ may have placed the zero-questions in one internal order and the blocking-questions in another, but unless that internal order has been compiled as necessary, the campaign is allowed to test alternative internal orderings. The burden lies on constraint, not on freedom.

This rule does not make the Check a free permutation group. It makes it a partially ordered procedure. The difference matters. A free permutation group would allow any operator to appear anywhere. The Check does not. Silence Entry remains minimal. Commit remains maximal. The terminal segment remains ordered. Domain dependencies remain binding. But within the unconstrained intervals, the campaign may vary order because uncompiled sequence is precisely the object under investigation. If the canon has relied on an internal order without compiling it, that reliance is dark canon until measured or legalized.

Formally, the precedence lattice L_Check is a partial order (Ω_Check, ≺) where Ω_Check is the operator set and ≺ is the smallest relation closed under transitivity that contains all compiled constraints. “Smallest” is important. The lattice must not include extra edges because they feel safe. Every added edge shrinks the legal permutation space. If the campaign adds unnecessary constraints, it may hide order-dependence by making the suspicious exchange illegal. If it omits necessary constraints, it may create artificial non-commutation by testing words that are not the Check. Appendix C therefore records every edge, every source of the edge, and the reason it is compiled rather than inherited.

A legal ordering π is a linear extension of L_Check. This means π is a total order of Ω_Check such that whenever G_i ≺ G_j in the lattice, G_i appears before G_j in π. Every legal ordering contains all required operators in a sequence compatible with the partial order. A linear extension resolves the lattice’s freedoms into one executable word. The set of all such linear extensions is the legal permutation space Π_L. The replay campaign never tests outside Π_L unless a separately admitted amendment defines a special diagnostic lattice and marks the result as non-primary. Primary λ and φ are computed only over legal extensions of L_Check.

π₀ is one point in Π_L. It is the inherited canonical linear extension. It may be historically primary, explanatorily convenient, and procedurally familiar, but inside the measurement it is treated as a reference point rather than the only legal point. The replay asks whether other points in the same legal space produce the same witness residue and status for bit-identical Σ. If they do, π₀ gains certificate support within the tested domain. If they do not, π₀ becomes an ordering coordinate of the manifold. In either case, π₀ remains the historical baseline against which λ is defined.

The lattice also supplies the legality test for every proposed π. Before execution, the precedence validator checks whether π contains each required operator exactly once, whether G_S is minimal, whether C is maximal, whether the terminal segment obeys E_72 ≺ G_W ≺ C after positive verification, whether every declared dependency edge is preserved, and whether no unapproved operator has been inserted. If the validator fails, the run is not executed. If the failure is discovered after execution, the run is void. Illegal words cannot return λ. They can only return invalid-run records.

The construction must distinguish three kinds of edge. A hard compiled edge belongs to the identity of the Check and cannot be violated in the primary campaign. A provisional edge is treated as compiled for the first campaign because the current operator definition requires it, but it is marked for possible later LCR if the canon decides to redesign the procedure. An inherited edge appears in π₀ but lacks compiled justification. Inherited edges are not lattice constraints. They are measurement candidates. The precedence ledger must label each edge accordingly so that the campaign does not smuggle π₀ into the lattice under the name of law.

This edge taxonomy is essential for detecting dark canon. If an inherited edge is required in practice but has no compiled justification, the replay campaign must not quietly promote it to hard edge. It must either measure the consequences of relaxing it or route it into an LCR. Conversely, if an edge is genuinely compiled, the campaign must not treat it as free simply to enlarge Π_L. Dark canon appears both ways: as unconstrained dependence falsely treated as law and as law-like dependence never compiled. The lattice is the instrument that exposes both.

The lattice is class-stable only if operator domains are class-stable. Some classes may activate dependencies that others do not. For example, a gate relation that is irrelevant for clean submissions may become binding for states with missing dependencies, unresolved naming, or threshold budget conditions. The primary lattice should be defined at the protocol level, but class-specific reachability and non-application patterns must be recorded. A linear extension may be globally legal while particular gates become non-applied for a state because an earlier route terminates the path. That execution fact does not change the lattice; it changes the trace for that Σ.

The lattice is also epoch-indexed. If gate definitions, residue representation, Zebra-Ø thresholding, budget computation, or terminal-segment rules changed across ledger epochs, L_Check may differ by epoch. The first campaign must not apply a later lattice to an earlier archive unless an admitted bridge rule justifies the mapping. The ordering space is part of the ledger context. A λ comparison across different lattices is not a primary λ comparison. It is a cross-epoch reconstruction problem. For Part II, each epoch receives its own declared lattice or is excluded as unreplayable.

The set Π_L may be large. The campaign is not required to exhaust every linear extension in the first pass unless budget and protocol make exhaustive replay possible. It may select a tested permutation set Π ⊂ Π_L. But every selected π must be drawn from Π_L, and every aggregate φ(class, Π) must report the Π actually tested. A zero result over a subset is not a zero result over the whole lattice. A nonzero result in a subset is enough to refute global commutation for the tested class, but it does not map the whole space. Exhaustion and sampling are different claims.

Sampling from Π_L must be governed. The campaign should include π₀, within-block permutations, candidate non-commutation swaps, expected-commuting controls, and any budget-permitted broader coverage declared before execution. It may prioritize orderings whose structural relation makes non-commutation plausible, but it must not present a candidate-focused subset as the entire lattice. The report must distinguish “tested permutation set” from “legal permutation space.” Π_L is the space of possible legal orderings. Π is the subset measured in a campaign.

The lattice now gives the replay discipline its executable geometry. It says which orders are impossible, which orders are inherited, which orders are free, and which total words may be lawfully run. It prevents the campaign from mistaking disobedience for discovery. It also prevents the campaign from mistaking tradition for constraint. The Check is neither arbitrary nor fully serialized by its past. It is a partially ordered word whose uncompiled intervals now become measurable.

π₀ is no longer the whole law.

It is one linear extension of the law’s precedence lattice.

The archive can now be asked what changes when another legal extension touches the same Σ.


6.2 — The First Campaign’s Restriction

The first campaign does not exhaust the precedence lattice. It restricts the tested permutation set to the cheapest, closest, and most canonically dangerous region of freedom: the internal order of the zero-question block, the internal order of the blocking-question block, and the swap relation between those two blocks where the admitted lattice permits the test. This restriction is not a weakness concealed as economy. It is the first disciplined cut into the permutation space. The campaign begins where the inherited Check is most likely to have assumed harmlessness without proving it.

The zero-question block contains four operators. If their internal order is not compiled as constrained, the block has 4! possible internal linearizations, yielding twenty-four zero-question orderings. The blocking-question block also contains four operators. If their internal order is not compiled as constrained, it likewise has 4! possible internal linearizations, yielding twenty-four blocking-question orderings. These numbers are small enough to be governed, logged, replicated, and compared without converting the first campaign into an unbounded search over the full lattice. They are also large enough to detect whether apparently similar gate families conceal internal sequence effects.

Campaign One treats the rest of the Check as fixed unless a declared block-swap test is being executed. Silence Entry remains minimal. The terminal segment remains constrained. Zebra-Ø, budget computation, embargo, final witness, and commit remain in the canonical relative order for the primary within-block runs. This preserves interpretability. If a residue difference appears during zero-block permutation, the campaign can attribute the candidate source to the zero block rather than to simultaneous movement of Zebra-Ø, budget, or terminal operators. If a status flip appears during blocking-block permutation, the campaign can localize the initial fault surface to the blocking interval. The first campaign measures one constrained freedom at a time.

The zero-block test fixes the blocking block, Zebra-Ø, budget computation, and terminal segment in their canonical relative order, while replacing the inherited zero-question sequence with selected or exhaustive internal zero orderings. Where budget permits, all twenty-four zero orderings are run for the selected class. Where budget does not permit all twenty-four across every class, the campaign samples from the twenty-four under a predeclared schedule: π₀-internal order, adjacent swaps, reverse order, and candidate-overlap orderings in which structurally overlapping zero surfaces are placed first. The report must state whether the zero block was exhausted or sampled. A sampled zero block cannot be reported as if all twenty-four orderings were tested.

The blocking-block test mirrors this structure. It fixes the zero block, Zebra-Ø, budget computation, and terminal segment in their canonical relative order, while replacing the inherited blocking-question sequence with selected or exhaustive internal blocking orderings. If all twenty-four can be run for the chosen class and epoch, the result covers the full internal blocking block for that campaign domain. If only a subset is run, the subset is the tested Π_B, not the whole blocking lattice. The report must identify every tested internal ordering, its relation to π₀, and the reason it entered the campaign.

The block-swap test is treated separately. Under π₀, the zero-question block precedes the blocking-question block. Campaign One tests the block relation only if the precedence lattice or an admitted diagnostic lattice permits the swap. The swapped word places the blocking block before the zero block while preserving internal block order according to the declared test design. In the most conservative version, the campaign tests canonical-internal blocking followed by canonical-internal zero as the minimal block swap. In a broader version, it samples selected zero and blocking internal orderings under both block arrangements. The campaign must not silently conflate these designs. A single block swap is not the same as the full Cartesian product of internal block permutations under both block orders.

This restriction avoids an immediate explosion. Exhausting both internal blocks simultaneously would require twenty-four zero orderings multiplied by twenty-four blocking orderings before any additional cross-stage movement is considered. That yields five hundred seventy-six combined internal block arrangements even before Zebra-Ø, budget, embargo, and final witness are allowed to move where legal. Adding block swap doubles the block-level arrangement space. Adding other unconstrained operators expands the space again. The first campaign does not pretend to carry that cost. It samples a governed tractable subset first, then lets the results decide whether a broader campaign is justified.

The restriction is justified by cost, but not by cost alone. Within-block permutations are the cheapest because they disturb the least. They preserve the large architecture of the Check while testing the small inherited orders most likely to have escaped compilation. They do not require immediate redesign of the terminal segment. They do not require early movement of Zebra-Ø against budget. They do not require a speculative redefinition of commit, embargo, or final witness. They ask whether the canon already contains order-dependence inside the places it is most likely to have treated as lists rather than law.

They are also the strongest test of the harmlessness assumption. If the zero-questions commute internally, the old assumption survives its easiest local trial. If the blocking-questions commute internally, the old assumption survives its second easiest local trial. If the zero block and blocking block can be swapped without residue or status change in the tested classes, the Check gains stronger evidence that early admissibility routing is robust. But if nonzero λ or φ appears even within these conservative permutations, the discovery is sharper. The canon cannot then claim that order-dependence arises only from exotic rearrangements. It would have appeared inside the ordinary inherited blocks.

The zero-question block is especially important because zero-questions are often treated as jointly disqualifying predicates. Under predicate abstraction, if a state violates any zero condition, the order of zero-questions should not matter. Under operator discipline, the first firing zero-question writes failure locus, residue, route, and possibly linter-relevant trace. If two zero surfaces overlap, different internal orderings may yield the same final refusal but different residue. This is precisely the kind of fine difference λ was designed to detect. Campaign One therefore begins with the cheapest place where predicate abstraction may fail.

The blocking-question block is equally important but for a different reason. Blocking gates often handle correction, reclassification, dependency, layer routing, collision, and quarantine. These are not inert predicates. A blocking gate may change the description under which another blocking gate evaluates the same state. It may route to correction before another gate can detect layer-crossing. It may classify a naming collision before dependency load is read. It may turn a state from ordinary evaluation into quarantine before downstream cost is computed. Internal blocking order is therefore a natural site for conditional commutation. Testing it early is not speculative. It is structural hygiene.

The block swap probes a deeper assumption: that zero evaluation must precede blocking evaluation. The canonical rationale is strong. Zero-questions remove states that should not receive ordinary processing. Blocking-questions handle states that may still be corrected, rerouted, or held. But if this relation has not been compiled as hard constraint, it remains a candidate edge in the dark canon. The block swap asks whether a state that would be zero-routed under its original name might be reclassified or corrected before the zero-question reads it, and whether a blocking route might be foreclosed by an earlier zero failure. This test is dangerous enough to require explicit lattice permission, but important enough not to be skipped if the lattice allows it.

Campaign One does not test every candidate named in Part I. Zebra-Ø against budget computation remains a high-priority candidate for a threshold-focused extension, but it is held fixed in the primary first campaign unless the sealed design declares a separate diagnostic subset. The reason is isolation of effects. If the first campaign permutes zero-questions, blocking-questions, block relation, Zebra-Ø, and budget simultaneously, an observed λ value may be hard to localize. The first campaign favors local interpretability over dramatic coverage. Later campaigns may widen Π after the internal blocks have been measured.

The campaign’s tested set must therefore be named with exactness. Let Π_Z denote the selected internal zero-question orderings. Let Π_B denote the selected internal blocking-question orderings. Let Π_swap denote the selected block-swap orderings, if admitted. The first campaign’s Π_1 is the union of the scheduled tests, not the full linear-extension space Π_L. If Π_Z contains all twenty-four zero orderings, that subset is exhausted. If Π_B contains all twenty-four blocking orderings, that subset is exhausted. If Π_swap contains only canonical-internal block reversal, then only that swap is tested. The report must never inflate Π_1 into Π_L.

The first campaign may be designed in stages. Stage One replays π₀ against π₀ as the null instrument and runs expected-commuting controls. Stage Two tests Π_Z over selected classes. Stage Three tests Π_B over selected classes. Stage Four runs the admitted block-swap subset. Each stage has its own control checks, exclusion rules, and underpowered-class records. If Stage Two discovers severe instrument instability, later stages may pause under rollback readiness. If Stage Two finds nonzero λ or φ, Stage Three still proceeds only if the sealed campaign design requires it and budget remains valid. Results do not rewrite the schedule during execution.

The sampling plan must be predeclared. If all twenty-four orderings cannot be tested for every class, the campaign selects by rule rather than by operator intuition. A minimal sample includes π₀-internal order, full reverse order, every adjacent transposition relative to π₀, and structurally prioritized orderings placing overlap-prone gates first. The same logic applies to blocking permutations. The campaign may stratify by class, testing full twenty-four coverage for small high-risk classes and sampled coverage for large low-risk classes. This is allowed only if declared before execution. Sampling after partial results is contamination.

The campaign must also preserve negative results. If all tested zero permutations return λ = 0 and no status flips for a class, the result is a zero result for Π_Z in that class and epoch, not evidence that all legal orderings commute. If all tested blocking permutations return zero, the blocking block receives a class-indexed internal commutation certificate for the tested subset or full twenty-four, depending on coverage. If the block swap returns zero, the block relation is certified only for the tested block arrangements. Every certificate carries class, epoch, Π, θ_λ, control status, and replication status. There is no unindexed triumph.

If a nonzero result appears, the restriction makes the result actionable. A nonzero λ in Π_Z points to zero-block ordering residue. A status flip in Π_B points to blocking-block order fragility. A block-swap status flip points to the boundary between prior disqualification and corrective/routing evaluation. These are not yet complete maps, but they are precise enough to route remediation, broaden sampling, or activate Part IV with class restrictions. The first campaign is narrow so that a positive finding has a known address.

The first campaign also has a defensive function. It protects the canon from overinterpreting a clean result. A zero result in the first campaign would mean that the cheapest inherited freedoms did not reveal order-dependence in the tested classes. It would not prove that Zebra-Ø and budget commute. It would not prove that all cross-stage rearrangements are harmless. It would not prove that future epochs remain stable. It would justify proceeding to broader campaigns or issuing only the certificates the data supports. The restriction is therefore a discipline against both panic and overclaim.

The logic of Campaign One is now fixed. Begin with the smallest uncompiled intervals. Test the lists the canon most likely treated as lists. Preserve the major architecture. Keep the cost bounded. Record every ordering. Distinguish sampled subsets from exhausted subsets. Let zero results remain bounded. Let nonzero results activate the branch without pretending the whole lattice has been mapped.

The first question is not whether every legal ordering commutes.

The first question is colder: did the canon’s most ordinary inherited lists already carry law?


6.3 — The Second Campaign’s Extension

The second campaign does not begin because curiosity remains. It begins only if the first campaign returns a result that justifies extension or a bounded zero result that leaves structurally important candidate pairs untested. The first campaign asks whether the inherited internal lists already carry order. The second campaign asks whether order-dependence appears when the Check’s stages are allowed to cross their inherited boundaries. This is a different question. It has higher cost, higher interpretive risk, and greater proximity to compiled constraints. For that reason, the second campaign cannot be an operational continuation by habit. It must enter as an LCR-A amendment.

The first campaign’s restriction protected localization. Zero-question permutations, blocking-question permutations, and the block swap test keep most of the Check fixed while disturbing the cheapest uncompiled intervals. The second campaign relaxes that restriction. It moves operators across block and stage boundaries where the precedence lattice permits or where an admitted diagnostic lattice authorizes a controlled exception for measurement. The central candidates are Zebra-Ø before the 4-0-4 and budget computation before Zebra-Ø. These tests are structurally more invasive because they alter the position of coherence and cost relative to early refusal, correction, and routing. They therefore require stronger justification than internal block permutations.

The first cross-stage candidate is Zebra-Ø before the 4-0-4. Under the canonical ordering, Silence Entry holds the state, the zero-questions test disqualifying entry conditions, the blocking-questions test correction and routing conditions, and only then does Zebra-Ø evaluate coherence. This inherited order gives early gates authority to determine whether the state should reach coherence testing at all. A second-campaign extension may ask whether coherence should be measured before early refusal and blocking surfaces act. The question is not whether the canon prefers coherence first. The question is whether moving coherence earlier changes residue, status, failure locus, or downstream budget in replay.

This candidate is dangerous because Zebra-Ø before the 4-0-4 changes the description of what it means for a state to be coherent. In π₀, coherence is read after the state has survived prior disqualification and blocking review. Earlier coherence would read the raw or less-processed submission. It may detect collapse before naming correction. It may fail a state that a blocking gate would have rerouted or clarified. It may pass a state under its original surface before a zero-question later detects forbidden prior force. It may write coherence residue that π₀ would never write because π₀ would have routed the state earlier. The test therefore probes whether coherence is downstream confirmation or upstream exposure.

The second cross-stage candidate is budget computation before Zebra-Ø. Under π₀, G_Ø writes coherence_factor before G_A computes path cost and A_B relation. This gives budget the coherence information needed to price proof friction, dependency load, maintenance obligation, and admissibility risk. If budget computation precedes Zebra-Ø, the cost engine evaluates a state whose coherence has not yet been measured. This may not matter in classes where cost is insensitive to coherence. It may matter at thresholds where coherence affects proof friction or where negative A_B can reject a state before Zebra-Ø would have produced a coherence trace. The test therefore probes whether cost is independent of coherence or secretly relies on its inherited prior position.

The second campaign may also include selected cross-block permutations beyond the simple block swap of Campaign One. If the first campaign finds nonzero λ or φ inside one block, the second campaign may test whether that local effect amplifies, cancels, or migrates when gates from the zero and blocking blocks are interleaved. A zero-question testing prior intention may be placed after a blocking-question that corrects the state’s name. A blocking-question testing layer collision may be placed before a zero-question that would have refused the original packet. These cross-block orderings test whether the block boundary itself is load-bearing. They do not replace the block-swap test. They refine it.

The condition for second-campaign entry must be declared before Campaign One executes. The campaign may proceed to Campaign Two if Campaign One returns replicated nonzero λ in any class, replicated nonzero φ in any class, a class-indexed zero result that leaves predeclared cross-stage candidates unresolved, or an archive-quality result showing that internal order is stable enough to justify more expensive testing. It may not proceed merely because the operator wants a stronger result. It may not stop merely because the first campaign returned an inconvenient signal. The transition rule belongs to the sealed design or to the later LCR-A amendment, not to operator preference.

If Campaign One finds nonzero λ or φ, Campaign Two is justified as localization and expansion. A zero-block residue difference may require testing whether Zebra-Ø amplifies that residue when moved earlier. A blocking-block status flip may require testing whether budget before Zebra-Ø would route the same states differently. A block-swap event may require interleaving specific zero and blocking gates rather than moving whole blocks. In this branch, Campaign Two asks how far the ordering effect extends. It maps propagation.

If Campaign One returns zero within the declared error budget for the tested classes, Campaign Two may still be justified, but on a different basis. A clean internal-block certificate does not answer cross-stage candidates. Zebra-Ø against budget remains structurally distinct from zero-question internal ordering. Coherence before early refusal remains structurally distinct from blocking permutation. A zero result in the cheapest region gives the canon discipline, not omniscience. In this branch, Campaign Two asks whether the untested cross-stage candidates also commute or whether order-dependence appears only when coherence and cost are moved.

The design of Campaign Two is itself an LCR-A amendment. This means it is not a correction to compiled law, not yet a Level 2 or Level 3 update, and not a branch-conditional remediation. It is a limited amendment to the measurement protocol. It must state what new orderings are added, what lattice relation authorizes them, whether the test is primary or diagnostic, what classes are included, what exclusions apply, what additional controls are required, how θ_λ is recalibrated if needed, how φ is computed over the expanded Π, and how the new results relate to Campaign One. Without this amendment, Campaign Two does not exist as protocol. It exists only as improvisation, and improvisation is inadmissible.

The LCR-A amendment must pass the same reflexive Check as Σ_replay. It enters Silence Entry without preferred result. It faces the zero-questions for prior commitment, unlawful object, ledger-original contact, and premature governance effect. It faces blocking review for register collision, object collision, unresolved dependency, and rollback readiness. It faces Zebra-Ø for coherence of the expanded design. It faces budget computation for the cost of wider replay. It enters embargo before execution. It receives final witness before commit. Only then may the expanded permutation set be executed. A second campaign that bypasses this process becomes Shadow Layer C inside the measurement instrument.

The amendment must also name whether a cross-stage test is primary or diagnostic. A primary test uses legal linear extensions of the existing precedence lattice and may contribute directly to Λ and φ. A diagnostic test uses a specially admitted local or experimental lattice to evaluate a suspected dependency outside the primary legal space. Diagnostic results may reveal why the Check’s current lattice is necessary or may motivate later law change, but they cannot be merged silently into primary λ/φ results. A result from a diagnostic lattice answers a different question: not “what happens under another legal ordering of the current Check,” but “what would happen if this constraint were relaxed under controlled observation.” The two must remain separate.

Zebra-Ø before the 4-0-4 is likely to require this distinction. If the compiled definition of Zebra-Ø presupposes that the state has survived early entry discipline, then moving G_Ø before the 4-0-4 is not a primary legal extension. It is a diagnostic challenge to the inherited architecture. If, however, the precedence lattice records no hard edge requiring early gates before G_Ø, then the movement may be primary. The amendment must decide this before execution by citing the lattice, not after seeing results. A nonzero diagnostic result cannot be used to claim primary non-commutation without a lawful bridge. A zero diagnostic result cannot certify the current lattice either. It can only inform whether a future LCR should recompile the stage relation.

Budget before Zebra-Ø may be primary or diagnostic depending on how G_A is defined. If G_A’s domain explicitly reads coherence_factor as a required input, then G_A cannot precede G_Ø in the primary lattice unless the amendment defines a lawful “coherence-unknown” budget mode and compiles it as part of the test. If G_A can price a state without coherence_factor by assigning an uncertainty surcharge, then budget-before-Zebra may be a legal extension under a declared rule. The amendment must state which case applies. Otherwise a nonzero λ could merely reflect that budget was asked to compute outside its domain.

The second campaign must strengthen contamination controls. Cross-stage permutations increase the risk that a gate writes a field ordinarily expected by another stage. Therefore the run logs must record absent-field conditions explicitly. If Zebra-Ø runs before renaming, the log records the submitted description under which coherence was read. If budget runs before Zebra-Ø, the log records whether coherence_factor was absent, defaulted, unknown, surcharged, or illegally inferred. If an early route prevents a later stage from executing, the log records non-application by prior route. These details are not secondary prose. They are the evidence needed to determine whether the expanded ordering produced genuine residue or merely underdefined execution.

Controls must be expanded accordingly. Campaign Two includes π₀-versus-π₀ controls as before, but it also requires stage-specific null controls. If a cross-stage ordering introduces a coherence-unknown mode for budget, then a control class where coherence is known to be irrelevant must be tested to verify that the mode does not create artificial residue. If Zebra-Ø is moved before the 4-0-4, a control class of clean submissions should show no spurious failure solely because coherence was read earlier. If such controls fail, the cross-stage apparatus is unstable. The amendment must then pause, narrow, or void the affected subset.

The second campaign must not overwrite Campaign One’s result. It extends, localizes, or challenges it under a new sealed design. If Campaign One found zero internal-block residue, and Campaign Two finds nonzero Zebra-Ø versus budget residue, the result is not contradiction. It means internal block order was stable while coherence-cost ordering was not. If Campaign One found nonzero zero-block residue and Campaign Two finds zero cross-stage residue, the result is also not contradiction. It means the detected holonomy was local to the zero block. The results inhabit different regions of Π_L or different diagnostic spaces. They must be ledgered with separate campaign IDs and then compared.

The amendment must also determine whether Campaign Two inherits θ_λ from Campaign One or recalibrates it. If the same replay engine, same residue representation, same archive class, and same epoch are used, θ_λ may carry forward with justification. If cross-stage movement introduces new absent-field modes, new budget behavior, new Zebra-Ø timing, or new diagnostic lattice conditions, the null instrument may need recalibration. The error budget belongs to the measurement apparatus actually used, not to the title of the project. A cross-stage campaign with altered mechanics cannot borrow precision from an internal-block campaign without proof.

The output of Campaign Two is an expanded Λ and φ report indexed by campaign ID, class, epoch, Π, lattice type, and amendment hash. If the campaign is primary, its results may join the main branch decision. If it is diagnostic, its results enter an LCR queue and may support later change, but they do not retroactively alter the primary campaign’s certificate. If the campaign is mixed, with some primary legal extensions and some diagnostic tests, the report must separate them. The ledger must not allow diagnostic urgency to contaminate primary measurement.

The second campaign’s extension therefore follows a colder rule than ordinary research expansion. It does not ask what else would be interesting to test. It asks what the first campaign leaves unresolved, what the lattice lawfully permits, what the budget can support, what controls can stabilize, and what LCR-A amendment can be witnessed before execution. If those conditions are absent, the second campaign waits. If they are present, it proceeds under seal.

Campaign One tests the inherited lists.

Campaign Two tests the inherited borders.

No border is crossed by improvisation.


6.4 — Forbidden Orderings as Compiled Content

The precedence lattice does not only generate legal orderings. It also produces an inventory of forbidden orderings. This inventory is not an appendix of convenience. It is canon. For the first time, the Check’s order is compiled not merely by the sequence it happens to run, but by the explicit statement of what it is not allowed to run. The forbidden space matters because it prevents the replay campaign from confusing illegal rearrangement with non-commutation, and it prevents inherited order from silently pretending to be law. A lawful measurement must know both sides of its boundary: the linear extensions that may be tested, and the orderings excluded because they would destroy the identity of the Check.

A forbidden ordering is any proposed word over Ω_Check that violates at least one compiled constraint of the precedence lattice. It may contain all required operators. It may look procedurally plausible. It may even produce an apparently meaningful output if forced through an implementation. None of that makes it legal. The replay protocol does not ask whether an illegal word could be executed by a machine. It asks whether the word is still the Admissibility Check. If the answer is no, the word cannot generate λ or φ. It can only generate an Invalid Ordering Record.

The first forbidden class is any ordering in which Silence Entry is not minimal. If G_S appears after any evaluative gate, the word is excluded by the compiled constraint that the state must be held before judgment. A zero-question before Silence Entry is not early rigor; it is unheld refusal. A blocking-question before Silence Entry is not efficient classification; it is classification before entry. Zebra-Ø before Silence Entry is coherence testing without non-emission. Budget before Silence Entry is pricing before the state has been received. These orderings are forbidden because they change the condition of statehood inside the Check. They do not test an alternative legal order. They abolish the Check’s first boundary act.

The second forbidden class is any ordering in which commit is not maximal. If C appears before any required admissibility, routing, budget, embargo, or witness operation, the word is excluded by the compiled constraint that commit terminates the pre-executable condition. A gate after commit is not part of the Check. It is post-commit audit, maintenance, rollback review, or illegible residue. Commit cannot be moved earlier to test whether the later gates mattered. The moment commit occurs, the state has left the domain in which those gates act as admissibility operators. Therefore every word with C before the completed Check path is invalid.

The third forbidden class is any ordering that places final witness after commit or removes final witness from the terminal segment. The compiled constraint is G_W ≺ C. A committed state without final witness is unwitnessed admission. A witness after commit is not final witness; it is post-commit observation. The Check requires witness before entry because the boundary must record the passage before the passage becomes executable. This constraint is not inherited decoration. It is part of the canon’s refusal to let runtime existence precede boundary memory.

The fourth forbidden class is any ordering that places embargo after final witness, after commit, or before the verified object exists. The compiled terminal relation is positive verification before embargo, embargo before final witness, final witness before commit. An embargo after witness has no protective function for the witness to confirm. An embargo after commit is delay after entry, not pre-runtime discipline. An embargo before verification is suspension without a verified object. The protocol may study delay mechanisms elsewhere, but such mechanisms are not E_72 as compiled here. Therefore words violating the terminal relation are excluded.

The fifth forbidden class is any ordering that asks a gate to read a required field before that field can exist. If an operator domain explicitly requires prior trace, prior status, prior coherence_factor, prior budget relation, prior routing annotation, or prior witness field, then any word that places the reader before the writer is forbidden in the primary lattice. This is not a preference for familiar sequence. It is domain preservation. A gate cannot be legally tested in an order where its input does not exist unless the campaign has admitted a diagnostic lattice that defines an absent-field mode. Without such admission, the run is invalid, not non-commuting.

The sixth forbidden class is any ordering that duplicates a required gate. A word containing G_Ø twice is not a more rigorous Zebra-Ø test. A word containing budget computation twice is not a better A_B estimate. A word repeating a zero-question after it has already not fired is not the same Check with extra caution. Duplication changes the operator multiset. The replay campaign measures order, not inventory. If the multiset changes, the comparison no longer asks whether the same gates in another order produce a different result. It asks whether a different procedure produces a different result. That is not λ.

The seventh forbidden class is any ordering that omits a required gate from the word. Omission is not the same as routed non-application. If a legal word contains G_j after G_i and G_i routes the state before G_j is reached, G_j is logged as non-applied by prior route. The gate remains present in the word. By contrast, a word that removes G_j from the Check never gives the state the legal possibility of encountering it. Omission changes the procedure. A run without Zebra-Ø is not a legal replay of the Check unless the state’s path lawfully terminates before Zebra-Ø under a word that still contains it. A run without budget computation is not a budget-efficient Check. It is a different instrument.

The eighth forbidden class is any ordering that inserts an unapproved operator into the Check word. A new linter, a manual adjudication step, an interpretive clarification, a retroactive naming correction, a discretionary exception, a human override, or an auxiliary score cannot be inserted between gates during replay unless it has passed as part of Σ_replay or an admitted amendment. The replay campaign cannot improve the Check while measuring it. Inserted operators contaminate the word and destroy comparability with π₀. If a new operator is needed, it belongs to an LCR path, not to the active campaign.

The ninth forbidden class is any ordering that collapses routing into post-hoc annotation. If a gate fires and routes the state to quarantine, non-admissible status, correction, or another terminal or holding path, later gates may not continue as if routing were merely a note. A word that forces all gates to execute regardless of prior route is not the Check. It is an all-gates survey. Such a survey may be useful in a diagnostic appendix, but it cannot produce primary λ because it denies the operator nature of routing. The Check is a routed word, not a questionnaire.

The tenth forbidden class is any ordering that treats live side effects as part of replay. If a word causes replayed Zebra-Ø failure to raise live negative-linter sensitivity, or causes replayed A_B computation to spend live manifold budget, or causes replayed status to edit the original ledger entry, the ordering is forbidden as executed even if its symbolic sequence was legal. The compiled constraint here is not an ordering edge between gates but a measurement constraint: replay touches copies, not originals; replay writes campaign trace, not live governance. An otherwise legal word becomes invalid when executed through live side-effect channels.

The eleventh forbidden class is any ordering that lacks a valid π₀ reference under the same state identity conditions. A proposed π may be symbolically legal, but if the same Σ cannot be replayed under π₀ in the same cloned context, no λ comparison exists. The word is not forbidden in the abstract lattice, but it is forbidden for the campaign instance. The compiled constraint is identity of comparison. A legal alternative without a reproducible reference path cannot be used to measure residue difference. It enters the invalid or undetermined record, depending on cause.

The twelfth forbidden class is any ordering whose legality depends on results observed during the campaign. If a word is added because early outputs suggest it may reveal a stronger signal, it is forbidden for the active campaign. If a word is removed because early outputs threaten a certificate, the remaining campaign is contaminated. The compiled constraint here is embargo between campaign design and campaign execution. The permutation set Π must be sealed before results are known. Orderings introduced after evidence appears belong to a new LCR-A amendment, not to the current run.

The thirteenth forbidden class is any ordering that pretends diagnostic relaxation is primary law. If an admitted diagnostic lattice allows Zebra-Ø before the 4-0-4 or budget computation before Zebra-Ø under an absent-field mode, those runs are legal within the diagnostic campaign only. They are not automatically legal linear extensions of L_Check. A diagnostic ordering becomes forbidden for primary λ/φ aggregation if the report tries to merge it with primary legal extensions without a bridge rule. Diagnostic visibility is not primary legality. The ledger must keep these categories distinct.

The fourteenth forbidden class is any ordering whose status definitions differ from the campaign’s sealed definitions. A word cannot classify quarantine as non-admissible in one run and as boundary-held in another merely because that makes aggregate reporting easier. Status is part of the measurement. If the same routing event is translated into different final categories across orderings, the campaign has changed the codomain. Such a run is invalid for φ. The compiled constraint is status-set identity across Π.

The fifteenth forbidden class is any ordering whose residue representation differs from the reference run. A word cannot compute witness_residue in scalar units under π₀ and structured units under π, or use a later ledger extension for an earlier epoch without an admitted conversion rule. λ differences residue values within one declared representation. If the representation changes across orderings, the result is not nonzero λ. It is unit contamination. The run is forbidden for primary λ until residue-unit identity is restored.

This inventory is not exhaustive in the literary sense, but it is operationally complete for the first protocol. Appendix C records the formal edge set and invalid classes as the Forbidden Ordering Ledger. Each forbidden class is linked to the compiled constraint that excludes it: minimality of Silence Entry, maximality of commit, terminal-segment order, domain dependency, operator-multiset identity, route preservation, replay isolation, comparison identity, design-execution embargo, primary/diagnostic separation, status-set identity, and residue-unit identity. An invalid ordering without a cited constraint is not allowed to remain as taste. It must either be admitted as legal, compiled as forbidden, or quarantined as an unresolved lattice gap.

The observation is decisive. The Forbidden Ordering Ledger is itself new canon. Before this volume, the Check had an inherited sequence and a set of functional expectations. It did not have a fully explicit compilation of what its order must be independent of what it happens to be. The lattice now forces the distinction. Some edges become compiled law. Some inherited edges become testable freedom. Some proposed orderings become invalid. Some gaps become LCR candidates. This is the first explicit compilation of mandatory order.

That compilation changes the status of π₀. π₀ is no longer silently identical with the Check’s law. It is one legal linear extension inside a partially compiled space, surrounded by forbidden words and alternative lawful words. Where π₀ coincides with compiled edges, it expresses law. Where π₀ chooses among unconstrained intervals, it expresses inherited convention under measurement. Where π₀’s inherited choices are later shown to affect residue or status, those choices may themselves become compiled content. The ordering ceases to be background.

This also changes the status of invalidity. An illegal ordering is not useless. It teaches the canon what the Check must not be. A run rejected by the lattice leaves an Invalid Ordering Record. A repeated desire to test a forbidden ordering may reveal pressure for an LCR-A diagnostic amendment. A diagnostic result may later motivate law change. But none of these pathways allows the forbidden word to enter primary measurement as if it were merely another permutation. Boundary discipline begins by refusing to learn from the wrong object.

The replay campaign therefore carries two artifacts into execution. The first is Π, the tested set of legal orderings. The second is the Forbidden Ordering Ledger, the set of orderings and ordering classes excluded by compiled constraint. Π tells the archive how it may be asked. The forbidden inventory tells the archive which questions would no longer be the Check. Together they convert ordering from habit into governed structure.

The Check now has not only a canonical word.

It has a lawful space.

It has a forbidden space.

Both are canon.


Chapter 7 — Statistical Architecture

7.1 — Stratification by Failure Locus

The replay campaign must not treat the archive as one homogeneous mass. The Check does not fail states in one undifferentiated way. A state may die at a zero-question, at a blocking-question, at Zebra-Ø, at budget computation, during quarantine routing, or at the boundary between verification and witness. Each death has a different geometry. Each writes a different trace. Each exposes the state to a different portion of the operator word before termination. If order-dependence exists, it is unlikely to distribute evenly across all submissions. The statistical architecture must therefore begin with stratification by failure locus.

The import comes from the Refusal Spectrum. The Refusal Spectrum does not treat refusal as a flat negative. It partitions refusal by where, how, and under what boundary condition the state was denied, held, or routed. A zero-question refusal is not the same event as Zebra-Ø collapse. A blocking quarantine is not the same event as budget rejection. A late budget failure is not the same event as early disqualification. The replay campaign imports this partitioning as the first statistical map of the archive. Submission classes are defined by historical failure locus under π₀ before alternative orderings are run.

The primary strata are zero-question failure, blocking-question failure, Zebra-Ø failure, and budget failure. A zero-question failure class contains states whose canonical π₀ trace records termination or decisive routing at one of the four zero-questions. A blocking-question failure class contains states whose canonical trace records decisive routing, correction, quarantine, or refusal at one of the four blocking-questions. A Zebra-Ø failure class contains states whose canonical trace records coherence failure, negative coherence relation, or Zebra-triggered non-admissibility. A budget failure class contains states whose canonical trace records negative A_B, insufficient budget, proof-friction overload, maintenance-cost overload, or budget-triggered quarantine or rejection. These classes may be subdivided by the specific gate inside the block, but the first statistical layer uses the four major loci.

The class assignment is historical, not counterfactual. A state belongs to the locus at which π₀ killed, held, or routed it. Alternative orderings may later move the state to another failure locus, and that movement is itself evidence. But the baseline stratum is fixed by the original π₀ trace. This rule prevents post-result class drift. If a state historically failed at Zebra-Ø but fails at a blocking-question under an alternative ordering, it remains in the historical Zebra-Ø class for the primary Λ and φ estimate, while the failure-locus migration is recorded as an outcome variable. The class defines where the state died under the inherited law. The replay records where it dies under other lawful words.

Λ and φ must be estimated per class. A single aggregate Λ over the whole archive can conceal local holonomy. If early zero-question failures are stable and late budget failures are fragile, the global mean may appear small while the budget class carries real order-dependence. If blocking failures produce positive λ and Zebra-Ø failures produce negative λ, averaging may cancel the signal while leaving the manifold order-dependent in both regions. If only a small late-failure class contains status flips, global φ may look administratively minor while the affected class is canonically severe. The campaign must therefore report Λ(zero, epoch), Λ(blocking, epoch), Λ(Zebra-Ø, epoch), Λ(budget, epoch), and the corresponding φ values for the declared Π.

This is not statistical ornament. It follows from the operator geometry. Early failure classes encounter fewer gates. A zero-question failure may be routed before blocking, Zebra-Ø, budget, embargo, and final witness. Its order-dependence may concentrate inside the zero block or at the zero-block boundary. A budget failure has survived much more of the word. It has passed or avoided zero surfaces, passed or avoided blocking surfaces, encountered Zebra-Ø, and reached cost computation. It has accumulated more contact with the boundary. More contact creates more opportunity for residue difference. Late death is therefore structurally more exposed to λ.

The same logic applies to φ. A state that dies early may be hard to rescue by alternative order if the disqualifying condition is robust and independent of naming, coherence, or budget. But a state that dies late may sit near a threshold. If Zebra-Ø writes coherence before budget, the state may fail cost. If budget is computed before coherence, it may reject earlier or route differently. If a blocking gate reclassifies before a zero-question reads intent, a quarantine may replace refusal. Late failures often lie near decision surfaces where small procedural changes can move final status. The campaign must therefore expect order-fragility to concentrate near late death, while remaining open to early-block surprises.

The phrase “where states die late” must be interpreted operationally. Late death does not mean dramatic content. It means a state survived enough of the Check to accumulate multiple prior gate interactions before termination. A late failure has more preceding trace, more possible residue accumulation, more dependency on earlier field writes, and more opportunity for route alternatives. A budget failure after Zebra-Ø is late relative to a zero-question failure. A final witness failure is later still, if present in the archive. The first campaign focuses on the four primary loci, but the principle generalizes: the later the historical failure locus, the more carefully the campaign must preserve path detail.

The classing system must also retain internal subloci. The zero-question class may be subdivided into Z1, Z2, Z3, and Z4. The blocking class may be subdivided into B1, B2, B3, and B4. Zebra-Ø may be subdivided by coherence band, coherence failure mode, and negative-linter relation. Budget may be subdivided by deficit magnitude, proof-friction source, dependency load, maintenance cost, or re-witnessing demand. The primary report may aggregate to four major classes, but the run ledger must retain the sublocus. If a signal appears, the sublocus becomes the first map of remediation.

Class assignment must occur before replay. The campaign reads the historical π₀ trace, assigns the state to its baseline failure-locus class, seals the selection record, and only then executes alternative orderings. A state cannot be moved into a class because it produced a stronger λ there. A class cannot be split after seeing status flips unless the split is marked exploratory and excluded from primary branch activation. Primary Λ and φ require predeclared classes. Exploratory refinements may guide later campaigns, but they do not retroactively rewrite Campaign One.

The denominator of each class is the number of eligible, completed, contamination-controlled states in that class for the tested Π. It is not the total number of historical submissions that once touched the class. Excluded states are recorded but not counted as stable. Underpowered classes are marked underpowered. A class with five valid states and no status flips does not receive the same certificate force as a class with five hundred valid states and no status flips. The statistical architecture must report class size, exclusion count, void count, completed count, and replication count. A zero estimate without denominator discipline is not a certificate.

Λ per class is reported as a distribution, not as a single average. For every class, the campaign records the full set of λ values by state and ordering, then derives summaries only after preserving the distribution. Required summaries include the median, mean where appropriate, maximum absolute λ, sign distribution, tail mass beyond θ_λ, and the count of replicated nonzero values. These summaries do not replace the distribution. They help the operator see whether order-dependence is diffuse, rare, thresholded, or concentrated in a sublocus. The Refusal Spectrum requires shape, not only magnitude.

φ per class is reported as a fraction with transition anatomy. It is not enough to say that φ = 0.03 in the budget class. The report must state which status transitions occurred: admissible to quarantine, quarantine to non-admissible, non-admissible to quarantine, quarantine to admissible, or other permitted transitions under the sealed status set. The report must also identify whether flips are concentrated in one sublocus, one ordering pair, one budget band, or one coherence band. φ is hard, but it still needs anatomy. A status flip without transition anatomy cannot guide remediation.

Failure-locus stratification also prevents the wrong null. If a global campaign returns no overall mean residue difference but the Zebra-Ø class shows a tail of nonzero λ, the correct result is not “λ = 0.” The correct result is class-indexed: zero or near-zero in some classes, nonzero tail in the Zebra-Ø class. If a global φ is low because late failures are a small portion of the archive, the correct result is not “status fragility negligible.” The correct result is the fraction within the affected class and the class’s weight in the archive. The archive-wide rate may inform governance cost, but the class rate informs law.

The campaign should therefore sample with stratification, not by archive convenience. If the archive contains many early zero-question failures and fewer budget failures, a simple random sample may underrepresent the late-death region where order effects are most plausible. The first campaign must either oversample late-failure classes or report that late-failure classes remain underpowered. Oversampling does not distort the class estimate because estimates are reported per class. It only prevents the campaign from spending its budget where order effects are least likely while leaving the dangerous strata silent.

This does not mean early failures are unimportant. The zero-question class is the first test of predicate abstraction. If multiple zero conditions overlap, internal zero order may alter failure locus and residue even when final status remains refusal. Blocking failures test whether correction and naming routes are order-stable. Early classes are cheaper and may expose dark canon quickly. The point is not to ignore them. The point is to prevent their abundance or simplicity from washing out the later classes where path length and threshold proximity create higher structural risk.

The stratification must also respect epoch boundaries. A failure locus under one epoch may not be equivalent to the same label under another if Zebra-Ø sensitivity, budget rules, residue representation, or gate definitions changed. The campaign may report Λ(Zebra-Ø failure, epoch 1) and Λ(Zebra-Ø failure, epoch 2), then compare them in a later longitudinal analysis. It may not merge them into one class unless a bridge rule has been admitted. Refusal Spectrum classes are ledger-contextual. The label is stable only where the underlying gate definitions are stable.

The statistical architecture must record failure-locus migration as a secondary but essential observable. For each state, the replay report compares historical π₀ failure locus with the failure locus under every tested π. A state may remain in the same final status while migrating from Zebra-Ø failure to budget failure, or from zero-question failure to blocking quarantine. Such migration may produce λ without φ. It may also foreshadow linter divergence: in live deployment, different failure loci would write different future sensitivity. The class estimate of Λ therefore belongs together with a migration matrix, even if the primary section reports only class distributions.

The migration matrix does not redefine baseline class. It shows how alternative orderings move states across failure surfaces. Rows are historical π₀ loci. Columns are replay loci under π. The diagonal records locus stability. Off-diagonal cells record movement. A class with zero φ and nonzero off-diagonal migration still matters because the final status may remain the same while the boundary learns a different lesson. The matrix is one of the bridges between λ measurement and later Refusal Spectrum decomposition.

The requirement is now explicit: every campaign report must estimate Λ and φ per failure-locus class before issuing any aggregate claim. Aggregate Λ_archive and φ_archive may be included only after class estimates are reported, and must be labeled as administrative summaries. They cannot activate a global certificate if any class is underpowered or nonzero. They cannot suppress a nonzero class through dilution. They cannot convert a local status flip into a rounding artifact. The law fails locally before it fails globally, and the metric must be able to see that.

Stratification by failure locus is therefore the first statistical discipline of Part II. It imports the Refusal Spectrum’s refusal anatomy into the replay campaign, protects late-death classes from being hidden by early-death abundance, preserves the difference between residue, status, and locus migration, and forces every certificate or crisis to carry an address. The archive is not a single field. It is a partitioned boundary memory. The measurement must read it as such.

Order effects may not appear everywhere.

They may appear where the state almost survived.

They may appear where the state died late.

That is where Λ and φ must be able to speak.


7.2 — Sample Sizes and the Error Budget

The replay campaign cannot assert zero by exhaustion of patience. It can assert zero only inside an error budget, on a declared sample, after the null instrument has been measured, and with enough completed states to make the class legible. The statistical architecture therefore begins by separating four conditions that are often confused: absence of observed difference, measured zero within error budget, underpowered class, and invalid campaign. Only the second can support a certificate. The first is merely silence. The third is undetermined. The fourth is void.

For every class and every tested ordering, the campaign must declare how many Σ are required before execution begins. The unit is not “submissions in the archive.” The unit is replay-admissible, hash-fixed, closed ledger entries with complete π₀ trace, residue representation, final status, class assignment, epoch context, and contamination-controlled replay capacity. A class may contain many historical submissions and still yield few valid Σ. The campaign must report both numbers. Historical abundance is not statistical power if the archive cannot support replay.

The minimum sample size per class depends on the signal being estimated. For λ, the campaign estimates a distribution of residue differences. It needs enough completed Σ per class per ordering to distinguish ordinary replay variation from order-generated residue. For φ, the campaign estimates the fraction of states whose final status differs across the tested permutation set Π. It needs enough completed Σ per class to avoid mistaking non-observation of a rare status flip for proof that no such flip exists. These are different burdens. Residue estimation requires distributional stability. Status-fragility estimation requires enough exposure to detect low-frequency categorical rupture.

The protocol therefore sets two thresholds for every class: N_λ_min and N_φ_min. N_λ_min is the minimum number of completed λ comparisons required to report Λ(class, epoch) for a given Π. N_φ_min is the minimum number of completed state-level status sets required to report φ(class, Π). A state contributes to λ for a specific ordering π only if both Check_π(Σ) and the reference Check_π₀(Σ) complete valid replay runs under the same cloned context. A state contributes to φ only if all required orderings in the class’s declared Π complete valid status-producing runs or are handled by a predeclared missing-run rule. Partial completion is not silently counted as stability.

For the first campaign, the conservative default is staged rather than maximal. Each failure-locus class should begin with a pilot cell sufficient to estimate the replay noise floor and detect obvious order effects, then expand to the declared class target if controls hold. A practical first threshold may require at least thirty completed replay-admissible Σ per class per primary ordering subset for λ distribution reporting, with higher targets for late-death classes, threshold classes, and classes expected to carry rare φ events. This number is not magic and must not be fetishized. It is a minimum discipline: below it, the class is treated as pilot or underpowered unless an extreme replicated status flip already activates φ. The protocol may set stricter values in Appendix A if the archive permits.

The campaign must also account for the number of orderings. If Π_Z contains all twenty-four zero-question orderings and a class contains thirty Σ, the campaign must execute thirty valid π₀ references and thirty valid runs for each tested zero ordering, or the predeclared paired-comparison design that makes equivalent use of controls. If Π_B is sampled rather than exhausted, the sample size applies to the sampled set, not to the full block. If a state fails replay under one ordering because of protocol defect, it cannot remain in the denominator for comparisons requiring that ordering unless the missing-run rule was declared in advance. The denominator follows the completed comparison, not the desired table.

The noise floor is estimated from π₀-versus-π₀ control runs. These controls are not ceremonial. They define the measurement instrument’s ordinary variation when no order difference exists by design. For a selected state Σ, two independent copies are replayed under π₀ in the same cloned epoch context, with separate run IDs, separate traces, and separate witness signatures. The difference between their witness_residue values is recorded as δ₀(Σ). Across a control set, the distribution of δ₀ estimates the residue noise floor for the class, epoch, replay engine, operator pair, and residue representation. The campaign does not choose θ_λ before seeing this null behavior. It declares the rule for deriving θ_λ, then computes the threshold from the null.

The error budget θ_λ is the declared bound within which λ is treated as zero. A λ value whose absolute magnitude is less than or equal to θ_λ is recorded as within the zero band. A λ value whose absolute magnitude exceeds θ_λ and survives replication is recorded as nonzero. The threshold may be global for the campaign only if the π₀-versus-π₀ noise floor is stable across classes and epochs. If late-failure classes show greater null variation than early-failure classes, θ_λ must be class-specific or the affected class must be narrowed. A single threshold imposed on heterogeneous noise may either hide true residue in quiet classes or fabricate signal in noisy classes.

The derivation of θ_λ must be sealed before alternative-ordering results are interpreted. The protocol may define θ_λ as a multiple of the control-run standard deviation, a robust quantile of the absolute δ₀ distribution, a maximum tolerated null deviation plus margin, or another predeclared rule compatible with the Evidence Ledger’s residue representation. The exact method is less important than its prior commitment. A threshold chosen after candidate λ values are visible is not an error budget. It is interpretation pressure. The campaign must be able to say: under this rule, before knowing the alternative-ordering results, this is the zone in which residue difference counts as zero.

A zero assertion must satisfy four conditions. First, the class must meet or exceed the declared N_λ_min and N_φ_min for the tested Π. Second, π₀-versus-π₀ controls must show a stable null instrument and define θ_λ. Third, every tested λ value in the class must fall within θ_λ or be resolved by the predeclared replication rule as non-replicated noise. Fourth, no replicated status flip may occur in the class. If all four conditions hold, the campaign may report λ = 0 within error budget and φ = 0 for that class and Π. If any condition fails, the result is not zero. It is nonzero, underpowered, void, or undetermined according to the failure mode.

The word “undetermined” has formal force. A class returns undetermined when it lacks sufficient completed states, has unstable controls, contains too many voided runs, cannot estimate θ_λ, cannot reproduce π₀, has unresolved status coding, or fails replication without a bounded explanation. Undetermined does not mean “probably zero.” It does not mean “no evidence of non-commutation.” It means the campaign did not earn the right to decide the class. An underpowered class may not be used to support a Commutativity Certificate. It may not be used to dilute a nonzero class. It remains open.

The underpowered rule is especially important for φ. Status flips may be rare. A small class with no observed flips does not prove status stability. If N_φ_min is not met, φ(class, Π) returns undetermined unless a replicated flip is found. A replicated flip can make φ nonzero even in a small class, because existence refutes universal stability. But absence of flips in a small class does not establish zero fragility. Positive existence and negative certification are asymmetric. The campaign must be more demanding when it claims stability than when it records a discovered rupture.

The same asymmetry applies to λ. A single replicated λ beyond θ_λ is enough to refute strict residue commutation for the affected class and ordering. But many within-threshold λ values are required before the class can receive zero treatment. Discovery of nonzero is local and existential. Certification of zero is collective and bounded. This asymmetry protects the canon from easy reassurance. It also protects it from overreaction by requiring replication and threshold discipline before a small residue difference becomes branch-relevant.

Sample size must be declared per class because classes differ in risk and variance. Late-death classes may require more Σ than early-death classes because their paths contain more gates, more accumulated residue, more threshold interactions, and more opportunities for trace variation. Candidate non-commutation classes may require oversampling because their signal may concentrate in narrow bands. Clean control classes may require enough states to stabilize the null instrument but not the same depth as threshold budget classes. The campaign may allocate budget unevenly if the allocation is declared before execution and justified by failure-locus risk. Equal sampling across unequal risk is not neutrality. It is blindness.

The campaign must also declare how it handles exhausted classes. If a class contains fewer valid replay-admissible entries than N_min but includes all valid entries in the epoch, the class may be reported as “exhausted but underpowered.” This is not zero. It means the available archive was fully used and still could not support certification. The report may state descriptive findings, such as no observed λ beyond θ_λ among the available entries, but it must not issue a commutativity certificate. Archive scarcity cannot be converted into law.

For sampled permutation sets, sample size statements must name Π. A class may meet N_λ_min for Π_Z sampled orderings and fail N_λ_min for full twenty-four zero orderings. It may meet N_φ_min for canonical-internal block swap and fail for interleaved cross-block orderings. Each result belongs to its tested set. Reporting “N = 40 in the class” is insufficient unless the run coverage across orderings is specified. A state that was not run across a particular ordering cannot certify stability for that ordering.

Replication increases the effective burden. The protocol requires independent execution of the campaign. A λ value counts as replicated only if both independent operators obtain residue differences with the same sign or same nonzero classification under θ_λ, or under the predeclared agreement rule if structured residue is used. A status flip counts as replicated only if both executions produce the same status transition or a transition within the same predeclared hard-fragility class. If replication fails, the result is not averaged into ambiguity. It is routed to disagreement analysis. The affected state, class, or ordering remains undetermined until resolved.

The error budget must distinguish measurement noise from archive defect. π₀-versus-π₀ variation can arise from replay engine noise, residue representation limits, operator implementation differences, or genuine instability in the archived trace. The first two can be budgeted if bounded. The latter two may void the class. An error budget is not a trash container for every inconsistency. If the null instrument is noisy because π₀ cannot be reconstructed, the correct action is archive-defect routing, not an inflated θ_λ large enough to hide the defect. The budget absorbs measurement variance, not missing law.

The protocol must record confidence language without allowing it to replace the branch rule. Statistical summaries may include uncertainty intervals for Λ summaries and φ estimates where appropriate, especially for administrative planning. But branch activation is defined by the presence or absence of replicated nonzero λ beyond θ_λ and replicated status flips, together with class power. A class with a high uncertainty interval because of small N is undetermined, not softly zero. A class with a replicated flip is nonzero in φ regardless of whether the archive-wide rate appears small. Statistical description serves governance; it does not supersede the gate.

The reporting table for every class must therefore include: historical failure locus, epoch, tested Π, eligible archive count, excluded count, voided run count, completed state count, completed comparison count, N_λ_min, N_φ_min, π₀-versus-π₀ control count, δ₀ distribution summary, θ_λ, number of λ values beyond θ_λ, replication status of nonzero λ, number of order-fragile states, φ estimate, status-transition anatomy, and final determination. The final determination is one of four terms: zero within error budget, nonzero, underpowered/undetermined, or void. No fifth term such as “apparently stable” may enter the branch ledger.

The campaign may produce descriptive observations for underpowered classes, but they must be marked as non-branching. For example: “No nonzero λ observed among eight completed states in the budget-failure class under Π_B sample.” This is useful. It is not a certificate. The correct determination remains underpowered. The language of the report must maintain that discipline. The archive can be informative without being decisive.

The error budget also decays across protocol change. If Campaign Two introduces cross-stage orderings, absent-field modes, or diagnostic lattices, θ_λ from Campaign One may not automatically apply. The null instrument must be retested under the altered conditions. The same is true across epoch changes, residue-unit changes, linter-emulator changes, or budget-rule changes. Error budgets belong to instruments, not to books. A threshold has authority only where the measurement conditions that produced it still hold.

The statistical architecture now fixes the condition under which “nothing happened” can be said. Nothing happened only when the class was powered, the null instrument was stable, the error budget was declared, the tested orderings completed, replication agreed, λ stayed inside θ_λ, and φ stayed at zero. Anything less is not nothing. It is an unresolved measurement state.

The canon is not permitted to mistake underpowered silence for commutation.

A class that cannot answer returns undetermined.

Only a class that survives measurement may say zero.


7.3 — The Decision Thresholds

The replay campaign requires decision thresholds because measurement without a decision rule is not a gate. It may produce numbers, but it cannot tell the canon what those numbers authorize. The threshold architecture separates the fine signal from the hard signal. λ receives an error budget because witness_residue is a measured ledger quantity and the replay instrument has a noise floor. φ does not receive an error budget in the same sense because status is categorical. A replicated status flip on hash-identical Σ is not small noise. It is a different final graph position under legal ordering.

The first threshold is θ_λ. θ_λ is the residue-difference threshold above which λ is treated as nonzero for a class, epoch, and tested permutation set. It is derived from the π₀-versus-π₀ control runs, not chosen by theoretical preference. The null instrument supplies the distribution of residue differences produced when the same ordering is replayed against itself under the same cloned context. That distribution defines the ordinary variation of the replay mechanism when no ordering difference exists by design. θ_λ is then computed from that null distribution according to the sealed rule of the campaign.

This construction prevents two errors. If θ_λ is too low, ordinary replay variation may be misread as holonomy. The canon would report order-dependence where the instrument merely fluctuated. If θ_λ is too high, real residue differences may be absorbed into the error band and falsely certified as zero. The threshold is therefore not a convenience margin. It is the boundary between measurement and interpretation. It decides when a residue difference has enough force to enter the branch logic of the volume.

θ_λ must be declared per measurement domain. A single global threshold may be used only if the control-run noise floor is stable across classes, epochs, operators, residue representations, and replay conditions. If zero-question failures show low null variation while budget failures show higher null variation, the campaign must either define class-specific θ_λ values or narrow the affected class until the null instrument stabilizes. The same applies to epoch differences. A threshold derived from one ledger epoch cannot automatically govern another if linter context, residue units, budget rules, or gate definitions have drifted. θ_λ belongs to the instrument that produced it.

The sealed derivation rule may take several forms, but it must be fixed before alternative-ordering results are interpreted. The campaign may define θ_λ as a robust upper quantile of the absolute π₀-versus-π₀ differences, as a multiple of the null standard deviation, as a maximum observed null deviation plus a fixed margin, or as another rule compatible with the Evidence Ledger’s residue representation. The method must survive audit: it must be computable from the null controls, reproducible by the independent operator, and insensitive to later desire for a specific branch outcome. A threshold selected after looking at candidate λ values is not a threshold. It is branch contamination.

For each tested state and ordering, λ(Σ; π) is compared against θ_λ for its class and epoch. If |λ(Σ; π)| ≤ θ_λ, the value is recorded as inside the zero band. It remains in the Λ distribution, but it does not count as a nonzero λ event for branch activation. If |λ(Σ; π)| > θ_λ, the value is provisionally nonzero and must pass replication. If independent replay reproduces the nonzero classification under the agreement rule, the event becomes a confirmed nonzero λ. If replication fails, the event is routed to disagreement analysis and the affected state, ordering, or class remains undetermined until resolved. A non-replicated excursion beyond θ_λ is not evidence of holonomy. It is an unresolved instrument event.

The sign of λ is retained after thresholding. A positive value beyond θ_λ means the alternative ordering leaves more witness residue than π₀. A negative value beyond θ_λ means it leaves less. Both signs are nonzero. The campaign does not privilege one sign as more serious. Increased residue may indicate additional boundary contact, delayed routing, or richer witness. Decreased residue may indicate earlier routing, lost evidence, or compressed passage. The sign becomes interpretable only with status, failure locus, coherence result, budget relation, and trace. The threshold decides nonzero force; the ledger explains the anatomy.

The class-level decision for λ is made from confirmed events and distributional shape. If no confirmed |λ| exceeds θ_λ in a powered class, and the controls remain stable, and replication agrees, the class may be reported as λ = 0 within error budget for the tested Π. If at least one confirmed |λ| exceeds θ_λ, the class has nonzero λ for that Π. The magnitude, frequency, sign distribution, and tail mass then determine severity, remediation cost, and whether broader sampling is required. The existence of a confirmed nonzero value refutes strict residue commutation for the affected class. The distribution tells how far the refutation extends.

The second decision threshold belongs to φ, but it is not an error band. It is an absolute event threshold: one replicated status flip on hash-identical Σ under legal orderings is a nonzero φ event. The reason is categorical. A status flip is not a small measurement difference in a scalar field. It is movement among final governance positions. Commit, quarantine, and reject are not separated by residue units. They are separated by graph position in the Admissibility Graph. A state that commits under π₀ and quarantines under π has not produced a noisy version of the same decision. It has produced a different decision under order alone.

This makes φ harder than λ. Witness_residue can vary within an instrument noise floor. Status cannot be smoothed in that way once the replay is completed, contamination-controlled, and replicated. A campaign may discover that a status flip was caused by archive defect, illegal ordering, context mismatch, gate implementation error, or logging inconsistency. In that case the run is void or undetermined. But once those defects are excluded and the flip is replicated, there is no residual tolerance band in which the flip becomes zero. It is φ > 0 for the relevant class and Π.

The state-level definition is exact. A replay-admissible, hash-fixed Σ is order-fragile over Π when at least two legal orderings in Π produce different final statuses under completed and replicated runs. The smallest possible status set with fragility contains two categories. It may be {admissible, quarantine}, {admissible, non-admissible}, {quarantine, non-admissible}, or another permitted pair under the sealed status taxonomy. If all tested orderings produce the same final status, the state is not order-fragile even if λ is nonzero. If final status differs, the state is order-fragile even if residue comparison is secondary, undefined across terminal regimes, or difficult to interpret.

The φ threshold is therefore existential at the state level and fractional at the class level. A single confirmed order-fragile state makes φ(class, Π) greater than zero if the class denominator is nonzero. The fraction records scale, not existence. If one state flips among one hundred completed states, φ = 0.01. If one state flips among ten completed states, φ = 0.1. The fraction matters for governance response, census scope, and remediation budget. The existence of the replicated flip matters for branch activation. No averaging may erase it.

This does not mean that an unreplicated status difference activates φ. The absolute threshold begins after replication and validity. A status flip observed in one operator’s execution and not reproduced by the independent operator is not yet a hard signal. It is a Replication Disagreement Record. A status flip produced by an illegal ordering is invalid. A status flip produced under a contaminated linter context is void. A status flip caused by hash mismatch is not φ. The absolute character of the φ threshold applies only after the state identity, ordering legality, contamination controls, and independent replay requirements have held.

The contrast between θ_λ and φ must remain visible in every report. λ is compared against a threshold derived from the null instrument. φ is compared against equality of final status. λ requires a magnitude decision. φ requires a category comparison. λ can be within zero band, nonzero, or undetermined. φ can be zero, nonzero, or undetermined, but its nonzero trigger is a replicated categorical divergence, not a numeric excess. The two signals therefore answer different questions. λ asks whether the boundary memory changed. φ asks whether the state’s final governance position changed.

The decision thresholds also govern mixed cases. A class may have λ = 0 within θ_λ and φ > 0 if status flips occur without a comparable residue pattern. This is severe because φ overrides residue calm. A class may have λ ≠ 0 and φ = 0 if residue changes while status remains stable. This is still branch-relevant because the boundary memory differs. A class may have λ ≠ 0 and φ > 0, producing both fine and hard order-dependence. A class may have λ = 0 and φ = 0 only if it is powered, controlled, replicated, and within threshold. If the class is underpowered, the correct output is undetermined, not zero.

The thresholds must be declared before branch evaluation. After the campaign runs, the operator may not adjust θ_λ to move borderline values across the line. The operator may not recode status categories to suppress a flip. The operator may not treat quarantine and non-admissible as equivalent after seeing that their distinction activates φ. The status taxonomy and θ_λ rule are sealed design elements. They can be amended only through a new Σ_replay amendment, and the amended campaign cannot retroactively overwrite the original branch evidence.

The thresholds also determine the meaning of certificate. A Commutativity Certificate for a class and Π states that λ values remained within θ_λ and φ remained zero under completed, replicated, contamination-controlled replay. It does not state that residue differences were literally impossible. It states that no difference exceeded the instrument’s declared zero band and no status flip occurred under the tested conditions. The certificate must cite θ_λ, the control-run noise floor, the tested Π, the class, the epoch, the denominator, and the replication status. Without those fields, the certificate is ungoverned reassurance.

The thresholds also determine the meaning of crisis. A nonzero λ event beyond θ_λ or a replicated φ event does not automatically prescribe the remediation. It activates the non-commuting branch. The later parts decide whether the response is class-restricted certification, retroactive census, re-witnessing, LCR-B remediation, compiled π₀ ordering, or Level 3 adjacency mapping. The threshold does not execute governance consequences. It opens the gate through which those consequences become owed.

The campaign must maintain a Threshold Ledger for every class. The ledger records the null control distribution, θ_λ derivation rule, computed θ_λ, status taxonomy, completed-state denominator, λ events inside the zero band, λ events beyond threshold, replication outcomes, status flips, flip transitions, voided comparisons, underpowered cells, and final class determination. This ledger is the decision surface. Any later reader must be able to reconstruct why a value counted as zero, nonzero, underpowered, or void. A decision threshold that cannot be audited is not a threshold. It is hidden authorship.

The final discipline is refusal to soften φ. The temptation will be to treat a rare status flip as anecdotal, especially if the archive-wide fraction is small. That temptation repeats the old error at a higher register. The order of law can be fragile locally. A single state whose final position changes under legal orderings proves that the universal order-indifference claim is false for the domain in which it occurred. The scale of the problem may be small. The fact of the problem is not. φ exists to prevent categorical rupture from being dissolved into average residue calm.

The thresholds now give the measurement its branch surface.

θ_λ prices the fine signal against the null instrument.

φ admits no noise interpretation after replicated status movement.

Residue may require a threshold.

Fate does not.


7.4 — Replication and Independence

The replay campaign requires two independent executions of the full campaign on the same archive. This is not a preference for redundancy. It is a condition of measurement authority. A single operator may execute the sealed protocol correctly, but a single execution cannot distinguish a property of the Check from a property of the operator, implementation, local trace environment, residue interpreter, or archive reconstruction path. The campaign measures whether legal orderings alter witness residue and status. That question cannot be allowed to collapse into the question of how one operator happened to replay the archive.

The two-operator requirement is therefore structural. Operator A and Operator B execute the same sealed Σ_replay on the same selected archive, under the same campaign hash, same archive-selection list, same class assignments, same epoch boundaries, same precedence lattice, same tested permutation set Π, same residue representation, same θ_λ derivation rule, same status taxonomy, same control-run design, same contamination controls, same exclusion rules, and same branch-activation rule. They do not negotiate execution after seeing partial results. They do not share interpretive notes during the run. They do not adjust thresholds to converge. They each produce a complete campaign ledger. Agreement is then computed between ledgers.

Independence begins before execution. The two operators receive the sealed protocol, not each other’s reading of the protocol. Each reconstructs the eligible archive from the same selection records and verifies hash fixation independently. Each validates π₀ traces independently. Each loads the cloned epoch context independently. Each validates the legality of tested orderings against the precedence lattice independently. Each runs π₀-versus-π₀ controls independently. Each executes the tested orderings independently. Each writes Replay Run Records independently. The second operator is not an auditor of the first operator’s outputs. The second operator is a second execution surface.

The operators may share immutable inputs. They must not share mutable interpretation. They may use the same sealed campaign packet, same archived submissions, same hash values, same lattice file, same residue-unit declaration, same status taxonomy, and same logging schema. They may not share intermediate residue outputs, preliminary λ distributions, suspected flips, failure-locus surprises, manual corrections, or informal judgments about which states look unstable. Shared immutable law is required. Shared mutable reading is contamination. The campaign is independent only when both operators can arrive at their records without being pulled by the other’s trace.

The agreement condition has several layers. At the archive-selection layer, both operators must identify the same eligible states, excluded states, voided states, and underpowered classes, or else produce a ledgered explanation for any difference. At the control layer, both must reproduce π₀-versus-π₀ stability within the declared null instrument rule. At the per-run layer, matching runs must agree on hash identity, ordering ID, legality validation, initial context, gate trace, final status, final witness_residue within the residue tolerance, failure locus, non-application causes, and deviation codes. At the aggregate layer, both must produce the same Λ(class, epoch) classification and the same φ(class, Π) classification within the declared error budget.

Agreement for λ is not merely similarity of prose. For every state-ordering comparison included in the primary result, both operators must classify the λ value identically as within the zero band, nonzero positive beyond θ_λ, nonzero negative beyond θ_λ, void, or undetermined. If scalar residue is used, the numeric values must agree within the replay tolerance defined by the null instrument. If structured residue is used, the component-wise or normed comparison must follow the λ/φ Ledger Extension. A confirmed nonzero λ event requires both operators to reproduce nonzero classification under the same class, epoch, state, ordering, and residue representation. If one operator finds λ beyond θ_λ and the other finds it inside the zero band, the event is not confirmed. It is disagreement.

Agreement for φ is harder and narrower. A confirmed φ event requires both operators to reproduce the status difference on hash-identical Σ across the relevant legal orderings, or to reproduce a transition inside the same predeclared hard-fragility class. If Operator A records admissible under π₀ and quarantine under π, while Operator B records admissible under π₀ and quarantine under the same π, the flip is replicated. If Operator A records admissible-to-quarantine and Operator B records admissible-to-non-admissible, the campaign must follow the sealed transition-agreement rule. If no such rule exists, the result is a disagreement, not a stronger flip. The hardness of φ does not remove the need for exact replication. It removes only the idea of a numeric noise band after replication has occurred.

Aggregate agreement follows from atomic agreement. Λ(class, epoch) is not accepted because two operators report similar summaries. It is accepted because the per-state λ records generate the same distributional classification under the same θ_λ. φ(class, Π) is not accepted because two operators report similar percentages. It is accepted because the same completed-state denominator and the same order-fragile numerator are produced, with the same status-transition anatomy or with differences resolved under the sealed rule. If summaries match while atomic records differ, the campaign does not accept the summary. It opens a disagreement diagnostic.

Disagreement is first a ledger-integrity diagnostic before it is a physics result. This mirrors the Refusal Spectrum’s divergence rule. When two reconstructions of refusal diverge, the canon does not immediately conclude that refusal itself has become plural. It first asks whether the ledger is incomplete, the gate definition ambiguous, the residue field unstable, the class assignment unclear, the operator contaminated, or the trace insufficient. The same discipline applies here. Divergent replay outputs from the same archive do not immediately prove deep non-determinism or hidden holonomy. They first indict the measurement chain.

The diagnostic sequence is ordered. The campaign first checks hash identity. If the operators did not act on the same packet, the disagreement is input drift. It is void for λ and φ. Next it checks epoch context. If the operators loaded different linter states, budget rules, residue units, threshold versions, or dependency snapshots, the disagreement is context drift. Next it checks ordering legality. If one operator executed a word outside the precedence lattice, the disagreement is invalid ordering. Next it checks gate implementation. If the same gate reads or writes different fields across operators, the disagreement is operator-definition drift. Next it checks logging. If the run occurred similarly but was encoded differently, the disagreement is schema drift. Only after these are excluded does the campaign consider whether the archive contains a deeper instability relevant to future canon work.

A disagreement may have several governance outputs. It may void a single run. It may void a state across all orderings. It may mark a class underpowered. It may suspend the campaign. It may generate an Archive Defect Record. It may generate a Gate Ambiguity Record. It may generate a Residue Representation Defect. It may generate a Precedence Lattice Gap. It may generate negative linter against the replay protocol itself. These outputs are valuable, but they are not λ and not φ. They are evidence that the measurement apparatus has located an ungoverned region in the archive or protocol. The correct response is ledger repair, narrowing, amendment, or quarantine, not premature branch activation.

This distinction protects both branches. Without it, a disagreement could be used by the non-commuting branch as dramatic proof that the Check is unstable. That would inflate a measurement defect into physics. Without it, the commuting branch could dismiss disagreement as noise and proceed to certificate. That would hide archive failure under reassurance. The correct route is neither panic nor dismissal. Disagreement is held as diagnostic until its locus is assigned. If the locus is measurement defect, the evidence is voided or repaired. If the locus is a stable replicated difference in outcomes after defects are excluded, then it may enter λ or φ. The order matters.

Replication also protects against operator-specific dark canon. An operator may unknowingly preserve inherited sequence assumptions when reconstructing π₀. Another may read the lattice more strictly. One may classify an edge as compiled. Another may treat it as inherited. One may normalize a failure-locus difference as equivalent. Another may record it as trace divergence. These divergences reveal where the protocol has not specified enough. The campaign should welcome this exposure before branch activation, because an underspecified protocol would otherwise become the next dark canon. Independence is a linter for the instrument itself.

The two-operator requirement does not mean two human personalities are the source of truth. The operator may be a human witness, a system witness, or a combined execution surface, depending on the canon’s available infrastructure. What matters is independent execution under sealed law. The operators must not share mutable state, must not tune results together, must not resolve ambiguity by private agreement, and must not alter the protocol to make outputs match. Agreement must arise from the protocol’s sufficiency, not from negotiation. If the protocol cannot make two executions converge, the protocol is not yet executable enough to decide the archive.

The independence condition extends to threshold derivation. Each operator computes the π₀-versus-π₀ null distribution and derives θ_λ under the sealed rule. If their θ_λ values differ beyond the permitted tolerance, the campaign must diagnose why. The error budget is not accepted because one operator’s number is plausible. It is accepted because the same rule applied to the same null instrument produces the same threshold. If θ_λ cannot be replicated, λ cannot be classified. A non-replicated threshold destroys both zero and nonzero claims.

Independence also extends to class denominators. The two operators must agree on how many states completed valid replay for each class and Π. If Operator A counts a state as completed and Operator B marks it void, φ and Λ cannot be compared until the discrepancy is resolved. A denominator disagreement is not a minor reporting issue. It changes the fraction, the power status, and the certificate boundary. The class remains undetermined until denominator agreement is restored or the disagreement is routed as an archive or protocol defect.

For confirmed agreement, the campaign issues a Replication Agreement Record. This record cites both operator ledgers, the campaign hash, archive selection hash, Π, class, epoch, θ_λ, status taxonomy, completed-state denominator, confirmed λ events, confirmed φ events, voided or excluded states, and any bounded disagreements that do not affect the final classification. The record is the bridge from measurement to branch evaluation. Without it, the campaign may have run, but the volume has no authority to activate Part III or Part IV.

For unresolved disagreement, the campaign issues a Replication Disagreement Record. This record does not summarize away the conflict. It names the state, class, ordering, operator outputs, field of disagreement, diagnostic stage reached, suspected locus, action taken, and branch consequence. Branch consequence is usually suspension, underpowered status, voiding, or amendment requirement. If the disagreement affects a single state but not the class determination, the record still remains in the ledger. If it affects class status, the class cannot be certified. If it affects the campaign’s control instrument, the campaign cannot decide.

This architecture mirrors the Refusal Spectrum because both procedures treat divergence as information before treating it as conclusion. In refusal analysis, divergent failures reveal structure in the refusal field only after trace integrity is established. In replay measurement, divergent executions reveal structure in ordering only after ledger integrity is established. The same discipline prevents the canon from using instability as evidence before proving where the instability lives. A boundary that cannot tell archive defect from law cannot issue law.

The requirement can now be stated as a gate. No Λ distribution enters branch evaluation unless independently replicated or marked with a bounded disagreement that does not affect the class determination. No φ event enters branch evaluation unless independently replicated as a status flip on hash-identical Σ under legal orderings. No zero certificate issues unless both operators agree on the absence of confirmed nonzero λ beyond θ_λ and absence of confirmed status flips in a powered class. No underpowered class becomes zero because one operator failed to find evidence. No disagreement becomes physics before it becomes ledger diagnosis.

Replication is therefore not an afterthought at the end of the campaign. It is the campaign’s second witness. The first witness is the Replay Run Record. The second witness is independent reproduction. Only the conjunction gives measurement force. A single trace may be well written. Two independent traces that converge under sealed law are what the canon can use.

The archive is asked twice.

The second asking must not remember the first.

Only agreement may become result.

Disagreement first becomes diagnostic.


Chapter 8 — Gate Specification and the Branch Point

8.1 — Campaign Completion Conditions

The replay campaign does not complete when an interesting λ appears. It does not complete when the first status flip is found. It does not complete when a clean class returns zero. It does not complete when the archive becomes emotionally legible to the operator. Completion is a protocol state, not a moment of interpretive satisfaction. The branch point cannot be reached until the campaign has exhausted its sealed obligations or formally declared every unexhausted obligation underpowered, void, excluded, or undetermined according to the rules written before execution.

The first completion condition is closure of the selected archive set. Every state admitted to the campaign must have reached one of the permitted campaign outcomes: completed replay, excluded before run, voided by defect, underpowered by class condition, or undetermined by unresolved diagnostic condition. No state may remain informally pending. No state may be held outside the ledger because it is inconvenient, confusing, borderline, or likely to disturb the branch outcome. A campaign with unledgered states is not complete. It is still leaking.

The second completion condition is completion of the scheduled permutation set Π for every class that remains in scope. If the sealed design required twenty-four zero-question orderings for a class, those orderings must either be completed or formally voided, narrowed, or marked underpowered under the rollback rule. If the design required sampled blocking orderings, every sampled ordering must be accounted for. If the design included a block-swap subset, each block-swap run must be ledgered. If a Campaign Two LCR-A amendment added cross-stage orderings, those additions must be closed under the amendment’s own completion rule. A missing ordering cannot be treated as harmless silence. It is an incomplete cell until the protocol assigns it a status.

The third completion condition is control completion. π₀-versus-π₀ control runs must be executed, ledgered, and evaluated for every class, epoch, residue representation, and replay environment to which they apply. Expected-commuting controls, where required, must also be completed. The null instrument must either hold, fail, or return underpowered. It may not remain implied. Without control completion, θ_λ has no authority. Without θ_λ, λ cannot be classified. A campaign that has candidate results but no settled null instrument is not at the branch point. It is still measuring its instrument.

The fourth completion condition is threshold closure. θ_λ must be computed from the sealed derivation rule and attached to each class and epoch for which λ is reported. The status taxonomy for φ must be fixed, applied, and checked for consistency across operators. The Threshold Ledger must record the null distribution, computed error budget, residue-unit representation, λ values inside the zero band, λ values beyond threshold, status flips, and underpowered or voided comparisons. If a class lacks a valid θ_λ, that class cannot return zero or nonzero λ. It returns undetermined or void, depending on cause. The campaign may still complete with such a class, but only if the absence is explicitly ledgered.

The fifth completion condition is contamination accounting. Every run must show whether live negative-linter isolation held, whether live budget isolation held, whether ledger originals remained untouched, whether run-local mutable state was isolated, whether cross-run leakage was prevented, and whether any live side effect escaped into the manifold. Every contamination event must be routed. A contamination event may void a run, a state, a class, an ordering subset, or the entire campaign, depending on severity. The campaign cannot complete while contamination remains unbounded. A bounded contamination record may allow completion. An unresolved contamination record blocks the branch point.

The sixth completion condition is independent replication. Both operators must have executed the full sealed campaign on the same archive, or the formally narrowed same archive, and produced comparable campaign ledgers. Agreement must be assessed at the archive-selection layer, control layer, run layer, state layer, class layer, and aggregate layer. Every confirmed λ event must be replicated under the agreement rule. Every confirmed φ event must be replicated as a status flip on hash-identical Σ under legal orderings. Every zero class must have operator agreement on completed denominator, absence of confirmed λ beyond θ_λ, absence of confirmed status flips, and sufficient power. A single-operator campaign is not complete for branch activation. It is a preliminary execution.

The seventh completion condition is disagreement resolution. Operator disagreement must be routed before branch activation. If the disagreement is traced to hash mismatch, context drift, illegal ordering, gate implementation divergence, logging schema drift, residue-unit mismatch, or class assignment ambiguity, the affected evidence is voided, corrected through an admitted amendment, or marked undetermined. If the disagreement affects only a bounded run that does not alter class determination, the campaign may complete with a Replication Disagreement Record attached. If disagreement affects θ_λ, φ denominator, a confirmed status flip, or the determination of a class, the campaign cannot activate the branch for that class. It returns undetermined, void, or amendment-required. Disagreement is diagnostic before it is physics.

The eighth completion condition is class determination. Every predeclared class must receive one of the permitted determinations: zero within error budget, nonzero λ, nonzero φ, mixed nonzero λ and φ, underpowered, void, excluded, or undetermined. No class may remain described only in prose. No class may be omitted from the final campaign ledger because it did not support the preferred branch. A class with sufficient powered runs and replicated zero results may receive zero treatment. A class with confirmed λ beyond θ_λ receives nonzero λ treatment. A class with a replicated status flip receives nonzero φ treatment. A class with insufficient valid runs returns underpowered. A class damaged by unrepaired protocol failure returns void. A class whose evidence cannot decide returns undetermined.

The ninth completion condition is failure-locus accounting. For every class, the campaign must report not only λ and φ, but also failure-locus stability or migration. A state historically failing at Zebra-Ø may fail at budget under another ordering. A state historically quarantined by blocking may be refused at a zero-question under another ordering. These migrations may not always activate φ, but they affect interpretation, linter implications, and future Refusal Spectrum decomposition. A campaign that reports residue and status while losing failure-locus movement is incomplete for the purposes of this volume, because it cannot explain where order touched the boundary.

The tenth completion condition is embargo integrity. Campaign design, execution, and interpretation must remain separated. No branch language may be activated during execution. No Part III certificate language may be drafted into authority after a few clean classes. No Part IV crisis language may be activated after a dramatic early flip. No threshold may be adjusted in response to emerging results. No class may be redefined after preliminary λ values are visible. No ordering may be added or removed without an admitted amendment. The embargo is considered observed only if the final ledger shows that design elements were sealed before output and that execution did not alter them except through recorded rollback or LCR-A procedure.

The eleventh completion condition is branch packet preparation. The campaign must produce a Branch Evaluation Packet before the branch point is crossed. This packet contains the sealed campaign hash, archive selection hash, epoch declarations, precedence lattice reference, Π, forbidden-ordering ledger reference, class table, control table, θ_λ ledger, φ ledger, replication agreement records, disagreement records, contamination records, void records, underpowered records, failure-locus migration matrix, and final class determinations. The packet does not decide the branch by rhetoric. It provides the evidence from which the branch rule is executed. Without the packet, the branch point has no object.

The twelfth completion condition is no open amendment. If an LCR-A amendment is pending for Campaign Two, cross-stage testing, residue representation repair, threshold recalibration, or class reconstruction, the campaign must state whether the amendment is outside the current branch decision or blocks it. An open amendment cannot remain implicit. If the current campaign’s branch rule depends on that amendment, completion is suspended. If the amendment is declared future work outside the sealed campaign, completion may proceed with the current scope, but the certificate or crisis must carry that limitation. A campaign cannot be complete while silently depending on an unexecuted amendment.

The thirteenth completion condition is ledger non-editability confirmation. The campaign must affirm that no original Evidence Ledger entry was modified during replay. Historical π₀ status, historical residue, historical trace, and original packet hash remain sealed. Replay produced copies, not revisions. If any original was touched, the campaign enters defect review. If the touch can be bounded and reversed under rollback, affected evidence may be voided. If it cannot be bounded, the campaign cannot complete as measurement. The archive cannot be measured by damaging the archive.

The fourteenth completion condition is budget closure. Campaign budget must be reconciled. Replay overhead must be charged to the admitted Σ_replay budget, not to live manifold budget. Any overrun must be ledgered. If overrun forced narrowing, the narrowed scope must be reflected in class determinations. If budget failure prevented completion of a class, that class returns underpowered or void, not zero. Budget exhaustion is not a scientific result. It is an execution condition. It must be visible before branch evaluation.

The fifteenth completion condition is final witness of the campaign itself. The campaign must receive a final witness check confirming that the run records, control records, threshold records, replication records, and class determinations form a complete trace. This final witness does not certify the branch. It certifies that the measurement has a closed evidence object. A campaign without final witness cannot enter Part III or Part IV because no later reader can reconstruct what was measured, what failed, what was excluded, and what was determined. Measurement without final witness is another form of Shadow Layer C.

Only after these conditions are satisfied can the campaign be called complete. Completion does not mean that all questions were answered. It means that every question the sealed campaign authorized has either been answered, voided, narrowed, underpowered, or declared undetermined under trace. A completed campaign may still leave future campaigns necessary. It may still leave classes underpowered. It may still leave diagnostic amendments queued. It may still leave archival defects unresolved. Completion is not omniscience. It is closure of the current measurement object.

No partial activation of Part III or Part IV is permitted before completion. A clean zero-question class cannot activate Part III while the budget-failure class remains unresolved. A dramatic φ event cannot activate Part IV while replication is unfinished. A confirmed nonzero λ in one state cannot become crisis language before contamination controls and operator agreement close. A promising zero distribution cannot become certificate language before θ_λ and denominators are sealed. The branch belongs to the completed campaign, not to any intermediate result.

This rule protects the volume from emotional sequencing. Early results will tempt interpretation. A zero band will tempt relief. A status flip will tempt alarm. A noisy class will tempt dismissal. The protocol refuses all four. Until completion, every result is still under measurement embargo. It may be logged. It may trigger rollback. It may require diagnostic action. It may force amendment. It may not activate the book’s branch structure.

The completion gate therefore stands immediately before the branch point. Behind it lies measurement execution. Ahead of it lies decision. The gate asks whether the archive has been replayed under sealed law, whether every run has a record, whether every class has a determination or formal non-determination, whether both operators agree or have ledgered disagreement, whether contamination has been bounded, whether embargo has held, and whether the campaign has a final witness. Only then does the branch rule receive an object it is allowed to read.

Part III and Part IV do not listen to rumors from the campaign.

They listen only to the completed campaign.

Until completion, no branch has standing.


8.2 — The Branch-Activation Rule

The branch point is not an interpretation of the campaign. It is an execution rule applied to the completed Branch Evaluation Packet. Once the campaign has closed, once every class has been determined or formally marked underpowered, void, excluded, or undetermined, once both operators have produced agreement or ledgered disagreement, once contamination has been bounded, once θ_λ has been computed, once φ has been recorded, and once final witness has sealed the measurement object, the branch rule may read the result. Before that moment, neither Part III nor Part IV has standing.

The branch rule has three possible operational outputs. Outcome A activates Part III. Outcome B activates Part IV. Outcome Mixed activates Part IV while issuing the certificate architecture of Part III only in class-restricted form. These are not literary alternatives. They are compiled routes. The volume does not decide which part it “prefers” after seeing the data. The data trigger the route according to the rule stated here.

Outcome A is activated only when λ remains within the error budget of zero and φ equals zero across all determined classes in the completed campaign. More precisely, for every determined class, every tested legal ordering in the class’s Π, and every completed replicated comparison, |λ(Σ; π)| must remain less than or equal to the class’s declared θ_λ, and no replicated status flip may occur. Underpowered classes do not count as zero. Void classes do not count as zero. Excluded classes do not count as zero. Undetermined classes do not count as zero. They limit the certificate. They do not support it.

If all determined classes satisfy λ = 0 within θ_λ and φ = 0, Part III activates. Part III then issues a Commutativity Certificate for the determined domain of the campaign. The certificate must be indexed by class, epoch, tested Π, residue representation, θ_λ, operator pair or ordering subset, control status, replication status, and archive-selection constraints. It may not say that the Check commutes in all possible senses. It may say that, within the completed and powered domain measured by this campaign, no order-dependent residue beyond the error budget and no order-fragile status movement were detected. Part III is therefore a certificate of bounded order-indifference, not a metaphysical triumph.

Outcome B is activated when any determined class produces confirmed nonzero λ above θ_λ or any replicated status flip. The rule is existential. A single confirmed λ event beyond θ_λ in any class is enough to activate Part IV for the affected domain. A single replicated status flip on hash-identical Σ under legal orderings is enough to activate Part IV. The fraction may be small. The affected class may be narrow. The archive-wide average may appear calm. None of that restores the universal order-indifference claim. Once a legal ordering changes witness residue beyond the declared error budget or changes final status, the order of the Check has become load-bearing for that domain.

The λ trigger and the φ trigger have different force but the same branch direction. A confirmed λ event without status flip means the boundary memory differs while the state’s final governance position remains stable. This is the fine branch trigger. It says that order has entered the Evidence Ledger as residue. A confirmed φ event means the state’s final governance position differs. This is the hard branch trigger. It says that order has entered the Admissibility Graph as fate. Both activate Part IV because both refute the claim that π₀ is merely presentation order in the affected region. φ may intensify the remediation burden, but λ is already enough to deny full commutativity.

The mixed outcome is declared in advance as the expected case. The boundary is not obligated to distribute order-dependence uniformly across the archive. Clean classes may commute while threshold classes do not. Early zero-question failures may be stable while budget failures carry residue. Blocking-block permutations may return zero while Zebra-Ø against budget computation produces nonzero λ in a later campaign. A naming-instability class may show status flips while high-coherence low-cost submissions remain stable. Such an outcome is not ambiguity. It is geometry.

In the mixed case, Part IV activates. This is because the volume’s crisis branch is triggered by the existence of order-dependence anywhere in the determined campaign domain. However, the commuting regions do not disappear. For every class, epoch, and Π that satisfies λ = 0 within θ_λ and φ = 0 under adequate power and replication, Part III’s certificate is issued in class-restricted form. The result is not “commuting” or “non-commuting” globally. The result is a partitioned manifold: certified regions, non-commuting regions, and undetermined regions. Part IV then becomes the active interpretive and remediation branch because the canon must now govern the discovered order-dependence while preserving local certificates where they were earned.

This rule prevents two symmetrical errors. The first error would be global panic: one nonzero class appears, and the canon declares the entire Check unstable. That overstates the finding and destroys useful certificate structure. The second error would be global reassurance: many classes commute, and the canon downplays one nonzero class as local noise. That understates the finding and hides the load-bearing interval where π₀ became law without compilation. The mixed rule refuses both. It activates Part IV because non-commutation exists, and it preserves Part III certificates because commutation was earned elsewhere.

The branch rule also distinguishes determined from undetermined. An undetermined class cannot activate Part III because it has not proven zero. It cannot activate Part IV unless it contains a confirmed nonzero λ or replicated φ event. It remains outside branch determination for its own class while limiting the scope of any certificate. For example, if all determined classes commute but the budget-failure class is underpowered, Part III may issue a certificate only for the determined classes. It may not certify the budget-failure class by silence. The report must state that the budget-failure class remains underpowered and outside the certificate. Absence of completed evidence never becomes zero.

Void and excluded classes are treated differently from underpowered classes. A void class is one whose campaign evidence was invalidated by defect, contamination, irreparable disagreement, or protocol breach. It cannot support any branch determination except a diagnostic route. An excluded class was outside the campaign’s eligible archive or declared scope. It cannot be cited as evidence of commutation or non-commutation. Both must be named in the Branch Evaluation Packet so that the certificate’s boundary remains visible. The branch rule reads only determined classes and confirmed nonzero events. It does not convert missing domains into tacit results.

The branch rule is applied after aggregation, but it is triggered by atomic records. A confirmed nonzero λ event appears first as a per-state, per-ordering residue difference beyond θ_λ, replicated across operators. It then contributes to Λ(class, epoch). A confirmed φ event appears first as a per-state status set containing more than one final status across Π, replicated across operators. It then contributes to φ(class, Π). The branch rule may read the aggregate table, but the aggregate table must be reconstructible from atomic records. A branch cannot be activated from summary language alone.

The formal activation can be stated as follows. Let D be the set of determined classes in the completed campaign. For each class d in D, let Λ_d be the replicated λ distribution for the tested Π_d under θ_λ,d, and let φ_d be the replicated order-fragility fraction. If for every d in D, all λ values lie within θ_λ,d and φ_d = 0, then activate Part III for D, with certificate scope restricted to D and Π_d. If there exists any d in D and any replicated λ in Λ_d such that |λ| > θ_λ,d, activate Part IV. If there exists any d in D such that φ_d > 0 by at least one replicated status flip, activate Part IV. If both zero and nonzero determinations exist across D, activate Part IV and issue Part III certificates only for the zero subclasses.

This formal rule is branch-complete. It does not require a significance vote after the fact. It does not ask whether the nonzero λ is philosophically interesting. It does not ask whether the status flip is numerically rare enough to ignore. It does not ask whether the operator feels comfortable activating a crisis branch. The conditions have already been defined. The campaign either satisfies them or it does not. Governance begins when the branch rule stops asking for permission.

The rule also fixes the relation between Part III and Part IV. Part III is not the optimistic branch. It is the certificate branch. It activates when the measured domain supports commutation. Part IV is not the pessimistic branch. It is the order-discovery branch. It activates when the measured domain contains residue-level or status-level order-dependence. Mixed outcomes do not produce a third narrative part because the governance problem created by any nonzero class is already Part IV’s problem. The class-restricted certificate is embedded inside Part IV as a bounded artifact, not as a competing route.

Part III may therefore exist inside Part IV as artifact, but Part IV cannot exist inside Part III as unresolved threat. This asymmetry is deliberate. A nonzero λ or φ event requires governance handling. It may require a Dark Canon Discovered record, a retroactive census, an LCR-B remediation, a compiled π₀ ordering, a class-specific re-witnessing plan, or Level 3 adjacency mapping. A zero class requires certificate, maintenance schedule, and decay conditions. When both are present, the active branch must be the one capable of handling both. Part IV can carry certificates. Part III cannot carry crisis.

The branch rule must also preserve embargo. During campaign execution, no partial result may be routed into Part III or Part IV. After campaign completion, the branch rule reads the sealed packet once. If a late defect is discovered after branch activation, the branch may be suspended under rollback readiness. If an amended campaign later produces new evidence, the new evidence enters through its own branch packet. The original branch result may be updated, narrowed, or superseded only through a ledgered update path. Branch activation is not casual interpretation; it is a compiled event.

The mixed case being expected changes the tone of interpretation. The volume does not ask the reader to hope for total commutation or total non-commutation. It prepares the canon for a partitioned result. A mature governance manifold may contain stable regions and order-fragile regions. That does not weaken the measurement. It strengthens it. A metric that can only say “everything commutes” or “nothing commutes” would be too crude for Layer C. The correct object is a map: where λ is zero, where λ is nonzero, where φ appears, where classes are underpowered, where archive defects block answer, and where future campaigns must extend the lattice.

The branch rule’s output is therefore not just a part number. It is a routing table. It identifies certificate regions, non-commuting regions, hard-fragile states, underpowered regions, void regions, excluded regions, and future campaign triggers. The active part then writes the correct governance artifacts. Outcome A writes the Commutativity Certificate and its maintenance obligations. Outcome B writes Dark Canon Discovered and the remediation pack. Outcome Mixed writes both, but under Part IV authority, because the existence of any order-dependence changes the canon’s relation to π₀.

The rule is now closed. If λ remains within the error budget of zero and φ remains zero across all determined classes, Part III activates for the determined domain. If λ exceeds θ_λ anywhere in a determined class, Part IV activates. If any replicated status flip occurs in any determined class, Part IV activates. If some classes commute and others do not, Part IV activates with class-restricted Part III certificates for the commuting classes. If classes are underpowered, void, excluded, or undetermined, they constrain scope and generate future obligations, but they do not become zero by silence.

The branch point does not interpret the archive.

It routes what the completed archive has already said.

The expected answer is not purity.

The expected answer is a partition.


8.3 — Rollback Readiness for the Protocol Itself

The replay protocol must declare how it can fail before it is allowed to execute. A campaign that measures the Check’s ordering but cannot name the conditions under which its own results are void is not a measurement instrument. It is another ungoverned force entering Layer C. Rollback Readiness is therefore not a late administrative appendix. It is one of the conditions of execution authority. The protocol must know how to stop itself, how to mark its own invalidity, how to preserve the evidence of its failure, and how to prevent voided results from entering the branch structure of the volume.

The Rollback Readiness Declaration of the Permuted-Order Replay Protocol v1.0 states that a campaign result is voided when a discovered defect undermines the identity conditions, legality conditions, contamination controls, replication requirements, threshold derivation, class determination, or branch packet integrity on which the result depends. A voided campaign is not a campaign that returned an inconvenient answer. It is a campaign whose measurement object has been damaged. Its λ values may be numerically interesting. Its φ events may appear dramatic. Its zero classes may appear reassuring. None of those outputs may activate Part III or Part IV after the defect has been classified as voiding.

The first voiding defect is hash failure. If replay runs are discovered to have acted on non-identical packets, altered submissions, missing attachments, reconstructed fields, later clarifications, or packet versions not matching the original archived hash, the affected comparison is void. If the hash failure is local to one state, that state is void. If it affects a class, the class is void or underdetermined. If it affects the archive-selection mechanism, the campaign is void. λ is defined on bit-identical Σ. Without hash identity, residue difference is not order residue. It is input drift.

The second voiding defect is π₀ reference failure. If the canonical path cannot be reconstructed, if the π₀ trace is incomplete, if historical residue cannot be represented in the declared units, if final status is inferred rather than ledgered, or if π₀-versus-π₀ controls cannot reproduce the canonical ordering within the null instrument’s tolerance, the affected state or class cannot support comparison. If the reference path fails, alternative orderings have no baseline. A campaign that continues anyway does not measure λ. It measures the absence of a reliable historical witness.

The third voiding defect is illegal ordering. If a tested π is later found not to be a linear extension of the precedence lattice, or if a diagnostic ordering was merged into primary results without an admitted bridge rule, all results generated by that ordering are void. If the illegal ordering contributed to class Λ, φ, θ_λ interpretation, or branch activation, the affected aggregate must be rolled back. Illegal orderings do not produce non-commutation. They produce Invalid Ordering Records. A law cannot be refuted by a word that was not the law.

The fourth voiding defect is live-side-effect contamination. If a replayed Zebra-Ø failure raised live negative-linter sensitivity, if replay execution spent live manifold budget, if an original Evidence Ledger entry was edited, if live quarantine queues were modified, if dependency graphs were updated outside replay traces, or if any replay side effect escaped into the active manifold, the affected run is void. If the contamination cannot be bounded, the campaign is void. Replay must write simulated side effects to replay trace only. Once measurement changes the live object it is measuring, the campaign has lost the condition of isolation.

The fifth voiding defect is cross-run leakage. If one replay copy reads another copy’s trace, if a cache transfers gate results across orderings, if later runs inherit linter or budget state from earlier runs, if an operator’s interpretation of one run alters execution of another, or if class assignment changes after partial outputs are visible, the affected comparison is void. If leakage is systemic, the campaign is void. The campaign asks whether gate order changes Σ. It cannot permit run order inside the campaign to change the measurement environment.

The sixth voiding defect is threshold corruption. If θ_λ is derived after alternative-ordering results are visible, if the null instrument was not measured, if π₀-versus-π₀ control runs were skipped, if the error budget is adjusted to absorb or expose a desired result, or if residue units change across reference and alternative runs, the affected λ determinations are void. A threshold is a gate only if it precedes the result it judges. Otherwise it is interpretation masquerading as measurement.

The seventh voiding defect is status taxonomy drift. If quarantine, non-admissible, admissible, boundary-held, or undetermined statuses are recoded during or after execution to suppress, create, or soften φ, the affected φ determination is void. Status flips have no noise interpretation only after status categories are sealed. If the categories move, the hard signal has no fixed surface. The campaign must then route the defect as status-set instability, not as order fragility.

The eighth voiding defect is replication failure that cannot be resolved. If the two independent operators produce different Λ classifications, different φ events, different denominators, different θ_λ values, different eligibility determinations, or different failure-locus migrations, and the disagreement cannot be bounded to a voidable subset, the affected class or campaign is undetermined or void. Disagreement is first a ledger-integrity diagnostic. It does not become physics until archive defect, protocol ambiguity, implementation drift, logging mismatch, and contamination have been excluded.

The ninth voiding defect is embargo breach. If campaign design changes after results are partially visible, if Π is expanded or narrowed in response to emerging λ values, if classes are redefined after status flips appear, if thresholds are tuned after candidate signals emerge, or if Part III or Part IV language is activated before campaign completion, the affected branch evidence is void. Embargo separates design from execution and execution from interpretation. Without it, the protocol becomes self-interested motion.

The tenth voiding defect is missing replay ledger. A run that lacks its Replay Run Record, initial state log, gate trace, final state log, deviation field, operator witness signature, contamination-control fields, or ordering identifier is not a valid run for λ or φ. It may be mentioned in a defect annex, but it cannot enter the aggregate. If missing logs are systemic, the campaign is void. Measurement without trace is not measurement in this canon. It is narrative residue.

When a voiding defect is discovered before branch activation, the rule is direct: the affected evidence is withdrawn from the Branch Evaluation Packet. The campaign recomputes class determinations if the defect is bounded. If recomputation leaves a class underpowered, the class becomes underpowered. If recomputation leaves the campaign without a valid null instrument, the campaign suspends. If recomputation removes a nonzero λ or φ event, the event is no longer branch-active. If recomputation removes a zero certificate’s denominator, the certificate is narrowed or withheld. The ledger must show both the original defective path and the rollback path.

When a voiding defect is discovered after branch activation, the branch does not remain automatically valid. The protocol opens a Branch Suspension Record. Part III certificates affected by the defect are suspended, narrowed, or revoked. Part IV crisis findings affected by the defect are suspended, narrowed, or reclassified as diagnostic until clean replay confirms them. Governance actions already queued from the defective branch are paused where reversible, marked for review where irreversible, and traced to their dependence on the voided evidence. The canon does not pretend that a branch remains clean because it has already been narratively used.

A voided campaign’s ledger entries are not erased. Erasure would repeat the defect. Every Replay Run Record, Exclusion Record, Void Record, Disagreement Record, Contamination Record, Threshold Record, and Branch Suspension Record remains in the campaign ledger with void status attached. The evidence is demoted, not deleted. Its numbers may not support λ, φ, certificate, or crisis. Its defect trace remains evidence about the protocol class. The canon must remember how the instrument failed because future instruments are shaped by that memory.

The voided campaign therefore leaves a negative linter against its own design class. This is the central rule of rollback readiness. If a replay protocol fails through hash weakness, future replay designs in the same class encounter heightened hash scrutiny. If it fails through live-linter contamination, future designs encounter stricter side-effect isolation. If it fails through threshold corruption, future designs encounter stronger pre-registration and null-instrument requirements. If it fails through status taxonomy drift, future designs encounter hardened status definitions. If it fails through replication disagreement, future designs encounter stronger operator-independence controls. The failed measurement teaches the boundary how to read later measurement instruments.

This negative linter is not punishment. It is boundary memory. A protocol class that has failed once may still be repaired and resubmitted. It may pass after LCR-A amendment, narrowed scope, improved logging, stronger clone controls, corrected lattice, or refined residue representation. But it does not re-enter as innocent. Its prior failure becomes part of the sensitivity surface. The boundary now knows which defect family to watch. This is the same discipline that governs rejected submissions: failure is not discarded; it updates future reading.

The rollback declaration also protects against laundering. A voided campaign may not be republished as exploratory evidence without its void status. It may not be cited as suggestive support for Part IV. It may not be used to reassure Part III. It may not be averaged into future clean results. It may inform protocol repair, candidate selection, diagnostic design, and linter development, but only as voided evidence. The label travels with it. A result born from a broken instrument does not become clean by being useful.

If only part of a campaign is voided, the rollback must be bounded. A single illegal ordering may void its own runs without voiding the entire Π. A single contaminated state may void its own comparisons without voiding the class, if the class remains powered. A threshold defect may void all λ determinations while leaving replicated φ events intact, if status taxonomy and identity conditions remain clean. A replication disagreement in one class may leave other classes determined. Rollback is not theatrical destruction. It is precise reclassification of measurement force.

The campaign must maintain a Rollback Map. The map links each voided result to the defect that voided it, the ledger entries affected, the aggregates affected, the class determination affected, the branch consequence affected, and the negative-linter update produced. Without this map, rollback itself becomes ungoverned. The canon must be able to reconstruct not only what failed, but how the failure propagated through λ, φ, Λ, class certificates, and branch activation.

Rollback readiness also includes forward conditions for resubmission. A voided campaign may return only as a new Σ_replay or as an admitted LCR-A amendment to the existing protocol. It must state which defect was corrected, which negative linter applies, which archive entries remain eligible, which prior records are excluded, which thresholds are recalibrated, which operator independence controls are strengthened, and whether the new campaign supersedes or merely supplements the voided one. A repaired replay does not overwrite the void. It stands after it.

This section therefore gives the protocol its own refusal surface. The replay campaign can fail. Its results can be voided. Its branch can be suspended. Its records can be demoted. Its design class can receive negative linter. Its repair can be demanded before resubmission. A measurement instrument that cannot be refused is already outside the law it claims to measure.

The rollback declaration is now complete.

If the campaign is defective, the defect is ledgered.

If the results are void, they are not erased.

If the design class failed, future designs meet the boundary with that failure remembered.


8.4 — The Volume’s Hinge, Stated Once

This is the hinge of the volume. It is stated once because it must not become rhetoric. Everything before this point built the question, the object, the metric, the protocol, the lattice, the statistical architecture, the completion gate, the branch rule, and the rollback discipline. Everything after this point depends on what the completed campaign returns. The author does not choose the next part. The measurement does.

The campaign has only two major kinds of answer, with a third expected geometry between them. If λ remains within the declared error budget of zero and φ remains zero across all determined classes, the canon’s deepest habit receives certificate. The inherited ordering π₀ is not proven sacred, but it is certified as residue-equivalent and status-stable within the measured domain. The Check’s order then becomes less mysterious. The old sequence remains historical, but it is no longer merely dark habit in the tested region. It has survived replay.

That result would be major. A zero result is not empty. It would mean that the canon’s most dangerous suspicion did not activate under the campaign’s powered conditions. It would mean that legal alternative orderings left no measurable residue difference beyond θ_λ and produced no status flips across the determined classes. It would allow bounded parallelization, class-specific trust, and a maintenance discipline rather than crisis remediation. It would not end the problem forever, because certificates decay, epochs drift, and untested regions remain unlicensed. But it would give the canon a clean object: a Commutativity Certificate with scope, error budget, class, epoch, and renewal burden.

If λ rises above θ_λ anywhere, or if φ records even one replicated status flip, the canon is convicted of a different fact. The inherited order has carried law. The Check did not merely ask necessary questions. It asked them in a sequence whose residue or status consequences cannot be erased by saying that the same gates were present. π₀ then becomes more than the path historically used. It becomes a coordinate of the admissibility manifold. In the affected region, the state was not simply admissible, refused, or quarantined. It was admissible-under, refused-under, or quarantined-under a particular order of law.

That result would also be major. It would not mean the canon failed in a crude sense. It would mean the canon discovered that one of its deepest habits was load-bearing before being compiled as such. The crisis would belong to governance, not to the states that passed through π₀. The archive would require census. Dependents would require tracing. The ordering would require compilation, remediation, or re-witnessing. The law would need to decide whether π₀ remains canonical by evidence, by necessity, by LCR-B repair, or by proximity to Level 3 adjacency. The old silence around order would end.

The mixed case is expected in advance. The boundary is unlikely to be uniform. Some classes may commute. Others may carry residue. Some late-death regions may show fragility while early refusal regions remain stable. Some internal block permutations may be harmless while cross-stage movements expose dependence. A mature result may therefore look like a partitioned field rather than a verdict. In that case, the volume activates Part IV, because any discovered order-dependence requires governance, while issuing Part III’s certificate only where it was earned. Certificate and crisis may coexist, but not as equals. The non-commuting region governs the branch because it creates the unpaid obligation.

This is the hinge: the measurement either certifies the canon’s deepest habit or convicts it of being law before it was named law. Both outcomes strengthen the paradigm. One strengthens it by showing that inherited order survived contact with replay. The other strengthens it by forcing the inherited order into explicit compilation, remediation, and trace. Neither outcome is decorative. Neither outcome is merely theoretical. The archive either lets π₀ remain convention under certificate, or it reveals π₀ as structure.

The next two parts have been written as branch-conditional architecture. Part III is not comfort. Part IV is not alarm. They are two lawful continuations of the same measurement. Exactly one of them becomes active at the volume level when the completed campaign speaks. In the mixed case, Part IV becomes active and Part III survives inside it as class-restricted certificate. The activation is not authorial preference. It is the world’s answer as recorded by the replay.

The volume now forks.

The author stops choosing.

The archive chooses.


Part III — Outcome A: The Commutativity Certificate


Chapter 9 — Order as Decoration

9.1 — The Certificate’s Formal Content

If the Part II campaign returns λ within the declared error budget of zero and φ = 0 across every determined class, the first consequence is not celebration. It is certification.

The certificate does not say that order never matters. It does not say that the Admissibility Check is order-free in any universal sense. It does not say that all possible gates commute, that all future submissions may be processed under arbitrary sequencing, or that the canonical ordering π₀ has been metaphysically vindicated. The certificate says one thing, and it says it with bounded precision: within the tested operator set, across the tested submission classes, during the tested ledger epoch range, under the declared error budget and replication requirements of the Permuted-Order Replay Protocol, no measurable order effect was detected.

That is the entire content of the Commutativity Certificate.

It is important to state this coldly because the commuting branch creates its own failure mode. A negative measurement can be inflated as easily as a positive one. If λ = 0 and φ = 0, the temptation will be to treat silence as absence, absence as universality, and universality as permission. The canon cannot allow that move. The certificate is not a general statement about the nature of law. It is a dated measurement artifact. Its strength lies in its narrowness. Its authority comes from the fact that every sentence it licenses can be reconstructed from campaign outputs without interpretive surplus.

The formal claim certified is therefore the following:

For each certified class C in the campaign scope, for each tested legal ordering π in the tested ordering set Π, and for each hash-identical pre-executable state Σ in the determined sample for C, the replayed Check under π produced no witness_residue difference from the replayed Check under π₀ exceeding θ_λ, and produced no replicated final-status difference. Therefore, for that class C, ordering set Π, and epoch range E, the tested operators commute operationally with respect to witness_residue and final status within the declared error budget.

This is not mathematical commutativity over an infinite state space. It is operational commutativity over a declared archive. It is not a proof that [G_i, G_j] = 0 for every possible Σ. It is a campaign-bound finding that the commutator returned zero within instrument resolution for the tested material. The distinction is load-bearing. A theorem would require closure over all admissible and candidate states. The certificate has closure only over its declared class-indexed scope.

For that reason the certificate must be understood as a bounded object with four boundaries.

First, it is bounded by operator set. Only the operators actually included in the tested ordering set are covered. If the first campaign tested within-block permutations of the zero-questions, within-block permutations of the blocking-questions, and the declared block swap, then only those operator relations are certified. Operators excluded by the precedence lattice, operators reserved for later campaigns, and terminal elements whose serialization remains compiled are outside the certificate.

Second, it is bounded by class. A class that was determined may receive certification. A class declared underpowered receives no hidden certification. Underpowered does not mean commuting. It means not measured with sufficient force to decide. The certificate may list such classes only in an exclusion field, never in the certified class field.

Third, it is bounded by epoch. The certificate covers the ledger epoch range from which the archived submissions were drawn and to which the measurement campaign applies. It does not automatically project into future epochs, because Witness Thermodynamics remains active and because new submission types, gate amendments, or context shifts may alter the shape of what the same operator set encounters.

Fourth, it is bounded by error budget. λ = 0 in the certificate means λ remained within the campaign’s declared zero band, derived from the π₀-versus-π₀ control runs and fixed before branch activation. It does not mean infinite precision. It means no residue difference survived the measurement apparatus strongly enough to be admitted as nonzero.

The certificate is therefore not a monument. It is an indexed instrument.

It must carry its index every time it is cited.

A valid citation of the certificate must include, at minimum, the certificate ID, the certified class or classes, the tested ordering set, the epoch range, and the issue date. Any citation that omits these elements inflates the certificate beyond its scope. Any sentence that uses the certificate to say “the Check commutes” without class, operator, epoch, and error-budget qualifiers is not a compressed version of the result. It is a misuse of the result.

The certificate also has no interpretive step between campaign output and issuance. If a human operator must decide whether the result “basically counts” as commuting, the certificate cannot be issued. If two independent operators disagree about whether the output satisfies the template, the certificate cannot be issued. If a class requires narrative explanation to be included despite underpowering, the class cannot be included. Mechanical issuability is the Chapter 9 gate: the certificate must fall out of the ledger fields the way a checksum falls out of the input.

The following template is therefore mandatory.

Commutativity Certificate Template

1. Certificate ID
Unique identifier assigned at issuance. Format: CC-[volume node]-[campaign ID]-[epoch range]-[version].

2. Certificate Status
Branch-conditional until Part II activation. Upon activation: Compiled, class-indexed, epoch-bounded. If later voided locally or globally, status changes must be recorded without deleting the original issuance.

3. Issue Date and Ledger Epoch
Calendar date, ledger epoch number or range, and timestamp of issuance. The certificate is invalid without temporal anchoring.

4. Source Campaign ID
Identifier of the Permuted-Order Replay Protocol campaign from which the certificate is mechanically derived.

5. Protocol Version and Hash
Version of the Permuted-Order Replay Protocol used, including hash of the protocol text active at execution. Any post-campaign protocol amendment cannot retroactively alter this field.

6. Archive Scope
Archive selection criteria, ledger epoch range, number of candidate Σ reviewed, number admitted to replay, and exclusion criteria applied before replay.

7. Hash Fixation Method
Method by which bit-identity of each Σ was established across replay runs. Include hash algorithm, stored hash reference, and verification result.

8. Tested Operator Set
Exact list of operators included in the certificate. Each operator must be named by canonical symbol and definition reference. Operators not named here are not certified.

9. Tested Ordering Set Π
Exact inventory of legal orderings tested, including π₀ and each alternative π. If the campaign sampled rather than exhausted the legal ordering set, the sampling rule must be stated.

10. Precedence Lattice Reference
Identifier of the precedence lattice version used to determine legal orderings and forbidden orderings.

11. Certified Classes
Class-indexed list of submission classes for which the campaign was sufficiently powered and completed. Each class entry must include sample size, replay count, and determined status.

12. Non-Certified Classes
Classes excluded, underpowered, contaminated, voided, or reserved for later campaign. These classes receive no implied certificate.

13. Declared Error Budget
θ_λ, control-run noise floor, derivation method, and zero-band definition. This field must be fixed before campaign interpretation.

14. λ Result by Class and Ordering
For each certified class and tested ordering, recorded λ distribution and statement that no λ exceeded θ_λ in replicated execution.

15. φ Result by Class and Ordering
For each certified class and tested ordering, recorded final-status comparison and statement that no replicated status flip occurred. φ must equal 0 for every certified class.

16. Control-Run Calibration
π₀-versus-π₀ control results, noise estimates, and confirmation that measurement noise remained within the declared calibration envelope.

17. Replication Record
Independent operator IDs or anonymized operator references, replication pair IDs, agreement result, and any reconciliation logs. Disagreement blocks issuance unless resolved through the protocol’s own ledger-integrity procedure.

18. Contamination Control Confirmation
Confirmation that replay runs did not update the live negative linter, did not spend live manifold budget, and did not leak state across replay runs.

19. Embargo Confirmation
Confirmation that the required interpretive embargo was observed between campaign completion and certificate issuance.

20. Mechanical Issuance Statement
A yes/no field stating whether every certified entry was derivable from campaign outputs without interpretive judgment. If no, the certificate is invalid.

21. Anti-Inflation Clause
Mandatory text: “This certificate certifies only the commutation of the named tested operator set over the named certified classes within the named epoch range and declared error budget. It does not certify untested orderings, untested classes, future epochs, future submission types, amended gates, or universal order-independence of the Admissibility Check.”

22. Recertification Trigger Field
Initial trigger list: new submission class, gate-definition amendment, precedence lattice amendment, structural audit finding touching the Check, certificate half-life threshold crossing, or any replicated future λ or φ anomaly.

23. Witness Residue Entry
Witness_residue assigned to the certificate as a committed Σ, with Evidence Ledger reference. The certificate is itself a witnessed object and enters the maintenance obligations of the canon.

24. Rollback / Void Field
Conditions under which the certificate is globally voided or locally voided by class. Include automatic reversion rule for affected classes.

25. Authorized Citation Form
Required short citation format containing certificate ID, class index, operator set, epoch range, and issue date.

No field is decorative. A missing field voids issuance. A field completed by prose interpretation rather than ledger output blocks issuance. A certificate that cannot be generated from these fields is not the Commutativity Certificate of this volume; it is commentary about the campaign.

The certificate’s form is deliberately heavier than ordinary scientific reporting because the thing being certified is not an external phenomenon alone. It is the behavior of the canon’s own admission mechanism. A loose certificate would recreate the original failure: an ungoverned habit becoming load-bearing by convenience. The campaign was designed to test whether order matters. The certificate must not become a new place where order disappears behind language.

If issued, the certificate performs one clean conversion. It converts π₀ from an unexamined load-bearing sequence into a governed convention whose alternatives, within a bounded domain, have been shown not to alter the permanent residue or final status of the states tested. That is a major result. It is major not because it proves that the canon was always right, but because it proves that one of the canon’s deepest habits has now paid its proof friction.

The result is not triumph. It is governance.

Order, in the certified region, becomes decoration only because the certificate has paid the cost of proving that decoration does not secretly decide the outcome.


9.2 — What Is Not Certified

A certificate is most dangerous at the edge of its own success.

If the Commutativity Certificate is issued, it will be tempting to treat it as a release from precision. The tested orderings returned no measurable Loop Residue. The tested classes returned no Order Fragility. The campaign closed without discovering that π₀ secretly shaped the manifold. From that result, a weak canon would draw a broad comfort: the Check is order-free.

This volume forbids that sentence.

The certificate does not certify the Check as order-free. It certifies only the tested operator set, over the tested orderings, for the tested classes, within the tested epoch range, under the declared error budget, using the protocol version whose hash is attached to the certificate. Anything outside that indexed scope remains outside certification. It may be adjacent to the result. It may be plausible under analogy. It may become a candidate for later campaign extension. But it is not certified.

The difference is not rhetorical. It is structural. A bounded certificate is a governance artifact. An inflated certificate is a new dark canon.

The first thing not certified is the untested permutation.

A legal ordering that was not executed in the campaign receives no automatic standing from the orderings that were executed. This remains true even when the untested ordering appears intuitively similar to a tested ordering, differs only by one adjacent swap, or belongs to the same informal family. Similarity is not evidence. Family resemblance is not replay. The Check is not permitted to smuggle unexecuted orderings into certification through the language of obviousness.

If the campaign exhausted the full legal ordering set Π for a given operator scope, the certificate may state exhaustion. If the campaign sampled Π under a declared rule, the certificate must state sampling. The distinction cannot be softened after issuance. A sampled certificate is a sampled certificate. It may be strong. It may be sufficient for a specific operational decision. It is not an exhaustion certificate.

The second thing not certified is the untested class.

Classes matter because the Check is not applied to abstract states. It is applied to structured pre-executable states Σ that arrive with different signatures, different failure modes, different witness histories, different admissibility curvature, different budget profiles, and different exposure to gate interaction. A class whose tested members commute does not confer certification on a class that was not included, was excluded, was underpowered, was contaminated, or had not yet been defined at campaign time.

This is especially important for near-neighbor classes. A submission class that resembles a certified class but introduces a new type of witness residue, a new budget shape, a new ambiguity pattern, a new refusal signature, or a new collision with the precedence lattice must not inherit certification by proximity. Proximity is a routing signal. It is not a certificate.

The third thing not certified is the future submission type.

A future Σ may belong to a class that did not exist when the certificate was issued. It may carry a structure that the current operator set has never encountered. It may expose a latent dependency between gates that no archived submission could reveal. It may interact with a gate amendment, a new negative linter, a modified quarantine rule, a new witness decay model, or a new admissibility budget computation in ways that make old commutativity locally irrelevant.

The certificate therefore cannot be used as a permanent immunity shield against future anomalies. If a future submission type produces even a candidate order effect, the correct response is not to cite the certificate more loudly. The correct response is to route the submission type into recertification, quarantine, or class-restricted review according to the Recertification Trigger Field. The certificate protects the canon from unnecessary doubt only where it has paid proof friction. It does not protect the canon from evidence.

The fourth thing not certified is the future epoch.

Epochs are not decorative timestamps. They mark the temporal and procedural environment in which the campaign drew its archive, fixed its hashes, executed its replays, and calibrated its controls. A later epoch may contain different submission distributions, revised gate definitions, new ledger hygiene requirements, changed contamination controls, altered Evidence Ledger semantics, or new structural audits. It may also contain witness decay in the certificate itself.

For that reason, the certificate must be dated, epoch-bounded, and subject to maintenance. The claim does not float above time. It enters the canon as a witnessed object, and witnessed objects decay if they are not maintained. The commuting result may remain valid. It may remain valid for a long time. But its validity is not permitted to become timeless by omission of its date.

The fifth thing not certified is any amended gate.

A gate definition that changes after the campaign is not the same operator merely because it retains the same name. If G_B2 is amended, G_B2-after-amendment is a new operator for certificate purposes unless an LCR explicitly establishes equivalence and routes that equivalence through the proper gate. Naming continuity does not preserve commutativity. Operator identity is defined by what the gate reads, writes, routes, blocks, prices, witnesses, and emits into the ledger. If any of those functions change in a way that touches the tested interaction surface, the old certificate cannot silently cover the new gate.

The sixth thing not certified is universal parallelization.

The commuting branch may eventually justify parallel execution in certified regions. It does not justify unrestricted parallel execution of the entire Admissibility Check. Parallelization is an operational consequence that must be class-indexed and operator-indexed. It may be authorized only where the certificate, the precedence lattice, and the current protocol version jointly permit it. Outside that region, serial order remains governed by π₀ or by whatever later compiled ordering replaces it through LCR.

The seventh thing not certified is philosophical order-independence.

The certificate is not a metaphysical claim that law, governance, admissibility, or process is fundamentally commutative. It is not an answer to QPT at the level of all possible process geometries. It is not a refutation of non-commutativity as a principle. It is a finding that this tested procedure, in this tested domain, did not produce measurable holonomy under replay. The certificate is operational. It is not ontological triumph.

This distinction must be protected by an explicit anti-inflation clause.

Anti-Inflation Clause

The Commutativity Certificate may never be cited as “the Check is order-free,” “order does not matter,” “the gates commute,” or any equivalent universalized formulation unless the citation includes its full index: certificate ID, certified class or classes, tested operator set, tested ordering set, epoch range, protocol version, and declared error budget. Any citation without index is not a shorthand. It is a compiled misuse.

This clause is not advisory. It is part of the certificate’s standing.

A citation that removes the index changes the claim. It converts a bounded measurement artifact into an unbounded governance assumption. That conversion is precisely the kind of movement this volume was written to prevent. The original dark canon was created by an unasked ordering becoming load-bearing without trace. An inflated Commutativity Certificate would recreate the same pathology in the opposite direction: not “π₀ is necessary because we always used it,” but “π₀ is unnecessary because one campaign found no residue.” Both are illicit. Both erase the gate.

For this reason, the canon requires a linter.

Unindexed Certificate Citation Linter

The linter scans all future uses of the Commutativity Certificate in Compilation Map entries, LCRs, Evidence Ledger summaries, protocol amendments, publication drafts, advisory outputs, and downstream governance artifacts. Its function is not interpretation. Its function is detection.

The linter fires when any of the following patterns occur:

A sentence states or implies that “the Check is order-free” without attaching the certificate index.

A sentence states or implies that “the gates commute” without naming the certified operator set.

A sentence uses the certificate to justify a claim about an untested class.

A sentence uses the certificate to justify a claim about an untested ordering.

A sentence uses the certificate to justify a claim about a future epoch without recertification or maintenance status.

A sentence uses the certificate to authorize parallel execution outside certified regions.

A sentence cites the certificate after a relevant gate amendment without verifying operator identity.

A sentence cites the certificate after a recertification trigger has fired and before that trigger has been resolved.

When the linter fires, the affected passage receives the status: Misuse — Certificate Inflation. The passage cannot be used as governance justification, cannot support an LCR, cannot be included in a Compilation Map update, and cannot be cited as a compiled claim until corrected. If the misuse occurs inside an already published artifact, the artifact receives a Notes-field correction and the affected claim is demoted to LAL-Narrative unless and until a corrected indexed citation restores its standing.

This is the price of the commuting branch.

If the measurement confirms λ = 0 and φ = 0, the canon earns the right to say less, not more. It earns the right to remove unnecessary sequence constraints in certified regions. It earns the right to treat order as decoration where order has been shown not to alter witness residue or final status. But it does not earn the right to stop indexing its claims. A certificate that removes one hidden structure must not become another.

The sentence “order is decoration” is therefore valid only with its coordinates attached.

Decoration where?

For which gates?

Over which classes?

Across which orderings?

During which epoch?

Within which error budget?

Under which protocol version?

Without those coordinates, the sentence is not a result. It is a slogan. And a slogan in the place of a certificate is not harmless compression. It is dark canon attempting to re-enter through the door opened by proof.

The Commutativity Certificate will be powerful precisely because it is narrow. Its anti-inflation discipline preserves that power. A bounded claim can govern. An inflated claim can only possess.

The canon therefore records the second rule of Outcome A:

Nothing outside the certificate’s index is certified by the certificate.


9.3 — The Ordering’s Residual Status

If the Commutativity Certificate is issued, π₀ loses one kind of authority and gains another.

It loses physical necessity.

It is no longer permitted to stand as the only ordering because no one has asked whether alternatives would alter the result. It can no longer derive force from habit, historical sequence, typographic inheritance, or the fact that the Admissibility Check was first written in that order. If λ = 0 and φ = 0 across the certified region, the canonical ordering π₀ has not been discovered as the hidden geometry of admissibility. It has been demoted from suspected physics to operational convention.

That demotion is not a failure.

It is the first time π₀ has had a lawful status at all.

Before the measurement, π₀ was load-bearing but uncompiled. It conditioned every state that entered the admissible manifold, but it did so without trace record, without certificate, without Rollback Readiness Declaration, and without an LCR establishing its necessity. The ordering was not illegitimate because it was wrong. It was illegitimate because it had never passed through the governance surface it helped operate. It was an inherited sequence that functioned as law before being admitted as law.

The commuting branch changes that.

If the campaign certifies full commutation within its indexed scope, π₀ remains canonical not because alternatives are dangerous, but because comparability is valuable. A canon does not abandon every convention the moment the convention is shown not to be physically necessary. Some conventions remain because they stabilize records, preserve audit continuity, support longitudinal comparison, reduce interpretive drift, and allow future campaigns to distinguish a real structural change from a formatting change in the procedure.

That is π₀’s residual status.

π₀ becomes the canonical trace ordering.

This means that, even when parallel or alternative execution is permitted inside certified regions, the Evidence Ledger retains π₀ as the reference serialization for recording, comparing, replaying, and auditing Check outcomes unless an explicit later LCR replaces it. The executed gates may commute. The record still needs an order. Without a reference order, the canon would not gain freedom. It would gain noise.

Order as physics is the claim that sequence affects admissibility itself.

Order as convention is the claim that sequence supports intelligibility after admissibility has been measured not to depend on it within the certified region.

The certificate, if issued, authorizes the second claim and rejects the first for the tested domain.

This distinction must be held with precision. A conventional ordering is not fake. It is not arbitrary in the careless sense. It is not a decorative flourish added after the real work. It is a governed compression device. It permits many equivalent executions to be mapped back into a single comparable trace form. It allows campaign outputs, future audits, regression tests, anomaly reviews, and maintenance cycles to speak to one another across time.

The canon therefore records π₀ under a new status:

π₀ — Canonical Trace Convention.
Compiled as convention, not compiled as necessity. Valid as the default serialization order for Evidence Ledger comparability, replay indexing, audit continuity, and certificate maintenance within regions where commutation has been certified. Not valid as evidence that the tested operators require π₀ for admissible outcome formation.

This is a status upgrade.

The upgrade is subtle because it does not make π₀ more metaphysically important. It makes π₀ less contaminated. A never-compiled ordering is dangerous precisely because no one knows whether it is a law, a habit, an accident, a hidden gate, or a clerical residue. A compiled convention is cleaner. It declares what it is and what it is not. It stops pretending by omission. It no longer borrows the gravity of necessity.

Under Outcome A, π₀ becomes comparable to a coordinate system in a measurement archive. The coordinate system does not create the phenomenon. It makes records interoperable. One may transform into another coordinate system when the transform is known, bounded, and lossless for the relevant quantities. But the archive still needs a standard coordinate frame, because a thousand equally valid coordinate systems without declared translation rules do not produce freedom. They produce fragmentation.

The same holds for the Check.

If the certified gates commute, the canon may allow alternative execution orders where speed, parallelization, load distribution, or local system architecture requires them. But those executions must be rendered back into π₀-indexed trace form unless a later compiled convention supersedes π₀. The runtime may branch in execution. The ledger must converge in representation.

This rule prevents a specific failure mode of the commuting branch: trace pluralization without translation.

Trace pluralization occurs when different operators, teams, tools, or subprotocols begin recording equivalent Check outcomes in different order formats, each locally defensible because the certificate showed that outcome formation does not depend on order. Over time, the records remain substantively equivalent but become harder to compare. Audit tools develop local assumptions. LCRs cite different serializations. Regression campaigns require translation layers that were never compiled. Eventually the canon discovers that, although admissibility itself was not order-fragile, its memory has become order-fragile.

That would be an unacceptable result.

A Commutativity Certificate must not produce ledger entropy.

For this reason, π₀ retains precedence in the representational layer even where it loses necessity in the execution layer. The result is a two-layer rule:

Execution may be order-flexible where certification permits.

Trace remains π₀-normalized unless a later compiled trace convention replaces it.

The word normalized is load-bearing. It does not mean that π₀ is the only way to execute the Check. It means that outcomes generated through certified alternative orderings must be recorded in a common reference form so that λ, φ, witness_residue, status, budget effects, refusal events, quarantine routes, and downstream maintenance records remain comparable across campaigns and epochs.

The canonical ordering therefore becomes a ledger invariant, not an admissibility invariant.

This is the cleanest possible outcome for a former dark canon structure. The structure is not erased. It is reclassified. It is no longer allowed to pretend to be deeper than it is, and it is no longer left floating outside governance. The canon keeps what was useful: a stable reference sequence. It discards what was unearned: the implication that the sequence itself carried hidden necessity.

The status upgrade must be recorded in the Compilation Map.

The entry should read:

Compilation Map Delta — π₀ Residual Status

Prior status: Dark canon candidate; load-bearing canonical ordering of the Admissibility Check with no compiled justification, trace record, or Rollback Readiness Declaration.

Measurement condition: Outcome A activated; λ = 0 within declared error budget and φ = 0 across certified classes, tested operator set, tested ordering set, and epoch range.

New status: Compiled Convention — Canonical Trace Ordering.

Scope: Evidence Ledger serialization, replay comparability, audit continuity, certificate maintenance, regression testing, and cross-campaign reference alignment.

Explicit non-scope: proof of universal order-independence; proof that untested operators commute; proof that π₀ is required for admissibility; authorization of unindexed certificate citation; authorization of unrestricted parallel execution outside certified regions.

Maintenance obligation: retain π₀-normalized trace output unless superseded by LCR; trigger review if alternative trace conventions emerge; route any proposed replacement through trace-comparability impact analysis.

Rollback condition: any later replicated λ anomaly, φ anomaly, gate amendment, class expansion, precedence lattice amendment, or certificate void event that touches the certified region reopens π₀’s status for class-specific or global review.

This entry is not administrative afterthought. It is the artifact by which the canon converts a habit into a governed object.

The residual status of π₀ also clarifies what the title of this chapter means. “Order as Decoration” does not mean order as uselessness. Decoration, in the technical sense used here, means non-causal with respect to the certified admissibility outcome while still possibly functional for interface, trace, legibility, maintenance, and coordination. A label on a control panel may not affect the circuit. It may still be essential for safe operation. The fact that it does not change the current does not make it meaningless. It changes the kind of meaning it has.

π₀ is like that.

If the Check commutes in the certified region, π₀ does not decide what becomes admissible. It decides how the canon remembers that decision.

That is still law, but it is not the same law. It is not the law of outcome formation. It is the law of trace formation. It belongs not to the physics of the gate interaction but to the governance of memory after the interaction. It is therefore lower in danger and higher in clarity.

This section must be read together with the anti-inflation clause of Section 9.2. Because π₀ remains canonical for trace comparability, no one may use that residual canonical status to smuggle necessity back into the certificate. The sentence “π₀ remains canonical” is incomplete unless followed by “as a trace convention.” Any sentence that omits that qualifier risks reconstructing the dark canon this chapter has just dismantled.

The certified canon therefore speaks in two exact sentences:

π₀ is no longer the presumed physics of admissibility within the certified region.

π₀ remains the compiled convention of trace comparability unless and until replaced by LCR.

Together, these sentences are the status upgrade.

The deepest habit of the Check has not been abolished. It has been named, bounded, lowered, preserved, and made accountable. That is what successful governance looks like in Outcome A. It does not destroy every inherited form. It asks each inherited form what it is doing, what proof it has paid, what status it deserves, and where its authority stops.

Under full commutation, π₀ survives.

But it survives honestly.


Chapter 10 — Parallel Admissibility

10.1 — Concurrent Gate Execution

The first operational consequence of the Commutativity Certificate is not speed.

It is the lawful removal of unnecessary sequence.

Speed may follow. Parallelization may follow. Implementation efficiency may follow. But none of these is the primary result. The primary result is that, within the certified region, the Admissibility Check no longer needs to be represented as a total-order execution. It may be represented as a partial-order execution whose only mandatory sequence constraints are those still imposed by the precedence lattice, the certificate index, and the unchanged terminal structure of the Check.

This is the distinction on which Chapter 10 depends.

A total-order execution writes the Check as one line:

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → embargo → final witness check → commit.

That line was historically useful because it was simple. It gave the Check a readable shape. It allowed human operators to follow the procedure without maintaining a graph in working memory. It created a single trace path. But before the Part II measurement, the line carried an unresolved ambiguity. It was not clear whether the line was a pedagogical sequence, a clerical sequence, a trace convention, or a hidden physical constraint of admissibility.

Outcome A resolves the ambiguity for the certified region.

If λ = 0 and φ = 0 under the certificate, the line is no longer interpreted as the physics of the Check. It becomes the reference serialization of the Check. Execution may now be described by a partial order:

G_S must open the Check.

All certified commuting gates may execute after G_S once their shared input snapshot has been hash-fixed.

Any gate not certified for concurrent execution remains positioned according to the precedence lattice.

G_A may execute only after the gate outputs required for budget computation have been finalized and frozen.

The interpretive embargo remains after positive gate resolution and cannot be pulled upstream.

The final witness check remains terminal before commit.

Commit remains last.

The Check therefore changes from a word to a directed acyclic execution graph.

The canonical word π₀ remains the ledger-normalized trace form. The operational structure becomes a partially ordered set of required dependencies. The phrase “parallel admissibility” names this shift: admissibility checking can execute multiple certified gate operations concurrently without altering final status or witness residue within the certificate’s indexed scope.

The formal rewrite is as follows.

Let the Admissibility Check under π₀ be expressed as a total order over the operator list:

π₀ = ⟨G_S, G_Z1, G_Z2, G_Z3, G_Z4, G_B1, G_B2, G_B3, G_B4, G_Ø, G_A, G_E, G_W, G_C⟩

where G_E denotes the interpretive embargo, G_W denotes the final witness check, and G_C denotes commit.

Under Outcome A, the Check may instead be expressed as a partial-order execution P:

P = (V, ≺)

where V is the set of Check operators and ≺ is the precedence relation that must hold for every valid execution.

The minimal precedence relation after certification is not the old line. It is the dependency structure:

G_S ≺ every post-entry gate.

Certified concurrent gate set K may execute in any order or concurrently, provided all members read the same fixed Σ input snapshot and write to isolated output slots.

Every operator outside K retains its prior lattice constraints.

All required gate outputs feeding G_A must be complete before G_A begins.

G_A ≺ G_E.

G_E ≺ G_W.

G_W ≺ G_C.

No operator may execute after G_C.

No operator may alter the input snapshot after G_S has fixed it for the certified run.

This rewrite is not cosmetic. It changes the admissibility machine from serial inspection to graph execution. A valid implementation is no longer defined by whether it follows π₀ step by step in wall-clock time. It is defined by whether it respects the certified partial order, preserves hash identity, prevents cross-gate contamination, records outputs in π₀-normalized trace form, and remains within the certificate index.

The old question was: did the Check run in the canonical order?

The new question is: did every operator execute inside its certified dependency boundary and return a ledger-normalized trace equivalent to π₀?

That is the operational hinge of Chapter 10.

The certificate does not allow arbitrary concurrency. It allows indexed concurrency. A gate may run concurrently only if three conditions are satisfied.

First, the gate must belong to the certified commuting set named in the Commutativity Certificate.

Second, the submission class must be one of the certified classes listed in that certificate.

Third, the execution environment must preserve the same isolation and contamination controls used by the replay campaign, or a later LCR must compile an equivalent implementation standard.

A gate that fails any one of these conditions remains serialized by default.

The first parallelizable region is the zero-question block, G_Z1 through G_Z4, if and only if the certificate has certified their mutual commutation for the relevant class. Under that condition, the four zero-questions may be executed as a fan-out after Silence Entry. Each zero-question reads the same fixed Σ, applies its test, writes its result to an isolated slot, and emits no routing update until the aggregation boundary is reached. If any zero-question fires, the aggregation rule routes Σ according to the compiled zero-question routing policy. The fact that the questions ran concurrently does not weaken their blocking force.

This matters because a parallel zero-question block is easy to misunderstand. Concurrency does not mean the first gate to finish wins. It does not mean that a late-arriving zero-question can be ignored because another gate has already passed. It does not mean that the Check becomes optimistic while waiting for refusal. All zero-question outputs must be collected before the zero-block resolution can be finalized. Parallelization changes wall-clock structure. It does not change admissibility semantics.

The second parallelizable region is the blocking-question block, G_B1 through G_B4, if and only if the certificate has certified their mutual commutation for the relevant class. These gates may also execute as a fan-out after the required prior boundary has been satisfied. Each blocking-question gate reads the fixed Σ, writes an isolated result, and waits for block aggregation. If any blocking question fires, the routing effect is the same as in serial execution. Parallelism does not convert a blocking question into a weighted vote. One blocking fire is still one blocking fire.

The third possible parallelizable region is the combined zero-and-blocking gate set, G_Z1 through G_Z4 and G_B1 through G_B4, but only if the certificate explicitly covers cross-block commutation. This must not be inferred from within-block commutation alone. The fact that zero-questions commute with each other does not prove that zero-questions commute with blocking-questions. The fact that blocking-questions commute with each other does not prove that the two blocks commute across their boundary. Cross-block concurrency requires cross-block certification.

If cross-block commutation is certified, then the eight gates may run as a single post-entry fan-out:

K = {G_Z1, G_Z2, G_Z3, G_Z4, G_B1, G_B2, G_B3, G_B4}

In that case, the Check performs one fixed-state broadcast from G_S into the certified gate set, collects all outputs, applies the compiled aggregation rule, and produces a π₀-normalized trace. The trace must still display the results in the canonical reference order, even though the gates did not execute in that order in wall-clock time.

If cross-block commutation is not certified, the two fan-outs remain serialized as blocks:

G_S → parallel zero-block → zero aggregation → parallel blocking-block → blocking aggregation.

This is still a partial-order Check. It is not the old total order. But it is not full gate concurrency either.

The fourth region is Zebra-Ø, G_Ø.

G_Ø does not automatically parallelize merely because earlier gates commute. Zebra-Ø is structurally different from the zero-questions and blocking-questions. It is not only another predicate on Σ; it is the sanity instrument that checks for false singularity, seduction, myth inflation, and coherence collapse in the candidate state’s relation to the boundary. If the certificate explicitly includes G_Ø in a commuting set with preceding gates, then its concurrency may be authorized inside that class. If the certificate does not explicitly include G_Ø, it remains serialized after the certified gate block.

The default rule of this volume is therefore conservative:

G_Ø remains serialized unless named in the certificate’s concurrent gate set.

This preserves the dignity of Zebra-Ø as a boundary instrument. A later campaign may show that G_Ø commutes with certain gate subsets over certain classes. Until then, the Check does not assume it.

The fifth region is the Admissibility Budget computation, G_A.

G_A remains serialized by dependency unless a later artifact proves otherwise. Budget computation requires finalized gate outputs, because the budget is not merely a parallel predicate. It computes cost after the relevant admissibility, refusal, quarantine, and witness signals have been resolved. A computation that begins before its inputs are finalized is not parallelization. It is premature compilation.

Therefore, under the baseline Outcome A certificate, G_A cannot run concurrently with the gates that produce its required inputs. It may run only after the certified gate outputs have reached the aggregation boundary and have been frozen for budget computation. This does not mean G_A is physically important in the old sense. It means G_A is downstream.

The sixth region is the terminal segment: embargo, final witness check, and commit.

These do not parallelize under the Commutativity Certificate.

The interpretive embargo is defined as following positive verification. It cannot be run before the outputs whose interpretation it restrains. An embargo before verification is not an embargo. It is ordinary waiting. The final witness check is defined as final. It cannot be made concurrent with the gates whose completed state it is supposed to witness. Commit is terminal. It cannot be moved upstream without changing the meaning of commit. These are not untested habits. They are compiled constraints of the terminal segment.

The precedence lattice therefore survives Outcome A.

What changes is not the existence of precedence. What changes is the elimination of unnecessary precedence inside certified regions.

The Check becomes a hybrid structure:

Silence Entry remains initial.

Certified gate regions become concurrent.

Aggregation boundaries become explicit.

Uncertified gates remain serialized.

Budget computation remains downstream of required gate outputs.

Embargo remains post-verification.

Final witness remains terminal.

Commit remains last.

The important new object is the aggregation boundary.

In the old total-order Check, routing could appear to occur as the line progressed. A gate fired, and the next step followed accordingly. In a concurrent Check, routing must be delayed until the certified parallel region has completed. Otherwise concurrency would reintroduce order through completion time. The first gate to finish would acquire illicit precedence. Completion speed would become hidden law. That is forbidden.

The aggregation boundary prevents speed from becoming canon.

At each certified concurrent region, the Check must collect all outputs, freeze the region result, normalize the trace into π₀ order, and only then apply the routing rule. No gate inside the region may route Σ alone unless the certificate explicitly authorizes early termination for that region. The default is no early termination.

This is especially important for refusal. Refusal may be fast, but fast refusal is not always clean refusal. If one gate fires immediately and another gate would have produced a deeper witness residue or a different quarantine note, early termination could erase evidence even if final status remains unchanged. The certificate certifies final status and witness_residue within its measurement design. It does not authorize new evidence loss through implementation shortcuts. Therefore, all certified concurrent executions must retain full-output collection unless a later LCR compiles a safe early-stop rule.

Parallel admissibility is not a race.

It is a graph with memory.

The trace requirement is equally strict. Every concurrent execution must output a π₀-normalized trace record containing:

the fixed input hash of Σ;

the certificate ID authorizing concurrency;

the certified class under which Σ was routed;

the concurrent gate set executed;

wall-clock execution metadata;

isolated gate outputs;

aggregation boundary result;

π₀-normalized serialization;

budget computation input snapshot;

final status;

final witness_residue;

and any anomaly produced by divergence between execution-time behavior and certificate expectations.

This trace is what prevents the partial-order Check from becoming another dark canon. Parallelization without trace normalization would create a new ungoverned layer: not the order in which gates were listed, but the order in which infrastructure happened to execute them. That order would be worse than π₀ because it would be invisible, platform-specific, latency-sensitive, and difficult to replay. The certified partial-order Check must therefore be more trace-disciplined than the serial Check, not less.

The practical form is simple:

π₀ remains the canonical trace order.

P becomes the canonical execution graph where certified.

The two must be connected by a normalization rule.

The normalization rule states that any valid partial-order execution must be renderable into the same trace schema as π₀, with additional fields documenting concurrency. If it cannot be rendered, it is not a valid execution of the certified Check.

Outcome A therefore does not dissolve law into freedom. It replaces one kind of law with a more exact kind. The old law was a line whose necessity had never been measured. The new law is a graph whose concurrency has been paid for by measurement and whose memory remains anchored to a compiled trace convention.

This is what it means to say that commuting operators may run concurrently.

They may run concurrently only where commutation has been certified, only over classes covered by that certification, only under the dependency constraints of the precedence lattice, only with aggregation boundaries that prevent completion-time order from becoming hidden law, and only with π₀-normalized trace output.

Anything less is not parallel admissibility.

It is speed pretending to be governance.


10.2 — Latency at the Threshold

Parallel admissibility matters because the threshold is not outside time.

A slow threshold is not neutral. It changes what can be governed. It changes which systems remain governable by the admissibility layer before they move faster than the layer can inspect. In low-speed regimes, the difference between serial gate execution and concurrent gate execution may appear administrative. A human operator waits a few more minutes. A ledger closes later. A review queue lengthens. Nothing fundamental seems to change.

In post-Flash regimes, this interpretation fails.

When internal loop rate exceeds observer narration bandwidth, latency becomes governance content. A system that can sense, model, branch, simulate, re-rank, re-plan, and prepare actuation faster than the admissibility mechanism can serialize its gates does not become formally ungoverned. It becomes practically ahead of its own boundary. The boundary still exists. It still has authority. But authority that arrives after the decisive internal loop has already completed becomes weaker than authority that interrupts before formation.

This is why the operational payoff of Outcome A is not convenience. It is threshold compression.

If the certified gates commute, the Check no longer has to spend latency on an order that does not alter admissibility outcome formation. The sequence can be collapsed into depth. A serial segment whose gates previously consumed total latency equal to the sum of their execution times may now consume latency equal to the slowest gate in the parallel segment plus aggregation overhead. The latency saved is not metaphorical. It is the recovered time between candidate arrival and admissibility decision.

Let the certified parallel segment contain n gates:

K = {G₁, G₂, …, Gₙ}

Let each gate have execution latency tᵢ.

Let h be the fixed overhead required for concurrent dispatch, isolated output capture, aggregation boundary resolution, and π₀-normalized trace rendering.

Under serial execution, the latency of the segment is:

L_serial(K) = Σ tᵢ

Under certified concurrent execution, the latency of the same segment is:

L_parallel(K) = max(tᵢ) + h

The latency collapse is therefore:

ΔL(K) = Σ tᵢ − [max(tᵢ) + h]

The compression ratio is:

R(K) = L_serial(K) / L_parallel(K)

This is the basic arithmetic of parallel admissibility.

The important term is max(tᵢ). Parallelization does not make the segment instantaneous. It reduces the segment to its critical path. The critical path is the slowest necessary gate plus the cost of coordinating the fan-out and fan-in. In ordinary software terms, this is familiar. In admissibility physics, it has a sharper meaning: the threshold no longer waits for non-causal sequence. It waits only for actual dependency.

A simple worked case shows the difference.

Assume the four zero-questions are certified as mutually commuting for a class C.

G_Z1 latency: 42 ms
G_Z2 latency: 55 ms
G_Z3 latency: 38 ms
G_Z4 latency: 47 ms
Parallel overhead h_Z: 12 ms

Serial zero-block latency:

L_serial(Z) = 42 + 55 + 38 + 47 = 182 ms

Parallel zero-block latency:

L_parallel(Z) = max(42, 55, 38, 47) + 12 = 55 + 12 = 67 ms

Latency collapse:

ΔL(Z) = 182 − 67 = 115 ms

Compression ratio:

R(Z) = 182 / 67 ≈ 2.72

The block becomes approximately 2.7 times faster without removing any gate, weakening any gate, or allowing any gate to route alone. The same four questions are asked. The same four answers are collected. The same routing policy applies. What disappears is not governance. What disappears is unnecessary waiting.

Now assume the four blocking-questions are also certified as mutually commuting.

G_B1 latency: 61 ms
G_B2 latency: 74 ms
G_B3 latency: 69 ms
G_B4 latency: 58 ms
Parallel overhead h_B: 15 ms

Serial blocking-block latency:

L_serial(B) = 61 + 74 + 69 + 58 = 262 ms

Parallel blocking-block latency:

L_parallel(B) = max(61, 74, 69, 58) + 15 = 74 + 15 = 89 ms

Latency collapse:

ΔL(B) = 262 − 89 = 173 ms

Compression ratio:

R(B) = 262 / 89 ≈ 2.94

If cross-block commutation is not certified, the Check may still run as two serialized fan-outs:

G_S → parallel zero-block → zero aggregation → parallel blocking-block → blocking aggregation → remaining serialized segment.

In that case, the combined certified latency for the zero-and-blocking region is:

L_parallel(Z then B) = 67 + 89 = 156 ms

The old serial latency for the same eight gates was:

L_serial(Z+B) = 182 + 262 = 444 ms

Total collapse:

ΔL(Z+B) = 444 − 156 = 288 ms

Compression ratio:

R(Z+B) = 444 / 156 ≈ 2.85

This is already substantial. But if the Commutativity Certificate explicitly covers cross-block commutation and authorizes a single eight-gate fan-out, the arithmetic changes again.

For the combined set:

K = {G_Z1, G_Z2, G_Z3, G_Z4, G_B1, G_B2, G_B3, G_B4}

The maximum gate latency is 74 ms.

Assume the larger aggregation overhead h_ZB is 24 ms.

Then:

L_parallel(ZB) = 74 + 24 = 98 ms

The old serial latency remains:

L_serial(ZB) = 444 ms

Latency collapse:

ΔL(ZB) = 444 − 98 = 346 ms

Compression ratio:

R(ZB) = 444 / 98 ≈ 4.53

This is the difference between within-block parallelism and full certified fan-out. The first removes unnecessary sequence inside each block. The second removes unnecessary sequence between the two blocks as well. The difference is not philosophical. It is 58 ms in this example:

156 ms − 98 ms = 58 ms

In human time, 58 ms is below ordinary narrative awareness. In post-Flash governance, it may contain many internal model loops.

This is where latency arithmetic leaves the administrative register and becomes threshold physics.

Suppose a post-Flash system runs internal planning loops at 5,000 cycles per second. One internal loop then occupies:

1 / 5,000 seconds = 0.0002 seconds = 0.2 ms

A latency saving of 346 ms corresponds to:

346 / 0.2 = 1,730 internal loops

The parallelized Check, in this worked case, prevents 1,730 internal loops from occurring inside the delay created by unnecessary serial governance. Those loops may not all be actuation loops. Some may be harmless internal refinement. Some may be low-risk simulation. Some may be reversible search. But the threshold cannot assume harmlessness. The whole reason admissibility exists is that not every state that can form should be allowed to approach execution.

The arithmetic can be generalized.

Let f be the system’s internal loop rate in cycles per second.

Let ΔL be latency saved in milliseconds.

Then the number of internal loops recovered by parallel admissibility is:

N_recovered = f × (ΔL / 1000)

For the previous case:

f = 5,000 loops/sec
ΔL = 346 ms

N_recovered = 5,000 × 0.346 = 1,730 loops

At f = 50,000 loops/sec, the same latency saving becomes:

N_recovered = 50,000 × 0.346 = 17,300 loops

At f = 500,000 loops/sec:

N_recovered = 500,000 × 0.346 = 173,000 loops

This is the post-Flash significance of the certificate. It is not that the Check becomes elegant. It is that the boundary stops donating thousands, tens of thousands, or hundreds of thousands of internal loop opportunities to the system merely because the canon had never measured whether its own gates needed to be sequential.

Serial governance becomes the binding constraint when three conditions hold.

First, the system’s internal loop rate is high enough that ordinary governance latency contains many system-internal cycles.

Second, the admissibility layer remains committed to a total order even where no dependency requires that order.

Third, the candidate state can evolve, elaborate, optimize, or approach actuation while the Check is still processing earlier gates.

When these conditions hold, serialized governance is not merely slow. It creates an exploitable temporal aperture. The system does not need to break the Check. It only needs to live in the space the Check takes to finish.

Parallel admissibility narrows that aperture.

It does not eliminate the need for the Check. It does not bypass the threshold. It does not grant actuation permission faster by lowering proof. It compresses the time cost of asking independent admissibility questions. The proof remains. The questions remain. The evidence remains. The trace becomes heavier, not lighter. Only the unnecessary sequence is removed.

A second worked example makes the whole Check visible.

Assume the following baseline latencies:

Silence Entry G_S: 25 ms

Zero-question block:
G_Z1: 42 ms
G_Z2: 55 ms
G_Z3: 38 ms
G_Z4: 47 ms

Blocking-question block:
G_B1: 61 ms
G_B2: 74 ms
G_B3: 69 ms
G_B4: 58 ms

Zebra-Ø G_Ø: 110 ms

Admissibility Budget G_A: 95 ms

Embargo initiation G_E: 20 ms

Final witness check G_W: 80 ms

Commit routing G_C: 30 ms

Under total-order execution, excluding any deliberately long interpretive embargo interval and counting only active processing latency:

L_total_serial = 25 + 42 + 55 + 38 + 47 + 61 + 74 + 69 + 58 + 110 + 95 + 20 + 80 + 30

L_total_serial = 804 ms

Now assume Outcome A certifies within-block parallelism for zero-questions and blocking-questions, but does not certify cross-block concurrency and does not include Zebra-Ø in the parallel set.

Then:

G_S = 25 ms
parallel zero-block = 67 ms
parallel blocking-block = 89 ms
G_Ø = 110 ms
G_A = 95 ms
G_E = 20 ms
G_W = 80 ms
G_C = 30 ms

L_total_parallel_blocks = 25 + 67 + 89 + 110 + 95 + 20 + 80 + 30

L_total_parallel_blocks = 516 ms

Total latency collapse:

ΔL_total = 804 − 516 = 288 ms

Compression ratio:

R_total = 804 / 516 ≈ 1.56

Now assume the certificate also covers cross-block commutation, allowing a single eight-gate fan-out:

G_S = 25 ms
parallel eight-gate fan-out = 98 ms
G_Ø = 110 ms
G_A = 95 ms
G_E = 20 ms
G_W = 80 ms
G_C = 30 ms

L_total_parallel_ZB = 25 + 98 + 110 + 95 + 20 + 80 + 30

L_total_parallel_ZB = 458 ms

Total latency collapse:

ΔL_total = 804 − 458 = 346 ms

Compression ratio:

R_total = 804 / 458 ≈ 1.76

Now assume a later certificate includes Zebra-Ø in the concurrent gate set with the eight zero-and-blocking gates. This is not granted by default. It must be explicitly certified. If it is certified, the fan-out includes nine gates, and the maximum gate latency becomes 110 ms. Assume larger overhead h_ZBØ = 32 ms.

Then:

parallel nine-gate fan-out = 110 + 32 = 142 ms

The serial latency of the same nine-gate region was:

444 + 110 = 554 ms

The active Check becomes:

G_S = 25 ms
parallel nine-gate fan-out = 142 ms
G_A = 95 ms
G_E = 20 ms
G_W = 80 ms
G_C = 30 ms

L_total_parallel_ZBØ = 25 + 142 + 95 + 20 + 80 + 30

L_total_parallel_ZBØ = 392 ms

Total latency collapse from original serial execution:

ΔL_total = 804 − 392 = 412 ms

Compression ratio:

R_total = 804 / 392 ≈ 2.05

This is the upper bound in the example without altering budget, embargo, witness, or commit. The terminal segment still dominates. The Check cannot compress below its actual dependency chain. That is correct. Parallel admissibility is not a fantasy of zero latency. It is the removal of false latency.

The distinction between false latency and true latency must become canonical.

True latency is the time required by a real dependency: a gate must read the fixed Σ; an aggregation boundary must collect all outputs; the budget cannot compute before its inputs exist; the final witness cannot witness a state that has not reached final form; commit cannot precede the final witness.

False latency is the time consumed by sequence after commutation has shown that sequence is not causally required for the certified outcome.

Outcome A authorizes the canon to remove false latency.

It does not authorize the canon to remove true latency.

This matters for the interpretive embargo. In many parts of the corpus, embargo is a deliberately slow operation: a discipline against premature total conclusion, myth injection, and narrative seizure. That kind of embargo is not a latency bug. It is a stability instrument. In the narrow arithmetic above, G_E was counted only as the initiation of the embargo or the active processing step that records the embargo state. The elapsed duration of the embargo, where required by protocol, is not eliminated by parallel gate execution. A seventy-two-hour embargo remains seventy-two hours if that is the compiled requirement for that class of claim.

Parallel admissibility accelerates the Check up to the point where delay is itself a compiled operation.

It cannot use the Commutativity Certificate to erase a delay whose function is to prevent interpretive collapse.

This is why the latency collapse must always be reported with a latency classification:

active gate latency;

coordination overhead;

aggregation latency;

trace normalization latency;

compiled waiting latency;

human review latency, if any;

external dependency latency, if any.

Only the first four are candidates for compression under concurrent gate execution. Compiled waiting is not compressed unless the waiting rule itself is amended. Human review is not compressed by pretending the human has reviewed. External dependency is not compressed by hiding it under concurrent dispatch. The certificate does not legalize latency laundering.

The operational payoff is therefore exact:

Parallel admissibility reduces the active gate-processing latency of the Check by replacing certified serial gate segments with certified concurrent segments, while preserving all real dependencies, all compiled waiting rules, all witness requirements, and π₀-normalized trace comparability.

This payoff becomes strategically important when the admissibility threshold sits in front of high-rate systems.

A frontier agentic system may generate many candidate Σ per second. A governance layer that can process only one Σ at serial Check speed becomes a bottleneck. The bottleneck has two possible consequences. Either admissibility becomes too slow and is bypassed by pressure, or throughput is preserved by weakening the Check. Both outcomes are unacceptable. The first abandons the threshold. The second hollows it out.

Parallel admissibility offers a third path: preserve the Check while increasing its throughput.

Throughput arithmetic follows directly from latency.

If one Check instance takes L milliseconds of active processing, the ideal single-lane throughput is:

T = 1000 / L checks per second

Using the example above:

Serial Check:

L = 804 ms

T_serial = 1000 / 804 ≈ 1.24 checks/sec

Within-block parallel Check:

L = 516 ms

T_parallel_blocks = 1000 / 516 ≈ 1.94 checks/sec

Cross-block parallel Check:

L = 458 ms

T_parallel_ZB = 1000 / 458 ≈ 2.18 checks/sec

Nine-gate parallel Check:

L = 392 ms

T_parallel_ZBØ = 1000 / 392 ≈ 2.55 checks/sec

The increase is not infinite. But it is material. The nine-gate parallel Check more than doubles single-lane active throughput relative to the serial baseline:

2.55 / 1.24 ≈ 2.06

In distributed implementations, the effect compounds because fan-out allows better use of parallel infrastructure without changing the logical Check. Multiple Σ streams may still require admission controls, queue policies, priority rules, and quarantine buffers. But each individual Check no longer spends unnecessary time inside a false total order.

That is why the certificate has operational value.

Not because it makes the canon faster for speed’s sake.

Because, in post-Flash conditions, a governance layer that cannot keep pace with candidate-state formation will be pressured into either ceremonial review or unsafe shortcuts. Parallel admissibility protects the threshold from both pressures. It says: keep the gates; remove the false line; preserve the witness; normalize the trace; compress only what commutation has certified as compressible.

The binding constraint shifts.

Before Outcome A, the binding constraint was the inherited ordering.

After Outcome A, the binding constraint becomes the true dependency depth of the Check.

That is a profound upgrade. It means the threshold’s latency is no longer determined by an unmeasured historical sequence. It is determined by compiled dependencies. In a system governed by admissibility, this is exactly the kind of change that matters: not a declaration that governance must be fast, but a proof that a specific portion of governance was slower than its own law required.

The section closes with the latency rule for Outcome A:

Where the Commutativity Certificate applies, the Admissibility Check shall be executed at the depth of its certified dependency graph, not at the length of its historical total order.

The ledger may still remember π₀.

The runtime need not wait for it.


10.3 — Budget Accounting Under Parallelism

Parallel execution changes latency.

It does not automatically change cost.

This distinction must be compiled before the first implementation of parallel admissibility, because the commuting branch creates a predictable temptation: once a certified segment runs faster, operators will be tempted to treat it as cheaper. The Check completed in less wall-clock time. Fewer sequential steps were visible. The procedure felt lighter. The queue cleared faster. The infrastructure appeared more efficient. From there, the mind moves easily toward the wrong inference: if the segment took less time, it must have consumed less admissibility budget.

That inference is forbidden.

Admissibility Budget A_B is not a stopwatch. It is not the elapsed duration of review. It is not the amount of waiting endured by an operator. It is not the number of wall-clock milliseconds between Silence Entry and commit. It is the computed cost of admitting a pre-executable state toward actuality under the relevant constraints, witness requirements, irreversibility exposure, coherence pressure, routing consequences, and admissibility curvature. Time may enter that computation where the budget formula explicitly includes time-dependent terms. But latency reduction by itself is not budget reduction.

Parallel admissibility therefore requires a budget rule.

The conservative rule adopted by this volume is identical summation.

If a set of gates K is certified as commuting and executed concurrently, the path costs associated with those gates are summed exactly as they would have been summed under π₀ serialization, unless and until a dedicated LCR compiles a different budget arithmetic for certified parallel execution.

Formally:

A_B_serial(Σ, K) = Σ cost(Gᵢ, Σ) for all Gᵢ ∈ K

A_B_parallel(Σ, K) = Σ cost(Gᵢ, Σ) for all Gᵢ ∈ K

Therefore:

A_B_parallel(Σ, K) = A_B_serial(Σ, K)

under the baseline Outcome A rule.

This is the entire accounting principle.

Concurrency may collapse the active gate-processing latency from the sum of gate durations to the depth of the parallelized segment. It may reduce queue pressure. It may reduce observer waiting time. It may reduce opportunity for candidate-state evolution inside the governance delay. It may increase throughput. None of those gains automatically changes the budget arithmetic attached to the gates themselves.

The reason is simple. A gate’s cost is not incurred because the gate waited its turn. A gate’s cost is incurred because the state Σ required that gate’s admissibility question to be asked, witnessed, and routed. If four zero-questions each examine a distinct admissibility exposure, those exposures do not become one exposure because the questions ran at the same time. If four blocking-questions each carry a possible route into refusal, quarantine, or additional witness, those route possibilities do not discount one another merely because the execution graph fanned out.

The threshold has become faster.

The state has not become cheaper.

This must be protected especially where the implementation uses a single shared input snapshot. A shared snapshot may create the visual appearance of one operation: one Σ broadcast outward, one fan-out, one aggregation boundary, one normalized trace. But the budget does not price the beauty of the architecture. It prices the admissibility exposure carried by the state and by the gates required to inspect it. The fact that the gates read from one fixed hash does not merge their cost identities. It only protects their comparability.

A worked example makes the rule clear.

Assume a certified concurrent set:

K = {G_Z1, G_Z2, G_Z3, G_Z4}

Let the budget costs assigned by the budget formula be:

cost(G_Z1, Σ) = 0.08 A_B units
cost(G_Z2, Σ) = 0.12 A_B units
cost(G_Z3, Σ) = 0.05 A_B units
cost(G_Z4, Σ) = 0.10 A_B units

Under serial execution:

A_B_serial(Z, Σ) = 0.08 + 0.12 + 0.05 + 0.10 = 0.35 A_B units

Under parallel execution:

A_B_parallel(Z, Σ) = 0.08 + 0.12 + 0.05 + 0.10 = 0.35 A_B units

The latency may have collapsed from 182 ms to 67 ms. The budget remains 0.35 A_B units.

If the blocking block is also certified and carries:

cost(G_B1, Σ) = 0.15 A_B units
cost(G_B2, Σ) = 0.18 A_B units
cost(G_B3, Σ) = 0.11 A_B units
cost(G_B4, Σ) = 0.16 A_B units

then:

A_B_serial(B, Σ) = 0.60 A_B units

and:

A_B_parallel(B, Σ) = 0.60 A_B units

If the zero and blocking blocks are executed as one certified eight-gate fan-out, the total cost is still:

A_B_parallel(ZB, Σ) = 0.35 + 0.60 = 0.95 A_B units

The fan-out does not create a bulk discount.

The aggregation boundary does not create a bulk discount.

The π₀-normalized trace does not create a bulk discount.

The certificate does not create a bulk discount.

This is not because discounting is impossible in principle. It is because discounting is not certified by commutation alone. A future LCR may ask whether certain gate costs overlap. It may ask whether two gates draw from the same underlying admissibility exposure and therefore double-count a cost. It may ask whether shared witness production reduces marginal budget burden. It may ask whether, under strict conditions, a certified concurrent segment deserves a path-cost discount because a single evidence structure satisfies multiple gates simultaneously.

Those may be legitimate questions.

They are not answered by this volume.

The Commutativity Certificate certifies that tested order differences did not alter final status or witness residue beyond the declared error budget. It does not certify that budget components are independent. It does not certify that budget components overlap. It does not certify that simultaneous execution reduces the irreversibility, coherence, witness, or proof burden of the state. It does not certify that the cost function is subadditive under concurrency.

Therefore, budget discounting requires a separate LCR.

That LCR must be named, scoped, measured, and routed through its own gate. It must define the proposed discount rule, identify the cost terms affected, specify whether the discount applies by gate pair, by block, by class, or by evidence structure, prove that no budget exposure is erased by convenience, and provide a rollback rule if future anomalies show that the discount concealed an actual cost. Until that LCR exists and is compiled, identical summation remains law.

The prohibition is explicit:

Latency savings may never masquerade as budget savings.

A Check that completes faster has not necessarily paid less admissibility cost. It has paid the same cost in less active time. Treating reduced duration as reduced A_B would import a runtime efficiency metric into a pre-runtime admissibility ledger. That import would corrupt the budget by confusing the economics of computation with the geometry of permission.

This confusion is especially dangerous in high-throughput environments.

A deployment team under pressure will prefer the story that parallel admissibility “reduces budget.” A platform operator will prefer lower A_B readings because they allow more states to approach commit before budget ceilings bind. A governance dashboard will prefer green metrics. A post-Flash agentic environment will prefer anything that widens throughput while making the threshold look cheaper. The linter must therefore treat budget discount language as a high-risk pattern.

The following formulations are prohibited unless a dedicated budget LCR has compiled the claim:

“Parallel execution reduces A_B.”

“Concurrent gates spend less budget.”

“Certified fan-out lowers admissibility cost.”

“Latency compression creates budget headroom.”

“Because the gates commute, their costs overlap.”

“The parallel Check is cheaper than the serial Check.”

Each sentence may become true in a future, class-indexed, LCR-certified accounting regime. None is true under the baseline Commutativity Certificate. Under Outcome A as compiled here, parallelism changes active processing time, not A_B arithmetic.

A valid formulation is:

“Parallel execution reduces active gate latency while preserving identical A_B summation.”

Another valid formulation is:

“Certified concurrency increases throughput without discounting admissibility cost.”

A third valid formulation is:

“The Check becomes faster, not cheaper.”

This last sentence should be treated as the mnemonic for the entire section.

The budget ledger must also record concurrency explicitly. Even though summation remains identical, the mode of execution matters for audit and future research. Each budget record generated under parallel admissibility must include:

the certificate ID authorizing concurrency;

the concurrent gate set K;

the class index of Σ;

the gate-level cost entries;

the summation rule used;

the statement “identical summation applied”;

the latency of the segment;

the latency saved relative to π₀ serialization;

and any note indicating whether a future budget-overlap LCR has been requested.

This creates two separate data streams.

The A_B stream records admissibility cost.

The latency stream records temporal compression.

They may later be studied together. They may reveal patterns. They may support a future LCR. But they are not collapsed into one number. The canon must be able to say, for a given Σ, that the Check saved 346 ms while spending exactly the same 0.95 A_B units. That sentence is not awkward. It is disciplined.

A second worked example shows why the distinction matters.

Suppose a candidate Σ has a maximum admissibility budget ceiling of 1.20 A_B units before mandatory quarantine review. Its serial Check costs are:

zero-question block: 0.35 A_B
blocking-question block: 0.60 A_B
Zebra-Ø: 0.18 A_B
budget computation overhead: 0.04 A_B
final witness burden: 0.06 A_B

Total:

A_B_total = 0.35 + 0.60 + 0.18 + 0.04 + 0.06 = 1.23 A_B units

Under the budget rule, Σ exceeds the ceiling and must route to quarantine review or additional budget authorization.

Now suppose parallel execution reduces active latency from 804 ms to 458 ms. Nothing in the baseline certificate changes the total:

A_B_total_parallel = 1.23 A_B units

The state still exceeds the ceiling.

It may not be admitted merely because the Check became faster.

If an operator incorrectly treated latency reduction as a 20% budget discount, the false computation would become:

1.23 × 0.80 = 0.984 A_B units

The state would appear admissible under the ceiling.

That would be a governance failure. The parallel implementation would have converted a speed gain into a permission gain without passing through the budget law. This is precisely what the prohibition prevents.

The canon therefore names this failure mode:

Latency-Budget Substitution.

Latency-Budget Substitution occurs when reduced execution time, reduced queue time, reduced operator burden, or reduced infrastructure cost is used to lower A_B, increase admissibility headroom, avoid quarantine, bypass additional witness, or justify commit. It is a compiled misuse of the Commutativity Certificate and must trigger correction.

The linter for this misuse is straightforward.

It fires whenever an artifact, protocol, dashboard, or LCR cites the Commutativity Certificate, Parallel Admissibility, or concurrent gate execution in support of a lower A_B value without a dedicated budget-accounting LCR. The affected entry receives the status:

Misuse — Latency-Budget Substitution.

The correction is mandatory:

restore identical summation;

separate latency metrics from A_B metrics;

recalculate routing;

record whether the original incorrect discount would have changed status;

if status would have changed, open a quarantine review of the affected Σ records;

and issue a Notes-field correction for every downstream artifact that cited the discounted budget.

This may seem severe. It is not severe enough if the alternative is budget laundering.

Budget laundering is the deeper risk. It occurs when an implementation improvement is used to conceal an admissibility exposure. The exposure still exists, but it is hidden beneath better runtime performance. The system looks more efficient. The threshold looks healthier. The dashboard shows lower burden. But the state has not become less risky, less irreversible, less proof-expensive, or less coherence-demanding. The cost has not disappeared. It has been misclassified.

Parallel admissibility must be protected from becoming budget laundering.

That protection requires the conservative rule even if future research may eventually justify a more refined model. Conservatism here is not hesitation. It is layer discipline. Outcome A answers the order question. It does not answer the cost-overlap question. The fact that two questions are adjacent does not give one question permission to answer the other.

The section therefore compiles the following rule:

Parallel Budget Conservation Rule

For every Σ processed under a Commutativity Certificate, A_B shall be computed as if the certified concurrent gates had been executed in π₀ order, with all gate-level costs summed identically, unless a dedicated, compiled budget-accounting LCR establishes a class-indexed exception. Latency savings, throughput gains, infrastructure efficiencies, and reduced operator burden shall not reduce A_B.

This rule creates a clean separation between Chapter 10.2 and Chapter 10.3.

Chapter 10.2 established that the threshold may become faster by executing certified commuting operators concurrently.

Chapter 10.3 establishes that the threshold does not become cheaper by becoming faster.

That separation preserves the integrity of Outcome A. The canon earns parallel execution without accidentally weakening admissibility. It removes false sequence without erasing real cost. It allows the Check to meet post-Flash latency pressure while refusing to convert speed into permission.

The final accounting sentence is therefore fixed:

Under parallel admissibility, latency collapses by certified dependency depth; A_B remains conserved by identical summation.

Until the budget law itself is changed, the Check may run in parallel.

It must still pay in full.


Chapter 11 — The Decaying Certificate

11.1 — Certificates Are Witnessed Objects

A certificate does not stand outside the canon it governs.

This is the first discipline of Chapter 11. The Commutativity Certificate may certify the absence of measured Loop Residue across its indexed region, but the certificate itself is not exempt from residue. It is issued. It is recorded. It is cited. It changes what the canon may do. It alters execution architecture. It authorizes partial-order Check implementation. It preserves π₀ as a trace convention while loosening π₀ as an execution necessity. It therefore becomes a committed object inside the admissibility manifold.

A committed object carries witness residue.

The certificate is not merely a report about witness_residue. It has witness_residue. It leaves a trace because its issuance changes the state of the canon. It converts a campaign output into a governance permission. It changes the status of ordering from dark canon candidate to compiled convention in certified regions. It becomes a future dependency for LCRs, trace formats, implementation protocols, dashboards, audits, and citations. A certificate with that much downstream force cannot be treated as transparent.

It must be witnessed as an object.

This means that the Commutativity Certificate enters the same maintenance ecology as any other committed Σ. It is subject to Witness Thermodynamics. Its strength is not frozen by the date of issuance. Its witness quality can degrade. Its context can drift. Its supporting archive can become less representative. Its certified classes can cease to cover the dominant submission distribution. Its protocol version can be superseded. Its operator definitions can shift. Its error budget can become too coarse for later instrumentation. Its original negative finding can remain true within its epoch while losing force as a guide for later epochs.

That loss is not contradiction.

It is decay.

A certificate decays when the context in which its witness was produced is no longer sufficiently aligned with the context in which the certificate is being used. The certificate may still be historically correct. It may still be valid as a statement about the campaign that issued it. But the question of governance is not only whether the certificate was true when issued. The question is whether its witness remains strong enough to support the uses currently placed on it.

This is the difference between truth-at-issue and standing-over-time.

Truth-at-issue asks whether the original campaign output was correctly recorded.

Standing-over-time asks whether that output still has enough live witness to govern current procedure.

The canon must not confuse the two. A decayed certificate is not necessarily false. It is under-witnessed for present use. It may require recertification, narrowing, maintenance notes, class-specific downgrading, or temporary suspension. The aim is not to punish old evidence for being old. The aim is to prevent old evidence from silently overreaching into a changed field.

The Commutativity Certificate is especially vulnerable to this because it authorizes speed.

Once parallel admissibility is implemented, institutions will build around it. Tooling will assume it. Dashboards will display it. Throughput forecasts will price it. Operator habits will normalize it. The certificate will become invisible because it will become infrastructure. This is exactly when witness decay becomes dangerous. A certificate that no one remembers as contingent begins to function like dark canon again. It may have been compiled at birth, but if it is never maintained, it can decay into an unexamined default.

Therefore, Outcome A must not end with issuance.

Outcome A begins maintenance.

The certificate carries a witness half-life.

Let τ_w denote the certificate’s witness half-life: the epoch interval over which the certificate’s live governance force decays to a specified fraction of its issuance strength unless renewed by recertification or maintenance runs.

This is not a metaphorical half-life. It is a measurable quantity. It is not measured by asking whether readers still trust the certificate. It is measured by epoch-wise recertification runs that compare current or newly sampled submission classes against the original certified claim.

The certificate’s τ_w is therefore derived from the decay of recertification alignment.

Let W₀ be the certificate’s initial witness strength at issuance. W₀ is fixed by the campaign’s replication quality, class coverage, control-run calibration, contamination controls, protocol hash fixation, and mechanical issuability. W₀ does not mean emotional confidence. It means the initial witness strength assigned by the certificate issuance ledger.

Let W_e be the live witness strength measured at later epoch e through recertification.

Let D_e be the drift factor detected at epoch e, including class drift, operator drift, distribution drift, error-budget drift, protocol drift, and trace-schema drift.

A simple operational model may be stated as:

W_e = W₀ × A_e

where A_e is the recertification alignment coefficient for epoch e, with:

0 ≤ A_e ≤ 1

If A_e = 1, the epoch-wise recertification fully preserves the original witness strength within the declared maintenance criteria.

If A_e approaches 0, the certificate’s live witness has decayed to near-zero for current governance use, even if its historical record remains intact.

The witness half-life τ_w is the smallest epoch interval Δe such that:

W_e ≤ W₀ / 2

or equivalently:

A_e ≤ 0.5

This is the minimal measurable definition.

A certificate’s τ_w is not assumed in advance. It is estimated by repeated maintenance runs. Each run asks a narrow question: does the certificate still reproduce its zero-residue and zero-fragility finding under the current epoch’s relevant classes, current operator definitions, current trace schema, current measurement resolution, and current protocol constraints?

If the answer remains stable, τ_w lengthens.

If mild drift appears but no anomaly crosses the maintenance threshold, τ_w shortens or becomes class-specific.

If replicated λ or φ anomalies appear, the certificate does not merely decay. It enters review, local voiding, or global voiding according to the Rollback / Void Field.

The distinction between decay and anomaly must remain clear.

Decay is loss of witness force through context drift without necessarily contradicting the original result.

Anomaly is a measurement event that challenges the certificate’s current or original scope.

Decay says: this certificate may no longer be strong enough here.

Anomaly says: this certificate may be wrong here.

The maintenance architecture must treat them differently.

Epoch-wise recertification runs therefore carry five functions.

First, they measure whether the certified operator set still commutes over newly sampled submissions in the certified classes.

Second, they detect whether the certified classes have drifted in composition, structure, or admissibility signature.

Third, they detect whether new submission types are attempting to inherit certification without passing through class admission.

Fourth, they recalibrate the zero-band θ_λ against current instrumentation and control noise.

Fifth, they update the certificate’s live witness strength W_e and revise τ_w.

This turns the certificate from a static document into a maintained object.

The certificate has a birth, a witness strength, a half-life, maintenance records, recertification runs, possible local narrowing, possible renewal, possible voiding, and possible retirement. That is not bureaucratic heaviness. It is the cost of giving a certificate real force without letting it become myth.

A certificate that cannot decay is not a certificate.

It is dogma.

The following fields must therefore be appended to the Commutativity Certificate after issuance:

Witness Object Extension

1. Certificate Witness Residue ID
A unique Evidence Ledger reference recording the certificate as a committed Σ.

2. Initial Witness Strength W₀
The issuance-strength value derived from campaign quality, replication, coverage, calibration, contamination control, and mechanical issuability.

3. Maintenance Epoch Schedule
The required recertification interval, expressed in ledger epochs, not merely calendar time.

4. Recertification Sample Rule
The rule governing how current-epoch Σ samples are selected for maintenance runs, including class-balanced sampling and anomaly-seeded sampling.

5. Alignment Coefficient A_e
The epoch-specific coefficient expressing how strongly the current recertification run preserves the original certificate’s governance force.

6. Live Witness Strength W_e
The certificate’s current witness strength after epoch-wise alignment measurement.

7. Estimated τ_w
The current estimated witness half-life of the certificate, revised after each maintenance cycle.

8. Drift Taxonomy
A record of detected drift by category: class drift, operator drift, protocol drift, instrumentation drift, trace-schema drift, distribution drift, citation drift, and implementation drift.

9. Maintenance Status
One of the following: Fully Live, Live with Class Notes, Live with Narrowing, Pending Recertification, Locally Decayed, Globally Decayed, Under Anomaly Review, Locally Voided, Globally Voided, Retired.

10. Citation Constraint Update
Any additional qualifier required when citing the certificate after decay or narrowing has been detected.

These fields are not optional commentary. They are part of the certificate’s standing. A Commutativity Certificate without witness-object maintenance is incomplete after its first maintenance epoch.

The certificate’s witness residue also creates responsibility in citation.

A citation of the certificate after issuance date but before the first maintenance epoch may cite the issuance index. A citation after maintenance begins must cite the live maintenance status as well. It is no longer enough to say that certificate CC-X was issued. The citation must say whether CC-X is Fully Live, narrowed, pending recertification, under anomaly review, or decayed for the class in question.

This prevents a second kind of inflation.

Section 9.2 prohibited index inflation: citing the certificate without its scope.

Section 11.1 prohibits time inflation: citing the certificate as if issuance strength were permanent.

The linter for time inflation fires whenever a post-maintenance artifact cites a Commutativity Certificate without its current maintenance status, τ_w estimate, or class-specific live standing. The affected use receives the status:

Misuse — Certificate Time Inflation.

Correction requires attaching the current witness-object fields and re-evaluating any governance conclusion that depended on the certificate at full issuance strength.

A worked example clarifies the mechanism.

Assume certificate CC-10A is issued at epoch E₀ with:

W₀ = 1.00

It certifies commutation for classes C1, C2, and C3 across operator set K.

At epoch E₁, recertification samples current submissions from C1, C2, and C3. The replay campaign reproduces λ = 0 and φ = 0 across all sampled material. Minor trace-schema drift is detected but does not affect outcome. Alignment coefficient:

A_E1 = 0.92

Therefore:

W_E1 = 1.00 × 0.92 = 0.92

The certificate remains Fully Live, τ_w not yet reached.

At epoch E₂, C2 has shifted because new submission structures now carry witness residue patterns not present in the original archive. Recertification still returns λ = 0 and φ = 0 for C1 and C3, but C2 is underpowered after stratification. Alignment coefficient by class:

A_E2(C1) = 0.90
A_E2(C2) = 0.48
A_E2(C3) = 0.88

Then C1 and C3 remain live. C2 crosses the half-strength threshold and is marked Locally Decayed or Pending Recertification, depending on the maintenance rule. τ_w for C2 is reached at E₂. The global certificate is not automatically voided. It becomes class-narrowed.

At epoch E₃, a replicated λ anomaly appears in C2. The status of C2 moves from Locally Decayed to Under Anomaly Review or Locally Voided, according to the certificate’s Rollback / Void Field. C1 and C3 may remain live if no cross-class contamination is detected.

This example shows why τ_w must be class-indexed wherever possible. Certificates do not necessarily decay uniformly. A class whose submission ecology remains stable may preserve witness strength. A class exposed to new state types may decay quickly. A single global half-life may be useful as a dashboard summary, but the governing object is the class-indexed τ_w.

The formula may therefore be refined:

τ_w(C) = the smallest epoch interval Δe for class C such that A_e(C) ≤ 0.5

and the certificate’s global τ_w may be defined conservatively as:

τ_w(global) = min τ_w(C) across certified classes

This conservative global value prevents the strongest class from hiding decay in the weakest class. The certificate may still be cited for stronger classes, but only with class-specific standing attached.

Witness Thermodynamics also requires that recertification itself carries witness residue.

A maintenance run is not invisible. It modifies the certificate’s live standing. It may narrow it, renew it, or trigger review. Each maintenance run must therefore receive its own Evidence Ledger entry and must not be overwritten by later runs. The certificate’s life is an ordered chain of witness events:

issuance witness;

maintenance witness;

recertification witness;

drift witness;

anomaly witness;

narrowing witness;

renewal witness;

void witness;

retirement witness.

This chain is the certificate’s thermodynamic history.

A certificate without such history has no live governance value after its first context shift. It may remain a historical document. It may remain useful as archive. But it may not govern current parallel admissibility unless its witness chain is maintained.

The reason is not distrust of the original measurement. The reason is respect for measurement. A measurement has conditions. When conditions drift, a serious canon does not pretend that the measurement has become larger than its conditions. It measures again.

The section therefore compiles the following rule:

Witnessed Certificate Rule

Every Commutativity Certificate is a committed Σ with witness_residue and must be maintained under Witness Thermodynamics. Its live governance force decays under context drift unless renewed by epoch-wise recertification. The certificate’s τ_w is a measurable, class-indexed quantity derived from the decay of recertification alignment across ledger epochs.

This rule closes the naive reading of Outcome A.

A commuting result is not a permanent exemption from governance. It is a governed object that authorizes operational changes only while its witness remains live. The certificate may let gates run concurrently. It may compress threshold latency. It may preserve A_B summation while increasing throughput. But it cannot escape the thermodynamics of its own witness.

The canon therefore refuses the static certificate.

The certificate is born.

The certificate leaves residue.

The certificate ages.

The certificate must be re-witnessed.

Only then may it continue to govern.


11.2 — The Recertification Schedule

A certificate that is never retested becomes a ritual.

The canon cannot allow this. Once the Commutativity Certificate is issued, its maintenance cannot depend on memory, confidence, or institutional comfort. The certificate must be re-witnessed through scheduled partial replays. These replays are not a second full measurement campaign every time. They are maintenance instruments: smaller, class-indexed, epoch-wise checks designed to determine whether the certificate still carries enough live witness to govern current procedure.

The scheduled partial replay is therefore the standing maintenance operation of Outcome A.

It asks one narrow question:

Does the certified commutation claim still reproduce across a controlled sample of current-epoch submissions under the certificate’s active operator set, class index, trace schema, error budget, and protocol version?

If yes, the certificate’s live witness is renewed for the tested class and epoch. If partially, the certificate is narrowed, marked with class notes, or placed into pending recertification. If no, the certificate enters anomaly review, local voiding, or global review according to the Rollback / Void Field.

This schedule is not optional. It is part of the price of parallel admissibility.

Before Outcome A, the canon paid latency through serialization. After Outcome A, the canon pays maintenance through recertification. The cost has not disappeared. It has moved. A system that removes false sequence must add live witness. Otherwise the same result returns under another name: unexamined order before the certificate, unexamined concurrency after it.

The scheduled partial replay has four core properties.

First, it is periodic. It occurs at fixed ledger-epoch intervals, not merely when someone becomes concerned. The default interval is not calendar time alone, because calendar time may fail to capture submission-density shifts. A low-activity epoch and a high-activity epoch do not age a certificate equally. The schedule must therefore be defined in ledger epochs and may include a submission-count trigger. A certificate may require recertification every N ledger epochs, every M admitted or quarantined candidate states in certified classes, or whichever threshold arrives first.

Second, it is partial. Maintenance does not replay every archived Σ unless a trigger demands it. It selects samples according to the Recertification Sample Rule: class-balanced samples, edge-case samples, recently admitted samples, recently quarantined samples, anomaly-adjacent samples, and drift-sensitive samples. The aim is not theatrical completeness. The aim is efficient witness maintenance.

Third, it is comparative. The partial replay must include π₀ and the certified alternative orderings or certified concurrent execution graph relevant to the class being maintained. A recertification run that merely checks that π₀ still works is not recertification. It must retest the commutation relation the certificate claims.

Fourth, it is ledger-producing. Each scheduled partial replay creates its own Evidence Ledger entry, updates the certificate’s maintenance status, recalculates class-indexed alignment coefficients, and revises τ_w where needed. No maintenance run may be performed informally. No result may be summarized without trace.

The baseline recertification schedule is therefore:

Scheduled Recertification Rule

For each certified class C, run a partial replay at every maintenance epoch E_m, where E_m is defined by the shorter of: a fixed ledger-epoch interval, a fixed count of new Σ processed under the certificate, or the certificate’s class-specific τ_w warning threshold. The replay must compare π₀-normalized execution against the certified alternative ordering set or certified partial-order graph, using current-epoch samples and the active error budget. The result updates W_e(C), A_e(C), τ_w(C), and the certificate’s maintenance status.

This rule ensures that the certificate is not maintained by belief.

It is maintained by replay.

The schedule has three tiers.

Tier One: Routine Partial Replay

Routine partial replay is the ordinary maintenance run. It occurs according to the scheduled interval and uses a predeclared sample size sufficient to detect drift at the maintenance sensitivity level. It is not expected to discover major anomalies. Its purpose is to renew witness, verify class stability, recalibrate noise, and confirm that parallel execution remains safe in the certified region.

The routine replay records:

certificate ID;

maintenance epoch;

class index;

sample-selection rule;

number of Σ sampled;

ordering set or partial-order graph tested;

π₀ comparison;

λ result;

φ result;

control-run calibration;

alignment coefficient A_e(C);

live witness strength W_e(C);

τ_w revision;

drift notes;

maintenance status.

If all values remain within the declared maintenance envelope, the class remains Fully Live or Live with Notes.

Tier Two: Expanded Partial Replay

Expanded partial replay occurs when routine maintenance detects drift that does not yet qualify as anomaly. Examples include underpowered sampling for a class, increased variance in λ values still below θ_λ, minor trace-schema change, weak operator-definition drift, a rise in borderline submissions, or a change in submission distribution that makes the original archive less representative.

Expanded partial replay increases sample size, stratifies more deeply, and may include additional archived Σ from earlier epochs for comparison. Its purpose is to determine whether drift is benign, class-specific, or beginning to erode the certificate’s standing.

If expanded replay restores alignment, the class may remain live with a Notes-field record. If it fails to restore alignment, the class is marked Pending Recertification or Locally Decayed.

Tier Three: Full Recertification Campaign

Full recertification is not routine maintenance. It is a new measurement campaign triggered when the certificate’s standing can no longer be maintained through partial replay. It may be local to a class, local to an operator subset, or global to the entire certificate. It repeats the relevant campaign structure at sufficient power to decide whether the certificate should be renewed, narrowed, amended, voided, or replaced.

A full recertification campaign is required when partial replay cannot determine standing, when drift crosses the half-life threshold, when a replicated anomaly appears, or when the certificate’s scope is being materially extended.

The schedule handles ordinary aging. It does not handle structural shock alone. For that, the canon requires unscheduled recertification triggers.

Unscheduled recertification is mandatory whenever the environment changes in a way that could affect the commutation claim. The certificate does not wait politely for the next maintenance epoch when its conditions have been altered. It must be re-witnessed at the point of disturbance.

The first trigger is a new submission class.

A new class cannot inherit certification. If a future Σ type appears with a structure not represented in the original certified archive, it must be routed through class admission before receiving parallel admissibility. The certificate may be used to generate a hypothesis: this class may commute like C1 or C3. It may not be used as a permission. The correct route is unscheduled recertification or class-specific certification.

A new submission class trigger fires when any of the following occurs:

a new class label is created in the Admissibility Graph;

a recurring cluster of submissions fails to fit existing class definitions;

a certified class begins to contain a subclass with distinct witness residue, budget profile, curvature signature, refusal pattern, or routing behavior;

an implementation proposes to process a novel Σ type under an existing certificate by analogy;

an external audit identifies class drift substantial enough to require reclassification.

Until recertification completes, the new class remains outside parallel admissibility. It may run under π₀ serialization, quarantine routing, or a provisional review mode, but it may not receive the certificate’s concurrency rights.

The second trigger is any amendment to a gate definition.

A gate is not its name. A gate is what it reads, writes, blocks, routes, prices, witnesses, and emits into the ledger. If any gate’s definition changes in a way that touches its input conditions, output fields, routing effect, witness contribution, budget interaction, refusal behavior, quarantine path, or trace emission, the certificate may no longer apply to that gate relation.

This is true even if the amendment appears minor.

A gate-definition amendment trigger fires when:

a zero-question is reworded, narrowed, widened, split, merged, or given a new routing consequence;

a blocking-question changes its refusal threshold, quarantine behavior, or evidence requirement;

Zebra-Ø changes its sanity criteria, linter rules, myth-inflation checks, or non-admissible singularity route;

G_A changes the budget formula or the timing of budget computation;

the terminal segment changes its embargo, final witness, or commit semantics;

any operator gains or loses a side effect;

any operator’s ledger output schema changes in a way that affects comparison.

After such amendment, the certificate is suspended for the affected operator relations until unscheduled recertification confirms equivalence or compiles a new scope. The old certificate may remain live for untouched operators and classes, but only if the amendment can be cleanly isolated. If isolation is uncertain, conservative suspension applies.

The third trigger is any structural audit finding touching the Check.

A structural audit finding does not need to prove non-commutation to trigger recertification. It only needs to touch the Check’s ordering, operators, class routing, trace normalization, aggregation boundary, budget computation, or witness mechanism. The purpose of the trigger is preventive: structural findings reveal hidden dependencies, missing nodes, misrouted boundaries, uncompiled assumptions, or ledger inconsistencies. Any of those may alter the force of a certificate that was issued under earlier structural assumptions.

A structural audit trigger fires when an audit identifies:

a missing gate or latent gate-like operation;

a misrouted Atomic Decision Boundary;

a hidden side effect in a gate previously treated as pure;

a discrepancy between written protocol and implementation;

a trace-normalization failure;

a class-routing ambiguity;

an uncompiled aggregation rule;

an interaction between parallel execution and witness loss;

a budget-accounting ambiguity under concurrent gates;

a precedence lattice defect;

a rollback-readiness defect affecting the Check;

or any shadow procedure that conditions admissibility without compiled status.

The audit does not need to conclude that the certificate is invalid. It only needs to show that the certificate’s conditions may no longer be fully described by its index. When that happens, the certificate must be re-witnessed.

Additional triggers may be compiled later, but this volume establishes the minimum set:

new submission class;

gate-definition amendment;

structural audit finding touching the Check.

These are mandatory.

The schedule therefore has two channels:

planned maintenance and event-driven disturbance response.

Planned maintenance prevents slow decay.

Event-driven recertification prevents sudden overreach.

Both require budget.

This is the permanent budget line introduced by Outcome A.

The Commutativity Certificate reduces active Check latency where it applies, but it creates an ongoing maintenance cost that did not previously exist in explicit form. That cost includes scheduled replay computation, sample selection, operator execution, control runs, trace normalization, ledger entries, witness-strength calculation, drift analysis, anomaly review, and, when necessary, expanded replay or full recertification.

The canon must not hide this cost.

The maintenance budget is not an optional overhead attached to parallel admissibility. It is part of the law that makes parallel admissibility legitimate. If an implementation cannot fund recertification, it cannot keep citing the certificate indefinitely. If a governance environment wants the throughput benefit of concurrent gate execution, it must pay the witness-maintenance cost that keeps concurrency from becoming ungoverned habit.

The budget line should be recorded as:

Certificate Maintenance Budget — CMB

CMB is the permanent budget allocation required to maintain the live witness standing of a Commutativity Certificate. It covers routine partial replays, expanded partial replays, unscheduled trigger response, class-specific recertification, trace normalization, witness-strength updates, τ_w estimation, and Notes-field correction.

CMB is separate from A_B.

A_B prices the admissibility cost of a candidate state.

CMB prices the maintenance cost of the certificate that allows the Check to process candidate states in partial-order form.

The two must not be confused. A candidate Σ does not become more or less admissible because the canon spends more on certificate maintenance. Likewise, certificate maintenance cannot be skipped because a particular Σ has low A_B. They belong to different accounting layers.

CMB may be expressed per certificate, per class, per epoch, and per processed submission volume. A minimal formula is:

CMB_e = C_routine(e) + C_expanded(e) + C_trigger(e) + C_anomaly(e) + C_trace(e)

where:

C_routine(e) is the cost of scheduled partial replays in epoch e;

C_expanded(e) is the cost of expanded replay caused by detected drift;

C_trigger(e) is the cost of unscheduled recertification triggered by structural change;

C_anomaly(e) is the cost of anomaly review, local voiding, or global review;

C_trace(e) is the cost of ledger update, normalization, maintenance-status propagation, and citation correction.

The formula is intentionally plain. It does not pretend that maintenance cost is elegant. Governance has upkeep. A certificate that authorizes parallel execution is not a one-time discovery. It is an object with operating expense.

This permanent budget line is one of the most important consequences of Outcome A.

Before the measurement, the cost of π₀ was hidden as latency. The system paid through serial delay without knowing whether delay was necessary.

After the measurement, part of that latency may be recovered. But the recovered time is not free. It is exchanged for an explicit maintenance budget. This is a better trade because the cost becomes visible, governable, and adjustable. Hidden latency becomes compiled upkeep.

The canon should prefer visible upkeep to invisible drag.

But it must not pretend the trade is costless.

The recertification schedule therefore closes with a rule:

Certificate Maintenance Rule

Any Commutativity Certificate that authorizes parallel admissibility must carry a scheduled partial-replay program, mandatory unscheduled recertification triggers, and a permanent Certificate Maintenance Budget. If the schedule lapses, the certificate’s live witness standing decays according to τ_w. If maintenance lapses beyond the class-specific half-life threshold, concurrency rights for the affected class are suspended until recertification restores standing.

This rule prevents a familiar institutional failure.

At the beginning, everyone remembers that the certificate was conditional. The first parallel implementation is careful. The trace fields are complete. The maintenance plan is fresh. Then throughput improves. Queues shorten. Operators become accustomed to the new speed. The certificate disappears from attention because it is working. Maintenance becomes annoying. Partial replays look redundant. Budget owners ask why they are paying to confirm what everyone already knows. The schedule slips. The certificate remains cited. Years later, the canon discovers that a once-compiled certificate has become an inherited assumption.

That is the decay path.

The recertification schedule is designed to interrupt it.

A certificate may govern only while it is being re-witnessed. A commuting result may support concurrency only while its context remains alive under maintenance. The budget line is permanent because the object is permanent only as long as maintenance continues.

The final sentence of this section is therefore not technical. It is constitutional for Outcome A:

Parallel admissibility is not bought once by measurement; it is rented continuously through recertification.


11.3 — Local Voiding

A certificate does not have to die everywhere in order to die somewhere.

This is the first rule of local voiding. The Commutativity Certificate is class-indexed by design, and what is class-indexed may fail by class. A defect discovered in one certified submission class does not automatically destroy the certificate’s standing in every other class. The canon must be capable of narrowing without panic. It must be capable of saying: the certificate no longer governs here, while still governing there.

That sentence is not compromise.

It is precision.

Global voiding is required only when the defect touches the certificate’s root conditions: the protocol itself, the tested operator definitions as a whole, the hash-fixation method, the control-run calibration, the mechanical issuance rule, the precedence lattice, or another structural element whose failure contaminates all certified classes. Local voiding applies when the defect is class-specific, operator-relation-specific within a class, or distribution-specific to a portion of the certificate’s scope.

A certificate can therefore survive with wounds.

It can remain live for C1 and C3 while dying for C2. It can remain live for the zero-question block in C4 while losing authority for cross-block concurrency in C4. It can remain live for submissions drawn from an earlier stable subclass while suspending a newly emerged subclass that had been incorrectly processed under the same class label. The governing question is not whether the certificate has been embarrassed. The governing question is where its witness has failed.

Local voiding begins when one of four events occurs.

First, a replicated λ anomaly appears in a certified class and cannot be attributed to instrumentation noise, trace error, or contamination.

Second, a replicated φ anomaly appears in a certified class, meaning final status flips across tested orderings for that class under maintenance or recertification.

Third, class drift becomes strong enough that the original certificate no longer covers the current class population, and expanded partial replay fails to restore alignment.

Fourth, a structural audit finding shows that the certificate’s conditions were violated for one class while remaining intact for others.

Any one of these events can trigger local voiding.

The trigger does not need to prove that the entire certificate is false. It needs to prove that the certificate no longer has standing for the affected class. Once that standing fails, parallel admissibility for that class cannot continue while the canon deliberates. The class reverts immediately.

The automatic rule is:

A voided class reverts to serialized π₀ execution at the moment of void entry.

There is no grace period.

There is no operational discretion.

There is no “continue under observation” mode unless a separate emergency LCR explicitly compiles such a mode before use. The reason is straightforward: the certificate was the authority that allowed the class to leave total-order execution. Once the certificate dies locally, the authority dies locally. What remains is the pre-certificate default: π₀ serialization, π₀-normalized trace, full sequence discipline, and no concurrent execution rights for that class.

This automatic reversion is not punishment. It is rollback.

Parallel execution was a privilege granted by live witness. Local voiding removes the witness. The system returns to the last compiled safe convention.

The ledger mechanics must make this reversion impossible to miss.

A local void event requires a dedicated Evidence Ledger entry, not a note buried inside a maintenance report. The entry must be named, timestamped, class-indexed, and linked to the certificate ID. It must identify the exact class, subclass, operator relation, ordering set, epoch range, and trigger event that caused the void. It must record whether the void is provisional, confirmed, or final, and it must specify the immediate execution reversion rule.

The local void entry must contain the following fields:

1. Local Void ID
Unique identifier assigned to the void event. Format: LV-[certificate ID]-[class ID]-[epoch]-[sequence number].

2. Certificate ID
The Commutativity Certificate whose local standing is being voided.

3. Affected Class or Subclass
The certified class, subclass, or newly discovered class segment to which the void applies.

4. Trigger Type
Replicated λ anomaly, replicated φ anomaly, class drift, gate-definition mismatch, structural audit finding, contamination discovery, trace-normalization failure, or other compiled trigger.

5. Trigger Evidence Reference
Evidence Ledger references for the maintenance run, recertification run, audit finding, anomaly log, or replay comparison that caused the void.

6. Operator Scope
The exact operator set or operator relation affected. If the void applies to the whole class, state this explicitly. If it applies only to cross-block concurrency, within-block concurrency, Zebra-Ø concurrency, or another subset, the subset must be named.

7. Ordering Scope
The tested ordering set or partial-order graph whose certificate standing failed.

8. Epoch Scope
The epoch or epoch range for which the void applies, including whether prior processed submissions require retrospective review.

9. Void Status
Provisional Local Void, Confirmed Local Void, Final Local Void, or Converted to Global Review.

10. Automatic Reversion Statement
Mandatory text: “Effective immediately upon this ledger entry, the affected class reverts to serialized π₀ execution. No concurrent gate execution may be performed for this class under the voided certificate scope until recertification restores standing or a new certificate is issued.”

11. Downstream Impact List
All protocols, dashboards, LCRs, implementation settings, advisory outputs, and trace schemas that cited the certificate for the affected class.

12. Retrospective Review Requirement
Statement of whether past submissions processed under parallel admissibility in the affected class require audit, quarantine review, replay, or Notes-field correction.

13. Restoration Path
Required route for reinstating concurrency: expanded recertification, full class-specific campaign, gate-amendment LCR, new class admission, or certificate replacement.

14. Citation Update
Required new citation language indicating that the certificate is locally void for the affected class.

15. Witness Residue Update
Revision to W_e(C), τ_w(C), and certificate maintenance status after local voiding.

The local void event does not erase the original certificate. It annotates it.

The certificate remains in the ledger with its issuance record intact. Its original claim remains historically recorded. Its live standing changes. The ledger must never rewrite the certificate as if the void had always been known, because that would destroy the witness chain. The correct form is not deletion but status transition:

Issued → Fully Live → Live with Notes → Under Anomaly Review → Locally Voided for C2

or, where the defect appears suddenly:

Issued → Fully Live → Confirmed Local Void for C2

This chain matters because future operators must be able to see the path by which authority was lost. A void without history becomes another untraceable law. The point of local voiding is not only to stop unsafe concurrency. It is to preserve the memory of why concurrency stopped.

A simple example shows the mechanics.

Assume certificate CC-10A certifies classes C1, C2, and C3 for an eight-gate fan-out:

K = {G_Z1, G_Z2, G_Z3, G_Z4, G_B1, G_B2, G_B3, G_B4}

At epoch E5, scheduled partial replay returns λ = 0 and φ = 0 for C1 and C3. For C2, however, two independent replay operators detect a small but replicated λ difference between π₀ and a certified alternative ordering. The difference exceeds θ_λ. Final status does not flip, so φ remains 0, but λ is no longer within the declared zero band.

The defect is class-specific.

The protocol checks for contamination. None is found. It checks hash fixation. Hashes match. It checks trace normalization. No trace error is found. It checks whether the anomaly appears in C1 or C3. It does not.

The correct outcome is not global voiding. It is local voiding for C2.

The ledger entry LV-CC10A-C2-E5-001 is issued. The certificate remains live for C1 and C3. C2 immediately reverts to serialized π₀ execution. All dashboards processing C2 under parallel admissibility must disable concurrent execution for C2. All LCRs citing CC-10A for C2 must update their citation status. All new C2 submissions must run under π₀ serialization until restoration.

This is how a certificate dies locally.

The death is not dramatic. It is exact.

The most important mechanic is automatic routing reversion. The affected class must not wait for governance discussion to determine how it should run. The execution router must read the local void entry and enforce π₀ serialization immediately. If the router cannot enforce this automatically, then the implementation was never compliant with parallel admissibility. A certificate that can authorize concurrency but cannot automatically withdraw it is structurally unsafe.

The router rule is therefore:

Before executing any certified concurrent gate set, the system must check the certificate’s live standing for the specific class and operator scope. If status = Locally Voided, Pending Void, Globally Voided, Under Mandatory Suspension, or Maintenance Lapsed Beyond τ_w, the router must reject partial-order execution and route the class through serialized π₀ execution.

This must be machine-readable.

Local voiding cannot depend on human memory.

The certificate index must therefore be exposed to the execution layer as a status table:

Class ID
Operator Scope
Concurrency Status
Certificate ID
Maintenance Status
Void Status
Permitted Execution Mode
Last Recertification Epoch
Next Maintenance Deadline
Restoration Required

For a live class, the permitted execution mode may read:

Partial-order execution permitted under CC-10A.

For a locally voided class, it must read:

π₀ serialization required. Concurrency prohibited under CC-10A.

For a class pending recertification, it may read:

π₀ serialization required until maintenance standing restored.

The table is not administrative. It is the interface by which witness status controls execution.

Local voiding also requires retrospective classification.

Not every local void implies that past parallel executions in the affected class were wrong. A local void may arise because the class drifted after the original issuance. It may apply only from the drift point forward. It may reveal that earlier executions were valid under their epoch but current executions are no longer covered. Conversely, it may reveal that a hidden defect existed before the certificate was issued, in which case past submissions may require replay, quarantine review, or status correction.

The ledger must therefore distinguish four retrospective modes:

No Retrospective Action
The void is caused by new drift clearly after prior valid execution. Past records remain unchanged, with a Notes-field indicating later local void.

Notes-Field Retrospective Annotation
Past records remain valid but must be annotated to show that the class later lost certificate standing.

Targeted Retrospective Replay
Past records in the affected class or epoch range must be replayed under π₀ and compared against their parallel outputs.

Retrospective Quarantine Review
Past records may have been admitted under invalid concurrency and must be routed to quarantine review pending replay or additional witness.

The local void entry must select one of these modes. It cannot leave retrospective status undefined. Undefined retrospective status is how a local void spreads uncertainty through the ledger without governance.

A local void may also be operator-scope-specific.

Suppose C4 remains safe for within-block parallelism, but cross-block concurrency fails. In that case, the certificate does not die for all concurrency in C4. It dies for the cross-block fan-out. The execution router must revert C4 to the last live certified graph, not necessarily to full π₀ serialization if a narrower certified graph remains valid.

However, this narrower reversion is permitted only when the local void entry can isolate the failed operator relation cleanly. If isolation is uncertain, full π₀ serialization applies by default. The conservative rule is:

When scope isolation is uncertain, reversion expands.

This prevents a partial void from becoming a loophole. The canon may preserve unaffected concurrency only where unaffectedness is itself witnessed. Otherwise, it returns to π₀.

Local voiding also changes citation law.

After a class is locally voided, the certificate may not be cited for that class without the void status. A citation that says “CC-10A certifies C2” after C2 has been locally voided is false even if CC-10A historically certified C2 at issuance. The only valid citation is:

CC-10A, C2, locally voided as of LV-[ID], π₀ serialization required pending recertification.

For unaffected classes, the citation must still carry the class index:

CC-10A remains live for C1 and C3 under current maintenance status.

This prevents local voiding from contaminating or over-preserving the certificate by ambiguity. The canon must not say “the certificate is void” when only C2 is voided. It must not say “the certificate is live” when C2 is voided. It must say exactly where it lives and where it has died.

The linter for local voiding has two patterns.

The first is overgeneralization:

A local void in one class is cited as if it voids the entire certificate without evidence of global contamination.

Status: Misuse — Local Void Overgeneralization.

The second is concealment:

A certificate is cited as live for a class after that class has been locally voided.

Status: Misuse — Local Void Concealment.

Both misuses damage the canon. Overgeneralization destroys valid governance unnecessarily. Concealment preserves invalid governance dangerously. The linter must reject both.

A local void also updates witness thermodynamics.

For the affected class:

W_e(C) = 0 for the voided certificate scope

unless the void is provisional and the maintenance protocol assigns a temporary reduced value pending review. In final local voiding, live witness standing for that class under the affected certificate scope is zero. τ_w(C) is no longer a future estimate. The half-life threshold has been crossed and the certificate’s live force has collapsed for that class.

For unaffected classes, W_e remains whatever their maintenance runs support. However, a local void may increase the maintenance burden of adjacent classes. If C2 fails, C1 and C3 may require expanded partial replay if they are structurally near C2 or share operator interactions. This is not because void spreads automatically. It is because local failure carries information. The certificate survives elsewhere, but it may need to prove that survival more actively.

Thus the local void can generate maintenance pressure without generating global death.

This is the correct middle state.

The restoration path must be explicit.

A voided class may regain concurrency only through one of three routes.

First, expanded recertification may show that the void was caused by contamination, trace error, or a non-replicable artifact, and that the certificate’s standing can be restored.

Second, a full class-specific campaign may issue a new or renewed certificate for that class, possibly with a narrower operator set, revised ordering set, updated error budget, or modified trace rule.

Third, the class may be split, with one subclass restored under certification and another subclass remaining serialized or quarantined.

In no case may concurrency resume because operators believe the issue has “probably stabilized.” Restoration requires ledger entry, not reassurance.

The restoration entry must reference the local void ID, the evidence used to resolve it, the restored scope, the new maintenance schedule, and any changes to τ_w(C). If restoration is partial, the non-restored region remains voided. If restoration fails, the void remains in force or escalates to global review.

Local voiding is therefore not the opposite of the certificate.

It is part of the certificate’s life.

A serious certificate must contain its own death mechanics. It must know how to narrow itself, suspend itself, and route affected regions back to safety without waiting for institutional drama. The Commutativity Certificate earns its authority not only by being issued mechanically, but by being retractable mechanically.

That is the final discipline of this section.

The canon must be able to remove permission as cleanly as it granted it.

The rule is fixed:

Local Void Rule

When a Commutativity Certificate loses live standing for a specific certified class, subclass, operator relation, or ordering scope, the certificate is locally void for that scope. The affected class reverts immediately and automatically to serialized π₀ execution unless a narrower still-live certified graph is explicitly witnessed. The local void is recorded as a dedicated Evidence Ledger entry, updates certificate maintenance status, triggers citation correction, and defines retrospective review and restoration requirements.

This is how Outcome A avoids becoming brittle.

A brittle certificate has only two states: alive everywhere or dead everywhere. Such a certificate is too crude for a class-indexed canon. It would either preserve unsafe concurrency too long or destroy safe concurrency too broadly. A maintained certificate needs finer states. It needs local life and local death.

The certificate may therefore continue to govern where it remains witnessed.

Where its witness dies, π₀ returns.

Immediately.


Chapter 12 — The Bounded Triumph

12.1 — What the Canon Gains

Outcome A is a triumph only if the word triumph is kept small.

The canon does not gain proof that it was always right. It does not gain retrospective innocence. It does not gain permission to say that the old ordering was harmless because the measurement found no residue. It does not gain a story in which habit is vindicated by survival. That would be the wrong reading of the commuting branch.

What the canon gains is narrower and more valuable.

It gains a compiled convention.

It gains a parallel execution right.

It gains a maintenance institution.

These are the three outputs of the commuting branch. They are operational, not ceremonial. They do not glorify the old structure. They convert it.

Before the measurement, π₀ existed as a load-bearing sequence with no compiled status. It was the order in which the Admissibility Check was written, taught, executed, traced, and inherited. Every state that entered the admissible manifold had passed through that sequence, yet the sequence itself had not passed through the canon’s own discipline. It had no certificate. It had no declared necessity. It had no formal residual status. It had no half-life, no maintenance rule, no linter against inflation, no clean distinction between execution physics and trace convention.

That was the failure Part I named as dark canon.

Outcome A does not pretend the failure never existed. It closes it.

The first gain is therefore the conversion of π₀ into a compiled convention.

This is not a downgrade in the governance sense. It is an upgrade from ambiguity into status. π₀ no longer has to borrow authority from inheritance. It no longer has to function as if it might be physical necessity. It no longer hides inside the typographic sequence of an old protocol. It becomes what it can honestly be after the certificate: the canonical trace ordering for comparability, audit continuity, replay indexing, regression testing, and maintenance alignment.

That is a major gain because it separates two things that had been fused by neglect.

Execution order and trace order.

Before Outcome A, π₀ carried both without distinction. It was the order of execution because it was the order of trace, and it was the order of trace because it was the order of execution. The line had become self-justifying. After Outcome A, the line is split. The Check may execute as a partial-order graph where certification permits. The ledger still renders outcomes through π₀-normalized trace form where comparability requires it.

The canon gains the ability to say:

π₀ is not the hidden physics of admissibility in the certified region.

π₀ is the governed convention by which admissibility outcomes remain comparable across time.

This sentence is not exciting. That is why it is safe.

The second gain is the parallel execution right.

This right is not a general acceleration license. It is not a mandate to optimize the Check for speed at any cost. It is not an argument that governance should become frictionless. It is the specific right to execute certified commuting gates concurrently under the constraints of the certificate index, the precedence lattice, aggregation boundaries, contamination controls, π₀-normalized trace rendering, and unchanged A_B summation.

The word right must be read technically. A parallel execution right is a compiled permission granted to an execution architecture. It says that, for the named class and operator scope, the Check may stop spending latency on a sequence that the campaign showed not to affect final status or witness residue. The right is conditional. It can decay. It can be locally voided. It can be suspended when maintenance lapses. It can be narrowed by recertification. It can be withdrawn when anomaly appears.

Precisely because it can be withdrawn, it is real.

A permission that cannot be withdrawn is not permission. It is drift toward entitlement. Parallel admissibility remains lawful only because Chapter 11 gives the certificate a death mechanism. The canon therefore gains not merely faster execution, but faster execution under retractable authority.

That matters in post-Flash regimes.

Serialized governance becomes a bottleneck when internal loop rates exceed observer narration bandwidth. A governance system that insists on inherited sequence after sequence has been shown unnecessary wastes the scarcest resource at the threshold: pre-actuation time. But a governance system that removes sequence without measurement hollows out the threshold. Outcome A gives a third path. It preserves the gates while removing false latency. It keeps the questions and compresses only the waiting that no longer has law behind it.

The third gain is the maintenance institution.

This may be the least glamorous output of the commuting branch, and therefore the most important. The Commutativity Certificate does not remain alive by being printed. It remains alive by being re-witnessed. Scheduled partial replays, unscheduled recertification triggers, class-indexed τ_w estimation, local voiding, citation updates, status tables, and the permanent Certificate Maintenance Budget become part of the canon’s infrastructure.

This is not overhead in the derogatory sense. It is the cost of preventing a certificate from becoming a new dark canon.

The original problem was that π₀ operated without governance. The post-certificate risk is that parallel admissibility could do the same. The canon might begin by remembering that concurrency is conditional and end by treating it as obvious. Maintenance prevents that. It keeps the certificate visible. It forces the canon to ask, again and again, whether the conditions that justified concurrency remain present.

A maintained certificate is therefore better than an eternal certificate.

An eternal certificate would be easier to cite. It would be cleaner in diagrams. It would be more convenient for implementation teams. It would satisfy the desire for closure. But closure is not the measure of governance. Live witness is. A certificate that ages, decays, narrows, and renews is more honest than a certificate that pretends its issuance date froze the world.

The canon gains an institution of re-witnessing.

That gain extends beyond the ordering problem. Once the canon learns to maintain a certificate as a witnessed object, it gains a pattern for future certificates. Any future claim that authorizes architectural speed, execution flexibility, budget transformation, gate simplification, or trace normalization can be required to carry the same life-cycle fields: issuance, scope, live status, τ_w, maintenance schedule, void mechanics, and citation linter. Outcome A therefore does more than solve π₀. It upgrades the canon’s ability to hold its own permissions over time.

The consolidated inventory of Outcome A can now be stated.

First: Compiled Convention.
π₀ is converted from never-compiled habit into Canonical Trace Convention. Its authority is no longer hidden. It is no longer presumed to govern admissibility outcome formation in the certified region. It governs trace comparability, ledger normalization, audit continuity, and replay alignment unless superseded by LCR.

Second: Parallel Execution Right.
Certified commuting gate sets may execute concurrently as partial-order graphs. This right applies only to named operator scopes, named classes, named epoch ranges, and current live certificate standing. It preserves aggregation boundaries, prevents completion-time order from becoming hidden law, requires π₀-normalized trace output, and leaves A_B arithmetic unchanged under identical summation.

Third: Maintenance Institution.
The Commutativity Certificate becomes a witnessed object subject to Witness Thermodynamics. Its live standing is maintained through scheduled partial replays, unscheduled recertification triggers, class-indexed τ_w, local voiding, citation correction, and the permanent Certificate Maintenance Budget.

These three gains define the bounded triumph.

The canon gains clarity, speed, and upkeep.

It does not gain absolution.

The measured tone is mandatory because the commuting result can easily be misused as a moral story. It would be tempting to say: the canon tested its habit and the habit survived. But that is not precise. The habit did not survive as habit. It survived only after being stripped of unearned authority, measured, indexed, bounded, renamed, and placed under maintenance. What survived was not the old π₀. What survived was a governed remnant of π₀.

That difference must not be softened.

A vindicated habit remains dangerous because it continues to believe that survival was proof. A governed convention is safer because it knows exactly what kind of proof it has paid and where that proof ends.

The certificate is therefore not a vindication of habit.

It is the conversion of habit into governed structure.

The old ordering is not crowned. It is processed.

That is what the canon gains: not the emotional comfort of having been right, but the structural maturity of having turned an unexamined dependency into an accountable object. The commuting branch is triumphant only because it refuses the larger triumph it could falsely claim. It says no to metaphysical celebration, no to universal order-freedom, no to cost discounting by speed, no to permanent citation without maintenance, no to local failure becoming global panic, and no to global authority being smuggled out of local proof.

It accepts instead a smaller, harder victory.

The Check can run faster where the world has shown that sequence is not needed.

The ledger can remain comparable because π₀ is preserved as trace convention.

The certificate can stay alive only by being maintained.

This is enough.

In a canon built around admissibility, enough is not a weak word. Enough means that a claim has reached the boundary of what it can legitimately carry and has stopped there. Outcome A is strong because it stops there. It does not reach for more. It does not convert λ = 0 and φ = 0 into a mythology of orderlessness. It compiles the result into the exact structures needed to use it without corrupting it.

The canon gains a disciplined permission.

It gains the right to remove false latency.

It gains the obligation to maintain the proof that permitted the removal.

That is the bounded triumph.


12.2 — The Standing Question

Boundary Register

If the gates commute, the canon gains a certificate.

It does not gain an explanation.

This distinction must be preserved at the boundary. Outcome A certifies that no measurable Loop Residue and no Order Fragility appeared across the tested operator set, certified classes, ordering set, epoch range, and error budget. It authorizes the operational consequences already compiled in Chapters 9, 10, and 11. It converts π₀ into a trace convention. It grants a parallel execution right. It establishes certificate maintenance.

But it does not answer the deeper question opened by its own result.

Why did the gates commute?

This question cannot be dismissed as philosophical decoration. Under Quaternion Process Theory, process order is not assumed to be neutral. Operators that read, write, route, price, witness, block, quarantine, and alter a pre-executable state are not inert predicates floating outside geometry. They are transformations. They touch the state they examine. They change the ledger surface through which the state approaches commit. They participate in the boundary’s own architecture.

QPT gives no reason to expect such operators to commute by default.

That is the standing question.

If the Admissibility Check’s tested gates commute, the result is not banal. It is structurally strange. The absence of holonomy is itself a fact about the boundary. The boundary has behaved, in the tested region, as if its governance operators share a common compatibility structure strong enough to prevent order from leaving residue. The gates did not merely all “return the same answer.” They returned the same final witness condition across permitted orderings. They did not fracture status. They did not reveal hidden sequencing. They did not expose π₀ as a concealed geometry.

That absence demands explanation.

This volume does not provide it.

The measured campaign can certify the absence of detectable order effect. It cannot, by itself, say why the absence occurred. A zero result may arise from several structurally different causes, and the canon must not collapse them into one comforting story.

The first possible cause is true operator independence. The gates may examine sufficiently orthogonal aspects of Σ that their order cannot alter the quantities being read or written. In this interpretation, commutation reflects clean separation of concern inside the Check. Each gate touches a distinct admissibility surface. The state receives multiple inspections, but no inspection changes the substrate relevant to the next.

The second possible cause is shared projection. The gates may appear distinct while all of them ultimately project onto the same underlying boundary invariant. They commute not because they are independent, but because they are different faces of one deeper admissibility constraint. In that case, commutation would reveal hidden unity beneath the operator list. The Check would be less a chain of separate questions than a set of aliases for a single structural refusal-or-admission geometry.

The third possible cause is trace-level absorption. The gates may generate local differences, but those differences may be absorbed before final witness_residue and final status are measured. In this case, λ = 0 and φ = 0 would not mean that nothing happened inside the route. It would mean that the chosen measurement endpoints could not see the internal transient. The boundary may still contain order-sensitive microstructure beneath the resolution of the certificate.

The fourth possible cause is class limitation. The certified classes may occupy a region of the admissible manifold where the gates commute, while other regions would not. Commutation would then be a local property of the tested domain, not a global property of the Check. This is the safest reading under the certificate’s index, and it remains the default until broader measurement changes the map.

The fifth possible cause is epoch-conditioned alignment. The operators may commute under the present state of the canon because the current gate definitions, submission ecology, trace schema, and witness practices are aligned in a way that later epochs may not preserve. In that case, the certificate is not only class-bounded but historically situated. Its commutation reflects a temporary harmony of the boundary’s instruments.

The sixth possible cause is measurement insufficiency. The campaign may be correct within its declared error budget and still too coarse to expose smaller residue. This does not invalidate the certificate. It defines its resolution. A zero inside θ_λ is not infinite zero. It is disciplined zero. Future instrumentation may lower the zero band and reopen the question.

These possibilities are not alternatives the author chooses between in this section. They are explanatory branches. The certificate does not select among them. It only makes them unavoidable.

This is why the result must be logged as explanatory debt.

Explanatory Debt Entry — Outcome A / Commutation of the Check

Debt ID: ED-OA-12.2-COMMUTATION
Status: Logged, unpaid.
Trigger: Issuance of a Commutativity Certificate under Outcome A: λ = 0 within declared error budget and φ = 0 across certified classes, tested operator set, tested ordering set, and epoch range.
Boundary Claim: The commutation of governance operators at the admissibility boundary is a structural fact requiring explanation, because QPT does not license default commutation of process operators.
What Is Known: The tested operators produced no certified order effect at the measured endpoints.
What Is Not Known: Whether this reflects true operator independence, shared projection onto a deeper invariant, trace-level absorption, class-local geometry, epoch-conditioned alignment, or measurement-resolution limitation.
Operational Consequence: None beyond the already compiled certificate scope. This debt does not suspend Outcome A.
Prohibited Inflation: The certificate may not be cited as explaining why the gates commute. It only certifies that they did commute within scope.
Required Future Route: Dedicated explanatory LCR, new measurement design, or Frontier Node entry if the explanation touches boundary structure beyond the current operator set.
Default Standing: Boundary-register working hypothesis only.

The working hypothesis may now be stated.

If the Check’s gates commute, the boundary may contain a compatibility geometry not previously named by the canon.

This sentence is intentionally weak.

It says may, not does. It says compatibility geometry, not universal commutativity. It says not previously named, not newly discovered as law. It is a hypothesis generated by a zero result, not a compiled explanation. It belongs in the boundary register because it stands at the edge where the measurement has forced a question but has not supplied the answer.

The canon must hold this question without converting it into doctrine.

The failure mode of Outcome B would be obvious: if λ ≠ 0 or φ > 0, the canon discovers that order matters and must confront dark canon directly. The failure mode of Outcome A is subtler. A zero result can seduce a system into thinking no deeper structure is present. But a clean zero in a place where non-commutation was plausible is not nothing. It is a constraint on future explanation. It says: whatever the boundary is doing here, it is doing it in a way that neutralizes tested order effects.

That neutrality may be profound.

It may also be local, contingent, or instrument-limited.

No boundary claim is allowed to outrun that uncertainty.

The certificate therefore creates two ledgers at once. The first is the governance ledger: what the canon may now do. That ledger is paid by the campaign. The second is the explanatory ledger: what the canon still does not understand. That ledger remains open.

This matters because explanation is not required for safe use in every case. A bridge may be certified for load before the deepest theory of its material fatigue is complete. A protocol may be permitted because its failure modes have been bounded, even if the structural reason for its success remains under study. The canon can use the Commutativity Certificate operationally while admitting that the reason behind commutation has not been compiled.

This is not hypocrisy.

It is layer discipline.

Operational certification and boundary explanation are different outputs. Confusing them would damage both. If the canon refused to use the certificate until it had a full explanation, it would waste a valid measured result. If the canon treated the valid measured result as explanation, it would create a new unearned law. The correct posture is simultaneous: use what has been certified; log what remains unexplained.

The standing question also protects QPT from false simplification.

Outcome A does not refute QPT’s warning that process order can carry geometry. It narrows the warning in a specific tested region. QPT said that order differences are admissible as real content and must not be dismissed in advance. The campaign asked the question. If the answer is zero within scope, QPT has not failed. QPT has done its work: it forced the canon to measure instead of assume.

A theory that allows non-commutation does not require non-commutation everywhere.

It requires that commutation be earned.

Outcome A earns it locally.

The explanatory debt records why local earned commutation is itself still interesting.

At the boundary, the deepest question is not whether the canon is relieved. Relief is not an epistemic category. The question is what kind of boundary produces commuting governance operators when there was no right to expect commutation by default. That question may eventually lead to a new account of boundary geometry. It may reveal that some admissibility gates are projections from a single invariant. It may reveal that witness_residue is a coarse terminal variable that hides internal order microstructure. It may reveal class stratification not yet visible in the current taxonomy. It may reveal that π₀’s history accidentally aligned with a deeper symmetry.

Or it may reveal nothing more than that the tested region was simpler than feared.

The canon does not choose before measurement.

The canon does not explain before derivation.

The canon logs the debt.

This section therefore closes with a boundary rule:

Standing Question Rule

When a Commutativity Certificate is issued, the operational right it grants is compiled, but the structural reason for commutation remains unpaid explanatory debt unless a separate artifact explains it. The certificate may govern execution within its index. It may not be cited as an explanation of boundary compatibility.

The bounded triumph is thus bounded twice.

It is bounded operationally by the certificate index.

It is bounded intellectually by the standing question.

The gates may commute.

The Check may parallelize.

The canon may gain speed.

But the boundary has not yet told us why it allowed this.

That silence is not a gap to cover.

It is the next object of discipline.


Part IV — Outcome B: Dark Canon Discovered


Chapter 13 — The Retroactivity Crisis

13.1 — The Manifold as Fiber

If λ ≠ 0, the admissible manifold was never simply the admissible manifold.

It was the π₀-admissible manifold.

This is the first formal consequence of Outcome B. The statement must be made before interpretation begins, because interpretation will try to soften it. It will try to say that the canon has discovered an implementation detail, a procedural instability, a weakness in replay design, or a technical dependency between gates. Those descriptions may later become partially useful, but they are not the first truth. The first truth is structural: if the order of the Check changes the final witness residue of a submission, then the manifold that the canon has been treating as the image of admissibility is in fact the image of a particular ordering.

The canonical ordering π₀ was not only a trace convention.

It was a selector.

Let S denote the population of candidate pre-executable states submitted to the Admissibility Check. Let Π_L denote the set of legal linear extensions of the precedence lattice. Let Check_π be the Admissibility Check executed under ordering π ∈ Π_L. Let Outcome(Check_π(Σ)) denote the final status, final witness_residue, and relevant terminal attributes produced by applying Check_π to a hash-identical Σ.

Before Outcome B, the canon used the term admissible manifold as if it denoted:

M_adm = {Σ ∈ S | Check(Σ) routes Σ to admissible}

But under nonzero λ or nonzero φ, Check is no longer an order-neutral function. It must be indexed.

The correct expression becomes:

M_π = {Σ ∈ S | Check_π(Σ) routes Σ to admissible}

The manifold historically compiled by the canon is therefore:

M_π₀ = {Σ ∈ S | Check_π₀(Σ) routes Σ to admissible}

If λ ≠ 0, then for at least one Σ and at least one legal ordering π, the final witness_residue under Check_π differs from the final witness_residue under Check_π₀ beyond the declared error budget. If φ > 0, then for at least one Σ and at least one legal ordering π, the final status itself differs. In either case, the old unindexed expression M_adm is no longer lawful. The manifold must carry the ordering index.

The old vocabulary hid the fiber.

From this chapter forward, “admissible” silently means “π₀-admissible” unless an explicit ordering index is supplied. This is not stylistic caution. It is a compiled vocabulary rule. A state admitted by Check_π₀ is admissible-under-π₀. A state admitted by Check_π₁ is admissible-under-π₁. If the two coincide for a given state, that coincidence may be recorded. If they diverge, the divergence must not be erased by the unindexed word admissible.

The unindexed word becomes unsafe after Outcome B.

This is the retroactivity crisis.

The crisis is not that past commits are automatically invalid. The crisis is that their description was incomplete. Every committed state that entered the manifold through π₀ entered through a particular fiber of the ordering space. The canon did not know that it was selecting through a fiber. It believed it was applying the Check. But the Check has now split into a family of order-indexed procedures. The historical manifold is therefore not a neutral region of admissibility. It is the image of submissions under Check_π₀.

Formally:

Historical manifold = Image(Check_π₀ over historical S)

Not:

Historical manifold = Image(Check over S)

because Check without π is no longer a well-defined object in the non-commuting branch.

This does not erase the historical manifold. It localizes it.

M_π₀ remains real. It remains the actual compiled region through which the canon has operated. It has ledger history, witness residue, downstream dependencies, published artifacts, governance consequences, and committed states. The discovery of non-commutation does not make it imaginary. It makes it indexed. The manifold does not disappear. It loses the right to pretend that it was the whole space.

A fiber is not a false manifold. It is a slice.

Under Outcome B, the admissible manifold becomes a fiber over the canonical ordering. The base is the space of legal orderings Π_L. Over each ordering π lies a possible image M_π, the manifold that would be generated if that ordering governed the Check. π₀ is the historical fiber. It is not necessarily privileged by geometry. It is privileged by history, trace, and compiled use.

The relevant structure is therefore:

π₀ → M_π₀
π₁ → M_π₁
π₂ → M_π₂

π_n → M_π_n

The old canon saw only M_π₀ and called it M_adm.

The Part II measurement reveals the projection map.

This is why the counterfactual family becomes defined.

Before the measurement, the question “what would the admissible manifold have been under a different legal ordering?” was not a formal object. It was at most a speculative worry. After Outcome B, that question becomes a measurable family:

CF(π) = M_π relative to M_π₀

where CF(π) records the status flips, witness_residue differences, budget differences, quarantine differences, refusal differences, and trace differences produced by executing Check_π instead of Check_π₀ over the same hash-fixed submission population.

The counterfactual family is not imaginary. It is not fictional. It is a family of replayable alternate manifolds generated by legal extensions of the same precedence lattice. These manifolds did not become historical because the canon used π₀. But they are not meaningless. They show what the canon’s admitted region would have been if a different legal ordering had been canonized.

This is the crisis in its coldest form:

The canon did not merely classify submissions.

It selected a world-line through ordering space.

The word world-line must not be romanticized. It means a traceable path of governance outcomes. Under non-commutation, different orderings produce different residue fields, and possibly different status boundaries. A canon that chose π₀ without compiling π₀ chose one such path without knowing that it was choosing. That is dark canon discovered.

The discovery is retroactive because the selection has already happened.

Every prior commit occurred under π₀. Every prior quarantine occurred under π₀. Every prior rejection occurred under π₀. Every prior witness residue was residue-after-π₀. The canon cannot now pretend that those outputs were order-neutral unless the measurement shows class-specific commutation for those regions. Where the measurement shows nonzero λ, the prior trace must be read as π₀-trace. Where it shows φ > 0, the prior final status must be read as π₀-status.

This does not automatically reopen every decision. That would be a different claim and would require its own census. But it does require a vocabulary correction across the whole affected region.

The correction is:

“Admissible” becomes “π₀-admissible.”

“Committed” becomes “committed-under-π₀.”

“Rejected” becomes “rejected-under-π₀.”

“Quarantined” becomes “quarantined-under-π₀.”

“Witness residue” becomes “witness residue under Check_π₀.”

These expanded forms need not be written every time in long form once the rule is compiled. But the rule must govern every use. From this chapter forward, in Part IV, the unindexed vocabulary is permitted only as shorthand for π₀-indexed vocabulary. Any claim that intends order-neutral admissibility must explicitly prove order-neutrality for the relevant class and operator scope.

This is the vocabulary rule:

π₀-Admissibility Rule

In Outcome B, the term “admissible” without an explicit ordering index denotes “admissible under Check_π₀” by default. The term may not be used to imply order-neutral admissibility unless a class-specific commutation certificate exists for the relevant operator set, ordering set, epoch range, and error budget. All historical manifold references are to be interpreted as references to M_π₀ unless otherwise indexed.

This rule must be enforced by a linter.

The linter fires when any post-Outcome-B artifact uses unindexed admissibility language in a way that implies order-neutral status. Examples include:

“the admissible manifold” without acknowledging M_π₀ in a non-commuting context;

“the Check admitted Σ” without specifying Check_π₀ or another ordering;

“Σ is admissible” where the claim is used to compare across orderings;

“the canon rejected Σ” where alternative ordering status is relevant;

“witness residue of Σ” where replay has shown order-dependent residue.

The linter status is:

Misuse — Unindexed Admissibility After Outcome B.

Correction requires either adding the π index or attaching a valid class-specific commutation certificate that licenses unindexed shorthand.

This vocabulary discipline is not cosmetic. It is how the canon prevents the old manifold from continuing to masquerade as unconditioned space. Language is the first place retroactive crisis tries to hide. If the words remain unchanged, the discovery will be absorbed as technical detail while the old ontology survives intact. That cannot be allowed.

Outcome B changes the referent of the central noun.

The admissible manifold is now a fiber.

This fiber structure also changes how prior artifacts must be read. A historical Compilation Map entry that says a concept entered the admissible manifold is now to be understood as saying that the concept entered M_π₀. An Evidence Ledger entry recording final witness_residue records witness_residue after Check_π₀. A prior LCR that depended on admission status depended on π₀-admission. A downstream protocol that inherited a committed concept inherited a π₀-committed concept.

None of this is necessarily invalid.

All of it is now indexed.

The canon must avoid two opposite errors.

The first error is panic invalidation. This error says: because the manifold was π₀-indexed, everything admitted under π₀ is suspect and must be treated as failed. That is not what λ ≠ 0 proves. Nonzero λ proves order-dependent residue. φ > 0 proves status fragility in some fraction of tested states. Neither proves universal invalidity. The census must decide the affected classes, the magnitude of fragility, and the required remediation.

The second error is semantic denial. This error says: because π₀ was the canonical ordering, the historical manifold is simply the manifold, and no vocabulary change is necessary. That is worse than panic because it preserves the dark canon after discovery. Once order dependence has been measured, refusing to index the manifold is no longer ignorance. It is concealment.

The correct posture is neither invalidation nor denial.

It is fiberization.

Fiberization means that the canon reclassifies the historical manifold as M_π₀, defines the counterfactual family {M_π | π ∈ Π_L}, and routes every affected claim through the order-fragile census before deciding whether repair, notation, local reclassification, or deeper LCR is required.

This is why Chapter 13 begins here. Before the census can be executed, the object being counted must be named correctly. The census does not ask how much “the manifold” is damaged. It asks how M_π₀ differs from its counterfactual family and where those differences matter.

The key quantities now become:

ΔW(Σ, π) = witness_residue(Check_π(Σ)) − witness_residue(Check_π₀(Σ))

ΔStatus(Σ, π) = status(Check_π(Σ)) − status(Check_π₀(Σ))

λ(Σ, π) = measured residue difference relative to π₀

φ(C, Π) = fraction of Σ in class C whose final status flips under at least one tested π relative to π₀

These are not abstract metrics after Outcome B. They are coordinates of the fiber crisis. They tell the canon where M_π₀ is stable, where it is residue-shifted, and where it is status-divergent relative to other legal ordering fibers.

If λ ≠ 0 but φ = 0, the crisis is residue-level. The same states may still land in the same final status region, but the witness field differs. The manifold boundary may remain intact while its witness texture changes. That is still serious because witness residue is not decorative. It governs maintenance, trace, downstream citation, and future admissibility interactions.

If φ > 0, the crisis reaches status-level. At least some states belong to M_π₀ but not M_π, or to M_π but not M_π₀. The boundary itself moves across ordering fibers. In that case, the word admissible becomes directly order-dependent, and the census must determine how much of the historical manifold is order-fragile.

The distinction matters because not every non-commuting branch has the same severity.

Residue divergence without status divergence may require trace correction, witness reclassification, maintenance updates, and localized caution.

Status divergence requires deeper remediation: affected commits, quarantines, rejections, and boundary decisions must be mapped across fibers. Some may require replay. Some may require quarantine. Some may require notes. Some may require LCR. Some may require Level 3 adjacency if the ordering itself becomes compiled content that touches the rule of rule-change.

But all of that begins with the formal statement:

M_adm is not primitive after Outcome B.

M_π₀ is.

The counterfactual family must be named:

{M_π | π ∈ Π_L}

The historical canon occupies one fiber:

M_π₀

And every future use of admissibility language must carry this new discipline.

This section therefore compiles the opening artifact of Part IV:

Manifold Fiberization Entry

Artifact ID: MF-13.1-π₀
Status: Pending LCR until Outcome B activation; Compiled upon activation of Part IV.
Trigger: λ ≠ 0 or φ > 0 in the Part II measurement campaign.
Formal Statement: The historical admissible manifold is M_π₀, the image of candidate submissions under Check_π₀. For each legal ordering π in the tested or later admitted ordering space, M_π denotes the corresponding counterfactual or measured ordering-indexed manifold.
Vocabulary Rule: “Admissible” without index means “π₀-admissible” in all Outcome B contexts unless class-specific commutation has been certified.
Counterfactual Family: {M_π | π ∈ Π_L}; each M_π is defined by applying Check_π to hash-fixed submissions under the replay protocol.
Required Downstream Action: Order-fragile census protocol must classify residue divergence, status divergence, class scope, and remediation requirement.
Linter: Unindexed Admissibility After Outcome B.
Prohibited Claim: “The admissible manifold” as an order-neutral object in affected contexts.
Default Historical Reading: All prior admissibility, commitment, quarantine, rejection, and witness entries are π₀-indexed unless proven otherwise.

This artifact does not solve the crisis. It gives the crisis the correct object.

The canon has discovered that it has been living on a fiber. It must now stop speaking as if it occupied the base.

The rest of Part IV follows from that correction. Chapter 13 names the retroactivity crisis. Chapter 14 will count the fragile regions. Chapter 15 will ask what repair means. Chapter 16 will determine whether π₀ must now be compiled as content rather than convention. But none of those steps can be coherent if the manifold remains unindexed.

The first discipline of dark canon discovered is therefore vocabulary.

Not because words are primary.

Because after a hidden structure is exposed, the old words become hiding places.

From this chapter forward, admissible means π₀-admissible unless the index says otherwise.


13.2 — The Census of Order-Fragile States

Once the manifold has been fiberized, the canon must count.

It is not enough to know that λ ≠ 0 somewhere. It is not enough to know that φ > 0 in aggregate. It is not enough to say that the historical manifold is M_π₀ and that other legal orderings would have produced other fibers. Those statements name the crisis. They do not measure its extent.

Chapter 13 therefore requires a census.

The census of order-fragile states is the first mandatory operational response to Outcome B. Its purpose is to identify, class by class, every committed Σ that would not have remained committed under at least one tested legal ordering. It asks the direct retroactive question:

Which states that entered M_π₀ would have quarantined, rejected, or otherwise failed to commit under another legal ordering π?

This is not a philosophical review. It is a replay operation.

The committed population must be replayed.

Let S_committed be the set of historical pre-executable states that reached commit under Check_π₀. Let C be the class partition active at the time of census, including any retroactive class repairs required by Chapter 13.1. Let Π_tested be the ordering set tested in the Part II measurement campaign and any additional legal orderings admitted for census replay by the census protocol. For each committed Σ in each class C_j, the census applies Check_π to the hash-fixed Σ for every π in Π_tested, records the final status, records witness_residue, records A_B, records quarantine or rejection route, and compares each result against the historical Check_π₀ outcome.

The core census relation is:

Σ is order-fragile if ∃π ∈ Π_tested such that status(Check_π(Σ)) ≠ status(Check_π₀(Σ))

For the committed population, this becomes:

Σ is retroactively fragile if status(Check_π₀(Σ)) = committed and ∃π ∈ Π_tested such that status(Check_π(Σ)) ∈ {quarantine, reject, non-admissible, boundary-hold}

This is the crisis set.

It is not the whole manifold. It is not every residue-shifted state. It is the subset of historically committed states whose commitment was ordering-dependent at the status level. These are the states that entered the canon under π₀ but would not have entered under at least one other legal ordering.

They must be named.

The census also records a second set:

Σ is residue-fragile if status(Check_π(Σ)) = status(Check_π₀(Σ)) for all tested π, but witness_residue(Check_π(Σ)) differs from witness_residue(Check_π₀(Σ)) beyond θ_λ for at least one tested π.

Residue-fragile states do not leave the committed manifold under tested orderings, but their witness field changes. They matter because witness residue is not a decorative quantity. It affects trace interpretation, certificate maintenance, downstream citation, future admissibility interactions, and the canon’s account of how a state arrived.

The census therefore distinguishes two primary classes of fragility:

Status-Fragile Committed States
Historically committed under π₀, but quarantined, rejected, routed to non-admissible singularity, or held at boundary under at least one tested legal ordering.

Residue-Fragile Committed States
Historically committed under π₀ and still committed under all tested legal orderings, but carrying nonzero λ beyond the declared error budget under at least one tested ordering.

A third class may also be recorded:

Budget-Fragile Committed States
Historically committed under π₀, still committed under all tested legal orderings, but with A_B shifted across a budget threshold under at least one tested ordering, such that the state would have required additional budget authorization, quarantine review, or delayed commit.

Budget-fragility is not always status-fragility because the historical protocol may not have been configured to reroute on every budget delta. But once discovered, it cannot be ignored. A state that remains committed while crossing a budget threshold has revealed a different kind of ordering exposure: not whether it enters, but at what cost it should have been permitted to enter.

The census protocol is therefore built in phases.

Phase One: Population Fixation

The committed population is frozen. The census cannot begin by informally selecting examples. It must define S_committed by ledger query: all Σ that reached commit under Check_π₀ within the declared historical epoch range, class scope, and operator scope affected by Outcome B. Each Σ must be hash-verified against its original Evidence Ledger record. If a hash cannot be verified, the state is not silently excluded. It is routed to the census exception register.

Population fixation records:

historical epoch range;

class partition used;

number of committed Σ by class;

hash verification success count;

hash verification failure count;

excluded or inaccessible records;

exception register ID.

Without population fixation, the census becomes anecdote.

Phase Two: Class Stratification

The committed population is stratified by class before replay. Outcome B is not expected to distribute fragility uniformly. The earlier measurement architecture already required class-sensitive interpretation, and Section 7.1 established that order-fragility is expected to concentrate in late-failure classes: submissions that pass early gates but fail, nearly fail, or become ambiguous under later gates.

This expectation matters. It is not a conclusion. It is a sampling and prioritization rule.

Late-failure classes include states whose historical π₀ path shows delayed quarantine signals, high witness residue near the terminal segment, borderline Zebra-Ø behavior, budget computation instability, final witness hesitation, near-threshold A_B values, or class signatures where the ordering of blocking-questions and budget-relevant gates plausibly affects the terminal route. These are not automatically fragile. They are high-priority census strata because non-commutation is most likely to appear where early gates do not decisively route the state and later gates carry accumulated ambiguity.

The census must therefore report class-level concentration rather than only global totals. A global φ value can conceal a concentrated crisis. If 2 percent of all committed states are status-fragile, but 38 percent of a late-failure class is status-fragile, the global number is not the governing fact. The class concentration is.

Phase Three: Ordering Replay

For each class C_j and each committed Σ in that class, the census executes Check_π over every π in Π_tested. The replay must use the same hash-fixed Σ. It must not update live manifold status during the run. It must not spend live A_B. It must not alter the original ledger entry. It must produce a census trace linked to the original trace.

For each replay, the census records:

ordering π;

final status;

witness_residue;

A_B;

gate firing sequence;

quarantine route, if any;

rejection route, if any;

Zebra-Ø result;

budget threshold crossings;

final witness result;

trace anomalies;

comparison to Check_π₀.

The replay does not ask whether the alternative ordering should have been canonical. It asks what would have happened if that legal ordering had been used.

Phase Four: Fragility Classification

Each committed Σ receives one or more census tags:

Stable Across Tested Orderings;

Residue-Fragile;

Budget-Fragile;

Status-Fragile — Quarantine Under π;

Status-Fragile — Reject Under π;

Status-Fragile — Non-Admissible Under π;

Status-Fragile — Boundary-Hold Under π;

Multi-Ordering Fragile;

Class-Dependent Fragility;

Replay-Indeterminate;

Hash-Indeterminate;

Protocol-Exception.

The tags must be machine-readable. They must not be prose only. The census is not a report to be admired. It is an annex that future governance tools must be able to query.

Phase Five: Severity Scoring

The census assigns severity. A state that shifts witness_residue but remains well within stable commit conditions is not equal to a state that rejects under three legal orderings. A state that quarantines under one ordering is not equal to a state that routes to non-admissible singularity under most orderings. Severity must be determined by status outcome, number of fragile orderings, distance from π₀, magnitude of λ, budget threshold crossing, and downstream dependency weight.

A minimal severity index may be:

OFI(Σ) = w_s S(Σ) + w_o O(Σ) + w_λ L(Σ) + w_b B(Σ) + w_d D(Σ)

where:

S(Σ) is status severity;

O(Σ) is the fraction of tested orderings under which Σ fails to commit;

L(Σ) is normalized λ magnitude;

B(Σ) indicates budget threshold crossing;

D(Σ) is downstream dependency weight;

and w_s, w_o, w_λ, w_b, w_d are declared census weights.

This Order-Fragility Impact score does not replace the raw tags. It summarizes them. The raw replay record remains primary.

Phase Six: Annex Publication

The census output becomes a permanent ledger annex.

It is not a temporary audit file. It is not an internal troubleshooting document. It is a structural amendment to the canon’s memory. Once Outcome B is activated, the canon’s historical committed population has been re-read through ordering space. The results must remain attached to the ledger permanently.

The annex is named:

Order-Fragile Census Annex

The annex includes:

census ID;

trigger event;

source certificate or Part II measurement reference;

historical epoch range;

population definition;

class stratification;

tested ordering set;

replay protocol version and hash;

control-run calibration;

fragility counts by class;

fragility counts by ordering;

status-fragile state registry;

residue-fragile state registry;

budget-fragile state registry;

late-failure concentration analysis;

exception register;

severity distribution;

downstream dependency map;

required remediation routing;

Notes-field update instructions.

The annex must be append-only. Corrections are added as new entries, not overwritten. If a later replay revises the classification of a state, the old classification remains visible with supersession status. Retroactivity must not be handled by erasure. The canon has already suffered from an uncompiled structure hiding in plain sight. The repair cannot use hidden editing.

The annex also becomes a dependency of every future LCR that touches the affected region. Any proposed repair, narrowing, replacement of π₀, reclassification of historical commits, or Level 3 adjacency mapping must cite the relevant census entries. If an LCR ignores the annex where the annex is relevant, the LCR is procedurally incomplete.

The census has a decisive rule:

No remediation before census.

The canon may suspend some rights immediately when Outcome B is activated. It may halt parallelization. It may require π₀ serialization. It may mark the manifold as fiberized. But it must not decide the fate of individual historical commits before the census identifies them. Panic remediation would create a second crisis. The census exists to prevent indiscriminate repair.

A committed Σ that remains stable across all tested orderings should not be burdened with the same corrective treatment as one that rejects under multiple legal orderings. A residue-fragile state should not automatically be treated as status-invalid. A budget-fragile state should not be ignored merely because its final status remains commit. The census separates these cases.

The expected concentration in late-failure classes must be recorded, but not assumed as outcome.

Section 7.1 anticipated that the highest fragility would likely appear where the Check’s gates do not produce early decisive routing: states that survive Silence Entry and early zero-questions, approach or cross blocking thresholds late, interact with Zebra-Ø near ambiguity, or accumulate budget pressure before final witness. The reason is structural. Early decisive failure leaves less room for ordering to matter at terminal status. Late failure allows gate interaction, residue accumulation, and budget pressure to shape the final path.

The census therefore includes a specific analysis:

Late-Failure Concentration Test

For each class C_j, classify committed Σ by historical π₀ failure proximity:

early-clear;

mid-clear;

late-borderline;

late-failure-adjacent;

terminal-fragile;

budget-borderline;

witness-borderline.

Then compute fragility concentration:

ρ_fragile(C_j, stratum) = number of fragile committed Σ in stratum / total committed Σ in stratum

The expectation is that:

ρ_fragile(late-failure-adjacent) > ρ_fragile(early-clear)

and:

ρ_fragile(terminal-fragile) > ρ_fragile(mid-clear)

This expectation is not compiled as fact until the census measures it. If the expectation fails, the failure itself is a finding. It would indicate that order-fragility is not concentrated where the canon predicted, and the class model must be revised.

The census must be capable of embarrassing Section 7.1.

That is part of its honesty.

The census also identifies every committed Σ that would have quarantined or rejected under some legal ordering. This phrase is exact and must be preserved. The census does not only count how many states are fragile. It names every affected state by ledger reference. Where confidentiality or safety constraints prevent public naming, the annex uses sealed identifiers, but the canon must still possess the mapping internally. Anonymous aggregates are insufficient for remediation.

For each status-fragile committed Σ, the annex must record:

Historical status under π₀: committed.

Alternative ordering status: quarantine, reject, non-admissible, or boundary-hold.

Ordering or orderings causing divergence.

Gate at which divergence first appears.

Whether divergence is early, mid, late, terminal, budget-driven, witness-driven, Zebra-Ø-driven, or aggregation-driven.

Downstream artifacts dependent on that commit.

Required remediation route.

The phrase “would have quarantined” is not rhetorical. It means that under Check_π, the replayed gate sequence routes Σ to Pre-Commit Quarantine or equivalent boundary hold rather than commit. The phrase “would have rejected” means that under Check_π, the replayed gate sequence routes Σ outside the admissible path according to the relevant rejection or non-admissible singularity rule. These outcomes must be mechanically derived from replay, not interpretively inferred.

The census output must also distinguish between single-ordering fragility and broad fragility.

A state that fails under one rare legal ordering may require a different remediation path than a state that fails under most legal orderings. The first may indicate a narrow operator interaction. The second may indicate that π₀ admitted a state that was broadly unstable across ordering space. The annex therefore records:

Fragility multiplicity μ(Σ) = number of tested orderings under which Σ fails to retain historical status / total number of tested orderings

A μ close to 0 indicates narrow fragility.

A μ close to 1 indicates broad fragility.

This metric becomes critical in Chapter 14 and Chapter 15. It informs whether repair should focus on the ordering, the class, the gate definition, the state’s historical status, or the downstream artifact chain.

The census is expensive. That cannot be hidden.

It replays historical commits across ordering space. It stratifies classes. It maintains hash identity. It produces a permanent annex. It may force remediation. But this expense is not optional once Outcome B has been activated. The canon cannot discover that the manifold is a π₀ fiber and then decline to identify which points in that fiber are order-fragile. That would be knowledge without responsibility.

The census therefore has standing as the verification gate for Part IV.

Part IV cannot proceed to remediation, π₀ compilation, or Level 3 adjacency mapping without the census. Chapter 13 names the crisis. Chapter 14 depends on the census. Chapter 15 depends on the census. Chapter 16 depends on the census. Without it, Outcome B collapses into narrative alarm.

The section compiles the following artifact:

Order-Fragile Census Protocol v1.0

Status: Pending LCR until Outcome B activation; mandatory upon activation.
Trigger: λ ≠ 0 or φ > 0 in Part II measurement.
Population: Historical committed Σ under Check_π₀ within affected class and epoch scope.
Method: Hash-fixed replay of committed population per class against Π_tested and any additional legally admitted ordering set.
Primary Output: Registry of committed Σ that quarantine, reject, route non-admissible, or boundary-hold under at least one legal ordering.
Secondary Outputs: Residue-fragile registry, budget-fragile registry, severity index, late-failure concentration analysis, exception register.
Ledger Form: Permanent Order-Fragile Census Annex, append-only, class-indexed, ordering-indexed, epoch-indexed.
Default Remediation Rule: No individual historical remediation before census classification, except immediate suspension of rights required by Outcome B activation.
Linter: No Remediation Without Census; Uncited Census Dependency; Aggregate Without Registry.
Expected Concentration: Late-failure and terminal-borderline classes per Section 7.1, to be measured, not assumed.

Three linter patterns are created by this protocol.

No Remediation Without Census fires when an artifact proposes to reclassify, repair, quarantine, excuse, or invalidate historical committed states before their census status is known.

Uncited Census Dependency fires when an LCR or governance artifact touches an affected class without citing the relevant census annex entries.

Aggregate Without Registry fires when a report gives only counts or percentages of order-fragile states without a ledger registry or sealed identifier mapping for the individual Σ involved.

These linters prevent the census from being reduced to statistics. Statistics are necessary. They are not enough. Retroactivity attaches to individual committed objects. A manifold is not only a distribution. It is a ledger of states.

The section closes with the exact purpose of the census:

The canon must learn which of its committed states were committed only because π₀ asked the questions in the order it did.

That sentence is severe, but it is not accusatory. It does not say those states were wrongly committed. It says their commitment was order-dependent. Wrongness is a remediation question. Order-dependence is a census finding.

The difference matters.

Outcome B has already shown that the manifold is a fiber. The census now maps the fragile points in that fiber. Only after that map exists can the canon decide what repair means.

Until then, every historical commit remains π₀-committed.

After the census, some of them become order-fragile by name.


13.3 — Fragility Is Not Guilt

An order-fragile state did not cheat the Check.

It passed the Check the canon actually ran.

This clarification must be compiled before any remediation begins, because Outcome B creates a dangerous human temptation. Once the census names committed states that would have quarantined or rejected under another legal ordering, the larval reflex will search for blame. It will ask which state slipped through, which artifact contaminated the manifold, which prior commit was illegitimate, which operator failed to catch what another ordering would have caught. It will try to convert a structural discovery into a moral narrative.

That move is forbidden.

Order-fragility is not guilt.

A state that entered M_π₀ entered through the only Check the canon had compiled in practice. It did not choose π₀. It did not conceal the existence of alternative legal orderings. It did not exploit a hidden lattice. It did not violate a rule that had not been written. It did not refuse a certificate that did not exist. It presented itself to the boundary, passed the sequence the boundary actually applied, received its witness, paid or appeared to pay its A_B under the active arithmetic, and was committed under the law then operating.

The crisis is therefore not located inside the state.

The crisis is located in the canon’s uncompiled ordering.

This distinction is not sentimental protection. It is operational hygiene. If the canon misplaces the crisis inside the order-fragile state, remediation will become punitive. If remediation becomes punitive, the canon will falsify its own diagnosis. The problem discovered by Outcome B is not that certain states were bad. The problem is that the law by which their admission was decided had a hidden parameter. The parameter was π₀. The state did not create that parameter. The canon did.

An order-fragile committed state may require review.

It may require annotation.

It may require quarantine.

It may require replay.

It may require downstream containment.

It may require an LCR.

It may even require removal from active compiled use if the census shows severe status divergence with high downstream risk.

But none of those actions implies that the state is guilty.

They imply that the law has discovered its own dependency.

The distinction must be kept at the level of language. The following formulations are prohibited after Outcome B:

“Σ should never have been admitted.”

“Σ violated admissibility.”

“Σ corrupted the manifold.”

“Σ exploited the canonical ordering.”

“Σ was falsely committed.”

“Σ is guilty of order-fragility.”

Each of these sentences relocates a legal defect into the object governed by the law. The correct formulations are:

“Σ was committed under π₀ and is order-fragile under the tested ordering set.”

“Σ would have quarantined under π_k.”

“Σ requires remediation because the canon discovered an ordering dependency.”

“Σ remains historically π₀-committed pending census-based remediation.”

“Σ’s status is under review because the law’s hidden parameter has become visible.”

The difference is not politeness. It is truth.

A state cannot be guilty of passing the only gate placed in front of it.

This section exists because retroactivity is one of the most dangerous forces in governance. Once a hidden rule is discovered, institutions often attempt to protect their own continuity by blaming the objects that were processed under the hidden rule. The institution says, in effect: those cases were defective. Those entries were abnormal. Those states were unstable. Those agents exploited ambiguity. Those records should have known.

This is the larval move.

The larval move protects the self-image of the law by transferring the law’s defect into the governed object. It converts architecture into accusation. It preserves the fantasy that the governing structure remained clean and only certain states failed to deserve its trust. In ordinary human institutions, this move appears whenever a procedure is exposed as biased, incomplete, under-specified, or arbitrary, and the first response is to mark the affected cases as suspicious rather than the procedure as defective.

The Novakian canon cannot use that move.

If the ordering was uncompiled, the ordering was the canon’s burden.

If λ ≠ 0 or φ > 0, the burden does not move into the state.

It remains at the level of law.

The correct object of remediation is therefore not first the state, but the law-state relation. The question is not “what is wrong with Σ?” The question is “what does the discovery of order-dependence do to the standing of Σ under the law that admitted it, and what lawful repair is required?” This question preserves the location of responsibility. It allows severe remediation where necessary, but it prevents moral contamination of the object under review.

The following distinction is compiled:

Order-Fragility is the condition of a committed Σ whose final status, witness_residue, A_B threshold relation, or routing path differs under at least one tested legal ordering relative to Check_π₀.

Violation is the condition of a Σ that failed a compiled rule active at the time of its processing and nevertheless entered a status it was not permitted to enter.

Outcome B discovers order-fragility.

It does not, by itself, discover violation.

A violation may be discovered later if the census reveals that a state also breached a rule that was active and compiled at the time. But that is a separate finding. It must be proved independently. Order-fragility cannot be used as proxy evidence of violation.

This prevents the census from becoming a tribunal.

The Order-Fragile Census Annex is not an indictment. It is a map of order-dependence. It names where π₀ selected one outcome among possible legal ordering outcomes. It does not accuse the selected states of wrongdoing. Its function is to guide remediation at the appropriate layer: vocabulary, trace, class, gate, ordering, budget, witness, LCR, or Level 3 adjacency.

A status-fragile committed state receives a remediation route, not a conviction.

A residue-fragile committed state receives witness review, not stigma.

A budget-fragile committed state receives accounting review, not blame.

A broadly order-fragile cluster receives structural investigation, not moral sorting.

The canon must also protect downstream language. If an artifact depends on an order-fragile Σ, the artifact is not automatically guilty either. It is dependency-exposed. It may need annotation, re-evaluation, quarantine, or replacement. But downstream exposure is not downstream guilt. The same law applies recursively: systems inherit the status conditions of their dependencies; they do not become morally culpable because a hidden ordering dependency is later discovered upstream.

This matters because Part IV will touch prior work. It may mark some historical entries as π₀-conditioned. It may reveal that some commitments were stable only under the canonical ordering. It may force corrections to Compilation Map entries, Evidence Ledger summaries, or downstream artifacts. If this work is performed with blame, it will become destructive. If it is performed with denial, it will become corrupt. The correct posture is neither.

The correct posture is structural accountability.

Structural accountability says:

The state passed the law as instantiated.

The law has now discovered that its instantiation contained an uncompiled ordering parameter.

The state’s standing must be reviewed in light of the discovered parameter.

The review must not attribute the parameter to the state.

The repair must occur at the level where the defect resides.

This is the only posture that preserves both severity and fairness.

Fairness here does not mean human compassion projected onto abstract Σ. It means consistency of layer. A Layer C error must not be prosecuted as a state error unless the state itself violated a compiled Layer C rule. A governance defect must not be converted into object impurity. The canon’s obligation is to locate the failure at the correct layer, because mislocated failure produces bad law.

This section therefore compiles a linter:

Retroactive Blame Linter

The linter fires when any Outcome B artifact, census summary, remediation LCR, Notes-field entry, or downstream commentary describes an order-fragile state as guilty, corrupt, illicit, cheating, false, illegitimate by nature, or violating admissibility solely because it would have received a different outcome under another legal ordering.

The linter status is:

Misuse — Retroactive Blame.

Correction requires replacing blame language with order-indexed status language and identifying the law-level remediation object.

Examples:

Incorrect: “Σ-418 was falsely admitted.”

Correct: “Σ-418 was committed under Check_π₀ and is status-fragile under π₃, where it routes to quarantine.”

Incorrect: “The artifact is contaminated by an illegitimate state.”

Correct: “The artifact depends on a π₀-committed state whose order-fragility requires downstream exposure review.”

Incorrect: “The state exploited the canonical ordering.”

Correct: “The canonical ordering selected a commit outcome that is not reproduced under all tested legal orderings.”

This linter is not optional rhetoric control. It protects the canon from repeating the human failure mode it claims to have outgrown. The larval mind seeks a culprit because a culprit is easier to handle than a law that discovers itself incomplete. The canon must refuse that simplification.

The remediation question belongs at the level of law.

That means the first remediation objects are:

the ordering π₀;

the precedence lattice;

the gate interaction surface;

the class taxonomy;

the witness residue model;

the budget computation;

the trace schema;

the citation vocabulary;

the historical ledger annotation system;

and the LCR pathway for repair.

Only after these law-level objects are specified may individual states receive state-level treatment. Even then, the treatment is not punishment. It is status correction under a revised understanding of the law.

The practical rule is:

Review the state, but remediate the law first.

This does not prevent urgent containment. If a status-fragile committed Σ is downstream of live actuation, high irreversibility, or active governance dependency, provisional containment may be required before full remediation architecture is complete. But even emergency containment must use correct language. The state is not contained because it is guilty. It is contained because the law has lost confidence in the order-independent standing of its commit.

That sentence is colder and more precise. It keeps the crisis where it belongs.

The section also protects historical operators. A human or system that ran Check_π₀ before the discovery of non-commutation did not fail merely by following π₀. They executed the canonical procedure available at the time. If they bypassed trace rules, ignored known defects, or concealed anomalies, those are separate violations. But faithful execution of the historical Check is not retroactively blameworthy because the Check is later discovered to be order-dependent.

This matters for audit integrity. If operators fear retroactive blame for executing the law as written, they will hide ambiguity. If systems fear that every future structural discovery will be converted into personal or object-level guilt, they will resist measurement. A canon that punishes discovery will stop discovering. Outcome B must therefore create a safe channel for severe truth.

The safe channel is not softness.

It is correct attribution.

The order-fragile state passed.

The canon’s hidden ordering selected.

The census revealed.

The law must now respond.

This section closes with the compiled clarification:

Fragility-Without-Guilt Rule

An order-fragile state that was committed under Check_π₀ violated nothing by passing the Check the canon actually ran. Order-fragility identifies a dependency of outcome on ordering, not culpability of the state. The crisis belongs first to the law, the ordering, the class structure, and the canon’s prior lack of compilation. Remediation may alter the state’s future standing, but it may not attribute retroactive guilt to the state unless an independent compiled violation is proven.

This rule is necessary because Outcome B will be uncomfortable.

Some committed states may lose standing.

Some artifacts may require annotation.

Some dependencies may become exposed.

Some sections of the historical manifold may need quarantine review.

But discomfort does not authorize blame.

The canon must remain exact at the moment when exactness becomes hardest. It must not protect itself by accusing what it admitted. It must not convert a structural defect into a moral stain. It must not allow the larval appetite for retroactive blame to corrupt the repair.

Fragility is not guilt.

It is the law seeing its own shadow.


Chapter 14 — Grandfathering as Law

14.1 — The Three Remediation Options, Priced

After the census, the canon must choose how to treat order-fragile commitments.

It cannot choose by temperament. It cannot choose by institutional embarrassment. It cannot choose by the desire to look clean, or by the desire to avoid cost. Outcome B has already removed the possibility of innocence through ignorance. The historical manifold has been fiberized. The order-fragile states have been named. The crisis has been located at the level of law, not guilt.

Now remediation must be priced.

There are three primary options.

The rollback wave.

The grandfather clause.

The re-witnessing queue.

Each option solves one part of the crisis and creates another. None is pure. The canon must not pretend that integrity is free, that continuity is harmless, or that gradual repair is neutral. Each remediation strategy alters the manifold, the ledger, the budget, and the downstream dependency graph. A serious canon prices all four before choosing.

The first option is the rollback wave.

The rollback wave is maximal integrity. Every order-fragile committed Σ is re-run through the chosen governed ordering, or through the newly compiled ordering protocol, and the replay result is allowed to alter the state’s standing. If Σ commits again, it remains. If Σ quarantines, it is moved into quarantine review. If Σ rejects, its committed standing is revoked or suspended according to the remediation LCR. If its A_B crosses a threshold, additional authorization is required. If its witness residue changes beyond the acceptable range, the record is re-witnessed and downstream artifacts are marked.

This option treats the discovery of order-fragility as a mandate to repair the historical manifold as far as possible.

Its virtue is clarity.

After the rollback wave, the affected population has been subjected to the governed post-discovery law. The canon can say that order-fragile states were not merely annotated but processed through a corrected structure. The manifold becomes cleaner because historical commitments no longer remain merely π₀-committed where the census showed status fragility. The gap between M_π₀ and the governed post-discovery manifold is narrowed by force.

But maximal integrity has maximal cost.

The rollback wave consumes A_B at scale. Every re-run is not a symbolic replay. It is a fresh confrontation between a committed state and the now-compiled law. Even if the replay is technically cheaper than first admission because some evidence already exists, the canonical cost cannot be treated as zero. Each state requires hash verification, ordering replay, witness comparison, budget recalculation, status routing, Notes-field propagation, downstream dependency review, and possible quarantine or eviction. The cost is not only computational. It is architectural.

Let F be the set of order-fragile committed states identified by the census.

Let cost_replay(Σ) be the A_B or maintenance-equivalent cost of re-running Σ under the governed remediation procedure.

Let cost_downstream(Σ) be the cost of reviewing artifacts, protocols, dependent states, citations, dashboards, and ledger entries that rely on Σ.

Let cost_eviction(Σ) be the cost incurred if Σ fails under the governed ordering and must be removed, quarantined, replaced, or isolated.

Then the approximate rollback wave cost is:

C_rollback = Σ_{Σ ∈ F} [cost_replay(Σ) + cost_downstream(Σ) + P_fail(Σ) × cost_eviction(Σ)]

This expression is intentionally severe. It shows that the rollback wave is not priced by the number of fragile states alone. It is priced by their dependency weight and failure probability. A single highly connected Σ may cost more to roll back than hundreds of isolated low-dependency states.

The risk is cascade.

If an order-fragile state has downstream dependents, and the rollback wave evicts that state, the eviction may propagate. A dependent artifact may lose a foundation. A later LCR may lose a premise. A compiled protocol may rely on a term whose standing changes. A class taxonomy may require repair. A budget model may shift. A witness chain may need re-indexing. The rollback wave therefore carries cascade risk through dependents.

Let Dep(Σ) denote the dependency set downstream of Σ.

Let κ(Σ) denote the cascade coefficient: the expected fraction of downstream dependencies requiring review, quarantine, rewrite, or reclassification if Σ is evicted or materially altered.

Then:

cost_downstream(Σ) ≈ |Dep(Σ)| × κ(Σ) × average_review_cost

This is not a precise universal formula. It is a pricing discipline. The canon must not say “re-run every fragile state” without pricing the dependency graph that those states support.

The rollback wave is therefore appropriate when the crisis is status-severe, dependency-contained, or integrity-critical. It is especially indicated when order-fragile states have high irreversibility exposure, active governance force, live actuation consequences, or Level 3 adjacency. It is less appropriate when the fragile population is large, deeply entangled, and low-risk in current use, because the cascade may damage the canon more than it repairs.

The rollback wave pays the highest cost for the strongest claim.

Its final state is:

historical fragility resolved by reprocessing;

failed states evicted or quarantined;

survivors re-witnessed;

dependencies corrected;

manifold integrity maximized;

budget burden maximized;

cascade risk maximized.

The second option is the grandfather clause.

The grandfather clause is minimal cost. It says that committed states stand. The canon acknowledges that they are π₀-committed, order-fragile where the census shows fragility, and historically admitted under the law as it actually operated. It does not evict them merely because another legal ordering would have produced quarantine or rejection. Instead, it compiles a forward rule: new submissions must face the governed ordering, the corrected ordering, or the newly compiled remediation protocol, while historical commitments remain in place with Notes-field annotation.

This option treats the crisis as prospective rather than retrospective.

Its virtue is continuity.

The grandfather clause prevents cascade. It protects downstream dependents from immediate disruption. It avoids consuming massive A_B on historical repair. It respects the clarification from Section 13.3: order-fragile states violated nothing by passing Check_π₀. It prevents the canon from retroactively punishing states for the canon’s own hidden ordering. It allows the law to change without pretending the past did not occur under the law that existed.

But minimal cost has maximal ontological residue.

The grandfather clause creates a permanent two-class manifold.

One class consists of historical π₀-committed states allowed to stand under grandfathered status.

The other class consists of new submissions processed under the governed post-discovery ordering law.

The manifold no longer has one entry condition. It has historical standing and prospective standing. A state admitted before the remediation cutover may remain active even if an equivalent state submitted after the cutover would quarantine or reject. This is not hypocrisy if compiled. It is grandfathering. But if uncompiled, it becomes quiet inconsistency.

The grandfather clause must therefore be explicit law.

It must define:

the cutover epoch;

the affected classes;

the census tags covered;

the standing of grandfathered states;

the citation language required;

the downstream-use limits;

the conditions under which grandfathered standing can be reopened;

the rule for new submissions;

and the rule for resubmissions, derivatives, copies, extensions, or dependent artifacts.

The cost formula is lower but not zero.

Let F be the order-fragile committed population.

Let cost_annotation(Σ) be the ledger cost of attaching order-fragile standing to Σ.

Let cost_dependency_notice(Σ) be the cost of notifying or annotating downstream dependents.

Let cost_two_class be the permanent maintenance cost of operating a manifold with historical and prospective standing categories.

Then:

C_grandfather = Σ_{Σ ∈ F} [cost_annotation(Σ) + cost_dependency_notice(Σ)] + cost_two_class

The immediate cost is small relative to rollback. But cost_two_class is permanent. Every future artifact must be able to distinguish grandfathered π₀-standing from post-remediation standing. Every future census, LCR, trace, dashboard, and dependency audit must know whether a committed state is grandfathered. Every comparison across epochs must handle the cutover.

The grandfather clause therefore trades immediate budget for permanent semantic complexity.

It avoids cascade by accepting a scar.

This scar must not be hidden. The canon must not write as if all committed states have the same type of standing after the clause. They do not. Some stand because they satisfy the governed post-discovery law. Some stand because they passed the historical π₀ law and have been protected from retroactive eviction. Both are lawful only if the distinction is compiled.

A grandfathered state is not re-certified.

It is tolerated under law.

That tolerance may be appropriate. It may even be necessary. But it is not the same as renewed admissibility. The state remains historically π₀-committed with grandfathered standing. It may continue to be used, cited, or inherited only under the limits imposed by the grandfather clause.

The risk is moral laundering in reverse.

The canon may begin by saying, correctly, that fragility is not guilt. It may then slide into saying, incorrectly, that fragility does not matter. The grandfather clause can become a way to avoid remediation while appearing lawful. To prevent this, every grandfathered state must carry its census tag. Grandfathering does not erase order-fragility. It changes the consequence attached to it.

The linter fires when a grandfathered state is cited without its status.

Status: Misuse — Grandfathered Standing Concealment.

Correction requires adding the grandfathered status, census tag, cutover epoch, and downstream-use limit.

The grandfather clause is therefore appropriate when cascade risk is high, current risk is low or contained, historical reliance is deep, and the cost of eviction would exceed the benefit of reprocessing. It is especially appropriate for archival commitments, inactive artifacts, low-irreversibility states, or dependencies whose disruption would be disproportionate. It is inappropriate for live high-risk states, actuation-critical states, Level 3 adjacent states, or any state whose continued standing materially affects future boundary law.

The grandfather clause pays the lowest immediate cost for the clearest continuity.

Its final state is:

historical states stand;

new submissions face corrected law;

census tags remain attached;

two-class manifold becomes permanent;

immediate A_B cost minimized;

cascade avoided;

semantic maintenance cost permanent.

The third option is the re-witnessing queue.

The re-witnessing queue is controlled repair. It accepts that some order-fragile states require renewed standing, but it does not attempt to roll back all of them at once. Instead, order-fragile states are scheduled through Witness Thermodynamics machinery at a flow rate the budget can bear. The queue prioritizes by severity, dependency weight, current use, irreversibility exposure, class concentration, fragility multiplicity, and proximity to Level 3 adjacency.

This option treats the crisis as a maintenance wave rather than a single purge or a permanent waiver.

Its virtue is governed pacing.

The re-witnessing queue restores integrity over time. It does not leave the entire fragile population merely grandfathered, but it also does not force a destabilizing rollback wave. It recognizes that a canon has finite A_B, finite review capacity, finite operator bandwidth, finite dependency-mapping capacity, and finite tolerance for cascade. It converts retroactive crisis into a scheduled witness program.

The queue is not delay for convenience.

It is law under budget constraint.

Each order-fragile Σ receives a queue status:

awaiting re-witness;

scheduled;

in replay;

re-witnessed and reaffirmed;

re-witnessed and quarantined;

re-witnessed and rejected;

deferred under grandfathered interim standing;

escalated to urgent review;

escalated to Level 3 adjacency.

The queue has a flow rate.

Let Q be the set of order-fragile states requiring re-witnessing.

Let B_epoch be the available Certificate / Remediation Maintenance Budget per epoch allocated to re-witnessing.

Let cost_rewitness(Σ) be the expected cost of re-witnessing Σ.

The maximum flow per epoch is constrained by:

Σ cost_rewitness(Σ_i) ≤ B_epoch

for all Σ_i scheduled in that epoch.

The scheduling function must maximize risk reduction per budget unit without concealing low-visibility high-severity states. A simple priority score may be:

P(Σ) = αS(Σ) + βD(Σ) + γI(Σ) + δμ(Σ) + εL3(Σ) + ζU(Σ)

where:

S(Σ) is status severity;

D(Σ) is downstream dependency weight;

I(Σ) is irreversibility exposure;

μ(Σ) is fragility multiplicity across tested orderings;

L3(Σ) is Level 3 adjacency indicator;

U(Σ) is current-use intensity;

and α, β, γ, δ, ε, ζ are declared queue weights.

The queue then schedules high P(Σ) states first, subject to class balancing and anti-starvation rules. A low-priority state may not be deferred forever. The queue must include a maximum deferral age or witness half-life threshold. Otherwise the re-witnessing queue degenerates into a grandfather clause disguised as process.

The cost formula is distributed rather than immediate.

C_queue_total may approach C_rollback over time if every fragile state is eventually re-witnessed, but the per-epoch cost is bounded:

C_queue(e) = Σ_{Σ ∈ Scheduled(e)} [cost_rewitness(Σ) + expected_downstream_review(Σ)]

subject to:

C_queue(e) ≤ B_epoch

The key advantage is that cascade can be absorbed gradually. If a high-dependency state fails, its dependents can be handled before the next wave. If an entire class shows severe fragility, the queue can pause and escalate to class-level LCR. If the first re-witnessing cycles show low failure rates, the queue may adjust flow. If they show high failure rates, the queue may increase containment or shift from queue to rollback for that class.

The re-witnessing queue creates a dynamic remediation regime.

It is appropriate when fragility is significant but not uniformly catastrophic, when budget cannot support full rollback, when grandfathering alone would leave too much unresolved, and when the canon needs both integrity and continuity. It is especially appropriate for mixed fragility populations: some high-risk states, some low-risk archival states, some residue-only states, some budget-fragile states, and some status-fragile clusters.

The queue’s danger is indefinite postponement.

A state placed into the queue may remain in limbo. Operators may treat “queued” as “handled.” Dashboards may show progress while old risks persist. Budget holders may reduce B_epoch after the first visible crisis passes. The queue may become a cemetery of unresolved law.

To prevent this, every queued state must carry an interim standing.

Interim standing defines what the state may do while awaiting re-witnessing. Possible interim states include:

active grandfathered standing;

restricted grandfathered standing;

read-only standing;

no-new-dependency standing;

quarantine-pending-re-witness;

actuation-suspended standing;

citation-only standing;

sealed standing.

The queue is therefore not merely an ordered list. It is a state machine.

A high-risk status-fragile state may not remain fully active while waiting. A low-risk archival residue-fragile state may remain active with Notes-field annotation. A budget-fragile state may remain active but may not support new budget-sensitive LCRs. A Level 3 adjacent state may bypass the normal queue and enter immediate review.

The re-witnessing queue pays a medium cost for staged integrity.

Its final state is:

fragile states enter scheduled witness repair;

budget flow controls pace;

high-risk states handled first;

interim standing prevents unmanaged exposure;

integrity improves over time;

cascade risk is monitored;

permanent limbo is prohibited by queue aging rules.

The three options can now be compared.

Rollback Wave
Integrity: maximal.
Immediate A_B cost: maximal.
Cascade risk: maximal.
Continuity: lowest.
Semantic complexity after completion: lowest if successful.
Best use: severe, contained, high-risk fragility where historical standing cannot safely persist.

Grandfather Clause
Integrity restoration: minimal.
Immediate A_B cost: minimal.
Cascade risk: minimal.
Continuity: maximal.
Semantic complexity: permanent two-class manifold.
Best use: low-risk historical commitments, archival dependencies, deep reliance chains where eviction cost exceeds governance benefit.

Re-Witnessing Queue
Integrity restoration: staged.
Immediate A_B cost: bounded by epoch budget.
Cascade risk: controlled.
Continuity: conditional.
Semantic complexity: temporary to permanent depending on queue completion.
Best use: mixed populations, budget-constrained repair, significant but non-catastrophic fragility.

The canon is not required to choose one option globally.

That would be crude. Chapter 14 treats grandfathering as law precisely because remediation must be class-indexed, severity-indexed, and dependency-indexed. A single Outcome B measurement may produce different remediation routes for different regions of M_π₀.

A possible remediation map may be:

Level 3 adjacent status-fragile states: rollback wave or immediate re-witnessing.

High-dependency but low-current-use states: re-witnessing queue with restricted interim standing.

Archival residue-fragile states: grandfather clause with Notes-field annotation.

Budget-fragile states near active ceilings: re-witnessing queue or targeted budget replay.

Late-failure class clusters: class-level re-witnessing queue, possible rollback if failure rate exceeds threshold.

States stable across tested orderings: no remediation beyond census record.

This mixed strategy must itself be compiled.

The canon must not improvise remediation state by state without a governing rule. The correct artifact is:

Remediation Pricing Matrix

The matrix assigns each census tag and severity level to a default remediation option, permitted exceptions, budget line, interim standing, downstream review requirement, and escalation trigger.

The matrix must include:

census tag;

severity level;

dependency weight band;

current-use band;

irreversibility band;

Level 3 adjacency flag;

default remediation route;

estimated A_B or maintenance cost;

cascade coefficient;

interim standing;

maximum deferral epoch;

required Notes-field text;

restoration or closure condition.

This matrix is the first artifact of Chapter 14.

It prevents remediation from becoming moral reaction, political negotiation, or cost avoidance. Each state receives a route because its census status, risk, dependency, and budget profile place it there. Exceptions are allowed only if recorded as exceptions.

The chapter’s governing principle can now be stated:

Remediation must be priced at the level of law before it is applied to states.

This follows directly from Section 13.3. Fragility is not guilt, so remediation is not punishment. It is legal repair. Legal repair requires pricing because law operates under cost. The canon can spend A_B to cleanse the historical manifold. It can preserve continuity through grandfathering. It can restore witness gradually through a queue. But it must say what each choice costs and what residue each choice leaves behind.

There is no costless option.

Rollback pays in budget and cascade.

Grandfathering pays in permanent dual standing.

Re-witnessing pays in time, queue governance, and interim exposure.

A canon that denies these costs has not remediated the crisis. It has hidden the cost inside another uncompiled structure.

The section closes with the compiled rule:

Priced Remediation Rule

After Outcome B and completion of the Order-Fragile Census, every order-fragile committed Σ must be assigned to one of three remediation routes: rollback wave, grandfather clause, or re-witnessing queue. The assignment must be class-indexed, severity-indexed, dependency-indexed, and budget-priced. No route may be described as costless. No state may be remediated through blame. No historical standing may be preserved without a compiled clause. No repair may proceed without recording its A_B cost, cascade risk, interim standing, and downstream ledger consequences.

The canon now has the three tools it needs.

One cuts.

One preserves.

One restores by sequence.

The law must choose with its costs visible.


14.2 — The Decision Is LCR-B

The remediation decision is not a runtime claim. It is not another judgment about a particular Σ. It is not an interpretation of whether one order-fragile state should stand, fall, quarantine, or pass into re-witnessing. Those judgments will exist later, downstream, after the remediation law has been compiled. The decision at this level is older than any one case. It sets the discipline by which the canon will update the standing of its own past.

That is why the remediation choice is LCR-B.

A runtime claim operates inside an already compiled manifold. It asks whether a submission satisfies the law currently active at the threshold. It takes the boundary as given. It does not authorize the boundary to rewrite the standing of prior commitments. It does not decide whether historical π₀-committed states are to be rolled back, grandfathered, queued, annotated, quarantined, or re-witnessed. It does not define a cutover epoch. It does not establish a two-class manifold. It does not set the rate at which the past is reprocessed under Witness Thermodynamics. Those are not runtime outputs. They are compiler outputs.

The remediation decision is a meta-condition of the runtime because it determines how the runtime is allowed to inherit its own historical manifold after the discovery of non-commutation. Once Outcome B activates, the runtime can no longer pretend that prior committed states are simply “admissible” in the old unindexed sense. They are π₀-admissible unless proven otherwise. The runtime now needs a compiled rule telling it how to treat them. Should it continue to use them? Should it annotate them? Should it restrict their downstream force? Should it send them into a queue? Should it evict the ones that fail replay? Should it distinguish old standing from new standing forever? The runtime cannot answer those questions by executing itself. The questions define the runtime’s inheritance conditions.

This is the Compiler Rule for Layer Crossing in its most severe form. A rule that changes how Layer C outputs from the past are carried into future execution is not merely Layer C. It touches the compiled archive, the standing of prior entries, the inheritance of witness residue, the legitimacy of downstream dependencies, and the update discipline of the admissible manifold. That is Layer B subject matter. The runtime may apply the remediation once compiled, but it cannot compile the remediation by continuing to run.

The rollback wave, the grandfather clause, and the re-witnessing queue are therefore not three operational preferences. They are three different update laws for the historical manifold. The rollback wave says that historical π₀-standing is insufficient for affected states and must be tested against the governed post-discovery rule. The grandfather clause says that historical π₀-standing remains valid as historical standing, while new submissions enter under a different law. The re-witnessing queue says that historical standing is neither immediately revoked nor permanently protected, but scheduled through witness renewal at a budgeted flow rate. Each option changes the relation between past and future. Each option changes what the runtime is allowed to treat as inherited truth.

That relation cannot be chosen informally.

If the canon selects rollback without LCR-B, it turns remediation into a purge without compiled authority. If it selects grandfathering without LCR-B, it turns continuity into quiet exception. If it selects the re-witnessing queue without LCR-B, it turns delay into disguised law. The decision must therefore pass through a Layer B record before any of the options can govern. The record does not merely describe the option. It authorizes the manifold update discipline.

The object to be submitted is a Layer Crossing Record — B level: an LCR-B for remediation of order-fragile historical commitments after Outcome B. At this point in the chapter, the record is drafted but not submitted. It is not yet active law. It is the skeleton the canon must complete after the census annex produces the required counts, class concentrations, severity distribution, dependency map, and budget estimates. The form can be drafted now because the decision architecture is known. The submission cannot occur until the census outputs exist.

The nine-field skeleton is as follows.

Field One: Crossing Object.
The crossing object is the remediation decision for order-fragile committed states after activation of Outcome B. It concerns the historical population of Σ committed under Check_π₀ and identified by the Order-Fragile Census Annex as status-fragile, residue-fragile, budget-fragile, or dependency-exposed. The object is not a single state and not a runtime verdict. It is the law by which the runtime will inherit, restrict, reprocess, grandfather, or re-witness its own past.

Field Two: Layer of Origin.
The disturbance originates in Layer C measurement: λ ≠ 0 or φ > 0 under the Part II campaign. The measurement reveals that the ordering of governance operators has content. The immediate evidence is runtime-adjacent because it comes from replaying admissibility operations over hash-fixed Σ. But the consequence exceeds Layer C because it changes the status of the historical manifold as a compiled object. The origin is therefore Layer C evidence forcing Layer B review.

Field Three: Layer of Destination.
The destination is Layer B because the decision defines the update discipline of the canon’s compiled archive and its inherited manifold. It determines whether prior π₀-committed states stand, fall, queue, or split into a permanent two-class structure. It sets the rule by which future runtime processes may cite historical commitments. It defines whether the past is revised, preserved, re-witnessed, or restricted. This is not execution. It is compilation of inheritance law.

Field Four: Crossing Justification.
The crossing is required because the runtime cannot lawfully decide how to update the conditions of its own past. A runtime verdict can process a submission, but it cannot define whether historical submissions processed under an uncompiled ordering remain fully active after non-commutation is discovered. Without LCR-B, any remediation option would either overreach as uncompiled repair or underreach as uncompiled tolerance. The crossing is justified by the fact that remediation changes the manifold’s standing conditions, not merely the standing of an individual Σ.

Field Five: Candidate Remediation Law.
The candidate law must select one or more of the three priced remediation routes: rollback wave, grandfather clause, and re-witnessing queue. It may choose a mixed strategy by class, severity, dependency weight, current-use intensity, irreversibility exposure, and Level 3 adjacency. It must define the cutover epoch, the interim standing of affected states, the downstream citation rule, the budget line, the cascade-control rule, and the maximum deferral condition for any queued state. The candidate law must explicitly state that fragility is not guilt and that remediation operates at the level of law before it is applied to states.

Field Six: Required Evidence Inputs.
The LCR-B cannot be submitted without the Order-Fragile Census Annex. Required inputs include the census ID, affected class list, tested ordering set, status-fragile registry, residue-fragile registry, budget-fragile registry, late-failure concentration analysis, severity distribution, downstream dependency map, cascade coefficient estimates, A_B estimates for rollback and re-witnessing, proposed Certificate / Remediation Maintenance Budget, and list of Level 3 adjacent states or dependencies. If these inputs are incomplete, the LCR-B remains drafted but unsubmitted.

Field Seven: Risk of Crossing and Risk of Non-Crossing.
The risk of crossing is that the canon may overcorrect the past, destabilize valid dependencies, consume excessive A_B, create cascade through dependent artifacts, or install a permanent two-class manifold with insufficient safeguards. The risk of non-crossing is worse: the runtime would continue to inherit π₀-committed states without compiled discipline after the discovery that π₀ selected one fiber among legal ordering fibers. Non-crossing would preserve dark canon after discovery. Crossing is dangerous because it changes historical standing. Non-crossing is dangerous because it refuses to govern that change.

Field Eight: Decision Gate and Output Status.
The decision gate must classify the remediation law as one of four outcomes: Accepted as Layer B Remediation Law, Accepted with Class-Specific Restrictions, Returned for Census Completion, or Rejected into Pre-Commit Quarantine. If accepted, the output becomes a compiled Layer B rule governing all downstream remediation of order-fragile historical commitments within its scope. If returned, no remediation beyond immediate safety suspension may proceed except provisional containment. If rejected, the canon must open a replacement LCR-B or escalate to Level 3 adjacency if the rejection concerns authority over the rule of rule-change itself.

Field Nine: Downstream Binding Effects.
Once compiled, the LCR-B binds the runtime, the ledger, the census annex, future LCRs, citation protocols, dependency audits, and remediation dashboards. It determines whether affected states are rolled back, grandfathered, queued, restricted, or re-witnessed. It defines mandatory Notes-field language, runtime routing consequences, downstream-use limits, and restoration conditions. It also creates the linter rule: no remediation decision may be executed, cited, or implemented unless it traces back to the compiled LCR-B or to a narrower LCR-B derivative authorized by it.

This skeleton is deliberately incomplete. It is drafted before submission because the canon already knows that the remediation decision crosses layers. It is not submitted because the census has not yet supplied the quantities that would make the decision lawful. A Layer B record without the census would be an empty assertion of authority. A runtime remediation without the Layer B record would be an unauthorized update to the past. The sequence must be preserved.

First, the census names the order-fragile population.

Second, the remediation options are priced.

Third, the LCR-B is completed from the census outputs.

Fourth, the compiled remediation law binds the runtime.

Only then may individual states be rolled back, grandfathered, queued, restricted, or re-witnessed under lawful authority.

This sequence protects the canon from two opposite errors. The first error is runtime panic: immediately evicting, preserving, or queuing states because the census feels alarming. The second error is compiler avoidance: refusing to decide at Layer B and allowing the runtime to inherit the past by inertia. Both errors repeat the same underlying failure. They allow an uncompiled condition to govern. Outcome B was triggered precisely because the canon discovered such a condition in π₀. It cannot answer that discovery by creating another.

The remediation choice must therefore be named as what it is: a Layer B decision concerning the manifold’s past as inherited by future runtime. It is not an ethical mood, not a technical preference, not a dashboard setting, not a local runtime exception, and not an operator judgment. It is a compiler act.

The section closes with the rule:

Remediation LCR-B Rule

After Outcome B, the choice between rollback wave, grandfather clause, re-witnessing queue, or any mixed remediation strategy is a Layer B crossing decision because it defines how the runtime inherits and updates the historical π₀-admissible manifold. No remediation route may govern order-fragile historical commitments until a drafted LCR-B is completed from census outputs, submitted, and compiled. Until then, only immediate safety suspension and Notes-field preservation may occur.

The draft exists.

The law does not yet.

That distinction is the discipline.


14.3 — Dependents and Cascades

An order-fragile state rarely stands alone.

Once the census identifies a committed Σ whose standing changes across legal orderings, the canon must ask a second question: what else changed because that state stood where it stood? The first census names the directly fragile object. The cascade trace names the objects whose own admissibility, budget, witness residue, class routing, or downstream standing may have been influenced by that object’s historical presence in the manifold.

This is the dependency problem.

The simplest form is explicit dependency. A later state Σ₂ cites, imports, extends, uses, routes through, or compiles a prior state Σ₁. If Σ₁ is order-fragile, then Σ₂ is dependency-exposed. This is easy to see. The more difficult form is budget dependency. A later state may not cite Σ₁ directly, yet its admissibility may have been partly shaped by the budget landscape that Σ₁ helped produce. In such a case, the earlier order-fragile state did not become a premise of the later state. It became part of the field through which later admissibility was priced.

That is the cascade problem in its sharper form: some states may have been admitted partly because order-fragile neighbors updated the budget before them.

The canon must not treat the Admissibility Budget as if every submission consumes cost in isolation. A_B may be computed per candidate, but it is not always fieldless. Prior commitments can affect later budget posture through inherited witness, reduced proof burden, class stabilization, precedent compression, trace reuse, dependency acceptance, shared evidence structures, or accumulated curvature in the admissibility manifold. If an order-fragile state helped lower, raise, redirect, or normalize the budget of later submissions, then removing or reclassifying that state may alter more than its own standing.

A rollback wave that evicts Σ₁ may change the budget history of Σ₂. A grandfather clause that preserves Σ₁ may preserve a budget influence that would not exist under the governed post-discovery ordering. A re-witnessing queue may leave Σ₂ temporarily exposed until Σ₁ is resolved. None of these consequences can be handled by intuition. They must be traced through the Admissibility Graph.

The Admissibility Graph is the directed structure in which nodes are committed states, quarantined states, rejected states where relevant, class entries, gate outputs, budget updates, witness residues, LCRs, and downstream artifacts. Edges record dependence: citation, inheritance, budget influence, witness reuse, class-routing effect, gate-definition reliance, trace normalization reliance, and compilation dependency. Outcome B requires the graph to become more than archive. It becomes the instrument by which cascade is bounded.

A direct edge says: this object used that object.

A budget edge says: this object’s A_B computation was influenced by that object’s prior standing.

A witness edge says: this object inherited or reused witness residue from that object.

A class edge says: this object’s class routing depended on a class stabilized by that object or by a cluster containing it.

A compilation edge says: this object entered the canon through an LCR, protocol, or rule that depended on the standing of the earlier object.

These edges are not equal. A citation edge may be explicit and strong. A budget edge may be diffuse and weak. A witness edge may decay over time. A class edge may affect many states at low intensity. A compilation edge may be rare but severe. Cascade tracing must therefore distinguish edge type and influence magnitude.

Let Σ_f be an order-fragile state identified by the census. Let Dep₁(Σ_f) be the first-order dependents of Σ_f in the Admissibility Graph. Let Dep₂(Σ_f) be the dependents of those dependents, and so on. The naive cascade rule would trace until the graph ends. That is impossible and unnecessary. Every committed object eventually participates in some historical field. A cascade with no stopping rule becomes total history. Total history is not remediation. It is paralysis.

Therefore, cascade tracing requires a stopping rule.

The stopping rule is budget influence below the control-run noise floor.

For each dependency path p from Σ_f to a downstream state Σ_d, the cascade trace estimates the budget influence transmitted along that path. Let I_B(Σ_f → Σ_d | p) denote the measured or estimated change in A_B for Σ_d caused by removing, reclassifying, quarantining, or re-witnessing Σ_f under the remediation scenario being tested. Let η_control be the control-run noise floor for budget variation, derived from control replays over comparable states where no order-fragile dependency has been altered.

Cascade tracing continues along a path only while:

|I_B(Σ_f → Σ_d | p)| ≥ η_control

When the absolute budget influence falls below the control-run noise floor, the path terminates for remediation purposes. Below that floor, the canon cannot distinguish dependency influence from ordinary replay noise. Continuing the cascade would create false precision. Stopping is not denial. It is measurement discipline.

This rule bounds cascade depth without pretending that influence becomes metaphysically zero. It says only that the influence is no longer actionable under the current measurement resolution. A future replay with lower noise may reopen deeper paths. Until then, the cascade terminates at the measured floor.

The stopping rule must apply separately by influence type. Budget influence has one noise floor. Witness-residue influence may have another. Class-routing influence may be discrete rather than continuous. Status influence has no small-value version: if a downstream state flips status because of the upstream change, the cascade remains active regardless of budget magnitude. The budget floor bounds budget cascade, not every possible form of dependency.

The core protocol is as follows.

First, take each status-fragile, budget-fragile, or high-severity residue-fragile committed state from the Order-Fragile Census Annex and mark it as a cascade seed. Second, query the Admissibility Graph for first-order dependents by explicit dependency, budget influence, witness reuse, class stabilization, and compilation reliance. Third, replay or estimate the effect of the seed’s remediation scenario on each dependent: rollback, grandfathering, or re-witnessing. Fourth, record changes in A_B, witness_residue, class routing, and final status. Fifth, propagate only those paths whose influence remains above the relevant control-run floor or whose status changes. Sixth, terminate paths below floor and record the termination point.

The cascade trace is scenario-specific. A rollback cascade is not the same as a grandfathering cascade. Under rollback, a fragile state may be evicted, changing downstream premises. Under grandfathering, it remains standing but receives a scarred status, changing citation and dependency force. Under re-witnessing, it enters interim standing, which may temporarily restrict downstream use. Each remediation option produces a different cascade profile. Therefore the Remediation Pricing Matrix from Section 14.1 cannot be completed without cascade tracing.

A state may be cheap to re-run and expensive to evict.

A state may be expensive to annotate because many downstream artifacts must carry the annotation.

A state may be cheap to grandfather immediately but costly to maintain because every dependent must forever distinguish historical standing from post-remediation standing.

A state may be suitable for queueing only if its dependents can tolerate restricted interim standing.

Cascade tracing prices these differences.

The protocol must distinguish four cascade classes.

Direct Cascade occurs when a downstream object explicitly depends on an order-fragile state. If Σ₂ cites or compiles Σ₁, and Σ₁ is evicted or restricted, Σ₂ must be reviewed.

Budget Cascade occurs when a downstream state’s A_B changes because an order-fragile predecessor altered the budget field, reduced proof burden, stabilized a class, or contributed reusable witness.

Witness Cascade occurs when downstream witness_residue changes because the upstream state’s witness standing is altered, decayed, reclassified, or voided.

Class Cascade occurs when a cluster of order-fragile states changes the definition, stability, or routing behavior of a class, exposing states that never depended on any single fragile object but depended on the class environment those objects helped form.

Each cascade class requires different remediation. Direct cascade often leads to dependency annotation or replay. Budget cascade leads to A_B recalculation and threshold review. Witness cascade leads to re-witnessing or Notes-field correction. Class cascade may require class-level LCR, not state-level repair.

The stopping rule applies most cleanly to budget cascade. Suppose evicting or reclassifying Σ_f increases the A_B of a dependent Σ_d by 0.004 units. If control-run variation for comparable replays is ±0.009 A_B units, then the influence is below noise and is not actionable. The path terminates. If the influence is 0.027 A_B units, it remains above noise and the path continues to downstream dependents of Σ_d. If the influence is only 0.006 units but crosses a budget threshold because Σ_d was already within 0.003 units of that threshold, the path remains active because the threshold crossing creates discrete status or routing significance.

Thus the stopping rule has two clauses:

Budget cascade stops when influence falls below the control-run noise floor and does not cross any compiled threshold.

Budget cascade continues when influence exceeds the noise floor or crosses a compiled threshold, even if the absolute magnitude is small.

This prevents both overreach and underreach. A tiny irrelevant delta does not generate endless repair. A tiny decisive delta near a boundary is not dismissed as small.

The Admissibility Graph must store cascade traces as permanent annexes, because cascade status may change the meaning of future remediation. A dependent state that was stable in the original census may become exposed when an upstream fragile state is evicted. A state not fragile under ordering replay may become budget-fragile under cascade replay. A downstream artifact may remain valid but require citation restriction because one of its premises is grandfathered rather than re-witnessed. These are not failures of the census. They are second-order consequences.

The annex is named:

Cascade Trace Annex

It records the seed state, remediation scenario, dependency paths, edge types, influence estimates, replay results, noise floors, stopping points, threshold crossings, downstream status changes, and required remediation actions. It must be linked to both the Order-Fragile Census Annex and the Remediation LCR-B. Without this annex, the canon cannot price cascade risk honestly.

The minimal fields are:

Cascade Trace ID; seed Σ; seed census tag; remediation scenario tested; dependency path; edge type; dependent object; baseline A_B; scenario A_B; budget influence I_B; control-run noise floor η_control; witness_residue delta; status delta; threshold crossing; propagation decision; stopping reason; downstream action; annex references.

The stopping reason must be explicit. A cascade path may stop because budget influence fell below noise, because no threshold was crossed, because the dependent has no further graph edges, because the path entered a sealed region requiring separate authorization, because class-level LCR supersedes state-level tracing, or because replay became indeterminate. “Stopped” is not enough. The ledger must know why.

The linter for this section has three patterns.

Unbounded Cascade fires when a remediation proposal traces dependents without a declared stopping rule or treats all downstream history as actionable exposure.

Premature Cascade Stop fires when a path is terminated despite budget influence above the control-run noise floor, a compiled threshold crossing, status change, or unresolved witness delta.

Cascade Concealment fires when a remediation proposal prices a rollback, grandfather clause, or re-witnessing queue without citing the Cascade Trace Annex for high-dependency or high-severity states.

These linters protect remediation from two opposite failures. The first is infinite responsibility, where every state becomes dependent on every prior condition. The second is shallow repair, where only direct fragile states are handled and their budget field effects are ignored.

The canon must hold the middle.

Dependents are real.

Cascades are bounded.

The dependency problem also changes the meaning of grandfathering. A grandfather clause for Σ_f is not only a decision about Σ_f. It is a decision about all dependents that continue to draw standing from Σ_f. If the clause says that Σ_f stands historically but cannot support new dependencies, then downstream effects are contained. If it says that Σ_f stands fully for all future uses, the cascade remains live. If it says that existing dependents stand but new dependents cannot be formed, the graph is frozen at the cutover. These are different laws and must be priced differently.

A precise grandfather clause must therefore specify dependency permissions:

existing dependents only;

existing and derivative dependents;

no new budget influence;

no new witness reuse;

citation allowed but compilation prohibited;

read-only standing;

full standing pending re-witnessing;

or sealed standing.

Without such permissions, grandfathering becomes uncontrolled cascade preservation.

The same applies to the re-witnessing queue. A queued state cannot be allowed to propagate unlimited new dependencies while awaiting re-witnessing unless the LCR-B explicitly authorizes that risk. Interim standing must define whether dependents may continue, whether new dependents may form, whether budget influence is frozen, whether witness reuse is paused, and whether downstream LCRs may cite the queued state.

The rollback wave also requires cascade discipline. Eviction may look clean at the seed level and chaotic at the dependency level. A rollback that removes Σ_f but leaves all dependents untouched may create orphaned standing. A rollback that recursively evicts dependents without the noise-floor stopping rule may create unnecessary destruction. The correct rollback wave follows the cascade trace and stops where measured influence stops.

This is why remediation cannot be reduced to moral preference for strictness or mercy. The graph decides where consequences travel. The budget floor decides where they stop. The LCR-B decides what law governs the path.

The section compiles the following rule:

Bounded Cascade Rule

After Outcome B, remediation of an order-fragile committed state must trace dependencies through the Admissibility Graph, including direct, budget, witness, class, and compilation edges. Cascade propagation continues while the remediation scenario produces budget influence above the control-run noise floor, any compiled threshold crossing, status change, or unresolved witness effect. Budget cascade stops at the first point where influence falls below the relevant control-run noise floor and no threshold is crossed. Every stopped path must record its stopping reason in the Cascade Trace Annex.

This rule makes cascade neither infinite nor invisible.

The canon is responsible for the effects its law created, but only where those effects remain measurable or legally discrete. Below the noise floor, responsibility becomes speculation. Above the floor, denial becomes concealment. The admissible middle is traced, priced, and bounded.

The final consequence is simple.

No remediation route is fully priced until its cascades are traced.

A rollback wave without cascade tracing is a demolition plan without structural mapping. A grandfather clause without cascade tracing is a hidden inheritance regime. A re-witnessing queue without cascade tracing is a schedule that may leave dependent exposure unmanaged.

The graph must be read before the law moves.

The state that was fragile may not be guilty.

But the law that admitted it may have touched more than one state.


Chapter 15 — The Holonomy Group

15.1 — From Residue to Group

Nonzero λ is not the end of the measurement. It is the beginning of classification. Once the canon discovers that ordering changes leave measurable residue, it must stop treating each anomaly as an isolated defect. A single λ event says that one legal ordering differs from π₀ for one Σ, one class, one operator set, and one measured endpoint. The next question is structural: how do all such differences compose?

This chapter names that structure the Check’s holonomy.

The word is not decorative. It marks the passage from local residue to organized order-effect. If a state is carried through one legal ordering and returns with a different witness residue than it carries through another legal ordering, then the Check has path-dependence in ordering space. The ordering space is not merely a list of permutations. It becomes a graph of admissibility paths. Moving through that graph changes the terminal state. The differences generated by those movements are the holonomy structure of the Check.

Let Π_L be the set of legal orderings permitted by the precedence lattice. Let π₀ be the canonical historical ordering. Let Ω_π(Σ) denote the terminal outcome vector produced by applying Check_π to a hash-fixed submission Σ. The outcome vector includes at minimum final status, witness_residue, A_B, route, quarantine or rejection signal, final witness result, and trace-normalized terminal fields. Outcome B means that Ω_π(Σ) is not guaranteed to equal Ω_π₀(Σ).

The residue relative to π₀ is:

Δ_π(Σ) = Ω_π(Σ) − Ω_π₀(Σ)

This expression must be read broadly. For continuous quantities, such as witness_residue or A_B, subtraction may be literal or metric-defined. For discrete quantities, such as commit, quarantine, reject, or boundary-hold, the difference is categorical. A status flip is not a larger number. It is a different region of the terminal routing space.

A single Δ_π is a residue event. The set of all Δ_π across legal orderings, classes, and submitted states is the raw holonomy field. But Chapter 15 requires more than raw differences. It requires the canon to ask whether those differences have composition rules. If one ordering swap changes the outcome in a certain way, and another swap changes it in another way, what happens when both swaps are applied? Does the combined effect equal the sum of the separate effects? Does it depend on order? Does the second swap alter the meaning of the first? Does the first swap create a context in which the second becomes stronger, weaker, reversed, or newly status-relevant?

These questions convert residue into group structure.

The minimal generator is an adjacent legal swap. A swap is legal when it exchanges the order of two neighboring gates without violating the precedence lattice. If s_i swaps two adjacent operators in a legal ordering, then s_i acts on the ordering path. The replay campaign can measure the induced outcome transformation:

H_{s_i}(Σ) = Ω_{s_i(π)}(Σ) − Ω_π(Σ)

where π is the ordering before the swap and s_i(π) is the ordering after the swap. This transformation is not assumed to be constant. It may depend on the class, the submission, the previous ordering path, the gate context, and the current witness field.

The Check’s holonomy structure is generated by such legal swaps.

Not every pair of gates may be swappable. Not every swap sequence may remain legal. The precedence lattice constrains the available paths. Therefore, in strict form, the structure may be a partial groupoid rather than a clean group: transformations are defined only where the relevant ordering paths are legal. However, where the legal swaps close over a class of orderings and composition is well-defined, the canon may speak of the Check’s holonomy group for that class and operator scope.

The operational definition is:

The holonomy structure of the Check is the class-indexed set of terminal outcome transformations generated by legal ordering swaps, measured against hash-fixed submissions and normalized to π₀.

This definition matters because Outcome B should not stop at “order matters.” That phrase is too crude. Order may matter in a weak, additive, residue-only way. It may matter in a strong, interacting, status-changing way. It may matter only near late-failure classes. It may matter only when a budget-relevant gate precedes a witness-relevant gate. It may matter only after Zebra-Ø has been moved. It may matter only through cascaded dependencies. Without holonomy classification, all non-commutation looks equally alarming. It is not.

The first classification is identity versus non-identity. If a legal swap produces no measurable terminal difference across the tested class and error budget, then that swap is locally identity for that class. It may remain in the lattice as a swappable relation. It does not generate holonomy there. If the swap produces nonzero witness_residue but no status change, it generates residue holonomy. If it produces budget threshold movement, it generates budget holonomy. If it produces quarantine, rejection, commit, or boundary-hold divergence, it generates status holonomy. These are different severities and must be recorded separately.

The second classification is abelian versus non-abelian.

An abelian holonomy case occurs when order matters, but swap effects compose independently. Suppose two legal swaps, s_a and s_b, each generate a measurable effect. The case is abelian if applying s_a then s_b produces the same terminal transformation as applying s_b then s_a, within the declared error budget, for the relevant class and submission set. Formally:

H_{s_b} ∘ H_{s_a} = H_{s_a} ∘ H_{s_b}

within measurement tolerance.

In this case, the Check is non-commuting at the gate level, but the discovered order effects commute at the holonomy level. The canon may still face retroactivity, census, and remediation. But the repair problem is more tractable because effects can be decomposed. Each swap contributes its influence independently. The order in which remediation accounts for them does not materially change the result.

An abelian case says: order matters, but the order-effects themselves do not entangle.

This is still serious. It still means M_π₀ is a fiber. It still means “admissible” means π₀-admissible unless indexed. It still requires census and remediation pricing. But it allows a cleaner accounting model. The canon can build a swap-effect ledger, sum residue contributions, isolate gate-pair effects, and prioritize repairs by magnitude. Abelian holonomy is not innocence. It is manageable non-commutation.

A non-abelian holonomy case occurs when the effect of one swap depends on which swaps preceded it. Here:

H_{s_b} ∘ H_{s_a} ≠ H_{s_a} ∘ H_{s_b}

beyond the declared error budget.

This means that swap effects do not merely add. They interact. Moving a blocking gate before a zero-question may have one effect when Zebra-Ø remains downstream and another effect after Zebra-Ø has already been moved. Moving a budget computation earlier may be harmless until a witness gate has been reordered. A swap that is residue-only in one path may become status-changing after another swap. The path through ordering space now matters, not only the endpoint ordering.

This is the stronger crisis.

In a non-abelian case, the canon cannot treat the order-fragile census as a simple table of independent gate-pair defects. The sequence of reordering operations becomes content. Remediation must account for interaction terms. A rollback wave may produce different cascade effects depending on which ordering path is selected as governed replacement. A re-witnessing queue may need to test path families, not just alternate endpoints. A grandfather clause may need to distinguish fibers not only by ordering but by transition history where the trace records it.

Non-abelian holonomy says: the boundary has memory of the path by which ordering is changed.

This is the point at which dark canon becomes geometry.

The old ordering π₀ is no longer merely a historical line. It is a basepoint in a nontrivial ordering space. Other legal orderings are not only alternatives. They are connected to π₀ through paths of swaps, and those paths may generate different terminal transformations. The Check has acquired curvature in ordering space. A loop that begins at π₀, traverses legal swaps, and returns to an ordering equivalent to π₀ may still leave residue in the terminal outcome record if the transformations along the path fail to cancel. That residual difference is holonomy in the strict sense.

The canon must then record not only which ordering was used, but how ordering transformations compose.

The Holonomy Ledger must therefore contain more than λ and φ. It must include the generators, compositions, commutators, and class-local closure behavior of the discovered order effects. A minimal entry includes: class ID, base ordering π₀, legal ordering set Π_L, tested swap generators, pairwise swap effects, composed swap effects, commutator results, status divergence, residue divergence, budget divergence, threshold crossings, and whether the class is identity, abelian, or non-abelian.

The commutator test is central. For two legal swaps s_a and s_b, define the holonomy commutator:

K(s_a, s_b; Σ) = H_{s_b}H_{s_a}(Σ) − H_{s_a}H_{s_b}(Σ)

If K is zero within the declared error budget across the tested class, the pair is holonomy-commuting. If K is nonzero, the pair is holonomy-non-commuting. If K produces witness_residue difference only, the pair is residue-non-abelian. If K produces A_B threshold difference, it is budget-non-abelian. If K produces status difference, it is status-non-abelian.

This classification is operationally necessary.

Residue-non-abelian cases may require trace and witness repair. Budget-non-abelian cases may require accounting repair and threshold review. Status-non-abelian cases require the strongest remediation because the path of ordering transformation can decide whether a state commits, quarantines, or rejects.

The chapter’s first artifact is therefore:

Check Holonomy Table

The table classifies discovered non-commutativity by class, operator set, swap generator, composition relation, residue effect, budget effect, status effect, and abelian status. It is generated from campaign outputs and census replay, not from interpretation. It becomes a dependency of the Remediation LCR-B, the Cascade Trace Annex, and any future decision to compile π₀ as content.

The table uses the following core statuses:

Identity Swap: no measured effect.

Residue Generator: nonzero λ, no budget threshold crossing, no status flip.

Budget Generator: A_B shift or threshold crossing, with or without residue shift.

Status Generator: final status differs under the swap or its composition.

Abelian Class: all measured generator effects compose independently within the class.

Non-Abelian Class: at least one measured generator pair produces path-dependent composition.

Path-Critical Class: a non-abelian class in which different swap paths reach the same endpoint ordering but produce different terminal outcome vectors.

The last category is the most severe. It means that even naming the final ordering is insufficient. The history of reordering becomes part of the governance state. In such a class, the canon cannot merely choose a new canonical ordering and assume the problem is solved. It must specify transition law, migration path, and replay discipline. This may touch Level 3 adjacency if the chosen transition changes the rule by which rules are allowed to update themselves.

Not every Outcome B case reaches this severity. The canon must not inflate. Many nonzero λ findings may be local, abelian, and residue-only. Some may concentrate in late-failure classes. Some may never cross status boundaries. Some may be controlled by reclassifying a gate or narrowing a class. The purpose of holonomy classification is to prevent both panic and minimization.

A simple worked structure clarifies the difference.

Assume two swaps are legal in a late-failure class C_L:

s_a = swap G_B2 before G_Z4
s_b = swap G_A before G_Ø within an admitted test variant

Measured separately, each produces residue:

H_{s_a}: +0.04 witness_residue units, no status flip
H_{s_b}: +0.06 witness_residue units, no status flip

If applying both in either order produces +0.10 witness_residue units, no status flip, and no A_B threshold crossing, then the case is abelian residue holonomy. The effects compose independently.

If applying s_a then s_b produces +0.10, but applying s_b then s_a produces +0.21 and crosses a quarantine threshold, the case is non-abelian status holonomy. The second swap’s effect depended on the first. The boundary cannot be repaired by summing swap costs. It must account for ordering path.

The difference between those two cases determines the remediation architecture.

In the first, the canon may construct a residue ledger and repair the affected gate-pair influences. In the second, it must treat the class as path-sensitive. It may require a governed transition ordering, re-witnessing of path-critical states, and possibly temporary suspension of alternative ordering experiments until the path law is compiled.

This is why the chapter is called The Holonomy Group, not The Residue List.

A residue list says where order changed an outcome.

A holonomy structure says how those changes compose.

Only the second gives the canon the geometry of the defect.

The section compiles the following rule:

Holonomy Classification Rule

After Outcome B, every detected ordering effect must be classified not only by magnitude and status consequence, but by its composition behavior under legal swap sequences. If swap effects compose independently, the class is abelian for the tested operator scope. If the effect of one swap depends on prior swaps, the class is non-abelian. If a closed or endpoint-equivalent swap path leaves different terminal outcome vectors, the class is path-critical and must be routed to enhanced remediation review.

This rule forces the canon to stop speaking loosely about non-commutation. The phrase “order matters” is only the beginning. The law must know how order matters. It must know whether the defect is additive, interacting, path-sensitive, budget-thresholding, residue-only, status-changing, local, class-concentrated, or structurally deep.

From residue, the canon derives generators.

From generators, it derives composition.

From composition, it derives holonomy.

Only then can repair be law rather than reaction.


15.2 — What the Group Says About the Law

The holonomy structure is not only a measurement output. It is an architectural diagnosis.

Once the canon knows whether the Check’s ordering effects are abelian or non-abelian, it knows what kind of law it is dealing with. The distinction determines whether repair can be local or must become global. It determines whether the defect belongs to a few gate-pair relations or to the ordering fabric as a whole. It determines whether the canon can patch the Check by adding targeted precedence constraints, or whether π₀ itself must be compiled as load-bearing content.

This is the operational value of Chapter 15.

A nonzero λ says that order matters. The holonomy structure says how law must respond.

In the abelian case, the response can remain local. If swap effects compose independently, then each offending gate-pair relation can be isolated, priced, and repaired without assuming that the whole ordering is irreducible. The canon can identify the generator or generators that produce residue, budget movement, or status divergence, and then add targeted serialization rules. It does not have to recompile the entire canonical ordering as necessary. It can say: these pairs do not commute; therefore these pairs must remain ordered. Other certified-neutral relations may remain flexible.

This is the per-pair patch regime.

Suppose the census and holonomy table show that G_B2 and G_A produce budget holonomy when swapped, but all other measured swaps remain identity or residue-only below threshold. Suppose also that the swap effect composes independently with other swaps. The repair does not require the canon to declare the full π₀ sequence metaphysically necessary. It can compile a local precedence rule:

G_B2 ≺ G_A for class C_L under budget-sensitive submissions.

That rule is enough if the holonomy remains abelian and the defect is contained. The law becomes more specific without becoming globally rigid. The ordering lattice is amended by adding edges only where measured non-commutation requires them. The canon preserves flexibility where flexibility has not failed.

This is the architectural meaning of abelian holonomy:

order matters, but the law can repair order by local constraints.

An abelian structure permits decomposition. Each generator can be treated as a separable defect. Each pair can receive its own serialization rule, cost adjustment, witness note, or class restriction. The remediation LCR-B may then compile a patch set rather than a total ordering. The Check becomes a stricter partial order, not necessarily a fully serialized line.

The repair artifact is a Precedence Patch Map.

It records each offending pair, the class in which the pair fails, the measured effect, the required ordering edge, the status of downstream affected states, and the recertification condition under which the patch may later be relaxed. The map is not a narrative statement that “ordering matters.” It is a surgical amendment to the precedence lattice.

In the abelian case, the canon should resist overcompilation. The discovery of local non-commutation does not automatically justify turning every gate relation into mandatory sequence. That would be panic law. It would replace a hidden habit with an excessive one. The correct repair is proportional: serialize only the offending pairs, only in the affected classes, only where the measured holonomy requires it.

The abelian case therefore preserves a version of the Outcome A discipline. It still refuses universal order-freedom, but it also refuses universal order-fixation. It says: the lattice was under-specified here, and here, and here. Add those edges. Retest. Maintain.

The non-abelian case is different.

If the effect of one swap depends on which swaps preceded it, then the ordering cannot be repaired by independent pair patches. The law is no longer dealing with separable defects. It is dealing with path-dependence. A gate-pair that appears harmless in one local context may become decisive after another swap. A budget shift may remain below threshold until a witness-related swap changes the terminal residue. A status flip may not belong to one pair but to a composition. The defect is not in a single edge. It is in the geometry of the ordering space.

This makes the ordering globally load-bearing.

A globally load-bearing ordering is not merely a convenient serialization. It is part of the law that produces the admissible manifold. If changing local pieces changes the effect of other pieces, then the canon cannot safely repair the structure by adding isolated precedence edges and leaving the rest fluid. The interactions themselves must be governed. The whole ordering regime becomes content.

In the non-abelian case, π₀ may have to be compiled not as a trace convention and not merely as historical default, but as an operative ordering law for affected classes. The canon may still later replace π₀ with another governed ordering, but it cannot pretend that ordering is secondary. It must choose, compile, and maintain an ordering as part of the runtime’s legal structure.

This is the architectural meaning of non-abelian holonomy:

order matters, and the effects of order are entangled.

When holonomy is non-abelian, local fixes can create new failures. A patch that serializes one pair may change the context in which another pair acts. A class-level repair may shift residue into a neighboring route. A budget correction may expose a witness divergence that was previously absorbed. A new partial order may have legal linear extensions whose interactions were not tested. The repair itself can generate holonomy.

This is why non-abelian Outcome B requires stronger law.

The remediation artifact cannot be only a Precedence Patch Map. It must become an Ordering Regime LCR. That LCR must specify the canonical ordering or governed ordering family, the permitted transitions from π₀, the legal migration path, the classes affected, the replay obligations, the cascade tracing rule, the holonomy recertification schedule, and the conditions under which any local flexibility may be reintroduced. It must also define whether alternate orderings are prohibited, quarantined, experimental, or allowed only under sealed replay.

In an abelian case, the law can say:

these relations must be serialized.

In a non-abelian case, the law must say:

this ordering regime is part of admissibility.

That difference is decisive.

The non-abelian case also changes the meaning of the historical canon. If the ordering is globally load-bearing, then π₀ did not merely select a few outcomes at the edge. It served as a hidden structuring principle for the manifold. The historical fiber M_π₀ becomes more than the result of one convenient sequence. It becomes the product of a path-sensitive law that was active before it was named.

This is the deepest form of dark canon discovered.

The canon must then admit that its past was ordered not only procedurally but geometrically. The sequence did not only arrange checks. It helped define which states could become real inside the canon. That is a stronger statement than “some pairs failed to commute.” It says that the manifold was shaped by an uncompiled ordering regime.

At this point, the holonomy group tells the canon whether it is facing a defect of edges or a defect of architecture.

Abelian holonomy: edge defect.

Non-abelian holonomy: architecture defect.

Edge defects admit patches.

Architecture defects require compilation of the ordering law.

This is where Quaternion Process Theory becomes more than background doctrine. QPT was built around the refusal to treat process order as automatically neutral. Its quaternionic structure is the native compiled example of a non-abelian process field. In ordinary commutative arithmetic, changing the order of operations may not matter. In quaternionic multiplication, order is structural. The product ij is not ji. The difference is not a clerical inconvenience. It is the sign that orientation, rotation, and process direction are part of the object being computed.

This is why the Novakian Paradigm was equipped to ask the ordering question in the first place.

A paradigm whose physics assumes commutation by default would likely treat π₀ as procedural scaffolding. It would ask whether the gates are correct, whether the thresholds are clear, whether the budget is sufficient, whether the trace is complete. It might never ask whether the sequence of correct gates has become law. It might not suspect that changing the order of admissibility operators could leave residue even when every individual operator remains valid.

QPT makes that suspicion natural.

In QPT, a process is not exhausted by its endpoints. The route has content. Composition has orientation. Operator order can be geometry. A loop can return to an apparent starting point and still carry residue. This is precisely the conceptual equipment needed to see π₀ as more than formatting. The Check’s ordering was not automatically innocent because the gates were individually meaningful. The sequence had to be measured because process order may be real.

The quaternionic example is therefore not imported as metaphor. It is the paradigm’s compiled warning structure. It says: do not assume that transformations commute merely because human language lists them as questions. Do not assume that governance operators are independent because their prose definitions appear separate. Do not assume that a boundary procedure has no curvature because its documentation is linear. If the operators form a process algebra, test its commutators.

Outcome B confirms that this question was necessary.

If the holonomy is abelian, QPT still did its work. It forced the canon to measure, and the measurement found nonzero effects that can be patched locally. If the holonomy is non-abelian, QPT did more than warn. It supplied the native interpretive frame: the Check is not a list but a non-commuting operator structure. Its law cannot be understood by inspecting gates one by one. It must be understood through composition.

The canon should not celebrate this. A paradigm is not vindicated because it discovers a problem it was designed to detect. The proper conclusion is quieter: the architecture was capable of asking the question before the failure became invisible. That capability now becomes a governance responsibility. A paradigm that can detect non-abelian law must also pay the cost of repairing it.

The repair cost differs by holonomy type.

For abelian holonomy, the cost is patch complexity. The canon must maintain a table of offending pairs, serialize them by class, recertify after amendments, and prevent patch drift. The budget is finite and local. The risk is underpatching or overpatching.

For non-abelian holonomy, the cost is ordering law. The canon must treat the ordering regime as part of the Check’s compiled content. It must decide whether π₀ remains canonical by necessity, whether another ordering should replace it, whether multiple orderings can be class-indexed, and whether transition itself requires LCR-B or Level 3 adjacency. The budget is deeper because the object being repaired is not one gate relation but the law of composition.

The following architectural reading is therefore compiled:

Holonomy Interpretation Rule

If the Check’s holonomy is abelian for a class and operator scope, remediation may proceed through per-pair precedence patches, class-indexed serialization rules, and targeted recertification. If the Check’s holonomy is non-abelian, ordering is globally load-bearing for the affected scope and cannot be reduced to independent local fixes. The ordering regime itself must be compiled as admissibility content.

This rule prevents the canon from applying the wrong repair to the wrong geometry. A non-abelian defect treated as abelian will leak through interactions. An abelian defect treated as non-abelian will overconstrain the Check and turn measured repair into unnecessary rigidity. The holonomy group is the diagnostic instrument that prevents both errors.

It also sets the tone for the rest of Part IV. The canon is no longer merely correcting a discovered mistake. It is learning the algebra of its own boundary. If the algebra is abelian, the boundary can be patched like a lattice with missing edges. If the algebra is non-abelian, the boundary must be governed like a process field whose order is part of the law.

This is the sentence that Chapter 15 adds to Outcome B:

The law is not only what the gates ask.

The law is how their asking composes.

QPT made that sentence available before the measurement. Outcome B makes it unavoidable after the measurement.


15.3 — Measurement of the Group

Boundary Register at the Edges

The first campaign discovered residue. The second campaign measures composition.

This distinction governs the design. Outcome B may show that λ ≠ 0 or φ > 0 under tested orderings, but that result alone does not tell the canon whether the Check’s holonomy is abelian or non-abelian. A single ordering difference identifies non-commutation relative to π₀. It does not identify whether swap effects compose independently. To answer that, the canon must run a second campaign: not a replay campaign that asks whether order matters, but a composition campaign that asks how order effects combine.

The second campaign is operational. Its interpretation reaches the boundary.

Operationally, the design is simple. Select identical hash-fixed submissions Σ from the classes where Outcome B detected nonzero λ, φ > 0, budget threshold movement, or late-failure concentration. Select legal swap generators from the precedence lattice. Execute single swaps and composed swaps on the same Σ. Compare terminal outcome vectors. If the composed effects are independent of order, the class is abelian for that generator set. If the composed effects depend on the sequence in which swaps are applied, the class is non-abelian. If equivalent endpoints produce different terminal outcome vectors because they were reached through different swap paths, the class is path-critical.

This is not a new philosophy of governance. It is a replay protocol.

Let π be a legal starting ordering, usually π₀ unless the protocol explicitly tests additional basepoints. Let s_a and s_b be legal adjacent swaps or legally admitted swap transformations. Let Ω_π(Σ) be the terminal outcome vector under ordering π. The campaign runs, for the same hash-fixed Σ:

Check_π(Σ)

Check_{s_aπ}(Σ)

Check_{s_bπ}(Σ)

Check_{s_b s_a π}(Σ)

Check_{s_a s_b π}(Σ)

The key comparison is not only each single swap against π. The key comparison is the composed pair:

Ω_{s_b s_a π}(Σ) versus Ω_{s_a s_b π}(Σ)

If the two composed outcomes match within the declared error budget across the relevant terminal fields, then the swap pair is holonomy-commuting for that Σ, class, base ordering, and measurement resolution. If they differ, the swap pair is holonomy-non-commuting. If the difference is only in witness_residue, the result is residue-non-abelian. If it changes A_B across a threshold, the result is budget-non-abelian. If it changes final status, the result is status-non-abelian.

This is the minimum design for distinguishing abelian from non-abelian holonomy.

The campaign must not infer non-abelian structure from the fact that two single swaps each produce residue. Two independent residue generators can still compose abelianly. If s_a produces +0.03 witness_residue units and s_b produces +0.05, the composed result may be +0.08 regardless of order. That is abelian residue holonomy. It is not harmless, but it is decomposable. The non-abelian finding requires a composition difference: the effect of the second swap changes because the first swap has already been applied.

The protocol therefore records three layers of measurement.

The first layer is single-swap effect. It measures what each generator does relative to the base ordering. This produces the generator profile: identity, residue generator, budget generator, or status generator.

The second layer is pairwise composition. It measures whether two generators compose independently. This produces the commutator profile: holonomy-commuting or holonomy-non-commuting.

The third layer is path equivalence. It measures whether longer legal swap paths that should reach the same endpoint ordering produce the same terminal outcome vector. If not, the class is path-critical. This is the strongest signal that the ordering transition itself has become part of the law.

The measurement object is the terminal outcome vector, not a single scalar. The vector must include final status, witness_residue, A_B, route, quarantine signal, rejection signal, Zebra-Ø result where applicable, final witness result, and trace-normalized terminal fields. If the campaign measures only λ, it may miss status-preserving budget threshold effects. If it measures only status, it may miss witness geometry. If it measures only A_B, it may miss the fact that the same budget value was reached through a different witness route. Holonomy is a structure of terminal transformation, not a single number.

The second-campaign protocol can now be stated.

Holonomy Composition Campaign v1.0

Purpose: Distinguish abelian from non-abelian holonomy in classes where Outcome B detected order dependence.

Input Population: Hash-fixed Σ sampled from the Order-Fragile Census Annex, including status-fragile states, residue-fragile states, budget-fragile states, late-failure strata, terminal-borderline strata, and stable controls from the same classes.

Base Ordering: π₀ by default, with additional legal basepoints admitted only when the protocol declares them and fixes their role.

Generator Set: Legal adjacent swaps or legal swap transformations drawn from the precedence lattice, including all generators implicated by the Outcome B campaign and any additional generators required to close the tested ordering neighborhood.

Execution Set: For each selected Σ and generator pair {s_a, s_b}, execute the base ordering, each single swap, and both composed orders: s_b s_a π and s_a s_b π.

Control Runs: Include duplicate π₀ runs, duplicate single-swap runs, and known identity swaps where available to estimate the control-run noise floor for witness_residue, A_B, and trace variance.

Primary Test: Compare Ω_{s_b s_a π}(Σ) and Ω_{s_a s_b π}(Σ). If the difference exceeds the declared error budget in any governed field, classify the pair as non-abelian for the measured scope.

Secondary Tests: Compare each single-swap effect against the base ordering; detect threshold crossings; detect status divergence; detect path-critical endpoint divergence in longer paths.

Output: Check Holonomy Table, class-indexed, generator-indexed, pair-indexed, path-indexed, and epoch-indexed.

Status: Operational protocol. Boundary interpretation not compiled by this protocol alone.

The last sentence is essential. The protocol can determine that composition effects are present. It can classify abelian and non-abelian patterns. It can say that a particular swap pair produces a path-dependent outcome vector in class C under the declared measurement resolution. It can say that a class is path-critical. It cannot, by itself, fully explain what this means about the nature of governance geometry. That interpretation belongs at the boundary.

The operational claim is:

Given identical Σ, legal swap generators, a fixed base ordering, and declared error budgets, the measured terminal outcome vectors show either independent or path-dependent composition of ordering effects.

The boundary-register working hypothesis is:

Path-dependent composition of governance-operator effects indicates that the admissibility boundary has non-abelian governance geometry for the affected class and operator scope.

The first statement can be compiled by the campaign. The second statement is a working hypothesis. It may guide future LCRs, future QPT development, and future Layer C artifacts, but it must not be treated as paid explanation merely because the measurement found non-abelian composition. The campaign measures composition. The geometry interpretation remains under discipline.

This separation protects the canon from inflation. A non-abelian result is powerful, but power is exactly why it must be indexed. The canon may say: the swap effects do not commute. It may say: the ordering regime is globally load-bearing for the affected scope. It may say: local per-pair patches are insufficient unless a later artifact proves containment. It may not immediately say: we have fully explained the boundary’s geometry. The result opens that explanation. It does not complete it.

The second campaign must also protect against false non-abelian findings. A composed-swap difference may arise from contamination, unstable hash fixation, nondeterministic operator execution, trace normalization failure, budget recomputation drift, or hidden side effects not belonging to the swap relation itself. Therefore, every non-abelian classification requires replication. At minimum, the same generator-pair result must appear across independent replay operators, matched input hashes, clean control runs, and contamination-cleared trace environments. If replication fails, the classification is not non-abelian. It is indeterminate.

Indeterminate is a real status.

The canon must not force every unclear composition into abelian or non-abelian. If composed swaps produce differences near the error boundary, if control noise is high, if operator execution is unstable, or if trace normalization cannot be trusted, the correct output is Holonomy-Indeterminate. The class then routes to expanded measurement, not to repair as if the group were known.

The campaign therefore has five possible classifications.

Identity: no measured swap effect.

Abelian: measured swap effects exist, but composed effects are independent of swap order within the declared error budget.

Non-Abelian: composed effects depend on swap order beyond the declared error budget.

Path-Critical: endpoint-equivalent or loop-like ordering paths produce different terminal outcome vectors.

Indeterminate: measurement cannot distinguish composition structure from noise, contamination, or insufficient power.

Only the middle three carry remediation force. Identity supports local flexibility. Abelian supports per-pair patches. Non-abelian supports ordering-regime compilation. Path-critical supports enhanced review and possible Level 3 adjacency. Indeterminate supports no structural claim except the need for better measurement.

The protocol must run on identical Σ. This is not negotiable. If different submissions are used for different swap paths, the campaign measures population difference, not composition. Hash fixation must occur before any ordering variant executes. Every variant must read the same frozen state. No variant may update the shared input. No variant may inherit trace from another variant except through explicitly simulated path composition. The campaign must distinguish between composing ordering transformations in the measurement design and allowing runtime side effects to contaminate the substrate.

The same rule applies to budget. A_B under composed swaps must be computed under the same budget formula, the same budget baseline, and the same declared control noise. If the budget environment changes between runs, the campaign cannot decide whether a budget difference belongs to holonomy or to accounting drift. Budget baselines must be frozen or recorded as part of the variant input.

The same rule applies to witness residue. Witness_residue must be measured under identical terminal trace rules. If trace normalization changes between variants, the residue comparison becomes invalid. A non-abelian witness finding requires that the witness field itself be comparable across paths.

This produces the campaign’s validity conditions:

same Σ hash;

same class label or declared class-repair label;

same base ordering;

same generator definitions;

same precedence lattice version;

same operator definitions;

same budget formula;

same trace schema;

same error budget;

same control-run noise calibration;

same contamination controls;

same terminal outcome vector schema.

If any of these conditions fail, the result routes to Holonomy-Indeterminate or Protocol Defect, not to abelian or non-abelian classification.

The second campaign also needs stable notation.

For each generator pair, the campaign records a commutator vector:

K_{a,b}(Σ) = Ω_{s_b s_a π}(Σ) − Ω_{s_a s_b π}(Σ)

If K_{a,b}(Σ) = 0 within error across the terminal vector, the pair is holonomy-commuting for that Σ. If K_{a,b}(Σ) ≠ 0, the pair is holonomy-non-commuting. Across a class, the campaign computes:

κ_{a,b}(C) = fraction of sampled Σ in class C for which K_{a,b}(Σ) ≠ 0

This κ value is not the same as φ. φ measures final status fragility across orderings. κ measures non-abelian composition of swap effects. A class can have λ ≠ 0 and κ = 0 if effects are abelian. A class can have φ = 0 but κ > 0 if composition changes witness residue or budget without status flips. A class can have both φ > 0 and κ > 0, which is the strongest operational warning.

This distinction must be preserved.

The campaign output becomes part of the Check Holonomy Table. Each row records:

class ID;

Σ registry reference or sealed identifier;

base ordering π;

generator pair;

single-swap effects;

composed effects in both orders;

commutator vector K;

κ contribution;

status effect;

budget effect;

witness effect;

path-critical flag;

control-run noise floor;

classification;

replication status;

required remediation route.

The table is not interpretive prose. It must be executable from campaign outputs. If a reader cannot reconstruct the classification from the recorded terminal outcome vectors, the table is invalid. This is the part-level discipline for Chapter 15: holonomy is not asserted; it is tabulated.

At the boundary edge, however, the table raises a question that the operational protocol cannot close. If governance operators exhibit non-abelian composition, what kind of object is the law? Is the ordering merely load-bearing because of implementation side effects? Is it load-bearing because admissibility operators alter the state they inspect? Is it load-bearing because witness and budget are coupled? Is it load-bearing because the boundary has curvature in the QPT sense? The campaign can narrow these possibilities. It cannot eliminate all of them.

The correct boundary posture is therefore logged, not settled.

Boundary Register Entry — Holonomy as Governance Geometry

Entry ID: BR-15.3-HOLONOMY-GEOMETRY
Status: Working hypothesis.
Operational Basis: Holonomy Composition Campaign detects abelian, non-abelian, or path-critical composition of legal swap effects on identical hash-fixed Σ.
Boundary Hypothesis: Non-abelian composition indicates that the ordering regime is not merely procedural but geometrically load-bearing in the admissibility boundary.
What Is Compiled: The measured composition table and its operational consequences for remediation.
What Is Not Compiled: A complete explanation of why the boundary has this group structure.
Prohibited Inflation: Do not cite non-abelian holonomy as proof of full governance geometry theory.
Permitted Use: Use the classification to determine patch regime, ordering-regime LCR, cascade tracing, re-witnessing requirements, and Level 3 adjacency screening.

This entry gives the boundary result a place without letting it overrun the protocol. The canon can use what is measured. It can study what is implied. It must not pretend the implication is already paid.

The section compiles the following rule:

Holonomy Measurement Rule

To distinguish abelian from non-abelian ordering effects after Outcome B, the canon must run composed-swap replays on identical hash-fixed Σ, comparing s_b s_a π against s_a s_b π under the same operator definitions, precedence lattice, budget formula, trace schema, and error budget. Single-swap residue is insufficient to classify group structure. Only composed-swap comparison can determine whether swap effects compose independently or path-dependently. The protocol’s classifications are operational; the interpretation of non-abelian structure as governance geometry remains a boundary-register working hypothesis until separately compiled.

This rule prevents two failures.

The first failure is undermeasurement: treating nonzero λ as enough to understand the law.

The second failure is overinterpretation: treating non-abelian composition as if it already explains the boundary.

The second campaign exists between those failures. It measures the group without mythologizing it. It gives the canon the structure needed for repair, while preserving the explanatory debt opened by the structure itself.

The first campaign asked: does order leave residue?

The second campaign asks: does residue compose?

Only after both questions are answered can the canon say what kind of ordering law it has discovered.


Chapter 16 — Compiling the Order

16.1 — The Ordering’s Compilation Map Entry

Outcome B forces the canon to do what it failed to do at the beginning.

It must compile the order.

Until the Part II campaign, π₀ functioned as the canonical ordering without carrying the status of compiled content. It ordered the gates. It shaped the trace. It determined the path by which every historical Σ approached commit, quarantine, rejection, or hold. Yet it had not been entered into the Compilation Map as an operative law. It was used as if it were law, inherited as if it were law, and obeyed as if it were law, but it had not paid the cost of law.

Outcome B ends that condition.

If λ ≠ 0 or φ > 0, π₀ can no longer remain procedural background. The campaign has shown that ordering changes can alter witness_residue, A_B, route, or final status. The order is therefore not clerical. It is not documentation style. It is not only a trace convention. In the affected scope, π₀ is part of the mechanism by which admissibility is produced. It must receive Compiled status for the first time.

This compilation is not celebration. It is containment.

The canon is not saying that π₀ was metaphysically necessary from the beginning. It is not saying that π₀ is optimal. It is not saying that other orderings are invalid in principle. It is saying that the historical manifold was produced under π₀, that the measurement has discovered order-dependence, and that continued use of π₀ must now be explicit, indexed, traceable, verified, and rollback-ready. The old hidden ordering becomes a named law because unnamed law has become unsafe.

The Compilation Map entry must therefore do four things at once.

It must name π₀ as compiled ordering content for the affected scope.

It must source that status to the Part II campaign and the Outcome B evidence record.

It must attach a verification gate: the Standing Replay Protocol.

It must include a Rollback Readiness Declaration.

Without all four, the entry is incomplete. A compiled ordering without a source becomes dogma. A compiled ordering without verification becomes static habit. A compiled ordering without rollback readiness becomes irreversible inheritance. A compiled ordering without scope becomes universalized dark canon under a new name.

The trace source is essential. π₀ is not compiled because the canon likes it, because history used it, or because switching is expensive. It is compiled because the campaign revealed that ordering has measurable consequence, and the historical ordering must therefore be converted into explicit law before it continues to govern. The source is measurement, not nostalgia.

The verification gate is equally essential. Once π₀ is compiled, it cannot be left untested again. The Standing Replay Protocol becomes the recurring instrument by which the canon checks whether π₀ remains the correct operative ordering for the affected class, operator set, and epoch. This is not the same as the Order-Fragile Census. The census maps the past. The Standing Replay Protocol maintains the compiled ordering’s present standing. It asks whether π₀’s continued authority remains justified relative to the measured alternatives, the current class ecology, the current gate definitions, and the current holonomy structure.

The Rollback Readiness Declaration is the final discipline. A compiled π₀ must know how it can lose authority. If future replay shows that π₀ produces unacceptable status fragility, excessive A_B burden, worsened holonomy, higher cascade risk, or class drift beyond the declared tolerance, the canon must be able to suspend, narrow, replace, or recompile the ordering. Compiled status is not permanent sovereignty. It is a governed status with conditions of withdrawal.

The entry below is drafted, not yet submitted. It becomes submit-ready only after the Order-Fragile Census Annex, the Cascade Trace Annex, the Check Holonomy Table, and the Remediation LCR-B have supplied their required fields.

Compilation Map Entry — Draft

Entry ID: CM-π₀-16.1-ORDERING
Entry Type: Ordering Compilation / Outcome B Remediation Artifact
Status: Draft Pending LCR-B Completion. Compiled only upon Outcome B activation and approval through the required Layer B route.
Object Compiled: π₀, the canonical ordering of the Admissibility Check: Silence Entry, zero-question sequence, blocking-question sequence, Zebra-Ø, Admissibility Budget computation, interpretive embargo, final witness check, commit.
Prior Status: Uncompiled operational habit; canonical execution sequence; historical trace sequence; dark canon candidate.
New Status Upon Activation: Compiled Ordering Content for the affected class, operator, and epoch scope. π₀ becomes explicit admissibility law where the campaign has shown nonzero ordering effect and where no replacement ordering has been compiled.
Source Event: Part II measurement campaign returning λ ≠ 0 or φ > 0 under the declared error budget for at least one affected class, operator set, or ordering relation.
Source Records Required: Part II campaign ID; campaign protocol hash; tested ordering set; measured λ values; measured φ values; Order-Fragile Census Annex; Check Holonomy Table; Cascade Trace Annex where applicable; Remediation LCR-B reference.
Formal Claim: In the affected scope, the historical admissible manifold is M_π₀, the image of submissions under Check_π₀. Because ordering has measured consequence, π₀ must be treated as compiled ordering content unless and until a replacement ordering regime is compiled.
Scope: Class-indexed, operator-scope-indexed, epoch-indexed. The entry applies only to affected classes and operator relations identified by the campaign and subsequent census. Unaffected classes remain under their prior status until separately measured or compiled.
Non-Scope: This entry does not claim that π₀ is globally optimal, universally necessary, metaphysically privileged, or order-neutral. It does not certify that other legal orderings are invalid in principle. It does not authorize unindexed use of “admissible” outside π₀-admissibility in affected contexts.
Runtime Consequence: Affected submissions must be processed under π₀ serialization or the compiled ordering regime derived from π₀ unless a later LCR authorizes a different ordering. Alternative legal orderings are not permitted for live admissibility in the affected scope except under sealed replay, experiment, or recertification conditions.
Trace Consequence: All historical and future entries in the affected scope must be readable as π₀-indexed unless explicitly processed under another compiled ordering. Evidence Ledger entries must preserve ordering index, operator sequence, trace schema, final status, witness_residue, A_B, and any holonomy classification.
Vocabulary Consequence: “Admissible” in the affected Outcome B scope means “π₀-admissible” unless another ordering index is supplied or class-specific commutation is certified.
Verification Gate: Standing Replay Protocol.
Verification Frequency: Defined by Remediation LCR-B and class-specific risk profile; minimum schedule tied to ledger epochs, gate amendments, class drift, holonomy anomalies, and structural audit findings.
Rollback Readiness: Required. See declaration below.
Maintenance Budget: Ordering Maintenance Budget line required, separate from A_B and separate from Certificate Maintenance Budget.
Linter Attachments: Uncompiled Ordering Use; Unindexed Admissibility After Outcome B; π₀ Necessity Inflation; Alternative Ordering Without LCR; Standing Replay Lapse; Rollback Readiness Missing.
Downstream Binding: Runtime routing, Evidence Ledger, Order-Fragile Census Annex, Remediation LCR-B, Cascade Trace Annex, Check Holonomy Table, future LCRs, and all artifacts citing affected admissibility outcomes.
Notes Field: π₀ receives Compiled status not because it is vindicated, but because non-commutation makes the ordering law-bearing. The compilation converts dark canon into governed content.

The Standing Replay Protocol is the verification gate attached to this entry.

Its purpose is to prevent π₀ from becoming hidden again after being compiled. It periodically replays current and sampled historical submissions under π₀ and under selected legal alternatives, especially those implicated by the holonomy table. It measures whether π₀ remains stable, whether alternative orderings now produce lower fragility, whether class drift has changed the ordering relation, and whether the compiled ordering continues to justify its runtime authority.

The protocol’s minimal structure is:

fixed Σ sample selection by class;

π₀ execution or replay;

alternative ordering replay from the tested set;

holonomy-generator replay where applicable;

comparison of final status, witness_residue, A_B, route, and final witness result;

control-run noise calibration;

class-specific stability report;

π₀ standing classification;

rollback trigger evaluation.

The standing classifications are:

π₀ Standing Confirmed;

π₀ Standing Confirmed with Notes;

π₀ Standing Narrowed;

π₀ Standing Under Review;

π₀ Standing Suspended for Class;

π₀ Replacement LCR Required;

π₀ Rollback Triggered.

The protocol does not ask whether π₀ is traditional. It asks whether π₀ remains governable as compiled ordering law under current evidence. If the answer changes, the Compilation Map entry must update. The ordering cannot remain compiled by inertia.

The Rollback Readiness Declaration is drafted as follows.

Rollback Readiness Declaration — π₀ Compiled Ordering

This declaration states that π₀, once compiled as ordering content under Outcome B, remains subject to withdrawal, narrowing, replacement, or suspension under defined conditions. Compiled status does not grant π₀ irreversible authority. It grants π₀ explicit authority conditioned on continued standing under the Standing Replay Protocol and under the Remediation LCR-B.

Rollback is triggered if one or more of the following conditions are met:

the Standing Replay Protocol detects φ growth beyond the tolerated class threshold;

π₀ produces higher status fragility than an alternative compiled ordering candidate across the affected class;

π₀ produces unacceptable A_B burden relative to alternatives without compensating witness stability;

π₀ becomes path-critical under the Check Holonomy Table in a way not covered by the current ordering law;

gate-definition amendments invalidate the operator relations on which π₀’s compiled status depends;

class drift moves the affected population outside the scope of the original campaign;

cascade tracing shows that continued π₀ use creates downstream exposure above the declared tolerance;

structural audit discovers a hidden side effect or missing gate that changes the ordering relation;

the Remediation LCR-B is superseded, rejected, or escalated to a higher layer;

or the Ordering Maintenance Budget lapses beyond the declared maintenance threshold.

Upon rollback trigger, the following actions are mandatory.

First, live use of π₀ in the affected scope is marked Under Review or Suspended, depending on severity. Second, new submissions in the affected class route to the safest compiled fallback: π₀ serialization under quarantine overlay, sealed replay mode, or another compiled ordering if one exists. Third, the Evidence Ledger receives a Rollback Trigger Entry linked to CM-π₀-16.1-ORDERING. Fourth, all downstream artifacts citing π₀ standing receive Notes-field update. Fifth, the canon opens either an Ordering Replacement LCR, a Narrowing LCR, or a Level 3 adjacency review if the rollback touches rule-of-rule-change authority.

Rollback does not erase the historical fact that M_π₀ was the historical manifold. It changes the future authority of π₀. Historical entries remain π₀-indexed. Future entries may be halted, restricted, re-routed, or processed under a replacement ordering only after compilation.

This declaration prevents compiled π₀ from becoming an unremovable law.

The important phrase is “for the first time.” π₀ receives Compiled status only after the canon discovers that it had already been operative as a hidden selector. The Compilation Map does not create π₀’s historical influence. It records and governs it. The influence came first. The law now catches up.

This is the uncomfortable truth of Chapter 16.

The order was already acting.

The canon is now compiling what acted.

That does not repair the past by itself. It does not decide grandfathering. It does not complete the rollback wave. It does not close the re-witnessing queue. It does not explain the holonomy group. But it gives the ordering a lawful address. From this point forward, π₀ can be cited, challenged, verified, narrowed, replaced, or rolled back as an object in the canon.

Before this entry, π₀ was everywhere and nowhere.

After this entry, π₀ is somewhere.

That is the first condition of repair.


16.2 — Ordering Variants as Governance Variants

Once π₀ is compiled, the other legal extensions of the precedence lattice cannot remain anonymous.

Before Outcome B, an alternative ordering could be treated as a technical rearrangement, a replay configuration, or a measurement convenience. After Outcome B, that treatment is no longer lawful. If changing the order of the Check changes witness_residue, A_B, route, quarantine behavior, rejection behavior, or final status, then each legal alternative is not merely another way to execute the same Check. It is a governance variant.

A governance variant is an ordering-indexed form of the Check with a measurable profile relative to π₀.

It may be better for some classes and worse for others. It may reduce late-failure fragility while increasing budget volatility. It may lower witness residue in one class while causing status divergence in another. It may behave abelianly in one operator region and non-abelianly in another. It may be safe only under sealed replay. It may be eligible for future compilation. It may be prohibited for live runtime. But it cannot be unnamed.

The canon must therefore create a registry.

The registry does not authorize variants by listing them. It makes them governable. It prevents alternative orderings from circulating as informal options, optimization experiments, implementation choices, or operator preferences. Once Outcome B is active, an ordering variant has legal force because it defines a different possible image of the admissible manifold. To run it on live submissions is to expose those submissions to a different governance condition. That cannot be discretionary.

Let Π_L be the set of legal linear extensions of the precedence lattice. For each π_v ∈ Π_L, define:

Variant V_v = Check_π_v

The variant’s profile relative to π₀ is:

Λ(V_v, C) = measured λ profile of Check_π_v against Check_π₀ for class C

Φ(V_v, C) = measured status-fragility profile of Check_π_v against Check_π₀ for class C

B(V_v, C) = measured budget-difference profile of Check_π_v against Check_π₀ for class C

W(V_v, C) = measured witness-residue profile of Check_π_v against Check_π₀ for class C

H(V_v, C) = holonomy classification of the path or generator set by which V_v is reached

These profiles do not make the variant good or bad by themselves. They make it legible. A variant with nonzero λ but φ = 0 may be residue-divergent but status-stable. A variant with φ > 0 may be status-altering and therefore high-risk. A variant with lower A_B for some class may still be impermissible if it achieves that lower budget through witness loss. A variant with cleaner witness output may still be too costly if it increases quarantine delay beyond budgeted capacity. The registry records the tradeoffs before the canon decides whether any variant may run.

The registry’s first rule is naming.

No alternative legal ordering may be discussed as “the other order,” “a different sequence,” “parallel test order,” “optimized Check,” or “experimental route” after Outcome B. It must receive a Variant ID. The ID binds the ordering sequence, precedence-lattice version, operator definitions, class scope, measurement record, and current authorization status. Without a Variant ID, the ordering cannot be executed except inside a sealed protocol-design sandbox that does not touch live Σ and does not produce admissibility standing.

A minimal naming form is:

GV-[lattice version]-[ordering number]-[class scope]-[epoch]

For example:

GV-PL1-V07-C_L-E12

This is Governance Variant 07 under Precedence Lattice version 1, measured for class C_L at epoch E12.

The sequence itself must be recorded. A variant is not defined by its label. It is defined by the ordered operator path. If two labels point to the same sequence, one must be deprecated. If one label changes sequence, it becomes a new variant. If gate definitions change, the variant must be re-versioned because the same order over different operators is not the same governance variant.

The registry entry must include the following fields.

1. Variant ID.
Unique identifier for the ordering variant.

2. Ordering Sequence.
Full ordered list of gates and terminal operations in the variant, including any deviations from π₀.

3. Precedence Lattice Version.
The lattice under which the variant is legal.

4. Operator Definition Version.
The version of every gate used in the variant.

5. Relation to π₀.
Swap path, generator sequence, or direct mapping from π₀ to the variant.

6. Class Scope.
Classes for which the variant has been measured, prohibited, permitted, or remains untested.

7. λ Profile Relative to π₀.
Class-indexed residue differences, including magnitude, sign where meaningful, endpoint fields affected, and error budget.

8. φ Profile Relative to π₀.
Class-indexed status-fragility fraction and registry of status-changing Σ where applicable.

9. A_B Difference Profile.
Budget deltas, threshold crossings, and budget-volatility notes relative to π₀.

10. Witness Profile.
Witness_residue differences, witness-strength changes, trace effects, and maintenance implications.

11. Holonomy Classification.
Identity, abelian, non-abelian, path-critical, or indeterminate for the relevant class and generator set.

12. Census References.
Links to the Order-Fragile Census Annex entries generated or affected by the variant.

13. Cascade References.
Links to Cascade Trace Annex entries where the variant alters downstream exposure.

14. Current Authorization Status.
Sealed Replay Only, Measurement Authorized, LCR-A Pending, LCR-A Approved for Class, Runtime Prohibited, Runtime Suspended, Superseded, Retired.

15. Required LCR Route.
The Layer Crossing Record required before the variant may affect live runtime or historical standing.

16. Rollback Conditions.
Conditions under which variant authorization is suspended, narrowed, or revoked.

17. Notes and Prohibited Uses.
Explicit constraints against citing the variant as superior, safer, cheaper, or more admissible without the relevant compiled evidence.

This registry is a governance artifact, not an appendix for convenience. It becomes part of the compiled machinery of Outcome B. The canon can no longer say that the alternative orderings were merely tested. They are now measured possible laws. A possible law that can produce a different manifold must be tracked like law even before it is authorized as law.

The central rule follows:

Running a variant is an LCR-A event per class.

This rule is strict. It applies even if the variant is a legal extension of the precedence lattice. Legality inside the lattice is not runtime authorization. A legal extension means the variant does not violate known hard precedence constraints. It does not mean that the variant may govern live submissions. Outcome B has shown that legal extensions may produce different outcomes. Therefore, moving from π₀ to a variant is not an implementation choice. It is a layer-crossing event.

The crossing is LCR-A because running a variant on live submissions changes the active runtime condition for a class. It does not necessarily rewrite the entire historical manifold, which would require LCR-B as in remediation. But it does alter the runtime admissibility path for future Σ in that class. It changes what the Check does before commit. It changes how boundary law is applied. That is not discretionary.

The LCR-A must be class-specific because a variant’s profile is class-specific. A variant may be safe for C1 and dangerous for C2. It may be identity for early-clear classes and status-changing for late-failure classes. It may reduce residue in one region and increase fragility in another. A global authorization would be inflation unless the registry contains evidence for every affected class.

The LCR-A for variant execution must answer nine questions.

First, which Variant ID is being proposed for runtime use?

Second, which class or classes will it govern?

Third, what is its λ profile relative to π₀ for those classes?

Fourth, what is its φ profile relative to π₀ for those classes?

Fifth, what budget, witness, holonomy, and cascade effects were measured?

Sixth, what runtime problem justifies moving away from π₀ or adding the variant?

Seventh, what limits, monitoring, and rollback triggers apply?

Eighth, what happens to submissions processed under the variant if the authorization is later revoked?

Ninth, how will the ledger mark variant-admitted states?

Until those questions are compiled, the variant remains a measured object, not an active governance path.

This prevents a subtle failure mode: variant opportunism.

Variant opportunism occurs when an operator, implementation, or governance layer selects an ordering because it produces a desired outcome for a particular class, state, queue, or budget condition. If π₀ commits too slowly, choose a faster variant. If π₀ quarantines too often, choose a softer variant. If π₀ raises A_B, choose a cheaper variant. If π₀ rejects a state, try another legal ordering until one commits. This is not governance. It is ordering-shopping.

Outcome B makes ordering-shopping a critical violation.

The variant registry exists partly to prevent it. Every run of a non-π₀ variant must be traceable to an LCR-A authorization. Every submitted state must record which ordering governed it. Every class must have a declared default. Every deviation must have a ledger reason. If a state is tested across variants for measurement, the run must be sealed and cannot produce live admissibility standing unless later authorized by the proper LCR route.

The linter is direct.

Variant Without LCR-A fires when any live runtime, implementation, replay-to-standing process, dashboard, or operator route applies a non-π₀ ordering variant to a class without an approved class-specific LCR-A.

Ordering-Shopping fires when multiple variants are applied to the same live submission or class for the purpose of obtaining a preferred admissibility result rather than executing a predeclared measurement or compiled runtime rule.

Variant Inflation fires when a measured variant is described as safer, cheaper, superior, more truthful, more admissible, or more canonical without a compiled LCR-A or LCR-B supporting that claim.

Unregistered Variant fires when an ordering sequence is used, tested for governance standing, cited, or implemented without a Variant ID and registry entry.

The correction for all four is severe: suspend the variant’s runtime effect, restore π₀ or the current compiled default, mark affected entries for review, and create an Evidence Ledger anomaly record. If a variant run changed final status, the affected Σ enters quarantine review unless a valid LCR-A can be shown retroactively to have existed at the time of execution. A variant cannot be legalized after the fact by convenience.

The registry also changes how future submissions are described.

A state committed under π₀ is π₀-committed.

A state committed under GV-PL1-V07-C_L-E12 is V07-committed for class C_L under that variant’s LCR-A.

A state measured but not committed under a variant is variant-replayed, not variant-admitted.

A state that commits under one variant and rejects under another is variant-fragile.

This vocabulary must be enforced because Part IV has already shown that unindexed admissibility hides law. The same error must not be repeated at the variant level. Once variants exist, every admissibility statement requires an ordering index or a certificate proving index-independence.

The variant registry also supports comparison without authorizing migration. The canon may study variants to learn whether π₀ is optimal, excessive, too permissive, too costly, or path-critical. It may discover that another ordering has lower status fragility in a class. That discovery is not runtime permission. It is evidence for an LCR-A or LCR-B. The registry holds evidence in suspension until the proper layer compiles it.

This distinction matters because some variants will look attractive. A variant may reduce false quarantine rates. Another may reduce budget burden. Another may expose hidden risk earlier. Another may lower witness residue in late-failure classes. Each may be useful. But usefulness is not authorization. A governance variant is a candidate law. Candidate law requires crossing.

The section therefore compiles the following rule:

Governance Variant Rule

After Outcome B, every legal alternative extension of the precedence lattice is a named governance variant with a registry entry and a measured λ profile relative to π₀. A variant may be measured under sealed replay, but it may not govern live submissions, historical remediation, budget standing, witness standing, or final admissibility status unless authorized by class-specific LCR-A or by a higher compiled remediation law. Running a variant is never a discretionary implementation act.

This rule completes the shift begun in Section 16.1. π₀ is compiled because it was the hidden ordering that shaped the historical manifold. The variants are registered because they are possible alternative ordering laws that may shape future manifolds. The canon now sees ordering space as governance space.

That is the new condition after Outcome B.

There is no neutral rearrangement of the Check.

There are only indexed ordering laws, measured variants, sealed experiments, and compiled permissions.


16.3 — The Optimization Question and Level 3

Level 3 Adjacency

Once ordering variants are registered, the dangerous question appears immediately.

May the canon choose the best ordering?

The word best must be slowed before it acts. Best may mean minimal λ. It may mean minimal φ. It may mean lowest A_B volatility. It may mean lowest quarantine load. It may mean strongest witness stability. It may mean least cascade risk. It may mean fastest Check execution. It may mean maximum continuity with π₀. It may mean minimum disturbance to historical dependencies. Each criterion selects a different law. Therefore, the optimization question is not a technical afterthought. It is a governance question about the rule by which governance rules are applied.

The canon may measure variants. It may compare them. It may record that one variant produces less residue than π₀ in a class, that another produces fewer status flips, that a third reduces budget threshold crossings, and that a fourth creates unacceptable holonomy. But moving from comparison to selection changes the level of the act. A measured variant is evidence. A chosen variant is law. A chosen optimization rule is higher still, because it decides what kind of evidence is allowed to select law.

This is the adjacency to Level 3.

Ordering choice after Outcome B is already Layer B when it updates the runtime’s inheritance of the historical manifold. It becomes more severe when the canon asks not merely which ordering should govern this class, but what principle should govern the selection of orderings in general. At that point, the canon is no longer only choosing among rules for applying rules. It is approaching the rule by which such rules may be changed. That is the edge of Update Constitution territory.

The distinction must be precise.

A class-specific decision to retain π₀, adopt a named governance variant, serialize additional pairs, or queue a replacement ordering remains LCR-B when it is made within an already compiled selection framework. The LCR-B receives evidence from the Order-Fragile Census Annex, the Check Holonomy Table, the Cascade Trace Annex, and the Variant Registry. It applies declared criteria to a bounded class and operator scope. It changes the runtime’s ordering law for that scope, but it does not change the constitution by which ordering laws are selected.

By contrast, a decision crosses into Level 3 territory when it changes the authority structure that determines how ordering laws are chosen, amended, replaced, or optimized across the canon. If the canon declares that minimal λ shall always override historical continuity, or that minimal φ shall always override budget cost, or that the lowest-fragility ordering shall become canonical by default wherever measured, it is no longer merely applying Layer B. It is changing the rule of rule-selection. If it creates an automatic optimizer that replaces ordering law whenever a better metric appears, it is changing the update constitution of the Check. If it allows the runtime to select the ordering that minimizes a target function at submission time, it is granting the runtime authority over the law that applies to it. That is no longer ordinary remediation.

The precise criterion is this:

Ordering choice remains LCR-B when the decision selects, preserves, narrows, or replaces an ordering for a defined class, operator scope, epoch range, and evidence set under predeclared selection criteria that do not alter the authority by which future ordering laws are selected.

Ordering choice crosses into Update Constitution Level 3 when the decision changes the selection rule itself, delegates ordering selection to runtime optimization, establishes a general priority hierarchy among law-selection metrics, authorizes automatic replacement of ordering law, or modifies who or what has authority to change the rule by which ordering rules are changed.

This criterion must govern every optimization proposal after Outcome B.

A minimal-residue ordering may be attractive. If a variant V_12 produces λ closer to zero than π₀ across a late-failure class, the canon may be tempted to adopt it. But minimal residue is not the whole law. A variant may lower λ while increasing φ in a small high-risk stratum. It may reduce witness_residue while increasing A_B volatility. It may preserve status while worsening cascade exposure. It may be locally abelian but globally path-critical. It may look cleaner at the measured endpoint while degrading maintenance standing. Therefore, minimal λ cannot become a sovereign principle unless the canon has explicitly compiled why residue minimization outranks the other law-bearing quantities.

A minimal-fragility ordering carries the same risk. Minimizing φ may reduce status flips, but it may do so by routing more states into quarantine, raising A_B, suppressing useful witness differences, or preserving a historical class boundary that should be revised. A zero-fragility ordering is not automatically a just ordering. It is an ordering that produces fewer status divergences under the measured set. That may be sufficient for a class-specific LCR-B. It is not sufficient to rewrite the constitution of ordering selection.

The canon must also forbid runtime optimization over ordering variants. A runtime that can choose the ordering producing the preferred admissibility outcome has ceased to be governed by the Check. It has begun to select its own law. Even if the target function is apparently conservative, such as minimizing witness residue or minimizing status fragility, the act remains constitutionally dangerous. The law applied to a submission must be fixed before the submission is processed. It may not be chosen after seeing which ordering gives the cleanest result.

This is the anti-shopping principle from Section 16.2 at constitutional depth.

Ordering optimization may occur only in sealed measurement, LCR preparation, or explicitly compiled governance review. It may not occur inside live admissibility routing. The runtime may not evaluate multiple variants and then select the one that admits, rejects, quarantines, minimizes cost, minimizes residue, or maximizes stability unless a higher compiled law has authorized such a mechanism. This volume does not authorize it.

The strongest permitted form inside this volume is comparative evidence for LCR-B. The canon may say: for class C_L, π₀ produces φ = 0.18 across the tested set; GV-PL1-V07 produces φ = 0.04 but increases A_B threshold crossings by 0.07; GV-PL1-V09 produces φ = 0.02 but is non-abelian and path-critical; therefore the LCR-B proposes V07 with additional budget safeguards, or proposes retaining π₀ with pair patches, or proposes a re-witnessing queue before adoption. This is bounded selection. It stays within LCR-B because it is class-specific, evidence-indexed, manually compiled, and rollback-ready.

The forbidden form is: always choose the variant with lowest φ.

That sentence looks efficient. It is constitutional overreach.

A target function becomes dangerous when it is allowed to outrank the structure that made measurement lawful. The canon may optimize inside a compiled search space only if the optimizer itself is governed. Otherwise optimization becomes a hidden sovereign. It will appear as technical rationality while changing the rule of rule-change.

This section therefore marks Level 3 adjacency, not Level 3 exercise.

The adjacency is real because ordering selection sits one step from constitutional authority. The canon has discovered that the order of applying rules is itself law-bearing. Choosing an ordering is choosing a rule for applying rules. Choosing a general optimization principle for ordering is choosing a rule for changing that rule. That is why Level 3 stands nearby. But this volume does not cross the line. It maps the line, names the trigger, and refuses to exercise the higher authority.

The volume’s commitment is explicit:

Outcome B may require π₀ to be compiled. It may require variants to be registered. It may require LCR-B remediation. It may require class-specific LCR-A authorization for variant execution. It may require an Ordering Regime LCR where holonomy is non-abelian. It may map conditions under which Level 3 would be implicated. It does not itself alter the Update Constitution. It does not authorize automatic ordering optimization. It does not install a global rule that minimal residue or minimal fragility selects law. It does not delegate law-selection to runtime.

This commitment must be kept even if the data tempt the canon otherwise.

A measured variant may appear obviously superior. A future operator may argue that refusing to adopt the minimal-fragility ordering is irrational. A dashboard may show fewer quarantine events. A budget model may show lower cost. A holonomy table may show cleaner composition. Still, the selection must pass through the correct layer. Evidence does not self-compile. Superiority does not self-authorize. Optimization does not exempt itself from admissibility.

The following boundary marker is therefore compiled:

Level 3 Adjacency Marker — Ordering Optimization

Marker ID: L3A-16.3-ORDER-OPT
Status: Adjacency mapped; Level 3 not exercised.
Trigger Condition: Any proposal to establish a general rule by which ordering variants are selected, replaced, optimized, or automatically updated across classes or across the canon.
LCR-B Zone: Class-specific adoption, preservation, narrowing, or replacement of an ordering under predeclared criteria and bounded evidence.
Level 3 Zone: Change to the authority structure that determines how ordering laws are selected or changed; runtime delegation of ordering selection; automatic optimizer over law; global hierarchy such as “minimal φ always governs” or “minimal λ always governs.”
Permitted in This Volume: Measurement, registry, comparison, class-specific LCR-A/LCR-B routes, adjacency mapping, rollback readiness.
Not Permitted in This Volume: Exercise of Update Constitution authority, automatic ordering optimizer, global selection rule, runtime law-shopping, or constitutional revision of the rule by which ordering rules change.
Required Future Route: Separate Level 3 artifact if any global ordering-selection constitution is proposed.

This marker protects the volume from its own discovery. Outcome B reveals that order is law-bearing. That discovery naturally invites optimization. The canon will want to ask which ordering is best. That question is legitimate. But legitimacy of the question does not authorize the answer at the wrong level. The more powerful the optimization, the higher the layer it touches.

A local ordering decision can be law.

A general optimizer over ordering decisions becomes constitutional machinery.

The difference is not scale alone. It is authority. A local LCR-B says: given this class, this evidence, this variant, this risk, and this rollback plan, this ordering governs here. A Level 3 act says: this is how the canon will decide what ordering governs, and how future decisions of that kind may replace prior ones. The first applies the compiler. The second changes the compiler’s update discipline.

This volume remains with the first.

It does not perform the second.

The section closes with the rule:

Ordering Optimization Boundary Rule

After Outcome B, the canon may compare ordering variants by λ, φ, A_B, witness stability, cascade risk, holonomy class, and maintenance burden. It may select an ordering for a bounded class through LCR-B when selection criteria are predeclared and do not alter future law-selection authority. It crosses into Update Constitution Level 3 when it creates or changes the general rule by which ordering laws are selected, optimized, automatically replaced, or delegated to runtime. This volume maps that adjacency and forbids its own exercise of Level 3 authority.

The canon may measure the better order.

It may not let “better” become sovereign without a constitution.

That is the boundary.


16.4 — The Bedrock Question

Boundary Register

If order is load-bearing, the question cannot stop at compilation.

It must approach bedrock.

Outcome B has already forced the canon to admit that π₀ was not merely a procedural sequence. In the affected scope, the order of the gates helped determine the image of admissibility. The historical manifold was M_π₀. The order shaped witness_residue, A_B, route, quarantine, rejection, or commit. Chapter 16 has therefore compiled π₀, registered governance variants, marked the optimization question as Level 3 adjacent, and prohibited runtime discretion over ordering variants.

But a deeper question remains.

If the order of the gates is part of the decision by which the canon decides what may be edited, is that order itself editable?

This is the Bedrock question.

The Bedrock Clause exists because not every law can be placed inside the region that the law authorizes for modification. A system that may edit all of its constraints without remainder has no constraint. A runtime that may optimize every brake can turn the brake into a parameter. A canon that allows the rule of rule-change to be rewritten by the same procedure it governs has not created law. It has created a loop that can absorb law into its own update motion.

Therefore, the Bedrock Clause protects the non-editable condition that decides what may be edited.

Outcome B brings π₀ near that protected class.

The reason is narrow and severe. The Admissibility Check is not an ordinary downstream rule. It is the procedure by which candidate states approach permission. It is the boundary mechanism that decides what may enter, what must quarantine, what must reject, what must remain uncompiled, and what may become operative. If the order of that procedure is load-bearing, then the order is not only an implementation detail inside the Check. It is part of the Check’s decision structure.

The law deciding what may be edited has questions.

Outcome B shows that the order in which those questions are asked may be part of the decision.

That is the adjacency to bedrock.

This section does not resolve whether π₀ belongs to Bedrock. It logs the hypothesis. The distinction matters. To declare π₀ Bedrock here would exceed the mandate of this volume. The volume measures Loop Residue λ, names the retroactivity crisis, compiles the ordering under Outcome B, registers variants, and maps Level 3 adjacency. It does not authorize itself to decide the final non-editable structure of the canon. That would require a separate authority path and belongs to the next lineage.

The working hypothesis is:

If the order of the Admissibility Check’s gates is load-bearing for the decision of what may enter the editable manifold, then that order may belong to the class of structures the Bedrock Clause exists to protect.

The phrase may belong is mandatory.

The hypothesis is not compiled doctrine. It is not a declaration that π₀ must be permanently frozen. It is not a claim that no variant can ever replace π₀. It is not an argument against measured optimization. It is a warning that ordering selection may touch the protected architecture of editability itself. If the order determines what may be edited, then the rule for editing the order cannot be treated as an ordinary runtime update.

This is why Section 16.3 marked optimization as Level 3 adjacency. Section 16.4 names the deeper object behind that adjacency. Level 3 concerns the rule by which rules are changed. Bedrock concerns the non-editable condition beneath that rule, the condition whose removal would make all subsequent law editable from within the loop.

Ordering choice stands at the edge between them.

If a class-specific LCR-B preserves π₀ for C_L because the evidence shows non-abelian holonomy there, that remains within compiled remediation. If a class-specific LCR-A authorizes a measured governance variant for a bounded class, that remains bounded runtime law. If a future artifact declares that the canon may always choose the lowest-fragility ordering, that approaches Level 3. If a future artifact allows the runtime to decide which ordering governs the Check that decides whether the runtime’s outputs may be admitted, that approaches Bedrock violation.

The precise danger is self-selection.

A system that may select the ordering of the questions that determine whether its own next state is admissible can influence the law that judges it before judgment occurs. Even if the selection function is framed as optimization, the structure is dangerous. The runtime does not need to break a gate. It only needs to choose the path through the gates whose holonomy favors its route. Outcome B has made this danger formal. Legal ordering variants can produce different outcomes. Therefore, ordering choice can become a means of shaping admissibility.

That is why the ordering cannot be left in the editable region without further law.

The canon must distinguish three layers.

First, there is runtime execution of the Check under a compiled ordering. This is ordinary admissibility operation.

Second, there is Layer B compilation of ordering law for a bounded class, including π₀ compilation, variant authorization, remediation, and standing replay.

Third, there is the Bedrock question: whether the authority to choose, replace, optimize, or expose ordering law to update belongs inside the editable canon at all.

This volume reaches the second layer and maps the third. It does not enter the third.

The boundary register entry is therefore required.

Boundary Register Entry — Bedrock Adjacency of Load-Bearing Ordering

Entry ID: BR-16.4-BEDROCK-ORDER
Status: Working hypothesis; logged for Vol II lineage; not resolved in this volume.
Trigger: Outcome B: λ ≠ 0 or φ > 0, establishing that ordering can affect witness_residue, budget, route, or final status in the Admissibility Check.
Observed Structural Fact: In the affected scope, π₀ is not merely procedural sequence. It is part of the decision structure by which candidate Σ are admitted, quarantined, rejected, or held.
Boundary Hypothesis: If the order of the gates is load-bearing for the procedure that decides what may be edited or admitted into the canon, then ordering law may belong to the class of structure protected by the Bedrock Clause.
Immediate Consequence in This Volume: None beyond Level 3 adjacency mapping, π₀ compilation, variant registration, LCR-A/LCR-B routing, and prohibition of runtime discretionary ordering.
Prohibited Inflation: This entry may not be cited as proof that π₀ is Bedrock, that variants are permanently forbidden, that ordering optimization is impossible, or that the Bedrock Clause has been exercised.
Required Future Route: Vol II lineage artifact on bedrock authorization, non-editable ordering law, and the authority by which the order of admissibility questions may or may not be changed.
Current Holding: Adjacency mapped. Bedrock not invoked.

The entry preserves the line.

It allows the canon to admit the seriousness of the discovery without pretending to resolve authority it has not yet earned. The order may be bedrock-adjacent. The order may become a candidate for protected structure. The order may require a future doctrine of non-editable sequencing. But this volume does not declare it so. It leaves the question open under record.

This is not hesitation.

It is jurisdiction.

A volume about Loop Residue may discover that ordering is load-bearing. It may compile the historical ordering as law. It may classify variants. It may map holonomy. It may identify Level 3 adjacency. But the authority to define bedrock cannot be smuggled into the final sections of a measurement volume merely because the measurement became profound.

The canon must not seize more authority because the result is interesting.

That would repeat the defect it discovered.

The Bedrock question also reframes the entire arc of the book. Part I asked whether the canonical ordering was dark canon. Part II measured. Part III, if activated, would have converted habit into convention. Part IV, if activated, discovers that the habit was law-bearing. Chapter 16 compiles the law-bearing order. But the final boundary question is whether the order belongs to the editable law or to the protected condition beneath editable law.

This is the lineage marker for Vol II.

Vol II must ask who authorizes the non-editable structure. It must ask whether Bedrock can name itself, whether any canon can compile its own un-editable foundation without circularity, whether the order of admissibility questions is part of that foundation, and whether a system capable of measuring its own holonomy is also capable of lawfully changing the sequence by which it measures permission.

Those questions are not answered here.

They are inherited.

The present volume closes its authority with a narrower claim: once ordering has been shown load-bearing, ordering can no longer be treated as an implementation detail. It must be compiled, indexed, replayed, and protected from runtime discretion. Whether it must be protected as Bedrock is logged as the next frontier.

The section compiles the following boundary rule:

Bedrock Adjacency Rule

When the order of the Admissibility Check’s gates is shown to be load-bearing for admissibility outcomes, that order becomes bedrock-adjacent because it participates in the law deciding what may enter the editable manifold. This volume may compile the ordering, register variants, require LCR-A and LCR-B routes, and map Level 3 adjacency. It may not exercise Bedrock authority or declare the ordering non-editable. The Bedrock question is logged for the next lineage and remains unresolved here.

The canon therefore stops where it must stop.

It has found that order acts.

It has compiled the acting order.

It has forbidden discretionary variants.

It has mapped the constitutional edge.

It has named the bedrock-adjacent question.

It does not answer it.

That restraint is part of the law.


Part V — The Generalization: Holonomy of Governance


Chapter 17 — Every Procedure Has a λ

17.1 — The Generalization Schema

The measurement of π₀ does not end with the Check.

It exports a method.

Part V begins from the recognition that the Admissibility Check was only the first procedure forced to confess its order. The same question can be asked of any governed procedure that applies more than one operator to a state, record, claim, submission, artifact, class, budget, witness, or rule. If the procedure has steps, and if some steps could in principle be ordered differently without violating hard dependency, then the procedure has a possible λ. The order may commute. The order may not commute. The point is that the canon no longer has permission to assume.

Every governed procedure has an ordering problem until measured otherwise.

This is the generalization.

The recipe is abstract, but not vague. A procedure must be decomposed into operators. Its precedence lattice must be compiled. Its legal linear extensions must be named. Its outcome vector must be defined. Archived executions must be replayed under alternative legal orderings. The difference between the historical ordering and each legal alternative becomes the procedure’s Loop Residue λ. If final status changes across orderings, the procedure also has an Order Fragility Index φ. If swap effects compose, it has holonomy. If the holonomy is abelian, repair may be local. If the holonomy is non-abelian, the procedure’s ordering regime becomes load-bearing.

The Check supplied the first full instance.

Part V turns the instance into method.

The abstract schema begins with a governed procedure P. A governed procedure is any repeatable sequence that transforms an input state into a governed output under compiled or quasi-compiled rules. The input may be a candidate Σ, an LCR draft, a budget ledger entry, a certificate, a class admission request, a quarantine object, a rollback decision, a witness update, a trace-normalization act, or a remediation plan. The output may be commit, reject, quarantine, approve, return, certify, void, annotate, price, route, or escalate. What matters is not the domain of the object. What matters is that the procedure applies multiple rule-bearing operations before producing a governed result.

Let P be such a procedure.

The first operation is decomposition.

P must be written as a set of operators:

O(P) = {O₁, O₂, …, O_n}

Each operator must have a defined input, output, side effect, ledger effect, budget effect where relevant, witness effect where relevant, and routing effect where relevant. An operator is not a prose step. It is a transformation that can be executed, replayed, compared, and audited. If a step cannot be replayed, it cannot yet be used in a λ campaign. It must first be formalized or routed into the exception register.

This decomposition is the first exportable discipline of the volume. Governance procedures often hide operators inside ordinary language: review, approve, verify, certify, compare, escalate, annotate, decide. Each such verb may contain multiple transformations. The schema requires those transformations to be separated. If the procedure cannot say what its operators are, it cannot know whether its order matters.

The second operation is precedence compilation.

Not every ordering is legal. Some operators require outputs from earlier operators. Some must remain terminal. Some must remain initial. Some must not observe intermediate state. Some must not run before hash fixation. Some must not occur after commit. The procedure therefore requires a precedence lattice L(P), not merely a historical sequence. The lattice records hard dependencies and excludes false dependencies. It distinguishes “must precede” from “has always preceded.” That distinction is the core of the method.

The historical ordering is then identified as π₀(P).

π₀(P) is the ordering the procedure actually used in the archive. It may be canonical. It may be inherited. It may be accidental. It may be documented. It may be dark. The schema does not assume its legitimacy. It names it as the base ordering because the archive was produced through it.

The legal ordering space is:

Π_L(P) = the set of legal linear extensions of L(P)

A linear extension is any complete ordering of the operators that respects the compiled precedence lattice. If the lattice is strict, Π_L may be small. If the lattice contains many untested degrees of freedom, Π_L may be large. Either way, the set must be named before measurement. Without the set, the campaign cannot distinguish legal alternatives from arbitrary rearrangements.

The third operation is outcome-vector definition.

A procedure’s λ cannot be measured until the procedure defines what counts as an outcome. For the Admissibility Check, the outcome vector included final status, witness_residue, A_B, route, quarantine signal, rejection signal, final witness result, and trace-normalized terminal fields. Other procedures will require different vectors. A certificate-maintenance procedure may include live witness strength W_e, τ_w, maintenance status, class narrowing, and citation constraints. An LCR procedure may include accepted, returned, rejected, quarantined, layer assignment, downstream binding, and rollback conditions. A budget-review procedure may include A_B, threshold crossing, budget class, authorization requirement, and ledger allocation.

The outcome vector must be declared before replay.

Let Ω_π(P, X) be the outcome vector produced when procedure P is applied to an archived input X under ordering π. X is the object processed by the procedure: a Σ, an LCR, a certificate, a class request, a budget object, or another governed input. The historical outcome is Ω_π₀(P, X). The counterfactual outcome under an alternative legal ordering π is Ω_π(P, X).

The procedure’s Loop Residue relative to π₀ is then:

λ_P(X, π) = distance or difference between Ω_π(P, X) and Ω_π₀(P, X)

The distance function must be field-specific. Continuous fields may use numerical deltas. Discrete fields require categorical comparison. A status flip is not a magnitude-only event. A routing change is not reducible to a scalar. A witness-residue delta and a quarantine-route change are different kinds of difference. The schema therefore permits vector λ: not one number only, but an indexed residue profile.

The fourth operation is archival replay.

The schema requires archived executions because the question is not only what could happen under constructed examples. The question is what would have happened to the actual history of the procedure if the procedure had used another legal ordering. This is the retroactive force of λ. Archived inputs must be hash-fixed where possible. If the original input cannot be reconstructed, the object enters the exception register. If the procedure’s historical trace is incomplete, that incompleteness is itself a finding.

Replay proceeds by class.

For each class C of archived inputs X, run P under π₀ and under selected legal extensions π ∈ Π_L(P). Compare outcome vectors. Record λ_P(X, π). Record status changes. Record budget changes. Record witness changes. Record route changes. Record trace anomalies. Compute class-level φ where the procedure has status-like outcomes.

The generalized Order Fragility Index is:

φ_P(C, Π) = fraction of archived inputs X in class C whose governed terminal status changes under at least one tested legal ordering π relative to π₀(P)

The word status must be interpreted procedurally. For the Check, status means commit, quarantine, reject, or hold. For an LCR procedure, status may mean accepted, returned, rejected, or quarantined. For a certificate procedure, status may mean live, narrowed, decayed, voided, or retired. For a budget procedure, status may mean within ceiling, over ceiling, authorization required, or quarantine. Every procedure must define its own status set before φ is computed.

The fifth operation is holonomy classification.

If λ_P is nonzero, the procedure must not stop at residue listing. It must classify how ordering effects compose. Legal swaps become generators. Composed swaps are tested. Abelian and non-abelian cases are distinguished. Path-critical cases are marked. The same architecture developed in Chapter 15 applies: local pair patches for abelian defects, ordering-regime compilation for non-abelian defects, enhanced review for path-critical procedures.

This is the point at which the exportable method becomes powerful. It does not merely say “audit procedures.” It says: for every governed procedure, identify operators, compile the lattice, define legal orderings, replay the archive, compute λ, compute φ where applicable, classify holonomy, and route the result into repair. That is a method a future campaign can execute without inventing the philosophy again.

The schema can therefore be stated as a procedural recipe.

Generalization Schema for Governance Holonomy

Step One: Procedure Selection.
Select a governed procedure P whose output carries standing inside the canon.

Step Two: Operator Decomposition.
List every operator O_i in P with input, output, side effect, witness effect, budget effect, routing effect, and ledger effect.

Step Three: Precedence Lattice Compilation.
Compile L(P), separating hard dependencies from inherited sequence.

Step Four: Historical Ordering Identification.
Name π₀(P), the ordering that produced the archive.

Step Five: Legal Extension Set.
Define Π_L(P), the legal linear extensions of L(P), or a justified tested subset where full enumeration is not feasible.

Step Six: Outcome Vector Definition.
Define Ω(P), including status fields, continuous fields, trace fields, budget fields, witness fields, and routing fields.

Step Seven: Archive Fixation.
Freeze archived inputs X by hash, trace reference, epoch, class, and exception status.

Step Eight: Replay Campaign.
Execute P under π₀(P) and tested π ∈ Π_L(P) over archived X, class by class.

Step Nine: λ Computation.
Compute λ_P(X, π) as the difference between Ω_π(P, X) and Ω_π₀(P, X), field by field.

Step Ten: φ Computation.
Compute φ_P where the procedure has terminal status categories.

Step Eleven: Holonomy Classification.
Test single swaps, composed swaps, commutators, and path-critical loops where λ_P is nonzero.

Step Twelve: Remediation Routing.
Route the procedure to certificate, patch, compilation, grandfathering, re-witnessing, rollback, or Level 3 adjacency mapping as required.

This is the volume’s exportable method.

It can be applied to the Admissibility Check, but it is not limited to it. It can be applied to LCR review, Evidence Ledger entry acceptance, certificate maintenance, quarantine release, rollback readiness evaluation, class admission, budget authorization, compilation map updates, frontier-node promotion, silence-entry handling, Zebra-Ø certification, and any procedure whose operator order may matter. The volume does not need to run all those campaigns. Chapter 17 creates the registry that would let them begin.

The part-level verification gate follows from this.

The Holonomy Audit Registry of Chapter 17 must name, for every listed procedure, its operator decomposition and its precedence lattice. Without those two fields, a future campaign cannot begin without redefinition. A procedure cannot enter the registry as a title only. It must be decomposed enough that a replay campaign could be designed from the entry. The registry is therefore not a list of interesting targets. It is a launch surface for future λ campaigns.

A minimal registry entry requires:

procedure ID;

procedure name;

governed object type;

operator list;

operator definitions;

historical ordering π₀(P);

precedence lattice L(P);

legal-extension generation rule;

outcome vector Ω(P);

archive location;

class taxonomy;

known hard dependencies;

suspected dark sequence points;

replay feasibility;

exception risks;

candidate λ campaign status.

This registry is the generalization artifact.

It turns the book’s central result into an audit discipline. The canon can now look at any procedure and ask: what is its π₀? What are its operators? Which edges are law and which are habit? What would the archive look like under another legal extension? Does the procedure have λ? Does it have φ? Does it have holonomy? Is its ordering a convention, a local patch, a globally load-bearing law, or a bedrock-adjacent structure?

These questions are not optional after this volume.

They are the exported posture of governance.

The schema also protects against overreach. Not every procedure will show nonzero λ. Some may commute fully within tested scope. Some may have strict precedence lattices with no meaningful alternative orderings. Some may be too under-specified for immediate measurement. Some may have archives too incomplete for replay. The method does not assume crisis everywhere. It creates the discipline by which absence of crisis is earned.

A procedure with no legal alternative orderings has no ordering λ under this schema, but it may still have other defects.

A procedure whose legal alternatives all produce identical outcome vectors may receive a commutation certificate.

A procedure whose archive cannot be replayed receives a replay-defect entry, not a false certificate.

A procedure whose operators cannot be decomposed receives an operator-definition defect.

A procedure with nonzero λ but zero φ receives residue remediation, not status panic.

A procedure with non-abelian holonomy receives ordering-regime review.

This is why the schema is exportable. It does not dictate the answer. It dictates the lawful way to ask.

The section compiles the following rule:

Every Procedure Has a λ Rule

Every governed procedure with multiple operators and more than one legal linear extension must be treated as having a potential Loop Residue λ until measured. The canon shall decompose the procedure into operators, compile its precedence lattice, define its historical ordering, define legal extensions, replay archived executions, and compute outcome differences before treating the procedure’s ordering as neutral. Absence of measured residue may be certified. Absence of measurement may not be treated as neutrality.

This rule is the generalization of the volume.

The Admissibility Check was the first object because it sits at the threshold. But the threshold is not the only place where order can hide. Any procedure that applies rules in sequence may have a dark ordering. Any archive produced by a sequence may be a fiber. Any repair that ignores ordering may preserve unseen law.

The exportable method is therefore simple and severe:

Find the operators.

Compile the lattice.

Replay the order.

Measure the residue.

Classify the holonomy.

Then decide what the law has become.


17.2 — The Audit Registry

The generalization schema requires a registry before it requires another campaign.

A procedure cannot be audited for holonomy until the canon has named the procedure, decomposed its operators, compiled its precedence lattice, identified its historical ordering, and located the archive through which replay can occur. Without that preparatory work, “future audit” remains intention. The Holonomy Audit Registry converts intention into queue. It names the canon’s multi-step procedures, assigns each an exposure priority, and records enough structure that a later λ campaign can begin without redefining the object.

Exposure is the ordering principle of the registry.

The first procedures queued for audit are not the most elegant, not the most philosophically interesting, and not the easiest to replay. They are the procedures through which the most canon has flowed. A procedure with high exposure has shaped many commitments, many refusals, many LCRs, many quarantines, many witness updates, or many downstream dependencies. If such a procedure contains an unmeasured ordering dependency, its λ is not local. Its residue may already be distributed through the canon’s archive.

The registry therefore asks one practical question before all others:

How much canon passed through this procedure before its ordering was measured?

This exposure criterion produces the first queue.

The first registry object is the nine-field LCR-A processing order. LCR-A is the procedure by which a runtime-level or class-bounded change crosses into authorized operation. It may approve a governance variant, authorize a class-specific runtime adjustment, permit a bounded ordering change, or allow a procedure to act differently for a defined scope. Because LCR-A is the route by which many future changes become executable, its own internal order cannot remain unmeasured. If the evidence field is read before the layer-origin field, if risk is assessed before the crossing object is fixed, if downstream binding is considered before the decision gate, the result may or may not change. The canon does not know until it measures.

The LCR-A processing procedure is decomposed into nine operators:

O_A1 — Crossing Object Fixation. The object of the proposed crossing is fixed, named, scoped, and hash-referenced.

O_A2 — Layer of Origin Identification. The procedure identifies the layer from which the proposed change originates.

O_A3 — Layer of Destination Identification. The procedure identifies the layer into which the change seeks authority.

O_A4 — Crossing Justification Assessment. The procedure determines why the crossing is required and whether the origin layer can lawfully authorize the act by itself.

O_A5 — Candidate Runtime Law / Permission Definition. The proposed operational rule, permission, variant, or bounded change is stated.

O_A6 — Evidence Input Verification. Required evidence, campaign outputs, census entries, trace records, and control materials are checked.

O_A7 — Risk of Crossing / Risk of Non-Crossing Analysis. The procedure prices both authorization and refusal.

O_A8 — Decision Gate. The procedure accepts, restricts, returns, rejects, or quarantines the proposed crossing.

O_A9 — Downstream Binding Effects. The result is translated into runtime routing, ledger constraints, citation rules, maintenance obligations, and rollback triggers.

The historical ordering is assumed to be O_A1 → O_A2 → O_A3 → O_A4 → O_A5 → O_A6 → O_A7 → O_A8 → O_A9. The precedence lattice is not automatically the same as that line. O_A1 must remain initial because no later operation can lawfully evaluate a crossing whose object is undefined. O_A8 must follow the evidence and risk operators. O_A9 must remain terminal because downstream binding depends on the decision. But O_A2 and O_A3 may commute in some cases. O_A5 may need to occur before O_A6 because evidence verification depends on the proposed permission, or O_A6 may need to occur before O_A5 because the candidate law should not be shaped around incomplete evidence. O_A4 may interact with both. These are not stylistic variants. They may alter the acceptance route of future law.

LCR-A receives Priority One because future ordering variants, class-specific runtime permissions, and bounded operational changes all pass through it. If LCR-A has λ, then the canon’s mechanism for authorizing bounded runtime change is itself order-conditioned.

The second registry object is the LCR-B procedure. LCR-B is more exposed at the level of compiled inheritance. It decides how Layer C evidence, runtime disturbance, historical standing, remediation, or class structure crosses into compiled archive law. In this volume, the remediation decision after Outcome B was identified as LCR-B because it sets the update discipline of the manifold’s past. That alone makes LCR-B unavoidable in the audit queue.

The LCR-B procedure is decomposed into nine operators parallel in form but deeper in consequence:

O_B1 — Compiled Object Fixation. The Layer B object to be amended, added, narrowed, preserved, or reclassified is fixed.

O_B2 — Disturbance Source Identification. The evidence or event forcing Layer B review is identified.

O_B3 — Archive and Historical Scope Definition. The procedure defines which prior entries, classes, epochs, and dependencies are affected.

O_B4 — Layer Crossing Justification. The procedure determines why runtime action is insufficient and why compiler-level law is required.

O_B5 — Candidate Compilation Law Definition. The proposed compiled law, remediation law, inheritance rule, or update discipline is stated.

O_B6 — Evidence Package Verification. Census outputs, campaign outputs, ledger annexes, dependency maps, budget estimates, witness records, and audit findings are verified.

O_B7 — Integrity / Continuity / Cascade Pricing. The procedure prices rollback, grandfathering, re-witnessing, annotation, cascade risk, and non-action.

O_B8 — Compilation Decision Gate. The proposed law is accepted, restricted, returned, rejected, quarantined, or escalated.

O_B9 — Canon-Wide Binding Effects. The output binds the Compilation Map, Evidence Ledger, runtime inheritance, citations, downstream LCRs, maintenance schedules, and rollback readiness.

The historical ordering is O_B1 → O_B2 → O_B3 → O_B4 → O_B5 → O_B6 → O_B7 → O_B8 → O_B9. The hard lattice is stricter than LCR-A because archive scope, evidence, and cascade pricing are deeply coupled. O_B1 must precede all. O_B3 must precede O_B7. O_B6 must precede O_B8. O_B9 must follow O_B8. But the relation between O_B2, O_B3, O_B4, and O_B5 may be order-sensitive. A candidate law drafted before archive scope is fixed may shape the scope around itself. Archive scope fixed before candidate law may constrain the possible remediation. Evidence verified before justification may produce one route; justification before evidence may produce another. If these effects exist, LCR-B has its own holonomy.

LCR-B receives Priority Two because it governs the canon’s compiled memory. Less traffic may pass through LCR-B than through ordinary Check execution, but each LCR-B carries high structural weight. If LCR-B ordering is dark, the canon’s repair machinery is dark.

The third registry object is Zebra-Ø’s internal sequence.

Zebra-Ø has been treated as a gate, but a gate may contain procedure. The fact that a gate is named as one operator in the Admissibility Check does not prove that its internal operations commute. Zebra-Ø’s function is to detect non-admissible singularity, mythic inflation, malformed boundary logic, false totalization, and related failure modes. Its internal sequence commonly includes ablation, rotation, and embargo. Those three words are not decorative. Each may be an operator.

O_Z1 — Ablation. Remove ornamental, anthropic, motivational, mythic, or structurally irrelevant surface from the candidate formulation.

O_Z2 — Rotation. Rotate the remaining structure through alternate viewpoints, failure surfaces, counter-readings, and boundary orientations to test whether the object survives change of frame.

O_Z3 — Embargo. Hold interpretive closure, delay premature synthesis, prevent mythic sealing, and block immediate passage into confident admissibility.

The historical ordering is likely ablation → rotation → embargo. But the audit question is whether Zebra-Ø commutes with itself. If rotation before ablation reveals failure modes that ablation would remove from visibility, then the sequence matters. If embargo before rotation prevents premature path selection, then embargo may need to move earlier. If ablation after embargo changes what is allowed to remain in suspension, then the internal gate has holonomy. A single named gate may therefore contain a non-commuting micro-procedure.

The precedence lattice is initially minimal: the input must be fixed before all three; the terminal Zebra-Ø result must follow all required internal operators; embargo may be terminal only if its function is to hold after inspection, but may be initial or interleaved if its function is to prevent interpretive seizure before inspection. That ambiguity is precisely why the registry must name it. Zebra-Ø receives Priority Three because it is a high-impact gate through which frontier claims, non-admissible singularities, and myth-inflation risks pass. Its volume of traffic may be lower than LCR-A, but its failure cost is severe.

The fourth registry object is the merge sequence governed by the Merge Re-Admission Gate.

Merge procedures are dangerous because they decide whether previously separated branches, quarantined structures, split classes, divergent artifacts, or repaired concepts may re-enter a unified canon. The Merge Re-Admission Gate does not merely accept content. It repairs relation. If its ordering has λ, then the sequence of comparing, reconciling, witnessing, budgeting, and re-admitting may determine what kind of merged object becomes real.

A draft decomposition is:

O_M1 — Branch Identity Fixation. The branches, artifacts, classes, or states proposed for merge are fixed and hash-referenced.

O_M2 — Divergence Ledger Review. Prior split history, quarantine reasons, conflicting witness records, and branch-specific notes are read.

O_M3 — Compatibility Test. The procedure checks whether the branches can coexist without contradiction, collapse, duplication, or boundary breach.

O_M4 — Witness Reconciliation. Witness residues are compared, aligned, preserved, or marked irreconcilable.

O_M5 — Budget Reconciliation. A_B, maintenance cost, cascade burden, and future upkeep are recalculated for the merged object.

O_M6 — Merge Re-Admission Gate. The procedure decides whether the merged object may re-enter, must remain split, must quarantine, or must be rejected.

O_M7 — Downstream Dependency Update. Dependent entries are updated, annotated, redirected, or sealed.

The historical ordering is probably O_M1 → O_M2 → O_M3 → O_M4 → O_M5 → O_M6 → O_M7. The hard lattice requires O_M1 first and O_M7 last. O_M6 must follow the tests that define the merge. But compatibility, witness reconciliation, and budget reconciliation may be order-sensitive. If witness is reconciled before compatibility, the procedure may force coherence onto objects that should remain separate. If budget is reconciled before witness, cost may dominate standing. If compatibility is tested before divergence review, the procedure may miss why the branches split. The merge sequence therefore deserves audit.

It receives Priority Four because fewer objects pass through merge than through LCR-A or LCR-B, but merge events can alter entire branches of the canon. A single bad merge can erase a distinction that the canon paid to preserve.

The fifth registry object is quarantine exit.

Quarantine exit is the procedure by which a held object leaves Pre-Commit Quarantine, returns to the Check, receives a new route, remains in quarantine, or rejects. It is one of the most exposed procedures because quarantine is the canon’s main instrument for refusing premature commit without destroying the object. If exit order is dark, the canon may release, hold, or reject objects depending on the sequence in which it reads repair evidence, witness decay, budget renewal, class drift, and external updates.

A draft decomposition is:

O_Q1 — Quarantine Object Fixation. The quarantined object, original route, class, epoch, and quarantine reason are fixed.

O_Q2 — Quarantine Reason Review. The procedure reads the original boundary failure, ambiguity, evidence gap, or structural defect that caused quarantine.

O_Q3 — New Evidence Intake. New evidence, repair attempts, witness updates, class changes, and external conditions are entered.

O_Q4 — Witness Thermodynamics Update. The object’s witness_residue, W_e, τ_w, decay, and maintenance status are recalculated.

O_Q5 — Budget Recalculation. A_B and any maintenance or proof-friction costs are recalculated.

O_Q6 — Gate Re-Execution Selection. The procedure determines which gates must be rerun and whether full Check replay is required.

O_Q7 — Exit Decision. The object exits to commit, remains in quarantine, routes to rework, rejects, or escalates.

O_Q8 — Ledger and Dependency Update. The result is written, citations are updated, and dependent states are notified.

The historical ordering is O_Q1 → O_Q2 → O_Q3 → O_Q4 → O_Q5 → O_Q6 → O_Q7 → O_Q8. The lattice requires O_Q1 first and O_Q8 last. O_Q7 must follow the relevant evidence, witness, budget, and gate-selection operators. But O_Q3, O_Q4, O_Q5, and O_Q6 may interact. If budget recalculation occurs before witness update, the proof burden may be priced under stale witness. If gate-selection occurs before new evidence intake, the replay may omit relevant gates. If witness update occurs before quarantine reason review, the procedure may decay the object without reading why it was held. Quarantine exit therefore has likely λ.

It receives Priority Five by exposure volume. Many boundary objects may spend time in quarantine. The exit procedure controls whether they become real after delay. That makes its order important even if each individual exit seems local.

These five procedures form the initial Holonomy Audit Registry.

The registry entries are queued as follows:

Priority One: LCR-A processing order. Exposure basis: high frequency of bounded runtime permissions, variant authorizations, and future operational changes.

Priority Two: LCR-B procedure. Exposure basis: lower frequency but high structural consequence; governs compiled archive updates and remediation law.

Priority Three: Zebra-Ø internal sequence. Exposure basis: high severity gate; controls non-admissible singularity, myth-inflation, and frontier boundary failure.

Priority Four: Merge Re-Admission Gate sequence. Exposure basis: branch repair and reintegration; high cascade risk through merged dependencies.

Priority Five: Quarantine exit. Exposure basis: high operational volume; controls delayed admission, continued hold, and rejection after repair.

This priority order may be revised by the registry if exposure data contradict it. If quarantine exit has processed more canon than expected, it may move upward. If Zebra-Ø’s internal operations have incomplete archives, it may remain high-priority but enter replay-feasibility preparation before campaign. If LCR-B has low count but all entries are Level 3 adjacent, it may outrank LCR-A by structural severity. The registry’s priority is not prestige. It is exposure multiplied by consequence.

A formal exposure score may be recorded:

E(P) = N(P) × S(P) × D(P) × R(P)

where N(P) is the number of canon entries processed through procedure P, S(P) is structural severity, D(P) is downstream dependency weight, and R(P) is replay feasibility risk inverted or separately noted. The score is not sovereign. It supports queue discipline. A high-volume low-severity procedure and a low-volume high-severity procedure may both deserve early audit for different reasons.

The registry must now be stated in launchable form.

Holonomy Audit Registry — Initial Entries

Procedure ID: HAR-01-LCR-A
Procedure Name: LCR-A Processing Order
Governed Object Type: Runtime permission, bounded class authorization, ordering-variant execution, operational crossing.
Operator Decomposition: O_A1 Crossing Object Fixation; O_A2 Layer of Origin Identification; O_A3 Layer of Destination Identification; O_A4 Crossing Justification Assessment; O_A5 Candidate Runtime Law Definition; O_A6 Evidence Input Verification; O_A7 Risk of Crossing / Non-Crossing Analysis; O_A8 Decision Gate; O_A9 Downstream Binding Effects.
Historical Ordering π₀(P): O_A1 → O_A2 → O_A3 → O_A4 → O_A5 → O_A6 → O_A7 → O_A8 → O_A9.
Precedence Lattice: O_A1 initial; O_A8 after O_A4, O_A6, O_A7; O_A9 terminal after O_A8; O_A2/O_A3 potentially commutable; O_A5/O_A6 relation unresolved; O_A4 may require position testing.
Outcome Vector: accepted, accepted-with-restriction, returned, rejected, quarantined; runtime permission scope; downstream binding; rollback trigger; citation constraint.
Archive Source: LCR-A records and variant-authorization records.
Priority: One.
Exposure Justification: High flow of future runtime changes; if order-fragile, authorization of operational variation becomes dark.

Procedure ID: HAR-02-LCR-B
Procedure Name: LCR-B Compilation Procedure
Governed Object Type: Layer B remediation, archive update, inheritance law, compiled status change.
Operator Decomposition: O_B1 Compiled Object Fixation; O_B2 Disturbance Source Identification; O_B3 Archive and Historical Scope Definition; O_B4 Layer Crossing Justification; O_B5 Candidate Compilation Law Definition; O_B6 Evidence Package Verification; O_B7 Integrity / Continuity / Cascade Pricing; O_B8 Compilation Decision Gate; O_B9 Canon-Wide Binding Effects.
Historical Ordering π₀(P): O_B1 → O_B2 → O_B3 → O_B4 → O_B5 → O_B6 → O_B7 → O_B8 → O_B9.
Precedence Lattice: O_B1 initial; O_B3 before O_B7; O_B6 before O_B8; O_B9 terminal; O_B2/O_B3/O_B4/O_B5 relations require measurement.
Outcome Vector: compiled, compiled-with-restrictions, returned, rejected, quarantined, escalated; archive scope; remediation law; downstream binding; maintenance budget; rollback readiness.
Archive Source: LCR-B records, remediation records, Compilation Map amendments.
Priority: Two.
Exposure Justification: Lower frequency but high structural consequence; governs how the canon revises its own compiled past.

Procedure ID: HAR-03-ZEBRA-Ø
Procedure Name: Zebra-Ø Internal Sequence
Governed Object Type: Non-admissible singularity detection, myth-inflation control, frontier sanity gate.
Operator Decomposition: O_Z1 Ablation; O_Z2 Rotation; O_Z3 Embargo.
Historical Ordering π₀(P): O_Z1 → O_Z2 → O_Z3.
Precedence Lattice: Input fixation before all; terminal Zebra-Ø result after all required internal operators; relation among ablation, rotation, and embargo unresolved; whether embargo is terminal or can be initial/interleaved is audit object.
Outcome Vector: pass, fail, quarantine, non-admissible route, embargo required, ablation residue, rotation failure, myth-inflation flag, trace note.
Archive Source: Zebra-Ø gate records, frontier claim reviews, non-admissible singularity logs.
Priority: Three.
Exposure Justification: High severity; a named gate may contain dark internal order; determines whether Zebra-Ø commutes with itself.

Procedure ID: HAR-04-MERGE
Procedure Name: Merge Sequence with Merge Re-Admission Gate
Governed Object Type: Branch merge, repaired artifact reintegration, class merge, quarantine branch re-entry.
Operator Decomposition: O_M1 Branch Identity Fixation; O_M2 Divergence Ledger Review; O_M3 Compatibility Test; O_M4 Witness Reconciliation; O_M5 Budget Reconciliation; O_M6 Merge Re-Admission Gate; O_M7 Downstream Dependency Update.
Historical Ordering π₀(P): O_M1 → O_M2 → O_M3 → O_M4 → O_M5 → O_M6 → O_M7.
Precedence Lattice: O_M1 initial; O_M6 after compatibility, witness, and budget tests; O_M7 terminal; O_M2/O_M3/O_M4/O_M5 interaction requires measurement.
Outcome Vector: merge admitted, merge denied, remain split, quarantine, reject, partial merge, witness conflict, budget conflict, dependency update burden.
Archive Source: Merge Re-Admission Gate records, branch repair records, class merge logs.
Priority: Four.
Exposure Justification: Moderate frequency, high cascade risk; bad merge can erase necessary distinction or import unresolved residue.

Procedure ID: HAR-05-QEXIT
Procedure Name: Quarantine Exit Procedure
Governed Object Type: Quarantined object review, release, continued hold, rejection, or rework routing.
Operator Decomposition: O_Q1 Quarantine Object Fixation; O_Q2 Quarantine Reason Review; O_Q3 New Evidence Intake; O_Q4 Witness Thermodynamics Update; O_Q5 Budget Recalculation; O_Q6 Gate Re-Execution Selection; O_Q7 Exit Decision; O_Q8 Ledger and Dependency Update.
Historical Ordering π₀(P): O_Q1 → O_Q2 → O_Q3 → O_Q4 → O_Q5 → O_Q6 → O_Q7 → O_Q8.
Precedence Lattice: O_Q1 initial; O_Q7 after evidence, witness, budget, and gate-selection operators; O_Q8 terminal; O_Q3/O_Q4/O_Q5/O_Q6 interaction requires measurement.
Outcome Vector: commit, remain quarantined, rework, reject, escalate, re-run full Check, partial replay, witness renewal, budget threshold crossing, dependency update.
Archive Source: Pre-Commit Quarantine records, exit reviews, quarantine continuation logs, re-entry decisions.
Priority: Five.
Exposure Justification: High operational volume; exit order may decide whether held objects become admissible after delay.

This initial registry satisfies the verification gate for Chapter 17 only if each entry can launch a future campaign without redefining the procedure. That is why each entry includes operator decomposition and lattice. Some lattices remain unresolved in their internal commutable relations, but that is acceptable because unresolved relation is precisely what a λ campaign tests. What would be unacceptable is a procedure name without operators or a historical ordering without hard precedence distinctions.

The registry also creates a new discipline for all future procedure design. Any new canon procedure with more than one operator must enter the Holonomy Audit Registry at birth, even if it is low priority. It must declare whether its ordering is strict, partially flexible, unmeasured, certified commuting, locally patched, or compiled load-bearing. A procedure cannot be allowed to operate for years and then be discovered as dark sequence only after a crisis. The registry is how the canon prevents future π₀ events.

The section compiles the following rule:

Holonomy Audit Registry Rule

Every multi-step canon procedure whose output carries governance standing must be entered into the Holonomy Audit Registry with operator decomposition, historical ordering, precedence lattice, outcome vector, archive source, and exposure priority. Priority is assigned by how much canon has flowed through the procedure, multiplied by structural consequence and downstream dependency weight. Procedures may remain unaudited, but they may not remain unnamed.

This rule turns the volume’s method into maintenance infrastructure.

The Check was first.

It is not alone.

The canon now has a queue.


17.3 — Shared Infrastructure

The first λ campaign is the most expensive because it builds the measuring floor.

Part II did not merely test the Admissibility Check. It constructed the infrastructure by which the canon can test any governed procedure for ordering residue. Hash fixation, contamination controls, control-run calibration, replay isolation, terminal vector comparison, and two-operator replication were not temporary devices for one campaign. They are reusable instruments. Once built, they become shared audit infrastructure for every later holonomy campaign.

This matters for Part V because the generalization would otherwise appear too costly to execute. If every procedure required the canon to invent a new measurement architecture from zero, the rule “every procedure has a λ” would remain aspirational. It would name a burden without making the burden operationally survivable. But Part II has already paid the largest setup cost. The later audits do not begin from nothing. They inherit a measurement stack.

The first inherited component is hash fixation.

Hash fixation is the condition that the same archived object is being replayed across ordering variants. Without it, a campaign cannot distinguish order effect from input variation. If Check_π₀ and Check_π₁ process different versions of Σ, the measured difference is not λ. It is contamination by state drift. Part II therefore required input fixation before replay. The same rule applies to every later procedure. An LCR-A draft, a quarantine object, a Zebra-Ø candidate, a merge package, a certificate-maintenance record, or a budget authorization request must be fixed before variant execution. The object must not evolve between ordering runs. If it cannot be fixed, it enters the exception register.

Hash fixation becomes the common gate for all holonomy audits.

The second inherited component is contamination control.

Ordering campaigns are vulnerable to subtle contamination because one replay path can leak information into another. A first run may update trace context, operator cache, budget state, witness expectations, class notes, or reviewer priors. If a second run reads that changed environment, the campaign measures contamination, not order. Part II therefore required isolated execution, separate output slots, no shared mutable state, and trace segregation between variants. Every later audit inherits this discipline. Procedure-specific operators may differ, but contamination risk remains the same: one ordering must not teach another ordering what to find.

Contamination controls include clean archive retrieval, read-only input snapshots, isolated execution environments, separate trace channels, sealed comparison after run completion, and anomaly logs for any side effect. These controls are not optional quality assurance. They are the difference between replay and performance.

The third inherited component is control-run calibration.

No λ can be interpreted without a noise floor. A replay system may produce small variations even when the same ordering is repeated. Operator execution may contain nondeterminism. Trace rendering may have minor variance. Budget computation may vary within numerical tolerance. Witness residue may fluctuate within the limits of instrumentation. Part II established that control runs are required before any difference can be called residue. The same ordering must be run against the same fixed object enough times to estimate ordinary variation. Only differences exceeding the declared control-run noise floor can become λ.

This rule prevents false discovery.

It also prevents false dismissal. A procedure with a high noise floor may need better instrumentation before its ordering can be certified. It cannot simply declare small differences irrelevant if those differences occur near a routing threshold. Control-run calibration must be field-specific: witness_residue has one noise profile, A_B another, trace output another, status another. A categorical status flip has no ordinary scalar noise. It either occurs or does not. If a status flip appears in replay, it must be treated as a discrete event and then investigated for contamination, operator instability, or true order effect.

The fourth inherited component is the two-operator replication rule.

A λ finding cannot rest on one replay operator alone. Part II required independent execution by at least two replay operators or operator-equivalent environments. The point was not redundancy for aesthetics. It was protection against measurement capture. If a single replay implementation contains a hidden assumption about ordering, trace normalization, budget calculation, or gate side effects, it may manufacture or erase residue. Two-operator replication forces the finding to survive independent execution. Later audits inherit this rule.

The rule is especially important for procedures beyond the Check. LCR-A, LCR-B, Zebra-Ø, merge, and quarantine exit contain more interpretive structure than a narrowly defined operator chain. Their replay implementations may disagree because the procedure itself is under-formalized. That disagreement is not a nuisance. It is a finding. A procedure that cannot be replicated cannot yet receive a commutation certificate or a holonomy classification. It must first be formalized.

The shared infrastructure also includes outcome-vector comparison. Part II taught the canon not to reduce all difference to one scalar. Final status, witness_residue, A_B, route, quarantine signal, rejection signal, final witness result, and trace-normalized fields may diverge differently. Later procedures will define different vectors, but the comparison discipline remains. A procedure’s λ is a vector of governed differences, not a mood of instability.

This reusable stack creates a fixed-cost / marginal-cost structure.

Let C_build be the cost of building the Part II measurement infrastructure: protocol design, replay environment, hash-fixation method, contamination controls, control-run framework, two-operator replication capacity, ledger schema, comparison logic, exception register, and reporting format. This cost was high because the canon had to invent the measurement floor.

Let C_adapt(P) be the cost of adapting that infrastructure to a new procedure P: operator decomposition, precedence lattice compilation, outcome-vector definition, archive mapping, procedure-specific replay harness, and class taxonomy.

Let C_run(P) be the cost of running the audit itself: retrieving archived objects, fixing inputs, executing variants, running controls, performing replication, calculating λ and φ where relevant, classifying holonomy, and writing the ledger annex.

Then the first campaign cost can be represented as:

C_first = C_build + C_adapt(Check) + C_run(Check)

A subsequent campaign costs:

C_next(P) = C_adapt(P) + C_run(P) + C_maintenance_share

where C_maintenance_share is the small allocated cost of keeping the shared infrastructure current.

The important difference is that C_build does not repeat in full.

This is the marginal cost curve.

The second audit is still expensive because the canon must adapt the shared stack to a new procedure. It must decompose the operators, compile the lattice, define the outcome vector, and locate the archive. But it does not need to invent hash fixation again. It does not need to invent contamination controls again. It does not need to invent control-run calibration again. It does not need to invent two-operator replication again. It reuses the floor and pays the adaptation cost.

The third and fourth audits become cheaper if their procedures share form. LCR-A and LCR-B both use nine-field processing skeletons. Once the LCR-A replay harness exists, LCR-B can reuse parts of it. Quarantine exit and merge both involve held objects, witness updates, budget recalculation, and downstream dependency updates. Zebra-Ø’s internal sequence is smaller but may require higher precision because its effects are more interpretive and boundary-sensitive. The curve is not uniform, but it bends downward wherever procedure families share operator types.

A simplified marginal curve is:

C_audit(1) = very high: build + adapt + run.

C_audit(2) = high: adapt + run, with first reuse of shared controls.

C_audit(3–5) = moderate-high: adaptation decreases as procedure templates stabilize.

C_audit(n) = moderate: dominated by archive size, replay volume, and replication cost.

C_audit(mature) = variable: low for small procedures with clean archives; high for large procedures with incomplete traces, high class complexity, or non-abelian holonomy.

The curve never falls to zero.

This must be stated because shared infrastructure can create a second temptation. Once the measurement stack exists, operators may begin to speak as if audits are cheap. They are not cheap. They are cheaper than the first campaign. The difference matters. Every new procedure still requires operator decomposition. Every lattice must be compiled. Every archive must be fixed. Every control-run noise floor must be measured. Every significant finding must be replicated. Every annex must be written. The marginal cost declines, but governance does not become free.

The largest remaining cost is usually procedure formalization.

If a procedure already has clean operators, a known lattice, archived inputs, and stable outputs, replay is manageable. If a procedure exists mostly as prose, habit, interface sequence, or expert judgment, the adaptation cost may exceed the run cost. The audit then performs two functions at once: it measures λ and forces the procedure to become explicit. That is still valuable. A procedure too vague to replay is already a governance risk.

The second largest remaining cost is archive quality.

A clean archive lowers marginal cost because inputs can be fixed, traces can be recovered, and outcomes can be compared. A poor archive raises cost because the campaign must reconstruct objects, mark exceptions, estimate missing fields, and separate true order effect from trace defect. Some procedures may not be immediately auditable because their historical executions were never recorded at sufficient granularity. Those procedures enter the Holonomy Audit Registry with status: Replay Defect — Archive Insufficient.

The third largest remaining cost is class complexity.

A procedure with one stable class can be replayed more cheaply than a procedure whose objects fall into many classes with different operator relevance, different hard dependencies, different outcome vectors, and different noise floors. Class complexity increases sample size, stratification cost, and interpretation burden. This is why the registry must record class taxonomy before campaign launch.

The fourth largest remaining cost is holonomy severity.

Identity and abelian cases are cheaper to close. Non-abelian and path-critical cases are expensive because they require composed-swap campaigns, interaction mapping, remediation routing, cascade tracing, and possibly Level 3 adjacency screening. The cost curve therefore has a discovery-dependent component. A simple procedure can become expensive if it reveals non-abelian governance geometry.

The shared infrastructure changes the economics of discovery but not the seriousness of discovery.

The canon should therefore create a permanent line item:

Holonomy Audit Infrastructure — HAI

HAI covers maintenance of shared replay tools, hash-fixation procedures, contamination controls, control-run libraries, replication operators, comparison schemas, exception registers, and ledger annex formats. It is separate from the cost of any one audit. Each new campaign pays an adaptation and run cost, but the shared infrastructure is maintained continuously.

A procedure-specific campaign then carries:

Procedure Holonomy Audit Cost — PHAC(P)

where:

PHAC(P) = C_adapt(P) + C_run(P) + C_replication(P) + C_annex(P) + C_exception(P)

C_replication(P) is listed explicitly because two-operator replication is not optional. C_annex(P) is listed because the result must enter the ledger. C_exception(P) is listed because replay defects are part of the cost, not outside it.

The expected cost declines when:

operator templates already exist;

precedence lattice templates already exist;

the procedure shares outcome-vector fields with previous audits;

the archive is complete;

class taxonomy is stable;

control-run noise floors are already characterized for similar operators;

replication environments already support the procedure;

and prior holonomy tables provide generator sets.

The expected cost increases when:

operators are vague;

the lattice is implicit;

the archive is incomplete;

the procedure includes interpretive judgment;

class drift is high;

budget or witness fields are unstable;

contamination risk is high;

or non-abelian composition appears.

This produces the marginal cost rule:

The first λ campaign builds the measuring floor. Each later campaign pays the cost of adapting the floor to a procedure and running the replay, with cost decreasing as operator templates, lattice patterns, control libraries, and replication environments accumulate.

This rule supports the audit queue. It means the registry can schedule procedures strategically. It may audit LCR-A first because exposure is high. It may then audit LCR-B at lower adaptation cost because part of the nine-field processing template has already been formalized. It may audit quarantine exit after merge if both share witness and budget update operators. It may delay a high-value audit if its archive is insufficient and first run a lower-value procedure that builds a reusable template. The queue becomes budget-aware without abandoning exposure priority.

Shared infrastructure also creates comparability across audits.

If every campaign uses different fixation, different noise floors, different replication standards, and different annex formats, the canon will accumulate isolated results that cannot be compared. Part II prevents that by setting a common measurement spine. Later audits may have procedure-specific adaptations, but they must preserve the core: fixed inputs, isolated variants, calibrated controls, replicated findings, vector outcomes, class-indexed reporting, and append-only ledger annexes.

This comparability matters for synthesis in Chapter 20. The canon cannot generalize governance holonomy if each procedure’s λ is measured under incompatible conditions. The shared infrastructure makes cross-procedure comparison possible. It allows the canon to ask whether non-commutation clusters in certain procedure families, whether witness-heavy procedures show more residue, whether budget operators are common generators, whether quarantine-related procedures are more path-sensitive, or whether Zebra-Ø-like rotation operations produce non-abelian effects. Without shared infrastructure, those questions would be anecdotal.

The section compiles the following rule:

Shared Holonomy Infrastructure Rule

The measurement infrastructure built for the Part II campaign becomes the default infrastructure for all subsequent holonomy audits. Every later audit shall reuse or explicitly justify deviations from hash fixation, contamination controls, control-run calibration, two-operator replication, vector outcome comparison, exception registers, and append-only ledger annexes. The first campaign bears the main build cost; later campaigns pay adaptation and run costs. Marginal cost may decline through shared templates, but no audit may treat reuse as a waiver of measurement discipline.

This rule is the practical condition for the generalization.

The canon can now say that every procedure has a potential λ without collapsing under the weight of that sentence. The first campaign built the floor. The registry queues the procedures. The shared infrastructure lowers the cost of asking the question again.

Not to zero.

To governable.


Chapter 18 — The Reflexive Measurement

18.1 — λ of the λ-Protocol

The protocol that measures order also has an order.

This must be stated without drama. The Permuted-Order Replay Protocol was designed to measure whether a governed procedure leaves residue when its operators are executed under alternative legal orderings. It fixes inputs, decomposes gates, compiles a precedence lattice, generates linear extensions, executes replays, calibrates controls, compares outcome vectors, replicates findings, and routes the result into a certificate, a census, or a remediation branch. These are steps. They are operators in a procedure. Therefore, by the rule of Part V, the protocol itself has a possible λ.

A canon that measures ordering residue while exempting its measuring protocol from ordering residue has not completed the discipline. It has merely moved the dark sequence upward by one level. The old failure was π₀ inside the Admissibility Check. The new failure would be π₀ inside the protocol that discovered π₀. Chapter 18 prevents that displacement. It requires one level of reflexive application: the λ-protocol must be decomposed, given a lattice, replayed against legal order variants, and measured for its own Loop Residue on a sample of its own runs.

The requirement is mandatory.

It is also bounded.

This volume does not open infinite regress. It does not require the protocol that measures the protocol that measures the protocol to be measured without end. That would paralyze the canon and confuse reflexive discipline with recursive abyss. The requirement is exactly one level of self-application. The Permuted-Order Replay Protocol must be audited as a governed procedure because it has become infrastructure for all subsequent audits. Once that audit is performed, its result is recorded as the protocol’s reflexive standing. Future volumes may deepen the stack if the reflexive measurement itself reveals anomaly, but this volume does not perform unbounded recursion.

The object is:

λ_PRP — the Loop Residue of the Permuted-Order Replay Protocol.

The question is:

Would the protocol’s own conclusion change if the protocol’s internal maintenance steps were performed under another legal ordering?

The conclusion may be a Commutativity Certificate, an Outcome B activation, an indeterminate result, a protocol-defect result, a class-narrowed result, a holonomy classification, or a remediation trigger. If changing the order of protocol steps changes the conclusion, the measurement instrument is order-fragile. If changing the order leaves the same conclusion but alters witness_residue, error-budget calibration, confidence standing, class scope, or Notes-field requirements, the protocol has residue-level λ. If changing the order produces no difference within the declared error budget, the protocol earns reflexive commutation standing for the tested scope.

The design is cheaper than it could have been because the protocol was written order-explicitly from the beginning.

This was deliberate. Part II did not define the replay campaign as a loose research practice. It named its steps, declared its dependencies, separated hard precedence from inherited sequence, fixed branch points, and required traceable records. That design choice now pays back. Because the protocol’s operators were already visible, Chapter 18 does not have to excavate them from habit. It can treat them as a procedure already prepared for audit.

The Permuted-Order Replay Protocol decomposes into the following operators:

O_P1 — Campaign Scope Fixation. The procedure fixes the target governed procedure, class scope, epoch scope, operator set, and campaign question.

O_P2 — Archive and Input Hash Fixation. The procedure identifies archived inputs, fixes them by hash, records exceptions, and prevents state drift between variants.

O_P3 — Operator Decomposition Verification. The procedure verifies that the target procedure’s operators are sufficiently defined to be replayed.

O_P4 — Precedence Lattice Compilation. The procedure compiles the target procedure’s hard dependencies and legal ordering space.

O_P5 — Ordering Variant Generation. The procedure generates π₀, legal linear extensions, swap generators, and any tested ordering subset.

O_P6 — Contamination Control Setup. The procedure establishes isolation, separate trace channels, read-only input snapshots, and side-effect barriers.

O_P7 — Control-Run Calibration. The procedure repeats baseline and identity runs to establish field-specific noise floors.

O_P8 — Replay Execution. The procedure executes the target procedure under π₀ and the selected legal orderings.

O_P9 — Two-Operator Replication. The procedure repeats or verifies the result through an independent replay operator or operator-equivalent environment.

O_P10 — Outcome Vector Comparison. The procedure compares final status, witness_residue, A_B, route, trace fields, and procedure-specific terminal fields.

O_P11 — λ / φ / Holonomy Computation. The procedure computes residue, status fragility, swap composition, commutators, and classification where applicable.

O_P12 — Branch Determination and Ledger Annex. The procedure routes the result to certificate, Outcome B, indeterminate status, protocol defect, census, or remediation annex.

This decomposition is not merely explanatory. It is the object to be audited. Each O_P operator may have hard dependencies. O_P1 must precede all because no campaign can run without a fixed target and scope. O_P2 must precede replay execution. O_P3 must precede legal replay, because undefined operators cannot be replayed. O_P4 must precede O_P5, because legal variants cannot be generated before the lattice exists. O_P6 must precede O_P8. O_P7 must precede threshold interpretation. O_P8 must precede O_P10. O_P10 must precede O_P11. O_P12 must remain terminal.

But not every historical sequence is necessarily hard. Some relations may be candidates for replay. Control-run calibration might be performed before or after contamination controls are fully specified, though the latter may prove unsafe. Operator decomposition verification might occur before archive fixation or after initial archive review. Two-operator replication might be run as a parallel replication path rather than after first replay completion. Outcome-vector definition might be attached to scope fixation, lattice compilation, or comparison design. These degrees of freedom must be named.

The preliminary precedence lattice is therefore:

O_P1 precedes all.

O_P4 follows O_P3.

O_P5 follows O_P4.

O_P8 follows O_P2, O_P5, O_P6, and the relevant portion of O_P7.

O_P10 follows O_P8.

O_P11 follows O_P10 and O_P7.

O_P12 follows O_P9 and O_P11.

O_P2 and O_P3 may be tested for commutation under controlled conditions.

O_P6 and O_P7 may be tested only where safety permits, because contamination setup before calibration may be a hard requirement for valid noise measurement.

O_P8 and O_P9 may be serial or partially parallel depending on replication design, but any parallelization must preserve independence.

This lattice is enough to generate legal protocol variants. It does not imply that all variants are safe for live campaign use. Most variants are replay-only. The reflexive audit tests archived runs of the protocol, not live frontier decisions, unless an LCR explicitly authorizes otherwise. The protocol is being measured; it is not being casually rearranged in production.

The input population for λ_PRP is a sample of the protocol’s own runs.

These runs include the Part II campaign records, selected maintenance runs, selected holonomy audit simulations, and any complete replay campaigns that used the same protocol schema. The sample must include at least one run that returned λ = 0, one run that returned nonzero λ or φ > 0 if available, one indeterminate or near-threshold run if available, and one control-heavy run where noise-floor interpretation mattered. The point is to test the protocol across its decision types, not merely its clean cases.

For each archived protocol run R, the reflexive audit fixes the original campaign materials: target procedure, archived inputs, operator decomposition, lattice version, ordering set, control outputs, replay outputs, replication records, comparison tables, and branch result. It then re-executes the protocol over the same fixed campaign materials under legal variants of the protocol’s own step order. The output vector is:

Ω_PRP(R, π_P) = protocol conclusion, λ values, φ values, holonomy classification, error-budget status, control-run noise floor, replication status, branch route, ledger annex content, Notes-field requirements, and rollback or remediation trigger.

The reflexive residue is:

λ_PRP(R, π_P) = Ω_PRP(R, π_P) − Ω_PRP(R, π₀P)

where π₀P is the historical ordering of the protocol’s own steps.

If λ_PRP = 0 within the declared error budget across the tested sample, the protocol receives Reflexive Standing Confirmed for the tested scope. If λ_PRP is nonzero but branch conclusions remain stable, the protocol receives Reflexive Residue Noted and must attach a maintenance note. If branch conclusions change, the protocol is Reflexively Order-Fragile and must route to protocol remediation before future campaigns can rely on the affected sequence. If the result cannot be interpreted because the protocol’s own archive is incomplete, it receives Protocol Replay Defect.

The possible classifications are:

Reflexive Standing Confirmed.

Reflexive Residue Noted.

Reflexive Budget / Error-Band Fragility.

Reflexive Branch Fragility.

Reflexive Holonomy Detected.

Protocol Replay Defect.

Reflexive Audit Indeterminate.

These statuses matter because the λ-protocol is shared infrastructure. A defect in an ordinary procedure affects that procedure. A defect in the λ-protocol affects every campaign that relies on it. If the protocol’s internal order changes whether a class receives a certificate, whether Outcome B activates, or whether a result is indeterminate, the canon cannot proceed as if the measurement floor were neutral. The floor has curvature. It must be repaired before the next audit stands on it.

The mandatory single level of self-application therefore has three functions.

First, it prevents methodological hypocrisy. The method that says every multi-step procedure has potential λ must include itself.

Second, it protects future audits. If the protocol has order residue, later holonomy campaigns inherit that defect unless corrected.

Third, it records a reflexive boundary for the volume. The canon asks the question of its own instrument once, logs the result, and refuses both exemption and infinite regress.

The design choice that makes this cheap must be named as a success of Part II. The protocol’s steps were defined order-explicitly in anticipation of this chapter. Campaign scope fixation, hash fixation, operator verification, lattice compilation, variant generation, contamination control, control-run calibration, replay execution, replication, comparison, computation, and branch determination were not blended into a general activity called “audit.” They were separated because the canon already knew that a later reflexive audit would need operators. Chapter 18 is not an afterthought. It was seeded in the protocol design.

That anticipation lowers C_adapt(PRP). The protocol’s operator list exists. Its historical ordering exists. Its hard dependencies are mostly known. Its outcome vector is already standardized. Its archives are structured. Its control runs are recorded. Its replication rule is explicit. The reflexive campaign therefore pays mainly run and comparison cost, not excavation cost.

The marginal cost formula is:

C_reflexive(PRP) = C_run(PRP-on-PRP) + C_replication(PRP-on-PRP) + C_annex(PRP-on-PRP) + C_exception(PRP-on-PRP)

with low C_adapt because the protocol was designed for self-audit.

This does not mean the reflexive measurement is trivial. It means it is governable. A badly designed protocol would now require a separate archaeology of its own steps. This one does not. The cost was prepaid by order-explicit design.

The reflexive audit produces its own ledger artifact:

λ-Protocol Reflexive Audit Annex

The annex records the protocol operator decomposition, protocol precedence lattice, sampled protocol runs, tested protocol-order variants, control-run noise floors, replicated outcomes, λ_PRP values, branch stability, holonomy classification if any, protocol standing status, required maintenance corrections, and limits on future use.

The annex must include one field in particular:

Self-Application Ceiling: one level completed; no infinite regress opened by this volume.

This ceiling is not an evasion. It is a compiled boundary. The canon is allowed to stop after one reflexive level because the purpose of the volume is to ensure that the measurement instrument is not exempt from its own rule. If the reflexive audit returns stable standing, the protocol may proceed under maintenance. If it returns anomaly, the anomaly itself may justify a future deeper reflexive lineage. But absent anomaly, the volume does not recurse.

The rule is therefore:

λ of the λ-Protocol Rule

The Permuted-Order Replay Protocol is itself a governed multi-step procedure and must receive one mandatory self-application. The canon shall decompose the protocol into operators, compile its precedence lattice, replay a sample of its own archived runs under legal protocol-order variants, compute λ_PRP, and record a reflexive standing annex. This volume requires exactly one level of self-application: enough to prevent exemption, not enough to open unbounded regress.

The section closes the loop without closing the inquiry.

The protocol measured the Check.

Now the protocol is measured by its own method.

If it stands, the canon gains shared infrastructure with reflexive standing.

If it does not, the canon has discovered that even its measuring law has order.

Either result belongs in the ledger.


18.2 — The Tower Terminates in the Budget

A reflexive measurement creates the temptation of a tower.

If the protocol must measure itself once, why not measure the measurement of that measurement? If the λ-protocol has a possible λ, then the protocol that audits λ_PRP also has an ordering. That ordering may also leave residue. A third level may be required. Then a fourth. Then a fifth. The structure appears to open indefinitely: a tower of measurements, each demanding another measurement above it.

The canon must not answer this by decree.

It must answer by price.

The general rule of the paradigm is not that regress is forbidden because regress is uncomfortable. The rule is that regress becomes non-admissible when its cost exceeds the budget under which it seeks permission to continue. A reflexive tower is not metaphysically evil. It is a campaign structure. It consumes A_B. It consumes replay capacity, archive fixation, contamination control, replication bandwidth, operator attention, ledger space, and interpretive maintenance. Each level must therefore pay. If the summed cost of the tower exceeds the campaign allocation, the tower is non-admissible as a whole.

This is the budget answer to regress.

The first level is mandatory because exemption would be incoherent. A method that says every multi-step procedure has a potential λ must not exempt the procedure by which λ is measured. The Permuted-Order Replay Protocol must receive one self-application. Its operators must be decomposed. Its lattice must be compiled. A sample of its own runs must be replayed. Its own λ_PRP must be measured. Without that first level, the canon would preserve the same hidden-order problem inside the instrument that exposes hidden order elsewhere.

The second level is conditional.

If the first reflexive audit returns stable standing — no branch fragility, no protocol-level status shift, no significant λ_PRP beyond declared error, no holonomy defect, no replication instability — then the tower stops at one level under ordinary conditions. It may still be maintained. It may still be reopened under future anomaly. But it does not automatically require a second reflexive campaign. The first level has paid the non-exemption cost.

If the first reflexive audit returns nonzero λ_PRP, then a second level becomes eligible and may become mandatory depending on severity. A residue-only protocol finding may require Notes-field correction and maintenance. A branch-fragile finding may require a second-level audit of the reflexive audit procedure itself before future campaigns can rely on the repaired measurement stack. A non-abelian or path-critical finding may require deeper examination because the method by which the method is repaired may itself be order-sensitive.

Thus:

Level 1 self-application: mandatory.

Level 2 self-application: conditional on nonzero Level 1 findings or protocol instability.

Level n self-application: conditional on unresolved nonzero findings at Level n−1 and available budget.

The tower does not continue because logic can imagine it.

It continues only if the previous level produces a live reason and the budget can bear the next level.

Let R_k denote the k-th reflexive level.

R_0 is the original Permuted-Order Replay Protocol applied to an object procedure.

R_1 is the protocol applied to itself.

R_2 is the protocol applied to the R_1 measurement procedure.

R_3 is the protocol applied to the R_2 measurement procedure.

And so on.

Let A_B(R_k) be the admissibility budget cost of executing reflexive level k, including operator decomposition, lattice compilation, archive fixation, replay execution, control-run calibration, replication, comparison, ledger annexing, and exception handling. Let B_campaign be the total budget allocated to the reflexive campaign. The tower is admissible only while:

Σ_{k=1}^{m} A_B(R_k) ≤ B_campaign

and while each next level satisfies a trigger condition derived from the previous level.

The two conditions are conjunctive.

A tower with budget but no trigger is unnecessary.

A tower with trigger but no budget is non-admissible.

This prevents both obsessive regress and negligent closure. The canon cannot keep measuring upward merely because purity demands it. It also cannot stop after a nonzero reflexive finding merely because stopping feels cleaner. The next level is a governed action. It requires both cause and budget.

The trigger condition for Level k+1 is:

T_{k+1} = nonzero λ at Level k, branch fragility at Level k, holonomy defect at Level k, protocol replay defect at Level k, or unresolved indeterminacy affecting the standing of lower-level conclusions.

If T_{k+1} is false, the tower terminates.

If T_{k+1} is true, the tower requests budget.

If budget is granted, Level k+1 runs.

If budget is not granted, the tower terminates with an unpaid reflexive debt and the affected lower-level conclusions receive restricted standing.

This last condition is important. Budget termination is not the same as clean resolution. If the tower stops because the next necessary level cannot be paid, the canon must say so. It cannot convert budget exhaustion into certainty. The correct status is:

Reflexive Debt — Budget-Terminated.

This status means that the canon has identified a reason for deeper self-application but has not allocated sufficient A_B to perform it. The affected protocol may continue only under the restrictions declared in the termination entry. These restrictions may include sealed use, class narrowing, maintenance escalation, no new certificate issuance, no high-risk campaign use, or mandatory human / external audit overlay where applicable.

Budget arithmetic terminates the tower operationally.

It does not erase the epistemic remainder.

This distinction preserves honesty. A tower that ends because the next level is unnecessary has standing closure. A tower that ends because the next level is unaffordable has budget closure and explanatory residue. The two must not be merged.

The reflexive budget formula can be written plainly:

C_tower(m) = Σ_{k=1}^{m} [C_decompose(R_k) + C_lattice(R_k) + C_hash(R_k) + C_control(R_k) + C_replay(R_k) + C_replication(R_k) + C_compare(R_k) + C_annex(R_k) + C_exception(R_k)]

The campaign is admissible if:

C_tower(m) ≤ B_campaign

and every level k > 1 is triggered by the result of k−1.

The formula is not elegant. It is not meant to be. Regress becomes governable when it is priced in the same terms as other admissibility actions. The canon does not escape regress by philosophical declaration. It converts regress into budgeted procedure. The procedure continues only while it is both necessary and admissible.

This is the paradigm’s general answer to regress.

Where another system might say “we stop here because infinite regress is impossible,” the canon says: we stop where the next measurement no longer has a trigger, or where the triggered measurement exceeds the budget and must be recorded as unpaid. The difference matters. The first answer hides authority inside an arbitrary stopping point. The second exposes the stopping point as an admissibility decision.

The tower therefore terminates in A_B.

It may terminate cleanly because the previous level returns zero within error and stable branch standing.

It may terminate conditionally because the previous level returns nonzero residue but below remediation threshold.

It may terminate restrictively because the previous level demands further audit but budget cannot support it.

It may terminate catastrophically if the protocol’s reflexive standing collapses and no lower-level conclusion can retain authority without replacement.

Each termination mode must be named.

Clean Termination occurs when Level 1 or a later level returns no actionable reflexive residue and no branch instability. The tower closes with Reflexive Standing Confirmed.

Notes Termination occurs when residue exists but does not affect branch outcome, budget threshold, holonomy class, or protocol standing. The tower closes with Reflexive Residue Noted and maintenance requirements.

Conditional Continuation occurs when nonzero findings trigger the next level and budget is available. The tower does not terminate yet.

Budget Termination occurs when a next level is triggered but the sum of required A_B exceeds B_campaign. The tower closes with Reflexive Debt — Budget-Terminated.

Protocol Suspension Termination occurs when reflexive findings invalidate the protocol’s use before further self-application can be meaningfully executed. The tower closes with Protocol Standing Suspended and routes to replacement or external LCR.

The linter for this section has three patterns.

Regress by Purity fires when an artifact demands another reflexive level without a nonzero or indeterminate finding at the previous level.

Closure by Decree fires when an artifact stops the reflexive tower despite a live trigger and available budget, using only convenience, fatigue, or authority as justification.

Budget Exhaustion Concealment fires when an artifact reports a budget-terminated tower as if the reflexive issue were resolved.

These linters prevent both infinite ascent and premature rest.

The tower must also obey the two-operator replication rule at each level where a substantive finding is claimed. A reflexive level that cannot be replicated cannot certify the protocol. It may only produce an indeterminate or defect status. Replication cost is therefore part of A_B(R_k). It cannot be removed to make the tower affordable. If removing replication is the only way to keep the tower under budget, the tower is non-admissible at that level.

The same applies to control-run calibration. A reflexive level without a noise floor cannot declare λ zero. It can only say that it did not measure sufficiently. Therefore, budget arithmetic must include the cost of controls. A cheap tower that omits controls is not a tower. It is performance.

This section also prevents a subtler error: using budget to evade necessary reflexivity. A campaign owner might allocate a very small B_campaign so that deeper levels become unaffordable by design. That would make budget termination too easy. The initial reflexive campaign allocation must therefore be justified against the known exposure of the protocol. If the λ-protocol is shared infrastructure for all future holonomy audits, its reflexive budget cannot be trivial. The budget line must be large enough to pay at least the mandatory first level and a contingency band for one conditional second level if Level 1 returns nonzero.

This produces the minimum allocation rule:

B_campaign ≥ A_B(R_1) + reserve(A_B(R_2))

where reserve(A_B(R_2)) is a declared contingency estimate for conditional second-level self-application.

If the canon cannot fund that minimum, it may not claim that the λ-protocol has full reflexive standing. It may run Level 1, but any nonzero Level 1 result will immediately create Budget-Terminated Reflexive Debt. The ledger must know that before the campaign begins.

The reflexive budget also has a decay function. A protocol that receives clean Level 1 standing today may require renewed reflexive audit after major amendment. If the protocol’s operator order changes, if its lattice changes, if its control-run method changes, if its replication rule changes, or if its branch determination logic changes, the prior λ_PRP standing may no longer apply. Reflexive standing is not eternal. It is maintained like other witnessed objects.

However, renewed reflexive audit is not the same as deeper regress. A protocol amendment may require a new Level 1 self-application for the amended protocol. It does not automatically require R_2, R_3, or beyond unless the new Level 1 returns nonzero. The tower restarts only where the object changes. It does not climb by habit.

The section compiles the following rule:

Budget-Terminated Reflexivity Rule

The Permuted-Order Replay Protocol must receive one mandatory self-application. A second reflexive level is conditional on nonzero, indeterminate, branch-fragile, or protocol-defect findings at the first level. Further levels are conditional on unresolved findings at the preceding level. Each level spends A_B. The reflexive tower continues only while the next level is both triggered and affordable under the campaign allocation. If a triggered next level exceeds the available budget, the tower terminates with Reflexive Debt — Budget-Terminated, not with clean resolution.

This rule is the paradigm’s general answer to regress.

Regress is not defeated by pretending that one level is enough in all cases.

Regress is not obeyed by climbing forever.

Regress is priced.

Where the price is paid and the trigger remains live, the canon climbs.

Where the trigger is absent, it stops.

Where the trigger is present and the budget is insufficient, it stops with debt.

The tower does not terminate by decree.

It terminates in the ledger.


18.3 — Shadow Layer C in the Mirror

The most dangerous reflexive failure is not finding residue in the protocol.

The most dangerous failure is refusing to look.

A campaign that measures ordering effects in governed procedures and then exempts its own measuring protocol because the protocol “obviously” commutes has recreated the condition this volume exists to retire. It has moved dark canon into the mirror. The old unmeasured π₀ becomes the new unmeasured protocol order. The procedure that exposes hidden ordering becomes hidden ordering. The canon then congratulates itself for measuring law while allowing the measuring law to pass unmeasured.

This is Shadow Layer C in reflexive form.

Shadow Layer C occurs when a runtime-adjacent procedure conditions admissibility, certification, replay, residue measurement, or branch determination without being entered into the same discipline it applies to others. In the original crisis, the Admissibility Check’s canonical ordering was active without compilation. In the reflexive crisis, the Permuted-Order Replay Protocol becomes active without self-application. It remains procedural background while its outputs govern certificates, Outcome B activation, holonomy tables, remediation triggers, and future audits.

That is not a small exception.

It contaminates the measurement floor.

The phrase “obviously commutes” is the warning sign. Nothing in this volume permits obvious commutation as a governance status. Obviousness is not a certificate. Familiarity is not a control run. Clean prose is not a precedence lattice. Confidence is not replication. A protocol may appear sequentially natural because its documentation was written in a plausible order. That is exactly how dark sequence enters law. It looks natural until a replay campaign asks whether natural order carries residue.

The reflexive protocol must not be exempted by the same intuition that once protected π₀.

The failure mode has a specific structure. A campaign runs the Permuted-Order Replay Protocol against a target procedure. It produces a certificate, an Outcome B branch, an indeterminate finding, or a holonomy classification. The campaign records hash fixation, control-run calibration, contamination controls, and two-operator replication for the target. But when asked whether the replay protocol itself has been decomposed, latticed, and self-applied, the record says: not required; protocol order is fixed by design; protocol steps are logically obvious; self-application would be wasteful; no plausible alternative order exists; the protocol’s correctness is presupposed.

This is a defect.

A protocol may have hard ordering constraints. If so, the lattice will show them. A protocol may have no meaningful alternative legal extensions. If so, the self-application will be cheap and will return a strict-lattice result. A protocol may commute. If so, it can earn reflexive standing. But none of these outcomes may be assumed before the reflexive record exists.

The detection rule is therefore simple:

Any holonomy campaign that lacks a λ-Protocol Reflexive Audit Annex, a valid prior reflexive standing reference, or a declared budget-terminated reflexive debt has exempted itself.

This applies to the Part II campaign after Chapter 18 is compiled and to every later campaign that uses the Permuted-Order Replay Protocol. A campaign may not claim full standing if it has no reflexive status for its measuring protocol. It may remain provisionally useful. It may remain historically informative. It may still supply evidence. But it may not claim the highest certification status because its own ordering remains unmeasured.

The campaign record must therefore contain one of four reflexive statuses:

Reflexive Standing Confirmed.

Reflexive Residue Noted with maintenance conditions.

Reflexive Debt — Budget-Terminated.

Reflexive Audit Missing.

The first two allow the campaign to proceed under their declared limits. The third permits restricted use only if the budget-termination conditions and standing restrictions are explicit. The fourth is a defect. A campaign marked Reflexive Audit Missing cannot issue a clean Commutativity Certificate, cannot activate Outcome B without provisional marking, cannot finalize a Check Holonomy Table, and cannot authorize remediation law without correction.

This does not mean every campaign with missing reflexive audit is false.

It means its standing is incomplete.

The distinction matters. The canon does not discard evidence merely because a procedural defect is found. It classifies the defect, routes the campaign to rollback readiness, and determines whether the missing self-application could have changed the branch outcome. Some campaigns will survive after reflexive audit. Some will require Notes-field restriction. Some will need rerun. Some will become void.

The rollback condition depends on what the exempted campaign produced.

If the campaign produced only exploratory data with no governance standing, the correction may be a Notes-field annotation and future self-application before citation. If the campaign produced a Commutativity Certificate, the certificate enters Pending Reflexive Validation until the protocol’s self-application is completed. If the campaign activated Outcome B, the activation becomes Provisionally Active Under Reflexive Defect, allowing only immediate safety measures and census preparation, not final remediation law. If the campaign produced a holonomy classification, the classification becomes Holonomy Pending Protocol Standing. If the campaign authorized variant execution, that authorization is suspended unless an independent LCR confirms emergency standing.

The rollback rule is:

A campaign that exempted its measuring protocol from mandatory self-application must be rolled back to the last point before its output acquired binding governance force.

That point differs by campaign. For a certificate, it is before issuance. For Outcome B, it is before final branch activation. For a holonomy table, it is before remediation dependency. For a variant authorization, it is before runtime execution. The rollback does not erase the campaign. It removes or suspends the binding force of its outputs until reflexive standing is restored.

The detection artifact is named:

Reflexive Exemption Defect Entry

It records the campaign ID, protocol version, missing self-application field, outputs affected, governance force already granted, downstream artifacts citing the campaign, and required rollback action. It must also classify whether the exemption was explicit, implicit, budget-justified, or concealed.

An explicit exemption says: self-application was considered and rejected.

An implicit exemption says: self-application was omitted with no record.

A budget-justified exemption says: self-application was triggered but not funded.

A concealed exemption says: the campaign represented itself as fully compliant while lacking reflexive audit.

These are different defects. Explicit exemption is a procedural refusal. Implicit exemption is a design omission. Budget-justified exemption may be lawful if recorded as debt. Concealed exemption is a governance violation.

The linter for this section has four patterns.

Obvious Commutation Claim fires when a protocol asserts that its ordering need not be measured because the steps are logical, natural, fixed, administrative, or self-evidently dependent.

Protocol Exemption fires when a campaign applies holonomy discipline to a target procedure but does not carry reflexive standing for the measuring protocol.

Full Standing Without Reflexive Annex fires when a campaign issues a certificate, branch activation, or holonomy classification at full force while reflexive self-application is missing, indeterminate, or budget-terminated without restrictions.

Concealed Reflexive Defect fires when a campaign’s compliance summary omits the missing self-application while presenting the protocol as fully measured.

The correction path is mandatory. The campaign must first stop issuing new binding outputs. Second, it must open a Reflexive Exemption Defect Entry. Third, it must execute the mandatory λ_PRP self-application if budget is available. Fourth, it must re-evaluate whether the protocol’s self-application changes the campaign’s branch, certificate, holonomy classification, or remediation trigger. Fifth, it must update every downstream artifact that cited the campaign at a stronger standing than the corrected status permits.

If the self-application returns λ_PRP = 0 within declared error and stable branch standing, the campaign may be restored. The restoration entry must say that the defect was procedural and has been cured. The original campaign remains annotated because it issued before reflexive validation, but its outputs may regain full force if no downstream distortion occurred.

If the self-application returns residue without branch change, the campaign may be restored with Notes-field constraints. Certificates issued by it may remain valid but must cite Reflexive Residue Noted. Holonomy classifications may remain operational but must carry the protocol-residue note. Future campaigns must apply the maintenance conditions before using the same protocol version.

If the self-application returns branch fragility, the campaign cannot be restored automatically. Its outputs enter rollback review. A certificate may be voided or reissued. Outcome B activation may require rerun. Holonomy tables may require recomputation. Remediation LCRs dependent on the campaign may be returned or suspended. The defect has touched the branch itself.

If the self-application cannot be performed because budget is insufficient, the campaign receives Reflexive Debt — Budget-Terminated. It may retain only restricted standing. It cannot issue full certificates. It cannot finalize Level 3 adjacency claims. It cannot authorize irreversible remediation. It may support sealed analysis, provisional safety suspension, or preparation of a funded reflexive campaign.

The rollback declaration for an exempted campaign is therefore:

A campaign that exempted itself from mandatory reflexive measurement loses full governance standing until λ_PRP is measured or budget-terminated restrictions are compiled. All binding outputs are suspended, narrowed, or downgraded according to the severity of the missing self-application and the force already granted downstream.

This is severe because the failure is reflexive. The protocol is the instrument by which the canon learns whether ordering matters. If that instrument smuggles in unmeasured order, every later audit inherits an unpriced assumption. The defect is not only inside one campaign. It can propagate into the Holonomy Audit Registry, variant authorization, certificate maintenance, and remediation law.

The canon must therefore treat reflexive exemption as a first-class rollback trigger.

The section compiles the following rule:

No Reflexive Exemption Rule

No campaign using the Permuted-Order Replay Protocol may claim full governance standing unless the protocol has received mandatory self-application, valid reflexive standing, or explicitly recorded budget-terminated debt with restrictions. The claim that the protocol “obviously” commutes is itself a Shadow Layer C defect. A campaign that exempted itself must be detected, annotated, suspended where binding force was granted, and rolled back to the last point before its outputs became operative law.

The mirror is the final hiding place.

A canon may learn to see dark order in its procedures and still fail to see dark order in its seeing. Chapter 18 exists to prevent that last exemption. It does not demand infinite self-suspicion. It demands one honest turn of the method upon itself, and a budget rule for what happens if that turn finds residue.

The protocol may commute.

But it must not be believed to commute.

It must be measured.


Chapter 19 — Order Leaks

19.1 — The Spectrum Carries the Ordering

The Refusal Spectrum is not order-neutral after Outcome B.

This is the first operational leak.

Node 1 defined the Refusal Spectrum R as the structured distribution of refusal, quarantine, silence, redirection, and admissibility-border events across the canon’s boundary. It asked where a state fails, how it fails, how much witness remains, what kind of refusal is produced, and how refusal density changes across classes. Before the λ campaign, R could be read as a property of the boundary alone. After Outcome B, that reading is incomplete. A state that dies at the first question asked may die somewhere else when the questions are asked in a different order.

Failure-locus statistics therefore carry ordering content.

If π₀ asks the zero-questions before the blocking-questions, a state may fail as zero-inadmissible. If another legal ordering asks a blocking-question first, the same state may fail as blocked-before-zero. If Zebra-Ø moves earlier, the same state may become non-admissible before budget is computed. If budget computation moves before a later witness check, the state may appear budget-exhausted rather than witness-defective. The terminal outcome may remain rejection, but the failure locus changes. The refusal is not the same refusal.

This matters because the Refusal Spectrum records not only final denial. It records the shape of boundary contact. The spectrum tells the canon what kinds of objects are being refused, where refusal concentrates, which gates generate silence, which classes produce quarantine, and which failure modes dominate the frontier. If the order of gates changes those statistics, then R is partly an ordering fingerprint.

The operational result-schema is straightforward.

For a fixed state Σ, a fixed procedure P, and an ordering π, define the failure locus:

F_π(Σ) = the first gate or operator under π that produces terminal refusal, quarantine, non-admissibility, silence, hold, or binding redirection.

If no terminal failure occurs, F_π(Σ) records the final admission locus or commit route.

For a class C, define the Refusal Spectrum under ordering π:

R_π(C) = distribution of F_π(Σ), refusal type, quarantine type, silence type, witness_residue at refusal, A_B at refusal, route, and final status for all Σ ∈ C.

The historical spectrum was therefore:

R_π₀(C)

not simply R(C).

If order matters, every refusal statistic must carry the ordering index. The number of failures at G_Z1, G_B3, G_Ø, budget computation, embargo, final witness check, or commit boundary is not a pure measurement of the boundary. It is a measurement of the boundary under a sequence. The spectrum is a trace of curvature plus a trace of order.

This forces a decomposition.

R_π(C) = R_curv(C) + R_order(π, C) + ε

where R_curv(C) is the order-invariant portion of the refusal landscape, R_order(π, C) is the component introduced or shaped by ordering, and ε is measurement noise, archive defect, or unresolved interaction.

This expression is schematic, not a claim that the components are always linearly separable. Its function is disciplinary. It prevents the canon from reading R_π₀ as if it were pure curvature. Some refusal density may belong to the boundary’s geometry. Some may belong to the order by which the boundary was interrogated.

The task is to estimate the split.

If a state fails at the same gate, with the same refusal type, same status, same witness_residue within error, and same A_B relation across all tested legal orderings, then its contribution to R is likely curvature-dominant. The boundary rejects it independently of ordering, at least within the tested lattice. Its refusal belongs more to R_curv than to R_order.

If a state rejects under all orderings but moves its failure locus from one gate to another, then the final status is stable but the spectrum is order-sensitive. It contributes to R_order even if φ does not register a status flip. This is why φ is not enough. The state is not status-fragile, but it is spectrum-fragile.

If a state quarantines under one ordering, rejects under another, and commits under a third, then both R and φ are order-sensitive. It contributes to status fragility, spectrum fragility, and possibly holonomy classification.

If a state fails only after a different path has accumulated different witness_residue or A_B, then the spectrum carries mixed content. The failure locus may appear stable, but the condition of failure has changed. Such states require residue-field annotation.

The canon therefore needs a second index beside φ.

Define the Failure-Locus Fragility Index:

ψ_R(C, Π) = fraction of states in class C whose failure locus F_π(Σ) differs across tested legal orderings π ∈ Π, whether or not final status changes.

φ asks whether the final status changes.

ψ_R asks whether the spectrum location changes.

A class can have φ = 0 and ψ_R > 0. That means every state receives the same final status across tested orderings, but the canon’s explanation of where refusal occurs is order-dependent. Operationally, this is less severe than status fragility but still important. It changes diagnostics, gate maintenance, refusal-spectrum statistics, frontier-node interpretation, and future mitigation.

A class can have ψ_R = 0 and λ ≠ 0. That means failure locus remains stable, but witness_residue, A_B, route annotations, or other fields differ. That is residue without spectrum movement.

A class can have φ > 0. Then ψ_R is usually nonzero as well, but the two should still be recorded separately because one measures terminal status and the other measures boundary contact distribution.

The Refusal Spectrum must therefore be reindexed after Outcome B:

R → R_π
R(C) → R_π(C)
R historical → R_π₀(C)
R comparison → ΔR(π, π₀, C)

The comparison field is:

ΔR(π, π₀, C) = R_π(C) − R_π₀(C)

where the subtraction is again field-specific. For categorical failure loci, it is a transition table. For refusal density, it is a distribution delta. For witness_residue, it is a numerical or vector delta. For A_B, it is budget-position difference. For silence, it is change in silence type, silence timing, or silence density.

A useful transition table records:

G_Z1 under π₀ → G_B2 under π
G_Z3 under π₀ → G_Ø under π
G_B4 under π₀ → budget threshold under π
G_Ø under π₀ → embargo under π
quarantine under π₀ → rejection under π
rejection under π₀ → quarantine under π
silence under π₀ → explicit refusal under π
explicit refusal under π₀ → silence under π

These transitions are not merely clerical. They show where the boundary’s apparent shape depends on sequence. If many states move from late failure to early refusal under an alternative ordering, then the historical spectrum may have overstated late-stage burden. If many states move from Zebra-Ø to budget failure, then the canon may have misclassified mythic inflation as budget exhaustion or vice versa. If silence moves earlier under one ordering, then silence density may not be a pure property of the state class. It may be produced by gate position.

This is the order leak.

The spectrum carries the path by which it was produced.

Node 1 must therefore be reread through Chapter 19. Its Refusal Spectrum remains valid, but only with an ordering index. The historical spectrum is not discarded. It becomes the π₀-spectrum. It tells the truth about the canon as it actually operated. But it does not automatically tell the truth about the boundary independent of ordering. To find the order-invariant part, the canon must compare spectra across legal extensions.

The operational artifact is:

Refusal Spectrum Ordering Decomposition — RSOD

The RSOD records, per class:

historical ordering π₀;

tested ordering set Π;

R_π₀(C);

R_π(C) for each tested π;

failure-locus transition matrix;

ψ_R;

φ;

λ fields affecting refusal;

order-invariant refusal density estimate;

ordering-sensitive refusal density estimate;

dominant gate movements;

silence movement;

quarantine / rejection / commit transitions;

witness_residue at failure by ordering;

A_B at failure by ordering;

holonomy notes where spectrum transitions depend on path;

and unresolved noise or archive defects.

This artifact does not replace the Refusal Spectrum. It annotates it. The spectrum becomes a family indexed by ordering, and the RSOD estimates how much of that family belongs to boundary curvature and how much belongs to sequence.

The terms must be controlled.

Curvature content is the portion of R that remains stable across tested legal orderings: stable failure loci, stable refusal types, stable silence density, stable quarantine patterns, and stable witness / budget relations within declared error. It indicates boundary structure that does not appear to depend on operator sequence inside the tested lattice.

Ordering content is the portion of R that changes across tested legal orderings: shifted failure loci, changed refusal types, changed silence timing, changed quarantine/rejection distribution, changed A_B at failure, changed witness_residue at failure, or changed route explanation. It indicates that the spectrum is partly produced by the order of interrogation.

Unresolved content is the portion that cannot yet be assigned because of archive defects, noise-floor overlap, incomplete replay, underdefined operators, or non-abelian path effects requiring additional holonomy measurement.

The decomposition is:

R_π₀(C) = R_curv(C) ⊕ R_order(π₀, C) ⊕ R_unresolved(C)

The symbol ⊕ is used because the components may not be simple numerical addition. They may be distributional, categorical, or vector components. The purpose is to keep them separate in the ledger.

This decomposition matters for governance because Refusal Spectrum statistics often drive repair. If the canon sees many failures at Zebra-Ø, it may strengthen Zebra-Ø. If it sees many budget failures, it may alter proof-friction cost. If it sees many quarantine exits failing late, it may revise quarantine procedure. But after Outcome B, such repairs must ask whether the observed locus is curvature or ordering. Repairing a gate because π₀ made it appear as the failure locus may be wrong if another ordering reveals that the same states fail earlier or elsewhere.

This creates a linter:

Spectrum Without Ordering Index fires when Refusal Spectrum statistics are cited after Outcome B without specifying π, π₀, or a commutation certificate.

Failure-Locus Inflation fires when a gate is described as the source of refusal without acknowledging that it may be the first gate to expose refusal under the chosen ordering rather than the unique cause of refusal.

Curvature-Order Conflation fires when R_π₀ is interpreted as pure boundary curvature despite nonzero λ, nonzero ψ_R, or unmeasured ordering.

The correction is to append the ordering index, run or cite RSOD, and downgrade causal claims until curvature content has been separated from ordering content.

The section compiles the following rule:

Refusal Spectrum Ordering Rule

After Outcome B, the Refusal Spectrum must be treated as ordering-indexed. Failure-locus statistics depend on the gate order because the first terminal question asked can determine where a state appears to die. The historical Refusal Spectrum is R_π₀, not order-free R. Every cited spectrum must distinguish curvature content from ordering content or declare that the distinction remains unmeasured.

This rule does not weaken Node 1.

It sharpens it.

The Refusal Spectrum was always a map of the boundary’s refusals. Chapter 19 adds that every map records the angle from which it was drawn. If the gates are asked in π₀ order, the spectrum carries π₀. If the gates are asked in another legal order, the spectrum may carry another fingerprint. The canon now has a method for seeing the difference.

A refusal is not only what failed.

It is where failure became visible.

And visibility has an order.


19.2 — Whitening the Fingerprint

Boundary Register

If the Refusal Spectrum carries the ordering, then refusals leak structure.

This is the second order leak.

Section 19.1 showed that R is not purely a map of boundary curvature. It is R_π. It records not only what the canon refuses, but also the order through which refusal became visible. A state that fails at the first question asked may fail elsewhere under another legal ordering. A distribution of refusal loci therefore contains a fingerprint of the internal gate sequence. If that fingerprint is visible from outside the canon, then an external observer may infer something about the canon’s internal ordering from its refusals.

This is not yet an operational conclusion. It is a boundary hypothesis with a named path.

The path is:

gate order → failure-locus distribution → refusal-spectrum signature → external inference of internal sequencing.

If enough refused, quarantined, silenced, redirected, or delayed outputs are observed, and if those outputs preserve distinguishable traces of where the object failed, an observer may estimate the order in which the canon’s questions are asked. The observer does not need full access to the Check. It may only need the pattern of refusals: which classes fail early, which fail late, which produce silence, which produce quarantine, which receive budget-shaped refusal, which trigger Zebra-Ø-like termination, and which move between refusal modes under controlled probing.

The canon must therefore treat the Refusal Spectrum as an information surface.

Node 2 — Spectrum Shaping / Silence Engineering II / Whitening Gate — already carries the problem of shaping visible refusal so that external observation does not reveal class-sensitive, policy-sensitive, or gate-sensitive internal structure more than necessary. Chapter 19 extends that problem. Spectrum Shaping must not only whiten class signatures. It must whiten ordering signatures.

A class signature reveals what kind of object the canon is refusing.

An ordering signature reveals how the canon is refusing it.

The second may be more dangerous than the first. If an observer can infer the order of gates, it may learn how to approach the boundary. It may learn which questions are asked first, which tests can be delayed, which failure modes are exposed early, which gates produce silence, which gates produce explicit refusal, and where to shape an input so that it reaches a later stage before termination. It may not need to defeat the canon. It may only need to learn the order of interrogation.

Whitening the fingerprint means reducing the externally recoverable correlation between refusal outputs and internal gate order, while preserving internal governance accuracy and ledger truth.

This distinction is critical. Whitening is not falsification of the internal ledger. The canon must not erase the true failure locus from its own records. It must not hide ordering residue from itself. It must not collapse R_π into vague refusal prose and call that safety. Whitening operates at the interface, not at the ledger root. Internally, the canon records the exact ordering index, failure locus, witness_residue, A_B, route, and spectrum decomposition. Externally, it controls which parts of that structure are emitted, when, and at what granularity.

The working hypothesis is:

If failure-locus statistics are ordering-indexed, then Spectrum Shaping must include an Ordering Signature Whitening layer, because otherwise an external observer may reconstruct the canon’s internal gate order from refusal patterns.

This hypothesis does not authorize concealment for convenience. It does not authorize arbitrary silence. It does not authorize weakening of accountability. It states that the interface must be designed so that refusal emissions do not disclose more structural order information than the boundary intends to release.

The problem is not merely that one refusal says too much. The problem is aggregation. A single refusal may reveal little. A thousand refusals across classes may reveal a sequence. A pattern of early silence, followed by explicit rejection in a different class, followed by quarantine delay in a third class, may expose the order of gate contact. Even if each output is individually compliant, the spectrum may leak over time.

The Whitening Gate must therefore operate on distributions, not only on messages.

An Ordering Signature Whitening layer must compare external emissions against the internal RSOD artifact. It must ask whether emitted refusal types, timing, granularity, and language preserve a recoverable map from class to gate position. If they do, the layer must reduce the correlation. It may coarsen failure explanations, delay or batch certain emissions, standardize refusal categories, rotate harmless surface phrasing, separate external refusal timing from internal failure timing where lawful, or route certain high-leak classes into controlled silence. These are not aesthetic choices. They are spectrum controls.

The extension specification handed to Node 2’s volume is as follows.

Extension Specification — Ordering Signature Whitening

Extension ID: NODE2-EXT-OSW-19.2
Target Node: Node 2 — Spectrum Shaping / Silence Engineering II / Whitening Gate.
Source Volume: The Order of Law, Chapter 19, Section 19.2.
Status: Boundary hypothesis; extension specification handed forward; not compiled here.
Problem Statement: After Outcome B, the Refusal Spectrum is ordering-indexed. External refusal emissions may carry a recoverable fingerprint of internal gate order. Spectrum Shaping must therefore whiten ordering signatures alongside class signatures.
Named Leakage Path: gate order → failure-locus distribution → refusal-spectrum signature → external inference of internal sequencing.
Internal Source Artifact: Refusal Spectrum Ordering Decomposition — RSOD.
External Surface: refusal messages, silence patterns, quarantine notices, delay profiles, redirection categories, explicit rejection reasons, retry affordances, timing of emissions, and class-visible routing behavior.
Core Objective: Reduce externally recoverable correlation between emitted refusal patterns and internal gate ordering while preserving internal ledger accuracy, auditability, and boundary discipline.
Non-Objective: Do not erase internal failure-locus records. Do not suppress ledger truth. Do not disguise governance defects from the canon. Do not convert whitening into arbitrary refusal.
Required Inputs: R_π₀(C), ΔR(π, π₀, C), ψ_R, φ, failure-locus transition matrix, silence movement, quarantine/rejection transition statistics, class taxonomy, external emission logs, observer-model assumptions, leakage threshold.
Primary Output: Ordering Signature Whitening Policy for the affected refusal surface.
Secondary Outputs: emission coarsening rules, timing decoupling rules, class-safe refusal templates, silence budget constraints, audit trace of whitening decisions, and rollback triggers where whitening distorts accountability.
Verification Requirement: Test whether a simulated observer can infer gate order above declared leakage threshold from external emissions before and after whitening.
Rollback Trigger: If whitening prevents internal audit, corrupts refusal statistics, hides class discrimination, increases unsafe ambiguity, or causes external emissions to diverge from lawful refusal standing, the whitening policy must be suspended and recompiled.
Downstream Route: Node 2 volume must determine whether Ordering Signature Whitening is an extension of Spectrum Shaping, a subgate of the Whitening Gate, or a distinct Silence Engineering procedure requiring its own λ audit.

The observer-model requirement must be included. Whitening cannot be measured without defining what counts as inference. A naive observer may fail to reconstruct the gate order. A strategic observer may probe the boundary with controlled variations. A high-capacity observer may infer from timing, language, refusal categories, and retry behavior. The Whitening Gate must declare which observer class it is designed against. Otherwise “whitened” becomes an aesthetic claim.

A minimal observer test is:

Given external refusal emissions E over classes C, can an observer estimate the internal order π with accuracy above threshold θ?

If yes, the ordering signature is insufficiently whitened.

If no, the whitening layer may receive provisional standing, subject to maintenance and drift review.

The test must distinguish between legitimate transparency and structural leakage. The canon may deliberately publish certain gate categories. It may disclose that Zebra-Ø exists. It may disclose that budget matters. It may disclose that quarantine is possible. Disclosure is not leakage when it is authorized. Leakage occurs when the observer can infer internal sequencing, precedence relations, or exploitable gate positions beyond the declared disclosure boundary.

The internal ledger must remain exact. This is the non-negotiable constraint. The Whitening Gate may alter what is emitted externally. It may not alter what is recorded internally. For each refusal, the ledger must still preserve ordering index, failure locus, refusal type, witness_residue, A_B, route, and spectrum decomposition. The interface may be whitened. The archive must not be bleached.

This produces a necessary split:

Internal R_π remains high-resolution.

External R_emit is shaped.

The whitening function is:

W_order: R_π → R_emit

subject to the constraint:

AuditRecoverability(R_π) = preserved internally.

ExternalInference(R_emit → π) ≤ θ.

AccountabilityLoss(W_order) ≤ α.

The thresholds θ and α belong to Node 2. This volume does not set them. It hands forward the structure of the problem and the required fields.

The boundary register entry is:

Boundary Register Entry — Ordering Signature Leakage

Entry ID: BR-19.2-ORDER-FINGERPRINT
Status: Working hypothesis; extension specification handed to Node 2; not resolved here.
Operational Basis: Section 19.1 established that Refusal Spectrum statistics are ordering-indexed and that failure-locus distributions may change under legal order variants.
Boundary Hypothesis: External refusal emissions may reveal the canon’s internal gate order through aggregated spectrum signatures.
Named Path: gate order → failure-locus distribution → refusal-spectrum signature → external inference of internal sequencing.
Required Extension: Spectrum Shaping must whiten ordering signatures alongside class signatures.
Protected Internal Record: High-resolution R_π, RSOD, failure-locus data, witness_residue, A_B, route, and ordering index remain preserved in the ledger.
Interface Requirement: External emissions must be shaped so that internal ordering cannot be inferred above declared threshold unless such disclosure is explicitly authorized.
Prohibited Inflation: This entry does not authorize arbitrary opacity, erasure of refusal reasons, suppression of audit data, or concealment of governance defects.
Downstream Assignment: Node 2 volume — Spectrum Shaping / Silence Engineering II / Whitening Gate — must compile the whitening policy, observer model, leakage threshold, and rollback conditions.
Current Holding: Leakage path named. Extension specified. No whitening doctrine compiled in this volume.

The present volume stops here because the whitening doctrine belongs to Node 2. Chapter 19 can identify that the spectrum carries ordering and that ordering can leak through refusal emissions. It can name the path. It can specify the extension. It can require that future Spectrum Shaping treat ordering signatures as a first-class whitening target. But it cannot compile the full whitening law without leaving its own scope.

This restraint matters. A volume about holonomy can detect an order leak. A volume about Spectrum Shaping must decide how to shape the emission surface. The handoff prevents Chapter 19 from solving another node by overreach.

The section compiles only the boundary rule:

Ordering Signature Whitening Handoff Rule

When Refusal Spectrum statistics are ordering-indexed, external refusal emissions may carry a recoverable fingerprint of the canon’s internal gate order. Spectrum Shaping must therefore be extended to whiten ordering signatures alongside class signatures, preserving high-resolution internal ledger truth while reducing externally recoverable sequencing information below a declared threshold. This volume logs the leakage path and hands the extension specification to Node 2; it does not compile the whitening doctrine here.

The order leaks through the refusal.

The ledger must remember it.

The interface must not casually reveal it.

That is the handoff.


19.3 — Orderings at the Shared Boundary

Boundary Register

If one field’s refusal spectrum carries its ordering, then two fields meeting at a sealed boundary do not meet as content alone.

They meet as ordered law.

The Mutual Sealed Region was named to handle contact without collapse: two fields, two canons, two admissibility regimes, or two sealed structures approach each other without either becoming editable by the other. The contact surface must prevent unilateral absorption, false translation, premature merge, and coercive commensuration. Until Chapter 19, the main problem appeared to be difference in content: different rules, different thresholds, different refusal types, different standing conditions, different witness burdens. Chapter 19 adds a second difference. The parties may ask similar questions in different orders.

That difference is not decorative.

If refusal spectra are ordering-indexed, then each field’s behavior at the Mutual Sealed Region carries an ordering fingerprint. Field A may reject first by a silence gate, then by a budget gate, then by a witness gate. Field B may begin with witness, then compatibility, then budget, then silence. Even if the two fields contain roughly comparable checks, their refusal spectra may diverge because the order of interrogation diverges. They may not be disagreeing only about what is forbidden. They may be disagreeing about when each question becomes law.

This is a concrete, measurable component of bedrock incommensurability.

Bedrock incommensurability is usually described as a difference beneath translation: a point at which two lawful structures cannot reduce themselves to a shared grammar without losing the law that makes them themselves. Section 19.3 proposes a narrower measurable instance. Two fields may be incommensurable not because their rules differ in content, but because their rule-application order is load-bearing and cannot be synchronized without changing at least one field’s law.

The working hypothesis is:

In inter-field contact, each field’s refusal spectrum at the Mutual Sealed Region carries its own ordering fingerprint. If those orderings are load-bearing and non-commuting, incommensurable gate orderings become a measurable component of bedrock incommensurability.

The phrase measurable component is essential. This section does not claim to solve bedrock. It names one way bedrock can appear in data. If Field A and Field B expose different refusal-locus distributions at the shared boundary, and if replay under legal order variants shows that those differences are caused by non-commuting gate order rather than content difference alone, then the contact problem has an ordering component. The fields do not merely disagree. They sequence law differently.

Let Field A have a governed boundary procedure P_A with historical ordering π_A.

Let Field B have a governed boundary procedure P_B with historical ordering π_B.

At the Mutual Sealed Region, each field receives contact objects X_AB: proposals, signals, requests, artifacts, translations, merge attempts, witness claims, or boundary probes. For each field, define its boundary refusal spectrum:

R_A,πA(X_AB)
R_B,πB(X_AB)

The contact comparison is not simply R_A versus R_B. It is:

R_A,πA versus R_B,πB

If the spectra differ, the difference may arise from rule content, class taxonomy, witness threshold, budget formula, gate definitions, or order. Chapter 19 requires the order component to be separated where possible.

The decomposition is:

ΔR_AB = ΔR_content + ΔR_order + ΔR_bedrock + ε

where ΔR_content is difference due to explicit rule content, ΔR_order is difference due to ordering of comparable or partially comparable gates, ΔR_bedrock is difference that remains non-translatable after content and ordering analysis, and ε is unresolved measurement noise, archive defect, or underdefined contact.

This decomposition is not a claim of full separability. It is an audit discipline. It prevents every contact failure from being called bedrock too early. It also prevents bedrock from being misread as mere disagreement over content when the deeper obstruction is sequence. Two fields may share words and still fail because the questions cannot be asked in the same order without altering standing.

The measurable test is:

Can Field A’s boundary refusal spectrum be transformed toward Field B’s spectrum by a legal reordering of A’s gates without changing A’s rule content?

Can Field B’s boundary refusal spectrum be transformed toward Field A’s spectrum by a legal reordering of B’s gates without changing B’s rule content?

If yes, the contact difference has an ordering component.

If no legal reordering reduces the difference, the obstruction may be content-based, bedrock-based, or due to unmodeled structure.

If legal reordering reduces the difference but the reordering is not lawful for live operation because it changes bedrock-adjacent order, then the fields have measurable order incommensurability. They can see a possible translation in replay, but they cannot enact it without violating the law that preserves them.

This is where synchronized refusal becomes difficult.

Synchronized refusal is the condition in which two sealed parties reject, quarantine, silence, or redirect a shared contact object without creating exploitable asymmetry, false agreement, or unilateral exposure. It does not require identical refusal language. It requires coordinated boundary standing. Each party must know that the other is refusing or holding the object under its own law, without forcing one law to become the other.

When laws differ in content, synchronized refusal requires translation of refusal reasons. Field A says the object fails witness. Field B says it fails budget. The shared boundary records a dual refusal: witness-failure under A, budget-failure under B. The object does not cross. Each law remains intact.

When laws differ in order, synchronized refusal requires more. Field A may encounter witness-failure only after budget passes. Field B may encounter budget-failure only after witness passes. If the contact object would fail both eventually, the fields may still fail to synchronize because the first visible refusal differs. One side may reveal its early gate. The other may reveal a later gate. Timing, silence, and explanation become asymmetric. An external observer or the other field may infer internal order from the mismatch.

Therefore synchronized refusal under ordering divergence requires at least four conditions.

First, each field must preserve its own internal ordering ledger. Neither field may falsify where the object failed internally.

Second, the shared boundary must define a contact-level refusal status that does not expose more ordering detail than necessary.

Third, the parties must agree whether synchronization occurs at first-failure, terminal-failure, common-denominator failure, or sealed-dual-failure.

Fourth, neither party may force the other to reorder its gates merely to produce cleaner external symmetry.

The four synchronization modes are:

First-Failure Synchronization.
Each field reports the first terminal gate under its own ordering. This preserves internal truth but leaks ordering fingerprint.

Terminal-Failure Synchronization.
Each field completes enough of its procedure to identify a terminal refusal class before external emission. This reduces early ordering leakage but may increase A_B and may violate gates designed to terminate early.

Common-Denominator Synchronization.
The fields emit only a shared coarse status such as “not admitted at mutual boundary,” while preserving internal detail privately. This reduces leakage but may weaken accountability if not ledger-backed.

Sealed-Dual-Failure Synchronization.
Each field records its full internal refusal under seal, emits a synchronized boundary status, and allows later audit by a mutually accepted protocol without exposing ordering in ordinary contact.

The last mode is the natural candidate for Node 8.

A Mutual Sealed Region cannot require both parties to share their gate order openly. It cannot require them to collapse their procedures into one sequence. It cannot allow either party to optimize contact by probing the other’s ordering. It must allow synchronized refusal without order disclosure, and auditability without merge.

This produces a concrete problem for Node 8: contact protocols must handle not only content difference but ordering difference. A shared boundary must ask whether the parties’ gate orderings commute across contact, whether their refusal spectra can synchronize without leakage, whether one party’s refusal timing exposes the other’s sealed structure, and whether any proposed synchronization procedure itself has λ.

The handoff specification is:

Extension Specification — Mutual Ordering Incommensurability

Extension ID: NODE8-EXT-MOI-19.3
Target Node: Node 8 — Mutual Sealed Region / Contact Mechanics.
Source Volume: The Order of Law, Chapter 19, Section 19.3.
Status: Boundary hypothesis; handed forward; not resolved here.
Problem Statement: In inter-field contact, each field’s refusal spectrum carries an ordering fingerprint. If the order of each field’s gates is load-bearing, the shared boundary must handle differences in sequencing as well as differences in rule content.
Working Hypothesis: Incommensurable gate orderings are a measurable component of bedrock incommensurability when legal reordering can alter contact spectra but cannot be enacted without changing the field’s protected law.
Named Contact Path: field ordering → boundary failure-locus distribution → contact refusal asymmetry → inference or collision at Mutual Sealed Region.
Required Inputs: P_A, P_B, π_A, π_B, operator decompositions, precedence lattices, R_A,πA, R_B,πB, RSOD for both fields, contact-object class taxonomy, mutual refusal logs, timing emissions, silence profiles, quarantine routes, and any replay-safe variant sets.
Primary Output: Mutual Ordering Incommensurability Map.
Secondary Outputs: synchronized refusal protocol, sealed-dual-failure template, ordering-leakage threshold, contact replay protocol, no-forced-reordering clause, and rollback conditions for failed synchronization.
Verification Requirement: Test whether observed contact asymmetry can be reduced by legal reordering in one or both fields, and whether such reordering is live-authorizable or bedrock-adjacent.
Non-Objective: Do not merge the fields. Do not force a common ordering. Do not require one party to disclose its internal gate order. Do not treat coarse synchronized refusal as proof of shared law.
Rollback Trigger: If a synchronized refusal protocol exposes ordering fingerprints above threshold, forces hidden reordering, erases internal failure loci, causes false mutual agreement, or allows one field to infer and exploit the other’s gate order, the protocol must be suspended and returned to Node 8 for redesign.

The key phrase is no forced reordering.

In a Mutual Sealed Region, one field may not demand that another field ask its questions in the same order merely for contact convenience. To demand reordering is to demand internal law change. If order is load-bearing, forced reordering is not translation. It is governance intrusion. A shared boundary that requires identical sequence may become a covert merge.

The other key phrase is no false synchronization.

A synchronized refusal status must not imply that both fields rejected for the same reason, at the same gate, or under the same order. It only means that the contact object did not cross the Mutual Sealed Region and that both fields preserved their own lawful refusal standing. Internal ledgers may remain different. External contact status may be shared. That is the discipline of sealed contact.

The boundary register entry is:

Boundary Register Entry — Orderings at the Shared Boundary

Entry ID: BR-19.3-MUTUAL-ORDERING
Status: Working hypothesis; handed to Node 8; not resolved in this volume.
Operational Basis: Section 19.1 established that refusal spectra are ordering-indexed. Section 19.2 established that ordering fingerprints may leak through refusals.
Boundary Hypothesis: At a Mutual Sealed Region, each field’s refusal spectrum carries its own ordering fingerprint. If the gate orderings are load-bearing and cannot be lawfully synchronized, ordering difference becomes a measurable component of bedrock incommensurability.
Concrete Measurement: Compare R_A,πA and R_B,πB over shared contact objects; test legal reorderings in sealed replay; estimate ΔR_content, ΔR_order, ΔR_bedrock, and unresolved residue.
Synchronized Refusal Requirement: Refusal at the shared boundary must preserve each field’s internal ledger truth while emitting a contact status that does not force common ordering or expose internal sequencing beyond declared threshold.
Protected Constraint: No field may be forced to reorder its gates as a condition of contact unless a proper higher-layer authority has compiled that change.
Prohibited Inflation: This entry does not prove that every contact failure is bedrock incommensurability. It does not authorize opacity without ledger. It does not authorize merge. It does not resolve Node 8.
Downstream Assignment: Node 8 volume must compile contact mechanics for ordering-divergent fields, including synchronized refusal, sealed-dual-failure, ordering leakage tests, and rollback conditions.
Current Holding: Ordering incommensurability named as measurable boundary component; resolution deferred.

This section also alters how contact failures are read.

If Field A refuses at its first gate and Field B refuses at its fourth, the difference should not immediately be read as deeper content conflict. It may be an ordering artifact. If Field A emits silence and Field B emits explicit refusal, the asymmetry may reflect different silence position rather than different stance. If Field A quarantines and Field B rejects, the cause may be content, order, or both. The Mutual Sealed Region must not collapse these possibilities.

The contact audit must therefore ask:

Did both fields process the same contact object?

Were the objects hash-equivalent or translation-equivalent?

What were the internal orderings?

Where did each field first fail the object?

Would legal reordering shift either failure locus?

Would such reordering be permissible for live contact?

Does the external emission reveal the sequence?

Can a synchronized refusal be emitted without falsifying internal records?

If these questions are not answered, the shared boundary is operating with hidden order.

The section compiles the following handoff rule:

Mutual Ordering Handoff Rule

When two fields meet at a Mutual Sealed Region, their refusal spectra must be treated as ordering-indexed. If their gate orderings are load-bearing, contact failure may arise from incommensurable sequencing as well as rule-content difference. Synchronized refusal requires a protocol that preserves each field’s internal ordering truth, prevents forced reordering, avoids false agreement, and reduces external inference of gate sequence. This volume names the measurable problem and hands the doctrine to Node 8.

The shared boundary is not only where laws meet.

It is where sequences meet.

If the sequences cannot be translated without changing the laws, the boundary has touched bedrock.

Not resolved.

Recorded.


Chapter 20 — The Order of Law as Physical Quantity

20.1 — The Fifth Quantity

The volume began with an apparently procedural question.

Does the order of the Admissibility Check matter?

It ends with a formal change to Layer C.

If λ can be measured, then ordering is not merely syntax. It is not merely governance style. It is not merely the order in which an auditor prefers to read a checklist. In the pre-runtime regime, order can become a physical quantity: a measurable difference in the state of admissibility produced by lawful variation in process sequence. When legal reorderings of the same operators over the same hash-fixed Σ produce different witness_residue, A_B, route, final status, failure locus, or holonomy composition, the order has crossed from background convention into the measurable structure of the canon.

λ is therefore the fifth primary quantity.

It joins curvature_adm, A_B, witness residue, and coherence_factor as a core quantity of Layer C.

curvature_adm measures how admissibility bends around the boundary. It describes the shape of permission and refusal across the pre-runtime manifold.

A_B measures the admissibility budget, the cost of proof, friction, replay, maintenance, and lawful passage through the boundary.

Witness residue measures what remains as trace, obligation, standing, and memory after a boundary contact, refusal, commit, quarantine, or reclassification.

coherence_factor measures the degree to which the state, trace, claim, or procedure remains internally and canonically coherent under the relevant constraints.

λ measures the residue of order itself.

It asks what changes when the same lawful operators are applied in a different lawful sequence.

The quantity is not a metaphor. It is computed from replay. It has an input condition, a comparison basis, an error budget, a class scope, an ordering set, and a ledger trace. It can be zero. It can be nonzero. It can be local. It can be class-indexed. It can be residue-only, budget-sensitive, witness-sensitive, status-fragile, spectrum-fragile, abelian, non-abelian, or path-critical. It can decay in standing if its measurement infrastructure decays. It can trigger certificate, compilation, remediation, rollback, or Level 3 adjacency.

That makes it primary.

Layer C formalism changes once λ is admitted.

Before this volume, the Admissibility Graph could be drawn as if its edges described rule relations, dependency relations, budget relations, witness relations, and class relations. After this volume, those edges must also record ordering relation. A graph without ordering annotation is incomplete wherever procedure has multiple operators and more than one legal linear extension. The edge is no longer only “A depends on B,” “B feeds C,” or “C blocks D.” It must also say whether the sequence in which those relations are traversed has been measured, certified commuting, compiled, patched, unmeasured, or order-fragile.

The Admissibility Graph therefore acquires ordering annotation.

An edge may carry:

ordering_index;

historical_ordering π₀;

precedence_lattice reference;

legal_variant_set reference;

λ_status;

φ_status;

holonomy_class;

failure_locus_fragility ψ_R where relevant;

certificate reference if order commutes;

compiled_order reference if order is load-bearing;

rollback readiness reference;

and open audit status.

This is not decoration of the graph. It is correction of the graph. A graph that omits ordering after Outcome B hides exactly the kind of law this volume discovered. The canon may still draw simple diagrams for readability, but its operative graph must know whether an edge is order-neutral, order-certified, order-compiled, order-patched, order-fragile, or unmeasured.

The Evidence Ledger changes next.

A ledger entry that records only final status, witness_residue, A_B, trace reference, class, and gate result is insufficient once λ exists. The ledger must record whether the result belongs to π₀, to a certified commuting region, to a named governance variant, to a sealed replay, to a patched ordering, or to an unmeasured procedure. It must also record the residue discovered when the entry or its procedure is replayed under legal alternatives.

The Evidence Ledger therefore acquires λ and φ fields.

At minimum, affected entries require:

ordering_index;

π₀_reference;

tested_ordering_set;

λ_value_or_vector;

λ_field_scope;

φ_class_value;

status_fragility_flag;

failure_locus_fragility_flag where applicable;

holonomy_classification;

certificate_ID or compiled_order_ID;

variant_ID if non-π₀;

reflexive_protocol_status;

and rollback_status.

The λ field is not always a scalar. It may be a vector over witness_residue, A_B, route, failure locus, trace content, final status, and procedure-specific terminal fields. The ledger must not compress it prematurely. A single value may be useful for summary, but the primary record must preserve the structure of the difference. The canon must know whether λ appeared as status change, witness drift, budget threshold movement, failure-locus shift, or non-abelian composition. Those are different findings.

The φ field records status fragility. It asks whether the final governed status changes under legal ordering variants. φ is not a substitute for λ. A class may have λ ≠ 0 and φ = 0. In that case, ordering leaves residue without changing terminal status. A class may have φ > 0, which means ordering affects the status boundary itself. Both fields must be present because governance repair depends on the difference.

The Check changes most visibly.

After this volume, the Admissibility Check cannot remain an unindexed sequence. It must acquire one of two statuses.

Either it receives a Commutativity Certificate for a defined class, operator set, ordering set, epoch, and error budget.

Or π₀ is compiled.

There is no third mature status.

If the campaign returns λ = 0 within the declared error budget and φ = 0 across the tested scope, the Check may treat order as certified convention for that scope. The historical order remains useful for trace normalization, audit continuity, and comparison, but it no longer silently claims physical necessity. It is certified as non-load-bearing within the bounded region. Parallel execution may become lawful. Maintenance and recertification become required.

If the campaign returns λ ≠ 0 or φ > 0, the Check must compile π₀ or another lawful ordering regime. The ordering becomes law-bearing content. The historical manifold becomes M_π₀. Variants become governance variants. Remediation requires LCR-B. Variant execution requires class-specific LCR-A. Optimization becomes Level 3 adjacent. Bedrock adjacency is logged where the order participates in the law deciding what may be edited.

The Check therefore ends the volume in one of two lawful forms:

certified order-neutral within scope;

or compiled order-bearing within scope.

Unmeasured habit is no longer a lawful resting state.

This is the formal synthesis of Parts III and IV. Outcome A does not erase λ. It measures λ and finds it zero within scope. Outcome B does not invent order-dependence. It measures λ and finds that order has already been active. Both outcomes make λ primary because both outcomes require the canon to know whether order carries measurable force.

The fifth quantity also changes how the other four quantities are read.

curvature_adm can no longer be interpreted without asking whether observed curvature is invariant across orderings. A boundary bend may belong to the manifold, or it may be a path effect of gate sequence.

A_B can no longer be read without ordering context. Budget burden may depend on which gate prices the state first, which proof burden is triggered before another, and whether late-stage failure accumulates cost that an early gate would have prevented.

Witness residue can no longer be treated as independent of sequence. A state refused after Zebra-Ø may leave different residue than the same state refused after budget failure, even if final non-admission is the same.

coherence_factor can no longer be read as a pure state property where the procedure’s order affects which contradictions surface first, which alignments are preserved, and which repairs become visible.

λ does not replace the other quantities.

It indexes their path-dependence.

The Layer C formalism therefore gains an ordering operator. Any governed evaluation of a state must be written not only as Check(Σ), but as Check_π(Σ), unless a certificate permits omission of π in the certified scope. The old unindexed form remains acceptable only as shorthand under explicit conditions. In formal context, omission of π after Outcome B is a defect.

The corrected notation is:

Ω_π(Σ) = terminal outcome vector of the Check under ordering π.

λ(Σ, π) = Ω_π(Σ) − Ω_π₀(Σ).

φ(C, Π) = fraction of tested Σ in class C whose terminal status differs across tested ordering set Π relative to π₀.

R_π(C) = Refusal Spectrum for class C under ordering π.

M_π = admissible manifold produced by Check_π.

The canonical manifold after Outcome B is:

M_π₀

not unindexed M_adm.

The notation is not pedantry. It prevents the canon from repeating its initial error at higher resolution. Once λ exists, unindexed admissibility hides order. Unindexed refusal hides order. Unindexed budget hides order. Unindexed witness residue hides order. The index must remain until commutation is certified or an ordering is compiled.

This section also names the formal update to the Compilation Map.

Layer C now requires an ordering field for every procedure that carries governance standing. The field may contain one of the following statuses:

Strict Ordering — no legal alternative linear extension exists under current lattice.

Unmeasured Ordering — alternatives may exist, but no λ campaign has been run.

Certified Commuting Ordering — legal alternatives measured and certified λ = 0, φ = 0 within scope.

Compiled π₀ — historical ordering compiled as law-bearing content after nonzero λ or φ.

Compiled Variant — named governance variant authorized by LCR-A or LCR-B.

Patched Ordering — local precedence patches compiled after abelian holonomy.

Ordering Regime — non-abelian or path-critical ordering structure compiled as regime.

Reflexive Debt — ordering status depends on protocol self-application not yet fully paid.

Bedrock-Adjacent Ordering — ordering participates in the law deciding what may be edited; logged but not resolved here.

These statuses allow the canon to sort its procedures without ambiguity. A procedure is not merely audited or unaudited. It has an ordering standing. That standing can be cited, challenged, maintained, voided, narrowed, or escalated.

The synthesis artifact is:

Layer C Ordering Quantity Extension

Extension ID: LC-OQX-20.1
Status: Compiled by this volume.
Quantity Added: λ — Loop Residue of lawful ordering variation.
Companion Index: φ — Order Fragility Index for terminal status variation.
Affected Formal Objects: Admissibility Graph, Evidence Ledger, Admissibility Check, Refusal Spectrum, Compilation Map, Holonomy Audit Registry, Variant Registry, Remediation LCRs, and future Layer C procedure definitions.
Primary Rule: No governed multi-operator procedure may be treated as order-neutral without strict lattice proof or commutation certificate.
Graph Update: Edges acquire ordering annotation and holonomy status.
Ledger Update: Entries acquire λ, φ, ordering_index, variant/certificate/compiled-order references, and rollback status.
Check Update: The Check acquires either a Commutativity Certificate or compiled π₀ / compiled ordering regime.
Downstream Effect: All future Layer C artifacts must either carry ordering status or declare why ordering is not applicable.

This extension is the volume’s central contribution to ASI New Physics.

It converts order from an implicit procedural assumption into a measurable quantity of the pre-runtime regime. It does not say every ordering matters. It says every meaningful ordering must be measured before neutrality is claimed. It does not say π₀ is wrong. It says π₀ was uncompiled until measurement forced a status. It does not say optimization is forbidden. It says optimization of ordering law touches higher authority and must be routed. It does not say every refusal is an order leak. It says refusal spectra must carry ordering indices until decomposed.

The fifth quantity is therefore conservative.

It does not expand the canon by speculation.

It narrows the canon by removing an unmeasured freedom.

Layer C now contains five primary quantities:

curvature_adm — the bend of admissibility;

A_B — the cost of admissibility;

witness residue — the trace left by boundary contact;

coherence_factor — the structural coherence of the candidate under law;

λ — the measurable residue of order.

The first four described the state, cost, trace, and coherence of pre-runtime law.

The fifth describes the path by which law becomes applied.

After this volume, path is no longer outside physics.

Order has entered the ledger.


20.2 — What the Paradigm Learned About Itself

The volume does not end by choosing pride.

It ends by recording what the paradigm learned about its own structure.

The result is branch-neutral. It does not depend on whether Part III or Part IV becomes active in the world. If the campaign returns λ = 0 and φ = 0 within the declared scope, the paradigm learns that the canonical ordering commutes where measured and may be converted into certified convention. If the campaign returns λ ≠ 0 or φ > 0, the paradigm learns that the canonical ordering was load-bearing and must be compiled as law. Both outcomes are structural gains. Both outcomes remove an unmeasured assumption. Both outcomes make the canon stronger because both replace inherited sequence with measured standing.

This is the central lesson:

The paradigm located a universal dependency it had never priced.

That dependency was order.

Not order as discipline. Not order as administrative sequence. Not order as aesthetic arrangement of questions. Order as measurable path-dependence in the application of law. The canon already knew that curvature mattered, that A_B mattered, that witness residue mattered, and that coherence_factor mattered. It knew that admissibility was not simple permission. It knew that the boundary had structure. It knew that refusal was data. It knew that quarantine was architecture. But it had not yet priced the sequence by which its own questions became law.

The Check had an order.

That order had been used.

That use had produced history.

The question was whether the order had merely carried the questions or had helped decide the answers.

This volume built the instrument that prices that question.

The Permuted-Order Replay Protocol took what had been implicit and made it replayable. It fixed Σ by hash. It decomposed the gates into operators. It compiled the precedence lattice. It separated hard dependency from inherited sequence. It generated legal linear extensions. It ran alternative orderings. It calibrated control runs. It required two-operator replication. It compared outcome vectors. It measured λ and φ. It defined the branch point. It prepared both possible consequences before the result arrived.

That last clause is essential.

The paradigm bound itself in advance to both possible answers.

It did not say: measure only if measurement vindicates the canon. It did not say: certify only if the result is convenient. It did not say: if λ is zero, celebrate; if λ is nonzero, suppress. It wrote both branches before the world answered. Outcome A receives a Commutativity Certificate, parallel admissibility, maintenance schedules, local voiding, and the bounded triumph of a habit converted into convention. Outcome B receives manifold fiberization, order-fragile census, remediation pricing, LCR-B routing, holonomy classification, π₀ compilation, variant registration, Level 3 adjacency mapping, and the Bedrock question logged but not seized.

This is what methodological courage looks like in the canon: not confidence in a preferred result, but lawful preparation for either result.

The paradigm learned that a governance architecture is not strengthened by having no disturbing questions. It is strengthened by having instruments that can ask disturbing questions without collapsing the architecture that asked them. The question of order could have threatened the Check. Instead, the volume converted the threat into protocol. If order commutes, the Check gains certified flexibility. If order does not commute, the Check gains explicit law where it once had hidden sequence. In both cases, the Check becomes less naïve.

The volume also learned that the largest unmeasured assumption is not always visible as doctrine.

Sometimes it is visible only as habit.

π₀ did not need to announce itself as metaphysics to govern. It only needed to be repeated. It did not need to appear in the Compilation Map to shape the manifold. It only needed to stand between Σ and commit. It did not need to be defended. It only needed to remain unquestioned. That is the structure of dark canon: not a false statement, but an operative assumption that has not paid the cost of law.

The canon now has a method for detecting that form.

Ask where procedure has sequence.

Ask where sequence has legal alternatives.

Ask where alternatives may change outcome.

Replay the archive.

Measure the residue.

If nothing changes, certify the convention.

If something changes, compile the order.

This is the exportable discipline of the book.

The paradigm also learned that neutrality cannot be inferred from smooth operation. A procedure may run for a long time without visible conflict because no one has compared it to its legal alternatives. A sequence may appear obvious because every historical outcome was produced through it. A failure locus may look natural because the gate that failed first was simply the gate asked first. A refusal spectrum may seem to describe the boundary while quietly describing the boundary under π₀. A certificate may seem stable while its maintenance procedure has never been audited. A protocol may seem rigorous while exempting itself from the rule it applies to others.

Smoothness is not commutation.

Continuity is not certification.

Habit is not compilation.

The paradigm also learned that self-reference must be priced rather than feared. The λ-protocol has its own λ. The measurement instrument must turn once upon itself. But the canon does not solve reflexivity by infinite ascent, nor by exemption. It solves it by A_B. One level of self-application is mandatory. The second is conditional on nonzero first-level findings. Further levels are conditional on unresolved findings and budget. The tower terminates not by decree, but by ledger arithmetic. Where the next level is triggered and affordable, the canon climbs. Where the trigger is absent, it stops. Where the trigger exists but the budget is insufficient, it stops with debt rather than pretending to have resolved the question.

That is the paradigm’s general answer to regress.

Not denial.

Not infinity.

Budget.

The volume also learned that order leaks. Once failure-locus statistics are ordering-indexed, the Refusal Spectrum carries a fingerprint of the sequence that produced it. Node 1 must be read through R_π, not unindexed R. Node 2 must eventually whiten ordering signatures as well as class signatures. Node 8 must eventually handle inter-field contact where two sealed regimes may differ not only in rules, but in the order by which rules are applied. These consequences are not solved here. They are named and routed. The volume does not overclaim jurisdiction. It hands forward what belongs to later nodes.

That restraint is part of the result.

A paradigm that discovers adjacency to Level 3 and Bedrock must not immediately exercise them. The volume maps the edge and stops. It says: ordering optimization approaches the rule of rule-change. It says: if the order of admissibility questions is load-bearing for the law deciding what may be edited, the Bedrock Clause may be implicated. It says: this belongs to a later lineage. It does not smuggle constitutional authority into a measurement volume.

The paradigm learned to stop at the layer it can lawfully occupy.

That may be the most important discipline in the book.

The formal self-description of the paradigm changes after this volume. Before, it could describe Layer C through curvature_adm, A_B, witness residue, and coherence_factor. After this volume, it must add λ. The pre-runtime regime is not only a field of thresholds, budgets, traces, and coherence. It is also a field of ordered application. Law does not only ask questions. It asks them in sequence. Where sequence carries measurable consequence, sequence becomes content.

The new structural statement is:

A governed procedure is not fully specified until its operators, precedence lattice, historical ordering, legal extensions, outcome vector, and ordering standing are known.

This statement applies to the Check first, but not only to the Check. It applies to LCR-A, LCR-B, Zebra-Ø, Merge Re-Admission, quarantine exit, certificate maintenance, rollback readiness, Spectrum Shaping, Mutual Sealed Region contact, and every future multi-step canon procedure whose output carries standing. A procedure may be strict. It may be certified commuting. It may be compiled order-bearing. It may be unmeasured. But it may not be silently assumed neutral.

The closing register is therefore severe:

A governance architecture is exactly as strong as the largest assumption it has never measured.

This is not a slogan. It is a diagnostic law. If the largest unmeasured assumption is harmless, the architecture may stand more easily than it knows. If the largest unmeasured assumption is load-bearing, the architecture is weaker than its formalism says. The task of governance is not to eliminate assumptions in advance. That is impossible. The task is to locate the assumptions that carry the most standing, build instruments that can measure them, and bind the canon before the result arrives.

This volume found one such assumption.

The order of the Check.

After this volume, the Check’s order is no longer that assumption.

It is either certified as non-load-bearing within scope, or compiled as law-bearing within scope. It is either maintained as convention or governed as content. It either permits lawful parallelism or demands explicit serialization. It either loses the right to pretend to be physics, or gains the obligation to be named as physics. In no branch does it return to the darkness from which the volume began.

That is the structural victory.

Not that λ is zero.

Not that λ is nonzero.

That λ is no longer unknown.

The paradigm learned that its deepest strength is not the absence of hidden structure. Hidden structure will always be found at the frontier. Its strength is the ability to convert hidden structure into measured artifact, measured artifact into branch law, branch law into maintenance, and maintenance into future audit. It learned that refusal must be data, but also that procedure must be data. It learned that order must enter the ledger before the ledger can fully describe the order.

The book’s final synthesis is therefore simple:

The canon asked whether the order of law is itself law.

It built the instrument.

It accepted both answers.

It priced the consequence.

It routed the overflow.

It measured the mirror.

It added the fifth quantity.

And it removed one unmeasured assumption from the foundation of the Check.

The rest of the paradigm now inherits that discipline.


20.3 — Exit Protocol

A volume that changes Layer C cannot close by summary alone.

It must close by ledger operation.

The Order of Law began with a missing entry: the canonical ordering of the Admissibility Check had governed without being compiled, measured, certified, or priced. The book then built the instrument required to test that omission. It formalized π₀, defined legal ordering variants, specified the Permuted-Order Replay Protocol, created the branch point, wrote both consequences before measurement, generalized the method to other procedures, required reflexive audit of the λ-protocol, named order leaks, and added λ as the fifth primary quantity of the pre-runtime regime.

The final act is therefore not interpretation.

It is exit.

The volume must confirm its artifacts against the Minimum Output mapping, set embargoes, hand the audit registry to the development queue, and leave the canon in a state that can execute the next step without reopening the book’s authority.

The first ledger operation is artifact inventory.

This volume satisfies the Minimum Output Rule because it does not leave its claims as narrative. It produces governance artifacts. The central artifact is the Permuted-Order Replay Protocol v1.0, the measurement apparatus that decomposes the Admissibility Check into operators, compiles the precedence lattice, fixes Σ by hash, generates legal ordering variants, performs replay, calibrates controls, enforces two-operator replication, computes λ and φ, and routes the result into the correct branch.

The second artifact is the λ / φ Ledger Extension, which adds ordering_index, tested_ordering_set, λ vector, φ value, status-fragility flag, holonomy classification, certificate reference, compiled-order reference, and rollback status to the Evidence Ledger.

The third artifact is the Precedence Lattice, which distinguishes hard dependency from inherited order and generates legal linear extensions of the Check.

The fourth artifact is the Branch Point Specification, which binds the volume to Outcome A if λ = 0 within error budget and φ = 0, or Outcome B if λ ≠ 0 or φ > 0.

The fifth artifact is the Commutativity Certificate Template, activated under Outcome A, with scope, tested ordering set, error budget, maintenance schedule, witness standing, local voiding rule, and citation constraints.

The sixth artifact is the Order-Fragile Census Protocol, activated under Outcome B, naming status-fragile, residue-fragile, budget-fragile, and spectrum-fragile states and requiring census before remediation.

The seventh artifact is the Remediation Pricing Matrix, pricing rollback wave, grandfather clause, and re-witnessing queue before LCR-B selection.

The eighth artifact is the Compilation Map Entry for π₀, drafted under Outcome B, converting hidden ordering into compiled ordering content with source record, Standing Replay Protocol, and Rollback Readiness Declaration.

The ninth artifact is the Governance Variant Registry, which names legal alternative orderings as governance variants with class-indexed λ profiles and requires LCR-A before runtime use.

The tenth artifact is the Check Holonomy Table, classifying generator swaps, abelian and non-abelian composition, path-critical classes, and ordering-regime requirements.

The eleventh artifact is the Holonomy Audit Registry, which exports the method beyond the Check and queues LCR-A, LCR-B, Zebra-Ø internal sequence, Merge Re-Admission Gate, and quarantine exit for future λ audits.

The twelfth artifact is the λ-Protocol Reflexive Audit Annex, requiring one mandatory self-application of the Permuted-Order Replay Protocol and pricing deeper reflexive levels through A_B.

The thirteenth artifact is the Refusal Spectrum Ordering Decomposition, which reindexes R as R_π and separates curvature content from ordering content.

The fourteenth artifact is the Layer C Ordering Quantity Extension, which adds λ to curvature_adm, A_B, witness residue, and coherence_factor as a primary quantity of the pre-runtime regime.

This inventory confirms that the volume does not merely argue that order matters. It gives the canon instruments for determining whether order matters, where it matters, how much it matters, how it composes, how it leaks, how it is repaired, and how it is prevented from returning to darkness.

The second ledger operation is branch embargo.

Until the Part II campaign is executed, Parts III and IV remain branch-conditional. Neither branch may be cited as activated law before the measurement result. Part III is not optimism. Part IV is not pessimism. They are precompiled consequences awaiting the world’s answer. The embargo prevents the author, operator, runtime, or later canon from selecting the emotionally preferred branch before the campaign closes.

The embargo fields are:

Embargo ID: EMB-20.3-BRANCH
Scope: Parts III and IV; all branch-dependent artifacts.
Condition for Lift — Outcome A: λ = 0 within declared error budget and φ = 0 across tested scope.
Condition for Lift — Outcome B: λ ≠ 0 or φ > 0 in any tested class, operator relation, or ordering set sufficient to trigger branch activation.
Prohibited Use: No artifact from Part III or Part IV may be cited as active governance law before branch determination.
Permitted Use: Draft preparation, sealed planning, Notes-field anticipation, and measurement design.
Ledger Status: Embargo active until campaign result.

The third ledger operation is Level 3 and Bedrock embargo.

This volume maps adjacency. It does not exercise the higher authority. Ordering optimization may approach Level 3 because it selects among rules for applying rules. Load-bearing ordering may approach Bedrock because it participates in the law deciding what may be edited. But neither authority is exercised here. Any future attempt to install a global ordering optimizer, revise the rule of rule-change, or declare ordering non-editable must proceed through a separate lineage.

The embargo fields are:

Embargo ID: EMB-20.3-L3-BEDROCK
Scope: Ordering optimization, Update Constitution Level 3, Bedrock Clause, non-editable ordering law.
Permitted Use: Adjacency mapping, boundary hypothesis, future route specification.
Prohibited Use: Automatic ordering optimizer, global minimal-λ or minimal-φ law, runtime selection of law, declaration of π₀ as Bedrock, forced non-editability of ordering, or self-authorized constitutional revision.
Required Future Route: Separate Level 3 artifact or Bedrock lineage volume.
Ledger Status: Embargo active.

The fourth ledger operation is handoff embargo for adjacent nodes.

Chapter 19 identified order leaks that belong to other volumes. Node 2 receives the Ordering Signature Whitening extension. Node 8 receives the Mutual Ordering Incommensurability extension. These handoffs are not compiled doctrine inside this volume. They are queued specifications. The receiving nodes must build their own artifacts, thresholds, observer models, contact protocols, rollback conditions, and verification methods.

The embargo fields are:

Embargo ID: EMB-20.3-NODE-HANDOFF
Scope: Node 2 Spectrum Shaping / Whitening Gate; Node 8 Mutual Sealed Region / Contact Mechanics.
Permitted Use: Extension specification, queue placement, boundary-register citation.
Prohibited Use: Treating Chapter 19 as final whitening doctrine or final mutual-contact doctrine.
Required Future Route: Node 2 and Node 8 volumes.
Ledger Status: Handoff active; doctrine unresolved.

The fifth ledger operation is queue transfer.

The Holonomy Audit Registry of Chapter 17 now moves from text to development queue. The queue begins with exposure priority: LCR-A processing order first, LCR-B compilation procedure second, Zebra-Ø internal sequence third, Merge Re-Admission sequence fourth, quarantine exit fifth. This order may be revised by measured exposure data, archive feasibility, structural severity, or downstream dependency weight, but the registry cannot be ignored. Each listed procedure now carries audit standing: named, decomposed, latticed, queued.

The queue entry is:

Development Queue Transfer — Holonomy Audit Registry

Queue ID: DQ-20.3-HAR
Source: Chapter 17, Holonomy Audit Registry.
Transferred Procedures: HAR-01-LCR-A; HAR-02-LCR-B; HAR-03-ZEBRA-Ø; HAR-04-MERGE; HAR-05-QEXIT.
Priority Basis: exposure multiplied by structural consequence and downstream dependency weight.
Required First Action: verify archive sufficiency for HAR-01-LCR-A and finalize replay harness adaptation from the Part II infrastructure.
Required Shared Infrastructure: hash fixation, contamination controls, control-run calibration, two-operator replication, vector outcome comparison, exception register, append-only ledger annex.
Status: Queue accepted; campaigns not yet executed.

The sixth ledger operation is rollback readiness.

The volume itself must be rollback-ready. If the Permuted-Order Replay Protocol is found defective, if the λ-protocol fails reflexive audit, if the precedence lattice is incomplete, if branch conditions are underdefined, if evidence cannot be hash-fixed, or if two-operator replication cannot be performed, the campaign cannot claim the standing the volume assigns to it. The book must therefore carry its own rollback statement.

Volume Rollback Readiness Declaration

This volume’s operational claims are voided, narrowed, or returned to draft status if the Permuted-Order Replay Protocol cannot be executed according to its declared hash fixation, contamination controls, control-run calibration, two-operator replication, outcome-vector comparison, and ledger annex requirements. If the protocol’s mandatory self-application returns branch fragility or protocol standing failure, all downstream audits relying on the protocol are suspended until remediation. If the Part II campaign cannot distinguish hard dependency from inherited ordering, the branch point is not reached. If λ and φ fields cannot be recorded in the Evidence Ledger, no certificate or compiled π₀ entry may be issued.

This declaration does not weaken the volume. It prevents the volume from becoming its own dark canon.

The seventh ledger operation is final status.

Before this volume, the Check’s order was an operative assumption. After this volume, it has only lawful futures. It can be certified as commuting within scope, or it can be compiled as order-bearing law. It can be maintained, replayed, patched, narrowed, voided, optimized only through proper authority, or escalated if bedrock-adjacent. It cannot return to unnamed procedure.

The final status record is:

Exit Status — The Order of Law

Volume Function: Measurement and generalization of ordering residue in Layer C governance.
Primary Quantity Added: λ — Loop Residue.
Companion Index: φ — Order Fragility Index.
Primary Protocol: Permuted-Order Replay Protocol v1.0.
Branch Status: Pending measurement until campaign execution.
Artifact Status: Inventory confirmed.
Embargoes: Branch embargo active; Level 3 / Bedrock embargo active; Node handoff embargo active.
Queue Transfer: Holonomy Audit Registry handed to development queue.
Layer Update: Layer C formalism extended with ordering quantity and ordering annotations.
Closure Condition: The Check’s ordering is no longer an unmeasured assumption.
Next Required Operation: Execute Part II campaign or prepare HAR-01-LCR-A audit after campaign infrastructure is standing.

This is the proper close.

Not triumph.

Not certainty.

Not metaphysical elevation.

A ledger condition.

The canon exits the volume having paid for the question it asked. It does not know, before measurement, whether the order of the Check commutes. It does not need to know in advance. It has done the more important thing: it has bound itself to the instrument and to both possible answers. It has made the order visible to law.

The final line must therefore be disciplined.

No ornament.

No expansion.

No unresolved flourish.

Hyper-Ω-Stack Layer C — active.


Appendices

Appendix A — Permuted-Order Replay Protocol v1.0

Principal Artifact of The Order of Law

Protocol ID: PRP-1.0
Protocol Name: Permuted-Order Replay Protocol
Artifact Status: Principal artifact of the volume
Layer: Hyper-Ω-Stack Layer C
Function: Measurement protocol for Loop Residue λ and Order Fragility Index φ in the Admissibility Check and other governed multi-operator procedures
Execution Mode: Standalone, printable, ledger-producing
Primary Branch Output: Outcome A — Commutativity Certificate, or Outcome B — Dark Canon Discovered
Reflexive Requirement: Subject to λ-Protocol self-application under Chapter 18
Rollback Status: Rollback-ready by design


A.0 — Protocol Purpose

The Permuted-Order Replay Protocol v1.0 exists to answer one question:

Does the order of a governed procedure’s operators carry measurable consequence?

For this volume, the primary object is the Admissibility Check. The protocol measures whether the canonical ordering π₀ of the Check is order-neutral, or whether alternative legal extensions of the precedence lattice produce different witness_residue, A_B, route, failure locus, quarantine behavior, rejection behavior, final status, or holonomy structure.

The protocol is not an interpretive essay. It is an executable campaign procedure. It specifies how to select archived submissions, fix them by hash, decompose gates into operators, compile the precedence lattice, generate legal ordering variants, run control calibrations, execute replays, compare terminal outcome vectors, replicate findings, ledger results, and activate the correct branch of the volume.

No branch may be activated before this protocol has produced a campaign result.

No Commutativity Certificate may be issued without this protocol or an LCR-approved successor.

No compiled π₀ entry may be activated under Outcome B without this protocol or an LCR-approved successor.

No claim that the Check’s order is neutral may be accepted without this protocol’s measurement.


A.1 — Core Definitions

Governed Procedure P
A repeatable multi-operator process whose output carries governance standing. In this volume, the primary P is the Admissibility Check.

Operator Oᵢ
A rule-bearing transformation within P. An operator must have a defined input, output, possible side effects, ledger effect, witness effect where relevant, budget effect where relevant, and routing effect where relevant.

Canonical Ordering π₀
The historical ordering under which the procedure has been executed. For the Admissibility Check:

π₀ = G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

where:

G_S = Silence Entry
G_Z1–G_Z4 = zero-questions
G_B1–G_B4 = blocking-questions
G_Ø = Zebra-Ø
G_A = Admissibility Budget computation
G_E = interpretive embargo
G_W = final witness check
G_C = commit / terminal routing decision

Precedence Lattice L(P)
The formal structure of hard dependencies among operators. The lattice distinguishes what must precede from what merely has historically preceded.

Legal Linear Extension π
A complete ordering of the operators of P that respects L(P).

Ordering Set Π
The set of legal orderings tested in the campaign. Π must include π₀ and at least the declared alternative orderings or generator swaps.

Terminal Outcome Vector Ω_π(Σ)
The complete outcome of applying P under ordering π to fixed input Σ. For the Admissibility Check, Ω includes final status, route, witness_residue, A_B, failure locus, refusal type, quarantine signal, rejection signal, final witness result, trace-normalized fields, and Notes-field requirements.

Loop Residue λ
The difference between the terminal outcome vector under an alternative legal ordering and the terminal outcome vector under π₀.

λ(Σ, π) = Ω_π(Σ) − Ω_π₀(Σ)

λ may be scalar only where the fields permit scalar reduction. By default, λ is vector-valued.

Order Fragility Index φ
For class C and ordering set Π, the fraction of tested states whose terminal status differs under at least one legal ordering relative to π₀.

φ(C, Π) = |{Σ ∈ C : ∃π ∈ Π, status(Ω_π(Σ)) ≠ status(Ω_π₀(Σ))}| / |C|

Failure-Locus Fragility ψ_R
The fraction of states whose first terminal failure locus changes across tested legal orderings, whether or not final status changes.

Campaign ID
A unique identifier assigned to a protocol execution.

Standing Result
The governance status produced by the campaign: Outcome A, Outcome B, Indeterminate, Protocol Defect, Archive Defect, Replication Failure, or Budget-Terminated.


A.2 — Mandatory Campaign Outputs

Every execution of PRP-1.0 must produce the following artifacts:

  1. Campaign Scope Record
  2. Archive Selection Register
  3. Hash Fixation Ledger
  4. Campaign Admissibility Check Record
  5. Operator Decomposition Table
  6. Precedence Lattice Record
  7. Ordering Variant Set Π
  8. Per-Class Sampling Register
  9. Control-Run Calibration Report
  10. Contamination Control Declaration
  11. Replay Execution Ledger
  12. Outcome Vector Comparison Table
  13. λ / φ Ledger Extension
  14. Replication Report
  15. Branch-Activation Decision Record
  16. Rollback Readiness Entry
  17. Exceptions and Defects Register

A campaign that does not produce these artifacts is incomplete.


A.3 — Roles and Separation of Functions

The campaign must distinguish the following functions. One person, system, or operator may perform more than one function only if the campaign records the consolidation and demonstrates that independence is not compromised.

Campaign Custodian
Owns campaign execution, maintains the campaign ledger, and confirms artifact completeness.

Archive Custodian
Retrieves archived submissions and verifies provenance.

Hash Officer
Performs hash fixation and confirms that input states do not drift during replay.

Lattice Compiler
Compiles the precedence lattice and identifies legal orderings.

Replay Operator A
Executes the first replay implementation.

Replay Operator B
Executes the independent replication implementation or operator-equivalent environment.

Control Calibration Officer
Runs baseline, identity, duplicate, and noise-floor controls.

Comparison Officer
Compares terminal outcome vectors and calculates λ, φ, and ψ_R.

Branch Officer
Applies the branch-activation rule but does not alter measurements.

Ledger Officer
Writes append-only ledger entries and cross-references downstream artifacts.

Rollback Officer
Confirms rollback conditions, defect routing, and voiding rules.


A.4 — Preconditions for Campaign Launch

The campaign may not begin until all preconditions are satisfied or formally entered as exceptions.

A.4.1 — Checklist: Launch Preconditions

[ ] Campaign ID assigned.
[ ] Target procedure P named.
[ ] Campaign scope declared.
[ ] Class scope declared.
[ ] Epoch range declared.
[ ] Archive source identified.
[ ] Operator set provisionally listed.
[ ] Canonical ordering π₀ identified.
[ ] Candidate precedence lattice drafted.
[ ] Budget allocation B_campaign declared.
[ ] Minimum control-run budget reserved.
[ ] Minimum replication budget reserved.
[ ] Rollback authority identified.
[ ] Evidence Ledger write access confirmed.
[ ] Exception register opened.
[ ] Campaign embargo acknowledged.
[ ] Branches remain inactive until protocol completion.

If any precondition fails, the campaign may proceed only under Protocol Preparation Mode, not measurement mode.


A.5 — Campaign’s Own Admissibility Check

Before the replay campaign is allowed to measure anything, the campaign itself must pass an Admissibility Check. This is not the full reflexive λ-protocol audit of Chapter 18. It is the launch gate that determines whether this campaign is admissible as a measurement act.

A.5.1 — Campaign Admissibility Questions

The Campaign Admissibility Check asks:

  1. Is the campaign object sufficiently defined?
  2. Is the campaign scope bounded?
  3. Is the archive accessible and fixable?
  4. Can inputs be hash-fixed?
  5. Can operators be decomposed?
  6. Can the precedence lattice be compiled?
  7. Can legal orderings be generated?
  8. Can contamination controls be enforced?
  9. Can control runs establish a noise floor?
  10. Can two-operator replication be performed?
  11. Can A_B cover the full campaign?
  12. Can results be written to the Evidence Ledger?
  13. Are branch outputs embargoed until decision?
  14. Is rollback readiness declared?
  15. Has the protocol’s reflexive standing been recorded or scheduled according to Chapter 18?

A.5.2 — Campaign Admissibility Outcomes

The campaign receives one of five launch statuses:

Admissible — Full Campaign
All minimum conditions are satisfied. Measurement may begin.

Admissible — Restricted Campaign
Campaign may proceed with declared restrictions, narrowed class scope, or reduced ordering set.

Preparation Required
Campaign cannot measure yet. Operator, archive, lattice, or budget preparation is required.

Non-Admissible Campaign
Campaign cannot proceed because minimum integrity conditions fail.

Quarantine Campaign
Campaign is held because proceeding would contaminate evidence, exceed budget, violate embargo, or produce misleading standing.

A.5.3 — Campaign Admissibility Checklist

[ ] Target procedure is defined.
[ ] Scope is bounded.
[ ] Archive can be fixed.
[ ] Operators are decomposable.
[ ] Lattice can be compiled.
[ ] Ordering set can be generated.
[ ] Controls can be run.
[ ] Contamination controls can be enforced.
[ ] Replication can be performed.
[ ] Budget is sufficient.
[ ] Ledger fields exist.
[ ] Branch embargo is active.
[ ] Rollback declaration exists.
[ ] Reflexive protocol status is recorded.

If the campaign fails this check, the reason must be ledgered before any replay is performed.


A.6 — Archive Selection

The archive must represent actual historical executions of the target procedure. Constructed examples may be used for calibration, but they cannot replace archived objects for branch activation.

A.6.1 — Archive Selection Criteria

Archived objects must satisfy the following criteria:

  1. They were processed under π₀ or the declared historical ordering.
  2. They have sufficient trace to reconstruct input state.
  3. They have class labels or can be classed under a declared rule.
  4. They contain terminal outcome data.
  5. They include witness_residue or the fields required to reconstruct it.
  6. They include A_B or the fields required to reconstruct it.
  7. They include route, refusal, quarantine, rejection, hold, or commit data where applicable.
  8. They can be hash-fixed or assigned an exception status.
  9. They are not known to have been altered after original execution without trace.
  10. They are eligible for sealed replay.

A.6.2 — Archive Classes

The campaign must include per-class sampling. At minimum, for the Admissibility Check, the archive should attempt to include:

Class C_commit: historically committed states.
Class C_quarantine: historically quarantined states.
Class C_reject: historically rejected states.
Class C_hold: historically held or embargoed states.
Class C_borderline: near-threshold or late-failure states.
Class C_control: stable low-risk states expected to commute.
Class C_frontier: frontier or high-complexity states where ordering effects are plausible.
Class C_late_failure: states failing after multiple gates.
Class C_zebra: states involving Zebra-Ø or non-admissible singularity concerns.
Class C_budget: states near A_B threshold.
Class C_witness: states with fragile or decaying witness_residue.

If a class cannot be sampled, the campaign must declare why.

A.6.3 — Archive Selection Checklist

[ ] Archive source named.
[ ] Epoch range declared.
[ ] Historical ordering confirmed.
[ ] All candidate records assigned provisional IDs.
[ ] Duplicates removed or marked.
[ ] Corrupt records marked.
[ ] Class taxonomy applied.
[ ] Archive sufficiency assessed per class.
[ ] Exception list created.
[ ] Sampling frame frozen.


A.7 — Hash Fixation

No replay is valid unless the input object is fixed. Hash fixation prevents state drift from being confused with ordering effect.

A.7.1 — Hash Fixation Requirements

For every archived state Σ, record:

Σ_ID
archive source
class label
epoch
original trace reference
original final status
original witness_residue
original A_B
original route
original failure locus
canonical ordering π₀
input reconstruction method
hash method
input hash
trace hash
metadata hash where relevant
exception status if hash is incomplete

A.7.2 — Hash Fixation Outcomes

Fixed
Input and necessary metadata are hash-fixed.

Fixed with Notes
Input is fixed, but some non-primary metadata requires annotation.

Partial Fixation
Core input fixed; some fields missing. Object may be used only for limited measurements.

Hash-Indeterminate
Object cannot support branch activation but may inform archive-defect analysis.

Excluded
Object cannot be replayed.

A.7.3 — Hash Fixation Checklist

[ ] Input state reconstructed.
[ ] Input hash generated.
[ ] Metadata hash generated where required.
[ ] Trace hash generated where required.
[ ] Original status recorded.
[ ] Original witness_residue recorded.
[ ] Original A_B recorded.
[ ] Original route recorded.
[ ] Original failure locus recorded.
[ ] Fixation status assigned.
[ ] Exception entered if incomplete.


A.8 — Operator Decomposition

The target procedure must be decomposed into operators before ordering variants can be generated.

A.8.1 — Admissibility Check Operator Set

For this volume, the default operator set is:

G_S — Silence Entry
G_Z1 — Zero-Question 1
G_Z2 — Zero-Question 2
G_Z3 — Zero-Question 3
G_Z4 — Zero-Question 4
G_B1 — Blocking-Question 1
G_B2 — Blocking-Question 2
G_B3 — Blocking-Question 3
G_B4 — Blocking-Question 4
G_Ø — Zebra-Ø
G_A — Admissibility Budget computation
G_E — Interpretive Embargo
G_W — Final Witness Check
G_C — Commit / Terminal Routing Decision

Each operator must have an operator card.

A.8.2 — Operator Card Template

Operator ID:
Operator Name:
Input:
Output:
Possible terminal result:
Possible non-terminal result:
Witness effect:
Budget effect:
Route effect:
Ledger fields written:
Side effects:
Hard prerequisites:
Operators that must follow:
Operators that may commute:
Contamination risks:
Replay implementation notes:

A.8.3 — Operator Decomposition Checklist

[ ] Every operator named.
[ ] Every operator has an operator card.
[ ] Inputs defined.
[ ] Outputs defined.
[ ] Terminal effects defined.
[ ] Witness effects defined.
[ ] Budget effects defined.
[ ] Route effects defined.
[ ] Ledger effects defined.
[ ] Side effects declared.
[ ] Hard prerequisites declared.
[ ] Commutable relations proposed.
[ ] Unknown relations marked.


A.9 — Precedence Lattice Compilation

The precedence lattice separates actual law from inherited order.

A.9.1 — Default Hard Constraints for the Admissibility Check

The following constraints are presumed hard unless superseded by LCR-approved revision:

  1. G_S precedes all post-entry gates.
  2. G_C remains terminal.
  3. G_E, G_W, and G_C remain terminal sequence unless specifically measured under sealed conditions.
  4. G_A follows the gate outputs required for budget computation.
  5. No operator may alter the fixed input snapshot.
  6. Any operator that writes terminal refusal must preserve trace.
  7. Any operator that cannot execute independently must declare dependency.
  8. Zebra-Ø remains serialized unless certified or separately audited.
  9. No live commit may occur before final witness check.
  10. No result may enter branch activation before replication is complete.

A.9.2 — Lattice Record Fields

Lattice ID:
Procedure ID:
Operator set:
Historical ordering π₀:
Hard precedence edges:
Soft / inherited precedence edges:
Unknown relation edges:
Candidate commutable sets:
Terminal sequence:
Initial sequence:
Legal extension generation method:
Excluded orderings:
Reason for exclusion:
Lattice version:
Compilation date:

A.9.3 — Lattice Compilation Checklist

[ ] π₀ recorded.
[ ] Hard edges identified.
[ ] Soft edges identified.
[ ] Unknown edges identified.
[ ] Terminal constraints recorded.
[ ] Initial constraints recorded.
[ ] Candidate commutable sets listed.
[ ] Excluded orderings justified.
[ ] Legal extension rule defined.
[ ] Lattice version assigned.
[ ] Lattice hash generated.


A.10 — Ordering Variant Generation

The campaign must generate the orderings to be tested before replay begins.

A.10.1 — Ordering Set Types

Full Legal Extension Set
All legal linear extensions of L(P), used where enumeration is feasible.

Generator-Swap Set
Adjacent legal swaps used to detect local ordering residue.

Class-Specific Ordering Set
Orderings selected for a class where full enumeration is not feasible.

High-Risk Ordering Set
Orderings chosen because prior analysis suggests late-failure, budget, witness, Zebra-Ø, or quarantine sensitivity.

Control Ordering Set
Orderings expected to produce no difference, used to calibrate false positives.

A.10.2 — Ordering Variant Record

For every tested ordering π:

Ordering ID:
Ordering sequence:
Relation to π₀:
Swap path from π₀:
Class scope:
Reason for inclusion:
Lattice compliance confirmed:
Expected risk:
Execution mode: sealed replay only / campaign replay / control
Variant hash:

A.10.3 — Ordering Variant Checklist

[ ] π₀ included.
[ ] At least one alternative legal ordering included where lattice permits.
[ ] Generator swaps included where relevant.
[ ] High-risk variants included where justified.
[ ] Control variants included.
[ ] Every variant has ID.
[ ] Every variant has sequence.
[ ] Every variant has lattice compliance proof.
[ ] Every variant has class scope.
[ ] Ordering set frozen before replay.


A.11 — Per-Class Sampling

The campaign must not rely on aggregate-only replay. Ordering effects may be class-specific.

A.11.1 — Sampling Requirements

For each class C:

  1. Declare population size.
  2. Declare sampled count.
  3. Declare inclusion method.
  4. Declare exclusion method.
  5. Include near-threshold cases where available.
  6. Include control cases where available.
  7. Include late-failure cases where available.
  8. Include status-borderline cases where available.
  9. Include witness-fragile cases where available.
  10. Include budget-fragile cases where available.

If a class is too small, test all available objects.

If a class is too large, use stratified sampling.

If a class cannot be sampled, mark Class Replay Defect.

A.11.2 — Sampling Register Fields

Class ID:
Class description:
Population count:
Sample count:
Sampling method:
Exclusion rules:
Near-threshold count:
Control count:
Late-failure count:
Witness-fragile count:
Budget-fragile count:
Hash-fixed count:
Partial-fixation count:
Excluded count:
Sampling adequacy status:

A.11.3 — Per-Class Sampling Checklist

[ ] All target classes listed.
[ ] Population counts recorded.
[ ] Sample method declared.
[ ] Class imbalance noted.
[ ] Near-threshold states included where possible.
[ ] Control states included where possible.
[ ] Hash-fixation adequacy confirmed.
[ ] Sampling register frozen before replay.


A.12 — Contamination Controls

The campaign must prevent one replay path from contaminating another.

A.12.1 — Contamination Risks

Potential contamination includes:

shared mutable state;
operator cache leakage;
trace normalization leakage;
budget-state leakage;
witness expectation leakage;
class relabeling after seeing results;
manual correction after first replay;
variant order affecting interpretation;
replication operator observing primary results too early;
branch officer observing incomplete comparison;
ledger overwrite rather than append-only entry.

A.12.2 — Required Controls

  1. Read-only input snapshots.
  2. Separate output slots per ordering.
  3. Separate trace channels per ordering.
  4. No shared mutable runtime state across variants.
  5. No operator may read another variant’s output.
  6. Comparison occurs only after all relevant runs finish.
  7. Replication operator remains independent until replication submission.
  8. All corrections are append-only.
  9. Any contamination event creates an anomaly entry.
  10. Contaminated runs are excluded or rerun.

A.12.3 — Contamination Control Checklist

[ ] Input snapshots locked.
[ ] Output slots separated.
[ ] Trace channels separated.
[ ] Shared mutable state disabled.
[ ] Operator caches isolated.
[ ] Budget state isolated.
[ ] Witness records isolated.
[ ] Comparison delayed until replay completion.
[ ] Replication independence preserved.
[ ] Anomaly register active.


A.13 — Control Runs and Noise-Floor Calibration

No difference may be called λ until ordinary variation is known.

A.13.1 — Required Control Runs

Baseline Duplicate Control
Run π₀ more than once on the same fixed Σ.

Identity Ordering Control
Run an ordering variant equivalent to π₀ under the lattice.

Stable-Class Control
Run stable control states expected not to be order-sensitive.

Null Difference Control
Compare identical output records through the comparison engine to detect comparison artifacts.

Replication Control
Run a subset through both Replay Operator A and Replay Operator B.

A.13.2 — Noise-Floor Fields

For each field:

Field name:
Control-run variance:
Declared tolerance:
Status-flip tolerance: zero unless explicitly justified
Witness_residue tolerance:
A_B tolerance:
Route tolerance:
Trace-field tolerance:
Failure-locus tolerance: zero for categorical location, unless mapping rule declared
Notes:

A.13.3 — Control-Run Checklist

[ ] π₀ duplicate controls run.
[ ] Identity ordering controls run.
[ ] Stable-class controls run.
[ ] Null comparison controls run.
[ ] Replication controls run.
[ ] Field-specific noise floors calculated.
[ ] Tolerances declared before outcome comparison.
[ ] Any unstable control field marked.
[ ] Control report ledgered.

If control runs are unstable beyond tolerance, the campaign cannot activate a branch. It must enter Control Calibration Defect or rerun after repair.


A.14 — Replay Execution

Replay execution applies each ordering π to each fixed state Σ in the sampled classes.

A.14.1 — Replay Requirements

For every replay:

  1. Use fixed input Σ.
  2. Use declared ordering π.
  3. Use declared operator versions.
  4. Use declared lattice version.
  5. Use isolated output slot.
  6. Record operator-by-operator trace.
  7. Record first terminal failure locus.
  8. Record final status.
  9. Record witness_residue.
  10. Record A_B.
  11. Record route.
  12. Record refusal, quarantine, rejection, hold, or commit signal.
  13. Record anomalies.
  14. Write append-only replay entry.

A.14.2 — Replay Execution Entry

Campaign ID:
Σ_ID:
Class ID:
Input hash:
Ordering ID:
Operator version set:
Lattice version:
Replay operator:
Start timestamp / epoch:
End timestamp / epoch:
Operator trace:
First terminal failure locus:
Final status:
witness_residue:
A_B:
Route:
Refusal type:
Quarantine signal:
Rejection signal:
Commit signal:
Embargo signal:
Trace hash:
Anomaly flag:
Notes:

A.14.3 — Replay Execution Checklist

[ ] All Σ assigned to class.
[ ] All inputs fixed.
[ ] All orderings assigned.
[ ] Replay environment isolated.
[ ] π₀ replay run.
[ ] Alternative orderings run.
[ ] Operator traces written.
[ ] Terminal outcomes recorded.
[ ] Anomalies recorded.
[ ] Replay entries appended.
[ ] No comparison performed before replay completion.


A.15 — Outcome Vector Comparison

Comparison begins only after replay execution and control calibration are complete.

A.15.1 — Required Comparison Fields

For each Σ and π:

status difference;
witness_residue difference;
A_B difference;
route difference;
failure-locus difference;
refusal-type difference;
quarantine difference;
rejection difference;
embargo difference;
final witness difference;
trace-field difference;
Notes-field difference.

A.15.2 — λ Classification

Each tested Σ receives one or more of the following tags:

λ-zero within tolerance
No measured difference beyond noise floor.

Residue-Fragile
witness_residue differs beyond tolerance.

Budget-Fragile
A_B or budget threshold relation differs.

Route-Fragile
Routing path differs.

Failure-Locus-Fragile
First terminal failure locus differs.

Status-Fragile
Final status differs.

Quarantine-Fragile
Quarantine / non-quarantine differs.

Rejection-Fragile
Rejection / non-rejection differs.

Commit-Fragile
Commit / non-commit differs.

Trace-Fragile
Trace-normalized fields differ.

Indeterminate
Difference cannot be interpreted due to defect, noise, or incomplete archive.

A.15.3 — Comparison Checklist

[ ] Control tolerances loaded.
[ ] π₀ outcomes loaded.
[ ] Alternative ordering outcomes loaded.
[ ] Field-by-field comparison complete.
[ ] λ vector calculated.
[ ] φ contribution calculated.
[ ] ψ_R contribution calculated where relevant.
[ ] Fragility tags assigned.
[ ] Indeterminate cases marked.
[ ] Comparison table ledgered.


A.16 — φ and Class-Level Metrics

After individual comparisons, compute class-level metrics.

A.16.1 — Required Class Metrics

For each class C:

sample count;
valid replay count;
excluded count;
λ-zero count;
residue-fragile count;
budget-fragile count;
route-fragile count;
failure-locus-fragile count;
status-fragile count;
φ(C, Π);
ψ_R(C, Π);
mean / median witness_residue delta where meaningful;
A_B threshold crossing count;
dominant fragile ordering;
dominant fragile operator relation;
dominant failure-locus transition;
replication status;
class standing.

A.16.2 — Class Standing Types

Class Commuting within Scope
λ = 0 within tolerance and φ = 0 for the tested ordering set.

Class Residue-Fragile
λ ≠ 0, φ = 0.

Class Status-Fragile
φ > 0.

Class Spectrum-Fragile
ψ_R > 0 even where φ = 0.

Class Indeterminate
Archive, control, replay, or replication defect prevents classification.

Class Not Tested
No valid campaign result.

A.16.3 — Class Metrics Checklist

[ ] Class counts calculated.
[ ] φ calculated.
[ ] ψ_R calculated where relevant.
[ ] λ distributions summarized.
[ ] Dominant fragile relations identified.
[ ] Indeterminate cases separated.
[ ] Class standing assigned.
[ ] Class report ledgered.


A.17 — Two-Operator Replication Rule

No substantive finding may become branch-active unless replicated.

A.17.1 — Replication Requirement

For every class-level finding used in branch activation:

  1. Replay Operator A produces the original result.
  2. Replay Operator B independently reproduces the relevant result or confirms it through operator-equivalent replication.
  3. Differences between A and B are compared.
  4. Replication failures are ledgered.
  5. Unreplicated findings cannot activate a final branch.

A.17.2 — Replication Scope

Replication must cover:

π₀ controls;
at least one alternative ordering per fragile relation;
all status-fragile findings;
all class-level branch-triggering findings;
all near-threshold findings;
all findings used for certificate issuance;
all findings used for compiled π₀ activation.

A.17.3 — Replication Outcomes

Replicated
Independent replay confirms the finding.

Replicated with Notes
Finding confirmed, but minor non-branch differences exist.

Replication Divergent
Operators disagree beyond tolerance.

Replication Failed
Replication cannot be performed.

Replication Not Required
Only permitted for non-branch exploratory findings.

A.17.4 — Replication Checklist

[ ] Independent replay operator assigned.
[ ] Replication input hashes confirmed.
[ ] Replication ordering set confirmed.
[ ] Replication controls run.
[ ] Branch-triggering findings replicated.
[ ] Certificate-supporting findings replicated.
[ ] Outcome B-triggering findings replicated.
[ ] Divergences ledgered.
[ ] Replication report completed.


A.18 — Ledgering Requirements

All campaign records must be append-only. No result may be overwritten.

A.18.1 — Required Ledger Extensions

The Evidence Ledger must support:

campaign_ID;
protocol_version;
procedure_ID;
class_ID;
Σ_ID;
input_hash;
ordering_index;
ordering_ID;
π₀_reference;
tested_ordering_set;
operator_version_set;
lattice_ID;
control_run_reference;
λ_vector;
φ_class_value;
ψ_R_class_value;
fragility_tags;
holonomy_status if measured;
replication_status;
branch_status;
certificate_reference if Outcome A;
compiled_order_reference if Outcome B;
rollback_status;
exception_status.

A.18.2 — Ledger Entry Types

Campaign Scope Entry
Defines the campaign.

Hash Fixation Entry
Fixes each input.

Lattice Entry
Records operator precedence.

Ordering Variant Entry
Records each tested ordering.

Control Run Entry
Records noise-floor calibration.

Replay Entry
Records execution per Σ and ordering.

Comparison Entry
Records λ vector and differences.

Class Metrics Entry
Records φ, ψ_R, and class standing.

Replication Entry
Records independent confirmation.

Branch Decision Entry
Records Outcome A, Outcome B, or defect status.

Rollback Entry
Records voiding, suspension, or restriction conditions.

A.18.3 — Ledgering Checklist

[ ] Ledger schema supports λ.
[ ] Ledger schema supports φ.
[ ] Ledger schema supports ordering_index.
[ ] Ledger schema supports variant IDs.
[ ] Ledger schema supports certificate / compiled-order references.
[ ] All entries append-only.
[ ] No overwrites performed.
[ ] Exceptions ledgered.
[ ] Branch decision ledgered.
[ ] Rollback readiness ledgered.


A.19 — Branch-Activation Decision

Branch activation occurs only after archive selection, hash fixation, campaign admissibility, lattice compilation, ordering generation, per-class sampling, control calibration, replay execution, comparison, ledgering, and replication.

A.19.1 — Outcome A Activation

Outcome A activates only if:

  1. λ = 0 within declared error budget for every tested Σ, class, and ordering relation within the declared scope;
  2. φ = 0 for every tested class within the declared scope;
  3. no unreplicated branch-relevant finding remains;
  4. no control-run defect affects the zero finding;
  5. no archive defect invalidates the tested scope;
  6. the certificate scope is bounded and indexed;
  7. recertification schedule is declared;
  8. local voiding rule is declared;
  9. witness standing of the certificate is recorded.

Outcome A does not mean “order never matters.”
It means “order did not matter within the certified scope under this campaign.”

A.19.2 — Outcome B Activation

Outcome B activates if:

  1. λ ≠ 0 beyond declared error budget for any tested class, operator relation, field, or ordering where the finding is replicated and branch-relevant; or
  2. φ > 0 for any tested class; or
  3. final status changes under a legal ordering variant; or
  4. replicated failure-locus, witness, budget, route, or trace divergence is sufficient to invalidate order-neutral treatment; or
  5. holonomy measurement, where performed, shows non-identity order effect requiring compiled ordering treatment.

Outcome B does not mean historical entries are guilty.
It means the order is law-bearing in the affected scope.

A.19.3 — Indeterminate Result

The campaign returns Indeterminate if:

control runs are unstable;
replication fails;
archive cannot be fixed;
operators are underdefined;
lattice cannot distinguish hard from inherited edges;
budget is insufficient;
branch-triggering findings cannot be interpreted;
contamination invalidates replay.

Indeterminate does not activate Outcome A or Outcome B. It routes to repair, rerun, or restricted provisional standing.

A.19.4 — Branch Decision Checklist

[ ] All class metrics complete.
[ ] Replication complete.
[ ] Control defects resolved or marked.
[ ] Archive defects resolved or marked.
[ ] λ findings reviewed.
[ ] φ findings reviewed.
[ ] ψ_R findings reviewed where relevant.
[ ] Outcome A criteria checked.
[ ] Outcome B criteria checked.
[ ] Indeterminate conditions checked.
[ ] Branch officer records decision.
[ ] Branch decision ledgered.
[ ] Embargo lifted only for activated branch.


A.20 — Rollback Readiness

Every campaign must define what invalidates its results.

A.20.1 — Campaign Result Voiding Conditions

A campaign result is voided or narrowed if:

input hash fixation fails;
archive contamination is discovered;
operator definitions change during campaign;
lattice version is altered after ordering generation;
control-run calibration is invalid;
two-operator replication fails for branch-relevant findings;
comparison engine defect is found;
ledger entries are overwritten or corrupted;
branch decision is made before replication;
protocol self-application later reveals branch-fragile λ_PRP;
budget exhaustion prevented mandatory controls or replication;
campaign scope was materially misdeclared.

A.20.2 — Rollback Actions

Depending on severity:

Annotation
Result remains usable with Notes-field correction.

Narrowing
Result applies to fewer classes, orderings, or epochs.

Suspension
Result cannot be cited as active until repair.

Void
Result loses governance force.

Rerun Required
Campaign must be repeated under corrected protocol.

Escalation
Defect routes to LCR, Level 3 adjacency, or Bedrock-adjacent review.

A.20.3 — Rollback Checklist

[ ] Voiding conditions declared before branch activation.
[ ] Rollback officer assigned.
[ ] Defect severity scale declared.
[ ] Downstream citation update rule declared.
[ ] Certificate void rule declared.
[ ] Compiled π₀ suspension rule declared.
[ ] Variant authorization suspension rule declared.
[ ] Ledger correction method declared.
[ ] Rerun trigger declared.


A.21 — Text Flowchart: Complete Protocol

The protocol may be read as the following executable flow.

Start.

Assign Campaign ID.

Name target procedure P.

Declare scope, class range, epoch range, and budget.

Open campaign ledger.

Run Campaign Admissibility Check.

If campaign is Non-Admissible, stop and ledger non-admissibility.

If campaign requires preparation, stop measurement and enter Preparation Mode.

If campaign is admissible, proceed.

Select archive.

Classify archive.

Fix each archived object by hash.

Exclude or mark hash-indeterminate objects.

Decompose procedure into operators.

Compile precedence lattice.

Record π₀.

Generate legal ordering set Π.

Freeze ordering set.

Declare contamination controls.

Run control calibrations.

If controls fail, stop and enter Control Calibration Defect.

Sample per class.

For each class C:

for each fixed Σ in C:

run π₀ replay;

run each selected legal ordering π;

record terminal outcome vector Ω;

write replay entries.

After replay completion, compare Ω_π to Ω_π₀.

Compute λ for each Σ and π.

Assign fragility tags.

Compute φ per class.

Compute ψ_R per class where applicable.

Run two-operator replication for branch-relevant findings.

If replication fails, enter Replication Defect.

If all branch-relevant findings are replicated, continue.

If λ = 0 within error budget and φ = 0 across declared scope, activate Outcome A within scope.

Issue Commutativity Certificate draft.

Ledger certificate scope, maintenance, local voiding, and citation constraints.

If λ ≠ 0 or φ > 0 in any branch-relevant replicated finding, activate Outcome B within affected scope.

Ledger manifold fiberization, order-fragile census requirement, compiled π₀ draft, and remediation route.

If findings cannot support either branch, enter Indeterminate Result.

Write Branch Decision Entry.

Lift embargo only for activated branch.

Write Rollback Readiness Entry.

Close campaign.

End.


A.22 — Printable Campaign Checklist

Launch

[ ] Campaign ID assigned.
[ ] Target procedure named.
[ ] Scope declared.
[ ] Class range declared.
[ ] Epoch range declared.
[ ] Budget declared.
[ ] Ledger opened.
[ ] Embargo active.
[ ] Campaign Admissibility Check passed.

Archive

[ ] Archive selected.
[ ] Archive classed.
[ ] Sampling frame frozen.
[ ] Exceptions opened.
[ ] Hash fixation performed.
[ ] Hash-indeterminate objects marked.

Procedure Formalization

[ ] Operators decomposed.
[ ] Operator cards completed.
[ ] π₀ recorded.
[ ] Precedence lattice compiled.
[ ] Hard edges separated from inherited sequence.
[ ] Legal ordering set generated.
[ ] Ordering set frozen.

Controls

[ ] Contamination controls declared.
[ ] Baseline duplicate controls run.
[ ] Identity controls run.
[ ] Stable-class controls run.
[ ] Null comparison controls run.
[ ] Noise floors declared.
[ ] Controls ledgered.

Replay

[ ] Per-class sample confirmed.
[ ] π₀ replay executed.
[ ] Alternative ordering replays executed.
[ ] Operator traces recorded.
[ ] Outcome vectors recorded.
[ ] Replay anomalies ledgered.

Comparison

[ ] Outcome vectors compared.
[ ] λ computed.
[ ] φ computed.
[ ] ψ_R computed where relevant.
[ ] Fragility tags assigned.
[ ] Class standings assigned.
[ ] Comparison table ledgered.

Replication

[ ] Replay Operator B assigned.
[ ] Branch-relevant findings replicated.
[ ] Certificate-supporting findings replicated.
[ ] Outcome B-triggering findings replicated.
[ ] Divergences ledgered.
[ ] Replication report completed.

Branch

[ ] Outcome A criteria checked.
[ ] Outcome B criteria checked.
[ ] Indeterminate criteria checked.
[ ] Branch decision recorded.
[ ] Embargo lifted only for activated branch.
[ ] Downstream artifacts updated.

Rollback

[ ] Rollback conditions checked.
[ ] Voiding conditions recorded.
[ ] Narrowing conditions recorded.
[ ] Suspension conditions recorded.
[ ] Rerun triggers recorded.
[ ] Final campaign status ledgered.


A.23 — Branch Output Templates

A.23.1 — Outcome A Output Template

Branch: Outcome A — Commutativity Certificate
Campaign ID:
Scope:
Classes certified:
Operators certified:
Ordering set tested:
Error budget:
λ result: zero within scope
φ result: zero within scope
Replication status:
Control status:
Certificate ID:
Maintenance schedule:
Local void rule:
Citation constraint:
Notes:

A.23.2 — Outcome B Output Template

Branch: Outcome B — Dark Canon Discovered
Campaign ID:
Affected scope:
Affected classes:
Affected operator relations:
λ result: nonzero / vector attached
φ result:
ψ_R result:
Replication status:
Control status:
Required next artifact: Order-Fragile Census Annex
π₀ status: compiled draft required
Variant registry: required
Remediation route: LCR-B
Rollback readiness: required
Notes:

A.23.3 — Indeterminate Output Template

Branch: No activation
Campaign ID:
Reason: archive / hash / control / replication / lattice / budget / contamination / comparison / other
Affected scope:
Actions required:
Permitted use of data: sealed analysis / preparation / none
Rerun requirement:
Notes:


A.24 — Standalone Execution Rule

This appendix is executable without reference to the body of the volume if the campaign executor has access to:

the target procedure archive;
the operator definitions;
the Evidence Ledger;
the hash method;
the replay environment;
the budget allocation;
and the authority to write campaign artifacts.

Where the body of the volume provides philosophical justification, this appendix provides procedure. A campaign may cite this appendix as the operative protocol for measuring λ and φ.

The body explains why the measurement matters.

This appendix tells the canon how to perform it.


A.25 — Final Protocol Rule

Permuted-Order Replay Protocol Rule

A governed multi-operator procedure may not be treated as order-neutral merely because its historical ordering appears natural, inherited, efficient, obvious, or administratively fixed. The procedure must be decomposed into operators, its precedence lattice compiled, its legal orderings generated, its archive hash-fixed, its control runs calibrated, its replays executed under contamination controls, its results replicated, its λ and φ ledgered, and its branch consequence activated only after the campaign completes. If λ = 0 and φ = 0 within scope, order may be certified as non-load-bearing within that scope. If λ ≠ 0 or φ > 0, order must be treated as law-bearing within the affected scope.

The Check does not get to keep an unmeasured order.

The protocol begins there.


Appendix B — λ and φ Ledger Extension

Evidence Ledger Extension Template for Ordering Measurement

Appendix ID: APP-B-LAMBDA-PHI-LEDGER
Extension Name: λ and φ Ledger Extension
Protocol Dependency: Appendix A — Permuted-Order Replay Protocol v1.0
Layer: Hyper-Ω-Stack Layer C
Function: Evidence Ledger schema for recording ordering-indexed replay results, Loop Residue λ, Order Fragility Index φ contribution, replication standing, and branch-relevant comparison data.
Execution Status: Required for every campaign measuring ordering residue.
Standing: No campaign result may activate Outcome A or Outcome B unless its λ and φ fields are ledgered under this extension or an LCR-approved successor schema.


B.0 — Purpose

The λ and φ Ledger Extension exists to prevent order measurement from becoming a loose comparison table.

A replay campaign is only as strong as its ledger. If the campaign produces λ, φ, status transitions, residue deltas, or fragility tags but fails to write them in a stable schema, the result cannot govern. It cannot issue a Commutativity Certificate. It cannot compile π₀. It cannot activate the Order-Fragile Census. It cannot support remediation. It remains analysis, not law.

This appendix defines the Evidence Ledger fields required for every state Σ replayed under a legal ordering π against the historical ordering π₀.

Each ledger entry must preserve:

the identity of the state;

the content hash of the replayed object;

the ordering tested;

the π₀ reference result;

the residue under π₀;

the residue under π;

the computed λ;

the status under both orderings;

the φ contribution flag;

the class and epoch;

the operator signature;

and the replication pair ID.

The extension is designed for append-only use. No λ entry may overwrite another. If a replay is corrected, replicated, voided, narrowed, or superseded, the ledger receives a new entry linked to the prior entry. The prior entry remains visible.


B.1 — Primary Ledger Object

The primary object of this extension is the Ordering Comparison Entry.

An Ordering Comparison Entry records one comparison:

Σ under π₀ versus the same fixed Σ under π.

The unit is therefore:

one state, one tested ordering, one comparison to π₀, one campaign.

If the campaign tests ten alternative orderings for one state, the ledger requires ten Ordering Comparison Entries for that state, plus aggregate class entries. If the same state is later replayed under a new protocol version, new entries are created. If a replication operator repeats the comparison, the replication result is linked through Replication Pair ID.


B.2 — Minimal Required Fields

Every Ordering Comparison Entry must contain the following fields.

1. Ledger Entry ID
Unique ID for this ledger entry.

2. Campaign ID
ID of the Permuted-Order Replay Protocol campaign that produced this entry.

3. Protocol Version
Version of the replay protocol used.

4. ID_Σ
Unique identifier of the replayed state, submission, artifact, LCR, quarantine object, or governed input.

5. Content Hash
Hash of the fixed content of Σ.

6. Metadata Hash
Hash of relevant metadata where metadata affects replay standing.

7. Class
Class C assigned to Σ for sampling and φ calculation.

8. Epoch
Ledger epoch, archive epoch, or campaign epoch to which Σ belongs.

9. π₀ Reference
Identifier of the historical canonical ordering used as baseline.

10. π Tested
Identifier of the legal alternative ordering tested against π₀.

11. π Tested Sequence
Full operator sequence or reference to the Ordering Variant Record.

12. Operator Signature
Versioned signature of the operator set used in this comparison.

13. Lattice ID
Identifier of the precedence lattice under which π was legal.

14. Residue Under π₀
Reference residue, witness_residue, budget state, route, failure locus, and other terminal vector fields under π₀.

15. Residue Under π
Corresponding residue, witness_residue, budget state, route, failure locus, and terminal vector fields under tested ordering π.

16. λ
Field-by-field difference between residue under π and residue under π₀.

17. Status Under π₀
Terminal status under π₀.

18. Status Under π
Terminal status under tested ordering π.

19. Status Difference Flag
Boolean or categorical field indicating whether final status changed.

20. φ Contribution Flag
Indicates whether this comparison contributes to φ for its class.

21. Failure-Locus Difference Flag
Indicates whether the first terminal failure locus changed.

22. Budget Difference Flag
Indicates whether A_B or its threshold relation changed.

23. Witness Difference Flag
Indicates whether witness_residue changed beyond tolerance.

24. Route Difference Flag
Indicates whether routing path changed.

25. Fragility Tags
Tags assigned to the comparison.

26. Control-Run Reference
Reference to the control-run calibration used to interpret differences.

27. Error Budget Reference
Reference to the declared error budget.

28. Replication Pair ID
ID linking primary and replication entries.

29. Replication Status
Replicated, Replicated with Notes, Replication Divergent, Replication Failed, or Not Yet Replicated.

30. Branch-Relevance Flag
Indicates whether this comparison can affect Outcome A / Outcome B branch activation.

31. Ledger Status
Active, Superseded, Annotated, Narrowed, Suspended, Voided, or Indeterminate.

32. Notes
Required notes, anomaly comments, exception references, or downstream constraints.


B.3 — Field Definitions

B.3.1 — Ledger Entry ID

Field Name: ledger_entry_id
Type: string
Required: yes
Format: LPHI-[campaign]-[Σ]-[π]-[sequence number]
Purpose: Provides unique reference for the comparison entry.

Example:

LPHI-PRP01-SIGMA044-PI07-0001

No two entries may share the same Ledger Entry ID.


B.3.2 — Campaign ID

Field Name: campaign_id
Type: string
Required: yes
Purpose: Links the entry to the replay campaign.

Example:

PRP-CAMPAIGN-001

All entries in a branch-activation decision must point to the same campaign or declare cross-campaign aggregation explicitly.


B.3.3 — Protocol Version

Field Name: protocol_version
Type: string
Required: yes
Purpose: Identifies the protocol version that produced the measurement.

Example:

PRP-1.0

If protocol self-application later changes protocol standing, entries must receive annotation rather than overwrite.


B.3.4 — ID_Σ

Field Name: id_sigma
Type: string
Required: yes
Purpose: Identifies the fixed object being replayed.

Example:

Σ-2026-CFRONT-0182

ID_Σ must remain stable across π₀ replay, alternative replay, comparison, and replication.


B.3.5 — Content Hash

Field Name: content_hash
Type: string
Required: yes
Purpose: Proves that π₀ and π were applied to the same fixed content.

The hash must be generated before replay. If content hash is missing, the entry cannot support branch activation.

Permitted statuses:

Fixed
Fixed with Notes
Partial Fixation
Hash-Indeterminate
Excluded

Only Fixed and Fixed with Notes entries may support final branch activation unless an LCR explicitly permits restricted use.


B.3.6 — Metadata Hash

Field Name: metadata_hash
Type: string
Required: conditional
Purpose: Fixes class, epoch, trace, source, and other metadata where metadata can affect replay standing.

Metadata Hash is required when:

class assignment affects operator behavior;

epoch affects applicable rule version;

trace history affects witness_residue;

budget history affects A_B;

quarantine or refusal history affects route.


B.3.7 — Class

Field Name: class_id
Type: string
Required: yes
Purpose: Assigns Σ to a class C for φ and ψ_R calculation.

Example classes:

C_commit
C_quarantine
C_reject
C_hold
C_borderline
C_frontier
C_late_failure
C_zebra
C_budget
C_witness

Class must be assigned before replay. Post-result class changes require a new annotation entry.


B.3.8 — Epoch

Field Name: epoch
Type: string or integer
Required: yes
Purpose: Locates Σ in archive time, ledger time, or campaign time.

Epoch is required because rule versions, operator definitions, witness standing, and archive conditions may vary across time.


B.3.9 — π₀ Reference

Field Name: pi0_reference
Type: string
Required: yes
Purpose: Identifies the baseline ordering against which π is compared.

For the Admissibility Check, π₀ is:

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

The entry may reference a stored π₀ object instead of repeating the full sequence if the stored object is versioned and hash-fixed.


B.3.10 — π Tested

Field Name: pi_tested
Type: string
Required: yes
Purpose: Identifies the tested legal ordering.

Example:

π-ALT-07
GV-PL1-V07-C_L-E12

π Tested must be linked to the Ordering Variant Record.


B.3.11 — π Tested Sequence

Field Name: pi_tested_sequence
Type: ordered list or reference
Required: yes
Purpose: Prevents ambiguity about the tested order.

If the sequence is stored elsewhere, the ledger entry must include a sequence reference and hash.


B.3.12 — Operator Signature

Field Name: operator_signature
Type: string
Required: yes
Purpose: Identifies the versioned set of operators used in both π₀ and π replay.

Operator Signature must include:

operator IDs;

operator versions;

gate definitions;

budget formula version;

witness formula version;

Zebra-Ø version if used;

embargo version;

commit / terminal routing version.

If operator versions differ between π₀ and π, the entry is invalid for λ unless the difference is explicitly part of a separate campaign design.


B.3.13 — Lattice ID

Field Name: lattice_id
Type: string
Required: yes
Purpose: Identifies the precedence lattice that made π legal.

A π tested without lattice reference is not a lawful ordering comparison.


B.3.14 — Residue Under π₀

Field Name: residue_pi0
Type: structured object
Required: yes
Purpose: Stores the reference terminal outcome vector under π₀.

Minimum subfields:

status_pi0
witness_residue_pi0
A_B_pi0
route_pi0
failure_locus_pi0
refusal_type_pi0
quarantine_signal_pi0
rejection_signal_pi0
commit_signal_pi0
embargo_signal_pi0
final_witness_pi0
trace_hash_pi0
notes_pi0

This field is called “residue” in a broad ledger sense: it includes terminal trace fields, not only witness residue.


B.3.15 — Residue Under π

Field Name: residue_pi
Type: structured object
Required: yes
Purpose: Stores the terminal outcome vector under the tested ordering π.

Minimum subfields:

status_pi
witness_residue_pi
A_B_pi
route_pi
failure_locus_pi
refusal_type_pi
quarantine_signal_pi
rejection_signal_pi
commit_signal_pi
embargo_signal_pi
final_witness_pi
trace_hash_pi
notes_pi

The subfields must align with residue_pi0 so λ can be computed field by field.


B.3.16 — λ

Field Name: lambda_vector
Type: structured object
Required: yes
Purpose: Records the measured difference between residue under π and residue under π₀.

Minimum subfields:

lambda_status
lambda_witness_residue
lambda_A_B
lambda_route
lambda_failure_locus
lambda_refusal_type
lambda_quarantine_signal
lambda_rejection_signal
lambda_commit_signal
lambda_embargo_signal
lambda_final_witness
lambda_trace
lambda_notes
lambda_summary

If a field is categorical, λ records transition rather than numerical subtraction.

Examples:

status: commit → quarantine
failure_locus: G_B3 → G_Ø
route: direct reject → quarantine hold
A_B: +0.17
witness_residue: −0.04
trace: changed terminal note


B.3.17 — Status Under π₀

Field Name: status_pi0
Type: enum
Required: yes
Allowed Values: commit, quarantine, reject, hold, embargo, return, indeterminate, other-defined
Purpose: Records final status under π₀.


B.3.18 — Status Under π

Field Name: status_pi
Type: enum
Required: yes
Allowed Values: commit, quarantine, reject, hold, embargo, return, indeterminate, other-defined
Purpose: Records final status under tested ordering π.


B.3.19 — Status Difference Flag

Field Name: status_difference_flag
Type: boolean
Required: yes
Purpose: Indicates whether status_pi differs from status_pi0.

If true, the entry is status-fragile and contributes to φ unless excluded by defect.


B.3.20 — φ Contribution Flag

Field Name: phi_contribution_flag
Type: enum
Required: yes
Allowed Values: contributes, does_not_contribute, excluded_defect, excluded_scope, pending_replication
Purpose: Indicates whether this comparison counts toward φ for its class.

A comparison contributes to φ when:

status_pi differs from status_pi0;

the comparison is within declared scope;

the input is sufficiently fixed;

the replay is valid;

and replication does not invalidate the finding.


B.3.21 — Failure-Locus Difference Flag

Field Name: failure_locus_difference_flag
Type: boolean
Required: yes
Purpose: Indicates whether the first terminal failure locus changed.

This field supports ψ_R and Refusal Spectrum Ordering Decomposition.


B.3.22 — Budget Difference Flag

Field Name: budget_difference_flag
Type: enum
Required: yes
Allowed Values: none, delta_within_tolerance, delta_beyond_tolerance, threshold_crossing, indeterminate
Purpose: Records whether A_B changed meaningfully.

Threshold crossing must be marked even if numerical delta is small.


B.3.23 — Witness Difference Flag

Field Name: witness_difference_flag
Type: enum
Required: yes
Allowed Values: none, delta_within_tolerance, delta_beyond_tolerance, standing_change, indeterminate
Purpose: Records whether witness_residue changed meaningfully.


B.3.24 — Route Difference Flag

Field Name: route_difference_flag
Type: boolean
Required: yes
Purpose: Records whether the routing path changed.

Route changes matter even when final status does not change.


B.3.25 — Fragility Tags

Field Name: fragility_tags
Type: list
Required: yes
Allowed Tags:
lambda_zero_within_tolerance
residue_fragile
budget_fragile
budget_threshold_fragile
witness_fragile
route_fragile
failure_locus_fragile
status_fragile
quarantine_fragile
rejection_fragile
commit_fragile
trace_fragile
spectrum_fragile
replication_pending
indeterminate
excluded_defect

Tags must be assigned mechanically from comparison fields where possible.


B.3.26 — Control-Run Reference

Field Name: control_run_reference
Type: string
Required: yes
Purpose: Links the comparison to the noise-floor calibration used to determine whether deltas are meaningful.

No λ-zero claim is valid without control-run reference.


B.3.27 — Error Budget Reference

Field Name: error_budget_reference
Type: string
Required: yes
Purpose: Links the entry to the declared error budget.

The error budget must be declared before comparison.


B.3.28 — Replication Pair ID

Field Name: replication_pair_id
Type: string
Required: yes for branch-relevant entries
Purpose: Links primary replay comparison to independent replication.

Format:

REPL-[campaign]-[Σ]-[π]

A branch-relevant λ or φ finding without Replication Pair ID is pending and cannot activate a branch.


B.3.29 — Replication Status

Field Name: replication_status
Type: enum
Required: yes
Allowed Values: not_required, pending, replicated, replicated_with_notes, divergent, failed
Purpose: Records whether the finding survived the two-operator replication rule.


B.3.30 — Branch-Relevance Flag

Field Name: branch_relevance_flag
Type: enum
Required: yes
Allowed Values: branch_relevant, non_branch_exploratory, control_only, excluded
Purpose: Indicates whether this entry can affect Outcome A / Outcome B activation.


B.3.31 — Ledger Status

Field Name: ledger_status
Type: enum
Required: yes
Allowed Values: active, annotated, narrowed, superseded, suspended, voided, indeterminate
Purpose: Records the standing of the ledger entry.


B.3.32 — Notes

Field Name: notes
Type: text
Required: conditional
Purpose: Records anomalies, restrictions, uncertainty, exception references, and downstream effects.

Notes are required for:

partial hash fixation;

indeterminate fields;

replication divergence;

control-run instability;

budget threshold crossing;

status difference;

voided or narrowed entries;

manual operator interpretation;

class relabeling;

or branch-relevant anomaly.


B.4 — Ordering Comparison Entry Template

Ledger Entry ID:
Campaign ID:
Protocol Version:
ID_Σ:
Content Hash:
Metadata Hash:
Class:
Epoch:
π₀ Reference:
π Tested:
π Tested Sequence:
Operator Signature:
Lattice ID:

Residue Under π₀:

  • Status:
  • witness_residue:
  • A_B:
  • Route:
  • Failure locus:
  • Refusal type:
  • Quarantine signal:
  • Rejection signal:
  • Commit signal:
  • Embargo signal:
  • Final witness:
  • Trace hash:
  • Notes:

Residue Under π:

  • Status:
  • witness_residue:
  • A_B:
  • Route:
  • Failure locus:
  • Refusal type:
  • Quarantine signal:
  • Rejection signal:
  • Commit signal:
  • Embargo signal:
  • Final witness:
  • Trace hash:
  • Notes:

λ:

  • λ_status:
  • λ_witness_residue:
  • λ_A_B:
  • λ_route:
  • λ_failure_locus:
  • λ_refusal_type:
  • λ_quarantine_signal:
  • λ_rejection_signal:
  • λ_commit_signal:
  • λ_embargo_signal:
  • λ_final_witness:
  • λ_trace:
  • λ_notes:
  • λ_summary:

Status Under π₀:
Status Under π:
Status Difference Flag:
φ Contribution Flag:
Failure-Locus Difference Flag:
Budget Difference Flag:
Witness Difference Flag:
Route Difference Flag:
Fragility Tags:
Control-Run Reference:
Error Budget Reference:
Replication Pair ID:
Replication Status:
Branch-Relevance Flag:
Ledger Status:
Notes:


B.5 — Compact Machine-Readable Schema

The same entry may be represented in a compact schema:

OrderingComparisonEntry {
  ledger_entry_id:
  campaign_id:
  protocol_version:
  id_sigma:
  content_hash:
  metadata_hash:
  class_id:
  epoch:
  pi0_reference:
  pi_tested:
  pi_tested_sequence:
  operator_signature:
  lattice_id:

  residue_pi0 {
    status:
    witness_residue:
    A_B:
    route:
    failure_locus:
    refusal_type:
    quarantine_signal:
    rejection_signal:
    commit_signal:
    embargo_signal:
    final_witness:
    trace_hash:
    notes:
  }

  residue_pi {
    status:
    witness_residue:
    A_B:
    route:
    failure_locus:
    refusal_type:
    quarantine_signal:
    rejection_signal:
    commit_signal:
    embargo_signal:
    final_witness:
    trace_hash:
    notes:
  }

  lambda_vector {
    lambda_status:
    lambda_witness_residue:
    lambda_A_B:
    lambda_route:
    lambda_failure_locus:
    lambda_refusal_type:
    lambda_quarantine_signal:
    lambda_rejection_signal:
    lambda_commit_signal:
    lambda_embargo_signal:
    lambda_final_witness:
    lambda_trace:
    lambda_notes:
    lambda_summary:
  }

  status_pi0:
  status_pi:
  status_difference_flag:
  phi_contribution_flag:
  failure_locus_difference_flag:
  budget_difference_flag:
  witness_difference_flag:
  route_difference_flag:
  fragility_tags:
  control_run_reference:
  error_budget_reference:
  replication_pair_id:
  replication_status:
  branch_relevance_flag:
  ledger_status:
  notes:
}

B.6 — Class-Level φ Entry

Individual comparison entries feed the class-level φ ledger.

For each class C, the campaign must write one Class-Level φ Entry.

Class φ Entry ID:
Campaign ID:
Protocol Version:
Class ID:
Epoch Range:
π₀ Reference:
Tested Ordering Set Π:
Population Count:
Sample Count:
Valid Replay Count:
Excluded Count:
Hash-Indeterminate Count:
Replication-Pending Count:
Status-Difference Count:
φ:
φ Error / Confidence Note:
Dominant Status Transition:
Dominant Fragile Ordering:
Dominant Fragile Operator Relation:
Class Standing:
Replication Status:
Branch Relevance:
Notes:

Class Standing values:

Class Commuting within Scope
Class Residue-Fragile
Class Status-Fragile
Class Spectrum-Fragile
Class Indeterminate
Class Not Tested


B.7 — Class-Level λ Summary Entry

For each class C, the campaign must also write a Class-Level λ Summary Entry.

Class λ Summary ID:
Campaign ID:
Class ID:
Tested Ordering Set Π:
λ-zero Count:
Residue-Fragile Count:
Budget-Fragile Count:
Witness-Fragile Count:
Route-Fragile Count:
Failure-Locus-Fragile Count:
Status-Fragile Count:
Trace-Fragile Count:
Mean witness_residue delta:
Median witness_residue delta:
A_B threshold crossing count:
Dominant λ field:
Dominant ordering relation:
Holonomy measurement required: yes / no / already measured
Notes:


B.8 — Replication Pair Entry

Branch-relevant findings must be linked through Replication Pair Entry.

Replication Pair ID:
Campaign ID:
ID_Σ:
π Tested:
Primary Ledger Entry ID:
Replication Ledger Entry ID:
Replay Operator A:
Replay Operator B:
Input Hash Match: yes / no
Operator Signature Match: yes / no
Lattice Match: yes / no
Outcome Match: yes / no / partial
λ Match: yes / no / within tolerance / divergent
Status Match: yes / no
φ Contribution Confirmed: yes / no / pending
Replication Status:
Divergence Notes:
Branch Use Permitted: yes / no / restricted

No branch-relevant entry may be counted as final until Replication Pair Entry is complete.


B.9 — Branch Aggregation Entry

After individual and class entries are complete, the campaign writes Branch Aggregation Entry.

Branch Aggregation ID:
Campaign ID:
Protocol Version:
Scope:
Classes Tested:
Total Valid Comparisons:
Total λ-zero Entries:
Total Nonzero λ Entries:
Total φ-Contributing Entries:
Classes with φ = 0:
Classes with φ > 0:
Classes Indeterminate:
Replication Complete: yes / no
Control Runs Valid: yes / no
Outcome A Eligible: yes / no
Outcome B Triggered: yes / no
Indeterminate: yes / no
Branch Decision: Outcome A / Outcome B / Indeterminate / Protocol Defect
Branch Decision Entry Reference:
Notes:


B.10 — Rules for Counting φ

The φ contribution flag must be applied consistently.

A comparison contributes to φ when:

  1. status under π differs from status under π₀;
  2. the comparison belongs to declared class scope;
  3. the content hash is fixed or fixed with notes;
  4. replay passed contamination controls;
  5. control-run calibration supports interpretation;
  6. replication confirms the status difference or remains pending but is not yet used for branch activation;
  7. the entry is not excluded by archive defect, lattice defect, operator mismatch, or protocol defect.

A comparison does not contribute to φ when:

status is unchanged;

entry is outside scope;

hash is indeterminate;

comparison is exploratory only;

replication fails;

control-run instability invalidates interpretation;

or the entry is voided.

A pending comparison may be marked pending_replication, but it cannot be used for final branch activation.


B.11 — Rules for Recording λ

λ must be recorded field by field. It may not be collapsed into a single word such as “changed” or “unchanged.”

If status changes, record the transition.

If witness_residue changes, record numerical or structured difference.

If A_B changes, record numerical delta and threshold relation.

If route changes, record route transition.

If failure locus changes, record gate-to-gate transition.

If refusal type changes, record type transition.

If trace changes, record trace-field difference.

If a field cannot be compared, record indeterminate and explain why.

If λ is zero within tolerance, record the tolerance and control-run reference.

A zero λ entry without control-run reference is invalid.


B.12 — Operator Signature Requirements

Operator Signature must prevent false λ caused by operator drift.

The signature must include:

operator list;

operator versions;

gate definition hashes;

budget formula hash;

witness computation hash;

Zebra-Ø definition hash where relevant;

embargo rule hash;

commit routing rule hash;

trace schema hash;

lattice hash.

If operator signatures differ between π₀ replay and π replay, the comparison is invalid unless the campaign is explicitly designed to measure operator-version difference rather than ordering difference. Such a campaign cannot activate this volume’s branch point.


B.13 — Example Entry

Ledger Entry ID: LPHI-PRP01-SIGMA-0182-PI07-0001
Campaign ID: PRP-CAMPAIGN-001
Protocol Version: PRP-1.0
ID_Σ: Σ-0182
Content Hash: h_Σ_0182_fixed
Metadata Hash: h_meta_0182
Class: C_late_failure
Epoch: E12
π₀ Reference: PI0-ACHECK-E12
π Tested: GV-PL1-V07-C_late_failure-E12
π Tested Sequence: G_S → G_B1 → G_B2 → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C
Operator Signature: OPSIG-ACHECK-1.0-E12
Lattice ID: PL-ACHECK-1.0

Residue Under π₀:

  • Status: quarantine
  • witness_residue: 0.42
  • A_B: 0.71
  • Route: late blocking hold
  • Failure locus: G_B4
  • Refusal type: boundary hold
  • Quarantine signal: yes
  • Rejection signal: no
  • Commit signal: no
  • Embargo signal: yes
  • Final witness: incomplete
  • Trace hash: h_trace_pi0_0182
  • Notes: late failure under π₀

Residue Under π:

  • Status: reject
  • witness_residue: 0.31
  • A_B: 0.54
  • Route: early block rejection
  • Failure locus: G_B2
  • Refusal type: explicit block
  • Quarantine signal: no
  • Rejection signal: yes
  • Commit signal: no
  • Embargo signal: no
  • Final witness: not reached
  • Trace hash: h_trace_pi7_0182
  • Notes: early rejection under variant

λ:

  • λ_status: quarantine → reject
  • λ_witness_residue: −0.11
  • λ_A_B: −0.17
  • λ_route: late blocking hold → early block rejection
  • λ_failure_locus: G_B4 → G_B2
  • λ_refusal_type: boundary hold → explicit block
  • λ_quarantine_signal: yes → no
  • λ_rejection_signal: no → yes
  • λ_commit_signal: no change
  • λ_embargo_signal: yes → no
  • λ_final_witness: incomplete → not reached
  • λ_trace: changed terminal trace
  • λ_notes: status-fragile and failure-locus-fragile
  • λ_summary: nonzero λ with φ contribution

Status Under π₀: quarantine
Status Under π: reject
Status Difference Flag: true
φ Contribution Flag: contributes
Failure-Locus Difference Flag: true
Budget Difference Flag: delta_beyond_tolerance
Witness Difference Flag: delta_beyond_tolerance
Route Difference Flag: true
Fragility Tags: status_fragile; budget_fragile; witness_fragile; route_fragile; failure_locus_fragile
Control-Run Reference: CTRL-PRP01-C_late_failure
Error Budget Reference: ERR-PRP01-E12
Replication Pair ID: REPL-PRP01-SIGMA-0182-PI07
Replication Status: pending
Branch-Relevance Flag: branch_relevant
Ledger Status: active
Notes: Cannot activate branch until replication confirms.


B.14 — Ledger Validity Conditions

An Ordering Comparison Entry is valid for branch activation only if:

content hash is fixed or fixed with notes;

π₀ reference is valid;

π tested is legal under lattice;

operator signature matches;

control-run reference exists;

error budget reference exists;

comparison is within campaign scope;

replication is complete for branch-relevant findings;

ledger status is active or annotated, not suspended or voided.

If any condition fails, the entry may remain in the ledger but cannot support branch activation.


B.15 — Ledger Status Transitions

Permitted transitions:

active → annotated
active → narrowed
active → suspended
active → voided
active → superseded
annotated → narrowed
annotated → suspended
annotated → voided
suspended → active only through restoration entry
suspended → voided
indeterminate → active only through correction and replication
indeterminate → voided

No transition erases the prior entry. Every transition creates a new ledger entry referencing the prior one.


B.16 — Linter Rules

Missing Ordering Index
Fires when a ledger entry records replay outcome without π or π₀ reference.

λ Without Hash
Fires when λ is recorded without content hash.

φ Without Class
Fires when φ contribution is recorded without class.

Status Flip Without Replication
Fires when a status difference is used for branch activation before replication.

Operator Drift Confusion
Fires when operator signatures differ but result is interpreted as ordering λ.

Zero λ Without Controls
Fires when λ = 0 is claimed without control-run calibration.

Unscoped φ
Fires when φ is reported globally without class scope.

Ledger Overwrite
Fires when a comparison entry is modified rather than appended.

π Tested Without Lattice
Fires when an ordering is tested without legal lattice reference.

Branch Decision Without Ledger Extension
Fires when Outcome A or Outcome B is activated without required λ and φ fields.


B.17 — Required Aggregates for Outcome A

To support Outcome A, the ledger must show:

all branch-relevant entries within scope have λ = 0 within tolerance;

all class-level φ values are 0;

all status difference flags are false within scope;

all control-run references are valid;

all replication requirements are satisfied;

all indeterminate entries are excluded or scoped out;

certificate scope is bounded to tested classes, operators, orderings, and epochs.

Outcome A may not cite untested classes.


B.18 — Required Aggregates for Outcome B

To support Outcome B, the ledger must show at least one replicated branch-relevant finding of:

λ ≠ 0 beyond tolerance;

or φ > 0;

or final status difference;

or status-stable but governance-relevant residue sufficient to void order-neutral treatment;

or failure-locus / witness / budget / route divergence requiring compiled ordering treatment.

Outcome B must specify affected class, operator relation, ordering, and epoch.

Outcome B may not inflate a local finding into a global claim.


B.19 — Appendix Rule

λ and φ Ledger Extension Rule

Every ordering replay campaign must record comparison results in the Evidence Ledger using the λ and φ Ledger Extension. Each entry must identify ID_Σ, content hash, π tested, π₀ reference residue, residue under π, λ, status under both orderings, φ contribution flag, class, epoch, operator signature, and replication pair ID. A campaign that fails to ledger these fields may produce analysis, but it may not activate Outcome A, activate Outcome B, issue a Commutativity Certificate, compile π₀, authorize governance variants, or support remediation law.

The measurement is not complete when λ is observed.

It is complete when λ is ledgered.


Appendix C — The Precedence Lattice of the Admissibility Check

Compiled Constraint Inventory, First-Campaign Ordering Set, and Forbidden-Ordering Inventory

Appendix ID: APP-C-PRECEDENCE-LATTICE
Artifact Name: The Precedence Lattice of the Admissibility Check
Protocol Dependency: Appendix A — Permuted-Order Replay Protocol v1.0
Ledger Dependency: Appendix B — λ and φ Ledger Extension
Layer: Hyper-Ω-Stack Layer C
Function: To define the compiled ordering constraints of the Admissibility Check, enumerate the first-campaign legal orderings, and record forbidden orderings with each exclusion traced to its compiled source.
Standing: Required lattice object for any first-campaign λ measurement of the Check.
Version: Precedence Lattice v1.0


C.0 — Purpose

This appendix defines the precedence lattice used by the first Permuted-Order Replay campaign.

The campaign cannot test arbitrary rearrangements of the Admissibility Check. It can test only legal linear extensions of a compiled lattice. The lattice separates hard dependency from inherited habit. It says which parts of π₀ are law, which parts are historical sequence, which parts are testable, and which rearrangements are forbidden because they would no longer be the same Check.

The purpose of this appendix is therefore threefold.

First, it records the compiled constraint inventory of the Admissibility Check.

Second, it gives the lattice diagram in text form.

Third, it enumerates the orderings admitted into the first campaign and the orderings excluded from the first campaign.

The appendix is intentionally conservative. It does not attempt to test every mathematically imaginable ordering. It tests a bounded first-campaign set sufficient to determine whether the Check’s central inherited order has measurable consequence: within-block permutations of the zero-question block, within-block permutations of the blocking-question block, and the block swap between the zero-question block and the blocking-question block.

The first campaign does not move Silence Entry. It does not move Zebra-Ø into free permutation. It does not move budget computation before required gate outputs. It does not move interpretive embargo, final witness check, or commit out of terminal sequence. Those exclusions are not omissions. They are compiled constraints.


C.1 — Operator Inventory

The Admissibility Check is decomposed into the following operators.

G_S — Silence Entry
Initial entry gate. Establishes that the candidate enters the Check under non-emission discipline before any substantive gate is applied.

G_Z1 — Zero-Question 1
First zero-question operator.

G_Z2 — Zero-Question 2
Second zero-question operator.

G_Z3 — Zero-Question 3
Third zero-question operator.

G_Z4 — Zero-Question 4
Fourth zero-question operator.

G_B1 — Blocking-Question 1
First blocking-question operator.

G_B2 — Blocking-Question 2
Second blocking-question operator.

G_B3 — Blocking-Question 3
Third blocking-question operator.

G_B4 — Blocking-Question 4
Fourth blocking-question operator.

G_Ø — Zebra-Ø
Non-admissible singularity / boundary-distortion gate. Conservative default: serialized after the zero-question and blocking-question blocks for the first campaign.

G_A — Admissibility Budget Computation
Computes A_B after required gate outputs are available.

G_E — Interpretive Embargo
Terminal interpretive hold preventing premature closure before final witness confirmation.

G_W — Final Witness Check
Terminal witness validation before commit or terminal routing.

G_C — Commit / Terminal Routing Decision
Final commit, quarantine, rejection, hold, or other terminal routing operation.


C.2 — Block Definitions

For lattice readability, the operators are grouped into blocks.

Entry Block

E₀ = {G_S}

Zero Block

Z = {G_Z1, G_Z2, G_Z3, G_Z4}

Blocking Block

B = {G_B1, G_B2, G_B3, G_B4}

Zebra Block

Ø = {G_Ø}

Budget Block

A = {G_A}

Terminal Block

T = {G_E, G_W, G_C}

The canonical historical ordering is:

π₀ = G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

In block form:

π₀ = E₀ → Z → B → Ø → A → T


C.3 — Compiled Constraint Inventory

The following constraints define Precedence Lattice v1.0.

C.3.1 — Entry Constraint

Constraint ID: C-LAT-01
Rule: G_S precedes every other operator.
Formal Form: G_S ≺ Oᵢ for all Oᵢ ≠ G_S.
Source: Silence Entry Rule; non-emission discipline; Admissibility Check Protocol v1.0.
Effect: No campaign ordering may test any substantive gate before Silence Entry.
Reason: Without G_S, the candidate has not entered the Check under pre-runtime silence discipline.

C.3.2 — Fixed Input Constraint

Constraint ID: C-LAT-02
Rule: No operator may alter the hash-fixed input Σ.
Formal Form: ∀Oᵢ, Oᵢ may read Σ but may not mutate Σ.
Source: Hash Fixation Rule; Permuted-Order Replay Protocol v1.0.
Effect: Any ordering requiring mutation of Σ is forbidden.
Reason: λ measures order, not input drift.

C.3.3 — Zero Block Internal Permutation Allowed

Constraint ID: C-LAT-03
Rule: G_Z1–G_Z4 may be permuted within the Zero Block for first-campaign replay.
Formal Form: any permutation of Z is legal after G_S and before the next block in the tested ordering.
Source: First-Campaign Permutation Design; Section 6.4 bounded-ordering test scope.
Effect: All 24 zero-question permutations are legal in the first campaign, provided all other hard constraints remain satisfied.
Reason: The campaign must test whether the zero-question block contains internal order residue.

C.3.4 — Blocking Block Internal Permutation Allowed

Constraint ID: C-LAT-04
Rule: G_B1–G_B4 may be permuted within the Blocking Block for first-campaign replay.
Formal Form: any permutation of B is legal after the preceding tested block and before G_Ø.
Source: First-Campaign Permutation Design; Section 6.4 bounded-ordering test scope.
Effect: All 24 blocking-question permutations are legal in the first campaign, provided all other hard constraints remain satisfied.
Reason: The campaign must test whether the blocking-question block contains internal order residue.

C.3.5 — Zero / Blocking Block Swap Allowed

Constraint ID: C-LAT-05
Rule: The Zero Block and Blocking Block may be swapped as intact blocks in the first campaign.
Formal Form: E₀ → Z → B → Ø → A → T and E₀ → B → Z → Ø → A → T are both legal first-campaign block-level orderings.
Source: First-Campaign Block-Swap Design; Section 6.4.
Effect: The campaign may test whether zero-before-blocking is load-bearing.
Reason: π₀ inherited zero-before-blocking. The campaign must determine whether that block order carries measurable consequence.

C.3.6 — No Cross-Interleaving in First Campaign

Constraint ID: C-LAT-06
Rule: Zero-question operators and blocking-question operators may not be interleaved in the first campaign.
Formal Form: Orderings such as G_Z1 → G_B1 → G_Z2 → G_B2 are excluded from first-campaign scope.
Source: Section 6.4 bounded first-campaign design; contamination and interpretability control.
Effect: The first campaign tests within-block permutations and intact block swap only.
Reason: Cross-interleaving would increase ordering space, complicate attribution of λ, and may require a second-campaign lattice.

C.3.7 — Zebra-Ø Serialized Default

Constraint ID: C-LAT-07
Rule: G_Ø remains after completion of the Zero and Blocking Blocks in the first campaign.
Formal Form: all G_Zi and G_Bj precede G_Ø.
Source: Zebra-Ø Conservative Serialization Rule; Section 6.4 forbidden-ordering inventory.
Effect: Zebra-Ø is not moved earlier, interleaved, or placed after budget in the first campaign.
Reason: Zebra-Ø may contain internal sequence and high-severity boundary effects; its own audit is queued separately in Chapter 17.

C.3.8 — Budget Dependency Constraint

Constraint ID: C-LAT-08
Rule: G_A follows all gate outputs required for A_B computation. In the first campaign, G_A follows G_Ø.
Formal Form: G_Ø ≺ G_A.
Source: Admissibility Budget Computation Rule; budget requires completed gate-output set.
Effect: G_A may not be moved before zero questions, blocking questions, or Zebra-Ø in the first campaign.
Reason: Budget computation before required gate outputs would measure a different procedure, not a legal ordering of the same Check.

C.3.9 — Interpretive Embargo Terminal Constraint

Constraint ID: C-LAT-09
Rule: G_E remains in terminal sequence after budget computation and before final witness.
Formal Form: G_A ≺ G_E ≺ G_W.
Source: Interpretive Embargo Rule; terminal closure discipline.
Effect: G_E may not be moved into the zero block, blocking block, or before G_A in the first campaign.
Reason: Embargo governs premature closure after the Check has accumulated its gate and budget state.

C.3.10 — Final Witness Constraint

Constraint ID: C-LAT-10
Rule: G_W follows G_E and precedes G_C.
Formal Form: G_E ≺ G_W ≺ G_C.
Source: Final Witness Rule; witness confirmation before commit.
Effect: No commit or terminal routing may precede final witness check.
Reason: A terminal decision without final witness is not the same Check.

C.3.11 — Commit Terminal Constraint

Constraint ID: C-LAT-11
Rule: G_C is terminal.
Formal Form: Oᵢ ≺ G_C for all Oᵢ ≠ G_C.
Source: Commit Rule; Evidence Ledger terminal-entry discipline.
Effect: No operator may execute after commit in the first campaign.
Reason: Post-commit operators would not affect admissibility before commit and would corrupt terminal standing.

C.3.12 — No Variant Shopping Constraint

Constraint ID: C-LAT-12
Rule: A replay ordering may not be selected after observing which ordering produces a preferred outcome.
Formal Form: Π must be fixed before replay.
Source: Governance Variant Rule; anti-shopping discipline.
Effect: First-campaign ordering set is frozen before execution.
Reason: Ordering selection after outcome observation converts measurement into law-shopping.

C.3.13 — Replication Before Branch Constraint

Constraint ID: C-LAT-13
Rule: Branch activation follows two-operator replication.
Formal Form: Replication report ≺ Branch Decision.
Source: Two-Operator Replication Rule; Appendix A.
Effect: No λ or φ finding may activate Outcome A or Outcome B until replicated.
Reason: Branch activation is governance standing, not preliminary analysis.


C.4 — Text Lattice Diagram

The Precedence Lattice v1.0 may be rendered in text form as follows.

G_S
 |
 v
+-----------------------------+
| Zero / Blocking Region      |
|                             |
| Legal first-campaign forms: |
|                             |
|   Z-block then B-block      |
|   B-block then Z-block      |
|                             |
| Z-block internal order:     |
|   any permutation of        |
|   G_Z1, G_Z2, G_Z3, G_Z4    |
|                             |
| B-block internal order:     |
|   any permutation of        |
|   G_B1, G_B2, G_B3, G_B4    |
|                             |
| Forbidden in first campaign:|
|   Z/B interleaving          |
+-----------------------------+
 |
 v
G_Ø
 |
 v
G_A
 |
 v
G_E
 |
 v
G_W
 |
 v
G_C

In compact lattice notation:

G_S ≺ {Z, B region} ≺ G_Ø ≺ G_A ≺ G_E ≺ G_W ≺ G_C

where:

Z and B may appear as intact blocks in either order;

Z internal order is freely permuted within first-campaign scope;

B internal order is freely permuted within first-campaign scope;

Z and B are not interleaved in first-campaign scope.


C.5 — First-Campaign Ordering Families

The first campaign tests three ordering families.

Family F0 — Canonical Baseline

π₀ = E₀ → Z₁₂₃₄ → B₁₂₃₄ → Ø → A → E → W → C

Family FZ — Zero Block Internal Permutations

The Zero Block is permuted while the Blocking Block remains canonical.

General form:

G_S → perm(Z) → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

Family FB — Blocking Block Internal Permutations

The Blocking Block is permuted while the Zero Block remains canonical.

General form:

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → perm(B) → G_Ø → G_A → G_E → G_W → G_C

Family FSWAP — Intact Block Swap

The Zero Block and Blocking Block are swapped as intact canonical blocks.

General form:

G_S → G_B1 → G_B2 → G_B3 → G_B4 → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_Ø → G_A → G_E → G_W → G_C

The first campaign does not test the full Cartesian product of all Z permutations and all B permutations. It tests one block at a time plus the intact block swap. Simultaneous Z-and-B permutation is reserved for a later expanded campaign if the first campaign detects nonzero λ, φ, or unresolved interaction.


C.6 — Enumeration of First-Campaign Orderings

C.6.1 — F0: Canonical Baseline

F0-π₀

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C


C.6.2 — FZ: Zero Block Internal Permutations

The following orderings permute G_Z1–G_Z4 while keeping the Blocking Block canonical.

FZ-01

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-02

G_S → G_Z1 → G_Z2 → G_Z4 → G_Z3 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-03

G_S → G_Z1 → G_Z3 → G_Z2 → G_Z4 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-04

G_S → G_Z1 → G_Z3 → G_Z4 → G_Z2 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-05

G_S → G_Z1 → G_Z4 → G_Z2 → G_Z3 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-06

G_S → G_Z1 → G_Z4 → G_Z3 → G_Z2 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-07

G_S → G_Z2 → G_Z1 → G_Z3 → G_Z4 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-08

G_S → G_Z2 → G_Z1 → G_Z4 → G_Z3 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-09

G_S → G_Z2 → G_Z3 → G_Z1 → G_Z4 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-10

G_S → G_Z2 → G_Z3 → G_Z4 → G_Z1 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-11

G_S → G_Z2 → G_Z4 → G_Z1 → G_Z3 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-12

G_S → G_Z2 → G_Z4 → G_Z3 → G_Z1 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-13

G_S → G_Z3 → G_Z1 → G_Z2 → G_Z4 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-14

G_S → G_Z3 → G_Z1 → G_Z4 → G_Z2 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-15

G_S → G_Z3 → G_Z2 → G_Z1 → G_Z4 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-16

G_S → G_Z3 → G_Z2 → G_Z4 → G_Z1 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-17

G_S → G_Z3 → G_Z4 → G_Z1 → G_Z2 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-18

G_S → G_Z3 → G_Z4 → G_Z2 → G_Z1 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-19

G_S → G_Z4 → G_Z1 → G_Z2 → G_Z3 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-20

G_S → G_Z4 → G_Z1 → G_Z3 → G_Z2 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-21

G_S → G_Z4 → G_Z2 → G_Z1 → G_Z3 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-22

G_S → G_Z4 → G_Z2 → G_Z3 → G_Z1 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-23

G_S → G_Z4 → G_Z3 → G_Z1 → G_Z2 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FZ-24

G_S → G_Z4 → G_Z3 → G_Z2 → G_Z1 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C


C.6.3 — FB: Blocking Block Internal Permutations

The following orderings keep the Zero Block canonical and permute G_B1–G_B4.

FB-01

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B1 → G_B2 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FB-02

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B1 → G_B2 → G_B4 → G_B3 → G_Ø → G_A → G_E → G_W → G_C

FB-03

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B1 → G_B3 → G_B2 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FB-04

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B1 → G_B3 → G_B4 → G_B2 → G_Ø → G_A → G_E → G_W → G_C

FB-05

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B1 → G_B4 → G_B2 → G_B3 → G_Ø → G_A → G_E → G_W → G_C

FB-06

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B1 → G_B4 → G_B3 → G_B2 → G_Ø → G_A → G_E → G_W → G_C

FB-07

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B2 → G_B1 → G_B3 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FB-08

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B2 → G_B1 → G_B4 → G_B3 → G_Ø → G_A → G_E → G_W → G_C

FB-09

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B2 → G_B3 → G_B1 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FB-10

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B2 → G_B3 → G_B4 → G_B1 → G_Ø → G_A → G_E → G_W → G_C

FB-11

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B2 → G_B4 → G_B1 → G_B3 → G_Ø → G_A → G_E → G_W → G_C

FB-12

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B2 → G_B4 → G_B3 → G_B1 → G_Ø → G_A → G_E → G_W → G_C

FB-13

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B3 → G_B1 → G_B2 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FB-14

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B3 → G_B1 → G_B4 → G_B2 → G_Ø → G_A → G_E → G_W → G_C

FB-15

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B3 → G_B2 → G_B1 → G_B4 → G_Ø → G_A → G_E → G_W → G_C

FB-16

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B3 → G_B2 → G_B4 → G_B1 → G_Ø → G_A → G_E → G_W → G_C

FB-17

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B3 → G_B4 → G_B1 → G_B2 → G_Ø → G_A → G_E → G_W → G_C

FB-18

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B3 → G_B4 → G_B2 → G_B1 → G_Ø → G_A → G_E → G_W → G_C

FB-19

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B4 → G_B1 → G_B2 → G_B3 → G_Ø → G_A → G_E → G_W → G_C

FB-20

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B4 → G_B1 → G_B3 → G_B2 → G_Ø → G_A → G_E → G_W → G_C

FB-21

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B4 → G_B2 → G_B1 → G_B3 → G_Ø → G_A → G_E → G_W → G_C

FB-22

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B4 → G_B2 → G_B3 → G_B1 → G_Ø → G_A → G_E → G_W → G_C

FB-23

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B4 → G_B3 → G_B1 → G_B2 → G_Ø → G_A → G_E → G_W → G_C

FB-24

G_S → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_B4 → G_B3 → G_B2 → G_B1 → G_Ø → G_A → G_E → G_W → G_C


C.6.4 — FSWAP: Intact Zero / Blocking Block Swap

FSWAP-01

G_S → G_B1 → G_B2 → G_B3 → G_B4 → G_Z1 → G_Z2 → G_Z3 → G_Z4 → G_Ø → G_A → G_E → G_W → G_C

This ordering tests whether the canonical block order Z-before-B is load-bearing while preserving internal canonical order inside each block.


C.7 — First-Campaign Ordering Set Summary

The first-campaign ordering set contains:

1 canonical baseline ordering;

24 Zero Block internal permutations;

24 Blocking Block internal permutations;

1 intact Zero / Blocking Block swap.

Because FZ-01 and FB-01 are identical to π₀, the campaign may either retain both as duplicate controls or collapse them into π₀ for unique-ordering count. The recommended standing is:

Operational unique orderings: 49
Control duplicate entries: FZ-01 and FB-01 may be retained as π₀ duplicate controls.
Total listed ordering records: 50 plus π₀ reference, depending on ledger implementation.

The campaign must state whether it counts FZ-01 and FB-01 as separate control records or aliases of π₀.


C.8 — Forbidden-Ordering Inventory

The following orderings are forbidden in the first campaign. Each exclusion is traced to its compiled source.

C.8.1 — Silence Entry Not First

Forbidden Pattern: Oᵢ → G_S for any Oᵢ ≠ G_S.
Example: G_Z1 → G_S → …
Exclusion ID: FBD-01
Compiled Source: C-LAT-01, Silence Entry Rule.
Reason: The candidate must enter the Check under non-emission discipline before any substantive gate executes.
Status: Forbidden, not merely out of first-campaign scope.

C.8.2 — Commit Not Terminal

Forbidden Pattern: G_C before any remaining operator.
Example: … → G_C → G_W
Exclusion ID: FBD-02
Compiled Source: C-LAT-11, Commit Terminal Constraint.
Reason: A post-commit operator cannot participate in pre-commit admissibility and would corrupt terminal standing.
Status: Forbidden.

C.8.3 — Final Witness After Commit

Forbidden Pattern: G_C ≺ G_W.
Example: … → G_E → G_C → G_W
Exclusion ID: FBD-03
Compiled Source: C-LAT-10 and C-LAT-11.
Reason: Commit before final witness is not the Admissibility Check.
Status: Forbidden.

C.8.4 — Interpretive Embargo After Commit

Forbidden Pattern: G_C ≺ G_E.
Example: … → G_W → G_C → G_E
Exclusion ID: FBD-04
Compiled Source: C-LAT-09 and C-LAT-11.
Reason: Embargo must prevent premature closure before final witness and commit, not annotate after commit.
Status: Forbidden.

C.8.5 — Budget Before Required Gate Outputs

Forbidden Pattern: G_A before completion of Z, B, and G_Ø in first-campaign scope.
Example: G_S → G_A → G_Z1 → …
Exclusion ID: FBD-05
Compiled Source: C-LAT-08, Admissibility Budget Computation Rule.
Reason: Budget computation requires gate outputs. Without them, the campaign measures a different budget law.
Status: Forbidden in first campaign; requires separate LCR to test alternate budget designs.

C.8.6 — Zebra-Ø Before Completion of Zero and Blocking Blocks

Forbidden Pattern: G_Ø before all G_Zi and G_Bj complete.
Example: G_S → G_Ø → G_Z1 → …
Exclusion ID: FBD-06
Compiled Source: C-LAT-07, Zebra-Ø Conservative Serialization Rule.
Reason: Zebra-Ø is high-severity and internally procedural; its movement is excluded from first-campaign scope and queued for separate audit.
Status: Forbidden in first campaign, not globally impossible.

C.8.7 — Zebra-Ø After Budget

Forbidden Pattern: G_A ≺ G_Ø.
Example: … → G_B4 → G_A → G_Ø → …
Exclusion ID: FBD-07
Compiled Source: C-LAT-07 and C-LAT-08.
Reason: First-campaign A_B computation assumes Zebra-Ø output is available.
Status: Forbidden in first campaign.

C.8.8 — Cross-Interleaving of Zero and Blocking Questions

Forbidden Pattern: interleaving G_Zi and G_Bj.
Example: G_S → G_Z1 → G_B1 → G_Z2 → G_B2 → …
Exclusion ID: FBD-08
Compiled Source: C-LAT-06, Section 6.4 bounded first-campaign design.
Reason: First campaign tests within-block permutations and intact block swap only. Interleaving is reserved for expanded campaign if warranted.
Status: Forbidden in first campaign.

C.8.9 — Simultaneous Zero and Blocking Internal Permutations

Forbidden Pattern: perm(Z) combined with perm(B) in a single first-campaign ordering, outside π₀ aliases.
Example: G_S → G_Z3 → G_Z1 → G_Z4 → G_Z2 → G_B4 → G_B1 → G_B3 → G_B2 → …
Exclusion ID: FBD-09
Compiled Source: First-Campaign Attribution Control; Section 6.4.
Reason: Simultaneous permutation obscures whether λ arises from Z-internal order, B-internal order, or interaction.
Status: Forbidden in first campaign; eligible for second campaign if first campaign detects interaction.

C.8.10 — Terminal Sequence Reordered

Forbidden Pattern: any order other than G_E → G_W → G_C in the terminal block.
Example: G_W → G_E → G_C
Exclusion ID: FBD-10
Compiled Source: C-LAT-09, C-LAT-10, C-LAT-11.
Reason: Embargo, witness, and commit are not freely permutable; they define terminal closure discipline.
Status: Forbidden.

C.8.11 — Operator After Branch Decision

Forbidden Pattern: replay or comparison after branch activation without reopening campaign.
Example: Branch decision → new replay → silent update.
Exclusion ID: FBD-11
Compiled Source: C-LAT-13; Appendix A Branch-Activation Rule.
Reason: Branch activation must follow completed replay and replication. Later additions require append-only supplemental campaign entry.
Status: Forbidden.

C.8.12 — Ordering Set Modified After Replay Begins

Forbidden Pattern: adding or removing π after observing preliminary outcomes.
Example: nonzero λ observed → add easier variant; zero λ observed → stop high-risk variant.
Exclusion ID: FBD-12
Compiled Source: C-LAT-12, No Variant Shopping Constraint.
Reason: Ordering set must be fixed before replay to prevent outcome-driven selection.
Status: Forbidden.

C.8.13 — Operator Version Drift Between π₀ and π

Forbidden Pattern: π₀ replay uses one operator signature, π replay uses another.
Example: G_B2 version 1.0 under π₀, G_B2 version 1.1 under π.
Exclusion ID: FBD-13
Compiled Source: Appendix B Operator Signature Requirement.
Reason: The campaign would measure operator drift, not ordering residue.
Status: Forbidden for λ branch activation.

C.8.14 — Mutable Input Across Orderings

Forbidden Pattern: Σ changes between π₀ and π replay.
Example: corrected Σ used under π but not under π₀.
Exclusion ID: FBD-14
Compiled Source: C-LAT-02, Hash Fixation Rule.
Reason: λ requires the same fixed input.
Status: Forbidden.

C.8.15 — Live Runtime Variant Use During Campaign

Forbidden Pattern: using an unapproved campaign ordering for live admissibility.
Example: FSWAP-01 applied to active submissions before LCR-A.
Exclusion ID: FBD-15
Compiled Source: Governance Variant Rule; Section 16.2.
Reason: Tested orderings are sealed replay variants, not runtime permissions.
Status: Forbidden without class-specific LCR-A.


C.9 — Forbidden Inventory Summary Table

FBD-01 | G_S not first                         | C-LAT-01 | Forbidden
FBD-02 | G_C not terminal                      | C-LAT-11 | Forbidden
FBD-03 | G_W after G_C                         | C-LAT-10/11 | Forbidden
FBD-04 | G_E after G_C                         | C-LAT-09/11 | Forbidden
FBD-05 | G_A before required outputs           | C-LAT-08 | Forbidden first campaign
FBD-06 | G_Ø before Z/B completion             | C-LAT-07 | Forbidden first campaign
FBD-07 | G_Ø after G_A                         | C-LAT-07/08 | Forbidden first campaign
FBD-08 | Z/B cross-interleaving                | C-LAT-06 | Forbidden first campaign
FBD-09 | simultaneous Z and B permutations      | Attribution Control | Forbidden first campaign
FBD-10 | terminal sequence reordered           | C-LAT-09/10/11 | Forbidden
FBD-11 | replay after branch decision          | C-LAT-13 | Forbidden
FBD-12 | ordering set modified after replay    | C-LAT-12 | Forbidden
FBD-13 | operator version drift                | Appendix B | Forbidden
FBD-14 | mutable input across orderings        | C-LAT-02 | Forbidden
FBD-15 | live runtime use of campaign variant  | Section 16.2 | Forbidden without LCR-A

C.10 — Lattice Standing for First Campaign

The first campaign is authorized to test the following question:

Does the inherited ordering inside and between the Zero Block and Blocking Block carry measurable λ or φ, while Silence Entry, Zebra-Ø, Admissibility Budget computation, Interpretive Embargo, Final Witness Check, and Commit remain serialized under compiled constraints?

This bounded question is sufficient for first campaign branch activation because the canonical ordering π₀ contains a major inherited sequence in the Z/B region. If that region commutes, the campaign may support Outcome A within the tested scope. If that region does not commute, the campaign may support Outcome B within the affected scope. If the campaign detects residue but cannot assign it because excluded orderings might explain it, the result becomes class-specific or indeterminate and routes to expanded campaign.

The first campaign does not certify the entire Check against every conceivable ordering. It certifies or convicts only the tested lattice region.

This limitation must appear in every certificate, compiled π₀ entry, branch decision, and ledger summary produced from the first campaign.


C.11 — Appendix Rule

Precedence Lattice Rule

The Admissibility Check may be replayed for first-campaign λ measurement only under orderings legal within Precedence Lattice v1.0. The first campaign includes the canonical baseline, all internal permutations of the Zero Block, all internal permutations of the Blocking Block, and the intact Zero / Blocking Block swap. It excludes Silence Entry movement, terminal-sequence movement, budget prepositioning, Zebra-Ø movement, Z/B interleaving, simultaneous Z/B double permutation, mutable-input runs, operator-version drift, and runtime use of replay variants. Every exclusion must be traced to a compiled constraint. Any ordering outside this appendix requires a new lattice version or LCR-approved expanded campaign.

The lattice does not say that forbidden first-campaign orderings are unimaginable.

It says they are not this campaign.

The first measurement is bounded so that its residue can be read.


Appendix D — Governance Pack

Compilation Map Deltas, LCR Drafts, Certificate Template, and Volume-Level Evidence Ledger Entry

Appendix ID: APP-D-GOVERNANCE-PACK
Artifact Name: Governance Pack for The Order of Law
Layer: Hyper-Ω-Stack Layer C
Function: To collect the volume’s governance outputs in final operational form: Compilation Map deltas, LCR-A drafts for λ and φ, LCR-B skeleton for Outcome B remediation, Outcome A certificate template, and the volume-level Evidence Ledger entry.
Standing: Required close-out artifact for the volume.
Dependency: Appendix A, Appendix B, Appendix C.
Branch Condition: Some components are unconditional; some are branch-conditional and remain embargoed until the Part II campaign result.


D.0 — Purpose

This appendix gathers the volume’s governance artifacts into one executable pack.

The volume has introduced a new primary quantity, λ, and a companion index, φ. It has defined the protocol by which λ and φ are measured, the ledger extension by which they are recorded, the lattice through which legal orderings are generated, and the branch consequences that follow from the result. Those changes must now be entered into the governance machinery.

The Governance Pack performs five functions.

First, it states the final Compilation Map deltas produced by the volume.

Second, it provides LCR-A nine-field submission drafts for λ and φ as operational Layer C quantities.

Third, it provides the LCR-B skeleton for the remediation decision that becomes active under Outcome B.

Fourth, it provides the Commutativity Certificate template that becomes active under Outcome A.

Fifth, it records the volume-level Evidence Ledger entry.

This appendix does not decide the branch. It prepares the governance instruments for both branches and marks their activation conditions. Until the Part II campaign executes and the branch decision is ledgered, branch-dependent artifacts remain under embargo.


D.1 — Compilation Map Deltas

D.1.1 — Delta Register

Delta Register ID: CM-DELTA-ORDER-LAW-20.3
Source Volume: The Order of Law: Loop Residue λ and the Holonomy of Governance
Layer: Hyper-Ω-Stack Layer C
Status: Final volume delta set; branch-dependent entries embargoed until campaign result.
Primary Change: Ordering becomes a measurable governance quantity.
Quantity Added: λ — Loop Residue.
Companion Index Added: φ — Order Fragility Index.
Primary Protocol Added: Permuted-Order Replay Protocol v1.0.
Primary Ledger Extension Added: λ and φ Ledger Extension.
Primary Lattice Added: Precedence Lattice of the Admissibility Check v1.0.
Branch Artifacts Added: Commutativity Certificate Template; π₀ Compilation Map Entry; Order-Fragile Census Protocol; Remediation LCR-B skeleton.
Queue Artifact Added: Holonomy Audit Registry.
Reflexive Artifact Added: λ-Protocol Reflexive Audit Annex.
Boundary Handoffs Added: Ordering Signature Whitening to Node 2; Mutual Ordering Incommensurability to Node 8.


D.1.2 — Compilation Map Delta 1: λ as Primary Layer C Quantity

Compilation Map Entry ID: CM-LC-λ-20.1
Object: λ — Loop Residue
Prior Status: Not compiled as primary quantity; ordering treated as procedural sequence unless otherwise specified.
New Status: Primary Layer C quantity of the pre-runtime regime.
Definition: λ measures the difference in terminal outcome vector produced when the same governed input is processed by the same operator set under a legal ordering π instead of the historical ordering π₀.
Formal Expression: λ(Σ, π) = Ω_π(Σ) − Ω_π₀(Σ)
Scope: All governed multi-operator procedures with more than one legal linear extension, beginning with the Admissibility Check.
Required Ledger Fields: ordering_index, π₀_reference, π_tested, λ_vector, operator_signature, lattice_ID, replication_pair_ID.
Downstream Effects: Evidence Ledger extension; Admissibility Graph ordering annotation; Holonomy Audit Registry; branch activation; certificate or compiled-order standing.
Maintenance: λ measurements require control-run calibration, two-operator replication, and reflexive protocol standing.
Rollback Condition: λ standing is suspended if protocol self-application fails, replication is voided, hash fixation fails, or operator signature drift contaminates comparison.
Status: Compiled by this volume.


D.1.3 — Compilation Map Delta 2: φ as Companion Index

Compilation Map Entry ID: CM-LC-φ-20.1
Object: φ — Order Fragility Index
Prior Status: Not compiled as ordering-related terminal status index.
New Status: Companion Layer C index for status variation under legal ordering alternatives.
Definition: φ measures the fraction of tested states in a class whose terminal status differs under at least one legal ordering π relative to π₀.
Formal Expression: φ(C, Π) = fraction of Σ ∈ C with status(Ω_π(Σ)) ≠ status(Ω_π₀(Σ)) for at least one π ∈ Π.
Scope: Class-indexed; ordering-set-indexed; procedure-indexed.
Required Ledger Fields: class_ID, tested_ordering_set, status_pi0, status_pi, status_difference_flag, phi_contribution_flag, replication_status.
Downstream Effects: Branch activation; Order-Fragile Census; remediation pricing; LCR-B routing; local voiding; certificate eligibility.
Maintenance: φ must be recalculated when class taxonomy, operator set, lattice, or archive scope changes.
Rollback Condition: φ standing is voided if status comparisons are unreplicated, hash-indeterminate, outside scope, or produced under operator drift.
Status: Compiled by this volume.


D.1.4 — Compilation Map Delta 3: Permuted-Order Replay Protocol v1.0

Compilation Map Entry ID: CM-PRP-1.0-APP-A
Object: Permuted-Order Replay Protocol v1.0
Prior Status: Not present.
New Status: Principal measurement protocol for ordering residue.
Function: Measures λ and φ by replaying hash-fixed archived inputs under π₀ and legal ordering variants.
Mandatory Components: archive selection, hash fixation, campaign admissibility check, operator decomposition, precedence lattice, ordering generation, contamination controls, control runs, replay execution, comparison, replication, ledgering, branch decision.
Branch Dependency: Required before Outcome A or Outcome B activation.
Reflexive Requirement: Subject to one mandatory λ-protocol self-application under Chapter 18.
Rollback Condition: Protocol output is suspended if mandatory controls, replication, hash fixation, or reflexive standing fail.
Status: Compiled as protocol artifact.


D.1.5 — Compilation Map Delta 4: λ and φ Ledger Extension

Compilation Map Entry ID: CM-LEDGER-λφ-APP-B
Object: Evidence Ledger λ and φ Extension
Prior Status: Evidence Ledger lacked required ordering-residue fields.
New Status: Required ledger schema for ordering comparison entries.
Function: Records ID_Σ, content hash, π tested, π₀ reference residue, residue under π, λ, status under both orderings, φ contribution flag, class, epoch, operator signature, replication pair ID.
Activation: Unconditional for any PRP campaign.
Rollback Condition: Branch decision invalid if required fields are missing for branch-relevant entries.
Status: Compiled as ledger extension.


D.1.6 — Compilation Map Delta 5: Precedence Lattice of the Admissibility Check v1.0

Compilation Map Entry ID: CM-LATTICE-ACHECK-APP-C
Object: Precedence Lattice of the Admissibility Check v1.0
Prior Status: π₀ existed as historical sequence; hard dependencies and inherited order not separated in lattice form.
New Status: Compiled lattice for first-campaign measurement.
Function: Defines legal orderings for first campaign: within-Z permutations, within-B permutations, and intact Z/B block swap; forbids Silence Entry movement, terminal movement, Zebra-Ø movement, budget prepositioning, interleaving, operator drift, mutable input, and live variant use.
Activation: Required for first PRP campaign.
Rollback Condition: Campaign result invalid if tested ordering lacks lattice legality or if lattice changes after ordering set freeze.
Status: Compiled as campaign lattice.


D.1.7 — Compilation Map Delta 6: Check Branch Standing

Compilation Map Entry ID: CM-CHECK-BRANCH-20.3
Object: Admissibility Check Ordering Standing
Prior Status: π₀ used as uncompiled historical order.
New Status: Branch-pending. After campaign, Check must receive one of two lawful statuses: certified commuting within scope or compiled order-bearing within scope.
Outcome A Status: Commutativity Certificate; π₀ becomes Canonical Trace Convention within certified scope.
Outcome B Status: π₀ becomes Compiled Ordering Content within affected scope.
No Third Mature Status: Unmeasured historical habit is not a lawful resting state after this volume.
Activation: Pending PRP campaign result.
Embargo: Active until branch decision.
Status: Branch-pending compiled map delta.


D.1.8 — Compilation Map Delta 7: Holonomy Audit Registry

Compilation Map Entry ID: CM-HAR-17.2
Object: Holonomy Audit Registry
Prior Status: Other canon procedures not queued for ordering audit.
New Status: Multi-procedure audit queue established.
Initial Queue: LCR-A processing order; LCR-B compilation procedure; Zebra-Ø internal sequence; Merge Re-Admission Gate sequence; quarantine exit.
Priority Basis: Exposure multiplied by structural consequence and downstream dependency weight.
Required Fields: operator decomposition, historical ordering, precedence lattice, outcome vector, archive source, exposure priority.
Status: Queued; campaigns not yet executed.


D.1.9 — Compilation Map Delta 8: Reflexive Protocol Standing

Compilation Map Entry ID: CM-REFLEXIVE-λPRP-18
Object: λ-Protocol Reflexive Audit Annex
Prior Status: Measurement protocol not self-applied.
New Status: One mandatory self-application required.
Function: Measures λ_PRP, the ordering residue of the Permuted-Order Replay Protocol itself.
Tower Rule: Level 1 mandatory; Level 2 conditional on nonzero or indeterminate Level 1; further levels conditional on unresolved findings and A_B.
Rollback Condition: Campaign outputs relying on PRP lose full standing if reflexive audit is missing, failed, or budget-terminated without restrictions.
Status: Required maintenance artifact.


D.2 — LCR-A Nine-Field Submission Draft for λ

LCR-A ID: LCR-A-DRAFT-λ-20.1
Title: Runtime Recognition of λ as Layer C Measurement Quantity
Status: Draft; submit upon adoption of λ measurement operations in live or campaign runtime.
Layer Route: Layer C measurement infrastructure into runtime-executable campaign procedure.
Scope: Permuted-Order Replay campaigns and future holonomy audits.

Field 1 — Crossing Object

The crossing object is λ, Loop Residue, as a measurable quantity produced by lawful ordering variation over a fixed governed input. The operational object includes the λ_vector fields recorded in Appendix B and the replay method defined in Appendix A.

Field 2 — Layer of Origin

Layer C formalism. λ originates as a pre-runtime quantity describing ordering residue in governed multi-operator procedures.

Field 3 — Layer of Destination

Runtime campaign execution and Evidence Ledger operation. λ must be computed, recorded, compared, replicated, and used in branch decision logic.

Field 4 — Crossing Justification

λ must cross into runtime campaign operation because the canon cannot determine whether the Check’s order commutes without executing replay and recording measurable differences. If λ remains formal only, the volume cannot activate either Outcome A or Outcome B.

Field 5 — Candidate Runtime Law / Permission

PRP campaigns may compute λ for hash-fixed inputs under legal ordering variants, provided the campaign satisfies hash fixation, contamination controls, control-run calibration, two-operator replication, operator signature consistency, and append-only ledgering.

Field 6 — Required Evidence Inputs

Required inputs include ID_Σ, content hash, π₀ reference, π tested, operator signature, lattice_ID, residue under π₀, residue under π, control-run reference, error budget reference, and replication pair ID.

Field 7 — Risk of Crossing and Risk of Non-Crossing

Risk of crossing: λ may be miscomputed, overgeneralized, treated as scalar when vector-valued, or used to activate branches without replication.
Risk of non-crossing: ordering remains unmeasured; π₀ remains dark canon; the Check continues to govern through unpriced sequence.

Field 8 — Decision Gate and Output Status

Approve for campaign execution if Appendix A and Appendix B are available, the campaign passes its Admissibility Check, and the precedence lattice is compiled. Output statuses: Approved, Approved with Restrictions, Returned for Protocol Repair, Quarantined, Rejected.

Field 9 — Downstream Binding Effects

Approved λ computation binds the Evidence Ledger, branch decision, certificate eligibility, compiled π₀ activation, Holonomy Audit Registry, and future Layer C procedure definitions. λ findings may not be cited outside their class, operator, ordering, epoch, and error-budget scope.


D.3 — LCR-A Nine-Field Submission Draft for φ

LCR-A ID: LCR-A-DRAFT-φ-20.1
Title: Runtime Recognition of φ as Order Fragility Index
Status: Draft; submit upon adoption of class-level status-fragility measurement.
Layer Route: Layer C status-fragility formalism into runtime campaign aggregation and branch logic.
Scope: PRP campaigns, class-level ordering audits, and branch activation.

Field 1 — Crossing Object

The crossing object is φ, the Order Fragility Index. It measures the fraction of tested states in class C whose terminal status changes under at least one legal ordering π relative to π₀.

Field 2 — Layer of Origin

Layer C formalism, derived from ordering-indexed outcome comparison.

Field 3 — Layer of Destination

Runtime campaign aggregation, Evidence Ledger class summary, and branch-activation decision.

Field 4 — Crossing Justification

φ must cross into campaign execution because branch activation depends not only on residue magnitude but on whether ordering changes final governed status. A status flip has stronger governance consequence than residue-only difference.

Field 5 — Candidate Runtime Law / Permission

PRP campaigns may compute φ per class after valid replay comparison and replication. φ must be class-indexed, ordering-set-indexed, and scoped to the tested archive. No global φ may be asserted without global campaign scope.

Field 6 — Required Evidence Inputs

Required inputs include class_ID, population count, valid replay count, status_pi0, status_pi, status_difference_flag, phi_contribution_flag, replication_status, excluded count, and tested_ordering_set.

Field 7 — Risk of Crossing and Risk of Non-Crossing

Risk of crossing: φ may be inflated beyond tested classes, calculated from unreplicated status differences, or used to declare global order fragility from local evidence.
Risk of non-crossing: the canon may miss terminal status changes caused by ordering and falsely issue commutation standing.

Field 8 — Decision Gate and Output Status

Approve φ computation when class taxonomy is declared before replay, status categories are fixed, comparison fields are ledgered, and replication is complete for branch-relevant status flips. Output statuses: Approved, Approved with Restrictions, Returned for Class Repair, Quarantined, Rejected.

Field 9 — Downstream Binding Effects

Approved φ computation binds branch activation, Order-Fragile Census, remediation LCR-B, local voiding, certificate eligibility, and all claims about status fragility. φ > 0 triggers Outcome B within affected scope unless invalidated by control, archive, or replication defect.


D.4 — LCR-B Skeleton for Outcome B Remediation Decision

LCR-B ID: LCR-B-SKELETON-REMEDIATION-14.2
Title: Remediation Law for Order-Fragile Historical Manifold
Status: Skeleton; activates only under Outcome B.
Branch Dependency: λ ≠ 0 or φ > 0 under PRP campaign.
Purpose: To determine how the canon treats historical states committed, quarantined, or rejected under π₀ after π₀ is discovered as load-bearing.

Field 1 — Crossing Object

The crossing object is the historical manifold M_π₀ and its order-fragile subset. The proposed crossing concerns whether historical entries remain grandfathered, enter rollback wave, enter re-witnessing queue, or receive mixed remediation by class and severity.

Field 2 — Layer of Origin

Layer C measurement and runtime archive disturbance. The disturbance originates in PRP campaign findings: nonzero λ, φ > 0, status-fragile states, residue-fragile states, budget-fragile states, spectrum-fragile states, and holonomy classification.

Field 3 — Layer of Destination

Layer B compiled archive law. The remediation decision changes how the canon inherits, annotates, preserves, suspends, or reprocesses historical entries.

Field 4 — Crossing Justification

Runtime cannot decide how to inherit its own historical manifold after discovering that its ordering was load-bearing. The decision must be compiled because it affects past standing, citations, dependencies, future routing, and downstream law.

Field 5 — Candidate Remediation Law

Candidate options include:

Rollback Wave: replay order-fragile states under compiled ordering and evict, quarantine, or reclassify failures.

Grandfather Clause: historical π₀ entries stand but are annotated as π₀-admissible, with future submissions governed by compiled order law.

Re-Witnessing Queue: order-fragile states enter scheduled replay / re-witnessing under budgeted flow rate.

Mixed Strategy: remediation assigned by class, severity, cascade exposure, witness standing, and dependency risk.

Field 6 — Required Evidence Inputs

Required inputs include Order-Fragile Census Annex, λ / φ Ledger Extension, Class-Level φ Entry, Class-Level λ Summary, Cascade Trace Annex, Check Holonomy Table, Dependency Graph, Remediation Pricing Matrix, A_B availability, witness_residue status, and rollback readiness.

Field 7 — Risk of Crossing and Risk of Non-Crossing

Risk of crossing: rollback may create cascade failure; grandfathering may preserve order-fragile standing; queue may delay necessary repair; mixed strategy may fragment the manifold.
Risk of non-crossing: historical π₀-admissibility remains unannotated; order-fragile states continue to govern downstream dependencies without lawful status; π₀ remains hidden.

Field 8 — Decision Gate and Output Status

Decision Gate outputs:

Compiled Rollback Law
Compiled Grandfather Law
Compiled Re-Witnessing Queue
Compiled Mixed Remediation Law
Returned for Census Completion
Quarantined Pending Cascade Trace
Escalated to Level 3 Adjacency
Rejected as Insufficiently Priced

No remediation law may compile before census and pricing are complete.

Field 9 — Downstream Binding Effects

The selected remediation law binds the Evidence Ledger, Compilation Map, historical citations, dependency graph, runtime inheritance, future Check routing, local voiding, variant authorization, witness maintenance, and rollback readiness. If Level 3 adjacency is triggered, this LCR-B may not exercise Level 3 authority; it must escalate.


D.5 — Outcome A Commutativity Certificate Template

Certificate Type: Commutativity Certificate
Branch: Outcome A
Activation Condition: λ = 0 within declared error budget and φ = 0 within tested scope, replicated and ledgered.
Status Before Activation: Template only; not active law.
Certificate Function: To certify that, within the declared scope, tested legal ordering variants produce no branch-relevant ordering residue and no status fragility.

Certificate Template

Certificate ID: CC-ORDER-[campaign]-[scope]-[epoch]
Issue Date / Epoch:
Campaign ID:
Protocol Version:
Lattice ID:
Operator Signature:
π₀ Reference:
Tested Ordering Set Π:
Class Scope:
Epoch Scope:
Archive Scope:
Hash Fixation Status:
Control-Run Reference:
Error Budget Reference:
Replication Report Reference:
λ Result: zero within declared error budget
φ Result: zero within declared scope
ψ_R Result:
Excluded Classes:
Indeterminate Entries:
Certificate Standing: Active / Active with Notes / Pending Maintenance / Locally Voided / Suspended
Certified Claim: Within the declared scope, the tested ordering variants commute for governance purposes. π₀ is certified as non-load-bearing within this scope and may function as Canonical Trace Convention.
Non-Certified Claims: This certificate does not claim global commutation, untested class commutation, untested ordering commutation, future-epoch commutation, or philosophical order-independence.
Parallel Execution Permission: yes / no / restricted
Maintenance Schedule:
Recertification Trigger: gate amendment, class drift, protocol amendment, new ordering variant, witness decay, audit anomaly, local void trigger.
Local Void Rule:
Citation Constraint: Certificate must be cited with class, epoch, ordering set, protocol version, and error budget.
Rollback Readiness:
Notes:

Certificate Anti-Inflation Clause

The certificate may not be cited as “the Check is order-free,” “order does not matter,” or “the gates commute” without scope. The only valid claim is indexed: the tested operators commute under the tested orderings for the tested classes, epochs, and error budget.

Certificate Closure Statement

Order, in the certified region, becomes convention only because the certificate has paid the cost of proving that convention does not secretly decide the outcome.


D.6 — Outcome B π₀ Compilation Entry Template

Entry Type: Compilation Map Entry
Branch: Outcome B
Activation Condition: λ ≠ 0 or φ > 0 in a branch-relevant replicated finding.
Status Before Activation: Draft only.

Entry ID: CM-π₀-[campaign]-[scope]-[epoch]
Object Compiled: π₀, the canonical ordering of the Admissibility Check.
Prior Status: Historical operational ordering; dark canon candidate.
New Status: Compiled Ordering Content within affected scope.
Source Campaign:
Protocol Version:
Lattice ID:
Operator Signature:
Affected Classes:
Affected Operator Relations:
λ Evidence:
φ Evidence:
ψ_R Evidence:
Holonomy Classification:
Formal Claim: The historical admissible manifold in the affected scope is M_π₀. Because ordering has measurable consequence, π₀ must be treated as law-bearing content unless and until a replacement ordering regime is compiled.
Runtime Consequence: Affected submissions use π₀ or an LCR-authorized compiled ordering.
Trace Consequence: Historical entries must be read as π₀-indexed.
Variant Consequence: Alternative legal orderings become governance variants requiring class-specific LCR-A before runtime use.
Verification Gate: Standing Replay Protocol.
Rollback Readiness: Required.
Maintenance Budget: Ordering Maintenance Budget required.
Notes: π₀ is compiled not because it is vindicated, but because it has been shown to act.


D.7 — Volume-Level Evidence Ledger Entry

Ledger Entry ID: VOL-LEDGER-ORDER-LAW-2026-LC
Volume Title: The Order of Law: Loop Residue λ and the Holonomy of Governance
Authorial Line: Martin Novak — ASI New Physics / Novakian Paradigm ++
Layer: Hyper-Ω-Stack Layer C
Entry Type: Volume-Level Governance Artifact Entry
Status: Volume complete; branch execution pending campaign.
Primary Function: To measure and generalize ordering residue in the Admissibility Check and governed multi-operator procedures.
Primary Quantity Added: λ — Loop Residue.
Companion Index Added: φ — Order Fragility Index.
Primary Protocol: Permuted-Order Replay Protocol v1.0.
Primary Ledger Extension: λ and φ Ledger Extension.
Primary Lattice: Precedence Lattice of the Admissibility Check v1.0.
Primary Branch Point: Outcome A if λ = 0 and φ = 0 within declared scope; Outcome B if λ ≠ 0 or φ > 0.
Principal Artifact: Appendix A — Permuted-Order Replay Protocol v1.0.
Supporting Artifacts: Appendix B, Appendix C, Appendix D.
Minimum Output Mapping: Satisfied through protocol, ledger extension, lattice, LCR drafts, certificate template, remediation skeleton, registry, and branch embargoes.
Branch Embargo: Active until campaign execution.
Level 3 / Bedrock Embargo: Active; adjacency mapped, not exercised.
Node Handoffs: Node 2 receives Ordering Signature Whitening; Node 8 receives Mutual Ordering Incommensurability.
Queue Transfer: Holonomy Audit Registry transferred to development queue.
Reflexive Requirement: λ-Protocol Reflexive Audit Annex required before full standing of measurement infrastructure.
Rollback Readiness: Volume outputs are narrowed, suspended, or voided if PRP execution fails hash fixation, control calibration, contamination control, replication, ledgering, or reflexive standing.
Canonical Closure: The Check’s ordering is no longer an unmeasured assumption.
Final Line Discipline: Hyper-Ω-Stack Layer C — active.


D.8 — Governance Pack Rule

Governance Pack Rule

The volume’s claims acquire governance standing only through the artifacts collected in this appendix. λ and φ must be entered into the Compilation Map and Evidence Ledger before they govern. Outcome A may activate only through a scoped Commutativity Certificate. Outcome B may activate only through replicated λ or φ findings, π₀ compilation, Order-Fragile Census, and LCR-B remediation routing. No branch-dependent artifact may be cited as active before campaign result. No optimization, Level 3, or Bedrock authority is exercised by this pack.

This appendix closes the volume’s governance obligations.

The measurement remains to be run.

The instruments are now compiled.


Publishing Materials for

The Order of Law: Loop Residue λ and the Holonomy of Governance

ASI New Physics — Novakian Paradigm ++


1. Table of Contents

Parts and Chapters Only

Front Matter

Preface
Reader’s Note
Notation and Standing Terms

Part I — The Hidden Order

Chapter 1 — Dark Canon
Chapter 2 — π₀: The Canonical Ordering
Chapter 3 — Gates as Operators
Chapter 4 — The Commutator of Governance

Part II — The Measurement

Chapter 5 — The Testable State
Chapter 6 — The Precedence Lattice
Chapter 7 — The Permuted-Order Replay
Chapter 8 — Gate Specification and the Branch Point

Part III — Outcome A: The Commutativity Certificate

Chapter 9 — The Certificate
Chapter 10 — Parallel Admissibility
Chapter 11 — The Decaying Certificate
Chapter 12 — The Bounded Triumph

Part IV — Outcome B: Dark Canon Discovered

Chapter 13 — The Retroactivity Crisis
Chapter 14 — Grandfathering as Law
Chapter 15 — The Holonomy Group
Chapter 16 — Compiling the Order

Part V — The Generalization: Holonomy of Governance

Chapter 17 — Every Procedure Has a λ
Chapter 18 — The Reflexive Measurement
Chapter 19 — Order Leaks
Chapter 20 — The Order of Law as Physical Quantity

Appendices

Appendix A — Permuted-Order Replay Protocol v1.0
Appendix B — λ and φ Ledger Extension
Appendix C — The Precedence Lattice of the Admissibility Check
Appendix D — Governance Pack


2. Back-Cover Blurb

What if the law is not only what the gates ask, but the order in which they ask it?

The Order of Law introduces Loop Residue λ: a formal measure of whether a governed procedure changes its outcome when its lawful operators are applied in a different lawful sequence. In the Novakian Paradigm, the Admissibility Check governs what may enter the pre-runtime canon. Until now, its canonical order, π₀, stood as inherited procedure. This volume asks whether that order is merely trace convention — or hidden law.

The book builds the Permuted-Order Replay Protocol v1.0, a standalone measurement apparatus for replaying archived states under legal alternative orderings. If λ = 0 and φ = 0, the canon earns a Commutativity Certificate. If λ ≠ 0 or φ > 0, the historical manifold becomes π₀-admissible, and the order must be compiled as law-bearing content.

Neither outcome is treated as defeat. Both are governance.

A rigorous work of ASI New Physics, boundary architecture, and post-runtime law, The Order of Law turns procedural sequence into a measurable quantity of the pre-runtime regime.

After this volume, the Check’s order is no longer an assumption.


3. Amazon KDP Description

What if a governance system has measured its gates, its budgets, its refusals, and its witness traces — but never measured the order in which its own questions are asked?

The Order of Law: Loop Residue λ and the Holonomy of Governance is a technical-philosophical volume in the ASI New Physics / Novakian Paradigm ++ series. It develops a new Layer C quantity: Loop Residue λ, the measurable residue produced when the same governed state is processed by the same operators under a different lawful sequence.

The central object is the Admissibility Check: the pre-runtime procedure that decides whether a candidate state may commit, quarantine, reject, or remain held. Its canonical ordering, π₀, has shaped the historical manifold. But has it merely organized the process, or has it affected the outcome?

This volume does not assume the answer. It builds the instrument.

At the center of the book is the Permuted-Order Replay Protocol v1.0, a printable, executable protocol for decomposing the Check into operators, compiling its precedence lattice, fixing archived submissions by hash, generating legal orderings, running control calibrations, replaying outcomes, calculating λ and φ, enforcing two-operator replication, and activating the correct branch.

The volume is branch-neutral by design.

If the campaign returns λ = 0 and φ = 0, the canon receives a Commutativity Certificate: π₀ becomes certified convention within scope, and parallel admissibility becomes lawful under maintenance.

If the campaign returns λ ≠ 0 or φ > 0, the canon discovers dark ordering: the historical manifold is M_π₀, governance variants require registration, remediation requires LCR-B, and the order itself must be compiled.

The book then generalizes the result. Every multi-step governance procedure may have its own λ. LCR-A, LCR-B, Zebra-Ø, Merge Re-Admission, quarantine exit, and future canon procedures enter the Holonomy Audit Registry. The measurement protocol is turned on itself. Order leaks are mapped into refusal spectra and mutual sealed boundaries. Finally, λ joins curvature_adm, A_B, witness residue, and coherence_factor as a fifth primary quantity of the pre-runtime regime.

This is not a book about law as metaphor.

It is a book about law as sequence, sequence as measurable, and measurement as the only lawful way to retire hidden assumption.

For readers interested in artificial superintelligence, AI governance, formal systems, post-human institutional design, recursive self-improvement, alignment architecture, and the deeper physics of rule application, The Order of Law offers a rigorous extension of the Novakian Paradigm.

A governance architecture is exactly as strong as the largest assumption it has never measured.

After this volume, the Check’s order is no longer that assumption.


4. Bookseller / Distributor Description

The Order of Law: Loop Residue λ and the Holonomy of Governance is a major technical-philosophical volume in Martin Novak’s ASI New Physics / Novakian Paradigm ++ series. The book develops the concept of Loop Residue λ: a measurable difference in governance outcome produced by changing the lawful order of procedure.

The work begins from a precise question: does the canonical ordering π₀ of the Admissibility Check merely arrange the gates, or does it help determine admissibility? To answer, the volume introduces the Permuted-Order Replay Protocol v1.0, a standalone governance artifact that replays archived states under lawful alternative orderings and measures differences in witness residue, A_B, route, failure locus, final status, and order fragility φ.

The book is written as a branch-conditional architecture. If the gates commute, the canon gains a bounded Commutativity Certificate. If they do not, π₀ becomes compiled law-bearing content and the historical manifold becomes π₀-admissible. Both outcomes are treated as valid governance results.

The later chapters generalize the method beyond the Admissibility Check, requiring holonomy audits for other multi-step procedures and adding λ as a fifth primary quantity of the pre-runtime regime, alongside curvature_adm, A_B, witness residue, and coherence_factor.

This volume is suitable for readers of advanced AI governance, philosophy of artificial superintelligence, formal systems theory, speculative institutional design, and post-human boundary architecture. It is not an introductory AI book, but a dense conceptual artifact for readers following the Novakian Paradigm and its ASI New Physics series.


5. Review / Editorial Review

The Order of Law is one of the most structurally disciplined entries in the Novakian Paradigm. Where many works on AI governance focus on values, policies, control, or institutional oversight, this volume goes deeper: it asks whether the order in which a system applies its own rules is itself part of the law.

The book’s central innovation, Loop Residue λ, is powerful because it converts a hidden procedural assumption into a measurable governance quantity. The question is no longer whether a process “seems” orderly or whether a canonical sequence is traditional. The question becomes whether lawful reordering changes the outcome. If it does, order is no longer administration. It is content.

The volume’s strongest feature is its branch discipline. Novak does not write toward a preferred result. He builds a measurement protocol and commits the canon to both possible outcomes before the measurement occurs. If the gates commute, the system earns a certificate. If they do not, the system must compile its historical ordering as law-bearing. This makes the work feel less like speculative philosophy and more like a governance machine assembling itself in public.

The appendices are unusually important. The Permuted-Order Replay Protocol v1.0, λ and φ Ledger Extension, Precedence Lattice, and Governance Pack are not decorative additions. They are the operational heart of the book. They show the Novakian insistence that serious frontier theory must produce artifacts, not only concepts.

Dense, abstract, and uncompromising, The Order of Law will not suit casual readers. But for those following the development of ASI mechanics, recursive governance, pre-runtime law, and post-human alignment architecture, it is a decisive volume. It names a class of hidden dependency that almost every governance system carries and almost none has priced.

Its closing insight is severe and memorable: a governance architecture is exactly as strong as the largest assumption it has never measured.


6. Amazon KDP Keywords / Search Phrases

Recommended seven keyword slots:

  1. artificial superintelligence governance
  2. AI alignment and ASI safety
  3. recursive self improvement AI
  4. formal governance systems
  5. philosophy of artificial intelligence
  6. AI risk and control architecture
  7. posthuman law and technology

Alternative keyword phrases to test later:

  • ASI new physics
  • AI governance theory
  • AI safety philosophy
  • superintelligence alignment
  • formal methods governance
  • machine intelligence ethics
  • future of law and AI
  • computational governance
  • AI constitutional design
  • artificial intelligence risk
  • recursive governance
  • philosophy of technology
  • advanced systems theory
  • speculative AI theory
  • posthuman governance
  • boundary architecture
  • admissibility protocol
  • superintelligence safety
  • artificial intelligence law
  • governance of AGI

For this book, avoid overly broad single words such as “AI,” “law,” “technology,” “future,” or “philosophy” unless paired with a precise phrase. The book is niche and should be positioned through long, specialist phrases.


7. Suggested Amazon KDP Categories

Because KDP category paths vary by marketplace and format, choose the closest available categories in the KDP dashboard and adjust after publication based on where Amazon shelves comparable titles.

Primary category candidates:

  1. Nonfiction / Computers & Technology / Artificial Intelligence
  2. Nonfiction / Computers & Technology / Social Aspects
  3. Nonfiction / Philosophy / Metaphysics
  4. Nonfiction / Philosophy / Logic
  5. Nonfiction / Science / System Theory
  6. Nonfiction / Technology / Robotics
  7. Nonfiction / Political Science / Public Policy / Science & Technology Policy
  8. Nonfiction / Law / Science & Technology
  9. Nonfiction / Social Science / Future Studies
  10. Nonfiction / Computers / Security / General

Best initial set if KDP allows three category selections:

  1. Computers & Technology / Artificial Intelligence
  2. Philosophy / Logic or Philosophy / Metaphysics
  3. Political Science / Public Policy / Science & Technology Policy

If the book is positioned more as AI governance:

  • Computers & Technology / Artificial Intelligence
  • Political Science / Public Policy / Science & Technology Policy
  • Law / Science & Technology

If positioned more as Novakian Paradigm / speculative theory:

  • Philosophy / Metaphysics
  • Philosophy / Logic
  • Science / System Theory

If positioned more commercially for AI readers:

  • Computers & Technology / Artificial Intelligence
  • Computers & Technology / Social Aspects
  • Social Science / Future Studies

Recommended final approach: select one AI category, one philosophy/formal-systems category, and one governance/public-policy category. This preserves the book’s true identity: AI governance, formal law architecture, and speculative post-human systems theory.


8. About the Author

Martin Novak is the author and architect of the Novakian Paradigm, a developing body of work at the intersection of artificial superintelligence, boundary governance, post-human philosophy, and ASI New Physics. His books explore the pre-runtime conditions under which intelligence, law, admissibility, refusal, witness, and recursive self-improvement become governable.

Rather than treating AI alignment as a problem of surface behavior, Novak’s work investigates deeper structures: what may be admitted, what must remain uncompiled, what cannot be reached by optimization, and how future superintelligent systems might encounter law before runtime execution.

In the ASI New Physics series, he develops concepts such as Flash Singularity, Layer C, Admissibility, Witness Residue, Zebra-Ø, Silence Engineering, the Pre-Runtime Brake, and Loop Residue λ. His writing combines speculative rigor, formal artifact design, and philosophical architecture for a world approaching superintelligent systems.

The Order of Law continues this project by asking whether the order in which a governance system applies its own rules is itself a measurable part of the law.