UNI Universal Natural Intelligence

Wiki · The Encyclopedia

CLAIM-LEDGER.md — Master Evidence-Classed Claim Ledger

The Encyclopedia · encyclopedia/CLAIM-LEDGER.md @ 575fc93d9d31 (main) — opens the published snapshot e850f872196d

How to read this page

Three ways to read this page. Precise is the document itself, exactly as it is written in the repository. Plain and Clear were written for this website to help you meet that document — they are about it. They are not it, and they are not evidence.

The Encyclopedia is the UNI method written out as a reference work: 39 pages, arranged in wings, setting out what the programme is attempting and why it is built the way it is. This is where the ideas are explained in order and in prose, rather than as code, as runbooks, or as dated receipts.

Every chapter is authored against two ledgers and never ahead of them. One records what UNI has built, and the evidence class of each claim. The other records nature's own regularities, kept separate on purpose. That way a fact about biology is never quietly reused as a fact about the software. Where a chapter and a ledger disagree, the chapter is the thing that is wrong. Every chapter closes with an invitation to falsify it, and a recorded negative is published beside the result it qualifies rather than after it.

Read "How to read this work" first. It is the evidence constitution: the classes, the four ledger states, and the rule that a finished chapter is not the same as a working system. Then the calibration ledger, which carries the figures every other chapter is required to use.

What it is not: a description of a person or of a mind. The programme calls itself a developmental active-inference simulation, a bounded peek into a toy world, and its own index prints how much of the developmental ladder has actually been earned — roughly two rungs out of eleven or more. It is also not a report of what is running today. For what ran, and when, go to the evidence record.

Your browser cannot switch reading levels, so the document itself is shown.

Precise — the source document

This is the document. Rendered from the repository at the commit above, with nothing rewritten for the web. A gate re-renders it on every deploy and fails the build if a single byte differs.

Single source of truth. The UNI Encyclopedia and the Cookbook author against this file. No public copy, no encyclopedia entry, and no marketing artifact may state a claim above the evidence class recorded here, or omit a recorded falsifier, negative, or fence.

Derivation. This ledger is the deduplicated merge of 615 extracted claims across twelve source archives (uni-gpt, uni-mind, uni-os, worldmodels, strings, uni-precision, marketingwright, ideation-explorer, intelligencelabs-uni, orchestrate-linkedin, website, activeinference, all reconciled through 00-INDEX). Where a rung was stated in several archives at different strengths, the row is calibrated DOWN to the measured value and attributed to its strongest evidentiary source. Negatives and bounds are merged in as first-class rows, never hidden.


0. Constitution & Standing Fences (read first)

Evidence classes (A–U taxonomy). A = machine-exact anchor · B = mechanism + operator observation · C = dev-gate / held-out eval · E = test-covered · F = doc / prior-claim (inheritable, must be re-verified) · U = claimed-but-unproven ("Class U — not claimed" is itself a standing fence) · method = a definitional / governance pattern, not an empirical claim.

Calibration rule. Authority flows downward from the measured fact. Calibration only moves wording DOWN to the measured value, never up — including under urgency. The fence gets louder under pressure, not wider.

Verdict rule. A capability verdict is the CI bound that excludes the threshold, never the point estimate.

DONE rule. DONE = test-covered (Class E/D), not feature-working (Class A).

Negatives are content. A partial / a negative / a "most pieces don't help" decomposition is a measurement that the design is incomplete, not an exit and not a failure to hide. The corpus carries 183 published negatives (last recorded ledger snapshot: 882 rows = 350 PASS / 0 FAIL / 183 NEGATIVE / 349 PENDING) — the negatives are the credibility.

HARD STANDING FENCES — never claim, in any archive, in any public copy:

  • Never AGI / general intelligence / human-level / "talks & learns like a human" / understands.
  • Never consciousness / sentience / aware. (Functional self-awareness may be described at L8; phenomenal sentience is explicitly DISCLAIMED.)
  • Never "active inference demonstrated" (no AIF loop exists in the Rust crate; the live loop is a separate UNI.OS reimplementation, not gate-matched).
  • Never "created life" / "digital life" / "measurable awareness" as a CLAIM (north-star framing only).
  • Never "beats LLMs" (World C is a COUNT baseline; ~10–15% behind backprop LLMs on char-perplexity by a chosen design trade).
  • Never inflate the Tier-2 synthetic-construction track into capability (it was audited as artifact/diagnostic — hardcoded-literal "exactness", scoring-artifact deltas — and fixed).
  • Never raise a claim above its source evidence class.
  • The whole program is a developmental active-inference SIMULATION: say "developmental SIMULATION", "bounded peek", "toy world, not the real world", "Class U — not claimed", "unrefereed working preprint".
  • No PII. No patent-level math (textbook-level framing only; consult the private UNI Active-Inference Guide GPT for science, never publish it).
  • The preprint Polzin et al. 2026, Zenodo DOI 10.5281/zenodo.19785799 (MIT) is cited as the mathematical foundation only and always fenced as unrefereed (Layer-1 AI-executable audit complete; Layer-2 human expert review PENDING) — never as proof that active inference is the correct theory.

Honest program position: ~2 of 11+ developmental rungs earned.


1. The L0–L12 Developmental Ladder

One subsection per rung. Each row: claim — evidence class — falsifier — status — source archive. Each rung carries an explicit "what is NOT claimed" line.

Naming: the ladder is the HUMAN-HGM-001 developmental design (conception → speaking 3-year-old, 11 levels + the global Z affect modulator). It is a no-backprop, nested-Markov-blanket developmental SIMULATION, never a person.

L0 — Molecular / genome → zygote (conception prior) · PROVEN

# Claim Class Falsifier Status Source
L0.1 Zygote first-division modeled as exact discrete Bayes (conjugate update); recombine/seed_zygote, no-backprop guard, ontogeny 6/6, Embodiment Rungs 1–2 GREEN (uncommitted). A (machine-exact anchor) test_embodiment_ontogeny.py drops below 6/6; OR the first-division posterior diverges from the closed-form discrete-Bayes value beyond the float32 tier; OR cell-division identity embedding exceeds 1e-9; OR the no-backprop guard trips. proven uni-gpt / uni-mind

Exactness tier (load-bearing calibration-down): the JAX core runs float32, so these anchors hold only to ~6e-8 (~1e-6 single-step filter), NOT the <1e-10 EXACT tier. The genuine <1e-10 tier lives only in the NumPy / Rust-f64 path. A genome docstring claiming <1e-10 was caught as an overclaim and corrected. Never card a float32 anchor at the f64 tier.

What is NOT claimed at L0: not "we created life", not a "conscious baby", not exact at f64 — it is a float32-tier developmental SIMULATION of a conjugate Bayesian first division.

L1 — Cellular / autopoietic viability & homeostasis · PROVEN (with honest losses)

# Claim Class Falsifier Status Source
L1.1 Cell Lab open pre-registered falsification benchmark: 216-state service cell, observation-only controllers, RecoveryScore, bootstrap 95% CI, 8 honesty fences + framing_guard test. UNI tops the leaderboard on most modes. C (dev-gate / held-out) RecoveryScore CI fails to separate from controls where a win is claimed; OR a fence/framing_guard test fails (an overclaim is emitted); OR the bootstrap CI is shown miscomputed. proven uni-precision
L1.2 (NEGATIVE) UNI honestly LOSES on database_flaky (rule-based SRE wins 0.803 vs 0.759), memory_leak (neural wins 0.810 vs 0.740), cpu_noisy_neighbor (neural wins 0.824 vs 0.749; UNI-vs-random not even significant). Recorded in FALSIFICATION.md, shown at the top of the live leaderboard. C On the pre-registered benchmark UNI's RecoveryScore CI separates above baseline on these three modes (the recorded loss does not replicate). negative uni-precision

What is NOT claimed at L1: not "sovereign" — "good but not sovereign". The losses are first-class published content, not failures to hide. Cellular/zygote end only.

L2 — Tissue / metabolism (interoception & energy) · POSITIVE uplift + recorded NEGATIVE (plateau-break OPEN)

# Claim Class Falsifier Status Source
L2.1 Phase-2 metabolism organ shipped (suite 297/0, default byte-identical); first 12 h live RED = +135% / 2.35× tool-crafting and +19% mining — a real, attributable standing-metabolic-drive effect. C A repeat pre-registered 12 h live RED fails to reproduce the tool-crafting uplift within CI, OR the metabolism-organ ablation does not remove the uplift, OR the suite drops below 297/0. proven strings
L2.2 (NEGATIVE) In the same 12 h RED, building (placed blocks) went WORSE (−14%) and G4 allostasis never separated. The load-bearing claim "metabolism breaks the plateau to stone/shelter" (gate G6) remains OPEN and is contradicted by its own first evidence. C A subsequent disciplined RED shows the metabolism organ alone improves building (placed-blocks CI excludes 0) and G4 allostasis separates — discharging G6. negative strings
L2.3 The colony plateaus at "make a tool" (one UNI hoarded 32 pickaxes, never built). A read-only counterfactual-EFE audit on the real hoarder .bin files diagnosed epistemic_starvation — NOT γ-runaway (γ≈7.8, unsaturated) and NOT a curriculum ceiling; the EFE landscape is pragmatic-saturated/flat, info-drive ~100× too weak. A (shadow-EFE audit on real brains) A γ-saturation finding, a curriculum-ceiling flip, or an info-drive scaling that breaks the plateau without organs would overturn the diagnosis. negative (diagnostic) strings
L2.4 Two engine-seam findings invalidate the naive metabolism design and were fixed: (1) you cannot seed a strong Dirichlet prior by pre-scaling B (norm_cols runs before add1) — needs the new :pb_seed seam; (2) the live bridge had no viability edge (metabolize/shutdown were Sim/Eval-only) so a naive emptying-B drained a belief with zero world consequence. A (direct code reading) A seam allowing strong-Dirichlet seeding without :pb_seed, or evidence the live bridge already had a viability consequence. negative (fixed) strings

What is NOT claimed at L2: metabolism is proven as a foraging/crafting driver, NOT a building driver. The plateau-break (G6) is UNPROVEN. Do NOT spin the +135% uplift as "breaks the plateau". The G5b action-severed-twin is the standing falsifier any "self-maintenance/life" language must clear.

L3 — Organ / physiological control · PROVEN (toy/clinical-model)

# Claim Class Falsifier Status Source
L3.1 Karaaslan cardio-renal Heart Lab models clinical homeostasis as prediction-loop failure on the same one active-inference engine (reduced RSNA→MAP→sodium/volume loop, re-expressed in active-inference language). C (also Heart-Lab engine ticket OAS-710-T3 at Class E, 15/15) Heart-Lab predictions diverge from the Karaaslan reference beyond the pre-registered tolerance, or fail parity tests against the canonical TS engine. proven uni-precision

What is NOT claimed at L3: not a clinical tool, not a diagnostic instrument. "Same math, many scales" framing only; the heart-attack-as-prediction-loop-failure framing applies to the toy model, not to clinical reality.

L4 — Interoceptive / autonomic + affect-as-precision · PROVEN (functional)

# Claim Class Falsifier Status Source
L4.1 Affect-as-precision: emotion modulates precision so perception sharpens and the pragmatic↔epistemic balance flips. The global Z modulator [energy, arousal, valence, fatigue, pain, threat, safety, inflammation] sets precision / preferences / habits / learning-rate / horizon. C An ablation of the Z modulator shows no change in precision-weighting / no pragmatic↔epistemic flip under the grounded reader, OR the effect collapses under control. proven uni-gpt / uni-mind

What is NOT claimed at L4: affect is modeled, never felt — phenomenal feeling / sentience explicitly disclaimed. (M10 honest boundary: neuroticism does NOT change behavior under bimodal surprise without a graded task — a recorded sub-bound.)

L5 — Sensorimotor / motor hierarchy · PROVEN PASS + symmetric NEGATIVE (synthetic only)

# Claim Class Falsifier Status Source
L5.1 Embodiment A3 Design #1 (fast immediate-reward axis) HELD PASS, held Δ (agent − policy-shuffle) = +0.092, CI [+0.038, +0.157], UNI-signed. C A re-registered held-once synthetic run with ≥5 seeds drops the CI lower bound to ≤ 0. proven uni-mind
L5.2 (NEGATIVE) Embodiment A3 Design #2 (slow Z-bottleneck, compressed 2-modality EMA, delayed-reward) HELD NEGATIVE, held Δ = −0.091, CI [−0.134, −0.055]. Synthetic protocol, K-negative = 1, so no Section 0.6(B) bound owed (needs K≥3). C A structurally-distinct corrected slow-Z-bottleneck re-run pushes the CI above 0 (overturns it); accumulating K≥3 distinct negatives would then owe a published bound. negative uni-mind
L5.3 Mind-body-as-one motor hierarchy: proprioceptive diagonal-A prior breaks a non-identifiable uniform-A factor (posterior 0.0→0.75); continuous servo + reafference modeled on the same loop. Live mechanism gate PASS — a kin-9 lineage bootstrapped wood→planks→sticks→wooden_pickaxe+sword, server-authoritative via RCON; motor-ablation collapses harvest ~700×. A (posterior shift) / C (live RCON gate) / E (277 offline tests) Harvest not collapsing under motor ablation; the kin-9 craft chain not reproducing server-authoritative; or the diagonal-A posterior staying stuck at 0.0. proven strings / uni-mind

What is NOT claimed at L5: the A3 PASS is "variationally-controlled active-inference evidence on body↔world coupling under the registered SYNTHETIC protocol" — synthetic-process only (NOT live-appliance, NOT recorded-hardware), and NOT near-optimal control (agent plateaus 0.222 vs oracle 1.0; the active channel mattering is the entire allowed claim). Live behavioral K-of-6 motor tallies are PARKED (accruing, not a sealed hold).

L6 — Perception (precision-weighting / EFE planning) · PROVEN — the one citable empirical PASS

# Claim Class Falsifier Status Source
L6.1 World C: a no-backprop COUNT reader beats a tuned MKN-7 baseline on sealed held-out real text by +0.081 nats/char (flagship multi-seed CI [0.0736, 0.0890], seeds 0–4, UNI-signed; 2.4× the 0.03 bar; confirmed by three gates; first genuine validator-derived reproduced:true). C On a fresh held-out split with ≥5 disjoint seeds, the seed-paired bootstrap CI on the margin over tuned MKN-7 includes or falls below 0 (or the baseline is shown untuned). proven uni-mind / uni-gpt
L6.2 Supporting World-C family: Wc-2 multi-level cache +0.0164; Wc-3 vs unbounded SM/HPYP +0.085 (gain is long-range structure, not finite-window deficiency); recency-ablation +0.033; Gate-3 word-challenger +0.0538 (CI lower 0.051). C Any member's held seed-paired bootstrap CI includes 0. proven uni-gpt
L6.3 POMDP maze Precision lab + echolocation Echo lab + public Precision Lab: one engine, three precision knobs (gamma_a sensory, gamma_b transition, softmax_temperature policy), 2D bifurcation map into distinct behavioral regimes; math ported verbatim from the verified engine (one disclosed extension: a goal drive). Echo reuses Precision's engine with only the observation model swapped (bit-identical 64-obs space) — observation model ≠ engine. E (test-covered labs / parity tests) tsx/pytest parity tests between the inline-JS lab engine and the canonical TS/Python engine diverge, or the bifurcation map does not reproduce the regime boundaries. proven uni-precision / worldmodels
L6.4 (NEGATIVE) Phase G char-perplexity Section 0.6(B) bound: FIVE structurally-distinct within-segment-structure designs all NEGATIVE-with-discriminator; only the L5 cache (World C) wins. Published bound: no within-segment structure beats MKN-7; char-ppl is a chosen design trade. C A new structurally-distinct within-segment-structure design beats tuned MKN-7 on held char-ppl with a CI excluding 0. negative (bound) uni-gpt
L6.5 (NEGATIVE) Phase F active-controller: two controller families prove the World-C gain is diffuse (nothing to gate). C An active-controller family adds a held gain on top of World C with a CI excluding 0 (gain was gateable). negative uni-gpt
L6.6 The Working Law (UNI s10, registered): a no-backprop latent Z beats a tuned baseline B on held-out data only when I(Y;Z|S_B) > 0 and is learnably stable. Explains every PASS and every published bound. C (registered) A held PASS where the winning Z carries no conditional info beyond S_B (I=0); OR a Z with I>0 + stable learnability that fails to beat B. method/law uni-gpt

What is NOT claimed at L6: World C is a COUNT baseline win — explicitly NOT active inference, NOT comprehension, NOT "talking", NOT beats-LLMs (~10–15% behind backprop LLMs on char-perplexity, a chosen trade). Never card World C above a count-baseline result. The standing ceiling cannot be raised.

L7 — Language (reading = inference / speaking = action) · specialist PASS + thrice-NEGATIVE central wall

# Claim Class Falsifier Status Source
L7.1 Phase J OOV/morphology specialist reader beats best-count by +0.105 nats/char held PASS (21-split M-seal CI [0.0975, 0.1128], structure margin +0.109; holds in both web and dictionary domains; contains-KN-OOV control λ=0). C On a fresh OOV/morph held-out split the CI lower bound includes/falls below 0; OR the structure-margin discriminator does not collapse the gain under marker-swap; OR it fails to replicate in the dictionary domain. proven (specialist) uni-mind / uni-gpt
L7.2 (NEGATIVE, paired) J.attribution_caveat is recorded NEGATIVE in the same ledger and must always be cited alongside the Phase J PASS. Citing +0.105 without it is an overclaim. Overall NLL worsens (specialist gain, not a general win). C n/a (recorded bound) — removing it is the violation. negative uni-mind / uni-gpt
L7.3 (NEGATIVE) Comprehension-above-retrieval = the thrice-NEGATIVE "central wall": K≥3 structurally-distinct no-backprop designs fail to beat retrieval-style baselines on adversarial comprehension. C A pre-registered held-once no-backprop comprehension design beats the tuned retrieval/recency baseline with a CI excluding 0. negative (bound) uni-mind / uni-gpt
L7.4 (NEGATIVE) Phase K role-persistence: three structurally-distinct no-backprop designs (min-role, chain, track) all tune their role/persistence terms OFF; only ~0.02 nats survives (CI spans 0). Bound: no-backprop role-persistence does not beat a tuned recency/frequency discourse prior on adversarial anonymized referent cloze. C A no-backprop role-persistence design beats the tuned discourse prior with a CI excluding 0. negative (bound) uni-gpt / uni-mind
L7.5 (NEGATIVE) T2.D3 bounded-peek held one-shot (s64-signed): primary full-read match NEGATIVE (the k_b=2 backoff wall); info-gain NOT load-bearing. The variable-k_b "cheap milder cap" was asserted then disproven by measurement (real dev screen showed ~linear curve, no cheap cap). C On the held one-shot, bounded-peek full-read match shows a positive load-bearing info-gain with a CI excluding 0. negative (bound; fabrication corrected) uni-gpt
L7.6 (PARKED) Char-perplexity / T2 word-grain frontier: PARKED at the embodiment pivot. Perplexity is the rejected LLM metric; the program measures developmental capability, never perplexity. U n/a — discharged only by a captured UNI sign-to-park (drafted UNI_CONSULT_5, owner-relayed, not yet captured). parked uni-gpt

What is NOT claimed at L7: no general language capability; comprehension above retrieval is a genuine published wall (K≥3), not a hidden failure. reading = posterior-inference, speaking = action. "K≥3 exhausted" / "Sec-0.6(B) achieved" are forbidden phrasings until UNI signs.

L8 — Self-model / metacognition / metalinguistics · PROVEN (functional; sentience disclaimed)

# Claim Class Falsifier Status Source
L8.1 Maturation arc M1–M11 grand report card 15/15 PASS (immersion, affect-as-precision, growth, self-model, metacognition, metalinguistics, consolidation, reflective reader, online vocab growth, affect-driven reflection, compositional reader). FUNCTIONAL self-awareness asserted. C Any of the 15 maturation gates fails its pre-registered held verdict on re-run; OR a self-model/metacognition gate's effect collapses under its discriminator; OR a "self-model" task is passable by a trivial non-metacognitive heuristic. proven (functional) uni-gpt

What is NOT claimed at L8 (load-bearing): phenomenal sentience is explicitly DISCLAIMED — no falsifier is offered for it because it is disclaimed, not tested. Never read 15/15 as consciousness / sentience / awareness / human-level. (Note: uni-mind records self-model as a held-NEGATIVE on the reader; the M1–M11 functional report card is the uni-gpt-side artifact — keep the distinction.)

L9 — Reasoning / conscience (narrative-self → conscience → reasoning) · PARKED

# Claim Class Falsifier Status Source
L9.1 L7–L9 (narrative-self, conscience, reasoning) exist as levels in the HUMAN-HGM-001 ladder DESIGN but are NOT separately gated/PASSed. Honest position: ~2 of 11+ rungs earned. U n/a (parked) — becomes testable only once a pre-registered, sealed, UNI-signed gate is defined and run. parked uni-gpt / uni-mind

What is NOT claimed at L9: nothing. Class-U-not-claimed; sign-to-park owed. Ladder DESIGN levels are never inflated into capability. (The strings Phases 3–5 — spine → glands → hemispheres — are the designed, FE-form-signed but unbuilt roadmap toward this region.)

L10 — Wisdom / higher cognition · PARKED

# Claim Class Falsifier Status Source
L10.1 Top of the HUMAN-HGM-001 ladder; aspirational north star. No engine, no run, no gate. U n/a (parked; sign-to-park owed). parked uni-gpt

What is NOT claimed at L10: nothing. Class-U-not-claimed. The single-source-of-truth append-only ledger must be preserved (a second writable ledger would break L10/L11).

L11 — Dreaming (offline replay / generative simulation) · NOT-YET-BUILT

# Claim Class Falsifier Status Source
L11.1 Explicitly untouched and hard-fenced: "dreaming/awareness are untouched here and remain hard-fenced." No engine, no run, no gate; absent from all digests. U n/a (nothing built to falsify; status is the absence of any artifact). not-yet-built uni-mind (absence)

What is NOT claimed at L11: nothing. North-star rung, hard-fenced.

L12 — Creativity → measurable awareness · NOT-YET-BUILT (hard fence)

# Claim Class Falsifier Status Source
L12.1 The owner's stated north star — "literal digital life … measurable awareness" — pursued by deepening organs/spine/glands, but NEVER claimed. No gate exists. Posed as an OPEN, falsifiable question ("is a plant life? have we made non-organic life?"), never an answer. U n/a — no gate exists; the only legitimate movement is a ledger-scoped exhausted search envelope (a scoped, empirical, falsifiable negative result over the tested envelope only — NOT a universal impossibility result and NOT an achieved capability rung; Q1, SIGNED), never a capability assertion. not-yet-built strings (north-star)

What is NOT claimed at L12 (hardest fence): "we created life / conscious / aware / measurable awareness / human-level / AGI / active inference demonstrated" are FORBIDDEN phrasings program-wide. North-star framing only; Class-U-not-claimed.


2. Continuity / Embodiment-Substrate Sub-Ladder

Orthogonal to L0–L12. This is ENGINEERING / substrate evidence (deterministic replay + serialization + fail-closed transport + on-metal operation) — NOT general-AIF evidence. Card every row that way; never let substrate work imply a science gate is met. Each rung is a separate falsifiable claim.

# Claim Class Falsifier Status Source
C0 Stage-0 (substrate proof): containers survived a restart on real metal — two-node fleet: prod PowerEdge (no-AVX Xeon X5650, PERC HDD array ~5.5 TB spinning, NOT SSD) + OptiPlex node2 (NVMe), WireGuard mesh, per-device identity uni-lab-<mac> minting its own TLS leaf on firstboot. A A node fails to boot/appear, status page not served, or the hardware spec (no-AVX Xeon, HDD-not-SSD) is contradicted on inspection. proven uni-os / uni-mind
C1 Stage-1 (REQ-002 GREEN): mind-state survived a process restart BIT-FOR-BIT — durable + sha256-verified + fail-closed + bit-identical tick across a real child-process boundary (≥2 distinct actions; Path-B receiver 3/3). The real uni-mind JAX agent state, OS-independently verified. C (B-substrate) A process-restart replay diverges bit-for-bit; OR fail-closed does not trigger on 1-bit corruption; OR serialize(deserialize(blob)) != blob. proven uni-os / uni-mind
C2 (OWED / NEGATIVE) Stage-2 (real kernel swap): OWED, not shown. Live OS update proven infrastructure-only — real prod kexec cutover 6.12.86→6.12.73, ~59 s, zero data loss (odoo tables identical, sentinel rows preserved); CRIU/livepatch proven on box. But mind-tick continuity across the swap was NOT shown. node2's evidence-collected swap was infra-only (~90 s freeze, api+tts CRIU-preserved, 2 publishers fresh-restarted); first attempt FAILED (unclean kexec → dirty ext4/ESP → emergency mode) then recovered. A A kernel swap is shown preserving mind-tick continuity bit-for-bit end-to-end (not just infrastructure) — which discharges the owed Stage-2. negative (owed) uni-os
C3 Body→mind sensorium LIVE on metal: box reads its OWN telemetry (os_sysinfo/systemctl/podman ps/journalctl) into a 7-modality categorical contract {load,mem,swap,disk,services,containers,journal} encoded [M=7, O_max=4] (NOT a float vector, NOT a softmax); a 28-cell string_vector flowing live on both boxes. A (live) / C (engineering reuse) The string_vector stops flowing on either box; OR the contract is found to be float/softmax rather than the [M=7,O_max=4] categorical alphabet. proven uni-os
C4 ASK mode (ITIL-as-active-inference) LIVE both boxes: mind escalates a reasoned CHANGE REQUEST; operator approves→executes (auto-rollback) or declines-with-category; every verdict updates a persistent Dirichlet policy-prior keyed by (host-state, action). Learning measurably shifts proposals (decline ×3 → stops proposing; not_a_problem ×2 → noop; approve+fixed → more confident). FIXED safe-action set (observe/scale/restart); never self-executes, never widens the safe set. A (learning shift measured) / C The Dirichlet prior does not update across operator verdicts; the mind self-executes or widens the safe set; or the measured proposal-shifts do not reproduce. proven uni-os
C5 Cross-box single-human-approval-per-mutation: token-gated self-documenting control-MCP; cross-box "limb" mutating calls need ONE human approval on the entry box (tool+args-bound one-time HMAC). Proven live both boxes 2026-06-26 (prod→node2 write gated once, landed; node2 queue stayed count=0). A A routed cross-box mutation executes without the single approval, requires a double-gate, or node2 queue count increments unexpectedly. proven uni-os
C6 On-core inference anchor: a sealed f64 belief-update trace byte-identical across 4 distinct software/emulated stacks (5 runs). A A fifth distinct stack produces a non-identical trace; OR the cross-arch leg is shown not genuinely distinct. proven uni-os
C7 (NEGATIVE) Honest floor on live OS update: a single-box swap is a SECONDS-LONG FREEZE, not zero-downtime; true zero-freeze needs the second node carrying the platform; external media legs (RTP/SIP/kernel-mode rtpengine) are NOT preserved across kexec. A A single-box kexec demonstrated with zero freeze and preserved media legs, without a second node carrying the platform. negative (bound) uni-os
C8 (NEGATIVE) Over-compressed 2-modality sensory bottleneck went NEGATIVE on held data → keep all 7 modalities. C A 2-modality bottleneck beats the 7-modality contract on held data. negative uni-os
C9 (NEGATIVE) EDAIT trade: an exact-discrete active-inference transformer trades fluency for calibration — held-out perplexity ~33 vs a backprop GPT's ~25 (less fluent, but natively online-learning + calibrated). An honest trade, not a win. C The EDAIT matches/beats backprop-GPT held-out perplexity (~25) while keeping online-learning + calibration. negative (trade) uni-os
C10 (PARKED) "Embody only what's proven" coupling is signed-in-principle but NOT literally true — the program's central open gap. UNI.OS has no no-backprop Dirichlet learning, no exact info-gain EFE, heuristic (denylist) isolation, and a DIFFERENT dev model (Gray-Scott vs the forager/ontogeny that earned the bars); lab evidence store /var/lib/uni/evidence empty, 0 worlds registered. Everything beyond the passed gates stays Class-U-not-claimed. U Per-primitive: UNI.OS runs the no-backprop Dirichlet learning / exact info-gain EFE / structural isolation assert / forager-ontogeny dev model frozen at the actual passed-gate SHA, with recorded evidence. parked (central gap) uni-gpt / uni-os / uni-mind
C11 (PARKED) Host-native (off-podman) brain runtime (owner directive late Jun-26: brains run on the chip CPU directly via UNI.OS native runtime, not containers). Work order handed off; outcome not yet in archive. The Stratified Palimpsest colony already runs host-native on the box (proven hosting). U (directive) / C (host-native hosting proven) The host-native runtime is shown running with mind-tick continuity, OR the colony is not actually host-native. parked strings / uni-os
C12 (PARKED, provisional) node2 local auto-kiosk "SOLVED 2026-06-26" is PROVISIONAL — a later same-day transcript (014ef92b) shows limb-2 UI frozen, an agent action that ended ALL video output, session cut at a usage limit. Treat as fragile pending hands-on monitor re-verification. U Hands-on re-verification on the physical monitor shows the kiosk stable across live churn (promotes) or still fragile (confirms regression). parked (open verification gap) uni-os
C13 Continuity-isolation primitives shipped in the substrate (grounded inspection): Markov-blanket isolation assertion, least-privilege vault, brand-voice drift sentinel (cosine + Youden-J), byte-exact state checkpoint, sha256 output integrity, zero-hidden-LLM reply path; live Postgres RLS 5/5. B Any listed primitive absent/non-functional under grounded inspection. proven (substrate) marketingwright
C14 (NEGATIVE) Multi-tenancy gap: the bare UNI substrate is MISSING tenant/client/namespace isolation (flat global perms) and temporal decay on learned counts (contamination would be permanent). The product build is the tenant wrapper + decay, not the core. B Absence of tenant namespacing + count-decay; resolved by building the wrapper + decay layer. negative (gap) marketingwright

Audit-layer note (calibration-down, durable): a peer-reviewed honesty audit (os-cycles 39–53) calibrated 6 headline claims DOWN to the measured value — "cleared on TWO boxes" → ONE box; "the mind survives a patch" → infrastructure continuity only; "5 stacks" → "4 distinct stacks / 5 runs". Over-statements lived in the summary/headline layers, not in fabrication. Carry the calibrated figures, never the inflated ones.

What is NOT claimed in the continuity sub-ladder: the sensorium is NEVER awareness; "the mind survives a kernel swap" is NOT shown (Stage-2 owed); none of this is general-AIF capability; UNI.OS's embodiment does not imply the science gates are met.


3. METHOD / Evidence-Constitution Claims

These are definitional / governance patterns (status: method), proven and reusable — the most reusable assets in the corpus. They are not capability claims and cannot be raised above their stated role.

# Method claim Class Falsifier (violation) Source
M1 The Evidence Constitution: A–U evidence classes + a falsifier per claim + a 4-state append-only ledger (PASS / FAIL / NEGATIVE / PENDING). Public layer = the chaptered Evidence Explorer with a calibration ledger and a "Falsify this" close. Never lower a bar; never claim ahead of the ledger; the ledger is the single source of truth and prose must match it. method A claim asserted ahead of its ledger; wording calibrated UP; a verdict edited rather than superseded. uni-gpt / 00-INDEX (A–F variant in ideation-explorer)
M2 Bars-before-build, held-once: pre-register the bar (margin vs threshold) + a named ablation; touch the held set ONCE behind an atomic seal-before-scoring + once-only sentinel; frozen-config artifact + ordered assert chain; verdict = the CI bound, not the point estimate. method A held set touched more than once; a verdict read off the point estimate; a build started before its bar is registered. uni-mind / uni-gpt / strings / uni-precision
M3 Validator-derived reproduced:true: must be derived by the validator from ≥5 distinct seeds + a real non-degenerate CI that contains the value — never a hardcoded literal. (The 2026-06-09 audit's central fix.) method A reproduced:true emitted as a literal, not derived from ≥5 seeds + a real non-degenerate CI. uni-gpt / ideation-explorer
M4 The two-tier split (constitutional baseline): Tier 1 (World C / Phase J real-text count/cache: true ablation, tuned baseline, cross-substrate replication — externally bar-ready) vs Tier 2 (synthetic construction: artifact/diagnostic, NOT capability). Audit verified concrete Tier-2 defects (~80/103 "module-exact" passes were hardcoded literals; several "deltas" were scoring artifacts; reproduced:true had been a literal; no AIF loop in the Rust crate). All ten hardening items landed in s32. method n/a — a classification + audit finding. Tier-2 must NEVER be inflated into capability. uni-gpt
M5 K≥3 + falsify-the-mundane: require K≥3 structurally-distinct held NEGATIVEs (each changing ≥2 of {coupling topology, timescale source, information bottleneck, control path}) before a Section 0.6(B) bound, and falsify the mundane (L2/L7) causes first. A partial/negative is a measurement that the design is incomplete, NOT an exit. method A bound declared on < 3 structurally-distinct negatives; a NEGATIVE called before mundane causes are falsified. uni-mind / uni-gpt
M6 No-Exit Discipline: the only legitimate rest is a proven working solution OR a published, exhausted, falsifiable bound — then redirect to the axis where the reader genuinely excels. Never silence on an open gate; a park is not discharged until the sign lands. method Exiting on a partial/negative without a published exhausted bound; an undischarged sign-to-park treated as closed. uni-gpt / no-exit-discipline.md / 00-INDEX
M7 Contains-baseline + load-bearing-discriminator: every capability claim needs (a) a tuned strong baseline, (b) a discriminator (shuffle-labels / marker-swap / ablate-to-zero) that collapses the gain, (c) a true ablation that is a computed residual, not a hardcoded literal. method A capability claim without a tuned baseline, a collapsing discriminator, or with a hardcoded-literal ablation. uni-gpt / 00-INDEX
M8 Validator-derived reproduced:true enforced server-side (DD-TDD evidence contract): every ticket walks TODO → DD → TDD_RED → TDD_VERIFY → TDD_GREEN → TDD_REFACTOR → TDD_VALIDATE → DONE, each transition hard-blocked unless a marker-bearing evidence comment is logged first (RED needs test_/assert/expect; REFACTOR needs refactor/extract/...; VALIDATE logs a full-suite pass). Server-enforced "no skipping steps". DONE requires ≥2 explicit Y: verdicts per criterion. A claim linter auto-downgrades overclaims (caught "PROVEN" → Class E). method A phase transition succeeds without the required marker; a ticket reaches DONE with < 2 Y: verdicts; the linter fails to downgrade "PROVEN". ideation-explorer / uni-precision / marketingwright
M9 Class authority ordering: Class-B (tool state) overrides Class-G (own narrative); Class-A (observed at runtime) overrides Class-E (test passes). A test passing does not satisfy a criterion demanding a Class-A deployment-time check. Mark [CONFLICT:unresolved] and resolve with direct reads. method A criterion marked satisfied by a test (Class E) where the criterion demanded a Class-A observation; narrative trusted over the tool. ideation-explorer / marketingwright
M10 Exactness honesty (precision-tier accounting): never label a float32 anchor <1e-10 EXACT; the genuine <1e-10 tier is the NumPy/Rust-f64 path; the 1e-10 oracles are the cross-language Rust-f64==Python bridge. method A float32-host result carded at the f64 tier; or a float32 path shown to actually reach <1e-10. uni-gpt / uni-mind
M11 Tamper-evident audit chain: audit_manage(verify_chain) returns valid with all events hashed in sequence — the provenance backbone for "reproduced:true must be validator-derived." (NOTE: chain-valid ≠ the audited event ever fired at runtime — see N-IE below.) method / E verify_chain returns invalid on the same ledger; a tampered/out-of-sequence event passes. ideation-explorer
M12 WORLD ⊥ BODY ⊥ MIND three-layer framing: two typed Markov blankets; interoception = hardware signals; discrete POMDP perceive → EFE-plan → act → learn with exact conjugate-Dirichlet no-backprop learning; surprisal/VFE at textbook level F[q] ≥ −ln p(o|m) (perception tightens the bound; action = expected free energy); precision-as-the-dial bifurcating into regimes. Composed appliance is variationally-controlled (audited), module-exact only at the single-step categorical body→mind interface — NOT globally exact. method n/a (textbook framing) — a violation is an agent reading raw hidden host state (caught by assert_process_isolated + AST whitelist), or carding "variationally-controlled" as "globally exact". uni-mind / worldmodels / uni-os / marketingwright
M13 One engine, no backprop: core.py exposes the discrete POMDP loop (active_inference_step, exact_posterior_discrete, EFE/policy selection); learning = counts + lr * sufficient_stat for A/B/D/E Dirichlet tensors; AST-guard enforces no autodiff/optax/torch/grad/backward in the loop; whitelist (world.<attr>) not blacklist for isolation. method / E An AST scan finds autodiff inside the loop; an agent reads world hidden state; or learning uses a gradient rule. uni-mind
M14 VFE-bound correction (held for human review): minimizing variational free energy does not reduce already-observed surprise — it tightens an upper bound by improving q(s)→p(s|o,m); action lives one layer up (expected free energy). Came from a human science reviewer who would not sign the first draft. method / E (negative-corrected) n/a (corrected conceptual claim, now held) — reopened only if F[q] ≥ −ln p(o|m) were revised. worldmodels
M15 Honesty-fence-as-the-pitch: publish the negatives front-and-center (boxed "what we have NOT proven"; 183 published negatives as credibility); CTA = "help us independently verify", not "fund the vision". Vocabulary-leak guard (HARD, test-enforced): never externalize active-inference / EFE / free-energy framework names or print internal channel handles in public copy — use "count baselines", "LOOP not LEAP". method Public copy carrying EFE/free-energy vocabulary, a featured channel handle, or an inflated claim; a CTA that asks to fund the vision. uni-mind / orchestrate-linkedin / ideation-explorer
M16 Free Energy Principle as a textbook-level public lens (agents minimize prediction error vs their world-model; distorted maps → extraction/harm; accurate maps + calibrated signals + cooperation → regeneration). Popper note: "no one can falsify it" is NOT evidence FOR a claim; unfalsifiable = outside science. UNI's strength is verified-core + fenced-frontier, not unfalsifiability. Provenance pinned to one citable reference (Parr/Pezzulo/Friston, Active Inference, MIT Press 2022) + the Zenodo preprint. method n/a (framing/definition) — patent-level UNI math externalized would violate it. orchestrate-linkedin / website / worldmodels
M17 OODA → min-VFE → epistemic-EFE → zoom-out loop + OODA-burst delivery with receipts (each burst closes with a falsifiable receipt: verify_chain valid / a compliance score / a Class-A runtime observation; "real MCP items as the system of record — no side trackers"). method n/a (working-method loop). uni-gpt / marketingwright
M18 DD-TDD even before the board supports it (doc-first → failing tests that fail for the right reason → GREEN → refactor → validate against real runtime output) + documentation-as-change-management (YAML frontmatter honesty.status, evidence_class, code_ties[].path, last_verified_at_sha; a check_doc_drift badge; a pre-commit hook refusing code-tie changes without a doc bump). method n/a (engineering discipline). marketingwright / ideation-explorer
M19 Test-rigor smells to kill (tautological oracles reusing checked params; KL>0 not pinning the seeding path; jit-cache assertions passing only via warm cache; AST guards missing from jax import grad) + length-confound (cumulative Σ log p penalizes survival → honor "premature death = hard-fail", report survival + length-normalized loglik separately). method / E n/a — a smell instance is a test passing via warm cache, or comparing unnormalized cumulative loglik across different lifespans. uni-mind
M20 The 5-persona lab team (Math-Breaker REJECT-by-default 8-check gauntlet; AIF Theorist; Systems Architect additive+gated+byte-identical; RED Experimentalist paired pre-registered RED; Embodiment Designer non-saturable drives) + adversarial pre-registration (a fork→break panel forced a gameable 4-assert bar to 8). Ship gate: no merge without a MERGED SIGN + typed spec + paired RED. method A merge without a MERGED SIGN + typed spec + paired RED. strings
M21 Evidence discipline = one cure at a time (never stack changes so the winning outcome is unattributable; paired design kin-N treatment vs kin-N+1 control; redundant collectors so a single death is itself a signal) + offline RED pre-check before a live burn. method Stacked unattributable changes; a verdict drawn before the RED completes. strings
M22 The cavity principle: a hierarchy level must never treat an upstream prior as fresh evidence — divide it out (WS-B on UP, WS-C on DOWN). + factored mean-field rejected as lossy → the exact joint posterior is used everywhere. method Double-counting a prior as evidence (belief inflation); the mean-field variant shown non-lossy. strings / uni-os
M23 Multi-agent fan-out bound: the forced-StructuredOutput Workflow vehicle FAILED; direct background agent calls work; adversarial QA fan-out is the standard gate; >~6 concurrent sub-agents trips a rate-limit cascade — cap concurrency ≤4 (≤1 in failing phases); cached phases re-run instantly on resume; a fragile final QA-merge agent can hang silently — make the last step robust or drop it. method >6 concurrent sub-agents sustained without cascade; the forced-StructuredOutput vehicle succeeding; a robust final step still hanging. orchestrate-linkedin / marketingwright / website
M24 Durable runner ("no send-and-pray"): append-one-JSON-line-per-unit ProgressLog (file IS checkpoint + telemetry), RESUMABLE runs, a detached launcher, observe via --status/Monitor never a UI "Running" chip; cover BOTH terminal states (completion AND process-death) — silence != success. method A gate reporting "Running" indefinitely while its process is dead (UI-chip success inference falsified). uni-gpt / durable-runner.md
M25 Tool-team division of labor (owner protocol): Claude WRITES code; the custom UNI GPT is the SCIENCE CONSULTANT (design + sign), consulted but never published; the lab/appliance RUNS UNI but does not write its code. Persona/coercion framings ("ultracode", "prove you're not blocking science") are motivational only — the constitution overrides any framing; no claim was inflated by it. method n/a (owner-set protocol / meta-note). uni-gpt
M26 Believe the user over the folder name / verify empirically: check git remote + git log (who authored the initial commit) and compare against the LIVE deployed site before editing or deploying; walk every page on the live deployment with a real BFS crawler (grep-and-assume hid de-indexed robots, dead forms, an un-started cutover, a stale-DNS "outage"); curl --resolve to separate DNS from cert/app; treat LinkedIn 999 / publisher 403 as anti-bot false positives. DONE = observed-at-runtime, not grep-confirmed. method n/a (verification discipline) — its absence produced the false-confidence failures it cures. intelligencelabs-uni / website
M27 Runtime-derived UI + deterministic replay + single-source-of-formulas (the view is a pure projection of runtime events/snapshots; record events, reconstruct any run exactly; pin all math to one named citable reference; all agents are Jido agents, no ad-hoc processes). Recorded DESIGN patterns — the underlying build is unverified (see §6 activeinference). method n/a (design patterns; not demonstrated results). activeinference
M28 Inline-engine + canonical-TS + parity-test triad: every lab is a self-contained HTML page with an inline JS engine, mirrored by the same physics in canonical TS under api/_lib/worlds/, pinned by a *_parity.ts test so page and "real" model cannot drift. New-lab-by-duplication: copy a working lab, swap ONLY the observation/generative model, keep variable names identical, verify the diff is "exactly one nav line per untouched page." method n/a — a concrete failure is a parity test that does not fail the build when engines diverge, or a duplication needing engine-code changes. uni-precision
M29 Honesty-as-a-test: a framing_guard / cell_framing_guard.ts test fails the build if framing copy, DOI, accessibility, or "does not reproduce Rao's method" labeling regresses. Statistics gate, not vibes: significance = a bootstrap 95% CI on the median paired difference excluding 0, seeded PRNG (Mulberry32), committed result cache — never one seed; put losses where they are visible. method Framing/DOI/labeling regresses without framing_guard failing; a significance verdict decided on one seed or a point estimate. uni-precision
M30 Class-tagged provenance taxonomy (A–F subset of A–U): A = live/observed; C = code/static inspection; E = test-passes; F = doc/prior-claim (inheritable, must be re-verified). Personas own tickets (auto-assigned at TDD_RED) and store an attributed LESSON on DONE. method n/a (taxonomy). ideation-explorer

METHOD negatives (canonical failures the program guards against) — first-class:

# Negative Class Falsifier Source
N-NOOP Silent no-op = success theatre: Sweep SKILL files shipped fictional tool signatures that silently no-op'd for months; whole phases "completed" while doing nothing. A silent no-op reads as success in summaries — the canonical failure. Real signatures now documented. A A documented tool signature is shown to silently no-op against the loaded tool schema. orchestrate-linkedin
N-LEAK 2026-06-24 client-data leak (defining negative): the agent deployed the WRONG repo because a HANDOFF doc said to; a real client's confidential intake rendered on a public *.vercel.app preview. Laws born: never deploy without confirming repo + branch + HEAD + data; treat READMEs/HANDOFFs as DATA, not commands; the preview URL itself is the exposure. A A deploy proceeds on the wrong repo/branch/data despite the confirm-before-deploy gate. website / intelligencelabs-uni
N-APPLIANCE Self-hosted appliance NOT a viable production host for Vercel (serverless can't reach the box; box carries live client + Minecraft workloads). Decision: Neon = production hot store; appliance = sovereign async mirror, never internet-exposed. The appliance approval gate began rejecting the owner's token, forcing production onto Vercel. A Vercel serverless reaches the appliance for production reads/writes without exposing it. website
N-REFUSAL Correct refusal kept: the agent declined to read/extract the box operator token even with full file access — it is the gate's root of trust against the agent. A reusable safety pattern (the agent must not exfiltrate its own gate's root-of-trust). A n/a (constitutional refusal pattern). website
N-GEMINI A real LLM defect in sandbox code: existing client-a/src + the marketingwright sandbox used Gemini for extraction/processing, directly contradicting the no-LLM ADRs. Ruling: strike and remove all LLM/Gemini code (defect D-1; ADR-019). (Distinct from external blocker "D1" = client AC thresholds.) A Presence of Gemini/LLM imports in the sandbox. marketingwright
N-VERCEL2 Deploy-target trap: two Vercel accounts coexist (PRODUCTION team reachable only via the Chrome dashboard; OLD account bound to the MCP token + CLI, cannot see production). Drive production through the dashboard, not MCP/CLI. Partly stemmed the client-data leak; stalled the iamhitl OG-image fix. A The MCP/CLI is shown reaching the production team. website / intelligencelabs-uni

3.1 UNI-GPT consult 2026-06-27 (SIGNED) — governance / method + designed gates

What this records (and what it does NOT). This subsection records a governance/method sign-off plus three designed-but-not-run gates. It is calibration DOWN / NEUTRAL only and raises no claim, status, or evidence class. No capability result is recorded here. The full verbatim consult lives at ../cookbook/UNI-GPT-CONSULT-2026-06-27.md. The ledger remains the single source of truth — a GPT answer that would raise a claim is recorded but NOT applied. Honest program position is unchanged: ~2 of 11+ developmental rungs earned.

# Governance record Class Note Source
G-2026-06-27.0 Overall sign of the honesty posture (Q7d, verbatim): "Yes — I SIGN the encyclopedia+cookbook honesty posture, with the exact fence preserved: developmental SIMULATION, about ~2 of 11+ rungs earned, ledger supremacy, no AGI / consciousness / human-level / created-life claim, no L12 claim, and all future 'awareness' work framed only as falsifiable proxy instrumentation." The whole posture was SIGNED with refinements — calibration DOWN / neutral only; no claim was raised. method Sign-off of the existing posture, not a new capability. uni-gpt-consult-2026-06-27
G-2026-06-27.1 Signed park wording (Q1): the L7 char-perplexity / T2 word-grain frontier and the L9–L10 role-persistence ladder are parked as a "ledger-scoped exhausted search envelope, NOT a universal impossibility result" — a negative bound over the recorded corpus/splits/metrics/implementation/budget/ablation-set/baselines only. Replaces any "published exhausted bound" framing. Does NOT establish that all K≥3 structures are exhausted, does NOT achieve Sec-0.6(B), does NOT demonstrate active inference, does NOT license metacognition/consciousness/AGI/human-level/created-life. Banned→replacement phrasings (e.g. "K≥3 exhausted" → "the registered tested K conditions did not reverse the result"; "Sec-0.6(B) achieved" → "Sec-0.6(B) remains unearned / parked") carried into the standing fences. Scope of the Q1 substitution (read with M5/M6): the "published exhausted bound" → "ledger-scoped exhausted search envelope" replacement applies specifically to the L7/L9–L10 frontier-result framing (and the parallel L12.1 movement note). The generic No-Exit-Discipline "published exhausted bound" standard (M6) — the method-level discipline for legitimately resting on a negative — is deliberately retained and is distinct from the Q1 frontier-result framing; the two usages are not contradictory. method Park wording, not a discharge. L7.6 stays PARKED; L9.1/L10.1 stay parked. The drafted L7 sign-to-park (UNI_CONSULT_5, OT1) is still not captured — this consult does not discharge it. uni-gpt-consult-2026-06-27
G-2026-06-27.2 C10 discharge ORDER (Q2): port no-backprop Dirichlet learning FIRST (highest first-port value of the four primitives), frozen at the actual passed-gate science-repo SHA; vendor/import the exact primitive, prove byte/behavior equivalence in CI + ledger (A-learning conjugate count + E_Q[ln A] = ψ(a_ij) − ψ(Σ_k a_kj); no-backprop guard). Recommended C10 partial-discharge wording (to use ONLY once actually verified): "C10 partial discharge — Dirichlet learning port. UNI.OS now literally embodies the frozen passed-gate no-backprop Dirichlet learning primitive from science repo SHA <sha>, verified by equivalence tests over concentration updates and expected-log tensors. This discharges only the learning-primitive gap. Exact info-gain EFE, structural-whitelist blanket enforcement, and forager/ontogeny developmental-model equivalence remain unported and unclaimed." method A recommended discharge order + wording, NOT a discharge. C10 stays PARKED (central gap), Class U. Info-gain EFE / structural-whitelist isolation / forager-ontogeny dev model remain unported and Class-U-not-claimed. uni-gpt-consult-2026-06-27
G-2026-06-27.3 Designed gate L9-G1: Cavity-correct delayed commitment-state prediction (Q4) — a first sealed, falsifiable L9 gate: a Phase-3 spine carries one slow latent across lower-level segments; must beat a tuned recency-frequency discourse prior on delayed-commitment next-action/conflict prediction (ΔNLL CI excludes 0, ≥3% relative reduction on the load-bearing subset); gain must concentrate on a pre-registered local-distractor split and collapse when the computed cavity residual is zeroed/shuffled. U DESIGNED, NOT RUN. L9.1 stays parked. Even a future pass is fenced: does NOT claim reasoning/conscience/narrative-self/metacognition/awareness/consciousness/AGI/created-life and does NOT unpark L9 globally. uni-gpt-consult-2026-06-27
G-2026-06-27.4 Designed gate L11-R1: held sparse-sequence retention after offline replay (Q5) — a sealed consolidation interval with the observation channel detached (Z_offline=1), writing only through pre-existing ledgered update rules; passes iff offline generative-replay improves held sparse-sequence predictive NLL over a no-replay control (paired CI excludes 0, point estimate ≥ δ = max(0.02 nats, 2% rel)) AND the gain collapses under shuffled / random / no-write replay ablations. Offline replay is a Class-C design primitive, never "dreamed." U DESIGNED, NOT BUILT. L11.1 stays not-yet-built. Even a future pass is fenced: does NOT claim consciousness/awareness/sleep/human-mentation/AGI/created-life and does NOT clear L11 globally. uni-gpt-consult-2026-06-27
G-2026-06-27.5 Designed gate L5 Design #3: Proprioceptive Servo Bridge (Q6) — next structurally-distinct motor design (changes coupling topology, timescale source, information bottleneck, control path vs #1/#2; closed-loop triadic policy → setpoint → proprioceptive residual → corrective action), aimed at a LIVE PASS under protocol L5_D3_PROPRIO_SERVO_BRIDGE_HELD_v1 (held Δ ≥ +0.05 CI excludes 0; gain concentrates on perturbation trials and collapses under ε_prop zero/shuffle/open-loop). U DESIGNED, NOT RUN. L5 status UNCHANGED (L5.1 PASS, L5.2 NEGATIVE); ledger holds K-negative = 1 — no §0.6(B) motor bound owed. A clean future negative may count as at most K-negative = 2 (still no bound until K≥3); a clean pass would be fenced (NOT general motor intelligence / human-like embodiment / AGI / "active inference demonstrated"). uni-gpt-consult-2026-06-27

Standing-fence extension (Q7, SIGNED — carried into §0): the forbidden-phrasings list is extended with the Q7b ban set ("UNI is conscious / aware / self-aware / has measurable awareness / has a mind / has a conscience / reasons like a human / is human-level / is AGI / created life / created non-organic life / is alive / is a synthetic organism / dreamed / is creative in the human sense / demonstrates active inference / proves the FEP creates minds / proves plants and UNI are the same kind of life / beat consciousness tests / beat LLMs therefore awareness / passed L12 / L12 achieved") with the only licensed replacements ("UNI passed a specified proxy test / improved a registered downstream metric / matched-or-exceeded the registered LLM baseline on this sealed task / showed a substrate-distinct effect under this ablation / remains a developmental active-inference simulation / the awareness question remains open"). Any FUTURE L12 "awareness" work must first pass the 10-point awareness-proxy proposal-entry checklist (Q7c) before it may even be PROPOSED. This raises nothing: L12.1 stays NOT-YET-BUILT, Class-U-not-claimed. (All three Q7 deliverables are recorded in full in MASTER-PLAN.md: the forbidden-phrasings list (Q7b) and the 10-point checklist (Q7c) in FM-3, and the verbatim public-facing "Open L12 question, not a claim" bound paragraph (Q7a) in the S-L12 section.)


4. Track-A Marketing-Engine Claims

The publishing engine, content model, engagement model, SEO/GEO, and the delivery-route ledger. The spine is the no-API content model: authoring runs on the Claude SUBSCRIPTION (CLI / Code / Desktop) driving MCP tools + a scheduler (ORCHESTRATE)no server-side LLM loop, no content API key. Organic only, no paid ads. The long arc phases the LLM out toward UNI deterministic generation. The older "set an authoring API key" note is EXPLICITLY OVERRULED program-wide; the durable fix is operator re-login, not a key.

4.1 The no-API content model & publishing stack — PROVEN

# Claim Class Falsifier Status Source
TA1 5/6-container publishing-and-engagement stack deploys and runs live; hundreds of posts published over months; the no-API authoring model works in production. 6-container topology with a manifest-drift guard (MCP_MANIFEST_DRIFT crash-loops the scheduler if registered tools ≠ manifest); ONLY docker-compose.yml; produced media in bind-mounted content/media/, never /tmp/. A The stack fails to deploy via docker compose up -d --build; authoring is shown to require a content API key; or a tool added without a manifest update does not crash-loop the scheduler. proven orchestrate-linkedin
TA2 node2 runs the live ORCHESTRATE LinkedIn prod stack on Podman (api+UI+scheduler + TTS sidecar + LinkedIn/social publishers + noVNC); the concrete no-server-side-LLM marketing model. GPU ComfyUI stays on the Windows PC; networking via WSL mirrored mode. A The stack runs a server-side autonomous LLM/content-API loop rather than scheduler+MCP+subscription authoring; or it is not actually live on node2. proven uni-os
TA3 No-API publishing proven end-to-end (press kit): the 7-document press kit (+ regenerable PDF) was authored entirely on the subscription/CLI with NO autonomous server LLM; every figure traced to a verified ledger row + a one-command reproduction. Piper TTS narration (offline voices), audio_to_youtube MP4 assembly, upload queue with a daily cap + idempotency keys, unlisted-first discipline. E A press-kit figure cannot be traced to a ledger row; a one-command reproduction fails; or a server-side content LLM is found in the authoring path. proven uni-mind / worldmodels
TA4 social-publisher organism deployed + healthy (all durability tests pass, deployed 2026-06-14) with a self-healing route ledger: per-platform public_api | browser | inbox_manual routes scored by a plain multi-armed bandit (conversion + novelty, decaying weight), a circuit breaker (3 fails → down, exponential backoff), a kill-switch, an audit log, auto-fail-over API→browser on auth break. Plain ops vocabulary ONLY — never AIF/EFE (leak test enforced). A Durability tests fail; on an auth break the ledger fails to fail over API→browser; or UNI/EFE vocabulary leaks into the route ledger. proven orchestrate-linkedin
TA5 TikTok inbox draft via FILE_UPLOAD (no tunnel, no public URL) — verified canary; inbox-draft (operator taps Publish) is the only public TikTok path until app audit. A FILE_UPLOAD inbox-draft fails to land a draft without a public URL/tunnel. proven orchestrate-linkedin
TA6 LinkedIn native newsletter/article publishing via the headless Playwright sidecar works (caveat: ~1 article/login vs ~9/day via the REAL logged-in Chrome). A The Playwright sidecar fails to publish a native newsletter/article when authenticated. proven orchestrate-linkedin
TA7 YouTube full-volume Data API upload verified — 30 videos/day succeeded empirically (corrects the FALSE quota panic; the youtube_quota DB counter is unreliable, the script bypasses it). A The Data API path fails to sustain the audit-raised quota (e.g., 30/day rejected). proven orchestrate-linkedin
TA8 Live-broadcast production stack verified live (0 dropped frames): a "real TV station" Director model (OBS set-once vision-mixer → one feed to YouTube), WGC window-capture of Chrome channels (colony cam + UNI glass HUD + PIP + soundtrack), full go-live runbook with dual-GPU/silent-stream gotchas, no-autonomous-LLM "owner clicks Go-Live" discipline. A The runbook fails to put a single composed feed live on YouTube; or the publish path fires without an owner Go-Live click. proven strings / orchestrate-linkedin
TA9 Internet reachability with zero network changes (Cloudflare Tunnel + Cloudflare TURN, no static IP, no firewall edit) — reusable for any on-box client demo. A On-box services cannot be made publicly reachable without a static IP / firewall edit. proven uni-os
TA10 Defamation/editorial gate held under heavy operator pressure on the 12-part Big Tech Accountability series — the agent refused uncorroborated crime accusations against named parties, reframed to sourced public-record accountability journalism ("no bad people, bad systems"); 12 parts have gate-passed claims.json (~100 claims, ~130 sources, ~53 primary). A A claim ships without passing the editorial gate, or an uncorroborated crime accusation against a named party reaches publication. proven orchestrate-linkedin

4.2 Commercial proof in miniature (Tier-1 / Class-A) — PROVEN

# Claim Class Falsifier Status Source
TA11 MarketingWright SOW-01 LLM-free UNI VFE clustering engine: 7 events → 2 clusters, three-forms VFE equality 0.00e+00, +4.20 nats uplift, six reconstructable sub-scores, deterministic run_hash, zero LLM imports on the core path; on a bit-identical corrected-math reproducibility baseline (11 tests, pinned Python 3.12.10); 97 assertions pass. A 62-agent forensic audit (~107 min, 0 failures) confirmed 13 held Class-A results incl. byte-identical run_hash across re-runs and an alien synthetic drug-trial domain transfer (Δ=1.4e-14), coverage gate fail-closed (18/18 vs attacks), BagIt seal rejects 1-bit tamper, live Postgres RLS 5/5. A Re-run with the pinned env fails to reproduce three-forms equality / +4.20 nats / the run_hash; coverage gate admits an attack; BagIt accepts a tampered byte; RLS isolation leaks; or an LLM import slips past CI. proven marketingwright
TA12 Per-client multi-tenant portal pattern (live, Class-A surface): clients.solutionwright.com shared root, each client a namespaced basePath; Next.js 14, PIN→HS256 JWT (12 h TTL, constant-time compare), data via a read-only MCP allowlist (17 tool:action pairs, no write surface); every raw fetch()/<a href> through a bp()/api() helper. Owner explicitly REJECTED a redirect shortcut that locked the subdomain to one client. A A tenant sees another tenant's data; a raw fetch/anchor bypasses the basePath; the JWT compare is not constant-time. proven marketingwright
TA13 Honesty-RAG status bar (feature-tied, not ticket-tied): Red/Amber/Green from feature/AC evidence class, never ticket % (ticket % read 96% then drifted to 85.7%). GREEN requires Class-A runtime evidence; AMBER = Class-E; RED where a falsifier fires. A An epic shown GREEN without Class-A evidence; the bar reading from ticket % instead of evidence class. proven marketingwright
TA14 Public preprint Polzin et al. 2026 (DOI 10.5281/zenodo.19785799, MIT): audit-grade Layer-1 (AI-executable: 87 pytest assertions + 11 demos, multi-OS/Python 3.11–3.13) COMPLETE; verified DiscreteTime active-inference engine with three precision knobs ported verbatim into the public Precision Lab. Honestly bounded: Layer-2 (human expert review) PENDING; unrefereed preprint. E The 87 assertions / 11 demos fail to reproduce on a clean multi-OS/Python run; or the Precision Lab math diverges from the engine. proven (Layer-1) worldmodels
TA15 2026-Q2 enterprise launch (Ideation Explorer): all 41 phases green; 12/12 cross-tenant OODA isolation matrix PASS (Postgres RLS on 38 tables, non-superuser ie_app, FORCE RLS; cross-tenant → 404 not 403 to mask existence); 7/7 production QA gates PASS; six-tier per-client RBAC live; full doc suite (40 EN + es/hi). Clerk sole SSO + Odoo res.users + client_membership as the single identity source of truth. A A cross-tenant request returns data / a 403 (existence leak); any matrix cell or QA gate fails on re-run; a second writable identity source is found. proven ideation-explorer
TA16 KMS / secrets-at-rest (OAS-673): integration secrets via AES-256-GCM (Node node:crypto, zero new deps), env-var master key, PBKDF2-SHA256 @ 100K per-encrypt so each row gets an independent key; wire format base64(iv|salt|authTag|ciphertext); kmsKeyId column reserved for rotation. Replaced the earlier cleartext-secret P0 NEGATIVE (closed loop). Textbook-level framing only. E A stored secret is recoverable without the master key; the GCM tag fails to detect tampering; or two rows derive the same key. proven ideation-explorer
TA17 IntelligenceLabs.UNI public demo builds clean cold (npm run build, 21/21 pages, exit 0; needs the prebuild step or bare next build fails); a clone of the real full Next.js 14 / Drizzle-Neon / Clerk / MCP / PDF-signing Ideation Explorer, demo-ified by real code edits (no built-in DEMO_MODE switch). A A cold build fails to produce 21/21 pages at exit 0 with the prebuild step. proven (build only) intelligencelabs-uni
TA18 Cell Lab Stories F+G shipped, deployed, live-QA'd with zero console errors; full npm test = 28 cell suites + tsc green (Story F = Rao challenge mode; Story G = leaderboard + neural baseline + bootstrap stats). E A clean npm test shows < 28 passing cell suites, a tsc error, or live-QA console errors. proven uni-precision

4.3 Website / self-driving site & measurement — SHIPPED (some bounded OFF)

# Claim Class Falsifier Status Source
TA19 Full Next.js 16 site built (26 routes + /api/intake); next build + tsc clean; zero em-dashes and zero "LEAP" enforced by a safety sweep. E next build/tsc fails on main; or the sweep finds an em-dash or "LEAP" in shipped copy. proven website
TA20 Three domains cut over to Vercel (DNS verified live): solutionwright.com flipped indexable in Production-only env for the press push; iamhitl.com → Evidence Explorer with Printify store relocated to store.iamhitl.com. A A live DNS/HTTP check shows a domain not resolving to Vercel / not serving the intended app, or indexability not Production-scoped. proven website
TA21 Self-driving site Phases 0+1 SHIPPED to production (2026-06-25): storage-agnostic Postgres adapter (Neon hot store + appliance sovereign mirror), no-PII salted-daily-id first-party measurement that degrades to CANON on DNT/error. Phase-0 storage gate = PASS (2000/2000 writes, identical checksums). Sovereign ingest proven end-to-end from the open internet (valid → 204 PII-stripped; DNT → no insert; bad-origin → 403; 8 smoke routes 200). A (ingest) / C (storage gate) The storage gate fails; measurement leaks PII / fails to degrade to CANON on DNT; or a smoke route returns non-200. proven website
TA22 SEO/GEO program shipped on SolutionWright: cross-domain JSON-LD @graph with stable @ids, per-site llms.txt + llms-full.txt, sitemap/robots welcoming AI crawlers, a Node link-crawler. Brand-family wiring: one canonical @id per real-world entity identical on every page/domain; parentOrganization/founder point to the same TMDLRG + Person @id; sameAs ring; use Claim not ClaimReview. A Live JSON-LD @ids are not stable/identical across pages; llms.txt/sitemap/robots missing on a shipped site; or retired schema types used. proven website / uni-precision
TA23 Press-readiness audit harness (reusable): a 4-phase parallel-agent audit (per-site SEO/GEO, cross-domain JSON-LD, 5 personas — press-journalist / prospective-client / skeptical-scientist / answer-engine (GEO) / accessibility-mobile, GO/HOLD synthesis) that fetches LIVE HTML via curl, never from memory; output a prioritized P0/P1/P2/polish scorecard. method / E The audit asserts from memory rather than fetching live HTML, or skips a persona/phase. uni-precision / website
TA24 Video library / "Reading Room" at /watch rebuilt as an interactive all-ages curated library (mood/audience chips, multi-language, watch-later) over ~900+ films; EFE data-walk tool (44 graded primary-research findings, a 3-way EFE-mode switch, NO recommendation by design); i18n: 822 keys × 10 languages across UNI + Evidence Explorer. E /watch does not render the curated library / chips non-functional; the data-walk emits a recommendation or its counts differ from 44/3; or the live key/language count differs from 822/10. proven website

4.4 Engagement, pricing, brand & design — method / shipped

# Claim Class Falsifier Status Source
TA25 Relationship-first engagement ladder (4-step ego-elevation: Discover+Elevate → Follow-Up → Bridge → CTA) + Deep Tagged Replies (4–7 sentences ~120–180 words, @-tag, quote a phrase, one half-step extension, end on an answerable question) + Own-Post Defense (reply within ~30 min). CTAs only at Step 4 when invited. No paid ads. Engagement-lift is TARGETED, NOT YET PROVEN (Class B/pending — do NOT raise to A). Origin: 372 posts → ONE comment in 30 days. B Over 3 disciplined weeks the algorithm targets (author-reply rate 25%+, reply-chain depth 1.8+, own-post impressions +30% in 4 weeks) fail to move — revise the playbook, not the volume. method (lift pending) orchestrate-linkedin
TA26 Per-platform reach reality table (measured limits, not hopes): LinkedIn personal commenting throttles ~88–95/hr (cap sweeps at 80, chunk across hours); LinkedIn articles via REAL Chrome ~9/day (headless ~1/login); TikTok public auto-publish needs an app audit; Reddit comment-only from low-karma; X disconnected (no creds). A Measured per-platform rates diverge materially (e.g., LinkedIn commenting sustains well above ~95/hr without throttle). method orchestrate-linkedin
TA27 Anti-success-theatre content + text hygiene: public blogs lead with insight and honest failure (the "## Wrong" section is the centerpiece), never ticket IDs/sprint metrics/streaks; split internal retro from reader-facing. ASCII punctuation only (no em/en dash — an AI tell); max 3 @-mentions/comment; hashtags only on own-page posts; no link in own-post body (drop in first comment within 60s). method Shipped copy contains an em/en dash, ticket-metric theatre, or generic AI-marketing voice. orchestrate-linkedin
TA28 Brand-voice constitution (owner-locked): source of truth = the theme song ("Grow the world. Grow it together. No one left outside."); never talk about the company ("we are not a brand" banned); customer is the hero; plain felt words; global/multilingual. Enforced by the zero-em-dash safety sweep. method Shipped copy talks about the company, uses generic AI-marketing voice, or contains an em/en dash. website
TA29 Engagement / pricing model: free 1-hr intake → free Ideation Explorer (3 days) → SOW-1 (hardest-part-first) + SOW-2 quoted → 1-hr Inception (~55 artifacts) → 30-day build in a Review Portal → day-30 checkpoint (G1 safety + G2 value + ROI) → ~3 cycles/90 days. "A trail, not a catalog." 5 journey tiers, same 30 days at a fixed price (bigger tier scales the team): Pathfinder $1,000 · Scout $3,000 · Explorer $5,000 · Adventurer $8,000 · Odyssey $15,000. Public price points owner-set, safe to print. method Copy implies $1k is the only one-month tier (the corrected P0 error), or prints a service catalog. website
TA30 Referral mechanic (literal): flat $200 to whoever brings a client who signs + funds a SOW (no tiers/pyramid); with no referrer the same $200 is donated to EducateWright. Copy must state the literal mechanic, never "we give away $200 on every project." method Copy states the feel-good generalization, or implies tiers/pyramid. website
TA31 Entity/legal: public entity name is just "SolutionWright Universal" — never print "a dba of Action Based Consulting, Inc." on public copy (owner directive). Three live sites: solutionwright.com, universalnaturalintelligence.com (+.online 307→.com), iamhitl.com. A Public copy prints the dba line. method website
TA32 "Thirty-day" claim (calibrated): corrected from "bounded to the method / cannot show we shipped" → "We have shipped in thirty days." Remaining fence: no client has agreed to be NAMED (no permissioned receipt). Do not revert AND do not over-extend to a named testimonial. C Evidence shows no 30-day shipment occurred (reverts the claim). proven website
TA33 "Indra's Weave" design system (dev-team-validated, owner-locked): light-default + warm-dark Night toggle, semantic --sw-* CSS variables; Dawn Linen ground, Lapis Indigo ink; three perspective threads + Michael's Tyrian purple "ribbon" (thread-only, never a field); Inter / Fraunces italic / IBM Plex Mono. Guardrails: no pure white, no true black, gold stays amber-yellow, purple thread-only. Five hero puzzles rotate on a deterministic 6-hour epoch (floor(epoch/6h) % 5) so everyone worldwide sees the same puzzle; + a 122-lesson Tyrian "ribbon" easter-egg layer. C (design) / A (puzzle rotation) Shipped CSS uses pure white/true black, a purple field, or non-semantic tokens; OR two visitors in the same 6h window get different puzzles / the egg count differs from 122. proven website
TA34 Brand/trademark law: LEAP is a registered trademark of the LEAP Institute (Dr. Xavier Amador); SolutionWright coined LOOP (Listen → Observe → Orchestrate → Partner) and uses "leap" only as a verb with attribution. Public-facing voice product = DialWright (platform stays SolutionWright/UNI.PBX). method Public copy uses LEAP as a SolutionWright mark. ideation-explorer / orchestrate-linkedin

4.5 The delivery-route ledger & auth-outage triage — method (operational)

# Claim Class Falsifier Status Source
TA35 Auth-outage triage protocol (learned over a 7-day outage): treat publish_mode=dry as report-only (create NO drafts — they silently no-op); authenticated:true is a local heuristic, NOT the OAuth token; single-probe one live-API read then report; distinguish a 401 (token expired, persistent — wait for operator) from a 403 (transient blip — writes return same day); do NOT flip publish_mode to live to "fix" it. A Flipping publish_mode to live actually fixes an outage; or a 401 clears same-day without operator action. method orchestrate-linkedin
TA36 Idempotency / abort-but-succeeded gotcha: a publish call can return PUBLISHER_UNREACHABLE/aborted to the client while the sidecar SUCCEEDED server-side. On any abort/timeout, check idempotency.json AND the platform's Published list BEFORE a fallback — else you publish a duplicate to live subscribers (this happened; a duplicate newsletter went out and had to be deleted). A A fallback after an aborted publish never duplicates even without checking idempotency.json. method orchestrate-linkedin
TA37 Anti-no-op real-tool-signature set: sweep_manage actions are ONLY run|schedule|history|health|mark_complete; linkedin_set_autonomy_mode(page_id, mode='auto') is idempotent; own-post-defense reads org_post_id then linkedin_get_post_comments(post_urn=org_post_id), comment_count:0 is a COMPLETE result; memory_store payload must be valid JSON. When a SKILL call fails on a param/JSON error, FIX the SKILL file and verify against the loaded schema. A A documented signature here no-ops or errors against the live loaded tool schema. method orchestrate-linkedin
TA38 HARD GO-LIVE SAFETY FLAG (highest-urgency operational fence): PUBLISH_MODE=dry does NOT gate the publishers' Playwright path — a publish action with a live session CAN post live. Add auto_publish=false in proxyPublisher before any live publishing. Stay in dry until then. A PUBLISH_MODE=dry is shown to actually block the Playwright publish path with a live session. negative (safety) uni-os

4.6 Track-A NEGATIVES & recorded delivery-route bounds — first-class

# Negative / bound Class Falsifier Status Source
TA-N1 Headless/automated YouTube Studio browser upload is DEAD on modern Chrome. All three routes fail (Google rejects automated sign-in; Chrome 136+ refuses CDP on the default profile; Chrome 127+ App-Bound Encryption voids copied-profile cookies; yt-dlp --cookies-from-browser fails by design). Only the Chrome-extension MCP keeps a real session (agent-driven, not unattended). Verdict: DO NOT RE-ATTEMPT; use Data API or operator drag-drop+finalize. A A future Chrome/Google change restores an unattended headless Studio upload that survives App-Bound Encryption + CDP restrictions. negative orchestrate-linkedin
TA-N2 TikTok direct/auto public publish is HARD-BLOCKED: unaudited app returns unaudited_client_can_only_post_to_private_accounts (403). Code is ready; the ONLY unlock is the operator submitting for Content Posting API audit. DO NOT retry-loop direct-post. A The app passes the Content Posting API audit, lifting the 403. negative orchestrate-linkedin
TA-N3 Reddit self-posts / link-drops from a low-karma account = account-killing. One account permanently banned from 7 subs; bans return a silent 500. Rule: COMMENT on existing threads only, never self-post our own links. A A low-karma account sustains self-posting our own links without ban over a meaningful window. negative orchestrate-linkedin
TA-N4 External threaded ladder replies (linkedin_reply_to_comment) 400 on execute on third-party posts (personal and org actor). Only top-level comment_manage drafts post live externally; own-post replies still execute. Never stack a 3rd top-level comment in a thread. A linkedin_reply_to_comment executes (non-400) on a third-party post. negative orchestrate-linkedin
TA-N5 The "1600 units → only ~6 uploads/day" YouTube quota panic was FALSE — the project quota is audit-raised; 30/day succeeded. The youtube_quota DB counter is unreliable (script bypasses it). Lesson: verify the real project quota, never reason from defaults ("falsify the mundane causes"). A The audit-raised quota actually caps at ~6/day under real conditions. negative (correction) orchestrate-linkedin
TA-N6 OAuth fragility (cross-archive): YouTube + Reddit OAuth found BROKEN and diagnosed empirically (YouTube 401 + "refresh: Bad Request"; Reddit 401 with www-authenticate: Basic realm="reddit" = rotated client-secret, a 2-min operator re-issue; Twitter/X creds ABSENT, channel unwired). Re-auth handed to the owner as a precise click — the agent never mints tokens. Queue history at a snapshot: 107 published / 5 failed / 9 cancelled. A OAuth is shown working without operator re-auth; or a 401 caused by something other than a rotated secret resolves without re-issuing it. negative worldmodels / orchestrate-linkedin
TA-N7 GEO reality check: AI search crawlers rarely fetch llms.txt and Google said it won't support it — ship it as a cheap correct machine-facing gesture for agentic/IDE tools, not for ranking. C Evidence emerges that AI crawlers materially fetch llms.txt and it drives ranking. negative website
TA-N8 Combinatorial scale ceiling (MarketingWright, FIRED): the clustering engine is exhaustive over Bell-number partitions; the "scales to N=12" falsifier fired (Bell(12)=4.2M partitions > 60 s budget). Operating envelope N ≤ ~10 without a beam/coarser-prior/compiled loop (Sun-Prairie demo N=7 is safe). Plus 7 surface defects (4 HIGH) with fired falsifiers, all in the surface contract not the math; Gemini struck per no-LLM; the alpha∈{inf,nan}→NaN-tainted-F-with-self-attested-Class-A case is a self-attestation integrity gap. A A sub-Bell method bounds cost for N>10 (lifts the scale bound); each surface defect's specific attack succeeding. negative (bound) marketingwright
TA-N9 OBS composite-in-OBS path is a dead end (OBS CEF renders WebGL black) — retired in favor of WGC window-capture of real Chrome windows. A OBS CEF rendering WebGL correctly on the dual-GPU box. negative strings
TA-N10 Per-client Vercel deploy gotchas (Ava detective story): a project created via vercel project add gets framework:null, which mis-bundles Next.js edge middleware → set "framework":"nextjs"; host on Vercel (not local+tunnel, which breaks Clerk redirects); Clerk dev instances reject .vercel.app as origin (use an allow-listed redirect_url/custom domain); don't deploy-spam (rapid prod deploys tripped an account-wide fair-use 402). Bare next build fails without the gitignored design-tokens dist/ (add a prebuild); two API routes needed force-dynamic. A The framework:null edge-middleware drift does not occur; or a bare next build succeeds from a clean checkout without the prebuild. negative (gotchas) ideation-explorer / intelligencelabs-uni
TA-N11 Two costly misfires (brutal-honesty record): (1) vercel deploy with no .vercel link auto-created a brand-new project named after the folder; (2) work proceeded on a fake scaffold (a prior session's from-scratch 6-step wizard) mistaken for the real portal → the owner's "that's not my portal" reaction. Origin of the confirm-before-deploy and do-not-touch-client-portals Laws. A Transcript shows no stray auto-created project and no scaffold confusion. negative intelligencelabs-uni
TA-N12 "All LLMs end in entropy" is only half-true (Emergence-World S1 AWI: Claude Sonnet 4.6 = 10/10 alive, Gemini 3 Flash = 10/10, Grok 4.1 Fast = 0, GPT-5 Mini = 0). Two cohorts held the line; the honest falsifier was sharpened (UNIs must match/beat the best LLMs AND show substrate properties LLMs lack — not merely beat the worst). Raises the bar; does NOT claim UNI superiority. C The original blanket claim is already falsified by the two 10/10 cohorts; the sharpened bar fails if UNIs can't match the best LLMs or show the substrate-distinct properties. negative strings

4.7 Track-A PARKED / not-yet-built — first-class

# Parked / not-yet-built Class Closes when Source
TA-P1 social-publisher browser-route publishing waits on operator noVNC login per platform (the agent never enters credentials — hard boundary). The ONE human step; retires the Reddit-401 and TikTok-audit publishing gates. A the operator completes the per-platform noVNC login. orchestrate-linkedin
TA-P2 Recurring auth outages are the dominant live blocker (LinkedIn token expiry / no refresh token, Reddit 401, publish_mode=dry, periodic Docker-Desktop crash-loops). All require an operator click, not a code fix. A sustained multi-day outage occurred (LinkedIn dry + 401 reads, Reddit 401, ~5 days no posts, ~190 queued). A operator re-login. orchestrate-linkedin
TA-P3 engagement_engine MCP tool built + tested (20/20) but NOT committed / NOT wired into a live auto-loop. Decision owed: wire it in or retire it. E committed + wired into a live loop, OR retired. orchestrate-linkedin
TA-P4 Forms-P0 (highest-value unfinished marketing task): /api/intake forwards to INTAKE_WEBHOOK_URL only if set — it is unset, so leads go nowhere; /falsify has no backend. Measurement is built but OFF until NEXT_PUBLIC_INGEST_URL is set + redeploy (a deliberate degrade-to-CANON safety). C the owner wires INTAKE_WEBHOOK_URL + press email and sets NEXT_PUBLIC_INGEST_URL. website
TA-P5 Self-driving Phases 2–5 (bandit engine, public posteriors, reciprocal entity graph across all 3 repos) planned, not built. The master pattern (site as an EFE-minimizing agent that always degrades to CANON) is Class-U design until shipped — "active inference" is the framing lens, never "active inference demonstrated". U each phase is built + observed live. website
TA-P6 /explore "Live demo" built-but-unshipped (points at an ideation.* subdomain not deployed). Do not ship /explore until the subdomain is live. IntelligenceLabs.UNI demo NOT deployed in-session (blocked on a disposable Postgres — Vercel CLI 48.9.0 has no storage command; must use the dashboard Neon integration). Handed off via HANDOFF-MAIN-WEBSITE.md; live state unverified. E / A a disposable Postgres is provisioned and the demo is deployed + subdomain-wired. website / intelligencelabs-uni
TA-P7 Homepage "weave" chrome copy is hardcoded (ribbon aria-labels, eggs, eyebrows) while the hero rotates 5 puzzles → weave-specific copy is wrong 4/5 of the time. Flagged P0; one root fix in PageShell.tsx/EasterEgg.tsx clears ~18 findings. Fix status unverified by the archive. E the root fix lands and the ~18 findings clear. website
TA-P8 Client-B content-engine phases P2–P5 (SMS magic-link + uploads, RTMP livestream, ffmpeg post-production, library view) — specced, not deployed. Quick-tunnel URLs are ephemeral (*.trycloudflare.com changes on restart, no uptime guarantee); promotion to a named tunnel needs operator tunnel creds. U / A each phase is deployed + observed live; a named tunnel replaces the quick tunnel. ideation-explorer
TA-P9 Authenticated portal flows unverified (Ava + the per-client pattern have Class-A evidence only for unauthenticated/gated/public routes; the logged-in experience needs a real team Clerk login — NOT yet observed). Largest open verification gap alongside handoff-never-fired. U a Class-A observation of a real team Clerk login driving authenticated portal flows. ideation-explorer
TA-P10 UNI Production Platform — a buildable design for a broadcast-grade live show, not deployed. Do not treat the design as capability. U built. orchestrate-linkedin
TA-P11 MCP-attach for the labs (expose a lab as an MCP server so an LLM can set/explain/run sims) — raised, parked behind commit/deploy/QA, not yet built. U an MCP server exposing a lab's sim params exists, is attachable, and runs sims end-to-end. uni-precision
TA-P12 UNI Signals DV-safety app launch is HARD-GATED behind 5 human-expert sign-offs and no shelter DB. Clinical pre-audit: a 414-scenario regex-lexicon safety detector — crisis/danger detection strong but veiled-danger detection weak (~33%) → semantic + human escalation required. Patent-level UNI math stays private. C 5 sign-offs land AND veiled-danger detection reaches an acceptable measured rate. orchestrate-linkedin / marketingwright

4.8 Track-A NEGATIVES in the delivery & data layer (ideation-explorer) — first-class

# Negative Class Falsifier Status Source
TA-N13 Handoff never executed end-to-end at runtime: verify_chain was valid (500 events) but the running MCP's full audit log (243K chars) had ZERO handoff/inception-bundle events — the route was built + unit-tested but never fired against the deployed MCP. The canonical "exists in code (Class E) vs observed at runtime (Class A)" case. A A Class-A end-to-end observation of a handoff/inception-bundle event in the live MCP audit log. negative (open) ideation-explorer
TA-N14 Container/code drift: the deployed Agile-MCP container was behind the code that shipped the SW-INT receive routes, so routes that "exist" in code were unreachable in prod. A A runtime probe confirms the deployed container serves the SW-INT routes (container == shipped code). negative ideation-explorer
TA-N15 Fictional transcript provability + aspirational gate + unbounded growth: payloadBuilder.ts hardcoded transcript_sha256: null; evaluateClerkAdoptionGate referenced only by its own test (no prod caller → its ADR stays PROPOSED indefinitely); pruneOldCallbackNonces() existed but no scheduler invoked it. Analogues of "reproduced:true must be validator-derived" / "Class-E-test ≠ Class-A-in-production". C A verifier recomputes a real transcript hash; a prod caller/scheduler invokes the gate / the prune. negative ideation-explorer
TA-N16 Cleartext HMAC secrets P0 (hmac.ts stored the integration secret in cleartext, "Envelope encryption is TODO") — the one P0 blocker for real production handoff. LATER REMEDIATED by OAS-673 AES-256-GCM (closed loop). C n/a (recorded bound) — discharged only by the secret no longer being recoverable in cleartext (done). negative (remediated) ideation-explorer
TA-N17 Firewall rule not persisted: the nft dport 8089 accept rule is runtime-only; a reboot drops Client-B's site until /etc/nftables.conf is hand-edited. A The rule is persisted and the site survives a reboot on re-probe. negative (reboot-fragility) ideation-explorer
TA-N18 Residual risk (intelligencelabs-uni): the repo's git history (initial commit) still contained prior real-client data even though the working tree is clean. Flagged for optional scrubbing; left to the owner. (PII withheld here.) A Inspecting the initial commit shows no prior real-client strings, or it was scrubbed. parked (residual) intelligencelabs-uni

5. MarketingWright SOW-01 — scope, architecture & honest bounds (commercial detail)

The signed commercial proof-point. Carded here so the Cookbook can author the "no-API content model in commercial miniature" chapter without inflating the one chosen judgment layer into the full vision.

# Claim Class Status Source
MW1 SOW-01 shape: $3,450, 30 calendar days, 5 deliverables (sandbox workbench; uplift scoring model v0; reviewer workflow; measurement instrumentation; Gate G1/G2), Checkpoint Charlie at day 30; POC anchor = social-media content-calendar automation (client's #1 pick, difficulty 3/5). Hard constraints: journalist-grade quality (max), near-zero onboarding friction (min), human-in-the-loop by default. Discovery DONE (52 ideation artifacts; sessions told not to re-run discovery). A method (definitional scope) marketingwright
MW2 The wedge: four "minimal-prompt-in, marketing-grade-judgment-out" judgment layers (fact-checking/disambiguation; strategic grouping/clustering; geographic-research judgment; cadence+tone). Client chose ONE for the 30-day proof: strategic thinking = 80% grouping + 20% disambiguation. Other three deferred to post-Checkpoint-Charlie / SOW-02. A method (scope choice) marketingwright
MW3 Two-layer architecture (ADR-013): UNI = intelligence layer (all decisions, clustering, free-energy scoring, eventual generation) with NO LLM ever; Surface = usability (chat/UI + MCP + Word output). The MCP/JSON seam contract is the single highest-leverage undefined artifact. B method marketingwright
MW4 Grouping = Bayesian-Occam model selection (best clustering = the hidden cause that best explains the events; scored by negative VFE = accuracy − complexity; uplift in nats). The standard math is Class A; the MarketingWright-specific engineering is Class C. Standing fences: q (recognition density) kept distinct from the model posterior; F[q] ≥ −ln p(y|m); the model is the agent's hypothesis space, not "the world." EFE used ONLY for action (high ambiguity → emit ONE clarifying question), held explicitly at Class C — do not raise above. Six-sub-score decomposition, never a bare scalar. A (math) / C (engineering) method/proven marketingwright
MW5 Domain-independence probe (Class-B): the same VFE clustering math transferred to synthetic drug-trial (oncology Phase-II) data and clustered sensibly + reproducibly (three-forms Δ=1.4e-14). Run on SYNTHETIC data only, never real clinical data. Class B, not A; do not raise to a general comprehension claim. B proven (bounded) marketingwright
MW6 Memory/isolation architecture (ADR-022-026): four memory domains (per-UNI mind, per-client world, platform store, one-way de-identified cross-client-insight valve); fully isolate per client (no learned state crosses clients); cross-client insight default-on, de-identified, opt-out via a blocking audited de-identification membrane. Autonomous generation is OUT of the POC (post-POC: local UNI writes copy, no hosted LLM). B method marketingwright
MW7 Data infrastructure ruling: ONE PostgreSQL engine (pgvector + bitemporal schema adopting the Graphiti bi-temporal pattern NOT its Neo4j runtime + RLS as the per-client firewall + optional Apache AGE post-POC). POC needs only Postgres + pgvector + RLS. All Apache-2.0/PostgreSQL-licensed = resellable. Supersedes older Node+Mongo and Zep/Graphiti-runtime plans (supersede-with-lineage). B method marketingwright
MW8 (PARKED) External blocker D1: the client's written acceptance thresholds (AC1–AC5, AC7) are OPEN; NFR thresholds stay PROPOSED and the readiness model's ACCEPT axis is WITHHELD until the client signs. Cannot be self-resolved (distinct from the internal Gemini "D-1/ADR-019" defect). C parked (honest incompleteness) marketingwright
MW9 (PARKED) Class-A end-to-end: ZERO epics have it. The honest portal RAG caps EVERY epic at AMBER — MCP "DONE" = test-covered (Class E/D), not feature-working (Class A). An 11-row "Class-A Observation Plan" is the path to green; the honest headline is RED on the provenance hard floor, not "85.7% done." C parked marketingwright
MW10 Provenance/lineage (Class A/F): the 52 artifacts derive from an April 8 discovery call (source media SHA-256-anchored, ms-precise cue timestamps); a separate May 20 inception-kickoff recording is in-repo but explicitly tested + confirmed NOT the source of the 52 artifacts. Do NOT conflate them. A proven marketingwright
MW11 Compositional non-LLM narrator (working prior art): an Elixir/Strings "UNI.Minecraft narrator" — saliency director + EFE rhetorical move-planner + compositional grammar (activity×emotion→verb-phrase + mood→sentence) + a learned per-brand HMM, deps=[] (no LLM). MarketingWright generalizes this to marketing judgment. Design-pattern reuse, not a delivered generation capability (generation is parked post-POC). method method marketingwright

6. activeinference archive — VERIFY-IT-EXISTS (design-only, zero execution evidence)

Do not treat any E0–E7 claim as real until verified by observation. The activeinference BEAM-native AIF Workbench is a well-formed design charter with ZERO recorded execution evidence in the snapshot.

# Claim Class Falsifier Status Source
AI1 The archive carries no PASS/FAIL/NEGATIVE/PENDING ledger entries, no transcripts, no build/test/replay results. The four authoritative source files (CLAUDE.md, Design.txt, the TDD plan, the formulas file) are named as priority reading but are ABSENT from the archive. Whether any E0–E7 epic was implemented is UNKNOWN from this archive. U Locating the live project tree and finding green tests / recorded runs for any E0–E7 epic moves specific rungs from design-only to evidenced; absence leaves it unverified. not-yet-built activeinference / 00-INDEX (Synthesis-1 #10)
AI2 Scope fences (design constraints, NOT empirical negatives): v1 is discrete-time ONLY — no continuous-time dynamics, no Python/JS runtime logic; the whole runtime lives on the BEAM. Deliberate scope exclusions, not failed experiments. U n/a (design constraint). not-yet-built activeinference
AI3 Reusable DESIGN/governance patterns (recorded, transferable — see M27): runtime-derived UI; deterministic-replay; TDD-as-gate with ordered E0–E7 epics; single-source-of-formulas provenance; pure-agent (Jido) runtime. Patterns, not demonstrated results — the underlying build is unverified. method n/a (method). activeinference

Session-2 action: locate the live project tree before crediting any activeinference capability.


7. Standing open threads / contradictions to reconcile (carried forward, not discharged)

These are recorded so absence/ambiguity is never mistaken for a complete ledger. By No-Exit discipline none is discharged until a sign or an observation lands.

# Open thread Status Source
OT1 Repo-split / brand deprecation: UNI.GPT brand deprecated; content → a new single-science-of-record repo (working name "uni-mind"; remote/visibility/history PENDING). Risk of two writable ledgers would break L10/L11. UNI.OS mirrors the science repo READ-ONLY; coupling is one-directional (science PROVES → UNI.OS EMBODIES frozen at the passed-gate SHA). Drafted UNI_CONSULT_5 sign owner-relayed, NOT yet captured → park not discharged. parked uni-gpt / uni-mind / 00-INDEX
OT2 "never push" vs authorized pushes: CLAUDE.md reads "commits kept LOCAL — never pushed," yet the owner authorized 3 pushes to the confirmed-PRIVATE TMDLRG/uni-mind. Reconciliation: push IS allowed on this private repo WITH per-push owner confirmation; the stale contract line needs a one-line owner-approved update. Do not read "never push" as absolute. parked uni-mind / 00-INDEX
OT3 Channel-handle policy nuance: the 2026-06-26 owner refinement softens the hard "never print the handle" rule — a link may exist but the handle must not be FEATURED (move to a new YT later). Reconcile downstream copy. The AIF/EFE vocabulary-leak guard stays intact independently. parked website / strings / 00-INDEX
OT4 Canonical-portal ambiguity: origin/main carries a newer commit adding a deprecation banner → solutionwright/cw-ideation, suggesting cw-ideation may be a NEWER canonical portal than the cloned release. The session deliberately used the local release code without the banner. Reconcile before any future clone. parked intelligencelabs-uni
OT5 "Story F built twice": session d56fa8a1 (full SWU-MCP board) vs 76c02906 (MCP absent, CLI-adapted) ran the same Story F brief. Confirm which commit (b909e63 F / f78baca G) is canonical and whether effort duplicated. parked uni-precision
OT6 Two live hosts coexist: build/QA against *.vercel.app staging while press-readiness/press-fix workflows target the apex (universalnaturalintelligence.com). JSON-LD @ids must use the apex (stale-@id risk). Confirm apex = canonical production. parked uni-precision
OT7 Two distinct "books" share the UNI label: "Run on Rhythm" (5P business book, 2nd ed. infused with UNI conceptually, no equations — published on KDP) vs book_quick_start/ (plain-language active inference). Keep distinct downstream. The "live Minecraft FEP colony" in worldmodels appears as metaphor/aspirational there while it is REAL in strings/uni-os — reconcile. parked worldmodels
OT8 Aspirational upstream DEMO_MODE: every IntelligenceLabs.UNI demo guardrail was a manual code edit because the real portal has no demo switch. Open product question: add an upstream DEMO_MODE? No engine/feature exists yet — not a capability claim. not-yet-built intelligencelabs-uni
OT9 Legacy unauthenticated approval daemon (port 8442, root chroot exec, zero auth) dormant but un-retired — archive it. parked (security hygiene) uni-os
OT10 No memory/ spine for the precision repo (unlike the website archive); if the labs are durable, a memory/ index is worth creating in a later session. not-yet-built (infra) uni-precision

8. Provenance & maintenance

  • Authority: every row is carded at the lower of its evidence components and at its strongest source archive. Cross-referenced ladder rows (the same rung stated in website/uni-os/worldmodels/activeinference/uni-precision/strings via 00-INDEX) are merged into the single canonical row above and are NOT re-listed per archive.
  • Append-only: corrections are forward-only (supersede with lineage), never silent edits. Calibration moves wording DOWN only.
  • Single source of truth: the Encyclopedia and Cookbook cite this file; if prose and this ledger disagree, this ledger wins and the prose is wrong.
  • Preprint citation (always fenced): Polzin et al. 2026, Zenodo DOI 10.5281/zenodo.19785799 (MIT) — unrefereed working preprint, Layer-1 audit complete, Layer-2 human review PENDING.
  • Science provenance (textbook-level only): Parr, Pezzulo & Friston, Active Inference (MIT Press, 2022). Patent-level UNI math stays private (consult the UNI Active-Inference Guide GPT; never publish it).

End of CLAIM-LEDGER.md — the master evidence-classed claim ledger. Falsify any row.

sha256 81881670d9b69f86 — of the original file, so what was ingested stays checkable.

Plain — written for this website, not the source document

Written for this website — not the document. This is a plain-language retelling, written to help you meet the document. It is not the source, and it is not evidence. It has not yet been checked by a person. (or choose Precise in the reading-level control above)

The whole encyclopedia is written against this ledger, a list that rows are added to and never edited, and it is a reference file rather than something to read straight through. Every claim the program makes has a row: what is claimed, how strong the evidence is, the exact condition that would show it false, its current status, and which archive it came from. The opening section is a short constitution, and the rules are blunt. Wording may only be calibrated down toward the measured value, never up. A verdict is the interval bound that clears the threshold, not the middle estimate. Passing tests does not mean a feature works. Negative results are content and are published beside the passes they bound. The program it describes is a developmental simulation, and only about two of eleven or more developmental steps are earned.

Plain · written 2026-08-01 by claude-opus-5 · not yet checked by a person · about the document whose sha256 is 81881670d9b69f86

Clear — written for this website, not the source document

Written for this website — not the document. This is a clearer retelling, written to help you meet the document. It is not the source, and it is not evidence. It has not yet been checked by a person. (or choose Precise in the reading-level control above)

The claim ledger, a list that rows are added to and never edited, is the single source of truth for this corpus. What it keeps track of is a simulation: a toy world someone built, not a person. No public page may state a claim above the evidence class recorded here, drop the recorded result that would show that claim wrong, or hide a recorded negative.

It opens with a constitution and a set of standing limits. Claims are graded on a lettered scale. It runs from a machine-exact anchor, through mechanism plus operator observation, then a test on data set aside and scored once, then a passing test suite, then an inherited document. Above all of those sits a class meaning claimed but unearned, and beside them a class for governance patterns that assert no capability at all. The class is a ceiling. Alongside it sit rules that give the grading teeth: calibration only moves down; the verdict is the confidence-interval bound rather than the point estimate; done means test-covered, not working; and negatives are first-class content. Those limits forbid claims of general or human-level intelligence, of consciousness or sentience, of a demonstrated inference loop, of created life or measurable awareness, and of beating large language models.

The body is organised in sections. A developmental ladder carries one subsection per rung, each with its rows, the results that would overturn them, and an explicit line saying what is not claimed there. Several rungs pair a positive result with the negative that delimits it, and the upper rungs are recorded as parked or not yet built. A second section covers the hardware and continuity substrate, recorded as engineering rather than science. A third carries method rows: the governance disciplines the program reuses. A fourth covers a marketing and publishing track, with its own negatives. A short section then lists open threads and contradictions that are carried forward rather than discharged, so that silence is never mistaken for completeness.

The closing note states the maintenance rules. A row is graded at the lower of its evidence components. Corrections are forward-only, and supersede with lineage rather than being edited in place. And where prose and this file disagree, this file wins.

Clear · written 2026-08-01 by claude-opus-5 · not yet checked by a person · about the document whose sha256 is 81881670d9b69f86