publisher workspace c10 membrane main post + explainer toggle view

C10 Membrane Publisher Workspace

One interactive publication surface for the main article and its deeper Part 2 explainer. The main post stands alone; the explainer stays available without turning the article into a white paper.

C10: The Membrane Is How Reality Becomes Capability

C10 is a reality-to-artifact compiler with a governance spine.

Today, C10 has real governance components, an established constitutional admission path, a separate artifact membrane prototype, and a tested local transition slice. It is not yet a universal live governance engine across every app and workflow.

That distinction matters.

C10 is designed for builders: someone brings an idea, problem, workflow, artifact, or objective, and the system is designed to assemble the relevant context, tools, safeguards, collaborators, and next actions needed to form a usable capability.

Not just a chat. Not just a project board. Not just a generated file.

A capability: something that can be reused, composed with later work, audited, improved, and connected to what came before.

Bring an idea. Leave with a living capability.

The hard problem is not generating artifacts. The hard problem is preventing generated artifacts, repeated signals, UI states, or persuasive interpretations from silently becoming "truth."

That is what the membrane is for.

Nothing Self-Admits

The core law of C10 is:

Nothing self-admits.

A request can propose a change.

A UI can expose a possibility.

A repeated pattern can attract attention.

A report can summarize evidence.

A prototype can prove a shape.

But none of those things may declare themselves canonical.

For something to become durable system reality, it needs a lawful crossing: source, route, authority, executor, and proof.

The target general transition architecture is:

Reality Constructor
  -> General Transition Membrane
  -> Applicable Domain Authority
  -> Transition Executor
  -> Postcondition Proof

Each part has a distinct job.

The Reality Constructor forms a raw request into a provenance-bound transition packet. It does not grant authority.

The General Transition Membrane is designed to classify, verify, and route a proposed crossing. It does not decide a domain's law.

The Applicable Domain Authority determines whether a transition is legitimate.

The Transition Executor performs only the authorized, plan-bound action.

The Postcondition Proof checks whether the resulting state matches what was authorized.

That separation matters because systems tend to blur proposal, execution, and truth. C10's architecture refuses that blur.

The Three Layers

C10's architecture separates reality, governance, and computation.

The Reality layer contains objects, edges, claims, and crossings: what is said, related, or observed.

The Governance layer contains the membrane, recognition, work-claim controls, tag tolls, proposal protocols, and conservation principles: how a change may become legitimate and durable.

The Computation layer contains lenses, emitters, projections, activation, UI, and reports: how the graph is interpreted and materialized without silently altering its meaning.

A claim is semantic reality:

Claim { statement; scope; confidence }

Confidence is not merely a number. It is a provenance pointer:

Confidence { level; crossing }

And a crossing records an event, never a conclusion.

A record can show that an action, proposal, review, or admission occurred. It does not automatically prove that an attached statement is true, important, canonical, or complete.

What the Membrane Does

The admission membrane is not a generic "check before doing things," and it is not a wall around the system.

It is a selective, recorded crossing mechanism.

Its functional organs are:

  • Gates - where a thing is caught and classified.
  • Valve - what turns catching into explained, recorded passage.
  • Channels - directed paths a crossing may travel.
  • Receptors - what the membrane is tuned to recognize.
  • Synapses - junctions that strengthen with repeated firing and prune with silence.

"One door" does not mean one universal function. It means durable crossings must be visible, attributable, and lawfully routed rather than self-authorized in the background.

The Membrane Family

C10 has several membrane-related systems with different standing.

The constitutional membrane is the established authoritative path for constitutional admission:

HYP0 eligibility
  -> applicable membrane
  -> ratification / P0N5
  -> receipt and replay evidence

Its executable substrate includes hyp0.py, membrane.py, p0n5.py, and admissions.jsonl.

The artifact membrane is a separate working prototype for ordinary artifact crossings:

Gate / claims / no-loss / usage toll
  -> artifact crossing
  -> artifact receipt

Its critical rule is:

No record means no crossing.

Artifact admission does not amend the constitution.

The readiness membrane is staged or partial. It can support evidence and review, but it is not a general admitting engine.

General Transition Membrane v3 is a narrow, local, dry-run-guarded transition slice:

Raw request
  -> Reality Constructor
  -> provenance-bound transition packet
  -> General Transition Membrane
  -> registered Launcher authority
  -> plan-bound, single-use token
  -> guarded executor
  -> postcondition proof

It has tested important behaviors: ambiguous resume requests stop for clarification; contradictory context blocks transition; missing or reused tokens are rejected; authority denial blocks execution; and postcondition mismatches are recorded.

That proves a transition shape. It does not prove universal live wiring.

Conservation and Replay

No-Loss Continuity is established as a governing conservation principle, with separate artifact-level implementation.

Its rule is simple: no meaningful transition may sever identity, provenance, lineage, typed prior-to-resulting references, cause, source revision, or governing policy.

Noise can be discarded. Meaningful lineage cannot.

In C10's governing model, canonical state is replay-derived from append-only evidence:

Proposal event
  -> toll decision
  -> canonical edge update
  -> append-only audit record

A workbench or read-only shell may consume that graph. Displaying it does not make the interface a canonical mutation surface.

Projection Is Not Authority

C10's computational architecture distinguishes the canonical graph from its projections:

Canonical graph
  -> Lens
  -> Emitter
  -> materialized semantic objects
  -> widgets / UI

A lens interprets the graph for a purpose.

An emitter materializes that interpretation into usable objects.

Widgets consume those objects.

Widgets do not reach upward into the graph to invent semantics.

Projection outputs are ephemeral by default. They become durable only through explicit lawful promotion.

Activation Layer v1 is specified as a separate responsibility for interaction context, salience, usage, and recurrence signals. It is not semantic judgment or admission.

It may surface that something keeps returning. It may reveal convergence signals. It may not decide that something is important, equivalent, necessary, proposal-ready, admitted, or canonical.

From Observation to Governed Change

C10's proposed change model is:

Observation
  -> Perturbation
  -> Proposal
  -> Decision
  -> Implementation

An idea can be published as a perturbation. It can recur, attract attention, and gather evidence.

That does not automatically create an implementation task, admitted object, or final decision.

Recurrence is attention, not authority.

Candidate S1FT is specified as the recurrence-to-convergence responsibility. It is not a live operating authority today.

ECO, Radius, and Work Control

ECO, or Economy Flight, is a constrained pre-pass before work expands. It scopes a request, reduces unnecessary movement, and preserves the smallest lawful next action.

It is useful operating tooling. It is not constitutional authority.

The Work-Claim Gate is a separate mechanical session-ownership layer for protected artifacts. It does not grant semantic authority or mint permanent ontology.

The Tag Toll and scoped registries are designed to route work and reveal unresolved ownership. They are probes and controls, not licenses to create durable meaning by label alone.

Radius is an integrity and provenance observation lens. Its current output is narrower than a universal scoring system: it provides a crossings-per-claimed-task ratio and evidence pointers.

Radius does not create standing, repair missing evidence, score importance, or mutate source material.

What C10 Refuses

C10's governing architecture refuses several shortcuts:

  • A raw request is not authorization to create persistent state.
  • A UI, widget, report, lens, or activation signal cannot grant itself authority.
  • Repetition cannot become importance or admission by repetition alone.
  • An artifact crossing cannot silently amend the constitution.
  • A local prototype cannot be called live integration merely because it is tested.
  • A label, date, or frequency pattern cannot mint canonical lifecycle meaning.
  • A readable runtime projection cannot replace ratified governing law.
  • A receipt is not a conclusion; it is evidence that a specific crossing occurred.

Where broader integration is not yet live, these are required governing constraints, not a claim that every C10 surface already enforces them.

Current Standing

SystemCurrent standingWhat that means
Constitutional membraneEstablished and authoritativeExecutable enforcement and admission/replay evidence in its domain
Artifact membraneSeparate working prototypeExecutable artifact controls; not proof of universal live wiring
Readiness membraneStaged / partialEvidence and review support; not a general admitting engine
General Transition Membrane v3Local, tested, dry-run guardedNot live-wired or durable shared state
No-Loss ContinuityEstablished principleSeparate artifact-level implementation preserves meaningful lineage
Activation Layer v1Specified separate responsibilityInteraction and salience; not semantic judgment or admission
Work-Claim GateMechanical ownership layerControls protected-session ownership, not semantic authority
RadiusIntegrity observation lensRatio and evidence pointers; no scoring, authority, or mutation
Candidate S1FTSpecifiedNot yet a live recurrence-to-convergence authority

The Point

C10 is not claiming that a finished universal machine already exists.

It is establishing the architecture that prevents a system from mistaking its own outputs for truth; proving narrow paths where that architecture already runs; and keeping the remaining gaps visible instead of hiding them behind polished interfaces.

Its aim is to transform reality into usable capability without allowing the transformation process to falsify its own legitimacy.

Semantic reality, governance, and computation remain distinct.

Lineage is preserved rather than overwritten.

Every meaningful durable change must have a source, route, authority, executor, and proof.

The membrane does not stop work.

It makes work explainable, attributable, replayable, and lawfully connected to what came before.

What Each Part Means for C10

This is Part 2: an explainer and FAQ companion to "C10: The Membrane Is How Reality Becomes Capability."

C10 is not trying to make every idea immediately actionable. It is trying to make sure that an idea can become action without losing the reason, evidence, authority, and history behind it.

Each part exists because a normal workspace has a predictable failure mode: a request, interface, repeated idea, or confident person quietly becomes more authoritative than it should be.

Reality Constructor

What it does

The Reality Constructor turns a raw request into a provenance-bound transition packet.

Instead of treating "continue this," "make this official," or "build that next" as self-explanatory commands, it captures what is actually being requested, what it came from, and what kind of change it would create.

What this means for C10

C10 does not have to guess what a vague request means. It can distinguish:

  • an observation from a request,
  • a request from a proposal,
  • a proposal from an authorized action.

Why it benefits C10

It stops ambiguity from becoming hidden action.

A human or AI can say, "continue the work." The Reality Constructor forces the system to ask: continue which work, against what evidence, with what authority, and toward what resulting state?

Current standing

This exists inside the narrow, local General Transition Membrane v3 slice. It is not yet the universal intake path for every C10 surface.

General Transition Membrane

What it does

The General Transition Membrane examines a transition packet before anything durable happens.

Its job is not to approve work. Its job is to determine what must happen next for the request to proceed lawfully.

Its tested outcomes include:

  • route the request,
  • request clarification,
  • require stronger evidence,
  • escalate to a relevant authority.

It does not declare itself the authority that can approve or grant a change.

What this means for C10

The membrane gives C10 a place to stop unsafe shortcuts.

If a request is ambiguous, contradictory, missing evidence, or attempting to reuse an authorization token, the system can stop there instead of pretending the request was clear enough.

Why it benefits C10

It prevents the most dangerous form of automation: software acting confidently on language that was never specific enough to authorize the action.

It also allows C10 to grow across domains without making every tool its own private authority system.

Current standing

General Transition Membrane v3 is a narrow local, tested, dry-run-guarded slice for Launcher-shaped transitions. It is not live-wired into the broader Launcher or ECO workflow, and it is not yet durable shared state.

Applicable Domain Authority

What it does

The Applicable Domain Authority decides whether a proposed change is legitimate within its own domain.

A constitutional change, an artifact change, a work-session claim, and a UI projection do not follow the same rules. The authority layer determines which rule set applies.

What this means for C10

C10 does not use one vague "approval" button for everything.

Instead, it can ask:

  • Is this a constitutional decision?
  • Is this an ordinary artifact crossing?
  • Is this only an interface action?
  • Is this a session-ownership issue?
  • Does this require explicit human approval?

Why it benefits C10

It prevents authority laundering: a small local mechanism pretending it has the right to decide something larger.

A UI can request a change. A report can recommend a change. A prototype can demonstrate a change. None of them automatically gains the authority to ratify it.

Current standing

The constitutional authority path is established. The broader general-authority routing model is proven only through the local v3 slice.

Transition Executor

What it does

The Transition Executor performs the action only after the correct authority has authorized a bounded plan.

In the v3 model, execution is tied to a plan-bound, single-use token. A token cannot be reused to perform a second action or quietly expand the first one.

Persistent-state creation requires explicit human approval.

What this means for C10

C10 separates deciding from doing.

The component that proposes a change does not execute it. The component that executes it does not redefine the plan while acting.

Why it benefits C10

This makes actions accountable.

Instead of saying, "the system did something," C10 can eventually show:

  1. what was requested,
  2. what authority allowed it,
  3. what exact action was permitted,
  4. what actually happened.

Current standing

The executor is proven only in the local, dry-run-guarded v3 transition slice. It is not a general live execution layer.

Postcondition Proof

What it does

Postcondition Proof checks whether the resulting state actually matches what the plan authorized.

If a result differs from the intended result, that mismatch is recorded instead of hidden.

What this means for C10

Success is not "the executor said it ran."

Success means the resulting state can be compared against the promised state.

Why it benefits C10

It turns automation from assertion into evidence.

Without postcondition proof, a system can claim it completed a task even when it created the wrong file, changed the wrong object, or produced an incomplete result.

Current standing

Mismatch and failure states are tested in the local v3 slice. This is not yet a universal verification system for every C10 workflow.

The Three Layers

Reality Layer

What it does

The Reality layer holds what was observed, claimed, related, proposed, or crossed.

A claim can have a statement, scope, and confidence. Confidence should point back to provenance rather than functioning as an unexplained score.

Why it benefits C10

It gives C10 a durable way to preserve what happened without prematurely deciding what it means.

A claim can exist before it is accepted. A pattern can exist before it becomes important. A proposal can exist before it becomes law.

Governance Layer

What it does

The Governance layer determines how something can move from "present in the system" to "legitimate and durable."

This is where membranes, authority, work claims, tolls, proposal rules, and continuity requirements belong.

Why it benefits C10

It protects the system from its own outputs.

Without governance, every useful signal slowly becomes treated as fact, every interface option becomes treated as permission, and every repeated request becomes treated as a priority.

Computation Layer

What it does

The Computation layer interprets and presents the system through lenses, emitters, reports, projections, and interfaces.

It is how C10 becomes usable without allowing usability tools to rewrite the meaning of the underlying system.

Why it benefits C10

The same underlying reality can be viewed through different purposes: planning, review, work coordination, history, or evidence, without each view inventing its own truth.

The Membrane Family

Constitutional Membrane

What it does

The constitutional membrane is the established authoritative route for changes to governing law.

HYP0 eligibility
  -> applicable membrane
  -> ratification / P0N5
  -> receipt and replay evidence

What this means for C10

C10 has a real path for distinguishing a governing decision from a suggestion, note, interface state, or temporary work artifact.

Why it benefits C10

It protects the system's core rules from casual editing or silent reinterpretation.

A constitutional rule cannot become real simply because someone wrote it persuasively, repeated it, or displayed it in a runtime surface.

Current standing

Established and authoritative, with executable enforcement and admission/replay evidence in its constitutional domain.

Artifact Membrane

What it does

The artifact membrane governs ordinary artifact crossings through a separate prototype path.

Its key rule is:

No record means no crossing.

What this means for C10

Files, artifacts, and ordinary work outputs can have their own accountable transition path without being confused with constitutional law.

Why it benefits C10

It makes artifact changes traceable. A file does not become official merely because it exists, and an artifact receipt does not silently rewrite governing doctrine.

Current standing

A separate working prototype with executable controls. It is not proof that every C10 artifact or app is already live-wired through it.

Readiness Membrane

What it does

The readiness membrane checks whether there is enough context, evidence, and coherence to move forward.

It can identify that something is incomplete or not ready.

What this means for C10

C10 can distinguish "this is worth reviewing" from "this is ready to become durable."

Why it benefits C10

It prevents premature promotion. A promising idea does not need to be rejected, but it also does not need to become official before the necessary evidence exists.

Current standing

Staged or partial. It is not a general admitting engine and does not have final authority.

Continuity, Evidence, and Replay

No-Loss Continuity

What it does

No-Loss Continuity is the rule that meaningful transitions must preserve identity, provenance, lineage, cause, source revision, governing policy, and typed links from prior state to resulting state.

Noise can be discarded. Meaningful lineage cannot.

What this means for C10

C10 should not "clean up" a system by destroying the history needed to understand how it became what it is.

Why it benefits C10

It makes correction possible.

If a later decision is wrong, C10 can trace what led to it, what authority permitted it, and what must be repaired, rather than treating the latest version as though it appeared from nowhere.

Current standing

Established as a conservation principle, with separate artifact-level implementation. It is not yet proof that every C10 surface has full end-to-end continuity protection.

Receipts and Replay

What they do

A receipt records that a specific crossing occurred. Replay reconstructs state from recorded evidence rather than relying on memory, interface appearance, or a person's summary.

What this means for C10

C10 can eventually answer, "How did this become true here?" with an evidence trail instead of a story.

Why it benefits C10

It makes review, audit, recovery, and disagreement possible without requiring everyone to remember the same history.

Current standing

Constitutional P0N5 replay and artifact-chain replay have been demonstrated. This is not yet a universal live graph-replay engine across C10.

Lenses, Emitters, Projections, and Activation

Lens

What it does

A lens interprets the canonical graph for one purpose.

For example, one lens may show unresolved work, another may show evidence gaps, and another may show a person's current operating context.

Why it benefits C10

C10 can look at the same underlying reality from multiple useful angles without changing the source material every time a new view is needed.

Emitter

What it does

An emitter turns a lens's interpretation into materialized semantic objects that an interface can use.

Why it benefits C10

It creates a clean handoff between meaning and presentation. The UI receives usable objects instead of inventing its own interpretation of raw graph data.

Projection and Widgets

What they do

A projection is the rendered result of a lens and emitter. Widgets and interfaces consume that projection.

They are not authorities.

What this means for C10

A dashboard can show a task, a relation, a recommendation, or a status without gaining the right to declare that object canonical.

Why it benefits C10

It prevents interface authority laundering: the common mistake where something looks official because it appears in a polished UI.

Activation Layer v1

What it does

Activation is specified as the layer for interaction context, salience, usage, and recurrence signals.

It can notice that something keeps returning or that multiple threads are converging.

What it does not do

It does not decide that a thing is important, equivalent, necessary, admitted, proposal-ready, or canonical.

Why it benefits C10

C10 can remain responsive to what people actually use and revisit without confusing attention with truth or authority.

Current standing

A separate architectural responsibility, not semantic judgment or admission. Broad shared-runtime wiring is not being claimed.

From Observation to Change

Observation

An observation is something noticed, recorded, or encountered.

Benefit: C10 can retain a signal without treating it as a commitment.

Perturbation

A perturbation is a low-commitment signal introduced into the system: a post, thought, experiment, test, or visible pattern.

Benefit: An idea can gather response and evidence before it becomes a proposal.

Proposal

A proposal is a bounded candidate for change.

Benefit: It makes the intended change reviewable instead of leaving it embedded in vague conversation.

Decision

A decision is an authorized determination about the proposal.

Benefit: It identifies who or what had the right to select, reject, defer, or request stronger evidence.

Implementation

Implementation is the actual authorized execution of the decision.

Benefit: It makes the difference between "we discussed it" and "the system changed" visible.

Candidate S1FT is the specified future responsibility for recurrence-to-convergence work: helping C10 recognize when recurring signals may deserve a bounded proposal.

It is not yet live authority.

ECO, Work Claims, Tolls, and Radius

ECO: Economy Flight

What ECO does

ECO is the constrained pre-pass before work expands.

Its sequence is:

  1. Receive a scoped request.
  2. Identify the smallest relevant context and boundary.
  3. Avoid unrelated movement, premature expansion, and unnecessary state creation.
  4. Find the smallest lawful next action.
  5. Hand off only what actually needs to move forward.

What this means for C10

ECO does not try to solve the entire project at once. It prevents C10 from paying for movement before it knows the movement is necessary.

Why it benefits C10

It keeps the system from becoming expensive, noisy, and self-distracting.

Economy does not mean "do less." It means every expansion of scope should pay for itself through evidence, necessity, or a clear objective.

Current standing

ECO is useful operating tooling and a constrained planning pre-pass. It is not constitutional authority, and it is not yet honestly Membrane-gated through the general v3 path.

Work-Claim Gate

What it does

The Work-Claim Gate is a separate mechanical layer for session ownership over protected artifacts.

It answers a practical question: who is currently allowed to work on this protected thing?

What this means for C10

Two people, agents, or processes should not quietly assume they own the same work at the same time.

Why it benefits C10

It prevents conflicting edits, duplicated work, and invisible ownership confusion.

It also keeps session control separate from semantic authority: being allowed to edit an artifact does not mean being allowed to define system truth.

Current standing

A separate mechanical session-ownership layer, not a general semantic authority engine.

Tag Toll and Scoped Registries

What they do

Tag Toll and scoped registries make labels, work categories, ownership claims, and unresolved areas visible and accountable.

A tag can identify or route something. It cannot create permanent ontology merely by being attached.

What this means for C10

C10 can use labels to organize work without allowing labels to quietly become canonical facts.

Why it benefits C10

It exposes unresolved ownership and prevents a category from becoming "real" simply because it appeared repeatedly in a task list or interface.

Current standing

Separate controls and probes. They are not licenses to mint durable meaning or authority.

Radius

What Radius does

Radius is an integrity and provenance observation lens.

Its current job is narrow: it compares work that claims formal significance with evidence that an actual crossing occurred. Its output includes a crossings-per-claimed-task ratio and evidence pointers.

What this means for C10

Radius can show the difference between:

  • "we say this work passed through governance," and
  • "there is recorded evidence that it did."

Why it benefits C10

It catches theater.

A team can have many labels, tasks, reports, and claims of rigor while very little work has actual evidence of passage. Radius makes that gap visible.

It does not judge whether work is good, important, smart, valuable, or complete. It only asks whether the claimed level of formality has matching evidence.

What Radius does not do

Radius does not:

  • score people,
  • create authority,
  • repair missing receipts,
  • decide importance,
  • mutate source material.

Current standing

An integrity and provenance observation lens. Richer relationship or status behavior remains specified rather than current output.

The Benefit to C10 as a Whole

Together, these parts give C10 a way to be ambitious without becoming careless.

C10 can welcome raw ideas, pattern recognition, AI assistance, interfaces, experiments, and fast-moving work.

But it does not need to let any of those things silently become authority.

The result is a system that can answer five questions about a meaningful change:

  1. What happened?
  2. Where did it come from?
  3. Who or what had authority to allow it?
  4. What exactly was executed?
  5. What evidence shows the result?

That is how C10 turns reality into capability without losing reality on the way.