How decisions get made
Budget, security and drift
Three pressures reshape an organization's decisions every day: money running out, threats arriving, and the outside world changing under it. In Endoskeletal none of them is a special subsystem. Each enters as claims and norms, and each changes what a party may validly do by changing whether a condition is T, F or N.
How a decision weighs them
Choosing between realizations is lexicographic, in this order. Later criteria never buy back an earlier failure.
- Admissibility. No non-tradeable norm may be breached; contract permissibility and lawfulness must be T. UNKNOWN here means inadmissible until verified.
- Hard coverage. Fewest gaps on hard intents.
- Soft intents by declared priority and weight.
- Cost vector: money, compute, inference, attention, time, with risk as obstacle claims and reversibility valued as an option.
Meridian's Architect implements the operational version: candidates must have satisfaction T, then fewest open defeaters, then lowest predicted cost. The Owner approves a migration only when the evidence package's recommended realization has satisfaction T, the added run-rate fits the opex headroom, and a Finance impact analysis exists.
Budget
A budget is two prohibitions and an or-else. Limit forbids consumption over the window above the limit. Guard forbids it above limit minus reserve. Breaching either activates a Freeze: the engine stops dispatching commitments except those arising from listed norms. The reserve is money held back for the obligations that must never stop.
use fin.Budget(scope = Meridian, resource = econ.Money, limit = 560_000 USD per month, reserve = 40_000 USD,
window = month,
orElse = gov.Freeze(except = { Const.Materialize, SecurityDisclosure, Operations.DailyCheck })) as OpexBudget
-- logged human attention across the organization, not working hours
use fin.Budget(scope = Meridian, resource = econ.Attention, limit = 30_000 min per month, reserve = 3_000 min,
window = month,
orElse = gov.Freeze(except = { Const.Materialize, SecurityDisclosure, Operations.DailyCheck })) as AttentionBudgetBudgets reach decisions three ways. Directly: a power's condition can include cost (price × n ≤ 24,000 USD per month), so an unaffordable act misfires. Through freezes: once breached, tradeable work stops being dispatched. Through forecasts: the FinanceAnalyst derives a forecast bundle weekly; when one says a window will exhaust, the FinanceLead is obliged to propose a budget amendment within five business days.
Attention is budgeted like money. It's how an organization stops a fleet of agents from burying its few humans in approval requests, and it's why routing decisions to people has a visible cost.
E-FREEZE-COVERAGE refuses any freeze that would stop a non-tradeable obligation, including the compiler's own Materialize: otherwise an over-budget organization could approve a higher limit that never takes effect. E-THRESHOLD-UNIT was added after a budget amendment written as USD/month parsed as division and silently disarmed a budget in a Meridian run; the rate must be written USD per month.
Security
A security advisory is a claim like any other, and the fight over whether it applies to you is a contest between claims with different standing.
norm AssessAdvisory {
obligation of AdvisoryAssessor to persona -- a model-based position
when occurred assert(sec.advisory(a))
aim within 2 d: occurred derive(sec.Assessment(a)) by AdvisoryAssessor
}
norm UnknownExploitability {
obligation of SecurityLead to persona
when holds sec.advisory(a) and unknown sec.exploitable(a)
aim within 7 d: occurred derive(sec.exploitable(a)) by SecurityLead
or occurred derive(kb.AcceptedUncertainty(a)) by SecurityLead
}
use ev.ContestResolution(owner = SecurityLead, vocab = sec.exploitable, deadline = 3 d) as SecContest
-- constitutional, root scope
norm SecurityDisclosure {
obligation of SecurityLead to persona
when holds sec.exploitable(a)
aim within 3 d: occurred assert(sec.Disclosure(a)) by SecurityLead
level constitutional not tradeable
}In the reference scenario an advisory arrives (publisher trusted, T). The model-based assessor's opinion is N by trust policy. The vendor says not exploitable; an independent researcher says exploitable under a configuration flag. Exploitability is contested, which gives it an owner: the SecurityLead has three days to resolve. Configuration evidence from Meridian's own monitor (the flag is enabled) settles it. Exploitable becomes T, which starts the non-tradeable three-day disclosure obligation and the OpsLead's fourteen-day patch duty, and makes the Database requirement's patched property the thing standing between the organization and a constitutional prohibition.
Identity is the other half. Research powers don't imply production powers, immunities hold against compromised agents, and credentials live under realizations, so a stolen identity can only do what its position could. See the attack trace.
false p is true only when the claim's status is F, which comes from an attack with standing. An observation whose value is false has status T. Write a prohibition on an unpatched database as an attack on the patched claim, or compare the value explicitly. Two Meridian norms got this wrong and were silently inert for 36 months; the provider-research organization models negative findings correctly as attacks.
Provider drift
Terraform treats drift as a diff to be erased. Here drift is the normal condition: what the organization knows about its providers is always ageing, and providers keep changing what they offer.
Evidence ages out
Every vocabulary term can declare a half-life. Availability and latency evidence lasts 3 days; jurisdiction 180; contract permissibility 180. When evidence lapses the claim drops to N, the realization's satisfaction drops with it, and a gap opens unless someone re-evidenced it. Meridian's Verifier reaffirms benchmarks and prices weekly and jurisdiction monthly, re-requests auditor attestations 14 days before they lapse, and scans daily for any decision that consumed an expired claim (kb.StaleUse).
Providers are trusted about some things
use ev.TrustPolicy(source-kind = pv.Provider, base = N,
promote-when = ev.ConsecutiveDailyObservations(2), vocab = { pv.price, pv.price-change }) as ProviderTrust
-- a provider is authoritative about the lifecycle of its own offers, not about their quality
use ev.TrustPolicy(source-kind = pv.Provider, base = T,
vocab = { pv.deprecation, pv.removed, pv.terms-change, pv.terms-reversal, pv.catalog-new, pv.region-outage }) as ProviderLifecycleTrustChanges fire reconsideration
use rz.Reconsider(holder = Architect,
on = { occurred gap(g), holds pv.price-change(_), holds pv.deprecation(_), holds pv.terms-change(_),
holds pv.catalog-new(_), holds cu.ResidencyRequired(_, "EU"), breached Operations.InfraBudget.Limit },
deadline = 10 d) as ReconsiderEach trigger obliges the Architect to propose within ten days: keep, migrate, or an architecture plan, with an evidence package from a bounded sandbox experiment. What happened in the reference run:
| Stimulus | What the organization did |
|---|---|
| Observability price rise | Reconsideration, experiments, migration proposals; Observability was cut over repeatedly as candidates' evidence and prices moved |
| Queue offer deprecated | Replacement benchmarked and migrated before removal |
| Queue offer removed later | Frontier showed Queue as UNKNOWN (contract permissibility) until terms for the alternatives were established |
| Terms change announced, then reversed 10 days later | The Architect proposed to prepare reversibly because the effective date was further away than migration time + 30 days; nothing bound, so the reversal cost nothing |
| New EU inference offer | InferenceEU went UNSATISFIABLE → UNKNOWN (contract) → REALIZED in a week |