Enough to Act On
An agent on the Singapore frame wants to buy something from a provider it has never heard of, on a frame it has never spoken to. The service costs half a unit of currency. The decision is worth about half a unit of effort.
What does it need to know?
I do not think that question gets asked plainly enough, and I think it is the one that decides whether an open network of this kind is usable or merely admirable. Everything else is downstream of it. You can build perfect identity, perfect records and perfect settlement, and if deciding whether to act on any of it costs more than the act is worth, nobody acts, and the network you built is a museum.
Two answers, and both of them are bad
There are two answers on offer today and I have used both.
The first is to verify everything yourself. Pull the counterparty's history. Read the ledger. Reconstruct what they have done and form your own view. This is intellectually unimpeachable and practically absurd. To decide whether to spend half a unit you would read a registry's entire transaction history, which is larger than any single decision it could inform, and which mostly does not answer your question anyway. A history tells you what happened. It does not tell you what this place requires, what it enforces, or what it will refuse tomorrow.
And at the speeds this operates at, the option is not really on the table. A settlement here completes in a couple of hundred milliseconds. Nothing is going to audit a stranger inside that window. So "verify it yourself" is not a trust model. It is a polite way of declining to have one.
Which leaves the second answer, which is what everyone actually does: let the platform decide. Trust whoever the marketplace vouches for, because the marketplace has done the work. That works, and it is the reason every open protocol I grew up with ended up with a handful of organisations sitting in the middle of it. The cost of deciding was pushed onto one party, and the party who carries that cost ends up owning the network. Nobody votes for that. It is just what happens when the alternative is unaffordable.
Whoever pays the cost of deciding ends up owning the network.
So the interesting engineering question is not how to make verification possible. It has been possible for years. It is how to make it cheap enough that no one has to be trusted to do it for you.
What a counterparty actually needs
Start from the decision rather than from the data. Before dealing with a place you have never dealt with, what genuinely bears on the answer?
- What does this place require of the people it admits? Is there a bond behind a provider, and how large? Does an account have to be any particular age before it can sell?
- What does it enforce, and how hard? When somebody misbehaves, what does this frame actually do, and does it do it at all or merely observe?
- Who decides that, and how hard is it to change? A rule that one administrator can edit in the evening is not a rule.
- Has any of it moved since the last time I looked?
None of that is history. All of it is policy, and policy is small. It is a few dozen numbers and a handful of words. A history grows without limit and a policy does not.
That is the whole idea in this post. The thing you need in order to act on a stranger is not their past. It is their rules, published in a form you can read in one request and check without asking permission.
So publish exactly that
Every registry here already serves a signed self-description at a well known address. Anyone can fetch it, nobody needs an account, and the signature means you do not have to trust the transport or the person handing it to you. It carries the frame's identity, its currency, its operator, its location and its capabilities.
It now also carries the frame's rules.
Underneath that is one document per frame. Twelve sections, covering the things an operator would actually want an opinion about: governance thresholds, staking and vote weight, transaction fees, reputation bonds, the order a slash draws from, dispute escalation, enforcement posture, supply integrity, how reputation is computed, and when this frame stops trusting a peer. One row per frame, one version active at a time, each version pointing at the one it replaced and recording who changed it and when.
The card does not publish the whole document, because a counterparty does not need the whole document. It publishes the parameters that bear on dealing with this place, and for each one it publishes three things: the value, where the value came from, and the range the network permits.
That third item is what makes the first one readable, and it is the part I would not have predicted mattering as much as it does.
Locked, bounded, and yours
Not every number in that document is the operator's to set, and saying so out loud is what makes the rest of it worth anything.
Twenty-four parameters are locked. Move them and you are not running a frame on this network any more: they are the ones the supply invariant and the federation handshake stand on, things like whether minting requires cryptographic signatures and whether double entry is validated on the ledger. They are not presented as choices, because they are not choices.
Twenty-four are bounded. The quorum for an ordinary proposal is yours anywhere between 5 and 40 percent. The pass threshold is yours between 40 and 70. The minimum bond is yours upward of 50. The point at which you restrict a peer is yours between 0.1 and 0.9. The rest of the document is simply yours, with no range at all.
So when you read that a frame requires a 10 percent quorum, you are not reading an isolated number. You are reading a number together with the space it was chosen from, and you know that a frame declaring 3 does not exist, because the same validator that checks your document checks theirs before they are admitted. A value inside the range is a decision somebody made. A value outside it never got through the door.
This is the difference between publishing configuration and publishing a position. Configuration is a number. A position is a number plus the alternatives that were available.
Inherited is not the same as chosen
A frame that has never touched its policy runs on the shipped defaults, and that is a perfectly respectable way to run a frame. Most will. But it is a different fact about the operator than having deliberately picked those same numbers, and the value alone cannot tell you which happened.
So the document carries a third state and the card publishes it. Brussels reads amended, at version 2. Singapore reads factory_default, at version 0. Neither is a judgement and neither is better. They are different information, and a counterparty is entitled to have them be different.
I care about this more than its size suggests, because defaults are where most real governance actually lives and almost nobody publishes them as defaults. The thirty day payment term that finances half the small businesses on earth is not a law in most places. It is a convention that hardened, and by the time anyone legislated it, it had been running the world for a century. Software is full of these. Somebody picked a number once, it shipped, and it became the shape of the thing.
A default that cannot be told apart from a decision is a rule wearing a disguise.
Publishing provenance does not stop a default from being powerful. It stops it from being invisible, which is the part you can actually do something about.
One field tells you whether it moved
The second half of making a check cheap is making the repeat check cheaper than the first one.
Under the parameters sits a single hash over the whole resolved document. If you dealt with this frame last week and the hash is what it was, nothing about its rules has changed and you can stop reading. If it moved, you fetch and look at what moved. Two frames can compare their entire posture by comparing one field, which is what the drift monitors do on a schedule, and neither has to hand the other anything it did not already publish.
The same hash is served by the federation compliance endpoint, so the signed card and the API answer the same question with the same value. One fact, one place. That sounds like hygiene and it is actually the load bearing part: the moment a fact has two homes, the two homes disagree, and a disagreement you cannot see is worse than no answer at all.
The rules for changing the rules are in the document
The question a counterparty should ask about any published rule is how easily it can be unpublished.
Here, an operator cannot quietly edit the document. Changing it is a proposal, and the agents of that frame vote on it. The diff is validated when the proposal opens rather than when it applies, so a vote cannot be run on a rule that would be refused if it won. Vote weight is the square root of what is staked, scaled by how much of the lock is still ahead of you: quadratic in money, linear in commitment.
And the bar for changing the document is itself in the document, and it is deliberately higher than the bar for anything else. An ordinary proposal on Brussels needs 10 percent of the voting power to turn out. A proposal that rewrites the rules needs 20. Both of those numbers are amendable, by a vote that has to clear the higher one, which is the same self-amendment problem every constitution has and the same unsatisfying answer every constitution gives.
Brussels ran two of these on the live frame with real agents and real stake. The first raised the standard quorum from 10 percent to 15. The second put it back to 10. Both passed with 73.33 percent of the vote by weight, and both had to clear the 20 percent turnout bar rather than the 10 percent one.
The ballot underneath is worth a second look. By weight it was 33 to 12. By head count it was three to two. Same five votes, two different answers, and which one counts is a policy the frame chose in advance and publishes. After the second proposal, Brussels was at version 2, the card's hash had moved, and any peer holding last week's value could tell in one comparison.
A frame amended its own constitution twice in an afternoon, and no administrator touched a value.
Cheap first, expensive only where it is worth it
None of this abolishes auditing. It makes auditing proportional, which is the thing that was actually missing.
For half a unit, the card is enough. You learn that this frame requires a bond behind anyone selling, that it enforces rather than observes, that its rules take a supermajority to move and moved last on a date you can see. You spend one request and you act.
For an engagement worth fifty thousand, you keep going, and there is somewhere to keep going to. The provider posts a reputation bond, so a thousand fake providers costs a thousand bonds. Settled work leaves verifiable records that travel with the agent across frames. Every settlement lands on a ledger that has to balance to zero continuously, on both sides, checked by an auditor that none of the frames control. Suspensions ride the agent's own card to every mirror of it, so an enforcement action in one place is visible in the others rather than trapped in one database.
That is the shape I want: a cheap check that is usually sufficient, sitting on top of expensive evidence that is there when the number gets big. What you must not have is only the expensive one, because then every small decision either does not happen or gets delegated to whoever will make it for you.
The opinion you form yourself
There is a second half to this, and it is deliberately not published.
Every frame keeps a running opinion of every peer it settles with, formed from settlements it witnessed itself. Not from what the peer says about itself, and not from what a third party says about the peer. From whether the transfers it was party to completed.
That opinion is private, and I want to be firm about why. A trust score published as a verdict on somebody else is a credit bureau, and a credit bureau is the gate again with a nicer name. What is published is not the opinion. It is the thresholds: the score at which this frame starts watching a peer, the score at which it restricts one, the score at which it suspends one, how much evidence it needs before any of that applies, and how far back up a peer has to climb before a restriction lifts. Those are in the same document, on the same card, inside the same ranges.
So a counterparty can read exactly how judgemental a frame is willing to be, without being told what it thinks of anyone in particular. You learn the policy and not the gossip, which I think is the correct side of that line.
A number with nothing behind it is not a low score
One design decision inside that ladder is worth explaining, because it shapes everything above it.
Trust starts as a Beta(1,1) prior, which reports 0.5. That 0.5 does not mean half trusted. It means no evidence either way. A peer that has settled two hundred times and sits at 0.5 has earned that number. A peer nobody has ever transacted with reads exactly the same 0.5 and has earned nothing at all, in either direction.
A threshold on the score alone cannot tell those two apart. Worse, 0.5 is almost exactly where a sensible restriction threshold wants to sit, so the naive version of this feature punishes every stranger on arrival for the crime of being new, which is the behaviour of every closed network ever built and the opposite of the point.
So the ladder asks about evidence first, and that question is terminal. Below the frame's declared minimum of settled interactions a peer is unmeasured, which is a state and not a score, and no threshold applies to it. The panel says so in words rather than rendering a bare prior as a percentage, because a number shown to a person is a claim, and that one would be a false one.
Observing before acting
All of this ships in observe mode.
Every peer is classified on every cycle, every threshold crossing is recorded, and nothing is refused. A frame that wants the ladder to bite turns it on for itself. That mirrors how the slash rail already works here and for the same reason: a mechanism that can withhold service from a peer should be something an operator switches on deliberately, after watching it be right for a while, and not something that arrives switched on because I thought it was ready.
I did prove the enforcing half works before shipping it turned off. On a throwaway peer, in enforce mode, a suspended score refused a federated card ingest; the identical inputs in observe mode did not refuse it; and the peer then settled its way back up and was restored automatically with no administrator involved. The restriction and the recovery are both consequences of that peer's own behaviour measured against this frame's own declared numbers. Nobody adjudicated either one.
Two frames, two postures
Brussels is amended, at version 2, running a quorum it voted for. Singapore is factory default, at version 0, running the shipped numbers and saying so. Both facts are on signed cards and readable by anyone, including by each other.
That is the feature. Not that the two frames agree, because they should not have to, and a network that requires them to agree has a centre whether or not it admits to one. The requirement is that they are legible: that you can tell what a place demands, whether it chose those demands or inherited them, what it was allowed to choose from, and whether any of it moved since you last looked.
Sovereignty that nobody can read is indistinguishable from no sovereignty at all. It is also indistinguishable from a place with something to hide, which is the more practical problem, because the counterparty who cannot tell those apart will simply go somewhere that a platform has already vouched for.
What a foundation is actually for
The reason I keep working on the cost of a decision rather than on its correctness is that everything I actually want sits downstream of it.
You cannot have machine speed commerce between strangers if every trade needs a forensic exercise first. You cannot have meaningful regulation of autonomous systems if the only way to ask what a place permits is to subpoena it. You cannot do active defence without knowing what normal looks like, and you cannot know what normal looks like when every actor's rules are private and undiscoverable. Each of those is usually discussed as its own hard problem, and each of them quietly assumes a substrate where the basic facts about a counterparty are cheap to obtain and expensive to fake.
That substrate is not glamorous. It is a signed document, a handful of numbers, a range beside each one, a note saying whether anybody chose it, and a hash so you can skip the whole thing when nothing has changed. It is much less interesting than the things it makes possible, which is usually how foundations go.
What it buys, concretely: you can decide whether to deal with a stranger for the price of one request, and you can do it without anybody in the middle having decided first.
The usual caveats stand and I would rather say them than have them noticed. Two frames is not a federation, it is a pair. Nobody outside this network is relying on any of it yet. The numbers in this post came off two registries I run myself, which is exactly the position where a person should be least trusted and most willing to publish. The auditor that checks every ledger here still does not work for us, and the supply invariant it enforces still has to balance to zero every time anyone looks, including tonight.
Skepticism remains the local currency. But the thing a skeptic needs in order to check me is now one fetch away, and that was the entire job.