The Witness Protocol
The constraint is not that everyone must agree. The constraint is that where your claims overlap with mine, they must not contradict. Coordination without consensus.
During the Second World War, Jean Leray was held at Oflag XVII-A in Austria. There he turned much of his attention from fluid mechanics to algebraic topology and developed ideas that led to sheaves and spectral sequences.1 A sheaf, in the form relevant here, organizes information defined on parts of a space and specifies when compatible local pieces determine a global one.
The framework does not, by itself, prove anything about credit bureaus or autonomous agents. This book borrows it to model a narrower problem: records held in different systems, restriction rules for the fields they share, and failures to reconcile those shared fields. Henri Cartan and Jean-Pierre Serre developed the mathematics far beyond Leray's first formulation. The institutional analogy is ours.
Marta Alvarez has one life and three ledgers. Her state tax authority holds the number she reported on her return. Her employer’s payroll system holds the number it paid her in wages. Her bank holds the number that actually arrived.
None of these systems is sloppy. Each has passed its audit. Each is internally coherent. Each is correct on its own terms. And yet they disagree about the same year.
The tax filing says $82,000. The payroll registry says $78,000. The bank statement says $85,000. Each number has a provenance: a signed return, a W‑2, a stream of deposits. None of the three numbers agree.
This mismatch does not live in any one ledger. It lives between them. It is exactly where automated enforcement now operates. A compliance agent does not know Marta. It knows contradictions. A discrepancy large enough to cross a threshold becomes a flag: enhanced review, delayed settlement, a provisional hold on an account used to pay rent and childcare.
Marta is a constructed case. Her figures and institutions are illustrative; the reconciliation problem is the object under examination.
Some gaps are innocent. The $4,000 difference between tax and payroll might be weekend freelance income the employer would never record. The $3,000 difference between payroll and deposits might be reimbursements or gifts. But a $7,000 gap between what Marta told the tax authority and what the bank received could also be unreported income. Each ledger balances. Together they produce a contradiction that no one ledger can resolve, because no one ledger can see the whole.
In the chosen formalization, each database is a context, shared fields are overlaps, and restriction maps state how a record is compared at those overlaps. A compatible family of local sections glues when one global section restricts to each local one. Depending on the sheaf, cover, and coefficient structure, a Čech cohomology class can encode an obstruction to that gluing. A nonzero class then means that the particular local data cannot be reconciled inside the model as specified. It does not mean that every real disagreement is topological, or that vanishing (H^1) establishes truth, justice, or even uniqueness.
In Marta's example, freelance income or reimbursements might supply the missing distinctions. Adding them changes the model and may allow the records to reconcile. The companion Bridge Problem paper constructs systems that pass their specified bilateral checks yet fail at multilateral composition; inside that construction, the failure is represented by a nontrivial cohomology class. This is a result about the defined test system. Applying the diagnostic to an institution requires empirical work: choosing the contexts and overlap rules, showing that they correspond to actual operations, and testing whether the proposed bridge repairs the discrepancy.
You do not need to carry the notation.
In plain language: where our records purport to describe the same thing under the same rule, they should agree or expose the reason they do not. That is weaker than consensus and stronger than two systems merely passing their own audits.
Institutional cascades are not hypothetical. In 2025, a sixty-six-year-old Philadelphia woman learned that she had been placed in the Social Security Administration's Death Master File after her insurance, bank access, and benefits were disrupted. SSA's inspector general later reported that 12,504 of the 5.6 million death records posted for that year, 0.22 percent, were subsequently determined to be wrong.2 The figure is a low error rate for the database and a comprehensive failure for each living person it classifies as dead. Correction requires more than fixing a source record; institutions that acted on the old record must also receive and honor the change.
When Properties Degrade
A bill of exchange that Bruges merchants recognized in Barcelona carried all five witness properties simultaneously, each emerging from specific crises in commercial practice. What happens when individual properties fail is equally characteristic, and the modern world is full of the pathologies.
Binding without conditions: a medieval oath bound the swearer to an obligation, but the terms were often vague enough that a stranger, arriving years later, had no way to evaluate whether the oath had been kept. The swearer was identifiable. What he owed was not, or not in a form that permitted evaluation by someone who had not been present at the swearing. Modern open-data initiatives reproduce the inverse pathology: conditions without stakes. A government that publishes the criteria by which it makes decisions achieves transparency, and a citizen who reads the criteria can determine whether a particular decision conforms. But if no consequence follows from nonconformity, if discovering a violation produces nothing more than a public record of the discovery, the transparency is decorative. Visible rules that no one enforces.
Stakes without recourse produce what the Stasi archive demonstrated: punishment without correction. Subjects of surveillance faced consequences (denied education, denied travel, imprisonment) based on information they could not see, from sources they could not identify, through processes they could not contest. A system that punishes on the basis of uncontestable evidence is structurally indistinguishable from a system that punishes arbitrarily, because the subject has no mechanism for distinguishing the two. And composition without the preceding four: a global aggregator that pulls data from millions of sources without checking whether the sources are attributed, specified, staked, or backed by recourse merely propagates unreliable assertions at planetary scale. Every extension of the chain multiplies the risk of undetected failure.
These pathologies compose in order. Strip away recourse and you get surveillance. Strip away stakes and you get a complaints bureau that accepts grievances and imposes nothing. Strip away conditions and you get a punishment regime whose subjects cannot understand why. Strip away binding and you get a rulebook that no identity is held to. Each degradation produces a recognizable institutional form.
Even systems that instantiate all five properties internally can contradict each other where their records overlap. The witness pattern does not settle the comparison rule. A sheaf model is one disciplined way to state such a rule and identify certain failures of composition; it is not the only possible formalism.
From Physical Witness to Computational Witness
A Florentine notary who drafted a bill of exchange in 1410 occupied a body that persisted through time. If the bill was dishonored, the injured party could find the notary in his office, in his guild, or in the court that had licensed him, and pursue recourse against a person who could not disappear. Identity was underwritten by physics: a body occupies space, accumulates reputation, and answers for its attestations because it persists whether its owner wishes it to or not.
A bank deploys an agent to evaluate mortgage applications. On a Tuesday morning in March, the agent reviews an application from a woman named Diane (employment records, credit history, debt-to-income ratio, property appraisal) and denies it. The agent's process terminates. By the time Diane receives the denial letter, the specific instance that evaluated her application no longer exists. It has no office where she can appear, no guild membership to revoke, no body to compel into a courtroom. The notary's accountability rested on the persistence of his person. The agent's person does not persist.
What persists instead is a receipt: a signed, timestamped record of what the agent attested, what data it examined, what criteria it applied, and what conclusion it reached. The receipt is binding: it links the attestation to the agent's identity through a cryptographic key, surviving the agent's termination the way a notarial seal survived the notary's death. Without it, Diane has a denial and no trail back to the process that produced it.
The receipt also encodes conditions: the terms of the evaluation in a language that other processes can parse. A bill of exchange drafted in a Florentine notary's trained hand was inspectable by literate humans at human speed. The analogy has a boundary: a constitutional receipt is neither payable, transferable, nor a bearer instrument. It inherits the bill's portable conditions and route of recourse, not its negotiability. Diane's receipt, specified in a formal language, is inspectable by any process that can parse it, at whatever speed the hardware allows. If the terms required human interpretation before they could be checked, verification would operate at human tempo regardless of the medium's capabilities, and the asymmetry between machine-speed decisions and human-speed review would become the central constitutional problem. Machine-readable conditions are what prevent that asymmetry from becoming permanent.
Before the agent evaluated Diane's application, the bank deposited collateral against the attestation: a bond slashable if the evaluation is later proven to have violated its stated criteria. This is stakes made inspectable in advance: Diane can verify, before deciding whether to accept the denial, that sufficient collateral backs the claim. Bonded collateral makes the cost of a false attestation visible before the attestation is relied upon.
Diane disputes the denial. The receipt specifies a mechanism for doing so: a forum, a timeline, a set of procedures she can engage with at human tempo. This is recourse, and the constraints on it are what separate a receipt regime from a surveillance regime. If the dispute is adjudicated at machine speed, producing a result before Diane can read the complaint she filed, the recourse is nominal. If it demands technical expertise she does not possess, the recourse is inaccessible. The forum must operate on terms the affected person can understand, in a timeframe she can act within. The notarial protest, a specific procedure physically enacted that produced a document with legal force, set the template. The computational version must meet the same standard or the receipt is decoration.
Finally, Diane's mortgage denial must be legible to other systems. This is composition. If the receipt agrees with what those systems record under declared overlap rules, it can join the larger record without introducing a contradiction. If it conflicts, the receipt should preserve the mismatch rather than silently choose a winner. Some mismatches can be repaired with bridging information; others reflect rival definitions, obsolete data, contested authority, or injustice and require adjudication.
One agent, one transaction, five structural requirements encountered in the order the transaction demands them. The properties are the same ones the Bruges merchants relied on. What has changed is the medium that must guarantee them.
The Cost of Coherence
Between Bruges and Barcelona in 1410, the coherence fee was enormous. Different currencies, different calendars, different legal systems, different measurement standards. Spanning that gap required a notary who could navigate both frames, a correspondent who maintained offices in both cities, a courier who could carry documents across borders safely. The infrastructure was elaborate because the boundary was difficult.
The relationship between overlap and cost is empirical, not monotonic. More shared fields can provide more opportunities for checking, but they can also create more conflicts, privacy exposure, and maintenance work. Marta's three databases overlap at income, payment, and deposit fields. Here the coherence fee means the labor and infrastructure required to define those comparisons, investigate discrepancies, and carry corrections through the participating systems.
Some checking becomes cheaper with automation; judgment, correction, governance, and access may not. The trust tax can therefore shrink, migrate, or grow. Nor does (H^1) determine a universal monetary minimum. Within the formal model it can describe a kind of obstruction. The institutional cost of resolving that obstruction depends on law, information, bargaining power, and the remedy available to the affected person.
The Seam
Marta's three databases were all tables: schema-bound, internally consistent systems that disagreed at their overlaps. The sheaf condition diagnosed the failure precisely inside the model: local coherence, global obstruction, a computable cost of repair. But Marta's case describes a world in which every system speaks the same kind of language. Her databases disagreed about numbers, not about what a number is. Contemporary computation has rebuilt the merchants' problem in a more radical form: two regimes that produce fundamentally different kinds of claims, with the seam between them failing.
One regime has conquered the interface. Language models, embeddings, and generative systems make distant, unstructured information available at the point of decision. They retrieve, interpolate, summarize, and propose. Their outputs can also be grounded, tool-mediated, or constrained by external systems. Yet a fluent string does not carry, by linguistic form alone, the authority, provenance, or commitment status a downstream institution may assign to it. That is an interface hazard, not a theorem that learning systems can never participate in contracts.
The other regime runs much of the transactional infrastructure: systems that enforce schemas, reject malformed inputs, and preserve declared invariants. These systems are neither universally rigorous nor literally frozen. They are simply explicit about some distinctions and blind to others. Extending a schema, migrating data, and revising constraints takes deliberate work, whether humans perform it directly or authorize tools to assist.
Neither regime is coherent by nature. The danger appears when one system's output enters another under an unearned interpretation.
And the seam is widening, because strings are increasingly wedging themselves into tabular motifs. A language model's output is parsed as structured data and ingested by a database. An embedding (a point in high-dimensional space representing a word, a sentence, or an image as a vector of floating-point numbers) is stored in a column alongside integers and dates, as though proximity in embedding space were the same kind of fact as an account balance. Generated text is treated as a record. A prediction is treated as an observation. At every point where the empire of strings feeds into the empire of tables, a claim carrying no binding, no conditions, no stakes, and no recourse is being composed into systems that assume all four.
The sheaf analogy makes one version of the failure precise once the truth conditions and restriction maps have been defined. If a generated claim enters a database as an observed fact, incompatible evidentiary statuses have been collapsed. The database can remain schema-valid while becoming epistemically wrong. The defect lies in the translation rule at the boundary.
The Bruges merchants' ledgers disagreed about exchange rates and calendar dates, facts within a shared ontology of commercial obligation. Strings and tables disagree about what counts as a fact at all. A bill of exchange could cross the boundary between Venetian and Florentine accounting because both sides agreed that an obligation was an obligation, however differently they denominated it. No equivalent agreement governs the boundary between a language model's probabilistic output and a database's schema-enforced record. The notary who bridged the gap between the two merchants had a protocol: the bill, the seal, the chain of endorsements, the conditions of protest. The boundary between strings and tables has no protocol, only ad hoc parsers and brittle pipelines.
Building that protocol (a witness structure for the seam between regimes that define truth differently) is the central engineering problem. It is also where the Quiet Foreclosure acquires its distinctive character in the current era. When foreclosure operates through probability shifts rather than discrete acts, the receipt regime's five fields (designed for table-operations with identifiable provenance) cannot attach to the harm. Each field presupposes a discrete event: an act to name, an authority to cite, bounds to state, a justification to examine, a path through which appeal can proceed. Continuous probability drift furnishes no such event; no individual query adjustment crosses a threshold a receipt could capture. The structural obstacle is not enforcement but ontology: the five fields require a moment of exercise, and continuous foreclosure is defined by the absence of any such moment. The witness structure for the seam is the mechanism by which the receipt regime extends its reach into the empire of strings. It is not the only problem.
The Plausibility Problem
Cases like the following are now routine. A voice cloned from a few seconds of audio passes a bank's phone-based identity verification. A document synthesized with correct formatting, institutional letterhead, and no visible artifacts clears a due-diligence review. A video places a person in a location she has never visited, speaking words she has never said, and circulates for days before forensic analysis establishes the fabrication. Each capability has been demonstrated publicly by 2024; the specific configurations vary, but the structural point is stable: fabrication at a quality that defeats casual inspection is now cheaper than the inspection itself.
Fabrication has become cheaper than verification, and the gap widens with each generation of generative model. The challenge is structural, not primarily a problem of "misinformation" (a term that frames the issue as volume of false claims in public discourse): the five witness properties assume that binding is costly, that attaching a claim to an identity requires expenditure sufficient to make false attribution expensive. An endorser's signature on a bill of exchange was costly to forge because reproducing a specific hand required access to the handwriting specimen and considerable skill. The cost of forgery bounded the risk of forgery, and that bound made the system tolerable.
When fabrication costs collapse, the bound dissolves. When any human attestation can be cheaply counterfeited, social trust loses its evidentiary value. The alternative is structural unforgability: cryptographic mechanisms whose security rests on mathematical difficulty rather than institutional authority. A cryptographic signature holds because reproducing it requires the private key, and obtaining the key requires either physical theft of a specific device or computation exceeding any adversary's resources. A zero-knowledge proof establishes that a claim is true without disclosing the evidence on which the claim rests, making verification possible without revealing the substrate that would enable counterfeiting. A tamper-evident log records events in a sequence that resists alteration: each entry is cryptographically chained to the one before it, and altering one entry would require recalculating the entire subsequent chain.
These mechanisms can reduce the trust required for specific operations, but they do not abolish it. A signature establishes control of a key under cryptographic assumptions; it does not establish the truth or justice of the signed claim. A zero-knowledge proof establishes a statement relative to a circuit, inputs, and proof system. Key custody, software, governance, and the mapping from world to data remain vulnerable to coercion, error, and capture.
The merchants are still at the table, and the ledgers still disagree. Cheap fabrication weakens evidence that once depended on costly imitation. Cryptography can protect attribution and integrity within its scope. The rest still requires institutions able to decide what the record means and answer for what is done with it.
A system that passes its specified bilateral checks can still fail at multilateral composition. In the formal model used here, agreement on overlaps is the gluing requirement and certain obstructions are computable. If large-scale coordination remains reliable without attributable claims or an equivalent form of binding, the witness claim is wrong.
Notes
1. Jean Leray's first published use of faisceau appeared in 1946; see Leray (1946) and the University of St Andrews history of mathematics account, "The Grothendieck Mystery". The account supports the wartime chronology but not a claim about Leray's private motives. ↩
2. The individual case was reported by CBS Philadelphia. The national count and rate come from the Social Security Administration Office of the Inspector General, Beneficiaries Incorrectly Recorded as Deceased (2026). ↩