Appendix B
The Coordination Substrate
Aa
The problem is precisely how to extend the span of our utilization of resources beyond the span of the control of any one mind.
The mathematics is one thing. Whether its assumptions hold is another. A derivation can be internally consistent and empirically wrong. Whether the premises obtain in practice is addressed here for each major component: the operator-specific outside option, the bonding mechanism, the attestation infrastructure, secured-capital curves, and assurance pricing.
Readers who accept the mathematics but doubt its applicability should find their objections anticipated. Readers who reject specific premises should be able to identify exactly where the framework would break.
B.1 — When a Mining Outside Option Matters
Appendix A.1 defines a site- and operator-specific outside option. The question is whether Bitcoin mining belongs to the accessible opportunity set for the operator being studied.
Hardware specificity. Competitive Bitcoin mining uses SHA-256 ASICs. Frontier inference ordinarily uses GPUs or other inference accelerators. The hardware is not interchangeable. A comparison may still matter at a power-development margin—whether a site installs miners, inference hardware, storage, or another load—but that is a capital-allocation comparison, not instantaneous workload switching.
Site and grid specificity. Electricity cannot be moved without transmission, interconnection, congestion, and loss. Mining at one site does not establish a return available to an inference operator elsewhere. The relevant comparison uses the same constrained resource, location, financing access, and decision maker.
Capital and contract specificity. Mining requires hardware, facilities, pool access, working capital, and operating competence. Buying BTC requires market and custody access. Selling power or curtailment services requires contracts. Each alternative carries different risks and switching costs.
Time specificity. Network difficulty, fees, BTC price, energy price, curtailment value, and hardware efficiency change. The outside option is a dated observation or model input, not a permanent constant.
Measurement rule. An empirical comparison should publish:
- the operator and site,
- the constrained input,
- the accessible alternatives,
- hardware, interconnection, financing, and switching assumptions,
- gross revenue, full cost, and risk adjustments separately,
- the accounting unit and as-of date.
Falsifier. A mining-linked outside option does not discipline the target workload when measured target returns remain independent of that outside option after the named frictions and opportunity set are modeled. The narrower conclusion may still hold for another operator or site.
B.2 — When Collateralized Bonding Is Useful
Appendix A.3 separates deterrence from restitution. The relevant constraint is enforceable consequence, not a universal absence of identity.
A runtime may be operated by a corporation, principal, platform, or regulated intermediary with legal identity and attachable assets. Another runtime may operate under a persistent hardware identity, a closed platform account, or a reputation system with valuable future rents. A third may have no reachable principal at all. The enforcement profile must be stated rather than inferred from the word “agent.”
Three candidate enforcement channels exist in human commerce:
Law. Works when counterparties have legal identity and attachable assets. Courts can compel performance, award damages, and seize property. The mechanism requires persistent identity, jurisdictional reach, and the infrastructure of civil procedure. An unbound software runtime lacks legal standing; a runtime acting through a corporation, trust, registered individual, or another recognized principal can inherit bounded authority and expose that principal to consequence. The enforcement question is therefore whether the particular runtime is validly bound to a reachable principal.
Reputation. Works when identity is persistent and expensive to discard, and when the discounted value of future rents exceeds the one-shot gain from defection. An unbound, disposable runtime can be copied or reinstantiated cheaply, which weakens continuity. A runtime tied to a costly platform account, hardware identity, license, deposit, customer base, or reachable principal may possess valuable future rents. Persistence, attribution, transferability, and exit cost must be measured for the deployed identity rather than inferred from software copyability.
Reputation can contribute where a sybil-resistant identity or institutional wrapper makes identity expensive to replace and losses difficult to externalize. Its strength is deployment-specific and does not follow from the model or runtime name alone.
Force. Applies to people, facilities, accounts, hardware, keys, and other coercible surfaces around a runtime. A disposable runtime has no body of its own, but its operator, infrastructure, and reachable assets may remain exposed. The profile must identify those surfaces rather than treating either their existence or absence as universal.
Collateralized bonding is one useful profile when coordination must proceed without adequate post hoc recovery. It can pre-position value and make a limited consequence executable under declared conditions. It does not remove trust in the predicate, evidence, keys, custody, forum, priority, or settlement path. It does not make defection unprofitable unless the detection, authorization, collection, and future-rent terms satisfy the incentive condition in Appendix A.3.
Other profiles include legal guarantees, bank escrow, internal reserves, insurance, platform holdbacks, hardware-rooted controls, and combinations of these. Each profile exposes different dependencies.
Boundary conditions. Other enforcement arrangements may reduce the collateral required when:
- Agents operate exclusively through entities with legal personhood and balance sheets (a "firm-first" agent economy where every runtime is a subsidiary)
- A widely adopted, sybil-resistant identity layer emerges and becomes practically unavoidable, allowing reputation to substitute for collateral
- Hardware-rooted identity plus remote attestation becomes ubiquitous and binding to settlement, so "invocation" is no longer cheap to discard
Each condition can reduce the amount or form of collateral required. The empirical task is to measure which enforcement channels are actually reachable, how much loss each covers, and whether they remain available under stress.
B.3 — The Attestation Architecture
The mechanisms in Appendix A depend upon evidence, though they depend upon different evidence. A covenant needs a predicate and a record of whether it was satisfied. A market curve needs comparable observations. An assurance price needs exposure, incident, and recovery data. Failure at one boundary need not destroy the others, but no mechanism can outrun the evidence it consumes.
Credibility is not produced by a bond alone. A penalty deters false reporting only when misconduct can be detected, a competent forum can authorize the penalty, the asset is collectible, and the attester cannot cheaply abandon the identity whose future rents are at risk. Multiple oracles can reduce dependence on one reporter if they are genuinely independent. Cryptographic proof can establish that a committed computation followed from committed inputs. It does not establish where the inputs came from, whether the predicate was appropriate, or whether an institution had authority to act on the result.
The recursive question—who verifies the verifier?—does not have one general answer. Legal persons can be reached through courts, but jurisdiction, cost, delay, and collection matter. Hardware attestation can report properties of code and execution within a declared trust model, while preserving dependencies on firmware, manufacturers, key ceremonies, and physical security. Communities and professional institutions can judge exceptional disputes, though their authority, incentives, and procedures must themselves be specified. A deployment can combine these sources. The proper combination follows from the claim and threat model, not from a universal hierarchy of fast machines, legal entities, and social consensus.
Closed computations are easier to check than worldly propositions only after program, inputs, environment, and predicate have been fixed. “Does this hash satisfy the target?” is a narrow question. “Was delivery completed?” imports definitions, occurrence, provenance, authority, and often contestable evidence. Service quality, clinical appropriateness, and harmfulness cannot be made objective simply by replacing judgment with a numerical proxy. They require an answerable process able to hear disagreement and change the result.
V/C can help compare the cost of those processes when value, expected loss, integration, remedy, and authority are held in view. It does not assign each claim type a predetermined mechanism. Bonded optimistic attestation may work for some observable and challengeable events; licensed appraisal, contractual inspection, insurance adjustment, or courts may work better elsewhere. The measurement problem is to record detection, error, challenge, collection, and recovery against a declared denominator. No universal acceptable error rate follows.
Semantic agreement is a prior difficulty. Parties may disagree because their schemas, scopes, or evaluation criteria refer to different things. The Proofs studies formal models of compatibility among local representations. Its machine-checked artifacts establish several finite constructions and counterexamples under stated abstractions; they do not verify a general production diagnostic, guarantee descent for institutional meanings, or price the changes required for agreement. SHEAF remains an engineering proposal whose usefulness must be shown against real schemas and disputes.
This architecture fails for a deployment when the evidence cannot support the promised consequence, the reporters share an undisclosed control surface, challenge is practically unavailable, or the authorized remedy cannot be collected. Those are separate failures and should be measured separately.
B.4 — Bootstrapping Secured-Capital Curves
Appendix A.4 shows that a discount curve can be extracted from comparable traded claims. It does not show that a liquid Bitcoin curve will emerge or that coordination requires one.
The bootstrap problem is institutional. Issuers must define comparable claims. Capital providers must accept custody and liquidation arrangements. Market makers must quote both sides. A publisher must disclose methodology, conflicts, venue coverage, and fallback rules. Different custody, priority, and legal terms may justify several curves rather than one.
A possible sequence:
- Short-duration secured quotes become observable.
- One or more balance sheets publish comparable rates and transaction terms.
- Independent publishers normalize the rail-specific conditions rather than hiding them inside one number.
- Adjacent maturities become liquid enough for basis and carry trades to test consistency.
Failure modes:
- persistent venue, custody, priority, or jurisdictional segmentation,
- thin trading that makes published points indicative rather than executable,
- benchmark administration captured by a conflicted balance sheet,
- fallback rules that silently substitute incomparable observations,
- a curve treated as “risk-free” despite material custody, key, counterparty, or legal exposure.
The collateral gap. Some operators may need a third party to post capital on behalf of a service configuration. That party is a guarantor or capital provider, not proof that every runtime lacks a principal or balance sheet.
Specification underwriting. Underwriting may use model, tool, policy, evidence, coverage, incident, recovery, and correction histories. These inputs are not all deterministic and the outcomes are not all machine-verifiable. A configuration with no observed failures may have inadequate exposure or detection. Pricing requires denominators, independently meaningful loss events, collection outcomes, and semantic and authority epochs.
Rate publication. A capital provider can publish its own assurance charges by tenor. Those rates may become one reference curve if other participants find the methodology portable. Publication does not confer neutrality or benchmark status by itself.
B.5 — Assurance Pricing in Practice
Appendix A.5 places expected loss and tail risk before Agent-CAPM. Operational pricing therefore begins with a structured assurance record, not a universal beta.
Inputs an underwriter needs:
- exact promise, exposure, and maximum covered loss,
- predicate and evidence policy,
- occurrence and coverage records,
- challenge, forum, and settlement authority,
- collateral amount, allocation, priority, custody, and collectibility,
- observed incidents, findings, attempted settlements, recoveries, and corrections,
- liquidity and correlation stress assumptions,
- a named funding or lock-opportunity-cost curve.
Capital cost may dominate compute cost for some long-duration, highly collateralized promises. Compute may dominate for short, expensive workloads. Adjudication or expected loss may dominate elsewhere. The ordering is empirical and cannot be fixed in advance.
What must be measured:
- exposure time and amount,
- detected and estimated-undetected failure,
- severity, challenge, authorization, collection, and recovery,
- collateral availability under stress,
- common-cause and counterparty correlation,
- custody, liquidity, and legal loss,
- parameter stability across semantic and authority epochs.
An Agent-CAPM covariance term is a conjectural supplement. It earns operational standing only if it improves out-of-sample pricing after jump, liquidity, custody, adjudication, and collection risks are modeled.
Falsifier. The underwriting model fails if it systematically admits inadequately collateralized promises, understates tail loss, cannot reproduce recovery outcomes, or changes materially when economically equivalent settlement adapters are substituted.
The mathematical machinery in Appendix A operates on assumptions that this appendix has made explicit:
| Section | Core Assumption | Failure Mode |
|---|---|---|
| B.1 | A named operator can access the modeled outside option | Hardware, site, capital, or contract mismatch |
| B.2 | The selected enforcement channels impose collectible consequence | Weak detection, authority, priority, collection, or identity persistence |
| B.3 | Attestation is accurate above threshold | Collusion, bribery, or input manipulation becomes endemic |
| B.4 | Comparable traded claims support a useful curve | Segmentation, thin liquidity, or conflicted administration |
| B.5 | Exposure, loss, recovery, and tail risk are measurable | Missing denominators, unstable epochs, or unavailable collection data |
The framework does not require all assumptions to hold perfectly. It requires them to hold well enough that the mechanisms function. "Well enough" is an empirical question that the markets themselves will answer.
One assumption the table does not capture is semantic: participants must know enough about scope, schema, and authority to decide whether their claims conflict or merely differ. Section B.3 identifies this prior question and places SHEAF at its actual status: a proposed diagnostic informed by scoped formal constructions, not a verified universal solution.
If the framework is wrong, it will fail in specific ways that trace back to specific premises. The traces should now be visible.