The Context Graph
The computational backbone
Aa
Part V: Specification
A supplier's report can spare another organization an investigation. Suppose the report identifies a component revision and records measurements relevant to its fit in an assembly. The recipient has a different identifier for the component, but it can establish the mapping, inspect the reported procedure and compare the dimensions with its own drawing. It need not repeat adequate measurements merely because another organization made them.
Everything in this dossier is hypothetical. Assume that the report identifies the units measured, the revision and the measurement conditions; that its source can be authenticated; and that the recipient's declared qualification procedure permits reliance on such measurements when their coverage and quality meet its requirements. No industrial standard or actual certification practice is being described. The component's fit, its other properties and permission to install it remain separate questions.
Work done once becomes available to a second undertaking without transferring the laboratory that did it. But the recipient contributes something of its own: it establishes that the report concerns these units and this revision, that the mapping reaches the drawing used in this assembly, and that the earlier measurement answers the proposed comparison. Its conclusion is neither a duplicate of the supplier's assertion nor an achievement independent of it.
The Report and the Drawing
An identifier match can be sufficient for retrieving the right dossier and insufficient for approving the component. Suppose a catalog entry joins two revisions under one commercial name. The recipient must determine which revision the earlier report covered. If that mapping is missing, the measurement may be perfectly good and presently unusable for this qualification. The missing relation belongs in the result. Calling the component defective would answer a question the investigation has not settled.
With the mapping established and the required dimensional checks complete, the recipient can record the fit conclusion on its actual grounds. The record names the earlier evidence, the mapping, the receiving drawing and the checks performed here. Someone inspecting it can distinguish what was inherited from what the recipient added. A subsequent operation asking the same adequately supported question can reuse that work too.
Now consider a different proposed use. The assembly will operate under conditions for which the dossier provides no endurance evidence. The dimensional measurements still establish what they established; a good fit has not become a bad fit. The recipient has asked for an additional property. It must obtain grounds for that property or leave the wider qualification unfinished.
This is where an interface can do damage while appearing helpful. A field labeled “verified component” can turn a passed dimensional comparison into a general permission to use. A record of the predicate actually tested resists that promotion. Admission of a definition specifies which question the system will evaluate; registration records an identified assertion and the witness its contract requires; certification reports the checks that established an answer within their scope. Authorization to install the component is another decision. Neither the name of the field nor the completion of its form supplies that authority.
The proposed contracts make these distinctions available to the next operation. They do not require a particular database. A relational design, a graph or another representation can preserve the necessary links, versions and outcomes. Their adequacy depends on what the recipient can establish from them, including what happens when an essential record is unavailable.
A Check Left Open
Suppose the endurance evaluation is required and has not finished. The result is Inconclusive: this qualification lacks a completed check. That is an answer about the proposed reliance, not a test finding that the component cannot endure the conditions. An explicit negative result would require the evidence of a failed requirement. Another test may supply the evidence missing from this dossier. Until then, recording a failed endurance requirement would misdescribe what the recipient knows and why it has withheld qualification.
The unfinished result leaves the receiving organization with a decision about its own conduct. A required test may be waiting for equipment, a report may be unavailable, or no adequate method may yet be known. These situations need different further work. A status saying only “pending” gives the next recipient no way to distinguish them, and gives the institution no occasion on which it must reconsider what the delay is doing.
For the proposed qualification, the record must therefore identify what remains unestablished, what could resolve it and who is responsible for deciding how the matter proceeds. The decision deadline or review point belongs to the intended use: before installation, for example, if installation is the act awaiting qualification. It is not a promise that a test will succeed or that an unknown method will be invented in time. If the question remains unsettled, the institution must follow the declared process for postponement, another source of evidence or a separately justified course. Simply issuing the same pending status again does not establish the grounds for continuing that course.
This distinction matters beyond components. An institution may be unable to settle the factual question by the time it must decide whether a restriction can continue. The absence of an answer supplies no additional authority to impose the restriction. Its continuation needs its own grounds and timely review under the applicable process. A person can be owed a decision about the burden before anyone can give a final answer about the evidence.
A recipient can also produce independent grounds. It may test the relevant units itself under a procedure adequate to the intended use. That work can earn a qualification the original report could not supply. Assistance from the supplier remains valuable even if it did not answer the whole question: it may have established dimensions, identified a revision or reduced the investigation still needed. Reliance need not choose between repeating everything and accepting everything.
Nor does an unfinished ordinary check settle every action that an institution may legitimately take. A separate process could authorize temporary precaution, restricted use or another course on its own evidence. It must say what justifies that act and what remains outstanding. Describing the act as “certified” would conceal the missing ordinary check instead of explaining the different authority under which it proceeded.
The budget is part of this account. A receiving operation can record the work it has bought, the checks reused and the ones it cannot yet complete. It cannot count an abandoned requirement as a successfully performed check. A representation with fewer comparisons may cost less because it asks less. A21 accounts for a declared checking regime; it supplies no universal cost ordering to settle whether that change was an improvement. The useful question is which duties remain, and whether the intended reliance has grounds for each of them.
Some comparisons can be exact. Others concern estimates, samples or judgments made under a declared policy. Two measured values within a tolerance may support a legitimate acceptance procedure without being equal; matching confidence intervals do not become one measurement. The sheaf theorem applies to an exactly matching family in the specified mathematical structure. It does not convert this dossier's empirical evidence into a proof of the component's unobserved behavior. What the recipient can gain from statistical evaluation must be assessed under that evaluation's own assumptions.
What the Correction Reaches
A later correction tests whether the result carried enough of its grounds forward. Suppose a later dossier contains both the dimensional report and a completed endurance evaluation. One recipient used only the dimensions. Another conducted its own endurance test; a third relied on the supplier's endurance conclusion. What the correction requires of them will depend on those different grounds.
Suppose the supplier withdraws the endurance result because the evaluation used the wrong component revision. The accepted correction identifies the assertion, evidence and version, with the grounds and authority for changing its status. It does not refute the dimensional report simply because both concerned a component under the same commercial name. It removes the support that depended on the misidentified revision.
The recipient that relied on that support must cease to advertise it as current. It may not yet know whether the component will satisfy a fresh test. Its qualification on the withdrawn basis cannot continue while that question is answered. The recipient with an adequate independent test can retain its conclusion on those identified grounds, provided the correction did not also undermine that test's identity or procedure. Independence is a relation to examine, not a label that exempts a result from examination.
A dependency graph containing every mention of the component would be too coarse. It would treat an unaffected dimensional comparison, an independent experiment and a copied endurance assertion alike. The useful record says which premise each operation consumed. That information permits a correction to travel selectively, and makes a claim of no effect inspectable. Without it, someone must investigate the relation; the missing work cannot be settled by choosing a reassuring status.
The same discrimination governs changes that are not corrections. Retiring an old component definition can stop its use in new queries without making a past measurement false. Introducing a broader category can preserve a positive implication without preserving the answers to all earlier queries. A version number identifies the terms under which work was done. It does not guarantee continuing support for the work, and a newer number does not discredit everything produced under the old one.
The Work Beyond the Receipt
There is no assurance that every recipient has been found. Evidence may have been copied without its dependency record, a contact may be unreachable, or the receiving institution may not yet have examined the notice. A source correction can be complete at its own boundary while its consequences remain outstanding elsewhere. The record must name that boundary. Sending a message, receiving an acknowledgment and establishing a dependent conclusion are different completed acts.
Authority also has a boundary. A stranger cannot revoke the recipient's conclusion merely by submitting a withdrawal instruction. The applicable process must establish who may correct the record and on what grounds. A substantive challenge can deserve investigation even when its sender has no unilateral power to withdraw an assertion. If the required authority check is unfinished, the system must preserve that incompletion rather than pretend either that withdrawal was authorized or that the challenge was answered.
Finally, suppose an affected component has already been installed. Altering its qualification record does not remove it from the assembly. The correction may require an inspection, a replacement or another response; which response is warranted depends on the evidence and on an institution able and authorized to act. A record can identify the installation and show that the matter was referred. It cannot declare repair complete merely because the source field has changed.
The contracts developed in this part therefore reach beyond provenance without claiming to replace judgment. They require the receiving operation to identify the support it used, stop claiming support properly withdrawn, state the grounds on which a conclusion survives and disclose the work that remains. Retaining history is subject to purpose, access and retention obligations. Evidence of a defective decision must not become a new permission for indefinite adverse use against a person described in it.
The difference matters outside the dossier. In the Horizon appeals, an accounting discrepancy had been made to bear a criminal inference without the necessary investigation and corroboration. At Knight Capital, an attempted rollback spread the old behavior to servers that had received the correct update. Wormhole accepted purported verification of a message that lacked the grounds for acceptance; restoring the bridge's backing required a further act after the verification failure. These are failures described by evidence law, operational risk management and authentication. Their connection is the work entrusted to a later operation on the strength of an earlier one. Following that dependence tells us where a repair must reach and where a different institution must take over. Appendix I's incident correspondence gives the sources and the limits of each identification.
The context graph, identity discipline, predicate package, query contract and correction account specify the records and operations needed to carry this inquiry forward. Appendix I gathers their interface obligations after the worked account; it also states which related Bulla capabilities are actually supplied. These are contracts to assess and implement, not a claim that listing them has made a complete system.
Reuse is worth preserving because one institution's work can enlarge what another can do. The receiver's obligation is to preserve the terms of that inheritance while establishing what its own use adds. When the grounds change, it must change what it claims to have established. What it has already done may demand more.
Chapter 20: The Context Graph
How beautiful the world would be if there were a procedure for moving through labyrinths.
This chapter formalizes the context-graph substrate as Anchor A22: a typed data model with five node types (Context, Claim, Witness, Constraint, Equivalence), five edge types, and three operations (glue, restrict, transport) that together constitute one proposed storage model for the Third Mode. A22 reifies the machinery developed in Parts II through IV into a concrete specification that builders can implement. The reader seeking the narrative motivation for this substrate should consult Vol I, Chapter 7 (The Witness Protocol), where the data-modeling problem is introduced through worked examples rather than formal schema.
What the Dossier Must Retain
The supplier dossier needs several things to remain distinguishable: the claim, its evidence, the context in which it was checked and the operation proposing to use it. A22 gives those relations a storage model. It asks what a builder would have to retain for another operation to examine the earlier result.
The answer is a typed data model with five node types, five edge types, and three operations. The five kinds separate responsibilities in this specification. No minimality theorem excludes an equivalent encoding with fewer node kinds, additional kinds, tables or typed metadata.
What the Substrate Must Represent
Part IV defined operations: predicate invention (A17), invariant checking (A17b, A18), proposal and certification (A19, A19b), search (A20), and cost accounting (A21). These are formal specifications. A builder asks: what do I actually store?
The representation must retain locality, witness grounds, constraints and operation contracts. Relational, triple-based and property-graph encodings can represent these objects. Their presence still leaves the relevant checks to be implemented.
Each capability from Parts II–IV implies a storage requirement:
| Capability | Storage Requirement |
|---|---|
| Local truth | Claims scoped to contexts |
| Typed verification | Witnesses with class labels |
| Site structure | Contexts with refinement morphisms |
| Transport | Equivalences with certificates |
| Conflict detection | Contradictions with proofs |
| Cost tracking | Operations annotated with budgets |
The substrate is the reification of this machinery.
Anchor A22: Context-Graph Substrate
NODES (five types):
- Context(U): A view with signature , invariants , logic , absence policy per A12
- Claim(p): A proposition with content, status (asserted | retracted | pending), and timestamp
- Witness(): Typed per A2c as decidable | probabilistic | attested
- Constraint(c): Typed per A18 as integrity | semantic | computational | authority; enforced at assertion-time and glue-time. (We use to avoid collision with , the invariant set of a context.)
- Equivalence(e): Witnessed sameness per A10 with kind , scope , transport certificate per A16
EDGES (five types):
- supports(, p): Witness supports claim
- scoped_to(p, U): Claim is asserted in context
- refines(U, V): Context refines . We write when U refines V (U is finer than V; claims in V can be restricted to U).
- transports(e, p, p′): Equivalence transports claim to
- contradicts(, p, q): Proof witness establishes and are inconsistent
Note on hyperedges: transports and contradicts are ternary relations (hyperedges). In storage, they are reified as junction tables or edge-nodes linking three objects.
Note on entities and overlaps: Entities (the objects claims are about) are opaque tokens inside claim content. The substrate maintains an entity incidence index: for each entity term , record which claims mention and in which contexts. Incidence yields candidate overlaps: two contexts potentially overlap on iff both contain claims mentioning . Whether those mentions co-refer is determined by Equivalence witnesses (A10) and becomes binding only after identity maintenance (Chapter 21). The index is not a node type because entity tokens are supplied by the host system; the Third Mode supplies equivalence, transport, and identity maintenance over those tokens.
OPERATIONS:
- glue(cover, target): Attempts sheaf condition. Under a specified effective sheaf construction, returns a global claim with its gluing evidence; otherwise returns an established failure or an incomplete obligation. An unsat core applies only to a corresponding unsatisfiability problem.
- restrict(, p): Restricts claim from coarser to finer context (functorial action).
- transport(e, p, footprint): Transports claim along equivalence, checking property footprint per A16.
Why Contexts Are Nodes
In this encoding, contexts are first-class nodes because you need to store multiple logics, signatures, and invariants simultaneously and move claims between them via explicit morphisms.
A claim in the FDA regulatory view and a claim in the EU regulatory view are not the same claim with different labels. They concern different regulatory acts; their proof logics and absence policies need not differ. The constructed interlude in Part III shows why keeping the market argument matters. The substrate must preserve the market argument wherever the claim is compared or reused. A typed annotation can supply that structure if its consumers retain it.
Moving a claim between contexts requires the applicable comparison map. Substitution along an entity equivalence has a further A16 property contract and can occur within one context; it is not identical to restriction along a site morphism. This encoding keeps the context maps and equivalence certificates available to the operation that uses them. Tables or typed records can retain the same distinctions.
The Five Node Types
Context (U)
A context is a view with typed payload:
- Signature : the vocabulary available in this context
- Invariants : the constraints enforced in this context
- Logic : the proof rules valid in this context
- Absence policy : how this context treats missing data (CWA, OWA, or explicit unknown)
Contexts form a site only when the chosen category, restrictions and coverage satisfy A12’s requirements. The refinement relation U refines V means U is more specific: claims valid in V can be restricted to U, but not necessarily vice versa.
Claim (p)
A claim is a proposition with metadata:
- Content: the assertion itself (including the entity terms it mentions)
- Status: asserted (active), retracted (withdrawn), or pending (under review)
- Timestamp: when the claim was made or last modified
Claims have no intrinsic "scope" field. Scoping is purely structural: every claim is linked to at least one context via scoped_to edges. A claim may be asserted in multiple contexts with different witnesses in each. The entity incidence index tracks which entities each claim mentions. Correction requires a separate use record identifying the property or premise consumed, evidence version and receiving scope (A26; Appendix G). Mentioning an entity is not itself dependence on every assertion about it.
Witness (π)
A witness is evidence that supports a claim, typed per A2c:
- Decidable: verification terminates with ok | fail
- Probabilistic: a completed statistical evaluation reports its result with the specified assumptions and bounds; missing required support returns Inconclusive
- Attested: verification checks provenance and applicable authority, returning ok_if_trusted(authority), an established failure, or Inconclusive if the required check is unfinished
A proposal can be stored without becoming a witnessed or certified assertion. Appendix I's Operation 2 separately registers an assertion with the witness its contract requires. Neither storing a proposal nor assigning a witness-class label supplies that evidence. The receiving operation must inspect the actual grounds under the declared regime.
Constraint (c)
A constraint is a rule that claims must satisfy, typed per A18:
- Integrity: structural validity (types, cardinalities, referential integrity)
- Semantic: domain-level rules (a dress cannot be both minimalist and maximalist)
- Computational: resource bounds (query must complete in 100ms)
- Authority: who is allowed to assert what (only certified labs can attest purity)
Constraints are scoped: different contexts may enforce different constraints on the same predicate.
Equivalence (e)
An equivalence is a witnessed sameness per A10:
- Kind : what type of sameness (identity, isomorphism, approximation)
- Scope : where the sameness holds
- Transport certificate: what properties can be moved along this equivalence per A16
Equivalences are themselves witnessed claims about identity across contexts. The same discipline applies: a proposed equivalence without the required grounds has no certified standing. Here the Equivalence node stores the “e” in transport operations. Equivalences are not implicit; they are first-class objects that license specific operations.
The Five Edge Types
supports(π, p)
Links a witness to the claim it supports. The edge carries no information beyond the linkage; typing is on the witness node.
scoped_to(p, U)
Links a claim to a context where it is asserted. A claim may be scoped to multiple contexts (with different witnesses in each). Note: scoped_to is a structural relation; restrict is an operation that produces a restricted claim.
refines(U, V)
Encodes site structure. U refines V means U is a more specific view. Claims in V can be restricted to U. The edge must identify the actual comparison map. Its existence as a stored edge does not establish functoriality or the site axioms.
transports(e, p, p′)
Links an equivalence to the claims it connects. The edge records which properties were checked (the footprint). Per A16, transport requires a certificate, which is stored on the Equivalence node.
contradicts(δ, p, q)
Links a proof witness δ to two claims p and q that are inconsistent. The asserted contradiction needs grounds for the aligned opposition. An uncompleted comparison remains a candidate conflict, with its missing checks identified.
The Three Operations
glue(cover, target)
This operation examines a cover of local claims and attempts the specified composition in the target context.
Input:
- A cover
{U_i → U}: contexts that jointly describe the target - Claims in each with witnesses
Procedure:
- Check the declared cover under the chosen topology.
- Obtain its overlaps and restriction maps. Shared entity incidence can suggest comparisons; it does not construct categorical pullbacks.
- Check the local values on those overlaps under the exact comparison.
- If the values match and the effective sheaf construction applies, construct the amalgamation and retain the evidence.
- If a verified pair disagrees, return that disagreement. If a map, hypothesis or completed check is missing, return the incomplete obligation.
Output:
- Success: GlobalClaim with the checked scope and construction. The local factual grounds retain their original assurance.
- Failure: Evidence of the failed condition. Pairwise disagreement need not be an unsatisfiable logical theory.
- Inconclusive: The unestablished hypothesis, missing evidence or resource limit. Failure to finish is not an obstruction theorem.
Cost: Charged per A21 model. Scales with number of overlaps and witness verification cost.
restrict(U → V, p)
For with U finer, the chosen restriction acts from data over V to data over U. It is total where the presheaf defines it and satisfies its laws. Withdrawing a derivable conclusion because an absence policy changed is a different operation; Chapter 10 requires that adapter to be specified separately.
transport(e, p, footprint)
Transports a claim along an equivalence, checking that the properties in the footprint survive.
Input:
- Equivalence connecting entities and
- Claim about
- Property footprint: which properties must be preserved
Output:
- Success: Claim about with transport certificate
- Failure: Evidence of a violated footprint requirement
- Inconclusive: Missing mapping, evidence or unfinished required check
The A16 contract withholds certified transport until the required property grounds are supplied. A separate estimate may still be useful under its own stated method and scope.
What the Substrate Is Not
Not a visualization. The context graph is a data model, not a UI pattern. You may visualize it, but that is not its purpose.
Representable in existing graph systems. Knowledge graphs can carry qualifiers, sources and typed statements1. Triple stores can reify claims and their evidence; property graphs can enforce a schema over nodes and edges. A22 is a proposed organization of this information and its checking contracts. It does not establish a new species of storage that those systems cannot express.
Separate from a domain vocabulary. A22 organizes claims, witnesses and their relations; a domain still supplies the concepts those claims concern. This separation does not establish that every domain can be adequately represented by filling the five node kinds.
Example: Fashion Catalog Substrate
Instantiate A22 for the running fashion example.
Contexts:
- U_brand_A: Brand A's catalog view (signature includes
puffy; evaluation is measurement-based; logic and absence policy are declared separately) - U_brand_B: Brand B's catalog view (signature includes
puffy; evidence includes a merchandiser’s attestation; logic and absence policy are declared separately) - U_global: Company-wide catalog (union signature, requires agreement on overlaps)
Claims and witnesses: Brand A claims dress_X is puffy, witnessed by measurement (volume ratio against a reference set). Brand B claims the same dress is puffy, witnessed by merchandiser attestation. Both claims are scoped to their respective contexts; both refine into the global view.
Glue attempt: The system attempts to compose these local claims into a global claim on U_global. Coverage passes — both brands' contexts jointly cover the item. Overlap is non-empty — dress_X appears in both. The question reduces to agreement: can the measurement witness and the attestation witness be reconciled?
Scenario A: Calibration exists. A calibration witness maps between the two vocabularies — showing, for instance, that scores above a threshold in the measurement scheme correspond to "puffy" in the merchandiser vocabulary. The outcome records the translated claim, the calibration and its domain. A GluingWitness is issued only when the exact construction and its hypotheses have been established; otherwise the result retains its statistical or attested regime. A checked exact correspondence on the declared domain can support the translated values there. A sampled calibration supports only its stated statistical inference; it does not by itself invoke unique sheaf gluing.
Scenario B: Calibration missing or fails. No calibration has been established, or a supplied mapping shows disagreement — the measurement score falls in a borderline range that the merchandiser vocabulary classifies differently. The system distinguishes the missing calibration from a demonstrated mismatch, retaining its grounds and the available next steps — obtain a calibration, restrict scope so no global claim is made for this item, or fork the predicate into puffy_measured and puffy_attested.
The records distinguish a supported translation, a demonstrated disagreement and an unfinished comparison. Each retains its grounds and remaining obligations.
Scenario C: Uncovered transport.
Brand A uses a local identifier brandA:dress_123. Brand B uses brandB:dress_9F2. An Equivalence node exists:
Equivalence(
e_X,
kind: identity,
scope: U_global,
witness: MatchingDossier(SKU_alignment_2026Q1),
certificate: {physical_properties: checked, pricing: not_checked}
)
A downstream system attempts to transport pricing information along e_X:
transport(e_X, p_price, footprint={pricing})
Result: Inconclusive for the proposed pricing transport. The certificate covers no pricing comparison. The operation returns:
Inconclusive(
reason: footprint_not_covered,
requested: {pricing},
available: {physical_properties},
unchecked_obligations: {pricing_comparison},
resolution: "obtain pricing grounds or choose a use requiring only the checked footprint"
)
Scenario D: Contradiction witness.
Brand A asserts sustainable(dress_X) with a supplier certificate. Brand B asserts ¬sustainable(dress_X) based on an audit finding. Once product, date, scope and sustainability criterion are aligned, these opposed propositions are inconsistent. The substrate records the comparison and its grounds:
Witness(δ, class=decidable, method=logical_contradiction)
contradicts(δ, p_sustainable_A, p_not_sustainable_B)
The contradiction is not inferred silently at query time. It is computed, witnessed, and stored. Downstream queries can ask: "what contradictions exist for dress_X?" and receive a structured answer with provenance on both sides.
Implementation Considerations
Storage options:
- Relational: contexts, claims, witnesses, constraints, equivalences as tables; edges as junction tables with foreign keys
- Graph database: natural fit for traversal, but must enforce schema discipline (no arbitrary edge types)
- Hybrid: claims in relational for query performance, edges in graph for traversal
Indexes to maintain:
- By context: all claims scoped to U
- By claim: all witnesses supporting p
- By entity: all claims about entity x across contexts
- By overlap: candidate comparisons from entity incidence, with the declared overlap and restriction maps checked separately
Cost tracking:
- Operations record estimated cost before execution and actual cost after
- Budget enforcement gates glue and transport operations
- Over-budget operations return early with budget_exceeded reason
Versioning:
- Claims carry timestamps
- Witnesses may expire (attested witnesses have authority validity periods)
- Predicate versions per A17b are tracked via claim metadata
- Migration witnesses link old and new versions per A17b; property transport uses A16
Consequence
The substrate is specified. Its proposed encoding uses five node types, five edge types and three operations. It is typed: witnesses have classes, constraints have kinds, contexts have logics. Its operational contracts distinguish completed checks, established failures and unfinished obligations. This chapter specifies them; it does not report a general implementation.
Everything in Part V builds on this substrate. Chapter 21 asks how identity emerges from witness networks rather than brittle keys. Chapter 22 asks what a predicate must carry to be accepted into the substrate. Chapter 23 asks what a query promises when it runs against this structure. Chapter 24 asks how the system survives time as predicates evolve and contexts change.
The next operation must establish which of the linked records actually concern the same thing. An incidence index has only made that question easier to find.