Witnessed Sameness
The grounds of a permitted substitution
Aa
Eadem sunt quorum unum alteri substitui potest salva veritate. Those things are the same of which one can be substituted for the other without loss of truth.
This chapter synthesizes the machinery of Part II into a single culminating definition: A10 (Witnessed Sameness). Where Chapters 6-8 developed invariants, isomorphisms, and adjunctions as progressively refined tools for relating representations, this chapter packages equivalence itself as a first-class artifact -- a tuple carrying relation kind, scope predicate, provenance, and operational contract. The definition distinguishes four relation kinds (equality, isomorphism, equivalence, adjunction-derived approximation), partially ordered by the substitution rights they grant, and introduces scoped transport operators whose correctness and composability must be established for their declared properties. The corresponding material in Vol I appears across Chapter 4 (Empire of Strings) and Chapter 6 (Evidence Without Custody), which develop the institutional and epistemic motivations for treating sameness as a structured, auditable claim rather than a bare predicate.
The Substitution Problem
Whether two things are "the same" depends on what you intend to do with the answer. The Morning Star and the Evening Star are both Venus; Frege needed that example to show that identity is not trivial. Even when two names point to the same object, the discovery that they do so can be a genuine extension of knowledge—and the substitution that follows can be safe in some contexts and catastrophic in others.
Consider two catalog entries. Catalog A: SKU-12345, "Navy cocktail dress," $299, sizes XS–XL. Catalog B: SKU-99887, "Dark blue evening dress," $315, sizes 0–14. A human has no difficulty with the conversational claim: these might describe the same product model sold through different channels. The text differs, the size systems differ, the prices differ, but the silhouette and the intent align. If you are shopping, you treat them as substitutes; if you are settling accounts, you cannot.
Now ask a system to do something with that belief.
If the question is "should a customer searching for blue cocktail dresses see both," the entries may both be useful candidates. The effect of displaying or ranking them depends on the receiving service; a read-only operation can still influence a consequential choice.
If the question is "should inventory count them as one," the answer is maybe. If these two records refer to the same physical stock, counting twice is wrong. But if they refer to different allocations or different sellers, merging destroys information.
If the question is "should a price guarantee apply across them," product similarity does not decide it. A price is not a color. A price is a commercial fact anchored to a seller, a region, a moment, and a policy. Treating it as transportable because the dress is "the same" is how you manufacture disputes.
Same item, different commercial facts—and the equivalence turns on that difference.
The naive version of "sameness" is a binary predicate: same or not same. That predicate is too small for the work it is asked to do. It hides the only question that matters: not "are these the same?" but "what can I do if they are?"
A bare match flag can conceal two different failures.
First failure mode: silent merges. The system fuses records because similarity is high. Later it invents contradictions: in_stock and out_of_stock at the same time, two prices for one item, two incompatible size charts. The system either fails noisily or, worse, picks arbitrarily.
Second failure mode: blocked joins. The system refuses to merge anything because it cannot prove identity. The result is duplicated items, fractured histories, and analytics that count the same thing twice.
Both failures come from the same absence: the system is missing an object that can be carried forward, inspected, and used to justify downstream actions.
The system doesn't need a yes/no; it needs a thing you can hold: kind, scope, provenance, what it licenses—a receipt.
From Predicate to Artifact
The predicate framing is older than computing. "x = y?" looks like a question with an answer. The difficulty is that the question quietly bundles five others: Who says x and y are the same? Under what conditions? For what purposes? With what confidence? Until when?
Human institutions solved this centuries before formal logic named the moves. In Vol I's prologue, two ledgers were internally coherent and mutually useless at the seam. The bill of exchange did not eliminate difference. It made difference composable by introducing an object that carried conditions, signatures, validity windows, and failure semantics. The bill did not identify one currency with another. Its terms and the receiving law governed what could be demanded; maturity did not simply end the holder’s claim.
That is the pattern we need for computation. Not the metaphysics of identity, but the discipline of actionable sameness.
Mathematicians already insist on this discipline. Equality, isomorphism, and equivalence are different claims with different substitution rights—a distinction that traces back to Leibniz's identity of indiscernibles.1 Practitioners know this in their bones: a primary key match is not a fuzzy entity resolution match; a foreign-key join is not a synonym expansion; a "compatible API" is not a bitwise identical artifact.
The missing step is to make those distinctions first-class. Not comments in code. Not assumptions embedded in a pipeline. First-class objects that downstream systems can interrogate.
So we make the equivalence itself into data. But to do that without turning the whole project into bureaucracy, we separate two layers that are often conflated.
The first layer is the semantic witness. This is the mathematical content: what kind of sameness is being claimed, between which entities, under which maps or coherences, within which scope, with which provenance.
The second layer is the operational contract. This is the system commitment: given this semantic witness, what are you allowed to do? Which transports are defined? Which operations are blocked? How do you treat uncertainty and expiration?
A purist is right to insist that "merge_prices is forbidden" is not mathematics. It is policy. But the purist is wrong to conclude it does not belong. Institutions always bundle semantics with enforceable permissions. The notary's act was both: a claim about an obligation and a definition of recourse.
We package them together, but we do not confuse them.
The Witness Question
The apparatus we are about to build requires witnesses. But what is a witness?
The question hides in plain sight. A witnessed sameness requires something that attests to the relationship, that vouches for the claim, that can be interrogated about its basis. For human institutions, the answer was obvious: a witness is a person who was present, who saw, who can testify and be cross-examined.
Human witnessing involves interiority. The witness attends to what happens. The witness remembers. The witness forms a belief about what occurred and expresses that belief sincerely or insincerely. The entire moral vocabulary of testimony—truthfulness, perjury, credibility—presupposes a being who could lie but chooses not to.
A cryptographic signature has none of these properties. Under the signature scheme’s assumptions, verification supports attribution of signed bytes to a key. It does not by itself establish the authorization or occurrence described in those bytes. It can say “this was signed” without anyone home to mean it. There is no sincerity because there is no possibility of insincerity. There is no belief because there is no believer. The signature is valid or invalid, not true or false in the sense that testimony is true or false.
This is not a defect to be fixed but a design that must be understood. Process-witnessing can automate repeatable checks without a witness’s memory or sincerity. It remains vulnerable to bad inputs, compromised keys, faulty implementation and misleading uses of valid records. The formal apparatus that follows will treat witnesses as mathematical objects: tuples with provenance, scope, and operational contracts. That treatment is correct for computational purposes.
But the reader should hold in mind the deeper question: when witnesses are processes rather than persons, something changes in what "attestation" means. The apparatus cannot answer this question. But without asking it, we will not understand what the apparatus does and does not provide.
A kidnapper sends a photograph: the hostage holding today's newspaper. Why does this work as "proof of life"?
The newspaper can constrain the photograph’s date if the issue is independently dated and the image is authentic. It does not establish the exact time or place, and an altered image could defeat the inference. The familiar device is useful because it joins pieces of evidence with different roles; none escapes examination by appearing beside the others.
A photograph is not a cryptographic commitment in the technical sense. The comparison helps identify questions about dating, binding and subject matter, while the answers depend on different mechanisms.
Digital witnesses separate these roles:
- The anchor: a timestamping or publication record with stated ordering and clock assumptions. A hash or Merkle root alone supplies no trustworthy date.
- The commitment: a signature, a hash, a zero-knowledge proof—something that binds data to the anchor.
- The payload: the claim whose bytes are bound. Verifying the binding does not establish the transaction, identity or relationship asserted.
A witness is not a boolean. It is an artifact you can carry forward, inspect, and use to justify downstream actions. The kidnapper's photograph can be analyzed, contested, dated by forensic experts. A cryptographic witness can be verified, traced, and revoked.
The formal apparatus that follows treats witnesses as structured objects with provenance, scope, and operational contracts. That structure is the computational equivalent of the Polaroid: not just "true" or "false," but when, by whom, under what conditions, and for what purposes.
Witnessed Sameness
A witnessed sameness between A and B is a tuple:
where:
- K = relation kind (equality, isomorphism, equivalence, adjunction-derived approximation); the receiving policy specifies which substitutions that relation supports
- A, B = the entities being related
- S = scope predicate over contexts and time:
- E = evidence supporting the stated relationship: maps and checked laws, a specified statistical procedure, or an inspectable attestation
- F = property footprint: the properties, relations and evaluations the evidence supports transporting
- prov = provenance (axiom | authority | computation) + confidence + expiration
- ops = operational contract: transport operators, permissions, validity gate
Scope order: iff for all ctx, t:
Validity gate: Every witness has a function that evaluates scope, expiration, and provenance-specific checks.
- Valid: transport proceeds subject to permissions
- Invalid: transport blocked
- Unknown: the gate has not established applicability; any permitted use must retain that status and satisfy its own evidence and authority requirements
The proposed default blocks merge, delete and commit under Unknown. Read-only display is not a general exemption: ranking or presenting a claim can impose consequences without modifying the source record.
Laws:
- Scope law: Write-transports are defined only when is true and . Read-only views under Unknown must also respect the declared use policy; absence of a write is not proof of harmlessness.
- Composition law: If and , composition requires compatible intermediate interpretations and transport operators, with scope contained in . Exact maps compose under their laws; approximate or probabilistic evidence needs a justified rule for accumulated error and dependence
- Non-escalation law: Transport grants only operations supported by the established relation, evidence, property footprint and scope; naming K does not establish those grounds
A2c classifies witnesses by their checking regime: DECIDABLE, PROBABILISTIC or ATTESTED. K answers a different question: which relationship is claimed. The receiving policy may order substitution rights for specified properties. The schematic order = ≽ ≅ ≽ ≃ ≽ ≲ describes one such policy, not a universal ordering of mathematical constructions or confidence. An attested claim of isomorphism does not inherit a checked isomorphism’s assurance. The evidence must establish the relationship and the property the recipient intends to carry across it.
Equality (=): Identity in the declared mathematical setting. Definitional equality can be checked by the setting’s conversion rules; a propositional identity requires its proof. Substitution follows the equality rules of that setting and the properties of the declared representation. Equality of an identifier does not identify every record using it.
Isomorphism (≅): Structure-preserving bijection witnessed by maps (f, g) such that f∘g = id and g∘f = id. Substitution is permitted in contexts that respect the structure preserved by f and g.
Equivalence (≃): Invertibility up to the coherence required by the setting: for categories, functors inverse up to natural isomorphism; for types, the corresponding equivalence data. This does not require every arrow in the categories to be invertible. The artifact must identify the setting, maps and laws its claim uses.
Adjunction-derived approximation (≲): When interchangeability fails, A9's adjunctions give principled one-way or lossy translations. In A10, these become witnesses that permit transport only along declared one-way operators. A promote/demote pair from Chapter 8 becomes a witness with asymmetric transport rights. Non-escalation is strictly enforced: you cannot obtain an operation requiring isomorphism from an approximation witness.
This fourth relation kind keeps A9 inside the unified story rather than adjacent to it. The adjunction's unit and counit become part of the witness structure; the lossy direction is explicit in the operational contract.
Transport Operators
The key operational content of A10 is transport: given a witness, what can you move across it?
In type theory, transport is the mechanism by which an identity proof permits substitution across a dependent type family.2 We keep that intuition but define transport in systems-native terms.
A witness carries a family of partial transport operators indexed by property class. This family structure echoes the dependent type families of Martin-Löf type theory3, where types can depend on values.
Attributes: scalar values like color, size, price. Transport may be defined for some attributes but not others.
Predicates: boolean properties like in_stock, returnable, on_sale. Transport may have time windows.
Aggregations: counts, sums, statistics. Transport requires de-duplication semantics.
Joins: relational links to other entities. Transport may be blocked for links carrying independent commercial terms.
Each transport operator is partial. Not every property transports under every witness. Even when transport exists, it is scoped and validity-checked.
The non-escalation law makes this precise. A search-level equivalence may license ranking and recall expansion, but it cannot license inventory merge. A supplier attestation may support an inventory operation if its grounds and the receiving contract suffice. The same item can belong to separate stocks; identity alone does not license summing or merging them. Price and return terms require their own reconciliation.
Consider the fashion catalog example.
SemanticWitness:
kind: Attested product correspondence
lhs: catalog_a.SKU-12345
rhs: catalog_b.SKU-99887
maps: (size_chart_mapping, color_normalization)
scope: inventory_counting
provenance: supplier_crossref_2026
assurance: supplier-attested; no numerical calibration claimed
expiration: 2026-02-01
OperationalContract:
transport_operators:
attributes: {color, size, material}
predicates: {in_stock} with 24h window
aggregations: {inventory_count} with de-dup
permitted: [merge_counts, substitute_in_search]
forbidden: [merge_prices, merge_return_policy]
validity: Valid requires scope, time, evidence and transport checks; an unexpired date alone is insufficient
The contract is where the "receipt" earns its name. A downstream system does not have to guess. It can ask the witness: Are you valid here and now? What class of property am I trying to transport? Do you define transport for that class? What is permitted, what is forbidden?
Witnessing Without Interiority
The apparatus is now complete: relation kinds, scope predicates, transport operators, validity gates. The system can ask whether a witness is valid, what it licenses, how it composes. But we deferred a question that the formalism cannot answer.
What is witnessing when the witness has no interiority?
Giorgio Agamben distinguished two Latin concepts of witness: testis, the third-party observer who can be called to testify, and superstes, the one who has lived through an event and carries it in their being. 4 The courtroom witness is testis—present at the scene, able to report. The survivor is superstes—marked by the experience, speaking not merely about what happened but from within it.
Human witnessing involves both dimensions. The witness observes (testis) and is affected by observing (superstes). The witness can be cross-examined not only about facts but about their attention, their memory, their reasons for believing what they report. Truthfulness is a virtue because the witness could lie; sincerity matters because the witness could deceive. When a notary certifies that two signatures match, the notary can be asked: Did you compare them carefully? What convinced you? A hash function that produces the same output for two inputs cannot be asked anything.
A cryptographic attestation does not reproduce either human position. It can support attribution of signed bytes under the scheme’s assumptions; it does not establish that the event those bytes describe occurred. The signature itself neither observed nor survived that event. It cannot be cross-examined about attention or belief. Those questions may instead concern the people, sensors and procedures responsible for the assertion.
This is not a limitation to overcome but a categorical fact to recognize. Process-witnesses produce validity, not truthfulness. A valid signature supports attribution of the signed bytes under the scheme’s assumptions; it does not establish that the key holder had authority for the described operation. It does not prove that anyone meant the authorization, intended its consequences, or stands behind its implications. The signature attests; it does not vouch.
The distinction matters for what witnessed sameness can and cannot do. A witnessed equivalence produced by human attestation carries the weight of human judgment—someone decided these entities are the same, and that someone can be questioned about the decision. A witnessed equivalence produced by algorithmic matching carries no such weight. The algorithm found a pattern; whether the pattern means "same" in any sense that matters for downstream action depends on scope, not on the algorithm's conviction.
The formal apparatus handles this through the provenance field: axiom, authority, computation. But the field does not capture the phenomenological difference. Human authority carries interiority; computational provenance does not. The system can record the difference. It cannot bridge it.
The trilogy's fourth formulation, ‘Humanity needs mercy,’ concerns a further constitutional demand. Volume III distinguishes an accurate record from authority for its continued adverse use, and public release from a wronged party's forgiveness. Neither those distinctions nor their institutional rules follow from the relation kinds defined here.
Running Examples
NYC vs New York City
The string pair "NYC" and "New York City" is a trap because it feels obviously identical until you name a context.
An illustrative address service might accept both strings under a documented normalization rule. A historical query still needs the source’s date and intended boundary. This does not mean the two names have different legal referents by definition. The mistake would be to treat success in the first task as evidence that the second had been answered.
A scoped normalization record should identify its rule, routing fields and validation basis. This example asserts no particular USPS contract.
Composition Failure (Worked Example)
This is where non-escalation earns its keep.
Suppose item A matches item B in search scope under a specified similarity procedure. Its record retains the procedure, evidence and permitted search use. A similarity score alone does not establish the maps and laws of A9’s adjunction-derived relation K = ≲. A supplier attests that item B corresponds to item C under an inventory mapping, claiming K = ≅. That second witness is ATTESTED in A2c’s terminology: the claimed maps and their suitability for inventory use still require the receiving contract’s checks. A naive system composes the two records and claims A matches C.
That is exactly the bug. If both scopes permit the relevant display use, their intersection includes it; if either excludes inventory merge, their intersection excludes that operation. The embedding witness cannot escalate to license inventory operations. Without scope-indexed composition and non-escalation, the system silently promotes a search hint into an inventory merge—and creates phantom stock.
Non-escalation blocks promoting the search evidence into an inventory guarantee. It does not supply a composition theorem for arbitrary similarity scores. That requires an error relation and compatible maps; where none has been established, even the weaker composed claim remains unsupported.
Morning Star and Evening Star
Two names, one referent. The witness is an alignment procedure: observations at dawn, observations at dusk, ephemeris model that establishes both tracks correspond to one orbiting body.
Transport is partial. The positional facts transport. The cultural role does not automatically transport. "Evening Star" can carry different mythic associations than "Morning Star," even if the referent is the same.
This is the point of touchstone T2 inside the systems frame developed across The Proofs. Identity is informative because witnesses carry structure. A10 is the discipline of carrying that structure explicitly, so that a system does not confuse "same referent" with "same meaning."
Build Artifacts
Consider two build artifacts, v1.2.3 and v1.2.4.
Suppose a declared API contract establishes directional compatibility between them. That relation needs its own witness; it is not equality.
Witness:
kind: Directional compatibility contract
maps:
upgrade: v1.2.3 clients work with v1.2.4 server
downgrade: v1.2.4 clients work with v1.2.3 server (lossy)
scope: api_compatibility
provenance: CI tests + semver discipline
permitted: [route_old_clients_to_new_server]
forbidden: [assume_feature_parity]
The example records asymmetric compatibility. CI tests and a version label do not establish an adjunction: its categories, maps and universal law would require separate proof. The compatibility contract can still be useful on its tested and justified domain.
What Witnessed Sameness Is Not
This is not an argument that nothing is really the same. It is an argument that "same" is a claim with operational consequences, and claims with consequences must carry conditions.
This is not computationally free—witnesses cost money. Someone must create them, store them, refresh them, and resolve conflicts. But the absence of witnesses is not free either. It is paid later as phantom inventory, corrupted analytics, and brittle integrations that fail at seams.
This is not relativism. Scope is not weakness. Scope is precision. A scoped normalization claim demands less than unrestricted interchangeability. Its advantage is that its conditions can be examined and enforced; narrower scope does not make the proposition logically stronger.
This is not a replacement for domain expertise. A system cannot conjure a supplier mapping from vibes. What it can do is prevent the supplier mapping from being misused. It can ensure that a witness that licenses search does not silently license settlement.
Consequence
Part II set out to build a calculus of sameness that an engineer can implement and a mathematician can respect.
Chapter 6 gave invariants: what survives transformation, what is real in the presence of changing coordinates.
Chapter 7 gave isomorphisms: when two representations are genuinely interchangeable.
Chapter 8 gave adjunctions: when interchangeability fails, the best possible translations under constraint, with explicit asymmetry. Cost requires a further measurement or model.
Chapter 9 gives witnessed sameness: the synthesis. Equivalence is an artifact, not a predicate. It has kind, scope, provenance, validity, and transport operators.
We can now say precisely what was previously hand-waved. Substitution requires a witness. Substitution requires a scope. Substitution requires transport operators, and transport is partial. Composition requires overlap, and overlap requires compatibility.
But we have deferred one question on purpose.
What is a scope?
Here, scope has been a minimal predicate over contexts and time, ordered by inclusion. That minimal shape was enough to make the discipline real. It identifies conditions a gate must enforce. The gate’s implementation and evidence determine whether it blocks an invalid use; the notation alone does not.
Part III will give scope its full content. A scope is a context, a view of the world with its own vocabulary, invariants, and equivalences. Contexts overlap. They agree or disagree on their overlaps. Global coherence is not a single global truth. It is local truths that match where they meet.
We have a calculus of sameness. Now we need a calculus of scopes.