Update log
- 7 September 2026 - First edition. Drawn from the White Paper's laws, the Yellow Paper's judge and evidence tiers and shadow runtime, the architecture programme's chapters on conflict isolation, plan drift, incident crystallisation, refusal portability and the evidence complexity budget, and the acceptance records of the sealed line. Object names are given as the shape of the design.
Short answer
The White Paper's third law: "Evidence before computation. The protocol judges claim + evidence + effect set + capability + constitution into a verdict. It never computes what it can verify." The Yellow Paper gives the judge its signature: a claim, a delta, evidence and the version of the algebra go in; a verdict comes out. Hot-path cost "is bounded by evidence verification, never by program execution."
The evidence algebra is what makes that judgement well-defined. Evidence comes in tiers, and the floor is deterministic replay: "every claim class is judgeable by replay alone." Above it sit signed receipts, proofs that are cheaper to verify than to replay, and attested enclaves that are "admissible only in defined lanes, never sole trust root". External signed receipts "are never canonical alone; they bind through reconciliation invariants." Missing evidence is a state of its own, never a false; and the programme budgets evidence - bytes, latency, retention, disclosure, independence, parsers, attestors, reviewer effort - because unbounded proof is its own failure mode.
The distinctive part is what happens when evidence disagrees. Most systems resolve contradiction by picking a side or by hiding it. FxChain's direction escrows it. An unresolved conflict is materialised as an isolation cell with its resource, authority, evidence and dependency radius made explicit "so unrelated accounts, assets, markets, and rails continue"; resolution "needs explicit authority and a receipt". A plan assumption broken by implementation creates an amendment proposal, "never silently rewrites a ratified plan". And the programme's list of questions includes the one this dossier answers: "How does the architecture continue useful work under contradiction without lying?"
On the sealed line, the algebra is already practised at small scale: the reconstruction tribunal preserves asymmetric refusal as an outcome instead of voting it away, and the acceptance discipline requires every candidate to carry its own falsifiers.
What is established, what is in development, what is not claimed
| Claim | Status | Basis | Limit |
|---|---|---|---|
| Deterministic replay as the line's evidence floor: frozen vectors, conformance runs, two independent reconstruction paths | Proven today | Conformance surface; reconstruction family | Local; replay of preserved history, not of a network |
| Asymmetric refusal preserved as an outcome, never resolved by voting | Proven today | Reconstruction tribunal record | Reported, not adjudicated |
| Candidates must carry falsifiers and negative controls; a green run without them is not evidence | Proven today | Acceptance discipline; acceptance records | Practised on the line |
| Evidence tiers: replay floor, signed receipts, proofs, attested enclaves in defined lanes only | Research | Yellow Paper, judge and evidence tiers | Design |
| External signed receipts never canonical alone; binding through reconciliation invariants | Research | Yellow Paper; architecture programme | Design |
| Contradiction escrow as a conflict isolation cell with an explicit blast radius; resolution by explicit authority and receipt | Research | Architecture programme, conflict isolation cell | Design; "the implementation form of Contradiction Escrow, not an additional competing truth owner" |
| Plan drift: echo receipts classify every exercised assumption, and a load-bearing contradiction creates an amendment proposal | Research | Architecture programme, plan drift records | Design; the change core that would decide amendments is not built |
| Incident crystallisation: every material incident becomes a reproducer, a negative control and a regression vector, with exactly one typed law disposition | Research | Architecture programme, history as corpus | Design; the habit is practised in the acceptance discipline |
| Shadow activation of new power classes requiring zero contradiction artifacts | Research | Yellow Paper; White Paper | Design |
| An evidence complexity budget published per wave, with a scalar composite as display only | Research | Architecture programme | Design |
| An evidence correlation graph and a quorum diversity profile | Research | Architecture programme, research horizon | "Remains research until identity, liability disposition, refresh, correlation, censorship, and recovery models are falsifiable" |
| A verifier or oracle market | Research | Architecture programme | "Not an active protocol dependency" |
| Any of these running on a network | Not claimed | Every specification | None exists |
Judging, not computing
The judge takes four things: a claim, the delta it asserts, the evidence offered for it, and the version of the algebra under which it is to be read. It returns a verdict. The consequence for the hot path is structural: the cost of accepting a claim is the cost of checking its evidence, which the protocol controls, not the cost of running the program that produced it, which the claimant controls.
claim + delta + evidence + algebra version
|
v
JUDGE --> verdict
|
cost bounded by verification (protocol's choice),
never by execution (claimant's choice)
Figure 1 - The judge. The protocol checks; it does not run.
The Yellow Paper draws the line at the bottom of the stack too: the compatibility sidecar for foreign virtual-machine code "is the lowest evidence tier, isolated, with an explicit state bridge". Nothing is admitted at a higher tier because it is familiar.
The tiers
tier admissible as note
------------------------ ----------------------------- ---------------------------
deterministic replay the floor: every claim class "completeness floor"
is judgeable by replay alone
signed receipts evidence bound through never canonical alone
reconciliation invariants
proofs fee-discounted where cheaper to verify than
verification is cheaper to replay
attested enclaves defined lanes only "never sole trust root"
Figure 2 - Evidence tiers. Higher tiers may be cheaper; none may replace the floor.
Two rules protect the tiers from collapsing into trust. First, the floor is universal: whatever a proof or an enclave asserts, the same claim class must remain judgeable by replay, so that a broken proof system or a compromised enclave degrades cost, not truth. Second, an external signed receipt - a bank's, a custodian's, a rail's - is evidence about the world, bound to protocol state only through reconciliation invariants. This is the evidence-algebra form of the six-axis rule that an external claim never becomes canonical state by stronger assurance, and of the settlement-truth law that missing evidence is not false.
The programme adds the institutional consequence for refusals: a denial must identify "the unmet rule, evidence, authority, time, disclosure class, appeal or remediation path, and stable reason code without leaking protected facts", and refusals get service objectives - latency and availability by risk class for producing, verifying, appealing and superseding them - with the caveat that "an SLA never weakens a safety rule; missed service targets remain measurable operational failures."
Contradiction escrow
A contradiction is two pieces of admissible evidence that cannot both be acted upon. The ordinary responses - pick the newer, pick the more trusted, halt everything - each either lie or stop the world. The programme's response is to give the contradiction a shape and a boundary.
The conflict isolation cell "materialises the resource, authority, evidence, and dependency radius of an unresolved conflict so unrelated accounts, assets, markets, and rails continue." The cell is not a third truth: it "is the implementation form of Contradiction Escrow, not an additional competing truth owner." Inside the radius, nothing proceeds until "explicit authority and a receipt" resolve it; outside the radius, the protocol keeps working, and can say exactly why it is entitled to.
contradiction detected
|
v
+---------------------------------------------------+
| isolation cell |
| resource radius ..... which assets, accounts |
| authority radius .... which powers are held |
| evidence radius ..... which claims conflict |
| dependency radius ... which rails, markets |
+---------------------------------------------------+
| |
v v
inside: HELD until explicit outside: continues,
authority + receipt resolve it with the boundary on record
Figure 3 - Escrow, not erasure. The contradiction is kept, bounded and visible until someone with authority resolves it and leaves a receipt.
The same instinct governs the shadow runtime: a new power class "runs in shadow on real traffic ... producing evidential facts with zero authority; activation requires zero contradiction artifacts, a satisfied readiness profile and a governance seal." A contradiction between what the shadow would have done and what the canonical path did is not an anomaly to be explained away; it is the artifact that blocks activation.
Working under contradiction without lying
The programme applies the escrow to itself. Every implementation wave must emit an echo receipt "classifying each exercised plan assumption as confirmed by implementation, broken by evidence, not exercised, or inconclusive, with exact evidence." Receipts feed "a forward-only sequence" of drift records. "Load-bearing contradiction creates an amendment proposal; it never silently rewrites a ratified plan or grants amendment authority." A separately authorised act decides whether the plan is amended, superseded or left unchanged.
plan assumption --- implementation ---> echo receipt
|
+------------+-------------------+------------------+
v v v v
confirmed broken by evidence not exercised inconclusive
|
v forward-only drift record
AMENDMENT PROPOSED (never a silent rewrite)
Figure 4 - Plan drift as a receipt. The plan may be wrong; the record of being wrong is never lost.
This is the mechanism by which the line has already worked under contradiction in public. The reconstruction family's closure found its own witness measuring a declaration instead of an execution; it did not rewrite the earlier green runs, it separated the facts and gave each an owner. The sealed-history dossier tells that story; this dossier names the rule behind it.
Incidents become law, or say why not
"Every material incident must become a minimal deterministic reproducer, negative control, expected observer/reason assertion, mutation family where applicable, and permanent regression vector." Historical failures "remain calibration cases with their original outcome and authority boundary; they are never silently rewritten to fit the current implementation."
And every incident receives exactly one typed disposition: a candidate invariant created, an existing invariant strengthened, or - with a justification and a reviewer - no law extractable. The third option is the honest one most processes lack: it forbids pretending that every failure taught a rule, while requiring someone to sign the claim that this one did not.
The corpus that results is replayed in full at major promotions; routine runs may use a bounded sample only "with deterministic selection, population commitment, coverage metrics, rotation law, excluded-class disclosure, and periodic full replay. Sampling may not be biased toward passing history or reported as complete coverage."
The evidence budget
Evidence is not free, and unbounded evidence is a way of hiding. The programme budgets "proof computation, bytes, latency, retention, disclosure, independence, parser count, policy branches, attestors, common failure domains, and reviewer effort", and requires each wave to publish its counts - owners, cross-references, alias ambiguities, state machines, unexecutable invariants, failure domains, parsers, artifacts per capability, assurance effort per product capability - together with "baseline, delta, budget, explanation, and reduction action." Historical labels such as a proof economy or an architectural entropy budget "map to this bounded optimisation family; they are not automatically markets."
evidence budget (per wave)
+-----------------------------------------------------------+
| proof compute . bytes . latency . retention . disclosure |
| independence . parsers . policy branches . attestors |
| common failure domains . reviewer effort |
+-----------------------------------------------------------+
published as baseline -> delta -> budget -> explanation -> reduction
scalar composite: display aid only; raw dimensions govern
Figure 5 - Evidence that must fit. A proof nobody can review is not evidence; it is volume.
On the research horizon sits an evidence correlation graph: attributed, challengeable claims about failure domains that could one day constrain validator admission - with the rule that unestablished diversity "yields held or policy-typed refusal, never fabricated diversity."
What the evidence algebra does not do
- It does not run on a network. Replay, conformance and reconstruction exist on the local line; tiers, escrow and budgets are design.
- It never lets a higher tier replace the floor, and never lets an external receipt become canonical alone.
- It does not resolve contradictions by rank, recency or vote. It bounds them and waits for authority and a receipt.
- It does not rewrite a plan or a historical outcome; it records the drift and proposes.
- It does not treat every incident as a lesson: it allows "no law extractable", signed.
Verdict
The evidence algebra is the third law with its consequences drawn out: a judge that checks rather than runs, tiers that can lower cost but never lower the floor, external receipts that stay evidence, and a budget that keeps proof reviewable. Its signature move is contradiction escrow - the refusal to hide, halt or vote when evidence disagrees, replaced by a bounded cell, a visible radius and a receipt. The line already lives by the small version of that rule: its tribunal reports disagreement instead of settling it, and its closure separated four facts one green tick had merged rather than rewriting the tick. Working under contradiction without lying is not a slogan in this architecture; it is a question the programme requires itself to answer.
Frequently asked questions
Why "never compute what you can verify"?
Because the cost of verifying evidence is the protocol's to bound, and the cost of executing a claimant's program is the claimant's to inflate. A judge that only checks cannot be made to do an attacker's work.
Are zero-knowledge proofs the top tier?
They are a cheaper tier where verification costs less than replay, fee-discounted for that reason. They are not a replacement for the floor: every claim class must remain judgeable by deterministic replay.
What happens when two sources disagree?
The disagreement is escrowed: isolated with its resource, authority, evidence and dependency radius stated, held inside that radius until explicit authority resolves it with a receipt, while everything outside continues.
Does the plan ever change?
Yes, by proposal. An assumption broken by evidence produces a receipt and a drift record; a load-bearing contradiction produces an amendment proposal; a separately authorised act decides. Nothing is rewritten in place.
What exists today?
Deterministic replay as the floor - frozen vectors, conformance runs, two independent reconstruction paths - and the habit of preserving refusal and disagreement as outcomes. The tiers, the escrow cell, the drift receipts and the budget are design.
Sources and methodology
Drawn from the White Paper's laws and shadow runtime, the Yellow Paper's judge, evidence tiers and shadow activation, the architecture programme's chapters on the conflict isolation cell, plan drift, incident crystallisation and history as corpus, refusal portability, the evidence complexity budget and the research horizon, and the acceptance records of the sealed line. Quotations are from those sources. Implementation claims are limited to the line's conformance and reconstruction surfaces; design claims carry the status research.
The papers and the programme are not published on this portal and are not reproduced here; objects and dispositions are reported as shape. Figures shown anywhere on this portal come from a single dated snapshot; none are introduced by this dossier.
Related reading: The evidence lab; The replay domain for asymmetric refusal preserved; Receipts, denials and capsules; Six axes, never one status.