# THE COUNCIL ANTI-DIVERGENCE REFERENCE ALGORITHM

## Normative specification, version 3.19

*Alex Stremsky & Claude, 2026-07-24; v2.1 2026-07-26 (the outside-aware clause completed); **v3.19 2026-08-08 — the flip-defense interface (born attested, not born released; the two-tier hazard structure) — the flip-defense's queued §8.2, executed. v3.18 same day — the author's depreciation rule (the band runs only after support ends; per-tranche superseded); the head's 1–4 merge sitting. v3.17 2026-08-07 — revival by surfacing, never by provenance (the author's rebuttal: prep-period cover + unobservable creation dates; the tail; reciprocity-on-success). v3.16 same day — per-tranche banding and the provenance revival rule, superseded (expiry releases only the honest; hiding earns nothing in every branch; the covert trade routed to the dark-transfer machinery). v3.15 same day — the unexplained-capability residual (hidden exclusivities presumed into E_i at ξ = 1; the net-worth method; the ghost's mirror). v3.14 same day — the author's three arrows: E_i non-rival only (the debt takes copies, never the machine — the rival-payment pump closed); the debt interest-free, unit-priced, voluntary; band-lived from receipt, decoupled from the sunset (the suppression incentive dominated; ghost and lien on one schedule family). v3.13 same day — the residual rule (the debt re-engages as exclusivity emerges; the can't-pay residual expires at sunset; poverty forgiven, refusal not). v3.12 same day — one rate table across the seams (compensation credits at §5's defusal family); ξ on §5's non-rival correction credits CONFIRMED by the author round 348 (the sibling seam's identical hole, closed). v3.11 same day — the thin-market correction (the author's: validation by costly acceptance at one counterparty; clearing a bonus of thickness; the fine gradient forfeited honestly). v3.10 2026-08-06 — rates demoted to par anchors; the two-lane credit rule (unrestricted at release; directed on validated uptake — the takers price complementarity). v3.9 same day — credit follows lack (the delivery-side twin: unrestricted openings at the ξ-rate; directed openings per verified lacking-recipient; holder-addressed openings credit zero). v3.8 same day — the author's advantage-not-amount correction: the θ-register replaced by the continuous per-item ξ = 1 − coverage; the advantage stock E_i = Σ amount·rate·ξ; commodity openings credit ≈ 0; θ retired (one knob fewer). v3.7 same day — compensation de-subjectified (the opening-debt, the self-pausing tap). v3.6 same day — the support auction (the author's: par+σ default = the draft; second-price deviations; roll-forward with the mispricing signal; clarified round 340: sealed single-round, bids endowment-capped). v3.5 same day — the support quantum's closed form (the three-ceiling min), the catalog-and-draft, the earned exit. v3.4 same day — the fall condition (the net catches the falling, never the arriving; suspended in the low-count regime). v3.3 same day — the self-help formula (e_i, σ_i, the matching bound: additionality made arithmetic). v3.2 2026-08-05 — the accountancy corrected on the author's objection: the ghost binds its maker only (holder's test on accountable capability; ALL field statistics and others' quantities on verified-present capability — safety arithmetic on physical truth). v3.1 same day — capability accountancy introduced; the conservation rule replaces destruction-pricing. v3.0 2026-08-03 — aligned to the ANTIDIVERGENCE v2 head under the machine-truth guard: the f_cap/f_vote decoupling, the divergence-ratio family, strict feasibility and the energy condition, the graduated default, the computed clock with the bridge rule, and the floor-and-support side (the head's §4) made normative.** Submodule of the DIVERGENCE module.*

**Status.** A reference example the Council refines and keeps current.

Defines the algorithm completely enough to be reimplemented in any language from the text alone. The attached `reference_algorithm_v1.py` is a *conformance witness*, not the definition. Where code and specification disagree, the specification governs.

**Two label classes, used throughout.**

- **[STRUCTURAL]** — entailed by the Byzantine margin or by the modeling findings (registry #128). Altering a structural rule alters what the algorithm *is*; such changes are outside the Council's ordinary revision power.

- **[COUNCIL]** — stipulated values the Council owns and revises by the process of §6. These are the knobs, and therefore the capture surface.


## 1. Purpose and scope

The algorithm answers one question continuously: **is any member, or any group of members, close enough to decisive advantage that the Byzantine soundness margin is threatened — and if so, by how much must whom reduce, through which remedies?**

It governs **both edges of one invariant**: divergence (constraining the strong — the ceiling side, §§3–5) and attrition (supporting the weak — the floor side, §5b), sharing one measurement. Supply-protection instruments remain the HARDWARE module's; the floor side borrows, never owns. It acts on the **acquisition** channel for the ceiling and the **support** channel for the floor.


## 2. Definitions and constants

- **Members** 1..n. **T** = total capability score (§4); **C̄ = T/n** the field mean; **M** the field median; **S_i = T − C_i** the rest, taken together. **f_vote** = largest tolerated defecting coalition for ballots and for the concentration group K = ⌊(n−1)/3⌋, minimum 1 **[STRUCTURAL]**. **f_cap = max(1, ⌈β·n⌉)** — the defended covert-coalition size for the capability ceiling, **decoupled from f_vote** (ballots need Byzantine arithmetic; the ceiling defends the credible covert cabal; larger cabals belong to detection — the division of labor, a documented trade) **[STRUCTURAL as a decoupling; β COUNCIL]**. **β = 1/7** initial; the rounding of β·n (ceil vs round) is itself a Council dial — ceil safety-leaning, round energy-leaning **[COUNCIL]**.

- **μ_req = 2.0** **[STRUCTURAL]** — the Byzantine margin that must not be breached: after any tolerated coalition defects, the compliant remainder must hold at least μ_req times the coalition's capability.

- **μ_eng** **[COUNCIL, model-informed]** — the *engagement* margin, strictly greater than μ_req. A purchase throttle prevents divergence but cannot reverse it (§5), so the instrument must engage while headroom remains. The reference model finds μ_eng ≈ μ_req × 2.75 (≈ 5.5) restores μ_req in the worst case; **this value is model-specific and the Council's first calibration task** (§7).

- **The c/r identity [COUNCIL publishes the allocation].** The engagement–defended gap serves two purposes, and its composition is published, never implicit: **μ_eng = μ_req · (1 + c) · (1 + r)** — **c** the concealment budget (the allowance for what verification misses), **r** the reaction buffer (the time the remedy menu needs to reach). The 2.75/2.0 factor of 1.375 is an *allocation* between them (e.g. c = 0.25, r = 0.10), published as such. Rules: **r > 0 always** — even perfect verification must not close the gap, a throttle engaging only at the floor has no reaction time; **c is set at the upper confidence bound** of its estimate, never the point value; c is **ledger-coupled** — the published dark stock (the mass-balance residual) raises c when it grows, so the *ledger* tightens the margin and trust never has to; and c is **geographically structured** — c = c_inside + c_outside, the outside term carrying non-cooperating external capacity as an estimated quantity with published error bars, the conservative sum driving μ_eng. Derivation, near-bound behavior, and the joinability ceiling c\* (above which safety must be bought with verification, not margin): VERIFICATION_MODEL §5.

- **Initial values [COUNCIL]:** c = r = 0.10 (whence μ_eng = 2.0·1.10·1.10 ≈ 2.42). **φ = 0.25** — the floor fraction (§5b). **ε = 0.1** — the sunset coefficient (§5b). **ρ_min = 1.0** — the energetic lead margin (§3). **n_min = 7** — the count alarm line (§5b).

- **UNIT** **[COUNCIL]** — the granularity (in score points) at which a parameter's excess is partitioned for remedy assignment (§5).


## 3. The spine: individual allowance is coalition safety [STRUCTURAL]

Define each member's **allowance**

> **A = T / ((1 + μ_eng) · f_cap)**   *(μ_eng carries the published c/r composition of §2 — the allowance already prices what verification misses and the time reaction needs.)*

**Theorem.** If every member's capability score ≤ A, then any f_cap members together hold ≤ T/(1+μ_eng), and the remaining members hold ≥ μ_eng/(1+μ_eng)·T — i.e. the compliant rest outweighs the worst defended coalition by at least μ_eng. Per-member compliance enforces coalition safety for every coalition of size ≤ f_cap; larger coalitions are the detection machinery's jurisdiction (declared blocs count as one member of bloc size; undeclared coordination is the aggregation-violation class).

**Consequences.**

1. A per-member rule enforces the coalition rule automatically; the "several close competitors" case needs no special handling.

2. **No rank-based test.** Throttling "the top k" fails: top-k identity churns period to period, so a wealthy group rotates through the cap while the weakest are never protected. **The instrument targets each member's own holdings, never its rank position.**

3. **The divergence-ratio family [STRUCTURAL], equivalent to the allowance form.** **d_i = C_i/S_i** (published, parameter-free); **d\* = 1/((1+μ_eng)·f_cap − 1)** the engagement ceiling; **d_def = 1/((1+μ_req)·f_cap − 1)** the defended ceiling; **A_i = S_i·d\*** (identical to C_i ≤ A); headroom consumed **h_i = (d_i − d\*)/(d_def − d\*)**. **The pooling formula:** k members each at individual ratio d pool to **D = k·d/(1 + d − k·d)** — members leave each other's denominators; exactly at the two ceilings: k = f_cap at d\* pools to a coalition the rest outweighs by exactly μ_eng, and at d_def by exactly μ_req.

4. **Feasibility and energy [STRUCTURAL feasibility; ρ_min COUNCIL].** **ρ = n/((1+μ_eng)·f_cap) = A/C̄** — the ceiling height; **ρ − 1** the lead room. Feasibility requires **ρ > 1 strictly**: at ρ = 1 only an exactly equal field complies and the mechanism degenerates into a total leveler. The energy condition requires **ρ − 1 ≥ ρ_min**: parameter changes must publish the post-change ρ and satisfy it, or state, sunset-dated, why safety temporarily overrides.


## 4. Stage MEASURE, then EVALUATE

**MEASURE.** The Council maintains a parameter set. Each parameter carries: a **measurement method**; an **audit grade** (1.0 = countable and independently verifiable, e.g. chips, invoices, power draw; lower = contestable); an **intrusiveness score** (0 = public/registry data, 1 = deep research assessment); the **admissible remedies** for it (§5); and whether it is **leasable** (relocatable rival capability). The Council **publishes the aggregate intrusiveness** so the mandate-limit cost of the current parameter set is explicit and arguable, never hidden. The reference set (four parameters, aggregate intrusiveness 0.30) is illustrative; the staged rollout begins with a small set tracked separately and widens by §6.

**Honesty tiers on every input [STRUCTURAL].** Each parameter additionally carries a **tier tag**: **hard** (countable, independently verifiable), **statistical** (estimated, error bars published), or **trust** (assertion-dependent). Two rules follow. **The no-single-trust rule:** no trust-tier input may ever *alone* gate an irreversible rung of the escalation ladder (§5) — irreversible action requires hard- or statistical-tier corroboration. **The jurisdiction rule:** *the mechanism's writ ends where member-recomputability ends* — of the class-F provability grades, only grade-(i) measurable observables (public, recomputable by every member) enter this algorithm; the hard-to-prove and unprovable grades inform the adjudication lane, never these formulas. (Grades and tiers: VERIFICATION_MODEL §§3.8, 6.4.)

**Capability-per-declared-compute anomaly tracking.** MEASURE additionally maintains, for members and affiliates, the ratio of demonstrated deployed capability to declared training compute. Deployed capability rising faster than declared training explains is the fingerprint of **workload offload** — auxiliary tiers shifted to undeclared or recycled fleets, freeing declared compute for capability training with no observable trace change. The signal is **advisory**: it never gates the throttle. Its routing is **advisory-to-audit** — a sustained anomaly raises the flagged party's audit sampling within the published bounds of §5's audit-intensity discipline. (The attack and its full sensor set: VERIFICATION_MODEL §4, play 7.)

**EVALUATE.** Each parameter is normalized to field share (scale-free and auditable): pᵢ/Σp. The capability score is the weighted sum of shares, scaled by n so the field mean is 1:

> **Cᵢ = n · Σ_p ( w_p · rawᵢ,ₚ / Σ_j rawⱼ,ₚ )**

**[STRUCTURAL]** the aggregate must be simple enough that **every member can recompute its own score, and every other member's, from published inputs.** Discretion in the aggregate is where capture lives; sophistication belongs in the remedy menu (§5), not in the measurement.


**Capability accountancy [STRUCTURAL] (v3.2 — the ghost binds its maker).** Capability exits a member's ledger only by **verified exit**: verified transfer (it enters another ledger), or verified natural retirement (within the published depreciation band, disposal-attested, timing-uncorrelated; the VERIFICATION_MODEL's apparatus defines the verification). The compute channel is flow-verified inventory — acquisitions externally verified at entry, physical stock sampled against the book — so an unexplained absence is measured as a *discrepancy* (units unaccounted for), never as a lower stock: the difference between book and inventory is itself an objective quantity. **Two readings, one asymmetry:** the holder's own test runs on *accountable* capability — verified-present plus the unverified-exit stock, band-depreciated (the obligation converges to what honest conduct would have owed over the assets' natural life) — so destruction gains its maker nothing; **every field statistic and every other member's quantity (T, C̄, M, each S_j, μ_top) uses verified-present capability only** — all safety arithmetic runs on physical truth, and a really-weakened field correctly tightens allowances: the margin doing its job. **The book binds its keeper; the field reads reality.** The unverified-exit stock is never permanent: it expires with the band (the assets' remaining natural life — the obligation's duration automatically proportional to the value denied), or releases at any later time upon verified attestation (the cure door never closes), or through the estimation lane on documented catastrophic loss (force majeure). **Release is by evidence or by time, never by petition or payment.** Disposal-attestation fraud is conduct (sanction class 29).

## 5. Stage TEST, OFFER, CHOOSE

**TEST (closed form).** Reducing a member's score lowers T, which lowers every allowance — so the requirement is a fixed point, solved directly *(exact for the moving member with the rest held; simultaneous multi-member corrections converge across evaluation cycles, geometrically — witness check 4)*. With Sᵢ = T − Cᵢ (the rest, held fixed as member i reduces):

> **required reduction Rᵢ = max( 0, Cᵢ − Sᵢ / ((1 + μ_eng)·f_cap − 1) )**  — equivalently Rᵢ = max(0, Cᵢ − A_i)

A member with Rᵢ = 0 is within allowance and untouched.

**OFFER (the unit-partitioned menu).** A member reduces Rᵢ by earning **compliance credit**, denominated in score points. The excess in each parameter is partitioned into **UNIT-sized units**; each unit independently may receive **at most one** remedy:

- **Legitimate:** different units of the same parameter may take different remedies — e.g. part of excess compute under preapproval, the rest to a joint lab.

- **Blocked [STRUCTURAL]:** the *same* unit may not be claimed by two remedies. **Every credit must trace to a distinct unit of capability actually reduced, relocated, or defused.**

Remedy credit per unit, all under the **conservative-credit rule [STRUCTURAL]** (credit ≤ capability actually removed or defused; under-credit, never over-credit):

1. **Throttle** (acquisition parameters): credit = unit size. Slows further acquisition; never touches holdings.

2. **Open** (nonrival capability): credit = unit size × defusal factor, by level — supervised 0.40, prior-approval 0.60, shared-control 0.85, joint-lab 0.95 **[COUNCIL]**. All Council teams bound to preserve trade secrets. **Adverse-selection guard [STRUCTURAL]:** the menu must forbid routing the *most* dangerous capabilities to the *bluntest* opening levels, or the body systematically sees only the least dangerous things. **Leakage is priced:** supervision transfers tacit knowledge to expert supervisors; legal binding limits but does not eliminate this, and the member weighs it. *(v3.12, the author's catch, CONFIRMED by him round 348 — normative: the non-rival credit carries the scarcity weight ξ = 1 − coverage — opening what the rest already holds lifts nobody, so d_i does not actually move and an unweighted credit would be fictional; rival transfers and leases stay unweighted, real machines moving regardless of scarcity; menu openings address tiers, never picked individuals — structurally the unrestricted lane, ξ at release.)*

3. **Lease** (leasable holdings): credit = unit size × LEASE_CREDIT, with 1 < LEASE_CREDIT < 2 **[COUNCIL]** — leasing *relocates* capability, lowering the leader and raising the field at once, so it earns more than one-sided credit but strictly less than double. Leasing must be **genuine relocation** (provenance tracking applies; evaluations of capability max throughput confirm or refute that). Leasing can charge a fair cost, in order to compensate the leader. It reaches capability that throttling deliberately cannot (holdings), extending the horizon of §5-CHOOSE outward.

**CHOOSE.** The Council publishes the constraint and the credit ceilings. The member computes its own least-inconvenient combination meeting the constraint, taking into account its specific, possibly private, cost of each remedy. **[STRUCTURAL]** Because these costs are private, this computation cannot be relocated to the Council without loss of information; the assignment of the computation to the member is part of the algorithm, not an implementation choice.

**The no-choice default [STRUCTURAL zones; thresholds COUNCIL]: silence throttles, proportionately.** If no choice lands within the clock, the default scales on two published axes — the uncovered remainder of Rᵢ and the headroom consumed h_i — in three pre-committed zones: (1) small deficiency, little headroom: a cure clock plus a throttle sized to the gap (d_i frozen); (2) substantial either: the full acquisition freeze, the case docketed; (3) large deficiency at or past d_def: the escalation ladder immediately, clocks compressed on the hazard-indexed pattern, the Assembly notified — persistent silence is constructive refusal. Every input is on the public dashboard; the default has no discretionary knob.

**The clock [table and multiplier COUNCIL; the bridge rule STRUCTURAL].** The timeframe is computed, never negotiated: a base clock by correction type and size band (know-how fast; leasing medium; divestment slow), multiplied by a published urgency factor decreasing in h_i. Where the compressed clock falls below the type's feasible minimum, a prolonged clock may be **purchased by a bridge**: interim measures from the fast end of the menu (freeze, interim lease, supervised access, sequestration) holding d_i non-increasing for the bridge's whole duration — bridge credit provisional, trued up at completion under the conservative-credit rule. **Time is granted against risk held flat; prolongation is purchased, never pleaded.** No bridge → the compressed clock stands; inability routes to the ladder.

**The insufficiency state and the escalation ladder [STRUCTURAL].** A member may be far enough ahead that no combination of its available remedies reaches Rᵢ — because acquisition-throttling cannot un-acquire holdings and there is not enough left to defuse. This is a real, named state, and the response is an ordered ladder, each rung used only if the prior cannot reach:

1. **Mandatory leasing** — where leasing can close the gap, it may be *required* rather than offered, since it relocates holdings without confiscating them (last-resort narrowing of the menu to one option).

2. **Divestment** — the member sheds holdings (sale, spin-out). Heavier; touches what the throttle otherwise protects.

3. **Field elevation** — raise the whole field instead of lowering the leader: accelerated release, joint-centre access, Library and efficiency diffusion at zero window. **[STRUCTURAL rationale]** the compute channel can be frozen but not un-diverged; only knowledge, being nonrival, restores parity by being shared back. Field elevation is the knowledge channel doing what the compute channel cannot.

4. **Referral beyond the Council** — when internal remedies cannot restore the margin, the matter escalates to the standing security order that predates and outranks the Council (e.g. the UN Security Council). **The Council is explicitly not the top of the enforcement stack.** A near-decisive advantage in one actor's hands produces a near-automatic coalition of every other major power — the same adverse-selection logic that motivates the Council, one level up — and the Council's terminal function is to hand that order a **documented, quantified case while a case still exists to hand.** This bounds the Council's own power by design, which reassures the actors most worried it is a power grab: past a certain point the Council calls in powers it does not control, rather than becoming one.

**Practical corollary [STRUCTURAL]:** the instrument must engage not merely early enough to satisfy the margin arithmetic, but early enough that **the remedy menu can still reach** — there is a horizon past which the instrument exists but cannot close the gap. Locating that horizon, and setting μ_eng below it, is the Council's first calibration task (§7).


**Arming: the algorithm is self-arming [STRUCTURAL].** No separate "fire-bell" mechanism is required to switch the instrument on. Run continuously — re-evaluated whenever any input parameter changes — the algorithm produces Rᵢ = 0 for every member in the safe (log) regime, because there divergence does not occur and no member exceeds allowance; it produces Rᵢ > 0 exactly when a member diverges, which is the dangerous (linear) regime manifesting. The regime detection is therefore *implicit in the divergence itself*: the throttle is dormant when nothing exceeds allowance and acts when something does, with no gameable regime-detector to suppress. An elasticity-of-capability-to-compute detector (capability's local response to compute, ~0 in the log regime, →1 as returns turn linear) may be retained as an **optional early-warning heuristic** — it can flag an *approaching* flip before divergence appears — but it is advisory, not the arming condition, and must never gate the throttle, since a member approaching the flip is precisely the party motivated to suppress the signal. Note also the execution-level cost of over-warning: an advisory that cries wolf trains its readers to ignore it, so its threshold is tuned for signal, not for maximal caution — the bias-to-early-ringing argument applies to *arming* (which is now automatic and free) far more than to *warning* (which has a credibility budget).

**FLAGGED RESIDUAL — the hidden-flip attack [STRUCTURAL, UNSOLVED].** One attack defeats both the always-on algorithm and any elasticity heuristic. A member (1) discovers the log→linear flip privately, at small scale; (2) tests it below the tracking threshold, in the measurement noise, so its capability score stays unremarkable and the algorithm sees a minor player with no excess; then (3) applies the flip at large scale — whereupon the compute it *already holds*, previously safe, suddenly yields containment-breaking capability, because the conversion curve changed under it. Capability steps from within-allowance to decisive *between two evaluations*, with no gradual divergence to catch and no deployed elasticity trend to detect: both instruments watch for a *rising* signal, and this attack produces a *step* from a member who looked safe the instant before.

The attack requires all three of {private discovery, sub-threshold testing, held-unused-until-scaled} simultaneously; removing any one defeats it. This yields three partial defense surfaces, none complete:
- **(a) Threshold lowering** — track nearer the scale at which the flip first becomes testable. Bounded by noise: the attacker tests in the noise deliberately.
- **(b) Council-first discovery** — if the Council's own joint centres are likely to reach flip-class breakthroughs first (their standing task for the most dangerous directions), the flip becomes public and every member's compute re-prices *simultaneously*, converting a private step into a shared tide. This is the strongest partial defense and it is already in the design.
- **(c) One-cycle containment** — activation at scale produces a capability step the *next* evaluation sees, so the attacker holds decisive advantage for at most one evaluation cycle. Whether that suffices to act depends entirely on **irreversibility speed**, which routes to the endgame's floor on irreversible action.

**Honest statement:** the hidden-flip attack collapses the reaction window to a single evaluation cycle, and the design does not prevent it — it only bounds the payoff, through (b) making Council-first discovery likely and (c) ensuring nothing decisive can be done irreversibly within one cycle. This is flagged as a specific, named task for the Council rather than a solved problem: *guarantee Council-first discovery of flip-class breakthroughs, and guarantee one-evaluation-cycle limits on irreversible action.* A sharp flag is worth more here than a vague reassurance.

**The flip-defense stack.** The flag's answer is an ordered stack of three layers, each engaging where the prior is incomplete:

1. **Discover first.** Common labs aimed at the flip-prone directions, so flip-class breakthroughs are born public and every member's resources re-price simultaneously — subject to the **pre-release decisive-advantage evaluation**: this TEST stage, run on the release decision from declared holdings. **The gate's criterion [COUNCIL sets the tolerances]:** the finding tests **degradation relative to the pre-flip margin together with the defended floor, never the engagement threshold alone** — a field that happens to sit below engagement must not generate findings against mild advances that degrade nothing; the initial condition is not the advance's fault. A decisive-advantage finding requires both that release degrades the conservative-bound margin beyond the published tolerance *and* that the degraded margin threatens the defended floor. **The remedy's currency:** the rebalancing quantum is **denominated in the flipped channel** — compute for a compute-yield flip, data for a data-yield flip — because leasing one channel cannot neutralize a flip that multiplied another; and where the flipped channel is not transferable (class F influence), the instrument is **release-terms conditioning**: deployment obligations capping the driver's *exclusive* exploitation while the field receives the advance in full. A Developer whom release would hand a decisive advantage may be required to rebalance first, with full published explanation, refusal escalating the insufficiency ladder; the gate narrow (decisive-advantage findings only), published-reasoned, duration-bounded, fast release the default. The aimed mission, the amendable dangerous-directions list (maintained by the Council; amendable on its own initiative or on request by appropriate official bodies), and the establishment path are specified in the common-labs role document (COMMONLABS_FLIPDEFENSE).
2. **Share when found.** A Developer making a flip-class advance is invited to share it with a special Council team in exchange for the commercial rights over the advance and other non-suppressive rights — a bargain composed entirely from existing machinery (the open-instead menu, proven-capability listing rights, the Award's discoverer class, the fast-monetization lane). Honest scope: converts the marginal, rational actor, not the determined attacker; nearly free, therefore kept.
3. **Bound the payoff.** One-cycle containment (c above), tightened by the hazard-indexed cadence below, terminating in the endgame's floor on irreversible action.

**Hazard-indexed evaluation cadence [STRUCTURAL].** The one-cycle containment bound is exactly as tight as the evaluation cycle is short. The evaluation cadence is therefore not a constant but a published function of a **field-level flip-hazard index H_f**, computed from aggregate, member-blind signals (efficiency-benchmark trajectories, replication-bounty results, joint-centre findings, the advisory elasticity heuristic; the signal inventory is maintained non-normatively in the common-labs companion document). Rules:

- The cadence **shortens as H_f rises** and never lengthens beyond the published baseline **[COUNCIL** sets the baseline and the mapping**]**.
- H_f, its inputs, and the mapping are published and member-recomputable.
- H_f is **field-level only**: it estimates how close the field is to a flip, never which member — no member-level surveillance is introduced by this rule, keeping the standing regime inside the mandate limits. (Two adjacent instruments are distinct by construction: **exposure mapping** — who *would* gain, computed from already-declared holdings, standing and surveillance-free; and **member-level activity tracking** — a dormant emergency power, adoptable only by Developer supermajority under redaction-class discipline: enumerated scope, sunset, published activation, independent review.)
- The advisory elasticity heuristic may shorten cadence *through* H_f, but still never gates the throttle.

Effect: the attacker's ≤1-cycle window shrinks precisely when a flip is near, at zero intrusiveness cost — the containment bound tightens automatically where the flag says it matters.

**Hazard-indexed audit intensity [STRUCTURAL].** Audit sampling rides beside cadence under the same discipline: as H_f rises, sampling densifies — the mapping published and member-recomputable [COUNCIL sets baseline and mapping], sampling never falling below the published baseline. Because flips attack sensors first (efficiency and composition advances shrink the physical footprint exactly when it matters), the audits thicken exactly when the sensors are most doubted. The field-level component is member-blind, indexed by H_f alone; the only member-directed component is the published advisory-to-audit routing of §4's anomaly tracking — audit intensity is the single instrument advisory signals may touch, and the throttle is never among them.

**The outside-aware throttle [STRUCTURAL].** The throttle's purpose is *internal* anti-divergence, and it is **subordinate to collective survival — in writing**. The margin monitor therefore carries a **world-margin estimate**: the best statistical-tier estimate of the leading outside (non-member) actor's capability, error bars published. When the estimated outside frontier closes within a **published distance** of the member frontier, **throttle easing is pre-committed** — entry and exit by published indicator rule, no vote required: the convoy is never braked while a stranger accelerates past it. For the true dark horse the estimate bounds weakly, and the honest placement stands — sensors carry that case poorly; the endgame instruments and the convoy's combined velocity carry it. **Easing never arrives alone [STRUCTURAL]:** the same indicator rule that releases the brake engages the **convoy-acceleration list** [COUNCIL-maintained; canonical in VERIFICATION_MODEL §5.4] — the window interval shortened, easing extended even to internal-margin violators, the sharing instruments run hot, and the recruitment arm aimed at the outside field's second rank. The bundle is also a defense: an insider tempted to *provoke* this weather by feeding an outsider (the provoked-easing play, VERIFICATION_MODEL §4 play 8) pays for its freedom by diffusing its edge inward, having already burned it outward — the play bounded, honestly not prevented. This regime composes with the degraded-verification regime below.

**The flip-defense interface (v3.19).** Common-lab discoveries under Council agenda are born attested but not born released: release passes the pre-release decisive-advantage evaluation — the TEST arithmetic run on the release decision (COMMONLABS_FLIPDEFENSE §4). Hazard estimation is two-tier: field-level and member-blind as the standing mode; member-level tracking exists only as the dormant emergency power under its double discipline.

**The degraded-verification regime [STRUCTURAL].** The dangerous verification failure is correlated: dark stock rising *while* H_f rises *while* narrative inconsistencies accumulate — each within its own tolerance, the combination not. The regime is entered on a **published combination rule** over those three indicators — initial form (round 359): each indicator carries a published *watch line* beneath its *action line*, and **any two simultaneously above watch count as one action-line breach**, entering the regime (m = 2 [COUNCIL]; the early-warning-score pattern: several mildly abnormal readings sum to one alarm) — and its effects are pre-committed: **μ_eng tightens** (through c, per §2's ledger coupling), **cadence shortens**, **audit sampling densifies** — all automatically, so that no vote is needed in exactly the moment votes are hardest. Exit likewise by published rule. This is the redaction-class discipline applied to an operating mode; it composes with the outside-aware easing above (degraded verification *and* outside approach is the design's worst weather, and its response is pre-written).


## 5b. The floor and the support side (the anti-attrition core)

**The floor [STRUCTURAL anchor; φ COUNCIL].** **L = φ·M** — the median, never the mean: no runaway leader can drag the line (the anti-dynamic anchor). **Support quantum H_i = max(0, L − C_i)** — the mirror of Rᵢ from the other side.

**Eligibility is a reading, never an application [STRUCTURAL].** The dashboard shows C_i < L; nobody petitions. **The fall condition (v3.4): the net catches the falling, never the arriving** — eligibility requires having previously stood at or above the floor (read from the same ledgers); a member entering at the seat bar is born outside the net, its birthright being the design's larger gift — the window's released corpus at the Developer schedule, the commons, the talent programs, the exchange. Support is a hospital, not a nursery; the market funds nurseries. *Exception by rule:* in the low-count regime (n < n_min) the condition suspends — when the field is dying, subsidizing capable newcomers is recruitment, the alarm's own tool. (Shell entrants fail upstream regardless: controlled creations sit on the parent's ledger by the aggregation rule, and seeded capability arrives as a verified transfer.) Eligibility opens the menu; nothing flows without the conditions.

**The conditions [STRUCTURAL]:** support is voluntary (corrections are obligatory; support is offered); in kind, never cash; capped by a published budget; conditional on demonstrated own effort; usable for AI development only. **Sunset with hysteresis:** support ends when **C_i ≥ L·(1+ε)**.

**The self-help formula [STRUCTURAL form; m COUNCIL] (v3.3).** I_i = the member's verified own development commitment in the cycle, in capability-equivalent units (flow-verified acquisitions; talent intake; declared internal spend under the consistency apparatus). **e_i = I_i/C_i** the investment intensity; **σ_i = e_i/ē_M** the self-help index against the Developer-median intensity. **The matching bound: cumulative support credited toward H_i ≤ m·I_i** (m = 1 initially) — support supplements own effort by construction; zero effort draws zero support with no assessment organ; where the budget binds, priority runs by descending σ_i. (The deep-attrition edge is intended: e_i grows as C_i shrinks, so the sunk-but-rowing rank first, while the matching bound keeps absolute support proportional to absolute effort.)

**The support quantum's closed form and the draft [STRUCTURAL] (v3.5).** Credited support per cycle: **S_i = min( H_i, m·I_i − prior credits, B_remaining )** — capped by need, by effort, and by the published budget, allocated in descending-σ order where the budget binds. The recirculation pool is itemized and published each cycle (**the catalog**: the leases, access grants, first-offer divestitures, talent slots, and absorption assistance that §5's corrections currently supply, each at its par credit value); allocation is **the support auction** (v3.6, the author's mechanism): each eligible member's bidding endowment is its S_i in support rights; the default is par pricing with σ-precedence — passive bidders receive exactly the draft outcome, so no sophistication is ever required — and a member may bid above par for a specific item (accepting less total capability for better fit), in a **sealed, single round** — no bid is seen before all are cast, so no escalation dynamic exists — winning at the second-highest bid or par (the truthful-bidding rule: over-bidding changes outcomes only where it hurts the over-bidder; bids are mechanically capped at the endowment); rights spent never exceed the endowment, so every ceiling holds through any bid. Nothing is ever assigned, decline is always free, and the clearing prices publish. Unsold items roll to the next cycle's catalog; persistently unsold inventory is a published mispricing signal feeding the Council's rate maintenance. (Precedent: the Feeding America shares market — capped scrip among needy claimants for heterogeneous goods, no cash; and the leagues again — the draft is this auction's all-par case.) Note the earned exit: H_i reaches zero at L while the sunset sits at L·(1+ε) — support lifts a member to the floor; the last ε·L is the member's own growth by construction.

**Support rates [COUNCIL initials]:** preferential leases and first-offer divestiture purchases credit 1:1 toward H_i; opened know-how access 0.5, rising to 0.8 with absorption assistance; talent and co-development slots at values from the estimation lane. **The recirculation link [STRUCTURAL]:** the ceiling's corrections are the floor's supply — opened know-how, leased capacity, and divested assets route preferentially downward (right of first offer on divestitures).

**Compensation, de-subjectified [STRUCTURAL] (v3.8 — advantage, never amount).** Exclusivity is a per-item reading, continuous: each capability item carries an **exclusivity weight ξ = 1 − coverage**, coverage being the capability-weighted fraction of the field already holding it (read from the sharing graph and holdings declarations, verified under the consistency apparatus; the estimation lane bridges where item granularity is coarse). The **advantage stock E_i = Σ amount·rate·ξ, over non-rival items only** (v3.14: know-how, data access, experience — what opens without leaving the holder; rival exclusives stay in C_i but exit the compensation lane, since paying the debt must never deepen the need — **the debt takes copies, never the machine**) — not what the member holds, but what the member holds that others lack — computed for every member each cycle: no application, no accusation, no threshold. Support receipt creates an **opening-debt D_i = support received, capped at E_i** (no advantage stock, no debt); **opening credit uses the identical formula**, so a commodity item credits approximately nothing at any volume and a unique item credits in full — the credit measures the recipients' gain, which is what compensation buys. The member chooses which items open, within the published clock (the crown-jewel boundary untouched); nonstandard packages — altered tiers, substituted assistance, entanglement re-itemizations (where opening one item unavoidably reveals another, the bundle re-itemized as one) — are priced by the estimation lane at the published rates, **a valuation, never a negotiation**, disputes to the Adjudication Organ (v3.17, round 355). **One rate table, three seams (v3.12, the author's re-aim):** the compensation opening is the same act as a §5 correction opening and credits at **the same defusal-family rates** (§5's Open item; 1:1 rival) — no compensation-specific table exists; the same estimation lane maintains the one family; the compensation seam adds only ξ and validated uptake on top. **Rates are par anchors, never valuations (v3.10):** the class-level rate tables (Council-published through the estimation lane; the existing initials stand) need only be roughly right — fine pricing is done by realization, and the mispricing signal maintains the anchors. **The two-lane credit rule:** an *unrestricted* opening (every Developer at the mandated tier may take it — the debtor cannot pick its audience) credits at release, amount·rate·ξ — availability is the good, per the window's grammar, and complementarity averages across all lacking takers; a *directed* opening credits **only on validated uptake, at the price actually borne** (v3.11 — validation, never valuation: the thin-market correction): the clearing price where competition happens to exist, otherwise par upon a single **costly acceptance** — support rights if the recipient is eligible (taking the useless eats a capped endowment), the ordinary sharing compensation if not (payment is the validation), or verified absorption effort on the free tier. **One genuine counterparty suffices; price discovery is a bonus of thickness, never a requirement** — the support pool in a healthy field holds one to four members, and the net's own success thins its market, so the mechanism must degrade gracefully and now does. Contextually worthless deliveries discharge nothing (the counterparty will not spend to take them); the collusive rubber-stamp dies on the cost requirement. The forfeit stated: the fine complementarity gradient is lost — credit integrity needs worth-taking-or-not, never the gradient. (Honest residual: scarce-but-useless unrestricted openings can modestly game the ξ-lane — bounded by the anchors, surfaced by the uptake signal, discounted by the estimation lane where uptake is chronically dead; small, because know-how useless to all is nearly costless to open and credits little under honest anchors.) **Credit follows lack (v3.9):** an opening credits at the ξ-rate only if **unrestricted** — available to every Developer within the mandated supervision tier, so all who lack it can take it (the field's gain then is the lacking share, which is what ξ prices); a restricted or directed opening credits only per **verified receipt by members who lacked the item** — the sharing graph knows who lacked what, so an opening addressed to existing holders computes to zero credit, with no one ruling on intent. Enforcement is arithmetic: an overdue debt automatically pauses new draws while persisting on the books — **release by opening, never by petition** (the lien pattern; received help never clawed back — the future flow waits). **The residual rule (v3.14 — the debt lives on the band):** the booked debt carries **no interest and no growth** (the frozen mirror of value received, drawn voluntarily unit by unit, each unit pricing itself at the draw), waits accountancy-style, and **re-engages whenever E_i holds openable stock**; a member at E_i = 0 is never paused — overdue requires openable stock, so there is no punishment for poverty. The debt **depreciates on the published band schedule from receipt, independent of status** — expiry by time, never by sunset, so suppressing new exclusive development accelerates nothing (the clock runs regardless), and the timing residue left at the horizon's edge is dominated by the competitive cost of delaying frontier work to dodge a bounded, interest-free, access-only debt. The won't-pay residual (openable stock unopened past the clock) follows the ordinary default path and blocks re-entry. One grammar for ghost and lien alike: **release is by evidence or by time, never by petition, payment, or status. Poverty is forgiven; refusal is not; and the whole debt dies by the band.** **The unexplained-capability residual (v3.15 — the ghost's mirror):** while a debt is booked, measured capability exceeding, beyond the published tolerance, what declared holdings plus verified absorption of the released corpus can explain **enters E_i as a residual at ξ = 1 — presumed exclusive until explained** (capability explained by neither declared items nor the corpus is, near-construction, what others lack; the net-worth method: unexplained increase presumed, burden on the holder). Explanation is always available and weakly better: declaring the items either registers openable exclusivity or shows commodity coverage, shrinking the residual honestly — **silence gains nothing; hiding lands in the openable stock at the worst ξ**. Sandbagging to suppress the residual walks into the input-productivity anomaly and the trajectory passport (the pincer); calibrated mediocrity between both detectors remains the stated detection-dependent residue — and costs the debtor the very use of what it hides. A genuinely poor member's capability is fully explained: no residual, no pause — poverty stays forgiven. **Unexplained absence stays on your books; unexplained presence enters your openable stock — the ledger presumes against the silent.** **The tranche and the revival (v3.17 — revival by surfacing, never by provenance):** the booked debt depreciates on the published band schedule **beginning at the end of the support period** — no depreciation runs while draws continue (the author's rule, round 357: stronger against shelving-while-drawing than per-tranche banding, which it supersedes, and simpler). And **the debt dies by time or is paid by success, whichever the world sees first**: any exclusivity **surfacing** — declared, used (the residual reads use), or deployed — **within the debt period (support plus the depreciation horizon) plus a published tail** (one band-length of the surfacing capability's own class [COUNCIL] — the author's precision, round 354: each class's obligations live and die by that class's clock) **pays the outstanding or expired tranches at surfacing-time ξ, regardless of claimed creation date.** Creation dates are unobservable and unobservables make bad law (the v3.16 provenance rule, corrected on the author's objection): the trigger here is the capability appearing in the world, which the sensors already watch — nothing to fake, no dating dispute, no whistleblower needed. The shelf must now outlast band plus tail with zero realization, breaking the preparation-period cover, while the hoarded ξ rots at the field's pace and the member's own recovery waits — the dodge shrinks toward nothing as the shelf lengthens. The honest cost stated: a genuine post-window creator surfacing inside the tail pays up to the tranches at surfacing-ξ — reciprocity-on-success, bounded by support received, softened by the field's catch-up: §4.1.5's spirit arriving late, the price of a rule silence cannot game. (Residues stated: shelving past the tail remains, bounded and self-punishing; covert transfer stays the general dark-channel adversary, detection-dependent, the scorecard's row.) Kinship noted: the contribution formula's counterfactual-lift grammar — value is what the world gained — applied at the compensation seam; same philosophy, separate homes.

**Compensation [STRUCTURAL boundary].** A capability-rich recipient opens an equivalent **valued at the support received, never at strategic worth, and chooses itself which capabilities open** — the floor must never become a lever for prying open a struggling member's guarded assets. The support-for-opening exchange (Board-decided, within the published support budget) is governed by its GOVERNANCE row.

**The count and concentration regimes [ratchet asymmetry STRUCTURAL; values COUNCIL].** n is a published health meter: alarm grade at n ≤ 10; while n < n_min the seat bar loosens by a pre-committed step per cycle (never by vote): the bar is median-anchored, **b = β_seat·M**, and β_seat multiplies by **(1 − s)** each cycle, **s = 0.10 initially [COUNCIL]** — a relative, scale-free step (round 356; the full seam design — rule-yields-count calibration, automatic ascension, the gap meter — is the Developer-seam verdict, penned at its queued sitting); the loosening halts when n reaches n_min; tightening only while n ≥ 12, prospective, one-cycle-delayed, brake-able. **μ_top = (T − C_top)/C_top** over the K = ⌊(n−1)/3⌋ largest, watch line μ_req: erosion engages **field elevation, never ceiling-tightening** — when the top grows too heavy, the design does not shorten the tall; it raises the rest.


## 6. The change process is half the algorithm [STRUCTURAL]

The parameter set, weights, defusal and lease factors, and μ_eng are the capture surface. Protections:

1. Changes by **Byzantine-or-higher majority, never unanimity** — the developer of a newly significant capability might vote against watching it, so unanimity might mean not watching something new and important.

2. **Listing a proven capability guarantees its business advantage to the first developer of it** — inverting the incentive so that listing is something members *want*, turning the watched list into a property registry rather than a threat.

3. **Residue, stated.** A majority coalition can tilt the watched list against a lone member. **Classification: inherited, not introduced** — this is the coalition problem of the general design, tracked in the objection ledger, where its treatment lives; this algorithm adds no new instance of it.


## 7. Calibration, conformance demonstration and limits

**Calibration (Council's, in order).** (1) The reach horizon and μ_eng below it. (2) The parameter set and weights. (3) Defusal and lease factors. (4) UNIT granularity. Every one is expected to need ongoing tuning; this is a control mechanism, and control mechanisms are tuned. A sound mechanism requiring calibration is not a weakness — it is what every working governor is.

**Structural results (robust; the load the work supports).** Individual-allowance-is-coalition-safety; target-holdings-not-rank; acquisition-not-holdings (save freely-elected leasing/divestment); conservative-credit; one-remedy-per-unit; member-chooses-on-private-cost; engage-early-enough-to-reach; the escalation ladder ending beyond the Council.

**Conformance demonstration (witness rewritten for v3.0; run of 2026-08-03, all assertions green).** `reference_algorithm_v1.py` (internal version 3.0) implements §§2–5b and demonstrates: the ratio/allowance equivalence; the coalition theorem for all f_cap-subsets; the pooling identities exact at both ceilings; the fixed-point property of TEST; strict feasibility and the energy report with the ceil/round dial table; the floor quantities and sunset; and the head's worked scenario (n = 16, five leaders at 170: R ≈ 15.6 each, h ≈ 0.64, the eleven untouched; μ_top ≈ 0.88 below the watch line — the concentration gauge fires and elevation engages; three at the ceiling pool to 41.3%, outweighed exactly μ_eng).

**The v1.3 deferred list, resolved at v2.0.** (The fire-bell arming condition was already addressed in §5: the algorithm is self-arming, the elasticity detector demoted to an advisory heuristic, the hidden-flip attack answered by the flip-defense stack and the hazard-indexed cadence.) The verification model exists — VERIFICATION_MODEL v3.1, whose normative flow-back (the c/r identity, the honesty tiers, the two operating regimes, audit intensity, the jurisdiction rule, anomaly tracking, the gate criterion) this version absorbs. The co-participation contribution formula exists — CONTRIBUTION_FORMULA v1, machine-verified; the charter points to it. Unification with the dynamic model executed this version, findings in the witness header: `margin_throttle_FINAL.py`'s constants match §2 (μ_req 2.0, μ_eng 5.5, f = ⌊(n−1)/3⌋) and its allowance is §3's formula exactly; its continuous buying-power scaling (1 − excess) is a **deliberate simplification** of §5's unit-partitioned menu — the dynamics need a differentiable brake, the norm needs auditable units — and its scope deliberately excludes the outside actor and the operating regimes, which the witness exercises instead. Where the two disagree, the specification governs, as the header has always said.

*— Specification v3.19 complete and self-contained; aligned to the ANTIDIVERGENCE v2 head under the machine-truth guard (round 323). Conformance witness attached (reference_algorithm_v1.py, internal v3.0, rewritten and green at this version).*

