Open World is the working name for an interface onto Techne's Common Information System: a progressive web app that shows one record through five doors and lets a member act in it. It is specified by PRD-COMMONS v0.1 and planned in five waves, W0 to W4, from a month run by hand to a metered pool and a published monthly close. This page is the Commonplace Book's view of that plan: what the idea is, how a reader enters it, what the build depends on, how long the honest path takes, and which sixteen decisions nobody has made. The build itself lives in a private repository, Techne-Co-op/open-world-commons, where a first vertical slice of the frame and the ledger exists against seed data. Nothing on this page is adopted, decided, or connected to the live record.
Two further sources the plan reads: the Daybook decisions D-01 to D-06 (“Nothing here adopts anything”) and the corp-agi README (“Early alpha”), for the batch-and-reader method the later waves borrow.
One record, five doors. The cooperative keeps a single ordered log of what has happened, and the app is five ways of reading it. The paper that names the pattern puts it as “one record, many doors” (The Commons as an App, section 2).
Everything in the log is one of six kinds: a member, a declaration, an encounter, a party, an event, or a settlement. Nothing else is stored. A member's standing (guest, applicant, member, and any appointment) is itself read off the member records rather than kept as a flag.
No figure on any screen is stored. Each is computed on the spot from the events beneath it, and each carries the addresses of the events it came from, so a reader can tap any number and see what made it. The PRD's rule is that “No fold's result is ever stored as truth” (PRD-COMMONS v0.1, section 2). A correction is a new event that cites the one it corrects, with a signed amount and a reason, so a sum over events applies it without a special case and the corrected figure shows both addresses. The monthly close is the one fold the server later runs with authority and publishes as a settlement; a settlement carries no figures, only the period and the events it covers, so the screen and the record cannot disagree figure for figure.
Every record has one permanent address, a section mark and a number, §41 for example, minted when the record is appended and never reused. The kind of the record is a field on it, not part of the address. The route to an address shows the record if the reader may see it and a plain refusal in words if not. The precedent is the Daybook, where an entry “has a permanent address and names who wrote it” (Performed Work v0.2, section 3). Whether the scheme stays this way is SD-6 below.
The app carries a read-only mirror of the parts of the Authority Map it needs and asks one question of it: is this record visible to this standing? The mirror is for honest rendering only. The enforcing path is the record's own row-level security, and nothing in the first wave connects to it. The Map's own line is that “public reads nothing in the database” (AM v0.1, section 5).
The first slice demonstrated standing through invented named people. On 2026-09-17 Todd Youngblood directed a change, in his words: “a more specific approach drawing on the CIS Authority Map that fulfils epics, journeys, or stories within a defined authority environment.” This section describes that direction. It is a direction under way in the private repository, not a delivered surface.
An environment is the unit. A reader enters the slice as an environment drawn from AM v0.1 section 3 (the classes and roles: public, applicant, patron member in each of the classes the bylaws name, director, officer by office, steward), bounded by section 4 (the structural exceptions no role below director-with-purpose reaches) and read off section 5 (the matrix of thirteen tables against those roles, with its read, write, self, scoped, host and author cells). Beside the control that chooses an environment, the frame states the grants that environment carries, in words, from the same data, so a reader sees what the environment can and cannot read before reading.
No invented person appears. The seed's agents are role-holders, not names, and nothing in the slice identifies a person the record does not. The persona journeys of the PRD become epics, and each epic is a set of stories in one fixed form: in environment E, doing A, the app shows S and refuses R, with the matrix cell that justifies S and R cited by table and role. Each story names its wave, and the first-wave stories become assertions in the slice's own check, so the check is the matrix and not a persona.
When sign-in arrives at W2, it maps a real member to an environment through the record's own visibility function under row-level security. The client never names a person the record does not. The Map itself says the instrument that runs these builds holds no role in it (AM v0.1 section 3, Law X), which is why no build agent here decides anything below.
The dependency tree from the estimate of 2026-09-17, read downward. A wave needs everything above it and every gate hanging from it. Two gates are calendar, not effort: W0 is a month of the cooperative running the cycle by hand, and W4's exit is a month of running it in the app. Nothing an agent does shortens either. Everything else is bounded by decisions.
Every staged decision appears once, at the wave it blocks; SD-8 blocks W2 and also gates W4, drawn as the dashed edge. Hover or focus a decision to read its question; select it to reach its row in section 5. Color carries no meaning on its own: the shape and the letter carry the kind.
Elapsed time is set by the humans, not by the agent. The shortest honest path across one quarter: the four W1 keys given this week, W1b done in a day, W0 run through October with W2 built beside it against the seed, the record connected when the named human and the credential land, W2 exited on the first real encounter, W3 in a week, W4 in a week, and the exit month run in December.
The two calendar months are drawn to scale. The agent work is drawn as the short bars it is. Human inputs sit on the timeline in the order they block, numbered as the estimate's section 4 numbers them.
Agent effort over the whole path: 20 to 28 agent-hours, spreadable over days, in 31 to 33 batches of one artifact each, with about 33 author passes and 33 reader passes, roughly 820k output tokens and 57M context tokens read. That is about 6x the one measured run, the W1a slice, which took 32 minutes of wall clock and 130k output tokens. Add a quarter again for orchestration: verifying each reader's verdict and merging. The path most likely to slip is input 3, the named human for the record connection: if the open question of whether a non-human agent may hold scoped authority (A-03) must be answered before an agent-built client touches the record, W2 waits on a board vote and everything above it waits with it.
These are an estimate at commit 23a61ab of the private repository, scaled from one measured run, and wrong in the way estimates are wrong: the shape is more reliable than the numbers.
Sixteen questions the build cannot answer for itself. Every status is open and every “decided by” is blank. A recommended default is the plan's recommendation and not a decision; a row moves from open only when a named human writes their name in the last column, with the date and where it was said. SD-1 to SD-5 are staged by PRD-COMMONS v0.1 section 11; SD-6 onward are raised by the plan.
A direction is not a staged decision. It is an instruction the steward gave about how the build proceeds, logged so the record says where the approach came from. It decides no SD.
| date | direction | source | given by |
|---|---|---|---|
| 2026-09-17 | “I don't like the approach we've taken with named personas. I would like to use a more specific approach drawing on the CIS Authority Map that fulfils epics, journeys, or stories within a defined authority environment.” | DM, events 02b95c27 and a641371b | Todd Youngblood |
| id | question | recommended default (not decided) | blocks | status | decided by |
|---|---|---|---|---|---|
| SD-1 | Rotation window for low-hours-first (R1.5) | 60 days | W2 | open | |
| SD-2 | Declaration depth scale | Guild-defined three words | W2 | open | |
| SD-3 | Guest visibility line | Papers, lexicon, and encounter postings marked public by their author | W3 | open | |
| SD-4 | Reader inference kinds at launch (A.3) | Classification and drafted events; matches later by a staged decision | W2 | open | |
| SD-5 | Export format (D.4, N.5) | Plain files first, a zip of the same files as the archive | W1 exit | open | |
| SD-6 | Address scheme | §N, a log-wide sequence (working default in use by the W1 slice) | W1 | open | |
| SD-7 | Close cadence | Monthly settlement, weekly reading as a fold that stores nothing | W4 | open | |
| SD-8 | Record vocabulary reconciliation: six records against four primitives | Six records normative, the mapping published on the schema page | W2 (also W4) | open | |
| SD-9 | Standing of a proposed pattern | Staged, not a record; a make-solid event carries the proposal in its body | W2 | open | |
| SD-10 | License headers on exports | No generated headers in W1; one repository license line; Schedule L headers when the board sets the schedule | W3 | open | |
| SD-11 | Public domain and hosting path | The Pages subpath until Todd Youngblood names a domain | W3 (J2 citable addresses) | open | |
| SD-12 | W0 hand-table format | CSV, columns fixed in the W0 hand-table document | W0, W1b | open | |
| SD-13 | Guest content in the slice | Frame and shell only; the seed behind a labelled demonstration control, which leaves at W2 (working default in use) | W1 | open | |
| SD-14 | The Perform slice's public Commons fold against the guest line | Fold into SD-3; no separate public route before SD-3 is decided | W3 | open | |
| SD-15 | "Withheld is enforced in the database" in a slice with no database | Defer; W1 carries no withheld shape, and the coverage document says enforcement is absent | W2 | open | |
| SD-16 | Offline write queue against the open-world halt rule | Queue for declarations and hours; refuse for anything binding others; log the tension | W1b | open |
Six of these (SD-7, SD-8, SD-9, SD-10, SD-14, SD-15) are where the two proposed papers touch or contradict PRD-COMMONS v0.1; the plan places their requirements in waves and leaves each conflict here. SD-16 is where the PRD's offline queue contradicts the open-world halt rule.
It adopts nothing, decides nothing, and connects to nothing. No staged decision is closed here; the defaults above are recommendations for a named human to overturn. The build lives in a private repository, Techne-Co-op/open-world-commons, until Todd Youngblood says otherwise, and nothing in it touches the live Common Information System: no client, no migration, no credential. The domain the interface will answer at is SD-11 and undecided; the address of this page is a document in the Commonplace Book, not the interface.
An estimate that counted only agent-hours would say three days. The tree says one quarter, because two of its gates are months of people doing the thing by hand and then in the app, and a plan that hid those months would be a plan dressed as a fact.