Spec

53 live assertions across 16 areas, 4 withdrawn and kept on the record. None is stable yet, on purpose.

Each assertion states one thing the method requires, cites the source it was read from, and carries a trust token saying how far to trust it. Nothing reaches stable while Q-G-0001 is open and no transcript has been re-read by a human. See the legend.

THG Thing

IDTitleTrustLevelStatus
PM-THG-0010 A Thing is a class in a subclass hierarchy SRC-PATENT MUST draft
PM-THG-0020 A Thing compiles to an OWL class SRC-PATENT MUST draft
PM-THG-0030 An imported model's main Thing becomes a subclass of the importing model's SRC-PATENT MUST draft

PRP Property

IDTitleTrustLevelStatus
PM-PRP-0010 A Property belongs to a Thing SRC-PATENT MUST draft
PM-PRP-0020 A Property compiles to a schema property with its Thing as domain SRC-PATENT MUST draft
PM-PRP-0030 A relationship Property is the predicate of a Filter proposition INFERRED MUST draft

AGT Agent

IDTitleTrustLevelStatus
PM-AGT-0010 An Agent is the actor that moves instances through their States SRC-PATENT MUST draft
PM-AGT-0020 Agents form a hierarchy that inherits privileges SRC-PATENT MUST draft
PM-AGT-0030 An Agent holds no logic SRC-PATENT MUST NOT draft

STA State

IDTitleTrustLevelStatus
PM-STA-0010 A State is calculated, never received or stored as a label SRC-PATENT MUST draft
PM-STA-0020 A State is modelled as a subclass of a Thing SRC-BLOG MUST draft
PM-STA-0030 Both objects' States are calculated before a transition is evaluated SRC-PATENT MUST draft
PM-STA-0040 An Operation achieves exactly one State SRC-PATENT MUST draft
PM-STA-0050 States carry an inferred prerequisite ordering SRC-PATENT MUST draft

STR State Restriction

IDTitleTrustLevelStatus
PM-STR-0010 A State Restriction is the membership criterion for a State SRC-BLOG MUST draft
PM-STR-0020 Restrictions are evaluated closed-world INFERRED MUST draft
PM-STR-0030 Restrictions in the sources' own style are not mutually exclusive CONFLICT MUST NOT draft
PM-STR-0040 A State Restriction is a subclass cardinality restriction, positive or negative SRC-PATENT MUST draft

PTN Partition

IDTitleTrustLevelStatus
PM-PTN-0010 A Thing may have several independent state dimensions OPEN MAY draft
PM-PTN-0020 If Partitions exist, state selection is per Partition DESIGN MUST draft
PM-PTN-0030 A Partition is not a Filter and not a Component DESIGN MUST NOT draft

OPR Operation

IDTitleTrustLevelStatus
PM-OPR-0010 An Operation changes an instance's State SRC-PATENT MUST draft
PM-OPR-0020 Operations are Transactions or Actions SRC-PATENT MUST draft
PM-OPR-0030 An Operation declares the Thing it transitions CONFLICT MUST draft

EVT Event

IDTitleTrustLevelStatus
PM-EVT-0010 An Event is the domain's only interface to the outside SRC-PATENT MUST draft
PM-EVT-0020 An Event is inbound or outbound SRC-PATENT MUST draft
PM-EVT-0030 Nothing but an Event may cause a transition DESIGN MUST NOT draft

AUT Authorization

IDTitleTrustLevelStatus
PM-AUT-0010 An Authorization grants Agents access to a group of Events SRC-PATENT MUST draft
PM-AUT-0020 Authorization is scoped to a domain SRC-PATENT MUST draft
PM-AUT-0030 Derivations attach to an Authorization, not to an Operation SRC-PATENT MUST draft

FLT Filter

IDTitleTrustLevelStatus
PM-FLT-0010 A Filter qualifies the applicability of an Operation SRC-PATENT MUST draft
PM-FLT-0020 A Filter's proposition relates two States through a predicate SRC-BLOG MUST draft
PM-FLT-0030 The transitioning object is the Object of the proposition INFERRED MUST withdrawn
PM-FLT-0040 A Filter without a quantifier is not a proposition CONFLICT MUST withdrawn
PM-FLT-0050 A Component completes and constrains the Filters of the models it imports CONFLICT SHOULD withdrawn
PM-FLT-0060 A Filter's proposition is existentially quantified on both positions SRC-PATENT MUST draft
PM-FLT-0070 A Component refines the Filters it imports and MUST NOT alter them SRC-PATENT MUST draft
PM-FLT-0080 No fixed position binds the transitioning object to the proposition CONFLICT MUST NOT draft

CND Condition

IDTitleTrustLevelStatus
PM-CND-0010 A Condition gates the arrival at a new State SRC-BLOG MUST draft
PM-CND-0020 A failed Condition leaves the State unchanged and emits an outbound event naming the violated constraints SRC-PATENT MUST draft
PM-CND-0030 Conditions are state-specific and validate both objects' transitions SRC-PATENT MUST draft
PM-CND-0040 Whether a Condition sees the pre-transition or post-transition data is unresolved CONFLICT MUST withdrawn
PM-CND-0050 A Condition is evaluated against the State the Operation would achieve SRC-PATENT MUST draft

DRV Derivation

IDTitleTrustLevelStatus
PM-DRV-0010 A Derivation derives the data a transition requires, per Agent SRC-BLOG MUST draft
PM-DRV-0020 Derivation covers five distinct kinds of rule SRC-BLOG MUST draft
PM-DRV-0030 A Derivation guarantees the target State by writing what its Restriction requires SRC-BLOG SHOULD draft

CLS Classification

IDTitleTrustLevelStatus
PM-CLS-0010 The three abstraction levels are distinct model kinds SRC-PATENT MUST draft
PM-CLS-0020 Scope and abstraction are independent axes INFERRED MUST NOT draft
PM-CLS-0030 Whether the classification is complete is unresolved OPEN MUST NOT draft

CMP Composition

IDTitleTrustLevelStatus
PM-CMP-0010 Models form a three-level hierarchy related by import SRC-PATENT MUST draft
PM-CMP-0020 An imported model is not modified by importing it SRC-PATENT MUST NOT draft
PM-CMP-0030 Composition is recursive and uses one mechanism SRC-PATENT MUST draft
PM-CMP-0040 A model release is the unit of composition DESIGN MUST draft

SPO Subject-Predicate-Object protocol

IDTitleTrustLevelStatus
PM-SPO-0010 A SPOP message carries a subject, a predicate and an object SRC-PATENT MUST draft
PM-SPO-0020 Agents communicate with the ESTCA engine over SPOP SRC-BLOG MUST draft

DET Determinism

IDTitleTrustLevelStatus
PM-DET-0010 The determinism claim, stated OPEN SHOULD draft
PM-DET-0020 What a determinism contract has to exclude DESIGN MUST draft