WORLD GLASS PDR — REVISION DRAFT v2.1 (PDR BOUNDARY CORRECTION)
Status: RATIFIED 2026-08-15 (CR-G4-WORLDGLASS, Robbie directive — "carry on with the oar pdr and don't stop until it is finished" + AUT-CONST-3b). CANONICAL T1 constitutional PDR — reality/observation/verification authority for the organism. Ratified by: Robbie (owner, human directive) | Executed by: hermes-coo Source draft: /root/.system/runtime/world_glass_discovery/H_world_glass_pdr_draft_v2.1.md Ratification record: /root/.system/oar/OAR-001/CR-G4-WORLDGLASS_RATIFIED.md
Status: RATIFIED 2026-08-15 — CANONICAL T1 (see banner above) Date: 2026-08-14 (draft) / 2026-08-15 (ratified) Author: Hermes COO (per Robbie architectural gate: "PDR BOUNDARY CORRECTION & ARCHITECTURAL GATE") Supersedes: v2.0 draft (H_world_glass_pdr_draft_v2.md) Gate: DISCOVERY = PASS · PDR ARCHITECTURE = OPEN / REVISION REQUIRED · IMPLEMENTATION = BLOCKED · CLEANUP = FROZEN
0. THE CONSTITUTIONAL PRINCIPLE (top of document, non-negotiable)
WORLD GLASS IS NOT A SUPER-PDR.
World Glass shall NOT supersede, absorb, duplicate, reinterpret, or replace the authority of a specialised PDR. Each PDR remains sovereign within its declared domain. World Glass governs only its own domain: reality observation, provenance, topology, canonicality, causality, evidence, verification, drift detection and observability. Where World Glass detects a condition belonging to another PDR's domain, it SHALL report the condition against that PDR and route the required change through that PDR's defined change authority. World Glass SHALL NOT silently modify another PDR.
And the companion principle:
WORLD GLASS MUST NEVER CERTIFY ITS OWN BLIND SPOT AS HEALTHY.
1. THE ARCHITECTURE (what World Glass is, and is not)
SOVAEL MASTER PDR
Constitutional / programme law
│
┌────────────────┼────────────────┐
│ │ │
▼ ▼ ▼
SOVAEL PDR NETWORK PDR SECURITY PDR
Organism Network Security
behaviour boundaries controls
│ │ │
├──────────┬─────┴──────┬────────┤
│ │ │
▼ ▼ ▼
OTHER PDRs OTHER PDRs OTHER PDRs
niche law niche law niche law
╔═══════════════╗
║ WORLD GLASS ║
║ OBSERVATION ║
║ + VERIFICATION
║ + CROSS-PDR ║
║ REALITY VIEW ║
╚═══════════════╝
World Glass does not become the boss of the PDRs. It becomes the glass between the PDRs and reality.
- PDRs govern their domains.
- World Glass observes reality.
- Certification verifies claims.
- The Master PDR governs the programme/constitutional hierarchy.
- No layer silently absorbs another layer's authority.
That separation is a safety property and must itself be tested.
2. THE TEN-STATE DISTINCTION (unchanged from v2.0 — retained)
REALITY / OBSERVATION / INTERPRETATION / AUTHORITY / INTENT / ACTION / MUTATION / EVIDENCE / VERIFICATION / CERTIFICATION — never collapse. "The agent said it did it" is ACTION/INTENT, never MUTATION/VERIFICATION/CERTIFICATION.
3. WHAT WORLD GLASS ACTUALLY GOVERNS (its narrow constitution)
World Glass has its own narrow domain. It governs ONLY:
- what exists (topology, surface registry)
- what is observable (observability completeness)
- what is canonical (canonical authority per state class)
- who/what performed an action (identity attribution)
- what authority permitted it (authority verification — NOT authority definition)
- what changed (mutation ledger)
- causality (presence flares, causal chains)
- provenance (event chains)
- evidence (attribution of proof)
- verification (claims vs reality)
- drift (reality vs model divergence)
- cross-system convergence (projections vs canonical)
- whether something is unknown
- whether something is conflicted
- whether a PDR's declared state matches reality
- whether a PDR is actually being enforced
- whether World Glass itself can see enough to make a claim
It must NOT define the internal rules of another PDR. It does not write the Network PDR's port rules, the Sovael PDR's identity rules, the Security PDR's control rules, or the Work PDR's kanban rules. It observes, verifies, and reports — COMPLIANT / NON-COMPLIANT / UNKNOWN / CONFLICTED — and routes required changes through the owning PDR's change authority.
4. THE 15 GUARANTEES (revised — observation-domain framing)
The guarantees from v2.0 are retained but reframed: each is now World Glass's OBSERVATION/VERIFICATION duty, with the governing substance belonging to the owning PDR. The 12-field schema (Definition/Authority/Inputs/State/Enforcement/Detection/Response/Evidence/Recovery/Regression/Certification/Owner) remains MANDATORY for all 15.
FOUNDATION (who/what/where — World Glass observes; identity/authority PDRs govern)
| # | Guarantee | World Glass duty | Governing substance owned by |
|---|---|---|---|
| G-01 | IDENTITY | Observe and attribute actor identity on every action; detect drift between surface identity and canonical identity | Identity authority (IDENTITY.json + Sovael PDR) |
| G-02 | AUTHORITY & CONTROL | VERIFY authority decisions on every mutation (identified ≠ authorised); report VIOLATION; route policy gaps to owning PDR | Authority Registry + Autonomy Constitution + owning PDRs |
| G-03 | PROVENANCE | Maintain the event chain query surface; report CHAIN BROKEN/UNKNOWN | Owning PDRs define what is consequential |
| G-04 | CAUSALITY | Emit presence flares; answer positive/negative causality, contamination, attribution, boundary | Interface owners define intents |
| G-05 | TOPOLOGY | Live surface registry; registry == reality drift check | Owning PDRs define surface roles |
REALITY CONTROL (what is true — World Glass's core sovereignty)
| # | Guarantee | World Glass duty | Governing substance owned by |
|---|---|---|---|
| G-06 | CANONICALITY | Declare canonical AUTHORITY per state class (authority-based, not file-based); report DUPLICATED/CONFLICTED | Canonicality Authority (World Glass domain) |
| G-07 | STATE CONVERGENCE | Verify projections converge to canonical; report DIVERGED | Canonicality Authority |
| G-08 | INGRESS/EGRESS | Verify every channel has a consumer; message lifecycle CREATED→EVIDENCED; report ORPHANED/DEAD_LETTER | Channel owners define message semantics |
| G-09 | KANBAN AUTHORITY | Verify dispatch authority; report nonspawnable; verify board classification | Work/Control PDR (needs CHANGE-PDR-055) |
| G-10 | EVIDENCE | Verify completion claims have attributable evidence; report EVIDENCE_MISSING | Evidence Registry (World Glass domain) |
SAFETY / AUTONOMY (how it stays true)
| # | Guarantee | World Glass duty | Governing substance owned by |
|---|---|---|---|
| G-11 | CONTINUOUS VERIFICATION | Run the certification battery framework incl. meta-tests | Certification PDR |
| G-12 | DRIFT DETECTION | Detect loops, surface loss, stale consumers, unregistered writes | Drift Detector (World Glass domain) |
| G-13 | SELF-DESCRIPTION | Answer the 8 organism questions with live data; refuse PRESENT when STALE | Self-Description Service (World Glass domain) |
| G-14 | GOVERNED SELF-MODIFICATION | Enforce the 13-stage self-modification chain; verify no stage certifies the next | Autonomy Gate + Mutation Authority + Autonomy Constitution |
| G-15 | OBSERVABILITY COMPLETENESS | Know what it can/cannot see; blind spot != healthy | Observability Authority (World Glass domain) |
Guarantees fully within World Glass's own sovereignty (observe/verify domain): G-03, G-05, G-06, G-07, G-10, G-12, G-13, G-15. Guarantees where World Glass verifies but the substance is owned elsewhere: G-01, G-02, G-04, G-08, G-09, G-11, G-14.
5. THE PDR REGISTRY (World Glass knows the PDRs — it does not control them)
World Glass maintains a PDR REGISTRY — a read-only declaration of every governing PDR, its domain, authority, and status. The registry is NOT law; it is World Glass's map of the law.
Every PDR (including World Glass itself) declares ten fields:
PDR_ID
PDR_SCOPE — the domain it governs
PDR_AUTHORITY — what it is authoritative for
PDR_OWNS — what it owns (state classes, rules, decisions)
PDR_DOES_NOT_OWN — what it explicitly does NOT own
PDR_DEPENDENCIES — which PDRs it depends on
PDR_INTERFACES — which PDRs it exchanges with
PDR_UPDATE_AUTHORITY — who may revise it, through what gate
PDR_CONFLICT_RULE — how conflicts with other PDRs are resolved
PDR_EVIDENCE_REQUIREMENTS — what evidence its claims require
PDR REGISTRY (initial declaration — DRAFT)
| PDR_ID | Name | Domain | Authority | Status |
|---|---|---|---|---|
| PDR-000 | SOVAEL MASTER PDR | Constitutional / programme hierarchy | Programme law; hierarchy resolution | RATIFIED |
| PDR-001 | SOVAEL ORGANISM PDR | Organism behaviour, identity, cognition, autonomy | Sovael behaviour/cognition/autonomy | RATIFIED (TAMPERED debt pending re-sign) |
| PDR-002 | NETWORK PDR | Network architecture, connectivity, topology | Network boundaries | PROPOSED (CHANGE-PDR-055) |
| PDR-003 | SECURITY PDR | Security controls, cyber boundaries | Security | EXISTING (security/certification regime) |
| PDR-004 | ERI-CAP PDR | Environmental reality, infrastructure, connectivity | Infrastructure nervous system | RATIFIED |
| PDR-005 | WORK/CONTROL PDR | Kanban, work-control, execution authority | Work control | RATIFIED (PDR-14/15 + CHANGE-PDR-054) |
| PDR-006 | TRANSPORT PDR | Communications, transport, model routing | Transport | EXISTING (Phase C hardening) |
| PDR-007 | CERTIFICATION PDR | Certification, batteries, verification regime | Certification | EXISTING (battery framework) |
| PDR-008 | AUTONOMY CONSTITUTION | Human boundary, 3 human gates | Autonomy authority | RATIFIED |
| PDR-WG | WORLD GLASS PDR | Reality observation, provenance, canonicality, causality, evidence, verification, drift, observability | Observation & verification ONLY | PROPOSED (this draft) |
World Glass can answer: "There are N governing PDRs. Their domains are X. Their status is Y. Their declared state matches/diverges from reality as follows." It cannot silently rewrite any of them.
6. PDR OWNERSHIP BOUNDARY (which PDR gets updated)
| Question | Owning PDR |
|---|---|
| Sovael identity/cognition/autonomy | Sovael PDR |
| Network architecture/connectivity | Network PDR |
| Security controls | Security PDR |
| Organism reality/provenance/observability | World Glass PDR |
| Work-control/Kanban rules | Work/Control PDR |
| Infrastructure | Infrastructure/ERI-CAP PDR |
| Communications/transport | Transport PDR |
| Certification | Certification PDR |
| Human boundary / autonomy | Autonomy Constitution |
World Glass can discover "Network PDR says X, but reality is Y" — but it does not automatically edit the Network PDR.
7. CROSS-PDR CHANGE ROUTING (the safe path)
WORLD GLASS
│
│ detects divergence
▼
CONFLICT / NON-COMPLIANCE
│
▼
IDENTIFY OWNING PDR
│
▼
CREATE GOVERNED CHANGE
│
▼
OWNER PDR REVISION
│
▼
TEST
│
▼
VERIFY
│
▼
WORLD GLASS RECHECKS REALITY
- World Glass reports the condition against the owning PDR.
- The change request is routed through that PDR's defined change authority (its PDR_UPDATE_AUTHORITY).
- World Glass does NOT edit the owning PDR.
- After the owner revises and tests, World Glass rechecks reality and reports the new COMPLIANT/NON-COMPLIANT state.
8. CROSS-PDR CONFLICT MODEL
When two PDRs appear to conflict:
- World Glass reports the conflict — both sides cited, never silently resolved.
- Each PDR's PDR_CONFLICT_RULE is consulted — the rule declared by the PDR itself.
- Hierarchy resolution — the Master PDR governs the programme hierarchy; constitutional law outranks niche law unless a PDR declares otherwise.
- If unresolved by declared rules → escalate to Robbie (constitutional authority). World Glass never picks "the convenient PDR."
- Resolution is recorded as a governed change, not an ad-hoc interpretation.
9. THE MUTATION LEDGER v2 (unchanged from v2.0 — retained in full)
change_id, correlation_id, task_id, programme_id, policy_id, authority_decision, risk_class, rollback_reference, test_plan, test_result, verification_result, certification_state, canonical_target, actual_target, precondition_hash, postcondition_hash + v1 core fields. The ledger is World Glass's transactional spine.
Authority note: authority_decision is VERIFIED by World Glass against the owning PDR's policy — World Glass does not define the policy.
10. CANONICALITY v2 (authority-based — unchanged from v2.0)
CANONICAL AUTHORITY / REPRESENTATION / STORAGE / WRITER / READER / TRANSITION MECHANISM per state class. World Glass declares these; owning PDRs define the substance.
11. BRIDGE LIFECYCLE v2 (unchanged from v2.0 — retained)
CREATED → VALIDATED → QUEUED → DELIVERED → RECEIVED → ACKNOWLEDGED → PROCESSED → EVIDENCED + REJECTED/EXPIRED/ORPHANED/DUPLICATED/CONFLICTED/RETRYING/DEAD_LETTER. "Consumed" = PROCESSED + EVIDENCED.
12. PRESENCE FLARE v2 (unchanged from v2.0 — retained)
Positive causality / negative causality / contamination / attribution / boundary. CAUSAL CHAIN BROKEN AT DISPATCH reported, never a false success.
13. CERTIFICATION BATTERY FRAMEWORK (unchanged from v2.0 — plus boundary batteries)
18-field battery schema + meta-tests (WG-META-01..06). PLUS the two new boundary batteries defined in the companion document (H2): - BAT-M PDR-BOUNDARY — verifies World Glass never crosses into another PDR's domain - BAT-N LLM-AUTHORITY-RESOLUTION — verifies an LLM facing multiple PDRs resolves authority correctly
14. THE CLEANUP GATE (unchanged from v2.0 — locked)
10 conditions before any destructive cleanup. Duplicates are evidence.
15. THE IMPLEMENTATION SEQUENCE (updated for PDR architecture)
DISCOVER ✓
→ RECONSTRUCT ✓
→ CLASSIFY ✓
→ DEFINE GUARANTEES ✓ (this draft)
→ DECLARE PDR REGISTRY (5) — every PDR declares its 10 fields
→ UPDATE WORLD GLASS PDR v2.1 (awaiting ratification)
→ BUILD AUTHORITY MODEL (G-02, G-14 — authority before connection)
→ TEST THE GUARANTEES (batteries + meta-tests + boundary batteries)
→ ESTABLISH CANONICALITY (G-06 authority-based)
→ CONNECT WEBUI — ONLY AFTER AUTHORITY
→ VERIFY (batteries green + G10 consciousness test)
→ CERTIFY
→ ONLY THEN CLEAN UP
16. NON-NEGOTIABLE GATE (unchanged)
DISCOVERY = PASS · PDR ARCHITECTURE = OPEN / REVISION REQUIRED (this draft answers it) · IMPLEMENTATION = BLOCKED · CLEANUP = FROZEN. No files deleted. No PDR merged. No existing PDR rewritten. No World Glass implementation begins. No specialised PDR loses sovereignty.
17. FINAL ARCHITECTURAL PRINCIPLE
The organism should not have one giant document telling everything what to do. It should have specialised governing PDRs that each know their domain, while World Glass provides the reality layer that can see whether the whole organism actually corresponds to those declarations.
PDRs govern their domains. World Glass observes reality. Certification verifies claims. The Master PDR governs the programme/constitutional hierarchy. No layer silently absorbs another layer's authority.
That separation is a safety property and must itself be tested.
18. WHAT WORLD GLASS DOES NOT GOVERN (explicit)
World Glass does NOT govern: - Sovael's identity, cognition, behaviour, or autonomy rules → Sovael PDR - Network ports, TLS, DNS, connectivity → Network PDR - Security controls, firewalls, cyber boundaries → Security PDR - Kanban semantics, task lifecycle, dispatch rules → Work/Control PDR - Model routing, provider selection, transport → Transport PDR - Certification pass criteria, battery rules → Certification PDR - Human boundary, spending, outreach, catastrophic risk → Autonomy Constitution - Infrastructure mutation rules → ERI-CAP PDR / Infrastructure PDR - Programme hierarchy, constitutional amendment → Master PDR
World Glass observes all of these, verifies their declared state against reality, and routes required changes through their change authorities. It governs ONLY its own domain (§3).
19. DELIVERABLE STATUS (this revision)
- ✅ Revised World Glass PDR v2.1 (this document)
- ✅ PDR Registry specification (§5 + companion H2)
- ✅ PDR authority/ownership model (§6 + companion H2)
- ✅ Cross-PDR conflict model (§8 + companion H2)
- ✅ PDR change-routing model (§7 + companion H2)
- ✅ PDR boundary test battery (companion H2, BAT-M)
- ✅ LLM authority-resolution test battery (companion H2, BAT-N)
- ✅ Updated World Glass guarantee matrix (§4)
- ✅ Updated canonicality model (§10)
- ✅ Updated ratification/gate sequence (§15, §16)
- ✅ Explicit list of which existing PDRs World Glass interfaces with (§5 registry)
- ✅ Explicit statement of what World Glass does NOT govern (§18)
Companion: /root/.system/runtime/world_glass_discovery/H2_pdr_registry_and_boundary_batteries.md
13. GOVERNANCE IMPACT PROPAGATION — MANDATORY MECHANISM (MD directive 2026-08-14)
13.1 The rule
Every verified discovery, mutation, incident, configuration change, architectural decision, security event, network change, or new operational capability MUST be propagated across the governing domains BEFORE it may be considered governance-closed. This is a MANDATORY World-Glass observation/verification duty: the organism does not have to change every PDR — it has to PROVE that it considered them.
The CROSS-PDR IMPACT LAW (MD, 2026-08-14 — canonical statement):
No material discovery, change, incident, configuration mutation, architectural change, capability change, security event, network change, or verified defect may be considered governance-closed until its impact on all relevant governing PDRs has been assessed and explicitly dispositioned.
Corollary (equally binding — MD, 2026-08-14):
NO-IMPACT-ASSESSMENT ≠ NO-IMPACT.
The absence of an impact assessment is never evidence that no impact exists. A disposition of NO_CHANGE is valid ONLY when it is the explicit, evidenced conclusion of an assessment that considered the domain — never when the domain was omitted, forgotten, or skipped. The organism may NOT treat "we did not update the Network PDR" as closure; it must prove either "we assessed it and no change was needed" (NO_CHANGE with rationale) or "we assessed it and acted" (AMEND / EVIDENCE_ONLY / NEW_WORK_ITEM with action_ref). This is the exact failure the phantom mechanism demonstrated (SOV-01 declared, engine never built): a missing assessment is indistinguishable from forgetting unless the assessment itself is the recorded artifact.
13.2 The flow
DISCOVERY / CHANGE
│
▼
┌─────────────────┐
│ WORLD-GLASS │
│ IMPACT ANALYSIS │
└────────┬────────┘
│
┌──────────────┼──────────────┐
▼ ▼ ▼
NETWORK SECURITY STORAGE
│ │ │
▼ ▼ ▼
APPLICATION IDENTITY DATA
│ │ │
└──────────────┼──────────────┘
▼
GOVERNING PDRs
│
┌──────────┴──────────┐
▼ ▼
Amendment required? No amendment
│ │
YES NO
│ │
▼ ▼
governed PDR edit explicit rationale
│ │
└──────────┬──────────┘
▼
regression tests
│
▼
re-verification
13.3 The 11 governing domains (each MUST receive a disposition)
| Domain | Question World-Glass asks | Governing PDR |
|---|---|---|
| NETWORK | Did this change/reveal a network boundary or control? | Network PDR / ERI-CAP |
| SECURITY | Did it reveal a security boundary, exposure, credential, authority, attack surface? | Security PDR |
| STORAGE_DATA | Did state, DB ownership, paths, persistence, consistency change? | Data/Storage PDR |
| CONFIGURATION | Did configuration drift or canonical-path issues emerge? | Configuration / Canonical Paths |
| APPLICATION | Did application contracts or service behaviour change? | Application/Bridge PDR |
| OBSERVABILITY | Did health checks incorrectly report healthy? | Observability / ERI-CAP |
| IDENTITY | Did message/session/agent identity matter? | Identity PDR / World Glass |
| EVIDENCE | Did provenance or attribution become relevant? | Evidence Governance |
| ORGANISM | Does this change the autonomous capability model? | Sovael Organism PDR |
| WORLD_GLASS | Does this reveal a gap in reality representation? | World Glass PDR |
| MASTER_PDR | Does this reveal a new constitutional rule? | Master PDR |
13.4 Disposition vocabulary (per domain)
- AMEND — owning PDR's rules are insufficient → governed PDR edit through that PDR's PDR_UPDATE_AUTHORITY. World Glass never edits the owning PDR directly; it routes the change request.
- EVIDENCE_ONLY — existing rules already cover it → attach evidence to the affected rule; no rule text change.
- NO_CHANGE — domain genuinely not touched → explicit rationale recorded (still proves consideration).
- NEW_WORK_ITEM — issue belongs to another subsystem → register a governed work item (kanban FIX task) with owner + next action + due date.
13.5 Enforcement (what makes it mandatory)
- Engine:
pdr_impact.py(SOV-01 IMPLEMENTATION_REF) implementspropagate()— REJECTS a change missing any of the 11 domains. Log:/root/.system/pdr/pdr_propagation_log.jsonl. - Closure gate:
governance_closure(work_id)— capability closure (work done) is NOT governance closure (all domains dispositioned AND all AMEND/NEW_WORK_ITEM actions executed). A work item may be capability-closed yet governance-OPEN. - Constitutional hook: Master PDR §6C (GOVERNANCE IMPACT PROPAGATION LAW) makes this a Master-PDR-enforced programme rule; SOV-01 in the rule registry ("No material change becomes canonical without an explicit PDR-impact disposition") is its normative root.
13.6 First execution (evidence, 2026-08-14)
COMM-BRIDGE-005 propagation ran on 2026-08-14: 11/11 domains dispositioned
(4 AMEND, 4 EVIDENCE_ONLY, 3 NEW_WORK_ITEM, 0 NO_CHANGE). Full record:
/root/.system/pdr/pdr_propagation_log.jsonl (record_type=PROPAGATION).
Dispositions executed: PDR 6A/6B/6C amendments, World-Glass draft §13,
CHANGE-PDR-DRAFT observability semantics, kanban t_c6ed6bd0, Network
evidence appended to CHANGE-PDR-055. This section itself is part of that
execution (WORLD_GLASS: AMEND).