What I Inverted
If this holds, an agent can be granted authority over government and enterprise data — because it can prove a record is absent rather than merely not found, and the refusal reaches the actuator.
A successor to Codd (1970)
Codd’s relational model is four things, and a successor has to answer all four: one uniform data structure, a closed algebra with equivalence laws, a decomposition theory, and data independence. Its primitive — the tuple — was deliberately provenance-free. In 1970 that was correct; it bought data independence for a single trusted data bank. Where knowledge is derived by machines across parties that do not trust each other, a provenance-free fact is the liability.
The served state is a signed fold over an ordered provenance log, and a fact is a rate over that lineage — the novel signal it introduces over the distinct sources that produced it.
The state cannot change without a signed log event. Every layer is doubly signed and verifies offline, with the derivative bound to the live state. Codd assumed a trusted engine around the data; this assumes none. Relationships are discovered by the values two columns share — inclusion dependencies — not by column name.
Three theorems close the gaps on Codd’s own ground. Declarative access: a submodule is reached by a predicate over its fields with its anchor returned as output, path independent and invariant under order. A closed algebra: join, union, project and select closed over the relation, with proven laws — the central one being that variance composition is the provenance set-union law. Lossless reform: restructuring routes every unmatched record to a residual, making reform a total partition.
A successor to Setun (1958)
Sobolev and Brusentsov built Setun at Moscow State University; fifty were made between 1959 and 1965. Its primitive, the trit, was arithmetic — a digit whose third state was the number zero. Binary won, and it won fairly: the extra state bought density, and density got cheap. Where decisions are derived by machines over evidence that is routinely insufficient, the third state has a job two values cannot do at all. It carries the refusal to decide.
τ adapts per attribute, so criticality widens the refusal. The neutral absorbs from above: no quantity of conforming evidence raises a marginal unit to release. Two-valued logic has no such element, so a marginal fact is forced to a side — silently passed or falsely failed. The gate is algebraic, not a policy a later layer can decline.
Five theorems, each with a passing test or a signed artifact. The neutral is non-erasable. The empty conjunction is not vacuously true — Boolean AND over an empty rule set returns true, so every binary compliance system silently passes any case no rule covers; here the empty aggregate is 0 and routes to a human. Composition is measured, not assumed. The verdict reaches the actuator, or nothing does — a directive batch actuates only if the signed chain verifies and the batch rehashes to what was signed; tamper with one byte and the whole batch is refused, never partially applied. Absence is provable, not asserted.
The five absence classes
| Class | Primitive | Condition | Remedy |
|---|---|---|---|
| Structural | absences() blind pair | No value relates two domains | Acquire a ledger |
| Referential | partitionValues().residual | A key with no resolving parent | Reconciliation |
| Contradictory | Kleene composition → 0 | Two present values, both cannot hold | Adjudication |
| Observational | ABSENT sentinel | Field present, value void | Not fixable |
| Categorical | Path to a set, not an instance | Relates to a cohort, not a record | Often not fixable |
Categorical is the most dangerous, because it is the only class that looks like an answer. The first three recede under investment; the last two do not. Residual never reaches zero across parties who legally cannot share schemas, and the signed proof of that irreducible floor is the artifact only this substrate produces.
What It Shows
554 tests passing, zero regressions on the relational successor; the three theorems contribute 20 of them. Against Codd’s requirements: one uniform structure holds; set semantics by design, the state being an ordered signed fold, proven commutative when no gate binds; data independence, closed algebra and lossless decomposition all earned; integrity and provenance exceed.
50 tests green on the ternary successor — 21 in the browser port, 22 in the reference, two independent implementations of one algebra and therefore the check on it, plus 7 over the absence certificate. The energy result is pinned by a zero-dependency golden test: 21,528 float energy units against 3,078 ternary, a factor of 6.99, still recovering structure at ARI 0.6 or better.
Composition is a signed lookup, not a designed truth table. The law is ed25519-signed at τ = 0.2 over 10 corpora and 113 modules, and its nine cell counts sum to exactly 1,404,816 triads. Two cells are states no two-valued table can hold: conformance to a contested standard composes to 0 at 0.4215 — indeterminate rather than passed — and failure against a standard the regulation supersedes composes to +1 at 0.7925, compliant rather than failed.
For an absent key the estate returns a sorted Merkle non-membership proof: the two adjacent present neighbours that strictly bracket the query, their inclusion proofs, the committed root and the set size, bound under one signature against a pinned key. A third party re-derives it offline. Adjacency and strict inequality mean a present key cannot be dressed as absent, and a routing miss is typed apart from a grounded abstention, so the gate never certifies a false absence.
Five acts. Estate — the signed governed corpus, sealed partitions present, counted, withheld. Architect — relations discovered by value overlap, with evidence and provenance union printed and refused pairs shown with reasons. Corpora — heterogeneous ingest of images, technical documents, telemetry and tabular data under one commitment. Operate — the MCP agent layer. Coverage — the estate publishes its own blind spots, contradictions and bounds.
Eleven governed MCP tools: overview, connect, relations, coverage, aggregate, rollup, watch, indications, ask, records, verify. The substrate mints inside the perimeter and verifies with the network off: zero egress, no execution surface, no write path, no code generation. The console UI is generated from the estate rather than hand-built per domain, so the marginal cost of an additional estate is near zero.
Five deployed estates: an oil refinery, an offshore field, a diversified industrial group with an export-controlled division provably sealed while the rest stays fully queryable, an aerospace programme on public data, and an energy/maritime trade corridor. Each seals into a single portable file that verifies with no connection.
Governance lineage. The same discipline first ran as a participatory data estate — SGUNCCH, live UNC student-government infrastructure, 40 policies across 8 departments, with relevance-gated retrieval and a publicly readable approval ledger.
What It Doesn't Show
No external user has run it. Five estates, all built by me. Pre-revenue, no legal entity, no team. That is the binding constraint, and no additional building moves it.
About 40% of full-precision accuracy on hard continuous data. The win is energy, not capability.
The composition law is measured over 10 corpora and 113 modules. The 1,404,816 triads are sampling depth, not breadth of domain.
Not a replacement where the relational model is optimal, which is ground-truth facts in a trusted store. Nor a replacement for binary where binary is optimal, which is computation over known values. Both claims are narrow on purpose.
Absence is proven relative to the commitment — the releasable corpus — not absolutely.
Needs conferring rather than building: security accreditation, IdP integration, and the authority to be the system of record.
Sources
- latentocean.com/spacex — the live estate. Under a severed network it refuses and names the reason instead of answering from cache.
- latentocean.com — the substrate, the five acts, the deployed estates.
- A Successor to Codd (PDF) — the four requirements, the verdict table, the three theorems, 554 tests. Marks the departure from Green, Karvounarakis & Tannen, Provenance Semirings, PODS 2007: there provenance annotates Codd’s relations, here the composing quotient is the primitive.
- A Successor to Setun (PDF) — the open zero band, the five theorems, the measured composition law, the energy result. Łukasiewicz 1920 and Kleene 1938 are the algebra; SQL’s NULL its most deployed instance.
- github.com/direncode/sguncch — the governance lineage: approval ledger, RLS policies, relevance-gated retrieval.