Generative Relational Public Knowledge Infrastructure - Social Facts, Knowledge Evolution, and Institutional Justice
Transcript
Abstract
Public knowledge infrastructures shape the conditions under which accounts become intelligible, credible, contestable, and reusable. Their design therefore concerns the organization of social and institutional relations as well as the preservation of artifacts. This paper develops a generative relational account of public knowledge infrastructure in which the trajectories of claims, evidence, interpretation, contribution, and institutional decision remain addressable for continued inquiry. The argument distinguishes historical occurrence, recorded description, attributed assertion, evidentiary warrant, and institutional consequence. It connects these distinctions to epistemic, procedural, distributive, and recognition-based concerns, and examines legal constraints on personal information, retention, attribution, and reuse. The method combines conceptual reconstruction, an interdisciplinary literature review, normative argument, scoped legal analysis, and constructive architectural modeling. The resulting proposal organizes representation and processing around domain-extensible records, temporal histories, controlled disclosure, contestation, and governed transitions across autonomous custodians. It also specifies institutions for authority, representation, review, maintenance, and succession. AI mediation provides a consequential setting in which source selection, synthesis, adoption, and recursive reuse can alter the public status of a claim. Analytical cases examine conflicts among preservation, participation, privacy, attribution, and institutional action. The contribution is an integrated account of the public purposes and design conditions of knowledge infrastructure, with explicit limits on historical reconstruction and technical guarantees. A bounded formal-language package supports representational precision; institutional legitimacy and empirical usefulness require further participatory and comparative evaluation.
Keywords: knowledge infrastructure; social facts; knowledge commons; epistemic justice; institutional governance; information law; provenance; public participation; AI-mediated knowledge.
Discussion Paper Note
This manuscript is a discussion paper circulated to support interdisciplinary inquiry into public knowledge. Its definitions, arguments, formal representations, and practical proposals remain open to revision. The paper provides a basis for scholarly exchange and further research; its circulation does not establish an adopted technical standard or an authoritative institutional position.
The author welcomes objections, discussion, corrections, alternative interpretations, counterexamples, and suggestions for further development. Contributions from different disciplines and from people whose knowledge or interests could be affected by the proposed infrastructure are especially valuable. Readers are invited to identify conceptual ambiguities, formal errors, omitted literature, relevant practices, and disagreements with the normative or institutional assumptions. Comments may be sent to huangwanhong@serendip.ngo. Identifying the paper, version, and relevant passage will assist review.
The author makes no claim to conceptual priority or first origination of the concepts discussed in this paper. Similar or equivalent concepts may already exist in other disciplines, intellectual traditions, languages, or bodies of practice, including under different terminology. The literature review is selective and remains open to correction and expansion. References to earlier, parallel, or independently developed work are welcome. The proposed vocabulary, connections, and applications should be assessed through their arguments and evidence. Attribution of this manuscript identifies its authorship and source; it does not establish priority for its underlying concepts.
Responsible Use and Rights Reservation
This section records a request for responsible scholarly conduct and clarifies the scope of the author’s rights reservation. The author encourages good-faith criticism, independent inquiry, and responsible application, and asks users to consider foreseeable harms when adapting or applying the proposals. These ethical requests add no conditions to the licence stated in the Notices and leave its permissions and otherwise lawful uses unchanged.
Any reservation is limited to rights the author actually retains under the licence and applicable law, consistently with the licence’s grants, waivers, and nonassertion provisions. The author asserts no exclusive control over the underlying concepts through this notice. Attribution and reuse do not imply authorial endorsement of subsequent interpretations, applications, or institutional positions. Applicable copyright exceptions and limitations remain available, and third-party material retains its applicable conditions.
Notices
These notices identify the manuscript’s discussion status, conditions of reuse, research context, and preparation process. They accompany the invitation to criticism and the statement on conceptual priority in the Discussion Paper Note.
Publication status and revision.
This is a developing discussion paper. Its arguments, terminology, formal statements, organization, and numbering may change. Objections, discussion, corrections, and references to antecedent work are welcome. When citing or commenting on the paper, readers are asked to include its title, author, and any available version information so that later revisions can be distinguished.
Licence.
Except where otherwise indicated, copyright 2026 Wanhong Huang. This manuscript is available under the Creative Commons Attribution-NonCommercial 4.0 International licence (CC BY-NC 4.0), subject to its official legal code. That legal code governs the permissions, conditions, disclaimers, and limitations of the licence. The responsible-use requests and rights reservation in this paper do not amend those terms. Third-party material remains subject to its applicable conditions.
Research scope and evidence.
Constructed cases in this paper are analytical examples. The accompanying source audits record online verification and the limits of access. Formal results and bounded artifact checks are identified within their stated assumptions and scope. The project has no field deployment; institutional proposals remain proposals for discussion and evaluation.
AI assistance and author responsibility.
The preparation of this manuscript involved OpenAI’s ChatGPT. AI assistance supported exploratory dialogue, source discovery and verification, argument criticism, conceptual and formal reconstruction, and manuscript preparation in LaTeX. The author retains responsibility for review and the final manuscript, including its arguments, representations, conclusions, and errors.
Introduction
Public knowledge depends on institutions that determine which accounts can be preserved, encountered, credited, challenged, and revised. A published article, dataset, historical finding, or public explanation is one point in a longer trajectory of observation, interpretation, contribution, disagreement, and institutional action. Decisions within that trajectory can matter as much as the final proposition: an excluded observation can alter the apparent strength of a finding; an omitted contributor can disappear from its recognized history; and a correction can remain ineffective when downstream systems continue to circulate an earlier account. The infrastructure problem concerns the organization of those relations and the conditions under which the resulting record can serve continued public inquiry.
This paper develops an interdisciplinary proposal for a generative relational public knowledge infrastructure. Its central argument is that the preservation of knowledge evolution requires an integrated account of representation, epistemic participation, legal protection, and institutional authority. The architecture of a record helps distribute practical capacities: to make a claim intelligible, to offer evidence, to obtain recognition, to challenge a classification, and to secure an effective correction. Justice and law therefore enter the specification of the infrastructure’s objects and procedures. They also constrain the collection, processing, and dissemination through which a technically available record becomes public knowledge.
Knowledge Evolution and Public Consequences
Consider a community environmental investigation combining residents’ observations, laboratory measurements, and an institution’s analysis. A public report attributes an observed pattern to one explanation. Later review finds that a classification excluded observations recorded in another language and that a temporal aggregation concealed a relevant local variation. An AI-assisted summary circulates the report’s earlier conclusion without the subsequent qualification. Some contributors seek recognition and correction; others seek protection against the disclosure of locations and identities. The institution retains responsibility for its report while a separate community body contests its authority to release certain contextual material.
The example presents several problems at once. The historical question concerns what was observed and recorded. The epistemic question concerns what those observations warrant. The distributive question concerns whose contribution becomes visible and who bears the work of correction. The procedural question concerns access to a competent reviewer. The legal question concerns applicable authority, personal information, protected expression, and remedies. A public record that preserves the final report while collapsing these distinctions can be technically intact yet inadequate for the inquiry that its consequences require.
The case is synthetic and does not establish how frequently existing infrastructures fail. It identifies an analytical object: the trajectory through which heterogeneous contributions acquire an increasingly stable public representation and practical effects. The infrastructure proposed here preserves selected dependencies within such trajectories and supplies procedures for their interpretation, contestation, and revision. The selection is governed and revisable, because preserving everything would itself change the conditions of participation and expose information without sufficient justification.
Generative, Relational, and Public Commitments
The term generative directs attention to how knowledge arises and to the conditions of further inquiry. An infrastructure should make it possible to revisit an assumption, recover a neglected contribution, formulate a different interpretation, or build a synthesis whose premises remain addressable. Generation does not imply progress: the same infrastructure can amplify error, extract labor, or stabilize an unjust classification. Its generative capacity therefore requires evaluation in relation to its epistemic and public purposes.
The term relational directs attention to the people, institutions, instruments, concepts, environments, and normative orders through which knowledge acquires meaning and practical significance. A contribution can have a historical relation to an idea, an evidentiary relation to a claim, a recognition relation within an institution, and a legal relation concerning permitted reuse. These relations may be governed differently. A change in recognition need not alter the prior occurrence, and a permission to reuse protected expression need not settle attribution or historical priority.
The term public concerns the justification and organization of access, participation, scrutiny, and institutional accountability. Open scientific knowledge is one important component. UNESCO’s Recommendation on Open Science also addresses infrastructures, engagement with society, and dialogue with other knowledge systems, situating openness within a broader institutional project (UNESCO 2021). The proposed infrastructure extends that orientation to heterogeneous public knowledge practices. Public function can include protected custody and limited disclosure when these are justified and subject to suitable oversight. The release of every source is neither a prerequisite for that function nor a sufficient measure of its success.
Research Questions and Central Thesis
The inquiry addresses four connected research questions. First, which relations and conditions of knowledge formation require representation to support meaningful interpretation, responsibility, and future revision? Second, how should justice, rights, and institutional authority shape the selection and processing of those representations? Third, which architecture can preserve their temporal and contextual distinctions across autonomous custodians? Fourth, under what conditions can the architecture’s public value and practical limits be assessed?
The thesis has three parts. Knowledge preservation should retain the distinctions among occurrence, recorded description, attributed assertion, evidentiary assessment, and institutional consequence. The capacities to contribute, interpret, contest, and obtain remedies should be designed into the infrastructure’s governance, with attention to unequal resources and exposure. Technical operations should make those distinctions and procedures effective through accountable admission, versioned interpretation, controlled disclosure, and explicit revision. These are mutually dependent commitments. A correct record format without usable review can preserve an exclusion; a legitimate decision without effective propagation can leave public representations unchanged.
This thesis does not turn an infrastructure into a universal authority over truth. Institutions still need to make findings and coordinate action under uncertainty. The proposal makes the basis and scope of such decisions addressable while preserving appropriate opportunities for challenge and further inquiry. Its preferred relation between stability and revision is therefore procedural and temporal: an institution can act on a declared finding without treating that finding as permanently immune to criticism.
Contributions, Method, and Paper Organization
The paper makes four proposed contributions. It develops an account of knowledge trajectories that connects the genesis of claims to public representation and institutional consequences. It derives preservation and processing requirements from epistemic, procedural, distributive, and legal considerations. It specifies a reference architecture in which attributed assertions, temporal histories, domain autonomy, and governed transitions support those requirements. It supplies analytical cases and an evaluation framework that examine public participation and institutional capacity alongside technical behavior.
The method combines conceptual reconstruction, a verified interdisciplinary literature review, normative argument, bounded legal analysis, and constructive architectural modeling. The cases test tensions and failure conditions; they are not field observations. A small formal-language package provides implementation-facing precision and bounded consistency checks. Those checks establish neither institutional legitimacy nor empirical effectiveness. Section 3 states the method and evidentiary limits in more detail.
The inquiry treats social, normative, and legal analysis as constitutive of infrastructure design. Its architectural claims therefore depend on the account of public responsibility developed here, together with the explicit assumptions and limits of the formal model. Detailed language metatheory and jurisdiction-specific adjudication remain beyond the paper’s scope.
The argument begins with knowledge infrastructure and social facts in Section 2, examines method and AI mediation in Sections 3 and 4, and develops justice and legal constraints in Section 5. The subsequent sections derive preservation requirements and architectural operations. Institutional governance is developed in Section 13; the cases, assessment, and discussion in Sections 14–16 examine the proposal’s implications and limits. The conclusion identifies the argument established at this research stage and the evidence still required.
Knowledge Infrastructure, Social Facts, and Public Institutions
The concept of public knowledge infrastructure requires an account of the social relationships that make records intelligible and consequential. This section develops that account through infrastructure studies, social ontology, social epistemology, and knowledge-commons scholarship. The argument moves from the conditions of infrastructural participation to the distinctions a public record must preserve, then examines the institutional conditions of criticism and collective stewardship. These literatures supply analytical resources for the proposal; their translation into design commitments remains an argument advanced by this paper. The central claim is that preservation shapes the distribution of opportunities to interpret, challenge, and develop knowledge. Its adequacy consequently depends on the relationship between retained information and the institutions through which people can use it.
Infrastructure, Practice, and the Installed Base
Infrastructure studies provides a starting point for identifying the object being designed. Star and Ruhleder’s study of the Worm Community System treats infrastructure as a relation to organized practice. Its characteristic embeddedness, dependence on learned conventions, and inheritance of an installed base explain how the same arrangement can support one group while presenting substantial obstacles to another. Their empirical case also shows that favorable judgments about an interface can coexist with difficulties of access and use (Star and Ruhleder 1996). An infrastructure proposal therefore requires attention to the circumstances in which a representation becomes usable: training, equipment, institutional affiliation, time, and opportunities to obtain assistance all influence participation.
For the present project, the installed base includes archives, repositories, laboratory practices, public agencies, community organizations, and professional standards. It also includes established divisions of labor. A researcher may already deposit an article, a librarian maintain its descriptive record, and a community organization preserve relevant testimony. Introducing a common history format redistributes work among these actors. Requiring each to reconstruct the others’ context would produce an exchange standard with weak institutional support. An integration layer becomes plausible when its obligations can be attached to existing work, its additional costs are funded, and participants can question the classifications they are asked to apply. Compatibility is consequently an institutional achievement involving responsibility and negotiated meaning as well as software interfaces.
Edwards and colleagues place the production, circulation, and contestation of knowledge within an infrastructure research agenda concerned with the redistribution of authority and power. Their report emphasizes the mutual adjustment of emergent practices and established knowledge institutions (Edwards et al. 2013). This perspective supports a broader unit of design than the information service considered in isolation. The relevant infrastructure includes arrangements for maintaining expertise, resolving disagreement, and making resources available over time. A repository can remain technically reachable while losing the staff capable of interpreting obsolete terminology or locating supporting evidence. Conversely, a community can preserve valuable interpretive knowledge while lacking the facilities needed to make its records discoverable beyond its immediate membership.
These observations establish two requirements for a public infrastructure. First, the design must identify the institutions and work on which each preservation promise depends. A statement that evidence will remain available requires a custodian, resources, and an intelligible succession arrangement. Second, the system must distinguish the commonality of an interface from the uniformity of practices behind it. A museum accession, a scientific correction, and an administrative finding can share mechanisms for identifying records and documenting changes while retaining different standards of evaluation. Their interoperability depends on explicit translation and qualified equivalence. Treating their local statuses as interchangeable would conceal the institutional work through which those statuses acquired meaning.
The resulting conception is relational in a precise sense: an infrastructure supports specified activities for specified participants under historical and organizational conditions. This conception gives practical content to the project’s ambition to connect existing institutions. It also constrains that ambition. A system’s ability to exchange records establishes only one condition of public usefulness. Further inquiry must examine whose activities become easier, whose labor increases, and whose ways of producing knowledge become harder to express.
Social Facts, Representations, and Institutional Recognition
The term social fact requires conceptual discipline because an infrastructure can preserve descriptions of social life while also participating in the practices that establish institutional statuses. The following distinctions organize these relationships without settling the competing metaphysical accounts of society. They separate material occurrences, evidence, representations, institutional recognition, and legal status according to their roles in an inquiry. The distinctions can apply to overlapping objects and should never be read as a universal sequence in which a fact becomes more real each time it passes an institutional gate.
A material occurrence concerns what happened: a meeting took place, a measurement was produced, or a person performed work. Evidence comprises materials and testimony used to support an interpretation of that occurrence. A representation expresses an account through selected concepts, boundaries, and descriptions. Institutional recognition concerns the acceptance or classification of an account by an organization or community under a specified practice. Legal status concerns consequences recognized within an applicable legal order. An observer’s description can be well supported while lacking institutional recognition; an institution’s recognized classification can remain substantively contested. Legal validity, institutional acceptance, and epistemic justification require their own grounds.
Searle’s analysis of institutional facts explains one reason to preserve these differences. On his account, certain social statuses depend on collective recognition and constitutive rules, while statements about those statuses can still be assessed as objectively correct or incorrect. Dependence on human practices is compatible with determinate facts about an institution (Searle 2006). A record of an appointment illustrates the architectural relevance. The recorded utterance, the appointment procedure, the resulting office, and the description of its holder are related objects. Their relationships require an account of authority and procedure; their meanings cannot be recovered from a timestamp or an authenticated signature alone.
The project’s use of social facts also extends to consequences that remain unrecognized or arise unintentionally. Lukes’s direct critique of Searle questions the restriction of social analysis to linguistically constituted institutions and calls attention to interactions between institutional arrangements and material power (Lukes 2006). This criticism matters for the proposed infrastructure because a recognition-centered model could erase precisely the experiences that public inquiry needs to examine. A person’s contribution may have occurred despite its exclusion from an official account. A community may suffer an effect before an agency recognizes the relevant category. The capacity to record and investigate such claims must remain available alongside descriptions of established institutional classifications.
Consider a hypothetical dispute over participation in an environmental study. Residents collect samples and describe changes in water quality. A laboratory produces measurements, a research team publishes an interpretation, and an agency classifies the evidence under its procedure. Several questions remain independent: which sampling activities occurred, whether the measurements support the published inference, whether residents received appropriate recognition, and what consequences the agency’s classification has within its mandate. A public knowledge record should permit these questions to be asked separately and then connected. An authoritative classification may explain an institution’s action without resolving every dispute about the evidence or the contributions that produced it.
Recording can itself become a consequential social act. A register established under a valid institutional procedure may help constitute a status; a research annotation usually records a claim about its subject. The architecture must identify which operation is being performed and under whose authority. A generic admission service has authority to accept a conforming submission only within its assigned role. Its success response supplies evidence of admission. Any further inference about recognition, entitlement, or legal effect requires the relevant institutional account. This distinction is especially significant when records travel across systems and the receiving interface has less context than the institution that produced them.
The six proposed categories, Entity, Relation, State, Property, Process, and Event, supply practical forms for expressing these accounts. Their function is organizational and computational. They provide ways to identify participants, connect roles, qualify descriptions, and represent persistence and change. They carry no proof of metaphysical completeness. An experience of exclusion, for example, might require a process, a relation, several attributed descriptions, and supporting narrative. Assigning it a first-level category does not determine its social meaning or settle its evidentiary status. Communities need domain concepts, explanations, and revisable mappings through which the common grammar can remain useful as interpretation develops.
Classification, Situated Knowledge, and Representational Authority
Classification connects formal representation to social recognition. Examining this connection clarifies why schemas belong within the infrastructure’s governance arrangements. Bowker and Star show how categories and standards organize social interactions, distribute advantages and burdens, and make particular perspectives visible or obscure. Their examination of classification systems makes the formation and maintenance of categories an empirical and political subject (Bowker and Star 1999). A public knowledge schema should therefore be assessed through its consequences for participation and interpretation as well as its logical consistency.
The power to define an admissible record precedes many later decisions about its credibility. A contribution form that accepts only formally employed researchers as contributors may make local observation difficult to recognize. A schema that requires an exact date can exclude testimony whose uncertainty is itself historically significant. A shared vocabulary that merges two local concepts can remove a distinction needed for a community’s explanation of its experience. These are design counterexamples, not claims about the prevalence of any particular practice. They show how a system may distort an inquiry before any reviewer evaluates its content. Once a classification is widely reused, correcting its consequences may require changes to derived records, queries, and institutional habits as well as to its formal definition.
Haraway’s account of situated knowledges supplies a related epistemic orientation. Her analysis associates responsible objectivity with accountable positions and partial perspectives, while retaining the ambition to provide adequate accounts of a shared world (Haraway 1988). For infrastructure design, this orientation supports the preservation of relevant conditions of observation and interpretation. The implication concerns accountable description: a record should make its standpoint and limitations sufficiently available for the inquiry being conducted. It provides no general justification for demanding comprehensive disclosure of a contributor’s identity or life. The relevance and permissible visibility of contextual information require independent assessment.
The proposed design accordingly treats schema revision as a change in interpretive commitments. A revised term can alter what a query includes and what a historical comparison appears to establish. Migration needs an account of the mapping, the judgments involved, and the distinctions it leaves untranslated. Preservation of an earlier schema supports examination of prior interpretations; continued display of a harmful label presents a separate question of access, presentation, and redress. Historical intelligibility can sometimes be maintained through a contextual explanation or a protected record. The architecture must support the decision without presupposing that every earlier expression should remain publicly searchable.
Representational pluralism also needs limits. Allowing communities to define their own concepts creates the possibility of ambiguous mappings, strategic relabeling, and incompatible standards. The answer proposed here is an inspectable account of the scope of each translation. Cross-domain exchange can preserve a local statement together with an attributed interpretation of its relationship to another vocabulary. Institutions remain responsible for deciding when the mapping is adequate for a particular use. A statistical comparison, a historical interpretation, and an administrative determination may reasonably require different levels of alignment. The common grammar should help expose those differences while retaining channels through which affected people can challenge the representational choices themselves.
Testimony, Criticism, and Epistemic Participation
Social epistemology clarifies the relationship between a retained history and the justification of public claims. Longino’s contextual empiricism emphasizes the influence of background assumptions on the evidential relationship between data and hypotheses and locates scientific objectivity within social inquiry (Longino 1990). Applied to the present problem, that perspective directs attention to the assumptions, responses, and revisions through which evidence is interpreted. A derivation record identifies selected dependencies. Its epistemic value also depends on the availability of criticism and on the capacity of inquiry to respond to relevant objections.
The infrastructure can contribute by preserving which criticism was made, what part of a claim it addressed, and how a subsequent interpretation responded. A change from a broad conclusion to a restricted one is more useful when readers can identify the reason for the restriction. A synthesis should similarly distinguish an objection answered by further evidence from an objection set aside through a procedural decision. Both can lead to a completed publication, although they establish different grounds for confidence. The paper therefore treats the history of criticism as part of a claim’s public interpretability. This is a proposal about retained information and responsive institutions, with empirical benefits still requiring evaluation.
Fricker’s analysis identifies wrongs inflicted on people in their capacity as knowers. Its distinction between testimonial and hermeneutical injustice brings attention to credibility and to the resources through which social experience becomes intelligible (Fricker 2007). The architectural application extends beyond giving each speaker an account identifier. Admission, discoverability, classification, and review can each affect whether a contribution becomes available to others as a candidate for knowledge. A durable record can retain an excluded person’s words while the surrounding organization continues to deny those words serious consideration. Preservation needs a relationship to procedures through which a contribution can acquire a hearing and a response.
This requirement does not imply equal evidential weight for every submission. Different claims require different competences and methods of assessment. A useful institutional arrangement distinguishes the opportunity to contribute and challenge from the judgment that a particular proposition is well supported. It should explain the grounds of exclusion or rejection in terms that can themselves be examined. Where moderation is needed to address harassment, fabricated submissions, or repetitive obstruction, reasons and review procedures help make the exercise of that authority answerable. Otherwise, the promise of contestation could leave the practical capacity to participate dependent on the unrestricted discretion of the incumbent operator.
The distribution of documentation capacity also matters. Well-resourced actors may generate extensive formal histories, whereas people with less time, equipment, or institutional support may rely on sparse records or testimony. If a design treats the quantity of recorded provenance as a general measure of credibility, it risks converting resource advantages into epistemic authority. The proposed safeguard is interpretive: absence of a particular trace must be reported as a limitation of the available record, with its significance assessed through the relevant inquiry. Assistance with submission, translation, and preservation can improve participation, although these services require resources beyond the representation language. The conditions of knowledge production consequently remain part of the object to be studied and supported.
Publicness and the Institutional Structure of a Knowledge Commons
Publicness concerns the relationship between knowledge resources and those whose inquiry or lives they affect. The present paper distinguishes access to information, participation in interpretation, accountability for consequential decisions, and continuity of the institutions that sustain these activities. These dimensions may reinforce one another, yet they can also diverge. A publicly downloadable dataset can be difficult for an affected community to interpret or challenge. A restricted archive can contribute to public accountability through authorized review and an adequately informative explanation. Assessing public function requires attention to this combination of capabilities and to the reasons for any limits placed on them.
Anderson’s experimentalist account of democratic knowledge emphasizes the contribution of diverse experiences, discussion, dissent, and feedback to collective learning (Anderson 2006). Its relevance here concerns the organization of inquiry around consequences that different participants are positioned to observe. A record of a policy evaluation should allow an affected group’s account to be related to the assumptions and outcomes under review. The paper does not infer from this account that an information service itself constitutes a democratic institution. It uses the relationship between participation and correction to justify examining whose experience can enter the record and influence subsequent reconsideration.
Knowledge-commons scholarship supplies an institutional complement. Hess and Ostrom’s framework organizes analysis around resource characteristics, community attributes, rules in use, action situations, and outcomes. It distinguishes institutions as understood and practiced rules from the formal texts that purport to describe them (Hess and Ostrom 2005). Their edited collection further situates knowledge sharing within problems of preservation, enclosure, intellectual property, and collective organization (Hess and Ostrom 2006). A commons therefore requires examination of the arrangements through which people maintain and govern a resource. Making files available under an open license establishes one relevant condition while leaving the durability, distribution of work, and responsiveness of those arrangements to be assessed.
For the proposed infrastructure, the resource includes preserved artifacts, their contextual relations, and the maintained capacity to examine and revise them. The participating community includes people who produce and steward records, as well as those who rely on or are materially affected by their use. These groups overlap imperfectly. Contributors may prefer recognition and durable access; subjects of records may need correction or protection; operators may need sustainable workloads; downstream users may seek efficient reuse. A governance model restricted to paying institutions or active contributors could therefore omit people who bear important consequences of the infrastructure’s operation. The appropriate forms of representation and standing require domain-specific institutional design.
Access decisions should be understood within these relationships. Public availability can enable criticism and reuse, while unqualified disclosure of sensitive testimony can undermine the conditions under which people can contribute. Restricted material can support a public claim when an accountable process explains the restriction, identifies the available grounds of assessment, and provides an appropriate route for challenge. Such arrangements have costs and possible failures: reviewers may be captured, summaries may omit material qualifications, and affected people may be unable to contest the evidence used against them. A responsible architecture must keep these limitations visible and subject the arrangement to review. Confidentiality alone supplies an incomplete account of public legitimacy.
Publicness is thus a continuing institutional responsibility. Its assessment should include who can obtain a reasoned response, whether records remain usable beyond a funding cycle, and whether communities can participate in changing the rules that organize their contributions. Decentralized custody may support local authority and continuity, although it also creates uneven resources and potential local concentrations of power. Shared interfaces are useful when accompanied by arrangements for assistance, appeal, and succession. The governance implications developed later in the paper follow from this understanding of the common resource and its participants.
Generative Relational Preservation and Its Limits
The preceding analysis defines the generative relational approach as a proposed integration of historical preservation, attributed representation, and public revisability. Generative refers to the selected processes through which claims, interpretations, and institutional judgments take shape and change. Relational refers to their dependencies on evidence, participants, concepts, material settings, and institutions. The combined thesis is both epistemic and normative: retaining relevant connections can support the assessment of a claim, and the selection and governance of those connections affect people’s opportunities to take part in future inquiry. The contribution claimed here concerns an architectural integration guided by that thesis. Established work on infrastructure, situated knowledge, and commons governance already supplies substantial antecedents for its components.
The proposal faces a serious objection from the costs and effects of documentation. Recording a decision can support accountability while altering the conditions in which people deliberate. Routine capture of exploratory conversation could discourage tentative ideas, expose vulnerable participants, or make ordinary revisions appear suspicious. Elaborate contribution records could become instruments of managerial monitoring. Detailed histories can also create a misleading appearance of completeness when undocumented work, oral transmission, or excluded experience remains outside the system. These are foreseeable design risks and candidate mechanisms for empirical study. Their possibility defeats any simple inference from greater capture to better knowledge or greater justice.
Selective preservation must therefore be justified by the inquiries and responsibilities it serves. Readers should be able to use the retained history to examine a decision’s grounds, revisions, and objections. A suitable record may consist of a reasoned decision, the evidence it relies on, and an account of the objections considered. Preserving every preceding exchange would require an additional justification. Choices about selection should identify the interests served, the omissions that matter, and the procedure through which the selection can be reconsidered. Retention can be graduated across public explanations, controlled evidence, and material whose preservation is unnecessary or impermissible.
A second objection concerns the relationship between historical reconstruction and explanation. Replaying admitted records can recover what a system held under a specified interpretation. Explaining how knowledge developed also requires judgments about causal importance, unrecorded conditions, and the meaning of disagreement. A sequence of entries establishes only the history of the retained representation. It may provide evidence for a richer genealogy, whose adequacy remains open to inquiry. The architecture should consequently preserve attributed explanations and their evidentiary grounds alongside operational traces, with clear indications of the limits of each.
A third objection concerns institutional authority. The availability of a complete-looking history may encourage an agency, platform, or model operator to treat its own representation as the decisive public account. The response proposed here combines addressable reasons, alternative interpretations, and procedures through which affected participants can seek correction. These capabilities can support public revisability only where institutions provide the resources and standing needed to exercise them. A technically preserved challenge with no prospect of examination would offer a weak form of participation.
These limits lead to a bounded preservation commitment. The infrastructure should sustain enough contextual and historical information for specified forms of examination while preserving the conditions under which people can continue to contribute, interpret, and revise knowledge. Its success would consist in improved inquiry and accountable institutional practice under those conditions. The later architecture translates this commitment into representational boundaries and services; the evaluation must examine both their operational behavior and their consequences for participation.
Related Work and Research Method
The proposal requires a method that connects social and normative explanation to executable distinctions. A representation can be formally precise while preserving an inadequate account of participation, and a compelling principle can remain ineffective when no operator can implement its remedy. This section positions the research against existing approaches, specifies the steps of the inquiry, and distinguishes conceptual arguments from formal and empirical evidence. The comparison concerns combinations of tools and institutions as well as individual standards.
Interdisciplinary Literature and the Integration Problem
Infrastructure studies and social epistemology establish that the organization of knowledge involves classification, expertise, recognition, and maintained practices, as developed in Section 2. Commons scholarship examines the institutions through which shared resources are governed. Justice and information law identify claims and constraints that can conflict within a single knowledge trajectory. The present research uses these approaches to determine which distinctions an infrastructure must make operational, while retaining their disagreements about authority, participation, and the proper object of protection.
Technical antecedents address overlapping parts of the same problem. FAIR connects reuse to discoverability, interpretable metadata, provenance, and appropriate access procedures (Wilkinson et al. 2016). CARE directs attention to collective benefit, authority, responsibility, and ethics in Indigenous data governance (Carroll et al. 2020). These frameworks support different dimensions of an infrastructure’s public purpose. A deployment’s use of persistent identifiers or an access-control vocabulary is insufficient to establish that the substantive goals of either framework have been achieved.
Research-object approaches directly challenge any suggestion that existing systems preserve only finished products. RO-Crate 1.2 describes resources together with contextual entities and information about production and reuse (RO-Crate Community, n.d.). Nanopublications provide an antecedent for connecting core assertions to context and provenance through existing linked-data technologies (Groth et al. 2010). Their relevance narrows the possible contribution here. The research concerns a specified relationship among assertion lifecycle, temporality, institutional decision, and public contestability; it does not claim to originate contextual packaging or individually addressable assertions.
Representation, Provenance, and Historical State
PROV-DM already represents activities, agents, derivation, revision, and provenance of provenance, with domain extension (World Wide Web Consortium 2013a). A generative history can therefore use its concepts without treating provenance as synonymous with a simple author field. The present architecture makes claims about such histories separately attributable and contestable. An alleged derivation must remain distinguishable from an institution’s accepted finding about it when records cross system boundaries.
RDF datasets, SHACL validation, and SPARQL queries provide established representation and processing substrates (World Wide Web Consortium 2014, 2017, 2013b). A graph name alone does not define the authority or evidentiary status of the graph’s content. A validation result concerns the selected constraints, while an answer depends on its query and entailment regime. The proposal consequently attaches interpretation and authority to declared profiles. A graph adapter can implement much of this design, provided it preserves these distinctions explicitly.
Temporal databases distinguish valid time from transaction time (Jensen et al. 1998); causal ordering identifies system-event dependencies without converting concurrent communications into a historical priority finding (Lamport 1978). Event sourcing provides a further antecedent for reconstructing recorded state and for the need to handle external effects carefully during replay (Fowler 2005). The architecture uses these results at their appropriate level. A historical correction can change a present account of an occurrence, and a reconstructed workflow can show what an institution did, without either operation recreating the occurrence itself.
Replication likewise requires a bounded claim. CRDT research supplies convergence conditions under stated assumptions (Shapiro et al. 2011). Compatible record histories can be combined deterministically while their interpretations remain contested or their workflow decisions conflict. The institutional meaning of a merged record therefore needs an account beyond transport convergence.
Comparative Position and Candidate Contribution
Table 1 identifies the comparison contract. Its third column states questions for the present integration, rather than claiming that the antecedent can never address them through extensions or governance. An evaluation must compare adequately configured systems that face the same knowledge problem and protection requirements.
| Approach | Relevant established contribution | Integration question |
|---|---|---|
| Knowledge commons and infrastructure studies | Situated institutions, classifications, maintenance and participation | How do these considerations govern concrete representation and processing choices? |
| FAIR and CARE | Reuse, stewardship, collective interests and authority | How are their distinct commitments reflected in admission, release and remedy? |
| RO-Crate and nanopublications | Contextual research packages and addressable assertions | How are changing endorsements, contested authority and restricted histories exchanged? |
| RDF, PROV, SHACL and SPARQL | Graphs, extended provenance, validation and querying | Which profiles preserve assertion status and the scope of derived answers? |
| Temporal and event-based systems | Recorded histories, reconstruction and time distinctions | How are epistemic correction and institutional consequences kept distinct? |
| Distributed replication | Convergence under explicit mathematical and delivery assumptions | How are local authority, semantic disagreement and workflow conflict governed? |
The prospective contribution is the interdisciplinary derivation and specification of those interactions. Its value would be shown where the architecture prevents a consequential conflation, makes a previously impractical remedy effective, or reduces the cost of a justified preservation practice. A new term, ontology, or language is insufficient evidence of that value. If an existing composition supplies the same capabilities more effectively, the appropriate result is to adopt or adapt that composition.
Conceptual Reconstruction and Normative Argument
The research proceeds through five stages. The first reconstructs the relationships among occurrence, representation, warrant, recognition, and institutional effect. This stage asks which distinctions are necessary to understand the problem cases and which can safely be combined. The six structural categories of the language are tested as a practical means of representation, with no inference that they exhaust social reality.
The second stage articulates normative commitments and their tensions. Meaningful epistemic participation, responsible disclosure, contestable authority, and the continuing possibility of inquiry are evaluated together. A preservation proposal must explain the interests it serves, the burdens it creates, and the protections available to affected people. A reasoned limit on collection can consequently be part of a successful public infrastructure.
The third stage uses scoped legal rules as constraints and stress tests. Section 5 distinguishes existing law from jurisprudential and institutional proposals. European data protection provides a concrete example of overlapping obligations concerning purpose, accuracy, protection, and retention; treaty provisions help separate information and attribution from exclusive rights in expression. Their use does not establish a complete comparative legal analysis or decide every jurisdictional question.
The fourth stage constructs an architecture in which these distinctions have defined consequences. Artifact-oriented design research provides an antecedent for inquiry through the construction and evaluation of an artifact (Hevner et al. 2004). The present artifact comprises a conceptual model, institutional allocation, service architecture, and bounded formal language. The method combines these deliberately; it does not treat computational correctness as a substitute for the normative argument.
The fifth stage tests the proposal through counterexamples and scenarios. The cases examine what a design makes possible, what it leaves undecided, and what new burdens it creates. They can defeat an internally inconsistent claim or identify a missing institution. Their success cannot show how an actual community will respond, how much work a deployment requires, or whether an affected party experiences the process as legitimate.
Evidence Levels and Reproducibility of the Inquiry
Four evidence levels are kept separate throughout. Conceptual claims are supported by distinctions, arguments, and engagement with alternatives. Normative proposals require reasons about interests, authority, and burdens. Formal claims depend on specified models and assumptions. Empirical claims require observations or evaluated deployments. The first three are developed to different degrees in this paper; the proposed field and comparative evaluations remain future work.
The source review is purposive and interdisciplinary, rather than a systematic exhaustive search. Primary publications, author or institutional repositories, official standards, and authoritative legal texts were checked before citation insertion. The accompanying audits state whether the inspected material was a full text, a chapter, or an abstract. The architecture’s proposed consequences are identified as inferences or design choices and are not attributed to a source merely because it supplied a related concept.
The formal-language checks demonstrate only selected representational and computational behavior. They do not prove the architecture’s justice, legal compliance, security, or practical usefulness. Section 15 therefore combines an analytical assessment of the present design with a separate evaluation program for its eventual implementation and institutions.
AI-Mediated Knowledge Formation and Public Responsibility
AI mediation changes the routes through which material is selected, transformed, and presented as knowledge. Its relevance to public infrastructure extends from generated text to classification, retrieval, translation, indexing, and the allocation of attention. This section examines those mechanisms, distinguishes several kinds of provenance, and derives responsibilities at consequential transitions. The analysis identifies possible failure mechanisms and institutional responses; it does not estimate their prevalence across all AI systems.
Transformation, Compression, and Apparent Authority
A summary transforms a set of records into a representation fitted to a purpose and audience. Its value often depends on compression: readers cannot inspect every source relation before using a public explanation. Compression becomes problematic when the distinctions omitted from the summary are material to its use. An institutional finding, an unreviewed suggestion, and a contested witness account may appear in one confident narrative even though their evidentiary roles differ.
Generative-AI risk guidance identifies confabulation, information integrity, and component or value-chain integration among relevant concerns (National Institute of Standards and Technology 2024). For the present proposal, the infrastructural implication is that an adopted output must remain connected to the claims, assessments, and decisions that justify its public use. This connection is a proposed response to those risks, with effectiveness still requiring evaluation. It does not establish that every generated statement can be traced to one determinate source or that source retrieval alone establishes accuracy.
Apparent authority can arise at several transitions. A generated suggestion enters an editor’s draft; an editor adopts it without retaining its uncertainty; a repository indexes the resulting statement as an institutional conclusion; and a later application cites that repository as independent confirmation. Every step can preserve its own bytes while the chain changes the statement’s public status. The infrastructure therefore needs to record adoption and classification decisions, including the scope of the responsibility accepted by the adopting actor.
The same concern applies to outputs produced without generative models. Automated language identification can exclude material from a corpus, and retrieval ranking can systematically make one interpretation easier to find. A governance model focused only on the final text would miss these upstream conditions. The proposed process representation consequently includes selection criteria, transformation methods, responsible operators, and materially relevant omissions where recording them is justified and feasible.
Provenance at Different Levels
Provenance in an AI-mediated trajectory has several distinct objects. Artifact provenance records the origin and versions of files. Operational provenance records a particular invocation and its inputs, parameters, outputs, and service dependencies to the extent available. Evidentiary provenance records which sources an adopter relies on for a specific proposition. Intellectual genealogy concerns the broader history of concepts and contributions. These relations can overlap without being interchangeable.
A logged prompt and output can help reconstruct a documented interaction. They do not reveal every influence represented in a model’s training or establish who originated an idea. A retrieval-augmented response can identify documents supplied at invocation, while the evidentiary relevance of those documents remains a matter for assessment. A generated citation can itself require verification. The proposed infrastructure gives these different claims separate types, speakers, and provenance, avoiding an undifferentiated assertion that an output has complete provenance.
Reproducibility also has several meanings. Replaying a stored output means retrieving the retained artifact. Reproducing an invocation requires access to the relevant model, software, parameters, and execution conditions, and may still be affected by nondeterminism. Reproducing the underlying scientific or historical warrant requires additional evidence and methods. A public interface should identify which of these activities is available before describing a result as reproducible.
Where sources or model details are inaccessible, an institution may still choose to use an output under a justified review process. Its record should state the limits of examination and the compensating checks on which it relies. An attestation from a service provider can be evidence about an operation while leaving the substantive claim unverified. The availability of an explanation and the adequacy of a justification thus remain related but separate questions.
Human Adoption and Distributed Responsibility
Responsibility must attach to actions and capacities within the trajectory. A contributor who supplies testimony, a laboratory that processes a sample, a model provider, an institution that adopts a synthesis, and an operator that distributes it have different knowledge and control. A requirement that one final author explain every upstream dependency can be impossible to satisfy; allowing each actor to disclaim the final effect can leave a remedy without an accountable institution.
The proposed allocation therefore identifies responsibility for bounded operations: collection, source selection, transformation, substantive adoption, release, correction, and continued distribution. An institution publishing a finding should state the assessments it performed and retain the ability to correct its own public representation. A model provider’s documentation can support that assessment without replacing the adopter’s decision about suitability for the particular public use. Specific legal liability remains governed by the applicable rules discussed within the bounded scope of Section 5.
Raji and colleagues propose internal auditing across the development lifecycle, with documentary outputs connecting decisions to an organization’s stated principles (Raji et al. 2020). The present architecture draws a limited lesson about preserving decision trajectories. Its public responsibility requirements extend further as a proposal: an internal audit may need a permitted public explanation and an independent route for affected parties to challenge consequential uses. Those additional institutions cannot be inferred from the existence of the audit documentation.
Human review itself requires scrutiny. A nominal approval field can conceal insufficient expertise, time, access, or power to alter the output. The record should make the scope of review and available evidence assessable where appropriate, while the institution supplies the resources and authority needed to make that review meaningful. The objective is an accountable decision process rather than a ceremonial human signature.
Correction, Reuse, and Recursive Amplification
A later correction can alter a statement’s public warrant while earlier copies remain embedded in summaries, indexes, or training corpora. The infrastructure can identify known dependencies and issue permitted correction notices, but it cannot guarantee that all recipients will revise their copies or that a model’s internal state will change. The record must distinguish performed corrections, acknowledged notices, and unresolved downstream effects.
Recursive reuse also complicates apparent corroboration. Several accessible sources may derive from one earlier assertion. A public query can report their common ancestry where known, so repetition need not be treated as independent support. The absence of a recorded derivation does not establish independence; it may reflect incomplete history. Domain evidence standards determine how these limits affect a finding’s weight.
The architecture therefore preserves attributed lineage and selected transformation events while keeping the final evidentiary judgment explicit. A synthesis can rely on a narrower corrected claim, preserve the challenged branch for historical inquiry, and describe the reach of its correction. Further contributors can extend this account through new evidence and interpretation. Continued generation remains compatible with institutional decisions because the record identifies their time, scope, and revisability.
Automation, Labor, and Participation
Automation can reduce the work of describing a record, translating a submission, or finding related evidence. It can also shift verification and correction costs onto people with the least capacity to contest an output. The relevant design question concerns the distribution of those costs and opportunities. An automated annotation should have an identified provenance and a proportionate route for correction; it should not automatically acquire the status of a verified social fact.
Interfaces for public contribution should permit uncertainty, partial knowledge, and a statement that the provided categories fail to capture a relevant experience. A contributor should be able to submit an intelligible account with assistance, while a steward translates it into structured form with the contributor’s relationship to that translation preserved. Otherwise, the infrastructure risks admitting only the experiences its automated schema can already recognize.
These considerations make AI mediation one part of a broader institutional design. The significance of a model lies in the relations through which its outputs are selected, adopted, and acted upon. Governing those relations requires the combination of preservation, review, responsibility, and participation developed in the following sections.
Justice, Rights, and Legal Pluralism
This section establishes the normative and legal conditions under which a generative relational infrastructure could deserve public support. Its method combines conceptual analysis of justice, a bounded examination of legal instruments, and institutional design arguments. The analysis proceeds from epistemic participation and fair procedure to distribution, information rights, provenance, plural authority, and remedies. These concerns determine which records the infrastructure may create and how those records acquire practical force. They therefore enter the architectural argument before the specification of authorization services. The proposed safeguards remain claims requiring institutional justification and evaluation; the legal examples specify existing constraints within their stated scope.
Normative Commitments and Legal Relations
Public knowledge governance involves several distinct forms of justification. A normative commitment explains why an affected person should have an opportunity to challenge a damaging representation. A legal entitlement identifies a right recognized within an applicable legal order. An institutional rule allocates authority and resources to a review process. A technical capability makes submission, suspension, or correction operationally possible. The four forms can support one another, while retaining different conditions of validity. A review button establishes a capability; an effective avenue of redress additionally requires an institution willing and able to act.
Hohfeld’s analysis supplies a useful discipline for distinguishing a claim correlated with another party’s duty, a liberty, and a power to alter legal relations (Hohfeld 1913). Applied to the present proposal, a contributor’s liberty to publish a criticism differs from a claim that a repository consider a correction request and from a curator’s institutional power to alter the repository’s operative metadata. A person described in a record may have interests or entitlements concerning the description while possessing neither authorship nor editorial office. Accordingly, a single field labelled owner would conceal relationships that the architecture must preserve.
The proposed rights representation identifies a claimant, the actor bearing the corresponding obligation, the protected operation or interest, the source and scope of the entitlement, and the available remedy. Legal authority, contractual undertakings, community mandates, and proposed ethical duties receive distinguishable source types. This arrangement permits a deployment to strengthen participatory commitments beyond a legal minimum without misrepresenting those commitments as universally enforceable law. It also allows a person to question the source of an asserted administrative power.
Justice remains broader than accurate execution of these rules. An institution can apply an exclusionary policy consistently and publish a complete audit trail of the resulting harms. Consequently, the architecture must support review of the rules that produce decisions alongside review of individual decisions. Rule authorship, amendment, representation, and oversight are constitutive parts of public knowledge infrastructure. Their justification and architectural consequences must be considered together when assigning institutional responsibilities.
Epistemic Justice and Representational Power
Epistemic justice concerns participation in the production and interpretation of knowledge. Fricker identifies wrongs affecting people in their capacity as knowers and distinguishes testimonial from hermeneutical injustice (Fricker 2007). The former directs attention to prejudicial credibility judgements; the latter concerns disadvantages associated with shared interpretive resources. These distinctions motivate an infrastructural question: which people can contribute intelligible accounts, and which accounts can become discoverable evidence?
The proposal treats collection and classification as exercises of representational power. Consider a synthetic community inquiry concerning industrial pollution. An institutional repository may already contain instrument measurements and inspection reports, while residents describe intermittent symptoms, changes in local practice, or experiences omitted by the measurement schedule. Requiring every submission to instantiate the institution’s existing exposure categories can exclude an account before its evidential quality receives consideration. Conversely, admitting the account as testimony provides a basis for investigation while preserving uncertainty about its interpretation and causal explanation.
An appropriate representation therefore distinguishes a person’s account, the categories used to encode it, the interpreter responsible for the encoding, and the evidential assessment subsequently made. Original wording and contextual explanation should be retained where their collection and retention are justified. Translation and classification become attributable operations that can be challenged. A speaker may accept a transcript while disputing the category assigned to it. Supporting that distinction makes the schema itself open to epistemic criticism. Schema compliance then concerns the adequacy of an encoding, while public consideration also concerns the experience that the encoding may inadequately capture.
Participation also requires a distinction between epistemic standing and evidential weight. A route for submitting evidence should remain available to affected persons with limited institutional credentials. The eventual weight assigned to a claim can still depend on source quality, corroboration, methodological competence, and domain-specific standards. This distinction avoids a false equivalence between equal respect for contributors and equal warrant for their propositions. A deployment should document its grounds for credibility assessment, including the use of institutional credentials, and evaluate whether those grounds systematically suppress relevant perspectives.
Preservation alone can intensify exclusion if downstream retrieval repeatedly surfaces prestigious summaries while leaving corrections or local accounts practically invisible. The proposal therefore extends contestability to ranking, canonicalization, and semantic mappings. A challenge should identify whether the alleged wrong concerns an assertion’s content, its classification, its prominence, or the disappearance of its qualification during reuse. Evaluation must examine whose contributions survive successive transformations, including AI summaries. A complete event history with persistently unequal visibility would satisfy a storage objective while failing the epistemic objective developed here.
Procedural Justice and Effective Contestation
Procedural justice supplies criteria for the institution’s response when a record affects a person’s standing, opportunities, or responsibilities. The following safeguards are proposed design commitments for a knowledge institution. Their application as enforceable legal duties depends on the institution and applicable law. The central commitment is that a consequential finding should remain answerable to affected persons through accessible reasons, a meaningful opportunity to respond, and review by a competent body.
A review process requires several distinctions. Receiving a submission, determining its procedural admissibility, evaluating its evidence, publishing a finding, and implementing a remedy are separate actions. Each can fail independently. A repository may accurately register a complaint and then leave it unanswered; a panel may reach a justified finding that downstream services fail to implement. The proposed process records responsibility for each stage and gives the claimant an intelligible account of its progress. The mechanism should support assisted and confidential submission, language access, reasonable opportunities to supply evidence, and conflict-of-interest review. Access to a formal language is an implementation option for skilled users; a person’s standing should survive inability to write a valid program.
Fair procedure must also accommodate contested evidence and unequal exposure to retaliation. A public allegation can injure its target before review, while immediate publication of a complainant’s identity can make participation unsafe. Institutions should distinguish private intake, provisional protective measures, and the publication of a reasoned outcome. Decisions concerning temporary restriction require a stated basis, duration, and review path because protective measures can themselves suppress inquiry. Protected evidence may require an authorized reviewer and a disclosure arrangement that gives the affected party sufficient grounds to answer without exposing a vulnerable source unnecessarily.
Unrestricted reopening would make findings unusable and invite strategic exhaustion of reviewers. A defensible procedure can therefore differentiate appeal on procedural error, reconsideration on materially new evidence, and repetitive submissions. Such thresholds should be published and reviewable. Resource constraints justify prioritization through an accountable policy; they also create a duty within the proposed institution to report unresolved work. Closure of a particular proceeding is compatible with a record that retains uncertainty, minority reasoning, and the possibility of later revision. The architecture should preserve these distinctions whenever an AI service summarizes an institutional finding.
Distribution, Recognition, and Infrastructural Dependence
Distributive justice examines the allocation of benefits, costs, and capacities associated with knowledge preservation. Recognition examines the standing accorded to contributors and communities. Fraser’s account warns that recognition politics can displace redistribution and can reify group identities (Fraser 2000). The proposal uses these warnings to assess whether public visibility is accompanied by an effective capacity to shape and use the record.
An infrastructure can publish contributions openly while distributing their benefits unevenly. Well-resourced organizations may perform large-scale analysis, control high-visibility interfaces, and influence vocabulary standards, while contributors supply translation, moderation, contextual explanation, and correction labour. These are plausible mechanisms of unequal benefit, requiring investigation in deployment. Attribution can acknowledge that labour, but acknowledgment by itself supplies neither maintenance funding nor a practical ability to contest institutional decisions.
The proposed institution should therefore account separately for contribution credit, compensation where appropriate, operational resources, and governance voice. Its budget should make review, accessibility, preservation, and community participation visible as continuing responsibilities. Federation can support local custody, yet the costs of secure hosting and semantic maintenance can produce dependence on a few providers. A credible exit arrangement consequently requires usable exports, documented interfaces, assistance with migration, and a receiving institution with sufficient capacity. A nominal right to fork has limited value when the dissenter loses identifiers, context, or access to the users who depend on the record.
Recognition can also generate an enduring hierarchy. An earlier contributor may deserve historically accurate attribution while lacking competence to govern later applications. A community may revise its honorary designation of a founder while preserving evidence about chronology. The infrastructure should represent contribution, priority, recognition, endorsement, and administrative authority independently. This separation allows correction of historical erasure without automatically transferring editorial power to the person newly recognized. It also permits later contributors to acknowledge ancestry while dissociating themselves from an originator’s interpretation.
Collective representation introduces an additional tension. Recognizing a community’s authority can protect its knowledge from appropriation, while a single designated spokesperson can conceal internal disagreement. The proposed governance record should identify how representatives acquire and retain their mandate and how members can contest it. Collective self-government and individual participation require an articulated relationship. The adequacy of that relationship must be assessed through situated engagement with the community; a universal participation score would obscure the relevant social and institutional differences.
Personal Data and the Legal Conditions of Preservation
The European Union’s General Data Protection Regulation provides a bounded legal test of the preservation proposal. Article 3 connects territorial scope to establishment and, in specified circumstances, offering goods or services to people in the Union or monitoring their behaviour there. An architecture therefore needs a deployment-specific scope assessment. Public accessibility alone does not establish that every node is subject to the GDPR. Article 4 also distinguishes the actor determining processing purposes and means from an actor processing on that actor’s behalf (European Parliament and Council of the European Union 2016).
For a federation, the design implication is that responsibility follows the activities and decisions of participating organizations. Technical labels such as peer, archive, or relay leave that allocation unresolved. The proposal requires a deployment register connecting organizations to their processing functions, purposes, decision roles, and contact routes. A person seeking correction should be able to identify the responsible institution even when a query traverses several services. This register supports analysis and accountability; its entries remain open to legal assessment.
Articles 5 and 6 require processing principles and an applicable lawful basis; the relevant principles include purpose limitation, minimization, accuracy, storage limitation, and accountability. Article 9 imposes additional conditions for specified special categories of personal data. A public-interest mission statement is insufficient to establish these conditions. For example, Article 6(1)(e), read with Article 6(3), requires a task grounded in Union or Member State law, and Article 9(2)(j) connects its research and archiving condition to such law and safeguards (European Parliament and Council of the European Union 2016).
These provisions make selection a necessary component of genesis preservation. A deployment should articulate which historical relations are necessary for its purposes and justify the granularity of identity, context, and interaction data it retains. A record of a research transformation may require the responsible laboratory and method while providing little justification for publishing every participant’s private conversation. The resulting preservation profile should connect each information class to a purpose, authorized uses, retention review, and responsible institution. It should also address derived records: a classification or AI-generated summary can expose information about a person even when the underlying source remains locally controlled.
Article 25 addresses data protection through design and defaults, and Article 32 requires security measures appropriate to risk (European Parliament and Council of the European Union 2016). In the proposed architecture, these obligations motivate separation of identity from public contribution records, differentiated custody, restricted sensitive payloads, and review of disclosure through indexes and metadata. These arrangements are candidates for implementation and evaluation. A sensitive payload can remain protected while its surrounding links reveal participation, location, or affiliation; control of the payload alone would leave the exposure unresolved.
Pseudonymization requires particular care. Article 4(5) and Recital 26 describe conditions involving additional identifying information; pseudonymization does not automatically produce anonymous information (European Parliament and Council of the European Union 2016). Persistent identifiers, timestamps, and relational patterns may permit linkage even when names have been removed. The proposed disclosure assessment therefore examines reasonably available linking information and intended recipients. Whether a particular transformation removes identifiability remains a contextual assessment. A generic anonymous flag cannot establish that conclusion for every subsequent combination of records.
Correction, Erasure, Research, and Portability
Information rights require differentiated lifecycle operations. GDPR Articles 16–19 address rectification, conditional erasure, restriction, and notification to recipients, with qualifications specified in the relevant provisions. Article 18 includes restriction while contested accuracy is verified. Article 17(3) qualifies erasure where processing is necessary for specified purposes, including expression and information, legal obligations, legal claims, and qualifying research or archiving whose objectives would otherwise be seriously impaired (European Parliament and Council of the European Union 2016). The architecture therefore needs decisions addressed to particular records, purposes, and operations.
The interpretive difficulty arises when a historically accurate record of an allegation contains an inaccurate allegation about someone. An infrastructure can distinguish the occurrence of the allegation from its truth and later disposition, yet that distinction does not itself justify continued public exposure. The proposal assigns the institution a further decision about which representation should remain available for which purpose. Possible measures include correcting current descriptions, appending a qualification, restricting access to historical payloads, or erasing information where required. Each measure affects historical intelligibility differently and should receive reasons proportionate to the conflict it addresses.
Article 89 requires safeguards for research, statistics, and archiving in the public interest, particularly minimization. Its paragraphs 2 and 3 allow Union or Member State law to provide specified derogations subject to conditions of necessity and serious impairment; paragraph 4 confines those derogations to the relevant purposes (European Parliament and Council of the European Union 2016). Accordingly, the research label supplies neither a blanket exception nor an independent authorization for all downstream reuse. A deployment invoking a derogation should identify its legal source, affected right, purpose, safeguards, and justification. Moving a record from historical inquiry into another application requires renewed assessment of the applicable conditions.
Erasure also exposes the limits of federation. The proposed institution should maintain an inventory of controlled copies and known disclosures sufficient to implement remedies and communicate them to relevant recipients. The public record of an erasure can itself reveal protected information, so a tombstone also requires a disclosure decision. Where independent recipients retain copies, a completed local operation should report its actual scope. The architecture must distinguish an instruction sent, an action acknowledged, and an action verified. This is necessary for a remedy to remain assessable without promising technical recall beyond the institution’s control.
Article 20’s portability right concerns qualifying personal data provided by the data subject under its stated lawful-basis and automated-processing conditions, with protection for others’ rights (European Parliament and Council of the European Union 2016). The broader institutional proposal for exporting knowledge trajectories consequently needs its own authorization framework. A contributor’s permitted export may include their contributions and public contextual links while excluding confidential testimony concerning other people. Portability should preserve the meaning and qualifications of permitted records, and the export should explain material omissions at a level consistent with their protection.
Provenance, Attribution, and Intellectual Property
Provenance requires a legal vocabulary that distinguishes historical relations from rights over protected subject matter. Article 2 of the WIPO Copyright Treaty locates copyright protection in expression, excluding ideas and related abstract subject matter as such. Article 5 protects qualifying intellectual creation in database selection or arrangement without extending that protection to the data themselves. Berne Convention Article 6bis separately recognizes authorship and certain integrity interests, with remedies governed by the country where protection is claimed (World Intellectual Property Organization 1996). These treaty anchors support distinctions; they leave jurisdiction-specific application to the relevant legal order.
The proposed record therefore separates a historical contribution, a claim of authorship, an asserted legal interest, a licence concerning specified subject matter, and an institutional attribution rule. Evidence that a person first recorded a concept can support a chronology finding without establishing exclusive control over later uses of the concept. Conversely, the absence of copyright in an idea does not determine permission to reproduce its particular expression or disclose personal or confidential information surrounding it. A licence attached to an artifact should identify its scope and source of authority. Its presence cannot settle every legal relation associated with the artifact’s provenance graph.
This differentiation addresses two opposed risks. Weak provenance can permit later actors to erase predecessors, misdescribe dependence, or appropriate recognition. Unqualified ancestral control can burden every later use with permissions from an expanding chain of contributors. The proposal preserves attributable relations while requiring an independent source for downstream control. It supports accurate descriptions of influence, independent development, revision, and disagreement, as well as a contributor’s recorded dissociation from later endorsement. Responsibility for a harmful alteration must similarly be examined through the actor’s intervention, role, and relevant duties; remote ancestry alone is an inadequate allocation rule.
Attribution remedies should correspond to the relation established by the evidence. A correction may restore an omitted source, qualify an exclusive priority claim, distinguish a translation from the original, or identify an uncertain attribution. The institution should avoid converting every successful challenge into a singular founder designation. Several contributors may occupy different historical roles. Preserving those roles gives later inquiry a more informative record and reduces the pressure to resolve complicated histories through a single status ranking.
Community Authority and Plural Legal Orders
Legal pluralism directs attention to the interaction of normative orders within social life, a problem developed in Merry’s account of legal and social ordering (Merry 1988). For this proposal, pluralism identifies an institutional condition: territorial law, Indigenous legal traditions, professional duties, research agreements, and repository rules may concern overlapping records. Their coexistence creates questions of competence and justification that a technical policy-combining rule cannot resolve alone.
The United Nations Declaration on the Rights of Indigenous Peoples supplies a specific normative anchor. Article 31 addresses Indigenous peoples’ cultural heritage, traditional knowledge, and related intellectual property interests; Article 33 concerns membership and institutional self-determination. Article 46 also addresses the rights of others and the Declaration’s interpretation (United Nations General Assembly 2007). The proposal consequently treats an affected people’s authority as a matter requiring engagement with its institutions and applicable law. Recording one custodian’s access preference would leave questions of representation, collective benefit, and continuing responsibility unresolved.
A federated arrangement should allow a community to retain sensitive material locally, define the scope of an authorized release, and identify the institution through which further requests are considered. Derived disclosure deserves specific consideration because a summary can reveal protected relationships or change the cultural setting of interpretation. Public benefit may be served through a controlled explanation, a community-approved description, or an aggregate whose limitations remain visible. Such arrangements are institutional proposals to be negotiated with the people concerned. They do not establish that every restriction is justified or that any single mechanism implements collective authority adequately.
The difficult case concerns conflict: a research participant seeks disclosure, a community authority objects, and a territorial legal obligation may point in another direction. The architecture should preserve the respective claims, their sources, affected interests, and the body competent to decide the particular operation. A deployment must obtain a situated legal and institutional determination. Temporary restriction may be appropriate pending review, but it requires a review route and duration. A universal rule that every restriction prevails could empower strategic censorship; a universal rule that public interest prevails could enable appropriation. The proposed federation provides procedural space for a reasoned determination and differentiated publication scope. It offers no general solution to conflicts of law or competing claims of sovereignty.
Evidence, Institutional Findings, and Remedies
The evidential role of an infrastructural record depends on the proposition for which it is offered. Hohfeld distinguishes facts that operate to change legal relations from facts that provide evidence of relevant occurrences (Hohfeld 1913). A repository receipt may help establish that an assertion was submitted at a particular stage; whether the submission constituted a legally effective act depends on additional rules. Similarly, a digital signature can support an integrity and key-attribution assessment while leaving the signer’s authority, the truth of the content, and legal effect open to further proof.
The U.S. Federal Rules of Evidence provide a scoped illustration. Rule 901 addresses authentication, while Rules 902(13) and 902(14) provide specified certification routes for electronic records and copied data, including notice requirements. Relevance, exclusion, and hearsay are addressed separately in Rules 401–403 and 802 (United States House of Representatives, Committee on the Judiciary 2025). This example shows why successful verification of a digest or signature cannot be presented as a universal certificate of legal admissibility. The infrastructure can preserve material useful to an evidential inquiry, subject to the applicable forum’s rules.
Institutional findings require comparable boundaries. A repository panel may correct metadata under its charter while lacking authority to determine civil liability or direct another organization. The finding should identify the question decided, evidence considered, standard applied, decision-maker, institutional competence, qualification, and review status. An exporter or AI summarizer should retain these conditions when reporting the finding. Otherwise, a bounded administrative conclusion can circulate as an unrestricted statement of legal or historical truth.
Remedies should address the operation through which harm occurs. Correcting an assertion may leave a ranking, a derived profile, or an earlier disclosure unchanged. The proposal therefore connects findings to responsible operators and to the transformations affected by the correction. Remedial completion requires an account of implemented changes, remaining copies, and unresolved consequences. Public accountability also requires a path beyond the institution when it fails to respond, subject to applicable external remedies. A generative history becomes valuable for justice when affected persons can use it to obtain reasons, challenge authority, and pursue effective change.
Public Purposes and Preservation Requirements
The social and legal analysis determines what counts as adequate preservation. A record should support justified inquiry while making its classifications, omissions, and consequential uses open to appropriate challenge. This section derives requirements from those purposes, identifies the decisions needed to balance them, and connects each requirement to architectural behavior. The threat analysis includes the effects of ordinary institutional practices as well as deliberate misuse.
From Public Interests to Design Obligations
The conception of publicness in Section 2 requires more than successful retrieval. A person whose experience is represented needs an intelligible account of that representation and an effective means of contesting consequential errors. A contributor seeking attribution needs the relation between contribution and recognition to remain addressable. A custodian protecting sensitive material needs to limit disclosure without misrepresenting the resulting public account as fully reproducible. These interests generate different obligations, and their conflicts require an identified decision process.
The justice and legal analysis in Section 5 also changes the unit of design. Protecting one file while exposing its relationships can leave a person’s identity or a community’s protected knowledge accessible. Conversely, removing every relation after a disclosure objection can prevent an affected contributor from obtaining correction. An adequate design must therefore represent purposes, affected parties, decision authority, retention conditions, and the scope of a permissible explanation alongside the content.
The proposal uses a reasoned preservation decision with five elements: the public or domain purpose; the information and relationships necessary for that purpose; the interests and risks of affected parties; the alternatives available through aggregation, restriction, attestation, or noncollection; and the authority and review process for the decision. The decision is revisable when purposes, risks, evidence, or applicable rules change. This procedure is a normative design proposal, not a claim that a universal balancing formula resolves the relevant conflicts.
Question-Oriented Preservation
Preservation begins with a declared inquiry scope. A domain node should state which questions its records support, which source classes it accepts, and which omissions are expected. For the running case, required questions include the identity of each recorded speaker, the evidence selected for a claim, the interval affected by a correction, and the operational authority behind a release. A model-output archive intended only for reproducible text retrieval may require a different selection from an archive intended to support priority disputes.
Table 2 groups the requirements into observable contracts. The grouping makes responsibility and test design explicit while preserving the separate requirements of the language package.
| Identifier | Preservation contract | Observable acceptance condition |
|---|---|---|
| R1 | Attributed content and evidence | A reader can distinguish description, speaker commitment, and cited evidence within an authorized view. |
| R2 | Temporal reconstruction | With retained interpretable dependencies, a delayed correction leaves an earlier cut’s support state reconstructable within the current authorized view. |
| R3 | Disagreement and revision | Opposing assertions coexist; withdrawal of one leaves independently asserted support intact. |
| R4 | Authorized processing | A failed transaction leaves no accepted partial effect; observed events do not execute themselves. |
| R5 | Federated custody | A receiver handles duplicate and missing dependencies explicitly and does not infer authority from transport alone. |
| R6 | Controlled disclosure | Current policy governs query and export, including evidence, identifiers, and derivations. |
| R7 | Retention and continuity | Reconstruction reports available scope after sealing, erasure, or custody transfer. |
| R8 | Practical stewardship | Each critical operation has an accountable role, escalation route, and resource assumption. |
| R9 | Representation and voice | A contributor or materially affected person can challenge a category or supply an account requiring assisted interpretation. |
| R10 | Independent review and remedy | A consequential decision has an identified reviewer and an effective correction route. |
| R11 | Purpose and rights protection | Collection, retention and release identify their governing purposes, authority and legal constraints. |
| R12 | Participation and institutional continuity | Costs, portability and succession are assessed for contributors and affected communities. |
Context selection itself requires provenance. A steward who omits a private conversation from a public trajectory may have good reasons, yet the resulting record should avoid implying that every relevant interaction was captured. Where safe, a scope statement can describe the collection boundary. Where even an omission’s existence is sensitive, a more general qualification may be necessary. An apparently complete graph can otherwise make collection choices look like features of historical reality.
Identity, Evidence, and Authority Threats
The integrity threat model includes fabricated sources, falsely attributed assertions, duplicate identifiers with different payloads, compromised keys, and imported records whose schemas are unavailable. It also includes an ordinary user’s mistaken inference that a valid signature establishes truth. The infrastructure must expose the scope of verification: authenticated bytes, admitted representation, accepted institutional finding, and substantive credibility are different statuses.
Authority inflation can occur without any forged signature. A source may be competent to attest that a file was deposited while lacking competence to declare who originated its ideas. A domain reviewer may be authorized to classify a submission while lacking authority over another community’s knowledge. The request and receipt therefore identify the exact operation and scope of authority. Human judgment remains necessary when that scope is contested or its institutional basis is inadequate.
Disclosure and Availability Threats
Disclosure threats extend beyond raw payloads. A graph edge can reveal contact between people; an evidence identifier can reveal participation in a study; a count or query timing difference can expose a restricted record. Derived artifacts and cached explanations can continue to disclose information after access policy changes. The architecture consequently treats metadata, proof dependencies, and query-result behavior as protected information flows.
Availability threats include unavailable nodes, abandoned schemas, stale indexes, lost decryption keys, missing withdrawal records, and institutional closure. A system must distinguish a reproducible available projection from a promise that all past content remains reconstructible. In particular, missing lifecycle information can make a formerly endorsed assertion unusable for a current support computation, even when its original payload survives.
Institutional and Resource Assumptions
The initial deployment assumes identified operators, governed trust anchors, bounded membership, and finite retained datasets. Contributors may be malicious, but the minimal consistency argument assumes that admitted receipts have been validated according to the declared profile. Adversarial federation requires additional mechanisms and evaluation. No blockchain or global consensus service is a prerequisite of the proposed local profile.
Institutional risks include concentrated control over schema catalogs, procedural exclusion, burdensome contestation, and selective preservation that privileges well-resourced contributors. The architecture can expose decisions and provide revision interfaces, yet its efficacy depends on who can use those interfaces and obtain a reasoned response. Evaluation must therefore measure steward workload and participant burden alongside technical correctness.
Shared Information Model and System Boundaries
The information model translates the distinction between social experience, attributed accounts, and institutional judgment into a shared representational structure. Its purpose is to preserve the differences needed for interpretation and contestation across those relationships. The analysis introduces domain records, assertion and commit envelopes, identity, and epistemic status, then identifies their institutional limits. The accompanying language specification provides the exact grammar; the present account explains the choices through the public purposes established in Sections 2 and 5.
Knowledge Trajectories and Selection Boundaries
A knowledge trajectory is a purpose-bounded network of recorded accounts, contributions, evidence, transformations, disputes, and institutional decisions selected to make a development intelligible. Its shape can branch, converge, or retain unresolved alternatives. A trajectory need not possess a single origin or final endpoint. Its boundary reflects a stated inquiry, the material available, and the authority under which that material may be used.
For example, an inquiry into the revision of a public environmental report can connect observations, translations, a disputed assessment, an adopted finding, a later correction, and affected summaries. An inquiry into the intellectual origins of the assessment method may select a different network from some of the same records. Both selections can be defensible if their purposes, omissions, and interpretive assumptions are explicit. The trajectory therefore differs from the complete commit ancestry: the latter records the dependencies of admitted operations, while the former selects relationships relevant to an inquiry into knowledge development.
Architecturally, the selection is realized through domain records, attributed relations, relevant history cuts, and permitted query results. A saved view should identify its selection procedure, schemas, context and temporal scope, collection boundary, and material dependency limits. Human judgments of relevance or causal importance should themselves remain attributable. The trajectory is a higher-level view or domain construction over these structures; it adds no seventh primitive category or automatic authority to the language. Its adequacy is assessed through the questions it helps answer and the consequential context it leaves out.
Domain Records and Structural Categories
A domain record is an immutable typed description with an opaque identifier. The proposed grammar organizes domain types into Entity, Relation, State, Property, Process, and Event. An Entity describes a participant or referent; a Relation connects named roles; a State describes a subject’s configuration; a Property records a characteristic; a Process describes an extended activity; and an Event describes an occurrence. Communities define narrower types and their interpretation through versioned schemas.
The six categories organize descriptions for processing; their adequacy is assessed against a domain’s inquiries. They provide no universal ontology of social life. A narrated experience can contain meanings that remain outside its structured encoding, and a disputed occurrence can receive several incompatible descriptions. A schema therefore needs an account of the purposes for which its categories are suitable and the interpretive work left to supporting material. Retaining a permitted narrative alongside its encoding allows subsequent contributors to examine that relationship. A representation that passes structural validation can still require conceptual revision.
These categories serve structural roles. A historical priority claim, an institutional recognition, and a legal status can each involve several such records. Their distinct conditions of existence and revision belong in domain schemas and interpretive practice. A change to a recognition record need not change a recorded account of a past occurrence. Similarly, a Property can describe the confidence assigned by a particular assessor without introducing a universal confidence scale.
Processes and events remain independent of the storage mechanism. A Process can include instruments, institutions, purposes, and inputs that explain the conditions of a transformation. An Event can record a critical occurrence within that process. The commit ledger preserves changes to the representation; it does not replace the domain account of how knowledge was generated.
Assertion and Commit Envelopes
Creating a typed record permits it to be mentioned without endorsing its content. An assertion separately identifies a record, positive or negative polarity, speaker, context, applicability interval, evidence references, and disclosure policy. The same description can therefore be endorsed by one speaker and denied by another. Logical polarity and cryptographic signatures are distinct: a negative assertion can be cryptographically authenticated just as a positive one can.
A commit groups admitted operations atomically and identifies its parents, submitter, receipt time, execution profile, and validation receipt. Assertion and commit envelopes are technical structures rather than additional domain categories. A domain Event can nevertheless refer to an assertion being challenged or a commit being reviewed. This supports governance of the record without conflating the record with its subject.
The separation also applies to Claim entities. A record can describe the text of a proposition while its speaker merely attests that the proposition was published. Acceptance of that proposition’s content requires an explicit domain assertion with the intended semantics. This avoids treating the presence of a quotation as endorsement of its message.
Identity and Schema Interpretation
Opaque record identities avoid conflating similarly named people and permit cyclic references within a jointly validated transaction. Record payloads and schema artifacts have separate digests. An imported identifier accompanied by different immutable content is an integrity conflict, irrespective of which copy arrived first. The receiver quarantines the conflict and retains appropriate protected evidence of the incident.
Exact schema identity includes the artifact digest. A human version label alone is insufficient because a change to field meaning, argument order, or an enum can alter the interpretation of old content. Migrations produce new records or views through an explicit, attributed mapping. Identity alignments likewise remain claims whose scope and provenance are visible; they do not silently collapse distinct referents across communities.
The core treats people, processes, and occurrences as intensional descriptions: their record identities contribute to their proposition keys. Relations, states, and properties are extensional under exact schema identity and complete field values. Consequently, separately stored copies of the same fully qualified relation can carry opposing assertions. A difference in a material qualifier produces different content, requiring a more specific domain account of their relationship.
Descriptive metadata participates in the same representational politics as the content it organizes. A subject can challenge an identity alignment, a contributor designation, or an assigned classification while accepting the underlying transcript. Such challenges need addressable targets, attributed reasons, and a route to the institution responsible for the mapping. Changing an operative classification should preserve the relation between the earlier interpretation and its replacement to the extent retention is justified. Immutability here identifies a record version within the model; decisions about continued custody and disclosure remain governed by the lifecycle arrangements. This distinction permits exact historical interpretation without requiring indefinite public exposure of every earlier label.
Support and Institutional Status
For a selected context, interval point, and authorized history view, an exact proposition can have positive support, negative support, both, or neither. These states summarize available assertions. They leave substantive truth and evidentiary weight to the selected domain method. Neither means that this view contains no usable support; it does not establish global absence or falsity.
Incompatible positive values require a further distinction. Two reviewers can classify the same claim as accepted and contested without either explicitly denying the other’s full assertion. A declared exclusivity constraint can report this as a functional conflict. An operational review system can also hold a single controlled status, established by an authorized procedure. Its status remains a fact about that procedure’s record, with an independent route for substantive challenge.
The application interface should display these distinctions using ordinary language. A reader can see who asserted a relation, when it applied, whether opposing support is available, and whether an institution issued a finding. The interface should avoid a single unqualified badge that merges verified identity, accepted syntax, operational approval, and factual correctness.
Components, Interfaces, and Deployment Profiles
The component architecture assigns responsibility for preserving evidence, interpreting submissions, making decisions, and controlling public release. These boundaries give operational form to the institutional distinctions developed above. This section examines a domain node, the dependencies among its services, and alternative deployment profiles. The decomposition is logical: an initial implementation can place several services in one process while retaining distinct responsibilities for custody, validation, review, and the exercise of delegated powers.
Institutional and Representational Dependencies
Figure 1 places the service architecture within the wider infrastructure. Public purposes provide grounds for preservation and constraints on its use; knowledge practices supply accounts and criticism; governing institutions allocate powers and responsibilities. Shared records and services make selected relationships addressable and consequential. The arrows indicate reciprocal dependencies. Experiences of classification or review can motivate institutional change, just as a revised mandate can change the permitted operation of a service. These relationships require interpretation and accountable decisions; they are not automatic execution paths.
Domain Node and Trust Boundaries
A domain node is a governed service boundary with a declared schema catalog, admission policy, retained history, and disclosure interface. It may belong to a research group, archive, institution, or community organization. Node membership is an operational relationship, not a finding that every admitted statement is reliable. A node can admit a disputed assertion precisely to make its grounds and subsequent review addressable.
Figure 2 shows the component responsibilities. The control plane implements effective permissions under a declared institutional mandate; domain records describe the subjects and events of inquiry. A public application accesses a permitted view through the query and release boundary. Direct access to an assertion store would bypass that boundary and therefore requires an independently authorized operator role.
The diagram describes information and decision dependencies rather than a mandatory network topology. Every admission consults the trusted policy service even where the drawing omits that edge for legibility. Federation imports pass through admission before their receipts become locally admitted history. A protected deployment may keep custody, policy, and public query services on separate machines; a small prototype can retain the same logical boundaries within one application.
Technical control and warranted authority require separate accounts. An administrator may possess the capability to change a policy while lacking a mandate to decide the underlying dispute. The node’s institutional record should identify the source, scope, duration, and review of each delegated decision role. Its software configuration then implements the permissions associated with that role. A configuration change can be logged and authenticated even when its mandate is contested. Review must consequently be able to examine the delegation and its exercise, with a route outside the ordinary administrator’s discretion when that administrator is implicated. The formal admission model assumes such an allocation; its justification and continued supervision belong to the governing institution.
Custody, Schema, and Assertion Services
The custody service retains artifacts or versioned references to external repositories. Its contract includes identifier, retrieval method, version, integrity information where appropriate, and the conditions under which a payload can be obtained. A stable reference can remain useful when access is restricted, provided disclosure of that reference is itself permitted. Artifacts with unavailable or uncertain versions are recorded with that limitation rather than assigned an invented fixed version.
The schema service supplies immutable artifacts containing type declarations, constraints, and relevant rule or workflow profiles. It resolves imports from an explicit catalog, with resource limits and digest checks. The admission service validates source structure, expands references, checks typed payloads, and records any mapping used during import. It rejects incompatible identities before they enter the admitted store.
The assertion store indexes attributed commitment separately from content. Queries can retrieve all available witnesses for a proposition without duplicating its extensional value. Withdrawals reference exact assertion IDs and intervals. Indexes must retain enough lifecycle information to determine whether a witness remains active, even when a reason or evidence payload requires more restrictive access than the public assertion.
History, Workflow, and Projection Services
The commit service stores a directed acyclic graph of admitted transactions. Branch labels point to tips; the labels themselves can change without rewriting the identified commits. Each commit’s parent closure equals the pre-state evaluated during admission. This condition prevents a command from being evaluated on one branch while silently inheriting a conflicting branch as an additional parent.
The workflow service maintains receipt-derived tokens for controlled runs. Each run binds a Process record to a machine and subject. Start establishes an initial token, advance consumes the expected current token, and an authorized resolution consumes a complete set of conflicting maximal tokens. The service does not interpret every Event record as an executable instruction. External actions require a distinct adapter whose invocation is outside replay.
The projection service reconstructs temporal support and workflow state from admitted data. Materialized views carry schema, rule, cut, and policy dependencies. An update can invalidate a cached conclusion even where the conclusion’s text remains unchanged. A complete implementation needs either recomputation or an incremental method shown equivalent to the specified semantics.
Query, Review, and Discovery Services
The query service accepts an authenticated requester, purpose, historical cut, valid instant where relevant, context, and operation. It returns permitted results with the interpretation and scope needed to assess them. Explanation is a controlled output: a readable conclusion does not automatically make each premise, contributor, or inference step public. Result completeness is stated relative to the supplied authorized view and available dependencies.
The review service provides addressable challenges, reasons, responses, and decisions. It can coordinate ordinary correction workflows and refer higher stakes questions to designated institutions. Discovery identifies nodes and their declared capabilities, without certifying their claims or requiring a single global registry. A federation membership directory may be useful, but its own admission and removal decisions require a governed process.
Assisted intake links the participant’s original account, its structured interpretation, the responsible interpreter, and the participant’s response under appropriate disclosure conditions. Each case has an assigned recipient, an addressable status, and an intelligible account of the next available step. These operational requirements implement the participation commitments in Sections 5 and 13.
Deployment Profiles
The first profile is a single governed node with local fixtures and a small schema catalog. Its value is a complete and inspectable path from submission through correction and reconstruction. The second profile adds external artifact custody while maintaining one authority boundary for admission. The third connects several autonomous nodes through scoped exchange manifests and explicit trust agreements.
Each profile has different failure costs. A single node simplifies consistent workflow admission while concentrating operational dependence. Federation supports local custody and institutional autonomy while increasing schema, availability, and authority coordination work. The architecture permits both profiles, and evaluation should identify the smallest arrangement adequate for a domain’s actual preservation questions.
Knowledge Evolution and Historical Reconstruction
Historical reconstruction serves inquiries into the grounds of a claim, the information available at a decision, and the institution’s response to later criticism. This section specifies the changes needed to support those inquiries through admission, withdrawal, revision, branching, and replay. The formal model identifies the coordinates of a reconstruction; the accompanying discussion explains how they relate to evidentiary interpretation, practical consequences, and the permitted retention of historical material. Complete operational rules are recorded in the accompanying formal specification.
Admission and Atomic Commit
A submission contains candidate records and operations together with a claimed principal and parent frontier. The service resolves its schema dependencies, validates immutable identities and payload types, authenticates the submitter, and evaluates authority against the trusted pre-state. All operations are accepted together or none become admitted domain history. A separate protected audit record can describe a rejection without making the rejected assertion an accepted part of the knowledge view.
This boundary permits forward references among jointly declared records while preventing self-authorization. A transaction can introduce a policy descriptor as domain content; it cannot use that new content to establish the authority required for its own acceptance. Delegation, trust anchors, and effective policy come from the separately governed control plane. The resulting receipt binds the evaluated parents, schema and policy profiles, command identities, and accepted effects.
Temporal Applicability and Record History
An assertion carries the interval over which its speaker claims that the description applies. A commit identifies when that assertion enters the accepted history of a node. Occurrence time and observation time can be fields of the described Event or Process. These coordinates support retrospective correction without pretending that the infrastructure received the correction earlier than it did.
For a commit c, let H be the admitted commit graph. Equation 1 defines the history cut selected by c.
Every query that claims historical reproducibility names such a cut, or a federation manifest defining several compatible cuts. A local receipt sequence can support a convenience mapping from a wall-clock time to a stored cut. That mapping must identify its clock and node assumptions. A federated application cannot replace this contract with an unqualified timestamp and infer that all nodes shared the same state.
Withdrawal, Revision, and Synthesis
Withdrawal targets one speaker’s exact assertion and a validity interval. At cuts containing the withdrawal, the target ceases to supply support within the intersection of those intervals. Independent assertions with equal content remain unaffected. Withdrawal supplies no automatic negative support. A speaker who denies the proposition can record a separate negative assertion with its own grounds and scope.
Revision creates a new description and an attributed relation to the prior one. A corrected dataset can retain its prior version as evidence where retention permits; a corrected interpretation can narrow the scope of an earlier claim without changing the underlying observation. Synthesis creates an additional knowledge object and identifies selected inputs, method, and responsible adopter. It can preserve a minority interpretation as a distinct branch even when a public document presents one institution’s chosen account.
These operations have different consequences for retrieval. A user requesting the current endorsed view may see the revision first. A user studying a decision’s history may need the withdrawn assertion and the information available at its original cut. Interface ordering is therefore a presentation policy with explicit scope, rather than a destructive rewrite of history.
Withdrawal of epistemic commitment, withdrawal of permission, and removal of a harmful public representation address different relationships. A speaker may cease to endorse a claim while allowing its retention for historical inquiry. Conversely, a restriction on personal information can change its availability while leaving the institution’s assessment of an occurrence unresolved. A lifecycle decision should therefore name the assertion, payload, permission, or operative finding it affects. Its implementation must also identify dependent summaries and indexes within the institution’s control. Retaining a history of the decision can support accountability where permitted, although disclosure of that history requires its own assessment. This separation connects the formal operations to the information-rights analysis in Section 5 without reducing a remedy to a change of logical polarity.
Branch Merge and Workflow Conflict
A knowledge merge unites compatible admitted histories and recomputes support from their assertions and withdrawals. It preserves opposing speakers and causal lineage. The merge operation does not determine which interpretation is correct. A separate finding or synthesis can express an authorized resolution within a specified domain, while the source assertions remain addressable where disclosure permits.
Operational state has a stricter condition. Two branches can each consume the same review token and produce different outputs. Their union leaves both outputs maximal. An ordinary advance requires one expected current token, so further dependent action pauses until an authorized resolution names and consumes the complete conflict set. Equal output labels also require review when they arise from different concurrent tokens; label equality alone does not establish that the actions were equivalent.
The core supports per-run invariants. Cross-run constraints, such as a shared release quota or mutually exclusive institutional commitments, need a declared coordination profile. Disjoint write sets cannot guarantee such constraints: two individually admissible transactions might each consume the final unit of a shared resource. A broader deployment must validate the merged candidate state or coordinate before accepting those operations.
Reconstruction and Replay Boundaries
A reconstruction depends on retained histories, interpretable schemas, the available payloads, and the requester’s current authority. Equation 2 expresses this dependency. Here D is the available dependency store, Gamma the pinned interpretation environment, and q the authenticated request at the current policy epoch Pi.
Equation 2 is a semantic dependency model rather than a mandate to materialize a privileged full graph in a public query process. Implementations can push authorization into storage and projection while preserving lifecycle effects. A hidden withdrawal reason, for example, must not cause its target assertion to become active again. Missing lifecycle data can instead make the relevant support unavailable.
Replay projects committed effects and decision receipts. It does not invoke recorded events, call an external model, repeat a release, or recompute past authorization using current rules. A later challenge to a justification can change epistemic support without undoing an earlier operational receipt. A reversal needs a fresh authorized compensation or resolution and an account of any consequences already outside the system’s control.
Full reconstruction remains conditional. Deleted payloads, lost keys, unavailable schemas, and restricted dependencies can prevent it. The service then returns a permitted partial view or an unavailable result. A retained digest cannot reconstruct erased content, and an intact ledger cannot by itself establish the accuracy of its historical account.
Historical interpretation also depends on how the retained events were selected and described. A reconstructed review state can establish that an institution recorded approval under a specified procedure. Whether the procedure gave affected people an adequate hearing requires examination of its practices and available evidence. Reproducible projection supports that examination by fixing the representation under discussion. It leaves room for later accounts of omitted experience, misclassification, or concealed conditions to revise the explanation of the same history.
Federation, Synchronization, and Cross-Domain Exchange
Federation connects institutions whose responsibilities, communities, and interpretive practices can differ. Its public purpose is to make relevant knowledge relations available across those boundaries while maintaining an account of the authority and obligations governing exchange. This section examines scoped manifests, receiver admission, query interpretation, and correction under partial delivery. The proposed protocol provides an operational contract within a wider institutional agreement; its guarantees are assessed against the scope of that agreement.
Participating institutions need to identify permitted purposes, the parties responsible for collection and subsequent processing, the conditions of downstream disclosure, and the procedures for correction and disagreement. Applicable law, community mandates, and contractual commitments can impose different constraints on the same exchange. A federation agreement should make those sources and their allocation inspectable, as developed in Sections 5 and 13. The arrangement also needs a process for responding when obligations become incompatible, including suspension of an exchange and referral to competent review. Local custody provides a useful technical boundary, while responsibility for a particular use depends on the decisions and relationships involved. The protocol’s node identifiers alone cannot resolve that allocation.
Scoped Manifests and Dependency Closure
An exchange manifest identifies the records, assertions, schema artifacts, and history fragments offered for a particular recipient and purpose. It declares required dependencies and the interpretation profile under which the packet was produced. The sender evaluates the release of the manifest itself, including identifiers and dependency existence. A protected source graph is never assumed to be an appropriate public export.
Dependency closure is a verification condition, not a demand for compulsory disclosure. A receiver needs enough permitted information to interpret the packet’s stated claim. Where original provenance is restricted, a separately authorized attestation may support a narrower claim. The receiver can then verify the attestation under a declared trust arrangement, while remaining unable to reproduce the underlying transformation. The interface should state that distinction directly.
Refusal to disclose can be a legitimate exercise of custodial responsibility. A node should be able to decline an incompatible request without its records automatically losing epistemic standing throughout the federation. Where permitted, a scoped response can identify the unmet condition and a review route. When even that explanation would expose protected information, the institution needs a confidential accountability procedure. Meaningful refusal also requires federation governance to review exclusion from shared discovery or services, since such exclusion could otherwise make formally voluntary exchange practically compulsory. A justified restriction and a finding about the truth of a claim remain distinguishable decisions.
Schemas require the same discipline. A reference to an unavailable artifact does not authorize a receiver to substitute the latest similarly named schema. It can defer admission, retain the packet as an uninterpreted transport artifact, or request an explicit compatible mapping. An optional annotation can remain opaque only when its absence cannot alter validity, authority, equality, or inference.
Receiver Admission and Delivery Semantics
Transport delivery has several stages: received, structurally checked, dependencies resolved, authenticated, locally admitted, and eligible for disclosure. A receipt from another node provides evidence under that node’s profile. Local acceptance requires an explicit decision that the profile and issuer are suitable for the intended use. Importing a remote Event never dispatches a local operational action.
The protocol permits duplicate delivery. A receiver deduplicates immutable packets by identity and canonical body and returns the original admission receipt where appropriate. A matching ID with changed content is quarantined. Delivery of a child before its parents leaves the packet pending until the required closure is available. Timeouts or failed requests create an explicit availability outcome; they do not establish that a claimed antecedent never existed.
Union of compatible admitted records is commutative and idempotent, but nodes can legitimately make different admission or disclosure decisions. Their visible views may therefore differ even after every permitted packet has been delivered. A convergence claim must state which admitted set, trust profile, schema interpretation, and authorization view are held equal. Semantic agreement among communities remains outside the transport guarantee.
Cross-Domain Mapping and Query Scope
A cross-domain mapping is a versioned transformation with an identified author, source and target schemas, method, and loss report. A mapping can translate a review label, align a contributor identifier, or derive a narrower statement from a locally detailed record. It should preserve the distinction between exact translation and interpretive approximation. Competing mappings can coexist as separate attributed processes.
A federated query carries a declared node set or discovery policy and obtains results tied to node-specific cuts. The response identifies the cuts actually used and the permissible scope of completeness. A node that cannot disclose its holdings may need to return an indistinguishable response across several internal states. Completeness metadata must therefore undergo the same disclosure review as the rows it accompanies.
The minimal profile avoids unqualified global aggregates. Combining counts across partial or overlapping domains requires a deduplication policy, compatible meanings, and an account of unavailable inputs. A result such as “four visible supporting assertions across these two supplied cuts” is well-defined under that scope. An unqualified statement that four supporting assertions exist in the knowledge commons would exceed the query’s evidence.
Correction Propagation and Membership Change
A correction propagates as a new attributed operation referencing its target. Receivers can update affected indexes and notify authorized consumers without erasing the original causal record. Notification is itself an operation with recipient, content, and permission conditions. A restricted correction can invalidate a public projection while its detailed reason remains available only to designated reviewers.
Membership change requires continuity procedures. A departing node can export permitted records, transfer custody, revoke operational credentials, and publish a scoped service-retirement notice. Other nodes retain their own responsibilities for previously received copies. Removing a node from a directory cannot recall its earlier disclosures or establish that all its historical assertions are false. The infrastructure must preserve the distinction between ending a service relationship and revising knowledge.
Governance Interfaces and Information Lifecycle
This section translates the justice and legal analysis in Section 5 into operational responsibilities. It specifies how purposes and authority govern authorization, derivation, contestation, and retention, and examines how remedies affect dependent services and third parties. The method traces each proposed interface to the interests it should protect and the institutional decisions it requires. Requirements R9–R12 in Table 2 extend the technical contracts to representational voice, independent review, rights protection, and practical continuity. The scoped legal discussion already establishes constraints relevant to these interfaces and grounds the account of institutional responsibility developed here.
Purpose, Authority, and Policy Formation
An operative policy requires a documented account of the activity it governs. The preservation decision identifies the information selected, its purpose, affected persons and communities, proposed uses, retention conditions, and the institution responsible for review. It should distinguish an applicable legal requirement from a contractual undertaking, a community mandate, and an additional ethical commitment. This distinction connects rights protection to a source of authority that a reviewer can examine. It also identifies whose interests require consideration even when those people neither contributed the record nor operate the service.
Policy formation must address relationships as well as payloads. A dataset’s collection may serve one inquiry, while an inferred affiliation or a public profile creates another consequential use. The institution should assess whether the new purpose and information flow are justified before installing rules that permit them. A machine-readable purpose identifier supports enforcement and auditing once its interpretation has been established. The identifier alone establishes neither the factual purpose of an operation nor the legal adequacy of its asserted basis. Operators consequently need documented processing boundaries, approved classes of use, and a route for reviewing new combinations or material changes in purpose.
The constitutional and review arrangements in Section 13 govern the installation and amendment of these policies. The corresponding operational record binds the policy version to its issuer, effective interval, delegation, and review conditions. Technical control of an administrator credential provides the ability to install a rule, while the justification for exercising that ability depends on the institutional process. A dispute about the issuer’s mandate should therefore reach that process and cannot be resolved solely by showing that the issuer signed the rule correctly.
Operation-Specific Authorization
An authorization request identifies principal, operation, target scope, purpose, relevant context, current policy epoch, and credential evidence. Operations include read, query, assert, withdraw, derive, advance, resolve, export, seal, erase, and declassify. A general declaration that material is open or restricted is insufficient to determine every operation: a domain may permit local analysis while controlling identity disclosure and redistribution. Requests involving several records also identify material restrictions and third-party interests associated with the proposed combination. A contributor’s authority to export their contribution does not automatically settle the disclosure conditions of other people’s testimony attached to it.
The proposed decision interface returns permit, deny, indeterminate, or not-applicable. Only an effective permit authorizes a protected action. Under the minimal combining profile, applicable denial overrides permission and missing mandatory authority evidence produces indeterminacy. A different combining rule requires an explicit profile. The requester’s source text cannot select a more permissive decision procedure. These are rules for the service’s execution boundary. A denial-overrides profile does not establish that every asserted prohibition deserves legal or normative priority. The profile applies to policies that the institution has recognized as applicable; disagreements about that recognition require escalation to a competent reviewer. Indeterminacy should produce an intelligible status and referral route, with explanation limited where necessary to protect confidential evidence.
The decision receipt binds its principal, operation, targets, profile, policy epoch, conditions, and reason. Preconditions must be discharged before execution. Post-operation obligations require a monitored process, an accountable role, and evidence of completion. ODRL provides an antecedent for expressing permissions, prohibitions, duties, and policy profiles (World Wide Web Consortium 2018); an operative decision still requires a competent issuer and an enforcement boundary defined by the deployment. An obligation’s receipt should distinguish scheduling, attempted performance, acknowledgment, and verified completion. Issuing an instruction to notify a recipient is different from establishing that the recipient corrected its copy. Material policy changes before execution require renewed evaluation under the transaction profile. Historical permission remains evidence about the earlier decision; present processing depends on the currently effective conditions.
Derived Information and Disclosure
The disclosure service evaluates the information released by an operation, including its metadata and explanation. In a simple audience model, a derived artifact’s audience must be compatible with the audiences of its required inputs and rules. Purpose or time restrictions may further narrow that compatibility. Public availability of one input does not authorize a combined release of all inputs. The relevant release includes query counts, identifiers, rankings, explanations, and reusable caches where these expose information. A policy that protects a source while allowing an unrestricted explanation of every dependency may disclose the very relation it was intended to protect. Such effects connect the disclosure interface to R11’s purpose and rights requirements.
Declassification is an explicit transformation with independently verified authority. It can produce a public aggregate, a reviewed explanation, or an attestation whose release conditions differ from the protected source. The receipt identifies what was released and the approving process. Merely renaming a source or removing a label does not establish a valid release. An aggregation procedure also needs its own privacy analysis before any mathematical privacy guarantee can be claimed. The institution should assess effects on people described in the output, including those whose data were never directly supplied to the service. An apparently harmless combination can create a consequential classification, and the people classified may have a stronger interest in review than the person requesting the query. Disclosure review consequently identifies the intended audience, likely onward use, attribution conditions, and means of seeking correction. Where purposes or protected interests conflict, the service can route the request for a reasoned decision instead of inferring permission from the derivation’s successful execution.
Integrity labels remain independent from confidentiality. A public assertion may be low-trust, while a confidential receipt may be authoritative for a specific operation. Inference can use permitted low-trust content to report what has been asserted without treating that content as a credential. The distinction is especially relevant for imported assertions and AI-generated proposals whose readability can otherwise be mistaken for operational authority. Derived publication also creates a maintenance responsibility. A service that publishes a synthesis should retain enough permitted dependency information to assess later corrections and policy changes. The required information depends on the consequence of the synthesis and the permitted retention scope. Maintaining this connection supports subsequent correction while avoiding an indiscriminate collection of sensitive internal activity.
Contestation, Correction, and Appeal
A contestation interface accepts an identified target, grounds, requested remedy, and evidence under suitable disclosure conditions. It can address a factual assertion, attribution, mapping, access decision, or institutional finding. The target’s type determines the appropriate review process: a correction of a file hash differs from a dispute about conceptual ancestry or community authority. Requirement R9 extends contestation to the categories used to encode an account. The service distinguishes challenges to wording, classification, and downstream interpretation, preserving the object of each requested remedy.
The review record should distinguish submission, admissibility, notice, response, provisional measures, finding, and appeal. Its conclusion identifies the scope of the decision and the operator responsible for implementing it. An institution can require a correction in the records it controls while leaving a broader historical interpretation open to further evidence. A public finding should retain that boundary in downstream exports. The review body specifies its competence, the evidence relevant to the claim, and the standard applied. A sound content-integrity check can settle a technical discrepancy while leaving the authenticity, interpretation, or legal effect of the underlying evidence unresolved. This distinction connects the evidential analysis in Section 5.9 to the review record without prescribing a universal standard of proof.
Procedural access follows the assisted-intake contract in Section 8, supported by the participation resources specified in Section 13.3. A consequential access or classification decision should have a route to a reviewer with sufficient independence from the original decision-maker. Section 13 specifies the proposed allocation of competence and escalation. Interim restriction may protect a vulnerable participant or contain an ongoing disclosure, while its scope, expiry, and review remain explicit. Finality rules may limit repetitive reopening under published grounds, preserving a route for materially new evidence and procedural error.
A finding should produce a remedial plan identifying affected assertions, indexes, profiles, derived artifacts, and responsible operators. Corrective processing can include recalculation, qualified republication, restriction, or deletion as appropriate to the decision. The plan distinguishes changes within institutional control from notices addressed to independent recipients. Completion records should identify outstanding effects and explain relevant limits to the claimant. A remedy affecting another person’s contribution requires consideration of that person’s interests and an appropriate opportunity to respond. The success condition for R10 is an effective, reviewable response to the harm, extending beyond the presence of a complaint record.
Retention, Sealing, and Erasure
The information lifecycle distinguishes support withdrawal, access restriction, sealing, payload erasure, key destruction, and ordinary loss. Each action has different effects on what can be inferred and reconstructed. A record can remain historically admitted while its payload becomes unavailable. A withdrawn assertion can remain available for historical inquiry. Conflating these states would make both correction and privacy controls unreliable. Retention is governed by the justified purpose and applicable obligations identified in the preservation decision. Review points should permit a change in purpose, evidence, risk, or institutional capacity to trigger reconsideration. The GDPR example in Section 5.6 demonstrates why a deployment needs qualified decisions about research retention, restriction, and erasure. An archival designation cannot itself determine the outcome of every rights request. The interface should record the governing basis, decision scope, and review route without requiring public disclosure of protected details.
An erasure plan identifies controlled replicas, indexes, caches, backups, derived artifacts, and known exports. Its receipt records performed actions and outstanding dependencies using only permitted detail. A public tombstone requires an independent disclosure decision because an identifier or digest may reveal sensitive participation. The operator should describe its effective control over copies without promising recall of information already held by independent recipients. Payload deletion also requires examination of the remaining record. A digest can permit comparison against known material, and a persistent identifier can preserve a sensitive association. Destroying an encryption key has a different operational meaning from demonstrating that identifying information has ceased to be reasonably recoverable in the relevant context. Consequently, the plan must evaluate the information retained in receipts, relations, and backups, as well as the principal artifact. A minimized account of the intervention may remain useful for accountability where its continued retention and access are justified.
Current policy governs present access to past cuts. Historical permission receipts remain evidence of what the service decided at the time; they do not grant permanent access. A reconstruction can consequently preserve semantic history while providing different permitted views to different requesters. The architecture must state those view conditions whenever it claims reproducibility. Retirement or transfer adds the continuity dimension of R12. A successor must receive an intelligible account of permitted custody, pending remedies, retention commitments, and effective credentials. A transfer of files alone would leave those responsibilities unassigned. Where a suitable successor or lawful continuing purpose is unavailable, controlled retirement should preserve an accurate description of the remaining service and evidence, subject to the same disclosure conditions. Governance history consequently records both the growth of the knowledge infrastructure and the limits of its continuing authority to preserve and use information.
Interoperability and Incremental Adoption
Adoption depends on whether a community can obtain useful preservation and review capabilities within its existing practices and resources. This section examines repository adapters, mapping fidelity, AI-assisted annotation, legacy interpretation, and exit. The incremental method connects each integration to a specified inquiry and makes the resulting redistribution of interpretive and maintenance work part of the adoption decision.
Repository and Workflow Adapters
An initial adapter can retain an existing repository’s artifact identifiers, version references, and available contribution history. It then creates attributed descriptions of selected semantic changes, such as evidence added, interpretation narrowed, or source corrected. The extraction method is itself recorded. A file difference may identify changed text while leaving the reason for that change unknown; an adapter should preserve that uncertainty rather than generate an unsupported intent claim.
A review-system adapter can connect comments and decisions to the claim or evidence they concern. Domain participants can initially supply a small number of semantic annotations around important transitions. Automated extraction can propose further links for review. This approach makes adoption contingent on useful preservation questions, avoiding a requirement that every contributor learn the full formal language before participating.
The infrastructure may delegate persistent publication identifiers to durable external providers. Its internal IDs support immediate graph reference and local history, while mappings to public identifiers preserve the distinction between an evolving record and a published artifact version. Creating a new global identifier or publishing institution is a separate stewardship decision with costs beyond the language design.
Structured Exchange and Mapping Fidelity
A graph adapter represents assertions as addressable resources containing speaker, polarity, context, validity, and evidence. An optional accepted-view graph must declare the evidentiary policy that selected its content. Exporting all recorded relations as unqualified assertions would change the meaning of the source corpus. Round-trip tests should therefore compare proposition keys, attribution, intervals, and lifecycle behavior, rather than only the number of triples retained.
A query adapter preserves set semantics where the language requires distinct tuples and identifies its entailment regime. A provenance adapter preserves the attribution of alleged derivations. A typed JSON envelope supplies a portable exchange boundary, with exact quantities represented independently of floating-point conversion. The selected canonicalization profile follows JCS (Rundgren et al. 2020); implementation must validate the complete profile before claiming interoperable signatures or digests.
The loss report is part of the adapter output. It states which temporal, workflow, context, or policy distinctions were preserved, approximated, or omitted. A receiver can reject a lossy transformation for a sensitive task while accepting it for a simpler discovery view. Semantic adequacy is therefore evaluated against an intended use, with the source retained where permitted.
AI-Assisted Annotation and Intellectual Genealogy
An AI-assisted adapter can propose relations between a document and earlier claims, methods, or contributions. Evaluating these relations requires the distinctions among operational, evidentiary, and intellectual provenance developed in Section 4. A digest can establish the identity of retained input; an invocation log can describe an operation. An assertion of conceptual ancestry additionally requires an interpretation of how an idea was transmitted, reformulated, or independently developed. Shared wording or an earlier timestamp can inform that inquiry while leaving its conclusion open.
An adopted genealogical link should therefore identify the proposed relation, the relevant passages or other grounds, the method used to propose it, and the person or institution accepting responsibility for its use. A contributor should be able to dispute the link, its description of their role, or the priority inference drawn from it. Several interpretations can coexist, such as direct influence and independent convergence, pending further evidence. These annotations can enrich a knowledge trajectory while remaining distinguishable from authenticated file lineage. Adoption should prioritize links useful for attribution, criticism, or further inquiry and provide the review capacity their generation requires.
Legacy Import and Schema Evolution
Legacy records often lack exact timestamps, explicit speakers, or stable versions. The import process should distinguish observed metadata from an importer’s reconstruction. An unknown occurrence time can remain unknown, and an attributed inference can propose a bounded interval with its evidence. Such reconstruction is a knowledge contribution with its own provenance.
Schema evolution requires an immutable old artifact and a new interpretation artifact linked by a versioned mapping. A migration can fail for some records, produce multiple alternatives, or lose distinctions. Those outcomes must remain inspectable. A deployment should test historical queries before and after migration and preserve the ability to identify which schema produced each view.
The adoption decision should also consider abandonment. A schema catalog needs custody succession; a module whose only interpreter disappears can make retained bytes operationally inaccessible. Human-readable schema descriptions, test fixtures, and permitted exports reduce this dependency, though they do not eliminate the cost of maintaining interpreters and mappings.
Portability and Exit
Portability includes permitted content, schema artifacts, provenance, withdrawal masks, and enough receipts to interpret accepted operations. A content-only export can preserve documents while losing the meaning of their later corrections. A full internal export can disclose more than the departing participant is entitled to obtain. The exit contract must therefore specify both semantic sufficiency and disclosure limits.
Exit also requires a usable destination and assistance proportionate to the participant’s dependence. An export that demands unavailable expertise or loses the visibility of pending corrections offers limited protection against institutional domination. The adoption agreement should therefore address migration support, resolvable identifiers, continued access to permitted case records, and the handling of unresolved responsibilities. These conditions connect technical portability to the institutional continuity discussed in Section 13.
An institution planning adoption should identify a successor custodian or a controlled retirement path. Transfer records identify the responsible parties, retained obligations, unresolved disputes, and availability changes. These procedures make institutional durability part of the architecture’s operation, with explicit limits where no successor can be found.
Institutional Governance and the Political Economy of Participation
This section develops the institutional arrangements through which a generative relational infrastructure could acquire, exercise, and retain public authority. The analysis proceeds from the distribution of decision powers to the constitution of rules, participation and review, material support, and succession. Its method is institutional design reasoning: the proposed arrangements are assessed against identifiable mechanisms of exclusion, dependency, and concentrated control. They remain hypotheses for deliberation and empirical assessment. The normative considerations in Section 5 supply reasons to constrain infrastructural power; the present section examines the organizational capacities those constraints require. An executable policy can determine whether a service permits an operation, while the legitimacy of installing that policy depends on a different institutional process. Preserving this distinction is essential to the infrastructure’s claim to serve public knowledge.
Public Purpose and Polycentric Authority
The allocation of authority begins with the objects and populations affected by a decision. Public knowledge infrastructure supports multiple publics: contributors seeking recognition, communities represented in records, researchers evaluating evidence, institutions maintaining collections, and people affected by downstream classifications. Their interests can diverge. Open access benefits inquiry, whereas publishing the identity of a vulnerable source can undermine participation. Shared terminology facilitates exchange, whereas a compulsory vocabulary can make a local account unintelligible on its own terms. A public purpose consequently requires a defensible procedure for addressing such differences and an account of whose interests receive standing. The UN’s DPI safeguards initiative provides a relevant policy antecedent by treating public infrastructure through technical, normative, and organizational dimensions and by addressing safety and inclusion across its lifecycle (United Nations 2024). Application to knowledge governance requires an additional argument about epistemic authority and represented persons; the framework’s existence alone supplies no endorsement of the present design.
Ostrom’s analysis of polycentric governance identifies the significance of multiple centers of decision making, institutional arrangements fitted to local conditions, accessible conflict resolution, and participation in rule modification (Ostrom 2009). The analogy needs care. Copying a disclosed assertion generally leaves that assertion available to others, while natural common-pool resources frequently face subtractive use. For this project, the principal shared constraints include reviewer attention, maintenance capacity, secure custody, and the willingness of participants to entrust knowledge to institutions. Polycentricity is therefore a proposal for organizing differentiated competences under interdependence, with local capture and coordination costs remaining open concerns.
At the community level, participants can develop representational conventions, identify sensitive relations, and specify how their testimony enters a record. A community’s internal diversity requires routes through which members can challenge the spokesperson or custodian claiming to represent them. At the domain level, a repository or disciplinary consortium can establish admission standards and issue findings within its collection and declared expertise. At the federation level, participating institutions can coordinate exchanges, credential recognition, correction notices, and review across nodes. A federation needs an explicit delegation before it can require a member to change an institutional representation. The geographical reach of its service and the number of records it indexes establish neither general jurisdiction nor authority over every person described in those records.
The proposed distribution of functions appears in Table 3. The table distinguishes competence from institutional form: a small deployment can combine several functions, provided that contested decisions retain an independent route of review.
| Institutional function | Decision competence | Review route | Scope boundary |
|---|---|---|---|
| Community representation | Local vocabularies and participation arrangements | Members’ challenge and external referral | Representation remains contestable |
| Domain stewardship | Admission, custody, and scoped findings | Independent domain review or agreed referral | Authority follows collection and mandate |
| Federation coordination | Exchange rules and member commitments | Cross-node panel and charter review | Recognition follows explicit delegation |
| Constitutional governance | Purpose, representation, reserved powers, amendment | Public reasons and periodic constituent review | Routine administration cannot amend the charter |
| Independent review | Procedural complaints and assigned appeals | Reconsideration under published grounds | Review competence and remedies remain bounded |
Coordination can still require common decisions. A correction that affects several collections needs an institution able to identify responsible implementers and track responses. The federation could issue a scoped notice under membership commitments, while each member selects an appropriate implementation in its own systems and records material deviations. An independent archive remains free to evaluate the notice under its own mandate. The resulting disagreement belongs in the public record. A uniform transport protocol can carry heterogeneous recognition decisions without disguising them as a single universal finding. Escalation should be justified by cross-domain effects, conflicts of interest, or inadequate local remedies, since automatic central review of every objection would undermine both local competence and institutional capacity.
Constitutional Rules and Policy Installation
The distinction between constitutional decisions and routine administration specifies how the infrastructure obtains the rules it subsequently executes. A deployment charter should identify its public purposes, represented constituencies, delegated powers, amendment procedures, and limits on disclosure and exclusion. These choices govern the conditions under which ordinary admission and review can be legitimate. A change in the definition of eligible participants, the availability of independent appeal, or the permitted sale of custodial assets consequently demands broader scrutiny than an update to a file-format validator. Constitutional importance follows the practical effect of a change, including changes presented as technical maintenance.
Policy installation should preserve an intelligible institutional chain: a proposal and its expected effects; notice to affected constituencies; reasons and responses; a decision by the authorized body; and a bounded delegation to the operator implementing it. The machine-readable record identifies the resulting policy version, effective time, affected operations, and review conditions. The constitutional proceeding also needs a readable explanation of what participation and disclosure will change. Source code can demonstrate the behavior of a policy while leaving its allocation of power difficult for participants to assess. Testing that behavior and deliberating about its acceptability perform complementary functions.
The distinction has a specific consequence for the social-fact language. Recording an assertion that an organization owns a collection, that a person is its founder, or that a community has authorized disclosure cannot by itself install the corresponding permission. The asserted relation may be contested, outside the issuer’s competence, or relevant to only a limited operation. An authority registry therefore requires its own admission procedure, with delegations checked against the charter and applicable institutional context. The registry contains evidence of recognized authority and its scope; institutional justification remains open to review. Cryptographic signatures identify participating credentials and protect record integrity, while the validity of an appointment or the representativeness of an organization requires additional evidence.
Emergency powers expose the costs of this separation. A credential compromise may require immediate suspension of new operations before a representative body can meet. The charter can authorize a narrow temporary intervention, specifying the responsible role, preserved evidence, expiration conditions, and subsequent review. Review should assess both the original grounds and the effects on affected participants. An administrator’s continuing ability to extend the exception would otherwise convert temporary protection into an alternative amendment procedure. Older receipts should remain associated with their historical authority conditions, while new access decisions use the currently effective policy. This arrangement supports both timely containment and examination of whether the institutional response exceeded its mandate.
Representation and Effective Participation
Participation concerns the distribution of practical opportunities to influence representation and governance. A contributor electorate has useful knowledge of infrastructure operation, yet contribution volume provides an incomplete basis for representation. People described in records can experience serious consequences while lacking accounts, affiliation, spare time, or fluency in the infrastructure’s working language. The proposed constituency therefore includes materially affected persons as well as active contributors and operators. Identifying such persons is itself a revisable institutional judgment, especially for collective histories whose effects cross generations and boundaries.
A possible arrangement combines elected contributor and steward representatives with representatives of affected communities and independent public-interest members. The charter would specify selection, terms, disclosure of interests, removal, and the means of challenging a representative’s claim to speak for others. Reserved representation can protect interests that an undifferentiated majority overlooks, but permanent seats can also stabilize unaccountable spokespersons. Periodic constituency review and accessible member challenges are therefore part of the same design choice. Financial support, institutional prestige, and the production of many records should confer neither additional case votes nor a permanent appointment privilege.
Participation also has material conditions. Translation, assisted submission, accessible evidence summaries, compensation for substantial governance work, and protected channels for vulnerable participants require explicit resources. Requiring participants to encode objections directly in the DSL would make formal competence an admission barrier to public accountability. An assisted submission should preserve the participant’s original account, the formal interpretation made by an intermediary, and the participant’s opportunity to correct that interpretation. This preserves a route to challenge the translation between lived experience and an institutional schema.
Representative rulemaking and evidentiary judgment require different procedures. Participants may collectively decide which questions a collection will prioritize and which review safeguards it will fund. A vote about those priorities supplies limited grounds for deciding whether a particular historical occurrence took place. A review body must explain its assessment of the relevant evidence even when its conclusion is unpopular. Conversely, specialist knowledge of evidence does not entitle reviewers to settle the infrastructure’s public purpose. This division gives democratic participation a determinate object while preserving the possibility of expert criticism and minority dissent. An operative decision can coexist with a retained dissenting account, with each carrying its issuer, grounds, scope, and status.
Review, Evidence, and Proportionate Intervention
The review system connects the availability of a challenge to the possibility of an effective, reasoned response. Its object can be an attributed assertion, an evidentiary assessment, a schema mapping, a disclosure decision, or the conduct of the operator itself. Routing follows that object. A person alleging that a custodian altered an attribution should have a channel outside the custodian’s exclusive control. A person challenging the wording of an institutional finding requires access to the issuing body’s procedure and to any independent appeal promised by its charter. A technically valid submission receipt establishes that a request was received; meaningful review additionally requires authority, resources, and a responsible recipient.
Review independence has organizational and evidentiary dimensions. Appointments, case assignment, funding, and publication of findings should be protected against control by parties whose interests are implicated. Reviewers need conflict disclosures and recusal procedures, and an institution named in a complaint should have limited discretion over appointing the panel that reviews its own conduct. A shared review pool can assist small organizations, although repeated reciprocal appointments can reproduce the same conflicts at federation scale. Rotation, published selection procedures, and referral outside the immediately involved network offer safeguards whose effectiveness would need evaluation. Confidential evidence can be inspected through an authorized independent channel, accompanied where possible by a usable summary and an opportunity to challenge the inference drawn from it.
Evidentiary weighting should be specific to the proposition under review. An authenticated timestamp can strongly support the recorded availability of a document while leaving its conceptual originality uncertain. Repeated citations to a single source should remain identifiable as dependent support. A participant’s testimony may illuminate experience that an institutional archive omitted, with credibility assessed through relevance, context, corroboration, and limitations. The absence of a retained record warrants particular caution where recordkeeping was selective. Reviewers should explain which inferences the evidence supports and where alternatives remain viable. A universal credibility score would obscure these differences and invite reuse of a ranking beyond the context in which it was justified.
The grounds for intervention and the strength of a remedy should also be separated. A plausible disclosure risk can justify a temporary restriction while a fuller inquiry proceeds. An incomplete priority claim may call for qualification or additional provenance. A supported finding that metadata misidentifies a contributor can justify correction in records under the institution’s control. The appropriate response depends on expected harm, evidentiary strength, reversibility, and the effects on third parties. The design should retain the original finding, the operative measure, its implementation, and later revisions as distinct records. An appeal can suspend a measure when continued application risks serious harm, although automatic suspension of every correction would permit delay through repeated objections.
An unrestricted demand for full adjudication creates a competing injustice: participants with abundant resources could exhaust a review system through duplicative or abusive challenges. Published admissibility criteria can require an identifiable issue and explainable grounds, consolidate substantially identical submissions, and close repetitive proceedings subject to materially new evidence. Restrictions on a person’s future access need their own reasons, limited duration or review conditions, and an independent challenge route. Linguistic difficulty, unconventional presentation, or disagreement with a dominant interpretation provides an inadequate proxy for abuse. Priority setting should consider urgency and the consequences of delay, while preserving capacity for less visible cases. Aggregate reporting on waiting times, exclusions, reversals, and unimplemented findings can expose systematic disparities without publishing sensitive case details.
Continuing Supervision and Preventive Duties
Continuing supervision addresses consequential changes before an affected person must discover and challenge them. The proposed institution assigns a responsible steward to each active collection and consequential processing service. Its operating profile specifies review intervals, material changes that trigger reassessment, records needed for that review, and the authority available when an obligation is unmet. Relevant changes include the withdrawal of supporting evidence, a revised disclosure basis, loss of a dependency, changed model behavior, or an altered mandate of a participating custodian. These are proposed supervisory commitments; their legal sources and scope must be identified separately where a deployment asserts binding duties.
Dependency notices can identify conclusions that require reassessment, but the consequence of a notice depends on the use at issue. A steward may need to qualify a displayed finding, commission a review, suspend a particular reuse, or inform downstream recipients. Automatic detection can support this work under a declared profile; an incoming description does not itself acquire the authority to execute an operational change. Material decisions retain the reason-giving and review conditions established above.
Periodic review also examines whether continued retention serves its declared purpose, whether restrictions still have grounds, and whether participation and correction routes remain usable. Missed reviews should produce an escalation to a named role, with proportionate interim measures for the affected operation. The institution should record unresolved dependencies and failures of response. This continuing responsibility connects preservation to care for the conditions of later use, including circumstances in which the appropriate action is narrower collection or retirement.
Financing, Maintenance Labor, and Capture
The political economy of the infrastructure concerns which activities receive durable support and how resource providers can shape public authority. Benkler’s analysis of peer production identifies modularity, contribution granularity, and integration costs as important conditions of collaborative production (Benkler 2002). A generative record permits small contributions, such as a correction or contextual annotation, but sensitive review can require sustained case knowledge and coordinated judgment. The proposal therefore cannot assume that every necessary function will emerge from voluntary contributions. Its financial model must account for work whose public value remains high when its visibility and private rewards are low.
Jackson’s account of repair foregrounds maintenance and care in understanding technological continuity (Jackson 2014). Applied here, the analytical consequence is that preservation depends on recurring human and organizational work: resolving ambiguous identities, updating schema interpretations, answering affected persons, maintaining protected access, and repairing broken dependencies. A system that records the genealogy of celebrated contributions while omitting these activities would distort its own conditions of production. Contribution vocabularies should therefore permit acknowledgment of curation, translation, mediation, and maintenance where disclosure is appropriate. Acknowledgment should support recognition without requiring workers to expose confidential cases or produce exhaustive activity logs.
A plausible financing arrangement combines recurring institutional support, public-interest funding, and charges for additional services, with subsidized participation for communities lacking resources. Core correction and complaint channels need protection from payment barriers, since their users include people seeking relief from the infrastructure’s own representations. Additional service revenue can support operations, but revenue priorities should be examined for their effects on admission, search visibility, and review queues. The Principles of Open Scholarly Infrastructure provide concrete antecedents for transparent governance, sustainable operational revenue, explicit reserves, recognition of volunteer labor, and planned succession (POSI Adopters 2025). The present proposal additionally treats a budget for contestation and assisted participation as part of the cost of making public knowledge dependable.
Funding diversification alone offers incomplete protection against capture. Several sponsors may share an interest in minimizing corrections that affect their reputations. Publication safeguards, protected review budgets, disclosed funding conditions, and recusal rules therefore need to operate together. Resource allocation should be reviewable as a governance decision: funding more ingestion while leaving correction under-resourced changes whose records acquire durable authority. Expansion should consequently be paced against the capacity to maintain, contest, and appropriately retire what has already been admitted. This creates a defensible reason to limit coverage when available support cannot sustain the associated responsibilities.
Recognition and economic reward must also remain distinguishable from ownership of subsequent inquiry. Provenance can establish a person’s role in an intellectual trajectory while leaving later contributors free to develop, criticize, or independently reinterpret the idea under the applicable reuse conditions. Founder recognition should carry the scope of the historical finding; governing office should carry the scope and duration of an explicit appointment. Combining these relations would permit genealogical evidence to become an accumulating source of institutional control. The design therefore records attribution, compensation, custody, and decision authority separately. Such differentiation permits fair recognition of contributions while keeping the shared capacity for knowledge evolution available to successors and critics.
Continuity, Exit, and Responsible Retirement
Institutional continuity concerns the preservation of capabilities and responsibilities through organizational change. Publicly reusable code and exportable records improve the feasibility of succession, while practical continuity additionally depends on interpreters, domain knowledge, protected credentials, and people able to assume pending responsibilities. POSI’s provisions on accessible and preserved resources and an institutional living will supply relevant continuity commitments (POSI Adopters 2025). For this infrastructure, an adequate transfer also needs to identify unresolved challenges, commitments to sources, and the authority under which restricted materials can be handled. The recipient’s ability to store a collection provides only one component of fitness to succeed its custodian.
Succession planning should specify the assets and roles to be transferred, the criteria for an acceptable successor, the participants whose interests require consultation, and the conditions under which transfer must be refused. Open records may support continued public access, while restricted collections may require new authorization, continued sealing, or retirement. Historical delegations and keys should be retained as evidence where appropriate, with retired credentials disabled for future acts. A compromised key warrants assessment of the affected period and receipts; the compromise alone supplies limited grounds for judging the substantive truth of every associated assertion. Schema and interpreter retirement similarly calls for preserved versions, interpretation guidance, and migration evidence sufficient to explain changes in reconstruction.
Exit offers protection against institutional domination only when meaningful alternatives are available. A nominal ability to export data has little force if a dominant federation controls discovery, credentials, and the recognition of corrections. Portability should therefore include permitted provenance, schema definitions, identifiers or resolvable aliases, and review status alongside payloads. A departing member can continue its own institutional account, while other nodes retain properly disclosed evidence of past membership and findings. Departure does not establish that an adverse finding was false. Equally, continuing a factual record of membership should not become an instrument for imposing indefinite operational control over a former member. Exit changes prospective commitments within the terms of the relevant institutional arrangement and applicable law.
Responsible retirement can be preferable to an unsupported promise of permanence. An institution losing custodial capacity may need to stop new admissions, resolve or transfer urgent matters, and publish a bounded account of which services will end. Retention, sealing, and erasure choices require assessment of permitted custody and the interests affected. An archival withdrawal notice or tombstone can itself reveal sensitive participation, so its disclosure needs independent consideration. Retirement should leave future users an accurate account of available evidence and reconstruction limits. The public value at stake is continuity of responsible inquiry, including the capacity to acknowledge loss, uncertainty, and the end of an institution’s effective control.
Accountability Across AI and Service Dependencies
Accountability across service dependencies addresses the distribution of practical control when several organizations contribute to one consequential representation. A model provider, local deployer, retrieval service, source custodian, and institutional reviewer can each shape an AI-assisted account. The resulting division of labor can make failures difficult to investigate if every participant records only its own final output. Raji and colleagues propose internal algorithmic auditing throughout development, with documentation linking successive stages to an overall assessment (Raji et al. 2020). The present infrastructure extends the institutional question to relationships among autonomous operators and to the people represented in their outputs.
Each consequential transformation should identify the responsible operator, the service and version used where available, the permitted inputs, and the human or institutional decision that adopted the result. This attribution supports an inquiry into responsibility without automatically assigning legal liability or assuming that every earlier contributor endorsed the final representation. A downstream institution that chooses to publish a synthesis must maintain a route to question that publication even when a vendor controls the underlying model. Participants should receive a coordinated response through an accountable contact, with internal referrals retaining the case history and unresolved questions. Requiring the affected person to reconstruct the entire commercial and technical chain would transfer the infrastructure’s coordination burden to the person seeking correction.
Service selection has constitutional implications when a provider becomes indispensable to interpretation, moderation, or discovery. Procurement should therefore consider evidence access, notice of material changes, incident cooperation, and the feasibility of replacement alongside performance and cost. A provider’s refusal to retain or disclose necessary evidence can limit the functions for which its service is suitable. The limit may require keeping consequential review within an institution possessing adequate access and competence. A human approval step provides meaningful oversight only if the reviewer has time, relevant evidence, authority to reject a proposal, and a working alternative when the automated service fails.
Institutional evaluation should consequently examine whether objections reach decision makers, whether explanations permit substantive challenge, whether corrections propagate through responsible operators, and whether dependency changes preserve those capacities. Logs, representative bodies, and audit reports supply evidence for such evaluation; their presence alone leaves the effectiveness of review unresolved. The governing commitments must themselves remain objects of generative preservation, so that later participants can reconstruct how authority was acquired, contested, revised, and relinquished. Public knowledge evolution then includes the institutions through which knowledge becomes publicly consequential.
Analytical Cases of Public Knowledge Evolution
This section examines the proposal through two constructed cases: a community environmental inquiry and a dispute about intellectual genealogy. The cases connect the representational, epistemic, legal, and institutional distinctions developed above to consequential decisions. Their method is analytical variation: the account follows a trajectory, changes an evidentiary or institutional condition, and examines which distinctions the architecture must retain for a defensible response. All persons, organizations, records, dates, and proceedings are hypothetical. The cases supply neither field evidence nor estimates of the proposal’s effectiveness. Their purpose is to expose failure mechanisms and test the coherence of the proposed response, including the limits that remain when records are complete. Institutional powers described below are assumptions of each constructed arrangement; they assert no general legal authority for an actual repository or public agency.
Community Environmental Inquiry and Institutional Response
The first case concerns a local association, a university laboratory, and a regional archive collaborating on a catchment study. Residents contribute accounts of intermittent changes in water appearance and use. The laboratory maintains a scheduled sampling program and publishes a technical assessment. The archive connects their records to a public map and explanatory summaries. Under an assumed voluntary charter, a joint board can fund additional monitoring, govern the map’s presentation, and commission independent review. It has authority over these activities and its own publications. A finding about their adequacy remains separate from any determination of environmental liability or exercise of governmental power. The case follows an initial classification dispute through contested evidence, provisional response, and downstream correction.
Classification, Testimony, and Evidential Scope
The classification problem concerns whether the inquiry can receive evidence outside its original collection conventions. Residents describe changes occurring after irregular overnight releases, whereas the initial laboratory schedule covers fixed daytime visits. The case assumes that several residents also describe disruption of customary activities without claiming a measured pollutant concentration. An initial intake schema offers only fields for instrument readings and accredited observers. Under that schema, relevant experience can fail admission before anyone assesses its interpretation. The exclusion originates in the definition of an admissible account and then affects the apparent completeness of the retained evidence.
The association therefore proposes a testimony type that preserves an account’s wording, uncertain occurrence interval, reported setting, and the intermediary who structured it. A resident can confirm the transcript while challenging its classification as an allegation of a specific discharge. These commitments require separate assertions. An account of a change, an interpretation of its cause, and a finding that the evidence warrants further investigation are different propositions. Connecting them makes disagreement intelligible without assigning them a common evidentiary status. A revised schema retains the earlier mapping as an attributable interpretive decision, with public exposure of sensitive content decided separately.
The laboratory’s measurements remain relevant within their sampling conditions. The residents’ accounts identify possible gaps in those conditions and supply grounds for a revised inquiry. Neither institutional affiliation nor the number of accounts determines the conclusion. Several reports could describe the same occurrence, while one well-situated account could reveal a material gap in the sampling schedule. The record therefore relates each assessment to the proposition under examination, the observation conditions, and known dependencies among sources. The review can recognize the residents’ standing and the laboratory’s methodological competence while requiring both to explain the inferences they draw. This implements the distinction between participation and evidentiary weight developed in Sections 2 and 5.
Contestation and Temporal Reconstruction
The temporal problem concerns the difference between when an assessment was recorded and the period to which its author applied it. Let Alice be the laboratory’s designated assessor and Bob a community reviewer. The disputed proposition states that monitoring program D has adequate temporal coverage for comparison under method M at specified sites. D identifies the program; its changing arrangements and observations have separate records. The claim concerns the adequacy of coverage for the stated comparison. It leaves causal attribution and broader safety conclusions to other inquiries.
At commit c0, received on 20 June, Alice endorses that proposition as a standing assessment applicable from 1 June. At c1, received on 1 July, Bob denies the same proposition with applicability from 1 June, citing omitted observation periods. Later records document additional coverage beginning on 1 July. At c2, received on 1 August, Bob withdraws his denial only for the interval beginning on 1 July. These operations are assumed admissible and public under the test policy. Alice and Bob use different record identifiers for the Relation, but its exact schema and complete field values coincide. The architecture consequently recognizes opposing assertions about the same qualified content.
Table 4 shows the resulting support states. A query at c0 for 15 July reports the standing assessment available at that cut; it establishes what Alice had committed to, with no claim that July observations were already known on 20 June. Bob’s later withdrawal also supplies no independent positive assessment. Alice’s assertion remains the source of positive support.
| History cut | Valid instant | Support | Interpretation |
|---|---|---|---|
| c0 | 15 July | Positive only | Alice’s standing assessment applies. |
| c1 | 15 July | Both | Bob’s recorded denial also applies. |
| c2 | 15 July | Positive only | Bob’s denial is withdrawn for this interval. |
| c2 | 15 June | Both | The withdrawal leaves the earlier disagreement intact. |
This trace makes a potential injustice visible: presenting c2 as evidence that the earlier challenge was unfounded would erase the continuing disagreement about June. The reviewer may accept improved coverage while maintaining that the initial report overstated its basis. The query therefore needs the history cut, applicability instant, assertion witnesses, and permitted account of the revision. If protected evidence prevents public reconstruction of the grounds, the interface should identify the limit of the available explanation. Preserving the distinction protects the intelligibility of both the criticism and the institution’s subsequent learning.
Protected Evidence and Provisional Institutional Action
The remedial problem combines urgency with uncertainty and unequal exposure. Assume that detailed testimony identifies residents who face a credible risk of retaliation within the case, while the public map still displays an unqualified assurance based on the initial assessment. The board commissions an independent reviewer authorized to inspect protected testimony and laboratory records. Public release is assessed separately. An explanation may identify the sampling gap and the basis for reconsideration without publishing households, exact reporting times, or sensitive relationships. A pseudonym alone would leave these relational disclosure risks unresolved.
The respondent laboratory must receive a sufficiently informative account of the challenge to answer it. If a proposed explanation is too vague to permit response, the institution must consider alternatives: protected access by an independent expert, a revised summary, corroborating evidence, or a more limited finding. A confidential assertion cannot automatically acquire decisive weight because a custodian certifies its existence. The proposed arrangement requires a reasoned assessment of what the restricted evidence supports and what procedural limits affect that assessment. The choice remains difficult where even a summary would identify the source; the architecture preserves the conflict and the decision’s scope while supplying no automatic resolution.
The board can meanwhile fund additional monitoring and temporarily replace the map’s assurance with a scoped statement that coverage is under review. These actions address a possible gap within the board’s assumed mandate. They leave causation and liability unresolved. Their justification considers the effects of continuing the assurance, the burdens of changing it, available alternatives, and the reversibility of the measure. The decision identifies an expiration or review condition, an implementer, and a channel for affected parties to object. Urgent institutional action is thus compatible with an evidentiary record that preserves several interpretations. Procedural authority determines which temporary action the board may take; evidentiary assessment supplies reasons for its exercise.
Concurrent review illustrates the technical consequence of these boundaries. Two authorized panels might independently advance the same review run from its initial token, one to supported and one to contested. Both receipts can be locally admissible. Their merge retains two maximal tokens, so an ordinary advance pauses until a competent resolver considers the complete conflict set. A resolution creates the operative workflow status and preserves the earlier receipts. It leaves the substantive source assertions available for separate assessment. Selecting the branch with more endorsements would bypass the declared decision procedure and confuse recorded support with institutional authority. The resolver’s decision can itself be appealed through the independent channel described in Section 13.
AI Synthesis and the Reach of Correction
The downstream problem arises when the archive’s hypothetical AI service compresses the reviewed material into a public summary. Suppose its first output says that the laboratory found no meaningful change and residents raised unsubstantiated concerns. The phrasing removes the coverage limitation, collapses testimony into causal allegation, and omits the board’s provisional decision. Logging the output would preserve those errors faithfully. The additional requirement is to connect the generated proposal to its selected sources and to the institution that adopted it for publication, so that each transformation can be questioned.
A successful challenge leads the archive to replace its summary with a scoped account of measurements, reported experience, the coverage dispute, and the review’s disposition. The correction identifies which inference changed and which earlier facts remain supported. The service records the revised output, source cuts, relevant method information, and responsible adopter. Known recipient nodes receive a permitted correction notice, with acknowledgment and implementation tracked separately. A recipient may have produced its own synthesis and must assess the affected dependency under its own responsibility. The issuing archive can report the reach of its correction without claiming that all independent copies or model representations have changed.
The record’s value consequently depends on presentation as well as retention. The corrected explanation should be discoverable where users encounter the earlier assurance. A preserved challenge that remains buried under the superseded summary provides limited practical relief. At the same time, disclosure review can restrict the historical payload while retaining enough authorized context to explain the revision. The case therefore joins genesis preservation to governed visibility, responsiveness, and the material work of implementing corrections.
Intellectual Genealogy, Attribution, and Independent Rediscovery
The second case examines the relation between reconstructing a contribution and allocating authority over subsequent inquiry. Assume that a small group developed a conceptual distinction in local workshop notes. Years later, a university team publishes a related formulation after using an AI assistant to organize its own analysis. A scholarly archive records the university publication as the origin of the distinction. A member of the earlier group challenges that description and supplies dated notes and testimony. The archive’s assumed charter permits it to revise its metadata and publish a scoped historical assessment. The case varies whether the available record establishes chronology, dependence, or independent development, then examines the consequences of each finding.
Chronology, Dependence, and Interpretive Equivalence
The historical problem begins with the propositions compressed by the word origin. An earlier inscription, first public dissemination, conceptual systematization, and later recognition can concern different contributors. The archive therefore represents the notes, publication, circulation events, and proposed conceptual relationship separately. A repository receipt supports an account of when a deposited artifact entered that repository. Additional evidence is required to assess an asserted earlier creation date and the meaning of the concept at that time. A finding about an earlier documented formulation must retain its scope when reused in a biography or synthesis.
Conceptual similarity also requires interpretation. The university’s term may match the workshop wording while functioning differently in its argument, or use different language for a substantially related distinction. Reviewers should identify the passages, contextual assumptions, and criteria underlying their comparison. The resulting mapping is an attributed assessment available for criticism. A revision can preserve the earlier group’s wording and the reviewer’s interpretation without requiring the group to endorse the later concept. This provides a richer account of intellectual development than a single earliest-author field.
The documented AI interaction gives a further, bounded source of evidence. Its retained prompt and output can show that the university team requested a particular comparison and adopted parts of the response. Suppose the earlier notes appear among the invocation’s retrieved inputs: that fact bears on the documented production process, while the role of the notes in the adopted argument still requires assessment. Alternatively, suppose the retained inputs contain no such notes and the team reports independent development. That absence establishes a limit of the available invocation record. It cannot settle every training influence, unrecorded encounter, or intellectual dependency. The archive can recognize an earlier formulation while leaving the relationship between the two trajectories indeterminate.
Recognition, Remedy, and Continued Inquiry
The remedial problem concerns what follows from a successful challenge. Assume that review supports the existence of the earlier formulation and finds the archive’s exclusive origin description unjustified. The archive can correct that description, connect the trajectories, acknowledge the earlier group’s documented contribution, and qualify claims about independence. It should also distinguish collective work within the group where the evidence supports several roles. A single founder designation could suppress the very collaboration the review recovered. Retained dissent can explain disagreement about the conceptual equivalence without preventing the archive from correcting an overstatement within its own record.
These findings supply no automatic authority over downstream research. Attribution, intellectual genealogy, licences concerning particular artifacts, and an appointment to editorial office have distinct sources and scopes, as Section 5 explains. A proposed policy granting the earliest recorded contributor a veto over every later derivation would therefore require an independent justification; the provenance graph alone could not install it. The earlier group may seek accurate acknowledgment and dissociate itself from the university’s interpretation. Later authors may criticize both formulations and propose another account while retaining accurate relations to the work they used. Preservation supports this continued inquiry by identifying the question each historical assessment actually resolved.
The university team also remains entitled within the assumed procedure to challenge evidence, explain independent work, and obtain a correction if an accusation exceeds the finding. A visible dispute marker needs a defined object and disposition so that temporary review does not become an indefinite reputational label. If further evidence later demonstrates direct dependence, the institution can issue a revised assessment and review relevant downstream descriptions. If that evidence remains unavailable, uncertainty belongs in the resulting account. Neither outcome requires rewriting the fact that an earlier procedure reached a particular conclusion on the evidence then available.
Design Consequences and Unresolved Conflicts
The comparison identifies the architectural commitments exposed by both cases and the questions that representation leaves unresolved. Attributed assertions and scoped mappings make the object of disagreement inspectable. Temporal reconstruction preserves the difference between a later correction and an earlier position. Separate authority records prevent evidentiary support from silently acquiring operational force. Differentiated disclosure permits a public explanation to coexist with protected evidence, and dependency records identify sites where a correction requires further action. These consequences follow from the constructed failure mechanisms; their practical effectiveness requires evaluation in institutions with actual participants and constraints.
Several conflicts remain substantive. Independent review needs resources and can still reproduce interpretive hierarchy. Confidentiality can limit an adversarial response. A provisional remedy can reduce one harm while imposing another. Scholarly uncertainty can coexist with a pressing institutional decision, and recognition can repair an omission while producing a new hierarchy. The infrastructure’s contribution is to preserve the relevant distinctions, responsible actors, reasons, and avenues of revision so that these conflicts remain answerable within public inquiry. The adequacy of that answer depends on the institutions using the record and the opportunities available to those affected by it.
Analytical Assessment and Evaluation Strategy
Assessment of a public knowledge infrastructure must address the adequacy of its distinctions, the justification of its institutions, and the consequences of its operation. This section assesses the proposal at its present stage and develops a strategy for the empirical work that remains. It first examines the argument through constructed cases and counterexamples, then defines comparative and participatory evaluations. Conceptual coherence, executable behavior, legal compliance, and public value require different forms of evidence. Success in one category cannot discharge the obligations of the others.
Assessment of the Conceptual and Normative Argument
The paper’s conceptual contribution can be assessed through distinctions whose removal changes an interpretation or decision. In the environmental case, combining occurrence, testimony, and institutional finding into a single fact status would make the authority of the assessor difficult to inspect. Combining record identity and assertion identity would obscure the difference between an available description and a particular participant’s commitment to it. Combining historical applicability with the date of recording would prevent a reader from distinguishing a later correction about an earlier period from the account available when the original decision was made. These are analytical reasons for preserving the distinctions. They establish neither that the chosen representation is uniquely adequate nor that participants will find its implementation intelligible.
The case analyses also identify differences that the formal core deliberately leaves to domain interpretation. Two statements may instantiate different qualified records while expressing claims that a community considers substantially equivalent. A translation may be structurally valid while misrepresenting its speaker. The ontology therefore requires a way to record contested mappings and contextual accounts beyond its proposition keys. The critical question is whether participants can make an inadequacy visible and obtain a response with consequences for the operative representation. The six-category basis is defensible as a common representational discipline only while its use remains compatible with that capacity.
The normative argument rests on a related conditional claim. If an infrastructure helps determine how an account becomes publicly credible and consequential, affected persons have grounds to demand intelligible procedures for contesting that treatment. Those grounds support the proposed arrangements for notice, representation, reason-giving, review, and remedy. They do not entail an unrestricted entitlement to publish any content, obtain every underlying record, or suspend collective action indefinitely. Restrictions require their own justification in relation to the interests affected, the available alternatives, and the authority taking the decision. The institutional proposal makes these justifications an object of governance.
The strongest consistency test arises when commitments conflict. Detailed provenance can improve accountability while exposing a vulnerable witness. Preserving dissent can support criticism while repeated abusive allegations increase the cost of participation. Local custodianship can protect a community while limiting an affected dissenter’s access to review. The design responds through differentiated disclosure, supported participation, reasoned restrictions, independent review, and explicit limits on preservation. These responses identify responsible decision processes. Their adequacy depends on institutional resources and actual outcomes. A design that recorded every conflict yet provided no feasible remedy would fail its own public purposes.
Available Technical Evidence and Its Limits
The formal-language package provides a bounded check on some architectural distinctions. Its grammar, type specification, temporal support semantics, workflow projection, exchange schema, and constructed examples make selected contracts precise enough to criticize. The performed checks cover syntax recognition, structural validation, and small semantic models. Appendix B records their exact scope. The semantic tests are separate oracles; they do not constitute an interpreter for the supplied source programs. There is currently no complete runtime, federation implementation, or field deployment.
The checks are relevant because representational errors can defeat normative intentions at the operational level. A hidden withdrawal that accidentally reactivated an assertion would undermine correction. An imported event that executed a workflow would let exchanged descriptions exercise local authority. A newly asserted permission that authorized its own transaction would collapse the distinction between describing power and legitimately installing it. Repairing such counterexamples makes the proposal more coherent. It supplies no evidence that the underlying correction policy, institutional mandate, or distribution of power is justified.
Formalization also exposes the limits of a result. Four-valued support retains positive and negative attributed support under specified coordinates; it does not measure evidentiary quality. Deterministic projection reconstructs accepted receipts given retained dependencies; it does not establish the fairness of the decisions recorded in those receipts. These limitations should remain visible in service documentation and interfaces. Evaluation should test whether users understand them, since a mathematically precise backend can still support a misleading public presentation.
Comparative Design and Institutional Baselines
A useful comparison must configure alternatives to meet the same substantive needs. One baseline should combine an existing repository with relational assertions, versioned schemas, and temporal queries. A second should combine RDF, provenance, validation, a query service, and an event ledger. A third should use a typed rule engine for the finite signed-support fragment. The comparison should document extensions, integration work, maintenance, interoperability assumptions, and the consequences of unavailable inputs. Existing tools may satisfy a domain’s requirements at lower cost. Such a finding would appropriately narrow the rationale for a dedicated language or additional infrastructure layer.
Institutional comparison is equally necessary. A well-supported archive with accessible staff, documented editorial decisions, and an effective appeals route may preserve consequential context more successfully than a richer technical system with weak stewardship. Conversely, a manual process may work within one institution while losing correction histories when records circulate. The relevant comparison therefore includes combinations of technology and institutional practice. It should assess the marginal benefit of additional structure relative to the labor and risk that structure creates. Claims of superiority based solely on feature counts would neglect this relationship.
Ablation studies can identify the contribution of individual distinctions. Removing attribution separation, explicit valid time, or immutable schema identity should change answers to specified competency questions. Removing review independence or participation support should be studied through institutional exercises rather than simulated as a missing database column. The methods differ because the causal mechanisms differ. Both forms of comparison should preserve adequate baseline resources and record the conditions under which results would generalize.
Participatory Evaluation and Consequential Outcomes
The first institutional study should involve a bounded inquiry with willing custodians, contributors, and affected persons, including people whose views could be represented without their having submitted records. Participants should help define the consequential questions and the costs they regard as acceptable. Domain expertise is needed to assess evidence; experience of exclusion is needed to assess whether the categories and procedures make that evidence accessible. Recruitment through the system’s existing administrators alone would provide a narrow view of participation.
An initial exercise can follow a disputed account through collection, translation, assessment, publication, challenge, correction, and downstream reuse. Participants should examine both ordinary use and cases in which a steward’s decision is itself challenged. Appropriate consent, confidentiality, and independent review of the research protocol are needed before undertaking research involving people or sensitive records. The constructed cases in this paper provide materials for planning such a study; they supply no observations about how any actual community would respond.
Table 5 relates the normative commitments to evidence that could support or weaken them. The indicators belong to an interpretive evaluation; they are unsuitable as a single score of institutional justice. Low appeal volume, for example, may reflect satisfaction, inaccessible procedures, fear, or lack of awareness. Short processing time may reflect efficient remedy or superficial dismissal. Interviews, observation, decision records, and participant review are needed to interpret the measurements.
| Dimension | Evidence to examine | Potential failure |
|---|---|---|
| Representational adequacy | Participant review of categories, translations, and consequential omissions | Valid encoding suppresses the substance of an account |
| Epistemic participation | Access to contribution, discoverability, and response to criticism | Dissent is stored but practically inaccessible |
| Procedural fairness | Reasons, assistance, time to remedy, independence, and implementation of decisions | Formal completion substitutes for effective hearing |
| Distribution of burdens | Time, cost, exposure, maintenance labor, and access to assistance across groups | Benefits accrue to consumers while contributors bear risks |
| Rights and disclosure | Scoped legal assessment, authorized access, retention actions, and protected review | Preserved metadata recreates an exposure |
| Institutional continuity | Budget, succession exercise, export usability, and ability to challenge rule changes | Dependence on a funder or custodian defeats accountable exit |
Evaluation should follow consequences beyond the database. A corrected record may leave an earlier public report, recommendation, or institutional decision unchanged. Researchers should examine whether notices reach relevant recipients, whether the correction changes later use, and who bears the work of obtaining those changes. The same applies to recognition: adding a contribution edge may have little value if attribution disappears in the interfaces and publications through which credit is distributed. Meaningful assessment therefore requires a specified follow-up period and an account of the downstream contexts the study can actually observe.
Generative Use and Further Inquiry
The proposal also requires an evaluation of the activity that gives generative preservation its purpose: developing further knowledge from a retained trajectory. A comparative task could ask participants to explain a change in an assessment, recover a discarded interpretation worth reconsidering, or formulate a qualified research question from a disagreement. Another task could ask for a synthesis that identifies both shared grounds and unresolved differences. Participants would receive the same permitted source materials, with different arrangements for accessing their contextual relations and histories. Baselines should retain the contextual information that their actual workflows would ordinarily provide.
The study should assess the grounds, qualifications, and traceability of the resulting interpretations as well as time and workload. Domain reviewers and relevant participants may disagree about whether an interpretation is useful; those disagreements should remain part of the findings. Producing more hypotheses or a longer account would not alone demonstrate improved knowledge. A persuasive result would show that the retained relationships helped participants identify consequential evidence, avoid an unsupported inference, or develop an inquiry with clearer grounds and limits.
AI-assisted conditions require additional attention to the relation between apparent fluency and evidentiary adequacy. A synthesis may become easier to read while losing an uncertainty or minority interpretation that mattered to the task. Comparing the adopted result with its available sources and subsequent criticism can expose that loss. Such a study would assess whether the infrastructure supports responsible knowledge development under the specified conditions. It would provide no automatic measure of originality or guarantee of progress across other domains.
Operational Robustness and Revision Conditions
Technical evaluation should measure reconstruction accuracy, attribution loss during exchange, query and migration cost, and failures of admission or disclosure controls. Fault cases include delayed dependencies, duplicated packets, changed bytes under reused identities, revoked credentials, stale policy caches, concurrent workflow advances, and unavailable evidence. Disclosure assessment must include identifiers, explanations, counts, errors, and observable control flow. Filtering visible result rows alone cannot establish protection against inference or existence disclosure.
The proposal should be revised when evidence shows that a distinction cannot be understood at reasonable cost, a governance role lacks credible support, or an ostensibly public process entrenches unequal power. Revision may involve simpler representations, narrower collection, a different distribution of authority, or abandonment of a proposed feature. These are substantive research outcomes. The present paper establishes an interdisciplinary design argument and a program for testing its consequences; claims of effectiveness remain conditional on the comparative and participatory work described here.
Discussion of Publicness, Authority, and Knowledge Evolution
The interdisciplinary proposal joins a representational architecture to an account of public institutions. This section examines the implications of that combination and the objections that remain unresolved. The discussion considers the meaning of publicness, the limits of historical preservation, the relationship between contestation and collective action, and the distribution of institutional power. Its method is argumentative: each objection identifies a condition under which a technically functioning system could frustrate the purposes developed earlier in the paper.
Publicness and Differentiated Access
Publicness cannot be reduced to the number of publicly downloadable records. The proposal locates it in the purposes served, the answerability of decisions, and the opportunities for affected persons to participate in governing the infrastructure. Differentiated access can support these purposes where unrestricted disclosure would expose witnesses or prevent contribution. However, restricted custody can also conceal favoritism, weak evidence, or arbitrary authority. An institution’s declaration that material is sensitive therefore requires a reviewable basis, a limited scope, and an account of the public explanation that remains possible.
The difficult case concerns a conclusion whose evidentiary basis cannot be made broadly inspectable. Protected independent review may provide a form of assurance, but readers must understand what the reviewers inspected, their competence and independence, and the limits of their conclusion. These arrangements distribute epistemic trust; they do not eliminate it. A public system should allow a reasoned challenge to the arrangement itself, including the selection of reviewers. Some conclusions may warrant a qualified or restricted use because the available assurance is insufficient for a more consequential use.
This account also distinguishes open infrastructure from open participation in every decision. A public institution can require expertise for a particular assessment while permitting affected persons to challenge the assessment’s framing or consequences. Expertise, affected standing, stewardship, and representation provide different reasons for involvement. Governance must explain how those reasons bear on a particular power. A universal membership vote would obscure the differences as readily as exclusive administrative control would ignore them.
Generative Continuity and the Limits of Documentation
The term generative expresses a capacity for further inquiry from retained relations and revisions. It carries no presumption that accumulating records produces epistemic or moral progress. Records can reproduce prejudice, encourage surveillance, and impose categories that later become difficult to escape. A longer history may improve the reconstruction of an error while also prolonging its practical effects. The value of continuity depends on selection, interpretation, and the ability to change how retained information is used.
An objection to the proposal is that its emphasis on addressable trajectories creates a presumption in favor of recording social life. Such a presumption would contradict its account of justice. The relevant preservation obligation is purpose-dependent and defeasible. Before collecting an account, a custodian should identify the inquiry served, the information necessary for that inquiry, the people exposed, and less intrusive alternatives. Some relationships should remain undescribed, some evidence should be kept under restricted custody, and some retained material should later be retired. The infrastructure must make these decisions possible without presenting an incomplete record as a complete history.
Historical absence also has several meanings. Material may never have been recorded, may have been lost, may be inaccessible, or may have been removed under a justified decision. Even disclosing which explanation applies can sometimes reveal protected information. A public response must therefore express its evidentiary limits at a level appropriate to the disclosure context. Complete public explanations of every omission are incompatible with some legitimate forms of confidentiality. Where review requires more detail, a separate protected channel may be necessary.
The resulting history is a situated resource for inquiry. It is never the full genesis of the knowledge it describes. Unrecorded teaching, background practice, tacit understanding, and relationships outside the collection can remain causally important. Provenance graphs should carry collection boundaries and permit contextual additions. Their apparent precision should not convert incomplete ancestry into a definitive account of contribution or responsibility.
Contestation, Closure, and Institutional Action
Preserving disagreement creates a further difficulty: public institutions often need to act while knowledge remains contested. Environmental protection, publication, and archival access cannot always wait for consensus. The architecture therefore separates epistemic openness from an operative institutional decision. A competent institution can adopt a provisional finding, explain its evidentiary standard, and authorize a bounded action while preserving contrary accounts and the conditions for reconsideration. The continued existence of opposition does not by itself invalidate the decision; the decision does not by itself settle the underlying truth.
This separation permits review without making every transaction indefinitely provisional. A procedure can specify the consequence of new evidence, the grounds for reopening a matter, and the treatment of repetitive or abusive submissions. Restrictions require reasons and proportionate means, especially where an institution might characterize inconvenient criticism as abuse. Administrative convenience alone cannot establish the legitimacy of a closure rule. Institutions need a route for challenging the rule and a means of protecting participants from retaliation.
The technical distinction between an assertion conflict and a workflow-token conflict gives this argument a precise operational consequence. Epistemic disagreement can persist in a query result. Incompatible operational states require a resolution before the affected process can continue coherently. The authorized resolution determines how that process proceeds. Resolution alone leaves source assertions intact; restriction or erasure requires a separately justified lifecycle operation. A change in workflow status cannot retrospectively make an unfair hearing fair. Repair of institutional harm may require renewed participation, revised decisions, compensation, or other remedies beyond a change to the process state.
Classification, Pluralism, and Common Representation
A shared formal language promises interoperability while creating pressure to standardize meaning. The six domain categories provide one structural basis for expressing people, relationships, states, properties, processes, and events. Their broadness allows many encodings; it also permits an apparently valid representation to omit the concepts that make an account meaningful to its participants. Formal extensibility therefore needs institutional counterparts: local vocabulary development, accountable translation, plural mappings, and a route for challenging the federation’s dominant schema.
The paper does not establish that this category basis is optimal across disciplines or communities. That claim requires comparative encodings and participant assessment. A successful counterexample might show that an important practice can be represented only through an unwieldy translation, or that the distinction between entity and process misdirects a domain’s attention. The appropriate response would be to revise the profile or its scope. Treating the formal scheme as a universal ontology would undermine the inquiry it is intended to support.
Legal pluralism intensifies this issue because apparent semantic disagreement can concern competing authority. A local rule, a community mandate, a contractual restriction, and a statutory obligation may apply to overlapping operations with different sources and consequences. Encoding each precisely does not determine which prevails. A federation needs arrangements for identifying conflicts, obtaining competent advice or adjudication, and limiting exchange where no acceptable resolution is available. Its technical membership agreement cannot independently settle those questions for every affected person or legal order.
Power, Maintenance, and the Cost of Accountability
The proposed institutions are resource-intensive. Classification review, translation, secure custody, appeals, and dependency maintenance require skilled work. An infrastructure can formally distribute authority while concentrating effective control in the organization able to pay for this work. Contributions by volunteers or vulnerable participants can become an unacknowledged subsidy for institutions that capture the benefits of reuse. These risks make financing and labor allocation part of the justice argument. Participation cannot be assessed only through formal eligibility.
Polycentric governance can distribute decisions and create alternatives to central control, yet it can also increase coordination burdens and leave participants uncertain about responsibility. The institutional design therefore couples local autonomy with named obligations, review routes, and succession arrangements. Exit is meaningful only if participants can obtain usable records and sufficient context, and if dependent public interests receive appropriate continuity. A theoretically available export that requires unfunded reconstruction offers limited protection against dependency.
An additional risk is procedural legitimation. A detailed audit trail can give an unjust institution the appearance of accountability. The paper’s response is to make the substantive distribution of voice, burdens, and remedies an independent object of assessment. Recorded procedure is relevant evidence about what an institution did. Evaluation must also examine whether participants could influence that procedure and whether its decisions addressed the harms at issue. Technical consistency is compatible with systematic injustice; the normative argument cannot be delegated to the log.
Research Scope and Further Development
The present design remains limited by its purposive literature review, constructed cases, bounded legal examples, and incomplete implementation. Theoretical traditions cited here contain disagreements that a single architectural paper cannot adjudicate comprehensively. The legal analysis identifies consequential constraints within specified instruments and jurisdictions; it supplies no general compliance determination for an unconfigured deployment. The normative proposal requires further engagement with actual institutions and affected communities.
These limits identify several directions for further inquiry. Formal work can refine the language and establish properties under precise assumptions. Jurisprudential research can deepen the account of authority, standing, recognition, responsibility, and remedies. Implementation and field studies can assess whether the integrated arrangements preserve useful context at an acceptable social and operational cost. The present paper develops an argument about the conditions under which public knowledge infrastructure should be designed and judged. Further work may strengthen, narrow, or revise those conditions in response to evidence.
Conclusion
This paper has developed an interdisciplinary account of public knowledge infrastructure through the relationship between social facts, their recorded representations, and the institutions that make those representations consequential. The inquiry began with the loss of contextual relations across knowledge artifacts and examined that problem through infrastructure studies, social epistemology, justice, law, and constructive architectural analysis. Its central result is a conditional design argument: preserving knowledge evolution requires both addressable histories and institutions through which participants can interpret, challenge, and revise the public use of those histories.
The first part of the argument concerns representation. An occurrence, an account of it, a participant’s assertion, evidentiary support, institutional recognition, and legal consequence have different conditions of assessment. Public infrastructure should preserve these distinctions where they affect inquiry or action. The proposed information model connects artifacts to attributed assertions, contexts, temporal scopes, and revision histories. Its domain categories provide extensible structure, while classifications and translations remain open to criticism. Historical reconstruction is limited to the dependencies and interpretations that remain available; a retained graph cannot establish a complete history of knowledge production.
The second part concerns the public organization of that representation. Selection, classification, visibility, retention, and reuse distribute epistemic opportunities and exposure. Justice consequently enters the infrastructure through the terms of contribution, the treatment of dissent, the allocation of maintenance burdens, and the availability of effective remedy. The scoped legal analysis further demonstrates that preservation and openness must be organized around applicable duties and rights. Provenance, authority, attribution, and control over information require separate justifications. Their conflation would give technical metadata consequences that the record itself cannot warrant.
The third part concerns operational and institutional continuity. The architecture separates recorded observations from authorized commands, epistemic disagreement from process conflict, and historical interpretation from current disclosure. Federation permits qualified exchange across local custodians while retaining responsibility for admission and use. These arrangements depend on institutions that can authorize policy, represent affected interests, hear challenges, fund maintenance, and provide succession. The proposed governance structure places those responsibilities within the infrastructure’s design and assessment.
AI mediation makes the combined argument especially consequential. Selection, classification, synthesis, and adoption can transform the practical status of a claim while obscuring its evidentiary or intellectual ancestry. A public knowledge infrastructure should preserve the distinctions needed to assess those transformations and to respond when their basis changes. Documentation can support this work only when a responsible institution can act on a correction and affected persons can contest consequential uses.
The constructed cases and bounded formal checks establish a basis for criticism and further implementation. They provide no measured evidence of social effectiveness or general institutional legitimacy. Comparative technical studies and participatory evaluation must assess whether the proposal improves contextual understanding, review, and continuity without imposing disproportionate burdens or exposure. The resulting conception of public knowledge evolution is therefore both generative and revisable: retained relations make further inquiry possible, while the terms of their preservation and use remain subject to justified change.
Initial Interface and Preservation Contracts
This appendix consolidates the component-facing contracts needed for an initial implementation. It identifies required request information, observable outcomes, and acceptance boundaries. The contracts describe semantics rather than a finalized HTTP API or signing protocol.
Admission and Query Contracts
Admission accepts an identified candidate transaction, parent frontier, authenticated submitter, schema artifacts, policy request, and operations. Success produces an immutable commit and authenticated receipt. Failure produces a safe diagnostic and no accepted partial domain effect. Repetition of identical admitted bytes under the same identifier returns the original receipt; changed bytes under that identifier trigger an integrity response.
Query accepts a historical cut, a valid instant where applicable, a context, an operation, and authenticated purpose and principal metadata. Success returns distinct results under the selected semantics, permitted explanations, the actual cut, interpretation-profile identities, current policy epoch, and a safe statement of scope. A request lacking required authority or dependencies can return denial, indeterminacy, partial results, or unavailability according to the declared profile. The response must avoid revealing protected existence through its choice of error detail.
History and workflow-current operations have different coordinates from temporal support. History includes permitted active and inactive records at the selected cut. Workflow-current projects accepted tokens at that cut. Their result metadata identifies any supplied validity or context parameter that does not affect their semantics. This prevents a uniform request envelope from suggesting a false temporal interpretation.
Exchange and Lifecycle Contracts
Exchange accepts a recipient and purpose, a proposed record set, dependency requirements, and the applicable release decision. It produces a scoped manifest whose payload and metadata are both permitted. A receiving node separately validates structure, dependencies, identities, authentication, and local admission. Exchange does not execute remote operational commands.
Lifecycle operations identify targets, action, competent decision record, controlled stores, affected derivatives, and the intended public or restricted explanation. A sealing action preserves a payload under designated custody; an erasure action removes specified controlled material. Their receipts report performed actions and remaining limitations using permitted detail. Neither operation may claim to remove independent copies beyond the operator’s effective control without evidence of that outcome.
Error and Responsibility Allocation
Table 6 connects error families to their first response owner. Each deployment must define an escalation route where the owner is unavailable or materially involved in the dispute.
| Error family | Initial response | Accountable role |
|---|---|---|
| Syntax or type mismatch | Reject candidate with a safe diagnostic | Language/service maintainer |
| Immutable identity conflict | Quarantine incoming packet and preserve incident evidence | Admission operator |
| Missing schema or history | Defer, report permitted incompleteness, or refuse evaluation | Custodian and schema steward |
| Denied or uncertain authority | Prevent protected operation and identify permitted review route | Policy authority |
| Workflow token conflict | Preserve receipts and require complete authorized resolution | Designated process steward |
| Disclosure or cache incident | Contain release, invalidate affected projections, investigate scope | Disclosure operator |
| Retention or succession loss | Report available scope and activate continuity procedure | Archive or successor custodian |
Requirement Traceability
The requirements in Table 2 connect to the design as follows. R1 is realized through the information model in Section 7; R2 and R3 through temporal reconstruction and revision in Section 9; R4 through atomic admission and controlled tokens in Sections 8 and 9; R5 through the exchange contract in Section 10; R6 through the authorization and disclosure boundary in Section 11; R7 through lifecycle, portability, and continuity in Sections 11, 12, and 13; and R8 through the operating roles in Section 13. R9 connects classification and voice in Sections 2, 7, and 13. R10 connects review and remedy in Sections 5, 11, and 13. R11 connects purpose and rights protection in Sections 5 and 11. R12 connects practical participation and continuity in Sections 12 and 13. These mappings identify where a requirement is addressed in the proposal; they do not certify institutional effectiveness. Section 15 and Appendix B distinguish available checks from the implementation and institutional evidence still required.
Formal Artifact and Bounded Validation Record
This appendix identifies the technical evidence accompanying the manuscript and the conclusions that evidence supports. The artifact is GRK-DSL version 0.1, comprising a design model, EBNF, static and dynamic semantic specifications, a JSON exchange schema, and worked source examples. The records below concern checks performed on those artifacts. They should be read alongside the broader assessment in Section 15.
Syntax and Structural Checks
The EBNF-driven syntax recognizer passed 25 self-tests and recognized the three supplied source examples. These checks exercise selected accepted and rejected syntax forms. They provide no evidence that every recognized program is well typed or operationally admissible. A complete parser with an abstract syntax tree, elaborator, resolver, and type checker remains to be implemented.
The exchange schema passed validation against the JSON Schema 2020-12 metaschema. One structural fixture validated, and six deliberately invalid variants were rejected. The accepted fixture contains placeholder schema identities and is unsigned. Its structural validity therefore establishes no claim about authentication, referential completeness, authorized admission, or production exchange. The structural schema and formal semantics impose different obligations.
Semantic Oracles and Counterexamples
Fifteen bounded semantic oracle checks passed for selected aspects of proposition identity, context and schema separation, historical cuts, interval-scoped withdrawal, grounded rule closure, non-explosion, and workflow-token projection. The token checks include permutations of small receipt sets. The oracles use simplified value and time domains and do not execute GRK source. They test small mathematical models of the intended rules; they are neither an end-to-end implementation nor a proof over all programs.
The accompanying design review records counterexamples that led to explicit constraints on self-authorization, hidden withdrawals, event subjects, and conflict resolution. An assertion of permission cannot authorize its own admission. A hidden withdrawal reason cannot reactivate the withdrawn assertion. An event used for a workflow advance must concern the run’s subject. Conflict resolution must identify the complete expected conflicting token set. These repairs strengthen particular contracts while leaving broader implementation correctness and information-flow analysis open.
Reproduction and Evidence Boundaries
The project includes the scripts check_syntax.py, check_semantics.py, and check_ir.py, together with their fixtures and documented invocation requirements. The language package index and validation report identify the current inventory. A separate manuscript checker examines active inputs, labels, citations, numbered displays, captions, and selected build warnings. Document validation establishes editorial and structural consistency; it supplies no assessment of the substantive argument.
No throughput, security, usability, field effectiveness, or justice-related outcome is reported as measured in this paper. The full implementation, comparative study, legal assessment of a specified deployment, and participatory institutional evaluation remain distinct research obligations.