D0
The common object and its graph view
□DESIGN PRINCIPLEIn words script L sub t equals the tuple O sub t, R sub t, E sub t, M sub t, H sub t, A sub t: objects, relations, epistemic records, methods, history and reader authority at step t
In words The graph view: its vertices are the recorded objects; its edges are the relation instances of R sub t.
Φ Framework notation, with the status of what it expresses.
t indexes recorded steps. Oₜ is a finite set of typed objects (Work, Edition, Copy, Passage, Person, Place, Memory, Concept, Question, Inquiry, Instrument). Rₜ holds the relation instances among them. Eₜ holds the epistemic records; each has content, a target, an origin κ and a reader decision δ, kept as separate fields: κ ∈ {source text, bibliographic record, reader testimony, system inference, interpretation, invention} and δ ∈ {undecided, accepted, rejected, revised}. An acceptance never overwrites an origin. Mₜ holds the instruments (D6). Hₜ is the event history, within the scope of D5. Aₜ is the reader’s authority, the only source of δ for personal meaning.
Not claimed. A conceptual model, not a data schema.
D1
Admissible transformation (Plasticity | Fidelity)
□DESIGN PRINCIPLEIn words Phi of script L sub t, x sub t, C sub t equals script L at step t plus 1: the library state after input x sub t, under constraints C sub t
In words The effect, apply, is partial; the transition Phi is total.
Φ Framework notation, with the status of what it expresses.
The effect is partial: a candidate result exists only when the input can be applied at all. Each constraint c ∈ Cₜ is a predicate on the current state, the input and that candidate. The transition is total. Accepted: if the input applies and every constraint holds, Φ returns the candidate, with the acceptance appended to its history. Refused: otherwise Φ returns ℒₜ with only its history extended by a refusal event, whose reason is “not applicable” or the failed constraints. So ℒₜ₊₁ always exists, and a refusal changes nothing but the history. Constraint families in the framework: provenance, identity, permissions, source fidelity, privacy, reader authority, epistemic status. Revisable fields: interpretations, questions, methods, associations, confidence. Fidelity-protected fields: source origin, exact-copy identity, historical record, permissions, provenance; Φ changes these only through an explicit, recorded correction.
Not claimed. No numerical dynamics, no algorithm running in the app, and no meaning of Φ outside this project: not the golden ratio, not integrated information.
D2
Relation record and temporal consistency
The design□DESIGN PRINCIPLEThe theory drawn on◆ESTABLISHED THEORYIn words An edge records its endpoints u and v, its relation type r, the time recorded tau, its provenance pi, its origin kappa and the reader's decision delta.
In words At every moment t, every edge recorded by t has both endpoints recorded by t.
Φ Framework notation, with the status of what it expresses.
The relation vocabulary is partitioned. Derivation: grounded-in, quoted-from, edition-of, contains, generated-by, revision-of, answers, asks-about. Evidential: supports (evidence found later), resists or complicates (E⁻). Descriptive or comparative: compares, shares an image with, located-at, recalls. Only derivation relations are traced as provenance.
Not claimed. Graph theory is established; the relation record is Φ Framework notation for a design principle.
D3
Provenance against evidence
The design□DESIGN PRINCIPLEThe theory drawn on◆ESTABLISHED THEORYIn words If x was formed from y, then y was recorded no later than x.
In words What bears on x splits into supporting and resisting evidence.
Φ Framework notation, with the status of what it expresses.
Two different relations on records. der: x was formed from y; acyclic and time-respecting. ev: y bears on x, as E⁺ or E⁻; it can be added at any time. The provenance trace (the Provenance Microscope) is the der-closure of x (why-provenance) and, for quotations, the exact passage in an exact copy or edition (where-provenance). The evidence balance is ev⁻¹(x). These answer different questions: where a claim came from, and what bears on it (Reichenbach’s distinction of discovery and justification). The origin of a claim is not evidence for it, and a supporting passage found later is evidence, not origin. Gaps are records: an unknown link ends in an explicit gap, never in silence. W3C PROV-DM is a formal analogue, with no conformance asserted.
Not claimed. No claim that the app computes these closures today.
D4
The provenance invariant
□DESIGN PRINCIPLEIn words I sub P of Phi of S equals I sub P of S: on surviving claims that were not corrected and whose sources were not deleted, the transformation leaves each claim's origin and derivation unchanged
In words Restricted to surviving claims K that were neither corrected nor touched by a deletion, the provenance record after the step equals the record before.
Φ Framework notation, with the status of what it expresses.
For one admissible step S → S′ (S is shorthand for the library state ℒₜ; the step is Φ(ℒₜ, xₜ, Cₜ) under its stated constraints, with the displayed input and constraints held fixed), let K be the claims present before and after, Corr those with a correction event in the step, and Del those with a deletion event for the claim or for a record in its derivation closure. The restricted record keeps, for each claim, its origin and its derivation closure. Every surviving claim that was neither corrected nor touched by a deletion keeps exactly its origin and its derivation closure. Exceptions, each recorded: a corrected claim changes exactly as its correction event states, and the event appears in its trace; a deleted record in a closure is replaced by a deletion record without its words (in the app’s intended design, the item’s identifier and the time, which stay linkable to the item on the device), and nothing else changes; new and removed claims lie outside the equality, and a claim leaves only through a recorded deletion. As the framework puts it: “The principle is not that records can never be corrected or deleted; it is that transformation must not silently falsify origin.”
Not claimed. Not equality over all claims: a step may add or remove claims.
D5
Revision without erasure
□DESIGN PRINCIPLEIn words S sub t becomes S at step t plus 1, and the next history is the current history with one event appended.
In words An earlier state is recovered by replaying the retained history, with deleted items replaced by their markers.
Φ Framework notation, with the status of what it expresses.
Scope: the synthetic demonstration and, in the product, only retained, authorized records. Revision is recorded, not overwritten: within retained records, Hₜ is a prefix of Hₜ₊₁. Deletion is itself an appended event: it removes the deleted content from every retained state and from the replayable history, and, in the app’s intended design, a record of the deletion stays on the device: the item’s identifier and the time, never its words, linkable to the item. Backups made in the app carry that record, and a device backup may include it. Formal analogues, as correspondence only: persistent data structures (which keep every version by design — exactly where the analogy stops for private content), valid time against transaction time, and AGM belief revision.
Not claimed. Never implies that deleted private content is kept; no claim of completed permanent erasure (for example from backups outside the app’s control) follows. The deletion record is described as intended design until its implementation is verified. The app implements no AGM operator.
D6
Validated generativity
□DESIGN PRINCIPLEIn words D sub t, arrow labelled V, f sub D sub t: a discovery becomes a method only after validation, reader authorization and epistemic qualification
In words The methods gain the instrument only if V holds; otherwise they are unchanged, and the refusal or revision request is recorded.
In words Every instrument made from a discovery, that is every method not in the initial set M sub 0, has a matching reader validation event in the history.
Φ Framework notation, with the status of what it expresses.
Dₜ ∈ Eₜ is a discovery (a distinction, pattern or question) with its origin and basis. f_Dₜ is an instrument: a function from a library state and a scope to proposals. The map from D to f_D is higher-order: it returns a function (Church; Strachey; Reynolds). V is a guard, not a computation. It holds only when both hold: (i) reader authorization, an explicit accept event by the reader; and (ii) epistemic qualification: purpose, scope and assumptions stated; the basis in Dₜ recorded; the instrument checked against at least one resisting case, or the absence of one recorded; Dₜ’s origin and status still visible. Instrument outputs are proposals, with the origin “instrument f_D, applied”, and need reader review; an instrument never writes trusted state directly.
Not claimed. Not an automatic promotion: no discovery becomes a method because it exists in the system.
D7
Interpretation
The theory drawn on◆ESTABLISHED THEORYThe correspondence◇STRUCTURAL CORRESPONDENCEIn words Each interpretation is computed from the previous one in a new context c.
In words The passage's text stays byte-identical across the loop.
Φ Framework notation, with the status of what it expresses.
For a passage p with fixed text, an interpretation is context-indexed, i(p ∣ c), for contexts from passage to book, collection, reader and world. The loop recomputes the interpretation in each new context; the invariant is the passage’s text, identical at the start and on return.
Not claimed. No convergence is claimed: understanding is never final (Gadamer).
D8
Counterevidence
The theory drawn on◆ESTABLISHED THEORYThe design□DESIGN PRINCIPLEIn words The supporting and resisting evidence for an interpretation H are both drawn from the epistemic records.
In words In illustrative Bayesian models only: the likelihood ratio of an item of evidence e.
Φ Framework notation, with the status of what it expresses.
E⁺(H) and E⁻(H) are shown together. Resistance comes in two kinds (Pollock): rebutting, evidence for not-H; and undercutting, evidence that a supporting link fails, for example a disputed translation. Bipolar argumentation formalises support together with attack. In illustrative Bayesian models only: factors multiply only under conditional independence; a posterior probability requires exhaustive hypotheses; evidence reduces entropy only on average. Discovery is not similarity: retrieval by resemblance over-selects E⁺ (confirmation bias), so E⁻ must be sought explicitly.
Not claimed. No calibrated probabilities; the app is not claimed to compute any.
D9
Agency
□DESIGN PRINCIPLEIn words A proposal's origin kappa is fixed; the reader's decision delta is held separately.
Φ Framework notation, with the status of what it expresses.
An AI proposal has the origin “system inference” (shown as AI-proposed), and that origin does not change when the proposal is accepted or edited. The decision δ is the reader’s, in a separate field. An edit creates a new record authored by the reader, derived from the proposal. Only reader decisions change the status of personal meaning: suggestion followed by human selection, in the levels-of-automation sense.
Not claimed. Assistance ≠ Authority.
D10
Emergence
The correspondence◇STRUCTURAL CORRESPONDENCEThe theory drawn on◆ESTABLISHED THEORYIn words The pattern chi holds on the arranged graph, and fails on some graph G prime with the same vertex labels.
Φ Framework notation, with the status of what it expresses.
A collection pattern χ is a predicate on the labelled graph Gₜ (χ, not π, which names an edge’s provenance). It is emergent (non-aggregative, in Wimsatt’s sense) if χ(Gₜ) holds and some G′ with the same multiset of vertex labels has χ(G′) ≠ χ(Gₜ): the pattern depends on the arrangement of relations, not only on the parts. Four layers stay distinct: stored facts; derived relationships; emergent pattern; interpretation of the pattern.
Not claimed. No stronger, metaphysical emergence is claimed.
D11
Humility
□DESIGN PRINCIPLEIn words A pattern is not a person.
Φ Framework notation, with the status of what it expresses.
A typing rule. Patterns are predicates on the collection graph, never on the reader. No rule maps a pattern to a reader attribute: diagnosis, personality, ideology, identity or stable belief. Any statement about the reader has the origin “reader testimony”. Aggregation can reveal what no single record reveals, which is exactly why emergent patterns stay about books.
Not claimed. Prediction ≠ Identity.
D12
Recursion
□DESIGN PRINCIPLEIn words The next state is Phi of the current state, the input x sub t and the constraints C sub t; when the previous output, y at step t minus 1, the output of the state at step t minus 1, is fed back after review, the input contains it.
Φ Framework notation, with the status of what it expresses.
A system output re-enters trusted state only through reader review (D9), and for methods also through V (D6).
Not claimed. No fixed point, convergence or stability is claimed.
D13
Distinction
The design□DESIGN PRINCIPLEThe theory drawn on◆ESTABLISHED THEORYIn words The edition relation links copies to editions and need not cover every copy; embodiment relates editions and works, many to many.
In words The conditional entropy of the recorded copy attributes A given the recorded edition, under a stated distribution over the copies.
Φ Framework notation, with the status of what it expresses.
Relations, not total maps: a copy’s edition may be unknown (“edition not recorded” is a legitimate record) and a bound-with volume can join several editions in one copy; an anthology or omnibus edition embodies several works, and a work has many editions. Only in a labelled, simplified case (one known edition per copy, one work per edition) may these be written as functions. Reference model: IFLA LRM (Work, Expression, Manifestation, Item); the product folds Expression into Edition, a limit it states. Information loss, stated only under a defined distribution: take a finite collection with a stated distribution over its copies, A the recorded copy-level attributes and Edition the recorded edition, written out in full so that it is not confused with E, the edges. H(A ∣ Edition) is positive if and only if some edition with positive probability has copies whose recorded attributes differ; an edition with exactly two copies whose recorded inscriptions differ, in n equally likely copies, contributes (2/n) × 1 bit. By the data-processing inequality, nothing computed from the edition recovers what H(A ∣ Edition) measures. Missing copy detail is a gap, not entropy. An ISBN identifies a publication — a given title in a given edition and binding — not a work and not an individual copy. The ISBN became ISO 2108 in 1970, building on the UK's Standard Book Number of 1966–67. Many older printings carry no ISBN, but publishers must number their backlist, and the ISBN must appear in the first available reprint or reissue of a backlist title (ISBN Users' Manual, 6th ed., 2012, §5.7). A copy record must therefore never require an ISBN.
Not claimed. Nothing is claimed about unrecorded copies or real collections.