Receipt page · The Terminal
How the Terminal suite measures
This is a receipt page. Dossier §8.2 fixes what one contains, and the five sections below are that anatomy in order: the versioned methodology, the pre-registrations, the proof corpus, the changelog, and the invitation to recompute any published number without asking me for anything. Nothing has been measured yet. Three of the five sections are therefore empty, and they are empty in a way you can inspect — the structure is printed, the slots are named, and each one says NOT YET PUBLISHED rather than showing you something plausible. Looking for what this family will contain instead? That is the Terminal suite hub.
Receipt anatomy · dossier §8.2Terminal suiteReceipt version v1.0
- Instruments in scope
- 1
- Metrics defined
- 4
- Pre-registrations posted
- NOT YET PUBLISHED
- Artifacts published
- NOT YET PUBLISHED
- Measurements published
- NOT YET PUBLISHED
- 01Methodology, versionedProse and formal definitions. Every metric carries its name, its definition, the estimator that computes it, its known failure modes, and what it does not establish. The page carries a version, and the version is printed on it.DEFINED · v1.0
- 02Pre-registrationsDeclarations made and dated before any measurement runs: decision thresholds, exclusion rules, completeness bars. Immutable once posted — an amendment appends beneath the original with its reason, and never overwrites it.NOT YET PUBLISHED
- 03Proof corpusThe published artifacts themselves: dataset descriptors, content hashes, download links, and the version tag of the code that generated each one. A result whose inputs are not downloadable is not a receipt.NOT YET PUBLISHED
- 04ChangelogAppend-only, dated, written by a person. What changed on this page, when, and why. A correction is a new entry naming the entry it corrects — entries are never edited away.1 ENTRY
- 05Independent recomputationThe exact numbered steps a stranger follows to re-derive a published number without asking me for anything. Where the recomputation disagrees, the disagreement is the finding.PROCEDURE STATED
Methodology, versioned
version v1.0last changed 2026-08-014 metrics · 1 instruments
The Terminal suite is the display layer under the same discipline as everything beneath it: a working quant cockpit of roughly ninety panels in which every displayed number carries its provenance — the git SHA and the sha256 of the source artifact it was computed from — or the panel enters an explicit LOCKED state and refuses to render. It does not measure a new quantity; it enforces that no quantity reaches a screen without proof of where it came from.
The July 2026 incident on my core engine included fake telemetry painted into a live cockpit — random numbers presented as a working system. The terminal is the structural answer, built as the anti-cockpit: it cannot display a number it cannot prove. A LOCKED panel is the design succeeding, not failing — an honest refusal where a dishonest system would have painted something plausible.
Every metric below carries five fields, because four of them are the fields a methodology usually leaves out. Definition states what the quantity is, closely enough that a stranger could implement it. Estimator states how it is computed and which parameters must be fixed before the data is read. Known failure modes states where the estimator breaks — written now, while nothing depends on it, rather than conceded later under questioning.Does not establish states the claim the metric will not support, however natural the reading. The last field is the one that costs something to publish, which is why it is published.
A working quant cockpit in which a number renders only with its provenance attached. A panel that cannot prove its number enters a LOCKED state and refuses to render, visibly.
P16.1Per-number provenance stamp
- Definition
- The git SHA of the code that produced a displayed figure, together with the SHA-256 of the source artifact it was computed from, carried by the figure itself.
- Estimator
- The stamp is the render condition, not a tooltip courtesy: the panel resolves both identifiers before painting, and a figure missing either is not painted at all.
- Known failure modes
- A stamp proves which artifact and which code produced a number. It does not prove the artifact was produced correctly — which is exactly why the upstream disciplines exist and are sold separately.
- Does not establish
- A stamped number is not thereby a correct number. Provenance and correctness are different claims, and the terminal only makes the first.
P16.2LOCKED state incidence
- Definition
- The occasions on which a panel refused to render because its artifact was missing, its hash did not match, or its upstream went quiet.
- Estimator
- Lock events are recorded per panel with the failing condition; both the count and the reason publish, since suppressing a lock would be the precise failure the design exists to prevent.
- Known failure modes
- A panel that is never exercised cannot lock, so a low lock count on an idle panel means nothing. Panel exposure publishes beside the count so the denominator is visible.
- Does not establish
- A LOCKED panel does not establish that the upstream data is wrong — only that it could not be verified at render time.
P16.3Panel coverage
- Definition
- How much of the cockpit’s display surface is governed by the render-or-lock discipline, enumerated rather than asserted.
- Estimator
- An enumeration against the discipline with no privileged exemption — not for status lights, which were exactly what was faked in July 2026.
- Known failure modes
- Counting panels rather than figures would let one unverified number hide inside a large panel, so the enumeration is per figure and the panel count is only a summary of it.
- Does not establish
- Full coverage does not establish that every displayed number is correct.
P16.4Verification refresh discipline
- Definition
- How often a panel re-verifies its artifact rather than trusting a verification made earlier.
- Estimator
- A re-verification cadence is declared per panel and then observed. A panel whose observed cadence falls behind its declaration is a defect, not a tolerance.
- Known failure modes
- A cadence that is too aggressive locks panels on transient upstream latency. The trade-off is declared per panel rather than tuned quietly until the screens look calm.
- Does not establish
- A verified refresh does not establish that the artifact is current with the market.
Standing limit. The terminal displays what has been computed and proven — nothing else. A LOCKED panel is not an error to suppress; it is the honest state of an unproven number.
Full instrument page →
Versioning rule: this page is v1.0. A change to any definition, estimator, failure mode or limit above increments the version and appends an entry to the changelog in §04 naming what changed. Definitions are never edited silently, because a definition that can move after a result is published is not a definition — it is a degree of freedom.
Pre-registrations
A pre-registration is a declaration made and dated before the measurement runs: the thresholds that will decide, the rules that will exclude, and the sample bar below which the honest null publishes instead of a number. Its entire value comes from its ordering. Posted before the answer is known it is a constraint; posted afterwards it is a description of a result, which is a different and much cheaper object wearing the same clothes.
Pre-registration record · TerminalNOT YET PUBLISHED
No pre-registration has been posted for the Terminal suite. Not one that is pending review, not one that is drafted and unhashed — none. This block is the structure a registration will occupy, printed empty on purpose, because the alternative is a page that describes a discipline while quietly implying it has already been exercised.
A pre-registration is worth exactly the provability of its ordering. It has to be posted, dated and content-hashed while the answer is still unknown; posted afterwards it is a description of a result, which is a different and much cheaper object. So the first registration cannot be backdated into this slot, and the slot stays visibly empty until one is posted in the only way that counts.
The field schema of a pre-registration record for the Terminal suite: each field, what it will hold, and its current value. Every value reads NOT YET PUBLISHED because no registration exists.| Field | What it will hold | Value |
|---|
registration_ref | The permanent identifier this registration is cited by. | NOT YET PUBLISHED |
|---|
scope | The instruments and the measurement window the declaration binds. | NOT YET PUBLISHED |
|---|
declared_utc | When the declaration was posted — necessarily before any data was touched. | NOT YET PUBLISHED |
|---|
first_data_utc | When collection began. This must fall after the line above, and the ordering is the evidence. | NOT YET PUBLISHED |
|---|
thresholds | Every decision threshold, fixed while the answer was still unknown. | NOT YET PUBLISHED |
|---|
exclusion_rules | What will be dropped from the sample, and on what stated grounds. | NOT YET PUBLISHED |
|---|
completeness_bar | The minimum sample below which the honest null publishes instead of a number. | NOT YET PUBLISHED |
|---|
document_sha256 | The content hash of the registered document itself. Any later edit changes it, visibly. | NOT YET PUBLISHED |
|---|
amendments | Appended corrections, each with its own date and reason. The original text stays. | NOT YET PUBLISHED |
|---|
What a Terminal registration must fix in advance. The lists below are classes of declaration, not declarations. They name the decisions that have to be made before the data is touched, because each one is a decision that could otherwise be made afterwards, in the direction that flatters the result. No value below has been registered.
Thresholds
- The freshness bar beyond which a panel must lock rather than render.
- The re-verification cadence declared per panel.
- What constitutes a verification failure, so LOCKED means one thing across the whole surface.
Exclusion rules
- Which artifact each panel is entitled to read, declared per panel rather than inferred at render time.
- How transient upstream latency is separated from an unverifiable artifact.
- What, if anything, is exempt from the render-or-lock discipline. The standing answer is nothing.
Completeness bars
- The minimum panel exposure required before a lock count is reported, since an idle panel cannot lock.
- The coverage denominator: figures enumerated, not panels, so one unverified figure cannot hide inside a large one.
- The minimum observation window before a declared refresh cadence is reported as observed.
Immutability, stated before it is tested. Once a registration is posted it is not edited. If it is wrong, an amendment is appended beneath it carrying its own date and the reason for the change, and the original text stays where it is, readable, above the correction. A registration that quietly improved after the data arrived would be indistinguishable from one that was right all along — which is precisely why the append rule is written here, now, while there is nothing yet to be tempted by.
Amendment rule, stated in advance: a posted registration is never edited. An amendment is appended beneath the original carrying its own date and its reason, and the original text stays above it, readable. This page will show both.
Proof corpus
The corpus is the set of artifacts a published measurement ships with — not a description of them, the artifacts themselves, downloadable, each with the digest that proves you received the bytes I measured and the code tag that produced them. A result whose inputs cannot be downloaded is not a receipt; it is an assertion with better typography.
The corpus for this suite is empty. Every row below is a slot, and every slot is NOT YET PUBLISHED. The table is printed anyway, because a reader should be able to see the exact shape of what will arrive — and because a page that described a corpus without showing how empty it currently is would be making the claim it exists to refuse.
Five columns: artifact, contents, content hash, code tag, download. Scroll sideways if they do not all fit.
Proof corpus for the Terminal suite: the seven artifact classes a published receipt carries, what each will contain, and its current state. Every content hash, code tag and download reads NOT YET PUBLISHED, because no artifact from this suite's proof corpus has been published yet.| Artifact | What it will contain | Content hash | Code tag | Download |
|---|
| Registered methodology document | The versioned document these definitions are taken from, in the exact form it was registered — estimators, parameters, and the limits stated above. | SHA-256NOT YET PUBLISHED | NOT YET PUBLISHED | NOT YET PUBLISHED |
|---|
| Pre-registration record | The dated declaration: thresholds, exclusion rules and completeness bars, plus any amendments appended beneath the original with their reasons. | SHA-256NOT YET PUBLISHED | NOT YET PUBLISHED | NOT YET PUBLISHED |
|---|
| Panel artifact set | The source artifacts the enumerated panels read, by digest, together with the stamps the panels displayed for each figure. | SHA-256NOT YET PUBLISHED | NOT YET PUBLISHED | NOT YET PUBLISHED |
|---|
| Result set | Per-metric results with intervals and effective sample sizes, and the honest nulls wherever a sample could not support a metric. | SHA-256NOT YET PUBLISHED | NOT YET PUBLISHED | NOT YET PUBLISHED |
|---|
| Can-fail proof transcript | For every test in the battery: the planted defect, the refusal that was expected, and the outcome that was observed. | SHA-256NOT YET PUBLISHED | NOT YET PUBLISHED | NOT YET PUBLISHED |
|---|
| Kill-ledger extract | Hypotheses registered against this suite and killed by the data, each with the run that killed it. Published with the same visibility as a registration. | SHA-256NOT YET PUBLISHED | NOT YET PUBLISHED | NOT YET PUBLISHED |
|---|
| Generation code | The tagged commit that produced the result set, with its build receipt. Named here because a result whose code version is unstated cannot be re-run. | SHA-256NOT YET PUBLISHED | NOT YET PUBLISHED | NOT YET PUBLISHED |
|---|
Corpus state, per instrument
Per instrument, so that the emptiness cannot hide behind a suite-level summary.
Changelog
Append-only, dated, written by a person. It records changes to this page — it is not a measurement log, and it will not become one. A correction is a new entry that names the entry it corrects; nothing here is ever edited away, because a changelog you can rewrite is a marketing surface with a monospace font.
2026-08-01 · v1.0
Receipt page established for the The Terminal suite, carrying all five parts of the §8.2 anatomy: the versioned methodology with a formal definition, estimator, failure modes and non-claim for each of the 4 metrics its 1 instruments measure; the pre-registration structure with no registration in it; the proof-corpus table with no artifact in it; this changelog; and the independent-recomputation procedure. Supersedes the earlier per-suite methodology summary at this URL, which carried the battery outline without the receipt anatomy. No measurement, pre-registration, artifact or hash accompanies this version — every receipt slot below is empty as a matter of fact, not of omission.
Independent recomputation
Independent recomputation is what makes the rest of the page checkable rather than merely well-written. It is the exact sequence a stranger follows to re-derive a published number from this suite using only artifacts I published — no account, no request, no conversation with me at any point.
Today the procedure terminates at step 1, because no measurement from the Terminal suite has been published and there is no receipt to open. The steps are written now, in the specific form they will take for this suite, precisely so that they exist before the first result does and cannot afterwards be shaped to fit one.
Open the receipt and take its four identifiers.
Every published measurement links a receipt carrying four: the registration reference, the methodology-document digest, the input-manifest digest, and the generation-code tag. If any one is missing, stop — the result is not recomputable and should not be treated as though it were, including by me.
Verify the methodology document against its digest.
Download it, hash it, compare. A mismatch means the method you are about to apply is not the method that was registered, and everything after this step would be measuring a different thing.
Check the ordering before you check anything else.
The registration timestamp must precede the first-data timestamp on the manifest. If it does not, the registration is a description of a result rather than a constraint on one, and no statistic downstream can repair that.
Take any published figure and read its stamp.
The git SHA of the producing code and the SHA-256 of the source artifact. Fetch the artifact by digest and confirm its bytes hash to the value that was on the glass.
Apply the registered rules yourself.
Which artifact the panel is entitled to read, the freshness bar beyond which it must lock, and what counts as a verification failure. A panel that renders outside those rules is a defect regardless of whether its number happens to be right.
Check out the producing code at the stamped SHA and run it against the verified artifact.
The stamp exists so this step needs nothing from me: the SHA and the digest are the whole of the instruction.
Recompute the figure and compare it against what the panel displayed.
They must agree exactly. The terminal renders computed values, not rounded summaries of them, so there is no tolerance to argue about.
Run the can-fail proof.
Corrupt one byte of a copy of the artifact and confirm the panel enters LOCKED rather than rendering. A panel that renders against a mismatched artifact has failed in the exact way this instrument exists to prevent.
If your number differs, the difference is the finding.
Send it with your inputs and the version you ran. A confirmed discrepancy publishes as a correction appended beside the original — and the original stays exactly where it is, unedited, because the error is the part of the record that proves the discipline is real.
The point of publishing this before there is anything to check: a recomputation procedure written after a result is a procedure written by someone who already knows which steps would be inconvenient.