Expound/Platform/Continuous Finality™
Continuous Finality
A verdict is true when it is computed. Continuous Finality keeps it true, or tells you it is not. Because dependencies are recorded when someone relies on a result, finding everything affected when something changes is a query, not an investigation. The original decision stays in the record as what was true then.
The failure it prevents
The decision that was right, until the world moved.
The dangerous case is not the decision that was wrong when it was made. It is the decision that was right when it was made, and is still sitting in a system authorizing work long after the thing it rested on stopped being true.
A production line’s release depends on a sensor whose calibration lapsed. The batch record says released, and nothing in the record knows about the sensor.
Nothing was wrong with the batch record when it was written. Paper records cannot be expected to know this. Computed records can: if reliance on the batch depends on the calibration, the dependency is recordable, the lapse is detectable, and the release decision can be recomputed, before shipment rather than in the recall.
A record may exist≠It may be current≠It may be currently authoritative
The third does not follow from the first two.
Lifecycle
What happens when a basis fails.
Detect
A dependency fails: an upstream approval, a calibration, a policy version, a model version, a rebuilt retrieval index, a threshold somebody adjusted.
Compute the affected set
From the recorded links of who relied on what, rather than from memory. Followed outward one hop at a time until there are no more.
Recompute
Every decision inside the set recomputes. The failing obligation is named and becomes UNKNOWN. The verdict moves to DEGRADED only where a compensating obligation was declared in advance, is independent of what failed, and is itself discharged. Any other required obligation at a lower grade still controls the result. A required obligation that fails outright takes the result to BLOCKED.
Narrow or withdraw, with notice
Licenses narrow to the exact decisions still supported, or are withdrawn. The historical record stays true as history.
Consumers that read again learn before they act, and the ones that cannot be reached are named rather than assumed: nobody had to remember who was relying on what, because the reliance edges are that memory.
Two orderings
Out of use before recomputed, not after.
Usually the corrected answer comes first and the warning comes later, if at all. In between, people are still acting on the old answer. Blood banks, auditors and ratings agencies all learned to do it the other way around: stop people from using it first, figure out the corrected answer second.
A consumer that checks at the moment of reading
Sees not-applicable immediately and needs no message. Whether a result currently applies is computed on every read, not stored anywhere.
A consumer working from a saved copy
Is limited by the freshness bound written into its own license. That bound works like a library loan: when the time is up the copy stops counting, whether or not anyone told the consumer.
Neither requires cooperation
Which is the point, because some consumers will not be there. Between a supersession and a lapse, a cached consumer that never reads again can act on a withdrawn value, and the length of that window is exactly the freshness bound.
The difference is visible from the outside. Where applicability is kept in a stored column, the value read after a basis change is the last value some actor wrote. Here, the value read after a basis change is a value no actor wrote. A reader can separate the two cases by asking, of one result in their own system, whether any person or system anywhere can write that value directly.
The unwind
A withdrawal that tells you who it could not reach.
Pulling a result back and reaching everyone who relied on it is what these standards call an unwind. In the invoice example, one invoice has one relying party, and that is what makes it easy to watch. In a real fleet of agents, reaching them is where a withdrawal usually fails quietly.
So the rule is that Finality Assurance Standards (FAS) does not invent a notification it cannot prove it sent. A consumer that cannot be reached stays an explicit unresolved reliance, named, rather than being counted as notified.
An unreachable consumer≠A notified consumer
Rounding an unknown up to a notification is a standard way a withdrawal reports success it did not achieve.
Next steps
Staying current is automatic. The cost is counted.
What it took to reach any outcome at all is recorded in its own right.
Accepted Work
The unit that still means something when the cost of producing output approaches zero.
Explore →NextLadder and Four Corners
Claim ceilings and reconstructability, both kept apart from the verdict.
Explore →EngagementIf you act on others’ results
Currency is usually where the consumer side hurts first. Start with one decision.
How an engagement runs →