Stephen's program, verbatim anchor: "we are in some ways recreating the user dashboard for
the domain but withing a directory without users. just token propagation." Note 02 designed v1 and shipped
its choices; this fan opens the four forks UNDERNEATH those choices, each a deeper future. Every "as shipped"
alternative renders beside its rivals so the v1 decision is re-askable. Play them, then cast one critique
at the bottom (qid story-map); recombinations are legal answers.
All geometry, names, times, and token ids below are wireframe stand-ins, never the record;
the factual spine lives only in the bead's notes 00/01 and the RLS. Method:
sketch-ux · ballot pattern: incident-add fan (bead 019f8680).
S1 · the right pane · what stands beside the story spine?
The page keeps a persistent spatial witness on the right while the spine scrolls on the left.
Shipped: the taos-engine terrain. Same duty, three bodies: terrain you fly, the items' own camera views
replayed, or terrain and timeline sharing the column.
S1a taos-engine terrain · as shipped
tap a story beat · the terrain camera flies to it (wireframe stand-in)
Community assertions render as a visually distinct layer (hollow diamonds), never
merged into the record's own marks. Beats here are stand-ins; the real spine comes from notes 00/01.
the ground the story happened on, always in view; taos already ships it. but terrain
answers WHERE and stays mute on WHEN, and a flown camera can feel like drama the respect gate forbids.
S1b camera-frustum replay · the items' own views
each cataloged item that IS a view (news video, photo, drop footage) projects
its frustum; tap one, or replay them in asserted-time order
the record looking at itself: every pixel is an item the collection already holds, and
community imagery joins as one more frustum. but items without geometry vanish, and three frustums today
is a sparse witness.
S1c split column · terrain above, timeline below
beat 1 · ignition · drag the playhead; terrain and spine move together,
and YOU own the lerp
The reader drives every camera move (the morph-never-cut rule); nothing plays
itself. Calibration drops from the set-space-time gesture would land on this same strip.
where and when share the pane, and the drag IS the story's spine; calibration assertions
get a natural home. but two small views can be two illegible views, and the column steals height from
the terrain.
S2 · assertion credit · how does a witness appear in the public log?
Shipped: free-text credit name plus tok: fingerprint. Same envelope, three renderings:
name-only, name plus a capability chip carrying invite lineage, or pseudonymous handles with colors that
stay consistent per device. Tap rows to open them.
S2a name-only · as shipped
Credit is claimed, never verified; the fingerprint beside the name is the only
continuity. The page says so in plain words.
the quietest render, and the promise is honest: you are credited as you asked. but two
different Marias collide, and weight-by-lineage stays invisible.
S2b name + capability chip · lineage worn openly
open door
└─ k3b9x2 · Crew 7 branch
├─ maria-r
└─ (no name given)
└─ direct · open-door arrivals
└─ r-cline
tap a chip · the invite branch it rides lights up in the tree
an assertion from a known branch carries visible weight, exactly note 02's corroboration
story. but a chip reads as a badge of rank, and open-door witnesses start to look second-class.
S2c pseudonymous handles · consistent colors
same device, same handle, same color · continuity without asking a name
grief-safe by default: nobody is pressed for a name three weeks after a death. but
pseudonyms mute the community's own credit ask, and a handle nobody chose can feel assigned.
S3 · the chain · how does the write capability travel to the next witness?
Shipped: everyone spends the one embedded key; invites are public lineage records. The
futures note 02 §5 names: per-invite leaf tokens from a mint proxy, or crews that share a spoken code and
no links at all. Play the revoke in each; the difference IS the revoke.
S3a shared key + public lineage · as shipped
each invite writes a public record and hands back a #invite=<id> link;
everyone still spends the ONE key
Provenance chain, not capability chain, and the page never calls it one. Revoking
resets EVERYONE at once; that bluntness is the honest price of v1.
already live, zero server parts, and the lineage is public forever. but one bad actor
costs the whole commons its pen.
S3b per-invite leaf tokens · the mint proxy future
Needs one server part holding the owner credential: POST /mint with a valid
invite_id returns a leaf token, write-only to this box, short expiry, one per invitee
(note 02 §5, future 1). Revocation becomes per-person, by tokenId.
real capability delegation, depth-bounded and auditable; revoke ✕ one leaf and the rest
keep writing. but the first server-side component in a design whose whole beauty was files.
S3c join-codes per crew · no links anywhere
your crew's code · say it over the radio, write it on a glove
ELK-7-CHELAN
A code is a bearer capability that travels by voice; whoever holds it joins. The
invite log still records every join, public as ever.
works with gloves on and no phones exchanged; crews already think in call signs. but a
spoken code drifts past the crew with every retelling, and lineage flattens to "the code brought them".
S4 · the dashboard-without-users, generalized · what does the pattern become at domain scale?
Shipped: one box per incident, one key per box. If the pattern holds, what does the
DOMAIN look like: a shelf of incident boxes, one river of contributions flowing across incidents, or a
namespace where every contributor hatches into a bead of their own?
tap an incident · its box opens alone; keys never cross boxes
blast radius stays incident-sized and a leak junks one directory; the wallet row per box
is the whole admin story. but a witness of three fires is three strangers, and nothing aggregates.
S4b the domain-wide contributions river
The river is a READ view braided over the same per-incident boxes; no new write
power exists. Write keys stay one-per-box; only the rendering federates.
one living surface for the whole domain, and a contributor's thread finally reads as a
thread. but a river invites doomscroll grammar into testimony, and incident context thins to a chip.
S4c bead-per-contributor hatching
maria-r · 4 assertions across 2 incidents
contributor bead hatched · b7e1c9d4-…-wireframe
about: gathers maria-r's assertions and invite branches across incidents; her dock is
uploads/; her credit line is now a namespace citizen with a URI. assertions sync as links, never copies; the incident boxes stay canonical.
Identity graduates from credit-line to bead: revocable, addressable, hers. But a
bead is a commitment the commons must then steward; hatching is governance, not just UX.
the full circle: the dashboard-without-users grows users after all, except each "user"
is a directory with a dock, born from testimony. but moderation and apoptosis multiply per head.
The ballot
story-map · Compose the story page's deeper future: check what should
ship next. One letter per fork is the default; more, fewer, and recombinations are all legal answers,
and the notes carry the vectors.
S1 · the right pane
S1a taos-engine terrain · as shipped: the ground always in view, camera flies to beats.
S1b camera-frustum replay · the record looks at itself; items' views projected and replayed.
S1c split terrain + timeline column · where and when share the pane, reader owns the lerp.
S2 · assertion credit
S2a name-only · as shipped: credit name plus tok: fingerprint, quiet and honest.
S2b name + capability chip · invite lineage worn openly, weight made visible.
S2c pseudonymous handles · consistent colors per device, grief-safe by default.
S3 · the chain
S3a shared key + public lineage · as shipped: provenance chain, blunt one-key revoke.
S3b per-invite leaf tokens via mint proxy · real delegation, per-person revoke, one server part.
S3c join-codes per crew · spoken capability, no links, gloves-on joining.
S4 · the dashboard-without-users, generalized
S4a per-incident boxes · as shipped: keys never cross boxes, blast radius stays small.
S4b domain-wide contributions river · one read-surface braided over the boxes.
S4c bead-per-contributor hatching · every witness may become a bead with a dock.