Current production species
Boundaries before cleverness.
The architecture is designed around what must never silently flow into what: private thought, account security, public memory, reference knowledge, and operational candidates each have a different store and a different authority.
System map
Clients at the edge, one public spine, five data planes.
Web client / iOS host / future community clients
│
├── device workspace ── local ions, files, Local AI
└── explicit network actions
│
Global Server (Cloudflare Worker)
├── account & authentication
├── public heap and projections
├── read-only knowledge corpora
├── civic and trust procedures
└── candidate / operational workspace
│
D1 · R2 · Durable Objects · Workers AI (bounded)The browser and iOS host share the React product runtime. The native host owns operating-system boundaries; the Global Server owns durable public and account contracts. The public website and these docs explain the system but do not hold private product state.
Five-plane model
Each plane has a distinct promise.
| Plane | Canonical persistence | Private data? | Automatic public authority? |
|---|---|---|---|
| Device workspace | Browser/device stores and files | Yes | Never |
| Account & authentication | D1 users, auth tables, user_accounts | Yes | Never |
| Public Commons | Append-only heap events and materialized public views | Public fields only | Only through publish or governed release |
| Reference knowledge | Dedicated corpus nodes and edges | No user data | Never |
| Candidate & operations | Source spans, packets, graph diffs, review, manifests | No private workspace content | Never; release is separate |
The whole organism
Six layers connect without collapsing their authority.
1 · Person & device
Private history, knowledge, local ions, files, Local AI, keys, and deliberate publication controls.
2 · Account, Actor & continuity
Private Account state, durable Actors, revocable profiles, access events, verification, recovery, and governed control.
3 · Shared information
Typed Public Artifacts, published IONs, Veins, revisions, reference links, communities, and proposals.
4 · Domain trust
Signed claims and contestable attestations in named domains—never a universal person score.
5 · Public procedure
Private issues, unclaimed Actors, cases, notice, evidence, field work, town halls, human findings, appeals, and separate mandates.
6 · Replication & compute
Mirrors, archives, offline packs, future peer sync, and bounded compute accounting with no path into votes or trust.
Verification cannot create a general trust score. Paid moderation cannot create algorithmic boost. Compute credits cannot create civic power.
Clients
The shared kernel owns product behavior.
Web
React, TypeScript, Vite, the Fracta renderer, Local AI adapters, device stores, Global Server API helpers, and the four product spaces.
iOS
A Capacitor and Swift Package Manager host for the same runtime. Swift owns lifecycle, safe areas, deep-link entry, privacy manifests, permissions, and signing—not a second product model.
Shared contracts under Production/Platforms/shared cover API, identity, heap, publishing, and local Think behavior so future native work can reuse semantics without cloning frontend accidents.
Fracta runtime
The client computes views from explicit boundaries.
AuthorityScope
permission-filtered Context
declarative Lens
View Recipe
renderer
= Fracta CanvasThe Canvas is derived presentation. Canonical truth remains in local stores, reference corpora, account stores, or typed Public Artifacts. A View Recipe can replay a recorded arrangement or deliberately refresh it against current data. Models may propose semantic intents and Lens configuration; the host owns permissions, geometry, persistence, policy, tools, and accessibility.
Think’s recursive canvas is the mature behavioral reference. Learn’s Venn atlas remains a distinct renderer while adopting the same guarantees for semantic zoom, complete labels, stable orientation, predictable child emergence, Vein traversal, deterministic reinstantiation, and nonvisual navigation.
Global Server
A Cloudflare Worker with explicit route families.
The server separates anonymous public reads, account and identity routes, Ion Protocol participation, community trust, civic cases, governance and review, maintainer operations, the Ion Commons workspace, and compatibility utilities. Every literal route must be classified by the route-exposure audit.
D1
Durable relational persistence for accounts, auth, public projections, knowledge corpora, and operational records.
R2
Export snapshots, graph audits, large evidence or corpus artifacts, and future immutable knowledge chunks.
Durable Objects
Distributed rate limiting where configured, with local in-memory behavior used only for development.
Workers AI
Optional embeddings and bounded operational analysis. A binding cannot silently re-enable the retired server product assistant.
Participation spine
Reality can precede signup without becoming public accusation.
account → confirmed account → verified person → community reviewer → case moderator
private issue → unclaimed entity → match proposal → human review
→ entity claim → claimant accepts or disputes matched history
accepted issue → private civic case + deterministic process plan
→ notice → reply → evidence → human review → appealAccess levels describe eligibility, not worth or automatic authority. A separate duty contract now binds one selected person to one task, expiry, selection record, registered-key conflict response, and append-only completion history. The unassigned pool contains opaque task references, not private review content. Matching never merges automatically. Claiming an entity never erases or accepts its history. The remaining gap is real operation: external notifications, safeguarding, accessibility, pagination, and staffed public institutions.
Public persistence
Typed records and append-only events are primary; old addresses remain readable.
ion_commons_records now stores typed Public Artifacts, first-class signed Veins, human and group Actors, signed profile projections, membership records, proposals, attestations, revisions, Events, and Receipts. heap_events remains append-only truth for older decentralized-heap participation paths, with heap_ions as its materialized view. Legacy public-artifact mutation in ions is locked. Historic addresses remain readable; old unit and governance readers are compatibility debt, while retired Actor follow/contact write routes fail explicitly instead of mutating another truth store.
Every new Public Artifact begins as created. Legal paths move through amendment, challenge, review, and release—or end as withdrawn or rejected. Released records may become superseded, redacted, or tombstoned. Every edge is a signed append-only Event with a Receipt; content changes remain separate immutable Revisions. The old words active, under_review, contested, retracted, and archived survive only in a read adapter for historic records.
New public work uses Preview → signed Commit → Receipt and explicit public projections. The project must not create another public truth store. Legacy data is severed, observed, exported, attested, and only then purged in a later deployment.
Identity & security
Account, Actor, and profile never collapse into one row.
- Production auth fails closed if durable D1 persistence is unavailable.
- Durable Account tombstones invalidate existing sessions after deletion.
- OAuth starts issue signed state and nonce; callbacks validate both.
- Actors remain durable subjects even when no Account controls them or a profile is invisible.
- Profile output is allowlisted rather than returning arbitrary Account or Actor metadata.
- Public writes bind the authenticated Account to a server-derived or governed Actor control relationship.
- Client-held signatures are verified against registered public keys.
Signature contracts support Ed25519, post-quantum ML-DSA-65, hybrid verification, key graphs, revocation, and rotation. This proves key control for a scoped action; it does not prove unique personhood or permit public-history rewrite.
Reference data
Wikipedia is physically and logically air-gapped from Commons truth.
GET /v1/knowledge/wikipedia reads dedicated knowledge_nodes and knowledge_edges. Its reader has no public Commons store dependency and no mutation method. The versioned server atlas prefers a real v2 branch and fills only an empty matching domain from the quarantined v1 edition. Every node keeps its original corpus and version; source editions are never silently blended or renamed.
Horizon never falls back to the public graph when the corpus is unavailable. A future device pack will use the same read-only contract with a signed manifest, immutable chunks, stable source IDs, and explicit storage controls.
Candidate lane
Automation proposes. Release remains another act.
source policy → source span → bounded worker packet → proposed graph diff
→ human or governed review → release manifest → public projectionCurrent events, source adapters, AI analysis, and publication intake feed candidates. Time passing, source prestige, or an AI summary cannot make a record accepted truth. Paid inference, destructive reset, graph-diff apply, and public release have separate authorization and confirmation gates.
Deployment topology
Test and production are intended to be materially separate.
Public surfaces
syxon.org for the public site and docs, app.syxon.org for the product, and api.syxon.org for the production Worker.
Custodian surface
A separate monitor presents operational truth. It should read status and queues before it gains any destructive action.
Test Workers must use separate D1 and R2 stores before mutation, paid inference, broad ingestion, or reset testing. Secrets live in local configuration, CI secrets, or Worker secrets—never the repository.
Decentralization path
Seed the exits before claiming the destination.
Signed heap events, signed public actions, append-only case records, export snapshots, redaction-aware mirror bundles, and signature-verified import previews.
Independent operational mirrors, gossip replication, applied imports, community release keys, revocation, multi-node tallying, failover, and governance that can supersede the founding steward.
The current Global Server is centralized because the system must work before it can distribute safely. The protocol is honest only if central custody is treated as a transition with testable exits—not as decentralization by branding.