Current production species

Boundaries before cleverness.

The architecture is designed around what must never silently flow into what: private thought, account security, public memory, reference knowledge, and operational candidates each have a different store and a different authority.

Executable boundariesHeap migration underway

System map

Clients at the edge, one public spine, five data planes.

Web client / iOS host / future community clients
        │
        ├── device workspace ── local ions, files, Local AI
        └── explicit network actions
                  │
           Global Server (Cloudflare Worker)
             ├── account & authentication
             ├── public heap and projections
             ├── read-only knowledge corpora
             ├── civic and trust procedures
             └── candidate / operational workspace
                  │
            D1 · R2 · Durable Objects · Workers AI (bounded)

The browser and iOS host share the React product runtime. The native host owns operating-system boundaries; the Global Server owns durable public and account contracts. The public website and these docs explain the system but do not hold private product state.

Five-plane model

Each plane has a distinct promise.

PlaneCanonical persistencePrivate data?Automatic public authority?
Device workspaceBrowser/device stores and filesYesNever
Account & authenticationD1 users, auth tables, user_accountsYesNever
Public CommonsAppend-only heap events and materialized public viewsPublic fields onlyOnly through publish or governed release
Reference knowledgeDedicated corpus nodes and edgesNo user dataNever
Candidate & operationsSource spans, packets, graph diffs, review, manifestsNo private workspace contentNever; release is separate

The whole organism

Six layers connect without collapsing their authority.

1 · Person & device

Private history, knowledge, local ions, files, Local AI, keys, and deliberate publication controls.

2 · Account, Actor & continuity

Private Account state, durable Actors, revocable profiles, access events, verification, recovery, and governed control.

3 · Shared information

Typed Public Artifacts, published IONs, Veins, revisions, reference links, communities, and proposals.

4 · Domain trust

Signed claims and contestable attestations in named domains—never a universal person score.

5 · Public procedure

Private issues, unclaimed Actors, cases, notice, evidence, field work, town halls, human findings, appeals, and separate mandates.

6 · Replication & compute

Mirrors, archives, offline packs, future peer sync, and bounded compute accounting with no path into votes or trust.

Three arrows are forbidden.

Verification cannot create a general trust score. Paid moderation cannot create algorithmic boost. Compute credits cannot create civic power.

Clients

The shared kernel owns product behavior.

Web

React, TypeScript, Vite, the Fracta renderer, Local AI adapters, device stores, Global Server API helpers, and the four product spaces.

iOS

A Capacitor and Swift Package Manager host for the same runtime. Swift owns lifecycle, safe areas, deep-link entry, privacy manifests, permissions, and signing—not a second product model.

Shared contracts under Production/Platforms/shared cover API, identity, heap, publishing, and local Think behavior so future native work can reuse semantics without cloning frontend accidents.

Fracta runtime

The client computes views from explicit boundaries.

AuthorityScope
 permission-filtered Context
 declarative Lens
 View Recipe
 renderer
= Fracta Canvas

The Canvas is derived presentation. Canonical truth remains in local stores, reference corpora, account stores, or typed Public Artifacts. A View Recipe can replay a recorded arrangement or deliberately refresh it against current data. Models may propose semantic intents and Lens configuration; the host owns permissions, geometry, persistence, policy, tools, and accessibility.

Think’s recursive canvas is the mature behavioral reference. Learn’s Venn atlas remains a distinct renderer while adopting the same guarantees for semantic zoom, complete labels, stable orientation, predictable child emergence, Vein traversal, deterministic reinstantiation, and nonvisual navigation.

Global Server

A Cloudflare Worker with explicit route families.

The server separates anonymous public reads, account and identity routes, Ion Protocol participation, community trust, civic cases, governance and review, maintainer operations, the Ion Commons workspace, and compatibility utilities. Every literal route must be classified by the route-exposure audit.

D1

Durable relational persistence for accounts, auth, public projections, knowledge corpora, and operational records.

R2

Export snapshots, graph audits, large evidence or corpus artifacts, and future immutable knowledge chunks.

Durable Objects

Distributed rate limiting where configured, with local in-memory behavior used only for development.

Workers AI

Optional embeddings and bounded operational analysis. A binding cannot silently re-enable the retired server product assistant.

Participation spine

Reality can precede signup without becoming public accusation.

account → confirmed account → verified person → community reviewer → case moderator

private issue → unclaimed entity → match proposal → human review
             → entity claim → claimant accepts or disputes matched history

accepted issue → private civic case + deterministic process plan
               → notice → reply → evidence → human review → appeal

Access levels describe eligibility, not worth or automatic authority. A separate duty contract now binds one selected person to one task, expiry, selection record, registered-key conflict response, and append-only completion history. The unassigned pool contains opaque task references, not private review content. Matching never merges automatically. Claiming an entity never erases or accepts its history. The remaining gap is real operation: external notifications, safeguarding, accessibility, pagination, and staffed public institutions.

Public persistence

Typed records and append-only events are primary; old addresses remain readable.

ion_commons_records now stores typed Public Artifacts, first-class signed Veins, human and group Actors, signed profile projections, membership records, proposals, attestations, revisions, Events, and Receipts. heap_events remains append-only truth for older decentralized-heap participation paths, with heap_ions as its materialized view. Legacy public-artifact mutation in ions is locked. Historic addresses remain readable; old unit and governance readers are compatibility debt, while retired Actor follow/contact write routes fail explicitly instead of mutating another truth store.

A status change is an event, not an overwrite.

Every new Public Artifact begins as created. Legal paths move through amendment, challenge, review, and release—or end as withdrawn or rejected. Released records may become superseded, redacted, or tombstoned. Every edge is a signed append-only Event with a Receipt; content changes remain separate immutable Revisions. The old words active, under_review, contested, retracted, and archived survive only in a read adapter for historic records.

This is migration debt, not architectural permission.

New public work uses Preview → signed Commit → Receipt and explicit public projections. The project must not create another public truth store. Legacy data is severed, observed, exported, attested, and only then purged in a later deployment.

Identity & security

Account, Actor, and profile never collapse into one row.

  • Production auth fails closed if durable D1 persistence is unavailable.
  • Durable Account tombstones invalidate existing sessions after deletion.
  • OAuth starts issue signed state and nonce; callbacks validate both.
  • Actors remain durable subjects even when no Account controls them or a profile is invisible.
  • Profile output is allowlisted rather than returning arbitrary Account or Actor metadata.
  • Public writes bind the authenticated Account to a server-derived or governed Actor control relationship.
  • Client-held signatures are verified against registered public keys.

Signature contracts support Ed25519, post-quantum ML-DSA-65, hybrid verification, key graphs, revocation, and rotation. This proves key control for a scoped action; it does not prove unique personhood or permit public-history rewrite.

Reference data

Wikipedia is physically and logically air-gapped from Commons truth.

GET /v1/knowledge/wikipedia reads dedicated knowledge_nodes and knowledge_edges. Its reader has no public Commons store dependency and no mutation method. The versioned server atlas prefers a real v2 branch and fills only an empty matching domain from the quarantined v1 edition. Every node keeps its original corpus and version; source editions are never silently blended or renamed.

Horizon never falls back to the public graph when the corpus is unavailable. A future device pack will use the same read-only contract with a signed manifest, immutable chunks, stable source IDs, and explicit storage controls.

Candidate lane

Automation proposes. Release remains another act.

source policy → source span → bounded worker packet → proposed graph diff
              → human or governed review → release manifest → public projection

Current events, source adapters, AI analysis, and publication intake feed candidates. Time passing, source prestige, or an AI summary cannot make a record accepted truth. Paid inference, destructive reset, graph-diff apply, and public release have separate authorization and confirmation gates.

Deployment topology

Test and production are intended to be materially separate.

Public surfaces

syxon.org for the public site and docs, app.syxon.org for the product, and api.syxon.org for the production Worker.

Custodian surface

A separate monitor presents operational truth. It should read status and queues before it gains any destructive action.

Test Workers must use separate D1 and R2 stores before mutation, paid inference, broad ingestion, or reset testing. Secrets live in local configuration, CI secrets, or Worker secrets—never the repository.

Decentralization path

Seed the exits before claiming the destination.

Available now

Signed heap events, signed public actions, append-only case records, export snapshots, redaction-aware mirror bundles, and signature-verified import previews.

Still required

Independent operational mirrors, gossip replication, applied imports, community release keys, revocation, multi-node tallying, failover, and governance that can supersede the founding steward.

The current Global Server is centralized because the system must work before it can distribute safely. The protocol is honest only if central custody is treated as a transition with testable exits—not as decentralization by branding.