The shared interface contract

One canvas language. Four different kinds of work.

Learn, Think, Explore, and Connect are the only product spaces. Each view starts by saying who may read or act, which records matter now, and how they should be arranged. Geometry helps people think, but it never becomes hidden truth.

Pass-one foundation activeInstitutional pilots still ahead

The compact model

A boundary, a selection, and a view become the canvas.

The interface uses four precise protocol names under the hood. In ordinary use, they answer four plain questions: who may act, what matters now, how should it be shown, and how can this view be reopened?

AuthorityScope decides what may be read or changed
 Context selects the relevant permitted objects
 Lens declares how to interpret and render them
 View Recipe remembers this particular view
= Fracta Canvas, a derived and reproducible interface
The canvas is a view, not a verdict.

Position, clustering, colour, scale, and visual emphasis are derived presentation. Canonical records live in their stores with stable identifiers, revisions, policies, provenance, and relationships.

The four spaces

The runtime is shared; authority is not.

SpaceContextPrimary authorityTypical lenses
LearnRead-only reference objects, sources, and citationsRead reference material; save a cited local ionField → cluster → concept → source
ThinkLocal ions, local Veins, files, memories, conversations, and recipesEdit local work on the deviceRecursive tree, document, whiteboard, local graph
ExplorePublic artifacts, revisions, Veins, events, policies, sources, and findingsInspect public history; start local drafts for outward actionsPublic graph, provenance, challenge, timeline
ConnectActors, profiles, communities, duties, capabilities, issues, cases, appeals, and assembliesParticipate only through named procedures and capabilitiesPeople and work, duty queue, case record, assembly

Identity and access, public duties, private issues, cases, appeals, files, tools, memories, and people are not extra spaces. They are objects, processes, drawers, queues, or lenses reached from the four-space shell.

Who may read or act · protocol term: AuthorityScope

Every view declares whose boundary it is inside.

AuthorityScope is the precise name for the policy, privacy, storage, and synchronization boundary around an action or selection. A scope can be device-private, account-private, community-private, Commons-public, or reference-readonly. The interface should always make the active scope and data location legible before a consequential action.

Scope is not a folder

It answers who may read, change, sync, publish, or govern an object—not where the user happened to browse.

Capabilities remain bounded

An access level may make someone eligible. A named invitation, acceptance, expiring capability, action, and receipt are still required.

Policy travels with action

Consequential records identify the policy and scope that allowed them, so later review can reproduce the decision boundary.

What matters and how it is shown · protocol terms: Context and Lens

Selection and interpretation remain separate.

Context answers “which permitted records matter now?” A Lens, shown simply as View in the product, answers “how should those records be interpreted and arranged?” Keeping them separate lets the same records be inspected without pretending one layout is truth.

Context

The permitted objects relevant to the current task: a branch, source set, selected Actors, case record, or local constellation. Context may be temporary. It does not need to become a folder or durable graph.

Lens

A declarative interpretation: renderer rules, accessibility behavior, layout family, semantic-zoom thresholds, and a deterministic seed. A model may propose a Lens configuration; it may not inject arbitrary code or control the DOM.

A View Recipe records the Context and Lens revisions, renderer, seed, camera, pinned objects, groupings, panes, and annotations. A model may compose one only as a temporary view. A person may explicitly Save view on their device, or discard it. Saving a recipe never turns geometry into knowledge. Replay reopens the recorded view. Refresh intentionally recomputes it against current permitted data.

The Fracta Canvas

Think is the mature behavioral reference; Learn extends the grammar.

Think already demonstrates the richest recursive behavior: edit a local ion in place, enter it, grow children, connect structures, keep hierarchy, and navigate without surrendering context. Its tree geometry and direct manipulation are the behavioral constitution for Fracta. Learn’s nested Venn atlas keeps its own renderer and spatial identity while inheriting the same continuity, legibility, inspection, and intent laws. The system is a hybrid of interaction grammar, never a forced merger of the tree and Venn algorithms.

Semantic zoom

Complete labels and meaningful children appear at the earliest legible scale and enlarge proportionally in both dimensions.

Stable orientation

Zoom reveals detail without randomly replacing parents, moving unrelated branches, or changing the implied structure.

Accessible equivalent

Every spatial relation has a navigable nonvisual representation. Meaning cannot depend on colour, animation, or geometry alone.

The common verbs are Zoom, Branch, Follow a connection, Focus, Hide, Compare, and Open record details. Individual spaces may expose only the verbs their authority permits.

Veins

Relationships are records, not decorative lines.

A Vein is a typed, attributable relationship assertion. It names its source, target, direction, relation type, responsible Actor, provenance, evidence, lifecycle status, governing policy, history, and—where useful—the origin of any strength estimate.

A challenge does not edit its target.

It creates a separate public artifact and a governed Vein connecting the records. Citation, derivation, authorship, containment, response, challenge, supersession, and delegation remain visibly different relations.

Shared shell

Three surfaces compress complexity without hiding it.

Next steps

A small, finite queue of suggestions. Each names its reason, what it read, who or what proposed it, what it could affect, the expected result, uncertainty, risk, and expiry. It is not an engagement feed. The protocol calls this a proposal queue.

Record details

The dependable inspection surface for record type, revision, status, responsible person or group, sources, creation history, permissions, policy, connections, receipt evidence, and actions the current person may actually take.

Intent Dock

Before submission, it shows the space, Context, selection, model location, memories and tools in scope, and whether the result will be temporary, local, or an explicit public action.

The top shell keeps the current space, who may read or act, breadcrumb, meaningful scale, View, search, sync and data location, Account, and active public identity visible. Files, memories, tools, and people remain drawers or views of shared objects rather than competing destinations. The web runtime now has a common adapter and Lens registry for file, memory, and Actor references so these drawers can converge without destructive data migration.

Bounded intelligence

AI proposes semantic intent. Syxon owns authority.

IntentWhat it may doWho retains control
@VisualizeOffer temporary presence or emphasisThe host renderer
@ComposeCompose a temporary Canvas Recipe from the current permission-filtered Context and installed LensThe host preserves each renderer’s geometry; the person may replay, refresh, or ignore it
@SuggestCreate an expiring proposal with reasons and sourcesThe person accepts, rejects, or ignores it
@NavigateRequest a Context or Lens changeThe host applies permission and accessibility rules
@ActRequest a tool or side effectPolicy and capability checks gate execution
@CommitRequest durable private or public stateThe host owns persistence; public commit always uses a doorway

Current web runtime: @Compose is now a real host tool, not only a declared command. It may seed the current installed renderer and emit a typed, non-canonical temporary Canvas Recipe; it cannot replace Think’s recursive tree law, Learn’s Venn geometry, or save the recipe itself. Replay uses the recorded seed set. Refresh deliberately rebuilds the recipe from the current permitted Context. Only an explicit human Save view action persists a recipe on the device, and that action receives a device Receipt. Any accepted suggestion that creates durable local state must also return a Receipt; missing receipts are shown as an incomplete action rather than silently treated as success.

No model gets direct authority over geometry, storage, policy, findings, votes, mandates, entity merges, or resource allocation.

AI output remains visibly proposed until the appropriate person or governed process accepts it.

The publication doorway

A local ion never changes identity into a public ION.

Local ionPrivate, addressable, recursive work in Think.
PreviewChoose fields, sources, licence, visibility, Actor, policy, and exclusions. Nothing public is written.
Signed commitA new typed public artifact and any selected signed connections receive global identifiers.
ReceiptThe server returns exactly what it accepted; the device retains the result and reconciliation state.

A published ION is one kind of public artifact. Claims, attestations, cases, evidence records, findings, policies, mandates, proposals, challenges, responses, decisions, and revocable profile projections are separate typed records. Bringing a public artifact into Think creates a new local ion with a citation or derived_from connection; it never turns the public object private.

Current runtime truth:

The web publication flow now uses Preview → signed Commit → durable local Receipt. The Global Server validates declared public-artifact shapes, verifies the current Actor’s registered device signature, issues stable addresses, and accepts signed first-class connections through a separate idempotent doorway. Safe public proof routes connect an accepted event, its receipt, and its subject without exposing private account data. Actor-authored claims, attestations, evidence, proposals, challenges, responses, and profile projections may use this doorway; cases, findings, policies, mandates, and decisions are rejected unless they come from their named governed procedure.

Implementation truth

The contract is becoming one lived system.

Active foundation

Four spaces, private recursive Think structures, the Learn atlas, public inspection and stable links, typed signed publication, durable device receipts, signed Veins, read-only corpora, Account/Actor/profile separation, object context, and bounded AI paths now exist.

Runtime joined

The shell now consumes the canonical AuthorityScope, Context, Lens, Proposal, Presence, and Canvas Recipe types rather than parallel display lookalikes. @Compose, Replay, Refresh, proposal acceptance receipts, Record details, Next steps, and the Intent Dock are joined to live web behavior. Technical protocol names remain inspectable in documentation; the visible product leads with plain language.

Not yet an institution

Live independent mirrors, mature replication, proven unique-person verification, staffed review, binding democratic governance, field operations, and safe resource mandates still require technical, legal, social, and operational work.

Never implied

The interface must not present proposals as facts, access levels as authority, reference sources as Commons truth, canvas geometry as canonical data, or AI analysis as a human finding.