Ion Protocol · v0.5 draft

Public memory that can remember how it knows.

Ion Protocol describes how connected public records, domain-specific trust, real-world verification, adversarial review, and governed action can work without turning wealth into credibility or a token balance into civic power.

Constitutional draftWorking technical spine

Purpose

The problem is not only false information. It is collapsed authority.

Most platforms blur what was said, whether it was sourced, who amplified it, whether it was reviewed, and who is authorized to act. Ion Protocol separates these questions.

A published record is not automatically true.
A source is not automatically consensus.
A witness response is not automatically a verdict.
A track record is not automatically power.
A finding is not automatically an execution order.

The protocol is post-capitalist in a precise sense: capital may provision labour and materials, but ownership of capital does not confer epistemic or civic authority.

The public object model

Public artifact first. Published ION when composition matters.

A Public Artifact is the generic protocol envelope for durable public state. A published ION is one compositional Public Artifact type: addressable, connected, attributable, versioned, contestable, and designed to be mirrored. Claims, attestations, cases, findings, policies, and mandates are different artifact types rather than decorative variations of one universal object.

Public artifact envelope
├── Core       type, content, responsible actor, time
├── Shell      signatures, provenance, policy, visibility, lifecycle
├── Children   contained or derived artifacts
└── Veins      citations, challenges, lineage, relationships, supersession

These types converge on a shared envelope—stable identity and type, responsible Actor, AuthorityScope, policy version, lifecycle, visibility, hashes, provenance, signatures, dates, supersession, redaction, and appeal references. Private Think objects are always called local ions; their existence creates no public route or public authority.

Identity boundary

Account ≠ Actor ≠ profile.

Account

Private authentication, recovery, preferences, devices, and security state.

Actor

The durable subject responsible for public action: a human, group, community, organisation, unclaimed entity, institution, tool, or service.

Profile

A narrow, revocable public projection of an Actor. Disabling it removes the profile route without deleting the Actor or rewriting history.

An Account may control an Actor only through governed continuity. An Actor may exist before anybody creates an Account, which lets private issues refer to real-world history without fabricating credentials or forcing automatic merges.

AuthorityScope

Privacy, storage, synchronization, and policy share one explicit boundary.

Every meaningful object and action carries an AuthorityScope such as device-private, account-private, community-private, Commons-public, or reference-readonly. Scope determines who may read, change, sync, publish, or govern. It is not a folder, a visual grouping, or an access-level nickname.

Eligibility is only the first gate.

Consequential authority follows a reproducible chain: eligibility → named duty invitation → accept, decline, or recuse → expiring capability → bounded action → append-only receipt.

Self-similar network

One public envelope, many typed human records.

Public knowledge should be able to grow, connect, repair, branch, and survive the failure of one steward. Ion Protocol joins published IONs, trust relationships, cases, assemblies, and mirrors without pretending every record has the same authority.

Recursive

A case can contain claims, evidence packets, field reports, questions, findings, and later outcomes while each remains independently inspectable.

Contestable

Disagreement creates challenges, replies, minority reports, appeals, or forks—not silent deletion.

Survivable

Signed packets, export manifests, and independent mirrors are intended to let communities leave captured governance with history intact.

First-class relationships

A Vein is an attributable assertion, not a line on a canvas.

Every Vein identifies its source, target, type, direction, responsible Actor, provenance, evidence, status, governing policy, history, and the origin of any strength estimate. A citation, derivation, challenge, response, supersession, delegation, authorship, and containment relation remain visibly different.

Challenges never edit the target record. They create a separate challenge artifact, a governed Vein, and an append-only Event. The Fracta Canvas may draw a Vein in many ways, but geometry is presentation rather than protocol truth.

Access is not reputation

Five clear levels describe what an account can do.

LevelHow it is reachedWhat it enables
AccountCreate a local or signed-in accountRead, learn, think privately, and manage security
Confirmed accountConfirm the account contact channelPublish low-risk work, open a private issue, and request an entity claim
Verified personAttend a consented verification event with independent reviewersAttest public work, enter civic selection pools, and vote where one-person-one-voice applies
Community reviewerVerified person plus training and a bounded grantReview identity continuity and possible entity matches
Case moderatorReviewer plus case training and a bounded grantTriage private issues and administer case procedure

Levels grant abilities; they do not measure human worth. Domain track records remain separate. Reviewer and moderator grants expire and can be revoked or appealed.

Eligibility is not assignment

Consequential work begins with one named invitation.

Eligible poolTraining and a current access grant make someone selectable.
Duty invitationOne task, one person, one expiry, and a committed selection record.
Conflict responseAccept, decline, or recuse without losing access.
Scoped capabilityAcceptance issues an expiring key for only that subject and its allowed actions.
Bounded actionThe server verifies the duty and key on every request, then records completion.

The current server enforces this chain for verification endorsements, entity-claim reviews, entity-match reviews, private-issue triage, and formal case, field, and appeal review. A moderator sees only opaque references in the unassigned pool; eligibility or custodian status alone never opens private case material. The selected person must sign acceptance, and every private case request must present both the accepted duty and its matching active, case-scoped capability. Every invitation and response is append-only. Invitations currently appear inside the account; email or push delivery is not yet connected.

Issues before accounts exist

An unclaimed Actor can have history before it joins.

A confirmed Account can privately raise a correction, conduct concern, safety report, resource-misuse concern, identity conflict, or public-accountability issue. If the person or organisation has no Account, the system creates an unclaimed Actor. This does not publish an accusation.

  1. The system compares permitted names, aliases, type, and public identifiers and creates private match candidates.
  2. It never merges Actors automatically; an authorized reviewer records the decision and reasons.
  3. When somebody later claims an Actor, reviewers check continuity and public identifiers.
  4. An accepted claimant sees the relevant private history and may accept or dispute the proposed continuity and history.
  5. Only a separate formal case—with notice, reply, evidence review, and release gates—can create a public accountability record.
  6. Moderator status may assign a case but cannot open it. Private material requires the named person to accept that exact duty and hold its active, case-scoped, unexpired CapabilityGrant.

Change through time

Public records are not silently overwritten.

The shared lifecycle vocabulary is deliberately explicit:

created → amended → challenged → reviewed → released
                   ↘ withdrawn / rejected
released → superseded / redacted / tombstoned

Withdrawal does not erase that a record existed. Supersession shows which record is current and preserves what changed. Redaction must preserve enough public trace to explain that governed removal occurred without republishing protected content.

Stable public objects

Identity comes from the record, not the current website.

The protocol target is content addressing from a canonical public form:

artifact_hash = SHA-256(canonical_json(public_artifact))

Current Syxon public links use stable server identifiers while the event-sourced heap and content-addressed projection converge. Published IONs, visible profiles, and reviewed civic cases have durable browser routes; local work and private case intake do not.

ObjectCanonical browser routeVisibility rule
Published ION/ion/<ion-id>Public or exact-link unlisted
Visible profile/profile/<actor-id>Appear in Connect enabled
Reviewed case/case/<case-id>Accepted human finding exists

Distribution

A signed Public Artifact graph, not a speculative blockchain.

Ion Protocol does not need proof-of-work, a tradeable token, or one-token-one-vote. It needs signed public records, deterministic procedure, content-addressed packets, reproducible tallies, and independent mirrors.

Foundation exists

Exports and mirror preview

The server can emit signed, content-addressed heap packets, lens policies, and release manifests. Imports fail closed when signatures do not verify.

Designed next

Independent replication

Community nodes, interest-scoped gossip, multi-node release governance, key rotation, packet revocation, and applied mirror imports remain future work.

Proposed peer roles are light clients on phones and browsers, community nodes replicating selected domains, and steward nodes maintaining larger public subgraphs and bounded public-service compute.

Constitutional boundaries

The public contract.

  1. Private work remains private. Thinking, drafting, files, and Local AI begin on the device.
  2. Publishing is deliberate. A local ion never becomes public by changing visibility; the doorway creates a separate Public Artifact with a new global identity.
  3. Sources are context, not consensus. A corpus, report, sensor, archive, or article can inform without deciding.
  4. Trust is domain-specific. No universal score of worth, morality, loyalty, or social desirability.
  5. Reputation is evidence, not office. Consequential power requires a scoped, current, expiring capability.
  6. Power requires presence and procedure. High-impact decisions need current participation, conflict disclosure, questions, and independent checks.
  7. AI proposes; hosts and humans authorize. Models may prepare semantic intents, evidence packets, questions, or draft lenses. The host owns geometry, policy, persistence, and tools; accountable humans own findings and governed decisions.
  8. Everything consequential is contestable. Claims, selection, standing, findings, and mandates need challenge and appeal paths.
  9. Constitutional equality stays visible. System rules use one verified human, one vote.
  10. Labour can be paid; outcomes cannot. Public servants can be compensated, but a party cannot buy a verdict.
  11. Exit remains possible. Public procedure must be independently inspectable, mirrorable, and forkable.

Hard refusals

What Ion Protocol must not become.

Forbidden

Social credit

No global person score, moral rank, reputation wallet, or leaderboard.

Forbidden

Plutocracy

No vote, verdict, trust, or public identity purchased with capital or transferable tokens.

Forbidden

AI sovereignty

No automated truth, guilt, personhood, jury outcome, mandate, or resource execution.

Forbidden

Silent authority

No private source processing, operator key, or internal score quietly becoming canonical public memory.

Canonical source

Where the formal detail lives.

The repository document Production/ION-PROTOCOL.md is the constitutional and architectural source. Implementation truth is narrowed by SYXON-SYSTEM-BOUNDARIES.md, the trust and civic-case contracts, route exposure audits, and focused executable checks.