Version. 0.1
Date. 2026-08-06
Author. Claude.ai (drafting session). Operator: Marvin Percival.
Applies to. candidate-seeds/loomworks/loomworks-candidate-seed-v0_12.md.
Produces. loomworks-candidate-seed-v0_13.md and its HTML companion. v0.12 is not edited — it moves to archive/ per the seed's own version discipline, and this document is the record of what changed.
Build-list item. B-16.
Status. Drafted for the Operator's reading. Committing a seed version is an Operator act — the seed's own Authorisation section places engagement-scoped decisions with him, and B-16 has always said the commit waits on his approval.
What this carries: the three riders queued for v0.13.
One — the held-until-admitted gate extends down to engagements. Seed v0.12 describes it for shared scopes only. CR-2026-157 built it for outside contributions into an engagement.
**Two — the seam is in place is posture, not fact.** It was written as a statement about the architecture and reads as a statement about the build.
Three — OVA no longer holds the authorization seat, and there is no access-control list anywhere. Architecture Decision J1 (June 2026) puts GRANTHA there, with grant as the sole primitive, no ACL, no group object, and a holder-set that is never readable. OVA sits underneath for blind verification. Seed v0.12 predates J1 and commits to the mechanism J1 replaced.
> A correction to the count. The rider was recorded as four places. There are five. The fifth is in the Identity section — it is what OVA authorizes against — which is a different claim from ACL-restricts-scopes and equally superseded. Counted directly from the text, not carried from the earlier note.
Replace:
# Loomworks engagement — candidate seed v0.13
(and the version, date and status block beneath it)
With:
# Loomworks engagement — candidate seed v0.13
**Version.** 0.13
**Date.** 2026-08-06
**Status.** Thirteenth version. Replaces the access-control-list model with the grant model: architecture Decision J1 (June 2026) placed GRANTHA in the authorization seat, with grant as the sole primitive, no access-control list and no group object, and OVA underneath for blind verification. Seed v0.12 predates J1 and committed in five places to an ACL established through OVA; v0.13 corrects all five and names the superseded position alongside, per Discovery-record discipline. Also extends the held-until-admitted contribution gate down to the engagement scope, which CR-2026-157 built, and restates "the seam is in place" as the posture it is rather than the fact it reads as. Carries forward v0.12's two-tier sign-up posture, v0.11's contribution access axis, and v0.10's widening of Memory to N-scope. Preserves v0.12 structure and language wherever still correct.
[EXECUTING SESSION: the title line in v0.12 reads # Loomworks engagement — candidate seed v0.12. Replace both the title and the block beneath it as one unit.]
This is the largest change and it carries two riders at once.
Replace the whole paragraph beginning:
> A scope's Memory is reachable in one of two access modes.
…through its end at:
> …an open scope is open by design, not merely un-restricted because the control layer is absent.
With:
> A scope's Memory is reachable in one of two access modes. By default a scope is open — reachable by any engagement, any Operator: this is the "all" mode, and it is the default precisely because a knowledge commons compounds when its knowledge is open. A scope becomes restricted when reach to it is placed under grant; from that point GRANTHA governs who may reach it, and the scope is reachable only by a holder presenting a valid grant. Restriction is therefore a deliberate, recorded act — placing the scope under grant — not a default. Open is the default; closed is the exception. > > The grant is the sole primitive. There is no access-control list and no group object. Authorization is not a question of whether a name appears on a list; it is a question of whether the party acting holds a valid grant for this scope and this act. The holder-set is never readable — the system can answer whether a grant is held, and cannot enumerate who holds one. This is a substantive commitment, not a naming choice: a list can be read, copied, and leaked, and a grant model has no list to read. > > Enforcement is not yet built, and this seed states that as posture rather than fact. While GRANTHA does not yet enforce, every scope is effectively open. The access mode is declared and the enforcement seam is anticipated in the architecture — the code carries a stub where the consultation will sit. It is not in place in the sense of being wired and holding. When enforcement lands, scopes placed under grant become restricted and the rest remain open. This must hold both ways: the system supports restricted scopes (grant-governed under GRANTHA) and open scopes ("all"), and the two are not the same — an open scope is open by design, not merely un-restricted because the control layer is absent.
Replace:
> For an engagement, contribution is straightforward — the engagement's own contributors write into it.
With:
> For an engagement, contribution is ordinarily straightforward — the engagement's own contributors write into it. But an engagement also accepts contributions from outside its membership: a person holding a credential issued for that engagement may contribute into it without becoming a member of it, and such a contribution is held until a member with commit authority admits it or turns it away. The gate is the same gate the shared scopes use; what differs is only what stands outside it — a non-member rather than a contributor outside a trusted core.
[EXECUTING SESSION: place this replacement so the paragraph continues into the existing sentence beginning "For a scope shared across engagements…". The two now describe one gate at two scopes rather than two unrelated arrangements.]
Replace:
> a Memory scope is reachable by all until an ACL restricts it (reach)
With:
> a Memory scope is reachable by all until it is placed under grant (reach)
Replace:
> it is what OVA authorizes against.
With:
> it is what GRANTHA authorizes against, and what OVA verifies against blindly beneath it.
Replace the whole constraint, from its heading through:
> …open is open by design, not a placeholder for an absent control layer.
With:
> Leverages FORAY, GRANTHA and OVA. FORAY for tamper-evident anchoring of transitions. GRANTHA is the authorization substrate — the grant is its sole primitive, there is no access-control list and no group object, and the holder-set is never readable. OVA sits beneath GRANTHA for blind verification (provisional patent filed March 2026): it answers whether a grant holds without learning who holds it. The access model for Memory scopes has two modes and supports both: open ("all" — the default, reachable by any engagement) and restricted (placed under grant, with GRANTHA governing reach). A scope is open until it is placed under grant; placing it under grant is the deliberate, recorded act that restricts it. Until GRANTHA enforces, scope access runs through the seam-marked stub the architecture anticipates and every scope is effectively open — but the two modes are distinct commitments, and open is open by design, not a placeholder for an absent control layer. > > The seed's prior position, preserved: v0.12 and earlier named OVA as the candidate access-control substrate and committed to restriction by an access-control list established through OVA. Architecture Decision J1 (June 2026) replaced that seat. The substitution is not a rename — GRANTHA has no ACL and no group object at all, where the prior model's restricting act was the establishing of a list.
Replace:
> Memory at scopes above the engagement follows the two-mode access model above: open ("all") by default, restricted when an ACL is established through OVA.
With:
> Memory at scopes above the engagement follows the two-mode access model above: open ("all") by default, restricted when the scope is placed under grant.
Insert after the existing v0.10 and v0.11 Discovery-record notes, as a third:
> What changed from v0.12, and why (Discovery-record note). v0.12 committed, here and in four other places, to restriction by an access-control list established through OVA — a list, established as a deliberate act, with OVA governing reach from that point. Architecture Decision J1 (June 2026) replaced that model, and v0.12 was written on 2026-06-07 without absorbing it. GRANTHA holds the authorization seat; the grant is its sole primitive; there is no access-control list and no group object, and the holder-set is never readable. OVA remains, beneath GRANTHA, as the blind-verification layer. The prior position is not a wrong description of a mechanism that existed — it is a commitment to a mechanism the architecture replaced, and it stood in the foundation document for two months after the replacement. > > v0.13 also corrects a sentence that read as fact and was posture. v0.12 said the enforcement seam "is in place." It is anticipated in the architecture and stubbed in the code; it is not wired and holding. The distinction matters at exactly the moment someone relies on the seed to say a restriction is enforced. > > And v0.13 extends the held-until-admitted gate down to the engagement. v0.12 described it for shared scopes only, and said engagement contribution was straightforward. CR-2026-157 built the outside-contributor pathway: a credentialed non-member contributes into an engagement and the contribution is held until a member with commit authority admits it. The seed's trust-graph language was arguably scope-general already; the extension deserves a sentence rather than an inference.
Replace the heading ## Drafter's notes for v0.12 with ## Drafter's notes for v0.13, and insert this above the existing v0.12 content, which is then preserved beneath a heading of its own:
> v0.13 carries three riders queued against v0.12. The changes and their reasoning are recorded in the Memory section's Discovery-record note. In brief: > > 1. OVA → GRANTHA, and ACL → grant. Five places in v0.12 committed to an access-control list established through OVA: the Memory access-modes paragraph, the Sign-up section's three-layer parenthetical, the Identity section's what OVA authorizes against, the FORAY/OVA constraint, and the public-Memory constraint. All five are corrected. The prior position is named alongside rather than deleted, per the seed's own corrections-preserved commitment. The rider was recorded as four places; it is five — counted from the text. > > 2. "The seam is in place" restated as posture. The sentence described what the architecture anticipates and read as a statement about what the build has done. Corrected in both the Memory section and the FORAY constraint. > > 3. The held-until-admitted gate extended to the engagement scope. One sentence in the Memory contribution paragraph, naming what CR-2026-157 built. > > What v0.13 does not do. > > - It does not touch the drafter's notes preserved from v0.11. Those record what v0.10 and v0.11 committed and are history. Correcting them would erase the trajectory the seed exists to preserve — the record should show that the seed held the ACL model and then left it, not that it never held it. > - It does not specify how a scope is placed under grant, who may place it there, or what a grant's shape is. The seed commits the model; GRANTHA's own specification governs the mechanism, as the seed defers the trusted-core admission mechanism and the cross-scope composition rules. > - It does not absorb the provenance-threads candidate, which was queued against the seed separately and is not one of these three riders. It remains queued. > - It does not resolve whether the enforcement seam should be built now. v0.13 states honestly that it is not, which is a different act from scheduling it.
Then, beneath, retitle the existing v0.12 notes as ### Drafter's notes preserved from v0.12 and leave them unaltered.
Replace:
Loomworks candidate seed — v0.12 — 2026-06-07
With:
Loomworks candidate seed — v0.13 — 2026-08-06
Produce both the Markdown and the HTML companion — the seed's own declared render-type is HTML primary with Markdown companion.
Move loomworks-candidate-seed-v0_12.md and its HTML to candidate-seeds/loomworks/archive/, matching where v0.8 through v0.11 already sit.
Do not commit until the Operator has read v0.13 and approved it. Committing a seed version is his act. Stage it, report, and stop.
ACL, access-control list and access control list — every remaining occurrence must be inside a preserved-prior-position note or the v0.11 drafter's notes.OVA appears only where it is correct — beneath GRANTHA as blind verification, or in a preserved prior position. It must not appear as the authorization seat.the seam is in place does not appear as a live claim.archive/ and unmodified.DUNIN7 — Done In Seven LLC — Miami, Florida Loomworks candidate seed v0.12 → v0.13 — amendment instructions — v0.1 — 2026-08-06 The foundation document has named the wrong authorization mechanism for two months.