The formal version · v1.9 draft

The EDEN White Paper

The full design: how money is minted, routed, governed, and defended — every result graded and every open question labeled.

White Paper — Version 1.9 (Draft — the Corporate, Custody & Accountability Release; awaiting owner ratification)

July 18, 2026 · Author: Devan Allen · v1.9 layer drafted from the July 17–18 corporate/custody/accountability program (Claude Fable 5, owner-directed); v1.8 body (July 11, Opus 4.8) carried intact below

STATUS: DRAFT — AWAITING OWNER RATIFICATION. UNREVIEWED (AI-PRODUCED). This release was compiled by an Anthropic model (Claude, Opus 4.8) integrating the vault's committed record; it has had no out-of-family human review. Per the program's standing rule — in-family; verify, don't trust — every number below traces to a committed artifact, but AI review of AI-built work is weak evidence and the two standing non-model obligations (hostile economist review; field measurement of willingness-to-pay) remain open. Treat this as a research draft to be attacked, not a finished spec.

This release consolidates three bodies of work that landed after v1.7 (July 7): the substrate/architecture adversarial program (04 Simulations, sims v11–v15 against 01 Canon/EDEN Protocol Architecture v0.1, plus the machine-checked proofs artifact); the multi-sponsor federation build (EVE Sim v6.8, discharging the v6.7 IOU); and the economics-literature red-team with its canon notes (EDEN Red-Team — The Economics Literature vs EDEN, spawning the EBI Methodology, Incidence, Monetary-Position and Cross-Check specs). It further folds in the July 9–11 sweep (v16–v34, the banking-and-savings layer, the decision-support cells v31/v32, and the index-drift and Baumol cells v33/v34), and — most consequentially for honesty — the three verification passes (v2/v3/v4) and the gate-tightening recode (Backlog #4b), which re-scored several passing results downward. It is structured as the program's releases always are: a complete changelog, then drop-in amendment text for every affected section, then a consolidated Evidence Base reflecting the current, corrected record. Sections not amended here stand as written in v1.5/v1.6/v1.7, which are preserved unedited. The normative spec remains 01 Canon/EVE Algorithm v1.4 - Ratified Spec as amended by the July 10 ratifications (Velocity Defense v1.4, EBI Methodology, Monetary Position, Banking & Savings Layer, EBI Cross-Check Addendum), catalogued in the current-canon section below.


Changelog — v1.8 (the substrate, verification & consolidation release)

The headline change: the program stopped adding claims and started subtracting the ones its own tools could no longer support. v1.6 opened the economy; v1.7 attacked its defenses; this release does two things at once. It descends a layer — from the currency mechanism into the substrate the mechanism runs on (civic validation, the proof-of-engagement pipeline, the price oracle, cross-layer composition, the governance cap function, and the banking-and-savings layer canon previously lacked) — and it audits itself twice (Verification v3 and v4, then a gate-tightening recode), with the result that the record got worse-looking and more true. Six previously-clean results now carry registered failures, one whole model (ecology) resolved negative, and one flagship rigor artifact was reconciled from three contradictory tallies to a single one with grade labels. Everything below is stated against the post-correction record; where an earlier number circulated, the correction is carried in place.

What v1.8 folds in, concretely:

(1) The substrate/architecture program (v11–v15) — NEW EVIDENCE, five gate candidates. Civic validation by sortition (v11) survives capture at budgets the program takes seriously (cheapest safety capture ~$613M, 20× the v9 attacker) — with the honest surprise that the binding wall is honest-pool size (H* ≈ 5,500 volunteers), a live public gate quantity like reserve months. The proof-of-engagement aggregator pipeline (v12) is policed by light private-sample audit (break-even 0.62% of batches) provided payouts vest (168 epochs); the oracle (v13-Oracle) is sabotage-only-not-theft (faking the index costs $99.5M at an 80× cost/payoff loss) but fails two registered bars honestly — re-validation speed is the load-bearing safety parameter (delivery dips to 0.888 under the pessimistic triple-combo, O3c FAIL; the essentials lane clears the 5× "expensive fake" bar only at 4.3×, O4 FAIL). Cross-layer composition (v14) fails two bars as the finding: one adversary wearing four hats pays 0.66× the separate cost and composes the identity blast radius past the 2% gate (1.37% → 3.74%) — closed by a single 15%-combined cross-layer cap (X4). The governance cap function (v15) is robustly non-plutocratic (a 30% whale squashed to ~1%; majority needs ~1,595 colluders) and caught a real flaw in itself — the single-pass cap leaked to 9.4%, forcing an iterative water-filling v0.2 that holds it at exactly 5.00%. Gate candidates 15–19 surfaced; each prices the mechanism around the identity keystone and says so.

(2) Multi-sponsor federation (v6.8) — the v6.7 IOU discharged. Escrow (≥6 months, = the step-up lag) plus a single-sponsor share cap (≤40%) turns v6.7's catastrophic −92% single-sponsor exit into a −9.9% ripple (the currency actually rises), delivery unbroken, zero printing. J4 FAILED and matters: "cheaper than welfare" is a peacetime number — the survivor who backstops a mid-storm collapse sees its saving compress from ~24% to ~9% and carry to 2.7%, so the backstop obligation must be priced. Federation is the ratified end-state for the sponsor layer; escrow and the diversification cap are canon terms.

(3) The economics-literature red-team + its canon notes. The ten strongest published objections (Lucas, Hayek/calculation, Boskin index bias, Goodhart, Myerson–Satterthwaite incidence, Krugman/Obstfeld crisis models, Mundell/Oates OCA, unit-of-account inertia, Arrieta-Ibarra data-valuation, Baumol) were argued at full strength and scored honestly. The scorecard's owed instruments have since largely been built: the EBI Methodology Spec (chaining + bias budget — the pass's top item), the one-page Incidence Note, the Monetary Position Note (EVE claims the EBI as numéraire, not a unit-of-account takeover), the EBI Cross-Check Addendum, and the owed cells (v16 Lucas sweep, v17 composition, v18/v19 crisis, v20/v32 OCA-exit, v33 index-drift, v34 Baumol). The current standing is stated below with its known counting discrepancy carried, not hidden.

(4) The verification passes (v2/v3/v4) + the gate-tightening recode (Backlog #4b). Two full re-execution passes (v3, July 9; v4, July 10–11) confirmed the mechanical layer is honest — code regenerates JSON, JSON backs prose, every registered failure recorded — but found the passing side uneven: hardcoded sanity gates, tautological checks, and four write-ups that had gotten ahead of their runs. The July 10–11 fixes moved the scoreboard in both directions. The gate-tightening recode (July 11) then converted the disclosed-but-hardcoded gates into computed ones without moving a single registered bar, flipping four verdicts honestly: - v18 Y4 → FAIL (refuted expectation: the registered interior optimum τ* ≈ 2–3% is refuted; the frontier is τ-degenerate and τ* lands at 5%). The mechanism is unweakened for drain-bounding — canon τ = 3% rests on Y1 (PASS on a computed clause) — but the tuning expectation was wrong in public, and the v5 re-score (July 12) flipped Y0 too: its false-quarantine clause, scored across the full registered σ_xc sweep {0.5%, 1%, 2%} instead of the central dial only, FAILS at σ=2% (12.5% of months vs the 5% bar) — so τ=3%'s quarantine comfort is σ-conditional (fine at ≤1% honest noise, or with the coded median smoothing). - v21 K4 → FAIL (scored against the registered 6% political bar, which no split clears; the "closes within 24 months" clause is now a disclosed non-result). This strengthens gate-22 — it is the measured reason to pre-commit the taper/slice split. - v26 Q5 → disclosed non-result (stipulated_not_computed: the engine models no origination-refusal, so contract-freedom scores are stipulated, not measured). - v28 SB2 → disclosed non-result (detection_assumed_not_measured: the "detection" number echoed an assumed input; the engine has no velocity/graph model).

(5) v33 Index Drift — the bias budget is not enough against systematic drift. A fixed 0.05 measurement-bias budget cannot absorb a persistent ±0.5pp/yr EBI drift: a one-directional under-read exhausts the budget in ~9.3 years and leaves the floor at 0.856 of essentials by year 50 (ID1); the mirror over-read drains the reserve in 2.5 years while the §5 instantaneous-rate telemetry only lights at 9.8 years (ID2 — a level trigger watching the wrong quantity). Actionable: the binding re-basing cadence is set by the reserve side (~2.5 years), not the delivery side (~9–10 years) — canon's 5-year re-basing is delivery-safe but reserve-unsafe (ID3). Amends EBI Methodology §5.

(6) v34 Baumol Governor Drift — index the floor to essentials; index the governor to the EBI and sunset c_min. Over a century, an aggregate-productivity-tuned governor drifts against the slow (care/essentials) sector: essentials inflate to 3.74× while the governor's own gauge reads flat (BM1). EDEN's essentials-indexed floor delivers a full 1.10× basket every month of the century where a naive aggregate-CPI floor breaches at year 8.8 and collapses to 0.20× by year 100 (BM3) — indexing the floor to essentials is what disarms Baumol for recipients. But two bars fail as findings: Baumol delays the v7 generational-floor crossover from year 46 to year 92 (BM2), and essentials-indexing the governor cuts drift 62% but only a post-bootstrap c_min sunset removes it entirely (BM4). Canon candidates: index the governor to the EBI and sunset c_min once machine-pay matures; keep the floor on essentials.

(7) v16 extension (#9) — the layer sweep and the FAIL-tier WTP sensitivity. With v12/v13-oracle/v14 refactored, the Lucas envelope now sweeps those three layers too (v14's joint-cap fix holds 32/32; two dial-local findings reported, gate-18 unaffected). The sharpest honest result: at anchors ÷10 ($60-world), EDEN's safety promises survive (sponsor-backed floor delivery 0 months below; cheaper-than-welfare ratio WTP-invariant at 0.785) but its builder-economy/self-funding promises break (median builder $420 → $45/mo; share clearing $200/mo 88% → 3%; endogenous floor coverage ~13% → 7%). The data-valuation gap made quantitative: what is WTP-fragile is exactly what the pending field experiment (H1) must settle.

(8) v31/v32 — the austerity floor re-ratified and the payer-exit rule found. v31 swept the sponsor recession-payment floor × escrow depth jointly and resolved the two open UNCERTAINs negative: escrow is inert against austerity (it pays at exits, not underpayment), so the "≥50% + deeper escrow" candidate is dead; ≥0.60 holds delivery in both seeds → re-ratify gate-20 at ≥0.60, escrow unchanged at 6 months. v32 resolves v20's payer-exit countdown: you cannot bill the survivors (a slice-bump alone needs +80.2% of givers' burden vs the 6% bar, RB1 FAIL); the taper is the humane tool (a mixed rule — 6%-capped bump + 41.2% taper — closes the $3B/mo hole at 0.956 delivery), and the 9-vs-24-month reserve question is really an 18-vs-48-month diplomacy budget.

(9) The ecology resolution (v13.1) — RESOLVED-NEGATIVE. The provisional ecology model (v13.0) failed its own harness-trust gate; the regression-gated rebuild (v13.1, 68/68 legacy bars reproduced exactly) answers the funding question: the ecology-era floor is structurally unfundable at the registered dials — the funding streams carry 2–5% of obligations, a labeled jump-start proves it is not a bootstrap gap, and obligations eventually exceed the model's entire settlement volume (a 100% tax could not fund it). Zero printing throughout (the old 2,163× inflation was pure floor-printing, now removed). This forces a canon-level purse-vs-promise-vs-subsidy decision now in the ratification queue; the white paper cannot assert an ecology-era floor until one of the three is ratified and re-run.

(10) Canon ratifications and the Decision Record. Since v1.7, the owner ratified (provisionally, pending economist + out-of-family review): progressive-by-size demurrage (A2) as Velocity Defense v1.4; the full-reserve banking direction with a FREE-market credit side plus a universal right-to-exit (Banking & Savings Layer Spec v0.1); the EBI Methodology, Monetary Position, Incidence, Governance Cap-Function, Oracle Protocol, and Cross-Check notes. Every choice, its roads not taken, its revisit-triggers, and its reversal path are logged in 00 DECISION RECORD (DR-01…DR-17). The settlement-slice transient is DEFERRED; the cross-check τ is HELD at 3% pending a tuning sweep.

v1.0–v1.7 preserved unedited. The July 9–11 program: 24 registered SPECs across the window (v11–v34, several owner-directed same-day), a machine-checked proofs artifact (10/10 with grade labels), a proving-cost desk benchmark, two full verification passes and a gate-tightening recode, one model resolved negative, and — the count that matters most — eleven registered bars failed and all eleven are on the record as failures, with six more re-scored to failures or disclosed non-results by the verification discipline. All code/JSON/figures public with plain-language companions throughout.


Part A0 — The v1.9 layer: corporate participation, ownership registry, data custody, and the accountability commons (July 18, 2026)

Everything in this section was decided and evidence-backed on July 17–18, 2026: five Decision Record entries (DR-18…DR-22, all owner-ratified, provisional per the standing convention), five simulation cells (v35–v39, all SPEC-before-code with pre-registered bars; three of the five recorded refuted registered expectations, filed as findings), and one funding-mix extension. Roads not taken are preserved, shovel-ready, in 00 DECISION RECORD; every number traces to the committed results_v3x.json files.

A0.1 — Corporations: coordinators, never owners (DR-18; v35). A corporation cannot pass the human-minting event, so it can never be the mint-anchor of EVE income. It organizes work and takes a capped coordinator's share (25%); commissioned assets carry a 30-year commercial term and commons-ify at min(contributor death, term); outside capital enters via non-transferable, time-limited revenue shares. Evidence: naive corporate ownership rebuilds dynastic persistence to 77.1% (worse than the 67.7% buyable-catalog counterfactual); the ratified rule set holds it at 10.5% vs the 10.4% mobility line with the full registered attack battery running, at ~2/3 of naive corporate participation. Chosen over: naive ownership, permissive equity under the demurrage stack (contains dynasties only by negative carry — exclusion in market clothing), and hard exclusion.

A0.2 — The ownership registry: register to own, registrations are deeds (DR-19; v36 + mix extension). An entity holds income streams only through registered, human-rooted owner links; the link is the title record (only the linked owner can reassign it — a defecting nominee keeps the shell, which is what makes straw owners expensive); the aggregation gate closes transitively to human roots; enforcement = a refundable flow-scaled link-bond (≈1×; honest cost ~4%/yr carry) + a provenance-anomaly audit (floor a_n ≥ 0.05/yr). Evidence: the payout-only variant fails (whales consume through unlinked shells at 9.46× the cap, audit-immune); the strong form takes blind shell-evasion from 24.7× to ~1.2×. Anonymity is preserved: the anchor is one verified, living, unique human — a name attaches only at the fiat bridge. Entity read-logging was measured and declined (public state is unmeterable — 95% evasion via mirrors; every paid query is already a public flow). Chosen over: payout-gate-only, revocable links (reopen evasion 4–14×), fee-primary funding (flat tax on honesty; cannot target nominees).

A0.3 — Public floats and funds: threshold look-through (DR-21; v38). Intermediated ownership resolves by threshold look-through at θ = 5%: bonded, KYC'd qualified intermediaries must pass through any ultimate holder at ≥5% of an entity; the sub-threshold float terminates at the intermediary (a legitimate accountable root — termination re-roots aggregation, it never breaks it). Officer/controller links are title-class — the load-bearing choice: it closes the hidden-empire channel at zero marginal audit (a_c* = 0.0), where revocable officer governance would need 0.162/yr of empire detection. Wolf packs of genuinely distinct humans multiply nothing the ownership gate polices (increment 0.0) — concert harms belong to the governance/market-power layer by design. Chosen over: unconditional terminate-at-fund (fund-washing at 3.3–7.2×) and full look-through (institutional participation collapses to 0.41).

A0.4 — Data custody and pricing as one system (DR-20; v37). The pay-once-copy-forever attack is real: under per-access terms a full corpus copies for ~1.6% of its living-stream value. The defense matches custody class to freshness half-life (boundary τ* ≈ 4.35 yr): short-lived data sells under export license (the copy rots — stolen snapshots hold 0.1–7% of a live subscription's value); long-lived archives (genomics-class: a copy is still ~85% as useful a decade later) never leave — compute-to-data, queries in, answers out, per-buyer egress budgets on a rising curve (reconstruction ≈ 500× an honest subscription), budgets aggregated across commonly-owned buyers. Pricing: the non-waivable, essentials-indexed minimum ask is confirmed load-bearing (without it, seller competition collapses the price to ~5% of the revenue-optimal reserve; ~90% would undercut if allowed) — but a floor alone feeds theft (the thief's resale margin rises with the honest price); only custody starves it. The recommended fair rate is published, never binding (price oracles get captured). Terminology fixed network-wide: the floor = the essentials guarantee; the minimum ask = data's price minimum. Chosen over: status quo, floor-only, DRM, single custody class, binding oracle, waivable floor.

A0.5 — The conduct-claim class: the whistle market (DR-22; v39). EDEN's rails compose into an accountability market about outside entities: pseudonymous claims + attested evidence + claim bond + the accused's counter-window (non-adopters answer without joining) + sortition-jury verdicts (substantiated / unsubstantiated / unverifiable as an honest third) + truth bounty / slash-on-false. Evidence: the market separates (truth profits, lies ruin) across 54.6% of the searched bond/bounty grid, tolerating jury error to ε* = 0.639; flooding self-bankrupts; extortion threats are empty. Launch at (B, β) = (2.0, 0.5), low-bond (sponsors proved counterproductive at low bonds). Two structural properties: certified capture (transparent, unmodifiable recording straight into EDEN) removes the authenticity half of jury error and is the armor against improving AI forgery — but the market separates even without it; and account-silence is constitutional-class — the platform cannot confirm whose account disclosed (the anonymity set is the discloser's protection: rational disclosure at knower-sets of ~7 under typical retaliation). Two limits stated on the label: small-circle disclosers against ruinous retaliation remain at risk no bounty fixes, and short-and-distort is irreducible (off-protocol positions are invisible; bounded only by adjudication speed — securities law's handoff). Rollout is staged and governance-gated per the new PRE-MORTEM obituary #7 ("the leak that got it banned"). Chosen over: no conduct class, high-bond + sponsor infrastructure, waiting for capture-hardware ubiquity, confirmable accounts, and out-bonding the shorts.

Evidence-base addendum: the registered suite now runs v1–v39; the July-18 cells were verified by isolated re-execution (byte-identical, anchor chains re-run exactly) in VERIFICATION v6, with its same-thread independence caveat disclosed — the out-of-family pass remains the standing ask.


Part A — Drop-in amendments by section

§5–§6 (extends) — The substrate is now specified, and priced against attack

v1.5's §10 argued that "the substrate is the product." The substrate now has a canonical spec — 01 Canon/EDEN Protocol Architecture v0.1 — and its four trust surfaces have each been red-teamed under registered bars:

The defeater carried on the face of all three: each prices the mechanism around the identity/liveness keystone (registry rot, rental prices, forgery ceilings are dials; gates 9/14 are unmoved). Sortition over sock-puppets is no defense; only the pilot prices the puppets.

§7.4 / §7.7 (amends) — Demurrage is now progressive-by-size (Velocity Defense v1.4, A2)

The flat 5%/yr carry cost is retired. EVE Sim v24 measured that it landed on ordinary savers — a median household (~4 months' savings) paid ~$67/yr = 2.8% of wealth, and 67% of people paid a meaningful amount. The ratified replacement (Velocity Defense v1.4, owner decision July 10) is a marginal, band-by-band schedule on idle non-floor surplus, measured in months-of-essentials:

Idle surplus (months of essentials) Marginal annual demurrage
0 – 6 months 0%
6 – 24 months 2%/yr
24 – 120 months 5%/yr
above 120 months 8%/yr

Ordinary savers pay $0 (the fraction paying > 0.5%/yr of wealth falls 67% → ~28%); the top idle decile still pays ~4.8%/yr effective (above the 3% deterrence bar); circulation is preserved. All v1.3 exemptions (essentials floor, verified essentials purchases, small balances, money-in-motion), the ~2%/yr background inflation nudge, the 3× stress multiplier, and term-locks as the voluntary no-carry savings vehicle are unchanged; receipts still recirculate to the floor pool. The exemption threshold and band rates are pilot calibrations (hoarding elasticity is a field unknown); the structure is the ratified commitment.

§7.10 (replaces v1.6 text) — The banking & savings layer: full reserve, free credit, guaranteed exit

v1.6's §7.10 wrote fiat lien-credit into canon; the owner-directed banking wave (v25–v30) supplies the layer canon lacked, consolidated as Banking & Savings Layer Spec v0.1 (proposal grade). The load-bearing invariant: a bank is a lender, market-maker, and custodian — never a money-creator; broad money always equals what the mint governor issued. The fork was decided by measurement (v25): fractional reserve multiplies broad money to 6.4× the governor's target (20× at rr = 3%), drives +540% credit inflation the governor cannot see, reintroduces bank runs, and amplifies shocks 1.8× — a direct contradiction of EDEN's core control mechanism. Full reserve gives up the printing, not real lending: against sound first-round intermediation, a full-reserve system plus an active term-lock market recovers 44% at 40% lock-share and 67% at 60% (N4, honestly reframed).

§7.5 / §14 (amends v1.6 text) — Federation is the ratified sponsor end-state; escrow and the diversification cap are canon terms

v1.6 named escrow, a demand-diversification gate, and multi-sponsor federation as the target; v6.8 built and priced them. Escrow ≥ 6 months (= the step-up lag) plus a single-sponsor share cap ≤ 40% turns v6.7's −92% single-sponsor exit into a −9.9% ripple (the currency rises — escrow severance bridges the lag), delivery unbroken, zero printing; the compound storm (recession + austerity + mid-storm exit + contagion + chronic delay) passes on a designed-thin margin (delivery trough 1.062, drawdown 42%, recovery 4 months). The measured walls: cap* = 0.40 (at 100% share even with escrow, 59 months below floor — escrow buys months, the cap carries the currency); E* = 6 months (E = 0 → 4 months below floor). J4 failed and amends the pitch: the "26% cheaper than welfare" figure is a peacetime, funder-level number; a survivor absorbing a lapsed sponsor's share mid-storm sees its saving compress to ~9% and carry to 2.7% (both bars breached) — federation overhead concentrates on whoever backstops a collapse, so the backstop obligation must be priced into accession contracts. Cascade politics (24 draws): 83% zero-months-below, 100% no stranding.

§7.8 (amends) — Velocity defense v3 gains an oracle-independent cross-check and a corrected re-basing cadence

As v1.7's A.3 posture ("protect people, concede price"), now with two substrate-era additions. (a) The oracle→reserve loop is closed (v18): an independent endogenous-lane estimator with a divergence gate bounds the monthly over-draw to τ×lane rather than δ×lane ($0.30M with it on vs $19.8M off; the reserve survives the full 24-month horizon instead of draining in 2), folded into canon as EBI Cross-Check Addendum v0.1 (τ = 3% held pending a tuning sweep). Honest correction (gate-tightening, July 11): the registered expectation that the τ-tradeoff has an interior optimum near 2–3% is refuted — the frontier is τ-degenerate and τ* lands at 5% (v18 Y4 FAIL). This does not weaken the mechanism (canon τ = 3% rests on Y0/Y1, both PASS on computed clauses), but the tuning claim was wrong in public and a τ-vs-δ sweep is the owed successor. (b) The re-basing cadence is corrected (v33): the EBI Methodology's fixed 0.05 bias budget cannot absorb a systematic ±0.5pp/yr drift, and the binding cadence is set by the reserve side at ≤ ~2.5 years, not the 5-year delivery-safe cadence — a cumulative-draw over-read telemetry is the alternative.

§7 (amends) — The monetary position, stated on the record: the EBI is the numéraire, not a unit-of-account takeover

Canon now states explicitly (Monetary Position Note, ENDORSED provisional) what EVE claims to be, so the unit-of-account-inertia critique is answered by accepting half of it: everything that must hold its real meaning is denominated in the EBI — goods, not currency (the floor at 1.10×EBI, machine-pay floor prices, validator/aggregator bonds, the Redemption Window). Fiat remains the expected language of market prices at the interface, possibly forever; the entire v6 open-economy wave already runs in that world, and EVE-as-unit-of-account appears in zero registered bars. EVE mediates exchange within the ring and meets fiat at a priced, survivable edge; as a store of value it is deliberately bounded (holding limits, non-transferable streams, no compounding inheritance) because idle hoards are the incidence target of last-resort funding. One-line version: EVE prices its promises in groceries, settles them on a ledger, and lets dollars keep the job of being dollars.

§15 (amends) — Risk analysis: the restated claims, with the new failures carried

Adding to v1.7's four restatements:

The strongest standing criticisms are unchanged and restated for emphasis: proof-of-personhood liveness at scale (gates 9/14 measure, the pilot decides), real willingness-to-pay (v16-extension quantifies the fragility; the field experiment settles it), consent as politics (v5.4/v32), and the in-family discount on all AI-reviewed evidence pending out-of-family human replication.

§16 (amends) — Gates 15–22, with their status

Adding to the measured gates 12–14 (v1.7):

Gate What it bounds Status / reference
15 Honest-validator-pool floor + committee size + coerced-state cohort cap Candidate (v11): H* ≈ 5,500; k = 201; ≤15% cohort
16 Aggregator payout vesting Candidate (v12): 168-epoch vesting on the time-mint lane
17 Oracle re-validation speed + move-cap + quarantine Candidate (v13-Oracle); the 0.888 stress leg is disclosed, live oracle red-team still a launch gate
18 Live cross-layer concentration cap (combined across roles) Candidate (v14): 15% combined; robust in the v16-extension sweep
19 Governance contribution-house cap (iterative water-fill) Candidate (v15): exactly 5.00%; the v0.2 water-fill is load-bearing
20 Sponsor recession-payment floor Re-ratify at ≥0.60 (v16/v31; the ≥50% + escrow arm is dead — escrow is inert against austerity)
22 Payer-exit pre-commitment (accession contract) Candidate (v21/v32): the mixed rule — 6%-capped bump + ~41% taper — with a ramp ≤ the ratified reserve window

Also queued: a minimum-viable-scale wind-down gate (v21 K3 — the system has a fixed-cost floor at ~40% retained population, below which the 5% protocol share cannot fund validators/oracle) and a basket-cost-cap tightening (v17 C3 — food/shelter each compute $21.6M/yr against the $20M bar). A proposed benchmark gate: no currency pilot without a measured $/claim on the deployed proving circuit (the desk benchmark shows feasibility but a TEE-native P-256 device-key trap costs ~200× and the v12 fee dial fails 6–22× at today's outsourced-market prices).


Part B — The normative mechanism, current state (what stands as canon)

This section states the ratified mechanism as it stands after the July 10 ratifications, so a reader need not reconstruct it from seven changelogs. Normative chain: EVE Algorithm v1.0 → v1.1 → v1.2 → v1.3 → v1.4, as amended by the notes below. Everything here is ratified provisional — pending economist and out-of-family review — and logged in 00 DECISION RECORD with its roads not taken and reversal path (universal reversal = two-house + timelock; constitutional-class = supermajority + timelock).

  1. Issuance. EVE is minted only by verified humans' engaged attention to real digital work, governed by a one-way mint-rate governor (the core money-supply control). The effort-weight W_effort remains a cost, not a cure (v1.7 §7.1): anti-value-farming is delivered by outcome-linked minting on high-value classes, transparent-rule/private-sample audits, a bounded arbitrage spread, and the economic + identity ceilings that never depended on the weight. A constitutional Exploration-Subsidy floor c_min protects the mint coefficient until exploration pays for itself — with the v34 refinement that c_min should sunset once machine-pay matures (otherwise it blocks full Baumol stability).

  2. The floor (the guarantee). A guaranteed essentials floor F = 1.10 × 7-day rolling EBI — indexed to a measured goods basket, never to the currency, and never printed (delivery is staged to funding; the failure mode is honest rationing, not inflation finance). The 1.10× decomposes as 1.05× hardship-depth cushion + 0.05× measurement-bias budget. The floor is universal in guarantee, converging in strength (v1.7 §7.5): guaranteed from each region's accession, converging as time-equal minting turns joiners into contributors, with mandatory transfers capped at the consent bar. It launches floorless with staged activation (EVE Algorithm v1.4): all routing banks into a Floor Reserve; the floor activates on a solvency trigger (reserve ≥ 24 months of obligations + inflow ≥ obligations) with a vulnerable-dependence override (>2% vulnerably dependent for 12 months forces activation). v34 confirms the floor's essentials-indexing is what disarms Baumol for recipients across a century; v33 corrects the re-basing cadence to ≤ ~2.5 years (reserve-side binding).

  3. The EBI (the numéraire). The Essentials Basket Index prices a stated monthly quantity vector of survival-and-participation goods per person per region — not a CPI, not a cost-of-living or welfare measure. Composition changes are constitutional-class (two-house, ±10%/yr relative weight cap, ±2%/revision cost cap, categories defined by function not brand). The published index is a chained Törnqvist over settlement-lane data, median-of-three-bonded-classes at the observation layer, with move caps and quarantine (Oracle Protocol Spec, priced by v13-Oracle). EVE claims the EBI as numéraire, not unit-of-account (Monetary Position Note).

  4. Velocity defense (stability by formula). A USD-side stabilization reserve sized to projected mature inflow; capped, laddered term-locks; the Essentials Redemption Window paying EBI-real value through crashes; the reserve subordinated to the essentials lane, not to a price corridor (v1.7 §7.8); progressive-by-size demurrage (Velocity Defense v1.4, above); and an oracle-independent cross-check (τ = 3% held). Crisis performance is scored on income/essentials reaching people, not price paths.

  5. Banking (Part A §7.10). Full reserve; custodial + term-lock deposits; free-market credit with a universal right-to-exit; equity alongside debt; enforcement by reputation/collateral/garnishment without coercion; shadow banking bounded demand-side. Constitutional-class invariant: broad money = governor issuance.

  6. Distribution and anti-dynasty. Non-transferable income streams (no compounding inheritance; dynastic persistence 98% → ~11%, top-10% royalty capture 79% → ~17%); W_age and per-node caps on the dependency stream; the Ancestral Dividend as the terminal floor funder "while the living keep the garden." Three honest income tiers (builders earn livings; contributors earn supplements; members earn modest income plus storm-proof shadow savings) — median prosperity from passive participation is not claimed.

  7. Identity (the keystone, breach-survivable by design — v1.7 §7.9). The biometric is the uniqueness check, not the credential — stored as a salted, versioned, rotatable transform; daily use runs on revocable keys plus the accumulating continuity web; cohort caps ≤ 15%; the quarantine invariant (a compromised cohort's floor never turns off); due-process revocation + fallback registrar (un-personing fails). The liveness arms race (sensors vs synthetics, p_live) is the single load-bearing assumption in the whole program; only the pilot prices it.

  8. Governance. A two-house structure (one-person-one-vote + contribution-weighted-with-caps under the v15 iterative-water-fill cap function, exactly 5.00%), sortition juries of verified persons, subsidiarity/federation, delegation and quorum machinery, and constitutional change control (two houses + timelock; supermajority for constitutional-class).

  9. Substrate (Part A §5–§6). Civic validation by bonded-personhood sortition; a proof-of-engagement pipeline with vesting and private-sample audit; the cross-layer cap; the proving-cost profile — all specified in EDEN Protocol Architecture v0.1 and priced by v11–v14.


Part C — Evidence Base (the current, corrected record)

The program's evidence is now 34 pre-registered simulation waves (v1–v34, several with lettered sub-waves) plus a machine-checked proofs artifact (10/10, with grade labels) and a proving-cost desk benchmark. Every headline traces to a committed results*.json via the Replication Kit's Claims Register; the map is 04 Simulations/00 INDEX - Simulations Overview. Trust model: read every result as mechanism-existence under stated dials — "this rule closes this exploit; removing it reopens it" — never as a forecast. This section deliberately carries the failures as findings, mirroring the Economist Brief's candor: presenting a cleaner record than the vault holds is the specific error Verification v4 (D15) named. The prior eras (v1–v10) stand as documented in v1.0–v1.7 and Appendix A; the record below is what v1.8 adds and corrects.

C.1 — What was checked, and how

Two full verification passes then a gate-tightening recode define the confidence level. Verification v3 (July 9) re-ran every engine in the vault from the code on disk (49 of 54 reproduced exactly; the other five differ in explained, harmless ways). Verification v4 (July 10–11) independently re-executed all fifteen then-new engines (v16–v30) plus the proofs and the rewritten cost-envelope benchmark in an isolated sandbox: every one regenerated its committed results file, most byte-for-byte, figures included. v4's verdict, in one sentence: the outputs are honest; the tests were uneven — the mechanical layer (code → JSON → prose) is in excellent shape and eleven registered failures were all recorded, but the passing side carried hardcoded sanity gates, tautological checks, and four write-ups that had gotten ahead of their runs. The July 10–11 fixes moved the scoreboard in both directions. The gate-tightening recode (Backlog #4b, July 11) then converted the disclosed-but-hardcoded gates into computed ones without moving any registered bar, flipping four verdicts (v18 Y4 → FAIL, v21 K4 → FAIL, v26 Q5 and v28 SB2 → disclosed non-results). A fresh-session independent verification of the recode (Backlog #13) has since been completed: all recoded engines reproduce their committed JSON byte-for-byte and are deterministic, and the four verdict changes were independently judged genuinely computed and justified (six low-severity gate-quality caveats logged, all already disclosed). Update (July 31, 2026): the most recent independent run of the harness — by an out-of-family AI reviewer with only the public kit and site — reproduced 72 of 82 discovered programs within tolerance; every exception is classified in the run ledger.

The provenance caution travels with the batch: per the owner's record, most July 9–10 work ran as Opus 4.8 under inherited "(Fable)" signature labels (v23 the recorded exception) — which is why the verification discipline ignores signatures and re-executes everything.

C.2 — The substrate/architecture program (v11–v15, proofs, envelope)

v11 Validator Capture & Sortition — 11/11 bars. Cheapest safety capture ~$613M (bulk identity rental, 20× the v9 attacker); the binding wall is honest-pool size H* ≈ 5,500; k = 201 committee censors 0.483% of epochs at 25% infiltration (k = 101 fails at 3.16%); coerced-state channel needs 3 jurisdictions to censor, 5 to capture at the 15% cap. Counterfactuals measured-dominated: young PoS captured at $100M/$50M with security that crashes with the token (post-crash security ratio 19.1×); permanent authorities halt under 2 legal orders. Thin pass flagged: V3a's bond floor cleared its $100M bar by only 5.7% (index the bond, gate the pool). Gate-15 candidate. Defeater on the face: prices the mechanism around the identity layer.

v12 Aggregator Collusion & Re-Aggregation Audit — 6/6 bars (one disclosed harness repair, original archived). Break-even audit 0.62% of batches at 0.010% honest cost; vesting load-bearing (no-vesting +$323k → 7-day vesting ~$0); blast radius 0.0063% of annual mint at the 15% cap (ring ROI −$586M); 0/1,000,000 cross-aggregator duplicates. Counterfactual trusted single aggregator keeps $438B (1,580×). Gate-16 candidate: 168-epoch vesting. Defeater: forged attestations are spotted to the attacker for free (gate 9 again).

v13-Oracle Capture & Quarantine — 6/8 bars; O3-stress and O4 FAIL as honest findings. Faking 2-of-3 class-medians costs $99.5M (O1) and cannot pay for itself (80× cost/payoff, sabotage-only — the threat-model flip from thief to vandal, O2). Granted a free capture, the floor still delivers 0.960 of essentials monthly centrally (O3b) — but under the pessimistic triple-combo (4-week lag, 10%/yr inflation, 12-month re-validation) delivery dips to 0.888, just under the 0.90 stress bar (O3c FAIL): re-validation speed is the load-bearing safety parameter, not the capture. The essentials lane is the dearest class ($310M) but at 4.3× the reporter class, under the registered 5× bar (O4 FAIL — the "real commerce is the expensive fake" inversion holds qualitatively, the multiple doesn't clear). Counterfactuals: a single CPI feed is capturable at 1/995 the cost (Argentina INDEC precedent); an unbonded crowd 1/199. Gate-17 candidate. Defeater: does NOT discharge the live prize-funded oracle red-team, still a launch gate.

v14 Cross-Layer CompositionX1 and X2 FAIL exactly as registered — that IS the finding. Joint attack $483M vs $737M separately (0.66×, 34% shared-cohort discount, X1); identity blast radius composes 1.37% → 3.74% past the 2% gate (X2, 2.7×); oracle→reserve loop drains the reserve in 4 months while protecting delivery (X3); the fix works — one 15%-combined cross-layer cap → per-role reach 3.75%, composed fraud 0.96% (X4). Gate-18 candidate. Defeater: composition coefficients are stated estimates; inherits the identity keystone.

v15 Governance Capture under the Cap Function — G0/G2/G5 pass; G1 passes under the fix it motivated; G3/G4 reframed as findings. The contribution house is robustly non-plutocratic (√-concavity squashes a 30% whale to ~1%; majority needs ~1,595 colluders). The run caught a real flaw in the cap as first written (F1): the single-pass min(raw, κ·Σraw) leaks to 9.4% under concentration; iterative water-filling is required and holds it at exactly 5.00% → a v0.2 governance-spec refinement. √-weighting rewards identity-splitting 1.41× (= √2), closed only by the identity layer's ~120F-per-lifetime cost — governance anti-capture inherits the identity keystone. Gate-19 candidate. Defeater: what counts as contribution without becoming farmable is a separate, unsolved Goodhart problem.

Machine-checked proofs — 10/10 PROVED, with two grade labels applied in the open. The load-bearing theory/arithmetic claims are now sympy-symbolic and exact-rational-verified, committed as a harness engine so the replication kit re-verifies them forever. Theorem-grade: the taper's no-cliff property (marginal 0.5 → 1.0, income ≥ F, kink at 2F); the v11 committee-censorship tails as exact hypergeometrics matching committed floats to the last digit; the v15 water-fill terminating/summing/holding at 5.00%; identity-splitting gain ≡ k^(1−α) (√2 at k = 2); the cartel bound ≥ 11 at κ = 5%; the v14 blast-radius closed form (2.731887, 0.21σ/0.37σ from both MC seeds); the O0 capped-geometric formula (exactly 13/400, 13/320); and P9/P10 (crash-floor identity, Redemption Window invariance) as exact algebra with empirical premises named. The two honest grade labels: P8 is PROVED at self-consistency grade — the first pass hit its registered NOT-PROVED contingency, the envelope engine was rewritten the same evening to emit its own derivation (values unchanged, 195/195 leaves), and since emitter and checker share an author this certifies internal consistency, not independent re-derivation. P3 was re-scored to its registered clauses (≤n termination on all feasible cells + the previously-unchecked uniqueness clause, enumerated exactly over the 20-cell grid). Verification v4 found the proofs record was, before reconciliation, internally incoherent — three different tallies (10/10 vs 9/10 vs "still owed") — and the P8 re-grade circular; both are now reconciled to one story with the labels above. This correction is itself carried on the record.

Proving-cost desk benchmark. Proving a claim costs $7×10⁻⁷–$0.019 = 0.00007%–1.9% of the mint value it certifies — feasibility not in question — with a named exception (the TEE-native P-256 trap, ~200× cost) and an honest tension (the v12 fee dial holds 720× on the lean route, fails 6–22× at today's outsourced-market prices). Proposed gate: no pilot without a measured $/claim on the deployed circuit. Labeled a desk benchmark, not a hardware run.

C.3 — Federation (v6.8)

v6.8 Escrow & Multi-Sponsor Federation — J0–J3 + J5 pass; J4 FAIL as a finding. Federation + escrow turns v6.7's −92% single-sponsor exit into a −9.9% ripple (currency rises), delivery unbroken, zero printing. Walls: cap* = 0.40 (max single-sponsor share; 100% even with escrow → 59 months below floor), E* = 6 months (= step-up lag; E = 0 → 4 months below floor). Storm passes thin (trough 1.062, dd 42%, recover 4 months). J4: "cheaper than welfare" is a peacetime, funder-level number (~24% member-level here vs v6.4's 26% funder-level); a survivor backstopping a mid-storm collapse sees its saving compress to ~9% and carry to 2.7% — the backstop obligation must be priced. Cascade politics (24 draws): 83% zero-months-below, 100% no stranding.

C.4 — Robustness, capture, run/exit, adoption (v16–v23)

v16 Regime-Shift Envelope (Lucas sweep) + extension. Nine load-bearing dials shaken jointly (±50%, 32-point LHS, both seeds) through the committed engines. L1/L3/L4 pass; L2 FAILED — the headline: the storm result holds in only 47.4% of the envelope (bar 75%), 18/20 flips breach the 3-consecutive-month criterion, zero printing anywhere (honest rationing). The driver is the sponsor recession-payment fraction; committing the isolation slices (July 10) and running both seeds widened the bracket to g* ∈ (0.45, 0.60) straddling 0.50 (densified in the extension to (0.51, 0.52], with ≥0.60 standing at ~8–9pp margin). Envelope-robust: peacetime federation (100%), the governance cap (100% of 400 cells; the single-pass cap would have leaked in 7.75% — v0.2 water-fill load-bearing), the k = 201 committee (sharp wall at s* = 28%). The extension swept the refactored v12/v13-oracle/v14 layers through the same envelope (v14's joint-cap fix holds 32/32; two dial-local findings reported, gate-18 unaffected) and added the FAIL-tier WTP sensitivity (red-team A9): at anchors ÷10, safety promises survive (floor delivery 0 months below; cheaper-than-welfare WTP-invariant at 0.785) while builder-economy/self-funding promises break (median builder $420 → $45/mo; $200/mo share 88% → 3%; endogenous floor coverage ~13% → 7%).

v17 Composition Capture — C0/C1/C4/C5 pass; C2 and C3 FAIL (C3 re-scored July 10). Lobbying the basket is unprofitable, but the rate cap alone holds a hypothetical monopolist only to a thin ~1.6× loss (C2, below the 3× bar); scored as registered against "any single category," food and shelter each yield $21.6M/yr vs the $20M bar (C3 FAIL, previously coded energy-only). The load-bearing defense is the functional-category definition (C4: a price-taking supplier earns zero rent from a reweight). Defenses off: capture profitable ~12,400× (C5 — corrected from the previously-circulated ~5,000×; committed ratio 8.04×10⁻⁵, naive six-year prize $777.6M). Defeater: the definitions are themselves a governance surface — the composition analogue of "what counts as contribution."

v18 Oracle-Reserve Cross-Check — the divergence gate bounds the over-draw to τ×lane ($0.30M on vs $19.8M off; reserve survives 24 months vs draining in 2), delivery whole because the 1.10× cushion absorbs estimator noise. Under gate-tightening (July 11), Y4 flips PASS → FAIL: recoded to compute its registered interior-optimum expectation (τ* ≈ 2–3%), the frontier proved τ-degenerate and τ* lands at 5% — the expectation is refuted (a finding); the mechanism is unweakened (canon τ = 3% rests on Y0/Y1/Y2, all PASS on computed clauses). Honest residue (Y3): a 2-of-2 attack converts reserve-drain into a bounded ~1% delivery dip. Folds into EBI Cross-Check Addendum v0.1.

v19 Run plus Exodus — all five bars pass; the finding is structural: a per-capita goods floor cannot be "run" like a fixed-liability peg — when people leave, the bill shrinks as fast as the base. Correction carried (v4 D1, then executed): the "88% gone" figure that circulated was an inversion of the committed 88%-retained result; the registered sweep (now run) bottoms at 68% retained with delivery 1.0 everywhere; a forced-exodus extension confirms delivery 1.000 to the remaining 12% (reserve 98% full); a permanent-depression extension shows nothing breaks but the base drains to the 2% model floor — the floor can be abandoned, not run. Defeater: the reduced form omits fixed infrastructure costs (priced by v21 K3).

v20 Region Secession + v32 Payer-Exit Re-balancing — v20's five bars pass with a sharp asymmetry: nobody is stranded below their never-joined baseline; losing a net-drawer relieves the union; losing a net-payer opens a 53% drawdown + $3B/mo hole, the reserve buying ~24 months (committed sizing) or ~9 months (SPEC-registered sizing — a disclosed deviation, flagged for ratification). v32 resolves the countdown: RB1 FAILS as registered — a slice-bump alone needs +80.2% of givers' burden vs the 6% bar (13× over); you cannot bill the survivors. The humane tool is the taper (drawers self-fund 89.4%): a mixed rule — 6%-capped bump + 41.2% taper — closes the gap at 0.956 delivery; the 9-vs-24-month reserve question is an 18-vs-48-month diplomacy budget.

v21 Closeout BatteryK1 and K4 FAIL; K2/K3 pass. K1 (reassuring): capturing a category's definition is no more profitable than adding a category (both ~1.6× losing) — treat definitional edits as rate-capped. K2: the 2-of-2 oracle attack costs $410M = 4.1× the single-channel drain. K3: per-capita delivery is run-proof but the system has a fixed-cost floor at ~40% retained population → a minimum-viable-scale/wind-down gate candidate. K4 flipped PASS → FAIL under gate-tightening (July 11): its pass had been gated only on the 25% measured anchor while its "closes within 24 months" clause was hardcoded True; recoded against the registered 6% political bar, no split clears it → honest FAIL, the 24-month timing a disclosed non-result. This strengthens gate-22: it is the measured reason to pre-commit the taper/slice split.

v22 Adoption Timingseven of eight bars pass; T5 FAILED on re-score (July 10). The late-joiner catch-up leg, scored at the registered 10-year window (not the mis-indexed 20-year one), holds 0.78 of pioneer influence vs the 0.80 bar — dilution works but runs ~2 years behind the clock. The three headline answers stand: science symbiosis is real and causal (adopted institutions out-discover 1.92×/institution by year 20; ablations prove failure-data payment and visibility each carry ~half); government efficiency is a level not a path (26% saving at any join date; 1.74× savings-stock gap is the price of lateness); influence is rewarded then diluted on schedule (early wealth's 1.2× premium melts to 0.8× — below the adopted mean — by year 50). Correction carried: science self-funding is 74% of current spend at year 15 as a flow share; the "82%" that circulated was the year-50 cumulative (year-15 cumulative is 28%). All data-payment results are conditional on H1 (the WTP hinge).

v23 Sponsorship-Agenda Capturethree bars pass; B1/B2/B3/B5 FAIL — four of seven registered expectations falsified in public, the defense hierarchy inverting from what was registered. The steering premium is 1.9× (not 3×) and is entirely researcher data income — so the WTP hinge is also an anti-capture hinge; influence decays by metering (~15pp-years per treasury-month), not quickly; unburiability rents ~5 years of fog rather than forcing truth. The headline stands on the contrast: outside, ignorance is purchasable outright (0/18 evidence cells ever cross in 50 years under burial + compounding); inside, truth crosses anyway in 88.9% of cells, and the provenance discount (weight sponsored studies 0.3) is the only tested mechanism that closes the never-cross corner → a gate candidate. Displacement costs 5.68% of knowledge output (a marginal miss of the ≤5% bar). Verification v4 rated v23 the cleanest sim in the batch — 100% claims-trace, honest 4-of-7 failure reporting — and it is the one artifact the owner records as genuinely Fable 5.

C.5 — The banking & savings layer (v24–v30)

One line each; the paragraphs are in Part A §7.10. All findings, including failures, on the record.

C.6 — The century cells (v33, v34) and the ecology resolution (v13.1)

v33 Index Drift — ID0 passes; ID1/ID2/ID3 FAIL exactly as registered (the findings), and ID4 fails one clause honestly (a too-tight ±3-month cross-seed tolerance on the exhaustion month — its fourth FAIL, carried here per house rule; v5 D7). A one-directional under-read exhausts the 0.05 budget in ~9.3 years, breaches essentials at year 19.1, and leaves the floor at 0.856 by year 50 (ID1); the mirror over-read drains the reserve in 2.5 years while §5's instantaneous telemetry only lights at 9.8 years (ID2); the binding re-basing cadence is reserve-side ~2.5 years, not delivery-side ~9–10 years (ID3). Amends EBI Methodology §5. Verified byte-reproducing + gate-audited (July 11 fresh session; Verification v5, July 12).

v34 Baumol Governor Drift — BM0/BM1/BM3 pass; BM2 and BM4 FAIL as findings. The aggregate-tuned governor inflates essentials to 3.74× vs 2.17× essentials-tuned while its own gauge reads flat (BM1); the essentials-indexed floor delivers a full 1.10× basket every month of the century (the indexed promise — an identity of the floor rule; realized self-funding coverage bottoms at ~12% until the yr-92 crossover, sponsor-backed until then — v5 D6) where a naive aggregate-CPI floor breaches at year 8.8 and collapses to 0.20× by year 100 (BM3). BM2: Baumol delays the v7 generational-floor crossover from year 46 to year 92. BM4: essentials-indexing the governor cuts drift 62% but only a post-bootstrap c_min sunset removes it entirely. Canon candidates: index the governor to the EBI + sunset c_min; keep the floor on essentials. Fresh-session verify owed.

Ecology (v13.1) — RESOLVED-NEGATIVE. This supersedes all circulating "provisional" ecology language; v13.0 artifacts remain only as the investigation trail and must not be cited as results. The provisional v13.0 failed its harness-trust gate (a floor-printing wage-price spiral drove 2,163× inflation). The regression-gated rebuild (v13.1) reproduces 68/68 legacy bars exactly, then answers the funding question with 0 of 7 R-bars passing — the answer: at registered dials the ecology-era floor is structurally unfundable — funding streams carry 2–5% of obligations, a labeled jump-start proves it is not a bootstrap gap, and obligations eventually exceed the model's entire settlement volume (a 100% tax could not fund it). Zero printing in all 10,800 EDEN-months; inflation ~7%/yr (the old figure was pure printing). The E1/E2 delivery-vs-GDP thesis rode on the failing floor-print and is not claimed. This forces a canon-level decision — grow the purse (v5.2-scale slices, ~10×), shrink the promise (a partial/lower floor), or name a permanent bounded subsidy — now in the ratification queue.

C.7 — The economics-literature red-team scorecard

The ten strongest published objections, argued at full strength and scored honestly (EDEN Red-Team — The Economics Literature vs EDEN). The verdicts as scored in the document:

# Objection Verdict (as scored) Owed instrument — and its current status
A1 Lucas critique PARTIALLY ANSWERED Joint dial-shift envelope → built (v16); L2 storm FAIL is the honest result
A2 Hayek / calculation (basket) PARTIALLY ANSWERED EBI Methodology Spec → built; composition-capture cell → built (v17, C2/C3 FAIL)
A3 Index-number bias (Boskin) UNANSWERED → now PARTIAL (was the clean miss) Chaining/bias-budget spec → built (EBI Methodology §4/§5) answers the composition half; drift cell → built (v33, ID1–ID3 FAIL — the fixed 0.05 budget is insufficient; needs ≤~2.5-yr re-basing)
A4 Goodhart/Campbell ANSWERED IN-MODEL (the program's best work) Live red-team (registered)
A5 Myerson–Satterthwaite / incidence PARTIALLY ANSWERED Incidence Note → built
A6 Krugman/Obstfeld crisis ANSWERED by concession ("protect people, concede price") X3 cross-check → built (v18); run+exodus → built (v19)
A7 Mundell/Oates OCA + fiscal federalism ANSWERED as far as models go (the vault found it first) Region-secession → built (v20); payer-exit → built (v32); consent remains pilot
A8 Unit-of-account inertia PARTIALLY ANSWERED Monetary Position Note → built
A9 Data-valuation gap (Arrieta-Ibarra) ANSWERED IN DESIGN, pending empirically WTP field experiment (registered); FAIL-tier sensitivity → built (v16 extension)
A10 Baumol / automation displacement PARTIALLY ANSWERED (conscious wager) Century drift cell → built (v34, BM2/BM4 FAIL)

Counting, honestly (resolved July 11 per owner ratification). As scored, this is 4 answered-class verdicts (A4 in-model, A6 by concession, A7 as-far-as-models, A9 in-design), 5 partially answered (A1, A2, A5, A8, A10), and 1 originally unanswered (A3) = 10. The ECONOMIST BRIEF's earlier "3 answered / 4 partial / 1 miss" was a miscount (flagged by Verification v4 D17) and has been corrected to match this scorecard. Per the owner's ratification, A3 is now classed PARTIAL, not unanswered: the EBI Methodology Spec specifies the composition-governance half, and EVE Sim v33 (Index Drift) tested the measurement-drift half and found the fixed 0.05 bias budget insufficient — needing a ≤~2.5-yr re-basing rule (a canon candidate). The current effective tally is therefore 4 answered / 6 partial / 0 unanswered, A3 the newest partial. The material point stands: since July 9 the owed instruments were largely delivered, and the testing did not merely vindicate — v33 showed the bias budget is insufficient against systematic drift, and v34's Baumol cells failed two bars. The scorecard improved by being built out; it did not improve by being flattered.

C.8 — Corrections applied to previously-circulated numbers

The verification and gate-tightening passes re-scored several figures that had circulated in earlier drafts, briefs, or index rows. The corrected column is what v1.8 cites.

Previously circulated Corrected (committed artifacts)
v18 "all five Y-bars pass" Y4 and Y0 FAIL — Y4 on the recoded gate (τ* ≈ 2–3% interior optimum refuted; frontier τ-degenerate, τ* = 5%) and Y0 on the v5 registered-σ-sweep re-score (12.5% false-quarantine months at σ=2% vs the 5% bar; July 12). Drain-bounding unweakened: canon τ = 3% rests on Y1/Y2; its quarantine comfort is σ-conditional
v21 "K2/K3/K4 pass; K1 FAILs" K1 and K4 FAIL; K2/K3 pass — K4 scored against the registered 6% bar (no split clears it); the 24-month clause is a disclosed non-result
v26 Q5 "contract-freedom" scored Disclosed non-result (stipulated_not_computed) — no origination-refusal model
v28 SB2 "detection ~92%/3% (pass)" Disclosed non-result (detection_assumed_not_measured) — no velocity/graph model; the 92%/3% figure is an assumed input, not a measured output
v17 defenses-off capture "~5,000×" (0.0002×; $78M) ~12,400× — committed ratio 8.04×10⁻⁵, naive six-year prize $777.6M (C5)
v19 "88% of users gone, floor still delivered" Inversion of committed Z2 (88% retained); registered sweep bottoms at 68% retained, delivery 1.0; forced-exodus extension: delivery 1.000 to the last 12%, reserve 98% full; the floor can be abandoned, not run
v22 science self-funding "82% by year 15" 74% is the year-15 flow share; year-15 cumulative is 28% (82% was year-50)
v22 T5 catch-up "~0.90 within 10 years — PASS" Mis-indexed 20-year window; at the registered 10-year window 0.78 vs 0.80 — FAIL
Proofs "7 of 8 proved" 10 of 10 PROVED, with grade labels (P8 self-consistency; P3 re-scored to registered clauses)
v16 g* ∈ (0.45, 0.50] (single seed, uncommitted probes) Slices committed, both seeds: g* ∈ (0.45, 0.60) straddling 0.50 → gate-20 ≥0.60 (v31 killed the escrow arm); adopted ≥50% flagged for re-ratification
v24 M1 "all five carry configs pass" Four of five — auto-lock FAILS M1
v20 reserve "buys 24 months" ~9 months on the SPEC-registered $36B sizing (engine used $81.1B union volume — disclosed, probed, flagged); v32 quantifies the 18-vs-48-month phase-in
Position notes "persistence 79% → ~10%" Un-spliced: persistence 98% → 11%; royalty-capture 79% → 17% (v4 D14). Note (July 31, 2026): the separately committed purchase-channel artifact reports persistence 79.2% → 10.4% in its own calibration (self-labeled "illustrative; the ordering is the finding") — that artifact, not a splice of the two figures above, is what current site headlines cite.
Ecology "provisional; poor decile fill 1.0 through shocks" RESOLVED-NEGATIVE — floor structurally unfundable at registered dials; the delivery thesis rode on a floor-print spiral and is not claimed

C.9 — What this Evidence Base does not change (the standing out-of-family obligations)

Nothing above discharges any of the program's four real hinges, and the honest ordering of importance puts them ahead of every further model-hour:


Conclusion (amended paragraph, appended to the v1.7 conclusion)

The v6 program widened the proven middle; the v7 program reached for the horizon; the adversarial program armored the defenses; and this program did the two things a maturing research effort must do at once — it went down a layer, into the substrate the whole mechanism assumes, and it turned its verification tools on itself. Both moves cost the paper claims. The substrate holds at budgets the program takes seriously, but every substrate result prices the mechanism around the one assumption a model cannot settle — liveness against synthetic humans — and says so on the face of every readout. The self-audit was harsher still: two verification passes and a gate-tightening recode flipped six previously-clean results to failures or disclosed non-results, resolved a whole model negative, and reconciled the flagship rigor artifact from three contradictory tallies to one honest one. What EDEN now claims is therefore smaller and firmer than what it claimed a week ago. It claims a currency created only by verified human contribution, a floor indexed to groceries that never prints and delivers a full basket through a century of Baumol drift, a substrate whose capture costs are measured in the hundreds of millions and whose true wall is the honest-volunteer count, a banking layer that cannot create money and a credit market disciplined by the floor into a free-but-not-predatory equilibrium, and a set of failures it carries in the open: an oracle whose re-validation speed is load-bearing, a composition attack that must be capped, a self-funding story that is willingness-to-pay-fragile, an ecology-era floor it cannot yet fund, and a consent problem that is politics, not arithmetic. The roads not taken were measured, not merely argued. What stands between this paper and the world is unchanged and honestly short: liveness, willingness-to-pay, consent, external replication, and a hostile human expert who tries to break all of it. Proven in the middle, honest about both ends — attacked from below and audited from within, in public, with the receipts filed and the failures kept as findings.


End of v1.8 draft. DRAFT — awaiting owner ratification per program convention; unreviewed (AI-produced). Normative spec remains 01 Canon/EVE Algorithm v1.4 - Ratified Spec as amended by the July 10 ratifications catalogued in Part B (Velocity Defense v1.4; EBI Methodology, Monetary Position, Incidence, Governance Cap-Function, Oracle Protocol, and Cross-Check notes; the Banking & Savings Layer Spec at proposal grade) and logged in 00 DECISION RECORD (DR-01…DR-17). Still owed: a consolidated EVE Algorithm v1.5 spec ratification incorporating the substrate/architecture terms (validator sortition, aggregator vesting, the cross-layer cap), the banking layer, the demurrage A2 schedule, the federation terms, the EBI numéraire position, the corrected re-basing cadence (v33) and governor-indexing (v34), and gates 15–22; the fresh-session independent verification of the gate-tightening recode (Backlog #13); the ecology purse-vs-promise-vs-subsidy decision; and the four standing human/field hinges (H1–H6). v1.0–v1.7 preserved unedited. Compiled by Claude (Opus 4.8), July 11, 2026, from the committed record — 04 Simulations/00 INDEX, the v11–v34 RESULTS/JSON, VERIFICATION v2/v3/v4, the GATE-TIGHTENING PASS, the ECONOMIST BRIEF, and the 01 Canon specs. Verify, don't trust — including this file.