This note refines Candidate 017 with the interpreter, representation-dependency, vocabulary, authenticity, and access boundaries established by library and archival science. The contract does not promise to preserve all future meaning. It makes a finite claim that can fail.
Preservation package
For version , define
where:
- is payload bytes;
- is metadata, evidence, provenance, and fixity records in bytes;
- is format and rendering dependencies;
- is schema and type constraints;
- is vocabulary, authority, identity, and mapping versions;
- is the designated interpreter community and its assumed capabilities;
- is authenticity/custody evidence and authorized access state; and
- is executable dependencies, tests, emulators, or migration tooling.
The tuple is typed. Fixity of does not establish truth, authenticity, interpretability, or authorized accessibility. Provenance in records lineage; it does not validate assertions.
Registered query contract
For query family , declare native output space , distance , tolerance , evidence obligations , supported community , and decision horizon . For source package and a candidate transformed package , require
where and share the query's native unit and is a dimensionless failure probability. The evaluation distribution has frozen development, held-out in-family, and adversarial migration splits.
Evidence reachability is
where is the registered evidence set and is the set recoverable with valid lineage from . is dimensionless. It does not score whether the evidence supports a claim; that requires a separate inference and decision contract.
Interpreter and dependency validity
Let be a versioned capability vector for the interpreter community at time : supported languages, schemas, units, software, cryptographic algorithms, domain conventions, and required practiced procedures. Let be the corresponding requirements. Interpretability is
a dimensionless predicate under a declared partial order. “Human readable” or “standard format” is insufficient unless the supported community and dependencies are named.
For dependency graph and root package nodes , required closure is
Missing-dependency rate is
which is dimensionless. Criticality weights may be reported separately, but a weighted mean cannot hide the loss of a dependency required by every query.
Migration and vocabulary drift
For migration , maintain a manifest containing source/target versions, transformed and retained fields, known loss, dependencies, tests, reviewer/authority, and rollback or source-recovery path. Query regression is
in the native query unit. Vocabulary or authority mappings are separate versioned relations
A merge cannot silently transfer all evidence from both prior entities. Query tests must include namesakes, renames, splits, merges, multilingual labels, contested mappings, and temporal concept change.
Availability decomposition
For query , time , and community , a useful decomposition is
The five terms are dimensionless conditional probabilities; and share one declared decision unit. The product is a checklist unless dependence among failures is explicitly modelled. Report each component and joint failure cases; do not claim independence by notation.
Registered and unregistered use
The registered contract permits direct success/failure decisions. New unregistered query receives one of three typed outcomes:
- answer with a proof that its required fields and evidence are covered by an existing contract;
- recover retained source/dependencies and evaluate a new contract; or
- abstain as unsupported.
Unregistered-query regret over set is
where uses the query's declared decision loss. Report results by query family because averaging can hide systematic loss for a user, language, period, or evidence class.
Lifecycle accounting
For policy spanning capture through disposition, keep the native outcome vector
where byte-years, joules, person-hours, seconds, and task-native loss units are not added without published conversion weights. Charge payload, metadata, indexes, replicas, dependencies, emulators, tests, migrations, reviewer work, restore drills, legal holds, and verified deletion.
Byte reduction is
where every magnitude is bytes and is dimensionless. Backups or retained raw sources cannot be excluded from the numerator while supplying recovery.
Strongest null and rejection
Compare learned compaction with full version history, indexed snapshots plus suffix log, materialized views, key compaction and tombstones, lossless compression/deduplication, tiered cold archive, and an OAIS/PREMIS-style package with versioned schema/vocabulary and query-regression tests.
Reject the refinement when:
- ordinary packaging plus query regression matches registered-query error, evidence reachability, recovery, and lifecycle cost;
- supported queries or interpreter capabilities are chosen after migration;
- fixity, provenance, citation, ontology consistency, or findability is substituted for correctness;
- unregistered queries receive invented answers instead of recovery or abstention;
- required deletion, holds, privacy, or authorization are omitted;
- metadata, dependencies, migration, reviewer work, and cold fallback are not charged; or
- records survive turnover but operators cannot safely interpret or use them.
Editable diagram: query-registered-preservation.mmd.