Research portal

Mathematical note

Typed tolerance, response, and recovery lifecycle

math/typed-tolerance-lifecycle.md

Edition
Site v0.3.0 · continuous main snapshot
Source revision
ec2865b0eac15148675c629981a545632b3571c5
Extent
917 words
Public route
https://www.cordana.dev/math/typed-tolerance-lifecycle/
Mapped records1 mapped record

Direct repository links only; no document-level evidence status is implied.

This note turns the durable result of the immune tolerance audit into an evaluation contract. The useful transfer is not an “immune score.” It is the refusal to collapse representation, recognition, permission, response, suppression, deletion, impairment, memory, and recovery into one bit.

State vocabulary

For module or rule ii at time tt, define

zi(t)Z={absent,ignorant,eligible,active,quarantined,suppressed,impaired,contracted,memory,deleted}.z_i(t)\in\mathcal Z= \{\mathrm{absent},\mathrm{ignorant},\mathrm{eligible},\mathrm{active}, \mathrm{quarantined},\mathrm{suppressed},\mathrm{impaired}, \mathrm{contracted},\mathrm{memory},\mathrm{deleted}\}.

ziz_i is categorical and dimensionless. The names describe engineered states; they do not assert biological identity. Every transition stores:

  1. the previous and proposed state;
  2. the evidence and representation support used;
  3. the actor and authority that may make the transition;
  4. expected useful effect and distinct collateral-loss terms;
  5. compute, data, time, energy, and reserve budget;
  6. expiry, revalidation, rollback or recovery target; and
  7. the observed outcome and decision lineage.

“Inactive” is not an admissible terminal diagnosis. It can mean that the rule was never generated, relevant evidence was not represented, eligibility is unknown, policy suppressed it, resources starved it, prior response contracted, the rule is retained as memory, or the implementation is impaired.

Representation, recognition, and permission

Let S\mathcal S be the declared scenario set and RtS\mathcal R_t\subseteq\mathcal S the scenarios represented by current evidence. Representation coverage is

κt=sRtwssSws,\kappa_t=\frac{\sum_{s\in\mathcal R_t}w_s} {\sum_{s\in\mathcal S}w_s},

where scenario weights ws0w_s\ge0 and κt\kappa_t are dimensionless. κt\kappa_t describes the registered scenario set; it does not prove that an unrepresented state is safe or that represented evidence is current.

For principal pp, action aa, object oo, and epoch or time tt, permission is

allow(p,a,o,t)=authn(p,t)authz(p,a,o,t)safe(xt,a)fresh(et).\operatorname{allow}(p,a,o,t)= \operatorname{authn}(p,t) \land\operatorname{authz}(p,a,o,t) \land\operatorname{safe}(x_t,a) \land\operatorname{fresh}(e_t).

All predicates are Boolean. Authentication identifies the principal; authorization scopes the action and object; xtx_t is observed system state; and ete_t is evidence with provenance, coverage, uncertainty, and expiry. A recognition or anomaly score can inform xtx_t but cannot replace any predicate.

Cost-sensitive response

Let latent state ss range over benign/needed, harmful, compromised, and unresolved conditions. Let the action set include permit, monitor, rate-limit, quarantine, suppress, delete, and escalate. A calibrated policy chooses

a(x,c)=argminasL(a,s,c)Pr(sx,c),a^*(x,c)= \arg\min_{a} \sum_s L(a,s,c)\Pr(s\mid x,c),

where xx is observed evidence, cc is context and provenance, and every term L(a,s,c)L(a,s,c) is converted into one declared decision unit. Before any optional scalarization, the loss vector remains visible:

L=(Lfalse permit,Lfalse suppress,Lfalse delete,Lmissed harm,Ldelay,Lrecovery).\mathbf L= (L_{\mathrm{false\ permit}},L_{\mathrm{false\ suppress}}, L_{\mathrm{false\ delete}},L_{\mathrm{missed\ harm}}, L_{\mathrm{delay}},L_{\mathrm{recovery}}).

The components may use different native units—lost useful requests, incidents, seconds, joules, or currency—until a documented authority supplies conversion weights. Rare useful capability deleted by a gate is a measured outcome, not a free reduction in false accepts.

Population and contraction accounting

When modules can replicate, scale, pause, retire, or return from memory, track lineage ii as

dNidt=(ri(t)di(t)qi(t))Ni(t)+bi(t),\frac{dN_i}{dt}= \left(r_i(t)-d_i(t)-q_i(t)\right)N_i(t)+b_i(t),

where NiN_i is instances, rir_i is replication or scale-up rate, did_i is retirement/failure rate, and qiq_i is reversible transition into quiescence, all in s1^{-1} or h1^{-1}; bib_i is newly admitted instances per second or hour. A fall in active count must be attributed to retirement, contraction, movement, suppression, resource loss, or quiescence.

Lineage share and effective diversity are

pi=NijNj,D2=1ipi2.p_i=\frac{N_i}{\sum_jN_j}, \qquad D_2=\frac{1}{\sum_i p_i^2}.

pip_i and D2D_2 are dimensionless. D2D_2 is an effective count of equally represented lineages, not proof of functional independence, failure-domain separation, or future coverage.

Maintained memory and local placement

For retained memory instances M(t)M(t),

dMdt=(ρrefresh(t)δM(t))M(t)+ηC(t),\frac{dM}{dt}= (\rho_{\mathrm{refresh}}(t)-\delta_M(t))M(t)+\eta C(t),

where refresh and loss rates ρrefresh\rho_{\mathrm{refresh}} and δM\delta_M are in s1^{-1}, CC is candidate instances per second entering the memory pathway, and η\eta is a dimensionless conversion fraction. Storage without retrieval, refresh, invalidation, compatibility, and retirement is not credited as useful memory.

For copies mlm_l at location ll, compare placement policies with

minml0l[clmaintml+E(clmissUl(ml))+clmovevl].\min_{m_l\ge0} \sum_l \left[ c_l^{\mathrm{maint}}m_l+ \mathbb E(c_l^{\mathrm{miss}}U_l(m_l))+ c_l^{\mathrm{move}}v_l \right].

mlm_l and moved amount vlv_l use instances or bytes; unmet events UlU_l use events; coefficients convert all terms to joules or currency over one horizon. Local latency gains must pay for replication, refresh, inconsistency, invalidations, and recovery.

Reactivation and recovery gate

A quarantined, suppressed, or impaired module cannot be reactivated merely because load increased or the original detector score fell. Reactivation at time tt requires

Ri(t)=1[ei(t) is current]1[ui(t) authorizes re-entry]1[hi(t)himin]1[bi(t)bimin],\mathcal R_i(t)= \mathbf 1[e_i(t)\text{ is current}] \mathbf 1[u_i(t)\text{ authorizes re-entry}] \mathbf 1[h_i(t)\ge h_i^{\min}] \mathbf 1[b_i(t)\ge b_i^{\min}],

where indicators are dimensionless, health hih_i and its threshold share a declared unit or normalized scale, and resource headroom bib_i and its minimum share a unit such as joules, bytes, or operations per second. A pass creates a bounded probation state; independent outcome verification is still required.

Recovery time is measured to sustained useful service plus restored reserve:

Trecover=inf{ttf:Q(t:t+Δ)QminR(t:t+Δ)Rmin}tf,T_{\mathrm{recover}}= \inf\left\{t\ge t_f: Q(t:t+\Delta)\ge Q^{\min} \land R(t:t+\Delta)\ge R^{\min}\right\}-t_f,

where tft_f and TrecoverT_{\mathrm{recover}} are seconds, Δ\Delta is a frozen sustainment interval, and QQ and RR are task service and reserve in their declared units. A lower alert rate or an empty queue is not recovery.

Lifecycle boundary and null

Charge sensing, routing, candidate generation, training, evaluation, replication, serving, monitoring, replay, reserve, movement, retirement, and recovery in joules over the same horizon. Report task quality, false permit, false suppression, false deletion, missed harm, containment latency, verified recovery, rare-capability retention, second-event readiness, and energy as a vector.

The complete null is a typed state machine plus calibrated risk and abstention, least-privilege identity and access control, anomaly detection, constrained control, evolutionary or ensemble search where applicable, replay, placement, and resource-aware scheduling. Reject the immune framing if this ordinary stack reproduces its decisions and frontier at equal information, intervention, compute, storage, reserve, and maintenance budget.

Editable lifecycle diagram: typed-tolerance-lifecycle.mmd.