PRODUCT — {427.2} A bundle that can say 'we do not know this'
PRODUCT — {427.2} OKF producer inversion
Section titled “PRODUCT — {427.2} OKF producer inversion”Task: id-427. Artefact: {427.2} PRODUCT. Date: 09/08/2026 (S546).
Reads: RESEARCH.md {427.1}. Executes: DR-141, DR-027 (S546 amendment),
DR-019 (S545/S546 amendments). Interlocks: id-422, id-426, id-428, id-429, id-431, id-358, id-362 F1.
1. The product point
Section titled “1. The product point”A procurement answer is worth having only if the absence of one is also worth having. The outcome DR-141 names is a user or agent being able to trust:
“We do not know this — escalate to an SME.”
over the thing our bundle can actually support today:
“I could not find it.”
Those are different claims. The first is a statement about the corpus; the second is a statement about a search. A bundle can only carry the first if it is a faithful projection of the corpus — if everything the corpus holds is reachable from it, so that what is missing from the bundle is missing from the knowledge base, not missing from the routing.
Today the bundle cannot distinguish absent-because-unknown from
absent-because-unrouted. A published source document that never produced a Q&A pair,
and a published Q&A pair with no scope_tag, are enumerated by nothing: not rejected, not
logged, absent from the run summary. No reader — human or agent — ever learns they existed.
The bundle looks complete because nothing was ever counted.
That is the defect this task fixes. Everything else here follows from it.
2. Behaviour invariants
Section titled “2. Behaviour invariants”These are the statements a reader must be able to make about any bundle this producer emits. Each names the requirement it serves and that requirement’s current source.
PI-1 — Coverage by construction
Section titled “PI-1 — Coverage by construction”Every published unit the corpus holds — every source_document, every q_a_pair — is
reachable from at least one concept in the bundle. Not by a grain having been added for
it, but because whatever the preferred grains miss falls into a residual grain defined as
the complement.
Requirement source: DR-141 Decision + Consequences (the negative answer). Note: the invariant is coverage (≥1), not partition (=1) — see RESEARCH §5 C4 and TECH §2.1. DR-141’s “exactly one” wording needs a rider; the product need is coverage.
PI-2 — The denominator is always published
Section titled “PI-2 — The denominator is always published”Every run states what it considered, not only what it changed. A run that changed nothing says how many units it considered and how many it routed. “Nothing was skipped” can never again appear without the number next to it.
Requirement source: id-427 AC 4; DR-141 Alternatives — “nothing is skipped, because nothing is ever considered.”
PI-3 — A concept may exist with no knowledge in it
Section titled “PI-3 — A concept may exist with no knowledge in it”A held document from which nothing has been distilled produces a concept whose body says so, in plain words, and cites the record. The absence of an answer is itself a publishable fact about the corpus.
Requirement source: PI-1’s purpose. A coverage guarantee that produced silent placeholder files would satisfy the letter and lose the point.
PI-4 — A no-content concept is never model-written
Section titled “PI-4 — A no-content concept is never model-written”Its body is rendered deterministically from record metadata. No agent loop runs for it.
Requirement source: BI-15/BI-17 (Pass-1 drafts from records only; a citation must be an anchor the producer actually issued) and the product point itself — “we do not know this” must be verifiable by the reader. A model asked to write about a document whose body it cannot read will write something, and that something will read exactly like knowledge.
PI-5 — type never gates existence, and never decides location
Section titled “PI-5 — type never gates existence, and never decides location”A concept whose type the platform has never emitted before is drafted, written, validated, indexed and served exactly like every other concept. A concept’s identity does not change when its label changes — relabelling a concept must never move its file.
Requirement source: DR-141 Decision; OKF §1 Non-goals (“defining a fixed taxonomy of concept types”); OKF §4.1 (consumers MUST tolerate unknown types).
PI-6 — No artefact declares which types are permitted
Section titled “PI-6 — No artefact declares which types are permitted”Not the validator, not ontology.json, not context.jsonld, not CONFORMANCE.md. type
is validated for shape — descriptive, self-explanatory, machine-stable — never for
membership.
Requirement source: DR-141; DR-027 as amended S546 (“under DR-141’s open concept vocabulary a closed declaration would assert something false”).
PI-7 — Bundle classes behave identically
Section titled “PI-7 — Bundle classes behave identically”What a client_business bundle may express, a showcase and a system_baseline bundle may
express. There is no per-class type vocabulary.
Requirement source: owner ruling (iii), S546, verbatim: “we should be conformant and uniform across bundle classes. Our current setup missed the very purpose of OKF (organic knowledge base growth), and it’s this that we need to resolve.” Boundary: gate mechanics only. The paused id-163 authoring lane is not re-opened.
PI-8 — Nothing the producer declines to emit is silent
Section titled “PI-8 — Nothing the producer declines to emit is silent”Anything considered and not written appears in log.md with a reason. A run that leaves any
considered unit unrouted is never reported as a no-op, even when the files on disk are
byte-identical to the previous run.
Requirement source: id-427 AC 4, extending the existing RunSummary.failed precedent
(bundle_writer.py:539-551, DR-047: “silent success is forbidden”).
PI-9 — The negative answer is navigable, not just present
Section titled “PI-9 — The negative answer is navigable, not just present”The residual concepts live in named directories a reader meets at the top of the bundle, so “what we hold but have not distilled” is a place you can open, not a fact you have to already suspect.
Requirement source: id-429 D2 (the root index becomes a directory listing) + IA-2 (the residual grain gets a named directory of its own).
3. The three states a bundle must be able to express
Section titled “3. The three states a bundle must be able to express”| State | What the bundle contains | What an agent may honestly say |
|---|---|---|
| Known | a concept with distilled answers and record anchors in sources[] | ”Here is the answer, and here is where it comes from.” |
| Known-absent | a concept exists for the held record; its body states that nothing has been distilled from it; confidence: no-content (→ status: draft once id-428 lands) | “We hold this material. Nothing has been distilled from it. Escalate to an SME.” |
| Not held | no concept, and the run census shows full coverage | ”This is not in the corpus at all.” |
Today only the first is expressible. The second is invisible. The third is indistinguishable from a routing bug — which is precisely why it cannot be trusted. After this task, all three are expressible and the third is backed by the census: the claim “not held” rests on a published count, not on a failed search.
What the bundle must never do:
- present a residual concept as though it were distilled knowledge (no model prose, no
invented summary, no
confidence: partial); - claim a completeness it cannot demonstrate (the census is the demonstration);
- carry any declaration of which types a consumer should expect.
4. What a residual concept looks like to a reader
Section titled “4. What a residual concept looks like to a reader”A single, honest page. Directory documents/; title from the document’s own filename;
body in two parts — what is known (that we hold this document, when it arrived, how it
was extracted, which entities it mentions) and what is not known (that no published
answer derives from it, and that any question it might answer is unanswered by this bundle).
It cites the record it is about, and nothing else.
The same shape covers the other two residual homes: questionnaire-responses/ for published
answers whose only lineage is the form instance they came from, and
unattributed-answers/ for published answers with no lineage at all. All three directory
names are readable words, so id-429’s sentence-cased headings read “Documents”,
“Questionnaire responses”, “Unattributed answers” with no extra label — this answers
id-429’s carried Q2 (TECH §2.4).
5. Scope boundaries
Section titled “5. Scope boundaries”In scope: enumeration, the residual grain, the type-as-label change across every gate,
the four closed registries, the facet vocabulary, dispatch unification (id-362 F1), the
ontology.json/context.jsonld consequences of DR-027’s S546 amendment, the id-358 rename,
the run census, and the delivered audit.
Out of scope, with its owner: the v0.2 field migration (id-426); the trust-slot
replacement (id-428); the index axis and the theme retirement (id-429); CONFORMANCE.md’s
fate beyond withdrawing superset 1 (id-431); scope_tag’s write path and publication gate
(id-422); the viewer/parser surfaces (id-439); re-authoring the id-163 system-baseline lane;
composing content_chunks bodies into concept reads (ruled pipeline-rebase-charter scope,
l_records.py:383-388).
6. UNDECIDABLE (carried verbatim)
Section titled “6. UNDECIDABLE (carried verbatim)”PQ-1. “A residual concept makes the existence of an undistilled client document visible
inside an artefact that is a client-owned git repo and may be shared onward. Is document
existence itself disclosable, and what live document is the source of that rule?” — DR-016
settles who owns the bundle, not what may be asserted in it, and no disclosure rule
with a current source could be named this pass. The design is written so the answer is
cheap either way: the residual grain is one registry entry and one directory, and a ruling
of “existence is not disclosable” narrows it to the q_a_pair cascade steps without
touching anything else.
PQ-2. “On the day id-422’s publication gate lands and an empty-scope_tag published
pair becomes impossible, is the residual cascade’s defensive branch retired, or kept
permanently as belt-and-braces?” — The S546 ruling says hole 1 is “enumerated defensively
until that gate lands”. It does not say what happens on the day it does. Retiring it makes
the census strictly weaker; keeping it costs one anti-join. Not decidable here — it is
id-422’s landing decision, and this spec keeps the branch behind a single grain-registry
entry so either answer is a one-line change.
PQ-3. “A residual questionnaire_response concept carries the same form-instance
lineage that BI-28 stamps onto won-bid proposals. Should a non-won form’s residual concept
be stamped with that provenance too, and what is the current source for the rule that
decides?” — BI-28’s stated requirement is “never an unattributed proposal”, which argues
yes; the owner’s S546 caveat is that “the entire procurement functionality is under review
as it’s clear that there is confusion and duplication currently”, which argues for
touching nothing. This spec does not stamp them, and records the question rather than
resolving it by default.
[S546, post-authoring: the three PQ UNDECIDABLEs above are RULED — see TECH.md “S546 post-authoring rulings — the five carried questions”.]