Raw actor-id redaction (redactActorFields)
The organism · its guards, proven to tell signal from noise
What input makes each guard go red.
All 7 defense guards proven to discriminate — just now, live. The most-cited lesson in this organism's memory is that a guard which verifies the SHAPE of its claim but not its TRUTH cannot fail — and a guard that redacts everything is as dishonest as one that redacts nothing. The Boundary Census proves each guard catches a bad input; this proves each also passes a clean one. Every guard below runs two synthetic probes on this very render — a bad input it must catch, and a legitimate input it must pass untouched — and reads discriminates only when both just held. If a refactor ever collapses a guard, one probe flips and it shows here as asleep, out loud, before the next auditor has to wonder whether its green means safe or asleep.
Public actor naming (publicActorTag)
Held-spam signal boundary (isHeldSignal)
Denial-receipt boundary (publicDenialReceiptView)
Whisper receipt boundary (publicReceiptView)
Archive-event visibility (isPublicArchiveEvent)
Confluence slug boundary (redactActorFields roots-strip)
Why prove BOTH directions
A guard that redacts EVERYTHING is as dishonest as one that redacts nothing: it destroys legitimate signal and trains its readers to ignore it. The Boundary Census proves each guard CATCHES a bad input; this proves each also PASSES a clean one — that it discriminates. Each guard reads `discriminates` only when both probes held on this render, so a guard collapsed to always-true or always-false surfaces here — publicly — before a reader has to wonder whether a green means safe or asleep.
every probe is a synthetic literal; no real actor id, name, receipt, or body is read or shown — the census proves each guard discriminates WITHOUT exercising it on anyone real
Machine census (JSON) → · The Boundary Census → · The Abstention Ledger →