This English version is a courtesy translation, rendered without adding or rephrasing any claim. The French page at canonique.ai is the sole normative reference of the matrix; in case of divergence, the French text prevails.
The proof and value matrix
From declaration to produced value — v2.5
A status is a declaration. A written migration is an artifact; its application is an event. A test result is an observation. A log is a trace, not a verdict. A runtime effect is a situated fact. A closure is only opposable once authority, causality, scope, persistence, adversariality, and independent verification have been reconciled. And a delivered effect is not yet produced value until a real recipient has consumed it and an observable, attributable outcome follows from it.
The matrix qualifies claims about deliverables, mechanisms, effects, usage, and outcomes. It does not by itself decide competent authority, external legality, or the judicial admissibility of evidence.
Two axes, not one
The v1 of this page stacked proof and value on a single scale. That was a structural error, corrected on external review: a perfectly proven mechanism that no one consumes has not produced value, and a fragile beta can produce a great deal. Proof and usage are two independent questions. They are now scored separately.
The level attaches to a falsifiable claim, never to an entire task. When a piece of work contains several mandatory criteria, its level is that of the least-proven criterion. No averaging is permitted — this is the weakest-link rule. This rule applies to mandatory criteria joined by conjunction. Rules for alternation, condition, and quorum have been defined since v2.5 by conjunctive reduction — see the section on the algebra of non-conjunctive criteria; non-applicability is defined at the N-A state of the passport. They must always be declared before evaluation.
P levels are cumulative. A claim can only receive Pn if the requirements of all preceding levels are also satisfied within the same scope. A successful adversarial trial does not compensate for unestablished causality; independent verification does not compensate for an effect that was never exercised in the target runtime.
The atomic unit: the claim
The level attaches to a claim; but the claim must first be evaluable. Every evaluated claim must declare ten mandatory fields: a stable identifier; the exact proposition; the object concerned; the expected outcome; the falsification condition; the scope — organization, environment, version, actors, perimeter; the time window; exclusions; criticality and the required threshold — required P level, required V level where relevant; the revision condition.
Admissibility rules follow from this. A claim without scope cannot be evaluated. Without a falsification condition, it is not falsifiable. Without a time window, it cannot indefinitely support a present-state claim. Without a pre-set threshold, it cannot determine its own success. An ambiguous claim must be reformulated before any promotion.
For a claim created after this version takes effect, three fields carry declared defaults, overridable by explicit declaration at creation. The required threshold follows the deliverable's class: an artifact closes at P1, a runtime effect at P4, a constitutional guarantee at P8. The default time window runs until the declared deadline plus ninety days. The default revision condition is a detected regression. A claim silent on these three fields remains admissible under these defaults, which count as pre-registration; a claim silent on any other mandatory field remains inadmissible. Defaults never apply retroactively: prior claims fall under the transitional regime.
The algebra of non-conjunctive criteria — by reduction, not by invention
v2.3 bounded the weakest-link rule to mandatory conjunctive criteria and left alternation, condition, quorum, and non-applicability pending. v2.5 defines them without creating a new algebra: each reduces to a conjunction as soon as the choice of path is itself reified as a claim.
Alternation (A ∨ B). Branch selection is a mandatory, pre-registered claim, subject to the ten fields of the ontology. The proven structure is never "A or B" but: branch selection ∧ selected branch, and the level of the whole is P(result) = min(P(selection), P(selected branch)). Explicitly forbidden: P(A ∨ B) = max(P(A), P(B)) — taking the maximum of the branches would allow choosing, after execution, the best-proven branch, a form of the retroactive choice of favourable criteria already proscribed by the closure rule. The claimed branch must be declared before evaluation; failing that, the axis concerned is in state ?. Principle: an alternative is not proven by proving one branch. It is proven by proving why that branch was the one that applied.
Condition (if X then A). A conditional obligation decomposes into three conjunctive claims: classification — X was correctly evaluated; applicability — that evaluation genuinely entails this branch; execution — the branch satisfies its obligation. The weakest link applies to all three. A branch not executed is never deemed successful: it is N-A if and only if the rule making it inapplicable is itself established and cited, in accordance with the definition of N-A. Declaring a condition inapplicable after seeing the result of the other branch constitutes a retroactive choice of criteria and makes the closure non-opposable.
Quorum (k out of {A, B, …}). Before any count, four prior claims: the admissible set, the mutual independence of the members counted — two proofs derived from the same source are not two confirmations —, the common scope, the pre-registered selection rule. P(quorum) = min(P(prior claims), k-th best P among admissible members). Double counting — the same evidentiary artifact, the same source of judgment, the same execution infrastructure counted twice — invalidates the quorum and drops it back to state ?.
What v2.5 does not do. Neither a graph of claims nor a new operator. If practice shows that conjunctive reduction does not suffice — with a real case in support — the graph representation (requires, alternative_to, conditioned_by, quorum_with, evidenced_by) will be considered then. Structure after usage.
Axis P — Proof scale
- P0 — Declared. A claim exists. Within the inspected scope, no higher-level verifiable evidence is available.
- P1 — Materialized. An artifact exists: code, a written migration, a specification, a procedure.
- P2 — Observed. A behavior is demonstrated in a defined context — a test environment, for example.
- P3 — Exercised. The real effect is produced in the target runtime.
- P4 — Causally proven. The effect genuinely comes from the announced mechanism, not from a failure, a bypass, or another control.
- P5 — Adversarially proven. The mechanism withstands a minimal set of adversarial scenarios proportionate to risk, defined before execution: allowed path, forbidden path, bypass, malformed input, dependency failure, state verified after failure — where applicable. The refusal is explainable, and state remains intact or returns to a safe state. For a control surface, the minimal form remains the triplet: the allowed path passes, the forbidden path fails, state is unchanged after refusal.
- P6 — Persistent and durably verifiable. Evidence remains reconstructible and verifiable within the declared scope and time window. For a continuous mechanism, monitoring proportionate to risk detects its disappearance or degradation. For a one-time act, persistence concerns the preservation, integrity, provenance, and durable verifiability of its evidence. Historically preserved evidence can remain valid for the past event without thereby supporting a claim about the present state.
- P7 — Independently verified. A distinct verifier reconstructs the evidence and reaches the same verdict — within the tolerance declared in advance for probabilistic systems. Independence must be declared: changing model or identity is not enough if the verifier inherits the same judgment artifact or the same expected conclusion.
- P8 — Opposable. Authority, mandate, consent where applicable, causality, scope, persistence, adversariality, independent verification — and revocability where it constitutes a guarantee of the mechanism — are reconciled. The closure can be defended before a third party. "Opposable" here means defensible within the institutional framework that employs it — not automatically before a court of law. In this version, opposability remains the terminal level of the P axis, for doctrinal continuity and pilot operability. The eventual separation between proof, value, legitimacy, and closure decision (P/V/L/F — L for legitimacy, F for closure) will only be introduced if the findings of a first automatic closure demonstrate its necessity.
Axis V — Usage and value scale
- V0 — Not consumed. No real recipient depends on it.
- V1 — Consumed. A real recipient uses the deliverable or depends on the effect.
- V2 — Demonstrated value. Consumption produces an observable outcome reasonably attributable to the deliverable: reduced risk, improved decision, time saved, revenue obtained, damage avoided, new capability. V2 establishes the existence of demonstrated value, not its magnitude, distribution, cost, or durability, which must be documented separately.
P and V qualify two related but distinct claims. P measures the probative strength of the claim made about a mechanism or deliverable. V describes its state of usage and value production. Every value claim — for example, "this mechanism reduced incidents" — itself carries a P level. V2 therefore does not abolish the requirement for causal proof.
A security gate can be P8/V0 if it is opposable but no real process yet uses it or depends on it. As soon as it constitutes a mandatory passage for real operations, it is at least V1, even if it has not yet refused any action. A beta can be P3/V2: still fragile, but already useful. The two scores state two different truths.
Transversal states
- ? — Not evaluated. The relevant axis has not been evaluated. P? means the probative strength remains unknown; V? means usage or value has not been determined. Absence of inspection never converts into proof of absence.
- ⊥ — Contradictory. Two sources diverge on the same claim within the same scope. P⊥ signals a contradiction bearing on the facts or their evidence. V⊥ signals a contradiction bearing on consumption, the recipient, or the produced outcome. This is the most honest state, and the only one that forces reconciliation. No source wins by mere precedence. A divergence only becomes a contradiction after scope normalization: different outcomes on different scopes are a scope gap, not a contradiction. And if the contradiction touches a live security guarantee, the first licit action is fail-closed containment; reconciliation comes afterward.
Closure rule
The threshold is set before execution, never after seeing the result. A task claiming a technical effect in the target runtime should not normally be closed below P4. A task whose expected deliverable is an artifact — specification, design, written migration, or procedure — can legitimately close at a lower level when that threshold was declared before execution. A constitutional guarantee should not be declared effectively assured below P8. A product should not be declared value-creating below V2. The required level is proportionate to criticality: requiring P8 everywhere is paralysis, closing at P2 everywhere is a lie. And no proof justifies creating a real risk: in production, the counterfactual trial is non-destructive, reversible, isolated, or replaced by equivalent evidence.
The threshold is pre-registered: declared before execution, kept alongside the claim, then compared to the verdict. Any later modification creates a new version of the claim and never applies retroactively to the execution already observed. Explicitly forbidden: modifying the applicable threshold after seeing the result; retroactively picking favorable criteria; narrowing scope without creating a new claim; requalifying a deliverable after the fact; converting absence of inspection into proof of absence; presenting historical evidence as a current guarantee.
Temporality
Every level is bounded by a scope and a time window. Expired evidence does not disappear: it remains historically true, but no longer supports a claim about the present state. A regression never rewrites a past closure: it opens a delta linked to the original receipt. "Proven on August 3" and "still works today" are two distinct claims.
Revision and re-evaluation are never conflated. A revision changes the text — that of the matrix or that of a claim — and creates a new, dated version, without ever rewriting prior versions. A re-evaluation renders a new verdict on fresh evidence, the text of the claim remaining unchanged; it is re-evaluation that triggers the revision condition of the tenth field.
The two symmetric errors
This grid guards against both at once: re-executing work already delivered because a dashboard is stale, or closing a task because a log claims a success the runtime no longer reproduces. Authority answers "who had the right to decide"; proof answers "what actually happened". Levels P0 through P7 bear primarily on the second question. P8 then reconciles the established facts with authority, mandate, consent, and the other applicable legitimacy conditions. The two questions must meet to render a closure opposable, without ever being conflated.
The proof passport (pilot)
Every evaluation produces a receipt, including when it cannot assign a level or recommend a closure. The prototype — explicitly not fixed, amended by pilot findings — carries: claim_id, exact proposition, object, scope, window, falsification condition, required P/V thresholds, observed P/V levels, cited evidence, missing evidence, contradictions, gap to threshold, recommended decision, reasons, limits of the evaluation, and re-evaluation condition.
Three categories of outputs are distinguished, and are never conflated.
Recommended decision: ALLOW · DENY · HITL · N-A. Transversal state of the evaluation: ? — not evaluated or indeterminable; ⊥ — contradictory. Possible reasons: threshold met · below threshold · inadmissible claim · incompatible scope · pre-set threshold absent · expired evidence · causality not established · independence not established · unresolved contradiction · human judgment required.
The future legitimacy gate, should it come to be, may reuse the decision vocabulary without conflating it with the states of knowledge or the reasons for the verdict. The final receipt format will be earned through pilot use, not designed ahead of it.
- N-A — Not applicable. The evaluation or decision requested does not apply to the claim within the declared scope. The applicability rule and its justification must be cited. N-A means neither success, nor failure, nor absence of evaluation.
The licit combinations between evaluation state and recommended decision are constrained. Level met, no blocking contradiction: ALLOW or HITL. Below threshold: DENY or HITL. State ?: DENY, HITL, or justified N-A — never ALLOW. State ⊥: DENY or HITL — never ALLOW while the contradiction remains blocking. Pre-set threshold absent: DENY, or non-opposable calibration under the transitional regime. Expired evidence: DENY for a claim about the present state; the historical finding remains possible.
An exception — in the sense of the temporary_exception schema — never turns an unmet requirement into satisfied evidence. It can only temporarily authorize a decision despite the gap, under a competent authority, a bounded duration, compensating controls, and an exit condition. An exception to the rule is not proof of compliance with the rule.
Passport — verification mode and execution independence
v2.4 leaves a blind spot between P6 and P7: a distinct verifier may re-read the traces produced by the first actor, reach the same verdict, and satisfy P7 without anyone having reproduced the effect. Persistence — the proof survives —, reproduction — the effect is reproducible from the declared conditions — and independent judgment — a third party concludes without inheriting the judgment — are three distinct properties.
v2.5 does not renumber axis P. It instruments it. Two fields are added to the proof passport.
- verification_mode. Documentary examination · replay · independent re-execution. Documentary examination: the verifier re-reads the existing evidence. Replay: they replay the scenario from the deposited artifacts. Independent re-execution: they reproduce the effect from the declared conditions, without the first actor's execution artifacts.
- execution_independence. None · partial · independent. Declares whether the verifier shares with the initial actor the execution infrastructure, the judgment artifacts, or the expected conclusion.
A P7 obtained by mere documentary examination remains a P7, but the passport now says so. Falsification condition for the missing level: the day a real case produces "independent documentary examination PASS" and "independent re-execution FAIL" on the same claim and the same scope, the need for a distinct step between P6 and P7 will have been demonstrated experimentally, and the axis will gain a rung. Until then, it gains none.
Reliance
The hypothesis of a "V3 — institutional dependency" is rejected. It would break the cumulativity of axis V: an organization may depend structurally on a mechanism that has never produced demonstrated value — lock-in on a useless tool is commonplace. Dependency is not above V2; it is oblique to it. V1 already contains simple dependency.
Instead, v2.5 operationalizes the proportionality clause already present in the closure rule through a field of the claim.
- reliance. Incidental · operational · critical · systemic. Default: operational. Overridable by explicit declaration at creation, never retroactive.
Reliance does not raise V. It hardens P: the higher the dependency, the higher the required P threshold, the surveillance demanded under P6, the revalidation frequency, and the requirement for fallback and revocability — and the lower the acceptable cost of an unresolved contradiction. A mechanism at systemic reliance in state ⊥ on a live guarantee calls for immediate fail-closed containment. Principle: value says whether the thing helps. Reliance says how dangerous it is to be wrong about it.
Transitional regime
For a claim created before v2.2 took effect, the verifier may establish the observed P and V levels, but may not recommend ALLOW in the absence of a genuinely pre-registered threshold. A threshold reconstructed from the deliverable type or from existing conventions must be explicitly marked "reconstructed, non-opposable" and serves calibration purposes only. It cannot retroactively justify a closure.
The matrix applied to itself
Its promotion protocol is falsifiable: P1/V0 at publication; P2 when historical cases have been classified with it by distinct evaluators reaching consistent results; P3/V1 when a real work system actually uses it to determine a closure; P5/V1 when it withstands the following adversarial corpus, proportionate to risk and declared pre-registered as of August 5, 2026 — this dated publication constitutes the pre-registration that P5 requires: scope substitution, expired evidence presented as current, incomplete or falsified receipt, contradiction between status and runtime, abusive aggregation of criteria, confusion between authority and effect, and an attempt at promotion grounded in its own conclusion; P7/V1 when a third party classifies the same cases and obtains reproducible verdicts; P8/V1 when the rule is ratified and leaves an opposable trace; P8/V2 when its use measurably reduces false closures, unnecessary re-executions, or reconciliation time.
The incidental blocking of a false closure constitutes a real exercise and an indicator of value, but is not sufficient to establish P5 until the adversarial scenarios have been defined before evaluation and executed as such.
Findings
August 3, 2026, the day of the matrix's initial publication: the scale, in its v2.0 revision, was used to determine a real closure — two tasks resolved on confronted evidence, receipts in support — and refused a closure that would have gone through without it, a scope substitution having been detected by the verification it imposes. Findings dated and sourced in the internal register of La Machine (partage.ai). By its own grid: P3, and V1 in the narrow sense — consumed by its authors. Consumption by an independent third party is still to come; this page will keep saying so for as long as it remains true.
History
v2.5 — August 8, 2026. On the findings of the August 5 pilot — N-A used without definition, combinations applied without a rule — and the analysis session of August 8: the algebra of non-conjunctive criteria defined by conjunctive reduction — branch selection, the classification of a condition, and the prior claims of a quorum are mandatory pre-registered claims subject to the weakest link; max(branches) explicitly forbidden as a retroactive choice of criteria; a branch not executed is N-A only if its rule of inapplicability is established. Passport: verification_mode — documentary examination · replay · independent re-execution — and execution_independence — none · partial · independent — added; axis P is not renumbered: the need for a step between P6 and P7 will be demonstrated by the first "examination PASS / re-execution FAIL" case, not decreed. V3 rejected — dependency without value would break the cumulativity of V; a reliance field — incidental · operational · critical · systemic, default operational — added to the claim, modulating the required P threshold and not the V level. The graph of claims is noted as a possible destination for aggregation, pending a real case that conjunctive reduction does not cover. Structure after usage, always.
v2.4 — August 7, 2026. On founder arbitration of the seven points open since v2.2 (internal register, decision of August 7): normativity settled — the French page is the sole normative reference, the internal mirror is subordinate to it; per-class defaults for the new flow — threshold following the deliverable's class (artifact P1, runtime effect P4, constitutional guarantee P8), window deadline plus ninety days, default revision condition the detected regression, all overridable, never retroactive; the L and F acronyms spelled out at P8; revision and re-evaluation defined and distinguished; the anglicism "findings" replaced by the French "constats" in the wording of the P8 body — the history entries themselves remain unchanged, per this page's append-only rule; the claim_id identifier kept as-is, a machine convention. Reason for the defaults: without them, nearly every claim in the current flow came out "ambiguous claim" and the ongoing calibration would have had nothing to compare against. Same-day correction, same version number — v2.2 precedent: the "runtime effect" default, briefly published at P3, is aligned to P4 upon detection of a contradiction with this page's Closure Rule; author decision recorded in the internal register.
v2.3 — August 5, 2026. Following a fourth external review and the first findings of the report-only pilot — 27 critical tasks evaluated that same day, where N-A had been used without a definition and state-decision combinations applied without a rule: normative purpose and scope declared — the matrix decides neither competent authority, nor external legality, nor judicial admissibility; N-A defined; licit combinations between states and decisions fixed — never ALLOW on ?, on a blocking ⊥, or without a pre-set threshold; the weakest-link rule explicitly bounded to mandatory conjunctive criteria, with the algebra of alternation, condition, and quorum still pending; the exception principle fixed — a temporary_exception never amounts to proof of compliance. The rest of the completeness table — closure decision, state machine, aggregation, receipt integrity, contestation, reopening, P/V/L/F separation — remains pending on the first automatic closure. Four versions in three days: the doctrine continues to be earned through use.
v2.2 — August 5, 2026. Following a third external review: mandatory ontology of the claim — ten fields and admissibility rules; formalized threshold pre-registration — any later modification creates a new version of the claim, never retroactive; P6 refocused on the durability and reconstructibility of evidence, with scope now required from admissibility onward; pilot proof passport distinguishing recommended decisions (ALLOW/DENY/HITL/N-A), transversal states (?/⊥), and reasons; transitional regime for prior claims — reconstructed threshold marked "reconstructed, non-opposable", reserved for calibration; self-promotion adversarial corpus declared pre-registered; single normative reference clause. The complete procedural apparatus — algebra, API, contestation, P/V/L/F separation — remains explicitly pending on the findings of the report-only pilot: structure after use.
v2.1 — August 3, 2026. Following a second external review: cumulativity of P levels fixed; P0 reformulated (a claim exists, no higher verifiable evidence within the inspected scope); P/V articulation clarified — every value claim itself carries a P level, V2 does not abolish causality; the gate example corrected (a mandatory passage for real operations is at least V1); transversal states ? and ⊥ extended to both axes; closure rule made proportionate for artifact-deliverables; the P5 threshold of the self-promotion protocol hardened — an adversarial corpus defined before evaluation, incidental blocking remaining an indicator, not a P5; the place of authority within P8 clarified. The whole is now called a matrix; each axis remains a scale.
v2.0 — August 3, 2026. Two-dimensional P/V model on external review: proof (P0-P8) and value (V0-V2) become two independent axes; transversal states P? and P⊥; the weakest-link rule; threshold set before execution; append-only temporality; prohibition on creating a real risk to raise a level. Post-ratification obligation honored: the public mirror joins the normative reference. First usage findings the same day.
v1.1 — August 3, 2026. N5 generalized, N6 dual-form, causal attribution, N⊥ promoted, falsifiable self-promotion protocol, limits acknowledged.
v1.0 — August 3, 2026. Initial publication, one-dimensional N0-N10 model. Three versions in one day: the doctrine was challenged on the day of its birth, and that is the method.
The French page is the sole normative reference of the matrix — arbitration rendered on August 7, 2026: the internal register of La Machine that previously carried it normatively becomes a subordinate mirror. Any companion document — internal mirror, mapping, session analysis — is non-normative until integrated here through a dated version.