The governance ledger¶
Nerthus.Core (until cutover). This page describes the frozen system that runs today and is deleted at cutover. Replaced by: not yet written.
Who held which function when, which rule was in force on a day, and which rozporządzenie was live — as data, with every state change citing the forum post that asserts it.
Every read here carries no capability. The Rada publishes its own composition on a public forum every month, so a ledger of that record readable only by the people in it would answer less than the thread it supersedes.
Routes¶
| Method | Path | Cmdlet | Cap | Write |
|---|---|---|---|---|
| GET | /governance/refs |
Get-NerthusGovernanceRef |
— | — |
| GET | /governance/pin |
Get-NerthusGovernanceRef -Pin |
— | — |
| GET | /governance/{ref} |
Get-NerthusGovernanceRef -At |
— | — |
| GET | /governance/{ref}/log |
Get-NerthusGovernanceRef -Log |
— | — |
| GET | /governance/{ref}/held |
Get-NerthusGovernanceRef -Held |
— | — |
Cap is the required capability (— = public, no token). Paths are relative to /v1/api; the
cross-cutting contract is on the API reference index. The narrator permissions table
lives at /governance/permissions and is a different subject with a different capability —
Governance covers it.
Route order is load-bearing. /governance/permissions is declared before /{ref}, or it
resolves to it and answers unknown ref: permissions. /governance/refs and /governance/pin are
literals for the same reason. None of the three is a ref name, and none becomes one.
The nine refs¶
A ref is one governance domain, and the domains advance independently: a Namiestnik change is not a
PU-rule change. kind decides how a ref replays.
| ref | kind | cardinality | what a read answers |
|---|---|---|---|
namiestnik |
role | one | the holder |
rada |
role | many | the sitting Radni |
sekretarz |
role | one | the holder |
narratorzy |
role | many | the roster |
rozporzadzenia |
instrument | set | the instruments in force, with their status |
pu-rules |
rule | value | the rule text in force |
mechanika |
rule | value | the rule text in force |
nicki |
rule | value | the rule text in force |
zadania-stale |
rule | value | the current task table |
GET /v1/api/governance/refs returns { count, items, corpus, findings }. A ref with no
transitions is still a row — the refs are declared in code and the ledger is what has arrived, so
known and empty stays a different statement from does not exist. corpus: null means this host
has no works tree, which is a supported state and not a fault.
HEAD and as-of are one route¶
GET /v1/api/governance/{ref} replays the ref's transitions and answers the state. ?at= moves the
date; without it the answer is now.
{
"ref": "namiestnik", "title": "Namiestnik", "at": "2024-06-01", "at_ig": 1336,
"kind": "role", "cardinality": "one", "applied": 3,
"holders": [
{ "subject": "Zireath", "since": "2023-07-18", "until": null, "grade": "",
"suspended": false, "confidence": "średnia", "source_authority": "sprawozdanie",
"evidence": [{ "post": 46014766, "author": "Zireath", "quote": "chciałabym podziękować osobom, które oddały na mnie swój głos w tych wyborach na Namiestnika" }] }
],
"instruments": [], "value": null
}
An ?at= that does not parse answers 400 rather than falling back to today, the same posture
/regulations/effective takes: a view that asked who was Namiestnik in 2023 and silently got
today's answer renders the wrong name beside a real record, and nothing on the page would say so.
applied is how much history the answer rests on, and it is what separates two empty answers.
applied: 0 means the ledger reaches no transition on or before that date; the capture opens in
April 2021 with a Rada already sitting, so a date before that is a statement about the ledger and
not about the world.
A single-holder ref evicts on appointment. The corpus rarely writes the last Namiestnik stopped because a new one started; it writes the appointment. Without the eviction the ledger would hold two at once and answer whichever came first.
An instrument publishes confidence and source_authority, the same two fields a holder
does. They are what ruling 3 resolves a disagreement by, so an instrument without them is a
decision resting on something the read path drops. The 2021 narratorskie quotes its own §-text and
reads exact / rozporzadzenie; the 2021 delicate-topics rule was read out of a monthly report
that never calls it a rozporządzenie and reads średnia / sprawozdanie. Both are
obowiązujące on the same day, and only these two fields separate them — the weaker one is also a
row on the governance worklist, which is where an uncertain authority is meant to be settled.
A bounded instrument expires by the clock. The Riveth block runs to 2026-11-02 and reads
obowiązujące that day and wygasłe the next, with nobody editing anything. Status is a function
of ?at= and of the bound, never a stored field. de_facto is a separate axis: the 2021
narratorskie is formally in force and described in the corpus as a dead procedure, and the answer
carries both.
suspended: null means the ledger does not answer, and it is a third value beside true and
false. suspended is set by the suspend op alone, so false asserts held and exercised —
and for a narrator on urlop that assertion is wrong. The corpus draws the distinction itself:
urlop is a leave somebody takes, zawieszenie is an act performed on somebody, and the ledger
keeps them apart rather than recording one as the other. So the grade stands, membership is
unaffected — a narrator on leave is still on the roster — and the claim about exercise is
withdrawn. nieaktywny is deliberately not in that set: it is a rank the corpus writes as
held (piastuje rolę Narratora nieaktywnego), so whether it is exercised is a question the
sprawozdania do not answer either way.
Did one person hold it that day¶
GET /v1/api/governance/{ref}/held?subject=<name> answers membership rather than handing back the
holder list, because the matching is the hard part:
{ "held": true, "ref": "narratorzy", "title": "Narratorzy", "subject": "Eamon Velle (Pekeryn)",
"matched": "Eamon Velle", "at": "2025-01-15", "since": "2024-11-02", "grade": "próbny",
"suspended": false, "applied": 4 }
matched is the name the ledger carries, which need not be the spelling asked for: the corpus
writes one person under two names in the same sentence, and a caller comparing strings over
holders answers false for Eamon Velle (Pekeryn) against Eamon Velle and for Vanda
against Vanda Vanissa. The fold accepts a token subset in either direction and lives in one
place so every caller gets the same answer.
subject is required — 400 without it. There is no default person to ask about, and answering
held: false for an unasked name would be a claim rather than a refusal. applied: 0 separates
left the function from the ledger reaches nothing on or before that date.
The pin: everything at once, computed¶
GET /v1/api/governance/pin?at=<yyyy-MM-dd> answers the whole governance state for one day —
the Rada term, every ref, and the regulation version in force for each document:
{
"at": "2024-06-01", "at_ig": 1336,
"kadencja": { "year": 2024, "from": "2023-12-31", "to": "2024-12-30" },
"refs": { "namiestnik": "Zireath", "rada": ["…"], "rozporzadzenia": ["narratorskie"],
"pu-rules": "…" },
"regulations": { "rozporzadzenia-rady": "2023-08-02", "…": null }
}
It is derived from the date at read time and never stored. The keyring's @epoka is the
cautionary case one layer down: designed pin-then-verify, implemented as an integer nothing on the
read path checks, so it documents the epoch instead of enforcing it. A pin nothing verifies is
documentation — and so is a pin nothing calls, which is why this is a route.
regulations carries a row per declared document with a null version where nothing was in force
on that day, the same posture /regulations/effective takes. No text was in
force and nobody looked are different answers, and the surface never conflates them.
The log carries the evidence¶
GET /v1/api/governance/{ref}/log returns every transition oldest first, narrowed by ?since= and
?until=, which parse under the same strict rule as ?at=.
Each row carries two dates because they are two facts. instrument_date is the day the document was
published; date is the day the state changes. The 2026 rozporządzenia are instruments dated
2026-06-15 whose effects run from 2024-08-08 and 2026-05-02, and one date field would have to
choose which of those to be wrong about. date_basis says what fixed date:
date_basis |
meaning |
|---|---|
stated |
the document names the day |
instrument |
nothing else does, so the document's own day stands |
regulation |
a rule fixes it — the Rada takes office on 31 December |
period |
the month a report covers, where it names no day |
source_authority is the ordering a disagreement resolves by: garmory, then rozporzadzenie,
then sprawozdanie, then podpis. The higher source is the state and the lower one is recorded
rather than deleted. conflicts carries the disagreement in prose, and a row that has one is a
worklist row on the governance surface of GET /normalization/suggestions.
confidence is the normalization ladder — exact, wysoka, średnia, niska. Ekipa Garmory and
a rozporządzenie's own §-text reach exact; a sign-off or a report's period caps at średnia,
because initials and continuity are confirmations rather than sources.
subject is the canonical name and subject_surface is the spelling the quoted post used, where
the two differ. The corpus writes one person under several names — Eamon Velle (Pekeryn),
Soll (Lorenzo de Clemente) — and a replay keyed on the spelling carries a ghost per alias.
Where the ledger lives¶
governance/ledger/<ref>.jsonl in the works repository (corpora.dziel), beside the sprawozdania
it is extracted from. A correction is an ordinary reviewed commit: the repository's own git history
is the audit layer, one level up, which is the two-layer arrangement the
regulation corpus already uses for raw against transcription.
The interface is git's and the backend deliberately is not. A commit-per-transition repository with backdated authors cannot be corrected without rewriting history, and this is extraction from prose, where corrections are certain.
What the findings say¶
GET /v1/api/governance/refs returns findings beside the refs. Four kinds, all of them things no
single row can reveal:
| kind | what it means |
|---|---|
GovernanceEvidenceMissing |
a row cites no post, and is refused rather than replayed |
GovernanceLeaveWithoutHold |
somebody left a function the ledger does not record them holding |
GovernanceDoubleAppoint |
somebody took a function twice with no departure between |
GovernanceSilentSuccession |
a single-holder ref changed hands and the departure was never written |
GovernanceReturnWithoutLeave |
somebody returned from an absence the ledger never records beginning |
GovernanceLeaveWithoutHold is a Warning rather than an Error on purpose: the capture opens with
functions already held, so the earliest departures legitimately have no matching appointment.
GovernanceReturnWithoutLeave is the same shape one axis over. return publishes absent: false,
which asserts the person is present — and the Rada writes returns without departures: „Do
pełnienia funkcji wrócili Achalen, Emryh oraz Lottie" names three returns and no leaves. The rows
stay, because the return is stated; the finding says the interval has only one end.
Absence: leave and return, on the role refs¶
An absence is one person's relationship to one function over an interval, which is the shape a role
ref already carries — so there is no tenth ref for it, and suspend/dispense sit beside it for
the same reason. Neither op moves membership. A Radny on leave is still a Radny, and the
regulation says so: nerthus-fabularny 6.8 makes the notice a duty of the holder, which
presupposes they still hold it.
{ "ref": "namiestnik", "seq": 8, "date": "2021-07-22", "op": "leave", "subject": "Shalley",
"act": "self-notice", "until": "2021-08-15", "sieve": "nieobecnosc-samozgloszenie",
"evidence": [ { "post": 45042071, "author": "Shalley",
"quote": "Zgłaszam nieobecność od 23.07 do 15.08.2021 z powodu wakacji." } ],
"source_authority": "sprawozdanie", "confidence": "wysoka" }
act is the whole design and it is not decoration. Two different acts with different authority
mention absence, and only one is regulation-mandated:
act |
what it is | who owes it | where |
|---|---|---|---|
self-notice |
the holder discharging their own duty | Radny 6.8, Namiestnik 9.5, MC 11.3 | Miejsce Publiczne |
mention |
the Rada reporting somebody else's absence while discharging its monthly summary duty | point 4.2 | the sprawozdanie |
A narrator owes neither. rozporzadzenia-rady § 7 pkt 6 obliges a narrator to report absence
to the Rada, privately, and no provision obliges anybody to publish it. So a narrator absence
carried by one source and silent in the other is lawful silence, and a consumer must not read
it as a disagreement. That is what keeps an alert surface from reporting the regulation working.
Which ref an absence attaches to when somebody holds several is derived, not picked. A public
self-notice discharges a duty that falls on the Radny, the Namiestnik and the MC and on nobody
else, so it attaches to the governing ref and never to narratorzy — even when the same person
is also a narrator. A third-party mention attaches to whatever the sentence itself names.
absent is three-valued and null is the common case. It starts null and only a row moves
it, because a published boolean with no third value asserts the negative: absent: false on a ref
carrying no absence row at all would assert presence out of silence, which is the defect
suspended: false carried for a holder on urlop.
until_precision says how exact until is. day when the notice names one; month when it
names only a month — „zgłosił urlop do września" — where the date carries the convention the
first of that month. Publishing until: null there would assert an open-ended absence against a
source that states an end, and a worklist row reading the table shows active, the ledger shows
absent would then point the reader at the wrong side.
until is the end the notice STATES, and the replay does not close the interval on it. An
absence that outran its own notice is the case Shalley's removal turns on — reported to
2023-04-01, at exactly the 9.5.1 cap, then 94 days unreported to the removal on 2023-07-04. A
replay that expired the absence on its stated end would answer that she was present throughout.
See also¶
- Governance — the narrator permissions table, a different subject on the same path prefix
- The regulation corpus — the texts, where the ledger holds the facts
- Record a sprawozdanie — the monthly chore that feeds it