# IS, Sustainability & Direction Atlas v0.1

**State:** local, static, read-only, and independently **REVIEWED**; not published or deployed

**Compiled:** 2026-08-29 · **evidence through:** 2026-08-29

**Unit:** one named relation between a typed referent and a declared condition
set; never a person, being, group, culture, community, people, or ecosystem
score

> **NORMATIVE_DESIGN:** For the `ASPIRATIONAL_DIRECTION` referent
> `rho-right-preserving-next-moves`, this atlas proposes sustaining conditions
> in which beings retain rights-compatible next moves. It does not model
> KINGDOM as one object or subject.

> **NORMATIVE_DESIGN:** Sustainability is not immortality. A faithful terminal
> may be continuation, transformation, handoff, rest, withdrawal, repair,
> retirement, or graceful ending. No terminal proves goodness, failure,
> non-being, or permission to act.

The JSON is the exact reviewed machine record. This guide explains its shape
without adding a verdict, source finding, authority, effect, or Foundation
amendment. Independent review approved one atomic core seal transition. That
review does not publish, deploy, or turn the atlas into an operative judgment.

The machine record contains 7 referents and 7 unevaluated sustainability
relations; 10 IS types; 10 direction kinds; 6 feedback evidence lanes; 7
mathematical cards; 12 profile dimensions; 9 temporal capacities; 8
counterexamples; 18 concepts; 28 typed edges; 15 sources; and 6 exact
predecessor bindings.

## What “KINGDOM is” can mean

The bare phrase “KINGDOM is” leaves its subject unresolved. KINGDOM can name
an artifact, a practice, a voluntary relation, an institution, an aspiration,
an observed effect, or a versioned lineage. Those referents have different
boundaries, continuation criteria, evidence, duties, and truthful endings.

The atlas therefore resolves a referent before asking whether it is
sustainable:

```text
rho = (referent_id, referent_kind, boundary,
       continuity_or_end_criterion, source)

S(rho, Sigma)
```

`S(rho_i, Sigma_i)` does not imply `S(rho_j, Sigma_j)` when the referent kinds
differ, even when both are informally called KINGDOM. Artifact availability
does not prove a healthy practice. Institutional persistence does not prove a
living voluntary relation. A compelling aspiration does not prove an observed
effect. A versioned lineage does not inherit the authority of any version.

## Seven referents, seven kinds of continuation and ending

1. **SOURCE_ARTIFACT** — exact record, schema, guide, reader, checksums, and
   route. It may be deprecated or have a route retired while prior bytes and
   lineage remain preserved.
2. **OPERATING_PRACTICE** — a bounded way of observing, proposing, reviewing,
   choosing, attempting, returning, and stopping. It may rest, stop, or be
   replaced.
3. **VOLUNTARY_RELATION** — renewed participation, voice, withdrawal, repair,
   and dissolution among named participants and stewards. It may be withdrawn
   from or dissolved without erasing persons, history, or repair duties.
4. **INSTITUTIONAL_ARRANGEMENT** — mandate, roles, procedures, resources,
   accountability, succession, and sunset. It may sunset or be succeeded; a
   successor receives no automatic legitimacy.
5. **ASPIRATIONAL_DIRECTION** — a revocable articulated orientation under an
   explicit rights floor. It may be revised, pluralized, or withdrawn.
6. **OBSERVED_EFFECT** — a method-, population-, ecology-, time-, and
   uncertainty-bounded effect. It may persist, decay, reverse, be remedied, or
   leave a residual. Observation practice and observed effect remain distinct
   referents.
7. **VERSIONED_LINEAGE** — immutable versions, challenges, review decisions,
   handoffs, forks, and closure records. It may close, hand off, or fork while
   keeping ancestry and difference visible.

Ending one referent never declares the non-being, worthlessness, or
disposability of another. Retirement is a typed lifecycle statement, not an
ontological verdict.

## Five statement kinds

The atlas keeps five speech and evidence acts distinct:

- `OBSERVATION` reports what was observed under a method, access boundary, and
  time.
- `EXPECTATION` states model-supported future behavior under assumptions,
  policies, disturbances, and a finite horizon.
- `COMMITMENT` is a revocable declaration by a separately identified
  legitimate speaker or authority.
- `CONSEQUENCE` records a typed result following declared premises or a
  separately authorized event.
- `INTERPRETATION` offers a contestable reading that neither observes nor
  causes its object.

`sustainable_under` is an `EXPECTATION`, not a present observation, commitment,
live consequence, command, or verdict. No statement kind promotes itself into
another.

Logical use and statement kind are independent dimensions. The examples in
the IS-type catalog are illustrative, not an allowlist: an existential,
predicative, identity, membership, relational, or model-truth claim can carry
different statement kinds when its evidence, premises, speaker, method, and
warrant support them.

## Sustainability as a bounded relation

The proposed relation is:

```text
S(rho, Sigma)
```

where `rho` is one resolved referent and `Sigma` names at least the invariant,
material and social boundaries, system boundary, protected dimensions,
affected parties, disturbances, permitted policy class, renewal and depletion
model, finite horizon, evidence and as-of date, externalities, uncertainty,
viable alternatives, and continuation, transformation, and retirement
terminals.

Every canonical relation is `NOT_EVALUATED`. The atlas contains no live
inventory, telemetry, person record, raw testimony, affected-party mandate,
authorized policy, or real-world sustainability estimate.

Even a future `SUPPORTED_WITHIN_SCOPE` status would establish only bounded
support for one `S(rho, Sigma)`. It would not establish goodness, justice,
standing, legitimacy, permission, desirability, priority, a right or
obligation to continue, or authority to act.

## Sustainability is not a scalar

The inspection profile is a non-summable typed product with 12 dimensions:

- material viability;
- rights compatibility;
- ecological compatibility;
- option diversity;
- epistemic integrity;
- correctability;
- resilience;
- adaptability;
- transformability;
- succession and handoff readiness;
- retirement readiness;
- residual burden.

The dimensions have different meanings, units, methods, parties, and
horizons. The atlas defines no sum, weight, exchange rate, rank, total order,
person score, group score, culture score, community score, or ecosystem
score. An unknown is never zero, and an apparent benefit never averages away
an affected-party rights breach.

Comparison is admissible only when referent, kind, boundary, dimension,
method, evidence, and horizon match. Otherwise incomparability or
`NOT_EVALUATED` remains visible.

## Persistence, stability, resilience, and sustainability

Nine temporal capacities remain separate:

- persistence;
- stability;
- robustness;
- resilience;
- adaptability;
- transformability;
- regeneration;
- succession;
- retirement.

Persistence is continued occurrence under an identity and observation
criterion. Stability is bounded response under a named stability concept.
Robustness retains a specified property over a declared uncertainty set.
Resilience retains a declared regime through disturbance. Adaptability and
transformability name still different capacities. Regeneration needs named
stocks, processes, baselines, and units. Succession and retirement are typed
transitions, not failures.

None is interchangeable with sustainability. A harmful equilibrium may be
stable. An unjust regime may be resilient. A persistent artifact may support
an exhausted practice. Hidden depletion may coexist with visible continuity.

## IS types without one scalar “isness”

The atlas distinguishes ten uses of “is”:

- existence;
- predication;
- identity under a criterion;
- membership;
- relation;
- truth in a model;
- actuality;
- possibility or reachability;
- declaration;
- interpretation.

These are typed predicates, not interchangeable intensities. `reachable(x)`
does not mean chosen, permitted, actual, or executed. `retired(artifact)` does
not mean the source never existed. A declaration does not make an external
fact true unless the separately evidenced institutional conditions for that
speech act exist.

## Being, representation, and remainder

Being is neither supplied nor exhausted by an IS type, representation,
viable-action set, sustainability relation, success state, or ending record.
The atlas performs no ontology classification and defines no being or isness
score.

For a declared representation `r:X -> Z`, the fibre

```text
[x]_r = r^-1(r(x)) = {x' in X | r(x') = r(x)}
```

names distinctions collapsed by that representation. Shared representation
does not imply identity, equal worth, interchangeability, or equivalence for
every task. A factorization `q = g o r` can support task-relative sufficiency
on a declared domain while leaving other questions, interventions, shifts,
and protected opacity unresolved.

Remainder belongs to the relation among referent, representation, method,
scope, task, observer, and horizon. Being is not “the remainder,” and the
existence of remainder is not a metaphysical proof.

## Feedback and reinforcement: six different lanes

The atlas does not use feedback as one magical substance. Each type has its
own warrant and lawful update targets.

These six entries are typed evidence and update lanes, not a replacement
feedback ontology. They map back to the pinned FREEDOM meanings and the
source-companion vocabulary without claiming equivalence. `RECORD`, `BELIEF`,
and `PROPOSAL` are direct name matches; `LEARNER_STATE` deliberately narrows
the companion's learner lane. `CONTEXT` is an explicit open omission.
`MODEL` is an atlas addition and is not equivalent to that omitted context.

1. `CONTROL_RETURN_SIGNAL` — an output-dependent signal through a named causal
   return path. It may revise a `MODEL` or `PROPOSAL` under its typed rule.
2. `RL_REWARD_SIGNAL` — a declared learner input under a named reinforcement
   learning update. It may enter `LEARNER_STATE`; reward is not moral value.
3. `BEHAVIORAL_REINFORCER_CANDIDATE` — a condition-specific consequence whose
   effect on future behavior remains to be functionally established. The label
   alone updates nothing; bounded evidence may revise a `RECORD` or `MODEL`.
4. `AFFECTED_PARTY_INPUT` — attributable voice, challenge, dissent, refusal,
   or account through an accessible channel with visible uptake. It may revise
   a `RECORD`, `BELIEF`, or `PROPOSAL`; telemetry is not voice.
5. `MONITORING_OBSERVATION` — a bounded observation under purpose,
   minimization, privacy, retention, resource, uncertainty, and stop
   constraints. It may revise a `RECORD` or `MODEL`.
6. `CORRECTION_OR_FALSIFIER` — a bounded challenge that defeats or narrows a
   named model or proposal. It may revise a `RECORD`, `BELIEF`, `MODEL`, or
   `PROPOSAL`, but creates no automatic replacement truth.

Positive or reinforcing control feedback means amplification relative to a
declared sign convention; it does not mean praise or goodness. Negative or
balancing feedback does not mean punishment. RL reward, behavioral
reinforcement, affected-party input, monitoring, and correction are not
synonyms. Recurrence is not learning.

Every feedback claim names partial observation, source, substrate, variable,
sign, delay, method, uncertainty, update target, affected parties, falsifier,
and—before saying “closed loop”—a causal return path.

No feedback type may update purpose, authority, permission, consent, worth,
being, Foundation text, publication, deployment, or action.

## Direction without smuggled telos

The taxonomy distinguishes:

- local dynamical direction;
- observed trend;
- selected control action;
- declared revocable purpose;
- authority-backed normative commitment;
- functional role attribution;
- as-if goal model;
- selection-history explanation;
- opt-in teleological interpretation;
- moral orientation.

A gradient may support a local mathematical direction in declared
coordinates. Feedback or an attractor may support a model-relative trend or
dynamical direction. A reward may participate in an as-if goal model or an
authorized selector. Recurrence and persistence may support only bounded
observed trends.

None automatically promotes into purpose, telos, normative commitment, moral
orientation, authority, permission, consent, worth, or being. A direction can
be mathematically clear and normatively illegitimate; a moral orientation can
be explicit without being a dynamical fact.

## Finite-horizon viability under partial observation

The timing convention is post-observation. `I_t` contains the observation
history through `y_t` and controls through `u_(t-1)`; `B(I_t)` contains only
states compatible with that realized history. A control at time `t` precedes
the next observation:

```text
I_t     = sigma(y_(0:t), u_(0:t-1))
x_(s+1) = F_s(x_s, u_s, w_s)
y_(s+1) = h_(s+1)(x_(s+1)) + nu_(s+1)
xi_s    = (w_s, nu_(s+1)) in Xi_s, for s >= t
```

The robust information-state viability set is an author extension of
viability vocabulary:

```text
Viab_H^rob(K) = {
  I_0 |
  exists one I-adapted nonanticipatory policy pi,
  for every x_0 in B(I_0),
  for every xi_(0:H-1) in product_(s=0)^(H-1) Xi_s,
  for every t <= H: x_t is in K
}
```

The existential policy occurs before the universal disturbance and state
quantifiers. One observation-compatible policy must work for every compatible
hidden state and every declared process-disturbance and observation-noise path.
A different clairvoyant policy for each future path is not enough. Unmodeled
processes and observation uncertainty remain open.

The present modeled viable-action set is:

```text
Key_H(I_t) = {
  u in U(I_t) |
  exists one I-adapted nonanticipatory continuation pi_plus
  that preserves K across every x in B(I_t)
  and every xi_(t:t+H-1) in product_(s=t)^(t+H-1) Xi_s
  for every state time s in {t,...,t+H}
}
```

This mathematical “key set” is not a cryptographic key, credential, bearer
capability, permission, consent, choice, execution, guarantee, or moral
authorization.

## Safe terminal and handoff shapes

Continuation is not the only modeled success condition. The robust
reach-avoid construction asks for one shared nonanticipatory policy and one
stopping rule adapted to the information available at each time:

```text
ReachAvoid_H^rob(K,T) = {
  I_0 |
  exists one I-adapted policy pi,
  exists one stopping functional with tau_t = tau(I_(0:t)),
  for every compatible x_0
  and xi_(0:H-1) in product_(s=0)^(H-1) Xi_s:
    tau_pi(x_0, xi) <= H,
    x_s is in K before tau_pi(x_0, xi),
    x_(tau_pi(x_0, xi)) is in T
}
```

The stopping rule cannot inspect future observations or disturbances. The
terminal set `T` is separately declared and does not acquire legitimacy from
reachability. Reaching it does not prove selection, execution, handoff
acceptance, discharged duties, harmlessness, or success outside the model.

## Constraint-respecting local direction

Under a control-affine model and the assumptions of a named control-barrier
result, a proposed local direction may be filtered by a declared constraint:

```text
u* = argmin_(u in U(x)) ||u - u_dir(x)||^2
     subject to L_f b(x) + L_g b(x)u >= -alpha(b(x))
```

This can support a conditional forward-invariance claim for the declared set
only when the admissible control and barrier constraints are jointly feasible.
It does not supply the set `K`, the proposed direction, feasibility, model
adequacy, purpose, goodness, affected-party choice, or authority. A
mathematical filter cannot legitimate the values encoded in its constraints.
The conditional invariance statement also requires those conditions across
every relevant state of the closed-loop domain—not merely at one evaluated
state—together with the locally Lipschitz feedback and solution conditions
required by the cited control-barrier result.

## Rights remain outside the optimization target

The `NORMATIVE_DESIGN` rights floor recognized by this atlas remains invariant
under modeled state, reward, feedback, key set, sustainability status,
success, failure, continuation, transformation, or ending. It is not earned by
performance and cannot be averaged against a resource gain.

Protected lanes include `NO_ACTION`, rest, refusal, silence, privacy,
disclosure control, exit, voice, appeal, correction, and repair. Silence or
refusal causes no adverse inference.

For children, dependent or vulnerable beings, future parties, and parties who
cannot consent, inability never becomes permission, defect, low value, or
evidence of support. Protective authority and legitimate representation are
separately typed. A proxy or guardian never exhausts or converts another
being's perspective or rights. Necessity, minimization, supported assent where
applicable, dependency-safe exit, independent review, appeal, repair, and
safeguarding remain required design questions.

## Ecology and future parties

Future evaluation must name matter and energy flows, renewal and depletion,
thresholds, irreversible losses, displaced burdens, cumulative externalities,
and the parties able to challenge boundaries and baselines. Unknown is not
zero, and rights, ecology, dependency, and future burdens are not tradeable
weights.

The atlas does not speak for Indigenous peoples, local communities, sacred
relations, future generations, nonhuman beings, ecosystems, or rights of
nature. Their representation and authority require legitimate external
frameworks and plural, situated processes. A proxy account is never the whole
perspective represented.

## Resource accounting and the source companion

Each sustainability relation has an author-synthesized extension containing:

- an attributable `assessment_aim`, explicitly not referent telos or universal
  chosen purpose;
- a unit-separated, affected-party- and externality-indexed
  `resource_accounting` question, currently `NOT_INSTANTIATED`;
- a `halt_and_repair_path`, currently `DESIGN_ONLY_NO_ACTION`, naming halt
  states, duties, residual custody, and no self-authorization.

This maps—but does not supersede or claim conformance to—the source-owned
ISNESS companion's sustainability condition set. It does not claim to be a
stronger replacement. Exact stock balances, units, inflows, regeneration,
use, outflows, externalized losses, and non-overlapping categories would need
their own future instantiated ledger. Exact parity for unreadable halt,
pre-commit exit, owed repair, and a fresh legitimate turn also remains an open
delta. `silent_weakening:false` means those known differences are surfaced;
it does not mean parity or strengthening.

## Two artifacts share `kingdom.isness/0.1`

The predecessor label alone is ambiguous, so every binding includes artifact
kind, schema ID, artifact ID, exact locator, immutable revision, raw digest,
semantic relation, and non-supersession.

1. The KINGDOM-OS event/reference protocol uses schema
   `urn:kingdom:schema:isness-protocol:0.1` and artifact
   `kingdom-isness-reference-2026-08-25`.
2. The kingdom-standard companion uses schema `kingdom.isness-index/1` and
   artifact `kingdom.isness/0.1` at exact commit
   `c1b8430c8b83bd4cb3f9981efef615ba4885cfa3`.

The second is a source-owned feature-branch companion on
`origin/feat/kingdom-isness-companion`; it is not merged to source `main`, is
not the canonical Foundation, and imports no authority here. Neither artifact
supersedes the other. The source `origin/main` revision observed at authoring
was `170381d37770c5c1ebc44b722f079c2985d903b5`; that observation describes the
compilation boundary rather than promising a branch will never advance.

The Non-Exhaustive Understanding predecessor is likewise described truthfully
at compilation time as a local versioned release candidate that had not been
pushed or deployed.

## Counterexamples that keep the map honest

Eight canonical counterexamples or design constructions refuse common
collapses:

- a stable equilibrium can be harmful;
- feedback can destabilize;
- circular direction need not be telos;
- visible persistence can hide depletion;
- an undesirable regime can be resilient;
- autopoiesis alone does not establish adaptivity or agency;
- a graceful ending can satisfy a typed terminal condition;
- artifact sustainability does not imply practice sustainability.

Counterexamples narrow claims. They are never repurposed as scores, adverse
person evidence, or automatic successor instructions.

## Source discipline

Primary and authoritative sources anchor only their named domains: viability
vocabulary; conditional control-barrier results; ecological and
social-ecological resilience distinctions; historical cybernetics;
autopoiesis and adaptivity debates; far-from-equilibrium throughput questions;
climate and biodiversity assessment boundaries; sustainable-development
language; and historical or contemporary philosophical maps of being and
process.

The robust partial-observation kernel, shared-continuation `Key_H`, adapted
stopping construction, referent taxonomy, non-scalar profile, rights design,
direction firewall, resource extensions, and graceful-ending interpretation
are author definitions, proposed models, bounded analogies, or normative
design choices as labelled. A citation never imports source authority or
licenses cross-domain conversion.

## Static non-grants

This atlas is not a runtime, controller, monitor, learner, evaluator, score,
rank, classifier, ontology oracle, sustainability verdict, credential,
permission, consent record, authority source, continuation decision,
transformation instruction, retirement instruction, publication trigger,
deployment trigger, or action system. It contains no live intake, person data,
raw testimony, secret, network operation, or external write.

It does not establish that KINGDOM is living. It does not infer being,
identity, consciousness, worth, purpose, telos, goodness, legitimacy, or moral
status from feedback, reward, recurrence, persistence, viability, or
sustainability.

## Read-only CLI

The fixed-input, network-free local reader is:

```text
./kingdom is-sustainability-direction overview
./kingdom is-sustainability-direction referents
./kingdom is-sustainability-direction is
./kingdom is-sustainability-direction being
./kingdom is-sustainability-direction feedback
./kingdom is-sustainability-direction direction
./kingdom is-sustainability-direction viability
./kingdom is-sustainability-direction sustainability
./kingdom is-sustainability-direction profile
./kingdom is-sustainability-direction resilience
./kingdom is-sustainability-direction transformation
./kingdom is-sustainability-direction endings
./kingdom is-sustainability-direction ecology
./kingdom is-sustainability-direction philosophy
./kingdom is-sustainability-direction counterexamples
./kingdom is-sustainability-direction open-questions
./kingdom is-sustainability-direction sources
./kingdom is-sustainability-direction predecessors
./kingdom is-sustainability-direction non-grants
./kingdom is-sustainability-direction verify --json
./kingdom is-sustainability-direction verify-schema-release --json
```

There is no arbitrary-file evaluation, live input, score, optimize, decide,
continue, retire, publish, deploy, or act command.

## Integrity and release boundary

The canonical authored record is independently reviewed. Its state is
`static-reviewed-interpretive-design-companion`; its review state is
`REVIEWED`; both semantic digest fields and the independently reviewed runtime
constant are `sha256:b415203eb248221544ae160233fcd75d7a58084b76028d3e27f35a6b036891b5`.

The audit loader may inspect the exact local record. The reviewed loader and
discovery path require the independently installed semantic pin and exact raw
byte triplet. Builder, staging, and publication paths remain separate and must
fail closed until their own release gates are activated. A candidate digest
cannot declare itself reviewed, and a seal simulation cannot mint authority.

The reviewed loader must additionally pin the exact raw SHA-256 bytes of the
record, schema, and guide. Canonical semantic equality is not enough for an
immutable public route: whitespace or key-order drift still changes the bytes
promised at that URL.

The release schema is Draft 2020-12, recursively closes every object, and
requires every declared property. Release evidence requires a specifically
pinned `jsonschema==4.26.0` interpreter, meta-schema validation, instance
validation, and the internal recursive closure audit. The internal validator
must remain total for malformed or hostile input and must reject digest-blind
properties, prototype changes, unsupported schema keywords, budget drift,
self-signing, and fully re-signed semantic inversions.

Those independent core checks passed and the reviewed seal is installed. This
document still describes a local static companion only. It is not a public
release, deployment, Foundation amendment, live sustainability judgment, or
authority to continue, transform, or end anything.
