Bitspark constellation

CONCEPT

adstrate

The integration / realization runtime over the substrate (ADR 0029) — the layer that *does* what the record only *describes* (resolve → judge → enforce → mediate), realized by kosmos as a custodial fluency lens that holds clients' keys and runs the proof/signing machinery so clients hold nothing. It is not a tier of off-record referents: the surfaces a runtime brokers — content, state, flow, i.e. what the immutable-small-fact substrate cannot *be* (bulk, mutable, moving) — are realized by generic providers / connected services that register as downstream, none named by the model (corpus is the worked content provider; state/flow are unbuilt candidates). Providers are ordinary untrusted occupants; their bindings stay re-checkable under an identity discipline (e.g. content-addressing). The layer "adstrate" value (ADR 0018, re-pointed by 0029) marks the runtime; the Greek/Latin naming line is under review (kosmos is Greek yet is the adstrate, ADR 0029 §8). Access and storage are space-governed (ADR 0021/0022): the payload is stored within and owned by its space — keyed on (space, identity), reached only through its space-scoped binding fact and resolved by projection, never a bare-identity path. The bare identity (hash) names what the payload is; (space, identity) is the capability to reach it and the unit it is accounted to — every object is owned by exactly one space, so the space's read/write ACL is the content's ACL and quota/billing/lifecycle are per-space. This is what makes adstrate content delegable, federable, and billable like everything else. Writes go through the same fact interface (ADR 0024): a write is two facts by two parties — the caller asserts the binding (content; provenance + authority, self-proved to the record), the occupant asserts custody (stored; only the holder can) — and the byte upload itself needs no separate authorization, since binding-existence is the authority proof and content-addressing the integrity proof, so occupants stay untrusted for writes too (and stored doubles as the served-by routing signal).

Across these systems

The Bitspark constellation — how the systems are built and relate.

GitHub