Ledger and tie-outs
How the tables reconcile: six identities, eleven cases.
Eleven cases
Pick one to see which tables it lands in, which numbers move and which identities get checked.
Six identities
Each is one SQL statement in v_schema_invariants; a violation raises an alert.
- Identity 1Runs are conserved i
count(runs) = counts against policy + does not count - Identity 2The denominator is not the run total i
coefficients.n = count(runs WHERE counts_against_policy = true) - Identity 3Second books: no double, no gap i
each non-counting run is booked exactly once in one second ledger - Identity 4Passport hours add up i
rcsn_units.total_hours = Σ passport_events.hours_delta - Identity 5Rights are auditable i
public rows = runs WHERE rights_basis ∈ (rc_funded, api_granted, shared) - Identity 6Attestations are frozen i
attestations → run_sets.digest must match a recompute
One run, end to end
One 18-second grasp leaves 7 records. ILLUSTRATIVE
| # | What happened | Table | Row content |
|---|---|---|---|
| 1 | A slot is booked | orders | order_7731 · Verified Report · 3 bodies · shared data · $9,400 |
| 2 | This unit's config is installed | bodies | body_014 · xArm7 + WujiHand2 · 20 DoF · mount 740mm · config_version 1 |
| 3 | The robot moves; recording done | runs | run_8f2a41 · seed 0x5F3A9C21 · 4200K · μ0.42 · reset 42s · op 2.4min · facts only |
| 4 | The judge rules | judgments | jd_5c19 · rc-judge-v1 · attempt ✓ · success ✗ · grasp.slip · conf .91/.86 |
| 5 | Operator review | operator_labels | Operator 07 · 11s · agrees with judge → not added to calibration set |
| 6 | Verdict | run_outcomes view | Not a table: computed as arbiter operator > first operator > latest judge |
| 7 | Merged into the public table | coefficients | cf_4471 · body_014 × Policy A × pick_place · n +1 · success denominator +1 |
Data flow
Data flow · how many books one event enters
Three easy mistakes
Denominator ≠ total
520 runs minus 27 non-counting runs = a denominator of 493. Every report prints both.i
One event, two books, one entry
A hardware fault leaves the policy score and enters the passport: one event seen twice, not two entries.i
History is never rewritten
Judge upgrades, gripper swaps and taxonomy fixes are all new rows, never an UPDATE.i
The one asymmetry
| Flag | Axis | Error direction | Leaves a to-do? |
|---|---|---|---|
exclusion_ambiguous | Policy | may over-count | No: the conservative answer applies at once |
body_charge_deferred | Body | may under-record | Yes: the unit owes a passport entry, queued for manual backfill |
Why the axes differ, and why the names are asymmetric
Policy axis: when attribution is uncertain the run counts against the model, because weak evidence must not buy an exemption. Body axis: when uncertain, no fault is written; the run goes to the manual backfill queue. A fault the arm didn't earn would permanently lower its residual value and lease quote and can't be deleted, which is why env.* is structurally unable to enter the passport, not merely blocked by a flag.
Both flags come from the same cause (the judge falling back to a coarser class), but only one leaves a to-do. deferred implies a queue; ambiguous implies nothing. Name both "ambiguous" and a reader assumes the two axes fail symmetrically, treats an owed passport entry as denominator noise and never clears the queue. The bill arrives two years later as an unrecorded collision on a leased unit.