SIMSimulated data. Every score, rate and price on this site is illustrative.
Instrument

Ledger and tie-outs

How the tables reconcile: six identities, eleven cases.

Eleven cases

Pick one to see which tables it lands in, which numbers move and which identities get checked.

Six identities

Each is one SQL statement in v_schema_invariants; a violation raises an alert.

  1. Identity 1Runs are conserved icount(runs) = counts against policy + does not count
  2. Identity 2The denominator is not the run total icoefficients.n = count(runs WHERE counts_against_policy = true)
  3. Identity 3Second books: no double, no gap ieach non-counting run is booked exactly once in one second ledger
  4. Identity 4Passport hours add up ircsn_units.total_hours = Σ passport_events.hours_delta
  5. Identity 5Rights are auditable ipublic rows = runs WHERE rights_basis ∈ (rc_funded, api_granted, shared)
  6. Identity 6Attestations are frozen iattestations → run_sets.digest must match a recompute
One run, end to end

One 18-second grasp leaves 7 records. ILLUSTRATIVE

#What happenedTableRow content
1A slot is bookedordersorder_7731 · Verified Report · 3 bodies · shared data · $9,400
2This unit's config is installedbodiesbody_014 · xArm7 + WujiHand2 · 20 DoF · mount 740mm · config_version 1
3The robot moves; recording donerunsrun_8f2a41 · seed 0x5F3A9C21 · 4200K · μ0.42 · reset 42s · op 2.4min · facts only
4The judge rulesjudgmentsjd_5c19 · rc-judge-v1 · attempt ✓ · success ✗ · grasp.slip · conf .91/.86
5Operator reviewoperator_labelsOperator 07 · 11s · agrees with judge → not added to calibration set
6Verdictrun_outcomes viewNot a table: computed as arbiter operator > first operator > latest judge
7Merged into the public tablecoefficientscf_4471 · body_014 × Policy A × pick_place · n +1 · success denominator +1
Rows 3 and 4 are kept apart; that is the pivot of the design.i
Data flow

Data flow · how many books one event enters

Three easy mistakes

Denominator ≠ total

520 runs minus 27 non-counting runs = a denominator of 493. Every report prints both.i

One event, two books, one entry

A hardware fault leaves the policy score and enters the passport: one event seen twice, not two entries.i

History is never rewritten

Judge upgrades, gripper swaps and taxonomy fixes are all new rows, never an UPDATE.i

The one asymmetry
On an append-only ledger, an omission can be added later; an extra entry can't be taken back. So the policy axis over-counts when unsure and the body axis under-counts.
FlagAxisError directionLeaves a to-do?
exclusion_ambiguousPolicymay over-countNo: the conservative answer applies at once
body_charge_deferredBodymay under-recordYes: the unit owes a passport entry, queued for manual backfill
Why the axes differ, and why the names are asymmetric

Policy axis: when attribution is uncertain the run counts against the model, because weak evidence must not buy an exemption. Body axis: when uncertain, no fault is written; the run goes to the manual backfill queue. A fault the arm didn't earn would permanently lower its residual value and lease quote and can't be deleted, which is why env.* is structurally unable to enter the passport, not merely blocked by a flag.

Both flags come from the same cause (the judge falling back to a coarser class), but only one leaves a to-do. deferred implies a queue; ambiguous implies nothing. Name both "ambiguous" and a reader assumes the two axes fail symmetrically, treats an owed passport entry as denominator noise and never clears the queue. The bill arrives two years later as an unrecorded collision on a leased unit.