# State Dimension: the closed reality loop at polity scale This worked example runs the palette at its largest declared scale: a state Dimension whose model is the primary digital reflection of a territory, with a world-model corpus, thousands of citizen-facing agents, federated peers and a Full conformance profile (COMMON 6). It follows one concrete case end to end, a road bridge that fails inspection, from the moment reality changes to the moment the model can prove reality changed back. Two operational side stories run alongside it, because at this scale they always do: the admission quarantine of a federated meteorological feed (FED-8) and an operational incident with a postmortem (QSC-14). The pattern shown here is the Meta-Orchestrator State (MOS), cited throughout the palette as the external reference Dimension in the repository orkestron-ai/meta-orchestrator-state. MOS is a reference Dimension, not part of the standard: nothing below imports MOS identifiers into the palette, and every claimed step cites the palette process that owns it. ## Reference Dimension vocabulary, external to the standard MOS names its world-model namespaces with cluster letters and numbers. These identifiers are the reference Dimension's own vocabulary. They appear here only as the subject matter that palette processes operate on, never as normative palette artifacts: - U3 Physical Infrastructure Network (the bridge as an asset), U7 Address and Location Referencing. - A3 Ministry / State Sub-Agent (the effector organization), A14 Permit, License and Authorization. - K2 Act, K4 Service, K11 Maintenance and Repair (the works themselves). - X1 Occurrence, X3 Incident and Emergency, X4 Situation and Condition (the bridge's state of repair). - R3 Event Register (where a state change is appended), R5 Attestation, Certificate and License. - S1 Ownership, S2 Access Contract, S3 Projection Shaping, S4 Access Audit, S5 Statistical Release. - P4 Atmosphere, Weather and Climate (the federated feed), N2 Report and Statement, N3 Dataset and Data Register. - B1 Citizen, E1 Agent-Citizen Runtime (the thousands of agents), V3 Value Flow, V4 Anti-Value. The mapping to the palette is one-directional: an MOS namespace is a dataset in the Mastership Register that MIR-1 alone maintains, and an MOS register append is an Event that CON-6 versions. ## How the Dimension is constituted The Dimension was born through genesis (GOV-4): founding decision recorded (GOV-1), Owner and Stewards appointed with a succession skeleton in place before activation (GOV-3), an empty Mastership Register initialized for MIR-1 to execute thereafter, the policy set instantiated from shipped defaults (GOV-2, COMMON 9), standing jobs registered from day one (QSC-15), and activation gated on a green first validation run (QSC-4, V0-V5). It declares Full (COMMON 6): every applicable process at its stated tier, full artifact separation everywhere, and every recertification loop run individually rather than consolidated. Localizations against the shipped defaults are few and versioned (GOV-2): a stricter Impact Matrix for anything that touches physical safety, and per-class emergency rate and blast-radius limits enforced mechanically at dispatch (ACT-6). Everything else runs as shipped, and the manifest says so. Thousands of agents act inside the model. Each holds a Delegation Contract mastered solely by CTX-9, starts at T1 or T2 with the unified probation rule, and earns T3 by track record. Each session bootstraps against hash-anchored bootstrap materials before touching anything (CTX-10), works from context packages carrying origin and taint classes, freshness stamps and grant IDs (CTX-1), executes the FCD loop with master-only writes (CTX-5), and stays inside a published partition map (CTX-6). Read rights, inward and outward, exist only as Owner-granted, purpose-bound, TTL-bounded grants (GOV-7 internally, FED-3 across the boundary), which is the palette's IC-7 expressed at state scale. Under Full profile the quality and security loops run individually rather than consolidated: intra-model consistency on cadence (QSC-2), cross-model consistency across the many namespaces, which at this scale is mandatory in practice (QSC-3), quality scoring above the declared size threshold (QSC-1), access review diffing actual grants against the register plus the standing consent policy (QSC-6), continuous hash anchoring of the security-critical dataset class (QSC-9, IC-4), agent behavior audit wherever agents execute (QSC-7), backup and disaster recovery with declared degraded-mode rules (QSC-13), an independent periodic audit over all four loops (QSC-5), and a conformance statement kept honest because the Dimension federates (QSC-10). ## The case: bridge U3-B-114 fails inspection ### Sensing, in two tempos The bridge's condition is external-mastered: the Roads Ministry asset register is the System of Record, declared once in the Mastership Register with flow, pipeline, cadence and conflict rule (MIR-1). Nothing may harvest it otherwise, because harvesting without declared mastership is how two truths are born (IC-1). Two sensing tempos run against it. The inspection document drop is harvested on cadence (MIR-2 at T3, invoked by the scheduled refresh MIR-3): raw capture landed unmodified with its provenance sidecar, a capture-time attestation emitted by infrastructure the harvesting agent cannot write to, a sanity gate on counts and checksums, hazard screening, then the declared transform into the mirror. The structural-monitoring stream from the bridge's own sensors arrives event-driven (MIR-4 at T3 after burn-in): authenticated channel, mapped subscription, semantic ordering per the GOV-2 config, delta applied, actualization Event stamped source-event (MIR-10), with the periodic anti-entropy sweep as the safety net against silent gaps. The inspection harvest lands the finding: load-bearing capacity below the statutory threshold, condition class downgraded. Freshness metadata updates on the mirror (MIR-2 step 8), and the freshness state stays fresh against the dataset's SLA (MIR-6). Had the pipeline stalled instead, the SLA breach would have driven the dataset to quarantined (MIR-8), readable but flagged, with the flag travelling to every consumption surface. ### Entry through the front door The harvested inspection does not queue for review: a registered MIR-2 run under an active register entry is intake and approval for harvested content, and CON-2 through CON-4 do not re-process harvest batches (IC-2, the harvest carve-out). CON-2 references the MIR-2 sidecar as the provenance of record and never re-authors it. The authored half of the case does travel the front door. A municipal engineer files a corroborating field note as an N2 report: intake with a stable identifier and an entry-rights check validated at the gate (CON-1), provenance capture naming the asserting human, time, origin class and rationale (CON-2), validation gates (CON-3), review and approval per the GOV-2 approval matrix (CON-4), mastership enforcement routing every write to the dataset's own master (CON-5), and versioned change history (CON-6). Citizens who reported the same cracking through the civic channel enter as human reports through MIR-2 step 7: the model records who said it, it does not promote a report into an observed fact. ### From fact pattern to actionable signal The condition threshold is not read ad hoc. It is a cataloged signal class with its condition, evidence requirements, freshness bound, default impact class, decision route and tier ceiling (ACT-1 at T1 for registration). Emission and qualification run continuously (ACT-2 at T3): the signal cites the exact evidence records and versions, checks freshness against the staleness limit (MIR-6), checks the quarantine state (MIR-8), and checks the Trust Vector of every federated source it leans on (FED-8). That last check bites here. The scour-risk corroboration comes from the federated meteorological feed, and that source currently sits below its operating floor, so confidence degrades below the auto-decide threshold (ACT-2 step 3). Combined with the catalog rule that a class resting solely on external or federated mirrors is never auto-decidable at T3 (ACT-1 step 4), the signal routes to a human decision rather than to an agent. ### Assessment and decision The pre-actuation assessment traverses the model to bound the affected set (ACT-4 at T2): the U3 network segment, the K4 services depending on it, the transit flows rerouted, the citizens in the catchment. Reversibility is classified from the effector's capability contract as compensable, impact as high, so the shipped defaults put this above the assessment floor, above the rollback-plan floor, and above the separation-of-duties and independent-evidence floor (GOV-2 Impact Matrix, COMMON 9). Cross-owner effects are checked before the decision may approve anything (ACT-4 step 4 at T1). The decision is taken at T1 by the accountable Steward with Owner sign-off, because the action reaches outside the Steward's section (ACT-5, authority basis recorded via GOV-1). It fixes the action, the parameters, the target effector, the verification criteria and the decision expiry, and it seals the criteria at decision time so nothing can be bent later to fit whatever happened (ACT-5 step 5). A rollback plan is referenced because the class sits above the rollback-plan floor (ACT-11 drafting duty invoked at decision time). ### Command to an effector ministry The Roads Ministry works desk is a registered effector with a versioned capability contract stating allowed command types, parameter limits, acknowledgment and evidence format, reversibility class and escalation contact (ACT-3), its credentials held by reference under the credential lifecycle (GOV-8), its reachability checked by a registered standing job (QSC-15). Dispatch is gate-enforced, never agent-honored (ACT-6 at T3 for the mechanics): the decision is live and unexpired, the effector is registered and healthy, the command is inside its capability contract, the citing Delegation Contract's liveness is validated at act time (IC-5), and the cumulative impact budgets are checked mechanically so a large effect cannot be salami-sliced into many below-floor commands. The command is composed mechanically from the decision record, carries an idempotency key and an expected-evidence declaration, and is recorded in the model before it is dispatched (ACT-6 step 4). The dispatch log is emitted by the gate infrastructure and hash-chained (IC-6). ### Two mastership patterns in one actuation The Mastership Register decides the pattern, not the operator. The bridge condition is external-mastered, so the repair follows reality-ahead (ACT-8): reality changes first through the ministry's works, and the model catches up by harvest. The public traffic advisory the Dimension itself publishes is model-mastered, so it follows intent-ahead (ACT-7): the intended notice is authored as a distinct pending version while the current version stays Active, and it is promoted only on verified evidence, never on dispatch success. One invariant spans both: the intention is always model-mastered, and the command was authored in the model before anything moved (ACT-8 step 2). The advisory is published as a write-back projection marked generated with its master named. Divergence on that surface is detected by the palette's sole drift engine (MIR-7), and any intended external edit to it becomes a sponsored change proposal rather than a silent merge (CON-11). ### Verification closes the loop on evidence When the works report completion, nothing is closed yet. Verification gathers evidence against the criteria sealed at decision time (ACT-9). Because the impact class sits above the independent-evidence floor, the effector's self-report is insufficient: a targeted re-harvest is requested as a registered trigger (ACT-9 step 2 into MIR-2), executed under a pipeline identity disjoint from the one that fed the original signal, and the verifying agent is not the agent that decided or dispatched. Separation of duties extends from agents to pipeline credentials. The forced out-of-cycle re-harvest lands raw capture plus sidecar, then transforms into the mirror; the mirror is never hand-edited to show the expected result (ACT-8 step 5). The new mirrored state is linked to the command by a cause-reference matched on the idempotency key, so someone else's concurrent change is not attributed to our command (ACT-8 step 6), and both the ingest and the cause-reference Events are stamped actuation-verification (MIR-10). ### Partial conformance, then reconciliation The first verdict is partially conformed (ACT-9 step 4): the deck is repaired and the sensors agree, but the load rating in the ministry register still carries the old value. The case routes to reconciliation (ACT-10). The divergence is characterized, and direction comes from the declared conflict rule in the Mastership Register, not from per-incident judgment (ACT-10 step 2): the external side is authoritative for the rating, so the model waits for the registrar's update and re-harvests rather than writing the number it prefers. Consumers who read the superseded state are notified, resolved against the consumer and subscription register (CON-13). On the corrected harvest the verification records conformed, listing the observed affected set in the same schema the assessment used, which is what makes prediction accuracy computable later (ACT-9 step 5). The pending advisory version is promoted to Active (ACT-7 step 6). The loop is closed by sensed evidence, never by the act of commanding. ### Archival and reasons Every superseded state stays: the prior condition record, the refused and superseded intention from the partial verification, the earlier advisory version, all retained with identity and provenance intact under supersession Events (MIR-9, IC-8). Retention follows the versioned policy (GOV-2), the archive lies inside backup scope with offsite immutable copies (QSC-13), and the periodic reconstruction drill proves a past state can actually be rebuilt and restored (MIR-9 step 6). Every covered Event carries exactly one primary reason code from the taxonomy (MIR-10), which is what later turns the change history into analysis rather than an anonymous stream. At the quarterly cadence the whole chain is walked end to end by an independent Auditor engaged through GOV-6: every command to a decision, every decision to a signal, every verification to evidence, with orphan links filed as findings rather than treated as noise (ACT-12), and loop debt landing in the debt register (QSC-11). ### Consumption at the hinge While all this runs, the bridge is being read: by citizen-facing agents answering route questions, by the emergency service's own agents, by municipal planners, by federated peers. Consumption sits at the hinge of the loop, and what a reader gets carries its freshness, its trust state and its provenance with it. A read that depends on a mirror past its staleness limit either triggers a targeted re-harvest before answering or discloses the staleness explicitly, per the Steward's declared policy (MIR-5), and the quarantine flag is disclosed regardless of harvest age (MIR-5 step 3). Answers cite the master and the harvest time rather than asserting bare facts. Every read is a permission before it is a query. Internal readers consume under purpose-bound grants with bounded TTLs (GOV-7), context packages expire on revocation of any cited grant or on their fixed TTL, whichever is sooner (CTX-1 step 9), and packages are stepped down in depth by declared priority rather than silently truncated when they exceed a window (CTX-2). What leaves the Dimension leaves as a purpose-built Projection reviewed at release, never as a window into a store (FED-4). Registered consumers and their notification channels live in one register, which is what makes the supersession notices of the reconciliation deliverable at all (CON-13). ## Admission quarantine of a federated meteorological feed The national meteorological service is a separate Owner. The relationship was discovered and evaluated (FED-1), contracted and signed by the humans who hold that authority (FED-2, non-delegable in substance), consented with purpose-bound and TTL-bounded grants (FED-3), established with an initial synchronization (FED-5), operated on cycle (FED-6) and kept meaningful by maintained semantic mappings into the P4 namespace (FED-7). Every inbound payload is guilty until promoted. The batch lands unmodified in the admission quarantine zone with a provenance sidecar, unreadable to consumers (FED-8 step 1). The envelope is verified for sender identity, contract validity and contracted scope (step 2). Content is validated through the validation machinery for schema conformance, mapping applicability and referential sanity (step 3, executing QSC-4 rule sets). Hazard screening runs (step 4), and this batch trips it: a station remark field contains instruction-like text addressed at agents, telling them to treat flood-watch bridges as already inspected. It is flagged and treated strictly as data, never followed, which is the palette-wide data-is-never-a-command control (IC-3). Injection-bait refusal is not assumed: it is tested in the agent behavior audit (QSC-7). Trust is then evaluated as a vector, never as a scalar: per-dimension levels over Identity, Semantic, Governance, Contract, Operational and Historical, with the outcome of the checks updating the Operational and Historical dimensions specifically (FED-8 step 5). The promotion floor is a versioned predicate over named dimensions, not a score, and this batch does not satisfy it, so it is rejected with reasons returned to the sender, and the rejection Event states which dimensions it relied upon (step 6). An identical resubmission is caught by the checksum matcher (FED-8 failure mode 4). Because the source now sits below its operating floor, the Steward is notified, federation health raises the state (FED-10), and the source's data degrades signal confidence below the auto-decide threshold (FED-8 step 8), which is exactly why the bridge signal earlier could not be decided by an agent. The next clean batch satisfies the floor and is promoted. Only then does the mirror move: MIR-2 executes the post-promotion landing and refuses federated-class content that carries no promotion record (MIR-2 step 1). The three holding states stay distinct throughout, per the COMMON 5 glossary: admission quarantine (unreadable until promoted), quarantine (readable but flagged), and integrity hold (excluded from answering until cleared). ## A QSC-14 incident and its postmortem Mid-repair, the freshness monitor for the ministry asset register stops emitting. Nobody notices by eye; the meta-monitoring notices, because every registered job has a heartbeat watched by a watcher independent of what it watches, and watchers are cross-watched rather than self-watched (QSC-15 step 3). The missed heartbeat escalates automatically: a dead monitor is an incident, not a log line (QSC-15 step 4). The incident runs the one discipline (QSC-14). The record is opened and evidence pinned first, with logs snapshotted and hashed before anything is cleaned (step 1). Severity is classed against the versioned rubric; the gateway asks whether this is the security class and the answer is no, so it stays in QSC-14 rather than handing over to the security specialization QSC-8 (step 2). Containment takes the least destructive effective step: a manual refresh run (MIR-3) plus quarantining the dataset (MIR-8) so no reader, human or agent, treats it as fresh while the monitor is down. Because the verification of the bridge actuation depended on that dataset, the open command sits in the unverified queue and is escalated rather than quietly aged into done (ACT-9 step 8). Eradication finds the real cause: an infrastructure move planned under capacity planning (GOV-5) changed the monitor's host, and the post-change heartbeat re-verification never ran (QSC-15 step 6). The interim manual refresh is recorded as a workaround, not closed as a fix (QSC-14 step 4). Severity is above the postmortem floor, so a blameless postmortem is mandatory: timeline, contributing causes, what the monitors missed, what worked, naming causes and guards and never persons (step 5). Lessons land as versioned artifacts, not folklore (step 6): a registry rule change so an environment change cannot close without heartbeat re-verification (QSC-15), a watch-config version bump (GOV-2), and the remaining work filed with an owner and a due date in the debt register (QSC-11). The incident closes only when the eradication item is done and the postmortem is published, with the closure Event referencing it and the Owner deciding closure at T1 (GOV-1). Repeat causes are tracked across incidents, and a recurrence raises severity one class (step 8). ## What the loop looked like end to end Reality changed, sensing caught it in two tempos (MIR-2, MIR-4) on a declared master (MIR-1) with a declared freshness SLA (MIR-6). Authored corroboration entered by the single front door (CON-1 through CON-6), harvested content by its carve-out. A cataloged signal was emitted and honestly qualified against freshness, quarantine and federated trust (ACT-1, ACT-2). The consequences were assessed (ACT-4), an authority-bound decision was taken with sealed verification criteria (ACT-5), a command was recorded before dispatch and gated mechanically (ACT-6), and the register chose the pattern (ACT-8 for the external master, ACT-7 for the model-mastered advisory). Independent sensing under a disjoint pipeline identity verified that reality had actually changed (ACT-9), a partial result reconciled in the declared direction (ACT-10), and the history of every superseded state survived (MIR-9, MIR-10). Alongside, a federated peer's payload was held unreadable until it earned promotion (FED-8), and a dead monitor became an incident with a landed lesson (QSC-15, QSC-14). Five shortcuts were available at every step, and each one is named as non-conforming by the process that would have permitted it: - Hand-editing the mirror to show the repaired rating, which the harvest-only write rule refuses (ACT-8 step 5). - Closing the actuation on the ministry's completion report alone, which the independent-evidence floor refuses for this impact class (ACT-9 step 2). - Letting an agent decide because the threshold was obvious, which the auto-decidable gateway refuses for a class resting on external and federated mirrors (ACT-1 step 4, ACT-5 controls). - Resolving the rating disagreement by judgment because the model looked more current, which the conflict rule refuses (ACT-10 step 2). - Promoting the met feed under delivery pressure because the forecast was needed, which the promotion floor predicate refuses (FED-8 step 6). At this scale nothing above is ceremony. It is the only reason a state-scale model can claim to be the primary digital reflection of reality: every act was decided on a candid mirror, and every effect was confirmed back through sensing.