1. Free to Send, Costly to Answer
Picture a moderation queue absorbing a burst of complaints against one account overnight. Each is well-formed and cites a real category. An automated rule reacts to complaint density and throttles the account before a reviewer opens the first file. Sending the burst cost its sender close to nothing. Answering it consumes review capacity the receiving team must take from something else.
A reporting endpoint is a write channel into somebody else's standing, and the sender pays nothing to use it. Notices aimed at a thousand parties cost the same per unit as notices aimed at one, while imposing a thousand separate obligations on the far side, each unwound by a party who did nothing.
Autonomous software changed the scale. Filing rate was once bounded by a person at a form and is now bounded by a request loop, and an agent told to protect its principal's interests files at machine cadence because filing costs it nothing.
The remedies platforms reach for share one assumption: that controlling bad accusations means identifying which accusations are bad. That assumption is what makes the problem intractable: determining merit is the most expensive operation in the pipeline and precisely the one a flood exhausts.
2. Why Existing Approaches Stall
Per-account rate limits fail because the account is the unit being limited and accounts are cheap. A campaign splits across identities and the aggregate rate is unchanged, while a limit tight enough to stop it also stops the legitimate high-volume reporter the system needs.
Trusted-flagger and reputation programs move the question from how much to who. They typically need a central operator to confer status and a scoring function stable enough to be relied upon, therefore stable enough to be gamed. They also do not bind across systems: standing conferred by one operator means nothing at another's endpoint.
Penalties for bad-faith notices are the most principled approach and the least deployable. Applying one requires first ruling that the notice was meritless, and that ruling is the scarce resource. Statutory notice regimes, as publicly described, generally provide for liability where a notice is knowingly false; somebody still has to make that determination, at volume, against a possibly uncontactable party.
Bonds, deposits, and staked collateral price the assertion, which is the right instinct, but in a currency disconnected from the accuser's capacity to act. A well-capitalized flooder posts the bond and proceeds. Denominating assertion in money also makes the right to accuse purchasable by the parties the mechanism meant to restrain.
The gap that survives all of these is narrow: nothing charges the act of asserting against the asserting party's own capacity to act, in the same units, without first deciding whether the assertion was right.
3. What the Filed Chapter Discloses
Chapter 4 of the filed provisional discloses assertion-cost symmetry as the express mirror of Chapter 3's refusal metering. An agent that refuses an execution pays a metered cost for the refusal; an agent that asserts against a counterparty pays a metered cost for the assertion. Neither cost turns on adjudication of merit, and both draw on one quantity held by the party taking the action, which governs that agent as asserting party and as evaluated party alike.
The assertion-cost counter sits in the issuing semantic agent's memory field: an issuance accumulator, a per-recipient-class register recording whether each origin-equivalence class of receiving parties has already contributed an increment within the metering window, a budget floor field, and a decrement schedule from the signed policy object in force. On issuance the agent builds a conduct evaluation artifact from its append-only lineage field, computes the receiving party's origin-equivalence class, and consults the register: where that class already contributed, no increment applies; otherwise the accumulator increments and the authorization budget is decremented by the scheduled amount, in units identical to those gating dispatch of the agent's own actions. No exchange rate is applied between assertion-denominated and execution-denominated quantities, and no budget is denominated in channel access, rating weight, or staked value. The agent then advances its dynamic agent hash chain to a successor epoch and attests the accumulator state and epoch identifier inside the artifact.
Responsive to the budget satisfying the declared floor, the authorization gate is written to the withheld state for an enumerated set of action classes and the agent enters the non-executing cognitive mode for those classes, with an escalation record emitted to its principal. What is withheld is the faculty of executing, not the capacity to issue artifacts, though at or below the floor the agent attaches no attestation to what it issues.
Enforcement lands at the receiver, which verifies the attested state before admitting the artifact to its admission evaluator: the attested epoch identifier must be a valid successor of one previously recorded for that issuer in its counterparty identity record, and the attested accumulator state must not be less than a state previously attested. A failing artifact is appended to the lineage field and not admitted, producing no determination, moving no value of the scoped integrity vector, and incrementing no counter.
Three properties close the obvious routes around that check. Since an attestation binds one accumulator state to one successor epoch, artifacts issued in bulk on a common state carry a common epoch identifier, and a receiver already holding an artifact bearing it detects the repetition from its own record. Epochs carry an unpredictability contribution and a volatile salt rather than a clock reading, so the interval cannot be advanced by clock manipulation. An issuer that over-splits its classification of recipients to reduce its own increments is caught by the class-splitting divergence record.
Replenishment is narrow: the budget is restored only on receipt of an admissible artifact from an origin-equivalence class absent from the replenishment register, bounded by a declared authorization budget ceiling and by an amount strictly less than the per-increment decrement, so an agent cannot finance issuance volume by the receipts its own issuance provokes. All four determinations replenish identically; elapsed time and window expiry replenish nothing.
Chapter 10 sharpens the schedule. The decrement can be conditioned on the reason-type of the edge to the recipient, resolved by a severance-survival test as want-sustained, payment-sustained, obligation-sustained, or not-typeable, with the greatest amount specified for a not-typeable edge. It can also rise with the issuance accumulator within a window. And where a receiving agent's own record affirmatively contradicts the artifact and yields a rejected determination, the issuer applies a further decrement at a declared multiple, conditioned on contradiction rather than mere disagreement.
4. A Reporting Campaign Run Through the Meter
Run a mass-reporting campaign through this and the economics invert on one axis: breadth. A dragnet across a population is what exhausts a review queue, and it is what the schedule prices hardest.
Notice after notice against one party costs a single increment, the per-recipient-class register having already recorded that class as contributing within the window. Spread the same volume across distinct classes and every class costs an increment of its own. The specification illustrates the shape: with a decrement of one unit and a budget of forty units, an issuer addressing sixty parties in sixty classes exhausts its budget at the fortieth increment, and the remaining twenty issuances carry no valid attestation and are not admitted. Had those sixty parties resolved to three classes, the accumulator would have reached three.
The sender cannot escape by multiplying identities on its own side. Origin-equivalence collapses an accuser's minted identities into one class at the receiver, computed from the receiver's own lineage field, and the receipt-verification register caps the verification work a single issuing class can force within a window. Past that cap, further artifacts from the class are appended, left unverified and unadmitted, and produce nothing, adverse or otherwise. Where the reason-type refinement is in force, an edge that no severance-survival test can type carries the greatest decrement in the schedule, which is exactly the profile of a stranger dragnet.
Denominating the budget in execution units gives the price teeth. An agent that spends its budget on notices has less capacity for its own work, and at the floor its gate is written to the withheld state for the enumerated action classes while an escalation record reaches its principal. There is no separate currency to buy more assertion capacity with.
None of this requires anyone to decide whether a notice was true. The receiver performs a mechanical check against its own counterparty identity record, and a true notice and a false notice bear one and the same decrement. Merit re-enters only as contradiction. Where the accused party's own record affirmatively contradicts the allegation, the rejected determination returns and the issuer takes a further decrement at the declared multiple. At a rate or run length declared in policy, an issuer whose artifacts repeatedly draw rejected determinations is demoted by one persistence tier in the receiving party's own counterparty identity record, after which its assertions no longer count toward renewal of authorization quantities. Nothing blocks it and nothing silences it. What a demotion strips is the contribution its assertions used to make to those renewals.
The result is a reporting endpoint that limits itself: no trusted operator in the middle, no scoring registry to capture, no money in the loop. Metering and verification run between the two parties to the exchange, which the specification states is all the mechanism depends on.
5. Deployment Considerations
Both endpoints must be governed agents. Verification presupposes a receiver with a memory field, a counterparty identity record, and an admission evaluator; metering presupposes an issuer with an authorization budget and a signed policy object. The natural fit is machine-issued notice traffic. Consumer reporting maps only where the client submitting on the person's behalf is itself governed, an integration cost rather than a footnote.
Every threshold is declared, not derived. The decrement schedule, floor, ceiling, window length in successor epochs, replenishment schedule, and verification cap all come from the signed policy object. The architecture supplies the structure and the invariants, including that replenishment must be smaller than the decrement, but not the numbers. Set the decrement too high and a legitimately busy reporter gates itself out of its own work; too low and the dragnet is unpriced.
How hard the deterrent bites depends on what the issuer has to lose. An agent whose budget also gates executions it values feels the cost at once; a reporting-only process with no meaningful execution surface feels less. Containment holds either way, since at or below the floor the agent attaches no attestation and its artifacts are not admitted. Of those two effects, only the second is unconditional.
The mechanism leaves a great deal untouched. It decides no notice's truth, removes no content, restores nothing wrongly removed, and discharges no statutory obligation a deployer may be under. A single well-aimed false accusation goes unstopped by design, and nothing here prevents an accuser from also being correct.
Two consequences are easy to miss. Expiry of a metering window resets the accumulator and clears the per-recipient-class register but restores no budget, the only path back being replenishment on exposure to an uncounted origin-equivalence class. And where the gate went to the withheld state for a reason other than the budget floor, replenishment returns it by no procedure at all.
Classification quality underwrites the whole scheme. Over-splitting by an issuer is detectable at receipt, but each party classifies over material its own memory field holds, so a sparse record can only produce coarse classes.
6. Disclosure Scope
The mechanisms described here are disclosed in U.S. Provisional Application No. 64/117,812 at Chapter 4, Assertion-Cost Symmetry, Sections 4.1 through 4.6: the assertion-cost counter and the authorization budget, the ordered issuance procedure and the budget-floor write, epoch metering and the bar on replay, recipient-side verification including the receipt-verification register and the class-splitting divergence record, and replenishment with its schedule and ceiling. Refinements to the decrement schedule and the return path are disclosed at Section 10.11: the reason-type-conditioned issuance decrement, the progressive issuance decrement, the rejected-determination return decrement, and the conduct-driven persistence tier with promoted-tier renewal counting.
What is disclosed is the specific architecture: pricing issuance against the issuing agent's own authorization budget in units identical to those gating dispatch of its actions, metering per origin-equivalence class of receiving parties within a window expressed in successor epochs, attesting the counter state inside the artifact and verifying it at receipt as a precondition of admission, capping verification obligation per issuing class, and replenishing only upon exposure to an uncounted class by an amount strictly less than the decrement.
What is disclaimed is the general subject matter. This publication claims no ownership of notice-and-takedown as a practice, of rate limiting, of moderation queues, of monetary bonds or staked collateral, of reputation or trusted-flagger programs, or of adjudicating whether a report is meritorious. The architecture expressly computes no adjudication of the truth of alleged conduct as a condition of the decrement.
This article is published as a defensive disclosure establishing a public, timestamped record of this architecture applied to reporting and takedown systems. It describes pending applications, asserts no infringement by any party, identifies no product or service, and states no requirement that anyone obtain a license.