1. Mechanism: Recursive Chain Composition Across Levels

Hierarchical governance composition specifies that the five-property governance chain, authority-credentialed observation, evidential weighting, composite admissibility, governed actuator execution, lineage-recorded provenance, operates simultaneously at multiple declared composition levels. The disclosure articulates a hierarchical composition doctrine in which a distributed world model operates at multiple scales through governance-policy-defined composition of localized world models: a unit-level model maintained by each autonomous unit (its own sensor observations, operator state, mechanical state, navigation state, and capability envelope), a place-level model maintained by each building, facility, campus, or operational zone, a zone-level model composing place-level models across a geographic zone, a regional model composing zone-level models, and a global model composing regional models at the broadest scale of governance. Each level runs the governed contribution, authority-credentialed, evidential-weighted architecture, and each level contributes a governance-policy-filtered, authority-appropriate summary to the next level rather than raw observations.

The composition is structural rather than orchestrational. Each localized model is self-contained and self-governing, with composition into broader models being additive rather than required for local governance. Lower-level chains operate autonomously over their own contributions while incorporating higher-level inputs as authority-credentialed observations evaluated through the same chain. A lower-level chain declining a higher-level input, because the input fails composite admissibility evaluation under the lower level's local context, is a structurally permitted outcome, recorded in lineage. Per-level governance autonomy means that every level accepts credentialed inputs, weights them by authority and source consistency, and decides admissibility under its own composite evaluation rather than under central command.

Governed summaries propagate bidirectionally between distributed and centralized composition. Filtered, authority-appropriate summaries propagate upward (a unit's sensor observations and confidence become a summary to the place level; the place level's aggregated state becomes a summary to the zone level, and so on toward regional and global models). Policy updates and credential revocations propagate downward: a credentialing authority emits a revocation as a governed observation identifying a specific device, credential, or credential class as no longer authoritative, and each consuming level down-weights or invalidates previously-admitted observations and incorporates the revocation through its own admissibility evaluation. Both directions traverse the same five-property chain at every composition level.

2. Operating Parameters and Engineering Envelope

Authority credentials governing each level are administered through the device credentialing lifecycle, which supports enrollment, issuance, rotation, update, and revocation of governance credentials. Credentials carry the authority-credential, temporal-scope, and cryptographic-attestation fields of the authority taxonomy. A credentialing authority emits credential issuance, rotation, and revocation as governed observations, so that credential administration is itself subject to the same five-property chain that governs operational mutations: an observation, evaluated for admissibility, applied, and lineage-recorded.

Policy and directive flow across levels uses the mesh-distributed governance-policy propagation mechanism. A deploying authority publishes a policy update as a governed observation carrying the policy version, the policy content, the deploying authority's signature, and an applicability-scope specification identifying the eligible devices. The update propagates through the governed mesh, including multi-hop relay and mobile store-and-forward carriage across sparse-connectivity regions, and at each receiving device is evaluated through composite admissibility, applied atomically with a rollback path on admission failure or subsequent revocation, and recorded in the device's lineage field. The mechanism supports hierarchical policy propagation, wherein a policy update issued by a higher-authority deploying authority supersedes a conflicting policy state established by a lower-authority deploying authority per the supersession semantics of the authority taxonomy, and scope-specific propagation, wherein an update may specify a geographic scope, a temporal scope, a device-class scope, or a combination thereof.

The architecture does not require centralized control, cloud connectivity, or single points of failure, and supports deployment from a single-vehicle self-model to a national sensing network through the same governed architecture at every level. Because composition into broader models is additive rather than required for local governance, a lower-level model continues operating under its last admitted state when upward connectivity is degraded, with degraded-mode continuation applying stricter admissibility criteria and the lineage field recording the transition for later reconciliation.

3. Alternative Embodiments

The number of composition levels is not fixed. The architecture admits any number of aggregation tiers, so that a deployment may compose few levels or many so long as each level runs the governed chain and contributes an authority-appropriate summary to the next. Levels need not be geographic: the disclosure is not limited to any specific number of aggregation tiers or topology of the distributed spatial world model, so a logical governance layer composes identically with geographic levels.

Aggregation topologies may be tree, lattice, peer-to-peer, or hybrid, and any governance-policy-defined aggregation function is within the scope of the disclosure. A tree topology assigns each lower level to a single higher-level parent; a lattice or peer-to-peer topology permits a lower-level chain to contribute to multiple higher-level models. Where contributions arrive from multiple authorities, the composite admissibility evaluation resolves them under the multi-authority superposition support of the architecture, which admits coexisting authorities without requiring coordination among them. The disclosure encompasses distributed, centralized, and hybrid world-model topologies, with governed summaries propagating bidirectionally between distributed and centralized composition.

4. Composition with Adjacent Primitives

Hierarchical composition is the structural carrier for cross-authority operations across boundaries: cross-jurisdictional handoff, in which the architecture supports cross-authority route composition spanning multiple jurisdictional authorities and multi-authority co-existence on a single physical location, regulatory directive propagation, in which a policy update issued at a higher-authority level descends to lower levels through credentialed governed observations under the hierarchical and scope-specific policy-propagation mechanism, and forensic reconstruction, in which lineage records issued at every level under their respective credentials are traversable to reconstruct prior state.

The primitive composes with the cascade-propagation primitive: cascade-propagation observations emitted at lower levels propagate through the governed mesh with their provenance preserved, supporting cross-level situational awareness without sacrificing per-level governance autonomy. It composes with marketplace and capability-envelope allocation primitives that govern resources such as port berths, charging stations, and airspace under participant credentials. It also composes with fleet-contributed skill emergence: per-agent adaptation artifacts are aggregated through governance-policy-defined functions at building, campus, zone, and regional levels per the hierarchical composition doctrine, with a cross-agent provenance recorder recording per-agent contributions to each aggregated artifact.

5. Prior-Art Distinctions

The disclosure distinguishes the hierarchical composition doctrine from three classes of prior multi-scale architecture. It is distinguished from centralized digital twin architectures, wherein all data flows to a central point, because each localized model is self-contained and self-governing and composition into broader models is additive rather than required for local governance. It is distinguished from federated data architectures, wherein central maintenance is required, because the architecture operates without cloud connectivity, centralized control, or single points of failure. And it is distinguished from hierarchical monitoring architectures, wherein lower-level systems depend on higher-level availability for operation, because a lower-level model continues governing locally when upward connectivity is degraded.

More broadly, prior architectures lack hierarchical composition producing governance-policy-filtered summaries at each scale, and lack the unified five-property governance chain imposed on every mutation. The distinguishing features of the disclosed doctrine are the same governed contribution, authority-credentialed, evidential-weighted architecture at every level, per-level summary functions contributing authority-appropriate summaries to the next level rather than raw observations, per-level governance autonomy, and recursive application of every primitive across composition levels.

6. Disclosure Scope

Disclosed in U.S. Provisional Application No. 64/049,409 (Governed Spatial Mesh) is the hierarchical composition doctrine, wherein a distributed world model operates at multiple scales through governance-policy-defined composition of localized world models, producing regional and global spatial intelligence from per-unit, per-place, per-zone, and per-region contributions. Each level runs the governed contribution, authority-credentialed, evidential-weighted architecture, contributes an authority-appropriate filtered summary to the next level rather than raw observations, retains per-level governance autonomy, and records its contributions in the lineage field. The disclosure is not limited to any specific number of aggregation tiers or topology of the distributed spatial world model, and encompasses tree, lattice, peer-to-peer, and hybrid topologies and any governance-policy-defined aggregation function.

A system implementing the disclosed architectural chain across composition levels with any present or future credential scheme, transport, or transduction substitution embodies the same architecture, because the governance-semantic layer is disclosed independently of any specific transduction choice under the technology-neutrality and future-proofing doctrine. Multi-scale architectures in which credentialed governance layers run authority-weighted composite admissibility over governed actuation, with governed summaries propagating bidirectionally between levels and lineage recorded throughout, fall within the disclosed doctrine even where an implementer does not name the layers as "levels" or "chains."