Mechanism

A governed observation is the unit of exchange on the spatial-mesh substrate, as taught in Provisional Application 64/049,409. Each observation is a structured envelope comprising at minimum an authority-credential field per the published authority taxonomy, a dynamic-device-hash field encoding identity continuity of the emitting device, a spatial-reference field encoding a position in a coordinate frame, a temporal-reference field encoding a time in a time reference, a time-to-live field encoding the observation's validity duration, a payload field encoding domain-specific observation content, and a lineage field recording provenance with a cryptographic integrity attestation over the foregoing fields.

The authority credential is not a hint and not metadata. It is a structural field of the observation envelope, carried per the authority taxonomy and bound into the cryptographic attestation that protects the envelope. The governed observation is structurally distinguished from un-credentialed sensor data, un-credentialed telemetry, and un-credentialed messages in that it carries a verifiable authority credential, carries a verifiable device-identity attestation, and carries a lineage record permitting deterministic reconstruction of provenance. It is structurally distinguished from prior signed-message schemes in that the authority credential carries hierarchical trust semantics consumed by a cognitive architecture, rather than a binary valid-or-invalid attribute consumed by a simple authentication check.

Each consuming agent evaluates an arriving governed observation through its own governance chain. The consuming agent's governance policy determines, by the credential's authority level and by the agent's own constraints, how the observation is admitted and at what evidential weight. The governance policy is referenced by version, and the version applied to each determination is recorded.

Admission is performed by a composite admissibility evaluator that runs ahead of any payload-handling logic in the consuming agent. The evaluator weighs the governed observation against the agent's governance policy and produces one of a plurality of admissibility outcomes: an admit outcome, wherein the observation is admitted into the agent's experiential observation store at the computed evidential weight; a gate outcome, wherein the observation is admitted at reduced evidential weight or subject to additional governance-policy-defined constraints; a defer outcome, wherein the observation is held pending corroborating observations until a deferral-expiration parameter elapses, after which the deferral resolves to an admit, gate, or reject outcome; a solicit outcome, wherein the evaluator emits a governed discovery query requesting additional observations to resolve uncertainty; a reject outcome, wherein the observation is not admitted, carrying a rejection-reason classification; and an escalate outcome, wherein the evaluator produces a cross-domain escalation upon detection of emergent conditions.

The composite admissibility evaluator operates uniformly across admissibility determinations within the consuming agent's cognitive architecture. A reject outcome carries a rejection-reason classification selected from insufficient authority, failed continuity validation, stale observation, failed corroboration, dispositional inconsistency, capability-envelope incompatibility, integrity conflict, or any governance-policy-defined rejection class. Device identity is established through trust-slope continuity rather than through static credentials such as application-programming-interface keys, long-lived certificates, or shared secrets.

Operating Parameters

The authority credential is drawn from a published authority taxonomy. The authority credential carries hierarchical trust semantics: an observation's evidential weight in each consuming agent's cognitive architecture follows from the contributing device's authority level. Observations from a high-authority contributing device carry high evidential weight and may be treated as substrate conditions; observations from a low-authority contributing device carry low evidential weight and contribute primarily as advisory input to the composite admissibility evaluator.

The observation is bounded in scope by its own fields. The spatial-reference field localizes the observation within a coordinate frame, the temporal-reference field localizes it within a time reference, and the time-to-live field encodes the validity duration. A stale observation, one whose validity duration has elapsed, is a recognized rejection-reason classification at the composite admissibility evaluator.

The continuity proof, the dynamic-device-hash, encodes identity continuity of the emitting device through trust-slope continuity. A producer whose continuity is broken, a hash that does not chain to the producer's prior credentialed state, draws a failed-continuity-validation rejection at the consuming agent's composite admissibility evaluator. Continuity is established through the device hash rather than through static credentials.

Each admissibility determination is recorded. The composite admissibility evaluator records the weights applied, the factors contributing to each weight, the outcome, and the governance-policy version applied, and the observation's lineage field records provenance with a cryptographic integrity attestation. An observation's contributions compose through the lineage field to produce a cross-device, cross-authority provenance record.

A deferred observation is bounded. A defer outcome includes a deferral-expiration parameter; the observation is held in a deferral queue until the deferral-expiration parameter elapses or until corroborating observations arrive, and is demoted to a reject outcome upon expiration without corroboration. The deferral-expiration parameters, the solicit-emission policy, and the escalation rules are set per governance policy.

Alternative Embodiments

In a first embodiment, the consuming agent's composite admissibility evaluator and governance policy run in-process on the consumer device. The governed contribution mechanism does not require an acknowledgment, a handshake, a delivery confirmation, or a registration with a central authority; the contribution is complete upon emission, and any device within signaling range that receives the encoded observation reconstructs it and evaluates it through the device's own governance chain. This embodiment suits autonomous units operating with intermittent connectivity to governance authorities.

In a second embodiment, the authority taxonomy is hierarchical, comprising levels such as a facility-operations authority, a zone-supervisor authority, a shift-lead authority, and an individual-operator authority. Each level in the taxonomy maps to a behavioral response through the same cognitive-architecture mechanism. The taxonomy is not limited to any specific number of levels, set of level names, or operational domain; any governance-policy-defined hierarchy of credentialed authorities is within scope.

In a third embodiment, observations cross authority taxonomies by federation: authority-mapping rules translate credentials across authority taxonomies so that a consumer operating across domains can evaluate observations credentialed under a foreign taxonomy. This federated-authority composition supports cross-domain interoperation in which a base authority is broadly recognized but specialized credentials are mapped through the federation's authority-mapping rules.

In a fourth embodiment, authority is delegated or escalated: under delegated-authority composition one authority delegates credentialing to another for specified observations, and under escalated-authority composition a higher authority overrides sub-authority credentials for specified observation types such as emergency response or regulatory inspection. The composite admissibility evaluator's escalate outcome produces a cross-domain escalation upon detection of emergent conditions.

In a fifth embodiment, a governed observation derived from multiple source observations inherits a composite authority credential derived from the source credentials per governance-policy-defined authority-resolution rules, together with a composite capability scope equal to the intersection of source capability scopes, or the union where governance policy defines. This supports operations bound simultaneously by multiple governance regimes, where the merged provenance-lineage record preserves each source observation's contribution.

Composition with the Spatial-Mesh Architecture

Every other primitive in the spatial-mesh architecture consumes governed observations, and consumes them through the same composite admissibility evaluator. Marker-track transport admits credentialed marker observations whose authority credential supports route construction. Confidence-governed actuation admits credentialed environmental observations and modulates actuator behavior by the consuming agent's confidence and the observations' evidential weight. Matched-pair settlement admits credentialed pairing observations and settles within the pairing's proximity window. The governed observation is the unit of exchange across the entire governance chain, and every actuation decision recorded in a lineage field references the governed observations upon which the decision was based.

The uniformity is the architectural property that makes the spatial mesh composable. The composite admissibility evaluator operates uniformly across admissibility determinations within the cognitive architecture, including admission of governed observations into the experiential observation store, admission of proposed actuations, admission of proposed mesh relays, and admission of proposed governance-policy updates. The governed observation primitive is uniform across sensing modalities, across signaling media, across deployment domains, and across device tiers.

Cross-domain interoperation follows from the same property. Maritime, aviation, terrestrial, and indoor authorities each issue observations within domain-specific authority taxonomies; a consumer operating across domains evaluates each observation through its governance chain, with authority-mapping rules translating credentials across authority taxonomies under federation. The cross-domain reach of the architecture follows from the authority taxonomy and the consuming agents' governance policies.

Prior-Art Distinction

The governed observation is structurally distinguished from prior centralized sensor-aggregation systems, prior Internet-of-Things platforms, and prior digital-twin architectures. The contribution is peer-to-peer through the governed mesh, requiring no network connectivity to a cloud service, a centralized collection endpoint, or a proprietary back-end. Each observation carries a verifiable authority credential that determines the observation's evidential weight in each consuming agent's cognitive architecture, rather than being treated homogeneously as undifferentiated sensor data. Device identity is established through trust-slope continuity rather than through static credentials such as application-programming-interface keys, long-lived certificates, or shared secrets. Contributions compose through the lineage field to produce cross-device, cross-authority provenance rather than disconnected per-device telemetry.

The composite admissibility evaluator is structurally distinguished from prior threshold-based, voting-based, and rule-based admission mechanisms. It computes a composite evidential weight integrating a plurality of factors, authority, staleness, modality, dispositional, reputation, integrity, and continuity, rather than applying a single-factor threshold. It produces a plurality of outcomes, admit, gate, defer, solicit, reject, and escalate, rather than a binary admit-or-reject. It emits a governed admissibility-determination observation recording the complete evaluation provenance, rather than producing only a pass-or-fail decision. It admits new factors, new outcome classes, and new rejection-reason classifications through governance-policy update without architectural modification, rather than embedding fixed evaluation logic.

Disclosure Scope

The disclosure of U.S. Provisional Application No. 64/049,409 covers the governed-observation envelope and its structural fields, the authority credential carried per the published authority taxonomy, the dynamic-device-hash continuity field, the lineage field and its cross-device cross-authority provenance, the composite admissibility evaluator and its admit, gate, defer, solicit, reject, and escalate outcomes, and the embodiments enumerated above. It also covers the composition of the primitive with marker-track transport, confidence-governed actuation, matched-pair settlement, and any subsequently added spatial-mesh primitive that consumes governed observations through the same composite admissibility evaluator.

The disclosure is independent of any particular sensor modality, transport medium, or operational domain. The same governed observation applies across sensing modalities; across wired, wireless, and store-and-forward signaling media; and across maritime, aviation, terrestrial, and indoor deployments. The disclosure is the structural primitive on which the spatial-mesh substrate's governance properties rest.