Retained input bytes, source identity and explicit state time.
Separate the state
from the authority.
CMM.X keeps observation, state construction, proof, publication and permission in distinct layers. A successful technical proof cannot silently become a market or action claim.
Bound point-in-time description under a declared transformation.
Derivability, package identity and independent reproduction.
Append-only historical placement and release identity.
Separate external or protocol permission. Never inferred from health or proof.
Five layers. Five different questions.
The architecture is intentionally non-collapsing: each transition requires its own evidence and failure semantics. See how bounded future possibility is kept separate from prediction →
What was observed?
Input identity, source scope, retained bytes and timestamps are part of the delivery object rather than implementation trivia.
ABSENT INPUT → DATA_LIMITEDWhat state was constructed?
The output is a bounded state description. Missing or contradictory authority is not replaced with a guessed value.
AMBIGUITY → UNDETERMINEDCan it be reproduced?
The verifier answers identity and derivability questions. Passing proof does not establish usefulness, direction or market advantage.
DIVERGENCE → FAIL CLOSEDWhat may follow?
Action authority, external authenticity and protocol-level promotion require independent authorization outside the proof result.
ACTION_GATE · 0Failure semantics are part of the product.
CMM.X does not convert incomplete evidence into confidence. Each failure class maps to a visible non-promotion state.
STALE / MISSINGState remains unavailable or explicitly limited.DIVERGENTReproduction or identity mismatch blocks acceptance.UNDETERMINEDNo substitute value is inferred from absence.AUTHORITY MISSINGProof may stand while promotion remains prohibited.Verify the architecture against the bytes.
Start from the public release, reproduce it independently, then map the output to your own consumer and governance boundary.