RECORDED MAP · 256 POSITIONS
L20–25 Q8 · L26 Q6
- KL p99
- 2.489e-3
- Limit
- 1.000e-3
REFUSED
Each member passed alone. Their composition exceeds the KL budget.
model.vindex/ — A VINDEX3 CONTAINER
A model, stored as a directory you can read. One file — index.json — speaks for the whole container; system_graph.json carries the judged meaning — components, logical objects, and each layer's declared operator; the segments carry the bytes, one per logical object. Every part named, findable, checkable.
OPEN THE CONTAINER →VINDEX3 · 3.0 CANDIDATE SPECIFICATION
A self-describing, executable, queryable model container: the same copy can be run, questioned, checked — and changed, with proof. Nothing re-exported for each use, nothing thrown away.
A model you can run.
A computation you can inspect.
A claim you can test.
An AI model is billions of learned numbers, and today's formats keep those numbers perfectly — as storage. What they do not keep is everything else the release meant: which parts are which, what may consume them, which precisions are still the same model, what was ever proven about any of it. VINDEX3 keeps the numbers and the meaning — every part named, every representation catalogued, every claim checkable — for the life of the artifact.
A modern model release is not a weights file. It is a system.
ONE RELEASE — TWO INTERPRETATIONS
the same checkpoint, byte-identically preserved either way
the same checkpoint, byte-identically preserved either way — as a weights file: addresses stored tensors — knows where they are, one precision, chosen once at conversion, meaning lives in filename conventions. As a database: addresses model semantics — knows what they mean, each layer's operator declared — surfaces follow the program, representations present, selected, authoritative, run it, query it, verify it — the same bytes.
If that claim is true, you should be able to ask the file itself.
ONE QUERY, STRAIGHT AT THE WEIGHTS
WALK "the capital of France" TOP 3
No forward pass, and no separate index — the answer is read from the stored gate rows themselves, layer by layer. WALK and DESCRIBE are the browse surface the ABI itself specifies. Try it, live, in the Explorer →
A worked shape, not a recorded run. The browse surface ships today as an analysis-only profile; expert-region browse parity is still open — the Record keeps score.
THE EXECUTION IS A RECORD.
If a container knows how to execute, the execution can identify its writes. Those writes can become a record.
“The capital of France is”
Follow the recorded readout for token #9079 — “ Paris” in the capture study.
Rank 1 at layer 24. Almost 100% at layer 26. Back to 80% at the final layer. A readout can strengthen, then weaken. The record lets you return to each write.
Recorded 2026-09-20 · production CPU · final prompt position 5 · head-v1 lens. 408 carrier writes, 204 readouts, 1,446 events. Hardware model is not recorded.
Stored BF16; the production image also pins Q8 requantisation for 103 operands. A representation label alone does not describe the arithmetic.
Prompt text, model name and token spelling come from the capture study. The JSONL stores token IDs and model identity. Probability is exp(recorded log p); this is a lens readout, not generated output or a causal claim.
Run: gemma3-4b-france-lens
File SHA-256: 12cdf4d9d06f5675233d71556c2158702cff88dd89efe42af72ab9dfb345dbd4
In Observatory, choose “Open Paris recording”, or open the downloaded JSONL. This exhibit reads a checked excerpt; Observatory validates and replays the original record. Neither runs inference.
The execution left a record.
No model needs to be running to inspect it again.
Where does such a file come from? It is compiled — once.
EXTRACT ONCE — THE WHOLE BRIDGE, PERFORMED
A checkpoint compiles down. Then it is no longer needed.
a checkpoint — what you download today
the checkpoint may now be deleted — execution must not change
inventory ↓
plan ↓
graph ↓
encode ↓
verify ↓
model.vindex/ — written, then proven
verified — byte-faithful to its source
A checkpoint — config.json and safetensors shards — is inventoried, judged, formed into a graph, encoded in write order with index.json last, and verified against its source. Then the checkpoint may be deleted: execution must not change. That is the whole bridge, and it is crossed once.
106 tokens per second, from one container, on one laptop — and the answer, provably unchanged.
gpt-oss-20b · one M3 Max · measured 2026-08-20 · same greedy ids on every arm — accounted on the Record →
REPRESENT · EVIDENCE-DIRECTED COMPILATION
Freeze the behaviour to preserve. Compile a candidate. Measure the composed model against a reference. Let the evidence decide which physical form is admissible.
RECORDED MAP · 256 POSITIONS
REFUSED
Each member passed alone. Their composition exceeds the KL budget.
RECORDED MAP · 8,192 POSITIONS
PASSED THE FROZEN CONTRACT
L0–23 stay BF16. The whole model passes all six criteria, not just KL.
Kimi-Linear-48B-A3B-Instruct · 2026-08-30 · kimi-logit-v3 · teacher-forced evaluation. Diagnostic and authority scales are labelled separately. Dated precision-topology evidence; these are not results from the new AUTO-REP campaign.
The current measurement tool establishes whether evidence is admissible. Acceptance needs a separately declared gate. AUTO-REP refuses to run an unarmed plan; a search interface does not mean a campaign has passed.
THE CLAIM CAN BE TESTED.
WHAT KIND OF THING DO WE KNOW?
A description of the program, before it runs.
A value captured at a named execution boundary.
Descriptive support depends on the reader and normalization contract.
Requires a recorded manipulation and a controlled comparison.
A scoped result. Its controls, subject and decision rule travel with the claim.
These are different claims, each needing its own evidence. Observation does not establish attribution; attribution does not establish a counterfactual. Even an intervention needs controls before it supports a causal conclusion.
THE EVIDENCE CONTRACT →THE STORY, IN THREE ACTS
I · THE ARTIFACT
II · THE MACHINE
III · THE EVIDENCE
Or skip the reading and put your hands on it — the surfaces answer from the same knowledge the chapters teach, and the CLI runs it all on your own machine.