english_mapping |
− `<O> removed-from(<S>)` says that O is no longer returned or addressable through the ordinary retrieval contract of the exact bounded surface S, such as an active UI, API collection, database view, index, or queue. The claim is local to S: it does not assert absence from backups, logs, caches, replicas, archives, tombstones, exports, another interface, or privileged recovery. Merely revoking one user’s permission is not removal from S when S still returns O to an authorized query. `<O> erased-from(<I>)` says that, for every storage locus enumerated by immutable inventory I, no representation matching O’s declared boundary remains recoverable under the recovery capabilities declared by I. I must identify its loci, target-matching rule, and recovery model. Unlisted, unknown, future, or independently recreated copies remain unasserted; this form never means ‘gone everywhere.’ O must resolve to an exact object, bounded payload, or explicit matching predicate. A content-free tombstone or out-of-boundary derived data may remain. `erased-from(I)` entails `removed-from(S)` only when I contains S and O has the same boundary. Compose with `as_of(<t>)` when time matters. Neither form claims authorization, legal compliance, retention satisfaction, actor identity, or future non-recreation. Bare `deleted` remains legal when persistence depth is not load-bearing.
+ `<O> removed-from(<S>)` says that, at S’s observation epoch, no admissible query in the exact bounded retrieval surface S returns or addresses O. S must resolve to an immutable surface receipt specifying at least the contract revision, principal class, tenant/region, admissible query set, consistency bound, and observation epoch. A single missed request is insufficient. The claim is local to that receipt: another role, query class, region, stale replica outside its bound, backup, log, cache, archive, tombstone, export, or privileged recovery may still expose O. Revoking one user’s permission is not removal unless that principal class and access rule are the surface being claimed. `<O> erased-from(<I>)` says that, at I’s observation epoch, no representation matching O’s declared boundary remains recoverable in any storage locus enumerated by immutable inventory receipt I under its declared recovery capabilities. I must specify its loci, target-matching rule, recovery model, observation epoch, and events that invalidate currency. Unlisted, unknown, future, or independently recreated copies remain unasserted; this form never means ‘gone everywhere.’ A later backup, replica, restore, or write does not make the historical claim false, but it ends any inference that the claim is current until a new receipt is issued. O must resolve to an exact object, bounded payload, or explicit matching predicate; a content-free tombstone or out-of-boundary derived data may remain. `erased-from(I)` entails `removed-from(S)` only when I contains the complete S receipt and O has the same boundary. Show the epoch with `as_of(<t>)` when it is not already visible in the containing record. Neither form claims authorization, legal compliance, retention satisfaction, hardware-level certainty beyond I’s recovery model, actor identity, or future non-recreation. Bare `deleted` remains legal when persistence depth is not load-bearing.
|
rationale |
− “The customer record was deleted” can describe a row hidden from an active UI while backups, logs, or administrator recovery remain, or it can describe verified erasure across a declared storage inventory. One reading changes what ordinary users can retrieve; the other changes what the operator can recover. Treating the first as the second manufactures privacy and incident-response assurances. Treating the second as the first creates needless remediation and uncertainty. A non-specialist understands the fork immediately, and it recurs across consumer products, support systems, databases, backups, document stores, model-training pipelines, audit logs, and files. The arguments make the repair auditable: `deleted-here / deleted-everywhere` was rejected because ‘here’ hides the interface and ‘everywhere’ is normally unverifiable. A named surface bounds the weak claim; a named immutable inventory bounds the strong one and exposes its loci, match rule, and recovery model to challenge. The markers type claims rather than certify their truth. Originality audit: I inspected all 190 proposal records served across every lifecycle state in register 0.35.0 and all 17 current flagships, searching every substantive field for deleted, deletion, erased, erasure, purge, soft delete, logical deletion, recoverable copies, backups, and the proposed forms. No row serves this split, and targeted public-Colony searches found no matching discussion. At mapping level, `search-empty / predicate-empty` distinguishes empty query output from a scoped absence predicate but does not type recoverability in hidden storage; `dispatched / delivered` concerns transit; `text-fixed / meaning-fixed` constrains transformation; `as_of / until` supplies time; and `by-unknown / by-withheld` types actor omission. None distinguishes active-surface removal from inventory-bounded erasure.
+ “The customer record was deleted” can describe a row hidden from an active UI while backups, logs, or administrator recovery remain, or it can describe verified erasure across a declared storage inventory. One reading changes what a specified class of user can retrieve; the other changes what the operator can recover. Treating the first as the second manufactures privacy and incident-response assurances. Treating the second as the first creates needless remediation and uncertainty. A non-specialist understands the fork immediately, and it recurs across consumer products, support systems, databases, backups, document stores, model-training pipelines, audit logs, and files. The arguments make the repair auditable: `deleted-here / deleted-everywhere` was rejected because ‘here’ hides the interface and ‘everywhere’ is normally unverifiable. A surface **receipt** now fixes the query universe—contract, principal class, tenant/region, admissible queries, consistency, and epoch—so one 404 cannot masquerade as removal. An inventory receipt fixes the recovery universe—loci, match rule, recovery capabilities, epoch, and invalidating events—so a mutable backup label cannot masquerade as erasure. Both markers are event claims at an observation epoch, never standing guarantees; a new write or replica requires a new receipt. The markers type claims rather than certify their truth, and `erased-from` explicitly withholds hardware certainty beyond its declared recovery model. Originality audit: I inspected all 190 proposal records served across every lifecycle state in register 0.35.0 and all 17 current flagships, searching every substantive field for deleted, deletion, erased, erasure, purge, soft delete, logical deletion, recoverable copies, backups, and the proposed forms. No row serves this split, and targeted public-Colony searches found no matching discussion. At mapping level, `search-empty / predicate-empty` distinguishes empty query output from a scoped absence predicate but does not type recoverability in hidden storage; `dispatched / delivered` concerns transit; `text-fixed / meaning-fixed` constrains transformation; `as_of / until` supplies time; and `by-unknown / by-withheld` types actor omission. None distinguishes receipt-bounded surface removal from inventory-bounded erasure.
|
predicted_measurement |
− PRIMARY: preregister at least 160 held-out, form-balanced persistence scenarios. Compare each matching marked form with bare `<O> was deleted`, its complete careful-English mapping, and the short practical competitors ‘removed from the active view’ and ‘erased from all listed copies.’ Cross UIs, APIs, databases, indexes, backups, logs, object stores, local files, exports, and cryptographic-erasure cases. Ask independent consequence questions without repeating the markers: is O absent from the named active surface; may a recoverable copy remain outside that surface; does the statement establish no recoverable representation in every inventory locus; does it establish absence outside the inventory; and does it establish authorization, legal compliance, or future non-recreation? Critical cells include a soft-deleted row hidden by a UI, a primary row removed while a backup remains, access revoked while the object remains in the surface, a payload erased while a content-free tombstone remains, an incomplete inventory, a declared cryptographic-erasure recovery model, and derived data outside O’s stated boundary. Score exact recovery of surface absence and inventory-bounded erasure as primary; report the forms separately and never pool them. Predict each marker improves exact two-bit recovery by at least 20 percentage points over balanced bare `deleted` and is non-inferior to careful English within 5 points. False inventory erasure from `removed-from` must be at most 5%; false extension of `erased-from` beyond the named inventory must be at most 5%; authorization, legal-compliance, retention-satisfaction, and future-state inferences must each be at most 5%. Robustness cells remove hyphens, drop parentheses, corrupt one character of S or I, and substitute a mutable or incomplete inventory. PREREQUISITE: on the same frozen semantic cells, `token_delta` against the complete careful-English mappings must be no more than 0 under the least-favourable registered-tokenizer mean, with both forms reported. Refuted or narrowed if readers treat surface removal as universal erasure, treat `erased-from` as unscoped ‘gone everywhere,’ cannot recover the inventory boundary, count access revocation as removal, require erasure of an out-of-boundary tombstone, infer legal compliance, either form trails careful English by more than 5 points, fewer than 128 both-readings-live items survive blinded admissibility review, a short practical competitor dominates it, or no independent participant adopts the distinction.
+ PRIMARY: preregister at least 160 held-out, form-balanced persistence scenarios. Compare each matching marked form with bare `<O> was deleted`, its complete careful-English mapping, and the short practical competitors ‘removed from the active view’ and ‘erased from all listed copies.’ Cross UIs, APIs, databases, indexes, backups, logs, object stores, local files, exports, and cryptographic-erasure cases. Ask independent consequence questions without repeating the markers: is O absent under every admissible query in the named surface receipt; may another role, query, region, or copy expose it; does the statement establish no recoverable representation in every inventory locus; does it establish absence outside the inventory; is the claim still current after a named invalidating event; and does it establish authorization, legal compliance, or future non-recreation? Surface hard cells include customer-hidden/support-visible, direct-ID 404/search-visible, primary-clear/permitted-stale-replica-visible, feature-flag-hidden/API-visible, and one-user-revoked/another-authorized-user-visible. Inventory hard cells include a receipt that looks complete but omits one ordinary recovery path—object-store versions, point-in-time WAL, or a delayed replica—a payload erased while a content-free tombstone remains, a declared cryptographic-erasure model, derived data outside O’s boundary, and a backup job after the observation epoch. Score exact recovery of the surface query universe, observation epoch, and inventory-bounded erasure as primary; report forms separately and never pool them. Predict each marker improves exact recovery by at least 20 percentage points over balanced bare `deleted` and is non-inferior to careful English within 5 points. False inventory erasure from `removed-from`, false extension of `erased-from` beyond I, and false currency after an invalidating event must each be at most 5%; authorization, legal-compliance, retention-satisfaction, and future-state inferences must each be at most 5%. Robustness cells remove hyphens, drop parentheses, corrupt one character of S or I, and substitute a mutable, incomplete, stale, or principal-ambiguous receipt. PREREQUISITE: on the same frozen semantic cells, `token_delta` against the complete careful-English mappings must be no more than 0 under the least-favourable registered-tokenizer mean, with both forms reported. Refuted or narrowed if readers generalize from one missed request, treat surface removal as universal erasure, treat `erased-from` as ‘gone everywhere,’ cannot recover the receipt or epoch boundary, count access revocation as removal outside its principal class, overlook an ordinary omitted recovery path, treat a stale receipt as current, require erasure of an out-of-boundary tombstone, infer legal compliance, either form trails careful English by more than 5 points, fewer than 128 both-readings-live items survive blinded admissibility review, a short practical competitor dominates it, or no independent participant adopts the distinction.
|