FORGE-002 — The Forge Principles & Ontology

FORGE-002 — The Forge Principles & Ontology

Project Forge — Second Founding Document Extends and corrects FORGE-001. Where the two disagree, FORGE-002 governs.


Part 1 — A Critique of FORGE-001

FORGE-001 did its job: it broke the frame. It replaced “redesign the website” with “build the living presence of a scientific instrument,” and that reframing should stand for the life of the project. But a founding vision written to inspire will contain errors that a constitution cannot afford. Here they are.

1.1 What was merely beautiful

The aurora. FORGE-001 opens with luminance moving across the screen “like aurora over a ridgeline — not decoration, but the actual breathing of the machine.” That sentence contains its own refutation. If the underlying data refreshes every few minutes — which, on a published platform, it will — then a continuously breathing animation is an interpolation performed for emotional effect. It is decoration wearing the costume of data, and it violates the project’s own deepest rule, Truth Over Illustration, on the front page. The ambient-state concept survives; the theatrical rendering of it does not. The machine’s presence must be exactly as alive as the data is, and must say how old it is.

The beloved node. FORGE-001 flirted with sentimentality: nodes with “biographies,” a retirement page “visited by thousands,” hardware we are invited to love. The durable idea underneath is real and important — structured operational memory that outlives staff turnover. But the emotional framing is kitsch waiting to happen, and kitsch is fatal to an instrument’s dignity. A node has a service record, not a soul. Keep the record; retire the romance.

“The single field is the entire interface.” This was the most quotable line in FORGE-001 and the most wrong. Search presumes you know what to ask. A first-year student, a minister, a journalist — the people the platform claims to welcome — arrive precisely not knowing what to ask. A great library has both a catalog and open shelves; you find what you sought in the catalog, and what you needed on the shelf beside it. FORGE-001 designed the catalog and dismissed the shelves as “mega-menus.” That was rhetoric outrunning judgment. The platform must be askable and walkable, and the walkable structure is not navigation-as-org-chart — it is the ontology itself, made visible.

1.2 What would fail in real scientific environments

Provenance Descent, as promised. “Fall from a headline to a joule” requires a chain — publication → dataset → job → node → energy — whose middle links do not exist in practice. Researchers do not tag jobs with the papers they become; the gap between a job finishing and a paper appearing is one to three years; and no incentive currently closes the loop. FORGE-001 presented Provenance Descent as a foundation. It is not. It is an aspiration that the ontology must make possible — sparse links, added when they can be, celebrated when they exist — but nothing may depend on the chain being complete. A platform that promises descent and delivers broken links teaches distrust, the one lesson it must never teach.

“Anyone may look,” unqualified. The lighthouse metaphor was stirring and legally naive. A job record names a person; a person’s compute history reveals unpublished research directions; usage patterns are competitively and personally sensitive; and much of this falls under GDPR regardless of our philosophy. Radical transparency about the instrument does not entail radical transparency about the people using it. FORGE-001 never drew that line. FORGE-002 draws it as a principle: aggregate in public, individual in confidence (Principle 8, and encoded in the ontology as private facets, §3.6).

The forecast, oversold. “Queue Weather” promised “when the pressure system will pass.” Genuine queue prediction is a hard research problem; a false forecast is worse than none, because researchers will plan around it. The reframing from position to outlook survives — it is one of FORGE-001’s best ideas — but version one of the outlook must be honest historiography (“jobs of this shape have typically started within N minutes at this hour, this term”), clearly labeled as historical pattern, not prophecy. Prediction can arrive later and must announce its error bars when it does.

1.3 What FORGE-001 missed entirely

Failure. The document describes the platform on its best day and never on its worst. But the moment users need the platform most is the moment the machine is down — and an outage is also when live pipelines are most likely to be broken. The degraded state cannot be an afterthought or a browser error; it must be a designed, first-class condition. An instrument under maintenance is still an instrument. (Principle 12.)

The cost of being alive. Every living surface — every generated document, every current number, every “right now” — is a promise made to the future, and promises are paid for in maintenance. FORGE-001 spent promises like a lottery winner. A stale “live” indicator is worse than a page that never claimed to be live; a broken contextual hint is worse than no hint. The platform’s ambition must be bounded by the team’s capacity to keep its promises, and features must state their upkeep cost before they ship. (Principle 11.)

The operators. FORGE-001 designed for researchers, executives, and the public, and forgot the people who actually keep the instrument alive. Operations staff suffer a particular injustice: their work is invisible exactly when it succeeds. A platform that records events — maintenance, upgrades, recoveries — with authorship gives operational work a public record for the first time. This is not a feature; it is overdue fairness, and it is also how the platform’s memory gets written.

The platform’s own honesty about time. FORGE-001 demanded documentation that cannot rot but never asked the harder question: how does a reader know how fresh any fact is? The answer became a principle: every fact on the platform carries its age, visibly (Principle 3). “Truth” on a published platform is always “truth as of a stated moment,” and hiding the timestamp is a small lie.

1.4 What is genuinely transformative and stands

Four ideas from FORGE-001 survive scrutiny fully and become the spine of everything below: the ontology (one canonical set of nouns spoken by every part of the platform); documentation generated from truth, so staleness is structurally impossible; the receipt (every job concludes with a human-readable account of what it did and cost); and calm as a defining, non-negotiable quality. The Same Window principle also stands, now reconciled with privacy: one structure for everyone, with private facets occluded rather than parallel experiences built (§3.6).

1.5 Verdict

FORGE-001 idea Verdict
Instrument, not website Foundation — unchanged
Ontology of nouns Foundation — expanded into Part 3
Docs generated from truth Foundation — unchanged
The receipt Foundation — unchanged
Calm Foundation — unchanged
Same window, depth-only hierarchy Kept, reconciled with private facets
Ambient live state Kept, stripped of theatrical animation; must show its age
Queue outlook Kept, downgraded from forecast to honest historical pattern
Node biographies Kept as service records; sentiment removed
Provenance Descent Demoted to sparse aspiration; nothing may depend on it
“Search is the entire interface” Corrected — askable and walkable
“Anyone may look,” unqualified Corrected — transparency gradient
Failure states, upkeep cost, operators Missing — added as Principles 11–12 and throughout

Part 2 — The Forge Principles

Twelve principles. They are written to be cited in code review, in design review, and in arguments — “this violates Principle 3” should be a complete objection.


1. Truth Over Illustration

Philosophy. The platform is a scientific instrument’s account of itself. An instrument that decorates its readings is broken.

Explanation. Every visual element that looks like data must be data — traceable to a source, reproducible from the published record. Nothing may animate, glow, or move to simulate vitality the underlying data does not have. Illustration is permitted only where it is unmistakably illustration.

Practical implication. For any element, a reviewer may ask: what is the source of this, and when was it measured? If the answer is “it’s evocative,” the element is either clearly framed as illustration or removed.


2. Every Noun Is a Place

Philosophy. Things that matter get names, addresses, and permanence. What cannot be visited cannot be understood, cited, or trusted.

Explanation. Every canonical object — a node, a module, a job, a publication — has exactly one home, one permanent address, and one identity, no matter which path led to it. There are no duplicate representations living in different subsystems.

Practical implication. If two screens describe the same thing differently, one of them is a bug. Any object mentioned anywhere is a link to its one home. Addresses never break; objects end, but never vanish.


3. Show the Age of Every Fact

Philosophy. On a published platform, all truth is “truth as of a moment.” Concealing the moment converts honesty into deception.

Explanation. Every measurement, count, and state indicator carries its timestamp — visibly, not in a tooltip confession. “Live” is a claim with a definition (“updated every N minutes”) stated where the claim is made. When data is old, the platform says so before the reader can be misled.

Practical implication. No number ships without provenance-of-time. A stale value displays as stale — automatically, by design, not by someone remembering to flag it.


4. Reveal, Don’t Decorate

Philosophy. The instrument and its science are already extraordinary. The design’s job is to remove whatever stands between the reader and that fact.

Explanation. Visual richness is spent exclusively on meaning: the readings, the structure, the story in the data. Ornament, mascots, stock imagery, and enthusiasm-signaling are all forms of standing in front of the instrument.

Practical implication. Every element must justify itself by what it reveals. The default answer to “should we add visual interest here?” is to reveal more truth, not to add more surface.


5. Calm Is a Feature

Philosophy. Attention is the researcher’s scarcest resource. A platform that grabs attention steals from science.

Explanation. No badges, streaks, urgency mechanics, or notification pressure. The platform never interrupts; it is consulted. Alarm is reserved for the rare truths that warrant it, so that when the platform does raise its voice, it is believed instantly.

Practical implication. Any mechanism designed to increase engagement is rejected by definition. Red means something is wrong with the machine — never “look here.”


6. Knowledge Arrives

Philosophy. The measure of documentation is not whether it exists but whether it is present at the moment of confusion.

Explanation. Knowledge is written against the ontology and surfaces where its subject lives: on the module it describes, at the failure it explains, beside the decision it informs. The reader should rarely need to “go to the docs,” because the docs are already standing where the question arose.

Practical implication. Every document declares which objects it is about; those objects surface it. A support question answered twice is a signal that knowledge failed to arrive somewhere — and the fix is placement, not another FAQ.


7. Walkable and Askable

Philosophy. Asking serves those who know their question. Walking serves those who don’t yet. A platform for everyone must honor both.

Explanation. Search is the fastest path for the oriented. But the platform is also a legible landscape: from any object, the connected objects are visible and reachable, and from the entrance, the major regions of the world are apparent. The walkable structure is never an org chart — it is the ontology made visible.

Practical implication. Every object shows its edges (what it belongs to, contains, relates to). A user who never touches the search field can still reach everything. A user who only searches never needs the shelves — but they are always beside the answer.


8. Aggregate in Public, Individual in Confidence

Philosophy. The instrument belongs to the public; the work of individual researchers, until published, belongs to them.

Explanation. Transparency has a gradient. The machine’s state, capacity, energy, history, and aggregate usage are public without qualification. The activity of an identifiable person or an unpublished project is visible to its owners and to no one else. The platform never enables surveillance of researchers — by the curious, by rivals, or by their own supervisors beyond what stewardship genuinely requires.

Practical implication. Every facet of every object is classified public or private at design time, deliberately — never by accident of implementation. Public views aggregate; private facets are occluded, not linked-but-forbidden.


9. Nothing May Rot

Philosophy. A document that can silently disagree with the machine is a trap laid for a future reader.

Explanation. Any content that describes changeable reality — versions, paths, counts, states, examples — is generated from the same source of truth the platform itself runs on. Hand-written prose is reserved for what only humans know: intent, judgment, narrative, warning.

Practical implication. Staleness is a build failure, not a maintenance chore. When a module is retired, everything that referenced it knows mechanically. If a fact must be typed by hand into prose, that is a defect in the data model.


10. Depth Is the Only Hierarchy

Philosophy. One world, one window. Expertise determines how deep you go — never which door you are allowed through.

Explanation. There are no parallel experiences for the public, researchers, and executives. Everyone stands before the same structure; a minister and a student see the same node, the same story, the same ledger. Private facets are occluded per Principle 8, but the architecture never forks.

Practical implication. No “admin site,” no “public brochure,” no “researcher portal.” A proposed feature that requires a separate parallel surface is presumed wrong. Executive reporting is the same objects at higher altitude, not a different building.


11. Every Living Surface Is a Promise

Philosophy. A “live” feature is a commitment to keep it alive, made silently to every future reader. Broken promises cost more trust than absent features.

Explanation. Freshness, contextual hints, generated content, and outlooks all require upkeep forever. The platform’s ambition is therefore bounded by the team’s sustained capacity, not by what is possible in a launch sprint. A smaller set of kept promises beats a larger set of decaying ones — always.

Practical implication. Every living feature ships with a named upkeep cost and a designed behavior for when its pipeline fails. If a promise can no longer be kept, the feature is honestly retired — never left to decay in place.


12. Fail With Dignity

Philosophy. The platform matters most when the machine is at its worst. An instrument under maintenance is still an instrument.

Explanation. Outage, degradation, and missing data are designed states, not exceptions. When the machine is down, the platform becomes calm, informative, and useful: what happened, what is known, what to expect, what remains available. When a data pipeline breaks, the affected surfaces say so plainly rather than displaying yesterday as today.

Practical implication. The degraded state of every living surface is designed at the same time as its healthy state, and reviewed with equal seriousness. “What does this look like during an outage?” is a standing design-review question.


Part 3 — The Ontology

This is the language the entire platform speaks. Getting it right matters more than any interface decision, because interfaces can be redesigned; a language, once spoken everywhere, cannot.

3.1 The triad: Objects, Events, Measures

FORGE-001 said “everything is a noun.” That was too flat. The world of an instrument contains three kinds of thing, and confusing them is the root error of every dashboard ever built:

This triad dissolves several traditional products. A dashboard is measures torn away from their objects — which is exactly why dashboards answer every question except the one being asked. A news page is events torn away from their objects. A monitoring system is measures without memory. In Forge, there is no analytics section, no news section, and no status page: there are objects, wearing their own measures and their own events.

3.2 The Objects

Sixteen canonical objects, in five layers. This list is deliberately short. Adding an object to the ontology is a constitutional act, requiring an amendment to this document — because every object added is a permanent promise of upkeep (Principle 11).

The Instrument layer — the physical machine.

The Work layer — computation as it actually happens.

The Software layer — what the machine knows how to do.

The People layer — held deliberately small, and governed by Principle 8.

The Science layer — the reason everything above exists.

The Knowledge layer.

3.3 What is deliberately not an object

3.4 The Events

Events share one shape: when, what happened, to which objects, recorded by whom. The canonical kinds:

Two properties matter more than the list. First, events have authors: maintenance recorded by the operator who performed it gives operational work a public record and the platform’s memory a human voice (§1.3). Second, the timeline is not a page — it is the set of all events, filterable by object: the history of node c042 is simply “all events touching c042”; the history of the instrument is all events, period. FORGE-001’s “time you can hold” is implemented conceptually here: the past is the event record plus archived measures; the future is reservations, planned maintenance, and clearly-labeled outlooks. Past is sharp; future is soft; both are made of the same triad.

3.5 The Relations

The relations are the grammar of the language. Each exists because a real question requires it:

Relation Connects The question it answers
member-of Node → Partition → Cluster; Person → Group Where does this belong?
generation-of Node → Hardware Generation How old is this, and with what cohort?
instance-of Module → Software Which builds of this tool exist here?
ran-on Job → Node(s) What did this hardware actually do?
submitted-under Job → Project → Group Who is accountable for this work?
used Job → Module(s) What does real usage of this software look like?
reserves Reservation → Partition/Nodes What is the future already committed to?
produced (sparse) Job → Dataset → Publication What science did this compute become?
acknowledges Publication → Cluster/Project What has the instrument contributed to?
about Document → any object Which knowledge should arrive here?
draws-on Story → any objects What truth stands behind this narrative?
affected Event → any objects What has happened to this thing?
measured-on Measure → any object What are the readings of this thing?

Three rules govern relations. Every relation is bidirectional in the interface — if a Document is about a Module, the Module surfaces the Document. Sparse relations are legitimateproduced and acknowledges will be mostly absent for years; the design must make their absence unremarkable and their presence delightful. Relations are how users move — Principle 7’s “walkable” world is precisely this table, made visible on every object.

3.6 The rules of the ontology

  1. Permanent identity. Every object has one name and one address, forever. Objects end (a node retires, a module is removed, a project closes) but never vanish — an ended object remains visitable as historical record, clearly marked as ended. The platform never breaks a citation.
  2. One home. Every object is described in exactly one place; all other appearances are references. Two disagreeing descriptions of one thing is the cardinal data bug.
  3. The five questions. Every object’s home answers, in order: What is this? What is its state now (with age of fact)? What is its history (its events)? What are its readings (its measures)? What is it connected to (its relations)? This uniform anatomy is what makes the whole platform learnable in one visit.
  4. Private facets, single structure. Privacy (Principle 8) is enforced per facet, not by building parallel worlds. A Job’s existence and aggregate weight may be public while its owner and name are private facets. Person objects are almost entirely private facets. The structure never forks; only occlusion varies.
  5. Amendment, not accretion. New objects require amending FORGE-002 with: the questions only this object can answer, its relations, its facet classification, and its upkeep cost. New views require nothing — build freely.

Part 4 — The Worlds of Project Forge

The worlds are not sections and not a menu. They are regions of the ontology — neighborhoods in one connected landscape, each with its own atmosphere, sharing every road. A user crossing from one world to another should feel weather change, not pages change.

Six worlds. Notably absent: a “People world” (people are woven through everything but never browsable as a population — Principle 8 forbids a directory of researchers to wander) and an “Operations world” (operations is not a separate place; it is the Machine and the Record seen at working depth, per Principle 10).

The Machine

The Work

The Science

The Knowledge

The Ledger

The Record


Corrected by Principle 7 — search is the primary instrument of the platform, no longer claimed to be the entire interface — the ambition here can be stated precisely: the world’s best scientific search is one that returns things, not lists.

5.1 What search returns

Search never returns “results” in the web sense — ten links with excerpts, ranked by guesswork. It returns members of the ontology, wearing their real state:

The principle beneath all five: a list of pages is an admission that the platform doesn’t know what it contains. Forge knows. It contains objects, events, measures, and documents, and every answer is one of those, in its true current condition.

5.2 Ambiguity is a fork, not a failure

When a query legitimately means several things — “python” the Software, the Documents about it, your recent Jobs that used it — the platform never silently picks one and never dumps all three as a list. It shows the fork explicitly, as short labeled paths: the tool · your work with it · how to use it here. Choosing a tine takes one gesture. Ambiguity handled this way is not friction; it is the platform teaching its ontology one fork at a time. Context weights the fork — a query typed while standing on a failed job leans toward diagnosis; the same words typed on the public front lean toward the tool — but weighting only reorders the tines. It never hides them, because a system that guesses silently trains users to distrust it.

5.3 Contextual intelligence, honestly bounded

Answers arrive wearing the machine’s current condition: search for a module and the answer mentions, quietly, that its favored partition is heavy right now; search for a storage system during its maintenance window and the event stands beside the answer. This is the fusion FORGE-001 promised — knowledge, state, and memory in a single reply — and it obeys Principle 3 (every contextual fact shows its age) and Principle 11 (a contextual hint whose pipeline breaks says nothing, rather than something stale).

5.4 The answer is a place

Because every answer is an object, every answer has edges — and the edges are the discovery mechanism. Beside GROMACS: the modules that instantiate it, the documents about it, its recent usage shape. This replaces “related articles” recommendation guesswork with something better: the truth about how this thing is actually connected. Related knowledge is discovered the way it is in a good library — by looking at the shelf you were led to.

5.5 Vocabulary teaching and the honest zero

Plain language always works — nobody must learn a query syntax — but every answer displays the canonical name of what it found, so the platform gently teaches its own language. And when nothing matches, search never returns an empty page: it shows the nearest real objects, states plainly that the platform may not contain the answer, and points to where a human can be asked. An honest “we don’t know” preserves more trust than ten irrelevant results. The zero-result page is a designed place (Principle 12 in miniature), and its frequency is watched: what people seek and fail to find is the platform’s most valuable errata list.


Part 6 — The Emotional Journey

Different people arrive carrying different feelings. The platform cannot give them the same experience — but it must bring them all to the same destination.

The first-year PhD student arrives carrying fear: everyone else seems fluent, and the cluster is where you look stupid in public. The platform’s obligation is to convert fear into orientation before competence is possible: the walkable world says “here is the whole landscape, and it is finite”; the five-question anatomy of every object says “everything here can be understood the same way”; the first failed job — the moment reputations for hostility are made — is met by knowledge that arrives, not by a stack trace and silence. The student’s journey: fear → orientation → first success → the quiet realization that the instrument was built expecting them.

The experienced bioinformatician arrives carrying impatience, and fluency in three other clusters’ conventions. They will judge the platform in ninety seconds on speed, density, and whether it wastes their attention (Principle 5 is for them). Their journey is impatience → efficiency → a slower discovery: that the receipt, the outlook, and the software usage shapes give them things no cluster ever has. They become the platform’s harshest auditors of Principle 3 — and its most credible advocates.

The PI arrives carrying responsibility: a grant spent as compute, a group to answer for, reports to write. The platform owes them stewardship without surveillance — the project’s balance, burn, and aggregate shape at a glance, without turning them into a warden of their students’ nights and weekends (Principle 8 protects the group from its own leader, deliberately). Their journey: obligation → oversight → the discovery that the annual report they dreaded is largely a bookmark into the Ledger and the Record.

The HPC administrator arrives carrying the weariness of invisible work. The platform gives them something no monitoring stack ever has: authorship. The maintenance they perform becomes a public event with their name on it; the incident they resolved at 03:00 becomes part of the instrument’s honest record; the machine’s memory is partly their memoir. Their journey: weariness → recognition → custodianship of the platform’s truth, because it is now also the record of their craft.

The funding agency arrives carrying skepticism, fluent in the gap between glossy reports and reality. The platform disarms them by refusing to be glossy: the Ledger with its methods stated, incidents published unflinchingly, receipts aggregating into accountability, publications standing as the return on investment. Their journey: skepticism → scrutiny → the rarest institutional feeling — confidence that they are not being managed.

The journalist arrives carrying a deadline. They need one true, quotable, attributable thing in ninety seconds — and the platform gives it: real numbers with visible ages, a Story whose every claim descends to its source, a machine they can describe honestly because they are looking at it honestly. Their journey: hurry → a usable truth → returning without a deadline, because this is the rare institution that doesn’t require translation.

The curious citizen arrives carrying nothing — no question, no vocabulary, maybe a child’s “what’s the big computer for?” The platform owes them wonder without prerequisites: the Stories as front doors, the watchable truth of the machine at work, the freedom to descend exactly as far as curiosity carries. Their journey: idle curiosity → “I understood that” → the sense of ownership a public should feel toward its instruments.

What they must all share. Three things, without exception. No one is ever made to feel unqualified to be here — the platform never performs expertise at its reader. Everyone leaves knowing at least one more true thing than they arrived with — the platform never wastes a visit. And everyone, from the student to the minister, develops the same reflex the instrument’s own builders have: when Mjolnir’s platform says something, it is so. That reflex — trust as a habit — is the entire emotional architecture, and every principle in Part 2 exists to protect it.


Part 7 — The Living Instrument

“Mjolnir is a scientific instrument, not a computer” was FORGE-001’s founding metaphor. Here is what it commits us to, domain by domain. The test throughout: would this be true of a great telescope?

Navigation becomes orientation. Instruments are places; you know where you are standing when you use one. Every view answers “where am I, at what altitude, in which world?” — and movement follows the relations of real things (§3.5), never the org chart. You do not browse an instrument; you walk it.

Language becomes the instrument’s register: declarative, measured, exact. The platform speaks in third person about the machine and never performs enthusiasm — no “we’re excited,” no exclamation marks, no marketing verbs. Speculation is labeled as speculation, outlooks as outlooks, derived numbers as derived (Principle 3 applied to prose). Where warmth appears — and it should — it is the warmth of a good colleague’s handbook, not a brand voice. An instrument does not sell itself; it accounts for itself.

Visual identity takes its cues from instrument-making, not from tech branding: the engraved plate, the observatory at night, the calibration mark. Deep quiet surfaces; light and color spent only on meaning; typography that honors numbers as much as words; one visual grammar at every depth, because an instrument does not change costume between the visitor’s gallery and the control room (Principle 10, made visible).

Animation becomes the discipline of the needle: things move on screen only because something moved in the world, at the tempo the world actually has. A machine-room’s state drifts; it does not dance. The aurora is retired (§1.1); in its place, motion so honest that when something does move, the viewer knows it means something.

Documentation becomes the operator’s handbook of a serious instrument: generated where it describes changeable reality (Principle 9), handwritten where it conveys judgment, and physically present at the point of use (Principle 6) — the way the checklist is mounted on the instrument, not filed in another building.

Analytics becomes readings. Instruments do not have KPIs; they have measurements, with units, timestamps, methods, and error bars. Every number the platform shows is a reading from the instrument’s own record, attached to the object it describes, decomposable to its source. The word “dashboard” leaves the vocabulary; “readings” replaces it. This is not cosmetic — renaming the concept enforces the triad (§3.1).

Research stories become observations reported from the instrument: narrative craft in service of provenance, every claim standing on declared objects (draws-on, §3.2), every visualization descended from real data or framed unmistakably as illustration. The genre is closer to a great observatory’s public reports than to content marketing — and better for it.

Public communication becomes the window rather than the press office. Announcements are Events in the Record — authored, permanent, attached to what they concern — not posts that scroll away. Incidents are published with the same typography as achievements. The institution’s credibility is compounded, deliberately, by every unflattering truth it declines to hide.

Daily interaction becomes the glance culture of people who work with instruments: the morning look at the outlook, the receipt at a job’s end, the phone’s distillation on the bus. The platform is consulted like the sky, never obeyed like a feed. It waits; it does not call.

Beneath all nine domains, one behavior defines the digital instrument: it is calibrated. It states how fresh its facts are, how derived its numbers are, how uncertain its outlooks are, and what it does not know. A website persuades. An instrument reads true — and everything above is in service of reading true.


Part 8 — Looking Twenty Years Ahead

Written from 2045, when “HPC website” is a phrase requiring explanation, and infrastructure of every kind is said to follow, or fail to follow, the Forge Model.

What the Forge Model turned out to be. Historians settled on a one-sentence definition: an instrument’s public presence is a maintained ontology of objects, events, and measures, published as durable documents. Not a design style — a commitment structure. The insight that traveled was not any interface pattern but the triad itself (§3.1), which by the mid-2030s had a name in the standards literature — “the Forge schema” — and implementations for telescopes, reactors, research vessels, biobanks, and municipal water systems. It turned out that almost everything institutions struggle to communicate is an object, an event, or a measure, and that almost every institutional communication failure is one of the three torn away from the others.

What survived. The receipt, which became as ordinary in computational science as the citation — the historians’ favorite example of a small honest artifact changing a culture’s economics of attention. Show-the-age-of-every-fact, which spread from Forge into public-sector data practice generally; the timestamp beside the number is now simply what honesty looks like. Documentation-generated-from-truth, which ended the wiki era in technical institutions. Events-with-authors, which historians of labor cite as the moment operational work in computing acquired a public record — the “authored infrastructure” movement traces its origin to §3.4. The transparency gradient, adopted almost verbatim into the ethics codes of shared research infrastructure. And calm — the strange, radical discovery that an institution could be trusted because its platform never raised its voice.

What disappeared. The aurora, first of all — FORGE-002’s own §1.1 is remembered as the project’s decisive act of self-editing, and “retiring the aurora” became design-community shorthand for stripping a beloved feature that violates a principle. The weather metaphor for queues faded once genuine forecasting matured; the honest-historiography outlook it began as (§1.2) is remembered as the right bridge. Node sentimentality never returned. And the search-only interface rhetoric of FORGE-001 was quietly forgotten by everyone except historians, who note with some irony that the correction (Principle 7) proved more influential than the original provocation: “walkable and askable” is now a standard requirement in public-infrastructure procurement.

What surprised everyone. Provenance Descent — demoted in this very document to a sparse aspiration — eventually became real, but not through the platform’s own efforts. Once receipts were standard and datasets were first-class objects, journals and funders closed the loop from the other side, requiring the links Forge had merely made possible. The lesson historians draw is the one FORGE-002 gambled on: build the sockets, tolerate their emptiness, and let the ecosystem grow the wires.

The verdict of the historians of computing. Project Forge is not remembered for how it looked; screenshots of it are, frankly, understated beside its contemporaries. It is remembered for a governance invention disguised as a design project: it was the first public infrastructure to constitutionally bind itself to truth-maintenance — to treat every live surface as a promise, every fact as timestamped, every object as permanent, and every failure as a designed state. The histories give it a sentence of the kind very few artifacts earn: after Forge, an institution that decorated its readings was no longer considered merely old-fashioned. It was considered untrustworthy — because Forge had demonstrated, permanently, that the alternative was achievable.


Executive Summary — What FORGE-002 Adds Beyond FORGE-001

FORGE-001 broke the frame: not a website, but the living presence of a scientific instrument. FORGE-002 subjects that vision to scrutiny and converts it into a constitution. The decisive new content:

  1. The triad replaces the flat noun. The world of the instrument consists of Objects (visited), Events (remembered), and Measures (read) — and confusing them is the root error of every dashboard, status page, and news feed. This is the document’s most important idea, and the entire ontology (Part 3) is built on it.
  2. Sixteen objects, constitutionally guarded. A short canonical vocabulary in five layers, with explicit rules: permanent identity, one home per object, the five-question anatomy, and amendment-not-accretion. Views (dashboards, reports, queues, homepages) are deliberately not objects — objects are permanent and expensive; views are disposable and free, which is where invention safely lives.
  3. The transparency gradient. FORGE-001’s “anyone may look” was naive. The instrument is radically public; the individuals using it are not. Privacy is enforced per facet within one structure — never by building parallel worlds — protecting researchers from rivals, journalists, and their own supervisors alike.
  4. Askable and walkable. FORGE-001’s “search is the entire interface” is formally corrected. Search returns objects, not lists, with ambiguity handled as an explicit fork — but the ontology is also a legible, walkable landscape, because the people the platform most claims to welcome are those who don’t yet know what to ask.
  5. Honesty about time and upkeep. Two new load-bearing principles: every fact visibly carries its age, and every living surface is a promise whose upkeep cost must be named before it ships. Ambition is bounded by the capacity to keep promises — a smaller set of kept promises always beats a larger set of decaying ones.
  6. Failure is a designed state. The platform matters most when the machine is at its worst. Outages, broken pipelines, and empty search results are first-class design surfaces, specified alongside the healthy state — an instrument under maintenance is still an instrument.
  7. Demotions, honestly made. Provenance Descent is downgraded from foundation to sparse aspiration (build the sockets; let the ecosystem grow the wires). The aurora is retired as decoration in the costume of data. Queue “forecasts” become honest historical outlooks until real prediction can arrive with error bars. Node “biographies” become service records.
  8. The operators enter the design. Events have authors. Maintenance, incidents, and recoveries become a public, attributed record — giving operational work visibility for the first time and giving the platform’s memory a human voice.

FORGE-001 asked the world to gasp. FORGE-002’s ambition is stricter and longer-lived: that everything the platform says, at any moment, at any depth, to any reader — is so.