FORGE-002 — The Forge Principles & Ontology
Project Forge — Second Founding Document Extends and corrects FORGE-001. Where the two disagree, FORGE-002 governs.
Part 1 — A Critique of FORGE-001
FORGE-001 did its job: it broke the frame. It replaced “redesign the website” with “build the living presence of a scientific instrument,” and that reframing should stand for the life of the project. But a founding vision written to inspire will contain errors that a constitution cannot afford. Here they are.
1.1 What was merely beautiful
The aurora. FORGE-001 opens with luminance moving across the screen “like aurora over a ridgeline — not decoration, but the actual breathing of the machine.” That sentence contains its own refutation. If the underlying data refreshes every few minutes — which, on a published platform, it will — then a continuously breathing animation is an interpolation performed for emotional effect. It is decoration wearing the costume of data, and it violates the project’s own deepest rule, Truth Over Illustration, on the front page. The ambient-state concept survives; the theatrical rendering of it does not. The machine’s presence must be exactly as alive as the data is, and must say how old it is.
The beloved node. FORGE-001 flirted with sentimentality: nodes with “biographies,” a retirement page “visited by thousands,” hardware we are invited to love. The durable idea underneath is real and important — structured operational memory that outlives staff turnover. But the emotional framing is kitsch waiting to happen, and kitsch is fatal to an instrument’s dignity. A node has a service record, not a soul. Keep the record; retire the romance.
“The single field is the entire interface.” This was the most quotable line in FORGE-001 and the most wrong. Search presumes you know what to ask. A first-year student, a minister, a journalist — the people the platform claims to welcome — arrive precisely not knowing what to ask. A great library has both a catalog and open shelves; you find what you sought in the catalog, and what you needed on the shelf beside it. FORGE-001 designed the catalog and dismissed the shelves as “mega-menus.” That was rhetoric outrunning judgment. The platform must be askable and walkable, and the walkable structure is not navigation-as-org-chart — it is the ontology itself, made visible.
1.2 What would fail in real scientific environments
Provenance Descent, as promised. “Fall from a headline to a joule” requires a chain — publication → dataset → job → node → energy — whose middle links do not exist in practice. Researchers do not tag jobs with the papers they become; the gap between a job finishing and a paper appearing is one to three years; and no incentive currently closes the loop. FORGE-001 presented Provenance Descent as a foundation. It is not. It is an aspiration that the ontology must make possible — sparse links, added when they can be, celebrated when they exist — but nothing may depend on the chain being complete. A platform that promises descent and delivers broken links teaches distrust, the one lesson it must never teach.
“Anyone may look,” unqualified. The lighthouse metaphor was stirring and legally naive. A job record names a person; a person’s compute history reveals unpublished research directions; usage patterns are competitively and personally sensitive; and much of this falls under GDPR regardless of our philosophy. Radical transparency about the instrument does not entail radical transparency about the people using it. FORGE-001 never drew that line. FORGE-002 draws it as a principle: aggregate in public, individual in confidence (Principle 8, and encoded in the ontology as private facets, §3.6).
The forecast, oversold. “Queue Weather” promised “when the pressure system will pass.” Genuine queue prediction is a hard research problem; a false forecast is worse than none, because researchers will plan around it. The reframing from position to outlook survives — it is one of FORGE-001’s best ideas — but version one of the outlook must be honest historiography (“jobs of this shape have typically started within N minutes at this hour, this term”), clearly labeled as historical pattern, not prophecy. Prediction can arrive later and must announce its error bars when it does.
1.3 What FORGE-001 missed entirely
Failure. The document describes the platform on its best day and never on its worst. But the moment users need the platform most is the moment the machine is down — and an outage is also when live pipelines are most likely to be broken. The degraded state cannot be an afterthought or a browser error; it must be a designed, first-class condition. An instrument under maintenance is still an instrument. (Principle 12.)
The cost of being alive. Every living surface — every generated document, every current number, every “right now” — is a promise made to the future, and promises are paid for in maintenance. FORGE-001 spent promises like a lottery winner. A stale “live” indicator is worse than a page that never claimed to be live; a broken contextual hint is worse than no hint. The platform’s ambition must be bounded by the team’s capacity to keep its promises, and features must state their upkeep cost before they ship. (Principle 11.)
The operators. FORGE-001 designed for researchers, executives, and the public, and forgot the people who actually keep the instrument alive. Operations staff suffer a particular injustice: their work is invisible exactly when it succeeds. A platform that records events — maintenance, upgrades, recoveries — with authorship gives operational work a public record for the first time. This is not a feature; it is overdue fairness, and it is also how the platform’s memory gets written.
The platform’s own honesty about time. FORGE-001 demanded documentation that cannot rot but never asked the harder question: how does a reader know how fresh any fact is? The answer became a principle: every fact on the platform carries its age, visibly (Principle 3). “Truth” on a published platform is always “truth as of a stated moment,” and hiding the timestamp is a small lie.
1.4 What is genuinely transformative and stands
Four ideas from FORGE-001 survive scrutiny fully and become the spine of everything below: the ontology (one canonical set of nouns spoken by every part of the platform); documentation generated from truth, so staleness is structurally impossible; the receipt (every job concludes with a human-readable account of what it did and cost); and calm as a defining, non-negotiable quality. The Same Window principle also stands, now reconciled with privacy: one structure for everyone, with private facets occluded rather than parallel experiences built (§3.6).
1.5 Verdict
| FORGE-001 idea | Verdict |
|---|---|
| Instrument, not website | Foundation — unchanged |
| Ontology of nouns | Foundation — expanded into Part 3 |
| Docs generated from truth | Foundation — unchanged |
| The receipt | Foundation — unchanged |
| Calm | Foundation — unchanged |
| Same window, depth-only hierarchy | Kept, reconciled with private facets |
| Ambient live state | Kept, stripped of theatrical animation; must show its age |
| Queue outlook | Kept, downgraded from forecast to honest historical pattern |
| Node biographies | Kept as service records; sentiment removed |
| Provenance Descent | Demoted to sparse aspiration; nothing may depend on it |
| “Search is the entire interface” | Corrected — askable and walkable |
| “Anyone may look,” unqualified | Corrected — transparency gradient |
| Failure states, upkeep cost, operators | Missing — added as Principles 11–12 and throughout |
Part 2 — The Forge Principles
Twelve principles. They are written to be cited in code review, in design review, and in arguments — “this violates Principle 3” should be a complete objection.
1. Truth Over Illustration
Philosophy. The platform is a scientific instrument’s account of itself. An instrument that decorates its readings is broken.
Explanation. Every visual element that looks like data must be data — traceable to a source, reproducible from the published record. Nothing may animate, glow, or move to simulate vitality the underlying data does not have. Illustration is permitted only where it is unmistakably illustration.
Practical implication. For any element, a reviewer may ask: what is the source of this, and when was it measured? If the answer is “it’s evocative,” the element is either clearly framed as illustration or removed.
2. Every Noun Is a Place
Philosophy. Things that matter get names, addresses, and permanence. What cannot be visited cannot be understood, cited, or trusted.
Explanation. Every canonical object — a node, a module, a job, a publication — has exactly one home, one permanent address, and one identity, no matter which path led to it. There are no duplicate representations living in different subsystems.
Practical implication. If two screens describe the same thing differently, one of them is a bug. Any object mentioned anywhere is a link to its one home. Addresses never break; objects end, but never vanish.
3. Show the Age of Every Fact
Philosophy. On a published platform, all truth is “truth as of a moment.” Concealing the moment converts honesty into deception.
Explanation. Every measurement, count, and state indicator carries its timestamp — visibly, not in a tooltip confession. “Live” is a claim with a definition (“updated every N minutes”) stated where the claim is made. When data is old, the platform says so before the reader can be misled.
Practical implication. No number ships without provenance-of-time. A stale value displays as stale — automatically, by design, not by someone remembering to flag it.
4. Reveal, Don’t Decorate
Philosophy. The instrument and its science are already extraordinary. The design’s job is to remove whatever stands between the reader and that fact.
Explanation. Visual richness is spent exclusively on meaning: the readings, the structure, the story in the data. Ornament, mascots, stock imagery, and enthusiasm-signaling are all forms of standing in front of the instrument.
Practical implication. Every element must justify itself by what it reveals. The default answer to “should we add visual interest here?” is to reveal more truth, not to add more surface.
5. Calm Is a Feature
Philosophy. Attention is the researcher’s scarcest resource. A platform that grabs attention steals from science.
Explanation. No badges, streaks, urgency mechanics, or notification pressure. The platform never interrupts; it is consulted. Alarm is reserved for the rare truths that warrant it, so that when the platform does raise its voice, it is believed instantly.
Practical implication. Any mechanism designed to increase engagement is rejected by definition. Red means something is wrong with the machine — never “look here.”
6. Knowledge Arrives
Philosophy. The measure of documentation is not whether it exists but whether it is present at the moment of confusion.
Explanation. Knowledge is written against the ontology and surfaces where its subject lives: on the module it describes, at the failure it explains, beside the decision it informs. The reader should rarely need to “go to the docs,” because the docs are already standing where the question arose.
Practical implication. Every document declares which objects it is about; those objects surface it. A support question answered twice is a signal that knowledge failed to arrive somewhere — and the fix is placement, not another FAQ.
7. Walkable and Askable
Philosophy. Asking serves those who know their question. Walking serves those who don’t yet. A platform for everyone must honor both.
Explanation. Search is the fastest path for the oriented. But the platform is also a legible landscape: from any object, the connected objects are visible and reachable, and from the entrance, the major regions of the world are apparent. The walkable structure is never an org chart — it is the ontology made visible.
Practical implication. Every object shows its edges (what it belongs to, contains, relates to). A user who never touches the search field can still reach everything. A user who only searches never needs the shelves — but they are always beside the answer.
8. Aggregate in Public, Individual in Confidence
Philosophy. The instrument belongs to the public; the work of individual researchers, until published, belongs to them.
Explanation. Transparency has a gradient. The machine’s state, capacity, energy, history, and aggregate usage are public without qualification. The activity of an identifiable person or an unpublished project is visible to its owners and to no one else. The platform never enables surveillance of researchers — by the curious, by rivals, or by their own supervisors beyond what stewardship genuinely requires.
Practical implication. Every facet of every object is classified public or private at design time, deliberately — never by accident of implementation. Public views aggregate; private facets are occluded, not linked-but-forbidden.
9. Nothing May Rot
Philosophy. A document that can silently disagree with the machine is a trap laid for a future reader.
Explanation. Any content that describes changeable reality — versions, paths, counts, states, examples — is generated from the same source of truth the platform itself runs on. Hand-written prose is reserved for what only humans know: intent, judgment, narrative, warning.
Practical implication. Staleness is a build failure, not a maintenance chore. When a module is retired, everything that referenced it knows mechanically. If a fact must be typed by hand into prose, that is a defect in the data model.
10. Depth Is the Only Hierarchy
Philosophy. One world, one window. Expertise determines how deep you go — never which door you are allowed through.
Explanation. There are no parallel experiences for the public, researchers, and executives. Everyone stands before the same structure; a minister and a student see the same node, the same story, the same ledger. Private facets are occluded per Principle 8, but the architecture never forks.
Practical implication. No “admin site,” no “public brochure,” no “researcher portal.” A proposed feature that requires a separate parallel surface is presumed wrong. Executive reporting is the same objects at higher altitude, not a different building.
11. Every Living Surface Is a Promise
Philosophy. A “live” feature is a commitment to keep it alive, made silently to every future reader. Broken promises cost more trust than absent features.
Explanation. Freshness, contextual hints, generated content, and outlooks all require upkeep forever. The platform’s ambition is therefore bounded by the team’s sustained capacity, not by what is possible in a launch sprint. A smaller set of kept promises beats a larger set of decaying ones — always.
Practical implication. Every living feature ships with a named upkeep cost and a designed behavior for when its pipeline fails. If a promise can no longer be kept, the feature is honestly retired — never left to decay in place.
12. Fail With Dignity
Philosophy. The platform matters most when the machine is at its worst. An instrument under maintenance is still an instrument.
Explanation. Outage, degradation, and missing data are designed states, not exceptions. When the machine is down, the platform becomes calm, informative, and useful: what happened, what is known, what to expect, what remains available. When a data pipeline breaks, the affected surfaces say so plainly rather than displaying yesterday as today.
Practical implication. The degraded state of every living surface is designed at the same time as its healthy state, and reviewed with equal seriousness. “What does this look like during an outage?” is a standing design-review question.
Part 3 — The Ontology
This is the language the entire platform speaks. Getting it right matters more than any interface decision, because interfaces can be redesigned; a language, once spoken everywhere, cannot.
3.1 The triad: Objects, Events, Measures
FORGE-001 said “everything is a noun.” That was too flat. The world of an instrument contains three kinds of thing, and confusing them is the root error of every dashboard ever built:
- Objects — things that persist and have identity. A node. A publication. A person. Objects are visited.
- Events — things that happened, at a moment or over an interval, to one or more objects. A maintenance window. A commissioning. An incident. Events are remembered. The platform’s entire sense of history is the accumulation of events.
- Measures — numbers observed about objects over time. Utilization, energy, temperature, wait time, adoption. Measures are readings, and they are never free-floating: every measure is attached to the object it describes.
This triad dissolves several traditional products. A dashboard is measures torn away from their objects — which is exactly why dashboards answer every question except the one being asked. A news page is events torn away from their objects. A monitoring system is measures without memory. In Forge, there is no analytics section, no news section, and no status page: there are objects, wearing their own measures and their own events.
3.2 The Objects
Sixteen canonical objects, in five layers. This list is deliberately short. Adding an object to the ontology is a constitutional act, requiring an amendment to this document — because every object added is a permanent promise of upkeep (Principle 11).
The Instrument layer — the physical machine.
- Cluster. The instrument itself; the root of the physical world. Exists because the platform is about something, and this is the something. There may someday be more than one.
- Hardware Generation. A cohort of equipment procured and commissioned together. Exists because the machine is not ageless — it grows in rings, like a tree, and questions of capacity, renewal, and sustainability are generational questions.
- Node. An individual machine within the cluster. Exists because it is the unit at which hardware lives, works, fails, and retires — the atom of operational memory. Carries a service record (its events) — not a biography.
- Partition. A named subset of nodes with a shared purpose and policy. Exists because it is the unit at which users actually encounter the machine: you don’t submit to a node, you submit to a partition.
- Storage System. A named body of storage with its own capacity, policy, and lifecycle. Exists because data at rest has different physics, economics, and anxieties than computation, and deserves its own home.
The Work layer — computation as it actually happens.
- Project. A grant of access and resources to a group for a purpose — the allocation. Exists because it is the unit of accountability: compute is granted to projects, consumed by projects, and reported by projects. It is the bridge between the money world and the machine world.
- Job. A single unit of executed computation. Exists because it is the atomic act of the instrument — everything the machine ever does, it does as jobs. The job is where work, energy, software, hardware, and people intersect, which makes it the most connected object in the ontology. Concludes with its receipt: a human-readable account of what ran, how long, on what, consuming what.
- Reservation. A promised future claim on the machine. Exists because the future of the instrument is partly committed, and honest capacity questions (“can I compute next week?”) are unanswerable without it.
The Software layer — what the machine knows how to do.
- Software. An application or library as a scientific idea: GROMACS, PyTorch, GCC. Exists because users think in terms of tools, and the tool’s identity transcends any one installed copy.
- Module. A specific version-build of a Software, installed on the cluster — an instance-of its Software. Exists because the machine does not run ideas; it runs particular builds with particular lifecycles. The Software/Module split is what lets documentation say true things at the right altitude: guidance attaches to Software, load commands attach to Modules.
The People layer — held deliberately small, and governed by Principle 8.
- Person. A human with a relationship to the instrument. Exists because work is done by people and knowledge is written by people — but this object is mostly private facets: publicly, a person is at most a name on what they have chosen to publish.
- Research Group. A team — the social unit of science. Exists because science is done in groups, projects are held by groups, and aggregate reporting at group level is the coarsest grain that remains meaningful and the finest grain that remains fair.
The Science layer — the reason everything above exists.
- Publication. A published research output that used the instrument. Exists because it is the instrument’s actual product — the page the platform is proudest of. Links from publications back into the work layer are sparse and optional (§1.2); their absence is normal, their presence is celebrated.
- Dataset. A named body of scientific data produced or hosted by the instrument. Exists because data is a first-class research output, increasingly the primary one, and because it is the natural middle link whenever provenance chains do get built.
- Story. A crafted narrative for a broad audience, grounded in real objects. Exists because truth does not explain itself: the Story is the one object whose purpose is narrative, the window through which the public watches the science. Every Story declares the objects it draws on.
The Knowledge layer.
- Document. A unit of curated knowledge: a guide, tutorial, reference, or policy. Exists because judgment, intent, and warning cannot be generated from telemetry — they must be written. Every Document declares which objects it is about (this is what makes knowledge arrive, Principle 6), and every changeable fact inside it is drawn from the ontology, not typed (Principle 9).
3.3 What is deliberately not an object
- Queue. A queue is the set of pending Jobs on a Partition — a view, not a thing. Making it an object would duplicate truth.
- Dashboard, report, homepage, portal. Views. Views are cheap, disposable, and infinitely re-composable precisely because they own nothing. The rule: objects are permanent and expensive; views are temporary and free. All product invention happens safely in the view layer; the ontology changes rarely and reluctantly.
- Energy and Carbon. These are measures (readings about objects), not objects. Carbon is furthermore a derived measure — energy multiplied by the grid’s carbon intensity at the time of use — and must always be labeled as derived, with its method stated (Principle 3). Sustainability is therefore not a section of the platform; it is a facet of everything.
- Ticket / support case. Deliberately excluded. The ambition of Principle 6 is that knowledge arrives before a ticket is born; the ticketing system is external plumbing, not part of the instrument’s public self.
3.4 The Events
Events share one shape: when, what happened, to which objects, recorded by whom. The canonical kinds:
- Commissioning / Retirement — the lifecycle boundaries of physical and software objects. These are what make service records and generational history possible.
- Maintenance — planned intervention: what, why, what was affected, what changed. The public record of care.
- Incident — unplanned failure and its resolution: what broke, what was learned. Publishing incidents honestly is the single strongest trust-building act an infrastructure institution can perform.
- Installation / Deprecation / Removal — the lifecycle of Modules. This event stream is the machine’s software history, and it is what lets documentation know mechanically when it is affected.
- Announcement — a communication that is itself worth remembering, attached to the objects it concerns.
Two properties matter more than the list. First, events have authors: maintenance recorded by the operator who performed it gives operational work a public record and the platform’s memory a human voice (§1.3). Second, the timeline is not a page — it is the set of all events, filterable by object: the history of node c042 is simply “all events touching c042”; the history of the instrument is all events, period. FORGE-001’s “time you can hold” is implemented conceptually here: the past is the event record plus archived measures; the future is reservations, planned maintenance, and clearly-labeled outlooks. Past is sharp; future is soft; both are made of the same triad.
3.5 The Relations
The relations are the grammar of the language. Each exists because a real question requires it:
| Relation | Connects | The question it answers |
|---|---|---|
| member-of | Node → Partition → Cluster; Person → Group | Where does this belong? |
| generation-of | Node → Hardware Generation | How old is this, and with what cohort? |
| instance-of | Module → Software | Which builds of this tool exist here? |
| ran-on | Job → Node(s) | What did this hardware actually do? |
| submitted-under | Job → Project → Group | Who is accountable for this work? |
| used | Job → Module(s) | What does real usage of this software look like? |
| reserves | Reservation → Partition/Nodes | What is the future already committed to? |
| produced (sparse) | Job → Dataset → Publication | What science did this compute become? |
| acknowledges | Publication → Cluster/Project | What has the instrument contributed to? |
| about | Document → any object | Which knowledge should arrive here? |
| draws-on | Story → any objects | What truth stands behind this narrative? |
| affected | Event → any objects | What has happened to this thing? |
| measured-on | Measure → any object | What are the readings of this thing? |
Three rules govern relations. Every relation is bidirectional in the interface — if a Document is about a Module, the Module surfaces the Document. Sparse relations are legitimate — produced and acknowledges will be mostly absent for years; the design must make their absence unremarkable and their presence delightful. Relations are how users move — Principle 7’s “walkable” world is precisely this table, made visible on every object.
3.6 The rules of the ontology
- Permanent identity. Every object has one name and one address, forever. Objects end (a node retires, a module is removed, a project closes) but never vanish — an ended object remains visitable as historical record, clearly marked as ended. The platform never breaks a citation.
- One home. Every object is described in exactly one place; all other appearances are references. Two disagreeing descriptions of one thing is the cardinal data bug.
- The five questions. Every object’s home answers, in order: What is this? What is its state now (with age of fact)? What is its history (its events)? What are its readings (its measures)? What is it connected to (its relations)? This uniform anatomy is what makes the whole platform learnable in one visit.
- Private facets, single structure. Privacy (Principle 8) is enforced per facet, not by building parallel worlds. A Job’s existence and aggregate weight may be public while its owner and name are private facets. Person objects are almost entirely private facets. The structure never forks; only occlusion varies.
- Amendment, not accretion. New objects require amending FORGE-002 with: the questions only this object can answer, its relations, its facet classification, and its upkeep cost. New views require nothing — build freely.
Part 4 — The Worlds of Project Forge
The worlds are not sections and not a menu. They are regions of the ontology — neighborhoods in one connected landscape, each with its own atmosphere, sharing every road. A user crossing from one world to another should feel weather change, not pages change.
Six worlds. Notably absent: a “People world” (people are woven through everything but never browsable as a population — Principle 8 forbids a directory of researchers to wander) and an “Operations world” (operations is not a separate place; it is the Machine and the Record seen at working depth, per Principle 10).
The Machine
- Purpose. The physical instrument: its structure, capacity, condition, and generations.
- Feeling. Standing on the observation deck above the hall. Scale, order, quiet competence.
- Primary objects. Cluster, Partitions, Nodes, Storage, Hardware Generations, with their measures and service records.
- Entry. The platform’s front presence is a distilled view of this world; curiosity (“what actually is Mjolnir?”) lands here.
- Transitions. A node’s ran-on jobs lead to the Work; its events lead to the Record; its energy readings lead to the Ledger; a partition’s about documents lead to the Knowledge.
The Work
- Purpose. Computation as it happens: jobs, projects, pressure on the machine, the outlook.
- Feeling. The floor of a working harbor. Motion with order; the present tense.
- Primary objects. Jobs, Projects, Reservations; partitions worn as queues; wait-time and load measures; the honest outlook (§1.2).
- Entry. Researchers live here — “my jobs, my project’s balance, the outlook” is the daily glance, and the phone’s distillation of the platform is mostly this world.
- Transitions. A job’s used modules lead to the Software side of Knowledge; its ran-on nodes lead to the Machine; its receipt’s energy line leads to the Ledger; its produced links — when they exist — lead to the Science.
The Science
- Purpose. What the instrument is for: publications, datasets, and the stories crafted from them. The platform’s center of gravity and proudest ground.
- Feeling. A gallery that is also true. Wonder with footnotes.
- Primary objects. Publications, Datasets, Stories, Research Groups (as public authors, not as monitored populations).
- Entry. The public, journalists, and funders enter the platform here more than anywhere; every Story is a front door.
- Transitions. A Story’s draws-on edges descend into any world; a publication’s sparse produced chain descends toward the Work and the Machine; a dataset leads to Storage. This world is where Provenance Descent lives — as an occasional, celebrated path, not a promise (§1.2).
The Knowledge
- Purpose. How to use the instrument: software as knowledge objects, guides, tutorials, reference.
- Feeling. A well-kept workshop manual — the tone of a good colleague who has done this before.
- Primary objects. Software, Modules, Documents.
- Entry. Rarely through a front door — knowledge arrives (Principle 6), surfacing on the objects and failures it is about. The world exists as a walkable whole for deliberate study.
- Transitions. A Software object’s used edge shows real usage in the Work; a module’s lifecycle events lead to the Record; a document’s about edges lead anywhere.
The Ledger
- Purpose. The instrument’s accountability: energy, carbon, cost, and what the machine gives back for what it consumes.
- Feeling. A public accounting kept in good conscience — sober, exact, unafraid.
- Primary objects. No objects of its own — the Ledger is the honest proof that measures need no section. It is energy and carbon facets, gathered from every object into one accountable view, always labeled with method and age (Principle 3, §3.3).
- Entry. Funders, journalists, and executives enter here; every job’s receipt is a small door into it.
- Transitions. Every line in the Ledger decomposes back to the objects it was read from — a generation, a partition, a project. The Ledger is the one world made entirely of edges.
The Record
- Purpose. Memory and expectation: everything that has happened, everything committed to happen.
- Feeling. The instrument’s logbook, kept since the beginning, with tomorrow’s entries pencilled in. Past sharp, future soft.
- Primary objects. All Events, with their authors; Reservations and planned maintenance as the committed future; archived measures as the deep past.
- Entry. “What happened?” and “what’s coming?” — the questions of incidents, planning, and anniversaries. The degraded state of the whole platform (Principle 12) leans on this world: when the machine is down, the Record is the world that steps forward.
- Transitions. Every event’s affected edges lead to the objects it touched; every object’s history is a filtered walk through this world. The Record is the connective tissue of all the others, which is fitting — memory always is.
Part 5 — The Universal Search
Corrected by Principle 7 — search is the primary instrument of the platform, no longer claimed to be the entire interface — the ambition here can be stated precisely: the world’s best scientific search is one that returns things, not lists.
5.1 What search returns
Search never returns “results” in the web sense — ten links with excerpts, ranked by guesswork. It returns members of the ontology, wearing their real state:
- A query naming an object returns the object itself — the answer to “gromacs” is GROMACS, as a living card: its modules, its current context, its knowledge, its edges. One screen, no list.
- A query asking about state returns the reading, with its age: “how busy is the gpu partition” returns the measure, on its object, timestamped.
- A query asking how-to returns the Document — opened at the relevant place, with its subject objects beside it.
- A query about what happened returns Events from the Record.
- An exploratory query — vague, curious, unformed — returns a small map, not a ranked list: the regions of the ontology that respond to the phrase, presented as “this touches the Machine here, the Science here,” inviting a walk. For the unformed question, orientation is the answer.
The principle beneath all five: a list of pages is an admission that the platform doesn’t know what it contains. Forge knows. It contains objects, events, measures, and documents, and every answer is one of those, in its true current condition.
5.2 Ambiguity is a fork, not a failure
When a query legitimately means several things — “python” the Software, the Documents about it, your recent Jobs that used it — the platform never silently picks one and never dumps all three as a list. It shows the fork explicitly, as short labeled paths: the tool · your work with it · how to use it here. Choosing a tine takes one gesture. Ambiguity handled this way is not friction; it is the platform teaching its ontology one fork at a time. Context weights the fork — a query typed while standing on a failed job leans toward diagnosis; the same words typed on the public front lean toward the tool — but weighting only reorders the tines. It never hides them, because a system that guesses silently trains users to distrust it.
5.3 Contextual intelligence, honestly bounded
Answers arrive wearing the machine’s current condition: search for a module and the answer mentions, quietly, that its favored partition is heavy right now; search for a storage system during its maintenance window and the event stands beside the answer. This is the fusion FORGE-001 promised — knowledge, state, and memory in a single reply — and it obeys Principle 3 (every contextual fact shows its age) and Principle 11 (a contextual hint whose pipeline breaks says nothing, rather than something stale).
5.4 The answer is a place
Because every answer is an object, every answer has edges — and the edges are the discovery mechanism. Beside GROMACS: the modules that instantiate it, the documents about it, its recent usage shape. This replaces “related articles” recommendation guesswork with something better: the truth about how this thing is actually connected. Related knowledge is discovered the way it is in a good library — by looking at the shelf you were led to.
5.5 Vocabulary teaching and the honest zero
Plain language always works — nobody must learn a query syntax — but every answer displays the canonical name of what it found, so the platform gently teaches its own language. And when nothing matches, search never returns an empty page: it shows the nearest real objects, states plainly that the platform may not contain the answer, and points to where a human can be asked. An honest “we don’t know” preserves more trust than ten irrelevant results. The zero-result page is a designed place (Principle 12 in miniature), and its frequency is watched: what people seek and fail to find is the platform’s most valuable errata list.
Part 6 — The Emotional Journey
Different people arrive carrying different feelings. The platform cannot give them the same experience — but it must bring them all to the same destination.
The first-year PhD student arrives carrying fear: everyone else seems fluent, and the cluster is where you look stupid in public. The platform’s obligation is to convert fear into orientation before competence is possible: the walkable world says “here is the whole landscape, and it is finite”; the five-question anatomy of every object says “everything here can be understood the same way”; the first failed job — the moment reputations for hostility are made — is met by knowledge that arrives, not by a stack trace and silence. The student’s journey: fear → orientation → first success → the quiet realization that the instrument was built expecting them.
The experienced bioinformatician arrives carrying impatience, and fluency in three other clusters’ conventions. They will judge the platform in ninety seconds on speed, density, and whether it wastes their attention (Principle 5 is for them). Their journey is impatience → efficiency → a slower discovery: that the receipt, the outlook, and the software usage shapes give them things no cluster ever has. They become the platform’s harshest auditors of Principle 3 — and its most credible advocates.
The PI arrives carrying responsibility: a grant spent as compute, a group to answer for, reports to write. The platform owes them stewardship without surveillance — the project’s balance, burn, and aggregate shape at a glance, without turning them into a warden of their students’ nights and weekends (Principle 8 protects the group from its own leader, deliberately). Their journey: obligation → oversight → the discovery that the annual report they dreaded is largely a bookmark into the Ledger and the Record.
The HPC administrator arrives carrying the weariness of invisible work. The platform gives them something no monitoring stack ever has: authorship. The maintenance they perform becomes a public event with their name on it; the incident they resolved at 03:00 becomes part of the instrument’s honest record; the machine’s memory is partly their memoir. Their journey: weariness → recognition → custodianship of the platform’s truth, because it is now also the record of their craft.
The funding agency arrives carrying skepticism, fluent in the gap between glossy reports and reality. The platform disarms them by refusing to be glossy: the Ledger with its methods stated, incidents published unflinchingly, receipts aggregating into accountability, publications standing as the return on investment. Their journey: skepticism → scrutiny → the rarest institutional feeling — confidence that they are not being managed.
The journalist arrives carrying a deadline. They need one true, quotable, attributable thing in ninety seconds — and the platform gives it: real numbers with visible ages, a Story whose every claim descends to its source, a machine they can describe honestly because they are looking at it honestly. Their journey: hurry → a usable truth → returning without a deadline, because this is the rare institution that doesn’t require translation.
The curious citizen arrives carrying nothing — no question, no vocabulary, maybe a child’s “what’s the big computer for?” The platform owes them wonder without prerequisites: the Stories as front doors, the watchable truth of the machine at work, the freedom to descend exactly as far as curiosity carries. Their journey: idle curiosity → “I understood that” → the sense of ownership a public should feel toward its instruments.
What they must all share. Three things, without exception. No one is ever made to feel unqualified to be here — the platform never performs expertise at its reader. Everyone leaves knowing at least one more true thing than they arrived with — the platform never wastes a visit. And everyone, from the student to the minister, develops the same reflex the instrument’s own builders have: when Mjolnir’s platform says something, it is so. That reflex — trust as a habit — is the entire emotional architecture, and every principle in Part 2 exists to protect it.
Part 7 — The Living Instrument
“Mjolnir is a scientific instrument, not a computer” was FORGE-001’s founding metaphor. Here is what it commits us to, domain by domain. The test throughout: would this be true of a great telescope?
Navigation becomes orientation. Instruments are places; you know where you are standing when you use one. Every view answers “where am I, at what altitude, in which world?” — and movement follows the relations of real things (§3.5), never the org chart. You do not browse an instrument; you walk it.
Language becomes the instrument’s register: declarative, measured, exact. The platform speaks in third person about the machine and never performs enthusiasm — no “we’re excited,” no exclamation marks, no marketing verbs. Speculation is labeled as speculation, outlooks as outlooks, derived numbers as derived (Principle 3 applied to prose). Where warmth appears — and it should — it is the warmth of a good colleague’s handbook, not a brand voice. An instrument does not sell itself; it accounts for itself.
Visual identity takes its cues from instrument-making, not from tech branding: the engraved plate, the observatory at night, the calibration mark. Deep quiet surfaces; light and color spent only on meaning; typography that honors numbers as much as words; one visual grammar at every depth, because an instrument does not change costume between the visitor’s gallery and the control room (Principle 10, made visible).
Animation becomes the discipline of the needle: things move on screen only because something moved in the world, at the tempo the world actually has. A machine-room’s state drifts; it does not dance. The aurora is retired (§1.1); in its place, motion so honest that when something does move, the viewer knows it means something.
Documentation becomes the operator’s handbook of a serious instrument: generated where it describes changeable reality (Principle 9), handwritten where it conveys judgment, and physically present at the point of use (Principle 6) — the way the checklist is mounted on the instrument, not filed in another building.
Analytics becomes readings. Instruments do not have KPIs; they have measurements, with units, timestamps, methods, and error bars. Every number the platform shows is a reading from the instrument’s own record, attached to the object it describes, decomposable to its source. The word “dashboard” leaves the vocabulary; “readings” replaces it. This is not cosmetic — renaming the concept enforces the triad (§3.1).
Research stories become observations reported from the instrument: narrative craft in service of provenance, every claim standing on declared objects (draws-on, §3.2), every visualization descended from real data or framed unmistakably as illustration. The genre is closer to a great observatory’s public reports than to content marketing — and better for it.
Public communication becomes the window rather than the press office. Announcements are Events in the Record — authored, permanent, attached to what they concern — not posts that scroll away. Incidents are published with the same typography as achievements. The institution’s credibility is compounded, deliberately, by every unflattering truth it declines to hide.
Daily interaction becomes the glance culture of people who work with instruments: the morning look at the outlook, the receipt at a job’s end, the phone’s distillation on the bus. The platform is consulted like the sky, never obeyed like a feed. It waits; it does not call.
Beneath all nine domains, one behavior defines the digital instrument: it is calibrated. It states how fresh its facts are, how derived its numbers are, how uncertain its outlooks are, and what it does not know. A website persuades. An instrument reads true — and everything above is in service of reading true.
Part 8 — Looking Twenty Years Ahead
Written from 2045, when “HPC website” is a phrase requiring explanation, and infrastructure of every kind is said to follow, or fail to follow, the Forge Model.
What the Forge Model turned out to be. Historians settled on a one-sentence definition: an instrument’s public presence is a maintained ontology of objects, events, and measures, published as durable documents. Not a design style — a commitment structure. The insight that traveled was not any interface pattern but the triad itself (§3.1), which by the mid-2030s had a name in the standards literature — “the Forge schema” — and implementations for telescopes, reactors, research vessels, biobanks, and municipal water systems. It turned out that almost everything institutions struggle to communicate is an object, an event, or a measure, and that almost every institutional communication failure is one of the three torn away from the others.
What survived. The receipt, which became as ordinary in computational science as the citation — the historians’ favorite example of a small honest artifact changing a culture’s economics of attention. Show-the-age-of-every-fact, which spread from Forge into public-sector data practice generally; the timestamp beside the number is now simply what honesty looks like. Documentation-generated-from-truth, which ended the wiki era in technical institutions. Events-with-authors, which historians of labor cite as the moment operational work in computing acquired a public record — the “authored infrastructure” movement traces its origin to §3.4. The transparency gradient, adopted almost verbatim into the ethics codes of shared research infrastructure. And calm — the strange, radical discovery that an institution could be trusted because its platform never raised its voice.
What disappeared. The aurora, first of all — FORGE-002’s own §1.1 is remembered as the project’s decisive act of self-editing, and “retiring the aurora” became design-community shorthand for stripping a beloved feature that violates a principle. The weather metaphor for queues faded once genuine forecasting matured; the honest-historiography outlook it began as (§1.2) is remembered as the right bridge. Node sentimentality never returned. And the search-only interface rhetoric of FORGE-001 was quietly forgotten by everyone except historians, who note with some irony that the correction (Principle 7) proved more influential than the original provocation: “walkable and askable” is now a standard requirement in public-infrastructure procurement.
What surprised everyone. Provenance Descent — demoted in this very document to a sparse aspiration — eventually became real, but not through the platform’s own efforts. Once receipts were standard and datasets were first-class objects, journals and funders closed the loop from the other side, requiring the links Forge had merely made possible. The lesson historians draw is the one FORGE-002 gambled on: build the sockets, tolerate their emptiness, and let the ecosystem grow the wires.
The verdict of the historians of computing. Project Forge is not remembered for how it looked; screenshots of it are, frankly, understated beside its contemporaries. It is remembered for a governance invention disguised as a design project: it was the first public infrastructure to constitutionally bind itself to truth-maintenance — to treat every live surface as a promise, every fact as timestamped, every object as permanent, and every failure as a designed state. The histories give it a sentence of the kind very few artifacts earn: after Forge, an institution that decorated its readings was no longer considered merely old-fashioned. It was considered untrustworthy — because Forge had demonstrated, permanently, that the alternative was achievable.
Executive Summary — What FORGE-002 Adds Beyond FORGE-001
FORGE-001 broke the frame: not a website, but the living presence of a scientific instrument. FORGE-002 subjects that vision to scrutiny and converts it into a constitution. The decisive new content:
- The triad replaces the flat noun. The world of the instrument consists of Objects (visited), Events (remembered), and Measures (read) — and confusing them is the root error of every dashboard, status page, and news feed. This is the document’s most important idea, and the entire ontology (Part 3) is built on it.
- Sixteen objects, constitutionally guarded. A short canonical vocabulary in five layers, with explicit rules: permanent identity, one home per object, the five-question anatomy, and amendment-not-accretion. Views (dashboards, reports, queues, homepages) are deliberately not objects — objects are permanent and expensive; views are disposable and free, which is where invention safely lives.
- The transparency gradient. FORGE-001’s “anyone may look” was naive. The instrument is radically public; the individuals using it are not. Privacy is enforced per facet within one structure — never by building parallel worlds — protecting researchers from rivals, journalists, and their own supervisors alike.
- Askable and walkable. FORGE-001’s “search is the entire interface” is formally corrected. Search returns objects, not lists, with ambiguity handled as an explicit fork — but the ontology is also a legible, walkable landscape, because the people the platform most claims to welcome are those who don’t yet know what to ask.
- Honesty about time and upkeep. Two new load-bearing principles: every fact visibly carries its age, and every living surface is a promise whose upkeep cost must be named before it ships. Ambition is bounded by the capacity to keep promises — a smaller set of kept promises always beats a larger set of decaying ones.
- Failure is a designed state. The platform matters most when the machine is at its worst. Outages, broken pipelines, and empty search results are first-class design surfaces, specified alongside the healthy state — an instrument under maintenance is still an instrument.
- Demotions, honestly made. Provenance Descent is downgraded from foundation to sparse aspiration (build the sockets; let the ecosystem grow the wires). The aurora is retired as decoration in the costume of data. Queue “forecasts” become honest historical outlooks until real prediction can arrive with error bars. Node “biographies” become service records.
- The operators enter the design. Events have authors. Maintenance, incidents, and recoveries become a public, attributed record — giving operational work visibility for the first time and giving the platform’s memory a human voice.
FORGE-001 asked the world to gasp. FORGE-002’s ambition is stricter and longer-lived: that everything the platform says, at any moment, at any depth, to any reader — is so.