Governance

WIM separates mission, architectural authority, implementation, assurance, research evidence, publication, and product experience so that no single surface can silently redefine the program.

Mission

The Mission states why WIM exists: to make AI-assisted work accountable to persistent, inspectable reality. It establishes direction without replacing the Specification or proving that WIM works.

Specification

The owner-approved, frozen WIM Specification v1.0 defines what WIM is. Implementation work operates within it. A code mismatch is an implementation defect or compatibility debt; it does not amend the Specification.

A change to WIM's meaning requires an explicit Architecture Review, owner approval, a linked decision record, a new version, and updates to affected constitutional and research artifacts.

Trust Invariants

Trust Invariants define permanent, implementation-independent properties that WIM must never violate. They are subordinate to the Specification and carry stable identifiers that connect architectural authority to enforcement, regression, Red Team attack, and independent audit evidence.

Insufficient evidence is not a pass. Adoption of the invariants defines an assurance target; it does not certify an implementation.

Reference Implementation

The canonical repository is the designated home of the reference implementation. The current implementation has not passed its assurance gate. Code earns authority through reproducible behavior and scoped evidence, not through naming, ambition, a passing test suite, or a successful demonstration. Implementation cannot silently redefine the Specification or Trust Invariants.

Assurance hierarchy

  1. Mission
  2. Specification
  3. Trust Invariants
  4. Implementation
  5. Verification
  6. Red Team
  7. Independent Audit
  8. Candidate
  9. Release

When Red Team or audit finds a failure, remediation and a fresh Red Team review are required before the sequence can continue.

Red Team reviews

Red Team attempts to falsify the implementation at trust boundaries. Accepted findings require bounded remediation and permanent regressions, followed by a fresh Red Team review. Red Team is not replaced by the builder's own verification.

Independent audits

Independent audit evaluates an exact candidate after internal verification and Red Team. Audit evidence must be independently retrievable and tied to immutable candidate identity. A failed audit remains part of the record; it is not rewritten by later remediation.

Research integrity

Technical merge authority, empirical-claim authority, and publication authority are distinct. A merged experiment does not approve its protocol. A completed result does not approve its interpretation. An approved interpretation does not authorize public disclosure.

Research preserves failed, null, contradicted, and leakage-invalidated work. Tests establish software behavior; they do not establish scientific claims. Unknown is preferred over unsupported certainty.

Reality as authority

WIM maintains models of reality; it does not define reality. Evidence, interpretation, confidence, and truth remain distinct. Reality is the final authority, and the system must remain corrigible when observations or outcomes contradict its current model.

No repository, website, product, company, model, implementation, or founder is allowed to become the authority over reality.