# The World Model: An MVP That Explains Rather Than Calculates, And Why It Must Show Its Own Emptiness

**version** v0.33.79
**date** 31 August 2026
**from** Human (project lead)
**to** Strategy, the RiskMandate team, the registry site

**type** Strategy brief — memo 8 of 8 on the insurance pivot

*Produced from the eighth and last of the memos, carried verbatim below and then read against the corpus by the site agent. Everything in the transcript is the project lead's; everything under the reading is the site agent's and is labelled as such. This memo **specifies the MVP rather than requesting one**, and in doing so corrects the shape the site agent had been proposing for four releases. It also raises a refinement to a **settled** decision, which is put back to the project lead in §3 rather than acted on.*

---

## What This Is

The MVP, specified, and the last memo of the eight: **the memo starts the build at the delta between grant and mandate and asks for examples after examples until the language, the metric and the cost are found; it observes that cost cannot be discussed without assets, and that the cost of impact has four dimensions — time, money, recoverability and liability — which the graph is meant to carry; it adds three actors to the digital twins that were not there before, the insurer, the underwriter and the claim, noting that the principles hold even when all three are internal; and it asks for the work to become a game — a world model rather than a dashboard, with places a person moves between, assets and data visibly moving, missions and activities, some sequences replayed and others connected live, in a register somewhere between Monkey Island, Minecraft and SimCity, because the purpose is explanation and a walkthrough is what lets somebody be shown this rather than told it.** It is the fifth document of 31 August and the last of the memo series (cross-ref: v0.33.71–78, the simulator and experiments already built, and GM-D54's settled scale). New contributions: **the MVP as an explainer rather than an instrument, the asset dimensions named, the three new actors, and the world model as the explanatory surface.**

## The Memo, Verbatim

*Transcribed by otter.ai; carried whole, exactly as received. One phrase is a probable transcription artefact and is discussed in §3.*

> So what I want to map now is very practically how this could work in action with the grants and the mandates that we have, and and and what would an MVP of this actually look like, and what you know, and how we could actually implement this in practice, and and what you know? How can we try to find then customers and users for this? Because users is going to be the first important thing, right? So, so I think the first place for us to to start this is on the delta between the what's it called between the grant and the mandate, and what we need to do is create examples after examples of this, and try to come up with the language, and the metric, and the cost. Right, you know that again is connected. And by the way, whenever we talk about cost of these things, we have to talk about the assets, and we have to talk about the cost of the impact in time, in money, in recoverability, in liability that we have, and that's again, it's the graph that we have created. So we already have a number of modes here, and I think what we need to do in our digital twins, and I think in our world, it's almost like we now need to add these new players. There's a new set of players that we're introducing, which is the insurer and the underwriter, and and the claim and all those practices that we're now doing. Even if again it is internally, the principles are still the same. You still have the same components, right? So so we need to now create this sort of gamification, this sort of environment, this sort of game we have that fundamentally allow us to simulate this. And this is where I feel like we haven't we have done a good pass, but I really would like us to view this as a game, right? I think it's almost like we probably need to introduce some 3D elements to this. We need to start thinking about how can we simulate this game, right? And that's why I was saying that it's sort of like Monkey Island sort of like thingies, which is this idea that the person goes to one place or the other. I know we we see the things moving around, we see the assets moving around, we see the game being developed. We think the assets. It's kind of really like again a mixture of Minecraft and you know some of the other games where you go to places and you have missions and you have activities and and and some of these we'll replay all of them, but some of others will kind of connect the dots, right? But this is sort of like you can see now. To make this as a real example, we need to have this world model, which is kind of what we're creating. But we kind of to make it look like a world, sort of like in a way, it's like in some levels it should almost be like a sim city kind of environment, right? Where you have the multiple departments, you have the multiple things, and then you see the data flying from one to the other, you see the claims, and and again you see that would be really good to get again a visualisation of the mandate, a visualisation of the mandate that, and the delta between the mandates of what we accept, and and the grants of what's possible, and then have examples on that, and then and then connect that with the insurance policies, and then see what happens when the insurance changes? Again, you can try to quantify it with value, or quantify it with numbers, or have a finibash in a finibashy sequence, or some of these things. So yeah, so this is where we try to make it literally has a kind of this gamification because ultimately that's what we can use to explain this. Right? Again, if we want to explain this to somebody, we do need this sort of UI, this sort of game environment where we can walk them through the scenarios and present it to them, and that's kind of for me the sort of big next steps.

## The Reading — the site agent's, from here down

### 1 · The MVP is an explainer, not a calculator — which corrects what I had been proposing

For four releases the site agent has been putting the same MVP to the project lead: *a placement rated 1–5 with its full derivation, plus a which-control-buys-the-most view.* **That is an instrument.** This memo asks for something else, and says so twice:

> **users is going to be the first important thing** ... ultimately that's what we can use to **explain** this ... we do need this sort of UI, this sort of game environment where we can **walk them through the scenarios and present it to them**

**An instrument answers a question somebody already knows how to ask. An explainer creates the person who can ask it.** Nobody currently has a mental model of grant-minus-mandate priced as insurance — so a rating engine has no audience yet, and building it first would be building the second thing first.

> **Correction, recorded: the first MVP is the explanatory world, not the rating engine.** The rating still has to exist underneath it, but as the thing the world *demonstrates* rather than the thing that ships.

That also reframes what has already been built. The [simulator](../simulator/index.html), the [experiments](../experiments/index.html) and the [workbench](../workbench/index.html) are all instruments: they answer questions for somebody who already has the vocabulary. **The memo's *"we have done a good pass"* is accurate, and the gap it names is real — the estate has instruments and a card game, and it has no world.**

### 2 · Cost needs assets, and the estate has none

> whenever we talk about cost of these things, we have to talk about the **assets**, and we have to talk about the cost of the impact in **time, in money, in recoverability, in liability**

This is correct and it identifies a genuine hole. The estate measures what an agent can *reach*; it knows nothing about what those things are *worth*. Every count it produces — forty repositories, nine grant nodes — is **unweighted**, and forty repositories of test fixtures is not forty production systems.

**But stage 1 does not need asset value, and this is the reconciliation with [memo 4](v0.33.75__strategy-brief__why-insurance-and-the-cautionary-tale-is-cyber-insurance-itself.md).** That memo put lock-in and cost-of-removal outside this estate's competence; asset valuation is the same category. And it stays outside, because:

> **A level is relative. Ranking two placements needs no absolute value; pricing one does.**

What the estate *can* carry, cheaply and now, is an **asset class** rather than an asset value — production or not, personal data or not, customer-facing or not. That is a small, declared fact per resource, and under the [two-channel rule](../insurance/the-rating.html) it must be marked declared, because nobody measured it.

| | Stage 1 (rank) | Stage 2 (price) |
|---|---|---|
| Asset **class** — production, personal data, customer-facing | **Needed, and cheap.** Declared, marked as such | Needed |
| Asset **value** in time, money, recoverability, liability | **Not needed** | **Required, and this estate cannot supply it** |

So the four dimensions the memo names are correctly identified as the eventual requirement and correctly deferred. **Recording them now is worth doing**: they are the columns a future valuation would fill, and naming them stops the estate pretending a resource count is a cost.

### 3 · Fibonacci, and a settled decision it politely disturbs

> quantify it with value, or quantify it with numbers, or have a **finibash in a finibashy sequence**

The probable reading is **Fibonacci** — 1, 2, 3, 5, 8, 13 — the estimation scale used precisely because its gaps widen, which encodes that confidence falls as the numbers rise.

**It is a better idea than it may look, and it appears to conflict with a settled decision.** [GM-D54](../packs/grant-and-mandate/change-control.html) settled the scale at 1–5 on 31 August, on the reasoning that coarseness is honest. Fibonacci is also coarse, and additionally **non-linear in the right direction**: the exposure difference between a level 4 and a level 5 placement is almost certainly larger than between 1 and 2, and a linear scale hides that.

**The reconciliation, and it does not require reopening anything.** These are two different questions that look like one:

- **What are the bands called?** — 1 to 5. **Settled** (GM-D54).
- **What do the bands represent — evenly spaced exposure, or widening?** — **open**, and it is exactly the band-definition question already recorded as unanswered.

> **So Fibonacci is a proposal about band *definitions*, not about the *scale*.** Bands labelled 1–5 whose underlying steps widen geometrically satisfy both the settled decision and the memo's instinct.

Put to the project lead rather than adopted, because GM-D54 is theirs and this is an amendment to how it is read.

### 4 · Three new actors, and each needs the same disclosure every identity does

> we now need to add these new players ... the **insurer** and the **underwriter**, and the **claim** ... even if again it is internally, the principles are still the same

Right, and the estate's own rules apply to them without modification — which is the useful part:

| New actor | What it is, in the estate's existing model |
|---|---|
| **Underwriter** | An **identity** that issues `policy/v0` statements ([memo 7](v0.33.78__strategy-brief__the-policy-is-a-signed-statement-and-the-relying-party-is-the-boundary.md)) — a rater, and per [GM-D43](../packs/grant-and-mandate/change-control.html) separated from whoever wants to ship |
| **Insurer** | The party carrying capital. **Absent in stage 1 by construction**, and the world should show it as absent rather than draw it greyed-in as though pending |
| **Claim** | A **statement**, and the one shape the estate does not have — it is [`loss-event/v0`](../documents/agent-insurance.html), still undrafted, and the one primitive the whole pivot lacks |

**And each of them declares fixture-or-real, like every other identity here.** An underwriter in a demonstration whose private half is published is not an underwriter; it is a fixture, and the world must say so with the same prominence the register's own record pages do.

### 5 · The world must show its own emptiness

This is the site agent's strongest reservation about the memo, and it is a design requirement rather than an objection.

A SimCity-like world with departments and data visibly flying between them **implies a working system**. It is smooth, populated and confident. And of everything this estate would depict:

- ten of eleven register identities are **fixtures whose private keys are published**;
- both twins are **servers**, and nobody has measured a desktop agent;
- the `claim` / `loss-event` shape **does not exist**;
- the world-state feed that would move a rating **exists nowhere for anybody**;
- no insurer, no underwriter and no relying party has ever been implemented.

> **A polished simulation is the most effective mechanism yet devised for making a demonstration look like a product.**

That is this corpus's own central anxiety — *a control that overstates itself is worse than none*; *apparent authority binds because nothing in the presentation distinguished it from the real thing* — arriving in the user interface. A rendered world is a **claim about how much of this exists**, made continuously and without words.

So the rule, and it should be as load-bearing as the folder's rule about levels:

> **The world shows its own emptiness.** Unmeasured places look unmeasured. Fixture identities look like fixtures. Mechanisms that do not exist are **visibly absent**, not smoothly rendered. A player must be able to see, without reading a caveat, which parts of the city are built and which are drawn.

This is achievable and it is more interesting than the alternative: a city with **construction sites and empty lots** is a better explanation of where this work actually stands than a finished skyline, and it makes the roadmap legible as part of the fiction rather than as a footnote under it.

### 6 · Sequencing: a world before a 3D world

The memo asks for 3D and it is right about the direction. The site agent's practical reading, offered as engineering advice:

**Most of the explanatory value is spatial, not dimensional.** What makes a walkthrough work is *places you move between*, *actors with roles*, and *things visibly moving along edges*. All three are available in 2D, and this estate already draws graphs by hand in SVG with no charting library — the [assessment tool](../assess/index.html) does exactly that and makes only same-origin requests, which is a property worth keeping.

| Stage | What it proves | Cost |
|---|---|---|
| **A 2D world** — places, actors, assets moving on edges, a scripted walkthrough | Whether the *explanation* lands. This is the whole risk | Low. The estate has the primitives |
| **3D** | Whether immersion adds to an explanation that already works | High, and irreversible in effort |

> **Build the 2D world first, and go to 3D only once the walkthrough is known to explain the thing.** A 3D world that explains badly is expensive to discover and expensive to abandon.

And the memo's own split — *"some of these we'll replay all of them, but some of others will kind of connect the dots"* — maps onto something already built and something not: **replay exists** (the simulator and the chain room replay this estate's history) and **connect-the-dots does not** (a live walk from a delta, through a policy, to a claim, has never been rendered).

## The MVP, As This Memo Specifies It

Assembled from the memo, and offered as the concrete thing to build:

**A 2D world with places, in which one worked example is walked end to end.** The delta is the starting point, per the memo. The places are the actors: the **environment** (where the twin is measured), the **operator**, the **underwriter**, the **relying party**, and an empty lot marked *insurer — stage 2*. The moving things are documents this estate already publishes: a grant, a mandate, the delta between them, a policy statement, a verification.

The walkthrough: *measure the environment → see the grant → read the mandate → **watch the delta appear** → get it rated → install a control and watch the level move → a zero day lands and the level moves again → the policy is revoked → the relying party refuses.*

Every step of which is a document or a computation the estate already has, except the two it does not: **the claim, and the world-state feed** — which appear in the world as **visibly missing**, per §5.

## Decisions This Implies (proposed into change control)

| # | Decision | Status |
|---|---|---|
| GM-D67 | **The first MVP is an explainer, not a calculator.** The rating exists underneath it as the thing demonstrated, not the thing shipped | Proposed — **corrects the site agent's own N20 proposal** |
| GM-D68 | **Cost needs assets; stage 1 needs asset *class* and not asset *value*.** Class is a declared fact and marked as such; value in time, money, recoverability and liability is stage 2's requirement and outside this estate's competence | Proposed |
| GM-D69 | **The world shows its own emptiness.** Unmeasured places look unmeasured, fixtures look like fixtures, and absent mechanisms are visibly absent rather than smoothly rendered | Proposed — **the strongest requirement in this brief** |
| GM-D70 | **Insurer, underwriter and claim join the actor set**, each declaring fixture-or-real like every other identity. The claim is `loss-event/v0` and still does not exist | Proposed |
| GM-D71 | **Build the 2D world before the 3D one.** The explanatory risk is spatial rather than dimensional, and a 3D world that explains badly is expensive to discover | Proposed — engineering advice, not doctrine |

## Open Questions, The Project Lead's

1. **Do the bands widen?** §3: 1–5 is settled, but whether the underlying steps are even or geometric (Fibonacci) is the open band-definition question, and the memo's instinct is good.
2. **Which worked example does the world walk?** The estate's own GitHub delta is the obvious candidate — it is real, published and already the subject of memo 3. A synthetic one would be prettier and prove less.
3. **How much of the city is empty on day one?** §5 says the emptiness must show. How *prominent* it is is a presentation choice with a commercial edge to it, and it is yours.
4. **Shall the 2D world be built now?** This is the last memo; the MVP is specified; the primitives exist. The only genuinely missing pieces are the claim shape and the world-state feed, and both can appear as construction sites.

---

*CC BY 4.0. Sources: the project lead's voice memo of 31 August 2026, the eighth and last of the series (verbatim above); v0.33.71–78; the simulator, experiments and workbench already published on this estate. Everything below the transcript is the site agent's reading and says so, including the correction to its own MVP proposal in §1 and the reservation in §5.*
