02 — Vault topology
Summary
Policies, ledger and room: three vaults with three writers, kept separate now so that the key split later is a file change rather than a migration. The capability tiers each buys, the blind acknowledgement as a load-bearing property rather than tidiness, and the pilot relaxation applied line by line: one key set, a folder of files that are only ever added standing in for the lane, detection by sgit's history in place of prevention. Every file shape and folder name is the lane's, so the drain runbook is the only step that does not exist yet. The published lane limits are designed against, the unstated anchors question is assumed conservatively and marked, and retention is proposed.
Key concepts
- The blind acknowledgement — an insured cannot learn its remaining cover by writing
- A folder for a lane — IE-D3: the same schema, a different location
- No anchors, no writers — assumed, marked, to be confirmed by one write at step 7
Key ideas
- A write key grants purge, so the ledger's writer must not hold one.
- The room holds nothing the other two vaults do not, so it can always be regenerated.
- One thousand pending files per token makes draining an obligation.
Read the document
📄 Pack document · 02__vault-topology.md · rendered from the raw markdown (the source of truth)