Begin with an Actual Action
This appendix supplies a recording structure, not ready-made answers. Select an action that will actually be taken or forgone, and state its object, deadline, authority, and observable result. A simple action can use a reduced form; expand it for actions with high consequences or multiple stages.
Mark blanks as unknown, not occurred, or not applicable. These differ: an unknown needs material, something not occurred cannot enter the actual ledger, and something not applicable does not belong to the object. Do not invent probabilities or costs to fill a table.
Every person, amount, labor period, device, and reading in D17 is fictional. The template may be transferred; the case thresholds may not be copied as rules.
Action Object Card
| Field | Record | Check |
|---|---|---|
| Object identifier | Unique number and version | Does it overwrite an old object? |
| Actors | Who may propose, execute, stop, and authorize | Has knowing been mistaken for having authority? |
| Action | What specifically happens in this round | Does it include a later stage? |
| Result | What fact counts as realization | Can it be jointly adjudicated? |
| Window | Start, deadline, and boundary | Is lateness being backfilled? |
| State | Candidate, adopted, executing, paused, closed | Does it match actuality? |
| Related objects | Source, prior version, subsequent version | Is every inherited item stated? |
When an object changes, first decide whether to update, recover, create another object, or archive. When the deadline has passed and the result can be adjudicated, a similar future opportunity normally needs a new identifier.
Goals and Consequences Page
List the primary pursuit first, then nonexchangeable constraints and auxiliary goals. Income, fulfillment, relationship, learning, and capacity may stand side by side without forced conversion into one unit.
| Action | Possible gain | Direct loss | Opportunity occupation | Hard-to-recover consequence | Next stopping point |
|---|---|---|---|---|---|
| Take no action | |||||
| Minimum inquiry | |||||
| Staged commitment | |||||
| Full commitment |
Separate historical consumption, present resources awaiting disposition, and future increments. Past inputs enter review and cannot authorize continuation alone; reusable results enter future comparison according to a specific plan and validation conditions.
Resource Ledger
For each resource, preserve at least quantity, use, authority, and time. Balance categories must be mutually exclusive, and conditional inflows do not enter currently available resources.
| Category | Quantity | Current state | Release condition | Protected object |
|---|---|---|---|---|
| Total | Confirmed | — | — | |
| Committed | Cannot be scheduled twice | Completion or formal cancellation | Existing obligations | |
| Used | Historical | Does not return | Review | |
| Protected | Exists but is not authorized | Preset recovery circumstance | Survival floor | |
| Unallocated | Not authorized | New action passes | Capacity to adjust | |
| Conditional inflow | Not received | Trigger condition occurs | Excluded from balance |
Recalculate time slots by period; unused slots do not accumulate across periods. The existence of cash does not make its use free, and an expected expense has not yet occurred.
Stage Gates
For each stage, record inputs, checks, passing conditions, released resources, failure action, and responsible person. Passing authorizes only the next explicit action.
| Stage | Required material | Passing condition | May release | Action if not passed | Validity period |
|---|---|---|---|---|---|
| Condition confirmation | |||||
| Local probe | |||||
| Formal execution | |||||
| Handoff acceptance |
Do not occupy resources secretly in an earlier stage merely because a later stage is expected to need them. Recheck entry readings, budgets, and authority at the corresponding time.
Shared Exposure and Joint Results
List people, equipment, materials, time, versions, authority, and the external window. When different paths share a node, do not assume independence merely because the number of projects has increased.
For two results A and B, a four-cell table can preserve both occur, only A, only B, and neither occurs. Without frequency material, retain event states in the cells and leave probabilities blank.
Record correlation, common causes, and resource competition separately. A shared node indicates a possible relation; it does not prove that failure has occurred.
Changes and Thresholds Page
The fact layer preserves original times and readings; the explanation layer lists competing mechanisms; the rule layer states a threshold's source, inclusion relation, version, and action after crossing; the consequence layer records pauses, deadlines, and resource changes.
| Threshold | Proposer | Protected object | Applicable version | Boundary inclusion | Action after crossing |
|---|---|---|---|---|---|
| Quality gate | |||||
| Cash floor | |||||
| Capacity margin | |||||
| Time deadline |
Label an illustrative curve as not fitted. Finite endpoints cannot automatically determine the actual crossing point, and a discontinuity in an action rule cannot impersonate an abrupt change in a natural process.
Path Ledger
| Node and time | Grounds at the time | Irrecoverable consumption | Remaining resources | Commitment formed | Material obtained | Branch changed |
|---|---|---|---|---|---|---|
Workflow order becomes a path relation only when it changes authority, resources, technical state, information, or deadline. Use different arrows for authority, resources, evidence, and candidate mechanisms.
A counterfactual changes one node only and states how far the inference reaches. Do not manufacture an unobserved result with a complete alternative story.
Exit Card
| Check | Time | Passing condition | Action if not passed | Responsible person | Resource disposition | Notice |
|---|---|---|---|---|---|---|
| Cash | Stop | |||||
| Capacity | Stop or reduce | |||||
| Version | Pause and create separately | |||||
| Technical gate | Stop or conduct a bounded recheck | |||||
| Window | Archive |
A bounded recheck needs an object, reason, number of attempts, and method of adjudication. A pause needs a deadline and default action. Any deviation first triggers a pause; form the new version before resources are released.
Five-Layer Result Page
| Layer | Question to assess | Must not be replaced by |
|---|---|---|
| Judgment | Did the material available at the time support adjudication? | The final outcome's desirability |
| Plan | Were steps, interfaces, buffers, and exits sufficient? | The existence of documentation |
| Execution | Did actual action conform to the version? | Character labels |
| Observation | Were critical facts found and preserved? | Number of problems |
| Endpoint | Did the original event occur? | Learning or consolation |
A good result cannot pardon process deviation, and a bad result does not prove every layer wrong. Rescuers, rescue costs, and favorable initial states belong in attribution.
Recovery Path
For repeated failures, first define the sequence of the same result, then separate direct failure types. A count triggers a check; it does not automatically generate a trend or probability.
Recovery checks at least settlement of old objects, the survival floor, remaining resources, repair of critical interfaces, a new-period inventory, and conditions for reentry. Completed recovery grants only eligibility to assess.
A cooling-off period needs a purpose and endpoint. A rollback restores only a local configuration; it cannot return time, cash, and relationships to the past.
Handoff Summary
The summary must answer at least these questions: What is the current active object? Which old objects are closed? How are cash and capacity classified? Which actions are prohibited? At which layer did the latest failure occur? To what range have controls been validated? Which mechanisms remain unknown? What is the first step after a new message arrives?
Test it with a person who did not participate and receives no oral supplementation. If that person cannot determine whether money may be spent, a message sent, or an old result updated, deny authorization by default and write the needed clarification back into the template.
Final D17 Reconciliation
Cash: opening balance twelve; first payment inflow three; one unit spent at each of G1, the first segment of G2, V3 review, and V3 execution; closing balance eleven. The final payment of three was not received, and no refund remains pending.
First action period: of ten slots, six existing, one G1, one first-segment G2, one Thursday investigation, and one remaining. Next period: seven existing, one V3 review, one V3 execution, and one unused recovery slot. The following period is inventoried anew as six existing and four unscheduled.
Objects: original R17 result Y = 0; D17-A0 completed; V2 and V3 both undelivered and archived; no V4. The E17-1 epistemic question remains open, and production authority is closed.
Do not conflate: V3's correct archive package is not a late delivery; T22 success is not production success; the one-slot ceiling for internal capability building is not authorized work; three unallocated units are not unconditionally spendable.
Final Check Before Use
- Are the object and window still the same?
- Have goals, hard constraints, and indicators been mixed?
- Are history, current resources, and future increments separated?
- Have conditional inflows, unreleased slots, or candidate paths been counted early?
- Does a threshold come from a rule or from natural material?
- Are failure types and shared exposure preserved separately?
- Do exit, recovery, and handoff each have a default action?
- Can a new holder adjudicate the state without oral memory?
If any question cannot be answered, keep the related action unauthorized. A record does not exist to urge action onward. It lets action receive results and continue to be revised under limited conditions.