Skip to content

Appendix C — Glossary

Appendix C — Glossary

Normative


Purpose

This glossary defines every canonical term used in the Mars® Protocol. Where a term is first defined in a specific section, the defining section is noted and the defining section’s text governs; this glossary is the normative index of those definitions. Any divergence between a glossary entry and the defining section is a defect to be repaired by updating the glossary to conform to the defining section — conformance may not be claimed under the weaker of two divergent statements.

Terms are listed alphabetically. Cross-references to other glossary terms are indicated in bold.


Instructions for population

Populate by extracting defined terms from §00 (overview) first, then §01 through §03-iv in order. A term belongs in this glossary if: (a) it is defined explicitly in the normative text with a “is defined as” or equivalent construction, or (b) it is a proper-noun term of art used across more than one section without re-definition. Common English words used in their ordinary sense are not glossary entries.

Target: 80–120 entries, 1–4 lines per entry.


A

Actuation anchor(§02c §4) The outbound boundary object produced by the integrated analysis layer, satisfying seven structural invariants, that gates downstream actuation. A compliant actuation anchor is a prerequisite for any actuation act governed by the Mars® architecture.

Admissibility verdict(§02e) The tri-state pre-invocation verdict produced by the pre-invocation governance layer: ADMIT, REFUSE, or REFER. A REFUSE or REFER at the pre-invocation boundary stops or diverts the invocation; the model does not execute.

AIGP(§02e §9) Causum’s preferred pre-invocation governance specification, owned by Kanjani AI Research and commercially licensed exclusively through Causum. Governs the pre-invocation phase of an AI invocation, where it is the fail gate, and its own post-invocation stages over the completed invocation; composes with Mars® across the structural boundary at model output (§02e, §02e appendix). The boundary partitions phases, not protocols — both specifications operate on both sides of it.

Analysis battery(§02a) The governed set of analytical methods applied to the order-typed lift of a target artifact. The battery operates across three layers (pre-IR, IR-level, post-IR) and produces a typed verdict and recomputation witness chain.

Aspect(§01) A domain dimension produced by order decomposition. Aspects are the output type of the order decomposition operation; each aspect corresponds to a distinct functional kind of expression in the domain.

Aspect-keyed query library(§03-i) The query library produced by semantic binding, indexed by domain aspect. Each entry in the library is a typed query parameterized by aspect, governing what may be retrieved from a bound data source.


B

Benchmark consumer interface(§03-iv) The formally specified interface through which a governed benchmark produced by §03-iv is consumed by an evaluation system. The interface is defined in the normative text of §03-iv.

Boundary-closure attestation(§01) The attestation produced at the conclusion of domain modeling that certifies the formal domain model is closed — i.e., that every term used in the model is defined within the model or in a registered prior model, and that no undefined term escapes the boundary.


C

Capitoline Triad — The three foundational protocol components of the Mars® architecture: Juno (§01, domain modeling), Jupiter (§02, analysis), and Minerva (§03, artifacts). The Triad is not a pipeline; it is a dependency graph. Each member produces artifacts that the subsequent members consume as governed inputs.

Conformance certificate(§02b §2) The terminal artifact of governed analysis, satisfying nine structural invariants. A conformance certificate is the instrument on which all downstream enforcement gates depend. It is independently re-derivable from retained evidence without internal system access.

Composition gate(§02a §3a) The battery execution discipline governing a composition invocation: ordered pass execution under declared ordering constraints, per-pass audit emission, and a mechanical tri-state status-determination rule. Each declared pass is a typed check emitting a PassRecord; the declared pass set is open and non-limiting (B6), so the gate is defined by the composition discipline rather than by any fixed number of stages.


D

Data gap resolution lifecycle(§03-iii) The formally specified lifecycle governing the detection, recording, and resolution of gaps in the evidence gathered during §03-iii operations.

Delta-attestation(§02b §5) The amendment-governance primitive for all registered artifacts. A delta-attestation record has seven required fields and is produced whenever a registered artifact is amended. The delta-attestation lifecycle governs the full lifecycle from amendment proposal through versioned re-discharge.

Domain aspect — See Aspect.

Domain model — See Formal domain model.

Domain specification(§01) The intermediate record produced from any combination of input modes (§01 §2), comprising at minimum a domain identifier and a set of verified examples. The domain specification is the input to all three constitutive operations.

DSL(§01) The domain-specific language defined in §01 §6, through which variants are declared and accessed as a typed surface. The DSL is the mechanism that makes variant consistency formally evaluable.


E

Evidence-gathering verification(§03-iii) The operation that verifies that evidence gathered for a governed invocation is grounded — i.e., that every claim in the gathered evidence is traceable to a source admitted by the semantic binding layer and retrievable via the aspect-keyed query library.


F

Formal domain model(§01) The primary artifact produced by Juno (§01). It is multi-order, multi-perspective, and multi-variant, constituted through order decomposition, perspective constitution, variant declaration, and higher-order synthesis. All downstream Mars® operations consume the formal domain model as a fixed governing reference.

Forensic record(§02c) The record produced by the elevated analysis layer (AIGP) for each admissibility verdict. The forensic record is retained as part of the recomputation witness chain and is required for independent re-derivation of the admissibility verdict.


G

Governed artifact — An artifact produced by a Minerva (§03) operation under a valid conformance certificate. A governed artifact carries a recomputation witness that enables independent re-derivation of the production verdict.

Governed benchmark(§03-iv) A benchmark produced by the governed benchmark generation mechanism of §03-iv. A governed benchmark satisfies the benchmark lifecycle requirements and exposes the benchmark consumer interface.

Governed round-trip — The closed loop from a declared named authority through domain modeling (Juno), analysis and conformance certification (Jupiter), and evidence-gathering and artifact production (Minerva) — terminating in an independently re-derivable terminal conformance certificate. The governed round-trip is the defining unit of Mars® governance.

Grounded conformance verdict(§03-iii) A conformance verdict produced by §03-iii that is grounded — i.e., every sub-verdict is traceable to a source admitted by the semantic binding layer. An ungrounded conformance verdict is non-conformant regardless of its content.


H

Higher-order synthesis(§01) The fourth constitutive operation of domain modeling. It operates over any selection of order outputs, perspective outputs, variant outputs, and prior higher-order outputs — at any granularity, in any combination, to any depth — to derive nontrivial relationships and findings. Its input selection is declared per synthesis act and is unconstrained.


I

Impera(§03-i) The embedded data source client class defined by the semantic binding layer. A data source is an embedded source when its content is stored as vectors in an embedding space and retrieval produces ranked results by a declared similarity or proximity measure. Mars® requires that the client satisfy the connect/encode/decode contract and commit to retrieval at the subchunk level — the minimal semantically coherent span within a chunk containing the specific supporting evidence. The Causum Impera project is the reference implementation (available from Causum; repository reference gitlab.com/causum/impera — an informative pointer, not a normative dependency: the normative requirement is the contract, not any implementation), governing federation across vector stores, embedding model management, metadata co-indexing, and subchunk-level retrieval accuracy. Licensees may implement the contract independently provided the subchunk accuracy commitment and structural contracts are met. See also Pymnemon.

Independent inspector — A person or entity with (a) no contractual relationship with the licensee, (b) no access to the licensee’s internal systems or source code, and (c) sufficient technical competence to execute external-observation differential testing. The independent inspector is the canonical verifier for all numbered properties in this specification.

Inbound boundary(§02c §2) The boundary governing what may enter the model. The inbound boundary is enforced by the non-language-provenance anchor (seven structural invariants) and its downstream verification gate (§02c §2.3, five refusal conditions).

Integrated boundary(§02c) The combined inbound boundary mechanism defined in §02c, comprising the non-language-provenance anchor and the ordered composition gate.


J

Jupiter — The second member of the Capitoline Triad. Jupiter governs law and conformance. See §02 Jupiter.

Juno — The first member of the Capitoline Triad. Juno governs authority and produces the formal domain model. See §01 Juno.


K

KB lifecycle(§03-ii) The formally specified lifecycle governing creation, versioning, and retirement of a knowledge base constructed under §03-ii.

Knowledge base(§03-ii) The co-indexed bidirectional store of aspect-typed primitives produced by §03-ii. The knowledge base is governed by the formal domain model and the semantic binding layer; every entry is traceable to an admitted source.


M

Mars® — The formal governance architecture for AI invocations specified in this document. Mars® is a registered trademark of Causum.

Minerva — The third member of the Capitoline Triad. Minerva governs knowledge and evidence. See §03 Minerva.

Model governance(§02c) The mechanism within the elevated analysis layer (AIGP) that governs which models may execute a governed invocation, under what conditions, and with what retained witness.

Multi-locus gap report(§03-i) The report produced by the semantic binding layer when the aspect-keyed query library identifies gaps — locations in the domain model for which no admitted data source provides evidence. The multi-locus gap report is a required input to the data gap resolution lifecycle (§03-iii).


N

Named authority(§02c §7) An organization, jurisdiction, or individual whose governing specification declares the permitted intents, prohibited acts, and in-scope/out-of-scope classification for an invocation class. Named-authority standing is established by a four-field named-authority record.

Named-authority record(§02c §7) The eight-field record establishing named-authority standing. A valid named-authority record is a prerequisite for any governed invocation.

Non-language-provenance anchor(§02c) The inbound boundary object, satisfying seven structural invariants, that certifies the non-linguistic provenance of the governing specification being applied at the inbound boundary. The non-language-provenance anchor is a prerequisite for composition gate entry.


O

Order(§01) A functional dimension of the formal domain model, produced by order decomposition. Each order corresponds to a distinct kind of expression: description, constraint, dynamic, interaction, and so on. The set of orders is domain-specific and declared during domain specification.

Order decomposition(§01) The first constitutive operation of domain modeling. It decomposes the domain along its functional dimensions and produces domain aspects as output.

Order-typed lift(§02a) The transformation of a target artifact (e.g., a prompt) into a representation typed by the order structure of the formal domain model. The order-typed lift is the input to the analysis battery.

Outbound boundary(§02c §4) The boundary governing what may exit the model as a governed output. The outbound boundary is enforced by the actuation anchor and the downstream actuation gate.


P

Perspective(§01) A stakeholder lens through which the relational structure of the formal domain model is constituted. A perspective is not a filter on an otherwise-complete model; it is generative — the relational structure of the model results from analysis through each stakeholder’s lens.

Perspective constitution(§01) The second constitutive operation of domain modeling. It constitutes the relational structure of the model through stakeholder lenses and produces perspective-structured relational output.

Procedural-confidence derivation(§02c) The mechanism within the integrated boundary layer that derives a typed confidence score from the composition gate outputs. The procedural-confidence score is a required field in the scope-of-applicability certificate.

Pymnemon(§03-i) The non-embedded data source client class defined by the semantic binding layer. A data source is a non-embedded source when its content is stored in structured, human-interpretable form — rows, documents, key-value pairs, object records, graph nodes and edges — and retrieval is by structured query returning typed, discrete results. Mars® requires that the client satisfy the connect/traverse/query contract: a stable declared connection interface, the ability to enumerate source structure (schemas, tables, collections, fields, and types), and execution of structured queries over content returning typed results. Non-limiting admitted store types include relational (SQL), document (NoSQL), key-value, object, and graph. The Causum Pymnemon project is the reference implementation (available from Causum; repository reference gitlab.com/causum/pymnemon — an informative pointer, not a normative dependency: the normative requirement is the contract, not any implementation). Licensees may implement the contract independently provided conformance with the connect/traverse/query contract is maintained. See also Impera.


R

R1, R2(§02c) The two enforcement constraints produced by the integrated boundary layer. R1 and R2 are typed constraints; failure to satisfy either at the inbound boundary produces a typed rejection and gates invocation.

R3, R4, R5(§02c §4) The three enforcement constraints produced by the actuation layer. R3, R4, and R5 govern outbound actuation; failure to satisfy any produces a typed rejection and gates downstream actuation.

Recomputation witness(§02a, §03-iii) The chain of retained evidence from which every verdict produced by the analysis battery or evidence-gathering verification can be independently re-derived by a qualified inspector. The recomputation witness has two required components as defined in §03-iii.

Registered artifact — An artifact entered into the specification registry under the Mars® architecture. All registered artifacts are subject to the delta-attestation lifecycle (§02b §5).

Reinforcement loop discipline(§03-iii) The constraints governing the symmetric reinforcement loop within §03-iii. The discipline prevents runaway reinforcement and ensures that the reinforcement loop terminates in a grounded verdict.


S

Scope-of-applicability certificate(§02c) The certificate produced by the integrated boundary layer certifying that a given governing specification is applicable to the invocation class in scope.

Semantic binding(§03-i) The operation that characterizes a data source and admits it for use in the knowledge-base and evidence-gathering operations of §03-ii and §03-iii. A data source that has not been admitted by semantic binding may not be used as an evidence source.

Soundness anchor(§02a §3a) The structural basis on which a governed result is independently reproducible by a qualified inspector without access to internal deployment state. An anchor names what a result is re-derived from; it is a structural object, not an assertion of correctness. A model-internal signal — logit, token probability, or any value computed inside a forward pass — may never serve as an anchor. Composed results inherit their constituents’ anchors rather than asserting soundness at the composed level (§01 §6, D43); results depending on acts across a structural boundary inherit the retained witnesses for those acts as an anchor segment (§02e §5).

Specification registry — The registry of governing specifications operating under the Mars® architecture. Each entry is a registered artifact and is subject to the delta-attestation lifecycle.

Sycophancy gate(§02c) The mechanism within the elevated analysis layer (AIGP) that detects and blocks admissibility for invocations where the model’s prior output history indicates sycophantic drift from the governing specification.

Symbolic lift(§02a) The transformation of a target artifact into a symbolic intermediate representation (IR) governed by the order-shape contract. The symbolic lift is the first stage of the analysis battery pipeline.

Symmetric reinforcement(§03-iii) The reinforcement mechanism within §03-iii that ensures that evidence gathered for a governed invocation reinforces the governing specification symmetrically — i.e., that no evidence is admitted that would selectively reinforce one order while suppressing another.


T

Terminal conformance certificate(§03-iii) The conformance certificate produced at the conclusion of evidence-gathering verification. It is the final instrument in the governed round-trip and is required for governed artifact production (§03-iv).

Triad — See Capitoline Triad.


V

Variant(§01) A semantically equivalent but expressionally distinct rendering of a model element, produced during domain construction as a first-class structural property of the formal domain model.

Variant consistency map(§01) The map recording known-equivalent correspondences between variants of the same model element. The variant consistency map is the calibration artifact for relational quantification mechanisms.

Variant declaration(§01) The third constitutive operation of domain modeling. It produces variants of model elements and records them in the variant consistency map.


W

Witness retention(§02c) The requirement that the forensic record and associated recomputation witness produced by the elevated analysis layer be retained for the full retention period specified in the license agreement.