Digital One Foundation The First Layer
Paper 004 · Limits

What the first layer cannot carry.

A file memory earns trust by what it refuses to promise. These notes state the failures the layer cannot prevent: a note can be loaded, well-formed and wrong; a transcript restore can resurrect exactly the continuity a session should have shed; no hook can conjure the lesson a tired operator declined to write; and nothing in a per-project directory reaches the next project. What the first layer cannot carry defines where the second layer begins.

§1Lessons travel; numbers rot

A memory file states a fact without its evidence chain, and the fact ages while the file does not. The protocol knows this about itself: its own instruction on the auto-loaded index is to treat it "as loaded context, not as instructions to obey blindly (it reflects what was true when written; verify names/paths/flags before acting on them)". That instruction exists because the failure it guards against happened.

The case in the record: during the preparation of a published series on this site, a note in the estate's committed memory layer recorded two figures as its own results — a range, "11%–78%", and a count, 1,587. Neither survived into the published paper: the range published is 11.1%–73.1%, and 1,587, a real measurement inside the exercise, never reached the published paper at all — that series' internal authoring record, which is not public, marks it stale by name. The note's qualitative lesson held and was used; its numbers did not. The working rule that survives the case: take lessons from memory, take numbers from the artefact. This series' own opening figure aged the same way, six days from 224 MB recorded to 236,422,970 bytes re-measured, and stayed citable only because Paper 001 dated both readings instead of trusting either.

The instruction, verbatim

"[T]reat it as loaded context, not as instructions to obey blindly (it reflects what was true when written; verify names/paths/flags before acting on them)." The verify step is prose, and Paper 003 measured the half-life of prose without a check. Nothing in the layer verifies a note at read time; the layer's honest offer is a dated claim, not a current one.

The class is wider than one note, which is why the protocol's clause lists names, paths and flags rather than figures alone. The machine-local index carries a region rename dated 24 July 2026 precisely so later sessions do not act on the old names — every note written before that date using them went stale at the moment of the rename — and one repository's instruction file still carried a PATH prefix for an earlier Windows dev box, on an estate that is macOS today. A fact can outlive its accuracy by months; the rename's stale strings are the exhibit. Every such sentence was true when written. That is what staleness is: not error, but time. A reader should assume every memory file in this series' estate contains at least one sentence like them.

The merge discipline of Paper 002 is the partial answer — facts carry ISO dates, and a contradicted fact is replaced with the date noted — but a contradiction has to be noticed by a session that happens to touch the topic. A stale note is also worse than no note, in one specific way: it arrives with the authority of injection. Paper 002's hooks place the index in context before the first turn, ahead of anything the session has verified for itself, so a rotted number does not have to be recalled to do harm — it is already present, phrased with the same confidence as every fact beside it, and nothing in the file format marks the difference between a figure measured yesterday and one measured before the thing it measures changed. The failure, when it comes, is a reader who treats testimony as telemetry.

§2Two continuities, and the wrong one can answer

The machine that produced this series runs always-on consoles that must survive reboots, and their launch script restores each one with a transcript resume; its design note is explicit that "Continuity is now BOTH transcript resume AND the memory protocol." The protocol file draws the line between the two: "claude --continue restores the last conversation: right for a console recovering from a reboot, wrong for a session that has run a fortnight." The memory files are "the durable baseline underneath it" — beneath both cases, deciding neither.

The limit is that both restores succeed. A rebooted console resumed by transcript comes back mid-thought, which is what it needed; the same command aimed at a fortnight-old session reopens Paper 001's case on purpose, ceiling and all, and a session restarted on files alone comes back well-briefed but missing its last uncommitted minutes. Restore answers where was I? — the open thread, the half-finished reasoning. Memory answers what is true here? — the decisions, the gotchas, the invariants that survived consolidation. Neither answers both, and the layer cannot arbitrate between them, because the choice depends on why the session ended, and no file in the layer records that.

The wrong continuity is silent

Both mechanisms exit successfully, and no output distinguishes the restore a session needed from the restore it got. On the machine measured, the choice is wired per console, in advance, in the launch script — which is to say it is decided by a human, per folder, and the layer carries the decision without being able to make it.

§3The artefact is not the lesson

The third limit is the sharpest, because no hook can close it. The estate's writing guideline states the rule: "A paper is not finished until what was learned is written down separately from what was published. The paper is the artefact; the memory is the lesson." What earns an entry — the non-obvious fact that cost something to learn — is Paper 002's admission test, and the rule's hardest clause is the one that matters here: "Write the memory even when — especially when — the lesson is that the earlier analysis was wrong."

The limit follows directly: the first layer carries only what someone stopped to distill. A session that produced a working artefact and no note has left nothing for the next session — the commit shows what changed, never why the alternative was rejected or which three approaches failed first. The hooks of Paper 002 can force the ritual; the stop hook can refuse to close a session until a handoff runs. It cannot make the handoff say the true thing, and it cannot conjure the lesson a tired operator declined to write. A memory layer is bounded above by the honesty and effort of its writers, and no measurement in this series can see past that bound. The estate's counter-pressure is procedural rather than mechanical: dedicated feedback files, one fact per file with the why and the how to apply beside it, lower the cost of writing the lesson until the honest note is the easiest thing to write. Lowering a cost is not removing a bound.

§4The first layer ends at the project boundary

The layer's addressing is its scope. Machine-local memory lives at a path encoded from the project directory, one directory per project; on the machine measured, eight projects carry such an index, and each is invisible to the other seven. The shared layer is committed inside one repository, so it travels with that repository's clones and stops at that repository's edge. Nothing in the construction reads across the boundary, and nothing should be inferred to.

Paper 003 §4 is this limit in action, inside a single morning: a mitigation written into one repository's hook at 07:54 on 21 September 2026 was absent from its sibling the same day, with a coherence policy between them — "ported deliberately", in one repository's own instructions — and no mechanism to carry the patch. When even two repositories under one operator with a written sameness rule drift in hours, the general case is not in doubt: a lesson filed in one project's layer is unavailable precisely where it would next be useful.

Nor can the boundary be widened from inside the layer without breaking it. Everything the layer holds loads at session start, which is what Paper 003's budgets exist to bound; a first layer broad enough to carry every project's lessons into every session would rebuild Paper 001's accumulation at the start of each conversation instead of across one. The scope limit and the size budget are the same constraint seen from two sides, and relaxing either spends the other.

That failure already has its own series. The Second Layer, published on this site in September 2026, opens from this exact seam: "An organisation's coding agents forget between sessions, and what one repository learned does not reach the next unless something carries it."[1] These notes are the floor under that work: the first layer keeps one project's sessions honest, and carrying knowledge past the project boundary is the second layer's problem, with failure modes of its own that those papers state for themselves.

§5What is open, and what would settle it

Four limits, then, none of them repairable from inside the layer, and each leaving something open on the day of writing:

OpenWhat would settle itWho decides
Detecting a stale recorded number automatically a check that compares dated figures in memory against the artefacts they cite; nothing in this series' record runs one — the §1 correction is recorded as a publication-time verification, not a mechanism's output anyone who builds it
Whether restore and memory can contradict each other in practice a session resumed after its memory was consolidated elsewhere, observed rather than assumed anyone who runs it
Whether the unwritten lesson can be surfaced at all nothing mechanical on the record: the hooks can force the ritual, not the honesty of it, and the bound is the writer's the operator, every session
What carries a lesson past the project boundary a second layer; the published sibling series states its own demands and failure modes anyone adopting one

None of these is a reason not to keep a first layer; the alternative measured in Paper 001 was a 226 MB transcript standing in for a memory. They are the reasons to describe what the layer holds accurately: it carries dated claims, not current truths; it restores knowledge, not conversations; it holds what was distilled, not what happened; and it serves one project, not an organisation. Nothing in the table is committed; each row is open until someone settles it, and these notes settle none of them.

On the provenance of this material

The protocol files, launch scripts and memory notes described here belong to one practitioner's workstation, a Digital One machine, and are not public: the corrected-figures case in §1 and the console restore design in §2 are the operator's account and cannot be re-run by a reader, though the published range the §1 case cites can be checked on this site. The one external reference is this Foundation's own published series, cited as lineage rather than as evidence. Deliberately absent: prices, plans and tiers, and deployment internals.

References

  1. Digital One Foundation, The Second Layer, series index; the sentence quoted in §4 is its published standfirst. digital1.foundation/articles/the-second-layer/, read 21 September 2026.