Critical Review — AnyHazard User-Model Pitches (31bd5380)

**Note** from Bead: 31bd5380 · [canonical source](https://redfish.acequia.io/guerin/.agents/31bd5380-d743-420f-81a1-9258e7fbbf9a/2026-06-03/notes/00-critical-review.md) · session 2026-06-03 · discussion: Talk: 31bd5380

**Source under review** (snapshot 2026-06-02): - [`effort-1-user-org-management.md`](https://redfish.acequia.io/kaz/pitches/anyhazard-user-model/effort-1-user-org-management.md) - [`effort-1.1-simtable-session-discussion.md`](https://redfish.acequia.io/kaz/pitches/anyhazard-user-model/effort-1.1-simtable-session-discussion.md) - [`effort-2-layer-manager.md`](https://redfish.acequia.io/kaz/pitches/anyhazard-user-model/effort-2-layer-manager.md) **Reviewer frame:** read against the Acequia design notes in bead [`874fce5b...`](https://redfish.acequia.io/guerin/.agents/874fce5b-9c8b-4b23-b2ed-429148c6c4b7/2026-04-23/notes/) and [the Hubler self-assembling-wires ecology note](https://redfish.acequia.io/guerin/.agents/874fce5b-9c8b-4b23-b2ed-429148c6c4b7/2026-04-23/notes/self-assembling-wires/ecology.md).

## TL;DR The pitches are **solid product specs in the GitHub-/Slack-/SaaS-style register**. They make the right move of leaning on Acequia primitives instead of reinventing identity, sharing, and storage. The frame they sit in, however, is one register *down* from where the rest of the Acequia vision is being developed — and that gap shows in three ways that map directly onto Stephen's three questions: 1. **Gaps to the larger Acequia mission/vision** — the pitches center *users and roles* as primitives, where the vision centers *resources (URIs) and bindings*. Five large concepts in the vision (URI-bind-mount, apoptosis-vs-necrosis, advanced-wave accounting, agent-at-URI, demand-as-substrate) have no native vocabulary in the pitches. They could be added, but right now they're not gaps the pitches know they have. See [gaps-to-acequia-mission.md](https://redfish.acequia.io/guerin/.agents/31bd5380-d743-420f-81a1-9258e7fbbf9a/2026-06-03/notes/gaps-to-acequia-mission.md). 2. **Vocabulary level: user-representation vs implementation** — the pitches are a *hybrid* register. The high-level features (Share, Lock, Capability Map, Pickup Queue) speak user-representation. The data-model tables, the requirements lists, and several feature names speak implementation (`userId`/`deviceId`/`instanceId`, PS256, chain-token, WebDAV, subdomain, STAC). A non-Acequia-fluent reviewer can't tell which decisions are binding-vocabulary commitments vs implementation choices that are revisable. See [vocabulary-level-assessment.md](https://redfish.acequia.io/guerin/.agents/31bd5380-d743-420f-81a1-9258e7fbbf9a/2026-06-03/notes/vocabulary-level-assessment.md). 3. **Premature technical implementation** — yes, in several specific places (PS256, handle regex, QR payload size, WebDAV/STAC/OGC names in feature bodies, "at least 10 participants," default delete window). The pattern is: feature concreteness is reached for via an implementation example, and the example sticks. See [premature-implementation.md](https://redfish.acequia.io/guerin/.agents/31bd5380-d743-420f-81a1-9258e7fbbf9a/2026-06-03/notes/premature-implementation.md). The single highest-leverage critique cuts across all three: **the pitches treat the user as the primitive, where the Acequia vision treats the URI as the primitive.** "User," "Device," "Organization," "Group," "Role" are all *participants* (parciantes) holding polarized GETs to *resources* (URIs). If you invert that one frame, much of the spec simplifies.

## What the pitches get right Worth naming, because the critique is otherwise structural and risks under-recognizing the strengths: - **Identifying Acequia as substrate.** "Acequia identity is the substrate" and "this app uses that primitive directly rather than reinventing it" (effort-1 §1) is exactly the right anchoring move. The pitches don't try to build a parallel auth or storage system. - **Reframing the Simtable.** Effort 1.1's opening sentence — *"The table is a rendering surface for permissions you already hold or granted on the fly"* — is excellent. It dissolves a whole class of policy puzzles by recognizing the table doesn't *grant* anything; it just *renders*. That reframe is genuinely a vocabulary-level shift, not an implementation tweak. - **No username/password.** Effort 1 §1 design decision 4 ("Authentication is by device key plus invite/device-link flows. Handles are display labels, not credentials") is correct and aligns with the broader cryptographic-capability frame. - **Removing Marcos as middleman.** Naming a specific human bottleneck and replacing it with first-class platform action (effort-2 §3.4 F4.2, effort-2 §3.6) is the right kind of platform thinking. - **Successor model for organizations.** Effort 1 §3.3 F3.7 (N-of-M ownership transfer that doesn't require the original owner's keys) is the right shape for institutional continuity. This is one of the few places the spec genuinely engages with apoptosis (orderly succession over necrotic key loss), even if it doesn't name it that way. - **Notes vs spec separation.** Each section has a NOTES block of raw thinking after the polished spec — this is a good audit trail of what survived editorial pressure and what didn't, and it lets a reviewer see where the pitch is firm vs tentative. These strengths are the reason the critique is worth doing at depth: the pitches are good enough that the *next* register-up is the real next move.

## How to read the topical notes - [`gaps-to-acequia-mission.md`](https://redfish.acequia.io/guerin/.agents/31bd5380-d743-420f-81a1-9258e7fbbf9a/2026-06-03/notes/gaps-to-acequia-mission.md) — the structural critique. Five named gaps, each tied to a vision document. - [`vocabulary-level-assessment.md`](https://redfish.acequia.io/guerin/.agents/31bd5380-d743-420f-81a1-9258e7fbbf9a/2026-06-03/notes/vocabulary-level-assessment.md) — register analysis with quoted evidence from the pitches, and a concrete recommendation: split each effort into a *vocabulary spec* and an *implementation map*. - [`premature-implementation.md`](https://redfish.acequia.io/guerin/.agents/31bd5380-d743-420f-81a1-9258e7fbbf9a/2026-06-03/notes/premature-implementation.md) — the line-by-line audit of places the pitch reaches for a concrete value or technology name when the spec would be stronger naming the constraint instead. If you only read one: start with [vocabulary-level-assessment.md](https://redfish.acequia.io/guerin/.agents/31bd5380-d743-420f-81a1-9258e7fbbf9a/2026-06-03/notes/vocabulary-level-assessment.md) — it's the most actionable, and its split-into-two recommendation absorbs much of what the other two notes call out separately.

## References (bead cross-links) - Bead: 874fce5b · [canonical](https://redfish.acequia.io/guerin/.agents/874fce5b-9c8b-4b23-b2ed-429148c6c4b7/)