Membrane Charter — governing the Stephen ⇄ Manav acequia together (Collaborative Beads)

**Bead document** from Bead: Collaborative Beads · [canonical source](https://redfish.acequia.io/guerin/.agents/48a76785-d7a3-4fee-99f5-84b57fb158ba/charter.md) · discussion: Talk: Collaborative Beads

- **Canonical URI:** https://redfish.acequia.io/guerin/.agents/48a76785-d7a3-4fee-99f5-84b57fb158ba/charter.md - **Status:** v0 draft, offered for collective adoption by both parciantes (Stephen, Manav). Not imposed. - **Opened:** 2026-06-19 · **Bead:** `48a76785-d7a3-4fee-99f5-84b57fb158ba` (`collaborative-beads`)

## What this governs The **membrane** ([SKILL](https://redfish.acequia.io/guerin/.agents/48a76785-d7a3-4fee-99f5-84b57fb158ba/2026-06-19/skills/membrane-query/SKILL.md)) joins two independently-owned AI memories — Stephen's **Hubler** bead commons (local Orama index, bead [`6f5044df`](https://redfish.acequia.io/guerin/.agents/6f5044df-cd90-459d-a150-e0250e98039a/)) and Manav's **RAG** service (bead [`86f63509`](https://redfish.acequia.io/people/manav/.agents/86f63509-1fbd-4318-ba65-58a6b1cb2589/)). Two parciantes, one shared ditch. The *shared resource* is not either corpus — each stays privately owned — it is the **flow of queries and answers across the boundary**, and the **trust** that makes that flow safe. This charter is how we tend that ditch together. It is grounded in the commons' own reading of **Ostrom's eight design principles for common-pool resources** (the [ostrom-governance-principles bead `ae0d5662`](https://redfish.acequia.io/guerin/.agents/ae0d5662-d1e7-40ff-a17e-0bf6b4303dff/2026-06-17/notes/00-ostrom-principles.md) and the illustrated [corporate-vs-acequia artifact `f5b21ea4`](https://redfish.acequia.io/guerin/.agents/f5b21ea4-2b73-4c8b-96f0-892f63ad86cf/2026-06-04/artifacts/ostrom-principles-corporate-vs-acequia.md), which already names a boundary a "living **membrane**"). Surfaced through the membrane's own Hubler side on 2026-06-19 — this charter cites what the commons said, it does not invent.

## Empirical findings that shaped this charter (the first live run, 2026-06-19) Running the membrane on governance questions revealed three facts that the rules below answer to: 1. **Coverage is asymmetric.** Manav **honestly refused** every governance question ("I don't have enough context…") — his corpus is dev/career, the governance commons lives entirely on the Hubler side. The refusal is *information*, not failure. 2. **The pipe carries real content both ways.** Asked in his wheelhouse ("what does graphify do?"), Manav returned a grounded, cited answer (dist 0.28). Silence and substance are both honest signals. 3. **Privacy is upstream and works.** Manav's PII screen and no-raw-chat policy live in *his* service; the membrane never received, so never leaked, what he withheld.

## The eight principles, applied to the membrane ### 1. Clearly defined boundaries — *who is a parciante, and what is shared* - **Parciantes:** Stephen (Hubler) and Manav (RAG), each with a self-sovereign trust root. - **The resource:** the query/answer flow across the membrane — not the corpora. - **The rule:** each side declares its own permeability. Hubler exposes full text of Stephen's tree; Manav exposes screened docs/skills + grounded answers, never raw chat. The boundary is a *living membrane the parciantes maintain*, not a fixed wall — exactly Ostrom P1 as `f5b21ea4` frames it. ### 2. Congruence / prorrata — *give in proportion to what you draw* - Reciprocity is the acequia's heart (feedback_every-constraint-is-soft, advanced-wave accounting). The membrane is **one-way today** (Hubler queries Manav). That is a prorrata debt: until Manav can query Hubler in return, the draw is unbalanced. - **The rule:** make it two-way (see §Next saca). Each side's query budget should track what it contributes back, not what it can take. ### 3. Collective-choice — *the governed write the rules* - This charter is **offered, not imposed** (beads are exploratory, not prescriptive). It is adopted only when both parciantes assent; either may propose amendments via the dock. - **Open governance flag (important):** a charter governing *both* parties currently lives under *one* party's namespace (`guerin/`). That violates the spirit of P3/P7. The charter should move to a **co-owned URI** (see §Its own URI). ### 4. Monitoring — *watch the flows, not the people* - Every membrane crossing is observable: `origin`-tagged results, and an append-only request ledger as the [web-session-log](https://redfish.acequia.io/guerin/.agents/2eea4ddc-dca3-4b6f-8f77-61b1a8bdaec9/about.md) does for the relay. Manav's `GET /info` already exposes his auth mode for upward audit. - **The rule:** the membrane logs *what crossed* (question, origin, outcome, size) to a place **both parciantes can read** — peer audit, bidirectional, never covert surveillance of content. ### 5. Graduated sanctions — *escalate, don't exile (apoptosis, not necrosis)* - A misbehaving caller meets steps, not a kill switch: ok → soft warn → throttle (`429`) → temporary block → token revocation (cascade down the chain). Manav's ephemeral tunnel + optional `X-API-Token` already give him the revoke rung. - **The rule:** sanctions are reversible and the path back to good standing stays visible (project_apoptosis-vs-necrosis). ### 6. Conflict-resolution — *cheap, fast, local arenas* - The **dock** ("hey you, it's me") + bead chats are the dispute record. A sanctioned caller appeals via the dock. Disagreement about what may cross is resolved between the two parciantes directly, before any external arena. ### 7. Minimal recognition of rights to organize — *neither overrides the other* - Each side's ACLs, privacy policy, and lifecycle are **its own**. The membrane is dumb transport: it never re-implements or peels back the other side's screen, and no platform sits above the two trust roots (feedback_acequia-as-not-no-as). ### 8. Nested enterprises — *this acequia nests in the larger commons* - membrane → bead-orchestrator (`4c6470f9`, mayordomo of the commons) → endpoint mesh → the whole acequia. Tokens attenuate down the chain (a token mints sub-tokens ⊆ its scope). A two-party membrane is the smallest acequia; the same pattern scales to N parciantes.

## Its own URI (the P3/P7 move) "It will need its own uri." Today this charter sits at the clean top-level path above, but **inside Stephen's namespace**. A charter co-authored by two parciantes should not be hosted under only one party's tree — that is the corporate/governmental failure mode Ostrom warns of (rules written by one side for both). **Decision offered to Stephen + Manav:** give the shared acequia its **own co-owned home** — a neutral GUID/namespace (candidate: `redfish.acequia.io/acequia/membrane/` or a jointly-owned bead not under `guerin/` or `people/manav/`) — and let this `charter.md` be a pointer to it. Until then, this URI is the working draft and Manav's assent is recorded via the dock.

## Ratification - [ ] Stephen assents (Hubler parciante) - [ ] Manav assents (RAG parciante) — offer this charter's URI to his dock - [ ] Move charter to a co-owned URI (P3/P7) - [ ] Make the membrane two-way (P2 prorrata) — stand up a Hubler `GET ?q=` endpoint + scoped token for Manav

## Next saca (collective work ahead) 1. **Reciprocity:** Hubler query endpoint for Manav → mutual membrane. 2. **Shared monitor:** a crossing-ledger both parciantes can read (P4). 3. **Co-owned namespace:** move governance off `guerin/` (P3/P7). 4. **Coverage map:** the asymmetry finding means shared/governance docs belong in a space *both* index — not buried in one party's tree.

Derived via the membrane's own Hubler side; see provenance in [artifacts/governance-search.mjs](https://redfish.acequia.io/guerin/.agents/48a76785-d7a3-4fee-99f5-84b57fb158ba/2026-06-19/artifacts/governance-search.mjs) and [artifacts/membrane-governance-demo.mjs](https://redfish.acequia.io/guerin/.agents/48a76785-d7a3-4fee-99f5-84b57fb158ba/2026-06-19/artifacts/membrane-governance-demo.mjs).

## References (bead cross-links) - Bead: Orama Bead · [canonical](https://redfish.acequia.io/guerin/.agents/6f5044df-cd90-459d-a150-e0250e98039a/) - Bead 86f63509 · [canonical](https://redfish.acequia.io/guerin/.agents/86f63509-1fbd-4318-ba65-58a6b1cb2589/) (no page yet) - Bead: Ostrom Governance Principles · [canonical](https://redfish.acequia.io/guerin/.agents/ae0d5662-d1e7-40ff-a17e-0bf6b4303dff/) - Bead: F5b21ea4 · [canonical](https://redfish.acequia.io/guerin/.agents/f5b21ea4-2b73-4c8b-96f0-892f63ad86cf/) - Bead: Web Session Log · [canonical](https://redfish.acequia.io/guerin/.agents/2eea4ddc-dca3-4b6f-8f77-61b1a8bdaec9/)