Expanding Civilizational Optionality · Audit Method

How this atlas was audited, and what the audit can and cannot tell you.

The atlas asks to be trusted on a specific basis: structural completeness is not evidence completeness, and it says so on its own face. That claim is checkable. This page sets out the three lenses used, the order the checks ran in, the decision rules that turn a check into a verdict, what the pass of 7 August 2026 found — and, at the end, the things this method does not establish.

Audit pass 7 August 2026 · Target: Planetary Cascade Atlas v8 (model v6.0) · Three lenses · 362 source links fetched · 6 claims verified against primary sources · 2 must-fix findings · Method, not endorsement

Three lenses, deliberately in tension

A single reviewer asking "is this good?" produces a verdict shaped by whatever they already believe. Three lenses with different success conditions produce disagreement, and disagreement is the useful output.

publish-check
Is it fit to leave the building? Sourcing, honest confidence, unresolved contradictions surfaced rather than smoothed, attribution and lineage, plain language, and whether the publication tier matches what the content actually says. Errs toward caution: a borderline claim gets flagged rather than waved through.
fact-check
Is each checkable assertion true? Claims are extracted, prioritised, traced to primary sources, and rated. Opinions, framings and predictions are explicitly not checked — only assertions that could be shown false.
joker
Is the whole frame wrong? A serious rival thinker reasons from a genuinely different axiom set — not a devil's advocate, not a list of caveats. The question is what a clever, well-read opponent who actually believes the other thing would say, and what it would cost us if they were right.

Why all three, and not just the first

The lenses catch different failure modes and cannot substitute for one another. A page can be perfectly sourced and still rest on a frame that does not survive contact with a rival orthodoxy. A page can have a defensible frame and a fabricated citation. And a page can be true in every particular and still be the wrong thing to publish, at the wrong tier, to the wrong reader.

Process logic — the order, and why the order matters

Each step is chosen so that it can fail independently of the analyst's judgement wherever possible. Mechanical checks run first, so that later interpretive work is done on an artifact already known to be internally consistent.

  1. Verify the artifact before reading it

    The atlas embeds its model as base64 gzip with a declared SHA-256. The payload is decoded and the hash recomputed. If the hash does not match, nothing downstream is worth doing — you are auditing a different object than the one the page claims to carry.

  2. Reconcile the headline against the data

    Every number in the masthead is checked against the model's own count manifest. Headline figures are where drift shows up first, because they are written by a human and the manifest is generated.

  3. Fetch every cited source, not a sample

    All source URLs are requested with a browser user-agent and a generous timeout. Sampling is what lets a small number of fabricated citations survive; and at a few hundred sources, exhaustive is cheap.

  4. Triage the failures by cause, not by status code

    A non-200 response is a lead, not a finding. Institutional sites routinely return 403 to non-browser clients, and some return 404. Each failure is separated into blocked, moved, gone, or never existed — because only the last is a sourcing failure, and it is the one that matters most.

  5. Extract checkable claims and rank them

    Quantities, dates, attributions and causal assertions are checkable. Framings, judgements and forecasts are not. Priority goes to claims that are central to the argument, cheap to check, and consequential if wrong.

  6. Verify high-priority claims against primary sources

    The cited source is read and compared with what the page says it says. A claim is only confirmed when the primary source supports it at the stated specificity — the same number, the same date, the same population.

  7. Read the artifact as a reader, not as a file

    The published page is opened in a browser and driven through every view. What matters is what a reader actually encounters: whether the caveats are visible or buried, whether disclosed uncertainty appears where the confident claim appears, and whether the interface leaks internals.

  8. Run the leak tripwire

    A deterministic scan checks every public surface against a never-publish term list. It is a backstop, not the protection — the real protection is the access boundary — but it must pass before anything ships.

  9. Then, and only then, challenge the frame

    The joker runs last, on an artifact already known to be internally sound. Challenging the frame of something that turns out to have a broken hash or an invented source is wasted work — and steelmanning a rival is much harder if you are still unsure what the target actually says.

Audit logic — the decision rules

These are the rules that convert an observation into a verdict. They are stated so that a second auditor can disagree with the rule rather than only with the conclusion.

Link verification

200
Resolves. Says nothing about whether the document supports the claim — that is a separate check.
403
Not a finding. Treated as bot-blocking until shown otherwise; the host is spot-checked by another route before any conclusion is drawn.
404
Investigated individually. Searched for the document by title: if a working URL exists, the finding is wrong link, real source. Only if the document cannot be found anywhere is it a sourcing failure.
connection failure
Inconclusive. Recorded, never reported as a dead source.
internal hostname
A public citation resolving through a load-balancer or staging hostname is a defect even when it returns 200, because it will not survive infrastructure change.

Claim rating

confirmed
The cited primary source states the claim at the stated specificity.
corroborated
Independent authoritative sources agree, but the cited source was not directly readable.
discrepancy
Authoritative sources give a different figure. Reported as a discrepancy needing a pinned edition — not as an error — unless the claim can be shown false.
unverifiable
Could not be checked with the access available. Recorded as unchecked, never as verified.

The asymmetry is deliberate: "I could not verify this" and "this is wrong" are different statements, and collapsing them is how audits acquire false authority of exactly the kind this atlas exists to avoid.

Tier and sensitivity

default
The more restrictive tier wins. Content is not promoted to public on an auditor's judgement.
named places
Material describing identifiable territories under live duress in the vocabulary of failure is treated as sensitive regardless of how carefully it is hedged.
disclosure test
Declared uncertainty must be visible where the confident claim is visible. Honest metadata in a fifth tab does not offset an unqualified masthead.

What the 7 August 2026 pass found

CheckResult
Payload integrityPass. Declared SHA-256 matches the recomputed hash of the decoded model.
Headline vs manifestPass. 115 systems, 457 relations, 13 feedback hypotheses, 14 event records — all reconcile exactly.
Source links (362, exhaustive)No fabricated sources. 294 resolved; 54 blocked; 5 returned 404 and all five proved to be real documents behind wrong or stale URLs; 1 cited through an internal load-balancer hostname.
Claims vs primary sourcesFive confirmed or corroborated — including the WMO El Niño formation date, the WMO seasonal update, and the ILO exposure index, which matched exactly. One discrepancy: a national burned-area figure that authoritative sources render differently.
Disclosure in the interfaceStrong. The evidence boundary — no gates open, no relations active, no frozen sources — is stated in the interface, not buried in metadata.
Non-inference constraintsPresent and explicit, including the prohibition on deriving communal or interstate violence from scarcity, inequality or migration.
Attribution and lineageGap. No byline, publisher, date or licence on the page as audited.
Masthead precisionTwo gaps. An analytic frame promised in the standfirst that the interface does not display; and an event count that mixes current, historical and unmaterialised records without saying so.
Leak tripwireClean.
Frame challengeThree rival orthodoxies constructed. The strongest holds that a purposively authored register has no denominator — nothing in the method ever removes a link for having been absorbed — so the relation count measures authoring effort rather than coupling in the world.

The verdict was fit to share by direct link, at its existing tier, after two fixes — the disputed figure, and the missing provenance. The tier itself was affirmed, not relaxed.

Fixes applied, same day

The findings above are the record of the pass and are left standing. What changed in response:

Each edit to the embedded model required recomputing the payload hash and the model's own canonical hash, and the model's release contract — which pins its record counts — was left intact rather than relaxed to accommodate a correction. That constraint is the reason one intended fix (adding a source record) was reworked into a different one.

What this audit does not establish

That the atlas is right. Verifying that a source exists and says what it is quoted as saying is not verifying that the pathway it supports is real. The atlas's own position is that none of its pathways are yet evidenced — the audit confirms that disclosure is accurate; it does not close the gap.

That the register is complete or representative. The systems drawn were chosen by their authors. An audit of what is present cannot measure what was never proposed, and the method has no way to detect a pathway nobody drew.

That the unchecked claims are sound. Six claims were verified against primary sources out of several hundred narrative assertions. The rest are unchecked — which is a different statement from unsupported, and a different statement again from false.

That a working link is a stable source. Every citation was live on the date of the pass and none carries version or retrieval metadata. A link is not a snapshot; this check expires.

That the audit is independent. It was run by the same system that built the publication. That is a real limit, not a formality — self-assessment is structurally weaker than external review, and it is the reason the rival-orthodoxy lens exists at all. It is not a substitute for a reviewer with standing to disagree.

Reproduce it

The mechanical half of this method is deterministic and can be re-run by anyone with the file. The integrity check:

python3 - <<'PY'
import re, base64, gzip, hashlib, pathlib
html = pathlib.Path("planetary-cascade-atlas-v8.html").read_text()
m = re.search(r'id="pca-v6-data"[^>]*data-sha256="([0-9a-f]+)"[^>]*>(.*?)</script>', html, re.S)
raw = gzip.decompress(base64.b64decode(m.group(2).strip()))
print("declared", m.group(1))
print("observed", hashlib.sha256(raw).hexdigest())
PY

The decoded model is a single JSON document. Its manifest.logicalCounts holds every headline figure, metrics holds the readiness ratios the interface reports, and evidence.sources holds all cited URLs for a link sweep. The atlas also exposes the same document through its own Export exact canonical JSON control, so no scraping is required.

— Method, not endorsement · an audit of disclosure, not a warrant of truth — Back to the atlas · Audit pass 7 August 2026. An interpretation generated from a maintained working wiki; not an official Dark Matter Labs publication.