Appendix F. Full KUN implementation trace and cross-domain proof
This trace shows how one physical truck becomes a durable vehicle identity, evidence dossier, social character, service history, telemetry source, governed commercial actor and transferable asset without collapsing those roles. Record names are…
Concept & directionLNK
This trace shows how one physical truck becomes a durable vehicle identity, evidence dossier, social character, service history, telemetry source, governed commercial actor and transferable asset without collapsing those roles. Record names are illustrative; every step uses the canonical admission path and receives its own proof/admission/projection receipts where applicable.
#F1. KUN ‘Prague Workhorse’ — end-to-end lifecycle
| Step | Intent / physical effect | Canonical record families | Rebuildable product views |
|---|---|---|---|
| 01 | Enroll physical asset | EntityRootCreated; EntityKindAssertion | Private owner vault and empty vehicle profile shell |
| 02 | Assert VIN, registration and aliases | IdentifierAssertion × n; IssuerEvidence; ConflictAssessment? | Masked identifiers and registry-status view |
| 03 | Attach tracker/MAC | DeviceRoot; IdentifierAssertion; InstallationRelationship | Current connected-device inventory; MAC remains private |
| 04 | Declare authority | OwnershipClaim; CustodyClaim; ProfileAdminGrant; EvidenceAssessment | Role-specific dashboard; no role is inferred from another |
| 05 | Capture as-received build | Inspection; ConfigurationSnapshot; Item/Port/Connection records | Exact current-build graph and type-recipe matches |
| 06 | Create KUN persona | PersonaVersion; RepresentationGrant; RightsGrant; VoicePolicy | Public name, Prague Workhorse story and bounded voice |
| 07 | Wash and photograph | CareActivity; MediaArtifacts; CaptureReceipt; ConditionObservations | Wash timeline card and rights/privacy-safe gallery |
| 08 | Calibrate telemetry device | CalibrationRecord; SoftwareRelease; ClockCharacterization | Device-health/configuration view |
| 09 | Record Prague drive | CaptureSession; SegmentManifest × n; GNSS/clock mappings | Private route, delayed/coarsened public mission summary |
| 10 | Derive trip metrics | DerivationReceipt; MetricObservation; QualityAssessment | Distance, duration, energy/fuel and story-ready facts with lineage |
| 11 | Detect service need | ConditionAssessment; MaintenanceRequirement; DueProjection | Owner reminder; no public defect disclosure by default |
| 12 | Authorize and perform service | WorkOrder; Approval; Labor/PartConsumption; ServiceExecution | Maintenance history and cost/warranty views |
| 13 | Install modification | ChangeRequest; EngineeringAssessment; Execution; ConfigurationDiff | Before/after build, compatibility and new recipe matches |
| 14 | Verify modification | Inspection/TestRun; Finding; ReleaseToServiceDecision | Verified-current badge qualified by scope/date |
| 15 | Run dyno/test | TestPlan; SetupConfiguration; Environment; RawArtifact; Result | Comparable chart only when correction/location/uncertainty are complete |
| 16 | Generate KUN post | ContentRequest; RetrievalReceipt; Draft; GroundingMap; Approval | Persona narration with factual and creative lanes visibly separated |
| 17 | Publish and converse | PublicationReceipt; ConversationTurn; Moderation/Correction records | Vehicle-native feed and cited answer surface |
| 18 | Receive a spotting | SpottingObservation; CandidateResolution; RedactionReceipt | Delayed/coarsened spotting card; no identity merge |
| 19 | Invite claimant/community | Invitation; ClaimAttempt; VerificationDecision | Join/claim flow scoped to proven role |
| 20 | Recommend race/event | RecommendationReceipt; Explanation; Consent/Preference state | Relevant event card without sensitive-owner inference |
| 21 | Buy ticket or training | ActionProposal; Confirmation; GrantDecision; Provider/Order receipts | Entitlement in owner/team wallet; UNKNOWN_EFFECT if unresolved |
| 22 | Sell merch/sponsorship | Campaign; RightsApproval; Catalog/Order; JournalEntries; RevenueShare | Labeled sponsored content and balanced beneficiary economics |
| 23 | Create live listing | Appraisal; Listing; SellerAuthority; DisclosurePackage | Asking price and evidence-backed dossier, distinct from bids/value |
| 24 | Run auction | AuctionVersion; BidReceipts; EligibilityFindings; CloseReceipt | Serialized eligible-bid view and immutable winner/no-sale decision |
| 25 | Settle transfer | SettlementSaga; Payment/Escrow; Title/Custody Handoff | Transaction status, payout/refund and delivery views |
| 26 | Decide persona succession | PersonaTransfer/License/Retirement; New RepresentationGrant | Followers see an explicit continuity, fork or retirement—not hidden takeover |
| 27 | Revoke old access | GrantRevocations; Key/Device Rotation; Cache/Disclosure Invalidation | New owner views begin at authorized scope; historical facts keep provenance |
| 28 | Export and replay dossier | ExportManifest; Files/Digests; Import/Replay Receipts | Portable full-life narrative regenerated from records and artifact manifests |
#F2. One transaction expanded: KUN buys a race ticket
- KUN's agent retrieves the public event, seat/price quote and the owner's current preferences through a purpose-bound projection.
- It creates an inert ActionProposal containing the exact event, seat class, beneficiary, total currency/amount, provider and proposal digest.
- The policy engine checks current principal authority, R3 risk, ticketing grant, period/action limits, jurisdiction, provider and conflict rules.
- The owner confirms the exact canonical proposal. The confirmation artifact binds amount, terms, proposal digest, expiry and confirmation method.
- Immediately before dispatch, policy reevaluates the unchanged proposal against the current grant epoch, mandate balance, quote validity and provider state.
- The connector sends one operation with stable RTracer action ID and provider idempotency key. The local action becomes EXECUTING.
- A provider success produces reservation/order/payment/entitlement records plus balanced journal entries and a final ActionReceipt.
- A possible-effect timeout produces UNKNOWN_EFFECT. Reconciliation queries the provider before any retry and ends in SETTLED, COMPENSATED or OPERATOR_REQUIRED.
- The social post ‘I’m going to the race’ can publish only after entitlement evidence exists; the post cites the safe projection, not payment secrets.
#F3. Cross-domain proof of the same substrate
| Asset | Differentiating composition | Same kernel records prove |
|---|---|---|
| 1/8 electric RC buggy | ground contact wheels; battery → inverter → motor → drivetrain; radio/manual and stabilization by function | asset/device identity, battery configurations, heats, telemetry, crashes, repairs, setup sheets and driver/team attribution |
| fan-propelled bicycle | wheels support/steer; engine or electric motor drives a fan; thrust reacts against air | support and propulsion remain independent, so the machine is not forced into wheel-driven bicycle or aircraft categories |
| airboat | buoyant hull support; above-water air propeller; rudder/steering in air/water interaction | medium, force path, exposed hazard zones, propeller guard, mission and marine-registry adapter |
| submerged-propeller boat | buoyant hull; shaft/electric drive; propeller reacts against water | same boat domain with a different reaction medium, port topology, efficiency/test and maintenance records |
| remotely flown blimp | buoyant gas support; propellers for translation/yaw; control surfaces; optional tether | gas envelope, ballast, tether state, airspace operation, remote link, payload, weather envelope and flight records |
| rocket dragster | ground wheels support/guide; rocket impulse provides thrust; parachute/brakes stop | support is not propulsion; consumable motor, safety authority, test/run evidence and exact configuration are first-class |
| transforming road eVTOL | wheeled road mode, deployed lift/propulsion surfaces, flight mode and transition configuration | one entity across mutually constrained configurations, domain transitions, software/calibration and function-scoped authority |
| rail inspection robot | rail guidance/support, traction drive, sensor utility and optional manipulator | route/authority, maintenance, observations, work orders and robot-specific domain pack coexist without a new kernel |
#F4. Proof obligations before claiming ‘the vehicle lives’
- Every factual statement made by the vehicle resolves to evidence/assessment IDs and an as-of checkpoint; fiction and affect are explicitly persona expression.
- Every external action resolves to principal, beneficiary, current grant, policy decision, confirmation when required, provider receipt and reconciliation state.
- Every physical capability resolves to an exact configuration, support/propulsion/action paths, operating domain and function-scoped controller—not a marketing label.
- Every price/value surface identifies whether it is an appraisal, asking price, standing offer, eligible bid, close price or settled transaction.
- Every ownership, custody, profile, persona, media, telemetry and economic right has its own time-bounded authority record.
- Every public location/media view is a disclosure projection; raw precise data remains separately authorized and retention-controlled.
- Every derived profile/feed/search/market state can be destroyed and rebuilt from the ledger, artifacts, registry locks and deterministic projection versions.