Tacit Source. Human knowledge. Licensed for machines.
The overhead switch console inside a machine cab, seen from the seat
Audit

Checked from both ends.

A licensee can check every hour it is invoiced for against the rows signed on its own machines. The person whose skill ran can check the hours run under their name. Both are reading the same rows. There is no second, separate record on either side.

Why this page exists

Being paid and being able to check the payment are different capabilities.

This page exists because of one honest limit in the deployed precedent for per-use payment. The limit is easier to state than it is to engineer around.

There is one deployed scheme that pays named contributors per use. A person contributes under their own name, is paid each time the contribution is used, and is paid on a regular cycle across many countries. It is a real arrangement, and it settles the question of whether per-use payment to an identified person can be operated at all.

It also carries a limit, and the limit is the interesting part. A contributor can see that they were paid. They cannot see whether they were paid correctly.

Those are different capabilities. The first needs a statement and a transfer. The second needs access to the thing the statement was derived from, held where the payer cannot quietly revise it, and readable without the payer's cooperation. That limit is not a criticism of the arrangement. It is what happens when the record a payment comes off sits with the payer and nowhere else — a structural limit, answered structurally or not at all. We built for the second half.

Two further features of that arrangement are choices rather than necessities, and we make them differently. It is offered in place of a right: the contributor gives up royalty and equivalent claims in exchange for it. And the payer sets the rate, on factors the payer determines. Here the licence sets the rate, and what is paid follows the hour a machine runs rather than the signature on a consent.

Who may check what

Two readers, one set of rows.

A check has to be possible without the cooperation of the party being checked, or it is not a check. Both readings below are available on that basis. Neither is a report we compile, and neither is a summary.

The licensee

Every hour it is invoiced for

  • Reads the signed rows produced on its own machines, in its own possession.
  • Reads which named way of working stood behind each row, and which release the machine held.
  • Reads the clearance that started each count, because the clearance and the count are one row and neither can be adjusted without the other.
  • Reads the invoice against those rows, line for line.

It does not read anything about the person beyond the name the licence runs under.

The person

Every hour run under their name

  • Reads the hours that ran under their name, and which licence each ran under.
  • Reads the same rows the licensee reads — not a statement derived from them.
  • Reads what is owed from the row the invoice came off, because the hour invoiced and the hour paid are the same row.

They do not read the licensee's job, its site, or anything of its work beyond the hours that ran under their own name.

There is no second, separate record on either side. That is a design decision and not an economy. Two ledgers can disagree, and when two ledgers disagree the argument becomes an argument about the ledgers, settled by whoever holds more of them. One row cannot disagree with itself. A disagreement here is resolved by going back to the row.

A diesel engine's intake piping and manifold viewed down into an open engine bay
What a count is

A record of custody, not a claim about truth.

A mechanism can make an already-recorded fact hard to alter afterwards. That is a real property and it is worth having. It is also narrower than it is usually sold as, and the gap is where most of the trouble in this area lives. Making the original recording trustworthy is a different problem, and no amount of work on the first problem touches the second.

So the work went into the second. The signature is put at the moment and the place the thing happened, in the hand of a named person who is there. The act that clears a machine to run is the act that starts the meter — one act, one row, signed at the machine. There is no later step at which a number is transcribed, assembled or reconciled, because a later step is exactly where the second problem lives.

The same reasoning sets where the checks run from. A record that only its custodian can check shows nothing to a party that doubts the custodian. We are not the party a licensee has to believe, and we are not the party the person has to believe. The rows sit on the licensee's own machines. The person reads those same rows under their own name. Being in the middle of that is a weaker position than being trusted, and it is the position we want to be in.

What this is not

Neither reading is a window into anybody's work. The rows carry what is needed to settle an hour and nothing further. A check is a check of the count.

The two readings

One object, approached from opposite sides.

The rows stay where they were made. Each reader reaches them directly. Neither reads them through us, and neither reads through the other.

Two independent readers of one set of signed rows One set of signed rows sits in the centre, made and signed at the machine. The licensee approaches from the left and reads every hour it is invoiced for. The person approaches from the right and reads the hours that ran under their name. Dashed rules mark the bounds of each reading, and a dashed rule below the rows marks that no check is read through Tacit Source. The licensee Reads every hour it is invoiced for Signed rows Clearance and count on one row signed at the machine The person Reads the hours run under their name No summary in between No summary in between Nothing beyond the name Nothing of the job No check is read through us Tacit Source Runs the mechanism Keeps no second ledger A disagreement is settled by returning to the row

Fig. 1 — Two readers, one object. The sealed mark denotes a signed row; dashed rules are bounds neither reading crosses.

Where a disagreement goes

A disagreement about an hour is not a negotiation between two accounts. It is a return to one row: which release the machine held, which name it ran under, who cleared it, and when. The row either says so or it does not. Where there is no row, the hour is not invoiced and it is not paid.

A gray engine cover with a perforated vent panel on top of a wheel loader
The standing rule

What a record is never used for.

A record is never supplied to assess the person, to an insurer or to anyone else. There is no score, no ranking, and no comparison of a person against their own earlier record.

The count answers one question — how many hours ran under which name, under which licence — and it answers no other question about anybody. It is not evidence of how well a job was done and it is not offered as evidence of anything of the kind. A licensee that wants to know how its work went has its own machines, its own crew and its own records, which are its own business and not ours.

The bound runs the other way too. A person reading their own hours reads hours. They do not read the licensee's job, and nothing in the reading is built to let them.

The honest limit

Counting, not attribution.

Per-use payment to an identified person works exactly where that person's contribution stays a selectable, addressable thing. Once a contribution is one of millions fitted into a general model's parameters, the configuration is gone and the counting goes with it.

Whether per-contributor attribution can be instrumented on a corpus small enough to individuate its items has not been attempted and reported by anyone. We do not claim it has. We do not need it, because nothing here is dissolved: a skill is selected by name before the work starts and metered by the hour it runs. That is a counting problem rather than an attribution problem, and a counting problem is one a second party can check.

Each step of that is a step somebody can point at. The registry holds entries by name and addresses them one at a time, which is what makes a row about one name meaningful. The release carries the name the licence runs under, which is what makes the row at the machine attributable when it is signed. The count comes off the same act that cleared the machine, which is what makes the row contemporaneous.

Separability is therefore not a feature. It is the condition on which every other promise on this site can be kept — the count, the payment and the withdrawal alike. Licensing several skills under one paper changes none of it: each member stays separately named, separately selectable, separately counted and separately endable. A set is a shelf, not a stew.

What we stand behind is a short list: the money owed, the count, and the deletion. Never the machine, never the job, never the output. The checks on this page cover the first two. The third is a matter of two dates, and a person is told both of them.

Want to see what a check looks like before you sign anything?

Bring your own auditor. The rows they would read are signed on machines you already own.