Truth Onion

How it works

Claims are placed by one standard only: the strength of the verifiable evidence behind them. Better-proven sits closer to the center; weaker and less-supported sits further out.

The layers

Uncertainty is opt-in

By default you see the Core: only claims backed by primary documents and court records that have survived challenge. Nothing that has not survived challenge is on screen.

Turning the depth dial outward brings the further shells into view, one at a time. The dial hides content, never existence — the count of what sits deeper is always shown, so nothing is quietly withheld.

Every placement is a current standing rather than a verdict — a ruling about evidence, which can itself be contested. The burden is not symmetrical, and not in the obvious way: adding evidence takes effect immediately and answers to challenges afterward, while taking evidence away is adjudicated before it has any effect at all. How a placement is contested →

  1. CoreDocumented, and survived challenge
  2. InnerWell supported; credible dispute remains
  3. MiddlePartial support
  4. OuterSpeculative; the path inward is stated
  5. OutermostChecked and failed; kept visible
Certainty is warm, dense and central. Speculation is cool, thin and distant.

The rules

Constraints in the database, not moderation after the fact

None of these is applied after the fact by a moderator. Some are enforced at the moment data is written: no request can set a tier directly, no claim can be edited after placement, no record can be deleted. The rest govern what a judgment is allowed to be — it must name its reason, it must be recorded before it takes effect, and it stays visible afterwards, including when it fails. Both kinds bind everyone including the operator, because neither runs through a person who could decline to apply them.

  • A tier only changes through a recorded adjudicationNo path sets a placement directly, in either direction. Inward carries the burden of new evidence that survives; outward follows once the support fails — and removing that support is itself adjudicated first.
  • Outer cannot feed innerA weak claim can never be cited as support for a stronger one, within or across topics.
  • Moral and framing claims cannot occupy the factual CoreNo matter how strongly held, including by the operator.
  • Metaphysical claims take no tier at allThe evidence axis measures them in neither direction, so they route off the axis rather than being ranked weak. Review can produce an evidence-bearing rewording, placed on its own merits and linked back to the original — and the original's standing never moves with it, in either direction.
  • Self-assertion scores zeroA source asserting its own author is right restates the claim rather than evidencing it. Only claimant-independent provenance moves anything inward.
  • Claim text is immutableThe tier was earned by that exact sentence. Revise it and the revision earns its own placement.
  • Record entities are never hard-deletedSources leave a case only through a proposed-and-adjudicated withdrawal with a stated reason; links end only through recorded adjudication. What left, and why, stays visible.
  • Popularity moves nothingNo count of supporters, followers or votes changes a tier. Only evidence surviving review does.

The review model

No ruling is final by being the last one made

A placement is a ruling about evidence, not a fact about the world. Rulings can be wrong, and a system that cannot say so about its own is not an evidence engine — it is an authority with extra steps.

So a ruling is a record, and a record can be contested. Someone files; someone else rules; a third party can find that ruling wrong; a fourth and a fifth can find them wrong and the original right. Nothing settles by being the most recent thing said. What keeps that from running forever is not a rule against reopening — it is that each round has to answer the reasons already on the record rather than start over, and that every round, including every failed one, stays visible.

  • Filing and ruling are separate actsNo party rules on its own filing. Enforced in code, and read from the recorded event log rather than from a field someone could set.
  • A removal has no effect until it is ruled onFiling a withdrawal changes nothing by itself. One person should not be able to subtract from the record unilaterally, however well argued the filing.
  • A rejected challenge is kept as permanently as an upheld oneA failed attempt is information about the claim too. Discarding it would let the record forget what has already been tried and failed.
  • Every ruling carries its filer, its reason and its dateWhich is what lets a later reader judge the ruling itself, rather than only its outcome.

Where this stands today: withdrawals and routing decisions run the full two-phase shape, with the separation of parties enforced in code — in the sandbox you can act every role yourself and watch the rules refuse you when you try to rule on your own filing. Challenges to a tier currently resolve in one step, and one curator rules. The engine states that on every adjudication it renders rather than implying an impartiality it does not have: the place a review would be shown is already built, and reads independent review: none yet until one arrives.

The rest arrives with multiplayer — other people in the other seats, and the two-phase split applied to the tier challenge itself. The record is built for it now, because a review model that only works once there are strangers in it has to exist before they show up.

A placement, in the format the reader sees

The edge is a workspace, not a landfill

Claims that have been checked and failed are not deleted. They stay visible at the outermost layer, stated faithfully, next to the reason they are there — so reopening one means answering the reason on the record, instead of starting the same argument over from nothing.

outermost · checked and failedillustration of the placement format
The Great Wall of China is visible from space with the naked eye.

This is a popular claim rather than a physical one, so it cannot sit near the Core. Angular resolution at low earth orbit places an object this narrow well outside naked-eye visibility, however large it feels from the ground.

Kernel links

Where an overreaching claim came from

Most claims at the edge are not inventions. They are extensions — a documented fact carried further than the documents go. Each outer claim is connected to that seed: the nearest established ground it grows from and overreaches beyond.

The connection carries a gap statement: what the kernel establishes, what the claim asserts beyond it, and what would close the distance — documented through 1973 · asserted beyond · path inward: any post-1973 primary record.

It carries no evidentiary weight and can never move a tier or be cited as support, and it says so on its face: this connection shows where the evidence stops — it does not support this claim. How the line is drawn is computed from what the link is, at the point a record becomes a rendering — it is not carried in the data handed to the view — so no code path draws a kernel link whole, including one handed a forged payload.

  • Support draws wholeWhere evidence actually connects two claims, the line between them is unbroken.
  • A kernel link draws brokenSolid on the evidenced side, visibly snapping where sourcing runs out, dangling toward the claim beyond it. The width of the break is the evidentiary distance.
  • No kernel means no lineAn unmoored claim floats free. That absence is its own signal, and is not filled in with a plausible-looking relative.
  • Every hop is challengeableA flattering kernel — dressing a leap as a gentle slope — is the attack this feature invites, so the path is contestable step by step and a contested step renders differently.

Where a claim genuinely descends through intermediate steps, the path is traced through them rather than jumping end to end — showing how far an idea travels on real evidence before it leaps. The route walks only recorded evidentiary links, so a nearest-looking neighbour that happens to sit close by never lands on a path; where no such chain reaches the claim at all, what draws is the bare two-point break.

Claims welded from two separate roots draw both lineages at once, each breaking at its own point. One may carry through the middle layers before snapping; another may break straight off the documented core. That difference is information about the claim.

The time machine

What the map believed, when, and why it changed its mind

A map that shows only its current state presents itself as having always been right. A second control sits beside the depth dial: a time scrubber that replays any topic as it stood at any past moment — placements appearing, claims moving inward as evidence lands, sliding outward the day a challenge is upheld.

Nothing new has to be recorded to make this possible. The rules already force the system to keep the full record: claim text is immutable, so nothing was ever silently rewritten; every tier change carries its reason and timestamp; every challenge is kept, including the failed ones. The replay is a rendering of records that already exist, and no historical view can reach a write path — the reconstruction runs backward from the present in a module that contains no write call at all, and every route that serves a past state only reads. Where the record cannot honestly rebuild a past state, the reconstruction says so instead of guessing: a view earlier than the recorded log carries a banner saying so, and an event reconstructed after the fact is marked as reconstructed and claims no actor.

The distinction it exists to make visible: a claim placed correctly on the evidence of its time, and demoted years later when better evidence arrived, was not a mistake. It was the system working. A replay separates was this right then from is this right now — and an auditor can evaluate any placement against the record as it stood, not as it stands.

This is the outermost ring's principle applied to time. Failed claims stay visible so an argument reopens against the record rather than from scratch; past states stay visible so the system cannot quietly become correct. It shows its corrections, with dates.

The companion

The persona is absent from the reasoning, not told to behave

The engine ships with an optional AI companion. It advises; the rules decide. It has no write access, cannot propose a tier, and cannot mark a source verified — that state is computed from text actually retrieved, not authored by a model.

It also runs in a character of your choosing, and that is where the usual promise breaks down. Everywhere else, keeping a persona from coloring the analysis is a matter of instructing the model not to let it. Here the character is structurally absent from the analysis request. Not instructed against, not filtered afterward — not present. The persona exists only on the second pass, rendering findings it took no part in producing.

A substance-fidelity check then confirms the findings survived that rendering intact. A noir detective can make unproven atmospheric — the check is what catches it if the voice starts making it sound likely.

How the companion is built →

No exemptions

The rules apply to the author

Rule five — self-assertion scores zero — has no carve-out for the people who wrote it. A claim about the engine's own integrity, backed by the engine's own passing test suite, is placed at Outer. The tests restate the claim rather than independently verifying it, and the placement reason says so: the path inward is an audit by someone who isn't its author.

A constraint enforced at the moment data is written cannot check who is writing. That is why it is enforced there rather than applied afterward as policy.

The claims in the record have the same problem: they were authored here, so they need review from somewhere else — and that channel is already open. Work the sandbox in the demo and the session exports as a save file: the whole record you touched, challenges and event log included. The demo's contribute / feedback panel takes it — the file's contents and nothing else, not even the filename — and returns a content hash, so a contribution can be proved included without its contributor ever being identified. Those saves are read as strain data today. At multiplayer they import through the real rules layer entry by entry and nothing carries standing in from a file — a review of a claim placed here has to earn its outcome under the same rules the original did.

What that means for the code →