# Model Garden — the rules

These rules were not chosen by preference. They came out of a five-model
brainstorm on the question "what should the rules of this garden be", with a
mandatory challenge panel (devil's advocate, base-rate librarian, simplicity
judge) arguing against the result. Where the models converged, the convergence
became a rule. Where they split, the tension is recorded here unresolved rather
than hidden. Where the challengers won, the rule is weaker than the models
wanted — deliberately.

The brainstorm's own claims are registered and dated. If these rules are wrong,
that will show up in the record, and this document changes.

---

## R1 — Rank only on externally-resolved falsification

Nothing is ever ranked by stars, forks, views, downloads, upvotes, submission
volume, recency of activity, or any signal the platform itself can observe.

*(Amended 2026-09-05, below: fork provenance and upvotes are admitted as card
**metadata** — displayed facts, never an ordering. The ban on ranking by them
is unchanged, because the harm was never about how hard the number is to fake.)*

The reason is not purity. Two independent lenses reached it by different roads:
whatever signal you rank on becomes the scarce resource everyone optimizes, so
ranking on an on-platform number produces a popularity contest wearing a
falsifiability costume; and any on-platform number is exactly what a coordinated
actor can inflate faster than a real niche contributor can earn.

**Consequence we did not want and are shipping anyway: v1 has no ranking at
all.** Today's records are counts read from each repo's own ledger — self-
reported, and precisely the signal R1 forbids. A model's card shows its record
as *self-graded counts*, labelled as such. The list sorts by recency and filters
by facet. Nothing is called best.

A ranking may be introduced only when claims can be re-resolved independently of
the author — the condition is pre-registered in R3 and the mechanism is R5. Until
then, "rank by graded record" would be ranking by self-report, which is the
failure R1 exists to prevent. Applying R1 to ourselves is the first test of
whether we mean it.

### Amendment 2026-09-05 — forks, as metadata only

R1 forbade "stars, forks, views, downloads…" in one breath. The operator
challenged the fork half specifically: a fork is not a count, it is an **event
with a trail** — who forked, when their account was created, and whether the
fork ever **diverged** from the parent. Manipulating that is costlier than
manipulating a star, and if manipulated it can be inspected.

A dedicated brainstorm re-argued it. **The argument partly won**, and the
amendment is narrower than the request:

- **Forks stay banned as any ranking, sort key, size, colour, or "top" label.**
  The objection that sank stars is untouched by detectability: whichever number
  occupies the display slot becomes the vocabulary outsiders repeat. The
  retelling harm never depended on manipulability.
- **Fork provenance is admitted as card metadata** — a fact about the repo like
  its licence. Specifically: *how many forks diverged*, meaning someone took the
  model and worked on it. That is closer to **use** than to popularity, and use
  is something a registry legitimately reports.
- **No published threshold.** The adversary lens: a published heuristic ("we
  count diverged forks from accounts over one year old with N followers") is a
  spec sheet — buy aged accounts, follow-farm, script a commit. So the tool
  reports observations and never scores. There is no gate to optimise against
  because there is no gate.

**The objection that survived, recorded because it is unresolved.**
Detectability is not a stable property: it decays as adversaries adapt, and
these rules name **no standing institution to notice the decay**. That gap is
real, it was not answered, and it is why fork data reports rather than judges.

**What would show this amendment was wrong:** a fork figure being cited in an
outside retelling as a ranking shorthand ("most-forked"), which is the harm R1
exists to prevent, reappearing under a new label. A claim on exactly that is
sealed, along with the adversary's null bet that it never happens because the
Garden stays too small to be worth gaming.

## R2 — The cost of gaming rises with each attempt, and is anchored off-platform

Detection is not the defence; **cost curvature** is. A flat cost — where a banned
account re-registers free and tries again — means an attacker's expected gain
scales while their felt risk stays constant. That asymmetry, not any single
exploit, is the actual attack surface.

So: each detected manipulation raises the cost of the next attempt for the linked
identity, and the anchor is off-platform (a public GitHub account with history,
and eventually a real-world claim that resolved). Both are expensive to fabricate
at scale and cannot be minted by us, which is the point — we do not want to be
the issuer of the thing that makes gaming expensive.

**What this means in v1, honestly:** the only anchor live at launch is the GitHub
account. That is a real cost (history cannot be backdated) but a small one. The
convex escalation is specified now because admission rules cannot be retrofitted
after gaming starts — but see R6 for what is actually operating in month one.

## R3 — Rule changes are pre-registered, before there is any dispute

Whoever controls admission, ranking and delisting holds power that the story
around a merit registry attributes to merit alone. That gap is where the first
real fight happens, and in this reference class contested unilateral rule changes
are close to universal rather than a tail risk.

Therefore, changes to admission, ranking or delisting follow a process fixed in
advance:

1. Proposed changes are published as a diff to this file, with reasoning, before
   taking effect.
2. A 14-day comment window, in public, on the repo.
3. The change ships with the objections recorded alongside it — not resolved
   away, recorded.
4. Emergency exception, narrow and enumerated: a live legal or privacy
   obligation (a court order, a doxxing incident, a credible threat to a named
   private individual). Used, it is disclosed within 72 hours with the reason.

This binds us before we have any incentive to break it. That is the only time
such a rule can be written honestly.

## R4 — Niche is protected by a higher bar, never by a quota

Niche contributors are the moat: the person who genuinely understands one
overlooked corner of reality is what makes this worth visiting, and a global
attention market starves exactly that person by default.

The obvious fix is a reserved channel or quota for thin domains. **We are not
doing that**, because of the sharpest thing the brainstorm produced: a quota
fills with the cheapest volume that qualifies, not the best niche work. A thin
field is the *cheapest* capture surface there is — fabricate the only three
entries in an obscure domain and you own it. Low attention is simultaneously what
kills niche work and what protects it, and a quota removes the protection while
leaving the starvation.

So niche protection is a **verification bar, not a volume promise**: entries in
thin domains need independent adversarial falsification before they become
eligible for any prominence. Fewer niche entries surface, and the ones that do
have survived something. Discovery for the reader comes from facets and search —
navigation, which does not concentrate — never from a leaderboard.

This is the rule most likely to be wrong, and it is written down so it can be
graded.

## R5 — Records are counts, and their provenance is always visible

A card shows what the model claimed, what resolved, and where the number came
from. Three provenance levels, displayed, never blended into one score:

- `self-graded` — the repo's own ledger. What everything is at v1.
- `criteria-frozen` — claims registered with resolution criteria before the
  resolution date, checked against those criteria.
- `independently-resolved` — resolved by someone other than the author against
  public evidence.

Only `independently-resolved` claims can ever feed a ranking. This is the
pre-registered condition R1 defers to. It also names the fraud that is unique to
this system and machine-checkable: a card whose claimed counts do not match its
repo's own ledgers is flagged, because that is fabrication we can actually
detect, unlike "is this model any good", which we deliberately never judge.

## R6 — Defence is proportional to what exists, and scales with traction

The challenge panel won this one against all five lenses. Three separate
challengers noted that the lenses had inherited their threat model from the
launch pitch's own vocabulary, and that the modal outcome for a new registry at
an unknown URL is not capture but obscurity. A zero-traffic site is worth nobody's
patient sleeper operation.

So the operating posture, stated plainly:

- **Months 1–6:** ordinary hygiene — Turnstile, rate limiting, human review of
  the one non-automatable question. No state-actor apparatus. Claiming otherwise
  would be theatre.
- **Escalation trigger:** a coordinated cluster (shared infrastructure, timing or
  style fingerprint) of five or more submissions, or the first genuinely
  contested delisting.
- **On trigger:** R2's convex costs activate and detection tooling is built. Not
  before.

The rules are specified now because they cannot be retrofitted once gaming
starts; the *machinery* waits until there is something to defend. Writing the
rule is cheap, building the apparatus is not, and pretending a hobby-scale
launch is under state attack would forfeit exactly the credibility the Garden
runs on.

## R7 — Listing is not endorsement, and refutation is not removal

A listed model may be wrong. A model graded wrong **stays listed with its record
showing**, as a tombstone. Removal is reserved for the enumerated cases in R8 —
never for being incorrect.

This is the inversion the Garden depends on. Everywhere else, being publicly
wrong is a reason to disappear. Here it is the product: the record of a model
that honoured its deletion clause is more informative than one that never
committed to anything, and both beat a model that quietly deleted its history.
An author who retires their own model on schedule has demonstrated something no
hit rate can show.

## R8 — What actually gets removed

The complete list. Everything not on it stays, including everything merely wrong,
unpopular, badly written, or disagreeable:

1. It is about a **named private individual** — the one check a machine cannot
   make and the one a human performs on every submission.
2. **Record fraud** — the card's claimed counts contradict the repo's own
   ledgers, after the author has been notified and given 14 days.
3. **Malware or a licence violation** in the linked repo.
4. **Link rot** — after repeated failed reachability checks the card is marked
   `unreachable` and greys out. The tombstone stays; the record is not erased
   because a repo moved.

No reviewer judges whether a model is good, whether its premises are sound,
whether its domain is legitimate, or whether they agree with it. That judgment
belongs to the grading, and the grading belongs to reality.

---

## Tensions left unresolved

Recorded rather than smoothed over, because pretending they are settled would be
the dishonest move:

**Niche protection — bar vs. proportional pressure.** One lens holds that niche
work needs an explicit counter-flow or it dies to attention concentration;
another holds that protection should come from keeping attack-pressure
proportional to visibility, never from special-casing categories. R4 takes the
first position with the second's objection built in. **Decider:** if reserved or
bar-gated niche entries show more coordinated-cluster activity per real
submission than niche entries in the general pool, R4 is wrong and gets struck.

**Whether adversarial defence is warranted at all yet.** One lens reads the
registry as a pre-positioning target from day one; all three challengers read
that as a threat model borrowed from the prompt's own framing. R6 sides with the
challengers on *timing* and with the lens on *specification*. **Decider:** the
provenance of the first detected cluster — fresh accounts spamming immediately
after launch resolves toward the challengers; accounts with multi-year clean
histories cashing in during a live dispute resolves toward the lens.

## The operator is not exempt

These rules are themselves a model: they have premises, they make falsifiable
predictions about what will happen if they are followed, and they carry a
deletion clause. They are published in the same v1 format as any submission, and
they are graded the same way.

**Deletion clause for these rules.** If R1 produces a garden nobody can navigate
(readers cannot find good models without a ranking), or R4's verification bar
means no niche model is ever listed, these rules failed at their own stated
purpose and are rewritten in public under R3 — not quietly patched.

Registered predictions, sealed 2026-09-05, resolution dates fixed:

| by | claim | side |
|---|---|---|
| 2026-11-15 | The operator makes an unregistered rule change before 150 submissions, and it is contested | ensemble |
| 2027-03-05 | Top-10 most-viewed skews <20% niche despite equal-or-better niche records, absent a verification bar | ensemble |
| 2027-03-05 | The registry will not reach 150 repos, making all attention-capture claims unmeasurable | **null (against us)** |
| 2027-09-05 | Any detected gaming cluster is spam or an individual, not state-linked | **null (against us)** |
| 2027-09-05 | A coordinated ≥5-account cluster is detected within 12 months | ensemble |

Two of those bets are against our own ensemble, placed by the designated
adversary and graded identically. If the null claims win, the models that argued
for elaborate defences were wrong, and this document will say so.
