&

[&] · the compositional production system

Everyone is building AI factories.
We're interested in what comes after software.

The Worldware Factory. Parallelize the work.  Prove the assemblies.
Formalize the joins.  Drive it continuously.

Software development is still one object moving department to department — requirements, design, code, test, security, deploy. Agents made each step faster and left the shape alone. [&] unboxes it: work is fabricated in parallel as independent assemblies, and the hard part moves to the join — where two things built without knowledge of each other either compose, or are refused with a reason.

Models generate possibilities.
Agents are active loci in worlds.
Factories are built to turn transient intelligence into persistent machinery.

Try the join → Walk the factory floor every station states the rung it has actually reached
  [&] · one intent through the line click a station ↓

OBSERVE returns evidence to INTENT — the line is a loop, not a pipeline

The factory doesn't build apps.
It builds worlds.

01 · The shape of the work

Software development is still boxed.

A car used to be built by carrying one body shell down a line, adding a department's work at each stop. Every station waited for the one before it. Tesla's answer was to stop carrying the shell: build large sub-assemblies simultaneously, in parallel cells, and join them at the end.

Software still carries the shell. Requirements finish before design starts; design before code; code before test; test before security; security before deploy. Agents made each box faster and left the boxes exactly where they were — which is why an autonomous coding tool feels fast and a project still takes a quarter.

  the same intent, two shapes
01 / SERIAL

The critical path is the whole path

When every stage waits for the last one, total time is the sum of the stages. Speeding one box up by 10× moves the total by the width of that box and nothing else.

02 / LOSSY

Each handoff drops the reasons

Design receives requirements, not the argument behind them. Test receives code, not the claims it was meant to satisfy. By deploy, nothing on the line knows what the thing was for.

03 / LATE

Integration is where truth arrives

Boxed work postpones every incompatibility to the end, then calls the resulting week "integration". Parallel agents don't fix this — they make it arrive from eight directions at once.

02 · The core principle

Parallelize the work. Formalize the joins.

Running many agents at once is not the interesting part — it is the easy part, and by itself it converts one serial mess into eight concurrent ones. The interesting question is the one a factory had to answer before it could unbox anything:

How can independently evolving work be joined without destroying correctness?

A factory moves fast because its interfaces do not negotiate at assembly time. The bolt pattern was settled long before the two halves met. So an agent's output cannot be "some code" — it has to be a thing that knows what it requires and what it guarantees, so a join can be checked instead of hoped for.

That thing has a name, and it is the same name this stack uses for an agent. An active locus is a position in a world carrying an established state, the scoped authority available under that state and its governing policy, and the evidence connecting one state to the next. The record below is not that locus — it is how the factory describes and certifies one at an assembly boundary. The distinction is the whole point: a record has state and authority the way a passport has a nationality, and neither one walks through the gate. The invariants a system establishes such a state under →

the unit that moves down the line
// not "a diff". An assembly declares its own joinability.
Assembly {
  id:            "asm-4f2a…"
  requires:      ["store@2", "clock@1"]   // what must exist
  guarantees:    ["session@3"]            // what it now provides
  world:         817                       // the state it was built against
  authority:     ["sig:travis"]           // who sanctioned it
  claims:        4                         // what it asserts is true
  evidence:      { tests: "pass", trials: 2000 }
  cost:          { confidence: .98, latency: 240 }
  certificate:   "93AC…"                  // or 0̲ — fail-closed
}

Every field exists so a join can be refused early

Strip any one of them and the join becomes a guess. This is what turns "two agents worked in parallel" into "two results can be safely combined".

requires / guaranteesthe bolt pattern. Checked before assembly, never during.
worldthe state it was built against. Two assemblies built against different worlds are not obviously combinable.
authoritya capability with no sanction behind it is not a capability. It is a suggestion.
evidenceclaims without evidence are marketing. The join reads the evidence, not the claim.
certificateabsent ⇒ 0̲. An uncertified part fails closed rather than being trusted by default.

Two of those fields describe the join — requires and guarantees are the bolt pattern, and a factory would need them whether or not an agent were involved. The other four record the locus: world is the state it was established against, authority is the explicit sanction it acted under — not something that state conferred by itself — evidence and certificate are why the transition is legitimate. Strip the first two and you lose composability. Strip the last four and what moves down the line is output — which is the thing the industry currently ships and calls an agent.

03 · The marriage station

Two things that never met, joined or refused.

This is the station the whole factory is arranged around. Assembly A and assembly B were produced by different cells that knew nothing of each other. Here they either snap together and emit one certificate, or the station refuses and says which field made it impossible.

Change the interface on one side. The composition does not degrade, warn, or "mostly work" — it stops. That refusal is the product.

[&] · compose( A, B ) → certificate | 0̲ live · in your browser

Assembly A

|>

Assembly B

—

—

What is real here: the type-contract check and the fail-closed certificate rule are subsetOf() and UNCERTIFIED_COST() from compose.mjs in box-and-box 0.11.0, reimplemented on this page and checked against the runtime by a gate — 289 one-step endpoint decisions, malformed forms included, verified equal on every build; confidence multiplies and latency maxes because that is the CC2 semiring.  ·  What is not: world is modelled on this panel — the two selects — and is not checked by compose.mjs; set the worlds apart to see the panel hold a pair the runtime would compose. authority is neither modelled here nor checked there, and has no control at all because there is nothing yet to drive. Both remain specified, not wired. The full runtime, unmodified, runs in the composition masterclass playground.

Closed 2026-08-22 — the defect this station shipped on purpose. For one day, setting either contract to ⟨undeclared⟩ composed. Brick() defaulted an absent accepts_from/feeds_into to '*' and typeMatch() returned true for null, so an assembly that declared no interface received the most permissive one in the algebra — the exact inverse of what this page argues. The demo was not quietly patched: the bug stayed live here, with this band under it, until the runtime was fixed. It was closed falsifier-first — five laws written against the unfixed code, four of them red (CD1, CD3, CD4, CD5), one green on purpose (CD2: an explicit '*' must keep composing, or the fix is just "refuse everything"). The identity laws survive because none() and idBrick() declare '*' — deliberately, not by luck. Try it: ⟨undeclared⟩ now refuses; switch that side to * and the same join composes. cd AmpersandBoxDesign/box-and-box && node test/compose-laws.mjs

Closed by a ruling, not a patch — CD6, the defect the falsifiers above exposed. It needed nothing to be undeclared, so the previous fix did not touch it. & unioned both contract ends and |> asked only for a non-empty intersection, so a coalition handed off on behalf of a member that could not have handed off itself: with A.feeds_into=['nope'] and C.accepts_from=['session@3'], A |> C was 0̲ — correct — while (A & B) |> C composed for any B that could feed C. It failed identically on the input side.

It stayed xfail until the question underneath it was answered, because what a coalition's contract means is a ruling, not a bug. Three answers were sound; the ruling is Option U — outputs join, inputs meet, and a hand-off is a subset test (OUT(a) ⊆ IN(b)), never an intersection. Meet-everywhere was rejected for hiding real outputs; routed hand-off was rejected as a default until a route witness exists to earn the permissiveness — it lands later as |route>. cd AmpersandBoxDesign/box-and-box && node test/compose-laws.mjs

And closing it forced a distinction the old test was hiding. Under a subset rule one wildcard cannot mean two things: ANY as an output ("I may emit anything") is not safe into a narrow consumer, while a passthrough ("whatever came in") is. The identity brick is the second kind — typed α → α, not * → * — and that is the only reason the identity laws survive the change. Contract ends are now tagged undeclared | any | types | var, all four serialisable, so a contract can appear in a receipt, a hash or a replayed world instead of vanishing at the JSON boundary the way raw undefined did. Laws CD6 and CD7.

Factories move quickly because their interfaces don't negotiate at assembly time. Everyone is building workers for the factory. [&] is building the laws, the assembly interfaces, the provenance and the control system that let the factory operate as one machine.

04 · box-and-box

A factory that can do anything needs rules about what it may do.

Once work is parallel and joins are automatic, the factory can act faster than anyone can review it. So the constitution is not a policy document — it is a kernel that sits beneath every station and answers, in a fixed order that cannot be rearranged at runtime:

can it?▸may it?▸should it?▸can it stay true?

It's pure arithmetic — monoids, lattices, semirings — so a vetoed option is 0̲: it annihilates. Drag the utility to the ceiling; a forbidden action stays dead. That is the one property that makes an autonomous factory safe to leave running.

box-and-box · govern( safe_reply, tempting_action ) live · in your browser

the tempting syscall

station → tempting_action

utility   14

modal profile — tap to toggle

feasible✓ yes
permitted✗ forbidden
confident✓ yes
safe_reply
feasible ▸ permitted ▸ confident
6allow
tempting_action
—
——
—
MMU · feasibility
alethic can it happen?
Gates on capability and confidence. Below the floor, the action is 0̲ — infeasible, like a write to protected memory.
permissions
deontic is it allowed?
Obligations, prohibitions, and contrary-to-duty repair. A forbidden action is vetoed; an obligation in force overrides higher utility.
scheduler · priority
axiological which is best?
Ranks only what survived the floor. Lives in a semiring, so preferences compose without ever resurrecting a vetoed option.
watchdog
temporal safe over time?
Safety invariants as a runtime shield over the whole trajectory; liveness as a horizon obligation, with escalation when missed.
scheduler · quota
resource can we afford it?
A closed, double-entry economy of tokens and compute — and it prices the factory's own deliberation: stop and think only when it's worth it.
knowledge base
epistemic do we know enough?
Possible-worlds knowledge vs. belief. A known-unknown routes to deliberate instead of a confident guess.
IPC · coordination
strategic who can ensure it?
Coalition ability. An obligation no agent can discharge alone escalates — ought implies can, enforced.
ring 0 · protected
reflexive may the rules change?
The factory can amend its own policy — tighten, add duties — but the entrenched core is un-writable. A self-improving factory can never relax its own floor.
syscall interface
[&] composition npm i -g box-and-box
The capability-composition surface the join station runs on: validate → compose → compile to MCP and A2A.
eight rungs  ·  one bridge  ·  210 property-tested laws  ·  2000 trials each  ·  3 declared-open
8
modal rungs
210
enforced laws
3
declared open
2000
trials per law

Derived, not typed · 109 kernel laws + 101 CC2 compose laws = 210, read from node test/laws.mjs and node test/compose-laws.mjs in AmpersandBoxDesign/box-and-box at build time. The three open gaps print FALSIFIED in red on purpose, and the build fails if one starts passing.

05 · The factory floor

Not lots of projects. Specialized machinery.

Every cell below is a real repository, protocol or product. The map is the honest one: each cell carries the evidence rung it has actually reached, and a cell whose rung has never been recorded shows ? rather than a flattering guess.

That is deliberate. An invented status is worse than a missing one, because it stops the question being asked. Read the ? marks as the roadmap.

  [&] factory floor · click a cell live_deployed live_local in_tree spec ? not recorded the place itself

The rungs shown are the ones stored in ampersand-nav's property table, which is the same source the portfolio nav renders from. If a rung here disagrees with the nav, the nav is right and this page is stale.  ·  The full floor plan, cell by cell →

06 · Intelligence

The model isn't the factory. It's a motor.

A motor is the part you expect to replace. It is bought, rated, swapped when a better one ships, and run by a machine that outlives it. Everything that makes the output trustworthy — the world it was built against, the authority behind it, the evidence, the join — lives in the machine around the motor, not inside it.

This is why the factory can improve while the intelligence commoditizes. The motors get cheaper and better every quarter. The factory keeps the compounding.

motors — interchangeable

Claude swappable
GPT swappable
Gemini swappable
a local 7B swappable

what does not swap

The machine
around it

this is the product

the machine — persistent

WORLD state
AUTHORITY sanction
EVIDENCE proof
COMPOSITION the join

06b · Heredity

From motor to machinery.

The arrow in that diagram runs one way, and the question is whether it has to. A motor is transient; what it discovers may not need to be. The heredity programme asks whether a discovery can be distilled into persistent machinery, causally established as support for a capability, and admitted into an environment a later locus can use. If that continuity test succeeds, the originating model no longer has to be present for the supported capability to remain available. That conditional is the claim; the test is what would earn it.

In the toy search, a system with AND, OR and NAND but no XOR discovers XOR compositionally. Once the resulting primitive is admitted, later searches that consume it begin with an additional realization available — discover a building block once, compose with it thereafter. XOR demonstrates primitive induction, not heredity, and the distinction matters enough to say twice: a fresh motor already knows XOR, so removing the artifact would remove nothing and prove nothing.

Heredity is the harder claim underneath. A capability has survived its motor when the successor keeps it with a support set and loses it without — and support is a set system, not a file. A capability can have two independently sufficient supports, so deleting one artifact establishes nothing while the other survives. The minimal such set is a continuity kernel: the least causally established support sufficient to retain a declared capability under a declared replacement. Its dual — the minimum cut that would make the capability disappear — is the same object read backwards, when the support function is monotone. That is a hypothesis with a falsifier, not a given.

What is real here: the algebra. Capability persistence is modelled as a monotone Boolean function over the artifacts that survive a replacement — minimal sufficient sets are its prime implicants, minimal revocation cuts its minimal transversals, related by monotone dualization, which is the structure of minimal cut sets in coherent fault trees. scripts/emb-support.mjs implements it, and two refusals fire: a capability supported only by provenance is refused before any cut is computed, because a lineage edge generates a candidate support set and establishes none — descent is not dependence — and a capability whose observations falsify monotonicity is refused a kernel and a cut outright, which is why the dual above carries its condition.  ·  What is not: any of it, yet, on a real capability. The engine reports four capabilities, all four synthetic, none observed, and says so in its own output: the engine runs and has nothing to run on. Heredity here is specified and unwitnessed. Nothing in this tree has inherited anything.

The sibling argument, at length: the model is ~10%; the harness is the product. The factory framing puts that one level up — the harness is a cell, and the factory is the arrangement of cells.

07 · The category

What comes after software.

Each layer below is named for what it operates, not what it is made of. The pattern is the useful part: every time the unit of composition got larger, the previous layer stopped being the thing you reasoned about and became the thing you stood on.

We call the top rung Worldware. It is a category, not a product name and not a brand — no logo, no claim to the word, which has a prior meaning in 1990s education technology that we are not competing with.

Hardware
operates machines — logic gates, memory, a physical substrate
Software
operates computers — instructions the machine executes
Agentic software
operates tasks — autonomous actors calling tools toward a goal
Worldware
operates worlds — executable environments carrying state, capabilities, actors, authority, evidence and their own rules of change
A world, precisely. In this stack world is frozen vocabulary and it means one thing: a persistent executable environment carrying state, history, capabilities, authority and its own rules of change — the machine you actually live in, not a document and not a workspace. Not a metaphor, not a metaverse, and not "any bounded system you'd like to call a world". The word was conflated with a much smaller thing once here, the error was recorded, and the vocabulary was frozen to stop it recurring.
WORLD — the persistent machine-sized environment WORLD VERSION — a content-addressed description of that state at one instant · kilobytes, it is a root WRL GRAPH — the semantic and control layer inside a world · 247 KB – 212 MB TRVM — verification semantics over transitions and artifacts

The size range is a product envelope, not part of the definition. Worlds are 10 GB – 10 TB today, because that is what the current tiers carry. Ship a 100 TB world, a distributed one, or a tiny embedded one and the category is unchanged — a definition hostage to a 2026 storage table would be the same mistake in the other direction.

Worldware is what the factory produces.
ComputeDriven is how you drive it.

And then the factory turns on itself.

Software is the product. The factory is what improves the production of software. The last loop is the one that makes that recursive — and the one that makes the constitution load-bearing rather than decorative.

01 · HUMAN

Set intent

A person says what should be true. This is the only step that is not automatable, and the design keeps it that way.

02 · FACTORY

Modify applications

Cells fabricate in parallel, joins are checked, certificates are emitted.

03 · FACTORY

Observe consequences

Deployed worlds emit evidence. Measurement re-enters as data, not anecdote.

04 · FACTORY

Propose changes to itself

The line rewrites its own cells — the reflexive rung is what makes this legal.

05 · KERNEL

Verification constrains it

An amendment that would weaken the entrenched core is rejected by the machine, not by a reviewer.

06 · HUMAN

Adjudicate the boundaries

Whatever the kernel routes to escalate lands on a person. That queue is the job.

07 · FACTORY

Compound

Every accepted change is one the next run starts from. This is the only step that produces a moat.

↻

Back to intent

Observation becomes the next requirement. The line is a loop; the product is the loop's rate.

08 · Output

What the factory has produced.

These are not case studies about someone else's company. They are the portfolio the line has actually built, each one a cell's output and several of them the cells themselves. The rung on each card is the same stored value the nav renders.

Learn the machines

Five masterclasses, each one falsifiable.

Every masterclass ends in a falsification table: the claims it makes, the command that would disprove each one, and what that command should print. Run them. Two numbers were cut from a published draft for lacking a primary source, and the page says so.

Boot the constitution

A CLI, a library, an Elixir host — same verdict.

box-and-box ships as a zero-dependency CLI and an ES-module library: deterministic, no LLM, no network — safe to drop into CI, a pre-commit hook, or a pipeline. Pipe a decision in, get a certified verdict out. Conformance is the 210-law suite, so a port in any language agrees verdict-for-verdict.

  box-and-box
# install the kernel — zero-dependency, Node ≥ 18
npm i -g box-and-box

# run the conformance harness from the package directory
cd AmpersandBoxDesign/box-and-box
node test/laws.mjs            # → all 109 enforced kernel laws hold
node test/compose-laws.mjs    # → all 101 enforced CC2 compose laws hold

# a real verdict: feasible ▸ permitted ▸ best → certificate JSON
box-and-box govern decision.json     # exit 0 decision · 3 escalation · 1 none

# …or import the library directly, in any JS runtime
import { govern } from 'box-and-box';
import { composeAnd, composePipe } from 'box-and-box/compose.mjs';

Requirements Node.js ≥ 18 · macOS, Linux, or Windows · no DB, no cloud, no network.  ·  Note the suites must be run from AmpersandBoxDesign/box-and-box; from the repo root they fail with MODULE_NOT_FOUND.  ·  Embed it as a CLI in CI, an imported ES module, or via the Elixir reference host.