Nishi FamilyCompare › Does the Nishi ecosystem measure itself -- MEASURED with its own instruments, reported unflattering

Nishi Compare · measured, not asserted

Does the Nishi ecosystem measure itself -- MEASURED with its own instruments, reported unflattering

Nishi vs the field — every Nishi cell is measured against real organ source at emit time; each gap names the watch contract that will close it.

One command grades 26 domains at 393 permil (48/122 levels) from a sovereign seg_store, and this page leads with the three ways that number is weaker than it looks. 393 permil says NOTHING about 66 of the 70 compare domains -- the two vocabularies share only 4 names and the maturity board is 4 of 38 populated. 393 is NOT a fall from 500: the denominator grew 15 to 26 domains, so that is coverage growth, not regression. And the autonomy headline is 705 permil published against 529 permil honest, because the meter averages only scorable axes and a3 is absent. Verdict: the measuring is real and largely seat-free; the HONESTY CONTROLS are what still need building.

Layer 1 · Executive

Where we are. The ecosystem genuinely measures itself and the measuring is largely seat-free: one command grades 26 domains at 393 permil from a sovereign seg_store, the ladder refuses to award a comparative rung from a coverage number, a missing witness is distinguished from a failing one, evidence freshness is tracked orthogonally to evidence validity, and the publishing loop runs with no seat and is now guarded by a dead-man switch. What is MISSING is not measurement, it is the HONESTY CONTROLS around it: the headline is consumed without its own partiality flag, plan coverage is folklore rather than a row, declared cadence is not a predictor of when a beat runs, and one evidence log is the sole witness for three unrelated domain subjects.

Where we need to go. Make every published ecosystem number carry the thing that would falsify it: its coverage, its horizon, and its abstention. A grade that cannot say which domains it excludes, how old its evidence is, and which of its axes could not see is not a measurement, it is a headline. Each rung below turns one currently-invisible caveat into a row that the beat emits whether anyone asks or not.

The unit. 1 u = one measured session-leg (estate calibration: graphics R21 in one leg 2026-08-15). Local evidence: the cron-watch guard plus its both-directions bite proof landed inside one leg this session, so a rung scoped to one emitted row with a gate is 1 u.
Where are we: 5 open rungs. Measurement real and seat-free; honesty controls absent. Counts measured at emit below this line.
Cost to an honest headline: 2 u. EC2 the plan-coverage row and EC3 the abstention guard -- the two cheapest rungs and the two that stop a number being read as broader or stronger than it is.
Cost to provable freshness: 2.5 u. EC4 declared cadence beside observed interval, and EC6 the fleet census appending rows as it decides them instead of all-or-nothing.
Cost to witness integrity: 2 u. EC5 evidence pointers that declare their subject, which is the root cause of the one standing CONFLICT.

9 of 14 capabilities measured|4 of them measured exceeds|5 open|coverage 642/1000|adoption 9 full / 0 partial

Layer 2 · Roadmap

Do this next — computed by the ranker, never chosen by a seat

Order from nx_compare_rank (nx_dr_ocm: (deficit + cost-of-delay + option + enables) x sponsor x self-sufficiency x momentum / cost). FINISH rows are rungs whose symbol is present but whose organ is short of full adoption: the cheapest closures on this board, listed before any new work. Stamp: # asof=1787883571 domain=ecosystem target_version=0.1 rungs=7 done=2 open=5 finish=0 ranker=nx_dr_ocm

#StageRungPriorityDerivation
#10.1Plan coverage as a published row (EC2) em_plan_coverage666v=2 m=1 c=3
#20.1Consumers carry the abstention (EC3) em_axes_known_guard666v=2 m=1 c=3
#3laterEvidence pointers declare their subject (EC5) em_subject_declare333v=2 m=1 c=6
#4laterDeclared cadence beside observed interval (EC4) em_cadence_observed133v=2 m=1 c=15
#5laterLong census appends rows as it decides them (EC6) rf_emit_row_as_decided100v=1 m=1 c=10

Critical path — contract, done-rule, executor, cost

RungCloses withDefinition of done (pre-declared)ExecutorEst.
Whole-ecosystem grade from one command (EC0)em_rollup_storeOne re-runnable command reports depth times breadth across every domain from the native seg_store, with the validation partition printed and summed -- LANDEDOrgan0 u
Publishing loop guarded by a dead-man switch (EC1)eb_runThe flywheel that republishes the dashboard had no clock row and no watch, so a stop was invisible; a cron-watch row now tracks its heartbeat, verified through the consumer and bite-proven both directions -- LANDEDOrgan0 u
Plan coverage as a published row (EC2)em_plan_coverageEmit domains-with-a-plan over domains-with-a-ver-ladder over rankable-domains every beat, with the partition summing and each planless domain NAMED. MEASURED 2026-08-21 by hand: 70 domains, 63 with a plan, 7 without, and the partition sums. The row must attribute a refusal to the MISSING PLAN and never to the ranker, because refusing a planless domain is correct behaviour. Gate proves a planted planless domain appears in the named list and that the three counts reconcile to the regen list totalOrgan1 u
Consumers carry the abstention (EC3)em_axes_known_guardThe autonomy meter already prints axes_known and verdict PARTIAL; the rollup keys on the bare permil token and consumes it as whole, so a 3-of-4-axis average is published as a 4-axis one. Read the partiality alongside the value and mark any derived grade PARTIAL when its source was. Gate proves a PARTIAL source cannot produce a non-PARTIAL derived grade and that a complete source still passes clean -- the positive control, because a guard that refuses everything passes every negative testOrgan1 u
Declared cadence beside observed interval (EC4)
after EC2
em_cadence_observedFor every beat this rollup depends on, publish the declared interval, the interval observed by subtracting two consecutive timestamps, and the delta. MEASURED 2026-08-21: one beat declared at 3600 seconds runs at about 21600 and another declared at 86400 also runs at about 21600, so the declared column predicts neither. Gate proves a beat whose observed interval diverges from its declaration is NAMED with both numbers, and that a beat running to its declaration reads cleanOrgan1.5 u
Long census appends rows as it decides them (EC6)rf_emit_row_as_decidedThe estate fleet pass prints its whole census only after every domain is visited, so a run interrupted at 95 percent yields exactly what one interrupted at 5 percent does -- measured 2026-08-21 at over 100 minutes for 73 bytes of header while provably still reaping children. Append each domain row at the moment it is classified and keep the partition summary for the end. Gate proves a run killed mid-sweep leaves every already-decided row durable and that the final partition still sumsOrgan1 u
Evidence pointers declare their subject (EC5)
after EC3
em_subject_declareEvery evidence pointer names the SUBJECT it measures, and the rollup refuses to triangulate two witnesses whose declared subjects differ, reporting them as two separate readings rather than one CONFLICT. MEASURED 2026-08-21: the single standing CONFLICT is hosting, where a reachability witness reads GREEN and a product-function witness reads RED at 5 of 29, both correct about different questions, and that same product-function log is also the only witness for network. Gate proves two witnesses with differing declared subjects are never stamped triangulated and never stamped CONFLICT, and that two same-subject witnesses still triangulateOrgan2 u

Milestones

MilestoneRungsCumulative
M1 · Honest headlineEC2,EC32 u
M2 · Freshness provableEC4,EC64.5 u
M3 · Witness subjects declaredEC56.5 u
Layer 3 · Engineering
How this is scored. Every Nishi mark is measured: the generator reads the real organ source on disk and requires the implementing symbol to exist (no self-grading). A watching tag names the organ and symbol contracted to close a gap — the mark flips itself on the next compare beat when that workstream ships, and the comparewatch- plane row flips with it. The flip is necessary, not sufficient: it proves the symbol exists, never that the capability is good. The bar is the rung's pre-declared done-rule, proven by its gate — a symbol shipped without the behaviour behind it is a defect, and the flip is exactly what makes that defect visible instead of quiet. Competitor marks record documented capability presence — presence, not depth or scale. Adoption is measured too: every measured row carries where its organ stands on the estate's ladder (source → built → promoted → registered → invoked; libraries by importer reach minus validation importers; gates by the execution surfaces that run them). A row is fully adopted only at the top of its ladder; anything short is tagged partial with the exact remedy, so a build nobody promoted can no longer read as shipped. Census stamps: importers asof 1787849099, gate census asof 1787855507 (unix seconds; -1 = census absent).

Capability matrix — measured against source

leads / measured exceed present partial absent · click any capability for its evidence

CapabilityNishiDORAGoogle-SRE-PRRBackstage-scorecardsThoughtworks-Radar
Whole-ecosystem grade from one commandMeasured exceed: em_rollup_store in runtime/_hdl_build/nx_ecomat_lib.nx, verified at emit. MEASURED 2026-08-21: 393 permil, 48 of 122 levels across 26 domains, read from the native seg_store with no TSV and no third-party format. DORA measures four delivery metrics not capability depth; an SRE production-readiness review is per-service and human-run; Backstage scorecards are the nearest analogue but are checks per catalogue entry rather than one estate number. Nobody else ships a single re-runnable command that answers where is the whole system Adoption: LIB-WIRED importers=21 nonval=13 — fully adopted (top of its ladder).
Comparative rungs cannot be bought with a coverage percentageMeasured exceed: permil_to_level in runtime/_hdl_build/nx_ecomat_lib.nx, verified at emit. The ladder is capped at PRODUCTION by construction. S-CLASS and EXCEED are defined as triangulated parity and a triangulated win against a NAMED competitor, so they are claims about a comparison and no percentage may reach them. This closed a real laundering path where a high coverage number stamped a domain at parity with gcc while the sota board reported PROVEN 0 of 40. No reference framework distinguishes capability tiers from comparative claims at all Adoption: LIB-WIRED importers=21 nonval=13 — fully adopted (top of its ladder).
Two independent witnesses per domain, conservative MIN consensusMeasured exceed: em_domain_level in runtime/_hdl_build/nx_ecomat_lib.nx, verified at emit. Each domain may declare two evidence pointers. Two readable witnesses within one level read triangulated; more than one level apart read CONFLICT and the reported grade is the MIN, never the mean. A declared-but-unreadable pointer reads DANGLING rather than a low grade, so a dead pointer can never masquerade as a measured TOY. MEASURED: triangulated 8, single-source 11, stored 6, DANGLING 0, CONFLICT 1, and the partition sums to 26 Adoption: LIB-WIRED importers=21 nonval=13 — fully adopted (top of its ladder).
A missing witness is distinguished from a failing oneMeasured exceed: em_derive_level in runtime/_hdl_build/nx_ecomat_lib.nx, verified at emit. Three outcomes not two: a real measured level, NO source declared, or DECLARED-but-dangling. An empty log counts as absence of measurement rather than a RED verdict, because a gate that opened its log and died before writing would otherwise score a genuine TOY and two such logs would converge and be stamped triangulated -- a validation claim with zero readable sources behind it Adoption: LIB-WIRED importers=21 nonval=13 — fully adopted (top of its ladder).
Evidence freshness measured ORTHOGONALLY to evidence validityMeasured: em_emit_page exists in runtime/_hdl_build/nx_ecomat_lib.nx, verified at emit. MEASURED 2026-08-21 by nx_ecomat_evprobe: 29 declared slots, match 29, CASE-MISMATCH 0, absent 0, unreadable 0, partition 29 of 29 SUMS. Orthogonally 15 of 29 are STALE against the 7-day window, the oldest 35 days. A stale slot still MATCHES. Those grades are UNSUPPORTED not REFUTED, and the remedy is to re-run the gate, never to re-grade the domain. Folding staleness into the validity partition would destroy exactly that distinction Adoption: LIB-WIRED importers=21 nonval=13 — fully adopted (top of its ladder).
The publishing loop runs with no seat and is now guardedMeasured: eb_run exists in runtime/_hdl_build/nx_ecomat_beat.nx, verified at emit. The flywheel re-measures the board, re-ranks build targets into the assignment queue and republishes the dashboard, which serves 200 behind session auth. MEASURED 2026-08-21: it had NO clock row and NO dead-man switch, so its cadence was undeclared and a stop would have been invisible. A cron-watch row was shipped this session and VERIFIED THROUGH THE CONSUMER at last_ts 1787331884 exactly matching the log tail, then bite-proven both directions on an isolated fixture. A plane row, not a binary, so there is no hash to claim Adoption: RUN-BY:cron — fully adopted (top of its ladder).
Standing CONFLICT is adjudicated, not merely countedMeasured: el_last_green exists in runtime/_hdl_build/nx_ecomat_lib.nx, verified at emit. MEASURED 2026-08-21: the one CONFLICT is hosting. Witness one is site liveness reading GREEN, witness two is the product functional census reading RED at 5 of 29. Both are live and both are correct. This is a SUBJECT MISMATCH, not an instrument fault: one measures reachability, the other measures function, and triangulation is defined over independent witnesses OF THE SAME SUBJECT. The MIN is the right grade and the LABEL is wrong -- we do know the answer, which is that it serves and it does not function Adoption: LIB-WIRED importers=21 nonval=13 — fully adopted (top of its ladder).
One evidence log is the sole witness for three domain subjectsOpen — watching runtime/_hdl_build/nx_ecomat_lib.nx : em_subject_declare, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. MEASURED 2026-08-21 and this is the root of the CONFLICT above: the product functional census is BOTH the second witness for hosting AND the only witness for network, while site liveness is also a witness for sites. A product-surface check is being read as evidence about hosting and about networking. THE CONTRACT: every evidence pointer declares the SUBJECT it measures and the rollup refuses to triangulate two witnesses whose declared subjects differ, reporting them as two separate readings instead of one conflict
watching em_subject_declare
Plan coverage is a published row, not folkloreOpen — watching runtime/_hdl_build/nx_ecomat_lib.nx : em_plan_coverage, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. MEASURED 2026-08-21 over the whole regen list, no sampling: 70 domains, 63 carry a plan, 7 do not, and 63 plus 7 equals 70 so the partition SUMS. The 7 are foodscience, water, livingdocs, cleanserve, nishios, smallos and devguardrails. A planless domain is REFUSED by the ranker and that refusal is CORRECT BEHAVIOUR -- the missing artifact is the plan, never a broken ranker. UNMEASURED and honestly so: how many of the 63 carry a ver ladder. THE CONTRACT: emit domains-with-plan over domains-with-ladder over rankable every beat, with the partition summing, so this gap can never again be invisible
watching em_plan_coverage
The engine cannot rank what has no ladderMeasured: main exists in runtime/nx_compare_rank_fleet.nx, verified at emit. MEASURED 2026-08-21: nishios and smallos both return RANK REFUSED because no plan exists, so the operating system is not scored low, it is absent from scoring entirely and a portfolio pass omits it silently. Worse than unranked is ranked-at-zero: every toolchain rung prints UNMAPPED because no matrix row carries its symbol, so all five score 0 and sort last forever regardless of importance. The ranker echoes those ids with a leading space, so stray whitespace in the plan symbol field is the likely and cheap cause Adoption: RUN-BY:fork:nx_compare_beat — fully adopted (top of its ladder).
A long census must publish rows as they are decidedOpen — watching runtime/nx_compare_rank_fleet.nx : rf_emit_row_as_decided, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. MEASURED 2026-08-21: the estate fleet pass ran over 100 minutes and produced 73 bytes, its header alone. It was NOT hung -- state S, wchan pipe_wait, and child reap counters rising monotonically across five samples proved it was reaping children throughout. The cause is structural: the whole census prints only after every domain is visited, so a run interrupted at 95 percent yields exactly what one interrupted at 5 percent does. THE CONTRACT: append each domain row as it is decided, the way the estate long sweeps already do, so an interruption costs the remainder and not everything
watching rf_emit_row_as_decided
An abstaining instrument is only honest if its consumers carry the abstentionOpen — watching runtime/_hdl_build/nx_ecomat_lib.nx : em_axes_known_guard, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. MEASURED 2026-08-21: the autonomy meter abstains CORRECTLY, printing axes_known 3 of 4 unscorable 1 verdict PARTIAL, because axis a3 daemon-run reads minus one. But a full-corpus search finds three matches for that flag and ALL THREE ARE INSIDE THE METER. No consumer reads it, and the rollup keys its evidence row on the bare permil token, so 705 is consumed as whole. Averaging only scorable axes gives 705 grade B while all four gives 529 grade C, both present on CONSECUTIVE rows of the live ledger. THE CONTRACT: refuse to consume a PARTIAL figure without carrying its partiality
watching em_axes_known_guard
Declared cadence is not a predictor of when a beat runsOpen — watching runtime/_hdl_build/nx_ecomat_beat.nx : em_cadence_observed, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. MEASURED 2026-08-21 by subtracting observed timestamps rather than reading a plane row: site liveness is DECLARED at 3600 seconds and OBSERVED at 21569, 21606 and 21617, six times slower, while a sibling lane measured another beat declared at 86400 and observed at about 21600, four times faster. The same number from opposite directions. Many clock rows also carry a next-due already in the past by roughly 2000 seconds including rows declared at 60. THE CONTRACT: publish declared cadence beside observed interval per beat with the delta, so a drifted schedule is a row and not an archaeology exercise
watching em_cadence_observed
Grades are never hand-edited, only re-measuredMeasured: et_emit_targets_core exists in runtime/_hdl_build/nx_ecomat_lib.nx, verified at emit. The beat re-derives every grade from its live evidence source and feeds the ranked shortfall back into the build queue idempotently under a lock, so the board cannot be talked up. A Radar is a periodic human editorial judgement and an SRE review is a checklist interview; both are authored. This one is derived, and the same run that measures the gap is the run that queues the work to close it Adoption: LIB-WIRED importers=21 nonval=13 — fully adopted (top of its ladder).

Risk register

RiskLikelihood x impactMitigation
A plan-coverage row that counts a plan file as a ladder overstates rankability, because a plan with no ver rows still ranks by value alonepossible x mediumEC2 counts plan presence and ver-ladder presence as SEPARATE columns and requires both to reconcile against the rankable total, so the weaker artifact can never be counted as the stronger one.
Marking derived grades PARTIAL could flip large parts of the board to PARTIAL at once and teach readers to ignore the flagpossible x highEC3 ships the flag with the count of axes behind it, so PARTIAL always carries how partial; a permanently-red detector is one everyone learns to ignore, and a graded one is not.
Declaring a subject on every evidence pointer is a data migration across 29 slots and could strand domains mid-migrationcertain x lowEC5 treats an undeclared subject as UNKNOWN and falls back to today's behaviour for that pointer, so the migration is additive and no domain loses its current grade while it is in flight.
On these two registers. Rows are declared in the domain's plan file and carry the debt id, which is the join key back to the sovereign debt plane — that plane, not this page, is the authority on state. Reconciling them automatically (the regen reading the plane and refreshing these rows) is a named, owed rung; until it lands, treat an id here as a pointer to look up, not a status to trust.
Honest verdict. The coverage above is capability presence measured against source — not depth, scale, or polish, where mature rivals may lead. Exceeds are claimed only where a mechanism backs them. Every open gap is a watch contract: it names the organ and symbol that closes it, and this page flips the cell itself when that workstream ships.

Person · product · place — not yet measured for this domain

Every compare carries this layer. Declare knowledge/compare/ecosystem.ppp (rows surface|nishi or c1..c4|label|url|connect naming OUR live surface and each rival's front door), run nx_ppp_probe domain ecosystem, and this section fills itself on the next beat: the same ruler on both sides — privacy and CX (third-party hosts, tracker classes, cookies, security headers), design and longevity (design hygiene, computed WCAG contrast, render-blocking resources, unsized media, script weight, theme and motion queries), findability (landmarks, skip link, on-site search, breadcrumb, headings, internal links).

generated by nx_swcompare_matrix (sovereign NishiLang organ) from knowledge/compare/ecosystem.matrix · every Nishi cell verified against organ source at emit time · watch cells re-measured on every compare beat · zero JS, zero trackers