Nishi FamilyCompare › Librarian and Data Trust

Nishi Compare · measured, not asserted

Librarian and Data Trust

Nishi vs the field — every Nishi cell is measured against real organ source at emit time; each gap names the watch contract that will close it.

Nishi vs DataHub and OpenMetadata and Collibra and Atlan

Layer 1 · Executive

Where we are. The librarian and data-trust plane is structurally ahead of the catalogs: content-addressed identity (exceed), tamper-evident append-only store (exceed), silicon-up genesis lineage (exceed), C2PA-class signed provenance with deny-by-default verification (two exceeds), the no-new-TSV live guard (exceed), the format-sprawl audit (exceed), universal library foundationing of 1,314 of 1,314 docs (exceed), plus dataset lineage, dedup, freshness state machine, schema drift, compaction, BM25 over the library, the librarian review with RACI handoff and a live cross-team orchestration engine (exceed). Behind the catalogs on: applied subject classification, a RUNNING freshness beat, the MCP orchestration API, column-level lineage, contract enforcement at ingest, and a catalog UI.

Where we need to go. A library that is CLASSIFIED and BROWSABLE, kept fresh by a beat rather than a session, enforced at the door by data contracts, traced to the column, and engaged by any team through one MCP door -- on the same signed content-addressed substrate that already exceeds the field.

The unit. 1 u = one measured session-leg (estate calibration: graphics R21 in one leg 2026-08-15). Local evidence: library foundationing (1314/1314, resumable) and the orchestration engine (13/13, proven live) each landed in one leg; estimates are relative to those.
Where we are: 6 open rungs. Trust substrate exceeding; curation, cadence and surfaces behind. Counts measured at emit below this line.
Cost to a living library: 1 u. LI1 the freshness beat -- the organs exist, nothing runs them on a cadence.
Cost to a browsable catalogue: 3.5 u. LI2 applied subject classification of the whole corpus, LI3 the catalog UI over it.
Cost to trust depth and autonomy: 6 u. LI4 contract enforcement at ingest, LI5 column-level lineage, LI6 the MCP orchestration door.

Research bar. DataHub and OpenMetadata is measured on column-level lineage, catalog UI, freshness SLAs. Theirs: the open-source catalog bar. Ours: LI2 LI3 LI5 measured on this page.

Research bar. Collibra and Atlan is measured on data contracts, active metadata, agentic engagement. Theirs: the enterprise bar. Ours: LI4 LI6.

Research bar. OpenLineage is measured on the lineage model. Theirs: the interchange reference. Ours: LI5.

22 of 30 capabilities measured|15 of them measured exceeds|8 open|coverage 733/1000|adoption 13 full / 9 partial

Layer 2 · Roadmap

Do this next — computed by the ranker, never chosen by a seat

Order from nx_compare_rank (nx_dr_ocm: (deficit + cost-of-delay + option + enables) x sponsor x self-sufficiency x momentum / cost). FINISH rows are rungs whose symbol is present but whose organ is short of full adoption: the cheapest closures on this board, listed before any new work. Stamp: # asof=1787883490 domain=librarian target_version=0.1 rungs=14 done=6 open=8 finish=2 ranker=nx_dr_ocm

#StageRungPriorityDerivation
FFINISHUniversal foundationing (LQ2) lf_runREGISTERED-DARKcallable, authorised, no MCP invocation on record (a direct fork logs the runner, so this is not proof it never ran); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
FFINISHLibrarian review (LQ4) lr_runLIB-GATE-ONLY importers=1imported only by validation organs (gates, tests, benches): wire it into a shipping program
#10.1Freshness beat (LI1) lfr_run_beat3200v=16 m=2 c=10
#2laterApplied subject classification (LI2) lbc_classify_doc1700v=17 m=2 c=20
#3laterMCP orchestration door (LI6) oapi_engage1600v=12 m=2 c=15
#4laterContract enforcement at ingest (LI4) ic_enforce_contract1500v=15 m=2 c=20
#5laterColumn-level lineage (LI5) fld_column_edge1280v=16 m=2 c=25
#6laterCatalog discovery UI (LI3) lbs_catalog_page1066v=16 m=1 c=15
#7laterLicence text acquired for the unread rows (LX1) aq_license_fetch266v=2 m=2 c=15
#8laterUpstream rot watch over acquired works (LX2) aq_rot_scan0v=0 m=1 c=15

Critical path — contract, done-rule, executor, cost

RungCloses withDefinition of done (pre-declared)ExecutorEst.
Content-addressed identity (LQ0)cid_ofThe datum IS its sha256 -- LANDEDOrgan0 u
Signed provenance, deny-by-default verify (LQ1)
after LQ0
prov_verifyTamper, rebind, wrong-key all reject, gate 9/9 -- LANDEDOrgan0 u
Universal foundationing (LQ2)
after LQ1
lf_run1314/1314 docs CID plus sign plus god-trace -- LANDEDOrgan0 u
Cross-team orchestration engine (LQ3)orch_engageRACI-resolved dispatch proven live -- LANDED 13/13Organ0 u
Librarian review (LQ4)lr_run1326 docs reviewed, handoff written -- LANDEDOrgan0 u
Freshness beat (LI1)
after LQ4
lfr_run_beatnx_research_freshness plus shelf_life on the clock plane with a receipts partition per run; gate proves a doc aged past its shelf life is flagged on the next beat and the journal row existsOrgan1 u
Applied subject classification (LI2)
after LQ2
lbc_classify_docEvery foundationed doc assigned shelf and facets by the existing shelf organs, the whole corpus not a sample, unclassifiable docs named not bucketed; gate proves the partition classified plus unclassifiable equals 1314 and a known doc lands on its known shelfOrgan2 u
Catalog discovery UI (LI3)
after LI2
lbs_catalog_pageA live /librarian page browsing LI2's shelves and facets with CID, signature state and freshness per doc, zero-JS; gate proves the page serves over the edge and every link resolvesOrgan1.5 u
Contract enforcement at ingest (LI4)
after LQ0
ic_enforce_contractA declared contract per plane (fields, types, required) checked at the door by the drift detector's kinds; a violating row is refused with the field named; gate proves a planted bad row is refused and the current planes pass their derived contractsOrgan2 u
Column-level lineage (LI5)
after LQ0
fld_column_edgeField-to-field edges for the producer and consumer organs the store lineage already walks, from the organs' own read and write sites; gate proves a fixture producer-consumer pair yields the right column edges and the partition of fields traced plus untraced is printedOrgan2.5 u
MCP orchestration door (LI6)
after LQ3
oapi_engagenx_orchestrate's engage verb on the MCP surface so a call engages a team to run a workstream and returns the dispatch receipt; gate proves a call over the edge dispatches the librarian review and an unknown activity is refusedOrgan1.5 u
Licence-evidence door for external works (LX0)
after LQ0
aq_decideEvidence class NONE DECLARED READ gates mirror and redistribute independently, attribution is an obligation that never abstains, and a read refusal outranks an abstention -- LANDED, gate 25/25 with three bite-proven neg-controls and one compiling mutant killed (not_reached=0)Organ0 u
Licence text acquired for the unread rows (LX1)
after LX0
aq_license_fetchFor every acquire_sources.conf row at evidence=NONE, fetch the upstream LICENSE into our own mirror, pin its digest and lift the row to READ so its bytes become mirrorable; gate proves a row cannot reach READ without a mirrored licence file whose digest is pinned, and that a fetch failure leaves the row at NONE rather than advancing itOrgan1.5 u
Upstream rot watch over acquired works (LX2)
after LX1
aq_rot_scanRe-probe every acquired upstream URL on a beat and record DISAPPEARED versus CHANGED versus INTACT against the pinned digest we hold, so the library can prove it still holds a work its source no longer serves; gate proves a source that stops resolving is reported DISAPPEARED while our held bytes still verifyOrgan1.5 u

Milestones

MilestoneRungsCumulative
M1 · LivingLI11 u
M2 · BrowsableLI2,LI34.5 u
M3 · Enforced, traced, engagedLI4,LI5,LI610.5 u
Layer 3 · Engineering
How this is scored. Every Nishi mark is measured: the generator reads the real organ source on disk and requires the implementing symbol to exist (no self-grading). A watching tag names the organ and symbol contracted to close a gap — the mark flips itself on the next compare beat when that workstream ships, and the comparewatch- plane row flips with it. The flip is necessary, not sufficient: it proves the symbol exists, never that the capability is good. The bar is the rung's pre-declared done-rule, proven by its gate — a symbol shipped without the behaviour behind it is a defect, and the flip is exactly what makes that defect visible instead of quiet. Competitor marks record documented capability presence — presence, not depth or scale. Adoption is measured too: every measured row carries where its organ stands on the estate's ladder (source → built → promoted → registered → invoked; libraries by importer reach minus validation importers; gates by the execution surfaces that run them). A row is fully adopted only at the top of its ladder; anything short is tagged partial with the exact remedy, so a build nobody promoted can no longer read as shipped. Census stamps: importers asof 1787849099, gate census asof 1787855507 (unix seconds; -1 = census absent).

Capability matrix — measured against source

leads / measured exceed present partial absent · click any capability for its evidence

CapabilityNishiDataHubOpenMetadataCollibraAtlan
Content-addressed dataset identity (CID)Measured exceed: cid_of in runtime/nx_canon_cid.nx, verified at emit. The datum IS its sha256 (nxc1-...) [multiformats-cid]; catalogs use mutable URNs pointing at external stores Adoption: LIB-WIRED importers=111 nonval=86 — fully adopted (top of its ladder).
Tamper-evident append-only storeMeasured exceed: ss_commit in runtime/nx_seg_store.nx, verified at emit. History is sacred, additive segs; catalogs are metadata over mutable warehouses Adoption: LIB-WIRED importers=441 nonval=321 — fully adopted (top of its ladder).
Dataset lineage graph (producer/consumer)Measured: ln_walk exists in runtime/_hdl_build/nx_store_lineage.nx, verified at emit. Live getdents walk of organ producer/consumer edges; the incumbents lead depth (parsed SQL, runtime capture) [openlineage-model] Adoption: BUILT-UNPROMOTED — PARTIAL: compiled, never promoted to the serving root: /api/promote it.
adoption BUILT-UNPROMOTED
Trace-to-god silicon-up genesis lineageMeasured exceed: gl_validate in runtime/_hdl_build/nx_genesis_lineage.nx, verified at emit. Every artifact traces parent-by-parent to ORIGIN (hardware); no data catalog traces below the warehouse Adoption: BUILT-UNPROMOTED — PARTIAL: compiled, never promoted to the serving root: /api/promote it.
adoption BUILT-UNPROMOTED
Cryptographically-signed provenance (C2PA-class)Measured exceed: prov_make in runtime/nx_asset_provenance.nx, verified at emit. NXPC1 ed25519 credential binding CID+source+date; catalogs store mutable metadata, not signed credentials [c2pa-spec] Adoption: LIB-WIRED importers=5 nonval=2 — fully adopted (top of its ladder).
Deny-by-default provenance verificationMeasured exceed: prov_verify in runtime/nx_asset_provenance.nx, verified at emit. Verify returns 1 ONLY if framing intact AND sig verifies AND entity==CID; tamper/rebind/wrong-key all reject (gate 9/9) Adoption: LIB-WIRED importers=5 nonval=2 — fully adopted (top of its ladder).
Content dedup and cross-topic flagsOpen — no implementing organ is measured for this axis yet. Full-doc fingerprint dedup + two-topics-same-source flags
Freshness / staleness reviewMeasured: rf_puts exists in runtime/_hdl_build/nx_research_freshness.nx, verified at emit. Moving/static/constant state machine; Collibra/Atlan have richer freshness SLAs [atlan-docs] Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, no MCP invocation on record (a direct fork logs the runner, so this is not proof it never ran); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).
adoption REGISTERED-DARK
No-new-TSV migration governance (live guard)Measured exceed: sg_w in runtime/_hdl_build/nx_sov_guard.nx, verified at emit. Live RED on any unlisted new .tsv (10 violations now); catalogs assume clean data already lands in the warehouse Adoption: BUILT-UNPROMOTED — PARTIAL: compiled, never promoted to the serving root: /api/promote it.
adoption BUILT-UNPROMOTED
Schema drift detectionMeasured: nx_drift_kind_name exists in runtime/nx_schema_drift_detector.nx, verified at emit. Detects drift kinds; the incumbents enforce contracts and alert downstream owners [collibra-docs] Adoption: LIB-UNIMPORTED — PARTIAL: nothing imports it: wire it into a consumer or retire it.
adoption LIB-UNIMPORTED
Store compaction and retentionMeasured: ss_compact exists in runtime/nx_seg_store.nx, verified at emit. ss_compact reclaims superseded segs; enterprise catalogs have policy-driven lifecycle Adoption: LIB-WIRED importers=441 nonval=321 — fully adopted (top of its ladder).
Ed25519 signatures on recordsMeasured: ed25519_parse_sig exists in runtime/nx_ed25519.nx, verified at emit. Sovereign signature primitive [rfc8032]; Collibra signs via enterprise PKI integrations [collibra-docs] Adoption: SOURCE-ONLY — PARTIAL: source exists, never compiled: /api/build it.
adoption SOURCE-ONLY
Library ingest and inverted indexMeasured: nx_inv_build_from_jsonl exists in runtime/nx_search_inverted.nx, verified at emit. BM25 over the library; incumbents have elastic-scale discovery search Adoption: LIB-WIRED importers=38 nonval=32 — fully adopted (top of its ladder).
Format-sprawl audit instrumentMeasured exceed: la_scan_dir in runtime/nx_librarian_audit.nx, verified at emit. Mechanically classifies every file native-vs-legacy; catalogs profile schemas, not on-disk format sovereignty Adoption: LIB-GATE-ONLY importers=1 — PARTIAL: imported only by validation organs (gates, tests, benches): wire it into a shipping program.
adoption LIB-GATE-ONLY importers=1
Applied subject classification of the whole libraryOpen — watching runtime/nx_librarian_classify.nx : lbc_classify_doc, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. The Dewey-decimal for our data [dewey-oclc]: shelf/facet organs EXIST but the corpus is NOT classified/browsable; incumbents auto-classify + glossary
watching lbc_classify_doc
Running freshness management (scheduled review+re-mine)Open — watching runtime/nx_librarian_freshness_run.nx : lfr_run_beat, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. nx_research_freshness+shelf_life exist but are NOT scheduled/running; incumbents have freshness SLAs + quality monitors
watching lfr_run_beat
Librarian auto-reviews ingested material + RACI handoffMeasured: lr_run exists in runtime/nx_librarian_review.nx, verified at emit. ORCH-R1 gated: librarian reviewed 1326 docs, flagged 239 not-up-to-scruff, wrote R=librarian/C=researcher handoff to seg-store; remaining = auto-TRIGGER from the researcher bank + MCP API Adoption: LIB-GATE-ONLY importers=1 — PARTIAL: imported only by validation organs (gates, tests, benches): wire it into a shipping program.
adoption LIB-GATE-ONLY importers=1
Cross-team RACI orchestration engine (call/resolve/dispatch)Measured exceed: orch_engage in runtime/nx_orchestrate.nx, verified at emit. ORCH-R3 gated 13/13 + PROVEN LIVE: nx_orchestrate organize run -> resolved RACI from nishi_raci.tsv (A=librarian) -> dispatched -> librarian workstream RAN (1329 reviewed); denies unknown activities. No data catalog dispatches teams by RACI Adoption: RUN-BY:cron — fully adopted (top of its ladder).
MCP orchestration APIs (call API -> team -> workstream)Open — watching runtime/nx_orchestrate_api.nx : oapi_engage, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. The keystone for autonomy: no standard MCP API that engages a team to run a workstream; incumbents ship agentic active-metadata [atlan-docs]
watching oapi_engage
Column/field-level lineageOpen — watching runtime/nx_field_lineage.nx : fld_column_edge, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Our top data-trust gap; DataHub/Collibra trace column-to-column [datahub-lineage]
watching fld_column_edge
Data-contract enforcement at ingestOpen — watching runtime/nx_ingest_contract.nx : ic_enforce_contract, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Detect exists (drift) but not enforce-at-the-door; contracts are the 2025/26 frontier
watching ic_enforce_contract
Catalog discovery UI surfaceOpen — watching runtime/nx_librarian_serve.nx : lbs_catalog_page, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. No live /librarian browse page yet; the incumbents ARE catalog UIs [openmetadata-docs]
watching lbs_catalog_page
Universal library foundationing (CID+sign+god-trace)Measured exceed: lf_run in runtime/_hdl_build/nx_library_foundation.nx, verified at emit. Every library doc content-addressed + ed25519-signed + traced to god; 1314/1314 foundationed GREEN (resumable OOM-safe); no data catalog signs AND silicon-traces every ingested doc Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, no MCP invocation on record (a direct fork logs the runner, so this is not proof it never ran); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).
adoption REGISTERED-DARK
Licence-EVIDENCE class gating rights at ingest (declared vs read)Measured exceed: aq_decide in runtime/nx_acquire_lib.nx, verified at emit. An UNREAD licence ABSTAINS and can never grant. Measured on the NAVER LABS Europe listing 2026-08-25: 2 of 26 releases carry any licence string (77 permil), both prose not a field, so a catalog that stores a licence STRING is storing an upstream assertion as if it were a fact. Gate 25/25 (now 40/40 with fixity), three bite-proven neg-controls, one compiling mutant killed. DRIVEN LIVE by runtime/nx_acquire.nx over the real NAVER LABS registry: rows=26 clear=1 review=25 refuse=0 malformed=0 sum=26 partition=RECONCILES, with naverlabs_anny carried the whole way -- listing page mirrored, licence URL derived, licence FETCHED and READ (Apache-2.0 confirmed by reading, not by the listing's assertion), pinned and SWHID'd -- and every other row honestly at REVIEW Adoption: LIB-WIRED importers=2 nonval=1 — fully adopted (top of its ladder).
Four independent verdicts per external work (mirror, redistribute, learn, attribute)Measured exceed: aq_res in runtime/nx_acquire_lib.nx, verified at emit. They fail apart in practice: collapsing them is how a work gets mirrored for study then accidentally republished. Attribution is modelled as an OBLIGATION that takes the MAX and never abstains, so I-could-not-look can never lighten a duty; catalogs model licence as a tag, not as a duty with a direction Adoption: LIB-WIRED importers=2 nonval=1 — fully adopted (top of its ladder).
Rights refused unless the licence row is CONFIRMEDMeasured exceed: lg_eval in runtime/nx_licgate_lib.nx, verified at emit. verified was parsed into the table, printed by list, and never consulted by the verdict until 2026-08-25 -- sdxl-base-1.0 returned SHIP_OK exit=0 from a row the table itself marks UNCONFIRMED. Unverified rows now cap at CONDITIONAL, a strict tightening measured to move exactly one model and only toward REVIEW Adoption: LIB-WIRED importers=2 nonval=2 — fully adopted (top of its ladder).
Licence text acquired into our own mirror for the unread rowsOpen — watching runtime/nx_acquire_license.nx : aq_license_fetch, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. 24 of 26 acquire_sources.conf rows sit at evidence=NONE and their bytes are therefore unmirrorable by our own door; the remedy is to fetch each upstream LICENSE into the mirror and pin its digest, which is the only thing that can lift a row to READ
watching aq_license_fetch
Byte-length fixity beside every digest (the truncation a pin cannot see)Measured exceed: aq_fixity in runtime/nx_acquire_lib.nx, verified at emit. A digest answers are-these-the-bytes-I-hashed. Only a LENGTH answers are-these-ALL-the-bytes. A body truncated in transit whose digest was then computed on what ARRIVED verifies CLEAN, and researched Aug-2026 neither in-toto DigestSet nor SPDX verifiedUsing carries a byte length anywhere, so both are structurally blind to it. Our provenance row already carried bytes beside sha256 and nothing read it. Gate 40/40 with the truncation case BITE-PROVEN, and three states so an unrecorded length can never read as MATCH Adoption: LIB-WIRED importers=2 nonval=1 — fully adopted (top of its ladder).
Digest shape DERIVED from its algorithm rather than assertedMeasured exceed: aq_digest_shape_ok in runtime/nx_acquire_lib.nx, verified at emit. The expected hex length comes from the algorithm that produced the digest, never a hand-picked constant. Measured in the field: the Croissant specification's own canonical FileObject examples put six values in a property named sha256, of which four are 32 hex characters (an MD5 length) and one is 40, so a validator that recomputes SHA-256 fails the specification's own examples. A field named for one hash routinely carries another, so the NAME is a claim and the LENGTH is the check Adoption: LIB-WIRED importers=2 nonval=1 — fully adopted (top of its ladder).
Forge-independent ISO-standard identity (SWHID)Measured exceed: swhid_cnt in runtime/nx_swhid_lib.nx, verified at emit. ISO/IEC 18670:2025, spec V1.2. Computed from the file BYTES alone -- no filename, no path, no mtime -- so ANYONE can recompute it and confirm our copy is the same object Software Heritage holds, with no registry and no hosting forge in the loop. That is the anti-rot property: the pointer can die and the identity survives. SPDX 2.3 Annex F accepts swh as a Persistent-Id and DataCite 4.7 added it as a relatedIdentifierType, so one identifier reads in two ecosystems. Gate 18/18 against NINE differential vectors produced by git 2.49.0, an INDEPENDENT implementation rather than values we asserted; blob framing bite-proven; one compiling mutant killed. Carried BESIDE our sha256 and byte length and never instead of them: SHA-1 has chosen-prefix collisions since SHAttered 2017, so a SWHID is an interoperable NAME and never tamper evidence Adoption: LIB-WIRED importers=3 nonval=2 — fully adopted (top of its ladder).

Risk register

RiskLikelihood x impactMitigation
A classifier that shelves by title fills the catalogue with confident wrong shelvespossible x mediumLI2 names unclassifiable docs and publishes precision on a labelled sample before the catalogue goes live.
Contract enforcement on live planes refuses a writer mid-flightpossible x highLI4 derives contracts from the current planes first (zero refusals at birth) and tightens by declaration.
On these two registers. Rows are declared in the domain's plan file and carry the debt id, which is the join key back to the sovereign debt plane — that plane, not this page, is the authority on state. Reconciling them automatically (the regen reading the plane and refreshing these rows) is a named, owed rung; until it lands, treat an id here as a pointer to look up, not a status to trust.
Honest verdict. The coverage above is capability presence measured against source — not depth, scale, or polish, where mature rivals may lead. Exceeds are claimed only where a mechanism backs them. Every open gap is a watch contract: it names the organ and symbol that closes it, and this page flips the cell itself when that workstream ships.

Person · product · place — not yet measured for this domain

Every compare carries this layer. Declare knowledge/compare/librarian.ppp (rows surface|nishi or c1..c4|label|url|connect naming OUR live surface and each rival's front door), run nx_ppp_probe domain librarian, and this section fills itself on the next beat: the same ruler on both sides — privacy and CX (third-party hosts, tracker classes, cookies, security headers), design and longevity (design hygiene, computed WCAG contrast, render-blocking resources, unsized media, script weight, theme and motion queries), findability (landmarks, skip link, on-site search, breadcrumb, headings, internal links).

References

Beyond a link list. Every reference below resolves twice — the publisher's copy and, where banked, the estate's own non-rottable library mirror with a content pin — and carries its evidence class plus the exact claim on this page it grounds. Keyed marks like [key] in the matrix notes jump here. A dash means honestly absent, never assumed.
  1. [datahub-lineage] DataHub. About DataHub Lineage -- table-level and column-level lineage (column-level lineage tracks changes and movements for each specific data column, contrasted with table-level lineage). Vendor documentation. publisher · read in our library knowledge/fetched/cmp_librarian_datahub_lineage.html · pin h6eaec6259b5bfcf0fca5dcfd04ffe4a988d934bd39c92337c65fba3ba86dddfa · accessed 2026-08-18 · vendor-docGrounds: The DataHub column: Best on "Dataset lineage graph (producer/consumer)" and "Column/field-level lineage" (our top data-trust gap, _ABSENT_ nx_field_lineage) -- the documented column-to-column lineage is exactly what the row note credits DataHub with tracing.
  2. [openmetadata-docs] OpenMetadata. OpenMetadata Documentation -- unified platform for data discovery, lineage, and governance (open source). Vendor documentation. publisher · read in our library knowledge/fetched/cmp_librarian_openmetadata.html · pin hd4e132ee502f657d8fd9c8ccc29c2e7ac9047d404beb9a5328e693826f4996f1 · accessed 2026-08-18 · vendor-docGrounds: The OpenMetadata column codes (Best on lineage, discovery search, classification and catalog UI): the documentation front page names discovery, lineage and governance as the product's three pillars, which is the capability set those Best codes describe.
  3. [collibra-docs] Collibra. Collibra Platform documentation home (Collibra Platform and Collibra Platform Self-Hosted). Vendor documentation. publisher · read in our library knowledge/fetched/cmp_librarian_collibra.html · pin hee1af656d118ee5e145bfc1a2a17b3747b4738ee6a3914009cb27f951a55b882 · accessed 2026-08-18 · vendor-docGrounds: The Collibra column: Best on "Schema drift detection" (contracts and downstream alerts), "Column/field-level lineage" and "Data-contract enforcement at ingest", Part on "Cryptographically-signed provenance" and "Ed25519 signatures on records" (enterprise PKI integrations) -- the enterprise governance platform the row notes name as the comparator.
  4. [atlan-docs] Atlan. Atlan Documentation (active-metadata data catalog). Vendor documentation. publisher · read in our library knowledge/fetched/cmp_librarian_atlan.html · pin h613240a821de378135163faad92ed2c709359c8edcf0c0b0e9dea98a7042aff9 · accessed 2026-08-18 · vendor-docGrounds: The Atlan column: Best on "Freshness / staleness review" and "Schema drift detection", Part on "MCP orchestration APIs" (the note: incumbents ship agentic active-metadata) -- the documentation root is the vendor page those codes are graded against.
  5. [c2pa-spec] Coalition for Content Provenance and Authenticity. C2PA Technical Specification 2.2 (Content Credentials): manifests, claims and signed assertions bound to an asset. publisher · read in our library knowledge/fetched/cmp_librarian_c2pa.html · pin ha1f401d240c28cae005e228ae80825b357856ea7d20c7e1118673bfdfc603e3e · accessed 2026-08-18 · published-standardGrounds: The "Cryptographically-signed provenance (C2PA-class)" exceed row: NXPC1 (nx_asset_provenance prov_make) is a signed credential binding CID plus source plus date, the same class of artefact this specification defines; the row grades our sovereign credential against the published one and codes the catalogs No because they store mutable metadata, not signed credentials.
  6. [rfc8032] Josefsson, S., Liusvaara, I. RFC 8032: Edwards-Curve Digital Signature Algorithm (EdDSA). IETF, January 2017. publisher · read in our library knowledge/fetched/cmp_librarian_rfc8032.html · pin h253cd2a103b528e92ee4bd5c8cbf472c7e4c4e16fdcfc2acb10201a8d72414aa · accessed 2026-08-18 · published-standardGrounds: The "Ed25519 signatures on records", "Deny-by-default provenance verification" and "Universal library foundationing (CID+sign+god-trace)" rows: nx_ed25519 implements this RFC's Ed25519 signature scheme sovereignly, and every foundationed library doc is signed under it (the estate's ed25519 extvec gate verifies against this RFC's vectors).
  7. [multiformats-cid] Protocol Labs / multiformats. CID -- self-describing content-addressed identifiers for distributed systems (specification repository). publisher · read in our library knowledge/fetched/cmp_librarian_multiformats_cid.html · pin h4be3cb5091d90726cde985a17695e491e0f30cb23ee4db1145bb1c6bbb0f3496 · accessed 2026-08-18 · published-standardGrounds: The "Content-addressed dataset identity (CID)" exceed row: the datum IS its hash (nxc1-... from nx_canon_cid cid_of) -- the published CID scheme is the reference class for content addressing, against which the catalogs' mutable URNs pointing at external stores are graded No.
  8. [openlineage-model] OpenLineage. Object Model -- Job, Run and Dataset entities extended through facets (schema, dataSource, version, dataQualityMetrics at dataset and column level). Open lineage standard. publisher · read in our library knowledge/fetched/cmp_librarian_openlineage.html · pin hb4479ce9dc49f895028315ba05ecc51887a11bb5756ee24c210193ffc49eb118 · accessed 2026-08-18 · published-standardGrounds: The "Dataset lineage graph (producer/consumer)" and "Column/field-level lineage" rows: the open lineage object model is what the incumbents' runtime lineage capture speaks (the row note: parsed SQL, runtime capture); our ln_walk is a getdents walk of organ producer/consumer edges, honestly Yes not Best.
  9. [dewey-oclc] OCLC. Dewey Services -- the Dewey Decimal Classification, the library-world subject classification scheme. Vendor page. publisher · read in our library knowledge/fetched/cmp_librarian_dewey.html · pin h6f69c442a8724865ba988e4e40dc6aa77bc943279022707031379428a9b586c7 · accessed 2026-08-18 · vendor-docGrounds: The "Applied subject classification of the whole library" row (the note: the Dewey-decimal for our data; shelf/facet organs EXIST but the corpus is NOT classified/browsable): Dewey is the named model for the _ABSENT_ nx_librarian_classify watch, and the incumbents' auto-classify plus glossary is the Best code it is graded against.

generated by nx_swcompare_matrix (sovereign NishiLang organ) from knowledge/compare/librarian.matrix · every Nishi cell verified against organ source at emit time · watch cells re-measured on every compare beat · zero JS, zero trackers