# AppStore2031 future-native forecast method

**Status:** active research method for the local draft; not frozen
**Target:** July 2031  
**Method family:** workflow-separated future-world generation followed by a
dated current-market and published-concept collision audit  
**Supersedes:** withdrawn continuity-led method v1

## 1. Forecast question

What new categories and Top 10 marketplace listings could plausibly dominate a
first-party mobile or successor software marketplace in July 2031 after five
years of interacting technological, economic, social, environmental,
demographic and geopolitical change?

The ranked object is a **marketplace listing**, not necessarily a conventional
downloadable phone app. A listing may resolve to a native application, agent,
capability pack, persistent companion, synthetic environment, autonomous
organisation interface, robot service, protocol client or another first-party
marketplace unit that becomes normal by the target date.

The public interface uses fictional products to make the forecast tangible.
The forecastable object underneath each product is a bounded archetype with
observable inclusion and exclusion criteria.

## 2. What this method is designed to prevent

The method must not:

- begin with current app categories, incumbents or the previous inventory;
- generate a present-day product and add AI, privacy, provenance,
  interoperability or a new payment rail as decoration;
- assume that uncertainty makes a consequential future unimportant;
- turn policy ambition into delivered adoption;
- make one region a proxy for the world;
- make one technology, institution, company or product a mandatory answer;
- preserve an old category, listing, probability or rank by default; or
- use the dated collision audit as creative inspiration for candidate generation.

## 3. Evidence boundary

Every factual premise has an evidence cutoff. Records distinguish:

- observed deployment or behaviour;
- measured trend;
- modelled projection;
- expert elicitation;
- policy target or institutional intent;
- weak signal;
- design inference;
- scenario assumption; and
- explicit unknown.

Sources retain publisher, URL, publication and access dates, geography,
language and translation method, evidence class, limitations and status.
Contradictory, rejected and superseded evidence remains visible.

A source can support a present condition, trend or scenario branch. It cannot
prove a fictional product, future category or precise rank.

## 4. Workflow-separated sequence

The forecast is produced in seven separated stages. Later-stage information
must not leak backwards.

This is workflow separation, not a claim that an AI starts with a blank mind.
Authors are not supplied the previous catalogue, current-market comparison
corpus, audit findings, rejected or other candidates, or ranks, and active
retrieval of those materials is blocked before sealing. Model pretraining and
unavoidable developer and workspace context still exist and are disclosed as
a limitation.

### Stage A — horizon scan

Independent scanners examine changes across at least:

- AI, compute and autonomous agency;
- economy, work, firms, ownership and finance;
- health, biotechnology, care and demography;
- education, relationships, culture, attention and meaning;
- energy, climate, food, water and materials;
- robotics, mobility, manufacturing, spatial systems and interfaces; and
- geopolitics, governance, security, identity and public infrastructure.

The scan looks ahead, across unfamiliar sources and beyond one culture. It
records Horizon 1 conditions, weak signals, potential Horizon 3 conditions,
counterforces, unknowns and measurable signposts. It does not propose apps or
categories.

### Stage B — cross-impact futures

Scenario builders receive only the horizon-scan evidence. They identify:

- key variables and structural assumptions;
- reinforcing and conflicting pairs of disruptions;
- second- and third-order consequences;
- changed scarcities and newly abundant resources;
- new rights, liabilities, institutions and economic actors;
- regional divergence; and
- conditions that would make each world internally inconsistent.

They create multiple coherent 2031 worlds using morphological and cross-impact
analysis. At least one world must represent constrained progress, at least one
transformative machine capability, and at least one material institutional or
geopolitical discontinuity. These are not optimism/pessimism variants of one
base case.

No scenario receives a probability merely to force a consensus. Where credible
external forecasts exist, their distributions and disagreements are shown as
evidence, not collapsed into false precision.

### Stage C — changed actors and needs

Needs researchers receive the world packets but no current-app baseline,
previous taxonomy or previous inventory. For each world they identify:

- who or what can act;
- what those actors control, own, owe, fear and value;
- which present institutions have weakened, merged or disappeared;
- which activities have become cheap, abundant, scarce or compulsory;
- new coordination, trust, identity and relationship problems; and
- behaviours repeated frequently enough to support marketplace discovery.

Actors may include people, households, communities, human-machine teams,
synthetic persons, autonomous agents, autonomous organisations, public bodies,
robot fleets and networked infrastructure. The list is illustrative, not a
quota.

### Stage D — marketplace ontology and categories

Taxonomy builders receive the changed-actor and changed-need records. They do
not see current app categories or the previous taxonomy.

They determine:

- what a marketplace distributes in each world;
- which units deserve independent listings;
- how people or agents discover and trust them;
- which recurring purposes form distinct browse categories; and
- which categories exist across worlds or only under named conditions.

A Stage D category is provisional. It qualifies for candidate research when
all of these are true:

- it gives a coherent recurring reason to browse;
- at least one marketplace unit could plausibly be distributed and chosen as
  an independent listing;
- its purpose traces to changed Stage C needs rather than a familiar category
  name; and
- its inclusion, exclusion, collision and July 2031 resolution rules are
  observable.

There is no minimum number of needs or jobs at Stage D. Needs and products are
many-to-many: one product may answer several needs, and several genuinely
different products may answer the same need. A masked-field collision check may keep
two products for the same need only when their indispensable capability,
service model, actor relationship, delivered experience or liability and
failure structure is materially different. A different name, provider, price,
region, visual skin or technology label is not a material difference.

Category count is research-derived. A provisional category becomes a
publishable chart only after Stage F leaves at least ten pairwise-distinct,
independently audited `future-dependent-no-collision-found` candidates. Stage G
selects and ranks exactly ten. Stage D never manufactures
ten jobs to justify a chart.

Public rights and accountable decisions remain outside a listing. A product
may execute, coordinate, translate, evidence, deliver, simulate, monitor or
support under external authority. It may not itself confer a legal right or
permission, set public priorities, exercise command or professional judgement,
make settlement final, or issue an official remedy. The category and candidate
records must say where that accountable authority sits. A listing does not
need to complete the whole sovereign or institutional outcome to count.

### Stage E — future-native candidate generation

Stage E starts from the hash-bound corrected Stage D synthesis manifest. A
candidate author receives the exact canonical category, only the worlds shared
by that category and one assigned actor need, the full hash-bound need, one
material-difference brief, the public-authority boundary, the exact Stage D
workflow-separation disclosure and source receipts, and the authoring guide.
They do not retrieve current products, current app charts, previous listings,
previous ranks, archived/rejected Stage D material or other candidate sets.
Ambient pretrained knowledge may exist, but it is not task evidence.

Each candidate specifies:

- the new actor and job;
- the changed 2031 condition that creates the job;
- the complete user or agent experience;
- essential capabilities and disqualifiers;
- distribution and business or funding model;
- dependencies and readiness path;
- consequences if an enabling condition fails;
- scenario fit and regional variation;
- potential benefit, potential harm and likely abuse;
- update signals and resolution criteria; and
- a plain-language explanation for a 16-year-old reader.

Each provisional category receives its own external author context. That
context handles the category's complete configured reserve — 12 candidates in
the initial edition. Candidates within the same category may influence one
another, so we do not describe them as independently drafted. The defensible
separation is narrower: no category author receives the withdrawn v1 catalogue,
current-market material, prior-art findings, ranks or another category's
packets. Category author contexts are distinct from one another and from every
critic or auditor context. A later refresh derives the number of one-category
author groups and each group's candidate count from that edition's validated
dispatch; neither number is hard-coded as a permanent catalogue shape.

After grouped drafting and before the candidate tree is sealed, a separate
masked-field critic context is assigned to each category. It compares every
unordered pair inside the category — `n(n-1)/2`, which is 66 when there are 12
candidates — and also records at least one masked cross-category nearest match
for every candidate. The critic material masks names, providers, prices,
regions, skins and technology labels. This masking applies only to the supplied
review material; it does not erase pretrained or ambient knowledge. The critic
records the material difference axes and rejects unresolved duplicates. This
check does not turn the number of needs into a candidate quota.

The number of prepared candidate briefs per provisional category is an
explicitly configured reserve, not a fixed ten. One actor need may be assigned
more than once only when each brief uses a different structural axis:
indispensable capability, service model, actor relationship, delivered
experience, or liability and failure structure. Candidate and brief IDs are
always different.

Candidate authors must describe the world first and the product second. They
may not justify a product solely with a growing market or better implementation
of a current task.

Every candidate carries a structured author identity, its category batch and
author group IDs, and the unchanged hash-bound receipt for its own
category/world/need/brief packet. All candidates in one author group reference
the same group session receipt. That receipt lists every candidate ID, category
batch, packet hash, permitted output root and normalized candidate-output hash.
Validation rebuilds it from JSONL outside the edition and proves one exact
`fork_turns=none` spawn at depth one, or depth two when an approved Stage E
coordinator delegates the author spawn. The receipt records the depth and exact
parent-thread and agent-path linkage, all group inputs delivered before authoring,
one task turn, bounded writes and the ordered group output hash. Reusing that
canonical context outside its one author group fails validation. Edition-
authored actor names are labels, not independence evidence.

The author copies an exact packet-bound authorship object whose initial
`authoredAt` is only a schema placeholder. It is not time evidence. Once the
external session transcript passes, the integrator replaces that value with
the receipt's exact `taskCompletedAt` and adds the shared session pointer.
Normalised candidate hashes omit only those two mechanically integrated
metadata fields; all product, evidence, dependency, safety and future-distance
content remains bound. A canonical candidate must therefore have an
`authoredAt` equal to or later than its externally verified task completion.

Every later call after the canonical packet and scope is fail-closed: the
author can patch only the assigned output root for its one category group —
12 candidate files in the initial edition — or run bounded deterministic/status
checks. Direct unbound reads, web, MCP, collaboration, old editions, present
products and collision-audit evidence are not permitted. Every call, argument
and output is hash-bound through completion.
An allowed `functions.exec` input must match one validator-rendered canonical
source template byte-for-byte. Semantic JavaScript equivalence is not
accepted: bracket or computed properties, aliases or destructuring, unknown
globals, extra expressions or statements, and multiple calls are rejected.
The patch form contains exactly one literal `tools.apply_patch` call.
Every output patch is followed by exact deterministic validation of the
assigned root.

A natural-language classifier may flag likely product-shaping directions in
the visible task context. That classifier is a heuristic warning aid only: a
pass cannot prove semantic absence of shaping material, blindness, independent
invention or novelty. Its warning result and this limitation remain together
in the process record.

The Stage E seal is derived only after canonical validation of the repaired
Stage D ontology and the complete Stage E preparation. Its ontology binding
contains the exact publishable category IDs and hashes of the canonical Stage D
category, ontology, packet, synthesis-manifest and verification-envelope
artifacts. The candidate, dispatch, author-batch and collision sets must match
that external category universe exactly; they cannot make an omitted category
disappear by agreeing with one another.

Lifecycle advancement uses a recoverable pending journal covering both
`manifest.json` and `refresh-run.json`. Until both replacements match the
journaled target hashes, Stage F fails closed. Recovery either recognises the
complete new pair or restores both exact original byte sequences; a corrupt or
missing rollback backup leaves the journal visible and blocks later work. File
contents and the affected directory entries are fsynced around journal writes,
renames and removals. Before Stage F, validation also rereads the exact Stage E
packet, recomputes every allowed-input receipt from live bytes, and requires the
Stage E record to contain exactly the canonical packet receipt and current
candidates, collisions and seal output receipts.

### Executed final synthesis — the active Stage F-H path

The sealed candidate set is completed through the bounded ranking, listing and
name-screen method in
[From sealed research to the AppStore2031 Top 10s](FINAL_SYNTHESIS_AND_LIMITS.md).
It uses one transparent 100-point judgement frame, preserves every exclusion,
projects conditional regional rank ranges, writes the product explanation for
a 16-year-old reader and records a dated exact-name screen.

The larger transcript-bound audit and causal-simulation design below was an
attempted maximum-assurance path. Live packets exceeded the agent interface's
reliable output capacity and were repeatedly truncated. No output from those
sessions was accepted. These sections are retained as design and failure
history, not as the executed method or a requirement for refresh.

### Historical Stage F proposal — not executed

Only after candidate files are sealed do separate auditors receive them plus a
fresh market scan at the evidence cutoff. The audit is dynamic; the method
contains no permanent product or company examples.

Independent Stage F collision researchers search official stores, product
sites, open-source repositories, research prototypes and delivered
infrastructure for each candidate's central job and capability combination.
The immutable category packet derives and hashes the exact indispensable
capabilities, experience, service model, authority boundary and
future-dependent requirements from each sealed candidate. Every dynamic query
and comparison row must cite those candidate-specific anchors; a generic
category search or reusable difference statement is invalid. Each query
records its search language; a local-language query preserves the exact
searched wording in its anchor translation alongside the English terms that
bind it back to the sealed candidate.

Each candidate is searched through at least two distinct surfaces. Retained
sources preserve a first-party official/primary identity, a publication date
no later than the cutoff, exact identity/date/capability excerpts, and a hash
of the complete direct-URL open response. The external transcript receipt
recomputes the hashes and proves that every excerpt appeared in the opened
content. The identity excerpt must name the organisation, the host must own
the URL, and the date excerpt must prove the declared date. Passing evidence
normally requires two independent official or
primary organisations. An exhausted search with fewer records stays visible
as an evidence gap and mechanically returns `revise-and-reaudit`.
Each category audit retains a hash-bound packet receipt linking one structured
auditor context to the round, complete category candidate set, verified seal,
derived anchor hashes, cutoff, search limits and output root. Its external
session receipt binds the exact packet and audit output, dynamic queries,
direct URL opens and opened-content hashes. The validator uses canonical Codex
context IDs—not edition aliases—to prove fresh, disjoint author, collision
critic and auditor contexts. After packet retrieval, only canonical web search
and direct HTTPS open wrappers, one bounded output patch and deterministic
validation are allowed; arbitrary browsing, shell/filesystem reads and
collaboration calls fail.

A candidate fails when its central experience is substantially delivered or
commercially available at the cutoff and its forecast difference is mainly:

- improved quality, speed, price or scale;
- an added AI assistant;
- an added permission, provenance or audit layer;
- broader interoperability;
- a different payment rail; or
- expected mainstream adoption of an already complete product.

A candidate can survive only when a named future condition materially changes
at least one of:

- who or what the user is;
- the job being performed;
- the level or duration of autonomous action;
- the economic or ownership relationship;
- the physical or social experience;
- the institution through which the outcome is delivered; or
- what was technically, legally or economically possible at the cutoff.

Under immutable protocol `audit-v3`, the packet derives content-hash anchors
for mechanism, experience, service, authority and future dependence directly
from the sealed candidate. For every closest match, the auditor completes a
mechanism-by-mechanism matrix plus a structural matrix spanning the other four
kinds. Every matrix explanation preserves the exact anchor content hash and
substantively applies a distinctive multi-word phrase and candidate-distinctive
lexical term. The buildability case, verdict rationale and public reason each
bind and apply all five kinds. The matrix derives absent future requirements
and a cutoff-buildability assessment. A fixed `0.8` threshold then computes
the result: equivalent-buildable-now or threshold equivalence is `reject`;
uncertainty or exhausted evidence is `revise-and-reaudit`; and
`future-dependent-no-collision-found` is possible only when every closest
match lacks at least one indispensable future-dependent structural
requirement. The stored verdict must equal that computed result. Candidate and
category IDs, numbers, source/evidence labels and copied anchor text have no
semantic weight. Fingerprints remove those identities and superficial anchor
vocabulary before exact and near-clone checks, so swapped IDs, cross-candidate
anchor substitution and template reintroduction are rejected.
Cloned source, capability, difference and verdict reasoning is rejected after
that de-identification, including near-clones disguised with different labels.

Dynamic query evidence is also per-anchor rather than one free-text claim for a
list of IDs. Every `anchorMappings` row binds one exact query segment,
translation bridge and semantic rationale to one content-hash anchor. Both
authored fields independently retain multi-word material from that requirement.
When several anchors share one web query, each mapping must use at least two
terms not shared by the other mapped anchors. Reusing the candidate phrase with
one changed verb, or swapping segments and explanations between anchors, fails.
An English segment must itself carry the distinctive anchor meaning; translation
text cannot turn a generic segment into evidence. A non-English segment requires
globally unique `languageBridgeEvidence` bound to an exact excerpt from an
authoritative official or primary language source opened for the same query.
The transcript-bound excerpt must state an explicit
`[source-language] local segment => [en] English meaning` relation and the
source must separately establish the named organisation's language authority.
Juxtaposition is not translation, and one source/capability pair cannot cover
another mapping or query. A group-global semantic fingerprint also prevents an
auditor from cloning the same source, source and target languages, normalised
local segment and normalised English target relation under a new capability or
anchor ID. The external receipt proves
both excerpts occurred in the opened response.

Each Stage F web-search call carries one query and each web-open call carries one
direct HTTPS URL. A retained source binds to the exact ordered search-result
record through its query ID, one-based ordinal and canonical record SHA-256;
its `queryIds` are derived from those attributions. Receipt reconstruction then
proves that the attributed record's URL is the uniquely opened URL. Batched
opens, swapped result records and authored query labels cannot substitute for
that transcript evidence.

The last
verdict means no dated collision was found in the searched surfaces; it is not
a claim of global novelty. Rejected candidates are not shown to the original
author. A fresh replacement author receives only the assigned
category/world/need/brief packet and a generic statement that an additional
distinct candidate is required.

Every audit round archives the exact sealed candidate tree and appends a
canonical hash-chained record containing its round number, time, complete candidate
IDs and complete source-linked verdicts. A replacement receives a new ID and
new full-tree seal; its record links the rejected or revise-and-reaudit
predecessor to the successor, verified successor seal, fresh replacement
author identity, externally verified canonical context and sealed generic
packet receipt. Replacement authors cannot
be prior authors or auditors and receive no rejection or audit findings.
Only the subset of rejected or revise outcomes needed to restore the
ten-survivor floor has to be replaced; untouched reserve failures remain in
the next complete audit record.
Earlier rounds are immutable evidence. They cannot be collapsed into a
convenient final all-pass list, and the active audit must exactly match the last
round.

A category does not publish if Stage F cannot produce at least ten pairwise-distinct,
independently audited `future-dependent-no-collision-found` survivors. It returns to candidate
research or remains an unpublished provisional category; rankings are never
filled with weaker duplicates.

### Historical Stage G proposal — not executed

Only candidates with a dated
`future-dependent-no-collision-found` verdict enter ranking.

Candidates are judged independently within each coherent world and geographic
lens on:

- need intensity and frequency in that world;
- size and reach of the affected actor population;
- feasibility by 2031 conditional on that world;
- marketplace discoverability and distribution;
- repeat use, dependency or network effects;
- regulatory and infrastructure fit;
- substitutes and bundling risk;
- harmful-use and legitimacy constraints; and
- evidence quality for the causal path.

Each category/metric combination is authored in a fresh workflow-separated
context under immutable protocol `causal-judgement-v8`. The author sees the
sealed survivors, six worlds, 12 lenses and cited edition evidence, but no
other metric judgements, ranking output, previous rank, current-market
comparison corpus or storefront fiction. Exact external session receipts bind
the packet, bounded write, validation, timestamps, context identity and lack of
parent interference. One context cannot author two metrics or be reused from
an earlier workflow role.

Authors provide lower, central and upper ordinal causal-plausibility bands,
plus assumptions, falsifiers, evidence limits and a counter-case. They do not
provide decimal scores or probabilities. Citation count, prose length and
filled-field count are not positive signals. This explicitly prevents a
complete-looking candidate record from scoring well merely because it is
complete-looking.

Every record also binds content-hash anchors for the candidate mechanism, the
exact world proposition and candidate/world change, and the exact geographic
constraint and candidate/geography effect. Separate causal-chain fields must
independently preserve a distinctive multi-word fragment from every source
they claim to connect, add at least five residual concepts spanning at least
two causal roles, and bind evidence by candidate, world and geography. Exact
and order-insensitive semantic fingerprints remove the changing candidate,
world, lens, anchor, metric and band vocabulary; the semantic form also stems
inflections, groups generic synonyms and ignores grammatical word order.
Residual stems count only when they occur in explicit semantic evidence-field
allowlists for the exact row's candidate, world, lens, bound source or bound
claim. URL, identifier, provenance and other metadata never provide grounding;
all unbound stems collapse to one `unbound-concept`. Every authored causal
relation must bind locally grounded arguments on both sides, and every authored
causal consequence must have a locally grounded argument. A grounded aside
elsewhere in the clause is insufficient. Only role-token occurrences inside an
exact fully copied anchor span are exempt; repeating an anchor's causal stem
later does not inherit that exemption. Anchor-span matching is clause-local and
never crosses punctuation or `->`, while case and comma normalisation inside a
single clause remains valid. Arrow boundaries are recognised with no spaces,
one-sided spaces, ordinary spaces or tabs. Generic prose with
inserted IDs, isolated anchor terms, an anchor-and-band-swapped or paraphrased
template, numbered or unrelated-noun stuffing, repeated fingerprints or
mechanically cloned band matrices fails validation.

Present-day delivery is not a positive strength anchor. Current evidence
supports the trajectory and enabling conditions, while feasibility is assessed
at the target date conditional on the world.

The deterministic simulator samples only the independently authored ordinal
ranges. It does not add synthetic noise or derive uncertainty from citation
counts. Conditional output uses broad simulation-share bands and integer rank
ranges, not a claimed probability that a world occurs or a fictional product
exists.

The compiled judgement file is a deterministic projection, not another
authored layer. Its source-tree receipt binds every packet, output byte/value
hash, session receipt and author context. Canonical validation re-reads and
revalidates all those files, reconstructs the compiled bytes and refuses any
substituted band, prose, anchor or author pointer before ranking.

The ranking file is also a deterministic projection, not an editable result.
The compiler and production validator call the same canonical projector with
the sealed candidates, active audits, six worlds, 12 lenses and reprojected
judgements. Validation reconstructs exact pretty-JSON bytes rather than merely
checking chart shapes or self-declared hashes. A source-to-ranking receipt
chains the causal author source-tree hash to the judgement-file hash and one
category-sorted ranking leaf. Each leaf separately hashes conditional lens
charts, world charts, the main chart, sensitivity, adjacent explanations and
the complete ranking record. Self-rehashing a substituted or reordered result
does not make it canonical.

The model produces:

- one Top 10 for every category and world;
- geographic variations where evidence supports them;
- a scenario-balanced main chart that is explicitly not a probability-weighted
  global event forecast;
- rank sensitivity across alternative defensible world weights;
- confidence and the strongest counter-case; and
- the reason each listing sits above the next candidate.

The main chart may not hide a high-impact candidate solely because its enabling
world is uncertain. Scenario-specific dominance and sensitivity remain visible
beside the balanced rank.

### Historical Stage H proposal — not executed

Fresh listing authors turn each ranked candidate into clear marketplace copy,
build dependencies, harms, imagined reviews and rank explanations. They supply
three fictional name/provider options but cannot publish or collision-clear
any of them.

After the exact listing drafts are compiled, the system creates immutable
category-scoped name-auditor packets under
`fictional-name-collision-audit-v3`. Each packet binds the draft hash and
provides exact quoted name-and-provider queries for every one of the three
options across app-store, domain, company and trademark discovery surfaces.
The auditor must run in a fresh depth-one context disjoint from every listing
author, run every query exactly in its own web call, and directly open one
official or primary result in its own web call for every query. The external
receipt reconstructs this one-query/one-structured-result-record/one-open chain
from Codex session JSONL. The output binds the retained record's zero-based
ordinal and canonical SHA-256; the receipt requires that exact record, rather
than accepting a URL substring elsewhere in the response. It rejects batch
and record-order swaps, derives `accessedAt` from the exact open-output
timestamp, requires a complete date in the transcript-bound date excerpt, and
binds direct URLs, exact excerpts and opened-content hashes. It also reprojects
fixed identity and rights-conflict signals from the exact opened result. Case,
spacing, punctuation and accents are normalized before a bounded deterministic
edit-distance check; similar identities are material collisions and cannot
clear. Auditor-authored labels cannot change the decision.

Auditors never assert their own independence, choose an identity or assign a
clearance verdict. A fixed rule derives material-collision decisions from the
opened-result signals. Only after all surfaces cover all three options does
the compiler select the lowest-numbered cleared authored pair whose name and
provider remain unique in the edition. No eligible cleared pair
means the listing cannot compile. This is a bounded collision check for a
fictional educational forecast, not legal trademark clearance.
Auditor entries remain in immutable packet candidate/rank order. Selection
runs in packet-index assignment order and then packet candidate order, so
reordering an output cannot decide which listing receives a shared first pair.

Before canonical listings compile or validate, the system reprojects both the
listing drafts and the compiled name audit from their immutable packets,
outputs and live external session receipts. Internally consistent replacements
or self-rehashed audit files do not pass.

## 5. Future-distance record

Every published listing includes a machine-readable future-distance record:

```json
{
  "cutoffBaseline": "What can be delivered at the evidence cutoff",
  "materialDifference": "What is structurally different in 2031",
  "enablingChanges": ["Evidence-linked or explicitly assumed changes"],
  "newActorOrRelationship": "The actor, right, institution or relationship that changed",
  "closestPriorArt": ["Dated source IDs found only after generation"],
  "auditVerdict": "future-dependent-no-collision-found",
  "failureCondition": "What would make this merely incremental"
}
```

`closestPriorArt` is a legacy compatibility field name. It contains only the
closest matches found in the named, dated current-market and published-concept
collision audit; it does not imply a complete prior-art search or a novelty
finding.

The public detail panel explains this as:

1. **Why this could not be the same product in 2026.**
2. **What changed in the world.**
3. **What the 2031 product lets someone or something do.**
4. **What could prevent it from appearing.**

## 6. Fiction and disclosure

Every name, developer, icon, rating, review and rank is fictional and labelled
at point of use. Imagined reviews may illustrate both benefit and failure but
cannot be written as evidence.

The site distinguishes:

- observed evidence;
- inference;
- scenario condition;
- product design;
- rank judgement; and
- imagined marketplace copy.

## 7. Refresh contract

A refresh is a new forecast run from the current evidence position, not an edit
of the previous inventory.

Before generation, the refresh process may read previous evidence to identify
due signals and source updates. Scenario, needs, taxonomy and candidate authors
must receive newly assembled workflow-separated packets that exclude previous
categories, products and ranks. This restricts supplied and actively
retrievable run material; it does not erase pretrained or ambient knowledge.

Each refresh must:

1. update the horizon scan and revisit the complete active disruption set;
2. rebuild cross-impacts and coherent worlds;
3. rederive changed actors and needs;
4. rederive marketplace ontology and categories;
5. generate candidates independently;
6. perform a new cutoff-date current-market and published-concept collision audit;
7. rerank the surviving inventory; and
8. only then compare the completed edition with its predecessor.

The change record identifies categories and products that appeared, vanished,
merged or changed, but those comparisons never become authoring inputs.

Method evolution is permitted only as an explicit versioned decision with its
own Gauntlet evidence. Old frozen editions remain immutable and are never
rewritten to match the new method.

If a named gate fails before candidate sealing, the failed research is not
quietly edited into a successor. The dedicated invalidation writer requires a
validator-clean pre-seal edition and an explicit edition-bound authorisation.
That authorisation binds the exact pre-state manifest and refresh-run, the
copied `FAIL` / `B-worlds` verdict JSON and Markdown, its complete artifact
receipt set, and the edition-local Stage B-D integration and lifecycle output
receipts. A verdict from another run therefore cannot authorise disposition.
The writer preserves the reached stage as history, protects the pre-state and
retained tree, excludes the edition from active forecast ancestry, and refuses
any Stage F or G state.

A clean replacement is not an evolution of that failed inventory. It has no
valid forecast predecessor, no predecessor freeze hashes and no category,
candidate, rank, listing or current-product carryover. Its only source-edition
artifact is a local receipt for the invalidated manifest and disposition; all
forecast-generating records are rebuilt.

## 8. Gauntlet evaluation

Builders never grade their own work. Each piece is inspected by a fresh critic
against real external foresight methods and the real candidate artifact.

The retained bootstrap and prompt bind the critic to exactly four ordered
packet-bound inspection calls: prompt, scope and two content files. Every
`functions.exec` source must match the canonical wrapper byte-for-byte. Bracket
or computed tool access, aliases or destructuring, extra expressions,
statements or calls, direct web/MCP/computer calls and unbound reads are
rejected. Every call, complete argument and adjacent output is hash-bound in
the external-session receipt; critics cannot inspect further files or edit.

An edition at `ranked` or later is invalid until all six required scopes have
passing final receipt artifacts. The validator reconstructs every receipt from
external Codex session JSONL and rejects empty, partial, alias-only, missing or
unverifiable sets. Canonical critic contexts are unique and disjoint from stage
builders, candidate and replacement authors, collision auditors and one
another. The field named `criticBlindPacket` is retained for file
compatibility, but it is a hash-bound workflow-separated critic packet, not
proof of a blank context. It hashes the actual ranked v2 artifacts, so old or
unbound criticism cannot complete a new edition.

Mandatory regressions include:

- workflow separation between generation and dated collision material;
- no named company or product in the general rules;
- no automatic carry-over from the previous edition;
- complete future-distance records;
- categories derived before current-category comparison;
- immutable, contiguous collision-audit rounds with complete rejection and
  replacement lineage;
- sealed author packets, category audit packets, externally rebuilt Codex task
  receipts and disjoint canonical author/auditor contexts;
- visible high-impact uncertainty;
- factual claims linked to dated sources;
- explicit harms and counterforces;
- understandable explanations; and
- local data, type, test, build and signed-out route proof.

## 9. Resolution and limitations

The final contract will define how a July 2031 assessor maps observed
marketplace listings to forecast archetypes without seeing predicted ranks.
Where the marketplace itself has changed, the assessor will first map the
observed first-party discovery surface to the forecast marketplace-unit and
category definitions.

The forecast cannot discover unknown unknowns on demand. It instead publishes
its scan coverage, excluded evidence, explicit unknowns, scenario omissions and
an `unforeseen field` so later scoring does not pretend the named candidates
were exhaustive.

The method aims for disciplined imagination, not certainty. A surprising
forecast is not automatically good, and a familiar outcome is not
automatically wrong. The requirement is that every published new product earns
its claimed temporal distance and that uncertainty is shown rather than
quietly converted into continuity.
