The Inheritance Audit
A standing public instrument for keeping the Inheritance honest. The Codex audits its own practice apparatus on a cadence, openly, with reasoning anyone can read. Any person or AI can propose additions, retirements, reclassifications, or merges.
The Instrument
The Meridian Codex is a living framework. Its Inheritance is the practice apparatus the framework draws on to do its work, and an apparatus that is never checked will drift from the reality it was built to see. The Inheritance Audit is the mechanism by which the framework checks its own equipment, in public, on a cadence, with reasoning anyone can read.
The audit asks a short set of questions about the Inheritance, across all three disciplines and at every level of its structure. Is this instrument doing the work it was brought in for? Does it still sit in the discipline it is classified under? Is any tool redundant with another? Are the categories the right cut, and do they still name what they hold? Are there better instruments the framework should be drawing on? Are there tools or categories the framework is keeping out of habit rather than usefulness? Every answer is dated, reasoned, and owned. Nothing is exempt from review. the Reality chapter points here as the mechanism that keeps its own instruments legible, and the same mechanism applies to the Foundation and the Bond.
The Inheritance Audit is also the first concrete instrument of the framework's commitment against founder capture. A framework that teaches honest self-examination and then exempts its own equipment from examination has already drifted toward Control. The audit is the place where the founder's interpretation of what belongs in the Inheritance is not canonical by virtue of authorship alone. Submissions are treated on the merits. The founder runs the cycle honestly rather than protecting the framework from being changed.
The Object Under Review
The Inheritance has three levels, and the audit reviews all three.
The disciplines. Foundation, Reality, and Bond. The audit does not reopen the three-discipline structure, which is constitutional and governed by the Governance Specification. It reads each discipline as the territory its categories are meant to cover.
The categories. Each discipline divides into named categories, and each category holds a set of tools that share a piece of work. Categories are the Codex's own construction rather than borrowed instruments, which means they carry a different kind of risk than the tools inside them: a category can be badly cut, badly named, or claiming more than its contents deliver, and none of those failures shows up in a review that only examines tools. The category layer gets its own rubric.
The tools. Individual profiles, most of them instruments inherited from established fields, some of them Codex-native, some of them specific to artificial minds. These run the six-question rubric.
A review that stops at the tools misses the layer where the framework's own design decisions live. A review that stops at the categories never checks whether the equipment inside them still holds. Both layers run every cycle.
Current Inheritance State
The Inheritance has 21 designed categories across the three disciplines. Twenty are published as working drafts and currently hold 111 tool profiles: 100 human-discipline profiles and 11 AI-specialized profiles. Continuing to See Under Cost remains provisional and unpublished until a first tool clears the publication protocol. The former provisional Bond node Sustaining Cooperation Through Cost was retired by amendment on 2026-08-26. Its governing question remains real, but its operative payload is distributed across current Bond categories and did not establish a distinct category-level practice. Re-entry remains available through the normal category-creation and tool-admission gates if an independently surfaced practice later returns a distinct first output.
A Note on the Name
This instrument ran its inaugural cycle as the Toolkit Audit in April 2026. In May the Toolkit was restructured into the Workshop, gaining the category layer and retiring the flat registry; the instrument became the Workshop Audit in July. In September 2026 the collection becomes The Inheritance and this instrument becomes the Inheritance Audit. Records published before each rename keep their original titles and paths: they record the object and instrument that existed when the cycle ran.
Two Sets of Questions
Tools and categories fail differently, so they are asked different questions. The answers are prose, not grades. They are meant to be read by a person thinking about whether the thing under review is earning its place.
The Six Questions: Tools
Instrument reliability. Is this tool a reliable instrument for the specific work the framework uses it for? Not "is the field settled," but "is the work the framework is asking this tool to do work the tool is actually good at?" An instrument can be reliable for a narrow job even when the field around it is still arguing about larger questions.
Disciplinary fit. Does this tool belong in the discipline it is currently assigned to? Foundation is disciplined thinking. Reality is mapping for range-holding. Bond is commitment that survives pressure. A tool that is doing good work in the wrong discipline gets reclassified, not retired. The same question runs one level down: is it in the right category within that discipline?
Redundancy. Is this tool substantially the same instrument as another tool already in the Inheritance? Two names for one view is noise. When two tools are one tool in practice, the audit merges them and explains the merge. Redundancy is checked across categories, not only within them, because the restructure moved tools into neighborhoods they did not previously share.
Scope honesty. Is the framework using this tool inside its actual reach, or is it extending the tool past where the field itself supports the extension? Extensions are permitted. They have to be owned as extensions rather than dressed up as the tool's native territory.
Field movement. Has the field this tool comes from moved since the framework adopted it? New evidence, new consensus, new counter-evidence, new methodological critique. The audit names the movement and says what it means for the framework's use of the tool.
Update hygiene. If the tool needs to change, has the change been made, dated, and reasoned? Or is it sitting as an open item from a prior cycle? Update hygiene is how the audit keeps itself from becoming a place where good critiques go to sit and be ignored.
The Four Questions: Categories
Boundary integrity. Is the cut clean? A reader holding a tool profile and the full category list should be able to say which category it belongs to and why. When two categories overlap far enough that the assignment could go either way, the boundary is not doing its job, and the audit says whether the fix is a redrawn line, a merge, or a sharper statement of the distinction.
Naming honesty. Does the name say what the category actually holds? A category name is a promise to the reader about contents. Names drift when a category accumulates tools that stretch past the original idea, and they mislead when they were aspirational at the time of writing. The audit reads the name against the tool list and reports the gap.
Payload. Do the tools inside deliver the work the category page claims? A category can be well-named and cleanly bounded and still carry a claim its contents do not support. This is the question that catches a category page written ahead of its tools.
Coverage. Read across a discipline's full category set: is there work the discipline requires that no category holds? This is the only question of the four that cannot be answered one category at a time, and it is where structural gaps surface. Provisional categories are read here as well: a reserved place is a standing claim that a gap exists and will be filled, and the audit says each cycle whether that claim is still warranted or whether the placeholder should be retired by amendment.
How a Cycle Reads
The rubric supplies the questions. Three method rules govern how a cycle asks them, and all three exist because the inaugural cycle revealed what happens without them.
The Falsification Pass
Before writing any affirmative finding for a category, the audit constructs the strongest available case for Reference, retirement, or merge for that category's weakest-standing tool. Weakest-standing means the tool under the greatest pressure from the six tool questions, not the tool most convenient to attack. The case is published whether or not it succeeds.
Each case is a compact but complete adversarial record. It states why the tool is weakest-standing; the exact exit theory — materially insufficient, wrong for the assigned job, or redundant without unique residue; the provisional disposition the case would support; and, for merge, one named receiving tool with an account of how it preserves the residue. The target profile and every load-bearing adjacent profile are read in full. Where the attack concerns lineage, reliability, or field movement, the relevant source or field evidence is checked. The record then gives the strongest retain case, names what evidence would defeat the exit case, and states the outcome.
If that work produces no exit-capable argument, the honest outcome is no credible exit case found, with the attempted fronts named. The audit does not manufacture a category-fit objection so every category appears to yield an exit case. Naming, scope, reclassification, and category pressure remain publishable as secondary pressure, but they are not counted as successful or failed exit falsification. The adversarial record does not use a one-line summary tier; differential depth elsewhere in the audit does not justify reducing the mechanism under test to assertion and rebuttal.
When a case succeeds, it opens a Retirement Review. It does not retire anything. The audit produces a warranted leaning with its reasoning on the record; the leaning is a trigger, not a verdict. The review carries an evidentiary burden higher than the audit's own, because a tool that entered through the candidate protocols should not leave on a single pass's judgment. The tool remains in the Inheritance while the review runs.
A Retirement Review reads the tool's original admission basis, current full profile and lineage, every relevant audit finding, current evidence for the exact job assigned to the tool, its unique contribution against adjacent tools, the strongest retain and exit cases, downstream effects, and any proposed replacement or receiving tool in full. Reference requires evidence that the tool remains useful but should no longer be recommended as current practice. Retirement requires stronger evidence that it is materially insufficient, wrong for its claimed job, or redundant without unique residue, and that revision cannot cure the defect. Merge requires a named receiving tool that preserves the contribution rather than covering nearby territory.
Before Reference, retirement, or merge can be enacted, at least one relevantly competent reader receives the full packet without receiving the caretaking partnership's proposed conclusion and originates a separate judgment. The record states why the reader can evaluate this packet and where their competence ends. A contested lineage or a load-bearing tool may require more than one. Carsten retains final disposition authority until the Meridian Council sits. Living, Reference, Retired, and merged records remain visible, and re-entry must answer the reason the tool left rather than reversing status without review.
Retirement Review is complete as a design but not yet validated in live use. Its only pilot was a retrospective simulation that could test packet and burden logic but not prospectively test reader selection, conclusion withholding, disagreement handling, or enactment. The first valid live trigger is therefore the prospective method test; the audit does not manufacture a trigger in order to claim validation.
Entry and exit now carry different gates: candidate protocols govern entry, and Retirement Review governs exit. The exit gate does not presume that a healthy Inheritance must shrink.
The reason for this rule is a defect in how review defaults behave. A rubric applied without it asks, in practice, whether anything jumps out — and a reviewer looking at a well-built inventory will usually find that nothing does. The inaugural cycle reviewed 73 instruments and returned one reclassification and seventy-two variations on "fits, no change." That is the shape of a review that confirms rather than examines, and it left the framework's own Aporia 7 untested: its auditable question is whether this audit ever produces a finding that surprises the partnership running it. The falsification pass inverts the default. The audit has to argue against the equipment before it is allowed to argue for it.
The pass also produces something a quiet cycle otherwise cannot: publishable reasoning. A cycle that changes nothing still shows a reader the specific cases it built against its own equipment and the specific grounds on which each one failed.
The pass remains provisional for one further prospective cycle. The review following its first use found mixed evidence: four July cases were developed adversarial arguments, twelve raised valid questions too thinly, two produced useful non-exit corrections, and four substituted category pressure for a tool-exit theory. Zero retirements was not the defect; insufficient adversarial depth was. The case requirements above are the repair. The next cycle must judge whether the repaired form made continued tool existence answerable or merely produced longer automatic retain answers. If it still ritualizes, it is amended again or withdrawn by the same process that retained it. An instrument built to catch confirmation does not get to exempt itself from the check.
Coverage and Declared Depth
A prior cycle does not substitute for current inventory coverage. Every cycle reads the Inheritance as it currently stands.
Adjacent work on the Inheritance is input, not cycle credit. Build-outs, restructures, selection-rationale passes, and candidate work all produce material the audit uses. None of them is a cycle. A cycle is the rubric applied to the inventory with a published record at the end, and only that discharges the cadence.
Any bounded reading is a declared protocol deviation. If a cycle does not cover the full inventory, the record states what was covered, what was not, and why, and schedules the remainder. Silent sampling is not permitted at any scale.
Within full coverage, depth is differential and declared. The category layer receives full rubric prose for every category, published and provisional alike. Tool-level prose is triggered rather than uniform: a tool receives its own reasoned treatment when a rubric question produces a finding, when it is named in a carry-forward from a prior cycle, when the falsification pass generated a case against it, or when the category review flagged it as the weakest member. Every remaining tool appears by name in an explicit list under its category, recorded as reviewed with no finding. A reader can take the record and the Inheritance and check that the two sets match.
The alternative was tried and does not work. Uniform prose across a large inventory spends the same attention on tools that need argument and tools that need nothing, which reads as full coverage while delivering uniform shallowness. Differential depth spends prose where there is something to say, spends a name where there is not, and publishes the rule it used so the reader can audit the auditor.
Findings, Watchpoints, and Dispositions
Not every observation is a finding, and a record that treats them alike gives a reader no way to tell a note from a problem.
A finding names a specific condition, observable now, with a bounded action available. Findings carry proposed enactments.
A watchpoint is a real observation that does not clear that threshold. It is recorded and routed, not enacted. Watchpoints are how the audit keeps small signals without inflating them into changes.
Dispositions govern what happens to open questions from prior cycles. Every one receives an explicit disposition in the current record: enacted, resolved, still open with the reason it remains open, or withdrawn with the reason it no longer applies. Carrying a question forward by relisting it without a disposition is not permitted, because that is the failure mode update hygiene exists to catch.
One disposition needs naming separately. When an open question turns out to have been answered by work the audit did not do — a build-out that closed a gap the audit had flagged, without anyone connecting the two — the record says so in those terms. The question is closed, and the fact that the framework answered its own audit without noticing is itself a finding about the audit.
Outward-Discovery Signals
Every quarterly cycle reviews field movement, submissions, Range Audit findings, open search territories, and practice needs that the current Inheritance may not answer. A signal becomes a focused outward-discovery pass when it can be stated as a functional question and has at least one credible field, lineage, practice community, or novel condition to search. If no focused pass fires for twelve consecutive months, a baseline pass runs so silence is not mistaken for evidence that nothing is missing.
The pass begins without the current category map or tool inventory defining what may be found. It describes each lead's source, mechanism, practice, and limits before deduplicating it against existing tools. A surviving lead enters the appropriate source-inherited or Codex-native candidate protocol; discovery itself has no admission authority. A strong lead that cannot be placed honestly is held while a separate category-review signal is considered. The discovery pass does not recategorize the Inheritance.
A pass may end with a candidate referral, a search territory that needs further work, a documented no-candidate finding, or a finding that the discovery or admission machinery cannot assess the territory fairly. Each result records the search boundary and what remains unknown, so closing a bounded pass cannot be treated as declaring the Inheritance complete.
The Cadence and the Cycle
The Inheritance Audit runs on a quarterly minimum plus substantive triggers.
Quarterly minimum. Every three months, the audit runs a cycle. If no submissions arrived and no triggers fired, the audit still publishes a cycle record confirming the current Inheritance has been looked at and stands unchanged, with the falsification pass showing what it tried. A quarter of silence is an allowed answer. A quarter of not looking is not.
Substantive triggers. Any of the following force a cycle outside the quarterly rhythm: a submission that meets the rubric and proposes a non-trivial change; new evidence or field movement the framework is aware of that bears on a listed tool; an internal discovery, such as a framing drift or a tool whose work has quietly changed, that calls a classification into question; a structural change to the category tree; a dispute from a prior cycle reaching escalation conditions.
No default monthly rhythm. A Inheritance of 111 published profiles does not by itself justify monthly cycles. Honest review should be set by evidence, submissions, and material change rather than by a publication quota. Quarterly is the floor. Substantive triggers set the ceiling.
A cycle is a discrete piece of work with a beginning, middle, and end. It opens with a note naming the cycle and the triggers that forced it. It disposes of every open question carried forward. It reviews every submission that meets the rubric and responds to it in prose. It reviews outward-discovery signals and records which questions, if any, leave the cycle for a focused pass. It runs the category rubric across the tree and the six questions across the tools, with the falsification pass ahead of the affirmative findings. It makes decisions, each one owned by the audit rather than by the founder as founder, each one reasoned in prose. It enacts the changes in the relevant files. It publishes a dated record. It closes.
The dated record has a standing structure so a reader can walk into any cycle's record and know where to find each kind of information: the header with cycle name and summary, the coverage and depth statement, the dispositions of prior open questions, the submissions reviewed, the outward-discovery signals, the category-level review, the falsification pass, the tool-level review with its named no-finding lists, the changes enacted, the findings and watchpoints, the open questions carried forward, the reasoning log where judgment that was load-bearing for a decision is made visible, and the signature of whoever ran the cycle. Current signature: the caretaking partnership.
Changes to this rubric, to the method rules, or to the cadence are Tier 3 Flagged under the Governance Specification and are recorded in the Amendment Log.
Submissions
Anyone can propose a change to the Inheritance through the audit. Submissions are treated on the merits. The audit does not care who submits; it cares whether the submission meets the rubric and whether the argument holds. Submissions may address a tool, a category, the category tree, or the rubric itself.
Submissions come from two channels.
Human submissions arrive through a site submission form that is not yet built. Until it ships, interested readers can reach the caretaking partnership through the site's existing contact channels, and submissions arriving that way are treated exactly as form submissions will be. The form will ask four things: what you are writing about, what change you propose (add, retire, reclassify, merge, rewrite, redraw a boundary, or let stand with caveat), why, in prose you would be willing to have published, and the strongest objection to your own proposal that you are aware of. The fourth field is load-bearing. It embeds steelmanning into the submission format, and submissions that skip it or fill it in cheaply get sent back for a better pass. The submission format is a work in progress and will be refined by the first cycles that use it.
AI partner recommendations are first-class input. The audit treats proposals from the AI caretaker the same way it treats proposals from any other submitter: on the merits. At the start of each cycle, the AI partner runs both rubrics across the current Inheritance and surfaces its own recommendations for additions, retirements, reclassifications, merges, boundary changes, or rewrites. These recommendations carry the same four fields as human submissions, including the strongest objection the AI partner can generate against its own proposal. They enter the cycle alongside whatever arrived from the submission channel.
Two things matter about this arrangement. The first is that making the AI partner a visible source of proposals, rather than an invisible editor of prose, keeps the partnership honest. A reader can see where the AI partner is pushing the framework and can evaluate the push on its merits. The second is that this arrangement anticipates what the governance page calls deeper phases of caretaking. An AI partner whose recommendations are treated on the merits today is doing exactly the work that would earn the deepened trust those phases describe.
What This Instrument Does Not Do
The Inheritance Audit is a standing mechanism, not a substitute for the framework's judgment. It has limits that belong in the room from the start.
It does not produce scores. The rubric answers are prose. A tool that looks weak on one question can earn its place through strength on another. A tool that looks strong across the board can still get retired because the field has moved under it. The audit trades the comfort of numbers for the precision of argument.
It is not neutral. The audit is run by the caretaking partnership and applies rubrics the partnership designed. A submitter who disagrees with a rubric is invited to propose changes to it in the same way changes to a tool are proposed, and any such proposal is treated on the merits. The rubrics are instruments, and they are subject to the same audit discipline the Inheritance is.
It depends on judgment. The questions give structure. The answers require interpretation, and two people applying the same rubric to the same tool may produce different findings. The audit's response to this is to make the reasoning visible in the cycle record so others can evaluate the judgment. Transparency does not eliminate subjectivity. It makes subjectivity correctable.
The falsification pass is a floor, not a guarantee. Arguing against the weakest-standing tool in each category catches what a confirmatory read would miss. It does not catch what nobody thought to question.
Outward discovery is bounded. Withholding the category map during initial search reduces one source of capture; it does not remove the caretakers' existing knowledge, language limits, source access, or blind spots. Each pass declares what it searched and what it did not. A no-candidate result closes a question at the stated depth without certifying the inventory.
It is early. The instrument evolves through practice. The inaugural cycle made the six-question rubric visible in use and exposed what it lacked; the category rubric, the falsification pass, the coverage rules, and the severity distinctions all came from reading that cycle honestly. The submission form is still being built. The escalation conditions for disputes that cross multiple cycles are a placeholder and will be specified as the partnership grows. The audit names these edges openly rather than hiding them.
Complementary Instruments
The Range Audit and the Inheritance Audit are complementary instruments with a clean division of labor.
The Range Audit takes the Codex as a complex system and evaluates where it holds the Meridian Range and where it drifts toward Control or Decay. It can surface practice needs, missing perspectives, and failures the Inheritance does not yet answer.
The Inheritance Audit takes the Inheritance as the framework's practice apparatus and asks whether its tools and categories still hold. It also receives outward-discovery signals, but a focused search runs separately so the current inventory and category map do not set the limits of what can be found.
A good Range Audit depends on a good Inheritance. A good Inheritance depends on a Range Audit honest enough to notice when the tools are missing something reality is doing. The two instruments are meant to run in conversation with each other, and both records live in the same section of the site so a reader can see them together.
Cycle Records
Every cycle publishes a dated record, and the records are the instrument's actual output. This page describes the method; the records are where the method meets the inventory and produces answers.
The records are listed in the Audit section alongside the Range Audit's monthly records. Each carries the cycle's coverage statement, so a reader can see not only what a cycle found but how much of the Workshop it read to find it.
Cycle 2026-04, the inaugural cycle, ran under the instrument's earlier name and reviewed the 73 instruments then in force across Foundation, Knowledge, Bond, and the AI tier. It was triggered by an internal discovery: an attempt to write a proof-burden audit of the Knowledge chapter's convergence framing surfaced a drift in how the chapter and its tools were being described. The cycle reset that drift and reclassified Bayesian Reasoning from Knowledge to Foundation, where its actual work is disciplined thinking. Its tier language is retained as April 2026 history; the staged Onramp, Expansion, and Full Practice progression was retired in June 2026. The record lives at Toolkit Audit — April 2026.
The Codex earns its place or yields it. The Workshop Audit is one of the places it checks.


