Each hop carries its build status on the right, and underneath the description, two lines: what stands in for it today, and what the real thing would be. Read the synthetic lines top to bottom and you get the answer to the only question that matters before hardware exists, which is how far a run can get.
A device on a boat or a mooring takes a reading. Three sensors: water temperature, light, and GPS position. That is the honest list, and it is what makes today's survey a temperature and position survey rather than a habitat survey.
Side-scan or single-beam returns, which is what turns position and temperature into an actual map of what is on the seabed. Nothing is built. No echosounder, no ingest, no log reader for any sonar format. Every depth in the system today is either an open bathymetry grid or a synthetic distance-to-coast stand-in, labelled as such where it is displayed.
Device to cloud over cellular, with a store-and-forward buffer so a reading taken out of coverage is not lost. The device stamps its own capture time, which is what lets a late arrival be placed correctly rather than at the time it happened to land.
A versioned transform turns the device payload into database columns. Versioned deliberately, and deployed in a fixed order: columns first, mapping second, and only then the app that reads the new fields. A consumer shipped early fails against columns that do not exist yet.
Rows land in a table with their provenance intact: where, when, by what, and at what quality. Readings are never overwritten.
Every reading gets a trust score combining where it was taken, when, and how well. The design choices here are the ones that matter: a weak reading is down-weighted rather than discarded, a lone weak reading is flagged as needing replication rather than deleted, and a bad reading collapses toward zero instead of poisoning the average it sits in.
Readings become a per-cell surface. One known defect: two grid systems are currently in play on one map, an H3 hex grid and an equal-angle grid, visible only because one layer is turned off by default. Converging on one is open work.
The per-cell surface against the known 2017 extent. Until recently a point-in-polygon test treated the old map as ground truth and deleted every observation outside it, which on the committed snapshot discarded 7 of 13 cells. The product exists to find where the meadow is not where the map says, so that was the worst defect in the system. A cell outside the 2017 polygon now renders as disagreement and is counted as disagreement.
Version a season's result, freeze it so it cannot be silently altered, and transfer custody to the municipality. This is what makes the difference between a record and a report, and it is the hinge of the whole sovereignty claim. Not built. The persistence migration is written and has never been applied.
What the meadow does next under a given plan. The Posidonia model is a single-box model, not a per-cell simulation, so the honest interim output is a per-cell surface of observations rather than predictions. The engine also does not yet take survey quality as an input, which means better surveying does not visibly improve the model.
Route what the comparison found to whoever can act: an anchoring proposal, a restoration priority, a practice change, a budget line. Monitoring nobody acts on is a hobby, and this is the layer that stops it being one.
The stage where evidence becomes a rule: a no-anchor zone drawn at a boundary the survey found, a seasonal closure, a permit condition, a changed mooring practice. This is where the whole chain is either worth its cost or is not, and nothing is built for it. No decision object, no record of what evidence a rule rested on, no way to look at a rule two years later and find the survey behind it.
Seasons stacked into a time series honest enough that someone can publish against it, or argue with it. That means the method, the sampling effort, the trust scores and the known defects travelling with the numbers, so a reader can see what the series can and cannot support. Nothing is built. There is one snapshot, not a series, and no format for shipping the method alongside it.
Hops 1 and 3 to 6 are built and tested, and no live data has moved through them since 8 July 2026, because the sensor fleet is dark. Everything currently rendered on every map in this system is synthetic, labelled as synthetic at the point of display. The protocol is real; the water is not in it yet.
Registry status is what platform/apps.json declares. Build status is what the code supports. Where they disagree, the disagreement is the useful information. The synthetic column asks a separate question: can this tool be run and shown with nothing real behind it, and if so, what exactly is it faking?
| Tool | Role | Registry | Build | Synthetic stand-in | What that means | |
|---|---|---|---|---|---|---|
| Triton | Sensor fleet | exists | dark | noneNo simulated device reports in. | The fleet view works. There is no fleet reporting into it, real or fake. | |
| Reckoning | Data scrape and sensor fusion | exists | built | partialConsumes synthetic rows, generates none. | Ingest and fusion layer, running, and everything it has fused so far was invented upstream. | |
| Tessera | Ecosystem map | exists | built | fullA whole synthetic per-cell surface. | The comparison surface. Where disagreement with the 2017 map is drawn, currently from synthetic cells. | |
| Helm | Host and project console | exists | built | noneHolds no data of its own to fake. | The project dashboard everything else hangs off. It shows whatever the other tools hold. | |
| Kairos | Actions | exists | partial | partialA synthetic finding, never a synthetic owner. | Action layer exists; the routing from a finding to an owner is thin, and untested even in simulation. | |
| Prodromos | Concept demo pipeline | exists | built | fullIts whole output is a stand-in. | Makes a demo before a build exists. New, already producing, and the one tool whose purpose is this column. | |
| Proteus | Local twin creator | mvp | partial | fullRuns on synthetic forcing. | Single-box model, not per-cell. Everything it has been forced with was generated. | |
| Nereus | Twin integrator | mvp | partial | partialInherits its twins' synthetic forcing. | Integrates twins that are themselves partial, so it has no fixture of its own to fail against. | |
| Portolan | Survey routing | mvp | partial | partialPlans over synthetic distance-to-coast depth. | Plans a survey and exports a route nothing currently reads back in, over depths nobody measured. | |
| Periplus | Survey execution | experimental | partial | fullA whole working day: speed, depth, sea state degrading quality, coverage, fuel, time. | The best stand-in in the system, and it persists nothing, so the day it simulates evaporates instead of feeding the next hop. | |
| Steward | Meadow health check | mvp | partial | fullFixed numbers, and only fixed numbers. | Declared field-ready. Actually a print brief with hardcoded values, which makes it entirely a stand-in with no path yet to a real one. | |
| Meadow Futures | Forecast and act | mvp | partial | fullSynthetic baselines under real credit prices. | Scenario model. Prices now sourced rather than placeholder, which leaves the ecology as the invented half. | |
| Nomos | Commons futures | mvp | partial | fullGovernance scenarios, synthetic by construction. | Governance and commons scenarios. Nothing here was ever going to be measured; the honesty question is whether the rules are plausible. | |
| Pharos | Routing | mvp | partial | partialSame synthetic depth stand-in as Portolan. | Routing surface. Overlaps Portolan; the consolidation is undecided, and both fake the same input. | |
| Augur | Risk | mvp | partial | partialRisk over inputs that are themselves invented. | Risk surface over partial inputs. A risk number derived from synthetic inputs is a demonstration of the arithmetic. | |
| Argus | Context scan | mvp | built | noneNo synthetic site to scan. | Site context intake, reading real sources. Feeds the project manifest, and a new coast cannot be rehearsed before it exists. | |
| Meridian | Project definition | mvp | built | partialDeclares a slot synthetic; is not itself faked. | Writes the project config that every app reads. It is where the word synthetic enters the system, which is why the labelling holds everywhere else. | |
| Aqueduct | Flow explainer | experimental | partial | fullWorked examples with invented values. | Explanatory surface, not on the delivery path, so being entirely synthetic costs it nothing. | |
| Product Map | Reference surface | experimental | built | noneA picture, with nothing to stand in for. | Actors, tools and the survey cycle in one picture. The absence here is not a gap. | |
| no surface | Sounding | Site research | scoped | absent | noneNeither real nor faked. | Scoped and not started. The registry says so, which is the registry working. |
Table scrolls sideways · synthetic column sits after build status
Portolan plans, Periplus runs, Pharos routes, and a separate community survey planner exists outside the registry entirely. Steward is declared a field-ready health check and is a print brief with hardcoded numbers. Deciding which one is the planner is open work, and it is the kind of overlap that grows quietly: this toolset already produced two mapping surfaces that were hard to tell apart.
A system where every stage has a synthetic stand-in can be run from end to end before any hardware is bought. That run is the cheapest test there is of whether the chain holds together: whether the shapes fit, whether the labels survive the trip, whether the thing at the far end is worth the thing at the near end. Where a stand-in is missing the run stops, and everything past that point is untested design rather than working software.
This chain has four stops in it. They are listed below in the order a run hits them.
Periplus simulates a full working day: speed, depth, sea state degrading data quality, coverage accumulating, fuel and time draining. That is a genuine survey stand-in and it is the reason a survey day can be reasoned about before anyone has run one. Prodromos exists to make a demo before a build does. The trust and provenance layer is real code that has only ever scored invented readings, and it works. Between them they show the pattern: the parts of this system with stand-ins are the parts that have found their own bugs, and the grid defect and the deleted-cells defect were both caught on synthetic data. The stages with no stand-in have never had the chance to fail, which is not the same as being sound.
The other pipeline, and the one that keeps the first one honest. Each step is cheap and checkable, and most of them fail loudly rather than passing quietly.
Before any file exists, the idea is matched against the questions we know how to ask and the tools already built. The check can return stop and reconsider, and that verdict is binding. Bespoke is a first-class answer: a one-coast surface does not belong in the shared toolset.
A new tool gets its slug, name, role and status in the registry before it gets a file. A tool that exists as a file but not in the registry is one nobody can be told to use.
One config file per coast, declaring every input slot's honest provenance: local, open, derived, calibrated, synthetic, pending or none. Apps read the config, so a second coast is a config swap rather than a rebuild. Synthetic is a legal value on purpose, which is what lets a stand-in run in production without pretending.
Generated artifacts are validated against schemas and fail on unresolvable citations. A manifest that proposes a tool for every question fails on purpose, because a system that always has an answer is not answering.
A coastline is fetched once per region and turned into a committed landmask. Painting cells over water without one is how a map ends up asserting things about land.
Every change copies to a new file and repoints a stable alias. The old version is never edited and keeps being served, so the previous state stays reachable and any claim about what changed can be checked by opening two tabs.
Claims carry verdicts: verified, partly true, incorrect, or unverifiable. A claim with no verdict is a draft, not a fact.
A route contract confirms every alias resolves to a file that will actually deploy, and a privacy policy held separately from the host config confirms nothing internal became public. Both run on push and both fail closed.
The carry, contract, store and score layers, which together are the part that makes community-collected data defensible. The comparison surface. The versioning and route discipline that keeps the past reachable. That is the protocol, and the protocol is the product.
Habitat sensing, so this is a temperature and position survey. Publication and custody, so nothing is yet a held record. Downstream of those, the policy decision and the scientific series, which are absent because nothing upstream has yet produced the thing they would consume.
Survey execution simulates a day well and persists nothing. The model is single-box and ignores survey quality. Two grids ship on one map. Four tools overlap on survey territory. None of these is a crisis; all of them are known.
Eight of thirteen hops can be run on stand-ins today, which is why the middle of the chain is the tested part. Five have no stand-in at all: the device itself, the scanner, the held record, the policy decision, the multi-season series. Not one of the five needs hardware or a partner to fake, only the decision to build the fake.
All of it, since 8 July 2026. Every figure on every map is synthetic and says so where it is displayed. The first real outing is the next stage, and until it happens the honest claim is about method rather than measurement.