Accession Networks

Abstract

Authorities can agree to accept one another’s documents and decisions by negotiating a separate agreement for each pair. Every relation then requires continuing attention to its terms. We study a common instrument that each authority joins through its own signed filing. Each authority states the limits of its consent and names any counterparties it refuses. Authenticated notice gives existing participants time to refuse a new relation. Under explicit rules and an alignment assumption on willingness, these filings establish the same relations and terms as unconstrained bilateral negotiation. One filing per authority suffices, while notices, exceptions, and continuing assurance can still require work for every pair. When willingness differs by counterparty, we bound the loss from common terms and give a sufficient condition for participation. Recognition through intermediaries retains the source evidence, restrictions on its use, and each receiving authority’s current decision. The supporting inspection and administration models identify the funding, collateral, qualified personnel, and independence conditions required for their results. Legal effect, actual detection and collection, and voluntary use require institutional evidence.

Author’s note. The author has a commercial interest in systems of the kind this paper describes.

1 Introduction

1.1 Recognizing another authority’s work

A registry receives a document authenticated in another jurisdiction. The document carries a determination by a foreign authority, but the receiving registry must decide what effect that determination has under its own law. The same problem arises when a court considers a foreign award or a registry encounters a security interest recorded elsewhere. We call the receiving authority’s decision to give stated effect to the foreign determination recognition. The question concerns both the content of that decision and how authorities establish relations in which such decisions can recur.

Two authorities can settle the terms in a bilateral agreement. Each additional counterparty then requires another negotiation, followed by review, amendments, dispute handling, and eventual exit work. An increase in the number of willing counterparties supplies no additional time to the people authorized to conclude these agreements. The model below makes that constraint explicit. It separates the effort of forming a relation from the work required to maintain it.

Under accession, an authority instead joins a common agreement through its own signed instrument. The agreement specifies the determinations it covers, the permitted limits on recognition, and the effect of a refusal concerning a named counterparty. The authority files its instrument with a designated recipient. We call this signed filing a deposit. Existing authorities receive authenticated notice and may refuse a relation within a stated period. The applicable rules determine the resulting pairwise relations from these instruments after the relevant notice periods.

Consider three authorities that accept a common standard for document authentication. The first and third accept its full terms. The second selects narrower terms and exchanges refusals with the third. The first can still recognize both others, on the terms allowed by each pair’s instruments. The refusal concerns the second and third authorities alone. Section 2.2 writes out this example and compares it with separate bilateral acceptances.

The authority that signs the instrument supplies the legal decision, including the questions it reserves for later determination. Joining therefore establishes only the relations and effects authorized by that instrument. A publisher records the instrument and applies its stated rules. This separation allows authorities to join without giving the publisher power to choose their recognition relations. It also makes notice consequential: a publisher that could postpone notice indefinitely would control when a relation takes effect. The proposed instrument starts each notice period from independently verifiable actual receipt. The acceding authority or the designated recipient of deposits, called the depositary, can serve that notice directly.

1.2 What the common agreement must preserve

The central question is whether accession can reproduce the relations that unrestricted bilateral negotiation would establish. The answer depends on what each authority is willing to offer. The equivalence theorem assumes one common set of terms for each authority’s acceptable counterparties, together with accurate refusals for the others. A reservation limits the common terms an authority accepts. The agreement must permit these limits and apply them reciprocally to that authority’s obligations and entitlements. It must also establish relations after notice unless refused and resolve conflicting declarations by a fixed rule. Theorem 4.5 separates these public rules from the assumption that the deposits express actual willingness. When willingness varies by counterparty, the later comparison measures the lost recognition and the savings that can still make participation worthwhile.

This question belongs to the established study of network formation. Jackson and Wolinsky [1996] study links requiring mutual consent, while Bala and Goyal [2000] study unilateral link formation. Here each authority can both join by its own act and refuse exposure to a named counterparty. The contribution is the comparison of the resulting relations, their terms, and their institutional costs under stated hypotheses. The treaty examples establish that the relevant procedures exist. Their membership totals do not identify the causal effect of a default rule.

Counting deposits alone leaves much of the problem unresolved. Every authority must receive the required notices, keep its terms current, and maintain the evidence on which others rely. Exit also entails migration of open matters, evidence transfer, and settlement of accrued rights. These tasks enter the same lifecycle comparison as initial formation. The service model then asks whether qualified people and separate funding can complete them within their deadlines.

Recognition through an intermediary poses a further question. The receiving authority needs the source determination, the restrictions on its use, and answers to any questions that it reserves for itself. A summary of the agreed terms cannot supply these missing conditions. The construction therefore retains the evidence and the receiving authority’s current decision when it combines recognition along a route. Inspections and collectible collateral support reliance on the claims in this process under explicit incentive assumptions. The administration assigns responsibility for these operations while each authority retains its recognition decisions.

1.3 Scope

The paper establishes formation, composition, and incentive results under stated hypotheses. It distinguishes conformance to a software specification, sovereign recognition, exercised rights, and title. Welfare, intermediary recognition under particular law, universal collusion, and adoption remain open legal or empirical questions. The Sovereign Jurisdiction Network studies the deployed system whose software behavior is tested against a published specification [Lorgat 2026c]. The present paper studies how its competent authority joins and what its accession can establish.

2 Model

2.1 Participants, grades, domains

The document-authentication example separates three matters: who recognizes whom, what subject the relation covers, and which terms the parties accept. A directed graph records the first matter. A list of subject matters records the second, and a grade records the agreed terms for each subject. The grade permits a comparison of instruments before a particular document arrives. The receiving authority still evaluates that document under the applicable clauses.

Let J be a finite set of participants with |J| = n. Let D be a finite set of domains — the separable subject matters over which recognition can be extended (in the instruments we study: document authentication, award enforcement, security-interest priority, and so forth).

For each domain, the instrument provides an ordered list of negotiated classes: C=\{\bot<\mathsf{conditional}<\mathsf{partial}<\top\} Here \bot denotes no recognition and \top denotes the full unreserved class. The intermediate labels name classes in the instrument. A grade selects one class for each domain, so the set of grades is L=C^D, ordered pointwise. Thus one grade lies below another when it lies below it in every domain. These classes record the terms selected in negotiation and accession. Their order governs the class calculations in Sections 2–5. Executable treatment also depends on the retained policy clauses, the request, and the use time. Section 6.3 defines that treatment.

This ordering compares the instrument’s classes. The names \mathsf{conditional} and \mathsf{partial} do not establish a universal order between executable policies. A satisfied condition can preserve all carried support, while a partial policy still caps that support. When the condition fails, the conditional policy carries no support.

A domain also needs a rule that makes it applicable to the matter under review.

Applicability remains a separate axis: an inapplicable domain is not a class in C. The sanctions coordinate is always \bot unless a separate instrument names the applicable lists, criteria for interests held or controlled by listed persons, transaction restrictions, direction, validity window, and revocation rule. This is the sanctions exception established in How Compliance Composes [Lorgat 2026a].

Definition 2.1 (Recognition network). A recognition network is a triple G = (J, E, \gamma) where E \subseteq J \times J is a set of directed edges and \gamma : E \to L \setminus \{\bot\} assigns a negotiated class to each edge. We write \gamma(i,j) = \bot when (i,j) \notin E. The network is not assumed symmetric: \gamma(i,j) and \gamma(j,i) may differ, and in practice they routinely do, because the two authorities have different domestic law to satisfy.

To compare the value available through different relations, the model assigns each participant a share of total network value. These shares are stipulated inputs, not measurements supplied by the paper.

Definition 2.2 (Weights). Each participant carries a weight w_i>0 with \sum_iw_i=1, representing its share of the value carried by the network.

2.2 The two constructions

Combining the terms of two authorities requires the lower class in each domain. We write this operation as \wedge, called the meet. The reverse operation, \vee or join, takes the higher class in each domain. On the product L, both operations act separately on every domain.

The smallest example has three authorities and one domain. Let J=\{a,b,c\}, let the standard grade be \top, and let a, b, and c deposit the reservations \top, \mathsf{partial}, and \top. Authority b declines c, and c declines b. The three deposits produce reciprocal edges a\leftrightarrow b at grade \mathsf{partial} and a\leftrightarrow c at grade \top. They produce no edge between b and c. The unconstrained bilateral construction gives the same relation and grades. Under opt-in, the same relation requires four pair-indexed acceptance entries: A_a=\{b,c\}, A_b=\{a\}, and A_c=\{a\}. A dense three-authority relation requires six.

Definition 2.3 (Bilateral construction). Fix a preference structure in which participant i is willing to recognise j at grade g iff g \preceq \beta_i(j) for a willingness function \beta_i : J \to L. Under bilateral formation, the pair \{i,j\} concludes an instrument only if a negotiation is conducted between them. Conditional on conclusion the edge grade is \beta_i(j) \wedge \beta_j(i) in each direction. The relation is \rho_B = \{\, (i,j) : i\neq j,\ \beta_i(j)\wedge\beta_j(i) \neq \bot,\ \ \text{and $\{i,j\}$ was negotiated} \,\}.

The negotiation requirement consumes time even when both parties already agree on acceptable terms.

Accession represents those terms through one declaration per authority. The declaration selects a reservation from the common menu and records excluded counterparties. A refusal of a relation with a named counterparty is called a declination.

Definition 2.4 (Accession construction). Fix a published standard S whose unreserved grade is \top_S\in L, and let L_S=\{g\in L:g\preceq\top_S\}. Fix a finite reservation menu R, whose elements are functions L_S \to L_S that lower a negotiated class (formally: r(g) \preceq g for all g\in L_S, and R contains the identity on L_S). An accession by i is a triple d_i = (\,\text{adherence to } S,\ r_i \in R,\ D_i \subseteq J\,) where r_i is i’s reservation and D_i is i’s set of declinations — participants with which i declares that no relation is established. The relation is then computed: \rho_A = \{\, (i,j) : i\neq j,\ j \notin D_i,\ i \notin D_j,\ r_i(r_j(\top_S))\neq\bot \,\}. For (i,j)\in\rho_A, set \gamma_A(i,j) = r_i\!\left(r_j(\top_S)\right). For (i,j)\notin\rho_A, set \gamma_A(i,j)=\bot, as in Definition 2.1. Note that \gamma_A is not symmetric for arbitrary weakening maps. Hypothesis (H1) restricts the admissible maps to meets, which commute. Hypothesis (H2) then gives the resulting grade reciprocal legal effect.

The instrument counts are the immediate contrast: the accession construction requires exactly n deposits. Bilateral construction requires one negotiation for each mutually compatible unordered pair, hence up to \binom{n}{2}. Section 3 adds failed attempts and maintenance.

2.3 Recognition through an intermediary

Suppose one authority recognizes an intermediary that recognizes the original issuer. The route contains two recognition relations, each with its own limits. A grade for the complete route must respect both limits. We first record that calculation for negotiated classes, then distinguish it from the evidence needed for a particular use.

Definition 2.5 (Path grade). For a directed path \pi = (i = v_0, v_1, \dots, v_k = j) in G, the composed grade is \gamma(\pi) \ =\ \bigwedge_{\ell=1}^{k} \gamma(v_{\ell-1}, v_\ell). The closure grade is \gamma^*(i,j) \ =\ \bigvee_{\pi : i \to j} \gamma(\pi), the coordinatewise availability envelope across all paths, with \gamma^*(i,j) = \bot if no path exists. Different paths may attain different coordinates of this envelope. One path need not attain the full vector. This envelope records negotiated classes. Execution retains jointly admissible route witnesses and each receiving authority’s current obligations.

Along a path, the meet preserves every authority’s limit. Across paths, the join records the highest class available in each domain. This collection of available classes is the class envelope. One route may support document authentication while another supports a different domain. The complete evidence must still be admissible together for the intended use. Section 6.3 defines that check and the required current decisions.

Averaging grades could exceed a restriction on one part of the route. Lemma 5.2 proves that the meet is the greatest operator that preserves every such restriction. Multiplication can instead measure loss of value along a route, as discussed in Section 5.1.

The value comparison needs a separate numerical scale. Let a valuation assign greater or equal value to a higher grade. An extra intermediary can reduce that value even when the class stays unchanged. The following definition records this loss with a factor \delta for each additional hop.

Definition 2.6 (Value functional). Fix a monotone grade valuation v:L\to[0,1], with v(\bot)=0 and v(\top)=1, and a per-hop factor \delta\in(0,1]. For a path \pi of length |\pi|, define q(\pi)=\delta^{|\pi|-1}v\!\left(\gamma(\pi)\right),\qquad q_k(i,j)=\max_{\substack{\pi:i\to j\\|\pi|\le k}}q(\pi), with a maximum of zero when no path exists. Then V_k(G)=\sum_{i\ne j}w_iw_jq_k(i,j). Thus V_1 is direct-edge value and V_k is value reachable within k hops. Attenuation acts on value, not on the finite grade lattice. The bound V_k\le1 follows from q_k(i,j)\le1 and \sum_{i\ne j}w_iw_j\le1.

This normalization bounds total value by one. It therefore constrains claims about growth with the number of participants.

Proposition 2.7 (No positive power law). Let \{(G_n,K_n)\}_{n\ge N} be any family for which W(n):=V_{K_n}(G_n)>0. No constants C>0 and \alpha>0 satisfy W(n)=Cn^\alpha for every n\ge N. If W has a positive differentiable extension, its elasticity d\log W/d\log n also cannot remain above a positive constant for all sufficiently large n.

Proof. Definition 2.6 gives W(n)\le1. The expression Cn^\alpha exceeds one for all sufficiently large n. For the elasticity statement, a lower bound \varepsilon>0 integrates to W(n)\ge W(N)(n/N)^\varepsilon, which again exceeds one. \square

3 The negotiation bound

3.1 The formation process

Bilateral formation consumes a scarce, non-storable input: the attention of the people authorised to conclude instruments. We model it directly.

Definition 3.1 (Convenor process). A distinguished participant, the convenor, has instantaneous negotiation throughput c(t) \ge 0 measured in attempts per unit time, subject to a capacity bound c(t) \le \bar{c}. Each attempt concludes an instrument with probability \sigma \in (0,1] independently. A failed attempt consumes the same capacity.

Definition 3.2 (Maintenance load). Each standing relation consumes throughput at rate \mu > 0: amendment, periodic review, dispute handling, and renegotiation on either party’s change of law. The throughput available for new formation at time t is therefore c_{\text{new}}(t) \;=\; \bigl(\bar{c} - \mu\, P(t)\bigr)_+, where P(t) is the number of standing relations.

With positive maintenance, the process converges to an asymptote instead of growing linearly. The proportional load is the model assumption tested by Theorem 3.4 and separated from the historical count in Remark 3.7.

Lemma 3.3 (Capacity-only bound). Ignoring maintenance (\mu = 0), let P(T) be the number of relations formed by time T. Then \mathbb{E}[P(T)] \le \sigma \bar{c} T, and for any \lambda > 0, \Pr\bigl[P(T) \ge (1+\lambda)\,\sigma \bar{c} T\bigr] \;\le\; \exp\!\left(-\frac{\lambda^2\,\sigma \bar{c} T}{2+\lambda}\right).

Proof. The number of attempts by time T is at most \bar{c}T. Successes are a sum of independent Bernoulli(\sigma) indicators, so the mean bound is immediate and the tail is the multiplicative Chernoff bound. \square

The bound does not mention M, the size of the eligible population. Doubling the number of eligible counterparties leaves the capacity-only upper bound unchanged.

Theorem 3.4 (The negotiation asymptote). Let M be the finite eligible population. With maintenance load \mu>0, consider the uncapped deterministic mean-field process \frac{dP}{dt}=\sigma\bigl(\bar c-\mu P\bigr)_+, \qquad 0\le P_0\le\bar c/\mu, and define the realised count by P_M(t)=\min\{M,P(t)\}. The uncapped process has the unique solution P(t) \;=\; \frac{\bar{c}}{\mu} \;+\; \left(P_0 - \frac{\bar{c}}{\mu}\right) e^{-\sigma\mu t}, and therefore \lim_{t\to\infty}P_M(t)=\min\!\left\{M,\frac{\bar c}{\mu}\right\}. Once M>\bar c/\mu, the ceiling is independent of both the time horizon and M. Consequently \frac{\lim_{t\to\infty}P_M(t)}{M} =\frac{\bar c}{\mu M}\xrightarrow[M\to\infty]{}0.

Proof. The equation is linear below \bar c/\mu, and the displayed solution follows by an integrating factor. It never exceeds \bar c/\mu. The map x\mapsto(\bar c-\mu x)_+ is Lipschitz, so the solution is unique. Taking the minimum with M gives the realised limit. \square

The realised ceiling is \min\{M,\bar c/\mu\}. Beyond M>\bar c/\mu, more eligible counterparties leave that ceiling unchanged.

Corollary 3.5 (Throughput must scale with the population). To reach a fixed fraction f of an eligible population of size M, the convenor requires \bar{c} \ge f\mu M: capacity must grow linearly in the population. Since \bar c is bounded by the available authorised negotiators, bilateral formation cannot maintain fixed density as the population grows.

Corollary 3.6 (Decentralised bilateral formation). Suppose there is no convenor and every participant negotiates on its own account under the same mean-field assumptions, each with capacity \bar c and maintenance \mu per standing relation. Participant i’s limiting degree satisfies \limsup_{t\to\infty} d_i(t)\le \min\!\left\{n-1,\frac{\bar c}{\mu}\right\}. Equality requires enough mutually willing counterparties and continuous use of residual capacity. The average degree obeys the same upper bound, so for fixed \bar c/\mu, \text{density} \;\le\; \frac{\min\{n-1,\bar c/\mu\}}{n-1} \;\xrightarrow[n \to \infty]{}\; 0 . Decentralising negotiation moves the capacity bound to each participant. It does not remove it.

The negotiation bound counts legal recognition relations. The following observation concerns operational links between deployments and uses separate assumptions. Suppose deployments form operational links at fixed positive cost. Let link value follow a non-increasing rank curve that does not depend on network size. Assume a link forms exactly when its value meets the cost and that no other constraint binds. If the curve falls below cost at a finite rank, every deployment has bounded degree and the total count is at most linear in n. If it never falls below cost, the complete mesh forms. Holding the other premises fixed, a count of order n\log n therefore requires incumbent value to grow with network size. This observation motivates formation cost. It is not a result about recognition edges.

3.2 A historical instance

UNCTAD records 2,861 bilateral investment treaties signed between 1959 and 2026, of which 2,236 are in force [UNCTAD 2026]. With roughly 200 jurisdictions there are about 19,900 unordered pairs. Their quotient, about 0.11, is an instrument-to-pair benchmark and an upper proxy for pair coverage. Exact graph density requires deduplication by unordered pair over a denominator matched to the register’s party universe. The count identifies a sparse instrument stock and supplies no estimate of \bar c or \mu.

Remark 3.7. The condition \mu>0 is an assumption. If maintenance load is zero, Lemma 3.3 gives a linear capacity bound rather than an asymptote. The empirical stock does not distinguish the two models by itself.

4 The accession equivalence

The capacity bound explains why willing parties may leave relations unformed. Accession avoids the need for a fresh negotiation, but it must still preserve the terms those parties would accept. The comparison therefore asks what bilateral negotiation would produce if every compatible pair could complete it at zero cost. Four rules govern the common instrument. A fifth assumption connects each authority’s declaration to its actual willingness.

4.1 The hypotheses

A permitted reservation must have an unambiguous effect when combined with another reservation. Reciprocity then makes the combined limit govern both directions. Notice determines when a refusal is timely, and a fixed conflict rule determines what inconsistent declarations mean. The instrument examples below supply procedural counterparts to these requirements. The Multilateral Convention to Implement Tax Treaty Related Measures to Prevent Base Erosion and Profit Shifting is abbreviated as the BEPS Multilateral Instrument, or MLI. The Vienna Convention on the Law of Treaties is abbreviated as VCLT.

Definition 4.1 (H1) — finite reservation menu. The reservation menu R consists of meet operators r_a(g) = g \wedge a on L_S, for a in a finite set A\subseteq L_S that contains \top_S. Thus r_{\top_S} is the identity on L_S. Instrument counterpart: the BEPS Multilateral Instrument, Art. 28(1) — “no reservations may be made to this Convention except those expressly permitted by” its exhaustive enumerated list. The finite enumerated configuration space makes validation bounded.

Definition 4.2 (H2) — reciprocal entitlement. A reservation modifies the reserving participant’s entitlements to exactly the same extent as its obligations, automatically and in both directions. Instrument counterpart: New York Convention, Art. XIV — “A Contracting State shall not be entitled to avail itself of the present Convention against other Contracting States except to the extent that it is itself bound to apply the Convention.” Analogously, MLI Art. 28(3)(a)–(b), and generally VCLT Art. 21(1).

Definition 4.3 (H3) — default-to-consent declination. Relations are established by default. Any participant may, within a window of length W opened by independently verifiable actual receipt of authenticated service, declare that no relation is established with a named other participant. The declaration requires no stated ground or counterparty assent, has bilateral effect only, and does not affect the accession’s validity or its effect against anyone else. Procedural analogues: Hague Apostille Art. 12 uses depositary notification and an incumbent-only six-month period. Hague Judgments Convention 2019, Art. 29 gives incumbents twelve months to notify an objection, while an acceding state declares at deposit and may later withdraw a declaration. The construction here applies one symmetric window opened by independently verifiable actual receipt.

Definition 4.4 (H4) — deterministic collision resolution. Where two participants’ declarations disagree about the pre-existing bilateral state, the outcome is fixed by rule rather than by negotiation or adjudication. Instrument counterpart: MLI Art. 6(5) — where both parties notify the same existing provision it is replaced. “In other cases” the new text is added. Disagreement resolves by a published rule. No adjudication is required.

Definition 4.4a (H5) — aligned willingness and deposit. Each participant’s willingness is counterparty-independent up to refusal. There is \theta_i\in A with \beta_i(j)\in\{\bot,\theta_i\}\quad\text{for every }j\neq i. Participant i deposits the reservation r_i=r_{\theta_i} and exactly the declination set D_i=\{j\in J\setminus\{i\}:\beta_i(j)=\bot\}. This hypothesis connects private bilateral willingness to the public deposit. It is behavioural, not an algebraic consequence of the other four hypotheses.

4.2 The theorem

Write \hat{\rho}_B and \hat{\gamma}_B for the unconstrained bilateral construction: Definition 2.3 with the negotiation clause deleted, i.e. the relation that would obtain if every pair could negotiate at zero cost.

Theorem 4.5 (Accession equivalence). Assume (H1)–(H5). Then \rho_A \;=\; \hat{\rho}_B \qquad\text{and}\qquad \gamma_A(i,j) \;=\; \hat{\gamma}_B(i,j) \ \ \text{for all } (i,j) \in \rho_A . Moreover the accession construction uses exactly n deposits and represents \rho_A with n+\sum_i|D_i| logical records, whereas the bilateral construction requires one negotiation for each mutually compatible unordered pair — up to \binom{n}{2}. If failed attempts are repeated independently until conclusion, concluding every possible pair takes \binom{n}{2}/\sigma attempts in expectation. Explicit enumeration of a dense relation still takes \Theta(n^2) time because it has that many edges.

If one grade coordinate uses O(\log|C|) bits and each participant identifier uses O(\log n) bits, the implicit representation uses O\!\left(n|D|\log|C|+\left(n+\sum_i|D_i|\right)\log n\right) bits. The n\log n term records each depositor. A pair query requires two set lookups and one coordinatewise meet. Its expected time is O(|D|) with hashed declination sets.

Proof. Relation. (\subseteq) Let (i,j) \in \rho_A. By Definition 2.4, neither participant declines the other and r_i(r_j(\top_S))\neq\bot. Under (H1) and (H5), this grade is \theta_i\wedge\theta_j=\beta_i(j)\wedge\beta_j(i), so (i,j) \in \hat{\rho}_B. (\supseteq) Let (i,j) \in \hat\rho_B. Then \beta_i(j)\wedge\beta_j(i)\neq\bot, so neither willingness is bottom. By (H5), neither participant declines the other. Under (H1), the accession grade is the same non-bottom meet. Hence (i,j) \in \rho_A.

Grade. By (H5) each participant’s reservation is r_{\theta_i}, a meet with the fixed element \theta_i. Meets in a lattice are commutative, associative, and idempotent, so \gamma_A(i,j) \;=\; r_{\theta_i}\!\left(r_{\theta_j}(\top_S)\right) \;=\; \top_S \wedge \theta_j \wedge \theta_i \;=\; \theta_i \wedge \theta_j , using \theta_i \preceq \top_S. By (H1) again, \beta_i(j) = \theta_i and \beta_j(i) = \theta_j on \hat\rho_B, so \hat\gamma_B(i,j) = \beta_i(j) \wedge \beta_j(i) = \theta_i \wedge \theta_j. The two agree. (H2) guarantees this grade governs the pair symmetrically without any further declaration, so no counterparty response is required to make it operative. Hypothesis (H4) guarantees that where the two deposits describe pre-existing state inconsistently the residual is fixed by rule rather than reopening a negotiation. (H3) guarantees the declination sets are well defined at a determinate time, and (H5) connects those sets to bilateral willingness.

Cost. The n deposits and their declination sets represent the relation implicitly. A query for one pair is a membership test on two published sets. Enumerating every pair retains the output-size lower bound. \square

Corollary 4.6 (Strict count advantage under capacity). Under the hypotheses of Theorem 4.5, let the eligible bilateral population in Theorem 3.4 be the |\hat\rho_B|/2 mutually compatible unordered pairs. Define the mean-field directed-edge count by B(t)=2P_M(t). Then \lim_{t\to\infty}B(t)=\min\!\left\{|\hat\rho_B|,\frac{2\bar c}{\mu}\right\}. The accession construction has |\rho_A|=|\hat\rho_B| edges. Its count is therefore strictly larger in the limit when |\hat\rho_B|>2\bar c/\mu. If P_0<\bar c/\mu, the count gap is strict at every finite time whenever |\hat\rho_B|\ge2\bar c/\mu. This is a comparison of mean-field counts, not a set-inclusion claim about a stochastic realised relation.

4.3 What the equivalence costs: the content gap

An authority may offer full terms to one counterparty and narrower terms to another. A common reservation that respects both offers must use their common lower bound. This can weaken the first relation, although the counterparty’s own terms may already impose the same limit. Proposition 4.7 identifies exactly when that loss occurs. An authority’s profile records its reservation and declinations. A network profile collects these declarations for all participants.

Proposition 4.7 (Exact content-gap criterion). Permit pair-specific willingness and define b_i=\bigwedge_{\substack{k\ne i:\\\beta_i(k)\ne\bot}}\beta_i(k), with b_i=\top_S when the index set is empty. Set r_i=r_{a_i} and D_i=\{k\in J\setminus\{i\}:\beta_i(k)=\bot\}. Call a_i\in A feasible when \top_S\wedge a_i\preceq\beta_i(k) for every k\ne i with \beta_i(k)\ne\bot. Every feasible unscoped profile satisfies the following bound on each mutually compatible pair, meaning a pair for which \beta_i(j)\wedge\beta_j(i)\neq\bot: \gamma_A(i,j)=\top_S\wedge a_i\wedge a_j \preceq\top_S\wedge b_i\wedge b_j \preceq\beta_i(j)\wedge\beta_j(i)=\hat\gamma_B(i,j). If each b_i belongs to A, the profile a_i=b_i attains the upper bound. Under that closure condition it reproduces the bilateral grades exactly if and only if the second inequality is equality for every mutually compatible pair. Pair-specific willingness alone does not imply a strict gap: another participant’s weaker term can mask the variation.

Proof. Feasibility puts \top_S\wedge a_i below every non-bottom grade that participant i offers, hence below their meet. Monotonicity gives the display. Membership b_i\in A makes the upper bound admissible. The final equality criterion is then necessary and sufficient. \square

Under (H1)–(H5), Theorem 4.5 preserves both the relation and its grades. Corollary 4.6 gives the accession construction a count advantage when its threshold holds. Without the counterparty-independent alignment in (H5), an unscoped reservation can lose both relation and content. If \top_S\wedge b_i\wedge b_j=\bot on a mutually compatible pair, the accession profile loses that edge. If this meet is non-bottom but lies below the bilateral grade, the edge remains at a weaker grade. MLI Art. 28(8) permits a reservation to be scoped to a named list of counterparty instruments, with the enforcement rule that “the reservations described in subparagraphs a) through o) above shall not apply to any Covered Tax Agreement that is not included on the list” — silence construed against the reserver. Scoping restores pair-specific content at the cost of O(n) declarations per participant, hence \Theta(n^2) declarations in the worst case.

Remark 4.8. \Theta(n^2) declarations is not \Theta(n^2) negotiations. A declaration is unilateral, machine-checkable, published, and takes effect on a clock. A negotiation requires a counterparty’s assent, cannot be timed, and can fail. The complexity class is the same. The institutional operation differs.

Exact equivalence can fail by a small amount or on only a few pairs. To measure both possibilities, the next proposition assigns evenly spaced numerical ranks to the four classes. It compares the declared common terms with bilateral willingness in the same represented domains.

Proposition 4.8a (Approximation and disagreement).

Give the four classes ranks 0,1/3,2/3,1, written s(c). For nonempty D, define d(g,h)=\max_{d\in D}|s(g_d)-s(h_d)|, \qquad q_i(j)=\begin{cases}\bot,&j\in D_i,\\a_i,&j\notin D_i.\end{cases} Here a_i\in A is the deposited cap. Set \varepsilon_{ij}=\max\{d(q_i(j),\beta_i(j)),d(q_j(i),\beta_j(i))\}. Under (H1), with absent edges assigned class \bot, d(\gamma_A(i,j),\hat\gamma_B(i,j))\le\varepsilon_{ij}. For probability weights p_{ij} on unordered pairs, \sum_{i<j}p_{ij}\mathbf1\{\gamma_A(i,j)\ne\hat\gamma_B(i,j)\} \le\min\left\{1,3\sum_{i<j}p_{ij}\varepsilon_{ij}\right\}. The same bound applies to disagreement about edge existence. If s_i counts directed entries where q_i(j)\ne\beta_i(j), at most \min\{\binom n2,\sum_i s_i\} unordered pairs have different classes.

Proof. Coordinatewise meet takes the minimum of the two ranks, and |\min(x,y)-\min(x',y')|\le\max\{|x-x'|,|y-y'|\}. Apply this inequality in each coordinate. Distinct classes have distance at least 1/3, giving the weighted bound. Every differing pair contains at least one differing directed willingness entry. \square

Hypothesis (H5) makes every \varepsilon_{ij} zero. The proposition also controls approximate profiles. Its error measure concerns represented domains. A clause outside those domains requires a separate recorded treatment.

4.4 Acceptance as the default requirement

A common instrument can require a separate acceptance before each relation takes effect. The authorities can still file their acceptances together, but the filing must identify every accepted counterparty. When most pairs should have a relation, this reverses which exceptions the register must record.

Proposition 4.9 (Opt-in collapse). Replace (H3) by its dual: accession has effect only for a participant that deposits an acceptance of the acceding participant. Let A_i denote i’s acceptance set, with A_i\subseteq J\setminus\{i\}. Then \rho_A' \;=\; \{(i,j) : i\ne j,\ j \in A_i \ \text{and}\ i \in A_j\}, and its representation contains n accession records plus \sum_i |A_i| pair-indexed acceptance entries. The entry count is \Theta(n^2) whenever the target relation is dense. One signed deposit may batch an entire set A_i, so this is not a lower bound on physical instruments. Under an explicit one-pair-per-signed-instrument rule, the physical instrument count is n+\sum_i|A_i|. The relation is pairwise in information even when signatures are batched. If issuing and maintaining pair-indexed entries has bounded throughput and positive maintenance load, Theorem 3.4 applies with those parameters. Quadratic counting alone does not imply an asymptote.

Proof. Immediate from the definition: every ordered membership in an acceptance set is one pair-indexed entry. Dense reciprocal acceptance has n(n-1) such entries. Batching changes the number of signed containers, not the represented relation. \square

The default determines which pair-specific decisions require entries. Opt-out records declinations and opt-in records acceptances. For a dense target relation, the former can be linear while the latter is quadratic.

4.5 Work over the life of a relation

A count of signed filings measures only formation. The same relation can require notices, updated terms, renewed evidence, and eventual settlement of open matters. These operations determine whether fewer negotiations also mean less total work.

Twenty sequential accessions require twenty deposits and 190 notices to incumbents. Each notice opens a separate receipt-based clock. Two subsequent updates by every participant produce forty updates and, with nineteen recipients each, 760 further receipt tasks. Certificate renewal and exception handling create additional work.

Compare the same participants, target relation, horizon H, and sequence of changes. Both constructions must meet the same receipt, certificate-age, availability, and effective-date requirements. Let m count active unordered pairs.

Proposition 4.9a (Lifecycle account). For sequential accession from an empty population, incumbent receipt tasks number N=\sum_{j=1}^{n}(j-1)=\frac{n(n-1)}2. Let U count participant updates. Update u has f_u notice recipients and requires amendments to k_u bilateral instruments. Write F=\sum_u f_u and K=\sum_u k_u. Let E count directed exception-processing events, including creation, amendment, and required review. Let R_v(H) and R_e(H) count participant and active-pair certificate refreshes after initial issuance. With fixed event prices, lifecycle costs are \begin{aligned} C_A={}&an+r(N+F)+dU+x_AE\\ &{}+v_AR_v(H)+e_AR_e(H)+Z_A(H),\\ C_B={}&bm+hK+x_BE+v_BR_v(H)+e_BR_e(H)+Z_B(H). \end{aligned} Here a,r,d price accession, receipt processing, and participant updates. The prices b,h cover bilateral formation and amendment, including their required communications. The remaining coefficients price the named exception and refresh events. The terms Z_A,Z_B cover standard preparation, initial certificate issuance, migration, exit, evidence transfer, and settlement of accrued rights.

Proof. The j-th accession has j-1 incumbents. Each update contributes its recipient and amendment counts. The remaining terms sum disjoint event classes. \square

The formation price b includes the attempts needed for a concluded bilateral instrument. An attempt-level account can instead substitute actual attempt costs. Independent repeated attempts with success probability \sigma have expected count m/\sigma. A separate entrant receipt requirement adds its actual receipt count to N. A shared transmission can carry several receipt tasks. Profile-processing prices must reflect domain count, exception content, and input size.

For fixed positive r, incumbent receipt work alone is \Omega(n^2). A total \Theta(n^2) claim also needs bounds on updates, exceptions, refreshes, and the horizon. With bounded degree and updates per participant, bilateral work can remain linear while all-incumbent notice remains quadratic. Both constructions must complete their work within the common deadlines. Aggregate costs alone do not establish a feasible schedule. Common refresh requirements remain in both totals, even when equal prices cancel in their difference.

A parallel receipt schedule. Start the clock when authenticated batch inputs are available at their receivers. Receiver i has h_i tasks, each requiring at most \tau_i processing time. Dedicated receiver workers process their queues independently without idle time. Processing finishes within \max_i h_i\tau_i. Consider relations whose eligibility conditions continue to hold and which receive no valid declination. Adding the largest applicable notice window bounds their latest effective time when expiry satisfies every remaining timing condition.

For one update by each of n authorities, with notice to every other authority, h_i=n-1. Equal service bounds \tau give processing time at most (n-1)\tau with n receiver workers. Aggregate receipt work is at most n(n-1)\tau. The elapsed-time bound uses independent processing. Unilateral instruments remove the counterparty-assent requirement. Dissemination time precedes this bound, and each authority retains its decision rights.

Constructed comparisons. Use twenty participants and two update rounds, with each participant updating separately in each round. Then U=40, F=760, and K=4m. Two certificate refresh rounds give R_v=40 and R_e=2m. Exception entries remain unchanged during these updates. The standard and initial certificates already exist. The horizon contains no exits or migrations, so Z_A=Z_B=0.

Use synthetic cost units: accession 1, receipt 0.1, participant update 1, exception entry 0.1, bilateral formation 4, bilateral amendment 1, and certificate refresh 0.25. Bilateral formation includes pair-specific terms, so x_B=0. Thus C_A=165+0.5m+0.1E,\qquad C_B=10+8.5m.

Common relation m E C_A C_B
Complete graph 190 0 260 1625
Perfect matching 10 360 206 95

The matching uses a common non-bottom class. Each participant declines its eighteen nonpartners, producing 360 directed entries for 180 excluded unordered pairs. The profile satisfies (H5). All-incumbent notice still covers the excluded pairs. Equal pooling allocates dense-graph costs of 13 and 81.25 per participant. The matching costs are 10.30 and 4.75. Pooling is an explicit allocation assumption, since sequential notice otherwise distributes work unevenly. Prices can reverse either comparison. For the matching, formation at 20 and amendment at 2 give C_B=295>C_A=206. For the complete graph, receipt processing at 2 gives C_A=2065>C_B=1625. These are computed examples with stipulated prices, rather than measured institutional workloads.

4.6 Participation and useful approximation

Lower total cost alone does not make accession attractive to every authority. A participant compares its own share of the savings with the value it loses by accepting common terms. The following condition requires accession to beat both bilateral service and abstention for that participant.

Proposition 4.9b (Strict participation condition). Fix a cohort, a common horizon, and a conservative profile from Proposition 4.7. Participant i’s gross benefit is G_i(\gamma)=\sum_{j\ne i}u_{ij}(\gamma(i,j)), \qquad R_i=\sum_{j\ne i}L_{ij}\varepsilon_{ij}, where u_{ij} is nondecreasing and L_{ij}-Lipschitz for the distance in Proposition 4.8a. Let C_i^A,C_i^B be allocated lifecycle costs, including migration and service charges. If C_i^B-C_i^A>R_i,\qquad G_i(\hat\gamma_B)-R_i>C_i^A, accession gives i greater net benefit than bilateral service and an abstention payoff of zero.

Proof. Proposition 4.8a and the Lipschitz bounds give G_i(\gamma_A)\ge G_i(\hat\gamma_B)-R_i. Subtract C_i^A and apply both strict inequalities. \square

The condition concerns a fixed joining cohort. It specifies individual participation gains without prescribing how that cohort first coordinates.

A useful profile beyond (H5). Take the dense twenty-participant example and one domain. Set \top_S=\top and A=\{\mathsf{partial},\top\}. Every directed willingness equals \top, except \beta_1(2)=\mathsf{partial}. Choose a_1=\mathsf{partial}, every other a_i=\top, and empty declination sets. This profile is conservative, but participant 1’s counterparty-dependent willingness violates (H5). Accession weakens eighteen of 190 unordered pairs. The pair \{1,2\} retains its bilateral class. Give each endpoint benefit u_{ij}(g)=(100/19)s(g). Participant 1’s bilateral and accession gross benefits are 5600/57 and 200/3. Its loss is 600/19. Participant 2 loses zero, and each other participant loses 100/57. Under equal pooling, each participant saves 81.25-13=68.25>600/19. The smallest accession gross benefit is 200/3>13. Thus every participant satisfies Proposition 4.9b despite pair-dependent willingness and eighteen class disagreements. The benefit and cost units are synthetic.

4.7 A prospective measurement design

A pilot can estimate profile error, lifecycle work, and voluntary use in one defined recognition domain. One reproducible design recruits twelve authorities and records every eligible invitation, refusal, enrolment, and withdrawal. Before elicitation, fix the standard, reservation menu, domain mapping, service deadlines, cost categories, and pair weights. Each authority assesses eleven counterparties, giving 132 directed assessments and 66 unordered comparisons. Preserve signed assessments separately from jointly negotiated outcomes.

Use matched source cases for accession and bilateral assessment. Counterbalance their order and keep initial assessments independent of the other method’s result. Archive each clause-to-coordinate mapping with its source-case identifier. Record omitted clauses, their materiality, and the responsible authority’s required treatment. A mandatory omitted clause receives explicit pair-specific handling whose work enters the exception account. This handling supplements the executable interface and its reserved local questions.

For each method, record profile bytes, class and exception entries, authoring and review time, signatures, and actual receipt dates. Compute directed willingness error, pair-class disagreement, and edge-existence disagreement using uniform and predeclared use weights. Distinguish declared willingness from negotiated classes. Repeat both assessments after the same predefined rule change at day ninety. Measure update effort, recipients, amendments, elapsed time, missed deadlines, and certificate refreshes. A negotiation still open at the measurement date remains an open case.

Compute participant loss from the declared utility schedule and observed class differences. Report R_i, assessed loss, allocated cost, and participation margins separately. Include sensitivity to predeclared class values and use weights. Follow voluntary deposits and exercised recognition for six months. Record signing, first use, repeated use, renewal, withdrawal, and the reasons given for each decision. These measurements distinguish participation from practical use.

Publish permitted source fixtures, clause mappings, event definitions, cost calculations, and de-identified records. Report complete cohort counts and missing assessments. Inference beyond the recruited cohort requires a separate sampling and recruitment argument. The computed examples establish feasible regimes, while this design specifies the observations needed to estimate them.

4.8 Empirical instances and the opt-in contrast

The Hague Conference produced two accession conventions with different defaults. Counts below are from the depositary’s status and acceptance tables on 31 August 2026 [HCCH 2026a, 2026c].

Convention Default Parties Accessions Pairwise acceptances
Apostille (1961), Art. 12 consent unless objected 130 listed, 128 in force 88 0 of 88
Evidence (1970), Art. 39 no relation until accepted 69 50 50 of 50

The Evidence Convention is a procedural contrast, not an exact instance of Proposition 4.9’s generic two-acceptance rule. Article 39 creates a pairwise relation when an incumbent accepts an acceding state, and the depositary publishes that acceptance matrix pair by pair. The Apostille Convention requires no bilateral acceptance for its 88 accessions. Twenty-one of those accessions drew at least one objection. No objection prevented the accession from entering into force generally. Each objection withheld only the objecting pair. This is historical evidence for the mechanism, not a controlled experiment: the instruments differ in other respects.

The BEPS Multilateral Instrument supplies a separate structural precedent. Article 2 brings a bilateral tax agreement within scope only when both parties independently list it. One multilateral text therefore modifies many existing bilateral instruments by intersecting unilateral declarations.

5 Recognition through intermediaries

Accession determines direct relations from the authorities’ instruments. An intermediary can make further evidence available when the governing law or instrument permits that use. The receiving authority then needs a rule for combining the restrictions on every part of the route. The class calculation and the executable evidence calculation answer distinct parts of that question.

5.1 The maximal operator on negotiated classes

Suppose an intermediary recognizes an issuer only at a partial grade. Full recognition of that intermediary must preserve the restriction on the issuer’s determination. Giving the complete route a higher grade would remove a limit merely by adding an intermediary. We call that failure grade laundering.

Definition 5.1 (Laundering resistance). A composition operator \circledast assigning a grade to each path is laundering-resistant if no path is graded above any part of itself: for every path \pi and every contiguous sub-path \sigma of \pi, \circledast(\pi) \preceq \circledast(\sigma).

The sub-path quantifier is necessary. Suppose the definition required only that appending hops never improve a grade. Then F(\pi) := \gamma(e_1), the grade of the path’s first edge, qualifies. Appending leaves the first edge untouched, so F(\pi') = F(\pi). Yet F is exactly the laundering attack — on a two-hop path with a strong first edge and a weak second, F returns the strong grade. Append-monotonicity constrains prefixes but not suffixes. Quantifying over every contiguous sub-path constrains both. The single-edge instances are the only ones Lemma 5.2 invokes. The full quantifier is what the informal statement means.

Lemma 5.2 (The meet is the maximal laundering-resistant operator). Let \circledast be any path-grade operator that agrees with \gamma on single-edge paths. If \circledast is laundering-resistant then \circledast(\pi) \;\preceq\; \bigwedge_{e \in \pi} \gamma(e) \qquad \text{for every path } \pi, and the bound is attained by the meet itself. Hence the meet is the greatest laundering-resistant composition operator: every safe alternative lies below it, and every operator that can exceed it on some path is unsafe.

Proof. Fix a path \pi and an edge e \in \pi. The single-edge path (e) is a contiguous sub-path of \pi and has grade \gamma(e) by hypothesis, so laundering resistance gives \circledast(\pi) \preceq \gamma(e) directly. As e was arbitrary, \circledast(\pi) \preceq \bigwedge_{e \in \pi}\gamma(e). The meet attains the bound and is itself laundering-resistant, since the meet over the edges of \pi is below the meet over the edges of any sub-path of \pi. \square

Corollary 5.3 (Which operators are unsafe). Any operator that can return a grade not below the meet of the path’s edge grades is not laundering-resistant. In a totally ordered numerical embedding, an arithmetic or geometric mean is therefore unsafe whenever unequal grades produce a mean above their minimum. Here safety means laundering resistance in the negotiated class order. Proposition 5.6a establishes the corresponding property for executable treatment.

A monotone scalar valuation into [0,1] can assign each path the product of its edge scores. The product is no larger than any factor, but it is a scalar rather than a grade in L. A nontrivial product with at least two nontrivial coordinates has no order-reflecting embedding into a total order and no canonical map from the product score back to a grade. Repeated intermediate scores also introduce path length. Multiplication therefore defines a possible value functional, not a grade operator. Definition 2.6 keeps the maximal grade operator as the meet and places attenuation in the scalar value.

Remark 5.4. Transitive-trust research analyses failures in path aggregation. Naive metrics that average or boost confidence along a path can exceed its weakest edge. Bottleneck and path-independent approaches address related failures [Beth, Borcherding & Klein 1994, Maurer 1996, Reiter & Stubblebine 1997, 1999]. Lemma 5.2 derives the maximal operator under Definition 5.1.

Definition 2.6 keeps path attenuation outside the grade lattice. The meet records the model’s composed negotiated recognition class. The applicable instrument and current-use witnesses determine executable treatment under Section 6.3. The scalar factor records the modelled loss in value from an additional operational hop. The first is a structural result. The second is a modelling choice.

5.2 Finding the available routes

For one domain, the best route is the route whose weakest relation has the highest grade. This is the established widest-path problem. Multiple domains require one such calculation per coordinate, with the routes retained when their evidence will be used.

Proposition 5.5 (Closure on a product of chains). Let L=C^D, with C a finite chain. Then:

  1. For one coordinate, the closure grade is the widest-path value. Single-source values are computable by a modified Dijkstra algorithm in O(m+n\log n) [Pollack 1960, Hu 1961].

  2. For L=C^D, the closure is the coordinatewise collection of those widest-path values. It is computable in O(|D|(m+n\log n)) per source. The path attaining one coordinate need not attain another.

  3. All-pairs closure is also computable by Floyd–Warshall over (L,\vee,\wedge) in O(n^3|D|) coordinate operations [Backhouse & Carré 1975, Rote 1990, Mohri 2002]. For a connected symmetric single-chain network, one maximum spanning tree contains every pair’s bottleneck value. For a disconnected network, the corresponding maximum spanning forest has this property within each component [Camerini 1978, Gabow & Tarjan 1988].

Proof sketch. On a chain, meet and join are minimum and maximum, so the standard widest-path proof applies. Products compute both operations coordinatewise. Floyd–Warshall is valid because a finite product of chains is distributive. The spanning-tree claim is the standard symmetric single-chain bottleneck result. \square

Remark 5.6 (Attenuated value). For \delta<1, the best scalar path value q_K also depends on path length. For an arbitrary monotone valuation v, an exact hop-indexed dynamic program must retain reachable grade states. Direct vector operations take O(Km|L||D|) time per source and O(n|L|) memory per layer. Precomputed meet and value tables reduce the transition bound to O(Km|L|). Pareto pruning can reduce the realised state set but not the worst-case bound. This computation does not change the grade closure.

A class label alone cannot express how a condition changes with a request or with time. For that calculation, a treatment map records how much of the incoming evidence an authority permits the receiver to use. An evidence-support lattice orders these possible amounts of support. A monotone map preserves that order, and a contractive map returns no more support than it receives. The next proposition shows that composing such maps preserves every intermediate restriction. Section 6.3 supplies the policies and current answers that select the maps.

Proposition 5.6a (Composition of executable treatment). Fix one request and use context. For each domain d, let \mathcal G_d be a common evidence-support lattice with bottom 0_d and top 1_d. Local encodings use explicit embeddings into this lattice. Each carried treatment map \varphi_{ij,d}:\mathcal G_d\to\mathcal G_d is monotone and contractive: x\le y\Longrightarrow\varphi_{ij,d}(x)\le\varphi_{ij,d}(y), \qquad \varphi_{ij,d}(x)\le x. For \pi=(v_0,\ldots,v_k), define \Phi_{\pi,d}=\varphi_{v_0v_1,d}\circ\cdots\circ\varphi_{v_{k-1}v_k,d}. This map is monotone, contractive, and bottom-preserving. Under pointwise comparison, it is below the treatment of every contiguous sub-path.

Proof. Composition preserves monotonicity and contractivity. Write the composition as A\circ B\circ C, where B is the selected sub-path. For every x, A(B(C(x)))\le B(C(x))\le B(x). The first inequality uses contractivity of A. The second uses contractivity of C and monotonicity of B. An empty prefix or suffix contributes the identity. Contractivity gives \Phi_{\pi,d}(0_d)=0_d. \square

An edge i\to j means that i recognises j, so evidence travels from j to i. For cap maps \varphi_{e,d}(x)=x\wedge k_{e,d}, the composition is exactly \Phi_{\pi,d}(x)=x\wedge\bigwedge_{e\in\pi}k_{e,d}. General treatment maps retain their ordered composition. Proposition 5.5 computes the negotiated class envelope. Executable evaluation also retains the path, source assertions, policy clauses, and questions reserved to each receiving authority for current determination. Its cost includes their validation and evaluation.

5.3 The value of additional routes

Allowing another hop retains every shorter route and may add a useful longer one. The first result states this consequence for the value functional. The star example then computes the added value when every peripheral participant has a direct relation only with the same central participant.

Theorem 5.7 (Horizon dominance). For every network and every 1\le K\le K', V_{K'}(G)\ge V_K(G),\qquad V_{K'}-V_K=\sum_{i\ne j}w_iw_j\bigl(q_{K'}(i,j)-q_K(i,j)\bigr). Because every w_i is positive, equality holds exactly when q_{K'}(i,j)=q_K(i,j) for every ordered pair i\ne j.

Proof. Every path admitted by the K-hop maximum is also admitted by the K'-hop maximum. Hence q_{K'}(i,j)\ge q_K(i,j) term by term. Summing gives the identity and the inequality. Positivity of the weights gives the equality criterion. \square

Theorem 5.8 (Star amplification). Let n\ge3, and let G be a bidirected star with hub h of weight w_h \in (0,1) and n-1 spokes of equal weight (1-w_h)/(n-1), all edges at grade \top, hop cap 2, attenuation \delta. Then \frac{V_2}{V_1} \;=\; 1 \;+\; \frac{\delta\,(1-w_h)\,(n-2)}{2\,w_h\,(n-1)} . This quantity is strictly increasing in n and strictly decreasing in the hub’s weight share w_h. In particular, with uniform weights w_h = 1/n, \frac{V_2}{V_1} \;=\; 1 + \frac{\delta (n-2)}{2} \;=\; \Theta(n).

Proof. V_1 counts the 2(n-1) directed hub–spoke pairs: V_1 = 2 w_h \sum_{i \neq h} w_i = 2 w_h (1 - w_h). The closure adds every ordered spoke–spoke pair at two hops, at value \delta: V_2 - V_1 \;=\; \delta\left[\Bigl(\sum_{i \neq h} w_i\Bigr)^{2} - \sum_{i \neq h} w_i^2\right] = \delta\left[(1-w_h)^2 - \frac{(1-w_h)^2}{n-1}\right] = \delta (1-w_h)^2 \frac{n-2}{n-1}. Dividing gives the formula. Monotonicity in n is immediate from (n-2)/(n-1) increasing. Its monotonicity in w_h follows from (1-w_h)/w_h strictly decreasing on (0,1). \square

Corollary 5.9 (The composition multiple is a concentration statistic). For a bidirected star with arbitrary spoke weights, V_2/V_1 \;=\; 1 + \delta\,\frac{(1-w_h)^2 - \sum_{i \ne h} w_i^2}{2\,w_h\,(1-w_h)}. For fixed w_h, the multiple increases exactly when \sum_{i\ne h}w_i^2 decreases. It is therefore maximal when the spoke weights are equal.

Whether composition value accrues to the periphery rather than the hub is a question about its distribution among participants. The scalar V_k cannot answer it. This paper defines no per-participant value functional, so the allocation remains open.

5.4 Why bilateral instruments do not compose by default

The additional routes have legal effect only when the applicable instruments or law permit recognition through an intermediary.

A bilateral instrument is a text between two parties. Absent an express transitivity or incorporation clause or applicable law, an AB instrument and a BC instrument do not determine AC effect. An applicable instrument or law must supply the rule.

Messages alone do not supply the persistent recognition grades used by the closure calculation. Each edge must record a grade in the common lattice, and the rules must determine how those grades combine without another negotiation. These conditions make the graph-theoretic difference computable. Executable use retains original assertions, ordered treatment maps, fresh obligations, and the current local decision. Legal realisability also requires applicable law or an express instrument to give the intermediary determination transitive effect. Without that legal effect, only direct-route opportunities can contribute. Realized value is then bounded by V_1, subject to admissible evidence and current decisions. Theorem 5.8 remains a graph-theoretic result, not a claim about legally realisable value.

6 The recognition instrument

The formal construction needs a legal instrument that states who consents, what that consent covers, and when its effects begin. A software test records observed behavior against a published specification. The authority’s signed instruction determines the recognition it gives under its own law. The instrument below separates these acts and implements the four public rules of the equivalence theorem. Theorem 4.5 retains the additional willingness assumption.

6.1 Conformance and recognition

Conformance reports software behaviour against a published suite. Recognition is an authority’s decision to give stated effect, under its own law, to another authority’s determinations. A conformance result can cap recognition. It cannot grant it.

The proposed instrument reserves each authority’s decisions through the following boundaries.

  1. No consensus process binds authorities that are not parties to the transaction.

  2. No shared log is authoritative state. Each authority keeps and signs its own state.

  3. No validator set speaks for an authority that did not produce the transaction.

  4. No network act creates, changes, or extinguishes an authority’s recognition relation.

Two authorities may still sign a bilateral commitment. It binds only them. The four boundaries concern the network and do not restrict direct agreement.

6.2 The listing and the signed instruction

A listing records an implementation’s conformance class, specification version, test date, and published evidence. Each class sets a ceiling on the grade that another authority may extend to that implementation.

A grade is an element of L=C^D. It records the negotiated class in each domain. The retained policy clauses determine a particular assertion’s treatment.

A standing recognition instruction is an authority’s signed local rule. For each domain it states a ceiling c_i, a minimum counterparty class, a minimum specification version, a maximum evidence age, and an exclusion set. It is optional. An authority without one remains free to recognize counterparties by individual instrument.

Let a_i be the class ceiling attached to authority i’s current listing, and let \theta_i=c_i\wedge a_i. A standing instruction must select \theta_i from the published menu A. Say that i and j are eligible when each satisfies the other’s class and version floors, each satisfies the other’s evidence-age rule, and neither appears in the other’s exclusion set. They establish a reciprocal relation exactly when they are eligible and \theta_i\wedge\theta_j\neq\bot. Its grade is g_{ij}=g_{ji}=\theta_i\wedge\theta_j=c_i\wedge a_i\wedge c_j\wedge a_j. Otherwise there is no edge. This uses the finite meet menu in (H1) and the aligned willingness in (H5) and the reciprocal grade required by (H2). The notice and collision rules below supply (H3)–(H4). Theorem 4.5 applies only when each authority’s deposit and declinations also match its willingness as (H5) states. Other instruments may create directed grades. They lie outside this equivalence theorem.

An express bilateral instrument and a standing instruction are separate grounds. For a domain addressed by both, the express instrument governs until it expires or both authorities replace it. For any residual conflict between the two standing instructions, the coordinatewise meet governs the negotiated class. Applicable treatment constraints combine by pointwise meet, and their fresh obligations combine by union. These fixed rules supply (H4). Bilateral texts compose only when an express clause, an applicable instrument, or applicable law supplies the rule.

6.3 Executable recognition

A registry can accept a foreign authentication while still deciding whether the document may be used for the requested filing. The agreed class summarizes the recognition terms. Execution applies their clauses to that filing and obtains each answer the receiving authority has reserved for itself. We call a question requiring such an answer a fresh question. Its answer may use existing evidence, but it must satisfy the rule for this request and time.

Let q identify one immutable request revision. It binds the action, subject, purpose, participating authorities, and applicable rule and specification versions. The context names the authority-use stage and its use time t. A later request revision has its own identifier.

A policy identifies the recognizing authority, the source authority whose evidence it accepts, and the questions the receiver reserves for itself. It must also retain the instrument and version that authorize this treatment. Its identifier distinguishes the policy record from the request identifier.

For an edge i\to j, a signed policy records P_{ij}=(\mathrm{id},i,j,R_{ij},F_{ij},\varphi_{ij},\alpha_{ij},\nu_{ij},I_{ij}). The field \mathrm{id} identifies the policy, i the recognizing authority, and j the source authority whose determinations it recognizes. Here R_{ij} names the domains whose typed evidence may travel from j to i. The set F_{ij} names fresh questions owned by receiving authority i. The fields \alpha_{ij}, \nu_{ij}, and I_{ij} identify the authorising instrument, exact version, and validity interval. The map \varphi_{ij,d}^{q,t}:\mathcal G_d\to\mathcal G_d gives the permitted evidence treatment in domain d. Carriage and fresh evaluation are independent. A carried domain may also be the subject of a fresh question. Carried evidence may inform that evaluation, while the receiving authority supplies the current answer. Evidence support is distinct from permission to perform the requested action.

The bottom and top of the evidence-support lattice are 0_d and 1_d. A partial policy caps support at an intermediate level p_d. A conditional policy uses a condition \chi(q,t) evaluated for the request and use time.

For 0_d<p_d<1_d, the executable policies include \begin{aligned} \varphi_{\mathrm{none},d}^{q,t}(x)&=0_d, & \varphi_{\mathrm{full},d}^{q,t}(x)&=x,\\ \varphi_{\mathrm{partial},d}^{q,t}(x)&=x\wedge p_d, & \varphi_{\mathrm{conditional},d}^{q,t}(x)&= \begin{cases}x,&\chi(q,t)=\mathsf{True},\\0_d,&\chi(q,t)=\mathsf{False}.\end{cases} \end{aligned} The condition requires an admissible answer with its authority and dependencies. An unanswered condition remains pending and supplies no admitted witness. An unresolved condition or missing comparison embedding leaves map comparison unresolved. Comparison means pointwise comparison of the actual maps at the stated context. At x=1_d, a true conditional gives 1_d>p_d, while a false conditional gives 0_d<p_d. The labels therefore have no universal semantic order.

Every applicable clause remains available to the evaluator. Let \mathcal C_{ij}(q,t) be the clauses selected by the instrument’s precedence rules. For a nonempty selected set, their combined treatment and fresh questions are \begin{aligned} \varphi_{ij,d}^{q,t}(x)&=\bigwedge_{\ell\in\mathcal C_{ij}(q,t)}\varphi_{\ell,d}^{q,t}(x),\\ F_{ij}(q,t)&=\bigcup_{\ell\in\mathcal C_{ij}(q,t)}F_\ell(q,t). \end{aligned} An empty selected set establishes no carriage right. Carried domains must satisfy every applicable carriage restriction. The evaluator retains the clauses as well as their negotiated class. A partial clause combined with a true conditional gives x\wedge p_d. The same partial clause combined with a false conditional gives 0_d. Thus a satisfied condition preserves the partial cap.

For \pi=(v_0,\ldots,v_k), compose the maps in the order of Proposition 5.6a. Retain the route’s carried domains and fresh obligations: \begin{aligned} R_\pi&=\bigcap_{\ell=1}^{k}R_{v_{\ell-1}v_\ell},\\ F_\pi&=\bigcup_{\ell=1}^{k}\{(v_{\ell-1},f):f\in F_{v_{\ell-1}v_\ell}\}. \end{aligned} The authority tag identifies responsibility for each question. Each route retains all its policies and unresolved obligations.

Proposition 6.1 (Executable accession equivalence). Suppose both constructions use the same versioned menu clauses. Each participant’s bilateral terms and deposit select the same clauses under (H5). Then Theorem 4.5 gives the same negotiated classes and relation. For every common context, clause evaluation gives the same edge maps and fresh-question sets. Ordered route evaluation gives the same transported evidence and obligations.

Proof. On each established pair, both constructions select the same clauses. Their pointwise meets and obligation unions agree. Induction on path length gives equal route maps and obligations. Equal admitted witnesses and local decisions then give equal executable outcomes. \square

Equality of policy maps still leaves a concrete evidence obligation. A witness is the retained evidence that supports the requested treatment. A witness family collects the source assertions, applicable policies, condition answers, and records needed to validate their combined use. A use certificate records that evidence’s validity for the exact request and current eligibility conditions.

A carried assertion retains its original act identifier, issuer, subject, purpose, rule, validity interval, and dependencies. A recognition receipt records the receiver’s treatment and consumed inputs. It preserves the source act and its original validity. Derived evidence retains the source acts, admitted derivation rules, and a checked computation receipt. Write \operatorname{Joint}(W,q,t) when witness family W is jointly admissible for the exact request and use time. This check covers source scope and validity, current authority, policy versions, condition answers, and compatible dependencies. A checked use certificate can bind a reusable determination to q without another human signature. Every fresh answer retains its owning authority and exact question. Its use certificate binds the answer to the current request and eligibility conditions. Pending questions retain their complete authenticated records. Expiry and supersession leave unanswered questions unresolved.

The destination’s current decision is a separate record: J_i(q,t)\in\{\mathsf{Allow},\mathsf{Refuse},\mathsf{Pending}\}. A standing instruction may authorise its automatic computation. The set F_W contains every authority-tagged fresh question required by the routes and derivation policies supporting W. The predicate \operatorname{RequiredSupport}_i(q,W) means that the admitted evidence supplies the support authority i requires for request q. The predicate \operatorname{FreshSatisfied} requires an admissible authoritative answer to each exact question. Each answer must satisfy its governing rule for the request revision and current eligibility conditions. Execution through witness family W requires \begin{aligned} \operatorname{Execute}_i(q,t,W)\iff{}&\operatorname{Joint}(W,q,t)\\ &{}\land\operatorname{RequiredSupport}_i(q,W)\\ &{}\land\operatorname{FreshSatisfied}(F_W,W,q,t)\\ &{}\land J_i(q,t)=\mathsf{Allow}. \end{aligned} Support summaries use jointly admitted witnesses. A coordinatewise class envelope does not supply those witnesses. Different routes may contribute evidence when the complete family passes the joint check. Imported evidence leaves a reserved local refusal authoritative.

For a fixed request revision and use time, a complete dependency record identifies every state input that can change the evaluation. Let \Sigma denote the evaluated state, o the outcome, and \Delta the complete set of dependencies. The evaluator emits both the result and that set: \operatorname{Eval}(q,t,\Sigma)=(o,\Delta). Write \Sigma\equiv_\Delta\Sigma' when two states agree on every dependency and its protected version. Dependency completeness requires \Sigma\equiv_\Delta\Sigma'\Longrightarrow\operatorname{Eval}(q,t,\Sigma')=(o,\Delta). Agreement covers every declared input and its protected version. Dependencies include point reads, ranges, absence predicates, and roots selecting rules, authorities, participants, and routes. They include the inputs that select witnesses and fresh questions. Isolated field-change checks do not establish this property. The current-use transition checks the relevant mutable inputs and records its decision in one protected operation. Those inputs cannot change between the check and the recorded decision. Its certificate names the actual authority-use stage and durable time. A later stage uses institutionally sufficient continuing authority or performs its own current-use check.

A successful recognition witness. Consider one domain d and the route i\to m\to j. Authority j issued an assertion with support 1_d. Authority m’s conditional policy has an admissible true answer. Authority i’s policy carries that evidence with cap p_d. The route supplies \Phi_{\pi,d}^{q,t}(1_d)=p_d. Suppose the filing requires support p_d. Its witness retains the original assertion, both policies, the condition answer, and their current-use certificates. Each receiving authority answers its own fresh questions. With \operatorname{Joint}(W,q,t) and J_i(q,t)=\mathsf{Allow}, the filing completes automatically. The source determination supplies reusable evidence, so the receiver does not repeat its production. A false condition instead supplies 0_d. An authoritative local refusal instead leaves \operatorname{Execute}_i(q,t,W) false. All three outcomes preserve the same source history.

6.4 Publishing the authorities' records

The public register contains signed deposits, listings, notices, instructions, declinations, and effective dates. Every version is content-addressed. An implementation verifies each signature and the referenced version from the object itself. The register may delay or omit an authentic object. It cannot create one.

Existing recognition relations live in each authority’s own signed registry. They continue if the public register is unavailable. Independent mirrors compare signed heads, and independent monitors repeat the published conformance tests against the listed endpoint. A listing is evidence of observed conformance at a stated time. It is not proof of institutional quality or of the truth of filed facts.

The instrument assigns each necessary operation to a named role:

  1. The standards body writes and versions the specification and conformance suite. It makes no conformance finding and grants no recognition.

  2. The certifier runs the suite, signs each conformance finding, and carries liability for that finding. It owns neither the standard nor the register.

  3. The depositary receives and dates signed instruments. It decides no application on the merits.

  4. The council maintains the public register through a registrar that performs prescribed operations without deciding the merits of recognition. It publishes authenticated objects and computed pairwise effects. It owns no sovereign state.

  5. The supervisory authority appoints the registrar, owns the register data, sets fees, and hears administrative complaints.

The standards body holds the specification, conformance suite, reference vectors, and conformance mark. It holds no depositary, registry, admission, recognition, fee-setting, or adjudicative power. The five bodies are institutionally distinct. The supervisory authority controls the register rather than any participant’s recognition. The Cape Town system supplies the ratified precedent for registrar, supervisor, and depositary separation. On 2 September 2026 the Convention had 90 states and one regional organisation as parties. The Aircraft Protocol had 87 states and one regional organisation, including 69 states by accession [UNIDROIT 2026].

6.5 From signature to effective relation

  1. The jurisdiction designates its competent authority by public function, assigns a unique authority-function identifier, and binds its signing key to that identifier. The register permits one active accession for each identifier.

  2. It commissions an implementation from any supplier it chooses.

  3. The certifier runs the published suite, signs the resulting finding, and submits the finding and evidence to the registrar. The registrar publishes the listing.

  4. The competent authority deposits its signed instrument with the depositary.

  5. The council publishes authenticated notice to each incumbent’s designated endpoint. The acceding authority or depositary may directly present the same object. Independently verifiable actual receipt by either route opens that incumbent’s notice clock. A signed acknowledgement is optional evidence.

  6. Each incumbent may decline the accession during the window W from its own receipt date.

  7. The relation enters into force pair by pair on the date computed from that notice and any declination.

  8. The registrar publishes the accession, each effective pair, and the signed objects from which the result was computed.

A delayed notice shifts only the affected pair’s effective date. It does not delay the accession or any other pair. A declination is signed by a competent authority, needs no stated ground, and affects only the two authorities. It may be withdrawn by signed notice. Suspension after entry follows the same pairwise form and states whether open transactions settle or freeze. Settlement is the default. Membership and pairwise effect therefore have distinct clocks. Appendix A compares ratified implementations of that distinction.

The contrast in ratified instruments is material. The Apostille Convention lists 130 parties, 128 in force. Twenty-one of its 88 accessions drew at least one objection, and none was blocked generally. The Evidence Convention lists 69 parties and 50 accessions. Each creates a bilateral relation only when an incumbent accepts it. The instruments differ in other respects, so this is evidence for the default rule rather than a controlled experiment. The UNCITRAL status page listed 13 jurisdictions with legislation enacting or influenced by MLETR on 31 August 2026. That younger and heterogeneous population is a rate caution, not evidence for the equivalence theorem [UNCITRAL 2026].

Once a relation takes effect, the receiving authority must be able to trace the determinations on which it relies. That record must survive recognition through an intermediary.

6.6 Recognition provenance and truncation

A composed determination carries an unordered recognition set. Each authority adds its own signed entry and the identifiers of the determinations it consumed. The signature covers the complete set presented by that authority and those consumed identifiers. A receiver can therefore verify every disclosed step without treating route order as part of the negotiated grade. The set indexes provenance. Each receipt also binds its consumed inputs, policy, request, and use context. The evaluator retains the ordered dependency graph for executable treatment.

A signed receipt or replay trace can bind a determination to the intermediary’s input. If that intermediary later omits the determination’s identifier from its signed output, the two signed records attribute the truncation. Disclosed provenance remains an attestation rather than a completeness proof. Executable use requires a complete dependency record for the declared evaluation. That requirement concerns declared computation inputs and does not establish disclosure of all real-world conduct. An authority that performs a fresh evaluation instead of recognizing a foreign determination issues its own determination and assumes responsibility for it.

A declination can reject any carried determination whose recognition set names the excluded authority. This reaches disclosed composition. An authority seeking a wider exclusion may instead narrow its own standing instruction against the excluded authority’s recognition neighbourhood. That choice is local, published, and deliberately broader.

A conformance statement identifies the disclosed dependencies, typed paths, policies, tests, and observation interval it covers. Let D_{\mathrm{declared}} contain disclosed inputs and D_{\mathrm{used}} contain inputs actually consumed. Extending the result to the actual computation requires correct typing, applicable recognition rules, and evidence that D_{\mathrm{used}}\subseteq D_{\mathrm{declared}}. The disclosed record alone cannot establish this inclusion. Two executions can publish the same record while one consumes an additional upstream determination. Every checker restricted to that record receives identical evidence in both cases.

The certifier states dependency completeness separately, with supporting evidence and observation scope. An identified undeclared dependency remains outside the certified scope until the certifier assesses it. The receiving authority requests that assessment or substitutes an authorised independent determination. Input traces and supplier declarations support assessment within the systems and suppliers they cover. The evaluator’s complete declared read set preserves computational dependencies within that boundary. It does not establish disclosure of every external influence.

6.7 Domains that require a separate instrument

Ordinary recognition never carries sanctions clearance. A sanctions certificate must name the lists or authority relied on, its direction, the parties, the covered transaction epochs, its validity period, and its revocation rule. Without that certificate, every receiving authority screens under its own current lists.

Every determination also names the legal tradition under which it was produced. No implementation may supply that field by default.

6.8 Private obligations and Recourse

Recognition gives legal effect to another authority’s determination. It does not execute a private obligation. Recourse is a separate application layer: the parties consent to an arbitration instrument, a tribunal determines the claim under the agreed rules, execution follows the award under the chosen enforcement route, and the record distinguishes the award, satisfaction, and recovery. Provider action cannot alter a sovereign recognition relation.

Each record must identify the legal object it establishes. Identity establishes who a person is, while authority requires the relevant grant. Recording an act does not itself establish legal finality. Recording a claim does not establish that it has been paid. An award and its recovery are separate events. A network holds no title. An opportunity alone establishes no executed right. A listing records conformance. An authority’s signed instrument creates recognition.

7 The security condition

The receiving authority relies on assertions about conformance and source determinations. An issuer may benefit from making a false assertion, while detecting it requires someone to pay for an investigation. Unilateral accession leaves this incentive problem unresolved. A bond can impose a loss after detection, but it gives an unpaid investigator no reason to do the work.

We first study a challenger paid only when an investigation finds falsity. If every issuer reports truthfully, that challenger pays to investigate and receives no reward. This explains why a finite reward can leave residual false reporting in equilibrium. A separate construction pays for completed inspections regardless of their findings and reserves collateral for all outstanding exposure.

7.1 The issuer and the investigator

An attestation is the issuer’s assertion whose truth the investigator can check. The bond is collateral available for the stated forfeiture if falsity is established. Here q will denote a false-reporting probability, independently of the request identifier in the preceding section. The model compares each actor’s gain from its available actions. An equilibrium means that neither actor gains by changing its own choice while the other keeps its strategy. A pure strategy chooses one action. A mixed strategy chooses actions with stated probabilities.

Definition 7.1 (Attestation game). An issuer chooses a truthful or false attestation. A false attestation yields private gain G>0 before sanction. The issuer posts a bond B\ge0. If a challenge detects falsity, a fraction \phi\in(0,1] of the bond is forfeited. A challenger pays \kappa>0 to investigate and detects falsity with probability \bar p\in(0,1]. The challenger receives \beta\phi B, where \beta\in[0,1). The remaining (1-\beta)\phi B is paid to an identified injured party. We assume that this payment is legally enforceable and that such a party exists whenever the model is applied. The game treats the challenger as a third party distinct from the injured party. No player observes falsity without investigation. Only the challenger chooses whether to investigate in this two-player game. An injured party’s distinct recovery motive is outside it.

A best response is an action that maximizes an actor's payoff against the other actor's strategy.

Definition 7.2 (Best responses). Let q be the probability of a false attestation and r the probability of investigation. The challenger’s best-response correspondence is \operatorname{BR}_C(q)= \begin{cases} \{\mathrm{investigate}\},&q\beta\phi\bar pB>\kappa,\\ \{\mathrm{abstain}\},&q\beta\phi\bar pB<\kappa,\\ \{\mathrm{investigate},\mathrm{abstain}\},&q\beta\phi\bar pB=\kappa. \end{cases} The issuer’s best-response correspondence is obtained by comparing G with r\phi\bar pB: false is strict above that expected sanction, truthful is strict below it, and both are best responses at equality.

Remark 7.3 (Prior art). The issuer’s inequality is the classical deterrence condition: expected sanction must exceed gain [Becker 1968, Polinsky & Shavell 2000]. The additional constraint is the challenger’s participation condition from private enforcement [Landes & Posner 1975].

7.2 The unpaid investigator

Theorem 7.4 (No-bounty impossibility). If \beta=0, then for every finite B the unique equilibrium is false attestation and no investigation. No finite bond induces truthful reporting.

Proof. Investigation pays -\kappa<0 regardless of the issuer’s action, so abstention is the challenger’s unique best response. Against abstention, falsity pays G>0 and truth pays zero. \square

Remark 7.5. Bond size alone does not secure the system. Expected forfeiture is the product of bond size, forfeited fraction, investigation probability, and detection probability. It is zero when investigation is unfunded.

7.3 A reward for finding falsity

Theorem 7.6 (Finite bond and equilibrium behaviour). Suppose 0<\beta<1, \phi>0, \bar p>0, \kappa>0, and write B^* \;:=\; \frac{1}{\phi\bar p}\,\max\left\{\,G,\ \frac{\kappa}{\beta}\,\right\}. Both incentive constraints — that the challenger is willing to investigate a false attestation, and that the issuer does not gain by making one against an investigating challenger — hold if and only if B \ge B^*. For any B > B^* the game has no pure-strategy equilibrium and its unique equilibrium is mixed, with the issuer misreporting at rate q^* = \kappa/(\beta\phi\bar p B) and the challenger investigating at rate r^* = G/(\phi\bar p B). The misreport rate is therefore exactly \kappa/(\beta\phi\bar p B), which is \Theta(1/B) and does not depend on G: raising the payoff to fraud raises the challenger’s investigation rate, not the fraud rate. Driving the misreport rate to zero requires B \to \infty.

Proof. (i) Challenger participation. Investigating a false attestation yields \beta\phi\bar p B - \kappa \ge 0, i.e. B \ge \kappa/(\beta\phi\bar p). (ii) Issuer deterrence. Against a challenger who investigates, a false attestation yields G - \phi\bar p B \le 0, i.e. B \ge G/(\phi\bar p). The conjunction is B \ge B^*. For the equilibrium: against a truthful issuer, investigating pays -\kappa < 0, so investigate is not a best reply and no profile with a truthful issuer and an investigating challenger is an equilibrium. This is an inspection game [Avenhaus, von Stengel & Zamir 2002]. Mixing, the challenger is indifferent when q\,\beta\phi\bar p B = \kappa and the issuer is indifferent when r\,\phi\bar p B = G, giving q^* and r^*. Both lie in (0,1) when B>B^*, and the profile is then the unique equilibrium. \square

A challenger can still expect a reward while one strategic issuer tells the truth if the wider sample contains other detectable false reports. The next result assumes that background source of errors and prevents the challenger from choosing samples after learning their contents. The assumption concerns every information state available when the challenger commits to investigate.

Corollary 7.6a (Full deterrence under blind sampling). Suppose each attestation is sampled with an exogenous probability s\in(0,1]. Conditional on a sample, the pool has a false-attestation rate \pi_b\in(0,1], even when the strategic issuer reports truthfully. The challenger undertakes to complete the sampled investigation before learning its issuer or other informative signals. More generally, each information state available at acceptance has posterior falsity probability at least \pi_b. The detection bound \bar p holds conditional on that information and falsity. Every sampled issuer supplies the stated collectible bond. Then truthful reporting by the strategic issuer and investigation of every sample form an equilibrium whenever B\ge B^{**}:=\frac{1}{\phi\bar p}\max\left\{\frac{G}{s},\frac{\kappa}{\pi_b\beta}\right\}.

Proof. Each sampled investigation pays \pi_b\beta\phi\bar pB-\kappa. A false attestation by the strategic issuer faces expected sanction s\phi\bar pB. Both incentive constraints hold at the stated bound. \square

The bound diverges as \pi_b\to0. The result depends on blind sampling and on an exogenous source of detectable errors. It does not establish full deterrence in the two-player game of Theorem 7.6.

Remark 7.6b. The statements cover different environments. Without an exogenous error pool, a bounty-funded challenger has nothing to find when every issuer is truthful. The two-player game gives a declining misreport rate. Blind sampling gives full deterrence only under Corollary 7.6a’s additional assumptions.

Corollary 7.7 (The binding constraint). B^* is set by the issuer’s gain when G > \kappa/\beta and by the challenger’s economics when G < \kappa/\beta. Both constraints bind when G=\kappa/\beta. In the second regime — cheap frauds that are expensive to detect — the bond is determined entirely by what it costs to find the fraud and by how much of the bond the finder keeps, and it is insensitive to the size of the fraud. Raising \beta lowers the required bond hyperbolically. The challenger reward share therefore determines whether the scheme is affordable.

Comparative statics. B^* is strictly decreasing in \phi and \bar p. It is non-increasing in \beta, strictly on the challenger branch. It is non-decreasing in G, strictly on the issuer branch, and non-decreasing in \kappa, strictly on the challenger branch.

7.4 Collateral for the value at risk

The incentive inequalities can restrict how much value a participant may expose to reliance on its attestations. This interpretation needs an upper bound on the gain from misreporting at that level of exposure. Here V denotes value at risk, distinct from the normalized network-value functional V_k.

Theorem 7.8 (The bond is a capacity price). Suppose the maximum gain extractable by misreporting is bounded linearly by the value at risk the participant carries, G \le \kappa_G V for a constant \kappa_G > 0. Then both constraints of Theorem 7.6 hold whenever V \;\le\; \frac{\phi\bar p\, B}{\kappa_G} \qquad\text{and}\qquad B \;\ge\; \frac{\kappa}{\beta\phi\bar p}.

Proof. G \le \kappa_G V \le \phi\bar p B gives the issuer branch B \ge G/(\phi\bar p). The second inequality is the challenger branch verbatim. \square

The required bond is the maximum of a fixed detection-cost floor and a linear value-risk term set by the gain from misreporting. The cap is sufficient for the issuer branch and is necessary only where the upper bound is tight — a participant whose extractable gain sits well below \kappa_G V is deterred at a larger V than the cap allows.

The governing instruments can implement these sufficient inequalities as a published bond schedule. A participant then deposits an accession instrument and separately posts the bond required for its value at risk. Whether the schedule creates a capacity right or removes administrative discretion depends on those instruments. The linear value-risk bound has the security-budget scaling studied by Budish and Auer, here applied to reliance on attestations [Budish 2018/2022, Auer 2019].

Repeated use creates a further problem: several false reports can generate gains before the first claim is paid. The same collateral cannot cover each report in full if it can be forfeited only once. We therefore group attestations into cohorts, each with a reserved collateral allocation and a bound on its total coordinated gain. Inspection fees come from a separate funded budget, so truthful operation still pays for completed work.

Definition 7.9 (Outstanding exposure cohorts). A cohort contains a fixed set of attestations covered by one collateral allocation b_j. Its contents close before its inspection sample becomes observable. The bound G_j covers the total gain from every coordinated false-reporting plan within the cohort, measured at its first exposure date. Fix one valuation date. Let w_j>0 discount values at cohort j’s first exposure to that date. For every coordinated plan, its total incremental gain is bounded by \sum_{j\in\mathcal F}w_jG_j. Here \mathcal F contains the cohorts with false reports, and the bound includes gains from coordination across cohorts. The factors w_j and cohort bounds are known when each cohort closes. The factor d_j below measures payment value at cohort j’s first exposure date. Let \mathcal O_t contain all cohorts with outstanding collateral obligations at time t. Their allocations are disjoint and satisfy \sum_{j\in\mathcal O_t}b_j\le B_t. Here B_t is collateral available after prior claims and other encumbrances. Each allocation remains pledged through the claim period and resolution of timely claims. A key change leaves these obligations attached to their collateral and liable person.

Proposition 7.10 (Funded inspections and repeated participation). For every history available when cohort j closes, and every false-reporting plan fixed before its sample becomes observable, assume these conditional bounds:

  1. An inspection samples at least one false attestation with probability at least s_j>0.

  2. Conditional on sampling falsity, completed inspections detect it with probability at least p_j>0.

  3. Conditional on detection, the appointed decision-maker establishes forfeiture and the custodian lawfully pays it by age D_j with probability at least c_j>0.

  4. On payment, realised collateral value is at least h_jb_j, with discount factor at least d_j>0.

All bounds condition on the issuer’s information and permitted control of other actors. Truthful reporting incurs no forfeiture in this model. The forfeiture fraction is \phi, and each cohort allocation can be forfeited once. Cohort j purchases k_j verifiably completed inspections at fee a_j\ge\kappa_j each. A funded budget A_j\ge k_ja_j pays these fees regardless of findings. Inspection budgets are funded separately from pledged collateral. Then truthful reporting is a best response throughout any finite sequence of cohorts if G_j\le\phi b_j\chi_j,\qquad \chi_j=s_jp_jc_jh_jd_j, \qquad \sum_{j\in\mathcal O_t}b_j\le B_t\quad\text{for every }t. Strict gain inequalities make every positive-gain false-reporting plan strictly unprofitable.

Proof. Conditional bounds give a payment-event probability of at least s_jp_jc_j. Discounted payment on that event is at least \phi b_jh_jd_j. Expected forfeiture therefore covers the cohort’s entire gain bound. Disjoint allocations permit addition across cohorts after multiplication by w_j. Conditional expectation extends the comparison to adaptive participation. The inspection budget pays for completed work even when every report is truthful. \square

The argument uses conditional bounds instead of inspection independence. Uniformly sampling k_j of N_j closed attestations gives s_j=k_j/N_j against every nonempty false subset. Revealing sample information before closure requires a separate conditional bound. Common control and coordinated interference enter the detection and collection bounds. The payment bound concerns recovery by age D_j. Pending claims continue to occupy collateral, while later recoveries may increase payment. Longer detection and collection periods increase outstanding collateral and its carrying cost. If G_j\le\kappa_G V_j, sufficient allocation is b_j\ge\frac{\kappa_G V_j}{\phi\chi_j}. This prices all reliance exposure within the cohort against one collectible allocation. A per-attestation gain bound cannot substitute for G_j when gains accumulate before collection.

Example 7.11 (Positive capacity and collateral reuse). Take N=20, k=10, and s=\tfrac12,\quad p=\tfrac45,\quad c=\tfrac34,\quad h=\tfrac45,\quad d=\tfrac9{10},\quad\phi=\tfrac12. Then \chi=27/125. Allocation b=2000 gives expected discounted forfeiture of at least 216. With V=2000 and \kappa_G=1/10, the gain bound 200 is below expected forfeiture 216. The corresponding sufficient capacity limit is V\le2160. Each inspection costs 2, so the funded inspection budget is 20. Legitimate benefit 80, collateral carrying cost 20, and other operating cost 20 leave surplus 20. These stipulated values exhibit a feasible regime.

Two outstanding cohorts require allocations totalling 4000. For a counterexample, take the sampling, detection, collection, valuation, and discount bounds as attained. Suppose both cohorts pledge the same 2000, and their corresponding random events coincide. The allocation pays once, with expected discounted forfeiture exactly 216. A deviation attaining 200 in each cohort then has expected net gain 400-216=184. Reducing collection probability c to 1/4 reduces the single-cohort sanction bound to 72.

The two-player model remains distinct. With B=100, \phi=1/2, \bar p=4/5, \beta=1/4, G=10, and \kappa=2, Theorem 7.6 gives B^*=25, q^*=1/5, and r^*=1/4. Both indifference equations equal zero, and detected falsity has probability 1/25. For a finite stream, let q_t bound misconduct probability conditional on history. Let L_t bound its attributable harm. Both bounds are nonnegative and measurable from that history. Conditional expectation gives \mathbb E[\text{total harm}]\le\mathbb E\!\left[\sum_tq_tL_t\right]. For deterministic bounds uniform over histories, this becomes \sum_tq_tL_t. That risk account remains separate from posted collateral and any amount actually collected. It supplies an exposure budget for a residual-misconduct regime.

7.5 Sources of positive detection probability

Theorem 7.6 assumes a positive conditional detection probability \bar p. A machine-decidable claim with public inputs and repeatable tests supplies one route. Mandated human inspection or an independent examination can supply another. Each method requires a measured lower bound for the population to which the theorem is applied. The bounty changes the investigation rate r, not the conditional detection probability \bar p.

  1. Deterministic tests. A claim that is decidable from published inputs can have a reproducible conditional detection rate.

  2. Independent access. Public reruns or mandated third-party access keep the subject from choosing which investigations can execute.

  3. Investigation funding. A positive bounty share can fund investigation as Theorem 7.6 specifies. Other mandated funding can change the challenger’s payoff model.

A negative control distinguishes a functioning suite from one that accepts a known-bad input. The governing law, the representation made, and the reliance placed on it determine the legal consequence.

7.6 Forfeiture and payment

The bounty-funded game of Theorem 7.6 imposes the distribution constraint below. The separately funded inspections in Proposition 7.10 use their own fee and collateral conditions. The severity schedule is a separate design recommendation.

Graded severity. Full forfeiture for every failure can exceed insurable exposure. Severity should track provability: full forfeiture only for conditions that are machine-provable from published evidence (equivocation — two conflicting attestations under one key — is the canonical example), materially less for conditions established by adjudication, and a per-period cap for availability failures.

Distribution. In the bounty-funded game, the forfeited bond must be split so that the challenger’s share \beta is strictly positive and large enough to satisfy Theorem 7.6’s participation constraint, with the balance going to the identified injured party or pro rata to identified injured parties. The certifier makes the conformance finding, and the registrar publishes it. Neither receives forfeiture proceeds. This rule keeps the decision-maker and the ministerial publisher outside the distribution.

Enforcement. Forfeiture across jurisdictions is a question of enforcing an award, not of achieving consensus. An award within Article I of the New York Convention may be recognized and enforced in its 172 party states, subject to reservations and declarations, forum procedure under Article III, refusal grounds under Article V, and applicable local law [United Nations 2026]. A protocol determination is not the arbitral award required by this enforcement route. The bond instrument must contain the arbitration agreement and direct a custodian to release against the award. A tribunal proceeding under that agreement must produce an award before this route can release the bond. The separate Recourse instrument supplies the tribunal and award that determine whether the bond is forfeit [Lorgat 2026b].

7.7 Boundary of the bond model

  • Universal collusion. If every potential investigator colludes with the issuer, the investigation rate is r=0, and false reporting yields G. Independent supervisory review, open challenger entry, and diverse funding are possible controls. Non-collusion remains an assumption.

  • Non-monetisable harm. Where a false attestation extinguishes a legal right or misstates a person’s status, a bond supplies compensation rather than the lost legal position. The bond condition prices and reduces monetisable misreporting in the game. Full deterrence requires Corollary 7.6a or Proposition 7.10’s additional assumptions. Legal safeguards govern other harms.

  • Correlated collateral. If the bond is denominated in an asset whose value falls when the network fails, the bond available at the moment of need is smaller than the bond posted. A denomination floor computed on a stressed valuation mitigates the exposure and consumes additional capital.

7.8 Inspection and service capacity

Funding an inspection does not establish that a qualified person can complete it before the deadline. Filings, renewals, translations, and decisions compete for available service time. Two urgent judgments can require the same qualified person while later administrative capacity remains unused. The following assignment model tests these restrictions for every group of tasks, then combines the resulting schedule with inspection funding and collateral.

Fix a finite planning horizon and a slot length \Delta>0. A service task occupies one qualified worker for one whole slot. Its declared processing time is at most \Delta, including required recording and handoff. Tasks with longer indivisible durations require a different scheduling model. Each available worker-slot has one canonical identity, even when several suppliers offer access to the same worker. Availability means reserved service capacity under the stated performance assumptions.

Let \mathcal J be the required tasks and \mathcal S the available worker-slots. For task i, let E_i\subseteq\mathcal S contain its eligible slots. Eligibility requires the qualification, current authority, available inputs, and completion deadline specified for that task. Input delivery occurs before its release time. Let E(U)=\bigcup_{i\in U}E_i for a subset U\subseteq\mathcal J. An assignment reserves a different eligible slot for each task. The task list includes existing commitments before it includes proposed additional exposure.

Proposition 7.12 (Exact service capacity in the slot model). Every task has a feasible assignment if and only if |U|\le |E(U)|\qquad\text{for every }U\subseteq\mathcal J. A maximum flow produces either a complete assignment or a subset whose demand exceeds its eligible capacity.

Proof. An assignment injects every subset U into E(U), which proves necessity. For sufficiency, join a source to each task with capacity one. Join each task to its eligible slots with capacity |\mathcal J|+1, and each slot to the sink with capacity one. A cut of capacity below |\mathcal J| cannot cross a task-slot edge. If its source side contains tasks U, it therefore contains E(U). Its capacity is at least |\mathcal J|-|U|+|E(U)|, hence at least |\mathcal J|. Integral maximum flow assigns every task. Conversely, a deficient minimum cut supplies the stated subset. \square

The total slot count checks only the special case U=\mathcal J. Two urgent judgments may share a single eligible slot while later administrative capacity remains unused. Such a subset identifies the qualification and deadline for additional service procurement. An added slot expands capacity only for tasks that can use it. The responsible operator can purchase the required capacity within its existing mandate and budget. This construction adds no decision-making body.

Fresh judgment remains a task even when its supporting certificate is reusable. Reuse removes a task only when the governing rule accepts the same evidence for the present request, rule version, and time. The model can reserve tasks for every outcome in a declared contingency workload. Different contingencies may share a reservation only when their mutual exclusivity is established. If actual service or input delivery fails, the premise changes and the remaining schedule must be recomputed. Existing duties retain their deadlines and require the specified replacement or escalation action.

Inspection tasks. Consider the simultaneously outstanding cohorts of Definition 7.9. Cohort j closes N_j records before a uniform sample of size k_j becomes observable. The sample selection is independent of the issuer’s choice of false records, conditional on its information at closure. Every reserved inspection slot is qualified to inspect every record in that cohort. Alternatively, the service schedule must be feasible for every sample the selection rule can produce. Selecting only the records that happen to fit a schedule changes the sampling law.

For any nonempty false subset, the sample encounters falsity with probability at least k_j/N_j. To see this, choose one false record. Its inclusion probability is exactly k_j/N_j. Write \eta_j=p_jc_jh_jd_j, \qquad L_j=\frac{G_jN_j}{\phi\eta_j}. The remaining conditional bounds and collection period are those of Proposition 7.10. The inspection fee a_j pays for accepted completed work and covers its stipulated cost. Payment remains the same for a truthful report and an adverse finding. Any resulting adjudication has separately reserved capacity and an outcome-independent service fee. The governing decision rule retains responsibility for the finding and forfeiture.

Proposition 7.13 (Joint inspection, funding, and collateral certificate). Let B be collectible collateral available for the cohorts, and let A be separately funded service money. For integers 1\le k_j\le N_j, reserve collateral b_j satisfying b_j\ge\frac{L_j}{k_j},\qquad \sum_jb_j\le B. Include the k_j inspection tasks and all background and reserved contingency tasks in \mathcal J(k). Let their fixed total fee be C(k). If C(k)\le A and Proposition 7.12 assigns every task, the cohort gain inequalities of Proposition 7.10 hold. Every stipulated task completes by its deadline under the declared service and input-delivery assumptions. An entirely truthful population receives the same funded inspection work.

Proof. Uniform sampling gives s_j\ge k_j/N_j. Thus \phi b_j\eta_jk_j/N_j\ge G_j. Separate allocations preserve this inequality under simultaneous claims, as in Proposition 7.10. The service budget covers all admitted fees, independently of inspection outcomes. The assignment gives distinct qualified slots within each task’s completion window. \square

The inequalities separate three resources: collectible collateral, service money, and qualified time. Increasing one resource can leave another constraint binding. For fixed cohorts with common eligibility for their records, exact least-fee planning over a finite slot catalogue is a finite problem: \min_{1\le k_j\le N_j}\ C(k) \quad\text{subject to}\quad \sum_j\frac{L_j}{k_j}\le B \quad\text{and a complete assignment for }\mathcal J(k). Integer sample counts can be enumerated, with one assignment computation for each vector in this common-eligibility case. Record-dependent qualifications require the corresponding feasibility checks for every supported sample. The least feasible value is optimal within this specified slot model. The enumeration has \prod_jN_j vectors, so this formulation makes no general efficiency claim for large instances. Approved additional service offers can enter as finite procurement choices with their stated prices and availability. The same calculation can identify the least-cost sufficient purchase.

Example 7.14 (Positive capacity and a binding inspection budget). Two cohorts each contain four records and have aggregate gain bound G_j=3. Take \phi=\eta_j=1, collateral B=12, and inspection fee a_j=1. These are stipulated quantities in a finite example. Other required services have separately reserved capacity and funding in this example. Required allocations are b_j=12/k_j. The plan (k_1,k_2)=(2,2) uses collateral (6,6) and service money 4. Four eligible inspection slots complete its work.

Every plan with at most three inspections uses at least 18 collateral. The best such integer vector is (1,2) or (2,1). Thus four inspections are necessary and sufficient at B=12. The least inspection fee is exactly 4, over all sixteen sample-count vectors. The all-honest case still pays for four completed inspections and collects zero forfeiture. If legitimate benefit is 10, collateral carrying cost is 2, and other cost is 1, the surplus is 3.

The example uses separate pools of 12 collateral and 4 service money. Spending four units from the collateral pool instead leaves only eight units pledged and fails the displayed gain bounds. For a strict deterrence example, keep the same plan and take G_j=29/10. The expected sanction bound remains 3, strictly above each cohort’s total gain bound.

Example 7.15 (A deadline obstruction and useful procurement). Add one filing to Example 7.14 and suppose five worker-slots are available. The four inspections can use only three of them before their common deadline. The filing can use either of the two later slots. Total tasks and total slots both number five, but the four inspections have only three eligible slots. They violate Proposition 7.12 with a deficit of one. An authorized purchase of one qualified slot before the inspection deadline completes the schedule. Purchasing a third late filing slot leaves the obstruction unchanged.

This links accession growth to a concrete service boundary. For one all-incumbent update per participant, the receipt workload is n(n-1) tasks before reuse or batching assumptions. If every receipt can use each of q dedicated slots per horizon, the capacity condition is n(n-1)\le q. Six such slots serve an update round for three authorities. A fourth authority requires twelve slots, and purchasing six suitable slots preserves the full update round. Filings, judgments, and inspections consume their own eligible capacity or compete through the same assignment graph. Accession removes repeated assent while this account prices the work required to exercise the resulting relations.

8 Administration and reserved recognition decisions

The preceding results require people to receive instruments, publish records, inspect claims, and decide contested matters. The governing instrument must identify who performs each act and who bears responsibility for it. A registrar can perform prescribed computations while each recognizing authority chooses its own recognition rule. This allocation also needs duties, funding, and a means of replacing the operator without losing participants’ records.

8.1 Ministerial and authority-conferring acts

Definition 8.1 (Ministerial performance). An operation is ministerial under the instrument when submitted objects, verifiable time, and published rules determine its output without merits discretion. Examples include receipt, timestamping, publication, circulation, and comparison with an authenticated register. This classification describes how an assigned operation runs. The instrument separately identifies who chooses or changes each governing rule. A mechanical operation can have legal consequences, as authenticated notice starts the recognition clock under (H3). Recognition decisions, admission, exclusion, rule-making, fees, and complaints decisions each require an express allocation. Applicable law determines duties and liability from the actor’s functions, statements, and conduct.

VCLT Article 76(2) requires the depositary to act impartially. Article 77(1)(d) directs it to examine whether an instrument is in due and proper form and to bring any defect to the filing state. Article 77(2) refers a difference between a state and the depositary about performance to the signatories and contracting states [VCLT 1969]. Definition 8.1 separately excludes a merits determination.

Definition 8.2 (Allocation of functions). The standards body versions the standard and the test suite. A separately incorporated certifier applies that suite and signs each finding. The depositary receives and dates accession instruments. The council, acting through an appointed registrar, publishes authenticated objects and authenticated notice to each incumbent’s designated endpoint. The depositary or acceding authority may directly present the same notice object. Independently verifiable actual receipt by either route opens the affected notice clock. The supervisory authority owns the register data, appoints and dismisses the registrar, approves operating rules, receives complaints, and sets fees. The governing instruments assign responsibility for filed facts to their signer, for conformance findings to the certifier, and for publication errors to the registrar. They also keep the register data and assignable operating rights with the supervisory authority. Each recognising authority signs or amends its own standing recognition rule. The registrar’s mandate identifies prescribed computations and the statements it may issue to relying parties.

Proposition 8.3 (Allocation of recognition decisions). Suppose effective governing instruments impose Definition 8.2’s allocation and the registrar performs its assigned operations. Those instruments reserve choice and amendment of each standing recognition rule to its recognising authority. The registrar computes and publishes the resulting records. Its replacement preserves participants’ signed accessions when the supervisor retains the data and assignable operating rights.

Proof. The instruments identify the authority that signs each rule and the operations assigned to the registrar. Replacement transfers those operations and their supporting rights. Each participant’s signed accession remains its own instrument. \square

The proposition establishes an allocation within the governing instruments. Legal duties, available claims, and liability require the applicable law and actual conduct. Cape Town Convention Article 28 combines registrar operations with liability and financial assurance. In Hydrolevel, apparent authority supported the standard-setting body’s antitrust liability [Cape Town 2001, Hydrolevel 1982].

The role schedule records these reliance and recourse terms:

  • The signer identifies its authority, filed representations, intended recipients, correction duty, and the instrument supporting claims about those representations.

  • The certifier identifies the tested object, suite, observation interval, assurance class, permitted reliance, contractual duties, and complaint route. Its financial assurance names the insured entity, covered acts, limits, exclusions, and claim period.

  • The depositary and registrar identify receipt, notice, publication, and availability duties. Their records preserve evidence for correction, complaints, and operational-error claims.

  • The supervisor identifies appointment, rule-making, fee, and complaints powers. The schedule distinguishes administrative complaints from compensation claims.

  • The bond instrument identifies the forfeiture decision-maker, custodian, claimants, governing law, forum, release conditions, and recovery priority.

Local legal analysis applies the schedule to the actual actors and intended reliance. Custody and insurance records substantiate the resources and coverage available for those obligations.

8.2 Interests, appointment, and funded substitutes

An expert can receive a fixed inspection fee while its controller profits from the asset under inspection. A substitute with no disqualifying interest may be available, but its appointment still requires qualified time and funds permitted for that service. Example 8.7 computes this case after the conditions are defined.

A decision can also affect financing, referrals, and expected future work. A fee independent of the outcome removes only the incentive created by that fee. The assessment must therefore include the persons who control the decision and the rights through which they benefit. We apply these conditions to the service assignment already defined.

Fix a case and its affected objects, including the specified linked assets and economic rights. Fix also the decision parameters, applicable conflict rule, and materiality thresholds. A dated assertion names its subject, relation, object, evidence, effective interval, and evidence-receipt time. An assessment uses the assertions admitted by a stated receipt cutoff, called the evidence cut. Effective time determines when a relation applies. Receipt time determines when the assessment can use its evidence. A completeness determination names the case, participants, relevant objects, relations, and interval covered by the assessment. Missing or disputed required facts remain unresolved.

Control and economic participation have separate types. At time t, write u\rightsquigarrow_t v when an active directed control path runs from u to v. Let C_t(v) contain v and its controlling persons. The control relation includes the appointment, dismissal, remuneration, or other influence specified by the governing assessment rule. An economic right alone supplies neither a control edge nor permission to exercise another person’s authority. Each right keeps its constituting instrument, beneficiary, affected object, quantity basis, and effective interval. These distinctions are the rights and action distinctions developed in One Entity in Many Jurisdictions.

For a proposed worker-slot, the relevant persons include the decision-maker, appointing actor, and challenge reviewer. The screening rule examines their control sets at each relevant time. It also specifies which roles require distinct persons and disjoint control sets. Case-interest clearance and role separation answer different questions. A person can lack a stake in a case while reviewing that person’s own decision. Appointment and challenge rights remain assigned by the governing instruments. The following construction schedules their exercise within those rights. Naming those actors records their roles and screening conditions. Actual appointment and challenge work enters the workload as separately funded service tasks or retains its existing reserved capacity.

An economic right can benefit its holder through different channels, such as sale proceeds or future fees. Its outcome sensitivity measures the declared change associated with the case’s decision, using the unit specified for that channel. The screen adds the absolute sensitivities within each channel and compares them with a declared threshold. It therefore keeps unlike units separate and requires disclosure of the relevant rights.

Definition 8.4 (Declared interest clearance). For each distinct active economic right r, let d_r be its declared outcome sensitivity in channel and unit k(r). Channels can represent proceeds, financing, referrals, or future remuneration. Let R_t(i,s) contain the rights held by the relevant control sets and affecting case i. For positive thresholds \theta_k, define the gross screening quantity D_k(i,s,t)=\sum_{\substack{r\in R_t(i,s)\\k(r)=k}}|d_r|. A slot has declared interest clearance when every D_k(i,s,t)<\theta_k, the required role separations hold, and the relevant evidence is complete. These conditions hold throughout the service interval and at the terminal decision time.

The gross quantity is a specified conservative screen. It keeps units separate and prevents opposing entries from concealing a material incentive. The governing rule supplies the sensitivities, thresholds, affected-object scope, and required disclosures. Two distinct six-unit rights exceed a ten-unit threshold jointly. Two observations of the same right require one reconciled representation of that right before aggregation. This condition establishes clearance under the declared rule, rather than statistical independence or knowledge of undisclosed facts.

Dated paths must exist simultaneously. Suppose A controls B before time 10 and B controls a worker from time 10 onward. Those two assertions alone produce no time at which A controls the worker through B. For a finite record, partition the service interval at assertion boundaries and compute the active control closure on each segment. Check the terminal act separately when it occurs at the slot endpoint. Authority valid on [0,11) covers work during [10,11), but an act at 11 requires authority effective at 11. Later evidence can change the assessment of an earlier effective time. The historical evidence cut remains recorded while remaining acts use the current assessment.

Funding the eligible service. A willing substitute also needs payment from a legally available source. A funding pool identifies the estate entitled to the money, the cash it contains, and the purposes for which it may be spent. Existing claims and reservations reduce the amount available for another task.

An offer o names a task i(o), canonical worker-slot s(o), fee a_o, and paying pool b(o). It binds the service contract, worker, times, case parameters, asset, and supported resource slice. The same physical worker at the same time supplies one slot across all suppliers. The pool retains its legal estate, canonical account or disjoint custody slice, and permitted use. Let its recorded cash, senior encumbrances, and pending reservations be c_b,e_b,r_b. Its additional available funding is f_b=(c_b-e_b-r_b)_+. Several estate labels cannot supply overlapping slices of the same underlying cash. Proceeds rights and common control confer no additional funding or spending authority. Service money remains separate from the collateral allocations of Proposition 7.13.

An offer is eligible when it has reserved availability, suitable qualification, timely inputs, current action rights, and Definition 8.4’s clearance. The spending authority binds that offer’s exact fee, payer, recipient, task, and resource. The proposed batch contains new tasks. Existing tasks retain their reservations and occupy their existing slots. The new batch uses only the resulting free cash and residual time. Reassignment of an existing task requires a separate transition preserving its duties and reservation identity.

Selecting an offer chooses a worker, service time, fee, and permitted payer together. The constraints require one offer for every task, prevent double booking, and limit spending from each funding pool. Enough workers and enough aggregate cash can still fail this joint test.

Proposition 8.5 (Exact funded assignment under declared interests). Fix a finite task batch, a finite eligible offer catalogue \mathcal O, and the evidence and resource snapshot. A funded assignment is exactly a vector x\in\{0,1\}^{\mathcal O} satisfying \sum_{o:i(o)=i}x_o=1,\qquad \sum_{o:s(o)=s}x_o\le1,\qquad \sum_{o:b(o)=b}a_ox_o\le f_b. Complete enumeration returns a feasible assignment exactly when one exists in the catalogue. For fees in one common currency, choosing the least total fee returns a least-fee assignment. If initial pool coverage holds, reserving the selected fees preserves each pool’s coverage.

Proof. Every admitted vector selects one eligible offer for each task. Its second constraint prevents two tasks from consuming the same worker-slot. Its third constraint reserves no more than each pool’s free amount. Conversely, every funded catalogue assignment gives such a finite vector, so complete enumeration visits it. Taking the least objective value among the feasible vectors proves the stated optimality. For each pool, the reservation increment u_b satisfies u_b\le c_b-e_b-r_b. Thus e_b+r_b+u_b\le c_b, as required. \square

The enumeration is an exact finite construction. It makes no general efficiency claim for offer-priced, estate-constrained assignment. Actual reservation uses one serialised comparison and update against the checked resource and capacity state. A changed evidence cut, authority, or reservation state requires a fresh assignment check. With the stated availability, input-delivery, and duration premises, the reserved assignment completes each task within its deadline. Actual interest disclosure and institutional performance remain premises with their own evidence.

Corollary 8.6 (The fixed-fee specialization). Suppose each task has one fixed fee and one fixed permitted paying pool, independent of its selected slot. A funded assignment exists exactly when the eligible graph satisfies Proposition 7.12’s subset inequalities and \sum_{i:b(i)=b}a_i\le f_b\qquad\text{for every pool }b.

Proof. The funding inequalities have the same values under every matching. Proposition 7.12 supplies a complete eligible matching exactly under its subset inequalities. \square

An obstruction can therefore identify the missing qualified independent time, the restricted funding pool, or both. With assignment-dependent fees or alternative paying pools, funding and matching require the joint constraints of Proposition 8.5. A successful matching and sufficient total cash alone leave those constraints undecided.

Example 8.7 (Useful independent substitution). Two required inspections cost two and three currency units. The initial expert and two substitutes have qualified slots before both deadlines. A controller of the expert holds a twenty-unit proceeds exposure in the affected asset. The declared threshold is ten, so the expert’s offers fail the interest screen despite outcome-neutral inspection fees. The two substitutes, appointing actor, and challenge reviewer satisfy the declared interest and role conditions. Five free units in the permitted service estate fund the two substitute assignments. Both inspections and their deadlines remain in the completed plan. The other actors’ required service work has separately reserved time and funding in this example.

If only one substitute is available, the two inspections have one eligible slot and a capacity deficit of one. An authorized, funded purchase of a second clear qualified slot repairs that exact deficit. By contrast, two six-unit tasks restricted to an estate with six free units have a funding obstruction. Another estate’s six units change that result only through an effective permitted funding route. These examples preserve useful service while making the scarce resource and the interested decision route explicit.

8.3 A partial ratified precedent

The 2001 Convention on International Interests in Mobile Equipment supplies a ratified precedent for the separation of registrar, supervisory authority, and depositary. It also allocates title to the data, operating-right portability, and registrar liability. It has no separate conformance certifier and is therefore a partial instance of Definition 8.2. The Aircraft Protocol has 87 states and one regional economic integration organisation as parties, including 69 states by accession.

  • Art. 62 — the Convention assigns its depositary functions to UNIDROIT.

  • Art. 17(2)(b) — the Supervisory Authority appoints and dismisses the Registrar.

  • Art. 17(2)(c) — a standing duty to “ensure that any rights required for the continued effective operation of the International Registry in the event of a change of Registrar will vest in or be assignable to the new Registrar.” Article 17(2)(c) imposes forward portability.

  • Art. 17(2)(d)–(f) — regulations made or approved after consulting the Contracting States, administrative procedures for complaints, and supervision of the Registrar.

  • Art. 17(2)(h) — the Supervisory Authority sets and periodically reviews the fee structure.

  • Art. 17(4) — “The Supervisory Authority shall own all proprietary rights in the data bases and archives of the International Registry.” The Registrar does not own the data.

  • Art. 28(1) — the Registrar is liable in compensatory damages for loss “directly resulting from an error or omission of the Registrar … or from a malfunction of the international registration system”, with a narrow force-majeure carve-out benchmarked to “best practices in current use”.

  • Art. 28(2) — and is not liable “for factual inaccuracy of registration information received by the Registrar or transmitted by the Registrar in the form in which it received that information”.

  • Art. 28(3)–(4) — contributory fault reduces recovery. The Registrar must carry insurance or a financial guarantee “to the extent determined by the Supervisory Authority”.

  • Art. 27(4)–(5) — the register’s “assets, documents, data bases and archives shall be inviolable and immune from seizure or other legal or administrative process”, while a claimant against the Registrar is entitled to the information and documents necessary to pursue the claim.

Articles 28(1)–(2) allocate liability for specified registrar errors and system malfunctions, but not for factual inaccuracies received and transmitted unchanged. They do not supply a precedent for the separate certifier in Definition 8.2. That certifier’s duties and liability follow from its governing instruments and applicable law. The register’s protected assets are distinct from the registrar’s Article 28 liability. Article 44 identifies the courts with jurisdiction over actions against the registrar.

Article 17(2)(h) assigns fee-setting to the supervisory authority. This places fee-setting and data control with the Supervisory Authority, not the Registrar. The global legal-entity identifier system offers a narrower governance comparison. Its central operating foundation is a non-profit under public oversight. The oversight memorandum creates no legal rights and is not legally binding [GLEIF 2018, ROC–GLEIF 2015]. It does not supply the pricing precedent used here.

The same allocation also reduces exposure where a commercial registrar competes in a market whose access it administers. Appendix B states that jurisdiction-specific argument and the United States certification-mark boundary.

8.4 The limit of self-assessment

Self-assessment establishes only what its evidence supports. The listing must state whether the result comes from self-assessment, independent testing, accredited assessment, or legal determination. A standing instruction may require any one of those classes. The standards body must not describe one class as another.

9 Threat model

The construction relies on different conditions for different failures. The table separates false reporting, failures of service, abuse of decision rights, and losses a bond cannot restore. It includes rational participants, challengers, registrars, certifiers, coalitions, non-strategic failure, and negligence. We assume cryptographic primitives are sound and that all parties can read the published standard and register.

# Threat Mechanism relied on Covered?
T1 False attestation for private gain bond + bounty (Thm 7.6) Partially — the equilibrium rate is \kappa/(\beta\phi\bar p B), zero only as B \to \infty. Full deterrence follows under the additional conditions of Cor. 7.6a or Prop. 7.10.
T2 Equivocation — two conflicting attestations under one key machine-provable from published evidence, a stated forfeiture fraction, and blind sampling under Cor. 7.6a Partially. Full deterrence requires the stated sampling or funded-inspection conditions.
T3 Availability failure of a participant capped per-period forfeiture and an instruction that may condition its own edge on current evidence Partially. Effect follows only where the instruction states the evidence-age rule.
T4 Collusion between issuers and all challengers none internal to the scheme No (Section 7.7)
T5 Sybil accession — many shell participants unique authority-function identifier, one active accession per identifier, and the relation rule in Definition 2.4 Additional participants do not change whether a fixed pair of existing authority-function identifiers belongs to the relation. Duplicate active identities for one function are blocked. Designation games remain open.
T6 Objection abuse — incumbents excluding a newcomer bilateral-only effect of declination (H3). No participant can exclude another from the network. Partially. The rule limits the objection to that pair but does not prevent discriminatory use.
T7 Grade laundering — routing through a permissive intermediary class meet (Lemma 5.2), actual map composition (Prop. 5.6a), and joint witness admission Covered for disclosed correctly typed paths. Completeness of actual dependencies requires separate evidence under §6.6.
T8 Forking — a large participant runs a private variant the register and the mark. Documented nonconformance, or evidence staleness under an instruction’s stated age rule, removes an edge whose standing instruction requires current conformance. Partially
T9 Registrar capture — the registrar favours its own market position ministerial functions with separate governance, certification, and supervision (Prop 8.3, App. B) Reduced, not eliminated
T10 Certifier negligence — a conformance finding is wrong separate certifier liability under governing instruments and applicable law. Cape Town Art. 28 allocates only registrar liability. Allocated by design, not eliminated
T11 Correlated collateral — bond value collapses with the network stressed-valuation floor on the bond Partially
T12 Non-monetisable harm — an extinguished right none No (Section 7.7)

The two uncovered rows mark the boundary of the construction. T4 is an assumption. Bonding cannot restore the non-monetary legal status or right in T12.

10 Assumptions and proof status

10.1 Assumptions on which the theorems depend

The formation comparison relies on the instrument’s public rules and the participants’ willingness. The inspection comparison relies on detection, collection, and the actors’ incentives. The table records these dependencies so that evidence for one condition is not used as evidence for another.

# Assumption Used in Status
A1 Maintenance load \mu > 0 per standing relation Thm 3.4, Cor 3.5–3.6 Asserted. See Remark 3.7.
A2 Finite enumerated reservation menu Thm 4.5 Hypothesis (H1)
A3 Reciprocal entitlement Thm 4.5 Hypothesis (H2), present in NYC Art. XIV and MLI Art. 28(3)
A4 Default-to-consent declination with actual notice Thm 4.5, H3-dual in Prop. 4.9 Hypothesis (H3)
A5 Deterministic collision resolution Thm 4.5 Hypothesis (H4), present in MLI Art. 6(5)
A6 Aligned willingness, deposit, and declination (r_i=r_{\theta_i}, j \in D_i \iff \beta_i(j) = \bot) Thm 4.5 Hypothesis (H5). Props. 4.8a and 4.9b quantify approximation and fixed-cohort participation. Preference elicitation requires observations.
A7 Negotiated classes form a finite lattice and reservations are meets Thm 4.5, Lem 5.2 Class model. Executable maps and witnesses follow Prop. 5.6a and §6.3.
A8 Non-collusion between issuers and challengers Thm 7.6, Thm 7.8 Assumed, not proved
A9 Detection probability \bar p bounded below Thm 7.6 Assumed positive model parameter
A10 Gain from misreporting bounded linearly by carried value Thm 7.8 Modelling choice
A11 Disinterest of the supervisory authority is achievable Appendix B Institutional assumption

10.2 Modelling choices that are not results

The per-hop factor \delta, the hop horizon K, and the multiplicative weights w_iw_j are modelling choices. Theorems 5.7–5.8 are identities conditional on them. This paper supplies no empirical calibration of \delta or of the participant weights, and it makes no measured claim about the magnitude of composition value.

Each displayed theorem follows from its definitions and named hypotheses. Legal effect, adoption, and empirical calibration require separate evidence.

10.3 Open problems

  1. Intermediary effect. The legal interpretation of V_K for K>1 is conditional on a participant accepting recognition state that reached it through an intermediary. The graph-theoretic results in §5 hold without that legal effect. Applicable law and practice determine the legal effect. Without transitive acceptance, only direct routes can have legal effect. Legally realised value is then bounded by direct-route opportunities, subject to current-use requirements, even when the class-model q_K exceeds q_1. A recognition instrument can state the intended transitive effect for each domain.

  2. Legal assurance. An executable test suite establishes protocol conformance. It does not establish that a participant’s law has been represented correctly. Technical conformance sets a ceiling on the grade. Counsel may inform the authority’s signed ceiling. The notice and declination process determines whether the pair exists. The relation between protocol conformance and legal assurance remains open.

  3. Adoption. Proposition 4.9b gives a sufficient participation condition, and §4.7 specifies its measurement. Voluntary recruitment, retained participation, and repeated recognition require observations from the defined population.

  4. Collusion resistance. Section 7.7 and threat T4 assume non-collusion. A model with coalitions and endogenous detection remains open.

  5. Welfare distribution. The value functional is global. A per-participant decomposition must identify how composition value is distributed between a hub and a peripheral participant.

  6. Competition-law generality. Appendix B uses three decisions from one jurisdiction. Extension to other competition regimes requires a separate jurisdiction-specific analysis.

  7. Maintenance calibration. Remark 3.7 assumes positive maintenance load. Without it, Theorem 3.4 weakens to Lemma 3.3’s linear bound in time rather than an asymptotic ceiling.

12 Conclusion

A common instrument can preserve each authority’s consent while removing the need to negotiate every relation separately. The result depends on the terms authorities actually accept and the rules that give their declarations effect.

In the stated mean-field model, pairwise formation is bounded by negotiation capacity and maintenance. Its stock approaches \bar c/\mu, so its density vanishes as the eligible population grows.

Unilateral accession computes the same relation with one deposit per participant under five stated hypotheses: a finite reservation menu, reciprocal entitlement, declination by default after actual notice, deterministic collision rules, and deposits and declinations that match bilateral willingness. Reversing the default restores bilateral acceptance. The Apostille Convention’s 88 accessions required no pairwise acceptance. Objections withheld individual pairs without blocking an accession generally. Each of the Evidence Convention’s 50 accessions followed a pairwise-acceptance procedure. The membership totals do not identify the default’s causal effect. The lifecycle comparison also counts receipt, updates, exceptions, and assurance on the same horizon. Proposition 4.9b gives a useful participation regime even when willingness varies by counterparty.

Negotiated recognition classes compose by meet. Executable treatment composes context-indexed maps and retains each receiving authority’s fresh obligations. The finite-horizon class value cannot fall when the path horizon grows, and the bidirected-star calculation isolates the exact contribution from two-hop spoke relations. These are conditional mathematical results, not empirical valuations.

In the stated attestation game, positive investigation requires a funded challenger. Under its payoff model, no finite bond induces truthful reporting without a bounty. With forfeiture fraction \phi, detection probability \bar p, and challenger share \beta, the two-player inspection game has the threshold B^*=\frac{1}{\phi\bar p}\max\left\{G,\frac{\kappa}{\beta}\right\}. Above it, the equilibrium misreport rate falls as 1/B but remains positive. Corollary 7.6a requires a controlled posterior error rate within blind samples. Proposition 7.10 supplies a separate truthful regime through funded inspections and disjoint collateral allocations. Its capacity bound covers aggregate gains during outstanding exposure periods and includes delayed, stressed collection.

These results impose corresponding duties on the administration. Qualified people need reserved time, eligible appointments, and service funding separate from collectible collateral. The standards body, supervisory authority, certifier, depositary, and registrar perform the functions assigned by the governing instruments. Every recognition edge follows from the recognizing authority’s own signed rule. The public register preserves and publishes the evidence for that rule’s effect. Recourse governs private obligations separately and cannot change a sovereign recognition edge.

Two questions remain decisive. The first is whether an authority will give legal effect to a determination that reached it through an intermediary. The second is whether software conformance is useful evidence of legal assurance in the relevant domain. The mathematics assumes neither answer.

A Membership and pairwise-effect clocks

Joining the instrument and establishing a relation with an incumbent can occur on different dates. This is the distinction between membership and pairwise effect under (H3). The MLI separates them explicitly: Article 34 fixes entry into force for a party, while Article 35 keys pairwise effect to the later party’s entry into force. The Judgments Convention instead keys entry into force to expiry of the notification window itself. Its status table illustrates the distinction across several accessions [HCCH 2026d].

Judgments Convention Article 29(2) fixes a twelve-month notification period. Article 28(2)(a) places entry into force on the first day of the following month. The second paragraph of Apostille Convention Article 12 fixes six months after receipt of the depositary’s notification. Its third paragraph adds sixty days before entry into force.

B United States competition-law and certification-mark boundaries

A registrar or certifier can affect market access even when its published criteria are mechanical. The following United States cases address the conduct and interests of those controlling that process. They support a jurisdiction-specific legal argument, not a mathematical theorem.

Three decisions define the exposure of a body that controls market access through certification.

  • Radiant Burners, Inc. v. Peoples Gas Light & Coke Co., 364 U.S. 656 (1961): refusal of a seal of approval, by a body in whose process the applicant’s competitors participated, stated a Sherman Act claim.

  • American Society of Mechanical Engineers v. Hydrolevel Corp., 456 U.S. 556 (1982): a standard-setting body was answerable for officials who used apparent authority within its process to disadvantage a competitor.

  • Allied Tube & Conduit Corp. v. Indian Head, Inc., 486 U.S. 492 (1988): private standard-setting with anticompetitive effect was not protected by petitioning immunity.

The cases concern actual conduct, competitive effects, and apparent authority. Published criteria, written reasons, independent complaints procedures, and separated decision functions constrain specified opportunities for abuse. Their legal adequacy depends on the governing law and facts. Argument B.1 describes that allocation. It establishes neither a general immunity nor an exclusive lawful structure.

Argument B.1 (Discretion and economic interest). Let a registrar (O) compete in a market (M) whose access the register controls. Discretionary admission or exclusion by (O) leaves the decision with an economically interested party. Appeals, operating rules, and fees still require decisions even when admission follows the published price in Theorem 7.8. Assigning those functions to a body with no economic interest in (M) removes the registrar’s discretion over them. The cited courts do not establish that this allocation is the only adequate structure.

Conditional consequence B.2. If the governing competition law treats economic interest and discretion as decisive, assigning fee-setting to the disinterested supervisor assigns the decision to that supervisor and removes the registrar’s discretion over it. Cape Town Convention Article 17(2)(h) implements that assignment.

A separate United States trademark limit applies. A certification mark is subject to cancellation where its registrant markets the certified goods or services, or discriminately refuses certification to a person who maintains the standards [15 U.S.C. § 1064(5)(B), (D)]. A registrant that markets the certified goods or services therefore cannot rely on that statutory form. An ordinary trademark licence may instead require continuous conformance, a public executable suite, public evidence, and a contractual duty to license every qualifying applicant that those applicants can enforce. That structure constrains discretion through contract. It does not invoke the statutory certification-mark regime.

References

Instruments and status data

  • Convention Abolishing the Requirement of Legalisation for Foreign Public Documents (1961), Arts. 3, 4, 6, 7, 8, 9, 11, 12, 14, 15. Status table retrieved 31 August 2026: 130 Contracting Parties listed, 128 in force, 88 accessions, 21 objected to, 0 blocked generally. [HCCH 2026a, official Convention text, official status table]

  • Convention on the Taking of Evidence Abroad in Civil or Commercial Matters (1970), Arts. 36, 38, 39. Status: 69 Contracting Parties, 50 accessions, each subject to a pairwise-acceptance procedure. [HCCH 2026c, official Convention text, official status table]

  • Convention on the Recognition and Enforcement of Foreign Judgments in Civil or Commercial Matters (2019), Arts. 24, 25, 26, 28, 29, 30, 31, 32. [HCCH 2026d, official Convention text, official status table]

  • Convention on the Recognition and Enforcement of Foreign Arbitral Awards (1958), Arts. I–III, V, and XIV. United Nations treaty status retrieved 31 August 2026: 172 parties. [United Nations 2026, official Convention text, official treaty status]

  • Multilateral Convention to Implement Tax Treaty Related Measures to Prevent Base Erosion and Profit Shifting (2016), Arts. 2, 6, 26, 27, 28, 31–35, 37, 38, 39. [official text]

  • Convention on International Interests in Mobile Equipment (2001), Arts. 17, 27, 28, 44, 62, and the Protocol on Matters Specific to Aircraft Equipment. UNIDROIT status tables retrieved 2 September 2026: Convention, 90 states plus one regional economic integration organisation. Aircraft Protocol, 87 states plus one such organisation, 69 states by accession. [official Convention text, Convention status, Aircraft Protocol status]. See R. Goode, Official Commentary, UNIDROIT, 4th ed., 2019.

  • UNCITRAL Model Law on Electronic Transferable Records (2017). Status page retrieved 31 August 2026: 13 enacting or influenced jurisdictions. [UNCITRAL 2026, official status]

  • Vienna Convention on the Law of Treaties (1969), Arts. 20(5), 21(1), 76, 77. [official text]

  • UNCTAD, International Investment Agreements Navigator, retrieved 4 September 2026: 2,861 bilateral investment treaties signed, 2,236 in force. [UNCTAD 2026, official navigator]

  • 15 U.S.C. § 1064(5)(B), (D). [official text]

  • Global Legal Entity Identifier Foundation, Statutes, Bylaws & Policies, retrieved 4 September 2026. [GLEIF 2018, official governance page]

  • Regulatory Oversight Committee and Global Legal Entity Identifier Foundation, Memorandum of Understanding (2015), Art. II.12. [ROC–GLEIF 2015, official signed text]

Cases

  • Radiant Burners, Inc. v. Peoples Gas Light & Coke Co., 364 U.S. 656 (1961). [official opinion]

  • American Society of Mechanical Engineers, Inc. v. Hydrolevel Corp., 456 U.S. 556 (1982). [official opinion]

  • Allied Tube & Conduit Corp. v. Indian Head, Inc., 486 U.S. 492 (1988). [official opinion]

  • Case 120/78, Rewe-Zentral AG v Bundesmonopolverwaltung für Branntwein [1979] ECR 649.

Literature

  • Avenhaus, R., von Stengel, B. & Zamir, S. (2002). “Inspection Games.” In Handbook of Game Theory with Economic Applications, vol. 3, ch. 51.

  • Auer, R. (2019). “Beyond the doomsday economics of ‘proof-of-work’ in cryptocurrencies.” BIS Working Paper No. 765.

  • Backhouse, R. C. & Carré, B. A. (1975). “Regular algebra applied to path-finding problems.” Journal of the Institute of Mathematics and its Applications 15(2), 161–186.

  • Bala, V. & Goyal, S. (2000). “A Noncooperative Model of Network Formation.” Econometrica 68(5), 1181–1229.

  • Becker, G. S. (1968). “Crime and Punishment: An Economic Approach.” Journal of Political Economy 76(2), 169–217.

  • Beth, T., Borcherding, M. & Klein, B. (1994). “Valuation of Trust in Open Networks.” ESORICS 1994, LNCS 875, 3–18.

  • Breidenbach, L., Daian, P., Tramèr, F. & Juels, A. (2018). “Enter the Hydra: Towards Principled Bug Bounties and Exploit-Resistant Smart Contracts.” USENIX Security 2018.

  • Budish, E. (2018). “The Economic Limits of Bitcoin and the Blockchain.” NBER Working Paper 24717. Revised 2022 as “The Economic Limits of Bitcoin and Anonymous, Decentralized Trust on the Blockchain.”

  • Büthe, T. & Mattli, W. (2011). The New Global Rulers: The Privatization of Regulation in the World Economy. Princeton University Press.

  • Buterin, V. & Griffith, V. (2017). “Casper the Friendly Finality Gadget.” arXiv:1710.09437.

  • Camerini, P. M. (1978). “The min-max spanning tree problem and some extensions.” Information Processing Letters 7(1), 10–14.

  • Castro, M. & Liskov, B. (1999). “Practical Byzantine Fault Tolerance.” OSDI 1999, 173–186.

  • Ellison, C. & Schneier, B. (2000). “Ten Risks of PKI: What You’re Not Being Told About Public Key Infrastructure.” Computer Security Journal 16(1), 1–7.

  • Ford, B. & Böhme, R. (2019). “Rationality is Self-Defeating in Permissionless Systems.” arXiv:1910.08820.

  • Gabow, H. N. & Tarjan, R. E. (1988). “Algorithms for two bottleneck optimization problems.” Journal of Algorithms 9(3), 411–417.

  • Hu, T. C. (1961). “The maximum capacity route problem.” Operations Research 9(6), 898–900.

  • Jackson, M. O. & Wolinsky, A. (1996). “A Strategic Model of Social and Economic Networks.” Journal of Economic Theory 71(1), 44–74.

  • Lamport, L., Shostak, R. & Pease, M. (1982). “The Byzantine Generals Problem.” ACM TOPLAS 4(3), 382–401.

  • Landes, W. M. & Posner, R. A. (1975). “The Private Enforcement of Law.” Journal of Legal Studies 4(1), 1–46.

  • Lemley, M. A. (2002). “Intellectual Property Rights and Standard-Setting Organizations.” California Law Review 90(6), 1889–1980.

  • Lorgat, R. (2026a). How Compliance Composes.

  • Lorgat, R. (2026b). Recourse.

  • Lorgat, R. (2026c). The Sovereign Jurisdiction Network.

  • Mattli, W. & Büthe, T. (2003). “Setting International Standards: Technological Rationality or Primacy of Power?” World Politics 56(1), 1–42.

  • Maurer, U. (1996). “Modelling a Public-Key Infrastructure.” ESORICS 1996, LNCS 1146, 325–350.

  • Mohri, M. (2002). “Semiring frameworks and algorithms for shortest-distance problems.” Journal of Automata, Languages and Combinatorics 7(3), 321–350.

  • Myerson, R. B. & Satterthwaite, M. A. (1983). “Efficient Mechanisms for Bilateral Trading.” Journal of Economic Theory 29(2), 265–281.

  • Nicolaïdis, K. & Shaffer, G. (2005). “Transnational Mutual Recognition Regimes: Governance without Global Government.” Law and Contemporary Problems 68(3–4), 263–317.

  • Pollack, M. (1960). “The maximum capacity through a network.” Operations Research 8(5), 733–736.

  • Polinsky, A. M. & Shavell, S. (2000). “The Economic Theory of Public Enforcement of Law.” Journal of Economic Literature 38(1), 45–76.

  • Reiter, M. K. & Stubblebine, S. G. (1997). “Path Independence for Authentication in Large-Scale Systems.” ACM CCS 1997, 57–66.

  • Reiter, M. K. & Stubblebine, S. G. (1999). “Authentication Metric Analysis and Design.” ACM Transactions on Information and System Security 2(2), 138–158.

  • Rote, G. (1990). “Path problems in graphs.” Computing Supplementum 7, 155–189.