Recourse

Abstract

A seller can win an award and remain unpaid. The tribunal determines the obligation, while banks, custodians and courts act under separate authority. Recourse specifies how a dispute moves between these actors without treating a decision as payment. The parties agree their arbitration route when they assume the obligation. Record queries answer bounded factual questions, with an unconditional route to a tribunal and independent review of contested record integrity. A common evidence record then distinguishes the award, permission to act, completed transfers and final value received. Under explicit authentication, identity and journal assumptions, the record preserves these distinctions through later stays, corrected reports and repeated evidence. Payment quantities cannot be used twice across claims. A qualifying award alone gives no positive lower bound on recovery. The same discipline governs institutional continuity: a successor retains unfinished computations, outstanding duties and funded reservations, with each future action subject to current authority. These results assume effective legal instruments, competent decisions and provider evidence. They establish neither those external facts nor a measured recovery rate.

Author’s note. The author has a commercial interest in systems of the kind this paper describes.

1 From a disputed invoice to payment

A seller delivers goods across a border and invoices 100,000. The buyer disputes part of the delivery. An arbitrator hears both parties and awards 80,000. The award determines the amount owed. Payment still requires the buyer to comply, a custodian to release controlled property, or a court to permit execution against available assets. If none of these routes succeeds, the seller remains unpaid.

This paper asks how a system should carry that dispute from the parties’ agreement through adjudication and possible recovery. Its records must say who decided each question, what that decision permits, and what the recipient actually received. Those answers can change at different times. A court may stay further execution after an earlier payment. A bank may report a credit after the recipient has spent it. A second report of that credit must not count as a second payment.

The intended setting is a network of independent jurisdictions. Each jurisdiction operates a system that records its entities, evaluations and signed decisions. We call that system a deployment. A corridor is a bilateral arrangement for exchanging compliance records on terms the two jurisdictions set (The Sovereign Jurisdiction Network, Accession Networks). The record can establish which operation ran and which signed result it produced. It cannot by itself interpret a contested undertaking or compel a defaulting party to pay. No network authority stands above the participating jurisdictions.

Recourse uses the parties’ agreement to fix a forum before default. Every private obligation in the design carries a written arbitration agreement that binds its parties under applicable law. The agreement may sit in the transaction instrument or in a multilateral participation agreement. Accession can occur directly, through delegated authority, or through an authorised program where that law recognises its act. The agreement fixes one seat, one set of rules, one appointing authority and one governing law. The seat is the legal jurisdiction that supervises the arbitration. A tribunal consists of natural persons appointed as arbitrators. The 1958 New York Convention supplies a recognition route for a qualifying award, subject to its reservations and refusal grounds (section 4). These requirements describe the proposed instruments. They do not establish that any identified parties have adopted them.

The procedure uses recorded evidence where a bounded query can answer the submitted question. Questions requiring judgment go to a tribunal. So does every challenge to the record’s integrity. A party can unconditionally require tribunal adjudication of a lower-tier determination (section 5 and section 6). That determination remains a contractual instrument within its adopted scope. Settlement, voluntary payment, custody release and court enforcement retain their own legal bases.

The formal problem begins when these independent acts must appear in one account of the dispute. The construction records what happened, what is currently authorised, what value arrived, and what remains unresolved. Its main theorem preserves those distinctions under explicit evidence assumptions (theorem 9.2). It also preserves each payment’s quantity across claims. In particular, an accepted award gives no positive lower bound on recovery (corollary 9.3). Recovery requires value credited to the entitled recipient, legal finality and closure of the applicable provider reversal windows.

The institution administering the process has the same unfinished obligations as its parties. It needs independent decision-makers, funded service commitments and a successor for work that outlasts its administration. The later construction preserves pending computations and payment reservations through such a transfer. Its useful continuation result remains conditional on current authority, sound decoding, custody and execution controls. The paper therefore treats adjudication, payment and continued service as connected obligations whose completion requires different evidence.

2 A delivery dispute and its receipts

Consider the delivery dispute just described. The seller is in state A and the buyer in state B. They trade through a corridor between their jurisdictions. The following agreement, award and payment facts are assumed for this example. Each party signed the same multilateral participation agreement before trading. That agreement states that each participant offers to arbitrate covered disputes with every other participant, and that each signed accession accepts those offers. It names the rules, a seat in a third state S that is party to the Convention, one arbitrator, and a named appointing authority. The applicable law is assumed to recognise that written accession mechanism. A transaction agreement can instead carry the clause directly. Consent is the parties’ own written agreement under Article II of the Convention. No digest, rule pack, register entry or state accession supplies it. A separate escrow agreement places 60,000 units of one currency with an independent custodian under a mandate that permits release on a qualifying award or on a joint instruction of the parties.

The UNCITRAL Model Law on International Commercial Arbitration, with its 2006 amendments, is referred to below as the Model Law. The seller delivers goods and invoices 100,000. The buyer disputes part of the delivery. The seller sends a notice of arbitration to the buyer under the rules. The administering centre’s registrar records the notice and has no adjudicative authority. This registrar performs ministerial case-service acts. The register operator in Accession Networks holds a different office. The appointing authority appoints a natural person as sole arbitrator. Both parties present their cases. They settle one issue during the proceeding, and the arbitrator records that part as an award on agreed terms (Model Law Article 30). He decides the remaining issue and awards 80,000 in total. Both dispositive parts form one award under the rules and the law of the seat.

The buyer pays 20,000 voluntarily. That payment needs no recognition order. The custodian verifies the award, the arbitrator’s signature, the mandate and the exact release instruction. A current affirmative release-eligibility determination covers the authority, asset and action. A query finding no stay in a log supplies no such determination. The trustee and award-executor sign the same instruction and release 60,000. The seller’s bank credits both amounts. The credits reach legal finality under that bank’s rule, the bank charges a 100 receipt fee, and the reversal windows close. The recovery ledger then holds two receipts and one fee: (+20{,}000)+(+60{,}000)+(-100)=79{,}900. The award amount is 80,000. Gross receipt is 80,000. Net recovery is 79,900. These are three quantities. The equality of the first two is contingent: it holds here because the buyer paid part and the escrow was funded, and section 9.8 gives the cases in which it fails.

The seller also applies for recognition in two forums where the buyer holds assets. Forum F_1 recognises the award. Forum F_2 adjourns its decision under Article VI because a setting-aside application is pending at the seat. Before the seller levies on an account in F_1, the court of F_1 stays execution pending the seat’s decision. At that view time, coercive execution in F_1 is unavailable. The voluntary payment, the custody release and the receipts remain historical facts. The stay changes current authority. It does not rewrite what occurred.

Each stage has its own evidence. The model of section 9 records each fact under its own authority and its own time. No fact implies the next. Case administration cannot create consent. A notice cannot constitute a tribunal. A signature by an officer of the centre cannot make an award. An award cannot make a forum recognise it. Recognition cannot reach an immune asset. A credit inside a reversal window is not recovery.

3 Why the network cannot decide

The seller can tender a signed delivery record. That evidence still leaves two questions: who may decide its contractual significance, and who may execute the resulting obligation? Giving those powers to the network would change the independent-authority setting of this paper. The proposed use of network adjudication encounters three limits.

A sovereign network has no authority above its members.

The architecture forbids a global validator set with authority over records, and the prohibition is not a scaling compromise. It is the property that makes a jurisdiction willing to run a deployment at all. A jurisdiction that accepted a network quorum’s determination of what its own registry says would have delegated its registry (Accession Networks, the four boundaries). So the network cannot vote on what happened. Deciding contested state by consensus is incompatible with that boundary. Identity is not authority: a signed statement proves who spoke, and it does not make the speaker the judge of what the statement means.

A record is not a remedy.

The proof objects establish what the system did: which rules ran, on which inputs, producing which signed outcome, at which time. They are evidence. They cannot establish what a party undertook and failed to do, because undertakings live in instruments the deployment does not interpret. They cannot move money out of a defaulting party’s account, because moving money requires coercive power that no record has. And a record is not legal finality: a ledger entry says that a provider moved value on its own books, and the moment at which that transfer became irrevocable is fixed by the rule that governs the provider in its legal order (section 9.4).

The provable and the arguable are different categories.

Some contested propositions are settled by looking: whether an operation was recorded, whether a rule pack (the versioned set of rules an evaluation ran under) was the one the jurisdiction ratified, whether two signatures conflict. Others are not settled by looking at all: which of two properly recognised rule sets governed, whether a condition attached to a recognition grade held (the grade is the level at which a receiving jurisdiction accepts a foreign evaluation, defined in How Compliance Composes), whether conduct was negligent, what quantum follows when quantum is not arithmetic. The first category requires a query. The second requires a tribunal. Treating a query as an adjudication undermines the query. Sending a question of legal construction to software produces a result that binds no one.

Adjudication therefore requires an authority outside the deployment. The design uses arbitration for covered private disputes. Its cross-border recognition route explains that choice.

4 Cross-border recognition of an award

A court judgment and an arbitral award can each support coercive enforcement. Their cross-border recognition regimes differ, and that difference determines the design.

A foreign arbitral award is eligible for recognition and enforcement under one multilateral instrument, the Convention on the Recognition and Enforcement of Foreign Arbitral Awards, concluded in New York in 1958 and in force in 172 states as at the UNCITRAL status table of 31 August 2026. Article V gives a closed list of refusal grounds: incapacity of a party or invalidity of the agreement, absence of proper notice or inability to present a case, an award beyond the scope of the submission, irregular composition of the tribunal or irregular procedure, an award not yet binding or set aside or suspended where it was made, and, on the court’s own motion, non-arbitrability and public policy. The article is permissive, and Article VII preserves any more favourable right the enforcing state’s own law confers. The merits are not on the list. For the grounds in Article V(1), the party resisting enforcement must furnish proof. Article V(2) permits the enforcing court to address non-arbitrability and public policy itself.

Cross-border recognition of a foreign court judgment depends on bilateral treaties, regional instruments, or the enforcing forum’s own law. Those rules commonly impose jurisdictional review, reciprocity conditions, and in many states a further examination of the merits or of the public interest. The 1971 Hague judgments convention required a supplementary bilateral agreement between each pair of states before it took effect between them, and has five parties fifty-five years on. Its 2019 successor uses a different rule. Under Article 29 the Convention applies between two parties unless one of them notifies otherwise, so accession is the default and bilateralisation the exception. It entered into force in 2023 but has far less coverage than the New York Convention. Within a single bloc the position is different: Regulation (EU) No 1215/2012 gives judgments automatic recognition across the 26 member states it binds, and Denmark by parallel agreement, with no declaration of enforceability at all.

The reason is structural. A judgment is an exercise of one state’s sovereign power. An award rests on the parties’ agreement to submit a dispute to a tribunal. The Convention commits its parties to recognise that agreement and qualifying awards, subject to the stated refusal grounds. That common commitment has reached 172 states. No global judgments convention has comparable coverage.

What the clause creates.

Two parties can establish a cross-border arbitration route in their contract even when their states have no bilateral judgment-recognition treaty. Consent is the parties’ own written agreement under Article II; no digest, rule pack, register entry or state accession substitutes for it. The result remains forum-specific. A state that made the reciprocity reservation in Article I(3) applies the Convention only to awards made in another contracting state. A state that made the commercial reservation applies it only to relationships its law considers commercial. The Convention establishes a recognition and enforcement route, not collection. Article III uses each state’s own procedure. Article VI permits adjournment and security while a setting-aside application is pending. Immunity, asset location, priority and insolvency remain separate conditions (section 9.9). Voluntary payment, settlement, enforcement of security, an independent guarantee, set-off and a consent order can produce recovery without an award. The model in section 9 records the legal origin of each receipt and forces none through an award or a court.

The network’s formation mechanism uses the same legal structure. A recognition network is built by unilateral accession to a published standard rather than by pairwise negotiation, and Accession Networks proves when that construction reproduces what bilateral negotiation would have produced. The Convention applies that structure to recognition and enforcement of awards. Corridors carry typed compliance state under an accession instrument. An arbitration clause governs the private obligations attached to that state. Neither mechanism requires a bilateral treaty. Together they govern the cross-border regulatory state and the private obligations attached to it.

The multi-hop problem, and what the clause reaches.

Recognition composes along paths. An entity’s compliance state reaches jurisdiction C through B, having originated in A, and How Compliance Composes treats the composition and its grading. When a transaction that crossed A \to B \to C goes wrong, who decides, under which law, and can the answer be collected in C? It is two questions. The first is prospective and regulatory: will C’s law give effect to a determination composed across A and B? That is the recognition question, answered in advance to the extent the accession instrument, the conformance suite (the published tests a participant must pass) and the grade the corridor carries fix it, and Accession Networks states what remains open. The second is adjudicative and becomes live at the moment of failure: when the transit breaks, whose forum hears it, and does its answer bind assets in C? Until a dispute exists, transitive acceptance is a policy statement. At the moment of dispute it is a jurisdictional question in a forum nobody chose.

Recourse answers the second through the parties’ agreement. A single network arbitration clause is written into the corridor instrument at every hop and into every participation agreement: one seat, one set of rules, one appointing authority, and one governing law for the corridor obligation. The parties therefore fix the tribunal and governing law at accession. Where the Convention applies in C, it supplies a recognition and enforcement route. Collection remains subject to C’s procedure, the available asset and every other route-specific fact. A composition refusal becomes a merits question in the forum the parties specified, rather than a jurisdictional question in a forum they did not.

The clause reaches private obligations, and it stops there. C’s regulator retains every part of its statutory authority. An award cannot license an entity, register an offering, or clear a payment C prohibits. The clause instead makes the private obligations attached to composed state enforceable in C. It supplies a forum for the parties’ bargain without changing any regulatory approval the transaction requires. Two risks remain. Article V(2)(a) permits a court to refuse enforcement where the subject matter is not capable of settlement by arbitration under its own law, and Article V(2)(b) where enforcement would be contrary to its public policy. A state may hold that a dispute over its own regulatory determination is not arbitrable. The clause is therefore drawn to cover the private obligation, whether the party performed, whether the bond is forfeit, whether the corridor fee is owed, and does not purport to adjudicate a regulator’s decision. That is the boundary the network already draws between conformance and recognition, and drawing it consistently keeps the enforcement layer inside the Convention.

Disputes after a bilateral commit.

A corridor operation can await completion while both endpoints reserve resources for it. A prepared endpoint has made that reservation but still awaits the joint outcome. The final recorded outcome is the terminal decision. The bilateral protocol preserves one ordered terminal decision. A lease sets the local waiting deadline. Lease expiry records that deadline and can initiate a request for the decision. Prepared resources remain reserved until the durable terminal outcome authorises their disposition. A local expiry alone supplies no joint abort or release authority (The Sovereign Jurisdiction Network, section 5.4).

The recorded reservation, expiry, decision and missing evidence are separate facts. A proposition the record decides enters the record tier of section 5. The corridor instrument can determine loss allocation by arithmetic on recorded values. Other questions of loss allocation require the competent tribunal. Escrow release follows its qualifying basis, mandate and applicable law. Recovery uses the collection rule in section 9.4. An assertion of equivocation raises an integrity question for the full tribunal. Different local progress at the two endpoints supplies no inference of blame.

5 Three tiers and a routing test

Online dispute resolution can reserve human procedure for questions that need it (Katsh and Rifkin 2001, Rule 2010). The remaining problem here is authority. A software answer may be useful evidence without binding the parties or authorising payment. The UNCITRAL Technical Notes on Online Dispute Resolution (2016) provide the administrative case-service role used below. The comparison with existing systems is developed in section 12.

Recourse records submission standing, party status and adjudicative authority separately. An evaluated entity, corridor endpoint, watcher or relying counterparty can submit a claim or evidence under the intake rules. A watcher checks and attests a recorded history under the network’s evidence rules. That role grants no adjudicative authority. Submission and reliance establish neither arbitration consent nor authority to bind another person.

A head of claim is one separately identified demand for relief. Each head names its parties and jurisdictional basis. An arbitration route records the agreement, applicable law, seat, scope, capacity, notice and authority that determines each disputed predicate. A binding basis can include an effective accession or another basis recognised by applicable law. Its validity requires a determination for the identified party and claim.

A contested jurisdictional basis can enter a jurisdiction inquiry under the seat’s law and the applicable rules. Authority to conduct that inquiry differs from authority to decide the merits. Model Law Article 16 supplies the relevant structure where enacted. Court rights, statutory powers and contractual custody mandates retain their own authority bases.

After admission under its recorded authority basis, each arbitrable head enters one of three procedural tiers. The mechanical test applies separately to each head. A notice asserting heads that route differently is split.

These tiers determine procedure. They are distinct from the evidence states of Event-Collect BFT and the trust levels of The Sovereign Jurisdiction Network. Similarly, the tribunal modal of Lex records which authority asserts a verdict. It is not a tribunal of arbitrators.

For the delivery dispute, the record might establish whether a signed delivery entry exists. Whether that entry proves contractual performance can still require legal judgment. The routing test keeps those questions separate. It asks three questions.

Does the record decide the proposition?

Five conditions must hold. The proposition names a closed evidence snapshot and uses the bounded query language below. Evaluation returns a known value with the required evidence. The query chooses no governing rule between properly recognised alternatives. It traverses no discretion the applicable rules leave open, including a typed discretion hole of Lex, which marks a decision left to an authorised actor. Any absence result concerns only the named retained log intervals.

The evidence snapshot.

Re-execution must examine the same retained evidence. The record therefore fixes a snapshot before evaluating the query. A snapshot \Sigma fixes its view time, schemas, verification profile, authority bindings and key-status evidence. Each source log has an identifier, inclusive retained interval [\ell,u] and head observation cutoff. The snapshot carries the commitment before \ell, the commitment at u and every raw entry between them. The verifier checks consecutive positions and reconstructs the upper commitment from the lower commitment and complete interval. The upper head carries the required watcher attestations. A corridor query verifies each endpoint’s interval separately. These checks establish coverage of committed intervals under the named authentication assumptions. Truthful reporting and coverage of external events require their own evidence.

Source tables are typed views derived from complete raw intervals. The snapshot fixes their row order and derivation rules. A missing interval entry, unresolved required dependency or unsupported schema prevents a known result. A failed proof or asserted integrity defect invokes the integrity rule below. Selected inclusion proofs alone establish no complete search result.

The admitted query language.

A published profile fixes maximum input bytes B, syntax nodes M, source rows N, tuple arity K and scalar width W. It fixes output, memory and instruction limits. Scalar expressions contain literals, typed row fields, checked arithmetic, comparisons, Boolean operations and finite conditional expressions. They can read authentication results established by the snapshot verifier. Every primitive has a deterministic specification and finite cost bound. Missing required values and arithmetic overflow produce typed obstructions.

The query can select rows, count them, add a recorded quantity, test for an entry, or test for its absence. Let each L_j be a snapshot table. The domain D contains the tuples formed by their product. The predicate p selects tuples, and e or \bar e specifies their scalar output. A query has one of five forms: \begin{split} D=L_1\times\cdots\times L_k,\qquad 1\leq k\leq K,\\ q\in\{\mathrm{select}_{p,\bar e}(D),\ \mathrm{count}_{p}(D),\ \mathrm{sum}_{p,e}(D),\\ \mathrm{exists}_{p}(D),\ \mathrm{none}_{p}(D)\}. \end{split} The predicate and output expressions use the scalar constructors above. Evaluation visits source tuples in fixed order. Aggregation uses checked arithmetic and respects the output limit. Queries contain no nested queries, recursion, program hooks, network reads or mutable external state. Comparisons between recorded rule-pack digests remain available. Executing a rule-pack program requires the separate institutional runtime.

Admission checks syntax, types, source bindings and resource bounds. For m\leq M syntax nodes, at most (N+1)^k source tuples are visited. A conservative instruction bound is c_{\mathcal P}(W)\bigl(B+(m+1)(N+1)^k\bigr), where c_{\mathcal P}(W) bounds the profile’s parsing, verification and scalar primitives. Admission also bounds complete output and working memory. Excess requests receive \mathrm{Unknown}(\mathrm{ResourceBound}). The interpreter meters instructions and allocation. Exhaustion returns that typed result and discards partial output.

Evaluation returns \mathrm{Known}(v) or \mathrm{Unknown}(o), where o identifies the obstruction. Unsupported syntax, incomplete evidence and missing external facts have distinct types. Unknown never becomes false, zero, an empty table or a successful absence result.

Proposition 5.1 (Bounded query evaluation).

Under a fixed admitted profile, every admitted query terminates within its resource limits. Termination does not imply that the proposition is decided.

Proof. Input and syntax lengths are bounded before interpretation. Structural induction and the primitive bounds establish termination of every scalar expression. Each query visits a finite product of bounded tables and emits bounded output. Admission bounds those visits and evaluations. Metered exhaustion returns Unknown within the limit. Completed evaluation returns Known when every required check succeeds. Both outcomes terminate. ◻

Log absence and external facts.

A successful absence query produces a \mathrm{NoEntry} certificate. It binds the query, snapshot digest, verification profile, log identifiers, retained intervals, boundary commitments, observation cutoffs and coverage evidence. It states that no matching entry occurs in those retained intervals. An interval starting after the first entry establishes nothing about earlier entries. A later observation can report an earlier external event.

NoEntry does not establish that an operation never occurred, a ratification never existed or a court issued no stay. An external proposition lacking its competent authority’s required determination returns \mathrm{Unknown}(\mathrm{ExternalFact}). A query can extract an attestation and identify its authority, scope and effective interval. It supplies no independent determination of that external proposition. Unknown follows the Tier 1 and Tier 2 routing rules. An asserted integrity defect takes priority.

Is the integrity of the record itself in issue?

Integrity is in issue where a party asserts forgery or key compromise, an append-only violation, a proof that does not verify, equivocation between two signed objects, a commitment that does not match the message it names, a stale or unquorate timestamp, a proof envelope missing a required element, or that the rule pack an operation pinned is not the pack the competent authority ratified.

Does resolution turn on law, construction, discretion or characterisation?

This includes which of two recognised packs governed, the construction of a corridor instrument or of its grade, whether a condition attached to a conditional grade held, the exercise of a discretion, the characterisation of conduct, quantum that is not arithmetic on recorded values, and every question of transitive acceptance.

A proposition the record decides, with no integrity question and no question of law, goes to Tier 0, record resolution. The registrar executes the admitted query against its immutable snapshot. A determination requires a Known result. It states the proposition, verbatim query, snapshot digest, verification profile, resource limits and result. It includes the extract and coverage evidence needed for independent re-execution. Any absence statement carries its NoEntry certificate and exact retained intervals. Checking instructions name the authentication assumptions and source authorities. No tribunal is constituted. No arbitrator is appointed. No hearing is held.

A proposition the record does not decide, with no integrity question and no question of law, goes to Tier 1, the expedited procedure: a sole arbitrator, on the documents, on a fixed timetable and for a fixed fee, who issues an award and not a determination. Where the matter cannot fairly be decided without oral evidence, that arbitrator does not decide it. The claim is re-routed to a full tribunal by procedural order and the fee is credited, which is what makes a documents-only tier defensible. A question of law goes there too where the amount is at or below a published monetary ceiling and no party requests a hearing, which is the condition Model Law Article 24(1) attaches to a documents-only procedure. The ceiling is published, uniform across parties, and never varied case by case.

Everything else goes to Tier 2, the full tribunal, and one rule dominates the others. Where record integrity is in issue, the head of claim goes to Tier 2 regardless of the other answers, regardless of amount, and regardless of any party’s agreement to the contrary. Tier 0 derives its entire authority from the integrity of the record. A machine cannot adjudicate the assertion that the machine is compromised. An institution that routes an integrity question to an automated tier has destroyed the evidential basis of every other tier it operates.

This governs an assertion that the record is compromised. It leaves untouched the verification steps that precede any tier: a digest that matches, a signature that verifies, a replay that reproduces the signed outcome, and a conforming equivocation certificate (two conflicting signed objects under one key at one index) that verifies on its face. These are performed mechanically and are not heads of claim. The Sovereign Jurisdiction Network develops that mechanical layer, the certificate it produces, and the watchers whose bonded attestations of the chain head make a history served differently to different parties surface as conflicting heads. It also states the ordering this section turns into a routing rule: integrity questions are machine questions with exact answers, interpretation questions belong to people who know the traditions, and integrity comes first. Recourse governs what happens when a party contests the mechanical result. A party’s assertion that a certificate is unsound puts integrity in issue and goes to a tribunal.

Emergency relief.

Emergency-arbitrator provisions run beside every tier, including matters routed to record resolution. The emergency arbitrator is a natural person appointed under the rules. Tier 0 issues no relief. Relief binds the private parties. It takes effect on a deployment’s record only through that deployment’s own signed act, and it never displaces a sovereign halt or the countermand window that protects the halt (The Sovereign Jurisdiction Network, section 9.8). Reversible throughput relief can use an expedited procedure. Value-moving relief requires notice and security. The Convention treatment of an emergency arbitrator’s order is forum-specific. Court enforcement of an interim measure depends on the forum’s law, including Model Law Article 17H where enacted.

Routing is administrative.

It is not a decision on the merits, it binds no tribunal, and a tribunal must not treat it as a finding. Routing errors are corrected in one direction: upward on a party’s unilateral request, never downward against objection. A head of claim routed to Tier 0 or Tier 1 that any party contends belongs higher goes higher, without grounds and without leave. A head routed to a tribunal is demoted only by the written agreement of every party. A party may always buy the fuller procedure. Tier 0 requires the admission, evidence and Known-result conditions above. Unknown follows the tribunal routing rules. Integrity assertions and escalation take priority over a Known result.

6 A determination is never an award

The effect of a record query depends on the instrument through which the parties use it. Requiring a full tribunal, retained counsel and a hearing for a question the record answers in milliseconds can make ordinary disputes uneconomic. Describing a machine determination as an award can make the instrument unenforceable when a party presents it to a foreign court.

Extraction, adoption and adjudication.

An advisory extract reports a query, its bound evidence and its result. Issuing or reading it creates no contractual determination. A published service schedule may provide the extract without charge. A fee for producing evidence arises only under the separate service terms. A contractual determination additionally names the parties’ effective adoption, the proposition submitted, the permitted effect and the challenge procedure. An award requires the separate tribunal route. The instrument type, adoption basis and charging basis remain distinct fields throughout storage, transmission and succession.

An advisory extract becomes an input to a contractual determination only through the parties’ effective adoption and a determination within its scope. Silence after an unsolicited extract supplies no adoption. An adopted determination creates only the effect specified by the controlling instrument and law. Its query result supplies neither a tribunal nor a power to execute against an asset. These distinctions allow the same evidence service to support informal inquiry, agreed record resolution and subsequent adjudication without conflating their authority or economics.

So Recourse states the separation on the face of every instrument. Every Tier 0 determination carries, in its body and not in a schedule, a statement that it is a determination and not an arbitral award, that it is the result of a query executed against a record, that it has contractual effect between the parties under the rules they adopted and no other effect, that it is not enforceable under the Convention, that no arbitrator has been appointed and no tribunal has considered the matter, and that any party may require the matter to be decided by a tribunal within a published period, unaffected by anything else in the document.

The rules make the right to escalate unconditional. It requires no grounds, no leave and no showing of error. It carries no escalation fee beyond the fee of the tier escalated to. The rules do not permit advance waiver, shortening, a deposit condition, or any threshold of amount or merit; the governing law decides whether each restriction is effective. On escalation the determination ceases to bind and stands only as evidence. If no party escalates within the published period, the determination binds as a matter of contract in the manner of an expert determination. Under the English authorities cited here, fraud or a departure from the parties’ instructions remains reviewable (Jones v Sherwood Computer Services plc, Veba Oil Supply & Trading GmbH v Petrotrade Inc). Other governing laws require their own analysis. The automated function runs the query the parties adopted. Its result remains a determination and not an award.

An Unknown output is a routing receipt. It records the unanswered proposition and obstruction. Expiry of a response or escalation period cannot turn Unknown into Known. A NoEntry certificate retains its log scope throughout any later proceeding. Integrity assertions and a party’s escalation request take priority over a Known result.

Costs do not condition the right. The tribunal allocates them under the agreed rules and applicable law. It may consider the parties’ conduct. The rules state that exercising the escalation right is not, by itself, a ground for adverse costs.

This separation makes the machine tier compatible with tribunal access. Consent is the basis on which an award is enforceable. A procedure that prevents access to a tribunal and later labels a machine result an award creates possible defences under Articles V(1)(b) and V(1)(d). The unconditional escalation right preserves the adjudicative route.

A party who needs an enforceable instrument rather than a contractual one may submit the claim to arbitration once the escalation period has run. This is a new adjudicative proceeding, not a conversion by form. The claimant pleads the proposition under the arbitration agreement, the respondent has the period the rules allow to answer, and the arbitrator may proceed on default under Model Law Article 25 if it does not. The arbitrator is a natural person appointed under the rules, is not bound by the determination, independently assesses the material, and issues any award under the seat law and the rules. Absence of opposition does not turn the determination into an award. The tribunal’s own dispositive instrument does. A settlement may be recorded as an award on agreed terms under Model Law Article 30 when its conditions hold.

7 The record as evidence

In a generalist forum, a proof object produced by the network is one party’s software output. It is proved like any other electronic record, by expert evidence, at expert cost, on expert timescales, and the party relying on it carries the burden of establishing what it is before arguing what it shows.

Under rules drafted for the record, the same object is presented in a defined form: the extract, the proofs, the verification profile, the instructions for independent re-execution. The rules provide that an extract in that form is admitted without further proof of authenticity, with any party free to challenge what it shows. The burden shifts from proving the instrument to contesting its content, which is where the argument belongs.

Two constraints keep this inside the bounds of an evidentiary rule. Verification must be independent: the extract carries every proof needed to check the result without trusting the institution, the operator, or the deployment whose record is in issue, and the query is published in a form that permits re-execution by the other side. A rule that requires the tribunal to trust the party tendering the evidence is not an evidentiary rule. And the tribunal retains the power to determine the admissibility, relevance, materiality and weight of any evidence, with the mandatory due-process requirements of the law of the seat untouched. Rules define a form and allocate a burden. They do not make a document true.

8 Security, the instrument and the record

Networks that carry legally relied-upon claims secure them economically. A participant posts a bond, and the bond is forfeit if the participant misreports. Accession Networks proves that a bond deters only where detection has positive probability, detection requires an investigator, and an investigator participates only if rewarded. It also defines the resulting finite bond. That paper defines the three-role separation under which a private operator administers a register without acquiring authority over it, and the separate certifier entity that carries liability for the operator’s own errors. This paper begins after detection.

Forfeiture needs an authority.

Forfeiting a bond is a transfer of property against the owner’s will. Someone must have authority to declare it. Nothing in a permissionless network confers that authority, and the network’s own prohibition on a global validator forecloses the obvious substitute. What remains is an award, and, for the one class of fault a machine can decide, an instrument the bondholder agreed to in advance. Advance consent works in that class and in no other. A party can bind itself to a machine’s answer where there is nothing to contest: two conflicting signatures under one key at one index are checkable without judgment, given the registry’s key binding. It cannot bind itself in advance to a machine’s answer on a question the machine cannot decide, because there is then no determinate thing it consented to. That is the line the routing test draws. Without a forum, slashing is an administrative penalty register: a list of names the operator has decided to punish, with no mechanism to make the punishment stick against a participant who declines to cooperate, and no defence against the accusation that the operator punishes selectively. The larger the bond, the greater the incentive to contest forfeiture, and a contested forfeiture with no forum is an unenforceable claim on a solvent counterparty.

Reliance demotion is the network’s own consequence and is a different thing. On a certificate, a corridor’s trust level drops to its floor and is rebuilt through the same promotion thresholds as a new corridor (The Sovereign Jurisdiction Network, section 5.8). The network controls its own reliance. It cannot fine or compel a sovereign. A participating state’s written agreement can submit covered corridor obligations to arbitration. Recognition and execution against state property then depend on the forum’s statute, the asset class and any required consent to execution (section 9.9).

The escrow.

The seller can collect the reserved 60,000 only if the custodian has authority to release those funds. A custody mandate names its property, parties, trustee, bonded party and award-executor. It fixes the authorised actions, conditions, signing roles, governing authority and replacement procedure. A signature authorises one instruction. Its digest binds the mandate revision, property slices, predecessor, action, basis, recipient, amount, unit and nonce. Every signature uses that digest. The trustee and award-executor act independently of the network operator, which holds no key or beneficial interest.

The trustee controls custody. The bonded party owns the bonded interest, and the award-executor supplies the independent execution signature allowed by the mandate. Write T_\mu(k,t), B_\mu(k,t) and E_\mu(k,t) for these three roles’ valid signatures on instruction k at execution time t. Their authority must remain effective for that action. The signing condition is \mathrm{Keys}_\mu(k,t)=T_\mu(k,t)\wedge\bigl(B_\mu(k,t)\vee E_\mu(k,t)\bigr). The trustee with either other signer can authorise an eligible instruction. The bonded party and executor together cannot. A generic two-of-three threshold implements a different policy.

An instruction also requires an admitted legal basis, current release eligibility, funded property and its unconsumed predecessor. The mandate’s stage condition must hold for the exact action: \begin{aligned} \mathrm{EscrowPermit}_\mu(k,t)={}&\mathrm{Keys}_\mu(k,t)\wedge\mathrm{Basis}_\mu(k,t)\\ &\wedge\mathrm{Current}_\mu(k,t)\wedge\mathrm{Funded}_\mu(k,t)\\ &\wedge\mathrm{Fresh}_\mu(k)\wedge\mathrm{Stage}_\mu(k,t). \end{aligned} Here \mathrm{Fresh} requires the current custody predecessor and unused nonce. Execution consumes them atomically. \mathrm{Current} includes the custodian’s affirmative release-eligibility determination and every applicable hold. Missing or conflicting authority blocks the action. A conforming certificate proves its named condition. The accepted mandate supplies its authority. An award supplies a distinct basis. A signature creates neither basis.

Suspense and distribution.

A certificate can authorise movement from funded collateral into suspense when the mandate expressly provides that action. The trustee retains the identified property under that mandate. This reservation distributes nothing and reports no recipient recovery. The certificate, key binding, notice recipients and challenge deadline enter the custody record. The trustee moves the property through \mathrm{EscrowPermit}.

Distribution requires a separate instruction and current authority. An unchallenged certificate route requires completed notice, expiry of the prescribed period and a closed intake snapshot covering that period. The snapshot establishes notices received through the designated channels. It establishes no absence of external stays. A qualifying award, settlement, joint instruction or mandate condition can instead support its authorised action. An unresolved challenge blocks disputed distribution under the certificate route. An independently authorised, undisputed amount remains collectible.

A party can lodge a challenge with the trustee or independent review service without operator approval or an advance fee. A timestamped submission remains pending until the challenge enters the durable custody order. An accepted receipt identifies that committed position. The challenge goes to Tier 2. The custodian serialises accepted challenges, review dispositions and release instructions in one order. Distribution requires a fresh predecessor containing every earlier accepted receipt.

Closing the challenge period requires a complete intake cut from every designated channel. Every submission received within the period must enter the custody order before that cut can close. A disconnected channel leaves intake incomplete and blocks certificate-based distribution. Reconnection cannot discard its pending submissions. Legal hold expiry still follows the independent review rule below. Later notice does not erase a completed transfer. Its consequences follow the correction and return rules in section 9.4.

A challenge preserves a hold only for its authorised scope and interval. Before expiry, the independent reviewer must decide continuation, substitution, partial release or return under its authority. A timeout invokes that review path. It never distributes disputed property or extends a hold beyond its legal authority. A subsequent hold or transfer requires its own current basis and applicable signatures. Operators and watchers bond. State recognition and an operator’s bond remain separate instruments. An allocated-property mandate uses the same action and custody conditions.

Funded access and progress.

Before accepting collateral, the custodian records funded coverage for independent challenge intake, emergency review, custody and replacement service. Each active matter receives a disjoint reservation from a separate operating reserve. Disputed collateral, expected forfeitures and unpaid promises supply no coverage. The service contract names capacity, response times and an independent replacement route. Exercising the challenge right requires no claimant funding decision.

The reserve covers each committed procedural stage and custody until its next authorised review. Additional stages require funded commitments before existing coverage expires. Insufficient coverage stops new collateral intake and activates the funded continuity route. It cannot cancel an existing challenge or create release authority. Ordinary cost allocation remains a later decision under the applicable rules.

Progress requires completed notice, available review capacity and funding, and a competent decision within the procedural bound. It also requires the custody provider to execute eligible instructions within its service bound. Under those premises, an unchallenged conforming demand can reach distribution after notice. A challenged demand reaches an independent disposition within its review bound. That disposition can authorise collection, continued protection, substituted security or return. Continued protection carries its next review deadline and funding. A missed premise creates a dated service or authority obstruction with its independent next action.

Pre-funding is available only for obligations funded in advance. Corridor performance, counterparty default, licence-fee obligations and breach by a sovereign participant ordinarily are not pre-funded. A qualifying award supplies an adjudicative route for those obligations, and collection still requires voluntary compliance, security, a guarantee, set-off or execution under forum law. The Convention supports recognition and enforcement of the award. An escrow shortens the route only for controlled value within its mandate.

A selected remedy is not yet a valid remedy.

A remedy record names the obligation, the legal basis, the person or authority that may direct execution, the recipient, the asset or performance sought, the route, the amount and unit, the execution conditions, and the rule for any shortfall. It is executable at a view time only when five independent facts hold. The directing person has authority under the instrument and applicable law. The executing court, trustee, custodian or provider has authority and practical capacity to perform the instruction. The identified asset exists, is controlled on the named route, and is available after stays, sanctions, immunity, priority, insolvency and competing claims are applied. Any escrow or custody leg is funded and its mandate permits the exact release. The record preserves any shortfall as an outstanding obligation and names the next recovery route. A selected remedy whose execution would exceed controlled value is executable only to the controlled amount.

Execution is still not recovery. Execution creates the applicable custody, coercive or voluntary event. Recovery arises only from the recipient-credit and legal-finality evidence in section 9.4. A remedy can therefore be selected but unauthorized, authorized but infeasible, feasible but partly funded, executed but not final, or final with a residual shortfall. The status record keeps those cases separate.

Proposition 8.1 (Remedy selection is non-dispositive).

Selecting a remedy implies none of authority, execution, full funding or recovery.

Proof. Hold the selected remedy record fixed. Its directing authority can expire, a court can stay execution, a custodian can control less than the stated amount, or a receiving provider can leave a credit inside its reversal window. Each change leaves the selection unchanged and makes one required fact false. The implication therefore fails in every case. The route predicates and economic-effect ledger record the facts separately. ◻

What an award does to the record.

Commencement is recorded on the corridor as the DisputedOverlay branch of the corridor lifecycle, which records a proceeding without erasing the underlying state (The Sovereign Jurisdiction Network, section 5.9). An outcome re-enters a deployment’s record only by that deployment’s own signed act, which is the fourth boundary of Accession Networks: no act of the network creates, modifies or extinguishes a recognition edge without the node’s own signature. An award or a determination is a pinned input to the issuer’s next signed evaluation at a new index, never an edit of an earlier one. That is supersession. Revocation is an authority’s own withdrawal of an attestation, a key or a recognition. Compensation is a receipt that reverts an effect. Where the issuer is a sovereign, re-evaluation is its own act. Where the issuer is an operator bound by the corridor instrument, re-evaluation on award is a contractual term, collectible as money if refused. An award never creates, modifies or extinguishes a recognition edge or a grade. Damages price a withheld recognition. A deployment that declines an award binding on it faces the ordinary Convention remedy.

9 Status from consent to recovery

Return to the seller after the two receipts and the later stay. The award remains in the record. Further execution in F_1 is unavailable. The seller has received 79,900 net. One status called enforced cannot report these facts accurately.

The model derives a view from an append-only evidence log. It keeps historical acts, current permissions, economic effects and unresolved conditions in separate components. We call the calculation that builds this view a fold. It reads evidence and changes no external account. A later compromise can invalidate an earlier object while preserving its raw entry. Cash remains in the economic view only where valid authoritative evidence continues to establish it.

9.1 Times and evidence objects

A bank credit and the report of that credit need not arrive together. Likewise, a later court decision can change the assessment of an earlier act. The model must retain when an event occurred and when its evidence became available. Fix a dispute identifier d and an append-only raw evidence log L. Every raw entry z has an event identity, an event time t_e(z), an observation time t_o(z), an issuer, a subject, a type, a content digest, a schema version, authentication evidence, and the identities of the earlier entries it links. The event time is when the reported act occurred. The observation time is when the evidence entered L. The view time t is the cut at which a reader derives status. A late observation can describe an earlier event.

Let \mathrm{auth}_L(z;t) mean that z has a canonical encoding, a supported schema, and authentication evidence that verifies against the recorded issuer and key epoch. This test does not apply a later compromise finding. Let K_t be the authenticated key-status relation supplied by the registry or key-binding authority under its separate root of trust. It maps an affected key or object to the earliest compromised event time. Its construction does not call \mathrm{valid}_L, so the definition is not recursive. Let \mathrm{valid}_L(z,t_e;t) mean that \mathrm{auth}_L(z;t) holds and K_t contains no applicable compromise at or before t_e. The authentication subsystem computes K_t, \mathrm{auth}_L and \mathrm{valid}_L before the dependency fold starts, and their values stay fixed throughout that fold. An ordinary later key expiry does not invalidate a signature that was valid when made. A compromise entry in L records a finding already present in K_t; it does not authenticate itself. Below, “valid” abbreviates the fixed value of \mathrm{valid}_L. The model uses the following evidence objects.

Agreement C.

The arbitration agreement and its authenticated binding context. The context identifies every party, covered claim, applicable law and basis on which that law binds the party. It records capacity, the seat, the rules and the authority that determines disputed applicability.

Jurisdiction inquiry J.

The asserted agreement, parties, claims, appointment evidence, notice and authority to decide jurisdiction. It identifies the natural persons conducting an arbitral inquiry or the competent court. Its authority and disposition remain separate from merits admission.

Case K.

Commencement, notice, response, claims, service and case identity. A party, a process server, an administering institution, the centre’s registrar or a tribunal can supply it. No administrator is required.

Tribunal T.

Appointment and acceptance evidence for each natural-person arbitrator, binding the tribunal to d, C, the appointment method, the rules and the seat, and recording challenges and replacements.

Award A.

The tribunal’s signed dispositive instrument, deciding contested issues or recording agreed terms. It binds parties, dispute, tribunal, claims, seat, rules, date, and a set of relief items I(A), each with an amount and a unit or a non-money performance.

Recognition N.

A forum act that recognises an award as binding or grants an enforcement order. It identifies the award, forum, legal route and covered relief items. Its lifecycle certificate identifies the legally supported effective interval and termination conditions. The certificate can refer to a rule supplied by the competent forum. An unresolved duration remains unknown.

Interim measure M.

An interim measure ordered by the tribunal or by a court and given effect in a forum against an asset, before or after the award.

Review V.

A correction, interpretation, challenge, stay, suspension, refusal, set-aside, discharge or supersession, naming the competent authority, the affected routes and relief items, its effect and its effective interval.

Settlement \sigma and joint instruction \iota.

An authenticated settlement of d, and an authenticated instruction signed by both parties to a custodian.

Custody mandate \mu.

An authenticated instrument binding its parties, custodian, identified property, actions, conditions, delegated authority and effective interval. Its governing authority determines applicability independently of arbitration consent. Each instruction binds the exact mandate revision and condition evidence.

Voluntary compliance P.

An authenticated instruction or completed transfer by the obligor under a stated basis.

Custody release U.

An accepted release by a contractual custodian, identifying the mandate, the controlled property, the release basis and the conditions satisfied at the event time.

Coercive execution X.

A completed act under forum law against identified property, identifying the forum, the asset, the executing authority, the basis and the procedure. A plan, a levy request or a filing is not a completed act.

Attestation.

\mathrm{Attest}(\alpha,\pi,I,v) records a named authority’s determination of predicate \pi over legal interval I. A determination about an act at one time can use a singleton interval. A continuing status requires its own supported interval. Evidence freshness is separate from that interval. The lapse of evidence freshness does not terminate the legal act.

Source checkpoint.

An authenticated checkpoint identifies a source stream, sequence number, prefix digest, covered subjects, complete-through time and evidence-expiry time. It certifies the source-issued updates included through that cutoff. It supplies evidence about the stream and no recognition or actionability determination of its own.

Compromise.

\mathrm{Compromise}(z', t'): the log record of a finding in K_t that object z' is forged, misidentified or signed under a key compromised from t'.

Economic effect \epsilon.

Defined in section 9.4.

9.2 Routes and predicates

The seller may receive voluntary payment, collect under the escrow mandate, or seek execution in a particular forum against particular property. A route identifies that means of performance and the authority on which it depends. A route is one of \rho ::= \mathrm{Court}(f, a) \mid \mathrm{Custody}(c, a) \mid \mathrm{Voluntary}(b), where f is a forum, c a custodian, a identified property and b a payment basis. Route identity prevents authority in one forum, over one asset, or under one mandate from being reused elsewhere.

A legal predicate is a question such as whether a particular asset is currently available for execution. Its value comes from the competent authority. Every legal predicate carries two times: the event time it speaks about and the view time at which it is evaluated. The route predicates are \begin{align*} &\mathrm{RecognizedAt}(A, f, i, t_e; t), &&\mathrm{ActionableAt}(A, f, a, i, t_e; t),\\ &\mathrm{ReleaseEligibleAt}(\beta, c, a, t_e; t), &&\mathrm{VoluntaryBasisAt}(b, t_e; t). \end{align*} Here i is a relief item and \beta \in \{\mathrm{Award}(A),\ \mathrm{Settlement}(\sigma),\ \mathrm{JointInstruction}(\iota),\ \mathrm{MandateCondition}(\mu,k)\}.

The voluntary-basis predicate resolves b to an accepted award, settlement or joint instruction for the exact parties, claim and action. Settlement and instruction authority are independent of arbitration consent. For \gamma\in\{\sigma,\iota,\mu\}, \mathrm{InstrumentApplies}(\gamma,d,s;t) records formation, capacity, party binding, scope and action authority under the instrument’s applicable law. It also binds any representative’s delegated authority. An affirmative instrument predicate creates no coercive power or arbitration agreement. For \mathrm{MandateCondition}(\mu,k), the accepted mandate supplies the basis and k identifies the exact action and condition evidence. The custody guard checks both. A certificate can satisfy a mandate condition and cannot satisfy \mathrm{QualifyingAward}. Custody applicability supplies no voluntary-payment basis. The process predicates are \begin{align*} &\mathrm{AgreementApplies}(C, d, t_e; t), &&\mathrm{ProperNotice}(K, t_e; t),\\ &\mathrm{ProperlyConstituted}(T, t_e; t), &&\mathrm{QualifyingAward}(A, t_e; t),\\ &\mathrm{RecognitionAct}(N, f, t_e; t), &&\mathrm{ReviewAct}(V, t_e; t),\\ &\mathrm{InterimAct}(M, f, a, t_e; t). \end{align*} Indexing recognition and actionability by relief item lets the model represent partial recognition and partial set-aside. Article V(1)(c) and Model Law Articles 34(2)(a)(iii) and 36(1)(a)(iii) provide for both. The fold never evaluates a legal predicate. It reads determinations from entries of L. The route fixes which authority may determine each predicate. The forum determines court predicates, the custodian determines release eligibility, and the tribunal or seat court determines process predicates. The resolver below distinguishes missing, false and conflicting determinations. The legal assumptions in section 9.6 state when an authoritative determination is correct.

For every party p and head of claim h, the binding context resolves \mathrm{PartyBound}(C,p,h,s;t). It identifies the agreement, scope, capacity and applicable-law basis. \mathrm{AgreementApplies}(C,d,s;t) requires affirmative binding determinations for every party and head admitted in d. A reliance record alone supplies none of these determinations. \mathrm{InquiryAuthority}(J,s;t) separately identifies the seat-law or court-law authority to decide a contested jurisdictional basis. An inquiry disposition can supply a binding determination through its competent authority. It creates no agreement or merits award by itself.

9.3 Recognition lifecycle

The seller need not obtain a new recognition act merely because time passes. Yet an intervening stay may block a proposed levy. The record must reuse the recognition basis while checking the later events that affect its use. A recognition act and evidence about its continuing effect have separate lifecycles. Let \nu identify the forum’s lifecycle profile. The profile names the competent sources, update scopes, freshness rules and legal supersession rules. The competent forum supplies these parameters.

For each recognised relief item, a lifecycle certificate binds \ell=(N,A,f,i,\nu,I,\mathcal{T},\Gamma). Here I is the legally supported effective interval. Its endpoint can be open when the applicable rule supports continuation until a named event. \mathcal{T} contains the termination and suspension conditions. \Gamma identifies every update source required by the profile. Each condition names the authority and evidence that resolves it. An unresolved condition produces an explicit obstruction.

The certificate establishes the recognition basis once. A reader reuses that basis while its legal interval and conditions support the requested use. The reader refreshes evidence about subsequent events. That refresh requires no new signature on the recognition act.

Ordered sources.

Each source update binds its stream, sequence number, predecessor digest, issuer, covered subjects and legal effective interval. It names the act or determination it changes. A stay names the predicates and relief items it suspends. A lifting order identifies the stay it lifts. A correction identifies its predecessor. Sequence order establishes publication order within the source. Legal priority between authorities requires its own basis.

A checkpoint authenticates one complete stream prefix for its stated scope. A sequence gap produces \mathrm{SourceGap}. Incompatible successors produce \mathrm{SourceConflict}. Either obstruction prevents a positive current-use guard. Repeated delivery changes neither the prefix nor legal status. Authorised supersession replaces its named determination over the specified interval. An ordinary later timestamp establishes no supersession. Unresolved incompatible determinations produce \mathrm{PredicateConflict}. An execution stay need not withdraw recognition.

Freshness and completeness.

Freshness requires compliance with the profile’s evidence-expiry rule. Completeness requires the relevant source prefix. A recent timestamp supplies neither completeness nor evidence against an intervening order.

For a use at time s\leq t, each required source supplies a complete prefix through s, or a source-authorised current-use witness. The witness binds the checked prefix and proposed action. Its issuing mechanism orders the check against updates preceding that action and prevents reuse after an intervening blocking update. A source-signed delegation can authorise these checks. Its authority covers the actual use stage, including provider acceptance when the governing institution requires that stage.

One checkpoint can cover many subjects within its certified scope. Reusing authenticated instruments and updates creates no new recognition act. A disconnected cache retains the historical act and its last supported interval. It reports \mathrm{EvidenceStale} when current-use evidence has expired. Completeness covers updates issued by the named sources through the cutoff. A later decision can have an earlier legal effective date. Coverage of every legally relevant source remains a forum-specific obligation.

A current reassessment incorporates every relevant update observed by t, including updates issued after the queried action time s. The earlier prefix fixes the recorded historical guard only.

Current use.

A proposed action binds its award, forum, asset, relief item, operation and action identity. A value-moving action also binds recipient, quantity and unit. Its guard tests predicates at the action time s under observation cutoff t: \mathrm{RecognizedAt}(A,f,i,s;t),\qquad \mathrm{ActionableAt}(A,f,a,i,s;t). Recognition supplies the first predicate only. The second requires the executing route’s separate determination. Custody uses its mandate and current release eligibility. Current-use evidence binds the complete action and checked source prefixes. The executing authority records its determination and evidence cutoff with the completed act. Reusing recognition cannot reuse an action identity or consumed allocation capacity.

Later and backdated changes.

A later order can change the current assessment of an earlier legal interval. The record retains the earlier act, its evidence cutoff and its contemporaneous determination. It records the later order and revised assessment separately. A backdated stay can create a disputed-authority assessment or restitution duty. It cannot erase an execution or payment. A lifting order removes only the stay it identifies. Another operative stay, terminated recognition or a different asset requires its own determination.

9.4 Economic effects and collected cash

Six events.

The record separates six events for every movement of cash. Instruction acceptance is the sending provider’s acceptance of an authorised instruction. Funding is the provision of value to the sending provider so that the instruction can execute. Ledger confirmation is the provider’s record that it has moved value on its own books. Legal finality is the moment at which the transfer becomes irrevocable and unconditional under the rule that governs that provider in that legal order. The Principles for Financial Market Infrastructures define final settlement in that sense, as the irrevocable and unconditional transfer of an asset or the discharge of an obligation at a legally defined moment, and this paper uses the same meaning. Receiving-institution receipt is the arrival of value at the recipient’s own bank, custodian or wallet provider. Recipient credit is the credit of usable value to the entitled recipient’s own account. Each event has its own time, evidence and reversal rule. Ledger confirmation is not legal finality. Receiving-institution receipt is not recipient credit. Provider confirmation is evidence of the one event the provider confirms and of no later event.

Two public statements fix the boundary at one named rail. The Federal Reserve describes the Fedwire Funds Service as a real-time gross settlement system whose transfers are immediate, final and irrevocable once processed. That finality is interbank finality in central-bank money between Fedwire participants. The beneficiary’s own credit is a separate obligation of the beneficiary’s bank that arises on its acceptance of the payment order, as Uniform Commercial Code section 4A-404 provides for that legal order. Other legal orders set their own rule, and the record names the rule that applies. The receiving leg is the recovery leg with the least evidence and the most time. Du, Huang and Scharfstein (2026, section 7.2) report Swift’s 2024 measurement that approximately 90% of cross-border payments transmitted over the Swift network reached the destination bank within one hour, and attribute the bulk of end-to-end delay to the leg between the beneficiary bank and the crediting of the end customer’s account. The property measured is elapsed time from transmission to arrival at the destination bank, over the payments Swift sampled in 2024, and the boundary is arrival at the beneficiary institution and not credit to the beneficiary. The record therefore never infers recipient credit from any earlier event. It collects recipient-credit evidence from the recipient’s own provider or from the recipient. A cross-border recovery contains at least two local executions: execution against property in the asset jurisdiction under that jurisdiction’s law and provider, and credit to the entitled recipient in the recipient’s jurisdiction under the recipient’s own provider, with conversion, transfer authority and compliance checks between them, each with its own time and evidence.

The seller’s two receipts raise a different problem from the award’s authority. We must identify each actual movement, establish its completion, and attribute its quantity to the correct claim. A provider callback and an account statement may describe the same credit. They add evidence, not another payment.

An economic occurrence is one identified movement on the nominated account. It has a stable identity and authenticated assertions about its attributes. One reported occurrence is \epsilon=(e_{\mathrm{id}},p,r,t_e,t_o,q,u,\delta,\kappa,e_{\mathrm{ref}}). Here e_{\mathrm{id}} identifies the occurrence report. It supplies no inference that another report describes a second movement. The stable occurrence key below identifies the movement across reports. The symbol p names the settlement namespace and r the recipient-side account. The times t_e,t_o record the event and observation. The reported quantity q\geq0 has unit u. The direction \delta\in\{-1,+1\} records a debit or credit relative to that account. The kind \kappa classifies the movement as a receipt, fee, tax, refund, reversal or unclassified movement. An optional reference e_{\mathrm{ref}} supports a claimed relationship to an earlier occurrence. That relationship neither supplies evidence that cash moved nor determines its direction. \mathrm{sgn}(\epsilon)=\delta(\epsilon). A fee refund therefore records its actual credit direction. An unsolicited debit remains a debit when its claimed legal origin or reversal reference fails.

A payment can have several accounting legs, such as the interbank transfer and the final credit to the seller’s account. The nominated accounting leg is the specific posting counted by this occurrence. The occurrence key binds the settlement namespace, authoritative occurrence reference, nominated accounting leg, recipient account and unit. Legal origin, observer identity and observation time remain outside that key. Provider observations of the same recipient credit bind to it through authenticated correspondence evidence. An interbank transfer and the recipient credit are different events linked by causation. They are not aliases. Evidence for an earlier leg cannot create a second recipient-credit occurrence.

Every raw assertion has its own event identity. Its canonical digest binds the occurrence key and the reported tuple, including direction, quantity and any relationship reference. A supporting wrapper is an authenticated evidence record attached to the assertion. It identifies the event its source confirms and binds that assertion and digest. \mathrm{Supp}_t(e) retains the valid authoritative wrappers observed by t. The current projection selects the applicable assertion revision and its matching support. Identical reports add support. Distinct legitimate partial transfers have distinct occurrence references and can add. An unresolved alias relation remains reconciliation evidence and supplies no additional attributed recovery.

Corrections and reported history.

The original reported quantity remains in the assertion history. A competent source can correct it through a separately identified assertion that names its predecessor and correction authority. The supported projection uses one authenticated assertion revision and its applicable evidence. Conflicting successors create an obstruction. A correction changes the current supported projection once and preserves each earlier report and committed claim transition. It is an accounting adjustment, not an invented physical debit.

The record therefore divides each occurrence’s quantity into identifiable slices at a fixed precision. A slice is an accounting portion of that occurrence.

For occurrence e, let Q_e be the quantity of uniquely identified attribution slices admitted over its assertion history. Slices have a fixed unit and precision. Increasing supported quantity can admit only newly established slices. Restoring a previously corrected slice restores its existing identity. It cannot issue that quantity twice. Let \mathcal{V}_t(e) be the subset currently substantiated by the accepted assertion revision. A correction names affected slices or uses the allocation rule fixed when they were admitted. Ambiguous portions remain an explicit reconciliation amount. An unsupported consumed slice creates an attributed-credit deficit. It does not erase the historical claim transition.

Finality knowledge.

A missing reversal-window field cannot establish that every applicable window has closed. The record needs the competent authority’s complete policy for this occurrence and payment route. Every occurrence carries route-specific knowledge: \mathsf{Unknown}\quad\text{or}\quad \mathsf{KnownComplete}(\rho,v,W,c,\alpha). The complete form names the route \rho, applicable policy revision v, exhaustive window set W, evidence cutoff c and authority \alpha. A provider reversal window is an interval during which an applicable provider rule permits the named reversal, recall or return. Its scope and applicability require the competent route authority’s evidence. Authenticated evidence binds these fields to the occurrence assertion and its nominated accounting leg. It identifies the authority entitled to state that W contains every applicable provider reversal window. An authenticated empty W means that this policy specifies no such window. Missing metadata remains \mathsf{Unknown}.

Legal finality and provider-window closure are separate evidence requirements for the specified accounting leg. Finality of an earlier interbank transfer cannot satisfy either requirement for the recipient’s credit. The competent authority identifies which rules apply to that credit. A later legal return duty remains a distinct event from completion of the original transfer. Conflicting policy evidence creates a typed obstruction. Each exported state carries its supported cutoff. Let h be the requested event-time horizon and t the observation cutoff. The current state S_t(d,L) uses h=t. A historical projection names its earlier horizon separately. A collected witness requires c\leq\min(h,t). Every applicable window must have closed by c. An exact current-horizon query also requires authoritative coverage and freshness through h. A future policy schedule can be known earlier, but its future closure cannot establish present collection.

Recovery states.

The complete support set determines state at its reported cutoff. An occurrence is provisional after authoritative ledger confirmation while its required account posting remains unconfirmed. Its intermediate available state records confirmed posting while the collection premises remain incomplete. A credit posting establishes usable recipient credit. A debit posting establishes the deduction from that account. The signed intermediate amount reports the corresponding exposure. Current funding uses its separate ledger.

An occurrence is collected when the following evidence requirements hold. They establish the account posting, legal finality and applicable \mathsf{KnownComplete} policy. Account-posting evidence means recipient credit for a credit occurrence and an authoritative account debit for a debit occurrence. Every window in W must have closed by the supported cutoff. Each premise binds the same supported assertion revision and accounting leg. Unknown, conflicting or stale policy evidence preserves observed available value and records the corresponding obstruction. Receiving-institution receipt remains a separate event.

Debits have their own authoritative occurrence evidence. An observed debit reduces current spendable backing when that evidence establishes the reduction. This protection does not wait for the debit’s finality classification. Its collected-state contribution to recovery uses the same complete-policy rule. A later competent decision can create a return duty. That duty and a completed return remain distinct events. A completed return enters as its own debit occurrence. Historical receipt and claim records remain available after the return.

Atomically describes one ordered record transition. Recipient credit and collection depend on their respective external events and evidence.

The settlement asset.

Each effect names the asset that discharges it: central-bank money, a bank deposit, electronic money, a token, or another claim. For any asset other than a bank deposit or central-bank money in the recipient’s own account, the record also names the issuer, the recipient’s redemption right, the redemption route into the recipient’s bank money, the redemption cycle, the market depth at the required size, and the legal finality rule for the transfer. A token credited to the recipient is a claim on its issuer. It becomes recovery only when the recipient can use it or redeem it at the recorded value. Du, Huang and Scharfstein (2026, section 7.2) report one issuer’s route on which a standard redemption into bank money settles on the next business day and a same-day redemption carries an expedited fee. That is one route on one date. It shows that redemption has its own cycle and cost, and it sets no bound for any other route. Where a provider’s transfer is irreversible on its own ledger, the record names the legal route for recovering a mistaken or excess transfer before any instruction is dispatched, because transfers on public blockchains are generally irreversible and an operational error can cause permanent loss (Du, Huang and Scharfstein 2026, section 7.5).

Conversion.

Where the award currency and the receipt currency differ, the value recovered is the amount the entitled recipient can use after conversion at the recorded rate, and the effect names the rate source, the rate date and any exchange-control authorisation. An official rate and a market rate can differ under exchange controls, and the record states which rate applied and under whose authority.

Conserved attribution.

Suppose a receipt of 100 discharges claim A. Another claim cannot use those same 100 merely by deleting the first allocation. Reassignment must adjust both claims under the required authority.

Each occurrence has one attribution journal shared by every dispute and legal origin that uses its quantity. Its slices form disjoint sets: unassigned U_e, reserved R_e, disputed consumed X_e, and attributed consumed S_e(d,o). Here d names the dispute and o the legal origin to which the slices are attributed. Bars denote quantity in the recorded unit. Their quantities satisfy Q_e=|U_e|+|R_e|+|X_e|+\sum_{d,o}|S_e(d,o)|. The journal records each slice, allocation identity, legal origin, recipient, unit, authority and committed predecessor. A reserve moves currently supported unassigned slices from U_e to R_e. A consumption requires current support and the exact claim authority at its recorded evidence cutoff. It moves those slices from R_e to S_e(d,o) and atomically applies its certificate’s claim transition. A payment-discharge transition also requires the settlement state specified by its obligation family. A release returns only unconsumed reservations to U_e.

A consumed allocation remains consumed. Removing its display row, changing its origin label or replaying its certificate never restores unassigned capacity. A reassignment of consumed slices preserves their consumption identities. It requires one authorised transaction that moves the slices and records compensating adjustments to both affected claim states. Every earlier consumption and adjustment remains in history. Each committed predecessor has one committed successor. Replaying that successor changes nothing. Conflicting uncommitted proposals can wait for the journal’s committed decision.

If alias reconciliation exposes competing historical consumptions of the same canonical slices, those slices enter X_e. Every historical claim credit remains recorded with its quantified discrepancy. Disputed consumed slices cannot return to U_e or support another discharge. An authorised reconciliation moves them to the correct S_e(d,o) and adjusts every affected claim. This preserves one active occurrence budget while retaining the full error history.

An attribution can record cash against an invalid legal origin while carrying the corresponding obstruction. The occurrence remains a cash fact. Any claim discharge also requires its own applicable authority. Cash attribution and satisfaction remain separate typed actions.

Write \mathrm{CashObserved}(e) for an authenticated occurrence and \mathrm{Allocated}(e,d,o) for its committed attribution to a dispute and origin. The first predicate never implies the second. An allocation certificate binds the occurrence slices, recipient, unit, claim revision and authority entitled to attribute the payment. A party-name match supplies none of that authority. An attribution to another invoice preserves the cash fact and contributes zero to this dispute. A payment attributed to an invalid award can remain recorded against that award, with its legal defect and any restitution question explicit. Its attribution establishes what was paid in that matter. The separate satisfaction predicate determines its effect on the claim.

The bound applies across all disputes. A dispute view cannot create another budget. Resource owners can maintain separate journals for distinct occurrences. The construction does not require one network-wide sovereign ledger.

Current cash backing.

The seller may spend a receipt before its evidence reaches the dispute record. That spending does not undo the earlier payment. It does affect how much cash can fund a new instruction. Receipt attribution and funding for a new cash command therefore use different ledgers. For each provider account and unit, let B\geq0 be reconciled funded backing. Let R^B and E^B be its reserved and encumbered quantities. Define F^B=(B-R^B-E^B)_+,\qquad D^B=(R^B+E^B-B)_+. Here x_+=\max(x,0). Thus B+D^B=F^B+R^B+E^B. A new cash command reserves quantity x\leq F^B and consumes that reservation once. The transition binds the current balance checkpoint and reservation revision. An award, receivable, promised reimbursement or bookkeeping release creates no funded cash. An adverse external event can increase D^B while preserving the recorded claims and reservations.

Attributing an earlier receipt does not debit current cash again. A recipient can spend a valid receipt before evidence arrives. The later receipt evidence can still support the original claim’s discharge. Ordinary spending does not erase that recovery.

Actual returns, unsolicited reversals and adverse quantity corrections update the relevant funding projection. A newer authoritative balance can already include the adjustment. The reconciliation record binds the source cutoff and covered occurrence or correction identities, so the adjustment applies exactly once. Unsupported reserved funding creates a quantified shortfall. It supports no additional funded command. Historical effects remain recorded while current backing reflects the evidence.

Gross and net.

In the delivery example, the two receipts total 80,000 and the fee reduces net recovery to 79,900. The following sums generalise that account while retaining quantity corrections and allocations across claims. Let s_t(e,d,o)=|S_e(d,o)\cap \mathcal{V}_t(e)| be currently substantiated consumed attribution. Then \sum_{d,o}s_t(e,d,o)\leq |\mathcal{V}_t(e)|. The ledger reports unsupported consumed attribution as a deficit beside historical claim transitions. It reports unapplied cash and unresolved debit attribution separately. A genuine return is a distinct debit occurrence. Its matched relationship can use only the earlier occurrence’s unmatched quantity. Any excess remains a full cash debit with a discrepancy or separate legal allocation. A failed relationship never suppresses the cash fact.

Let E_t^{\mathrm{col}}(u) contain occurrences collected at the reported cutoff. For fixed dispute d, define \mathrm{Gross}_t(u)= \sum_{e\in E_t^{\mathrm{col}}(u),\ \kappa(e)=\mathsf{Receipt}} \sum_o s_t(e,d,o), \mathrm{Net}_t(u)= \sum_{e\in E_t^{\mathrm{col}}(u)}\delta(e)\sum_o s_t(e,d,o). Recovery is a vector indexed by unit. A single reporting currency requires a named conversion policy, source, rate time and rounding rule. If one is missing, the model returns a conversion obstruction instead of adding unlike units. Provisional and available effects are reported beside the vector as exposure and are never added into it. Recovery in this paper means cash and asset receipts. Discharge without receipt, by set-off or delivery in kind, is satisfaction, a legal determination by a competent actor, recorded separately from recovery. The two never substitute for each other.

9.5 The state and the fold

The preceding definitions answer four different questions: what happened, what can be done now, what value moved, and what remains unresolved. The derived state at view time t is a product S_t(d, L) = (H_t, C_t, E_t, O_t). H_t is the currently accepted historical projection. It contains accepted legal and procedural entries, including jurisdiction inquiries and committed claim adjustments. The raw log retains reports even when later evidence changes their acceptance. Review-only extensions preserve H_t under the theorem’s conditions. Compromise findings and new legal attestations have the separate effects specified below. C_t records current recognition, actionability, release eligibility and other route predicates. Missing, false and conflicting predicate values create distinct obstructions. E_t contains occurrence assertions, their current support projections, attribution journals and the separately reconciled funding records. O_t contains typed obstructions, rejected relationships, shortfalls and provenance. A disputed legal allocation or relationship leaves the underlying cash occurrence in E_t.

Identity canonicalisation and order.

At view time t, take entries observed by t. Compute K_t, \mathrm{auth}_L and \mathrm{valid}_L once over that cut. Each raw assertion has its own event identity. An unauthenticated entry creates its own obstruction. Equal authenticated identities with equal content identify repeated evidence. Equal identities with conflicting content create an identity conflict.

Economic assertions additionally name their stable occurrence key. Keep their authenticated assertion history and supporting wrappers. Repeated wrappers cannot change occurrence quantity, create slices or revise allocations. A corrected assertion has a fresh identity, names its predecessor and carries its source’s correction authority. It updates the supported projection under the versioned correction rule. It never overwrites the earlier assertion. Conflicting successors leave the disputed support unavailable for new consumption and create a quantified obstruction.

Correspondence evidence can identify two reports as observations of the same recipient credit. It can also identify separate causal legs. Only the first relation merges occurrence identity. A reconciliation transaction maps previously admitted journals to canonical slices. Competing consumed portions enter X_e and contribute no newly claimed recovery while their attribution remains disputed. They remain consumed for capacity accounting. An authorised reconciliation adjusts all affected claims before assigning those portions. Historical duplicates and excess claim credits remain explicit deficits. An alias cannot silently delete a claim transition or manufacture capacity.

Write Q_t for the canonical entries and their retained histories. F1 and F3 make assertion identity and canonical ordering deterministic. F5 supplies the committed journal order for attribution and correction transactions.

For each predicate instance \pi at an event time s, let W_t(\pi,s) contain every value carried by a valid canonical act authorised to determine \pi at s and every value in a valid canonical attestation by the authority named for \pi whose interval contains s. The values that a \mathrm{Review} assigns to route predicates do not enter W_t; the historical fold records the review, and the current-state calculation applies its operative interval. The predicate guard holds only when W_t(\pi,s)=\{\mathsf{true}\}. An empty set creates \mathrm{PredicateMissing}(\pi,s), the singleton false set creates \mathrm{PredicateFalse}(\pi,s), and both values create \mathrm{PredicateConflict}(\pi,s,Z), where Z names the sources. The resolver is computed from Q_t before the historical fold. Its result is therefore total, deterministic and fixed during that fold.

Evidence can arrive after an object that depends on it. The historical calculation therefore repeats until every supported dependency has been accepted. Partition Q_t into historical entries Q_t^H, occurrence assertions Q_t^E, and journal transactions Q_t^J. Start from empty historical state. Scan Q_t^H in (t_o,e_{\mathrm{id}}) order and apply \delta_t^H to entries not yet accepted. Repeat until a pass accepts nothing. Each guard uses the fixed legal-predicate resolver and depends monotonically on accepted ancestors. The accepted set reaches its finite least fixed point. A missing ancestor remains an obstruction.

Next process occurrence assertions in the canonical order. Authentication, the nominated accounting leg and source evidence admit the physical report. An origin, refund reference or allocation dispute does not control that admission. Resolve claimed relationships after their endpoint assertions are known. An accepted refund relationship points to an earlier occurrence and consumes only its remaining matchable quantity. An unmatched or excessive debit remains a cash occurrence with a relationship obstruction.

Then validate the committed journal prefixes in Q_t^J. Each transaction names the authority, predecessor, exact occurrence slices and every affected claim revision. Atomic multi-claim adjustments consume all named predecessors together. A committed transaction records the evidence cutoff used by its guard. Replaying it preserves that event and its historical decisions. Later evidence changes current support, backing or a subsequent authorised adjustment. It does not turn a prior consumed slice into unused capacity.

The current view uses the latest supported assertion projections and reconciled balance cutoffs. Corrections and aliases apply once through their identified journal transactions. The historical fold, occurrence pass, journal validation and current-state calculation define \mathrm{Fold}_t(L).

Transitions.

A guard is a condition that must hold before the fold accepts an event. Each guard reads entries of L. A historical guard uses the fixed resolver at its stated event time. Rules 1 to 14 define \delta_t^H. Rule 15 admits occurrence evidence. The journal transitions in section 9.4 define attribution, correction and funding updates.

  1. \mathrm{Consent}(C) enters H_t if \mathrm{valid}_L(C,t_C;t). Its admission records the agreement and binding context. Invoking it requires the separate applicability guard.

  2. \mathrm{OpenInquiry}(J) enters if valid, properly notified and supported by \mathrm{InquiryAuthority}(J,t_J;t). The inquiry records the asserted agreement and competent decision-maker. It creates no accepted consent, merits commencement or award. A merits proceeding still requires the ordinary agreement, applicability and notice guards below.

  3. The instrument transitions are \mathrm{Settle}(\sigma), \mathrm{Instruct}(\iota) and \mathrm{CustodyMandate}(\mu). Each requires a valid instrument and its applicability guard: \mathrm{InstrumentApplies}(\gamma,d,t_\gamma;t). The authenticated context binds the corresponding instrument’s parties, claims, assets, acts and delegated authority. Each instrument requires its own applicable-law basis and no accepted arbitration agreement. A mandate permits only actions supported by its operative conditions. Merits commencement retains the separate agreement guard below.

  4. \mathrm{Commence}(K) enters if valid and linked to an accepted C. Both \mathrm{AgreementApplies}(C, d, t_K) and \mathrm{ProperNotice}(K, t_K) must hold. Applicability is tested when the agreement is invoked, not when it was executed, which is where Model Law Articles 8(1) and 16(2) and Article II(3) of the Convention place the test.

  5. \mathrm{Constitute}(T) enters if valid, links an accepted K, and \mathrm{ProperlyConstituted}(T, t_T) holds.

  6. \mathrm{Award}(A) enters if valid, links an accepted T, is signed by the natural persons T names as the rules require, and \mathrm{QualifyingAward}(A, t_A) holds. The tribunal’s signature is its own determination that the instrument is an award under the rules and the seat law.

  7. \mathrm{Recognize}(N, f) enters if valid, links an accepted A, names its scope, and \mathrm{RecognitionAct}(N, f, t_N) holds as the forum’s own act.

  8. \mathrm{Interim}(M, f, a) enters if valid, links an accepted K, and \mathrm{InterimAct}(M, f, a, t_M) holds.

  9. \mathrm{Review}(V) enters if valid and its issuer is the authority its route names, which is \mathrm{ReviewAct}(V, t_V) as carried. A stay, suspension, set-aside, refusal or discharge is an operative review over its effective interval.

  10. \mathrm{Attest}(\alpha,\pi,I,v) enters if valid and \pi’s route names \alpha as its authority. A source checkpoint enters under the same authentication and authority tests for its stream. Lifecycle and source metadata supply current evidence only. They supply no independent legal determination to the historical predicate resolver.

  11. \mathrm{Compromise}(z', t') enters if it authenticates under the root authority and matches the corresponding finding in K_t. It changes no accepted set during the fold. Its effect is already present in the fixed value of \mathrm{valid}_L for this view. Every object affected by that finding at or after t' fails validation and enters O_t with its provenance retained.

  12. \mathrm{VoluntaryComply}(P,b) enters when the instruction, payer, recipient, amount, unit and provider result authenticate. Its \mathrm{VoluntaryBasisAt}(b,t_P;t) determination resolves to an accepted award, settlement or joint instruction covering that exact payment. An independently binding settlement or instruction can supply this basis without arbitration consent. The transition creates no recognition, coercive actionability or custody-release authority.

  13. \mathrm{CustodyRelease}(U,c,a) enters if valid and linked to its mandate and asset. The custodian affirms \mathrm{ReleaseEligibleAt}(\beta,c,a,t_U;t) for that release. An award, settlement or joint-instruction basis must be accepted. A mandate-condition basis links its accepted mandate \mu and verified condition evidence for instruction k. The escrow profile requires its complete guard, \mathrm{EscrowPermit}_\mu(k,t_U). Its committed predecessor establishes the custody state used at execution. Suspense alone supplies no recipient credit or recovery amount.

  14. \mathrm{CoerciveExecute}(X, f, a) enters if valid, links an accepted A and a relief item i \in I(A), links an accepted basis in f, which is an accepted \mathrm{Recognize}(N, f) whose scope covers i, an attestation by f that its law enforces the award without a separate recognition act, or an accepted \mathrm{Interim}(M, f, a), and carries the executing authority’s act, which is its determination that \mathrm{ActionableAt}(A, f, a, i, t_X) held.

  15. \mathrm{Effect}(\epsilon) enters E_t through authoritative occurrence evidence for the nominated account and unit. Each wrapper binds the occurrence assertion and the event it proves. Support determines the provisional, available or collected state under section 9.4. Missing, invalid or conflicting origin attribution adds an obstruction and preserves the cash report. An unsupported reversal reference likewise preserves the full actual debit. Its accepted matching portion respects the referenced occurrence’s remaining quantity. Any excess receives a separate discrepancy or legal allocation. Attribution, claim discharge and cash funding each require their own journal transition.

Current state.

Let \Pi_t contain the current predicate instances required by accepted routes and relief items. For each \pi\in\Pi_t, the lifecycle calculation resolves the applicable legal interval and conditions. It applies authorised, scoped review and supersession effects from the required source prefixes. It then checks the evidence coverage required for current use.

An accepted recognition supplies a basis for \mathrm{RecognizedAt}(A,f,i,t;t) while its lifecycle supports that interval and relief item. It supplies no \mathrm{ActionableAt} value. An operative review affects only its named predicates, subjects and intervals. A lifting order removes only its named obstruction.

The legal result is true, false, missing, unresolved or conflicting. The evidence result is sufficient, missing, stale, incomplete or conflicting. Set C_t(\pi)=\mathsf{true} exactly when the legal result is true and the evidence result is sufficient. Otherwise set it false and retain every applicable typed obstruction in O_t. Unknown termination conditions and stale evidence therefore remain distinct. The profile, canonical prefixes and finite scoped updates determine each result uniquely.

Observation and dispatch.

The fold reads evidence and produces a view. Its input contains no provider capability and its output contains no executable command. A late assertion can revise support, attribution or a shortfall. It cannot authorise another transfer. Counterfactual queries use the same effect-free interface.

An external command has a separate durable record. Before dispatch, its key binds the immutable request, provider, account, recipient, unit, maximum amount and governing obligation revision. Command admission checks current action authority and reserves available funding in one protected transaction. The journal records the authority-use stage and evidence cutoff. Dispatch reads this admitted record through the provider’s idempotency contract. A retry uses the same key and the same payload. An ambiguous response retains its reservation and enters reconciliation. Provider acceptance, partial execution and terminal remainder closure remain separate states.

A residual command consumes an explicit transfer of remaining execution capacity. The original command must have terminal remainder evidence or a provider-enforced capacity transfer. Its possible further performance remains reserved until then. The combined outstanding capacity cannot exceed the obligation’s remaining amount after attributed performance. A return or replacement payment requires its own command, current authority and funding. Observing a return duty supplies the next required action, not its execution authority.

Capacity admission also accounts for completed performance awaiting attribution. Let D be the legally outstanding quantity, P completed possible performance absent from that claim state, and U possible additional performance under unresolved commands. These quantities use disjoint performance slices. New capacity x must satisfy 0\leq x\leq\max(D-P-U,0). The resolver reconciles provider performance before releasing command capacity. An unresolved attribution or support correction retains its ownership hold until an authorised reconciliation determines its consequence. The reconciliation adjusts all affected claim and command revisions atomically. Once a payment reduces D, its slices leave P in that same transition. Thus a payment of 40 against 100 leaves capacity of 60 whether its valid attribution is pending or completed. Terminal closure alone cannot make those 40 available again.

Proposition 9.1 (Replay separation).

For any finite evidence log, evaluating the fold issues zero provider commands. Repeating an admitted dispatch preserves its command identity. Under the provider’s idempotency contract, those repetitions cause at most one execution of that command’s authorised capacity.

Proof. Every fold operation reads authenticated entries, resolves relations or constructs a view. None has a dispatch transition or a provider capability. Induction on its finite computation gives the first claim. Dispatch accepts only a durable command record. Immutable request binding fixes the key and payload on every retry. The provider contract then supplies the execution bound. A changed request requires a new admission and cannot reuse the old capacity. ◻

9.6 Assumptions

The theorem establishes what the record preserves when its evidence mechanisms have the stated properties. It does not establish the truth of an award, a custody mandate or a provider report. Five formal assumptions carry the theorem.

F1, authentication.

For a fixed log cut and view time, the root authorities supply a deterministic authenticated key-status relation K_t, and verification returns deterministic \mathrm{auth}_L and \mathrm{valid}_L values for every entry. Constructing K_t does not call either function. A successful \mathrm{auth}_L test binds issuer, subject, content, event time, schema and key epoch, except with negligible cryptographic failure probability. A finding in K_t effective at or before the event time makes \mathrm{valid}_L false without changing \mathrm{auth}_L.

F2, identity binding.

Dispute, party, agreement, tribunal, award, route, asset, account, occurrence, assertion, allocation and claim-revision identifiers refer to their intended objects.

F3, canonical order.

Event times, observation times and assertion identities define deterministic total orders. Content digests are collision resistant. The admitted schema fixes units, precision, slice identities and deterministic correction-allocation rules. Each lifecycle profile fixes source identity, predecessor binding, scope comparison and deterministic update interpretation. Legal supersession requires its named authority relationship.

F4, authoritative economic evidence.

A wrapper is valid and comes from a source authorised to report its named event. It binds the occurrence assertion, account, unit, event time and evidence cutoff. Collection requires a complete applicable finality-policy certificate from the competent route authority. That certificate binds the supported assertion revision, accounting leg, policy scope and exhaustive window set. Under the declared provider assumptions, its list contains every applicable window and its cutoff supports the stated horizon. An empty list requires that same completeness evidence. Source corrections and balance statements identify the earlier assertions or adjustments they supersede or include.

F5, occurrence and journal authority.

The canonical occurrence relation identifies one recipient-side movement independently of legal origin or reporter. Authoritative correspondence distinguishes aliases from separate causal legs. Each attribution journal has one authenticated committed successor per predecessor. Atomic multi-claim transactions bind every consumed predecessor and resulting claim revision. Committed records preserve their evidence cutoffs and consumed slice identities. Balance reconciliation identifies which actual occurrences and corrections its checkpoint includes. These assumptions concern authority, identity and commit integrity. The transition rules impose the quantity guards.

Six legal predicates remain external. L1, consent, governs agreement formation, scope, capacity, party binding, separability and survival under the named applicable law. A relying participant’s intake status supplies no binding predicate. L2, arbitral process, governs notice, appointment, jurisdiction inquiries, merits competence, equal treatment, the opportunity to present a case and qualifying awards. L3 governs forum-specific recognition and review. L4 governs coercive actionability, including property, priority, insolvency, immunity and procedure. L5 governs custody-mandate applicability, release authority, operative holds and each mandate’s conditions. L6 governs settlements, joint instructions, claim adjustments and the authority for reallocating consumed credit. A competent tribunal, court, custodian or other named authority supplies each determination for its exact parties, claims, route and time. The paper proves no legal predicate.

9.7 Trace integrity

The main theorem checks the distinctions required by the seller’s dispute. An award needs its own procedural ancestors. Execution and release need their own authorities. Recovery needs a distinct, supported payment quantity. Later review changes current permissions without manufacturing or erasing cash. L3 also supplies the recognition lifecycle and competent review sources. Each concrete route establishes whether its source set covers all relevant events. Freshness and completeness retain the meaning certified by those sources. Authentication alone establishes neither legal coverage nor factual completeness.

Theorem 9.2 (Bitemporal authority and effect integrity).

Assume F1 to F5. Let S_t(d, L) = \mathrm{Fold}_t(L). For every log L, every view time t, and every choice of the values of the legal predicates, that is, whatever verdicts the attestations and carried determinations in L hold:

  1. Every accepted award in H_t has accepted consent, commencement and tribunal ancestors for d and is signed by the natural persons of that tribunal.

  2. Every accepted coercive execution links an accepted award, an accepted basis in its forum covering its relief item, and the executing authority’s own determination of actionability at the execution’s event time.

  3. Every accepted custody release links its mandate, its asset, an accepted basis and the custodian’s own determination of release eligibility at the release’s event time. A mandate-condition release links an accepted custody mandate and verified action condition. An escrow-profile release satisfies the mandatory-trustee guard and its committed custody predecessor.

  4. Voluntary compliance can support an economic effect and creates no recognition, actionability or release value in C_t.

  5. Each recovery summand uses uniquely identified occurrence slices and a committed consumed attribution. Across all disputes, unassigned, reserved, disputed consumed and attributed consumed slices partition the admitted quantity. Consumed slices never return to unused capacity. Reassignment preserves their identities and requires authorised adjustments to every affected claim. Current substantiated attributions sum to at most the supported occurrence quantity. Unsupported historical credits remain explicit deficits. Repeated evidence creates neither occurrence quantity nor allocation capacity. Every collected summand has the appropriate account-posting evidence, legal-finality evidence and a complete applicable policy certificate at cutoff c\leq\min(h,t). Every window in its exhaustive set has closed by c. An empty window list passes only with that certificate. Actual debits and corrections preserve history while updating current recovery and funding through their distinct rules. A receivable supplies no funded capacity.

  6. Extending the log only with valid review entries that have fresh event identities removes nothing from H_t or E_t, preserves every origin reference, and can change C_t.

  7. Extending the log only with valid legal-attestation or source-checkpoint entries that have fresh event identities preserves E_t and every origin reference. Legal attestations can revise H_t through the named historical predicate resolver. Lifecycle and source evidence can revise C_t through their named predicates, intervals, prefixes and coverage states. They create no economic occurrence or allocation capacity.

The fold is deterministic: S_t is a function of the entries observed by t. Under L1 to L6 the accepted objects are what their names say.

Proof. The historical derivation terminates. For each log cut and view time, F1 fixes authentication and key status before evaluating dependencies. The root-of-trust construction calls neither validation function. Predicate resolvers likewise remain fixed during that derivation. Canonicalisation separates assertion conflicts from committed occurrence history. The historical accepted set grows monotonically and is bounded by finite Q_t^H. Its passes therefore reach a least fixed point. Committed claim adjustments enter through the subsequent journal validation with their recorded authority and evidence cutoff.

The occurrence pass is finite. It admits cash reports before resolving their claimed relationships. Accepted relationship edges point to earlier occurrences, so their matching calculation terminates. F3 fixes their order and unmatched quantities. Failure of a relationship leaves the cash report intact.

F5 fixes each finite committed journal prefix. A transaction binds its predecessors, affected slices and claim revisions. A repeated transaction is idempotent. An atomic adjustment has one outcome across all its named claims. Its historical guard uses the recorded evidence cutoff. Each current projection then applies an identified correction or balance checkpoint once. These operations determine the historical journal, current support, attributed deficits and funding state.

Finally, the current calculation resolves a finite legal state and evidence state for each predicate. Scoped intervals, authenticated source prefixes and the fixed profile determine the result. Missing conditions, stale evidence, source gaps and unresolved conflicts have explicit cases. The corresponding C_t value and obstructions are total and deterministic. The complete fold is therefore a function of the observed entries and committed checkpoints.

Induct over accepted historical entries. The empty state satisfies clauses 1 to 4. An inquiry adds its own jurisdictional record and creates no merits authority. A commencement requires accepted agreement, applicability and notice. A merits tribunal requires that commencement. An award requires that tribunal and its required signatures. This proves clause 1. Coercive execution and custody release each store the exact basis, route, asset, time and competent determination required by their guards. This proves clauses 2 and 3. A custody mandate enters through its separate applicability guard. Its certificate proves a condition and enters no award set. The custody transition checks the escrow guard and predecessor where that profile applies. Suspense supplies no recipient credit. Voluntary compliance adds its historical act without creating recognition, actionability or release authority. This proves clause 4.

For clause 5, F5 identifies each nominated recipient-credit occurrence independently of legal origin. Its assertion history and repeated wrappers supply evidence, not additional quantity. Each newly established attribution slice has one identity. Initially every admitted slice is unassigned. Reserve, consume and release move existing slices between disjoint sets and preserve their total. A consume atomically applies its claim transition. A consumed slice cannot pass the release guard. Reassignment moves that same consumed slice and adjusts both affected claim states in one authorised transaction. It preserves the total and its consumption history. Induction over committed journal transitions proves the partition and prevents allocation to one claim followed by silent reuse for another.

Intersection with the supported slice set gives \sum_{d,o}|S_e(d,o)\cap \mathcal{V}_t(e)|\leq |\mathcal{V}_t(e)|. A correction changes that support set through its identified rule. It preserves consumed identities and reports the unsupported difference. Alias reconciliation maps overlapping histories to canonical slices and places competing consumptions in X_e. It preserves the active partition and every historical claim deficit. Resolving X_e requires an authorised claim adjustment and never issues another slice. Neither operation invents cash or releases consumed capacity.

The collection constructor requires all three evidence classes and \mathsf{KnownComplete} at the supported cutoff. Its guards require c\leq\min(h,t) and closure of every applicable window by c. Thus future closure cannot establish collection at an earlier view. Missing metadata cannot satisfy the constructor. An empty set of windows succeeds only through an authenticated completeness certificate. Wrong scope, conflicting policies and insufficient freshness fail their respective guards. F4 gives the asserted completeness its stated meaning under the provider assumptions.

Current funding uses its separate reconciled account state. New cash reservations fit free backing and consume once. Attribution of an earlier payment does not debit that account again. A real reversal remains its own debit occurrence, including any excess over a claimed reference. A correction changes the supported projection and reconciled balance once, even when a later statement already contains it. Historical payments and claim transitions remain recorded. Receivables never enter the funded balance. These facts establish the remaining parts of clause 5.

For clause 6, the new review entries have fresh identities, so identity canonicalisation preserves every prior canonical entry. A review adds its own historical entry and can change C_t. It does not change a historical predicate resolver, delete an award, a release, an execution, a voluntary act or an effect, or alter an origin reference. A compromise can change \mathrm{valid}_L only when the model computes a later view from the raw log; it is outside this review-only extension. The stated preservation follows.

For clause 7, fresh identities preserve earlier canonical entries. Legal attestations affect only the historical predicate instances they name. Lifecycle and checkpoint metadata supply no independent historical legal determination. Their current effects follow the fixed interval, source and coverage calculations. None enters the economic scan or attribution journal. Effects, origin references and allocation capacity remain unchanged. Economic evidence wrappers belong to their separate occurrence rules.

No step used the truth of any predicate. Each guard read a value from the log and stored it, so the clauses hold for every assignment of values. Under L1 to L6 each stored value is correct, so each accepted object is what its name says. ◻

Corollary 9.3 (Award is not recovery).

An accepted award gives no positive lower bound on \mathrm{Gross}_t(u) or \mathrm{Net}_t(u) in any unit.

Proof. A valid log can stop after the award. It can also continue with a refusal, a stay, immune property, an insolvency, a failed execution, or no located property. None of these adds a receipt effect, and a receipt that is not collected is not in E_t^{\mathrm{col}}(u). ◻

Corollary 9.4 (Review non-erasure).

If a coercive execution occurred while the forum’s determination of actionability held, a later stay can make current actionability false without making the historical execution false.

Proof. Clause 6 applied to an extension consisting of the stay. ◻

Corollary 9.5 (A record determination is not an award).

An object that is not signed by the natural persons of an accepted tribunal for d never enters the award set. In particular a Tier 0 determination, a case-service output, a machine result and a later countersignature by an officer do not.

Proof. Only the award transition writes the award set. Its guard requires a link to an accepted tribunal and the signatures of that tribunal’s natural persons. \mathrm{QualifyingAward} is the residual and can only narrow the set further. ◻

The result is a trace-integrity theorem. It does not compel recognition or collection, and it does not prove that an authenticated source reported the world truthfully beyond F1 to F5. What it removes is the possibility that a status reader is told that one stage occurred because another did.

9.8 Boundary cases

The monetary totals below use the collection and attribution conditions of section 9.4. A completed debit can reduce current backing before it qualifies for a collected net-recovery total.

No agreement.

A notice is filed and administered and no agreement of the parties is in the log. No commencement enters. Case administration cannot create consent.

Recognition without actionability.

Forum F recognises the award and execution immunity protects the identified asset. In the current state, \begin{aligned} C_t(\mathrm{RecognizedAt}(A,F,i,t;t)) &= \mathsf{true},\\ C_t(\mathrm{ActionableAt}(A,F,a,i,t;t)) &= \mathsf{false}. \end{aligned}

Different forums.

F_1 recognises and F_2 refuses. One scalar recognition status would be false reporting. The route-indexed state records both.

Partial recognition.

F recognises relief item i_1 and refuses i_2. A levy for i_2 in F has no basis and enters O_t.

Later stay.

A custodian releases while its mandate permits and a court later stays further action. The release and its receipt remain. Current release eligibility can become false.

Voluntary payment.

The debtor pays after the award without court process. The ledger records a voluntary origin and a receipt. It does not invent recognition or coercive execution.

Unrelated payment.

The debtor pays a separate invoice between the same parties. Its occurrence remains in the cash ledger. Its allocation does not belong to dispute d, so it does not increase that dispute’s recovery.

Payment under an invalid award.

A collected credit of 100 names an award later held invalid. Its cash occurrence remains. An authorised attribution of 60 to that matter records 60 of recovery with the award defect, while 40 remains unallocated. An unrelated invoice cannot consume those same 60 slices. A claim discharge or restitution duty requires its own competent determination.

Partial receipts and reversal.

Two receipts of 40,000 attributed to d give \mathrm{Gross}_t=80{,}000. A completed return of 20,000 attributed to the same dispute gives \mathrm{Net}_t=60{,}000. Repeated evidence counts that debit once. An actual debit of 50,000 remains a debit of 50,000 even if its reference names only a 40,000 receipt. Its matched part is 40,000. The excess remains an explicit discrepancy or receives its own authorised allocation.

Consumed allocation.

A receipt of 100 discharges claim A. Deleting its allocation row cannot make the same 100 available for claim B. Reassignment requires one authorised adjustment of both claims and preserves the original consumption identity.

Spent before observation.

The recipient spends a valid receipt before its evidence reaches the dispute record. The later evidence can still establish payment of the original claim. Current free cash does not govern attribution of that earlier receipt.

Corrected quantity.

An authority corrects a reported 100 credit to 80. The original report and committed claim transitions remain in history. Current substantiated attribution is at most 80, and the affected 20 appears as an attributed-credit deficit. Reconciliation applies the adjustment once, including when a newer balance statement already reflects it.

A fee refunded.

The provider refunds its 100 fee. The refund’s sign is the negative of the fee’s sign, so \mathrm{Net}_t returns to 80,000 and \mathrm{Gross}_t is unchanged.

Ad hoc case.

The claimant serves notice directly under the rules and no institution administers the case. Authenticated notice evidence can satisfy \mathrm{ProperNotice}.

Award on agreed terms.

The parties settle during valid proceedings and the tribunal records the settlement as an award. \mathrm{QualifyingAward} can accept it without pretending that unresolved merits remained.

Non-party custodian.

An award orders a bank to transfer funds. The bank accepted no custody mandate and no court order applies. Neither a release nor an execution has a basis.

Pre-award attachment.

A court attaches property on the tribunal’s interim measure before the award (Model Law Articles 17 and 17H). The attachment is an accepted interim measure, and a later execution cites it as its basis together with the award.

Set-off.

The parties’ cross-claims are set off and the obligation is discharged. No receipt effect exists. The discharge is a satisfaction determination and the recovery vector is unchanged, which is the correct report.

Duplicate receipt evidence.

A provider callback and an account statement describe the same recipient-credit occurrence under authenticated correspondence evidence. Both remain evidence. The ledger counts the effect once.

Credit inside a reversal window.

Usable credit of 60,000 remains available while an applicable window is open. Collection requires complete policy evidence and closure at the supported cutoff.

Unknown windows.

Recipient credit and legal-finality evidence arrive without a complete route-policy certificate. An empty metadata list remains unknown. An authenticated complete policy that specifies no windows can support collection at its stated cutoff.

Late evidence and replay.

A provider’s late statement establishes a credit that occurred before the recorded award. Its occurrence and attribution can change the current report. Re-evaluating the report sends no payment. A resulting repayment duty requires an independently admitted command with its own funding and authority.

Relying nonparty.

A relying watcher submits evidence without an agreement or other binding basis for arbitration. Intake records the submission. A merits proceeding requires its own affirmative party-binding and scope determinations. A disputed jurisdictional basis can enter the separate competent inquiry route.

9.9 The three routes after an award, and immunity

After an award, each route keeps its own authority. Voluntary compliance needs the debtor’s instruction, mode-appropriate evidence, the entitled recipient’s confirmation and a separate satisfaction determination, and it needs no recognition order. Contractual custody action needs a valid prior mandate covering the instruction, the property, the owner, the conditions, expiry, revocation, stays and third-party rights, and a custodian that never accepted that role is not bound by an award. Court execution needs recognition where the forum requires it, enforceable court authority, available property, local procedure, priority, exemptions, and provider evidence of each named event through recipient credit. Article III of the Convention sends enforcement through each state’s procedure, Article IV identifies the material supplied to the court, Article V states the refusal grounds, Article VI permits adjournment and security during a setting-aside application, and Article VII preserves more favourable rights. None makes collection automatic.

Immunity splits in two. An arbitration agreement can remove adjudicative immunity for arbitration-related proceedings under a forum’s statute. In the United States that result follows from the arbitration exception in 28 U.S.C. § 1605(a)(6), not necessarily from waiver. In the United Kingdom section 9 of the State Immunity Act 1978 removes immunity for proceedings relating to an arbitration the state accepted in writing, subject to the agreement’s terms. Execution remains separate. In the United States, 28 U.S.C. § 1610(a)(6) permits execution against property used for commercial activity when its other conditions hold. In the United Kingdom, section 13(4) permits process against property in commercial use or intended for commercial use. Central-bank and other protected property can remain immune: 28 U.S.C. § 1611(b)(1) and sections 13(3) and 14(4) of the 1978 Act state the forum-specific rules. Articles 17 to 19 and 21 of the United Nations Convention on Jurisdictional Immunities of States and Their Property (2004) likewise separate adjudication from measures against property. Any required consent to execution is therefore negotiated for the relevant participant, forum and asset class. The instrument answers that question before default. The ICSID Convention supplies a distinct route when Article 25 is satisfied: a legal dispute arising directly out of an investment, written consent, a contracting state or designated subdivision or agency, and a national of another contracting state. Article 54 requires each contracting state to recognise an award and enforce its pecuniary obligations as if it were a final domestic judgment. Article 55 preserves the forum’s law of execution immunity. Whether a deployment or corridor obligation falls within Article 25 depends on the parties, consent and investment facts; its label does not decide the question.

Recovery measurements.

Each measurement names the dispute, route, recipient, unit, cohort and start event t_0. The start can be default, filing, award or command admission. Comparisons use the same start definition. For each receipt, t_a is the event time of usable recipient credit. Its collected time t_c is the earliest supported cutoff at which every collection premise in section 9.4 holds. Time to available value is t_a-t_0. Time to collected recovery is t_c-t_0. Provider confirmation, destination-bank arrival and legal finality retain their separate timestamps. The observation time of each witness records when the reporting system learned that event.

For a recovery target q in unit u, report the first supported time at which attributed available receipts reach q. Report the corresponding collected threshold separately. A later reversal or correction retains those historical crossing times and reports the current shortfall. An unmet target is an outstanding observation at the named cutoff, with its unpaid quantity. It receives no artificial completion time. Route reports show gross receipts, fees, taxes, actual returns, net collected recovery, unsupported attribution and legally outstanding obligations separately. A non-cash satisfaction changes the last field through its own authority.

The cohort includes every admitted matter, including refusals, stays, abandoned claims, unknown finality and partial receipts. Reports state coverage, unresolved counts and observation cutoffs beside completion rates and time distributions. They separate nominal amounts from any conversion policy. A comparison with another procedure uses matching claim classes, asset access, jurisdictions and start events. These definitions support a prospective study with an existing institution. Measured effectiveness requires its case records, provider evidence and the stated comparison. The definitions alone supply no recovery-rate estimate.

10 The institution

A dispute can remain unresolved even when the rules are clear: no qualified arbitrator may be available, or case administration may lose its funding. This section specifies an institution capable of carrying the procedure. A neutral is an independent professional appointed to adjudicate. The design requires available neutrals, lawyers who understand the procedure, reasoned outcomes and administrative staff. Its requirements are conditions for operation, not evidence that a particular centre satisfies them. Software carries the records. The relevant instruments and people supply authority and judgment.

10.1 What exists before intake

A centre accepts no matter until eleven decisions are made and sourced. The legal host: the entity, its registry, form, capacity, governing instrument, controlling body and effective interval. Public-law status: each licence, approval, registration or exemption with its issuer, conditions, expiry and dated official source.

The rules: the adopted rules, version, commencement date and amendment process. Administration: filing review, notice, timetable support, records, fees and communications. Appointments: nomination, confirmation, challenge, replacement and removal authority, each of which derives from the arbitration agreement, the incorporated rules or applicable law and never from the centre’s own instrument.

Independence: disclosure, recusal, challenge and complaints procedures. Records: confidentiality, privilege, access, retention, deletion, legal hold and publication authority. Money: each payer, recipient, beneficial owner, fee basis, refund rule, tax treatment and authorised holder.

Service contracts: governing law, forum, claims procedure, liability, indemnity and insurance. The court interface: interim relief, supervisory review, set-aside, recognition, stays and execution. Leadership: accountable officers, protected roles, committees, succession, audit and removal.

The centre administers only the functions a valid arbitration agreement, its governing instrument, applicable law and the incorporated rules confer. The tribunal decides its own jurisdiction under applicable law, subject to the competent court (Model Law Article 16). Rules bind through party agreement or a statutory mechanism, and a centre’s unilateral adoption binds no one.

10.2 Demand, and the queue

An independent new venue must attract parties who can instead choose established arbitral institutions. A venue named in the corridor instrument receives the disputes that arise under that instrument. Because the forum is fixed at accession, cases can arrive before the panel has enough capacity. The resulting risk is delay. The centre therefore publishes a fixed award deadline for the expedited tier and a quarterly breach rate that identifies every matter that exceeded it and the reason.

10.3 Supply: four classes and three forms

The seller, the tribunal and the registrar need different professional services. Their engagement terms must preserve the distinction between representing a party, deciding the dispute and administering the procedure. The supply side has four classes with different controls. Neutral adjudication: arbitrators and emergency arbitrators, under independent appointment, conflicts rules, due process and outcome-neutral fees. The centre cannot buy an outcome or promise an appointment. Institutional operations: case managers, the registrar’s staff, translators, trainers and governance reviewers, engaged by the centre under defined scope, review and protected decision roles. Party services: counsel, experts and enforcement providers, engaged by each party directly or under a lawful segregated arrangement. The centre may present eligible providers on a published rule and receives no share of their fees, no referral fee and no origination fee. Bounded public work: research and data tasks with public inputs, mechanical acceptance and duplicate control, which contain no confidential fact and no matter-specific advice.

Three contract forms supply the work. A continuing service contract reserves availability for case management, registrar support, panel administration, training or translation. Protected work uses the funded terms in section 10.4. The contract fixes remuneration, capacity, service level, term and funded replacement coverage. A fixed-fee engagement buys a defined public work product, such as a citation check, public-source index or data extract. A controlled bounty offers a fixed prize for a non-duplicate result that satisfies an objective test. Its inputs are public and acceptance is mechanical. The offer states the prize, review cost, expected pay and any guaranteed stipend. Substantive legal judgment remains with its designated professional role. Public piecework creates no appointment right or additional protected remuneration.

Eligibility comes before price. A practitioner is eligible only after the engagement record confirms the client, role, governing professional rules, admission and supervision, conflicts clearance, repeat-appointment disclosure, privilege holder, insurance, sanctions controls, data and security requirements, fee structure, worker classification, and applicable tax, immigration, procurement and competition-law limits. An unresolved eligibility condition cannot reserve protected work. The centre publishes the qualification schedule, unit prices and payment register. Membership contracts prohibit collective fee setting, wage fixing, no-poach agreements and competitively sensitive exchange between centres.

The contract forms select different people, and the fee must reflect each person’s alternatives. A fee below the relevant market rate attracts only practitioners whose alternatives pay less. A higher fee can reserve capacity that would not accept a conventional retainer. The machine tiers generate recurring, narrowly defined tasks: assemble and independently check a record extract, verify an evidence bundle against its proofs, witness a conformance rerun, re-execute a determination’s query, or certify a translation. Each artefact is admitted on the proofs it carries. A published fraction is re-executed blind by a second worker, and the centre publishes the disagreement rate.

The bounty layer supplies public research and mechanical verification under independent admission. Its work creates no authority to decide, appoint, resolve a challenge or alter a matter’s material record. No bounty worker sits on a tribunal in a matter whose record that worker touched. A person exceeding a published share of the centre’s bounty spend in a year is ineligible for appointment for the two years that follow. A challenger reward drawn from a forfeited bond has a separate instrument and budget. The same person cannot review a bounty result and claim the related reward. A reviewer whose acceptance can influence a matter receives the funded-term remuneration in section 10.4.

Published, reasoned awards reduce the cost and uncertainty of later cases. Publication is a term of the rules the parties accept at accession, with a named redaction standard and a stated opt-out. Article 34(5) of the UNCITRAL Rules permits publication with the consent of all parties or where a legal duty or proceeding requires disclosure. The centre records consent before it publishes an award under the consent route.

10.4 Funded protected remuneration

A fee schedule can avoid rewarding a particular winner and still reward additional hearings or appeals. The stronger requirement below fixes the protected person’s remuneration for the term before assignment. Let O contain the prevailing party, award amount, recognition, execution, satisfaction and recovery of a matter. Protected roles comprise every person who decides, appoints, reviews a challenge, administers a matter or controls its material records. They include the relevant executives and developers. A public-work supplier enters this class when its role acquires such authority or access.

A protected person’s remuneration includes fees, salary, bonuses, benefits and payments through related persons. Covered economic interests include beneficial rights in the centre, a party or a provider whose income depends on the matter. A person with such an interest cannot occupy an incompatible protected role. The compatibility test in section 10.5 applies before appointment and after a material relationship change. Commercial ownership remains possible outside those protected functions.

A published hourly or event rate has a limited invariance. With the rate, hours, procedural events and assignments fixed, changing a disposition leaves the scheduled charge unchanged. An outcome can change those other inputs. A rate of 100 gives fees of 1,000 and 2,000 for ten and twenty hours. Additional appeals can increase event fees. Protected work therefore uses a stronger contract.

Funded terms.

Before assignment, a closed compensation plan fixes each protected person’s total remuneration, payment dates, service capacity and term. It includes every related payment and benefit. The institution reserves the full cash obligation under a separate payment mandate. The mandate binds the person, term, currency and amount. Hours, appeals, case counts, assignments and dispositions cannot amend that entitlement or create another contract for the same person and term. Documented reimbursement of an actual third-party cost remains a separate pass-through and creates no retained gain.

The plan also reserves independently staffed continuity capacity. Additional hours use that capacity without increasing the deciding person’s remuneration. Each successor has its own funded term and conflict clearance. The successor receives fixed remuneration even when that capacity remains unused. Excess demand creates a recorded funding and continuity obligation. It cannot cancel an existing matter or review route. New intake uses available capacity under the service commitment. A later term requires its own prospective plan and disclosures.

Assignment and review.

Qualified candidates enter a fixed ordering under a committed allocation rule. The rule uses the named role, availability, competence, conflict evidence and committed selection seed. Dispositions, party victory, recovery, referral rewards and preferred answers supply no ranking input. The authorised appointing process remains responsible for appointment. A reasoned override identifies its authority and conflict evidence. It creates no additional remuneration. Challenges and appeals use separately cleared decision roles. Records preserve allocation inputs, overrides, workload, payment instructions, beneficial interests and repeat appointments for independent examination.

Proposition 10.1 (Protected remuneration under a funded term).

Fix the compensation plan, valid funding reservations, covered persons, calendar and applicable contractual authority before assignment. Consider two admissible traces under that plan. Outcomes, hours, appeals, assignment counts and workload may differ. Each protected person’s total remuneration entitlement and permitted compensation instructions are identical in the two traces. Actual receipt has the same conclusion when corresponding instructions complete under the same provider-execution and finality assumptions.

Proof. For each covered person i and term k, the plan fixes an amount F_{ik} and payment schedule. The payment mandate authorises only those scheduled amounts, whose sum is F_{ik}. None of the varying trace coordinates can change the plan, add a contract or authorise a top-up. A successor’s independently reserved term has the same property. Summing over the fixed plan preserves equality. Equal authorised instructions give equal realised payments under the execution assumptions. Execution failures remain separate facts under section 9.4. ◻

The proposition concerns funded contractual remuneration. Workload can still change effort and delay. Commercial surplus can change with demand and cost. Future employment and reputation can also create incentives. Independent ownership, appointment and payment records make those channels testable. Their actual effects require observed data and a stated causal design. The proposition supplies no empirical conclusion about impartiality.

10.5 Independence controls

A party challenging the network’s record must not depend on the network operator to choose its reviewer. Fixed remuneration alone does not resolve that conflict. Appointment, challenge and record-control powers also require separation. Accession Networks carries the ratified precedent and the general result: the Cape Town registry’s three roles held by three bodies, the operator holding no authority over what the register means, and the certifier’s liability carried by a separate entity. Recourse applies that separation to adjudication.

The members of the appointments and challenges body pass the same control-group test as arbitrators. The test identifies persons connected through actual control, as defined below. No payment buys eligibility. The body acts only through an authorised route, which applicable law, the arbitration agreement or the incorporated rules designate (Model Law Articles 11 and 13). Its members serve fixed terms and removal requires stated cause. A person cannot decide a challenge to that person’s own conduct or interest. A control-group result is evidence for the authorised process and cannot by itself appoint, remove or invalidate an arbitrator.

The conflict record is a dated, sourced typed graph. Its vertices include the centre, host, controllers, financiers, providers and persons under consideration. An actual-control edge records ownership control, appointment or removal power, financing control or contractual control. Each edge retains its direction, source, effective interval and applicable threshold. Control groups are connected components of the undirected graph formed from actual-control edges. This conservative conflict test retains the direction of each underlying right.

Direct financial interests, professional ties and material family or household relationships have separate conflict types. The compatibility matrix applies them without inferring transitive control. Routine service edges have a third type. A routine service alone does not join control groups. One pair can carry both a routine service and an independently supported control edge. Excluding the former preserves the latter. The centre and host remain vertices in every projection.

A named record custodian maintains source evidence. A reviewer independent of the affected groups resolves disputed classifications through the authorised process. Service administrators cannot delete or reclassify control evidence. Every classification names its source, responsible person, date and reasons. The assessment affirmatively covers relevant ownership chains, appointment rights, financing conditions and direct relationships. Absence of an edge supplies no clearance. Missing evidence blocks the affected pairing and creates no inferred transitive control edge.

The compatibility matrix classifies each protected-role pair as permitted, permitted with disclosure and recusal, or forbidden. It uses control-group membership, direct conflicts and unresolved pairwise obstructions. The authorised appointment or challenge process applies the result under section 10.1.

A centre administers and never decides. A tribunal consists of natural persons. No software, no ensemble of software and no automated process is a member of a tribunal or may be described as one. No appointment right over arbitrators, panellists or the centre’s executive passes to a private originator of the rules, whatever else that originator is granted: authorship credit, an honorary founding role, a seat on the panel at published rates. Published fee rates and fixed engagement charges use no prevailing-party input. Procedural volume and the centre’s commercial surplus remain separate variables. No payment, subsidy or benefit goes to any adviser, referrer or party representative for centre selection, and a demand-side subsidy takes the form of a published fee reduction to parties. Centre-interest legal opinions name the centre as client, use protected commissioning and review, and never touch jurisdiction, merits, appointments, challenges or awards.

10.6 Centre economics and earned expansion

Funding a new centre can consume cash that an existing matter still needs. The proposed expansion rule first protects those obligations, then limits expansion to cash earned and collected by the centre. Here collected has the exact meaning in section 9.4. The receipt requires usable recipient credit, legal-finality evidence and a complete applicable policy certificate at its supported cutoff. Every applicable window must have closed by that cutoff. A usable credit inside a return, recall or chargeback window is available and remains outside collected income. The centre attributes only its own earned receipts to this schedule. Client money, collateral, restricted funds, pass-through amounts, service advances and property held for others retain their separate ownership and accounting classifications.

The following accounting model uses its own period-indexed balances. Fix an entity, a currency and accounting periods t = 1, 2, \ldots. Let R(t) be the collected operating receipts from earned services in period t and P(t) every operating cash payment in t, fixed and variable, whose debit reached legal finality. The operating cash contribution is \mathrm{OCC}(t) = R(t) - P(t), signed. Let X_{\mathrm{in}}(t) be every external receipt: initial capital, grants, debt, equity, investing and other non-operating receipts, together with restrictions released and exchange-translation effects. Non-operating uses (expansion allocations, owner distributions, investing payments, financing repayments, transfers) are attributed by a pre-adopted order: a use draws the external balance only where the raising instrument of specific external capital restricts its proceeds to that use and that capital remains unspent, and every other use draws the earned balance. Write U_e(t) and U_x(t) for the two parts. The two balances are B(t) = B(t-1) + \mathrm{OCC}(t) - U_e(t), \qquad X(t) = X(t-1) + X_{\mathrm{in}}(t) - U_x(t), with B(0) = X(0) = 0, so that B(t) + X(t) is the closing cash represented by the two balances. The protected exposure union \mathrm{PE}(t) collects commitments that cash must cover before expansion. It contains unpaid due obligations, active-case commitments, working-capital needs, required reserves and, at full amount, every credit still inside a provider reversal window. Documented coverage and valid netting reduce it. Valid netting names its legal basis, a contractual set-off right, a statutory netting rule or the rules of a settlement institution, and that basis must remain enforceable in the counterparty’s insolvency under the relevant legal order. Netting without a named enforceable basis reduces nothing. Expansion-eligible liquidity is \mathrm{EL}(t) = \max(0,\, B(t) + X(t) - \mathrm{PE}(t)). The lawfully deployable amount D(t) applies solvency, capital-maintenance, fiduciary, regulatory-reserve, covenant, tax and exchange rules and the required approvals. The earned-expansion budget is E(t) = \max\bigl(0,\ \min(B(t),\ \mathrm{EL}(t),\ D(t))\bigr). It is the maximum amount the stated cash constraints permit. It does not confer spending authority.

A binding cap can absorb a deficit without changing the permitted budget. Let B=100, X=500, \mathrm{PE}=20 and D=10. Then \mathrm{EL}=580 and E=10. An additional deficit of 20 gives B=80 and \mathrm{EL}=560, while E remains 10. The earned balance records the full deficit. The deployable cap already limits expansion to 10.

Proposition 10.2 (Earned-cash provenance).

For every period t:

  1. B(t) = \sum_{s \le t} \mathrm{OCC}(s) - \sum_{s \le t} U_e(s). No external receipt enters the earned balance.

  2. E(t) \le \max\bigl(0, \sum_{s \le t} \mathrm{OCC}(s) - \sum_{s \le t} U_e(s)\bigr). The budget for a further centre never exceeds cumulative operating cash contribution net of earlier earned uses.

  3. Fix all other flows and the later values of X, \mathrm{PE} and D. An additional operating deficit \delta>0 in period s lowers B(t) by \delta for each t\geq s. Write E_\delta(t) for the resulting budget. Then 0\leq E(t)-E_\delta(t)\leq\delta. Another binding constraint can make both budgets equal.

  4. Each non-operating use reduces exactly one balance.

Proof. Clause 1 is induction on t from the recurrence, whose only inflow is \mathrm{OCC}. Clause 2 follows from clause 1 and E(t) \le \max(0, B(t)). For clause 3, changing only \mathrm{OCC}(s) by -\delta subtracts \delta from each later earned balance. At fixed X, \mathrm{PE} and D, the budget is a nondecreasing, 1-Lipschitz function of B. Maximum and minimum preserve these properties. A binding cap or zero floor can give equality. Clause 4 is the attribution order, which assigns each use to U_e or to U_x and to neither twice. ◻

A worked number shows why both constraints are needed. The stated budgets assume that the other caps permit them: D(1)\geq2{,}000, \mathrm{EL}(3)\geq3{,}000 and D(3)\geq3{,}000. These are assumptions of the numerical example, not findings of available legal or financial capacity. Initial capital of 500,000 arrives in period 1 and enters X. In period 1 one matter’s administration fee of 9,000 is collected, reserved case-management capacity costs 2,500, variable shared services cost 500 and fixed operating payments are 4,000. Then \mathrm{OCC}(1) = 9{,}000 - 7{,}000 = 2{,}000 and B(1) = 2{,}000. Closing cash is 502,000, the protected exposure union is 150,000, and \mathrm{EL}(1) = 352{,}000. The budget is E(1) = 2{,}000: the next centre may draw two thousand of earned cash because the rest is external capital. In period 2 receipts are 3,000 against payments of 7,000, so \mathrm{OCC}(2) = -4{,}000, B(2) = -2{,}000 and E(2) = 0. In period 3 a contribution of 5,000 gives B(3) = 3{,}000 and E(3) = 3{,}000, not 5,000. A zero floor would omit the earlier deficit. Treating a distribution as debt-funded would misclassify external capital as earned cash.

Centre and owner surplus can respond to matter volume and workload. Beneficial interests remain segregated from incompatible protected functions. Published concentration, assignment overrides, workload and payment records support independent evaluation of these channels. They establish neither constant commercial profit nor causal impartiality.

10.7 Wind-down and continuity

A centre’s states are operating, intake suspended, cure review, wind-down, emergency wind-down, transfer pending, case-administration-only, insolvency, closure review and closed. No wind-down state returns to operation. Authority loss, a protected-money breach, missing protected-money data, a required-reserve breach, protected-role unavailability and a centre-caused due-process failure override every other response and cause immediate intake suspension or emergency wind-down. Each open state names the responsible authority, effective time, funding source, missing-evidence branch and escalation authority. The operating response below is conditional on an externally specified demand test and a separate test called conversion in the operating policy. That policy must supply the conversion test’s subject, criterion and measurement. The term has no established meaning here and does not refer to the currency conversion rule in section 9.4. This paper supplies no numerical threshold for either operating test. One measured demand or conversion failure permits one changed design. A second failure starts wind-down, and a change of label does not reset the count.

Every active matter has a continuity record naming its agreement, rules, seat, tribunal, administrator, transfer authority, required consent, deadlines, records, deposits and successor. Authority loss cannot transfer or terminate a matter by itself. A party’s insolvency reaches the matter under the law that governs it (Regulation (EU) 2015/848 Article 18, Insolvency Act 1986 section 130(2), 11 U.S.C. § 362), and a host’s officeholder can disclaim the network’s continuity and shared-service contracts (Insolvency Act 1986 section 178, 11 U.S.C. § 365), so the continuity record binds no officeholder and the successor schedule names a route that needs none.

Closure requires that every matter is complete or validly transferred, and that every obligation for services, remedies, payments, refunds and clawbacks is satisfied, preserved, transferred or lawfully provided for. Every provider instruction must be released or must have reached legal finality under the provider’s recorded rule, with recipient-credit evidence where the provider is not the recipient’s own institution. An instruction can instead transfer with a funded reserve. Protected money and property must be returned or transferred and reconciled. Records, privilege and legal holds must have an authorised successor. Required notices, refunds, final audit and independent sign-off must be complete. Closure never depends on a provider reversal window that remains with the closed centre. Protected money is never a wind-down reserve.

Consent to arbitrate names an institution and its rules (Model Law Article 7, Convention Article II), so a clause executed before a centre’s removal from the network and never invoked is exposed to an argument that it is inoperative or incapable of being performed (Article II(3), Model Law Article 8(1)). The parties therefore consent to an irrevocable licence of the rules version in force at clause execution for every clause registered before removal, and to a published successor-administrator designation.

10.7.1 The continuing computation

A suspended program can retain duties after its administrator stops taking cases. Its next input may be an authority’s answer, a provider’s delayed outcome or an observation that fixes a future payment. Closing the case list does not settle these computations. The successor must receive their state and the means to continue them, together with the rights and resources on which they depend.

Partial payment during wind-down.

Consider a duty of 125 units with 40 units credited. An original command can still deliver 85 units, backed by a reservation of 85. The beneficiary’s outstanding right is 85. The successor receives that right, the original command and its reservation. It cannot issue another command for 85. Reuse the capacity model of section 9.5. Let D be the outstanding amount, P completed performance awaiting attribution, and u_j each live command’s possible additional performance. New exposure is bounded by \max\!\left(0,D-P-\sum_j u_j\right). The bounds use a common allocation model. Overlapping bounds cannot be treated as independent available capacity.

A late credit of 60 under the old command reduces the outstanding right to 25. Its remaining exposure and reservation are 25. Once authoritative evidence closes that command at its actual credited amount, a new authorised instruction may address the residual 25. Closure of the old command discharges no unpaid portion. Revocation of new-payment authority can block that instruction while leaving the successor able to receive evidence and preserve the beneficiary’s claim.

The same problem applies to a computation that is waiting for its next authorised reply. Its continuation is the remaining computation together with the state needed to resume it. Transferring only the unpaid amount would lose the pending work, just as transferring only the debt would lose the old payment command.

The economic identity follows Admissible Obligation Transitions. A duty is identified by the issuer’s authoritative namespace, its constituting act and its occurrence index. A family name, template, rules version or administrator is not part of that identity. The canonical journal J records each duty’s typed portions, beneficiary, debtor, asset, unit, condition, priority and disposition. It retains its economic amendments and original command bindings. A change of representation preserves this journal. A change of rights requires its own authorised act.

The journal distinguishes a reservation of duty portions from a reservation of cash. The former prevents two instructions from satisfying the same portion. The latter secures a command’s possible expenditure. Succession preserves both under their original identities. An administrator cannot replace a funded hold with a promise to fund one later, or count property held for a client as its own continuity reserve. A physical occurrence also retains its identity across successors. Changing its asserted credit, debit or legal role cannot create a second occurrence. Distinct causal legs require distinct occurrence evidence.

A successor needs a complete account of work and resources at the handover point. The cut below collects that account from every relevant source. Its namespaces distinguish the authorities that issue case, command, obligation and payment identities. Completeness is required from each source, including messages sent but not yet delivered.

Definition 10.3 (Complete continuation cut).

A continuation cut is a tuple C=(\mathcal N,V,M,J,R,O,G,E). Here \mathcal N is the authoritative registry of relevant namespaces. V gives an authenticated complete prefix in each namespace. M contains the live machine records and their stable identities. J is the canonical economic journal. R records funded resources, their owners, restrictions and reservations. O records undelivered messages and their stable delivery identities. G records the authority required for each future action. E retains evidence, disclosure duties and the receiving route for subsequent notices.

Each machine record binds its program and decoder, environment, store, pending request, continuation, completed effects and resource counters. It binds outstanding duties, command identities, reservations, authority conditions and recovery routes. Every emitted cross-namespace effect is either present at its destination or retained in O with its destination and exact payload. A received message retains its deduplication identity.

The registry covers case administration, prepared distributed decisions, external commands, claim evaluators, economic duties, deposits, future contribution rights and retained disclosure duties. Each source authority establishes its scope and completeness. An empty local list supplies no completeness evidence. A source gap or an omitted namespace remains an obstruction to closure.

In particular, a completed claim evaluation can precede delivery of the duty it creates. Complete evaluator and duty-ledger prefixes can therefore coexist with an in-flight duty-creation message. The outbox retains that obligation until the destination acknowledges the same identity. Succession neither discards the message nor regenerates it under a new identity.

The executable records.

The companion formalisms describe different parts of the retained computation. Lex describes programs that can await authorised replies. Op describes external commands and their outcomes. The Claim as Primitive describes evaluated claim instances. For Lex, the record includes the checked program identity, typed state, exact request and its continuation. Historical verified acts remain evidence. Current authority is checked when the continuation next uses it. For Op, the cut includes the original command and request digests, inbox, consumption epoch and cursor, occurrence and allocation journals, pending return links and cash reservations. For The Claim as Primitive, it includes the authenticated checkpoint, program and context binding, instance revision, journal heads, cached results, work counters, entitlement ledger and recorded command outcomes. Copying an output value omits this state.

A receiving runtime needs a decoder relation that preserves these meanings. For a stored state s, write D(\mathrm{enc}(s))\simeq s when decoding preserves the state and its possible next steps. The relation includes prior effects and pending requests, not merely the eventual return value. An opaque host-language closure requires retained runtime custody or a justified portable representation. A request description and a printed call stack do not reconstruct its executable continuation.

An owned representation of the next step.

A program can use one reply to determine what it asks next. In a dependent type, an earlier value can also determine a later value’s required shape. The dependent value and computation fragment of Lex admits a direct representation of this pending work. A function value contains its checked body and captured environment. A pending computation contains its control term, environment and continuation frames. A frame records the operation that follows the current return. These objects are finite data. Function application restores the captured environment and binds the argument. A dependent binding retains its expected type until the preceding computation returns. Thus a reply supplying n can determine the type \operatorname{Vec}(n) of a later request without restarting the program. Here \operatorname{Vec}(n) requires a vector containing exactly n entries.

Definition 10.4 (Durable local continuation).

For this fragment, a suspended state has the form S=(p,\delta,\iota,o,b,c,\eta,K,H,\tau,q). The exact program is p. The source and dependency profile is \delta. The instance identity \iota binds its host, immutable name and creation nonce. The next unused request ordinal is o, and b is remaining logical work. The checked control term is c, its captured environment is \eta, and K is the frame stack. Historical signed replies form H. Their admitted effects form \tau. The current request is q.

The constructor encoding represents each scalar, vector, pair, captured function and continuation frame by its corresponding finite data constructor. The preceding tuple identifies the suspended state whose fields those constructors encode. Encoding stores references to checked terms and complete values, environments and frames. Decoding rechecks p under \delta and resolves every reference in that checked program. A captured function recovers its original body and environment. A vector value retains its exact length and elements. Decoding checks dependent value shapes, reconstructs q, and verifies the complete consumed-ordinal history. Each committed suspension passes the receiving decoder’s bounds and exact round-trip check. Historical signatures use their retained verification keys. Current admission is a separate input to the next authority use.

The durable host authenticates the instance key, creation identity, program profile, revision, complete state and command receipts. A separate current-state commitment binds every instance head and the authority metadata. Every mutation updates its record and this commitment in one transaction. Restoring an older valid row against the current commitment fails. The same check rejects an older authority record. Source reconstruction checks structural correspondence. Authentication establishes that the decoded state came from the admitted execution history under the host’s storage assumptions. In particular, decoding arbitrary well-shaped data does not establish that the program reached that state.

Each command identity binds one complete operation and payload. The host reads its recorded receipt before invoking the runtime. An exact retry returns that result, including after later commands have committed. The returned historical result names its committed revision. It does not replace the current state. A changed payload requires another command identity.

For a new reply, the host checks the exact request, issuer, contract and scope. It serialises the current authority revision with reply consumption and the resulting state commit. A revoked authority cannot answer a pending request through its earlier admission. The original request and continuation remain available for an applicable future authority decision. An invalid signature, value, scope or effect preserves the pending computation and its logical work counter. A valid signed suspension retains its evidence and allocates a fresh ordinal.

Proposition 10.5 (Durable continuation correspondence).

Use the displayed constructor encoding and its fixed deterministic checker with unambiguous term references. Assume authenticated records, atomic durable commits and one serialised authority and consumption domain. Restoring an admitted suspended state preserves its next runtime step, dependent request, prior effects and remaining logical work. A reply command commits at most one continuation advance. Its exact replay returns the committed result. Current authority governs each new consumption, while historical acts retain their original evidence.

Proof. Rechecking the exact source fixes each checked term and binder. Induction on the finite value representation recovers every scalar, vector, pair and captured function. Induction on the frame stack recovers each pending binding and stopping action. The reconstructed request has the same instance, ordinal, program, environment, expected type and effect row. The runtime therefore starts from the same control and environment with the same stack and logical work. Its next step has the same premises and result. Historical signature checks preserve the retained acts and their complete effect sequence.

Consider the transaction that handles a command. A prior receipt selects the recorded result before execution. Otherwise the host reads current authority, consumes the reply and commits the new state with its receipt in one serial order. A crash before commit preserves the earlier state and receipt set. A crash after commit preserves both the advanced state and its receipt. These two cases exhaust the atomic storage outcomes. A retry therefore cannot consume the following request. Serialisation also orders every authority change before or after consumption. Each accepted reply uses the authority revision at that position. ◻

The reference construction uses the actual checked syntax, owned environments and frame machine of this fragment. Its storage adapter restores those objects directly. It admits dependent replies, higher-order captured functions, signed suspension, refusal and typed sanctions evidence. Failed-command receipts remain separate from consumed replies. The construction supplies the local decoder and persistence obligations used by a continuation cut. Cross-institution carriage additionally requires the complete namespace cut, resource equality and execution fences below.

The complete current-state commitment and its referenced records can still be restored together to an earlier authenticated state. Excluding that restoration requires a monotonic anchor outside its rollback domain, or an equivalent storage premise. Such an anchor retains the latest committed revision in a record that the same restoration cannot replace. A logical work counter bounds admitted execution. Physical work lost before an aborted commit requires its own operational budget. These two obligations are distinct from process-crash recovery.

10.7.2 Transferring custody of unfinished work

Restoring a computation locally leaves a further question at institutional transfer: which custodian may take its next step? Both institutions could hold valid copies. The transfer must give one successor the execution role while retaining old commands that may still complete. The following conditions express that handover. The generation identifies which custodian currently holds the execution role. A fence rejects new work from an earlier generation.

Definition 10.6 (Authorised continuation carriage).

A carriage transfers a complete cut C from a predecessor to one successor under the following conditions.

  1. The predecessor fences new work at an identified execution generation. Existing external commands retain their original identities and possible effects. Observation and reconciliation continue.

  2. The successor receives C, establishes its decoder relation and accepts custody under current authority for every required namespace. Its custody and funding evidence covers each retained resource and duty.

  3. A final compare-and-swap checks the current source revisions and the exact cut. Every admitted delta during preparation is carried before this step. One durable ownership transition activates the successor and makes the predecessor unable to start new work.

  4. Every subsequent action checks the successor’s current execution generation and its own action-specific authority. A reserved local decision remains with its competent authority. Receiving custody grants no additional execution permission.

The ownership transition changes the custodian and execution generation. It changes none of J, the economic resource and reservation entries of R, the pending messages of O, or the retained execution evidence. A replay returns the recorded transfer result without running a continuation or submitting an instruction.

The ownership condition requires an effective execution boundary. A single serialised coordination domain can implement it with a current generation and an atomic state transition. Independently governed domains require an agreement and protocol that make the relevant fences effective. A local generation change cannot recall a message already sent to a provider. Such commands remain observable, reserved and routed to the successor until their recorded contract resolves the remaining exposure.

Proposition 10.7 (Continuation and resource conservation).

Suppose C is complete, the source and decoder relations are sound, and the authority and execution-boundary conditions of Definition 10.6 hold. An authorised carriage preserves every recorded outstanding right, reservation, pending external effect and undelivered obligation. It has one active execution custodian. It admits no new authority, economic discharge or external instruction merely by transfer or replay. Every source continuation step whose current guard and environmental premises also hold at the successor remains available there.

Proof. Completeness assigns each live source object to a record in M or to an undelivered obligation in O. Decoder soundness preserves its pending state, prior effects and possible next steps. Equality of J preserves each typed duty portion and its disposition. Equality of the economic resource entries preserves cash, ownership, encumbrances and original reservations. Stable command and occurrence identities preserve the domain to which delayed evidence applies. Equality of O preserves each message until its original delivery identity is acknowledged.

The final revision check includes every admitted delta before the ownership transition. Atomicity selects one successor at that generation. The execution fence prevents a predecessor from starting another action. A previously sent command remains in the retained exposure, so its later completion is an observation of that command. It does not require a second dispatch. The current-use guard is checked separately and cannot be strengthened by custody. Transfer and replay emit no external instruction and change no duty disposition.

For the final assertion, take an available source step with the stated common guard and environmental premises. The decoder relation supplies the corresponding successor step from the retained state. Its prior trace and obligations are unchanged. Thus carriage preserves this useful step as well as the conservation properties. Existence of a future authority decision or provider response is a separate environmental premise. ◻

What the successor must preserve.

Omitting the original command preserves a visible debt but loses its still-executable exposure. Omitting the cash hold preserves the instruction but removes its funding. Copying the predecessor’s permission preserves a historical decision but grants an unauthorised current action. The cut, resource equality and current-use guard exclude these errors separately. An unavailable continuation decoder leaves the machine under an identified continuing custodian or an explicit obstruction. It does not become a completed case.

Institutional completion.

The construction permits closure of the predecessor’s administrative role when the successor validly carries the continuing obligations. The economic duties and machine states remain live at that successor. Actual custody transfer, protected-money treatment, institutional powers, provider fencing and insolvency effect require their identified legal and operational evidence. The proposition proves the stated carriage invariant relative to those premises. It does not turn a complete digital archive into an agreement, funded account or valid transfer of authority.

10.8 Seat, venue, and what a jurisdiction gains

The seat of an arbitration is its juridical place: the legal system whose arbitration law supervises the proceedings and whose courts hear applications to set the award aside. It is chosen by the parties or determined under the rules (Model Law Article 20(1)), and the Model Law supplies the supervisory framework most seats implement. The seat is not the place where hearings are held, and it is not the place where the administering institution keeps its offices. A centre established in one territory routinely administers arbitrations seated in another.

The protocol requires a Convention seat, a seat in a territory to which the Convention applies, because an award seated outside the Convention loses the recognition route in every enforcing state that made the reciprocity reservation of Article I(3). Many parties listed on the UNCITRAL status table have made that reservation. The commercial reservation is the second reason the clause recites that the relationship is commercial. The Convention’s territorial application is not uniform. Several territories with sophisticated commercial law sit outside it because no extension was notified on their behalf. Where a territory sits outside, the remedy is a notification under Article X(2) by the state responsible for that territory’s international relations, after which the Convention applies from the ninetieth day after receipt, or from the Convention’s entry into force for that state, whichever is later. Effective enforcement also requires domestic law that gives the Convention effect in the territory. Article X(3) asks each responsible state to consider extension, subject where constitutional arrangements require it to the consent of the territory’s own government. Where a party wants proceedings connected to such a territory, the protocol seats the arbitration in a Convention territory and designates the centre as administrator.

Two treaty configurations therefore need their own dated sources before a centre opens. The first is a seat in a territory with no extension on the United Nations treaty record: on that record it is not Convention territory until an Article X(2) notification takes effect. The second is a receiving state that declared the reciprocity reservation: its courts have no Convention route for an award made at the first seat until the extension is effective, while a receiving state without the reservation may apply the Convention to that award under Article I and its own forum law, and another domestic or treaty route may also apply. Local centre authority, the juridical seat, the domestic arbitration law and the Convention’s application are four separate facts, each with its own dated source.

The seat is chosen outside the control of either party to the dispute, so a corridor between two participating jurisdictions is seated in a third. What a jurisdiction gains from hosting a seat is distinct from what the network gains. A seat attracts counsel, experts, hearing services and the professional formation of a panel. It also builds standing as disputes are decided under its supervisory law. A chartered centre can be closed by the state that chartered it. Dubai Decree No. 34 of 2021 abolished the DIFC Arbitration Institute and the Emirates Maritime Arbitration Centre and directed their caseloads to a successor administering different rules. A private arrangement made six months later allowed the London Court of International Arbitration to continue administering every matter commenced on or before 20 March 2022 under the rules the parties had chosen. A corridor instrument must therefore name a fallback appointing authority and a fallback rule set, and preserve the chosen rules for every matter commenced before closure. These measures provide capacity and continuity. Standing follows only from decided cases in which the instrument was used and tested. The founding panel indicates the intended quality of that future record but cannot replace it.

11 The boundary of the protocol

Judicial power stays with courts. The protocol confers none. The courts of the seat retain their supervisory jurisdiction: their powers to constitute or replace tribunals, to hear challenges, and to set awards aside on the grounds their law provides. The protocol fixes which law the tribunal applies and what weight the record carries as evidence. The substantive law of each dispute stays with that law. An arbitral award is the product of a tribunal of natural persons. An adopted software determination is a contractual instrument within its adopted scope. An advisory extract remains evidence. The protocol reaches private obligations. Criminal law, the internal law of any jurisdiction, the recognition decisions of any competent authority, and any question the applicable law reserves to a court stay where they are.

A sanctions designation is never a Recourse matter. How Compliance Composes provides that one jurisdiction never accepts another jurisdiction’s sanctions clearance without an explicit shared-authority instrument. Lex requires every sanctions block to identify the asserting authority, the list and version matched, the as-of date and the procedure and forum for challenge under the asserting jurisdiction’s own rules. That contest route is the sovereign’s own. The private consequences of a block on a corridor obligation, including who bears a fee or a loss, may be a Recourse matter.

Three functions stay separate inside the protocol, and the separation is of authority, not of brands. Administration runs record resolution and arbitration under adopted rules and creates no authority. The record and its custody, conflict, stay and recovery controls preserve provenance and evidence, and a competent actor determines legal effect. Transmission carries authenticated records, awards, stays and custody instructions between authorised actors after an action-specific authority check, and law, contract, tribunals, courts, custodians and providers supply the effect. A protocol message does not create consent. A registry does not appoint itself as tribunal. A signed award does not prove cash recovery. A custodian instruction does not replace local enforcement law.

The claims layer interacts with Recourse at three points. A claim’s context carries its governing dispute clause, and a resolved claim instance is corrected only by a follow-on claim, never by a rewrite (The Claim as Primitive). The lifecycle interface under which claims default, dispute and recover is Admissible Obligation Transitions, and the dispute and recovery legs of that interface run under this paper’s forum. An oracle’s own adjudicator resolves settlement inside its protocol. A party contesting a settled outcome outside the protocol proceeds here, and the non-adversarial correction of an attestation is the issuer’s supersession at a new index with a Tier 0 determination supplying the record extract (Event-Collect BFT). Op defines the provider-instruction states that report movements of value and the finality policy under which a provider’s report becomes an external fact.

12 Prior art

Online dispute resolution.

eBay’s own dispute system, described by its director of online dispute resolution in 2010, handled more than 60 million disputes a year, 90 per cent of them resolved entirely by software, against more than 250 million registered users (Rule 2010). The figures are the operator’s own, and the largest tier is an automated problem-diagnosis step rather than an adjudication, so they indicate scale rather than a measured resolution rate. The indication is still the warrant for a machine tier: at consumer scale, most disputes are not arguable, and the ones that are can be identified cheaply. Katsh and Rifkin (2001) are the literature, and the UNCITRAL Technical Notes on Online Dispute Resolution (2016) supply the case-service role the registrar plays here. The public-sector counterpart fared differently. The European Union’s ODR platform, launched in February 2016, was closed in July 2025 under Regulation (EU) 2024/3228 after nine years in which traders had to carry a link to it and no obligation to answer a complaint made through it. Two to three million visitors a year produced on the order of two hundred resolved cases a year across the Union. The contrast identifies the condition rather than the technology. A machine tier works where the operator already holds the record and already controls the remedy, and fails where participation is optional.

On-chain adjudication.

Kleros (Lesaege, Ast and George 2019), Aragon Court and Augur (Peterson and others 2015) resolve disputes by incentivised voting among token-holding jurors, and their decisions bind what the protocol controls and nothing else. Where the contract executes the ruling, award, execution and receipt collapse into one transaction, and that is a custody release under a pre-agreed mandate, the \mathrm{Custody}(c, a) route of this paper, and not an award under Article I of the Convention or Articles 11, 12 and 31 of the Model Law. Ortolani (2016) draws the same conclusion from multisignature escrow. Where the parties made no written agreement between named parties, Article II is not met and Article IV(1)(b) cannot be complied with. Where they did, whether an award rendered by persons who cannot be identified is an award turns on the parties’ agreement and the seat’s law, and the resisting party may raise Article V(1)(a) and V(1)(d). Either way the decision cannot bind banks, custodians, creditors, regulators or any third party outside the protocol. The UK Jurisdiction Taskforce’s Digital Dispute Resolution Rules (2021) are the closest published instrument to awards that execute: an arbitrator may implement the decision directly on a digital asset, and the arbitration agreement may be made by digital signature. Their tribunal may itself operate the asset, so tribunal and custodian coincide, a case this paper keeps apart.

Institutional arbitration.

The International Chamber of Commerce reported 841 new cases in 2024 against 1,789 pending, an average amount in dispute of US$130 million for new cases against a median near US$5 million, and its administrative expenses are capped under Appendix III of its 2026 rules at US$180,000. The difference between the average and median shows that a small number of high-value matters materially affects the distribution. The Hong Kong International Arbitration Centre and the London Court of International Arbitration publish comparable caseload and cost schedules. The UNCITRAL Expedited Arbitration Rules (2021) and the expedited procedure of the ICC Rules (2021, Article 30 and Appendix VI) are the ancestors of Tier 1. Those institutions serve disputes that justify conventional arbitral procedure and cost. A network can also generate many low-value, record-decidable matters. The three tiers provide procedures for both groups.

Regional centre networks and treaty routes.

The Asian-African Legal Consultative Organization’s Integrated Scheme (1978) created a network of locally hosted arbitration centres under host-country agreements, from Kuala Lumpur (1978) and Cairo (1979) to Lagos (1989), Tehran (1997), Nairobi (2006) and Hong Kong (2021), and the Permanent Court of Arbitration concludes host-country agreements under which it administers proceedings on the host’s territory. Both show that a centre’s authority is local and hosted, which is section 10.1. ICSID Articles 53 to 55 are the treaty form of the sentence that an award is not recovery: enforcement as a final judgment with no Article V review, and execution immunity preserved. The state-immunity statutes cited in section 9.9 draw the adjudication and execution lines the model indexes by route.

Registries and standard-setting bodies.

The three-role separation of the Cape Town registry, the supervisory-body bargain in which fee-setting and open-data obligations pass upward in exchange for authority, and the liability line the standard-setting cases draw, on which the courts divide with control as the usual pivot, are carried in Accession Networks. This paper applies them to a venue.

Bitemporal records.

Event time, observation time and view time are the valid time, transaction time and query time of the temporal-database literature (Snodgrass and Ahn 1985, Jensen and Snodgrass 1999), standardised as system-versioned tables in SQL:2011 (Kulkarni and Michels 2012). Typed events, append-only logs and guarded transitions are established systems technique. This paper does not claim to invent them. Its formal contribution is the scoped product and the invariants that prevent event-time arbitral authority, current route-specific legal predicates and unit-indexed economic effects from being conflated.

Professional markets.

Rochet and Tirole (2003) and Armstrong (2006) supply the comparators for cross-side effects, price structure and multihoming in the two-sided market of section 10.3. Dezalay and Garth (1996) describe how the transnational arbitration bar and its institutions formed, which is the supply side this paper designs for. The IBA Guidelines on Conflicts of Interest (2024) are the disclosure standard the control-group rule sharpens.

What this paper adds.

Three things. A routing test that separates the provable from the arguable, with integrity dominance and a determination that is never an award, kept inside Article V by an unconditional escalation right. A bitemporal, predicate-indexed status fold whose seven invariants hold for every choice of the legal predicates, with an explicit rule that a later legal effect enters only as a new event. And a venue design that separates funded protected remuneration from outcomes, retains actual control in its conflict record, and bounds expansion by earned cash. The financial results state their fixed inputs and follow from the specified contracts and recurrences.

13 What is proved, what is assumed, what is open

Theorems.

Proposition 5.1 establishes termination under the admitted query profile and resource limits. A Known result also requires the snapshot and evidence checks. Proposition 9.1 separates evidence evaluation from provider dispatch. Theorem 9.2, Corollary 9.3, Corollary 9.4 and Corollary 9.5 are paper proofs under F1 to F5. Proposition 8.1 follows from the route and effect separations in section 8 and section 9.4. Proposition 10.1 and Proposition 10.2 follow from the contracts and recurrences in section 10.4 and section 10.6. Proposition 10.5 gives local continuation correspondence under its encoding, authority and storage premises. Proposition 10.7 gives continuation and resource conservation under its stated source, decoder and custody premises. No result is machine-checked.

Open problems and hypotheses.

Deterrence is not proved. The reliance-demotion mechanism increases the cost of equivocation, but no payoff model here establishes deterrence. Other open questions are execution against sovereign assets beyond commercial property; arbitrability and public policy under Article V(2); certifier liability for economic loss; named-forum instantiation of the route predicates; canonical encodings and provider evidence; key-compromise timing and correction; comparison of arbitration with security, guarantees, set-off, judgments and settlement without double-counting; and the queue that can form before sufficient panel capacity exists. Four participation claims remain hypotheses: verified capacity may increase centre selection; observable matters may increase reserved practitioner capacity; paid assignments may retain capacity within the independence limits; and a stated fee change may move participation by a stated threshold. No universal critical-mass number follows.

14 Recovery and continued performance

The seller’s award determines an obligation of 80,000. The two payment routes in the example produce gross receipts of 80,000 and net recovery of 79,900. The later stay changes further execution authority. These statements can all remain true together because each rests on its own act and evidence.

Recourse carries that distinction through the dispute. A private obligation created in one jurisdiction and carried through others has a forum fixed by the parties’ agreement. Record-decidable questions use a bounded procedure with unconditional tribunal access. Contested record integrity goes to a tribunal. A qualifying award has a recognition route under the Convention. Economic security still requires an authorised person able to forfeit the property. A qualifying deterministic release condition can move pre-funded property under an escrow or independent demand guarantee. Contested forfeiture and unfunded obligations require adjudication. Collection depends on available property, current route authority and recipient-side evidence.

An administrator’s closure creates the same need for exact accounting. A successor receives the outstanding right, the pending computation and the original payment reservations. It can continue a supported next step when its current authority and environmental premises hold. Transfer itself discharges no debt and sends no payment. The formal results preserve these distinctions. Actual agreements, professional independence, custody, provider performance and measured recovery remain obligations of the institutions using the protocol.

References

  • Armstrong, M. (2006). “Competition in Two-Sided Markets.” The RAND Journal of Economics 37(3), 668–691.

  • Asian-African Legal Consultative Organization. Integrated Scheme for the Settlement of Disputes in the Economic and Commercial Transactions (Doha, 1978), and the regional arbitration centres established under it.

  • Board of Governors of the Federal Reserve System. Fedwire Funds Service. Payment Systems web page, last updated 25 June 2024, accessed 2 September 2026. https://www.federalreserve.gov/paymentsystems/fedfunds_about.htm

  • Committee on Payment and Settlement Systems and Technical Committee of the International Organization of Securities Commissions (2012). Principles for Financial Market Infrastructures. Bank for International Settlements, April 2012, Principle 8 and the glossary definition of final settlement. https://www.bis.org/publications/principles-financial-market-infrastructures.pdf

  • Convention on the Recognition and Enforcement of Foreign Arbitral Awards. New York, 10 June 1958. Status table, United Nations Commission on International Trade Law, retrieved 31 August 2026.

  • Convention on the Recognition and Enforcement of Foreign Judgments in Civil and Commercial Matters. The Hague, 1 February 1971. Status table, Hague Conference on Private International Law.

  • Convention on the Recognition and Enforcement of Foreign Judgments in Civil or Commercial Matters. The Hague, 2 July 2019. Status table, Hague Conference on Private International Law.

  • Convention on the Settlement of Investment Disputes between States and Nationals of Other States. Washington, 18 March 1965, Articles 25, 53, 54 and 55.

  • Dezalay, Y. and Garth, B. G. (1996). Dealing in Virtue: International Commercial Arbitration and the Construction of a Transnational Legal Order. University of Chicago Press.

  • Du, W., Huang, C. and Scharfstein, D. (2026). Competing Rails for Cross-Border Payments: Banks, Fintechs, and Stablecoins. Harvard Business School working paper, 15 February 2026, sections 7.2 and 7.5.

  • Dubai Decree No. 34 of 2021 concerning the Dubai International Arbitration Centre.

  • Foreign Sovereign Immunities Act, 28 U.S.C. §§ 1605(a)(6), 1610(a)(6), 1611(b)(1).

  • Hong Kong International Arbitration Centre. Statistics, 2025.

  • Insolvency Act 1986 (UK), sections 127, 130(2) and 178. Regulation (EU) 2015/848 on insolvency proceedings, Article 18. 11 U.S.C. §§ 362(a) and 365.

  • International Bar Association (2024). Guidelines on Conflicts of Interest in International Arbitration.

  • International Chamber of Commerce. Arbitration Rules (2021), Article 30 and Appendix VI (Expedited Procedure Rules). Arbitration Rules in force 1 June 2026, Appendix III (Arbitration Costs and Fees).

  • International Chamber of Commerce. Dispute Resolution Statistics, 2024.

  • International Chamber of Commerce (2010). Uniform Rules for Demand Guarantees (URDG 758).

  • Jensen, C. S. and Snodgrass, R. T. (1999). “Temporal Data Management.” IEEE Transactions on Knowledge and Data Engineering 11(1), 36–44.

  • Jones v Sherwood Computer Services plc [1992] 1 WLR 277 (CA).

  • Katsh, E. and Rifkin, J. (2001). Online Dispute Resolution: Resolving Conflicts in Cyberspace. Jossey-Bass.

  • Kulkarni, K. and Michels, J.-E. (2012). “Temporal Features in SQL:2011.” SIGMOD Record 41(3), 34–43.

  • Lesaege, C., Ast, F. and George, W. (2019). Kleros: Short Paper v1.0.7.

  • London Court of International Arbitration. Schedule of Costs, 2023. Announcement of March 2022 on the administration of matters commenced under the DIFC-LCIA Arbitration Rules on or before 20 March 2022.

  • Ortolani, P. (2016). “Self-Enforcing Online Dispute Resolution: Lessons from Bitcoin.” Oxford Journal of Legal Studies 36(3), 595–629.

  • Permanent Court of Arbitration. Host country agreements, as published by the Court.

  • Peterson, J., Krug, J., Zoltu, M., Williams, A. K. and Alexander, S. (2015). Augur: A Decentralized Oracle and Prediction Market Platform. Aragon Association (2020). Aragon Court documentation.

  • Regulation (EU) No 1215/2012 of the European Parliament and of the Council on jurisdiction and the recognition and enforcement of judgments in civil and commercial matters (recast).

  • Regulation (EU) 2024/3228 of the European Parliament and of the Council, repealing Regulation (EU) No 524/2013 on online dispute resolution for consumer disputes.

  • Rochet, J.-C. and Tirole, J. (2003). “Platform Competition in Two-Sided Markets.” Journal of the European Economic Association 1(4), 990–1029.

  • Rodger v Comptoir d’Escompte de Paris (1871) LR 3 PC 465.

  • Rule, C. (2010). Using Technology to Manage High Volume Caseloads: The eBay/PayPal Experience. Administrative Conference of the United States, Washington DC, 1 November 2010.

  • Snodgrass, R. and Ahn, I. (1985). “A Taxonomy of Time in Databases.” Proceedings of the ACM SIGMOD International Conference on Management of Data, 236–246.

  • State Immunity Act 1978 (UK), sections 9, 13 and 14.

  • Swift (2024). Spotlight on Speed: Where to Focus for Faster International Payments. As reported in Du, Huang and Scharfstein (2026), section 7.2.

  • UK Jurisdiction Taskforce (2021). Digital Dispute Resolution Rules. LawtechUK.

  • UNCITRAL Arbitration Rules, 2010 revision with the 2013 and 2021 additions, Articles 3, 17(1), 34(2), 34(5) and 36.

  • UNCITRAL Expedited Arbitration Rules (2021).

  • UNCITRAL Model Law on International Commercial Arbitration, 1985, with amendments as adopted in 2006, Articles 7, 8, 9, 11, 13, 16, 17, 17H, 18, 19, 20, 24(1), 25, 26, 30, 31, 34, 35 and 36.

  • UNCITRAL Technical Notes on Online Dispute Resolution (2016), General Assembly resolution 71/138.

  • Uniform Commercial Code, Article 4A, section 4A-404: Obligation of Beneficiary’s Bank to Pay and Give Notice to Beneficiary. https://www.law.cornell.edu/ucc/4A/4A-404

  • United Nations Convention on Jurisdictional Immunities of States and Their Property (2004), Articles 17 to 19 and 21.

  • Veba Oil Supply & Trading GmbH v Petrotrade Inc [2001] EWCA Civ 1832.