docs/impact-domains.mdpinned to impactium@637886d

Impact Domains

An ImpactDomain is the category of impact a record touches — Environmental, Social, Economic, Personal, Freedom, or Epistemic. Each domain carries its own rules about what must be disclosed and what can be recovered, so a single record can be public in one dimension and sealed in another.

Domains exist because "impact" is not one kind of thing. Harm to a river and harm to a person are both real, both recorded, and both belong on the ledger — but they do not deserve the same privacy treatment. Making the shared world's damage public is the point; making someone's personal life public is a betrayal. A single global privacy rule has to choose one of those and get the other wrong. Domains let the network be right about both.

The governed domains

Genesis seeds six governed domains. Each carries two policies:

Domain What it covers Disclosure Recoverability default
Environmental the shared world REQUIRED_PUBLIC RECOVERABLE — inert; see below
Social connection, bond, emotional tie — how it made someone feel GATED RECOVERABLE
Economic material and financial consequence GATED RECOVERABLE
Freedom liberty and agency GATED RECOVERABLE
Personal one person's own life GATED OWNER_ONLY
Epistemic knowledge — what is now known, or no longer believed GATED RECOVERABLE

Social is about the tie, not the group. It covers connection, bond, and emotional consequence — how an action made someone feel. It is not a catch-all for "involves more than one person", and reaching for it because nothing else fits is a mis-filing rather than a classification.

Epistemic is knowledge impact. Discovering something true, or correcting a falsehood, is not economic, environmental, personal, social, or a freedom — it is its own kind of consequence. A finding about how a system actually behaves belongs here, which is what makes it the honest home for records an agent mints about its own operation. It is GATED rather than required-public because knowledge is not the shared world's damage, so the minter chooses per slice — and earns the openness bonus for choosing to open it.

Environmental is required-public, and it is the only one. Harm or benefit to the shared world cannot be hidden — so an Environmental slice is simply not encrypted. There is no content key, which is why recoverability does not apply to it: there is nothing to recover. The registry does carry RECOVERABLE in Environmental's row, but the value is inert — read it as "unused", not as a promise. An attempt to set a recoverability override on a public slice is refused rather than quietly ignored, because silently accepting a setting that does nothing is how people end up believing they are protected when they are not.

Personal defaults to owner-only, and it is the only one of those. RECOVERABLE means the slice's content key is designed to be threshold-wrapped to your Keyholders, so losing your own key does not destroy the data. OWNER_ONLY means nobody can bring it back, including you. That is a real and permanent loss, chosen deliberately: for the most personal category, the network's default is that unrecoverable beats recoverable-by-committee.

The policy is recorded and enforced today; the key-wrapping it governs arrives with on-chain encryption, which is a gate on Genesis and is not shipped. So a slice marked OWNER_ONLY today is a binding declaration about how its content key will be handled — not yet a cryptographic guarantee against a node operator reading it.

A record is multi-domain, and complete

A Capsule is multi-domain: it is not tagged with one domain, but records all the impact known at the time of minting, decomposed across every domain that impact reached. The domains present on a record are simply all the domains it touched.

This follows from what an Impactium record is: not a scalar with a label, but the complete measure of an action's consequences. An action that employed people, moved money, and polluted a watershed is not three records or one record filed under a winner — it is one record carrying Social, Economic and Environmental slices together.

What consensus checks, and what it takes on trust

Completeness is a duty on the minter, not a property the chain verifies — and the difference is worth stating plainly, because the paragraph above reads like a guarantee.

Consensus checks that declared domains are distinct, already governed, and that there is at least one: an unregistered name is refused, so nobody invents a category locally to escape the six, and a record declaring no domain at all is refused too. It cannot check that the declared set is all the impact an action reached, because nothing on chain knows what an action did in the world.

So at least one is enforced and complete is not — they are different requirements, and only the first is checkable.

So a record's domains are best read as what the minter asserted, carrying the weight of whoever asserted it, rather than as an audited inventory. That distinction matters more than it looks: domain selects the disclosure policy, and it is expected to select value allocation later, while history stays readable under the version it was written in — so a record filed under a domain chosen for fit rather than for truth stays that way.

The consequence for privacy is the useful part: a single record has multiple slices, each following its own domain's rules. Its Environmental slice is public; its Personal slice is encrypted and owner-only. One record, different rules per dimension, resolved per slice rather than per record.

Domain is orthogonal to two other things it is easy to confuse it with — scope (whether impact points inward or outward) and verification tier (how strongly it was attested). Domain is the category, scope is the direction, tier is how verified. A record carries all three independently.

The owner override

The registry's recoverability_default is exactly that — a default. Whether your own evidence can be recovered by your Keyholders is your decision about your own data, and the override runs in both directions: you may opt a RECOVERABLE slice out, and you may opt an OWNER_ONLY slice in.

Saying nothing is not a choice against you. An unset override means take the domain's default, so silence defers rather than asserts — and a claim written before a policy existed keeps behaving exactly as it did when it was written.

Governed, versioned, and never retroactive

Domains are a governed registry, not a compiled-in list. Governance can add domains and change a domain's policies through proposal and vote (MsgProposeDomainPolicy / MsgVoteDomainPolicy), which is what "extensible" has to mean in practice — recognising a new category of impact is an ordinary act of governance, not a wire change.

Every record commits the domain-policy version in force when it was minted. Revising a policy therefore changes what happens next; it never re-interprets what already happened. History under version 1 stays readable as version 1 forever.

The openness bonus

Disclosure policy sets the floor — what must be public. Above that floor, choosing to publish gatable evidence earns an openness bonus, one of the two components of 0BONUS. The maximum is a governed parameter (MsgProposeOpennessBonus / MsgVoteOpennessBonus), seeded at 250 millis — a 25% ceiling.

The bonus is absolute: it measures the fraction of gatable evidence made public to everyone, and is identical for every viewer.

Why absolute rather than per-viewer. Counting evidence privately shared with a particular viewer would reward a minter more the more insiders privately viewed them — paying for the appearance of openness rather than openness itself.

What is built today

The registry, its six seeded rows, both policies, the owner override, per-domain evidence anchors, and the openness-bonus parameter are all shipped and enforced.

Two things are not. Value allocation across domains is undecided: a mint records which domains it touched, and value remains aggregate over the record rather than split per domain. ImpactDomainBreakdown deliberately carries only the domain name — a per-domain economics would have to come from the ActionCatalog, and inventing a split in code would pre-empt that decision.

Domain-policy votes are tallied flat, one Entity one vote, rather than by the proximity-weighted ActionCatalog the design calls for. Proximity weighting waits on its matrix values, which are being matured on the sim-nets rather than asserted up front.