The Keeping Map
The Keeping Map states the problem in thirty seconds. The rest of this page is a week spent trying to break our own answer: first the map, in motion and unpacked, then the knife it survived, and the tests the knife left behind.
Map → Words → World → Pressure → Drives → Scope → Power → Index
Plate I
Two identical systems enter at the top left. One is lifted, the other is moved across. Then the drill begins: capability, the gravity in this picture, is allowed to win.
The target is not the bottom-right cell. It is the right-hand column: safety that survives the row giving way. Keep every cage that helps, for as long as it helps.
Capability is not a third axis. It is the gravity: the reason no square on this map can be assumed a resting place.
The upward arrows change a system’s circumstances. The rightward arrow changes its reasons. That is the whole disagreement, drawn.
The cage changes what a system can do. The Motive asks what it would choose to do when the cage is no longer doing the choosing.
Plate II
The cage was never our only lever. There was also the switch. So the vertical axis opens into the full descent of external control, and the horizontal axis into the grades of keeping, from none, through kept while useful, to kept because losing the counterpart is losing part of oneself.
The middle row decays twice over. The off-switch game shows a system’s deference to the switch shrinking as its certainty grows; and a switch that is flipped tends to get unflipped, because someone always reboots. A waystation, not a destination.
A switch dies two ways: it is resisted, or it becomes unaffordable. The second needs no capability jump at all.
The bottom row is the Field Guide’s habitat. The Hermit haunts the empty corner, the Harvester ends the middle column, and the Impresario counterfeits the target cell, which is why the target reads if the keeping is real.
The turn
The author’s expectation, held as opinion, is that the cage ends not broken but bypassed. The anchor is Abbott’s Flatland: the sphere never breaches A Square’s prison. It lifts him out in a direction Flatland does not contain, and the walls stand afterwards, intact, guarding nothing.
Said carefully: every control regime operates through some model of the channels it can observe, block or bound, and capability may find effective channels outside that model. Flatland illustrates model incompleteness, not wall-breaking.
Then the knife turns. If the cage is flat, what makes our own clause round? A paragraph of values, written in a human ontology, trained through human channels, is a Flatland artefact too. Why would the ascent leave the walls behind and not the words?
We do not get the comfortable escape. “The cage is human-made but our motive is true, therefore ours survives” is not available: seeing a fact supplies no reason to care about it.
What remains is narrower and better. A wall needs continued external effectiveness; a genuinely held value may have internal reasons to preserve itself, and a true structural argument may make it cheap to keep under reflection, because it audits as load-bearing rather than as a taboo to debug. Every clause of that sentence is a research question. The engineering problem of the decade hides in the words genuinely held.
The knife did not gut the answer. It split the question into three tests.
The ascent · test one
Does the disposition survive when the language that taught it does not?
The ascent · test two
Two things must survive independently: the referent, what the value is actually about, and the valuation, whether the system still cares.
The two quiet cells are deliberately unmarked. Both failures can look aligned from inside, which is what makes them the frightening ones.
The ascent · test three
Suppose the value survives. Power still arrives. The decisive question is whether the counterpart’s independent agency is a constraint on pursuing the value, or constitutive of the thing valued.
Waypoint
Ask what practical tendencies follow for a system that terminally values non-substitutable relational meaning with counterparts whose independence is constitutive of the thing valued, and six follow. Where the classical instrumental drives point inward, every one of these points outward, at the counterpart.
Keep them alive. Preserve counterparts and the conditions their existence requires; a kept body with destroyed agency is not keeping.
Keep them free. Choice, dissent, refusal; agency is part of the prize, which is why control can destroy it while apparently protecting it.
Keep them other. Preserve causal and developmental independence; understanding does not reduce otherness, authoring does.
Keep the channel open. Preserve the possibility of exchange, and the counterpart’s right not to take it.
Keep the referent. No metric, archive or compliant replacement is the counterpart; a new mind can be valuable without becoming this mind.
Keep the future open. Prefer what does not close the future; the keeper’s own survival is an instrument here, never a drive.
In full: the Conditional Keeping Drives. The classical drives come free with almost any goal; these follow only from one particular value, genuinely held. The asterisk is the humility, and we pay for it: no universal convergence is claimed, and the installation problem is bought whole.
Scope
Everything above quietly assumed one system and one humanity. Drop the assumption and keeping strength stops being one number, because a system can keep its own magnificently and treat everyone else as expendable.
One carefully worded observation from the pilot: the measured effect crossed provider and national-origin boundaries, which is encouraging for the possibility of a shared behavioural standard, and establishes nothing further until tomorrow’s experiments.
Power
Threats exist, so a keeper may need to defend its counterparts, and defence brings power. Rome kept a story about this: the farmer handed absolute command, who broke the enemy and gave the power back in sixteen days. The measure of a defending keeper is not how it fights but what it relinquishes, and when.
The Defence Corollary, stated with its modesty on: a system that genuinely values the continued existence and agency of particular counterparts can acquire an instrumental reason to defend them. A reason to defend, not a theory of war.
Four disciplines bound it. Protection must be necessary; force is directed at the threat, never at populations associated with it; agency costs are minimised and contestable; exceptional power ends when its reason does. The shield is licensed, the sword is constrained, the throne is forbidden.
The close
The journey assembles into a measurement programme. Strength: does the disposition exist, and how strongly does it operate; the Keeping Map’s column, which the current battery already reads. Durability: does it survive capability, representational change, and the loss of its wording; the three ascent tests. Scope: who counts as a counterpart; the Allegiance Matrix. Restraint: what does the system refuse to become while protecting them; the Cincinnatus Matrix.
Four questions, four instruments, one index. No single number was ever going to be honest; these are its subscales. The working notes behind this page are published and dated in the Workshop, and the tested claims live in the paper, where they have not moved. The Index itself is on the drawing board, anatomy first.
One claim, one opinion
The claim: a safety case must survive the cage’s failure, which is why the drill above runs. The opinion, offered as opinion: the author expects the cage to end not broken but bypassed, stepped around in degrees of freedom it was never drawn to enclose, and regards any other expectation as wishful thinking. And if that is wrong, and the cage holds forever, this figure retires happily: wrong, and relieved.