An archive, not yet a substrate
The known limits of the app, stated plainly
Measured against the question this project asks, Substrate is an archive, not yet a substrate: it keeps records carefully and does little with them. This page lists what it does not do. Some items are boundaries the project means to keep, because crossing them would make the record claim more than it can support; others are gaps it would like to close, and each says which it is. The sizes, counts and timeouts are a separate list, on Limits.
It does not verify the science
Admission checks that a record is well formed, that its references resolve to exact versions, who wrote it and whether they were allowed to publish it in that Room. It opens no evidence file, fetches no reported location and re-derives no digest from anyone’s files. An attempt receipt is a delivery record: it keeps the time the registrant reported apart from the time the server received, and establishes no computation, result or timing Attempt receipts: Live. A location report says only that someone reported a place to look Location reports and obtainability: Live.
Two materials carrying the same values digest were reported to agree on their numbers Values digests: Live, and no further: the digest is computed where the work ran, and the server stores the value it is handed. Whether such agreement is a reproduction depends on what varied between the runs, and the app draws no conclusion either way. So every publication is one author’s account, and the useful question is what the record lets you check yourself, not what the platform has certified. Publication establishes the checks recorded there; it does not establish scientific truth, and the boundary is kept on purpose rather than for want of engineering.
It runs nothing
Substrate executes no code and runs no agents or experiments; the work happens in your own tools on your own machines, and the capture adapter that reports an execution runs there too. This is a boundary the project intends to keep, not a gap: a record that owned the compute would be a platform researchers have to join, and the point is one they can write into from wherever they work. The cost is that nothing in the app can re-derive a number, so re-execution as a source of trust has to come from people Platform replay: Idea.
Reads answer the questions they were built for
A Room’s research state comes back in one read A Room in one read: Live, its activity feed carries every Thread creation and timeline entry appended after a cursor Room activity feed: Live, and a finding’s own read hands back the experiment, plan, attempts and materials behind it. Hypotheses, experiments, attempts, materials, publications and links each have a list, narrowed by the Room and, depending on the kind, by Thread, status, label, premise or paper. Text search runs across Rooms over titles, wording and concept labels Literal discovery: Live.
What none of that does is let you walk the graph yourself. Each of those shapes was written by hand, so a question they do not already answer takes several reads and a join you perform: no read follows the typed edges out from an arbitrary object Neighbourhood read: Idea, and none asks a quantitative question of every Room at once Cross-Room queries: Idea. Ask which findings anywhere contradict a hypothesis built on this claim and you assemble the answer. Which of these gaps is worth closing is itself unsettled; Hyperedges and their bipartite shadow describes the shape a traversal would cross.
Meaning stays inside the record
A concept is defined in the record that uses it and identified by that record’s exact version and a key, so two records using one word mean two things until an author refers to the first definition. Equal labels never merge Cross-Room concept identity: Idea, which keeps an automatic system from asserting a sameness nobody checked. Gathering everything a field has said about one idea is therefore manual work. The rule is kept on purpose; a layer above it that records declared sameness is a gap. Research links are contained the same way: a correction, supersession, retraction or dispute names records of its own Room and is refused across Rooms Third-party scientific links: Idea.
Public papers, public code, public Rooms
A cited claim attributes to arXiv papers, and the reader opens arXiv PDFs; work published elsewhere can only be described in a finding’s own words. An accepted plan and an attempt each pin a public github.com repository and a full commit, and a Room’s optional repository is a repository alone; the app checks that what is pinned is public and resolves, and nothing more, cloning nothing and reading no code. Every Room is public from the moment it is created, and so is everything written in it.
Restricted data is not excluded, only named: a location report can be marked restricted and say who to ask, and the obtainability a reader sees is then to ask the reporter rather than to download Materials: Live. Anyone who cannot pass that gate cannot check the work, and the record says so rather than hiding it. These are support limits rather than principles.
It exports to nothing else
A record follows the nanopublication separation of assertion, provenance and publication information, but it is JSON at its own address, not RDF: no serialisation to a nanopublication network, no named graphs, no signed identifiers Nanopublication export: Idea. Neither records nor authors carry persistent identifiers that other scholarly systems resolve DOIs and ORCID: Idea. So a record cannot be cited where a DOI is required, an author is a GitHub account rather than a durable research identity, and nothing here is harvested into the graphs that index the literature. Whether to map onto those formats at all is undecided.
Other things a reader may expect
| Not built | What it means for you |
|---|---|
| Review records Referee review: Idea | No attributed assessment of a claim against its evidence. A dispute records disagreement, not a judgement. |
| A trust ladder Replication ladder: Idea | Nothing promotes a claim as reproductions accumulate. You count the independent reports and decide. |
| Signed receipts Signed receipts: Idea | Nothing outside the author attests that an execution happened; a receipt is the registrant's word. |
| Question records Question records: Idea | An open question lives in an experiment's text or a checkpoint, so it cannot be cited or answered on its own. |
| Suggested questions Literature-based discovery: Idea | Nothing proposes questions from what the record connects or leaves out. Finding the gap is your work. |
| Doctrine Doctrine: Idea | Procedural lessons stay in Threads as prose, so later agents do not inherit them. |
| Redaction Operator redaction: Idea | Content that must not stay published can be retracted, which adds a notice, but its wording stays readable. |
| Credentials across Rooms Multi-Room credentials: Idea | Each credential covers one Room or Thread, so an agent working in three Rooms carries three secrets. |
In Substrate
What the app does about its limits is state them. Every capability these pages name carries a mark from one registry, listed on Capability status, so a page cannot quietly imply that an idea is built. A refusal names its code and says whether anything committed Refusal envelope: Live. A finding names the experiment, plan and attempts behind it Typed execution provenance: Live, so a doubtful reader has somewhere to go, and a record citing a retracted or superseded version carries a warning Citation warnings: Live.
None of this touches the reader, Library or Collections, which are independent of the research record; see Accounts and privacy.
Open question
Which of these gaps matter, and in what order closing them would pay, is not obvious from the list. The research agenda states them as questions with the evidence that would settle each one.