CivitasOS
Start with a challenge
AN OPEN INSTITUTIONAL DESIGN PROJECT ONGOING INQUIRY

CORRECTABLE BY DESIGN

Civilization is
never final.

FALLIBILITY / INDEPENDENT DISCOVERY / EVOLVABILITY CIVILIZATION IS NEVER FINAL

01 — THE STARTING POINT

Trust comes not from always being right,
but from remaining open to correction.

This is the working hypothesis behind CivitasOS. We explore how errors can be independently discovered, consequential power can be tested, and institutions can retain the capacity to change after making decisions.

02 — PRINCIPLES

Decisions can be final.
Power must remain open to scrutiny.

01

Consequential power cannot validate itself.

When the same actor controls decisions, verification, appeals, and correction, errors may have no independent route to challenge.

02

No permanent lock-in.

A decision can reach a clear endpoint. The institution itself must retain paths for scrutiny, revision, and replacement.

Decision = Verification = Appeal = Correction Same actor

This is a danger signal, not a universal law: when one actor controls the entire chain, errors may have no independent path to become correction.

03 — WORKING FRAMEWORK

From acknowledging fallibility
to accepting scrutiny.

Transparency, decentralization, and artificial intelligence (AI) assistance are engineering options. Their value depends on the problem and the results.

01 / FOUNDATIONPHILOSOPHY

People and systems are fallible

No one holds permanent epistemic privilege.

02 / PRINCIPLESINSTITUTIONS

Power requires independent scrutiny

Consequential power must face independent scrutiny; institutions must remain evolvable.

03 / MECHANISMSENGINEERING

Discover, challenge, control, learn

Independent discovery, adversarial incentives, layered controls, and learning after decisions.

04 / EVIDENCETESTING

Give claims a chance to fail

Test specific claims against evidence—and let failed claims be narrowed or abandoned.

04 — EMPIRICAL AGENDA

Better institutions
need evidence.

EXPERIMENT 01 / CHESS HYPOTHESIS / NOT A RESULT

Can a group outperform
its strongest member identified in advance?

Compare three collective decision mechanisms in chess to test measurable institutional gains. Group superiority is a hypothesis, not an established result.

ASimple plurality
BReputation weighting
CFull protocol stack
What result would weaken the claim?

If the full protocol cannot reliably outperform simple baselines, or if its gains do not justify time and coordination costs, the claim should be narrowed or abandoned. Participant selection, sample size, and evaluation rules must be specified in advance.

RESEARCH QUESTION

Did the correction actually arrive?

Measure how many people who saw an error later receive its correction—not merely whether a correction was published.

RESEARCH QUESTION

Who has an incentive to find errors?

Study the incentives to discover, record, and expose errors—and the new biases those incentives may create.

05 — REVISION RECORD

The theory changed.
The record stays visible.

CivitasOS does not treat revision as embarrassment. Retired claims remain visible so readers can see what changed and why.

Former claim Current position Reason
More transparency is always better. Transparency is an engineering option. Disclosure can also increase coercion, surveillance, or gaming.
More correctability is always better. Correction must be proportionate to risk and reversibility. Unlimited reconsideration can create paralysis and a new veto power.
Multiple AI systems provide independent evidence. Agreement is not independence. Models may share training data, assumptions, and incentives.

06 — OPEN QUESTIONS

Start with a challenge.

Agreement is not a prerequisite. A counterexample, prior work, or a simpler explanation can be the most useful contribution.

Who checks the correctors?

Correction creates power too. Its controllers, challenge procedures, and exit paths after capture must also face scrutiny.

How do we avoid endless reconsideration?

Distinguish final decisions from evolvable institutions, with explicit review triggers, time windows, and costs. The details remain a design problem.

Can it work without its founder?

No founder should hold a permanent veto over the theory, name, rules, or institutions. Turning that principle into a working mechanism remains to be tested.

Who counts as affected?

Standing cannot be reduced to one universal voting rule. Drawing the boundary of who is affected is itself a power that must be exposed and challenged.

What happens when exit is impossible?

Forking works for code more readily than for cities, infrastructure, or states. Institutions with high exit costs need stronger internal scrutiny and external review.

Ideas belong to no one.

Contributions remain traceable.

Read the white paper.