Forgetting

When “this state provably no longer contains X” is a designable property of a system that still works: one object grading how thoroughly a state forgets, what keeping the system working costs that grade, and where robust forgetting stops being purchasable at all.

The systems here are small grown worlds. A state is a positive integer, a move multiplies it by a member of that state's menu — the moves the state admits — and a route is the sequence of moves from the start state 1, its product being the state it ends at. A world is read at a temperature β: a move m is taken with probability proportional to mβ, normalized by the state's normalizer, the sum of mβ over its menu. A route's probability is then the product of its moves' weights divided by the product of the normalizers it passed through — and since the moves' product is the endpoint, two routes reaching one endpoint differ only in those interior normalizers. Everything about which route was taken lives in what the intermediate states could have done otherwise.

Three worlds carry the census — an exhaustive fiber-by-fiber read, exact throughout. The depth column takes the constant menu {2, 3} at every state; plain breadth takes the squarefree moves 2..30 coprime to the state; and the tuned amnesiac is a hand-built world — menu 1 → {2, 3}, 2 → {3, 5, 15}, 3 → {2, 10} — whose menus were solved to make one endpoint's routes equiprobable at a named temperature (the one-way design). A world free to reuse a prime it already holds recycles; one every move of which is coprime to the state it acts on cannot.

The certificate's data is three things and a family. A forgotten datum X, any function of history — the route itself, the first move, the multiset of moves. A state map Φ, carrying a history to the still-working present. The weight family, here the temperatures. The fiber of a state is the set of histories Φ sends to it, and the posterior of X there is its conditional distribution on that fiber. What a state keeps is what Φ keeps — the dated endpoint, the value reached together with the number of moves, or the age alone.

The certificate

The four grades and their two witnesses rule

What a state map forgets is graded at one of four grades, increasing in strength; a certificate for X at Φ is a witness at one of the three above the lowest. R, readable: X is a function of Φ, and there is no certificate. P, possibilistic: every fiber meets at least two X-classes, so X is not recoverable as a value; the strongest witness for it is a state-side factoring, a presented split of the history space into X and a remainder with Φ constant in the X slot, which needs no weight at all. T, tuned-flat: at one named temperature the posterior of X is uniform on every fiber's consistent values. S, robust-flat: uniform at every weight in the family. Flatness is fiber-uniformity — maximum entropy behind what the living state logically pins, and never posterior = prior, since a grown world's state is its present and so always informs its past possibilistically. It upgrades to posterior = prior for every prior exactly where the split carries the WEIGHTS with it, which is the inheritance lemma below.

Grade S is bought two ways, and the two forgetting specimens here sit there by different witnesses — they differ in which lemma applies, not in how they are built. Inheritance: where the history space splits as X against a remainder, with X's prior weight-free and Φ reading only the remainder, the posterior of X equals its prior at every state and every weight, with no tuning. Destination universality is grade S by that witness: the adapted reader's state is a function of its metabolism — the resources it is given to spend — and never of the data it is shown, which is the factoring. Weight-side symmetry: where the multiset of interior normalizers agrees along every route of a fiber, the route posterior is uniform at every β — route weight is proportional to the product of the reciprocals of those normalizers, and equal multisets have equal products. The depth column is grade S by that witness, every normalizer in it being the same polynomial. A third lemma collapses the obvious alternative to a witness: a quotient through which Φ factors, each of whose classes meets every X-class, exists if and only if every Φ-fiber meets every X-class. So “factors through a quotient killing X” is extensionally the FULL-SPREAD case of the possibilistic grade — every fiber meeting every class rather than merely two — and a split witness adds provenance rather than extension.

Scope. The three lemmas proved, scope-free. The grading is an observation exhaustive at the census scope — 406 fibers, the depth column read to age 5, breadth to age 3 and the tuned world to age 2, across β ∈ {1, 2, 3}, exact in rationals throughout — and the four grades land whole, with zero fibers they cannot express. The counts land R 3 and T 2 in the tuned world, R 10 and S 10 in the depth column, R 18 and P 363 in breadth. The destination-universality row enters by inheritance together with the factoring measured on the reader side, which holds under every loss that reads only what the reader has committed to and fails outside that family.

verifier: explore_forgetting_certificate.py

The two clauses are independent observation

A certificate carries a structural clause — is there a witness? — and a measure clause — is the posterior flat? Neither implies the other, and both crossings print. Structural kill without flatness: at all 363 of breadth's multi-route fibers the state factors through the quotient that remembers which moves were made and not the order they came in, so the ORDER is possibilistically dead at every one of them — and the posterior still reads that order through the normalizers at β = 1. Flatness without any structural witness: the tuned world's endpoint 6 at age 2 is flat at β = 1 with the witness absent, which is the signature of tuning — it buys one temperature and no more, and the census separates tuned from structural flatness by inspection. What a world forgets is also fiber-local: that same tuned world hides the ORDER at endpoint 6 and hides the move SET at endpoint 30 ({2, 15} against {3, 10}, each admitting exactly one order).

Scope. Exhaustive at the census scope above. The crossing in the remaining direction — robust flatness with no witness — occurs at no fiber here, and whether it can occur at all is the obstruction the coprimality dichotomy below settles.

verifier: explore_forgetting_certificate.py

The count leak rule

A certificate for X does not descend to functions of X. Take the depth column, which is route-uniform at every temperature with the weight-side witness present — perfect symmetry, the strongest grade there is. The posterior of the FIRST MOVE at the endpoint 2a3b is nonetheless exactly (a/(a+b), b/(a+b)) — independent of β, and a leak. Route-uniformity does not coarsen to feature-uniformity, because a uniform posterior counted over unequal coarse classes is not uniform. Two leak channels: the WEIGHT leak, where the measure itself is asymmetric, and the COUNT leak, where only the geometry of the fiber is. Every coarsening needs its own flatness clause.

Scope. The a/(a+b) law proved for the two-move constant menu — equal route weights with binomial fiber counting — and verified at every mixed fiber to age 5; other menus were not scanned. The two-channel reading is an observation.

verifier: explore_forgetting_certificate.py

Forgetting while the system still works

A still-working system must RETAIN a required function g of its history while certifying that it no longer holds X. Φ computes g exactly when g factors through Φ — equivalently, when Φ's partition of the history space refines g's — so the admissible state maps are exactly the interval from g to the partition into single histories, and the question is whether that interval holds a partition that is spread (every block meets at least two X-classes) and flat — a cure. It decomposes fiber by fiber, and the price of a cure is the number of blocks it takes, summed over fibers. Where X is a function of g there is nothing to design: the state is readable.

Refinement never cures, coarsening exposes rule

Two-class conservation. On a g-fiber carrying exactly two X-classes, of masses m₁ and m₂, every spread block holds both classes and flatness forces their two masses equal inside each block; summing over blocks gives m₁ = m₂. So a two-class fiber is curable only where Φ = g is already flat: refinement never cures a two-class leak. The count leak is therefore not merely undescended but UNREMOVABLE while the dated endpoint is retained — deleting a record's attribute while keeping the record runs into a parity-style obstruction that no state design crosses.

The numerator effect. Retention is not monotone the way admissibility is. Conditioning on a dated endpoint cancels the move weights in the numerator, the moves' product being the endpoint itself; conditioning on the AGE alone surfaces them. In the depth column the posterior of first move 2 at an age fiber is exactly 3β/(2β + 3β) — 3/5 at β = 1 — a strict majority at every temperature, and a mass majority is partition-free, so every age fiber leaks whatever state map is built over it. A coarser retained function admits MORE state maps and certifies FEWER: retaining less exposes more.

Scope. Two-class conservation proved. The numerator effect's mechanism is proved and its instances measured at scope: in the depth column with the dated endpoint retained and X the first move, every fiber whose two exponents differ leaks (8 of 20), the equal-exponent ones cure at price 1 and the pure powers are readable, while coarsening to the age alone converts route-uniform fibers into majority-readable ones — the same reversal holding in the tuned world. Where the majority test passes and the individual weight ties a cure would need do exist, no cure assembles at ages 2 or 3 either, so the effect is not a majority artifact.

verifier: explore_working_amnesiac.py

The no-majority criterion criterion

On a uniform-weight g-fiber whose X-class counts are c₁ ≥ ⋯ ≥ cr totalling N, a spread flat partition exists if and only if c₁ ≤ Nc₁ — if and only if no class holds a strict majority. Necessity survives the weighted case as a MASS-majority test, which is partition-free and therefore runs at any fiber size, however far past exhaustive search. Sufficiency is exact subset-mass matching and is NOT claimed weighted, and the distance between the two is where the real price sits: with unequal weights, all 118 searchable non-majority breadth fibers fail to cure. In uniform-weight fibers necessity IS sufficiency; the gap between them is exactly the exact-subset-sum structure of the weight family.

Scope. Proved at uniform-weight scope, and cross-validated against exhaustive partition search — capped at 8 routes per fiber — on all 49 uniform fibers inside that cap, with zero mismatches. The matching-gap count is an observation at the census scope above.

verifier: explore_working_amnesiac.py

The strict amnesiac and the tie desert observation

What the three laws above price is curability; what they leave open is whether refinement ever STRICTLY beats the coarsest working state. It does, rarely, and cheaply. In the depth column with the dated endpoint retained and X the first TWO moves, five fibers cure STRICTLY: the coarsest working state Φ = g leaks, and a refinement of it is spread and flat at every temperature. The specimen is class counts (2, 1, 1) with baseline posterior (½, ¼, ¼), cured at price 2 by pairing the two singletons. Partition design alone buys a robust certificate the coarse state does not have — and the ties it rides need not be symmetric: a designed recycled-prime world whose one fiber holds two tie classes at different products has a leaking coarse state cured strictly by pairing at every temperature. But it is confined to worlds carrying exact weight ties, and plain breadth is a TIE DESERT: across all its multi-route fibers to age 4 — 363 at ages up to 3 and 441 one age deeper — the interior-normalizer product is INJECTIVE: not one pair of routes carries equal products at β = 1, so no pair ties across all temperatures at once, and no working state hides the route anywhere in it. For X the first move, of the 291 fibers inside the search cap 173 die by mass majority and 118 pass necessity but admit no exact-tie partition, and none cures. Partition design manufactured no tie anywhere it was searched, and where a certificate does turn up it is a symmetry, a tuning — one temperature only — or a recycled-prime menu design supplying the ties.

Scope. Exhaustive at the census scope above — the tie scan run one age deeper in breadth, the 441 age-4 fibers — exact in rationals, the partition search capped at 8 routes per fiber. The 72 breadth fibers above that cap carry no all-temperature mass majority — the partition-free test runs at any size — so they stay genuinely open rather than decidably leaking. At every temperature at once the desert is proved — the coprimality dichotomy below bars any all-temperature tie in breadth at any age; at a single temperature it is a measurement, injective through age 4 and unsearched beyond.

verifiers: explore_working_amnesiac.py, explore_tie_world.py

What robust forgetting costs

That leaves the obstruction the certificate opened: does robust flatness FORCE a structural witness? It is a factoriality question about the normalizers. Two routes flat at every temperature means their interior-normalizer PRODUCTS agree as functions of β; a weight-side witness means the two MULTISETS agree. So the question is whether equal products force equal factors — and it settles both ways, on one axis, and the axis is coprimality. A world free to recycle its own primes can close a two-route fiber flat at every temperature with distinct multisets, so robust flatness does not force the witness. In a coprime world no dated multi-route fiber is flat at every temperature at any age, so there the answer is yes, vacuously — no multi-route fiber is flat for the question to test. Both halves, and the dichotomy they make — the coprimality dichotomy — are the one-way design. That leaves how WIDE the recycling door is, which is a question about the normalizers alone.

Retention is what prices the certificate. Two-class conservation freezes the count leak, the no-majority criterion prices what is left, and the numerator effect shows that a certificate is not monotone in what is kept — a system holding less of its own history does not thereby forget more of it. And the boundary of robust forgetting is not age but prime recycling: a world whose menus never reuse its own primes cannot help writing its history into its weights. Read as a deletion guarantee — a record removed under a certificate rather than under a retraining story — the price line is that certified forgetting costs prime recycling, and that certifying the erasure of a record never certifies the erasure of its attributes.

How much room that door leaves is the one question the price line does not answer, and it is a question about unique factorization: two routes flat at every β means equal PRODUCTS of interior normalizers, while a structural witness would mean equal MULTISETS, so the door's width is the gap between the two. Menu collisions carries it, from collisions so generic that almost none of them is a failure of factorization at all down to a bound on how far a genuine failure can escape one variable.

The worlds turned outward

Because every posterior above is an exact rational, these worlds also serve as a measuring instrument for tools that estimate such a posterior from samples. Two published deletion audits were scored that way, and both state a certainty that outruns the accuracy behind it — one a band that narrows with data while its coverage stays where it was, the other a probability more extreme than its exact posterior over a majority of the audited mass, a miss more data concentrates rather than cures. The first of the two also returns, in two replicates in five at the size its own paper calls converged, a number its equation has no solution for, and says nothing. One scalar in the tool's own coefficients decides that, and the same scalar cut at a different level decides whether the verdict lands on the wrong side of the midpoint — which is the one thing an auditor holding no truth can price about their own number, and the price is measured there too. Deletion audits carries all of it.