The discipline of reality
Nothing else in the digital-twin literature says "either we have evidence and it exists, or we do not." This is the most distinctive page on the site, and the constraint it describes is the source of the primitive's power rather than a limitation on it.
1. The rule
"in this model, everything has to be relevant, everything has to be a fact, everything has to exist, because it is based on reality. It forces the discipline: either we have evidence and it exists, or we do not."
Read that against how risk work is normally done. A threat model is populated with things that could happen to systems that might exist, assessed by people who may or may not be in the room. It is useful, and it is unfalsifiable, and the two facts are related. The consequence, stated in the source: "the graph never fills with potential, out-of-context risks that become pollution."
| A graph of twins | A threat model | |
|---|---|---|
| What may be a node | Something that exists, with evidence | Anything anyone can imagine |
| How it grows | By connecting to more of what is there | By adding more of what might be |
| What "unknown" looks like | A tracked air gap, recorded | Absence, indistinguishable from covered |
| Can it be wrong? | Yes, and checkably so | Not really |
| Failure mode | Small: it covers less than you hoped, and says so | Pollution: plausible items nobody can retire |
The cost is real and worth naming. A discipline that admits only what exists cannot reason about what has not happened yet, which is exactly what a security team is paid to do. That tension is not resolved here, it is published as question 3, and it is where this rule and the simulation ambition meet head on.
2. Connectedness is a fact
"whether we can continue to reality is a measurable fact, it is connected or it is not."
This is the sentence that makes the rest computable. Most model-quality questions are matters of judgement: is this accurate, is it complete, is it current. Whether a twin has a live route to the thing it stands for is not a judgement. It is a fact about the estate, answerable by asking.
3. The tracked air gap
The obvious objection is that most things are not connected. The answer is not to pretend otherwise:
"a place to represent an air gap that is understood and tracked: this has no API, this is updated manually once a week."
An air gap is a first-class object rather than a blank. That single design choice changes what the model can be asked. An unconnected twin is not a failure of the model. An unrecorded one is.
A live route to reality
An API, a connector, a feed. The twin can be refreshed by asking the real thing. Measures grounded here are observations.
Known, recorded, dated
No API, updated by hand once a week. Still a twin, still in the graph, and everything downstream can see exactly what it is standing on.
The one that costs you
A place the graph implies coverage and has none. This is the state the air-gap object exists to abolish, and the state the coverage measure counts.
4. The extension: coverage over a legal instrument
The July regulation-graph work takes connectedness and turns it into a number. If every paragraph of a legal instrument is a graph, and its provisions carry hooks that attach to the things an organisation actually has, then hooks with nothing attached are measurable:
"a provision whose hooks have no twin attached is a provision that has not yet been connected to anything the organisation actually has, and counting those is a direct, computable statement about how much of the instrument has been genuinely mapped rather than merely imported."
The regulation graph itself is owned by standards.sgit.ai, which holds the instrument, the paragraph-level model and the definitions. This site owns the twin idea inside it: the hook, the attachment, and the fact that a missing attachment is countable. The boundary, stated →
5. Where the rule is oversimplified
Binary connectedness is what makes coverage computable, and it hides something. The agent-twin brief carries the objection itself, as "the standing question of how connected the twin actually is to reality."
A twin updated "manually once a week" is connected under the binary rule, and on a Friday it is six days stale. Connectedness is binary; freshness, latency and fidelity are not, and nothing in the model captures them. A coverage number that treats a weekly spreadsheet and a live API as the same thing is a number with a defect in it.
The likely shape of the fix is a staleness dimension on the connection rather than on the twin, so a measure can state both that it is grounded and how old its grounding is. Nobody has written it. Question 1 →