The industry's digital twin is a simulation of a physical asset, valued for how faithfully it copies. This one is different, and the difference is the point: a twin here is an interface to a real thing, valued for whether it is connected. It is where a graph stops modelling and starts touching the world. This site owns that primitive: what it is, the discipline it imposes, the one that actually works, and the naming collision the corpus caught in itself.
"a digital twin is, in essence, a system that has properties, behaviours, functions, and inputs and outputs, and we can define all of those."
And its generality, which is the sentence worth memorising: we can make one "of anything: an organisation, an element, a mail system, an inbox, a person, a behaviour, an event, an action, external factors like weather, even luck." Non-determinism included: "the fact that in the real world they are not deterministic, or maybe random, we can capture that." Uncertainty is something the twin models, not something that defeats it. The full primitive →
These graphs refuse properties. "properties do not have meaning, they are just words; we capture meaning through connectivity." That creates a problem at the edge: if meaning is connectivity, where does connectivity stop? The twin is the answer, and it is why Twin is the bottom rung of the grounding ladder rather than an application built on top of it.
"the power of the twin is that we always arrive at the twin, so the edges and the peaks and the endpoints of the graph continue into the twin, and then ideally into reality."
Every terminal node is a twin, and the twin is "the doorway from the model to the real system." The grounding ladder states it as Measure := an observation of the node it measures, grounded on a Twin, and the edge grammar's reality edge is "the connection from any node to a twin and onward to reality is connected_to." The doorway role → · the ladder itself lives on graphs.sgit.ai ↗
Not four features. Four claims that separate this twin from the one the industry sells, each of which can be argued with.
"whether we can continue to reality is a measurable fact, it is connected or it is not." Where it is not, the state is recorded as a tracked air gap, known rather than hidden. Applied to a legal instrument, that turns twins into a coverage measure.
Read → Idea 2 · primitive"everything has to be relevant, everything has to be a fact, everything has to exist, because it is based on reality. It forces the discipline: either we have evidence and it exists, or we do not." No speculative risks polluting the graph.
Read → Idea 3 · designed"every action that updates the graph, including accepting a risk, is performed by a twin", with reasoning documented and a persona carried. Twins are not only modelled. They act, and every acceptance becomes an attributable graph transformation.
Read → Idea 4 · designed"simulate, write unit tests, integration tests, simulations, plans, and analysis, use static analysis and visualisations and rules, the same techniques we use with software", turned on an organisation's risk, because the twin gives them something to run against.
Read →A site about a primitive that is load-bearing across five other sites owes the reader its build state before it owes them anything else. Here it is, unsoftened.
| Artefact | State | What it proves |
|---|---|---|
| The S3-compatible vault container | Working | A twin is a drop-in interface: "code using boto3 believes it is talking to real S3" and the consuming code does not change |
| The AWS twins in the IAM config risk engine | Spec with real code behind it | Facts from twins, judgement elsewhere. Python, unit-tested, JSON out |
Twin in the grounding ladder, connected_to in the edge grammar | Established | Cited across the estate. Owned by risks. and standards.; the rung is ours |
| The 2FA demo, the world model, the org twin, the agent twin | Designed, unbuilt | Nothing yet. Labelled as design everywhere it appears |
The honest headline: one working twin, one set of half-built twins, two established primitives, and a large designed layer. The S3 container matters more than its size, because it is the proof that a twin here is a drop-in interface rather than a dashboard. Built, and designed, in full →
"the container is a digital twin of S3, presenting the same S3-compatible API, so that code using boto3, the AWS CLI, or any S3 SDK believes it is talking to real S3, while the files are served from a vault, from local disk, or from memory, chosen as a swappable backend; the service's own code does not change."
Its value is not that it simulates S3 well. It is that boto3 cannot tell the difference, which is the whole claim in one sentence: the twin is the face, the backend is swappable, the consuming code is untouched. It also demonstrates stacking, since real S3, a vault, or memory sit behind the same face and are selected per environment. The worked proof →
In August a brief arrived describing a "Service Twin": an execution broker that holds credentials inside its own boundary and performs authorised operations on an agent's behalf. The corpus's own review said what needed saying.
"the name collides, because twin already means something specific in this corpus."
It does, and the two are near-opposites where it matters. A corpus twin is the graph's endpoint into reality and holds no credentials; the broker is a credential-holding intermediary whose whole function is to hold them. So this site rules: twin keeps its corpus meaning, and the broker is presented by its function. The collision itself is published, because a system that catches its own drift is the reality-document discipline visibly working. The ruling → · the broker, on its own terms →
Nine applications across the estate. This site owns the primitive; almost all of the applications live elsewhere, which is the right shape for a reference site. Each one here is a short statement and a link to its owner.
Measure is grounded on a Twin. The ladder's bottom rung, and the reason the primitive cannot be optional.
Provision hooks attach to twins. Hooks with no twin become a computable coverage measure over a legal instrument, which is the best twin idea in the corpus and has never been run.
Read → risks. / riskmandateTwins as the integration layer: "the system only ever sees a twin, so it works in an enterprise way from the first moment."
Read → nhi."the digital twin built from identities", with visualisation as "not a feature you add later but where you start."
Read → sg-compute.sg-compute ships it. This site explains why it is a twin rather than a mock.
Read → The whole mapPlus the agent twin, the 2FA capstone, the world models, and twins as the hyperscaler abstraction.
Read →Five open questions and five tensions travel with this material, and burying them would cost more than printing them. The two that matter most:
Connected-or-not is binary in the model, and that is what makes coverage computable. Freshness is not binary. A twin updated "manually once a week" is connected, and six days stale. The discipline needs a staleness dimension and does not have one.
Read → Question 4It "becomes the highest-value target in the estate because it must hold usable credentials, which inverts the catastrophic failure property the rest of the architecture depends on." The corpus states the cost and does not decide. Neither do we.
Read → Six gapsA second working twin. The coverage measure computed once. A typed Schema__Twin, because "properties, behaviours, functions, inputs and outputs" is stated everywhere and typed nowhere.
This site is published by the sgit project, which builds the graph model and the vault layer the twin primitive sits inside. So it is a participant publishing a definition, stated here upfront. That is why the build state leads rather than trails, why every designed thing is labelled as design, and why we publish where this approach loses: binary connectedness hides staleness, one working twin is not a pattern, and the discipline of reality and the simulation ambition pull against each other.