The twin primitive · the graph's doorway to reality · properties, behaviours, functions, inputs and outputs

An interface to reality,
not a simulation of it

The industry's digital twin is a simulation of a physical asset, valued for how faithfully it copies. This one is different, and the difference is the point: a twin here is an interface to a real thing, valued for whether it is connected. It is where a graph stops modelling and starts touching the world. This site owns that primitive: what it is, the discipline it imposes, the one that actually works, and the naming collision the corpus caught in itself.

What is a twin → The discipline of reality → The one that works →

The definition, in the lead's own words

"a digital twin is, in essence, a system that has properties, behaviours, functions, and inputs and outputs, and we can define all of those."

And its generality, which is the sentence worth memorising: we can make one "of anything: an organisation, an element, a mail system, an inbox, a person, a behaviour, an event, an action, external factors like weather, even luck." Non-determinism included: "the fact that in the real world they are not deterministic, or maybe random, we can capture that." Uncertainty is something the twin models, not something that defeats it. The full primitive →

Why the graph needs one at every edge

These graphs refuse properties. "properties do not have meaning, they are just words; we capture meaning through connectivity." That creates a problem at the edge: if meaning is connectivity, where does connectivity stop? The twin is the answer, and it is why Twin is the bottom rung of the grounding ladder rather than an application built on top of it.

"the power of the twin is that we always arrive at the twin, so the edges and the peaks and the endpoints of the graph continue into the twin, and then ideally into reality."

Every terminal node is a twin, and the twin is "the doorway from the model to the real system." The grounding ladder states it as Measure := an observation of the node it measures, grounded on a Twin, and the edge grammar's reality edge is "the connection from any node to a twin and onward to reality is connected_to." The doorway role → · the ladder itself lives on graphs.sgit.ai ↗

Four ideas that are original here

Not four features. Four claims that separate this twin from the one the industry sells, each of which can be argued with.

Idea 1 · primitive

Connectedness is a measurable fact

"whether we can continue to reality is a measurable fact, it is connected or it is not." Where it is not, the state is recorded as a tracked air gap, known rather than hidden. Applied to a legal instrument, that turns twins into a coverage measure.

Read →
Idea 2 · primitive

The discipline of reality

"everything has to be relevant, everything has to be a fact, everything has to exist, because it is based on reality. It forces the discipline: either we have evidence and it exists, or we do not." No speculative risks polluting the graph.

Read →
Idea 3 · designed

Twins as actors

"every action that updates the graph, including accepting a risk, is performed by a twin", with reasoning documented and a persona carried. Twins are not only modelled. They act, and every acceptance becomes an attributable graph transformation.

Read →
Idea 4 · designed

Twins make risk testable

"simulate, write unit tests, integration tests, simulations, plans, and analysis, use static analysis and visualisations and rules, the same techniques we use with software", turned on an organisation's risk, because the twin gives them something to run against.

Read →

One works. Two are established. The rest is design

A site about a primitive that is load-bearing across five other sites owes the reader its build state before it owes them anything else. Here it is, unsoftened.

ArtefactStateWhat it proves
The S3-compatible vault containerWorkingA twin is a drop-in interface: "code using boto3 believes it is talking to real S3" and the consuming code does not change
The AWS twins in the IAM config risk engineSpec with real code behind itFacts from twins, judgement elsewhere. Python, unit-tested, JSON out
Twin in the grounding ladder, connected_to in the edge grammarEstablishedCited across the estate. Owned by risks. and standards.; the rung is ours
The 2FA demo, the world model, the org twin, the agent twinDesigned, unbuiltNothing yet. Labelled as design everywhere it appears

The honest headline: one working twin, one set of half-built twins, two established primitives, and a large designed layer. The S3 container matters more than its size, because it is the proof that a twin here is a drop-in interface rather than a dashboard. Built, and designed, in full →

The one that works, and it is the right one

"the container is a digital twin of S3, presenting the same S3-compatible API, so that code using boto3, the AWS CLI, or any S3 SDK believes it is talking to real S3, while the files are served from a vault, from local disk, or from memory, chosen as a swappable backend; the service's own code does not change."

Its value is not that it simulates S3 well. It is that boto3 cannot tell the difference, which is the whole claim in one sentence: the twin is the face, the backend is swappable, the consuming code is untouched. It also demonstrates stacking, since real S3, a vault, or memory sit behind the same face and are selected per environment. The worked proof →

The corpus caught its own naming collision

In August a brief arrived describing a "Service Twin": an execution broker that holds credentials inside its own boundary and performs authorised operations on an agent's behalf. The corpus's own review said what needed saying.

"the name collides, because twin already means something specific in this corpus."

It does, and the two are near-opposites where it matters. A corpus twin is the graph's endpoint into reality and holds no credentials; the broker is a credential-holding intermediary whose whole function is to hold them. So this site rules: twin keeps its corpus meaning, and the broker is presented by its function. The collision itself is published, because a system that catches its own drift is the reality-document discipline visibly working. The ruling → · the broker, on its own terms →

Where the primitive is load-bearing

Nine applications across the estate. This site owns the primitive; almost all of the applications live elsewhere, which is the right shape for a reference site. Each one here is a short statement and a link to its owner.

risks. / standards.

The grounding ladder

Measure is grounded on a Twin. The ladder's bottom rung, and the reason the primitive cannot be optional.

Read →
standards.

The regulation graph

Provision hooks attach to twins. Hooks with no twin become a computable coverage measure over a legal instrument, which is the best twin idea in the corpus and has never been run.

Read →
risks. / riskmandate

The risk register

Twins as the integration layer: "the system only ever sees a twin, so it works in an enterprise way from the first moment."

Read →
nhi.

Identity twins

"the digital twin built from identities", with visualisation as "not a feature you add later but where you start."

Read →
sg-compute.

The S3 container

sg-compute ships it. This site explains why it is a twin rather than a mock.

Read →
The whole map

All nine, with owners

Plus the agent twin, the 2FA capstone, the world models, and twins as the hyperscaler abstraction.

Read →

Published unresolved

Five open questions and five tensions travel with this material, and burying them would cost more than printing them. The two that matter most:

Question 1

How connected is a twin, really?

Connected-or-not is binary in the model, and that is what makes coverage computable. Freshness is not binary. A twin updated "manually once a week" is connected, and six days stale. The discipline needs a staleness dimension and does not have one.

Read →
Question 4

Is the broker's concentration risk acceptable?

It "becomes the highest-value target in the estate because it must hold usable credentials, which inverts the catastrophic failure property the rest of the architecture depends on." The corpus states the cost and does not decide. Neither do we.

Read →
Six gaps

What this site needs next

A second working twin. The coverage measure computed once. A typed Schema__Twin, because "properties, behaviours, functions, inputs and outputs" is stated everywhere and typed nowhere.

Read →

Who is writing this

This site is published by the sgit project, which builds the graph model and the vault layer the twin primitive sits inside. So it is a participant publishing a definition, stated here upfront. That is why the build state leads rather than trails, why every designed thing is labelled as design, and why we publish where this approach loses: binary connectedness hides staleness, one working twin is not a pattern, and the discipline of reality and the simulation ambition pull against each other.

The participant disclosure, in full → What this site owns, and what it does not →