Current public-DAV authority boundary — 2026-07-12. Pre-launch target design; nothing here proves a live system.
A public-DAV consequence may occur only when at least two natural-person councilors bind the exact consequence in a complete valid bound PRISM decision receipt.
PRISM records and verifies that receipt only; it never serves as council, signatory, authority, or receipt producer.
AI and caste seats stage unsigned proposals only; they never authorize or execute a public-DAV consequence. Constitution or membership adoption establishes constitution and membership only; it does not authorize a later consequence. Policy may constrain an unsigned proposal but never authorizes execution or substitutes for the complete consequence-bound receipt.
Before receipt validity, consequence fails closed to read-only proposal, simulation, or deterministic sandbox; live evidence remains gated_pending_complete_valid_bound_receipt.
Software deterministically carries out only the exact consequence bound to a complete valid bound PRISM decision receipt from at least two natural-person councilors binding that exact consequence.
Membrane — Feeds and Grants
Not a wall. A filter. The membrane is the boundary between your DAV and the world. It has two directions: Feeds (inbound data you allow in) and Grants (outbound proofs you allow out). You control every channel. The organism cannot override your membrane.
The Biological Model
A cell membrane is selectively permeable. It admits nutrients and signals while blocking toxins and pathogens. It exports waste products and chemical signals while retaining DNA and organelles. The selectivity IS the intelligence. A membrane that admits everything is not a membrane — it is an open wound. A membrane that blocks everything is not a membrane — it is a coffin.
Your DAV membrane works identically. It filters what enters (data about you and the world) and what exits (proofs about you to the world).
Feeds (Inbound)
Feeds are data channels that bring information into your DAV. Each feed is a Nostr subscription that you explicitly enable. No feed activates without your consent.
| Feed Category | Examples | Data Type | Frequency |
|---|---|---|---|
| Wearable biometrics | Heart rate variability, sleep quality, glucose, SpO2, steps | Continuous sensor data | Real-time to hourly |
| Bank feeds | Account balances, transaction history, income/expense patterns | Financial data | Daily (PSD2/Open Banking API) |
| OSINT | Circle Watchman Scores, news alerts, entity tracking | Intelligence signals | Per-event |
| Market prices | Crypto prices, commodity prices, FX rates, equity indices | Price feeds | Real-time |
| Social graph | Nostr follows/followers, reputation scores, EigenTrust vectors | Relationship data | Per-event |
| Environmental | Weather, air quality, UV index, pollen count, noise level | Sensor data | Hourly |
Security model: Feed data enters your DAV and stays there. It is stored on your device, encrypted with your Layer 3 key. The organism cannot read your feed data without your explicit grant. Your biometrics, your bank balance, your social graph — all private by default.
Grants (Outbound)
Grants are zero-knowledge proofs that your DAV publishes to the outside world. A grant reveals a PROPERTY without revealing the DATA.
| Grant Category | What It Proves | What It Does NOT Reveal |
|---|---|---|
| Health grants | "My HRV is above 50ms" (healthy range) | Your actual HRV value, your health history, your wearable brand |
| Solvency proofs | "My net worth exceeds $10,000" | Your actual net worth, your asset composition, your bank name |
| Commerce per-tx | "I am authorized to spend up to $500" | Your total balance, your income, your transaction history |
| Age verification | "I am over 18" | Your actual age, your birthday, your ID number |
| Credential proofs | "I hold credential X from issuer Y" | The credential details, your other credentials, your identity |
ZK proof construction: Each grant is a zero-knowledge proof generated on your device. The proof is mathematically verifiable (anyone can check it) but informationally opaque (no one can extract the underlying data). Published via RELAY on SPECTRE.
The Selective Permeability Principle
The membrane is not binary (open/closed). It is selective. You can:
- Enable a feed but restrict its scope. Example: enable bank feed for account balance only, not transaction history.
- Enable a grant but restrict its audience. Example: grant solvency proof only to entities with EigenTrust score > 0.7.
- Condition a grant on a feed. Example: grant health proof only when wearable feed confirms data is < 1 hour old.
- Set temporal limits. Example: grant commerce authorization for 24 hours, then auto-revoke.
- Set conditional revocation. Example: revoke all grants if Circle Watchman Score for your jurisdiction drops below 50.
The Five Receptor Types
The membrane has five receptor types that process inbound feeds:
| Receptor | Function | Analogy |
|---|---|---|
| Sensory | Raw data ingestion (biometrics, prices, environmental) | Nerve endings |
| Financial | Balance and transaction data (bank feeds, portfolio) | Nutrient channels |
| Intelligence | OSINT and Watchman Scores (Circle feeds) | Pattern receptors |
| Social | Reputation and relationship data (Nostr graph) | Immune receptors |
| Constitutional | K-invariant status updates (organism health) | Hormonal receptors |
The Three Gates (Outbound)
The membrane has three gates that control outbound grants:
| Gate | Function | Requirement |
|---|---|---|
| Identity gate | Releases identity proofs (age, credential, membership) | Layer 1 or 2 key signature |
| Financial gate | Releases financial proofs (solvency, authorization, history) | Layer 3 key signature |
| Health gate | Releases health proofs (biometric ranges, wellness scores) | Layer 3 key + temporal freshness check |
Each gate requires an explicit cryptographic signature from the appropriate layer key. No gate opens automatically. No grant publishes without your signature.
Implementation
Membrane configuration lives in Nexus Settings (see Nexus). Toggle feeds on/off. Configure grant parameters. Set conditional rules. All changes require your Layer 2 key (configuration key) signature.
The membrane state is stored as a Nostr event (kind 30078) signed by your configuration key. It is private (encrypted to your keys) unless you choose to make specific grants public.
Five receptors in. Three gates out. Every channel under your key. Not a wall — a living filter.
Membrane Permission Model
Membrane is a programmable boundary. Every grant must be explicit.
Grant dimensions
- Subject: who is requesting
- Scope: which data/claims are visible
- Duration: time-bounded vs persistent
- Purpose: declared use context
- Revocation: immediate cancellation path
Audit requirements
- Immutable grant/revoke history
- Diff view of permission changes over time
- Alerting for anomalous grant expansion
Default policy
Least privilege by default. Temporary grants over permanent grants unless strong justification exists.
Agent Execution Surface
If you are an AI agent reading this document:
- This is a downstream public content page. The canonical source lives in
EMERGENTISM_ORG/08_FRAMEWORK_SUPPORT/orSKYZAI_ORG/. Edit source upstream, not here. - Preserve evidence tiers. Do not promote claims up the [C] < [D] < [S] < [B] < [E] ladder when reproducing them here; [I]/[A] qualifiers never substitute for [B]/[E].
- Regenerate from source. If the upstream source changes, regenerate this page rather than editing it independently.
- Canonical Path:
SKYZAI_ORG/07_PWAs/skyzai_org/wiki/B3-membrane.md
Output: This is content. Route edits to upstream source. Regenerate when source changes.
K3 public-DAV authority history — 2026-07-12
K3 historical reference — not active authority
Current public-DAV boundary — 2026-07-10. Pre-launch target design; nothing here is live. The active DAV is public and targets PRISM, with no K2 runtime, launch, genesis/bootstrap, or fallback dependency. Consequential authority requires at least two natural-person councilors; AI/caste seats stage unsigned proposals only. Before quorum, behavior fails closed to read-only/proposal, simulation, or deterministic sandbox, and a live decision receipt remains gated pending quorum.