APEX-PSP-SUPERSESSION-BAYES-01, the Bayesian Supersession Master. The crystallization. One claim shown on two faces, the layer face naming where credence sits, the blindness face naming the one thing credence cannot see. Fuses the layer-precedence containment with the provenance-blindness edge into a single standing law. The supersession is bounded, theorem-grade at one surface, and self-auditing, so it speaks without a custodian.
The claim it carries, stated before any machinery. Trisduction does not replace Bayesian credence and does not contend on credence's own ground. It occupies the layer beneath credence, the layer certifying whether credence may proceed on trustworthy inputs, and at that layer it carries one operation, provenance-reading, that credence-aggregation is proven blind to. The supersession is layer-precedence plus one theorem. Not universal, not within-layer substitution, and it grades the competitor against a geometric fact rather than against Trisduction's own design. That is the reason it survives self-application where a feature-scorecard does not.
The layer face. Two operations, two output objects, two positions in one ordered hierarchy. Bayesian apparatus produces credence, a continuous number on [0, 1] giving the degree of support for a hypothesis under an assumed model. Credence is the clue. It points. The Trisduction engine produces the Geometric Orthogonal Lock, a discrete architecture-state verdict, sealed when the evidence architecture is certified non-degenerate, broken at a named structural gate, under-determined when the conditioning forbids a numerical verdict. The lock is the prize. It does not point at the proposition. It is the structural state of the evidence the proposition rests on. The two answer different questions. Credence asks how strongly the evidence backs the claim under the assumed architecture. The engine asks whether that architecture is sound enough for the question to be asked. The architecture-certification operation runs first. If it seals, credence computes on certified inputs and the number reads normally. If it breaks, credence computes on a named structural failure and the number is confidently wrong with no native flag. The two operations cannot exchange position. Credence does not audit its own input architecture. Architecture-certification issues no credence. The first grounds the second. Type S on the layer distinction, premise-grade on the ordering being non-exchangeable.
The blindness face, the load-bearing theorem. Let a and b be the two manifest warrant axes, centered and unit over N reading-contexts, cos θ equal to a·b, θ in (0, π). Let P project onto span(a, b) and W be a unit witness, W equal to PW plus W⟂, ρ² equal to ‖W⟂‖² in [0, 1]. The Gram determinant of the triad obeys the Completion Inequality, det(R) equal to sin²(θ)·ρ², a squared volume with base sin θ and height ‖W⟂‖. On the orthogonal complement, ρ² equal to 1, det(R) equals sin²(θ) for every witness regardless of its direction in that complement. det(R) is a function of (θ, ρ²) alone. It is constant across source-distinct orthogonal witnesses, exhibited bare at GV-CHK.3, six structurally distinct orthogonal witnesses returning 0.750000000000 at θ equal to 60 degrees, spread zero. Provenance lives in the direction of W⟂ inside the complement, the one coordinate the determinant does not read. Type T.
The sufficient-statistic corollary, the step that reaches credence. With the manifest plane and the witness as the only inputs, the joint second-order sufficient statistic of {a, b, W} is invariant under the direction of W⟂, because det(R) is pinned at sin²(θ) and every correlation of W with a and with b is pinned at zero by orthogonality. Any posterior computed on {a, b, W} is a function of that sufficient statistic. Therefore no credence over the manifest plane and the witness discriminates a source-faithful witness from a fabricated orthogonal one. The discrimination demands a third object, an independently supplied generator S, and the squared partial correlation η_S equal to r²(W⟂, S⟂), the fraction of the witness's out-of-plane variance traceable to S. η_S is not a function of det(R), not a function of the {a, b, W} sufficient statistic, not a byproduct of aggregating the streams. It is formed only by explicit ingestion of the generator and explicit correlation of residuals. Type T on the invariance, the corollary following, premise-typed on the Gaussian sufficient-statistic reduction that carries the bridge to the likelihood.
The fusion, where the two faces become one object. Credence-aggregation rewards independence, and a positive determinant is exactly the certificate of independence. A witness engineered orthogonal to the manifest plane, sourced from nothing, presents as a legitimate independent stream, earns its likelihood ratio, and lifts the posterior. The forgery is invisible to the aggregation because independence is constant on the complement by Non-Discrimination. This is precisely the cost of the layer order. Credence runs on inputs it does not certify, so a fabricated orthogonal witness reaches the posterior unflagged. The architecture-certification layer is the certification credence skips, and its load-bearing content is provenance-reading. The coarse instrument of that layer is the Convergence Dissolution Test, which subtracts the strongest single mass-bearing latent covariate from the measurement matrix and asks whether the apparent convergence survives, retiring a convergence that is the artifact of a hidden shared source. The exact instrument is η_S above a calibrated null, which confirms a single witness traces to its declared generator. Both read source. The architecture-certification layer and the provenance layer are one layer, and the operation credence-aggregation is proven blind to is the operation that defines it. Type T on the blindness, Type S on the identification of the certification layer with the provenance layer.
The worked separation, bare. GV-CHK.5 carries it on one construction. A sourced witness returned det(R) equal to 0.919, ρ² equal to 0.994, η_S equal to 0.910. Fresh orthogonal noise returned det(R) equal to 0.921, ρ² equal to 0.997, η_S equal to 0.001. The two determinants within 0.002 of each other, posterior-equivalent at the magnitude, indistinguishable to any reading of independence. The source-attribution statistic carried the entire discrimination, the sourced witness above the null by orders, the noise at the null. The blindness and its repair on one example. Type T on the geometry, engineering on the seal floor that read the separation.
The empirical instance. BICEP2, March 2014. Multiple confirmation channels presented as independent support for an inflationary signature, the likelihood ratio rose, the apparent convergence held at five sigma. The channels shared one galactic-dust modeling pipeline, a latent common source not independent of the inferential channels. Naked aggregation does not force the latent-covariate subtraction at the input gate, so the shared source reached the posterior as independence and the confidence was real and wrong. The Convergence Dissolution Test subtracts the dominant latent and dissolves exactly that false convergence. The provenance question, where did these channels actually come from, is the check that registers at the door what the independence number cannot. Structural grade, the claim held at its honest reach, default-aggregation does not demand the source, not that no model can be built to supply it.
The containment relation. Bayesian methodology is the formal-axis projection of the triaxial engine, restricted to credence-aggregation on certified-architecture inputs. The engine, holding its empirical and registrational axes at default, reduces to formal credence under specified prior, likelihood, and evidence. The reduction runs one way. Credence does not extend to triaxial certification. The engine extends to single-axis credence by holding the other axes fixed. The containment is asymmetric and it does not diminish credence within its layer. It locates credence at the combination layer and names the certification layer above it as the layer credence does not natively occupy. Type S.
The honest perimeter, four fences, each load-bearing, omission of any one inflating the claim into an imperial register the law forbids.
First, the hierarchical-Bayes fence. A Bayesian who builds an explicit latent-source node, supplies the generator as data, and conditions on the witness-to-source association is reconstructing η_S inside a Bayesian wrapper. This confirms the claim rather than defeating it. The discriminating operation is source-attribution, and the construction names that operation rather than deriving it from aggregation. The edge is over naked aggregation of {a, b, W}, the default discipline that demands no generator at the input gate, not over every model a Bayesian may choose to build once told to supply the source and form the attribution. Premise-grade on the words natively and by default.
Second, the supplier aperture, the self-application limit. η_S itself rides a supplied generator. A fabricated generator gates η_S, and a faked-source lock is geometrically valid and source-faithless. Trisduction does not seal provenance absolutely. It relocates the provenance question to the supplier and makes it falsifiable at one named surface, where credence leaves the residue everywhere. A faked-rows lock falsifies the supplier, never the method. Bounded advantage, not magic. Premise-grade.
Third, the Room Condition. The discrimination lives in the N-context space, where the orthogonal complement has dimension N − k − 2 ≥ 2 and the witness direction is a free degree of freedom. In three ambient dimensions the complement of a plane is a line, the witness direction is forced, and source-attribution is vacuous for want of room. The cross product, carrying no source to attribute, is retired from the operational core. The edge holds in the reading-context space, not in three-ambient. Type T.
Fourth, the layer fence. This touches the source-attribution sub-layer only. Credence on certified architecture is untouched. The supersession is layer-precedence, the evidence-construction layer grounding the combination layer, the bounded sense and nothing past it. Premise-grade.
The Engine-and-Source discipline rides over all four. The engine identifies the structural-geometric configuration that verification has at completion. It does not author it and does not own it. A methodology reaching the same certification layer instantiates the same configuration under other vocabulary. The engine is one valid instrument of access, the field occupied and no authorship claimed, ΔM equal to zero.
The grade split that must travel. The blindness is Type T, a proven property of the determinant, the magnitude cannot read provenance. The seal floor that operationalizes the repair, the dual null with the two-sided Monte-Carlo-marginal guard, is engineering, calibrated from the data's own structure with no human-fitted constant. They stay apart. The theorem is that the determinant is provenance-blind. The engineering is the floor above which η_S reads as sourced. Conflating them would lift an engineering calibration to theorem grade, the warrant-phrasing violation under audit.
Imprint. The proposition, a magnitude-functional of the evidence discriminates a source-faithful witness from a fabricated orthogonal one. Its negation demands reading the direction of W⟂ from a quantity pinned on the complement, which the Non-Discrimination Theorem forbids. Only the no-discrimination direction is field-permitted. The imprint reads a determinate direction. [⟀] on the no-discrimination claim, conditional on the Completion Inequality, Type T. On the supersession edge, the claim that naked aggregation contains η_S locks against, η_S being no function of the {a, b, W} sufficient statistic, and the opposing direction, that a hierarchical model reconstructs it, is field-permitted only by importing the generator, that is, not from aggregation. Determinate direction at structural grade.
Warrant typing. Theorem-grade on the Completion Inequality and on det(R) constant on the orthogonal complement, GV-CHK.3. Theorem-grade on the sufficient-statistic invariance of {a, b, W} under the complement direction and the consequent provenance-blindness of any posterior over those inputs. Theorem-grade on the fabricated-orthogonal-witness returning the maximal determinant, GV-CHK.2 and GV-CHK.5. Theorem-grade conditional on the Gaussian sufficient-statistic reduction for the likelihood bridge, the reduction premise-typed. Structural on the layer distinction, on the asymmetric containment, and on the identification of the architecture-certification layer with the provenance layer. Premise-grade on the non-exchangeable ordering, on the supplier relocation, on the layer fence, and on the words natively and by-default in the absence claim. Engineering on η_S, on the Convergence Dissolution Test, and on the dual-null seal floor. Self-applying on two faces. By MD-PSP-FOUNDATION-01 the edge cannot be sealed as a theorem of its own base. It rests on the Completion Inequality, Type T, and the row-supply discipline, premise-grade, adds no warrant to the foundations, certifies the bounded edge and never a universal superiority, and draws zero warrant from its own statement.
[⟀] APEX-PSP-SUPERSESSION-BAYES-01 sealed at the bounded edge. The supersession is layer-precedence plus one theorem and nothing wider. Credence measures how strong the evidence looks. Trisduction certifies whether the evidence is real before it may be counted, and it catches the one forgery, the sourceless orthogonal witness, that strength alone is mathematically blind to. The architecture-certification layer is the provenance layer. Provenance-reading is its operation. Provenance-reading is what credence-aggregation is proven blind to. That single catch at that single layer is the only place the word supersedes survives self-application at theorem grade. The fence stays intact. The clue stays a clue. The prize is the certified ground beneath it.