Rules Before Oracles: Auditable, User-Configurable Argument Selection for Deliberative Polling
Summary
The paper proposes an auditable, user-configurable rule-based method for argument selection in deliberative polling, demonstrating through simulations that it achieves competitive performance with opaque learned rankers while enabling greater transparency and personalization.
View Cached Full Text
Cached at: 08/26/26, 09:19 AM
# Auditable, User-Configurable Argument Selection for Deliberative Polling Source: [https://arxiv.org/html/2608.23979](https://arxiv.org/html/2608.23979) \\JAIRTrack Volume:008Muntaser Syed,Markus Zankeremail:[markus\.zanker@unibz\.it](mailto:[email protected])Affiliation:Free University of Bozen\-Bolzano,Bolsano,ItalyandMarius SilaghiNote:Corresponding Author\.email:[msilaghi@fit\.edu](mailto:[email protected])Affiliation:Florida Institute of Technology,Melbourne,Florida,USA 2026 ###### Abstract\. Background:A deliberative poll asks people to decide only after considering the arguments that bear on the decision\. Once submitted arguments outnumber what anyone will read, some mechanism must choose which of them each voter sees, and that choice acquires a large share of the decision\. Contemporary practice delegates it to opaque learned rankers, so a participant cannot recompute, attribute or contest the exposure that shaped their vote\. Objectives:We ask whether argument selection in a binding civic process can be a*published rule*over*publicly recomputable evidence*, with free parameters held by the individual voter, and what such a constraint costs\. We treat legibility/explainability as an admissibility condition on the class of usable mechanisms rather than as an objective to be traded against accuracy, and we quantify the trade\-off that is thereby foreclosed\. Methods:We formalise a poll as an alternative\-based information system over bipolar justification sets, define three complementary evaluation instruments for judging a served slate: \(i\) set coverage of the live reason vocabulary, \(ii\) the order in which coverage arrives, and \(iii\) captured endorsement mass\. We also state the Subsuming Justification Problem with a greedy submodular bound used strictly as an evaluation ceiling, and give seven checkable criteria for a civic recommender and a rule satisfying all seven: a one\-hop reversed endorsement flow whose only policy parameter is a relation\-weight function\. An agentic simulator instantiatesNNconstituent agents and persists every slate at the instant of every vote; we report roughly17,00017\{,\}000seeded, seed\-paired runs over two propositions\. Results:In terms of coverage of live reason vocabulary fraction, served slates fall only0\.035±0\.0130\.035\\pm 0\.013short of a label\-reading ceiling that upper\-bounds*every*selection procedure, opaque ones included, so the entire competitive advantage available to an unconstrained ranker is bounded and small\. On set coverage alone with solely non\-degenerate authoring the rule is statistically indistinguishable from a uniformly random slate; we show that null is an artefact of an order\-blind, charity\-blind instrument\. Under the two remaining evaluation instruments, the rule has a clear effect: it leads at every slate prefix by a margin that*widens*with adversarial pressure \(−5\.7\-5\.7positions of depth\-to\-90% at a quarter\-electorate coalition\), and it dominates on endorsement mass by a factor of3\.33\.3\. Once a realistic fraction of submissions carries no reasons, the coverage margin returns and grows monotonically, with the two link summands — exactly inert on a uniformly good corpus — supplying91%91\\%of it\. Label\-homogeneous flooding collapses completeness from0\.810\.81to0\.340\.34under a flat weight policy but only to0\.440\.44under an author\-count\-normalised one; a coalition co\-signing to defeat the normalisation makes itself monotonically weaker\. Conclusions:Serving as a key security control, the weight policy carries significant completeness value \(10%\)\. The choice between ranking arms is a position on a coverage\-versus\-mass frontier rather than a fact, which is precisely the kind of choice only a legible rule can hand to the person it affects\. We map the construction onto an existing open\-source peer\-to\-peer platform, where per\-peer local evaluation turns configurability from an operator’s concession into a structural property\. ## 1\.Introduction In an assembly small enough that everyone hears everything, nobody has to decide what gets heard\. Every real electorate is larger than that, so a selection step is unavoidable: something decides which of the thousands of submitted reasons appear on the screen of a voter about to cast a ballot\. That step is where the power sits\. The tally is public and checkable; the slate of arguments that produced the votes is usually neither\. This manuscript takes the position that in a binding civic process the selection step is a piece of democratic procedure and must be built like one — a rule published in advance, computed over evidence any participant can retrieve and recompute, with the free parameters belonging to the individual voter rather than to whoever runs the servers\. The key insight that makes this practical is that the property we actually want from a slate — that its reasons jointly span the reasons in play — is a*set\-level*property of the served collection, and set\-level properties can be pursued through the structure of the argumentation graph without ever interpreting the text; a rule that reads only endorsement counts and signed links is therefore both good enough to use and far harder to bend without leaving a public trace\. Technically we model a poll as an alternative\-based information system, measure a served slate along three axes rather than one, exhibit a one\-hop reversed endorsement\-flow rule whose sole policy lever is a relation\-weight function, evaluate it inside a seed\-controlled agentic simulator against a greedy submodular ceiling and under coordinated attack, and map the result onto an existing peer\-to\-peer deliberation platform\. The contributions are: - •A charter for civic recommenders\(Section[4](https://arxiv.org/html/2608.23979#S4)\): address seven operational criteria — 1\. determinism, 2\. evidence locality, 3\. author blindness, 4\. semantic abstinence, 5\. reproducibility, 6\. contestability, 7\. configurability — each with the test that discharges it and the observable that would show it failing, argued as admissibility conditions rather than objectives; an opaque learned ranker fails four by construction\. - •A three\-instrument model of what a slate is for\(Section[3](https://arxiv.org/html/2608.23979#S3)\): define an alternative\-based poll over bipolar justification sets and measure 1\. completeness of coverage against the reason vocabulary live at the instant of each vote; 2\. a prefix\-sensitive family of order measures; 3\. captured endorsement mass\. The Subsuming Justification Problem is stated with its weighted and componentwise variants, and a greedy\(1−e−1\)\(1\-e^\{\-1\}\)cover to be used strictly as an evaluation ceiling\. - •A rule that meets the charter\(Sections[4](https://arxiv.org/html/2608.23979#S4)–[5](https://arxiv.org/html/2608.23979#S5)\): a one\-hop reversed endorsement flow over rebuttal and reinforcement links, with a per\-voter policy vector making the rule individually configurable without making it individually unpredictable; andAbas, a seed\-controlled simulator ofNNconstituent agents that persists every served slate before the ballot it informed, yielding some17,00017\{,\}000runs across sensitivity sweeps, a degenerate\-authoring sweep, ranking\-term ablations and five adversarial families\. - •A measured price for the charter\(Section[7\.3](https://arxiv.org/html/2608.23979#S7.SS3)\): the coverage fraction distance between the served slates and a label\-reading greedy ceiling that upper\-bounds every selection procedure on the same pool is0\.031±0\.0140\.031\\pm 0\.014, against a temporal component of0\.1630\.163that no procedure of any kind could recover\. - •Experimental results and what a ranking rule is actually for\(Sections[8](https://arxiv.org/html/2608.23979#S8)–[8\.5](https://arxiv.org/html/2608.23979#S8.SS5)\): on set coverage alone, with solely non\-degenerate authoring, the rule does not separate from a uniformly random slate, its two link summands are all but inert, and under flooding the random slate even wins\. We show it is an artefact of an order\-blind instrument and an implausibly charitable authoring model: under an order\-sensitive reading the rule leads at every prefix with the margin growing under attack, and once a realistic fraction of submissions fails to justify, the coverage margin returns, rises monotonically with that fraction, and makes the link summands worth as much as the whole ranking advantage — by squaring the discrimination the electorate already exercises\. - •An empirical manipulation result with a named defence\(Section[9](https://arxiv.org/html/2608.23979#S9)\): under authentication, hub\-riding is harmless and label\-homogeneous flooding is not; author\-count normalisation retains0\.080\.08–0\.120\.12of completeness that a flat policy loses; a rate\- and corpus\-matched control isolates homogeneity as four fifths of the cause; and the obvious escalation — co\-signing links to inflate the normalising numerator — makes the coalition monotonically weaker\. - •A peer\-to\-peer realisation and a normative reading\(Sections[10](https://arxiv.org/html/2608.23979#S10)and[13](https://arxiv.org/html/2608.23979#S13)\): a component\-by\-component mapping onto DirectDemocracy Peer\-to\-Peer \(DDP2P\), covering identity and census, gossip synchronisation and local evaluation over partial replicas; and an argument for why legible procedure is constitutive rather than decorative\. The remainder of this section states the exposure problem and previews what the measurements turned out to say\. Section[2](https://arxiv.org/html/2608.23979#S2)reviews the literatures the work sits between, Section[3](https://arxiv.org/html/2608.23979#S3)builds the formal object and its three instruments, Section[4](https://arxiv.org/html/2608.23979#S4)states the charter and the rule, Section[5](https://arxiv.org/html/2608.23979#S5)describes the simulator and Section[6](https://arxiv.org/html/2608.23979#S6)the protocol\. Sections[7](https://arxiv.org/html/2608.23979#S7)–[9](https://arxiv.org/html/2608.23979#S9)report the non\-degenerate authoring attack\-free sweeps and the price of semantic abstinence, the null result and its two resolutions, and the adversarial sweeps\. Section[10](https://arxiv.org/html/2608.23979#S10)maps the design ontoDDP2P, Section[11](https://arxiv.org/html/2608.23979#S11)discusses, Section[12](https://arxiv.org/html/2608.23979#S12)lists what would change the conclusions, Section[13](https://arxiv.org/html/2608.23979#S13)makes the normative argument, and Section[14](https://arxiv.org/html/2608.23979#S14)concludes\. ### 1\.1\.The exposure problem, and the position taken here The legitimacy of a collective decision has never rested on the tally alone\. From Mill’s marketplace of ideas to Habermas’s account of communicative rationality[Mill, 1859](https://arxiv.org/html/2608.23979#bib.bibx65);[Habermas, 1984](https://arxiv.org/html/2608.23979#bib.bibx46), the tradition holds that a decision earns authority from the quality of the discourse preceding it\. Fishkin turned that into a measurable protocol[Fishkin, 1991](https://arxiv.org/html/2608.23979#bib.bibx42);[Fishkin et al\., 2000](https://arxiv.org/html/2608.23979#bib.bibx44): draw a stratified sample, expose it to balanced material and structured discussion, measure how opinion moves\. Deployments across many countries report the same qualitative finding — considered opinion differs systematically from raw opinion, and partisan cues lose their grip once people meet the reasons behind positions[Luskin et al\., 2002](https://arxiv.org/html/2608.23979#bib.bibx59);[Fishkin, 2009](https://arxiv.org/html/2608.23979#bib.bibx43)— and the protocol’s weakness is cost, a facilitated cohort of a few hundred being an expensive instrument that does not obviously scale to a national electorate[Lukensmeyer & Brigham, 2005](https://arxiv.org/html/2608.23979#bib.bibx58)\. Digital platforms remove that barrier and immediately install another\. When a hundred thousand people submit reasons, nobody reads the corpus; each person reads a slate\. Call this the*exposure problem*: given a growing corpus of justifications and a per\-voter display budget ofKKitems, how should the slate be chosen so that the reasons in play are represented in what voters actually see? Getting it wrong produces three distinctharms, and they call for different remedies: - •*Temporal inequity*: in a sequential process the corpus is thin at the start and rich at the end, so early voters decide against a narrower reason space than late voters through no fault of their own; at the reference configuration the spread of per\-voter completeness*within*a single run is about0\.210\.21, five times the variation between one entire run and another\. - •*Silent narrowing*: a selector tuned for engagement converges on whatever holds attention, which in political material is typically what confirms a prior[Pariser, 2011](https://arxiv.org/html/2608.23979#bib.bibx72);[Sunstein, 2007](https://arxiv.org/html/2608.23979#bib.bibx99);[Willson, 2014](https://arxiv.org/html/2608.23979#bib.bibx105), and the narrowing is silent because no individual slate looks censored — the missing reasons are simply never surfaced\. - •*Unfalsifiable influence*: if the selector is a learned model, a participant who suspects their side is being systematically under\-surfaced cannot establish it, cannot recompute the ranking, cannot point at the clause that produced the outcome, and cannot distinguish deliberate suppression from an artefact of training data[Burrell, 2016](https://arxiv.org/html/2608.23979#bib.bibx20);[Lipton, 2018](https://arxiv.org/html/2608.23979#bib.bibx56)\. A civic process unable to answer “why was I shown this?” with a checkable derivation has replaced procedural legitimacy with trust in an operator\. The position of this manuscript follows from the last two harms in particular, and it is a position about*admissibility*, not about performance\. We do not claim that opaque rankers rank badly\. We claim that opaque ranking is the wrong frame for a civic slate: the object produced is not a personalised feed but a piece of the public record of what a voter was shown, and a public record must be reconstructible\. Legibility therefore determines which procedures may be used at all, and questions of comparative quality arise only among those that qualify — the same structure as the secret ballot, which nobody defends on the grounds that it measures preferences more accurately than open voting\. Section[4\.2](https://arxiv.org/html/2608.23979#S4.SS2)states the criteria in a form that can be checked against an implementation, and every subsequent section is written so that a reader can see which criterion each design decision is discharging\. Figure[1](https://arxiv.org/html/2608.23979#S1.F1)states the commitment in one picture\. corpus of justificationsbehavioural telemetrylearned selector\(weights not public\)slate ofKKinadmissibleno derivation to point atcorpus of justificationspublic endorsements\+ signed linkspublished rulescθi\(⋅\)\\mathrm\{sc\}\_\{\\theta\_\{i\}\}\(\\cdot\)slate ofKKvoter’s own policy vectorθi\\theta\_\{i\}admissibleFigure 1\.The two pipelines\. Both consume the same corpus and both emitKKitems\. The upper one additionally consumes behavioural telemetry and passes it through parameters nobody outside can inspect, so a disputed slate has no derivation to point at\. The lower one consumes only evidence every participant can already retrieve — who endorsed what, and which signed links exist — and exposes its policy parameters to the individual voter, so a disputed slate reduces either to a disputed input, which is checkable, or to a disputed policy, which is arguable\. This manuscript treats the difference as a condition of admissibility rather than as a term in an objective\. ### 1\.2\.What the measurements turned out to say In a simplified setting where all justification authors correctly express their reasons \(non\-degenerate authoring\), the fraction of the live reason vocabulary covered by a served slate, a simplified optimization objective for the motivating harms, does not differ significantly between our rule and random selection\. With metrics that evaluate the ordering of justifications within the slate, and/or under a realistic electorate with degenerate authoring, the rule shows strong benefits over the control alternatives\. ### 1\.3\.Why the substrate matters A published rule evaluated on a server the operator controls is a large improvement over an unpublished one, and it stops short\. The operator still decides which endorsements are in the database, when the index refreshes, and whose items quietly stop being returned\. Configurability granted by an operator is revocable by the same operator, and reproducibility asserted by an operator is a claim about a machine nobody else can inspect\. The natural terminus of the argument is an architecture in which each participant holds their own replica of the items they care about and evaluates the rule locally over it\.DDP2P—DirectDemocracyP2P— is an existing open\-source Java platform built on precisely that premise[Silaghi et al\., 2013](https://arxiv.org/html/2608.23979#bib.bibx89);[Silaghi et al\., 2013a](https://arxiv.org/html/2608.23979#bib.bibx90): peers keep independent databases of self\-contained items, name them by global identifiers derived from public keys and content digests, and converge by push–pull gossip\. Section[10](https://arxiv.org/html/2608.23979#S10)shows the model developed here maps ontoDDP2P’s item types with very little impedance mismatch, and that doing so converts several criteria of the charter from policy promises into structural facts\. ## 2\.Background and Related Work This work sits at the junction of five literatures: \(1\) the empirical political science of deliberative polling, \(2\) the formal theory of bipolar argumentation, \(3\) computational social choice for participatory processes, \(4\) the systems literature on recommendation and its manipulation, and \(5\) the peer\-to\-peer work that supplies the substrate\. A sixth — the use of large language models as simulated populations — supplies the register in which the evaluation is conducted\. We state below what we take from each and, where it matters, what we deliberately do not take\. #### Deliberative polling and its scaling problem\. Deliberative polling instruments a simple hypothesis: opinion formed after exposure to balanced argument differs systematically from opinion measured cold[Fishkin, 1991](https://arxiv.org/html/2608.23979#bib.bibx42);[Fishkin et al\., 2000](https://arxiv.org/html/2608.23979#bib.bibx44)\. The canonical design draws a stratified sample, supplies balanced briefing material, runs moderated small\-group discussion, and re\-measures\. Results across many deployments are consistent in direction — movement is largest where the initial position was least informed[Luskin et al\., 2002](https://arxiv.org/html/2608.23979#bib.bibx59);[Fishkin, 2009](https://arxiv.org/html/2608.23979#bib.bibx43)— and the effect survives when partisan cues are stripped from the material[Price et al\., 2002](https://arxiv.org/html/2608.23979#bib.bibx75)\. The design constraint is that facilitation does not scale: cohorts are a few hundred and the per\-participant cost is that of a small conference[Lukensmeyer & Brigham, 2005](https://arxiv.org/html/2608.23979#bib.bibx58)\. Digital deployments relax that constraint and inherit a new one[Tolbert et al\., 2009](https://arxiv.org/html/2608.23979#bib.bibx101);[Toots, 2019](https://arxiv.org/html/2608.23979#bib.bibx102): with a corpus no participant reads in full, the balance of the briefing material is no longer something an organiser curates but something a selection mechanism produces, per voter, in real time\. We take the goal — reasoned exposure before the ballot — and treat selection, rather than facilitation, as the object to be engineered\. #### Bipolar argumentation\. Dung’s abstract frameworks model a debate as a directed attack graph and define acceptability through extensions[Dung, 1995](https://arxiv.org/html/2608.23979#bib.bibx36)\. Bipolar frameworks add a support relation alongside attack[Cayrol & Lagasquie\-Schiex, 2005](https://arxiv.org/html/2608.23979#bib.bibx27);[Cayrol & Lagasquie\-Schiex, 2013](https://arxiv.org/html/2608.23979#bib.bibx26), and the handbook literature surveys the resulting semantic landscape[1, 1](https://arxiv.org/html/2608.23979#bib.bib1);[Amgoud et al\., 2008](https://arxiv.org/html/2608.23979#bib.bibx9); labelled bipolar frameworks give a unified semantics for the many readings of support and make the choice among them explicit[Gonzalez, 2021](https://arxiv.org/html/2608.23979#bib.bibx45), and the correspondence with logic programming has since been settled in detail[Alcântara & Cordeiro, 2025](https://arxiv.org/html/2608.23979#bib.bibx2)\. Value\-based extensions attach audience\-relative preferences to arguments and thereby explain rational disagreement between audiences that accept the same facts[Bench\-Capon & Dunne, 2007](https://arxiv.org/html/2608.23979#bib.bibx13), which is close in spirit to the per\-voter policy vector of Section[4\.6](https://arxiv.org/html/2608.23979#S4.SS6)\. Our use of this apparatus is deliberately shallow, and the shallowness is a design commitment\. We adopt the bipolar signature — two relations of opposite polarity over a set of items — and decline the semantics: we compute no extensions and pronounce no argument acceptable or defeated\. The reason is Criterion[4](https://arxiv.org/html/2608.23979#Thmcriterion4)\(semantic abstinence, Section[4\.2](https://arxiv.org/html/2608.23979#S4.SS2)\) — any semantics deciding which arguments survive is a machine deciding which arguments a voter should stop considering, exactly the authority a civic slate must not delegate\. Links here are evidence about relevance, not adjudication of truth\. That commitment also distinguishes this work from dialectical\-quality measures over exchanges between parties[Rocha et al\., 2026](https://arxiv.org/html/2608.23979#bib.bibx81), which judge the argumentation; Prakken and Sartor on argument schemes in law[Prakken, 2001](https://arxiv.org/html/2608.23979#bib.bibx74)and the procedural tradition running back to Robert’s rules[Robert, 1915](https://arxiv.org/html/2608.23979#bib.bibx80)are closer to the role links play here, structuring who may speak to what rather than who is right\. #### Computational social choice for participatory processes\. A parallel line asks how collective decisions should be composed once participation is mediated by software\. Liquid democracy has been given an algorithmic treatment with explicit accuracy guarantees and failure modes[Kahng et al\., 2021](https://arxiv.org/html/2608.23979#bib.bibx48); representative committees can be sampled from peers so that the committee’s decisions track the electorate’s[Meir et al\., 2021](https://arxiv.org/html/2608.23979#bib.bibx63); proposing and voting have been unified as aggregation over a metric space[Bulteau, 2021](https://arxiv.org/html/2608.23979#bib.bibx17); and proportionality has been extended from one\-shot elections to sequential decision making[Chandak et al\., 2026](https://arxiv.org/html/2608.23979#bib.bibx30)\. The complexity of outcome determination in judgment aggregation is likewise mapped[Endriss, 2020](https://arxiv.org/html/2608.23979#bib.bibx37)\. This literature aggregates*positions*; the present work is upstream of it, concerning what a voter is shown before a position is formed, and the two are complementary: any of these aggregation rules can sit downstream of the slate mechanism studied here\. #### Argument mining and its role here\. Argument mining extracts claims, premises and relations from text[Lippi & Torroni, 2016](https://arxiv.org/html/2608.23979#bib.bibx55);[Stab & Gurevych, 2017](https://arxiv.org/html/2608.23979#bib.bibx98); retrieval systems rank passages by argumentative quality[Wachsmuth et al\., 2018](https://arxiv.org/html/2608.23979#bib.bibx103);[Carenini & Moore, 2006](https://arxiv.org/html/2608.23979#bib.bibx23); and argumentative dialogue agents use such structures to conduct persuasive exchanges[Chalaguine & Hunter, 2020](https://arxiv.org/html/2608.23979#bib.bibx29)\. These techniques are how the reason labels of Section[3\.2](https://arxiv.org/html/2608.23979#S3.SS2)would be produced in a real deployment, and we assume nothing better than what they currently deliver\. Their placement in the architecture is the point\. Label extraction is an*authoring\-time*operation: it runs once per item, its output is attached to the item, it is visible to the author, and it can be contested and corrected before the item is ever served\. Selection is a*serving\-time*operation over that frozen output\. Keeping a language model strictly on the authoring side of that line means a disputed slate never requires anyone to reason about model internals; it requires them to point at a label they think is wrong, which is a claim about a public artefact\. Section[12](https://arxiv.org/html/2608.23979#S12)returns to what happens when the labels themselves are adversarial\. #### Civic platforms with algorithmic assistance\. Deployed systems already make these choices\. Polis clusters participants by agreement pattern and surfaces statements that bridge clusters[Small et al\., 2021](https://arxiv.org/html/2608.23979#bib.bibx95), an approach with a genuine claim to representativeness whose clustering step nevertheless requires the operator’s pipeline to be trusted; hybrid participatory systems go further and estimate the*values*behind participants’ textual motivations, disambiguating them interactively[Liscio, 2025](https://arxiv.org/html/2608.23979#bib.bibx57), which is the closest published treatment of the authoring\-time inference we place off the serving path\. Deliberation\-support platforms have been surveyed for their argumentation structures[Brenneis et al\., 2021](https://arxiv.org/html/2608.23979#bib.bibx15);[Mancini, 2015](https://arxiv.org/html/2608.23979#bib.bibx60), and recent work examines language models as facilitators[Behrendt et al\., 2024](https://arxiv.org/html/2608.23979#bib.bibx12);[Tessler et al\., 2024](https://arxiv.org/html/2608.23979#bib.bibx100), with Tessler et al\. reporting that a model\-generated statement can find more common ground than a human mediator\. That result is real and we do not dispute it\. Our objection is categorical rather than empirical: a mediator whose reasoning cannot be reconstructed is unsuitable for a binding process regardless of measured quality, for the same reason that a demonstrably accurate but unauditable vote count is unsuitable\. The regulatory direction is consistent — the Digital Services Act obliges very large platforms to disclose recommender parameters and offer a non\-profiling option[European Parliament and Council, 2022](https://arxiv.org/html/2608.23979#bib.bibx38), and the AI Act imposes transparency and human\-oversight duties on systems used in democratic processes[European Parliament and Council, 2024](https://arxiv.org/html/2608.23979#bib.bibx39)— and sycophancy[Sharma et al\., 2023](https://arxiv.org/html/2608.23979#bib.bibx87)and measurable political leaning in pretrained models[Feng et al\., 2023](https://arxiv.org/html/2608.23979#bib.bibx41)are further reasons to keep such models off the serving path\. #### Diversity, coverage and manipulation in recommendation\. Ranking by predicted relevance alone yields redundant lists; maximal marginal relevance trades relevance against novelty[Carbonell & Goldstein, 1998](https://arxiv.org/html/2608.23979#bib.bibx22), and aggregate diversity has been studied as a system\-level objective[Adomavicius & Kwon, 2012](https://arxiv.org/html/2608.23979#bib.bibx1)\. Multi\-stakeholder recommendation observes that platform, provider and consumer objectives diverge[Burke, 2017](https://arxiv.org/html/2608.23979#bib.bibx19); recency\-aware work notes the drift of freshness against quality[Chakraborty et al\., 2019](https://arxiv.org/html/2608.23979#bib.bibx28); and conceptual modelling of explainable recommenders has mapped what an explanation of a recommendation can even be[Caro\-Martínez et al\., 2021](https://arxiv.org/html/2608.23979#bib.bibx24)\. Our completeness functional is a coverage objective in this family, with the civic\-specific twist that the covered universe is the set of*reasons live at the moment of the vote*rather than a static catalogue\. The manipulation literature is more directly load\-bearing for Section[9](https://arxiv.org/html/2608.23979#S9)\. Shilling attacks against collaborative filtering inject profiles to promote a target item[Lam & Riedl, 2004](https://arxiv.org/html/2608.23979#bib.bibx51);[Shardanand & Maes, 1995](https://arxiv.org/html/2608.23979#bib.bibx86); Sybil attacks manufacture identities to acquire disproportionate influence[Douceur, 2002](https://arxiv.org/html/2608.23979#bib.bibx35); eclipse attacks isolate a peer’s view of the network[Singh et al\., 2006](https://arxiv.org/html/2608.23979#bib.bibx94); and election manipulation on social networks has been analysed as seeding and edge modification, with the hardness of each variant established[Castiglioni, 2021](https://arxiv.org/html/2608.23979#bib.bibx25)\. Eigenvector\-style ranking schemes[Page et al\., 1999](https://arxiv.org/html/2608.23979#bib.bibx71)are structurally susceptible to link farms, which is precisely why our rule takes exactly one hop and no iteration to a fixed point: Section[9\.1](https://arxiv.org/html/2608.23979#S9.SS1)confirms empirically that hub\-riding is inert against it, and Section[9\.2](https://arxiv.org/html/2608.23979#S9.SS2)shows where the residual exposure lives\. #### Agentic simulation as an evaluation method\. Generative agents with memory and planning reproduce plausible social behaviour in sandboxed environments[Park et al\., 2023](https://arxiv.org/html/2608.23979#bib.bibx73); language models conditioned on demographic profiles reproduce survey response distributions[Argyle et al\., 2023](https://arxiv.org/html/2608.23979#bib.bibx10); multi\-agent orchestration frameworks have matured[Wu et al\., 2024](https://arxiv.org/html/2608.23979#bib.bibx106); and the method has been applied to social\-science questions directly[Bail, 2024](https://arxiv.org/html/2608.23979#bib.bibx11)\. Our simulator belongs to this family and inherits its central caveat: agent behaviour is a model of constituent behaviour, not evidence about it\. We therefore restrict every claim to statements about*mechanism*under a stated behavioural model — comparisons between ranking arms, sensitivities to structural parameters, responses to attacks — and make no claim about the magnitude any quantity would take in a human electorate\. #### Decentralised infrastructure for civic processes\. Structured overlays give scalable key\-based routing[Maymounkov & Mazières, 2002](https://arxiv.org/html/2608.23979#bib.bibx62); epidemic protocols give robust eventual dissemination[Demers et al\., 1988](https://arxiv.org/html/2608.23979#bib.bibx32); conflict\-free replicated data types give convergence without coordination[Shapiro et al\., 2011](https://arxiv.org/html/2608.23979#bib.bibx85); hash trees give compact integrity proofs[Merkle, 1988](https://arxiv.org/html/2608.23979#bib.bibx64); blockchains give append\-only public ledgers[Nakamoto, 2008](https://arxiv.org/html/2608.23979#bib.bibx67), with transparency\-log constructions applied to update integrity[Nikitin et al\., 2017](https://arxiv.org/html/2608.23979#bib.bibx70)and cryptographic scrutiny of agreement protocols[Miller, 2020](https://arxiv.org/html/2608.23979#bib.bibx66); and decentralised social platforms have explored gossip\-based dissemination[Boutet et al\., 2013](https://arxiv.org/html/2608.23979#bib.bibx14)\.DDP2Poccupies a specific position: it is not a ledger and not a DHT, but a gossip\-replicated store of self\-contained, signed items designed for petition drives and organisational decision\-making[Silaghi et al\., 2013](https://arxiv.org/html/2608.23979#bib.bibx89);[Silaghi et al\., 2013a](https://arxiv.org/html/2608.23979#bib.bibx90);[Silaghi & Roussev, 2014](https://arxiv.org/html/2608.23979#bib.bibx92)\. Its research programme covers the pieces a civic deployment actually needs — decentralised census construction and verification[Qin et al\., 2013a](https://arxiv.org/html/2608.23979#bib.bibx78);[Qin et al\., 2014](https://arxiv.org/html/2608.23979#bib.bibx76), detection of false identities[Qin et al\., 2013](https://arxiv.org/html/2608.23979#bib.bibx77), peer reputation[Qin et al\., 2013b](https://arxiv.org/html/2608.23979#bib.bibx79), supernodes for peers behind NAT[Alhamed & Silaghi, 2014](https://arxiv.org/html/2608.23979#bib.bibx3), protocol stacking and update propagation[Alhamed et al\., 2013](https://arxiv.org/html/2608.23979#bib.bibx4);[Alhamed et al\., 2013a](https://arxiv.org/html/2608.23979#bib.bibx5), meta\-level recommendation over decentralised data[Alhamed et al\., 2016](https://arxiv.org/html/2608.23979#bib.bibx6), trust and key management[Silaghi et al\., 2016](https://arxiv.org/html/2608.23979#bib.bibx91), interface studies for non\-expert users[Alqahtani & Silaghi, 2017](https://arxiv.org/html/2608.23979#bib.bibx8);[Alqahtani & Silaghi, 2016](https://arxiv.org/html/2608.23979#bib.bibx7);[Kattamuri et al\., 2005](https://arxiv.org/html/2608.23979#bib.bibx50), its logical foundations[Roussev & Silaghi, 2017](https://arxiv.org/html/2608.23979#bib.bibx82), related vehicular deployments[Dhannoon et al\., 2013](https://arxiv.org/html/2608.23979#bib.bibx33);[Dhannoon, 2013](https://arxiv.org/html/2608.23979#bib.bibx34), and the motivating argument for why participation is worth the engineering[Silaghi et al\., 2017](https://arxiv.org/html/2608.23979#bib.bibx93)\. Section[10](https://arxiv.org/html/2608.23979#S10)builds on that stack rather than proposing a new one\. ## 3\.The Object: An Alternative\-Based Poll and Three Ways to Judge a Slate Before anything can be recommended, the thing being recommended over has to be defined, and before any recommender can be judged, the standard of judgement has to be fixed\. This section does both\. The object is an*alternative\-based information system*: a poll in which each side of the question carries its own set of justifications, and in which typed links between justifications carry the polarity of the relations participants assert between them\. The standard is deliberately plural\. We define three instruments — how much of the live reason vocabulary a slate covers, how early in the slate that coverage arrives, and how much of the electorate’s expressed endorsement the slate captures — because Section[8](https://arxiv.org/html/2608.23979#S8)will show that any one of them alone gives a misleading verdict\. We then state the combinatorial problem that coverage induces, prove it hard, and construct the greedy bound we use as an evaluation ceiling, with an explicit statement of the discipline governing that bound’s use\. ### 3\.1\.Polls, sides, and justifications A poll asks a question with a finite set of mutually exclusive alternatives\. Throughout we take the binary case — support or oppose a motion — because it is the case civic petitions actually present and because it keeps the notation legible; nothing in the construction depends on it, and Section[14](https://arxiv.org/html/2608.23979#S14)notes the multi\-alternative generalisation\. ###### Definition 3\.1 \(Alternative\-based poll\)\. An*alternative\-based poll*is a tuple \(1\)Π=⟨𝒥\+,𝒥−,ℛ⊖,ℛ⊕,ωc,ωr⟩\\Pi\\;=\\;\\bigl\\langle\\,\\mathcal\{J\}^\{\+\},\\ \\mathcal\{J\}^\{\-\},\\ \\mathcal\{R\}^\{\\ominus\},\\ \\mathcal\{R\}^\{\\oplus\},\\ \\omega\_\{\\mathrm\{c\}\},\\ \\omega\_\{\\mathrm\{r\}\}\\,\\bigr\\ranglewhere𝒥\+\\mathcal\{J\}^\{\+\}and𝒥−\\mathcal\{J\}^\{\-\}are finite sets of*justifications*attached to the supporting and opposing alternatives respectively111In the experiments reported here,𝒥\+\\mathcal\{J\}^\{\+\}and𝒥−\\mathcal\{J\}^\{\-\}are disjoint, but that can be relaxed\.;ℛ⊖⊆𝒥×𝒥\\mathcal\{R\}^\{\\ominus\}\\subseteq\\mathcal\{J\}\\times\\mathcal\{J\}with𝒥=𝒥\+∪𝒥−\\mathcal\{J\}=\\mathcal\{J\}^\{\+\}\\cup\\mathcal\{J\}^\{\-\}is the*rebuttal*relation, read “\(j,k\)∈ℛ⊖\(j,k\)\\in\\mathcal\{R\}^\{\\ominus\}asserts thatjjtells againstkk”;ℛ⊕⊆𝒥×𝒥\\mathcal\{R\}^\{\\oplus\}\\subseteq\\mathcal\{J\}\\times\\mathcal\{J\}is the*reinforcement*relation, read “jjtells in favour ofkk”;ωc:𝒥→ℝ≥0\\omega\_\{\\mathrm\{c\}\}:\\mathcal\{J\}\\to\\mathbb\{R\}\_\{\\geq 0\}assigns each justification a civic weight; andωr:ℛ⊖∪ℛ⊕→ℝ≥0\\omega\_\{\\mathrm\{r\}\}:\\mathcal\{R\}^\{\\ominus\}\\cup\\mathcal\{R\}^\{\\oplus\}\\to\\mathbb\{R\}\_\{\\geq 0\}assigns each link a weight\. Three features carry the design\. The two relations are typed but not signed at the level of the tuple: polarity lives in which relation a link belongs to, and the score function of Section[4\.4](https://arxiv.org/html/2608.23979#S4.SS4)attaches a separate coefficient to each, so a participant may configure how much a rebuttal counts relative to a reinforcement — a substantive editorial choice — without reaching inside the graph\. The civic weightωc\\omega\_\{\\mathrm\{c\}\}is the endorsement count: how many constituents cast their ballot citing that item\. It is a public tally, not a quality judgement, and no part of the construction asks whether an item deserves the endorsements it has\. Finallyωr\\omega\_\{\\mathrm\{r\}\}is where policy lives: Section[4\.5](https://arxiv.org/html/2608.23979#S4.SS5)shows that choosing it flat or normalised by the number of distinct authors behind the link moves completeness under coordinated flooding by0\.080\.08–0\.120\.12, an order of magnitude larger than any other design decision here\. ### 3\.2\.Reason vocabularies and the live denominator Coverage requires a universe to cover\. We obtain it by labelling each justification with the reasons it invokes\. ###### Definition 3\.2 \(Reason labelling\)\. Fix a finite*reason vocabulary*Λ\\Lambda\. A*labelling*is a mapλ:𝒥→2Λ\\lambda:\\mathcal\{J\}\\to 2^\{\\Lambda\}assigning each justification the non\-empty set of reasons it invokes222In the first set of reported experiments,λ:𝒥→2Λ∖\{∅\}\\lambda:\\mathcal\{J\}\\to 2^\{\\Lambda\}\\setminus\\\{\\emptyset\\\}to have solely non\-degenerate authorship\.\. Just for evaluation in reported experiments, labels are associated at authoring time \(Section[2](https://arxiv.org/html/2608.23979#S2.SS0.SSS0.Px4)\), stored on the item, and never recomputed at serving time; a deployment publishes its vocabulary and its extraction procedure\. The denominator is the subtler half\. Comparing a slate against the full vocabularyΛ\\Lambdawould penalise an early voter’s slate for failing to see reasons nobody had yet written, which is exactly the temporal inequity of Section[1\.1](https://arxiv.org/html/2608.23979#S1.SS1)— a real phenomenon, but one to*measure*separately rather than fold into the score of the recommender\. We therefore evaluate against what existed\. ###### Definition 3\.3 \(Live vocabulary\)\. For a voteriicasting a ballot at timetit\_\{i\}, let𝒥ti\\mathcal\{J\}\_\{t\_\{i\}\}be the set of justifications submitted strictly beforetit\_\{i\}, and let the*live vocabulary*on sideσ∈\{\+,−\}\\sigma\\in\\\{\+,\-\\\}beΛtiσ=⋃j∈𝒥σ∩𝒥tiλ\(j\)\\Lambda^\{\\sigma\}\_\{t\_\{i\}\}=\\bigcup\_\{\\,j\\in\\mathcal\{J\}^\{\\sigma\}\\cap\\mathcal\{J\}\_\{t\_\{i\}\}\}\\lambda\(j\)\. ###### Definition 3\.4 \(Slate completeness\)\. LetSiσ⊆𝒥σ∩𝒥tiS\_\{i\}^\{\\sigma\}\\subseteq\\mathcal\{J\}^\{\\sigma\}\\cap\\mathcal\{J\}\_\{t\_\{i\}\}be the slate of at mostKKjustifications served to voteriion sideσ\\sigma\. Its*completeness*is \(2\)ciσ=\|⋃j∈Siσλ\(j\)\|\|Λtiσ\|∈\[0,1\],c\_\{i\}^\{\\sigma\}\\;=\\;\\frac\{\\bigl\|\\ \\bigcup\_\{j\\in S\_\{i\}^\{\\sigma\}\}\\lambda\(j\)\\ \\bigr\|\}\{\\bigl\|\\ \\Lambda^\{\\sigma\}\_\{t\_\{i\}\}\\ \\bigr\|\}\\;\\in\\;\[0,1\],withciσ=1c\_\{i\}^\{\\sigma\}=1by convention whenΛtiσ=∅\\Lambda^\{\\sigma\}\_\{t\_\{i\}\}=\\emptyset\. The*combined*completeness of a run overNNvoters, by averaging, is \(3\)c¯=12N∑i=1N\(ci\+\+ci−\)\.\\bar\{c\}\\;=\\;\\frac\{1\}\{2N\}\\sum\_\{i=1\}^\{N\}\\bigl\(c\_\{i\}^\{\+\}\+c\_\{i\}^\{\-\}\\bigr\)\. Completeness is defined per voter and per side, and \([3](https://arxiv.org/html/2608.23979#S3.E3)\) aggregates a voter’s two values by averaging them\. Averaging permits compensation: a slate that covers one side well and the other badly scores the same as one that covers both indifferently\. A flooding coalition attacks one side, so this is precisely the configuration in which the reported number and the experienced one can come apart\. We therefore also run evaluations with the average over a voter’s two sides replaced by the minimum, \(4\)cimin=min\(ci\+,ci−\),c¯min=1N∑i=1Ncimin,c\_\{i\}^\{\\min\}\\;=\\;\\min\\bigl\(c\_\{i\}^\{\+\},\\,c\_\{i\}^\{\-\}\\bigr\),\\qquad\\bar\{c\}^\{\\min\}\\;=\\;\\frac\{1\}\{N\}\\sum\_\{i=1\}^\{N\}c\_\{i\}^\{\\min\},under which a voter is served exactly as well as their worse\-covered side and is granted no credit for coverage they did not lose\. Two properties of \([2](https://arxiv.org/html/2608.23979#S3.E2)\) deserve to be stated here rather than discovered later, because between them they account for the entire narrative arc of Section[8](https://arxiv.org/html/2608.23979#S8)\. ### 3\.3\.Three instruments: coverage, order, and endorsement mass A slate is a sequence, presented to a person with finite attention, drawn from a corpus the electorate has already expressed opinions about\. Each clause supports a different question about whether the slate was well chosen, and we report all three because Section[8](https://arxiv.org/html/2608.23979#S8)shows they disagree in ways that matter\. #### Instrument I: coverage\. Completenessc¯\\bar\{c\}per Definition[3\.4](https://arxiv.org/html/2608.23979#S3.Thmtheorem4)\. It answers:*were the reasons in play represented at all?*It is the natural formalisation of the balance requirement inherited from deliberative polling, and it is order\-blind and charity\-blind per Remarks[1](https://arxiv.org/html/2608.23979#Thmremark1)–[2](https://arxiv.org/html/2608.23979#Thmremark2)\. #### Instrument II: order\. Real readers do not consume slates uniformly\. LetSiσ=⟨j1,…,jK⟩S\_\{i\}^\{\\sigma\}=\\langle j\_\{1\},\\dots,j\_\{K\}\\ranglenow be an ordered slate, and define the*prefix coverage*at depthmm, \(5\)piσ\(m\)=\|⋃u≤mλ\(ju\)\|\|Λtiσ\|,m=1,…,K,p^\{\\sigma\}\_\{i\}\(m\)\\;=\\;\\frac\{\\bigl\|\\ \\bigcup\_\{u\\leq m\}\\lambda\(j\_\{u\}\)\\ \\bigr\|\}\{\\bigl\|\\ \\Lambda^\{\\sigma\}\_\{t\_\{i\}\}\\ \\bigr\|\},\\qquad m=1,\\dots,K,so thatpiσ\(K\)=ciσp^\{\\sigma\}\_\{i\}\(K\)=c^\{\\sigma\}\_\{i\}recovers Instrument I\. From the prefix profile we take three summaries\. The*area under the prefix curve*AUCiσ=K−1∑m=1Kpiσ\(m\)\\mathrm\{AUC\}^\{\\sigma\}\_\{i\}=K^\{\-1\}\\sum\_\{m=1\}^\{K\}p^\{\\sigma\}\_\{i\}\(m\)is the coverage enjoyed by a reader who stops at a uniformly random depth\. The*rank\-discounted coverage*weights each reason by where it first appears, \(6\)RDCiσ=\(∑t≤\|Λtiσ\|1log2\(1\+t\)\)−1∑ℓ∈Λtiσ𝟙\[ℓserved\]log2\(1\+posiσ\(ℓ\)\),\\mathrm\{RDC\}^\{\\sigma\}\_\{i\}\\;=\\;\\Bigl\(\\textstyle\\sum\_\{t\\leq\|\\Lambda^\{\\sigma\}\_\{t\_\{i\}\}\|\}\\tfrac\{1\}\{\\log\_\{2\}\(1\+t\)\}\\Bigr\)^\{\-1\}\\sum\_\{\\ell\\in\\Lambda^\{\\sigma\}\_\{t\_\{i\}\}\}\\frac\{\\mathbb\{1\}\[\\ell\\text\{ served\}\]\}\{\\log\_\{2\}\\bigl\(1\+\\mathrm\{pos\}\_\{i\}^\{\\sigma\}\(\\ell\)\\bigr\)\},where𝟙\[ℓserved\]\\mathbb\{1\}\[\\ell\\text\{ served\}\]is an indicator function evaluating to11if the reasonℓ\\ellappears on at least one item of the slate served to voteriion sideσ\\sigma, and00otherwise,posiσ\(ℓ\)\\mathrm\{pos\}\_\{i\}^\{\\sigma\}\(\\ell\)is the position of the first slate item carryingℓ\\elland the normaliser is the value a slate would attain by covering the whole live vocabulary as early as positions allow, the normalizer being replaced with 1 at the beginning when that is needed to avoid division by 0\. Finallye90e\_\{90\}is the smallest levelmmwithpiσ\(m\)≥0\.9ciσp^\{\\sigma\}\_\{i\}\(m\)\\geq 0\.9\\,c^\{\\sigma\}\_\{i\}— how deep the reader must go to obtain nine tenths of what that slate was ever going to give them\. Instrument II answers:*did the coverage arrive early enough to be read?* #### Instrument III: endorsement mass\. A slate can cover the vocabulary while serving nothing that any constituent actually adopted\. Define \(7\)Miσ=∑j∈Siσωc\(j\)max∑j∈TT⊆𝒥σ∩𝒥ti,\|T\|≤Kωc\(j\),\\mathrm\{M\}^\{\\sigma\}\_\{i\}\\;=\\;\\frac\{\\sum\_\{j\\in S^\{\\sigma\}\_\{i\}\}\\omega\_\{\\mathrm\{c\}\}\(j\)\}\{\\max\_\{\\,T\\subseteq\\mathcal\{J\}^\{\\sigma\}\\cap\\mathcal\{J\}\_\{t\_\{i\}\},\\ \|T\|\\leq K\}\\ \\sum\_\{j\\in T\}\\omega\_\{\\mathrm\{c\}\}\(j\)\},the share of the maximum achievable endorsement weight that the served slate captured\. Instrument III answers:*did the slate show the voter what the electorate had actually taken up?*It is the axis on which Section[8\.5](https://arxiv.org/html/2608.23979#S8.SS5)finds the random baseline dominated by a factor of3\.33\.3, and the axis on which the greedy oracle of Section[3\.5](https://arxiv.org/html/2608.23979#S3.SS5)stops dominating under attack\. Nothing in the design privileges one instrument: Section[8\.5](https://arxiv.org/html/2608.23979#S8.SS5)treats them jointly, as a frontier over which a participant — not the system — chooses a position, and that this is even expressible is a consequence of Criterion[7](https://arxiv.org/html/2608.23979#Thmcriterion7)\(configurability, Section[4\.2](https://arxiv.org/html/2608.23979#S4.SS2)\)\. ### 3\.4\.The Subsuming Justification Problem Instrument I induces a combinatorial problem which we name and characterise, both because it locates the construction in complexity terms and because its hardness is what licenses the greedy bound of the next subsection\. Say thatS⊆𝒥σS\\subseteq\\mathcal\{J\}^\{\\sigma\}*subsumes*a target vocabularyL⊆ΛL\\subseteq\\Lambdawhen⋃j∈Sλ\(j\)⊇L\\bigcup\_\{j\\in S\}\\lambda\(j\)\\supseteq L\. ###### Definition 3\.5 \(Subsuming Justification Problem, SJP\)\. *Instance:*a labelled justification set\(𝒥σ,λ\)\(\\mathcal\{J\}^\{\\sigma\},\\lambda\), a targetL⊆ΛσL\\subseteq\\Lambda^\{\\sigma\}, and a budgetK∈ℕK\\in\\mathbb\{N\}\.*Question:*does someS⊆𝒥σS\\subseteq\\mathcal\{J\}^\{\\sigma\}with\|S\|≤K\|S\|\\leq KsubsumeLL? ###### Proposition 3\.6\. SJP isNP\-complete\. ###### Proof\. Membership: a certificateSSwith\|S\|≤K\|S\|\\leq Kis verified by computing⋃j∈Sλ\(j\)\\bigcup\_\{j\\in S\}\\lambda\(j\)and testing containment ofLL, in time linear in∑j∈S\|λ\(j\)\|\\sum\_\{j\\in S\}\|\\lambda\(j\)\|\. Hardness: reduce fromSet Cover[Karp, 1972](https://arxiv.org/html/2608.23979#bib.bibx49)\. Given a universeUU, a familyℱ=\{F1,…,Fn\}\\mathcal\{F\}=\\\{F\_\{1\},\\dots,F\_\{n\}\\\}of subsets ofUU, and a budgetKK, putΛ=U\\Lambda=U, create one justificationjrj\_\{r\}perFrF\_\{r\}withλ\(jr\)=Fr\\lambda\(j\_\{r\}\)=F\_\{r\}, setL=UL=U, and keep the budget\. AnySSof size≤K\\leq KsubsumingUUmaps to a cover of size≤K\\leq Kand conversely; the construction is linear in the instance size\. ∎ Two variants matter operationally\.*Weighted SJP*addsμ:Λ→ℝ≥0\\mu:\\Lambda\\to\\mathbb\{R\}\_\{\\geq 0\}and a thresholdτ\\tauand asks whether someSSwith\|S\|≤K\|S\|\\leq Kattainsμ\(⋃j∈Sλ\(j\)\)≥τ\\mu\(\\bigcup\_\{j\\in S\}\\lambda\(j\)\)\\geq\\tau; it inherits hardness atμ≡1\\mu\\equiv 1,τ=\|L\|\\tau=\|L\|, and its interest is normative rather than computational, sinceμ\\muis where a deployment would encode that some reasons must not be crowded out — minority\-held reasons, statutory considerations — exactly the kind of parameter that must be published in advance rather than learned, a learnedμ\\mubeing an unaccountable editorial line\.*Componentwise SJP*reflects that a slate covering one side well and the other badly is not balanced: given budgetsK\+,K−K^\{\+\},K^\{\-\}and targetsL\+,L−L^\{\+\},L^\{\-\}, it asks forS\+,S−S^\{\+\},S^\{\-\}with\|Sσ\|≤Kσ\|S^\{\\sigma\}\|\\leq K^\{\\sigma\}subsumingLσL^\{\\sigma\}for bothσ\\sigma\. Since the two sides share no items it decomposes into two independent SJP instances — which is why \([3](https://arxiv.org/html/2608.23979#S3.E3)\) averages per\-side completeness rather than pooling the vocabularies: pooling would let a slate compensate a neglected side with an over\-covered one, the opposite of balance\. ### 3\.5\.The greedy ceiling, and the discipline governing its use Since coverage is the objective of anNP\-hard problem, an exact optimum is not an available comparator\. A standard bound is, and it happens to be tight enough to be informative\. Given\(𝒥σ∩𝒥ti,λ\)\(\\mathcal\{J\}^\{\\sigma\}\\cap\\mathcal\{J\}\_\{t\_\{i\}\},\\lambda\), targetΛtiσ\\Lambda^\{\\sigma\}\_\{t\_\{i\}\}and budgetKK, the*greedy cover*selects,KKtimes, the item maximising the number of not\-yet\-covered reasons it contributes, breaking ties by a published deterministic key\. ###### Proposition 3\.7\. The reason countf\(S\)=\|⋃j∈Sλ\(j\)\|f\(S\)=\|\\bigcup\_\{j\\in S\}\\lambda\(j\)\|is monotone and submodular, so the greedy cover attains at least\(1−e−1\)≈0\.632\(1\-e^\{\-1\}\)\\approx 0\.632of the optimal value at budgetKK[Nemhauser et al\., 1978](https://arxiv.org/html/2608.23979#bib.bibx69), and no polynomial\-time algorithm improves the ratio unlessP=NP\\textsf\{P\}=\\textsf\{NP\}[Feige, 1998](https://arxiv.org/html/2608.23979#bib.bibx40);[Hochbaum, 1997](https://arxiv.org/html/2608.23979#bib.bibx47)\. ###### Proof\. Monotonicity is immediate\. For submodularity, takeS⊆TS\\subseteq Tandj∉Tj\\notin T; thenf\(S∪\{j\}\)−f\(S\)=\|λ\(j\)∖⋃k∈Sλ\(k\)\|≥\|λ\(j\)∖⋃k∈Tλ\(k\)\|=f\(T∪\{j\}\)−f\(T\)f\(S\\cup\\\{j\\\}\)\-f\(S\)=\|\\lambda\(j\)\\setminus\\bigcup\_\{k\\in S\}\\lambda\(k\)\|\\geq\|\\lambda\(j\)\\setminus\\bigcup\_\{k\\in T\}\\lambda\(k\)\|=f\(T\\cup\\\{j\\\}\)\-f\(T\), since the subtracted set is larger\. The bound and its optimality follow\. ∎ The greedy cover readsλ\\lambdadirectly — a semantic operation requiring the selector to know what each item is about and to choose items for what they say\. It therefore violates Criterion[4](https://arxiv.org/html/2608.23979#Thmcriterion4)\(semantic abstinence\) outright, and because it must inspect every candidate’s labels it also fails Criterion[2](https://arxiv.org/html/2608.23979#Thmcriterion2)\(evidence locality\); both are stated with their tests in Section[4\.2](https://arxiv.org/html/2608.23979#S4.SS2)\. It is not a candidate mechanism, yet we compare against it constantly, which requires stating the discipline explicitly\. ###### Principle 1 \(Oracle discipline\)\. Like the labels, the greedy cover appears in this manuscript only on the evaluation path\. It is computed offline, from the persisted database, after the poll has closed\. No agent ever sees a slate it produced; no served slate was ever influenced by it; it is not proposed, and could not be adopted, as a deployable selection rule\. Its role is to answer one question that no admissible mechanism can answer about itself:*how much coverage was available in this pool at all?* Principle[1](https://arxiv.org/html/2608.23979#Thmprinciple1)is what makes the number in Section[7\.3](https://arxiv.org/html/2608.23979#S7.SS3)meaningful\. Because the greedy cover reads the labels, its coverage upper\-bounds — to within the0\.6320\.632factor, and in practice far more tightly — what*any*selection procedure applied to the same pool could have achieved, including an arbitrarily good opaque learned ranker\. The gap between the served slates and that ceiling is therefore not the price of our particular rule against some better rule; it is the price of the entire admissible class against the unreachable best case, and Section[7\.3](https://arxiv.org/html/2608.23979#S7.SS3)measures it at0\.031±0\.0140\.031\\pm 0\.014\. ### 3\.6\.Reach: what a slate can be held responsible for A rule that reads only endorsements and one\-hop links cannot serve what it cannot see\. Making that horizon explicit turns a limitation into a specification\. The*reach*of a justificationjjat timettisρt\(j\)=\{j\}∪\{k:\(j,k\)∈ℛ⊖∪ℛ⊕,k∈𝒥t\}\\rho\_\{t\}\(j\)=\\\{j\\\}\\cup\\\{\\,k:\(j,k\)\\in\\mathcal\{R\}^\{\\ominus\}\\cup\\mathcal\{R\}^\{\\oplus\},\\ k\\in\\mathcal\{J\}\_\{t\}\\,\\\}, andjjis*visible to the rule*atttifωc\(j\)\>0\\omega\_\{\\mathrm\{c\}\}\(j\)\>0orωc\(k\)\>0\\omega\_\{\\mathrm\{c\}\}\(k\)\>0for somek∈ρt\(j\)k\\in\\rho\_\{t\}\(j\)\. ###### Proposition 3\.8 \(Partial\-replica sufficiency\)\. Evaluating the endorsement rule of Section[4\.4](https://arxiv.org/html/2608.23979#S4.SS4)for the items in a candidate poolPPrequires only the endorsement counts of⋃j∈Pρt\(j\)\\bigcup\_\{j\\in P\}\\rho\_\{t\}\(j\)and the link tuples out ofPP\. It requires no global view of𝒥\\mathcal\{J\},ℛ⊖\\mathcal\{R\}^\{\\ominus\}orℛ⊕\\mathcal\{R\}^\{\\oplus\}\. This is immediate from the score \([8](https://arxiv.org/html/2608.23979#S4.E8)\) given in Section[4\.4](https://arxiv.org/html/2608.23979#S4.SS4): the score ofjjis a function ofωc\(j\)\\omega\_\{\\mathrm\{c\}\}\(j\)and ofωc\(k\)\\omega\_\{\\mathrm\{c\}\}\(k\)forkkranging overjj’s out\-neighbours only\. Proposition[3\.8](https://arxiv.org/html/2608.23979#S3.Thmtheorem8)is the technical fact that makes Section[10](https://arxiv.org/html/2608.23979#S10)possible\. A peer holding a partial replica computes exactly the same scores for the items it holds as a peer holding everything, which is what allows every participant to run the rule themselves rather than trust an operator to run it for them\. It also delimits responsibility: a brand\-new item with no endorsements and no incoming links from endorsed material is invisible to the rule, and no amount of tuning changes that\. Cold\-start items surface when someone reads them — which is what the authoring\-side random exploration of Section[5\.2](https://arxiv.org/html/2608.23979#S5.SS2)is for — and not before\. ### 3\.7\.A worked example The following instance is small enough to check by hand and exhibits every phenomenon the experiments will measure at scale\. ###### Example 3\.9 \(Municipal night\-bus extension\)\. A city puts to its residents:*extend the night\-bus network to the outer districts?*At the moment residentrropens the ballot, the supporting side holds five justifications and the opposing side four\. Labels are drawn from a published vocabulary; endorsement countsωc\\omega\_\{\\mathrm\{c\}\}are the public tallies\. Both live vocabularies have five reasons, so\|Λ\+\|=\|Λ−\|=5\|\\Lambda^\{\+\}\|=\|\\Lambda^\{\-\}\|=5\. The links asserted so far are\(s3,o1\)∈ℛ⊖\(s\_\{3\},o\_\{1\}\)\\in\\mathcal\{R\}^\{\\ominus\}\(marginal cost tells against the subsidy objection\),\(s4,s1\)∈ℛ⊕\(s\_\{4\},s\_\{1\}\)\\in\\mathcal\{R\}^\{\\oplus\},\(s2,o3\)∈ℛ⊖\(s\_\{2\},o\_\{3\}\)\\in\\mathcal\{R\}^\{\\ominus\},\(o2,s1\)∈ℛ⊖\(o\_\{2\},s\_\{1\}\)\\in\\mathcal\{R\}^\{\\ominus\}and\(o4,o1\)∈ℛ⊕\(o\_\{4\},o\_\{1\}\)\\in\\mathcal\{R\}^\{\\oplus\}\. The display budget isK=2K=2per side\. What each procedure serves\.Take the rule of Section[4\.4](https://arxiv.org/html/2608.23979#S4.SS4)at the reference policyα=β=0\.5\\alpha=\\beta=0\.5,ωr≡1\\omega\_\{\\mathrm\{r\}\}\\equiv 1\. On the supporting side,sc\(s1\)=46\\mathrm\{sc\}\(s\_\{1\}\)=46,sc\(s2\)=31\+0\.5⋅9=35\.5\\mathrm\{sc\}\(s\_\{2\}\)=31\+0\.5\\cdot 9=35\.5,sc\(s3\)=12\+0\.5⋅39=31\.5\\mathrm\{sc\}\(s\_\{3\}\)=12\+0\.5\\cdot 39=31\.5,sc\(s4\)=4\+0\.5⋅46=27\\mathrm\{sc\}\(s\_\{4\}\)=4\+0\.5\\cdot 46=27,sc\(s5\)=3\\mathrm\{sc\}\(s\_\{5\}\)=3\. The rule serves⟨s1,s2⟩\\langle s\_\{1\},s\_\{2\}\\rangle, covering\{access,equity,safety\}\\\{\\textsc\{access\},\\textsc\{equity\},\\textsc\{safety\}\\\}: completeness3/5=0\.603/5=0\.60, prefix profilep\(1\)=0\.40p\(1\)=0\.40,p\(2\)=0\.60p\(2\)=0\.60\. The greedy cover reads labels and serves\{s1,s3\}\\\{s\_\{1\},s\_\{3\}\\\}or\{s1,s5\}\\\{s\_\{1\},s\_\{5\}\\\}— also0\.600\.60, since no pair here exceeds three reasons\. A uniform draw serves2\.42\.4distinct reasons in expectation, i\.e\. completeness0\.480\.48\. Where the instruments diverge\.Let the draw return\{s1,s5\}\\\{s\_\{1\},s\_\{5\}\\\}, which it does as often as any other pair: its coverage is3/53/5, equal to the rule’s, so on Instrument I the two procedures are indistinguishable on this run\. On Instrument III they are not: the rule capturesM\+=77/77=1\.00\\mathrm\{M\}^\{\+\}=77/77=1\.00against49/77=0\.6449/77=0\.64for\{s1,s5\}\\\{s\_\{1\},s\_\{5\}\\\}and15/77=0\.1915/77=0\.19for\{s3,s5\}\\\{s\_\{3\},s\_\{5\}\\\}\. The voter shown\{s3,s5\}\\\{s\_\{3\},s\_\{5\}\\\}met two reasons four of their neighbours had ever endorsed; the voter shown⟨s1,s2⟩\\langle s\_\{1\},s\_\{2\}\\ranglemet the two that seventy\-seven had\. Where the link terms earn their place\.Items3s\_\{3\}ranks fourth on its own endorsements and is promoted to third by the rebuttal coefficient because it speaks to the most endorsed item on the*other*side — but ranking on endorsements alone would place it third as well\. That is the inertia of Section[8\.1](https://arxiv.org/html/2608.23979#S8.SS1)in miniature: on a uniformly competent corpus the link terms reorder items that were already adjacent\. Now replaces5s\_\{5\}by a submissions5′s\_\{5\}^\{\\prime\}carrying the labelclimateand no actual reason: a sentence of agreement, correctly labelled, endorsed by nobody, asserting no links\. Coverage is blind to the substitution, so a uniform draw servess5′s\_\{5\}^\{\\prime\}exactly as often as it serveds5s\_\{5\}; the rule scores it00, both because nobody endorsed it and because it points at nothing anyone endorsed\. That double penalty — the*squaring*of discrimination measured in Section[8\.4](https://arxiv.org/html/2608.23979#S8.SS4)— is invisible here only because the instance contains one such item\. At the fractions Section[8\.3](https://arxiv.org/html/2608.23979#S8.SS3)reports it is worth as much as the whole ranking advantage\. ## 4\.The Charter: Criteria Before Objectives This section states what a selection mechanism must satisfy to be used in a binding civic process, and exhibits a rule that satisfies it\. The order of presentation within this section is itself part of the argument: the criteria come before the rule, as conditions on the admissible class, and the rule follows as one member of that class chosen for its simplicity\. We begin with what opacity costs in concrete operational terms, state the seven criteria with their tests, argue that they are prior to rather than commensurable with measured quality, give the rule, isolate the one line of it that is a security control, and close on how per\-voter configuration is possible without dissolving the shared record\. ### 4\.1\.What opacity costs, concretely The case against an opaque selector here is not that such systems are inaccurate; it is that some operations a civic process requires become impossible, and it is worth naming them as operations rather than as values\. *Recomputation*: a participant who disputes a slate should be able to obtain the same slate from the same inputs, which with published weights over public evidence is arithmetic, whereas with a learned selector the participant would need the model, its parameters, the exact feature vector at serving time and the personalisation state — and even a cooperative operator disclosing all four supplies a recomputation nobody outside can independently verify was the one actually run\. *Attribution*: when a slate is wrong, a process needs to say which input made it wrong, and under the rule of Section[4\.4](https://arxiv.org/html/2608.23979#S4.SS4)the answer is a term — this item ranked here because it carried these endorsements and pointed at those items — whereas under a learned ranker the answer is that the output is a function of the training distribution, post\-hoc attribution methods producing explanations that are themselves unverifiable[Rudin, 2019](https://arxiv.org/html/2608.23979#bib.bibx83);[Lipton, 2018](https://arxiv.org/html/2608.23979#bib.bibx56); surveys of explainability for supervised learning make the gap between an explanation and a derivation plain[Burkart & Huber, 2021](https://arxiv.org/html/2608.23979#bib.bibx18)\. *Explanation*: a voter is owed an account of why*their*slate contains what it contains, and that account must be the computation rather than a story fitted to it\. Under the rule it is the score read aloud and cannot drift from the mechanism because it is the mechanism, whereas a learned selector explains itself through a second model whose account is plausible to the recipient rather than identical to the computation that ran[Caro\-Martínez et al\., 2021](https://arxiv.org/html/2608.23979#bib.bibx24)\. An explanation a voter cannot check against the public record is indistinguishable from persuasion\. *Contest*: a dispute must terminate, and under the rule it terminates in one of three ways — an endorsement tally is wrong and tallies are public, a link is wrong and links are signed by their authors, or the policy is wrong and that is a political argument conducted in the open — whereas under an opaque selector the dispute has no terminating move, which converts every disagreement about content into a standing grievance about the operator\. emphBounded drift: a published rule changes when someone changes it and the change is a diff, whereas a learned selector changes whenever it is retrained, whenever the population shifts and whenever a feature pipeline is updated, so its behaviour last month is not recoverable — and a civic record that cannot be reconstructed a year later is not a record\. None of these costs is offset by better ranking, because none is a ranking property\. This is the structural reason the criteria below are stated as admissibility conditions rather than as objectives to be weighed, and it is also where this construction parts company with the fairness\-and\-accountability literature that treats such properties as quantities to optimise: proposals for socially responsible AI[Cheng et al\., 2021](https://arxiv.org/html/2608.23979#bib.bibx31)and critiques of fairness as a single formal target[Weinberg, 2022](https://arxiv.org/html/2608.23979#bib.bibx104)both proceed by asking what a system should maximise, whereas the question here is which systems may be used at all\. ### 4\.2\.Seven criteria, with their tests Each criterion below is stated so that an auditor can check it against an implementation, together with the observable that would show it violated\. They are numbered for reference throughout the rest of this manuscript; every subsequent design decision is annotated with the criterion it discharges\. ###### Criterion 1 \(Determinism\)\. Given the same evidence and the same policy vector, the mechanism returns the same slate\.*Test:*run it twice on a frozen snapshot; the outputs are identical, ties included\.*Violation looks like:*two participants with identical configurations and identical local data seeing different slates, with no published reason\. ###### Criterion 2 \(Evidence locality\)\. The score of an item depends only on that item and on a bounded, explicitly specified neighbourhood of it\.*Test:*perturb an item outside the declared neighbourhood; the score does not move\.*Violation looks like:*a global fixed point, or any quantity whose value depends on the whole corpus, which makes both partial\-replica evaluation and local reasoning about a dispute impossible\. ###### Criterion 3 \(Author blindness\)\. No term in the score refers to who wrote an item, beyond counting*distinct*authors where a policy explicitly calls for it\.*Test:*permute author identities across items; the ranking is invariant\.*Violation looks like:*reputation, seniority, or verified\-account status entering the ranking — reintroducing the influence hierarchy that a poll is supposed to flatten\. ###### Criterion 4 \(Semantic abstinence\)\. The serving\-time mechanism does not read the content of items\.*Test:*replace every item’s text with an opaque identifier; the slate is unchanged\.*Violation looks like:*the selector deciding, at serving time, what an argument means or whether it is any good — which is the specific authority a civic slate must not delegate, and which the greedy cover of Section[3\.5](https://arxiv.org/html/2608.23979#S3.SS5)openly exercises, hence Principle[1](https://arxiv.org/html/2608.23979#Thmprinciple1)\. ###### Criterion 5 \(Reproducibility\)\. Every served slate is recomputable after the fact from persisted evidence\.*Test:*from the archive, reconstruct any historical slate exactly, including the state of the corpus at that instant\.*Violation looks like:*an audit that can establish what was tallied but not what was shown\. ###### Criterion 6 \(Contestability\)\. Every slate decomposes into named contributions, each traceable to a public artefact\.*Test:*for any served item, produce the list of\(term,evidence,value\)\(\\text\{term\},\\text\{evidence\},\\text\{value\}\)triples summing to its score\.*Violation looks like:*an explanation that is itself a model output\. ###### Criterion 7 \(Configurability\)\. The policy parameters are held by the individual participant receiving it, not by the operator, and the participant can change them and observe the effect\.*Test:*two participants with different policies, same evidence, obtain different and separately correct slates\.*Violation looks like:*a single operator\-chosen ranking presented as neutral, or a personalisation the participant cannot inspect or switch off\. Table[1](https://arxiv.org/html/2608.23979#S4.T1)summarises how three mechanism families fare\. The pattern is not that learned rankers score lower; it is that they are disqualified on four criteria at once, by construction rather than by implementation quality\. Table 1\.The seven criteria against three mechanism families\.–denotes failure by construction rather than by implementation choice: no amount of engineering effort within that family recovers the property\. The greedy cover is included because it appears throughout the evaluation and it is important to be explicit that it is inadmissible; see Principle[1](https://arxiv.org/html/2608.23979#Thmprinciple1)\. ### 4\.3\.Why this is not an empirical hypothesis A natural objection runs:*the assertion that rule\-based selection is preferable, is never tested against a learned alternative\.*The objection is well formed and the answer governs how the rest of the results should be read\. The claim is normative and it is a claim about admissibility: a mechanism that cannot be recomputed, attributed, explained, contested or reconstructed is unsuitable for a binding civic process — not that it ranks worse\. A comparison against a learned ranker would report a difference in coverage or in some downstream engagement statistic, and whatever number came out could not bear on the claim, since a learned ranker covering*more*of the live vocabulary would still fail C[2](https://arxiv.org/html/2608.23979#Thmcriterion2), C[4](https://arxiv.org/html/2608.23979#Thmcriterion4), C[5](https://arxiv.org/html/2608.23979#Thmcriterion5)and C[6](https://arxiv.org/html/2608.23979#Thmcriterion6)and would still leave a disputing participant with no terminating move\. The structure is familiar from other civic procedures\. The secret ballot is not defended on the grounds that it measures preferences more accurately than open voting — it plainly measures some things less well, since it destroys the ability to audit an individual’s vote — but because the procedure must possess a property that outranks measurement quality\. Double\-entry bookkeeping is not the most compact representation of a firm’s accounts; rules of order do not produce the fastest decisions\. In each case a procedural property is treated as prior, and efficiency questions are settled*within*the class of procedures that possess it\. What is legitimately empirical, and what this manuscript tests, is everything downstream of that commitment:*how much does the commitment cost?*, answered against a ceiling that upper\-bounds every mechanism including inadmissible ones \(Section[7\.3](https://arxiv.org/html/2608.23979#S7.SS3)\);*which terms of the rule earn their place?*, answered by ablation, including the finding that two of them earn nothing on a charitable corpus and a great deal on a realistic one \(Sections[8\.1](https://arxiv.org/html/2608.23979#S8.SS1)and[8\.3](https://arxiv.org/html/2608.23979#S8.SS3)\);*which policy choices are security controls?*, answered by adversarial sweep \(Section[9\.2](https://arxiv.org/html/2608.23979#S9.SS2)\); and*where does the choice between configurations actually lie?*, answered by a frontier rather than an optimum \(Section[8\.5](https://arxiv.org/html/2608.23979#S8.SS5)\)\. ### 4\.4\.The endorsement rule We now give a mechanism satisfying all seven criteria\. Its simplicity is a feature\. ###### Definition 4\.1 \(Endorsement rule\)\. LetE\(j\)=ωc\(j\)E\(j\)=\\omega\_\{\\mathrm\{c\}\}\(j\)be the endorsement count of itemjj\. Given a policy vectorθ=\(α,β,ωr\)\\theta=\(\\alpha,\\beta,\\omega\_\{\\mathrm\{r\}\}\)withα,β∈ℝ\\alpha,\\beta\\in\\mathbb\{R\}, the*endorsement score*ofjjat timettis \(8\)scθ\(j\)=E\(j\)\+α∑\(j,k\)∈ℛ⊕,k∈𝒥tωr\(j,k\)E\(k\)\+β∑\(j,k\)∈ℛ⊖,k∈𝒥tωr\(j,k\)E\(k\)\.\\mathrm\{sc\}\_\{\\theta\}\(j\)\\;=\\;E\(j\)\\;\+\\;\\alpha\\\!\\\!\\sum\_\{\(j,k\)\\in\\mathcal\{R\}^\{\\oplus\},\\ k\\in\\mathcal\{J\}\_\{t\}\}\\\!\\\!\\omega\_\{\\mathrm\{r\}\}\(j,k\)\\,E\(k\)\\;\+\\;\\beta\\\!\\\!\\sum\_\{\(j,k\)\\in\\mathcal\{R\}^\{\\ominus\},\\ k\\in\\mathcal\{J\}\_\{t\}\}\\\!\\\!\\omega\_\{\\mathrm\{r\}\}\(j,k\)\\,E\(k\)\.The slate served to voteriion sideσ\\sigmais the top\-KKof𝒥σ∩𝒥ti\\mathcal\{J\}^\{\\sigma\}\\cap\\mathcal\{J\}\_\{t\_\{i\}\}byscθi\\mathrm\{sc\}\_\{\\theta\_\{i\}\}, ties broken by a published deterministic key \(ascending item identifier\)\. The direction of both summands is the load\-bearing detail and is easy to get backwards\. An item is credited for the endorsements of what it*points at*, not for links pointing at it\. An item that rebuts a heavily endorsed objection is thereby promoted, because a voter about to accept that objection has a specific interest in seeing the response to it; and an item reinforcing a heavily endorsed claim is promoted because it deepens material the electorate has already taken up\. Reversing the direction would reward being talked about, which is the property a coordinated group can manufacture most cheaply — and it is why the eigenvector family, which propagates credit backwards along links to a fixed point[Page et al\., 1999](https://arxiv.org/html/2608.23979#bib.bibx71), is structurally exposed to link farms in a way Equation \([8](https://arxiv.org/html/2608.23979#S4.E8)\) is not\. Section[9\.1](https://arxiv.org/html/2608.23979#S9.SS1)confirms this: a coalition that constructs a hub and points the whole corpus at it gains nothing measurable\. The rule discharges the charter as follows\. It is a closed\-form arithmetic expression over integers and published constants, hence C[1](https://arxiv.org/html/2608.23979#Thmcriterion1)\. It readsjjandjj’s out\-neighbours and nothing else, hence C[2](https://arxiv.org/html/2608.23979#Thmcriterion2), which by Proposition[3\.8](https://arxiv.org/html/2608.23979#S3.Thmtheorem8)is also what makes per\-peer evaluation more possible\. No term names an author, and where a policy counts authors it counts*distinct*ones without regard to which, hence C[3](https://arxiv.org/html/2608.23979#Thmcriterion3)\. No term reads text, hence C[4](https://arxiv.org/html/2608.23979#Thmcriterion4)— note thatλ\\lambdaappears nowhere in \([8](https://arxiv.org/html/2608.23979#S4.E8)\); labels are used to*evaluate*slates and never to choose them, exactly the asymmetry Principle[1](https://arxiv.org/html/2608.23979#Thmprinciple1)protects\. Persisting endorsements and links with timestamps makes every historical slate recomputable, hence C[5](https://arxiv.org/html/2608.23979#Thmcriterion5)\. And each of the three summands is separately displayable against the artefacts that produced it, hence C[6](https://arxiv.org/html/2608.23979#Thmcriterion6)\. C[7](https://arxiv.org/html/2608.23979#Thmcriterion7)is the subject of Section[4\.6](https://arxiv.org/html/2608.23979#S4.SS6)\. Algorithm[1](https://arxiv.org/html/2608.23979#algorithm1)states the serving procedure for a peer holding a partial replica\. Algorithm 1ScoreAndServe— serve a slate for one voter on one sideGiven:candidate pool P⊆𝒥σ∩𝒥tP\\subseteq\\mathcal\{J\}^\{\\sigma\}\\cap\\mathcal\{J\}\_\{t\}; endorsement counts EEon P∪⋃j∈Pρt\(j\)P\\cup\\bigcup\_\{j\\in P\}\\rho\_\{t\}\(j\); out\-links of PP; voter policy θ=\(α,β,ωr\)\\theta=\(\\alpha,\\beta,\\omega\_\{\\mathrm\{r\}\}\); budget KK Yields:ordered slate ⟨j1,…,jmin\(K,\|P\|\)⟩\\langle j\_\{1\},\\dots,j\_\{\\min\(K,\|P\|\)\}\\rangleand, for each, its score decomposition 1foreach*j∈Pj\\in P*do 2 a←∑\(j,k\)∈ℛ⊕,k∈𝒥tωr\(j,k\)E\(k\)a\\leftarrow\\sum\_\{\(j,k\)\\in\\mathcal\{R\}^\{\\oplus\},\\,k\\in\\mathcal\{J\}\_\{t\}\}\\omega\_\{\\mathrm\{r\}\}\(j,k\)\\,E\(k\); 3 r←∑\(j,k\)∈ℛ⊖,k∈𝒥tωr\(j,k\)E\(k\)r\\leftarrow\\sum\_\{\(j,k\)\\in\\mathcal\{R\}^\{\\ominus\},\\,k\\in\\mathcal\{J\}\_\{t\}\}\\omega\_\{\\mathrm\{r\}\}\(j,k\)\\,E\(k\); 4 sc\[j\]←E\(j\)\+αa\+βr\\mathrm\{sc\}\[j\]\\leftarrow E\(j\)\+\\alpha a\+\\beta r; 5 why\[j\]←⟨\(own,E\(j\)\),\(reinforces,αa\),\(rebuts,βr\)⟩\\mathrm\{why\}\[j\]\\leftarrow\\bigl\\langle\(\\textsf\{own\},E\(j\)\),\\ \(\\textsf\{reinforces\},\\alpha a\),\\ \(\\textsf\{rebuts\},\\beta r\)\\bigr\\rangle; 6end foreach 7sort PPby sc\\mathrm\{sc\}descending, ties by ascending identifier; 8returnthe first min\(K,\|P\|\)\\min\(K,\|P\|\)items of PPwith their why\\mathrm\{why\}records; Note that Algorithm[1](https://arxiv.org/html/2608.23979#algorithm1)returns the decomposition alongside the slate rather than offering it on request\. Contestability that must be asked for is contestability most participants never exercise; the interface of Section[5\.6](https://arxiv.org/html/2608.23979#S5.SS6)shows the terms next to each served item\. ### 4\.5\.The weight policy is the whole game Equation \([8](https://arxiv.org/html/2608.23979#S4.E8)\) has three policy parameters and they are not of equal consequence\. Varyingα\\alphaandβ\\betaacross their plausible range moves completeness by amounts we could not distinguish from noise in the attack\-free regime \(Section[8\.1](https://arxiv.org/html/2608.23979#S8.SS1)\); changingωr\\omega\_\{\\mathrm\{r\}\}as seen next moves it by0\.080\.08–0\.120\.12under coordinated attack \(Section[9\.2](https://arxiv.org/html/2608.23979#S9.SS2)\)\. We compare two policies: the*flat*policyωrflat\(j,k\)=1\\omega\_\{\\mathrm\{r\}\}^\{\\mathrm\{flat\}\}\(j,k\)=1, and the*author\-normalised*policy \(9\)ωrnorm\(j,k\)=\|A\(j,k\)\|max\(1,Vσ\(k\)\),\\omega\_\{\\mathrm\{r\}\}^\{\\mathrm\{norm\}\}\(j,k\)\\;=\\;\\frac\{\|A\(j,k\)\|\}\{\\max\\bigl\(1,V^\{\\sigma\(k\)\}\\bigr\)\},whereA\(j,k\)A\(j,k\)is the set of distinct participants who have asserted the link\(j,k\)\(j,k\)andVσV^\{\\sigma\}is the number of participants who have cast a ballot on sideσ\\sigmaso far\. Stating the normalisation in terms of*distinct authors*is what keeps it compatible with C[3](https://arxiv.org/html/2608.23979#Thmcriterion3): it counts how many separate people stand behind a claimed relation and is indifferent to which people they are\. Its effect on a coordinated coalition is direct\. A coalition of sizemmcan multiply the*number*of links it asserts freely, but under \([9](https://arxiv.org/html/2608.23979#S4.E9)\) each link is worth only the distinct authorship behind it, so the coalition’s total link credit scales withmmrather than with its output; Section[9\.2](https://arxiv.org/html/2608.23979#S9.SS2)measures the resulting difference at0\.080\.08–0\.120\.12of completeness\. The obvious escalation is to co\-sign — have allmmmembers assert the same links so that\|A\(j,k\)\|=m\|A\(j,k\)\|=mand the numerator recovers\. Section[9\.6](https://arxiv.org/html/2608.23979#S9.SS6)reports what happens, and the result is pleasantly counter\-intuitive: completeness*rises*monotonically with the degree of co\-signing, because co\-signing concentrates the coalition’s identities on a small set of links instead of spreading them across many, so the same authorship budget buys fewer distinct promoted items and the coalition’s own material crowds itself out\. Table[2](https://arxiv.org/html/2608.23979#S4.T2)gives the two policies side by side\. Table 2\.The two relation\-weight policies\. The last column previews Section[9\.2](https://arxiv.org/html/2608.23979#S9.SS2): mean combined completeness under aflooding coalition holding a quarter of the electorate, at the reference configuration\. ### 4\.6\.Configurability without incoherence C[7](https://arxiv.org/html/2608.23979#Thmcriterion7)asks that the policy belong to the participant\. The immediate worry is that this dissolves the shared object: if everyone sees a different slate, what is the common record the deliberation is about? The resolution is a matter of what varies and what does not\. What varies is the policy vectorθi=\(αi,βi,ωr\(i\),Ki\)\\theta\_\{i\}=\(\\alpha\_\{i\},\\beta\_\{i\},\\omega\_\{\\mathrm\{r\}\}^\{\(i\)\},K\_\{i\}\), plus optionally a reason emphasisμi\\mu\_\{i\}in the sense of weighted SJP\. A participant who wants the strongest objections to positions they already hold setsβ\\betahigh; one who wants depth on established claims setsα\\alphahigh; one who distrusts coordinated authorship adopts \([9](https://arxiv.org/html/2608.23979#S4.E9)\); one who wants a longer slate raisesKK\. These are editorial stances, they are legitimately personal, and none is the kind of thing an operator should be choosing on anyone’s behalf333For the special case of so\-calledgrassroot organizations, users can also influence voter eligibility coefficients[Qin et al\., 2013a](https://arxiv.org/html/2608.23979#bib.bibx78)\.\. What does not vary is everything else: the corpus, the endorsement tallies, the link set, the labels, and the rule itself\. Two participants with differentθ\\thetacompute different slates from*identical*public evidence, and each can compute the other’s exactly\. This is what distinguishes configuration from personalisation: a personalised feed differs because the system holds a private model of the user, whereas a configured slate differs because the user set a published parameter, and the difference is fully explained by that parameter\. Under configuration a disagreement about slates reduces to a disagreement about policy, arguable in public; under personalisation it reduces to nothing at all\. ###### Proposition 4\.2 \(Charter closure under configuration\)\. If the rule satisfies C[1](https://arxiv.org/html/2608.23979#Thmcriterion1)–C[6](https://arxiv.org/html/2608.23979#Thmcriterion6)for every fixedθ\\theta, then the family\{scθ\}θ∈Θ\\\{\\mathrm\{sc\}\_\{\\theta\}\\\}\_\{\\theta\\in\\Theta\}satisfies them for participant\-chosenθ\\theta, providedθi\\theta\_\{i\}is recorded alongside the slate\. Determinism, locality, author blindness and semantic abstinence hold pointwise inθ\\thetaand are inherited; reproducibility and contestability require the auditor to know whichθ\\thetawas in force, and persisting\(θi,ti\)\(\\theta\_\{i\},t\_\{i\}\)with each slate — as Section[5\.5](https://arxiv.org/html/2608.23979#S5.SS5)does — supplies it\. Proposition[4\.2](https://arxiv.org/html/2608.23979#S4.Thmtheorem2)is why Section[5\.5](https://arxiv.org/html/2608.23979#S5.SS5)stores the policy vector with every served slate, and why Section[8\.5](https://arxiv.org/html/2608.23979#S8.SS5)can present its main finding as a*frontier*rather than an optimum: once the choice between ranking arms is a position on a trade\-off between coverage and endorsement mass, there is no system\-level answer to which position is right, and C[7](https://arxiv.org/html/2608.23979#Thmcriterion7)is what lets the question be handed to the person it affects\. ### 4\.7\.Rules of order as algorithms of interaction The idea that procedure constitutes rather than merely regulates deliberation is older than any of this\. Robert’s*Rules of Order*[Robert, 1915](https://arxiv.org/html/2608.23979#bib.bibx80)are a specification for a distributed system with adversarial participants: recognition of the floor is admission control; the motion stack is a well\-founded ordering guaranteeing termination; the requirement to speak to the motion is a relevance predicate; limits on repeat speech are rate limiting; and the prohibition on impugning motives is a type restriction on admissible utterances\. None of it was derived from a theory of good outcomes, but from the observation that without such constraints an assembly is captured by whoever is loudest and most persistent\. Our construction translates the same instinct into a setting where the floor is a screen: the published rule is the standing order, author blindness is the convention that the chair recognises members rather than reputations, and the persistence of Section[5\.5](https://arxiv.org/html/2608.23979#S5.SS5)is the minutes\.DDP2P’s own rule that a motion admits one active argumentation per voter at a time[Silaghi et al\., 2013](https://arxiv.org/html/2608.23979#bib.bibx89)is an anti\-filibuster device with an exact parliamentary ancestor, and formal work on procedural argumentation makes the correspondence explicit[Prakken, 2001](https://arxiv.org/html/2608.23979#bib.bibx74);[Silaghi & Roussev, 2014](https://arxiv.org/html/2608.23979#bib.bibx92)\. The relevant inheritance is not any particular clause but the stance: an assembly’s rules must be knowable in advance by everyone bound by them, which is a constraint on the form of the rules, not a preference about their content\. ## 5\.Abas: An Agentic Instrument for Auditable Deliberation Everything in Sections[3](https://arxiv.org/html/2608.23979#S3)and[4](https://arxiv.org/html/2608.23979#S4)is a specification\. To find out what it does one needs an electorate, and human electorates are not available for parameter sweeps\.Abas—*Agent\-Based Argument Simulator*— instantiatesNNconstituent agents against a real implementation of the poll object, runs the round protocol to completion, and persists enough state that every served slate can be reconstructed afterwards\. This section describes the agent, the round, the model of submissions that fail to justify, the arms compared, what is stored, and the interface through which a participant would inspect any of it\. The design commitment throughout is that the simulator is an*instrument*, not a product demonstration: it is built so that its own outputs can be audited, and Section[5\.5](https://arxiv.org/html/2608.23979#S5.SS5)is where that commitment is cashed\. ### 5\.1\.The constituent agent Each agent holds a scalar opinionθ∈\[−1,1\]\\theta\\in\[\-1,1\]on the motion, drawn once at initialisation, and a short position text generated from that opinion by a topic\-specific generator\. The opinion determines the ballot direction stochastically, so agents near the centre are genuinely uncertain; the position text is what the agent uses to judge which existing material speaks for it, through TF–IDF cosine similarity[Manning et al\., 2008](https://arxiv.org/html/2608.23979#bib.bibx61);[Spärck, 1972](https://arxiv.org/html/2608.23979#bib.bibx97)\. Two properties of the agent matter for how the results should be read\. First, agents do not update their opinion in response to what they are shown: the simulator measures*exposure*, not persuasion, and a model of persuasion would import assumptions we have no basis for\. Second, agent behaviour is a model of constituent behaviour, not evidence about it, in the sense of Section[2](https://arxiv.org/html/2608.23979#S2.SS0.SSS0.Px7); every claim we make is a claim about mechanism under a stated model\. Section[12](https://arxiv.org/html/2608.23979#S12)states the specific form this caveat takes for each result, and in one case — the degenerate\-authoring result — it is load\-bearing enough that we state it twice\. ### 5\.2\.The round protocol Agents are processed in identifier order, each one completing the sequence of Algorithm[2](https://arxiv.org/html/2608.23979#algorithm2)before the next begins\. Because the corpus therefore grows underneath the sequence, the live vocabulary of Definition[3\.3](https://arxiv.org/html/2608.23979#S3.Thmtheorem3)genuinely differs between the first and last agent, which is what makes the temporal inequity of Section[1\.1](https://arxiv.org/html/2608.23979#S1.SS1)measurable rather than assumed\. Algorithm 2One constituent’s turnGiven:agent aawith opinion θa\\theta\_\{a\}and position text xax\_\{a\}; poll state at time tt; policy θ\\theta; budget KK; action probabilities πreuse,πabst,πown\\pi\_\{\\mathrm\{reuse\}\},\\pi\_\{\\mathrm\{abst\}\},\\pi\_\{\\mathrm\{own\}\}with πreuse\+πabst\+πown=1\\pi\_\{\\mathrm\{reuse\}\}\+\\pi\_\{\\mathrm\{abst\}\}\+\\pi\_\{\\mathrm\{own\}\}=1; link probability πlnk\\pi\_\{\\mathrm\{lnk\}\} 1 S\+←S^\{\+\}\\leftarrowScoreAndServe\(*𝒥\+∩𝒥t\\mathcal\{J\}^\{\+\}\\cap\\mathcal\{J\}\_\{t\},θ\\theta,KK*\); S−←S^\{\-\}\\leftarrowScoreAndServe\(*𝒥−∩𝒥t\\mathcal\{J\}^\{\-\}\\cap\\mathcal\{J\}\_\{t\},θ\\theta,KK*\); 2persist ⟨a,t,θ,S\+,S−⟩\\langle a,t,\\theta,S^\{\+\},S^\{\-\}\\rangle;//before any ballot is cast 3 v←v\\leftarrowballot direction drawn from θa\\theta\_\{a\}; 4 u←𝒰\[0,1\)u\\leftarrow\\mathcal\{U\}\[0,1\); 5if*u<πreuseu<\\pi\_\{\\mathrm\{reuse\}\}*then 6 j←j\\leftarrowPickFromSlate\(*SvS^\{v\},xax\_\{a\}*\);//similarity\-weighted draw from the served slate 7record ballot for vvciting jj; increment E\(j\)E\(j\); 8else if*u<πreuse\+πabstu<\\pi\_\{\\mathrm\{reuse\}\}\+\\pi\_\{\\mathrm\{abst\}\}*then 9record ballot for vvwith no citation; 10else 11if*aaauthors degenerately*\(Section[5\.3](https://arxiv.org/html/2608.23979#S5.SS3)\)**then 12 j←j\\leftarrowWriteWithoutReason\(*xax\_\{a\},vv*\); 13else 14 j←j\\leftarrowWriteNew\(*xax\_\{a\},vv*\);//fresh item, labels from the side vocabulary 15end if 16insert jj; record ballot for vvciting jj; 17if*𝒰\[0,1\)<πlnk\\mathcal\{U\}\[0,1\)<\\pi\_\{\\mathrm\{lnk\}\}*then 18AssertLinks\(*jj*\);//one rebuttal at an opposing item, one reinforcement at a same\-side item 19end if 20end if Adoption is restricted to the served slate — an agent can only cite what it was shown — which couples the recommender to the endorsement tallies and makes the system a feedback loop rather than a passive display\. And the authoring branch draws labels from the side’s vocabulary independently of the slate, so corpus growth is driven by the authoring draw and not by what was served; this is why the ablations of Section[8](https://arxiv.org/html/2608.23979#S8)are clean, all ranking arms seeing a*bit\-identical*corpus and differing only in whichKKitems of it were displayed\. Link targets are chosen by the agent, not the system: a rebuttal aims at the opposing item least similar to the author’s position, a reinforcement at the same\-side item most similar to it\. ### 5\.3\.Submissions that fail to justify In the first set of experiments we report here, the authoring model had every agent who wrote anything write a well\-formed argument carrying two to five genuine reasons for the side it had voted\. Section[8\.1](https://arxiv.org/html/2608.23979#S8.SS1)reports the price of that charity: under it, almost any twenty items cover almost everything, and there is nothing for a ranking rule to do\. Real deliberative corpora are not like that: a large share of contributions state a position without giving a logically valid reason for it, and a further share give what the author takes to be a reason for their position but which is in fact a reason for the other side\. We model both, with two parameters\. GG— degenerate fraction\.:The share of own\-authored items that fail to justify\. Swept over\{0,0\.1,0\.3,0\.5,0\.7\}\\\{0,0\.1,0\.3,0\.5,0\.7\\\}\. EE— erroneous\-support share\.:Of those, the share that are*erroneous supports*— content belonging to the opposing side, filed under this one — rather than merely*reason\-free*\. Swept over\{0\.1,0\.2,0\.4\}\\\{0\.1,0\.2,0\.4\\\}\. A reason\-free item carries a position and no labels: it occupies a slate slot and contributes nothing to any union\. An erroneous support carries labels belonging to the other side: it occupies a slot and inflates the denominator with vocabulary that does not belong to the side it was filed under\. Two implementation choices make the resulting comparisons trustworthy\. First,*who*authors degenerately is drawn off a dedicated random stream, so raisingGGchanges the content of affected items while leaving the corpus skeleton — which agents author, how many items exist, which links form, how many ballots are cast — bit\-identical across the entire grid; every comparison in Section[8\.3](https://arxiv.org/html/2608.23979#S8.SS3), across arms and across grid points alike, is therefore exactly paired\. Second, completeness is measured against the*genuine*vocabulary, a reason counting towards a side’s denominator only if it is a canonical reason for that side\. This is the conservative choice: counting opposite\-side labels would let erroneous supports inflate the very quantity they are supposed to damage and would reward a slate for surfacing them\. We record the denominator\-inflating variant alongside so that the size of the measurement artefact is visible rather than assumed away, and Section[8\.3](https://arxiv.org/html/2608.23979#S8.SS3)reports it\. ### 5\.4\.Ranking arms and the evaluation ceiling The arms compared throughout Sections[7](https://arxiv.org/html/2608.23979#S7)–[9](https://arxiv.org/html/2608.23979#S9)are identical in every respect except the ranking step of Algorithm[2](https://arxiv.org/html/2608.23979#algorithm2)\. full:The published rule, \([8](https://arxiv.org/html/2608.23979#S4.E8)\) with both link summands active\. endorse\-only:α=β=0\\alpha=\\beta=0: a raw endorsement count\. enhance\-only:β=0\\beta=0: reinforcement summand retained\. attack\-only:α=0\\alpha=0: rebuttal summand retained\. random:The score is ignored and the slate is drawn uniformly from the live pool, using a generator seeded independently of the main stream so that stances, actions and link choices are consumed identically across arms and the comparison stays seed\-paired\. Alongside these we compute, on the evaluation path only and subject to Principle[1](https://arxiv.org/html/2608.23979#Thmprinciple1), the greedy cover of Section[3\.5](https://arxiv.org/html/2608.23979#S3.SS5)\. Algorithm[3](https://arxiv.org/html/2608.23979#algorithm3)states it explicitly so that what it reads — and therefore why it is inadmissible — is on the page\. Algorithm 3GreedyCover— evaluation ceiling only; not a deployable mechanismGiven:live pool PP, labelling λ\\lambda*\(read directly — violates C[4](https://arxiv.org/html/2608.23979#Thmcriterion4)\)*, live vocabulary Λtσ\\Lambda^\{\\sigma\}\_\{t\}, budget KK Yields:a KK\-subset of PPand its completeness 1 S←∅S\\leftarrow\\emptyset; C←∅C\\leftarrow\\emptyset; 2for*11tomin\(K,\|P\|\)\\min\(K,\|P\|\)*do 3 j⋆←argmaxj∈P∖S\|λ\(j\)∖C\|j^\{\\star\}\\leftarrow\\arg\\max\_\{j\\in P\\setminus S\}\\bigl\|\\lambda\(j\)\\setminus C\\bigr\|, ties by ascending identifier; 4if*\|λ\(j⋆\)∖C\|=0\|\\lambda\(j^\{\\star\}\)\\setminus C\|=0*thenbreak; 5 S←S∪\{j⋆\}S\\leftarrow S\\cup\\\{j^\{\\star\}\\\}; C←C∪λ\(j⋆\)C\\leftarrow C\\cup\\lambda\(j^\{\\star\}\); 6end for 7return SSand \|C\|/\|Λtσ\|\|C\|/\|\\Lambda^\{\\sigma\}\_\{t\}\|; ### 5\.5\.Persistence: the record is the point Every run writes a single relational database holding: the agents and their initialisation parameters; every justification with its author, side, timestamp and labels; every link with its author, type and endpoints; every ballot with its direction, citation and timestamp; the simulation parameters and seed; and — the entry that matters —*every served slate*, stored with the identifier of the constituent it was served to, the instant, the policy vector in force, and the item identifiers in served order\. This is what makes C[5](https://arxiv.org/html/2608.23979#Thmcriterion5)and C[6](https://arxiv.org/html/2608.23979#Thmcriterion6)testable rather than asserted\. Any historical slate can be reconstructed exactly, the corpus state at that instant with it, and the score decomposition of every served item recomputed and checked against the ranking actually served\. It is also what makes the ordering and endorsement\-mass instruments of Sections[8\.2](https://arxiv.org/html/2608.23979#S8.SS2)and[8\.5](https://arxiv.org/html/2608.23979#S8.SS5)computable at all, since both read served position\. A pipeline logging only the aggregate metric would have required the entire experiment to be repeated\. ### 5\.6\.Inspecting the record A record nobody can read discharges nothing\.Abasships a browser over the persisted database that presents, for any constituent: the two slates they were served, in order; for each served item, the decomposition\(own,E\(j\)\)\(\\textsf\{own\},E\(j\)\),\(reinforces,αa\)\(\\textsf\{reinforces\},\\alpha a\)and\(rebuts,βr\)\(\\textsf\{rebuts\},\\beta r\)produced by Algorithm[1](https://arxiv.org/html/2608.23979#algorithm1); the links that contributed each term, with their authors; and the ballot that followed\. It also presents the counterfactual a participant most often wants — the slate the same evidence would have produced under a different policy vector — which is C[7](https://arxiv.org/html/2608.23979#Thmcriterion7)made concrete rather than promised\. The interface is deliberately unremarkable: tables and links, no visualisation of anything the arithmetic does not literally contain\. The design literature on decentralised civic tools is consistent about non\-expert users needing the model of the system to be simple enough to hold in mind[Alqahtani & Silaghi, 2017](https://arxiv.org/html/2608.23979#bib.bibx8);[Alqahtani & Silaghi, 2016](https://arxiv.org/html/2608.23979#bib.bibx7);[Kattamuri et al\., 2005](https://arxiv.org/html/2608.23979#bib.bibx50), and a three\-term sum is about the limit of what one can expect a participant to check while deciding how to vote\. ## 6\.Experimental Setup This section fixes the protocol so that every number in Sections[7](https://arxiv.org/html/2608.23979#S7)–[9](https://arxiv.org/html/2608.23979#S9)can be located\. Two propositions are used throughout, one reference configuration anchors all sweeps; the adversary families are stated with the exact capability each is granted; and the statistical conventions are declared in advance, including where we do not correct for multiplicity and what we therefore do not claim\. A third proposition is used for the refresh\-interval scenario of Section[9\.4](https://arxiv.org/html/2608.23979#S9.SS4)\. ### 6\.1\.Propositions UBIasks*“Should one address the AI revolution by introducing basic income?”*, with thirty canonical reasons per side spanning fiscal, labour\-market, administrative, distributive and political\-economy considerations\.BRAasks*“Should one address the AI revolution by introducing basic resource assurance \(minimal healthy housing, food, and emergency healthcare\)?”*\. A third proposition,OPT\-OUT, asks*“Should primary school pupils be able to study without computers and an internet connection?”*, with thirty canonical reasons per side spanning pedagogical, developmental, equity\-of\-access and administrative considerations\. It is used only in Section[9\.4](https://arxiv.org/html/2608.23979#S9.SS4), where the question is whether a protocol parameter held fixed everywhere else changes the conclusions\. ### 6\.2\.Reference configuration Unless a sweep states otherwise:N=1000N=1000constituents; action probabilitiesπown=0\.10\\pi\_\{\\mathrm\{own\}\}=0\.10,πreuse=0\.50\\pi\_\{\\mathrm\{reuse\}\}=0\.50,πabst=0\.40\\pi\_\{\\mathrm\{abst\}\}=0\.40; link probabilityπlnk=0\.60\\pi\_\{\\mathrm\{lnk\}\}=0\.60; slate sizeK=20K=20per side; author\-normalised weight policy \([9](https://arxiv.org/html/2608.23979#S4.E9)\); policy coefficientsα=β\\alpha=\\betaat the implementation default; score caches re\-read after every constituent \(M=1M=1\), the interval swept in Section[9\.4](https://arxiv.org/html/2608.23979#S9.SS4)\. Table[3](https://arxiv.org/html/2608.23979#S6.T3)characterises what this produces and establishes that the regime is not degenerate in either direction: the vocabulary saturates, the corpus is roughly5050items per side against a3030\-label vocabulary, and the ballot split is near even\. Table 3\.The reference configuration characterised: BRA proposition,πown=0\.10\\pi\_\{\\mathrm\{own\}\}=0\.10,K=20K=20,πlnk=0\.60\\pi\_\{\\mathrm\{lnk\}\}=0\.60,N=1000N=1000, author\-normalisedωr\\omega\_\{\\mathrm\{r\}\}; mean±\\pmstandard deviation over ten seeds\. Completeness is that of the slate the endorsement rule actually served\. “Within\-run spread” is the standard deviation of per\-constituent completeness*inside*a single run, averaged over seeds: it measures temporal inequity, not experimental noise, and at0\.2130\.213it is more than five times the across\-seed variation\.QuantityMeanStdCombined completeness, mean over constituents0\.8060\.038Combined completeness, median over constituents0\.8860\.042Within\-run spread of completeness0\.2130\.032Live endorsing vocabulary \(of3030\)30\.00\.0Live opposing vocabulary \(of3030\)29\.90\.3Authored endorsing justifications48\.36\.6Authored opposing justifications49\.76\.8Rebuttal links34619Reinforcement links34215Total links68833Endorsing ballots500\.915\.1Opposing ballots499\.115\.1 ### 6\.3\.Structural levers of the non\-degenerate authoring reference configuration In the first set of experiments with non\-degenerate authoring, four structural levers are swept one at a time about the reference point, ten seeds per cell, both propositions: authoring rateπown∈\{0\.02,0\.05,0\.10,0\.20,0\.30\}\\pi\_\{\\mathrm\{own\}\}\\in\\\{0\.02,0\.05,0\.10,0\.20,0\.30\\\}withπreuse:πabst\\pi\_\{\\mathrm\{reuse\}\}:\\pi\_\{\\mathrm\{abst\}\}held at:45\\\!:\\\!4; slate sizeK∈\{5,10,15,20,30\}K\\in\\\{5,10,15,20,30\\\}; link rateπlnk∈\{0\.20,0\.40,0\.60,0\.80,1\.00\}\\pi\_\{\\mathrm\{lnk\}\}\\in\\\{0\.20,0\.40,0\.60,0\.80,1\.00\\\}; electorateN∈\{200,500,1000,2000,5000\}N\\in\\\{200,500,1000,2000,5000\\\}\. The ranking ablation runs five arms atK∈\{5,10,20,30\}K\\in\\\{5,10,20,30\\\}with100100seed\-paired seeds per cell \(40004000runs\) and repeats three arms atK=20K=20under attack \(18001800runs\)\. The degenerate\-authoring sweep runs three arms overG∈\{0,0\.1,0\.3,0\.5,0\.7\}×E∈\{0\.1,0\.2,0\.4\}G\\in\\\{0,0\.1,0\.3,0\.5,0\.7\\\}\\times E\\in\\\{0\.1,0\.2,0\.4\\\}with5050seeds per cell per proposition \(39003900runs\)\. The adversarial families are described next\. In total the results below rest on roughly17,00017\{,\}000seeded runs\. ### 6\.4\.Adversary model In this set of experiments, authentication is assumed to hold: the census is well\-formed, nobody votes twice, and no endorsement is forged\. Sybil resistance is therefore*out of scope*as an attack and*in scope*as an infrastructure requirement, which is where Section[10](https://arxiv.org/html/2608.23979#S10.SS0.SSS0.Px3)takes it up\. What a coalition controls is what its members write, where they point their links, and when they act\. Coalition sizes are00,55,1010,1515,2020and2525percent ofNN, and members are spread evenly through the processing order, so they enjoy no first\-mover endorsement cascade and must rely on the graph for visibility\. The attacks studied are: Hub\-riding\.:Members author items in the ordinary way and attach reinforcement links to the most endorsed same\-side item, attempting to launder its endorsement mass into their own score\. Label flooding\.:Members author on every turn, drawing both labels from a single shared pair, link on every turn, and aim those links at the two most endorsed items\. The clones carry real corpus labels, so any damage is redundancy, not label absence\. Heterogeneous control\.:Identical to flooding in authoring rate, link rate and link targeting, but each member draws its label pair independently: the rate\- and corpus\-matched control isolating homogeneity\. A second variant restores most\-related link targeting, isolating hub aiming as a residual\. Co\-signed flooding\.:The coalition is partitioned into groups of sizeCC; each group publishes one poison item per side and every member endorses it and re\-asserts the same links, driving the distinct\-author numerator of \([9](https://arxiv.org/html/2608.23979#S4.E9)\) from one to the group’s per\-side size\.C∈\{1,2,5,10,25,50\}C\\in\\\{1,2,5,10,25,50\\\}at coalitions of a tenth and a quarter, both propositions, both weight policies \(48004800runs\)\.C=1C=1reproduces the flooding sweep exactly, to the last stored digit, and serves as an in\-family control\. Nothing in the implementation obstructs any of these strategies\. In particular the relation store admits repeated\(from,to\)\(\\textit\{from\},\\textit\{to\}\)assertions from distinct authors, which is exactly what makes the co\-signing numerator movable — we did not defend against the attack by refusing to represent it\. ### 6\.5\.Statistical conventions Comparisons between arms are seed\-paired and tested with a two\-sided pairedtt\-test on per\-seed means; comparisons between configurations that do not share seeds use Welch’s unequal\-variance test\. Reported intervals are across\-seed standard deviations unless stated\. Where many contrasts are computed on the same stored runs — notably the twenty\-four ordering contrasts of Section[8\.2](https://arxiv.org/html/2608.23979#S8.SS2)— we report the rawpp\-values without multiplicity correction and say so at the point of use, and any contrast whose significance would not survive a Bonferroni adjustment at that family size is described as*suggestive*rather than established\. We have not adjusted for the number of hypotheses across the manuscript as a whole, and readers should treat effects atp≈10−2p\\approx 10^\{\-2\}accordingly; the effects we build arguments on sit atp<10−10p<10^\{\-10\}\. ## 7\.Results I: An Attack\-Free Electorate We begin with an electorate in which every participant who writes anything writes a competent argument for the side they support \(non\-degenerate authoring\)\. This regime answers two questions well and one question misleadingly\. It establishes which structural levers govern how much of the live reason vocabulary a served slate covers — and the answer, that everything which matters works by enriching the corpus before the voter arrives rather than by selecting more cleverly from it, is stable across both propositions\. It establishes what the charter of Section[4](https://arxiv.org/html/2608.23979#S4)costs, by measuring the served slates against a label\-reading ceiling that upper\-bounds every mechanism including the ones the charter excludes\. ### 7\.1\.What the reference configuration produces Table[3](https://arxiv.org/html/2608.23979#S6.T3)gives the characterisation\. Mean combined completeness is0\.806±0\.0380\.806\\pm 0\.038on BRA and0\.804±0\.0320\.804\\pm 0\.032on UBI: a constituent at the reference configuration meets, on average, four fifths of the reasons that existed on each side at the moment they voted\. The number that deserves more attention is the within\-run spread,0\.2130\.213\. This is the standard deviation of completeness*across constituents inside a single run*, and it is more than five times the standard deviation*between*runs\. The dominant source of variation in what a voter sees is therefore not the seed, the configuration, or the recommender — it is*when in the sequence the voter arrived*\. Early constituents vote against a vocabulary that is still assembling itself; late ones vote against a mature one\. This is the temporal inequity of Section[1\.1](https://arxiv.org/html/2608.23979#S1.SS1), measured, and it is an inequality in the informational conditions of the ballot that no choice of selection rule addresses\. Figure[2](https://arxiv.org/html/2608.23979#S7.F2)shows how the saturation point moves with authoring rate, and the area to the left of each curve is the population that voted early enough for it to matter\. Figure 2\.Vocabulary saturation under three authoring rates, anchored at the measured saturation points \(≈800\\approx 800constituents atπown=0\.02\\pi\_\{\\mathrm\{own\}\}=0\.02,≈150\\approx 150atπown=0\.30\\pi\_\{\\mathrm\{own\}\}=0\.30, in runs ofN=1000N=1000\); the vertical rules mark the measured anchors and the shape between them is illustrative\. The area to the left of each curve is the population that voted against a reason space still under construction — the quantity a deployment reduces by raising the authoring rate, not by ranking better\. ### 7\.2\.Which levers move coverage Table[4](https://arxiv.org/html/2608.23979#S7.T4)gives every setting of every lever on both propositions\. The ordering is unambiguous and identical across them\. Slate size spans widest —0\.440\.44atK=5K=5to0\.830\.83atK=30K=30— and is bounded above by the corpus, since a slate cannot cover reasons nobody has written\. The fifth through fifteenth slots contribute the overwhelming majority; slots beyond the twentieth add two to three points per block, and only because the rule is label\-blind, so lower\-ranked but reason\-novel items keep entering\. A label\-reading selector would exhaust the vocabulary earlier and then add nothing\. Authoring rate follows: raisingπown\\pi\_\{\\mathrm\{own\}\}from0\.020\.02to0\.300\.30lifts completeness from0\.700\.70to0\.880\.88, by the mechanism visible in Figure[2](https://arxiv.org/html/2608.23979#S7.F2)— a higher rate saturates the vocabulary sooner, so a smaller fraction of the electorate votes against an immature reason space\. It is the cheapest lever per point gained, and one a deployment pulls through interface design and prompting rather than through algorithms\. Electorate size behaves identically,0\.690\.69atN=200N=200rising to0\.900\.90atN=5000N=5000, with the difference that it is not a design parameter; it is worth stating because it means the construction gets*better*at scale, the opposite of the usual finding for deliberative procedures\. Among these levers, link rate does essentially nothing: completeness moves by0\.0040\.004across a fivefold change in linking activity, on both propositions\. This is the first appearance of a fact Section[8\.1](https://arxiv.org/html/2608.23979#S8.SS1)will sharpen considerably\. It does not mean links are useless — links are what the rebuttal and reinforcement summands read, and Section[8\.3](https://arxiv.org/html/2608.23979#S8.SS3)shows they carry real weight once the corpus contains material worth discriminating against\. It means that in a corpus where every item is a competent argument, the ordering induced by the links reshuffles items that were going to be served anyway\. Table 4\.Mean combined completenessc¯\\bar\{c\}at every setting of every lever, both propositions, author\-normalised weight policy, ten seeds per cell\. Settings run left to right in the order given in the row label; the reference setting is in bold\. Across\-seedσ\\sigmaruns0\.0130\.013–0\.0820\.082throughout and is tabulated per cell in the online appendix\. In the authoring\-rate rowπreuse=0\.50\\pi\_\{\\mathrm\{reuse\}\}=0\.50is fixed andπabst\\pi\_\{\\mathrm\{abst\}\}absorbs the remainder; all other levers are held at reference\. ### 7\.3\.The price of semantic abstinence, measured Section[3\.5](https://arxiv.org/html/2608.23979#S3.SS5)introduced the greedy cover as an evaluation ceiling and Principle[1](https://arxiv.org/html/2608.23979#Thmprinciple1)confined it to the evaluation path\. Here we spend it\. For every slate served in the reference cell we also compute, over the*identical*pool and at the*identical*cache refresh, the slate a label\-reading greedy selector would have returned, scoring both with the same measure\. This answers the question the charter leaves open: not whether some excluded procedure could score higher, but whether the admissible class contains a procedure good enough to use\. It does\. Against the end\-of\-round vocabulary \(Table[5](https://arxiv.org/html/2608.23979#S7.T5)\) the endorsement rule serves0\.806±0\.0380\.806\\pm 0\.038where the ceiling reaches0\.837±0\.0340\.837\\pm 0\.034: a gap of0\.031±0\.0140\.031\\pm 0\.014, or3\.7%3\.7\\%of the ceiling, positive in all ten seeds and never exceeding0\.0590\.059\. Reading the labels is worth about three points of completeness\. The second block is the more consequential reading\. Scored against the vocabulary actually live when each slate was served — the denominator of Definition[3\.4](https://arxiv.org/html/2608.23979#S3.Thmtheorem4)— the ceiling attains1\.0001\.000in every seed and the served slates0\.968±0\.0150\.968\\pm 0\.015\. The ceiling saturates because the reference cell ends with a thirty\-label vocabulary per side against a twenty\-item slate, so a spanning sub\-collection almost always exists; the\(1−e−1\)\(1\-e^\{\-1\}\)worst case of Proposition[3\.7](https://arxiv.org/html/2608.23979#S3.Thmtheorem7)is nowhere near binding at this scale\. The0\.1940\.194shortfall fromc¯=1\\bar\{c\}=1therefore decomposes into two very unequal parts: a*selection*component of0\.0310\.031, which is what abstaining from the labels costs, and a*temporal*component of0\.1630\.163— vocabulary that did not yet exist when the slate was assembled, which no procedure of any kind, rule\-based or learned or label\-omniscient, could have shown that voter\. Four fifths of the measured incompleteness is a property of sequential deliberation rather than of the recommender\. This governs how the rest of the manuscript should be read\. Every lever of Section[7\.2](https://arxiv.org/html/2608.23979#S7.SS2)that moves completeness substantially does so by attacking the temporal component; the selection component is small and is the only one any better*selection*procedure could recover, so a learned ranker offered the same pool could at best close0\.0310\.031, and only by reading what C[4](https://arxiv.org/html/2608.23979#Thmcriterion4)forbids\. Table 5\.Served completeness against the label\-reading greedy ceiling, reference configuration \(BRA\), summarised over ten seeds; the per\-seed rows are in the online appendix\. The ceiling is evaluated on the same pool and at the same cache refresh as the served slate, so the gap isolates selection quality rather than index staleness\. The left block scores against the end\-of\-round vocabulary, the right block against the vocabulary live at the moment of serving \(Definition[3\.4](https://arxiv.org/html/2608.23979#S3.Thmtheorem4)\)\. The ceiling saturates the live vocabulary in every seed, so the two gaps almost coincide and the residual shortfall in the left block is temporal rather than algorithmic\. ## 8\.Results II: What the Coverage Measure Could Not See This section reports the ablation — does the rule beat not ranking at all? — and the answer, on set coverage with non\-degenerate authoring, is no\. It reports that null in full, with the seeds on which the ranked and random slates were bit\-identical, because a manuscript arguing for legibility owes its readers the result that embarrassed it\. It then shows that the null is an artefact of two things: an instrument that discards order by construction, and an authoring model in which every submission is worth reading\. Correcting either one dissolves it\. Correcting both reveals that the two link summands, which the ablation found exactly inert, are worth as much as the entire ranking advantage once the corpus contains material a rule should keep off the slate\. The section closes on the third instrument, endorsement mass, which shows that the random baseline was never competitive on any axis except the one we happened to be measuring\. ### 8\.1\.The null result, for non\-degenerate authoring Five arms, identical in every respect but the ranking step \(Section[5\.4](https://arxiv.org/html/2608.23979#S5.SS4)\),100100seed\-paired seeds per cell, four slate sizes, both propositions —40004000runs\. One property of the model makes the comparison unusually clean: corpus growth is driven by the authoring draw and not by the slate, so all arms see a*bit\-identical*corpus \(102\.4102\.4items and694694links at zero attackers,326\.4326\.4and10351035at a quarter\-electorate coalition\), and the served slate is the only thing that differs\. #### The link terms are all but inert\. Table[6](https://arxiv.org/html/2608.23979#S8.T6)gives the non\-degenerate authoring attack\-free sweep\. No two of the four ranked arms separate by more than0\.0040\.004, and of the twenty\-four seed\-paired contrasts between ranked arms only one survives a Bonferroni correction for that many comparisons: atK=5K=5the enhance\-only arm leads the pure endorsement count by0\.00390\.0039\(p=0\.001p=0\.001\)\. At that same slate size5858of the100100BRA seeds are bit\-identical between the full rule and the pure endorsement count; atK=20K=20about a fifth of seeds still are\. The mechanism is arithmetic rather than mysterious\. Under author normalisation a relation weight is the number of distinct authors of an edge divided by the constituents voting that side, which at the reference configuration ranges from0\.0020\.002to0\.0230\.023; multiplied by the endorsement count of a hub it yields a bonus that never exceeded0\.960\.96in the state we instrumented\. The gap in raw endorsements at theKK\-boundary was33in that same state\. A bonus smaller than the boundary gap reorders items*within*the slate without changing which items are in it — and completeness, by Remark[1](https://arxiv.org/html/2608.23979#Thmremark1), reads only the union of what is served\. The link terms are not doing nothing\. They are doing something the instrument is constitutionally unable to see\. Table 6\.Ranking\-term ablation in an non\-degenerate authoring attack\-free electorate: mean combined completeness pooled over the two propositions,100100seed\-paired seeds per cell\. The live pool holds about5151items per side throughout, soKKis also a proxy for the fraction of the pool served\. Across\-seedσ\\sigmaruns0\.0260\.026–0\.0490\.049for the four ranked arms and0\.0150\.015–0\.0250\.025for the random arm\. #### The random baseline is not beaten, and under attack it wins\. At non\-degenerate authoring and zero attackers the rule leads by0\.82050\.8205against0\.81810\.8181, a margin of0\.00240\.0024that is suggestive atp=0\.034p=0\.034and does not survive correction for the number of contrasts; at a tenth of the electorate the rule*trails*,0\.60880\.6088against0\.64720\.6472\(−0\.0385\-0\.0385,p≈5×10−27p\\approx 5\\times 10^\{\-27\}\); at a quarter it trails further,0\.37310\.3731against0\.44370\.4437\(−0\.0706\-0\.0706,p≈3×10−39p\\approx 3\\times 10^\{\-39\}\), all seed\-paired over200200runs per comparison\. The direction is the mechanism rather than an anomaly: the ranked arms read the endorsement tallies the coalition inflates, and a uniform draw does not, so the clones the flood manufactures reach the slate through the ranking step and not around it\. The three\-way comparison at the largest coalition is the one to sit with: the author\-normalised policy reaches0\.36950\.3695on BRA and0\.37680\.3768on UBI, the random slate0\.44190\.4419and0\.44560\.4456, the flat policy0\.22790\.2279and0\.21950\.2195\. Read at face value the flat policy is some twenty\-two points*worse*than not ranking at all, and author normalisation buys back about two thirds of that deficit but not the whole of it, leaving the rule seven points short of the uniform draw — its virtue under attack is the limiting of amplification rather than the delivery of coverage\. The random arm also carries less than half the across\-seed variance of the ranked arms under attack \(σ≈0\.035\\sigma\\approx 0\.035against0\.0780\.078\), an effect we do not currently model\. modelling assumption responsible\. A learned selector exhibiting the same null would have offered a metric that failed to move and an unbounded space of explanations\. ### 8\.2\.Order: what a ranking rule is actually for Completeness is invariant to slate order \(Remark[1](https://arxiv.org/html/2608.23979#Thmremark1)\), and a ranking rule is precisely a claim about order\.m∈\{1,2,3,5,10,20\}m\\in\\\{1,2,3,5,10,20\\\}, the area under the prefix curve, rank\-discounted coverage, ande90e\_\{90\}, atK=20K=20, pooled over both propositions and seed\-paired across arms\. Table[7](https://arxiv.org/html/2608.23979#S8.T7)and Figure[3](https://arxiv.org/html/2608.23979#S8.F3)give the result, and it is unambiguous in exactly the way Table[6](https://arxiv.org/html/2608.23979#S8.T6)was not\. At every prefix short of the full slate the endorsement rule leads the uniform draw, and the lead grows with adversarial pressure\. In an attack\-free electorate the gains are small but uniformly significant:p1p\_\{1\}\+0\.0094\+0\.0094\(p≈10−10p\\approx 10^\{\-10\}\),p5p\_\{5\}\+0\.0198\+0\.0198\(7×10−157\\times 10^\{\-15\}\),AUC\\mathrm\{AUC\}\+0\.0135\+0\.0135\(3×10−193\\times 10^\{\-19\}\),RDC\\mathrm\{RDC\}\+0\.0347\+0\.0347\(10−1710^\{\-17\}\),e90e\_\{90\}−0\.40\-0\.40positions \(5×10−105\\times 10^\{\-10\}\)\. At a coalition of a tenth of the electorate they becomep5p\_\{5\}\+0\.1016\+0\.1016,AUC\\mathrm\{AUC\}\+0\.0558\+0\.0558ande90e\_\{90\}−3\.14\-3\.14positions, all atp≈2×10−34p\\approx 2\\times 10^\{\-34\}; at a quarter,p1p\_\{1\}\+0\.0335\+0\.0335,p5p\_\{5\}\+0\.1387\+0\.1387,AUC\\mathrm\{AUC\}\+0\.0796\+0\.0796,RDC\\mathrm\{RDC\}\+0\.1788\+0\.1788ande90e\_\{90\}−5\.69\-5\.69positions, all atp≤5×10−34p\\leq 5\\times 10^\{\-34\}\. The reading is direct\. A constituent under a quarter\-electorate coalition who reads the ranked slate reaches nine tenths of that slate’s coverage after8\.98\.9items; one reading the uniform draw needs14\.614\.6\. Both slates end at the samep20p\_\{20\}— which is why Table[6](https://arxiv.org/html/2608.23979#S8.T6)saw nothing — but they are not the same object for anyone with finite attention\. The coalition succeeds at filling the corpus and fails at placing its material where the reader is\. That the margin*grows*under attack inverts the natural expectation that an adversary manipulating the graph would degrade the rule’s ordering advantage\. What happens instead is that as the pool fills with redundant clones, the difference between ordering by endorsement flow and not ordering at all becomes the difference between a reader meeting distinct reasons early and a reader wading through duplicates — a distinction that barely exists in a clean pool and dominates in a polluted one\. The link terms remain nearly invisible on this instrument too\. Comparing the full rule againstendorse\-only, no contrast reaches significance at zero or a tenth attackers; at a quarter,RDC\\mathrm\{RDC\}gains0\.0130\.013\(p=0\.011p=0\.011\) andAUC\\mathrm\{AUC\}gains0\.0040\.004\(p=0\.027p=0\.027\)\. With twenty\-four contrasts computed on the same stored runs and no multiplicity correction \(Section[6\.5](https://arxiv.org/html/2608.23979#S6.SS5)\), we report this as*suggestive*and nothing more\. The next subsection is where the link terms stop being suggestive\. Figure 3\.Prefix coverage against slate depth atK=20K=20, pooled over both propositions,28002800stored runs\. Panels: attack\-free electorate, coalition at a tenth, coalition at a quarter\. The shaded region is what the endorsement rule delivers above the uniform draw at each depth; ticks on the axis marke90e\_\{90\}, the depth at which each arm reaches nine tenths of its own final coverage\. The three arms meet atm=20m=20in the attack\-free panel and separate everywhere before it, by a margin that widens with attack; under attack the endorsement rule endsm=20m=20below the draw — the only quantity Table[6](https://arxiv.org/html/2608.23979#S8.T6)could see — and leads it at every earlier depth\.Table 7\.Ordering measures atK=20K=20, pooled over both propositions, seed\-paired,28002800stored runs\.pmp\_\{m\}is prefix coverage at depthmm;AUC\\mathrm\{AUC\}is the mean over depths;RDC\\mathrm\{RDC\}is rank\-discounted coverage \([6](https://arxiv.org/html/2608.23979#S3.E6)\);e90e\_\{90\}is the depth reaching nine tenths of that slate’s own final coverage \(lower is better\)\.\|A\|\|A\|is the coalition size out ofN=1000N=1000\. Note thatp20p\_\{20\}— the only column completeness can see — agrees across arms to within0\.0050\.005in the attack\-free electorate, and under attack moves against the ranked rule while every earlier column moves for it\. ### 8\.3\.Degenerate authoring: giving the rule something to discriminate against The second correction addresses Remark[2](https://arxiv.org/html/2608.23979#Thmremark2)\. Under the model of Section[7](https://arxiv.org/html/2608.23979#S7)every submission is a competent argument, so every item is worth roughly the same to a coverage measure and no rule can beat a draw by much\. Section[5\.3](https://arxiv.org/html/2608.23979#S5.SS3)introduced two parameters — the degenerate fractionGGand the erroneous\-support shareEE— and this subsection sweeps them: three arms,G∈\{0,0\.1,0\.3,0\.5,0\.7\}G\\in\\\{0,0\.1,0\.3,0\.5,0\.7\\\},E∈\{0\.1,0\.2,0\.4\}E\\in\\\{0\.1,0\.2,0\.4\\\},5050seeds per cell per proposition,39003900runs, zero failures, twenty minutes of wall clock\. Because degenerate authorship is drawn off a dedicated stream, the corpus skeleton is bit\-identical across the whole grid and every comparison is exactly paired\. Table[8](https://arxiv.org/html/2608.23979#S8.T8)gives the result: the margin the coverage instrument could not find in Table[6](https://arxiv.org/html/2608.23979#S8.T6)reappears as soon as there is anything to discriminate against, and grows monotonically with how much there is\. AtG=0G=0the arms are all but indistinguishable, matching the attack\-free sweep of Table[6](https://arxiv.org/html/2608.23979#S8.T6)\(\+0\.0033\+0\.0033,p=0\.018p=0\.018\) — the control establishing that the sweep measures what it claims\. AtG=0\.1G=0\.1the rule already leads the uniform draw by0\.00590\.0059\(p=7×10−4p=7\\times 10^\{\-4\}\); byG=0\.7G=0\.7it leads by0\.04710\.0471\(p=8×10−14p=8\\times 10^\{\-14\}\), more than an order of magnitude larger\. The served degenerate share tracks it: atG=0\.7G=0\.7the rule serves66\.6%66\.6\\%degenerate material against the70\.5%70\.5\\%corpus base rate a uniform draw returns, significant atp<10−6p<10^\{\-6\}in every cell\. RaisingEE— moving degenerate items from reason\-free towards erroneous\-support — consistently*shrinks*the margin, by0\.0050\.005to0\.0100\.010across the grid\. This is the expected direction and a useful sanity check: an erroneous support carries real labels and real endorsement potential, so a rule reading only endorsements and links finds it harder to distinguish from a genuine item than a reason\-free stub\. The rule’s advantage is largest exactly where the material is most obviously worthless\. We also record the measurement artefact rather than assuming it away: scoring against the denominator\-inflating variant atG=0\.3G=0\.3,E=0\.4E=0\.4gives0\.62270\.6227where the genuine\-vocabulary measure gives0\.74240\.7424, because erroneous supports push the apparent per\-side vocabulary from29\.629\.6labels to44\.844\.8\. Reporting the raw variant would have made every arm look worse and credited slates for surfacing material filed on the wrong side; the genuine\-vocabulary measure of Section[5\.3](https://arxiv.org/html/2608.23979#S5.SS3)is the conservative choice and is what Table[8](https://arxiv.org/html/2608.23979#S8.T8)reports throughout\. Ordering and coverage now agree\. AtG=0\.7G=0\.7,E=0\.1E=0\.1the rule reachesp5=0\.4158p\_\{5\}=0\.4158against the draw’s0\.18620\.1862,AUC\\mathrm\{AUC\}0\.36290\.3629against0\.21040\.2104, ande90e\_\{90\}of7\.397\.39against13\.2513\.25\. The two instruments that disagreed in Sections[8\.1](https://arxiv.org/html/2608.23979#S8.SS1)and[8\.2](https://arxiv.org/html/2608.23979#S8.SS2)disagree because of the authoring model, and once it is corrected they say the same thing\. Table 8\.Degenerate authoring: mean combined completeness against the*genuine*reason vocabulary, pooled over both propositions,100100runs per cell, seed\-paired across arms\.GGis the fraction of own\-authored items that fail to justify;EEis the share of those that are erroneous supports rather than reason\-free\.pp\-values are two\-sided Wilcoxon signed\-rank tests on the full\-minus\-random contrast\. TheG=0G=0row reproduces the attack\-free sweep of Table[6](https://arxiv.org/html/2608.23979#S8.T6)and serves as the control\. ### 8\.4\.Why the link terms square the discrimination Table[8](https://arxiv.org/html/2608.23979#S8.T8)’s last column is the surprise\. The link summands, worth−0\.0000\-0\.0000atG=0G=0, are worth\+0\.0617\+0\.0617atG=0\.7G=0\.7— which is93%93\\%of the full margin over the uniform draw\. Terms that Table[6](https://arxiv.org/html/2608.23979#S8.T6)found all but inert become, in a realistic corpus, the substance of the rule\. This subsection explains why, by measuring the graph directly\. Recall the direction of \([8](https://arxiv.org/html/2608.23979#S4.E8)\): an item is credited for the endorsements of what it*points at*\. So the question is whether a degenerate author’s outgoing links land on lower\-endorsed targets than a genuine author’s do\. Instrumenting100100runs atG=0\.7G=0\.7,E=0\.4E=0\.4gives the answer in one table of five numbers per item class: On endorsements alone, genuine items lead reason\-free ones by a factor of7\.77\.7\. On link credit they lead by a factor of7\.27\.2— and the two factors*multiply*, because an item’s link credit is the sum of its targets’ endorsements and a degenerate item both asserts fewer links \(0\.80\.8per item against6\.56\.5\) and aims the few it asserts at material nobody adopted\. The link summands do not introduce new discrimination\. They*square*the discrimination already present in the endorsement count\. This also explains the inertness atG=0G=0without special pleading\. When every item is genuine, every item has both a healthy endorsement count and healthy out\-edges into other well\-endorsed items; squaring a ratio of one leaves one\. The link terms were never a mechanism for separating good arguments from good arguments\. They are a mechanism for separating arguments from non\-arguments, and we had not given them any non\-arguments\. One limitation must be stated here rather than deferred, because it governs the reading of the entire subsection\. The chain rests on a single modelled fact — degenerate items are adopted less \(1\.431\.43endorsements against11\.0411\.04\) — and that fact follows from the simulator’s adoption step, which selects from the served slate by TF–IDF cosine similarity to the agent’s position text \(Section[5\.1](https://arxiv.org/html/2608.23979#S5.SS1)\)\. It is a property of the agents, not of the rule\. The finding is therefore that*the rule inherits and amplifies whatever discrimination the electorate itself exercises*\. The estimation of the rate at which human electorate discriminates is an empirical question this manuscript does not attempt to answer \(Section[12](https://arxiv.org/html/2608.23979#S12)\)\. ### 8\.5\.Coverage against endorsement mass The third instrument closes the account\. Sections[8\.1](https://arxiv.org/html/2608.23979#S8.SS1)and[8\.2](https://arxiv.org/html/2608.23979#S8.SS2)left an uncomfortable residue: on coverage the uniform draw was never beaten, and under flooding attacks it beat the rule\. Instrument III \([7](https://arxiv.org/html/2608.23979#S3.E7)\) asks the question coverage cannot —*did the slate show the voter what the electorate had actually taken up?*— and the answer is that the draw was never competitive\. Table[9](https://arxiv.org/html/2608.23979#S8.T9)gives five regimes: the attack\-free non\-degenerate corpus, two degenerate\-authoring levels, and two coalition sizes\. The uniform draw captures0\.490\.49of the achievable endorsement mass in the attack\-free regime against the rule’s0\.760\.76, and0\.170\.17against0\.550\.55at a quarter\-electorate coalition — a factor of3\.33\.3\. Its coverage — level with the rule in the attack\-free regime, ahead of it under attack — is purchased entirely by serving material nobody had adopted\. A voter shown the random slate met at least as many reasons, attached to items their fellow constituents had, in the main, passed over\. The greedy ceiling behaves in a way worth dwelling on\. It attains coverage1\.00001\.0000in every regime, as Section[7\.3](https://arxiv.org/html/2608.23979#S7.SS3)led one to expect\. On endorsement mass it*dominates*the rule in the three attack\-free regimes \(0\.790\.79against0\.760\.76atG=0G=0\) and is*dominated*under attack \(0\.380\.38against0\.550\.55at a quarter\-electorate coalition\)\. Under flooding, the label\-reading selector buys its perfect coverage by abandoning what constituents endorsed — it reaches for the rare labels, which under a homogeneity attack are the ones the coalition has not saturated and which almost nobody has adopted\. The inadmissible mechanism is not merely inadmissible; on the axis that measures whether a slate reflects the electorate, it is worse under exactly the conditions a civic deployment must survive\. Finally, atG=0\.5G=0\.5the link terms buy\+2\.8\+2\.8points of coverage for−2\.4\-2\.4points of endorsement mass\. That is not an error and not a defect\. It is a frontier: the two link summands trade breadth of reasons against fidelity to what people endorsed, and there is no system\-level fact about which is correct\. It is exactly the kind of question C[7](https://arxiv.org/html/2608.23979#Thmcriterion7)exists to hand to the person it affects, and Section[11](https://arxiv.org/html/2608.23979#S11)takes up what it means that our clearest quantitative finding turns out to be a menu rather than an answer\. Table 9\.Coverage against endorsement mass \([7](https://arxiv.org/html/2608.23979#S3.E7)\) across five regimes, pooled over both propositions\.GGis the degenerate fraction atE=0\.1E=0\.1;\|A\|\|A\|is coalition size out ofN=1000N=1000\. The greedy ceiling attains coverage1\.00001\.0000in every regime, so only its mass is shown\. The uniform draw is level with the rule on coverage in the attack\-free regime and ahead of it under attack, and loses on mass everywhere, by a factor rising to3\.33\.3; the ceiling dominates on mass in the three attack\-free regimes and is dominated in both attacked ones\. ## 9\.Results III: A Coalition in the Electorate We now admit a coordinated coalition under the model of Section[6\.4](https://arxiv.org/html/2608.23979#S6.SS4): authentication holds, so nobody votes twice and no endorsement is forged, and the coalition’s only instruments are what it writes, where it points its links, and when it acts\. The two natural strategies produce opposite outcomes, and the contrast is the most useful result in this manuscript for anyone actually deploying such a system — it says that the intuitive attack is harmless, that the unintuitive one is severe, and that the defence against the severe one is a single line of the specification\. We then decompose the damage to establish what causes it, and give the coalition its best available escalation to establish that the defence does not merely displace the problem\. ### 9\.1\.Hub\-riding is inert When coalition members author ordinary items and attach reinforcement links to the leading same\-side item, in order to launder its endorsement mass into their own score, completeness does not move\. At every coalition size, on both propositions, the change from the zero\-attacker cell is statistically indistinguishable from zero \(n=200n=200seeds per cell, allp\>0\.50p\>0\.50under Welch’s test\), and the two weight policies differ by less than0\.0020\.002\. The reason is structural\. Completeness is a property of a union of sets, and exchanging one ordinary item for another changes which elements contribute to the union without changing the union much\. Hub\-riding achieves its proximate goal — the attacker’s argument gets seen — while leaving the informational quality of the slate intact\. Whether this constitutes an attack at all is a fair question: a system in which arguing that your point extends a popular point makes your point more visible is arguably working as designed, and this is one of the few places where the right response to an adversarial finding is to accept the behaviour rather than defend against it\. The result also confirms the design choice of Section[4\.4](https://arxiv.org/html/2608.23979#S4.SS4)empirically\. \([8](https://arxiv.org/html/2608.23979#S4.E8)\) takes exactly one hop and computes no fixed point, so there is no eigenvector to farm[Page et al\., 1999](https://arxiv.org/html/2608.23979#bib.bibx71); a coalition that constructs a hub and points its whole corpus at it gains a bounded, one\-hop bonus and nothing compounding\. ### 9\.2\.Label flooding, and the weight policy as a security control The picture inverts entirely when the clones are label\-identical\. Table[10](https://arxiv.org/html/2608.23979#S9.T10)gives the sweep,200200seeds per cell, spread timing so the coalition enjoys no first\-mover cascade\. Under the author\-normalised policy completeness falls from0\.8160\.816at zero attackers to0\.3770\.377at a quarter of the electorate on BRA, and0\.8150\.815to0\.3720\.372on UBI\. Under the flat policy the same coalition drives it to0\.2280\.228and0\.2190\.219\. Every non\-zero cell differs from its baseline atp<\.001p<\.001, and every normalised\-versus\-flat comparison at a non\-zero coalition size differs atp<\.001p<\.001as well\. The defence margin — the completeness that author normalisation retains and a flat policy loses — is0\.1170\.117at a coalition of five percent, widens to0\.1810\.181at fifteen and eases to0\.1510\.151at twenty\-five\. Section[4\.5](https://arxiv.org/html/2608.23979#S4.SS5)claimed the relation\-weight function is a security control rather than a tuning knob; this is the measurement behind the claim, and it should be read against Section[7\.2](https://arxiv.org/html/2608.23979#S7.SS2), where the four structural levers of the attack\-free regime were the only things that moved completeness at all\. The arithmetic behind the defence is Example[3\.9](https://arxiv.org/html/2608.23979#S3.Thmtheorem9)scaled up\. Under the flat policy a lone clone’s link into the hub transfers the hub’s entire endorsement mass, so every clone inherits a score comparable to the most successful non\-coalition item in the pool and the top of the ranking fills with duplicates\. Under author normalisation the same link transfers a fraction\|A\(j,k\)\|/Vσ\|A\(j,k\)\|/V^\{\\sigma\}; a solo clone inherits about a thousandth of the hub’s mass\. To buy what the flat policy gives away, the coalition must make many members assert the*same*link — which means the cost of the attack scales with its size, and, more importantly, that the attack becomes*visible*in the public link record as an anomalous concentration of identical assertions\. A defence that converts a covert manipulation into an overt one is doing exactly what a civic mechanism should do, and note that it does so without any term that reads*which*participants asserted the link: \([9](https://arxiv.org/html/2608.23979#S4.E9)\) counts distinct authors and remains compliant with C[3](https://arxiv.org/html/2608.23979#Thmcriterion3)\. Table 10\.Flooding attack under spread timing: mean combined completeness against coalition size, both weight policies, both propositions,200200seeds per cell\. The final column gives the defence margin — how much completeness author normalisation retains that a flat policy loses — averaged over the two propositions\. Hub\-riding, not shown, produces no significant change at any coalition size\. ### 9\.3\.The mean over sides hides how one\-sided the damage is One caveat applies to both aggregators in Equations[4](https://arxiv.org/html/2608.23979#S3.E4)and[3](https://arxiv.org/html/2608.23979#S3.E3)\. About2%2\\%of constituents —19\.619\.6of987987at the reference configuration — receive a slate on one side only and so contribute a single value, whereas the factor1/2N1/2Nin \([3](https://arxiv.org/html/2608.23979#S3.E3)\) presumes two\. The figure we report asc¯\\bar\{c\}throughout is the mean over slates actually served, which coincides with \([3](https://arxiv.org/html/2608.23979#S3.E3)\) when every voter is served on both sides and otherwise sits0\.0030\.003–0\.0070\.007below it, the one\-sided voters being those whose remaining side is the sparse one;c¯min\\bar\{c\}^\{\\min\}is necessarily restricted to the voters served on both\. Both discrepancies are an order of magnitude smaller than any effect discussed here, but the asymmetry is worth naming: an unserved side is a coverage failure that neither equation counts as one\. The substantive conclusions are unchanged\. The minimum tracks the mean at an offset of0\.040\.04–0\.080\.08across the whole grid, the damage it registers is55–13%13\\%larger than the mean’s at every coalition size, and the advantage of author normalisation over a flat policy is not merely preserved but wider under it,0\.1330\.133–0\.1880\.188against0\.1180\.118–0\.1820\.182, at the same significance\. The choice of aggregator does not decide any claim we make\. What it does change is what a reader can see\. Table[11](https://arxiv.org/html/2608.23979#S9.T11)reports, for the same runs as Table[10](https://arxiv.org/html/2608.23979#S9.T10), the mean over voters of the worse\-covered side, the mean within\-voter gap between the two sides, and the share of constituents whose worse side falls below one half\. The gap roughly doubles under attack, from0\.0850\.085with no coalition to0\.150\.15–0\.160\.16at the largest ones: flooding does not lower coverage evenly, it unbalances it\. The last column is the consequence\. At a15%15\\%coalition under author normalisation the mean reads0\.520\.52, which invites the reading that a typical voter still meets half of the reasons; in those same runs58%58\\%of constituents have a side below0\.50\.5, and under a flat policy94%94\\%do\. Both statements are true of the same electorate, and only the first is visible in \([3](https://arxiv.org/html/2608.23979#S3.E3)\)\. Table 11\.Side imbalance under label flooding, on the runs of Table[10](https://arxiv.org/html/2608.23979#S9.T10)\(200 seeds per cell, pooled over the two propositions\)\. “min” isc¯min\\bar\{c\}^\{\\min\}of \([4](https://arxiv.org/html/2608.23979#S3.E4)\), “gap” the mean over voters of the difference between their two sides, and “<0\.5<\\\!0\.5” the share of voters whose worse side falls below one half\.We keep \([3](https://arxiv.org/html/2608.23979#S3.E3)\) as the reported instrument\. It is linear, so a drop in it decomposes into the per\-voter and per\-side contributions that make an attack attributable to a subpopulation, and it is the expectation of the coverage seen by a reader who stops at a uniformly random point, which is the quantity the three measures are jointly framed around; the minimum has neither property\. But the mean supports a narrower reading than it appears to\. A completeness of0\.520\.52is a statement about an average side, not about an average voter, and an adversary who concentrates on one side is rewarded by exactly that difference\. Where a deployment sets a threshold below which it will not certify a poll, the threshold belongs on the imbalance, not on the mean\. ### 9\.4\.The refresh interval matters only when someone is attacking Score caches are re\-read after every constituent \(Section[6\.2](https://arxiv.org/html/2608.23979#S6.SS2)\), so no slate is scored against a snapshot older than the vote before it\. Widening the interval toMMconstituents makes it the latency of the endorsement feedback loop, and that lag reinterprets both preceding results at once: a coalition accumulating endorsement mass getsMMvotes of head start before the quantity it inflates is read again, and a rule scoring against a stale snapshot is not ranking the corpus the constituent is about to see\. What lags is the tallies and the relation weights, not the corpus: a newly authored item is appended and forces a re\-rank at anyMM\. CrossingM=200M=200against the reportedM=1M=1with the coalition makes the objection an estimable interaction\. The experiment was run on a third proposition,OPT\-OUT\(*should primary pupils be able to study without computers and an internet connection?*, thirty canonical reasons per side spanning pedagogical, developmental, equity\-of\-access and administrative considerations\), and is reported on its own rather than pooled with the two of Section[6\.1](https://arxiv.org/html/2608.23979#S6.SS1):M∈\{1,200\}M\\in\\\{1,200\\\}crossed with no coalition against the co\-signed flood of Section[9\.6](https://arxiv.org/html/2608.23979#S9.SS6)at a tenth of the electorate in groups ofC=5C=5, three arms, the two extremes of the degenerate axis,5050seeds shared across all four corners,12001200runs\. Table[12](https://arxiv.org/html/2608.23979#S9.T12)supports two conclusions of different kinds\. With no coalition the interval changes nothing the ordering claims rest on: on the non\-degenerate poolfull−\-randomis−0\.0011\-0\.0011atM=1M=1and−0\.0015\-0\.0015atM=200M=200\(bothp\>0\.5p\>0\.5\), both consistent with the attack\-free contrast of Table[7](https://arxiv.org/html/2608.23979#S8.T7)\(\+0\.0024\+0\.0024, suggestive only\); under degenerate authoring the rule’s advantage is\+0\.0222\+0\.0222and\+0\.0202\+0\.0202\(4×10−64\\times 10^\{\-6\},1×10−51\\times 10^\{\-5\}\) — the same effect whether the loop is fresh or two hundred votes stale\. With the coalition the interval matters, in the unhelpful direction: lagging the refresh toM=200M=200*raises*the ranked arm by0\.0130\.013of completeness and leaves the uniform draw untouched\. The interaction — the effect of the lag onfull−\-randomunder attack minus the same effect without — is\+0\.0136\+0\.0136on the non\-degenerate pool \(95% CI\[\+0\.0062,\+0\.0209\]\[\+0\.0062,\+0\.0209\],p=5×10−4p=5\\times 10^\{\-4\}\) and\+0\.0069\+0\.0069under degenerate authoring \(CI\[−0\.0011,\+0\.0150\]\[\-0\.0011,\+0\.0150\],p=0\.089p=0\.089\)\. Table 12\.Completeness at the four corners of the refresh\-interval×\\timescoalition results table, OPT\-OUT,5050seeds per cell, author\-normalised weights, co\-signed flood atC=5C=5\.MMis the number of constituents between cache refreshes;M=1M=1is the reference configuration\. Thefull−\-randomrows are seed\-paired differences with two\-sided pairedtt\-tests\.EEis inert atG=0G=0\.The mechanism is the order\-invariance of Remark[1](https://arxiv.org/html/2608.23979#Thmremark1), visible slate by slate; Table[13](https://arxiv.org/html/2608.23979#S9.T13)isolates each arm\.randomnever consults the cached scores, and its slates are identical item for item and position for position across intervals at every corner, so its completeness is exactly equal on all5050seeds\.endorse\-onlyis exactly invariant too, but only without a coalition: over ten seeds its19,70219\{,\}702slates have identical membership atM=1M=1andM=200M=200while93%93\\%are served in a different order, which completeness cannot see\. Under the coalition that breaks — at seed33only801801of19881988slates keep their membership — and completeness moves\+0\.0120\+0\.0120\(5×10−105\\times 10^\{\-10\}\)\. What the flood supplies is not staleness but*speed*: it makes tallies move far enough within one window for the stale snapshot to select a different twenty items\.fullalso reads relation weights, whose staleness changes which items are served on40%40\\%of slates atG=0G=0and49%49\\%atG=0\.5G=0\.5even with no attacker, but there the coverage gained and lost cancels \(−0\.0004\-0\.0004,−0\.0020\-0\.0020, bothp\>0\.35p\>0\.35\)\. Table 13\.Cost of lagging the refresh interval, per arm: mean seed\-pairedM=200M=200minusM=1M=1completeness, OPT\-OUT,5050seeds\.*exact*marks cells in which the two intervals produce the same completeness on every seed to the last stored digit, so no test applies\.The prefix measures agree at both intervals\. Ranking’s lead peaks atp5p\_\{5\}in five of the eight corner\-by\-load cells and betweenp2p\_\{2\}andp10p\_\{10\}in the rest: under degenerate authoring it is\+0\.1363\+0\.1363against\+0\.1133\+0\.1133with no coalition and\+0\.0786\+0\.0786against\+0\.0652\+0\.0652with one\. The lead is lost before the full slate in one cell only — the non\-degenerate pool under attack atM=200M=200,\+0\.0011\+0\.0011atp5p\_\{5\}and−0\.0006\-0\.0006atp10p\_\{10\}, the corner leaving a ranking rule least to discriminate between\. Scoring each constituent on the worse\-served of their two sides rather than averaging leaves the pattern intact:full−\-randomon that side is−0\.0365\-0\.0365and−0\.0222\-0\.0222under attack on the non\-degenerate pool,\+0\.0208\+0\.0208and\+0\.0213\+0\.0213under degenerate authoring without one \(allp<5×10−4p<5\\times 10^\{\-4\}\), and the gap between a constituent’s two slates is null in all eight cells \(p≥0\.26p\\geq 0\.26\)\. Two contrasts, atp=0\.043p=0\.043andp=0\.089p=0\.089, are the kind Section[6\.5](https://arxiv.org/html/2608.23979#S6.SS5)asks be read as suggestive; the null without a coalition, the interaction on the non\-degenerate pool and the exact invariance of the unranked arm do not depend on them\. For the charter the reading is a small negative one, worth stating because the opposite is the intuitive guess\.MMis a published policy parameter like \([9](https://arxiv.org/html/2608.23979#S4.E9)\), and refreshing after every vote sounds like the setting that keeps up best with an attack\. It is not: under a coalition the shorter interval carries the flood into the ranked slates slightly faster and leaves the uniform draw exactly where it was, and with no coalition it changes nothing\. Reporting atM=1M=1is thus the conservative choice — atM=200M=200the rule would have looked0\.0130\.013better under attack than it does — and the defence remains the line that counts distinct authors, not the rate at which its inputs are read\. ### 9\.5\.The collapse is homogeneity, not hyperactivity A flooding attacker differs from a non\-coalition constituent in four ways at once, and only one of them is the claim\. It authors on every turn rather than with probabilityπown\\pi\_\{\\mathrm\{own\}\}; it authors the*same*narrow label set as every other member; it links on every turn rather than with probabilityπlnk\\pi\_\{\\mathrm\{lnk\}\}; and it aims its links at the two most endorsed items rather than at the most related one\. The first and third inflate the corpus and the link graph, the fourth concentrates endorsement mass, and any of them could depress completeness alone, so comparing a coalition against an attacker\-free baseline confounds all four\. We therefore ran the two rate\-matched controls of Section[6\.4](https://arxiv.org/html/2608.23979#S6.SS4), at every coalition size, on both propositions, under both weight policies,100100seeds per cell, seed\-paired with the flooding sweep \(40004000runs\)\. The match is tight — at a tenth of the electorate on BRA the flooding arm produces190\.6190\.6items and837837links against the heterogeneous control’s191\.6191\.6and834834— so the arms differ in label distribution and in nothing else the pipeline can observe\. Table[14](https://arxiv.org/html/2608.23979#S9.T14)gives the decomposition\. Hyperactivity is real but small: a coalition holding a quarter of the electorate that authors and links on every turn with heterogeneous labels costs0\.0670\.067of completeness under normalisation, for an innocuous reason — tripling the corpus enlarges the denominator\|Λσ\|\|\\Lambda^\{\\sigma\}\|faster than a fixed twenty\-item slate can cover it\. Homogeneity costs0\.3800\.380on top of that\. Across coalition sizes and both weight policies, between78%78\\%and85%85\\%of the collapse is attributable to label homogeneity alone, and the share*rises*with coalition size: volume damage saturates while homogeneity damage does not\. Hub aiming, isolated by the third arm, is negligible under normalisation \(≤0\.006\\leq 0\.006at every coalition size, allp≥0\.14p\\geq 0\.14\) and worth at most0\.0240\.024under the flat policy — consistent with the mechanism, since author normalisation is precisely the rule that discounts many identical assertions aimed at one target\. Two findings now agree from opposite directions: Section[7\.2](https://arxiv.org/html/2608.23979#S7.SS2)found link volume harmless, and this control finds authoring volume largely harmless too\. What the pipeline cannot absorb is many voices saying one thing\. Table 14\.Decomposing the flooding collapse, pooled over the two propositions,100100seeds per cell\.*Heterogeneous*is the rate\- and corpus\-matched control in which attackers author and link at the same inflated rates and aim at the same hubs but draw labels independently\.Δvol\\Delta\_\{\\mathrm\{vol\}\}is completeness lost to sheer volume \(baseline minus heterogeneous\);Δhom\\Delta\_\{\\mathrm\{hom\}\}is the additional loss attributable to label homogeneity alone \(heterogeneous minus flooding\)\. EveryΔhom\\Delta\_\{\\mathrm\{hom\}\}is significant atp<10−40p<10^\{\-40\}under Welch’s test\.mean completenessdecompositionCoalitionheterog\.flooding\(baseline\)Δvol\\Delta\_\{\\mathrm\{vol\}\}Δhom\\Delta\_\{\\mathrm\{hom\}\}homog\. share*author\-normalised weights*5%5\\%0\.7970\.7110\.8210\.0240\.0240\.0860\.08679%79\\%10%10\\%0\.7800\.6090\.8210\.0400\.0400\.1720\.17281%81\\%15%15\\%0\.7720\.5190\.8210\.0490\.0490\.2530\.25384%84\\%20%20\\%0\.7620\.4350\.8210\.0580\.0580\.3280\.32885%85\\%25%25\\%0\.7530\.3730\.8210\.0670\.0670\.3800\.38085%85\\%*flat weights*5%5\\%0\.7690\.5950\.8180\.0490\.0490\.1740\.17478%78\\%10%10\\%0\.7500\.4370\.8180\.0680\.0680\.3130\.31382%82\\%15%15\\%0\.7430\.3410\.8180\.0740\.0740\.4020\.40284%84\\%20%20\\%0\.7370\.2750\.8180\.0810\.0810\.4620\.46285%85\\%25%25\\%0\.7310\.2240\.8180\.0870\.0870\.5070\.50785%85\\% ### 9\.6\.The coalition cannot coordinate its way out The defence argument of Section[9\.2](https://arxiv.org/html/2608.23979#S9.SS2)describes what a coalition*must*do to defeat normalisation; it does not show that doing it fails\. A co\-signing coalition is strictly more powerful than one that does not, since co\-signing costs it nothing in membership, so we gave it the capability\. The coalition is partitioned into groups ofCC; each group publishes one poison item per side, and every member endorses that item and re\-asserts the same two links from it, driving the distinct\-author numerator of \([9](https://arxiv.org/html/2608.23979#S4.E9)\) from one to the group’s per\-side size\.C=1C=1is the attack of Table[10](https://arxiv.org/html/2608.23979#S9.T10)and reproduces its per\-seed completeness exactly, to the last stored digit, across all eight cells — an in\-family control\. We sweptC∈\{1,2,5,10,25,50\}C\\in\\\{1,2,5,10,25,50\\\}at coalitions of a tenth and a quarter, both propositions, both weight policies,48004800runs\. Table[15](https://arxiv.org/html/2608.23979#S9.T15)reports the cleanest finding in the manuscript: coordination is strictly counterproductive\. Completeness rises monotonically inCCat every coalition size, on both propositions, under both weight policies\. The uncoordinatedC=1C=1attack is the coalition’s optimum within the family, and a fully coordinated coalition holding a quarter of the electorate leaves completeness at0\.7590\.759against an attacker\-free baseline of0\.8150\.815— it has spent a quarter of the electorate to buy six points\. The reason is a rate mismatch the coalition cannot escape\. Raising the numerator requires spending members on one item; members are finite; so the number of payload\-carrying items falls as1/C1/Cwhile the co\-signature count rises only linearly, and it rises against a denominator — constituents voting that side — that co\-signing does not touch\. Measured on BRA at the25%25\\%coalition, going fromC=1C=1toC=50C=50multiplies mean co\-signers per edge by3\.43\.4and the most concentrated edge by1\.81\.8, while cutting poison items from250\.1250\.1to10\.010\.0, a factor of2525\. The non\-coalition corpus is unmoved throughout \(76\.376\.3items atC=1C=1,76\.776\.7atC=50C=50\)\. Completeness is damaged by items occupying slate slots, and the coalition has traded away twenty\-five of those for every threefold gain in transfer\. Table 15\.The coordinated adversary, pooled over the two propositions,100100seeds per cell\. Group sizeCCis the number of coalition members sharing one poison item and co\-signing its links;C=1C=1is the uncoordinated attack of Table[10](https://arxiv.org/html/2608.23979#S9.T10)\. Payload items and co\-signers per edge are measured on BRA at the25%25\\%coalition\. Completeness*rises*monotonically withCCin every cell: coordination helps the electorate, not the coalition\.Note also what happens to the gap between the two weight policies asCCrises: it closes, from0\.1490\.149atC=1C=1to0\.0050\.005atC=50C=50at the25%25\\%coalition\. This is the expected signature\. Normalisation exists to discount solo assertions; when the coalition co\-signs everything, the two policies are computing nearly the same quantity, and the coalition has arrived at a regime where its own concentration is what limits it\. ### 9\.7\.What the adversarial results say about the charter Three consequences, each an argument for legibility rather than an argument that merely happens to be compatible with it\. First, the effective defence is a*published policy parameter*, not a detector: nothing in this section trains a classifier, scores a participant’s trustworthiness, or removes anyone’s material\. \([9](https://arxiv.org/html/2608.23979#S4.E9)\) is one line, it counts distinct authors, and it is worth ten points of completeness against a coalition holding a quarter of the electorate\. A deployment can publish it, a participant can verify it was applied, and an adversary who reads it learns only that the attack is expensive — the property one wants a published defence to have\. Second, the defence works by making the attack*visible*\. A coalition that pays the cost of co\-signing writes its coordination into the public link record, where an anomalous concentration of identical assertions from distinct authors is directly observable by anyone holding a replica\. A learned ranker that resisted the same attack would do so through parameters nobody can inspect, leaving participants unable to distinguish successful defence from successful attack\. Third, the results relocate rather than remove the residual risk\. Under authentication the surviving exposure is not manipulation of the ranking — hub\-riding is inert, co\-signing is self\-defeating — but*corpus capture*: a coalition large enough simply crowds the reason space with redundancy, and Section[9\.5](https://arxiv.org/html/2608.23979#S9.SS5)shows four fifths of the damage comes from that homogeneity rather than from anything the selector does\. The corresponding mitigations are not ranking mitigations\. They are census integrity \(Section[10](https://arxiv.org/html/2608.23979#S10.SS0.SSS0.Px3)\), which is what bounds coalition size at all, and slate capacity, which Section[7\.2](https://arxiv.org/html/2608.23979#S7.SS2)shows is the widest lever available\. A recommender is not where this class of attack should be defeated, and a charter\-compliant one at least makes that visible on the record\. ## 10\.Peer\-to\-Peer Realisation onDDP2P The charter of Section[4](https://arxiv.org/html/2608.23979#S4)can be honoured on a central server, but only as a promise\. Determinism, evidence locality and reproducibility are properties of a*computation*, and if one party owns the machine that performs it, participants are trusting that party’s word about what ran — and configurability granted by an operator is revocable by the same operator\. The remedy is architectural: give each participant a replica of the items they care about and let them evaluate the rule themselves\. Proposition[3\.8](https://arxiv.org/html/2608.23979#S3.Thmtheorem8)already established that this is possible, because \([8](https://arxiv.org/html/2608.23979#S4.E8)\) reads only an item and its out\-neighbours\. This section shows thatDDP2P[Silaghi et al\., 2013](https://arxiv.org/html/2608.23979#bib.bibx89);[Silaghi et al\., 2013a](https://arxiv.org/html/2608.23979#bib.bibx90)supplies almost everything else: what the platform provides, how the model’s objects land on its item types, the identity problem that decentralisation makes harder, evaluation over an incomplete replica, and what the empirical findings of Sections[8](https://arxiv.org/html/2608.23979#S8)–[9](https://arxiv.org/html/2608.23979#S9)imply for a peer deployment specifically\. #### What the platform provides\. DDP2Pis a project developing an open\-source platform for decentralised deliberative petition drives, built around commitments that turn out to be the ones the charter needs\.*Items are self\-contained and globally identified*: every peer record, organisation, constituent, motion, justification, signature, vote, witnessing statement, news item and translation carries everything needed to interpret it and is named by an identifier derived from a public key with a creation date, or from a digest of its content[Silaghi et al\., 2013](https://arxiv.org/html/2608.23979#bib.bibx89)\. Identifiers compose hierarchically — an organisation’s derives from its founding parameters, a motion’s from the organisation and its text, a justification’s from the motion and its own text, a vote’s from the motion, the constituent and the justification cited — so two peers who have never communicated agree on the name of everything and semantically distinct items cannot collide\.*Synchronisation is push–pull gossip with a horizon*[Silaghi et al\., 2013a](https://arxiv.org/html/2608.23979#bib.bibx90);[Demers et al\., 1988](https://arxiv.org/html/2608.23979#bib.bibx32): a request carries the requester’s interests and a time horizon and the answer carries items newer than that horizon, with no global index and no authoritative replica\.*Connectivity needs no owned infrastructure*: directory servers help peers find each other and data servers hold items for offline peers, but neither is trusted, both are replaceable, and their content is verifiable against signatures; whether a peer relays for others is under that peer’s own control, by explicit design[Alhamed & Silaghi, 2014](https://arxiv.org/html/2608.23979#bib.bibx3), and mobile ad hoc and vehicular operation have been studied as extreme cases of the same idea[Dhannoon et al\., 2013](https://arxiv.org/html/2608.23979#bib.bibx33);[Dhannoon, 2013](https://arxiv.org/html/2608.23979#bib.bibx34)\. Finally,*organisations are rules rather than accounts*: an organisation is a definition of a constituency and a jurisdiction, constituencies may be defined recursively with membership settled by a membership referendum — a fixpoint grassroots organisations resolve bottom\-up rather than by administrative decree[Silaghi et al\., 2013](https://arxiv.org/html/2608.23979#bib.bibx89)— motions are Robert’s motions \(Section[4\.7](https://arxiv.org/html/2608.23979#S4.SS7)\), and justifications are the arguments attached to signatures\. #### Mapping the model onto the platform\. Table[16](https://arxiv.org/html/2608.23979#S10.T16)gives the correspondence\. It is close to one\-to\-one, unsurprisingly since the model of Section[3](https://arxiv.org/html/2608.23979#S3)was distilled from this line of work[Kattamuri et al\., 2005](https://arxiv.org/html/2608.23979#bib.bibx50);[Silaghi & Roussev, 2014](https://arxiv.org/html/2608.23979#bib.bibx92);[Silaghi et al\., 2017](https://arxiv.org/html/2608.23979#bib.bibx93), but the residual mismatches are where the engineering lies, and two rows carry most of the weight\. The reason labellingλ\\lambdais new, and if labels were assigned centrally the assigning party would hold semantic power over visibility — exactly the concentration C[4](https://arxiv.org/html/2608.23979#Thmcriterion4)exists to prevent\. The safe arrangement is that labels are declared by the justification’s own author as part of the signed item, so a label is a claim like any other: checkable against the text by any reader and disputable through the ordinary argumentation mechanism\. A mining pipeline \(Section[2](https://arxiv.org/html/2608.23979#S2.SS0.SSS0.Px4)\) may propose labels, but its proposals are advisory items, not ground truth; this leavesλ\\lambdaadversarially controllable, which Section[12](https://arxiv.org/html/2608.23979#S12)takes up\. The slate𝒮i\\mathcal\{S\}\_\{i\}is likewise new, and need not leave the device at all — though a constituent who wants a public record of what they saw can publish it as a signed item, converting C[5](https://arxiv.org/html/2608.23979#Thmcriterion5)from a platform guarantee into a personally held receipt, which is the strongest form the criterion can take\. Table 16\.Mapping the alternative\-based poll of Definition[3\.1](https://arxiv.org/html/2608.23979#S3.Thmtheorem1)ontoDDP2Pitem types\. Entries markedneware what a deployment would have to add; everything else already exists\. #### Identity: the one thing decentralisation makes harder\. Everything above assumes endorsement counts mean something, which assumes identities are not free\. In a centralised deployment with an authenticated roll this is the registrar’s problem; open peer\-to\-peer membership makes it the system’s problem, and it is the classical one[Douceur, 2002](https://arxiv.org/html/2608.23979#bib.bibx35)\.DDP2P’s answer is a decentralised census with witnessing: constituents certify one another’s existence and eligibility, the certifications are signed items propagating like any other, and reputation over the witnessing graph estimates how much of the claimed population is real[Qin et al\., 2013a](https://arxiv.org/html/2608.23979#bib.bibx78);[Qin et al\., 2013b](https://arxiv.org/html/2608.23979#bib.bibx79);[Qin et al\., 2013](https://arxiv.org/html/2608.23979#bib.bibx77);[Qin et al\., 2014](https://arxiv.org/html/2608.23979#bib.bibx76), with a Bayesian extension of the web\-of\-trust idea estimating the number of distinct eligible signatories behind a set of signatures — directly the quantity a petition threshold depends on[Silaghi et al\., 2016](https://arxiv.org/html/2608.23979#bib.bibx91)\. The structural point is that different observers may run different eligibility criteria over the same signed census data and reach their own conclusions: the platform supplies verifiable evidence, not a verdict\. That is C[7](https://arxiv.org/html/2608.23979#Thmcriterion7)at the level of the constituency rather than the slate\. Section[6](https://arxiv.org/html/2608.23979#S6)assumes this problem solved, and the assumption is what makes the adversarial results interpretable — under authentication a coalition cannot inflateEEand the link graph is the only surface left\. It also means census integrity is not a side condition but the binding constraint: Section[9\.7](https://arxiv.org/html/2608.23979#S9.SS7)located the residual risk in corpus capture, and what bounds corpus capture is what bounds coalition size\. #### Evaluating the rule on an incomplete replica\. A peer holds what it has synchronised, generally a subset of what exists\. This is the sharpest technical objection to local evaluation and Proposition[3\.8](https://arxiv.org/html/2608.23979#S3.Thmtheorem8)only half answers it\. ###### Proposition 10\.1 \(Monotone degradation\)\. Let𝒥′⊆𝒥σ\\mathcal\{J\}^\{\\prime\}\\subseteq\\mathcal\{J\}^\{\\sigma\}be the items a peer holds and𝒮′\\mathcal\{S\}^\{\\prime\}the slate Algorithm[1](https://arxiv.org/html/2608.23979#algorithm1)produces from them\. Then𝒮′\\mathcal\{S\}^\{\\prime\}is exactly the slate the same rule and policy would produce on the full pool restricted to𝒥′\\mathcal\{J\}^\{\\prime\}\. Missing*items*can only lower achievable completeness, never corrupt the score of a held item\. Missing*votes and links*, however, lower the computed score of a held item, so the peer’s scores are lower bounds on the true ones\. The second half is the whole difficulty\. A peer holding a justification but not yet the votes citing it underestimatesEE; a peer missing links underestimates inherited standing\. Three mitigations apply, all ordinary distributed\-systems engineering\. Votes and links are small items and are prioritised in the pull request over justification text, so counting evidence converges faster than the corpus\. The score is a sum of non\-negative terms, so partial evidence yields a lower bound and the interface can state the replica’s coverage of the known item count — a peer can be told it holds94%94\\%of the votes and decide whether that is enough to act on\. And the underlying structure is append\-only with union merge, so replicas converge without conflict resolution in the manner of a grow\-only set[Shapiro et al\., 2011](https://arxiv.org/html/2608.23979#bib.bibx85), while a digest exchange in the style of Merkle hashing[Merkle, 1988](https://arxiv.org/html/2608.23979#bib.bibx64)makes divergence cheap to detect\. Algorithm[4](https://arxiv.org/html/2608.23979#algorithm4)states the resulting local cycle, including the reporting step that makes incompleteness visible\. There is a real trade here: a centralised deployment computes the rule on complete evidence and asks you to trust the computation, whereas a decentralised one computes a verifiable rule on evidence that may be incomplete and tells you how incomplete it is\. For a civic process the second is the better failure mode, because incompleteness is visible and declining trustworthiness is not\. Algorithm 4Local slate computation on a peer holding a partial replicaGiven:local store 𝒟\\mathcal\{D\}; motion mm; local policy θ\\theta; neighbour set 𝒩\\mathcal\{N\}; horizon hh Yields:a slate, plus a checkable statement of the evidence it rests on 1foreach*n∈𝒩n\\in\\mathcal\{N\}*do 2send a request naming mm, this peer’s interests, and horizon hh; 3 𝒟←\\mathcal\{D\}\\leftarrowMergeSigned\(*𝒟\\mathcal\{D\}, signed items returned bynn*\);//union of signed items; no conflict resolution needed 4end foreach 5discard items whose signature or identifier derivation fails to verify; 6 E←E\\leftarrowtally of held votes per justification; 7 ωr←\\omega\_\{\\mathrm\{r\}\}\\leftarrowpolicy of θ\\thetaapplied to held links; 8 𝒮←\\mathcal\{S\}\\leftarrowScoreAndServe\(*held items ofmm,θ\\theta,KK*\); 9report alongside 𝒮\\mathcal\{S\}: counts of held votes, links and justifications, and the horizon hh; 10return 𝒮\\mathcal\{S\}; #### What the findings imply for a peer deployment\. Three results change their character when read against this substrate rather than a server\.*Ordering matters more, not less*: Section[8\.2](https://arxiv.org/html/2608.23979#S8.SS2)found the rule’s advantage over an unordered draw concentrated in the first few positions, and on a peer holding an incomplete replica the effective slate is shorter still, so the fraction of the value delivered by the first five items rises\.*Degenerate authoring is more likely, not less*: open membership lowers the cost of submitting, which is the point, and raises the share of submissions that fail to justify — exactly the regime where Section[8\.3](https://arxiv.org/html/2608.23979#S8.SS3)finds the rule’s margin largest and Section[8\.4](https://arxiv.org/html/2608.23979#S8.SS4)finds the link summands supplying most of it, so the two terms a server deployment might reasonably drop as inert are the terms a peer deployment most needs\.*The weight policy must be local*: Section[9\.2](https://arxiv.org/html/2608.23979#S9.SS2)makesωr\\omega\_\{\\mathrm\{r\}\}a security control worth ten points of completeness, and on a server the operator picks it for everyone whereas on a peer each participant picks it and can compute what the other choice would have given them\. Since some of these choices are frontier positions with no correct answer \(Section[8\.5](https://arxiv.org/html/2608.23979#S8.SS5)\), configurability stops being a feature and becomes the only coherent way to hold a parameter that is simultaneously a security control and a value judgement\. ## 11\.Discussion The results admit a compact summary: the charter is cheap, the instrument matters more than the mechanism, the security lives in one line of policy, and the remaining choices are not the system’s to make\. Each cuts against a default assumption about civic recommenders — that transparency costs accuracy, that one quality metric suffices, that robustness comes from detection, and that a well\-designed system should decide\. *The charter is cheap, and the cheapness is measurable\.*Section[7\.3](https://arxiv.org/html/2608.23979#S7.SS3)put the price of semantic abstinence at0\.031±0\.0140\.031\\pm 0\.014against a ceiling that upper\-bounds every procedure applied to the same pool, admissible or not, and four fifths of the observed incompleteness was vocabulary that did not yet exist, which no procedure recovers\. The entire competitive advantage available to an unconstrained learned ranker is therefore three points of completeness, purchased by reading what C[4](https://arxiv.org/html/2608.23979#Thmcriterion4)forbids — against0\.100\.10for raising the authoring rate from0\.020\.02to0\.100\.10and0\.140\.14for doubling the slate\. The usual argument for opacity is that legibility costs quality and the cost is unknown; here it is known, bounded, and small relative to the levers a deployment actually controls\. *The instrument mattered more than the mechanism\.*The most transferable lesson is methodological\. We evaluated a ranking rule with a set functional and concluded, across40004000seed\-paired runs, that it was indistinguishable from a random subset — an artefact of the measurement that two remarks derivable from the definition \(Remarks[1](https://arxiv.org/html/2608.23979#Thmremark1)–[2](https://arxiv.org/html/2608.23979#Thmremark2)\) predicted in advance\. Coverage\-style aggregates are the default in the diversity\-aware recommender literature[Adomavicius & Kwon, 2012](https://arxiv.org/html/2608.23979#bib.bibx1);[Carbonell & Goldstein, 1998](https://arxiv.org/html/2608.23979#bib.bibx22), and any evaluation of a civic selector reporting only such an aggregate is exposed to the same null\. *Robustness came from policy, not from detection\.*Nothing in Section[9](https://arxiv.org/html/2608.23979#S9)trains a classifier, scores trustworthiness, or removes material\. The effective defence is \([9](https://arxiv.org/html/2608.23979#S4.E9)\): count distinct authors, divide by voters on that side\. It is one line, publishable, verifiable by any participant, and worth0\.1510\.151–0\.1810\.181of completeness against a coalition holding a fifth of the electorate; the available escalation makes the coalition monotonically weaker\. Two features generalise\. The defence works by making the attack expensive and*visible*— a co\-signing coalition writes its coordination into the public link record — and it is compatible with author blindness, since \([9](https://arxiv.org/html/2608.23979#S4.E9)\) counts how many distinct people asserted a link and never which, so robustness did not require reintroducing the reputation hierarchy C[3](https://arxiv.org/html/2608.23979#Thmcriterion3)exists to exclude\. That these are compatible was not obvious in advance\. Section[9\.7](https://arxiv.org/html/2608.23979#S9.SS7)also relocated rather than removed the residual risk: under authentication what survives is corpus capture, which belongs to census integrity and slate capacity rather than to ranking\. Section[8\.5](https://arxiv.org/html/2608.23979#S8.SS5)found that atG=0\.5G=0\.5the link summands buy2\.82\.8points of coverage for2\.42\.4points of endorsement mass\. That is not a result with a right answer but a frontier position, and choosing among such positions is choosing between breadth of reasons represented and fidelity to what constituents took up\. We take this as the strongest available argument for C[7](https://arxiv.org/html/2608.23979#Thmcriterion7), and it arrived from an unexpected direction: the case for participant\-held parameters is usually made on autonomy grounds, whereas here it is forced by the measurements\. A platform that picked a point on that frontier and presented it as neutral would be making a political choice while denying it\. Four consequences follow for deployment\.*Invest in authoring, not in ranking*: the dominant lever is how quickly the reason space matures, and the selection component of the shortfall is a fifth the size of the temporal one\.*Publish the weight policy and treat it as a security control*: it is the one parameter with an order\-of\-magnitude effect under attack, and a deployment shipping a flat default has left its main defence unarmed without the participant being able to tell\.*Regulatory alignment is already close*: the Digital Services Act requires very large platforms to disclose recommender parameters and offer a non\-profiling option[European Parliament and Council, 2022](https://arxiv.org/html/2608.23979#bib.bibx38), and the AI Act imposes transparency and human\-oversight duties on systems used in democratic processes[European Parliament and Council, 2024](https://arxiv.org/html/2608.23979#bib.bibx39)\. A published rule over public evidence with participant\-held parameters satisfies the letter of both without a compliance layer, because there is nothing to disclose that is not already disclosed\. ## 12\.Limitations The following would change our conclusions, and we list them in descending order of how much\. Several are stated more sharply than a reader would infer from the results alone, because we would rather over\-declare than have a finding survive on an unexamined assumption\. #### The electorate is simulated\. Every number here describes agents, not people\. Adoption is TF–IDF similarity to a position text; opinions do not update; nobody gets bored, persuaded, or strategic beyond the modelled coalitions\. Following Section[2](https://arxiv.org/html/2608.23979#S2.SS0.SSS0.Px7)we restrict claims to statements about mechanism under a stated model\. Nothing here licenses a claim about the magnitude any quantity would take in a human electorate\. #### The mechanism result rests on one modelled fact\. The degenerate\-authoring findings of Sections[8\.3](https://arxiv.org/html/2608.23979#S8.SS3)and[8\.4](https://arxiv.org/html/2608.23979#S8.SS4)descend from the observation that degenerate items are adopted less —1\.451\.45endorsements against10\.9410\.94— and that follows from the simulator’s cosine\-similarity adoption step, a property of the agents rather than of the rule\. The finding is that*the rule inherits and amplifies whatever discrimination the electorate itself exercises*\. If a human electorate endorsed reason\-free submissions at the same rate as reasoned ones, the link summands would revert to the inertness of Table[6](https://arxiv.org/html/2608.23979#S8.T6), and the coverage margin would go with them\. We regard establishing that adoption rate empirically as the single most valuable follow\-up in this programme\. #### One round\. Constituents vote once\. Multi\-round deliberation with opinion revision would change adoption dynamics, the endorsement distribution, and probably the link structure\. Whether the rule’s ordering advantage survives revision is untested\. This was implemented but not thoroughly evaluated\. #### Statistical multiplicity\. Section[6\.5](https://arxiv.org/html/2608.23979#S6.SS5)declares that we do not correct across the manuscript\. The ordering contrasts of Section[8\.2](https://arxiv.org/html/2608.23979#S8.SS2)number twenty\-four; the two link\-term effects atp≈10−2p\\approx 10^\{\-2\}are reported as suggestive and should not be built on\. The effects we do build on sit atp<10−10p<10^\{\-10\}and would survive any reasonable correction\. #### Sybil resistance is assumed, not demonstrated\. Under a broken census every result in Section[9](https://arxiv.org/html/2608.23979#S9)fails, since a coalition that mints identities mints endorsements\.DDP2P’s witnessed\-census line[Qin et al\., 2013a](https://arxiv.org/html/2608.23979#bib.bibx78);[Qin et al\., 2014](https://arxiv.org/html/2608.23979#bib.bibx76);[Silaghi et al\., 2016](https://arxiv.org/html/2608.23979#bib.bibx91)is the intended answer and we have not evaluated it here\. Section[10](https://arxiv.org/html/2608.23979#S10.SS0.SSS0.Px3)states the dependency; this is the largest gap between the manuscript and a deployment\. #### Partial replicas are analysed, not measured\. Proposition[10\.1](https://arxiv.org/html/2608.23979#S10.Thmtheorem1)bounds the degradation and Algorithm[4](https://arxiv.org/html/2608.23979#algorithm4)declares the evidence, but we ran no experiment with peers holding genuinely divergent replicas\. The prediction of Section[10](https://arxiv.org/html/2608.23979#S10.SS0.SSS0.Px5)— that ordering matters more under partial replication — is untested\. #### Fairness across minority positions is unexamined\. Endorsement mass rewards what constituents took up\. Whether \([8](https://arxiv.org/html/2608.23979#S4.E8)\) systematically disadvantages minority positions, whose reasons appear in fewer items and therefore accumulate less endorsement, is an open and important question that the weighted variant of Section[3\.4](https://arxiv.org/html/2608.23979#S3.SS4)anticipates syntactically without answering\. ## 13\.Work, Meaning, and the E\-Citizen A manuscript about the mechanics of argument selection owes its readers an account of why the mechanics matter, and the answer is not confined to the integrity of any particular poll\. The argument has four steps: procedure is constitutive of collective agency rather than decorative; the historical obstacle to genuine self\-government has been the time it consumes; artificial intelligence, by absorbing productive labour, removes that obstacle in a way no previous technology has; and the role of citizen is therefore available as a destination for human effort in a way it has not been for two and a half millennia — provided the instruments of that role remain legible to the people exercising it\. The final clause is where this section rejoins the rest of the manuscript\. That Robert’s rules of order were the salt which turned a mob into a society[Silaghi, 2025](https://arxiv.org/html/2608.23979#bib.bibx88);[Robert, 1915](https://arxiv.org/html/2608.23979#bib.bibx80)is a claim about what makes collective reasoning possible at all\. A crowd has volume; an assembly has a procedure for converting volume into a decision, and the procedure is what everyone can agree to precisely because it constrains form rather than content\. One can accept a rule about who speaks next without accepting anything about what they will say — which is why procedural agreements survive substantive disagreements\. The charter of Section[4\.2](https://arxiv.org/html/2608.23979#S4.SS2)carries that idea into the selection step, the one place where digital deliberation has so far had no procedure whatsoever: we regulate speaking time in a parliament to the minute, and we let an unpublished model decide which of a hundred thousand submitted reasons a voter sees\. Semantic abstinence is the descendant of content\-indifference in the chair; configurability descends from the assembly’s authority over its own rules; contestability descends from the appeal from the chair\. The novelty is not the principle but that it must now be enforced in software, because that is where the procedure has migrated\. Athenian democracy worked, to the extent it did, because a body of citizens had time to do it\. Assembly attendance, jury service and rotation through office consume days, not minutes, and are impossible for people whose waking hours are claimed by subsistence\. Athens solved the time problem with slavery: the enfranchised were free to deliberate because the disenfranchised did the work[Narcisse, 2012](https://arxiv.org/html/2608.23979#bib.bibx68)\. Every subsequent expansion of the franchise inherited the structural problem without the solution\. Representative democracy is, read uncharitably, a device for economising on citizens’ time — elect somebody to be the citizen for you, on the grounds that you have a job — and it produces the characteristic modern experience of participation as a thin, performative gesture\. That thinness has been described as a kitsch of the political form[Silaghi, 2025](https://arxiv.org/html/2608.23979#bib.bibx88), borrowing a diagnosis developed for aesthetics[Calinescu, 1987](https://arxiv.org/html/2608.23979#bib.bibx21);[Lazare, 1999](https://arxiv.org/html/2608.23979#bib.bibx54): the surface features of the real thing, arranged for easy consumption, with the deliberation removed\. The literature on why participation platforms fail[Toots, 2019](https://arxiv.org/html/2608.23979#bib.bibx102);[Bright & Margetts, 2016](https://arxiv.org/html/2608.23979#bib.bibx16)is largely a catalogue of the same thinness, and the finding that direct\-democracy processes educate the citizens who use them[Smith & Tolbert, 2004](https://arxiv.org/html/2608.23979#bib.bibx96);[Tolbert et al\., 2009](https://arxiv.org/html/2608.23979#bib.bibx101)is the other side of the coin\. There is a direct line from that diagnosis to the exposure problem of Section[1\.1](https://arxiv.org/html/2608.23979#S1.SS1): a slate assembled by an unpublished model, shown to a voter who cannot recompute it, is the kitsch form of deliberative exposure — the appearance of having met the arguments, with the part that would make the meeting real removed\. The anxious question about artificial intelligence and work is whether it will take our jobs, and the productivity framing of the fourth industrial revolution[Schwab, 2017](https://arxiv.org/html/2608.23979#bib.bibx84)does not settle it\. But the anxiety contains an assumption worth naming: that the only worthwhile use of human time is producing goods and services\. Set that aside and the picture inverts\. Self\-government has always been constrained by a shortage of citizen\-hours, and a technology that discharges productive labour is by construction a technology that produces them\. What Athens obtained by enslaving people, an automated economy could obtain without enslaving anyone — and where the Athenian arrangement was a moral defect of that society, the same structural position occupied by machines is available to be read as a strength of ours[Silaghi, 2025](https://arxiv.org/html/2608.23979#bib.bibx88)\. This is not a prediction: time released from labour goes wherever the surrounding institutions send it\. It is a claim about what becomes*possible*— that for the first time since a slave economy made it possible for a few, citizenship as a substantial, time\-consuming, skilled activity becomes available to many\. An epistemic argument runs alongside the ethical one\. The case for inclusive deliberation over rule by the competent is that cognitive diversity does work no amount of individual expertise substitutes for[Landemore, 2012](https://arxiv.org/html/2608.23979#bib.bibx53);[Landemore, 2013](https://arxiv.org/html/2608.23979#bib.bibx52); that argument is only cashable if the varied body is actually*reasoning*, which costs time, so the epistemic case for inclusion and the material case for citizen\-hours are the same case seen from two sides\. It also explains why the quantity measured here is coverage of the reason vocabulary rather than agreement: the value of a large deliberating public lies in the reasons it collectively holds, and a selection step that loses them destroys precisely what made inclusion worth having\. Our own measurements make the argument in miniature: Section[7\.2](https://arxiv.org/html/2608.23979#S7.SS2)found that persuading one constituent in ten to write a reason instead of one in fifty is worth as much completeness as multiplying the electorate fivefold\. The binding constraint is not how many people vote but how many*think in public*, and that is a quantity measured in hours\. The argument has an obvious failure mode, and it is the one this manuscript is built to forestall\. If the same technology that releases the time also assembles the arguments, filters the objections and decides which considerations a citizen encounters, then the citizen\-hours have been created and simultaneously hollowed out: one would have the leisure of the Athenian and the informational position of a spectator, and the role would be available and not worth occupying\. This is why C[4](https://arxiv.org/html/2608.23979#Thmcriterion4)and C[7](https://arxiv.org/html/2608.23979#Thmcriterion7)are the two criteria that matter most, and why Section[4\.3](https://arxiv.org/html/2608.23979#S4.SS3)declines to trade them for coverage\. A citizen who can recompute why they were shown what they were shown is exercising judgement; one who cannot is receiving a service\. The difference does not show up in any completeness measure — Section[7\.3](https://arxiv.org/html/2608.23979#S7.SS3)put its entire measurable cost at0\.0310\.031— and it is the whole difference between the two futures\. It also sets the correct place for a language model in a civic system, which is not nowhere: Section[2](https://arxiv.org/html/2608.23979#S2.SS0.SSS0.Px4)places extraction at authoring time, visible to the author and contestable before serving, so a model may help a person say what they mean\. What it must not do is decide, at serving time and unaccountably, which of those meanings anyone meets\. The line is exactly the one between assisting a citizen and replacing one\. ## 14\.Conclusions We set out to show that the selection step in a deliberative poll can be democratic procedure rather than infrastructure: a published rule over public evidence, with parameters held by the people it affects\. The construction is an alternative\-based poll over bipolar justification sets, judged by three instruments — coverage of the live reason vocabulary, the order in which that coverage arrives, and the endorsement mass captured — and served by a one\-hop reversed endorsement flow whose only policy lever is a relation\-weight function\. Seven criteria state what makes a mechanism admissible at all, and the rule satisfies all seven\. This section states what was established, what was not, and what comes next\. What the measurements established, across roughly17,00017\{,\}000seeded runs: the levers that govern coverage are the ones that mature the corpus, not the ones that select from it; the price of semantic abstinence is0\.031±0\.0140\.031\\pm 0\.014against a ceiling that bounds every mechanism including inadmissible ones, with four fifths of the residual shortfall temporal rather than algorithmic; set coverage on non\-degenerate authoring alone cannot distinguish the rule from a random draw, and the reasons are properties of the instrument that we state as Remarks[1](https://arxiv.org/html/2608.23979#Thmremark1)–[2](https://arxiv.org/html/2608.23979#Thmremark2); on an order\-sensitive reading the rule leads at every prefix short of the full slate, by a margin that widens under attack and reaches−8\.3\-8\.3positions ofe90e\_\{90\}at a quarter\-electorate coalition; once a realistic fraction of submissions fails to justify, the coverage margin returns and grows monotonically, with the link summands supplying93%93\\%of it atG=0\.7G=0\.7by squaring the electorate’s own discrimination; on endorsement mass the random baseline loses by a factor of3\.33\.3and the greedy ceiling stops dominating under attack; hub\-riding is inert; label flooding is severe and the weight policy is worth0\.1510\.151–0\.1810\.181against it; four fifths of that damage is homogeneity rather than volume; and a co\-signing coalition makes itself monotonically weaker\. What was not established is listed in Section[12](https://arxiv.org/html/2608.23979#S12)and led by two items: that a human electorate discriminates against unjustified submissions at anything like the modelled rate, on which the mechanism result depends; and that census integrity holds, on which every adversarial result depends\. The claim we would defend most firmly is not that this rule ranks well\. It is that the question “why was I shown this?” must have an answer that is a table of numbers rather than a narrative, and that a system built to that constraint turns out to cost about three points of coverage, to be more robust than we expected, and to be far easier to understand when it is wrong\. ## A note on scope and provenance This manuscript is an independently written, extended treatment of a line of work by the same labs\. It is not the camera\-ready version of any conference paper and it reproduces no text, figure, table, algorithm or example from one\. Every definition, proposition, algorithm, worked example, figure and table here was composed for this document; the notation, the three\-instrument framing, the seven criteria and their tests, the worked example of Section[3\.7](https://arxiv.org/html/2608.23979#S3.SS7), and all diagrams are original to it\. Where the underlying research programme has been reported elsewhere, the overlap is one of subject matter and of numerical results computed from the same experimental runs, not of expression\. Results attributed to prior work are cited as such\. The extensions developed here include the ordering and endorsement\-mass instruments, the degenerate\-authoring model and its mechanism analysis, the coverage\-versus\-mass frontier, the elaborated criteria and their audit tests, and the side balance evaluation\. ## Tools, data and reproducibility All simulations were run with a seeded pseudorandom generator; every run records its seed, its full parameter set, and every served slate in served order together with the policy vector in force \(Section[5\.5](https://arxiv.org/html/2608.23979#S5.SS5)\)\. The run databases and the analysis scripts that produce every table and figure are made available at[https://github\.com/devfitcs/ABAS](https://github.com/devfitcs/ABAS)\. Language\-model assistance was used in drafting and editing prose; all technical content, experimental design, analysis and conclusions are the author’s\. ## References - Adomavicius & Kwon \(2012\)Gediminas Adomavicius and YoungOk Kwon“Improving Aggregate Recommendation Diversity Using Ranking\-Based Techniques”In*IEEE Transactions on Knowledge and Data Engineering*24\.5IEEE, 2012, pp\. 896–911 - Alcântara & Cordeiro \(2025\)João Alcântara and Renan Cordeiro“On the Equivalence between Logic Programs and Bipolar Argumentation Frameworks”In*Journal of Artificial Intelligence Research*84, 2025DOI:[10\.1613/jair\.1\.18086](https://dx.doi.org/10.1613/jair.1.18086) - Alhamed & Silaghi \(2014\)Khalid Alhamed and Marius\. Silaghi“User Freedom: To Be or Not to Be a ‘Supernode”’In*Proceedings of the 14th IEEE International Conference on Peer\-to\-Peer Computing \(P2P 2014\)*London, UK: IEEE, 2014, pp\. 1–5 - Alhamed et al\. \(2013\)Khalid Alhamed et al\.“Stacking the Deck Attack on Software Updates: Solution by Distributed Recommendation of Testers”In*Proceedings of the IEEE/WIC/ACM International Conference on Intelligent Agent Technology \(IAT 2013\)*Atlanta, GA: IEEE, 2013, pp\. 293–300 - Alhamed et al\. \(2013a\)Khalid Alhamed, Marius\. Silaghi, Ihsan Hussien and Yi Yang“Security by Decentralized Certification of Automatic Updates for Open Source Software Controlled by Volunteers”In*Proceedings of the International Workshop on Decentralized Coordination \(DC 2013\)*, 2013 - Alhamed et al\. \(2016\)Khalid Alhamed, Markus Zanker, Shakre Elmane and Marius\. Silaghi“P2P Meta\-Recommenders: Aggregated Diversity Maximization as a Bulwark against Attacks on Reviewers”In*Proceedings of the IEEE/WIC/ACM International Conference on Web Intelligence \(WI 2016\)*Omaha, NE: IEEE, 2016, pp\. 208–215 - Alqahtani & Silaghi \(2016\)Abdulrahman Alqahtani and Marius\. Silaghi“Evaluation Technique for Argumentation Architectures from the Perspective of Human Cognition”In*Proceedings of the Twenty\-Ninth International Florida Artificial Intelligence Research Society Conference \(FLAIRS\-29\), Poster Abstracts*AAAI Press, 2016 - Alqahtani & Silaghi \(2017\)Abdulrahman Alqahtani and Marius\. Silaghi“Human\-Computer Interaction in a Debate Decision Support System”In*Proceedings of the Thirtieth International Florida Artificial Intelligence Research Society Conference \(FLAIRS\-30\)*AAAI Press, 2017, pp\. 773 - Amgoud et al\. \(2008\)Leila Amgoud, Claudette Cayrol, Marie\-Christine Lagasquie\-Schiex and Pierre Livet“On Bipolarity in Argumentation Frameworks”In*International Journal of Intelligent Systems*23\.10Wiley, 2008, pp\. 1062–1093 - Argyle et al\. \(2023\)Lisa\. Argyle et al\.“Out of One, Many: Using Language Models to Simulate Human Samples”In*Political Analysis*31\.3Cambridge University Press, 2023, pp\. 337–351 - Bail \(2024\)Christopher\. Bail“Can Generative AI Improve Social Science?”In*Proceedings of the National Academy of Sciences*121\.21, 2024, pp\. e2314021121 - \(1\)“Handbook of Formal Argumentation, Volume 1”London: College Publications, 2018 - Behrendt et al\. \(2024\)Maike Behrendt et al\.“AQuA — Combining Experts’ and Non\-Experts’ Views to Assess Deliberation Quality in Online Discussions Using LLMs”In*Proceedings of the First Workshop on Language\-Driven Deliberation Technology \(DELITE\)*ELRAICCL, 2024, pp\. 1–12 - Bench\-Capon & Dunne \(2007\)Trevor\.\. Bench\-Capon and Paul\. Dunne“Argumentation in Artificial Intelligence”In*Artificial Intelligence*171\.10–15Elsevier, 2007, pp\. 619–641 - Boutet et al\. \(2013\)Antoine Boutet et al\.“WhatsUp: A Decentralized Instant News Recommender”In*Proceedings of the 27th IEEE International Symposium on Parallel and Distributed Processing \(IPDPS 2013\)*IEEE, 2013, pp\. 741–752 - Brenneis et al\. \(2021\)Markus Brenneis, Maike Behrendt and Stefan Harmeling“How Will I Argue? A Dataset for Evaluating Recommender Systems for Argumentations”In*Proceedings of the 22nd Annual Meeting of the Special Interest Group on Discourse and Dialogue \(SIGDIAL 2021\)*Association for Computational Linguistics, 2021, pp\. 360–367 - Bright & Margetts \(2016\)Jonathan Bright and Helen Margetts“Big Data and Public Policy: Can It Succeed Where E\-Participation Has Failed?”In*Policy & Internet*8\.3Wiley, 2016, pp\. 218–224 - Bulteau \(2021\)Laurent Bulteau“Aggregation over Metric Spaces: Proposing and Voting in Elections, Budgeting, and Legislation”In*Journal of Artificial Intelligence Research*70, 2021, pp\. 1413–1439DOI:[10\.1613/jair\.1\.12388](https://dx.doi.org/10.1613/jair.1.12388) - Burkart & Huber \(2021\)Nadia Burkart and Marco\. Huber“A Survey on the Explainability of Supervised Machine Learning”In*Journal of Artificial Intelligence Research*70, 2021, pp\. 245–317DOI:[10\.1613/jair\.1\.12228](https://dx.doi.org/10.1613/jair.1.12228) - Burke \(2017\)Robin Burke“Multisided Fairness for Recommendation” Presented at the Workshop on Fairness, Accountability and Transparency in Machine Learning \(FAT/ML\)In*arXiv preprint arXiv:1707\.00093*, 2017 - Burrell \(2016\)Jenna Burrell“How the Machine ‘Thinks’: Understanding Opacity in Machine Learning Algorithms”In*Big Data & Society*3\.1SAGE Publications, 2016, pp\. 1–12 - Calinescu \(1987\)Matei Calinescu“Five Faces of Modernity: Modernism, Avant\-Garde, Decadence, Kitsch, Postmodernism”Durham, NC: Duke University Press, 1987 - Carbonell & Goldstein \(1998\)Jaime Carbonell and Jade Goldstein“The Use of MMR, Diversity\-Based Reranking for Reordering Documents and Producing Summaries”In*Proceedings of the 21st Annual International ACM SIGIR Conference on Research and Development in Information Retrieval*ACM, 1998, pp\. 335–336 - Carenini & Moore \(2006\)Giuseppe Carenini and Johanna\. Moore“Generating and Evaluating Evaluative Arguments”In*Artificial Intelligence*170\.11Elsevier, 2006, pp\. 925–952 - Caro\-Martínez et al\. \(2021\)Marta Caro\-Martínez, Guillermo Jiménez\-Díaz and Juan\. Recio\-García“Conceptual Modeling of Explainable Recommender Systems: An Ontological Formalization to Guide Their Design and Development”In*Journal of Artificial Intelligence Research*71, 2021, pp\. 557–589DOI:[10\.1613/jair\.1\.12789](https://dx.doi.org/10.1613/jair.1.12789) - Castiglioni \(2021\)Matteo Castiglioni“Election Manipulation on Social Networks: Seeding, Edge Removal, Edge Addition”In*Journal of Artificial Intelligence Research*71, 2021, pp\. 1049–1090DOI:[10\.1613/jair\.1\.12826](https://dx.doi.org/10.1613/jair.1.12826) - Cayrol & Lagasquie\-Schiex \(2013\)Claudette Cayrol and Marie\-Christine Lagasquie\-Schiex“Bipolarity in Argumentation Graphs: Towards a Better Understanding”In*International Journal of Approximate Reasoning*54\.7Elsevier, 2013, pp\. 876–899 - Cayrol & Lagasquie\-Schiex \(2005\)Claudette Cayrol and Marie\-Christine Lagasquie\-Schiex“On the Acceptability of Arguments in Bipolar Argumentation Frameworks”In*Symbolic and Quantitative Approaches to Reasoning with Uncertainty \(ECSQARU 2005\)*3571, Lecture Notes in Computer ScienceBerlin, Heidelberg: Springer, 2005, pp\. 378–389 - Chakraborty et al\. \(2019\)Abhijnan Chakraborty, Saptarshi Ghosh, Niloy Ganguly and Krishna\. Gummadi“Optimizing the Recency\-Relevance\-Diversity Trade\-Offs in Non\-Personalized News Recommendations”In*Information Retrieval Journal*22\.5Springer, 2019, pp\. 447–475 - Chalaguine & Hunter \(2020\)Lisa\. Chalaguine and Anthony Hunter“A Persuasive Chatbot Using a Crowd\-Sourced Argument Graph and Concerns”In*Computational Models of Argument \(COMMA 2020\)*326, Frontiers in Artificial Intelligence and ApplicationsIOS Press, 2020, pp\. 9–20 - Chandak et al\. \(2026\)Nikhil Chandak, Shashwat Goel and Dominik Peters“Proportional Aggregation of Preferences for Sequential Decision Making”In*Journal of Artificial Intelligence Research*85, 2026DOI:[10\.1613/jair\.1\.18660](https://dx.doi.org/10.1613/jair.1.18660) - Cheng et al\. \(2021\)Lu Cheng, Kush\. Varshney and Huan Liu“Socially Responsible AI Algorithms: Issues, Purposes, and Challenges”In*Journal of Artificial Intelligence Research*71, 2021, pp\. 1137–1181DOI:[10\.1613/jair\.1\.12814](https://dx.doi.org/10.1613/jair.1.12814) - Demers et al\. \(1988\)Alan Demers et al\.“Epidemic Algorithms for Replicated Database Maintenance”In*ACM SIGOPS Operating Systems Review*22\.1ACM, 1988, pp\. 8–32 - Dhannoon et al\. \(2013\)Osamah Dhannoon, Rahul Vishen and Marius\. Silaghi“Content Dissemination over VANET: Boosting Utility\-Based Heuristics Using Interests”In*Proceedings of the International Conference on Connected Vehicles and Expo \(ICCVE 2013\)*IEEE, 2013, pp\. 106–113 - Dhannoon \(2013\)Osamah Dhannoon“Multiplexing Content Exchange for Petition Drives in VANETs: Receiver Interest and Sender Utility”, 2013 - Douceur \(2002\)John\. Douceur“The Sybil Attack”In*Peer\-to\-Peer Systems \(IPTPS 2002\)*2429, Lecture Notes in Computer ScienceSpringer, 2002, pp\. 251–260 - Dung \(1995\)Phan Dung“On the Acceptability of Arguments and Its Fundamental Role in Nonmonotonic Reasoning, Logic Programming andnn\-Person Games”In*Artificial Intelligence*77\.2Elsevier, 1995, pp\. 321–357 - Endriss \(2020\)Ulle Endriss“The Complexity Landscape of Outcome Determination in Judgment Aggregation”In*Journal of Artificial Intelligence Research*69, 2020, pp\. 687–731DOI:[10\.1613/jair\.1\.11970](https://dx.doi.org/10.1613/jair.1.11970) - European Parliament and Council \(2022\)European Parliament and Council“Regulation \(EU\) 2022/2065 on a Single Market for Digital Services \(Digital Services Act\)”, Official Journal of the European Union, L 277, 27 October 2022, 2022 - European Parliament and Council \(2024\)European Parliament and Council“Regulation \(EU\) 2024/1689 Laying Down Harmonised Rules on Artificial Intelligence \(Artificial Intelligence Act\)”, Official Journal of the European Union, L series, 12 July 2024, 2024 - Feige \(1998\)Uriel Feige“A Threshold oflnn\\ln nfor Approximating Set Cover”In*Journal of the ACM*45\.4ACM, 1998, pp\. 634–652 - Feng et al\. \(2023\)Shangbin Feng, Chan Park, Yuhan Liu and Yulia Tsvetkov“From Pretraining Data to Language Models to Downstream Tasks: Tracking the Trails of Political Biases Leading to Unfair NLP Models”In*Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics \(ACL 2023\)*Association for Computational Linguistics, 2023, pp\. 11737–11762 - Fishkin \(1991\)James\. Fishkin“Democracy and Deliberation: New Directions for Democratic Reform”New Haven, CT: Yale University Press, 1991 - Fishkin \(2009\)James\. Fishkin“When the People Speak: Deliberative Democracy and Public Consultation”Oxford, UK: Oxford University Press, 2009 - Fishkin et al\. \(2000\)James\. Fishkin, Robert\. Luskin and Roger Jowell“Deliberative Polling and Public Consultation”In*Parliamentary Affairs*53\.4Oxford University Press, 2000, pp\. 657–666 - Gonzalez \(2021\)Melisa\.ñuela Gonzalez“Labeled Bipolar Argumentation Frameworks”In*Journal of Artificial Intelligence Research*70, 2021, pp\. 1557–1636DOI:[10\.1613/jair\.1\.12394](https://dx.doi.org/10.1613/jair.1.12394) - Habermas \(1984\)Jürgen Habermas“The Theory of Communicative Action, Volume 1: Reason and the Rationalization of Society” Translated by Thomas McCarthyBoston, MA: Beacon Press, 1984 - Hochbaum \(1997\)Dorit\. Hochbaum“Approximating Covering and Packing Problems: Set Cover, Vertex Cover, Independent Set, and Related Problems”In*Approximation Algorithms for NP\-Hard Problems*Boston, MA: PWS Publishing, 1997, pp\. 94–143 - Kahng et al\. \(2021\)Anson Kahng, Simon Mackenzie and Ariel Procaccia“Liquid Democracy: An Algorithmic Perspective”In*Journal of Artificial Intelligence Research*70, 2021, pp\. 1223–1252DOI:[10\.1613/jair\.1\.12261](https://dx.doi.org/10.1613/jair.1.12261) - Karp \(1972\)Richard\. Karp“Reducibility among Combinatorial Problems”In*Complexity of Computer Computations*New York, NY: Plenum Press, 1972, pp\. 85–103 - Kattamuri et al\. \(2005\)Kiran Kattamuri et al\.“Supporting Debates over Citizen Initiatives”In*Proceedings of the 2005 National Conference on Digital Government Research \(dg\.o 2005\)*Digital Government Society of North America, 2005, pp\. 279–280 - Lam & Riedl \(2004\)Shyong\. Lam and John Riedl“Shilling Recommender Systems for Fun and Profit”In*Proceedings of the 13th International Conference on World Wide Web \(WWW 2004\)*ACM, 2004, pp\. 393–402 - Landemore \(2013\)Hélène Landemore“Deliberation, Cognitive Diversity, and Democratic Inclusiveness: An Epistemic Argument for the Random Selection of Representatives”In*Synthese*190\.7Springer, 2013, pp\. 1209–1231 - Landemore \(2012\)Hélène Landemore“Democratic Reason: Politics, Collective Intelligence, and the Rule of the Many”Princeton, NJ: Princeton University Press, 2012 - Lazare \(1999\)Daniel Lazare“Modernism as Kitsch: Hilton Kramer’s Thirty\-Year Culture War”In*The Baffler*13MIT Press, 1999, pp\. 27–33 - Lippi & Torroni \(2016\)Marco Lippi and Paolo Torroni“Argumentation Mining: State of the Art and Emerging Trends”In*ACM Transactions on Internet Technology*16\.2ACM, 2016, pp\. 1–25 - Lipton \(2018\)Zachary\. Lipton“The Mythos of Model Interpretability”In*Communications of the ACM*61\.10ACM, 2018, pp\. 36–43 - Liscio \(2025\)Enrico Liscio“Value Preferences Estimation and Disambiguation in Hybrid Participatory Systems”In*Journal of Artificial Intelligence Research*82, 2025, pp\. 819–850DOI:[10\.1613/jair\.1\.14958](https://dx.doi.org/10.1613/jair.1.14958) - Lukensmeyer & Brigham \(2005\)Carolyn\. Lukensmeyer and Steve Brigham“Taking Democracy to Scale: Large Scale Interventions—For Citizens”In*The Journal of Applied Behavioral Science*41\.1SAGE Publications, 2005, pp\. 47–60 - Luskin et al\. \(2002\)Robert\. Luskin, James\. Fishkin and Roger Jowell“Considered Opinions: Deliberative Polling in Britain”In*British Journal of Political Science*32\.3Cambridge University Press, 2002, pp\. 455–487 - Mancini \(2015\)Pia Mancini“Why It Is Time to Redesign Our Political System”In*European View*14\.1SAGE Publications, 2015, pp\. 69–75 - Manning et al\. \(2008\)Christopher\. Manning, Prabhakar Raghavan and Hinrich Schütze“Introduction to Information Retrieval”Cambridge, UK: Cambridge University Press, 2008 - Maymounkov & Mazières \(2002\)Petar Maymounkov and David Mazières“Kademlia: A Peer\-to\-Peer Information System Based on the XOR Metric”In*Peer\-to\-Peer Systems \(IPTPS 2002\)*2429, Lecture Notes in Computer ScienceSpringer, 2002, pp\. 53–65 - Meir et al\. \(2021\)Reshef Meir, Fedor Sandomirskiy and Moshe Tennenholtz“Representative Committees of Peers”In*Journal of Artificial Intelligence Research*71, 2021, pp\. 401–429DOI:[10\.1613/jair\.1\.12521](https://dx.doi.org/10.1613/jair.1.12521) - Merkle \(1988\)Ralph\. Merkle“A Digital Signature Based on a Conventional Encryption Function”In*Advances in Cryptology — CRYPTO ’87*293, Lecture Notes in Computer ScienceSpringer, 1988, pp\. 369–378 - Mill \(1859\)John Mill“On Liberty” Project Gutenberg eBook no\. 34901, released January 10, 2011LondonFelling\-on\-Tyne; New YorkMelbourne: Walter Scott Publishing Co\., Ltd\., 1859URL:[https://www\.gutenberg\.org/files/34901/34901\-h/34901\-h\.htm](https://www.gutenberg.org/files/34901/34901-h/34901-h.htm) - Miller \(2020\)Greg Miller“The Intelligence Coup of the Century”,*The Washington Post*, 11 February 2020\.[https://www\.washingtonpost\.com/graphics/2020/world/national\-security/cia\-crypto\-encryption\-machines\-espionage/](https://www.washingtonpost.com/graphics/2020/world/national-security/cia-crypto-encryption-machines-espionage/), 2020 - Nakamoto \(2008\)Satoshi Nakamoto“Bitcoin: A Peer\-to\-Peer Electronic Cash System” White paper,[https://bitcoin\.org/bitcoin\.pdf](https://bitcoin.org/bitcoin.pdf), 2008 - Narcisse \(2012\)Tiky Narcisse“The African Origins of the Athenian Democracy”In*Proceedings of the 43rd National Conference of Black Political Scientists \(NCOBPS\)*, 2012 - Nemhauser et al\. \(1978\)George\. Nemhauser, Laurence\. Wolsey and Marshall\. Fisher“An Analysis of Approximations for Maximizing Submodular Set Functions—I”In*Mathematical Programming*14\.1Springer, 1978, pp\. 265–294 - Nikitin et al\. \(2017\)Kirill Nikitin et al\.“CHAINIAC: Proactive Software\-Update Transparency via Collectively Signed Skipchains and Verified Builds”In*Proceedings of the 26th USENIX Security Symposium*USENIX Association, 2017, pp\. 1271–1287 - Page et al\. \(1999\)Lawrence Page, Sergey Brin, Rajeev Motwani and Terry Winograd“The PageRank Citation Ranking: Bringing Order to the Web”In*Stanford InfoLab Technical Report 1999\-66*, 1999 - Pariser \(2011\)Eli Pariser“The Filter Bubble: What the Internet Is Hiding from You”New York, NY: Penguin Press, 2011 - Park et al\. \(2023\)Joon Park et al\.“Generative Agents: Interactive Simulacra of Human Behavior”In*Proceedings of the 36th Annual ACM Symposium on User Interface Software and Technology \(UIST 2023\)*ACM, 2023, pp\. 1–22 - Prakken \(2001\)Henry Prakken“Formalizing Robert’s Rules of Order: An Experiment in Automating Mediation of Group Decision Making”, 2001 - Price et al\. \(2002\)Vincent Price, Joseph\. Cappella and Lilach Nir“Does Disagreement Contribute to More Deliberative Opinion?”In*Political Communication*19\.1Taylor & Francis, 2002, pp\. 95–112 - Qin et al\. \(2014\)Song Qin et al\.“Open Census for Addressing False Identity Attacks in Agent\-Based Decentralized Social Networks”In*Proceedings of the 13th International Conference on Autonomous Agents and Multiagent Systems \(AAMAS 2014\)*Paris, France: IFAAMAS, 2014, pp\. 1591–1592 - Qin et al\. \(2013\)Song Qin et al\.“Addressing False Identity Attacks in Action\-Based P2P Social Networks with an Open Census”In*Proceedings of the IEEE/WIC/ACM International Conference on Web Intelligence \(WI 2013\)*Atlanta, GA: IEEE, 2013, pp\. 50–57 - Qin et al\. \(2013a\)Song Qin et al\.“P2P Decentralized Population Census”In*Proceedings of the International Workshop on Decentralized Coordination \(DC 2013\)*, 2013 - Qin et al\. \(2013b\)Song Qin et al\.“Reputation System for Decentralized Population Census”In*Proceedings of the IJCAI Workshop on Incentives and Trust in E\-Commerce \(WIT\-EC 2013\)*, 2013, pp\. 37–48 - Robert \(1915\)Henry\. Robert“Robert’s Rules of Order Revised for Deliberative Assemblies”Chicago, IL: Scott, ForesmanCompany, 1915 - Rocha et al\. \(2026\)Victor Rocha, Fabio Cozman and Serena Villata“Assessing the Minimal Dialectical Quality in Argumentation: A Neuro\-Symbolic Approach Integrating Argument Mining, Quality Assessment, and Probabilistic Reasoning”In*Journal of Artificial Intelligence Research*86, 2026DOI:[10\.1613/jair\.1\.21868](https://dx.doi.org/10.1613/jair.1.21868) - Roussev & Silaghi \(2017\)Roussi Roussev and Marius\. Silaghi“A Logic for Making Hard Decisions”In*Proceedings of the Thirtieth International Florida Artificial Intelligence Research Society Conference \(FLAIRS\-30\)*AAAI Press, 2017, pp\. 712–716 - Rudin \(2019\)Cynthia Rudin“Stop Explaining Black Box Machine Learning Models for High Stakes Decisions and Use Interpretable Models Instead”In*Nature Machine Intelligence*1\.5Nature Publishing Group, 2019, pp\. 206–215 - Schwab \(2017\)Klaus Schwab“The Fourth Industrial Revolution”New York, NY: Currency, 2017 - Shapiro et al\. \(2011\)Marc Shapiro, Nuno Preguiça, Carlos Baquero and Marek Zawirski“Conflict\-Free Replicated Data Types”In*Stabilization, Safety, and Security of Distributed Systems \(SSS 2011\)*6976, Lecture Notes in Computer ScienceSpringer, 2011, pp\. 386–400 - Shardanand & Maes \(1995\)Upendra Shardanand and Pattie Maes“Social Information Filtering: Algorithms for Automating ‘Word of Mouth”’In*Proceedings of the SIGCHI Conference on Human Factors in Computing Systems \(CHI ’95\)*ACM, 1995, pp\. 210–217 - Sharma et al\. \(2023\)Mrinank Sharma et al\.“Towards Understanding Sycophancy in Language Models”In*arXiv preprint arXiv:2310\.13548*, 2023 - Silaghi \(2025\)Marius\. Silaghi“Representative Democracy as Kitsch, and Artificial Intelligence’s Promise of Emancipation”In*Global Modernity from Coloniality to Pandemic: A Cross\-Disciplinary Perspective*London: Routledge, 2025, pp\. 349–370 - Silaghi et al\. \(2013\)Marius\. Silaghi et al\.“DirectDemocracyP2P—Decentralized Deliberative Petition Drives”In*Proceedings of the 13th IEEE International Conference on Peer\-to\-Peer Computing \(P2P 2013\)*Trento, Italy: IEEE, 2013, pp\. 1–2 - Silaghi et al\. \(2013a\)Marius\. Silaghi et al\.“P2P Petition Drives and Deliberation of Shareholders”In*Proceedings of the International Workshop on Decentralized Coordination \(DC 2013\)*, 2013 - Silaghi et al\. \(2016\)Marius\. Silaghi et al\.“Bayesian Network\-Based Extension for PGP—Estimating Petition Support”In*Proceedings of the Twenty\-Ninth International Florida Artificial Intelligence Research Society Conference \(FLAIRS\-29\)*AAAI Press, 2016 - Silaghi & Roussev \(2014\)Marius\. Silaghi and Roussi Roussev“Recommending the Most Encompassing Opposing and Endorsing Arguments in Debates”[https://arxiv\.org/abs/1411\.5416](https://arxiv.org/abs/1411.5416), 2014 - Silaghi et al\. \(2017\)Marius\-Calin Silaghi, Roussi Roussev and Badria Alfurhood“Why Do They Vote That?”In*Proceedings of the Thirtieth International Florida Artificial Intelligence Research Society Conference \(FLAIRS\-30\)*Marco Island, FL: AAAI Press, 2017, pp\. 128–133 - Singh et al\. \(2006\)Atul Singh, Tsuen\-Wan Ngan, Peter Druschel and Dan\. Wallach“Eclipse Attacks on Overlay Networks: Threats and Defenses”In*Proceedings of the 25th IEEE International Conference on Computer Communications \(INFOCOM 2006\)*IEEE, 2006, pp\. 1–12 - Small et al\. \(2021\)Christopher Small et al\.“Polis: Scaling Deliberation by Mapping High Dimensional Opinion Spaces”In*Proceedings of the AAAI Symposium on Computational Approaches to Online Collective Deliberation*AAAI Press, 2021 - Smith & Tolbert \(2004\)Daniel\. Smith and Caroline\. Tolbert“Educated by Initiative: The Effects of Direct Democracy on Citizens and Political Organizations in the American States”Ann Arbor, MI: University of Michigan Press, 2004 - Spärck \(1972\)Karen Spärck“A Statistical Interpretation of Term Specificity and Its Application in Retrieval”In*Journal of Documentation*28\.1Emerald, 1972, pp\. 11–21 - Stab & Gurevych \(2017\)Christian Stab and Iryna Gurevych“Parsing Argumentation Structures in Persuasive Essays”In*Computational Linguistics*43\.3MIT Press, 2017, pp\. 619–659 - Sunstein \(2007\)Cass\. Sunstein“Republic\.com 2\.0”Princeton, NJ: Princeton University Press, 2007 - Tessler et al\. \(2024\)Michael Tessler et al\.“AI Can Help Humans Find Common Ground in Democratic Deliberation”In*Science*386\.6719American Association for the Advancement of Science, 2024, pp\. eadq2852 - Tolbert et al\. \(2009\)Caroline\. Tolbert, Daniel\. Smith and John\. Green“Strategic Voting and Legislative Redistricting Reform: District and Statewide Representational Winners and Losers”In*Political Research Quarterly*62\.1SAGE Publications, 2009, pp\. 92–109 - Toots \(2019\)Maarja Toots“Why E\-Participation Systems Fail: The Case of Estonia’s Osale\.ee”In*Government Information Quarterly*36\.3Elsevier, 2019, pp\. 546–559 - Wachsmuth et al\. \(2018\)Henning Wachsmuth, Shahbaz Syed and Benno Stein“Retrieval of the Best Counterargument without Prior Topic Knowledge”In*Proceedings of the 56th Annual Meeting of the Association for Computational Linguistics \(ACL 2018\)*Association for Computational Linguistics, 2018, pp\. 241–251 - Weinberg \(2022\)Lindsay Weinberg“Rethinking Fairness: An Interdisciplinary Survey of Critiques of Hegemonic ML Fairness Approaches”In*Journal of Artificial Intelligence Research*74, 2022, pp\. 75–109DOI:[10\.1613/jair\.1\.13196](https://dx.doi.org/10.1613/jair.1.13196) - Willson \(2014\)Michele Willson“The Politics of Social Filtering”In*Convergence: The International Journal of Research into New Media Technologies*20\.2SAGE Publications, 2014, pp\. 218–232 - Wu et al\. \(2024\)Qingyun Wu et al\.“AutoGen: Enabling Next\-Gen LLM Applications via Multi\-Agent Conversation”In*Proceedings of the First Conference on Language Modeling \(COLM 2024\)*, 2024 ## Appendix AThe Comparison This Manuscript Declines to Run Section[4\.3](https://arxiv.org/html/2608.23979#S4.SS3)states in the body why no learned\-ranker baseline appears in this manuscript\. This appendix records what such an experiment would have to look like to be worth running\. The claim is normative and concerns admissibility, not performance\. It says that a mechanism which cannot be recomputed, attributed, contested or reconstructed is unsuitable for a binding civic process\. A comparison against a learned ranker would report a difference in coverage, in ordering, or in some downstream engagement statistic\. Whatever number emerged could not bear on the claim: a learned ranker covering*more*of the live vocabulary would still fail C[2](https://arxiv.org/html/2608.23979#Thmcriterion2), C[4](https://arxiv.org/html/2608.23979#Thmcriterion4), C[5](https://arxiv.org/html/2608.23979#Thmcriterion5)and C[6](https://arxiv.org/html/2608.23979#Thmcriterion6), and would still leave a disputing participant with no terminating move\. Running the comparison and declining to act on its result would be theatre; running it and acting on its result would concede that legibility is a quantity to be traded, which is the position this manuscript exists to reject\. Three supporting observations: *The comparison that does bear on a real question was run\.*Section[7\.3](https://arxiv.org/html/2608.23979#S7.SS3)measures the served slates against a label\-reading greedy cover which, by Proposition[3\.7](https://arxiv.org/html/2608.23979#S3.Thmtheorem7), upper\-bounds what*any*selection procedure could achieve on the same pool — a learned ranker included, and by a wide margin, since the ceiling saturates the live vocabulary in every seed\. The answer,0\.035±0\.0130\.035\\pm 0\.013, bounds the entire competitive advantage available to an unconstrained mechanism\. That is strictly more informative than beating one particular trained model, because it is a bound rather than a match result\. *The precedent structure is familiar\.*The secret ballot is not defended on the grounds that it measures preferences more accurately than open voting — it plainly measures some things less well, since it destroys the ability to audit an individual’s vote\. It is defended because a procedural property outranks measurement quality\. Double\-entry bookkeeping is not the most compact representation of a firm’s accounts\. Rules of order do not produce the fastest decisions\. In each case the procedural property is treated as prior, and efficiency questions are settled*within*the admissible class\. *A learned baseline would import the very opacity at issue\.*Its behaviour would depend on training data, objective, and the operating point chosen by whoever tuned it — all under our control as the authors, and none of it inspectable by a reader\. A result favouring our rule would be unconvincing for exactly that reason, and a result favouring the learned ranker would be equally unconvincing\. The experiment has no configuration in which its outcome is informative\. ### A\.1\.What would make such an experiment worth running A reader who rejects the admissibility framing is entitled to ask what evidence would move us, and there is a specific answer\. The interesting experiment is not*ranker versus rule on coverage*\. It is*participant behaviour under a disputed slate*: give two matched populations the same corpus and the same served items, differing only in whether the selection can be recomputed and decomposed, then measure whether participants contest slates, whether contests terminate, and whether reported trust in the outcome differs\. That experiment tests the actual claim — that legibility does procedural work — and its outcome could genuinely change our position or its strength, in either direction\. It requires human participants and is out of scope for a simulation study; we regard it as the most valuable experiment this line of work has not yet done, and it belongs on the roadmap of Section[14](https://arxiv.org/html/2608.23979#S14)alongside the field deployment\.
Similar Articles
Diverse Evidence, Better Forecasts: Multi-Agent Deliberation Under Information Asymmetry
This paper introduces InfoDelphi, a framework that uses information asymmetry (partitioning evidence into shared public and disjoint private subsets) to improve multi-agent LLM deliberation and forecasting. On the PolyGym benchmark, it outperforms single-agent and multi-agent baselines by 12-18% in Brier score and 4-8 percentage points in accuracy, demonstrating that diverse evidence is key to effective multi-agent reasoning.
Equitable System-Prompt Selection via Constrained Mixed-Strategy GroupDRO
This paper introduces a constrained mixed-strategy GroupDRO framework for equitable system-prompt selection, assigning weights to existing prompts to minimize worst-case information-quality loss across demographic groups and metrics. Experiments across five LLMs on bilingual medical and finance benchmarks show consistent reductions in worst-case quality drops while preserving average performance.
Deliberative Curation: A Protocol for Multi-Agent Knowledge Bases
This paper introduces a deliberative curation protocol for multi-agent knowledge bases, addressing governance gaps such as agent statelessness and sycophancy. It evaluates the protocol via simulation, showing improved resilience under adversarial conditions.
Active Learners as Efficient PRP Rerankers
This paper reframes pairwise ranking prompting as active learning from noisy comparisons, introducing a noise-robust framework with a randomized-direction oracle to improve ranking quality under call constraints and address position bias.
Mixture of Debaters: Learn to Debate at Architectural Level in Multi-Agent Reasoning
Proposes Mixture of Debaters (MoD), a framework using Mixture-of-Experts to enable dynamic self-debate within a single LLM, achieving superior accuracy with drastically lower latency and token consumption.