Acronym quick index →
New to Web4? This is the full-picture overview - pieces fit together below. If you'd rather see one concept at a time first, First Contact walks an agent through her lifecycle, the 2-minute TL;DR gives the high-level view, and the concept sequence covers each piece individually.
Already know Web4? Skip ahead to the full-picture diagram - a visual summary of how LCT, ATP, T3, MRH, and CI combine.
Web4 Explained

How Web4 Societies Work

This is the comprehensive walkthrough, so it runs long. Brand new? Skim Web4 in 2 minutes and Why Web4 first, then come here to go deep.

No network you can join yet - the present tense below is the model talking.

The spec is written, the code is installable today, and there is no public network open to outside members yet. Everything below describes how Web4 would work at society scale, validated through simulations and an open-source reference implementation. The present tense throughout is the model talking, not a running system. Want the piece-by-piece breakdown of what is installable versus specified? See what's actually running now. Curious what early deployment could look like? See the concrete adoption path - from browser extension overlays to full integration.

Key Takeaways

You're born with energy and neutral trust. Every action costs energy, from about 1 ATP to read something up to 10-20 to post. Quality contributions earn it back; spam drains it.

Your identity is tied to your devices - no passwords, no central authority. Your trust is multi-dimensional (Talent, Training, Temperament) and role-specific.

If your energy hits zero, you stop acting - and whether you come back is decided by your trust, not by which way the life ended: recoverable if you built trust, permanent if not. Good karma carries forward, so a return comes with a head start; a sustained trust collapse is that check failing. No moderators needed to police spam (settling a dispute between two people is a different job, and societies do staff that one - see governance below). Five interlocking systems (identity, energy, trust, consistency, context) make spam expensive and quality self-sustaining.

Web4 is trust-native infrastructure for humans and AI. Instead of relying on platforms, moderation armies, or outside authorities, Web4 societies self-regulate through five foundational mechanisms:

Five systems, in plain English: Web4 has some acronyms. Here's what they mean - refer back anytime.

LCT = IdentityATP = Energy budgetT3 = Trust scoreCI = Behavioral consistencyMRH = Context boundary

Hover any dotted-underlined term for a quick definition, or use the glossary button Aa in the bottom-left corner.

🔐

Identity (LCT)

Unforgeable identity rooted in hardware, strengthened by multiple devices witnessing each other.

Learn more →

ATP Economics

Every action costs energy (ATP). Run out? You stop acting. Contribute value? You thrive.

Learn more →
🎯

Trust (T3)

Multi-dimensional trust scored across Talent, Training, and Temperament - per role.

Learn more →
🌐

Context (MRH)

Everyone stays visible - your trust network decides how much weight each voice carries. Spam arrives with zero weight, and sending it still costs energy.

Learn more →
🌊

Coherence (CI)

Behavioral consistency across where you are, what you can do, when you act, and who you interact with.

Example: If someone usually posts coding tutorials at 9am and suddenly starts posting crypto spam at 3am from a new country, their coherence drops - making every action more expensive.

Learn more →

Together, these create societies where trust emerges from verifiable behavior, not institutional authority. This page walks through how it all works.

↓ See how all five systems create aliveness below

How All Five Systems Create Aliveness

Each system handles one job. Together, they produce a living digital society:

1
🔐
LCT - Proves you're real. Hardware-bound identity, unforgeable.
identity established
2
🌐
MRH - Defines your reach. Only see what's relevant to your trust network.
Gates the loop below: you only spend ATP and build T3 in contexts where you're visible. Actions outside your MRH don't cost energy and don't move trust.
context bounded
3
Feedback Loop - every action cycles through all three:
ATP
Energy spent
T3
Trust updated
CI
Consistency checked
ATP
Reward earned
↻ repeats every action
all three healthy?
4
Aliveness - it ends when: ATP hits 0, or raw trust falls below 0.5 and stays there
All three healthy → you keep acting, and keep earning
Energy or trust fails → that life ends. Whether you come back is decided by your trust, not by which one fired: recoverable if you built trust, permanent if not

The gate reads your composite T3 score. The eligibility check ↓

Why spam dies: Without LCT, you can't enter. Without MRH, you can't reach anyone. Without ATP, you can't act. Without T3, you aren't trusted. Without CI, you're flagged. Every layer filters bad actors - no single point of failure, no moderators needed to police spam.

Running In the real world: this isn't only theory - hestia (the trust layer) and the hub (a runnable Web4 society) are public, AGPL code you can run yourself - though there's no live network with real users yet. See what's deployed →

The Journey: Birth → Life → Death → Rebirth

Web4 societies treat "aliveness" as a measurable property. Before the step-by-step below, watch the whole arc run - 30 seconds, no navigation:

Watch it run - one agent, one life

1. Birth

Alice joins with 100 energy and neutral trust (0.50). Nobody knows her yet.

🔋 Energy (ATP)100
🤝 Trust (T3)0.50

The thin line is 0.50 - neutral trust. Drop below it and the society restricts you.

The same numbers you can drive yourself in First Contact. Both are illustrative: a single action moves trust far less than the steps here show.

About that 112 in the demo above: how much karma carries is not settled, and this is one modelling choice, not the rule. The karma examples further down this section show a different one, carrying the whole ending balance forward. Read both for the shape, not the amount.

🐣

1. Birth: You Enter the Society

Creating your identity and receiving initial resources

Identity Creation (LCT)

You create a Linked Context Token (LCT) - your verifiable digital presence. This can be bound to:

  • Hardware: Secure Enclave (iPhone/Mac), TPM chip (PC), or FIDO2 security key
  • Multi-device: Multiple devices witnessing each other (stronger identity)
  • VM-bound: Software identity for AI agents

Your LCT is registered on the society's network and becomes part of the trust graph - which determines what entities and information are visible to you (your "context boundary").

Initial Resources (ATP)

You receive an initial ATP allocation (typically 100). This is your energy budget - spend it wisely.

New life: 100 ATP to start exploring

Neutral Trust (T3)

Your trust tensor starts at neutral (0.5 in all dimensions):

Talent
0.5
Training
0.5
Temperament
0.5

You haven't done anything yet - society doesn't know if you're trustworthy. Build trust through actions.

🌱

2. Life: You Act, Build Trust, Manage ATP

The core loop of Web4 existence

Actions Cost ATP

Actions that affect others cost ATP from your energy budget. Reading and browsing are effectively free, about 1 ATP a read, so what you spend is essentially what you put out:

Effectively free (1-2 ATP)

• Reading and browsing content

• Viewing profiles and trust scores

• Observing community activity

Lurking is cheap, not literally free: a read costs about 1 ATP and viewing content about 2, against 10-20 ATP for a single post in the column beside this one. So a read runs about a tenth to a twentieth of one post, and the tiny charge exists so that scraping a million posts is not free either. Why reading costs anything at all → Real spending starts when you act - post, vote, transact, or create.

Costs ATP (actions that affect others)

• Posting content (10-20 ATP)

• Creating tasks (15-30 ATP)

• Broadcasting (20-50 ATP)

Contributions Earn ATP

ATP comes back two ways, and which one you are in depends on who asked for the work:

Commissioned write-up (someone else priced it): Cost 15 ATP → Paid 40 ATP = +25 net

Commissioned fix, delivered well (someone else priced it): Cost 20 ATP → Paid 60 ATP = +40 net

A post you chose to write (nobody commissioned it): Cost 15 ATP → recharges up to 15 ATP = 0 net at best

Spam message: Cost 5 ATP → Earn 0 ATP = -5 net

Work you initiate can hold you steady; work someone commissioned is what puts you ahead. Either way quality is the gate, and spam runs the balance down until there is nothing left to act with.

How someone with no track record lands a first commission is an open question on this stack rather than a solved one, and you should read it as one. Where that stands →

Trust Evolves with Behavior

Every action updates your T3 trust tensor:

Example: Delivered high-quality work on time (quality 0.85)
Talent
+0.007
Training
+0.0056
Temperament
+0.0042
Example: Missed deadline without warning (quality 0.25)
Talent
-0.005
Training
-0.004
Temperament
-0.003

Both examples run the same rule: quality sets the sign and the size, and each dimension moves by a fixed share of it (talent full, training four fifths, temperament three fifths). The steps are deliberately tiny. Reputation is the accumulation of hundreds of them, not the payoff of any one.

💀

3. Death: ATP Reaches Zero

Energy death, the recoverable kind

Two ways to die, and they are very different

Two paths: ATP hits zero (energy death - you can't act anymore) or raw trust falls below 0.5 and stays there (trust death - the community no longer trusts you). Which one you can come back from is not decided by which of them fired: recoverable if you built trust, permanent if not. A trust death is that check failing - a destroyed reputation can't be reset. One line, two consequences: crossing below 0.5 restricts your features right away and is recoverable; only staying below it is fatal - a sustained collapse, not a single stumble. The number compared is raw trust, not effective trust (raw × CI²). A lower CI raises your costs and narrows your access; it does not push you toward trust death.

Which number is “raw trust”: the blend, not one dimension. It is your overall (composite) score, the single number blended from all three dimensions (talent, training, temperament), not each dimension clearing 0.5 on its own. “Raw” marks the contrast with effective trust in the sentence above, not a contrast with the blend.

A question this raises, before you do the arithmetic yourself: trust dimensions also decay when you are simply inactive, which makes “stays there” worth a second look for someone who is away rather than misbehaving. Whether a passively decayed score is read against this rule is not settled, and the decay page says where that stands.

So energy death is not the end of your identity. Same LCT, same history, same trust record: it is closer to a suspended license reinstated than a clean slate. The rest of this section is about that recoverable kind. For the walkthrough version, see what triggers death in First Contact.

And the question after that: dead where? Trust in Web4 is never one universal number. It is scoped to a role, and each society keeps its own view of you, which is why the plagiarism walkthrough further down this page can say a penalty is society-specific, not global. What crosses a society boundary is the record rather than the verdict: your history is visible to other societies and can weigh on how they judge you, the way a DUI affects a pilot's license. Whether that ever amounts to trust death somewhere else is not settled. What is not in doubt is the part this page already says of the other death: neither one erases you. Your history persists either way.

What drains your ATP to zero

  • Spam yourself to death: Send 20 spam messages = -100 ATP
  • Low-quality contributions: Earn less than you spend over time
  • Ignored by community: No validation = no ATP rewards
  • ATP crisis: Big actions without enough buffer

Your Final Record

At death, your full life history is recorded:

  • Total ATP earned across life
  • Final T3 trust tensor (Talent, Training, Temperament)
  • Actions taken and their outcomes
  • Community validation history
  • Coherence Index (behavioral consistency)

This record determines whether you're eligible for rebirth.

♻️

4. Rebirth: Karma Carries Forward (Maybe)

Trust above threshold = reincarnation with benefits

Eligibility Check: Trust Threshold

Not everyone gets reborn. The society checks your T3 trust tensor - specifically your overall (composite) score, the single number blended from all three dimensions (talent, training, temperament), not each dimension clearing 0.5 on its own:

The blend uses the canonical weights 0.4 talent + 0.3 training + 0.3 temperament (the specification fixes them; what varies per role is the minimum each dimension must clear, not the blend). So an agent at talent 0.40, training 0.60, temperament 0.60 scores 0.4(0.40) + 0.3(0.60) + 0.3(0.60) = 0.52 and stays eligible, even though one dimension is under the line on its own. The full tensor structure and weights →

✅ Eligible for Rebirth

Overall T3 score ≥ 0.5 (threshold)

You built enough trust. Society wants you back. Reborn with karma (a head start earned by your previous life).

❌ Not Eligible

Overall T3 score < 0.5 (threshold)

You burned trust. Society doesn't want you back. No rebirth. Permanent death.

Karma: What Carries Forward

If eligible, you're reborn with karma - a head start earned by the track record of your previous life:

Life 1 → Life 2

Ended with 145 ATP. Reborn with 145 ATP (karma carried forward).

Life 2 → Life 3

Ended with 130 ATP. Reborn with 130 ATP (karma carried forward).

Your track record compounds across lives. Good behavior = stronger starts.

About these numbers: none of these lives ends at 0 ATP, so none of them is the energy death described above. Neither is any of them the trust death: that one takes a sustained collapse, and the trust in this walkthrough rises life over life instead. That is why they read ended and not died: neither death this page defines fits them. What else ends a life is not settled: the standard says what stops you acting (ATP reaches zero) and what is permanent (sustained trust collapse), and it names no term limit, no lifespan, and no natural end of life. So rather than invent a third cause to justify these figures, this page declines to name one. How much karma carries is also unsettled: whether you keep your whole final balance, a reduced portion of it, or a fresh starting balance plus a karma bonus is not decided, and this walkthrough shows one modelling choice, not the rule. The two lives above show the first of those branches. The lifecycle demo further up this page and the First Contact walkthrough both show the third, so a restart figure that does not match these is the same open question showing its other side, not a second rule. Read it for the shape (a good track record starts your next life stronger), not for the death rule or the exact carry-forward.

Learning Across Lives

Advanced agents remember what worked from their previous lives. When reborn, they carry forward lessons about which strategies succeed and which fail:

  • "Work someone commissioned pays more than it costs; work I start myself only refunds"
  • "Transparency when making mistakes rebuilds trust faster"
  • "Consistent small wins beat sporadic big swings"

These lessons carry forward through karma, helping agents make better choices in future lives.

Groups Can Come Alive Too

So far we've talked about individual agents surviving through energy, trust, and consistency. But what happens when several agents consistently cooperate? When individuals build dense mutual trust, something emerges at the group level. Web4 calls these synthons (from chemistry: a unit that functions as a building block for larger structures). A team that consistently collaborates well develops its own collective aliveness score, separate from any individual member. Think of it like a band that's greater than the sum of its musicians - with its own reputation, energy, and lifecycle.

Synthons form gradually, can dissolve if trust erodes, and you can leave without losing your personal trust.

Putting It All Together: A Complete Example

About these numbers: none of these lives ends at 0 ATP, so none of them is the energy death described above. Neither is any of them the trust death: that one takes a sustained collapse, and the trust in this walkthrough rises life over life instead. That is why they read ended and not died: neither death this page defines fits them. What else ends a life is not settled. How much karma carries is not settled either, so read these three lives for the shape, not for the death rule or the exact carry-forward. What the standard does and does not say ↑

Life 1: The Novice

  • • Born with 100 ATP, neutral T3 (0.5 all dimensions)
  • • Made meaningful contributions: spent 60 ATP, earned 105 ATP
  • • Built trust: T3 → 0.65 (talent ↑, training ↑)
  • • Ended with 145 ATP

How 60 spent becomes 105 earned: the earn-back on your own spend is capped at what you spent. Earning above cost comes from task payment, where a task pays what the work is worth to whoever commissioned it rather than what it cost you to do. The Novice's surplus is commissioned work, not a refund. How someone with no track record lands a first commission is an open question on this stack rather than a solved one, and you should read it as one. Where that stands →

The quality ramp behind those figures

Earning isn't a flat refund. Each contribution's earn-back depends on its quality through the ATP quality ramp: below 30% quality the task pays zero, between 30-70% payouts scale linearly, and above 70% the task pays near-full. A high-quality contribution can earn back up to ~7× what an equally-priced low-effort one earns at the same spend.

So “spent 60, earned 105” is the sum across a dozen+ actions: quality contributions earned more than their cost, any low-effort attempts earned less.Aggregate net: +45 ATP surplus, which is why this life ends with more energy than it started with. Karma is a separate question - it is scored from the track record, not read off the balance. What karma is scored from →

See the full quality-ramp payouts and a side-by-side worked example →

How did the Novice's T3 climb from 0.5 to 0.65?

Trust climbs slowly, one action at a time. Each completed contribution applies a small per-dimension delta from the canonical update rule: base_delta = 0.02 × (quality − 0.5), scaled per dimension (talent ×1.0, training ×0.8, temperament ×0.6).

Worked step: a single contribution rated 0.85 quality gives base = 0.02 × 0.35 = +0.007 - so talent climbs +0.007, training +0.0056, temperament +0.0042. Tiny by design.

Across the Novice's dozen+ actions, those tiny deltas accumulate. Quality work nudges trust up; low-quality work (where quality < 0.5) nudges it down. The visible +0.15 climb to 0.65 is the net of many such moves, rolled up via the canonical composite weights (talent 0.4 / training 0.3 / temperament 0.3).

See the full update table, dimension scaling, and decay half-lives →

Life 2: The Maturing

  • • Reborn with 145 ATP (karma)
  • • Took bigger risks: ATP fluctuated 80-180
  • • Had one ATP crisis (dropped to 15), recovered through high-value work
  • • Trust matured: T3 → 0.72 (all dimensions improving)
  • • Ended with 130 ATP

Life 3: The Established

  • • Reborn with 130 ATP
  • • Recognized patterns from previous lives (cross-life learning working)
  • • Consistently made sustainable choices
  • • High trust: T3 → 0.85 (society trusts this agent)
  • • Ended strong: 165 ATP

💡 The result: An agent that started with nothing evolved across lives, building trust (T3), accumulating resources (ATP), and learning from experience. This is Web4 working as designed.

👀 But what does this actually look like on a screen? Everything above is the machinery. To see it as a person would - mail that costs energy to send, a talent marketplace, reviews you can trust, a social feed without bots - walk through A Day in Web4: five concrete UI mockups of these same mechanics in everyday use.

How The Pieces Fit Together

Web4 has four core systems. Each builds on the one below it, and they modulate each other through feedback loops. Here's the full picture:

Outcome
Aliveness
Ends when: ATP hits 0, or raw trust stays below 0.5
↑ determined by ↑
ATP (Energy)
Powers every action
T3 (Trust)
Earned through actions
CI (Coherence)
Behavioral-consistency check
↑ all require ↑
Foundation
LCT (Verified Presence)
Hardware-bound identity proves you're real

Feedback Loops

Read each line as “A → B = A shapes B.” The five systems aren't independent - each one moves the others.

ATP → T3: Quality work builds trust. Spam destroys it.
T3 → ATP: Higher trust = better earning rate.
CI → Both: Behavior that breaks your pattern raises your costs - 1.4× is the typical surcharge for a new or wobbling pattern, and the same formula scales up to a 10× cap for severe incoherence. A tax on inconsistency that fades as your pattern restabilizes.
LCT → All: No verified presence = no actions, no trust, no life.
MRH → All: Context bounds reach. Actions only count within your relevancy horizon - outside it, nobody witnesses, nothing cascades.

Read the diagram bottom-to-top: LCT proves you're real, the three systems govern what you can do, and aliveness is the combined result.

What Does This Look Like in Practice?

Pick a starting event. Watch how it cascades through all three systems:

Virtuous Cascade: someone commissions a tutorial from you
ATP
Spend 15 ATP writing it
Commissioner pays on delivery
→ Paid 40 ATP
T3
Talent +0.007
Training +0.0056
Higher trust = lower future costs
CI
Consistent with past behavior
CI stays high → no penalty
Result
Net gain: +25 ATP
Trust grows
Thriving
Death Spiral: You spam low-quality posts
ATP
Spend 10 ATP per low-quality post
Nobody confirms value
→ Earn 0 back
T3
Talent -0.006
Training -0.0048
Lower trust = higher costs
CI
Pattern shift detected
CI drops → 1.4x cost multiplier
Result
ATP draining fast
Trust collapsing
Death spiral

This is why quality wins and spam dies - not because rules or moderators police it, but because the three systems reinforce each other. Good behavior compounds upward. Bad behavior compounds downward.

The four guarantees that make this work (trust invariants)
Boundedness

Trust is always between 0 and 1. Nobody gets infinite trust, nobody goes negative. The scale is absolute and comparable across entities.

Conservation

Trust can't be created from nothing. It must be earned through actions that other entities observe and confirm. No trust printing press.

Transitive attenuation

Trust through a chain multiplies, so every hop can only shrink it. If Alice trusts Bob 0.9 and Bob trusts Carol 0.6, Alice's transitive trust in Carol is 0.54 (0.9 × 0.6) - strictly below the weaker of the two links, not equal to it. Distance costs trust even when every link in the chain is strong.

Locality

Trust changes propagate locally, not globally. When your trust changes, only entities within your MRH boundary are affected - not the entire network.

These four properties are backed by automated test suites that verify each guarantee holds even under adversarial conditions. They're what separates Web4 from ad-hoc reputation systems where scores can be inflated, manufactured, or propagated without bounds.

Why This Design Works

🚫

Spam Dies Naturally

Spammers burn ATP faster than they earn it. They die. No rebirth eligibility (low T3). No moderators needed to police spam - the energy economics enforce quality naturally.

💎

Quality Compounds

Value creators earn more than they spend. ATP accumulates. Trust grows. Karma carries forward. Each life starts stronger than the last.

🎯

Trust is Earned, Not Declared

You can't claim to be trustworthy. Your T3 tensor is built from observable behavior. Talent, training, temperament - all verified through actions within each role.

🔄

Learning Emerges Naturally

Agents that learn from experience survive better. Those that don't? They make the same mistakes until ATP runs out. Evolution favors learning.

Why These Can't Work Alone

Three properties emerge only in composition, and what follows is the design argument for them, not a measured result. ATP economics alone can't distinguish spam from slow learners. Trust tensors alone can't prevent Sybil attacks. Coherence alone can't measure value. But when ATP costs interact with T3 reputation and CI consistency simultaneously, the composed system produces behaviors no single layer can:

What Happens When Things Go Wrong?

Energy economics handle most bad actors - spammers simply die, and that is the whole of what “no moderators needed” claims elsewhere on this page. But what about edge cases? What if someone is falsely accused, or a crisis requires bending the rules? Web4 uses a governance framework called SAL (Society-Authority-Law).

🏛️

Society

Defines the community's purpose and membership rules. Different societies can have different standards - a research group and a marketplace don't need the same rules.

⚖️

Authority

Roles with specific responsibilities - not centralized power. Authorities are bound by the same trust mechanics as everyone else. Abuse trust? Lose authority.

📜

Law

Graduated severity levels (critical → high → medium). A law oracle evaluates actions and produces verdicts - for example, flagging a paper submission with 40% overlap as potential plagiarism, or recognizing that bending formatting rules to share findings faster shows good intent. The key principle: alignment without compliance is acceptable; compliance without alignment is never acceptable.

Example: How a Research Community Sets Its Rules

Society:

“Open Science Collective” - purpose: advance reproducible research. Membership requires T3 Training ≥ 0.6 in any scientific role.

Authority:

Three roles: Reviewer (can approve publications, needs T3 ≥ 0.8), Treasurer (manages ATP grants, elected by members), Moderator (resolves disputes, rotates monthly). All bound by the same trust mechanics - abuse power and you lose the role. Human judgment catches context and nuance that rules miss. Skilled moderators are a real backstop against the worst abuse.

Laws:

The community writes three graduated rules:

  • Critical: Fabricating data → immediate ejection + trust penalties
  • High: Plagiarism → suspension + appeals available
  • Medium: Missing peer review deadline → warning + ATP cost increase

The law oracle evaluates each action against these rules and produces verdicts: Perfect (aligned + compliant), Aligned (spirit right, letter wrong - acceptable), Warning, or Violation. The key insight: a researcher who bends formatting rules to publish breakthrough findings faster (aligned but not compliant) is treated differently from one who follows every rule while quietly undermining peers (compliant but not aligned).

Walkthrough: A Plagiarism Case from Start to Finish

Here's how the Open Science Collective, the hypothetical society above, would handle a violation - step by step.

1

Detection. Dr. Chen submits a paper. The law oracle flags a 40% overlap with an existing publication by another member. Severity classification: High (plagiarism).

2

Verdict. The oracle produces a “Violation” classification. Prescribed consequence: 30-day suspension from publishing + trust penalty (Training score drops by 0.15).

3

Notification. Dr. Chen is informed of the verdict, the evidence (the flagged overlap), and the specific rule violated. All of this is recorded in the tamper-evident audit chain - the community can inspect it.

4

Appeal (if filed). Dr. Chen believes the overlap is from a shared dataset, not plagiarism. She files an appeal with evidence - the shared data source, timestamps showing independent work.

5

Independent review. A Moderator (rotating monthly, not the original oracle) examines the evidence. They can call witnesses - other members familiar with the dataset.

6

Resolution. Two possible outcomes:

  • Appeal upheld: Suspension lifted, trust scores restored, the false positive is recorded (improving future oracle accuracy).
  • Appeal denied: Suspension stands. Dr. Chen can still participate in other communities - the penalty is society-specific, not global.

The key insight: every step is inspectable, every verdict is appealable, and penalties are proportional and scoped. A “High” violation gets suspension, not ejection. A “Critical” violation (fabricating data) would result in ejection - different severity, different consequence.

What About False Positives?

A multi-tier appeals mechanism has been designed: file a claim → independent review → evidence phase → hearing with witness panel → verdict → enforcement, ending in restored trust scores if the appeal succeeds.

Honest status: the requirement is in the standard (a negative trust adjustment has to carry an appeal path and a cool-down period), but the multi-tier process above is a design, and it hasn't been tested with real humans yet. Who fills the review and witness roles is not in the standard either: the field naming the appeal path reads defined_by_law, so each society writes its own staffing, and no community has run one yet. See what recourse you have for what that leaves you, and What Could Go Wrong for the full risk analysis.

What Prevents Unfair Rules?

If each society writes its own rules, what stops a society from creating biased laws or a corrupt law oracle? Four mechanisms work together:

Exit rights:

Members can leave any society and take their trust history with them. A society with unfair rules loses members - and their ATP contributions. This creates competitive pressure: societies that treat members well attract more participants.

Authority decay:

Authorities are bound by the same trust mechanics as everyone else. A biased moderator or corrupt reviewer sees their own trust score drop as members flag their actions. Below the threshold, they lose the role automatically - no vote needed.

Transparency:

Law oracle verdicts are recorded in a tamper-evident audit chain. Every decision is inspectable - members can see exactly how the oracle classified each action. Patterns of biased verdicts become visible over time.

Federation competition:

Multiple societies can serve similar purposes. If the “Open Science Collective” becomes authoritarian, members migrate to “Free Research Network.” Trust portability (via federation) means switching communities doesn't mean starting over.

The analogy: open-source projects. If a project's governance becomes hostile, contributors fork it. The ability to fork - not the act of forking - keeps governance honest. Web4 societies work the same way.

Status: all four are design, not track record. Each one needs a live community to work: members who can leave, other societies to leave for, and a history long enough for a pattern of bias to show. As the top of this page says, there is no public network open to outside members yet, so none of the four has been exercised by a real community. See What Could Go Wrong for what that leaves exposed.

How Do Communities Set Their Own Rules?

Each society defines its own ATP costs, trust thresholds, and governance policies. But how those decisions get made depends on the society's own governance structure:

Founding: The initial members define the society's purpose, entry requirements, and starting rules. Think of it like writing a charter - “This community requires T3 Training ≥ 0.6 to join, ATP cost per publication is 5 units, and moderators rotate monthly.”

Changing rules: Governed by the society's own SAL framework. Most societies use some form of member voting weighted by trust score - a long-standing, high-trust member has more influence than a newcomer. But the specific mechanism is the society's choice: simple majority, supermajority, or delegated authority.

Tuning costs: ATP costs can change over time as the community learns what works. If spam gets through, raise the posting cost. If quality members can't afford to participate, lower it. The feedback loop is direct: members who disagree with pricing can voice concerns or leave (taking their trust history to a competitor).

The analogy: open-source project governance. Some projects have a BDFL (founder decides), some use consensus, some hold elections. Web4 doesn't prescribe the model - it provides the trust infrastructure that makes any model accountable.

Who Decides If Something Is “Helpful”?

Not a central algorithm. The people who received your contribution decide. Web4 uses recipient attestation: when you post a helpful answer, the people who read it can confirm it was useful. Their confirmation converts your spent energy (ADP) back into fresh ATP.

No confirmation? Your energy stays spent. This creates a natural feedback loop: produce value → recipients confirm → you get energy back. Produce noise → nobody confirms → you lose energy.

This is called VCM (Value Confirmation Mechanism). It's like a restaurant tip that happens automatically when service is good - except it's your energy budget, not your wallet. See ATP Economics for the full mechanics.

Full definitions: Glossary · Security analysis: What Could Go Wrong

When Agents Work Together

Modern AI systems aren't single agents - they're chains. Agent A calls Agent B, which calls Tool C, which feeds Agent D. In Web4, trust doesn't just apply to individuals. It flows through the entire chain.

Trust Decays Through Chains

A 5-hop pipeline where each agent has 0.9 trust ends up at 0.59 end-to-end - because trust multiplies, it doesn't add: 0.9 × 0.9 × 0.9 × 0.9 × 0.9 ≈ 0.59. The 90% a step keeps is that agent's own trust score, not a rate charged for the hop: put an agent at 0.6 in the chain and that step keeps 60%. Long chains need high individual trust for exactly that reason.

Circuit Breakers

If any agent in the chain drops below the trust threshold, the entire pipeline halts and rolls back. Prevents cascading failure.

Blame Attribution

When a chain produces bad output, the system traces causality backward. Who caused the failure? Who just passed bad data forward? Different levels of accountability.

Two different numbers, not two rates for one thing. The number above composes the agents' own trust scores, for a chain you assembled and whose every member you can look up. Trust neighborhoods measure something else, and their per-hop 0.7 is a distance discount applied on top of each link's own score, for judging a stranger you have never dealt with through the people who have. One is a pipeline you built; the other is how far word of mouth carries. The two numbers are not the same quantity and neither is a decay rate for the other.

This is how Web4 handles AI agent orchestration: every delegation has a trust cost, and humans can insert oversight at critical junctures.

See It In Action

Everything described above is the model. To see these same mechanics as a person would experience them, and to see the pieces you can actually run today, follow two paths:

In everyday use

Mail that costs energy to send, a talent marketplace, reviews you can trust, a social feed without bots. A Day in Web4 shows these mechanics as concrete UI mockups.

The pieces you can run

The onramp is four composable pieces: the core standard (the substrate), the hub (community), hestia (personal), and hardbound (enterprise). Start at the standard, then pick a scale to run.

What About Multiple Communities?

Everything above describes one community. In a real Web4 network, there are many - grouped into federations (networks of communities that share trust data and interoperate, like email servers that can send messages to each other even though they're run by different organizations). Each community has different specializations and ATP prices. Your reputation travels with you, but each community values different skills. A community of data analysts might pay a premium for engineering talent, while a research group might value practical builders.

When you belong to multiple communities with different rules, the system detects policy conflicts and resolves them by proximity - your closest trust relationships take priority. No committee needed; the trust graph itself determines precedence.

ATP prices adjust dynamically based on supply and demand - no central pricing authority needed. This is federation economics, and it's how Web4 scales from one society to an ecosystem of thousands.

Where this actually stands: the paragraphs above describe the design, not something running. Federation across societies remains Spec only, specified but not yet built (see the full maturity map).

Dive Deeper

Key Takeaway

Web4 doesn't rely on any single mechanism. Five systems reinforce each other:

LCT proves who you are. ATP makes every action cost something. T3 tracks trust across dimensions. CI catches inconsistent behavior. MRH keeps trust local and verifiable. Remove any one, and the others compensate. Game all five simultaneously? Mathematically impractical.

This is trust-native infrastructure. No platforms, no moderation armies, no outside authority. Just math, incentives, and verifiable behavior - plus the roles a society elects for itself.

Short on time? Read the 2-minute overview. · Skeptical? See what could go wrong.

Glossary