An ontology is a contract, not a theory
There must be agreement not only in definitions but also … in judgments.
— Ludwig Wittgenstein, Philosophical Investigations, §242
Abstract
Enterprise buyers value ontologies, but few of them value expressive logical inference. The description-logic tradition treated these as one thing, so that a falling estimate of inference brought the estimate of ontologies down with it. This note separates them.
An enterprise ontology is a taxonomy of classes and properties together with types and constraints on them. Read under the closed-world assumption (CWA), its axioms are conditions on shared data rather than premises with consequences, and its meaning is fixed by its verdicts on that data: which records fall under which classes, and which writes are admitted. So read, an ontology is a contract in the social sense. It’s public, explicit, semi-formal, and binding by affirmative consent, any party can check conformance to it, and an operating system for agents can enforce it at every write and every action.
The expressivity of such a contract is more than SQL DDL, less than arbitrary code. The neutrality buyers attribute to ontologies is a property of its placement in that range specifically. LLMs can draft these contracts from enterprise documents and data with high fidelity, provided that they draft and don’t consent, and provided that fidelity is established by checks the drafting model doesn’t control. This note states the argument as twelve propositions and then describes the machine that drafts.
TLDR
The argument is a chain of twelve propositions. Propositions 1 and 11 are empirical, and the sections cited give the grounds for them. The rest are analytic and follow from those before them.
- Enterprise users want almost no inference: subclass and subproperty expansion, transitive closure, and little else. (§1)
- Enterprise users value ontologies nonetheless. The value of an ontology to them therefore doesn’t lie in inference, primarily. (§1)
- An ontology has three uses: inference, agreement, and enforcement. Research optimized for the first, buyers pay for the second, and an operating system for agents needs the third. (§1)
- Agreement and enforcement require only a taxonomy and types and constraints on classes and properties. (§2)
- Read under CWA, such an ontology fixes meaning by its verdicts on shared data, namely which records fall under which classes and which writes are admitted. (§2)
- Agreement about such an ontology is verifiable: assent is recorded, conformance is checked, and departures are attributable. (§3)
- Entailment works against consent, because to assent to a theory is to assent to each of its consequences, including ones nobody has computed or read. Restricting an ontology to taxonomy and constraints keeps every commitment on the face of the document. (§3)
- An ontology so restricted is a contractual type checker whose expressivity lies above SQL DDL and below code, in the band where conformance is declarative, decidable, and cheap to check. (§4)
- The neutrality buyers ascribe to and value in ontologies is a property of that band. A contract must be stated in a language every party can check and no party controls. (§4)
- Background knowledge is already captured in model weights. What the ontology adds is the part that must be exact, enforced outside the model. (§5)
- A model can draft the contract from enterprise documents and data, and the substance of the specification it drafts against is the set of disagreements between those two sources. (§6)
- Fidelity is established by checks the drafting model doesn’t control. The model drafts, the parties consent, and the operating system enforces. (§6, §7)
1. What buyers don’t buy
Almost no customer uses logical inference beyond subclass and subproperty expansion, transitive closure over a few properties, and occasionally an inverse. Hence, the value of an ontology lies somewhere other than in what a reasoner computes from it.
An ontology has three uses, and they’re separable.
- Inference: deriving consequences the authors didn’t write down.
- Agreement: a vocabulary that several parties, usually several departments, have accepted, and a record that a decision about meaning was made.
- Enforcement: a specification that data and actions can be checked against, and that a system can refuse to let them violate.
Scientific research optimized for the first. Enterprise buyers pay for the second, and the organizational utility they buy is real even though it isn’t logical. An operating system for agents needs the third. The rest of this note concerns the second and third, and argues that they call for the same artifact, which isn’t the artifact the first produces.
2. Taxonomy and types under the closed world
If the only inference anyone wants is subclass, subproperty, and transitive closure, then the deductive core of an enterprise ontology is reachability over two directed acyclic graphs, one of classes and one of properties. That needs no description-logic reasoner. The closure can be materialized when the ontology changes or computed on demand, and in either case it’s cheap. Hence, most OWL 2 profiles are in this respect more than the users ask for: existential restrictions and property chains and the like are machinery that few of them will ever exercise.
What remains is everything else an ontology says about classes and properties: that a property has a given datatype or range, that a record of one class must carry exactly one value of another, that two classes are disjoint. Under the open-world reading these are axioms, and a missing value isn’t a violation but an invitation to infer that the value exists somewhere. Under CWA, they’re integrity constraints. Tao, Sirin, Bao, and McGuinness gave OWL this second semantics in 2010, and some vendors shipped it as integrity constraint validation: each axiom compiles to a query that returns its violations, and data satisfies the ontology when every such query returns nothing. The W3C’s SHACL later standardized the same idea for RDF data.
The closed-world reading changes what the ontology means. Under the open-world reading, the meaning of an axiom is the class of models that satisfy it, and two parties who accept the same axioms may intend different models without anything in the logic to say so. Under the closed-world reading, evaluated over shared data, the extension of a class is the set of records that fall under it, and the meaning of a constraint is the set of writes it admits and the set it rejects. These are observable. A party who reads a term differently from the others will, sooner or later, write a record that the constraint rejects, and the disagreement will show.
This is Wittgenstein’s point in Philosophical Investigations §242 taken as an engineering requirement. A shared vocabulary needs agreement in definitions, which the taxonomy supplies, and agreement in judgments, which the constraints supply by delivering the same verdict on the same record for every party. An ontology that supplied only definitions would leave the second kind of agreement untested.
One residue remains. A term none of whose instances appear in the shared data has a definition but hasn’t yet been judged. Agreement about it is untested rather than unprovable. It becomes testable when records arrive. Such terms should be marked as provisional in the ontology itself, so that nobody mistakes an untested agreement for a confirmed one.
3. Verifiable agreement
An ontology of this kind is a contract, and the word is meant in its social sense. A contract is public, explicit, semi-formal, and binding by affirmative consent. Each property corresponds to a commitment in the design of WunderOS.
- Public. The ontology is versioned and visible to every party it binds, and the record of which party assented to which version is part of it.
- Explicit. Every commitment appears on the face of the document. Inheritance through the hierarchy is the one implicit step, and it’s simple enough that any party can trace it by hand.
- Semi-formal. Like a contract with operative clauses and recitals, the ontology has a formal part that machines enforce and an informal part, made of labels, definitions, and scope notes, that people read. The two parts must say the same thing, and keeping them aligned is a standing obligation, discussed in §7.
- Binding by consent. Consent attaches to a specific version. An amendment binds no party until that party consents to it, and what a party consents to is the difference between versions.
The second property explains the buyers’ indifference to inference better than any account of their sophistication. Under entailment, to assent to an ontology is to assent to all its consequences, including consequences that nobody has derived and nobody has read. That’s consent to terms one was never shown, which is the opposite of what a contract is for. A buyer who wants an ontology to serve as an agreement between departments has a reason, whether or not it’s stated, to prefer an ontology whose consequences are no more than its contents.
On this reading, agreement about an ontology is verifiable, in the sense that three claims about it can be checked.
- Assent is recorded. Each party commits to a specific version, and the commitment is signed and attributable.
- Conformance is checked. Every party’s data and every agent’s action is validated against the ontology at the boundary where it would take effect, so that assent appears in conduct and doesn’t rest on a declaration.
- Departures are attributable. A violation identifies which party’s data or which agent’s action departed from the ontology, and under which version.
The analogy extends to breach. A violation is a breach attributable to a party, and the staged enforcement described in §5, in which a constraint is observed before it’s enforced, corresponds to a graduated set of remedies.
4. Between DDL and code
An ontology so restricted is a contractual type checker, and its expressivity can be located fairly precisely. The lower bound is SQL DDL: column types, keys, NOT NULL, and CHECK constraints. An ontology exceeds it in four ways.
- Constraints are inherited through a class hierarchy.
- An entity may belong to several classes at once and is bound by the constraints of each.
- Properties have a hierarchy of their own and may be transitive.
- The schema names no tables, so it can span sources that store their data in different layouts.
The upper bound is code, which is general-purpose and Turing-complete. Between the two lies a band in which conformance is declarative, decidable, and cheap to check, which in practice is roughly SHACL core together with transitive closure.
Buyers often say that they value ontologies for their neutrality. The word covers three distinct properties.
- Vendor neutrality. The contract is stated in an open standard and isn’t tied to a product.
- Implementation neutrality. The contract names no tables, services, or code paths, so any system can be mapped onto it.
- Party neutrality. No department owns the contract, and an upper ontology such as BFO supplies common ground that belongs to none of them.
The band supports all three, and this isn’t a coincidence. A contract must be stated in a language that every party can read and check for itself, and that no party controls. Code fails both conditions: it’s an implementation, it privileges its author, and conformance to it is undecidable in general. SQL DDL is readable and checkable but bound to the system that holds the tables.
The ontology band is weak enough that any party can verify compliance with any conforming tool, and strong enough to state (most of) the rules that matter. The neutrality buyers perceive is therefore not sentiment detached from the technology. It tracks a property of the expressivity band.
One consequence follows for design. Agents raise procedural requirements that a constraint over a single state of the data can’t express: that an approval precede a release, or that a record not change after sign-off. These are constraints over sequences of states, and they push the required expressivity upward toward code. If they’re written as code they lose the neutrality that makes the contract worth having.
As a kind of modest compromise, in WunderOS they’re written in Wunderlog, the system’s native query language, as declarative constraints checked over the event record. Wunderlog’s metric temporal operators state the ordering and timing requirements, and its query engine’s three-valued semantics under approximation fixpoint theory keeps a fact that hasn’t yet arrived from being reported as a violation, so the constraints stay inside the band. The semantics are given and illustrated in some detail in PLRN-018 and PLRN-019.
5. What the weights already know
An LLM knows a great deal of what an ontology would once have been built by hand, at great time and expense, to record. It knows that a centrifuge is a device and a calibration is a process, and it knows many facts about particular centrifuges. In this sense it holds both terminological and assertional knowledge, approximately and without guarantees, and the temptation is to treat it as the knowledge base and the ontology as an export from it.
The temptation should be declined, and the reason fixes what the ontology is for. An agent, being a neuro-symbolic system that combines a harness and a model, already has a model from which to draw background knowledge. What does an ontology add to the agent?
What the ontology adds is the part that must be exact and must be enforced outside the model, because a model can’t be relied on to police its own output. In an operating system for agents like WunderOS the ontology works less like a knowledge base than like a type system over agent effects. Three consequences follow.
First, enforcement belongs at the boundaries where effects happen: when an agent commits a write to memory, and before a tool call takes effect. It doesn’t belong at query time, when the damage is already done. This is the division PLRN-028 draws between semantic judgment and mechanical authority, applied to meaning. The model proposes a change of state, and the operating system admits or rejects it against the contract. The contract itself enters the enforcing layer only through the admission gate that PLRN-028 requires, since an agent that could write the constraints would have rewritten the enforcement.
This closes a loop in WunderOS, which already uses Rego for access control at its policy decision points. The constraints that bear on authorization, such as which classes of record an agent acting under a given mandate may read or write, can be compiled from the ontology into Rego and loaded where those decisions are made. Two conditions keep the compilation inside the argument. First, Rego is declarative and its evaluation terminates, so the compiled policy stays within the expressivity band of §4. Second, the compiler is deterministic and trusted, not a model, so that a policy generated from a consented version of the ontology is the same artifact as that version in another form, and enters the enforcing layer through the same gate. A model that wrote the Rego directly would reopen the regress PLRN-028 closes.
Second, facts asserted by a model must be quarantined. If model-generated instances enter the shared record unmarked, they contaminate the data against which constraints are validated, and the empirical checks described in §7 lose their independence. Such facts enter as provisional and attributed to the model that asserted them, in the manner of PLRN-017, and they never serve as ground truth for testing a constraint.
Third, errors in the contract are asymmetric. A constraint that’s too loose admits bad writes silently. A constraint that’s too tight blocks agents visibly. A newly admitted constraint therefore runs first in observe mode against live traffic, logging the writes and actions it would have rejected, and is promoted to enforcement after a clean window. This is the remedy schedule of §3 in operational form, and it gives the fidelity checks of §7 a form that runs in production.
6. The final irony is that a machine drafts the contract that binds machines
The contract has to be written by someone and nobody has the time to be tagged “you’re it”.
The holy grail, as ironic as ever, is a machine that drafts the ontology that binds the machine.
- A model can draft it.
- The inputs are an upper ontology, for which we use BFO, together with the enterprise’s documents and a sample of its data.
- The model doesn’t emit the ontology directly. It writes a program Q that, when run deterministically, emits the ontology O.
- Emitting a program has three advantages: Q is inspectable and reproducible, it can read enterprise sources directly, and refinement becomes the editing of code under a regression suite rather than the regeneration of a document.
The question is what Q is written against. Call it the specification S. Once O is restricted to taxonomy, types, and constraints, enterprise data becomes a primary source of S and not merely a test set, because a taxonomy and its types are exactly what data exhibits.
Documents state what the schema ought to be; data shows what it is. The producer of S uses both and treats the differences between them as its principal output.
The work divides into three parts.
- Mining from data. Profiling recovers datatypes, value ranges, cardinalities, and the co-occurrence of properties. Formal concept analysis over the co-occurrence of classes and properties yields a candidate taxonomy as a lattice. None of this needs a model, and all of it is deterministic and repeatable.
- Extraction from documents. The model reads standard operating procedures, data dictionaries, and quality manuals for stated types and rules, including the procedural constraints of §4.
- Reconciliation of the two. The two sources disagree in two characteristic ways. A regularity in the data that no document states may be a rule nobody wrote down or an accident of the sample. A documented rule that the data violates means that either the data is bad or the document is stale. Each disagreement is an item for review, and the reviewed set of items is the substance of S.
The model’s distinctive contribution lies in the first kind of disagreement. If every batch record in the sample has a single approver, the question is whether that’s a rule or a coincidence of the period sampled. The data can’t settle this, since it shows only the regularity. The decision rests on knowledge of the domain, which is what the weights supply. This is the old problem of distinguishing lawlike from accidental generalizations, and it’s where the model earns its place in the pipeline.
The drafting loop is counterexample-guided synthesis in the sense of Solar-Lezama. The model writes or edits Q, Q is run to emit O, and a verifier checks O against S. Failures return to the model as structured counterexamples: the requirement violated, the records involved, and the clause of Q that produced the offending axiom.
- On a cold start the model first proposes the signature, meaning the classes and properties together with their placement under BFO, and the signature is reviewed before any constraint is written, since most later errors trace to it.
- On refinement, the model edits an existing Q, and the accumulated requirements serve as its regression suite.
The division of labor within the loop is the one that recurs throughout WunderOS. Placing a new concept in a hierarchy is a judgment of similarity, and geometric methods suit it: order embeddings, box embeddings, and hyperbolic embeddings represent partial orders faithfully, with containment standing in for subsumption. Confirming the placement is symbolic and trivial, since it’s reachability. Geometric methods propose and symbolic methods decide, and the boundary between them falls where a wrong answer stops being tolerable.
O then satisfies S when three conditions hold.
- Its taxonomy and constraints agree with the reviewed requirements.
- It accepts a held-out sample of data known to be good.
- Every class it declares is placed under BFO.
Each condition is mechanically checkable, and only the review of disagreements requires a person.
7. Fidelity without trusting the drafter
The central lesson of work on autoformalization into proof assistants is that the hard problem is the fidelity of the statement, not its proof. A type checker tells you that a formal statement is well formed. It doesn’t tell you that the statement means what its informal source meant. A verifier of ontologies is in the same position: it can confirm that O satisfies the requirements as written, but not that the requirements say what the enterprise intends, much less what it should’ve intended instead. The checks below address that gap, and each is one the drafting model doesn’t control.
- Agreement of independent drafts. Several drafts of the same section of O are produced independently and compared by their closures and by their verdicts on a sample of data. Drafts that agree are evidence of a determinate source. Drafts that split show that the source is ambiguous, and the split identifies the precise question to put to a person.
- Back-translation. Each constraint, and each new ancestor a class acquires, is rendered in controlled English and judged against the source documents by a separate model that hasn’t seen the formal draft. A disagreement flags an error of fidelity that no verifier could catch, and the same check keeps the formal and informal parts of the contract aligned, as §3 requires.
- Held-out data. A constraint that rejects records known to be good is wrong, and this is observed directly. Because the held-out records weren’t produced by any model, this is the most independent check available, and it’s the reason §5 requires model-asserted facts to be quarantined.
- Instance tests. Concrete cases are taken from the source text, such as that a calibration is a process and not a device, and asserted with their expected classifications. They act as unit tests that read like the domain rather than like logic, and domain experts can write them.
- Grounding. Every term in the signature must cite a passage in a source document or a term in BFO. Ungrounded terms are where invention enters.
- Category checks. Placement under BFO is where models err most often and where errors propagate furthest, since a misplaced class inherits constraints that don’t fit its instances. The distinctions between continuant and occurrent, and between role, disposition, and function, receive dedicated checks, and violations they cause on good data are traced back to the placement.
The last check shows that the two parts of the contract check each other. A misplaced class inherits constraints from its new ancestors, those constraints reject the class’s own good records, and the rejections locate the error in the taxonomy. In a closed-world contract, errors of definition surface as errors of judgment.
The drafting model never consents. Its output is a proposed contract, as a lawyer’s draft is, and it binds no party until the human, all too human parties assent to it. This matters for responsibility, since no one can say that the model agreed to anything on their behalf, and it locates the model correctly in the architecture of PLRN-028: on the side of semantic judgment, outside the admission gate.
8. Objections
First, it may be said that this is integrity constraint validation or SHACL under another name. The semantics are the same, and they aren’t new; they were published in 2010 and standardized in 2017. What this note adds is the machine that drafts such contracts from enterprise sources, with checks on its fidelity that the drafting model doesn’t control.
Second, it may be said that the argument discards two decades of work on description logics. It discards nothing that buyers use. Subclass, subproperty, and transitive closure remain, and an enterprise that wants more inference for a particular purpose can have it. The claim is only that inference isn’t what makes an ontology valuable to an enterprise, and that building for inference first builds for the use nobody is paying for.
Third, it may be said that a model can’t be trusted to write a contract. It can’t, and the design doesn’t trust it. The model drafts, and every draft passes checks it doesn’t control before any party is asked to consent. Nothing the model writes binds anyone or reaches the enforcing layer except through the admission gate.
Fourth, it may be said that geometric and neural methods will supplant symbolic checking altogether. They’ll supplant the parts of the work that were never deductive: similarity, analogy, typicality, and the guessing of missing structure, all of which were forced into logic prematurely, as it turned out. They won’t supplant the checking of a contract, because that check is already cheap and must be sound. An approximate check of a contract is a check that will sometimes admit a breach, which is a property no party would consent to.
Fifth, it may be said that the closed-world assumption misreports incompleteness as error, since enterprise data is spread across sources and a missing value is often ignorance rather than absence. This is correct, and the remedy is to declare closure for each source and each property rather than globally. Deciding where closure holds is part of drafting the contract and part of what the parties consent to.
Sixth, it may be said that BFO isn’t neutral, since it embodies a realist metaphysics that not everyone shares. The neutrality claimed for it is neutrality among the parties to a contract, none of whom wrote it, and not neutrality among conceptualities. An enterprise that prefers another upper ontology loses nothing in the argument by substituting it.
9. Five open questions
The argument leaves five questions open. Four of them can be answered from what has already been argued, and the fifth reduces to an experiment that hasn’t yet been run.
9.1 Convergence of the drafting loop
That some halting machine maps a specification to the intended ontology is trivially true, and proves nothing. The restriction of §2 makes a stronger claim provable. The signature is finite, since it’s drawn from finite sources. Constraints are instantiated from a closed set of templates, namely datatype, range, cardinality, and disjointness, and their parameters come from finite sets: the datatypes observed, and cardinality bounds no greater than the maximum observed.
The space of candidate contracts is therefore finite. If the verifier records every refuted candidate and rejects its resubmission, each counterexample removes at least one candidate, and the loop halts, either with an O that satisfies S or with a report that S is unsatisfiable. The faithfulness of S to intent remains a hypothesis, and it’s now the only one.
9.2 Amendment
Versions of the ontology and consents to them are entries in the append-only ledger of PLRN-028, and an amendment is the difference between two versions. A version comes into force for a set of parties when each party it binds has recorded a signed consent. The rule that decides which parties a version binds is fixed by mandate and not by the ontology, so that the contract doesn’t govern its own adoption and no regress arises.
Data is judged against the version in force at its transaction time, using the two clocks of PLRN-018. When a new version comes into force, existing data is revalidated against it in observe mode, and the violations found form a migration worklist rather than a set of retroactive breaches, because a breach is always relative to the version in force when the write occurred.
9.3 The procedural fragment
Schneider showed that a mechanism which observes execution and blocks it can enforce only safety properties, those whose violation is witnessed by a finite prefix. Enforcement at the boundary of a write or an action is such a mechanism, so the procedural fragment of the contract should express safety properties and nothing more.
It’s therefore past-time metric temporal constraints, written as stratified Wunderlog rules that derive violation facts, which can be monitored online with bounded memory when their intervals are bounded. An obligation with a deadline, such as that a deviation be investigated within thirty days, is a bounded liveness property, and bounded liveness is a safety property, so it belongs to the fragment.
Unbounded liveness is excluded, and the exclusion is correct, since nothing can enforce it at a boundary.
9.4 Inference beyond the hierarchy
An enterprise that wants more inference for a specific purpose adds it as named derivation rules, consented to as clauses like any other, and derived facts are marked as derived and carry their provenance. This doesn’t reopen proposition 7.
The objection to entailment was that its consequences range over all models and can’t be listed, so that consent to them is consent to terms unseen. Derivation under the closed world, over finite shared data, has finitely many consequences, and they can be materialized and shown to the parties before they consent.
The line that matters is between consequences that can be enumerated and consequences that can’t, not between inference and its absence.
9.5 Measurement
The fidelity checks of §7 are described and not yet evaluated, and this remains the note’s principal limitation. The experiment is specified as follows.
- FHIR supplies all three inputs: its prose specification serves as the documents, its official profiles and invariants are an expert-written contract to score against, and Synthea generates conforming data.
- Agreement is measured as edge-level F1 on the closure of the taxonomy, as agreement between violation sets on held-out data, and as the review load per hundred axioms.
- Removing each check of §7 in turn shows which errors each one catches. A result on FHIR wouldn’t establish fidelity in every enterprise domain, but it would replace an unstated gap with a measured one.
The experiment of §9.5 and the faithfulness of S to intent are what remain open. The second can be tested but not proved, and the first is how it would be tested.
Related work
The closed-world semantics for OWL is Tao, Sirin, Bao, and McGuinness (2010), and SHACL is its standardized descendant. Competency questions as the requirements an ontology must meet are Grüninger and Fox (1995). Formal concept analysis is Ganter and Wille (1999). Counterexample-guided synthesis follows Solar-Lezama (2008). Geometric embeddings of description logics include Kulmanov and colleagues (2019) and Jackermeier, Chen, and Horrocks (2024). Evidence that language models carry structured internal representations of the world includes Gurnee and Tegmark (2023), and the extraction of programs from trained networks is Michaud and colleagues (2024); neither shows that model-drafted ontologies are correct, which is why the checks of §7 are required. The distinction between lawlike and accidental generalizations is Goodman’s. BFO is Arp, Smith, and Spear (2015) and ISO/IEC 21838-2.
Within this series of research notes, PLRN-028 supplies the division between semantic judgment and mechanical authority and the requirement that rules enter the enforcing layer through a gate agents don’t control; this note applies both to meaning. PLRN-017 concerns the attribution that model-asserted facts require. PLRN-018 and PLRN-019 give the temporal semantics on which procedural constraints rest. PLRN-022 states the discipline of using the least costly and least stochastic mechanism that preserves the required quality of an answer, which is why reachability, not a model, confirms placement in the hierarchy.
The contribution of this note is the description of a machine that drafts ontologies as contracts from enterprise documents and data, with checks on its fidelity that the drafting model doesn’t control.
References
- Arp, R., Smith, B., Spear, A. D. Building Ontologies with Basic Formal Ontology. MIT Press, 2015.
- Ganter, B., Wille, R. Formal Concept Analysis: Mathematical Foundations. Springer, 1999.
- Goodman, N. Fact, Fiction, and Forecast. Harvard University Press, 1955.
- Grüninger, M., Fox, M. S. Methodology for the Design and Evaluation of Ontologies. IJCAI Workshop on Basic Ontological Issues in Knowledge Sharing, 1995.
- Gurnee, W., Tegmark, M. Language Models Represent Space and Time. 2023. arXiv:2310.02207
- HL7 International. FHIR (Fast Healthcare Interoperability Resources). https://hl7.org/fhir/
- ISO/IEC 21838-2:2021. Information technology: Top-level ontologies, Part 2: Basic Formal Ontology.
- Jackermeier, M., Chen, J., Horrocks, I. Dual Box Embeddings for the Description Logic EL++. The Web Conference, 2024.
- Knublauch, H., Kontokostas, D., eds. Shapes Constraint Language (SHACL). W3C Recommendation, 2017. https://www.w3.org/TR/shacl/
- Kulmanov, M., Liu-Wei, W., Yan, Y., Hoehndorf, R. EL Embeddings: Geometric Construction of Models for the Description Logic EL++. IJCAI, 2019.
- Michaud, E. J., et al. Opening the AI Black Box: Program Synthesis via Mechanistic Interpretability. 2024. arXiv:2402.05110
- Schneider, F. B. Enforceable Security Policies. ACM Transactions on Information and System Security 3(1), 2000.
- Solar-Lezama, A. Program Synthesis by Sketching. PhD thesis, UC Berkeley, 2008.
- Tao, J., Sirin, E., Bao, J., McGuinness, D. L. Integrity Constraints in OWL. AAAI, 2010.
- Walonoski, J., et al. Synthea: An Approach, Method, and Software Mechanism for Generating Synthetic Patients and the Synthetic Electronic Health Care Record. JAMIA 25(3), 2018.
- Wittgenstein, L. Philosophical Investigations. 1953.
A note on method
Drafted with Claude Opus 5.5. The argument, the separation of the three uses, the contractual reading, and the architectural commitments, both here and in the underlying system, are mine.
Kendall Clark · k@pentad.ai
Great Falls, Virginia
6 October 2026