Falsifiable rules

Six portable invariants.

These are not design preferences. Each invariant names a generalized failure scenario and the rule that prevents it. They are a growing release set, not a second set of the five contract families.

01

Publishability and indexability are separate

The failure

Temporary fallback states emit noindex. Crawlers cache it. Legitimate URLs disappear after recovery.

The rule

Tiers decide what a page may render. Robots directives come only from explicit indexability policy.

02

Timeouts are not entity absence

The failure

A timed-out existence check becomes 404 or 410. Latency shrinks the index.

The rule

Model support as supported, unsupported, and unknown. Only canonical evidence produces permanent absence.

03

Rendered truth beats resolver intent

The failure

A resolver says ready while production returns a placeholder or the wrong robots policy.

The rule

Validate sitemap and link eligibility against rendered output, not registry membership alone.

04

A single rendered page must not disagree with itself

The failure

Suppression copy says no public claim while an adjacent module emits from $199.

The rule

One resolver. Suppression is a property of the page, not of a module.

05

Partial guards are false signal

The failure

A policy covers N of M emission surfaces. The rest keep leaking the claim.

The rule

Treat any partial implementation as unshipped, regardless of how many surfaces it covers.

06

One decision, many surfaces

The failure

Body, headers, JSON-LD, agent APIs, and sitemaps each re-derive the same fact.

The rule

One resolver per public fact. Every surface derives from it. Never copy. Never re-invent.

Scenario, not proof claim

Every invariant must be paired with a probe.

An invariant without an applicable probe is a belief. When required probe inputs are missing, the result is UNMEASURED—not PASS.