Cittadelle

The Method
How the work is done here

The Manifesto says what Cittadelle is for. This says how it actually works — the mechanics that are not obvious from the outside, and the few places where the platform asks something precise of you. Read it once and the rest of the site explains itself.

01 Codes and citation

Everything that matters here has a code, and every code is a live citation anywhere you write it.

Write SRC-0034 in a post, a comment, a verification note, a Brief or a contestation argument. No brackets, no button, no special syntax — the bare code is enough. It becomes highlighted, hoverable, and clickable: hovering shows the object's title, type and current status; clicking opens it.

The consequence is the whole point. A claim carries its evidence's standing with it at the moment of reading. If a source is contested next month, every argument that ever cited it says so, without anyone going back to edit anything.

The codes you will meet

CodeWhat it is
SRC-a source in the archive
VN-a verification note on a source
CONT-a contestation of a whole source
CONTN-a contestation of a single note
CONTG-a contestation of a graph connection
BRF-a Brief
PROP-a proposal to add something to a graph
POST-a post and its discussion
CHA- / STR-a Chamber, a strand within it
GRF- / FTM- / PYR-a node or connection in Octopus, Follow the Money, Pyramid
ENT-an entity, independent of which graph it appears in

One thing deliberately has no code: private messages. They cannot be cited, anchored or introduced as evidence anywhere. That is the purpose of them, not a missing feature — a private conversation should never become an exhibit.

02 The kinds of source

Seven kinds. The kind you choose decides which fields the source carries and — more importantly — which of the two verification paths it takes.

KindIts own fields
Archive / official documentholding institution, reference or protocol number, classification level, declassification date
Academic / researchjournal or publisher, DOI or ISBN, pages
Journalisticoutlet or publication
Financial recordissuing body, period covered, document type
Legal documentcourt or jurisdiction, case number
Audiovisualproducer or channel, duration, transcript availability
Imageplace, agency or photographer, sub-type (photo, chart, map, screenshot)

Everything also carries a date — free text, so 1971, March 1971 and 1968–1972 are all valid — an institution or author, and a language.

What is required when you submit

A title, a URL or an uploaded file, and a note saying what the document is and why it matters. Nothing else. Every other field can be completed later by anybody — an empty field is an invitation.

Audiovisual material is always linked, never uploaded. Hosting video is out of scope, and a link plus the archived copy keeps it checkable.

The cited passage

Optional, and worth more than it looks: transcribe the specific passage you are relying on. It appears as a quotation on the source page, and it turns "this document says X" into something a reader can check in five seconds instead of forty pages.

Who can change what

Empty field — anyone can fill it. This is how the archive improves after the fact.
Filled field, source not yet verified — only the uploader can change it.
Filled field, source verified — frozen. If something is wrong in a verified source, that is what contestation is for. Nothing here can be quietly overwritten.

03 Two paths to verification

This is the single most important mechanic on the platform, and the one newcomers most often get wrong: sources are not all established the same way.

The distinction is not about how good a source is. It is about whether the document authenticates itself.

▣ Primary source

Self-authenticating: an official URL or a DOI that lets anyone check it immediately. A court ruling on the court's own site, a parliamentary act, a paper with a DOI, an official financial filing.

Three confirmations. Members confirm that the reference is genuine and corresponds to the document. No argued note is required — there is nothing to argue about, only something to open and look at.

Result: ▣ Authenticated

✓ Source

Everything else: journalism, audiovisual, photographs, archival material, financial records that are not official filings.

Three argued notes, each carrying its own distinct reference — another source in the archive, an external URL, or an uploaded file. Three notes pointing at the same thing do not count as three.

Result: ✓ Verified

Why declaring "primary source" cannot be gamed. Say a document is a primary source without a real reference behind it, and nobody confirms it — because confirming means opening the link and finding the document there. It simply stays unsubmitted. The mechanism regulates itself without anyone policing it.

What verification does not mean

It does not mean the document is telling the truth. Verification establishes that a document is authentic and is what it claims to be. Whether its contents are accurate, and what they imply, is argued in Chambers and synthesised — provisionally — in Briefs. Keeping these two questions apart is what keeps the archive usable by people who disagree with each other.

04 Writing a verification note

A note is not an opinion about a document. It is a piece of evidence about a document.

A note needs two things:

An argument. What you checked, and what it establishes. "The dates match the Church Committee testimony on pages 4 and 11" is a note. "Looks legitimate" is not.
A reference, distinct from the others. An internal SRC- code, an external URL, or a file. If two earlier notes already cite a document, yours has to bring something else.

The independence requirement sits on the references, not on the people. You may verify your own source. What makes a source hard to wave through is that three genuinely distinct pieces of corroborating evidence are hard to invent — not a rule about who is allowed to click.

If your reference is an external URL or a file, you will be prompted to add that material to the archive as a source in its own right. This is how the archive grows sideways: verifying one document tends to produce another.

The other path: a Brief

A Brief corroborates every source it cites. It is much heavier than writing a short note, and correspondingly more robust — and the relationship is two-way, so a source page shows which Briefs rest on it. See section 11.

05 The statuses

Every source carries one, everywhere it is cited.

StatusWhat it meansWhat changes it
UnsubmittedNothing has been established yetThe first note or confirmation
ReviewedOne note. A real state, not a waiting room — in a young archive it means somethingTwo more notes
✓ VerifiedThree argued notes with distinct referencesA contestation, or a note being contested
▣ AuthenticatedA primary source confirmed by three membersA contestation — but it never drops below this
⚑ In ReviewOne contestation is open. Visible immediately, not hiddenTwo more contesters, or defenders outnumbering them
⚑ ContestedThree or more contestersDefenders outnumbering contesters
DismissedA contestation was rejected; the source returns to what it was

The ratio of contesters to defenders is always visible — ⚑ 3 · ◈ 5 — so nobody has to take the status on faith.

06 Contestation

There is no moderator who decides whether a document is genuine. There is a procedure, it runs in public, and it has an explicit rule for how it ends.

Three kinds, for three different objects.

Contesting a whole source — CONT-

One contester moves the source to In Review at once. Three make it Contested. It resolves as Dismissed when defenders outnumber contesters — the contesters do not have to withdraw, and nobody has to concede. Only one whole-source contestation can be open at a time: someone with a different objection joins the existing one rather than starting a parallel fight. The uploader cannot contest their own source. Anyone can withdraw their position at any point, and the counts recalculate.

Contesting a single note — CONTN-

Only on non-primary sources: a primary source has nothing to argue about note by note. The contested note stops counting toward the threshold, so the source may drop a status — from Verified back to Reviewed, for instance. It resolves when a new valid note takes its place in the count, or when the contester withdraws.

The contested note is never removed. It stays visible as part of the record. Being shown to be wrong is history, not something to erase.

Contesting a graph connection — CONTG-

Same majority mechanism. A connection under contestation is drawn differently in the graph, and its panel links to the contestation. It does not reach back and reopen the proposal that created it: that proposal stays Merged. The history is frozen; the dispute is about the claim as it stands now.

What contestation is not for. It establishes whether a thing is what it claims to be. It is not a way to register disagreement with an interpretation — which is why Briefs cannot be contested at all.

07 Chambers and strands

Chambers are where the work happens. The archive and the graphs are where the results live.

A Chamber is a persistent community around a subject, divided into strands — threads of enquiry. A Chamber on the Cold War might carry strands for CIA & Covert Ops, the Nuclear Race, Proxy Wars, Propaganda. Every post, source and proposal can be attached to a strand, which is what keeps a busy Chamber navigable a year later.

Any member can open one and becomes its first moderator, and can invite others to moderate. Moderation is housekeeping — structure, strands, tidiness. Moderators do not decide what is true, and have no power in any contestation.

A source submitted inside a Chamber belongs to the whole platform immediately. Chambers produce; they do not own.

08 Proposing something to a graph

Nobody writes into the shared maps alone, and nobody needs permission from an authority. The gate is three people willing to put their reasoning on the record.

Inside a Chamber, you propose a node or a connection for one of the three graphs. You must write your case — why this connection exists — and attach the sources that support it.
The proposal appears in the Chamber's feed, in its Proposals tab, and in the Chamber's Map in progress, drawn as provisional so nobody mistakes it for established.
Other members endorse it, each attaching their own reasoning, or raise objections. What they must do to endorse depends on the kind of connection — see the next section.
At three endorsements the proposal becomes eligible for migration.
The proposer migrates it. Everything is created at once: the node, any new co-nodes, the connections. The proposal is marked Merged and the endorsers are notified.
Migration is irreversible. From then on the element is public, citable and contestable by anyone — and permanently linked back to the proposal, the sources and the case that produced it.

Nothing in the graphs is anonymous or unexplained. Click any node or connection and you can read who proposed it, on what evidence, with what argument, and who agreed.

Revising something already in the map

You do not edit it. You propose a new connection that supersedes the old one, and the old one remains queryable as history. In Pyramid this is explicit: every ownership stake is stated "as of" a date, and a slider moves the whole graph back in time.

09 Direct or structural

The least obvious choice on the platform, and the one that decides how much work your endorsers have to do.

When you propose a connection you must say which of the two it is. The question is simple: does the source state this connection, or do you infer it?

◆ Direct / self-evident

The source says it plainly. A contract naming both parties, a filing recording a transfer, a ruling stating a relationship.

Endorsers only confirm. They read the source, see the statement, and endorse. No note required — there is no inference to examine.

⬡ Structural

Control, influence, infiltration, parallel structure. The source supports it, but does not say it: you are drawing a conclusion from the evidence.

Every endorser must deposit a verification note setting out the inferential chain — the steps by which the evidence leads to the claim. Endorsing a structural connection is an argument, not a click.

The asymmetry is deliberate. Structural claims are where a graph can quietly fill with plausible-sounding assertions, so the cost of endorsing one is higher: three people must each write down, in public, exactly how they got there. If they cannot, the connection does not migrate.

Pyramid has no structural option at all. An ownership stake is either documented or it is not — "I believe they effectively control it" is a claim for Octopus, not a shareholding. Every Pyramid connection is direct by definition, which is why that graph holds the strictest evidence bar of the three.

10 The three graphs

Three maps of the same world. Choosing the right one is mostly a matter of which question you are answering.

⬢ Octopus — who is connected to whom

People, organisations, events, concepts and places, and the relationships between them. Node size grows with how connected a node is, and clusters form by theme. This is the graph for relationships that are not financial and not ownership.

⬡ Follow the Money — who gave what to whom

Directional and layered: position on the page means depth in the flow, not decoration. Amounts drive the width and opacity of each arrow. Dense groups collapse into a single clickable proxy, and path mode traces a chain between any two entities.

▲ Pyramid — who owns what, and how much

Ultimate owners at the top, operating companies at the bottom. Its distinctive capability is effective ownership: if X owns 50% of Y and Y owns 50% of Z, X effectively holds 25% of Z. With several paths and circular holdings this is not a multiplication but an algebraic problem, and the platform solves it — so selecting a company gives you the list of the real human beneficiaries at the end of the chain, with their computed stakes.

It also flags circular ownership as a finding in its own right rather than hiding it — in practice it is often the mechanism for diluting minority shareholders — and it tells you when the known stakes in a company add up to more than 100%.

All three share the same machinery: codes, citation, contestation of connections, the proposal pipeline, entity pages, search, embedding in Briefs, and a working sub-view inside every Chamber.

11 Briefs

Where a line of enquiry ends — for now.

A Brief is a short documented argument. The name carries both senses: a brief document, and a brief argued in front of a court. It is not an encyclopaedia entry and not a summary of everything known: it is a mini-thesis about connections found inside one strand.

Publication requires at least two contributors. That is structural, not decorative: a Brief is meant to be something more than one person's essay. Paragraphs carry per-author attribution, citations become footnotes automatically, and a Brief can embed graph connections inline, drawn in the visual language of their graph.

Briefs are not contested

They receive endorsements — a count, conferring nothing. If you disagree with a reading of the evidence, the answer is another reading: write your own Brief, or open a Chamber. Contestation is a procedure for documents, and an interpretation is not that kind of claim.

12 Grades, invites, contributions

A record of work done. Nothing more — grades confer no powers at all.

One currency: contributions. Building the graphs counts exactly like filling the archive — writing your case for a connection, or examining someone else's and putting your name behind it, is the same kind of work as submitting a document.

Withdrawing an endorsement takes the contribution back, and only your first objection on a given proposal counts. Otherwise endorsing and un-endorsing in a loop would be a way of earning nothing while appearing to work.

ActionCounts
Submitting a source1
Writing a verification note1
Opening or defending a contestation1
Proposing a node or a connection1
Endorsing a proposal1
Objecting to a proposal1
Joining a session1
Co-authoring a published Brief3
GradeAtGradeAt
Stranger0Notary150
Wanderer5Alderman300
Freeman20Councillor600
Journeyman60Chronicler1000

Your grade is invisible in the feed, on posts, and beside your verification notes. It appears only on your own page and in The Roll. This is a constraint we hold deliberately: a newcomer's well-referenced note has to be able to outweigh a veteran's assertion, and it cannot if the veteran's rank is printed next to it.

Invites

Three when you arrive, one more for every ten contributions, and one on first reaching Wanderer, Freeman, Notary, Alderman and Chronicler. Each code works once.

Who invited whom is recorded and shown on both pages. Inviting is an act with your name on it — and since there is no moderator to correct the community's drift, who gets in is the only real quality control the platform has.

That is the whole method. The rest is reading documents.

Visit as guest →