When AI and physics simulation carry real consequences, capability is not enough; trust is the missing architecture. jBOK is the organization-neutral blueprint for earning, establishing, and keeping it through contracts, evidence, and accountable evolution — built on one conviction: make trust verifiable.
High-consequence decisions increasingly run through AI models and physics simulation. What's missing isn't capability — it's an architecture of trust: shared contracts that let independent organizations build interoperable capabilities, prove claims with evidence, and replace any component without unwinding the whole. Trust here has a lifecycle: earned through evidence, established by accountable accreditation, kept through monitoring and re-review — and revocable. jBOK is that architecture, kept deliberately free of every vendor, product, and use case so it can serve all of them.
Every capability sits behind the six versioned interface-contract families defined by ADR-0005. Five seed contract specifications are currently schema-backed with executed conformance tests; the security-contracts family remains reserved. Adaptable by Design: replaceability behind stable interfaces is the testable floor; governed adaptation within validity envelopes is the goal.
Model contracts classify every parameter's origin — down to hand tuning without an external anchor
and undischarged assumption
. Disclosure is legitimate; disguise is a contract violation. Absence of a declaration never reads as confidence (ADR-0006).
Accreditation is a use-specific decision by an identified authority, with recorded basis, conditions, and revocation triggers. Runtime assurance means monitoring plus an assured intervention path. Human authority boundaries stay explicit.
An RFC-style living document: versioned chapters, appendices, and specs; twelve architecture decision records (ADRs) guarding narrative and taxonomy, including ADR-0008 on watcher/recognizer placement; five review gates; 36 executed conformance tests in CI. External research is incorporated fully attributed and severable — replaceable as the field moves.
Use cases, products, and organizations reference the architecture. The architecture references none of them back. One implementation profile — JWM — is documented as evidence, and the book can never depend on it.
jBOK doesn't just describe architecture — it metabolizes implementation experience.
ADR-0006 (parameter provenance & completeness) was generalized from JWM's PROV-0 register — the profile is the origin of, and first conformance data point for, that contract language.
Principle evolution is governed by ADR-0007. Terminal values are durable, not frozen — mechanisms adapt continuously under evidence; the values themselves are revised only by human insight, deliberately, through an ADR.
JWM is a working single-developer implementation of this reference architecture: a trusted world-model harness with a DLMA structure (Distributed/Decoupled, Layered, Modular, Adaptive), four physics domains composing through one registry seam, evidence packets as end-user artifacts, validity envelopes, human authority boundaries, and PROV-0 parameter provenance. The evidence language in ADR-0006 was generalized from this profile.
The 2026-07-07 profile session documents a committed USD interop stage carrying physics schemas: five rigid bodies with PhysicsRigidBodyAPI and PhysicsMassAPI, colliders, a revolute joint, a gravity scene, and Z-up at 1 m/unit.
The stage opens cleanly through the Pixar reference implementation (usd-core), including a custom jwm:hash (fnv1a64) integrity attribute read back through that parser.
The same content renders as USDZ in Apple Quick Look at geometry level, by design.
A full headless Isaac Sim 6.0.1 session ran the stage: opened, physics-stepped, free bodies falling under gravity, provenance attributes read inside the running runtime. The stage NVIDIA's writer saved back was re-ingested at home and its jwm:hash integrity pin verified.
OpenUSD interoperability is verified end to end: the reference implementation, an independent render path, an Isaac Sim 6.0.1 runtime session, and the round trip through NVIDIA's writer with hash re-verification. One open item — revolute-joint rest-pose semantics under runtime solve — is recorded in the JWM implementation profile.