Federation

One site, or a hundred.

VALIS runs as many independent sites — one per team or location — that share a single converged picture across the links between them, however slow or unreliable those links are. Each site is a complete, self-sufficient VALIS that keeps working on its own. Together, they behave as one system.

Three sites, three separate databases, showing the same digest
Three sites, one digest — three separate databases, the same digest: the pictures are provably identical.
No single point of failure

Every site is authoritative for its own work. Lose one — even the primary — and the others carry on, undisturbed. There is no central server whose loss stops everything.

Built for a bad connection

Sites reconcile over reduced, intermittent bandwidth by exchanging only what has changed. The link is treated as precious: kilobytes settle what would otherwise be gigabytes.

The important work comes back first

On reconnection, the analyst’s live work — investigations, assessments, watchlists, tags and links — reconciles before bulk telemetry. Shared understanding returns in seconds, not after a full backfill.

A change arriving unprompted from another site
A change arrives — from another site. The analyst didn’t ask for it.

Proof, not “probably”

And you can prove it.

Every site computes a cryptographic digest of its entire workspace, from its own database. When two sites show the same digest, their pictures are not “probably in sync” — they are provably identical.

That is the difference between a claim and a proof. It is also the answer to the only question that matters when two sites disagree: who has the right picture?

Disconnected mode

Go dark for weeks. Rejoin without losing a thing.

A site can drop off the network entirely — for hours, days or weeks — and keep working the whole time. Its analysts carry on collecting, tagging and assessing against their own database.

When it comes back, VALIS reconciles the two divergent pictures with provably no data loss: nothing done while disconnected is overwritten or discarded, and where two sites edited the same thing, both versions are preserved for an analyst to judge rather than silently resolved.

The design goal, in one line. Losing a link degrades convenience, never data.

One control: the link is gone and the site keeps working
Go dark — one control. The link is gone, and the site keeps working.
With the link cut, the pictures diverge and the digests say so
Diverged — with the link cut, the pictures genuinely diverge, and the digests say so.
The disconnected site rejoins: nothing lost in either direction, and all three prove they match
Reconverged — the disconnected site rejoins. Nothing was lost, in either direction, and all three can prove they match.
Two analysts, one record, no lost work

Two analysts at different sites can assess the same entity at the same moment, neither aware of the other. Both assessments survive, everywhere. A last-write-wins system would have silently destroyed one of them — and nobody would ever have known. Where a genuine conflict occurs, VALIS converges on a deterministic answer and keeps the superseded assessment for a human to adjudicate.

Each site owns its own data

Every site holds its own store and shares only what it is entitled to share, workspace by workspace. Sites collaborate on the objects that matter without exposing everything — and a site can relay traffic on behalf of others that it is not itself cleared to read. Federation extends reach without widening trust.

Seven contacts, one link graph, three organisations, nobody coordinated
One link graph — seven contacts, three organisations. Nobody coordinated.