diff --git a/CLAUDE.md b/CLAUDE.md index f878bc6..fc4fe84 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -442,7 +442,19 @@ queries exactly as it did. That is the safety argument and it is not negotiable. The table's order is load-bearing. Every comment on it argues a reason between two sources, and above all it carries "the owner's data first, then the world". Naming `SourceWorld` does not -send the turn outside. His notes, his facts and the personal boundary still run first. +send the turn outside on its own. His notes and his facts still run first, because +they look rather than guess. + +**The personal boundary is the one exception and it is deliberate.** It guesses, +so naming `SourceWorld` drops it. That is what stops it answering "кто такой +Линус Торвальдс?" with "не нашла у тебя такой записи", which it did on +2026-08-07. The cost is that a destination a model wrote can now take the +boundary off a turn. A question about him that the model calls `world` reaches +SearXNG, where today the boundary stops it. Only the utterance leaves the box, +never his notes or history, so this widens what is asked and not what is sent. +`TestNamingRecallKeepsTheBoundary` pins the other half: naming `SourceRecall` +keeps the boundary in front of the world. Whether a model may drop it at all is +the owner's call and has not been made. What comes out is only the sources that **guess**. Those decide a turn is theirs by cosine against frozen seeds, then answer whatever they claimed. They hold no table