# 01 — Concepts Index

Every distinct open-source idea in the corpus, with its canonical source and a verbatim quote. The classification column is the site's editorial spine:

- **[C]** — a widely-held view. Say it briefly and move on; the world does not need another restatement.
- **[P]** — a strong personal position. Argue it, and name the counter-case.
- **[O]** — an original argument. **These are the site.**

**Counts: 56 concepts — 24 [O], 22 [P], 10 [C].** That ratio is unusually good. Most of what you have written is not available elsewhere.

Paths are relative to `/root/SGraph-AI__App__Send/` unless marked otherwise. Word counts are the containing file's, measured with `wc -w`.

---

## The concepts

| ID | Name | Verbatim quote | Path | Date | File words | Maturity | Type |
|---|---|---|---|---|---|---|---|
| **OS1** | Sovereignty requires open source | "it is only when the code is open source that there is a possibility and the ability to have independence and sovereignty. Because if you suddenly get cut off from the service, at least you have a chance… That is why you have to have open source in order to have sovereignty." | `/root/SGraph-AI__App__Send/team/humans/dinis_cruz/briefs/06/13/open-source-and-sovereignty/v0.33.26__strategy-brief__sovereignty-requires-open-source-code-and-data-schemas-thesis.md` | 13 Jun 2026 | 1,749 | mature | **P** |
| **OS2** | Schemas matter as much as code; access ≠ control | "the data schemas are as important as the code. Sometimes you say the data is open, you have access to the data, but you do not have access to the code or the schemas. And by access I mean you need to be able to control it, to own it…" | same as OS1 | 13 Jun 2026 | 1,749 | mature | **O** |
| **OS3** | One SLA away from losing access | "without owning it you are dependent on service-level agreements, so you are one SLA away from losing access. And… whichever government has jurisdiction and control over the company that controls the code controls the other countries. It is literally that simple." | same as OS1 | 13 Jun 2026 | 1,749 | mature | **P** |
| **OS4** | Company nationality is not sovereignty | "who owns a company is already very fuzzy… especially with acquisitions you lose control. A European company gets acquired by a US company and the sovereignty moves, you lose it." | same as OS1 | 13 Jun 2026 | 1,749 | mature | **O** |
| **OS5** | The real issue is rent extraction, not innovation | "I do not buy that this will stifle innovation, because the work is there. It is a question of whether there is a rent-extraction process happening, which is what proprietary software provides." | same as OS1 | 13 Jun 2026 | 1,749 | mature | **P** |
| **OS6** | The success paradox: proven tech, broken economics | "open source is ridiculously successful yet underappreciated, it succeeded despite the opposition of nearly every major incumbent… its real weakness is the commercial and economic model rather than the technology" | `…/briefs/06/13/open-source-and-sovereignty/v0.33.26__research-brief__open-source-success-paradox-evidence-business-models-maintenance.md` | 13 Jun 2026 | 1,990 | mature | **P** (evidenced) |
| **OS7** | Open source is a strategy, not charity | "the power of open source is not for the community, it is not because it is nice for others, and it is not to give back." | `…/briefs/07/17/open-source-strategy/v0.33.49__strategy-brief__sg-send-open-source-as-strategy-not-charity-gen-ai-startups-no-tech-moat-lock-in-in-quality-and-certification-share-across-companies.md` | 17 Jul 2026 | 2,378 | mature | **O** |
| **OS8** | Technology is not the moat | "it allows for the removal of the idea that technology is the moat, more and more technology and software is not the moat, technology gets recreated, gets customised." | same as OS7 | 17 Jul 2026 | 2,378 | mature | **C→P** |
| **OS9** | Lock-in relocates to quality and certification | "the lock-in is not on the technology, the lock-in is in the quality and the services and the new versions and the maintainability and the certification of versions." | same as OS7 | 17 Jul 2026 | 2,378 | mature | **O** |
| **OS10** | Open source is a workflow, not a licence | "open source is so powerful, almost like a workflow that allows for much healthier companies." | same as OS7 | 17 Jul 2026 | 2,378 | developing | **O** |
| **OS11** | Portfolio sharing across parallel companies | "a lot of times you develop a lot of technology but you only end up commercialising a part of it, and this way all of that technology still continues to be available to the team." | same as OS7 | 17 Jul 2026 | 2,378 | developing | **O** |
| **OS12** | Everything open; the only line is at the customer | "my line is that everything the company does, the code, the logic, the functionality, and the schemas, is open source. There should be nothing proprietary. You never have the temptation of the bait model… because the community always sees through it" | `…/briefs/06/18/agentic-permissions/v0.33.40__strategy-brief__open-source-strategy-everything-open-line-at-the-customer-compete-on-value.md` | 18 Jun 2026 | 2,016 | mature | **P** |
| **OS13** | The customer boundary is the natural place for proprietary | "that becomes the natural place for proprietary… at that point it is the customer's data and their strategy. If the customer has an open-source strategy, great; if not, great, it is their decision." | same as OS12 | 18 Jun 2026 | 2,016 | mature | **O** |
| **OS14** | Rent extraction is a losing game | "As soon as you move into rent extraction, you lose sight of it: you are playing the game of making it less expensive to keep you than to leave, and then they leave with pain. I do not want us to fall into that." | same as OS12 | 18 Jun 2026 | 2,016 | mature | **P** |
| **OS15** | The value is adoption and stewardship | "even with zero contributions, being open dramatically simplifies the tech stack… If you are the creator and maintainer of the core technology, the core ideas, the core standards, there is crazy value, and that is where we want to play." | same as OS12 | 18 Jun 2026 | 2,016 | mature | **P** |
| **OS16** | Burden of proof on the sceptic | "I am yet to see evidence that open source is a deterrent to the business. All the evidence is that it is only a problem when companies shoot themselves in the foot." | same as OS12 | 18 Jun 2026 | 2,016 | mature | **P** |
| **OS17** | Open source is right even with zero contributions | "even if there are no contributions, no external people submitting code and patches, and there is a lot of AI slop now, with even open-source repos not accepting submissions because of the mess… open source is still the right strategy" | `…/briefs/06/04/nhi-2.0/v0.32.3__strategy-brief__sg-send-nhi-2.0-open-source-not-free-freedom-trust-moat.md` | 4 Jun 2026 | 3,646 | mature | **O** |
| **OS18** | Lock-in degrades *your own* architecture | "you introduce attrition, and by introducing attrition you create much worse architectures, because there is a lot of simplicity when you do not have copyrights, licensing, and restrictions." | same as OS17 | 4 Jun 2026 | 3,646 | mature | **O** |
| **OS19** | Open source frees you to cannibalise your own code | "it makes you more motivated, and with less false sense of ownership, to cannibalise your own code or remove code you had, because it is open source, the code does not particularly have value" | same as OS17 | 4 Jun 2026 | 3,646 | mature | **O** |
| **OS20** | Open source is not free — someone always pays | "It is not free to take a piece of open source and run it in your environment, because somebody is always paying for people… They will not fully understand it, and the more time they spend, the more it costs." | same as OS17 | 4 Jun 2026 | 3,646 | mature | **O** |
| **OS21** | The value-margin question | "there is a price point… where it is more cost-effective to pay the company who did it, or a company, to maintain it than to do it yourself. The question is, where is that value? That is literally the simple question." | same as OS17 | 4 Jun 2026 | 3,646 | mature | **P** |
| **OS22** | The 10% subset version | "a company might only need 10% of them. So we create a version with only 10% of the features. It has much less attack surface, it is much cheaper to run" | same as OS17 | 4 Jun 2026 | 3,646 | developing | **O** |
| **OS23** | Freedom, not free; the moat is trust | "open source is not free, somebody is always paying for it. What you get from open source is freedom, that is different… We play the game of empowering the user and being the reputable source of trust. We are selling trust." | same as OS17 | 4 Jun 2026 | 3,646 | mature | **P** |
| **OS24** | The rising tide / judo strategy | "you want to build a model where the better your competitors are, the better you become, and open source is the key element of that strategy." | `…/briefs/06/18/agentic-permissions/v0.33.40__strategy-brief__sg-send-rising-tide-strategy-better-competitors-better-us-open-source-the-need-wont-go-away.md` | 18 Jun 2026 | 1,702 | mature | **O** |
| **OS25** | Copyable code, uncopyable adoption | "Anyone competing closed-source can copy and re-implement and leverage the LLM capabilities, but they will not have the users and the adoption." | same as OS24 | 18 Jun 2026 | 1,702 | mature | **P** |
| **OS26** | The organic-food model for OSS funding | "Charity will not fix this. 'It is the right thing to do' will not fix this. The only thing that will fix this is market forces." | `…/briefs/03/29/v0.19.7__article__opensource-organic-food-model.md` | 29 Mar 2026 (path) | 1,074 | mature | **O** |
| **OS27** | Pay proportionally as a supply-chain cost | "Based on the value contribution, pay the open source projects you depend on. Not as charity. As a cost of doing business. The same way you pay for cloud infrastructure, for office space, for salaries." | same as OS26 | 29 Mar 2026 | 1,074 | mature | **O** |
| **OS28** | Paying is cheaper than not paying | "Here is the counterintuitive part: paying for open source is cheaper than not paying… They spend more money internally maintaining open source software than they would have spent supporting the project directly." | same as OS26 | 29 Mar 2026 | 1,074 | developing | **O** |
| **OS29** | The restaurant-health-rating label for OSS | "Just like a restaurant health rating on the door: you can still choose to eat at the restaurant with a bad rating. But you know." | same as OS26 | 29 Mar 2026 | 1,074 | developing | **O** |
| **OS30** | Survivability is a copyright/trademark property, not a licence property | "Survivable is not a property of the licence file. It is a property of the copyright and trademark structure." | `…/briefs/07/24/sovereignty-and-osmm/v0.33.51__arch-brief__sg-send-ontology-sovereignty-maturity-model-osmm-fractal-predicates-change-of-control-stress-test.md` | 24 Jul 2026 | 3,459 | mature | **O** (best in corpus) |
| **OS31** | The Change-of-Control Stress Test | "HashiCorp went BUSL, IBM acquired it, and the licence stayed." / "The stress test is a query, not an interview. 'Show me the CLA' and 'show me who holds the trademark' are answerable from public artefacts, and a vendor that cannot answer them has answered them." | same as OS30 | 24 Jul 2026 | 3,459 | mature | **O** |
| **OS32** | Fork capacity must be a named party | "'The community would fork it' with no named party" listed as the *failing* pattern; passing requires "A named party with the headcount and mandate to run the fork" | same as OS30 | 24 Jul 2026 | 3,459 | mature | **O** |
| **OS33** | Source-available is not open source | "REDCap is free to non-profits and source-available to licensees, but it is not open source… Open source, in the accepted sense, means freedom to use, study, modify, and redistribute for any purpose including commercial use" | `…/briefs/06/13/doctor-patient-and-comparisons/v0.33.26__research-brief__sg-send-redcap-comparison-research-data-capture-open-source-zero-knowledge.md` | 13 Jun 2026 | 1,925 | mature | **C** (precisely argued) |
| **OS34** | Sovereignty bounties: fund the exit, not the maintenance | "they should have projects that basically finance companies to develop and service open source technology and services that basically are able to move a customer from one closed source technology into the open source alternative." | `…/briefs/07/24/sovereignty-and-osmm/v0.33.51__strategy-brief__sg-send-sovereignty-bounties-grant-funded-migration-off-proprietary-platforms-survival-milestones-vendor-sponsored-proof-of-no-lock-in.md` | 24 Jul 2026 | 4,205 | mature | **O** (strongest single idea) |
| **OS35** | Bounty size as a published lock-in metric | "it's then market economics, like the more complicated is the bigger the bounty; it's sort of like a bounty system." | same as OS34 | 24 Jul 2026 | 4,205 | developing | **O** |
| **OS36** | Vendor-sponsored proof of no lock-in | a vendor funding "a documented, working exit path from its own product acquires a strong and checkable claim that it does not hold its customers by lock-in" | same as OS34 | 24 Jul 2026 | 4,205 | developing | **O** |
| **OS37** | Somebody has to be the villagers (NFR maintenance as a market) | "the sweet spot is to find the economic value where it's cheaper for these companies to pay a third party to maintain what I call the non-functional requirements, which fundamentally is the whole version control, reliability, resilience, security, backups, consistency, explainability, and documentation." | `…/briefs/07/31/markets-and-field-demo/v0.33.54__strategy-brief__sg-send-somebody-has-to-be-the-villagers-maintaining-non-functional-requirements-scarce-asset.md` | 31 Jul 2026 | 3,059 | mature | **O** |
| **OS38** | Code-reading is the appreciating scarce asset | "The scarce asset in this market is the ability to read and repair code somebody else wrote" — "Demand for a specific skill is rising sharply while the mechanism that produces that skill is being dismantled" | same as OS37 | 31 Jul 2026 | 3,059 | mature | **O** |
| **OS39** | Explorers are now everybody | "this market is going to grow exponentially because every single team, every single department, every single function, even professionals, are going to create tons and tons of apps." | same as OS37 | 31 Jul 2026 | 3,059 | mature | **P** |
| **OS40** | Maintainer sustainability: the commercial line is where package meets app | "the commercial line is where the package touches the target app." / "A consultancy can study the package. The maintainer **is** the package." | `…/briefs/05/11/v0.27.32__strategy-brief__package-manager-commercial-model.md` | 11 May 2026 | 2,781 | mature | **O** |
| **OS41** | No paywall on knowledge; the platform is what's missing | "It does not pull docs behind paywalls… That generosity is a core principle of open source and it stays." / "A solo maintainer publishing a Python package today has no realistic path to capture value from production users. The relationship is missing because the platform is missing." | same as OS40 | 11 May 2026 | 2,781 | mature | **O** |
| **OS42** | Signed Creative Commons (CC BY-S / MIT-S) | "**Licences are not optional.** Open source licences (GPL, MIT, Apache) and Creative Commons licences… have decades of legal precedent… What if we add a SIGNED requirement to the licence?… This is the legal stick that forces players to maintain provenance." | `…/briefs/02/23/part-4/v0.6.14__architecture__signed-creative-commons-legal-enforcement.md` | 24 Feb 2026 | 2,230 | developing | **O** |
| **OS43** | Open source karma / why I share | "I like that I live in a world where now it is all open source, I can share, I can talk about everything I do, I do not have to worry about intellectual property, NDAs, or secrets. It is a much more interesting and empowering world." | `…/briefs/06/16/theses-and-reflections/v0.33.38__strategy-brief__why-share-collaborate-pay-it-forward-open-source-karma.md` | 16 Jun 2026 | 980 | mature | **P** |
| **OS44** | Students know neither Git nor open source | "Neither student could explain what open source was. Not the philosophy. Not the licences… A student graduating in 2026 without understanding version control is like a student graduating in 1996 without understanding email." | `…/briefs/03/28/v0.19.7__article__education-gaps-git-opensource.md` | 28 Mar 2026 (path) | 943 | mature | **P** |
| **OS45** | Abstraction narrative has done damage | "I would argue that this narrative has caused more damage than people admit… Applications with 2,000 dependencies. CI pipelines that download half the internet… The answer was never 'stop abstracting.' The answer was 'someone still needs to understand what is underneath.' Linus Torvalds reads C code." | `…/briefs/03/21/v0.16.26__article__who-should-read-the-code.md` | 21 Mar 2026 (path) | 1,521 | mature | **P** |
| **OS46** | The moat is a rate, not a wall | "A competitor who forks our code today gets our position as of today. They do not get our velocity." / "The code is open source. The execution is not forkable." | `…/briefs/05/02/v0.27.5__article__moat-on-open-source-stack.md` | `date: 2026-05-09` (front matter) | 1,274 | mature | **P** |
| **OS47** | Empower consultancies as an open-source channel | "we should be empowering them, and because our platform is open source, they can integrate it, use it, and leverage it, and help grow the market" | `…/briefs/06/30/partners-market-and-library/v0.33.38__strategy-brief__sg-send-consulting-firms-partner-segment-empower-open-source-managed-service-dual-role.md` | 30 Jun 2026 | 1,370 | developing | **P** |
| **OS48** | They want to *use*, not *maintain* | "they want to be a user of this technology, they do not want to be maintaining it." | same as OS47 | 30 Jun 2026 | 1,370 | mature | **P** |
| **OS49** | 100% open-source sovereign cloud with API compatibility | "The proposed sovereign cloud must be **100% open-source** to ensure verifiability, security, and long-term sustainability, while simultaneously maintaining **full compatibility with major cloud APIs**." | `/root/docs.diniscruz.ai/docs/2025/02/24/an-open-source-sovereign-cloud-for-an-open-europe.md` | 2025/02/24 | 7,570 | mature | **P** (published) |
| **OS50** | Publish read keys, never write keys | "publishing read keys for public vaults is fine and is what publication already means, whereas a central list of vault keys would be a single artefact whose compromise hands over write access to everything" | `…/briefs/08/14/sgit-site-and-hub/v0.33.58__strategy-brief__sgit-topic-sections-catalogue-read-keys-yes-write-keys-never-frozen-vaults.md` | 14 Aug 2026 | 3,338 | mature | **O** |
| **OS51** | Publishing is irreversible: the frozen vault | "escrow the write key before publishing, not after. A vault published without its write key secured is a permanent, uncorrectable artefact" | same as OS50 | 14 Aug 2026 | 3,338 | mature | **O** |
| **OS52** | De-commoditisation: build the shield around the commodity | "the custom layer around the commodity grew large enough that the commodity stopped being the rational choice for that workload" | `…/briefs/05/17/v0.27.55__article__de-commoditising-the-commodity (1).md` | 17 May 2026 | 2,947 | mature | **O** |
| **OS53** | Torvalds vs Brooks's Law | "Linus Torvalds has challenged Brooks's Law on the grounds that open source is an observable counterexample, with the Linux kernel sustaining on the order of a thousand contributors and consistent growth." | `…/briefs/07/28/ways-of-working-and-market-position/v0.33.53__strategy-brief__sg-send-scaling-collaboration-coordination-tax-was-the-ceiling-agents-pay-it-bigger-teams-more-juniors.md` | 28 Jul 2026 | 3,910 | mature | **C** |
| **OS54** | The Permissions Bill of Materials (PBOM) | "you could argue this mapping is more important than the SBOM, because it should impact the SBOM" | `…/briefs/06/18/agentic-permissions/v0.33.40__arch-brief__permissions-bill-of-materials-augmenting-sbom-permissions-gate-exploitability.md` | 18 Jun 2026 | 1,712 | mature | **O** |
| **OS55** | Semantic OWASP: OWASP knowledge as an open graph | organisations "either use the broad standards as-is… or fork them into static custom guides, losing the benefit of OWASP's ongoing improvements" | `/root/docs.diniscruz.ai/docs/2025/04/02/semantic-owasp__leveraging-genai-and-graphs-to-customise-and-scale-security-knowledge.md` | 2025/04/02 | 8,891 | mature | **O** (published) |
| **OS56** | Wikipedia as the bottom-up model | "We see this in open projects like Wikipedia, where thousands of editors organically adjust categories and links" | `/root/docs.diniscruz.ai/docs/2025/03/29/from-top-down-to-organic-evolving-graphs-ontologies-and-taxonomies.md` | 2025/03/29 | 4,435 | developing | **C** |

---

## Reading order — five altitudes

The corpus is dense at the strategic layer and empty at the introductory one. A reader arriving cold has nowhere to start. Build the ladder in this order.

**Altitude 1 — What open source actually is.** Licence families, copyleft vs permissive, the OSD, source-available vs open source. **The corpus has almost none of this** — OS33 is the only precise statement, and it is good: *"Open source, in the accepted sense, means freedom to use, study, modify, and redistribute for any purpose including commercial use."* Everything else comes from `03__`. Keep it short and link out; the world has good introductions.

**Altitude 2 — Why it wins, and why the usual reasons are wrong.** `03__`'s findings. Unix as a compliance artefact, BSD's litigation cloud, Netscape's six-year near-failure, "eyeballs" as a non-property. This is where the site earns trust: it corrects the romantic story before making its own argument.

**Altitude 3 — The position.** OS7 (strategy not charity), OS23 (freedom not free), OS8/OS9 (technology is not the moat; lock-in relocates to quality and certification), OS12/OS13 (everything open, the line at the customer), OS24/OS25 (the rising tide; copyable code, uncopyable adoption), OS46 (the moat is a rate, not a wall).

**Altitude 4 — The structural arguments.** OS30/OS31/OS32 (survivability, the stress test, named fork capacity), OS1–OS5 (sovereignty), OS34–OS36 (bounties), OS26–OS29 (the organic-food model). **This is the centre of gravity** — four of the five original pages live here.

**Altitude 5 — The agent era.** OS37–OS39 (the villagers, code-reading as scarce asset), OS17–OS22 (not free, the value margin, the 10% subset), OS20/OS21. See `05__` — this is the least-written and most original layer.

---

## Three notes on using this table

**1. The [O] concepts cluster in two documents.** The 24 Jul OSMM/bounties pair (`sovereignty-and-osmm/`, 3,459 + 4,205 words) carries seven of them, and the 4 Jun `nhi-2.0` brief carries six. If time is short, those three files are two-thirds of the original material.

**2. Several concepts share one file.** OS1–OS5 are all the 13 Jun sovereignty brief; OS17–OS23 are all the 4 Jun `nhi-2.0` brief; OS26–OS29 are all the organic-food article. Do not build five thin pages from one document — build one strong page with five sections.

**3. Three documents are genuine essays and can go up nearly untouched.** `who-should-read-the-code` (21 Mar, 1,521 w), `opensource-organic-food-model` (29 Mar, 1,074 w), `education-gaps-git-opensource` (28 Mar, 943 w). Everything else in the corpus is written in the house brief style — em-dash-free, front-loaded with a 300-word abstract, third person about *"the project lead"* — and **the quotes are excellent while the connective tissue will need rewriting.** Budget for that; it is the single largest production cost in the build.

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
