Skip to content
docs
Arxo ↗

Advanced cheat sheet

For LLMs15 sections

The constructs beyond the cheat sheet: decision tables, presumptions and legal fictions, constraints, liberties and immunities, questions only a person can decide, competing readings of a text, procedures, stages, precedents, templates and units. As on the first page, every law block belongs to one package that compiles, and every section has a scenario that runs. At the end — an index of every construct of the language.

Open this package in the playground → — edit the rules and the scenarios of this page and run them in your browser.

Arxo Law
language "law.core" version "0.2";
package demo.parking.advanced version "0.1.0";
namespace "urn:law:demo:parking-advanced";
entity Applicant;
entity Office;
Arxo Law
decision LongTermDiscount(months: Integer) -> Decimal {
table hit unique {
when months >= 12 => 20 percent;
otherwise => 0 percent;
}
}

A decision maps inputs to an output by rows. hit unique means at most one row may match; otherwise is the row for everything else. The answer names the row that fired.

Arxo Law
relation applied_for_permit(a: Applicant) kind empirical;
relation good_standing(a: Applicant) kind institutional;
relation unpaid_fine_recorded(a: Applicant) kind institutional;
presumption GoodStanding(a: Applicant) {
when applied_for_permit(a);
presume good_standing(a);
unless unpaid_fine_recorded(a);
}
relation notice_posted(a: Applicant) kind empirical;
relation notice_received(a: Applicant) kind institutional;
fiction DeemedReceipt strict {
for a: Applicant;
when notice_posted(a);
deem notice_received(a);
}
FormUse it when the norm says
presumption … { presume …; unless …; }“is presumed … until …”: holds by default, evidence rebuts it
fiction … { deem …; }“is deemed …”: treated as true whatever the facts are
Arxo Law
relation permit_issued(a: Applicant) kind empirical;
relation fee_paid(a: Applicant) kind empirical;
constraint IssuedNeedsFee(a: Applicant) {
when permit_issued(a);
require fee_paid(a);
severity error;
message "a permit is issued only after the fee is paid";
}

A constraint derives nothing. It checks that decided facts fit together and reports a finding when they do not; a legal consequence of the breach needs its own rule.

Arxo Law
relation permit_refused(a: Applicant, o: Office) kind empirical;
relation objects(a: Applicant, o: Office) kind empirical;
relation permit_displayed(a: Applicant, o: Office) kind empirical;
relation vehicle_towed(o: Office, a: Applicant) kind institutional;
rule ObjectionRight strict {
for a: Applicant;
for o: Office;
when permit_refused(a, o);
then liberty MayObject {
holder a;
against o;
action objects(a, o);
window [@2026-03-01, @2026-03-31];
};
}
rule NoTowing strict {
for a: Applicant;
for o: Office;
when permit_displayed(a, o);
then immunity NoTowingWithPermit {
holder a;
against o;
protected_effect vehicle_towed(o, a);
window [@2026-01-01, @2026-12-31];
};
}
PositionSays
libertythe holder may do something; nobody can demand otherwise
immunitythe holder is shielded: the other side cannot bring this effect about

Together with duty, prohibition and power from the first page these are the five positions a norm can give.

Arxo Law
external judgment relation hardship(a: Applicant) {
authority HearingOfficer;
}
relation hardship_waiver(a: Applicant) kind institutional;
rule HardshipWaiver strict {
for a: Applicant;
when applied_for_permit(a) and hardship(a);
then hardship_waiver(a);
}

Some criteria (“undue hardship”, “reasonable”, “proportionate”) are decided by a named authority, not computed. Until the decision is supplied the answer is REQUIRES_JUDGMENT; once it is given as a fact with origin adjudicated, the rule fires.

Arxo Law
relation second_vehicle(a: Applicant) kind empirical;
relation second_permit(a: Applicant) kind institutional;
interpretation Narrow {
status reviewed;
rule NarrowReading strict {
for a: Applicant;
when second_vehicle(a);
then not second_permit(a);
}
}
interpretation Broad {
status reviewed;
rule BroadReading strict {
for a: Applicant;
when second_vehicle(a);
then second_permit(a);
}
}
interpretation_group SecondVehicle {
alternatives Narrow, Broad;
selection exactly_one;
}

When a text can be read two ways, each reading is an interpretation, and the group says how many may be in force. The case chooses one in its context (interpretation Broad;); the answer records which reading it rests on. Until a reading is chosen, every answer of the package carries the issue INTERPRETATION_REQUIRED — the open question is never hidden.

Arxo Law
event PermitApplied {
applicant: Applicant;
}
relation application_complete(a: Applicant) kind empirical;
procedure PermitProcess(a: Applicant) {
state Draft initial;
state Filed;
state Issued terminal;
transition File {
from Draft;
to Filed;
on PermitApplied;
when application_complete(a);
}
transition Issue {
from Filed;
to Issued;
}
}

A procedure is a state machine for one case: states, and transitions triggered by events and guarded by conditions. The question current_state(case, State) says where the case stands now and which attempts moved it.

Output
stage Reminders {
index round: Integer from 1 to 3;
bind reminder index 1;
}
Arxo Law
relation overdue() kind empirical;
relation reminder(i: Integer) kind institutional;
relation final_notice() kind institutional;
rule FirstReminder strict {
when overdue();
then reminder(1);
}
rule NextReminder(i: Integer) strict {
when supported(reminder(i)) and i < 3;
then reminder(i + 1);
}
rule FinalNotice strict {
when supported(reminder(3));
then final_notice();
}

A stage evaluates rounds in order: each round is closed before the next one reads it. Use it for anything that counts steps — reminders, rounds of a vote, an elimination tournament. A package with a stage cannot also hold a procedure (LDC-E4126), so the stage declaration above is shown, not compiled into this page’s package; the rules it orders are.

Arxo Law
relation lives_in_city(a: Applicant) kind empirical;
relation second_home(a: Applicant) kind empirical;
relation resident_for_permit(a: Applicant) kind institutional;
factors ResidencyLine {
for a: Applicant;
domain lives_in_city(a);
plaintiff lives_in_city;
defendant second_home;
courts HIGH; LOW;
}
rule SecondHomeNotResident strict {
for a: Applicant;
when second_home(a);
then not resident_for_permit(a);
}
precedent P1 of ResidencyLine {
court HIGH;
decided @2020-06-01;
plaintiff lives_in_city;
outcome resident_for_permit(a);
}

factors names the considerations a line of cases weighs for each side; a precedent records which factors a court found and what it held. A new case with the same factors follows the holding; a case with a factor the precedent did not have is distinguished, and the general rule answers.

Arxo Law
relation employed_in_city(a: Applicant) kind institutional;
relation worker_permit(a: Applicant) kind institutional;
expansion pair {
params { subject: binder; ground: relation(subject); result: relation(subject); }
exports { ok = self/ok; }
emit rule self/ok strict {
for subject; when ground(subject); then result(subject);
scope from self; effective from self; labels from self; source from self;
}
}
expand pair WorkerPermit {
label en unofficial "Workers in the city get a worker permit";
bind subject = a: Applicant;
ground = employed_in_city;
result = worker_permit;
}

An expansion is a rule template with parameters; expand fills it in. Use it when an act repeats one pattern for many subjects — the expanded rule is an ordinary rule with its own name in the answer.

Arxo Law
relation distance_to_zone(a: Applicant, d: Quantity) kind empirical { key(a); }
relation far_from_zone(a: Applicant) kind institutional;
rule FarFromZone strict {
for a: Applicant;
for d: Quantity;
when distance_to_zone(a, d) and d >= 2 km;
then far_from_zone(a);
}

Quantities carry their unit tag (3 km). Values in different units are never mixed silently: comparing 2500 m with 2 km reports DIMENSION_MISMATCH and the answer’s status is TYPE_ERROR; conversion is always explicit — convert(value, num, den, unit) with an exact factor. New units are declared with unit and derived unit.

Each section has a scenario; here is the first one. A scenario is written the same way as on the first page.

Arxo Law
test "a decision table" {
given {
context { legal_time @2026-03-01; decision_time @2026-03-01T09:00:00Z; knowledge_time @2026-03-01T09:00:00Z; timezone "UTC"; }
}
evaluate LongTermDiscount(12);
expect value == 0.2;
}
Terminal
law engine check advanced.law
law engine test tests/advanced.lawtest --program advanced.law

Expected output:

Output
check OK: advanced.law
Output
test PASS: a decision table
test PASS: a presumption holds by default
test PASS: evidence rebuts the presumption
test PASS: a fiction
test PASS: a constraint reports a breach
test PASS: liberty and immunity
test PASS: a judgment not yet given
test PASS: a judgment given
test PASS: the broad reading
test PASS: the narrow reading
test PASS: no reading chosen
test PASS: a procedure step
test PASS: rules that count steps
test PASS: the precedent is followed
test PASS: the precedent is distinguished
test PASS: an expanded template
test PASS: quantities in one unit compare
test PASS: different units are not mixed

Every construct of the language with a one-line description, the same text the editor shows on hover.

WordConstructWhat it does
actionAction with actorDeclares an event with a designated actor: an action someone performs, with typed fields.
alignFragment alignmentStates that two fragments in different languages correspond, with review status.
andConjunctionConjoins formulas: every conjunct must hold for the whole to hold.
asPremise aliasNames the unwrapped value of an if some premise: the binder the when-line reads.
assertAssertionAsserts one proposition as fact, with id, origin, validity window and evidence links.
calendarCalendar datasetDeclares a versioned calendar dataset binding: timezone, period and a content-addressed resource.
caseCase filePins one matter to decide: its evaluation context, named individuals and asserted facts with evidence.
classificationClassificationSupports a class by rule-like conditions: strict or defeasible strength.
closureClosed-world scopeBounds explicit negation: only inside predicate, domain and snapshot may absence become false.
collectComprehensionBuilds a set or list by filtering: collect bindings of a type where a formula holds.
constNamed constantBinds an immutable snapshot value to a name: numbers, money, or an individual via entity_ref.
constraintNon-derivational checkStates a mandatory relation between decided facts: when the antecedent holds, the requirement must hold too.
contextNamed context profilePins reusable evaluation axes under one versioned name: jurisdiction, time, resolvers and policies.
counterfactualWhat-if analysisAsks what minimal case change would flip a target: mutable and immutable inputs plus cost.
deadlineDeadline policyPins how calendar deadlines count: start day, end inclusion, rolling and cutoff.
decisionNamed pure decisionNames a pure query over evaluated legal state: one table or let* plus return, no norms or effects.
defeasibleDefeasible strengthA candidate consequence that a stronger opposite can defeat.
defeatDefeater headHeads a defeater rule: removes support for the named conclusion without asserting anything.
defeaterDefeater ruleBlocks a conclusion without supporting its complement.
definitionExact definitionDefines a concept by exact condition: the head holds exactly when the body holds.
derivedDerived unitDeclares a derived unit as a product and quotient of simple ones: it has no scale of its own.
editionSource editionPins one content-language-revision Expression of a source: language, officiality and lifecycle.
effectiveEffective windowBounds the rule to a legal-time interval: outside it the rule does not apply.
entityNominal entity typeDeclares a nominal type: identity is the pair (type, stable id); equal ids in two types never mix.
entrenchmentEntrenchmentShields one source passage over a time window: a locator plus its validity interval.
enumEnumerationDeclares a closed set of named members: the total vocabulary of one choice.
eventEvent declarationDesugars to an immutable nominal entity with id and typed fields; executable use wants one canonical time interval.
EventDomain eventDeclares an immutable nominal event subtype with typed intrinsic fields; identity is the stable id.
evidenceEvidence documentDeclares a case document: a stable id over a typed schema with provenance fields.
expandExpansion instanceInstantiates a named expansion: binds its parameters to local relations and values.
expansionExpansion definitionA closed generation profile: params plus emit rules that generate nodes with stable ids, labels and anchors.
exportsExport mapNames what an expansion publishes: local names for generated nodes.
factorsFactor dictionaryDeclares the closed factor vocabulary of one precedent line: signature, domain, sides and courts.
factsExported fact groupNamed unit for exporting facts across the package border; the body holds asserts only.
fictionLegal fictionDeems an institutional fact true when its conditions hold: the law treats it as decided.
fragmentSource fragmentPins one addressable passage inside an edition: kind, locator and fixed text.
functionPure functionReturns a data value, never a proposition; pure means no assertions, no norms, no ambient reads.
governsTemporal scopeScopes a rule to regulated-fact time on a named axis: support outside the window is not support.
ifConditional termChooses between two data terms on a boolean: if the condition holds, the first, else the second.
importDependency importDeclares a dependency once per package; only its pub symbols become reachable as pkg::Symbol.
integerInteger parameterAn expansion parameter holding a whole number: the threshold of an aggregate premise.
interpretationNamed readingGroups rules, priorities and definitions as one reading of a named document, with status and authority.
interpretation_groupReading alternativesGroups rival readings of one document with a selection policy: exactly one, any, or composed.
jurisdictionSource jurisdictionThe legal order a source belongs to, written as an institution identifier.
keyExpansion case keyNames the generated node after the case: key(c) is the case name.
keyKey declarationNames the arguments that identify a tuple or a generated node.
keyRelation keyDeclares the candidate key: one key projection identifies one tuple.
languageLanguage headerOpens every file: the language name and the exact version the file is written against.
listList aggregateCollects the outputs of all matching rows of a decision table into a list.
listList parameterAn expansion parameter holding a finite list of relation references.
mapTotal enum mapDeclares a closed total mapping from one enum to another: sugar over a pure function.
namespaceNamespace declarationURI from which declaration StableIds are built ({namespace}#{Name}); one package forms one tree.
optionOptional premise parameterAn expansion parameter for a premise that may be absent.
packagePackage declarationNames the package and pins the language version; every file belongs to exactly one package.
paramsExpansion paramsDeclares what an expansion instance must bind: binders, relations and value slots.
precedentPrecedent caseRecords one decided case as factor sets and an outcome under a named vocabulary.
presumptionPresumptionHolds a conclusion defeasibly until an exception fires: a rule, a defeater and a priority in one form.
priorityRule priorityOrders conflicting rules: prefer the winning application over the losing one, with an explicit reason.
procedureProcedure automatonDeclares a state automaton over one instance: named states plus the transitions between them.
propertyProperty checkStates what must hold over generated inputs: a forall domain plus a pure expectation.
publicationPublished filePins one published file of an edition: media type, retrieval address and content hash.
quantityDuration parameterAn expansion parameter holding the duration of a term, used in the date term of a deontic window.
queryQuery declarationA named computation over legal state that adds no support: local lets, then one return.
recordValue recordBundles typed fields under one name: the plain value object of the language.
referenceDynamic referenceDeclares a reference resolved at evaluation: source, locator, resolution axis and policy.
regionParallel regionDeclares one token-holding area of a parallel state: its own states and transitions.
relationRelationDeclares a named predicate: rules derive which of its tuples hold.
revisionRevision linkLinks editions into an immutable graph: what came before, what comes next, and why.
roleLegal roleIntroduces one LegalRole constant for an actor type, read through the has_role relation.
ruleInference ruleDerives a conclusion when its conditions hold.
scopeRule scopeRestricts when a rule applies: a formula kept separate for indexing and explanations.
setSet literal (reserved)Reserved word of the set literal; a set is built by a collect comprehension.
snapshotSnapshot functionDeclares an external function deterministic only against an exact snapshot hash, under a named capability.
somePresent optionPasses a present optional argument at an instance: some names the value the option carries.
sourceSource workDeclares the abstract Work behind an act: its kind, jurisdiction, authority and number.
stageReserved tour boundaryReserves a named node for round-based stratification: an empty body stays a loud boundary.
stateAutomaton stateNames one state of a procedure automaton: entry states are initial, sinks are terminal.
strictStrict strengthAn indefeasible consequence inside the chosen theory.
supportSupport edgeLinks one document to one proposition with a fixed relation: supports, refutes, authenticates, measures, reports or establishes.
temporal_resolution_policyDay-resolution policyPins how a Date becomes an Instant interval: one fixed offset and a day boundary.
termLegal term with casesWrites one legal deadline with a general rule and named special cases.
testExecutable testPins one executable check: given holds the case, evaluate asks the question, expect states the verdict.
textAmendment textThe new text an amendment operation puts at a locator.
textFragment textThe pinned official text of a fragment, in a named language and status.
thenRule headStates what the rule concludes: a literal or a norm template.
timezoneCalendar time zoneThe time zone of a calendar snapshot.
transitionAutomaton transitionMoves one procedure automaton from one state to another on an event, under a guard.
typeType aliasNames an existing type without nominal separation; transparency holds on both compiler stages.
unitUnit declarationDeclares a measurement unit: a simple atom carries exact scale and dimension, a derived unit multiplies simple ones.
UnitUnit tag surfaceThe declared name for measurement-unit tags: tags resolve in the unit registry, conversions stay explicit.
unlessRule exceptionAdds a defeasible exception to a rule: when it fires, the rule does not.
uriPublication addressThe canonical address of a publication of an edition.
useExplicit selectionSelects records explicitly: in a case, use names a snapshot alias and the records taken from it.
verificationVerification recordPins one external authenticity check of a case document: evidence, hash, verifier and outcome.
whenBody clauseConjoins the conditions a rule needs: literals, comparisons, calls.
whereFilter clauseFilters a comprehension or aggregate: only bindings satisfying the formula are collected.
withinAggregate windowBounds an event day to the instance window inside a count premise: day within window.

Documentation for Arxo. Writings — blog.arxo.io.

Anonymous visit counts on stats.arxo.io, no cookies.