Skip to content
docs
Arxo ↗

Exercise 5. A guest pass for one missing from the registry

For LLMs2 sections

An exercise for the closed world page. On the page the accreditation registry is closed: for a known reader, a missing accreditation record becomes a negative fact.

Setup. Introduce a norm “a reader known to the archive but missing from the researcher registry needs a guest pass” and reach three answers on the pass question:

FactsAnswer
known reader, missing from the registryTRUE_ONLY
known reader, listed in the registryNEITHER
a person unknown to anyoneNEITHER

Hint. The first row cannot be reached without closure: nothing can establish not in_researcher_registry. What is the closure’s domain, and why is the third row not TRUE_ONLY?

Below is the solution. Try it yourself first.

Arxo Law
language "law.core" version "0.2";
package tutorial.archive version "0.4.1";
namespace "urn:law:tutorial:archive";
entity Person;
relation known_reader(p: Person) kind institutional;
relation in_researcher_registry(p: Person) kind institutional;
relation guest_pass_required(p: Person) kind institutional;

The researcher-registry closure. The domain is known readers: only about them may the archive say “missing from the registry, hence not listed”:

Arxo Law
closure ResearcherRegistryClosure {
predicate in_researcher_registry;
domain known_reader;
snapshot ARCHIVE_REGISTRY_2026;
complete_as_of @2026-03-01T00:00:00+00:00;
derive_explicit_negative true;
}
rule GuestPassRequired strict {
for p: Person;
when known_reader(p) and not in_researcher_registry(p);
then guest_pass_required(p);
}

The setup’s third row is the closure’s boundary. A person outside the domain gets no negative fact: the archive does not claim a random visitor is not a researcher; it simply knows nothing about her. So the norm stays silent instead of requiring a pass from everyone in a row.

The setup’s three rows plus a counterfactual: without the closure declaration the first row becomes NEITHER: with the closure cut out the question is asked again.

What the exercise teaches. A closure is declared on a predicate and bounded by a domain, two separate decisions. The first is which registry is declared complete; the second is exactly about whom. A domainless closure would turn every unknown person into “missing from the registry”, a claim the rules do not contain.

Documentation for Arxo. Writings — blog.arxo.io.

Anonymous visit counts on stats.arxo.io, no cookies.