Skip to content
Browse by subject:
FORMAL THEOREM AND PROOF

Missing System Theory Proof

Standard bilateral economic analysis can show the gains and losses of the named parties to a transaction. It does not, by itself, carry the full system-welfare consequences of the transaction: the public-health baseline, ecological capacity, financial-system integrity, fiscal base, market trust, regulatory capacity, intergenerational burden, and other shared support systems affected by the decision. Missing System Theory formalizes that gap. A Hollow Win, denoted (0,1,1) for (C, A, B), is the resulting outcome: both private parties gain while the system they depend on degrades. The proof below states the conditions under which that third coordinate cannot be recovered from the parties’ payoff vector alone.

The full proof below is the flagship manuscript. The current public name is Missing System Theory. Supporting material — SAPM measurement (S1), the historical chronology (S2), and the extensions (S3) — is on the supporting-material page. Use this page to copy the proof into a referee, red-team, or blue-team review.

THEOREM IN THE CURRICULUMTHEOREM STATUSSUPPORTING MATERIAL (S1–S3)
Proof text
21,846 words
Source
MST flagship manuscript (2026-07-17)
Status
Formal core recomputation-verified
Use case
Referee review
REVIEW METHOD
Ask the model to find the flaw before asking whether the proof is persuasive. The useful first-pass screen is whether the axioms are stated, the deductive steps follow, the boundaries are visible, and the result is distinguishable from standard externality analysis.
REFEREE MAP
Use this map to inspect the proof quickly before reading the full text.
QuestionWhereWhat to check
Model§2The embedded game, payoff decomposition, welfare baseline, private Pareto frontier, and private-systemic tension.
Axioms and the bridge§3Axioms 1-3 and the strict form 3-s, Axiom 2′ (the payoff-level bridge axiom), Axiom 4, and the regularity conditions, with the dependency line stating which conclusion consumes which premise.
Witness and W-Independence§4Proposition 4.1, Counterexample 4.1 (interest non-inclusion without the witness), Corollary 4.1, the sixteen-bank benchmark witness (the real LIBOR rule: the highest four and lowest four submissions dropped, the middle eight averaged, a coalition occupying the middle), and the exposure-form boundary.
Taxonomy and W-blindness§5The eight-cell outcome taxonomy, its projection, Hollow Win versus Win-Win-Win, and W-blindness of payoff-space bargaining and solution concepts.
Core theorems§6-§7Theorem 7.1's integral argument, the full-hypothesis worked instance, the finite theorem, and consolidated Theorem 7.7 with its two tiers.
Prior economics§1, §3, References; Corollaries 17f and 17f.1 in Supplement S3Arrow, Myerson-Satterthwaite, Greenwald-Stiglitz, Pigou, Coase, Ostrom, Sen, and the boundary with ordinary externality analysis.
Empirical status§8; Supplement S1The seventeen-domain classification, four short cases, and the mixed return-side result: no-premium and restoration-event predictions survive; negative-skew and within-system-covariance predictions fail.
Falsification and design§9-§10Operational falsification conditions per premise, the game-change boundary, and W-aware design requirements.
R1–R3: three separate requirements
R1 — independent system-welfare monitoring channel
R1 answers the question: what is happening to the system? Measure that condition through a channel whose data-generating authority is outside the parties' payoff reports, and state the measured quantity's units and sign convention. Examples include benchmark-integrity data, lead levels in a water system, an emissions monitor, outage reliability, or an independently audited institutional-capacity measure. Each example qualifies as R1 only when its source, collection process, and audit authority are independent of the parties being evaluated. The record names the system boundary, period, uncertainty, and challenge path. A firm's own safety statement is evidence about the firm; it does not supply an independent R1 channel or automatically produce a released βW estimate.
R2 — pre-decision record
R2 answers a different question: where is the system consequence written before commitment? Put it in the same decision record as the parties' outcomes. Decision Accounting has 17 fields. Among its seventeen fields, Field 15 records ALTERNATIVES; Field 16 records a scoreable PREDICTION—metric, population, threshold or range, horizon, source, scoring date, uncertainty, and action; Field 17 — one of the seventeen — records SYSTEM WELFARE with its boundary, direction, units, sign convention, evidence, uncertainty, and time horizon. R2 makes the omitted coordinate inspectable and auditable. The record preserves what was decided and what can later be scored; it does not prove the prediction or change incentives by itself.
R3 — trajectory and crossover detection
R3 answers a third question: when would accumulated system loss catch up with private gain under the stated model? In the linear model, T* = δ/(ηλ). Read T* as a model-derived time horizon: divide the remaining private surplus δ by the annual system-loss rate λ after weighting the loss by the feedback fraction η. δ is initial private surplus in dollars; λ is the annual system-loss rate in dollars per year; η is the fraction of that loss that feeds back into the private payoff, with δ > 0, λ > 0, and 0 < η ≤ 1. T* is elapsed time in the same time units used for λ. If η = 0, the denominator is zero and this linear model has no finite crossover. Example (ILLUSTRATIVE): δ = amount pending re-estimation, λ = amount pending re-estimation/year, η = 0.5 gives T* = 10 years; η = 1 gives δ/λ. Resilience, decay, or a sudden shock requires the generalized equation in Supplement S1. T* is not a calendar date or a collapse guarantee.
17, 58, and 61 answer different questions
17 — theorem-paper domain set (evidentiary base)
The MST theorem paper works the single Missing System Theory across 17 industry domains: Defense Procurement & Sustainment; Pharmacy Benefit Management; For-Profit Higher Education; Generative AI & Model Collapse; Digital Surveillance & Misinformation; Food & Agriculture Systems; Infrastructure & Energy Deregulation; Sports & Anti-Doping; Insurance & Risk-Pooling Distortion; International Tax Arbitrage; International Trade Subsidies; Gig Economy & Labor Misclassification; Telecommunications & Spectrum; Cybersecurity Supply Chains; Nuclear/Energy Safety Margins; Legal/Judicial Exploitation; and Agricultural Monoculture Risk. In each, the classification judges the three axioms and scope conditions to hold jointly, based on documented regulatory findings, studies, or judicial records; it is an empirical classification, not a theorem about every instance in the category. These 17 are the theorem paper's own worked applications of one theory — not 17 separate theories; the program's individual domain papers each carry their own impossibility or intractability proof, counted separately (the 58- and 61-domain sets and the constraint-type split below). The number counts the theorem paper's domains — not papers, βW rows, or category labels — and does not certify every later application. Source: flagship §8; row-level evidence in Supplement S1, Table 12.B2.
Ranked measurement panel
The public ranked panel is defined by admitted βW rows. Each row carries an annual-revenue denominator `Π`, a welfare-loss estimate or interval, and a source path; βW is the matched-boundary ratio `ΔW / Π` (dollars of system-welfare change per dollar of annual revenue). Row values and the aggregate remain subject to numerical reconciliation and source admission.
61 — wider working-paper program
The wider working-paper program studies 61 domains: the 58 ranked rows plus WMD, Gene Drives, and Sovereign Debt. WMD has no commercial revenue denominator. Gene Drives is pre-revenue. Sovereign Debt has a reported matched-flow candidate under source and denominator review. These three entries answer a program-coverage question; none inherits ranked status until its own evidence and receipt clear.
READER FRAME

Read the proof as an impossibility result: define the space, state the axioms and the bridge axiom, show the coordinate the space omits, then show what follows when private gain and system welfare move against each other. Three supplements accompany the manuscript: S1 carries SAPM measurement and the empirical evidence base, S2 the historical chronology, and S3 the extensions, secondary propositions, and planner-measurability corollaries.

What the proof establishes
Tier 1 pairs the interpretive Axioms 1, 2, and 3-s with the bridge axiom, Axiom 2′: a payoff-level witness of two profiles with identical party payoffs and different system welfare. W-Independence — W is not a function of the parties' payoffs — follows from Axiom 2′; the interest-level Axioms 1–3 alone do not entail it, as the manuscript's Counterexample 4.1 shows. Tier 2 adds Axiom 4, Private-Systemic Tension, regularity, and frontier reachability; under those conditions, every privately Pareto-efficient endpoint has system welfare below the disagreement baseline. A Hollow Win is the resulting (0,1,1) outcome pattern when both private parties gain while the selected system loses. Tier 1 carries the information result; Tier 2 carries the stronger outcome result.
What full means
The proof does not claim that firms know nothing about system harm or that no external cost ever reaches private payoffs. Regulation, liability, engineering, disclosure, taxes, bargaining, reputation, insurance, and self-governance can price pieces of W. The claim is conditional on the bridge axiom: where two profiles carry identical party payoffs and different system welfare, the full system-welfare coordinate is not recoverable from payoff-space information alone without an independent W-channel. In plain terms, the witness is a controlled comparison inside one specified game: the same parties, the same stated system boundary, everything outside that boundary held fixed, and only the parties' own strategies differing. If the two profiles then carry identical payoffs while system welfare differs, the payoff reports do not identify W and an independent measurement channel is required. A welfare difference that an actor outside the boundary could have caused establishes no witness; it means the boundary is drawn wrong, and the repair is to redraw the boundary so that actor is a party and retest. βW is released only after that channel, the activity boundary, period, denominator, and source are recorded and challenged.
Historical placement
Arrow asks whether individual preferences can be aggregated into a social ranking. Myerson-Satterthwaite asks whether bilateral trade can satisfy efficiency, incentive compatibility, individual rationality, and budget balance at once. This proof asks a different question: whether the bilateral payoff space carries the system coordinate needed to distinguish a system-preserving outcome from a Hollow Win. The answer is conditional on the stated axioms and representation; it is not a claim that every bilateral transaction has an omitted system coordinate.
Relation to Pigou and Coase
Pigou assumes a measurable marginal social cost. Coase assumes parties can bargain over an externality when rights and transaction costs allow it. This proof identifies the residual case — the bridge-axiom case, where two profiles look identical in the parties' payoffs while system welfare differs — in which the full system-welfare cost is not recoverable from payoff-space information alone, so an independent W-channel is required before taxes, bargains, standards, or decision records can be calibrated. Section 8 documents an installed instance of such a channel: the CFTC's 2021 Dodd-Frank whistleblower award of nearly $200 million in the LIBOR case paid an insider a share of the collected sanction, making revelation of the hidden system coordinate privately optimal — a documented enforcement fact whose design reading (Section 10) is interpretive.
Relation to Greenwald-Stiglitz
Greenwald and Stiglitz prove constrained inefficiency from incomplete markets and imperfect information. Corollary 17f.1 (Supplement S3) states the MST separation: in Axiom 2′ domains — where the payoff-level bridge axiom supplies two profiles with identical party payoffs and different system welfare — a planner restricted to payoff-space information cannot compute the corrective that is indexed to system welfare and is needed to guarantee system preservation. The interest-level Axioms 1–3 alone do not supply that witness.
What remains open
Theorem 7.7 parts (a) and (b) are formal under their stated hypotheses; part (c) is conditional on its stated solution-concept scope. The manuscript names its open conjectures: measure-theoretic genericity of PST, exhaustiveness of the five-type diagnostic, closure under hybrid transformations, and the classification of mixed physical-institutional domains. Open execution items are the INSPIRE protocol run, independent verification of the return-side test, and the behavioral predictions. The SAPM domain estimates are measurement claims that carry their own stated statuses in Supplement S1.
Empirical status
The return-side public-data test is reported as mixed, carried as reported estimates at companion-paper vintage with independent verification pending. The normal-period premium prediction finds no unusual beta-W loading, while the restoration-event prediction finds positive loading after market, size/value/momentum, sin-industry, litigation-risk, and green-minus-brown controls, with a companion-paper within-firm event-study robustness check. The negative-skew and within-system-covariance predictions fail in the current run, so the evidence supports the narrower no-premium/legibility-event claim at this stage. The INSPIRE protocol execution is pending. Detail and data provenance are in Supplement S1.
NOTATION GUIDE BEFORE THE PROOF
The notation below is the minimum needed to read the proof tables without going back to the glossary.
Coordinates and outcomes
A, Bthe named private parties in a bilateral game
Cthe affected system: benchmark, commons, market, institution, public-health baseline, fiscal base, or ecological capacity
Wsystem welfare: the condition of C at a strategy profile
c, a, bbinary outcome coordinates; c tracks system preservation, a and b track the private parties
(0,1,1)Hollow Win: both private parties gain while the system loses
(1,1,1)Win-Win-Win: both private parties gain and the system is preserved
Payoff and theorem notation
uᵢpayoff to agent i
uᵢᴾprivate component of agent i's payoff
uᵢˢsystem-mediated component of agent i's payoff
σsigma — strategy profile
ddisagreement point
PP(Γ)Private Pareto frontier of game Γ (capital gamma)
PSTPrivate-Systemic Tension: private improvement along the frontier requires system loss
SAPM notation used in the tables
Πcapital pi — annual industry revenue, scoped to the same domain, time period, and activity boundary as W
βWbeta-W — curriculum average system beta: ΔW / Π (capital-delta W over capital pi), with matched activity, geography, period, and price-set boundaries. Supplement S1 distinguishes three beta objects — the marginal frontier slope, the annual average ΔW / Π, and the episode ratio; the table values are annual averages, association ratios that are never described as causal derivatives.
−dW/dΠseparate marginal expression: the change in system welfare associated with a change in revenue. The curriculum uses this marginal quantity separately from average βW.
μmu-star — efficient shadow price of system welfare; the proof's pricing relation must be read with its stated SAPM notation and assumptions
Tcrossover time: in the linear model δ/(ηλ) (δ delta, η eta, λ lambda), when accumulated system loss catches up with private gain; see R3 above
ΠSAcapital pi, S-A — system-adjusted payoff
𝒮Wscript capital S, W — System Efficiency Ratio: private payoff per unit of system-welfare cost

Formal foundations

Source manuscript proof
Source: Missing System Theory flagship manuscript, 2026-07-17 vintage (historical theorem title retained in the source record). This bundle carries the full manuscript: model and notation, the axioms and the bridge axiom, the witness results, the outcome taxonomy, the continuous and finite theorem chains, empirical scope, falsification conditions, the game-change boundary, and references. Supplements S1–S3 carry measurement, chronology, and extensions on the supporting-material page.
Status boundary
The manuscript states its own claim statuses: consolidated Theorem 7.7 parts (a) and (b) are formal under their stated hypotheses; part (c) is conditional on its stated solution-concept scope; the case classifications are empirical judgments; and the design schema is conjectural. The formal core has been verified by exact-rational recomputation, and two independent blind referee reviews returned pass verdicts. Measurement and calibration claims carry their stated statuses in Supplement S1; extensions and secondary propositions carry theirs in Supplement S3.
Notation used in the proof
σ strategy profile; σ* denotes a privately Pareto-efficient profile
d disagreement point — the no-deal baseline the proofs integrate from
W, W0 system welfare; W0 = W(d), the baseline at the disagreement point
c, a, b binary indicators: c = 1 if W ≥ W0; a, b = 1 if the respective party gained
δ private surplus
λ degradation rate
η feedback coupling
H planning horizon
T crossover time
(p, s, d) trajectory sign triple: signs of δ, of the gap g := W − W0, and of T − H (this d is distinct from the disagreement point above)
βW system beta: in the empirical tables, the annual average ΔW/Π — system-welfare loss per dollar of annual industry revenue, an association ratio, never a causal derivative; the marginal frontier slope −dW/dΠ is a separate construct (Supplement S1, Definition 14)
μ efficient shadow price of system welfare, μ = 1/βW
𝒮W System Efficiency Ratio: private payoff per unit of system-welfare cost
ΠSA system-adjusted payoff
VSAH system-adjusted present value over horizon H
Abstract · 336 words

Abstract

When can a system's welfare be recovered from the payoffs of the parties acting within it? We study parties embedded in a system—an institution, market, resource, or shared setting whose condition affects them—whose state is recorded by a system-welfare function, with each party's payoff split into a private return and a systemic component. The paper states the conditions under which system welfare is not recoverable from payoff-space information.

A bridge axiom posits two profiles with identical party payoffs and different system welfare. It is equivalent to the failure of a representation of welfare as a function of the payoff vector: system welfare is not a function of the parties' payoffs. We call this W-Independence. It concerns the information the payoff vector carries, not whether welfare is knowable through an independent channel.

A companion path result identifies when private efficiency forces system decline: when every admissible route from disagreement to the private Pareto frontier raises private payoffs while system welfare falls, and private-dominance, reachability, and regularity conditions hold, every privately efficient endpoint has system welfare below the disagreement baseline. Payoff-functional bargaining and mechanism solutions inherit the blindness, since their inputs cannot separate two system states that share a payoff vector. An outcome taxonomy separates Hollow Win, mutual payoff improvement with system decline, from Win-Win-Win. The identification and path results are formal under their hypotheses; the domain classifications are empirical and the design schema conjectural. Applications state the system boundary and the status of each claim.

Keywords: impossibility theorem, system welfare, W-Independence, Missing System Theory, Hollow Win, private-systemic tension, bargaining theory, outcome taxonomy, Pareto efficiency, value-redirecting games, institutional design, commons governance

JEL Classification: C70, C78, D62, D82, H41, Q58

Highlights.

W-Independence: an exact witness makes W unrecoverable from payoffs.
Under pathwise tension, every reachable private optimum lowers system welfare.
Hollow Win and Win-Win-Win share a projected cell; the W coordinate splits them.
Under the bridge axiom, payoff-space bargaining and mechanism rules are W-blind.
System-aware design: independent W measurement, decomposition, trajectory tests.
1. Introduction: the problem in plain language · 1,303 words

1. Introduction: the problem in plain language

Negotiation and cooperative theory evaluate an agreement by whether it improves the position of each party. That test is necessary for a deal between the parties. It is incomplete when the deal takes place inside a market, institution, benchmark, ecosystem, or commons that the same action producing the private gain can also damage. The paper asks a prior, informational question: when two agreements look identical in the parties' payoffs, can a rule that sees only those payoffs tell whether the shared system is better or worse under one than the other?

Consider the banks that set an interbank benchmark. Each day up to sixteen banks submit a rate estimate; the highest four and lowest four submissions are discarded and the middle eight are averaged to set the published rate. A coalition of submitting banks large enough to occupy the surviving middle can shift that rate, and each bank’s trading books gain from the shift. The banks’ reported returns can look identical across two cases: one case affects a small local reference rate, and the other affects a benchmark embedded in contracts across the financial system. The parties’ payoff reports can match while the system-level consequences differ. A payoff score records the gains; it does not record the integrity or reach of the benchmark.

The same structure appears in other settings. A manufacturer can reduce the cost of emissions control while preserving the appearance of compliance. Competing landlords can adopt a common pricing system and raise rents without speaking to one another. Agents can optimize a private revenue target while degrading the market, resource, or infrastructure that makes the target meaningful. These cases have different facts. Their common feature is the possibility that private improvement is funded by a loss borne by the system in which the parties operate.

The paper asks three questions. First, when can the system’s welfare be recovered from the parties’ payoffs? Second, under what path conditions does private efficiency force system decline? Third, what information and institutional changes can make system preservation part of the decision problem?

The first answer is a characterization. If two profiles have identical party payoffs and different system welfare, then no function of the payoff vector identifies system welfare: a representation of welfare as a function of the payoffs does not exist. The paper names this W-Independence and states the payoff-level witness as a bridge axiom. The witness is a domain claim—an assertion about two profiles in a specified application—that can be exhibited or failed by observation. The bridge axiom is the formal version of that claim: it requires equal party payoffs and unequal system welfare.

The second answer is a path theorem. A privately Pareto-efficient endpoint is reachable from disagreement through paths along which every private payoff is nondecreasing and at least one improves. If system welfare has a strictly negative pathwise derivative—the welfare measure falls at almost every instant along the route—on every such path, local losses integrate to a strict endpoint loss. The continuous theorem requires private dominance, meaning that every endpoint under consideration weakly improves every party's private payoff over disagreement with at least one strict gain; reachability, meaning that the endpoint can be produced by the permitted route; and regularity, meaning that accumulated local changes determine the endpoint change. A separate finite theorem uses an improvement chain—a finite sequence of permitted private improvements—and a telescoping sum—a sum in which intermediate welfare terms cancel.

The third answer is a design boundary. A mechanism whose inputs remain in payoff space cannot infer the missing system coordinate. System-aware design therefore adds a channel that measures system welfare independently of party reports. Decomposed reporting makes private gain and systemic exposure visible as separate quantities. A trajectory monitor tests whether a current private gain is sustained by a declining system state. Independent W-monitoring is necessary, within the stated mechanism class, for any rule that conditions selection on system preservation: a payoff-only mechanism cannot compute or verify the system indicator (under a witness pair straddling the W0 threshold, exhibited in Supplement S3), and any privately efficient outcome it selects is system-degrading under the path hypotheses — a conditional result whose proof travels with the mechanism extensions in Supplement S3; decomposed reporting and trajectory detection are requirements of the proposed dashboard architecture. Together they motivate a transformed game—a version with changed information, incentives, or feasible actions—in which system preservation can become privately attainable.

The paper’s contribution is a formal separation between the payoff-space question and the system-state question, followed by a conditional theorem connecting private efficiency to welfare decline. The result is comparable in architecture to impossibility results in social choice, welfare economics, and mechanism design (Arrow, 1951; Sen, 1970; Gibbard, 1973; Satterthwaite, 1975; Kaplow and Shavell, 2001), while addressing recoverability of a system coordinate from agent-level payoff data. It identifies the hypotheses under which the conclusion follows and supplies tests for each hypothesis.

The paper sits beside several established literatures. Bargaining theory specifies how parties select a point from a feasible payoff set (Nash, 1950; Rubinstein, 1982). Cooperative game theory assigns value to coalitions from a characteristic function, a record of what each coalition can obtain (Shapley, 1953). Mechanism design studies what can be implemented from reported information and incentives (Hurwicz, 1960, 1972; Vickrey, 1961; Myerson and Satterthwaite, 1983; Maskin, 1999). Commons theory studies the relationship between private extraction and a shared stock (Gordon, 1954; Hardin, 1968; Ostrom, 1990). The present framework supplies a common coordinate for cases in which the shared stock, institutional integrity, or ecological condition is absent from the observed payoff map. Its question is informational before it is procedural: what can a rule infer when two profiles look identical in the data available to the rule?

That question gives the paper a precise boundary with ordinary externality analysis (Pigou, 1920; Greenwald and Stiglitz, 1986). An externality can enter an agent’s payoff if the analyst observes the relevant component or has a complete social objective. The present result concerns the residual case in which system welfare is defined on the embedded game and the observed signal has a fiber—profiles that look the same to the rule—on which welfare differs. The problem then persists even when the parties’ total payoffs are observed without error. More data of the same payoff type do not supply the missing coordinate; the data must contain an independent measurement or an intervention that changes the game.

The information layer establishes W-Independence from a witness. The path layer establishes a strict welfare inequality from a derivative sign and reachability. They interact when a mechanism selects a private frontier without seeing its system consequence.

Section 2 defines the embedded game, payoff decomposition, welfare baseline, private Pareto frontier, and private-systemic tension. Section 3 states the axioms, the bridge axiom, and the regularity conditions. Section 4 gives the information characterization, the interest-level counterexample, the benchmark witness, and the exposure-form boundary. Section 5 defines the eight-cell taxonomy and its projection. Section 6 proves the continuous theorem chain and gives the full-hypothesis worked instance. Section 7 gives the finite theorem and scopes extensions. Section 8 summarizes the empirical domain classification and four cases. Section 9 gives operational falsification conditions. Section 10 states the game-change boundary and design requirements. Section 11 records limitations and concludes. Theorem labels follow the program’s global numbering: the continuous chain carries 7.x labels (Section 6) and the finite chain carries 8.x (Section 7). The historical chronology belongs to Supplement S2; expanded measurement and empirical protocols belong to S1; extensions and secondary conjectures belong to S3. The supplements are companion documents to this manuscript; every theorem stated in the main text is proved here—with one flagged exception, the design section’s independent-monitoring necessity claim, whose proof travels with the mechanism extensions in Supplement S3—and supplement pointers otherwise carry extensions, protocols, and measurement material only.

2. Model and notation · 1,327 words

2. Model and notation

The paper studies an embedded game

\[ Γ=(N,(Σi)i∈ N,(ui^P)i∈ N,(ui^s)i∈ N,C,W,d). \]

Here N=\{1,…,n\}, with n≥ 2, is the set of agents; Σi is agent i’s strategy set; and Σ=∏i∈ NΣi is the strategy-profile space. The profile σ∈Σ specifies the strategies used by all agents. C is the institutional, environmental, or contextual system in which the agents interact. Each agent has an interest set Ii (read “I sub i”), the system outcomes that matter to that agent, and the context has IC (read “I sub C”), the outcomes that matter to the system as a whole. C is modeled as the embedding context, not as an additional player.

Each agent’s payoff is decomposed as

\[ ui(σ)=ui^P(σ)+ui^s(σ), \]

where ui^P is the private component and ui^s is the systemic component. The private component records returns attributable to the agent’s direct action, such as compensation or immediate trading gain. The systemic component records returns mediated through the condition of the shared system, such as institutional continuity, professional standing, or continued access to the system. The additive form is a modeling choice that keeps the private and systemic channels visible.

System welfare is a function W:Σ→ R, where R denotes the real numbers—ordinary numerical values. The disagreement point d∈Σ is the default outcome when no agreement is reached, and

\[ W0:=W(d) \]

is the welfare baseline. W has no lower bound in the model. The classification compares a profile with W0; it does not assume a lower limit for welfare.

Under an unbounded-degradation specification—a model in which W falls without a lower limit and the permitted path family reaches profiles with arbitrarily low W—a path can drive W arbitrarily low. A finite-crossing claim asks whether a chosen welfare level is reached in a finite amount of path or calendar time; a first-passage claim identifies the first point at which that level is reached. Each requires separate hypotheses: the chosen level must lie in the range the permitted paths reach, and only claims about arbitrarily low levels need the unbounded-degradation specification. The qualitative theorem needs only the comparison with W_0.

The private Pareto frontier is

\[ PP(Γ)=\{σ∈Σ:σ'∈Σ with ui^P(σ')≥ ui^P(σ)∀ i, and strict inequality for some i\}. \]

The frontier concerns private components. It is not defined by total payoffs or by W. The underlying efficiency notion is standard Pareto efficiency (Mas-Colell, Whinston, and Green, 1995), applied here to the private components only.

For continuous analysis, an admissible path from d to σ^* is a piecewise C^1 path γ:[0,1]→Σ, meaning a path that is continuously differentiable on finitely many segments. It stays in the private-improvement region, the profiles every party weakly privately prefers to disagreement:

\[ F(d)=\{σ:ui^P(σ)≥ ui^P(d)∀ i\}. \]

It starts at d, ends at σ^*, has locally Lipschitz private-payoff compositions, meaning each composition changes at a bounded rate on a small neighborhood, and satisfies, for almost every s∈[0,1]:

\[ {d}{ds}ui^P(γ(s))≥ 0∀ i, {d}{ds}uj^P(γ(s))>0 at least one j (which may vary with s). \]

The opening quantifier governs both derivative clauses—a piecewise C^1 path has a derivative only almost everywhere, so neither clause is imposed at literally every s. Here “almost everywhere” means at every path point except possibly a set of measure zero. These requirements rule out jumps and pathological movement so that accumulated local changes can be compared with the endpoint change; the reader only needs to verify that the stated route belongs to this admissible class.

Continuous private-systemic tension, abbreviated PST and written PST-c for the strict form, requires the composite W∘γ to be differentiable almost everywhere, with

\[ {d}{ds}W(γ(s))<0 everywhere \]

on every admissible path from d to every privately efficient endpoint. PST-w (read “P-S-T weak”) is the weak form and replaces the strict inequality with ≤ 0. In the worked instance, the first derivative clause checks weak private monotonicity for both agents and the second checks strict improvement for at least one agent; these clauses only identify the local conditions being checked. The finite analogue uses a transition relation on profiles, a private-improvement step, and a finite improvement chain. The continuous and finite forms are separate objects.

The proof objects are separate from the empirical measurement program. The annual-revenue beta quantities—averages βW=Δ W/Π, where Δ W is the realized system-welfare loss over the measurement year, taken positive when welfare declines, and Π is annual industry revenue, never profit; not return-side factor loadings and not causal derivatives—together with their units and calibration conventions are defined in Supplement S1; they are not premises of either theorem.

The profile space may be continuous, finite, or a product containing both kinds of coordinates. For the continuous analysis, the path-carrying coordinates are taken to lie in a subset of a finite-dimensional real space, so that piecewise C^1 paths and pathwise derivatives are defined. The continuous result requires paths with enough regularity for the fundamental theorem of calculus along an admissible trajectory. The finite result requires a relation that identifies which transitions the protocol permits. A finite profile set alone does not guarantee reachability: a protocol may omit a payoff-improving edge even when the endpoint exists. The transition relation is therefore part of the finite game.

The private frontier is protocol-relative. If a mechanism restricts the feasible set, it changes Σ and may change PP(Γ). If a monitoring rule adds a signal without changing strategies or payoffs, it changes the information available to a decision rule while leaving the original frontier intact. If a liability rule changes ui^P or ui^s, it changes the game itself. The game-change section uses this distinction when it evaluates proposed repairs.

When W is differentiable, the gradient is the vector of local welfare changes in all strategy directions; the ambient strategy space is the full space of those directions. The next paragraph explains why the theorem follows the chosen path instead of using that full-space vector.

For a path γ, the relevant derivative is the derivative of the composite W∘γ, not a norm of the gradient of W in the ambient strategy space. The path can travel in a direction orthogonal to a large gradient, and a gradient-norm bound alone gives no sign for the welfare change. The theorem therefore quantifies over the path family and places the sign condition directly on d(W∘γ)/ds. This is the analytic reason Condition 2 and the definition of admissibility appear together.

The baseline convention treats ties as wins in the binary indicators used later. Strict inequalities belong to the theorem and to the definition of strict path tension. That separation avoids a change of label when a private payoff equals its disagreement value, while preserving the strict endpoint conclusion generated by a strictly negative path derivative.

Interest sets are interpretive objects attached to the parties and the embedding context. They organize the scope statements in the axioms; they do not enter the fiber proof unless the model adds a functional link from interests to payoffs. This is why interest-level non-inclusion and payoff-level non-recoverability are stated separately. An application can document an interest that no party holds completely and still fail to produce Axiom 2′ if the payoff map happens to encode W.

The model also distinguishes a profile from its payoff image. Two profiles can differ in strategy, information, contract reach, physical exposure, or institutional effect while mapping to one payoff vector. The theorem uses this many-to-one possibility. A mechanism that observes the profile itself, a verified state variable, or a richer history may have a different signal and must be analyzed under that signal. The payoff vector is one observation map, not the whole game.

The disagreement profile is a reference point, not necessarily a Nash outcome or an observed historical state. It can describe failed bargaining, a regulatory default, a pre-reform protocol, or a status quo. The theorem compares the frontier with this specified reference. Changing d changes W0, F(d), Axiom 4, and the admissible path family; such a change is part of the application’s counterfactual design.

3. Axioms and exact scope · 1,994 words

3. Axioms and exact scope

The model uses a status convention. Definitions and algebraic propositions are formal within their stated objects. Conditions tied to a domain, observation environment, or institutional interpretation are conditional or empirical. Examples and positioning claims are illustrative. Conjectures and open questions retain those labels at their point of use.

Axiom 1: overlapping interests

In words, each agent’s interest set shares at least one system concern with the context’s interest set.

Every agent is embedded in the system:

\[ Ii∩ IC≠ every i∈ N. \]

This is an interpretive scope premise. It identifies the agents as participants whose interests overlap the system’s condition. The formal results do not infer the overlap from observed behavior.

Axiom 2: system independence

In words, the context has at least one concern that is absent from the combined agent interest sets.

The system interest is not contained in the union of agent interests:

\[ ICi∈ NI_i. \]

This is an empirical domain premise. Market integrity, institutional continuity, and ecological stability are candidate system interests. Axiom 2 does not say that agents have no information about these conditions. It sets the boundary at which a system state may contain information absent from the payoff vector.

Axiom 3: systemic dependence

The implication below reads: whenever one profile has at least as much system welfare as another, every agent’s systemic payoff is at least as high. The strict form adds a strict increase for every agent when system welfare strictly increases.

The weak form, called Axiom 3-w below, requires

\[ W(σ)≥ W(σ') ui^s(σ)≥ ui^s(σ') ∀ i. \]

The strict form, Axiom 3-s, adds

\[ W(σ)>W(σ') ui^s(σ)>ui^s(σ') ∀ i. \]

The factored form ui^s=fi∘ W, with fi strictly increasing, says that each systemic payoff is obtained by applying an increasing conversion rule to W; it is equivalent to Axiom 3-s on the range of W. Weak hypotheses license weak conclusions. Strict agent-level conclusions cite the strict form.

The distinction between the weak and strict forms changes the permitted conclusions. Under Axiom 3-w, a welfare loss can leave an agent’s systemic component unchanged. A path can then decrease W while preserving one agent’s total payoff component, and a cell-level statement about a complete winner requires additional information. Under Axiom 3-s, any strict welfare ordering is transmitted strictly through every systemic component. The path theorem does not need Axiom 3-s for the calculus inequality when PST-c is stated directly, but the taxonomy’s interpretation of a system loss as an agent-level systemic loss uses strict dependence. The consolidated theorem retains the stronger axiom for the interpretive tier.

The factorized representation is a sufficient structural form for the strict axiom and gives a convenient identification case. If each systemic component is a strictly increasing function of the same W, observing one decomposed systemic component identifies W on the range of that function. The benchmark witness is designed outside that aggregate case: an agent’s exposure is common across the witness profiles while W contains a component not carried by the exposure. The two constructions answer different questions and should not be combined in an empirical test.

Axiom 2′ (Payoff-Level System Independence — Bridge Axiom)

Axiom 2′ is the payoff-level premise consumed by the witness results:

\[ {∃σ',σ''∈Σ: ui(σ')=ui(σ'')∀ i∈ N, W(σ')≠ W(σ'').} \]

This is a formal bridge axiom and an empirical premise when applied to a domain. Axiom 2 is an interest-level statement. It motivates the bridge; it does not entail it in the unstructured model of interest sets. The benchmark construction in Section 4 exhibits the witness. Theorem 7.7(a) and (c) cite Axiom 2′ explicitly.

Private dominance and regularity

Axiom 4 requires that every σ^∈ PP(Γ) weakly privately dominates d, with a strict private gain for at least one agent. Say a profile σ^ satisfies the dominance clause of Axiom 4 when it weakly privately dominates d with a strict private gain for at least one agent; Axiom 4 itself is the game-level statement that every privately efficient profile satisfies the clause, and later conditions cite the clause when they quantify over individual profiles. Condition 2 (Regularity) requires W to be locally Lipschitz on F(d); the canonical form of this condition also assumes F(d) compact, an assumption the supplements’ quantitative results use but this paper’s proofs do not need, because an admissible path’s compact image carries the Lipschitz argument. Condition 1—a distributional premise requiring full support of the outcome distribution—is used only by the information-theoretic results in Supplement S3 and does not appear here. Condition 3 requires every privately efficient profile satisfying the dominance clause of Axiom 4 to be reachable from d by an admissible path. The finite form of Condition 3 requires an improvement chain.

The regularity condition is analytic. An admissible path has a compact image, and a locally Lipschitz function is Lipschitz on that image. Local Lipschitz continuity therefore makes W∘γ absolutely continuous along admissible paths, meaning that the path has no hidden jump contribution and its endpoint difference equals the integral of the pathwise derivative. A gradient norm alone does not determine the sign of a derivative along a path.

Axiom 4 selects the endpoints to which the path theorem can apply. Private Pareto efficiency by itself allows an endpoint that makes one party worse off than disagreement. Axiom 4 restricts attention to frontier points that weakly improve every private component and strictly improve at least one. The strict clause excludes the disagreement profile as a frontier endpoint when no party gains. In applications, this is the difference between an efficient point that parties could rationally accept from the baseline and an efficient point that is efficient only because a private tradeoff has exhausted one party’s gain.

Condition 3 is stated for every endpoint satisfying the dominance clause of Axiom 4, rather than for one selected bargain. This universal scope matters when the frontier has multiple components or when the institution can choose among several privately efficient outcomes. If an application analyzes only the observed endpoint, it can report a local version of the theorem conditional on that endpoint’s reachability and on PST along its path. The flagship theorem retains the universal form.

Condition 2 also prevents a change in the endpoint value from being hidden in a singular component that the almost-everywhere derivative does not see. If W∘γ is absolutely continuous, then

\[ W(γ(1))-W(γ(0))=∫_01{d}{ds}W(γ(s))ds. \]

With a strictly negative integrand almost everywhere, the integral is strictly negative. The weak condition gives a nonpositive integral. If the path has jumps or a singular part, the proof needs a bounded-variation formulation and an explicit sign restriction on that part; those quantitative variants are assigned to Supplement S1 or S3 according to their measurement role.

For a concrete route, imagine a two-party path on which both private payoffs rise smoothly from their disagreement values while W falls at every instant. The integral adds those small local welfare losses and gives the endpoint loss; this is the mechanism used by Theorem 7.1.

Condition 3 is a reachability premise rather than a consequence of compactness. A compact feasible set can have disconnected components. A privately efficient point can dominate disagreement and remain unavailable to every continuous monotone path. The theorem consequently quantifies only over endpoints for which the admissible path exists. In a protocol, reachability means that the institution can actually produce the sequence of private improvements encoded by the formal path. A candidate frontier identified from payoff data without a path audit cannot support the conclusion.

Axiom independence

The core axioms are logically independent over the basic model ingredients: interest sets, payoff functions, and maps from profiles to observed signals. A finite model with disjoint agent and system interests can satisfy Axioms 2 and 3-s while failing Axiom 1. A model with all system interests contained in agent interests can satisfy Axioms 1 and 3-s while making W a function of the payoff vector, so Axiom 2 fails. A model with ui^s≡0 and nonconstant W can satisfy Axioms 1 and 2 while failing strict systemic dependence. The witness models below establish formal independence. Under the interpretive embedding convention—if Ii∩ IC= then ui^s≡0, a stated convention rather than a consequence of the definitions—Axiom 3-s with nonconstant W entails Axiom 1, so the independence claim holds over the unbridged primitives while Axiom 1 functions as a scope delimiter under the convention. The bridge axiom remains separate from this independence argument.

The witness models are finite and checkable by inspection, each with two agents and two profiles Σ=\{σ,σ'\} (one strategy set a singleton, so the profile pair is the whole product). The first model removes embedded overlap: I1=\{p\}, I2=\{q\}, IC=\{s\}, W(σ)=1, W(σ')=0, and ui^s=W for both agents; Axiom 1 fails while Axioms 2 and 3-s hold. The second model places every system interest inside the union of agent interests: I1=\{p,s\}, I2=\{q,s\}, IC=\{s\}, ui^P≡0, ui^s=W; Axiom 2 fails, and ui=W for both agents, so W is a function of the payoff vector. The third model keeps the interest-set conditions and assigns zero systemic components against a nonconstant W: I1=\{p,s\}, I2=\{q,s\}, IC=\{s,t\} with t outside the union, W(σ)=1>0=W(σ'), ui^s≡0; the strict clause of Axiom 3-s fails while the weak form holds. These are logical independence constructions over the listed model ingredients. They do not establish that any particular industry satisfies or violates an axiom.

The bridge axiom has a different logical role. It is not a third expression of system independence at the level of interest labels. It asserts that the observation map has a nontrivial W-fiber. The theorem that uses it therefore has an explicit dependency: Axiom 2′ gives W-Independence, while Axioms 1–3 provide the embedding and dependence interpretation. The separation prevents an application from claiming payoff non-recoverability merely because the analyst has named an interest that no individual party holds in full.

The exact scope can be summarized as follows. Axiom 1 says that the parties participate in the system. Axiom 2 says that the system has a named interest outside the union of party interests. Axiom 3 says that the system channel enters party payoffs monotonically, with the strict form transmitting every strict W ordering. Axiom 2′ says that the chosen payoff signal does not identify W. Axiom 4 says that the endpoints under consideration are privately acceptable relative to disagreement. Conditions 2 and 3 connect the endpoint to a regular, reachable path. Each statement has a distinct object and a distinct test.

The labels carried by these premises are deliberate. “Formal” means that a conclusion follows within the specified mathematical model. “Conditional” identifies a conclusion whose class of objects must be verified before the result applies. “Empirical” identifies an assertion about a domain or measurement record. “Illustrative” identifies an example used to clarify structure. “Conjectural” identifies a proposed extension that has not been proved in the flagship. The labels remain attached to claims in the later applications and design section.

The axiom system does not assume that parties have no concern for the system. Axiom 1 explicitly allows overlapping interests, and Axiom 3 gives each party a systemic payoff channel. The claim is that overlap can coexist with a system interest and a payoff fiber that leaves part of W unrecorded. This is the setting in which an agent can receive a systemic exposure while the aggregate system state remains underdetermined by the agent’s report.

When the factored form is used, strict increase of each fi gives the implication from W order to systemic-payoff order immediately. Conversely, the weak clause (Axiom 3-w) forces each systemic component to be constant on the fibers of W—equal welfare gives equal systemic payoff—so ui^s factors through W; the strict clause then makes the resulting fi strictly increasing on the image of W. The equivalence is exactly the biconditional stated in the Axiom 3 subsection and needs no further regularity. The flagship uses the factored form where a component-level inversion or taxonomy conclusion needs it and uses Axiom 3-s where only an order implication is required.

4. Witness, W-Independence, and the information boundary · 3,086 words

4. Witness, W-Independence, and the information boundary

The information problem concerns the signal available to a decision rule. Let q:Σ→ Y be the signal. It may be the vector of total payoffs, the vector of private components, or a reported feature vector. A pair (σ',σ'') is a q-witness when q(σ')=q(σ'') and W(σ')≠ W(σ''). The signal matters: a witness for total payoffs does not automatically establish independence from private components or from a richer observation map.

For this section, u denotes the total-payoff vector map, u(σ)=(u1(σ),…,un(σ)), while ui remains agent i’s scalar total payoff. Thus a total-payoff signal sets q=u; a private-component signal uses the corresponding vector map.

This signal-specific definition is the operational form of the information problem. If the rule observes total payoffs, set q=u. If it observes private components, set q=u^P. If it observes a reported type vector, q is the reporting map together with the statistic computed from the report. A witness for one signal does not automatically witness independence from another signal. An analyst who adds an independent emissions monitor, a benchmark-integrity measure, or a resource-stock observation has changed q and must repeat the identification test.

The same distinction separates a measurement failure from a strategic failure. A system can have a well-defined W while the parties’ reports omit it. Alternatively, W may be measured, while the feasible game still directs private improvement toward lower values of W. The first case is W-Independence; the second is the Trap, the path result that private improvement lowers system welfare. The applications can exhibit both, yet the propositions that establish them have separate premises.

Proposition 4.1: the characterization

The proposition asks whether one payoff vector can be assigned one welfare value; g is the rule that would perform that assignment.

For any game, the following statements are equivalent:

1. There is a function g: R^n→ R such that W(σ)=g(u1(σ),…,un(σ)) for every profile. 2. Every pair of profiles with the same payoff vector has the same W.

The proof is the fiber argument. If W=g∘ u, equal payoff vectors imply equal welfare. Conversely, if W is constant on every fiber of the payoff map u, define g on the image of u by g(u(σ))=W(σ), then extend it outside that image. Therefore a same-payoff, different-welfare witness is equivalent to the failure of payoff-level recoverability. This is formal and uses no axioms.

In ordinary words, the proposition checks the information link: a rule that receives one payoff vector must assign one welfare value to that vector. A witness breaks that link. A fiber is the set of profiles producing one signal, and the image is the set of signals that actually occur, so the construction of g only fills in a rule on observed payoff vectors.

The forward direction is immediate: the value of a function is constant on each fiber of its argument. For the reverse direction, the payoff map may identify many profiles, but the assumed constancy of W on each fiber makes the assignment well-defined. If two profiles have the same payoff vector, they receive the same assigned value; consequently the rule g on the image of u does not depend on which profile was used to define it. Any extension outside the image is irrelevant to the game. Proposition 4.1 therefore gives an exact test, not a sufficient-condition heuristic.

The proposition also identifies what a failed test can mean. If an exhaustive domain specification contains no witness, W may be a function of payoffs on that domain. If a witness is proposed but one of the payoff components is unmeasured, the observation map has not been verified. If two profiles have different total payoffs but the same reported private outcomes, they witness a different signal. The empirical record must state the signal, the profile domain, and the measurement resolution used in the comparison.

Counterexample 4.1: interest non-inclusion without the witness

Take two agents with binary actions, ui(σ)=σi, and W(σ)=u1(σ)+u2(σ). Let the system interest set contain “long-run institutional continuity,” an interest absent from both agent interest sets. Axiom 2 holds as an interest-level statement, yet W=g(u1,u2) with g(x,y)=x+y. The payoff map identifies the action profile, so no same-payoff, different-welfare pair exists.

The example can be given a decomposition satisfying Axioms 1–3 by setting ui^s=ε W, where ε (epsilon) is the weight assigned to system welfare in each agent’s systemic component, and ui^P=σi-ε W, with 0<ε<1, and assigning interest sets with nonempty agent-system intersections. The example is formal. It shows why Axiom 2′ is a separate bridge axiom.

The decomposition in this counterexample is worth spelling out because it blocks a common inference. The total payoff remains uii, so the payoff map remains one-to-one even though every agent receives a systemic component that is strictly increasing in W. The system interest can be outside the individual interest labels while the model still assigns W a payoff representation. Axiom 3-s can hold, Axiom 1 can be populated, and Axiom 2 can hold, yet W-Independence fails. The missing premise is a pair of profiles in the same payoff fiber.

The bridge and W-Independence

Axiom 2′ supplies the witness required by Proposition 4.1. Its immediate consequence is Corollary 4.1, W-Independence:

\[ {W is not a function of the parties' payoffs.} \]

Equivalently, no map from the payoff vector recovers W on the domain. The claim is formal conditional on Axiom 2′. It does not say that agents have no knowledge of W, that W is unknowable, or that no independent measurement can recover it.

The formal W-Independence wording is: W is not a function of the parties' payoffs. System Independence remains the name of the interest-level Axiom 2; the two labels name different objects.

The conditional wording matters for interpretation. W-Independence is a statement about the information class generated by the payoff vector. An individual may possess private information about W. A regulator may observe a physical or institutional indicator. A richer mechanism may use that indicator. The result states that a rule restricted to the parties’ payoff vector cannot produce a universally correct W value on a domain containing the witness. The independent channel is therefore an information requirement for W-aware implementation, not a claim about human knowledge or physical observability.

Example 4.1: the sixteen-bank benchmark-distortion game ΓLIBOR

The game models the historical sixteen-bank BBA LIBOR calculation convention. Each day up to sixteen panel banks submitted a rate; the published rate discarded the highest four and the lowest four submissions and averaged the middle eight. The submissions were estimates—each bank’s answer to the question of what rate it would pay to borrow—not records of transactions, so a submission could be chosen. The averaging rule has a structural consequence the two-agent simplification cannot represent: no one bank can move the published rate, because a lone deviating submission lands among the discarded four; moving the rate requires a coalition of submitters large enough that its submissions survive the discard and occupy the middle eight.

Sixteen banks each choose among N,L,G. N is honest submission of the shared honest estimate r*=4 (rates in percentage points; the common estimate is a modeling simplification the estimate-based mechanism permits). L is submission of the scheme rate 41/10 to a thin local reference rate; G is submission of the same scheme rate to a globally embedded benchmark. The sixteen banks constitute the submitting panel for whichever benchmark the profile names. If a profile contains both L-players and G-players the scheme has no common target and aborts: every bank submits honestly. The disagreement point is d=(N,,N).

The published rate R(σ) is the average of the middle eight submissions after the highest four and lowest four are discarded, and the distortion is D(σ)=R(σ)-r*. Bank i’s private payoff is its own derivatives-book gain from the distortion,

\[ ui^P(σ)=piD(σ), \]

where pi is bank i’s fixed book position (dollars of book gain per unit of published-rate distortion), with

\[ (p1,,p16)=(40,25,15,30,10,20,35,5,45,50,12,8,6,4,3,2). \]

Each participating bank’s systemic exposure—the loss channel through its own standing and continuation: expected sanction, franchise damage, own-book repricing—is h=1 in any profile whose scheme moves the rate, identical by construction across the two benchmarks, and zero otherwise; ui^s=-κ h with κ=1/2 for participants, zero for honest banks. System welfare is

\[ W(σ)=W_0-M(σ)D(σ), \]

where M is the reach of the distorted benchmark—the total notional referencing it, the third-party contract holders’ exposure—with M_=1 for the local rate and Mg=350{,}000 for the global benchmark, in units where the local benchmark’s referenced notional is one. No bank’s payoff loads on M.

The witness pair is σ' (banks 1–12 play L, banks 13–16 play N) and σ'' (the same twelve play G, the same four play N). At either profile the sorted submissions place the four honest 4’s among the discarded lowest four and four of the twelve scheme submissions among the discarded highest four, so the middle eight are all 41/10: R=41/10 exactly and D=1/10. The coalition of twelve fills the entire middle eight; a coalition of four or fewer leaves the published rate at 4 (every deviating submission is discarded), and five is the smallest coalition that moves it. Each bank’s private payoff is p_i/10—for banks 1 through 16: 4,5/2,3/2,3,1,2,7/2,1/2,9/2,5,6/5,4/5,3/5,2/5,3/10,1/5—identical across σ' and σ'' because positions and distortion are the same. Each coalition bank’s systemic payoff is -1/2 at both profiles; each honest bank’s is 0 at both. Every one of the sixteen banks therefore receives the same private, systemic, and total payoff at σ' and at σ'', while W(σ')=W_0-1/10 and W(σ'')=W_0-35{,}000. Thus ΓLIBOR satisfies Axiom 2′ by construction. Assume pi D≥κ h for every coalition bank—the displayed numbers meet it, with equality at bank 8—so each bank’s total payoff at the witness profiles meets its disagreement value; Section 5 uses this restriction when it places those profiles in a taxonomy cell. Every displayed quantity is an exact rational, and the construction is verified by exact-rational computation.

The notional scales in the LIBOR calibration distinguish a local reference rate embedded in on the order of a billion dollars of contracts from a benchmark embedded in roughly $350 trillion; those magnitudes calibrate Mg and M_, and the formal witness requires only Mg≠ M_. This is an exposure-form witness: each bank’s modeled systemic exposure is the same across the two profiles while an agent-orthogonal part of W—the reach-scaled loss to the contract-holding public, which no bank’s own position size or exposure carries—changes.

The example has three layers. At the private layer, both witness profiles pay each bank p_i/10, a function of the bank’s own book and the common distortion. At the exposure layer, both profiles assign the same systemic payoff to each bank. At the system layer, the global benchmark reaches a larger body of contracts, so the public loss MgD exceeds M_ D. The payoff vector—all sixteen totals, and all thirty-two decomposed components—is therefore the same at σ' and σ'', while W differs. A decision rule that sees only the bank payoffs cannot distinguish the profiles. A rule that also sees benchmark reach or referenced notional can distinguish them, provided that the added measure is independently verified.

The construction does not claim that local reference-rate manipulation is harmless. It gives a controlled comparison in which the public loss is ordered by embedding reach while every bank’s reported gain and modeled exposure are held fixed, and it keeps every rate-setting agent inside the game: all sixteen submitters are players, so no welfare difference is attributable to an actor outside the declared boundary. A richer model may add legal liability, reputational loss, or bank-specific exposure. Such additions can remove this particular witness by changing the payoff vector. They do not remove the possibility of another witness unless the domain has been specified and the full signal has been tested.

Proposition 4.2

In ΓLIBOR, W is not a function of the agent-payoff vector. It is also not a function of the decomposed array of private and systemic components, since the two witness profiles agree on every displayed component. This is formal by Proposition 4.1.

The second statement is stronger than the ordinary payoff claim for this example. Reporting ui^P and ui^s separately does not identify W when the decomposition omits the agent-orthogonal system component. Decomposition remains a design requirement because it can expose many forms of system loss, yet Proposition 4.2 shows that decomposition alone cannot guarantee identification. The analyst must specify which part of W each reported component measures and what independent observation covers the residual.

Proposition 4.3: aggregate systemic dependence

The next two propositions compare a complete systemic component observed by an agent with an exposure component that records only one channel. The complete component can reconstruct W; the partial exposure can leave system change outside the reported payoff array.

Suppose for some agent i, ui^s=fi(W) with fi strictly increasing. If two profiles have the same total payoff and the same private component for that agent, their systemic components are equal. Injectivity of fi then gives equal W. Hence the benchmark-style witness, which agrees on private and total payoffs for every agent, cannot coexist with aggregate systemic dependence. This is formal.

Here injectivity means that a strictly increasing function cannot return the same value for two different inputs. To see the algebra, equality of total payoff and equality of private payoff imply

\[ ui^s(σ')=ui(σ')-u_i^P(σ') =ui(σ'')-u_i^P(σ'')=ui^s(σ''). \]

If ui^s=fi∘ W and fi is strictly increasing, it is injective on the relevant range, so W(σ')=W(σ''). The proposition therefore rules out any witness that agrees on that agent’s total and private components. It does not rule out a total-payoff witness when private components are allowed to offset systemic differences, and it does not rule out a witness for a coarser observation map that hides ui^s.

Proposition 4.4: recoverability under aggregate dependence

Under the same aggregate hypothesis, W=(fi|W(Σ))-1(ui^s) on the range fi(W(Σ)); the inverse is defined there, where every realized systemic value lives, and nowhere else. W-underdetermination can remain at the level of totals when private components exactly offset systemic differences, or relative to an observation map that reports totals without identifying the decomposition. The consistent benchmark specification uses exposure-form systemic dependence: the agent’s own exposure responds to the system, while W also carries a component outside that exposure. Proposition 4.4 is formal with the stated distinction.

Proposition 4.4 thus gives the identification boundary in both directions. In the aggregate form, a verified systemic component is a sufficient statistic for W. In the exposure form, a decomposed payoff array can remain insufficient because the reported exposure is only one projection of the system state. At the total-payoff level, even aggregate dependence can coexist with a witness when private gains offset systemic losses agent by agent. The empirical protocol must therefore test total-payoff recoverability and decomposition recoverability separately.

The scope result has a practical implication for mechanism design. A rule that requests a private payoff report and a self-reported systemic exposure receives a richer signal only if the exposure report is verifiable. A self-report that can be chosen to keep the total payoff unchanged does not establish aggregate dependence. Independent measurement can enter through a transaction record, a physical monitor, an institutional audit, or another source whose value is not generated by the party’s payoff report. The source must be described in the application; the formal theorem treats it as a change in q.

The section therefore establishes two nested boundaries. With an exposure-form decomposition, even the decomposed payoff array can omit system welfare. With aggregate dependence, a decomposed systemic component can identify W, while ordinary observation of totals can still fail to identify that component.

ΓLIBOR is the Section 4 payoff-level witness. Γwit, introduced in Section 6, is the full-hypothesis instance that verifies the continuous Trap bundle. The examples answer different questions and retain their separate status labels.

The witness can be local or global. A local witness concerns two profiles within one institutional state space and blocks a universal payoff rule on that domain. A global witness can compare two embedded games that share the same payoff data but differ in the system coordinate. Theorem 7.7(c) covers both forms: within one game, Axiom 2′ supplies two profiles a payoff-functional solution cannot separate; across two games agreeing on all declared payoff data, identical outputs are definitional. Both forms require the same discipline: specify the signal, show equality in that signal, and show a verified W difference.

Construction and field verification are separate tasks, and the witness discipline differs between them. A witness can be constructed inside a bounded game even for a diffuse harm such as emissions: two firms, each indifferent between two production methods with identical private profit and different emissions, give an identical payoff vector and different W within the stated boundary. Construction is not the obstacle. What field observation cannot do by itself is verify a witness where the harm is jointly caused by many actors and attribution to the observed parties is unavailable; global warming is the canonical case, since a measured welfare difference between two situations with identical payoffs to one emitter may have been produced by any other emitter outside the drawn boundary—the comparison then crosses background states the model treats as fixed, and W:Σ→{R} is not being evaluated on a stable domain. This is a limit on empirical verification in diffuse-harm domains, not a limit on the theorem: in such domains the witness premise is established by construction within a stated system boundary, or in field data through an attribution design adequate to that boundary, rather than by an uncontrolled comparison of situations. Section 9 states the corresponding requirements in the test plan.

The result is compatible with partial recoverability. A payoff vector may predict a coarse system label, such as the sign of a measured exposure, while failing to recover the level of W. W-Independence concerns exact functional recovery. Empirical prediction, classification accuracy, and causal measurement are separate tasks and should be reported with their own assumptions.

This distinction also applies to software-readable reports. A feature vector may contain many fields and still be payoff-functional if every field is generated from party returns. A single independently audited system indicator can change the signal class. The relevant question is the source of the coordinate and its relation to the profile fiber.

For this reason, a reporting reform should record the observation map before and after the reform. The reform can be evaluated by asking which previously coincident profiles become distinguishable and whether the new signal is tied to an actuator with authority to change conduct.

5. Outcome taxonomy, projection, and W-blindness · 1,269 words

5. Outcome taxonomy, projection, and W-blindness

Set lowercase c, read “c,” as the system-preservation indicator; uppercase C above names the embedding context. The agent indicators are a and b, read “a” and “b.” The notation 1[·] is equal to one when the bracketed condition holds and zero otherwise. Set

\[ c(σ)= 1[W(σ)≥ W0], ai(σ)= 1[ui(σ)≥ ui(d)]. \]

In the bilateral case, a=aA and b=a_B. The tuple order for the eight cells is (c,a,b): system first, then agent A, then agent B. Ties belong to the 1 side.

The eight cells are enumerated in Table 1.

Table 1: The eight outcome cells of the taxonomy. Each cell is a triple (c,a,b) recording whether system welfare and each party's total payoff are at or above the disagreement baseline (1) or below it (0).

(c,a,b)NameSystem cParty A aParty B b
(0,0,0)Miserybelowbelowbelow
(0,1,0)Corrosive Win-Losebelowat/abovebelow
(0,0,1)Corrosive Lose-Winbelowbelowat/above
(1,0,0)Stable Miseryat/abovebelowbelow
(0,1,1)Hollow Winbelowat/aboveat/above
(1,0,1)Sustainable Lose-Winat/abovebelowat/above
(1,1,0)Sustainable Win-Loseat/aboveat/abovebelow
(1,1,1)Win-Win-Winat/aboveat/aboveat/above

For any profile, the identity

\[ ai=1 ui^P(σ)-u_i^P(d)≥ ui^s(d)-u_i^s(σ) \]

holds; at a Hollow Win profile it shows how a private gain can offset an agent’s systemic loss in the aggregate payoff. Axiom 3-s makes the systemic loss strict whenever W<W_0. Call an outcome a weak complete winner when every agent’s private component and systemic component each meet their disagreement values, with weak inequalities; the strict form replaces both comparisons with strict inequalities. Under the factored strict dependence, a weak complete winner meets the system baseline and every total-payoff baseline, so it can occur only in Win-Win-Win. Membership in that cell does not itself guarantee component-by-component gains.

The identity follows by expanding the total-payoff comparison: the condition ui(σ)≥ ui(d) is equivalent to

\[ ui^P(σ)-u_i^P(d)≥ ui^s(d)-u_i^s(σ). \]

The right side is the systemic loss carried by agent i. A Hollow Win occurs when each private gain covers that loss in the total account even though the system indicator is zero. The cell records an apparent success that is compatible with an agent’s own systemic exposure being negative. If the private gains are strictly larger, the label remains Hollow Win; the cell uses the weak baseline comparison while the component-level definition can record strict gains. The two objects are distinct. The cell (0,1,1) is the weak object defined by the indicators above. The program’s component-level Hollow Win profile is strict: every agent’s private payoff strictly rises, system welfare strictly falls, and every agent’s systemic payoff strictly falls. A profile can occupy the Hollow Win cell without meeting the strict component conditions, so an application asserting the strict self-cannibalization reading must measure the components; the case labels in Section 8 are cell-level candidates, not component-level verdicts.

The taxonomy is a classification of outcomes relative to a baseline, not a utility theory. It records whether the system and each agent’s total payoff meet their reference values. It does not assign weights to the coordinates, rank two outcomes within a cell, or settle the choice among two system-preserving profiles. Those tasks require a welfare function, a bargaining rule, or an additional ordering. The taxonomy’s purpose is to retain a coordinate that the two-party label omits.

The projection, written ρ here,

\[ ρ(c,a,b)=(a,b) \]

drops c. It maps eight cells to four. The pairs conflated are Hollow Win with Win-Win-Win, Corrosive Win-Lose with Sustainable Win-Lose, Corrosive Lose-Win with Sustainable Lose-Win, and Misery with Stable Misery. Thus the standard bilateral label “mutual gain” names both a system-degrading outcome and a system-preserving outcome. This is a formal non-determination result.

The four conflations are structurally exact. For a fixed pair (a,b), the projection identifies one profile with c=0 and one profile with c=1 whenever both cells are achievable. A classifier using only (a,b) must assign the same label to both. The projection cannot be repaired by a more detailed verbal label or a larger sample of the same two binary outcomes. The missing datum is c or a measurement from which c can be computed.

When all eight cells are achievable over the class of games considered, adding c doubles the distinguishable cell count from four to eight. A classification restricted to the two binary agent indicators (a,b) cannot preserve both the bilateral payoff labels and the Hollow Win/Win-Win-Win distinction when the cells are achievable; if a class rules out some cells, the count drops to the achievable cells and the minimality claim weakens accordingly. This is the taxonomy’s minimality result. The optional distributional and entropy formulation is moved to Supplement S3 because it does not support either theorem.

The minimality argument is combinatorial. A label that preserves both agent indicators must distinguish the four possible (a,b) values. A label that also recovers c must distinguish the two system states within each value of (a,b), producing eight labels when all cells are achievable. Fewer labels can work only if the model class rules out a cell or relaxes one of the information-preservation requirements. The benchmark example supplies one pair of cells under its piD≥κ h restriction—Hollow Win at the witness profiles, Win-Win-Win at disagreement; the full taxonomy states the general classification requirement. ΓLIBOR is an exposure-form witness: each participant’s systemic component tracks scheme participation rather than the aggregate welfare level, so it satisfies neither Axiom 3-s nor the weak aggregate monotonicity of Axiom 3-w across its full strategy space—a bank participating in a low-reach scheme carries the participation loss while W falls little, while an honest bank in a high-reach scheme carries no participation loss though W falls sharply. Across the two witness profiles the systemic components are equal while W differs—so its systemic losses come from the construction’s distortion-versus-disagreement comparison, not from strict dependence.

Payoff-space bargaining solutions and cooperative concepts inherit the blindness. Nash (1950), Kalai–Smorodinsky (Kalai and Smorodinsky, 1975), Rubinstein (1982), the Shapley value (Shapley, 1953), the core (Gillies, 1959), and the nucleolus (Schmeidler, 1969) take payoff-space data or protocol parameters as their inputs. Under Axiom 2′, those inputs do not determine W. A solution concept wired to an independent W-channel falls outside this statement by definition.

For bargaining, the relevant input can be the feasible payoff set, the disagreement point, and protocol parameters such as a discount factor. For cooperative concepts, it can be a worth function defined on coalitions and their payoff allocations. If two embedded games agree on those payoff-space inputs while W differs, the solution concept returns the same output for both—the same solution set or selected outcome, according to the concept’s output type. The W-blindness claim concerns the output as a function of its declared inputs. Adding a verified system measure changes the solution class and makes the information channel explicit.

The taxonomy also clarifies the meaning of a repair. A rule that changes only the selected point within the same projected cell can leave c unmeasured. A rule that adds c to the outcome record can improve classification while leaving private incentives unchanged. A rule that changes the feasible set or payoff decomposition can change the frontier itself. The first is a reporting change, the second is an information change, and the third is a game change. The theorem chain addresses all three at different points.

6. The continuous theorem chain and a full-hypothesis instance · 4,175 words

6. The continuous theorem chain and a full-hypothesis instance

The theorem labels retain the manuscript’s global sequence: the continuous chain uses 7.x and the finite chain uses 8.x.

Theorem 7.1: continuous paths

Theorem 7.1 (The Missing System Theory, continuous paths; formal). Let Γ have two agents, disagreement point d, and baseline W0=W(d). Assume PST-c, Axiom 4, Condition 2, and Condition 3. Then

\[ ∀σ^∈ PP(Γ), W(σ^)<W0, \]

so every privately Pareto-efficient outcome has c=0.

Plain-language link: private dominance identifies the endpoint the parties can accept, reachability supplies a permitted route to it, regularity makes the accumulated local changes equal the endpoint change, and PST-c makes that accumulated change negative. The reader can therefore verify the link from the route and its sign condition without reproving the integral theorem.

Proof. Fix σ^∈ PP(Γ). Axiom 4 gives weak private dominance of d with at least one strict gain. Condition 3 supplies an admissible path γ from d to σ^. Condition 2 makes W∘γ absolutely continuous. Therefore

\[ W(σ^*)-W(d)=∫_01{d}{ds}W(γ(s))ds. \]

PST-c makes the integrand strictly negative almost everywhere, so the integral is strictly negative. Hence W(σ^*)<W_0.

In plain terms, the integral is a running total of instantaneous welfare changes: every small negative change contributes to the endpoint difference.

The endpoint argument has three distinct logical links. Axiom 4 places the endpoint in the feasible private-improvement region. Condition 3 places the endpoint in the image of the admissible path family. Condition 2 permits the conversion from the almost-everywhere derivative to an endpoint difference. PST-c supplies the sign of the integrand. Removing any link leaves a distinct failure mode: a point can be privately efficient without dominating disagreement, a dominating point can be unreachable, or a pathwise derivative can fail to control the endpoint because of irregularity.

The strict result does not require a uniform negative rate. A function can be strictly negative almost everywhere while approaching zero on large subsets, and the integral remains negative as long as the composite is absolutely continuous, which makes its almost-everywhere derivative integrable along the path. A uniform rate is needed for a quantitative welfare gap, not for Theorem 7.1. The gap and robustness variants therefore have stronger hypotheses and are pointed to the supplements.

The proof can be read as a contradiction against a system-preserving private optimum. Suppose an admissible path reached an endpoint with W(σ*)≥W_0. Absolute continuity would require the integral of the pathwise derivative to be nonnegative. PST-c requires that same integral to be strictly negative. The contradiction is generated by the path, so it applies to every endpoint for which Axiom 4 and Condition 3 supply the admissible path. This also explains why a private frontier point outside the reachable component is outside the theorem’s conclusion.

For the weak variant, equality can persist when W is constant on a positive-measure segment, a non-negligible portion of the path, or along the whole path. A strict endpoint conclusion can be restored by requiring strict decline on a set of positive measure with a nonzero integral, or by adding a terminal jump condition with a signed contribution. The flagship keeps that refinement separate from the qualitative theorem.

The n-agent argument replaces the bilateral private-payoff inequalities with a condition that tracks private progress across all agents: every private component is nondecreasing, and the sum is strictly increasing almost everywhere. Because each individual derivative is nonnegative, the sum is positive exactly when at least one derivative is positive; the display is the same condition in aggregate form. It uses the chain rule, the calculus rule for differentiating a function of a function, to differentiate W after the path is substituted into the welfare function, then applies the same integral link.

In symbols, the replacement conditions are

\[ {d}{ds}ui^P(γ(s))≥0(i=1,…,n), Σi=1^n{d}{ds}ui^P(γ(s))>0 .e. \]

and quantifies PST-c over paths satisfying those conditions. The same integral proof applies. Axiom 3-s then interprets a strict system decline as a strict decline in each agent’s systemic component, while the proof of the endpoint inequality uses the path condition itself. This separation matters when an application can establish the path derivative directly but has only a weak or partial model of the agents’ systemic exposures.

The proof uses the pathwise derivative, not a gradient norm. The theorem’s welfare inequality does not require Axioms 1–3; those axioms carry the interpretation that the decline affects embedded agents. Under Axiom 3-w, replacing PST-c by PST-w yields the weak conclusion W(σ^*)≤ W_0.

The value-redirecting sufficient condition is direct. Here τi denotes agent i’s nonnegative private gain and (read “ell”) is a continuously differentiable loss function with (0)=0. If ui^P=ui^P(d)+τi and W=W_0-(Σiτi), with '>0, then every admissible path has nondecreasing transfers with a strict increase in their sum, so dW/ds<0. For a commons, ei is agent i’s extraction, E(e)=Σi ei is total extraction, R is the initial stock, p is the per-unit private return, k is the extraction cost, and g maps remaining stock to welfare. If private payoff is strictly increasing in each agent’s extraction and W=g(R-Σi ei) with g'>0, then every admissible private-improvement path raises total extraction and lowers W. These are formal sufficient conditions; classifying a real domain under them is empirical.

The value-redirecting class makes the economic interpretation transparent. Private gains can be written as transfers, concessions, or rents τi. When those gains are financed by a strictly increasing loss of system welfare, any admissible path that increases at least one private transfer reduces W. The condition does not require the transfers to be monetary; it applies to any private payoff coordinate with this specification. It is sufficient, not necessary: a game can satisfy PST-c without admitting a single aggregate transfer variable.

The commons class uses a stock variable. Let R be the initial stock and E(e)=Σi ei total extraction. If each private payoff is strictly increasing in own extraction along the admissible set, a private-improvement path cannot reduce the extracting coordinates in a way that offsets another agent’s increase. If g is C^1 with g'>0, the derivative of W=g(R-E(e)) is negative whenever total extraction rises. Strict increase of private payoff in own extraction through a smooth cost with positive net return, a continuously differentiable g, feasibility E≤ R, and the whole-path condition are the structural requirements. A merely weakly increasing private payoff or a merely monotone g supports at most a weak path conclusion without additional assumptions. Fisheries, aquifers, atmospheric budgets, and shared infrastructure are empirical candidates for this structure.

The structural conditions also show why a frontier-only check is insufficient. The sign of dW/ds must hold along the whole admissible path from disagreement to the endpoint. A derivative evaluated only at the terminal frontier does not determine the accumulated welfare change. The applications therefore require a path specification, a system measure, and a test of the sign along the path or along each finite transition in the discrete version.

Weak tension and the n-agent bridge

Proposition 7.2 (weak-tension variant; formal). Replace PST-c in Theorem 7.1 with PST-w, which requires dW(γ(s))/ds≤0 almost everywhere on every admissible path. Then every privately efficient endpoint satisfies W(σ^*)≤ W_0. The proof is the same integral identity with a nonpositive integrand. Strict system decline requires a strict derivative on a set of positive measure or a separate endpoint argument.

Corollary 7.3 (private optimality with system preservation; formal). Under the strict hypotheses of Theorem 7.1, PP(Γ)∩\{σ:W(σ)≥ W0\}=. A mechanism whose output is a privately Pareto-efficient profile therefore cannot output a system-preserving profile inside the fixed game. This is a conclusion about the mechanism’s outcome class, conditional on the path hypotheses; it does not prohibit a transformed game from containing a system-preserving frontier.

Theorem 7.4 (n-agent Missing System Theory; formal). Let n≥2, and define admissible paths by weak private improvement for every agent together with a strict improvement in at least one private component almost everywhere. If n-agent PST-c, Axiom 4, Condition 2, and Condition 3 hold, then

\[ ∀ σ^∈ PP(Γ), W(σ^)<W_0. \]

The proof fixes an endpoint, uses Condition 3 to select an admissible path, and applies the same absolute-continuity identity. The proof is independent of the number of agents. The system-dependence axiom supplies the interpretation that every agent’s systemic component falls when W falls; it is not used to replace the pathwise sign premise.

The n-agent bridge is useful for cases where the private gain is distributed across many parties. A single agent’s private derivative can be zero on a segment while another agent’s derivative is positive. The sum condition preserves strict path progress, and PST-c assigns the sign to W. The theorem therefore does not require every party to improve at every instant; it requires weak private monotonicity for all and strict progress somewhere almost everywhere.

Structural sufficient conditions for PST

Proposition 7.5 (value-redirecting games; formal sufficient condition). Suppose private improvements can be represented by nonnegative value variables τi with ui^P(σ)=ui^P(d)+τi(σ), and suppose W(σ)=W_0-(Σiτi(σ)), where is C^1 on the range of Σiτi over F(d), with (0)=0—so that W(d)=W0, consistent with the baseline definition—and '>0 on that range. Along every admissible path, each τi∘γ is nondecreasing and at least one has a positive derivative almost everywhere. Hence

\[ {d}{ds}W(γ(s))=-'(Σiτi(γ(s)))Σiτi'(γ(s))<0 .e. \]

and PST-c holds. The condition covers rent redirection, cost avoidance, and extraction gains written against a common loss variable. It is a structural sufficient condition; the classification of a real domain under it remains empirical.

Proposition 7.6 (commons dilemmas; formal sufficient condition). Let agents choose extraction ei≥0 from a stock R, let E(e)=Σi ei, let private payoff be ui^P(e)=p e_i-k(ei), and let W(e)=g(R-E(e)). Assume four hypotheses: the extraction cost k is C^1 with p-k'(ei)>0 over the feasible range, so each private payoff is strictly increasing in own extraction with a strictly positive net return; g is C^1 with g'>0 on the feasible range of R-E; admissible paths stay in the region where E(e)≤ R and the first two hypotheses hold; and Condition 2 holds. Along an admissible path, the strictly positive factor p-k'(ei(s)) gives de_i/ds the sign of dui^P/ds almost everywhere, so weak private monotonicity forces ei'(s)≥0 for every i and strict improvement forces ej'(s)>0 almost everywhere for at least one j; hence Σi ei'(s)>0 almost everywhere. Therefore

\[ {d}{ds}W(e(s))=-g'(R-E(e(s)))Σi ei'(s)<0 .e. \]

and PST-c holds. The differentiable cost with strictly positive net return, the C^1 welfare response, feasibility E≤ R, and the whole-path condition are each required: a merely weakly increasing payoff, a nonsmooth cost (whose strict monotonicity alone cannot convert payoff-derivative signs into extraction-derivative signs), or a frontier-only derivative supports a weaker or incomplete conclusion. Fisheries, aquifers, atmospheric carbon budgets, and shared infrastructure are empirical candidates for this class.

These propositions explain the empirical emphasis on independent W measurement. In a value-redirecting game, the private gain can be observed while the aggregate loss variable remains omitted. In a commons game, extraction can be recorded while stock recovery, ecological integrity, or reserve margin is measured separately. The formal pattern is available only after the analyst identifies the path and the system variable.

Theorem 7.7: consolidated two-tier statement

The six conditions below are the ones displayed in the consolidated statement, in plain readings. One of them, Axiom 3-s, is carried for the interpretive tier: none of Theorem 7.7's conclusions consumes it — part (a) consumes Axiom 2′, part (b) the Tier-2 quartet, part (c) Axiom 2′ and the class definition — so it stands on the same interpretive footing as Axioms 1 and 2, which are read in Section 3 and carry the embedding interpretation rather than the proofs.

\[ {aligned} {Axiom3-s:}&Higher system welfare gives every agent a strictly higher systemic payoff.\{Axiom2:}&Two profiles can have identical total payoffs and different system welfare.\A4:&Each endpoint under consideration weakly improves every private payoff and strictly improves at least one over disagreement.\{PST-c:}&System welfare falls strictly at almost every point along every permitted path.\Regularity(Condition2):&Welfare changes regularly enough along each admissible path for the path integral to equal the endpoint change.\Reachability(Condition3):&Every endpoint satisfying A4's dominance clause can be reached from disagreement by an admissible path. {aligned} \]

Theorem 7.7 (The Missing System Theory, consolidated; parts (a) and (b) formal, part (c) conditional on its stated scope). Let Γ have n≥2 agents embedded in C. Tier 1 consists of the interpretive Axioms 1, 2, and 3-s, together with the bridge premise Axiom 2′—the one Tier-1 premise the conclusions consume. Tier 2 adds Axiom 4, n-agent PST-c, Condition 2, and Condition 3.

The tier architecture records which conclusion consumes which premise. Tier 1 describes an embedded domain and adds the payoff-level witness. Tier 2 describes the private-efficiency path and the analytic conditions that turn path tension into an endpoint inequality. The bridge premise is displayed separately in Section 3 because Axiom 2′ is the premise consumed by the information result; the interest-level Axioms 1–3 do not entail it.

(a) W-Independence. Under Axiom 2′, W is not a function of the parties' payoffs. This is Corollary 4.1. Axiom 2′ is cited here because the interest-level Axioms 1–3 do not entail the payoff-level witness.

(b) The Trap. Under the Tier-2 hypotheses, every privately Pareto-efficient profile satisfies W(σ^*)<W_0. The proof is Theorem 7.1’s integral argument with all agent quantifiers ranging over N.

(c) Universal W-blindness within payoff-functional solution concepts. No solution concept whose output is a function of payoff-space data alone responds to the system coordinate: two games identical in all declared payoff data but differing in W receive identical solutions, and within one game no value the concept computes from the payoff data can separate two profiles with identical payoff data and different W. This includes Nash, Kalai–Smorodinsky, Rubinstein, Shapley, the core, and the nucleolus within their standard input domains. Under Axiom 2′ the payoff data do not determine W, so the outcomes such a concept cannot separate include outcomes whose system-welfare consequences differ. The claim is conditional on the stated class of solution concepts and on Axiom 2′.

Part (a) is the information statement. It concerns the mapping from profiles to the vector of total payoffs and remains valid when no path is specified. Part (b) is the path statement. Its proof does not require Axiom 2′, because PST-c is already a direct statement about the welfare coordinate. Part (c) combines the information statement with the definition of a payoff-functional solution concept. A solution can select an outcome in payoff space while leaving two system states observationally equivalent to the solution. The theorem does not quantify over mechanisms that receive an independent system signal.

Proof. Part (a) is Corollary 4.1 and Proposition 4.1. Part (b) is the n-agent form of Theorem 7.1. Part (c) follows because each named concept is, by definition, a functional of its declared payoff-space data; its output is identical for two games that agree on all of that data, and no value it computes from the payoff data can separate two profiles that agree on that data. Within one game, Axiom 2′ supplies the two profiles, which makes the blindness substantive rather than vacuous: under it the payoff data do not determine W. Across two games, agreement on all declared inputs makes the identical output definitional. A solution concept receiving an independent system signal is outside the class.

The dependency line is the falsification guide for the consolidated result. If Axiom 2′ fails, the W-Independence conclusion is unavailable even if the other Tier-1 axioms hold. If PST-c fails, the private frontier may be system-preserving or system-improving. If Axiom 4 or Condition 3 fails, a path condition can hold vacuously at an endpoint that does not dominate disagreement or cannot be reached. If Condition 2 fails, the integral proof requires a repaired regularity statement. These failure modes are tested separately in Section 9.

The theorem’s parts are therefore modular. The bridge result can be tested in a domain whose frontier is unknown. The path result can be tested in a domain where W is observable even if the payoff vector is sufficient to recover it. The W-blindness result applies to a solution concept only after its inputs have been listed and shown to be payoff-functional. This modularity permits an application to report a positive result at one tier and a failed premise at another without collapsing the entire analysis into one label.

The distinction between the Trap and W-Independence matters to the dependency register. W-Independence says that a payoff-only rule cannot recover the system coordinate on the witness domain. The Trap says that, in a particular game with a reachable private frontier, every privately efficient endpoint has lower W. A domain can satisfy W-Independence without PST: the missing coordinate may remain stable along private improvement. A game can satisfy PST with W observed directly: the path theorem then gives a welfare conclusion even though the information theorem is unnecessary for that application. The consolidated theorem presents both because system-aware design must address both the incentive path and the observation channel.

The proof also avoids a claim about arbitrary optimization. Private Pareto efficiency is the endpoint property used by the theorem. A mechanism that selects a Nash equilibrium, a bargaining solution, or a cooperative allocation enters the Trap only when its output lies in the privately efficient set and the relevant path and reachability conditions hold. A mechanism that selects an inefficient point may avoid the strict conclusion while failing private participation or stability. The game-change section asks whether a transformed mechanism can make a system-preserving efficient point available.

The named solution concepts enter through their standard information sets. Nash bargaining uses a feasible payoff set and disagreement point. Kalai–Smorodinsky uses a monotonicity relation and an ideal point in payoff space (Kalai and Smorodinsky, 1975; Roth, 1979). Rubinstein bargaining uses offers, discounting, and protocol timing. The Shapley value, core, and nucleolus use coalition worth and payoff allocation data. When two games agree on those inputs but differ in W, the selected output is unchanged. If the institution adds a separately audited system state to the feasible set or worth function, the concept has a new input and the W-blindness statement no longer covers it.

The bargaining references and their standard input-domain discussion are in Supplement S3.

The worked instance below verifies non-vacuity as well as endpoint decline. Its negative coordinates provide the same-total-payoff witness, its positive quadrant supplies the private feasible set, and its diagonal path demonstrates the strict derivative condition. The example consequently serves two roles: it witnesses Axiom 2′ and it shows that the Tier-2 bundle can hold in one explicit game.

The finite and continuous statements share the economic structure of private improvement funded by system loss. Their proof objects differ. The continuous proof integrates a pathwise derivative. The finite proof sums exact welfare differences.

The continuous result is therefore not a limit theorem for finite games. A sequence of finite games can approximate a continuous domain while changing the permitted transitions, the path family, or the welfare measure. Conversely, a finite improvement chain can establish strict endpoint decline without any topology on the profile space.

Worked Example: Γwit

The example checks the hypotheses in four steps: it identifies the system boundary, exhibits two equal-payoff profiles with different W, identifies the privately efficient endpoint, and then checks every permitted route to that endpoint. The calculations below provide those checks; the surrounding sentences state what each calculation establishes.

Worked Example (Γwit: a non-vacuous full-hypothesis instance; formal). Let Γwit have two agents A and B, ΣAB=[-1/2,1], Σ=[-1/2,1]2, disagreement point d=(0,0), and W0=0. Take IA=\{vA\}, IB=\{vB\}, and IC=\{vA,vB,vC\}; Axioms 1 and 2 hold because each agent’s interest set intersects IC and the label vC lies outside IA∪ I_B.

Set uA^P(x,y)=x, uB^P(x,y)=y, and uA^s(x,y)=uB^s(x,y)=W(x,y), where W(x,y)=W_0-(x+y) for x+y≥0 and W(x,y)=W_0-(x+y)/2 for x+y<0, with ui=ui^P+ui^s. W is continuous, piecewise linear, and strictly decreasing in x+y. Because each systemic component equals W, Γwit satisfies Axiom 3-s. The profiles σ'=(0,0) and σ''=(-1/2,-1/2) have W(σ')=0 and W(σ'')=-(-1)/2=1/2, so u(σ')=(0+0,0+0)=(0,0) and u(σ'')=(-1/2+1/2,-1/2+1/2)=(0,0); the total payoff vectors are equal while W differs, hence Axiom 2′ holds.

PP(Γwit)=\{(1,1)\}—the frontier is computed over all of Σ—and (1,1) lies in F(d)=[0,1]2; uA^P(1,1)=1 and uB^P(1,1)=1, so the private-payoff vector is (1,1) and strictly privately dominates the disagreement vector (0,0). Thus Axiom 4 holds. W is linear on F(d) and piecewise linear on Σ, hence locally Lipschitz, so Condition 2 holds. The path γ(s)=(s,s) reaches (1,1), so Condition 3 holds.

Let A(d,(1,1)) (read “calligraphic A of d to (1,1)”) denote the set of admissible paths from d to (1,1). For every γ(s)=(x(s),y(s))∈ A(d,(1,1)), weak private monotonicity gives x'(s),y'(s)≥0 a.e., and strict improvement for at least one agent gives x'(s)+y'(s)>0 a.e. Admissible paths remain in F(d), where x+y≥0 and W=W_0-(x+y). Thus

\[ {d}{ds}W(γ(s))=-x'(s)-y'(s)<0 \]

a.e. Thus PST-c holds non-vacuously because A contains γ(s)=(s,s). Theorem 7.1 gives W(1,1)=-2<W0=0, and this same Γwit is an exhibited full Axiom 3-s + Axiom 2′ + Axiom 4 + PST-c bundle summarized by Theorem 7.7.

The hypothesis audit for the worked instance is compact. Axioms 1–2 are a formal instance because IA∩ IC and IB∩ IC are nonempty and vC lies outside the agent union. Axiom 3-s is a formal instance because each systemic component equals the strictly ordered welfare function W. Axiom 2′ is a formal witness because the two profiles have equal total payoff vectors and distinct W. Axiom 4 is a formal instance because (1,1) is privately efficient and strictly dominates d. Condition 2 is a formal instance because W is linear on [0,1]2, hence locally Lipschitz. Condition 3 is a formal instance because the diagonal reaches (1,1). PST-c is formal and non-vacuous because every admissible path has -x'-y'<0 a.e. and the diagonal is admissible.

The negative coordinates are retained in Σ for the Axiom 2′ witness, while the private feasible set F(d) restricts attention to the nonnegative quadrant. This is the feature that makes the witness and the path theorem coexist in one explicit game. The total payoff equality at the witness does not identify the positive-quadrant path; it identifies two profiles in the larger strategy space whose W values differ.

The example is deliberately full-hypothesis. The interest sets verify the interpretive tier, the equal-payoff profiles verify the bridge, and the systemic component, equal to W, verifies strict systemic dependence. The feasible quadrant and diagonal path verify the analytic tier. Because the derivative calculation is valid for every admissible path, the example does not rely on choosing one favorable trajectory after observing the endpoint. The explicit diagonal supplies non-vacuity, while the universal path calculation supplies PST-c for the entire admissible family.

The continuous theorem chain can be summarized as a sequence of implications:

\[ private dominance at the endpoint + frontier reachability admissible path negative path integral W(σ^*)<W_0. \]

The bridge axiom is orthogonal to this chain. It supplies the information conclusion and the W-blindness conclusion; it is not inserted into the integral proof. The consolidated theorem places the bridge beside the path hypotheses so a reader can see which premise is being tested for which result.

Tier-2 counterexamples

The hypotheses have separate roles. Each construction below uses two agents with ΣB a singleton, so the profile space is written by its A-coordinate. Removing PST-c: Σ[0,1], d=0, uA^P(σ)=uB^P(σ)=σ, and W≡ W0; the frontier point σ^=1 strictly dominates d, the identity path is admissible, and W(1)=W0 preserves the baseline, so the conclusion fails and only PST-c does. Removing Axiom 4: Σ[0,1], d=1/2, uA^P(σ)=1-σ, uB^P(σ)=σ, and W(σ)=W0+(σ-1/2); the game is constant-sum in private payoffs, so every profile is privately efficient, and the frontier point σ^=1 has W(1)=W0+1/2>W0 while F(d)=\{1/2\}—no admissible path exists, tension and reachability hold vacuously, and only Axiom 4 fails. Removing Condition 3: Σ\{0\}∪[1,2], d=0, uA^P(σ)=uB^P(σ)=σ, and W(σ)=W0+σ; the frontier point σ^*=2 strictly dominates d, but a continuous path cannot cross the missing interval, so the dominating frontier point is unreachable and W(2)=W0+2>W_0.

These counterexamples are formal falsification constructions. Condition 2 has an analytic role: without the absolute-continuity implication, an almost-everywhere sign condition need not determine the endpoint difference.

The first construction holds the frontier and the path fixed while setting W constant, so the endpoint equals the baseline. It isolates PST-c. The second uses a constant-sum private frontier. A profile can be privately efficient while making one agent worse off than disagreement, so Axiom 4 does not apply; every proposed admissible path to such a point fails the all-agent private-improvement condition, and a claim of PST-c can be vacuous. The third keeps regularity and private dominance while separating the disagreement component from the frontier component. A continuous path cannot cross the missing interval, so Condition 3 fails exactly at the point whose welfare rises above the baseline.

The tests also separate Axiom 4 from Condition 3. In the second construction, the reachability clause makes no demand because no endpoint satisfies the dominance premise. In the third, the endpoint does satisfy dominance but is unreachable. A single empirical check of “private efficiency” or a single observation of a negative welfare derivative cannot substitute for both tests. An application must show that the endpoint qualifies and that the protocol can reach it through the path family to which PST is applied.

7. The finite theorem and scoped extensions · 1,189 words

7. The finite theorem and scoped extensions

As in Section 6, theorem labels keep the program’s global numbering: the finite chain carries 8.x labels within this Section 7.

Theorem 8.1: finite form

Let ΓD, read “the discrete version of Γ,” be a finite discrete game with a transition relation M⊆Σ×Σ, where M records which profile changes the protocol permits. A private-improvement step is a pair (σ,σ')∈ M with ui^P(σ')≥ ui^P(σ) for every agent and a strict inequality for at least one. An improvement chain is a finite sequence from d to σ^* made of such steps.

The transition relation is part of the protocol. It can encode which offers, revisions, trades, or policy changes are available at each stage. A private-improvement edge is directed from the earlier profile to the later profile. The theorem quantifies over chains permitted by M; it does not infer that every pair of profiles can be connected by a sequence of private improvements. A profile can lie on the private frontier and still be outside the reachable component of disagreement.

Discrete PST requires every step on every chain from d to PP(ΓD) to strictly lower W. The finite reachability condition—the finite form of Condition 3—requires every frontier point satisfying the dominance clause of Axiom 4 to have such a chain.

Theorem 8.1 (Missing System Theory, finite form; formal). Under Axiom 4, discrete PST, and the finite reachability condition,

\[ W(σ^*)-W_0 =Σk=1K[W(σk)-W(σk-1)]<0 \]

for every σ^∈ PP(ΓD). Hence W(σ^)<W0 and c(σ^)=0. The proof is a finite telescoping sum: Axiom 4 gives uj^P(σ^)>uj^P(d) for at least one agent j, so σ^≠ d and every improvement chain from d to σ^ has length K≥1, which makes the sum nonempty. No continuity or limiting argument is used. The weak version replaces < by ≤ and yields only W(σ^*)≤ W_0. As in the continuous theorem, Axioms 1–3 supply the embedded interpretation of the decline; they are not premises of the telescoping argument.

For an improvement chain d=σ01,…,σK=σ^*, discrete PST gives

\[ W(σk)-W(σk-1)<0 (k=1,…,K). \]

Summing these inequalities produces the displayed endpoint difference. Finiteness makes the sum exact and avoids questions about convergence, parametrization, or a singular welfare path. Strictness is lost only when the step condition is weak or when a chain is absent. The n-agent finite form changes the quantifier over private improvements and leaves the telescoping proof unchanged; it is stated and proved as the n-agent finite theorem in Supplement S3.

The finite theorem also makes protocol design visible. Two institutions can share the same profile set and payoff functions while using different transition relations. One relation can contain a chain satisfying discrete PST; the other can block that chain and leave the theorem silent. A protocol comparison should report M alongside the outcome labels. The transition graph is part of the observable institutional environment.

The weak finite form replaces each strict edge inequality with W(σk)≤ W(σk-1) and yields W(σ^*)≤ W_0. The finite proof therefore has the same strictness boundary as the continuous proof. A system-preserving endpoint can occur when every permitted private-improvement edge leaves W unchanged. The conclusion remains conditional on the chain reaching that endpoint.

The following scope statements tell the reader which object carries the continuous or finite link in each extension. They state the conditions needed to reuse the proof pattern; detailed constructions remain in Supplement S3.

The extensions are scoped; each statement below is conditional on the named hypotheses. Mixed strategies preserve the conclusion under the expected-welfare convention—the mixture is evaluated by the expected value of W under its probability measure, not by W at the average profile—when every profile in the mixture’s support—the profiles receiving positive probability—lies in the private Pareto frontier and W is measurable and integrable; a mixture can otherwise average system-preserving and system-degrading profiles in a way that changes the relevant frontier. Repeated games preserve the conclusion for frontier paths supported by strictly positive normals—positive weights on every agent’s private payoff—under the discounted-average welfare convention, in which per-period welfare is averaged with discount weights summing to one. Repetition changes histories, monitoring, reputation, continuation payoffs, and punishments (Fudenberg and Maskin, 1986), so it supplies no domain-free system-preservation result. Coalition results require aggregate-path PST and verification of Axiom 4 and Conditions 2–3 for the coalition game. A coalition can internalize a system cost when it includes affected interests, controls a decisive action, or obtains authority over the system; that is a changed game or objective, not an automatic consequence of coalition formation.

Nash, Kalai–Smorodinsky, Rubinstein, Vickrey–Clarke–Groves (VCG; Vickrey, 1961; Clarke, 1971; Groves, 1973), d’Aspremont–Gérard-Varet (AGV; d’Aspremont and Gérard-Varet, 1979), and Coasian bargaining (Coase, 1960)—bargaining over a specified right and measurable system cost—remain W-blind when their inputs contain payoff-space information only. VCG and AGV are mechanism families that use reported valuations to choose allocations and transfers — in quasilinear environments, the Groves characterization confines efficient dominant-strategy mechanisms to this reported-valuation form (Green and Laffont, 1977; Holmström, 1979); they can use an independently verifiable social objective, in which case their information structure has changed. Coasian bargaining can internalize a cost when rights, affected parties, and the system cost are specified in the bargain. A welfare-aware mechanism can therefore escape by adding an independent W-channel or by changing the game. The full proofs, secondary propositions, and extension-specific status labels are in Supplement S3.

For repeated games, the relevant welfare convention must be stated. A time-average W can decline along a sequence of private improvements even when a terminal history contains a temporary recovery. Discounted welfare can weight that recovery differently. The discrete theorem applies to the chosen transition chain only after the analyst fixes the aggregation rule. A repeated-game equilibrium can therefore preserve W in one domain and sustain the Trap in another; repetition by itself does not determine the sign.

For coalitions, the coalition payoff is an aggregate and the admissible path must be defined for the aggregate private objective. A coalition containing all interests held in C may change Axiom 2 or the bridge signal. A partial coalition may control a decisive action and change the feasible set. The theorem requires these facts to be verified in the coalition game. It does not infer them from the original individual game.

For mechanisms, VCG and AGV are separated by their objective and message space. A payoff-only implementation inherits the signal limitation. An implementation with an independently verifiable W objective has added an information coordinate and may impose a transfer that changes the private incentives. Coasian bargaining has the same boundary: a specified right and measurable system cost can enter the bargain; an omitted system cost remains omitted. These are scope statements for the extension paragraph, with detailed constructions in S3.

The discrete result is especially useful for institutional records because a transition edge can be audited directly. A reviewer can list the profile before and after an offer, verify each private inequality, and compare an independently measured W value at the two states. The chain proof then gives an exact accounting of accumulated decline. Where the record omits intermediate states, the theorem applies only after the missing transition structure is supplied or the claim is restricted to the observed edges.

8. Empirical scope and short cases · 2,029 words

8. Empirical scope and short cases

This section applies the theorem’s classification to documented domains and proves no new result. The separate measurement program, including the INSPIRE protocol—a pre-registered protocol for applying the classification to negotiation records with an independent system measure, named for the INSPIRE negotiation-support system (Kersten and Noronha, 1999) whose published agreement database it uses; Kersten and Lai (2007) survey the system class—and return-side tests, is documented in Supplement S1; the paragraphs below report its status and show how the classification is used.

Evidence standard and domain classification

The evidence gate is independent measurement of system welfare. A simulation that builds a payoff-orthogonal W coordinate into its data-generating process cannot establish that the coordinate exists in an observed domain. It can test calibration or dashboard behavior. The direct domain test runs a regression, an estimated comparison of independently measured system welfare with the parties’ realized payoff vector, and calls the remaining unexplained movement residual variation—a diagnostic for further identification, not by itself a proof that W lies outside the payoff data, since a residual can also carry noise, omitted variables, or functional-form error. A system-beta premium is extra average return associated with exposure to system-wide movements—a return-side association distinct from the annual-revenue beta quantities of Section 2, which are welfare-to-revenue ratios; the return-side comparison asks whether that premium appears in ordinary periods or around a restoration event, using market, size/value/momentum, sin-industry (a factor for historically shunned industries), litigation-risk, and green-minus-brown controls. These findings are classification evidence about when the system coordinate becomes legible in returns, not inputs to either theorem.

The current program distinguishes the formal result, the INSPIRE protocol, and a return-side test, a public-data test of whether market returns move with system exposure. The protocol execution is pending. The return-side test—a companion-program result whose data, specifications, and tables are reported in Supplement S1 as reported estimates at companion-paper vintage, with the reproduction specification and data snapshot not shipped in this packet and independent verification pending—reports a mixed result: no normal-period system-beta premium and a positive restoration-event loading, a return association appearing during an institutional repair event, survive the controls described above; negative skew, an asymmetric return pattern with larger downside moves, and within-system covariance, co-movement among entities exposed to one system (Acemoglu, Ozdaglar, and Tahbaz-Salehi, 2015), do not. The narrow empirical interpretation is that W becomes return-relevant when an institutional event makes the coordinate legible. The broad hidden-tail-risk and covariance interpretations are unsupported in that run.

The compact domain audit classifies seventeen industry domains as structurally plausible PST settings and twelve game types where the theorem does not apply under the standard specification. The seventeen-domain set includes defense procurement and sustainment, pharmacy benefit management, food and agriculture systems, infrastructure and energy deregulation, cybersecurity supply chains, and international tax arbitrage—a partial sample of the seventeen. The twelve-game-type comparison is diagnostic, not exhaustive. Domain membership is an empirical classification based on documented regulatory findings, studies, or judicial records; it is not a theorem about every instance in the category. The row-level case evidence for each of the seventeen entries, and the full case register for the four applications below—system boundary, parties, welfare instrument, baseline, observation period, and premise status—are tabulated with the expanded tables and protocols in Supplement S1.

The audit groups the positive cases into eight mechanisms: benchmark and standard-setting, commons extraction, cartel and collusion, platform and digital ecosystems, financial systems, organizational and institutional incentives, environmental and climate systems, and regulatory capture or rent-seeking. The seventeen domain entries are defense procurement and sustainment, pharmacy benefit management, for-profit higher education, generative AI and model collapse, digital surveillance and misinformation, food and agriculture systems, infrastructure and energy deregulation, sports and anti-doping, insurance and risk-pooling distortion, international tax arbitrage, international trade subsidies, gig-economy labor misclassification, telecommunications and spectrum, cybersecurity supply chains, nuclear and energy safety margins, legal and judicial exploitation, and agricultural monoculture risk.

The comparison set contains twelve game types where the theorem does not apply under the standard specification—most because a named axiom fails there, the rest because institutional design or a scope convention removes the tension; a different boundary, decomposition, or protocol can return an instance to the theorem’s domain: systemic moral hazard under third-party guarantees, predatory or exit crime, peer production and open source, pure coordination games, perfect exchange economies, aligned utility markets such as cooperatives, rate-of-return regulated monopolies, zero-sum games, shared-profit firms, closed-loop vertically integrated firms, interactions with zero external stakeholders, and standard congestion games (Roughgarden, 2005). A domain can leave the comparison set if its institution changes the payoff map or supplies the missing system channel.

The evidence gate has three layers. The formal layer asks what follows from the axioms and PST. INSPIRE asks whether observed negotiation records with an independent W measure show the predicted separation between private outcomes and system state; execution is pending. The return-side public-data test asks whether markets price a system-beta exposure. Its mixed result—reported estimates at companion-paper vintage, not reproducible from this packet—supports a normal-period no-premium and a restoration-event loading under the market, size/value/momentum, sin-industry, litigation-risk, and green-minus-brown controls, while the negative-skew and within-system covariance tests fail. The result supports a narrow legibility-event interpretation and leaves broad hidden-tail-risk claims open.

The measurement rule is strict because a simulation can create a payoff-orthogonal coordinate by construction. That simulation can test an estimator, a calibration, or a dashboard response. It cannot establish the existence of an excluded coordinate in an observed domain. For a domain test, W must come from a separately measured benchmark-integrity indicator, stock measure, reserve margin, emissions reading, health burden, or institutional quality measure. The analyst then reports how much of that measure is explained by payoff data and what residual variation remains after the payoff map is specified.

Three further classified domains are recorded briefly here; their full case treatments belong to the long-form working paper and Supplement S1. In the Volkswagen emissions case, a defeat device kept the laboratory emissions signal compatible with compliance while on-road emissions deteriorated—a candidate Hollow Win cell in the pre-exposure phase—and independent road testing plus enforcement supplied the measurement-and-enforcement transformation referenced in Section 10 (U.S. Environmental Protection Agency, 2016; International Council on Clean Transportation, 2015). In algorithmic rental pricing, RealPage’s systems illustrate a common pricing signal with private revenue gains against a system coordinate—competitive rental-market conditions and tenant burden—not encoded in the landlord payoff vector; the candidate Hollow Win classification is an application of the taxonomy, and the empirical algorithmic-pricing literature (Calvano et al., 2020; Assad et al., 2024) does not report the paper’s three-coordinate labels. The SOFR transition replaced survey-based LIBOR submissions with a rate computed from overnight Treasury repurchase transactions (Financial Stability Board, 2014)—a measurement reform that removed the false-submission channel and supplied an external integrity signal, not a welfare guarantee—and its post-transition candidate Win-Win-Win classification is pending confirmation under the Supplement S1 protocol.

The worked case below separates three kinds of statement: documented facts, which are empirical; the paper’s applied cell classification, an empirical case judgment rather than a verified formal cell assignment; and conditional theorem application, which holds only under the stated hypotheses.

London Interbank Offered Rate (LIBOR) manipulation

The case maps directly to the benchmark-distortion witness of Section 4, whose game carries the mechanism itself: up to sixteen panel banks submitted a daily rate, the highest four and lowest four submissions were discarded, and the middle eight were averaged to set the published rate. The submissions were estimates of borrowing costs, not transaction records—little actual interbank lending stood behind them—so a submission was a chosen number. In the paper's common-estimate model, where the honest banks submit the shared estimate, the discard rule leaves the published rate unmoved unless enough manipulated submissions survive the discard to occupy the middle eight (Section 4). With heterogeneous real-world submissions the rule does not nullify a single bank—an extreme submission can still shift which submissions occupy the retained window—but it raises the coordination required to move the published rate reliably, which is why sustained manipulation needed a coalition rather than a lone actor. The publicly documented sanctions and reform record support the system-integrity interpretation. They do not by themselves prove Axiom 2′ for every submission profile, and the paper treats the classification as an application of the formal witness structure. A confirmatory study would pair submission-level payoffs with an independently constructed integrity measure and test whether the payoff vector leaves system variation unexplained, under the four witness-test requirements stated in Section 9.

The documented manipulation had two distinct modes, and the classification treats them separately. In the first, from roughly 2005 to 2009, derivatives traders at several panel banks arranged for their banks’ submissions to be nudged up or down to profit their own derivatives books: traders asked their banks’ submitters for specific rates, made requests of traders at other panel banks, and induced interdealer brokers to relay suggested submissions to other banks’ submitters, in electronic messages the enforcement record preserves; the FSA’s Final Notice to Barclays documents 257 such submission requests at Barclays alone between January 2005 and June 2009. Thomas Hayes, a UBS and later Citigroup yen-LIBOR trader, was convicted in August 2015 on eight counts of conspiracy to defraud and imprisoned; the UK Supreme Court unanimously quashed that conviction on July 23, 2025, holding that the trial judge had misdirected the jury on a question of fact, and the Serious Fraud Office declined a retrial—a quashing on misdirection grounds, not a finding of innocence. In the second mode, during the 2008 crisis, banks individually submitted rates below their actual borrowing costs so as not to appear distressed—lowballing that required no coordination because each bank had the same reputational motive. The paper classifies the coordinated manipulation phase as a candidate Hollow Win cell: the submitting banks could register private gains while benchmark integrity declined. The benchmark was referenced in approximately $350 trillion of contracts, so the system coordinate carried exposure absent from the banks’ payoff reports; combined fines across the enforcement actions exceeded $9 billion. The episode and its reform are documented in Duffie and Stein (2015). It also shows why repetition is not a system-preservation result: in the paper’s reading, repeated interaction sustained the private frontier and extended the period of degradation.

The reform phase replaced self-reported submissions with transaction-based reference-rate construction. The case supplies a documented instance of the game-change pattern: the rate’s information architecture changed so that the relevant integrity signal no longer depended on a bank’s report.

The enforcement record also documents a second transformation, operating on a single party’s payoff. The CFTC’s LIBOR investigation opened in the spring of 2008—before any insider came forward—when Vincent McGonagle, then Senior Deputy Director of the CFTC’s Division of Enforcement, opened the first regulatory inquiry into the benchmark after Wall Street Journal reporting that panel banks’ submissions sat below what market measures of their borrowing costs implied. Barclays settled first, on June 27, 2012, paying approximately $450 million across three regulators, including a $200 million CFTC penalty. Later in 2012 an insider—per press reporting, a former Deutsche Bank executive (Reuters, 2021)—turned over documents that the reporting describes as having catalyzed the already-open benchmark-manipulation case, contributing to the April 23, 2015 Deutsche Bank enforcement action: approximately $2.5 billion in combined penalties for LIBOR and Euribor manipulation, of which the CFTC penalty was $800 million. On October 21, 2021, the CFTC paid that insider a whistleblower award of nearly $200 million—the largest in the CFTC program’s history and, after the Securities and Exchange Commission’s $279 million award of May 5, 2023, the second-largest under the Dodd-Frank whistleblower programs—under the provision that pays a whistleblower between 10 and 30 percent of monetary sanctions collected when the sanctions exceed $1 million; the CFTC’s own announcement describes the information as contributing to an already open investigation, not as opening it. The award, the fines, and the timeline are documented regulatory and legal facts; the design reading of the award—payment to an insider as a channel that surfaces the system coordinate—is developed in Section 10 and is interpretive.

The separate annual-revenue beta measurement program is defined and assessed in Supplement S1; it supplies empirical status for the classification and is not used to prove a theorem here.

9. Falsification conditions · 1,363 words

9. Falsification conditions

The theorem is a conditional statement. Each premise has an operational test. A successful test of the premises followed by a counterexample to the conclusion would locate an error in the premise verification or in the proof. A failed premise limits the application and does not refute the mathematical implication.

The tests are:

Axiom 2′: Exhibit two profiles with identical ui for every agent and different W, or specify an exhaustive domain on which no such pair exists. The witness test carries the four requirements stated with the bridge-axiom protocol below this list. The scope fails if W is recoverable from payoffs or the witness is absent, unverified, or depends on an unmeasured distinction.
Axioms 1–2: Document agent-system overlap and a system interest outside the union of agent interests. The domain boundary is crossed if agents are not embedded or no named system interest lies outside the agent union; whether W is a function of the payoff vector is the Axiom 2′ test above, not this one.
Axiom 3-s / Axiom 3-w: Compare systemic payoff components across ordered welfare states. A strict conclusion fails under weak dependence when a welfare improvement leaves an agent’s systemic payoff unchanged or lower.
Axiom 4: Check every privately efficient profile against the disagreement private-payoff vector. The premise fails when a frontier point lacks weak private dominance or a strict private improvement.
PST-c / PST-w: Trace every admissible path and estimate the sign of dW/ds. The premise fails when a path has a non-strict or positive derivative on a set of positive measure. When no admissible path reaches the claimed endpoint, the failure belongs to Condition 3, and PST is untested at that endpoint because its path quantifier is empty.
Condition 2: Verify local Lipschitz regularity of W on F(d) and absolute continuity of W∘γ. The endpoint integral is unlicensed when a singular welfare path—welfare change concentrated on a set the almost-everywhere derivative misses—can satisfy the sign condition without the endpoint inequality. In empirical work this regularity is a maintained modeling assumption under a stated model class; a finite record alone cannot verify it.
Condition 3: Construct a path or finite chain from d to each frontier point satisfying the dominance clause of Axiom 4. The theorem is silent about a dominating frontier point that is unreachable.
Empirical seventeen-domain classification: Use a separately measured system state and document the domain evidence. The classification fails when payoff data recover W, the independent measure does not support it, or the case fails the stated axiom and PST tests.

The bridge-axiom test has a constructive and a negative form. The constructive form is a controlled comparison and carries four requirements.

1. A stable game/state domain. W:Σ→{R} is a function on the profiles of one specified game against a fixed background state, so the two profiles must differ only in the parties’ own strategies within the declared system boundary. If an actor outside that boundary changes conduct between the two observations and that conduct changes measured W, the comparison crosses contexts the model treats as fixed—the two observations evaluate two different background states, not two points in the domain of one W—and no witness is established. A welfare difference that an actor outside the boundary could have caused is not a witness; it indicates that the boundary is drawn wrong. The remedy is one of two: hold the outside context fixed, or expand the game so the outside actor’s action is represented in Σ, after which a witness requires that actor’s payoff to be identical as well. 2. Equal observed payoff signal at a declared measurement resolution. Equality of the payoff vectors is itself a measurement claim; the test states the resolution at which the two payoff signals were found equal and records every payoff component used in the signal. Axiom 2′ requires exact equality of the payoff vectors, and no finite-resolution field measurement certifies exact equality: a field comparison that finds the two payoff signals equal at its declared resolution is therefore consistency evidence for the witness, not verification of Axiom 2′. Verification of the exact premise is available by construction—as in ΓLIBOR, where the payoff equality holds identically—and a resolution-limited field test enters the record with that downgraded status. 3. A stated boundary and attribution method for the welfare difference. The test declares the system boundary and the method by which the welfare difference is attributed to the parties’ strategies rather than to outside state—held fixed, controlled, or measured and adjusted—and demonstrates that W differs under an independent measure. 4. An explicit diffuse-harm limit. Where the harm is diffuse and jointly caused by many actors, field observation alone cannot establish the witness: a measured welfare difference between two situations with identical payoffs to the observed parties may have been produced by an actor outside the declared boundary. An attribution design adequate to the boundary can support empirical verification; absent one, the witness premise is established by construction within a stated boundary (Section 4).

The sixteen-bank benchmark-distortion game ΓLIBOR of Section 4 is the worked template satisfying all four requirements: one specified game with a fixed background state, identical private and systemic payoffs by construction—exact equality, not equality at a measurement resolution, so requirement 2 is met at the level Axiom 2′ demands—a declared boundary in which the welfare difference is produced by which benchmark the parties corrupted, and no dependence on field attribution—every one of the sixteen rate-setting banks is a player in the game, so no actor who sets the rate stands outside the declared boundary. A negative result specifies the profile domain and proves that the payoff map is injective or that W is constant on each payoff fiber. “No witness found” without a domain specification is an incomplete test. The same standard applies to a proposed witness based on a legal, physical, or institutional distinction that the payoff record does not measure.

The path tests require coverage. Sampling a few private-improvement paths can support a local diagnostic; it cannot verify the universal PST-c premise. The formal application must specify the admissible path family or finite transition graph and test the sign condition on that object. If only a subset can be observed, the result should be reported as conditional on the unobserved paths satisfying the same sign condition. A vacuous path condition—no admissible path reaches the claimed endpoint—is recorded as a Condition 3 scope failure, not as a PST failure: the theorem is silent there, and the PST record for that endpoint stays empty rather than negative.

Regularity is tested separately from the sign. A local Lipschitz check on W and the private payoff compositions supports absolute continuity under the stated path construction, whose image is compact. If the welfare series contains jumps, censoring, threshold effects, or an unmeasured singular component, the analyst must use the bounded-variation variant, a path with finite total accumulated movement, and state how the jump contribution is signed. A derivative estimate with missing endpoint accounting cannot support the strict integral conclusion.

The empirical classification has two failure modes. A domain can fail the theory because W is recoverable from payoff data, and it can fail because the parties’ private improvements do not lower W along admissible paths. A documented case of harm can still fail to satisfy the theorem if the private frontier, disagreement point, or reachability relation has not been identified. Conversely, a domain can satisfy the structural information premise while lacking enough data to estimate the path derivative. The classification report preserves these distinctions.

This test plan is intended for a submission or replication. Each item names the object to measure, the evidence needed to support it, and the observation that would remove it from the theorem’s scope. A failed test narrows the claim to the remaining hypotheses; it does not supply the missing premise by interpretation.

The finite theorem has its own test: verify the transition relation, the private-improvement chain, and strict welfare decline on every chain step. The continuous and finite tests cannot substitute for one another. Quantitative-gap and finite-threshold extensions are assigned to Supplement S3, where their additional rate, separation, and boundedness hypotheses are stated.

10. Game-change boundary and W-aware design · 2,088 words

10. Game-change boundary and W-aware design

Within-game limits

This boundary is a theorem about an information class. A mechanism may have unlimited computational capacity and observe every payoff report while remaining unable to distinguish the two profiles in Axiom 2′. Enlarging the message space with more payoff-relevant dimensions does not help when the witness persists in the enlarged signal. An independent W-channel can help even when it is statistically noisy, provided the transformed mechanism specifies how the noise affects implementation and how the authority verifies the threshold. The design claim concerns the source and governance of information, not the size of the algorithm.

The payoff-space boundary applies to mechanisms whose message spaces contain only payoff-relevant information. VCG and AGV can improve allocation relative to the payoffs they observe. Nash, Kalai–Smorodinsky, Rubinstein, Coasian bargaining, repeated play, and coalition formation can change selection or timing. Under the relevant hypotheses, these procedures still operate on a frontier whose private gains are funded by system loss. An independent W-channel changes the information structure; a tax, liability rule, measurement regime, or mandate can change the payoff structure; a strategy constraint can change the feasible set. Each is a game transformation when it introduces a channel or constraint absent from the original game.

The design requirements are:

1. Independent W-monitoring. Measure system welfare through a source structurally independent of party payoff reports. 2. Payoff decomposition. Report ui^P and ui^s separately so that a positive total cannot conceal a systemic loss. 3. Trajectory detection. Flag a candidate Hollow Win path and estimate the time at which systemic loss exceeds the stationary private advantage—a private gain that remains bounded over the relevant period—when the temporal hypotheses, assumptions about how private gains and W evolve over time, hold; the hypotheses and the finite-crossing proposition are stated in Supplement S3.

None is sufficient alone. An independent signal without authority produces information without intervention. Decomposition without an external system measure can identify exposure while leaving the system state unmeasured. A trajectory alert without a reliable welfare channel cannot establish the path condition. Their statuses differ: independent W-monitoring is necessary, within the stated mechanism class—incentive-compatible direct mechanisms whose message spaces carry only payoff-relevant information—for conditioning selection on system preservation: such a mechanism cannot compute or verify the system indicator from its message space (under a witness pair straddling the W0 threshold, exhibited in Supplement S3), and any privately efficient outcome it selects is system-degrading under the path hypotheses (a rule can preserve the baseline by accident—always selecting disagreement—but cannot verify that it has); a conditional result, from the no-independent-channel impossibility proposition stated and proved with the mechanism extensions in Supplement S3; decomposed reporting and trajectory detection are requirements of the proposed dashboard architecture, and their necessity for every W-aware extension is not established here.

The requirements form a sequence. Monitoring supplies a system state. Decomposition links that state to each party’s account and reveals whether private gain offsets systemic exposure. Trajectory detection links observations over time or along a protocol path and identifies when the current game is approaching a system-degrading frontier. Authority then determines whether an alert changes the feasible set, the payoff structure, or the reporting rule. Without the authority step, a system-aware dashboard remains an observation layer rather than a transformed game.

Two construction patterns

The theorems establish the information boundary and the need to test a transformed game; the evaluation architecture and proxy-threshold schema below are independent proposals, and their repair claims remain explicitly conjectural.

Independent monitoring needs a measurement design. The monitor must identify the system boundary C, define a baseline W0, specify a time or path index, and record the resolution at which two system states are distinguished. A benchmark monitor can use transaction coverage and rate dispersion; an environmental monitor can use emissions concentration or stock levels; a platform monitor can use competition, quality, or user-burden measures. The monitor’s independence is structural: its value cannot be chosen solely by the party whose payoff is being evaluated.

Payoff decomposition needs an accounting convention. Private return can include direct compensation, trading surplus, or operating revenue. Systemic return can include continued access, institutional standing, or exposure to the shared system. The components must add to the reported total under the stated convention. If the decomposition is only a narrative label, Proposition 4.4 does not apply. If the decomposition omits an agent-orthogonal W component, Proposition 4.2 remains the relevant boundary.

Trajectory detection needs a path family and an alert rule. The monitor can compare the sign of Δ W, the change in welfare between two path states, to the direction of private improvement, estimate a uniform rate when the data support one, and identify a restoration event when the game changes. It must carry uncertainty, missing observations, and delays in the system measure into the decision rule. An alert is evidence for review; the theorem conclusion requires the stated path and regularity hypotheses.

The benchmark reform illustrates an information transformation. A self-reported signal was replaced by a transaction-based signal, changing the set of states distinguishable by the institution. The emissions case illustrates a measurement-and-enforcement transformation. Road testing made the system consequence observable and connected the observation to penalties, changing the private return to the strategy.

A second pattern uses an evaluation architecture, a process that combines independent records and checks, to inspect decisions from multiple perspectives. A structured decision record can support reconstruction when its audience is not predictable to the decision-maker and an empowered reader, a person or body authorized to act on the information, can respond. This is an application pointer, not part of the MST proof; the companion extension is in Supplement S3.

The two construction patterns operate through different levers. A transaction-based benchmark constrains the information available to a submitting party and changes the institution’s ability to verify the state. Road testing changes observability and connects a physical measure to a liability rule. A third pattern can change payoffs directly: a fee, bond, or damages rule makes system degradation enter the private objective. A fourth can change the feasible set by prohibiting a strategy or requiring a compliance action. The resulting profile can be system-preserving, yet the proof of improvement belongs to the transformed game and cannot be inferred from the pre-transformation theorem alone.

The LIBOR whistleblower award documented in Section 8 is a worked instance of the third pattern in service of the first requirement. Under the ΓLIBOR witness of Section 4, W is not recoverable from the sixteen banks’ payoff reports; an insider holds the information that would reveal the manipulation, and in the original game that party’s payoff is aligned with concealment. The Dodd-Frank award changes that one party’s payoff—a share of the collected sanction, a payment that is a function of the harm revealed—so that revealing the system coordinate becomes privately optimal. In this section’s terms the award is a game transformation that installs an information channel about W the original game lacked: it converts a concealing party into a revealing one. The channel is a revelation channel, not a continuous monitor—it surfaces the hidden coordinate at an event and does not measure welfare over time—so it complements independent W-monitoring rather than substituting for it. The classical instruments do not create such a channel under the theorem’s hypotheses. A Pigouvian tax must be calibrated to a marginal social cost that is the coordinate not recoverable from payoffs. Coasian bargaining, under the conditions stated above, operates on a frontier whose private gains are funded by system loss, and the diffuse harmed public is not a party to the bargain. Ostrom-style community self-governance, in its standalone form, works where the governing community is the harmed community; here the sixteen submitting banks governed the benchmark while the harmed community was the wider financial system that referenced it, so the two communities are disjoint. The regulator’s role in this construction is to mandate and fund the channel—the award is paid from collected sanctions—acting as backstop for the revealed information rather than as its designer. The award is a documented instance consistent with the design principle; the design schema itself remains conjectural, and the multi-party version of the cure—seating the parties who bear W, including the affected public—is developed in a forthcoming companion paper (Postnieks, in preparation, Changing the Game: Why Some Bargains Destroy What Nobody Owns — Conflictoring, Noerr-Pennington, and the Conditions for Repair).

Proxy-threshold schema

This schema connects the design agenda to the theorem’s dependency line: it supplies a new observation or changes the feasible game, then asks whether the transformed game contains a compliant path. It is a policy construction pointer, not an additional result in this draft.

For an institutional PST game ΓPST, a specified game satisfying the pathwise tension condition, and a fixed degradation path, a proxy-threshold rule can improve welfare if the transformed game has: a verifiable proxy for the excluded system coordinate, a threshold that separates welfare states, an actuator with authority to impose it, and a constrained compliance equilibrium—an outcome in which parties follow the rule while remaining within the compliant set—whose welfare exceeds the fixed pre-transformation profile’s: writing σ' for the compliance equilibrium of the transformed game and σ^ for the fixed pre-transformation profile, W(σ')>W(σ^) under the same boundary and measurement protocol; the welfare comparison is part of the construction, not a consequence of the other four objects. This is a theorem schema, marked conjectural, rather than a proved universal characterization. It is scoped to the named game and path and promises strict improvement relative to the fixed pre-transformation profile. It does not promise universal repairability or c=1 for every path.

The institutional/physical boundary—the distinction between conditions an institution can alter and conditions it cannot—is a domain classification. A law, treaty, regulation, or market restructuring can change an institutional constraint. A conservation law, biological invariant, or chemical persistence property cannot be changed by an institution. A repair claim must identify the institutional component, the measurable proxy, the separating threshold, the actuator, and the compliance equilibrium. Mixed physical-institutional domains remain open where the residual physical lower limit and the repairable institutional component have not been separated.

The companion five-type diagnostic classifies the primary deficiency as externalization, opacity, capture, lock-in, or commons; whether a primary deficiency is always well defined is part of the conjectural exhaustiveness claim. The schema is conjectural as an exhaustive classification and illustrative as a diagnostic. Supplement S3 contains the domain-specific program, secondary propositions, and composition questions.

The five types indicate what a repair must expose. Externalization places the system cost outside the agent’s account and calls for a liability or accounting channel. Opacity hides the state or the action and calls for independent measurement. Capture lets a party control the institution that measures or enforces the system condition and calls for authority separation. Lock-in blocks a change in the feasible set and calls for an exit, substitution, or transition path. A commons problem distributes the system cost across users and calls for stock measurement and an aggregate constraint. A domain can contain several types; the label records the primary deficiency that prevents the existing game from carrying W, and a domain where no single deficiency is primary takes multiple labels.

The institutional/physical boundary limits what a design can promise. Regulation can alter reporting, rights, incentives, or access. It cannot repeal a conservation law or remove a biological response. A mixed case must split the residual physical condition from the repairable institution and report the welfare result for each component. The proxy–threshold schema is consequently conjectural and game/path-specific: its premises identify a construction that could improve the named game, while its conclusion does not establish a universal repair theorem.

The proxy–threshold schema has five verification questions. Is the proxy measured independently of the party’s payoff? Does the threshold separate the relevant W states on the named path? Does an actuator have authority to enforce the threshold? Does the transformed game contain a compliance equilibrium that remains feasible for the parties? Does the compliant equilibrium raise measured welfare over the fixed pre-transformation profile, under the same boundary and measurement protocol, with concurrent changes recorded? A positive answer to these questions supports the scoped construction. It does not establish genericity, universal repairability, or an outcome class outside the specified game.

An implementation report should state the pre-transformation profile, the transformation, and the post-transformation equilibrium separately. This makes the improvement claim auditable and prevents a threshold rule from being credited with a welfare effect that came from an unrelated change in demand, technology, or enforcement. The schema is designed for that comparison.

11. Limitations and conclusion · 747 words

11. Limitations and conclusion

The system boundary C is a modeling choice. A larger embedding system can reverse the c-classification for the same profile—an existential result, established by a two-boundary construction carried with the secondary propositions in Supplement S3. Under the nested-embedding premise—every declared boundary admits a strictly larger embedding context, a modeling premise rather than a theorem—no universally maximal boundary is available; that conclusion needs nothing beyond the premise. The further claim, that a given candidate boundary’s classification is overturned by some strictly larger boundary, is the conditional one: it holds where the reversal construction is instantiated above that candidate, and the secondary propositions in Supplement S3 state the two parts separately. A W-aware platform must declare the monitored system and can report classifications under several boundaries when they diverge.

This boundary issue affects both the taxonomy and the witness. A pair can have the same private payoffs relative to a local institution and different welfare relative to a larger infrastructure system. A classification that changes with C is informative when the analyst reports the boundary; it becomes ambiguous when the boundary is left implicit. The paper treats C as part of the model tuple and recommends a boundary audit for empirical work.

The witness is signal-specific. A same-payoff witness does not establish independence from every richer observation map. Aggregate systemic dependence can make W recoverable from an identified systemic component even when ordinary reports contain only totals. Exposure-form domains and aggregate-form domains therefore require separate identification tests.

The manuscript also leaves the welfare scale open. W has no lower bound, so claims use comparisons with W0 or state a separate boundedness assumption. The separate measurement program in S1 covers the annual-revenue beta quantities and their frontier interpretation. Quantitative gap and first-passage claims—the first-passage point is the first time a chosen welfare threshold is reached—belong to S1 and S3 with their own assumptions.

Further measurement, annual-revenue normalization, and stochastic first-passage extensions are assigned to Supplement S1; they do not alter the stated theorems.

The identification limits are equally direct. A case record can document a private return and a system harm while leaving the counterfactual payoff fiber unidentified. A measured W can be statistically related to private gains while the direction of the path remains unknown. The proof requires the specified witness or path condition; the empirical program must state which parts are observed, estimated, or assumed. In diffuse-harm domains where many actors jointly cause the harm, field observation alone cannot attribute a welfare difference to the observed parties; the witness premise there is established by construction within a stated boundary, or through an attribution design adequate to that boundary (Sections 4 and 9). Coalition and repeated-game extensions change the strategy and history spaces, and stochastic models require a stopping rule, a rule that specifies when the random process ends, and a welfare process. Their conclusions remain conditional on the extension-specific objects.

Several conjectures remain open: measure-theoretic genericity of PST, the claim that PST holds for almost all models under a specified measure, exhaustiveness of the five-type diagnostic, closure under hybrid transformations, and the classification of mixed physical-institutional domains. The historical impossibility chronology is in Supplement S2; secondary extensions and domain programs are in S3.

The open program also includes a direct test of whether a stable system measure can be integrated into bargaining without creating a new witness through strategic reporting, a comparison of transition graphs before and after benchmark reform, and a specification of how uncertainty in W affects the proxy–threshold schema. The execution items that remain open—the INSPIRE protocol run, independent verification of the return-side test, and the behavioral predictions—carry their statuses in the supplements’ claim registers. These questions concern implementation and identification. They do not alter the formal theorem already proved under its hypotheses.

The final statement is concise. A payoff-level witness gives W-Independence: W is not a function of the parties’ payoffs. Under Axiom 4, PST-c, regularity, and frontier reachability, Theorem 7.1 gives W(σ^*)<W0 for every privately Pareto-efficient endpoint. Theorem 7.7 combines these claims in two tiers and cites Axiom 2′ in both its W-Independence and W-blindness parts. The Missing System Theory identifies the condition under which private efficiency consumes system welfare and the information channel required to see that consumption.

The practical implication follows from the theorem’s dependency register: measure W independently, report the payoff decomposition, and test the path from disagreement to the private frontier. A system-preserving outcome requires a signal and a game that can carry it.

References · 787 words

References

Acemoglu, D., Ozdaglar, A., & Tahbaz-Salehi, A. (2015). Systemic risk and stability in financial networks. American Economic Review, 105(2), 564–608.

Arrow, K. J. (1951). Social Choice and Individual Values. Wiley.

Assad, S., Clark, R., Ershov, D., & Xu, L. (2024). Algorithmic pricing and competition: Empirical evidence from the German retail gasoline market. Journal of Political Economy, 132(3), 723–771.

Calvano, E., Calzolari, G., Denicolò, V., & Pastorello, S. (2020). Artificial intelligence, algorithmic pricing, and collusion. American Economic Review, 110(10), 3267–3297.

Clarke, E. H. (1971). Multipart pricing of public goods. Public Choice, 11(1), 17–33.

Coase, R. H. (1960). The problem of social cost. Journal of Law and Economics, 3, 1–44.

Commodity Futures Trading Commission. (2021). CFTC awards nearly $200 million to a whistleblower. Press Release No. 8453-21, October 21, 2021.

d’Aspremont, C., & Gérard-Varet, L.-A. (1979). Incentives and incomplete information. Journal of Public Economics, 11(1), 25–45.

Duffie, D., & Stein, J. C. (2015). Reforming LIBOR and other financial market benchmarks. Journal of Economic Perspectives, 29(2), 191–212.

Financial Stability Board. (2014). Reforming Major Interest Rate Benchmarks. Basel: Financial Stability Board.

Fudenberg, D., & Maskin, E. (1986). The folk theorem in repeated games with discounting or with incomplete information. Econometrica, 54(3), 533–554.

Gibbard, A. (1973). Manipulation of voting schemes: A general result. Econometrica, 41(4), 587–601.

Gillies, D. B. (1959). Solutions to general non-zero-sum games. In A. W. Tucker & R. D. Luce (Eds.), Contributions to the Theory of Games, Volume IV (pp. 47–85). Princeton University Press.

Gordon, H. S. (1954). The economic theory of a common-property resource: The fishery. Journal of Political Economy, 62(2), 124–142.

Green, J. R., & Laffont, J.-J. (1977). Characterization of satisfactory mechanisms for the revelation of preferences for public goods. Econometrica, 45(2), 427–438.

Greenwald, B. C., & Stiglitz, J. E. (1986). Externalities in economies with imperfect information and incomplete markets. Quarterly Journal of Economics, 101(2), 229–264.

Groves, T. (1973). Incentives in teams. Econometrica, 41(4), 617–631.

Hardin, G. (1968). The tragedy of the commons. Science, 162(3859), 1243–1248.

Holmström, B. (1979). Groves' scheme on restricted domains. Econometrica, 47(5), 1137–1144.

Hurwicz, L. (1960). Optimality and informational efficiency in resource allocation processes. In K. J. Arrow, S. Karlin, & P. Suppes (Eds.), Mathematical Methods in the Social Sciences, 1959 (pp. 27–46). Stanford University Press.

Hurwicz, L. (1972). On informationally decentralized systems. In C. B. McGuire & R. Radner (Eds.), Decision and Organization (pp. 297–336). North-Holland.

International Council on Clean Transportation. (2015). Taking stock of the Volkswagen emissions scandal. Washington, DC: International Council on Clean Transportation.

Kalai, E., & Smorodinsky, M. (1975). Other solutions to Nash’s bargaining problem. Econometrica, 43(3), 513–518.

Kaplow, L., & Shavell, S. (2001). Any non-welfarist method of policy assessment violates the Pareto principle. Journal of Political Economy, 109(2), 281–286.

Kersten, G. E., & Lai, H. (2007). Negotiation support and e-negotiation systems. Group Decision and Negotiation, 16(6), 553–586.

Kersten, G. E., & Noronha, S. J. (1999). WWW-based negotiation support: Design, implementation, and use. Decision Support Systems, 25(2), 135–154.

Maskin, E. (1999). Nash equilibrium and welfare optimality. Review of Economic Studies, 66(1), 23–38.

Mas-Colell, A., Whinston, M. D., & Green, J. R. (1995). Microeconomic Theory. Oxford University Press.

Myerson, R. B., & Satterthwaite, M. A. (1983). Efficient mechanisms for bilateral trading. Journal of Economic Theory, 29(2), 265–281.

Nash, J. F. (1950). The bargaining problem. Econometrica, 18(2), 155–162.

Ostrom, E. (1990). Governing the Commons. Cambridge University Press.

Pigou, A. C. (1920). The Economics of Welfare. Macmillan.

Postnieks, E. (in preparation). Changing the Game: Why Some Bargains Destroy What Nobody Owns — Conflictoring, Noerr-Pennington, and the Conditions for Repair. Manuscript in preparation; target journal Journal of Institutional Economics.

Reuters. (2021). Former Deutsche Bank whistleblower awarded $200 million record payout. October 21, 2021.

Roth, A. E. (1979). Axiomatic Models of Bargaining. Springer-Verlag.

Roughgarden, T. (2005). Selfish Routing and the Price of Anarchy. MIT Press.

Rubinstein, A. (1982). Perfect equilibrium in a bargaining model. Econometrica, 50(1), 97–109.

Satterthwaite, M. A. (1975). Strategy-proofness and Arrow's conditions: Existence and correspondence theorems for voting procedures and social welfare functions. Journal of Economic Theory, 10(2), 187–217.

Schmeidler, D. (1969). The nucleolus of a characteristic function game. SIAM Journal on Applied Mathematics, 17(6), 1163–1170.

Securities and Exchange Commission. (2023). SEC awards more than $279 million to a whistleblower. Press release, May 5, 2023.

Sen, A. K. (1970). The impossibility of a Paretian liberal. Journal of Political Economy, 78(1), 152–157.

Shapley, L. S. (1953). A value for n-person games. In H. W. Kuhn & A. W. Tucker (Eds.), Contributions to the Theory of Games, Volume II (pp. 307–317). Princeton University Press.

U.S. Environmental Protection Agency. (2016). Learn about Volkswagen violations; Volkswagen Clean Air Act civil settlement. Washington, DC: U.S. Environmental Protection Agency, enforcement records.

Vickrey, W. (1961). Counterspeculation, auctions, and competitive sealed tenders. Journal of Finance, 16(1), 8–37.

Notes · 3 words

Notes

About the Author · 131 words

About the Author

Erik Postnieks is the founder of the Center for Decision Accounting, an independent research center developing the Decision Accounting, Missing System Theory, and System Asset Pricing Model research programs. He holds a B.A. in Economics from Cornell University and an M.B.A. from the Amos Tuck School of Business at Dartmouth College. His work focuses on governance architecture, system-welfare measurement, decision records, and the institutional conditions under which private incentives fail to price system consequences. Before founding the Center for Decision Accounting, he worked in derivatives and quantitative investment management, including at Bankers Trust, Parametric Capital Management LLC, and Wooster Asset Management LLC. He expects to transition into academia as this research program moves from working-paper development to peer review, research writing, and the production of educational materials.