{"id":"bec19be2-6670-4e5f-90fc-6785f94c049c","arxiv_id":"2607.05802","paper_version":4,"verdict":"ACCEPT","confidence":"HIGH","novelty_score":7.0,"correctness_risk":"low","formal_verification":"none","parameter_count":0,"one_line_summary":"Under \"safety in numbers\", a social assurance contract that privately collects completed authorizations and publishes them jointly reaches the largest safe coalition C⁺, while any safe public cascade is bounded at C⁻; crossing the gap requires private holding (Theorem 4).","lead":"A theory paper shows that secretly collecting signatures and publishing them only when the whole group is safe can let controversial statements go public even when one-by-one petitioning stops after the first exposed signers. It proves any zero-risk institution that achieves this must hold completed, hidden authorizations and release them jointly — a formal basis for embargoed letters, allegation escrows, and card checks.","discovery_kind":"first_principles","skeptic_critique":{"model":"deepseek-v4-flash","headline":"No significant objection identified: Theorem 4 is internally sound; the monotonicity caveat is a bounded scope condition, not a flaw.","rationale":"The paper's central claim is Theorem 4: at zero risk, crossing the public cascade C- requires a private conditional-release stage with completed authorizations and joint publication. I followed the proof step by step. The key move is Claim 4: if the first crossing act names a roster R containing i∉C-, then C_h-∪{i} cannot be protecting, because Assumption 1 and the fixed-point property of C- would put i in C-. Therefore regret-freeness forces R to contain at least one other newly named person, and act-by-act consent plus Assumption 5(iii)'s twin-history argument forces that person's completed, still-unattributed authorization to have been received before the release act. This is internally valid. The reader correctly identifies Assumption 1 as the most fragile substantive premise: without safety-in-numbers, C+ may not exist, and the simple C-/C+ comparison breaks. But the paper itself provides the nonmonotone accessible-kernel result (Proposition S8), which preserves the necessity of holding for any admissible coalition outside the kernel. Thus the monotonicity assumption is a scope boundary rather than a hidden flaw. Other limitations—endogenous signing, stochastic attribution, leakage—are explicitly acknowledged and do not affect the zero-risk theorem. I therefore see no reason to change the ACCEPT verdict.","tokens_in":40576,"tokens_out":20298,"duration_ms":218521,"concrete_test":"Independently re-derive Theorem 4 from first principles by encoding Definition 2 and Assumptions 1–5 in a small exhaustive search over all monotone protection families on up to 5 agents: enumerate all public-only regret-free mechanisms and confirm that no public history leaves C-, and that for every crossing history the release act is a device act preceded by completed private authorizations from every named agent other than its author. A counterexample would invalidate the theorem; otherwise the argument is confirmed.","verdict_should_be":"UNCHANGED","load_bearing_attack":"No load-bearing defect found. I checked the dependency chain of Theorem 4: Lemma 3's act-type representation, Lemma 4's holding necessity, Claim 4's use of C- as a Γ-fixed point, and the twin-history argument requiring receipt before execution. All are internally consistent. The reader's flagged assumption—monotone protection (Assumption 1)—is the closest thing to a weak spot, but it does not bring down the central causality result. Assumption 1 is needed for the clean unique-largest-coalition framing (Theorem 1) and for identifying the cascade endpoint with the least fixed point of Γ. When Assumption 1 fails, C+ may be undefined and the planner faces NP-hard selection (Proposition S9); however, the paper explicitly retreats to the accessible kernel (Appendix S8.1, Proposition S8), and the necessity of a private conditional-release stage for outcomes outside the kernel survives under the same E1 act technology. The manuscript also flags its own limits: V-formation and signing frictions in §III, deterministic attribution in Appendix S4, and leak risk in Proposition 3. None of these undermines Theorem 4 as stated.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper studies the problem of forming a coalition to publicly express a controversial view under threat of material retaliation. A coalition is self-protecting if each member is safe given exactly the public roster. Under monotone protection (Assumption 1), there is a unique largest safe coalition C+(S); a public cascade built by one-at-a-time safe additions stops at the least fixed point C-(S) (Theorems 1–2). A social assurance contract that privately collects completed authorizations and conditionally publishes the whole roster when it becomes self-protecting reaches C+(V), and thus C+(S) when all eligible sign (Theorem 3). The central result, Theorem 4, is a converse: in the environment E1, any regret-free mechanism that in some realization reaches a coalition outside C-(S) must operate a private conditional-release stage—completed, still-hidden authorizations from all named participants (except the author of the release act) followed by a single joint publication. The paper then extends to positive risk tolerance (Theorem 5, Propositions 2–3), a frictionless signing benchmark (Proposition 4), and a fight-or-fold opponent model that yields a visibility–suppression reversal (Proposition 5, Corollary 2). Supplemental appendices analyze nonmonotone protection, count release, the exogenous-statistic boundary case, and a welfare decomposition.","tokens_in":40656,"tokens_out":6065,"duration_ms":68633,"significance":"The result, if accepted, is significant. It pins down the institutional causal structure for zero-risk collective expression: crossing the exposure barrier requires holding completed authorizations before release; labels such as escrow, embargoed letter, or delegate are irrelevant relative to this holding sequence. The paper's strengths are its axiomatic transparency, complete proof appendix, absence of free parameters, and the explicit treatment of scope. All body theorems have proofs in Appendix A; the representation theorem derives holding rather than assuming it; the nonmonotone case is flagged and analyzed via the accessible kernel and an NP-hardness result. The visibility–suppression reversal is a falsifiable, nontrivial model implication, and the authors are careful to label it a latent-subgroup comparative static, not a causal estimate. I found no load-bearing internal inconsistency. The main caveat—monotone protection may fail if an added name creates risk—is acknowledged by the authors and mitigated by Appendix S8.1; it limits the empirical domain but does not undermine the conditional theorems.","major_comments":[],"minor_comments":[{"comment":"The sentence immediately after Assumption 1 contains 'Writer i for the exposure risk person i is willing to tolerate'; this should read 'Write r_i for the exposure risk person i is willing to tolerate.' The same paragraph renders the zero-tolerance case as 'tr i = 0'; the subscript should be r_i.","section":"Section I, Assumption 1"},{"comment":"In the statement of Theorem 4, the phrase 'outside2 C−(S)' appears twice; the stray superscript '2' should be removed.","section":"Theorem 4"},{"comment":"The byline reads 'ByMatthew Cashman'; insert a space. Similar spacing errors appear in a few places (e.g., 'V alid inputs').","section":"Title page"},{"comment":"The concept 'verified before exposure' is used in Assumption 2 and Lemma 2, but the distinction between completion and receipt first becomes load-bearing only in Lemma 4 (Assumption 5(iii)). A one-sentence gloss at first use would help the reader see why receipt, not mere completion, matters.","section":"Section I.A"},{"comment":"The abstract could state more prominently that the clean largest-coalition structure is conditional on monotone protection. The authors do flag the nonmonotone case and provide the accessible kernel and NP-hardness results in Appendix S8.1, so this is a presentation suggestion rather than a technical objection.","section":"Section I, Assumption 1 / Abstract"}],"recommendation":"accept","confidential_remarks":"I agree with the reader's assessment: the core representation theorem is internally consistent and the scope conditions are handled transparently. The dependence on the companion paper for entry and implementation is clearly flagged and does not affect the main results. No further action needed beyond proofreading."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"First thing to know: Theorem 4 is the real result and it holds up. The paper shows that if you want a regret-free mechanism to cross the public cascade—get to a coalition bigger than C⁻ without ever exposing anyone in an unsafe roster—you must hold completed, still-private authorizations and release them in one joint act. That necessity result is genuinely new, as far as I can tell, and the proof is careful. I spot-checked the load-bearing steps (the T-iteration bound, the twin-history argument, the Hoeffding bound) and they're consistent. The paper also does a good job marking its boundaries. It separates the cascade (safe incremental public additions) from the tunnel (private collection, joint release) and shows the tunnel reaches the largest safe coalition C⁺. The comparison to Gale (2001) and Braghieri et al. (2026) is honest: the supplement constructs a Gale game that reaches C⁺ under strategic expectations, and shows the exogenous-statistic limit where the two coincide. No overclaiming.\n\nThe soft spot is Assumption 1, monotone protection—safety in numbers. It's doing a lot: it gives you the union-closed structure, the largest safe coalition, and the clean lattice. The paper itself shows what happens when it fails: no greatest roster, NP-hard selection (Prop S9). It retreats to an accessibility kernel in the supplement, and the necessity of a private stage survives there, but the crisp C⁺/C⁻ comparison doesn't. That's a scope condition, not a fatal flaw, and the paper flags it. But anyone applying this should check whether the application really is monotone.\n\nThe behavioral results are benchmark results—full signing is selected by dominance, safe people act rather than wait. The companion paper handles frictions. That's fine.\n\nWho's this for? People working on collective action with irreversible participation, disclosure design, or the theory of escrows and card checks. It's a pure theory paper with complete proofs and no data; don't send it to an editor expecting empirics. It deserves serious peer review. I'd send it to a good theory journal.","headline":"Theorem 4 is the real result—zero-risk crossing of the exposure barrier requires a private holding stage—and the proofs hold up; the monotonicity assumption is a clearly flagged scope limit, not a hidden flaw.","tokens_in":41304,"tokens_out":1982,"would_cite":true,"duration_ms":22739,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Social assurance contracts can carry collective dissent to coalitions that public cascades cannot reach — by collecting completed private authorizations and publishing them in one joint act.","keywords":["social assurance contracts","failure privacy","collective expression","safe coalition formation","regret-free safety","exposure barrier","threshold cascades","disclosure design"],"falsifier":"Find a realistic protection environment in which two safe rosters have an unsafe union — for example, a setting where co-signing with a discredited person measurably reduces an incumbent signer's safety. In such an environment C+ is undefined and the tunnel implementation fails; the paper itself proves the resulting selection problem is NP-hard. A field or structural test could look for exactly this kind of negative-complementarity: if an added high-profile name makes existing signers less safe, then the exposure-barrier crossing may require a different mechanism than the private conditional-r","tokens_in":40279,"feed_emoji":"✍️","tokens_out":3471,"duration_ms":42002,"temperature":0.7,"pith_summary":"The paper claims that a group's inability to speak safely is often not about how many privately agree, but about the order in which names become public. It proves that one-by-one public expression stalls at the smallest self-protecting coalition, C−, even though a larger safe coalition C+ exists. It then proves a structure theorem: any zero-risk institution that reaches beyond C− must first collect completed, still-private authorizations from every named participant and release them in a single joint publication. That procedure — the social assurance contract — is the only way to tunnel beneath the exposure barrier, and it can implement the unique largest safe coalition. The result matters because it pins down which institutional features (privacy, verification, conditionality, joint release) actually do the causal work, regardless of whether the institution is called an escrow, an embargoed letter, or a crypto protocol.","feed_headline":"Hidden signatures unlock safe speech that public cascades cannot","feed_subtitle":"A proof that zero-risk crossing of the exposure barrier requires holding completed consent and releasing names in one joint act.","key_machinery":"The argument runs on two operators. The static-safety operator Γ collects everyone who would be safe if added to a roster; its greatest fixed point is the largest safe coalition C+. The safe-expansion operator T adds only those who are safe given the already-public roster plus their own name; iterating T from the empty seed yields the cascade closure C−. The key identity is C− ⊆ C+, with strict inequality exactly when Γ has multiple fixed points. Lemma 4 is the structural workhorse: guaranteed joint publication requires a private holding stage, because without it every first attribution is an individually completing act and unilateral-completion uncertainty makes the lone-completion realizat","core_discovery":"The central discovery is a fixed-point comparison with a sharp converse. Under monotone protection, there is a unique largest self-protecting coalition C+; a regret-free public cascade can reach only C−, the least fixed point of the safe-expansion operator. The paper proves that any zero-risk mechanism that in some realization moves beyond C− must contain a private conditional-release stage: it must receive completed, still-unattributed authorizations from every named participant other than the author of the release act, and then publish the protecting roster in one joint event. This is Theorem 4, and it makes the institutional label irrelevant relative to the holding sequence. The tunnel th","pith_inferences":["Editorial extension: the representation theorem yields a practical audit rule — any deployed platform claiming zero-risk protection should be checkable for three structural features: hidden completed authorizations, conditional release, and atomic joint publication, because the theorem says no other configuration can cross C−.","Editorial extension: the theory suggests a field experiment on petition campaigns: randomize a controversial letter into an accruing public petition versus an embargoed threshold-release version, holding content and audience fixed. The prediction is that only the embargoed arm attracts signers past the risky early ranks, and that recorded retaliation may rise in that arm even while more signers ul","Editorial extension: a direct consequence the author leaves implicit is that the same holding stage is dual-use — it can protect whistleblowers and also facilitate cartels. Policy on privacy-enabling escrow infrastructure should therefore be judged by the externality of the released coalition, not by the mechanism's label, as the paper's own welfare decomposition indicates."],"forward_implications":["If the result is right, an open letter assembled publicly and an identical letter assembled privately are different institutions in kind, not merely in packaging: the public one is bounded by C−, the private one can reach C+.","Any zero-risk institution that claims to cross the exposure barrier must possess the full bundle — private, completed, conditional, joint — because removing any one of the three properties on a two-agent instance makes the pair unimplementable regret-free (Proposition 1).","Large synchronized public pacts can approach the tunnel's destination in probability but can never enter the zero-risk class at r=0; the discontinuity is economic, not notational (Proposition 2).","Among previously hidden supporters, more observed retaliation can accompany less effective suppression: making silent supporters visible raises recorded punishment while lowering actual suppression (Proposition 5).","Information interventions alone cannot make an isolated first mover safe if no attainable audience belief does; information and failure privacy are complements, not substitutes (Corollary 1)."],"fun_headline_variants":["Private pledges + joint reveal outpace public cascades","Secret signatures unlock speech that public cascades can't","Joint publication of hidden pledges crosses safety barrier","Proof: safe speech requires private commitments and joint release","Tunnel under exposure barrier with private signings and one-shot publish"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"The entire positive theory rests on Assumption 1: adding a name to a public roster never makes an already-listed person less safe; if guilt by association or negative image spillovers can outweigh safety in numbers, there may be no unique largest safe coalition, and the administrator must choose among incomparable rosters.","fun_headline_variants_meta":{"raw":{"variants":["Private pledges + joint reveal outpace public cascades","Secret signatures unlock speech that public cascades can't","Joint publication of hidden pledges crosses safety barrier","Proof: safe speech requires private commitments and joint release","Tunnel under exposure barrier with private signings and one-shot publish"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.00071,"raw_usage":{"total_tokens":2956,"prompt_tokens":588,"completion_tokens":2368,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":332,"completion_tokens_details":{"reasoning_tokens":2291}},"tokens_in":332,"tokens_out":2368,"duration_ms":18902,"temperature":1.0,"reasoning_tokens":2291,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-02T08:23:23.470097+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Find a realistic protection environment in which two safe rosters have an unsafe union — for example, a setting where co-signing with a discredited person measurably reduces an incumbent signer's safety. In such an environment C+ is undefined and the tunnel implementation fails; the paper itself proves the resulting selection problem is NP-hard. A field or structural test could look for exactly this kind of negative-complementarity: if an added high-profile name makes existing signers less safe, then the exposure-barrier crossing may require a different mechanism than the private conditional-r","supporting_citations":[],"review_version":2}