Owner-side instruments: how an asset is read from outside
An owner-side instrument reads an asset from the outside, using only what any prospective guest, search engine or answer engine can also see. It writes what it observes into an Asset Record, marks every field with an explicit evidence state, keeps the raw artefacts under replay custody so that any figure can be reproduced, measures change against a counterfactual cohort rather than against last year, and refuses to state a claim that its evidence does not support. It produces a record, not a dashboard.
Why read an asset from outside
The party that owns an asset is rarely the party that operates it, and the operator's reporting is the operator's account of its own work. An outside-in reading is independent of that account. It is also the only reading available before an owner has any right of access, which is when it is most often needed.
The constraint is severe and it is the point. If the instrument depends on nothing but public evidence, the same reading can be taken of any comparable asset, at any time, without asking anyone's permission. That is what makes comparison and repetition possible.
The Asset Record
The Asset Record is the structured account of one asset as it can be observed from outside. It holds the estate that represents the asset, the intent that estate answers and the intent it leaves unanswered, the third-party surfaces that describe it, the reputation signal, and the commercial position visible in public rates and availability.
Each field carries three things with it: the source it came from, the time it was collected, and its evidence state. A field without those three is not a field. It is a rumour, and the record does not carry rumours.
Evidence states, and what fail-closed means
Every field is in one of a small number of declared states rather than being either present or absent.
- VerifiedCollected, checksummed, and reproduced by a second reading within the tolerance the field declares.
- ObservedCollected once, within tolerance, but not yet reproduced. Usable, and marked as such.
- UnverifiedCollected but failing a check: a checksum mismatch, a source that answered differently on a second reading, or a value outside the range the field allows.
- UnavailableThe source could not be reached at all. This is recorded as a fact about the reading, not silently omitted.
Fail-closed is the rule that connects the states to the output. Any statement that depends on an unverified or unavailable field is withheld, and the record says which statement was withheld and why. An instrument that carries on reporting through a source failure is not measuring; it is guessing with a house style.
Replay custody
Every artefact the instrument collects is stored as it arrived, with its checksum, its collection time and the version of the code that read it. Any figure in the record can then be recomputed from those artefacts, and must return the same value.
This is what makes a reading arguable a year later. When a figure is challenged, the answer is not a recollection of how it was produced. The artefacts are replayed and the figure either reappears or it does not, and if it does not, that is a defect in the instrument and is treated as one.
Counterfactual exposure cohorts
An asset that improves in a rising market has told you nothing. Movement is therefore read against a cohort of comparable assets, matched on observable characteristics, that were not exposed to the change being measured.
Cohort construction is the hard part and it is done before the outcome is known, not after. The matching variables, the exposure window and the assets in the cohort are fixed in advance and recorded, so that the comparison cannot be selected once the answer is visible. Validation is rolling-origin: the method is tested on periods it has not seen, with the leakage paths closed deliberately rather than assumed away.
Claim boundaries
Outside-in evidence supports a specific class of statement, and the instrument is built so that it cannot make any other. It can say what is exposed and what is not, what is answered and what is missing, what a third party asserts about the asset, and how the position moved against the cohort.
It cannot attribute a movement in revenue to a change in the estate, because the data required to do so is held by the operator. That boundary is enforced in code: the statement is not available to be written, rather than being permitted and then qualified in a footnote nobody reads. The reasoning behind that design, and the uncertainties still open in it, are set out in the research programme.
Why there are no dashboards
A dashboard implies that every figure on it is current and reliable at the moment it is read. An outside-in instrument cannot promise that, because its sources fail, change shape and rate-limit without notice.
The output is therefore a dated record: what was observed, when, from where, in what state, with what withheld. It can be filed, argued from, and re-read against next year's edition. These instruments are the ones behind the chapters of the Owner's Audit, where they are read as an audit rather than as a screen.
Common questions
-
What is an owner-side instrument?
A measurement system that reads an asset from outside it, using only evidence a prospective guest or an answer engine could also reach. It is owner-side because the owner, not the operator, is the party it reports to, and because it does not depend on being granted access to operating systems.
-
What is the Asset Record?
The structured account of one asset as it can be observed from outside: the estate, the intent it does and does not answer, the third-party surfaces that describe it, the reputation signal, and the commercial position. Every field carries its source, its collection time and its evidence state.
-
What does fail-closed mean here?
That an unverified state blocks the claim. If a source is unreachable, or the collected artefact does not match its checksum, the field is marked unverified and every statement that depends on it is withheld. The instrument reports less rather than reporting something it cannot support.
-
What is replay custody?
Every artefact the instrument collects is stored with its checksum, its collection time and the version of the code that read it. Any figure in the record can be recomputed from those artefacts and must return the same value. A number that cannot be replayed is treated as a defect.
-
What is a counterfactual exposure cohort?
A set of comparable assets, matched on observable characteristics, that were not exposed to the change being measured. Movement is read against the cohort rather than against the same asset last year, because a market-wide movement is not evidence of anything the owner did.
-
Does the instrument prove that a change caused revenue?
No, and it says so. Outside-in evidence supports statements about exposure, coverage, accuracy and position. Attribution to revenue requires operator data the instrument does not hold. That boundary is enforced in code rather than stated in a footnote.
-
Why are there no dashboards?
A dashboard implies that a figure is current and reliable at the moment it is read, which an outside-in instrument cannot promise. The output is a dated record with stated evidence states and stated limits, which can be filed, argued from and audited later.
-
Does the operator have to cooperate?
No. The instrument reads only what is already public. Operator cooperation improves the depth of what can be said, and where it is given the record states which fields depend on it.
-
Is this the same as an SEO audit?
No. An SEO audit reports rankings and recommendations against a tool's own index. An owner-side instrument records observable state with its evidence, withholds what it cannot verify, and is designed so that the same reading can be reproduced a year later.