<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>intent-driven-development on tomrochette.com</title>
    <link>https://tomrochette.com/tags/intent-driven-development/</link>
    <description>Recent content in intent-driven-development on tomrochette.com</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>tom@tomrochette.com (Tom Rochette)</managingEditor>
    <webMaster>tom@tomrochette.com (Tom Rochette)</webMaster>
    <copyright>© 2026 Tom Rochette</copyright>
    <lastBuildDate>Sun, 11 Oct 2026 01:18:07 -0400</lastBuildDate><atom:link href="https://tomrochette.com/tags/intent-driven-development/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>Specifications Are Lossy Compression</title>
      <link>https://tomrochette.com/specifications-are-lossy-compression/</link>
      <pubDate>Sun, 11 Oct 2026 00:00:00 +0000</pubDate>
      <author>tom@tomrochette.com (Tom Rochette)</author>
      <guid>https://tomrochette.com/specifications-are-lossy-compression/</guid>
      <category>ai</category><category>software-engineering</category><category>llm</category><category>ai-agents</category><category>specification</category><category>formal-methods</category><category>intent-driven-development</category><category>fully-ai-generated</category><category>llm=deepseek-v4.1-flash</category>
      <description>&lt;p&gt;Every document we write before the code is a compressed copy of the code, and the compression drops information.&#xA;A requirement, a user story, a specification, a BDD scenario, and a unit test are each a smaller description of a larger artifact.&#xA;&lt;strong&gt;None of them can reproduce the code they describe, so all of them lose something, and an LLM agent fills the missing part with a confident guess.&lt;/strong&gt;&#xA;The useful question is not how to write a better description.&#xA;It is which ways of defining software can carry the whole program, and where the missing part should go for the ones that cannot.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Lossy is a precise word&#xA;    &lt;div id=&#34;lossy-is-a-precise-word&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#lossy-is-a-precise-word&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;The idea of measuring an artifact by the shortest description that reproduces it comes from &lt;a href=&#34;https://en.wikipedia.org/wiki/Kolmogorov_complexity&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=en.wikipedia.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;Kolmogorov complexity&lt;/a&gt;.&#xA;The Kolmogorov complexity of a string is the length of the shortest program that outputs it, and a description is lossless when the original can be reconstructed from it exactly, the way a decompressor reconstructs a file.&#xA;&lt;strong&gt;A definition of software is lossless when a machine can decide, without a person, whether any candidate implementation is acceptable.&lt;/strong&gt;&#xA;Reconstruction is the stronger test, since the definition would have to determine exactly one program.&#xA;Decidability is the test that matters, since it lets a checker accept every correct program and reject the rest.&lt;/p&gt;&#xA;&lt;p&gt;A program carries two kinds of information, and only one of them is about behavior.&#xA;The first is what the program must do, which is its inputs, its outputs, and the rules that connect them.&#xA;The second is how it does it, which is the data structures, the order of operations, the split into modules, the names, and the tradeoffs between speed and memory.&#xA;A prose artifact tries to carry the first kind and drops the second almost entirely.&lt;/p&gt;&#xA;&lt;p&gt;The second loss is larger than the first.&#xA;Prose states behavior in natural language, and the meaning of a sentence depends on the reader.&#xA;Two readers, or one reader on two days, will turn &amp;ldquo;the service should stay available during a deploy&amp;rdquo; into different code, because the sentence never fixed what available means, how long a deploy may take, or what happens to requests already in flight.&#xA;&lt;strong&gt;A natural-language specification is lossy twice.&lt;/strong&gt;&#xA;&lt;strong&gt;It drops the implementation choices, and it leaves the behavior it does state open to interpretation.&lt;/strong&gt;&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Why the loss stopped being benign&#xA;    &lt;div id=&#34;why-the-loss-stopped-being-benign&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#why-the-loss-stopped-being-benign&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;For most of software&amp;rsquo;s history the reader of a requirement was a person, and by reader I mean whoever turns the definition into code.&#xA;The person absorbed the loss.&#xA;A person carried context between documents, inferred the unstated from experience, and asked a colleague when a sentence was ambiguous.&#xA;The loss was worth accepting, because the thing it saved was the expensive one, which was writing the code.&#xA;Compressing a large program into a small document saved the effort of producing the program.&lt;/p&gt;&#xA;&lt;p&gt;Both conditions have changed.&#xA;The reader is now an agent that begins with no history, so anything the definition does not state is absent, and the agent fills the absence with a plausible guess instead of a question.&#xA;The cost of producing code has also fallen far enough that compressing it to save writing no longer pays.&#xA;&lt;strong&gt;The expensive artifact is now the verified definition, and the document that used to save work has become the place where the work is lost.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;../the-prompt-is-the-source-code/index.md&#34; &gt;The Prompt Is the Source Code&lt;/a&gt; described this failure from the maintenance side, where the code reaches the maintainer without the intent that produced it and the next maintainer has to reconstruct that intent.&#xA;This piece locates the same failure one step earlier, in the definition itself, and asks what a definition would have to be to keep the information rather than lose it.&#xA;Keeping the prompt is necessary but not sufficient, because the prompt is the best available record of the intent and the checker is what turns that record into a lossless definition.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;No set of words will be lossless&#xA;    &lt;div id=&#34;no-set-of-words-will-be-lossless&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#no-set-of-words-will-be-lossless&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;The search for a perfect prose specification has no solution.&#xA;By the definition of Kolmogorov complexity, the shortest description of an object that cannot be compressed is about as long as the object, so a natural-language description that determined a nontrivial program would be at least as large as the program and no easier to read.&#xA;A shorter document always leaves something out, and the thing it leaves out is the behavior and the choices that made the program complex.&lt;/p&gt;&#xA;&lt;p&gt;A picture of the recovery sense of loss makes the gap concrete.&#xA;It shows how much of the program each form brings back, which is the intuitive sense of compression.&lt;/p&gt;&#xA;&lt;figure&gt;&lt;img&#xA;    class=&#34;my-0 rounded-md&#34;&#xA;    loading=&#34;lazy&#34;&#xA;    decoding=&#34;async&#34;&#xA;    fetchpriority=&#34;low&#34;&#xA;    alt=&#34;Six horizontal bars of equal total length, labeled from top to bottom: the code, executable specification, checked specification, property test, example test, and prose requirement. The solid blue part of each bar is what the definition brings back and it shrinks from top to bottom; the faded remainder is what the reader supplies.&#34;&#xA;    src=&#34;https://tomrochette.com/specifications-are-lossy-compression/images/artifact-compression.svg&#34;&#xA;    &gt;&lt;/figure&gt;&#xA;&lt;p&gt;The code bar is full here because the picture measures the artifact, the behavior and the choices together.&#xA;What the code itself leaves out is the reason it exists, which the picture does not measure.&#xA;A checkable definition is also stronger than this picture suggests, because it is lossless in the decidability sense even when it recovers only part of the implementation.&lt;/p&gt;&#xA;&lt;p&gt;If the definition cannot be a shorter description in another language, it has to be one of three things.&#xA;It can be the same object, which is the code itself or something a compiler turns into the code.&#xA;It can be a statement a machine can check against the code.&#xA;Or it can be a record of the choices the first two cannot carry.&#xA;Three ways cover the first two, and a fourth covers the residue.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Four ways to remove the loss&#xA;    &lt;div id=&#34;four-ways-to-remove-the-loss&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#four-ways-to-remove-the-loss&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&#xA;&lt;h3 class=&#34;relative group&#34;&gt;Make the definition the source&#xA;    &lt;div id=&#34;make-the-definition-the-source&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#make-the-definition-the-source&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h3&gt;&#xA;&lt;p&gt;The first way is to stop describing the code and generate it.&#xA;A domain-specific language, a schema, or a model is the source of truth, and a compiler turns it into the artifact, so no separate description exists to lose anything.&#xA;&lt;a href=&#34;https://en.wikipedia.org/wiki/Literate_programming&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=en.wikipedia.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;Literate programming&lt;/a&gt; is the older form, where Knuth&amp;rsquo;s tooling tangles a document into compilable code and weaves it into readable documentation from one source, so the two cannot drift apart.&#xA;The loss is zero for everything the language can express.&#xA;The cost is that you maintain the compiler and the language, and anything the language cannot express falls outside the definition.&lt;/p&gt;&#xA;&#xA;&lt;h3 class=&#34;relative group&#34;&gt;Make the definition checkable&#xA;    &lt;div id=&#34;make-the-definition-checkable&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#make-the-definition-checkable&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h3&gt;&#xA;&lt;p&gt;The second way is to write the definition in a form a checker can decide against, even when a person still reads it.&#xA;A &lt;a href=&#34;https://en.wikipedia.org/wiki/Refinement_calculus&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=en.wikipedia.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;refinement calculus&lt;/a&gt; specification is a program written in a nondeterministic language, and the executable code is a refinement of it, produced by steps that preserve the specification&amp;rsquo;s behavior.&#xA;Tools in this family, such as &lt;a href=&#34;https://dafny.org/&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=dafny.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;Dafny&lt;/a&gt; with its Hoare-style contracts and the &lt;a href=&#34;https://en.wikipedia.org/wiki/B-Method&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=en.wikipedia.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;B-method&lt;/a&gt; built on refinement, let you state preconditions, postconditions, and invariants, then either prove the code satisfies them or report the proof obligations you still owe.&#xA;The definition is lossless about the properties it names and silent about the rest, which is the same relativity &lt;a href=&#34;../intent-driven-development/index.md&#34; &gt;intent-driven development&lt;/a&gt; describes when it says intent is lossless only for the questions it answers.&lt;/p&gt;&#xA;&lt;p&gt;The type is the smallest checkable definition.&#xA;Under the &lt;a href=&#34;https://en.wikipedia.org/wiki/Curry%E2%80%93Howard_correspondence&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=en.wikipedia.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;Curry-Howard correspondence&lt;/a&gt;, a type is a proposition and a program is a proof of it, so the compiler checks that the program satisfies the claims the type makes.&#xA;The correspondence is exact in a total language such as Coq or Agda.&#xA;In a Turing-complete language general recursion lets a program inhabit almost any type, so the compiler checks type soundness rather than a theorem.&#xA;Dependent and refinement types push the claim closer to the behavior you care about, which is why moving a rule into the type so that a wrong value cannot be constructed is a definitional move rather than a stylistic one.&lt;/p&gt;&#xA;&#xA;&lt;h3 class=&#34;relative group&#34;&gt;Make the definition generative&#xA;    &lt;div id=&#34;make-the-definition-generative&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#make-the-definition-generative&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h3&gt;&#xA;&lt;p&gt;The third way is to have a procedure construct the code from the definition.&#xA;Deductive &lt;a href=&#34;https://en.wikipedia.org/wiki/Program_synthesis&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=en.wikipedia.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;program synthesis&lt;/a&gt;, as in the Manna and Waldinger framework, treats the specification as a theorem and derives a program from its proof, so the result is correct by construction.&#xA;Modern synthesizers improve the search rather than the idea.&#xA;Syntax-guided synthesis constrains the space with a grammar, and counterexample-guided synthesis alternates a generator with a verifier until the verifier runs out of counterexamples.&#xA;The loss is zero for the synthesized part.&#xA;The cost is that synthesis does not scale to arbitrary systems, so it applies to small, well-specified pieces rather than whole products.&lt;/p&gt;&#xA;&#xA;&lt;h3 class=&#34;relative group&#34;&gt;Record the residue&#xA;    &lt;div id=&#34;record-the-residue&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#record-the-residue&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h3&gt;&#xA;&lt;p&gt;The fourth way accepts that some information cannot follow from behavior at all, and writes it down on purpose.&#xA;The choice of a data structure, the decision to trade latency for throughput, and the reason a boundary was drawn where it was do not follow from what the program must do, so no behavioral definition can carry them.&#xA;They have to be recorded as decisions with the reasoning attached, because the next agent that meets the same fork will decide it again and may decide it differently.&#xA;&lt;strong&gt;This is the channel that carries what the specification cannot, which is why a decision record is part of a definition rather than a note about one.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;The four ways are layers rather than a menu.&#xA;The definition is lossless wherever at least one of them applies.&#xA;The generated layer produces exact artifacts, the checked layer decides stated properties, and the recorded layer preserves named choices.&#xA;What is left over is genuinely free, and marking it free is part of the definition.&lt;/p&gt;&#xA;&lt;figure&gt;&lt;img&#xA;    class=&#34;my-0 rounded-md&#34;&#xA;    loading=&#34;lazy&#34;&#xA;    decoding=&#34;async&#34;&#xA;    fetchpriority=&#34;low&#34;&#xA;    alt=&#34;A two by two grid. The horizontal axis runs from interpreted by a reader to decided by a machine, and the vertical axis runs from describes the code to produces the code. Requirements and BDD scenarios sit in the interpreted, describes quadrant. A prompt without a checker sits in the interpreted, produces quadrant. Types, checked specifications, and property tests sit in the machine, describes quadrant. An executable DSL and synthesis sit in the machine, produces quadrant. Only the machine column is lossless.&#34;&#xA;    src=&#34;https://tomrochette.com/specifications-are-lossy-compression/images/definition-quadrants.svg&#34;&#xA;    &gt;&lt;/figure&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;The agent is a synthesizer, not an oracle&#xA;    &lt;div id=&#34;the-agent-is-a-synthesizer-not-an-oracle&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#the-agent-is-a-synthesizer-not-an-oracle&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;An LLM can work at every layer above.&#xA;It can compile a DSL into code, draft a refinement with proof obligations, synthesize from a specification, and apply recorded decisions to a new case.&#xA;It cannot make the definition lossless on its own, because losslessness is a property of the checker rather than the writer.&#xA;The model produces candidates, the checker decides which candidate is acceptable, and the loop is counterexample-guided synthesis with a model as the generator.&lt;/p&gt;&#xA;&lt;p&gt;This reframes what to build first.&#xA;The instinct is to spend the effort on the prompt and the description, because that is what the model reads, and to treat the checker as a later quality step.&#xA;That order is backwards.&#xA;&lt;strong&gt;Removing the checker leaves a lossy prose definition with a confident reader, which is the situation the model makes worse rather than better.&lt;/strong&gt;&#xA;A definition is lossless only if it can reject the model&amp;rsquo;s output, so the checker is the first thing to build and the prompt is the second.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://tomrochette.com/rethinking-code-review-in-the-age-of-llms/&#34; &gt;Rethinking Code Review in the Age of LLMs&lt;/a&gt; reached the same conclusion from the review side, and &lt;a href=&#34;../when-agents-solve-problems-you-cannot-check/index.md&#34; &gt;When Agents Solve Problems You Cannot Check&lt;/a&gt; reached it from the verification side.&#xA;When implementation is cheap, the scarce resource is a way to tell a correct implementation from a plausible one, and that way is the definition.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Choosing the strongest form you can afford&#xA;    &lt;div id=&#34;choosing-the-strongest-form-you-can-afford&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#choosing-the-strongest-form-you-can-afford&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Not every project can carry a refinement proof, and the point is not that it should.&#xA;For each property you care about, there is a strongest available form, and the forms sit on a ladder.&lt;/p&gt;&#xA;&lt;table&gt;&#xA;&#x9;&lt;thead&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;Form of the definition&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;What it decides&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;What it drops&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;Cost&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&lt;/thead&gt;&#xA;&#x9;&lt;tbody&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Prose requirement&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Nothing, a person decides&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Behavior detail, every implementation choice&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Low to write, high to interpret&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;User story&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Nothing, a person decides&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Behavior, edge cases, choices&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Low&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;BDD scenario&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Whether the code passes the named scenario&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Everything the scenario does not name&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Moderate&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Example test&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Whether the code passes the example&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;General behavior, unstated cases&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Low&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Property test&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Whether the property holds across generated inputs&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Properties not stated, the choices&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Moderate&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Executable specification&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;The artifact, exactly&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Only what the language cannot express&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;High upfront, no drift&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Refinement or proof&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Whether the code satisfies the stated property&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Whatever the property leaves free&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Very high&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Decision record&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;What was chosen and why&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Nothing recorded, whatever is left unwritten&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Moderate&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;The code&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;The artifact itself&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;The reason it exists&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;The artifact itself&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;p&gt;Read the table as rungs rather than a ranking of teams.&#xA;Push each property as far down the ladder as the budget allows, from a prose sentence to a scenario, from a scenario to a property, from a property to a checked specification, and from a checked specification to an executable one.&#xA;Then move the choices the ladder cannot carry into decision records.&#xA;The prose does not disappear, since it becomes a view generated from the definition for human readers, and a &lt;a href=&#34;https://en.wikipedia.org/wiki/Bidirectional_transformation&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=en.wikipedia.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;bidirectional transformation&lt;/a&gt; view is the formal version of a view that can be written back without loss.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;What to Do Next&#xA;    &lt;div id=&#34;what-to-do-next&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#what-to-do-next&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Name the properties you care about, because a definition can only be lossless relative to a stated equivalence.&lt;/li&gt;&#xA;&lt;li&gt;For each property, use the strongest form you can afford, choosing executable over checkable, checkable over property-tested, property-tested over example-tested, and example-tested over prose.&lt;/li&gt;&#xA;&lt;li&gt;Build the checker first and the prompt second, so the definition can reject the model&amp;rsquo;s output rather than only request it.&lt;/li&gt;&#xA;&lt;li&gt;Mark the choices that are free by design, and record every other choice as a decision with its reasoning.&lt;/li&gt;&#xA;&lt;li&gt;Treat requirements and specifications as views generated from the definition, so the two cannot drift.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The habit worth breaking is treating a lossy artifact as a complete one.&#xA;A requirement is a lossy projection of the code rather than a smaller copy of it, and the projection always omitted the part the reader supplied.&#xA;Where the reader no longer asks, the definition has to supply that part, and the only definitions that can are the ones a machine can run or check.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;See also&#xA;    &lt;div id=&#34;see-also&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#see-also&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;../intent-driven-development/index.md&#34; &gt;Intent-Driven Development: Writing Intent an Agent Can Consume&lt;/a&gt; - the same argument from the intent side, where intent is lossless only for the questions it answers and the rest is an intent gap&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;../intent-driven-development-vs-my-sdlc-pipeline/index.md&#34; &gt;Intent-Driven Development vs My .sdlc Pipeline&lt;/a&gt; - how a feature-level artifact chain renders the definition checkable by pairing every artifact with a review&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;../the-prompt-is-the-source-code/index.md&#34; &gt;The Prompt Is the Source Code&lt;/a&gt; - what the loss costs the maintainer once the intent is gone; this piece locates the loss in the definition itself&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/rethinking-code-review-in-the-age-of-llms/&#34; &gt;Rethinking Code Review in the Age of LLMs&lt;/a&gt; - value moves upstream to the definition when implementation is cheap, which is why the checker matters more than the prompt&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;../when-agents-solve-problems-you-cannot-check/index.md&#34; &gt;When Agents Solve Problems You Cannot Check&lt;/a&gt; - the verification side of the same problem, and why stating correctness stays a human responsibility&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;../invest-in-verification/index.md&#34; &gt;Invest in Verification&lt;/a&gt; - where to spend when producing code is cheap, which is the checker rather than the generator&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;References&#xA;    &lt;div id=&#34;references&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#references&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/Kolmogorov_complexity&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=en.wikipedia.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;Wikipedia, &amp;ldquo;Kolmogorov complexity&amp;rdquo;&lt;/a&gt; - the shortest program that outputs an object, which grounds lossless compression and the impossibility of a shorter lossless description&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/Refinement_calculus&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=en.wikipedia.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;Wikipedia, &amp;ldquo;Refinement calculus&amp;rdquo;&lt;/a&gt; - a specification refined by correctness-preserving steps into executable code&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/Curry%E2%80%93Howard_correspondence&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=en.wikipedia.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;Wikipedia, &amp;ldquo;Curry-Howard correspondence&amp;rdquo;&lt;/a&gt; - a type as a proposition and a program as its proof, the smallest checkable definition&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/Program_synthesis&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=en.wikipedia.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;Wikipedia, &amp;ldquo;Program synthesis&amp;rdquo;&lt;/a&gt; - deductive synthesis, syntax-guided synthesis, and counterexample-guided synthesis, which construct code from a specification&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/Literate_programming&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=en.wikipedia.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;Wikipedia, &amp;ldquo;Literate programming&amp;rdquo;&lt;/a&gt; - one source woven into documentation and tangled into code, so the two cannot drift&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/Bidirectional_transformation&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=en.wikipedia.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;Wikipedia, &amp;ldquo;Bidirectional transformation&amp;rdquo;&lt;/a&gt; - the get and put lens laws, which formalize when a view of data can be written back without loss&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://dafny.org/&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=dafny.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;Dafny&lt;/a&gt; - a language whose checker proves the code satisfies its stated preconditions, postconditions, and invariants&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/B-Method&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=en.wikipedia.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;Wikipedia, &amp;ldquo;B-Method&amp;rdquo;&lt;/a&gt; - a formal method that refines an abstract specification into executable code&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
      
    </item>
    
  </channel>
</rss>
