One graph, assembled from what properties actually publish rather than from any checkout.
The workflow fetches every published directory fragment over the network and merges them into one estate graph — not read from this checkout. A graph built from local files proves the files are on one machine; a graph built from published URLs proves the estate publishes what it claims and can be reproduced by somebody who does not trust us.
It is also the only shape that lets a node the estate does not own ever join, because federation resolves an authority per repository rather than assuming one build.
A source that cannot be reached is reported and skipped, never silently dropped: a graph that quietly shrinks when a host has a bad afternoon is worse than one that fails loudly, because everything downstream reads it as fact.
That the graph is only what the domains publish, and that provenance is a citation to a declared emitter rather than to nothing. Fetch the same published fragments and re-assemble; an edge signed by an id no fragment declares is a citation to nothing, and the measure says so.
The estate graph is one entity-and-relationship graph assembled from what properties actually publish over the network, not from any checkout — so it proves the estate publishes what it claims, and reports the share of edges that cross a property boundary as the honest test of one graph.
estate graph →