How Heartwood thinks about proof
A fact in your tree is a conclusion you reached from evidence, not something you typed in. That's the Genealogical Proof Standard, built into how the app works.
Personas vs. people
Assertions attach to a persona — "the John Smith in this 1850 census" — not a stable Person node. Which real person a record describes is itself a conclusion requiring proof, so Heartwood models identity as a refutable claim with its own proof argument, backed by the personas it groups. That claim is un-mergeable and splittable, the same as any other conclusion.
Evidence classes
Every assertion carries an evidence classification — original/derivative and primary/secondary/indirect — and a Genealogical Proof Standard (GPS)-style certainty: proved / probable / possible / disproved. No confidence percentages; decimals are meaningless to methodologists.
The pending lane
AI-origin content lives in a visibly distinct pending lane. It cannot feed a proof argument, be exported as fact, or be shared until a human confirms it against the original source. Confirmation is itself a recorded provenance event. This is the structural version of "AI can't put anything in your tree without you seeing it" — not a promise that AI can't be wrong, but a promise that nothing ships unseen.
Transcriptions are claims, not facts
A transcription is a refutable claim about what a source image says, kept distinct from the image itself — vision models misread handwriting confidently, and conflating the two would let a misreading masquerade as the source.
Negative evidence and conflicts
Negative evidence is first-class: an expectation ("a man this age should appear in the 1870 enumeration"), the null-result search log entry that evidences the absence, and the inference drawn — never expressed as a flag on a positive assertion. Conflicts between contradicting assertions are surfaced and resolved via proof argument, never auto-merged.
Proof arguments
A proof argument is structured, not prose: a conclusion, the supporting assertions with their evidence classes, explicit correlation reasoning, and treatment of contrary evidence — GPS's "analysis and correlation" as data, not a text field.
Honest research logging
The MCP server sees only what your AI reports. Every assertion- or
source-creating tool call requires the search context that produced
it, so the log is a byproduct of evidence capture rather than a
separate, skippable step. Log entries stay agent-reported
until a human marks coverage user-confirmed — an
AI-only log can never satisfy a "reasonably exhaustive research"
claim in a proof argument without that human checkpoint.