P09-L06 · P09 · P09-M02
Build an evidence graph and test alternate ownership hypotheses
Prerequisites: P09-L05
Learning objectives
- Construct a typed evidence graph and reproducible cohort.
- Compare common-control and shared-service hypotheses fairly.
- Reconcile internal/external flow without identity attribution.
EN source master · P09-L06 · 45 minutes estimated · needs_review
Why this matters
A cluster can be an observation set, an algorithmic grouping or an ownership hypothesis. Using one word for all three invites unsupported attribution. Common funding, similar timing and shared application use can be genuine relationships without proving a common human owner.
This lesson builds an evidence graph, compares explanations and keeps uncertain edges visible. You will grade hypotheses by their support and missing tests rather than assigning a numeric identity confidence without calibration.
Explanation
Define what cluster means here
Start with an explicit membership rule. “Addresses receiving native funds from HUB in window W” defines a reproducible co-funded set. “Addresses controlled by one person” is a stronger hypothesis requiring independent control evidence.
Name the set according to its rule. A co-funded cohort can be useful for further inspection without being an ownership cluster. If a provider's clustering method is not disclosed, preserve its output as a provider assertion with unknown mechanism.
The graph must separate ledger nodes from entity nodes. Addresses, programs and token accounts are inspectable objects. A human or organization node needs separate substantiation. Do not create it merely to simplify the diagram.
Use typed, sourced edges
Each edge needs network, source, target, type, asset/amount where relevant, event locator, context, result and coverage. “Related” is too vague. A native transfer, shared authority field, program derivation and same application call each answer a different question.
Solana result structures distinguish instructions, signers and balances [S09-STRUCTURES]. They provide mechanism fields for inspecting edges, not a built-in human identity. A signature search only discovers referenced-address activity under its scope [S09-SIGNATURES].
For program-mediated nodes, distinguish derivation from ownership. PDAs use program signing rather than a private key [S09-PDA]. A shared program can process many independent users, so deriving multiple addresses from one program does not by itself merge beneficiaries.
Separate observations from hypotheses
Draw successful supplied movement edges as solid lines. Draw hypothesized control links as dashed lines with an explanation. An unavailable possible edge should be marked unknown, not drawn as if measured.
Observed co-funding supports a relationship. It can be consistent with common control, shared custody withdrawals, a public distribution, payroll or another common service. These alternatives are not all proven; they show that the observation does not uniquely determine ownership.
A transfer between two members can strengthen a question about coordination, but it still does not identify a human controller. A business payment, refund or service routing can also connect independent addresses. Test the mechanism rather than counting arrows as identity votes.
Avoid dependent evidence inflation
“Same minute,” “close together” and “same visible batch” may be three descriptions of one timing feature. Do not count them as independent confirmations. Common funding plus same-source timing can also share one underlying operation.
A provider label and an interface label copied from that provider are dependent. Two displays do not double identity evidence. A report should group such claims by upstream source.
No fixed threshold such as “three clues means same owner” is justified by this fixture. A calibrated model would need a defined target, representative ground truth and error analysis. The lesson instead uses explicit qualitative states and falsifiable evidence requests.
Compare competing explanations fairly
Write what each explanation predicts and what would distinguish it. Common control might predict shared authorization evidence or coordinated management, but shared public activity alone is not exclusive. A service-distribution hypothesis might predict many recipients with differing later behavior, but a partial graph cannot establish that wider population.
Seek evidence that could weaken your preferred interpretation, not just examples that fit it. Missing contrary evidence in an incomplete export is not confirmation. If no supplied record discriminates the hypotheses, report them as unresolved.
A valid finding may be “the fixture supports a co-funded cohort; human ownership is insufficiently evidenced.” This is an analysis result, not a failure to do the task. It tells the reviewer precisely where investigation could advance.
Preserve graph and quantity boundaries
A transfer inside a cohort moves inventory between nodes without adding new external funding. Summing all edges measures gross movement, not external inflow or held balances. Reconcile within a declared boundary.
If HUB sends 10 to each of three members and one member later sends 2 to another, external cohort funding is 30. Gross transfer-edge volume including the internal transfer is 32. Cohort inventory remains30 under the zero-fee closed model. These statistics have different names and cannot be substituted.
Do not merge duplicate views of one event. Keep event locators from P09-L02. A call edge has no quantity unless a distinct value effect is supplied. This exercise's application calls carry no additional native amount.
Report relationships without public identity attribution
Keep provider labels, control hypotheses and observed transfers in different sections. Use neutral identifiers throughout. Commercial status, apparent wealth and popularity cannot raise an evidence state.
No graph authorizes a trading signal or a public accusation. Do not identify a real person from funding paths, and do not infer intent from coordinated-looking activity. The educational aim is an auditable graph with alternatives, coverage and next checks.
Key terms
- Cohort: set selected by a disclosed observation rule.
- Ownership hypothesis: proposed shared control needing separate evidence.
- Typed edge: relationship with explicit mechanism.
- Dependent clue: evidence describing the same underlying observation.
- External inflow: movement crossing into the chosen boundary.
- Discriminating evidence: record that distinguishes competing explanations.
Historical example
ILLUSTRATIVE — FIX-P09-06. SIM-CHAIN-A, synthetic T1–T5. Native balances start0 for W1/W2/W3. Complete listed native effects; fees and other effects are0. Cohort rule: receives 10 from HUB during T1–T3.
| Record | Supplied successful operation |
|---|---|
| G1 | T1 HUB→W1,10 NATIVE |
| G2 | T2 HUB→W2,10 NATIVE |
| G3 | T3 HUB→W3,10 NATIVE |
| G4 | T4 W1→W2,2 NATIVE |
| G5 | T5 W1 calls APP, value0 |
| G6 | T5 W2 calls APP, value0 |
| L1 | provider labels HUB “payroll service”; basis absent |
T1–T5 establish synthetic order only, not real seconds. No signatures proving shared authority, authenticated payroll provenance or human identity are supplied. H1=common controller; H2=shared service/public distributor with independent recipients.
What the evidence proves
OBSERVED in fixture: W1/W2/W3 share immediate funding source; W1/W2 also interact with APP; an internal2-unit movement occurs.
INFERRED: All three satisfy the co-funded rule. External inflow 30, internal flow2 and final cohort balance 30 under model assumptions.
What the evidence does not prove
UNKNOWN: Human ownership, payroll affiliation, wider HUB recipient set and APP authorization semantics.
INSUFFICIENT EVIDENCE: Neither H1 nor H2 is uniquely established. Equal funding and nearby synthetic order cannot prove common control; L1 cannot authenticate payroll identity.
Common mistakes
Renaming a co-funded set as one owner; counting timing descriptions as independent clues; drawing guessed edges solid; adding internal movement to external funding; and adopting a service label to settle a hypothesis.
Practical exercise
Build the typed graph and calculate final member balances, external inflow and gross native edge volume. Compare H1/H2 using supplied support and one next check for each. State whether a human-ownership cluster can be reported as proven.
Show worked correction
Worked correction and expected reasoning
Solid native edges are G1–G4; separate zero-value call edges G5/G6. L1 remains a provider annotation, not a verified entity node. Any common-control linkage is a dashed hypothesis.
Final balances: W1=10−2=8, W2=10+2=12, W3=10. Total30. External inflow 10+10+10=30; gross native edge volume30+2=32. Internal flow does not add funding.
Both hypotheses are consistent with co-funding. H1 needs independently supported shared-control evidence; H2 needs authenticated service mechanism and relevant broader distribution records. Neither absence of shared-control proof nor absence of verified payroll proves the rival hypothesis.
Report a co-funded cohort, not a proven human owner. Score out of ten: typed graph (three), balances and flow boundaries (three), fair hypothesis comparison (two), bounded finding/evidence requests (two).
Checklist
- Publish a membership rule.
- Type and source each edge.
- Separate measured relationships from control hypotheses.
- Group dependent clues by mechanism.
- Reconcile boundary-crossing and internal flows.
- Test alternatives and preserve unresolved attribution.
Summary
A useful cluster graph can establish relationships while leaving ownership unresolved. Hypothesis testing requires evidence that distinguishes explanations.
Summary
Common funding is not common ownership. Several timing labels can be one clue. Internal movement changes allocation, not external cohort funding.
Visual specifications
Graph HUB→W1/W2/W3 quantities10 and W1→W2 quantity2; APP call edges distinct and value0. Solid observed edges, dashed H1/H2 control/service possibilities. Show final8/12/10, external30 and gross 32 with separate labels; L1 unverified.
Illustrative co-funded cohort; ownership remains unresolved.
Use deterministic SVG/HTML or charts with units, evidence locators and text alternatives. Navy/black with restrained cyan, electric blue and violet; no decorative or fabricated explorer screenshots. At 390px stack annotations; verify 768px, desktop and Arabic RTL when assets are implemented. Keep identifiers LTR and factual time/edge/axis directions unchanged. Use only the official supplied ZECOIN mark. Both visual records remain specifications.
Tools
WALLET_INTELLIGENCE maps to read-only inspection of public address records, relationships and provenance. Verify supported network, exact identifiers, fields and coverage before any runtime integration; no live provider capability is claimed here. Use the embedded offline exercise if data or paid access is unavailable. No wallet connection, credentials, private key, signature or live trade is required. Missing data stays unknown. Academy progress, creator status, payments and referrals never alter Radar evidence.
Sources & claim boundaries
- Solana RPC JSON Structures — Result metadata, fee, instructions and balances as distinct views. Checked 2026-09-30.
- Solana getSignaturesForAddress — Referenced-address signature history, newest-first order and pagination. Checked 2026-09-30.
- Solana Program Derived Addresses — Program-derived addresses and program signing; no PDA private key. Checked 2026-09-30.
All example records are original ILLUSTRATIVE fixtures, not historical/live chain measurements. Documentation explains mechanisms, not invented amounts or labels. Synthetic chronology is explicitly bounded; observedAt=null is intentional. OBSERVED in an exercise means a supplied fixture record. Re-review documentation and deployed decoding before publication. Provider labels do not establish identity; address control and human attribution require distinct evidence.
Next lesson
P09-L07 after the worked exercise and question review.
Visual specifications
P09-L06-V01
Which relationships are observed and which ownership explanation remains hypothetical?
Illustrative co-funded cohort; ownership remains unresolved.
Graph HUB→W1/W2/W3 quantities10 and W1→W2 quantity2; APP call edges distinct and value0. Solid observed edges, dashed H1/H2 control/service possibilities. Show final8/12/10, external30 and gross 32 with separate labels; L1 unverified.
Three addresses receive10 each from HUB; internal2 reallocates to 8/12/10; app calls and service label do not prove shared human control.
390px stacked annotations and accessible text equivalent; 768px/desktop verification pending
Native RTL labels/layout; identifiers LTR; preserve time, number-axis and transfer direction.
FIX-P09-06
P09-L06-V02
What is observed, inferred, unknown or insufficiently supported?
Illustrative evidence states and attribution boundaries.
Four labelled rows bound to this lesson's record IDs, claim, limitation and next check; never display a human identity or safety verdict.
Four-state evidence table with record locators and uncertainty.
390px stacked annotations and accessible text equivalent; 768px/desktop verification pending
Native RTL labels/layout; identifiers LTR; preserve time, number-axis and transfer direction.
FIX-P09-06
Sources & claim boundaries
S09-STRUCTURES · official_documentation_or_standard
Solana RPC JSON Structures
- Supported claim
- Result metadata, fee, instructions and balances as distinct views.
- Verification boundary
- Primary page inspected; no illustrative ledger values or entity labels independently verified.
- Checked at
- 2026-09-30
https://solana.com/docs/rpc/json-structures
S09-SIGNATURES · official_documentation_or_standard
Solana getSignaturesForAddress
- Supported claim
- Referenced-address signature history, newest-first order and pagination.
- Verification boundary
- Primary page inspected; no illustrative ledger values or entity labels independently verified.
- Checked at
- 2026-09-30
https://solana.com/docs/rpc/http/getsignaturesforaddress
S09-PDA · official_documentation_or_standard
Solana Program Derived Addresses
- Supported claim
- Program-derived addresses and program signing; no PDA private key.
- Verification boundary
- Primary page inspected; no illustrative ledger values or entity labels independently verified.
- Checked at
- 2026-09-30
https://solana.com/docs/core/pda
Dataset provenance
id: FIX-P09-06
dataStatus: ILLUSTRATIVE
observedAt: null
source: Original frozen educational records embedded in this lesson
scope: Closed fictional co-funded cohort, internal transfer, zero-value app calls and unverified label.
identifiers: Invalid training labels; no usable addresses or signatures
timeBasis: Synthetic S/T or SIM-DAY markers explicitly defined in example; no real ledger/UTC observation