How it holds over time

The boundary is not a setting fixed once; it is a muscle. Open → shock (a spam or malicious influx) → contract (retreat toward the whitelist or web-of-trust floor) → adapt in the between (the stack retunes, developers ship) → re-expand ({{ref:claim-expand-contract|expand–contract}}). Neither pole is the answer — the open pool is exposed, the hard whitelist defeats the purpose of joining a commons — so governance is the retuning between them, and the always-available floor is what licenses the experimentation above it: a credible commitment that failure never costs the commons itself. Each pass through the cycle leaves the option space larger — a new spec, a hackathon output, another web-of-trust function the space did not have before.

This is not an ecological metaphor imported onto Ostrom's framework; it is her own adaptive-management principle instantiated. "Being Prepared for Change" argues that fixed rules fail because they place too much confidence in the current state of knowledge, and that systems allowing change are "suboptimal in the short run but wiser in the long run" (verbatim, with locator, in {{ref:src-analyzing-knowledge-commons|the framework chapter}}). In cybernetic terms — the terms the Ostroms themselves worked in — the cycle is a feedback loop with the meta-level correction Ashby showed self-organization requires, except that on Nostr the correcting level is lateral and plural rather than singular ({{ref:concept-adaptive-governance|adaptive governance}}). One discipline governs this whole section: the observable oscillation is one thing; the maturation conjecture — that contractions grow shallower and recoveries faster until the loop disappears the way HTTPS disappeared into infrastructure — is a longer-horizon hypothesis the design is built to test, and it is always flagged as such ({{ref:q-maturation-hypothesis|maturation hypothesis}}).