Ledgers are caches — the third book returns
Pacioli described three books; everyone remembers two of them. The memoriale — the merchant's record of what actually happened — quietly died because capture was expensive and abstraction was cheap. That ratio has inverted. What is left to build is the trust layer.
Pacioli described three books. Everyone remembers two of them.
The journal and the ledger survived five centuries because they were cheap: compact abstractions, a few strokes per transaction, auditable by inspection. The third book — the memoriale, the memorandum where the merchant first wrote down what actually happened, in full narrative detail, before any of it became entries — quietly died. Not because it was wrong. Because capturing rich records of raw activity was expensive, and abstracting them was cheap. The profession kept the abstractions and let the evidence layer go.
Every accounting system since has inherited that trade. We record projections of economic events and discard the events. And then, because your projection and my projection of the same trade were keyed separately from separately-gathered evidence, we spend a remarkable share of the profession's total effort making them agree again. Reconciliation is not a natural feature of commerce. It is the deadweight loss of not sharing the scene.
The scene is the primary object
Strip any trade to its skeleton and you get one shared lifecycle: commitment → fulfilment → claim → settlement → receipt. That sequence happened once, in the world, between two parties. It is the primary economic object. Each party's ledger is a projection of it — the lifecycle mapped onto that party's chart of accounts, basis, and policy.
Read accrual accounting through that lens and it becomes interval arithmetic. A receivable is the open interval between claim and settlement. Deferred revenue is settlement arriving before fulfilment. The balance sheet is the set of intervals open at a point in time; the general ledger is the integral of the event stream. Bookkeeping has always computed exactly this — one keystroke at a time, from evidence each side collected on its own, with the disagreements surfacing later as reconciliation items.
None of this is a new observation. William McCarthy formalised it in 1982 — the REA model, resources-events-agents as the proper basis of accounting systems — and it became ISO 15944-4. Ian Grigg's triple-entry work put the sharpest edge on it: the receipt is the transaction — one signed record shared between parties beats two private ones. Kurt Cagle's recent writing on holonic accounting is the newest arrival in the same lineage: the intuition that the entry is a view and the event is the truth keeps being rediscovered, because it keeps being correct.
And it keeps failing. REA tooling, XBRL GL, a decade of triple-entry ventures — the graveyard is well populated, and the cause of death is on every certificate: adoption economics. The thesis always required someone to capture the memorial, and capturing the memorial was the expensive part. Nobody would key it in. The theory was never refuted; it was declined.
What changed
Three preconditions have arrived within a few years of each other, and none of them came from accounting.
The rails. Structured e-invoicing is becoming the default carrier of business activity rather than a compliance curiosity. The EU's ViDA package, adopted in 2025, makes digital reporting and structured e-invoicing the norm for cross-border trade from 2030. Australia has set 2026 deadlines for e-invoicing in federal procurement over the Peppol network, with the B2B network growing underneath. Watch what the regulator is becoming in these designs: not a reader of annual abstracts, but a subscriber to the activity stream.
The capture. Large language models read the unstructured residue — the emails, quotes, contracts and PDFs that surround every deal. The memorial no longer needs to be keyed by hand. The historic killer of the thesis is dead.
Settlement is already event-native. Payment processors emit webhooks; banks emit feeds. The settlement leg of the lifecycle became a machine-readable event stream years ago, and nobody had to argue for it.
One precondition is still missing, and it is not arriving from any standards committee: the trust layer — whatever makes a shared record of the scene admissible between parties whose interests are adverse, and to the auditors, lenders and regulators who rely on it. Representation formats we have in abundance. Warrant is the scarce thing.
Audit is the seam
Here is a claim we are prepared to be wrong about in public: audit transforms before bookkeeping does.
Bookkeeping erodes gradually, business by business, against incumbents who own the ledger and have every reason to defend it. Audit is different. When projection is a pure, replayable function — same scene, same declared policy, same output, every time — audit collapses into recomputation: re-run the function over the evidence and diff the result. Sampling was never a principle; it was a workaround for projections that couldn't be re-run. The audit file of the future is not a folder of PDFs and confirmations. It is a repository you clone and a diff you read.
The risk does not vanish; it changes shape, and honesty requires saying so. In a replayable world, errors are systematic rather than random. One wrong line of policy misstates everything it matches — identically, silently, at scale. That is precisely the argument for policy that is versioned, dated, attested and replayable: the error that once hid across ten thousand keystrokes becomes a one-line diff with a name attached. Where liability concentrates, attention follows. Whoever signs the policy is the accountant of 2035.
What we are building, and in what order
At LodgeiT Labs this programme is called the Scene Protocol, and it is deliberately three components in a specific order.
Mirror comes first — faithful ledger mirrors from the systems businesses already use (Xero, QuickBooks, MYOB). Every predecessor in the graveyard demanded adoption before it delivered value. Mirror inverts that: it delivers against the installed base on day one, no counterparty required, and gives the replay machinery real books to diff against. Scenery is the evidence layer — a canonical, hash-chained, portable export format for scenes; specification in progress. Casting is the policy layer — projection policy as versioned plain-text policy notes, where every resolved exception writes back as a new note: judgment exercised once and accreted, not re-exercised per transaction and not dissolved into a model's weights.
The specification will be prose, and prose is arguable. So the conformance suite is the law: golden files that any implementation — including a competitor's — can run to self-certify, up a ladder from honest export to full interchange. Alongside it, structural anti-capture commitments: the user's own repository is authoritative, hosted copies are caches that lose on conflict, and a host that cannot re-emit your full-fidelity files is nonconforming by definition. We have watched hosting convenience quietly capture open protocols before. The defence has to live in the conformance tests, not in good intentions.
Where this stands
Plainly: we run both sides of a live exchange stack — proposals, invoicing, settlement events, auto-journals — and we are turning it into the first conformance experiment. Nightly replay-diffs over a real engagement cohort; every diff classified; tamper-evidence demonstrated; the standard reports derived from the scene alone.
This is a hypothesis with a falsifier, not a result. If replay-diffs cannot be driven to explainable-zero on a real cohort, the thesis fails, and it fails in public. And a single operator running both sides can prove determinism and tamper-evidence — it cannot prove trust-minimisation between adverse parties. That claim waits for independent implementations exchanging scenes at the top of the conformance ladder.
The third book died because evidence was expensive and abstraction was cheap. That ratio has inverted. The memorial is coming back machine-readable — the only open question is whether its trust layer is built in the open, conformance-tested, and impossible to hold hostage, or arrives as somebody's product. We know which side of that question we are working on.
The methodology behind this programme is public in brain-pattern. The statutory calculators underneath it are verified in the open through the bounty programme, where practitioner reviewers are paid to break our reasoning against statute.