Why DKE is built this way
An answer you can't check is a rumour with better grammar. Most systems resolve contradictions before you see them, discard the question of who said what, and can't tell you what a record said last March. DKE refuses all three — structurally, not as policy.
Provenance has to be structural, not optional.
A system that can record an unattributed fact eventually will. DKE has no verb that writes a value without naming its source — not as policy, as grammar. An unattributed fact isn't disallowed; it's unsayable.
Disagreement is information.
When two sources contradict each other, most systems resolve it before you ever see it — usually by whichever ranked higher. That is the most valuable thing the store was holding, discarded silently. DKE keeps both claims live, counts the sources behind each, and makes you decide.
Time is not metadata.
“What did this record say last March” is the question audits are made of. It shouldn't require a separate warehouse to answer. In DKE, writes carry a validity window and reads carry an as-of instant — the history is the store, not a copy of it.
A system that can't be made to halt can't be relied on.
DKE's language has no while, no recursion, no unbounded loop. Every program terminates, and the same program over the same store gives the same answer. Not a feature — a property you can't switch off. Nothing an agent emits can hang the engine, because there is no unbounded loop to emit.
We publish the contract and keep the engine.
The language specification is MIT and versioned. Write a linter, a formatter, a language server, a competing compiler — the published document is the whole surface, and we're held to it. Your programs, and everything you build around them, outlive any decision we make.