Methodology · version 1.0
How the Ledger counts
The headline number is a public claim about real water, so it is held to the standard a public claim deserves. Nothing enters it except confirmed, hard-earned gallons: not modeled, not projected. Gallons somebody can point at.
Cleared all three steps and human review. This is the headline, the leaderboard, and every place the number is stated as fact.
Saved scenario deltas that have not been implemented or confirmed. Always labeled modeled. Never summed into the headline.
A real number is worth more than a fictional 318 million. The day someone audits this method, and in this industry someone will, the answer needs to be boring.
The three steps
The claim is filed against a Site and one System, carrying its baseline and proposed Scenarios, the makeup chemistry and parameters for both states, an implementation date, and a short narrative of what actually changed. The delta is computed by the shared diff engine, never typed in.
A countersigned one-page form from the facility acknowledging the change and its date, and permitting the anonymized result to be published. It carries no forward-looking numbers; that would make it a performance guarantee.
A person checks that the numbers, the evidence, and the story agree, then approves, rejects with a canned reason, or asks for more. Only after all three does an entry become confirmed and touch the headline.
Evidence hierarchy
Every claim is ranked by its best available evidence. A water bill before and a water bill after cannot be argued with. That is the whole ballgame.
| Tier | Evidence | Review posture | Credit |
|---|---|---|---|
| A | Utility bills (water, sewer, gas), at least three months either side | Strongest possible. Verify seasonality and that the meter serves the system claimed. | full |
| B | Makeup meter readings with dates and duration | Strong. Check the meter serves only this system. | full |
| C | Controller trend data or logged conductivity plus a mass balance | Moderate. Check the tracer and that blowdown was not just retimed. | full |
| D | Spot readings plus the model, nothing continuous | Insufficient alone. Accepted only with an agreement and a plausible narrative, credited at 50%. | 50% |
Caps, guards, and retirement
A system cannot return more than its own annual makeup. The ceiling comes from the baseline model and the credit is clamped to it.
Keyed on site, system, and change type. Re-saving the same optimization does not re-credit, which is what makes the number un-inflatable by anyone with a calculator.
The delta is credited once, on an annualized basis, for changes still in service. Stated here so it cannot drift.
A spot-reading claim is credited at 50% of the computed delta and labeled as such. If the evidence is weak, the number should be too.
If a system is later saved back toward baseline, its entry is retired and listed on this page. Nothing disappears quietly.
A worked example
A 420-ton hospital tower ran at 3.9 cycles as found. The rep raised it to 6.0 after confirming the makeup chemistry supported it, and filed a claim against the site.
| Line | Value | Where it came from |
|---|---|---|
| Baseline, as found | 3.9 cycles | scenario, pinned |
| Proposed, implemented 2026-04-14 | 6.0 cycles | scenario, pinned |
| Annual makeup, baseline | 8.38 Mgal | mass balance |
| Annual makeup, proposed | 6.17 Mgal | mass balance |
| Computed delta | 2.21 Mgal/yr | diff engine |
| Cap check, baseline annual makeup | 8.38 Mgal | not binding |
| Credited, Tier A, full | 2.21 Mgal/yr | confirmed |
The delta is computed by the same diff engine that runs scenario comparison and the bid rollup: one implementation, never typed in. The bills covered four months either side, so the claim is Tier A and credited in full. Had it been spot readings only, it would have been credited at half and labeled Tier D on the claim itself.
Review, and who does it
One human reads every claim at launch. Rejection reasons are canned and accumulate into a published rubric; once the rubric exists, Tier A claims under a threshold auto-approve on completeness and everything else stays human. The long-term answer is peer verification, two CWTs from companies other than the submitter’s signing off, which is how this industry already validates things.
While a claim is in review it sits pending, visible only to the submitter, labeled in review. No public number moves until it is confirmed. Methodology version 1.0: every confirmed entry records the version it was judged under, so a method change never silently rewrites history. Retirements are listed here, not deleted.
Filing a claim
A claim rides two saved Scenarios of one System, baseline and proposed, and the diff engine between them. Those arrive with My Sites, the next phase of the build, and the claim form and the review queue open with them. Until then the number above is zero on purpose.