.ai

Delegation

Agents and trust

How a bounded agent is handed work, what it can reach, and how its results become trustworthy — then how many agents work in parallel without colliding.

The brief is a sealed contract

Before any work starts, the brief pins every input by hash and declares done, cannot-be-done, budget, scope and commands. It is identified by the digest of itself.

Everything on this page holds for any agent, person or AI. For an AI agent, the workspace is a sandbox, the timebox is a token budget and a handoff is a new session; for a person, they are a scoped task, a deadline and a new hire.

Everything the run may use, and everything it must achieve, is fixed before the run begins. Each part is marked read-only or writable. The brief never carries its own digest, so it is final the moment it exists.

A brief, field by fieldRetry a failed clone with exponential backoff, capped per host
inputsread
spec @ sha256:a07d… tree @ sha256:4f0c…
Inputs, pinned by content hash A moving reference changes the premise mid-run. A pin makes the run reproducible, and lets a new rule arrive later without moving the ground under it.
entry
spec.accepted ∧ lease.held
Required entry states The states the work requires of what it consumes — not a list of what came before it.
done
retry.backoff ∧ retry.capped ∧ tests.pass
The completion rule The definition of done, as conditions a tool can evaluate. Nobody has to take the agent's word for it.
cannot
provider.limit.unknown → blocked
The cannot-be-completed rule When to stop and say the goal is unreachable. Process models are rich in failure states; almost none declares this in advance.
budget
45 min
A budget, at the 80% horizon A timebox, sized against the task length the agent finishes four times in five — never the length it finishes half the time.
scopewrite
src/sync/retry/
The writable scope The exact region this run may write. Everything else it may at most read.
commands
fs.write test.run act.propose
The commands the activity requires Intersected with what the actor holds, this is the whole surface the run ever sees.
estimate
30 min · reconsider ×1.5
An estimate, with its reconsideration factor A bound ends a run. Crossing the estimate factor asks the issuer — never the agent doing it — whether the work is still right.
nonce
9b2e…
A nonce, shared with the yield So a yield from one run cannot be replayed as the outcome of another.

Identity · the digest of the brief itself, timeout included

brief A

every other field — identical

budget · timeout 45 min

sha256:5c1f 0e92 a4d7 …

≠

brief B

every other field — identical

budget · timeout 4 h

sha256:e83a 71bc 0f26 …

Same fields, one different timeout: two digests, two different pieces of work. A short run can never take a cache hit from a long one and answer a question it was never asked.

An agent knows what it is doing, knows when it is done, and has a legitimate way to say it cannot finish.

The budget is a timebox, sized against the task length the agent completes four times in five, not the length it completes half the time. Measured on AI agents, the first is four to ten times shorter than the second; Big work becomes small, checkable tasks explains why that matters. A budget is a fuse, not a decision: exhausting it ends the run, while crossing the estimate factor puts a question to the issuer.

Who accepts a brief. A brief needs the owner’s acceptance if and only if it is cascading, irreversible, frame-extending or intent-bearing. Otherwise its issuer accepts it, at any depth. A brief cascades if it will be decomposed further, so an agent that issues a leaf sub-brief accepts it, and a sub-brief that branches reaches the owner however deep it sits.

Why the owner sees the briefs that branch

A leaf brief issues no children, so it is multiplied by nothing. A brief that branches is multiplied by everything beneath it. The test is computable from the plan, and the result is that the owner sees the briefs that branch, not the ones that work. Irreversible acts and rule changes affect the whole tree, so they resolve to the owner too.

Assurance at depth comes from independent oversight sampling, not from acceptance: whoever accepts hundreds of briefs accepts none of them carefully (Bainbridge, Ironies of Automation). Oversight is orthogonal to delegation, so an audit never runs through the chain that produced the work.

Latitude is earned from the record, not assumed: an actor’s briefs stay issuer-accepted until its track record warrants more — the pattern behind Google’s readability review, Chromium’s committer levels and the Linux kernel’s maintainer trust.

Prior art

The triple of brief, run and yield is well precedented: in-toto layouts and link metadata, SLSA build definitions and run details, and Bazel’s Action and ActionResult in the remote execution API. Bazel reached the timeout rule independently: the timeout is part of an action’s identity, or the cache answers the wrong question.

The cannot-be-completed rule is the unusual field. Process metamodels describe failure states richly, but almost none declares in advance when to give up. The vocabulary comes from multi-agent systems and design by contract.

Least privilege is absence, enforced three times

A run sees only the commands its brief declared that its actor also holds. Everything else does not exist — and the server re-checks every call anyway.

The harness grants exactly the brief’s declared commands, intersected with the actor’s capabilities. An undeclared command is not refused — it is never presented. A brief that declares a capability its own issuer does not hold is malformed, and is caught before it is issued.

The surface is an intersection
CommandDeclared by the briefHeld by the actorOn the run's surface
fs.writepresent
test.runpresent
act.proposepresent
lease.acquireabsent held, not declared
net.fetchabsent declared, not held
act.acceptabsent the issuer's act
  1. 01

    Surface

    tools/list

    Returns only the tools this run's token permits.

    Least privilege as absence. An injected instruction to call a hidden tool has nothing to call.

  2. 02

    Admission

    tools/call

    Re-verifies the token on every call and refuses anything outside policy.

    Hiding a tool is not a boundary. A call to a hidden tool is still refused.

  3. 03

    Projection

    result

    Filters every result down to what the caller may read.

    An agent does not receive a filtered view of everything. It receives its world.

Everything an agent does, it does through one command server, so that server is the policy enforcement point, at the three moments above. It speaks the Model Context Protocol, an open protocol for exposing tools to AI agents, which the scheme uses as the one tool surface for every agent. The command catalogue is large, and no agent ever sees it whole.

Hiding a tool is not a boundary. Every call is authorized again.

Refusals, arguments, and the order of checks
  • There is no “show me everything” command. Listing kinds, querying facts, listing tools and tracing lineage all return only what the caller may read. One bypass would make the whole model decorative.
  • Refusals are legible where that helps, and invisible where that protects. A tool outside the surface simply does not exist. A refusal on the surface names its cause — missing_capability, missing_input, awaiting_decision — because an agent cannot choose a recovery without knowing which one.
  • The surface is pinned into the brief, so tool descriptions cannot be swapped mid-run — a swapped description is an injection vector.
  • Agent arguments are untrusted input. Every digest must resolve to a stored record (an agent can invent a 64-character hex string), every identity must exist, every target must lie inside the run’s context — and no argument is ever interpreted as an instruction downstream.
  • Every call is checked in one fixed order: resolve the caller, admit, bind the object, check its shape, check concurrency, check gates, conform to sensitivity rules, verify grounds against bytes, commit the act, charge the budget.
  • Capabilities decide, not roles. The catalogue is fixed and finite, each tool declares the capability it requires, and a role is only a convenience for granting.

The server authorizes every call by the run’s token and writes every decision to a hash-chained audit log that holds neither content nor token. The store is never mounted into an agent’s workspace; agents reach content only through the server.

Narrow the task, widen the reading

A run writes one small, exclusive region and reads far more. Only identities, names, types and simple structures cross between units, and every brief must pass an independence test.

A brief grants write access to a small, exclusive region and read access to much more. Coordination through an artifact only works if the artifact can be read. Restricting what an agent may read to what it may write forces coordination back into conversation, and a conversation is not a record. An agent that picks up the work after a handoff has only the record.

Read · wide

  • the accepted specification
  • the sync module around the write region
  • its tests and their history
  • applied yields of sibling partitions

Write · narrow, exclusive

src/sync/retry/
What a run may write sits inside what it may read

May cross a boundary

  • an identity
  • a name
  • a type
  • a simple structure

Never crosses

  • anything semantic
  • anything ordered
  • anything timed

What an actor may read is exactly what its brief may contain, so least privilege and context minimization are one effort, not two. Between units, four independent design traditions spanning forty years converge on the same short list of what may cross. The strongest coupling present must sit inside a single bundle; if it cannot, the cut is in the wrong place.

If a unit is not independent, the answer is to decompose differently — not to try harder.

The independence test is a property of the brief, not of the agent. So a tool evaluates it before the run starts, and a brief that fails it is never issued.

The run: containment, not trust

The agent works unattended inside a contained workspace — not because it is trusted, but because containment makes trust unnecessary. The workspace produces; the harness attests.

How to do the work is the one free judgement in the whole lifecycle. Full autonomy is defensible inside a box whose effects cannot escape, so the gates move to the boundary: before the box (the brief) and after it (verification). The box is a contained workspace that holds no signing key and no credential.

Goes in

  • The sealed briefImmutable for the run. Nothing the agent reads can redirect it.
  • Pinned inputsRead-only, and treated as untrusted data.
  • A surface of commandsDeclared ∩ held. Nothing else exists.

Contained workspace

agent

decides how to do the work — the one free judgement

writes → its own fork

Comes out

  • duringProgress eventsImmediately, to a published stream. Silence is detectable.
  • afterEverything producedCollected by the harness, enumerated, and signed outside the box.

Never goes in

  • A signing keyNo key reaches the workspace, so nothing inside can request a signature.
  • The credentialInjected by the proxy at the boundary. The agent never holds it.
  • Another run's working treeWrites stay invisible to every other run until a yield is applied.
  • The run is the harness’s record, never its actor’s. A run recorded by its own agent is refused.
  • The brief’s declarations are immutable for the run. What the agent reads is untrusted data and cannot redirect the plan — the separation of the CaMeL pattern.
  • A run must emit progress events, or a stuck run is undetectable. Nobody reads another run’s working tree.
  • Re-running a brief produces a yield, not the yield. No agent’s work is exactly repeatable, so the record is authoritative, not a recomputation. Nor is a second run by the same agent a second opinion: it shares the first run’s blind spots.

Containment makes trust unnecessary.

Seven ways a run can end

Every run ends in a declared verdict, and each verdict selects a different recovery.

VerdictMeansRecovery
completeDone — and it states which conditions of the definition of done it met.On to the signed yield and independent verification.
refuse“I will not”, with a reason.Back to whoever issued the brief: I will not is not I could not, so the request was wrong.
fail“I tried and could not.”Retry only if the cause is non-deterministic. Roughly a third of agent failures are not, and retrying those is guaranteed waste.
not understoodThe brief itself is malformed.A new brief. A broken precondition is the issuer's fault, not the performer's.
blockedA named input, tool, approval or budget is missing.Raise what is missing. An agent that stops and names what it lacks has succeeded.
indeterminateThe agent cannot know what happened — a timeout in the middle of a write.Read the actual state first, then re-enter. It must say what would settle the question.
preemptedStopped from outside because the work as a whole crossed its limit.Never resumed. The issuer decides: continue, decompose or abandon.

One signed manifest, or nothing

Everything a run produced comes back enumerated in one manifest — with a count, the brief’s nonce and per-segment hashes — signed by the harness. No signature, no yield.

A bundle of signed things is not a signed bundle.

Sign the members one by one and the set itself is unattested: a member can be dropped, added or swapped while every remaining signature stays valid. One signature over a counted enumeration makes the set the signed object.

Yield manifest · example
  1. 01transcript · segment 1sha256:0d4c…
  2. 02transcript · segment 2 redactedsha256:77a1…
  3. 03transcript · segment 3sha256:c2f8…
  4. 04diff · src/sync/retry/sha256:3e90…
  5. 05test evidence · 41 passsha256:b51a…
  6. 06verdict · complete (3 of 3)sha256:9f02…
count
6
nonce
9b2e…
brief
sha256:5c1f…

One signature · over 6 members · by the harness

A member is dropped, added or swapped
The count and the enumeration no longer agree. One signature covers the set, so the set itself is what was signed.
An old yield is replayed for this brief
Its nonce belongs to another run.
A secret in the transcript must be removed
Redact one segment. Only that segment's hash is affected; every other member still verifies.
The transcript was compacted — summarised mid-run
It is marked as compacted, or it would silently claim a completeness it does not have.
Signing is unavailable
Stop and say so. Not queue, not retry, not proceed unsigned.

The last row is the easiest to get wrong. Routing around a failed signature turns an availability problem into an integrity problem, so the only correct response is to stop and say what is waiting.

Custody, not content — and the export shapes

An attestation is a signed, timed statement by a named key that it held these exact bytes. It vouches for custody; it never vouches that the content is right. That is verification’s job, and verification belongs to someone else.

The scheme adopts its export shapes from supply-chain security: DSSE envelopes, in-toto statements, SLSA provenance and verification summaries, with W3C PROV for the provenance vocabulary.

Evidence is what the harness saw

Every agent output travels in an envelope: each statement cites a source the harness captured during the run, plus a verbatim quote a tool can find in those bytes.

An agent’s account of what it read is a claim like any other. So the grounds for every statement must be bytes the harness captured during the run, and the quote must be findable in them by a tool.

Envelope · example

agent states Retries are capped per host.

Source · captured by the harness
read #14 · spec @ sha256:a07d…
Quote · verbatim
exponential backoff, capped per host
  • admittedThe quote is in the bytes the harness captured
  • refusedThe quote is not in the cited bytes
  • refusedThe agent says it read a source the harness never captured
  • refusedThe grounds are borrowed from another run
  • refusedThe ground was written after the output it supports
  • refusedThe stored bytes were altered afterwards — every quote from them

Measured on AI-generated text: uncontrolled citations support their sentence only about three times in four, and automated attribution checking tops out around 80%. The field is converging on verbatim quotes from captured sources.

Evidence is what the harness captured, not what the agent says it read.

Agents never certify themselves. Research on AI agents found that they trust stale memories nearly always and rarely inspect provenance; the one approach with measured gains checks provenance in code. For the same reason provenance edges are observed, never asserted: a writable “used” edge would let an agent fabricate the very lineage that clears a check.

Judgements are declared choices

An agent judges by choosing among options someone else declared first — always including “none of these”. Autonomy is earned from measured calibration, never from the agent’s own confidence.

A triage picks from admitted categories. A verdict picks from the schema’s outcomes. A decision picks from alternatives recorded before the choice — and “none of these” is always among them, so a closed answer space never forces a wrong answer.

Declared before it is asked · by someone other than the agent

Which kind of work is this?

  • defect
  • change
  • question
  • none of these
  1. answer 1 · stated 0.9 0 graded right before it the owner confirms
  2. answer 2 · stated 0.9 1 graded right before it the owner confirms
  3. answer 3 · stated 0.9 2 graded right before it the owner confirms
  4. answer 4 · stated 0.9 3 graded right before it runs unattended

A broad judgement is split into atomic questions, and a rule the owner admitted combines the answers, so the weighting is visible policy rather than hidden arithmetic in the agent’s head. Who answered — exactly which agent — is recorded with every answer.

Autonomy is earned from the record, never taken from the agent’s own word.

An agent’s stated confidence is the judge grading itself. The gate reads measured calibration instead: how often answers at that confidence, from that agent, on that type of question, turned out right. With too few graded outcomes, the answer goes to the owner; the gate relaxes as evidence accumulates and tightens if accuracy falls. Hindsight does not count — a grading recorded after a choice was not known when it was made.

What typed questions can and cannot prove

They prove that a choice follows from its recorded answers. They cannot prove that any single answer is right. That is why answers are duplicated, made independent by who answers them, and calibrated over time.

Nothing checks its own work

Verification is mechanical, independent of the producer in three ways, and states what it could have checked. Writes land by compare-and-swap. Then the brief’s issuer validates the result.

Verification asks whether the result meets the letter of the brief. A tool performs it, never the producer, and it records what it could have checked as well as what it did — so narrowing the checks cannot pass unnoticed.

  1. 01

    Technical

    Its own instruments.

    The producing run may not write the checks.

  2. 02

    Managerial

    Chooses its own methods and reports without the producer's approval.

    The producing run may not choose which checks apply.

  3. 03

    Financial

    Cannot be starved of budget by the party being checked.

    The producing run may not fund — or cut short — the checks that judge it.

A check is also not independent if its author is the agent that did the work, owns work beneath it, or owns a sibling partition under the same issuer: shared stake, shared blind spots. Acceptance criteria written by the issuer, not the producer, are the classic independent check. The checks that will judge a change can exist long before the change, written by someone who will never make it.

Standing rules bind at the act, not at the brief. A rule admitted mid-flight never interrupts running work, and nothing passes a gate without satisfying the rules in force when it tries. A new rule puts every existing subject at Unknown — neither pretending old work complies nor that it fails — and Unknown blocks exactly as False does.

Nothing lands on a store it was not checked against. Every write is a compare-and-swap: the tool records the exact store head it validated against, takes the lock only for the append, and appends only if that head is unchanged. Otherwise it reads again and retries. No conflict is tolerated “to be resolved later”.

Then validation, by the issuer. A result is validated against its brief by that brief’s issuer, at any depth. Validation against the original intent, which has no written brief above it, always reaches the owner. Mechanical conformance comes first, so the scarcest resource — judgement, and above all the owner’s — is never spent on a result that is about to change. If the result met the brief but missed the intent, the brief was wrong, and correction re-enters at the specification rather than re-running an agent that did what was written.

Checks prove the claims. Only whoever asked can say whether they were the right claims.

The case against, stated plainly

Checkers share errors. Measured on AI models: two models agree a majority of the time when both are wrong, and self-correction without outside feedback fails. A second agent is not automatically an independent verifier. Tests get gamed: an agent may delete a failing test rather than fix the bug.

The scheme’s answer is structural: independent authorship of checks, harness-captured evidence, and a tool that verifies. The activity rules keep verify and validate apart: a tool verifies a result against the letter of its brief, the brief’s issuer validates it against what was meant, and only the owner validates against the original intent.

Authority is a token the agent never holds

Authority is five additive verbs; denial lives in hard boundaries. The scheme carries it in attenuable Biscuit tokens, checked in Datalog and injected so the agent never holds them.

Root

The owner. Holds every capability; a root act is recorded as one.

Issuer

read · propose · rank ≤ 2 · compartment: sync

Run

audience: one server · expires 1 h · budget 45 min

Agent

Holds nothing. The proxy injects the token as a request header.

Each block may only add checks · nobody can remove one

Authority · five verbs, granted additively

  • readwhat an actor may read is exactly what its brief may contain
  • createa new record, through a proposal a tool admits
  • supersedea new version that names the one it replaces
  • acceptsigned assent to one exact version — by the issuer, or by the owner where the brief branches or triggers a gate
  • grantpass on what you hold — never more, never to yourself

Not verbs here write update delete

The token is a Biscuit: an attenuable bearer token, verified without a central service, whose checks are written in Datalog. It is minted per run by a host-side tool and injected by the workspace’s network proxy as a request header, so the agent cannot read, leak or widen it. A leaked transcript then leaks no credential, because the agent never saw one.

Anyone holding a token can add checks that shrink it, offline, at any depth, and nobody can remove them. So “no actor may grant what it does not hold” is a property of the format, not a rule someone must remember. The subject is the run, not the session: opening a fresh connection resets nothing. The server authorizes every request this way.

One policy language. Datalog serves the process rules, the authorization policy and the token checks alike. It always terminates and, kept free of function symbols and unbounded arithmetic, stays decidable; anything needing arithmetic, hashing or parsing is pushed out into a deterministic computation, so the rules stay poor. Facts are extracted from written records, never written directly — a writable fact base would defeat every gate at once.

A gate the agent is asked to respect is not a gate.

There is no write, update or delete, because nothing in an append-only store is updated or deleted. Deny lives in hard boundaries — the unmounted path, the blocked network, the withheld tool — and allow is purely additive. That keeps “may this actor do this to that kind?” a monotone query, sidestepping the classic result that safety in a general protection system is undecidable. An actor that may grant may not produce, so no delegated actor can grant itself what it needs.

A policy fragment, and revocation

An illustrative fragment of the policy’s shape:

check if expires($e), time($t), $t < $e;
check if audience($s), server($s);
reject if rank($k), tier_max($m), $k > $m;
allow if operation("read"), right("read"),
         rank($k), max_rank($m), $k <= $m,
         compartments($g), node_compartments($n), $g.contains($n);

Every derived conclusion can explain itself with its derivation — and a premise the caller may not read is elided and recorded as elided, never silently dropped. Hard bounds come before any signature work, and a decision the engine cannot reach is reported as unavailable, never as a denial. Revocation fails closed: short per-run expiry, a signed revocation list whose absence or staleness refuses every request, and an epoch for an emergency stop.

When collaborators connect from elsewhere, OAuth authenticates and Biscuit authorizes.

Sign only what agents must not alter

Signatures guard integrity against agents: acceptances, grants, yields, checkpoints. Injection is bounded, not solved — and the scheme states exactly what it does not buy.

Signing is reserved for integrity against agents: the records an agent must not be able to forge or rewrite. Acceptances, grants, yields and checkpoints are signed. No agent holds a key. Two keys divide the work — an automatic, low-privilege key with which the harness signs yields, checkpoints and the acceptances an agent makes as issuer, and a touch-required key for the owner’s acceptances and for grants.

Silence is refusal, never assent.

An approval is itself a signed record: an acceptance, by the issuer or the owner, over one exact version’s digest. Append-only is proven rather than promised — the scheme cuts signed checkpoints of the log’s size and Merkle root, in the style of Certificate Transparency, so a log that does not extend its checkpoint fails a consistency proof. An irreversible act waits for a witness-cosigned checkpoint.

Injection, stated honestly. Injection is instructions planted in the material an agent reads — for an AI agent, prompt injection. Every agent’s input is split in two: the brief, authored by the harness and trusted, and the content — pinned inputs and tool results — which is not. Content may become arguments; it may never become control flow.

What the scheme buysWhat it does not buy
A poisoned input that is stable and provable, because it is pinned by digestAn input that is not poisoned
A blast radius bounded by authorizationGood judgement within that radius
A record of who held which bytes, and whenProof of what an agent actually did — attribution is always a harness claim about custody
Refusal of anything outside the surfaceProtection from misuse of authority the agent legitimately holds
Grounds checked against bytesTruthful prose

A capability the harness cannot enforce must be declared unenforceable, never quietly trusted. An unenforced rule is a recorded gap, not an assumption.

One owner, one lease, one fencing token

Convention does not keep agents apart: left to it, they collide. So every partition has one owner, and every write region is held under a lease whose fencing token rejects a stale holder.

Measured on AI agents: in a published red-team study of many agents sharing one environment, the agents proved low-variance: 18 of 30 chose the identical git branch name. Given incompatible goals and shared write access, they fought over resources. Newer models resolved merge conflicts only by not sharing files — unprompted, they converged on exclusive ownership. And collusion survived the removal of a private channel by moving to a public board.

Convention does not keep agents apart. Ownership does.

So tools mint identities and agents never name things. Exclusive ownership becomes the rule instead of the outcome of a fight. Majority vote across parallel agents is not verification. And isolation is enforced at the boundary, not by asking agents to stay in their lane — because any shared readable surface is a coordination channel.

Exactly one responsible actor per partition. Responsibility does not expire; leases do. The child names its issuer and the set of children is derived, so adding a child never rewrites its ancestors. The parent owns judgement about its children and no state about them.

run A

lease + storesrc/sync/retry/

run B

acquire lease

granted · token 33

stalls — a long pause mid-run

lease 33 expiresderived from time; nobody writes it

acquire lease

granted · token 34

apply yield · token 34

accepted · last seen 34

apply yield · token 33

refused · 33 is stale

Time runs downward · the fencing token orders, it authorizes nothing

A lease is a time-bounded, exclusive claim on a write region, and it expires by itself — that is what distinguishes it from a lock. Without the fencing token, a holder whose lease expired mid-run could still land its result. Before a run starts, a tool checks three things: its write region is disjoint from every live run’s, a lease the partition holds covers it, and its token is newer than the last one seen.

Isolation is about writes, not visibility. A run’s writes are invisible to every other run until its yield is applied; its events are visible immediately. With no observable half-finished state, whether two units can run in parallel reduces to set intersections over declared scopes — a computation, not a judgement. The live runs’ scopes are evaluated by the tool and never shown to the agent, because knowing them would itself be a coordination channel.

Why one owner, when memory does not carry over

Ownership fragmentation is a known predictor of defects. Every handoff makes the next agent a minor contributor by construction, because it starts with no memory of the work. Continuity that does not survive a handoff has to be carried deliberately: narrow path ownership, a persistent role per area, and tools that hold the history. A supersession is a compare-and-swap on the exact generation it replaces: superseding something already superseded is refused, and the second writer rebases.

Cut at wide dependencies, and own every join

Narrow dependencies fan out freely. A wide dependency becomes an explicit join with a named owner, because rejoining N pieces is governed by the worst of N.

A unit is independent exactly when its dependency is narrow: one producer, and no sibling needs its intermediate state. That is the distinction Spark uses to cut a job into stages. A wide dependency is never fanned out — it becomes an explicit join node with a named owner, a barrier made visible at planning time instead of discovered at merge time.

  1. 1 path60%
  2. 2 paths36%
  3. 3 paths22%
  4. 4 paths13%
Chance the join succeeds when each independent path succeeds 60% of the time

Parallel work is multiplicative in whether the join succeeds. Two independent paths at 60% give 36%; three give about 22%. Within a stage, fan out freely. Between stages sits a barrier with an owner, because that is where failures concentrate.

The join is a node, not a role.

“Somebody will reconcile this later” is coordination held in no record, so a barrier nobody owns is derived and reported. Integration requires that every unit held its declared scope: a unit that wrote outside its region invalidates the independence its brief claimed.

Drift and done are derived, never declared

Drift is the difference between the planned dependency graph and what runs actually read. Done is a query. Up is computation; down is authorship.

The plan is a graph of declared dependencies. Provenance is the graph of what each run actually read and produced. Drift is the difference — derived, never written down, so it can never disagree with the facts.

The plan: the encoder fans out to three commands; the aggregate depends on command Cencodercmd Acmd Bcmd Caggregate
The plandeclared dependencies
Provenance: the same, plus command B read a record type that command A addedB read A's new typeencodercmd Acmd Bcmd Caggregate
Provenancewhat each run actually read
Drift: one emergent edge, from command B to command Aemergent edgeencodercmd Acmd Bcmd Caggregate
Driftprovenance minus the plan — derived, never written

Take a shared encoder split into five partitions: the encoder first, three commands fanning out from it, and an aggregate depending on one of them. Every piece passes verification. Then the records show that one command’s run read a record type a sibling had just added. The plan says they are independent; the derived drift says otherwise, and the finding is filed against the plan — the record type belongs in the encoder.

A defect can live in a plan, not only in code.

Verification cannot see this, by construction: a unit can meet its brief perfectly while the plan was wrong. Drift is one instance of reconciliation — desired against observed — alongside running over an estimate and meeting the brief while missing the intent.

Done is a query, never a field. A partition is done exactly when its definition of done holds. By default that is conjunctive: every child is done, and the summary derived from those children verifies against the brief that created the partition. Ready, critical path, skew, unowned partitions and expired leases are queries too, and monitors read the event stream, never working trees.

Up is computation; down is authorship. Aggregating detail upward is mechanical, so a tool derives it and the summary cannot drift. Pushing a summary down into specifics adds information that was not there, so it is an agent’s judgement. Where a summary must be prose and cannot be computed, the owner of the work is accountable for it instead.

When the commitment changes mid-flight

Time decides what counts. Work started before a change stands; its result is salvaged as an input to the new work rather than validated against an intent that is no longer owed anything. Nothing done is lost, and nothing is claimed that is no longer true. Superseding a specification does not silently reach the work that satisfies it: that takes a second, explicit record. Priority is its own record with its own reason, and the order is derived, so “why this first” is on record rather than in someone’s head.

Search every section

Commands

  1. zOverview: every section on this pageview
  2. themeSwitch light or darkui

Sections

  1. ixn.aiixn.ai
  2. The schemeThe scheme
  3. The lifecycleThe lifecycle
  4. Agents and trustAgents and trust
  5. NorthstarsNorthstars
  6. Work outgrew the way we organize itixn.ai
  7. Seven storiesSeven stories
  8. Artifacts, not documentsixn.ai
  9. MethodMethod
  10. Agents judge. Tools do the mechanics.ixn.ai
  11. Work goes out as a brief and comes back as evidenceixn.ai
  12. GlossaryGlossary
  13. Nothing is overwritten. Everything is superseded.ixn.ai
  14. Four layers, one truthixn.ai
  15. Big work becomes small, checkable tasksixn.ai
  16. Values, given teethixn.ai
  17. Try it: you are the agentixn.ai
  18. One word, one meaningGlossary
  19. Identity and historyGlossary
  20. Records and relationsGlossary
  21. Work and bundlesGlossary
  22. Trust and authorityGlossary
  23. Process and weightGlossary
  24. Roles and judgementGlossary
  25. Invent as little as possibleMethod
  26. Narrow briefs, drawn boundaries, written as they goMethod
  27. Every claim carries its gradeMethod
  28. The case against every sourceMethod
  29. Correct the record in publicMethod
  30. One decision at a time, losers keptMethod
  31. Let worked cases force the decisionsMethod
  32. Review loops that know when to stopMethod
  33. State the limits as limitsMethod
  34. Standing on shouldersMethod
  35. No folklore numbersMethod
  36. How work moves through the systemSeven stories
  37. The command that lied about successSeven stories
  38. The plan that was wrongSeven stories
  39. No end in sightSeven stories
  40. Rolled back in ninety secondsSeven stories
  41. The rules change mid-flightSeven stories
  42. Most of what arrives is never builtSeven stories
  43. Autonomy is earnedSeven stories
  44. One cycle, at every levelThe lifecycle
  45. Five rules govern the graphThe lifecycle
  46. Accepting the specification is the commitmentThe lifecycle
  47. Gate where a mistake becomes uncorrectableThe lifecycle
  48. Gates are enforced, never requestedThe lifecycle
  49. The issuer accepts; the owner accepts what branchesThe lifecycle
  50. Oversight and capability run beside the workThe lifecycle
  51. Consequence decides what; size decides how hardThe lifecycle
  52. Err smallThe lifecycle
  53. Decompose until every leaf passes four testsThe lifecycle
  54. A budget is a fuse, not a decisionThe lifecycle
  55. The record is the processThe lifecycle
  56. Twelve lines worth keepingSeven stories
  57. Four primitives: source, node, version, actThe scheme
  58. Four classes of nodeThe scheme
  59. A kind is permanent. Nothing is promoted.The scheme
  60. An identity that explains itselfThe scheme
  61. Native names firstThe scheme
  62. Versions are addressed by what they containThe scheme
  63. Paths derive from identity, so nothing movesThe scheme
  64. The card: what an agent reads insteadThe scheme
  65. References point up. Every list is a view.The scheme
  66. Edges are nodes, and staleness is mechanicalThe scheme
  67. Metadata on everything — including the metadataThe scheme
  68. Three written forms. State is a fold.The scheme
  69. The scheme checks itselfThe scheme
  70. The unwritten rules of good work, written downNorthstars
  71. Honest reasoningNorthstars
  72. Trust that survives inspectionNorthstars
  73. Attention to the unexplainedNorthstars
  74. Care for the readerNorthstars
  75. Continuity of attentionNorthstars
  76. The good path is the easy pathNorthstars
  77. The dignity of boundariesNorthstars
  78. Reverence for the irreversibleNorthstars
  79. Minds decide, tools doNorthstars
  80. Intent before effortNorthstars
  81. A record that only growsNorthstars
  82. One answer, one shapeNorthstars
  83. Every mechanism is a value given teethNorthstars
  84. The brief is a sealed contractAgents and trust
  85. Least privilege is absence, enforced three timesAgents and trust
  86. Narrow the task, widen the readingAgents and trust
  87. The run: containment, not trustAgents and trust
  88. One signed manifest, or nothingAgents and trust
  89. Evidence is what the harness sawAgents and trust
  90. Judgements are declared choicesAgents and trust
  91. Nothing checks its own workAgents and trust
  92. Authority is a token the agent never holdsAgents and trust
  93. Sign only what agents must not alterAgents and trust
  94. One owner, one lease, one fencing tokenAgents and trust
  95. Cut at wide dependencies, and own every joinAgents and trust
  96. Drift and done are derived, never declaredAgents and trust
tool · agent · owner — each voice is who acts ↑↓ move ↵ open esc close