Fourteen bodies of prior art: what each is, the part the scheme takes, the part it leaves, the case against each — and what the scheme defines where none reaches.
Each entry links to the source itself. Open The case against on any card: every source carries one.
01Causality
W3C PROV
The W3C's model of provenance: entities, the activities that use and generate them, and the agents responsible.
We take The backbone. Every artifact is related to another through the activity that consumed one and produced the other.
We leave RDF as the storage
The case against
PROV has no notion of correction or supersession in an append-only store, and its alternateOf is, in its own words, “a necessarily very general relationship”. Having provenance is also not using it: measured on AI agents, those with memory inspected it in about one episode in five.
02Versions and history
Git
The version-control system whose content-addressed objects, commits and branches made history cheap and trustworthy.
We take Its model: immutable versions, events that move pointers, drafts as branches, acceptance as a merge, corrections as new commits.
We leave a .git folder, squash and rebase
The case against
Git's tooling provides little of what the scheme needs, and a store that looks like a repository risks being treated as one by Git itself — so the store uses none of Git's file or folder names.
03Attestation
in-toto, SLSA and DSSE
The software supply chain's standards for signed statements about what was built, from what, and by whom.
We take The shape of a brief, a run and a signed result, addressed by the digest of the specification — and the rule that the harness signs, never the agent.
We leave the in-toto bundle format
The case against
SLSA's gold standard is reproducibility, which judged work cannot supply. Per-line signatures in the bundle format leave deletion and replay undetectable. And a signature proves less than people assume: not when, not completeness, not intent.
04Append-only, proven
Transparency logs
Merkle-tree logs — Certificate Transparency, Go's checksum database, witness cosigning — that make deletion detectable.
We take Signed checkpoints and consistency proofs, so “nothing was removed” is a proof, not a promise. Irreversible acts wait for a witness.
We leave content addressing as the whole answer
The case against
A misbehaving log can show different views to different clients, and the fix is still “an active area of research”. Every transparency design ends in “somebody else must look”; an unwatched log is a cost with no benefit.
05Rules
Datalog
A decades-old logic language that is decidable, terminating and able to explain every answer it gives.
We take One rule language for every gate, so each “blocked” comes with a proof tree of why.
We leave engine extensions that forfeit termination
The case against
Unfamiliar to most contributors, and a family rather than one language. It cannot count, and some real rules want counting. The chosen engine has a bus factor of about one — a stated risk with a cheap exit, since the rules are text the scheme owns.
06Vocabulary
SKOS and the thesaurus standards
The W3C and ANSI/NISO vocabularies for concepts, labels, hierarchies and scope notes.
We take One definition per term, alternate labels so things can be found, non-transitive hierarchy, and concept schemes as bounded contexts.
We leave OWL and RDFS as inference machinery
The case against
The field's own verdict on controlled vocabulary is modest: it recovers “a quarter to a third” of records, and “we still do not have definitive proof” that a thesaurus is worth building.
07Work identity
Bazel
Google's build system, which identifies each action by the digest of its full specification and sandboxes it.
We take Work identified by what it was asked to do, timeout included — and the lesson that a declaration is only true when something enforces it.
We leave the transparent cache
The case against
Bazel's cache assumes actions are reproducible. Judged work is not: reusing a result returns one attempt, not the answer. Reuse is a decision with a recorded reason.
08Division of labour
Parasuraman, Sheridan and Wickens
The 2000 human-factors model that splits automation into four independently set stages.
We take “Agents make judgements, tools perform the mechanics” as a named, peer-reviewed configuration rather than a slogan.
The case against
Designed for human operators of automated systems, which fits an agent who is a person working through tools. The transfer to AI agents is by analogy, not by measurement.
09Verdicts
FIPA, A2A and Design by Contract
Agent-communication and software-contract traditions that separate refusing, failing and not understanding.
We take “Will not”, “tried and could not” and “the request was wrong” as distinct verdicts, each with its own recovery.
The case against
FIPA is effectively defunct; its specification survives only in an archive, because its old address no longer serves it.
10Rationale
IBIS, Toulmin and Dung
Fifty years of work on recording reasons, warrants and attacks as first-class structure.
We take Claims and defeats as records whose standing is derived, not stored — with an agent as the scribe IBIS always needed.
We leave participants typing their own map
The case against
The scribe can invent: an agent writing twelve claims overnight is not corrected in the room. And a rationale graph that blocks people is one people will route around.
11Verification
NASA SE Handbook and IEEE 1012
Aerospace and software-assurance practice for verification, waivers and independent checking.
We take Completion as evidence-or-waiver plus every discrepancy closed, and independence three ways: who runs the check, who chooses it, who can cut it short.
We leave waivers without a clock
The case against
No source anywhere bounds a waiver with an expiry. IEEE 1012-2016 is superseded by 1012-2024, its widely quoted phase names come from a withdrawn edition, and its task tables are paywalled.
12Staleness
Build systems and suspect links
Early cutoff from build-system theory; suspect links from requirements-tracing tools such as Doorstop.
We take Mechanical staleness — every derived item remembers the versions it was built from — and propagation that stops when nothing really changed.
The case against
When an agent judges “meaning unchanged”, that judgement is the correctness boundary, and no theory covers a fallible equality.
13Authority
Object capabilities
The security model in which authority is held by reference and can only be narrowed when passed on.
We take Authority that flows down by attenuation only, recorded so it can be reviewed and revoked.
We leave ambient authority
The case against
Its classic weaknesses are review and revocation. The scheme answers both with an append-only log of grants.
14Tool surface
Model Context Protocol
An open protocol for exposing tools to AI agents over JSON-RPC.
We take The tool surface: every mechanical operation is a tool any agent can call, and a refusal is a result the agent can read.
We leave trusting unpinned tool descriptions
The case against
In the specification, authorization is optional and stdio transports are outside it. Tool descriptions are read by the agent that calls the tools, not by the owner who approved them — so the tool surface must be pinned by digest.
Six needs fall between the standards. Some are partly covered — FIPA, A2A and Design by Contract already split “will not” from “could not” — but the pieces that make the whole work are defined nowhere else. The scheme defines them.
What no standard covers, the scheme defines.
- 01
Agents as attested producers
Briefs, runs and results are signed, digest-addressed records. Custody is kept distinct from content.
Nearest prior art in-toto, SLSA
- 02
The “cannot be done” verdict
Stated in advance as part of the work's own contract, with a no-progress rule, and reconsidered when the reason for the work is superseded.
Nearest prior art FIPA, A2A, Design by Contract
- 03
Correction in an append-only store
A correction is a new record that supersedes the old one. Nothing is edited. None of PROV, CloudEvents, in-toto or SKOS provides this.
Nearest prior art review dispositions, argumentation, Kanban
- 04
Bounded waivers and parks
Every deferral carries a clock or a trigger. No source bounds a waiver; the scheme does.
Nearest prior art triage practice
- 05
Keeping derived knowledge current
Staleness is mechanical. “Meaning unchanged” is a judgement, made twice and recorded.
Nearest prior art build systems, suspect links
- 06
Claims admitted only with captured evidence
A claim enters with a verbatim quote found in bytes the harness read, checked by a different actor from its own reads.
Nearest prior art none found