Archive and history

Earlier prototypes, historical exhibits, deprecated predecessors and parked experiments. They are kept because they are part of the evidence trail. Nothing on this page is a current installation path; start from the Constellation front page and the status page instead.

On this page: earlier prototype · four-office exhibit · July 2026 artifacts · deprecated predecessors · classic lineage · parked · field lab and other experiments.

Earlier prototype: the stale-permission refusal

This is the runnable demonstration the site used before the current stack existed. It runs on agent_governor, the deprecated Python predecessor of Constellation AG. A permission is checked and found valid, exercised eleven seconds later against a ten-second bound, and refused on a named monotonic clock basis before any capacity moves:

  standing       verified      ← the credential WAS valid
  wicket         admitted      ← naive auth says yes here
  spendability   REFUSED       standing_before_spendability_not_bounded
    gap=11s  vs bound=10s  → over by 1s
    gap_basis: monotonic, source=process_monotonic epoch=boot:demo-single-host
  → refused. No capacity spent (effect_count=0).

Captured run: excerpt of literal stdout from ./demo/refused-spend.sh, run 2026-07-29 against an editable install of agent_governor at 485e557. Exit 0; the demo’s integrity tripwire fails loudly if it passes for the wrong reason. The refusal class is named spendability — whether otherwise-valid standing may still be exercised here and now, under the bounds that govern this effect.

The ten-second bound is demonstration-sized so the failure reproduces interactively; it is not a proposed operational timeout. Real bounds belong to the specific claim and effect class — and staleness in time is one instance of the failure, not its definition.

Read the full descent (premises, clocks, and the theorem that licenses the refusal) on the earlier-prototype demo page, or the same event written as a postmortem.

Four offices, one bounded change (July 2026)

Historical composition exhibit. Four separately-owned offices — systems that each answer one question and carry a written list of what they will not decide — carried one small Git change from proposal to evaluated testimony, with no office absorbing another’s jurisdiction and no code changes in any of them. It ran once, on 2026-07-26, against the Night Shift repository. It is superseded as the public starting point by the alpha.6 walkthrough; its ledger row is kept.

This is one exhibit, not the definition of the program. It demonstrates that these four artifacts compose for this one effect class. It is not evidence that the rest of the work composes, and it is not a product.

  1. Night Shift proposes a bounded, advisory, read-only intention. Binds intent only — never file lists, content bytes, or authority.
  2. Docket prepares the exact bytes as a prepared attempt. Preparation authorizes nothing. No standing exists at this point.
  3. AG ng authorizes that exact prepared attempt, burning its own one-use decision authority. Its issuance establishes nothing about repository state, and no authority object crosses the boundary.
  4. Docket verifies the issuance against its own stored attempt, mints local single-use standing, executes through its broker, and settles with evidence. Checks custody, not policy. Settlement is not a safety claim.
  5. NQ evaluates what the recorded testimony does and does not establish, against registered claims and configured consumer profiles. Emits testimony and typed refusals, never actions.
  6. Night Shift consumes NQ’s receipt and emits a read-only disposition. No actuation. The boundary is gate-enforced.
  7. A human remains the only party able to decide what happens next.

The same proposal, two evidence states

The interesting property is not that the admitted case worked. It is that the refusals happen before effect, and that each one leaves the world exactly as it found it.

Evidence state A — coherent
Trusted issuer; valid signature over the exact body bytes; fresh; the decision admitted; and every executor-owned field matching what the executor itself holds. Result: local standing minted once, spent once — effect settled committed.
Evidence state B — altered, stale, or mismatched
An altered issuance body; an expired issuance; an issuance naming a different prepared digest; an exact issuance replayed against a second attempt; a request refused outright upstream — a path outside the admitted catalogue, producing no issuance at all. Result: no standing, no reservation, no dispatch, no Git mutation, and no testimony describing an execution.

Cited: both states are recorded in Docket’s vertical-01.md, which was itself the governed change it describes: it was written, submitted through the vertical, and the commit that added it was authored by the runtime’s broker rather than by hand.

The non-grant — what the run refused to conclude

Authorization succeeded. Execution succeeded. Settlement succeeded. And the composition still declined to mint the one claim a reader would most want from it: safe_to_merge remained structurally non-mintable, and no registered claim verified from that testimony alone.

That is the point of the exercise. A chain of successful steps is not an argument that the result is safe, and a system that cannot say no to itself at the end is not evidence infrastructure — it is a conveyor belt with a receipt printer bolted on.

What warrants the claims above

the declaration
Night Shift’s FOUR_OFFICE_PILOT_01.md — written before execution, deliberately carrying no identifiers or verdicts. Its presence in the repository establishes only that the pilot was declared and that the governed change carrying it executed through those offices.
the prior run
The three-office vertical of 2026-07-25, in full, with its negative specimens — vertical-01.md.
the jurisdictions
Each office stated its own boundary and its own maturity, and the four statements agreed: nightshift · ag_ng · docket · nq. (The first three repositories have since been renamed to their Constellation names.)
what is assumed
Three premises hold the load and are written down as assumptions rather than guarantees — trust-model.md. Also: known gaps.
not available
The run’s identifiers, digests, and verdicts. They exist only in a private campaign record and cannot be inspected from here. This is the exhibit’s promotion condition, not an omission.

No notary exists in this composition. The downstream packet is operational testimony marked as a projection of executor-held records; its digests are producer self-consistency, not an independent chain of custody. Two premise kinds — upstream authorization premises and this effect class’s settlement premises — stay separate everywhere, and neither becomes the other. Upstream residual obligations travelled undischarged, reported as unrepresented because the upstream office could not yet express them; that was recorded as a producer limitation, not as their absence.

Artifacts as presented in July 2026

These entries preserve the names and maturity statements from the historical four-office exhibit. They are retained evidence, not current installation guidance; the current map is on the components page. Each entry says what replaced it. Do not install the classic unpingable/nq or agent_governor for current paths; their successors are not drop-in compatible.

nq (then: operational, pre-1.0; now: deprecated predecessor)
Role: testimony, claims, and reliance. Pulls bounded evidence from hosts, classifies failure modes, and keeps loss of observability visible. Refuses: turning a signal that disappeared into a healthy zero; letting a clean receipt approve a merge, deployment, restart, or incident closure. A reliance refusal is never the negation of the underlying claim. Limit: consumer identity is configured, not authenticated. Now: superseded by Constellation NQ. Do not install unpingable/nq; the repositories are not drop-in compatible.
ag_ng (then: exercised; now: historical name)
Role: authority. Decides whether exact prepared work may receive authority, and burns one-use decision authority. Refuses: a second issuance for the same decision. It does not own the wire contracts, execution, settlement, claim admissibility, or orchestration — and did not absorb the separately-defined mandate-custody and spendability offices. Limit: at the time of the exhibit, explicitly not production deployable, with an in-memory decision-burn ledger. Current Constellation AG spends authority durably through its campaign store and reconstructs historical spends on restart; that is still not a production-deployment claim. Now: ag_ng is an earlier name for the same Rust implementation, not a separate product; use Constellation AG.
docket (then: audited baseline; now: earlier state of Constellation Docket)
Role: governed execution. Prepares exact bytes, verifies an authenticated issuance against its own stored attempt, executes through a broker, and settles with evidence. Refuses: within its frozen Git baseline, any proposal outside the one admitted effect class — the atomic Git target-ref transition — with a typed refusal before standing is issued, a reservation created, a dispatch identity minted, or a provider runs. Its own reliance bridge refuses safe-to-merge as permanently inadmissible. Limit: frozen baseline gwr-greenfield-v0.1; source install, not a published package. Three trust-model premises are assumptions. Now: superseded by Constellation Docket, the same repository under its current name, which also carries a generic executor transport; alpha.6 dispatched Maude’s exclusive-create executor through it.
nightshift (then: exercised; now: earlier state of Constellation Nightshift)
Role: proposal and read-only orchestration. Schedules and resumes intent, not commands — “resume this intention under this policy” rather than “run this at this time.” Refuses: actuation of any kind, at a gate-enforced boundary; closing a loop before the witnesses needed for closure exist. Limit: not operator-ready. File-granular proposals are a library face; the deployment files are reference scaffolding. Now: superseded by Constellation Nightshift, the same repository under its current name.
agent_governor (legacy / historical)
Role: the classic Python admissibility kernel for AI coding agents, and the source of the earlier-prototype demo above. Dispositioned legacy on 2026-07-26: still maintained then, and the custody home of the frozen conformance corpus and of the bounded diagnostic drill helpers Night Shift imported. Refuses: prose as authority; tests passing treated as code ready to land; a rehearsal treated as production; permissions exercised after their observation horizon. Limit: receives no new authority work. No wire compatibility with ag_ng exists or is implied. Now: deprecated; the successor is Constellation AG.

Also listed then as shipped and independently usable: wicket (intent preflight) · standing (permission observation with age) · continuity (hash-chained cross-session state) · verifier (Z3 constraint sidecar) · porter (transport with exit-code custody) · maude (operator desk) · lean (proof artifacts, read-only audit).

Deprecated predecessors

Replaced by current components. The repositories stay public for history and migration; do not install them for new work. The classic and successor components are not drop-in or wire compatible.

Classic Agent Governor lineage

Tools and specimens built around the classic implementation. They document how the ideas developed; they are not part of the current stack.

Parked

Named, not retired: revisit if the forcing case arrives. None of these is part of the current stack.

Field lab and other experiments

The ATProto / Bluesky work is a field lab: a live network where receipt, drift and moderation claims meet real traffic. It is not part of the Constellation stack, and its projects are not peers of the components.

Standalone experiments: grid-dependency-atlas, a map of communities exposed to infrastructure decisions made outside their control; lexidoku, Wordle meets Sudoku.