Glossary
What the project vocabulary means, in one place. The prose elsewhere uses these terms; this page is where they’re defined. Where receipt identifiers and prose words diverge (prose permission, receipt field standing), the entry notes both.
If you're new, the bridge from plain words to the precise ones:
| plain term | precise term |
|---|---|
| system / component set | constellation |
| what can be relied on | admissibility |
| proposed / not yet accepted | candidate |
| public claim / accepted claim | minting |
| observed evidence | witness testimony |
| permission / scoped authority | standing |
| blocked — required evidence/action missing | obstruction |
| what agents are not allowed to do | non-grant |
admissibility approval attestation attempt authority authorization boundary candidate claim custody dispatch expiry gap indeterminate kernel minting non-grant obstruction occurrence permission policy preflight premise receipt refusal class settlement spendability standing wicket witnessed
- admissibility #
- A claim’s eligibility to become a premise for action. Custody decides admissibility; refusal classes name the specific ways it can fail. The Lean theorems live under
Admissibility.*and prove the class boundaries. Prose elsewhere on the site uses the longer phrase “allowed to become a premise” for cold readers; receipt and Lean identifiers use the noun directly. - approval #
- An explicit operator or gate decision over a specific proposal, at an authority-bearing surface, with scope, time, and evidence recorded. What approval is not: an agent saying “done,” a passing test run, a chat message, a completed rehearsal, a green check, or a demo succeeding. Approval is a bounded authority-bearing act — if nothing recorded a scoped decision, nothing was approved. Contrasts with automatic promotion: agents may propose; approval is a distinct operator/gate step, never a byproduct.
- attestation #
- Evidence that someone or something observed and recorded a claim, with attribution. Distinct from a signature (which proves who said the thing, not whether it was observed) and from a log line (which records but doesn’t attest). Receipts are attestations of custody decisions;
nqrecords attestations of operational observations. - attempt #
- Constellation Docket’s durable execution instance for one occurrence: the exact work and executor binding it accepted, the one dispatch, and the settlement or indeterminate evidence it retained. Docket delivers an attempt once and keeps it for same-attempt reconciliation. An occurrence and an attempt are related but not interchangeable: AG owns the occurrence and its authorization; Docket owns the attempt and its execution records.
- The right to make a decision binding on a system. Distinct from permission (which is the grant to act) and from policy (which is the rule the authority applies). In the conversion chain, authority sits between premise and action: a premise becomes an action only if some authority licenses it. In prose: an “authority-bearing surface” is one where touching it has binding effect.
- The question of whether an action is allowed under stated rules: returns yes/no over an input claim (“the credential says valid; the role says operator”). What conventional auth checks and most policy engines do well. Distinct from custody: authorization decides whether the action is permitted; custody decides whether the input claim is still good enough to act on.
- boundary #
- A named conversion point in the custody chain where one kind of claim becomes another — e.g., an observed permission becoming one usable at action time. The boundary is the place where the conversion can refuse.
- In receipt fields:
seam. - candidate #
- A proposed claim, action, or receipt that has entered the system but has not yet been admitted as authoritative. Agent output arrives as candidate: it may carry structure and content, but it does not carry authority until a gate admits it. The word is deliberately distinct from approved or accepted — candidate names the intermediate status where proposal exists but promotion has not.
- claim #
- An assertion that something is true: that a credential is valid, a monitor is green, an action is allowed. Claims arrive from many sources (log lines, API responses, model outputs, human approvals) and may be witnessed, stale, or self-reported. A claim is not yet a premise — whether it may become one is the custody question.
- custody #
- The layer that controls whether a claim may become a premise for action. Distinct from authorization (which asks only whether the action is allowed) and from policy (which decides over premises it has been handed). Custody decides whether the premises it would hand the policy are still good enough to act on.
- In Docket documentation the word is narrower: durable ownership of one attempt’s records and transitions, including identity, replay and recovery rules. Custody in that sense does not itself grant authority (Lean statement).
- dispatch #
- Docket’s invocation of the exact enrolled executor for one accepted attempt. A dispatch names the attempt and an executor-local idempotency marker that Docket issues for that attempt; the same attempt with a different marker, work, subject or scope is a substitution, not a retry. Dispatch is not arbitrary remote shell access. A dispatch with an unknown result is reconciled against the same issuance and attempt, never mechanically repeated.
- effect class #
- The narrowly-defined category of real-world change a governed runtime is willing to perform at all. Constellation Docket’s frozen Git baseline (
gwr-greenfield-v0.1) admits exactly one, the atomic Git target-ref transition, and refuses a proposal outside it with a typed refusal before any authority is issued and before any provider runs. Current Docket source also carries a generic executor transport for separately implemented executors; the alpha.6 release dispatched Maude’s authority-neutral exclusive-create executor through it. Recovery guarantees are properties of each effect class and its tested composition, not universal Docket guarantees. Breadth is decided once, in advance, rather than per request. - expiry #
- The time after which a previously-valid observation can no longer license an action. An observation’s expiry comes from whoever issued it, on a stated clock; the custody check at action time measures against that stated clock, not against wall time.
- In receipt fields and Lean theorems:
horizon. - gap #
- Elapsed time between when an observation was taken and when it’s being used — measured on a typed clock basis (named source, named epoch). The gap is compared to a bound declared at issuance time; the bound and the expiry are the same issuer-declared limit, expressed as a duration vs. a deadline. Custody refuses when the measured gap exceeds the bound on the named basis. Wall time is not the basis (it can move sideways under NTP); the basis is named explicitly in every receipt.
- indeterminate #
- The state of an attempt whose retained evidence cannot establish either that the effect completed or that it did not. An indeterminate record does not establish success or failure and never authorizes redispatch. The operator inspects first, then reconciles the same retained attempt with the same enrolled executor and configuration; Docket keeps the attempt for that purpose. Indeterminate is not permission to repeat the effect, and missing attempt evidence makes reconciliation refuse rather than imply failure.
- issuance #
- A signed decision from an authority office stating that one exact prepared piece of work may receive authority. An issuance is not the work, not a capability, and not standing to act. The executor verifies it against its own stored copy of the prepared bytes — never against the record’s own echoes — and then mints its own single-use standing locally. No authority object crosses the boundary; only the decision about one does.
- kernel #
- The minimal rule core of a check: small enough that its refusal classes can be stated precisely, and in this project, checked in Lean. Distinct from the runtime that implements it. “Custody kernel” = the rules that license refusals; “intent preflight kernel” (wicket) = the small set of conditions an intent must satisfy to become a premise.
- minting #
- Promoting a candidate into an authoritative artifact — a released version, an accepted claim, a receipt others may rely on. Minting is the explicit act of granting authority to something that previously carried none. Distinct from visibility: a candidate can be visible (committed, pushed, published as a draft) without being minted. Custody insists this step be explicit — not something that happens by accident when an agent finishes running.
- non-grant #
- A capability an agent is deliberately not given, with enforcing code and tests on the line that denies it. Not a warning or a policy note — a structural refusal. The non-grant list names what agents cannot do (approve themselves, promote their own output, mint authority from prose, use permissions after expiry, turn rehearsal into production, treat “tests passed” as safe to land) and points at the code that refuses each case.
- obstruction #
- A refusal grounded in missing evidence or action — the gate cannot proceed because a required witness, receipt, seal, or step is absent. Distinct from a substantive refusal (evidence exists but fails a predicate): an obstruction says “I do not have what I need to decide.” Reported as absence rather than inferred away; the point is that the gap is visible and named.
- occurrence #
- The stable identity of one exact governed work event and its authorization lifecycle: what the Constellation AG contracts call a run. AG governs one exact occurrence and spends one durable one-use permission for it; Docket custodies the resulting attempt. Success on one occurrence does not grant permission for the next, and a caller that lacks a terminal response reconciles the existing occurrence rather than submitting a replacement.
- office #
- A system with a stated jurisdiction: one question it is competent to answer, and a written list of what it will not decide. Offices are separate programs, owned separately; the property under test is that none of them absorbs another’s jurisdiction under pressure. In the current qualified composition, Constellation Nightshift proposes, Constellation AG authorizes, Constellation Docket executes and settles, and Constellation NQ evaluates bounded evidence. “Office” states jurisdiction, not maturity — it is not a claim that the system is stable or deployable.
- permission #
- An active grant to perform a thing, observed at a specific moment with a valid-until time. A permission valid when checked is not automatically usable at action time — the gap between check and action may exceed the permission’s expiry.
- In receipt identifiers and the component name:
standing. - policy #
- A set of rules that decides over inputs a system treats as premises — e.g., OPA/Rego over an input document, RBAC over an identity. Returns a verdict over what it’s been given. Distinct from custody: policy decides over premises; custody decides whether the underlying claims deserved premise status in the first place. The two compose — OPA can run happily inside a custody stack.
- preflight #
- A check that runs before an action is permitted to take effect. Distinct from logging (records but does not gate) and from postmortem (runs after). The custody stack uses preflight at three layers:
nqfor observation→claim, wicket for intents, andverifierfor declared constraints. - premise #
- A claim that custody has admitted as the basis of an action. The conversion claim → premise is what custody gates. Policy engines decide over premises; custody decides whether the underlying claims are allowed to become premises in the first place.
- receipt #
- A content-addressed record of a custody decision. The receipt id is a deterministic hash of the canonical decision inputs — the same inputs under the same schema always yield the same id, so the artifact is verifiable rather than merely logged. It is an address, not the claim: change the receipt schema and the id moves while the attested behaviour does not (see limits). Distinct from a log line: a log describes; a receipt attests, with attribution and a return address.
- refusal class #
- A typed category of refusal that the custody kernel licenses by definition — not a discretionary denial. Example:
standing_before_spendability_not_boundedis the refusal class for “permission observed earlier than the action, with the gap exceeding the bound.” The Lean theorems prove these class boundaries; the receipt attests the instance. See limits for what each does and doesn’t prove. - settlement #
- Docket’s retained description of what an attempt’s execution established, recorded from the executor’s report and Docket’s own evidence. A settled record is not automatically a successful outcome; it answers “did Docket settle the result, or is the attempt indeterminate?” separately from “did the executor report success or failure?”. Settlement is not a safety claim and mints nothing downstream: another consequence requires fresh observation, judgment and authority.
- spendability #
- A separate question from validity: given standing that is otherwise valid, may it still be exercised here and now, under the premises and bounds that govern this effect? Not merely TTL, credential expiry, or authority that decays continuously with age — time may be one bound, but exact content, identity, context, revision, custody, and prior use may all matter, and each is checked at the moment of use rather than inherited from the original grant. Receipt fields and refusal-class names use
spendability(e.g.,standing_spendability_seam); prose tends to use the longer phrase (“usable at action time”) because the bare noun reads as a coinage to cold readers. - standing #
- Code and receipt name for a permission observation with age and expiry. In prose, this site usually says permission. The component named
standingproduces standing receipts (with observation age); receipt fields likestanding_spendability_seamandstanding_before_spendability_not_boundeduse the code name. - testimony #
- A description of what was observed, or of what occurred, emitted by a system that has no power to act on it. Testimony is deliberately weaker than approval: NQ emits testimony and typed refusals and never actions, and a settlement record describes an execution rather than certifying that it was safe. Reading testimony as permission is the conversion this project exists to keep visible.
- wicket #
- The intent preflight kernel — decides whether an intent (the AI agent’s proposed action) may become a premise before any effect runs. Refuses intents from revoked or out-of-scope actors.
- witnessed #
- A claim is witnessed when its assertion is traceable to an observation that took it — with the observation’s source, time, and basis preserved. Distinct from signed (which proves an issuer’s signature but not what the issuer actually observed) and from self-reported (an actor asserting something about itself without independent attestation). Witnessing is the property the conversion observation→claim is supposed to preserve.
Notes on choices: this glossary preserves the project’s vocabulary where the ordinary alternative would launder a technical invariant (custody, premise, refusal class) and aligns prose with ordinary wording where it doesn’t (permission, expiry, boundary). Receipt identifiers and Lean theorems keep their original names; this page is the bridge.