One bounded piece, into an ordinary stack
Nothing here asks you to replace Kubernetes, IAM, CI, schedulers, databases, or orchestration — and nothing asks for cryptographically verified timestamps on every action. Adoption begins at one transition whose consequences matter. The surrounding platform stays; the inserted component owns one narrow question, and refuses to silently inherit authority from the rest of the stack.
These are the shapes the existing artifacts and exhibits actually demonstrate — different artifacts support different ones, and no artifact supports them all. The unit of adoption is not “the enterprise.” It is one consequential transition, one bounded claim, or one admitted effect class.
Thesis
The transitions under study
Evidence does not travel from a sensor to an action in one move. It crosses a series of boundaries, and at each one something is converted into something with more force than it had a moment earlier. The recurring failure is that the conversions happen silently — nothing records that they occurred, and nothing re-checks that they still hold at the moment of use.
Select a transition for the question it must answer. This is a schematic: it draws the boundaries the program studies, not a pipeline that six named services already implement end to end. Only the annotations below name an artifact, and only where one actually does the work.
schematic Illustrative. No artifact is mapped onto a transition it has not exercised; where the caption names one, the ledger carries its dated claim.
Continuity is a separate question
The last stage of a pipeline is a bad place to put memory. “Remember” is not one responsibility, and no artifact here owns it whole. It decomposes into five questions that have different owners, different expiries, and different failure modes:
- valid What still holds, as opposed to what merely still exists?
- attributable Whose testimony was it, and can it be recalled by origin?
- reusable May this be spent again, or was its authority consumed?
- reconstructible Can the decision be walked back to its premises from what survives?
- unknown What must stay unknown, or wait for renewed judgment, rather than be inferred?
Two of these have partial owners today. continuity holds hash-chained cross-session state, so a reliance cannot happen without a prior commit. NQ evaluates imported continuity snapshots as one narrow claim — continuity_rely_eligible — and implements none of continuity’s trajectory law. The other three are open questions, and the site does not pretend otherwise.
Exhibit — composition under qualification
Four offices, one bounded change composition
The clearest thing currently on the bench: four separately-owned offices — systems that each answer one question and carry a written list of what they will not decide — carrying one small Git change from proposal to evaluated testimony, with no office absorbing another’s jurisdiction and no code changes in any of them. It ran once, on 2026-07-26, against the Night Shift repository.
This is one exhibit, not the definition of the program. It demonstrates that these four artifacts compose for this one effect class. It is not evidence that the rest of the work composes, and it is not a product.
The same proposal, two evidence states
The interesting property is not that the admitted case worked. It is that the refusals happen before effect, and that each one leaves the world exactly as it found it.
committed- an altered issuance body
- an expired issuance
- an issuance naming a different prepared digest
- an exact issuance replayed against a second attempt
- a request refused outright upstream — a path outside the admitted catalogue, producing no issuance at all
cited Both states are recorded in Docket’s vertical-01.md, which was itself the governed change it describes: it was written, submitted through the vertical, and the commit that added it was authored by the runtime’s broker rather than by hand.
Authorization succeeded. Execution succeeded. Settlement succeeded. And the composition still declined to mint the one claim a reader would most want from it: safe_to_merge remained structurally non-mintable, and no registered claim verified from that testimony alone.
That is the point of the exercise. A chain of successful steps is not an argument that the result is safe, and a system that cannot say no to itself at the end is not evidence infrastructure — it is a conveyor belt with a receipt printer bolted on.
What warrants the claims above
No notary exists in this composition. The downstream packet is operational testimony marked as a projection of executor-held records; its digests are producer self-consistency, not an independent chain of custody. Two premise kinds — upstream authorization premises and this effect class’s settlement premises — stay separate everywhere, and neither becomes the other. Upstream residual obligations travelled undischarged, reported as unrepresented because the upstream office cannot yet express them; that was recorded as a producer limitation, not as their absence.
An exhibit you can run right now
Smaller, older, and fully reproducible — this is the refusal from the top of the page, with the clock basis restored: a permission checked and found valid, exercised eleven seconds later against a ten-second bound, and refused on a named monotonic basis, before any capacity moves.
standing verified ← the credential WAS valid wicket admitted ← naive auth says yes here spendability REFUSED standing_before_spendability_not_bounded gap=11s vs bound=10s → over by 1s gap_basis: monotonic, source=process_monotonic epoch=boot:demo-single-host → refused. No capacity spent (effect_count=0).
captured run Excerpt of literal stdout from ./demo/refused-spend.sh, run 2026-07-29 against an editable install of agent_governor at 485e557. Exit 0; the demo’s integrity tripwire fails loudly if it passes for the wrong reason. Not a cold clone — see the ledger row.
Descend into the receipt: premises, clocks, and the theorem that licenses the refusal →
How to read the labels
Four kinds of object, four kinds of thing shown
You have now seen both vocabularies in use. They exist so that you never have to guess whether something here is an idea, a design proposal, a working specimen, a qualified composition, or deployed evidence — and they are what the ledger below is written in.
Where a distinction is not yet earned, this site says so rather than smoothing it. Synthetic fixtures appear only where they are identified as synthetic and used to demonstrate conditional behaviour — never as testimony about a real estate. Terms of art are linked to the glossary at first use.
Evidence
Status ledger
One row per object: what it claims, when that was last verified and by what, where the evidence lives, and what would have to happen before the claim may be strengthened. Rows are dated statements, not a live panel — a mechanical check may satisfy a promotion condition, but promotion stays an explicit editorial act.
Four separately-owned offices carried one bounded Git change from proposal to evaluated testimony without any office absorbing another’s jurisdiction, and without code changes in any office.
Exactly one effect class is admitted — the atomic Git target-ref transition. A proposal outside it refuses with a typed refusal before any standing is issued, any reservation created, any dispatch identity minted, or any provider runs.
Decides whether exact prepared work may receive authority, and burns one-use decision authority. It does not own the wire contracts, execution, settlement, claim admissibility, or orchestration.
Pulls bounded evidence, keeps loss of observability visible rather than silently healthy, and emits testimony and typed refusals — never actions. A clean receipt approves no merge, deployment, restart, or incident closure.
Proposes bounded intent behind a gate-enforced no-actuation boundary. Its proposals bind intent only — never file lists, content bytes, or authority.
Still the custody home of the frozen conformance corpus and of the bounded diagnostic drill helpers Night Shift imports; no authority, policy decision, credential, or capability crosses that wire.
A permission valid when checked refuses at exercise time because the gap between observation and exercise exceeded its bound on a named monotonic basis — and no capacity is spent.
A firewall’s declared deny rule and an observed path are held apart and never merged into one story. The frozen probe exercises its witness path against real pfSense substrate in a controlled lab.
The tools operate over a system someone composed on purpose. That composition is currently unwritten: it lives in doctrine and in the operator’s head, and every tool re-derives it by hand.
Ledger as of 2026-07-29. Generated from
status.json by tools/render_status.py in the
site repository;
it is a dated statement, not a live panel. A row moves only by an explicit
editorial act — a passing test may satisfy a promotion condition, but it does
not promote the claim.
Artifacts
Implemented systems artifact
Small, self-hosted, independently useful. Python and Rust libraries and CLIs you run yourself — no SaaS, no hosted control plane, no shared datastore. Each states what it handles and, more usefully, what it refuses.
The four offices below are the ones the current composition exercises. The full catalogue — operator surfaces, memory, proof artifacts, field labs, and the parked list — lives on components.
- role
- Testimony, claims, and reliance. Pulls bounded evidence from hosts, classifies failure modes, and keeps loss of observability visible.
- refuses
- Turning a signal that disappeared into a healthy zero; letting a clean receipt approve a merge, deployment, restart, or incident closure. A reliance refusal is never the negation of the underlying claim.
- limit
- Consumer identity is configured, not authenticated.
- role
- Authority. Decides whether exact prepared work may receive authority, and burns one-use decision authority.
- refuses
- A second issuance for the same decision. It does not own the wire contracts, execution, settlement, claim admissibility, or orchestration — and did not absorb the separately-defined mandate-custody and spendability offices.
- limit
- Explicitly not production deployable; the decision-burn ledger is in-memory per process.
- role
- Governed execution. Prepares exact bytes, verifies an authenticated issuance against its own stored attempt, executes through a broker, and settles with evidence.
- refuses
- Any proposal outside its single admitted effect class — the atomic Git target-ref transition — with a typed refusal before standing is issued, a reservation created, a dispatch identity minted, or a provider runs. Its own reliance bridge refuses
safe-to-mergeas permanently inadmissible. - limit
- Frozen baseline
gwr-greenfield-v0.1; source install, not a published package. Three trust-model premises are assumptions.
- role
- Proposal and read-only orchestration. Schedules and resumes intent, not commands — “resume this intention under this policy” rather than “run this at this time.”
- refuses
- Actuation of any kind, at a gate-enforced boundary; closing a loop before the witnesses needed for closure exist.
- limit
- Not operator-ready. File-granular proposals are a library face; the deployment files are reference scaffolding.
- role
- The classic Python admissibility kernel for AI coding agents, and the source of the runnable exhibit above. Dispositioned legacy on 2026-07-26: still maintained, still the custody home of the frozen conformance corpus and of the bounded diagnostic drill helpers Night Shift imports.
- refuses
- Prose as authority; tests passing treated as code ready to land; a rehearsal treated as production; permissions exercised after their observation horizon.
- limit
- Receives no new authority work. No wire compatibility with
ag_ngexists or is implied.
Also shipped and independently usable, on components: wicket (intent preflight) · standing (permission observation with age) · continuity (hash-chained cross-session state) · verifier (Z3 constraint sidecar) · porter (transport with exit-code custody) · maude (operator desk) · lean (proof artifacts, read-only audit). The AT Protocol field lab and the standalone experiments are catalogued there too.
Proposition
The authored design layer proposition
The tools do not operate over “the enterprise.” They operate over a system someone composed on purpose — its boundaries, identities, relationships, and the evidence that would count for each. That composition is real, and it is currently unwritten: it lives in doctrine and in the operator’s head. Every artifact above re-derives it by hand.
Writing it down is the missing layer. An authored, versioned design; validated and ratified rather than silently amended; compiled into the bounded view each tool is competent to consume; then compared against what was actually witnessed. The verbs already exist across the work. The noun does not.
What it would buy: a declared surface to name (“the public edge”) instead of a list of hostnames pasted between tools; a comparison of declared structure against admissible observation, where divergence is a finding rather than a silent widening; and authority that binds to an exact design revision, so a changed system does not inherit the old permission.
The one narrow case that already runs
A firewall rule is a small declaration: this traffic is refused. NQ can read that rule over a read-only connection and probe the path from a named vantage point — and then refuse to let the declaration and the observation be quietly merged into one story. It is not a firewall test. NQ never rules the firewall correct or broken; it holds the two apart and says which one it actually saw.
The discipline is in what it will not say. A rule that does not match is cannot testify, never “allowed.” A blocked path proves nothing by itself — a dead vantage point looks exactly like a working rule — so “blocked” is admissible only alongside a control probe to a known-reachable target, proving the vantage had a way out at all. Only a real completed handshake to a declared-denied address is an unambiguous contradiction; a rejection packet is not a way through. The verdicts are typed and there is no is_ok() — a test asserts that the receipt contains no healthy and no green.
Pointed at a real firewall — a blocklist rule with 17,007 entries behind it — the answer was cannot testify: the rule was present and readable, the vantage had ordinary egress, and the path itself was deliberately never probed, because probing it means firing a packet at a named malicious host to make a demonstration look better. The interesting verdicts exist only on a scratch firewall built for the purpose, and the got-through case had to be staged with a deliberately broken rule.
cited The lab specimen is declared_deny_lab_subject_probe.md. NQ has never caught a real firewall failing to enforce a real block. It has shown it would notice. That is lab-backed compatibility evidence, never live testimony about a deployed estate.
Status of the proposition: named, not ratified. No implementation, no schema, no wire format — the filing is a handle for review, not authorization to build. It is on this page because the recognition is real and the site records direction honestly, not because anything ships. The firewall probe is one rule at a time, with none of the design layer above it: evidence that the comparison may be worth generalizing, not evidence that it exists. Nothing above the line in the diagram is built.
Thesis — formal work
Research
The papers name the failure classes; the artifacts carry the response. The Δt series is scaffolding for the check-versus-action logic in standing and the admissibility kernels. Some of this work is theoretical only; not everything here has an instantiation, and the papers are not evidence that anything is deployed.
Selected papers below — full list in the papers repo. Selected claims from the Δt series are machine-audited in Lean: unpingable/lean (proof reader’s portal). The theorems prove class boundaries of refusals — not that any deployed system is safe. See limits.
Temporal Coherence & Δt Theory
- Δt-Constrained Inference: A General Model of Temporal Coherence in Hierarchical Systems
- Detecting Temporal Debt in Language Models and Software Systems
- Temporal Closure Requirements for Synthetic Coherence
- You Need More Than Just Attention: Invariant Requirements for Temporal Coherence in AI Systems
- The Temporal Attack Surface: A Δt Framework for Asynchronous Security Systems
- Temporal Asymmetry in Censorship Systems
- The Gain Geometry of Temporal Mismatch: Shear, Leverage, and Capture in Multi-Timescale Systems
Systems & Institutional Dynamics
- The Coherence Criterion: A Unified Framework for Stability in Hierarchical Systems
- Control Laws for Hierarchical Kinetics: Design Principles for Multi-Timescale Systems
- The Second Law of Organizations: How Temporal Lag Drives Irreversible Institutional Decay
- Capacity-Constrained Stability: A Control-Theoretic Framework for Institutional Resilience
- Cybernetic Fault Domains: When Commitment Outruns Verification