Skip to content
HONESTASDecision-Evidence Operating System

For the Chief Operating Officer

Someone changed a threshold last quarter. Every decision taken since looks different, and nothing on record says why.

The decisions themselves may be well governed and still leave you exposed here, because the rules those decisions were taken under moved in a settings screen, at a date nobody logged, on the authority of whoever had the login. And the moment work crosses to another company — a recovery, a referral, a delegated authority — the governance stops at your firewall and the rest is email.

A change to the rules, taken the way a claim decision is taken

Change record · referral thresholdCertified
  1. change.proposedrecorded

    the field, the value it holds, the value proposed, and the named person proposing it

  2. change.replayedrecorded

    decided cases re-run under the proposed value, so the effect is measured before it is argued

  3. change.deliberatedobjection kept

    a room convened on the change itself, including the seat whose job is to object to it

  4. change.gatedsealed

    the cross-model gate run against the proposed rule, with both model versions sealed

  5. change.certifiedsealed

    a named approver, the reasons, the previous value kept, and a reversal that is one governed action

  6. change.effectivesealedsha256:6b02df…ac81 (illustrative)

    the first decision taken under the new value links back to this record, and so does every one after it

Corridor · recovery demand to another carrier
  1. submittedin flight

    the demand leaves with an industry-standard payload inside the task

  2. workingwaiting on a person

    the counterparty’s side is doing its own governed work, visible as a state, not a silence

  3. input-requiredwaiting on a person

    a named human on one side or the other is being waited on, and both sides can see it

  4. completeddually signed

    the artefact is signed by both companies and lands in both records

endpoint conformant to spec v0.3.0(shipped)migration to v1.0.0 — designed, not built(designed, not built)

[O] Illustrative composition, built from the components the product ships. No customer data appears anywhere on this site; the digest above is a placeholder. Gated capability bindings and the agent endpoint are observed at ROS/src/routes/skill-bindings.ts, ROS/src/routes/capability-bindings.ts and ROS/src/routes/public/beacon-agent-public.ts, with a conformance suite beside them.

The mechanism, in three lines

Changing a rule, a threshold, a persona or a model version is itself a governed decision that carries a certificate — and the same discipline extends to actions between companies.

First

A setting is a decision

A threshold, a checklist, an autonomy mode, a persona version and a model version all move through the same thread as a claim ruling: proposed, argued, gated, signed by a named person.

Then

The effect is measured before the argument

Decided cases are re-run under the proposed value, so the room is arguing about what the change actually does rather than about what someone expects it to do.

Finally

The discipline crosses the firewall

Work sent to another company travels as a task with states both sides can see and artefacts both sides sign, instead of as an attachment in a mailbox nobody can audit.

designed, not built(designed, not built)The gated bindings and the agent endpoint run today. The corridor operations on top of them do not, and the protocol version underneath them is one behind.

v0.3.0the agent-protocol spec version our endpoint conforms to today[O]
v1.0.0the current published spec version — a named work item, not a hidden one[V]
1certificate per change: a threshold moves the way a claim decision moves[O]
2signatures on a corridor artefact, one per company [P: to be calibrated][P]

The dual-signature figure describes a designed corridor, [P: to be calibrated] — the party model and the claim-state synchronisation it needs are not built, and the page will drop the marker when they are.

The honest limit