For the Chief Operating Officer
Someone changed a threshold last quarter. Every decision taken since looks different, and nothing on record says why.
The decisions themselves may be well governed and still leave you exposed here, because the rules those decisions were taken under moved in a settings screen, at a date nobody logged, on the authority of whoever had the login. And the moment work crosses to another company — a recovery, a referral, a delegated authority — the governance stops at your firewall and the rest is email.
A change to the rules, taken the way a claim decision is taken
change.proposedrecorded
the field, the value it holds, the value proposed, and the named person proposing it
change.replayedrecorded
decided cases re-run under the proposed value, so the effect is measured before it is argued
change.deliberatedobjection kept
a room convened on the change itself, including the seat whose job is to object to it
change.gatedsealed
the cross-model gate run against the proposed rule, with both model versions sealed
change.certifiedsealed
a named approver, the reasons, the previous value kept, and a reversal that is one governed action
change.effectivesealedsha256:6b02df…ac81 (illustrative)
the first decision taken under the new value links back to this record, and so does every one after it
EVERY CHANGE KEEPS ITS HANDLE
The previous value stays in the record, so the reversal is one governed action rather than an archaeology project. A rollback is itself a change, and it goes through the same thread — including the part where somebody has to sign it.
submittedin flight
the demand leaves with an industry-standard payload inside the task
workingwaiting on a person
the counterparty’s side is doing its own governed work, visible as a state, not a silence
input-requiredwaiting on a person
a named human on one side or the other is being waited on, and both sides can see it
completeddually signed
the artefact is signed by both companies and lands in both records
endpoint conformant to spec v0.3.0(shipped)migration to v1.0.0 — designed, not built(designed, not built)
REFUSED
CHAIN_DIVERGENCE
Our record of the claim state and the counterparty's no longer agree, so the corridor stopped rather than picking one.
Two companies working one recovery keep two records, and the interesting failure is not a dropped message but a quiet disagreement about what was agreed. Stopping and naming the divergence is what leaves both sides able to reconcile; automatically preferring ours would make our record authoritative over a company that never agreed to that. The surfacing of the conflict, and the party model it needs, are designed and not built — which is why this refusal is drawn here rather than screenshotted.
[O] Illustrative composition, built from the components the product ships. No customer data appears anywhere on this site; the digest above is a placeholder. Gated capability bindings and the agent endpoint are observed at ROS/src/routes/skill-bindings.ts, ROS/src/routes/capability-bindings.ts and ROS/src/routes/public/beacon-agent-public.ts, with a conformance suite beside them.
The mechanism, in three lines
Changing a rule, a threshold, a persona or a model version is itself a governed decision that carries a certificate — and the same discipline extends to actions between companies.
First
A setting is a decision
A threshold, a checklist, an autonomy mode, a persona version and a model version all move through the same thread as a claim ruling: proposed, argued, gated, signed by a named person.
Then
The effect is measured before the argument
Decided cases are re-run under the proposed value, so the room is arguing about what the change actually does rather than about what someone expects it to do.
Finally
The discipline crosses the firewall
Work sent to another company travels as a task with states both sides can see and artefacts both sides sign, instead of as an attachment in a mailbox nobody can audit.
designed, not built(designed, not built)The gated bindings and the agent endpoint run today. The corridor operations on top of them do not, and the protocol version underneath them is one behind.
The dual-signature figure describes a designed corridor, [P: to be calibrated] — the party model and the claim-state synchronisation it needs are not built, and the page will drop the marker when they are.
ROS/src/routes/public/beacon-agent-public.ts. The current spec version is the published Linux Foundation release (accessed 19 August 2026); we print both numbers together because a version claim with only one of them in it is the easiest kind of thing to leave stale. Change certification is the gated-binding mechanism at ROS/src/routes/skill-bindings.ts and ROS/src/routes/capability-bindings.ts. None of these is a customer measurement — we have no customers yet.The honest limit
WHAT THIS DOES NOT DO YET
- A2A migration from the spec version our endpoint conforms to (v0.3.0) to the current one (v1.0.0), plus the party model, claim-state synchronisation and conflict surfacing.