OpenSentience.orgUnboxed PatternsChapter 30 of 32 · Agency

UP-030 · Agency · STATED CHECKABLE RUNNABLE EXECUTED STAGED

Intervention Provenance

Every intervention carries the Worker and generation that made it and the evidence it acted on; an unattributable intervention is inadmissible.

Every intervention on the world carries the identity of the Worker and generation that made it and the evidence it acted on; an intervention that cannot be attributed is not admissible.
Standing
STATED CHECKABLE RUNNABLE EXECUTED STAGED PUBLISHED REPRODUCED
Last checked
never run
Source
none — this record cites no check
Limit
Cell 17 (append-only audit) is proved, which makes the record durable. The pattern asks for the EFFECT to be re-observed, and the honest half of this record is that the re-observation does not exist — Pty::winsize() has zero callers.
Next rung
in_tree — a caller for the re-observation, so that an intervention's effect is measured rather than assumed from its request.
Why this page says STATED — the derivation, not the word
  • ✗ a witness is named
  • ✗ its evidence kind is one the ledger already uses
  • ✗ the witness path resolves in this tree
  • ✗ its rung is in_tree or above
  • ✗ a run is recorded for these exact bytes
  • ✓ no claim is cited that could be REFUTED
  • ✗ a counterexample is shipped (required once WITNESSED)
  • ✗ not staged on this site, so it cannot run from the page

WITNESSED requires every line above to hold. The label is computed from them by build.mjs and cannot be typed into the registry — the build refuses a record that carries it.

Intent

Acting on a world someone else inhabits — a terminal, a filesystem, a user's machine — is admissible only when the action can be answered for: who, under which generation of authority, on what evidence. The operator-disclosure policy is keyed on Worker + generation because, when this was measured, no cross-peer terminal authority existed to key it on.

Technical register

Super D.1.3c·2d·2: outcome vocabulary APPLIED | REFUSED | INDETERMINATE (Three-Valued Outcome); provenance keyed on a Worker + generation. The same document records that the re-observation INDETERMINATE was to be repaired by does not exist — Pty::winsize() has zero callers — and refutes the predecessor round's settle-in-place design. Cell 17 (⊕ append-only) is the ledger property this depends on. Witness in super/, referenced not copied.

Problem

An agent writes to a terminal. Later, something is different. Which action did it, under whose authority, because of what? Without provenance the answer is a log grep and a guess, and the guess is usually 'the agent'.

Solution

Attach Worker, generation and evidence to every intervention before it is attempted. Append the outcome as one of three values. Never rewrite. Name the re-observation the design depends on and check it has callers.

Real-world analogy

A surgical count: every instrument signed in and out by name, and an operation that cannot account for one is not closed.

Structure — on the surface

compute surfaceinterveneinterveneaaction · no worker · no generationAn intervention on the world, and what it must carry to be admissible.

An illustration on a compute surface: loci above, carriers below. Press Play or Step; the takeaways collect as you go. Nothing here is evidence — the witness section is.

The chapter in WRL — and the chain so far

Chapter 30 of 32 — the fragment _patterns/wrl/chain/intervention-provenance.wrl, sealed alone by wrl.js

; INTERVENTION PROVENANCE — two writers (w=7, w=9) intervene on the same locus; every receipt names its writer
; and sequence. ip_in is the entry, fed by the sufficiency router.
[relay:ip_in]{sig_in, sig_out}
[spinner:ip_world](w=16, n=8, rotor=quarter_turn_z, configurable){sig_in, socket}
[orb:ip_view]{pose}

[ip_in] --sig--> [ip_world]
[ip_world] --socket--> [ip_view]

Its test bench _patterns/wrl/chain/intervention-provenance.bench.wrl — drives the entry for this chapter's own film; never part of the chain

; TEST BENCH — drives this chapter's entry alone; the chain replaces it with a wire from an earlier chapter
[pulser:ip_bench](every 1){sig_out}
[ip_bench] --sig--> [ip_in]

module + bench seal to → sem-28af0fc6bf2e128c06f301cb8034fd36dd2e56830f932f9d057a3aad049676dc

Run inputs — a ScenarioV1, the forge's own document, bound to this world's id and never part of it (D3) · ScenarioDigest scen-1b546f491ca3cfb245f… (the run inputs' own identity, computed by the forge)

epochwriter · seqoptargetrotorlabel
1w7 s1SetRotorip_world255.0.0.0SetRotor ip_world 255.0.0.0
3w9 s1SetRotorip_world0.0.255.0SetRotor ip_world 0.0.255.0

Reduced by the native reducer (ic32); the reference reducer reproduces every epoch's film hash (38.87s).

compute surfacesigsigsocketip_bench · Pulserip_benchpulserip_in · Relayip_inrelayip_view · Orbip_vieworbip_world · Spinnerip_worldspinnerledger · receipts · Ledgerledger · receiptsno receiptsThis chapter's world alone, before epoch 1. Reduced by TRVM's forge in 2.469s; the forge's id equals the seal above.

Receipts in the last epoch's Film

receipt:w=7,s=1,accepted=0b,apkey=0.0.255.0.0.0,epoch=1,outcome=Applied
receipt:w=9,s=1,accepted=5c,apkey=0.0.0.0.255.0,epoch=3,outcome=Applied
The Film, epoch by epoch (6)

epoch 1 · sha256:4facc1ac2251a4777e76dd3f436c1561b219bfbee20e1af2393def5e8b738c2f

FILM v0.7
t=1
spinner:ip_world:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00ff,0000,0000,0000,socket=ip_view,config=configurable
orb:ip_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=ip_world,fault=0
pulser:ip_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
relay:ip_in:cur_out=0,next_out=1
wire:w__ip_bench__ip_in:cur=1,nxt=1
wire:w__ip_in__ip_world:cur=0,nxt=0
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=7,s=1,digest=0b,pkey=0.0.255.0.0.0,payload=SetRotor:ip_world:255.0.0.0
receipt:w=7,s=1,accepted=0b,apkey=0.0.255.0.0.0,epoch=1,outcome=Applied
recognition:w=7,s=1,state=unambiguous

epoch 2 · sha256:bc8c7f1b849a86bb8f90f612503f663ec9a2aa89f221aeaf60655bf5407d8340

FILM v0.7
t=2
spinner:ip_world:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00ff,0000,0000,0000,socket=ip_view,config=configurable
orb:ip_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=ip_world,fault=0
pulser:ip_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
relay:ip_in:cur_out=1,next_out=1
wire:w__ip_bench__ip_in:cur=1,nxt=1
wire:w__ip_in__ip_world:cur=0,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=7,s=1,digest=0b,pkey=0.0.255.0.0.0,payload=SetRotor:ip_world:255.0.0.0
receipt:w=7,s=1,accepted=0b,apkey=0.0.255.0.0.0,epoch=1,outcome=Applied
recognition:w=7,s=1,state=unambiguous

epoch 3 · sha256:7cd76c0e21bbc2eaa790df6747952830cb4d64f5d9c22d2e6762da3af2b70dce

FILM v0.7
t=3
spinner:ip_world:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=0000,0000,00ff,0000,socket=ip_view,config=configurable
orb:ip_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0000,0000,00ff,0000,controller=ip_world,fault=0
pulser:ip_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
relay:ip_in:cur_out=1,next_out=1
wire:w__ip_bench__ip_in:cur=1,nxt=1
wire:w__ip_in__ip_world:cur=1,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=7,s=1,digest=0b,pkey=0.0.255.0.0.0,payload=SetRotor:ip_world:255.0.0.0
claim:w=9,s=1,digest=5c,pkey=0.0.0.0.255.0,payload=SetRotor:ip_world:0.0.255.0
receipt:w=7,s=1,accepted=0b,apkey=0.0.255.0.0.0,epoch=1,outcome=Applied
receipt:w=9,s=1,accepted=5c,apkey=0.0.0.0.255.0,epoch=3,outcome=Applied
recognition:w=7,s=1,state=unambiguous
recognition:w=9,s=1,state=unambiguous

epoch 4 · sha256:f22e4f00feb27da87d17d346264ca9ab0cf23f8bfd9dbb8e04d6f1b4d31f6a2e

FILM v0.7
t=4
spinner:ip_world:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=0000,0000,00ff,0000,socket=ip_view,config=configurable
orb:ip_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=ff02,0000,0000,0000,controller=ip_world,fault=0
pulser:ip_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
relay:ip_in:cur_out=1,next_out=1
wire:w__ip_bench__ip_in:cur=1,nxt=1
wire:w__ip_in__ip_world:cur=1,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=7,s=1,digest=0b,pkey=0.0.255.0.0.0,payload=SetRotor:ip_world:255.0.0.0
claim:w=9,s=1,digest=5c,pkey=0.0.0.0.255.0,payload=SetRotor:ip_world:0.0.255.0
receipt:w=7,s=1,accepted=0b,apkey=0.0.255.0.0.0,epoch=1,outcome=Applied
receipt:w=9,s=1,accepted=5c,apkey=0.0.0.0.255.0,epoch=3,outcome=Applied
recognition:w=7,s=1,state=unambiguous
recognition:w=9,s=1,state=unambiguous

epoch 5 · sha256:61b54c3a8791d1f86513a3ae529f01bc517c0461213e13fe5740f18e8a5736a5

FILM v0.7
t=5
spinner:ip_world:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=0000,0000,00ff,0000,socket=ip_view,config=configurable
orb:ip_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0000,0000,ff03,0000,controller=ip_world,fault=0
pulser:ip_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
relay:ip_in:cur_out=1,next_out=1
wire:w__ip_bench__ip_in:cur=1,nxt=1
wire:w__ip_in__ip_world:cur=1,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=7,s=1,digest=0b,pkey=0.0.255.0.0.0,payload=SetRotor:ip_world:255.0.0.0
claim:w=9,s=1,digest=5c,pkey=0.0.0.0.255.0,payload=SetRotor:ip_world:0.0.255.0
receipt:w=7,s=1,accepted=0b,apkey=0.0.255.0.0.0,epoch=1,outcome=Applied
receipt:w=9,s=1,accepted=5c,apkey=0.0.0.0.255.0,epoch=3,outcome=Applied
recognition:w=7,s=1,state=unambiguous
recognition:w=9,s=1,state=unambiguous

epoch 6 · sha256:10f15a32782ce94f1f7e8b732593e3bac86d6d1fd1a4a0e6ff1337d6954df621

FILM v0.7
t=6
spinner:ip_world:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=0000,0000,00ff,0000,socket=ip_view,config=configurable
orb:ip_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=00fc,0000,0000,0000,controller=ip_world,fault=0
pulser:ip_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
relay:ip_in:cur_out=1,next_out=1
wire:w__ip_bench__ip_in:cur=1,nxt=1
wire:w__ip_in__ip_world:cur=1,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=7,s=1,digest=0b,pkey=0.0.255.0.0.0,payload=SetRotor:ip_world:255.0.0.0
claim:w=9,s=1,digest=5c,pkey=0.0.0.0.255.0,payload=SetRotor:ip_world:0.0.255.0
receipt:w=7,s=1,accepted=0b,apkey=0.0.255.0.0.0,epoch=1,outcome=Applied
receipt:w=9,s=1,accepted=5c,apkey=0.0.0.0.255.0,epoch=3,outcome=Applied
recognition:w=7,s=1,state=unambiguous
recognition:w=9,s=1,state=unambiguous

Composes with the 29 chapters before it

The chain through this chapter — every earlier fragment, this one, and the links — seals to sem-3a8432458a2c00cdb3c6ee824c2babf74fafb04c16c95a8812100d029b5d9bc3: 103 objects, 93 edges (was 100 / 90; every earlier object and edge is still present — checked, or the build refuses).

Links only the chain carries

[rg_sufficiency] --sig--> [ip_in]
How to read this board

Five kinds of object, two kinds of wire, and one band per Part of the book. Signal flows left to right: it starts at a clock, travels through relays, and ends at a door — or turns a spinner, which drives an orb. Nothing below is the book's own vocabulary; each line is quoted from where the definition lives.

shapeisand so
a clock; the only source of signalEvery signal on the board starts at one of these. Nothing else can make one.
a pass-through, so signal can travelOne arrives, any number leave — a relay that fans out is the board's router.
a sink; signal arrives and stopsIt latches what reached it and passes nothing on. A door is where a path ends.
rotation: takes signal, drives a poseThe only object on the board that holds a value a claim can rewrite — and only if its config says configurable.
the thing that gets movedIt is driven, never driving: an orb is what you watch to see whether anything happened.
not a WRL role — the book's own drawing of the receipts in the epoch's FilmIt counts what the run admitted, and turns red on a Rejected outcome.
SignalWiresignal: a sig_out to a sig_inLegal from a Pulser or Relay, into a Relay, Door or Spinner. This is how the board moves.
SocketControlcontrol: a socket to a poseLegal only from a Spinner into an Orb. At most one may land on any input port — fan-in is a typed refusal.

Hover any object for what it is, which chapter put it there, and every field of its line in that epoch's Film — split into what it is doing now and how it was built. Click to pin the readout, then click a wired name to follow the signal. The field definitions come from TRVM/forge/film.py (the emitter), TRVM/forge/forge_state.py (nf, derived from the decoded counter and never from t), TRVM/forge/lower_e2a.py (the commit/react law), TRVM/FORGE_SEMANTIC_IR_v1_MEASURE.md §1.3; the shapes from WRL/learn.html and WRL/docs/spec/README.md. The build refuses if a Film emits a field this key does not explain.

compute surfaceI · The LocusII · CompositionIII · ProgressIV · Persistence and WorldV · Agencyal_locus · Spinneral_locusspinneral_view · Orbal_vieworbal_world · Pulseral_worldpulsercb_fixed · Spinnercb_fixedspinnercb_gate · Doorcb_gatedoorcb_in · Relaycb_inrelaycb_view · Orbcb_vieworbcc_carrier · Doorcc_carrierdoorcc_grant · Relaycc_grantrelaycm_in · Relaycm_inrelaycm_locus0 · Doorcm_locus0doorcm_locus1 · Doorcm_locus1doorcm_locus2 · Doorcm_locus2doorcm_locus3 · Doorcm_locus3doorcm_slot0 · Relaycm_slot0relaycm_slot1 · Relaycm_slot1relaycm_slot2 · Relaycm_slot2relaycm_slot3 · Relaycm_slot3relayct_in · Relayct_inrelayct_locus · Spinnerct_locusspinnerct_view · Orbct_vieworbcx_in · Relaycx_inrelaycx_machine0 · Relaycx_machine0relaycx_machine1 · Relaycx_machine1relaycx_replay0 · Doorcx_replay0doorcx_replay1 · Doorcx_replay1doordb_clock · Pulserdb_clockpulserdb_locus · Spinnerdb_locusspinnerdb_view · Orbdb_vieworbec_in · Relayec_inrelayec_ledger · Doorec_ledgerdoorec_subject · Spinnerec_subjectspinnerec_witness · Orbec_witnessorben_act · Dooren_actdooren_established · Relayen_establishedrelayen_in · Relayen_inrelayer_a · Relayer_arelayer_b · Relayer_brelayer_clock · Pulserer_clockpulserer_player · Doorer_playerdoorip_in · Relayip_inrelayip_view · Orbip_vieworbip_world · Spinnerip_worldspinneris_id · Orbis_idorbis_in · Relayis_inrelayis_seal · Spinneris_sealspinnerlc_core · Relaylc_corerelaylc_locus · Spinnerlc_locusspinnerlc_machine · Relaylc_machinerelaylc_thread · Relaylc_threadrelaylc_view · Orblc_vieworbmh_clock · Pulsermh_clockpulsermh_gate · Doormh_gatedoorop_clock · Pulserop_clockpulserop_locus · Spinnerop_locusspinnerop_view · Orbop_vieworbpj_artifact · Spinnerpj_artifactspinnerpj_in · Relaypj_inrelaypj_view_a · Orbpj_view_aorbpj_view_b · Orbpj_view_borbpp_homeA · Relaypp_homeArelaypp_homeB · Relaypp_homeBrelaypp_in · Relaypp_inrelaypp_locus · Spinnerpp_locusspinnerpp_view · Orbpp_vieworbpq_a · Relaypq_arelaypq_b · Relaypq_brelaypq_clock · Pulserpq_clockpulserpq_done · Doorpq_donedoorpu_admitted · Orbpu_admittedorbpu_busy · Pulserpu_busypulserpu_hop0 · Relaypu_hop0relaypu_hop1 · Relaypu_hop1relaypu_hop2 · Relaypu_hop2relaypu_locus · Spinnerpu_locusspinnerpu_progress · Pulserpu_progresspulserpu_sink · Doorpu_sinkdoorrb_record · Orbrb_recordorbrd_in · Relayrd_inrelayrd_real · Spinnerrd_realspinnerrd_view · Orbrd_vieworbrg_in · Relayrg_inrelayrg_page · Doorrg_pagedoorrg_sufficiency · Relayrg_sufficiencyrelayrj_join · Doorrj_joindoorrj_r · Relayrj_rrelaysd_in · Relaysd_inrelaysd_state · Spinnersd_statespinnersd_view · Orbsd_vieworbsm_in · Relaysm_inrelaysm_inside · Spinnersm_insidespinnersm_outside_a · Orbsm_outside_aorbsm_outside_b · Orbsm_outside_borbso_in · Relayso_inrelayso_pose · Orbso_poseorbso_rotor · Spinnerso_rotorspinnerts_root · Doorts_rootdoorts_version · Pulserts_versionpulsertv_a · Orbtv_aorbtv_b · Orbtv_borbtv_fixed · Spinnertv_fixedspinnertv_in · Relaytv_inrelaytv_open · Spinnertv_openspinner

The board so far: one band per Part, signal flowing left to right; relays that fan out are routers, doors are switches, pulsers are clock domains. Hover an object — or click the board and walk it with the arrow keys — for its role, its Part and what it is wired to. This board is the chain’s sealed shape; no Film drives it, so it has no state to report, and the whole board in the conclusion is where every object’s state is read epoch by epoch. Wheel zooms · drag pans · double-click fits.

Syntax — quoted from the tree at build time

The three outcomes, where they are specified (super/docs/reviews) super/docs/reviews/D_1_3C_2D_2_INTERVENTION_PROVENANCE.md:22

| 2 | the record is "appended before the ioctl is requested, **settled to** APPLIED/REFUSED/INDETERMINATE after" (§7) | `Ampd.Receipts` has **no update-in-place operation at all**. Three writes exist: append, wholesale replace, truncate. This is not implementable. | J2 |
| 3 | interventions are "keyed on `target.actor`, so `Ampd.Projection.agent/1`'s existing `record["actor"] == actor` filter is reused *correctly*" (§6, lines 260–262) | the filter reads a **top-level** `"actor"` (`projection.ex:231`). A nested `target.actor` yields `nil`, every intervention is dropped, and the C3 ruling is unmet with no crash and no failing test. | J3 |

Forces

Provenance costs a record per action and a key to attribute to. When the natural key (a terminal authority shared across peers) does not exist, the honest move is to key on what does — a Worker and its generation — and to say so, rather than invent the missing authority.

Applicability

Agent runtimes acting on user machines, terminal possession, any actuator shared between principals.

Transformations

Preserving
  • revoking a generation and refusing its later interventions
  • appending observations beside an attempt
Refusing
  • an intervention without a Worker and generation
  • rewriting an outcome
  • a repair path with zero callers presented as a property

A refusing transformation is not one that is discouraged: it is one that, applied, makes the invariant above false. The word is the tree's, and it is the same word the join uses.

Consequences

Interventions become answerable. The honest status: STATED, in a lane this book does not edit, with the specification's unimplemented dependency printed beside it.

Failure mode it answers

Agent Omniscience — Letting an agent's claims exceed its evidence boundary. Paid for at: AGENCY.md §6 (what is established vs a reading)

Witness

No witness. This pattern is STATED — the tree has no check for its invariant.

Counterexample

No counterexample shipped (required only when WITNESSED).

What to take away

  1. from the animationThe unattributed action was refused; the same action with Worker, generation and evidence was applied.
  2. from the syntaxThe policy is keyed on Worker + generation because the authority it would rather key on did not exist.
  3. from the literatureW3C PROV; surgical counts; the audit log that is a precondition rather than a record.
  4. from the witnessSTATED: the review in super/ specifies it and names its own unimplemented re-observation.

Invariant basis — and how each piece bears

basisbearsstatus
cell 17necessaryproved cells.json

Satisfying a basis is local. Nothing here implies global adequacy unless a theorem or a composition rule says so.

Prior art — and what is not claimed

workrelationwhat it shareswhere it differs
W3C PROVantecedenta standard vocabulary for who did what to whatPROV records provenance; the pattern requires the record to be re-observable
Audit logsrealizationappend-only record of intervention (cell 17)a log records the request; the pattern wants the effect re-observed

Novelty not claimed. Provenance standards exist and are better developed than this. The witness lives in super/, and the honest half of the record is that the re-observation it depends on does not exist — Pty::winsize() has zero callers.

Realizations in the tree

Relations with other patterns

Three-Valued Outcome STATED