OpenSentience.orgUnboxed PatternsChapter 27 of 32 · Agency

UP-027 · Agency · WITNESSED CHECKABLE RUNNABLE EXECUTED STAGED

State Does Not Grant Authority

A fact about a locus never constitutes a power.

Admissible action = f(established state, explicit grant, policy, contracts), never f(established state) alone; a fact about a locus never constitutes a power.
Standing
WITNESSED CHECKABLE RUNNABLE EXECUTED STAGED PUBLISHED REPRODUCED
Last checked
2026-09-11 15:27:41 UTC
Source
scripts/check-messaging-language.mjs @ 92d99bf0f69f · bytes 4c1baac1ee7b0a39…
Limit
Miller's argument restated for loci. It does not establish that any component in this tree refuses a state-derived authority claim, and under R7's criterion its family placement is itself unruled.
Next rung
live_local — a refusal on this page when authority is requested on the strength of a fact about the requester. The invariant is Miller's; what is missing is a place a reader can watch it hold.
Why this page says WITNESSED — the derivation, not the word
  • ✓ a witness is named
  • ✓ its evidence kind is one the ledger already uses (counterexample)
  • ✓ the witness path resolves in this tree
  • ✓ its rung is in_tree or above (in_tree)
  • ✓ a run is recorded for these exact bytes
  • ✓ no claim is cited that could be REFUTED
  • ✓ a counterexample is shipped (required once WITNESSED)
  • ✗ not staged on this site, so it cannot run from the page

WITNESSED requires every line above to hold. The label is computed from them by build.mjs and cannot be typed into the registry — the build refuses a record that carries it.

Intent

An established state may justify or constrain the issuance of authority; it never is the grant. Admissible action is a function of established state, an explicit grant, the governing policy and the contracts in force — never of state alone. The sentence that puts the grant inside the state is retired in AGENCY.md §4, and a gate refuses every paraphrase of it.

Technical register

AGENCY.md §4: the chain is established state + policy + explicit grant → admissible authority. Admissible action = f(established state, explicit authority, policy, contracts). The lint class STATE_DOES_NOT_ISSUE_AUTHORITY rejects the paraphrases; the invariants table's 'authority' field means the authority consequence an invariant is proposed to justify, not one it issues. Under ruling R7's criterion this pattern may belong to the locus family.

Problem

'I am the admin, therefore I may.' Every system that derives permission from an attribute of the subject has built ambient authority with an extra step: the attribute is observed once and then stands in for a grant forever. The Periodic Table shipped three paraphrases of it before the lint existed.

Solution

Keep grants as first-class objects with scope and policy preconditions. Evaluate admissibility as a function of the grant and the state, not of the state. Retire the sentences that skip the grant, list them, and run the list over every page that talks about authority.

Real-world analogy

A surgeon's licence is a grant; being a surgeon is a state. The licence can be suspended while the skill remains, and the skill never operated on anyone by itself.

Structure — on the surface

compute surfaceadmissible?admissible?sestablished: is-admin = trueAn established state, a policy, and the explicit grant that the state alone never is.

An illustration on a compute surface: loci above, carriers below. Press Play or Step; the takeaways collect as you go. Nothing here is evidence — the witness section is.

The chapter in WRL — and the chain so far

Chapter 27 of 32 — the fragment _patterns/wrl/chain/state-does-not-grant-authority.wrl, sealed alone by wrl.js

; STATE DOES NOT GRANT AUTHORITY — sd_state has state (a rotor) and no grant (not configurable). The claim at
; epoch 1 is Rejected(not_configurable). sd_in is the entry, fed by the established router.
[relay:sd_in]{sig_in, sig_out}
[spinner:sd_state](w=16, n=8, rotor=quarter_turn_z){sig_in, socket}
[orb:sd_view]{pose}

[sd_in] --sig--> [sd_state]
[sd_state] --socket--> [sd_view]

Its test bench _patterns/wrl/chain/state-does-not-grant-authority.bench.wrl — drives the entry for this chapter's own film; never part of the chain

; TEST BENCH — drives this chapter's entry alone; the chain replaces it with a wire from an earlier chapter
[pulser:sd_bench](every 1){sig_out}
[sd_bench] --sig--> [sd_in]

module + bench seal to → sem-0ab417c00718d1f43f30db9db1edf8a84b2e934f090672a74092941e3de55120

Run inputs — a ScenarioV1, the forge's own document, bound to this world's id and never part of it (D3) · ScenarioDigest scen-878c56a31ba154bc7e1… (the run inputs' own identity, computed by the forge)

epochwriter · seqoptargetrotorlabel
1w1 s1SetRotorsd_state255.0.0.0SetRotor sd_state 255.0.0.0

Reduced by the native reducer (ic32); the reference reducer reproduces every epoch's film hash (45.52s).

compute surfacesigsigsocketsd_bench · Pulsersd_benchpulsersd_in · Relaysd_inrelaysd_state · Spinnersd_statespinnersd_view · Orbsd_vieworbledger · receipts · Ledgerledger · receiptsno receiptsThis chapter's world alone, before epoch 1. Reduced by TRVM's forge in 2.469s; the forge's id equals the seal above.

Receipts in the last epoch's Film

receipt:w=1,s=1,accepted=f0,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable)
The Film, epoch by epoch (6)

epoch 1 · sha256:787eff16dda2c6f9eb2bd281227f1368a7057056fb24cab73d080b956458e3ca

FILM v0.7
t=1
spinner:sd_state:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=sd_view,config=fixed
orb:sd_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=sd_state,fault=0
pulser:sd_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
relay:sd_in:cur_out=0,next_out=1
wire:w__sd_bench__sd_in:cur=1,nxt=1
wire:w__sd_in__sd_state:cur=0,nxt=0
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=1,s=1,digest=f0,pkey=0.0.255.0.0.0,payload=SetRotor:sd_state:255.0.0.0
receipt:w=1,s=1,accepted=f0,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable)
recognition:w=1,s=1,state=unambiguous

epoch 2 · sha256:c9d94e6d9caf116ed18d63cd33a5429d4a37b9bcd0035545640362530d2c56c8

FILM v0.7
t=2
spinner:sd_state:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=sd_view,config=fixed
orb:sd_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=sd_state,fault=0
pulser:sd_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
relay:sd_in:cur_out=1,next_out=1
wire:w__sd_bench__sd_in:cur=1,nxt=1
wire:w__sd_in__sd_state:cur=0,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=1,s=1,digest=f0,pkey=0.0.255.0.0.0,payload=SetRotor:sd_state:255.0.0.0
receipt:w=1,s=1,accepted=f0,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable)
recognition:w=1,s=1,state=unambiguous

epoch 3 · sha256:401a14a099d43566e5b445049a6be4c77943b19d3ddddbe10e9a88aae6455204

FILM v0.7
t=3
spinner:sd_state:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=sd_view,config=fixed
orb:sd_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=00b5,0000,0000,00b5,controller=sd_state,fault=0
pulser:sd_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
relay:sd_in:cur_out=1,next_out=1
wire:w__sd_bench__sd_in:cur=1,nxt=1
wire:w__sd_in__sd_state:cur=1,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=1,s=1,digest=f0,pkey=0.0.255.0.0.0,payload=SetRotor:sd_state:255.0.0.0
receipt:w=1,s=1,accepted=f0,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable)
recognition:w=1,s=1,state=unambiguous

epoch 4 · sha256:13fdb57fa3e562b3b1f32c4a99d9aa8121392db59162ad90f7d295bdcfad1de1

FILM v0.7
t=4
spinner:sd_state:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=sd_view,config=fixed
orb:sd_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0000,0000,0000,00ff,controller=sd_state,fault=0
pulser:sd_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
relay:sd_in:cur_out=1,next_out=1
wire:w__sd_bench__sd_in:cur=1,nxt=1
wire:w__sd_in__sd_state:cur=1,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=1,s=1,digest=f0,pkey=0.0.255.0.0.0,payload=SetRotor:sd_state:255.0.0.0
receipt:w=1,s=1,accepted=f0,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable)
recognition:w=1,s=1,state=unambiguous

epoch 5 · sha256:e34979673ad2110d0ec85d5c5363d27ac5cb37a8d8a21cda6ac8ae6fcf24f7cc

FILM v0.7
t=5
spinner:sd_state:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=sd_view,config=fixed
orb:sd_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=ff4c,0000,0000,00b4,controller=sd_state,fault=0
pulser:sd_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
relay:sd_in:cur_out=1,next_out=1
wire:w__sd_bench__sd_in:cur=1,nxt=1
wire:w__sd_in__sd_state:cur=1,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=1,s=1,digest=f0,pkey=0.0.255.0.0.0,payload=SetRotor:sd_state:255.0.0.0
receipt:w=1,s=1,accepted=f0,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable)
recognition:w=1,s=1,state=unambiguous

epoch 6 · sha256:29afb9fb302781107834cb343344b744b9152b09051fb09956f8a20990b49b3d

FILM v0.7
t=6
spinner:sd_state:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=sd_view,config=fixed
orb:sd_view:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=ff02,0000,0000,0000,controller=sd_state,fault=0
pulser:sd_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1
relay:sd_in:cur_out=1,next_out=1
wire:w__sd_bench__sd_in:cur=1,nxt=1
wire:w__sd_in__sd_state:cur=1,nxt=1
admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0
claim:w=1,s=1,digest=f0,pkey=0.0.255.0.0.0,payload=SetRotor:sd_state:255.0.0.0
receipt:w=1,s=1,accepted=f0,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable)
recognition:w=1,s=1,state=unambiguous

Composes with the 26 chapters before it

The chain through this chapter — every earlier fragment, this one, and the links — seals to sem-e6779c4ebcb2ddcbf20ad935efdf96bff9402014c84df0b683200bed9b61886b: 93 objects, 83 edges (was 90 / 80; every earlier object and edge is still present — checked, or the build refuses).

Links only the chain carries

[en_established] --sig--> [sd_in]
How to read this board

Five kinds of object, two kinds of wire, and one band per Part of the book. Signal flows left to right: it starts at a clock, travels through relays, and ends at a door — or turns a spinner, which drives an orb. Nothing below is the book's own vocabulary; each line is quoted from where the definition lives.

shapeisand so
a clock; the only source of signalEvery signal on the board starts at one of these. Nothing else can make one.
a pass-through, so signal can travelOne arrives, any number leave — a relay that fans out is the board's router.
a sink; signal arrives and stopsIt latches what reached it and passes nothing on. A door is where a path ends.
rotation: takes signal, drives a poseThe only object on the board that holds a value a claim can rewrite — and only if its config says configurable.
the thing that gets movedIt is driven, never driving: an orb is what you watch to see whether anything happened.
not a WRL role — the book's own drawing of the receipts in the epoch's FilmIt counts what the run admitted, and turns red on a Rejected outcome.
SignalWiresignal: a sig_out to a sig_inLegal from a Pulser or Relay, into a Relay, Door or Spinner. This is how the board moves.
SocketControlcontrol: a socket to a poseLegal only from a Spinner into an Orb. At most one may land on any input port — fan-in is a typed refusal.

Hover any object for what it is, which chapter put it there, and every field of its line in that epoch's Film — split into what it is doing now and how it was built. Click to pin the readout, then click a wired name to follow the signal. The field definitions come from TRVM/forge/film.py (the emitter), TRVM/forge/forge_state.py (nf, derived from the decoded counter and never from t), TRVM/forge/lower_e2a.py (the commit/react law), TRVM/FORGE_SEMANTIC_IR_v1_MEASURE.md §1.3; the shapes from WRL/learn.html and WRL/docs/spec/README.md. The build refuses if a Film emits a field this key does not explain.

compute surfaceI · The LocusII · CompositionIII · ProgressIV · Persistence and WorldV · Agencyal_locus · Spinneral_locusspinneral_view · Orbal_vieworbal_world · Pulseral_worldpulsercb_fixed · Spinnercb_fixedspinnercb_gate · Doorcb_gatedoorcb_in · Relaycb_inrelaycb_view · Orbcb_vieworbcc_carrier · Doorcc_carrierdoorcc_grant · Relaycc_grantrelaycm_in · Relaycm_inrelaycm_locus0 · Doorcm_locus0doorcm_locus1 · Doorcm_locus1doorcm_locus2 · Doorcm_locus2doorcm_locus3 · Doorcm_locus3doorcm_slot0 · Relaycm_slot0relaycm_slot1 · Relaycm_slot1relaycm_slot2 · Relaycm_slot2relaycm_slot3 · Relaycm_slot3relayct_in · Relayct_inrelayct_locus · Spinnerct_locusspinnerct_view · Orbct_vieworbcx_in · Relaycx_inrelaycx_machine0 · Relaycx_machine0relaycx_machine1 · Relaycx_machine1relaycx_replay0 · Doorcx_replay0doorcx_replay1 · Doorcx_replay1doordb_clock · Pulserdb_clockpulserdb_locus · Spinnerdb_locusspinnerdb_view · Orbdb_vieworben_act · Dooren_actdooren_established · Relayen_establishedrelayen_in · Relayen_inrelayer_a · Relayer_arelayer_b · Relayer_brelayer_clock · Pulserer_clockpulserer_player · Doorer_playerdooris_id · Orbis_idorbis_in · Relayis_inrelayis_seal · Spinneris_sealspinnerlc_core · Relaylc_corerelaylc_locus · Spinnerlc_locusspinnerlc_machine · Relaylc_machinerelaylc_thread · Relaylc_threadrelaylc_view · Orblc_vieworbmh_clock · Pulsermh_clockpulsermh_gate · Doormh_gatedoorop_clock · Pulserop_clockpulserop_locus · Spinnerop_locusspinnerop_view · Orbop_vieworbpj_artifact · Spinnerpj_artifactspinnerpj_in · Relaypj_inrelaypj_view_a · Orbpj_view_aorbpj_view_b · Orbpj_view_borbpp_homeA · Relaypp_homeArelaypp_homeB · Relaypp_homeBrelaypp_in · Relaypp_inrelaypp_locus · Spinnerpp_locusspinnerpp_view · Orbpp_vieworbpq_a · Relaypq_arelaypq_b · Relaypq_brelaypq_clock · Pulserpq_clockpulserpq_done · Doorpq_donedoorpu_admitted · Orbpu_admittedorbpu_busy · Pulserpu_busypulserpu_hop0 · Relaypu_hop0relaypu_hop1 · Relaypu_hop1relaypu_hop2 · Relaypu_hop2relaypu_locus · Spinnerpu_locusspinnerpu_progress · Pulserpu_progresspulserpu_sink · Doorpu_sinkdoorrb_record · Orbrb_recordorbrd_in · Relayrd_inrelayrd_real · Spinnerrd_realspinnerrd_view · Orbrd_vieworbrj_join · Doorrj_joindoorrj_r · Relayrj_rrelaysd_in · Relaysd_inrelaysd_state · Spinnersd_statespinnersd_view · Orbsd_vieworbsm_in · Relaysm_inrelaysm_inside · Spinnersm_insidespinnersm_outside_a · Orbsm_outside_aorbsm_outside_b · Orbsm_outside_borbso_in · Relayso_inrelayso_pose · Orbso_poseorbso_rotor · Spinnerso_rotorspinnerts_root · Doorts_rootdoorts_version · Pulserts_versionpulsertv_a · Orbtv_aorbtv_b · Orbtv_borbtv_fixed · Spinnertv_fixedspinnertv_in · Relaytv_inrelaytv_open · Spinnertv_openspinner

The board so far: one band per Part, signal flowing left to right; relays that fan out are routers, doors are switches, pulsers are clock domains. Hover an object — or click the board and walk it with the arrow keys — for its role, its Part and what it is wired to. This board is the chain’s sealed shape; no Film drives it, so it has no state to report, and the whole board in the conclusion is where every object’s state is read epoch by epoch. Wheel zooms · drag pans · double-click fits.

Syntax — quoted from the tree at build time

The trap and the chain, verbatim (AGENCY.md §4) AGENCY.md:172

### State does not grant authority — the ambient-authority trap

The natural phrasing is *"the authority that state grants"*, and it is wrong in a way that undoes the <!-- lint-allow:STATE_DOES_NOT_ISSUE_AUTHORITY — quotes the retired phrasing in order to retire it -->
architecture. It licenses

```

The lint class, from the rules the gate runs scripts/messaging-rules.json:32

      "id": "STATE_DOES_NOT_ISSUE_AUTHORITY",
      "why": "AGENCY.md §4. An established state may justify or constrain the issuance of authority; it never constitutes the grant. `fact about me => power` is ambient authority with an extra step. The chain is: established state + policy + explicit grant -> admissible authority.",
      "instead": "\"the scoped authority associated with that established state\", or \"explicit scoped grants whose policy preconditions that state satisfies\". For the invariants table: \"a stated authority consequence\" / \"Authority claim\".",
      "scope": [
        "sites",

Forces

Attributes are cheap to check and grants are paperwork. Policies genuinely do depend on state — a grant may have preconditions the state must satisfy — which is why the sentence is so easy to write wrong: the state is in the chain, just not at the end of it.

Applicability

Access control, agent authority, capability tokens, and every paragraph of copy about any of them.

Transformations

Preserving
  • a policy whose preconditions a state satisfies
  • narrowing a grant's scope
  • revoking a grant while the state persists
Refusing
  • the sentence that makes a state the source of a grant (retired; the gate lists its paraphrases)
  • deriving admissibility from state alone
  • a field named authority read as proof that nothing exceeds it

A refusing transformation is not one that is discouraged: it is one that, applied, makes the invariant above false. The word is the tree's, and it is the same word the join uses.

Consequences

Authority becomes a thing that can be revoked, scoped and audited separately from the facts that justified it. The counterexample on this page is a sentence, and that is the point: a vocabulary pattern's falsifier is a lint.

Failure mode it answers

Ambient Authority — Granting access to an environment because some part of it needs one capability. Paid for at: AGENCY.md §4 (the phrasing that walks into it); Miller 2003 is the term's source

Witness

Source identity: scripts/check-messaging-language.mjs · shape lint · evidence kind counterexample · rung in_tree (rule class STATE_DOES_NOT_ISSUE_AUTHORITY)

Execution identity: 2026-09-11T15:27:41.066Z on PX13 · bytes 4c1baac1ee7b0a39… · repo HEAD 92d99bf0f69f

Not staged on this site: the page cannot run this witness. It runs from the command line: node scripts/check-messaging-language.mjs in ..

Counterexample

A sentence the ontology gate rejects: the authority that state grants — expected REFUSED.

What to take away

  1. from the animationThe established fact was refused alone and admitted with a scoped grant beside it.
  2. from the syntaxAdmissible action = f(state, grant, policy, contracts) — the state is an argument, never the function.
  3. from the literatureObject-capability discipline: authority is what you hold, not what you are.
  4. from the witnessThe gate rejected the counterexample sentence in this very registry until it was quarantined by rule id.

Prior art — and what is not claimed

workrelationwhat it shareswhere it differs
Object-capability discipline (Miller)antecedenta fact about a subject is not a permissionnone claimed — AGENCY.md §4 states it as 'fact about me ⇒ power is ambient authority with an extra step'

Novelty not claimed. This is Miller's argument restated for loci. Under R7's family criterion it may belong in the locus family rather than agency; that placement is unruled.

Realizations in the tree

Relations with other patterns

Capability-Bounded Composition WITNESSED