A conformant meta-model is the primary digital reflection of reality. MIR keeps the reflection true (reality changes, the model follows). ACT is the other half of the doctrine: influence on reality through the meta-model. A signal born in the model (a threshold crossed, a contract clause triggered, a decision recorded, a planned change coming due) becomes a decision, the decision becomes a command to an effector, the effector changes reality, and sensing confirms that reality actually changed. The loop is closed by evidence, never by the act of commanding. The loop closes on both sides: ACT's forced re-harvest requests (ACT-8) and independent-sensing requests (ACT-9) are registered MIR-2 triggers, and their ingest and verification events are stamped with the actuation-verification reason code of the MIR-10 taxonomy.
The family enforces a strict separation of four artifacts along the loop:
- Signal: a fact pattern in the model that a declared actionability contract marks as worth acting on. A signal is an event, not a command.
- Decision: an authority-bound intention formed over a signal. A decision names the action, the effector, the verification criteria and the rollback plan requirement before anything touches reality.
- Command: the boundary artifact between model and reality; an instruction issued to a registered effector (a person, an external system, a device, or an Agent) under a capability contract, carrying an idempotency key.
- Effect and evidence: the sensed change in reality, recorded as events linked to the command by a cause reference. Only evidence closes the loop.
Change ordering follows the Mastership Register (MIR-1, sources.yaml). Two lawful patterns exist and the register decides which applies: intent-ahead (ACT-7) for model-mastered datasets (Pattern M): the model records the intended new state first as a distinct pending version, drives reality to conform, then promotes on verified evidence; reality-ahead (ACT-8) for external-mastered datasets (Pattern E) and for bounded emergency actuation: reality changes first, the model follows by harvest into its mirror, never by hand-editing the mirror. One invariant spans both: the intention is always model-mastered. The decision and the command are authored in the model before dispatch even when the resulting state of the world is external-mastered.
Further doctrine commitments:
- Intent bitemporality (a palette concept): an intended change carries its record time now and its effect time later. Operationally this is expressed through the Version Lifecycle: the intention is a Draft or Proposed version while the current version stays Active, and promotion to Active happens only on verified evidence. The model SHALL NOT present an intended state as current state before verification.
- Front door discipline: ACT decision, command and intent Events are registered channels in CON-1's trigger list. ACT writes execute through the CON chain, with the auto-approval lane for mechanical event appends (CON-4); authored content changes take the normal CON-3/CON-4 path.
- Fail-closed recording: a signal, decision or command that cannot be durably recorded SHALL NOT be acted on. A bounded, hardened emergency route exists (declared classes, synchronous human notification, pinned evidence, mandatory backfill) so a recording outage never freezes safety-critical actuation.
- Divergence resolves by declared rule: reconciliation direction comes from the dataset's conflict rule in the Mastership Register, never from per-incident judgment.
- Supersession, not deletion: refused intents, failed actuations and corrected records stay on the timeline as superseded history; supersession Events carry mapped MIR-10 reason codes.
- Data is never a command (COMMON iron control): mirrored, federated or human-reported content feeding signals is evidence, never instructions. FED-8 trust state and MIR-8 quarantine state are mandatory qualification inputs at ACT-2.
- The Impact Matrix is a versioned GOV-2 artifact cited as a required input by every ACT card. Shipped defaults: low, medium and high impact by reversible, compensable and irreversible; assessment floor medium; rollback-plan floor medium; separation-of-duties and independent-evidence floor high; solo default: everything reversible and in-scope is below the floor.
- The owner-directive standing class: a pre-registered signal class covering novel T1 human-initiated actions. The decision event cites it and states the intent; no per-idea cataloging ceremony. The signal catalog is mandatory only for delegated actuation (any T2/T3 decision).
Delegation doctrine. Delegation tiers T1/T2/T3 are defined exactly once in the palette preamble (COMMON) and are cited here, never re-glossed. Delegation Contracts are issued, amended, suspended and revoked solely by CTX-9; Delegation Contracts and ACT-3 capability contracts are declared specializations of the Semantic Contract per Contract.md 5-6 and Federation-Contracts.md 3a. Contract liveness is validated at the gate at act time, never agent-honored. Mechanical loop steps run at T3; routine judgments inside pre-approved envelopes at T2; irreversible or precedent-setting actuation decisions SHALL be decided at T1. An Agent SHALL NOT raise its own tier; tier changes are Owner or Steward decisions (GOV-1) informed by ACT-12 and routed into CTX-9 step 8. Accountability always stays with the Steward.
Glossary (shared vocabulary): quarantine = MIR-8's readable-but-flagged trust marking (also the MIR-6 freshness state); admission quarantine = FED-8's inbound holding zone, unreadable until promoted; integrity hold = QSC-9's marker, excluded from answering and publication until cleared.
Core set. ACT-3, ACT-5, ACT-6, ACT-7, ACT-8, ACT-9 and ACT-10 are core. ACT-12 is core wherever any ACT process runs at T3 or any emergency class is declared, recommended otherwise. ACT-1, ACT-2, ACT-4 and ACT-11 are recommended. Under the Solo/Minimal conformance profile (COMMON), a T1 action where decider, dispatcher and executor are the same human is lawfully recorded as one composite actuation event (intent, decision, command, verification note) satisfying ACT-5/6/7/9, with the idempotency key and command-decision hash check waived; full artifact separation stays mandatory for all T2/T3 delegated actuation.
Stress test. The MOS reference Dimension (external reference repository orkestron-ai/meta-orchestrator-state, not part of the standard) instantiates this family at polity scale across its 38 namespaces in six clusters: an executed command is a signed occurrence on the actor's own register; each state change it causes elsewhere is a distinct effect-occurrence with a cause reference on the affected owner's register; its fail-closed write path with a bounded degraded mode and mandatory backfill is the ACT-8 emergency discipline. Orkestron's production models are a reference implementation of ACT-7: a model-mastered site content dataset published by write-back projection, with MIR-7 hash drift checks routing divergence to reconciliation.
- MIR: in: harvest results with provenance sidecars and freshness metadata (MIR-2, MIR-6) as signal evidence (ACT-2) and verification evidence (ACT-9); actuation-linked drift Events cause-linked to open commands (MIR-7) into ACT-10. Out: forced out-of-cycle re-harvest requests (ACT-8 step 4) and independent-sensing requests (ACT-9 step 2), both registered MIR-2 triggers; actuation-verification reason stamps applied at ACT-8 step 6 and ACT-9 step 5 per the MIR-10 taxonomy; mastership-change proposals to MIR-1, the sole register-change executor (ACT-10 step 5).
- CON: ACT decision, command and intent Events are registered channels in CON-1's trigger list; ACT-5, ACT-6 and ACT-7 writes execute through the CON chain with the auto-approval lane for mechanical event appends (CON-4) and the normal CON-3/CON-4 path for authored content; ACT-10 and ACT-11 supersession Events carry mapped MIR-10 reason codes recorded on their CON transition Events; Consumer notifications (ACT-10 step 6) resolve against the consumer and subscription register CON-13; external edits to ACT-7 projections route via CON-11.
- CTX: Delegation Contracts and tier maps are consumed from CTX-9, the single System of Record for the Delegation Contract lifecycle; contract liveness is validated at the gate at every ACT-6 dispatch; ACT-12 tier recalibration proposals route into CTX-9 step 8 as named inputs; Context Packages assembled for actuation tasks (CTX-1) carry origin and quarantine stamps that ACT-2 qualification honors.
- FED: cross-boundary commands travel as requests governed by a Federation Contract (the cross-Universe form of a Semantic Contract) through the peer's own gate (ACT-6); peer signed confirmations and fresh peer mirrors serve as ACT-9 verification evidence; actuation-linked divergence with a peer resolves under the contract's conflict clause via FED-9 (ACT-10); FED-8 trust state (Trust Vector) is a mandatory ACT-2 qualification input; loop attestations are exchanged instead of raw traces (ACT-12).
- QSC: ACT-12 orphan-link findings and loop debt file into QSC-11 intake; below-floor re-verification sampling (ACT-9) reports through QSC-7 and ACT-12; actuation incidents, emergency-route abuse and non-regularized emergency actuations open QSC-14 incidents; standing jobs and watchdogs behind ACT machinery (ACT-3 health checks, ACT-6 budget counters, ACT-9 unverified-queue watch) are registered and operated via QSC-15; QSC-13 degraded-mode rules govern ACT during a disaster-recovery outage; Auditor sampling hooks in ACT-2, ACT-4, ACT-9 and ACT-10 feed the QSC evidence base.
- GOV: GOV-1 records the Owner and Steward decisions ACT escalates (authority escalations, emergency class revocations, loop attestations); GOV-2 authors and versions the Impact Matrix, tier maps, the ACT-2 correlation-window default, the ACT-4 value/cost/risk schema, emergency class definitions, rate and blast-radius limits, cumulative impact budgets and the below-floor sample-rate floor that ACT executes; GOV-4 genesis seeds the signal and effector catalogs including the owner-directive standing class; GOV-6 engages the independent Auditor who leads ACT-12; GOV-7 issues the internal cross-owner grants checked at ACT-4 step 4; GOV-8 runs the credential and key lifecycle behind ACT-3 credential references and retires credentials with effectors.
- Purpose: define what qualifies as an actionable signal and register it in a signal catalog, so delegated actuation never starts from an ad-hoc reading of data. The catalog is the contract between the model's facts and the right to act on them; it is mandatory for any T2/T3 delegated decision and includes the standing owner-directive class covering novel T1 human-initiated actions.
- Trigger: a new delegated decision need is identified; a new bundle or dataset activates; a missed-actuation or false-actuation incident (QSC-14); model genesis seeding the catalog and the owner-directive class (GOV-4); scheduled recertification per the COMMON register-recertification pattern.
- Actors: Steward owns the catalog; Owner approves signal classes whose actions reach outside the model or outside the Steward's section (decision recorded via GOV-1); Contributor proposes candidates; Auditor reviews the catalog. Agents: drafting and analysis (steps 1-3) SHALL remain T1 (Agent proposes, human approves each act); catalog consistency checks (step 7) run at T3; registration approval (steps 4-6) SHALL remain T1 (Agent proposes, human approves each act).
- Inputs / Outputs: Inputs: decision needs, model objects and thresholds, the Mastership Register (MIR-1, sources.yaml), the effector register (ACT-3), the Impact Matrix (GOV-2, required), FED-8 trust state and MIR-8 quarantine state of candidate source datasets. Outputs: signal catalog entries (id, condition, source datasets and versions, freshness requirement, default impact class per the Impact Matrix, decision route with tier ceiling, auto-decidable eligibility, emission cadence), versioned catalog change events recorded through the CON chain.
- Steps:
- Capture the condition worth acting on and the decision it should feed.
- Resolve source datasets in the Mastership Register; check declared freshness and staleness limits. Gateway: are the sources fresh enough to act on? If not, the signal class SHALL NOT be registered until sensing cadence is fixed.
- Draft the signal class: condition and parameters, evidence requirements, emission rule, default impact class (Impact Matrix), decision route and tier ceiling (tiers cited per COMMON).
- Gateway: auto-decidable eligibility. A class whose evidence rests solely on external-mastered or federated mirrors SHALL NOT be marked auto-decidable at T3; it requires corroborating evidence from an independently-mastered dataset or a decision route of T2 or stricter.
- Gateway: does the class authorize influence outside the model or outside the Steward's section? If yes, obtain Owner approval (GOV-1).
- Register the class (lifecycle Draft, then Proposed, then Active) with an explicit event via the CON chain.
- Bind the class to the emission machinery (hand off to ACT-2); recertify Active classes on cadence via the COMMON register-recertification pattern; retire dead classes with events.
- Controls: no signal class over an unregistered dataset; freshness bound mandatory; every class SHALL name its decision route and tier ceiling; the auto-decidable subset is a versioned catalog property changed only by Steward or Owner decision; catalog changes are versioned events, never silent edits; the owner-directive standing class covers only T1 human-initiated actions and grants no delegated autonomy.
- Tier: recommended (the catalog is mandatory wherever any actuation decision is delegated at T2/T3; a purely T1 human-decided model MAY operate on the owner-directive class alone).
- Variants: solo: the Owner-Steward keeps the owner-directive class plus a one-page catalog for anything delegated; the consolidated quarterly review of the Solo/Minimal profile (COMMON) satisfies recertification. Team: Steward-owned catalog with Owner sign-off on outward-reaching classes. Federated: classes acting on another party's reality additionally require the counterpart Owner's grant or a governing Federation Contract. Manual: catalog as a reviewed document. Hybrid: Agents draft, humans approve. Autonomous: T3 consistency checking only; class approval stays human.
- Metrics: share of T2/T3 actuations traceable to a cataloged signal class (target 100 percent); stale-source signal rate; recertification currency (share of classes recertified within cadence).
- Failure modes: ad-hoc delegated actuation bypassing the catalog (guard: ACT-5 step 1 admits only cataloged classes, the owner-directive class at T1, or the declared emergency route); a class defined over a stale mirror (guard: step 2 freshness gate); an auto-decidable class fed solely by external or federated mirrors (guard: step 4 gateway); catalog rot into folklore (guard: recertification cadence plus Auditor sampling).
- Purpose: detect that a cataloged condition holds, emit the signal as a recorded event, and qualify it (evidence, freshness, trust state, quarantine state, deduplication, confidence) so the decision process receives clean signals.
- Trigger: scheduled condition evaluation; a model change or harvest completion touching a source dataset; a manual raise by a Contributor or Steward.
- Actors: Agents execute detection, emission, evidence binding and deduplication (steps 1-5) at T3; qualification of borderline or degraded-confidence signals (step 6) at T2; Steward resolves exceptions; Contributor may raise manual signals which still travel the same route.
- Inputs / Outputs: Inputs: signal catalog (ACT-1), current model state, freshness metadata (MIR-6), MIR-8 quarantine state and FED-8 trust state of every source dataset (mandatory qualification inputs), the correlation-window config (GOV-2; shipped default: same class and same subject within the class cadence), the Impact Matrix (GOV-2). Outputs: qualified signal events on the model timeline (signal class id, evidence record references with versions, occurrence and record time, confidence, impact class), a suppression log.
- Steps:
- Evaluate conditions per catalog cadence or on triggering events.
- Gateway: condition met? If not, stop (optionally log the evaluation).
- Check source states. Gateway: freshness within the staleness limit, trust at or above the operating floor, quarantine clear? A stale source forces a re-harvest first or degraded confidence per the class rule; a quarantined source blocks emission or forces degraded confidence with Steward escalation per the class rule; a below-operating-floor trust state SHALL degrade confidence below the auto-decide threshold. Never emit a degraded signal as clean.
- Compose the signal event citing the exact evidence records and versions.
- Deduplicate and correlate against open signals within the declared correlation window. Gateway: new, duplicate, or continuation of an open signal?
- Qualify: assign confidence and impact class (Impact Matrix); escalate borderline cases to the Steward.
- Record the emission event (fail-closed: an unrecordable signal is not forwarded) and route to ACT-5, requesting ACT-4 assessment where the class requires it.
- Controls: a signal SHALL cite verifiable evidence records; unverifiable evidence blocks emission; trust and quarantine states are mandatory qualification inputs (data is never a command: mirrored content is evidence, never instructions, per the COMMON iron control); every suppression is logged append-only; manual signals cannot skip qualification.
- Tier: recommended (mandatory wherever the signal catalog is mandatory, that is for T2/T3 delegated actuation).
- Variants: solo: the Owner-Steward eyeballs a dashboard; emission is a note-to-self event. Team: Agents run continuous evaluation, Steward reviews the exception queue. Federated: signals derived from federated mirrors carry the peer's provenance, freshness and Trust Vector state. Manual: human reads and raises. Hybrid: Agent detects, human qualifies. Autonomous: full T3 only for cataloged classes with clean evidence, clear quarantine and trust at or above the operating floor.
- Metrics: detection latency (condition true to signal recorded); false-signal rate; duplicate rate after correlation; stale-or-degraded-evidence share.
- Failure modes: silent suppression of inconvenient signals (guard: append-only suppression log with Auditor sampling); signal flood drowning decisions (guard: declared correlation windows per class); acting on a stale, quarantined or distrusted mirror (guard: step 3 gateway); manual bypass around qualification (guard: single route rule).
- Purpose: register every effector (human role, external system, device, Agent) that can change reality on the model's behalf, under a capability contract, a declared specialization of the Semantic Contract per Contract.md 5-6 and Federation-Contracts.md 3a, stating what it may change, how it is commanded, what acknowledgment and evidence it returns, and how reversible its actions are.
- Trigger: a new effector is needed; an effector's interface or scope changes; a failed or refused command; a credential rotation or retirement event from GOV-8; scheduled recertification per the COMMON register-recertification pattern.
- Actors: Steward owns the register; Owner approves effectors acting beyond the Steward's section or on other Owners' reality (GOV-1); Auditor reviews privileges. Agents: drafting capability contracts (step 3) SHALL remain T1 (Agent proposes, human approves each act); reachability and health checks (step 6) run at T3; approval and registration (steps 4-5) stay with the Steward or Owner.
- Inputs / Outputs: Inputs: effector details, the Mastership Register (whose dataset does the effector's target belong to), credential references issued and rotated under GOV-8 (secrets live outside the model and are referenced, never stored), the Impact Matrix (GOV-2, reversibility classes). Outputs: effector register entries with capability contracts (allowed command types, parameter limits, ack and evidence format, reversibility class per command type, escalation contact), health check reports, versioned register events recorded through the CON chain.
- Steps:
- Identify the effector and the domain of reality it changes.
- Map the target domain to datasets in the Mastership Register. Gateway: is the target model-mastered (route via ACT-7), external-mastered (route via ACT-8), or physical reality not yet modeled (create the register entry via MIR-1 first, including its Owner gate for new external systems)?
- Draft the capability contract, including reversibility class per command type and expected evidence format.
- Run the security check: least privilege, GOV-8 referenced credentials only. Gateway: does the effector act beyond the Steward's scope or on another Owner's reality? If yes, Owner approval required, plus the other Owner's grant (GOV-7 internally, a Federation Contract across Universes).
- Register the effector (Draft, then Active) with an event; a human effector SHALL explicitly accept their contract (a person commanded is a person who agreed to be commandable).
- Schedule periodic health and reachability checks as registered standing jobs (QSC-15).
- Recertify on cadence per the COMMON register-recertification pattern; retire with an event and trigger GOV-8 credential retirement; retired effectors are never dispatched to.
- Controls: no command to an unregistered or retired effector (enforced at ACT-6); least-privilege review; capability contracts versioned; credentials by reference only, lifecycle owned by GOV-8.
- Tier: core.
- Variants: solo: the Owner-Steward and a handful of scripts; the register is a short table and the consolidated quarterly review (COMMON) satisfies recertification. Team: per-section effector pools with Steward ownership. Federated: an effector operated by a peer Universe is registered behind a Federation Contract; commands cross the boundary as contract-governed requests. Manual: humans as the only effectors. Hybrid: mixed human and system effectors. Autonomous: Agent-effectors registered with tight envelopes and T3 health checking.
- Metrics: share of dispatched commands hitting registered effectors (target 100 percent); health check pass rate; recertification currency; privilege exceptions found per audit.
- Failure modes: shadow effectors commanded around the register (guard: dispatch refuses unregistered targets); over-privileged effector (guard: least-privilege review plus Auditor); effector found dead at actuation time (guard: scheduled health checks and dispatch-time check); credentials leaking into the model (guard: reference-only rule, GOV-8 inventory reconciliation and validation scan).
- Purpose: before a decision to actuate, assess the consequences inside the model: the affected set of meta-objects and parties, blast radius, reversibility, cost and value, risk. The model, being the reflection of reality, is the cheapest and safest place to test a change.
- Trigger: a qualified signal whose class requires assessment; any candidate action above the assessment floor of the Impact Matrix; a Steward or decision-maker request.
- Actors: Agents run assessments at T2, and at T3 for routine low-impact classes using standard templates; Steward validates high-impact assessments; Auditor samples predicted-versus-observed accuracy. Steps 1-3 and 5-7 are delegable at the stated tiers; step 4 cross-owner permission checks SHALL remain T1 (Agent proposes, human approves each act).
- Inputs / Outputs: Inputs: the qualified signal, the model's relationship graph (canonical traversal), effector capability contracts (reversibility classes), prior actuation history, the Impact Matrix (GOV-2, required), the minimal value/cost/risk output schema (GOV-2 config). Outputs: an impact assessment record: affected set recorded in the declared affected-set schema (shared with ACT-9 verification records), traversal depth used, reversibility class (reversible, compensable, irreversible), risk notes, projected value delta per the schema, recommended decision tier derived from the Impact Matrix, rollback plan stub.
- Steps:
- Resolve the target meta-objects in the model.
- Traverse relationships to bound the affected set, to the declared depth floor for the impact class.
- Classify reversibility from the effector capability contract and the nature of the change.
- Gateway: does the affected set cross ownership boundaries (another Owner, a federated party)? If yes, the affected Owner's grant (GOV-7 internally, a governing Federation Contract across Universes) SHALL be obtained before the decision may approve actuation.
- Estimate value, cost and risk per the GOV-2 minimal schema; when the model carries a simulation projection, simulate the change there first.
- Derive the recommended decision tier from the Impact Matrix; irreversible SHALL map to T1.
- Record the assessment as an event attached to the signal, citing model versions used.
- Controls: assessment depth floors are Steward-set and not reducible by the requesting Agent; irreversible class forces a T1 decision; cross-owner effects blocked without a grant; assessments cite the exact model versions they were computed against; the affected set uses the shared schema so ACT-9 can record the observed affected set comparably.
- Tier: recommended (mandatory for delegated actuation above the assessment floor; the shipped default floor is medium).
- Variants: solo: a structured checklist the Owner-Steward fills in minutes; under the solo Impact Matrix default, everything reversible and in-scope is below the floor. Team: Agent-computed assessments with Steward validation above the floor. Federated: assessments covering a peer's objects use only the projections that peer has granted. Manual: human walks the graph. Hybrid: Agent computes, human judges. Autonomous: T3 templated assessment for low-impact cataloged classes only.
- Metrics: assessed share of actuations above the floor (target 100 percent); prediction accuracy computed as predicted versus observed affected set, both recorded in the same schema (observed set supplied by the ACT-9 verification record); assessment latency.
- Failure modes: rubber-stamp assessments (guard: Auditor compares predicted against observed outcomes via ACT-12); underestimated blast radius (guard: conservative default depths, accuracy feedback loop); urgency used to skip assessment (guard: the emergency route in ACT-8 demands retroactive assessment within a bounded window).
- Purpose: decide over a qualified signal whether to actuate, what exactly, by which effector, and under whose authority. Converts a fact (signal) into an intention (decision) without yet touching reality.
- Trigger: a qualified signal with its required impact assessment; an owner-directive intent raised by the Owner or Steward; a regularization demand from the emergency route (ACT-8); a rollback proposal (ACT-11).
- Actors: the decision-maker per the Delegation Contract tier map (CTX-9): Owner for scope-exceeding or irreversible actions; Steward within their section; Agent at T2 inside pre-approved decision envelopes (bounded value, reversible, in-scope); Agent at T3 only for signal classes explicitly cataloged as auto-decidable. Anything irreversible or precedent-setting SHALL be decided at T1. Steps 1-3 (verification and preparation) are delegable at T3; the step 4 gateway is the decision itself and follows the tier map; steps 5-7 are delegable at T3 once decided.
- Inputs / Outputs: Inputs: qualified signal, impact assessment, the Delegation Contract tier map (CTX-9), the Impact Matrix (GOV-2), catalog decision route, budget and constraints. Outputs: a signed decision record (approve, reject, defer, escalate) fixing the action, parameters, effector, verification criteria, rollback plan requirement, expiry; recorded as an event with actor identity and authority basis through the registered CON-1 channel.
- Steps:
- Gateway, three lawful branches: (a) a cataloged and qualified signal; (b) the standing owner-directive class: a novel T1 human-initiated action cites it and the decision event states the intent, with no per-idea cataloging; (c) the declared emergency route (ACT-8). Anything else routes to ACT-1 for cataloging; never decide over an uncataloged signal silently.
- Verify authority: match the assessed impact class and reversibility against the tier map. Gateway: does the current decider hold authority? If not, escalate (GOV-1 ladder).
- Review the assessment; optionally request a deeper one.
- Gateway: actuate, reject, or defer.
- On actuate: fix the action, parameters, target effector, verification criteria (what evidence will close the loop and by when), rollback plan reference (mandatory above the rollback-plan floor of the Impact Matrix), and decision expiry.
- Sign and record the decision event: actor identity, authority basis, rationale, all inputs by reference.
- Route to command issue (ACT-6); the Mastership Register selects intent-ahead (ACT-7) or reality-ahead (ACT-8).
- Controls: no decision without identity and authority binding; verification criteria SHALL be fixed at decision time and sealed (never defined after the fact to match whatever happened); decision expiry mandatory; expired decisions SHALL NOT actuate without revalidation; irreversible actions SHALL NOT be auto-decided; a signal class whose evidence rests solely on external-mastered or federated mirrors SHALL NOT be auto-decided at T3 (corroborating independently-mastered evidence or a T2 or stricter decision required); decision events enter the model through the registered CON-1 channel with the auto-approval lane for mechanical appends.
- Tier: core.
- Variants: solo: the Owner-Steward decides everything at T1 via the owner-directive class; under the Solo/Minimal profile (COMMON) one composite actuation event satisfies ACT-5/6/7/9 when decider, dispatcher and executor are the same human. Team: tiered envelopes per Steward section. Federated: decisions touching a peer carry the Federation Contract clause that authorizes them. Manual: human decisions, recorded. Hybrid: Agents prepare and decide within envelopes, humans decide the rest. Autonomous: T3 restricted to the auto-decidable catalog subset.
- Metrics: decision latency by tier; escalation rate; expired-decision rate; share of decisions with verification criteria fixed pre-dispatch (target 100 percent).
- Failure modes: authority creep by Agents (guard: envelope check re-verified at dispatch, ACT-12 tier review routed into CTX-9); post-hoc verification criteria (guard: criteria sealed inside the decision event); a stale decision actuated against changed reality (guard: mandatory expiry plus revalidation); decision fatigue pushing everything to T3 (guard: the auto-decidable set is a versioned catalog property changed only by Steward or Owner).
- Purpose: translate an approved decision into concrete commands to registered effectors, record the command before dispatch, and track acknowledgment. The command is the boundary artifact between model and reality; the dispatch gate is where authority, budgets and limits are enforced mechanically.
- Trigger: an approved, unexpired decision routed for execution; a retry or corrective re-dispatch from ACT-10; a rollback command from ACT-11.
- Actors: Agents execute dispatch mechanics to system effectors (steps 1-3, 5-6, 8) at T3 within capability contract limits; commanding human effectors or adapting parameters (steps 4, 7) at T2; Steward handles refusals and exceptions. Accountability stays with the Steward.
- Inputs / Outputs: Inputs: decision record, effector register and capability contract (ACT-3), Delegation Contract liveness (CTX-9, checked at the gate), cumulative impact budget configs and emergency-class rate and blast-radius limits (GOV-2), the Impact Matrix (GOV-2), credential references (GOV-8). Outputs: command record (command id, decision reference, effector, parameters, idempotency key, expected-evidence declaration, issue time, expiry), acknowledgment record, append-only dispatch log.
- Steps:
- Gateway: is the decision still live (unexpired, unrevoked)? If not, stop and report.
- Gateway (gate-enforced, never agent-honored): the effector is registered and healthy; the command is within its capability contract; the citing Delegation Contract's liveness is validated at act time at the gate; per-agent and per-signal-class cumulative impact budgets (count, value, affected-set size per period) are checked mechanically, and a breach forces escalation to T1; for emergency-class commands, the per-class hard rate and blast-radius limits are enforced here. Any failure returns to ACT-5.
- Compose the command mechanically from the decision record (no manual re-entry), with an idempotency key and the expected-evidence declaration.
- Record the command in the model BEFORE dispatch, through the registered CON-1 channel. Intentions are always model-mastered: this holds even when the target dataset is external-mastered.
- Dispatch to the effector over its authenticated channel.
- Await acknowledgment within the contract deadline. Gateway: acknowledged, refused, or timed out?
- On refusal or timeout: retry per contract (same idempotency key) or route to ACT-10; a human effector's refusal is a first-class recorded response, never overwritten.
- Hand the open command to verification (ACT-9).
- Controls: a command SHALL reference a live decision; idempotency keys prevent double actuation; commands to humans are explicit requests requiring acceptance; the dispatch log is emitted by the mediating gate and channel infrastructure, never by the acting Agent, is append-only, and is continuously hash-chained with external anchoring at the declared COMMON cadence; a hash check ties command parameters to the decision record (waived, with the idempotency key, for the solo T1 composite actuation event per COMMON); budget counters and limit checks are mechanical gate configs (GOV-2), not agent judgment.
- Tier: core.
- Variants: solo: the "command" may be the Owner-Steward's own to-do, still recorded before doing; the composite actuation event (COMMON) lawfully covers it. Team: Agent dispatchers per effector pool. Federated: cross-boundary commands travel as Federation Contract governed requests to the peer's gate; the peer's acceptance is the acknowledgment. Manual: human issues and logs. Hybrid: Agent dispatches systems, humans brief humans. Autonomous: T3 for system effectors within contract, budgets and limits.
- Metrics: dispatch success rate; acknowledgment latency; duplicate-actuation incidents (target 0); refusal rate per effector; budget-breach escalations per period.
- Failure modes: double actuation on retry (guard: idempotency key honored by the effector contract); command drift from the decision (guard: mechanical composition plus hash check); dispatch to a dead effector (guard: dispatch-time health check); assumed or forged acknowledgment (guard: acks accepted only over the effector's authenticated channel); a suspended Agent continuing to dispatch (guard: gate-side contract liveness validation at act time); a large effect decomposed into many small below-floor commands (guard: cumulative impact budgets checked at the gate, breach forces T1).
- Purpose: execute change for model-mastered targets: record the intended new state in the model first as a distinct pending version, then drive reality to conform, then promote the intention to current state on verified evidence. The model leads, reality follows.
- Trigger: a command whose target dataset has master model (Pattern M) in the Mastership Register; a planned-change object coming due; retroactive regularization of a Pattern M emergency actuation handed over by ACT-8 step 7.
- Actors: Steward accountable. Agents: MAY execute the full sequence at T2 for routine classes and at T3 for fully cataloged low-impact classes; authoring the intended state SHALL remain T1 where human judgment shapes content (Agent proposes, human approves each act). Promotion (step 6) is mechanical on evidence and delegable at T3.
- Inputs / Outputs: Inputs: decision and command, Mastership Register, target meta-objects, the Impact Matrix (GOV-2). Outputs: an intended-state record (new version in Draft or Proposed, current version still Active), an actuation-intent event, a conformed write-back projection or effector-driven reality change, a promotion event on verification.
- Steps:
- Gateway: confirm master model for the target dataset. If not, this is the wrong pattern: route to ACT-8.
- Author the intended state as a new version (Version Lifecycle Draft or Proposed) while the current version stays Active. Intent bitemporality: the intention carries its record time now and its effect time later; it SHALL NOT be presented as current state.
- Record the actuation-intent event linking decision, command and intended version. All writes in this sequence execute through the CON chain: mechanical event appends via the registered CON-1 channel and auto-approval lane, authored content through CON-3/CON-4.
- Actuate: publish the write-back projection (marked generated, master named, do-not-edit notice) or command the effector to bring reality to the intended state.
- Await verification evidence (ACT-9).
- Gateway: did reality conform? On yes: promote the intended version to Active with an event; refresh projection metadata. On no or partial: keep the intention in Proposed and route to ACT-10.
- Close with cause-linked events: intent event to effect evidence. For the emergency-regularization trigger, the intent and command are recorded post hoc within the bounded backfill window and promotion still happens only on ACT-9 evidence.
- Controls: intention and current state SHALL be distinct records; promotion only on verification evidence, never on dispatch success; mastership check mandatory; write-back projections carry the generated marking per Data-Mastership Pattern M; drift on the published projection is detected solely by MIR-7, which routes actuation-linked divergence to ACT-10.
- Tier: core.
- Variants: solo: the Owner-Steward drafts the new version, applies it to reality, ticks verification; the composite actuation event (COMMON) lawfully covers the T1 same-human case; the discipline is the ordering, not the ceremony. Team: Agents run publication pipelines, Stewards approve promotions above the floor. Federated: a peer consuming the projection is notified of promotion via synchronization events. Manual: hand publication with a checklist. Hybrid: Agent publishes, human verifies. Autonomous: T3 end to end for cataloged low-impact classes (reference implementation: Orkestron's site projection with MIR-7 hash drift check).
- Metrics: intent-to-conformance latency; premature-promotion incidents (target 0); share of changes with intent recorded before dispatch (target 100 percent).
- Failure modes: the model lies (intention promoted before reality conformed; guard: promotion gate on evidence only); orphan intents lingering after failed dispatch (guard: intent expiry tied to decision expiry, periodic sweep); two truths via external edits to the projection (guard: MIR-7 Pattern M drift check; external edits become change proposals via CON-11, never silent merges).
- Purpose: execute and register change for external-mastered targets and bounded emergencies: reality changes first (by our command to an external System of Record, or by an effector acting in the physical world), and the model catches up by harvest, linking the sensed effect back to the command. Defines when reality-ahead is correct, how the model follows without corruption, and how the hardened emergency route is invoked and regularized under both mastership patterns.
- Trigger: a command whose target dataset has master external (Pattern E); an emergency actuation under a declared emergency class (safety deadline shorter than the model's normal write path), for either mastership pattern.
- Actors: Agents: execute the command to the external system and force re-harvest (steps 2-6) at T3 within contract; operate the emergency envelope (step 1 emergency branch, step 7) at T2; Steward accountable and synchronously notified on every emergency invocation; human effectors act in reality and report over authenticated channels; Owner and Auditor receive non-regularized emergency escalations.
- Inputs / Outputs: Inputs: decision and command (or emergency authorization of a declared class, GOV-2 definitions), Mastership Register, harvest pipelines (MIR-2), the Impact Matrix (GOV-2). Outputs: command record (the intention is still model-first), the external change, raw capture plus refreshed mirror with provenance, cause-reference events linking mirror state to the command stamped with the actuation-verification reason code (MIR-10), pinned and hashed triggering evidence for emergency invocations, retroactive assessment and regularized decision for the emergency branch.
- Steps:
- Gateway: confirm master external for the target (proceed with steps 2-6), OR confirm the emergency conditions of a declared emergency class are met. The emergency branch splits by mastership: a Pattern E target follows steps 2-6 with regularization per step 7; a Pattern M target has no mirror, steps 4-6 do not apply, and the change regularizes via retroactive ACT-7 (record intent and command post hoc within the bounded backfill window, verify by ACT-9 evidence, author the new state through the normal model-mastered write path and promote on evidence). Any non-emergency Pattern M case routes to ACT-7.
- Record the command and intent event (intentions are always model-mastered even when the target state is not). For emergency invocations additionally: pin and hash the triggering evidence at invocation so regularization cannot be fitted to the outcome; notify the Steward synchronously at invocation, not at backfill; a second invocation of the same class within the declared window SHALL escalate to T1 before dispatch. Per-class hard rate and blast-radius limits are enforced at ACT-6 dispatch, not by agent judgment.
- Actuate in the external system or in physical reality via the registered effector.
- Force an out-of-cycle re-harvest of the affected dataset (a registered MIR-2 trigger) rather than waiting for the normal cadence (SHOULD; the normal cadence is the fallback).
- Land evidence per the harvest discipline: unmodified raw capture with provenance sidecar, then the semantic transform into the mirror. Never hand-edit the mirror to show the expected result; expected-but-unharvested state MAY be shown only as a pending intention.
- Link the mirrored new state to the command by a cause-reference event, matching on the idempotency key so our change is not conflated with someone else's concurrent change; stamp the ingest and cause-reference events with the actuation-verification reason code (MIR-10).
- Gateway (emergency branch only): retroactive assessment (ACT-4) and decision regularization (ACT-5, or retroactive ACT-7 for Pattern M targets) SHALL complete within the bounded backfill window; non-regularized emergency actuations escalate to the Owner and the Auditor and open a QSC-14 incident.
- Controls: mirror writes only via the harvest pipeline; the emergency route is bounded to declared classes (GOV-2) with mandatory backfill (the discipline the MOS reference Dimension formalizes as degraded mode with provisional promises and mandatory backfill; external reference: orkestron-ai/meta-orchestrator-state); synchronous invocation notification, evidence pinning, rate and blast-radius limits and the repeat-invocation T1 escalation are non-waivable emergency controls; provenance mandatory on every capture; cause references only on evidence matched to the command.
- Tier: core.
- Variants: solo: the Owner-Steward changes the external system, then re-harvests before relying on the mirror. Team: Agents drive external APIs and harvest pipelines. Federated: changing a peer's reality happens only through the peer's own gate under a Federation Contract; our model holds a mirror of the outcome. Manual: change by hand, harvest by hand. Hybrid: human changes reality, Agent harvests and links. Autonomous: T3 for cataloged external-system commands with API-verifiable outcomes.
- Metrics: command-to-mirror-confirmation latency; share of actuations with forced re-harvest; emergency-route usage rate and regularization rate (a rising usage trend is a defect signal); repeat-invocation escalations per class.
- Failure modes: mirror faked to match intent (guard: pipeline-only mirror writes, validation flags hand edits as non-conforming); harvest lag masking a failed actuation (guard: forced re-harvest plus the ACT-9 verification deadline); the emergency route becoming the normal route (guard: usage metric reviewed in ACT-12, classes revoked by the Owner via GOV-1); attributing someone else's external change to our command (guard: idempotency-key matching in step 6); emergency change to a Pattern M target registered by harvest, an unlawful external-to-model flow (guard: the mastership branch in step 1 routes Pattern M regularization through retroactive ACT-7); regularization fitted to the outcome (guard: evidence pinned and hashed at invocation).
- Purpose: confirm by sensed evidence that reality actually changed as decided, and record the verification. The loop is closed by evidence, never by dispatch success or effector self-report alone.
- Trigger: a dispatched command reaching its expected-effect time; harvest completion for the target dataset; an effector completion report; a below-floor re-verification sample drawn per the declared sample-rate floor.
- Actors: Agents collect evidence and perform the mechanical comparison (steps 1, 3, 5) at T3; judge partial conformance (step 4 borderline cases) at T2; Steward rules on disputed verifications; Auditor samples. Separation of duties: for impact classes above the separation-of-duties floor of the Impact Matrix, the verifying Agent SHALL NOT be the Agent that decided or dispatched, and the verifying harvest SHALL run under a pipeline identity disjoint from the pipeline that fed the original signal (separation of duties extends from Agents to pipeline credentials).
- Inputs / Outputs: Inputs: the verification criteria sealed in the decision, the command record, sensed evidence (harvest results with provenance from MIR-2, effector reports, telemetry, human attestation), the Impact Matrix (GOV-2), the below-floor sample-rate floor (GOV-2 config). Outputs: a verification record (conformed, partially conformed, failed, unverifiable) with effect events cause-linked to the command and the observed affected set recorded in the ACT-4 assessment schema; freshness updates; the unverified queue.
- Steps:
- Gather evidence per the criteria fixed at decision time.
- Gateway: does the impact class require evidence independent of the effector's self-report (default floor: high)? If yes and only self-report exists, the verification is incomplete: request independent sensing via MIR-2 as a targeted harvest, under a pipeline identity disjoint from the one that fed the original signal, before judging.
- Compare intended state against sensed state mechanically where possible.
- Gateway: conformed, partially conformed, failed, or unverifiable?
- Record the verification event linking command to evidence with a cause reference, stamped with the actuation-verification reason code (MIR-10); the record SHALL list the observed affected set in the same schema as the ACT-4 assessment.
- On conformed: trigger promotion (ACT-7 step 6) or close the reality-ahead record (ACT-8).
- On partial or failed: route to reconciliation (ACT-10).
- On unverifiable past the deadline: escalate to the Steward; the actuation is treated as unconfirmed, never silently as done.
- Controls: verification criteria immutable after decision; independent-evidence rule per the Impact Matrix floor; verification deadline mandatory; unverified SHALL NOT become verified by the passage of time; separation of duties between deciding, dispatching and verifying (Agents and pipeline identities) above the floor; random independent re-verification sampling of below-floor actuations at a declared sample-rate floor, reported through QSC-7 and ACT-12; the solo T1 composite actuation event (COMMON) satisfies the verification note for the same-human case.
- Tier: core.
- Variants: solo: the Owner-Steward looks at reality and records what they saw; independence means looking at the thing, not at the script's exit code. Team: a verification Agent pool separate from dispatch, on separate pipeline credentials. Federated: the peer's signed confirmation or a fresh mirror of the peer's state is the evidence. Manual: human inspection with recorded attestation. Hybrid: Agent compares, human spot-checks. Autonomous: T3 where evidence is machine-comparable.
- Metrics: verification coverage (share of commands verified, target 100 percent); mean verification latency; independent-evidence share for high-impact classes; unverifiable rate and queue age; below-floor sample coverage against the declared floor.
- Failure modes: self-certification (the same Agent or pipeline identity decides, dispatches and verifies; guard: separation-of-duties rule over Agents and pipeline credentials); quiet abandonment of hard verifications (guard: unverified queue surfaced to the Steward with aging metrics); effector-forged evidence (guard: independent sensing for high impact, authenticated channels, disjoint pipeline identity); criteria bent to fit the outcome (guard: criteria sealed at decision time, Auditor diff); salami-sliced below-floor actuation escaping scrutiny (guard: random re-verification sampling plus ACT-6 cumulative budgets).
- Purpose: when reality refused the command, complied partially, or diverged after conformance, restore agreement between model and reality in the direction the Mastership Register dictates, and record what actually happened without rewriting history.
- Trigger: a failed or partial verification (ACT-9); an effector refusal (ACT-6); actuation-linked drift handed over by MIR-7 (a drift Event cause-linked to an open command) or by ACT-9; a counterparty or Consumer report of divergence on an open actuation. Non-actuation drift is MIR-7 and CON-11 territory and is not processed here.
- Actors: Steward decides direction in non-mechanical cases; Owner rules on mastership disputes (GOV-1); Auditor reviews repeat offenders. Agents: characterize divergence and execute standard reconciliations (steps 1, 3-4, 6) at T2, and fully mechanical drift repair within declared classes at T3; the step 5 escalation gateway SHALL remain T1 (Agent proposes, human approves each act).
- Inputs / Outputs: Inputs: verification record, conflict rules from the Mastership Register, divergence evidence, the consumer and subscription register (CON-13), the Impact Matrix (GOV-2). Outputs: reconciliation record; either a corrected model state (model follows reality, via harvest) or a corrective re-actuation plan (reality brought to the model) or a revised decision; supersession events stamped with mapped MIR-10 reason codes; Consumer notifications; escalations.
- Steps:
- Characterize the divergence: refusal (reality said no), partial effect, external counter-change, or silent drift on an open actuation.
- Gateway: which side is authoritative for the diverged dataset? Read the conflict rule in the Mastership Register; per Data-Mastership, resolving by per-incident judgment is non-conforming.
- If the external side wins: update the model by re-harvest and supersede the failed intention with a supersession event (correction or retraction); the refused intent stays on the timeline as history.
- If the model wins: plan corrective actuation; if within the original decision's scope and expiry, re-dispatch via ACT-6, else loop back to ACT-5 for a new decision.
- Gateway: does the divergence reveal a wrong mastership declaration, a wrong signal definition, or a wrong effector contract? Escalate accordingly: a mastership-change proposal to MIR-1 (the sole register-change executor, including its Owner gate), signal catalog changes to ACT-1, effector contract changes to ACT-3; all as versioned events.
- Record the reconciliation with cause references and mapped MIR-10 reason codes; notify Consumers who may have read the now-superseded state, resolved against the CON-13 consumer and subscription register.
- Gateway: repeated divergence on the same dataset or effector past the declared threshold? Open an Auditor review instead of another retry.
- Controls: reconciliation direction only per declared conflict rule; supersession-only correction (no deletions, no edits of history); supersession events carry mapped MIR-10 reason codes; mandatory Consumer notification against CON-13; recurrence counter forcing escalation over blind retry.
- Tier: core.
- Variants: solo: the Owner-Steward applies their own declared rule (writing the rule down beforehand is what makes this a process). Team: reconciliation queue worked by Agents with Steward exceptions. Federated: divergence with a peer resolves through the Federation Contract's conflict clause, executed via FED-9; federation never transfers mastership. Manual: human-led. Hybrid: Agent detects and proposes, human directs. Autonomous: T3 only for declared mechanical drift classes.
- Metrics: mean time to reconcile; recurrence rate per dataset and per effector; share resolved mechanically versus escalated; Consumer notification latency against CON-13 SLAs.
- Failure modes: judgment-call reconciliation (guard: conflict rule is law; deviation is non-conforming and Auditor-flagged); tug-of-war loops where the model re-actuates and reality re-refuses (guard: recurrence threshold forces escalation); silent history rewrite to hide the failure (guard: supersession-only rule, append-only timeline); reconciling the copy instead of the master (guard: mastership check in step 2); double-processing drift already routed to CON-11 (guard: trigger scope limited to actuation-linked divergence).
- Purpose: undo an actuation whose verification failed or whose consequences prove harmful; where undo is impossible, execute compensation (a new forward action restoring an acceptable state) and record the residual impact honestly.
- Trigger: a failed verification with a rollback decision; a harm signal emitted after actuation; an Owner or Steward order; an invoked rollback plan.
- Actors: the rollback decision follows ACT-5 authority (rolling back an irreversible-class actuation is itself a decision, usually T1). Agents: execute cataloged rollback plans (steps 2-4) at T2; T3 only for pre-approved automatic rollback classes (for example a deployment gate that reverts on a failed check); Steward accountable; Auditor reviews irreversible residue.
- Inputs / Outputs: Inputs: the rollback plan drafted at decision time, actuation and verification records, current sensed state, the Impact Matrix (GOV-2; rollback-plan floor default medium). Outputs: rollback or compensation commands, restored or compensated state, a residual-impact record, a closure event with mapped MIR-10 reason codes, lessons routed to ACT-4, ACT-1 and QSC-14.
- Steps:
- Gateway: reversibility class from the original assessment: reversible leads to rollback; compensable leads to a compensation plan; irreversible leads to mitigation plus residual-impact recording.
- Validate the rollback plan against current reality; reality may have moved since the plan was drafted. Gateway: is the plan still valid? If not, a stale rollback is a new actuation: route to ACT-5.
- Issue rollback or compensation commands through ACT-6; the full loop applies, because rollbacks are actuations too (assessment where the class demands it, command records, idempotency keys, budgets).
- Verify restoration through ACT-9.
- Record residual impact honestly: what could not be restored, valued and attributed; never zeroed for optics; supersession and residual-impact events carry mapped MIR-10 reason codes.
- Feed lessons back: assessment accuracy to ACT-4, signal and catalog revisions to ACT-1, effector contract revisions to ACT-3; harm above the severity floor opens a QSC-14 incident with a blameless postmortem.
- Controls: rollback plans SHALL be drafted at decision time for impact classes above the rollback-plan floor of the Impact Matrix, not improvised after failure; rollbacks travel the same command and verification machinery, no side door; residual impact SHALL be recorded; "irreversible" SHALL NOT excuse the absence of a mitigation plan.
- Tier: recommended (the requirement that decisions above the rollback-plan floor carry a rollback plan is a core control inside ACT-5; the standalone process is recommended because a minimal model may lawfully treat every rollback as a fresh ACT-5 decision).
- Variants: solo: the Owner-Steward keeps a one-line undo note per risky change. Team: rollback runbooks executed by Agents with Steward approval. Federated: compensation toward a peer is governed by the Federation Contract's remedy clause. Manual: hand-executed undo. Hybrid: Agent reverts systems, humans handle people-facing compensation. Autonomous: T3 automatic reverts only for pre-approved classes with machine-verifiable restoration.
- Metrics: rollback success rate; time to restore; residual-impact incidents and their valuation; share of above-floor actuations carrying a pre-drafted rollback plan (target 100 percent).
- Failure modes: rollback assuming a frozen world (guard: step 2 revalidation against current reality); compensation spiral where the fix causes new harm (guard: compensation is a full-loop actuation with its own assessment); irreversibility claimed to avoid planning (guard: irreversible class demands a mitigation plan and Auditor review); rollback via a side door skipping records (guard: same-machinery rule).
- Purpose: periodically audit the full loop end to end (reality to model to signal to decision to command to reality to sensing to reconciliation): trace completeness, latency, evidence quality, budget consumption and delegation-tier calibration, so the model remains a functioning actuator rather than a diary.
- Trigger: schedule per model cadence; a loop-metric threshold breach; post-incident review of a QSC-14 incident record; an Owner request.
- Actors: Auditor leads (engaged via GOV-6) and SHALL be independent of the executing Agents and Stewards. Agents: compile loop traces and metrics (steps 1-2, 4-5) at T3; draft findings (step 6) at T2. Steward and Owner receive the report and decide changes (GOV-1); tier recalibration is an Owner or Steward decision executed through CTX-9, never self-granted by Agents.
- Inputs / Outputs: Inputs: end-to-end actuation traces (signal to decision to command to verification to reconciliation chains), loop metrics from all ACT processes, budget consumption records (ACT-6), below-floor re-verification samples (ACT-9), incident records (QSC-14), Delegation Contracts (CTX-9), the Impact Matrix (GOV-2). Outputs: a loop health report, tier recalibration proposals routed into CTX-9 step 8 as named inputs, catalog, effector and assessment revision proposals (ACT-1, ACT-3, ACT-4), orphan-link findings and loop debt filed into QSC-11 intake, a closed-loop attestation to the Owner (GOV-1).
- Steps:
- Sample end-to-end traces; every chain SHALL be walkable: every command to a decision, every decision to a signal or the owner-directive class, every verification to evidence. Gateway: any orphan links? Orphans are findings, filed into QSC-11, not noise.
- Measure loop latency per stage and end to end; compare against the model's declared actuation service levels.
- Review Agent performance per tier: error and escalation rates against granted autonomy. Gateway: propose promotion toward higher autonomy, or demotion, per class; route proposals into CTX-9 step 8 as named inputs.
- Review emergency-route usage trends, repeat-invocation escalations, cumulative budget consumption and uncataloged-actuation attempts; propose class revocations or budget changes to the Owner (GOV-1, GOV-2).
- Compare predicted impact (ACT-4) against observed affected sets (ACT-9, same schema) to calibrate assessment quality; review below-floor re-verification sample results.
- Draft and publish the report; raise change proposals into ACT-1, ACT-3, CTX-9 and GOV-2 as versioned events; file findings into QSC-11.
- Attest loop health to the Owner (recorded via GOV-1).
- Controls: traces are read-only for the Auditor; Auditor independence (GOV-6 attestation); recalibration by Owner or Steward decision only, executed in CTX-9; sampling depth floors so the review cannot shrink into ritual; the Auditor recomputes headline metrics from raw traces rather than trusting reported dashboards; trace logs are infrastructure-emitted and hash-chained per COMMON, so the Auditor's evidence base cannot be rewritten by the audited Agents.
- Tier: core wherever any ACT process runs at T3 or any emergency class is declared; recommended otherwise.
- Variants: solo: a quarterly hour where the Owner-Steward walks five random chains end to end (may join the consolidated quarterly review of the COMMON Solo profile). Team: standing Auditor role with Agent-compiled evidence. Federated: peers exchange loop attestations under contract instead of raw traces. Manual: sampled by hand. Hybrid: Agent compiles, Auditor judges. Autonomous: continuous T3 trace-completeness checking with human-led periodic judgment.
- Metrics: orphan-link rate (target 0); end-to-end loop latency trend; correlation of Agent error rate with granted tier; emergency-route share trend; below-floor sample coverage.
- Failure modes: audit becomes ritual (guard: sampling floors and incident-triggered reviews); Agents grading themselves into autonomy (guard: independence rule, recalibration reserved to humans via CTX-9); gamed metrics (guard: Auditor recomputation from raw hash-chained traces); findings filed and forgotten (guard: proposals enter versioned change processes and QSC-11 debt intake with owners and due events).