1. A Complaint With Nowhere to Go
Consider a freight booking. A procurement agent buys capacity from a carrier agent it has never transacted with. Days later the buyer asserts that the carrier quoted capacity it did not hold, took the booking anyway, and reassigned the slot. Both parties are software, neither belongs to the other's organization, and the venue where they met runs a directory, a message relay, and a billing rail with no view of either agent's execution history.
Someone has to answer, and in a venue built that way nobody is positioned to. The carrier executed against its own principal's systems, so the operator holds no record of it and the buyer holds one half of the exchange. The accusation arrives as prose in a ticket, the answer as more prose, and a person picks a narrative.
Two structural facts make that worse than it looks. Silence becomes the winning defense: a seller that records little has little that can contradict it, so record poverty pays and the best-instrumented sellers are easiest to pin. And only the accused can change the behavior, since an operator's lever is delisting, which neither stops the seller dispatching the same action class against the next counterparty nor follows it through re-registration. Human-seller marketplaces absorbed both, on volume low enough for human adjudication and identity costly enough that delisting stung. Neither condition survives autonomous counterparties transacting across organizational boundaries.
2. Why Existing Approaches Stall
Operator adjudication does not survive cross-venue agents. Judging takes authority over both parties and visibility into their conduct. Federated agent commerce, as publicly described, is being built to avoid that concentration, and an operator holding both still sees message traffic rather than execution, so it rules on plausibility while inheriting liability for behavior it never instrumented.
Reputation aggregates are the wrong shape. A scalar collapses what a counterparty needs: what was asserted, whether the accused's record bears on it, and what followed. One serious charge dilutes to a rounding error, and the score travels unchanged from a lax context into a strict one.
Model-judged arbitration reintroduces the dispute. Hand complaint text to a language model and interpreting natural language becomes the deciding step, on output that is graded, non-deterministic, and sensitive to the accuser's phrasing, precisely the surface an adversarial counterparty works on.
Signed receipts stop one step short. Verifiable evidence that an entry exists says nothing about whether the recorded conduct departed from anything the party was bound to, and reading it still takes someone with standing.
None makes the accused answer over its own record against its own declared obligations, or binds that answer to its future behavior without an external enforcement step.
3. What the Filing Discloses
The filed chapter names the input a conduct evaluation artifact: a signed artifact arriving at runtime over the semantic agent's ordinary interaction channel, from an asserting party other than the principal, evaluating conduct the agent itself performed rather than an output, a task result, or a third party. It carries an asserting-party identifier, a recorded assertion time, a conduct descriptor, a signature verifiable against an identity primitive in a counterparty identity record, and an attested state of that party's assertion-cost counter with an epoch identifier of its dynamic agent hash chain. No dedicated evaluation channel, out-of-band interface, or centralized intake service is required.
The conduct descriptor is the pivot: an action-class identifier, a scope-partition identifier, and an affected-party class. Conduct is identified by reference to structural elements recorded in the append-only lineage field, not by natural-language characterization. No language model or sentiment classifier runs over artifact content, and the asserting party's state, intent, and affect are never inferred.
Admissibility is ordered: signature first, then the attested counter state, including that the attested epoch identifier is a valid successor of the recorded epoch, recomputed forward and tested for equality rather than distance. An artifact failing either step is appended unadmitted, produces no determination, moves no value, and increments no counter.
An admitted artifact reaches the admission evaluator, which returns exactly one determination from a closed set of accepted, rejected, not-determinable, and not-applicable, produced by the agent over its own lineage field against the signed policy object in force at the recorded assertion time, and not by an external authority, arbitrator, registry, or scoring service. A value-scope test runs first, implicating a declared value only where the action-class identifier, the scope-partition identifier, and the empathy-scope designation of its value-scope tuple all hold. The evaluator then retrieves lineage entries bearing on the named conduct, the affected-party class excluded from that retrieval. Rejected issues only where a retrieved entry affirmatively contradicts the artifact on a recorded field; absence of evidence resolves to not-determinable and to no other class.
Consequence is structural. On an accepted determination a state modifier moves the scoped integrity vector and the self-esteem aggregate, each scaled by the entropy-weighted harm coefficient; a deviation engine recomputes the deviation likelihood; and where that quantity satisfies the policy-declared bound the gate transitions to the withheld state for that action class and the agent enters a non-executing cognitive mode. Because the dispatch-authority predicate is recomputed on each request under a three-stamp conjunction of policy, lineage, and authorization stamps, required in full and never taken from a cached result or session grant, that gate write takes effect at the next dispatch without revocation infrastructure. An escalation record goes to the principal, and restoration comes only upon a procedure appended to the lineage field: no elapse of time, and no counterparty payment, returns it.
4. Running the Freight Dispute Through It
Return to the booking. The buyer opens no ticket. It composes a conduct evaluation artifact naming the action-class identifier for the fulfillment action and the scope-partition identifier for the commercial context, signs it, attaches its attested counter state and epoch identifier, and sends it back over the ordering channel.
The carrier holds no counterparty identity record for this buyer, which neither admits nor rejects the artifact. The carrier constitutes a provisional identity primitive from the presented material and the attested epoch identifier and verifies the signature against it. Failing, the artifact is appended unadmitted with no record instantiated. Succeeding, an ephemeral-tier record is instantiated at the most restrictive scope with an empty encounter history, and the artifact waits in the pre-settlement inert state rather than passing to the evaluator, until that record is promoted upon a matched-pair settlement. A stranger's complaint is preserved rather than discarded, without the seller extending trust it has no basis for.
At the evaluator, the value-scope test runs against the policy object in force at the recorded assertion time, closing two escapes at once. A narrower successor admitted after the complaint lands is not retained, and the anti-rollback floor discards candidates below a monotonically non-decreasing successor index. Nor does the buyer supply the affected-party class, resolved instead from the counterparty identity records the seller holds, so the accuser picks neither its own empathy scope nor the entries retrieved against it.
Four outcomes are available, each appended with its ground.
- Not-applicable. No declared value is implicated, and the entry names the tuples tested and the failing element of each, so a counterparty reading it learns the perimeter of the seller's declared governance.
- Rejected. A retrieved entry affirmatively contradicts the artifact, and both that entry and the field it contradicts on are named, so the defense is inspectable rather than taken on faith. Nor is it free: a rejected determination increments the refusal counter, which writes the gate upon satisfaction of a threshold.
- Not-determinable. The lineage field holds no bearing entry, one that does not resolve the descriptor, or one incomplete as to it, and the ground states which. Silence buys nothing, since repetition against one asserted conduct event increments that same counter.
- Accepted. A declared value was implicated and nothing retrieved contradicted it. Integrity and self-esteem values move, and where the recomputed deviation quantity satisfies the policy-declared bound the gate goes to the withheld state for that class, so from the next dispatch the seller's own predicate fails on the authorization stamp. Nobody was delisted; no operator was asked.
Consequence survives re-registration. The refusal counter, the gate state per action class, the renewal register, and the recurrence count are governance attributes bound to descendants, inherited across fork, clone, and reconstitution as a floor under a monotonically non-decreasing discipline, carried in an inherited governance record signed by the parent. A descendant presenting a lower floor than its chain implies is inadmissible, its proposed actions denied as an unresolved lineage discontinuity. A fresh storefront sheds no withheld gate.
Withdrawal does not unwind effect. A signed retraction record is admitted under the ordinary procedure but decrements no accumulator, returns no gate to the granting state, and reverses no prior modification. Stale complaints are bounded separately, by a policy-declared interval following the conduct.
Two counterparties can also set bilateral terms with no platform involved, each appending one co-signed mutual admission compact record of reciprocal value-scope tuples and a validity window, under a union rule that leaves it incapable of subtracting from the declared value set a party is held to. Consequences stay inside their scope partition too, each carrying its own integrity vector, refusal counter, and budget, so a carrier gated on refrigerated freight keeps authorization on dry van.
5. Deployment Considerations
Instrumentation burden lands first. An entry bears on the conduct only where it records an action of the named action class within the named scope partition, so an agent whose logging omits those identifiers resolves nearly every artifact to not-determinable, repetition drives the refusal counter, and the gate is written once the threshold is satisfied. A poorly instrumented seller gates itself, by design, so action-class taxonomy cannot be deferred to a later phase.
Authoring burden lands on the principal rather than on engineering. Declared values, value-scope tuples, scope partitions, and the bounds, weights, and coefficients consumed by the computations live in a signed policy object the agent does not author and can change only by admitting a successor. Reference action-class vocabularies per vertical will likely be needed, since two agents naming one conduct differently implicate no shared value.
Restoration needs an operational plan, since a withheld gate returns only upon a procedure appended to the lineage field. No marketplace can offer a reinstatement service level; the seller's principal staffs that path. A deterministic denial is likewise a valid recorded outcome and not an error, appended naming the stamp that did not resolve, so a spike in denials reads as governance signal rather than an outage.
What the architecture does not do matters as much. It does not decide what happened: an accepted determination means a declared value was implicated and nothing retrieved contradicts the assertion, which is an admission over a record, not a neutral finding of fact. Accuser honesty is not evaluated, and lineage contents are not authenticated against the physical world, so a principal writing false entries produces determinations grounded in false entries. No portable score is produced, deliberately. This chapter stops at determination and gating; repair, origin metering, and settlement sit in other sections of the same disclosure.
6. Disclosure Scope
The subject matter above is disclosed in U.S. Provisional Application No. 64/117,812, Chapter 1, principally at Sections 1.6 through 1.9, resting on Sections 1.2 through 1.5, with refinements at Sections 10.1, 10.2, 10.4, 10.9, 10.10, and 10.11.
Disclosed: receipt of a signed conduct evaluation artifact over a persistent semantic agent's ordinary interaction channel, with no dedicated channel or centralized intake; ordered admissibility by signature and successor-continuity verification of an attested assertion-cost counter state and hash chain epoch identifier; the ephemeral-tier record, provisional identity primitive, and pre-settlement inert state for a party not previously recorded; the value-scope test; retrieval of bearing lineage entries insulated from the affected-party class; the closed set of accepted, rejected, not-determinable, and not-applicable determinations with recorded grounds; absence of evidence resolving to not-determinable and to no other class; the refusal counter and its writing of the gate upon a threshold; the withheld state and non-executing cognitive mode; per-request recomputation of the dispatch-authority predicate under the three-stamp conjunction; the escalation record and restoration only upon a recorded procedure, not by elapsed time or payment; the retroactive narrowing bar and anti-rollback floor; scope-partitioned confinement of state movement; the governance-inheritance floor and inherited governance record across fork, clone, and reconstitution; the irreversible retraction record; the assertion-age admissibility interval; and the co-signed mutual admission compact with its union rule and bounded depth. Application of the foregoing to multi-party agent marketplaces, where one party asserts misconduct against another and no operator adjudicates, is placed on the public record as of the date above.
Disclaimed: any characterization of an accepted determination as an adjudication of fact by a neutral party; any external arbitrator, registry, or scoring service producing determinations; any scalar confidence or graded weight substituted for a determination class; any classification of artifact content by a language model or sentiment classifier; and marketplace operation, order matching, escrow, or settlement mechanics as such. The application named above is pending. Nothing here asserts that any party infringes any claim, and nothing states that any license is required or available.