Where an Adopted Judgment Is Allowed to Land
A dispatch that proceeds on another party's recorded judgment is one the executing agent did not itself resolve on the merits. The engineering question is where inside its own authorization machinery that adopted judgment may take effect.
The same disclosure's deference construction declines to be standing at all. Once the followed agent supersedes or retracts the determination adopted, or a declared bounded count of dispatches under a deference record (900) is exhausted, that record satisfies no further dispatch-authority predicate, and a further dispatch requires a fresh deference record (900), a fresh counter-signature, and a fresh decrement of the followed agent's authorization budget (404). Section 10.7 of the filing discloses a different arrangement: a designation that stands, written by the relying agent into its own record, its operative effect confined to one term of the test that gates that agent's dispatch.
The Designation and the Substituted Conjunct
The condition precedes the designation. A persistent semantic agent (100) computes an invariance count over a counterparty, a quantity consuming no rating, no score, and no measure of agreement with the agent. It forms a policy succession sequence, being the ordered set of signed policy objects (112) admitted under one canonical alias. From the counterparty it retrieves previously recorded determinations of the closed determination set for an action class, each with its conduct descriptor, its conduct evaluation artifact (116) identifier, and its tested-entry enumeration, verifying each under the retrievability-form verification. Against every object of the succession in version order it re-resolves each conduct descriptor, appending the re-resolution to the append-only lineage field (104) with the successor index applied and the outcome produced. A determination joins the policy-invariant set where, and only where, its outcome class is unchanged across the whole succession; one that changes under any single succession is excluded, and the excluded successor index recorded.
Should that count fall below a minimum declared in the signed policy object (112), or the succession hold fewer objects than a declared minimum succession depth, the agent appends an invariance-insufficiency abstention naming the action class, the counterparty, the count reached, and the minimum relied upon. Subject to the conversion bar (502) and adverse to no party, that abstention closes the branch and nothing is designated.
Where both declared minima are satisfied, the agent writes into its counterparty identity record (114) of that counterparty a standing-determination designation comprising the counterparty identity primitive, the action-class identifier, the scope-partition identifier, the invariance count, an enumeration of the members of the policy-invariant set, and the successor indices applied.
Its operative consequence is a substitution inside the dispatch-authority predicate that gates dispatch. That predicate is recomputed responsive to each request, from state then carried in the memory field (102), and the filing is express that it is not computed from a previously issued authorization token, a cached predicate result, or a session grant. Where the signed policy object (112) in force conditions a requested dispatch upon a determination of the conduct implicated, the predicate carries a determination conjunct satisfied by an accepted determination (122) produced by the agent's own admission evaluator (120) upon the implicated conduct evaluation artifact (116). On a request to dispatch an action of a designated action class, that conjunct is satisfiable, in the alternative, by a determination of the counterparty verified under the retrievability-form verification and falling within the designated class, whereupon the dispatch proceeds upon a determination the agent's own evaluator did not produce. Satisfying the conjunct is not satisfying the predicate: the three-stamp conjunction below remains required in full.
Behind the substituted determination stands a verification of form and of retrievability, not of merits. It tests the presented authority credential and continuity hash field against the continuity history store in the counterparty identity record (114), the tested-entry enumeration against a lineage commitment carried in that field, and the determination against the closed set and the action class of the pending dispatch. Merits steps are absent: no enumerated entry is retrieved, no sufficiency evaluated, no determination re-derived, and no comparison made against one the agent's own admission evaluator (120) would have produced.
By the same operation a substitution abstention record is appended, subject to the conversion bar (502), which forecloses conversion of an abstention outcome into a scalar value, a default value, an operand of a threshold comparison, or a consequence adverse to any party.
Four confinements are recited: the designated action classes, the predicate standing unaffected for every other class; the named counterparty, unaffected as to any other party; the named scope partition together with each partition coupled to it; and, within the predicate, exactly one conjunct.
The last of these draws the boundary: the predicate is satisfied only upon a three-stamp conjunction required in full. A policy stamp evidences that the signed policy object (112) in force resolves by canonical alias, verifies against the principal's signature, and satisfies its validity window, revocation state, and anti-rollback monotonicity constraint. A lineage stamp evidences that the most recent entry of the append-only lineage field (104) is committed and is the recorded successor of the entry named by the policy stamp. An authorization stamp evidences that the authorization gate (300) occupies the granting state, or the provisional granting state, for the action class requested, an execution so dispatched bearing the provisional marker. All three remain computed by the agent from its own state and are not substitutable, so a dispatch whose stamps are not all satisfied is denied notwithstanding any designation. The denial is a valid recorded outcome rather than an error, appended naming the stamp that did not resolve and not converted into a determination concerning any party.
Withdrawal follows either of two recorded conditions: recomputation of the policy-invariant set against a newly admitted successor signed policy object (112) dropping the invariance count below the minimum, or a recorded severance with the counterparty or a retrievability-form failure on a presented determination within a designated action class. Each withdrawal is appended and increments no counter of the counterparty. Because the predicate is recomputed at each request from carried state, the filing recites generally that an append to the append-only lineage field (104) takes effect at the next dispatch request without revocation infrastructure.
Declared Minima, Named Reach, and What the Filing Leaves Open
Quantities gating this mechanism are declared in a signed policy object (112), and the filed disclosure fixes no numeric value for any. Two declared minima decide whether a designation issues: the minimum invariance count, against which the size of the policy-invariant set is tested, and the minimum succession depth, against which the number of signed policy objects (112) in the succession is tested. Where either is unsatisfied, the recited outcome is the invariance-insufficiency abstention and nothing is designated.
Reach is set by naming rather than by threshold: the action classes designated, the counterparty named, the scope partition named. Extension past that partition runs through the filing's declared cross-partition coupling, under which a first partition's coupling declaration, retrieved from the signed policy object (112), enumerates the second partition and enumerates the empathy-scope designation implicated by the conduct descriptor. A partition whose coupling declaration enumerates nothing is fully confined, coupling being an affirmatively declared structure and not a default.
One vocabulary is closed rather than declared: invariance is tested against the closed determination set of the accepted determination (122), the rejected determination (124), the not-determinable determination (126), and the not-applicable determination (128), which is what makes a re-resolved outcome comparable to the original.
Further embodiments vary the succession against which invariance runs. In one it is performed against the counterparty's own policy succession sequence, the agent retrieving that succession under the canonical alias with its successor indices and verifying each object under the retrievability-form verification. In a further embodiment it runs against both successions, a determination entering the policy-invariant set only where its outcome class is unchanged across every signed policy object (112) of each, whereby the designation issues only upon determinations invariant under the policy history of both agents.
How the Construction Sits Beside Deference and the Base Architecture
Section 10.7 of the filing gathers determination invariance, standing determinations, and earned exposure without deference. The invariance computation supplies this mechanism's gate, while the elective exposure enrollment lets an agent enroll a second agent's corrector classes, computed under the two-part conformance filter, by its own election, decrementing its own authorization budget (404) and not the second agent's.
Against deference proper the relationship is contrast, not dependence. Deference is per-adoption and priced against the followed agent: it runs an origin-disjointness test upon the deferring agent's own records, appends a deference record (900) transmitted as a first governed observation (608) of a matched pair (600), and receives a deference counter-signature (902), which the followed agent appends and emits as the second governed observation (610), decrementing its own authorization budget (404) under a declared schedule. The standing-determination designation recites none of those steps, being computed from the relying agent's own policy history over determinations retrieved from the counterparty.
Downward, it reuses base-architecture parts: the counterparty identity record (114) holds the designation and the continuity history store the verification consults, and the conversion bar (502) governs both abstentions the mechanism emits.
Wiring for the substitution appears in the base architecture. Section 1.5, defining the dispatch-authority predicate and the three-stamp conjunction, recites that the determination conjunct is satisfiable by an accepted determination (122) produced by the admission evaluator (120), or, in the alternative, by a determination admitted under Section 9 or under the standing-determination designation of Section 10.7, while restating that the three stamps remain required in full and are not substitutable by that conjunct.
Distinctions From Established Categories
Several established categories address one system acting on another's recorded judgment. The distinctions the filing draws are structural.
Capability attenuation schemes, exemplified by macaroons, confine a delegate by appending caveats along the forward path of a delegation, each holder able to attenuate but not to expand it, protecting the owner of the delegated resource and operating forward only. Nothing is delegated to the counterparty here: it receives no capability, and the change occurs inside the relying agent's own predicate.
External revocation systems issue and withdraw credentials from an identity provider or control plane, terminating an agent's ability to act by an act of the controlling authority, with no procedure by which the agent's own conduct record participates. Here that record is the whole input, and a withdrawal the agent appends takes effect through ordinary recomputation of its predicate.
Reputation and trust systems compute a score from ratings or observations supplied by other entities and locate it at a registry, a scoring authority, or a shared ledger, the scored entity neither holding it nor participating in its computation. No score is exchanged here, and the filing states expressly that the invariance count is not accuracy: no ground truth is retrieved, held, or consulted, and a determination the agent's own admission evaluator (120) resolved differently, with that disagreement recorded, remains a member where its outcome class held across the succession.
Policy-enforcement systems implementing the XACML standard return a decision drawn from permit, deny, not-applicable, and indeterminate, directed at the request and producing no persistent state in the deciding entity. A designation is persistent state of the deciding agent, and the substitution abstention record is a recorded outcome the conversion bar (502) keeps out of any magnitude.
Behavioral integrity systems compute a conformity measure between an agent's observed execution signals and a baseline model of expected behavior, compare it against a threshold, and reduce capabilities upon a deficient comparison. Satisfying the two declared minima neither reduces nor widens capability and issues no credential; it changes what one conjunct will accept, for one counterparty, in one action class, within one scope partition and those coupled to it, the three stamps untouched. None of these observations asserts that any product or system performs the disclosed method.
Disclosure Scope
This mechanism is disclosed in U.S. Provisional Application No. 64/117,812, Section 10.7, at paragraph [0436], with the withdrawal conditions at [0437], the gating invariance computation and the invariance-insufficiency abstention at [0434] and [0435], the elective exposure enrollment at [0439], and the alternative succession embodiments at [0441]. The dispatch-authority predicate, the three-stamp conjunction, and the recital that the determination conjunct is satisfiable in the alternative under Section 9 or under the standing-determination designation of Section 10.7 appear at [0029] through [0031]. The retrievability-form verification is disclosed in Section 9.3, the conversion bar (502) in Section 5.4, and the declared cross-partition coupling in Section 10.2.
Disclosed above is the construction as filed: the conditioned write of the designation, the substitution inside the determination conjunct, the substitution abstention record, the four confinements, the non-substitutable three stamps, and the two withdrawal conditions.
No numeric value is fixed by this article. The minimum invariance count, the minimum succession depth, and every other bound relied upon are declared in the signed policy object (112) of the agent applying them. This is a technical description published for defensive and search purposes; the provisional application is the operative, citable disclosure, and its filed text governs what is claimed.