1. The Domain Problem

A purchasing agent at one manufacturer needs a component by Thursday. A supply agent at a distributor two states away has it in stock. The two firms have never done business: no account relationship, no exchanged credentials, no shared portal, no master agreement. The order is worth less than the cost of standing up the relationship that would let it be placed.

Commerce usually answers that gap by putting something in the middle. Where no intermediary serves a particular corridor, the fallback is an integration project that runs on the calendar of whichever side moves slower.

Agents turn setup cost into the entire cost. The point of giving an agent purchasing authority is that it transacts at a granularity no human procurement cycle would justify: small orders, unfamiliar suppliers, substitution under a deadline. Every one is a first encounter. If a first encounter requires enrollment, the agent works only inside relationships a human already built, which is the set of transactions that never needed an agent.

A second problem surfaces when something goes wrong. Settlement at an intermediary means the authoritative record lives there and each firm's own account is derivative. If that party is unavailable, applies its own retention practice, or is itself named in the dispute, the record a firm can defend to an auditor is weaker than it looked.

2. Why Existing Approaches Stall

Three families of answer are common, and each stalls in a different place.

Intermediary settlement puts a clearing party, processor, platform adjudicator, or escrow party between the two firms. It requires both parties enrolled with the same intermediary, and that intermediary to exist for the pairing of industries and jurisdictions. Across the long tail of cross-industry agent pairings, no such party is generally available, and where one is, it functions as a policy chokepoint over who may transact and on what terms.

Consensus systems replace the named intermediary with a network that agrees on shared state. That removes the single party but substitutes a different precondition: both firms must join the same network, and finality waits on a commit rather than attaching when the parties agreed. Settling across two networks reintroduces a bridge, which is an intermediary again.

Session-based integration exchanges keys and provisions accounts. It serves a recurring counterparty well and a first encounter not at all, because setup runs on a human timescale while the transaction is a machine-timescale event.

Three answers, one question: what stands behind a transaction between parties who do not already know each other. A fourth answer is available: the two parties' own signed statements and nothing else.

3. What the Filing Discloses

Chapter 6 of the filed provisional application discloses matched-pair settlement.

The unit is the governed observation: a signed structure comprising, at minimum and in sequence, an authority credential field, a continuity hash field encoding identity continuity of the emitting party, a spatial reference field, a temporal reference field, a time-to-live field, a payload field, and an observation lineage field. Emission is complete upon emission. The emitting party requires no acknowledgment, no handshake, no delivery confirmation, and no registration with a central authority as a condition of emission.

A matched pair comprises a first governed observation representing an offer, a tender, a claim, a demand, or a commitment, and a second from the other party representing an acceptance, a counter-tender, an acknowledgment, a refusal, or a fulfillment. The two are recognized as a pair by a pairing rule within one or more of a spatial proximity window and a temporal proximity window, as the governing policy object declares. The pair binds into a settlement record comprising the two signed observations, a cryptographic binding over both, and an attestation of the window in which it was recognized, verifiable by a downstream consumer from the record alone. Settlement occurs upon recognition and admission, finality attaches at that moment, and each party appends a settlement-lineage entry into its own append-only lineage field.

The chapter states three negative conditions explicitly. No third-party intermediary participates: no clearing party, payment processor, platform adjudicator, or escrow party is required for the pair to settle. No centralized consensus is computed: no quorum, ledger commit, or consensus round is a condition of settlement. No pre-negotiated session state exists: no account relationship, session key, standing channel, or prior enrollment is a precondition. Consent is expressed per transaction by the paired observations themselves.

Identity comes from continuity instead of enrollment. The continuity hash field holds a successor hash field, being the emitting party's dynamic agent hash at emission, and a continuity vector field of normalized projections of that party's operational state. A trust-slope validator computes a consistency measure over a declared tolerance window, and an observation is accepted on continuity only where the per-step distance stays within a declared ceiling and the measure meets a declared acceptance threshold. Admission is graded rather than binary: a settlement admissibility evaluator issues exactly one outcome from admit, gate, defer, solicit, reject, and escalate, driven by an evidential weight summed from four declared-coefficient factors, being authority, continuity, freshness, and corroboration.

4. How It Applies in This Domain

Two firms trading across a continent are not near each other. The spatial proximity window admits a scope-partition form, satisfied by a non-empty intersection of the scope-partition identifiers the two observations declare where the parties operate without physical co-location. Agents pair inside a shared commercial scope rather than a shared radius, and a settlement implicating a partition of each party is admissible only in that intersection.

Run the transaction. The purchasing agent emits a first governed observation carrying the requirement, bearing its authority credential and continuity hash. The supply agent, which has never seen this counterparty, verifies both against records in its own memory field, evaluates the input through the admissibility evaluator, and emits a second governed observation. On recognition within the window, both settle. In a further embodiment the receiving agent writes a first-encounter settlement-lineage entry and appends a first-encounter promotion record moving the counterparty's record from the ephemeral tier to the persistent tier. The relationship follows from transacting instead of preceding it.

Terms rarely match on the first pass. The parties exchange counter-observations producing revised terms, admitted per round through the same evaluator and bounded by a declared round count. Exhausting that count is non-convergence, a failure of the timeout class adverse to neither party. Settlement content is placed under an escrow custody record naming the content held, the custodian form, and the release conditions, the forms including a dual-lock arrangement in which each party holds one lock, time-locked release, and event-triggered release. Release in an embodiment is completion of the declared matched pair, and on failure the content is returned unchanged.

A pair may also be recognized only on satisfaction of a declared completion condition whose evidence is linked in the lineage field, such as a credentialed observation of an external event, an authority sign-off, a compliance demonstration, or an aggregation of a declared count of contributing observations. Multi-leg deals use a chained settlement dependency of ascending-indexed links. On failure at a link, that link and those of greater index roll back while lesser-index links stand settled, so rollback propagates downstream only.

A request for quote draws several responders. No pair is recognized until the temporal window elapses, each qualifying second observation held pending. On elapse a contested-pairing detector counts distinct emitter identities: one pairs and settles, while two or more identify a contest in which nothing pairs and the offer resolves to a not-determinable outcome, a contested-offer record enumerating each claimant. The offering party re-emits a fresh first observation naming exactly one identity from that enumeration, so the award is attributable to it and independent of arrival order, and every other bidder receives a non-selected claimant notice that is expressly not a refusal.

Third parties depend on settlements they were not party to, such as a lender advancing against a purchase order. A relying party that independently verifies a settled pair against the counterparty identity records it holds for both parties, then produces a determination consuming that settlement, appends a reliance record and emits it to both settled parties, each entering it in a reliance register. Reversal then carries a condition: the reverting party must append a reliance enumeration satisfying a reliance-completeness predicate against its own register, failing which the reversal stands as an attempted-reversal entry and the settlement is not reversed.

Refusal is metered, and nobody judges it. Declining to complete a pairing is emitted as a refusal observation, incrementing a refusal meter in the refusing party's own memory field, applied without any determination of whether the refusal was well founded. On satisfying its bound, that party's settlement-binding authorization moves from a granting state to a withheld state: it binds no further settlements, while its capacity to observe, to produce determinations, and to emit further refusal observations is preserved. Initiating a dispute record, non-convergence, a timeout, and a failed fulfillment increment no meter of either party.

Taken together: an agent transacts with a counterparty it has never encountered, neither side enrolls, and each party reconstructs its transaction history from its own settlement lineage without recourse to any registry.

5. Deployment Considerations

The governing policy object is the real integration surface. Issued by a deploying authority and resolved by the policy reference field of the party applying it, it declares the proximity and time windows, the pairing rule form, the continuity parameters, the evaluator's coefficients and thresholds, the refusal increment and bound, the escrow-depth bound, the chained-settlement length bound, the retry bound, the solicitation bound, and the deferral-expiration parameter. Where the parties resolve different policy objects, each applies its own, so two firms never have to agree on a rulebook, but each must choose one.

A deployment must still settle which time reference and coordinate frame the temporal and spatial reference fields use, and how partition identifiers are named across organizations that name things differently.

An authority credential comprises an issuing-authority identifier, a scope specification, a temporal-validity specification, a binding attestation, and a cryptographic attestation, and an observation lacking a verifiable authority credential is not a governed observation at all. The mechanism verifies credentials and grades them by evidential weight; it does not issue them. Self-issued escalation takes a self-escalation discount factor and is excluded from the corroboration factor, so no party can corroborate or escalate its own input.

Be clear on the limits.

  • It does not decide who was right. Refusal metering is merit-independent, and merits go to a credentialed dispute procedure initiated by either settled party under its authority credential and routed as the policy object declares, including authority adjudication, arbitration, regulatory review, legal-system procedures, or peer mediation.
  • It does not move funds or verify that goods conform. Escrow holds content and releases it on a stated condition; whether a shipment matched specification is a fulfillment observation judged against the declared completeness of the transaction type.
  • It produces no global view. Each party holds only its own settlement lineage, so anything needing network-wide state is not obtained here.
  • It does not punish a silent counterparty. A timeout resolves nothing against either party, so non-response is never a default judgment.
  • Continuity is tamper evidence, not corporate legal identity. Where legal identity matters the authority credential carries the weight. Storage grows monotonically, since a settlement-lineage entry is never removed or modified.

6. Disclosure Scope

The mechanisms described here are disclosed in U.S. Provisional Application No. 64/117,812, Chapter 6, Matched-Pair Settlement, at Sections 6.1 through 6.16, together with the further embodiments of Section 10 at Sections 10.4, 10.5, 10.8, and 10.13. The filed specification records that this subject matter originates in U.S. Provisional Application No. 64/049,409, filed April 25, 2026.

Disclosed subject matter includes the governed observation and its field structure; the matched pair and its content-matching, cryptographic-handshake, spatial-coincidence, temporal-coincidence, authority-pair, derivation-chain, and sequence-ordered pairing forms; the proximity windows and the scope-partition form; the settlement record and the settlement-lineage entry; settlement without intermediary, consensus, or pre-negotiated session state; identity by continuity through the successor hash field, the continuity vector field, and the trust-slope validator; the settlement admissibility evaluator with its six graduated outcomes and four-factor evidential weight; metered non-acceptance and the withholding of settlement-binding authorization; orphan observations and deferred pairing; escrow, escrow-depth bounding, and settlement in the partition intersection; bilateral demotion, consented forgetting, escrowed promotion, and authorization escrow; reliance bounding on provisional markers; counter-offer negotiation, chained settlement, and the ordered failure-response procedure; credentialed dispute resolution; and, in the further embodiments, first-encounter settlement and promotion, conditional settlement completion forms, contested pairing with attributable resolution by named re-emission, reliance records with the reliance-completeness predicate and transitive reliance chains, and matched-pair leg abstention.

Disclaimed: no payment rail, settlement network, messaging standard, or commercial product is disclosed here, and no third party's implementation is characterized. The application of the architecture to business-to-business agent commerce is placed in the public record as of the publication date shown.

Nothing here asserts that any person or system infringes any right, and nothing states that a license is required. The filings referenced are pending applications, and no claim scope is fixed until claims issue.