Who has to be told when an agent stops executing
An autonomous agent that has written its authorization gate (300) to the withheld state (310) for an enumerated set of action classes, and has transitioned into the non-executing cognitive mode (302), still has counterparties dispatching actions of those classes to it. In the architecture of U.S. Provisional Application No. 64/117,812, the disclosing agent's subsequent non-response to such a dispatch is not treated as a rejected determination (124) and is not treated as an accepted determination (122). It is recorded as a not-determinable outcome identifying the withheld action class as the unavailable input, resolving nothing against either party and incrementing no counter of either party, irrespective of how many such non-responses occur and over what interval.
Against that background the filing sets out a positive disclosure. The disclosing agent constructs and emits a non-execution attestation (504), a governed observation bearing its authority credential, a continuity hash field, a temporal reference field, a time-to-live field, and an observation lineage field. The payload comprises a withheld action-class enumeration, an enumerated evidentiary basis disclosing no conduct descriptor content, an attested epoch field, an abstention-class type marker whose declared type is the abstention type (506), and an express non-determination designation. The receiving agent, on a satisfied verification, writes the attestation as a carried abstention entry of the abstention type (506), where the conversion bar (502) forecloses its reduction to a scalar, a default, or a threshold operand.
That leaves the question of audience. The base rule of Section 5.6 answers it by dispatch history alone. Paragraph [0467] of Section 10.8 states a further embodiment in which the recipient set is narrowed by a second condition read out of the disclosing agent's own counterparty identity records (114).
Two conjuncts computed from records the agent already holds
Under the base rule, the attestation is appended to the disclosing agent's append-only lineage field (104) as an attestation lineage binding referencing the write that occasioned it, and is emitted to each counterparty recorded as having dispatched to the disclosing agent within an emission window declared in the signed policy object (112), and to no other party. Emission is complete upon emission: no acknowledgment is required, and the disclosing agent's state is unchanged by whether any receiving agent admits the attestation.
Paragraph [0467] adds the second conjunct. In the embodiment there disclosed, the disclosing agent emits a non-execution attestation only to each counterparty holding a counterparty identity record (114) at or above a persistence tier declared in the signed policy object (112), the tiers being ordered as declared in that policy object, and recorded as having dispatched to the disclosing agent within an emission window declared in that policy object, and to no other party.
Because the two conditions are joined conjunctively, a counterparty that dispatched inside the emission window while held at a record below the declared tier falls outside the recipient set, as does a counterparty held at a high tier that did not dispatch within the window. The filing places the persistence designation in the counterparty identity record (114) itself, and states the dispatch condition as a recorded fact about the counterparty rather than as a query put to any third party.
Tier ordering is policy-declared. A persistence designation held in the counterparty identity record (114) takes an ephemeral, a persistent, or a promoted value. An ephemeral-tier record is what the agent instantiates for a party from which it receives a conduct evaluation artifact (116) and for which it holds no record: a counterparty identity record (114) at the most restrictive scope, seeded only from the presentation, with an empty encounter history. On recognition of a first-encounter settled matched pair (600) within the pairing window, the agent writes a first-encounter settlement-lineage entry as the first entry of that empty history, appends a first-encounter promotion record, writes the record's persistence from ephemeral to persistent, and writes the provisional primitive as the recorded identity primitive. Promotion to the promoted value under a promotion policy object requires that the encounter history contain no unresolved corrective encounter.
Movement runs in both directions. Where an epoch identifier subsequently received from a promoted party fails the two-stage continuity validation against the sequence held in that record's continuity history, the agent appends a tier demotion record and writes the record's persistence from persistent back to ephemeral, the accumulated encounter history being unmodified and the demotion producing no rejected determination (124). Separately, a counterparty whose conduct evaluation artifacts (116) repeatedly produce rejected determinations (124), at a rate or a run length declared in the signed policy object (112), is demoted by one tier, that demotion being recorded as a persistence designation change in the append-only lineage field (104).
Two express foreclosures close the paragraph. The disclosing agent performs no survey of parties it has not encountered, and constructs no enumeration of parties for the purpose of the emission. The first is a limitation on where the recipient set may come from. The second forecloses a distinct artifact, namely a recipient roster assembled because an attestation is about to be emitted.
What the attestation is not is stated in the payload itself. The express non-determination designation is a recorded field declaring that the attestation is not a determination of the closed set and is not a denial of any dispatch, and the emission modifies no value of the disclosing agent's scoped integrity vector (106) and appends nothing to its counterparty identity record (114) of the receiving agent.
Declared quantities and what the filing leaves open
Every quantity this embodiment turns on is declared in the signed policy object (112) and carries no value in the filed specification.
- The persistence tier threshold. Emission goes to counterparties at or above a persistence tier declared in the signed policy object (112). Which tier that is remains a policy declaration.
- The ordering of tiers. The tiers are ordered as declared in that policy object. The filing names ephemeral, persistent, and promoted values of the persistence designation, and the ordering applied in the emission test is the declared one.
- The emission window. The window within which a counterparty must be recorded as having dispatched to the disclosing agent is declared in the signed policy object (112). No duration and no unit is stated.
- Demotion sensitivity. Demotion by one tier follows a rate or a run length of rejected determinations (124) declared in the signed policy object (112). Neither a rate nor a run length is given.
- Attestation validity. The non-execution attestation (504) bears a time-to-live field. Where that field elapses, a carried abstention entry is released as to an action class at the receiving agent, and the filing states that the elapse is no evidence that the class has been restored. No duration is declared for it.
Nothing in the filing makes emission contingent on receipt. Emission is complete upon emission, and the disclosing agent's state is unchanged by whether any receiving agent admits the attestation.
Where this sits in the withholding pipeline
Emission targeting is one stage of a sequence set out across Sections 5.6 through 5.9 and extended in Section 10.8. Upstream, the write of the authorization gate (300) to the withheld state (310) fixes the content of the attestation: the withheld action-class enumeration is the same set recited in that write, and no action class absent from that write is enumerated.
A companion embodiment constrains the payload toward each recipient. The enumerated evidentiary basis enumerates no entry of the append-only lineage field (104) tested against a conduct evaluation artifact (116) originating from the counterparty to which that attestation is emitted, so the disclosing agent does not identify a receiving agent as an occasion of its own withholding in the attestation it emits to that agent. Where the causal set of the write includes an accepted determination (122) upon such an artifact, the disclosing agent records the omission in the attestation payload, and the omission is not a determination concerning that counterparty. Targeting answers who receives; that embodiment answers what each recipient sees. A third adjusts resolution rather than audience, permitting the withheld action-class enumeration to enumerate at a declared granularity coarser than the action-class identifier, being a declared action-class group.
Downstream, the receiving agent verifies the authority credential and continuity hash field against the continuity history store held in its counterparty identity record (114), applies the successor-continuity test to the attested epoch field, and confirms that the abstention-class type marker resolves within the closed enumeration of abstention classes declared in the signed policy object (112) in force for it and that the withheld action-class enumeration is non-empty. Upon a satisfied verification it writes a carried abstention entry as a value of the abstention type (506), after which the conversion bar (502) governs: no conversion to a scalar, a default, or a threshold operand; no counter of the disclosing agent incremented; nothing adverse appended to its counterparty identity record (114).
Section 10.8 also states a receiver-side bound. Admission of a carried abstention entry is conditioned upon an attestation origin-equivalence gate, under which a further attestation from a party of an origin-equivalence class (200) already contributing more than a declared count of held entries is appended under the failing-element path and is not written as a carried abstention entry. And where a receiving agent's dispatch-authority predicate fails, by operation of carried entries then held, across a count of action classes exceeding a declared bound, that agent emits a relay non-execution attestation of its own, each hop preserving the abstention type.
How this differs from the disclosure patterns it resembles
Three families of prior work sit near enough to be worth separating.
Reputation and trust systems compute a score for an entity from ratings supplied by other entities and expose it to parties deciding whether to transact, locating the score at a registry, a scoring authority, or a shared ledger, with the scored entity neither holding the score nor participating in its computation. Defenses against unfair ratings in such systems, exemplified by the TRAVOS trust model, by beta-reputation filtering, and by the immunization mechanisms surveyed by Dellarocas, filter incoming ratings before aggregation, the filtering party being a disinterested aggregator rather than the rated entity. Two structural differences follow. The audience of a score is whoever queries the registry, which is not a set the scored entity bounds; and the object disclosed is a magnitude, where the object disclosed here is a value of the abstention type (506) that the conversion bar (502) forecloses from becoming one.
Behavioral integrity and probation systems compute a conformity measure between observed execution and a baseline, compare it against a threshold, and modify capability on the comparison. U.S. Patent No. 12,563,045 (Daon) computes an integrity score, modifies capabilities upon the comparison including by issuance of down-scoped tokens, and restores capability upon a reconciliation recorded to a ledger. U.S. Patent No. 12,526,244 (Citibank) maintains a reputation value, applies decay and penalty values, places the entity into a probationary status, and removes the probation after sustained standing. In both, the observable state is a status conferred by the evaluating system and derived from departure from an expected baseline. Here the state disclosed is a withholding the agent itself wrote, emitted to a set derived from its own counterparty identity records (114).
Ethical governor architectures, exemplified by the ethical adaptor of Arkin and Ulam, interpose an evaluative component between deliberation and actuation and restrict the permissible action set upon a determination that a candidate action violates a constraint. That structure addresses no outbound disclosure: the restriction is internal to the governed system, so there is no attestation to target and no recipient set to bound.
None of the above is an assertion about how any product or party operates. The comparison is between structures.
Disclosure Scope
The mechanism described here, non-execution attestation emission targeting by persistence tier, is disclosed in U.S. Provisional Application No. 64/117,812 at Section 10.8, paragraph [0467], with its base emission rule and attestation structure at Section 5.6, paragraphs [0168] through [0174], its receiver verification and abstention-type admission at Section 5.7, the persistence designation with its promotion and demotion conditions at paragraph [0484], and the ephemeral-tier record, first-encounter promotion, and continuity-break demotion at Section 10.4, paragraphs [0387], [0389], and [0392]. This article is a technical description of matter in that filing, offered as a public, timestamped disclosure. Reference numerals above are those of the filed specification. Parameters identified as declared in the signed policy object (112), including the persistence tier threshold, the tier ordering, and the emission window, carry no values in the filing. Nothing here is a claim construction, a legal opinion, or a statement about any product or party other than the applicant.