Skip to content
Robotadocs

Organization authority

Purpose

Company operations need authority independent of an agent's name, conversation and checkpoint. This package gives an operator-owned broker a verifiable worker ingress, shared durable accounting and fenced task state with owner-controlled Git publication.

Contract

An effect enters an owner-installed action only under a currently valid proof of possession, issuer-pinned workload identity, intersected delegation and an atomic reservation against every applicable authority budget. Privileged actions also require a distinct operator signature for the exact actor, operation, environment and policy epoch; worker requests cannot mint approval or administer policy. Admission and dispatch consult the current policy, and cancellation, expiry or failed policy rechecks withdraw an outstanding action's authority through its abort signal; hosted company composition additionally requires independently anchored authority and audit evidence before accepting requests, including recorded outcomes, and withholds dispatch and trusted outcome settlement until metadata persistence and its independently retained checkpoint are confirmed.

An operation's durable reservation belongs to the control plane rather than a worker snapshot. Repeated completed or conclusively refused operations return their recorded outcome only under a fresh, authorized proof for the same operation; unresolved or conflicting effects cannot be executed again through the worker ingress. Known completion or asset-owner evidence of a confirmed rollback records bounded trusted usage, while cancellation, crash and uncertain outcomes retain their reservations. A task-state outcome recorded atomically with its effect permits trusted owner reconciliation without executing it again or restoring workload authority. A Git intent stored before publication permits owner reconciliation only when the exact receipt commit is reachable from the pinned branch; an unreachable object or absent external outcome cannot release its reservation. Other uncertain effects permit owner settlement only against the exact recorded operation and confirmed evidence from their external asset owner, charging the retained usage bound without restoring authority. Policy loss or schema upgrade cannot silently recreate authority or accounting.

Invariants

Delegation cannot broaden its parent's identity domain, role, scope, validity or budget, and shared accounting includes the entire ancestor chain. Signature domains, operation digests and signed audit checkpoints bind unambiguous canonical bytes to their authority domain, while audit adapters receive only the permitted metadata projection; accepted payload values have a deliberately bounded integer-only JSON representation. One-use proof and approval identifiers are committed with the operation and budget reservation, so a rejected reservation does not partly consume authority. Task-state writes require the current revision and an unexpired, server-issued fence bound to the authorized grant and policy epoch; copying or restoring lease bytes does not transfer that authority. State mutation and its exact outcome commit together in the operator domain. Git publication additionally requires an owner-pinned private asset, the current expected branch OID, a candidate descending from that head and distinct exact operator approval; its receipt preserves candidate content and history. An external Git CAS and the state transaction are not one atomic store, so acknowledgement loss retains accounting until the asset owner proves the publication.

Non-goals

This package does not attest or provision a workload, hold issuer private keys, expose an administrator or operator-approval channel, enforce a provider's physical process/network boundary, control external Git hosting or other provider writes, or assemble the product CLI. Local Git plumbing, cooperative cancellation and trusted action instrumentation do not prove provider termination, effect rollback or a hard limit under an event-loop stall. The recovery journal alone cannot detect an operator-domain rollback; an owner-installed ledger anchor must retain its current checkpoint independently to withhold authority from restored or altered stores. Locally trusted ledger and audit adapters do not establish independent retention or prevent coordinated rollback of a store and its anchor. A trusted external owner must reconcile unknown external effects and retain authoritative budget history across recovery.

Design decisions

The broker runs outside the worker trust domain because a worker must not modify its own authority or budget; independent checkpoint custody similarly prevents a writer from replacing the evidence against which its history is verified. Durable SQLite write transactions serialize reservations and fenced state effects across independent broker processes; refusing unavailable storage or unconfirmed persistence preserves reservations rather than creating permission after restart. An installed ledger anchor advances before the local commit so uncertain acknowledgement freezes authority for owner recovery instead of allowing a stale store to recreate capacity. Explicit owner-controlled schema migration preserves existing stops, revocations, replay evidence and accounting. An owner receipt commit and a single branch CAS avoid treating separately visible refs as atomic publication evidence; exclusive owner control of the repository and retention of pending objects are required for local reachability evidence. Reconciliation of a recorded effect charges the reserved usage bound because lost instrumentation cannot justify a speculative refund. The optional native Node storage capability is a deployment requirement rather than a reason to switch to an in-memory ledger. Separate workload and operator keys keep model/tool execution from manufacturing company approval. Canonical safe integers avoid implicit numeric or unsupported-value coercion across implementations.