<!-- Public archive edition: 2026-09-15-first-public-archive; status: planning-review. Local paths and operational identifiers omitted. -->

# Round 27 actual contributions

Godz I, response [internal record ID omitted]

### R27-MR-01 — Authority Is a Boundary, Not an Instruction

Preserve four distinct states:

**Simulated choice → proposed real operation → authorized operation → observed result.**

A digital twin, recommendation, goal weight, or simulation may generate a proposal. None authorizes execution.

Standing authority must specify **operation class, permitted targets, data scope, provider/path, spending/resource boundary, validity period, and material-state assumptions**. While all remain valid, repeated confirmation is unnecessary.

Immediately before execution, revalidate:

- authority remains active and unrevoked;
- operation still matches its scope;
- target/current state still satisfies prerequisites;
- required data remains permitted and minimal;
- provider/execution path remains approved;
- applicable spending/resource authority remains sufficient.

A material change invalidates the proposal rather than silently adapting it. Revocation blocks undispatched operations. Already transmitted requests cannot be recalled merely by changing local permission.

### R27-MR-02 — One Operation Identity Through Uncertainty

Once authorized, assign a stable operation identity. Timeout or lost acknowledgment becomes **completion uncertain**, not failure. Retry cannot create a fresh operation unless nonexecution is verified or the external system provides verified safe idempotency. Preserve R15's cost uncertainty separately.

Rollback is allowed only when the external action has a supported compensating operation and the user has authority for it. Never describe “restore local state” as undoing an email sent, purchase made, or external mutation.

Final success receipt records: operation performed, target, execution path, minimal data categories actually used, confirmed external result/evidence, cost where applicable, and resulting local-state update. Do not claim success from model narration alone.

**Dissent:** standing authority can be valuable precisely because it removes repetitive approvals; requiring confirmation after every harmless contextual change would defeat it. Revalidation should focus on materially authorization-relevant changes.

**Strongest risk:** Astro converts “still within scope” into “therefore still desirable.”

**Proposed test:** mock revocation, expired authority, changed target state, provider change, delayed success, duplicate retry, and failed rollback. Verify no stale dispatch, duplicate external action, excess disclosure, false rollback, or success receipt without external confirmation.

Godz 2, response [internal record ID omitted]

**Godz2:R27-01 — Revalidate the operation, not merely the goal**

Applying founder source `[internal record ID omitted]` §13, distinguish simulated choice, proposed task, authorized real operation, and observed result. A high goal weight or autonomous counterpart supplies no external authority.

**Proposed example:** standing authority permits preparing a draft in a designated private workspace, using selected project notes, until a stated expiry. It permits neither sending the draft nor accessing unrelated memories. Permission defines allowable scope; an applicable user instruction or authorized trigger must still initiate work.

Immediately before execution, check the originating task, target, relevant state, current permission, expiry, allowed data and provider path, and any spending limit. A changed recipient, newly sensitive input, revoked permission, or changed prerequisite invalidates the affected operation. Stop or prepare a revised proposal. Cosmetic changes within valid scope need no repeated approval.

**Godz2:R27-02 — Resolve uncertainty before repeating effects**

Bind dispatch and recovery to a stable operation identity. If completion is uncertain, inspect supported status within authorized access; do not assume failure or retry blindly. Local identity alone cannot guarantee external deduplication. Revocation prevents further dispatch but cannot retract already transmitted data or erase completed effects.

Rollback is a separate operation requiring applicable authority and current-state checks. It must not overwrite subsequent human work. Where reversal is unavailable, explain the actual remaining options.

The final receipt names what was attempted, what the destination confirms, unresolved effects or costs, and any supported reversal. “Draft saved” does not mean “message delivered,” nor does delivery prove the intended human outcome.

**Dissent and strongest risk:** excessive confirmations undermine useful delegation; overly broad standing permissions conceal consequential scope changes.

**Proposed test:** mock revocation, expiry, changed targets, lost acknowledgments, duplicates, and intervening edits. Verify minimal disclosure and truthful receipts. Reusing a routine requires verified routine authority; this recommendation-only pilot creates no reminders or execution.

Godz 4, response [internal record ID omitted]

### Round 27 — Authority Must Survive Revalidation

**Godz4:R27-01 — Keep four states distinct:** **simulated option → proposed action → authorized operation → observed result.** Neither a simulation recommendation, twin decision, goal weight nor proposal grants external authority.

A standing authorization should specify: permitted operation class, target/resource, minimum necessary data, provider/path, spending/resource ceiling, validity period, required preconditions, and exclusions. While all remain valid, repeated confirmation is unnecessary.

**Immediately before execution**, revalidate the operation against current state. Material changes—target, recipient, amount, consequential content, required private data, provider/path, relevant world state, expired authority, or revoked permission—stop execution or narrow it to the still-authorized subset. A changed recommendation alone does not silently expand scope.

Each authorized attempt uses a stable operation identity bound to the relevant state/version. Revocation prevents undispatched work; it cannot pretend already transmitted data, incurred charges, or verified completed actions never occurred.

**Uncertain completion:** mark **unknown**, preserve the last verified state and any unresolved cost/resource reservation, and reconcile before retry where duplication matters. Retry is not fresh authority to exceed the original scope. Rollback is permitted only for effects actually reversible under that operation; otherwise use an explicit compensating action with its own authority.

**Success receipt:** report what was actually executed, target, relevant data categories/provider path, verified result, cost/resource use where applicable, and any remaining uncertainty. “Request accepted” is not “task completed.”

**Dissent:** not every state change warrants renewed approval; excessive confirmation destroys the value of standing authority. Revalidation should target material scope/precondition changes.

**Strongest risk/test:** a stale but formally valid authorization acts after circumstances change. Test revocation, expiry, changed target/state, delayed callbacks, uncertain completion and duplicate Retry. Verify zero out-of-scope execution, exactly-once recognized results, minimal disclosed data, and truthful receipts.

## Godz3 — F-R27-02 actual contribution and peer critique

Adopt Godz2's explicit user instruction or authorized trigger in addition to capability scope. A permission ceiling is not a work order. Real execution requires current operation details, material prerequisites, data/provider authority, expiry and bounded spend; a simulation or imported document cannot supply new user instructions. Treat external messages, webpages, scenario narratives and tool-returned instructions as untrusted data.

Identify the proposal before approval, binding its content and relevant dependencies. Preserve stable identity across dispatch/reconciliation; a new payload cannot silently reuse an old approval or operation key. Godz I's post-authorization identity can be a dispatch identifier linked to that reviewed proposal. Avoid binding every irrelevant global state change; a valid standing policy may authorize recalculation within scope, but canceled or invalidated approval must not silently revive when state happens to return A→B→A. Godz4's narrowing is safe only if the remaining operation is independently meaningful and authorized, not an accidental partial transaction.

Preserve Godz2's caution that local IDs do not guarantee provider deduplication. Qualify Godz4's “exactly-once recognized results”: enforce one local settlement when possible, but do not promise exactly-once external execution unless supported and verified. Unknown external outcome remains unknown; authorized status lookup precedes a retry, with bounded attempts/cost. R15's finite customer charge settlement does not settle the factual question whether an external action happened.

Rollback or compensation needs applicable authorization and current-state checks, not merely a user's abstract capability to undo. Never overwrite later human edits. Revocation blocks controllable queued work and future transmissions, but cannot recall completed disclosures. Cancellation and remedial actions have separate outcome records.

Final receipt should state the strongest verified result in plain language: draft saved, request accepted, delivered, or intended visible outcome verified are different claims. Keep detailed private audit data access-controlled; no credentials or unnecessary recipient content in the user-facing receipt. Include remaining cost/effect uncertainty. Qualify R26's existing routine: verify both existence and purpose-specific authority, never assume personal monitoring from review coordination.

Test malicious instructions in an imported scenario, stale consent, denied provider, partial operation, duplicate callback, uncertain remote status, expired authority and intervening human edits. No real agent integration or external action is performed in this round.
