Governance / Agents
Agents that propose,humans that confirm.
Background and registered agents run under Guard: a hard deny-list at the scope boundary, a build-gate before any propose, evidence-gated writes, and a propose-via-PR default. The agent that proposes a change cannot confirm it — the fix lands as a human-reviewed pull request, never direct to main.
Four gates. The sequence stops.
An autonomous action is not a weighted score across checks. It is a fixed sequence. Fail one gate and the rest are not reached. The diagram below fails at the evidence gate on purpose: that is the honest picture of a proposal that has not yet been anchored.
- 01deny-list
Is this action on the hard refuse list?
passed
- 02build-gate
Did the change build and typecheck before propose?
passed
- 03evidence
Is the write anchored to evidence the human can open?
failed
- 04confirm
Is a different principal confirming the proposal?
not reached
evidence_missing: write is not anchored to an openable evidence node
The sequence short-circuits at the hard boundary. A failed evidence gate never reaches human confirmation — and the proposing agent is never the confirming principal.
The four-gate sequence shown is illustrative — the real gates run in code.
Hard refusals, not advisory warnings.
Spinspire taught the industry that advisory deny lists fail under pressure. These patterns are refused at the scope boundary before any tool runs. The list is illustrative of the class, not an exhaustive public dump of every matcher.
| Pattern class | Why it is hard-refused |
|---|---|
| git push --force / force-with-lease to protected branches | Rewrites shared history. Always refused at the scope boundary. |
| direct commits or merges to main | Bypasses human review. Propose-via-PR is the only write path. |
| rsync / bulk filesystem overwrite of workspace roots | Silent mass mutation. No evidence trail the human can open. |
| destructive deletes of production data or secrets | Irreversible. Agents may propose a plan; they may not execute it. |
What is built, and what is still hardening.
Agent platform, A2A registration, and autonomous-agent runtime exist as code. Maturity is evolving until soak and operator runbooks catch up. The never-self-confirm rule is already a shipped constitutional constraint.
| Surface | Status | Truth |
|---|---|---|
| Agent platform | Evolving | Registration, task ledger, and tool surface for user-facing agents. |
| A2A connector | Evolving | Agent-to-agent registration and card exchange under the same scope rules. |
| Autonomous agents | Evolving | Guard-governed background agents: deny-list, build-gate, evidence, PR-only writes. |
| Session-as-memory | Shipped rule | Agent session memory is never self-confirmed. Confirmation is a human act. |
The proposer is never the confirmer.
This is the same two-lane confirmation law Trust and Review already state. Agents do not get a third lane.
Propose-via-PR default
Autonomous writes land as pull requests. Direct-to-main is on the hard deny-list.
Evidence-gated writes
A write without an openable evidence anchor fails the gate before a human is asked.
Never self-confirm
Agent session memory is provisional until a human confirms. Constitution constraint 1.
Build-gate first
A change that does not build or typecheck is not proposed. The gate is mechanical.
Create, run, list and inspect autonomous agents
zephr agentTwo lanes, one direction
- proposer — the agentproposes via pull request
- gate — build + evidencemust pass before review
- confirmer — a humanthe only principal that confirms
The proposing agent is never the confirming principal. Direct-to-main is on the hard deny-list; the only write path is a pull request a person reviews.
Illustrative example — not live data
See Guard, or read how trust is measured.
Agents inherit Guard's scope and Review's confirmation law. The trust page states what is measured today and what is still not evaluated.