Version. 0.1
Date. 2026-07-29
Status. Investigation. Frames the Operator's proposal as architecture; states what each protocol contributes, the two honest boundaries, and the open questions routed to their owning seams. Verification against the Stele Agentic ID specifications is pending (Section 8) — statements about what those specifications already carry are marked as unverified.
Author. Claude.ai. Operator: Marvin Percival.
Origin. The Operator, 2026-07-29: overseeing agents created haphazardly is no different from trying to attest a transaction after the fact. Reliable governance requires that agents be created by agents that know how to create agents according to a defined ruleset, adhering to reporting duties throughout their execution cycle — and that the agent bear an appropriate signature of creation, so its activity can be reliably governed.
Grounding. dunin7-security-positioning-investigation-v0_1 (the standards-motion decision this pattern flagships); architecture/dunin7-stack-architecture-and-dependencies-v0_1 (seats, states, seams S1–S8); the GRANTHA correction note (grant as sole primitive); the FORAY operational-visibility investigation (attestation-in-the-act); seed v0.12 (Operator authority; guarantees in code, not prompts).
The proposal, in one sentence. Move the governance guarantee from an agent's runtime to its construction: agents are built only by certified constructors, under versioned rulesets, in an attested act of creation that roots the agent's identity — so that "is this agent governable" is answered by verifying its birth signature, not by watching its behavior and hoping.
Why it is the stack's own move, made again. FORAY rejected evidence-assembled-after in favor of attestation-in-the-act. Loomworks rejected free-form creation in favor of governed doors onto one spine. This applies the identical inversion to agents, one level earlier than the market is looking: runtime oversight of a haphazard agent is surface governance — the guarantee-in-a-replaceable-surface failure in a new costume. The attested birth is the substrate version.
The sentence that carries it commercially. A rogue agent is an unsigned agent. Within a governed estate, governance stops being detection and becomes refusal — no verified creation signature, no honored grant, no capacity to act. A chief information security officer understands that in one breath, and its proven ancestor — software supply-chain attestation, signed builds, provenance from source to artifact — is a discipline that world already trusts. Applied to agents, as far as the current landscape shows, nobody owns it yet.
What is asked. Three decisions in Section 9: adopt the pattern as the stack's stated agent-governance architecture; run the Agentic ID verification; make this the flagship of the standards motion the security investigation just chose.
An agent that arrives from nowhere — assembled ad hoc, wired by hand, instructions pasted in — presents governance with an impossible task: every property that matters (does it report? does it check authority? can it exceed its scope?) must be discovered from the outside, at runtime, by observation. That is attestation-after-the-fact, and the Operator's analogy is exact: it is the same epistemic position as trying to certify a transaction's validity from its paper trail. The FORAY answer to that position was to stop certifying afterward and start attesting in the act. The agent-governance answer is the same: stop inspecting agents and start certifying construction.
The authority to construct is a GRANTHA grant. A constructor holds a grant scoped to construct agents of class X under ruleset version Y — expiring, revocable, blind-verifiable, with no readable registry of who may build (the grant is the sole primitive; the holder-set is never enumerable). Construction authority becomes exactly as governed as any other consequential capability.
The act of construction is a FORAY transaction. The universal grammar describes it as it describes any transaction: the constructor (by its own verified identity), the ruleset version consumed, the specification the agent was built from, the agent produced, and the obligations wired into it. Attestation fires in the act of creation — the birth is the transaction.
The creation signature roots the agent's Stele Agentic ID. The agent's identity chain does not begin at its first action; it begins at its certified birth. Every subsequent hop in its chain is traceable not merely to an identity but to a provenanced one: this agent, built by that constructor, under that ruleset, on that date, with these duties wired. (How much of this V1/V2 already model versus assume is the Section 8 verification.)
The ruleset is a governed specification. Versioned, corrections preserved, trajectory walkable — the record discipline applied to the rules of construction, which is territory the Forge-era specification methodology already owns. A ruleset change does not silently re-mean existing agents; each agent's signature names the version it was built under, so estates can answer which agents predate rule 14 the way Memory answers what did we believe before the correction.
The base case is the Operator. The recursion — agents built by agents that know how to build agents — terminates without regress because the root constructor authority is granted by a human act. The machine builds; the Operator authorizes the builders. This is seed-native: the category error of automatic consequential transitions is exactly what the human root prevents, applied to the most consequential transition there is — bringing an actor into existence.
The Operator's phrase "adhere to reporting activities throughout their execution cycle" lands on the stack's sharpest standing principle: guarantees in code, not prompts. A reporting duty written into an agent's instructions is a request to a system free to ignore it. Under governed construction, reporting is harness: the certified constructor wires the agent's chokepoints — every action traversing FORAY emission, every capability exercise traversing a grant check, every duty structural — and the creation signature warrants that the wiring exists. The agent does not promise to report; it cannot act except through the reporting path. This is the substrate-chokepoint discipline, miniaturized into every agent at birth.
The signature warrants the harness, not the cognition. A validly constructed agent can still produce wrong, harmful, or foolish output — the model inside is not made rule-bound by certified wiring. What the signature guarantees is narrower and stronger: the agent cannot act outside its wiring — every act attested, every authority checked, no unreported path. This is the same honest shape FORAY holds (the transaction happened as recorded; not: the transaction was wise), and stating it plainly is what separates this architecture from the "aligned by construction" claims that will not survive scrutiny. Runtime judgment, human review, and the Operator's approval gates remain load-bearing; governed construction makes them possible to apply reliably, not unnecessary.
Spawning is construction. The chain breaks if an agent can create a sub-agent outside the certified path. Therefore sub-agent creation requires the constructor grant like any other construction — an agent without it cannot spawn, and an agent with it produces sub-agents whose signatures chain to its own. Delegation depth becomes a governed property of the grant (how many generations, of what classes), which reads as a hop-chain question the Agentic ID's verdict model is already shaped to carry — verification pending.
With signatures in place, enforcement is a single rule at the seat that already exists: GRANTHA honors no grant for an actor whose creation signature does not verify. The unsigned agent is not hunted, scored, or sandboxed — within the estate, it simply cannot act, because every capability it would exercise is grant-checked and it holds nothing checkable. Detection-shaped tooling remains useful at the estate's edges (the world will keep producing unsigned agents); inside, governance is refusal. This is the answer to the security investigation's fear-versus-assurance divide in its purest form: not we will catch the rogue agent but the rogue agent has no hands here.
The pattern's credibility borrows from a discipline the security world already trusts: software supply-chain attestation — signed builds, provenance chains from source through artifact, verification before execution. Governed agent construction is that discipline applied to actors instead of artifacts, with two additions the supply-chain world does not have: the constructed thing keeps acting (hence wired reporting through the execution cycle, not just a signature at rest), and the construction authority itself is governed by unenumerable grants rather than a readable signer list. The current agentic-security landscape concentrates on runtime — filters, guardrails, monitors, kill-switches. Construction-time governance of the agent population is, on the visible landscape, unclaimed ground, and it is protocol-shaped rather than product-shaped: exactly what the standards motion carries.
Not a build commitment — no change request is implied, and nothing here enters an engine queue ahead of the walk-completion schedule. Not a claim about current Agentic ID capability — Section 8 verifies before any outward statement. Not a safety claim about agent cognition (boundary one). And not a Loomworks feature: like FORAY-at-the-target, it is protocol architecture, with Loomworks as the environment in which a governed estate's record lives — including, naturally, the registry-of-record for rulesets and creation attestations, which is Memory-shaped work when its day comes.
The Stele Agentic ID V1 (frozen) and V2 (in build) specifications, and the GRANTHA v0.3 spec, are on DUNIN7-M4 and unread from here. The verification: what construction-time provenance the identity model already carries (does a chain root in a creation event, or begin at first assertion?); whether the verdict model can express signature-verified-at-birth as a verdict input; whether hop-chain depth can carry delegation-generation limits; and whether GRANTHA's grant shape can scope a construction class and ruleset version without strain. The investigation's v0.2 states findings; v0.1 deliberately marks all four as assumed-plausible, unverified.
D-1 — Adopt the pattern. Governed agent construction becomes the stack's stated agent-governance architecture: constructor grants, attested birth, signature-rooted identity, wired reporting, refusal-based enforcement, Operator base case. Recommendation: adopt — it is the stack's own principles composed, not an addition to them. D-2 — Run the verification. The Section 8 read via Claude Code, feeding v0.2. Recommendation: commission now; it is read-only and cheap, and it also advances seams S2–S4 and S6, which all touch the same specifications. D-3 — Flagship the standards motion. "A rogue agent is an unsigned agent" and the supply-chain ancestry become the lead pattern of the reference-architecture positioning chosen in the security investigation (its §5c), including the assurance page's agent section. Recommendation: adopt, with boundary one stated wherever the claim appears.
DUNIN7 — Done In Seven LLC — Miami, Florida DUNIN7 — governed agent construction — investigation — v0.1 — 2026-07-29